Static | ZeroBOX

PE Compile Time

2071-08-20 11:10:47

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x0009fef4 0x000a0000 7.99463093072
.rsrc 0x000a2000 0x000015f8 0x00001600 5.40076952317
.reloc 0x000a4000 0x0000000c 0x00000200 0.101910425663

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x000a2130 0x00000568 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_GROUP_ICON 0x000a2698 0x00000014 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_VERSION 0x000a26ac 0x000002f2 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_MANIFEST 0x000a29a0 0x00000c55 LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with CRLF line terminators

Imports

Library mscoree.dll:
0x402000 _CorExeMain

!This program cannot be run in DOS mode.
`.rsrc
@.reloc
81;> gX
c 0(mXa
ZjSef
ZjSef
mf c^6
;Ca UgQ
v4.0.30319
#Strings
aww.exe
<Module>
UY8uo8VLWML98UIpua
Uvrhb8I7jqAMNcyMVh
ValueType
System
mscorlib
fbr0yCWQu8vLH1vlsy
YYqoXJHiB4QeJLBZm3
EqBfsJFAvxABwr8I7u
saO19xhxVo43DElGKU
qli0KkRE7bQBQV3ITa
ygZRQcNptNDc0urvr4
aH0bh8E0j2vT3c8xrq
gKsKRfPLAthV1Dhwp0
Object
qmrN8r7XrZcV9ugMo7
Mq1gI6zV0rLvQKEZXN
WvRmNFMYHBrCXALAbDc
s01T44MtaEdFa67wSrR
bBVnqHM2pefhQuggFhI
vKWhFsM0xdXLAsTICTH
q6QHr6MX0dlimLQo8HX
<PrivateImplementationDetails>
<Module>{939af396-f287-46ae-b4fd-87425cc46b40}
lVVDhldW0
DTmBB5UfK
fEXMgeMc1sQBrURE5PQ
byrX2wy3f
Jpqut1Q7B
JTY9nRkex
BfSyChhdN
QhE0vUqHZ
xgtafEMOVJ4w7UJDJiQ
Boolean
PPt3UOMFJPAKxEmcC4P
JN1cJRhBF
JvlOps6lP
SCx4suMhFrbAcOQpqOC
SnekKGZVk
cKijJ653l
x0f3FU5hm
Woe54bMPg
uPDqKmvRY
VP9scpMnS3EKmQNZZ24
kxSgn8MUmsUWoXUNVeC
NVI1WNWZ7
Fa7TiMdi3
rXoZtLMrV6FCeSFwXXy
M5IUBBGH1
UoLrQxYcj
pnuiQo0X8
y0M4N9fUQ
Wx2nGvWCA
Uen92vMeZtPxdpNlSDk
fgNptdMiG8CHpHy1XbK
brrL7pIU8
nqTopZfWn
O5XulGM4BdD5g55OIMw
KlUZYvikP
oVivohw3H
JYTdIpCsp
FUvlen0To
lN5Q40KfM
p2PUyHMw05fpEWu6PXH
iBE3TSM1F0KbnEVkT0E
l6BmwuPAv
FqpMKAEFAP
SUkMM5oiXO
zpOMVvG4r1
Socket
System.Net.Sockets
hX3MI9E4sY
Action`1
String
R4g1REMCNUNb4TKZjSq
AppDomain
get_CurrentDomain
ResolveEventHandler
IntPtr
add_AssemblyResolve
Thread
System.Threading
ThreadStart
AddressFamily
SocketType
ProtocolType
IPAddress
System.Net
IPEndPoint
EndPoint
Listen
AsyncCallback
BeginAccept
IAsyncResult
CB7MGbvqT6
Assembly
System.Reflection
ResolveEventArgs
Stream
System.IO
MemoryStream
ToArray
CopyTo
IDisposable
Dispose
wLDM6g1Axf
Af5MpdASfh
bsgM8rprp6
EndAccept
get_AsyncState
BeginReceive
SocketFlags
M2hMa018f0
RijndaelManaged
System.Security.Cryptography
Rfc2898DeriveBytes
CryptoStream
SymmetricAlgorithm
set_Mode
CipherMode
set_BlockSize
get_KeySize
DeriveBytes
GetBytes
Encoding
System.Text
get_UTF8
get_BlockSize
set_IV
CreateDecryptor
ICryptoTransform
CryptoStreamMode
RuntimeHelpers
System.Runtime.CompilerServices
InitializeArray
RuntimeFieldHandle
poIMJqqbav
GetString
Invoke
IndexOf
Console
WriteLine
EndReceive
ToString
kwSMghk5r9
trOMSJpiVV
S4XEDYMAGm1u4EU0HTX
GetExecutingAssembly
c3eQmsMLJiUftYbfpcA
GetManifestResourceStream
RVANB7MdnK0IO7s3ZJV
HKp0dfMl4gmpSuiXQOk
trHiMEMoPGa4hY2sptw
set_KeySize
j13RnZMErdpOq4tpxrV
set_Key
AxtY7sMPyVpqkDoE2Da
get_ASCII
yAcdB2MmgvPUhf8CdeZ
URhM9TqLrc
VjQMyTg8KN
McvMxThOdI
StringBuilder
xlEKRCYGYYDwok6ba1f
NQ3s3gY8oRoyNXX4JqE
NHSLtiYarT6uV05aF1r
ERIMB4PTOa
r9YMWjYnHN
.cctor
lPjMDNtGeB
ClassLibrary
Uxktfept
eIROhaY6hbC8MNWYoxm
f6PHSoM7JcJbn7Q59Tl
pXRMu6P09N
System.Threading.Tasks
get_Factory
TaskFactory
Action
StartNew
YmvQNQMzkmBkspneE42
FcxODHYKgt2HeK5rbjf
lpPMkeoN9W
jBiMjaJtAN
YGLMsSQUw3
lSh8q2YpxAiAHmNllZH
z85MHMtalq
Exception
IwXMq4UUUs
sdGAbZYf1hFnm1oqZgs
ORgudRYVCjhfZN4o8tZ
66840DDA154E8A113C31DD0AD32F7F3A366A80E8136979D8F5A101D3D29D6F72
m_ec0d54477ad54d1d919f573c0e207a8d
m_ff8c3a5149074da2ae8e5a2e0875d21e
m_5ba8c22aa44743e0b2b037f545900a76
m_581a402cd194479ea38ae152f02d92c5
m_188d1cf1aa5048f08e10f9f58f5f538f
m_c4d8732f62df4b8692b8a96db24376ef
m_334f9e86994b48b3945924bd56738fc3
m_37b17a50233c44ca97dcce8f05c2544f
m_dcc69731617a45b8b5146a3f67bb74bf
m_f5b027deeb104f8788bd4f911d533738
m_9d44e36333a24c2ea0817b72732103cb
m_b338885959654755803919bad93ebdde
m_d761e5dbc4da426f92d254167d794aad
m_b53ddef67af94877bcd2d488dee6deed
m_ac2c155712984b93be526776eff19f8e
m_55cb32a507eb455b9b02002cbdd261ed
m_4645ff1f29af4003a1b7df46c012b454
m_71a9c145419c4d17919307d86a672d9a
m_25a4be9fdffa460e9b4d1cd5e6cc418c
m_e0cc2baecd2b40f8b9b4ccdf27f23720
m_f364752e35e5418c98d2d8cb2e126d08
m_21ae186c8eb84b7b9c02c4a30b0783f6
m_9f979f35e7d548209ef27c7b3cddd63a
m_c330eb289f7443caa845d361548ceb34
m_2ae75e807745433f85341d1102eaa30e
m_77c3755f8ece4d699178b018302a2c46
m_518fc6c306bc4fd8acd8be023a468dfb
m_f2226534adc14e3baa10452179ae401e
m_c74e1379d8024c6dbb2351d30a58f216
m_13b223a754174b7885e0c0235f1128e0
m_e3ef859a2b604ab1ae1d2f355a4de6e8
m_4ec3fb9e68ea46889cf769ef0b79533a
m_dbbcb51616254d91860b2974178f581e
m_15340a3ee6b64e2aa12a5969137638d2
m_3231fbfe586e4916a6475f81246709a7
m_3dfb95ef783d4d1fb60ca0a4c7a419d7
m_970811f539654056bb55370d1846bbf3
m_63b597dd4c0040cc98429c9f464ebda6
m_9e402515fdb04d57b5e51731bb37a26f
m_711e563524634fbfab373ec83370ffcd
m_74b532f555834652887ebf35a3928005
m_9650e1c44d7549c8af965a83cd8e606f
m_84d51e1ae4cd401fb90a0952657fe161
m_3a16e35f215e425f8f028c656353361c
m_ba66ad1d6cb743a2894bb6af46b5ed65
m_968dd61256254669b9a09b8fb8341142
m_516338f5682f4c09a70b6eb946434e1f
m_d710cbc096184e3ab8de79ace429cce9
m_4dac3315238541fea222fffed5787633
m_1d4e02b442e3498aae72d645e0b71af3
m_46ea6faa67a34425b32add3e015ebde9
m_6b1d272186e9472283937a5a194195e4
m_db02953a3d144927855a32cc67cd0c14
m_8a110894dfb5461daf3ea4914b14e182
m_1bf6276f34d84e629b5d35b36e8adec5
m_fac5a2a5c9b8436dabc430b047324703
m_90f3adf70cbb4d6fafaf07a7f2dacb0d
m_b2f1ca04600746bdbcc7155deaa65972
m_fe6b64e759284e59804fbded1489017c
m_0fb526a0b2a744bcaa2a1fc4afdd5142
m_c2fadb171215445c9c7d059722a09c20
m_af379a5756024300b5e64a9100fe0799
m_30c1014b9d824db98cc943bf3055cef9
m_1c0de0a238ef4b61bde2fe157df0070f
m_595c53ee52a64a4792d3ec23665e0195
m_b745584d5dff4061b2e8e21fcf60272c
m_34f1f0d300264b7fa69e5c1194b2a00d
m_6bb9c5d77a304b739d5b64d7b4253656
m_5cb9d347b4da400b93dcfec734d8f013
m_7bdc955b28b94a56a5828544d0263f8d
m_84512a4b7daf44d5826da10ecd75355f
m_03c8f46e21264ecfb827fbb2f775175e
m_22d162ecc0ce41ff938b15530cce3571
m_50bf72470e0d44eea35f35b0a4023eb3
m_81f9570a09a74183b56a7d19b502ffee
m_ec0b28e215a94d218e666ec5bb8c2580
m_0be26922e04f4dfa81a83fbc729119f8
m_828ee55bac9740afb6c1d618e3dab3c2
m_ef28113eb76a43f795c6823ddc77fc78
m_7b76d5adcbf848a9b19b214f07ba113a
m_cdbef694cf3943b3b743aeb469e4631e
m_c84a1573edd74790b55e789291e18b14
m_4cb417dde83c413d9e593f2d26f288f6
m_5b05f36cf2034897841d8298c63eca85
m_7a168d0dce604a05943981fe7ae5ed7e
m_d45ff5536b874b8d87ca39638a5a9b12
m_2e6fa1b4173e47c2a8cd04a76eb96fbc
m_8a772ded6f234108a30eaeb7db2543e0
m_e6687483da59412aaefd5e54031b20bf
m_3c6406224c63412192cbbc366235df8f
m_6a4e9535111d4824999c796c6b408cfe
m_bbc3edc39bda4300be2002612403acfe
m_a250aaf855544c2aab1f15546455a906
m_df48909dcf744194b9e4381a96c6c559
m_d9eb137d8f9e43ac8aaf439cc6e75271
m_04b1959a4dbc45dfb57fa342ca2d2e6e
m_55ab5392dec04ca4b79125bf90a1a84b
m_5e57e0866f974671877353413fb57818
m_d4a8ce2d27884cc19a9d56cc039ac684
m_90c7cb728db643eb9ea98b73cd263344
m_b85b6edf29744edc808ac1d96c03ba66
m_71e41259527e4359bc6dba2caa14ce4a
m_516d01e9e80c46e5900971bcc87228a4
m_ed5625fced3646c58ab6d1c1d9cf0aea
m_3d8b0dc034784430b69000e17dcfc900
m_6987ddf98a48492b9066cfe9c406cd70
m_fcdb4e61ae764236a10eabc74430d0c6
m_e960b4433b8e47ffa98eee6963966fb3
m_c8c7739b37174549b202bdee275320f0
m_bf0b8a5d7ba04c138246654d52b14aae
m_aa6faf8cbe994a2c9cf6147826c2e160
m_ad6dfea5228340b4a545b3236afd482b
m_0467bcdf857340dbbde4ebefaca0bd7f
m_75176607c99849b08303b1643c4cf925
m_94aa77d54bc848eeb6a94779f3bc62f2
m_23488e7457d14d6e9282705eb35f92d9
m_4b2ea955378243e08a2a89d026c6a93c
m_79a61c430b0b49988e5216394bb54455
SRGYtxYIpWCtUquFyjH
a281c25227cdc442a9d58f78a28c731c8
BPLUyUYuAHvwku0etyv
e3bgyRY0hXjfaKE8Jhx
gHTOG0YXpvsZ2CynfmS
CompilationRelaxationsAttribute
RuntimeCompatibilityAttribute
DebuggableAttribute
System.Diagnostics
DebuggingModes
AssemblyTitleAttribute
AssemblyDescriptionAttribute
AssemblyConfigurationAttribute
AssemblyCompanyAttribute
AssemblyProductAttribute
AssemblyCopyrightAttribute
AssemblyTrademarkAttribute
ComVisibleAttribute
System.Runtime.InteropServices
GuidAttribute
AssemblyFileVersionAttribute
TargetFrameworkAttribute
System.Runtime.Versioning
CompilerGeneratedAttribute
STAThreadAttribute
Ntycov.Uxktfept.dll
WrapNonExceptionThrows
$34eea8f9-9033-428a-9303-2572dc1bde7f
1.0.1508.40811
.NETFramework,Version=v4.0
FrameworkDisplayName
.NET Framework 4
SL(($yc
6y5|49
e0_u<8
N<>Jau
8`UC 3)
Hl^H Q
\X8aXJ
g\Bs|ZB
frFpL0
Pv&LW&U
Iq&i%@Mh
5WN"aF
#FhEZ0
"x%7Cz
GY#:p%
<:Ps=b
m3@aUC_)
T8m4sZ
|=JF9L
RQQGeM[P
l/d*1R
|R$N=$
en'oo"
1Jj+rM
T27k#*
nOwYnv+
/1J|@
])g9@?
-% D6$6
uAGy{h
,4(]{j
3+D46l55<
p.`*u6
t|:DiqE
FSOC<'
8jrqMB~
%lP{j0
Y1.';ws
hYCSo|3
l%yYUw
/I kb]
w`ZfJSP
d8&$wYv
A@A|0`r
=f|_JA[
4sf$DM`
|C.9M,
t14uf-*
mXfx`c
Lbc"$L+
_FkaHU:
o~'t1zK
/;rq>u
VK!OmfC
@"q2H]
5HbD{|n
b=?}K%
ZdJSj?
XN!w|f{
$r3l\*A
J[&]CC
@UiV
c=@DJT
':_W\9
UB:S?G
$aJ_fl_
^y/Oog
^ %v-Or
-uo|h8
[%;j^W9
$Fy5.DGVl
:""88/
G"b+<A
qY)bZ@
Is_@/;.
*+L-2)`
\#a fE0\
kA`#F.r
|j^g`a
'O|Dl1"
JY9)O
'<(j),b
5'm4;V
/9U^71r
"H9b>Zx
b8OarX
"qZrE\*{^3
w/7[Iw
+%gJgn
Nr!"vn
x7IcCK
HK82S7
~g1Z67
$"UsC#Y
j^!v8
/4."--
[F2|5U
]oh.Z/#$
:f_4%D"
G@!et'
G.4jxZ
.]:h)v
7-^LG6
'M?p%>
8@yoX-
-|kKwL
n2~P{~
fp3FHkR78V
2v-[#r
Edas*6
<E3?M2
B?257"
U+jcA
QZqM,vq
NFiFH'
&T,xY)
}~&H`?T
F3&q-v
$n`w2z
sKti>'x
%C3Y0%
#1Vq#C
j6}\oz
G]!*g6
N0+*o7K
~rkCuKP
u,ri8)<.a
3648JB
RQWk8Y
{}A.@N)M
~)QN@,
T.UbHK
2^Z*R0i0
Z!;s<^
Jc}l/!
vO#XXc
,v tH
ewy<ca
#t=najco
PE6Gt^i"
Rc_S=:
:%j-S1
Lu~}5LO
.LP.9F
NoF]X*
W7Z`1-/
u#Dx6f{
do-/nY
Fg#=A4
NlA]6o
;`oO1]
Aqo>p#'
tmRi,a
;=DLu*
B~q6$-
4$,w90a
[2Ge@
$;J1%}
lP`~g*^q
KGblD`z
[QP::O
u_zJ?N
uDC{/C
yx9_I|
n)$-:+z
+8(fB>n!
m{S}IM
VoIcH)
Ncga>NT
EPo!}
yDv&uS
*'0x-{oo|Om
fB_$h@
=SLvgc
?KdI{J$
=8\9]6<
M"v:'8%&
%.U1,}
Y6}V0m
hulw:/]
tfS\I?d
Hw9J?
;%TO--
}7D1dL2B
W/j\t9
KU)Mhm
TiNhH
PUhb"A
IT(Ann
w2|:nwvb
k,<Lpt
AYS>:OU
&VFm1o
8eiw2r
`$[v,>!
Fm};NT
(`m<D\y
5hz~.
6\5 5d!5
m(i4x%
bTK9gUW
Boz`sI3
XIetF[
)!#h4Ea0
e ueYr
fnNwAsBFC
@NzP+gV
)<kWW
s[DK((
xz%/WC
+'8NF,c
=Qq0-p
XNi!|L.
F`nn!0
fGkJQa
km0).Zi
=[i_t
TbqsC0
b;[m,OH
S@OyAc
{t!`\P
#q'm~
b5a+l^j
[:pIJfw^
r")WO
\3"0K2
]\[f~O
[%9e;:MB
Et[koZ:
k0-TTY
/9$70"
sn6Woo
vJfYwgF
=8FP%x
$tdMb*
YQ6ouP#x
/y5JL@
Z"/?>o
"mK8)d
\WN'&Q
k2em4n
n-it4@
2uG\l_
&i)?i_
}'4uJ?g
o?v7$%
Os+7s1
Rlb Ro
W*RQF<!
.&#5|At
f3p3a
nqV+Hz
JF3?Du
z5zfTf
1m+0W"
k>UM!l
u-H{*~
Rx*O|??.
2<~.pA
.*(Z,GXL
dAWIXQ
}gsJ/0
bw/*I4
QZ5(Bx
i\@jGb0/
|Cv]y_
X(0 F}%
A-_S_"$
;To$Ai
s^` ]5{
tU^M\.
xcf|fF
3hNH|
tspVD
OH5=<Vr
9$E*Ko7.
&W~a<t
"}95$Q
I/\$c
O=ONxJ
[fmXV,
8aF4N}
2XOGyJ?
XBabz0
v5Ny7o
.'L})i
R++sO+
I0jNid
/$[{N&}6
/oW5CQ"
])D}3TY
.N=Q%Z
T70_ec
PFPjIW
)D1~O0
n_$YDq`
=9AAfZn
*,{{c@
F^32.j
%TjGmC
Zd.DF{
xzs6gB!
8q;E%jM
j3O]`w
2 NZ~
J}hc>Cb
.dI'px
O64},m
%&[P}Y
B$-<2J
?s$]=
k[9VV+!
7"xX#o
rPA^?E,
l29/;:
auRZsa
Pkw v9
E) pOSs
ebmHDB
aE#O{}
|JUEkZU$
F(ns9w~
WHrSM,,I
|i}6BQ3
}-qs4FTZ
S'`}?Xlff
EQ$YY&
8#os06
@*JOcBz(
R/a=0J
@xTlZY
jOusDt}
9w0P6F
QEOXw
A8\JN+
/uls"2
=KTZM,
_<OrB2
bBz?Bq
$9%wWD
Ktqb C
pN7c;5
X5iOs~t
l@2uEX
)pjg;D*
fa|dW/sY
e@:;Ea
:v`Ew:
Su+#t4
_TL]KZ
{+bUdR
,[(R`2
&5mr#w
z8Hw"p
Ax$_|#
C{TH!1D
9]w,0cCQ
"k]aXG
!c!zlKC
T9~w#DM3
jt$5b48
dAi? x
]pwOIQ
J3KPOp
:_c0STJ
a]_h@g
}9_ d-
I'G&Jw
V8/#[d17
*E@UCBQ
G!uZ!U8-
Tyb>4&
y.M5md
1F#tfE
xxJZU3
u{HrK9
%m7,b3\
]PC4`(PQ
*iY2<-
LU;FAQ7
5si>Q^
FS[|gu
F A4Cr
TEwk)^&
o9i-S:Jq
)LsfW,
rR1kuu
g_cc|H?
"+u.!hW#(
2Xh68c
#owJ"v
qI-Oj
q$bLwr
C[3bXls
$slx`TE
#J:x,b[
T(tQG%
@viD|
pa[v*r
Ie6zWw
?;&69w
]yd=Mg
_bdblz
`_cNKI*
z'\C.`
+5]LLC
[?]OYd]L
z'/J 4
jH!hC!P
mdpG?<
w$,NfXa
W?O-,V
J0LGn4?
e?*8:,
~KOB]M
;~<?8^|aMw
SWPb5\
iDmg0
FU`*C#
+u]zYl
ApXLcc
7S?Tc<
S).={B
Y6'qn(
j'Hi5{u
hg>aO@
sD7Y1c4
unsNc.d`
UX8Upn
N%X@[:p
b-9;b6
`i7V%zD
.H=NJG
dEU<}&
X1c"'{
1>v`8$J
!U#$K@
fI!P1N
H4Z]HH
k5mrzPn
Qkn&zxKe
(*UzPT
H)hx`E
<t,N\@
Vk586v
x wc^"
rf^&S&;
VeJI8
X:H|d
XoL|4FX
z/m9t+
/Nrfr@
s6+<-,
{&-`gmu
rpL{nf
k1b`gy
%ehJgu8
aiGlTT
s'kd,}y
F@XAf/[
6Fi$]`
TxT):n
N4XyKd
]Z8`V.7
nE<Y'H
QG?Fl!ke
D~D$$T
yfXveF@
a)1sNwL
!m=Eak
^ )w5)e
_"H4f,
R#U?vf
wo85'vn
T5oAtl$
eHOvF>
5hm@V%
nqDgpG
1e+d>/<
]i0:q)
EU\%dr'h
6X5};l
v-g_`@N
uz 1>Y
'H>5|x
rt>j.
;_x!sw
UVf pu
K{6Xo,
-Ctx9q
;%_<5]
!dx-|t
3oJJ':"
xM&`)Y
Y_PeWI
6:!P =K
&J?U\]
.}C6^5/)
rd*8V+
LeM<:4x
&w~TOF
hm1\F+
a^EL|#zX
!t;MPn
24Ukkf3R
tkajf*
6nKm2s
Z31IgH
mcsd{r
Sk.D?2
c~F$*
Zezy9S
:GI}'}~
9,Am^>
n##rq9
rSVA<H5
8jLi^3
/&>uuA05[i
gldSdANqU
&/L@%`
qe;) &r
;?Wp:V
/uK3tL
@I(iR3
A:w/~`
tsEx3s
B{5$&P
5<_`2D
14m(7tA|e\
ex{3Zd
E w_70
S&*J4WWn
qV8(\^
$=h<DN
njEmE8
*f-|X9
H{EF:
xhH88v
+6uG|ew}/
hXSp6+f
=^cw-I
;otq;[$
cE>QU4
Z^a<fn
vK]L8b
3>i4c+
9uI@4
LAR?a=
sDg9h-
`=t$}J
8P77}
/YQFe[
w39)i=
1O#t)*
<4Mc`7
VmVlo1ML
|sb.ex
u&D_'<e
DO?V&F
n^RcfQ
y{xu++
4-psFC
+kU4Xe
F'X%0+
?"gMoBQg&
P0_ixD
(M!OO!
j(LcT7lv
Kf>*$1
h,-AwN
b93==/
2,]@[c
mCS)m[}
{;yMCy
PhS%gE|
]i2o%+
pgUt"6
|>LMmD
L-#'0?Q
?g]=zP
e%*,wd
.G}e+P
ibuF(8,
rz;$pTY
"I}Spz
10qS[F]
A";x$S
]sq7f_/j<
!x4e&s`
/ki,)X
-0QSuB
X,E(6V
$j|*^nV
b;=gY~
;diLr~
xU-F7*
]b?k*C
%xU|0M
?Rif)2
|i!b355
)BvGkM
!:C9Y1
|n`gINaD
M*` |6
HS7VKg
kM7Mp#Z
;_~|qI3
%l:(xs
5FAuh,@
y%Lk*-
1U L&|(
7eI,#p
j_QT&V
9#fT+,aM
|]{vU5x
9 g64:Iq
7X*NKuuE
>%B5RI
cUNIm>9
~+~xyU
Es`366
T^q)Mw
^oD=e0
s1Qqk#
[2+<d{
T7Uvz+kN`|
9U8*u"k
,_?T^\Q
g=8 _7/`d
77FD6R
&eHA@@
Rb>Ca8g5
=RJ1Dz
*|l,-C
1*<pJb
"b1mL^
K{`?B&
pWA,]S
C~RVNA
kwce12
1`x0f
<tU'5g
cxqA16
-RY>K#
tsFG'$
w]Cwa$
!nR-*'
S?UF^S&
H%x!xX
5`tT=WV;
eDs$gW
2u043$i
T{hd9^
"RAMYOO
%rf# g
}{h@=/
Up="|i
JDH[~:&
M)$AZ<
p]eGoy
b2w>Vw
SFxcKA
7DTU~
#8KHqy}h
+xL Ni
7KBIU$
WIE*MU
|0aaJdK
V%$(8Y
NXiJ~oD
VS X3=
B|>fE+
&q=l?$
D/j,1x
_,0PA(
*fPuox9
@|C79w
XT}M_,
OX+M>$
/pZ4KQ'6
9-){E;
!T*".9
dEw`>;
qCA]C8
:F3u7|c!
<j[D>N
UHZblJ\
*&}iE;
J4{&<^T
"b4hz&g
\nt//nB
/rNiEEm
MW*Bo0&
pM7#=aI
8u6}s]
^Oyd;d
GAU\pBw
{.3M3L
mVh`23Bz
$[!K N
:[a*sY
H&S_(m#t
dK,A.
Yvv"r4
Z:690=
I!I)BX
4z:nwig
=PSuu@
F4*DK:
\>YZ:MM
/Qc?#Y
!O{:pX
YMSQ/c
o{>I:9
bKKhDB
my\(88
,LTNo5V
!@=r_yk
SJStqo
p"{*_\
@?CjzY
Sh/k.B?
PKzJ'E
<bqqyqt
~%2""\
{q9D-ej
Fe-<w/
)$>PP\
./G.Nvz>*
`W.dQ,
'UC3J
m1^-<9
}4rpR8
#IM0OJ
tNB1\?
7IVFN|
ngq0^J
+U.poA
e[HkbH
VNAqI
wKQv1P
^&E[Gr
("uU*]
SnxZ2FA
4>+(glav
0H[fB9
6h!Psq
CK{fwm
DSMHW3
Rb,R+i
3!:\}Y
uZP}_C
z!a"h>
OplWha3o
);P KE
&%6Ky4
T|&-Bi
T/(/HSpRW
AR?R_f
6i/(cu:
{4 ;j,t
JBI\\T;
[0iq-`\{h
B,O[)P
'^#*E]
L"[\u\
>$0'Bq|
Mcm<GF
<I-[uC
@(MPsQN
n>fvOk
x"5`O<`
^h8u)b!|Zt
x?3S!L
]g0m/
]`f&D'
5Z!_3K<q
hmD@<
Z\dXe;L
v52-h_
1;GM*9
&4WmS2
fpo=Yd
(gKyt"gL{D
Nf"yay
_4]hK)
|Y''KD"u#<U
?j`P_/
k<::uG
zd#X(/3
W$C.De
1_E>NR
\z1&Sg
-0`}j=]
hCf+h3E
S]]-*Z[
gU+6.
9)bUi
-gZviwUD
jp<r5
0WE[UV<^t3dF+[
kR]fv\
6g,.+,
R#|wW)s
nuw5~\
x_f+y~?
0&S,>_s
%28)y8
57g>"R
ICY$$}
V}oLi<
+vvzmH
;>+gH[
ZM=Q[(
OpgJ\3M
N'J\{yED
.C6I'5x
}2SHa;F
EaKFa88/
Q#PK0E
-F5@}b
T4Y-n/)N
:9=3 -
UF]ZWx
{?h&ba
8gbLj7
f*!*u0a
GJ]NFk
2|fE{*
?'BN-@*
;O"apw
2>HBJ2=J
8Pgh(k
i.o\8.d
g5i?#2
n($rBC
CT8yZpJ
]CAIuv
)o =Udm
fj7r{+
A$gm+dz
FgGV,AV
'C7}$w
OoPSY_
Wzi.&j@I
03V4Bg
P"*4QO
-W$h|q9F
'5uR[=
:C=F?C
cZe%:(
J\#@_*j~
';7M]~
td24:`r
M%x]^$V
?2/ON$
9Ktx^k
GVPWdn<
.Z}vy2
^GFQGr
(+3:0
4RWWbro
m"qM<*
c|sXMU*
nQ;rP;
UuP2^TM
!n38[II>
4#^Q7'x
[FBP[;r>xB
JJT,\dK
tkA~>K
xr<1}1
+)@/:]
YkZZZQ
]x[C0r
9:qk(3
joF&..
*2O!CzP~
DP)%U2
-o*5s,
mxBhYY
4#{enlx
vB_7gZ
5ZnD;M0
2hbJa\
q8:V6~
#L:T '
LY35`E
I)bB`
hh04h(-
CJoAftZ"
/gMQLsG_rn
^@lK:@q
|o<$!7
sydTfH
bBV1liU
-Wv\gS
FU2W-m
#zYjg9cJ\P
UzVw1bV4
Dh7Szv
+deq
6Rgm4QL
]5)8M
Y({c`?
aF~7t"
Z0egjAt
+bd%hYW
O( S/]
`-thy>
V/b[-i$
>18YU
luP2ZN
UP}/XT
cPEF1<
|0:^P3
r.iO`SU
j9Ny#c.o
[/+,"d
WhTL_azj
~DtD[T
<0U>O`
IB&<RM
"uLG!u;
fX(5D&
_%1AD4
GUOfC_
HD4^`Lr
v)F7r!
rtjt<Pg
D4ehEv
{:jAso
quyh4pFW4
P\[_K8X
k$KHy]
:Zf>BO
,{)^'T
CD6o%yo
Gu`J=!
5)S+pz
p!5eU$x
Z5l<Nv
A+yc._
~Aj{eG
o;x+CF
uIG]p2
MO .!'
YB<}#N
,:DP9j
oAcK}i
T:VcI
JgW0hT(
VZIWKd
0BN.V3
szC+B
uD4e<jW
Qtq,L]
IlkvC;z
vKY+a
e;[^k%
hA,\_~
RkC>:6
d->6-h
8*fgA%zMD
E&G~Vs
A'%;xT
g/tj$x
b3t.lt_
d;2O#!dr
w/)2=(
#mL5>?
{b6SH,
UDX/BSb
miz7nVRuC
lDge\1y
6\4ErC
)WF1\_
C43T}*E
O6+_c|
o:Tc/|2n
Z7oZ}
yTIacJ
;VJqtz
59OM'`C
hM@9:`
v&<s4}
im$%Og
^A.e%l
sRRm=AdT-B
#!m('?%
4u9*`R
fea`GY
e[j$MR
'q.+u1
}N,"h8-Q
&vZH-i
Kzq6yqh~
R{/?'`)
TR;F]L
eYT6vA
V^s<"8l
y$1(fc
RXct+@1
fk[<PJ
w[ueRnM
smp"!i]P
Gu9s-hi
V `oIs
b}\[gN
w kw@5
NWXXGY
^U-~Ba8>
Tk-[=t
z 7N6%
xt5}2J
@@8Y'b
o;Lz]5
4N3K5@
Xt-:Td
5hohpdh
'MhFf@
W96tX9
?-{pwp
\8-V51
==tiSU
yHC-^/
!,!; i
n$2@xg
C\RXWw
I~#6m{SX
j'UD>UHz_
Wn31%Pp
*WyO/5
TwQ:aAg
KEhydWs
eMLA<{O
rJJ#pP
{ngVWj
u;`_XH
Qed6YVN#
pC,xpQt
et-fb~
E)'XeS
}n~2-|
p'&hV`S
ac[ou_
qSK J
=T'_Hyf
:"T) Ud#
Z@}1r3%
< Y"Hc
TA\T(y
_CorExeMain
mscoree.dll
<?xml version="1.0" encoding="utf-8"?>
<assembly manifestVersion="1.0" xmlns="urn:schemas-microsoft-com:asm.v1">
<assemblyIdentity version="1.0.0.0" name="MyApplication.app"/>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v2">
<security>
<requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3">
<!-- UAC Manifest Options
If you want to change the Windows User Account Control level replace the
requestedExecutionLevel node with one of the following.
<requestedExecutionLevel level="asInvoker" uiAccess="false" />
<requestedExecutionLevel level="requireAdministrator" uiAccess="false" />
<requestedExecutionLevel level="highestAvailable" uiAccess="false" />
Specifying requestedExecutionLevel element will disable file and registry virtualization.
Remove this element if your application requires this virtualization for backwards
compatibility.
-->
<requestedExecutionLevel level="asInvoker" uiAccess="false" />
</requestedPrivileges>
</security>
</trustInfo>
<compatibility xmlns="urn:schemas-microsoft-com:compatibility.v1">
<application>
<!-- A list of the Windows versions that this application has been tested on
and is designed to work with. Uncomment the appropriate elements
and Windows will automatically select the most compatible environment. -->
<!-- Windows Vista -->
<!--<supportedOS Id="{e2011457-1546-43c5-a5fe-008deee3d3f0}" />-->
<!-- Windows 7 -->
<!--<supportedOS Id="{35138b9a-5d96-4fbd-8e2d-a2440225f93a}" />-->
<!-- Windows 8 -->
<!--<supportedOS Id="{4a2f28e3-53b9-4441-ba9c-d69d4a4a6e38}" />-->
<!-- Windows 8.1 -->
<!--<supportedOS Id="{1f676c76-80e1-4239-95bb-83d0f6d0da78}" />-->
<!-- Windows 10 -->
<!--<supportedOS Id="{8e0f7a12-bfb3-4fe8-b9a5-48fd50a15a9a}" />-->
</application>
</compatibility>
<!-- Indicates that the application is DPI-aware and will not be automatically scaled by Windows at higher
DPIs. Windows Presentation Foundation (WPF) applications are automatically DPI-aware and do not need
to opt in. Windows Forms applications targeting .NET Framework 4.6 that opt into this setting, should
also set the 'EnableWindowsFormsHighDpiAutoResizing' setting to 'true' in their app.config. -->
<!--
<application xmlns="urn:schemas-microsoft-com:asm.v3">
<windowsSettings>
<dpiAware xmlns="http://schemas.microsoft.com/SMI/2005/WindowsSettings">true</dpiAware>
</windowsSettings>
</application>
<!-- Enable themes for Windows common controls and dialogs (Windows XP and later) -->
<!--
<dependency>
<dependentAssembly>
<assemblyIdentity
type="win32"
name="Microsoft.Windows.Common-Controls"
version="6.0.0.0"
processorArchitecture="*"
publicKeyToken="6595b64144ccf1df"
language="*"
/>
</dependentAssembly>
</dependency>
</assembly>
127.0.0.1
Cahcol
Ntycov.Uxktfept.dll
ooWW@@
Fo7W(@
UoFW7@(
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
Comments
CompanyName
FileDescription
FileVersion
1.0.1508.40811
InternalName
aww.exe
LegalCopyright
LegalTrademarks
OriginalFilename
aww.exe
ProductName
ProductVersion
1.0.1508.40811
Assembly Version
1.0.1508.40811
Antivirus Signature
Bkav Clean
Elastic malicious (high confidence)
MicroWorld-eScan Clean
FireEye Generic.mg.8e87de15cd3da124
CAT-QuickHeal Clean
McAfee Artemis!8E87DE15CD3D
Cylance Unsafe
VIPRE Clean
AegisLab Trojan.Win32.Malicious.4!c
Sangfor Trojan.Win32.Save.a
K7AntiVirus Clean
BitDefender Clean
K7GW Clean
Cybereason malicious.9ec859
Baidu Clean
Cyren Clean
Symantec ML.Attribute.HighConfidence
ESET-NOD32 Clean
APEX Malicious
Avast Clean
ClamAV Clean
Kaspersky UDS:Backdoor.MSIL.NanoBot.gen
Alibaba Clean
NANO-Antivirus Clean
ViRobot Clean
Rising Clean
Ad-Aware Clean
Emsisoft Clean
Comodo Clean
F-Secure Heuristic.HEUR/AGEN.1129534
DrWeb Clean
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition BehavesLike.Win32.Trojan.jc
CMC Clean
Sophos Mal/Generic-S
Ikarus Clean
GData Clean
Jiangmin Clean
MaxSecure Trojan.Malware.300983.susgen
Avira HEUR/AGEN.1129534
MAX Clean
Antiy-AVL Clean
Gridinsoft Trojan.Win32.Stealer.dd!i
Arcabit Clean
SUPERAntiSpyware Clean
ZoneAlarm UDS:DangerousObject.Multi.Generic
Microsoft Trojan:Win32/AgentTesla!ml
Cynet Malicious (score: 100)
AhnLab-V3 Clean
Acronis Clean
BitDefenderTheta Gen:NN.ZemsilF.34722.Om0@a0HA10n
ALYac Clean
TACHYON Clean
VBA32 Clean
Malwarebytes MachineLearning/Anomalous.96%
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Tencent Clean
Yandex Clean
SentinelOne Static AI - Malicious PE
eGambit Unsafe.AI_Score_99%
Fortinet Clean
Webroot Clean
Paloalto generic.ml
CrowdStrike win/malicious_confidence_90% (W)
Qihoo-360 Clean
No IRMA results available.