Static | ZeroBOX

PE Compile Time

2021-08-02 09:35:02

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x000e3b44 0x000e3c00 7.47161161108
.rsrc 0x000e6000 0x000005c0 0x00000600 4.12085898848
.reloc 0x000e8000 0x0000000c 0x00000200 0.101910425663

Resources

Name Offset Size Language Sub-language File type
RT_VERSION 0x000e60a0 0x00000330 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_MANIFEST 0x000e63d0 0x000001ea LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with CRLF line terminators

Imports

Library mscoree.dll:
0x402000 _CorExeMain

!This program cannot be run in DOS mode.
`.rsrc
@.reloc
AeZ h@
Z g@@za8b
ntdlT
X_6%&8
XgTe%+
MZ 8C'
NtCoT
X ntinT
z"za8g
, ,j|`Z
NtCoT
X ntinT
X l.dlT
, D@C|Z pT
$,6%+
`\9%&88
Ja3d8
h~Z `#
ntdlT
X l.dlT
, t*yTZ
'XGR u
4qZ &Lx
:9}%&8Z
hq^%&
, jL+%Z
)U6Z C
3Z 8g=`a8
]8!|Z "
YZ Dv
k?R xZ
t Qok@a%
UZ >o(Ha+
-Z ]K*
Z xnF9a8
+)r>Z M
}%(pZ 8
|"wiZ
$Z UJSoa8
-vp/Z
Z ^hXEa8
rrCZ ??
(t\a8s
ym"a8_
swC)Z :
2+Z up
61t*Z
pWZ/
z-sP
*xNZ $
0&ezZ ?z
w-sP
\sP
*8na81
URlCZ a
m4ta8Y
u^sO
,Z @U0
DsP
p'Z Jf
,Z w=)\a8u
0 S*%+
!SZ Xx
<OCa8U
t^1q8
/^sO
DsP
jx?a8;
DsP
y^sO
DsP
Z |>_Ia8
W:_1Z {`
/1sO
OZ pG[Ua87
y1sO
q*sP
D>Z !*}Ta8
Z ]DAfa8
q*sP
@H3Z ^
q*sP
uZ 7G\
!,Z KE
U^sO
z-sP
DsP
G=SZ f
FQ4a8i
\fZ 32U
z-sP
VifZ XQ
BfFyZ
_fgx
IZ #d\ia8@
JosO
Z GC(ga8
Ro&aZ
Y(Z b$
63}#Z 1
d&sP
VsP
VsP
VsP
RZ 9X!Ia8
d&sP
]ZtbZ
'Z b mja8x
VsP
KeZ nCR
Z *;y:a8;
VsP
VsP
%2wLZ q
I`Z |j
J1sO
\g;Z !?
2Z 1NR
7oxlZ
d&sP
Z RuS
VsP
sYZ [k
zZ sQ9.a8
JWa\Z }
S!p7
OvZ ~
Z !+\ra8
SR<2Z
m$Z m>S
DsP
q+sP
rZ e5u
q+sP
hZ T36ga8h
Z 9)|'a8?
6iLa8|
4^sO
DsP
4,sO
~)sO
~WsO
DsP
q+sP
g%z-Z
DsP
<7Z G lna8
dZ Sk#Ca8V
aZ &h*
PZ F(GXa8
VsP
aD+a8G
kmZ ilU
l'sP
obMsZ
/q&XZ Jm
VsP
Z R; a8n
p#Z q
<XPZ Oi
VsP
l'sP
cA+HZ
?"sO
ij<a8-
Z m~~`a8#
oRsO
u'f%%+
QZ :`Qva8
VsP
GkbZ +/
VsP
4bZ 60b
Z ]".Va8
PZ ;{}ga8?
?"sO
:Z f16
@$_fZ
l'sP
0*Z D`
l'sP
w/]a8v
[g[=Z R-l$a8W
]^aZ |
oRsO
;|Ea8Q
Z )y81a8*
6xZ [
-Eb9 |?XJa%
ykgZ ?
VZ GLO
$Za8s
(;Z ,aJ
gSZa80
,: 9XXG
Z (@1^a+
ZgZa8H
Z B\~@a8d
Z 4d4ha8
"Z q,(
Z `}5Ta8u
a_Z >D
+25DZ
iZ Ay@
_oZ z%
Z 0)L]a8{
zX,a8J
Sb8Z
qKZ [/R
(+8Z
}{Z "N
Z bDUna8Q
Z 0g#ma8
iZ A$a
%V3Z E
s<:fZ 9&
79ajZ
]p~Z wO
P|3sZ
\Z l'%
U-\Z r
Z l9?Ra8
_iJ_Z
!yDa8i
tn'Z V(
.8VTZ @t
s8Z pP
z=$a8"
0Z x=d%a+
lSystem.Resources.ResourceReader, mscorlib, Version=2.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
fSystem.Drawing.Icon, System.Drawing, Version=2.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3aBj
QSystem.Drawing, Version=2.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a
System.Drawing.Icon
IconData
IconSize
System.Drawing.Size
System.Drawing.Size
height
dIDATx
O Ok?/
18,m^?
W_W{oM
1NfwIk
lSystem.Resources.ResourceReader, mscorlib, Version=2.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
PADPADP
lSystem.Resources.ResourceReader, mscorlib, Version=2.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
PADPADP
lSystem.Resources.ResourceReader, mscorlib, Version=2.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
PADPADP
lSystem.Resources.ResourceReader, mscorlib, Version=2.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
PADPADP
lSystem.Resources.ResourceReader, mscorlib, Version=2.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
PADPADP
lSystem.Resources.ResourceReader, mscorlib, Version=2.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
PADPADP
lSystem.Resources.ResourceReader, mscorlib, Version=2.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
PADPADP
lSystem.Resources.ResourceReader, mscorlib, Version=2.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
hSystem.Drawing.Bitmap, System.Drawing, Version=2.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3aPADPAD
QSystem.Drawing, Version=2.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a
System.Drawing.Bitmap
IDATx^
x_?v<;
4FzJ#:
WFwj0~
B.%(3]
YbbLz5
HW.fjh
J^"#v#
.KDdpjV
=pLxEw
uzz?!$Y
KI9tJK0"
<b4qf"
qn9JR>\
a4Qc>s
Aa0s\V
5Il+zF
=;VIp:
hI`RU#N
E8c6$q
%NsSYo
Xi>K~a
(}9ABc
wS}q"_'x
N<z](N
HCsJ-oo
+ue|O
6!Kx!%
;,KYOp
pna(6Q
o3<lF<q
yk~N7Gap6
8Z,CZ6
_Nddt?
&(|{%\
Js<Xvi'
rf[v*CB{
xwSpFJ
lc>V6K
H77!r`
[vlVne
2I&pi9
e"q!*t
|N(WS*
"6,pFk
WZ8/RK
L@^`Lb
y\#qRA
fwx%5Y
4Vn\Che
j%?o?$y
Z{chUM
(J~@=2
{pQ+AL0lk
54KVa]z
?M~H&7e7
`@L 9s
(M&E]`
QHI%TRH
TH)-EC
hQQVS$!
bUB+s%
\cmb<C
[3VJ$lP7fe
F0pT&+G
7\1Lwa
:6jeb2.
B~hHQ*
c['Kl,9
41ckX}
R>d-ee
cJT3+t
1P`r)Rv
/JDW[s
{LBz '^
`$sF`7h
xke2w]2
1=_0vk
K/jRN
._io~E
/0~eE_
gcz2o4
mwGYu+
r!yG"
Y5k-C'
Aqh(fv
R$%r1T
R6~-Gt
qp;Bt
fwqvp";5
8Z%3Ki*
.QDoQby
qVHKPm2
JF~?@p
qeU+)Q
2fTL}H
8k#.3/
g:%f+XU
3$5KcZ8
2cXj7}t/
a7wZoP
VYAA]S
&t0 |!
?<uq&C
=y_`Aig'
SW%svU(.
336iqc
lwF!-(
]4VD#]1
gGu`P.
N=*C\U
y41{6"
<k=9s5
vrl7+A7v>
Tfo.dee
'k21v1
J|s-/s
y:gdKiw
e~3Pt]
yv;rn*
.7 -bA
*JtS0JI
V\'Qr"
PymCzr,5
UNq"1X0[
by"$Z1T
U'UQj*#)8
w~? @x
eym .W
FZHsX%
3FKjr|
L#7.$q
ax<3F?7
.o&ol5
A'x 6Y&,
D"5Ry}h"
k@'o5Se
\ig{f>
w[Jo<`U
#ke"s$
l2w29b
)p9t7b
z2[F{"Y-
m@SG;?N/
2ZM?RX
(AY[,@)h5N
W\zZX
cN,P1b
OBpkv'
$Qnf1
he|rs1
n3ih1Cu
VwMC8m3W
k92w+0x
p<[;fQ
)ktBVe%r
4Wphs"
R'~J`.
FE/"~P:C
u8:qK
v<qdz?gt
.]m(>u
Jt-S|t
+wj'&S 4
zY0w\<[$
Qj'&J`T;
D>sPo/G
7Gs23
IJc:y;
'(w9$
j-~R-+
C^a6BP$
P<t2q|m
sqJ+Od
8c-Kn]
9}4{*t)S
L-uD4g
s&J0S
G1Pd-{
k$V&VX
3jV!~#
A!vfub7
3^0Dq!
3r"|E.c
9\/8x/
}}'{gl
C-w86d?
SR]q_"x
GD6{>=
Mn7)b*r
4WdCR=Q
w:YK](~hK
K#Q68E2M
Goh|iHL
x2q."{<
h~.`Tf
rm@&g
IuiF)g-/
sYq7MQ
/Sry3_
3*C/`pw
b'ZDdq
Q U:p[o
v)6GGs
Iax!^I
e1?0.<
1%5t(w
HxmesY?,o
At[|'p
>dbS;2
n$,O`2l
-X&%q#
y_X~l?
G+VhhpU
T'["gt
TNfJ.M?
tcqm8!
0?~?JO
s\0P\K^
i?88i |
Z|_YMmH%w
:[0#G.
e2viP1}
g;Fs-A
^CDp~6
Ei<?M0
u6MF?
9VeBj\
G!yt?~K
E)Z;^c
]bNw"u
k:uw^r
M,Vc7\
HkK63n
uE"b>v
=+[:im
lNpbK3
Enz,m'
d+Sb*)
xrf,1]
pcLokr
GoL2)i
r`\g2{?
)cNl`Kg6
*m&}i7
T*M#{u9
o qo>7
V()2:@
k(c.o"C
zfp"t6
UMtP+'
x=$]pv
Jyn5nb
*b\rYq
$9]`oH(
3i*/438
;'!RefpH>
gpJb'!>
=e3h=Z
k##"~b
?"Ku;o
E|/iD%<
%)(D-G
chjFuJ
?^{.1_
g#}w?1wo
m9D\o57
"qzVAW
OfW-f#
c<>O#G
GA(+N $e8
=ftjqtQ
d;jFP
.>"Fg>n"G
R>4.eg
CYf F&%8>2'
wi!^ZH
yTJ?E9
i@*;JTqw
q)+XwQ
<u=gQ{Z
uG$:Q!
b,oHR,
lv&s~{
Ekh t
V#I)]F
bLRu#a
"q.OZN"
&!?g%a
v?F3))
;Jw"b
O$rR79
!fJ;PjP
"\4Q_;
Y4h)C#Rh
OvAi{"
_%qt0
ar!34?s
uOSP~x
u?6`?S
8^OO!Mv+
ASQhka
|!Nv#9
_)//&0
a{1^5Ds4P
bYtg53C
S:Mh{+
{Xd.!x
<EDl6K
/J07)A.s
]PFB;_
/`yc:%
,#XtK`/+e0
9w`jdF
-'lQPS
+>sv2~
f#:>_p
;|!-c=
95+Ehx2
A|=dJSh
7fpr]21
$O]DM.
=.1gT+
vM`^X-
@Zy/HGP
B_a6b{
_&'b"4
/(.Iex
2)t9ys
f]F[K4^
ln-|By
^_R82Q_P$
r3"^63
i;"+u9}
H7}C(s?k
V3kB%s
RIDU|!
>a}c/;
*|!h@-
zf:iq]
"d@0c+
)T$C2T
3T,;yrc
w?X1~4M=
ssk=gM
x0U=_I
t|Jxhs
cxSTO}
5v7jYc+C
py6P`9
KO^,,
!rp.bK
U"v~+VC
r$d:%7
=EHl:
>2BD4%
a_buZi
2D?XpF~p
yd-*Fu
*IoOc(
'?cNF#
II>37*qg
-}X^aK
$%STlGsp
)(sL`7
Hb_}5S
._+nr/`
/3pJ=>
{p(PuA
>VeDx<
Sa)U+2P
5cg,!7l>k
l%Uo!T
@2i&#_
j{_ni_
:7bpb7jK,Q0
S7U"4K
JUa;_e2
c4e+W,
"GS&pF
Dhqv@8z
$jB1k:
tp93F}
#CS'b6g
NRj'07&
k"ex82
Ia]r'{"Ep
[4$od]|=
x+|uP"
B538j3
`,4O0Y
cywo8)6-(
#6nr'~W7
7fZ(%.
CMX,gB
L8I@@>
0LM%74
o9gz<x
uKELo$
SfXESrl#++~3|
/q6ON`
C{@#b=
_+1Zk+
7t5M1-
=.q_Hk
$je2*g'C]
)O6rSN
0V5_" a
*% >?
q&@w7^
7VVaDZWq
).0>=*WZ
x|:KZs
`!L^J*G"^
fwM9jKN
3wmQLNB.B
&{Vs?V
$G|*8!nLm
ljjZh?
8%7UI/P
kon@2x-S6
1y86/{i<
oi%Vlqd
0fv^Dt
uP4u3w<
|f\Je
J~N&B?
at|+!%
"nN^L]
_spoVgL
/-CcQ&
gB?rc_5
w,:sj(v
kv^8LwK.
W7,i|A
cGA!kDw
q:`=qS
t7s6Ib
,1anK=
fSzn"e
'{uB8(
X6*Wfr
T;W0&!
E{(zI"
,'\_lc
w#L_}b
["oEP
!DK\ct
IUcWu&
bv_xIG`++
H'y;uP
f8aa+8Z
OKJ5{=
@(c'}wv1S
m:g;R6
chz>}^
F,b^i#
R^/VC&
nyxP}k6
-+l6A
eyy Np
6gK3lF4
(lZGkm 69
fH^:-B
pbZ>wU
Hi+Zct
u]Fkt
e00|5Q
aWhlHd`\
! `(ii
l7A~b8
HC'[NL%:W
k)/8:H
{DoOa
9uv$60
s/kv~BE
.,s3I$
JiPDs)"
8NHi#~N
Ia>2[O
QtVocq
uFIxd.&
;OUY?:
@gD0aVWQ\
|M~IW}8?
eHh,gw
wljobk
A8*'3\k
%Wl=V=
d:_T&2.
sY<d&-Q
Z%6)"<^
h1xd<*
G<W|^r
fhOD]A
g-F]m)
Xza,+_fb
Ub?UKTY:
kov^NfI
3_8T"C
S?3Mb'jge
6#>ij
V`Rys[iT
NlS,__}Dc
U.PhHm
Lx]LXj
KvcQTNN
&Y2]r);gl`
HvM("up
iN'\n#k-_
bc.ZyMT'
P'Ai2Q
qGpH(E
>Is.qn
ewpSH`
FZ,/3E@r
;'I)/e
`FVe2F$
Zj_a-g
0pJ@Cw
Xsz'bkQ
) Bw&_j
j1vOI'J
Qfl^dL
.S&\FDn2
DmVCL&
o9>b#'
gFGcnS
KOsxf#
{m-B%m
1%kU?R%L
FNptF0
P~yo <m0w
Is:YUy
o_F^u@A
,6$1l%)}
Fdw/?zf2
&j#&#-
4Sc$km
jJov",z
tf;j#|A
5w"kjbY
-hltes
-O]p0z
?^3wT)
.9;& 3
A=/I,j'
705yGq
d:J+_ruD
]wMtFO
,=KmV.
/DJ9:Y
aNH??\
8zv/$D2
Q[`4NZt-Z
qagY}0
P1r#9m
p*[~iQ/|
Hrs]=.G
LCtC*/
6gyLJf
N(s)w(/O
t5FfW0
(MoLCw
h9bqc#
d~F"{%/2$=
U3Fk-d
j_L%{H'
Cx`2/']
x,m+3h
:m%0[z
2vxP<Z
y72~\0
2"Fd2p
m#\x:W.
b'$^v"ny
U|OnGD
BK92o
2x!;C%1
LSTDhK
7|pk%{f
K~}1#]
Y7 tz9
[QX.Gz}5
4dnV4S
mK9{B>
C(~:]'
D^f$UMC
aQAyO*
n4{6r<,
JRGGPj
->%8gs
dTS-qt
24o0-C@3
S9Y.&tp
KI}{J|]
{v)^Sl
}&j`y6
o91s0/
!uw%rm
%gD92<_
T(-/' }
.J]K+n
&Q*Cfs
l!,`14o#
!{&Rnw
{Tuop0v%3n
Hk|<ow6
D^c^n!
LWbxJ<
GQf4;8
JIrT/;
%IzH^R%
79^&Nbp3
6Sg.7+
cag6n>
2S}>Vf
jeWbw`,U#
_.g@Y7
_F/cYALj
G.7!=2
Exsd3{=ey
~-W>GSX
5C=Y4Y
vNBn{&
Z\P*FhX'ZU
MS(L>B
MS8$VO
r"~#_>
o/N#N2
7 ur3x
%}c:wl
;Wpqs
5g1"}!
a9l?Y^
d6FG[(
6^76po
k81q-/
(0Y#wjvV1
|Vf- [3
b\Flesp
.v^I!"
8_@}?x2
l|Mih9
$~aVp
g^{H#=
}!{&m=
/KDRpuS
",O~'<g.?-
Tx6An%
p6(M&B2
x|k7=s
u=DY^f[V)
sV.h{^
O>&3{#
QOV"1G
}4Eoa=
QVrl}4
NpwK2CT
rz`"Z}
nBWxcs
h4PdDv
.x=_W&1z
&C&IwsgO
6oR;Y]
sfZ+3
ehC)-^#(
!X<n"Q
<{le/
D1M".}
{h.3$Hd
f!bbHaD$n
x]c#?qo
FQ~1kC=
iE`||<
sfQ/Y}
tZ-JNpA=
m#b_3g
IDATkz
*lgH!}
\t6N",T
+Xtb<-
62d[A<K
j~o-@2
(xz0dE_
,F43GT
eaC_AA
E.}JGK^
yLf.d|
h8~W_q:
?|/L^
TI;~&'
m"5g9u#g
~AY$v|C
('%qL`{
?A`Awk8rf?
~u)5&*xn8@
8:Y"]4
:Kwh,}
dh<^Q7X
%INS_J
M%GnLS`
<||wq&5
\wxAYY3
zAbd8W
(B#z8c
:[6\Icy
tl"gFo!
ixEob0
}0/scK
Rhno%Lh
Sut<iK
Wfr(j#
%|/+c2M
:OYDVfp;N
a!aog!y
CWn&]|
J&hN+S
Y4m2}>
mIPl!'
?E9 iC
XP<y M
tx8Eq
P+zOciz>F
ut)EVs
p+2QJ`g
2B4:Xaw
Vuz'oolba
fFzJ?Z
2]z=-yN
;G\EMz
~LEmS7
'2gMFJC
^cgb0g
?HA-|0
33J2.rB
owCzQ7
^=GlH+3
/A/CH(
RNL?N_
_\KxJ.S>H
h6vW3*
g{\'<r
j9LF*
%8yl/3
u|2o}e
jt-MAe
1I,Uj'
t"|NQc
Z[fn3e
IcjS5c
oP1g>_'F
5<Kufj
Y3]i\8
KFDQq>
h|K?sBF
zQ\gD[
=KnZ5MC
i5jIci
qv$lvd
<gDI0U~1
{%?7Kc2
pPe@?+
"<G iX
6^nhF23
k;Upwj`
|[QSYLw
a(=<%x
a7t)mo/`
o\HiZ>2
3!+4Pt
e(y(S#;
"*7S(?
#Ty5z
`ts'pN
7N5!u!
om-ZNFL
CZF /T
.~i;P,
IDAT,}?
l$IA'9=e".gBq
96/n#h
ldi9nZ
HO*jsJP|
rr'$1h
K_Uq>&
5+H9+Ix
BkE)e.
X|Vfp(
4qeOHO
+nc?l6
DCi_$#
NApK?y
h/vK+R
AHa*C/
|@\s+N
M`]R/
_#/v83
:zfF4d>A
6Fx<Bk
IM\s|B
|)u`]P
AoA'Vz
tk0~{Zx2L
2x<l's
!MVz7RTv
w^S`D
R\jXCMx<
{(4}!vE
gvK2}|9
]BWr1
v$VS^b
wd<uRs
sTv& kR
}tG?gI
l&~DEt N"
t7(1wQ
x=.dzP
dz+c:s
EO1gS2w6
CkVpzu?
o.N+_p
9~]?8y<
y:V2J|T
z&4] |
x"GC_Q^
v$1se+=i
liZ6Vk
A[~$<C=4
bqWj/O&
z#6HLf
v*VO!
<O]v9J5
D'F`^t
pH~6O|
k)C$K1
d&wf7#N^d
an~#2'
{J#P}v
bv;LA$3
@R|F#y
F*y4!Q
F}vrsD$?z
y!2&~D1
8MYR^&s
=oaar..
&qw6*V2P.
AGi67$
nbY]3k,
mb()Wsq
&1[f9:[
wINMe}
Ni"z-#
YC9x|=
I.0o'c
Dj2&3^Q
3l{rx
e+1-I
ytLCp>
{;e(W~
[qbx0N
-%5s0j
nH'Ri/%bK
/Y=t33
v#Nd~@
PyQ S>.
cP}'FA
`*Ft{4
c9i&8=
cLGT)>
4b&:O}
V3e[ 9
PQJe7D
GSrt<+f
+>K_"{
OEy;m$
n%?eHN(G
Z7<+n1
rx:n>Y
4NP$CP
s)jN"$
5UV_H]
OcCG5*a
n'kv&5
eo_.[g!
p"6_:18_
0fB#f3^
xDUaTP
2B*m4?^
GQ`5e{G
@vxgqC
F4_Ksr})
vGppH=omuq
D4F~&/W
,B$gau
VU{(+6b
NlY1#v
<&-iGe
'Y2*f/
S9xj2E
qLL0`COs\
m8h]Ed
j#0O7g
z4GT#a>
%&NO`h^
^.HH!v
ced2Jn
Hmj{62w
zx*J76pe@_
B16]Oe
oBqY"G
?Yt`6OS
t%>O*y=
DanH;0
LfBn _
y>#hu-f
s_g4O
wMddK
G2:n?9
rzs-EN
kTH1-D
hRh!^|
&bzQr
|CaO3Q
<\(LjX
_[{xi
@MD2);
~v<ks^P
@i|/C|{
_Gb5b3
|"'Qw*
sn<:Bc
&qV|On
uriV)Nr
8LW .H
/w}A\+
H}oD|}=>:7
0tLEIS
:gf8ci
q32#5E
ZBo9(k
%po|4]-C
IwAho
#Q:`Ov
.jCQu
D'2rd?
rn'B&'
|}Aa~a
3G'pxO
L^pvsI=V
>2nT5V
Jw5c<-
r|t!b:*l
}.DnUeS
3Ru9N.]
M~H^_/
g8n5DdG
Nsx7}Q
BUflWd
w=.aRo
Y}'&!;
i[`@k~
bxrh6W
lSystem.Resources.ResourceReader, mscorlib, Version=2.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
PADPADP
lSystem.Resources.ResourceReader, mscorlib, Version=2.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
PADPADP
v2.0.50727
#Strings
#Strings
#Schema
5eKGLab.exe
mscorlib
SuppressIldasmAttribute
System.Runtime.CompilerServices
<Module>
.cctor
System
Process
System.Diagnostics
CloseHandle
kernel32.dll
IsDebuggerPresent
OutputDebugString
VirtualProtect
Thread
System.Threading
ParameterizedThreadStart
RuntimeTypeHandle
Module
System.Reflection
ValueType
NtQueryInformationProcess
ntdll.dll
Win32Exception
System.ComponentModel
AndOTA
stuSys
System.Windows.Forms
convertWorker
BackgroundWorker
transferList
ConvertWorker_ProgressChanged
ProgressChangedEventArgs
sender
ConvertWorker_RunWorkerCompleted
RunWorkerCompletedEventArgs
ConvertWorker_DoWork
DoWorkEventArgs
buttonConvert_Click
EventArgs
buttonBrowseTransferList_Click
buttonBrowseDataFile_Click
checkReadiness
setReadiness
buttonSaveOutputFile_Click
loadTransferList
updateStatus
status
ProgressChangedEventHandler
DoWorkEventHandler
RunWorkerCompletedEventHandler
OpenFileDialog
DialogResult
CommonDialog
FileDialog
SaveFileDialog
Object
get_OffsetMarshaler
get_ReturnMessage
OffsetMarshaler
ReturnMessage
MainFrm
components
IContainer
pictureBox1
PictureBox
menuStrip1
MenuStrip
ToolStripMenuItem
ToolStripMenuItem
ToolStripMenuItem
ToolStripMenuItem
ToolStripMenuItem1
ToolStripMenuItem
statusStrip1
StatusStrip
toolStripStatusLabel1
ToolStripStatusLabel
ToolStripMenuItem
ToolStripMenuItem
ToolStripMenuItem
ToolStripMenuItem
pictureBox1_Click
MainFrm_Load
ToolStripMenuItem_Click
ToolStripMenuItem_Click
ToolStripMenuItem_Click
ToolStripMenuItem_Click
ToolStripMenuItem_Click
ToolStripMenuItem1_Click
ToolStripMenuItem_Click
Dispose
disposing
InitializeComponent
ToolStripItem
Control
IDisposable
ISupportInitialize
ToolStripItemCollection
ToolStrip
System.Drawing
ToolStripDropDownItem
EventHandler
ImageLayout
DockStyle
PictureBoxSizeMode
ContainerControl
AutoScaleMode
ControlCollection
MyTool
connStr
myDataGridView
DataGridView
currentUserName
student_id
student_name
class_id
class_name
Reverse
getStudentIdByStudentName
studentName
getCourseIdByCourseName
courseName
getClassIdByCourseName
className
getStuListByClassId
ComboBox
classId
comboBox
queryDataToComno
sqlStr
columnName
comboBox1
queryDataToGrid
gridView1
executeCommand
sqlstr
System.Data
SqlConnection
System.Data.SqlClient
DbConnection
System.Data.Common
SqlCommand
DbCommand
SqlDataAdapter
DataSet
DbDataAdapter
ObjectCollection
DataTableCollection
DataTable
DataRowCollection
DataRow
InternalDataCollectionBase
ListControl
DataAdapter
sqlConnection1
sqlCommand1
sqlDataAdapter1
dataset
groupBox1
GroupBox
textBox2
TextBox
textBox1
label2
label1
button1
Button
button2
button1_Click
groupBox1_Enter
button2_Click
X_21398138721
X_1248931414
X_02312312
X_123123454363
X_85432343242
Assembly
X_12394147894
MessageBoxButtons
Padding
ButtonBase
FontStyle
GraphicsUnit
AppDomain
MethodInfo
MethodBase
NewChooseCourse
groupBox2
button3
CourseList
StudentList
ClassList
label3
dataGridView1
NewChooseCourse_Load
ClassList_SelectedIndexChanged
StudentList_SelectedIndexChanged
button3_Click
DataGridViewRow
DataGridViewCellCollection
DataGridViewCell
DataGridViewAutoSizeColumnsMode
DataGridViewColumnHeadersHeightSizeMode
NewCourse
NewStu
Stu_specialty
Stu_idnum
Stu_home
Stu_sex
label12
label11
label10
label9
label8
label7
Stu_position
Stu_politic
Stu_nation
Stu_age
Stu_name
label6
label5
label4
dateTimePicker2
DateTimePicker
dateTimePicker1
classList
NewStu_Load
classList_SelectedIndexChanged
NewStu_Load_1
DateTime
NewStuScore
NewStuScore_Load
TextBoxBase
Program
QueryCourse
groupBox3
button4
QueryCourse_Load
button4_Click
dataGridView1_CellContentClick
DataGridViewCellEventArgs
DataGridViewSelectedRowCollection
BaseCollection
DataGridViewCellEventHandler
QueryStu
datagridview1
QueryStu_Load
IEnumerable`1
System.Collections.Generic
IEnumerable
System.Collections
WithStep
startRange
endRange
Action`1
GetEnumerator
IEnumerator`1
System.Collections.IEnumerable.GetEnumerator
IEnumerator
<GetEnumerator>d__8
<>1__state
<>2__current
<>4__this
<max>5__1
<min>5__2
<current>5__3
System.IDisposable.Dispose
MoveNext
System.Collections.Generic.IEnumerator<System.Int32>.get_Current
get_Current
System.Collections.IEnumerator.Reset
System.Collections.IEnumerator.get_Current
NotSupportedException
System.Collections.Generic.IEnumerator<System.Int32>.Current
System.Collections.IEnumerator.Current
Toolbox
GetRangeset
List`1
source
TransferList
<Version>k__BackingField
<BlocksToWrite>k__BackingField
<FileContext>k__BackingField
FileInfo
System.IO
<Commands>k__BackingField
get_Version
set_Version
get_BlocksToWrite
set_BlocksToWrite
get_FileContext
set_FileContext
get_Commands
set_Commands
FromFile
FileStream
StreamReader
Stream
TextReader
Version
BlocksToWrite
FileContext
Commands
Tuple`2
Resources
stuSys.Properties
resourceMan
ResourceManager
System.Resources
resourceCulture
CultureInfo
System.Globalization
get_ResourceManager
get_Culture
set_Culture
get_cDvUnNB
Bitmap
Culture
cDvUnNB
Settings
ApplicationSettingsBase
System.Configuration
defaultInstance
get_Default
SettingsBase
Default
Method
stuSys.Functions
METHOD_TCP
METHOD_UDP
MinuFlood
Socket
System.Net.Sockets
connect
packet
method
IPAddress
System.Net
IPEndPoint
AddressFamily
SocketType
ProtocolType
EndPoint
SocketFlags
MainForm
stuSys.Forms
position
methods
attackButton
portBox
threadBox
packetBox
methodBox
githubPage
LinkLabel
groupBox4
logBox
stateLogBox
tabControl1
TabControl
tabPage1
TabPage
tabPage2
threadLogBox
stopButton
linkLabel1
closeButton
minimizeButton
attackButton_Click
stopButton_Click
githubPage_LinkClicked
LinkLabelLinkClickedEventArgs
linkLabel1_LinkClicked
minimizeButton_Click
closeButton_Click
<.ctor>b__4_0
MouseEventArgs
<.ctor>b__4_1
<.ctor>b__4_2
<attackButton_Click>b__5_0
<attackButton_Click>b__5_1
MouseEventHandler
ThreadStart
FormWindowState
BorderStyle
Cursor
FlatButtonAppearance
FlatStyle
ContentAlignment
LinkLabelLinkClickedEventHandler
FormBorderStyle
FormStartPosition
MouseButtons
Encoding
System.Text
5eKGLab
CompilationRelaxationsAttribute
RuntimeCompatibilityAttribute
DebuggableAttribute
DebuggingModes
AssemblyTitleAttribute
AssemblyDescriptionAttribute
AssemblyConfigurationAttribute
AssemblyCompanyAttribute
AssemblyProductAttribute
AssemblyCopyrightAttribute
AssemblyTrademarkAttribute
ComVisibleAttribute
System.Runtime.InteropServices
GuidAttribute
AssemblyFileVersionAttribute
STAThreadAttribute
CompilerGeneratedAttribute
DebuggerHiddenAttribute
DebuggerBrowsableAttribute
DebuggerBrowsableState
GeneratedCodeAttribute
System.CodeDom.Compiler
DebuggerNonUserCodeAttribute
EditorBrowsableAttribute
EditorBrowsableState
stuSys.AndOTA.resources
stuSys.Forms.MainForm.resources
stuSys.Login.resources
stuSys.MainFrm.resources
stuSys.NewChooseCourse.resources
stuSys.NewCourse.resources
stuSys.NewStu.resources
stuSys.NewStuScore.resources
stuSys.Properties.Resources.resources
stuSys.QueryCourse.resources
stuSys.QueryStu.resources
IntPtr
get_Size
op_Equality
UInt32
op_Explicit
String
Concat
Environment
GetEnvironmentVariable
FailFast
get_ProcessName
ToLower
Contains
set_IsBackground
get_CurrentThread
Debugger
get_IsAttached
IsLogging
GetCurrentProcess
get_Handle
get_IsAlive
GetTypeFromHandle
get_Module
Marshal
GetHINSTANCE
get_FullyQualifiedName
get_Chars
ToInt32
ArgumentException
GetProcessById
SizeOf
set_WorkerReportsProgress
add_ProgressChanged
add_DoWork
add_RunWorkerCompleted
ShowDialog
get_FileName
set_Filter
set_DefaultExt
set_Text
SuspendLayout
BeginInit
get_Items
AddRange
set_Location
set_Name
set_Size
set_TabIndex
get_DropDownItems
add_Click
set_BackgroundImageLayout
set_Dock
set_SizeMode
set_TabStop
set_AutoScaleDimensions
set_AutoScaleMode
set_ClientSize
get_Controls
set_MainMenuStrip
add_Load
ResumeLayout
PerformLayout
EndInit
ToString
ToCharArray
ExecuteScalar
get_Tables
get_Item
get_Rows
get_Count
set_SelectedIndex
set_DataSource
ExecuteNonQuery
Replace
get_Text
MessageBox
set_Margin
set_Padding
add_Enter
set_UseSystemPasswordChar
set_AutoSize
set_UseVisualStyleBackColor
set_Font
Convert
get_Length
FromBase64CharArray
GetDomain
GetType
GetMethod
Invoke
get_CurrentRow
get_Cells
get_Value
set_FormattingEnabled
add_SelectedIndexChanged
set_AutoSizeColumnsMode
SystemColors
get_ButtonHighlight
set_BackgroundColor
set_ColumnHeadersHeightSizeMode
get_RowTemplate
set_Height
get_Date
get_SelectedItem
set_ReadOnly
Application
EnableVisualStyles
SetCompatibleTextRenderingDefault
set_Visible
get_SelectedRows
set_AllowUserToAddRows
set_AllowUserToDeleteRows
get_ButtonFace
get_HighlightText
set_GridColor
add_CellContentClick
op_Inequality
WriteLine
Exists
OpenRead
ReadLine
get_Assembly
GetObject
Synchronized
SendTo
Connect
FromArgb
get_DimGray
get_White
get_Black
add_MouseDown
add_MouseMove
add_MouseUp
get_NewLine
set_Enabled
set_WindowState
set_BorderStyle
Cursors
get_Help
set_Cursor
set_BackColor
get_FlatAppearance
set_BorderSize
set_FlatStyle
set_ForeColor
set_Multiline
set_ActiveLinkColor
set_LinkColor
set_TextAlign
add_LinkClicked
set_ItemSize
set_FormBorderStyle
set_StartPosition
get_Button
get_Location
get_UTF8
GetBytes
S_MR{vF
Oo`U_eQ
Oo`U_eQT
Oo`U_eQ
O(uf[u
Oo`U_eQT
eQ(u7b
vpencL
WrapNonExceptionThrows
stuSys
Microsoft
Copyright
Microsoft 2015
$387011b6-c1f3-4c2b-b34b-f2296b826e53
1.0.0.0
3System.Resources.Tools.StronglyTypedResourceBuilder
16.0.0.0
KMicrosoft.VisualStudio.Editors.SettingsDesigner.SettingsSingleFileGenerator
16.7.0.0
_CorExeMain
mscoree.dll
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<assemblyIdentity version="1.0.0.0" name="MyApplication.app"/>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v2">
<security>
<requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3">
<requestedExecutionLevel level="asInvoker" uiAccess="false"/>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
$this.Icon
cDvUnNB
_ENABLE_PROFILING
_PROFILER
Image file (*.img)|*.img
Parsing transfer list...
cDvUnNB
hblVjq
ToolStripMenuItem
MainFrm
ToolStripMenuItem1
pictureBox1
menuStrip1
ToolStripMenuItem
ToolStripMenuItem
toolStripStatusLabel1
ToolStripMenuItem
statusStrip1
ToolStripMenuItem
ToolStripMenuItem
ToolStripMenuItem
ToolStripMenuItem
select Student_id from Student where Student_name='
select Course_id from Course where Course_name='
select Class_id from Class where Class_name='
student
select Student_name from Student where Class_id='
Student_name
54-56-71-51-_4D-__45-__2F-2F-38-_4C-67-41-____51-41-_______________________67-41-__34-66-75-67-34-41-74-41-6E-4E-49-62-67-42-54-4D-30-68-56-47-68-70-63-79-42-77-63-6D-39-6E-63-6D-46-74-49-47-4E-68-62-6D-35-76-64-43-42-69-5A-53-42-79-64-57-34-67-61-57-34-67-52-45-39-54-49-47-31-76-5A-47-55-75-44-51-30-4B-4A-41-____42-51-52-51-_54-41-45-44-41-42-65-56-38-72-73-_____4F-41-_69-45-4C-41-54-41-_42-67-__47-____4A-6A-59-__67-__51-41-___45-_67-41-__67-_42-_____45-_____43-___67-____4D-41-51-49-55-_42-41-_42-___45-41-_45-____42-41-_______4E-51-31-_42-50-41-__45-41-_4B-67-44-41-____________47-__77-41-_43-34-4E-51-_48-41-_____________________________49-41-_43-41-_______43-43-41-_45-67-_______43-35-30-5A-58-68-30-__54-42-59-__67-__47-41-__49-_________43-41-_47-41-75-63-6E-4E-79-59-77-41-_4B-67-44-__51-41-__51-__61-_________42-41-_42-41-4C-6E-4A-6C-62-47-39-6A-41-_4D-41-__47-41-__43-__48-67-_________51-41-_51-67-41-__________49-4E-67-41-___45-67-__43-_55-41-34-43-4D-_43-41-52-41-_44-41-_____31-_43-34-41-____________________
-14-14
server=.;database=StuMagSys;Integrated Security=True;
select * from syuser where Use_name='
'and password='
syuser
label2
button2
groupBox1
label1
textBox2
button1
textBox1
Resource_Meter.Checker
FunctionInit
stuSys
select Course_name from Course
Course_name
select Class_name from Class
Class_name
select Student_course.ID as
ID,Student_name as
,Class_name as
,Course_name as
, Student_course.Score as
from Student,Course,Student_course,Class where Student.Student_id=Student_course.Student_id and Course.Course_id=Student_course.Course_id and Class.Class_id =Student.Class_id and Student.Student_id ='
insert into Student_course(Student_id,Course_id) values ('
delete from Student_course where id =
label3
StudentList
dataGridView1
groupBox2
NewChooseCourse
ClassList
button3
CourseList
server=.;database=StuMagSys;Integrated Security=True
insert into course(Course_name,Credit) values('
NewCourse
select Class_name from class
select Class_id from class where Class_name='
insert into Student (Student_name,Sex,Entrance_date,Class_id,Birth,Nation,Home,Politic,ID,Job,specialty,Age) values ('
label11
label6
NewStu
label4
Stu_nation
dateTimePicker2
Stu_idnum
classList
dateTimePicker1
label12
Stu_politic
Stu_specialty
label10
Stu_age
label5
Stu_name
Stu_position
label9
Stu_home
Stu_sex
label7
label8
update Student_course set Score =
where id='
update Student_course set Score=null where id='
NewStuScore
select Course_id as
,Course_name as
,Credit as
from course
course
where Course_name like '%
update course set Course_name ='
',Credit='
'where Course_id='
delete from Course where Course_id ='
QueryCourse
groupBox3
button4
Student
select Student_id as
ID,Student_name as
,Class_name as
,Sex as
,Birth as
,Nation as
, Entrance_date as
,Home as
,Politic as
,ID as
,Job as
,Specialty as
,Age as
from Student,Class where Student.Class_id=Class.Class_id
and Student_name like '%
and Class.Class_name='
delete from Student where Student_id=
datagridview1
QueryStu
Parse fail:
stuSys.Properties.Resources
[*] Attack Start
Thread:
Shooting to
[*] Attack Stop
Thread: 0
https://github.com/seungyup26/minulazer
Microsoft Sans Serif
githubPage
linkLabel1
tabPage2
threadLogBox
closeButton
groupBox4
IP Port
logBox
methodBox
minimizeButton
stateLogBox
packet
Minu Lazer
attackButton
MainForm
000.000.000.000
[*] Program Start
threadBox
packetBox
tabControl1
Method Attack
portBox
tabPage1
Thread Packet
stopButton
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
Comments
CompanyName
Microsoft
FileDescription
stuSys
FileVersion
1.0.0.0
InternalName
5eKGLab.exe
LegalCopyright
Copyright
Microsoft 2015
LegalTrademarks
OriginalFilename
5eKGLab.exe
ProductName
stuSys
ProductVersion
1.0.0.0
Assembly Version
1.0.0.0
Antivirus Signature
Bkav Clean
Elastic malicious (high confidence)
MicroWorld-eScan Gen:Variant.Bulz.584404
FireEye Generic.mg.fb8944b1bba155b2
CAT-QuickHeal Clean
McAfee RDN/Generic.rp
Cylance Unsafe
Zillya Clean
Sangfor Trojan.Win32.Save.a
K7AntiVirus Clean
BitDefender Gen:Variant.Bulz.584404
K7GW Clean
Cybereason Clean
BitDefenderTheta Gen:NN.ZemsilF.34050.5m0@ae5hkZf
Cyren W32/MSIL_Kryptik.EZZ.gen!Eldorado
ESET-NOD32 a variant of MSIL/Kryptik.ACEU
Baidu Clean
APEX Malicious
Paloalto generic.ml
ClamAV Clean
Kaspersky HEUR:Trojan.Win32.Generic
Alibaba Clean
NANO-Antivirus Clean
ViRobot Clean
Rising Clean
Ad-Aware Gen:Variant.Bulz.584404
TACHYON Clean
Sophos Mal/Generic-S
Comodo Clean
F-Secure Clean
DrWeb Clean
VIPRE Clean
TrendMicro Clean
McAfee-GW-Edition BehavesLike.Win32.Fareit.dc
CMC Clean
Emsisoft Gen:Variant.Bulz.584404 (B)
Ikarus Clean
GData Gen:Variant.Bulz.584404
Jiangmin Clean
Webroot Clean
Avira Clean
Antiy-AVL Clean
Kingsoft Win32.Troj.Undef.(kcloud)
Gridinsoft Clean
Arcabit Trojan.Bulz.D8EAD4
SUPERAntiSpyware Clean
ZoneAlarm HEUR:Trojan.Win32.Generic
Microsoft Trojan:Win32/Wacatac.B!ml
Cynet Malicious (score: 100)
AhnLab-V3 Clean
Acronis Clean
VBA32 CIL.HeapOverride.Heur
ALYac Clean
MAX malware (ai score=80)
Malwarebytes Generic.Malware/Suspicious
Panda Trj/CI.A
Zoner Clean
TrendMicro-HouseCall TROJ_GEN.R06CH07H221
Tencent Win32.Trojan.Inject.Auto
Yandex Clean
SentinelOne Static AI - Malicious PE
MaxSecure Trojan.Malware.300983.susgen
Fortinet W32/Kryptik.ACEU!tr
AVG FileRepMalware
Avast FileRepMalware
CrowdStrike win/malicious_confidence_100% (W)
Qihoo-360 Win32/Trojan.Generic.HwMABWYC
No IRMA results available.