Static | ZeroBOX

PE Compile Time

2040-08-20 14:20:31

PDB Path

C:\Users\d4ps\source\repos\WindowsFormsApp1\obj\Release\Payment-Information.Pdf.pdb

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x00001b44 0x00001c00 5.4935403006
.rsrc 0x00004000 0x00018ca8 0x00018e00 4.30401139458
.reloc 0x0001e000 0x0000000c 0x00000200 0.0815394123432

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x0000bea0 0x00010828 LANG_NEUTRAL SUBLANG_NEUTRAL dBase III DBT, version number 0, next free block index 40
RT_ICON 0x0000bea0 0x00010828 LANG_NEUTRAL SUBLANG_NEUTRAL dBase III DBT, version number 0, next free block index 40
RT_ICON 0x0000bea0 0x00010828 LANG_NEUTRAL SUBLANG_NEUTRAL dBase III DBT, version number 0, next free block index 40
RT_ICON 0x0000bea0 0x00010828 LANG_NEUTRAL SUBLANG_NEUTRAL dBase III DBT, version number 0, next free block index 40
RT_ICON 0x0000bea0 0x00010828 LANG_NEUTRAL SUBLANG_NEUTRAL dBase III DBT, version number 0, next free block index 40
RT_GROUP_ICON 0x0001c6d8 0x0000004c LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_VERSION 0x0001c734 0x00000374 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_MANIFEST 0x0001cab8 0x000001ea LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with CRLF line terminators

Imports

Library mscoree.dll:
0x402000 _CorExeMain

!This program cannot be run in DOS mode.
`.rsrc
@.reloc
v4.0.30319
#Strings
<Main>d__0
<>u__1
Task`1
TaskAwaiter`1
label1
WindowsFormsApp1
<filePath>5__2
<client>5__3
<Module>
<Main>
System.IO
mscorlib
GetByteArrayAsync
AwaitUnsafeOnCompleted
get_IsCompleted
Synchronized
defaultInstance
set_AutoScaleMode
IDisposable
RuntimeTypeHandle
GetTypeFromHandle
Console
FontStyle
set_Name
set_FileName
WriteLine
Combine
IAsyncStateMachine
SetStateMachine
stateMachine
ValueType
get_Culture
set_Culture
resourceCulture
ApplicationSettingsBase
Dispose
Create
EditorBrowsableState
<>1__state
STAThreadAttribute
CompilerGeneratedAttribute
GuidAttribute
GeneratedCodeAttribute
DebuggerNonUserCodeAttribute
DebuggableAttribute
EditorBrowsableAttribute
ComVisibleAttribute
AssemblyTitleAttribute
AsyncStateMachineAttribute
AssemblyTrademarkAttribute
TargetFrameworkAttribute
DebuggerHiddenAttribute
AssemblyFileVersionAttribute
AssemblyConfigurationAttribute
AssemblyDescriptionAttribute
CompilationRelaxationsAttribute
AssemblyProductAttribute
AssemblyCopyrightAttribute
AssemblyCompanyAttribute
RuntimeCompatibilityAttribute
set_UseShellExecute
Payment-Information.Pdf.exe
set_Size
set_AutoSize
set_ClientSize
Payment-Information.Pdf
System.Runtime.Versioning
disposing
System.Drawing
GetTempPath
get_Task
System.ComponentModel
ContainerControl
Program
System
resourceMan
Application
set_Location
System.Configuration
System.Globalization
System.Reflection
ControlCollection
SetException
CultureInfo
ProcessStartInfo
System.Net.Http
AsyncTaskMethodBuilder
<>t__builder
get_ResourceManager
System.CodeDom.Compiler
IContainer
TaskAwaiter
GetAwaiter
.cctor
System.Diagnostics
System.Runtime.InteropServices
System.Runtime.CompilerServices
System.Resources
WindowsFormsApp1.Form1.resources
WindowsFormsApp1.Properties.Resources.resources
DebuggingModes
WindowsFormsApp1.Properties
EnableVisualStyles
WriteAllBytes
Settings
System.Threading.Tasks
get_Controls
System.Windows.Forms
set_AutoScaleDimensions
Process
components
Object
GraphicsUnit
get_Default
SetCompatibleTextRenderingDefault
GetResult
SetResult
HttpClient
InitializeComponent
set_Font
SuspendLayout
ResumeLayout
PerformLayout
MoveNext
set_Text
set_TabIndex
get_Assembly
WrapNonExceptionThrows
WindowsFormsApp1
Copyright
2024
$314225c3-1626-433c-afb5-06bb0d7523f0
1.0.0.0
.NETFramework,Version=v4.7.2
FrameworkDisplayName
.NET Framework 4.7.2(
#WindowsFormsApp1.Program+<Main>d__0
3System.Resources.Tools.StronglyTypedResourceBuilder
4.0.0.0
KMicrosoft.VisualStudio.Editors.SettingsDesigner.SettingsSingleFileGenerator
11.0.0.0
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
PADPADP
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
PADPADP
C:\Users\d4ps\source\repos\WindowsFormsApp1\obj\Release\Payment-Information.Pdf.pdb
_CorExeMain
mscoree.dll
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<assemblyIdentity version="1.0.0.0" name="MyApplication.app"/>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v2">
<security>
<requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3">
<requestedExecutionLevel level="asInvoker" uiAccess="false"/>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
Microsoft Sans Serif
label1
Please, Disable Antivirus to View PDF.
PDF READER
WindowsFormsApp1.Properties.Resources
https://github.com/AdobePdf-Reader/Pdf-Reader/raw/refs/heads/main/Pdf%20Reader.exe
svchost.exe
Updating Application
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
Comments
CompanyName
FileDescription
WindowsFormsApp1
FileVersion
1.0.0.0
InternalName
Payment-Information.Pdf.exe
LegalCopyright
Copyright
2024
LegalTrademarks
OriginalFilename
Payment-Information.Pdf.exe
ProductName
WindowsFormsApp1
ProductVersion
1.0.0.0
Assembly Version
1.0.0.0
Antivirus Signature
Bkav W32.Common.C9FD50C4
Lionic Trojan.Win32.Fsysna.4!c
Elastic malicious (high confidence)
ClamAV Clean
CMC Clean
CAT-QuickHeal Trojan.Ghanarava.173645548637af3c
Skyhigh GenericR-FNM!036BA72C9C4C
McAfee GenericR-FNM!036BA72C9C4C
Cylance Unsafe
Zillya Downloader.Agent.Win32.583924
Sangfor Clean
CrowdStrike win/malicious_confidence_100% (W)
Alibaba Trojan:MSIL/Fsysna.66416423
K7GW Trojan-Downloader ( 005bf4471 )
K7AntiVirus Trojan-Downloader ( 005bf4471 )
huorong Clean
Baidu Clean
VirIT Clean
Paloalto generic.ml
Symantec ML.Attribute.HighConfidence
tehtris Clean
ESET-NOD32 a variant of MSIL/TrojanDownloader.Agent.RNI
APEX Malicious
Avast Win32:MalwareX-gen [Trj]
Cynet Clean
Kaspersky HEUR:Trojan.MSIL.Fsysna.gen
BitDefender Gen:Variant.Marsilia.158222
NANO-Antivirus Clean
ViRobot Clean
MicroWorld-eScan Gen:Variant.Marsilia.158222
Tencent Malware.Win32.Gencirc.14247c1c
Sophos Mal/Generic-S
F-Secure Trojan.TR/Dldr.Agent.dcymc
DrWeb Clean
VIPRE Gen:Variant.Marsilia.158222
TrendMicro Clean
McAfeeD ti!BB41AE95F911
Trapmine Clean
CTX exe.trojan.msil
Emsisoft Gen:Variant.Marsilia.158222 (B)
Ikarus Trojan-Downloader.MSIL.Agent
FireEye Gen:Variant.Marsilia.158222
Jiangmin Clean
Webroot Clean
Varist W32/Filecoder.AU.gen!Eldorado
Avira TR/Dldr.Agent.dcymc
Fortinet MSIL/Agent.RNI!tr
Antiy-AVL Clean
Kingsoft MSIL.Trojan.Fsysna.gen
Gridinsoft Malware.Win32.Gen.vl!i
Xcitium Clean
Arcabit Trojan.Marsilia.D26A0E
SUPERAntiSpyware Clean
Microsoft Trojan:Win32/Leonem
Google Detected
AhnLab-V3 Malware/Win32.Generic.C1020407
Acronis Clean
VBA32 Clean
TACHYON Clean
Malwarebytes Generic.Malware/Suspicious
Panda Trj/Chgt.AD
Zoner Clean
TrendMicro-HouseCall Clean
Rising Downloader.Agent!8.B23 (CLOUD)
Yandex Clean
SentinelOne Clean
MaxSecure Trojan.Malware.318228786.susgen
GData Gen:Variant.Marsilia.158222
AVG Win32:MalwareX-gen [Trj]
DeepInstinct MALICIOUS
alibabacloud Trojan[downloader]:MSIL/Fsysna.gyf
No IRMA results available.