Static | ZeroBOX

PE Compile Time

2022-11-29 06:48:18

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x00000fbc 0x00001000 5.44284041684
.rsrc 0x00004000 0x0002aa00 0x0002aa00 5.93074816591

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x0002d650 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x0002d650 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x0002d650 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x0002d650 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x0002d650 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x0002d650 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x0002d650 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x0002d650 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x0002d650 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x0002d650 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x0002d650 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_GROUP_ICON 0x0002dab8 0x000000a0 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_VERSION 0x00004310 0x000003ec LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_MANIFEST 0x0002db58 0x00000d48 LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with CRLF line terminators

!This program cannot be run in DOS mode.
`.rsrc
v4.0.30319
#Strings
newversion5
<Module>
System.IO
mscorlib
Thread
set_IsBackground
CompressionMode
IDisposable
set_WindowStyle
ProcessWindowStyle
set_FileName
get_UserName
GetType
WebResponse
GetResponse
Dispose
Create
SetApartmentState
CompilerGeneratedAttribute
GuidAttribute
UnverifiableCodeAttribute
ComVisibleAttribute
AssemblyTitleAttribute
AssemblyTrademarkAttribute
TargetFrameworkAttribute
AssemblyFileVersionAttribute
SecurityPermissionAttribute
AssemblyConfigurationAttribute
AssemblyDescriptionAttribute
CompilationRelaxationsAttribute
AssemblyProductAttribute
AssemblyCopyrightAttribute
AssemblyCompanyAttribute
RuntimeCompatibilityAttribute
newversion5.exe
set_Tag
System.Threading
System.Runtime.Versioning
get_Length
Control
BufferedStream
GetResponseStream
GZipStream
MemoryStream
System
System.IO.Compression
System.Reflection
CopyTo
ProcessStartInfo
InvokeMember
Binder
.cctor
System.Diagnostics
System.Runtime.InteropServices
System.Runtime.CompilerServices
BindingFlags
System.Windows.Forms
System.Security.Permissions
Process
set_Arguments
Object
System.Net
WaitForExit
Environment
ThreadStart
WebRequest
get_Text
set_Text
set_CreateNoWindow
TextBox
ToArray
Assembly
System.Security
Martin Prikryl
.NETFramework,Version=v4.6
FrameworkDisplayName
.NET Framework 4.61
,WinSCP: SFTP, FTP, WebDAV, S3 and SCP client
WrapNonExceptionThrows
(c) 2000-2022 Martin Prikryl
WinSCP
$3c6fef73-6ec9-4ad4-a146-f658f86647c8
5.21.5.12858
System.Security.Permissions.SecurityPermissionAttribute, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089
SkipVerification
4fSc~n
;w;K/U
K:%$u"
CCCrvv6{
O;6Wm?
C__z{{
`")YJ*
IDAT-R8
K)kDD%
ALMMee
lO7&?C
*NZrD@
|F`[& `
(tt?}hh
$SW Ad:
)gp`?
W@jD#%c
hYz{E
?3!1;)
]|Re$i
g\tbu$
'05~0|
$-#0='
~r{831
k.qF/K
Pz_]sZ
{`RJFDL
8%_)f)
u+G?mi'/"
t)WZ^}
R[c,f
@h5k*
efj"[N
*{qmA3u
2-l} %
PYaj[?^4iF
ud^c{>
=}TwUe
dFfdTDfVO
mb{)\_
v56.#!
K///BP/
-x+l!d
4!=O(S
'DNC&H0
~CI !b
4e&DWTd
XD0f+o
/WYyuu
'n{b4I
my]`Ui>
3IDATDw
4rref;
bkqdzy
$"JzZA
5{L=]-
@OV+.?
J!CI,9]
T?M{QBKxODIuMFHtLFGrKGFpIIEnHJDmHKDmHKClGLCkFMBiEMAhDN@gDO@fCP?eBQ>dAR>cAS>cAS<a?T<`?U<`?U;_>V;^=W:]=X:]=X0J
"&&&1###9!!!@
UUL]Li
>>>x"""[
'''b!!!\
D111e___
||QyyyJ{{{H|||F~~~D
}wwLpppBppp@sss<uuu9rrr5rrr1sss.ppp*ggg']]]-ZZZ4WWW3ZZZ4ZZZ4ZZZ4ZZZ4WWW3WWW3SSS2PPP1III/AAA.<<<-888,888,888,
yrrDiii:hhh6jjj2hhh,ggg'ddd$ZZZFFF
skk;^^^1bbb,]]]']]]!TTT
pff1QQQ&OOO MMM
ic\&<<<
___F~~~7
ccc~dddR
mkj?jjj5lll-ddd$HHH
[ZX,RRR>>>
JJJbbb
<"""&&&&
e~+&!6
ZrrrCrrrNmmmlaaavZZZzYYYyYYYyVVVzTTTyTTTwRRRvQQQtOOOkMMMS333(
J]]])XXX
@@@$YYYDLLLTGGGZEEE]GGG]GGG]GGG]III^III^III^KKK_KKK_KKK_MMM_MMM_MMM_PPP`PPP`PPP`OOOa
0111Xjjj
{MzzzG
}rl9RRR+++
Fuuu^jjjjhhhnhhhnjjjolllolllommmpmmmpoooqppprppprrrrrssssssssuuutwwwv
ddd1mmm&eee2kkk@iiiAeee?XXX=UUU<
NfPH8
---"uuu
7nnn
Xlll@bbbFSSSDOOODOOODLLLCIIIBFFF>BBB2!!!
`U<z6)
CCC"777A111I111I444I444I777J777J777J999LRlTa>
lX0jRF+
<?xml version="1.0" encoding="utf-8"?>
<assembly manifestVersion="1.0" xmlns="urn:schemas-microsoft-com:asm.v1">
<assemblyIdentity version="1.0.0.0" name="MyApplication.app"/>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v2">
<security>
<requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3">
<!-- UAC Manifest Options
If you want to change the Windows User Account Control level replace the
requestedExecutionLevel node with one of the following.
<requestedExecutionLevel level="asInvoker" uiAccess="false" />
<requestedExecutionLevel level="requireAdministrator" uiAccess="false" />
<requestedExecutionLevel level="highestAvailable" uiAccess="false" />
Specifying requestedExecutionLevel element will disable file and registry virtualization.
Remove this element if your application requires this virtualization for backwards
compatibility.
-->
<requestedExecutionLevel level="asInvoker" uiAccess="false" />
</requestedPrivileges>
</security>
</trustInfo>
<compatibility xmlns="urn:schemas-microsoft-com:compatibility.v1">
<application>
<!-- A list of the Windows versions that this application has been tested on
and is designed to work with. Uncomment the appropriate elements
and Windows will automatically select the most compatible environment. -->
<!-- Windows Vista -->
<!--<supportedOS Id="{e2011457-1546-43c5-a5fe-008deee3d3f0}" />-->
<!-- Windows 7 -->
<!--<supportedOS Id="{35138b9a-5d96-4fbd-8e2d-a2440225f93a}" />-->
<!-- Windows 8 -->
<!--<supportedOS Id="{4a2f28e3-53b9-4441-ba9c-d69d4a4a6e38}" />-->
<!-- Windows 8.1 -->
<!--<supportedOS Id="{1f676c76-80e1-4239-95bb-83d0f6d0da78}" />-->
<!-- Windows 10 -->
<!--<supportedOS Id="{8e0f7a12-bfb3-4fe8-b9a5-48fd50a15a9a}" />-->
</application>
</compatibility>
<!-- Indicates that the application is DPI-aware and will not be automatically scaled by Windows at higher
DPIs. Windows Presentation Foundation (WPF) applications are automatically DPI-aware and do not need
to opt in. Windows Forms applications targeting .NET Framework 4.6 that opt into this setting, should
also set the 'EnableWindowsFormsHighDpiAutoResizing' setting to 'true' in their app.config.
Makes the application long-path aware. See https://docs.microsoft.com/windows/win32/fileio/maximum-file-path-limitation -->
<!--
<application xmlns="urn:schemas-microsoft-com:asm.v3">
<windowsSettings>
<dpiAware xmlns="http://schemas.microsoft.com/SMI/2005/WindowsSettings">true</dpiAware>
<longPathAware xmlns="http://schemas.microsoft.com/SMI/2016/WindowsSettings">true</longPathAware>
</windowsSettings>
</application>
<!-- Enable themes for Windows common controls and dialogs (Windows XP and later) -->
<!--
<dependency>
<dependentAssembly>
<assemblyIdentity
type="win32"
name="Microsoft.Windows.Common-Controls"
version="6.0.0.0"
processorArchitecture="*"
publicKeyToken="6595b64144ccf1df"
language="*"
/>
</dependentAssembly>
</dependency>
</assembly>
powershell
[System.Security.Principal.WindowsIdentity]::GetCurrent().Name
Lnsznczxtjcuamicss.Haechewabboewjyyobatqsqn
Zkrmrwysyvduojjms
http://85.209.134.86/Qyoapb.bmp
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
Comments
WinSCP: SFTP, FTP, WebDAV, S3 and SCP client
CompanyName
Martin Prikryl
FileDescription
WinSCP: SFTP, FTP, WebDAV, S3 and SCP client
FileVersion
5.21.5.12858
InternalName
newversion5.exe
LegalCopyright
(c) 2000-2022 Martin Prikryl
OriginalFilename
newversion5.exe
ProductName
WinSCP
ProductVersion
5.21.5.12858
Assembly Version
5.21.5.12858
Antivirus Signature
Bkav Clean
Lionic Clean
Elastic malicious (high confidence)
MicroWorld-eScan Trojan.GenericKD.63944180
FireEye Trojan.GenericKD.63944180
CAT-QuickHeal Clean
ALYac Trojan.GenericKD.63944180
Cylance Clean
Zillya Clean
Sangfor Clean
K7AntiVirus Clean
BitDefender Trojan.GenericKD.63944180
K7GW Clean
Cybereason Clean
BitDefenderTheta Clean
VirIT Clean
Cyren Clean
Symantec ML.Attribute.HighConfidence
tehtris Clean
ESET-NOD32 a variant of MSIL/TrojanDownloader.Agent.OEI
Baidu Clean
APEX Malicious
Paloalto Clean
ClamAV Clean
Kaspersky HEUR:Trojan.MSIL.Injuke.gen
Alibaba Clean
NANO-Antivirus Clean
Cynet Malicious (score: 99)
ViRobot Clean
Rising Clean
Ad-Aware Trojan.GenericKD.63944180
TACHYON Clean
Emsisoft Trojan.GenericKD.63944180 (B)
Comodo Clean
F-Secure Clean
DrWeb Clean
VIPRE Trojan.GenericKDS.61005154
TrendMicro Clean
McAfee-GW-Edition Artemis
Trapmine Clean
CMC Clean
Sophos Clean
Ikarus Clean
GData Trojan.GenericKD.63944180
Jiangmin Clean
Webroot W32.Malware.Gen
Avira TR/Dldr.Agent.akzyl
Antiy-AVL Clean
Kingsoft Clean
Gridinsoft Clean
Arcabit Trojan.Generic.D3CFB5F4
SUPERAntiSpyware Clean
ZoneAlarm Clean
Microsoft Trojan:Script/Phonzy.C!ml
Google Clean
AhnLab-V3 Clean
Acronis Clean
McAfee Artemis!355CE92CE35C
MAX malware (ai score=85)
VBA32 Clean
Malwarebytes Trojan.Downloader
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Tencent Msil.Trojan-Downloader.Ader.Cflw
Yandex Clean
SentinelOne Clean
MaxSecure Trojan.Malware.300983.susgen
Fortinet MSIL/Agent.OEI!tr.dldr
AVG Win64:DropperX-gen [Drp]
Avast Win64:DropperX-gen [Drp]
CrowdStrike win/malicious_confidence_60% (D)
No IRMA results available.