Static | ZeroBOX

PE Compile Time

2053-06-17 23:31:24

PDB Path

C:\Users\jpint\source\repos\wlwtproject\wlwtproject\obj\Release\wlwtproject.pdb

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x0000129c 0x00001400 5.21766359378
.rsrc 0x00004000 0x00000670 0x00000800 3.58922047813
.reloc 0x00006000 0x0000000c 0x00000200 0.0815394123432

Resources

Name Offset Size Language Sub-language File type
RT_VERSION 0x00004090 0x000003de LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_MANIFEST 0x00004480 0x000001ea LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with CRLF line terminators

Imports

Library mscoree.dll:
0x402000 _CorExeMain

!This program cannot be run in DOS mode.
`.rsrc
@.reloc
v4.0.30319
#Strings
IEnumerable`1
ToUInt32
get_UTF8
<Module>
System.IO
DownloadData
mscorlib
System.Collections.Generic
forgetPassword
Replace
resource
get_MainWindowHandle
username
SecurityProtocolType
GetType
integrate
GuidAttribute
DebuggableAttribute
ComVisibleAttribute
AssemblyTitleAttribute
AssemblyTrademarkAttribute
TargetFrameworkAttribute
AssemblyFileVersionAttribute
AssemblyConfigurationAttribute
AssemblyDescriptionAttribute
CompilationRelaxationsAttribute
AssemblyProductAttribute
AssemblyCopyrightAttribute
AssemblyCompanyAttribute
RuntimeCompatibilityAttribute
wlwtproject.exe
interfacing
Encoding
System.Runtime.Versioning
FromBase64String
ToString
GetString
finish
GetFolderPath
get_Length
length
user32.dll
set_SecurityProtocol
Program
System
System.Reflection
cleanup
InvokeMember
reader
SpecialFolder
Binder
ServicePointManager
tether
starter
.cctor
System.Diagnostics
System.Runtime.InteropServices
System.Runtime.CompilerServices
DebuggingModes
BindingFlags
options
get_Chars
onetimepass
GetCurrentProcess
Exists
Concat
Object
wlwtproject
System.Net
WebClient
Environment
Convert
System.Text
ShowWindow
nCmdShow
CreateSpecialByteArray
ToCharArray
identify
Assembly
GetCurrentDirectory
WrapNonExceptionThrows
RReleased wlwt weather reading app for win32/64 attributed systems for weather apps
wlwtscan
Copyright
2021
$0efaae0d-717a-4ca7-b5fc-14adbfc16821
23.11.14.0
.NETFramework,Version=v4.7.2
FrameworkDisplayName
.NET Framework 4.7.2
C:\Users\jpint\source\repos\wlwtproject\wlwtproject\obj\Release\wlwtproject.pdb
_CorExeMain
mscoree.dll
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<assemblyIdentity version="1.0.0.0" name="MyApplication.app"/>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v2">
<security>
<requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3">
<requestedExecutionLevel level="asInvoker" uiAccess="false"/>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
=,!ex=,!e.sr=,!eswo=,!rbger_te=,!npsa=,!\91=,!303=,!.0.4v\=,!kro=,!wema=,!rF=,!\TE=,!N.t=,!f=,!oso=,!rciM=,!\swo=,!dni=,!W\=,!:C=,!
fixedhost.modulation
cookie
/691.941.09.111//:ptth
txt.2meeder/691.941.09.111//:ptth
//graphic.exe
POGCHAMP
\POGCHAMP.exe
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
Comments
Released wlwt weather reading app for win32/64 attributed systems for weather apps
CompanyName
FileDescription
FileVersion
23.11.14.0
InternalName
wlwtproject.exe
LegalCopyright
Copyright
2021
LegalTrademarks
OriginalFilename
wlwtproject.exe
ProductName
wlwtscan
ProductVersion
23.11.14.0
Assembly Version
23.11.14.0
Antivirus Signature
Bkav Clean
Lionic Trojan.MSIL.Agensla.i!c
Elastic malicious (high confidence)
DrWeb Clean
MicroWorld-eScan IL:Trojan.MSILZilla.9574
FireEye Generic.mg.0e2cb83d70db215f
CAT-QuickHeal Clean
McAfee Artemis!0E2CB83D70DB
Cylance Clean
VIPRE Clean
Sangfor Clean
K7AntiVirus Clean
BitDefender IL:Trojan.MSILZilla.9574
K7GW Clean
Cybereason Clean
Arcabit Clean
BitDefenderTheta Clean
Cyren W32/MSIL_Troj.FPJ.gen!Eldorado
Symantec ML.Attribute.HighConfidence
ESET-NOD32 Clean
Zoner Clean
TrendMicro-HouseCall Clean
Paloalto generic.ml
ClamAV Clean
Kaspersky HEUR:Trojan-PSW.MSIL.Agensla.gen
Alibaba TrojanPSW:MSIL/Agensla.3298d9e1
NANO-Antivirus Clean
ViRobot Clean
Rising Clean
Ad-Aware IL:Trojan.MSILZilla.9574
Emsisoft IL:Trojan.MSILZilla.9574 (B)
Comodo Clean
F-Secure Clean
Baidu Clean
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition Artemis!Trojan
CMC Clean
Sophos Clean
Jiangmin Clean
MaxSecure Clean
Avira Clean
MAX malware (ai score=82)
Antiy-AVL Clean
Kingsoft Win32.PSWTroj.Undef.(kcloud)
Gridinsoft Clean
Microsoft Clean
SUPERAntiSpyware Clean
GData IL:Trojan.MSILZilla.9574
Cynet Clean
AhnLab-V3 Clean
Acronis Clean
VBA32 Clean
ALYac IL:Trojan.MSILZilla.9574
TACHYON Clean
Malwarebytes Clean
Panda Trj/GdSda.A
APEX Malicious
Tencent Msil.Trojan-qqpass.Qqrob.Gca
Yandex Clean
SentinelOne Static AI - Suspicious PE
eGambit Clean
Fortinet PossibleThreat
Webroot Clean
AVG FileRepMalware
Avast FileRepMalware
CrowdStrike win/malicious_confidence_90% (W)
No IRMA results available.