Static | ZeroBOX

PE Compile Time

2039-05-25 04:59:50

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
A_]\x13>2\x18\x1a 0x00002000 0x00009838 0x00009a00 7.99465987614
.text 0x0000c000 0x0000c408 0x0000c600 4.89996026863
.rsrc 0x0001a000 0x000005c8 0x00000600 4.11370304274
.reloc 0x0001c000 0x0000000c 0x00000200 0.0980041756627
0x0001e000 0x00000010 0x00000200 0.101910425663

Resources

Name Offset Size Language Sub-language File type
RT_VERSION 0x0001a0a0 0x0000033c LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_MANIFEST 0x0001a3dc 0x000001ea LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with CRLF line terminators

Imports

Library mscoree.dll:
0x41e000 _CorExeMain

!This program cannot be run in DOS mode.
`.rsrc
@.reloc
kdT:0;
lmiLHW
[>ZPve
;/Fe)Q
&%4\Km
\f$jIn
(bf 0wE
n1{E'o
\X8;M?.
pi"5iW
nhOYJi5S
Wsh_K?[
u`Gaso
qWbnK:K
A}:QiV
B.Bg96
DNCg9xk
Yn~f8C
!S)B`m
Z@8P:R"
x%X3\q
5Z-[lk
>*?_tEZ
3"rjG{9
~[o4FV
[G&7`A
tortyi
C>R$D`p
^cDAjLI
gt~Xc\
HV_"1O
q$X*A1
I3Fdj(]
ONvo+P9
Y(v UN
Auo($8
89X9K-<4u
]Z9D5O8
~Ze.ww
u1+]=3;
QcNM{5po
9F(n)3 wb
mJ1gbG
$0xRC|\
#[qx]3
bpFK6;=
[po^vn
hnfX0`r
TW^&in
RcnA*L
a)fv2,
|]:Ci}En
lwCffd
jGn67TA}
CM_,_
-NsHD^
'||ttu
x!`;FD
Krtl]e
Lf:"7
T:dz{D
JNX#91|
C$q#hn
3.b0o|
,bqMMv
]X"([c
m>W{#1
X8c5bW
7"=B~Yxi
9<,Ugs9+pZ
rU8YeU
~riVA6
C}b$ls
j4,W@
@b*+tzCJ|
aRVKgz
3#;X#w{
\Wq<dqpr
|mT|E9
STRT>p
Ma`_vr
=}W:B[<
5fu#st
,Z }Lr
_CorExeMain
mscoree.dll
v4.0.30319
#Strings
#Strings
#Schema
CloudyBtstrp.exe
mscorlib
SuppressIldasmAttribute
System.Runtime.CompilerServices
<Module>
Assembly
System.Reflection
.cctor
VirtualProtect
kernel32.dll
System
RuntimeTypeHandle
MethodInfo
MethodBase
Thread
System.Threading
ParameterizedThreadStart
Module
ResolveEventArgs
ValueType
Object
Stream
System.IO
PresentationFramework
Application
System.Windows
UriKind
yijgJjhlqxXEAHwzVNaTiQfsejzw
Window
System.Xaml
IComponentConnector
System.Windows.Markup
ProgressBar
System.Windows.Controls
TextBlock
TextBox
Task`1
System.Threading.Tasks
PresentationCore
RoutedEventArgs
MouseButtonEventArgs
System.Windows.Input
InitializeComponent
System.Windows.Markup.IComponentConnector.Connect
Connect
connectionId
target
TextBoxBase
System.Windows.Controls.Primitives
Exception
StringComparison
InvalidOperationException
AppDomain
DirectoryInfo
FileSystemInfo
StringComparer
FileInfo
Encoding
System.Text
ProcessStartInfo
System.Diagnostics
Process
MouseButton
UIElement
MouseButtonEventHandler
ButtonBase
RoutedEventHandler
5?*U2G+E~QF\L/sGP4>U/"f&+
IAsyncStateMachine
AsyncTaskMethodBuilder
System.Net.Http
HttpClient
HttpResponseMessage
FileStream
TaskAwaiter`1
TaskAwaiter
MoveNext
SetStateMachine
stateMachine
HttpCompletionOption
FileMode
FileAccess
HttpContent
HttpContentHeaders
System.Net.Http.Headers
Nullable`1
<7=\$22(E%o1tt[g1,HZVZW'%
AsyncTaskMethodBuilder`1
HttpRequestHeaders
AuthenticationHeaderValue
IDisposable
hlojjbpBy^CN@[C%UTV@R[G;!
AsyncVoidMethodBuilder
te/LP2v<L)HEef?,3|(c\}=T"
ResourceManager
System.Resources
CultureInfo
System.Globalization
Settings
CloudyBtstrp.Properties
ApplicationSettingsBase
System.Configuration
SettingsBase
Default
ConfusedByAttribute
Attribute
CloudyBtstrp
CompilationRelaxationsAttribute
RuntimeCompatibilityAttribute
DebuggableAttribute
DebuggingModes
AssemblyTitleAttribute
AssemblyDescriptionAttribute
AssemblyConfigurationAttribute
AssemblyCompanyAttribute
AssemblyProductAttribute
AssemblyCopyrightAttribute
AssemblyTrademarkAttribute
ComVisibleAttribute
System.Runtime.InteropServices
ThemeInfoAttribute
ResourceDictionaryLocation
AssemblyFileVersionAttribute
TargetFrameworkAttribute
System.Runtime.Versioning
DebuggerNonUserCodeAttribute
GeneratedCodeAttribute
System.CodeDom.Compiler
STAThreadAttribute
AsyncStateMachineAttribute
DebuggerStepThroughAttribute
EditorBrowsableAttribute
System.ComponentModel
EditorBrowsableState
CompilerGeneratedAttribute
DebuggerHiddenAttribute
CloudyBtstrp.g.resources
mzegQXxTnPFlrmXcJvVVJWgcMHtB
te/LP2v<L)HEef?\,3|(c\\}=T".resources
Environment
String
UInt32
IntPtr
op_Explicit
GetTypeFromHandle
GetMethod
Concat
Invoke
Equals
FailFast
set_IsBackground
get_CurrentThread
Debugger
get_IsAttached
IsLogging
get_IsAlive
get_Module
Marshal
GetHINSTANCE
get_FullyQualifiedName
get_Chars
MemoryStream
get_Length
ReadByte
RuntimeHelpers
InitializeArray
RuntimeFieldHandle
GetElementType
CreateInstance
Buffer
BlockCopy
get_UTF8
GetString
Intern
get_CurrentDomain
ResolveEventHandler
add_AssemblyResolve
get_FullName
get_Name
op_Equality
set_StartupUri
Create
get_Task
System.Core
Enumerable
System.Linq
Contains
IEnumerable`1
System.Collections.Generic
IEqualityComparer`1
Button
set_Topmost
System.IO.Compression.FileSystem
ZipFile
System.IO.Compression
ExtractToDirectory
Delete
AppendText
get_Message
set_Text
IndexOf
Substring
Exists
ReadAllText
get_BaseDirectory
GetDirectories
get_OrdinalIgnoreCase
Directory
GetFiles
WriteAllText
GetBytes
Convert
ToBase64String
Combine
set_FileName
set_UseShellExecute
get_Current
Shutdown
get_ChangedButton
DragMove
LoadComponent
add_MouseDown
add_Click
AwaitUnsafeOnCompleted
GetResult
GetAwaiter
get_IsCompleted
RangeBase
set_Value
GetValueOrDefault
Dispose
SetException
SetResult
GetAsync
EnsureSuccessStatusCode
get_Content
ReadAsStreamAsync
get_Headers
get_ContentLength
ReadAsync
WriteAsync
get_DefaultRequestHeaders
set_Authorization
ReadAsStringAsync
get_LocalPath
GetFileName
EndsWith
get_Assembly
Synchronized
ConfuserEx v1.0.0
WrapNonExceptionThrows
CloudyBtstrp
Copyright
2024
1.0.0.0
.NETFramework,Version=v4.7.2
FrameworkDisplayName
.NET Framework 4.7.2#
PresentationBuildTasks
4.0.0.0
8yijgJjhlqxXEAHwzVNaTiQfsejzw+hlojjbpBy^CN@\[C%UTV@R\[G;!
9yijgJjhlqxXEAHwzVNaTiQfsejzw+<7=\\$22(E%o1tt\[g1\,HZVZW'%
;yijgJjhlqxXEAHwzVNaTiQfsejzw+5?\*U2G\+E~QF\\L/sGP4>U/"f\&\+
3System.Resources.Tools.StronglyTypedResourceBuilder
4.0.0.0
KMicrosoft.VisualStudio.Editors.SettingsDesigner.SettingsSingleFileGenerator
11.0.0.0
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<assemblyIdentity version="1.0.0.0" name="MyApplication.app"/>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v2">
<security>
<requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3">
<requestedExecutionLevel level="asInvoker" uiAccess="false"/>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
Comments
CompanyName
FileDescription
CloudyBtstrp
FileVersion
1.0.0.0
InternalName
CloudyBtstrp.exe
LegalCopyright
Copyright
2024
LegalTrademarks
OriginalFilename
CloudyBtstrp.exe
ProductName
CloudyBtstrp
ProductVersion
1.0.0.0
Assembly Version
1.0.0.0
Antivirus Signature
Bkav W32.AIDetectMalware.CS
Lionic Trojan.Win32.Generic.4!c
Elastic malicious (high confidence)
ClamAV Clean
CMC Clean
CAT-QuickHeal Clean
Skyhigh BehavesLike.Win32.Generic.nh
ALYac Gen:Variant.MSILHeracles.179810
Cylance Unsafe
Zillya Clean
Sangfor Trojan.Win32.Agent.Vsly
CrowdStrike Clean
Alibaba Clean
K7GW Clean
K7AntiVirus Clean
huorong Clean
Baidu Clean
VirIT Clean
Paloalto generic.ml
Symantec ML.Attribute.HighConfidence
tehtris Clean
ESET-NOD32 Clean
APEX Malicious
Avast Win32:MalwareX-gen [Trj]
Cynet Clean
Kaspersky Clean
BitDefender Gen:Variant.MSILHeracles.179810
NANO-Antivirus Clean
ViRobot Clean
MicroWorld-eScan Gen:Variant.MSILHeracles.179810
Tencent Clean
Sophos Generic ML PUA (PUA)
F-Secure Clean
DrWeb Clean
VIPRE Gen:Variant.MSILHeracles.179810
TrendMicro Clean
McAfeeD Real Protect-LS!7022E230ADFB
Trapmine malicious.moderate.ml.score
CTX exe.trojan.generic
Emsisoft Gen:Variant.MSILHeracles.179810 (B)
Ikarus Clean
FireEye Generic.mg.7022e230adfb9b8a
Jiangmin Clean
Webroot Clean
Varist Clean
Avira Clean
Fortinet PossibleThreat
Antiy-AVL Trojan/Win32.AGeneric
Kingsoft malware.kb.c.947
Gridinsoft Trojan.Heur!.03013281
Xcitium Clean
Arcabit Trojan.MSILHeracles.D2BE62
SUPERAntiSpyware Clean
ZoneAlarm Clean
Microsoft Clean
Google Clean
AhnLab-V3 Clean
Acronis Clean
McAfee Artemis!7022E230ADFB
TACHYON Clean
VBA32 CIL.StupidPInvoker-1.Heur
Malwarebytes Generic.Malware/Suspicious
Panda Clean
Zoner Probably Heur.ExeHeaderL
TrendMicro-HouseCall TROJ_GEN.R002H09II24
Rising Malware.Obfus/MSIL@AI.82 (RDM.MSIL2:M1RWWUJLGjs3ElswKq1T6A)
Yandex Clean
SentinelOne Static AI - Malicious PE
MaxSecure Trojan.Malware.281440417.susgen
GData Gen:Variant.MSILHeracles.179810
AVG Win32:MalwareX-gen [Trj]
DeepInstinct MALICIOUS
alibabacloud Clean
No IRMA results available.