Static | ZeroBOX

PE Compile Time

2062-11-14 08:22:58

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x001d8fa8 0x001d9000 3.96328568105
.rsrc 0x001dc000 0x00019778 0x00019800 7.37645645341

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x001f4c50 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x001f4c50 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x001f4c50 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x001f4c50 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x001f4c50 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x001f4c50 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x001f4c50 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x001f4c50 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x001f4c50 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x001f4c50 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x001f4c50 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x001f4c50 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x001f4c50 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_GROUP_ICON 0x001f50c8 0x000000bc LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_VERSION 0x001f5194 0x000003e2 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_MANIFEST 0x001f5588 0x000001ea LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with CRLF line terminators

!This program cannot be run in DOS mode.
`.rsrc
v4.0.30319
#Strings
Func`1
IEnumerable`1
IEnumerator`1
__StaticArrayInitTypeSize=1933312
IDictionary`2
WindowsFormsApp28
get_UTF8
<Module>
<PrivateImplementationDetails>
F41B4C3AF807E2ADFF58F16D5A31A6358F3B1B9E36BB7E2EE21013EEAC1CB1DF
System.IO
GetData
mscorlib
System.Collections.Generic
Notepad
encoded
ReadToEnd
Invoke
Enumerable
IDisposable
RuntimeFieldHandle
ValueType
GetType
System.Core
WebResponse
GetResponse
Dispose
Create
CompilerGeneratedAttribute
GuidAttribute
DebuggableAttribute
ComVisibleAttribute
AssemblyTitleAttribute
AssemblyTrademarkAttribute
TargetFrameworkAttribute
AssemblyFileVersionAttribute
AssemblyConfigurationAttribute
AssemblyDescriptionAttribute
CompilationRelaxationsAttribute
AssemblyProductAttribute
AssemblyCopyrightAttribute
AssemblyCompanyAttribute
RuntimeCompatibilityAttribute
Notepad.exe
Encoding
System.Runtime.Versioning
ToString
GetString
Substring
get_Length
GetResponseStream
GetStream
Program
get_Item
set_Item
System
GAction
TryAction
action
System.Reflection
Exception
System.Linq
InvokeMember
StreamReader
TextReader
Binder
GetBuffer
IEnumerator
GetEnumerator
System.Diagnostics
System.Runtime.InteropServices
System.Runtime.CompilerServices
DebuggingModes
BindingFlags
System.Collections
RuntimeHelpers
Object
System.Net
TResult
ToLowerInvariant
get_Current
WebRequest
request
MoveNext
System.Text
Omwinkkvctxu
InitializeArray
Assembly
WrapNonExceptionThrows
Notepad
Microsoft Corporation
&Microsoft
Windows
Operating System
Microsoft Corporation. All rights reserved.
$ed230a8f-cbbe-48d1-a2ba-13ccd4475b8b
6.3.9600.17930
.NETFramework,Version=v4.6
FrameworkDisplayName
.NET Framework 4.6
4D5A90000300000004000000FFFF0000B800000000000000400000000000000000000000000000000000000000000000000000000000000000000000800000000E1FBA0E00B409CD21B8014CCD21546869732070726F6772616D2063616E6E6F742062652072756E20696E20444F53206D6F64652E0D0D0A2400000000000000504500004C0103005D7A37630000000000000000E0000E210B01060000B80E00000600000000000052D70E000020000000E00E000000400000200000000200000400000000000000040000000000000000200F000002000000000000030040850000100000100000000010000010000000000000100000000000000000000000F8D60E005700000000E00E00340300000000000000000000000000000000000000000F000C00000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000200000080000000000000000000000082000004800000000000000000000002E7465787400000058B70E000020000000B80E0000020000000000000000000000000000200000602E727372630000003403000000E00E000004000000BA0E00000000000000000000000000400000402E72656C6F6300000C00000000000F000002000000BE0E000000000000000000000000004000004200000000000000000000000000000000
DDEA<::?6
GIIEA<;;?332,'
DNEE<<??>22+(&&&'3
SRRQPE@??>2,,('''',+233
SQRQPNNDDD??,((,(,,+33222',6
MNNEDDDDDI,2,,2233232,2,,2C+
@DIIIICCGIC3>3>2?2??2?C3G63G
?IIIIILILL?GC?CC>GGGG>GCC?C,
DIILOOO
CKGGGGGGDCCCCCGGG
LLLLLILKK
LLLLIIIILIC
p5-h-/z1~
~zxjhj
4+++*(
@?=,+/
===111*!
!!!!!!
'141133!/!(!(!""/""
414;;4
/2/22222////2
;;;;4;3423332
;;;;4:
jZZ \ZdZ^nN
~nnn^^TdUhUlWVkt
gQkQml
.(..%%!!!!!%0
3.r6x.3+,+.0+*!
|r8kr33.33m
xx8rrk3+
f_UUURTP
gbXOOLOZ[dbp
GXXXXXXXXXX
)KK1.-%
$KB>;88$
8KH11.%"
H>KKH;;8)$
;K631-."
(PMKH>;8))
)TE@330."
;LTMMK>;8+$
KHFE@330.
8VTMLH>;.(
(WVTMK>;8+
IDATx^
|8?99zEc
sCN $A
mem2KJ
}^=47"
tz80&a%
5eR@PahB
'2+8Ly
UE&c'O
:({?<#k
X&9Lx"
3A%$[w
q27:^u
H~bXGB
J{L6nD
`lX06,?
ieKe|A
,k<.KQ
oon;M=
|*+@F!
0y;:]Z
h;Z|?2
e &!h+
4J} ^t
C>_J*A
V&Xax)
2hb6YX
Jvz:OO
]I#!4!
?#Q@i(2YD
& 4 10O
84c%ez
xywSIpg
wf!>Tg
QV+ODc
>m5l-B
Gmqxg"
Hc^YF3
?,M.3G2
yT"F]g
YvSfyw/
bJYL^T
.WF"hB
6d@u`+
}x5Jbf
m;xDv)
!({.}Q0H!
V.xOx_T
o3noje
!@!$*B
Re.!D:
FZdQ&r
L-|9.
dB!dB!hB
Jx$7}H
%.!$-T
$)IA%:
,(S!Y(Cf
(@!h(d
u@ @p=
YuU8]&ldx
GsS!t"
vfql:>C
|LVz>FE@
9{8d93
APkP<&
B/XoX_
JN}<:5
<:KmJ*0
CG1\U
Ja\-6G
yz\yWlM~
[qA*68
VL `wZd~
y~qpz:
ycn3)io
P[a(,E
J!:+_m
,>d=MT
x8K{?3~4
M6W}6kY
B!U~8Hg
774_kki
,$4ida
4543!! B
yur:QNO[
MML%BBBQ
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<assemblyIdentity version="1.0.0.0" name="MyApplication.app"/>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v2">
<security>
<requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3">
<requestedExecutionLevel level="asInvoker" uiAccess="false"/>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
Ciiqhzhk.Zudmofflcuroojwruakk
Jmcrgntnyzdqrk
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
Comments
Notepad
CompanyName
Microsoft Corporation
FileDescription
Notepad
FileVersion
6.3.9600.17930
InternalName
Notepad.exe
LegalCopyright
Microsoft Corporation. All rights reserved.
LegalTrademarks
OriginalFilename
Notepad.exe
ProductName
Microsoft
Windows
Operating System
ProductVersion
6.3.9600.17930
Assembly Version
6.3.9600.17930
Antivirus Signature
Bkav Clean
Lionic Clean
Elastic malicious (high confidence)
MicroWorld-eScan IL:Trojan.MSILZilla.23291
ClamAV Clean
CMC Clean
CAT-QuickHeal Clean
ALYac IL:Trojan.MSILZilla.23291
Cylance Clean
Zillya Clean
Sangfor Trojan.MSIL.Agent.gen
K7AntiVirus Clean
BitDefender IL:Trojan.MSILZilla.23291
K7GW Clean
Cybereason Clean
Baidu Clean
VirIT Clean
Cyren Clean
tehtris Clean
ESET-NOD32 a variant of MSIL/Injector.WDB
APEX Malicious
Paloalto Clean
Cynet Clean
Kaspersky HEUR:Trojan-Downloader.MSIL.Agent.gen
Alibaba Clean
NANO-Antivirus Clean
ViRobot Clean
Tencent Msil.Trojan-Downloader.Agent.Rsmw
Ad-Aware IL:Trojan.MSILZilla.23291
Sophos Generic ML PUA (PUA)
Comodo Clean
F-Secure Clean
DrWeb Clean
VIPRE IL:Trojan.MSILZilla.23291
TrendMicro Clean
McAfee-GW-Edition Clean
Trapmine Clean
FireEye Generic.mg.3e7dfad125cb539e
Emsisoft IL:Trojan.MSILZilla.23291 (B)
Ikarus Clean
GData IL:Trojan.MSILZilla.23291
Jiangmin Clean
Webroot Clean
Avira Clean
MAX malware (ai score=80)
Antiy-AVL Clean
Kingsoft Clean
Gridinsoft Clean
Arcabit IL:Trojan.MSILZilla.D5AFB
SUPERAntiSpyware Clean
ZoneAlarm Clean
Microsoft Trojan:Win32/Wacatac.B!ml
Google Clean
AhnLab-V3 Clean
Acronis Clean
McAfee Clean
TACHYON Clean
VBA32 Clean
Malwarebytes Malware.AI.4127197477
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Rising Clean
Yandex Clean
SentinelOne Static AI - Suspicious PE
MaxSecure Trojan.Malware.300983.susgen
Fortinet Clean
BitDefenderTheta Clean
AVG Win64:PWSX-gen [Trj]
Avast Win64:PWSX-gen [Trj]
CrowdStrike win/malicious_confidence_100% (W)
No IRMA results available.