Static | ZeroBOX

PE Compile Time

2055-10-17 01:03:31

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x000012c4 0x00001400 5.39737244502
.rsrc 0x00004000 0x00004be0 0x00004c00 2.81720580851
.reloc 0x0000a000 0x0000000c 0x00000200 0.0815394123432

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x00008168 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x00008168 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x00008168 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x00008168 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_GROUP_ICON 0x000085e0 0x0000003e LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_VERSION 0x00008630 0x000003b0 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_MANIFEST 0x000089f0 0x000001ea LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with CRLF line terminators

Imports

Library mscoree.dll:
0x402000 _CorExeMain

!This program cannot be run in DOS mode.
`.rsrc
@.reloc
v4.0.30319
#Strings
IEnumerable`1
Task`1
List`1
Func`2
WindowsFormsApp48
<Module>
get_ASCII
System.IO
mscorlib
System.Collections.Generic
GetByteArrayAsync
Thread
Interlocked
AddRange
CompareExchange
Invoke
IDisposable
Combine
GetType
Dispose
predicate
Delegate
STAThreadAttribute
CompilerGeneratedAttribute
GuidAttribute
UnverifiableCodeAttribute
DebuggableAttribute
ComVisibleAttribute
AssemblyTitleAttribute
AssemblyTrademarkAttribute
TargetFrameworkAttribute
ExtensionAttribute
AssemblyFileVersionAttribute
SecurityPermissionAttribute
AssemblyConfigurationAttribute
AssemblyDescriptionAttribute
CompilationRelaxationsAttribute
AssemblyProductAttribute
AssemblyCopyrightAttribute
ParamArrayAttribute
AssemblyCompanyAttribute
RuntimeCompatibilityAttribute
ToByte
FindFileRecursive
Remove
Pamsobix.exe
System.Threading
Encoding
System.Runtime.Versioning
GetString
Substring
get_Length
Bxuylxck
System
AppDomain
GetDomain
SecurityAction
System.Reflection
pattern
FileInfo
DirectoryInfo
System.Net.Http
Gnaqezar
InvokeMember
sender
Binder
EventHandler
System.Diagnostics
System.Runtime.InteropServices
System.Runtime.CompilerServices
DebuggingModes
GetDirectories
GetFiles
BindingFlags
EventArgs
System.Threading.Tasks
System.Security.Permissions
patterns
set_PriorityClass
ProcessPriorityClass
GetCurrentProcess
Object
add_Sfpoujct
remove_Sfpoujct
Qtsmbx_Sfpoujct
get_Result
HttpClient
Convert
System.Text
Qtsmbx
Pamsobix
Vivdwx
ToArray
Assembly
directory
System.Security
System.Security.Permissions.SecurityPermissionAttribute, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089
SkipVerification
WrapNonExceptionThrows
TODO: <File description>
TODO: <Company name>
TODO: <Product name>
Copyright (C) 2017
$99911a2d-e310-46dc-ae25-14df5e666327
1.0.0.1
.NETFramework,Version=v4.6
FrameworkDisplayName
.NET Framework 4.6
_CorExeMain
mscoree.dll
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<assemblyIdentity version="1.0.0.0" name="MyApplication.app"/>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v2">
<security>
<requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3">
<requestedExecutionLevel level="asInvoker" uiAccess="false"/>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
http://argentum.com.br/well-known/acme-challenge/k/h/d/g/Pjogwzrhh.bmp
Hilkvrriretg.Vujytmonuzo
Bizgooocjbtldpytzu
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
Comments
TODO: <File description>
CompanyName
TODO: <Company name>
FileDescription
TODO: <File description>
FileVersion
1.0.0.1
InternalName
Pamsobix.exe
LegalCopyright
Copyright (C) 2017
LegalTrademarks
OriginalFilename
Pamsobix.exe
ProductName
TODO: <Product name>
ProductVersion
1.0.0.1
Assembly Version
1.0.0.1
Antivirus Signature
Bkav W32.AIDetectNet.01
Lionic Trojan.Win32.Agensla.4!c
tehtris Clean
MicroWorld-eScan Trojan.GenericKD.65640264
ClamAV Clean
CMC Clean
CAT-QuickHeal Clean
McAfee Artemis!30B5426EE918
Cylance unsafe
Zillya Clean
Sangfor Infostealer.Msil.AgentTesla.V2a8
K7AntiVirus Trojan-Downloader ( 0059f57b1 )
BitDefender Trojan.GenericKD.65640264
K7GW Trojan-Downloader ( 0059f57b1 )
CrowdStrike win/malicious_confidence_100% (W)
Baidu Clean
VirIT Trojan.Win32.SmokeLdr.DOG
Cyren W32/MSIL_Kryptik.GLW.gen!Eldorado
Symantec MSIL.Downloader!gen7
Elastic malicious (high confidence)
ESET-NOD32 a variant of MSIL/TrojanDownloader.Agent.OVC
APEX Malicious
Paloalto generic.ml
Cynet Malicious (score: 100)
Kaspersky HEUR:Trojan-PSW.MSIL.Agensla.gen
Alibaba Clean
NANO-Antivirus Clean
ViRobot Clean
Rising Stealer.Agensla!8.13266 (CLOUD)
Sophos Mal/Generic-S
F-Secure Clean
DrWeb Clean
VIPRE Clean
TrendMicro Clean
McAfee-GW-Edition Artemis!Trojan
Trapmine Clean
FireEye Trojan.GenericKD.65640264
Emsisoft Trojan.GenericKD.65640264 (B)
Ikarus Clean
GData Trojan.GenericKD.65640264
Jiangmin Clean
Webroot W32.Trojan.MSIL.AGensla
Avira Clean
MAX malware (ai score=86)
Antiy-AVL Clean
Gridinsoft Trojan.Win32.Downloader.sa
Xcitium Clean
Arcabit Trojan.Generic.D3E99862
SUPERAntiSpyware Clean
ZoneAlarm HEUR:Trojan-PSW.MSIL.Agensla.gen
Microsoft Trojan:Win32/Casdet!rfn
Google Detected
AhnLab-V3 Trojan/Win.Generic.C5387268
Acronis Clean
VBA32 Downloader.MSIL.gen.rexp
ALYac Clean
TACHYON Clean
Malwarebytes Clean
Panda Trj/Chgt.AD
Zoner Clean
TrendMicro-HouseCall Clean
Tencent Clean
Yandex Clean
SentinelOne Clean
MaxSecure Clean
Fortinet MSIL/Agent.OVC!tr.dldr
BitDefenderTheta Gen:NN.ZemsilF.36276.bm0@aeue!cl
AVG Win32:PWSX-gen [Trj]
Cybereason malicious.6d8c38
Avast Win32:PWSX-gen [Trj]
No IRMA results available.