Static | ZeroBOX

PE Compile Time

2021-09-18 18:18:06

PDB Path

D:\MyProjects\SelfTraining\Csharp\ReconApp-Final\ReconApp\obj\x64\Release\alg.pdb

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x00003d42 0x00003e00 5.41176910953
.rsrc 0x00006000 0x00000594 0x00000600 4.0221432958

Resources

Name Offset Size Language Sub-language File type
RT_VERSION 0x00006090 0x00000304 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_MANIFEST 0x000063a4 0x000001ea LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with CRLF line terminators

!This program cannot be run in DOS mode.
`.rsrc
j_djZ
j_djZ
?j_djZ
v4.0.30319
#Strings
IEnumerable`1
List`1
_MuiChache1
Microsoft.Win32
get_UTF8
<Module>
System.IO
UploadData
_EdgeUserData
_ChromeUserData
mscorlib
System.Collections.Generic
MainProc
Thread
isBlocked
encrypted
System.Collections.Specialized
ReadToEnd
RunBulkCommand
RunCommand
set_Method
Replace
get_AvailableFreeSpace
get_TotalFreeSpace
FileMode
ZipArchiveMode
get_Message
AddRange
_ShellMuiCache
IDisposable
CheckDotNetVersionAcceptable
ZipFile
isFile
set_WindowStyle
ProcessWindowStyle
get_Name
set_FileName
GetRandomFileName
GetFileName
get_UserName
userName
DateTime
set_LastWriteTime
GetLastWriteTime
cmdLine
WriteLine
get_DriveType
set_ContentType
FileShare
_AssistantStore
WebResponse
GetResponse
Dispose
GetModifiedDate
Create
Delete
STAThreadAttribute
GuidAttribute
DebuggableAttribute
ComVisibleAttribute
AssemblyTitleAttribute
AssemblyTrademarkAttribute
TargetFrameworkAttribute
AssemblyFileVersionAttribute
AssemblyConfigurationAttribute
AssemblyDescriptionAttribute
CompilationRelaxationsAttribute
AssemblyProductAttribute
AssemblyCopyrightAttribute
AssemblyCompanyAttribute
RuntimeCompatibilityAttribute
set_UseShellExecute
ZipArchive
winDrive
ZipRecursive
alg.exe
GetFileSize
get_TotalSize
System.Threading
get_Encoding
set_Encoding
set_StandardOutputEncoding
System.Runtime.Versioning
FromBase64String
SizeToString
GetString
Substring
_ExtensionSetting
pathLog
GetLogPath
withFullPath
GetFolderPath
get_Length
set_ContentLength
StartsWith
TransformFinalBlock
get_VolumeLabel
FileStream
GetResponseStream
_OctectStream
GetRequestStream
Program
System.IO.Compression.FileSystem
SymmetricAlgorithm
Random
ICryptoTransform
System.IO.Compression
System.Reflection
NameValueCollection
WebHeaderCollection
Exception
_CurrentVersionRun
CopyTo
LogFileInfo
DriveInfo
FileSystemInfo
GetExplorerInfo
get_StartInfo
ProcessStartInfo
DirectoryInfo
pathZip
AddToZip
StreamReader
TextReader
SpecialFolder
CurrentUser
StreamWriter
TextWriter
UploadToServer
ExploreDir
get_StandardError
set_RedirectStandardError
.cctor
CreateDecryptor
cmdStr
System.Diagnostics
System.Runtime.InteropServices
System.Runtime.CompilerServices
DebuggingModes
GetDirectories
GetFiles
GetValueNames
FileAttributes
GetAttributes
ReadAllBytes
GetBytes
GetDrives
get_Ticks
System.Windows.Forms
Contains
get_Headers
FileAccess
Process
set_Arguments
Exists
GetRegSubKeys
Concat
get_DriveFormat
Object
System.Net
DateTimeOffset
op_Implicit
WaitForExit
get_Default
DialogResult
_Recent
WebClient
Environment
GetPathRoot
GetDecrypt
Convert
WebRequest
blockList
_AssistantPersist
get_StandardOutput
set_RedirectStandardOutput
WaitForNext
System.Text
CreateText
get_Now
set_CreateNoWindow
MessageBox
ToArray
get_IsReady
OpenSubKey
RegistryKey
System.Security.Cryptography
get_SystemDirectory
ZipProfileHistory
ZipChromeHistory
ZipBrowserHistory
GetRecentHistory
CreateEntry
ZipArchiveEntry
Registry
op_Equality
op_Inequality
WrapNonExceptionThrows
ReconApp
Copyright
2023
$6ca7856e-1c5e-4a7a-87e9-3c747b4a6f71
1.0.0.0
.NETFramework,Version=v4.5.2
FrameworkDisplayName
.NET Framework 4.5.2
D:\MyProjects\SelfTraining\Csharp\ReconApp-Final\ReconApp\obj\x64\Release\alg.pdb
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<assemblyIdentity version="1.0.0.0" name="MyApplication.app"/>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v2">
<security>
<requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3">
<requestedExecutionLevel level="asInvoker" uiAccess="false"/>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
Bytes
- <DIR> -
Drive type : {0}
Volumn label : {0}
File system : {0}
Total size of drive : {0}
Total available space : {0}
Available space to current user : {0}
Program Files\AhnLab
Program Files (x86)\AhnLab
Users\
\AppData\Local
\AppData\Roaming
Extension*
6BFhyp4iJoIrUO9Vu7j9rQ5F9w2Ylkh1XxEQ6cuIqao=
\Web Data
\History
\Bookmarks
\Login Data
\Default
Profile *
7Ir3prXxaNrY1TrpYldoaJY/joOH9O5DrqVDmtnygBmu/EJ6cPMmFB27VH6iQlsg
VFKRG6OXVbs6zYgBUn6xsr21utpLY+jx0M+8wcVOp7H0gwJIffV+PTZ2r3V63UNw
c5mHUXcCm8joJBkyS3iG5udRGJdWP9sCAHVtGictSvn6XpyO/XQwRBTFRLUA0Rak
*** Registry Keys ***
T4Nz2Xb8sckEJmve/fvRbXijQXbYm3HGZol/jIckMKctgQ3gaAoSwhy2bHCvnspJ
BDuZUpHskAOyOsdBVlra+Z5NGOmNc4IukXljfjDCg5t0zZE9NnMgLUFzZ1ttD1maG8zuc9ckCl7QTCTVRhhitkspdLikBryKJeC/k6cw2qo=
T4Nz2Xb8sckEJmve/fvRbfLwEJ5RAOX01JSFzLkt7to5OH5+1BNxHwkHqT4FG/pwUY6Vj7VHeXlfowMbmzhsCFch7noO2LDE6tDOa06gW5wBQUe6deL9F6nJKxlXZtU3
T4Nz2Xb8sckEJmve/fvRbfLwEJ5RAOX01JSFzLkt7to5OH5+1BNxHwkHqT4FG/pwUY6Vj7VHeXlfowMbmzhsCFch7noO2LDE6tDOa06gW5yXtzra3IiJDWJRNK3e/pd1
---------B{0:x}B---------
Content-Type
multipart/form-data; boundary=
v8LdAWODAiLLWloQ5IjoRf5qvE344NMeR6WgPXX+cx5PJINMLEIUtjr2hDRVN/aI
Content-Disposition: form-data; name="file"; filename="{1}"
--{0}--
qw+DUejhFDofeAYvTZn0FQ==
(Success)
interval
Command:
Output:
######################################################
text/plain
Fatal error
Please reinstall .net 3.5 first!
:\Windows
:\Users\All Users
:\Users\Default
:\Users\Default User
:\Users\Public
\AppData\Local\Comms
\AppData\Local\D3DSCache
\AppData\Local\OneDrive
\AppData\Local\Packages
\AppData\Local\Programs
\AppData\Local\Temp
\System Volumn Information
https://tosals.ink/uEH5J.html
Unknown error...
T4Nz2Xb8sckEJmve/fvRbXijQXbYm3HGZol/jIckMKctgQ3gaAoSwhy2bHCvnspJ
7Ir3prXxaNrY1TrpYldoaJY/joOH9O5DrqVDmtnygBmu/EJ6cPMmFB27VH6iQlsg
VFKRG6OXVbs6zYgBUn6xsr21utpLY+jx0M+8wcVOp7H0gwJIffV+PTZ2r3V63UNw
c5mHUXcCm8joJBkyS3iG5udRGJdWP9sCAHVtGictSvn6XpyO/XQwRBTFRLUA0Rak
BDuZUpHskAOyOsdBVlra+Z5NGOmNc4IukXljfjDCg5t0zZE9NnMgLUFzZ1ttD1maG8zuc9ckCl7QTCTVRhhitkspdLikBryKJeC/k6cw2qo=
T4Nz2Xb8sckEJmve/fvRbfLwEJ5RAOX01JSFzLkt7to5OH5+1BNxHwkHqT4FG/pwUY6Vj7VHeXlfowMbmzhsCFch7noO2LDE6tDOa06gW5wBQUe6deL9F6nJKxlXZtU3
T4Nz2Xb8sckEJmve/fvRbfLwEJ5RAOX01JSFzLkt7to5OH5+1BNxHwkHqT4FG/pwUY6Vj7VHeXlfowMbmzhsCFch7noO2LDE6tDOa06gW5yXtzra3IiJDWJRNK3e/pd1
6BFhyp4iJoIrUO9Vu7j9rQ5F9w2Ylkh1XxEQ6cuIqao=
qw+DUejhFDofeAYvTZn0FQ==
T4Nz2Xb8sckEJmve/fvRbbq8mTfGJiyRqNrqC7Cm9T1eGhfp0ivcAUQhVwYCntVy
v8LdAWODAiLLWloQ5IjoRf5qvE344NMeR6WgPXX+cx5PJINMLEIUtjr2hDRVN/aI
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
Comments
CompanyName
FileDescription
ReconApp
FileVersion
1.0.0.0
InternalName
alg.exe
LegalCopyright
Copyright
2023
LegalTrademarks
OriginalFilename
alg.exe
ProductName
ReconApp
ProductVersion
1.0.0.0
Assembly Version
1.0.0.0
Antivirus Signature
Bkav Clean
Lionic Trojan.Win32.Stealer.12!c
tehtris Clean
MicroWorld-eScan Trojan.GenericKD.68236738
ClamAV Clean
FireEye Trojan.GenericKD.68236738
CAT-QuickHeal Clean
ALYac Clean
Cylance unsafe
VIPRE Clean
Sangfor Infostealer.Msil.Agent.Vimn
K7AntiVirus Clean
BitDefender Trojan.GenericKD.68236738
K7GW Clean
Cybereason Clean
BitDefenderTheta Clean
VirIT Clean
Cyren Clean
Symantec Trojan.Gen.2
Elastic Clean
ESET-NOD32 a variant of MSIL/Agent.WIE
APEX Clean
Paloalto Clean
Cynet Malicious (score: 100)
Kaspersky HEUR:Trojan-PSW.MSIL.Stealer.gen
Alibaba Clean
NANO-Antivirus Clean
ViRobot Clean
Rising Clean
TACHYON Clean
Sophos Mal/Generic-S
Baidu Clean
F-Secure Clean
DrWeb Clean
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition Artemis
Trapmine Clean
CMC Clean
Emsisoft Trojan.GenericKD.68236738 (B)
SentinelOne Clean
GData Trojan.GenericKD.68236738
Jiangmin Clean
Webroot Clean
Avira TR/Agent.xgsya
Antiy-AVL Clean
Gridinsoft Clean
Xcitium Clean
Arcabit Trojan.Generic.D41135C2
SUPERAntiSpyware Clean
ZoneAlarm HEUR:Trojan-PSW.MSIL.Stealer.gen
Microsoft Program:Win32/Wacapew.C!ml
Google Clean
AhnLab-V3 Infostealer/Win.Generic.C5456906
Acronis Clean
McAfee Artemis!150E53A8C852
MAX malware (ai score=82)
DeepInstinct MALICIOUS
VBA32 Clean
Malwarebytes Clean
Panda Trj/Chgt.AD
Zoner Clean
TrendMicro-HouseCall Clean
Tencent Clean
Yandex Clean
Ikarus Clean
MaxSecure Trojan.Malware.300983.susgen
Fortinet Malicious_Behavior.SB
AVG PWSX-gen [Trj]
Avast PWSX-gen [Trj]
CrowdStrike win/malicious_confidence_70% (D)
No IRMA results available.