Static | ZeroBOX

PE Compile Time

2021-07-08 04:00:06

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x001fcc94 0x001fce00 7.95096038936
.rsrc 0x00200000 0x00001750 0x00001800 3.6171973504
.reloc 0x00202000 0x0000000c 0x00000200 0.101910425663

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x00200130 0x000010a8 LANG_NEUTRAL SUBLANG_NEUTRAL dBase IV DBT of @.DBF, block length 4096, next free block index 40, next free block 0, next used block 0
RT_GROUP_ICON 0x002011d8 0x00000014 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_VERSION 0x002011ec 0x00000378 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_MANIFEST 0x00201564 0x000001ea LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with CRLF line terminators

Imports

Library mscoree.dll:
0x402000 _CorExeMain

!This program cannot be run in DOS mode.
`.rsrc
@.reloc
??F(
--0(
v4.0.30319
#Strings
<>c__DisplayClass12_0
<>c__DisplayClass14_0
<>9__25_0
<RandomizeAuto>b__25_0
<>c__DisplayClass39_0
<shapesToolStripMenuItem_DropDownItemClicked>b__0
<ShowDialog>b__0
<PresentReplacement>b__0
Predicate`1
List`1
saveFileDialog1
openFileDialog1
label1
menuStrip1
pictureBox1
ToInt32
label2
sReverseS3
<Module>
System.Drawing.Drawing2D
AW_BLEND
AW_HIDE
AW_SLIDE
AW_ACTIVATE
AW_VER_NEGATIVE
AW_HOR_NEGATIVE
AW_VER_POSITIVE
AW_HOR_POSITIVE
get_ASCII
LineBL
HT_CAPTION
WM_NCLBUTTONDOWN
System.IO
AW_CENTER
get_jVbET
CS_DROPSHADOW
XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX_XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX
Form1Z
get_WorkingArea
FromArgb
mscorlib
System.Collections.Generic
Microsoft.VisualBasic
WndProc
get_IndianRed
RijndaelManaged
add_CheckedChanged
remove_CheckedChanged
get_Checked
set_Checked
_checked
add_DropDownItemClicked
shapesToolStripMenuItem_DropDownItemClicked
Interlocked
set_DoubleBuffered
get_IsMirrored
add_FormClosed
OnFormClosed
add_DocumentCompleted
<A>k__BackingField
<B>k__BackingField
<Name>k__BackingField
<Horizontal>k__BackingField
<LineColor>k__BackingField
Append
OnPaintBackground
Replace
Distance
set_Mode
set_AutoScaleMode
FileMode
CipherMode
replacee
get_Image
set_Image
get_BackgroundImage
DrawImage
_image
SendMessage
get_ReturnMessage
AddRange
CompareExchange
Invoke
IDisposable
get_Handle
RuntimeTypeHandle
GetTypeFromHandle
FillRectangle
get_ClipRectangle
get_ClientRectangle
DrawRectangle
Console
set_Title
DockStyle
set_BorderStyle
set_FormBorderStyle
ButtonBorderStyle
get_ClassStyle
set_ClassStyle
FontStyle
get_Name
set_Name
get_FileName
set_FileName
fontName
clickedname
FlatToolFrame
FlatFrame
dwTime
AddLine
WriteLine
activeLine
nextLine
DrawLine
newLine
Combine
GetType
get_Culture
set_Culture
resourceCulture
ReleaseCapture
MethodBase
ControlBase
WindowBase
Dispose
Invalidate
Delegate
Navigate
Animate
DebuggerBrowsableState
EditorBrowsableState
get_WindowState
set_WindowState
FormWindowState
get_White
STAThreadAttribute
CompilerGeneratedAttribute
GuidAttribute
GeneratedCodeAttribute
DebuggerNonUserCodeAttribute
DebuggableAttribute
DebuggerBrowsableAttribute
EditorBrowsableAttribute
ComVisibleAttribute
AssemblyTitleAttribute
AssemblyTrademarkAttribute
TargetFrameworkAttribute
AssemblyFileVersionAttribute
AssemblyConfigurationAttribute
AssemblyDescriptionAttribute
DesignerAttribute
CompilationRelaxationsAttribute
AssemblyProductAttribute
AssemblyCopyrightAttribute
AssemblyCompanyAttribute
DesignerSerializationVisibilityAttribute
RuntimeCompatibilityAttribute
get_DodgerBlue
OnMouseLeave
OnMouseMove
Remove
RCbgJ.exe
set_Size
titleSize
set_ImageScalingSize
set_MaximumSize
set_AutoSize
get_ClientSize
set_ClientSize
SetShadowSize
bodySize
Serialize
Deserialize
ISupportInitialize
Randomize
OnResize
System.Threading
set_Padding
LateBinding
Encoding
System.Runtime.Versioning
Hex2String
FromBase64String
MeasureString
ToString
GetString
DrawString
get_Disposing
disposing
moving
System.Drawing
SaveFileDialog
OpenFileDialog
CommonDialog
ColorDialog
ShowDialog
get_Msg
Attach
Refresh
SolidBrush
ForeBrush
BackBrush
AccentBrush
FontBrush
FillPath
GraphicsPath
GetPath
get_Width
set_Width
get_Length
get_PanNorth
callback
get_Black
add_Tick
_ticker_Tick
pictureBox1_Click
add_Click
saveToolStripMenuItem_Click
openToolStripMenuItem_Click
pictureBox1_DoubleClick
add_DoubleClick
get_Dock
set_Dock
TransformFinalBlock
get_Horizontal
set_Horizontal
set_Interval
FlatForeLabel
FlatLabel
System.ComponentModel
FlatBorderPanel
FlatPanel
set_TopLevel
ShadowLevel
user32.dll
System.Xml
FromHtml
IButtonControl
ContainerControl
FileStream
lParam
wParam
Program
get_ClickedItem
ToolStripDropDownItem
ToolStripItem
fileToolStripMenuItem
saveToolStripMenuItem
openToolStripMenuItem
shapesToolStripMenuItem
newToolStripMenuItem
System
SymmetricAlgorithm
htBottom
ICryptoTransform
resourceMan
ForePen
BackPen
AccentPen
FontPen
get_LimeGreen
get_PrimaryScreen
Between
System.ComponentModel.Design
origin
set_Margin
Application
get_Location
set_Location
get_saveFileDialog1_TrayLocation
get_openFileDialog1_TrayLocation
get_menuStrip1_TrayLocation
System.Globalization
System.Xml.Serialization
Action
Interaction
System.Reflection
ControlCollection
ToolStripItemCollection
ArrangedElementCollection
get_Position
set_StartPosition
FormStartPosition
get_ActiveCaption
caption
ApplicationException
get_Button
FlatForeButton
FlatCancelButton
set_HelpButton
FlatButton
FlatAccentButton
set_AcceptButton
FlatAcceptButton
OnMouseDown
IsMouseDown
get_Info
MethodInfo
CultureInfo
RandomizeAuto
OnMouseUp
Bitmap
ToolStrip
set_MainMenuStrip
set_Top
set_TabStop
FlatProgressBar
StringBuilder
sender
DrawBorder
get_ResourceManager
_ticker
get_OffsetMarshaler
ToolStripItemClickedEventHandler
FormClosedEventHandler
WebBrowserDocumentCompletedEventHandler
System.CodeDom.Compiler
IDesigner
IContainer
WebBrowser
set_Filter
OnMouseEnter
MouseOver
_wnd_minimOver
_wnd_maximOver
_wnd_exitOver
XmlSerializer
get_Color
get_LineColor
set_LineColor
SetForeColor
baseColor
set_BackColor
SetBackColor
SetAccentColor
SetFontColor
SetShadowColor
set_Cursor
ColorTranslator
IEnumerator
GetEnumerator
FlatForeSeperator
FlatSeperator
.cctor
CreateDecryptor
IntPtr
get_Graphics
CreateGraphics
graphics
System.Diagnostics
get_Bounds
set_MaximizedBounds
System.Runtime.InteropServices
Microsoft.VisualBasic.CompilerServices
System.Runtime.CompilerServices
System.Resources
KUI.Form1.resources
KUI.Windows.FlatFrame.resources
KUI.Properties.Resources.resources
shades
DebuggingModes
Brushes
KUI.Properties
EnableVisualStyles
set_ValidateNames
DrawLines
BindingFlags
dwFlags
ToolStripItemClickedEventArgs
FormClosedEventArgs
WebBrowserDocumentCompletedEventArgs
MouseEventArgs
PaintEventArgs
KUI.Controls
get_Controls
get_CreateParams
get_Items
get_DropDownItems
System.Windows.Forms
Contains
set_AutoScaleDimensions
Extensions
System.Collections
StringSplitOptions
MouseButtons
get_Chars
SystemColors
Cursors
Process
get_Progress
set_Progress
_progress
components
points
set_CheckFileExists
set_CheckPathExists
KUI.Windows
get_Ft
Concat
Format
ShadeRect
GetObject
LateGet
set_Left
htBottomLeft
htTopLeft
htLeft
htBottomRight
htTopRight
htRight
get_Height
set_Height
op_Explicit
EndInit
BeginInit
OnExit
SetCompatibleTextRenderingDefault
set_Result
set_DialogResult
PointToClient
PresentReplacement
InitializeComponent
get_Parent
set_Parent
parent
get_Current
Present
pevent
ControlPaint
OnPaint
FromPoint
previousPoint
firstPoint
DrawPoint
TitleFont
HeaderFont
SetFont
BodyFont
BringToFront
prompt
Convert
wmNcHitTest
SerializeList
DeserializeList
System.Windows.Forms.Layout
SuspendLayout
ResumeLayout
PerformLayout
set_DefaultExt
MoveNext
System.Text
get_Text
set_Text
ShowText
set_ResizeRedraw
HasShadow
DrawShadow
get_Window
AnimateWindow
FlatWindow
set_TabIndex
MessageBox
PictureBox
FlatForeCheckBox
FlatCheckBox
InputBox
TextBox
ToCharArray
set_Key
System.Security.Cryptography
get_Assembly
set_RestoreDirectory
op_Equality
DesignerSerializationVisibility
WrapNonExceptionThrows
MetroPCS
2020-2021 T-Mobile Company
$badd6554-de2d-4e3a-acae-7652966d7358
1.1.1.1
.NETFramework,Version=v4.0
FrameworkDisplayName
.NET Framework 4
3System.Resources.Tools.StronglyTypedResourceBuilder
16.0.0.0
@System.Windows.Forms.Design.ParentControlDesigner, System.DesignqSystem.ComponentModel.Design.IDesigner, System, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
PADPADP
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
gSystem.Drawing.Point, System.Drawing, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3aPADPADP7rY
QSystem.Drawing, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a
System.Drawing.Point
QSystem.Drawing, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a
System.Drawing.Point
QSystem.Drawing, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a
System.Drawing.Point
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
hSystem.Drawing.Bitmap, System.Drawing, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3aPADPAD
QSystem.Drawing, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a
System.Drawing.Bitmap
IDATx^
$!)%J(!M
_pfD^
UFSui8
6&Ns#@
04<L_A
Lxyf9o\
Y&8K81y
Ei(C4|
c;c"_u.a
Cxj8K
hWN+*a
<K&x0-
Hw7bzQ
/8Ul&
H~q0u);
R|%,hq
2.LNdo
6y+vOM
B}8uo;f&
=+12&4
Yr+P8U
T-eT^-
4VX<bJ
b%Zs:9
ZfGp"t
d:5Pf5
-cq-p`
^o=b\F,k4Bw
uW60 i!
)7LNq0v/
pads'1
O)S..b
w#?y(m
*$3u+G
wXw~"C
@3>l8A
!Xh&aI
?48?du
#p7lA~
/Kof5k
e.?6*1}
%5l,?g
o/B{%P
\Or/%3,
`+Q&IH
zd.6P=#
%o6,eV
BI+L6*D
[4VU`cT
T,Ioq!`B>s[
{/gF+r
ddL%Qv6[
\FG| rq
wjD=MGr
xnJo`Y
D=k`BA
%MjX'
DfqhA9
hJjz#-7
!]Y]K
K2kt/Lk
v7!$\(
pb$|P}
m}[A/
+'~F"sm
kt5]K&0
P;/G_&
CzrnS;
lfkt_N
^<6gPYT
qkn75s9@
,.L[MH
gvS<v"
a_m!;.
|-DO)"+
`;+"%w#
nnm0cOe
#/2ht!o5
~-;oi1
1}&oG^
)gg`Y+KC
i=O'GS
4/|ARN;K
71Yc)~
OF&~ O7='I
4B_is~@1
oR<|"B
sGf.Na
O#ma.RG
0H;X?L
l)sF*,f]q!W=
%'pp
@ex*vk
Xr~Z;R
v)Y3s
|$3aP&9
XEOt&I
=Anx4W
;R+<_?
W|~sss^
Gc3m9B
0vs?N4
-_Ormr
tk<&~bca
RxH_G'
,=h?RC
bz%?$&
k+3Z7#m~
Jlt;cnK3d
d0!G+H
IDAT#'
Hmc`r8V
.)Euq6
oP&;wS
&u1Vn7J
MLs=WS
M/xy~(
P"^&2P
/K[Nhz
e\]5@p
\w{b7K
E'B%~\
Ef5_>
f27$0~|
I>z|T3
<+WbvC$t(
N-Tk*q
#>`/C5
\T.Yb
i#Nh+P
xi&i/`
Nf*kbqk'
IMm _?
Ov~Vbl
Af\8An
q;-x$c
0S7\^[3c
Jzv$~}
_5G.n_
!|t)"5B
jrlA(M
:`-{e|y
3B}V?F
u3[mNP
~XDmb{
~_&ve5
=e|u~B
~ml:[C\
Yx1RZm
chn=ZKs
+O2xp;
Wq5kR
&^clM:
WO;08"(
D)l'v"-
mD#2-[hs
6^1fu]7
ESyr&|
#!~%]VG
j<AvD<%
zr)f%v
+TGOp&
{4zA5|
z%aLk
g:;N=!
j_9vNO0
Q_(?<N
iy#4ghr
{-Yb+X
NB6h=9
|^-75'p6
Yyg=jE
$nxJ[B9'
'stl0eJ
6|B?s(
3q+s4*
cU3nr
rd9zc8J
F{S{j
FL]:Qy
HOp [l
^$Gcty
P4qAmu)
*YLhv
tnEjd2
i68^Wc
LvNNc`
fYs!k=;
yDL-ct
wty4~%
Xg[3qk
5ldKN_
-v<KV$
i=}0yr
&GYr;U
L`{9.w
$IV%^`B
hI>JfE7
.zy<&=
d3}B'jKdQ{
Sw3oGGs9x(
KqH_T%
cTz=bb
hUoA-8
9:j/_g
2Db#{v
LJOCzb
M^m7D"
CO08o'
W=-ukh<V
qkfMn0
MCe~*2
i'q32#o
sHk_ \
W'3_v=
*r%;z^
M]8*J0|
bN<&0s>
"Wg<FbL3
}=9ZY(
9JTULa
~}{b>O
J\DW~0
/[@eoo
XNW?bn
g(],$>1
ng%K26
szca]D
X)l4^a
My93J.
/+GvS*
[`wu;&nb
VOxE$
s*XY)E
$oWu1+
FAH4mf
00AmoA
yDZ6 5
lu-}]?
({>+#{S
c`6/(R
2$>mc|
D-G}P./
kx7enO
?r)m2u
K:.)0_=
8=l;ODM
Mf!*b
v7nY.b
aAw9~Q
-.q7z*w
V&]qG=
[D;V2f
$3?m'q[
ZAaN<7
ae/fm(
8;pfq"
byz(gL
!*[5iu?
Cp,,&#^
sO"{a
qYXKxc
#|U=JW
~|9#,l
Kt|:G2
#2c&px
JTrZ(O
<FEL"UK
{4%c&pqj1ru:h
b6&hS5G
}KHns%/
htgp=WL
LFdN'C
6kv1b_
I#W2,n
&Cv?/>
r6/,Bx
j*W,j)
}V%qJ^
yY^,;O
FV,pA]
!Bs.}
0\a?^7
43Zi
d$"_p8
L%Yxy;Gn
$q_e1
do1S%7
SZvCQF
|`g4|Pj
8#R^:"o
#vWKa}
2N(!_
caN0g$
zN9 ~;
d:R%9D
b9i.cWO
Up_#%{X!S
}APL+u
QNT:fr
kSO0ow0
hy0qA=
4v}Ocu
Hg_/2=?
i&JU1[
u >SZ p
yB0g>Ou
#4k16EjT+6
=_{Ey]
{+;{2q{+
u%4w\%
l`gT%/
K>1>~c
L6;=gS
,O6%\~;
JnlwdMy3+
q.m93R
=edGjrlS
s!_z7%Vs
uk%/z&
X<a>e}F
i97#K(
(H_BqL'
p*'~v'J
_On"?y
F=]G=Q
rr:znnx
WKPF4-5
4&w8sq
b`F+sg
L?d'OGO
92FL ,R
}8AwG"
a)+$DJ!I
PBRHJIC
~GFk3J
%W9<w2
oBhf,G#V
h13tV2
~X-]L[
Aw)wHg
hXYHBv
3)LVoe
nQAi@;%a
?L*RX_t
h6-RAd`
h2&J3rk
k7pjF<
wB#7'x
DK>!P_
>ObR2c
,=YkPyR
3DdS!b
O|:T@t
gm<T5e
^\9jOgf=3N
I?`JDn
\qqGl^
|2+,y5p.
ra AYE(9
wc(F:
Gu,'2sx
;g~dxs,
*B]*I
8ed=fR
Jjh\HgJB
D":JPv
lWGhW8"
.[1PJp/O=8|
7.iW
EcaVX$
n%Vn5Mw
/mbzg(
Mgjh36
a|WPFR
w.?%#W
@|ZIwLgp
TVt_D#u
f4;284Z
nE\s%h
^H 5JI
^\i!3i/
&*M*Dy
p~[mgn-
B+d+jM}q
V_HTi"
p)fI+Q)
TAiN*n
+8:l4f;
g1YZS0L
\UF\6E;@
JL-5(R
9uu26#{i
KUez[C
y%a"=xOo
e`<rA6
}s?g.w
#}XoiA
cJH,J#
sep;vc
cUx0Ot
7vOxuV
ZqWP<}
>Jbx;Ng
-LWOY
f2}x?d
Ff$<Ft
MpbEN-
d1-:7n
rL'ss]!
:]eBluX
FD_?fI
U|?iLW
07Q%[q
Tu yL-
=6]Hec
pn;n'iu
W,\cM{
JVnhd4
aALb#=
;t!{'H
!}g%2J
:HpkY|x
*#sn*
v-=*V]f
Y4t$o^T3
31Wnc9
b4{8Q8>
e+lXyq
/]oRqX
Ees^v1y
.aWz=~
W^{):2
#hKwCxn
_u'O'.
Z)>J?9
!FR@4w
:q_Kx9`
v <m5o
>ZxWD1M
0*1CkD)
a[<k$O
G{e1Gv
&,OaH<
K umbx
@,%wppq8
R%.BJl
r-6SG3
q[o1.#
:v#W!6
K/oXsZ
po9Dwz!
?BZ5x
_,W?50
hlU/3s
_2O `U
0jmSiq>H
ep~^DE
9NW_FKE
]Vtin"6
WLoR.?%|0
d1Ud"l
2^'T(O
%E[y)Z
8|4DOv
t.`^f&M'
XGKbvfS
ND)!%B
$#"_'c
X@@d8w
/VRX&
{a=|njP<[
5-F$r$c
U>*^#J_
8pf3J1sI
m=JK,H
FIn#{.]d
wER5wSi)OR
]_E@Y*z_
#4k vo;9
niD%^F
a?G`>
HKN*7r2
CSN(e+$y
giBJ:8
1H}M%j
l_""_3+
2/x8%;S8
%R ]G
p#X <'
kg#_F5
aon,B/
E[gs/z5
!xnRC?=
p9FlA+O
AdTg2u
"Bn5:2
@~Gtad
G-Fvc99^?
TulD9<
,NH[R|v,
+e}ZKJ
zlNk3?
4F\)F;dC
Al];:JW
R%Df[c
DDyISF?
'2t}o`
B^mfd}
z<~:1U
8^kLh@"*
]'71Ao
Xjt35K
#F\m<O
97Z:39
OTH!#
23VlT!
Xz]%PI
9ifOKQ-C
DhH7J*
j{Jn3h
vc||5O
Wj[9+-
IDATl=
`W[B`K3%
1>b59JX$
Vg-?~B
^usQe<s
ur&HUk2
f yv2'
Z3uHYl$
'a$C6l
yOPc-4
!I/3j
XEj2^Q
's,{/6``.
w6zo m
mq#Zys
:tw\B&
{Wc2u$o
o08QP%
aO[I~.
$%~M5b
wu%>1}
e<9#RJ
>/n^fLW?
&jW5_":0
_mC`U$3
%pi`%sL
[ZpS1C
"*FoX=
4Z.BQc4*
!3x wrF27
T={LI
]IlA?,
;d6^3T
:}Dq=7
pe~M#
@Vr~]
dyx}5V
h)7'3m>f
.l@Ff3
|p%7f0u
TDIpfG
~ wr=w
'Gdh~)
Z2_SX?
6|1ws
y+N";q
w?sAr7)
o)+6Vb
gK.Kw]
L>*`VUOB
6tVL"B~
\3jdmC5
E8Xjp{t
p6>Vo9
#cqYTC
-J&m{-
SaMT;Y
<a<_'rs
rh&epZ1
Y4`zr&
KC/p\
#]h"!YWH8
sg(x/N
Mrp+8Na~0
w/7\?s
TJebx1
]XdMB{
+\Jkj*
KDv=#<M
6jR^R1V
iI"|j<
svH/aV
b$k#cy
7qLXC
=f;y53
cex!/+
`S1UGm
K0t[2
J6de0~k
~b%Q'/PT8
U0 yI.
q{Ryxy
3I ,v1
ljCIt.
@FY]b_
Bxp4ZW
H^4ob|
=gs;u/2
1b;vsi
>5?62g
+R%6i5
0g*Rp.
Gsn2Yw
^qtw>_
w#-7kx
1n\'[+
rl6I#M
)c^Mcs
_di \(
p5V<qet
hDGv(F
#iC5IIP
)}H6Wr
Kx{b*y
?MAg)o
Q<b7;
a*K3'!
hX>E]G
of{R=s
qaY&,Me
bX9>I7
)bOMCu
eR-k^o
I?PQ<,(
_|G|c0*
\&Ydb/5
wz;O"6
%0SmTJ4
(~^oYrB
)dCcqy
YQl6ibl
&rkj)*n
-Nx?#o
lC!Vo(
e&1N =
:\70ci
(0SD_07
Pq"+O]%r
29x-9?m
)+FDa9
N<{[y<
t3lV?"
Hv*QHQ
,iAJeo
'iB-QbaD
+fsI.E
x7:q=$x:q
4,I"Dp
GLg=d|k,
,5b_x&Z
wv4JgbI
6j3Oe6Q
Al!gvhbh>
".%?`W
$Dz}y~
w$=}NL
ir;81y
GFstC#
A\Pvc8vk
(&|?Nh
[yd\IB
2m_=Gu
e8O;J{
mYXk&0
>dph$F
7kS.dC
=g2/;R
njZ?06
xz|~sg
f'Ku>1
#}gV,/b
l6v{ ceJ]
:N^''e
7}N[I-
gUv4M{c
s*L<PD
K2QK o
(rev{-k
,LtwdJ
IFbtEE
;K}zJv
lswB+E
>L&]x1
Bz}%Se
&01y.{
bry.Iu39
lg`h,_>V
3o"0a0/
t,fMz'
s@#k7/
9Wrj|7a
b$%<D+4
nS8b<F
O(2Un0
Grg}*:!
]1mjr|
,8\X@n
z2j+fq
X*8"s%
Iw[Och
8j2WIpu
=};^F
vedu'}
70Pj.)
iG\ ?A
,"KnP}
xM9F7O
h6{`{&
VCWg1_
~_LLt2
|naIa&
|W!Vx5
/H(m!}
/Fgx4m
}.?"~p*
eJ<Csjp
Vr"/t2(
g4Vfa8u5}
,mSB:CRP:
H'%Rs`
B*t+cEGa#
Xr<rG5
k;"S[p
uat~%2
mgE);;
YkNHdrMr
E+/R=V
Q4W%T9+
e6]uf
Tx1nC
:Zays8
dL5@6V
MPH&\]
2/F1U-
?}"|x~
h]7{b:
P2Ehl
2$)$!E4
$RJ*QD
RdHEBDe(
L`R2VS
cri8QG
WMX~b0Q
fMuo^u
usBYSy
3lX&K)
bM:f=`
|/?NN\63U
8_$>!'o
fV]0B{w
RBcj)A#GQ~
,dd"i[z
D,|V8e
s%t2;ETp
KjD k4
1xP&.Ww
l.R(tx
`v'HQ!
1j6,+sar
7c}T(X
k|F(31[
AoT&"[
B/6q7"
C}.~?*
O0+;FV
&SOR2t
CO~>t@
.)*cn:
Iu7);f
0B(<M
AaY rb'Y
O&r#u5M
b8?+`{O?
2T^\bTm
PMn"nm2
`9FJz3|
D7Q.f-
5'1u+e
_4/cnS,
BIOIDQ}=
1,NTb
deX*YDS
SCVq8{
4fL{BN
$%n"-cA#
^$3vn,
0mS.Y^
gR.2XU
mx9KW?`
<f/1e
2on/vd
AC d?&
-{o/A*O
o`:w W
af?T<G
VJ~E3Z
h^HMj;_O
zH_QsJf-!
em7.R[
yMMP(+
^:v9qn
{t/r id?F^z
ke!?f8uSvSf<
Fq]-yN
)Ocf:[~
O3}n$
tfLb4[
0v9>F'
q[y:s1Z
L{u?2?
tc:Z:p_
6,Hwebl.
?"Ps:N
MBzI'}?
foTA/~
aC7;?^Bu
uj-/Nng
y7U0OEJ
0|x-C7VR#
=C)T.`
g,"X[J2
6om"_B
yh+"Ck
_|o2A2
mGJ} G
Wu35-wy]-L
3s'v$Af
GM#qe7
3GZFc~
FPx.?{
L+F~L`
ER)E)M
1l:9+v#
E4I7_rV
F|Vf`S
5>=p
8~=U'bP
~nua`N'
Ui(="9
E#Hz-O
u>yQG
[>iT2GL
V(>r"y
l>F\o<
+qd|*>
@=q$uMr
13n63}
0UaBz;UR{y
fnd|G:
5S82j2C
Pht%63
Qf\QA%
sAs)o'U
<(s&![
Aa!j.{
\.^k&N
*Y vcM
$>J@{~
=KLWxp7l
?8{|*Ik>q
>&:c=2
+pnT@ZS
Rj(G/U3
woypk6
NO&q^.
"&Ydpa
Ut;+E7
Fp#v,
qLl(C,
P3n;AS
*R*d4$e$
6_A~^1I
<ZJfy(+
0p'7/."
0"fJ2u
RHDD+I
9\3uY9
)?nJc:r
1wJI13
YL=WLJL
&FMyOh
S*H9/c
CP:^so!w'
l_3+`2#/
nsrs`
I$SB61
jw3kQ4
i}&a0-
PJ3@FA
G19DlZq
vtu>3"
I=Dr1>
]ih*>@a
&>IY5;
r[/2~G
=sS{c?~2
??QVQg
:2UgPm
R.Vgk
y{QnWE
i1GX>#
lJAa>G
U#81c*
$OJHu
7LN ru"
ZQNiA\
+^zmBs
_E.]pc
JCq[$K[
h|N'fS.
*CZ$%h
tH=Co*
FEq4S\
Yit-c1
P&>X4^
|CAi.+
13LF`1
gwoin\
DtD,!M
Jsw3qr
hv>U!A
x2jw"^
2msX2Y
7{/4ppd3w6&
W73iB<zZ
_en@"
!]d1[F,A6{%
6>AhW!C
lQbgY/.
/#-#1L
AtVDP+[
I`pw,2bW
7Ql?G~
4_5"YP
.w`ip=
(t_B_cM^|ob
u:C+61
]9Zb71
z{_RbO#y:
J\]Na~o
]G<~+U
Fm'Z6\
:+%6,p$
/{^|aS
K'/JwW
TD~N&FA
Q63M=x
e#h{5
:o#gp,M
y*JWu
]'^P?c
"/~MqdF
!r#C+<
pX>/CSi
]k)iyF
ai.d-
Fq2j)M
0-e(FY
bIT=3vK
|K-FcU$&=
1RQ^ ]
Yl>-LE
Cf(Q1N
"Y;k;VW'
}+vc\7
{' fkI
,6#6k!
rzh;+$^q
K'3Uk0
Ob~ g$V`"
Us9zi&
$!N?ib
dA'O?|
u/ORU
j.{KMX4L
=,P2!u
bWh3+
""-#+-J
2{Kxrl%35-
OQR#^=C
;N?POVB8[
1[VlGQ
X^f+2.
lo-cng
<uyIw
)&,i@H7
."I"V*
^ycZW;3aU.
II"zn0
yl/Wq%
!V"OAc)
_7bB@2
_]".Ca
'{5EIc
{<f#Wr
7WS!TL
'92N0k
^FuO+)y
XM2+?/&B
58m7F{
I9KN)!
*L/2\b
ZkIV~,
v`6b?y
vT}El
d>3z5I
JdF2ONDs[
}Bev,"
aZG.Gc
"^MxAbN6_
1~i~@}
.#cl:uS.
mE#hqic
8nH7c1P
$C;2F
^:vIQV
Yxf<@j
:OVNWA[
;%6+(N
?SFvf"oq
&tD} o
0>S|9f{
BG~AG
Cg0kB5
ZJwU1b
@Rr<9}@
wK 0E\
:Q }"|
q&+&Oei
G:`9u{
x>nurX
}YSvuE
*cb(wU
.<vFR0
,,t#j|
w/'ll+?+ZY
%y~g2br
n>;*lx
\&R'^`
^B1e-Cd
^B~a*
h^=F`A
EBpo6s
@Be?3r
DIi-%zD
'#y9U}
,cC|r
_7c|67
LYs}9Y
)R2A&3
z-EsKP]
~x6R=:
;1O{CTv
`9;Uy^
fux8T
|/%ax
4Sfu0c
,wWCmJ
y2w!Ks
kiKt&d
CrRLTK@
!{FgPe
?Xx]A{
6)3{j&
]d~9@k
pah*fZ
3N`is)Z
v$i*Sy0c8.B
1K%?q-
R4>OF{
z(DO!B
G-c0a/5
^36`6%R[
bcH/sd
WRDBU,
'3d*V_
t55b'Ydr
mT'p\:R
2\X=n;8;
$O\LXq>Wz
LgF7{L
9/es]/
IDATF!1
g eoES
-{P)va
&s<b2?
^3{W40m
%h6Rzo)m;
ZD&M`_p'
Pv{.6B
sX*!ESP/
p!n^5&'U
n!qP%{
'w`8s9
prn7o<
g&T8c7n
~It^]J
:$fU1["
|c,7-~
G"'P8p
U!2p63
l'Si&{o
r$Olt8[
wu9Jrex
$x90 3
kmBe}
5(3?w2F
]9o<6qTz2
GpJwA3
AA[(Tr
~Z4s+-
YLF(b,
Vc6yw}
\zU:Yd?
2Mw%eN'9Q
WKV#ah
AuM5CB
=fR*oDT
$FGrhQ
Ti[`g/
$_m7j
N+uv;Y
Rh!sZd
2N!$k;
'dKkx"
|x-G'L
#Vja,y
9rb<Fy
}_p!&C
I>KVQ*
cFpGg/#
,(ynBE
jwbtk(
9}p+y3K
2VI[sB
7yvf8
r4K?c
.|Jk_*
WZX%~d
;rJ);x
>j%^*G
bLo6%m
y#dx>(
hm9Ky5
IPM+M
f_*#ga
~>BBq3
#ti Q/C
Z.+v]&1I
r'X3jo
#X~x3!
>*A-m"e
{tz$`#
yRH+Wq0
-CVlg
fxy>M;V
ExF!K6
/F.J@^J
}n^M&\Bp
9t8\`D
YgRAsX
|Jme/Q
*%Xlh
[.S9g<
f,N|MZ
B^Hg3w
m5rbil
BE1I($
[xo+MwWrJ
S\x}y=s
7-;:i1
Uo}y{F
h6KeNr
wd;67
V}AaI#C
:Nh1\
!K,Gtq1
Q!|1_L
EDYj2/A
6_jb)Nr
?}*[;+y
lB5GW*
b&NpC<
:P_}G
{YC>skG
{P:[=
*O.L4Em
ni8U>c
.OLZo1
bSg9wM
*j5mWl
7G `n[
,*'pE.
OA|-1w
^Lok1V
+Ai#Yo
QS uZ|
HM&_{os
uX+uso
kzG?e}
l*~}vhm
Mb.I1?
>bn>!VX
b4{.?f
/10j%b
j3zkj8t
Es0/\G
JI!6M%
LED9OW~A
v#_2Npf
"9#|:T
#8n/b3&
94Hi"<W
ym4C}c
D"v3iM
l^>EvJ
Fw^)WsF
^Y-C\y
UYbL@
Cs]rf;
w,zbW8
&SA>.C
|f)k*
U(QtDUw"
Mwt^?g
2Ai9YF#p
TKZN7R
9!Fm]-
s|{'3#
3{E9>OP_5
GLB9v:
[G1^q!
f%Ru.c3
h@'+g}&
GxE(W>}
DZIqn\
\#Y6k:
bB&w2:R
By6k:Sh>_Ft
"PTh&q
j1$u=f7
rUD+nco
JKe$#R(B"
F*#[v**TV
^sn3Um
S|93<'
>T4}cl
t(Q|u.
`7R0TS
z6G\'+
'aCto<
c|K8!i*
E^s#B2C
tFy!z@
,;gKqo
wgEr4Y
Fjw7[BbY
v>Vn$*
H[E2"n8
u]!kdR
mZ+Y]2
8bi16kWq
thLM"*
y%("Gm
B'c6m-
N#jF|@
ed^2G#
n=gx`-Y
"vO"[%
eO%iv:
2`l56
g 7b5F
D]FQ4M TC
?UgW1E
r$q'<_
!Rs&3n
q>~LFiu
[c4g5
6naZ`=
YDm5C(`.K
"_vrd
W~jJQ8
:dQu
dx6k%y7
t6?NmB
BX4]B?8'<
Z6cwc<
t>J#v@
,Q|SCS
pqQ:]IOh
ehrZl-
LI*F4]
Xgo#uw
A"2'RR
"dt&GM
h2_<4p^
\pn!15
FpNb61~
M/>NMbFX,
n;\"5-
]t:LCM
wfo`aZ&
sq076K
#}t'2g
6}W72Ow
;]|yPYA
#Do:1|
cH[;ev
7!Ac&gb
4k+j82
j2$Ox0
@N}P'T,
pgm6+r
l% t++
p+sE.#
qmI8WLMH
`6nFWX
Cg!>d&
5cgd7*P
$4g%[t
Z({c-1
/`MD+g
.Bl{9q=
K.qsr%[G
1ce7k2
~.,]bE
lcNK?l
a8o$E+
lg@g2:
LSA&/'
@tU8}R
<b(EoM
fLb8UO
'#T|8wb'
dFOb>sb
x~l&eM
<J5G2g
G2Na/?
E%2TTh0
xX*Mn\7
fUy!Sg
cYuz!I
qGi!nA
rCQ03WN
b]9F.+
O'Dk$F
>#>_@W
v>>oop
^F8k)C
^@|t+z
Z1bB6vm
9}n|'#
i33a&6S2X
`E@6z/
Y$/H&Z
wHKMB-
U<zf"L{
(nGrf3
9:;71a
0&)l#lN
-O^}FxH4
+iR+p?
|Y\EkG(Z
lV?9Eq
2LeKG>c
DHUcwF
NwN;eS
n4+jyhg
fryN,
$U2y[4/l
bIN/?B.
n&5D~Y
KX/iEs
y-#rU.
je^Mqd
OF31r!
ve3#4\xY
n.#mb+
={'Ef]$^zO@
QLOPdJ
KqcYW#
X>6'R6
(t\~pv}5
vtrfh<
wi[k@m
;y<l#U
5Alw2b
@Nuj9=$
|[#>{L
fV.)`C
Hfn;Fq
R!$")I
f+-<,*8
%5z2u
R5VMh
nW3oI#
XBzw/;
~>j}gp
\zO_/y
z-T{vPS
E}xY F
v?VgZX QODY
FT~)f%
j4pmc2
5X8f2I&
@ t>.d
FZ_<cP
ZOMg3j
~Z_*2xb
mN$/S
V%zw'r@p
%^#gp
o52iM)
kzr*j-'
&^Gcn:#
i3v<2fL
8h-nn3
.|TK9w
_Dyh$G
/.("f
)[6B4
(VC[^
K4';2D:\pf
H02|8k
K(t)c)y
r8Cg}c
N~vvp7
&k6Lbwl
5rqo8KU
+IQ]Gr
\fsT_n
!CTp/#$Xre
n0Q'F#=
Fo&qvo
nDrT,o
/DLi(?
M@R>T W
)|uv!/Y
-Fop<c
v5T5\9
z0hF=>
Q^25Sc
-ddV$B
Y7r"Gf
,QLdJ{
}ghD3Y
B6^^GRv
p|Loj7+
Rr8[nb_
bBq'~WuHo
GW+^Gy
+{BPg$
*qGo;g
{Q40&x
Gm[-A)
g>U /G
x9p)gr
f!^wgb1
yR0j#=9
7QWF\>
,ASw:R>2
Jvz|1m
(=/'sa?
TJFG0n
S<~'/7
V]Fr\4
G[sQZZ
K0!|N"
"6j=%vU&
`{j!v{63`
!6f$&ova
n<GoE:
su7no3
%r<_=F2P
].GL/`
lGE &!
OZL:kn<a
9w[ S!\
Mlmr j
|`pl6
._H; A
<t&{!qq
o93j03g9
m%lo9[
7DrCx:3
[2bi5;,
izcK{@#
W~Tx2$,
X&Y-$`u
/bIQ7o[
@ O_dS
z74H*R@
h.H@[s
W{qm\H
21Lf>`
2els6Fqk?
DY]n?M
Crb0*K
na]\5;
'int4r
voCIj"
Nk;3o
E3"t7o2
~9[eW2l
=V|5=O
sdZG4j
/YC_aS7
<1F}~J
u"oN32
:LGgc\g
z[#If5
|;],9
&`n0R7
~3?2iw
<(~JCF
rB|qzc$
FQ{k*g
;{qaQ*
t>JwqN
azO."z
CxG0+G}E8
`gJ/s v
EJI$*)
1!~2o5
b.HK~%
Qf|yS
?2#asCn
}"YxLu
Antivirus Signature
Bkav Clean
Lionic Clean
Elastic malicious (high confidence)
ClamAV Clean
CMC Clean
CAT-QuickHeal Clean
ALYac Trojan.GenericKDZ.76321
Cylance Clean
VIPRE Clean
Sangfor Trojan.Win32.Save.a
K7AntiVirus Clean
BitDefender Trojan.GenericKDZ.76321
K7GW Clean
Cybereason malicious.84f746
Baidu Clean
Cyren W32/MSIL_Kryptik.ESE.gen!Eldorado
Symantec Scr.Malcode!gdn30
ESET-NOD32 a variant of MSIL/Kryptik.ABVM
APEX Malicious
Paloalto Clean
Cynet Clean
Kaspersky HEUR:Trojan.MSIL.Taskun.gen
Alibaba Clean
NANO-Antivirus Clean
ViRobot Clean
MicroWorld-eScan Trojan.GenericKDZ.76321
Rising Clean
Ad-Aware Trojan.GenericKDZ.76321
Emsisoft Trojan.GenericKDZ.76321 (B)
Comodo Clean
F-Secure Clean
DrWeb Trojan.DownLoader40.32316
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition BehavesLike.Win32.Generic.tc
FireEye Generic.mg.02a19d3dfdcf507f
Sophos ML/PE-A
Ikarus Trojan.MSIL.Inject
GData Trojan.GenericKDZ.76321
Jiangmin Clean
Webroot Clean
Avira Clean
eGambit Unsafe.AI_Score_72%
Antiy-AVL Clean
Kingsoft Clean
Gridinsoft Clean
Arcabit Trojan.Generic.D12A21
SUPERAntiSpyware Clean
ZoneAlarm Clean
Microsoft Trojan:Win32/AgentTesla!ml
TACHYON Clean
AhnLab-V3 Trojan/Win.Generic.C4545210
Acronis Clean
McAfee AgentTesla-FDAH!02A19D3DFDCF
MAX malware (ai score=80)
VBA32 Clean
Malwarebytes MachineLearning/Anomalous.100%
Panda Trj/GdSda.A
Zoner Clean
TrendMicro-HouseCall Clean
Tencent Clean
Yandex Trojan.AvsArher.bSIdr7
SentinelOne Static AI - Malicious PE
MaxSecure Trojan.Malware.300983.susgen
Fortinet MSIL/Basic.gen!tr
BitDefenderTheta Gen:NN.ZemsilF.34790.@n0@a4I6ubh
AVG Win32:MalwareX-gen [Trj]
Avast Win32:MalwareX-gen [Trj]
CrowdStrike win/malicious_confidence_100% (D)
Qihoo-360 HEUR/QVM03.0.884B.Malware.Gen
No IRMA results available.