Static | ZeroBOX

PE Compile Time

2074-01-02 02:46:42

PDB Path

C:\Users\H3OX\source\repos\ConsoleApp3\ConsoleApp3\obj\Debug\ConsoleApp3.pdb

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x00001958 0x00001a00 5.40798615096
.rsrc 0x00004000 0x000005f0 0x00000600 4.20477552033
.reloc 0x00006000 0x0000000c 0x00000200 0.0815394123432

Resources

Name Offset Size Language Sub-language File type
RT_VERSION 0x00004090 0x00000360 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_MANIFEST 0x00004400 0x000001ea LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with CRLF line terminators

Imports

Library mscoree.dll:
0x402000 _CorExeMain

!This program cannot be run in DOS mode.
`.rsrc
@.reloc
v4.0.30319
#Strings
<LoadWithNT>b__8_0
Microsoft.Win32
ConsoleApp3
<Module>
PAGE_EXECUTE_READ
PAGE_GUARD
PAGE_NOCACHE
PAGE_WRITECOMBINE
MEM_RELEASE
PAGE_READWRITE
PAGE_EXECUTE_READWRITE
PAGE_EXECUTE
MEM_RESERVE
MEM_RESET_UNDO
PAGE_NOACCESS
MEM_RESET
MEM_DECOMMIT
MEM_COMMIT
LoadWithNT
PAGE_READONLY
PAGE_WRITECOPY
PAGE_EXECUTE_WRITECOPY
value__
DownloadData
mscorlib
TypeAlloc
_disposed
<Asynchronous>k__BackingField
method
DownloadShellCode
encryptedShellCode
DecryptShellCode
shellCode
get_Message
EndInvoke
BeginInvoke
IDisposable
SafeHandle
_safeHandle
SafeFileHandle
RuntimeTypeHandle
GetTypeFromHandle
ProcessHandle
FreeConsole
WriteLine
get_None
FreeType
AllocationType
Dispose
MulticastDelegate
DebuggerBrowsableState
CompilerGeneratedAttribute
GuidAttribute
DebuggableAttribute
DebuggerBrowsableAttribute
ComVisibleAttribute
AssemblyTitleAttribute
AssemblyTrademarkAttribute
TargetFrameworkAttribute
AssemblyFileVersionAttribute
AssemblyConfigurationAttribute
AssemblyDescriptionAttribute
CompilationRelaxationsAttribute
AssemblyProductAttribute
AssemblyCopyrightAttribute
AssemblyCompanyAttribute
RuntimeCompatibilityAttribute
SetValue
ConsoleApp3.exe
RegionSize
bufferSize
SuppressFinalize
System.Threading
System.Runtime.Versioning
String
disposing
AsyncCallback
callback
Marshal
kernel32.dll
ntdll.dll
Program
System
CancellationToken
written
get_Location
Action
System.Reflection
PageProtection
Exception
SetRegistryStartup
ShellCodeLoader
buffer
ShellCodeCaller
TaskScheduler
CurrentUser
GetDelegateForFunctionPointer
Crypter
UIntPtr
System.Diagnostics
System.Runtime.InteropServices
System.Runtime.CompilerServices
DebuggingModes
Microsoft.Win32.SafeHandles
numberOfBytes
System.Threading.Tasks
TaskCreationOptions
GetCurrentProcess
BaseAddress
ZeroBits
Imports
get_Asynchronous
set_Asynchronous
Concat
Object
object
oldProtect
newProtect
System.Net
op_Explicit
get_Default
IAsyncResult
result
WebClient
StartNew
OpenSubKey
RegistryKey
GetExecutingAssembly
NtFreeVirtualMemory
NtAllocateVirtualMemory
NtWriteVirtualMemory
NtProtectVirtualMemory
get_Factory
TaskFactory
Registry
WrapNonExceptionThrows
ConsoleApp3UI
ConsoleApp3
Copyright
2024
$708169ff-d3e2-4a46-8fe3-5f5ecdb90ebf
1.0.0.0
.NETFramework,Version=v4.7.2
FrameworkDisplayName
.NET Framework 4.7.2
C:\Users\H3OX\source\repos\ConsoleApp3\ConsoleApp3\obj\Debug\ConsoleApp3.pdb
_CorExeMain
mscoree.dll
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<assemblyIdentity version="1.0.0.0" name="MyApplication.app"/>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v2">
<security>
<requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3">
<requestedExecutionLevel level="asInvoker" uiAccess="false"/>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
Microsoft Edge0
121231220000Z
20981231220000Z0
Microsoft Edge0
Microsoft Edge
Microsoft Edge
pLorO
20240806130341Z
DigiCert, Inc.1;09
2DigiCert Trusted G4 RSA4096 SHA256 TimeStamping CA0
230714000000Z
341013235959Z0H1
DigiCert, Inc.1 0
DigiCert Timestamp 20230
Ihttp://crl3.digicert.com/DigiCertTrustedG4RSA4096SHA256TimeStampingCA.crl0
http://ocsp.digicert.com0X
Lhttp://cacerts.digicert.com/DigiCertTrustedG4RSA4096SHA256TimeStampingCA.crt0
l2|X/gGe
(f*^[0
DigiCert Inc1
www.digicert.com1!0
DigiCert Trusted Root G40
220323000000Z
370322235959Z0c1
DigiCert, Inc.1;09
2DigiCert Trusted G4 RSA4096 SHA256 TimeStamping CA0
http://ocsp.digicert.com0A
5http://cacerts.digicert.com/DigiCertTrustedRootG4.crt0C
2http://crl3.digicert.com/DigiCertTrustedRootG4.crl0
DigiCert Inc1
www.digicert.com1$0"
DigiCert Assured ID Root CA0
220801000000Z
311109235959Z0b1
DigiCert Inc1
www.digicert.com1!0
DigiCert Trusted Root G40
]J<0"0i3
v=Y]Bv
http://ocsp.digicert.com0C
7http://cacerts.digicert.com/DigiCertAssuredIDRootCA.crt0E
4http://crl3.digicert.com/DigiCertAssuredIDRootCA.crl0
~qj#k"
DigiCert, Inc.1;09
2DigiCert Trusted G4 RSA4096 SHA256 TimeStamping CA
240806130341Z0+
/1(0&0$0"
@WhA6o
4zoB\/Y;
https://tmpfiles.org/dl/10700323/fixclient.bin
Failed to decrypt shellcode.
Failed to download shellcode.
Failed to download shellcode:
Failed to decrypt shellcode:
SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Failed to set registry startup:
ntdll.dll
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
Comments
CompanyName
ConsoleApp3UI
FileDescription
ConsoleApp3UI
FileVersion
1.0.0.0
InternalName
ConsoleApp3.exe
LegalCopyright
Copyright
2024
LegalTrademarks
ConsoleApp3
OriginalFilename
ConsoleApp3.exe
ProductName
ConsoleApp3
ProductVersion
1.0.0.0
Assembly Version
1.0.0.0
Antivirus Signature
Bkav W32.AIDetectMalware.CS
Lionic Clean
tehtris Clean
ClamAV Clean
CMC Clean
CAT-QuickHeal Clean
Skyhigh Clean
ALYac IL:Trojan.MSILZilla.139163
Cylance Clean
Zillya Clean
Sangfor Clean
K7AntiVirus Clean
Alibaba Clean
K7GW Clean
Cybereason malicious.bb601f
huorong Clean
Baidu Clean
VirIT Clean
Paloalto Clean
Symantec Clean
Elastic malicious (high confidence)
ESET-NOD32 a variant of MSIL/TrojanDownloader.Agent.QWP
APEX Clean
Avast Win32:MalwareX-gen [Trj]
Cynet Clean
Kaspersky HEUR:Trojan.MSIL.Injuke.gen
BitDefender IL:Trojan.MSILZilla.139163
NANO-Antivirus Clean
ViRobot Clean
MicroWorld-eScan IL:Trojan.MSILZilla.139163
Tencent Clean
TACHYON Clean
Sophos Clean
F-Secure Trojan.TR/Dldr.Agent.wtmzn
DrWeb Clean
VIPRE IL:Trojan.MSILZilla.139163
TrendMicro Clean
McAfeeD Clean
Trapmine Clean
FireEye IL:Trojan.MSILZilla.139163
Emsisoft IL:Trojan.MSILZilla.139163 (B)
Ikarus Trojan-Downloader.MSIL.Agent
GData IL:Trojan.MSILZilla.139163
Jiangmin Clean
Webroot Clean
Varist Clean
Avira TR/Dldr.Agent.wtmzn
Antiy-AVL Clean
Kingsoft Clean
Gridinsoft Clean
Xcitium Clean
Arcabit Trojan.Marsilia.D21E11
SUPERAntiSpyware Clean
ZoneAlarm HEUR:Trojan.MSIL.Injuke.gen
Microsoft Program:Win32/Wacapew.C!ml
Google Detected
AhnLab-V3 Trojan/Win.RATX-gen.C5645985
Acronis Clean
McAfee Clean
MAX malware (ai score=85)
VBA32 Clean
Malwarebytes Trojan.ShellCode.MSIL
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Rising Clean
Yandex Clean
SentinelOne Clean
MaxSecure Clean
Fortinet Clean
BitDefenderTheta Clean
AVG Win32:MalwareX-gen [Trj]
DeepInstinct Clean
CrowdStrike Clean
alibabacloud Clean
No IRMA results available.