Static | ZeroBOX

PE Compile Time

2022-10-12 00:44:47

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x001d3174 0x001d3200 3.71965954601
.rsrc 0x001d6000 0x00009400 0x00009400 6.71731332325
.reloc 0x001e0000 0x0000000c 0x00000200 0.101910425663

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x001da420 0x0000485d LANG_NEUTRAL SUBLANG_NEUTRAL PNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced
RT_ICON 0x001da420 0x0000485d LANG_NEUTRAL SUBLANG_NEUTRAL PNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced
RT_ICON 0x001da420 0x0000485d LANG_NEUTRAL SUBLANG_NEUTRAL PNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced
RT_ICON 0x001da420 0x0000485d LANG_NEUTRAL SUBLANG_NEUTRAL PNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced
RT_ICON 0x001da420 0x0000485d LANG_NEUTRAL SUBLANG_NEUTRAL PNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced
RT_GROUP_ICON 0x001dec90 0x0000004c LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_VERSION 0x001decec 0x0000038a LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_MANIFEST 0x001df088 0x000001ea LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with CRLF line terminators

Imports

Library mscoree.dll:
0x402000 _CorExeMain

!This program cannot be run in DOS mode.
`.rsrc
@.reloc
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
PADPADP
4D5A90000300000004000000FFFF0000B800000000000000400000000000000000000000000000000000000000000000000000000000000000000000800000000E1FBA0E00B409CD21B8014CCD21546869732070726F6772616D2063616E6E6F742062652072756E20696E20444F53206D6F64652E0D0D0A2400000000000000504500004C010300608F45630000000000000000E0000E210B01300000860E0000060000000000000EA50E000020000000C00E000000400000200000000200000400000000000000040000000000000000000F000002000000000000030040850000100000100000000010000010000000000000100000000000000000000000C0A40E004B00000000C00E00340300000000000000000000000000000000000000E00E000C00000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000200000080000000000000000000000082000004800000000000000000000002E7465787400000014850E000020000000860E0000020000000000000000000000000000200000602E727372630000003403000000C00E000004000000880E00000000000000000000000000400000C02E72656C6F6300000C00000000E00E0000020000008C0E000000000000000000000000004000004200000000000000000000000000000000
v4.0.30319
#Strings
get_UTF8
<Module>
System.IO
mscorlib
OpenRead
Thread
add_Load
add_CheckedChanged
set_Checked
ReadToEnd
set_AutoScaleMode
set_BackgroundImage
IDisposable
RuntimeFieldHandle
set_Name
ValueType
GetType
ButtonBase
WebResponse
GetResponse
Dispose
Create
Navigate
STAThreadAttribute
CompilerGeneratedAttribute
GuidAttribute
DebuggableAttribute
ComVisibleAttribute
AssemblyTitleAttribute
AssemblyTrademarkAttribute
TargetFrameworkAttribute
AssemblyFileVersionAttribute
AssemblyConfigurationAttribute
AssemblyDescriptionAttribute
CompilationRelaxationsAttribute
AssemblyProductAttribute
AssemblyCopyrightAttribute
AssemblyCompanyAttribute
RuntimeCompatibilityAttribute
ToByte
add_DragLeave
library.exe
set_Size
set_AutoSize
set_ClientSize
System.Threading
Encoding
System.Runtime.Versioning
GetString
Substring
disposing
System.Drawing
get_Length
System.ComponentModel
ContainerControl
GetResponseStream
FromStream
System
AppDomain
GetDomain
Application
set_Location
System.Reflection
ControlCollection
InvokeMember
StreamReader
TextReader
Binder
EventHandler
IContainer
WebBrowser
set_UseVisualStyleBackColor
System.Diagnostics
System.Runtime.InteropServices
System.Runtime.CompilerServices
WindowsFormsApp76.Forms.Form1.resources
DebuggingModes
EnableVisualStyles
BindingFlags
EventArgs
get_Controls
WindowsFormsApp76.Forms
System.Windows.Forms
set_AutoScaleDimensions
RuntimeHelpers
Object
System.Net
SetCompatibleTextRenderingDefault
WebClient
Convert
WebRequest
SuspendLayout
ResumeLayout
PerformLayout
System.Text
get_Text
set_Text
set_TabIndex
CheckBox
InitializeArray
Assembly
library
WrapNonExceptionThrows
FileZilla FTP Client
FileZilla Project
FileZilla
Copyright (C) 2006-2021
$c853a19f-6573-44c8-b871-51d982c8bec3
3.55.1.0
.NETFramework,Version=v4.6
FrameworkDisplayName
.NET Framework 4.6
_CorExeMain
mscoree.dll
((((((
GF7A9<<
%1?<!%
%%%DD<
@@@4<-,,,$
<<<<<<<<<3
<&)))))))E>>
H:::::
<<<<<<'
;;;;;;
!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!.!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!
J.............................
dJJJJJJJJJJXW[4
BM*@2q
JJJJJJJ
dddddddddd
eeeeeeeeeee
dddddd
]eeeeeeeeeeeT
99vzeee`fu
9999999QwQQQseee6QQQkHee>PQQQQ5_QQQQQQQw
wwwceee
eeeGwwwwwwwwwwww
Y`eeeb
eeln11111
111111111
eeeELLLLLLI\eeeh~LLLLLLL
pppp$eee
ppppppp
'eee^ ppppppp
""""""""-eeeeA|
=Z====
Reeeeeeeeeeeeeeeeey======Z}ZZZZZ
eeeeeeeeeeeeeeeeeiZZZZZZ
}}}}}7eeej\\\\\\\\\\\\\rK}}}}
U:::::/eee):::::::::::::::::::
U{UUUUU
?UUUUUUUUUUUUUUUUUUU{
{{{{{{#eee<
{{{{{{{{{{
teeeeeeeeeeee+
3a333333Deeeeeeeeeeeem3333333333
aaaaaa;eeeeeeeeeeeeSaaaaaaaaa
Fxxxxxxxxxxx%
JJJJJJJJJJJJJJJJJ
?E[-Hk
JJJJJJJJJJJ
dddddddddddddddd
Idddddddd
'{
5555555
*55555q_
65555555=/
q555555555
NNNNNNW
NNNNNN
ANNNNNNNNNNNNNNNNNN
!!!!!!!!|
!!!!!!!!!!
>!!!!!!!!!!!!!88888888]
e8888888888
888888888888PPPllllll
lllllllllll
lllllllllll
""<<<<<<<U
,<<<<<<<
QQQQQQQQQQ7
QQQQQQQQpppppppppp
apppppppp
%%%%%%%%%Z
%%%%%%%%%%%%%%%%%%%%%%%%%%%%
@@@@@@@@@O
@@@@@@@@@@@@@@@@@@@@@@@@@@@@
TTTTTTTTTT13
TTTTTTTTTTTTTT
))))))))))
;))))))))))))
CCCCCCCCCCC
ttttttttttttttttttt
CCCCCCCCCCCC
YYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYY
YYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYY
YYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYY
H$IDATx
0g #WV
1Xl}:Y
W"PX<N
$ (Q0+
$A-[:e
e,;NiY}
_:xpZ_
8dU2zg
ST)&(j(e
O]3W^X
ygC9R$P
Ct7ZO&+
v^pM1_
-O0"=\
M(mL>a:L
l;q_`z
Wx~|@l
pV(8>N
yK4bj\
:vti,)
GOZyxH
4-"jnlt
.v]QUe
.5KB|>
gn<fXFb
a]Ldix
`oN'VB
[7zt\+
1!U ?$
-Z${' NV
QP`h g
2)q#\R
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<assemblyIdentity version="1.0.0.0" name="MyApplication.app"/>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v2">
<security>
<requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3">
<requestedExecutionLevel level="asInvoker" uiAccess="false"/>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
GlobalSign Root CA - R31
GlobalSign1
GlobalSign0
160615000000Z
240615000000Z0Z1
GlobalSign nv-sa100.
'GlobalSign CodeSigning CA - SHA256 - G30
<paX7
"http://ocsp2.globalsign.com/rootr306
%http://crl.globalsign.com/root-r3.crl0c
&https://www.globalsign.com/repository/0
JEe-MI
GlobalSign nv-sa100.
'GlobalSign CodeSigning CA - SHA256 - G30
200825134207Z
230826134207Z0]1
Berlin1
Berlin1
win.rar GmbH1
win.rar GmbH0
Z>Jjv%
<http://secure.globalsign.com/cacert/gscodesignsha2g3ocsp.crt08
,http://ocsp2.globalsign.com/gscodesignsha2g30V
&https://www.globalsign.com/repository/0
.http://crl.globalsign.com/gscodesignsha2g3.crl0
%%2~,1Dog%y
DigiCert Inc1
www.digicert.com110/
(DigiCert SHA2 Assured ID Timestamping CA0
210101000000Z
310106000000Z0H1
DigiCert, Inc.1 0
DigiCert Timestamp 20210
http://www.digicert.com/CPS0
,http://crl3.digicert.com/sha2-assured-ts.crl02
,http://crl4.digicert.com/sha2-assured-ts.crl0
http://ocsp.digicert.com0O
Chttp://cacerts.digicert.com/DigiCertSHA2AssuredIDTimestampingCA.crt0
QJxy6z'
dwc_#Ri
DigiCert Inc1
www.digicert.com1$0"
DigiCert Assured ID Root CA0
160107120000Z
310107120000Z0r1
DigiCert Inc1
www.digicert.com110/
(DigiCert SHA2 Assured ID Timestamping CA0
fnVa')
http://ocsp.digicert.com0C
7http://cacerts.digicert.com/DigiCertAssuredIDRootCA.crt0
4http://crl4.digicert.com/DigiCertAssuredIDRootCA.crl0:
4http://crl3.digicert.com/DigiCertAssuredIDRootCA.crl0P
https://www.digicert.com/CPS0
8aMbF$
V3"/"6
GlobalSign nv-sa100.
'GlobalSign CodeSigning CA - SHA256 - G3
Sf(h<Y
DigiCert Inc1
www.digicert.com110/
(DigiCert SHA2 Assured ID Timestamping CA
220303143014Z0/
GlobalSign Root CA - R31
GlobalSign1
GlobalSign0
160615000000Z
240615000000Z0Z1
GlobalSign nv-sa100.
'GlobalSign CodeSigning CA - SHA256 - G30
<paX7
"http://ocsp2.globalsign.com/rootr306
%http://crl.globalsign.com/root-r3.crl0c
&https://www.globalsign.com/repository/0
JEe-MI
GlobalSign nv-sa100.
'GlobalSign CodeSigning CA - SHA256 - G30
200825134207Z
230826134207Z0]1
Berlin1
Berlin1
win.rar GmbH1
win.rar GmbH0
Z>Jjv%
<http://secure.globalsign.com/cacert/gscodesignsha2g3ocsp.crt08
,http://ocsp2.globalsign.com/gscodesignsha2g30V
&https://www.globalsign.com/repository/0
.http://crl.globalsign.com/gscodesignsha2g3.crl0
%%2~,1Dog%y
GlobalSign nv-sa100.
'GlobalSign CodeSigning CA - SHA256 - G3
~S\/Zl_
Zi&Di+
20220303143016Z0
GlobalSign nv-sa1)0'
Globalsign TSA for Advanced - G4
GlobalSign nv-sa110/
(GlobalSign Timestamping CA - SHA384 - G40
210527095523Z
320628095522Z0S1
GlobalSign nv-sa1)0'
Globalsign TSA for Advanced - G40
&https://www.globalsign.com/repository/0
-http://ocsp.globalsign.com/ca/gstsacasha384g40C
7http://secure.globalsign.com/cacert/gstsacasha384g4.crt0
0http://crl.globalsign.com/ca/gstsacasha384g4.crl0
#m-3Br
Of,.T*X
fsaE6J
)rwiux
.@]|Gt0
GlobalSign Root CA - R61
GlobalSign1
GlobalSign0
180620000000Z
341210000000Z0[1
GlobalSign nv-sa110/
(GlobalSign Timestamping CA - SHA384 - G40
a:c|9#ymt
"http://ocsp2.globalsign.com/rootr606
%http://crl.globalsign.com/root-r6.crl0G
&https://www.globalsign.com/repository/0
$KtZ}r
GlobalSign Root CA - R31
GlobalSign1
GlobalSign0
190220000000Z
290318100000Z0L1 0
GlobalSign Root CA - R61
GlobalSign1
GlobalSign0
PmBf/M
'YLv9[
"http://ocsp2.globalsign.com/rootr306
%http://crl.globalsign.com/root-r3.crl0G
&https://www.globalsign.com/repository/0
GlobalSign Root CA - R31
GlobalSign1
GlobalSign0
090318100000Z
290318100000Z0L1 0
GlobalSign Root CA - R31
GlobalSign1
GlobalSign0
,3:;%
GlobalSign nv-sa110/
(GlobalSign Timestamping CA - SHA384 - G4
GlobalSign nv-sa110/
(GlobalSign Timestamping CA - SHA384 - G4
http://images.pexels.com/photos/2246476/pexels-photo-2246476.jpeg
Qgyqiwqv.Zloqccuargebbmns
checkBox1
Gpwmyshyumdqw
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
Comments
FileZilla FTP Client
CompanyName
FileZilla Project
FileDescription
FileZilla FTP Client
FileVersion
3.55.1.0
InternalName
library.exe
LegalCopyright
Copyright (C) 2006-2021
LegalTrademarks
OriginalFilename
library.exe
ProductName
FileZilla
ProductVersion
3.55.1.0
Assembly Version
3.55.1.0
Antivirus Signature
Bkav Clean
Lionic Clean
tehtris Clean
DrWeb Clean
MicroWorld-eScan Gen:Variant.Tedy.220617
FireEye Generic.mg.92f3f7757c5dd136
CAT-QuickHeal Clean
McAfee Clean
Cylance Clean
VIPRE Gen:Variant.Tedy.220617
Sangfor Clean
K7AntiVirus Clean
BitDefender Gen:Variant.Tedy.220617
K7GW Clean
CrowdStrike win/malicious_confidence_70% (D)
BitDefenderTheta Gen:NN.ZemsilF.34698.4n2@aS@qkSl
VirIT Clean
Cyren Clean
Symantec ML.Attribute.HighConfidence
Elastic malicious (high confidence)
ESET-NOD32 a variant of MSIL/TrojanDownloader.Agent.NRN
Zoner Clean
APEX Malicious
Paloalto Clean
ClamAV Clean
Kaspersky Clean
Alibaba Clean
NANO-Antivirus Clean
ViRobot Clean
Rising Clean
Ad-Aware Gen:Variant.Tedy.220617
TACHYON Clean
Sophos ML/PE-A
Comodo Clean
F-Secure Heuristic.HEUR/AGEN.1202166
Baidu Clean
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition Clean
Trapmine Clean
CMC Clean
Emsisoft Gen:Variant.Tedy.220617 (B)
SentinelOne Static AI - Malicious PE
GData Gen:Variant.Tedy.220617
Jiangmin Clean
Webroot Clean
Google Detected
Avira HEUR/AGEN.1202166
Antiy-AVL Clean
Kingsoft Clean
Gridinsoft Clean
Arcabit Trojan.Tedy.D35DC9
SUPERAntiSpyware Clean
ZoneAlarm Clean
Microsoft Trojan:Win32/MarsStealer.MB!MTB
Cynet Malicious (score: 99)
AhnLab-V3 Clean
Acronis Clean
VBA32 Downloader.MSIL.gen.rexp
ALYac Clean
MAX malware (ai score=85)
Malwarebytes Malware.AI.2913672578
Panda Clean
TrendMicro-HouseCall Clean
Tencent Clean
Yandex Clean
Ikarus Trojan.Agent
MaxSecure Trojan.Malware.300983.susgen
Fortinet MSIL/Agent.NRN!tr.dldr
AVG Clean
Cybereason malicious.1bc95f
Avast Clean
No IRMA results available.