Static | ZeroBOX

PE Compile Time

2021-08-22 01:07:53

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x00079314 0x00079400 7.93615926863
.rsrc 0x0007c000 0x00007480 0x00007600 5.96484619377
.reloc 0x00084000 0x0000000c 0x00000200 0.101910425663

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x00080bb8 0x000023a8 LANG_ENGLISH SUBLANG_ENGLISH_US PNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced
RT_ICON 0x00080bb8 0x000023a8 LANG_ENGLISH SUBLANG_ENGLISH_US PNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced
RT_ICON 0x00080bb8 0x000023a8 LANG_ENGLISH SUBLANG_ENGLISH_US PNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced
RT_ICON 0x00080bb8 0x000023a8 LANG_ENGLISH SUBLANG_ENGLISH_US PNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced
RT_ICON 0x00080bb8 0x000023a8 LANG_ENGLISH SUBLANG_ENGLISH_US PNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced
RT_GROUP_ICON 0x00082f60 0x0000004c LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_VERSION 0x00082fac 0x00000354 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_MANIFEST 0x00083300 0x0000017d LANG_ENGLISH SUBLANG_ENGLISH_US XML 1.0 document text

Imports

Library mscoree.dll:
0x402000 _CorExeMain

!This program cannot be run in DOS mode.
`.rsrc
@.reloc
ct$X6T
Z?_b`
_bj2
_bY*
Z_bX
Y_cX*
v4.0.30319
#Strings
Assembly
System.Reflection
ResolveEventArgs
System
ValueType
Object
Stream
System.IO
System.Threading
ThreadStart
X509Certificate
System.Security.Cryptography.X509Certificates
EventArgs
Dictionary`2
System.Collections.Generic
CultureInfo
System.Globalization
AssemblyName
AssemblyTrademarkAttribute
AssemblyCopyrightAttribute
AssemblyProductAttribute
ComVisibleAttribute
System.Runtime.InteropServices
TargetFrameworkAttribute
System.Runtime.Versioning
AssemblyFileVersionAttribute
GuidAttribute
DebuggableAttribute
System.Diagnostics
DebuggingModes
RuntimeCompatibilityAttribute
System.Runtime.CompilerServices
CompilationRelaxationsAttribute
AssemblyTitleAttribute
AssemblyCompanyAttribute
AssemblyConfigurationAttribute
AssemblyDescriptionAttribute
STAThreadAttribute
CompilerGeneratedAttribute
MemoryStream
Buffer
String
List`1
Enumerator
IEnumerable`1
IDisposable
Environment
SpecialFolder
OperatingSystem
DriveInfo
StringBuilder
System.Text
MD5CryptoServiceProvider
System.Security.Cryptography
Encoding
HashAlgorithm
Directory
Thread
FileAttributes
DirectoryInfo
FileSystemInfo
RegistryView
Microsoft.Win32
RegistryKey
RegistryHive
WindowsIdentity
System.Security.Principal
WindowsPrincipal
WindowsBuiltInRole
RuntimeTypeHandle
Random
IEnumerator`1
IdentityReference
SecurityIdentifier
IntPtr
IdentityReferenceCollection
WellKnownSidType
IEnumerator
System.Collections
StreamWriter
TextWriter
StreamReader
Convert
TextReader
Delegate
EventHandler
AppDomain
StringComparison
Monitor
AssemblyNameFlags
Interlocked
ResolveEventHandler
Attribute
SecuritySafeCriticalAttribute
System.Security
RuntimeFieldHandle
RuntimeHelpers
Hashtable
Module
ModuleHandle
FieldInfo
MethodInfo
ParameterInfo
DynamicMethod
System.Reflection.Emit
ILGenerator
BindingFlags
MemberInfo
BitConverter
RuntimeMethodHandle
MethodBase
OpCodes
OpCode
Exception
ObfuscationAttribute
MulticastDelegate
IAsyncResult
AsyncCallback
SslProtocols
System.Security.Authentication
SecurityProtocolType
System.Net
X509Chain
SslPolicyErrors
System.Net.Security
IContainer
System.ComponentModel
System.Text.RegularExpressions
Process
WebClient
ProcessStartInfo
ProcessWindowStyle
ServicePointManager
RemoteCertificateValidationCallback
DeflateStream
System.IO.Compression
CompressionMode
HashSet`1
Enumerable
System.Linq
System.Windows.Forms
Message
Clipboard
Application
Control
ContainerControl
AutoScaleMode
ZipFile
Ionic.Zip
ZipEntry
GZipStream
Ionic.Zlib
System.Drawing
<Module>
Struct0
Struct1
Class0
Class1
Class2
Class3
Struct2
Class4
Struct3
Struct4
GClass0
GClass1
Class5
Class6
GClass2
Class7
Class8
GClass3
Class9
Class10
Class11
Class12
Class13
Class14
GClass4
Class15
Class16
Class17
Class18
Class19
Class20
Class21
ObfuscatedByAgileDotNetAttribute
SecureTeam.Attributes
<AgileDotNetRT>
<ClassD234>
{FE3C441D-DF9D-407b-917D-0B4471A8296C}
assembly_0
struct4_0
uint_0
struct0_0
uint_1
stream_0
struct0_1
struct0_2
struct0_3
struct0_4
struct0_5
class2_0
class3_0
class4_0
struct0_6
struct1_0
class0_0
class2_1
bool_0
struct1_1
uint_2
struct1_2
struct2_0
byte_0
sslProtocols_0
sslProtocols_1
securityProtocolType_0
securityProtocolType_1
securityProtocolType_2
string_0
string_1
string_2
string_3
string_4
mutex_0
<>9__0_0
<>9__0_1
<>9__0_2
string_5
string_6
string_7
string_8
string_9
string_10
string_11
string_12
string_13
string_14
hashSet_0
hashSet_1
int_10
icontainer_0
object_0
dictionary_0
dictionary_1
dictionary_2
DwAAAA==%
EAAAAA==%
AAAAAA==%
CwAAAA==%
DQAAAA==%
AgAAAA==%
IQAAAA==%
uAAAAA==%
uQAAAA==%
fQAAAA==%
FgAAAA==%
FQAAAA==%
MQAAAA==
MwAAAA==
1gAAAA==
YgAAAA==
MgAAAA==
QwAAAA==
RAAAAA==
RQAAAA==
RgAAAA==
SAAAAA==
TgAAAA==
TwAAAA==
RwAAAA==
TAAAAA==
VwAAAA==
WAAAAA==%
WgAAAA==
YQAAAA==
QQAAAA==
XAAAAA==
SQAAAA==
OgAAAA==
XwAAAA==
WwAAAA==
AQAAAA==
YAAAAA==
ZQAAAA==%
tgAAAA==
SgAAAA==
aAAAAA==%
aQAAAA==
xQAAAA==%
xgAAAA==%
eQAAAA==%
agAAAA==
QgAAAA==%
ugAAAA==%
awAAAA==
bwAAAA==%
cAAAAA==
AwAAAA==%
MAAAAA==%
2QAAAA==
TQAAAA==
OwAAAA==
cgAAAA==%
NwAAAA==
uwAAAA==
cwAAAA==%
dAAAAA==%
4QAAAA==
4gAAAA==%
4wAAAA==%
wgAAAA==%
vgAAAA==%
wwAAAA==%
xAAAAA==%
vwAAAA==%
PAAAAA==
ewAAAA==
ygAAAA==
fgAAAA==
ywAAAA==
zAAAAA==
PgAAAA==
FwAAAA==%
BQAAAA==%
EgAAAA==%
DgAAAA==%
BgAAAA==
gwAAAA==
hAAAAA==
hQAAAA==
CAAAAA==
CQAAAA==
CgAAAA==
hgAAAA==
jAAAAA==%
jQAAAA==%
fAAAAA==
VQAAAA==%
jgAAAA==%
.cctor
smethod_0
smethod_1
method_0
method_1
method_2
method_3
method_4
method_5
method_6
smethod_2
smethod_3
smethod_4
get_Boolean_0
OpenProcessToken
CloseHandle
AddClipboardFormatListener
System.Windows.Forms.Form.WndProc
Form1_Load
System.Windows.Forms.Form.Dispose
smethod_5
smethod_6
smethod_7
smethod_8
BeginInvoke
EndInvoke
Invoke
resolveEventArgs_0
stream_1
uint_3
long_0
long_1
byte_1
uint_4
intptr_0
intptr_1
x509Certificate_0
x509Chain_0
sslPolicyErrors_0
sender
disposing
cultureInfo_0
assemblyName_0
dictionary_3
dictionary_4
object_1
proxyDelegateTypeToken
GetManifestResourceNames
GetExecutingAssembly
get_Location
GetCustomAttributes
GetName
GetManifestResourceStream
op_Inequality
op_Equality
get_Name
ToString
ReadByte
get_Length
set_Position
get_CultureInfo
get_Flags
get_Value
IndexOf
GetValue
BlockCopy
get_Chars
Concat
Substring
ToUpper
Equals
EndsWith
ToLowerInvariant
IsNullOrEmpty
Dispose
GetFolderPath
get_ProcessorCount
get_UserName
get_MachineName
get_OSVersion
get_SystemDirectory
get_Is64BitOperatingSystem
GetPathRoot
Combine
GetTempFileName
GetTempPath
get_TotalSize
Append
get_ASCII
GetBytes
ComputeHash
Exists
CreateDirectory
SetAttributes
Delete
get_Attributes
set_Attributes
Refresh
OpenBaseKey
OpenSubKey
DeleteValue
SetValue
GetCurrent
get_Groups
IsInRole
GetTypeFromHandle
IsValidTargetType
IsWellKnown
GetEnumerator
MoveNext
WriteLine
FromBase64String
ToChar
ReadToEnd
get_CurrentDomain
GetAssemblies
add_AssemblyResolve
Exchange
InitializeArray
ContainsKey
get_Item
set_Item
GetModules
get_ModuleHandle
ResolveTypeHandle
ResolveMethodHandle
GetFields
get_FieldType
get_ReturnType
CreateDelegate
get_ParameterType
GetILGenerator
TrimEnd
ToUInt32
GetMethodFromHandle
get_IsStatic
GetParameters
Ldarg_0
Ldarg_1
Ldarg_2
Ldarg_3
Ldarg_S
Callvirt
IsMatch
GetProcesses
get_ProcessName
get_MainWindowTitle
GetProcessesByName
get_Handle
get_StartInfo
DownloadFile
set_CreateNoWindow
set_UseShellExecute
set_Arguments
set_FileName
set_ErrorDialog
set_WindowStyle
get_ServerCertificateValidationCallback
set_ServerCertificateValidationCallback
set_SecurityProtocol
ToList
WndProc
set_ClientSize
add_Load
get_Msg
SetText
ContainsText
GetText
SuspendLayout
set_Name
set_Text
ResumeLayout
set_AutoScaleDimensions
set_AutoScaleMode
ExtractWithPassword
Contains
get_Current
get_Count
TryGetValue
Boolean_0
Boolean_1
advapi32.dll
kernel32.dll
user32.dll
mscorlib
System.Core
DotNetZip
_ S6rc\,?c}OgE?8HT0 !\&J^E%.resources
costura.dotnetzip.dll.compressed
costura.costura.dll.compressed
costura.dotnetzip.pdb.compressed
.NETFramework,Version=v4.0
FrameworkDisplayName
.NET Framework 4
1.0.0.0
$b84c135b-a8d6-4716-9615-5af0962eb287
WrapNonExceptionThrows
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
PADPADP
ejq#[*
a:A Q[
N}VMg'
"AQ(aN
M\KM\GM,]!CWg]
9Ssn/M`
[}->h=.O-E7
X5(NL
X[YSC@
oF]+WP
Bx\P=*T
Ab+gEp
'7SwOj
m,q>oA
r|$2}3
!;YXr1N
*>dQhA8@
3j1efc
y8V$2I6
HIYr:N9]\
!4$Zg'
8;"W~D\'
!<?|y;$Z
9yjq
#Z0Jp0
=0gS6BW
R,;6pd
q*@w%]ZI
si==DIL
r@PHc6w
$uBR''
g|O,;1
&>zq[b
7HGi?Z
Jc$e+
lpxX[1F
3@uBu$
72.}gDp
Q))r$<
'MkYd
D)5aK
e=t [J
"EUj,z
iIU%2
fA?*~`Y
{Uc?}k
TpT}{}
}LR59|
>6FTE3
nz|lV$Y
cdiBnx
>&qr=:
7zFBFUP
{tF'C.
g2^IRZl
h)K@Z4
$RF9-1I
4CzPf]
5N1>mg
~Il-r"
N\<M,W
RLh7b""
J@,R-e
e3F5Iq
c;Y<fL8Y
^G!1l0Vx
|KX-L$L
Njx+nFfBO"
\sQ-mU)U
f'"Qs3
Zk^c^m
,]##u,
is=V+'
AyO+~Ou
r4x9y8z:
0Hq)^
)A.3R
8MFJMd4
#'i|=RJ
5chM2k
cVbx3J
'78{S;?JsVj
h[V'A{
5'\A{<
k\@nG_7
P5OW2'T
}TxSL&
EZsjhI
:Vjh~[h
|L8~VI
SV:l>'
/q$'X%x
|(uFzE7
rjDu!bcN
[8m7hI'
ia{I9;
?'8-l/
Thfsxz
0Fdb/-
l?9X$u
%+a/},
jJopZ^
NpJ|Hj
'8e<,
^)G,V{w
-[`9-o
srO.dDz
mG(R$A=
^*iX8y
E*1]Qk
eMi0O1
|?xmH_
icN'sz9
G)F|OP<
b9qN[N
6'.]w=0
,*^On?
X;^%6h
d1m\FjF
#bh`8682
I_W[{0
+c#;Ex0
;:6>02
oXQ\.n
<:!iD&
VZyONl
:x&R.)
ZhLfs,w
la]O&^p
aM;~Sq
@2X@5L
z!i+43yc
raXyLee
"eS4e(
<'TH$c|
<P0Egcl
".w|zAm.
2CzXKy
j%7DDvJe
)g$CeX:
9y$M[A
~F9#YRO
Y"l^J"
j;Q5$q
oJYB#/(H2
OGe>SN
"pA)nv
'+"meu
!dg9Z5
Tp1+A^
tpT3:4
mPx@*A
EcrLuL
H;,=1{4c
Lmo(@<5l
x5'k$WL
4GA5Jjs
xyjrmRS
|LK[UY
u1)=jS
PQ=.K@
#UEkQ<
px\.A>
aN==8z0
5en5}k
5e.5}k
,\B4`n
Tq<}<P
_i$@id
~i@f|~v
Nv2Y||
:<93917;'"'>1
zQAo2h
;+9/7'>
J9z|1D
'-9=5-
0v2vru2uu
BR_\TU[_
2M<DDEU
:C(dVV
z@:h;0
fx5h3b
06L,40ncnee%
PpdtttjzzQn
&/uxzzd
*yDw+s
eYnn$Z
WLl|BQ
(!..&&
4:&"*2
k|JJB|a
O'uzPK
cdfm[N
<XywsZp
1{+Kk|--V
?<R5jui
/!Xjrf
O3O5Z$
ww|8p7o
'U~<1"p
U d^2r
bpHHA~$
OaE-NQ
+6UyIR
PfVa5
lH3[Jh
Gphb[paet$
BFU]m[2
[^nS|b
StLfs#
rr:7R_
@`Qaj@
OPhbhP
~'7$:6
{^f<f?
?hkR0P5
T0.;T^
'7+*tX
i=xq]s
"U{Juk
KJ0+]k
cW1xqMdIj7
ZogqZo1(;
Ce>*_#)
[^@557
M6Y"_k
57LP:_
-+GizK
~GDt}k
IKNr$qf
H($?/|I
s1+eOrT
-0C4;
bHHNY@!B J
+Yc2n.\
J##*/m
-^>1|k
(r Ko=
f)W|I|Idk
FB|Y[.
VG}Y4~
~/f(4s
io'(8a{
rh%l%u
8YeHkv
jee%KV
T(gKOB
ZB_I;_
8QkuiM
QdG{p9
z`Fi9'
2F)JMj(e
|k{ ,~h
Q:(iBSoS
'Rn9\`
LU/H?XhC
H/i4Y@O
c*>zA?
`Im2"4#Cuwg
H\=i%(
lx517R
R*Bo[aM(
sEr}"
`(C2eJ
rp=[,_z
90t}A!
%$_'&>
=$o7Z
YOBFz/
\:*l%X8
=?)&|s
!46)0
h#sOUj
HJYy9E
UxU&oe
#ryZ%!
dY"TX#T*6
\F/>|
%<~8BlV
RZCq|i
Cnjv4M
Ib22QRs
^W=zXs
j@}d+/
Ocfv{%
}l8~bz2w
9s&WH+
YF}E=KqUw
eBO( DN
;oJ=b*?
|9NT8-
EI'Av.5
NA+?~%
X/)\J
&>&"nq5
OB? 6%
3csS3[
CQRl$J
!JIN@q
E=-BoJ
FVUUQF>)
^YEE9!
'XvTTd
o{8m7<
B5YYNv
*Hb`js?
^a2.6:
/`w=w}4w
Vcokz{Uv
&bBmcE
UZ;+VB
*U-{(nbS
ypO2C,xE
<4V07(
\zQ}2(
uhfU}!
uU=l*Y
#Fs=G-
u)Bv65XP
9ffl4},
~\ M>7x
IlW4\e-O|
MJN<@E
D>^wTzd
M31SX\
8tM[iY
UiYN|>|
m~ql0
0JIRcC
Z"D>4L
g*ZW#ZW
=3>9Gy
WkTj!^`
2;ccY&
(dO6Z<
oov8'u
!TnOT?
WNQ0%o~
`|r.ZRL3
R<h0Pb
n49nfD
2?fpdf.
SIB$~U
h09fc[
)15]`z*O
A+Eo?
?7RpTV
F{F$Lm
+nez8r
2C]!S!
#uy`gc
'ka?%cq
>" [B7
=+?{C/#?
nf/Fg:
ps]e|Rt
`|L<u3Cr=2fZ
iZ\5+`
@{ooi.
_bzxf/
kmMo4
~vad<x
@6x;r;
M6fTxHh
}={}_>?
Dt&</`
}qNEoB(SO
|a),DO.
oVSS0v
n(zH<~
,X!Y=i%
S4lN:\}o
yYo6yMM
tTiu59
KOt$aG
K{8d.{
a=]aqW
:~?1C:A
r?h2\v
PKJ"q+q
X/E>@l
wZn4rH
[1&wP
mzi@_s
B-l<7-o
[e1ab7a
sgUq\c
7?0Z{3y
(Wa%e(qA
$KdZ|=
-qSvS>
p?8>KkU^wC
DA?)nv
4[e^xh
~jzz0VkLcO
hX`g4C
8d=F=f
G*n{K+
?ZnL2\
{fgh__4z"
f[,\M ,,
Ao34,i
`Gjx>O
T#NQ
vz]BQoC
6w8r"V
)wd$7g
`yQ(4I
RagJ+C
UV\_b
)dHF2q
CxA!&Z
}`t(CcW$
a>im;!$
mz.QaC
(oMQng
cr3F%;
G7@YMW
\ tIV(
({7u7@{
X>T]1M
]k{{~s
q~lXllL
&&)@o_
NCBp2:?)?
:6%O]mz
T777/c
7$'*sn
wl,K';
K=8r%
VRVCwP
ky8o"G
jVdwu<-
9B`1EU
-KEYec
Tnm|&M
_jSl$v
z}Jj%TD
xhIp8R
64a[h;7
7HA'.8
sfsF+o
a(}ven
ENv>{QjA
b(u<6gg
gjSP0X8
qlh1-\
y;/|O{
Z!PuOy
C;C''k
@`>wu<p
D;;~O=
C6pO\u
}#:3i(!
8s>:wA0H
7O^c5j
Blv4/T[
OAN;vXw(
$p},%_
/ocjLyJG
bHPzTM
3'E4d@
qzl^R# S
dx$(Tu'
Tchm=>
oNXu{A,
jyI*rS
wB4<sQ'
|z\`On
xO5yin
^QY1f|
tvt@C0
zia6Yz
Me/ct9[
]*H!u`
rC,_+1
^fH1^P
PT%jW}
/}27yc4
Wf>i'}0?
g_c**w;
Z'[>b'
qNU"|p
z5NE;l
2=WW f9M
2'eM8)}w
{${Y_n
F~Yr-~V}
^6P6r0
zOpK_Q
R*F1n
W5Qyy.
,K& nHf
\%{b3#9yN
[AbbK-=
_$u&LU
O&2IrS
C!N~cSJ
mWNQs<
ijBmk1~
BKE'o$
rGVkPM69
M}YLhY
zMLbF
!~y{_]
=eulU<}?<
S'tHKJ
4^tXn|
hn&gmg
=5s;scgs
'ss.3;
{ l!D|'
z`W+63,
.6\^xr
7~wX_M
]eWwEEe
8-kO}K]
aY]b,+
,[:K7lV
\aK;T/j
<E5o=(
p:08
hk%#eQ\Q:
Ig=h-\
^11,_l
~wQAaZ``
47B{jT
.j/[C`*\
ygK#iQP[)
]OUO4U
dT=`s`
p3bU;Y
=PfZy0
8jOd]^
M7T_Gc
+Uo42d
*<1Z}
nk@{\l
>[$$,9
a}!WF1
Y$7p6p
\md7g#
>OQqxV
$r>MQay
D^Y1x
=qr]oS
p5p;p-
$<?/<o
.y_"y_
sO?@o=
#T`ry}U
Pl+1Tp
M7:Fwe
t6D="=
/`<`1
Lz\W;,
FRcrF*
8-u<-u
W@!`)`#`;
lmupee)
l<r=p?
VZ/?rq+
'yn> G
*VWiyZK
\-x5p9pD
FWZmT(m
;L{WVW
K}02)n
?ozu8TWS
]MYYtOd?/
rw%!F[
Q?L3$o
',^+@sY
12w(]:I
{^MC]ir
57tcCe]
YR39XO
|G[={p
7rCe?o
XXY}Mem
3{e;f(
Q"}7N~)
hVzC/Uc
1eZZj
Zv}9sv
b;^MP;
3#,|knX|
2=x?Gl
[{B[#z
cU~l#r
ksvZ}!
'2>A-O
se0p5}o
u|fDd.
O]BQDd
,&#Mld
R.8#qo>
9uMTl9k
{%*6}bu
wxoTel;
r@S@KAk@[A;A
3hT>stc
@[A;A{A
AQ0m-@
?^]*h/
ctu$6v7
C"e^Gco
rAKAk@
QScbo:-&q
+?3,LN
M>Wum%e
vGbK>i
g*);4P
~>_DQ$W
|XA='
@kA[A;A
pL0#&9
^PMr>^WM
AS5._U
!=HsFw7
>U1oZj=q
~q$?/u
N<oNjt
c1?@Q^
9>N. {
"~EAc~
k&hU{
=ujUU]Z
8;Yi.R
S.|u\t
j#eL\w
`9`#`+`7
cRzQUMz
|'Dh;6
;3B{\3
~#B{u3
+*K[X'
CN3KjJh
,K/oq97
+^*B0[
s^Ki|
?.kj,!g
&d2,!}}dB
0&!m8.!1
Ox&!1B
#f}S6p
mpFH;Ti
Rr/x{J
xYI%#I[
|~Wd|>
^}sv=O
yr:+N/
QT^[]U{
dO3rG<
<N1GZ]
S1{.l`
DOiD zx
|i}|p.
*O'k`9
tm=Hyg
xY\|%\C[a
[F7dl1m0
b#B91mC~
n5mB8Lh
f_wLd_
E|6(_g
ur,hf:^y
X {XG{
~-B{Q3
;+]WRVRW
-7u]O3
|Md~&}
x$MyUzy
?/:N;e
3/$vjae
}wKJ.h
Gqiqe^
q#hxq]m
/m,yQ{
~cQx^g
sm9GI:-
`)`-`3`;`
M*ZV
G$],yo
#gY`Rj
j;0Sb
JQ:^^}
Ns<]%e
6:Ub?uQ
Q}6>&
JidDIY
@]uder
P)QQ]u
WjgZ'|
{.2}M}n
8l?Fwlw
,*.[X1
X}&F;j
F!W7f9
,$7zjO
/r}881
|2jit=k
=EmiR0
{7O~VtN
\y7V{a
Uk3*[QW
wBe!{E
!?Dt/H
|cs\mzO
#fL>0Q
Ho$UhrP
FOY;zX
_E|'Ut
we. Lg
77AtRH
`)`-`+`
,_^y~q
6_XQyv
ed{Ms+
X"{hZ?
Zh/4himj'
^TAWA,?
\@!`)`
;md<}#
a<WwsXO
M{a?.?D{b|=
>>A<w7
qFVF^U^U`
@zV4s,
'4!4)T*
+4*4.t
:"tAhLhB
OhT(+O
:%4&tCh
:!tNh\
:'4*4.tG
)4&tChRh^
:$4*4.tG
7BY!i'
:%tAhRh
:$tBh\
](T!T#
4!4)T*
:'4*tG
:#4"tKh
)tJhBhR(g
:&tFhD
E~CD0B
:!tNhTh\(
PT(!tF
:"tChR}p
-wtt0K
,MYnSwx
*GMO*l
*chnR:
G>!:gR`
U7N\<]$
Ixk e?O
4`BN]O
U|!lku0
<-%iQ=
4`(f=b
8ch<Qw5T
Rc,Ak
Fk .;j0
J7g"Va
X5Ryc/Z
VlseGO
yuGTS{l[O
2\fJ-^
)"M, U
+2p^6}
YlBb:_
96O>V*+
*g+I6R=;_
ILLNKI
TgB\Zh
X9[0&?K
?.OA>s
lc~w5a
O#5%9.19%-
AyQPd]CZZ
XgBRrr
#5>99)
q"}Rvv
#eGb3p
ncn}O]
Lcw@cw
lCXK)L
eIaR6J
Cc7Sc7[
D^q}7
eG5v'4
){Cs.;V
FCEP1T
N7y;}&
C_B_A_C
6B/@/B/
_CorExeMain
mscoree.dll
2)N]:I
SWL=^Y
:bh=FI
/J@U7{
#oIDATx
@FFFFFFFFFFFFFFFFFFFFFF
IANf~B
_1iW|7
rk_?\z
8Dgta<-%
3S*FQi
?[.@`m
P!z"R
PT'#(M
AxIDn<
'pNKN@
'###################################
<?xml version='1.0' encoding='UTF-8' standalone='yes'?>
<assembly xmlns='urn:schemas-microsoft-com:asm.v1' manifestVersion='1.0'>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v3">
<security>
<requestedPrivileges>
<requestedExecutionLevel level='asInvoker' uiAccess='false' />
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
$+29BI
TG-b{
XK+(u`
_H-,*e
\F=,'8@(
{FE3C441D-DF9D-407b-917D-0B4471A8296C}
Software\Microsoft\Windows\CurrentVersion\Run
6.0.0.0
4.1.0.0
VS_VERSION_INFO
StringFileInfo
040904B0
CompanyName
Adobe Systems Incorporated
FileDescription
Adobe Photoshop Droplet
FileVersion
20.1 (x001 x003)
InternalName
Droplet Template
LegalCopyright
1990-2018 Adobe. All rights reserved.
OriginalFilename
Droplet Template
ProductName
Adobe Photoshop CC 2019
ProductVersion
VarFileInfo
Translation
Antivirus Signature
Bkav Clean
Lionic Trojan.Multi.Generic.4!c
Elastic malicious (high confidence)
MicroWorld-eScan Clean
FireEye Generic.mg.e38762223f23dd33
CAT-QuickHeal Trojan.YakbeexMSIL.ZZ4
McAfee Artemis!E38762223F23
Cylance Unsafe
VIPRE Clean
Sangfor Trojan.Win32.Save.a
CrowdStrike win/malicious_confidence_100% (W)
BitDefender Clean
K7GW Clean
K7AntiVirus Clean
Arcabit Clean
BitDefenderTheta Gen:NN.ZemsilF.34088.Gm0@au8mWnni
Cyren Clean
Symantec ML.Attribute.HighConfidence
ESET-NOD32 Clean
Baidu Clean
APEX Malicious
Paloalto generic.ml
ClamAV Clean
Kaspersky HEUR:Trojan.MSIL.Tasker.gen
Alibaba Clean
NANO-Antivirus Clean
ViRobot Clean
Rising Clean
Ad-Aware Clean
TACHYON Clean
Sophos Clean
Comodo Clean
F-Secure Clean
DrWeb Clean
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition BehavesLike.Win32.Generic.hc
CMC Clean
Emsisoft Clean
SentinelOne Static AI - Malicious PE
Jiangmin Clean
MaxSecure Trojan.Malware.300983.susgen
Avira Clean
Antiy-AVL Clean
Kingsoft Clean
Gridinsoft Risk.Win32.CoinMiner.ko!ni
Microsoft Trojan:Win32/Sabsik.FL.A!ml
SUPERAntiSpyware Clean
ZoneAlarm Clean
GData Clean
Cynet Clean
AhnLab-V3 Malware/Win32.Generic.C4378604
Acronis Clean
VBA32 Clean
ALYac Clean
MAX Clean
Malwarebytes MachineLearning/Anomalous.94%
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Tencent Clean
Yandex Clean
Ikarus Clean
eGambit Unsafe.AI_Score_100%
Fortinet PossibleThreat.PALLAS.H
Webroot Clean
AVG MSIL:CHMiner-C [Miner]
Avast MSIL:CHMiner-C [Miner]
No IRMA results available.