Static | ZeroBOX

PE Compile Time

2076-10-15 13:36:48

PDB Path

C:\Users\Administrator\Desktop\BuilderBot\BuilderBot\bin\Release\stub\un_priv\chemicals\obj\Release\dispersal.pdb

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x000013ec 0x00001400 5.41184251244
.rsrc 0x00004000 0x000005e4 0x00000600 4.17845821374
.reloc 0x00006000 0x0000000c 0x00000200 0.0815394123432

Resources

Name Offset Size Language Sub-language File type
RT_VERSION 0x00004090 0x00000352 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_MANIFEST 0x000043f4 0x000001ea LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with CRLF line terminators

Imports

Library mscoree.dll:
0x402000 _CorExeMain

!This program cannot be run in DOS mode.
`.rsrc
@.reloc
v4.0.30319
#Strings
IEnumerable`1
ToUInt32
get_UTF8
<Module>
System.IO
DownloadData
mscorlib
System.Collections.Generic
forgetPassword
Replace
resource
get_MainWindowHandle
google
username
logoutme
SecurityProtocolType
GetType
GuidAttribute
DebuggableAttribute
ComVisibleAttribute
AssemblyTitleAttribute
AssemblyTrademarkAttribute
TargetFrameworkAttribute
AssemblyFileVersionAttribute
AssemblyConfigurationAttribute
AssemblyDescriptionAttribute
CompilationRelaxationsAttribute
AssemblyProductAttribute
AssemblyCopyrightAttribute
AssemblyCompanyAttribute
RuntimeCompatibilityAttribute
to_save
dispersal.exe
interfacing
Encoding
System.Runtime.Versioning
FromBase64String
ToString
GetString
Setting
finish
GetFolderPath
get_Length
length
dispersal
user32.dll
set_SecurityProtocol
Program
System
reset_token
System.Reflection
cleanup
InvokeMember
reader
SpecialFolder
Binder
ServicePointManager
.cctor
System.Diagnostics
System.Runtime.InteropServices
System.Runtime.CompilerServices
sync_preferences
DebuggingModes
BindingFlags
chemicals
get_Chars
onetimepass
GetCurrentProcess
Exists
Concat
Object
System.Net
WebClient
Environment
Convert
Logout
System.Text
ShowWindow
nCmdShow
CreateSpecialByteArray
ToCharArray
verify
Assembly
GetCurrentDirectory
WrapNonExceptionThrows
chemtrails
RecreationArts
chemicals
Copyright
2021
$31b9e4cf-8bbf-4a18-9cf2-68756a11b1f1
23.14.11.0
.NETFramework,Version=v4.7.2
FrameworkDisplayName
.NET Framework 4.7.2
C:\Users\Administrator\Desktop\BuilderBot\BuilderBot\bin\Release\stub\un_priv\chemicals\obj\Release\dispersal.pdb
_CorExeMain
mscoree.dll
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<assemblyIdentity version="1.0.0.0" name="MyApplication.app"/>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v2">
<security>
<requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3">
<requestedExecutionLevel level="asInvoker" uiAccess="false"/>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
/gro.otpoh.sllafradec//:ptth
VpnHBe.txt
txTTBOFt.2TTBOFmeTTBOFedTTBOFer/grTTBOFoTTBOF.otTTBOFpoh.slTTBOFlafraTTBOFdec/TTBOF/:pttTTBOFh
Z7d6MexZ7d6Me.srZ7d6MeswoZ7d6Mrbger_teZ7d6MnpsaZ7d6M\91Z7d6M303Z7d6M.0.4v\Z7d6MkroZ7d6MwemaZ7d6MrFZ7d6M\TEZ7d6MN.tZ7d6MfZ7d6MosoZ7d6MrciMZ7d6M\swoZ7d6MdniZ7d6MW\Z7d6M:CZ7d6M
fixedhost.modulation
cookie
//explorerw.exe
dispersal
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
Comments
CompanyName
RecreationArts
FileDescription
chemtrails
FileVersion
23.14.11.0
InternalName
dispersal.exe
LegalCopyright
Copyright
2021
LegalTrademarks
OriginalFilename
dispersal.exe
ProductName
chemicals
ProductVersion
23.14.11.0
Assembly Version
23.14.11.0
Antivirus Signature
Bkav Clean
Lionic Clean
Elastic malicious (high confidence)
DrWeb Clean
MicroWorld-eScan IL:Trojan.MSILZilla.9574
FireEye Generic.mg.c41c006620779350
CAT-QuickHeal Clean
ALYac IL:Trojan.MSILZilla.9574
Cylance Clean
VIPRE Clean
Sangfor Clean
K7AntiVirus Clean
BitDefender IL:Trojan.MSILZilla.9574
K7GW Clean
Cybereason Clean
BitDefenderTheta Gen:NN.ZemsilCO.34266.am0@a4qIwUd
Cyren Clean
Symantec Clean
ESET-NOD32 a variant of MSIL/TrojanDownloader.Agent.JKD
APEX Malicious
Paloalto generic.ml
ClamAV Clean
Kaspersky HEUR:Trojan-PSW.MSIL.Agensla.gen
Alibaba Clean
NANO-Antivirus Clean
ViRobot Clean
Rising Clean
Ad-Aware IL:Trojan.MSILZilla.9574
Sophos Clean
Comodo Clean
F-Secure Clean
Baidu Clean
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition Clean
CMC Clean
Emsisoft IL:Trojan.MSILZilla.9574 (B)
Ikarus Clean
GData IL:Trojan.MSILZilla.9574
Jiangmin Clean
Webroot Clean
Avira Clean
MAX malware (ai score=85)
Antiy-AVL Clean
Kingsoft Clean
Gridinsoft Clean
Arcabit IL:Trojan.MSILZilla.D2566
SUPERAntiSpyware Clean
Microsoft Clean
Cynet Malicious (score: 100)
AhnLab-V3 Clean
Acronis Clean
McAfee Clean
TACHYON Clean
VBA32 Clean
Malwarebytes Spyware.AgentTesla.MSIL
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Tencent Msil.Trojan-downloader.Agent.Svhc
Yandex Clean
SentinelOne Clean
MaxSecure Clean
Fortinet MSIL/Agent.JJY!tr.dldr
AVG Win32:PWSX-gen [Trj]
Avast Win32:PWSX-gen [Trj]
CrowdStrike win/malicious_confidence_70% (W)
No IRMA results available.