Static | ZeroBOX

PE Compile Time

2021-08-06 09:06:04

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x000355d4 0x00035600 6.08831078253
.rsrc 0x00038000 0x00000548 0x00000600 3.99650970205
.reloc 0x0003a000 0x0000000c 0x00000200 0.101910425663

Resources

Name Offset Size Language Sub-language File type
RT_VERSION 0x000380a0 0x000002b4 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_MANIFEST 0x00038358 0x000001ea LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with CRLF line terminators

Imports

Library mscoree.dll:
0x402000 _CorExeMain

!This program cannot be run in DOS mode.
`.rsrc
@.reloc
KDBM(
|_MUIECUgjtu}zjvssyvua
vx|\NX[AWU CVTICIPLYZL\NMSEK>QDB_[G#1)=' "9'72 /+!7.)97-99/_6>293=;
#30%'3%
3(=+(6?8|6(4
R[DF\J^qqWASRRTdJKJVHZXa`F^eDBQ]~
xz4 #lrj.hvnb|4tj~;XYI_|jxz{u:_EXIF8
F)0EKKVIE_+
BAqk:?tw|crj`
#$/*uihhnommcs
NPFEOUOKQSVY^[
VMWT]YP
Ag{CEECS#jwmm:ophv%$6vkqq,_
vbrlaE
)*40.>*y
>18hs
N]^GC^V
@STPI^J
YHMBRCBAXFQ/X\F\CicewhVtnp`Ywwj{XyiPjdteXdp
T&>**%+
-#&&8a
5+2)>*
bBTLm@VKAvNN\PQc
U@\]Tf[AFV^{l|/HlvbKnkbpdQtu|j~@Havb1Rv`t+
,??(<*
6*-(=+
nYINAApxQFR
bFPDlRNXR[Uk[EQ]R^h`ynz)JnxlAjtsohGdnztpp~[o}f`MU~`g
*80*2(
EHKFMlCNaLC}dUKRI^JekLYO
wQEWdXPc{f`|/:Kgmrht'MkyGKu{vls{a%Mer`a
DVFSqIUPpI^Jii|SOWudaARVEkeme"-
`vsfuvRVI ;89>?<Havb
wzq/J;
F]'!<K#
$*%,t->14/3"}
5*71:?+52<i
dFTUVR[XJVSS
Seye${}`hl`oecc"#{vh""9pi)-6vb,2d
KUWEz)y+/mrq }
azh&{zg:g
cs?lsl799 u
iddf|2..23b`01&;aOY[c#3{}}d/*q{{
%%<i- "0~bbvw&$lmzg%
]WWJ_R^\B
hj>?,1*
cqr::(bjto&%xpri2p
}ye)7I[X
wiky~--{ta~:
8ft>60+ba4<>%v4;9
(5sYohiXr~<.`hjq$'~vpk<~}
c+57%Z
wiky~--{ta~:
v9yu=77*a`;==$q588:
PXZA*hgea}1/!30cg12'$`^.c#3{}}d/*q{{
$?h*!##?
acqv%%slyf"
f!a}5??"ih3
Pk}|cQ
sLT_WNMnybPBTRRZAcjdyacen{alndu`bysjvszgfi#mlkT{e
/?+34o
:=95g``[]Y_
;=9?q:uJaaxhlw-Eottjirlpqq&=t|b|;sua
Tz~6%%<, ;a
;3%{f<v8WQUSsrQW
<?:?2'
j[AX_HP`OBeHGtk
zKQHOX@gU_URZAVZYK|`{~gq\Tubv%^zlxK\<_`|gbseAV(
3#9-/!7
-9)-*&
3)=?1'
zD[]L@TqvKUOBBVGSI\ejWISVVBS_EPiChmM|nkbl_Cnkh`jFR{|Zm}z}}LFwcqg,
37'70"2T!/( '!##*+&3
CIGWCKL\Z`WXK
#)TMkimxnw\Mi`mk:_ym
CPruz~1Rv`t6,
qqunvhojnqif
jzKMDNQT
fH^\\PKU\^
`XU\QG*[zfzjoymq4C@3G1.)5 \']0&"Q!;U'-ZF,-Z.[]V'$#T_3
`isimjae
h|AGJ@[^
gOLGNJ
jZKJIPNY
pBTRRZAcjd:M74;DE3,412<7/YX,2]%TQ="P!# S*_^[[T:
|}rsmqvwthjkhisolmb~`afgde
}Z\]MQT}VKQQSW
\FZ`|BC\T
t[Xz~|l|S\
geescig`iGs|g|t|{}>az~ga@'
8$;&(;
4!7z9-?
}MSp@UTSJH_kTJOl\A@G^DSgZl
h|jPDl`rdbnIdswDPzzri{gyteKHT
8"&*<*($/")-
uL]CZQFD@RF
AXZMMQYUQ^uQ]]XZ
Hyg~}j~~vbruVukcsw}$6D]0h#=(J8H;7@A+
]I=&IJVA%Q#RP/XY-
#%/:`&"$
, 14i(;24
=3=*!!3!7$'>
ZJ[ZY@^IQWOSCUG^
wYk|{Dof`Ypbnr`hvh\rvxr]prqxCdtd`g
ZYXGAfDD .'' 42
>;+'/(
v[ZFHF@HQ
ABEHQKNH
ASSR\_VZXRGUFy|g{j_
d-Ssh-Tkcnlyk{CSmw}FAX:S@#7
*-<^7$?+
9>'1. +"%0.3u=?+=8<'">&.
uY]Sm]Yfj[FH[[LPF\]Kfvqsu8Ilvwok
LMA~zF);H[23?
/6:<,mn
~N_^ULRE`st
tZNPY^HR@cB^QEUXlbdl}'t54*psi`vdw}qu{l@wV|g
,"$,=g4utj
\_MWOBIK
KJVJP_R^
6$fhcj21rbsrqhva$'7i
loj}at/F~pr
XKPO ;
--.$%3
<839 u
aNQdAKIdtsAEBNJByI]XJZxXQAIABXFiim|yRIx}njsu(s|q!H}khzn )C
'$#.")'1
,9/$6""x/99
OYwYO\_ZMQD`stb_OL\Lwwxkl|~uvxjGJKAGAIQQLFUQFV@FMqm
skx`xcMRBW]!.16-:>?'-4>34!7&(7?*(=/7/&
tqmcacecacm
CEOZjNXLfJRgIK@@H
TJJcq\[_R^N
][cJkjazbyQNTQUbvs
iUxws]yvaubeGuf
)+(+&;!8>l'!5
$'*/5,*
-51>:1?
v|AGJ@[^
nERUFCLT\
jK]ODAGU\jgFZlbdl}SCxvoonm[=6-.[_X/(,!"! r$V-R*XY__X/P"VWQQ7
!'* ;>b
%25&#,4<x
+=/$!'5<
KBD`cn|
rBSRQHVAjth
o]NAD_CR
`aZ+Xh}|{bpgSLRW$U{hknqmxN_G@1Erfc
++$?8'0()=7* ).7!,"
*>"$,8
(<(;24
,:*47$
EYMu~]CJPBM
at\H\W^XigjaeRSMnaluortXDyxwlpk2owp MWtwz
'- !$,$
>/.%<"5
qrLCNKFMIfZ[ZQJRIA
Y__g{eZj{z]BX]RbsrUJPUJt{vS~uq@vq}@YW5^E
:!)8:#1%=1
iDF]\@@}CPSVIU@qS\]Khq
n]UDFWEQi^bol|YBN^PespbvQhruLrkn|D]SAdxsg
97)?'<;/9".l*.(6&76-?(8-,+9`
">1%58
ho@F][C
br]T^QYCRkgAeymU]{c
g-dcUbvs
iGQqlhX|pbhfcqq:
d!3)=:*0.$r=?%v1;
HNFJFs[BPHBDHDLzOH]Ka[]IS
TPB57xsXYE.Xc
iaeoeo!Uht
rK+& "4Fe}c
&=+="(6c
=>1<%?"y>&
f]QA[[cVWJSYW^Z
rfd+.N==@21B75@4)^)-X.)\PPTTP?Q{
1+3*-<
&9! "#'
(&# (
8-,+2 7#
K_@h@K}XGQYgTFCH_UL44wSNF
fD`qM~yijzIeagmTntFQQR^VMW\]IW324bxfe
LL<%*,",A("3+#6JLN
0*(u=!;
.:'>5?"$
MOUODA
IO\VKK17v\B\WY@vkeklbjhO{Pt`tsqu:*
]pri`||Aye`5S[]Xce/
$*;-/*!",cqLL
6,+|<''?\\?5&
$$sXBP
ZHVOPQJH
GXTYY]Zdyg|zj~#alm.bnwq4owknmswwpd?yes:
OXHRJVU
AA]AXCZFd}f3'?i9-1$(4ba-;(0|{+3/"2#"s? !
tSGIWCUIU{RP_VzRCY
{eem~ga??]srnebwvuihkq|yna|bXR"$q__[XZBXY
TMU_RWH
'77.4,
!;+,<,
334:7$$6 <
~X@XU]SC
qH;89>?<=0#1/>2$-Rzkq2?jx``y~x7&9J
9.h/!=!,6
{#"ne
HLDFLN@
QBLUpBVVSTVI_LOJ]AT
U_QVaggnga
#hpooZ%,muhlw
ryaw}scog`p
XTMV]daw`l
7spsvj
,5:<<>"x$%9
ZjKJAZBYaLNGO@QW[OQVPr]T^p\XSY@
Khkf{ax~,WlrR~t`Wzqu]sux|g>Put{`
,/"7-42h
>1<%?"
^[L\AM@GbCBIRJQyTV_WXIOSGY^X
muiecuJdw~
v4.0.30319
#Strings
! O d r }
'!8!P!b!
"Z#o#~#
$9$N$h$~$
%<%b%t%
&,&]&z&
&_'m'v'
(%(4(V(
(@)T)w)
*&*B*T*j*v*
+B,[,o,
; @ ;#
HMACSHA1
IEnumerable`1
ICollection`1
EventHandler`1
IList`1
HMACSHA512
Advapi32
kernel32
Microsoft.Win32
user32
ReadUInt32
ToUInt32
ReadInt32
ToInt32
KeyValuePair`2
Dictionary`2
ToUInt64
ReadInt64
ToInt64
DE8474BE-F400-4FE3-A86C-031882F06285
ReadUInt16
ToUInt16
ReadInt16
ToInt16
HMACSHA256
get_UTF8
<Module>
GetModuleFileNameA
GetVolumeInformationA
get_bindingConfigurationUID
set_bindingConfigurationUID
get_FormatID
GetHINSTANCE
get_ASCII
get_URL
set_URL
get_sSL
set_sSL
System.IO
GAlKmAxmeTqxWDjYhsCbXJvwGaUaxgKLwO
TripleDES
get_IV
set_IV
MoveFileExW
get_value__
set_value__
get_Data
set_Data
ProtectedData
GetObjectData
ProjectData
PropertyData
mscorlib
System.Collections.Generic
Microsoft.VisualBasic
SendAsync
ReceiveAsync
WndProc
get_Id
GetWindowThreadProcessId
GetProcessById
OpenRead
Thread
SHA1Managed
RijndaelManaged
get_LastModified
set_LastModified
set_Enabled
get_enabled
set_enabled
get_BytesTransferred
add_Elapsed
IsBypassed
get_LastAccessed
set_LastAccessed
get_Connected
add_Completed
System.Collections.Specialized
get_IsInvalid
get_Guid
GetField
TrimEnd
ReadToEnd
Append
get_Second
get_Millisecond
UBound
set_Method
CompareMethod
get_Clipboard
get_Keyboard
get_Password
set_Password
get_password
set_password
Replace
CreateInstance
get_GetInstance
GetHashCode
get_SocketErrorCode
set_Mode
FileMode
PaddingMode
CryptoStreamMode
CompressionMode
CipherMode
XmlNode
get_Unicode
get_BigEndianUnicode
IsTextUnicode
VaultFree
get_useSeparateFolderTree
set_useSeparateFolderTree
FromImage
SendMessage
MailMessage
AddRange
CredentialCache
EndInvoke
BeginInvoke
GetEnvironmentVariable
IEnumerable
IDisposable
ISerializable
ToDouble
get_Handle
RuntimeFieldHandle
SafeHandle
RuntimeTypeHandle
ReleaseHandle
CreateHandle
GetTypeFromHandle
handle
Rectangle
DownloadFile
DeleteFile
get_securityProfile
set_securityProfile
Console
get_MainModule
ProcessModule
MsgBoxStyle
get_Name
set_Name
get_FileName
set_FileName
GetRandomFileName
GetTempFileName
GetFileName
typeName
get_OSFullName
get_FullName
get_providerName
set_providerName
get_UserName
set_UserName
get_ComputerName
get_ProcessName
get_ProductName
get_accountName
set_accountName
GetProcessesByName
AssemblyName
assemblyName
GetDirectoryName
get_username
set_username
System.Net.Mime
FromFileTime
ToFileTime
DateTime
GetLastWriteTime
SetLastWriteTime
get_CreationTime
set_CreationTime
SetCreationTime
GetLastAccessTime
SetLastAccessTime
ReadLine
AppendLine
WriteLine
get_NewLine
Combine
LocalMachine
Escape
get_archivingScope
set_archivingScope
DataProtectionScope
get_Type
set_Type
set_MediaType
ChangeType
ValueType
StringType
SecurityProtocolType
BindToType
get_avatarType
set_avatarType
GetType
SocketType
set_ContentType
FileShare
Compare
PtrToStructure
get_InvariantCulture
get_CurrentCulture
Capture
ApplicationBase
NameObjectCollectionBase
HttpWebResponse
GetResponse
Dispose
TryParse
Reverse
Create
MulticastDelegate
GetKeyboardState
EditorBrowsableState
Delete
get_CanWrite
ThreadStaticAttribute
STAThreadAttribute
CompilerGeneratedAttribute
GuidAttribute
HelpKeywordAttribute
GeneratedCodeAttribute
EditorBrowsableAttribute
ComVisibleAttribute
FileAttribute
StandardModuleAttribute
HideModuleNameAttribute
DefaultValueAttribute
DebuggerHiddenAttribute
MyGroupCollectionAttribute
FlagsAttribute
CompilationRelaxationsAttribute
HandleProcessCorruptedStateExceptionsAttribute
ReliabilityContractAttribute
ParamArrayAttribute
RuntimeCompatibilityAttribute
SuppressUnmanagedCodeSecurityAttribute
AccessedThroughPropertyAttribute
set_UseShellExecute
get_Minute
ReadByte
ToByte
get_Value
DeleteValue
GetObjectValue
GetValue
SetValue
GetPropertyValue
Receive
set_KeepAlive
add_AssemblyResolve
Remove
GAlKmAxmeTqxWDjYhsCbXJvwGaUaxgKLwO.exe
get_Size
set_Size
get_HashSize
get_KeySize
Deserialize
Initialize
SuppressFinalize
Resize
SizeOf
get_ItemOf
LastIndexOf
get_Jpeg
System.Threading
set_Padding
NewLateBinding
UTF8Encoding
GetEncoding
System.Drawing.Imaging
FromBase64String
ToBase64String
EscapeDataString
UnescapeDataString
DownloadString
GetPrivateProfileString
CompareString
ToString
GetString
Substring
System.Drawing
ToULong
ToLong
get_enableLog
set_enableLog
get_Msg
get_PasswordHash
ComputeHash
get_ExecutablePath
GetFullPath
GetTempPath
GetFolderPath
get_Width
get_Length
SetLength
get_ContentLength
set_ContentLength
GetWindowTextLength
EndsWith
StartsWith
get_Month
PtrToStringUni
AsyncCallback
get_CapsLock
TransformFinalBlock
TransformBlock
get_CanSeek
get_kbok
set_kbok
AllocHGlobal
FreeHGlobal
Marshal
NetworkCredential
Decimal
System.Security.Principal
ConditionalCompareObjectGreaterEqual
ConditionalCompareObjectEqual
ConditionalCompareObjectNotEqual
set_Interval
Rijndael
get_AccountCredentialsModel
set_AccountCredentialsModel
System.Collections.ObjectModel
System.ComponentModel
System.Net.Mail
LateCall
User32.dll
user32.dll
vaultcli.dll
psapi.dll
ntdll.dll
bcrypt.dll
System.Xml
set_IsBodyHtml
set_SecurityProtocol
set_EnableSsl
FileStream
get_BaseStream
GetResponseStream
DeflateStream
get_EndOfStream
CryptoStream
GetRequestStream
MemoryStream
get_LParam
get_WParam
get_Param
get_Item
set_Item
VaultGetItem
get_FileSystem
OperatingSystem
SymmetricAlgorithm
HashAlgorithm
Random
ICryptoTransform
ToBoolean
IsLittleEndian
get_Screen
CopyFromScreen
get_UserToken
set_UserToken
Listen
System.ComponentModel.Design
ChangeClipboardChain
AppDomain
get_CurrentDomain
SeekOrigin
get_OSVersion
get_Version
set_Version
RtlGetVersion
get_version
set_version
Conversion
System.IO.Compression
get_Application
get_Location
SystemInformation
destination
get_AccountConfiguration
set_AccountConfiguration
get_BindingAccountConfiguration
set_BindingAccountConfiguration
MailAccountConfiguration
SmtpAccountConfiguration
System.Globalization
System.Runtime.Serialization
Interaction
System.Reflection
PropertyDataCollection
NameValueCollection
MatchCollection
GroupCollection
KeysCollection
ManagementObjectCollection
AttachmentCollection
KeyCollection
get_disabledByRestriction
set_disabledByRestriction
get_Position
set_Position
get_ContentDisposition
SearchOption
InvalidDataException
CryptographicException
ArgumentOutOfRangeException
ArgumentNullException
InvalidOperationException
SocketException
ArgumentException
get_Description
set_Description
get_StatusDescription
System.Runtime.ConstrainedExecution
Environ
StringComparison
get_CtrlKeyDown
get_ShiftKeyDown
get_AltKeyDown
SocketShutdown
CompareTo
CopyTo
get_Info
ImageCodecInfo
FieldInfo
FileInfo
CultureInfo
FileVersionInfo
GetVersionInfo
SerializationInfo
serializationInfo
ComputerInfo
NumberFormatInfo
get_StartInfo
ProcessStartInfo
GetLastInputInfo
DirectoryInfo
get_CHoo
set_CHoo
Bitmap
get_Year
ToChar
DirectorySeparatorChar
get_avatar
set_avatar
StreamReader
BinaryReader
SHA1CryptoServiceProvider
MD5CryptoServiceProvider
RNGCryptoServiceProvider
TripleDESCryptoServiceProvider
BCryptCloseAlgorithmProvider
BCryptOpenAlgorithmProvider
IFormatProvider
StringBuilder
SpecialFolder
set_Binder
SerializationBinder
GetDecoder
Encoder
SetBuffer
ServicePointManager
ToInteger
ManagementObjectSearcher
SecurityIdentifier
ElapsedEventHandler
ResolveEventHandler
System.CodeDom.Compiler
ToUpper
get_User
set_User
CurrentUser
get_Browser
set_Browser
ConditionalCompareObjectGreater
ToGenericParameter
EncoderParameter
BitConverter
BinaryFormatter
get_Computer
ServerComputer
get_DnsResolver
set_DnsResolver
SetClipboardViewer
ToLower
CreateProjectError
ClearProjectError
SetProjectError
SocketError
get_NumberDecimalSeparator
IEnumerator
ManagementObjectEnumerator
GetEnumerator
Activator
.cctor
Monitor
CreateDecryptor
CreateEncryptor
ReadIntPtr
MidStmtStr
get_Hour
Graphics
System.Diagnostics
get_Bounds
Microsoft.VisualBasic.Devices
get_WebServices
Microsoft.VisualBasic.ApplicationServices
System.Runtime.ExceptionServices
System.Runtime.InteropServices
Microsoft.VisualBasic.CompilerServices
System.Runtime.CompilerServices
Microsoft.VisualBasic.MyServices
GetInstances
get_ChildNodes
Matches
GetDirectories
get_Properties
ExpandEnvironmentVariables
GetFiles
EnumProcessModules
GetModules
NumberStyles
GetSubKeyNames
ReadAllLines
GetProcesses
GetHostAddresses
FileAttributes
SetAttributes
Rfc2898DeriveBytes
ReadAllBytes
GetAddressBytes
GetBytes
get_Values
SocketFlags
Strings
SocketAsyncEventArgs
ElapsedEventArgs
ResolveEventArgs
get_Ticks
ICredentials
get_Credentials
set_Credentials
get_DefaultCredentials
set_UseDefaultCredentials
Equals
CreateParams
VaultEnumerateItems
System.Windows.Forms
Contains
Conversions
System.Text.RegularExpressions
get_IncludeInGlobalOperations
set_IncludeInGlobalOperations
System.Collections
set_MaximumAutomaticRedirections
StringSplitOptions
RegexOptions
get_Groups
get_Chars
GetChars
GetImageEncoders
System.Timers
RuntimeHelpers
get_advancedParameters
set_advancedParameters
EncoderParameters
Operators
ManagementClass
ConditionalCompareObjectLess
FileAccess
get_Success
GetCurrentProcess
IPAddress
get_Address
set_Address
MailAddress
get_IdnAddress
set_IdnAddress
get_objects
set_objects
System.Net.Sockets
get_signaturePresets
set_signaturePresets
get_templatePresets
set_templatePresets
VaultEnumerateVaults
get_Attachments
set_Arguments
get_Exists
arrays
get_Keys
set_Keys
Concat
AppendFormat
ImageFormat
get_NumberFormat
Subtract
AddObject
AndObject
ModObject
DivideObject
ManagementBaseObject
CreateObject
ConcatenateObject
OrObject
XorObject
SubtractObject
GetObject
LeftShiftObject
ManagementObject
NotObject
MultiplyObject
set_Subject
Connect
set_AllowAutoRedirect
Unprotect
LateGet
LateIndexGet
System.Net
LateSet
get_passwordIsSet
set_passwordIsSet
set_AcceptSocket
get_signingEncryptionPreset
set_signingEncryptionPreset
get_Height
get_Lenght
set_Lenght
op_Explicit
WaitForExit
VaultCloseVault
VaultOpenVault
get_Default
IAsyncResult
MsgBoxResult
set_UserAgent
WebClient
SmtpClient
System.Management
XmlElement
Attachment
Environment
XmlDocument
get_Parent
GetParent
get_Current
IPEndPoint
get_LocalEndPoint
get_Count
get_TickCount
GetCharCount
EndAccept
BeginAccept
BCryptDecrypt
BCryptEncrypt
ThreadStart
Convert
get_Port
set_Port
get_InternalServerPort
set_InternalServerPort
get_port
set_port
FtpWebRequest
HttpWebRequest
XmlNodeList
get_Host
set_Host
ICredentialsByHost
get_host
set_host
set_Timeout
GetKeyboardLayout
get_StandardOutput
set_RedirectStandardOutput
MoveNext
System.Text
ReadAllText
AppendAllText
WriteAllText
get_InnerText
GetText
GetWindowText
StreamingContext
streamingContext
context
get_Now
GetForegroundWindow
NativeWindow
set_CreateNoWindow
ToUnicodeEx
GetModuleFileNameEx
RegQueryValueEx
UnhookWindowsHookEx
SetWindowsHookEx
CallNextHookEx
RegOpenKeyEx
LateSetComplex
MsgBox
get_Day
InitializeArray
ToArray
ToCharArray
CopyArray
Consistency
set_Body
get_Key
set_Key
OpenSubKey
RegCloseKey
MapVirtualKey
get_GuidMasterKey
set_GuidMasterKey
ContainsKey
BCryptImportKey
BCryptDestroyKey
RegistryKey
System.Security.Cryptography
get_Assembly
GetExecutingAssembly
get_AddressFamily
Multiply
BlockCopy
System.Runtime.Serialization.Formatters.Binary
get_TotalPhysicalMemory
CreateDirectory
get_Registry
get_Capacity
Quality
op_Equality
op_Inequality
get_priority
set_priority
System.Security
IsNullOrEmpty
BCryptGetProperty
BCryptSetProperty
set_Proxy
IWebProxy
ClipboardProxy
FileSystemProxy
GetProxy
RegistryProxy
<PrivateImplementationDetails>{28B7E2FF-8F85-4574-A553-985A3227EC65}
MyTemplate
14.0.0.0
My.Computer
My.Application
My.User
My.WebServices
4System.Web.Services.Protocols.SoapHttpClientProtocol
Create__Instance__
Dispose__Instance__
WrapNonExceptionThrows
$a7b1948c-a649-48ef-bfad-f56f97dfa22b
_CorExeMain
mscoree.dll
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<assemblyIdentity version="1.0.0.0" name="MyApplication.app"/>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v2">
<security>
<requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3">
<requestedExecutionLevel level="asInvoker" uiAccess="false"/>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
!%--314?7B9P=
)(*(+(,
credential
logins
+-0123456789ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz
HTTP/1.1
https://www.theonionrouter.com/dist.torproject.org/torbrowser/9.5.3/tor-win32-0.4.3.6.zip
sha512
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
FileDescription
FileVersion
0.0.0.0
InternalName
GAlKmAxmeTqxWDjYhsCbXJvwGaUaxgKLwO.exe
LegalCopyright
OriginalFilename
GAlKmAxmeTqxWDjYhsCbXJvwGaUaxgKLwO.exe
ProductVersion
0.0.0.0
Assembly Version
0.0.0.0
Antivirus Signature
Bkav Clean
Lionic Trojan.MSIL.Agensla.i!c
Elastic malicious (high confidence)
MicroWorld-eScan Trojan.GenericKD.46780329
FireEye Generic.mg.d91aec7f3d8b6583
CAT-QuickHeal Trojan.MsilFC.S17874635
Qihoo-360 Win32/TrojanSpy.DarkStealer.HwMAN9sA
ALYac Spyware.AgentTesla
Cylance Unsafe
Zillya Clean
Sangfor Trojan.Win32.Save.a
CrowdStrike win/malicious_confidence_100% (W)
BitDefender Trojan.GenericKD.46780329
K7GW Spyware ( 004bf53c1 )
K7AntiVirus Spyware ( 004bf53c1 )
Arcabit Clean
Baidu Clean
Cyren W32/Azorult.D.gen!Eldorado
Symantec ML.Attribute.HighConfidence
ESET-NOD32 a variant of MSIL/Spy.Agent.AES
APEX Malicious
Paloalto generic.ml
ClamAV Win.Packed.Razy-9862812-0
Kaspersky HEUR:Trojan-PSW.MSIL.Agensla.gen
Alibaba TrojanPSW:MSIL/DarkStealer.1f3258e5
NANO-Antivirus Clean
ViRobot Clean
Rising Clean
Ad-Aware Trojan.GenericKD.46780329
TACHYON Clean
Emsisoft Trojan.GenericKD.46780329 (B)
Comodo Clean
F-Secure Clean
DrWeb BackDoor.SpyBotNET.25
VIPRE Clean
TrendMicro TROJ_GEN.R002C0DHC21
McAfee-GW-Edition BehavesLike.Win32.Generic.dh
CMC Clean
Sophos Mal/Generic-S
Ikarus Trojan-Spy.Keylogger.AgentTesla
Jiangmin Clean
Webroot Clean
Avira TR/Spy.Gen8
Antiy-AVL Trojan/Generic.ASMalwS.345F4FA
Kingsoft Clean
Gridinsoft Clean
Microsoft PWS:MSIL/DarkStealer!MTB
SUPERAntiSpyware Clean
ZoneAlarm Clean
GData MSIL.Trojan.PSE.18D6RFG
Cynet Malicious (score: 100)
AhnLab-V3 Infostealer/Win.AgentTesla.R420346
Acronis Clean
McAfee GenericRXMK-GR!D91AEC7F3D8B
MAX malware (ai score=100)
VBA32 Trojan.MSIL.AgentTesla
Malwarebytes Generic.Trojan.Malicious.DDS
Panda Trj/GdSda.A
Zoner Clean
TrendMicro-HouseCall TROJ_GEN.R002C0DHC21
Tencent Win32.Trojan.Generic.Wqcw
Yandex TrojanSpy.Agent!LgGJovsgZ+g
SentinelOne Static AI - Malicious PE
eGambit Unsafe.AI_Score_99%
Fortinet MSIL/Razy.749950!tr
BitDefenderTheta Gen:NN.ZemsilF.34088.nm0@amjwhvp
AVG Win32:PWSX-gen [Trj]
Cybereason malicious.f3d8b6
Avast Win32:PWSX-gen [Trj]
MaxSecure Trojan.Malware.300983.susgen
No IRMA results available.