Static | ZeroBOX

PE Compile Time

2058-11-30 10:30:41

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x000fec44 0x000fee00 2.59177506239
.rsrc 0x00102000 0x000005f0 0x00000600 4.2329628933
.reloc 0x00104000 0x0000000c 0x00000200 0.0815394123432

Resources

Name Offset Size Language Sub-language File type
RT_VERSION 0x00102090 0x00000360 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_MANIFEST 0x00102400 0x000001ea LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with CRLF line terminators

Imports

Library mscoree.dll:
0x402000 _CorExeMain

!This program cannot be run in DOS mode.
`.rsrc
@.reloc
v4.0.30319
#Strings
BaB2Kmnk41
BitVector32
ConsoleApp192
get_UTF8
<Module>
kS4MZiK62a
iROSVVbvfb
mscorlib
System.Collections.Specialized
Append
GetMethod
CompileAssemblyFromSource
Invoke
GetType
MethodBase
GuidAttribute
DebuggableAttribute
ComVisibleAttribute
AssemblyTitleAttribute
AssemblyTrademarkAttribute
TargetFrameworkAttribute
AssemblyFileVersionAttribute
AssemblyConfigurationAttribute
AssemblyDescriptionAttribute
CompilationRelaxationsAttribute
AssemblyProductAttribute
AssemblyCopyrightAttribute
AssemblyCompanyAttribute
RuntimeCompatibilityAttribute
TmpFolder.exe
Encoding
System.Runtime.Versioning
FromBase64String
ToString
GetString
get_Length
GBmfuNONuj
Program
System
System.Reflection
StringCollection
SMxA0QJo1o
MethodInfo
Microsoft.CSharp
CSharpCodeProvider
CodeDomProvider
StringBuilder
TmpFolder
System.CodeDom.Compiler
.cctor
n5Dh00mp5s
System.Diagnostics
System.Runtime.InteropServices
System.Runtime.CompilerServices
DebuggingModes
get_ReferencedAssemblies
StringSplitOptions
get_Chars
CompilerParameters
CompilerResults
vTPjF7i5Pt
MJV2hCDpTt
Object
Convert
System.Text
get_CompiledAssembly
set_GenerateInMemory
WrapNonExceptionThrows
TmpFolder
Copyright
TmpFolder 2025
$8501d172-1ebb-4613-87a4-eef7f2546a27
7.4.4.2
.NETFramework,Version=v4.5
FrameworkDisplayName
.NET Framework 4.5
_CorExeMain
mscoree.dll
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<assemblyIdentity version="1.0.0.0" name="MyApplication.app"/>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v2">
<security>
<requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3">
<requestedExecutionLevel level="asInvoker" uiAccess="false"/>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
220, 177, 206, 204, 161, 103, 140, 238, 187, 167, 229, 174, 180, 099, 109, 192, 225, 199, 172, 221, 155, 165, 242, 229, 194, 192, 186, 183, 160, 176, 245, 188, 251, 217, 234, 211, 235, 213, 197, 197, 156, 112, 002, 206, 160, 178, 157, 146, 152, 169, 240, 178, 219, 192, 142, 150, 208, 207, 118, 128, 130, 196, 233, 216, 185, 191, 106, 217, 210, 183, 005, 183, 247, 149, 198, 209, 237, 227, 184, 244, 241, 145, 211, 241, 211, 209, 165, 222, 178, 128, 223, 173, 233, 185, 192, 170, 219, 147, 069, 122, 130, 086, 227, 225, 170, 193, 176, 230, 118, 180, 002, 176, 251, 205, 212, 121, 223, 216, 173, 247, 252, 128, 218, 229, 208, 191, 192, 003, 217, 109, 224, 172, 233, 090, 100, 189, 114, 095, 085, 141, 146, 105, 224, 219, 174, 200, 165, 244, 184, 094, 239, 177, 240, 198, 213, 183, 237, 206, 105, 234, 244, 209, 164, 207, 190, 217, 205, 001, 204, 166, 007, 210, 210, 171, 187, 147, 219, 194, 151, 206, 212, 172, 149, 175, 176, 195, 145, 241, 194, 091, 240, 170, 239, 194, 215, 184, 159, 161, 083, 136, 163, 122, 161, 154, 198,
186, 183, 216, 210, 159, 180, 103, 217, 180, 159
186, 183, 216, 210, 159, 180, 103, 184, 183, 165, 229, 111, 221, 194, 207
186, 163, 217, 180, 159, 179, 168, 184, 177, 167, 249
186, 178, 198, 208, 174, 142, 158, 233
Zz1jWzZCM25AKnY2bUlVPF5NLGM=
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
Comments
TmpFolder
CompanyName
TmpFolder
FileDescription
TmpFolder
FileVersion
7.4.4.2
InternalName
TmpFolder.exe
LegalCopyright
Copyright
TmpFolder 2025
LegalTrademarks
TmpFolder
OriginalFilename
TmpFolder.exe
ProductName
TmpFolder
ProductVersion
7.4.4.2
Assembly Version
7.4.4.2
Antivirus Signature
Bkav W32.AIDetectMalware.CS
Lionic Trojan.Win32.XWorm.m!c
tehtris Clean
ClamAV Clean
CMC Clean
CAT-QuickHeal Clean
Skyhigh Clean
ALYac Gen:Variant.Zusy.582328
Cylance Unsafe
Zillya Clean
Sangfor Suspicious.Win32.Save.a
K7AntiVirus Clean
Alibaba Backdoor:MSIL/XWorm.c202af1c
K7GW Clean
Cybereason Clean
huorong Trojan/MSIL.Agent.wi
Baidu Clean
VirIT Clean
Paloalto Clean
Symantec ML.Attribute.HighConfidence
Elastic malicious (high confidence)
ESET-NOD32 a variant of MSIL/TrojanDownloader.Agent.RSL
APEX Malicious
Avast Win32:PWSX-gen [Trj]
Cynet Clean
Kaspersky HEUR:Backdoor.MSIL.XWorm.gen
BitDefender Gen:Variant.Zusy.582328
NANO-Antivirus Clean
ViRobot Trojan.Win.Z.Zusy.1046528
MicroWorld-eScan Gen:Variant.Zusy.582328
Tencent Msil.Trojan-Downloader.Ader.Dkjl
TACHYON Clean
Sophos Troj/MSIL-THB
F-Secure Heuristic.HEUR/AGEN.1306794
DrWeb Trojan.PackedNET.3243
VIPRE Gen:Variant.Zusy.582328
TrendMicro Backdoor.Win32.XWORM.YXFBXZ
McAfeeD ti!6CCF42040462
Trapmine Clean
CTX exe.trojan.msil
Emsisoft Gen:Variant.Zusy.582328 (B)
Ikarus Clean
FireEye Generic.mg.8d283dc5f077e090
WebrootD Win.Infostealer.Lumma
Jiangmin Clean
Webroot Win.Infostealer.Lumma
Varist Clean
Avira HEUR/AGEN.1306794
Fortinet MSIL/Agent.RSL!tr.dldr
Antiy-AVL Clean
Kingsoft MSIL.Backdoor.XWorm.gen
Gridinsoft Malware.Win32.XWorm.tr
Xcitium Clean
Arcabit Trojan.Zusy.D8E2B8
SUPERAntiSpyware Clean
ZoneAlarm UDS:DangerousObject.Multi.Generic
Microsoft Trojan:Win32/AgentTesla!ml
Google Detected
AhnLab-V3 Trojan/Win.Generic.C5731580
Acronis Clean
McAfee Artemis!8D283DC5F077
MAX Clean
VBA32 Clean
Malwarebytes Trojan.Downloader.MSIL
Panda Trj/Chgt.AD
Zoner Clean
TrendMicro-HouseCall Clean
Rising Malware.Obfus/MSIL@AI.100 (RDM.MSIL2:dFFe7/qpYdyfmIHr9ddEjQ)
Yandex Clean
SentinelOne Static AI - Malicious PE
MaxSecure Trojan.Malware.300983.susgen
GData Gen:Variant.Zusy.582328
AVG Win32:PWSX-gen [Trj]
DeepInstinct MALICIOUS
CrowdStrike win/malicious_confidence_100% (W)
alibabacloud Clean
No IRMA results available.