Static | ZeroBOX

PE Compile Time

2046-12-14 03:15:45

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x000048d4 0x00004a00 5.92593146946
.rsrc 0x00008000 0x00000cb8 0x00000e00 4.20990812363
.reloc 0x0000a000 0x0000000c 0x00000200 0.0815394123432

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x00008448 0x00000128 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x00008448 0x00000128 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_GROUP_ICON 0x00008570 0x00000022 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_VERSION 0x00008594 0x00000334 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_MANIFEST 0x000088c8 0x000003ed LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with CRLF line terminators

Imports

Library mscoree.dll:
0x402000 _CorExeMain

!This program cannot be run in DOS mode.
`.rsrc
@.reloc
n 5%D<X
ee LKc
99ee w
n 5%D<X
1e 4Do
a KDS<a
99ee w
JOp+a
.*lQ
99ee w
n 5%D<X
n 5%D<X HX
Yf H?n
.*lQ
JOp+a
v4.0.30319
#Strings
ConsoleApp3
ConsoleApp3.exe
<Module>
Program
WindowsFormsApp19
Object
System
mscorlib
Resources
WindowsFormsApp19.Properties
Settings
ApplicationSettingsBase
System.Configuration
<Module>{8532559d-38b0-4d2c-be0d-20a0c4b82a0e}
RunParameter
ServicePointManager
System.Net
set_SecurityProtocol
SecurityProtocolType
WaitCallback
System.Threading
IntPtr
ThreadPool
QueueUserWorkItem
Boolean
Console
WriteLine
String
AddWorker
Enumerator
Dictionary`2
System.Collections.Generic
MethodInfo
System.Reflection
KeyValuePair`2
Assembly
GetExportedTypes
Reverse
WebClient
GetMethod
MethodBase
Invoke
GetEnumerator
get_Current
MoveNext
get_Value
Func`2
Enumerable
System.Linq
System.Core
FirstOrDefault
IEnumerable`1
IDisposable
Dispose
GetMethods
RunWorker
ProcessStartInfo
System.Diagnostics
set_FileName
set_Arguments
Process
ResolveParameter
AssetParameter
RuntimeTypeHandle
GetTypeFromHandle
GetParameter
ForgotParameter
get_Count
CallParameter
PushParameter
RestartParameter
ProcessWindowStyle
set_WindowStyle
CompareParameter
set_UseShellExecute
StartParameter
set_ErrorDialog
PrepareParameter
WaitForExit
_Product
m_Adapter
_Predicate
WriteParameter
.cctor
FillWorker
ValidateWorker
op_Equality
CloneParameter
CreateParameter
ConnectParameter
CalcParameter
op_Inequality
CollectParameter
MemberInfo
get_Name
worker
ResourceManager
System.Resources
m_Instance
CultureInfo
System.Globalization
PatchParameter
get_ResourceManager
get_Assembly
get_Culture
set_Culture
RegisterParameter
ValidateParameter
Culture
defaultInstance
PublishParameter
get_Default
PrintParameter
MapParameter
QueryParameter
SettingsBase
Synchronized
Default
m_09fff6f1a4e547fda0480a072faf476a
m_a285d9464b804cde8cf7a6aea34cbc7a
m_c4c32e1797a94c0c936f38c89b7a14cc
m_4e0487170ca942d7847b78f18f8a8f18
m_80dda1f3027749ac8843ea1fe3a172f5
m_4cac1138ac3c40829033b32c405e9f87
m_f69cb81342934808b63ad0acc46fb2d8
m_5bfedbd7e7c947149bf831feaf2b784d
m_3ff59700d1b74195bcc94a420bf8c3c8
m_cdb7dee9b16c4c2c95e80bcf8966d6be
m_e478d11397da4634bc95fcf9c006870a
m_3a48aeffe728457fb15198280832676a
m_76de178cdceb41a99329c3b608fdb94b
m_e06a6fbb3c5949f490fad812309232d5
m_2fd88b6157684467a845252399da4483
m_6450ec459da64d8d9e2a51bbce3ccee9
m_a59af393faf54c5a9f42078e4fb16b5a
m_de741a7a76d341a9bbd7e2ccb6951b57
m_cb7f91c290ba4bd380c89f75bca10c41
m_c66b1f03067649958389924f4a281393
m_b9bd346c5d104417a5319ad0cb4baa12
m_d27fc8bd4da94a92a53613be07e0b195
m_d34e52061eb04e24a499d1c9a2317c6a
m_fcf43da7310f4e1e9ac3f24de2c96fcd
m_b14e889ba256478ca8cd82952e21dd05
m_a4738a088c7e419c97ad3287246913a1
m_460e943ce45c48dc871fb5d27d23203f
m_71fd3289fec7451281a492683c457a62
m_7dae8e74a22e4dd5a5d7da4a890c6483
m_8079a28e2f6142edbb299d36bde20a6b
m_a0e8c96b7690405ca309498f07dcaf31
m_c1b130eac1ee4213b6bb643a4fe1880e
m_bdd9988421834b2bbd3ded14cfaf3fbf
m_88f475bc8cae41ddaef264328933d1c5
m_55391deb164d4243be5eb8156a3e2751
m_291094fd06774800942062f83b764916
m_bad2178c4c1940378e518b0fdbda4b4b
m_14da3cc73bff4831a4a1af09f10b858a
m_1aae75d06b73467882c817194e635d3f
m_165917d3abb245fbb1d369b197cd1be2
m_83dce687688548de9ad60f52db690dcf
m_5e2b52a793d54241ad94673035c06d95
m_af676f23a77a45df881431e6f8cea429
m_041dcba78b9e4c03b0cde28ea038d4b4
m_e3c062db5426492a8c4ad3b731f0a752
m_7f329ae9951a404e832df5d48463f932
m_2f6ecbedd42f49e9a7c128a116b39824
m_a4868c2f6ac946cea2aee18ddca2667b
m_efbcf1fdcfd34a73b1e0709413cd66e2
m_dcba472abbca412894341ac92733b7f4
m_ecfbe7583a7848309b3870c5e13c4642
m_86edf4f129af463296ad762524f5933e
m_296dd0aaaeb64d6a99d2a49636ca4a67
m_6a190c3e5d4d4db695dd41139602b4ce
m_b7cceb75ad04456c9c8e13fb89a00167
m_a6418aacdbe44cd1ac9b7a946342f1f9
m_b1793492f51e4ddf89eb3b44c609b3ea
m_bff720a352f1486e908cea43ddc0c0af
m_44373b7b398e4830aeddaba06c199c1f
m_39c264e0cbea424b9598b3da1d9a1e67
m_4871a3fe46394b2f9aabd36f1764a21e
m_6995a589f1a94c2da45dd2e064fb6657
m_c3697ffee6234f11969cf6db91293f9e
m_a21b41d4feee421fb5f5c79fe3dabbe9
m_6e52abe9a0c84cb89742459c38f91baa
m_720d8ec09594471d9eefc0818380071d
m_32033abc4e12478e894cae201ddfec87
m_a1059e6456d74b84836518013308b33e
m_e9a1bbd349d949589ca990b42c060765
m_bf54d6e41e4e4ae3bc2f16abd4d01e81
m_5255785557d4451289ac0c3448959984
m_2ad3d19143524407b973964ef06eabef
m_5c2d325073ea4aeb8ff1824e390925c9
m_41bb619da7974da487cf93c138916c19
m_a865106cf31342178ed5161cdc0f9783
m_2f3f0663411147d29a7d859eb5c39f45
m_7ca9378b317742269e6de3afae5cbea9
m_7e835798e58f4a38ab1cef0d6e690bb5
m_78adef88895449b18fd3f95013037193
m_507c082a155347a99b522378923026d1
m_39c1c506ea654e87ad68c160b578a88e
m_3d7e641612ee405cb1638ce99ffc7d5b
m_b30cd6a9a53e4e918c68390acc098586
m_6ce5f3882a3b4c4b9eb880eb451eb691
m_606628ba7b4b4b41a07f6d28932e7271
m_653fb7f30fe140f2aaa0f8d31ae9c568
m_678538f86ba34bb5948db3a10dd611a4
m_afd1405ea6ef46b6acc61b0afc4f738d
m_ea5d4f9b4cc847d597ce44b4a89ed0b5
m_28c773b9a291443aa76e9acab9c73288
m_7c21542b3d6243c1a67a774defaa57bb
m_562126064ab44007a2f403ac46af3f1d
m_0fe83bba7fce432a872927469afa08ec
m_02787334f50243bf973b78bcb57e1195
m_e685a0c14ddc4f1ebc46623963731de8
m_48013a5d44a64a5cafda3872b0ee267b
m_b9c72e106add4754a59658fdad9db06d
m_5dd1b828faec495db3942219895dcfb9
m_678378dbc8134a748400df26f703f888
m_c0b8f2e8a60e48858acb1577b2965370
m_5b9f6e0b3a5d4e4b9027ec4e3d9399a2
m_0542b38844f047228cbf8a19d1b88dd0
m_ec1c974c33164f27a0aeae95976b8618
m_d8425ab3c46449128e56468035516c24
m_2ab919dd338942dcb4b76b623bb33eb9
m_05972defff494c05b915d705155a1368
m_79546f8f13d14f0e8a9718a085fa0efa
m_51f7d5f56c2044afb303c56f18b490cd
m_04035f28659a431a92ce46861f1a0371
m_015e099a57a1473c9a183ffe3c5e2022
m_cd8e64c10408497b88c47693ed313381
m_4efbe0c31df240c8989426f873ee768d
m_8bf12048f939459d8dcfcc4e086bf36c
m_cfcfec6dda2a42c2a0b4fd6d03e4fc43
m_0345c73f64c04991bda089e60be75008
m_d7c5bc3e02e44aaa9efb57b4761b0359
m_37d3c621a936478d9a9c1870814c23a7
m_6556038a8ecc4c7cb4709e401cc80e1e
m_34b228e5f40a4158b322efa004ff784c
m_4609c6aa87b1425985ffa5cacced22f6
m_15bcabf156254c90a9f83046a5d548e4
m_9e6c70699de8485488f9473e1ea393e9
m_447b17a6f162426dbe1cb0bf6bb228f2
m_0cc0d883d13744debb5eba6b25f6feda
InstantiateParameter
t7669b116862a40d99b1a652e8d0da8a6
ConcatParameter
ReflectParameter
ResetParameter
CompilationRelaxationsAttribute
System.Runtime.CompilerServices
RuntimeCompatibilityAttribute
DebuggableAttribute
DebuggingModes
AssemblyTitleAttribute
AssemblyDescriptionAttribute
AssemblyConfigurationAttribute
AssemblyCompanyAttribute
AssemblyProductAttribute
AssemblyCopyrightAttribute
AssemblyTrademarkAttribute
ComVisibleAttribute
System.Runtime.InteropServices
GuidAttribute
AssemblyFileVersionAttribute
TargetFrameworkAttribute
System.Runtime.Versioning
STAThreadAttribute
GeneratedCodeAttribute
System.CodeDom.Compiler
DebuggerNonUserCodeAttribute
CompilerGeneratedAttribute
EditorBrowsableAttribute
System.ComponentModel
EditorBrowsableState
WindowsFormsApp19.Properties.Resources.resources
WrapNonExceptionThrows
KFCLEANER
Copyright
2014
$deb0f9e6-584f-4b72-a785-6ffcd0a76c66
1.0.0.0
.NETFramework,Version=v4.0
FrameworkDisplayName
.NET Framework 4
3System.Resources.Tools.StronglyTypedResourceBuilder
16.0.0.0
KMicrosoft.VisualStudio.Editors.SettingsDesigner.SettingsSingleFileGenerator
11.0.0.0
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
PADPADP
_CorExeMain
mscoree.dll
wwwwwwwwwwwwwwp
DDDDDDDDDDDDDDp
DDDDDDDDDDDDDDp
LLLLLLLLLN
DDDDDDDDDDDDD@
wwwwwwwDDDDDDDGO
DDDDDD
<?xml version="1.0" encoding="utf-8"?>
<assembly manifestVersion="1.0" xmlns="urn:schemas-microsoft-com:asm.v1">
<assemblyIdentity version="1.0.0.0" name="MyApplication.app"/>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v2">
<security>
<requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3">
<requestedExecutionLevel level="asInvoker" uiAccess="false" />
</requestedPrivileges>
</security>
</trustInfo>
<compatibility xmlns="urn:schemas-microsoft-com:compatibility.v1">
<application>
<supportedOS Id="{8e0f7a12-bfb3-4fe8-b9a5-48fd50a15a9a}" />
</application>
</compatibility>
<application xmlns="urn:schemas-microsoft-com:asm.v3">
<windowsSettings>
<dpiAware xmlns="http://schemas.microsoft.com/SMI/2005/WindowsSettings">true</dpiAware>
<longPathAware xmlns="http://schemas.microsoft.com/SMI/2016/WindowsSettings">true</longPathAware>
</windowsSettings>
</application>
</assembly>
-enc UwB0AGEAcgB0AC0AUwBsAGUAZQBwACAALQBzACAAMgAwAA==
DownloadData
http://www.taijimp3.com/zb_system/image/common/ConsoleApp3.bin
-enc aQBwAGMAbwBuAGYAaQBnACAALwByAGUAbgBlAHcA
powershell
-enc aQBwAGMAbwBuAGYAaQBnACAALwByAGUAbABlAGEAcwBlAA==
DoWork
WindowsFormsApp19.Properties.Resources
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
Comments
KFCLEANER
CompanyName
FileDescription
KFCLEANER
FileVersion
1.0.0.0
InternalName
ConsoleApp3.exe
LegalCopyright
Copyright
2014
LegalTrademarks
OriginalFilename
ConsoleApp3.exe
ProductName
KFCLEANER
ProductVersion
1.0.0.0
Assembly Version
1.0.0.0
Antivirus Signature
Bkav Clean
Lionic Trojan.Multi.Generic.4!c
Elastic malicious (high confidence)
MicroWorld-eScan Clean
CMC Clean
CAT-QuickHeal Clean
ALYac Clean
Cylance Unsafe
VIPRE Clean
Sangfor Clean
K7AntiVirus Clean
BitDefender Clean
K7GW Clean
CrowdStrike win/malicious_confidence_70% (W)
Baidu Clean
VirIT Clean
Cyren Clean
Symantec ML.Attribute.HighConfidence
ESET-NOD32 a variant of MSIL/TrojanDownloader.Agent_AGen.EY
APEX Malicious
Paloalto generic.ml
ClamAV Clean
Kaspersky HEUR:Backdoor.MSIL.Androm.gen
Alibaba Clean
NANO-Antivirus Clean
ViRobot Clean
Tencent Msil.Trojan-downloader.Agent_agen.Lorr
Ad-Aware Clean
Sophos Mal/Generic-S
Comodo Clean
F-Secure Clean
DrWeb Clean
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition Artemis!Trojan
FireEye Generic.mg.af4b309cb62dde65
Emsisoft Clean
Ikarus Win32.Outbreak
Jiangmin Clean
Webroot Clean
Avira Clean
MAX Clean
Antiy-AVL Clean
Kingsoft Win32.Troj.Generic_a.a.(kcloud)
Microsoft Trojan:Win32/Woreflint.A!cl
Gridinsoft Clean
Arcabit Clean
SUPERAntiSpyware Clean
GData Clean
Cynet Clean
AhnLab-V3 Clean
Acronis Clean
McAfee Artemis!AF4B309CB62D
TACHYON Clean
VBA32 Clean
Malwarebytes Clean
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Rising Clean
Yandex Clean
SentinelOne Static AI - Malicious PE
eGambit Clean
Fortinet Clean
BitDefenderTheta Gen:NN.ZemsilF.34114.bm0@a8Uqgfg
AVG Win32:DropperX-gen [Drp]
Avast Win32:DropperX-gen [Drp]
MaxSecure Trojan.Malware.300983.susgen
No IRMA results available.