Static | ZeroBOX

PE Compile Time

2070-08-28 12:04:05

PDB Path

C:\Users\Administrator\source\repos\GreenField\GreenField\obj\Debug\GreenField.pdb

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x000027bc 0x00002800 5.55169973671
.rsrc 0x00006000 0x000005e4 0x00000600 4.1486343171
.reloc 0x00008000 0x0000000c 0x00000200 0.0815394123432

Resources

Name Offset Size Language Sub-language File type
RT_VERSION 0x00006090 0x00000354 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_MANIFEST 0x000063f4 0x000001ea LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with CRLF line terminators

Imports

Library mscoree.dll:
0x402000 _CorExeMain

!This program cannot be run in DOS mode.
`.rsrc
@.reloc
v4.0.30319
#Strings
<downloadPhotoBoxTask>5__10
<downloadTK7Task>5__11
<message>5__1
<localPath>5__1
<client>5__1
<>s__1
<>u__1
Task`1
AsyncTaskMethodBuilder`1
TaskAwaiter`1
<>s__12
Microsoft.Win32
<url>5__2
<content>5__2
<>s__2
<>u__2
<>s__13
<response>5__3
<fileContent>5__3
<Main>d__3
<>s__3
<>u__3
<photoBoxProcess>5__14
<firstLinkUrl>5__4
<>s__4
<vbsProcess>5__15
<systemLinkUrl>5__5
<ex>5__5
<GetDownloadUrlAsync>d__5
<ex>5__16
<vbsDownloadUrl>5__6
<DownloadFileAsync>d__6
<systemDownloadUrl>5__7
<SendErrorToTelegram>d__7
<photoBoxExePath>5__8
<vbsFilePath>5__9
<Module>
<Main>
System.IO
mscorlib
DownloadFileAsync
GetStringAsync
GetDownloadUrlAsync
GetAsync
GetByteArrayAsync
chatId
AwaitUnsafeOnCompleted
get_IsCompleted
GreenField
EnsureSuccessStatusCode
get_Message
HttpResponseMessage
errorMessage
IDisposable
TryDeleteFile
get_MainModule
ProcessModule
get_FileName
set_FileName
fileName
Combine
IAsyncStateMachine
SetStateMachine
stateMachine
Dispose
Create
<>1__state
Delete
STAThreadAttribute
CompilerGeneratedAttribute
GuidAttribute
DebuggableAttribute
ComVisibleAttribute
AssemblyTitleAttribute
AsyncStateMachineAttribute
DebuggerStepThroughAttribute
AssemblyTrademarkAttribute
TargetFrameworkAttribute
DebuggerHiddenAttribute
AssemblyFileVersionAttribute
AssemblyConfigurationAttribute
AssemblyDescriptionAttribute
CompilationRelaxationsAttribute
AssemblyProductAttribute
AssemblyCopyrightAttribute
AssemblyCompanyAttribute
RuntimeCompatibilityAttribute
SetValue
GreenField.exe
System.Runtime.Versioning
String
filePath
GetFolderPath
get_Task
WhenAll
SendErrorToTelegram
Program
System
System.Reflection
SetException
get_StartInfo
ProcessStartInfo
System.Net.Http
AddToStartup
AsyncTaskMethodBuilder
<>t__builder
SpecialFolder
CurrentUser
TaskAwaiter
GetAwaiter
.cctor
System.Diagnostics
System.Runtime.InteropServices
System.Runtime.CompilerServices
DebuggingModes
WriteAllBytes
System.Threading.Tasks
GetCurrentProcess
StartProcess
set_Arguments
Exists
Concat
Object
WaitForExit
GetResult
SetResult
HttpClient
client
Environment
StartProcessWithWscript
MoveNext
OpenSubKey
RegistryKey
Registry
WrapNonExceptionThrows
GreenField
Amazon.com
Copyright
Amazon.com 2024
$fd0f031d-fedd-463d-991c-14337f1d2b62
1.0.0.0
.NETFramework,Version=v4.7.2
FrameworkDisplayName
.NET Framework 4.7.2
Program+<Main>d__3
!Program+<GetDownloadUrlAsync>d__5
Program+<DownloadFileAsync>d__6
!Program+<SendErrorToTelegram>d__7
C:\Users\Administrator\source\repos\GreenField\GreenField\obj\Debug\GreenField.pdb
_CorExeMain
mscoree.dll
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<assemblyIdentity version="1.0.0.0" name="MyApplication.app"/>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v2">
<security>
<requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3">
<requestedExecutionLevel level="asInvoker" uiAccess="false"/>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
SOFTWARE\Microsoft\Windows\CurrentVersion\Run
MyProgram
wscript
8159072313:AAEhU7O99DQT44s_1muDaJuGkynAfU4Kxl8
6653386349
Failed to download file:
. Error:
https://raw.githubusercontent.com/AsOld1/11/main/1
https://raw.githubusercontent.com/AsOld1/11/main/2
PhotoBox.exe
TK7.vbs
Failed to download PhotoBox.exe.
Failed to download TK7.vbs.
Unexpected error:
Error:
https://api.telegram.org/bot
/sendMessage?chat_id=
&text=
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
Comments
CompanyName
Amazon.com
FileDescription
GreenField
FileVersion
1.0.0.0
InternalName
GreenField.exe
LegalCopyright
Copyright
Amazon.com 2024
LegalTrademarks
OriginalFilename
GreenField.exe
ProductName
GreenField
ProductVersion
1.0.0.0
Assembly Version
1.0.0.0
Antivirus Signature
Bkav W32.AIDetectMalware.CS
Lionic Trojan.Win32.Crysan.m!c
Elastic malicious (moderate confidence)
ClamAV Clean
CMC Clean
CAT-QuickHeal Backdoor.MSIL
Skyhigh Artemis!Trojan
ALYac IL:Trojan.MSILZilla.149085
Cylance Unsafe
Zillya Backdoor.Crysan.Win32.7967
CrowdStrike win/malicious_confidence_100% (W)
Alibaba Backdoor:MSIL/Crysan.f7af4f41
K7GW Trojan-Downloader ( 005bc54b1 )
K7AntiVirus Trojan-Downloader ( 005bc54b1 )
huorong Clean
Baidu Clean
VirIT Trojan.Win32.MSIL.FZH
Paloalto generic.ml
Symantec ML.Attribute.HighConfidence
tehtris Clean
ESET-NOD32 MSIL/TrojanDownloader.Agent.RJL
APEX Clean
Avast Win32:MalwareX-gen [Trj]
Cynet Clean
Kaspersky HEUR:Backdoor.MSIL.Crysan.gen
BitDefender IL:Trojan.MSILZilla.149085
NANO-Antivirus Trojan.Win32.Crysan.ktfvin
ViRobot Clean
MicroWorld-eScan IL:Trojan.MSILZilla.149085
Tencent Malware.Win32.Gencirc.141e96df
Sophos Mal/Generic-S
F-Secure Trojan.TR/AD.Nekark.eexdy
DrWeb Clean
VIPRE IL:Trojan.MSILZilla.149085
TrendMicro Clean
McAfeeD ti!1C30611E8E3A
Trapmine Clean
CTX exe.trojan.crysan
Emsisoft IL:Trojan.MSILZilla.149085 (B)
Ikarus Trojan.IL.MSILZilla
FireEye IL:Trojan.MSILZilla.149085
Jiangmin Clean
Webroot Clean
Varist W32/ABTrojan.MQRZ-6219
Avira TR/AD.Nekark.eexdy
Fortinet PossibleThreat
Antiy-AVL Trojan/Win32.Agent
Kingsoft MSIL.Backdoor.Crysan.gen
Gridinsoft Clean
Xcitium Clean
Arcabit IL:Trojan.MSILZilla.D2465D
SUPERAntiSpyware Clean
ZoneAlarm UDS:DangerousObject.Multi.Generic
Microsoft Trojan:VBS/Phish
Google Detected
AhnLab-V3 Trojan/Win.MSILZilla.C5691550
Acronis Clean
McAfee Artemis!18208BA6920A
TACHYON Clean
VBA32 Clean
Malwarebytes Trojan.Downloader.MSIL
Panda Trj/Chgt.AD
Zoner Clean
TrendMicro-HouseCall Clean
Rising Backdoor.Crysan!8.10ECA (CLOUD)
Yandex Clean
SentinelOne Static AI - Suspicious PE
MaxSecure Clean
GData IL:Trojan.MSILZilla.149085
AVG Win32:MalwareX-gen [Trj]
DeepInstinct MALICIOUS
alibabacloud Clean
No IRMA results available.