Static | ZeroBOX

PE Compile Time

2072-01-12 05:28:45

PDB Path

C:\Users\B\Desktop\Builder\stub\5834921754\un_priv\FiLoRadio\obj\Release\FiLoRadio.pdb

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x000012bc 0x00001400 5.27178333208
.rsrc 0x00004000 0x00001874 0x00001a00 7.06752442638
.reloc 0x00006000 0x0000000c 0x00000200 0.0815394123432

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x00004100 0x000011df LANG_NEUTRAL SUBLANG_NEUTRAL PNG image data, 196 x 196, 8-bit/color RGBA, non-interlaced
RT_GROUP_ICON 0x000052f0 0x00000014 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_VERSION 0x00005314 0x0000035e LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_MANIFEST 0x00005684 0x000001ea LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with CRLF line terminators

Imports

Library mscoree.dll:
0x402000 _CorExeMain

!This program cannot be run in DOS mode.
`.rsrc
@.reloc
v4.0.30319
#Strings
UINT32
ToUInt32
get_UTF8
<Module>
omsLTL
DownloadData
factorData
string_to_b
mscorlib
GetMethod
Invoke
tocycle
GetType
declare
configure
MethodBase
FromBase
toparse
sparse
Reverse
GuidAttribute
UnverifiableCodeAttribute
NeutralResourcesLanguageAttribute
DebuggableAttribute
ComVisibleAttribute
AssemblyTitleAttribute
AssemblyTrademarkAttribute
TargetFrameworkAttribute
AssemblyFileVersionAttribute
SecurityPermissionAttribute
AssemblyConfigurationAttribute
AssemblyDescriptionAttribute
CompilationRelaxationsAttribute
AssemblyProductAttribute
AssemblyCopyrightAttribute
AssemblyCompanyAttribute
RuntimeCompatibilityAttribute
ToByte
FiLoRadio.exe
Encoding
System.Runtime.Versioning
FromBase64String
ToString
GetString
get_Length
JSonReadViewAll
kernel32.dll
user32.dll
Program
System
SecurityAction
System.Reflection
section
MethodInfo
FiLoRadio
secondary_help
variableRender
helper
delimiter
.cctor
charcas
System.Diagnostics
System.Runtime.InteropServices
System.Runtime.CompilerServices
System.Resources
DebuggingModes
checkforUpdates
System.Security.Permissions
get_Chars
letters
getInts
Concat
Object
System.Net
WebClient
Convert
System.Text
GetConsoleWindow
ShowWindow
nCmdShow
ToCharArray
licensekey
stringify
Assembly
System.Security
System.Security.Permissions.SecurityPermissionAttribute, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089
SkipVerification
WrapNonExceptionThrows
FiLoRadio
FiloRadio Application
FiLoTech
Copyright
2023
$14a51330-e7a0-4e02-9ea0-ed4e0b12f666
12.3.4.0
.NETFramework,Version=v4.7.2
FrameworkDisplayName
.NET Framework 4.7.2
C:\Users\B\Desktop\Builder\stub\5834921754\un_priv\FiLoRadio\obj\Release\FiLoRadio.pdb
_CorExeMain
mscoree.dll
)*!DUK
G#zDR>:E
wRrASP
PH\>yR
>,7bxXt-Z
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<assemblyIdentity version="1.0.0.0" name="MyApplication.app"/>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v2">
<security>
<requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3">
<requestedExecutionLevel level="asInvoker" uiAccess="false"/>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
1:Vae}
VpZD/ta.ihso//:sptth
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
Comments
FiloRadio Application
CompanyName
FiLoTech
FileDescription
FiLoRadio
FileVersion
12.3.4.0
InternalName
FiLoRadio.exe
LegalCopyright
Copyright
2023
LegalTrademarks
OriginalFilename
FiLoRadio.exe
ProductName
FiLoRadio
ProductVersion
12.3.4.0
Assembly Version
12.3.4.0
Antivirus Signature
Bkav Clean
Lionic Clean
tehtris Clean
DrWeb Clean
MicroWorld-eScan Clean
FireEye Clean
CAT-QuickHeal Clean
McAfee Artemis!03C3F979FEFF
Cylance Clean
VIPRE Clean
Sangfor Trojan.Win32.Agent.Viuc
K7AntiVirus Clean
BitDefender Clean
K7GW Clean
Cybereason Clean
BitDefenderTheta Gen:NN.ZemsilCO.36196.am0@aW@b75h
VirIT Trojan.Win32.MSIL_Heur.A
Cyren W32/ABRisk.EQPM-1226
Symantec MSIL.Downloader!gen8
Elastic malicious (moderate confidence)
ESET-NOD32 a variant of MSIL/TrojanDownloader.Agent_AGen.ASN
APEX Malicious
Paloalto generic.ml
ClamAV Clean
Kaspersky HEUR:Trojan-Spy.MSIL.Stealer.gen
Alibaba Clean
NANO-Antivirus Clean
ViRobot Clean
Rising Malware.Obfus/MSIL@AI.84 (RDM.MSIL2:f0dre26Wmu74kxFx4iCjxQ)
Emsisoft Clean
F-Secure Heuristic.HEUR/AGEN.1313615
Baidu Clean
Zillya Clean
TrendMicro TROJ_FRS.VSNTEH23
McAfee-GW-Edition BehavesLike.Win32.Infected.lh
Trapmine Clean
CMC Clean
Sophos Mal/Generic-S
Ikarus Clean
GData Clean
Jiangmin Clean
Avira HEUR/AGEN.1313615
MAX Clean
Antiy-AVL Clean
Gridinsoft Trojan.Win32.Downloader.sa
Xcitium Clean
Arcabit Clean
SUPERAntiSpyware Clean
ZoneAlarm HEUR:Trojan-Spy.MSIL.Stealer.gen
Microsoft Trojan:Win32/Leonem
Cynet Malicious (score: 100)
AhnLab-V3 Clean
Acronis Clean
VBA32 Clean
ALYac Clean
TACHYON Clean
Malwarebytes Malware.AI.2207490625
Panda Trj/Chgt.AD
Zoner Clean
TrendMicro-HouseCall TROJ_FRS.VSNTEH23
Tencent Clean
Yandex Clean
SentinelOne Static AI - Suspicious PE
MaxSecure Trojan.Malware.300983.susgen
Fortinet PossibleThreat
AVG Win32:PWSX-gen [Trj]
Avast Win32:PWSX-gen [Trj]
CrowdStrike win/malicious_confidence_90% (W)
No IRMA results available.