Static | ZeroBOX

PE Compile Time

2023-06-09 08:11:18

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x00001758 0x00001800 5.56956493308
.rsrc 0x00004000 0x00010fcd 0x00011000 7.36210996651

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x00014455 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x00014455 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x00014455 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x00014455 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x00014455 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x00014455 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x00014455 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x00014455 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x00014455 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x00014455 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_GROUP_ICON 0x000148f9 0x00000092 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_VERSION 0x000149c7 0x00000416 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_MANIFEST 0x00014e19 0x000001b4 LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with very long lines, with no line terminators

!This program cannot be run in DOS mode.
`.rsrc
-(&&+>
-'&&+9
&&+0r%
%,(Y+<+%
++$+)+.
-S&&8w
-O&&8r
-(&&+>
-'&&+9
v4.0.30319
#Strings
dxpserver.exe
dxpserver
<Module>
mscorlib
Object
System
System.Windows.Forms
PoweredByAttribute
SmartAssembly.Attributes
Attribute
Func`2
IContainer
System.ComponentModel
.cctor
Dispose
CompilationRelaxationsAttribute
System.Runtime.CompilerServices
RuntimeCompatibilityAttribute
AssemblyTitleAttribute
System.Reflection
AssemblyDescriptionAttribute
AssemblyConfigurationAttribute
AssemblyCompanyAttribute
AssemblyProductAttribute
AssemblyCopyrightAttribute
AssemblyTrademarkAttribute
GuidAttribute
System.Runtime.InteropServices
AssemblyFileVersionAttribute
TargetFrameworkAttribute
System.Runtime.Versioning
ComVisibleAttribute
STAThreadAttribute
.resources
WindowsFormsApp77.Properties.Resources.resources
Assembly
GetTypes
System.Core
Enumerable
System.Linq
IEnumerable`1
System.Collections.Generic
get_FullName
String
op_Equality
IDisposable
Container
System.Drawing
Control
set_Text
ContainerControl
set_AutoScaleMode
AutoScaleMode
set_ClientSize
Encoding
System.Text
get_UTF8
GetString
Convert
FromBase64String
System.Net.Http
HttpClient
GetAsync
Task`1
System.Threading.Tasks
HttpResponseMessage
get_Result
get_Content
HttpContent
ReadAsByteArrayAsync
InvokeMember
BindingFlags
Binder
ResumeLayout
SuspendLayout
set_AutoScaleDimensions
set_Name
Application
Thread
System.Threading
GetDomain
AppDomain
WrapNonExceptionThrows
Microsoft Sync Center
Microsoft Corporation
&Microsoft
Windows
Operating System
Microsoft Corporation. All rights reserved.
$5f8b9a16-75f2-44ec-aabf-a020fe0dd9b5
10.0.19041.1
.NETFramework,Version=v4.6
FrameworkDisplayName
.NET Framework 4.6(
#Powered by SmartAssembly 8.1.2.4975
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
PADPADP
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
PADPADP
:z:zzzzzz7
"66226266
:r#j6'*cc&7
#j2:v66
zszzsjw
jzsjsw
*r2s'vpzx
''&6:s
*'&6#c&
zv:sjw7
kqqqqr
qqqqhhhj
Bghqqqqqqqqqhqhhhfddf
8deggghhqhqhhhgeeddd9 c
K9dddgeggBgeBeddd99 i
 999d9AAdddA999
 98 98 8 

,__S:<
mmU<8B
?/8?kAB8 
 PM}
/:ANAABBBBBBABBBABBBBBNBBBB
a4?BBkBgkgkkkkkklklkkkkkkkB
K=Bggkgkkkllllplnlnnqllkkp
=?gkkhllppprrr
rrrrplql
=?kqqppq
QVkllllkVi}
jIKTTTTTTTKKKx
IJJJJKKJJIIHHp
IIIII5IIIHHyqA2
{~{\+-'
m~~{~v+-
A254554441441111I4n
-15==J=MMMNMMML==w
N3=JMNRU]___UROOP
A>NR_cc
aX.ijiN-
{yyl6
P55ALv5
P,,(+.8S.
>[d<5/555.K~wD
cGDDDM
Y^d`Z-
`WOOOn
*XtWP#U
{pca'F
G5&i~3
|_N "R
:<0x;R
(j?3~#~
(zEt8]
8^:z8\
N"82[=
Y.<GbP
:.s@pM]
?a*qX>
..a[Ogxez
A&GtDP
*/QB=j
_AS! 9
VOhn@
?jG`%E
o-,bgo
89V*,!
l0@.kM"
IDATL,|&
\FiI\k
O~3ZV)
)<64yC
9Y8p0)
s\m%a
PM/Cf=
Q@01uU=
"|Qt11
nPNLxp
w`Es;x
_qK0&@
8S.xPQ~q
|.[|EZFW%
dZFi+
$xcK3V
EZGAEH
x[W'nS
Uu*$HAynu
|(V'se
f\dBI*S*
z/]U3;
BnY0@'
7woC"`
iiFoS3
XFf=V
XJH~WZ
'y;-N+
7i40:1
#r_tlA
wEPO,i
5[ODv}
hn 36<|
'k d.v'
)n!b2},
)l";-s%
7y/*7z1
7y/E7x0
6x/N8y1
6x/H6x.
:{3]0t(
5w-!4w-34w,T3v,f3v,f3v+T2v+32u*!
&k}/y)
*o"b3~.
+n#+.t'
7y/B6x/
6x/36x.
5x.'5w-W4w-f3w,
3v,f2v+Z2u**
<?xml version="1.0" encoding="utf-8" standalone="yes"?><assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0"><assemblyIdentity version="1.0.0.0" name="MyApplication.app" /><trustInfo xmlns="urn:schemas-microsoft-com:asm.v2"><security><requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3"><requestedExecutionLevel level="asInvoker" uiAccess="false" /></requestedPrivileges></security></trustInfo></assembly>
U.#t.+t.3
Jndqqo.Xkgplnelgn
Rejeeu
http://file.xhamsterrr.com/v/panel/uploads/Amdjgsj.dat
Qcziuvfh
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
Comments
Microsoft Sync Center
CompanyName
Microsoft Corporation
FileDescription
Microsoft Sync Center
FileVersion
10.0.19041.1
InternalName
dxpserver.exe
LegalCopyright
Microsoft Corporation. All rights reserved.
LegalTrademarks
OriginalFilename
dxpserver.exe
ProductName
Microsoft
Windows
Operating System
ProductVersion
10.0.19041.1
Assembly Version
10.0.19041.1
Antivirus Signature
Bkav Clean
Lionic Clean
Elastic malicious (high confidence)
MicroWorld-eScan Clean
ClamAV Clean
CMC Clean
CAT-QuickHeal Clean
McAfee Clean
Malwarebytes Clean
Zillya Clean
Sangfor Suspicious.Win32.Save.a
CrowdStrike win/malicious_confidence_100% (D)
BitDefender Clean
K7GW Clean
K7AntiVirus Clean
Baidu Clean
VirIT Trojan.Win64.MSIL_Heur.A
Cyren Clean
Symantec ML.Attribute.HighConfidence
tehtris Generic.Malware
ESET-NOD32 a variant of MSIL/TrojanDownloader.Agent_AGen.AUB
APEX Malicious
Paloalto Clean
Cynet Malicious (score: 100)
Kaspersky HEUR:Trojan-Downloader.MSIL.PsDownload.gen
Alibaba Clean
NANO-Antivirus Clean
ViRobot Clean
Rising Malware.Obfus/MSIL@AI.100 (RDM.MSIL2:yjHU74bKemSo5tw6X5RmKA)
Sophos ML/PE-A
F-Secure Heuristic.HEUR/AGEN.1326390
DrWeb Clean
VIPRE Clean
TrendMicro Clean
McAfee-GW-Edition Clean
Trapmine Clean
FireEye Clean
Emsisoft Clean
Ikarus Clean
GData Clean
Jiangmin Clean
Webroot Clean
Avira HEUR/AGEN.1326390
MAX Clean
Antiy-AVL Clean
Gridinsoft Clean
Xcitium Clean
Arcabit Clean
SUPERAntiSpyware Clean
ZoneAlarm HEUR:Trojan-Downloader.MSIL.PsDownload.gen
Microsoft Program:Win32/Wacapew.C!ml
Google Clean
AhnLab-V3 Clean
Acronis Clean
BitDefenderTheta Clean
ALYac Clean
TACHYON Clean
DeepInstinct MALICIOUS
VBA32 Clean
Cylance Clean
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Tencent Clean
Yandex Clean
SentinelOne Static AI - Suspicious PE
MaxSecure Clean
Fortinet Clean
AVG Win64:MalwareX-gen [Trj]
Cybereason Clean
Avast Win64:MalwareX-gen [Trj]
No IRMA results available.