Static | ZeroBOX

PE Compile Time

2024-08-16 06:50:31

PDB Path

C:\Users\H3OX\Desktop\New folder\ConsoleApp3\obj\Debug\ConsoleApp3.pdb

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x00001a6c 0x00001c00 5.23170455436
.rsrc 0x00004000 0x000005e4 0x00000600 4.17319373865
.reloc 0x00006000 0x0000000c 0x00000200 0.0815394123432

Resources

Name Offset Size Language Sub-language File type
RT_VERSION 0x00004090 0x00000354 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_MANIFEST 0x000043f4 0x000001ea LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with CRLF line terminators

Imports

Library mscoree.dll:
0x402000 _CorExeMain

!This program cannot be run in DOS mode.
`.rsrc
@.reloc
v4.0.30319
#Strings
<LoadWithNT>b__5_0
Microsoft.Win32
ConsoleApp3
<Module>
PAGE_EXECUTE_READ
PAGE_GUARD
PAGE_NOCACHE
PAGE_WRITECOMBINE
MEM_RELEASE
PAGE_READWRITE
PAGE_EXECUTE_READWRITE
PAGE_EXECUTE
MEM_RESERVE
MEM_RESET_UNDO
PAGE_NOACCESS
MEM_RESET
MEM_DECOMMIT
MEM_COMMIT
LoadWithNT
PAGE_READONLY
PAGE_WRITECOPY
PAGE_EXECUTE_WRITECOPY
value__
DownloadData
mscorlib
TypeAlloc
_disposed
<Asynchronous>k__BackingField
method
DownloadShellCode
encryptedShellCode
DecryptShellCode
shellCode
get_Message
EndInvoke
BeginInvoke
IDisposable
SafeHandle
_safeHandle
SafeFileHandle
RuntimeTypeHandle
GetTypeFromHandle
ProcessHandle
FreeConsole
WriteLine
get_None
FreeType
AllocationType
Dispose
MulticastDelegate
DebuggerBrowsableState
CompilerGeneratedAttribute
GuidAttribute
NeutralResourcesLanguageAttribute
DebuggableAttribute
DebuggerBrowsableAttribute
ComVisibleAttribute
AssemblyTitleAttribute
AssemblyTrademarkAttribute
TargetFrameworkAttribute
AssemblyFileVersionAttribute
AssemblyConfigurationAttribute
AssemblyDescriptionAttribute
CompilationRelaxationsAttribute
AssemblyProductAttribute
AssemblyCopyrightAttribute
AssemblyCompanyAttribute
RuntimeCompatibilityAttribute
SetValue
ConsoleApp3.exe
RegionSize
bufferSize
SuppressFinalize
System.Threading
System.Runtime.Versioning
String
disposing
AsyncCallback
callback
Marshal
kernel32.dll
ntdll.dll
Program
System
CancellationToken
written
get_Location
Action
System.Reflection
PageProtection
Exception
SetRegistryStartup
ShellCodeLoader
buffer
ShellCodeCaller
TaskScheduler
CurrentUser
GetDelegateForFunctionPointer
Crypter
UIntPtr
System.Diagnostics
System.Runtime.InteropServices
System.Runtime.CompilerServices
System.Resources
DebuggingModes
Microsoft.Win32.SafeHandles
numberOfBytes
System.Threading.Tasks
TaskCreationOptions
GetCurrentProcess
BaseAddress
ZeroBits
Imports
get_Asynchronous
set_Asynchronous
Concat
Object
object
oldProtect
newProtect
System.Net
op_Explicit
get_Default
IAsyncResult
result
WebClient
StartNew
OpenSubKey
RegistryKey
GetExecutingAssembly
NtFreeVirtualMemory
NtAllocateVirtualMemory
NtWriteVirtualMemory
NtProtectVirtualMemory
get_Factory
TaskFactory
Registry
WrapNonExceptionThrows
ConsoleApp3
Copyright
2024
$708169ff-d3e2-4a46-8fe3-5f5ecdb90ebf
1.0.0.0
.NETFramework,Version=v4.7.2
FrameworkDisplayName
.NET Framework 4.7.2
C:\Users\H3OX\Desktop\New folder\ConsoleApp3\obj\Debug\ConsoleApp3.pdb
_CorExeMain
mscoree.dll
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<assemblyIdentity version="1.0.0.0" name="MyApplication.app"/>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v2">
<security>
<requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3">
<requestedExecutionLevel level="asInvoker" uiAccess="false"/>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
https://zakariya-ayt-amran.github.io/driver-/Driver.bin
Failed to decrypt shellcode.
Failed to download shellcode.
Failed to download shellcode:
Failed to decrypt shellcode:
SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Failed to set registry startup:
ntdll.dll
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
Comments
ConsoleApp3
CompanyName
ConsoleApp3
FileDescription
ConsoleApp3
FileVersion
1.0.0.0
InternalName
ConsoleApp3.exe
LegalCopyright
Copyright
2024
LegalTrademarks
OriginalFilename
ConsoleApp3.exe
ProductName
ConsoleApp3
ProductVersion
1.0.0.0
Assembly Version
1.0.0.0
Antivirus Signature
Bkav W32.AIDetectMalware.CS
Lionic Trojan.Win32.Agent.Y!c
tehtris Clean
ClamAV Clean
CMC Clean
CAT-QuickHeal Backdoor.MSIL
Skyhigh Clean
McAfee Artemis!11F656A0E8AB
Cylance Unsafe
Zillya Clean
Sangfor Downloader.Msil.Agent.Vzgt
K7AntiVirus Trojan-Downloader ( 005b78361 )
Alibaba Backdoor:MSIL/MalwareX.399c693b
K7GW Trojan-Downloader ( 005b78361 )
Cybereason malicious.0e8ab8
huorong Clean
Baidu Clean
VirIT Clean
Paloalto generic.ml
Symantec ML.Attribute.HighConfidence
Elastic malicious (high confidence)
ESET-NOD32 a variant of MSIL/TrojanDownloader.Agent.QWP
APEX Clean
Avast Win32:MalwareX-gen [Trj]
Cynet Clean
Kaspersky HEUR:Backdoor.MSIL.Agent.gen
BitDefender Gen:Variant.MSILHeracles.170548
NANO-Antivirus Clean
ViRobot Clean
MicroWorld-eScan Gen:Variant.MSILHeracles.170548
Tencent Malware.Win32.Gencirc.1416add7
TACHYON Clean
Sophos Mal/Generic-S
F-Secure Trojan.TR/Dldr.Agent.xasph
DrWeb Clean
VIPRE Gen:Variant.MSILHeracles.170548
TrendMicro Clean
McAfeeD ti!B4A7A6E6FB51
Trapmine Clean
FireEye Gen:Variant.MSILHeracles.170548
Emsisoft Gen:Variant.MSILHeracles.170548 (B)
Ikarus Trojan-Downloader.MSIL.Agent
GData Gen:Variant.MSILHeracles.170548
Jiangmin Clean
Webroot Clean
Varist W32/ABTrojan.BNWL-7194
Avira TR/Dldr.Agent.xasph
Antiy-AVL Trojan/Win32.Wacatac
Kingsoft MSIL.Backdoor.Agent.gen
Gridinsoft Ransom.Win32.Wacatac.sa
Xcitium Clean
Arcabit Trojan.MSILHeracles.D29A34
SUPERAntiSpyware Clean
ZoneAlarm HEUR:Backdoor.MSIL.Agent.gen
Microsoft Trojan:Win32/Wacatac.B!ml
Google Detected
AhnLab-V3 Trojan/Win.RATX-gen.C5659590
Acronis Clean
BitDefenderTheta Gen:NN.ZemsilF.36812.am0@a4vNdkh
MAX malware (ai score=84)
VBA32 Clean
Malwarebytes Generic.Malware/Suspicious
Panda Trj/Chgt.AD
Zoner Clean
TrendMicro-HouseCall TROJ_GEN.R002H07HH24
Rising Backdoor.Agent!8.C5D (CLOUD)
Yandex Clean
SentinelOne Static AI - Malicious PE
MaxSecure Trojan.Malware.11035479.susgen
Fortinet MSIL/Agent.QWP!tr.dldr
AVG Win32:MalwareX-gen [Trj]
DeepInstinct MALICIOUS
CrowdStrike win/malicious_confidence_100% (W)
alibabacloud Trojan[downloader]:MSIL/Wacatac.B9nj
No IRMA results available.