Static | ZeroBOX

PE Compile Time

2021-05-11 07:15:17

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x000762f4 0x00076400 7.98302253315
.rsrc 0x0007a000 0x0001109c 0x00011200 3.71177759618
.reloc 0x0008c000 0x0000000c 0x00000200 0.101910425663

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x0007a130 0x00010828 LANG_NEUTRAL SUBLANG_NEUTRAL dBase IV DBT, blocks size 0, block length 2048, next free block index 40, next free block 0, next used block 0
RT_GROUP_ICON 0x0008a958 0x00000014 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_VERSION 0x0008a96c 0x0000057c LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_MANIFEST 0x0008aee8 0x000001b4 LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with very long lines, with no line terminators

Imports

Library mscoree.dll:
0x402000 _CorExeMain

!This program cannot be run in DOS mode.
`.rsrc
@.reloc
Yfefeffefefe
Xffefeeffea
Yfefeffeeffea
Xfeffefefe
affeeffefeefa
Yfeffeefeffe
Xffeeffefehah
Yffeeffefehah
tH%?a
XY d*Fa
afefeffeeffea
Yfeffefefe_:
O9@X
Yfefeffeefa
v("Ha
=!fefeffeef
feffeefef
feffeefef
feffefefe
afefefeffefe
9feffeefefef
fefeffeefef
ffeeffefe
fefefeffe
=!fefefeffe
afeffeefef
fefeffeefYa8
dfefefefeffeY
=feffefefeXa8
feffefefeY
feffefefea
t~gfefefeffe(J
|*ffefeeffea(U
v4.0.30319
#Strings
Iephii
Iephii.exe
<Module>
Settings
Dqvosdkzw.Properties
ApplicationSettingsBase
System.Configuration
System
Connection
Dqvosdkzw.Polices
Object
mscorlib
PropertyGetterResolver
IssuerAttrExporter
Consumer
ListenerDic
Dqvosdkzw.Dictionaries
Iephii.Writers
Decorator
Dqvosdkzw.Exporters
Iephii.Database
Record
Iephii.Descriptors
RoleInterpreterID
Iephii.Identifiers
System.Windows.Forms
TestsInterpreterID
CreatorStubWriter
StructMessageDispatcher
Iephii.Dispatcher
TokenizerStateStrategy
Iephii.Strategies
CacheItemPriority
Exporter
RequestValueDescriptor
Authentication
Iephii.Specifications
MockInterpreterID
InterceptorExceptionContainer
Callback
ParamAttrPolicy
TemplateStubWriter
ParameterAttrExporter
InstanceAttrExporter
.cctor
SettingsBase
Synchronized
m_Product
m_Factory
m_Getter
m_Rules
m_Exception
row_first
Thread
System.Threading
get_CurrentThread
get_ManagedThreadId
CreateConnection
t3f35e2pwfmqpyd4d9a8efr9brylape3Xw0a
Boolean
CollectConnection
FillConnection
CancelConnection
NotSupportedException
reader
message
advisor
row_ident
SearchConnection
IncludeConnection
m_Interpreter
m_System
m_Bridge
m_Page
m_Publisher
next_ident
AddConnection
CompareConnection
SetConnection
ConnectConnection
CheckConnection
_Token
IContainer
System.ComponentModel
ResolveConnection
reference
EventArgs
visitor
MessageBox
DialogResult
String
Dispose
isasset
IDisposable
RemoveConnection
System.Drawing
Single
set_ClientSize
Control
set_Name
set_Text
EventHandler
IntPtr
add_Load
ResumeLayout
SuspendLayout
ContainerControl
set_AutoScaleDimensions
set_AutoScaleMode
AutoScaleMode
WriteConnection
Assembly
System.Reflection
MemoryStream
System.IO
Stream
GetExecutingAssembly
GetManifestResourceNames
Func`2
Enumerable
System.Linq
System.Core
SingleOrDefault
IEnumerable`1
System.Collections.Generic
GetManifestResourceStream
CopyTo
ToArray
UpdateConnection
BufferedStream
GZipStream
System.IO.Compression
CompressionMode
initializer
RunConnection
Contains
InitConnection
WebRequest
System.Net
ConvertValue
Newtonsoft.Json
Create
set_Method
Concat
Encoding
System.Text
get_ASCII
GetBytes
get_Headers
WebHeaderCollection
NameValueCollection
System.Collections.Specialized
set_ContentType
set_ContentLength
GetRequestStream
JsonConvert
SerializeObject
PrepareConnection
AppDomain
get_CurrentDomain
ResolveEventHandler
add_AssemblyResolve
Application
EnableVisualStyles
SetCompatibleTextRenderingDefault
InvokeConnection
ResolveEventArgs
m_Observer
status
m_Wrapper
m_Container
_Database
_Printer
_Composer
Dictionary`2
strategy
dispatcher
StackFrame
System.Diagnostics
StackTrace
MethodBase
GetFrame
GetMethod
MemberInfo
get_DeclaringType
RuntimeMethodHandle
GetTypeFromHandle
RuntimeTypeHandle
SetupConnection
mean_ident
Monitor
TryGetValue
RateConnection
var1amount
overridecfg
StringBuilder
UInt16
UInt32
AssemblyName
GetCallingAssembly
Append
ToString
set_Position
get_Unicode
GetString
Intern
set_Item
get_Count
PublishConnection
GetName
get_FullName
DefineConnection
GetPublicKeyToken
DisableConnection
start_attr
get_Assembly
InsertConnection
caller_Z
value__
m_Pool
_Customer
PatchConnection
ListConnection
CalculateConnection
ConcatConnection
EndOfStreamException
FindConnection
offsetlast
ReadByte
ChangeConnection
CalcConnection
indexOf_res
ArgumentOutOfRangeException
Buffer
BlockCopy
RegisterConnection
UInt64
List`1
AddRange
get_Name
get_Item
MoveConnection
AssetConnection
CustomizeConnection
get_MetadataToken
_Collection
m_Predicate
AwakeConnection
ComputeConnection
GetConnection
instance_counter
columnvis
PrintConnection
next_item
DeleteConnection
var1_high
second
CallConnection
StartConnection
MapConnection
VisitConnection
VerifyConnection
TestConnection
AssemblyFileVersionAttribute
CompilationRelaxationsAttribute
System.Runtime.CompilerServices
GuidAttribute
System.Runtime.InteropServices
ComVisibleAttribute
AssemblyTrademarkAttribute
AssemblyCopyrightAttribute
AssemblyProductAttribute
AssemblyCompanyAttribute
AssemblyConfigurationAttribute
AssemblyDescriptionAttribute
AssemblyTitleAttribute
RuntimeCompatibilityAttribute
TargetFrameworkAttribute
System.Runtime.Versioning
CompilerGeneratedAttribute
GeneratedCodeAttribute
System.CodeDom.Compiler
DebuggerHiddenAttribute
STAThreadAttribute
Iephii.Identifiers.RoleInterpreterID.resources
Dqvosdkzw.Newtonsoft.Json.dll
Dqvosdkzw.Resources.Seledpcrooo.dll
Dqvosdkzw.Resources.Voeboipvelbpsm.dll
5.5.0.7
$9e22982b-1704-477e-83f0-1672cdf69bae
d
<lightshot
<Skillbrains
<lightshot Setup
WrapNonExceptionThrows
.NETFramework,Version=v4.0
FrameworkDisplayName
.NET Framework 4
KMicrosoft.VisualStudio.Editors.SettingsDesigner.SettingsSingleFileGenerator
16.8.1.0
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
PADPADP
5"rot#}
7^?bpr
3ji TGe
i+|n5
Jc%5XR
~*0:/%6
f!|?4M(c:
u&Lg_6
WHhbM5
Ur~vgd
?=-Hkw
?G]fU,
;kwrh6
dWcD !
Q\_3n`3r
rkBrkD
Bn2$7)ro
{_ZOHn
3|HvHZ
m?* rH~2
,s$90h
j\y[qG
,V[1_=
LH9WQ
zYl<i9
j8 mkD
4U%H7
X<M=ExF
lpD5I]
J:Vi%RM-
K[gW{W|Pg
b:?Q?M
w8H~ZoFr
PSuc5V
Bbt-p\BI
4t>{O^
EUT:?"fL^\
x"Bt.
i?u8Y
y9[uM
6C%.'ms
sRC_QQ
s}g$OU
\{FY9?
R1zo>!
V,maN=
Fm:QFx
V<8|;H
MIz)Eo4A
JiQva;
V@'<MB
@'=]Bc[
;>ue29
ar@D&$H
)Dly^q.
QL%lBv
CTCw>(FS
e{>:s
Vms'+,
"@M9;o
_<xZkb
=^e]Z[
bOQd:?
tJJB}Hc
1fz0L^
K8y~X&
qvavk9r
xS<_=>QXPmj
%Z!Q,$
RlR,_ZT/
Dm9g^\
snc`O[
s flBsV
qF+U:,"
0yUq.*H/
Rn*^WaG
nKL|-
hbp"+2qF
@&\bo_
vMX>Qv_
w^*V*l
k#O!\u{c
op@}O}
tkuq]w
G'UMZ6U;v
tMlLz3
cc?Ls%
"-jXyz(
'(RnMd
>Z_zWt
jjT}:%
oY9UE3
I#BLwd
)LU$8:
i{~6|/U
BqQZyZ
~wi~0J
B8Ag|3
' n|"o
D"NYYm
g`im3C
>}E[{d4
Vxw- a
g^[*D,^
9#>H>l
/'@&/i
N2Yh1"Qw
1~8)FR
j;/pG~
B3v|#h
a$.D_
g3$AL
]K#)I;
Hp+^-;
P$Y-L$
{CNE.~
+>0pW*
o;Q>mP
mlo<
O#F-sp
,d0=W
-?]OI"
>c$V.;c
C>oR>{X
u0 b/
$&M655
>6WXX`,
/w8Re"R
Pic]:T\J
q1\O-d
.N6:gjX,R
}S#[b?f[b
;umhan=
@wSP|-
V+=3%e
IGp+{'
w+aAcX
(].bqz
F(LllR(8K
s[T_Br
Cb8:,^
CxbyK.U
I'aUV3
Ha_$zZq
&m`o'a
'10asMD
Pjpw>mH
sv$a:t
7CK~@s
N[Db'e
kT.'<!a
#]/C}w
Wqm{=@
#92}7U
xMB,=I
(I>K2dD`
]Pij9W
]iz|Ni
4Q;IsS
aVWOEN
/F2u3H
3MI3=K
4Gv94m
$~W:'K
O3Oa{Sf
lb(K5
+<oo)j
EjKu?X
[Pt[/D
ekm\`9qSn
2sdG|>
y+N0S|
g)}']*
+=cE p
m5!fz?
/deJ?
1/p<Jj
Z:rcmP
%R0}sm
m~iMKH[}>
o0S<9\{
1S|<G[
[y)>_h
xAXic'
e5hU|)
+X=9?Oe
7>Dng]a
&h?jE\
.W~j|]L
.0T*a
gJR3`v
\$MB^N
i}+ZV.
zyle(x
zO~ p2
3n]<Pq
5e*rX$
&WN#{G2
d3%{K(o
w;(o,
'^8yX[`>
l~sI-<
(plTS-t
8GLOM}
Eor[LoW}
~32!C{
w_U)iv*
9~cf Y
?w>pwI
p|_ssZ
Sj~B9{|
!mc!=sv
OCo2S!
n~?c>
7OH9o:
=9Ny>~
@@F
%f+.-Nh
{M>7]W2
s.yV5
I;:iG'
/V5l.V5\Q
+V5l+V5
[@?,EG
/EG(o-
qtVRn%
5L0::A
6z=L^m
ob^4Q?
6v?:x7
zy>F'a
-i[zo9e
Z2avR#}
'?x!7
pO=N'
xp'P#Y
P#Et=x1P#%t
x)P#et
Eh=P#n
Xn&nb1L
h+mTC[iK
.}7{:
%Ee%cK
j=:0<0>
?p$$$6'%
;<o[Og
ioqW{.u
^V'@+J
sf3&{T,(G
NgY~~fVqqan~nifIvVQ^Ani
Fjzv^.
wl}n$[r
"giQqiNan
+F`YV^i^~yQv
uEeT@u
;[6AQW
-}iO_4
g%=Wl:
^q;{q(l
ec]Mn}
|KCD"z><
=!cW6r
F+&IcuQ
j=s*>t
o\rk!V]b
I/9Z0GC
ht[_*NPm
B(VgY7
)cgqq+
MWg5KV
9P{C42
(,XTC?V
,OypMs
w*qB./M
56lb>)7
$O!,xP
^@Gx?<
\Tbh3oD#
*}]7M'
P6 h$=
'C'Tm&
`&c*"
Tgo)UC
LT#e|@
,C|8*9
^`/Hv
`^30@2U
%~&&V84
v&w8YI
y<u{kl
'^(_P>!
'pz~1~
9.`sRT
r)>_WG
^wAe/5?(
N9%eMFXc
nvR{E-8
Nd[|MI[9
*Y",PQ
7GkxR+~
+VO9M7
b{V}`}
7VglT3
B/ps|$
4k/[6[
jihk-
LK{ng+d
{0>y!~
UJG5I1
Yvnbx_W_nO
3@'D@7
bK_ok
Gi8WHjae
`qPf+76
N3z LGj
L><9t~
tl~fn!
@ET)WV
+fvi}}
p1FcFC
C981cH[
Swk/;w
pd3v9i
bx)4pT
>dPy8R6N
Na(DlW3
L9Bkb;LQ5
||$.+k
Wf/l}]
dO(ORg
6z1deT
ha<>KK
_(w1Vp
l~=mml
]m`y>;N
|}9(Mo
mpv}%w9
MONHNfe
,>-Z>m
XlyZXH
C#Q/7<)?TyG\2
LuY*^t
1%[(Vf
3s=N`.e
t1~$D7
=$PR)j
` _WUQ
L4X'6o
9QSxc}
]Rs]=IB
97J_V:
aLE!5y
vA7C x
m_48iTZ
{$`5VY
\z(H<8]
(-4;[4
1} a)T
-i"_]:
0'uVl[z%
ziq0L
oLl^o.
V}}}8
GGe\<g
y ~\Yq
OI<,5=|f
'lW-k+l
-IY:v&u
26GVm=
u)3}/o
S`QpNa
7TXKS9
E0,8+NX
ppS0pD|
xs5Wo~
J>C&o
?6cb_Rhy
&M)NY
VF\F{
J7/P@;
yzmqySF
yp/e`H=
T~fOMu
cFdsF_x\n
7/uv[
%`"\I_W
F"3UsE
N#F5x*
D[`IaK
bgM_/0
;i3~(Y
`fs5<g
etnc7b
m[}[Vn
oub(kI
84|X8q
drS/sE
Ju$rJw~k_S8@
E=W2h}
Nb9u@m
'r/En4
trN:T/
zTXm-qv+k<N
\~?nYmk
khrql{T
?@O*r@Z
}jNl6N
Y8+Q3Qh
lh8mk0<
;o_nl2r
#XQI6(
jyzDXF
kP,G%;
KewIfD
dH.}J#oD
6^yxam<+s
q<P}Z1d
.p1q+c
psoyo6
[)4|ysG
r;{P{C !ln
MS2SfM@9(ZMC2R4
|0Bq,
@ $@TpR
~)|7\j
~dL@~O
1QJ=A~8x
`FMU_a
JT~vB/
~R=4=]
Su7`9T!
$[f|E}
1HCan_J
ai+:l}
_Dc`UKu
IzIu9RJ
4Hs-J3
#)-![:(^
j@39++
4QIgJ)
DASe*H
!n;|&'6
1X?IZ?
0z~!!7
N7mTpWg
!NpRsut
lS0jZQ
0YjB9(L[h
>Scwnc
fp-nMb}
DuTo1W
[4D&Z<
ZL.>>k
dSB\GOu
{Me]ST
?SjtV6
$0RI39
/1SC0SC8
.xx0I+
fSO%e3
~ W|`+
[R-xV:d
UA@&aI&,
iqUm*Y:6D
X~O;Yhm#
u<3sW;
}!aDfv
G8;(nq
WI}3.m
P)E/@k
`?EA)`
G!W;z4
6@TG5Ct6
m2cf8n
LD`XY)
pWy<Ko}
PKEXS*
u9Lv$?
8hnQJ
O@}qdSTG
Az9,lc
><M&":
>1oGl*
uk.j#G
p]'71v
r*l'j-
8~/^~5~
i@N(>Q
F~|y-r
a4GGD
CjEso&
6^BO&Q
vS3nnj
mm1fpJ
TV)>7i
Ldcjp ;
-\"W#:o
)ZP68C
O@wR@1
H4=4,;)
|C#iZ[
|w{q!V
0R~$iR
W@@;Fd
<8y15^P)
t<05b+
Ck3`X*
j"aJHx
$A&NxK
A9El7K
`ot2LL#
uAVb]X'
_J! St
U^~U)/G
N2B?3Nz
4\Hius{n_X
nx-T!'
n:<8g;N~
ul9x"m\
5;,s0aRU
8eg?@u:
;74U^-;X
h|UN+o:
3^gD>|
52?{Bc
7F)`C0
P>^%}oPb
)2Wf(K
^5?Zg{2}
%q%wOm+O
/"uLe'
,uy7@8
mFr>+V(
FFwC~i
7B?uy>\
zc?'9G
so-{QE
y6f;5}
I(Ol2,;p3
wU@<L[
W`(=rm?
ajz{I:9
OgtX
+8Nfuc
aEf8;
w-39.hr
U*_,Rr@$
?g~nD>a
r\S`:(
Nh%ijf<L
0+s@&NI
\J$/]V
X~h{:U-
S|cw3v
)<)bOW
~];IiI
J8?ygW
MQV\d5
y0n{D6bW
/ERa;N
4&52Rl
IF]&heq
?$`}hy
gY(MAK
UD,H/f
V9FsU@,
MKS[-.K
!-c0&,
/f3%{E+:[A
Z/Q.q,xuK
DPH}\
e)KXh@
]o2M T
snZ`:?e
gR`*=:
wbaR|WRn2
aMRt**
!&AsOF
OIs~@.
HX~>/}
IL9cDI
uM;zQK|q
>sGWf}
w\f|S%
<q=Pz>
C"@(s\
Ur%w`LD
v,*b&h=
>hrF1o
#OO+At
F'gPiY
dmRcE;i
]X:-cB~?);
)|Iuw!K
Q_4L^P
|S? D?
USb u|
|36&\$
^1h!3^,
?7xAWI=
Z9uoN"
sy*f 2
;=rjCY
rDS21r
L6NZdb
UXO^nl
q=nfcD
@+;:Jj
1jK{ v
u\}'{$
>s7gwT
;2KFSs
5I9pJf\
Ch>&fR
026U~4
\pv]8> R#\
1}sE|~
PvE%,
)MHWXq\Q
3;2lkf
jb?aOY
i{V1|V
[DbC%(
#8+kPo
8Pe@>v
-_$M':
LC-*Zh>
%hOEB3
H>roz7
I48re:0
g"'BN
KXzBzU
rC3Cz&
H]p*:m|
'4{"2g
QsL\rP+/
w@w(@6%
QM:)>(
(-iP|6
R42;)h[
Lu)"g_Eq
{d{HJ=
F*,S`Vi
y^&5PoQ
,\F2?.L:N|
"5e ]p
5_S~y(
x>Wj^#
(<#pW>
YQ|e@@=
5Ho <(
=(J$|lB!
4y'XZ#
}kwChI
?d(;6\
F'kL^r
%7Z*3m
$]rE(l
i|:qaL
o<;*ZOA
.:YvW,H
S$(|~_
)zX%1AY
zBH#}6|
Wkv>t&
l5n%}S
m&sQ>w
-H?Hcm
GwCYao
\9lI<1
c0(3lI
qqDxH{
8;nF]d|
uHGIEf
~0v#UJ
kW".?9R
A?t$`S!=
_^JZJNZNF
@y@#@G8
8@>@e@#
=JV@>@y@
K@-I F
dh_TAl
5o`];v
0L&0.<
)`1`)`9`
M0KNX
"gFzBO
Qv!dFJ
gn31BSlV
`MHL1R-
X.&!@"h
wpk63-
B88KE[
|)XnVi
::%lcr
:d<#u>
f:G)9r
!7*@..lL
nxJ6hh4
FYKP;YG}
=DG2tG
h9Em@[
h#A{TD~
R)G4T
J]hd^h
gJ>CJ.
oSGA\}
M~ jp"
pZE'hp
,s&.32WB_
lGf1?2
/sd_&+qY
$R'I/gH
3pKG5nAs
=5zVt[
!1I1Cc
X>.(.<.&.9.#
40ihRq
@rpJDJR
KhZtZjZ
}*{dNe
8C|D|b|Z|\bb
.sO(GH
dk@?#\
Pp8a p
GWX+^H
vPMsMcK
R[W8g
ij /H
-LS9>M
`@B2iR
2V.Krr
7!CPdk;
)Hy`%VZ$[J$
J*"{zy4
">_HxBWK
]]H:'Q9
;*h6d?
"!sw)>u]
:H)$`Fq
O*$Ir_V
f%5RN.
2K,$H5
gp~Qxr
_CorExeMain
mscoree.dll
<?xml version="1.0" encoding="utf-8" standalone="yes"?><assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0"><assemblyIdentity version="1.0.0.0" name="MyApplication.app" /><trustInfo xmlns="urn:schemas-microsoft-com:asm.v2"><security><requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3"><requestedExecutionLevel level="asInvoker" uiAccess="false" /></requestedPrivileges></security></trustInfo></assembly>
Western Cape1
Durbanville1
Thawte1
Thawte Certification10
Thawte Timestamping CA0
121221000000Z
201230235959Z0^1
Symantec Corporation100.
'Symantec Time Stamping Services CA - G20
http://ocsp.thawte.com0
.http://crl.thawte.com/ThawteTimestampingCA.crl0
TimeStamp-2048-10
Symantec Corporation100.
'Symantec Time Stamping Services CA - G20
121018000000Z
201229235959Z0b1
Symantec Corporation1402
+Symantec Time Stamping Services Signer - G40
http://ts-ocsp.ws.symantec.com07
+http://ts-aia.ws.symantec.com/tss-ca-g2.cer0<
+http://ts-crl.ws.symantec.com/tss-ca-g2.crl0(
TimeStamp-2048-20
Arizona1
Scottsdale1
GoDaddy.com, Inc.110/
(Go Daddy Root Certificate Authority - G20
110503070000Z
310503070000Z0
Arizona1
Scottsdale1
GoDaddy.com, Inc.1-0+
$http://certs.godaddy.com/repository/1301
*Go Daddy Secure Certificate Authority - G20
0:yO_LG
PT5KiN
http://ocsp.godaddy.com/05
$http://crl.godaddy.com/gdroot-g2.crl0F
%https://certs.godaddy.com/repository/0
Arizona1
Scottsdale1
GoDaddy.com, Inc.1-0+
$http://certs.godaddy.com/repository/1301
*Go Daddy Secure Certificate Authority - G20
190530003946Z
220530003946Z0b1
Washington1
Seattle1
Kilonova LLC1
Kilonova LLC0
YrQj0!
, $F!)
$http://crl.godaddy.com/gdig2s5-4.crl0]
+http://certificates.godaddy.com/repository/0
http://ocsp.godaddy.com/0@
4http://certificates.godaddy.com/repository/gdig2.crt0
Arizona1
Scottsdale1
GoDaddy.com, Inc.1-0+
$http://certs.godaddy.com/repository/1301
*Go Daddy Secure Certificate Authority - G2
Symantec Corporation100.
'Symantec Time Stamping Services CA - G2
200801052521Z0#
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
Comments
lightshot Setup
CompanyName
Skillbrains
FileDescription
lightshot Setup
FileVersion
5.5.0.7
InternalName
Iephii.exe
LegalCopyright
LegalTrademarks
OriginalFilename
Iephii.exe
ProductName
lightshot
ProductVersion
5.5.0.7
Assembly Version
5.5.0.7
Antivirus Signature
Bkav Clean
Elastic Clean
MicroWorld-eScan Clean
FireEye Generic.mg.217779bed934af71
CAT-QuickHeal Clean
Qihoo-360 Clean
McAfee Artemis!217779BED934
Cylance Unsafe
VIPRE Clean
Sangfor Clean
K7AntiVirus Clean
BitDefender Clean
K7GW Clean
Cybereason malicious.8e7d56
Baidu Clean
Cyren Clean
Symantec ML.Attribute.HighConfidence
ESET-NOD32 a variant of MSIL/GenKryptik.FFEK
APEX Malicious
Avast Win32:PWSX-gen [Trj]
ClamAV Clean
Kaspersky UDS:DangerousObject.Multi.Generic
Alibaba Trojan:MSIL/GenKryptik.b24e72ab
NANO-Antivirus Clean
ViRobot Clean
AegisLab Clean
Rising Trojan.GenKryptik!8.AA55 (CLOUD)
Ad-Aware Clean
Sophos Mal/Generic-S
Comodo Clean
F-Secure Clean
DrWeb Clean
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition Artemis!Trojan
CMC Clean
Emsisoft Clean
SentinelOne Static AI - Suspicious PE
GData Clean
Jiangmin Clean
Webroot Clean
Avira Clean
MAX malware (ai score=61)
Antiy-AVL Clean
Kingsoft Clean
Gridinsoft Clean
Arcabit Clean
SUPERAntiSpyware Clean
ZoneAlarm Clean
Microsoft Trojan:Win32/AgentTesla!ml
Cynet Malicious (score: 100)
AhnLab-V3 Clean
Acronis Clean
BitDefenderTheta Gen:NN.ZemsilF.34688.Im1@aOSmm2k
ALYac Clean
TACHYON Clean
VBA32 Clean
Malwarebytes Malware.AI.57147645
Panda Clean
Zoner Clean
TrendMicro-HouseCall TROJ_GEN.R002H0DEB21
Tencent Clean
Yandex Clean
Ikarus Clean
eGambit PE.Heur.InvalidSig
Fortinet Clean
AVG Win32:PWSX-gen [Trj]
Paloalto generic.ml
CrowdStrike win/malicious_confidence_100% (W)
MaxSecure Trojan.Malware.300983.susgen
No IRMA results available.