Static | ZeroBOX

PE Compile Time

2103-07-14 09:30:07

PDB Path

VXCX.pdb

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
:(= (K0 0x00002000 0x00006080 0x00006200 7.99270038948
.text 0x0000a000 0x0000aa94 0x0000ac00 5.03427035067
.rsrc 0x00016000 0x00000586 0x00000600 4.02738930179
0x00018000 0x00000010 0x00000200 0.118369631259
.reloc 0x0001a000 0x0000000c 0x00000200 0.0980041756627

Resources

Name Offset Size Language Sub-language File type
RT_VERSION 0x000160a0 0x000002fc LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_MANIFEST 0x0001639c 0x000001ea LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with CRLF line terminators

Imports

Library mscoree.dll:
0x418000 _CorExeMain

!This program cannot be run in DOS mode.
`.rsrc
`.reloc
=~#y*F
q^%rf
A"_R;]
/AOS/`Z
=Qr<oY/
zkBD,^
RM+M{
+nA+/9
)HCS&9Z
:\i(/@
`~Xq e
V8ACVp"x
y\8*g.
:c\'re
u70Xoq^
>kz'X8
Fse;(tB
[7uB!L
2?R%qUH
XY~Wx"
Ub(QC?
W>CLD79h
'$ZauL
FgsUHO
n6Qg~$5
U Kh;'
?M-g:a
Qsa}fU
mjLZ4m[
*^7!=.IK
)g|l8O
WQVRfj
{f\Ps1
\Ka&l/
J7qf@`
Zw9c5<
^-@!CY3
fUGO}W
4{=[KRv
qOKQQKN
O>/;`Zr
,P-Z `D
/h;Z cR
4lN'Z
[$WWZ t
Q:uQZ %X
+ORZ "
c3JIZ
`qPZ `
z_.a8-
].YZ 6
VXCX.pdb
_CorExeMain
mscoree.dll
v4.0.30319
#Strings
#Strings
#Schema
Wq<h'@yZO&,8pI*h\/gArIY7(
B!rmB\@L{wk5xLTCtuW\g%!{)
<>9__6_0
Task`1
AsyncTaskMethodBuilder`1
TaskAwaiter`1
UInt32
ToInt32
ToInt16
+i0n@tHmt9$A#G_BznWnLJ,L6
get_UTF8
<Module>
CreateProcessA
Ji~9eOOscC)%Wx@%^Vv<1!nID
GetHINSTANCE
cMFRsWUeXmrVxCgOrVPCcGqMYqJF
PnGuuAD=XYIr!jO27MU<KH'&G
get_ASCII
System.IO
TripleDES
set_IV
mscorlib
DownloadStringTaskAsync
ResumeThread
get_CurrentThread
thread
get_IsAttached
AwaitUnsafeOnCompleted
get_IsCompleted
Synchronized
set_IsBackground
GetMethod
distance
CreateInstance
set_Mode
PaddingMode
CryptoStreamMode
CipherMode
get_Message
Invoke
IDisposable
RuntimeFieldHandle
RuntimeTypeHandle
GetTypeFromHandle
Console
get_Module
get_Name
get_FullyQualifiedName
get_FullName
DateTime
WriteLine
Combine
IAsyncStateMachine
SetStateMachine
stateMachine
ValueType
SecurityProtocolType
GetElementType
MethodBase
ApplicationSettingsBase
Dispose
Reverse
Create
EditorBrowsableState
posState
STAThreadAttribute
CompilerGeneratedAttribute
GuidAttribute
GeneratedCodeAttribute
DebuggerNonUserCodeAttribute
DebuggableAttribute
EditorBrowsableAttribute
ComVisibleAttribute
AssemblyTitleAttribute
AsyncStateMachineAttribute
DebuggerStepThroughAttribute
AssemblyTrademarkAttribute
TargetFrameworkAttribute
SuppressIldasmAttribute
DebuggerHiddenAttribute
AssemblyFileVersionAttribute
AssemblyConfigurationAttribute
AssemblyDescriptionAttribute
CompilationRelaxationsAttribute
AssemblyProductAttribute
AssemblyCopyrightAttribute
ConfusedByAttribute
AssemblyCompanyAttribute
RuntimeCompatibilityAttribute
ReadByte
matchByte
prevByte
get_IsAlive
add_AssemblyResolve
VXCX.exe
inSize
outSize
dwSize
windowSize
dictionarySize
SizeOf
System.Threading
set_Padding
Encoding
IsLogging
System.Runtime.Versioning
FromBase64String
ToBase64String
GetString
get_Length
FlushFinalBlock
get_Task
Marshal
System.ComponentModel
kernel32.dll
ntdll.dll
set_SecurityProtocol
inStream
CryptoStream
outStream
MemoryStream
stream
System
SymmetricAlgorithm
ICryptoTransform
IsLittleEndian
AppDomain
get_CurrentDomain
System.Configuration
System.Globalization
Action
ZwUnmapViewOfSection
System.Reflection
SetException
Intern
MethodInfo
CultureInfo
AsyncTaskMethodBuilder
sender
rangeDecoder
Buffer
ResourceManager
ServicePointManager
Debugger
ResolveEventHandler
System.CodeDom.Compiler
TaskAwaiter
GetAwaiter
BitConverter
.cctor
CreateDecryptor
IntPtr
System.Diagnostics
System.Runtime.InteropServices
System.Runtime.CompilerServices
System.Resources
Wq<h'@yZO\&\,8pI\*h\\/gArIY7(.resources
DebuggingModes
VXCX.Properties
properties
numPosStates
GetBytes
Settings
ResolveEventArgs
get_Ticks
System.Threading.Tasks
Equals
Models
NumBitLevels
numBitLevels
get_Chars
RuntimeHelpers
lpAddress
numTotalBits
numPosBits
numPrevBits
Format
Object
lpflOldProtect
VirtualProtect
flNewProtect
System.Net
op_Explicit
Default
GetResult
SetResult
WebClient
RuntimeEnvironment
get_TickCount
ParameterizedThreadStart
Convert
FailFast
MoveNext
System.Text
GetThreadContext
SetThreadContext
get_Now
VirtualAllocEx
startIndex
InitializeArray
ToArray
set_Key
System.Security.Cryptography
get_Assembly
GetCallingAssembly
GetExecutingAssembly
BlockCopy
ReadProcessMemory
WriteProcessMemory
GetRuntimeDirectory
op_Equality
Confuser.Core 1.6.0+447341964f
WrapNonExceptionThrows
Copyright
2025
$5535a97d-114a-4b60-bfb9-c3791e54eede
1.0.0.0
.NETFramework,Version=v4.5.2
FrameworkDisplayName
.NET Framework 4.5.2
3System.Resources.Tools.StronglyTypedResourceBuilder
4.0.0.0
KMicrosoft.VisualStudio.Editors.SettingsDesigner.SettingsSingleFileGenerator
11.0.0.0
7\+i0n@tHmt9$A#G_BznWnLJ\,L6+B!rmB\\@L{wk5xLTCtuW\\g%!{)
4PnGuuAD=XYIr!jO27MU<KH'\&G+Ji~9eOOscC)%Wx@%^Vv<1!nID
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<assemblyIdentity version="1.0.0.0" name="MyApplication.app"/>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v2">
<security>
<requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3">
<requestedExecutionLevel level="asInvoker" uiAccess="false"/>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
Comments
CompanyName
FileDescription
FileVersion
1.0.0.0
InternalName
VXCX.exe
LegalCopyright
Copyright
2025
LegalTrademarks
OriginalFilename
VXCX.exe
ProductName
ProductVersion
1.0.0.0
Assembly Version
1.0.0.0
Antivirus Signature
Bkav W32.AIDetectMalware.CS
Lionic Clean
Elastic malicious (high confidence)
ClamAV Clean
CMC Clean
CAT-QuickHeal cld.trojan.generic
Skyhigh BehavesLike.Win32.Generic.lh
ALYac Gen:Variant.MSILHeracles.222889
Cylance Unsafe
Zillya Clean
Sangfor Suspicious.Win32.Save.a
CrowdStrike win/malicious_confidence_100% (W)
Alibaba Trojan:MSIL/MalwareX.bc225940
K7GW Trojan-Downloader ( 005c66171 )
K7AntiVirus Trojan-Downloader ( 005c66171 )
huorong Clean
Baidu Clean
VirIT Clean
Paloalto generic.ml
Symantec ML.Attribute.HighConfidence
tehtris Clean
ESET-NOD32 a variant of MSIL/TrojanDownloader.Agent.RZB
APEX Malicious
Avast Win32:MalwareX-gen [Drp]
Cynet Clean
Kaspersky HEUR:Trojan.Win32.Generic
BitDefender Gen:Variant.MSILHeracles.222889
NANO-Antivirus Clean
ViRobot Clean
MicroWorld-eScan Gen:Variant.MSILHeracles.222889
Tencent Msil.Trojan-Downloader.Ader.Ltgl
Sophos Mal/Generic-S
F-Secure Trojan.TR/Dldr.Agent.lesyh
DrWeb Clean
VIPRE Clean
TrendMicro Clean
McAfeeD Real Protect-LS!A82A8D7CDFA5
Trapmine malicious.high.ml.score
CTX exe.trojan.msil
Emsisoft Gen:Variant.MSILHeracles.222889 (B)
Ikarus Trojan-Downloader.MSIL.Agent
GData Gen:Variant.MSILHeracles.222889
Jiangmin Clean
Webroot Clean
Varist W32/MSIL_Troj.C.gen!Eldorado
Avira TR/Dldr.Agent.lesyh
Antiy-AVL GrayWare/Win32.Wacapew
Kingsoft malware.kb.c.997
Gridinsoft Malware.Win32.Gen.tr
Xcitium Clean
Arcabit Trojan.MSILHeracles.D366A9
SUPERAntiSpyware Clean
ZoneAlarm Clean
Microsoft Trojan:Win32/Wacatac.B!ml
Google Detected
AhnLab-V3 Clean
Acronis Clean
McAfee Artemis!A82A8D7CDFA5
TACHYON Clean
VBA32 CIL.HeapOverride.Heur
Malwarebytes Generic.Malware/Suspicious
Panda Trj/Chgt.AD
Zoner Clean
TrendMicro-HouseCall TROJ_GEN.R014H07DT25
Rising Downloader.Agent!8.B23 (CLOUD)
Yandex Clean
SentinelOne Static AI - Malicious PE
MaxSecure Trojan.Malware.300983.susgen
Fortinet MSIL/Agent.RZB!tr.dldr
AVG Win32:MalwareX-gen [Drp]
DeepInstinct MALICIOUS
alibabacloud Trojan[dropper]:MSIL/Wacapew.C9nj
No IRMA results available.