Static | ZeroBOX

PE Compile Time

2023-06-29 06:22:17

PDB Path

C:\_RU\-ci_texAdEngine1-master\obj\x86\Debug\ci_texAdEngine1.pdb

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x000023d2 0x00002400 5.90526524123
.rsrc 0x00006000 0x000009ac 0x00000a00 4.61650549325

Resources

Name Offset Size Language Sub-language File type
RT_GROUP_ICON 0x00006100 0x00000006 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_VERSION 0x00006464 0x0000035c LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_VERSION 0x00006464 0x0000035c LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_MANIFEST 0x000067c0 0x000001ea LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with CRLF line terminators

!This program cannot be run in DOS mode.
`.rsrc
v4.0.30319
#Strings
<>p__0
<importantFlag>5__1
<client>5__1
<>p__1
<>u__1
IEnumerable`1
CallSite`1
Task`1
AsyncTaskMethodBuilder`1
TaskAwaiter`1
List`1
<Initialize>d__12
kernel32
<str01>5__2
<decryptedUrl>5__2
<>p__2
<LoadAssemblyFromEncryptedUrl>d__13
<str02>5__3
<response>5__3
<>p__3
Func`3
<pattern>5__4
<super>5__4
<handledResponse>5__5
<>s__5
Func`5
<virtualProtect>5__6
<>s__6
<asb>5__7
get_UTF8
<oldProtect>5__8
<>o__8
<ex>5__9
<Module>
System.Web
mscorlib
System.Collections.Generic
AwaitUnsafeOnCompleted
get_IsCompleted
method
set_Mode
PaddingMode
CipherMode
HtmlDecode
EndInvoke
BeginInvoke
IDisposable
RuntimeTypeHandle
GetTypeFromHandle
IAsyncStateMachine
SetStateMachine
stateMachine
System.Core
Capture
MethodBase
Dispose
Create
MulticastDelegate
<>1__state
CallSite
DynamicAttribute
EmbeddedAttribute
CompilerGeneratedAttribute
AttributeUsageAttribute
DebuggableAttribute
AsyncStateMachineAttribute
DebuggerStepThroughAttribute
TargetFrameworkAttribute
DebuggerHiddenAttribute
RefSafetyRulesAttribute
CompilationRelaxationsAttribute
RuntimeCompatibilityAttribute
get_Value
dwSize
set_Padding
Encoding
System.Runtime.Versioning
FromBase64String
DownloadString
GetString
AsyncCallback
callback
TransformFinalBlock
get_Task
Marshal
encryptedUrl
get_Item
System
SymmetricAlgorithm
ICryptoTransform
AppDomain
get_CurrentDomain
MessageBoxIcon
Version
System.Reflection
GroupCollection
SetException
MethodInfo
CSharpArgumentInfo
Microsoft.CSharp
InvokeMember
<>t__builder
Microsoft.CSharp.RuntimeBinder
CallSiteBinder
GetAwaiter
GetDelegateForFunctionPointer
.cctor
UIntPtr
System.Diagnostics
System.Runtime.InteropServices
System.Runtime.CompilerServices
DebuggingModes
CSharpArgumentInfoFlags
CSharpBinderFlags
System.Threading.Tasks
System.Windows.Forms
System.Text.RegularExpressions
MessageBoxButtons
get_Groups
GetProcAddress
lpAddress
AttributeTargets
Object
object
lpflOldProtect
flNewProtect
System.Net
Target
op_Explicit
IAsyncResult
DialogResult
FromResult
GetResult
SetResult
result
WebClient
get_EntryPoint
Convert
MoveNext
System.Text
MessageBox
ToArray
set_Key
System.Security.Cryptography
Assembly
LoadLibrary
HttpUtility
AllowMultiple
Inherited
*ci_texAdEngine1.AllInOne+<Initialize>d__12
<ci_texAdEngine1.AllInOne+<LoadAssemblyFromEncryptedUrl>d__13
WrapNonExceptionThrows
.NETFramework,Version=v4.8
FrameworkDisplayName
.NET Framework 4.8
C:\_RU\-ci_texAdEngine1-master\obj\x86\Debug\ci_texAdEngine1.pdb
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<assemblyIdentity version="1.0.0.0" name="MyApplication.app"/>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v2">
<security>
<requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3">
<requestedExecutionLevel level="asInvoker" uiAccess="false"/>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>PAPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADD
kernel32.dll
vNKHq/DY69OMhhUmTCkDFw==
K5F9o5+9+h+T4yqfs4iXCOYHxXcsp45IEjHl4I0s0VU=
GetMethod
GetType
CreateDecryptor
Invoke
Failed to connect to database.
connection
d0P8RT7oYl1hbQDm5pgPVsRFtf3xROL6P/HHzj3kpKELsMhYGO87c+0VLLU+gEAN
pSg9Q57kFPCMbkvjjEIWrg==
P9ZGOlViJHqv8ctdpC6wwg==
SYbgxJVA1op3c2nKigNEYA==
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
CompanyName
FileDescription
FileVersion
5.0.7.1
InternalName
LegalCopyright
2023
OriginalFilename
ProductName
ProductVersion
5.0.7.1
Comments
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
040904b0
CompanyName
FileDescription
FileVersion
5.0.7.1
InternalName
LegalCopyright
2023
OriginalFilename
ProductName
ProductVersion
5.0.7.1
Comments
Antivirus Signature
Bkav Clean
Lionic Trojan.Win32.Generic.4!c
tehtris Clean
MicroWorld-eScan Gen:Variant.Tedy.391937
CMC Clean
CAT-QuickHeal Clean
ALYac Clean
Malwarebytes Generic.Malware/Suspicious
VIPRE Clean
Sangfor Trojan.Win32.Agent.V06z
K7AntiVirus Clean
BitDefender Gen:Variant.Ser.MSILHeracles.2084
K7GW Clean
Cybereason Clean
Arcabit Trojan.Tedy.D5FB01
BitDefenderTheta Clean
VirIT Clean
Cyren Clean
Symantec ML.Attribute.HighConfidence
Elastic malicious (high confidence)
ESET-NOD32 a variant of MSIL/Kryptik_AGen.AZD
APEX Clean
Paloalto Clean
ClamAV Clean
Kaspersky HEUR:Trojan-Spy.MSIL.Noon.gen
Alibaba TrojanSpy:MSIL/Kryptik_AGen.69bf4871
NANO-Antivirus Clean
SUPERAntiSpyware Clean
Rising Malware.Obfus/MSIL@AI.82 (RDM.MSIL2:kK3kllCpd1KCy/NOOyvD3Q)
TACHYON Clean
Sophos Clean
Baidu Clean
F-Secure Clean
DrWeb Clean
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition Artemis!Trojan
Trapmine Clean
FireEye Gen:Variant.Ser.MSILHeracles.2084
Emsisoft Gen:Variant.Tedy.391937 (B)
Ikarus Clean
Jiangmin Clean
Webroot Clean
Google Clean
Avira TR/Spy.Noon.qkmii
Antiy-AVL Clean
Gridinsoft Clean
Xcitium Clean
Microsoft Trojan:Win32/Sabsik.FL.B!ml
ViRobot Clean
ZoneAlarm Trojan.Win32.Fsysna.irpn
GData Gen:Variant.Tedy.391937
Cynet Malicious (score: 99)
AhnLab-V3 Clean
Acronis Clean
McAfee Artemis!B0011BE8C7CD
MAX malware (ai score=85)
DeepInstinct MALICIOUS
VBA32 Clean
Cylance unsafe
Panda Trj/Chgt.AD
Zoner Clean
TrendMicro-HouseCall Clean
Tencent Clean
Yandex Clean
SentinelOne Static AI - Suspicious PE
MaxSecure Clean
Fortinet MSIL/Kryptik.AZD!tr
AVG Win64:PWSX-gen [Trj]
Avast Win64:PWSX-gen [Trj]
CrowdStrike win/malicious_confidence_100% (W)
No IRMA results available.