Static | ZeroBOX

PE Compile Time

2095-11-11 00:05:43

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
\x018\x00=!39d 0x00002000 0x00005178 0x00005200 7.99144904474
.text 0x00008000 0x0000b3a8 0x0000b400 5.9238542153
.rsrc 0x00014000 0x00001740 0x00001800 5.71983285707
.reloc 0x00016000 0x0000000c 0x00000200 0.0980041756627
0x00018000 0x00000010 0x00000200 0.122275881259

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x00014160 0x000010a8 LANG_NEUTRAL SUBLANG_NEUTRAL dBase IV DBT of @.DBF, block length 4096, next free block index 40, next free block 0, next used block 0
RT_GROUP_ICON 0x00015208 0x00000014 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_VERSION 0x0001521c 0x00000334 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_MANIFEST 0x00015550 0x000001ea LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with CRLF line terminators

Imports

Library mscoree.dll:
0x418000 _CorExeMain

!This program cannot be run in DOS mode.
=!39dxQ
`.rsrc
@.reloc
vJ?]g`Ru
TTncihg1
tr'q,#
m"O^QeY]
v!1D:9
0Ei:>%7n
p&ajFg
h5;l$-
z=4lFV
l5)P)]
P6X\Ynr
'}(,~\1W"
-a)wvR
Qs?f7-
djY)>A
c~\}q
g,U3WFe
U>n`B6&
.Ya-si
YRWahm<%
6BZ5k8
ixsqY
2`_iZc
/z8"sFGi
Pea &x
$xl,V~
G8\+\0
&LCohu
BVa[7$
Bw2q\LxP
t=X8*D
;i?wj/
},sM#@
QhdamR
6k09WC\
_vmS.<
79po9Yf
b*HCZ
dF_a8e
_CorExeMain
mscoree.dll
v4.0.30319
#Strings
#Strings
#Schema
vfadfaikoui.exe
<Module>
WikbxOsPqsHvrBpwXCVCtVBVUCgLLTUK+U=i[dg-F[vz!Syv||?'"
mscorlib
Assembly
System.Reflection
cmQvMLXEBcMAgsiHMjYPBJzYVdIqAsz6~^+\%gbeO3ZXpdR'*x 8l%
.cctor
CiUTwxCHbJCMnLBGVaZZQSqfevaiPxHh"'Sybjc\8h\"<d}Su=mG
OAleeQAlcSCFhfVSIDhatwXLOKyq%awwhr_G-F*I6#4YaSo'0H/d"
vGFKalhJNUdMjroOUJisZLZamgKPCC:Ki!oDv@GI=60s>{b2;] N&
VirtualProtect
kernel32.dll
ssGrmzbaYuqAVfAmyXZGeFMJOovG,g\SGM-isG%;O#i0BIM#-#el
QlFOajNrmmummRCrDEbrboCtoiwWAj"|;C/\ymU }~Y)YRe&>m67 1
System
RuntimeTypeHandle
ANvDZrFhVLatTqCcmfXfYRDthsWX-oWDydc:<I%3z{$jQH2:W*4`!
wjChzYuTVqBcjtpZgafQKRFDkQInE(%m)_ZT/EkAelKk'nXX!D)="
MethodInfo
ptqQSPNGmsJnmlhSmxrkcgCphgOg]-qLJV0N{+SW=I_;e,*=Oc`L!
tATayTdqaKlizmkEgyTOSnIushHT[&+u\ :Wxo7(oJiNpj#-?o41"
MethodBase
hdlkMIlzPYPQcxEhqyolDvxHMFCfCk11n9X)!n5I@];q90j766!?"
dTmngGmxaLCYkfXWiMnnYhAegbrx,nK,J$9SjT{LE'G%UE%t=, w/
RFEoqAyzNuVsYeaLUXxqPsRVibodb$u{ig6hiQ"E\bT}uM8WyA'
Thread
System.Threading
ParameterizedThreadStart
acQuOEheVSnzacInqVHcZsiClrRm Sph`4ehN$iy/kEV99~wTe!h"
kqupdDhPdrAHLRRlNiwAFPKWudtNA1(o16:Ca5`tIl{@oLvxbp,X}%
RgxzRbTvSSxVtkwuBlprJCPUjaNDpY(k7j)9\c/&e,PySi8)4Y:^"
oLBYRCUUCicAvcIVWoNWGfpWsdwE%H'C!'`G')c4b#1xZc_;Sa6
XjftRGhlyiYfZRgLnmfzilacDPTKn8Q]LM^eK!ht[VCK]G<c/h)b!
qllhYKKvollIjZpZNBAhCpEBEUKOAM*7v0)csyp )40|8 dCBL<L2$
GsJmAjbHOwRMOtuNleoZTLSUeQaJATl<<SWa~]tLHm^9]`$^<@h:s#
cLPnpCgLhBltFsjcWGNZmzNeFbwW9eRiX!"qrM!6,CX>ZRSV1"ew4
kHupSwDmBVfbkIXiyNAMbgqJIJPO]S_Oeh*LlW}#`?"d%c;S^+"h"
JkYNkmOdUqcrFuNVEcAVnlvSxmkm)^L|aBJm";^53j'}Fe%/`M1q!
PckmzSiSbPQgYKBkYEKvqclNGKJCA`MUu4;N j\!(z=:R 1,3>2Xz)
TNDaJOiaNRVINoLWphZEFRRvUUXM!6j>4{!'|-vf3p;'7j2+])4t(
DbTNSQttAaiZvhJqwCvFEtKpguQH>L^L:*1JA}17SOsFRRX)Asf1"
XQquEVubNoyLuTvSfCiOufrjGVwC<Q5yz,5F/?}^_{W0rI&KIBU$!
MPfpjipGCQwVRXsjTKjrdXAAtzYr`'Q]=5yVzh66-UrWe}sXH9p~"
Module
XGyRgVigZDMQdsKDxpuoauznBmChh=&R%;8>V#uu36A;/XYM L+L"
wdDROSICJPNrxKePFeXUYQbIeeUBAm7RhH4njHiSI%Fltq#V(r"r\#
MNHUEwnHiwNvogMeSGiCBXiWzyLV~_4n$; Me3,QwsvMONTCtJy--
vKqKcqvOeNDIdbqLBBIgAfXjaVtubkGOc/)US<'&(OhpH\gW@q-4S&
vthqTLDxBKBLrNzsqFCyrQpicCYHoC*k6Vv!j`M0|s_L{PS9o{DD#
lzcZJPctAboGOPWkyUAKFkmGQzL?u@hAty:wV92LYktH^]c+8(%
WHQAFLmhjNSbKwvGHdUyXxcWexCETD)`ls9RBh~Ao*`E[:)E:A`d
KWTwBmwmbzMwdCApGHUEFBBDkjrF^DEE=y5Ms';xxZ^N4@()'wU>!
ResolveEventArgs
dzwayviHrVmcyFZYHJNCWTSgVoTqmd/UEHxWlmQ=>vvVd^`2em2h!
bgmUesaMOFJTdVSMZezeHoLUUtJj9vu23[<^'^O|qb@&("V+L'83"
BbDwXTkGeMnRmFYQFtaYeJKKdeqAAbn%PT5oEBJ[zX#<=&2;LX_Ls'
ValueType
JbdZJwnitHTxgojXyDCqbavsFfRd-T `A[Of%@QMIhsnum9{=\^B
aPnxhIRJCPMRYSoVPYJLYkCczCyRM=Cs>;X'#jzY`8r`/vTfC`zS#
WVEElPPyMbMnGVlJwUzdOcPxdAJl0!4V>T&riNT@:|&p;o%x[uhc"
HGGtkmIsYmefJXymmMBROzStnzOj-XRE[+)z?Ev-l=ejM:J@;KAT'
PxQlpdykZzBuhQYqGPInDVcONect:r@?}[B\AIiFnwJ# X`&fQAe$
xsoRPBcwIdcdsIhkyPXrcxZLwilGc,ctRGS>k?I!G]=^W&bN8&S?!
INVqSSdCuwPoMLFkhOzmnpyIXoMhza%ct=43G%~z0C*'1_kKvH@L"
XaiBamCuqfbSNEOstonVNizSakBj)pc';vC@&Ctfg/Aw<-%,hk0U!
gbtblFayRMOIFPawQGtTuVSsMWOtA?J3A)JE`RLfdYUn"=!6)q7~|+
HOTPfhUEJThvTCvcdhynQgrDUIZAA6D^5M)DhV[R0OqSwLeuqP6aB%
FiGDkMbZgYMHUhFhSgTIdeSHtdcxBnn|/2C>&X~L!:iLDep <(UBW%
Object
naUPrsKPqTpoukNjgGNZBvpDrMKL]-p!9Rc5d"c[buaZ`[!glQh8"
BHolSReebFQMIFrSySsWytLrpMOJ0[us83KcHjJVLn3B|?HpUcDH!
XyfaurdRdgMPoAmdKnYztRivDDeJb-dk]?=B1sd3weU{2?(j[B^!5(
Stream
System.IO
EauFMlSWEUbQGRUoKdDrhAMchGefFiO>u%zWF]-p|FrC3wA\$M/p
fNLDjNHILuoUIpzeLoPeqDmibaJDA7oD,6+o^;^t}'5:@mGusW[^L"
zDiXjLxltfizxtSqXhsIYMNpgJEBAe0mmV8o$eA'(iy~6C<:P7WfR?
KjwdPFsuWWdxwYEAnEKVHBPUHNfSA#pgdn@,^)[q_221HJp'hXLYi%
FIPCzcKXDFCaPGOyzaKsWXVfSOQB<R+jYLHHO#~->Sk$Tf0m}RZ=
NcPdtlOELJhNSJwswGdwPKZcAEdM0(DOI^yd4VRNZW(WgV+R(<5R"
LssrbnZHxbyfGZKTQhNFTHyhCRGIA2H;,i8'UoqzA%6^Pc6F=A#(\%
AsigcdCickwmrJjKUGjPgSrbiGiRbT8i/IZOM1MCm16:Q+Xx7wZC9&
atiHpvRRSjkHdOaatsuaAQvZPLSGqg5^Oz%D"M&8hI(UEFUyD\'2!
xvixpWKfcUPbsoNQrOjkrKnapkER;&}ypJv1f?KV5DuADkGgcOj+#
KRqCEJjUXjYQqwvIwEHgcgenLBHRAJy&bRFhNwlkt?\3L3sKKA2!J'
QTquevszrCCcyPiSRkIyDwFAlQBAh)U/~C&[l;dw"'":v7Y%%Y~(
esNZiMllkYnixEStbWpcUGaKByqES<9Nxq&"~E$D)6Y6uTV:fLI=!
kPQyZCFjrVLgWBPqBwXOTdfmCzhma=T~BCj_t(4hvYlUJm']kK=L"
dghPfTmLBMqlaWRlYehgeykAuJrVA{{E_>%{Jzq&|2G8_"CE7hl3[&
wCYXPMgGKeEFWwLLvUoUwdWPbuVL&VVTb;)cK`lA_6*pn9,LdgZF"
YyyDEtmhiuFXcKUoDdoqbFcxEEHhZMKX E,R?X}TXjNwo_XqOXrF
HPbkpSKTkKByWzHemdgXruJWSAcq#M[Y|fW=#qH@eu13hy=ZT:3,$
EAYiBcLwoqjHDdLSrwgRPAVmEkeqA#BZX(WNqcjB>Flm/TJ6PY11/+
rKSvZSlXXygGaCmKxFWRBVYcrFUnASy::r,k-wd#5<![jU<zjEGR2(
zMYwfHEDtzjoGLnBeMejCUWzPttIID'QN:,;ou-^\'A-/M4l1)4C$
ixKfPkhGTvPXerJndgTUzNXbMfhfA7>dn_T!:m%#(BQ9#>VVl*/g*3
dAEeXjEOFzNQAzYoXfyTINvPWuwOMfNdIL<6E\8bvCv3<B89N`gA(
NSQqijXNVUYpGlBgKEQpnOwEDyYC+C)QKL;6x\ru|u~bIcITJdN]
CyjicYaIDizDmXXMttAMemeyLgkMV9=c`']-(xmUXF3@LpkeQwv/#
AmaBQvenuylSeEFhPuQGPQzAYyEeADVAV,L$mw6Kr~oj!BAFaR}A@#
WbJYKFllbEiTnQbuwVbkfAOcAAZHAv,zVZ@W_~d K#KY"KU"\5c4:6
JwcWgzRzxxMqMbsPUQnCwHeJcenhA)'=qYLF7C}1jM2!w70Ks+"~*$
dfprBAvrdLHPTgKGwPhHhepfghbaB[95-d:Y[zZ`1x8/5fle;gGI[$
vcLfWyfVgQnbliJomAmStPIjksibu]w"jYdwF,;*bGpRC[rXT$38
LhAgjeHXyYRyFOmZntqkmIIwvNQWz%v,{z<3HqxaV6KS%7m>(<yL#
WfSxfhmSdeLkzsFmJdYRHRMTKdSSA@2NoO=SCQE5lIIn-Xa|LX,B@#
GhuZePGKKADmfEjlmibSjdLiHrUZz=IN#t+4+:/5zs/$#+(Ng81X)
KAPdNymxQNrvpQIZXWOZytTXogkC'zR];&_9B7/f1#B6zW%}r/w2!
BGxGRScCEUdfXRmggSwxqAEUMfZJAp*]4DbD2Hsr0q}c/JE6^vmhH$
UIrXxEApIcoYJKNpPEzstpmGWJBo06 yPDrha:<E@WrMZQI T+|B'
CUELhANLYSUcemATxDZZUkQatYUp@'!Njjlz<!q$sj{%>z4h[j3H#
WgscOSQhBvRHxTXTnckMCPPwRJmA%$7h86e081'BT\quGn-nZ6V)
IKBIlcMmYSlgMohyHpXAqcqzIaBRRG|QAl-PpQH)y$Nk!Gu(C&Li!
MAFdHGmdHfhpmahPUpmQXrAoAEedb8DH)+,C~(/GR,~6m5D7bk'8M&
ANGpbbGZgoNkUdWXVutczKGLDkWjA4%TWq6~9iO@>$v2i:c*^~59R&
rzFBscHLrLbaugTCcKWKdJTiujqlBK_hIAHymr97#(Jk%tF`R}(%O#
PzrAMBdGBiBoHBoeLHHWatkeLdZRB^B[4V(D4Q{'I;(2)-Ti7Ny!0(
BSUakugBKcJMqKTGczSakwOimNBFAX]+9/Flt[|C)f+?jA${b=|*x$
zZzdySceCpRDVIagimPaZClbyVTzY#S[4ZqD"p!\}Q3D[\)o})>V#
qGdfSROOvuRxTiUlEISLKLLGresJu5"K|zgs5-'/bozhnHX+x /<"
QksiPCeNTuDbTzdywGAiLTyudXQOj9k3NoPpiT< 3/I)$?~UY&n6(
BazIDcbkJsCUaENvfzEsEKVBjsCqdHA1Bw`])Qh%?)w[7D5'`/U,1=
ePUdYvivwxZeisOyiWraBTnkYntQ(wdVEHsm=3E_B*3KC/`7S j$%
GjlWDyaQBtSurIhsQTvRgKLICflw^wi'q7k~,_" '7rKa>CFp;"Q%
DAPXmIUPFNDMyTvzXaqrjEFECyypAz+|(PB^<LzO`~?>I[ar:^Or"%
wLUwVzBnRPAQQLJATaQcAoplLrOwAgzHB{3r\4|hz:vTBSh1&uW6a"
yGRxdcRHESsfHyjPAstepQqAERrY"4L7A=)Pv312['4M-,}mVc2G(
rDvIAJJJPaSrObGpGSVOLVsIysGiA[E(P#e|^mM!YV ^<:EP}-GB'%
LMNvDCckCXMTXpPZgKjjoCtIBLvV\{0BV,m'4ZhSwH(R=3W 'JNu'
enaXHBPdMQhFMzTzXnXChGUdGUzgACvoxJN-fBP^ga_Hj0@=t <:9#
OFBjUFmjFLZdGcGyReqvIxypUgRAA+BR^4_T<DA8@3G:g:59ew{v2%
RovOZwdpzxbYilbGvqCbUvSnuPEi~ZAPuMRqMg1uvL}i1P+~WG6I!
MnchSDbpXFrGkoUseQnAgiSNdAsAb:3g`z`3B-X'[^O}?sf?Lhba $
VHPfRqHlagFTzexvuYodjvpOrckaAzh+r9~@;1'U\mI/a=#ym8k2M$
uJLCszlWbtjLEQDLbbEKMnakEDVIAY1<Dk n {o>1V6[P)Y0uUJX6#
xPtpjUvJeDYCKROgsFCScbInTKuJAu'm=N9MI:zVsN,YzF5Q6}\:=$
iaZIpLHufioQhuEdyEAnJOZsxzjqAu;N}L-L73BIHC&[pa2LPyoW(#
APKTkAOuQVpZfuDLdUBXahzshzrf~c0)ZT?tv;/e@yQZN( @]9gO
dYFNJjVJJEfEZavigHJsUWZXHXqSI2r^e!-V6PZ%7}9>\C@l|f)3'
cPDblPXNdplYJtqJfleGfnqINDsgO)xU^B`95mh}?t"]B=cYv+YS
wolORZfYSlpoVDVvCqWLddlUhCmHA5&(xn6W|}I!P`"8\J|7=`!Rm,
weRkiAogzsGzRGTRwpGkwKwCIGNfA[@|U0!u9s$)^f<G<-"@sRO%l,
wImKYODgUfQMfyzCIJMlkgLyVkynYEG'n&-pAz*} 8fv$I1d91}e&
cSxtszMwmvcZooMlzylVTEBPEEveAg(5wb1SkAcStZQK[vJTX\yZ!
HeuKHbUjIrtQBWQDcQmjOdUQvoBV>@WdC$)rmDn^~^&{DwNfhySN'
uoNHtPnczpaHjFkYJMvyeiMNixqxW6trl&aA"Tg-6)<ekN1Td&$ $
BnHbwtVmGVasMLShyjwGBDzhAWOyAPWz=1BR#>U@|%/5EA@zO3f(Z&
ghzmLcawFOqSbuikdDyDIJGWHSWCAC`[\}9aln6a@QE7]V`x-Rr;j$
WzJbAhghCoLHQaxyAzwNtrqUPpdcv|],J31{npNkg4%_oY{vKj_5
gIXyfFjEEpeViFsyjwIkFqVEhbbMAq5b*FH,TsLI*I*_^A**%44s5'
CCiUqvYUlfHmBwlNujeewBYPBajK+kX%y`rC{l\}GMI,,}$z`Fk{
SioOOCsZBwLEHnEFISGIKVhOGFitP~Ib) 7@uZNhGl'%d\!aPpoq$
WcmhaaDRVpfVZwCinXhavSPhsnsu^ 9e")X) B6fwQC5]kef$Q}1"
llhbIzkwswPpXOmYkuThkQLYRBJQoO7`QOpA}cZT8h/h&c D#z!p$
EbNWutaPsyYLWtoIlrIDywWRYHPg@LR>_1=992hCcjs?8=YH~|`="
ShellExecute
shell32.dll
kQNLSKVWKUlCiCtwIBNiEMRLOEEV{jn%d^Tl-6S+'ejx*gB<fP8T'
XzfbSVoRDDaACoqhdrnUBUdMHzarX_368klt%6N?\*7U!D[9~Y9[!
EqXwrvjlLWqeoscHEZrVhoNhAdzSB 4SMLA^0s5" `2a@zSZiM2E'
Encoding
System.Text
TMYesYetlKeQMWIvuujkwUqLnLcBb)tvY4Le?>zZ;@=EYX=X7L(b5*
GFoZrSqAZrBtyAIkLxFjvUJQxAMw>OI]F?=0$m!?FY!+x&CFTH~~*
soHFPZyOfqNVxBSioAdDkpepORKG7>V-|CRSWFcLO5 P^Ne"/)\V"
SZAVoNgOoqrjmxEhmiEoDCwXpCEhb0+0gbDII=$!m/s=LL}hW\Fcf"
jTJAnCAVWLIuZfdUEtEtfiovLotvAq^J_HB6>Z9LsohLN}b$$*7!E#
WebRequest
System.Net
yYoJAKIyPDJoOIMGTxlFdGTSSawIgf3Pr)W4Dv>#\\87l1A2dBA$"
WebResponse
udXjYMFnyGCWeSaKmPaWBCOsjmwYA,EbvFcY$<8uAO09"6`NNEG4?'
exsXMexqchToVVLQETAvfHqtFaOiAqE"d$Ee cc!8tNJJMU(a3o)|'
HttpWebResponse
VFyenHiqSsRdfeZtoLuUeKKDiwSvAFlu$:P*J9Q?7#{$uA`^p|[-)&
brtWuGnfiVuIMBckUcIeIFtkkCsjbE!_$6M{q!4#~)Kb8LW~3K60,1
StreamReader
xFlXWhNGTEDeiySUcnjZiMNsYSBv7,E'kL*%+}=Skf,mP{k\Wfjr!
oJlkWRRBSsFGOKdFHpjHRKDLjBnuM1Ek2<"#[xv_HH'10)Zt^)'&&
rldcapZhmjlxTuqIZdKaNRCufsUhYBQUq<9smOJ7voVoMD2;_eHD
TextReader
APKgiKrKwHFLybKOzVfcRDhCHaSKA+0+1-gE*FXiaA:w]<i)y<'":1
mGyDKxgExXvPCZJvZfbfbOIzDmgCgCbj95-aL{tjl,\Co/;Ho%m_
cvrAcjezdveCLUjjpYVfcOkYdzuASE|4C{EgG|H^=I<pl]toa^q'
UDfjiVmsXSEQmcUEkYZXOFtWZMhNbE=KV^Q6`>" xr,FDj8}x2#])
fpVWKRsATqdEAPeIOPEpojAnDfThM0?0!gt>iG!>!EF'[ M?k)~d"
NAtplBRGIyihlkbKGNnGcVSNUiGqfhk[t\M4[/]%3'jAzywBzg^="
Random
DOlEEHEXxoiOqbVdLpxataylHkzAAf41#VT:?*Xon@C%Y#O5{uS^A%
UZVIDBaiUtQnqJCiKpBSnkwVdIKRDXF\4?L+3AOZpg|PDJ7Kt%G8#
FileStream
FileMode
FileAccess
OEJePeZNhVKpKvBVBeTQxnuArDYq^3Z*Q<Q,+fj;1:F64N=[d0M@'
KQxQidArTbTGgTPnaBBYUALSSjYtPFoK7/B)g6$1LYAfZ@4jzS&D-
IDisposable
ZyYjwGqHSkEIJxpAnADWCynClorwAhA`5ZK##Avh]/\,-TN*3zcXK$
System.Windows.Forms
iQFawkTNSmKGvTkvHCcVfAfhgmfOU]v?g43:uB;)6Y6HH_e"EoA-"
gmBEkjJEFGSRLbMRWZBWRVtCMQfqYm:?38$BHDlW]:j)<z8IhD{M"
vGogbZVPFNRPBRTBRUKUGbxBkCgXY%3,x\OlLPdMh:N-"R<"JBI&'
PSnwlkHuUZHVhJgUgkBVAQVdDKLh0CW7=hGhH<9`yh_Sj^ zuTX&!
EventArgs
OnLoad
RCPiQEKcvhAjvIkAIvSKsvjAFAXyA)!JLr(+AUW,#CHR8R@?YJ9vl&
YbolHrjELSEXgFKFmqobsbcDbCwiARi,EOkE0B@"~dliW"?u_N6uQ"
iwuAnFeFKWHbsCjIRWoRYHgTdLQibYa_i\C)6HQ-OKzBYiPhm< B~/
MdqrfIyCWTWIPDcAqIwOkMwLozAf^9uajkVGR`nh3JWpreKQFC)C!
XaVNdzPBtqzStbwzxOdyCQHUEhYdAhuNeGtQ"]+]NK*Gw ;:Vr=Qn*
JWChcRGTDPeBdlrGFovcbWUdjsIcBd=h}taf0HH,4&H>3u5!8*"MJ,
RJPNkbpGGYEVFqwxoFiPADhXztjoA-!'YA0gHL<dQWOQQF66_T/WY#
Process
System.Diagnostics
cjHNNNHDwRTYnyMuhBEFpYoBaoZT9 v<8&2Ixn"5QGw|@^c1N,k%#
TTyLJkLmFaZINHGZbBRBBXkaWxpZNn$-"#>L=lXy>t/z06:}(?w"$
Control
lJniqzmrKgwPueFgebCEDCRNHwbNAc(EuS&YLu\&}q3o8Dj^Lrc>s"
CuGHhgPgXvJgNGQyPcKUrFPJOhLO-5bIM6`R5":4+iNX-vY\VG,F%
HcpSdfMvKaeSIFuughDUpcEMOXav0S/7",j>3>d\8Q9pKRWLD#_u&
UGTdsVZZHADanMxDhtePjglkXUhu%Kd5RV88#KQT'#/YX9QM9hR5#
TWTYcBfMgFPfxYUEfYocDukYZObKv)6z\wWUVP/$zbqpoD`C|b'M#
zCzhMShOvCJFbcqgfRDjcPEsRtZfBaDQhpT< 4P3=/YB60K8'!bOf>
uLaqzlnSbDtyZRbQaKYsHdUPgCpH;XA}$ENA%WT#w`}6ybhhrU9h
gYifkOVNYgBgocEdxPankaHWKxvGbI{{}ZT*bMkiIro}YcG}~pggQ"
xmDcsUWGelcQiCdgjnMKmxsLqsViA3Q:/Bd-mGVW<yc[hJu9sLyh*"
EfbHKYjinWeCWOKHZJyQFYqANvAxB!GU:2WOCV~b5x0>,[%PE-eXT%
ZBaFXkhQMwlhzAawzElRgipdAIDuAFbAtI]:p1}3/HM]Q\15MkbG`$
aTXAorKIkJyRVfyWWLmdYVblaAodAdKZ;N#<Y=rg/Hv-y<%\5$$y
VmUgoYPnpHAcLMkQglGvwqKosSuqb+@=~hEqr$x5#)Aj*,YXu/d{)
uIcTRjYmrsjhmxnkHRWZLXuicldf[Z}TK*8o5K 5$Ct%RJd9=&hs"
DCnbfHyumwBIQAeXgSzTyJByGHZGAxK&5#I9sIHDTW~eK5'cn"pST&
yPjdzJDDEQurbHyMrbKEYOnhuDWV(UOCDl9@</7a:RGr*6~g[ PD-
MrXCihCTQTlqmepIeqBspKryCiORAxx6*eD2fn1&r3# h$udaq[PX'
WQGAxstJKYAftdtaRfBsLpWVPEPGAn[D?YAI+xoe~e(V-1=mHL67Z#
aPVNjAJzDOPLxhIMAWrEGFuGbmav$ypDh::z@n/E|86Nh<p7V?wz!
HttpWebRequest
JqTMiXVnQpQLugbZdscHrvnXnGnVFj%ez%)hUx}}*z{UX(G=D+B %
oMmAqRmzCzNOLArgbqpARRERTufRk4Q;8IA2 h4EB9s[\V~z0(],#
zDnuBdsmGueOSGlEHxpmiRXBbLes3Uixi0*PKT0!!j^9NqcTD0KE&
MFlbPYKajSqMWilDmEQPwChusDQVjI?d86k/L:F*Fd_8bD*Uyd1'%
DrhMGgQijeayPCkqyPFYfjgBLKPlzHc8;@)QQ1~6{5/'l=Bo#++]!
WebClient
petCpiAjqTTmKVviKpqKYCLVnUaEbYj,cSB["#gHX/ R9wB4-`(JO-
IROAQZstbqGbrtVKKPtLNzamtdWL4:V\zy35{C7Qgh:Dv)|Yy; #%
OxQUOhtYVQxyjbnTyFtkaPpPEnDI^"V%Wk5Z>/o[$f/t3[Qc~d6h&
vjnqBwaBUSkDwxUvjlmgupxWcYNsI>&h?+S2tH*r9g&5qgg=!N6)"
FHojPZssDaXvDOeiJEhAzjIkdnKMj6c5'*VpsBLja/4Nt+EJM900#
qVRhSsBNOneiuGOMCSheMUgiVaAU(7D+"R^z,[oDJzz mWh(US<\#
n#V@Xaf3}QQX("v=st=taOmJ!
Attribute
@YsK+nN"E"vDtbw:;^*Z]t/k"
JO!|y?b^1CesDjGP+"Tu|_$i$
j{Q]t8$uD+ML[@CRWx1 $da$'
?:E@&s7- ZBqSjq-Tr[H,2X
"$\/h50{M0cuM(LK=@exZT?F#
m@:%g^|6*x[o2h>wk]`t[n B#
\!~J+8-~i)<{r5Ia6('uu*G3!
>xkpk#6&w]b$|kPFYrC\sr6>!
do0Q~%WOoDr;$rM$=FF %KC[
24q9bp"r~\Ja"^:?*Cr&tnZB"
Mxj*]3oT/Yj*~?p=tX!-}hO(%
x?$t|=Yn%l2cc)2}b*viA-C!*
(S\G93[CT_P?s>%&7Zk?3 aC(
vfadfaikoui
CompilationRelaxationsAttribute
System.Runtime.CompilerServices
RuntimeCompatibilityAttribute
DebuggableAttribute
DebuggingModes
AssemblyTitleAttribute
AssemblyDescriptionAttribute
AssemblyConfigurationAttribute
AssemblyCompanyAttribute
AssemblyProductAttribute
AssemblyCopyrightAttribute
AssemblyTrademarkAttribute
ComVisibleAttribute
System.Runtime.InteropServices
AssemblyFileVersionAttribute
TargetFrameworkAttribute
System.Runtime.Versioning
STAThreadAttribute
Environment
String
IntPtr
op_Explicit
UInt32
GetTypeFromHandle
GetMethod
Concat
Invoke
Equals
FailFast
set_IsBackground
get_CurrentThread
Debugger
get_IsAttached
IsLogging
get_IsAlive
get_Module
Marshal
GetHINSTANCE
get_FullyQualifiedName
get_Chars
MemoryStream
ReadByte
get_Length
RuntimeHelpers
InitializeArray
RuntimeFieldHandle
AppDomain
get_CurrentDomain
ResolveEventHandler
add_AssemblyResolve
get_FullName
get_Name
op_Equality
Buffer
BlockCopy
ToString
Replace
Combine
Exception
get_UTF8
Convert
FromBase64String
GetString
Create
GetResponse
GetResponseStream
get_CharacterSet
IsNullOrWhiteSpace
GetEncoding
ReadToEnd
op_Inequality
ExpandEnvironmentVariables
Dispose
GetType
GetCurrentProcess
set_Visible
set_ShowInTaskbar
set_Opacity
Registry
Microsoft.Win32
GetValue
set_UserAgent
SetValue
DownloadData
Application
EnableVisualStyles
SetCompatibleTextRenderingDefault
WrapNonExceptionThrows
vfadfaikoui
1.1.2.1
.NETFramework,Version=v4.0
FrameworkDisplayName
.NET Framework 4
555>444
zzz@777<
9zzzB%%%
)))S~~~
~~~k|||
|||lRRR
M i|||i
}}}!sss
mmmjDDD2
""""~~~
AAAzcccx
o444g~~~lRRR
&&&K666:vvvB
~~~E,,,
{{{RPPP9
wwwSjjj
444lHHHl
8sss;jjj
pppF}}}
555?555
vzzz
bbb{NNNg
^^^!rrr
vvvz@@@{
{{{o{{{
{{{B|||B}}}
<www=)))t
aaahaaa
XXXtccch
LLLiNNN
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<assemblyIdentity version="1.0.0.0" name="MyApplication.app"/>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v2">
<security>
<requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3">
<requestedExecutionLevel level="asInvoker" uiAccess="false"/>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
GetEnvironmentVariable
_ENABLE_PROFILING
?usSystem.DecodingernaSystem.Decodingme=
System.Decoding
%USRCARCAERPRCARCAROFRCARCAILE%
ApRCApDRCAata\RoaRCAming
FAASD.FAASDscFAASDr
oencpeencn
NikeAdidaseVhLTm5Ba2ZKbNikeAdidasGk3TThNTjNaazIweHNikeAdidasBlZFQ4eTQyNNikeAdidasEg=
NikeAdidas
alLFDJJ32sasd2aHR0cHMlLFDJJ32sasd2a6Ly9pcGxvZ2dlcilLFDJJ32sasd2a5vcmcvMWFCaGlLFDJJ32sasd2aQ3
lLFDJJ32sasd2a
aHjkJFKDASLO321sR0cHM6LjkJFKDASLO321sy9pcGxvZ2dlcjkJFKDASLO321si5vcmcvMWFOaGQjkJFKDASLO321s3
jkJFKDASLO321s
aHEncodeGetUTF8R0cHM6Ly9nEncodeGetUTF8dWlkZXJldmlld3EncodeGetUTF8MuYmFyLw=EncodeGetUTF8=
EncodeGetUTF8
aEncodeGetUTF8HR0cHM6Ly9hdXEncodeGetUTF8RvLXJlcGFpci1EncodeGetUTF8zb2x1dGlvbnMuYmFyLwEncodeGetUTF8==
aHEncodeGetUTF8R0cHM6EncodeGetUTF8Ly9vbmVwcmVtaXVtc3RvEncodeGetUTF8cmUuYmFyLw=EncodeGetUTF8=
aHEncodeGetUTF8R0cHM6Ly9wcmVtaXVtLXMwZnR3EncodeGetUTF8YXIzODc1LmJhci8EncodeGetUTF8=
p9_GlobalString1
GlobalString
p9_GlobalString2
p9_GlobalString3
p9_GlobalString4
p9_GlobalString5
p9_GlobalString6
p9_GlobalString7
SystemInitHKSystemInitEY_CURSystemInitRENT_SystemInitUSER\SofSystemInittware\BSystemInitrowserSystemInitDeat\BrowsSystemIniterOfSystemInitDea
SystemInit
W09/22
CSystemInit:\ProSystemInitgram FilSystemInites (x8SystemInit6)\BrSystemInitowseSystemInitrDeat\BrSystemInitowserOSystemInitfDea\chrSystemInitom.eSystemInitxe
10OUTPUT-ONLINEPNGTOOLS(
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
Comments
vfadfaikoui
CompanyName
vfadfaikoui
FileDescription
vfadfaikoui
FileVersion
1.1.2.1
InternalName
vfadfaikoui.exe
LegalCopyright
LegalTrademarks
OriginalFilename
vfadfaikoui.exe
ProductName
vfadfaikoui
ProductVersion
1.1.2.1
Assembly Version
1.1.2.1
Antivirus Signature
Bkav Clean
Lionic Trojan.Win32.Bulz.4!c
Elastic malicious (high confidence)
MicroWorld-eScan Gen:Variant.Bulz.744158
FireEye Generic.mg.ecb887b80ecdd78f
CAT-QuickHeal Clean
ALYac Gen:Variant.Bulz.744158
Malwarebytes Clean
VIPRE Clean
Sangfor Suspicious.Win32.Save.a
K7AntiVirus Clean
BitDefender Gen:Variant.Bulz.744158
K7GW Clean
Cybereason malicious.55c949
BitDefenderTheta Gen:NN.ZemsilF.34170.eu0@aCowjj
Cyren Clean
Symantec ML.Attribute.HighConfidence
ESET-NOD32 a variant of MSIL/TrojanDownloader.Agent_AGen.L
Baidu Clean
APEX Malicious
Paloalto generic.ml
ClamAV Clean
Kaspersky UDS:Trojan-PSW.MSIL.Reline.gen
Alibaba Clean
NANO-Antivirus Clean
ViRobot Clean
Tencent Clean
Ad-Aware Gen:Variant.Bulz.744158
TACHYON Clean
Sophos Mal/Generic-S
Comodo Clean
F-Secure Clean
DrWeb Clean
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition BehavesLike.Win32.Generic.lh
CMC Clean
Emsisoft Gen:Variant.Bulz.744158 (B)
Ikarus Clean
GData Win32.Trojan.Ilgergop.808OIX
Jiangmin Clean
Webroot W32.Infostealer.Redline
Avira Clean
Antiy-AVL Clean
Kingsoft Win32.PSWTroj.Undef.(kcloud)
Gridinsoft Trojan.Heur!.03011281
Arcabit Clean
SUPERAntiSpyware Clean
ZoneAlarm Clean
Microsoft TrojanSpy:MSIL/Redline.STA
Cynet Clean
AhnLab-V3 Clean
Acronis Clean
VBA32 CIL.StupidPInvoker-1.Heur
MAX malware (ai score=87)
Panda Trj/GdSda.A
Zoner Clean
TrendMicro-HouseCall HackTool.MSIL.REDLINE.USMANIM21
Rising Clean
Yandex Clean
SentinelOne Static AI - Malicious PE
MaxSecure Clean
Fortinet PossibleThreat
AVG FileRepMalware
Avast FileRepMalware
CrowdStrike win/malicious_confidence_90% (W)
No IRMA results available.