Static | ZeroBOX

PE Compile Time

2066-07-24 23:45:40

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x00001ba4 0x00001c00 5.58771333918
.rsrc 0x00004000 0x00004b0c 0x00004c00 2.656237558
.reloc 0x0000a000 0x0000000c 0x00000200 0.0815394123432

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x00004100 0x00004228 LANG_NEUTRAL SUBLANG_NEUTRAL dBase IV DBT of \200.DBF, blocks size 0, block length 16384, next free block index 40, next free block 0, next used block 0
RT_GROUP_ICON 0x00008338 0x00000014 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_VERSION 0x0000835c 0x000005ae LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_MANIFEST 0x0000891c 0x000001ea LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with CRLF line terminators

Imports

Library mscoree.dll:
0x402000 _CorExeMain

!This program cannot be run in DOS mode.
`.rsrc
@.reloc
v4.0.30319
#Strings
IEnumerable`1
IEnumerator`1
IList`1
get_UTF8
ConsoleApp9
<Module>
DownloadData
mscorlib
System.Collections.Generic
Pptsnc
Thread
Synchronized
<Name>k__BackingField
<Url>k__BackingField
<Offices>k__BackingField
Auckland
Office
defaultInstance
get_Message
AddRange
IDisposable
RuntimeTypeHandle
GetTypeFromHandle
Console
get_Name
set_Name
WriteLine
SecurityProtocolType
System.Core
get_Culture
set_Culture
resourceCulture
ApplicationSettingsBase
Dispose
EditorBrowsableState
Website
website
STAThreadAttribute
CompilerGeneratedAttribute
GuidAttribute
GeneratedCodeAttribute
DebuggerNonUserCodeAttribute
DebuggableAttribute
EditorBrowsableAttribute
ComVisibleAttribute
AssemblyTitleAttribute
AssemblyTrademarkAttribute
TargetFrameworkAttribute
ExtensionAttribute
AssemblyFileVersionAttribute
AssemblyConfigurationAttribute
AssemblyDescriptionAttribute
CompilationRelaxationsAttribute
AssemblyProductAttribute
AssemblyCopyrightAttribute
AssemblyCompanyAttribute
RuntimeCompatibilityAttribute
ConsoleApp9.exe
System.Threading
Encoding
set_ObjectCreationHandling
set_ConstructorHandling
System.Runtime.Versioning
String
System.ComponentModel
UserViewModel
set_SecurityProtocol
get_Url
set_Url
Program
System
resourceMan
AppDomain
GetDomain
System.Configuration
System.Globalization
System.Reflection
ArgumentNullException
Newtonsoft.Json
CultureInfo
InvokeMember
Binder
buffer
get_ResourceManager
ServicePointManager
Handler
System.CodeDom.Compiler
IEnumerator
GetEnumerator
.cctor
Consturctor
System.Diagnostics
ExtensionMethods
get_Offices
set_Offices
System.Runtime.InteropServices
System.Runtime.CompilerServices
System.Resources
Pptsnc.Properties.Resources.resources
DebuggingModes
Pptsnc.Properties
List_Types
GetExportedTypes
GetBytes
BindingFlags
JsonSerializerSettings
System.Collections
DeserializeObject
System.Net
get_Default
WebClient
get_Current
ParameterizedThreadStart
JsonConvert
MoveNext
System.Text
get_Assembly
WrapNonExceptionThrows
<Setup for WinSCP 5.17.8 (SFTP, FTP, WebDAV and SCP client)
<Martin Prikryl
<WinSCP
d(c) 2000-2020 Martin Prikryl
$7fdcffb0-fce2-43df-9ae7-6163740fef76
5.17.8.10803
.NETFramework,Version=v4.0
FrameworkDisplayName
.NET Framework 4A
3System.Resources.Tools.StronglyTypedResourceBuilder
16.0.0.0
KMicrosoft.VisualStudio.Editors.SettingsDesigner.SettingsSingleFileGenerator
11.0.0.0
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
PADPADP
_CorExeMain
mscoree.dll
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<assemblyIdentity version="1.0.0.0" name="MyApplication.app"/>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v2">
<security>
<requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3">
<requestedExecutionLevel level="asInvoker" uiAccess="false"/>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
{'Url':'http://www.google.com'}
https://store2.gofile.io/download/2197b10f-8453-488b-84e0-7735ece849ac/Dpfwxe.dll
qFxE2SgNjn
'Name': 'James',
'Offices': [
'Auckland',
'Wellington',
'Christchurch'
Auckland
Wellington
Christchurch
Jcgfbswviwqnsieblto
website
Pptsnc.Properties.Resources
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
Comments
Setup for WinSCP 5.17.8 (SFTP, FTP, WebDAV and SCP client)
CompanyName
Martin Prikryl
FileDescription
Setup for WinSCP 5.17.8 (SFTP, FTP, WebDAV and SCP client)
FileVersion
5.17.8.10803
InternalName
ConsoleApp9.exe
LegalCopyright
(c) 2000-2020 Martin Prikryl
LegalTrademarks
OriginalFilename
ConsoleApp9.exe
ProductName
WinSCP
ProductVersion
5.17.8.10803
Assembly Version
5.17.8.10803
Antivirus Signature
Bkav Clean
Lionic Trojan.MSIL.NanoBot.m!c
Elastic malicious (high confidence)
MicroWorld-eScan Gen:Variant.Bulz.639864
CMC Clean
CAT-QuickHeal Clean
McAfee AgentTesla-FDCV!6BE4CC72830A
Cylance Unsafe
VIPRE Clean
Sangfor Backdoor.MSIL.NanoBot.gen
CrowdStrike Clean
BitDefender Gen:Variant.Bulz.639864
K7GW Trojan-Downloader ( 005892271 )
K7AntiVirus Trojan-Downloader ( 005892271 )
Baidu Clean
Cyren W32/MSIL_Kryptik.FVA.gen!Eldorado
Symantec MSIL.Downloader!gen8
ESET-NOD32 a variant of MSIL/TrojanDownloader.Agent.JDM
APEX Malicious
Avast Win32:DropperX-gen [Drp]
ClamAV Clean
Kaspersky HEUR:Backdoor.MSIL.NanoBot.gen
Alibaba Backdoor:MSIL/AgentTesla.62677648
NANO-Antivirus Clean
SUPERAntiSpyware Clean
Tencent Msil.Trojan-downloader.Agent.Wtea
Ad-Aware Gen:Variant.Bulz.639864
Emsisoft Gen:Variant.Bulz.639864 (B)
Comodo Clean
F-Secure Clean
DrWeb Trojan.DownLoader43.46758
Zillya Clean
TrendMicro TROJ_GEN.R002C0DJL21
McAfee-GW-Edition AgentTesla-FDCV!6BE4CC72830A
FireEye Gen:Variant.Bulz.639864
Sophos Mal/Generic-S
SentinelOne Clean
GData Gen:Variant.Bulz.639864
Jiangmin Backdoor.MSIL.fdwa
MaxSecure Trojan.Malware.73691366.susgen
Avira TR/Dldr.Agent.ikaco
MAX malware (ai score=100)
Antiy-AVL Clean
Kingsoft Win32.Hack.Undef.(kcloud)
Gridinsoft Trojan.Win32.Downloader.sa
Arcabit Trojan.Bulz.D9C378
ViRobot Trojan.Win32.Z.Bulz.27648.A
ZoneAlarm Clean
Microsoft Trojan:MSIL/AgentTesla.DFA!MTB
Cynet Malicious (score: 100)
AhnLab-V3 Trojan/Win.MSILKrypt.C4714401
Acronis Clean
BitDefenderTheta Clean
ALYac Gen:Variant.Bulz.639864
TACHYON Clean
VBA32 Trojan-Downloader.MSIL.gen
Malwarebytes Trojan.Downloader.MSIL.Generic
Zoner Clean
TrendMicro-HouseCall TROJ_GEN.R002C0DJL21
Rising Clean
Yandex Trojan.DL.Agent!Q1SEg+AerWw
Ikarus Trojan-Downloader.MSIL.Agent
eGambit Clean
Fortinet MSIL/SnakeKeylogger.ADFA!tr
Webroot Clean
AVG Win32:DropperX-gen [Drp]
Paloalto generic.ml
No IRMA results available.