Static | ZeroBOX

PE Compile Time

2021-07-21 19:46:31

PDB Path

cDisplayClass1.pdb

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x001180c4 0x00118200 7.02449229506
.rsrc 0x0011c000 0x0000931f 0x00009400 4.76535917645
.reloc 0x00126000 0x0000000c 0x00000200 0.101910425663

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x001206d8 0x00004228 LANG_ENGLISH SUBLANG_ENGLISH_US dBase IV DBT of \200.DBF, blocks size 0, block length 16896, next free block index 40, next free block 61695, next used block 4279173120
RT_ICON 0x001206d8 0x00004228 LANG_ENGLISH SUBLANG_ENGLISH_US dBase IV DBT of \200.DBF, blocks size 0, block length 16896, next free block index 40, next free block 61695, next used block 4279173120
RT_ICON 0x001206d8 0x00004228 LANG_ENGLISH SUBLANG_ENGLISH_US dBase IV DBT of \200.DBF, blocks size 0, block length 16896, next free block index 40, next free block 61695, next used block 4279173120
RT_ICON 0x001206d8 0x00004228 LANG_ENGLISH SUBLANG_ENGLISH_US dBase IV DBT of \200.DBF, blocks size 0, block length 16896, next free block index 40, next free block 61695, next used block 4279173120
RT_ICON 0x001206d8 0x00004228 LANG_ENGLISH SUBLANG_ENGLISH_US dBase IV DBT of \200.DBF, blocks size 0, block length 16896, next free block index 40, next free block 61695, next used block 4279173120
RT_STRING 0x001249b4 0x00000034 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_STRING 0x001249b4 0x00000034 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_STRING 0x001249b4 0x00000034 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_GROUP_ICON 0x001249e8 0x0000004c LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_VERSION 0x00124a34 0x00000424 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_MANIFEST 0x00124e58 0x000004c7 LANG_ENGLISH SUBLANG_ENGLISH_US XML 1.0 document, UTF-8 Unicode (with BOM) text, with very long lines, with CRLF line terminators

Imports

Library mscoree.dll:
0x402000 _CorExeMain

!This program cannot be run in DOS mode.
`.rsrc
@.reloc
afefefefeffea
Xffefeeffeefa
afefeffefefe_
Xfeffefeefef
affeeffefe Y
Yfeffefefea
Xffeeffefefehah
Yfeffefefefe
affeeffefe Y
Yfeffefefea
Yffefeeffehah
Yfefeffeefa
afeffefeefefa
Yffefeeffehah
+feffefefefe
ofeffefeeffe
.nfefefeffe
feffeeffeef
affefeeffe
9ffeeffeefef
offefeeffe
feffeefef
.nfefefeffe
+ffeeffefe
affeeffefefe
efefeffeY
ffefeeffeXa
feffeefefY
feffefefeYa
fefefeffea~:
feffeefefa
yXffeeffefe~N
Z?_d
_b`*
;,B},2
v4.0.30319
#Strings
'5+p3
'[+,9
'}+t=
) i,pE
(!j, F
}#j,4F
(!j,HF
f'j,`F
}#k,tF
l'k,(G
z'm,dG
Hqy
$:$F$N$
cDisplayClass1
SuppressIldasmAttribute
System.Runtime.CompilerServices
mscorlib
System
AssemblyTrademarkAttribute
System.Reflection
String
AssemblyCopyrightAttribute
ComVisibleAttribute
System.Runtime.InteropServices
Boolean
AssemblyCompanyAttribute
AssemblyFileVersionAttribute
AssemblyDescriptionAttribute
AssemblyProductAttribute
TargetFrameworkAttribute
System.Runtime.Versioning
CompilationRelaxationsAttribute
RuntimeCompatibilityAttribute
AssemblyTitleAttribute
GuidAttribute
DebuggableAttribute
System.Diagnostics
9333a9a1-4ed0-4e64-83c8-b5380f9b1eab
cDisplayClass1.exe
<Module>
KILLER
Object
System.Windows.Forms
WindowsFormsApplicationBase
Microsoft.VisualBasic.ApplicationServices
Microsoft.VisualBasic
ValueType
MulticastDelegate
Computer
Microsoft.VisualBasic.Devices
STOREASSEMBLYSTATUSPARTIALINSTALLGetSerializableMembers
Necu.My
ApplicationSettingsBase
System.Configuration
<Module>{CAA3C3CE-4268-4F78-8111-F8D9908ABF7A}
Attribute
<PrivateImplementationDetails>{8A4A11B7-4BB4-45D7-BCF6-837F475ACE4F}
__StaticArrayInitTypeSize=256
__StaticArrayInitTypeSize=40
__StaticArrayInitTypeSize=30
__StaticArrayInitTypeSize=32
__StaticArrayInitTypeSize=16
__StaticArrayInitTypeSize=64
__StaticArrayInitTypeSize=18
STORECATEGORYSUBCATEGORYCompressed
GetOutArgBrowserHome
IntPtr
.cctor
Process
GetStringBuilderSubcategoryMembershipCategoryMembershipData
getStackBehaviourPopLeftWindows
UpdateCharSetMask
NotSupportedException
List`1
System.Collections.Generic
value__
IContainer
System.ComponentModel
TabControl
TabPage
ImageList
Exception
tbmijcx
Dispose
ComponentResourceManager
Container
Control
get_Controls
ControlCollection
System.Drawing
Padding
ImageListStreamer
get_Images
ImageCollection
Single
ResourceManager
System.Resources
CultureInfo
System.Globalization
Assembly
WebClient
System.Net
System.Text.RegularExpressions
IEnumerator
System.Collections
IDisposable
AuthenticationMode
OnCreateMainForm
AssemblyName
StringBuilder
System.Text
Stream
System.IO
StackTrace
StackFrame
MethodBase
UInt32
UInt16
RuntimeMethodHandle
EndOfStreamException
ArgumentOutOfRangeException
TextBox
Button
EventHandler
FontStyle
GraphicsUnit
Interlocked
System.Threading
CompareExchange
EventArgs
tl0qot
BeginInvoke
IAsyncResult
AsyncCallback
EndInvoke
Invoke
Hashtable
ArgumentException
GetHashCode
TargetInvocationException
get_IsDisposed
InvalidOperationException
Activator
CreateInstance
ToString
Component
Equals
UInt64
get_Item
set_Item
AddRange
IEnumerable`1
get_Count
GroupBox
ListView
ColumnHeader
ListBox
RadioButton
CheckBox
tv6am0
tyoi80
get_Columns
ColumnHeaderCollection
PictureBox
StatusStrip
ToolStripStatusLabel
SelectQuery
System.Management
ManagementObjectSearcher
ManagementObjectEnumerator
ManagementObjectCollection
ManagementObject
GetEnumerator
tzktrbr
ToolStripItem
ObjectQuery
MainMenu
MenuItem
ToolStripDropDownButton
ToolStripMenuItem
ToolStripSeparator
RichTextBox
TreeView
BackgroundWorker
u24yxab
u8m0lr6
ug2ktpo
Enumerator
ListViewItem
get_MenuItems
MenuItemCollection
get_TabPages
TabPageCollection
umi81o
DoWorkEventHandler
v1wkuh9
_Lambda$__R786-1
v97m3g9
vafpsaq
vdj0fx
MoveNext
get_Current
get_SubItems
ListViewSubItemCollection
ListViewSubItem
get_Items
ListViewItemCollection
_Lambda$__R791-2
DoWorkEventArgs
Bitmap
MemberHolderZAP
InternalLowCurrentCount
InlineTokgetAbbreviatedMonthNames
IsTypeSpecgetIsAssembly
AbortRequestedFindTokenByIndex
sender
ResolveStringTupleElementNamesAttribute
EmailNonUniqueAuthority
GetDecimalDigitValuegetIdentityObject
DaysDecimalConstantAttribute
AddAccessRSACspObject
SetOpaquegetMethodHandle
TailUnobservedTaskExceptionEventArgs
GenericParameterAttributesRectangular
IsOutputRedirectedEVENTACTIVITYCTRLCREATEID
get_Default
TYPEFLAGFOLEAUTOMATIONImpersonated
ISectionWithReferenceIdentityKeygetSpecialKey
TryParseGetDecimalDigitValue
FirstChanceExceptionEventArgsCoClassAttribute
OpenExistingResultopDivision
ShutdownEventHandler
DiscretionaryAclPresentSep
Default
Module
typemdt
FieldInfo
MethodInfo
callback
object
result
SortedList
Dictionary`2
GetTypeFromHandle
RuntimeTypeHandle
get_Assembly
RuntimeHelpers
InitializeArray
RuntimeFieldHandle
RSACryptoServiceProvider
System.Security.Cryptography
set_UseMachineKeyStore
BitConverter
GetBytes
SymmetricAlgorithm
AesCryptoServiceProvider
System.Core
RijndaelManaged
ObjectHandle
System.Runtime.Remoting
Unwrap
CryptoConfig
get_AllowOnlyFipsAlgorithms
MD5CryptoServiceProvider
HashAlgorithm
ComputeHash
BinaryReader
ParameterInfo
DynamicMethod
System.Reflection.Emit
ILGenerator
Monitor
GetManifestResourceStream
get_BaseStream
set_Position
get_Length
ReadBytes
MemoryStream
GetFields
BindingFlags
MemberInfo
get_MetadataToken
get_Module
GetGenericArguments
ResolveMethod
get_IsStatic
get_FieldType
Delegate
CreateDelegate
SetValue
GetParameters
get_DeclaringType
get_IsValueType
MakeByRefType
get_ParameterType
get_ReturnType
GetILGenerator
OpCode
OpCodes
Ldarg_0
Ldarg_1
Ldarg_2
Ldarg_3
Ldarg_S
Tailcall
Callvirt
Debugger
get_IsAttached
ICryptoTransform
CryptoStream
CryptoStreamMode
Convert
FromBase64String
Encoding
get_Unicode
GetString
get_Size
Marshal
ReadInt32
ReadInt64
AllocCoTaskMem
WriteIntPtr
WriteInt32
GetMethod
ProcessModuleCollection
ProcessModule
Version
ToInt32
ToInt64
ModuleHandle
GetField
GetType
get_Location
Exists
GetName
get_CodeBase
Replace
GetProperty
PropertyInfo
GetValue
LoadLibrary
kernel32
GetProcAddress
Concat
GetDelegateForFunctionPointer
so8WHSBJcy
op_Equality
FileStream
FileMode
FileAccess
FileShare
ToArray
set_Key
set_IV
CreateDecryptor
Reverse
GetPublicKeyToken
CipherMode
set_Mode
FlushFinalBlock
ReadIntPtr
WriteInt64
GetCurrentProcess
get_MainModule
get_BaseAddress
op_Inequality
get_Modules
ReadOnlyCollectionBase
get_ModuleName
ToLower
get_FileVersionInfo
FileVersionInfo
get_ProductMajorPart
get_ProductMinorPart
get_ProductBuildPart
get_ProductPrivatePart
op_GreaterThanOrEqual
op_LessThan
GetModules
GetHINSTANCE
get_Id
get_Position
get_UTF8
GetFunctionPointerForDelegate
get_ModuleMemorySize
get_EntryPoint
get_Method
get_ManifestModule
get_ModuleHandle
PrepareDelegate
get_MethodHandle
PrepareMethod
CreateEncryptor
ToBase64String
classthis
nativeEntry
nativeSizeOfCode
fHSkdAnkJf
hModule
lpName
lpType
lpAddress
dwSize
flAllocationType
flProtect
hProcess
lpBaseAddress
buffer
lpNumberOfBytesWritten
flNewProtect
lpflOldProtect
dwDesiredAccess
bInheritHandle
dwProcessId
DeflateStream
System.IO.Compression
CompressionMode
GetManifestResourceNames
ResolveEventArgs
get_Name
AppDomain
get_CurrentDomain
ResolveEventHandler
add_ResourceResolve
CopyTo
IsLittleEndian
$$method0x6000316-1
$$method0x600032e-1
$$method0x600032e-2
$$method0x600033c-1
$$method0x600033c-2
$$method0x600034f-1
$$method0x600038e-1
$$method0x60005ab-1
Thread
AutoScaleMode
FormBorderStyle
MatchCollection
CompareMethod
ShutdownMode
FormStartPosition
ContentAlignment
ClipboardProxy
Microsoft.VisualBasic.MyServices
DialogResult
ToolStripItemCollection
ToolStripStatusLabelBorderSides
PictureBoxSizeMode
ManagementBaseObject
Shortcut
BorderStyle
DockStyle
MsgBoxResult
MsgBoxStyle
SettingsBase
HttpContext
System.Web
HttpResponse
get_CurrentThread
get_ManagedThreadId
SuspendLayout
set_ImageList
set_Location
set_Name
set_SelectedIndex
set_Size
set_TabIndex
set_ImageIndex
set_Padding
set_Text
set_UseVisualStyleBackColor
GetObject
set_ImageStream
get_Transparent
set_TransparentColor
SetKeyName
ContainerControl
set_AutoScaleDimensions
set_AutoScaleMode
set_ClientSize
set_FormBorderStyle
set_Icon
set_MaximizeBox
ResumeLayout
ReferenceEquals
set_MinimizeBox
Matches
Operators
Microsoft.VisualBasic.CompilerServices
CompareString
DownloadString
Capture
get_Value
Conversions
ToBoolean
Strings
set_MainForm
get_UseCompatibleTextRendering
Application
SetCompatibleTextRenderingDefault
set_IsSingleInstance
set_EnableVisualStyles
set_SaveMySettingsOnExit
set_ShutdownStyle
GetFrame
Intern
IsInstanceOfType
get_FullName
Append
GetExecutingAssembly
GetCallingAssembly
ReadByte
Buffer
BlockCopy
set_Font
set_AutoSize
ButtonBase
set_StartPosition
PerformLayout
Combine
remove_Click
get_Text
Remove
add_Click
GetObjectValue
ContainsKey
GetResourceString
ProjectData
SetProjectError
get_InnerException
get_Message
set_TabStop
set_FullRowSelect
set_GridLines
set_MultiSelect
set_UseCompatibleStateImageBehavior
set_View
set_Width
set_Image
set_ImageAlign
set_TextAlign
ListControl
set_FormattingEnabled
get_Clipboard
SetText
add_Load
get_Icon
ISupportInitialize
BeginInit
set_Enabled
set_UseSystemPasswordChar
set_DialogResult
SystemColors
get_ControlDarkDark
set_ForeColor
ToolStrip
get_Red
set_BorderSides
ToolStripLabel
set_IsLink
set_SizeMode
EndInit
RunWorkerAsync
set_Index
set_MdiList
set_Shortcut
get_Black
ToolStripDropDownItem
get_DropDownItems
get_White
TextBoxBase
set_BackColor
set_ReadOnly
set_Multiline
set_BorderStyle
set_Dock
set_ShowLines
set_Menu
get_Blue
NewLateBinding
LateGet
Interaction
MsgBox
StrReverse
add_DoWork
ToCharArray
FromBase64CharArray
get_Green
get_Chars
remove_Closed
add_Closed
set_CheckForIllegalCrossThreadCalls
remove_DoWork
ObjectFlowControl
CheckForSyncLockOnValueType
get_SaveMySettingsOnExit
Synchronized
add_Shutdown
ResolveType
MessageBox
get_Response
DebuggerHiddenAttribute
DesignerGeneratedAttribute
DebuggerBrowsableAttribute
DebuggerBrowsableState
DebuggerNonUserCodeAttribute
DebuggerStepThroughAttribute
GeneratedCodeAttribute
System.CodeDom.Compiler
StandardModuleAttribute
EditorBrowsableAttribute
EditorBrowsableState
STAThreadAttribute
HideModuleNameAttribute
MyGroupCollectionAttribute
ThreadStaticAttribute
CompilerGeneratedAttribute
UnmanagedFunctionPointerAttribute
CallingConvention
CharSet
FlagsAttribute
.eyhr2
Necution
Copyright
Necution 2013
1.4.0.0
$An advanced chat-system for windows.
Necu 1.0
.NETFramework,Version=v4.0
FrameworkDisplayName
.NET Framework 4
WrapNonExceptionThrows
$65a8a467-0302-42a3-94ab-0e867667aab4
3System.Resources.Tools.StronglyTypedResourceBuilder
16.0.0.0
MyTemplate
11.0.0.0
System.Windows.Forms.Form
Create__Instance__
Dispose__Instance__
My.MyProject.Forms
4System.Web.Services.Protocols.SoapHttpClientProtocol
Create__Instance__
Dispose__Instance__
KMicrosoft.VisualStudio.Editors.SettingsDesigner.SettingsSingleFileGenerator
11.0.0.0
KILLER.
`1[[System.Object, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089]][]
SUsSystem.Runtime.InteropServices.CharSet, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089
CharSet
/_/[<Ca
eaIXqh
)(Bu"#
1S:E,
[&a97RW
NARMIn#M
xz%g4F.R
~XpkGA[
v&n&O'
%lnrfS
c:^79Z|
bk'8^n
Lk?q^;L
P3P^fc
<_;idF@
PVdb> l[
u`MeNeF.
{G(X$aH
ml`W-3
vtw&{7{
t(]Y*EM
r}Az*
xO2S"e
6caX;a
>!v>D~K:
14Z/<zTG?\
tj-M{S
6.G$dh
GtLDOR
WYGcJ]
v5vHV>N
Mi:s*p
Nemj<?2
iay2iA
'H[_[r
vhq|Fy<
I;*9+[
2o7Z<V
ES@oeZ&j(
tU.^P%/F
'(lT?<
J+m1=e
tN5]IUs
_yKaxPa6
5[3egC|
4R&fqE
wTXfC"5
?;KHm0($
Pksb5I
+.,Q#
4I)a/0w
*;k,`.
;kt7p~
q{c,ja
t`0GWL
FL+=#2
m~P/;{7&
3%TgxN
pl_:im
\[J]u3
bg,Q\s
b1dJ1/
u'@J}!
lsSO/D
}x?mj#v
lq32+OS^g
zENM=|h
vktwPR
"NbTW%
;MGFk<
lxp+p?
Rg)9:`Q
eJxFWa
YEO8x_B
G=__>
~s6!N]I
y%Av_.
H@sRc
[CY+!B&
ne9Ps)
LNTJ)c
pG|B%H
N(Om-%
c$dJV?
,/0+XJu
<<XHJ{
]1&{;T 
<y<>+xQ
cnH:6E*H
F8Cia}J
;cM=q:
a(2)f
4Cy!?+
}5FZOk
b'\lw3hjB1!
/PdD8\
qQ`]<C
qCsm>D
tpw7ZZ
kl]v)K
APPpgC
O jra9
H^W\~4
?piz^Im
fo_ !0{%
mcZ%UD
I e1:qv
/hjB&b
LzM9G>pc
5a_aK
WY5f"L
r(/&F;Pt
KkD$,l
jo8w4X
FiOYT"
vP.fP}Q@)
xh]T_J
L\>0qm
9}? (4
B]#lFc
3VTwH)*
:5wjA6
pYN0f>
zyfn]]
>$_BBJ
n*0S:PV
WI"Eg#J
Jge"c]
f!6Lnek1
_6`}X_H|R
6%RK*M
25o`yI
-TKY\M
;".FK3,
,{K,Qw
,D}&7K
_a"bj[
<OoZc8
p^h5Ujf
u:ZzL%
5A=y16
hH)4It
Pt-Os6+
+]g7!Sm
ayk7V0h
{\\e%5
@QE 96
t&BKB.<
Fo#YzZ
:H?H_'
(y8wF:
l*Gmb2eV
L!fF*dW
zv}7=m
-3'Rd
'FSt(Yfq#9]
)x-1J2
B>,X*,
A8ACfvj
sH)6}~
$>R^'w
g6dT\w
0!+j4W
K`noV"
X<1p M(
-#iofG
fB<ZP$
};%-<t
_0mhDk
%B^51b-/I
VYu>lI(M
%+Z}]+X
X^<R2q@
5Uu81uc
FdJUPb
9-m{"y
;~gBnb
{9l 2d
I\0?~@
~WLy"o
&'1j]nkE
n\w9RYj
vklF0gi
|J^1a:
HPCDcSrj
zEKAAeL
Z@IlWk
,&X$"
zk"J*t
RK P-I
t+CI6c
tj-8F%4
3`[%>"
=YGe"w9
47]?pj
#z!3s9
ID- @
~S67Pu
V@OIV4r/
Ey[`]:
m?szw:
:uR]@z<1
w;8[#
]6Tuh?
T8gkUdC
3K>s-m
Ze:L\<
t6_|f00y
vLxC}>
:LyhgNC
oP|2Bd
<0ZoTo
fWx6f.
hU-.H@}
/I4aV%
C$9bP~x
x<g)'WK W
CcdT2S
JGqcL@
]\aD^I
*9.:9
q.-/?k_Do
w`KJ!k!
*pbbWO
2~\p6R
LL[8J05l
\L+L'0];*2$
n}R`/Fsy
k5N*W3
eR i$?
'UADN;
wE>/yA
f+gopTA
O:"+=+
k\o.]y3
PzKX'i
%-/Qsju
wPqy/S
Gu,uW^
?P3qfZ
Jid<M;DW
cn6bSq
U3}/of
p3WF<R?
6]cM`A:
d&8sN|
d\[?7&[
8"X&r5S
FB/\G@
({4<Kn{2$
\a|;+>5
sLv6"1
V{OC$[
*1=[Y
l7Gr|](
_\h!Fu
&{)W-`
yHw))s
0nNvq^)
!ygo$(9k
e*IhP6Nr/F
XdhQ5bq51
hWq6YGa-
}B68B~W
||z^8c
Q:{a)N
/Jp]{&
HT}=8z1
7x6wd+~
TsnQM#^T
mlIHY;8dR
7Q#v=3
OhJ3+
d50Cgn
D}BRs9
q-ooZ+Z
~08^AcW5Tu
q9H[z1!BVMYol
HTo%h0
5Mw9'f
>[jh6
y1ykGe
1Ygymk
|ve9PP
@PU}S!K
dxm0Fib
EMTUR^
xx^RX^
<qT[!DK
Mb)2<F8
HA>vh?
GN01f6
2WAh_d
5O%yLK.0
\x>E`T
~8W!(>2
$*L6=DFb
yIz$C\
,z4:<1
SwU]\4U1
NVBc;:e
Y=pw9C}n!?Q
.$u\]~j2
8KqUk[-'
W8_Pr.
eoO{\W
RR|x:I^p
b<G6\%
ZhS1p#
-;j5S_
'GI )6
JaB^0%
xoEib%
FM20<xT
ND3JcA
eYGS[^
IvX_"+A
b(#Z]
0?f3zgB
8^[Cxj:
dT).8CN]
V3kG@
ucLni%@"
v~Y3|
Itq:4*90e3h
oK]y_K
L_|in>0dQm
d[O?3m
q/+qen
VdMsD@{j
2oG\ZU
Z.LyeQ
QvO9kC4d
MySpls
IL-(c,<
?+:$0a
1H=fPb
WH]#VY
qg"mVUL
eAw/7
|NVckO
zyORwLD
~Fphl@
H'^;a0
q;.#^y
l0e=z2
s&Ao+i
4y(#wUn
YbY`:$
e#=e) P!?
YHBH7q
*sfl<1
m)55;d!
KDUWWf
+GFlb"
~Of&Aj
{Q-X\N
)JEGda[d
]w1</=
.k`JSP
MfT-N=
eutR!z
G|kBRE
bj&lq[
@Z*A4r
mjEXj`
ns`,)Qn
I81%\G
+M4[`Fv
U"kvPz(
f'.P&F
S>yC1_
Wb/s.F"
wlaP"
}05uH"\F
j?J%=,
^n$5Q*
VKf0<
K2d2vT6F
"Dy^1X
2zUy8
g PTuG
Y2iP`,
vgOY=r
X2Xt`N
7u\4dzl
*bi5-'j<
l4'!ZA
'2;o1S
%P5wrZ
*O8M6k
u p*Al.8,Su
DbF=r\
=I<!O
Lm^!HZ
rZ$*#j)
f=5'{$
.rviAZ
ot^@r=zZ
EJr%.r
tR]wW=
ePeiAz
[x=skw
{,cPiM
>/`0qeT
|QP070
ohc<O!XJ
NJRKp7
~P@Z~l
%]-7~{
z{(:_`
/T|Ey9
PBZPov
/<p5*\
~$xC9%1
-t\+;'!
<Y4?d$
yctmb&
;8&/1?
sRO<1i
j[Jm[R
J4&0`uh
~w\go
["*>BE
Y5}(s@
t25cm]Wh
DGOJLR
DspwYR(
]Y>[cp
1i3A1/R
C:#&w^M
Ag5Kh(
s4#z'K
;`@\K-J
c.!yi0
#U[AN<+
tmg 09
(ZotQe5'
6Nh=x+
+^XyyCf
_W!fl)'
KXq?tb
05A)0g
V?HCQ
Eisu7'
p?`<;`_
X(\OKv`L
u:&V7)zd~
p1oZUq
;y.k,/
>~jy[4
_?@[uAL
@:p#-5
RN,e+h
do,Jdv
Capxu
Gx2I46
2#|y_=
/bnP}?\
Pshyjb
NP6m-Hm
n}H=_ =N
NZDAtv
ss\/=+|
U'LUsX
ex{3+7r
UjT##ae
DbyIoi
ORWn,3
&+h/-awIN7
#d)e#|:
k&Paqi]
nw&;|Jw
vK)1b<v
<iqy%h
-*}7;g
U~R,h`c
=q^cS-4p9
&0UteYZ
\ene8L
9cv+Q!
Y9kLwE
L~{gJ-
#3Wbd<
#1,osS
5/#?z0
0CEA~{2
'\ YA
0,{~8}
}w!V(Jp
8g[~X-
-oSZA-2x^
I+(o.y
0,LsEQ
`zL+~}
GPi&zz&
{|Xtl]
j9KP\k
ehkKVC&
H9rTvk3
~Ih/<$
{:*jt6i
Nu|($ui}
SRR`!S
kC1r,l
6XH8_E9
Mng)Zb"6
kv?5G+
>"x[p6
w?mXB1
khKk{q
9,%hWQH6j
Pj['w
+ab'Wx
"Y(({Q
=PJU/J
ru:7 $
?$jPXl
{j;o&U@
\.[,Ns
NQta'G
U&JmHU
la=`fI
{Zn$j(
W~'NNYe 1
I~73\[
dV@B@Z
sja=ZD
!+;stD
+wQDaT/
`d95>cb
g.A}L7
[v?3g9f
(G4Z*dJ7
%@:d_K
aG;ob06N
2/Q*v@
~/1W5X
"Y?j @n5j \i:K
1<VkV@
qTPTce
hy\Q;r,
]OQ{ (PA
rAb\OP
X&y,[o
V#=Mwa
u=JrLg
myN.VM
)jAkmgk
S-U\^8
8s$K|)
/0Kd;u
X$te`,
?,9X=t
8{YA_OJy
4|%8`1
&45C<Z
uvmlf,
aw'P{Ia
^.Ct;3
^xDgE8
1b7j+Lc
g(TyUzU
JqU4Xs
%r~ ZU
)~Y.Sr
[|R9)Y
=Sf}HCI
gQ+'/8
'Lr+](aT
R_mux0F
}K%A^^
<MXv_!
s$+^Yc
!Nd}wX
?uV*yV
1YA&a)
-c-fnjJ
WUS7<u
M4}Up0
-e/ 2=
8f'cTwNo9
57g>%4
!R-Xc
f<]2]UY:
)hNR&}
>)d;4a
ScU*}
#a.]qA
VTg2]Yw
y6YmNC
}tR1Ms
*A_\v\{I
moSF#G+
N$1&1 
;S7e]Q~
LnU0wp
z|xCTb)6["~
Pu:v{m
c@p}C^
M15u3v6
=f'Pjl
dgd2s
uLTiid
:,o)tO
bj_?VJ
$ZNZ`)
cE<nGI
qLPJd'_
bhsR_
ut\~tg
.M:f@H*
jVJQge^&
j;o@6g
:.v{.K
]^E@?C
lx=/lki
v[0R_:
hRtp_^*
"6~~;k^
_"<^LT
%TP"Ja
QK@fIU
#=V9`:
c M6wY
d/n@5L
ab][O)W
`^A@],`
C.rBQh
=)Gm5~
c|e$tk
&%'-pA
IY&)A?D
d?l^%H@
'Cykqjf
D%Fz=V5'
&/*x
Vd=c4!OTf
q mva#
lttD#PphM
($x!QU
3T0e[L
-P.<.j
ai;4FBT
B@yy~dF
"W('g/g
eH<^o(
G0\f~{>
C[\;R
e;D{
L"|6B>
+`tH%nR
>MUheZ
nMpu`?
]Cb12?K
Hs_z9
P}H2N
UL=Tov+
2*!8MW
h{5[G4
ves:4&q
gQZ[^V
|P#xA=hB
0aOWS
8m\`@Q
0$DPNn
;%*y0a
4^mhXx
]WMh;T`f#
ORygr
Ilp<L
C.3dm=
2xeR'~
$C_/IU
,#[gNL
,'pS0M
PPb4dlM
>Ovr!f
C5k{&d
hG=8KY
O45zjQ
}yyi?
ir0cMw
>pCuUZ
;lGAd6h
Ts5tmJ
.d7];@
GGizV)
U6A1yMf
S3}s^R
-S(A0@
YP1$d&
<UEb7~
,yxV=!
?KP84:
nCWOLx>
O\]c3k
51%[%
K:N]??
U_EcxL%%
[sz=Ek
`]mtC[
8;S[&[
sF-=M5
bJ"xjwyU
BeW?Ms\
s4[jv
/K,HEf.
L.f}>C
=(3km/
4fK]0;}
$;J8{%zm
&DZR-
_E$LQ,hRZ
>H')^D
B(-QfC
_PLi@!1k!n8
15Yxa{/d
&[cTQH7u
o4sI|^u
^G?n%T3
6t="J&^y
BaqPkM
ppA^3X:bC!
|Q[6TKIP
JX`BMA
k.5532
H9ff[b
(s[nz
U$H3v=b
SR--#Z8
)]jBl ch%
T,y"QZ
'R%+C`
F=XU,_
*VT'j/!
|e5#|>A
LhE}jyy
@pR_CdE
B!kb^k
I-YYoo6
x0][Hr
o$a(}t
;:JSc|R%<qaa
Cm)Nwf
;Jf4a?
;%\EUGG>
i2|JZy
AP!Pgv
Mqk mh Y
TDc4e<
mNi?)N
o6ILx6
+9SX#~$
%'Aqtr
y^EErE
0hc{T{"
-rn 7X
8018jF
uZcL@U
$TK0?9
0N1yV\mD
]B#_$'
?*@1-;
zo:f65
BE!^oY`0Et
Dms8TuK
cpnZGs
E6fOm,
onJYU';b
yBLd]I
qt\Qu_NL
;M{}1#[
R.22"+
MSg\|
<]\z6C[p
wv#,gn
Vj!]r${
OIu^'#-
HERuz7
<9;9nE
nf<FxV
_%5k#[
Z:!=lI
67G&Fxy
3}InM*8
Z1B%f}x
gxh3F(
^6RY@=
2_"+a.=y
{7Y7"W
M:u^89
+SMTCH
QtS{MT
c3zO1g
OB(vv@
na {L.
c~Uc`}6
;3}*on
(L&yu+
yzETne5
SV#%1iE
aYXY|zZ
q,Qg:5
BD}Eimr
2.h145AqN
h<YL33^
<b4esdjE
WzD&@I
,:@7Fx
-a#pHhP'EZh
|{!*c~dp
?5jZ_}
n.eZ{s
mLkL;@
?p%HjT
m-+URvv%
4_F"kI
|G[ #gC
><939<
JyvYzM
p00b=:G"y{
z74uwOf
Fl)WO)
~(w69'
>MT' -
Af7L=
OI9rHd
I`o5O{n
=F&iKz
ZOoQI/
q>K/#8
2Q'7_tO
xQI2zI(V
h*BrxH
l?5$!G
tgJky">g
07D=/3
YB7\!J
]Y,OEx
2i?Tz}^
v=-(Hx
}<`$)"0
k D!E!
PBGZq-
}k/k{F
/Bn/}6
vRrMhVKD
-vv>y1J
*|'#K5
KdH:.50
z%H'"*zc
3Tp'Kusk
o_7i}>
I*+\_|
}q[g>o
e3o 9a|
~/_HXQ
_:/Cum
<`J%?=
Ai.:Bo
5KzjCCC
6CX=Ty
,_{bwI#
7Scu-T.
,8@\dy
T@G&e:
8^D_S{
6!AoQTR
W#&!3b
Z|rs2g
G$\7\7
k<{CR?
Q}"?VN
V/J|!
7'n(6'_
5;YgoH
|sDU*t
X_79_5
M[\gLZw
$k#VWZ
~M:u+hV
.n] 1s&
U@Qy;o2
t5DyLH
.1r-t,Z
B3&<3q
|}HR=!
JEV#:0
QhN~Qn
7K=D%q
Z)g+G9
)K6"V|
,'p^gn[^
FJ34Q5O
~uY_/%`
<,q;)`
vM35's
,CARLi
~f6tH^
XJUn+c
akVk2Z
kN{P|p
cz6Dd@
<~DsTf
e"wz@E
.6T1\r
RsKC
p<>>cd
Luc<oNm
{`5X@s
C"BAc)
m7a)_V
ez[{YM|J
>JwL)7z
q9]:h>
6D]ZAs;
oTV/_N
Ys`<@S
B^}M^q&C
_):)4XH
"x^!,l
9!CZYS
f#\fC-
>T!JTnf
q{J3}~G
]rgb&3
[Iho0E
R-=<}v
%y+ts$
h73"f[H
6<:Z;e_
[hurh1G[6
V2Wyd`
qhB_K1
i.LnHBl
Dk:a/b.
_qR9N
h37p!*|^f>
Ka^VJ`M1a
Bhj1-%
QY\hq
)k9O2!h%z{t
z*MDrX1q:
nj5S0Vh;
Y6Cp4J
@RN:{t
: Fgun
\J=|js'
:cPxY
8o@?H(
\n<,Ym
(UgPtj
:I9},
OO`8<
ihH9K.-o
GkZ!4`h
mW'~dck
e~Z}iv
#gP$50
h=oke_
AQP%jw
!_3q(*0
wT.S'Y
SJo{W$
k$gx@&
^lbho/
iw}*tlE
-]^=pB
LA2!K(
L|a;va
aTN\WC
VyW'|x5Q
>"{5BG
m{;;+y
I"/vP(
c{,2;Q$
,Q~G7hT
Grg8A,5S
-i^.vq
EIQ6zH
d\Cgb
Ho*HF]
Uk|iy
jgc B@
[)%&o,+
*o,[>Q7
p%Mlgj
J~*,uc_n
9(J~gN
e4~t,?UWYI
.?`JF@w
?,aGBu("F
F}wb0h
K6uEqd
mW~_r<X?<
zezCh)
mmRXH^
z]?qmZ9C
/:9lcW
Ea'=MS
Rfhn M
cDisplayClass1.pdb
_CorExeMain
mscoree.dll
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0"><assemblyIdentity name="ZoomInstaller" processorArchitecture="*" version="1.0.0.0" type="win32"></assemblyIdentity><description>ZoomInstaller</description><dependency><dependentAssembly><assemblyIdentity type="win32" name="Microsoft.Windows.Common-Controls" version="6.0.0.0" processorArchitecture="*" publicKeyToken="6595b64144ccf1df" language="*"></assemblyIdentity></dependentAssembly></dependency><trustInfo xmlns="urn:schemas-microsoft-com:asm.v3"><security><requestedPrivileges><requestedExecutionLevel level="asInvoker" uiAccess="false"></requestedExecutionLevel></requestedPrivileges></security></trustInfo><compatibility xmlns="urn:schemas-microsoft-com:compatibility.v1"><application><supportedOS Id="{8e0f7a12-bfb3-4fe8-b9a5-48fd50a15a9a}"></supportedOS><supportedOS Id="{35138b9a-5d96-4fbd-8e2d-a2440225f93a}"></supportedOS><supportedOS Id="{e2011457-1546-43c5-a5fe-008deee3d3f0}"></supportedOS><supportedOS Id="{4a2f28e3-53b9-4441-ba9c-d6
Greater Manchester1
Salford1
Comodo CA Limited1!0
AAA Certificate Services0
040101000000Z
281231235959Z0
Greater Manchester1
Salford1
COMODO CA Limited1+0)
"COMODO RSA Certification Authority0
HCgNr*
2http://crl.comodoca.com/AAACertificateServices.crl04
http://ocsp.comodoca.com0
Greater Manchester1
Salford1
COMODO CA Limited1705
.COMODO RSA Extended Validation Code Signing CA0
191007000000Z
221006235959Z0
943491
Private Organization1
Dubai1
Dubai1;09
2Business Central Towers, Tower A, Office 2301 23031
Telegram FZ-LLC1
Telegram FZ-LLC0
https://sectigo.com/CPS0U
Dhttp://crl.comodoca.com/COMODORSAExtendedValidationCodeSigningCA.crl0
Dhttp://crt.comodoca.com/COMODORSAExtendedValidationCodeSigningCA.crt0$
http://ocsp.comodoca.com0#
AE-943490
Greater Manchester1
Salford1
COMODO CA Limited1+0)
"COMODO RSA Certification Authority0
141203000000Z
291202235959Z0
Greater Manchester1
Salford1
COMODO CA Limited1705
.COMODO RSA Extended Validation Code Signing CA0
=U5W5H
https://secure.comodo.com/CPS0L
;http://crl.comodoca.com/COMODORSACertificationAuthority.crl0q
/http://crt.comodoca.com/COMODORSAAddTrustCA.crt0$
http://ocsp.comodoca.com0
Greater Manchester1
Salford1
COMODO CA Limited1705
.COMODO RSA Extended Validation Code Signing CA
20210320173440Z
Greater Manchester1
Salford1
Sectigo Limited1,0*
#Sectigo RSA Time Stamping Signer #2
Greater Manchester1
Salford1
Sectigo Limited1%0#
Sectigo RSA Time Stamping CA0
201023000000Z
320122235959Z0
Greater Manchester1
Salford1
Sectigo Limited1,0*
#Sectigo RSA Time Stamping Signer #20
https://sectigo.com/CPS0D
3http://crl.sectigo.com/SectigoRSATimeStampingCA.crl0t
3http://crt.sectigo.com/SectigoRSATimeStampingCA.crt0#
http://ocsp.sectigo.com0
New Jersey1
Jersey City1
The USERTRUST Network1.0,
%USERTrust RSA Certification Authority0
190502000000Z
380118235959Z0}1
Greater Manchester1
Salford1
Sectigo Limited1%0#
Sectigo RSA Time Stamping CA0
?http://crl.usertrust.com/USERTrustRSACertificationAuthority.crl0v
3http://crt.usertrust.com/USERTrustRSAAddTrustCA.crt0%
http://ocsp.usertrust.com0
rRj;B7|
[C]e=P
Greater Manchester1
Salford1
Sectigo Limited1%0#
Sectigo RSA Time Stamping CA
210320173440Z0?
New Jersey1
Jersey City1
The USERTRUST Network1.0,
%USERTrust RSA Certification Authority
5AWfq@gY6
-,4365758795:5;5<5=5>5?5@5A5B5C5D5GFHFJIKILIMINIOIPI
System.Core, Version=3.5.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089
System.Security.Cryptography.AesCryptoServiceProvider
Debugger Detected
{11111-22222-50001-00000}
GetDelegateForFunctionPointer
clrjit.dll
System.Reflection.RuntimeModule
m_pData
System.Reflection.ReflectionContext
file:///
Location
ResourceA
Virtual
Write
Process
Memory
Protect
Process
Close
Handle
kernel
32.dll
{11111-22222-20001-00001}
{11111-22222-20001-00002}
{11111-22222-40001-00001}
{11111-22222-40001-00002}
Extraction Failed
File is corrupt
Cannot create folder '{0}'
Extracting
VS_VERSION_INFO
StringFileInfo
040904e4
Comments
Zoom Meetings Installer
CompanyName
Zoom Video Communications, Inc.
FileDescription
Zoom Meetings Installer
FileVersion
5,6,0,0
InternalName
Zoom Meetings Installer
LegalCopyright
Zoom Video Communications, Inc. All rights reserved.
LegalTrademarks
Zoom Meetings Installer
OriginalFilename
Zoom Meetings Installer
ProductName
Zoom Meetings Installer
ProductVersion
5,6,0,0
VarFileInfo
Translation
Antivirus Signature
Bkav Clean
Lionic Clean
Elastic malicious (high confidence)
MicroWorld-eScan Clean
CMC Clean
CAT-QuickHeal Clean
ALYac Clean
Cylance Clean
VIPRE Clean
Sangfor Clean
K7AntiVirus Trojan ( 0057df2d1 )
BitDefender Clean
K7GW Trojan ( 0057df2d1 )
Cybereason malicious.66b29b
Baidu Clean
Cyren Clean
Symantec Clean
ESET-NOD32 Clean
APEX Clean
Paloalto generic.ml
ClamAV Clean
Kaspersky UDS:DangerousObject.Multi.Generic
Alibaba Clean
NANO-Antivirus Clean
ViRobot Clean
Tencent Clean
Ad-Aware Clean
TACHYON Clean
Emsisoft Clean
Comodo Clean
F-Secure Clean
DrWeb Clean
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition Artemis!Trojan
MaxSecure Clean
FireEye Clean
Sophos Clean
Ikarus Clean
GData Clean
Jiangmin Clean
Webroot Clean
Avira Clean
Antiy-AVL Clean
Kingsoft Clean
Gridinsoft Clean
Arcabit Clean
SUPERAntiSpyware Clean
ZoneAlarm Clean
Microsoft Trojan:Win32/AgentTesla!ml
Cynet Clean
AhnLab-V3 Clean
Acronis Clean
McAfee Artemis!158F91E5817B
MAX Clean
VBA32 Clean
Malwarebytes Clean
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Rising Clean
Yandex Clean
SentinelOne Static AI - Suspicious PE
eGambit PE.Heur.InvalidSig
Fortinet Clean
BitDefenderTheta Clean
AVG FileRepMetagen [Malware]
Avast FileRepMetagen [Malware]
CrowdStrike win/malicious_confidence_90% (W)
Qihoo-360 Clean
No IRMA results available.