Static | ZeroBOX

PE Compile Time

2098-06-05 08:58:36

PDB Path

C:\Users\Administrator\Desktop\OneDrive\OneDrive\obj\Debug\OneDrive.pdb

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x000057dc 0x00005800 5.95687367714
.rsrc 0x00008000 0x0001c274 0x0001c400 3.07246418266
.reloc 0x00026000 0x0000000c 0x00000200 0.0815394123432

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x00023830 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x00023830 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x00023830 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x00023830 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x00023830 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x00023830 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x00023830 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x00023830 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x00023830 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x00023830 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x00023830 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_GROUP_ICON 0x00023ca8 0x000000a0 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_VERSION 0x00023d58 0x0000031c LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_MANIFEST 0x00024084 0x000001ea LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with CRLF line terminators

Imports

Library mscoree.dll:
0x402000 _CorExeMain

!This program cannot be run in DOS mode.
`.rsrc
@.reloc
Z:Ca;
  s_
 dsA
v2.0.50727
#Strings
<>9__24_0
<PrincipalWorker>b__24_0
E42B910EF43B9832D7930F42EE674A79DE5F75E3B4BF5E5E620A3ADD456DF702
__StaticArrayInitTypeSize=22
D8BF0A855FE0E8D661F4C91CA53DF73752F2182A529E8F6CF750BB726515E132
__StaticArrayInitTypeSize=32
Microsoft.Win32
UInt32
ToInt32
StringToBase64
__StaticArrayInitTypeSize=7
get_UTF8
EB2F1E89B1BC032DCD0BD3A076EB46A773DF8A95D944EF4B5A05063AD20E7689
<Module>
<PrivateImplementationDetails>
032D8D0DD02C4AA3B4E3FC8F9A488BCFD8C82D3DD8309F0CCDC474ADA8848B1A
capGetDriverDescriptionA
System.IO
value__
DownloadData
HandleData
mscorlib
Thread
Synchronized
GetField
RegistryValueKind
GetMethod
Replace
CreateInstance
defaultInstance
CompressionMode
SelectMode
FromImage
DrawImage
get_Message
Invoke
GetEnvironmentVariable
get_Available
IDisposable
get_Handle
RuntimeFieldHandle
RuntimeTypeHandle
GetTypeFromHandle
Rectangle
GetForegroundWindowTitle
Module
get_Name
cbName
GetTempFileName
get_MachineName
rootPathName
get_FullName
get_UserName
className
MutexName
lpszName
GetOsFullname
DateTime
get_LastWriteTime
LocalMachine
ValueType
GetType
FileSystemFeature
get_Culture
set_Culture
resourceCulture
MethodBase
ApplicationSettingsBase
Dispose
get_Date
EditorBrowsableState
CompilerGeneratedAttribute
GuidAttribute
GeneratedCodeAttribute
DebuggerNonUserCodeAttribute
DebuggableAttribute
EditorBrowsableAttribute
ComVisibleAttribute
AssemblyTitleAttribute
AssemblyTrademarkAttribute
AssemblyFileVersionAttribute
AssemblyConfigurationAttribute
AssemblyDescriptionAttribute
FlagsAttribute
CompilationRelaxationsAttribute
AssemblyProductAttribute
AssemblyCopyrightAttribute
AssemblyCompanyAttribute
RuntimeCompatibilityAttribute
ReadByte
WriteByte
DeleteValue
GetValue
SetValue
defaultValue
Receive
OneDrive
Remove
OneDrive.exe
volumeNameSize
nFileSystemNameSize
set_SendBufferSize
set_ReceiveBufferSize
get_Jpeg
System.Threading
add_SessionEnding
Encoding
System.Drawing.Imaging
FromBase64String
ToBase64String
SendString
Base64ToString
BytesToString
lpString
GetString
System.Drawing
ComputeHash
ComputeStringHash
get_ExecutablePath
GetFolderPath
get_Width
get_Length
processInformationLength
maximumComponentLength
GetWindowTextLength
EndsWith
StartsWith
SessionEndingCallback
RegistryKeyPermissionCheck
System.ComponentModel
Kernel32.dll
avicap32.dll
user32.dll
ntdll.dll
StartupCopiedAssemblyFileStream
NetworkStream
GZipStream
GetStream
MemoryStream
Program
System
HashAlgorithm
resourceMan
ToBoolean
CopyFromScreen
get_PrimaryScreen
CurrentPlugin
rawPlugin
Version
System.IO.Compression
Application
GetVolumeInformation
processInformation
CopyPixelOperation
System.Configuration
System.Globalization
System.Reflection
get_Position
set_Position
Exception
GetGenericInfo
FieldInfo
MethodInfo
FileInfo
CultureInfo
FileSystemInfo
Bitmap
DecompressGzip
ToChar
lpszVer
volumeSerialNumber
GetHardDriveSerialNumber
MD5CryptoServiceProvider
StringBuilder
SpecialFolder
sender
volumeNameBuffer
fileSystemNameBuffer
buffer
get_ResourceManager
PrincipalWorker
SessionEndingEventHandler
System.CodeDom.Compiler
VictimsOwner
CurrentUser
BitConverter
Cursor
.cctor
Monitor
IntPtr
Graphics
System.Diagnostics
get_Bounds
System.Runtime.InteropServices
System.Runtime.CompilerServices
System.Resources
OneDrive.Properties.Resources.resources
DebuggingModes
OneDrive.Properties
GetModules
GetValueNames
GetTypes
SendBytes
WriteAllBytes
StringToBytes
GetBytes
fileSystemFlags
SocketFlags
Settings
SessionEndingEventArgs
System.Windows.Forms
Contains
StringSplitOptions
get_Chars
RuntimeHelpers
Cursors
processInformationClass
hProcess
NtSetInformationProcess
GetCurrentProcess
System.Net.Sockets
SystemEvents
DoEvents
CameraExists
Concat
ImageFormat
PixelFormat
Object
Connect
System.Net
set_MinWorkingSet
Socket
get_Height
op_Explicit
get_Default
get_Client
WebClient
CurrentTcpClient
Environment
nMaxCount
ThreadStart
Convert
set_SendTimeout
set_ReceiveTimeout
System.Text
GetWindowText
GetForegroundWindow
wDriverIndex
GlobalMutex
InitializeArray
ToArray
CreateSubKey
OpenSubKey
RegistryKey
System.Security.Cryptography
get_Assembly
Memory
DeleteValueFromRegistry
GetValueFromRegistry
StoreValueOnRegistry
op_Equality
op_Inequality
WrapNonExceptionThrows
OneDrive
Copyright
2021
$ab4620bb-da7d-4571-8da8-2e859058d518
1.0.0.0
3System.Resources.Tools.StronglyTypedResourceBuilder
16.0.0.0
KMicrosoft.VisualStudio.Editors.SettingsDesigner.SettingsSingleFileGenerator
16.10.0.0
lSystem.Resources.ResourceReader, mscorlib, Version=2.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
PADPADP
C:\Users\Administrator\Desktop\OneDrive\OneDrive\obj\Debug\OneDrive.pdb
_CorExeMain
mscoree.dll
musicnote.soundcast.me
@!#&^%$
279f6960ed84a752570aca7fb2dc1552
HJr()b
4(PCFc%Q
@^kwVh
bg7jB<4"
a#mb'E
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<assemblyIdentity version="1.0.0.0" name="MyApplication.app"/>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v2">
<security>
<requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3">
<requestedExecutionLevel level="asInvoker" uiAccess="false"/>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
OneDrive.Properties.Resources
zwazwczwtzw
Unknown error
getvalue
Execute ERROR
Download ERROR
Executed As
Execute ERROR
Update ERROR
Updating To
Update ERROR
3losh-rat
3losh-
Software\
yy-MM-dd
??-??-??
SOFTWARE\Microsoft\Windows NT\CurrentVersion
ProductName
CSDVersion
Microsoft
Microsoft
SystemDrive
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
Comments
CompanyName
FileDescription
OneDrive
FileVersion
1.0.0.0
InternalName
OneDrive.exe
LegalCopyright
Copyright
2021
LegalTrademarks
OriginalFilename
OneDrive.exe
ProductName
OneDrive
ProductVersion
1.0.0.0
Assembly Version
1.0.0.0
Antivirus Signature
Bkav Clean
Lionic Clean
Elastic malicious (high confidence)
MicroWorld-eScan Trojan.Generic.30044843
FireEye Generic.mg.ae4019c955855d44
CAT-QuickHeal Clean
McAfee GenericRXAA-AA!AE4019C95585
Cylance Unsafe
VIPRE Clean
Sangfor Suspicious.Win32.Save.a
K7AntiVirus Trojan ( 005174541 )
BitDefender Trojan.Generic.30044843
K7GW Trojan ( 005174541 )
Cybereason malicious.955855
Baidu Clean
Cyren Clean
Symantec ML.Attribute.HighConfidence
ESET-NOD32 a variant of MSIL/Bladabindi.IU
APEX Malicious
Paloalto generic.ml
ClamAV Clean
Kaspersky HEUR:Backdoor.MSIL.Bladabindi.gen
Alibaba Backdoor:MSIL/Bladabindi.540f8bf7
NANO-Antivirus Trojan.Win32.Bladabindi.jbnlme
ViRobot Clean
Avast Win32:RATX-gen [Trj]
Tencent Msil.Backdoor.Bladabindi.Lohk
Ad-Aware Trojan.Generic.30044843
TACHYON Clean
Emsisoft Trojan.Bladabindi (A)
Comodo Clean
F-Secure Clean
DrWeb BackDoor.BladabindiNET.10
Zillya Backdoor.Bladabindi.Win32.25641
TrendMicro Clean
McAfee-GW-Edition Artemis!Trojan
CMC Clean
Sophos Mal/Generic-S
Ikarus Trojan.MSIL.Bladabindi
GData Trojan.Generic.30044843
Jiangmin Backdoor.MSIL.faoi
Webroot Clean
Avira TR/Spy.Gen8
Antiy-AVL Trojan/Generic.ASMalwS.349CC89
Kingsoft Clean
Gridinsoft Clean
Arcabit Clean
SUPERAntiSpyware Clean
ZoneAlarm Clean
Microsoft Trojan:MSIL/Bladabindi.OK!MTB
Cynet Malicious (score: 99)
AhnLab-V3 Malware/Win32.RL_Generic.C3552992
Acronis Clean
BitDefenderTheta Gen:NN.ZemsilF.34142.im0@aSS61Fe
ALYac Trojan.Generic.30044843
MAX malware (ai score=83)
VBA32 TScope.Trojan.MSIL
Malwarebytes Malware.AI.1590992093
Zoner Clean
TrendMicro-HouseCall TROJ_GEN.R002C0DIG21
Rising Clean
Yandex Clean
SentinelOne Static AI - Malicious PE
eGambit Unsafe.AI_Score_99%
Fortinet MSIL/Bladabindi.AZ!tr
AVG Win32:RATX-gen [Trj]
Panda Trj/GdSda.A
CrowdStrike win/malicious_confidence_100% (W)
MaxSecure Trojan.Malware.300983.susgen
No IRMA results available.