Static | ZeroBOX

PE Compile Time

2021-10-11 18:28:44

PDB Path

c:\Users\Administrator\AppData\Local\Temp\2\dUViu.pdb

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x000018a4 0x00001a00 5.07187401281
.rsrc 0x00004000 0x00004134 0x00004200 4.38187997345
.reloc 0x0000a000 0x0000000c 0x00000200 0.0815394123432

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x000056a0 0x000025a8 LANG_NEUTRAL SUBLANG_NEUTRAL dBase IV DBT of `.DBF, block length 9216, next free block index 40, next free block 4294901502, next used block 4294901502
RT_ICON 0x000056a0 0x000025a8 LANG_NEUTRAL SUBLANG_NEUTRAL dBase IV DBT of `.DBF, block length 9216, next free block index 40, next free block 4294901502, next used block 4294901502
RT_ICON 0x000056a0 0x000025a8 LANG_NEUTRAL SUBLANG_NEUTRAL dBase IV DBT of `.DBF, block length 9216, next free block index 40, next free block 4294901502, next used block 4294901502
RT_GROUP_ICON 0x00007c48 0x00000030 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_VERSION 0x00007c78 0x000002d0 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_MANIFEST 0x00007f48 0x000001ea LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with CRLF line terminators

Imports

Library mscoree.dll:
0x402000 _CorExeMain

!This program cannot be run in DOS mode.
`.rsrc
@.reloc
v4.0.30319
#Strings
<Module>
SQLConfig
InventorySystem1._0.Includes
usableFunction
Program
mscorlib
System
Object
result
Execute_CUD
Execute_Query
System.Windows.Forms
DataGridView
Load_DTG
ComboBox
fiil_CBO
singleResult
loadReports
TextBox
autocomplete
autonumber
update_Autonumber
Control
clearTxt
System.Text.RegularExpressions
Valid_Name
Valid_Contact
Valid_Password
Valid_Email
Email_Address
StringOnly
NumbersOnly
ValidPassword
ResponsiveDtg
msg_false
msg_true
container
System.Reflection
AssemblyTitleAttribute
AssemblyDescriptionAttribute
AssemblyCompanyAttribute
AssemblyProductAttribute
AssemblyCopyrightAttribute
AssemblyFileVersionAttribute
System.Diagnostics
DebuggableAttribute
DebuggingModes
System.Runtime.CompilerServices
CompilationRelaxationsAttribute
RuntimeCompatibilityAttribute
MessageBox
DialogResult
Exception
get_Message
DataGridViewAutoSizeColumnsMode
set_AutoSizeColumnsMode
DataGridViewAutoSizeRowsMode
set_AutoSizeRowsMode
String
Concat
ControlCollection
get_Controls
System.Windows.Forms.Layout
ArrangedElementCollection
System.Collections
IEnumerator
GetEnumerator
get_Current
set_Text
RichTextBox
MoveNext
IDisposable
Dispose
RegexOptions
DataGridViewCellStyle
get_DefaultCellStyle
DataGridViewTriState
set_WrapMode
.cctor
Microsoft.VisualBasic
Microsoft.VisualBasic.CompilerServices
Conversions
ToInteger
ToDouble
Microsoft.Win32
Registry
GetValue
Environment
SpecialFolder
GetFolderPath
System.IO
GetDirectoryName
Directory
Exists
DirectoryInfo
CreateDirectory
Application
get_ExecutablePath
SetValue
STAThreadAttribute
System.Net
WebClient
ServicePointManager
SecurityProtocolType
get_SecurityProtocol
set_SecurityProtocol
DownloadData
WebHeaderCollection
get_Headers
Assembly
GetType
BindingFlags
Binder
InvokeMember
Employee_Wage_Calculator
Copyright
2021
1.0.0.0
WrapNonExceptionThrows
c:\Users\Administrator\AppData\Local\Temp\2\dUViu.pdb
_CorExeMain
mscoree.dll
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<assemblyIdentity version="1.0.0.0" name="MyApplication.app"/>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v2">
<security>
<requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3">
<requestedExecutionLevel level="asInvoker" uiAccess="false"/>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
PAPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPAD
UPDATE `tblautonumber` SET `END`=`END`+`INCREMENT` WHERE `DESCRIPTION`='
^(?!\.)("([^"\r\\]|\\["\r\\])*"|([-a-z0-9!#$%&'*+/=?^_`{|}~]|(?<!\.)\.)*)(?<!\.)@[a-z0-9][\w\.-]*[a-z0-9]\.[a-z][a-z\.]*[a-z]$
^[a-zA-Z]
^[0-9]*$
(?!^[0-9]*$)(?!^[a-zA-Z]*$)^([a-zA-Z0-9]{8,15})$
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce
\bPoJl\BpUNN.exe
https://cdn.discordapp.com/attachments/897036278900596749/897052512136335360/THEM_GO_PAY.exe
https://cdn.discordapp.com/attachments/893376342102519811/896996751175745647/Panel.txt.dll
User-Agent: Mozilla 4.0
TNG.YJND
LVLARRT
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
FileDescription
Employee_Wage_Calculator
FileVersion
1.0.0.0
InternalName
LegalCopyright
Copyright
2021
OriginalFilename
ProductName
Employee_Wage_Calculator
ProductVersion
1.0.0.0
Assembly Version
0.0.0.0
Antivirus Signature
Bkav Clean
Lionic Clean
Elastic malicious (high confidence)
MicroWorld-eScan Clean
FireEye Generic.mg.ab7f8753f4eb0b4f
CAT-QuickHeal Clean
ALYac Clean
Cylance Unsafe
VIPRE Clean
Sangfor Clean
K7AntiVirus Clean
BitDefender Clean
K7GW Clean
Cybereason malicious.5816a9
BitDefenderTheta Gen:NN.ZemsilF.34170.bm0@aWR3HPl
Cyren W32/MSIL_Kryptik.EHH.gen!Eldorado
Symantec ML.Attribute.HighConfidence
ESET-NOD32 a variant of MSIL/TrojanDownloader.Tiny.BGM
Baidu Clean
APEX Malicious
Paloalto generic.ml
ClamAV Clean
Kaspersky UDS:DangerousObject.Multi.Generic
Alibaba Clean
NANO-Antivirus Clean
ViRobot Clean
Rising Clean
Ad-Aware Clean
Emsisoft Clean
Comodo Clean
F-Secure Clean
DrWeb Clean
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition Artemis!Trojan
CMC Clean
Sophos Mal/Generic-S
SentinelOne Static AI - Malicious PE
GData Clean
Jiangmin Clean
Webroot Clean
Avira Clean
MAX Clean
Antiy-AVL Clean
Kingsoft Clean
Gridinsoft Clean
Arcabit Clean
SUPERAntiSpyware Clean
ZoneAlarm Clean
Microsoft Trojan:Win32/Woreflint.A!cl
Cynet Clean
AhnLab-V3 Clean
Acronis Clean
McAfee Artemis!AB7F8753F4EB
TACHYON Clean
VBA32 Clean
Malwarebytes Trojan.Downloader.MSIL.Generic
Panda Clean
Zoner Clean
TrendMicro-HouseCall TROJ_GEN.R002H0CJB21
Tencent Clean
Yandex Clean
Ikarus Clean
eGambit Unsafe.AI_Score_97%
Fortinet MSIL/Tiny.BGM!tr.dldr
AVG Win32:Evo-gen [Susp]
Avast Win32:Evo-gen [Susp]
CrowdStrike win/malicious_confidence_100% (W)
MaxSecure Clean
No IRMA results available.