Static | ZeroBOX

PE Compile Time

2087-01-26 15:42:45

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x000009f4 0x00000a00 5.26713538104
.rsrc 0x00004000 0x000005cc 0x00000600 4.46638422588
.reloc 0x00006000 0x0000000c 0x00000200 0.0815394123432

Resources

Name Offset Size Language Sub-language File type
RT_VERSION 0x000040a0 0x00000340 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_MANIFEST 0x000043e0 0x000001ea LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with CRLF line terminators

Imports

Library mscoree.dll:
0x402000 _CorExeMain

!This program cannot be run in DOS mode.
`.rsrc
@.reloc
v4.0.30319
#Strings
Build2
<Module>
System.IO
mscorlib
Thread
get_IsAttached
DownloadFile
Console
set_FileName
ReadLine
ValueType
SecurityProtocolType
UnverifiableCodeAttribute
DebuggableAttribute
TargetFrameworkAttribute
CompilationRelaxationsAttribute
RuntimeCompatibilityAttribute
Build2.exe
Config
System.Threading
System.Runtime.Versioning
String
Mdsdddddddddddddfsh
GetTempPath
user32.dll
set_SecurityProtocol
Program
System
Application
System.Security.Authentication
get_StartInfo
ProcessStartInfo
Tfgfgfg_mp
ServicePointManager
Debugger
.cctor
System.Diagnostics
System.Runtime.CompilerServices
DebuggingModes
EnableVisualStyles
SslProtocols
System.Windows.Forms
GetCursorPos
SetCursorPos
Process
Concat
Object
System.Net
SetCompatibleTextRenderingDefault
SystemDefault
WebClient
lpPoint
Hdffffdddddddddsaiy
System.Security
System.Security.Permissions.SecurityPermissionAttribute, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089
SkipVerification
WrapNonExceptionThrows
.NETFramework,Version=v4.8
FrameworkDisplayName
.NET Framework 4.8
_CorExeMain
mscoree.dll
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<assemblyIdentity version="1.0.0.0" name="MyApplication.app"/>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v2">
<security>
<requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3">
<requestedExecutionLevel level="asInvoker" uiAccess="false"/>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>PAPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADD
spdlvrt.exe
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
FileDescription
Notepad++
FileVersion
8.5.2.0
InternalName
notepad++.exe
LegalCopyright
Copyleft 1998-2022 by Don HO
OriginalFilename
notepad++.exe
ProductVersion
8.5.2.0
Assembly Version
8.5.2.0
ProductName
Notepad++
CompanyName
Don HO don.h@free.fr
LegalTrademarks
Antivirus Signature
Bkav Clean
Lionic Trojan.Win32.Reline.4!c
tehtris Clean
MicroWorld-eScan Clean
ClamAV Clean
FireEye Generic.mg.2746fd51855e750a
CAT-QuickHeal Clean
McAfee Artemis!2746FD51855E
Malwarebytes Clean
VIPRE Clean
Sangfor Clean
K7AntiVirus Clean
BitDefender Clean
K7GW Clean
Cybereason malicious.d415b3
Arcabit Clean
Baidu Clean
Cyren Clean
Elastic malicious (high confidence)
ESET-NOD32 Clean
APEX Malicious
Paloalto Clean
Cynet Malicious (score: 100)
Kaspersky HEUR:Trojan-PSW.MSIL.Reline.gen
Alibaba Clean
NANO-Antivirus Clean
ViRobot Clean
Rising Stealer.Reline!8.132F4 (CLOUD)
Sophos Clean
F-Secure Clean
DrWeb Clean
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition BehavesLike.Win32.Infected.lz
Trapmine Clean
CMC Clean
Emsisoft Clean
SentinelOne Static AI - Suspicious PE
Jiangmin Clean
Webroot Clean
Avira Clean
MAX Clean
Antiy-AVL Clean
Gridinsoft Clean
Xcitium Clean
Microsoft Program:Win32/Wacapew.C!ml
SUPERAntiSpyware Clean
ZoneAlarm HEUR:Trojan-PSW.MSIL.Reline.gen
GData Clean
Google Clean
AhnLab-V3 Clean
Acronis Clean
BitDefenderTheta Gen:NN.ZemsilF.36196.bm2@a4MZ0od
ALYac Clean
TACHYON Clean
DeepInstinct MALICIOUS
VBA32 Clean
Cylance Clean
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Tencent Clean
Yandex Clean
Ikarus Clean
MaxSecure Clean
Fortinet Clean
AVG FileRepMalware [Misc]
Avast FileRepMalware [Misc]
CrowdStrike win/malicious_confidence_100% (D)
No IRMA results available.