Static | ZeroBOX

PE Compile Time

2102-06-20 09:06:22

PDB Path

CZXZDTGS.pdb

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
}{\x17t\x16f{\x1b 0x00002000 0x00005de8 0x00005e00 7.99253178182
.text 0x00008000 0x0000aa64 0x0000ac00 5.02805463476
.rsrc 0x00014000 0x000005a6 0x00000600 4.11323991998
0x00016000 0x00000010 0x00000200 0.122275881259
.reloc 0x00018000 0x0000000c 0x00000200 0.0980041756627

Resources

Name Offset Size Language Sub-language File type
RT_VERSION 0x000140a0 0x0000031c LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_MANIFEST 0x000143bc 0x000001ea LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with CRLF line terminators

Imports

Library mscoree.dll:
0x416000 _CorExeMain

!This program cannot be run in DOS mode.
`.rsrc
`.reloc
+k&I^!v
>R V6VE
{ZgprSM
'1p%s=
GXOA0y
"y/*l{v
bc95@R
7NVXg%
:,1qNS6M
P2%FlG
)sQ7EfB
N)W|Fg
Xh,*i"
dxO~\e
CE&TTF<
!-.H5'2D
<LBsZM
qF=o@
Svq_PC
\)bjFa
z]y=z$!
Z|d`s;
rz/SEI
PMIKgCN
mN_yY@}jl
<YvU9
i<KIO_
]/Y[ ad@9s
^g#\t_c
e1huY
vhN:Q|U
jbL9c U
2Z I{5Ya8
\3_ 8:
\3_ 8
2X8f8
@iqa8/
.+6TZ
Z 'gD
S^\Z k
v9Z oH
CZXZDTGS.pdb
_CorExeMain
mscoree.dll
v4.0.30319
#Strings
#Strings
#Schema
(trjg7kLg&WRgHtc5*Du#P$`#
,'66MVq&H2X+$4Ab=hGAa9px#
9*J=3d,_YeXj1/\vT8@nLCy4$
Wo4Hl"^FcQtlHou@Ld<}1L$e'
ak@$__Twev^-t3Ms'M$i2,F@0
<>9__6_0
Task`1
AsyncTaskMethodBuilder`1
TaskAwaiter`1
UInt32
ToInt32
ToInt16
get_UTF8
<Module>
CreateProcessA
GetHINSTANCE
get_ASCII
System.IO
TripleDES
CZXZDTGS
set_IV
tDjIxhFegKVDSAkDEPeSAPzbXjgGb
mscorlib
DownloadStringTaskAsync
ResumeThread
get_CurrentThread
thread
get_IsAttached
AwaitUnsafeOnCompleted
get_IsCompleted
Synchronized
set_IsBackground
GetMethod
distance
CreateInstance
set_Mode
PaddingMode
CryptoStreamMode
CipherMode
get_Message
Invoke
IDisposable
RuntimeFieldHandle
RuntimeTypeHandle
GetTypeFromHandle
Console
get_Module
get_Name
get_FullyQualifiedName
get_FullName
DateTime
WriteLine
Combine
IAsyncStateMachine
SetStateMachine
stateMachine
ValueType
SecurityProtocolType
GetElementType
MethodBase
ApplicationSettingsBase
Dispose
Reverse
Create
EditorBrowsableState
posState
STAThreadAttribute
CompilerGeneratedAttribute
GuidAttribute
GeneratedCodeAttribute
DebuggerNonUserCodeAttribute
DebuggableAttribute
EditorBrowsableAttribute
ComVisibleAttribute
AssemblyTitleAttribute
AsyncStateMachineAttribute
DebuggerStepThroughAttribute
AssemblyTrademarkAttribute
TargetFrameworkAttribute
SuppressIldasmAttribute
DebuggerHiddenAttribute
AssemblyFileVersionAttribute
AssemblyConfigurationAttribute
AssemblyDescriptionAttribute
CompilationRelaxationsAttribute
AssemblyProductAttribute
AssemblyCopyrightAttribute
ConfusedByAttribute
AssemblyCompanyAttribute
RuntimeCompatibilityAttribute
ReadByte
matchByte
prevByte
get_IsAlive
add_AssemblyResolve
CZXZDTGS.exe
inSize
outSize
dwSize
windowSize
dictionarySize
SizeOf
System.Threading
set_Padding
Encoding
IsLogging
System.Runtime.Versioning
FromBase64String
ToBase64String
GetString
get_Length
FlushFinalBlock
get_Task
Marshal
System.ComponentModel
kernel32.dll
ntdll.dll
set_SecurityProtocol
inStream
CryptoStream
outStream
MemoryStream
stream
System
SymmetricAlgorithm
ICryptoTransform
IsLittleEndian
AppDomain
get_CurrentDomain
System.Configuration
System.Globalization
Action
ZwUnmapViewOfSection
System.Reflection
SetException
Intern
MethodInfo
CultureInfo
AsyncTaskMethodBuilder
sender
rangeDecoder
Buffer
ResourceManager
ServicePointManager
Debugger
ResolveEventHandler
System.CodeDom.Compiler
TaskAwaiter
GetAwaiter
BitConverter
.cctor
CreateDecryptor
IntPtr
System.Diagnostics
System.Runtime.InteropServices
System.Runtime.CompilerServices
System.Resources
9\*J=3d\,_YeXj1/\\vT8@nLCy4$.resources
DebuggingModes
CZXZDTGS.Properties
properties
numPosStates
GetBytes
Settings
ResolveEventArgs
get_Ticks
System.Threading.Tasks
Equals
Models
NumBitLevels
numBitLevels
get_Chars
RuntimeHelpers
lpAddress
numTotalBits
numPosBits
numPrevBits
Format
Object
lpflOldProtect
VirtualProtect
flNewProtect
System.Net
op_Explicit
Default
GetResult
SetResult
WebClient
RuntimeEnvironment
get_TickCount
ParameterizedThreadStart
Convert
FailFast
MoveNext
System.Text
GetThreadContext
SetThreadContext
get_Now
VirtualAllocEx
startIndex
InitializeArray
ToArray
set_Key
System.Security.Cryptography
get_Assembly
GetCallingAssembly
GetExecutingAssembly
BlockCopy
ReadProcessMemory
WriteProcessMemory
GetRuntimeDirectory
op_Equality
Confuser.Core 1.6.0+447341964f
WrapNonExceptionThrows
CZXZDTGS
Copyright
2025
$84ab4d8b-2e09-4b5a-a184-c6c219e35d5d
1.0.0.0
.NETFramework,Version=v4.5.2
FrameworkDisplayName
.NET Framework 4.5.2
3System.Resources.Tools.StronglyTypedResourceBuilder
4.0.0.0
KMicrosoft.VisualStudio.Editors.SettingsDesigner.SettingsSingleFileGenerator
11.0.0.0
6Wo4Hl"^FcQtlHou@Ld<}1L$e'+\,'66MVq\&H2X\+$4Ab=hGAa9px#
6(trjg7kLg\&WRgHtc5\*Du#P$`#+ak@$__Twev^-t3Ms'M$i2\,F@0
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<assemblyIdentity version="1.0.0.0" name="MyApplication.app"/>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v2">
<security>
<requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3">
<requestedExecutionLevel level="asInvoker" uiAccess="false"/>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
Comments
CompanyName
FileDescription
CZXZDTGS
FileVersion
1.0.0.0
InternalName
CZXZDTGS.exe
LegalCopyright
Copyright
2025
LegalTrademarks
OriginalFilename
CZXZDTGS.exe
ProductName
CZXZDTGS
ProductVersion
1.0.0.0
Assembly Version
1.0.0.0
Antivirus Signature
Bkav W32.AIDetectMalware.CS
Lionic Clean
Elastic malicious (high confidence)
ClamAV Clean
CMC Clean
CAT-QuickHeal Clean
Skyhigh BehavesLike.Win32.Generic.lh
ALYac Trojan.GenericKD.76307250
Cylance Unsafe
Zillya Clean
Sangfor Suspicious.Win32.Save.a
CrowdStrike win/malicious_confidence_100% (W)
Alibaba Trojan:MSIL/MalwareX.bc225940
K7GW Trojan-Downloader ( 005c66171 )
K7AntiVirus Trojan-Downloader ( 005c66171 )
huorong Clean
Baidu Clean
VirIT Clean
Paloalto generic.ml
Symantec ML.Attribute.HighConfidence
tehtris Clean
ESET-NOD32 a variant of MSIL/TrojanDownloader.Agent.RZB
APEX Malicious
Avast Win32:MalwareX-gen [Drp]
Cynet Clean
Kaspersky HEUR:Trojan.Win32.Generic
BitDefender Trojan.GenericKD.76307250
NANO-Antivirus Clean
ViRobot Clean
MicroWorld-eScan Trojan.GenericKD.76307250
Tencent Msil.Trojan-Downloader.Ader.Gtgl
Sophos Mal/Generic-S
F-Secure Trojan.TR/Dldr.Agent.wvaby
DrWeb Clean
VIPRE Clean
TrendMicro Clean
McAfeeD Real Protect-LS!BE1055358485
Trapmine malicious.high.ml.score
CTX exe.trojan.msil
Emsisoft Trojan.GenericKD.76307250 (B)
Ikarus Trojan-Downloader.MSIL.Agent
GData Trojan.GenericKD.76307250
Jiangmin Clean
Webroot Clean
Varist W32/MSIL_Troj.C.gen!Eldorado
Avira TR/Dldr.Agent.wvaby
Antiy-AVL Trojan/Win32.Agent
Kingsoft malware.kb.c.981
Gridinsoft Malware.Win32.XWorm.tr
Xcitium Clean
Arcabit Trojan.Generic.D48C5B32
SUPERAntiSpyware Clean
ZoneAlarm Clean
Microsoft Trojan:Win32/Egairtigado!rfn
Google Detected
AhnLab-V3 Clean
Acronis Clean
McAfee Artemis!BE1055358485
TACHYON Clean
VBA32 CIL.HeapOverride.Heur
Malwarebytes Generic.Malware/Suspicious
Panda Trj/Chgt.AD
Zoner Clean
TrendMicro-HouseCall TROJ_GEN.R002H07DT25
Rising Downloader.Agent!8.B23 (CLOUD)
Yandex Clean
SentinelOne Static AI - Malicious PE
MaxSecure Trojan.Malware.300983.susgen
Fortinet MSIL/Agent.RZB!tr.dldr
AVG Win32:MalwareX-gen [Drp]
DeepInstinct MALICIOUS
alibabacloud Trojan[dropper]:MSIL/Wacapew.C9nj
No IRMA results available.