Static | ZeroBOX

PE Compile Time

2021-05-05 10:29:19

PDB Path

C:\Users\Administrator\Desktop\Client\Temp\mEqaESwCYd\src\obj\Debug\HebrewCalendar.pdb

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x0020d554 0x0020d600 7.99181211758
.rsrc 0x00210000 0x000005f4 0x00000600 4.21779240517
.reloc 0x00212000 0x0000000c 0x00000200 0.101910425663

Resources

Name Offset Size Language Sub-language File type
RT_VERSION 0x00210090 0x00000364 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_MANIFEST 0x00210404 0x000001ea LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with CRLF line terminators

Imports

Library mscoree.dll:
0x402000 _CorExeMain

!This program cannot be run in DOS mode.
`.rsrc
@.reloc
v4.0.30319
#Strings
Nullable`1
IEnumerable`1
ThreadSafeObjectProvider`1
List`1
get_label1
set_label1
ToWin32
get_label2
set_label2
get_DetailBorder2
set_DetailBorder2
get_IdentiferBorder2
set_IdentiferBorder2
get_GroupsBorder2
set_GroupsBorder2
get_label3
set_label3
get_label4
set_label4
get_label5
set_label5
get_label6
set_label6
ASManager2017
get_label7
set_label7
<Module>
System.IO
Dispose__Instance__
Create__Instance__
ProjectData
mscorlib
System.Collections.Generic
Microsoft.VisualBasic
connectionId
treeHead
add_Loaded
Grid_Loaded
remove_Loaded
UserLister_Loaded
_contentLoaded
detailsChanged
add_TextChanged
add_addClicked
remove_addClicked
add_buttonClicked
remove_buttonClicked
Interlocked
set_IsEnabled
add_DropDownOpened
remove_DropDownOpened
profileVersionComboBox_DropDownOpened
DriveLettercomboBox_DropDownOpened
childButtonPressed
s_WindowBeingCreated
Synchronized
UriKind
TargetMethod
get_Password
set_Password
changePassword
Replace
CreateInstance
get_GetInstance
defaultInstance
instance
set_ItemsSource
GetHashCode
treeNode
DN2Tree
insertToTree
get_Message
CompareExchange
EndInvoke
BeginInvoke
IEnumerable
IDisposable
Hashtable
RuntimeTypeHandle
GetTypeFromHandle
get_ResetProfile
set_ResetProfile
resetprofile
MsgBoxStyle
get_Name
get_DistinguishedName
get_MiddleName
set_MiddleName
GetFileName
get_GivenName
set_GivenName
username
get_Surname
set_Surname
get_userDetailsPane
set_userDetailsPane
Combine
ChangeType
delegateType
GetType
System.Core
PresentationCore
get_Culture
set_Culture
resourceCulture
ButtonBase
ApplicationSettingsBase
TextBoxBase
Dispose
StrReverse
_CreateDelegate
MulticastDelegate
DelegateAsyncState
DebuggerBrowsableState
EditorBrowsableState
ThreadStaticAttribute
STAThreadAttribute
CompilerGeneratedAttribute
DesignerGeneratedAttribute
GuidAttribute
HelpKeywordAttribute
GeneratedCodeAttribute
DebuggerNonUserCodeAttribute
DebuggableAttribute
DebuggerBrowsableAttribute
EditorBrowsableAttribute
ComVisibleAttribute
AssemblyTitleAttribute
StandardModuleAttribute
HideModuleNameAttribute
DisplayNameAttribute
AssemblyTrademarkAttribute
TargetFrameworkAttribute
DebuggerHiddenAttribute
AssemblyFileVersionAttribute
MyGroupCollectionAttribute
AssemblyDescriptionAttribute
ThemeInfoAttribute
CompilationRelaxationsAttribute
AssemblyProductAttribute
AssemblyCopyrightAttribute
AssemblyCompanyAttribute
CategoryAttribute
RuntimeCompatibilityAttribute
AccessedThroughPropertyAttribute
m_ThreadStaticValue
get_SelectedValue
WithEventsValue
GetObjectValue
openHomeDrive
callmapdrive
Remove
HebrewCalendar.exe
loadedFlag
System.Threading
NewLateBinding
Microsoft.VisualBasic.Logging
IsNothing
System.Runtime.Versioning
CompareString
get_domainString
set_domainString
ToString
get_ouString
set_ouString
Substring
System.Drawing
get_Log
ShowDialog
DNPath
get_ProfilePath
set_ProfilePath
EndsWith
StartsWith
set_StartupUri
AsyncCallback
DelegateCallback
add_Click
ResetProfile_Click
remove_Click
reloadButton_Click
addButton_Click
ChangePwdButton_Click
SaveButton_Click
saveButton_Click
mapOneDriveButton_Click
cancelButton_Click
DeleteGrpsButton_Click
addGroupsButton_Click
button_Click
OpenDocs_Click
add_MouseDoubleClick
remove_MouseDoubleClick
UserLister_MouseDoubleClick
PresentationFramework
GroupPrincipal
get_employeeIDLabel
set_employeeIDLabel
get_samAccountNameLabel
set_samAccountNameLabel
get_displayNameLabel
set_displayNameLabel
get_label
set_label
System.ComponentModel
LateCall
System.Xaml
TabControl
get_tabControl
set_tabControl
UserControl
HeaderedItemsControl
AddGroupsCtrl
PasswordChangeCtl
get_passwdctl
set_passwdctl
get_SelectedItem
getTreeViewItem
System
resourceMan
Boolean
System.ComponentModel.Design
AppDomain
get_CurrentDomain
MyWpfExtension
GetExtension
get_Application
ResourceDictionaryLocation
Information
System.Configuration
System.Globalization
Interaction
System.Reflection
ICollection
ItemCollection
TaskCanceledException
InvalidOperationException
ArgumentException
get_Description
set_Description
get_reloadButton
set_reloadButton
get_addButton
set_addButton
get_ChangePwdButton
set_ChangePwdButton
get_SaveButton
set_SaveButton
get_saveButton
set_saveButton
get_mapOneDriveButton
set_mapOneDriveButton
get_cancelButton
set_cancelButton
get_DeleteGrpsButton
set_DeleteGrpsButton
get_addGroupsButton
set_addGroupsButton
get_button
set_button
get_Info
CultureInfo
AssemblyInfo
DirectoryInfo
CompatibilityMap
Bitmap
System.Windows.Markup
System.Linq
HebrewCalendar
get_Header
set_Header
sender
get_DetailBorder
set_DetailBorder
get_IdentiferBorder
set_IdentiferBorder
get_GroupsBorder
set_GroupsBorder
get_Pager
set_Pager
get_ResourceManager
TextChangedEventHandler
addClickedEventHandler
buttonClickedEventHandler
RoutedEventHandler
MouseButtonEventHandler
handler
System.CodeDom.Compiler
caller
ToUpper
s_User
get_User
loadUser
MessageSurrogateFilter
get_UserLister
set_UserLister
s_Computer
get_Computer
get_RestrictedError
ClearProjectError
SetProjectError
ColorTranslator
IEnumerator
get_ValueEnumerator
GetEnumerator
Activator
.cctor
Selector
IComponentConnector
System.Diagnostics
get_OpenDocs
set_OpenDocs
Microsoft.VisualBasic.Devices
Microsoft.VisualBasic.ApplicationServices
System.Runtime.InteropServices
Microsoft.VisualBasic.CompilerServices
System.Runtime.CompilerServices
System.Resources
ASManager2017.My.Resources
ASManager2017.GDI.resources
HebrewCalendar.g.resources
ASManager2017.Resources.resources
DebuggingModes
_treeviewNodes
GetDirectories
System.Windows.Controls.Primitives
Strings
get_Settings
MySettings
TextChangedEventArgs
RoutedEventArgs
MouseButtonEventArgs
ReferenceEquals
loadUserDetails
userDetails
System.Windows.Controls
get_Items
get_SelectedItems
Contains
Conversions
System.Collections
get_addgrps
set_addgrps
loadGroups
RuntimeHelpers
loadUsers
Lusers
Operators
Process
Exists
get_Plus
System.Windows
s_Windows
get_Windows
MyWindows
Concat
get_TimeSpanFormat
GetObject
TargetObject
MyProject
System_Windows_Markup_IComponentConnector_Connect
LateGet
target
m_SingleUserEdit
get_SingleUserEdit
set_SingleUserEdit
get_ReflectionEmit
get_Default
IAsyncResult
DelegateAsyncResult
MsgBoxResult
System.DirectoryServices.AccountManagement
UIElement
FrameworkElement
element
LoadComponent
InitializeComponent
get_Current
addClickedEvent
buttonClickedEvent
addGroupsEvent
get_Count
UserList
System.Windows.Input
MoveNext
get_Text
set_Text
PrincipalContext
get_myTreeView
set_myTreeView
m_MainWindow
get_MainWindow
set_MainWindow
get_MenuWindow
set_MenuWindow
get_employeeIdBox
set_employeeIdBox
get_new1PasswordBox
set_new1PasswordBox
get_new2PasswordBox
set_new2PasswordBox
get_userNameBox
set_userNameBox
get_displayNameBox
set_displayNameBox
MsgBox
get_profileVersionComboBox
set_profileVersionComboBox
get_DriveLettercomboBox
set_DriveLettercomboBox
GroupBox
get_groupBox
set_groupBox
get_groupListBox
set_groupListBox
get_grouplistBox
set_grouplistBox
TextBox
ASManager2017.My
ContainsKey
get_Assembly
GetExecutingAssembly
get_HomeDirectory
set_HomeDirectory
ISectionEntry
set_Visibility
MySettingsProperty
WrapNonExceptionThrows
ASManager2017
Action Auto LTD
Action Auto
2017
$1a69028e-4c9a-442e-8836-dd73ccc1912c
3.0.0.0
.NETFramework,Version=v4.0
FrameworkDisplayName
.NET Framework 4
PresentationBuildTasks
4.0.0.0
groupBox
grouplistBox
addButton
button
label1
label2
cancelButton
saveButton
new1PasswordBox
new2PasswordBox
GroupsBorder
GroupsBorder2
groupListBox
IdentiferBorder
IdentiferBorder2
displayNameLabel
samAccountNameLabel
employeeIDLabel
displayNameBox
userNameBox
employeeIdBox
DetailBorder
DetailBorder2
userDetailsPane
addGroupsButton
addgrps
passwdctl
DeleteGrpsButton
label3
label4
label5
label6
GivenName
MiddleName
Surname
Description
HomeDirectory
ProfilePath
OpenDocs
ResetProfile
SaveButton
ChangePwdButton
DriveLettercomboBox
mapOneDriveButton
label7
profileVersionComboBox
myTreeView
reloadButton
MenuWindow
tabControl
UserLister
MyTemplate
11.0.0.0
3System.Resources.Tools.StronglyTypedResourceBuilder
16.0.0.0
KMicrosoft.VisualStudio.Editors.SettingsDesigner.SettingsSingleFileGenerator
16.0.0.0
System.Windows.Window
Create__Instance__
Dispose__Instance__ My.MyWpfExtenstionModule.Windows
My.Settings
ouString
OU String
domainString
Domain String
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
PADPADPW
EHebrewCalendar, Version=3.0.0.0, Culture=neutral, PublicKeyToken=null
clr-namespace:ASManager2017
ASManager2017
ASManager2017.Application
XPresentationFramework, Version=4.0.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35
NWindowsBase, Version=4.0.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35
SPresentationCore, Version=4.0.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35
9http://schemas.microsoft.com/winfx/2006/xaml/presentation
NSystem.Xaml, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089
x,http://schemas.microsoft.com/winfx/2006/xaml
clr-namespace:ASManager2017
Resources
MergedDictionaries
Source
Dictionary1.xaml?
EHebrewCalendar, Version=3.0.0.0, Culture=neutral, PublicKeyToken=null
clr-namespace:ASManager2017
ASManager2017
XPresentationFramework, Version=4.0.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35
NWindowsBase, Version=4.0.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35
SPresentationCore, Version=4.0.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35
NSystem.Xaml, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089
fadeBrush
Color
Offset
9http://schemas.microsoft.com/winfx/2006/xaml/presentation
x,http://schemas.microsoft.com/winfx/2006/xaml
clr-namespace:ASManager2017
#FF95A2F5
#FFC4C4EA
EHebrewCalendar, Version=3.0.0.0, Culture=neutral, PublicKeyToken=null
clr-namespace:ASManager2017
ASManager2017
ASManager2017.MainWindow
XPresentationFramework, Version=4.0.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35
NWindowsBase, Version=4.0.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35
SPresentationCore, Version=4.0.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35
9http://schemas.microsoft.com/winfx/2006/xaml/presentation
NSystem.Xaml, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089
x,http://schemas.microsoft.com/winfx/2006/xaml
d2http://schemas.microsoft.com/expression/blend/2008
mc;http://schemas.openxmlformats.org/markup-compatibility/2006
clr-namespace:ASManager2017
MenuWindow
Title$
AS Manager 2017
tabControl
Stretch=
0,0,0,0q
Stretch=
Machine Manager
#FFE5E5E5
User Manager
#FFE5E5E5.+
ASManager2017.UserList
UserLister
Stretch=
0,0,0,0q
Stretch=
domainString$
as.internal
ouString$6
0OU=AS Users, OU=Ashby School, DC=as, DC=Internal
fadeBrush#
EHebrewCalendar, Version=3.0.0.0, Culture=neutral, PublicKeyToken=null
clr-namespace:ASManager2017
ASManager2017
ASManager2017.AddGroupsCtrl
XPresentationFramework, Version=4.0.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35
NWindowsBase, Version=4.0.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35
SPresentationCore, Version=4.0.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35
9http://schemas.microsoft.com/winfx/2006/xaml/presentation
NSystem.Xaml, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089
x,http://schemas.microsoft.com/winfx/2006/xaml
mc;http://schemas.openxmlformats.org/markup-compatibility/2006
d2http://schemas.microsoft.com/expression/blend/2008
clr-namespace:ASManager2017
groupBox
Active Directory Groups
Stretch=
Stretch=
grouplistBox
Stretch=
0,0,0,0q
Stretch=
SelectionMode$
Extended=
Visible=
fadeBrush#
addButton
Right=
0,0,22,0q
Bottom=
button
Right=
0,0,22,0q
EHebrewCalendar, Version=3.0.0.0, Culture=neutral, PublicKeyToken=null
clr-namespace:ASManager2017
ASManager2017
ASManager2017.PasswordChangeCtl
XPresentationFramework, Version=4.0.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35
NWindowsBase, Version=4.0.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35
SPresentationCore, Version=4.0.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35
9http://schemas.microsoft.com/winfx/2006/xaml/presentation
NSystem.Xaml, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089
x,http://schemas.microsoft.com/winfx/2006/xaml
mc;http://schemas.openxmlformats.org/markup-compatibility/2006
d2http://schemas.microsoft.com/expression/blend/2008
clr-namespace:ASManager2017
0,0,0,0q
fadeBrush#
RadiusX$
22.641
RadiusY$
22.641
Effect
-System.Windows.Media.Effects.DropShadowEffect
label1
New Password
10,10,0,0q
label2
Repeat Password
10,41,0,0q
cancelButton
Cancel
116,72,0,0q
saveButton
196,72,0,0q
IsDefault
RenderTransformOrigin$
0.495,-0.774&
new1PasswordBox
116,16,0,0q
new2PasswordBox
116,47,0,0q
EHebrewCalendar, Version=3.0.0.0, Culture=neutral, PublicKeyToken=null
clr-namespace:ASManager2017
ASManager2017
ASManager2017.SingleUserEdit
XPresentationFramework, Version=4.0.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35
NWindowsBase, Version=4.0.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35
SPresentationCore, Version=4.0.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35
9http://schemas.microsoft.com/winfx/2006/xaml/presentation
NSystem.Xaml, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089
x,http://schemas.microsoft.com/winfx/2006/xaml
d2http://schemas.microsoft.com/expression/blend/2008
mc;http://schemas.openxmlformats.org/markup-compatibility/2006
clr-namespace:ASManager2017
Title$
Single User Edit
fadeBrush#
RowDefinitions
ColumnDefinitions
GroupsBorder
Stretch=
10,14,10,0q
Stretch=
CornerRadius$
Effect
-System.Windows.Media.Effects.DropShadowEffect
GroupsBorder2
Stretch=
10,14,10,0q
Stretch=
ZIndex$
groupListBox
10,14,10,10q
SelectionMode$
Extended=
IdentiferBorder
Stretch=
10,14,10,0q
IdentiferBorder2
Stretch=
10,14,10,0q
displayNameLabel
Display Name
15,0,0,0q
samAccountNameLabel
Username
15,21,0,0q
employeeIDLabel
Employee ID
15,0,0,0q
displayNameBox
103,3,0,0q
TextWrapping$
userNameBox
103,24,0,0q
employeeIdBox
97,3,0,0q
DetailBorder
Stretch=
10,76,10,0q
Stretch=
DetailBorder2
Stretch=
10,76,10,0q
Stretch=
Orientation$
Vertical=
ASManager2017.userDetails
userDetailsPane
5,5,0,0q
addGroupsButton
Add Groups
Center=
10,10,121,27q
Center=
ASManager2017.AddGroupsCtrl
addgrps
hidden=
domainString$
as.internal
ouString$7
1OU=AS Groups, OU=Ashby School, DC=as, DC=Internal
200,86,32,75q
ASManager2017.PasswordChangeCtl
passwdctl
23,104,0,0q
Hidden=
DeleteGrpsButton
Delete Groups
99,10,0,0q
EHebrewCalendar, Version=3.0.0.0, Culture=neutral, PublicKeyToken=null
clr-namespace:ASManager2017
ASManager2017
ASManager2017.userDetails
XPresentationFramework, Version=4.0.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35
NWindowsBase, Version=4.0.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35
SPresentationCore, Version=4.0.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35
9http://schemas.microsoft.com/winfx/2006/xaml/presentation
NSystem.Xaml, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089
x,http://schemas.microsoft.com/winfx/2006/xaml
mc;http://schemas.openxmlformats.org/markup-compatibility/2006
d2http://schemas.microsoft.com/expression/blend/2008
clr-namespace:ASManager2017
0,0,0,0q
RowDefinitions
Given Name
label1
Middle Name
0,26,0,0q
label2
Surname
0,52,0,0q
label3
Description
0,108,0,0q
label4
Home Directory
0,134,0,0q
RenderTransformOrigin$
-0.449,-0.602&
label5
Profile Path
0,160,0,0q
label6
0,205,0,0q
GivenName
110,2,0,0q
TextWrapping$
MiddleName
110,28,0,0q
Surname
110,54,0,0q
Description
110,110,0,0q
HomeDirectory
110,136,0,0q
ProfilePath
110,162,0,0q
45,207,0,0q
OpenDocs
428,136,0,0q
ResetProfile
428,162,0,0q
SaveButton
428,207,0,0q
ChangePwdButton
New Password
428,28,0,0q
DriveLettercomboBox
141,258,0,0q
mapOneDriveButton
Map OneDrive
10,258,0,0q
label7
115,256,0,0q
profileVersionComboBox
508,162,0,0q
EHebrewCalendar, Version=3.0.0.0, Culture=neutral, PublicKeyToken=null
clr-namespace:ASManager2017
ASManager2017
ASManager2017.UserList
XPresentationFramework, Version=4.0.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35
NWindowsBase, Version=4.0.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35
SPresentationCore, Version=4.0.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35
9http://schemas.microsoft.com/winfx/2006/xaml/presentation
NSystem.Xaml, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089
x,http://schemas.microsoft.com/winfx/2006/xaml
mc;http://schemas.openxmlformats.org/markup-compatibility/2006
d2http://schemas.microsoft.com/expression/blend/2008
clr-namespace:ASManager2017
myTreeView
Stretch=
0,0,0,0q
Stretch=
fadeBrush#
ContextMenu
DisplayMemberPath$
HasDropShadow
Effect
-System.Windows.Media.Effects.DropShadowEffect
reloadButton
Reload
Right=
0,0,25,0q
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
hSystem.Drawing.Bitmap, System.Drawing, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3aPADPAD
QSystem.Drawing, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a
System.Drawing.Bitmap
IDATx^
bVP@1'
V{k.{8
[`hxnf
=GkvGks
Int6at
}L}^c
kv>cq
$?|dGh
~u.|01f
wvfM'_
3YTsk;
M0|8'o
lc>gX}
32kH6M
F_dj.`
J:3_yC]
G6lK~Vc8GS<$W
!3r!kk\
{_D?qM
r1Qngsj>
jB6c~tK
7o6c}B
^>d,ze
O9_<co
foL^7o2U?
u5<G>$
@N$S9\_z
x zko
xNh-I~jG6
j9TM.
F^%Wv"
1z$'2#~
G6knl
;:dc\v
6OSo`t
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
hSystem.Drawing.Bitmap, System.Drawing, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3aPADPAD
QSystem.Drawing, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a
System.Drawing.Bitmap
IDATx^T
OH)c{9
<@_.wa
C\<PI\
*!XY9 ZY
>V0P>V
RDD+h
-Fdi1^
B7A>sm
.+,8|7j
8COf4
uq|C}E
o++0+++
d'i\*~
gJ 4=W
:%#;ll
8 X))Q#
+r+j
o~'kuG
Wqo]-)y
+HENA
"k\)K_e
9f$q9V
E455+5=,
glw4S7{
+n%5-#5$.5
n>H_
] z\b:
6TyXTv4
Bb^uT
MYlku;
iUf$1l
+aD t&
hzZ|%^U
f)YWE}
!b`lG0:$
Y]Gpa)>e,"
ePo2]H6
BX<j^1
;5fkoa
x1SNg6
>RJy-v
058YZ#
:zIv1,
v+Bp}
Z2;}8t
hvFD${
a?z8 "
e,JTV8
^tj~!:
y)S]h[
;fQ flHsm
ByjpH|
~E!|6M
',8D4L
.+qipHg
qA5v([7
NkxXR
kn!PZ2P
xLL"u
LhfG[e
)aeHZW
[0.$6G
r+!irQ
|^326T
\BGsfX
Op]o4Y
OfzM+
MO`@E''
yTN"=
~|:q>
J(.v)eS
Qx/`g?
g4g9?_
d,aUzo
Ay]f#/
oDtzYyJ
:p3V$W
ALyhzlU
IJtS1b
{SH/1<
m_'Xez
@pB,_x%
Kq3q7M
:9wdK=
yA<9}]
"k'Y3N
LlRpA7
'qR81E
BH#QL9
bsE~&B
Yk3qGl-m
p$^]!N
c,D0?"8
rJ&x(yW
)'y1Cc
?nQ`uSf
H;nVKe
]WCkfO
1Tp:XE[
7dx[U|
JdT!8b
:jp;$T
a=_i</=j
?a"fl0
kT"I8D3
HQ?y\_
EZe[9V
+g<}
<MD5"]i
csVG d
'G9pq^
PJ hye"_
5 G2pe
:j(Myo
mL^%IGf$
1j ht1
@^r6_O
n/e:~y
w69y@~
gD4RAzv
imeM];
"6.{l^h
-)}z#kp
:AqGw>\
8 u!n!
LQ]/GN
ExFtG2
_'[)\q
vV?}1
%@RHQ@
*1HFJ0
m"/Zp7
tmzlZL
B!n#/L
1Dpl0D
0ay[;)
G/-'(\B
-_c+GC
]T%!A
`c>ynM+X
RqBa5>Z
\TKk~v1
:i%MTu
}!*@-$
D/)nSlH
G(VM10
y@BYP)i
n-kT<8
1~rdH_
y1%Ew5H
@#E,\=+.=
C;Qye_
[RB9c(
Qn6!d8
A7jkW`~WNR
\`Z568
2lBYgK6
=_qvjij
4N~vJ,
mSMm:v
)r8*TJ:(
f@qC03
3""c'.
b?Dp-q
dqkD<Z_
H\SewLY)"L
o#XDA\
H(xCt
.v^brc
c)B$ls
I'K}L;b
~:q1C(
UZ$qb~
:Ey5"r\
V-*e@og%
>G ,0`
xHe?0
THj9U@S
8i2X&F
S8d-;a_c{
}Ih75'
78SQP]
>Gd)&
iwHT#}
Z9j5}%
xnS>!)>
X'vOeYK
6LPyr+K
//M[/=
_:f>^adr{"
kR\WP6c]
f$v$O#>
=>N]qB
{qlS[j
a.qTtf
K<'&FX
jGH}e*
92'5%x
u5>|pl
?Uc.$<
k/%U)
Y05sn-
+ _pRp
Z6A/g@
~2`#vCs+
,o}ok3
a#n'gaa
vdH-Y,,
=hJ4#/
)"WU}`
%Pz2b[
E!{<oGF
L1:J>wq
*B_I1)
~-v}""
x(#~?n
!7Z_I%
:^}u1;a
LG5k?)GE
@)hOtm
o+D1?xa9
QP'+?X
Xa?9*22F{
>jSG7.&WqS
-fw;7f
+fuGK6"
;7iPFp
6BN\S/
EH:_,=
VM^)8}
&c"#]
bE~t*Sbx5F
LI_iuGj.pE
iANeBcsN
ySrAa:KQ9U
\6>K2{(z
K?s/3K
=GwjsZ
{k?w+W3B
&`&EAc{
&G!DRJ"
t=mdgQ
M#2!3Z
24nL?Pa
#;aE#
fo{KN
P?j|K,
t#VSS#
KBr$ZX
CN?|+&
sEr._p
`5-f:
i|"1\N
_"G4*4B
t d\hP(O
U:sp9
?a|isL
&+KyJ(LZ
x,Jae
)pE-\`
M/jx~X
HNFHyV
fVIa6(
mYH+a'$
`r:Qq
Llv*zv(_Q
8EUr{J
Dw]vS&
k]jH?g,
GofXdPc
br9DtP
>LO7|"
fc+0@VJ
%KW"N:
{qkJhj}
'|)I5`r
iADt7$gu
lb/~USC7
|>V::N
P#Vi*`
bxY]ka]
/*/&^S
HYcMb_
}xV}Ul
/U0d4Ss<
}g}F{
@@d103
@8e>Jg
KFN]HJ
X_x+Me
BB@A.C
:xk=jQ
z9a+h>
w;t5=b`|(T
5n\_1i
{hdQXE
X5W#QV
CN-<{fD
5@hHxf
';YH6+
aLVckw
um@^6C
iD!wBE
{u_%$5
Sj_%)$
~Z3Ujk8*8
zOc~w;
z|<tLh-%`
zwGoLY
BA#y`4 C"
V#$efa
79-*a}pnjd
kv'Mrpy
/]S]7g
{''eYz
&i>eII
@a-i}w
jM}Vl2
,9a/7:
?=s)xH
/_Yt]l
hs74/t
vI^i9R
y8j}*i
.WT#$R]
}Vl/ 'R6
P]Ro_B
`c^)=$
+ 2z#:
'p:nQL!>
+HMz:I
06gjiF*
+wKDSD
>HY|A"
JczE|%
\m:g{3
x>%_7vZ
$+d7#3
f]l 7b
x=Au:-
;f*fjkI
5mTpY62
=P -`?
9;Zi1
3s=qRx
E7gfc.
~ht^PA
\=y)kn
/l,@x:
=*z1-q
f>]J"O
F4np"z
DYKhp
J`|f;o
'L>!4
Uy,w}:'
E+u*0v
,`(<-`
_INS@~L
%l?+,"
)K`!+E(
(H)nF]
j=AoIw
X^Ew&!
^{=+-B
*UtKy]
- o}~a
jg~qx
glS1O=
C8@@ 0
x{Vc =
|}vE)O:
OoI_d
qB/Y[p
)--#>2
)i:d2:
V]^ eZ
;*SNm8L
Kl(2L&
NztMHlca
c}O<~#
X>m;k8
k("Y8+
E?q9_>
x~GS}-
wX@ >j
MeCxY@
f5}DON=
0gqFrzM)m:/
^D0%c<f{
:[#zD\
R{u[sx
VRG62U
P+H")kx>'
M<U+]R|/w
nouV"on
^q6w<>
jSv9 p
DsM&{[
U$vcR8
1o~;?b
QGu&05
[neIop
Sc&:{Hk
`>5`R,V
xAB[7-
j,w{sF
(~~y0E
rux"|O
z@BZHQ
06Sr89
;qF][!
EVe(/{
@& cCP
.0e2>b
r_FL(E
g{iDy]
8l@\>
IkI${=<
xHT&)X
k_4w#$q:
!OTj#]
qjES.8
3d"c}S
yXqL:l
'JA}gP
,iGP%b
g&\(I6
<i\WgK
PZX'wi
Tk]uvN
Td$T((a
=N_O}wT,!
hi!s@J\
+QY sO
ZP}kLF
8usWIt1
.z{+Ni
XVc>K1
9?V{L!
\RpCub
! z]%t
5*aCEXl
`fi`l|90
.QX~8<!
U6m&"a9B
<r"G$9
'&3)Tug
c017Md{
@{D<h"
)XtAI
-Kp^{*%
-giy\Ye
M}QL=b
9(kJ;@]
v:Y1KI
c`5AGh
E%~.&V
aJ('_=
}~CCPP\
3.S/$O
9$86?7
G+yu1`
y:8C6Z
@ViGDLF
H&wvVW
H?wr|H
U?-rW`
#z|v(Q
q+k#g
1-((7v
.d`$:@
i<L#iK
-f?\bP
?B}%_A
Ppr0PdM
/W-E2[T
i=w'g5
yp["_p
[>`gsZ2
S1}^}V
}TA]NX
u9#~u9@r
F^oTOa
['XXa6
9q=EUY
5FV"YD
[B5!5]3
]Wt5r5Vp
hAx]>}
2}28}uoo
E0qm1Ra
;&pA^l
%&0t]j
2Yb:'e
{:NzEUg)
(/C-!oqu
:SCZ2|9?
qd__L~,
|P"JQA
5Hpwgp
I>hRu%
=%VUv(-UM
hc 1`p
9||#m\N
HJHMO:i0d
H_DziG[c
v|^tur
_g(]?*
EBo&<sG
~T1D{{"2
s?3,]C92f
H'C"<u
AC[ QX1w
IeDCh@
BRTFS3
7(?KI@
1B]I|k
dl%+h(c
n!@GTo
v]_<Y(
`~GXI
+#x\b7
-cIyA|h
~{nwP\
C@nep@T
+dfpOB
9>HKwH^
8DY!3Y*7>Fm
_&~E#>
q]unD+
o1QJG:
5EP!I}$u
.Wfx&-46
p_X#e|c
]Gwez&~*
Hvn=_ &^
y~{&52
ltZH<nO
/k:; B
m8j3k={
Whp(xX
k}E&J#c
B7P.!Wde
+q|}[
T2\%FD
LpZR]{
*?%t03
et}pn5A
v+PS!-z
'W4w}djR^
_>}xO:
<nEhc^
^_;:KtH
{NHL|
AJjavb
QJknz1
a<\~o6@/I
nJC'kx
\"v|QtS
g{zV~C?I
&|RNuGt/
[,8,[n
H.FH.`
>o{tv_L
{ECjV#
@<|MZ}
tHd2s]
ua+F$e
z)+Ke2
#~6,^
vu6me#
zuwRZX@
PGPe/>
eiF4S})
S/\4ej)
blr?VIZ
`!LQj?
y`3=9=
Rr(S'@[o
sBc.LrUb
Q1V}:)L(
"ko*-Y
#7tZO]
o90y.u/2
--.|JN&:
qD\8CZH
H/7~<z
BSJKjt
Dtg{gC
l>m}"3
J^~"<x
fA|WQ;
xIj9U
]v)B;x
h`6l*<
toa/>V
`.^g#x[
eQvc7+
mfk/j?
^2;1-n
W^|2y`
G"o=#KS
"n9l:r
xsQTIW
gRa/$\
Pd)5%zh
<U^SVk
t89?w(
.;ia}r
">lEte
,_~wrQ
"ouP|D
-HKKCN
hUxlv
3=-C>h
7$=U1.
sVR)e-
@"Xz^CW
_mVfd
LzOe83
]KOKjZG
!#4Rlw
)`UN~|
y7#Mjn%D
@=C|BE
SZa%ZM
v,?9rR
=1T{kg{
SHP/+#
u5>)NJ
/;kF&$n
6||hnA71";
;"rmst
]+%x:O
'_u$[W?
Dj"2\b
y<n.mB
|Q[hV
OYnU}u
"0O@%;
b/HdP*
KlY;O8e
2?0I!]RKP
R82dR(j>"
42&}Us
;Xe-%^&
qfoP+O
(_\o(5:
~Zn2Rx
3`".vA
d+/+i{
4<)6h6
xgT+sN
ZB3a_7
+'n!*i
')?Jv,
})$xIa
KVPe$8
09ViZ7
MDXWu\
vJ&ET\j&
cZ<>g.
`;Cb[1X_
/xQ*tD
/[owR{
gs4~"?
(ROrR*.
Wt5*4A
<9()c']
*+s"ps}
4`f4q}
rb|#(W
g=V_CL
v]tRJIc
iw1;|>5-
*n6+bZ
;M]%zX
6&|m1X
Gb8CWlW
R(Ytp]
Hk[1N
q?(ad6
m'-vhD
_K:Z-;!
2o>S1E
:e$Z"p
)_B_tZ
9(Vhv:
yuKBvK$
wx @QP
.cdXPO
8gt;c8
yGZnYa
&%Wv9tNi
4D<M@/
lGKjX[G[
a0:fbq
"0\";r
7X{%}#}
=[7E$a
beO6N%GT
/P&JhKkok<Y
mMdXv_
#4b6 v
E?JnXe
yiaXA#A
wek_WA
2U#)sMD0
{&vy3;
Vd{2xlQ
T-z;3*
;i'lv'
OKU4ydYv
aw#:5t"K
]^k?Fm?
YChMNi3
\,map
E'W$DP
75fR~2
K)0W |y
7N:6`)
Ux J:D
A87tDh9
miN)h:p
0.Ew=
2G7wdq
"wgb*_
q9IK@(
@WQu#3
o+qFh=d
GupQp`
*s2XL6
!B!ugw
9_`*3a
&)D2ZnP
8rUmo(j
f8.n;-
<jw=esJ$
6vx:dv
KpH$;-!F
TqeA8J
@m6JgX
hQWzG.
J6KzRf
jAZ|A5b/
N<4383
g\=u\I
/oP6co
abSW-7=
HQB5-+D
&Xa3_|TTt
X6a lM
})bd_^
oPe'Ys
~4aEz:
<<eW{
c)p3Z1
VF8-^I
t3Cr72
?d~r5.
.cIp3''Ow
n^(*]m
HcN'n$
dI=K?Y
By ONB
-G3yy\}
Y5aV6b
TYi^S}(
f?(a.ilI
F\]/c7Pl
A](BqU
:Xj(540\
3FSwk/^
M!; [j
XR{z"Y
.rUG>
ixL*R5.
S;z2sM
7i^K"
[@&>U4
1v\2O{H
<#Ylj\
$<>&5yi5x
$$8Tca
gr0QrE?
w=8Si%<]0>
MI;"[j(
]=6Z/2
4|K>GU
o&UPN'
](9'jy*5
4i4uI
k?yJxE
aRfoW3A
s]~l-T
wy[PA)X
G5M'2jh
G 0_f2
6v,;o>
+:QB;%w1d
K=Tz;s
2:R@kNo
+#Ds:/b
A a>CW
pVL[|
5583O=Jp
#oE"*r
X.Km22
IO,BxHW{
AHI>C[
}5Cg7[
.+F2jz
d4bg!z
5/@A5n
@Jn%<-
HA?&8L
JE,S3Q
(JUyok2
hg[;uS
LPW^+N
v#^?YN:
hkqoI|
(A#)@k
0x<T]h
]MQj*D
}Yl}M;
X]{'<#>
fx8`<E
g,hZj8
3cC{6m,
CM]v:[
hMRG5qu
pgI|yX
rv%@Fn
+)2N'p
_X@z{}
=&i@~9
v%bvuo
vQq\8S[
Zg8EE+`
@jR)?L
+^~(.<CJf|
b~LF?(
@P'&#P
X*zOLq6
+RSqPxg
Odpt<$o
5GQjtD
|PCIIJ
*F?m&.\
'Zt5s+
uph<:D
rUM$w
8,>b%"
e(u[z_
"O#R~PW'G
tocos
#|S*>P{8
-ldLuZ
{">`bD
%S`k.A
8|E7lY
UnOdj-
vIwg(f
i<y;))
iT!3AU
n8;o>9
r])$+
KZVA`?
!v"/[J
Qe2sJF
|"_XuB
p!1w).
YToZev
!5t.Q2
0|?*Hr
=yL->=
mz4fYRG
GiKP8x
}D[3Cl
\R$P?k
nL\cYe
\I,S|h/T
k9=YFf~
Tr((Hy
sw{Xmc
&pO7
CH*}'J
P}1Hru
?naN9(
|#<.ZyU
"6s~V[
RY4p<
7XE3{UW
V;T6wS
+i2I:6
6)\r)4NNs
']"g2|
ZWB=mf
)Uks-M
-K_7$Xnm
5hiM3[y
AD*fkxz
\rns+!X
HWmR$%A
@7-73
S";ET:
|5,vV?q&n
8LJ12X
]x[0C\i
FRNgOj
'@Q_jC
-:j5cH
d]l#Vt.
~yx}&r&
0-eY2PU
BUWBI>
Ku,*G&R
`0h<Ifeb
Wz;Fc&
HR9%'5>
t`IiD0"
[}fD3L
s3fi$"
UUpRWww
)=*6n
Wi>C"&#
)\pL;T
a7`</_
6=1M8g$
,A("Kd
Z&Mxkw
x1M#LR
9FAL>XtU
rllppU
J/N24#
r$}6xD
i3fs&'*n&
+&J6X%
eYb%K&
-qj:O0
{V(",Y:
J+,N(r<
AB8Vl^
)Vi\bq
Ta{E},
Up|("f\
Y?V&JKa@s
RB6p)8.
}/`cxZ9
=VzO$%
/JCA)N
=4) [1
y>^[9#)9
"d/T<F8
H2'w0p
,^m<Q&D
{i3<:}!
J~LJ6\4
twM!
1@tX$
$J<f&
:OG26*
SWX\9m
|+fy+Zy+X
e U'hT
UJfJVq
84Hwwwww
*Uv]0}
Ts5[s:
MlkRl_
>QGL2e
n#=18~Q
1_J*O@
6R1.64-
q$fE`$lnV
&e;1 ,
L~Y,L6
ou:U<`
IQD<CnKR
M['j>i
A2 E,o
Z,9i#L
)2gcyL
UID$B"
BZPPTNz
ZKd1udA
'<+y9H"9
!//ga7
z0Vjwl
~mlD<2
-nD056
C2lZl~
Ynk#:~
;).tW>F
%`[sDO
1hroa:
IDATvDZ@
iC#~2"&(
kD*zWy
E+H=,F5
x)Cqa\
jTW._LN
p)v0#$l
9!oT.5
G`2t&",7
8EIJ'%
c(u6O!)%
[WiL}0Q
eo_2Di
Mu:lA68
fukcSN
B6mi3"
?cRP'{sC
ili\)Sn:u
8SVXj?
My_D40
/:wb`T,
]%]Y|_x%
XH,D I}L
;oJ4Y9
<z)e;5Cv
}kO/%W!v
VE.OQJ
~7sH[I-
*d<]w'
ne3[EI
2=JV|/
YYSYfR
:`W(X7s
%fI'"7V
,I}Tlp
6wDm=.
PZ,/E^M
"5",IQ
f\w0c
)4,zW\x
oyJ}co
e2-M&D{3
`,aZ'}
3WNR>W
M^hL-F
(A5iZ$$n
a"8tsiy
4td4H
9Z"=Z5<
'4:G9t
Rj&n3r
;kuVl@A
6^!&am4?
R2&V]C
cg`*c^[
4}>t(*.O
G0T5sr
xHObPK
fq3$y5f
=ne'.v
oasKGj?
H)_(wC
@|}K/V
Oi4g;T
/K:Zp
j6om\[o
GG0Q!u(V
a,6kI_
%T"oC
V"v!iq
m<8rBNr
%%S^MB8
zN-0:
,p.k9"5
;e2Jx'(o
p&si;_
[SaF=|C37
cVIgd0}
&TbOf"
=Bh!s)n+A
ibL>vy
@>&I#j9
qSx"!
#u'(' i
<YEYro
:74l'q
g~@g]PG{&g
jin}me
!JWLaj
MpbNqka
T$^08&-k
/_H{s3
2iGBV!
;8GdNmK
q#@zkH
jo4:2'
C=:?N
Wsa<M(a
.6h]&\
6Sgv&[s
WFL\Q|
w9N'p4
o,vy\|
<&)QdQ
>5c#w3
mR[G63
C=.A@_
m+)>CZF,
RCA=!\Vl
@Pg>-s
x\Egyi
1mu^Z8
VB{}Tm
rB)o#M
O8juc&C
hPsk[n
k}Sv._kHJ
kMCVtx9
"F\"+(
ayrm{'
"TS#UI\{
7>}s|c
EW'~(-
yXOM1 7
"F2WQ=#
C^4qrN
Y2O:E>i
P%"g}s
qa_p[6
N>f?,c
\QR[J'
n#j~ic
_[jA@q
o&g{J
xaw9<L9
CT43$U
*`d1 0
<:8^[e
GIVX9V
=XQYkt
,xfBwM
&W|P.xw
0I$#5U
S:KP9E
0$c6a^
]E"~QO
-t$dRq
%oX9bW{
C.9EGK
IIf4Dr
|:u5DQ
16~($!
=LK7d$K
Q;KM0ZBA{
G.j^aF
o,tmP}
myQ7`/
_[6K!w
5_Rw<$
Pn-wx[1A
d}&Ae(1
=QC|g5
;~j@ FP
r'hC!y(7,
Kw3b5<
\$#cx*
:ld1gQ
/]>h9A"
Tk5mBw
d}fYAN
Ke@<>7
gdrZZ0
bZ#<3b
z49ZZAO
\z%f>DpP
V\g9%:
Antivirus Signature
Bkav Clean
Elastic Clean
MicroWorld-eScan Trojan.GenericKD.36852535
FireEye Trojan.GenericKD.36852535
CAT-QuickHeal Trojan.MSIL
McAfee Artemis!48DB1EFD4059
Cylance Unsafe
VIPRE Trojan.Win32.Generic!BT
Sangfor Trojan.MSIL.Bingoml.gen
K7AntiVirus Trojan ( 0057bf2d1 )
BitDefender Trojan.GenericKD.36852535
K7GW Trojan ( 0057bf2d1 )
Cybereason Clean
BitDefenderTheta Clean
Cyren W32/MSIL_Kryptik.EEN.gen!Eldorado
Symantec ML.Attribute.HighConfidence
ESET-NOD32 a variant of MSIL/Kryptik.AATA
Baidu Clean
APEX Malicious
Paloalto generic.ml
ClamAV Clean
Kaspersky HEUR:Trojan.MSIL.Bingoml.gen
Alibaba Trojan:Win32/starter.ali1000139
NANO-Antivirus Trojan.Win32.Bingoml.ivbltv
ViRobot Clean
Tencent Win32.Trojan.Inject.Auto
Ad-Aware Trojan.GenericKD.36852535
TACHYON Clean
Emsisoft Trojan.Crypt (A)
Comodo Clean
F-Secure Clean
DrWeb Trojan.PackedNET.624
Zillya Clean
TrendMicro TROJ_FRS.VSNW05E21
McAfee-GW-Edition PWS-FCWJ!48DB1EFD4059
CMC Clean
Sophos Mal/Generic-S + Troj/MSILIn-AQN
Ikarus Trojan.MSIL.Inject
GData MSIL.Trojan.PSE.17YXG5
Jiangmin Clean
Webroot Clean
Avira TR/AD.Inject.ghjpw
Kingsoft Clean
Gridinsoft Clean
Arcabit Trojan.Generic.D2325337
SUPERAntiSpyware Clean
ZoneAlarm HEUR:Trojan.MSIL.Bingoml.gen
Microsoft Trojan:MSIL/AgentTesla.FF!MTB
Cynet Malicious (score: 99)
AhnLab-V3 Trojan/Win.Generic.C4453000
Acronis Clean
VBA32 TScope.Trojan.MSIL
ALYac Trojan.GenericKD.36852535
MAX malware (ai score=81)
Malwarebytes Trojan.MalPack.ADC
Panda Trj/GdSda.A
Zoner Clean
TrendMicro-HouseCall TROJ_FRS.VSNW05E21
Rising Trojan.Kryptik/MSIL!1.D5BE (CLOUD)
Yandex Clean
SentinelOne Clean
eGambit Clean
Fortinet MSIL/Kryptik.AATA!tr
MaxSecure Clean
AVG Win32:PWSX-gen [Trj]
Avast Win32:PWSX-gen [Trj]
CrowdStrike win/malicious_confidence_100% (W)
Qihoo-360 Clean
No IRMA results available.