Static | ZeroBOX

PE Compile Time

2021-08-24 07:32:50

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x00035754 0x00035800 6.08448965483
.rsrc 0x00038000 0x00000540 0x00000600 3.97554134992
.reloc 0x0003a000 0x0000000c 0x00000200 0.101910425663

Resources

Name Offset Size Language Sub-language File type
RT_VERSION 0x000380a0 0x000002ac LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_MANIFEST 0x00038350 0x000001ea LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with CRLF line terminators

Imports

Library mscoree.dll:
0x402000 _CorExeMain

!This program cannot be run in DOS mode.
`.rsrc
@.reloc
KDBM(
CFA]GYI
rQOWOCAWytvw{|ht}}{tsg
tFB^L^]CU[.ATROAKNR[XJZLO]KI<WB@]%9!3/;%",7%54&-)?),+?1/;7!]484;1
e22&61/+>62;9/w
u88$2:
oSXEA]I_~pT@TSQU{KHKQIYYnaE_bEAP/LM]C`vdnoa.3)4%2Lqwzpkn2]D1'':%QK?
@CHWNV\:
YEDDz{yy
$0&&.>h|utk
6+(-h|
UKWoiqwg
ee0Ccjvfxu)ophv@EMwry'2^]>rs;l
M\Y^N_^ULRE
tpjhw]WYKTj@ZDTu[[FoLm}LvxhqLpdtf$Ghtoj{mSmwaq1Exra
,+%,,6
5+2)>*
EwkA\@AHrOURzrW@H
|XJ^wR_VDP}XYP~jT\}j~-Fbt`GjmbuZupyp@Havb1Rv`t(
75,+<,
">!$1'
GYMAFJ|tUBV
~ZLX}VHO[\sPBVX\djO{az|QAjtsohXPi~j9Z~h|!% 1Te{b
=)39446;u
kMYCpLDOWJLH
y_UkgYobxgg}9QqftuoicYwt|lrzoAQ{b~{~ax<
}hG[Kix}UFBQGIAI
KTJOZIBfb}
*+(\}j~ccne;&Wevilwkz%<\bc|xuv`|
RI;= W7
+?!& u
Ce,'.($>?*<-zy-3 #&9%0p
FNFJAKII
wZzbmm.[iuv9 =`hjq:xwuqm!?1# s'uu7TW
Hhhxy~
|}`}hhzh"*4/feq933&m
UXXZx6**>?nl45"?}BWFg'7
qqh#.u
VWDY2
U)$$&<rnnrs" pqf{!
.l~08:!
<)6rJJ@p>,fnhs:9|tvm>|sq}a-35'$w
KUWEz))
;{k#55,gb933&s3>:8&h
4pMGZJ^p>,fnhs:9|tvm>|sq}a-35'$w
LTTDE(*~
p>|n (*1dg>60+|>=??#kuwe
UXXZx6**>?nl45"?}A<x&4~vpk"!t|~e6t{y
&$:tll|} "vwdy?
kk%eq933&ml799 u
CHQKB@N_FDCITHI@A@C
CBA~]CIeYt[Xz~|lFn
eqka475GjjbK`mkypVaygsKCF
MNNqw
yEADWy
GA}y~o
)& ( 2
-!kjjikfdicb30&#=:
'!E\B[E]CQT
_]F^UWEM
Idf}kax Fjsqitmqstv#>yso
>tpbv/5
]AmkkmT
>"''to*"0.m%'3%~z594;b~&b.rjv1=9
j[AX_HP
iSOCMPWgmJ[M
ySGQrYXX{e}gL~fo-Rqiwgd}%Xiwnmzn^}pS~uFE5(
>"50%3
75,+<,
lGGJEsjAM@K}dUKRI^Jeu
qX^V__j|
xogmf`S\bqwbn~[TjiozvfCHug}ttdu}g
8*:.;=+
YNZGOBIrTBLTCWEVILWKZ`J\^FUG
;Dxl|n,^vbbmc[Hjyzt9Mk}iw1u
OXAHOLXMG&?
5 <=4
YX_F\K
nPFDDHSMDV
O=N$6LI;/607?537\"! XHusv|gb6Tfp
F16E5C@Ggr
hZLJJBYKBL
=8%HKK5=3A6312FRsu|vil<Y}~qxx7Dt
H;AFI:;A^BG@NYA
536<'"v
NLM}W_I{COUDzdKHWTV
xVPXAoqAF[QiK{xek/M}roibgsmjt;KlnosofO`}cc}yD
)!.1*&.%#l3,(53n
=)39?$$959
vnFJ\V\YGGsUIUEB_^VMLVYNQRDTQXFLZj{zy`~iqwr2usv7xww{.OsmBrcbaxfq9
,, ;%9+&3
'&5.6--
XJtOOCGBL
PSIAMI_HdJJ^NIbA_W_[Q
(#SH#u< ;_/](Z/,8Gzkqhoxvrdp8svt
9:5:29o{
|@EDKPTOJZMRHMm@UC@RFTnozl}|mnaluor[tdihovl{oi}aucul<;@BDA@EE
6"225-+=
,<,>(4==
Ps@jFGXYR
b^JaTH
ZQRxD\w~bjgG\V{zfhf`hq_Pro,Xuht~przoAsps~cy`fD
946?78/
=5$&7%1
bGPx54Yo|
-gmcnbnjb'9zxmz*)0-,>FvgfTW8
)4>-)>.8./=
: %=5!
:/.;<>"
XNI]KK
kNBSI`
p^JTURD^DkrAzgazz!xuvPespbvKu;Hxmlkr`wVEF7Zt
"5-,.'#!7
87786;
62$046'0
XNtyOCXLNH|QQCtDVOYUUc
MGA@]SkUVid}gz|"uoo<`edkpto&%nmsi}p
JIe;):=8#?&}
vbXZYFXNJ
wryapufhQM[L`JAlVEF
][cCGZZZEIRTDVUXBQJKO]#Tyd_|tt_ADt
>e<1:t(05%3{|
>/.%<"5kl
ZK]ZHP|URCU{K[V]
LYODVBnCDQGU{iz}xc
f=<.ubvs
iGlmznBbrcbaxfqT-<9)
(*#>;)5895!2=>::>4*$;3
$6",6#5/6
PQ().{DH`BTimb}zynjk{qhbg`ucjd[S~|i{kS^doBruu[F7FH}mjvrzaWqewS}g,
"#6 )(
pOGRPEW_guP]MSN]UDma^ZQe|{)@[PNwqrdhsR`hhqvpCKt|w
puwtutk?k
Awx[AIEAGP|nSSHJUPd
;o;K67M=2205D5E3,,.\s~uq[^QA6Guf
?#=QC0
0-*/\-
.?>5,2%
''<>9<
G]XXCOsUIUAyjIW^L^Q
tZ\TEkrZrfi`bSalko\]PnvqoztJjpnxNCb~qeuxJ-
,/"7-4o4"'u
;:1*2)| $6
J(,,P)&%+X{\{[x"!!4% 0#6/
`lp~GQVDTwEVILWKZiUXE|^]Oc]Rb
^GM/OblwrnjWevilwkz\ssfa
)7>,>1
;?5"~/lc
IHG\@[oBLEIFSUEQSTV
rq'?KO9"M9::-5C?57+Z),+]Xu}`d~ /$#\_Z
)'7#+,<:
=.!$?#2
cEFL\{IUV
RCSPLT\cyP^QX
`PEDCZxo/T!ymawf\L
TUIFLwku}ysq{Lfye
=#*0"-
*0(>(8r
>%3%:0
][^DLD
TPWSU_
RV@T4Xioo}e-@qovubv%7xwwhzni2k}}'79fJF
PS1@F5ED
;'8x900
DEMJZFCC
FSUGEHLIS]]35lO]KI
wPQ[~1(AZ`_8z
Dkkt~{mN~huS}t@crfl,
/7+.>/.wq
OhGGZNECQaONRTPW[KH\Z
u_RxRf~ymhcFhLtlieBnwnMiqm{l<,
\~q7zz
+9<<>o}@H
//25+)
4*-~flhc^Z
ujNXL~wOSz@AJSK53yZStbE
g{jf~(^Gaug[PjhG
|qvl+
Leye:o
e/!::a8"032.,"'1t4*>q+3/0!?&%2&z
XCSQfPzgijk[~doPt`tsPwsv]wzkso?dy
%(-:= >=0,#$54+7
km=jd9bc}e5bex
r`BSDdHEW^h]KW^PsG^RTD
<8n:m"5nc6-5g?a("-/
3-z+qpvrrsw&
ZY^_Z\WUQ#
Y:=LMBC@AFETDds}if
->*o`7#57,55xkr
2<&:&4v5-!
<m?9j?==a351777n
b+7z}{q}qq};duy
ja& ?9,"-$:"*&("(-;;
<! '>$3(0
MREHVISYk@MKYP
RY]u[]Pd
&Y|`xballr(Tiqj5Ktjo]~q|e
,(#)0k
8;6+1(.|
"422:!
EjKJAZBYaLNGO@QW[OQVP
]^Q\E_ByUXoJkjazbyAlngo`qw{oqvp4inwa~p{rUv
v4.0.30319
#Strings
ELhu
7 C \ j
"K"X"o"
%(%=%U%^%{%
( (*(>(l(
+ +)+2+;+b+
$:&T)[)
HMACSHA1
IEnumerable`1
ICollection`1
EventHandler`1
IList`1
HMACSHA512
Advapi32
kernel32
Microsoft.Win32
user32
ReadUInt32
ToUInt32
ReadInt32
ToInt32
KeyValuePair`2
Dictionary`2
ToUInt64
ReadInt64
ToInt64
ReadUInt16
ToUInt16
ReadInt16
ToInt16
HMACSHA256
4E0906C4-E858-4A79-857C-EC66E9F3FB66
get_UTF8
<Module>
GetModuleFileNameA
GetVolumeInformationA
get_bindingConfigurationUID
set_bindingConfigurationUID
get_FormatID
GetHINSTANCE
get_ASCII
get_URL
set_URL
get_sSL
set_sSL
nvroZXMqguqjUXBKNISBqbjenewIURvXL
System.IO
TripleDES
get_IV
set_IV
MoveFileExW
get_value__
set_value__
get_Data
set_Data
ProtectedData
GetObjectData
ProjectData
PropertyData
mscorlib
System.Collections.Generic
Microsoft.VisualBasic
SendAsync
ReceiveAsync
WndProc
get_Id
GetWindowThreadProcessId
GetProcessById
OpenRead
Thread
SHA1Managed
RijndaelManaged
get_LastModified
set_LastModified
set_Enabled
get_enabled
set_enabled
get_BytesTransferred
add_Elapsed
IsBypassed
get_LastAccessed
set_LastAccessed
get_Connected
add_Completed
System.Collections.Specialized
get_IsInvalid
get_Guid
GetField
TrimEnd
ReadToEnd
Append
get_Second
get_Millisecond
UBound
set_Method
CompareMethod
get_Clipboard
get_Keyboard
get_Password
set_Password
get_password
set_password
Replace
CreateInstance
get_GetInstance
GetHashCode
get_SocketErrorCode
set_Mode
FileMode
PaddingMode
CryptoStreamMode
CompressionMode
CipherMode
XmlNode
get_Unicode
get_BigEndianUnicode
IsTextUnicode
VaultFree
get_useSeparateFolderTree
set_useSeparateFolderTree
FromImage
SendMessage
MailMessage
AddRange
CredentialCache
EndInvoke
BeginInvoke
GetEnvironmentVariable
IEnumerable
IDisposable
ISerializable
ToDouble
get_Handle
RuntimeFieldHandle
SafeHandle
RuntimeTypeHandle
ReleaseHandle
CreateHandle
GetTypeFromHandle
handle
Rectangle
DownloadFile
DeleteFile
get_securityProfile
set_securityProfile
Console
get_MainModule
ProcessModule
MsgBoxStyle
get_Name
set_Name
get_FileName
set_FileName
GetRandomFileName
GetTempFileName
GetFileName
typeName
get_OSFullName
get_FullName
get_providerName
set_providerName
get_UserName
set_UserName
get_ComputerName
get_ProcessName
get_ProductName
get_accountName
set_accountName
GetProcessesByName
AssemblyName
assemblyName
GetDirectoryName
get_username
set_username
System.Net.Mime
FromFileTime
ToFileTime
DateTime
GetLastWriteTime
SetLastWriteTime
get_CreationTime
set_CreationTime
SetCreationTime
GetLastAccessTime
SetLastAccessTime
ReadLine
AppendLine
WriteLine
get_NewLine
Combine
LocalMachine
Escape
get_archivingScope
set_archivingScope
DataProtectionScope
get_Type
set_Type
set_MediaType
ChangeType
ValueType
StringType
SecurityProtocolType
BindToType
get_avatarType
set_avatarType
GetType
SocketType
set_ContentType
FileShare
Compare
PtrToStructure
get_InvariantCulture
get_CurrentCulture
Capture
ApplicationBase
NameObjectCollectionBase
HttpWebResponse
GetResponse
Dispose
TryParse
Reverse
Create
MulticastDelegate
GetKeyboardState
EditorBrowsableState
Delete
get_CanWrite
ThreadStaticAttribute
STAThreadAttribute
CompilerGeneratedAttribute
GuidAttribute
HelpKeywordAttribute
GeneratedCodeAttribute
EditorBrowsableAttribute
ComVisibleAttribute
FileAttribute
StandardModuleAttribute
HideModuleNameAttribute
DefaultValueAttribute
DebuggerHiddenAttribute
MyGroupCollectionAttribute
FlagsAttribute
CompilationRelaxationsAttribute
HandleProcessCorruptedStateExceptionsAttribute
ReliabilityContractAttribute
ParamArrayAttribute
RuntimeCompatibilityAttribute
SuppressUnmanagedCodeSecurityAttribute
AccessedThroughPropertyAttribute
set_UseShellExecute
get_Minute
ReadByte
ToByte
get_Value
DeleteValue
GetObjectValue
GetValue
SetValue
GetPropertyValue
Receive
set_KeepAlive
add_AssemblyResolve
Remove
nvroZXMqguqjUXBKNISBqbjenewIURvXL.exe
get_Size
set_Size
get_HashSize
get_KeySize
Deserialize
Initialize
SuppressFinalize
Resize
SizeOf
get_ItemOf
LastIndexOf
get_Jpeg
System.Threading
set_Padding
NewLateBinding
UTF8Encoding
GetEncoding
System.Drawing.Imaging
FromBase64String
ToBase64String
EscapeDataString
UnescapeDataString
DownloadString
GetPrivateProfileString
CompareString
ToString
GetString
Substring
System.Drawing
ToULong
ToLong
get_enableLog
set_enableLog
get_Msg
get_PasswordHash
ComputeHash
get_ExecutablePath
GetFullPath
GetTempPath
GetFolderPath
get_Width
get_Length
SetLength
get_ContentLength
set_ContentLength
GetWindowTextLength
EndsWith
StartsWith
get_Month
PtrToStringUni
AsyncCallback
get_CapsLock
TransformFinalBlock
TransformBlock
get_CanSeek
get_kbok
set_kbok
AllocHGlobal
FreeHGlobal
Marshal
NetworkCredential
Decimal
System.Security.Principal
ConditionalCompareObjectGreaterEqual
ConditionalCompareObjectEqual
ConditionalCompareObjectNotEqual
set_Interval
Rijndael
get_AccountCredentialsModel
set_AccountCredentialsModel
System.Collections.ObjectModel
System.ComponentModel
System.Net.Mail
LateCall
User32.dll
user32.dll
vaultcli.dll
psapi.dll
ntdll.dll
bcrypt.dll
System.Xml
set_IsBodyHtml
set_SecurityProtocol
set_EnableSsl
FileStream
get_BaseStream
GetResponseStream
DeflateStream
get_EndOfStream
CryptoStream
GetRequestStream
MemoryStream
get_LParam
get_WParam
get_Param
get_Item
set_Item
VaultGetItem
get_FileSystem
OperatingSystem
SymmetricAlgorithm
HashAlgorithm
Random
ICryptoTransform
ToBoolean
IsLittleEndian
get_Screen
CopyFromScreen
get_UserToken
set_UserToken
Listen
System.ComponentModel.Design
ChangeClipboardChain
AppDomain
get_CurrentDomain
SeekOrigin
get_OSVersion
get_Version
set_Version
RtlGetVersion
get_version
set_version
Conversion
System.IO.Compression
get_Application
get_Location
SystemInformation
destination
get_AccountConfiguration
set_AccountConfiguration
get_BindingAccountConfiguration
set_BindingAccountConfiguration
MailAccountConfiguration
SmtpAccountConfiguration
System.Globalization
System.Runtime.Serialization
Interaction
System.Reflection
PropertyDataCollection
NameValueCollection
MatchCollection
GroupCollection
KeysCollection
ManagementObjectCollection
AttachmentCollection
KeyCollection
get_disabledByRestriction
set_disabledByRestriction
get_Position
set_Position
get_ContentDisposition
SearchOption
InvalidDataException
CryptographicException
ArgumentOutOfRangeException
ArgumentNullException
InvalidOperationException
SocketException
ArgumentException
get_Description
set_Description
get_StatusDescription
System.Runtime.ConstrainedExecution
Environ
StringComparison
get_CtrlKeyDown
get_ShiftKeyDown
get_AltKeyDown
SocketShutdown
CompareTo
CopyTo
get_Info
ImageCodecInfo
FieldInfo
FileInfo
CultureInfo
FileVersionInfo
GetVersionInfo
SerializationInfo
serializationInfo
ComputerInfo
NumberFormatInfo
get_StartInfo
ProcessStartInfo
GetLastInputInfo
DirectoryInfo
get_CHoo
set_CHoo
Bitmap
get_Year
ToChar
DirectorySeparatorChar
get_avatar
set_avatar
StreamReader
BinaryReader
SHA1CryptoServiceProvider
MD5CryptoServiceProvider
RNGCryptoServiceProvider
TripleDESCryptoServiceProvider
BCryptCloseAlgorithmProvider
BCryptOpenAlgorithmProvider
IFormatProvider
StringBuilder
SpecialFolder
set_Binder
SerializationBinder
GetDecoder
Encoder
SetBuffer
ServicePointManager
ToInteger
ManagementObjectSearcher
SecurityIdentifier
ElapsedEventHandler
ResolveEventHandler
System.CodeDom.Compiler
ToUpper
get_User
set_User
CurrentUser
get_Browser
set_Browser
ConditionalCompareObjectGreater
ToGenericParameter
EncoderParameter
BitConverter
BinaryFormatter
get_Computer
ServerComputer
get_DnsResolver
set_DnsResolver
SetClipboardViewer
ToLower
CreateProjectError
ClearProjectError
SetProjectError
SocketError
get_NumberDecimalSeparator
IEnumerator
ManagementObjectEnumerator
GetEnumerator
Activator
.cctor
Monitor
CreateDecryptor
CreateEncryptor
ReadIntPtr
MidStmtStr
get_Hour
Graphics
System.Diagnostics
get_Bounds
Microsoft.VisualBasic.Devices
get_WebServices
Microsoft.VisualBasic.ApplicationServices
System.Runtime.ExceptionServices
System.Runtime.InteropServices
Microsoft.VisualBasic.CompilerServices
System.Runtime.CompilerServices
Microsoft.VisualBasic.MyServices
GetInstances
get_ChildNodes
Matches
GetDirectories
get_Properties
ExpandEnvironmentVariables
GetFiles
EnumProcessModules
GetModules
NumberStyles
GetSubKeyNames
ReadAllLines
GetProcesses
GetHostAddresses
FileAttributes
SetAttributes
Rfc2898DeriveBytes
ReadAllBytes
GetAddressBytes
GetBytes
get_Values
SocketFlags
Strings
SocketAsyncEventArgs
ElapsedEventArgs
ResolveEventArgs
get_Ticks
ICredentials
get_Credentials
set_Credentials
get_DefaultCredentials
set_UseDefaultCredentials
Equals
CreateParams
VaultEnumerateItems
System.Windows.Forms
Contains
Conversions
System.Text.RegularExpressions
get_IncludeInGlobalOperations
set_IncludeInGlobalOperations
System.Collections
set_MaximumAutomaticRedirections
StringSplitOptions
RegexOptions
get_Groups
get_Chars
GetChars
GetImageEncoders
System.Timers
RuntimeHelpers
get_advancedParameters
set_advancedParameters
EncoderParameters
Operators
ManagementClass
ConditionalCompareObjectLess
FileAccess
get_Success
GetCurrentProcess
IPAddress
get_Address
set_Address
MailAddress
get_IdnAddress
set_IdnAddress
get_objects
set_objects
System.Net.Sockets
get_signaturePresets
set_signaturePresets
get_templatePresets
set_templatePresets
VaultEnumerateVaults
get_Attachments
set_Arguments
get_Exists
arrays
get_Keys
set_Keys
Concat
AppendFormat
ImageFormat
get_NumberFormat
Subtract
AddObject
AndObject
ModObject
DivideObject
ManagementBaseObject
CreateObject
ConcatenateObject
OrObject
XorObject
SubtractObject
GetObject
LeftShiftObject
ManagementObject
NotObject
MultiplyObject
set_Subject
Connect
set_AllowAutoRedirect
Unprotect
LateGet
LateIndexGet
System.Net
LateSet
get_passwordIsSet
set_passwordIsSet
set_AcceptSocket
get_signingEncryptionPreset
set_signingEncryptionPreset
get_Height
get_Lenght
set_Lenght
op_Explicit
WaitForExit
VaultCloseVault
VaultOpenVault
get_Default
IAsyncResult
MsgBoxResult
set_UserAgent
WebClient
SmtpClient
System.Management
XmlElement
Attachment
Environment
XmlDocument
get_Parent
GetParent
get_Current
IPEndPoint
get_LocalEndPoint
get_Count
get_TickCount
GetCharCount
EndAccept
BeginAccept
BCryptDecrypt
BCryptEncrypt
ThreadStart
Convert
get_Port
set_Port
get_InternalServerPort
set_InternalServerPort
get_port
set_port
FtpWebRequest
HttpWebRequest
XmlNodeList
get_Host
set_Host
ICredentialsByHost
get_host
set_host
set_Timeout
GetKeyboardLayout
get_StandardOutput
set_RedirectStandardOutput
MoveNext
System.Text
ReadAllText
AppendAllText
WriteAllText
get_InnerText
GetText
GetWindowText
StreamingContext
streamingContext
context
get_Now
GetForegroundWindow
NativeWindow
set_CreateNoWindow
ToUnicodeEx
GetModuleFileNameEx
RegQueryValueEx
UnhookWindowsHookEx
SetWindowsHookEx
CallNextHookEx
RegOpenKeyEx
LateSetComplex
MsgBox
get_Day
InitializeArray
ToArray
ToCharArray
CopyArray
Consistency
set_Body
get_Key
set_Key
OpenSubKey
RegCloseKey
MapVirtualKey
get_GuidMasterKey
set_GuidMasterKey
ContainsKey
BCryptImportKey
BCryptDestroyKey
RegistryKey
System.Security.Cryptography
get_Assembly
GetExecutingAssembly
get_AddressFamily
Multiply
BlockCopy
System.Runtime.Serialization.Formatters.Binary
get_TotalPhysicalMemory
CreateDirectory
get_Registry
get_Capacity
Quality
op_Equality
op_Inequality
get_priority
set_priority
System.Security
IsNullOrEmpty
BCryptGetProperty
BCryptSetProperty
set_Proxy
IWebProxy
ClipboardProxy
FileSystemProxy
GetProxy
RegistryProxy
<PrivateImplementationDetails>{06AF4B9D-49D8-4F18-A5D1-CD1C16516248}
MyTemplate
14.0.0.0
My.Computer
My.Application
My.User
My.WebServices
4System.Web.Services.Protocols.SoapHttpClientProtocol
Create__Instance__
Dispose__Instance__
WrapNonExceptionThrows
$ef1c7b61-7b9a-437d-bcaf-7fc28b88c078
_CorExeMain
mscoree.dll
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<assemblyIdentity version="1.0.0.0" name="MyApplication.app"/>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v2">
<security>
<requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3">
<requestedExecutionLevel level="asInvoker" uiAccess="false"/>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
!%--314?7B9P=
)(*(+(,
credential
https://api.telegram.org/bot1987848583:AAHSwmprTFpvEybmL0ROJO4AawZ1x9yuNZs/
1120598411
logins
+-0123456789ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz
HTTP/1.1
https://www.theonionrouter.com/dist.torproject.org/torbrowser/9.5.3/tor-win32-0.4.3.6.zip
sha512
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
FileDescription
FileVersion
0.0.0.0
InternalName
nvroZXMqguqjUXBKNISBqbjenewIURvXL.exe
LegalCopyright
OriginalFilename
nvroZXMqguqjUXBKNISBqbjenewIURvXL.exe
ProductVersion
0.0.0.0
Assembly Version
0.0.0.0
Antivirus Signature
Bkav Clean
Lionic Trojan.MSIL.Agensla.i!c
Elastic malicious (high confidence)
DrWeb BackDoor.SpyBotNET.25
MicroWorld-eScan IL:Trojan.MSILZilla.1773
FireEye Generic.mg.6646213e564d27b3
CAT-QuickHeal Trojan.MsilFC.S17872954
McAfee GenericRXMT-NF!6646213E564D
Cylance Unsafe
VIPRE Clean
Sangfor Trojan.Win32.Save.a
K7AntiVirus Clean
BitDefender IL:Trojan.MSILZilla.1773
K7GW Clean
CrowdStrike win/malicious_confidence_100% (W)
BitDefenderTheta Gen:NN.ZemsilF.34110.nm0@a0vtjDe
Cyren W32/Azorult.D.gen!Eldorado
Symantec ML.Attribute.HighConfidence
ESET-NOD32 a variant of MSIL/Spy.Agent.AES
Zoner Clean
TrendMicro-HouseCall Clean
Paloalto generic.ml
ClamAV Win.Packed.Razy-9862812-0
Kaspersky HEUR:Trojan-PSW.MSIL.Agensla.gen
Alibaba Trojan:Win32/thief.ali2000020
NANO-Antivirus Clean
ViRobot Clean
Rising Spyware.AgentTesla!1.CDBE (CLASSIC)
Ad-Aware IL:Trojan.MSILZilla.1773
TACHYON Clean
Emsisoft IL:Trojan.MSILZilla.1773 (B)
Comodo Clean
F-Secure Clean
Baidu Clean
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition BehavesLike.Win32.Generic.dh
CMC Clean
Sophos Mal/Generic-S
Ikarus Trojan-Spy.Keylogger.AgentTesla
GData MSIL.Trojan.PSE.18D6RFG
Jiangmin Clean
MaxSecure Trojan.Malware.300983.susgen
Avira TR/Spy.Gen8
Antiy-AVL Clean
Kingsoft Win32.PSWTroj.Undef.(kcloud)
Gridinsoft Clean
Arcabit Clean
SUPERAntiSpyware Clean
ZoneAlarm Clean
Microsoft PWS:MSIL/DarkStealer!MTB
Cynet Malicious (score: 100)
AhnLab-V3 Infostealer/Win.AgentTesla.R420346
Acronis Clean
VBA32 Trojan.MSIL.AgentTesla
MAX malware (ai score=100)
Malwarebytes Generic.Trojan.Malicious.DDS
Panda Clean
APEX Malicious
Tencent Win32.Trojan.Generic.Wnmk
Yandex Clean
SentinelOne Static AI - Malicious PE
eGambit Unsafe.AI_Score_100%
Fortinet MSIL/Razy.749950!tr
Webroot Clean
AVG Win32:PWSX-gen [Trj]
Cybereason malicious.e564d2
Avast Win32:PWSX-gen [Trj]
No IRMA results available.