Static | ZeroBOX

PE Compile Time

2021-07-29 15:19:32

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x000fd7b0 0x000fd800 7.68724737418
.rsrc 0x00100000 0x00030790 0x00030800 5.84440755157
.reloc 0x00132000 0x0000000c 0x00000200 0.101910425663

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x0012fd30 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x0012fd30 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x0012fd30 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x0012fd30 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x0012fd30 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x0012fd30 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x0012fd30 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x0012fd30 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x0012fd30 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_GROUP_ICON 0x001301a8 0x00000084 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_VERSION 0x0013023c 0x00000354 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_MANIFEST 0x001305a0 0x000001ea LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with CRLF line terminators

Imports

Library mscoree.dll:
0x402000 _CorExeMain

!This program cannot be run in DOS mode.
`.rsrc
@.reloc
k}s;
u+s>
u+s>
u+s>
u+s>
z4s>
")s>
")s>
")s>
""s>
dTs>
dTs>
dTs>
YTs>
*;s;
YTs>
[%s>
/*s;
t%s>
v4.0.30319
#Strings
get_Label10
set_Label10
get_Label20
set_Label20
get_Label30
set_Label30
get_ParamArray0
get_Label11
set_Label11
get_Label21
set_Label21
get_Label31
set_Label31
ThreadSafeObjectProvider`1
get_Label1
set_Label1
m_Form1
get_Form1
set_Form1
get_Button1
set_Button1
get_ProgressBar1
set_ProgressBar1
get_Timer1
set_Timer1
get_DataGridView1
set_DataGridView1
get_PictureBox1
set_PictureBox1
get_GroupBox1
set_GroupBox1
get_TextBox1
set_TextBox1
get_Germany1
get_Label12
set_Label12
get_Label22
set_Label22
get_Label32
set_Label32
get_Label2
set_Label2
m_Form2
get_Form2
set_Form2
form1dan2
get_Button2
set_Button2
get__1457028_w2
get_DataGridView2
set_DataGridView2
get_PictureBox2
set_PictureBox2
get_Label13
set_Label13
get_Label23
set_Label23
get_Label33
set_Label33
get_Label3
set_Label3
m_Form3
get_Form3
set_Form3
get_Button3
set_Button3
get_DataGridView3
set_DataGridView3
get_PictureBox3
set_PictureBox3
get_Label14
set_Label14
get_Label24
set_Label24
get_Label34
set_Label34
get_Label4
set_Label4
get_PictureBox4
set_PictureBox4
get_Label15
set_Label15
get_Label25
set_Label25
get_Label35
set_Label35
get_Label5
set_Label5
get_Button5
set_Button5
get_PictureBox5
set_PictureBox5
get_Label16
set_Label16
get_Label26
set_Label26
get_Label6
set_Label6
get_Label17
set_Label17
get_Label27
set_Label27
get_Label7
set_Label7
get_Label18
set_Label18
get_Label28
set_Label28
get_Label8
set_Label8
get_Label19
set_Label19
get_Label29
set_Label29
get_Label9
set_Label9
<Module>
Dispose__Instance__
Create__Instance__
StoreTransactionDa
get_chelsea
m_Italia
get_Italia
set_Italia
System.Data
ProjectData
System.Data.OleDb
DialogsLib
mscorlib
Microsoft.VisualBasic
Thread
Form1_Load
Form2_Load
Form3_Load
add_Load
Score_Load
Profil_Load
newPlayer_Load
get_Red
set_Enabled
get_IsDisposed
m_FormBeingCreated
Synchronized
DataGridViewBand
get_England
OleDbCommand
CreateInstance
get_GetInstance
defaultInstance
instance
set_DataSource
get_de
GetHashCode
set_AutoScaleMode
set_ColumnHeadersHeightSizeMode
DataGridViewColumnHeadersHeightSizeMode
set_BackgroundImage
get_Message
get_DarkOrange
DataTable
IDisposable
Hashtable
set_Visible
ToDouble
RuntimeTypeHandle
GetTypeFromHandle
Console
FontStyle
MsgBoxStyle
set_Name
rename
DateAndTime
DateTime
get_labtime
set_labtime
get_labcutime
set_labcutime
WriteLine
set_Multiline
GetType
m_Score
get_Score
set_Score
get_Culture
set_Culture
resourceCulture
ConsoleApplicationBase
ButtonBase
ApplicationSettingsBase
TextBoxBase
Response
m_choose
get_choose
set_choose
Dispose
DebuggerBrowsableState
EditorBrowsableState
ThreadStaticAttribute
STAThreadAttribute
CompilerGeneratedAttribute
DesignerGeneratedAttribute
GuidAttribute
HelpKeywordAttribute
GeneratedCodeAttribute
DebuggerNonUserCodeAttribute
DebuggableAttribute
DebuggerBrowsableAttribute
EditorBrowsableAttribute
ComVisibleAttribute
AssemblyTitleAttribute
StandardModuleAttribute
HideModuleNameAttribute
DebuggerStepThroughAttribute
AssemblyTrademarkAttribute
TargetFrameworkAttribute
DebuggerHiddenAttribute
AssemblyFileVersionAttribute
MyGroupCollectionAttribute
AssemblyDescriptionAttribute
CompilationRelaxationsAttribute
AssemblyProductAttribute
AssemblyCopyrightAttribute
get_ArrayAttribute
AssemblyCompanyAttribute
RuntimeCompatibilityAttribute
AccessedThroughPropertyAttribute
get_DeepSkyBlue
get_Value
set_Value
m_ThreadStaticValue
WithEventsValue
GetObjectValue
Remove
StoreTransactionDa.exe
set_Size
set_AutoSize
set_ClientSize
ISupportInitialize
System.Threading
NewLateBinding
System.Runtime.Versioning
GetResourceString
CompareString
ToString
disposing
System.Drawing
get_Manchester_United_FC_crest_svg
tambah
get_StartupPath
get_Length
Koneksi
bukakoneksi
sintak
Callstack
Timer1_Tick
add_Tick
remove_Tick
Label10_Click
Label11_Click
Label1_Click
Button1_Click
PictureBox1_Click
Label12_Click
Button2_Click
PictureBox2_Click
Label3_Click
Button3_Click
PictureBox3_Click
Label4_Click
PictureBox4_Click
Label5_Click
Button5_Click
PictureBox5_Click
Label6_Click
Label7_Click
Label8_Click
Label9_Click
add_Click
remove_Click
Helplink
get_arsenal
ConditionalCompareObjectEqual
set_Interval
System.ComponentModel
m_Profil
get_Profil
set_Profil
tampil
DotsCell
DataGridViewCell
ContainerControl
m_Spanyol
get_Spanyol
set_Spanyol
get_Tottenham
Program
get_Item
System
set_Maximum
resourceMan
get_Tan
m_Jerman
get_Jerman
set_Jerman
System.ComponentModel.Design
AppDomain
GetDomain
MessageBoxIcon
get_Application
MyApplication
set_Location
System.Configuration
System.Globalization
Interaction
System.Reflection
DataTableCollection
ControlCollection
OleDbConnection
get_ActiveCaption
get_GradientActiveCaption
TargetInvocationException
InvalidOperationException
get_InnerException
ArgumentException
System.Data.Common
get_Maroon
Button
get_Brown
get_SaddleBrown
get_SandyBrown
get_RosyBrown
CultureInfo
Bitmap
set_TabStop
EndApp
ProgressBar
Linear
GetChar
InvokeMember
OleDbDataReader
ExecuteReader
m_AppObjectProvider
m_UserObjectProvider
m_ComputerObjectProvider
m_MyWebServicesObjectProvider
m_MyFormsObjectProvider
sender
Binder
get_ResourceManager
ComponentResourceManager
EventHandler
System.CodeDom.Compiler
IContainer
get_User
m_New_User
get_New_User
set_New_User
Hunter
OleDbDataAdapter
get_Computer
MyComputer
get_Silver
m_newPlayer
get_newPlayer
set_newPlayer
set_ForeColor
set_BackColor
set_UseVisualStyleBackColor
ReturnError
ClearProjectError
SetProjectError
Activator
.cctor
connStr
System.Diagnostics
get_es
Microsoft.VisualBasic.Devices
get_WebServices
MyWebServices
Microsoft.VisualBasic.ApplicationServices
System.Runtime.InteropServices
Microsoft.VisualBasic.CompilerServices
System.Runtime.CompilerServices
System.Resources
form1dan2.My.Resources
form1dan2.Form1.resources
form1dan2.Form2.resources
form1dan2.Form3.resources
form1dan2.Italia.resources
form1dan2.Score.resources
form1dan2.choose.resources
form1dan2.Profil.resources
form1dan2.Spanyol.resources
form1dan2.Jerman.resources
form1dan2.New_User.resources
form1dan2.newPlayer.resources
form1dan2.Resources.resources
form1dan2.Inggris.resources
DebuggingModes
get_Tables
EnableVisualStyles
BindingFlags
Strings
get_Settings
MySettings
EventArgs
m_Inggris
get_Inggris
set_Inggris
ReferenceEquals
get_Controls
System.Windows.Forms
get_Forms
MyForms
set_AutoScaleDimensions
Conversions
System.Collections
MessageBoxButtons
get_Chars
RuntimeHelpers
SystemColors
Operators
components
Concat
Format
AddObject
GetObject
MyProject
LateGet
DataSet
get_MenuHighlight
get_it
EndInit
BeginInit
GraphicsUnit
get_Default
SetCompatibleTextRenderingDefault
DialogResult
MsgBoxResult
InitializeComponent
get_Transparent
set_Font
SuspendLayout
set_BackgroundImageLayout
ResumeLayout
PerformLayout
get_Text
set_Text
get_CryptoKeyAccessRu
DataGridView
get_CurrentRow
DataGridViewRow
get_Index
set_TabIndex
get_NewRowIndex
MessageBox
PictureBox
MsgBox
GroupBox
TextBox
form1dan2.My
get_TimeOfDay
ToCharArray
ContainsKey
get_Assembly
get_Germany
ExecuteNonQuery
MySettingsProperty
WrapNonExceptionThrows
form1dan2
Profitpros
Profitpros (C)
$fa65ce2b-c7e2-4e98-9bfe-acc122d3913d
2.0.5.0
).NETFramework,Version=v4.0,Profile=Client
FrameworkDisplayName.NET Framework 4 Client Profile
Button1
Button2
Button3
Button5
ProgressBar1
Timer1
Label1
labtime
Label2
labcutime
GroupBox1
Label11
Label3
Label4
Label5
Label10
Label6
Label9
Label7
Label8
DataGridView1
Label12
DataGridView2
DataGridView3
Label34
Label35
Label13
Label14
Label15
Label16
Label17
Label18
Label19
Label20
Label21
Label22
Label23
Label24
Label25
Label26
Label27
Label28
Label29
Label30
Label31
Label32
Label33
PictureBox1
PictureBox2
PictureBox3
PictureBox4
PictureBox5
TextBox1
MyTemplate
11.0.0.0
3System.Resources.Tools.StronglyTypedResourceBuilder
16.0.0.0
KMicrosoft.VisualStudio.Editors.SettingsDesigner.SettingsSingleFileGenerator
16.0.0.0
System.Windows.Forms.Form
Create__Instance__
Dispose__Instance__
My.MyProject.Forms
4System.Web.Services.Protocols.SoapHttpClientProtocol
Create__Instance__
Dispose__Instance__
My.Computer
My.Application
My.User
My.Forms
My.WebServices
My.Settings
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
hSystem.Drawing.Bitmap, System.Drawing, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3aPADPAD
QSystem.Drawing, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a
System.Drawing.Bitmap
UNICODE
$.' ",#
(7),01444'9=82<.342
!22222222222222222222222222222222222222222222222222
%&'()*456789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz
&'()*56789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz
4c+! n?Z
5Zy"d!f
rM*F7~
mO3n9f
L7@U*m
\Cne2&
I#XneF
kY9MY&e
T:t)2F
Uf;+4]
bgkxAR
U9nmdWCpQ:
9>&VK!
ebz+-Z
V,.%$+v
8 rG=O
,.X^33
\jS["\&
#5Rm#L
qao1&HWw
kNp]53
?"k5ui
+3Spn*
VK7^1])A
J+u=EYKH
_$zR4`U
0=)AQU
ep;RG">
UI-O`j
784m,9
7R?zpi
Tft*VA
Rn;2y\
R/ZxCJ
fS.z/4
R$8=+Amy
UPEXFjx
=khF1MhA
yNGZrG
XFwO.~
u}^Rwz
>E&EV.EFd$
#mt}OZ
O<zT/<
}8ldTohe#s
.f"mV{
it}FKm>
NzR[^El
f(/L.L\
KwM[Masl
hRA7U3
ZF~T1/
nNFsW<
Gg)=F=
fFy?xM
kckpE|
.$=W';G
+j:\wp
+!9*})J\
Kkr@;NP
J;vWFc
$;S+28
K#!o+N
uo@{zm
]@A{i5
h0zlp?J
R){)=
4dKI_b[
{0M5s1~
$gponNiV+
]Z&V{Ti
9~)b(&
B7m5H.
Uk]29nX5
EPk[[DF
4G8=x^
}>[?;2
=Oa^w$
#4Y?68'
LE]CP[
Eo)y%f
QNNN@?)8
DEXC T
+r]2O4
dS&uT%
&>R22:
;@.yrrFT
3N[_.d
bjkK{f
5,:bGo
gfO?L}:U
~uw3/
Drc,x9?
$K#r29
M'Ul.b
e8%S$T
D%A>Lg
SDVV%A!
dJ3;`dFy
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
hSystem.Drawing.Bitmap, System.Drawing, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3aPADPAD
QSystem.Drawing, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a
System.Drawing.Bitmap
%&'()*456789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz
&'()*56789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz
F0piLc
8G=HAU
^K{gYb
kz?}o8
N}}kc""Kc8
QE8.{P
T*@#a8=p}
REe*GP{
9 2Om!
[Xu[Al
f&!GN['
CjA?( w
dWeuV#
2>YV%_
V%[,-
1,rOSR<
]6ML]N
HIrH?e,v
uMp_\\~
<)iqn66p
IW=X/<
_?\xR#
-CRYuK
F3Iuu$
wqIo4,\H
iKyz~$
]2-2-K
c,[vNz
PC"]G,2%
S<Ij,l
^FI%QW?A
hAtTI
Q!'i*UOr
F>RrNzW
.BKois
;rZ)"f.
V9d(y#
5)VY,l
x{NK=+C
|B<-c1;
3uki3l
iqje.mm'WE
Ye0kK_
+!# 0
%Ib}I=k
KHAeF!O
i$B[k6
,-[Rcm
zW=8*k
$gvgv9,
|2XFHA
dz0S~G
,^BNr3E<
]L]G:k
Xx{KQ%
V@EGR[
duA9n2
hCo^UI).VwE
1ZmndeQ
All"Yn
.5yci7
mj}T%K
=/vHVymZ<
m"v$[a{=
qgpBrTV
s7DQBT
HKy/|3
\K"oFV
^k=r7|
p\}iuK
)!U_,1
yd%$fPs
nka#2!
v!9kOs
eispl#
I_#9@r
k3P6HXG
!|x3^\
bU#k?-
y2Jp\nR
_:E,y8
ZLcp88
~{W7sjD
b2Dg;~
_Saf20U
d#fc&Q
o.6=H\
k[?NkJ
SU.|Sys
*en:~5S
.;{Wcc
h-[2wa
=*/"sk
9;Alrp:W
i8->>l
SolW3}s
O$T0@
!n/dKh
]v}.c$cc
T/|Ksq#
rI=k<1
zV-6zT
5TQu/=
!jKE(v
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
PADPADP
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
PADPADP
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
PADPADP
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
hSystem.Drawing.Bitmap, System.Drawing, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3aPADPAD
QSystem.Drawing, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a
System.Drawing.Bitmap
IDAThC
,BTl@D
>Vlr.
rxce%E$
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
hSystem.Drawing.Bitmap, System.Drawing, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3aPADPAD
QSystem.Drawing, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a
System.Drawing.Bitmap
IDAThC
^z;vMP
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
hSystem.Drawing.Bitmap, System.Drawing, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3aPADPAD
QSystem.Drawing, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a
System.Drawing.Bitmap
LIDAThC
7nClrEX
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
hSystem.Drawing.Bitmap, System.Drawing, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3aPADPAD.
QSystem.Drawing, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a
System.Drawing.Bitmap
%&'()*456789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz
&'()*56789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz
F0piLc
8G=HAU
^K{gYb
kz?}o8
N}}kc""Kc8
QE8.{P
T*@#a8=p}
REe*GP{
9 2Om!
[Xu[Al
f&!GN['
CjA?( w
dWeuV#
2>YV%_
V%[,-
1,rOSR<
]6ML]N
HIrH?e,v
uMp_\\~
<)iqn66p
IW=X/<
_?\xR#
-CRYuK
F3Iuu$
wqIo4,\H
iKyz~$
]2-2-K
c,[vNz
PC"]G,2%
S<Ij,l
^FI%QW?A
hAtTI
Q!'i*UOr
F>RrNzW
.BKois
;rZ)"f.
V9d(y#
5)VY,l
x{NK=+C
|B<-c1;
3uki3l
iqje.mm'WE
Ye0kK_
+!# 0
%Ib}I=k
KHAeF!O
i$B[k6
,-[Rcm
zW=8*k
$gvgv9,
|2XFHA
dz0S~G
,^BNr3E<
]L]G:k
Xx{KQ%
V@EGR[
duA9n2
hCo^UI).VwE
1ZmndeQ
All"Yn
.5yci7
mj}T%K
=/vHVymZ<
m"v$[a{=
qgpBrTV
s7DQBT
HKy/|3
\K"oFV
^k=r7|
p\}iuK
)!U_,1
yd%$fPs
nka#2!
v!9kOs
eispl#
I_#9@r
k3P6HXG
!|x3^\
bU#k?-
y2Jp\nR
_:E,y8
ZLcp88
~{W7sjD
b2Dg;~
_Saf20U
d#fc&Q
o.6=H\
k[?NkJ
SU.|Sys
*en:~5S
.;{Wcc
h-[2wa
=*/"sk
9;Alrp:W
i8->>l
SolW3}s
O$T0@
!n/dKh
]v}.c$cc
T/|Ksq#
rI=k<1
zV-6zT
5TQu/=
!jKE(v
QSystem.Drawing, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a
System.Drawing.Bitmap
IDATx^\
vvfN!s
(aS.ju
ANHC2j<
SNXe^yya
#L'YZ.
W{Y(aF,
=DL,}q
#f{p[M
yLy1+-*}
%Hbi{b
rGYs#f
MskQ@BnK
"'%s_h{
{NT8&sj
ZR<i41Y
5Daa7)
ED}PH1
b6zt7b,
ZEL<:/
..qxvRP
=^ut]}
A)^)6{ ]
Dc9<?l
z$,R\p`Pn
b)i:j
XCi<0PH
Y*TKK@
.*7+|]s
Rx_>Kn
|}z*g8
41of,b<s%
Y060?x6
z`f$];Z1
hr3U g
3KZA2i
-EZ2E\
^[3Iz6
\(yG6i
1OV2edhA
/RsK:
g+cY$-
!TK95d
w5<@ac
MV)|IZN$
Nd."b=d
-f1[7z&
?|s+hx
uOzjFTJ.]
GQD/l0
^suS[SG
2GO$<j
}Z!2`g
e'EOovu
C\8$Jq
ss"5Wa
Y?z|>~
A'F#8/
X.O*^!A[
c5]S;(1
3`a4GK)
P&-MclF
_=ixRJ9a
it5&hq
"^%cwI,L
oH7&Jk
E/IEiB
j#DE1Gv
;$D~4T
2XZKek2J
J<U]!4e
_Sm9mv
i4w87=
X78\92
8NYByZ
e~.q|`
&y&$JmG3
e|!JUd.
$X6')t
S<YY6R
a32]I#w
Q[/'~~
Gn;C)Jo
,t](S{S
@6#]Sl
vaC[RCe
9RSwd8
i9DOqT
0gaPF0
bAi&SV
[K_LTp
|AWd{9
YiaY=T
[YiKY|,
`#2'_n
-, Sfd
caR!$*Hr
Z00|q;*
yRtUe<
p9K\<lV
/X2})j
7t:7C
%VLR$UZ(
~`$bF
u2Y;UdD
$FE?Y>
[<LZEg
'S=k$
f$BR9]
b"5m&G{
^!K;|:vi
I=kzG%
28!F(#H
zo7>q[
E=&Oh8
Kdf7h>Ad
?7gm01
#"|.FvKc9
^s}UIK
bn#Q!g9
>)>|y5
nL]W4y
i)*",>5
@_Yf+W(=
vj6B#|
t9}$y,C
@hi%fl
g^wSj;
&KE{o,8
u)*)_1h
-ECnW"
4@Q;)tx
wJ"w10i
J16a S
~oi-d@
/cTG __
0c3aGi
2C%.qKilt
;h2>)>o&
DR/D[a
Ph\Jc"x
,%lw$Up
O.)g"@>
p-\G.>
8C> bA\c
B>"2DbK
~q:snz
YXo(>O'
]wZ>*P
\/)J U
_lgcLQ2
#>kqt4a|
qNfQ{>
&aG)B?Q_2
#[iG/^
wv`S}i9H*P
8/$/O'
S*Ioe|(
Xq"Jec
$uCMjZ#F
KtTRdP/
3/-E(c4a
w:Tm;h
,SgCpE
V"Drv
,23KSg?
^>^u2xm
~.Ik)Lp
{#l)BA
(tPo b
::'wp,
itoRfGNp
hjtLH7
p"u4~o
'<{yvQ)
"FFr3J
*m]T>r
N20L7j
<9\e9'
?0c 0g
E7TN]E}
6/z4{M
Y.Fj*a1^
FNq#`7
C"noAc
8JD]`]
%f;@0,
4_#{5vk
+qfO+bX
+Xj&B6'
:!Q.Dt
r;eT4$m
V=|X}m
fVMLJ}
DDNHM"
[d>jI)
?U3b{_h
>c13'g
st6DZ5/L83$
/ai3BU
h]:$J%
h#PTzx
yQ&K\ t
ecmyas
J\W2aJ
i}2Jx
&K$\Whuk
+rRqEMp
jQ%'w@k
R\n?li
@S)m5e
ZWc0xh
PV1/5N
-4xm6x9
*lF}|}
6uV9{gS
'(a7S21
$+z:IA#I
$U\lLf75"
B"LIvG<
O7QD'F
N0(c f
"|PCmY
X)XQ|z
.gM4>K
\]o=yn
VGgvO7_'cX
pZs1$h!(U
>Gk/+O
D5Iel
fq=W@N
/O9+!WM
9S7:@}G
7?(8rJ;p
atIpm$>
_:ZA9tQ
[+@*Q9
;ZS6G'
hQ7hF%}F
+|'I2~.h{
&7d8qw
|?{IHd
a(|a7|
.`p-ug=
:+HdGb
\EiQ1f
4xiVy
G+c{;R1B
%~P^mhK
,ix8Jrs
:N`Z#pm
X|a+0[gm
EVN/l
K9iuE9
hR=[-9
=O_ N1
$H/T b
G:w&u%
psgJ0~
<8>R(ES
%M1[.Vju
(0 ;1N
a@fH'tD
_,pm:Qm
RE4Ab&}
F11Oh4
pR+\M$!a
KSQ2Fm#!
m8!=k{
{&aek2(;
R8/\_]a)
5HuVz-a
waq}!7
o?9>/7;
=wu;2:h
sVn^q0/J*$B
m>%b|/b
~bP[$4I
<QJssq
::}S4h
7K8@i-
pU!'gUB`
MK]=:[WXT
q2#~V
#f<)e7
S[\qp`
V"SzBk'uU
\7q+"
kq6Q[X^z
Ws_O[5
n>iqqZ
t*Vj#0
-1U&AM/
8k$Hm%
-t?(&z
hk'k5d
):Hf"k
Vz!oNb
vLzTPZ
/KL/lrq9
gwI.B"`x
:6 tYa
#)TiCHn
LP!Xb!l
Av"w
NfZ-}%
4^ih3f
q68g9,-
7i<~o%
3*s?OE
z>e`m\
)VBppFR
sH>!u
n[bs}On
~zY;iH
&/LjAh:
>c&RPlt
;K-YWG
`,(MA=
94J1KfE
HCvDX;Oj
3/35DA
>g}#0J:
@gt$y6
E"$r/]
M(-w|4
muof--
$l6n2n"f
5zjwOs
G$[9N4wg
"IW|\^2
j|A>VkhQ<
ScRiyK
KzA$wll
MsXJ1*qv
MR&_}i%
D.rn &
9+;lw}P
()l`BF6
ig,Ws(/
aQTp2Q8
_;J?!/
<C4]6r
<u*zml
h( lb-
wtg*H*
U.8|5m
J4<M^<
(rZ*Lp
PuK,/?
pE`|}U
\/_P@{
{cY%50
|LwQphK
%(+F5d
]q ]#A
qRS}"E
C'_Nvb
tJFaN|
8a3>C@=Z
\]vy&!>
\Ka!H*P
_;J[D5
3f@>1m[
4'AwCN
D(n>Mo[c
=#}nVf
FDKfq;J)
C(76&u
a/;<C
o|/MrU(f
1n|FLY
&I'mR3
vmSC\$
/H73kh
w WXefy
wM:zi98M
NN3J+-
3373#t
cL_K2R
yRZq?w
~4eAh5#
g<>}>,
Sw*G}[
|117Yj
B.;i6~
2<Sb2-
;:A=em
Ft|\>&
R"N2'~
RU7$C;
Az)A1m!8
4W`|Se
Cni^cm~
%rch"Bv
`cgW!Ab
f}wRZ)
T7BwHo
8Y$?3
_i)U'#
b|{b S
U-e3Fm
;,^uX$tz1E
O?rzXu
Hcy4*C-N
bD'=B1c
"q2ML`S
mcQ*BE
BH:3RS
h4u['B
Je?`UA
PItMAY
W1dW|%M
{rq6e>
:N-8O9
H>_LMn
}6R8w5Y0c
'b@IT
uN*)-5
1CCmY)
W84ox
&(>VBw
0RbB[7B
naUm57
77\ai_
l5F]w`
I+CV!`
"Q2K)$
gR1T<R/%t
,9{fI)
9Qc5!X1
.QHi1Z!
JdOVt<q
O?P.az#Ut
)S&260
uQ{V8 f
$c@caG
GATvjU
I^$Bwkx
?s4MCD
c\#vLwr0
#zHZMT
]p*6wA+
@n-H 8
@m{>q]N
/d"JfI
"fUe|]
.@t[cS
F!;gd/w"5
N={'xL
~L?1Yp
w@,:9x
9vm8Pp
Q;VdJK
vJ$><jcz
#h[?F$
^a49%<
TFHK{Y
WZj-Q`n
Q}~2<o<
97GTTHh
j=nptC
xFOe;d
;J['=o
iB:Tap
}p}7*1
8xyp>z
ii<bl|^
3:Dmv,
m\rts_
y4EqTD
.3|zD%d
n=<LmE
Cu\D"c
C:JAzi
izN'o/
x#PWA*
#X4zX?
nr<k6Q
B9.Ghx
$ahOU0j
"]&wR2
K";TTX
!g5qwX
T>B=9Z
b-vb0*.m
au_E|P
,C#P>
#B_13o6
BmvYvU
Fe|4\A
U}lw?\
7;k\+3
iV"`^
N6T4N6`
)q5OVJ
23o@\/)
Ef&#n'
F?h:e7
NQk'kQ
OVxRf_
.@>TFs
4S6//>
h;}S6y
DM]F2.
Eo/Yp!
A#<by_
|G*NrA
W,Al[/`
jdb}1h
>q<OA[=
Vkbi)0
k7%'|^
p!:zA9
O4|'5<
,,k8/L
z4|-NH
`(0N.1
-RPbmj
;JS'ptV!
yrIhhat
:(XR2nW^
KVy<|H
%Y*SXf
JY&>&Kz
CPO@6^\
$z1;-
zt}ow1]c
"^^$9.
{K.@W#
ZV]E\%
4>*j1RO
=5ji]W
e&iuW:9}
K5(|,N
<4NEw]
e&g.w(U>^b
p$bw$u
sd!3^
wDUcaZ
NJQ[S+
LA%vN(
_&Z.Yz|
l8&Fh^EF
[cU~q>
p(PFYg<B
Kw"$5G
3S7z$c'0\3Fh
aFJK[=
k<^j.e
YvPvU`f
/%Z=d'->
l5T&>LY-
ec8DwA
!st6tv
$pAI!R
rVu~Y9
i5Rf@
P(MW&X
1lp{A\
"vJc-[
HmbFdP
FAJHp>e
FdQFcms
rCmI90dx
|"CQ?ZMkd
xA{$o>
K|>v\9
$o;A9T^/
<}ae[1
og"#`Q_4
G{q HD
IDAT!-
i`*%EQp
<uhG4<
M 472h,
yj6Kg^
IggU~y
L;uM>{W
[I87jt+1
k0 M;,
l&^dhs
1WvuCp
F)%jSV
j`0VKp
6Dr[O?
_hV?\
&[`oxU$
6o~OA^
gM8{}H
\6n*$h["
u5HRIaW
u\y!7FPq
N?rB&28
O@WGp
N`}~~^
js0io*
=E>Q%NwJDT
: v7GZ
e1_V[d
^~O+z!
N9H]Q[
WJ,_1Yh
zmA>$J
9fZY`]C
Lku<;R9
|B6]G{=
N]s,oy
bCPXc'
+5^A>Q
Cu+0_H
c;fNJ`
H9Fpf(U
}WOX3a
^6 ow
`xsa5LB2
J>&JGW-
5#lP44%3
P?'t@>4
4,ts[?V
@::=B
L1ItB<
HX-%NZ
5rEbnrUd
1>0r.V5
4ba$}X
9*}kVV)
I8=M])e%=)
wSp)(la
PM4_cQN^a
4-=)}Sk
wL.H4D
vvd,CMx@
q2?t/S
]/wr#4
yGf)~6
F[^S)~{=f
||s%!T
pm`9Ti,
-9smnw
=~*UMC
b>0|D8
X.n H*S
fB/t_{
Hm^-uT
(mI*Ja
?'GN.8>j0
6W&(,(
|~dh4
ROA#m<s
`0[gK
9c26a@
wIa^_F
rGfOZq
**Kv;;
$vzJ\fL
:N@t00n
v}Pnd>
2L$*$e
%Dj*m&
;;Fgt=_
?T%/T14
BcoN^=
k"^wb&
:0lG,x
Mu_`f'$
9IXb6lhY[
:Ff"Lv
:-?<+y
4>n-H%D
|@uay!
TBd*h"
n+jgM)
t/&IL(B
48\nh613
S\5Hu4
"u59~^
r8Cd$z
/~xr#^
'EHe-
+QzsWH
^'%%2H
)P6 C"
V}5Qc'
.F01>(
vh(8*}
r50neWy
#0MG(<^{h
H0qahH
= M:E
_DS)*j
Y&vQx'tHp
6]@e)w
X},$E5t)
&d-B3Xi
wp`qJDQ
Z=9?|m
qm=sgL}
IMaE9h
.,'^v|
|RZWSXR
!)8*&-
J7{~S3
@V9T95
t*L:%
Z+@o.
-IL"O@
o`C4$m
/:-zvu
*pP"/,>g
?wJajAO
f)uE.g
XufzUu
P $HuL
Q]XXHX$
djMBI6
G</bTzU;
cwiu#d
q:k\3R
igTV7
Nz"w$p
tqn{)m
OoQAG)
h*!)^}
ST=&Cr
C.0U["
g4zG2mQ
C{;&b}x
1Baw+/
QJ;^!k
|u}B=C
ZByJ)Y
KA5f<v
[u-5MpmCT
9Oy-'m`
T?|#('n
0HW@p0
m'&\;k
-0}czm
D)Bv\O
Wt,4.VN
}8.0d.
ls]c10i(
foymd/%
z9F{]LgH
";br#$
Qm"!IZ&
gHC]eI
c^5/).
)W[r;J7
;J+q XNI
8j2-VH
)MNpK(
Dkxih/
l4_>]3[
:L;1Lb
pFPf,f?
i$mT8j
GHk+Sv
><DAU%YK
\tI?WE
`EiBHh
mo/$vV%]
*!8`&m
.ic\h4~}
0AoCa$
JPR'~
vE(:B!
;Ky4Ex
>hxG8C
%2VnB)
UJm1 }j
KP.~VC
%F?)T'
6w"AJh:
JGj/Ku&p
W%AaO
EQo4*GQ
QSystem.Drawing, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a
System.Drawing.Bitmap
dIDAThC
}9!YDH)
)g\qy9
QSystem.Drawing, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a
System.Drawing.Bitmap
IDAT8O
QSystem.Drawing, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a
System.Drawing.Bitmap
%IDATXG
QSystem.Drawing, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a
System.Drawing.Bitmap
IDATx^
A01<)4
Qd~{hd
w%)?~>2
+*"#f3?
9W_%2GI
VeZ>MfN
zvMbvL
b`MkK
oDk D3b
%KHx>-
u%/8&=
.mKM|g
JjVx\G
D_sdRn
)YYnjk
R^h)HJ
Y#j=h_
;e1XvX?
V~ e4Vw
6a}aih
;RKwc2>
8ivhx3
~/2wmSo
>"u6O.
_G7;E"
41&d\O
O/cQTm
"@?;$2
[g;zISd
'Kl9LHx
- t`B4A
Hl<uxvY|
Hv2ep2
X);lF*1
#tI)~B
ScFYe
WFbTW6c
Y(fky[/
T2TSlDI
]IAT7R
Yef\Va
kVt?y{
9<~)aB
3e=JSO
UWTD_Pc
-bL2cF
w3!mCix
^ak$M9
PIQ,9LH;\4
'D<cf)aB
trW@7!
/=ki``0
#Bo!3B
PK!<C5
)&SV-u
A}WxO`_
:kdURD9
6V*JS
+IE?*PO/
<vxZ=ey
CdpX4P
~DG,H.
W)Aq$g
RCNH?j
TArOKU/;
Uud1qW
L}^)l*
-r[^8V
{VLqcd&
QSystem.Drawing, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a
System.Drawing.Bitmap
$(4,$&1'-=-157:::#+?D?8C49:7
7%%77777777777777777777777777777777777777777777777777
}2D@DD
0)9O]~
ul|:*e
QSystem.Drawing, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a
System.Drawing.Bitmap
$(4,$&1'-=-157:::#+?D?8C49:7
7%%77777777777777777777777777777777777777777777777777
%k+Y*Y
uRG3#
kpO>#d
iPYqK@Sn
U'OX\4nC
1;a?u\SK
f5V*j8
eTQ\<+
-.nL}%
>#wubv
<i-;dU
QSystem.Drawing, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a
System.Drawing.Bitmap
$(4,$&1'-=-157:::#+?D?8C49:7
7%%77777777777777777777777777777777777777777777777777
VYfmR.4
'$%1M6f
9~uC`
;r?)`E
me\]+OB9
$Pt9$V*
pbFny"
R}LPJM
$%H*66
81=Mr^
J']m-&
XlQZ%{
i9PG1~'
OvgvFb
E9.BYJ
]=P~y-
&e nVI$
)iZe9)e
7NCh@e
8rEUaR
'j%Rtu
q/KK-y
PsCH!2'
Qhr4yt3&
QSystem.Drawing, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a
System.Drawing.Bitmap
IDAThC
'p8z>
QSystem.Drawing, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a
System.Drawing.Bitmap
IDAThC
]_k;:6
*-LGSq
g)@KC?
QSystem.Drawing, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a
System.Drawing.Bitmap
IDAThC
.X3P'D6ck
U.D6a[
M6as:7\`$s
17) B6x3"
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
hSystem.Drawing.Bitmap, System.Drawing, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3aPADPAD
QSystem.Drawing, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a
System.Drawing.Bitmap
Ee'(89
1AQaq"
;+\t/*8
9zHQ(%,
>:c<Km)ni
Oh$)=J
m(m!!4
$)IUWM
AYUjCi
\}:j[.
*^OPZ{
$IZ[m@
[Y})ueN
>z4HQW@E
f5&Td"BT
5*Si#3
(xPERk
$!*%%Y
})Qq.4
Y) u$P
RWEjVJ
Z[yn6?
i=29W?
sMAPPP
l)USiV
Ox]aJC
uUt%-6
GbRN9hP
u?04{-f
ocfh!-
VMJ7In2
Ly4m4[a
goAwyj
bI(&@K
\lw"~]
Z;S~i:
*iZvw`
Ay*IoJPSR
\JG%v|e
m7(a)X
On='rEuw
7Rh;6}^
e=|)J-
.gmawa
A58Jq]
Zj>!6}V
8TQg=2[
:7I k\
&<vW'r
[qdkuHV
|w1On5
JRA%=
.{}azP
do/9<y
"JS%C*
e^dguj
i][ZNiP)
Z6o9r&
D'JJ|*FAU'
+H%E>%v
%E3P.I}jp
5ss[Wn?
[=b`)Z
,+qmHh ~&
qVcjU=
RZiG4s
1%+\w$[e
QAS@(%@
]fBoJQ
'MjzS/
9}\8`^
cLF!Bh
~+_yGf|
+$7JJq
2iZ2m@)
.LD8p!2
x#jr7$r
@JAQH<"
IHqk:N;
v@ZmVg
[ce;pR-7
BHVZORh)A^
)n9)Ni
1:)cqoxS5
~V"2-v
g\fK(=R
K-y~ZU
F(w&1m
n:fUfX
Vd-!CS
k%9P4Q
[%C?n6kN
YnduBzR49
"bMmk)
i-7yDy
{1[Lq%
eJ/H;V
HKh:sPQMs
\p&I$)NJs
|fd4)g
EI]I5*
]yjYUE
O:(PCl
>fKxK-
no^cG3
'/jM29`
,G`$)*
%6X4)"
<uKJ($
AA@8}'
Rf\?3y
CI<UlB
i!!'1J
p[-.!IkG
%%9%=k
qLm!OZ|
2~CJD}
l;R|*$
vkW'Z-/n
20I=@T
p`H}L:
?vrUs9b
GKx8{EB
+6ys[u0
=;zck|
n@n|"N
5gQ:RNTn
KiH>]J
$W";{(;
())9dU
-5.8v.F
^#L$$2
8o<[KwM
:fPi&:
`)cP49
ud5fMhi\
M)AR:v~
X5K6 R{
qdEXX!A
v*m%O)
w %A5t(
)d,))9
oR{hi{
!y 9sHz
qjPm)m
amCfRb
\TR34)
>kZdGL
3Ir;hs
-5BT%[
IVt) u
}e]xz&
MX"L_#
9":CKjQi
f[/77J
MhpEe<g
_=GO(?
6R)\{I/}
r#H)Nn$
q;)(e
y!l9U4j
+?Z<h?Y
;iI3Ck4
(n?@6y;b~
<A+oX7
Densd|
3[%)LH
^[*\Wa
EZRJ[#U*h0D
(XvZ!X
v$%)I,
x"b[65
tr+ir!mjR
fX"0Xw
K1eOi3
Dn[m+x
CHqt:i
pEd<7m
I6FU6B
O%)?a8
b*iZTc
r!92Cr
dxkZ*I4
6$G&Knh
Bu!HENy
kZGCCC@:w
H[&yH/3RWJ
Antivirus Signature
Bkav Clean
Lionic Trojan.Win32.Malicious.4!c
Elastic malicious (high confidence)
MicroWorld-eScan Trojan.GenericKD.37315588
CMC Clean
CAT-QuickHeal Clean
McAfee Artemis!B158C924678C
Cylance Unsafe
VIPRE Clean
Sangfor Trojan.Win32.Save.a
K7AntiVirus Clean
BitDefender Trojan.GenericKD.37315588
K7GW Clean
Cybereason malicious.78360c
Baidu Clean
Cyren W32/MSIL_Kryptik.DZG.gen!Eldorado
Symantec Trojan.Gen.2
ESET-NOD32 a variant of MSIL/Kryptik.ACEH
APEX Malicious
Paloalto generic.ml
ClamAV Clean
Kaspersky HEUR:Trojan.MSIL.Taskun.gen
Alibaba Trojan:MSIL/Kryptik.f682212d
NANO-Antivirus Clean
ViRobot Clean
Rising Clean
Ad-Aware Clean
Emsisoft Clean
Comodo Clean
F-Secure Clean
DrWeb Trojan.PackedNET.967
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition BehavesLike.Win32.Generic.tc
FireEye Generic.mg.b158c924678cd5ba
Sophos Mal/Generic-S
SentinelOne Static AI - Malicious PE
GData Win32.Trojan-Stealer.LokiBot.ARLQ8J
Jiangmin Clean
MaxSecure Trojan.Malware.300983.susgen
Avira Clean
MAX malware (ai score=98)
Antiy-AVL Clean
Kingsoft Win32.Hack.Undef.(kcloud)
Gridinsoft Clean
Arcabit Clean
SUPERAntiSpyware Clean
ZoneAlarm Clean
Microsoft Trojan:Win32/AgentTesla!ml
Cynet Malicious (score: 100)
AhnLab-V3 Clean
Acronis Clean
BitDefenderTheta Clean
ALYac Clean
TACHYON Clean
VBA32 Clean
Malwarebytes Clean
Panda Clean
Zoner Clean
TrendMicro-HouseCall TROJ_GEN.R002H0CGT21
Tencent Clean
Yandex Clean
Ikarus Trojan.MSIL.Crypt
eGambit Unsafe.AI_Score_99%
Fortinet MSIL/Agent.GIQ!tr
Webroot W32.Trojan.Gen
AVG Win32:PWSX-gen [Trj]
Avast Win32:PWSX-gen [Trj]
CrowdStrike win/malicious_confidence_100% (W)
Qihoo-360 Clean
No IRMA results available.