Static | ZeroBOX

PE Compile Time

2021-10-19 16:42:02

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x0005d384 0x0005d400 6.38601439705
.rsrc 0x00060000 0x00006af6 0x00006c00 6.82356668121
.reloc 0x00068000 0x0000000c 0x00000200 0.101910425663

Resources

Name Offset Size Language Sub-language File type
PNG 0x00060450 0x00004101 LANG_TATAR SUBLANG_NEUTRAL PNG image data, 256 x 64, 8-bit/color RGBA, non-interlaced
RT_ICON 0x00066134 0x00000330 LANG_TATAR SUBLANG_NEUTRAL data
RT_ICON 0x00066134 0x00000330 LANG_TATAR SUBLANG_NEUTRAL data
RT_ICON 0x00066134 0x00000330 LANG_TATAR SUBLANG_NEUTRAL data
RT_ICON 0x00066134 0x00000330 LANG_TATAR SUBLANG_NEUTRAL data
RT_ICON 0x00066134 0x00000330 LANG_TATAR SUBLANG_NEUTRAL data
RT_ICON 0x00066134 0x00000330 LANG_TATAR SUBLANG_NEUTRAL data
RT_ICON 0x00066134 0x00000330 LANG_TATAR SUBLANG_NEUTRAL data
RT_ICON 0x00066134 0x00000330 LANG_TATAR SUBLANG_NEUTRAL data
RT_ICON 0x00066134 0x00000330 LANG_TATAR SUBLANG_NEUTRAL data
RT_ICON 0x00066134 0x00000330 LANG_TATAR SUBLANG_NEUTRAL data
RT_ICON 0x00066134 0x00000330 LANG_TATAR SUBLANG_NEUTRAL data
RT_ICON 0x00066134 0x00000330 LANG_TATAR SUBLANG_NEUTRAL data
RT_DIALOG 0x00066464 0x00000076 LANG_TATAR SUBLANG_NEUTRAL data
RT_STRING 0x000664dc 0x00000178 LANG_TATAR SUBLANG_NEUTRAL data
RT_GROUP_ICON 0x000666b0 0x0000005a LANG_TATAR SUBLANG_NEUTRAL data
RT_GROUP_ICON 0x000666b0 0x0000005a LANG_TATAR SUBLANG_NEUTRAL data
RT_VERSION 0x0006670c 0x00000200 LANG_TATAR SUBLANG_NEUTRAL data
RT_MANIFEST 0x0006690c 0x000001ea LANG_TATAR SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with CRLF line terminators

Imports

Library mscoree.dll:
0x402000 _CorExeMain

!This program cannot be run in DOS mode.
`.rsrc
@.reloc
Ivan Medvedev
@Z@[(k
U@Z(k
`Q@Y(k
@W@X(k
`P@Y(k
@Z@Z(k
@R@[(k
@M@Y(k
@P@Z(k
@F@[(k
`^@Z(k
}4si@#
4I %4Iai("
@Z@[(k
@Z@X(k
wX}c@#
[XZ_bX
[YZ_bX
[YZ_bX
[XZ_bX
[YZ_bX
[YZ_bX
[XZ_bX
[YZ_bX
#LNU|e
8q@X(k
[YZ_bX
[XZ_bX
[YZ_bX
[YZ_bX
[YZ_bX
[YZ_bX
[XZ_bX
F+ +2p@#
[YZ_bX
[XZ_bX
[YZ_bX
[XZ_bX
[XZ_bX
[YZ_bX
[YZ_bX
[YZ_bX
[YZ_bX
[YZ_bX
^LwA#
[YZ_bX
[XZ_bX
[XZ_bX
#\Tt^1(
[XZ_bX
[XZ_bX
[XZ_bX
[XZ_bX
[YZ_bX
[YZ_bX
[XZ_bX
[YZ_bX
#tM|j%h
#M,]-=+
[YZ_bX
[YZ_bX
[XZ_bX
[XZ_bX
# E%d[8
[YZ_bX
[YZ_bX
[XZ_bX
[XZ_bX
#"pUZG
[XZ_bX
[YZ_bX
Pd@Y(k
[YZ_bX
[YZ_bX
[XZ_bX
[YZ_bX
[XZ_bX
[XZ_bX
`R@Z(k
#gA)'Eu
#(1,rxG
#4oRY~e
[XZ_bX
[YZ_bX
[YZ_bX
[YZ_bX
[YZ_bX
[YZ_bX
[YZ_bX
[YZ_bX
@t:eA#
[YZ_bX
[YZ_bX
[XZ_bX
[XZ_bX
[XXnZ>
#j'1!,.
#B7b^b
]aiXaaX}
vGY#aiefYea
YXXYe}
eYfef}
aieYXe
wR?{^_[
2.O^_[
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
PADPADP
M A"P1Y;S=|
I*X9U7_1w
@-I*X9U7_1w
s1\8[)H$F*D
S<X;I(D&L"$
qY4<{
};T0S!F)K#M
T&G+I!O
xN B!S2^<
b$I+H5T
M D&R0X4T2t
I$6+3R<6=S
?M,6*$H
.@!M+A
Y3W*X7X
O-E'_.
qY0*#Q.?
j,=/&T3\
U82/[7
@,N"!g
F'K%"L
y|:W/!S
X;I(1#J$R?[8I(D
_'6[90/
C.H+Y'K
<Y+J"p
|:<0&T5O
=Y:>_3)@.h
Q2@ '/6T
Z5Y;OQ
_2V+Y\0P.
S82Q"'K)@.
?K*4V>P
Q#B$<)G
7Z8D*l
0Q=U2U
^=<-@"?Q
G*;(X9F$L"S>Z(Z9A%L
Q<W)[\
L!D'G+3
'T9]:
v!L(G*D
2F%W2S*
X9U3P7E!>W
1\8J$G%
wD)M.G&J
j"O+H:[7U
])@"-m
\.O",F%]
b0@.>N#
V<[--m
C1Fg
*G#6DG
0R:J.C'
M D&9(?]
O'9;V2P
N#*I;I%G
B&E-9L
K)A%c2X!.'
_2V5)H$5]
M.\3L*1[
>S=U8\?-L 1Y
2Q#8I$B
a[7U3P
H:[-<O
J)[0I%<L
B&?#B.L#={
&G4\" M)I
fT8Z(3q
3Z4,^9+I!O
5Q2?9?
%W6P2|
N\8[~
o;W5S=
2S?S(;}
<_-BP2Z4r
1S;K/B&E7,@"
E(J)[:c
,A%F,L B
p6[?\.O#A)G
J'U4H*B,&K/K9X4V
WR3_=-?y
U_=U1d
w1R#:7P&.
z8J+=_&C
>+K(Z5
OM!C!O
:[7T1_
@-?\P%I"
}1I&4@
wE&T+G%<J
G+I )Y
_=U;9T0R A-O
tQ2@!%G/0v
o%W6P2Z4
{=P4W%D
`K'E#F
wq66<
M,^?S1Y
R?[2-E
A]?W/i
;,D*hc
5T8Y1_
.A%F$E)K
<\4Z4Y=^
(E!B)H$5]
A3R8Z2\
]1S7.R
\K(Z1V
^.E-!M)
Y+J%J$b
/\=Q)AS7G
1C"D&=M
.C'>9P+B
)D 98N
~8K/L-A
Q=_63_
92P8Rr
"P"C%=*
v0S+@+
!W5])\,7O'
X"?K2'I
"@,N%&J
Y+n$360B/K
Zp6[5V
G_3Q/A
h=Q3Q?h
vK'E#M
v//?K- @
@_;X A-$A/X*8
qY.JK&"&
X5I)[:J(@.h
J+G$L"d
,L$J)D C
+O,T"G
\.O#A(F
D)M.[:M%M
^'W3T/
^3/L=\&D
";X*#O,D f
]?S1O!
#O-;w1\
!S2X:*
Y4J)3
j%I+=S
Z8(t2_5V
f7S0<]
c5Q2:[
$V7U77};V,O
]0N-7t
y,^?M/
\i/B C
"J$\1-
}W;Y+E
]!H&Z7+&S2X:**k
\?%#N,>P
;+H:Q3Q
5&T5U-
2W9V;_<
^/E4-;X0T
]0J)Y6\8
9q7V049V
"F%Q02P8V
H$F*7h
B.L ;x
@!M)A/i
B*>N#G$;*C!
Z7S0@!M/E+m
U8RS!:,N&H
F%W5M''
N<]+6Y!T3F @
[8J*3!G)T9]>#B.;S;
'D6Q75]2t
T9]>L-A#+
=O.>Z0
X5Q.4@+I
<+F"='1\>L
r3^0S!@'1[2h
{<Q+H8T
Z7)J8Y"
6O#-Y'E
0J'3:/6R
9T,'=[7K#M
<X;.i
_87P:Q
G*N)];D
i.@ -7
U4X6Y.`
M:J!-G&M
[01S51d
U2I"Q5@
-L!<R&J
S*8=F,M
O"B.B*;l
O$<L/=B
F!B&4L
U**X!.
9T087Q_''
S>P30?
*"360=:
>)[:L.5H
#M)J.OG%<E
?^2?W7
vW6Z.;N
DH(@.a
n!;V\5
+J7@.K
>2_;N)=
V(:0>B
=?9.U#?EW&A,H
_-M?T%3J
"J$X}
)=Q3W(H
S4V-3^]&56G
X<_,(tx
~419Y+@
u";N#@
A"399A
T.!D*V1*I5*F$1/c
;W5\&Y
X4P)[&7Q
VW%D(9M
4Y7*X9T
XQ97-@$F
/L>N"!=
&K/K.M
\=Q2G%Z
B(8J3A)
e(Z;O# N
E 3A L.1_
9F$V1R)
I H&\1U%P
g5V;Z2\<A
a'+3(=[7K
7V:R'@
JX;X;S=
2S?S(8~
?\.EK)A
S7T&G+I
4A"J$[%:
E!B&;O
W:X.U#H
gC1P6A$J
b!C+;v
R>\*.j
4J&D(5f
S"F%W6Z8=S
NY.7O,H
(Z;Q C-k
^?S''\
W;Y-2g
-M+GQ9W
P!@&1U4a
{=P.:C"=[
N*I;Z6T)G
D%M#U8\?
nL>_-<O!g
*K';+X
D C'0^9
Tg5D%:u
%*H:U.E
F%+5@
u2_5I4D!
_(]'/N;G!2P(p
N*I1:X7
K(@.X5Q2
T/L8F%6Y
*F"A#B.L
S!!1+&G
NY.$A
A!E&P1].?:
Y%V7U*;D
Z#<C(Fl
%H,E&>*
*H D$I-$
Q<X12J
T5]31\8J8::0;T
L.\7H%<M
O+H93I
_"N,D*l
7 B0Q6
_;X#1V
~2L#@2S
s#293'I
&+G%M#e
,S=Y:A
Q)J":Z1L
\.7G%6I
*G#63I
v0]/6F$7P
U-I*T5Y*;>
^3D'U4
]*;O,D
\R A#0S
N#=H<Z%B
Y=^+%3
Y6D/=K
C$-@2+
a'J$1E!<Y
H+Y./@
B$@#M,@
;Y1U5X<5
A+O,N/C!
D#4N+A
J:Z#6M
==T7E$
iY!>L7E#
H)A/%H,>L
W3@ "!F
N"F%G&J(
Q2$K%A"I
V#B(=N
=D&T/0M
!6*\.O
@"F%S2^+<;
dJ.M9E!2R
K;I(:G*
.B >:~
;K/L:[7D%4
e,K$2=N
U-N&6V=@
*<X;E$H
c&L(K[*!
T&#A)=
M 1R A
R/G#Z0
U!R3Y.?@
0T7?Kl
]Q#B$5X
v1]9ZJ
%(D&N f
W3@ "!F
k-6H+S
t=<W%4U
.B&E0@%
X5>]/N
}D#<:E&
p0J*Bw
YH:[-'
_O=\*5X6_.
*H D$I-$
>'C1P5
/R>Z9D
U+3S:A
X<_)H$5V!
=O+H*K'E
3$F4U2
L=\*;L
>@ <=U
V(5I'8O
5Q2?9?
5M)J4U9J
2P8L,A%
-0\>V8~
<Q5E77?5@-k
U9[);u
k-:GJ%><K
V4F!:S*?Q}
+V$EU}
T,,P7F
J6H%5@
e,K$2=N
U-N&6V=@
b%I-N^/
$H,O-L B
Q##3)$I
3;H)?P1N
].>$l
,+'W%D
c%H"+[7J#
)79GQ
v0]5E*#
N#4W%D
<>V.K#
K 1I*B
3Q9M-@$
.3_=U;}
V7!P<X;B
;C#9:T
Q+2B";N
F D'Q0\->9
R@$GW&%C-k
Q<E&T5
\=U5h
\M?^("
;V2G$<(
N#/V&D
^):K90
W%%-'2[
%D],=
F*N-X(=
?G4U3D%:u
m%5M'D
"1Q#<=Z!J
o<Q5L7E"
T9]45K
!-^?M"C
_;I";T+@
]0T-N&"
y9A C1P
\R A'2U;l
Z9K 9N
*F"A,<I
S A'8I
`N*I5A%6V
]&<=S+K"9u
qY*&X*K!0S=j
~8U-=B
vZ$9I4D"
y9A!;8R
8=Q3[5s
D#4N+A
J:Z#6M
==T7E$
;>R0X6p
C-I*Ql
r$V7Q"E
K;I(>I
U9[)1y
J'0S!@
'.L>Y";B'9
hA,H!L
q%W6T#F(],
x?S7TH
]0T30M
f3^:O,I
R1A.9D!
Z4 I-N
wm+F"
,N<S,F.@
I'U4W"+4S+/61/;1
p6Q"\
!B!S18D
u3T0S!/
[9Q?5X<^
.N-_4Z4I U1(
%L"Z74?
G+I ;w
\>V.U/#
:W3F!6I!?sM
0S!6N$E
H+Y.5O
a\>V.U+$/L
]>L,-A
0H*B+Aj
E(L%WZ6C'
]TW$5M
].O#7_U
A L-2E
V:2D%.
H+H:Q=
\.O!C+E
C,H+9V:X N
:G&@"D
n"<P"I
R>\*1l
|:E#<p
955.?]1I
<U6D$4B
P[6R'-
>O".W%E
y?R,<<I
rV$EU
=P4M,37h
=@-I ?=@
:7-0(/2Lf
!9-=4-
O, ;+2-Z
)s#B+E
U9[)49T
I*B&U1-
-L"=T);i
U9[)4a
:V4R+Z&.<8H
E6W1@!O
.?\.K'E
Z8]>LO
z^3W-U
H$:R<z
(E!8=T
X4P)[1S
9]>B#H
I-N2F#
P,H)3X4V8K
O<]'9&
N+C#R:M)
Y=^+:V4Z4b
6+M.N/C!
K(Y8J(:N
2]8[#6R
d#Q0R%%
V:)%7O
@2S5W P
@%4G)F
z<Q4C3O
;Z6JDd
l)D)>K
=\0Q&D
]&?M,!4O
\4X:3F
C"N,%3h
B H"S.
D(9H)6.&/"W)I
D,eB/K(R
)K&B!S2^<
}_5R2]?T7w
[7W7F(>^7Z
V1*I5*F$1/e
SX!=?>q
O"P1]?W9
G,EW8Q
L.F'9 D'KLZ
.+;K)8Q
$G5P<?L
L!?I02N F
R.?K,%<]5Ut
U3N)6I
&-=M0@
\/O$');{
^_;X*,
&S2T%?
x4C)I(2M
T%H,E5
C!I#T3
4&G+G-2n
(K(P =F
?Q-H+S
4O,T$9D
M B =Z
)G+??)`
lN+J#l3_<}
#R=|&I+Z
8N0]1\3v
Y5R#S3`
D#O-E+m
`&:^='
b#N +1A,N
V!8E$?8M#
D).D)F
n!IV"I
}:W-;==<Q(:i
C.J)<=D$;E
[2.?L-;F
?4P3?M
y;V2&*K
|+H(83A
\-@$=M
#?M"=O
P9L)J v
N!C!>e
B$/A"9
n(;7C0Q7/(
=6*:G&D
E0Y8%Q6V
[7P;J,/U>Q
K'W7F(%I"M
!N<]'.p
%S1Y-X05J+9P
R 7G$@
U9<@!e
]1VW(J'b
d#ZA#R
E)N6F(E
=\.O#A)G
P1]5]-A,
H:[6T<R
C.>]/N
`&:^='
2<]1S;U
~L0C#x
*I;I%G
_2L/>a
{M-B!u
qG'L/i
mS1Y7V
-A#A/J)B
J!1=ES
O)G+C!$b2
Z1R A-O'I
pWF"5g
3P"2^:*
L!;X(*<
R1C!(4E
_>W:L"G%
;F)6ls
6Z>]%DL
Z7S0@!M/
#@(F>R6U
A"J$Q8I#;G#
t!<,G$5
Z(I#A)G[6R1&G+I^0v
=N/93,A
R0B#>X
5K"6Z8G
T31'?^2?O
.B&;6G
t2_1?<
.B&;6<%5K
W:\?M,
Q2@!M/G)o
'D6F*H
L$^ 7C$
^:Y!-+
S!0%l$S,-P
"<IL0Q,>*<i
!A3R4Vb
"A3R-<C
+E!87;,<B
oY;S=^3W4
B/K(Z;U7_1
d"O+H9X4Vy
&E7E)K
>=[72M
U'K)8C
mS(-5b
,-^?S1R
K$L"9A
[:2@,N
lV4\2W:^=
]?W9;V2P
G$V&J(,8j
Z@"=V)E
=O+>9N
e(L-0B
5U'F BN
;^=O.1O
7\6B%3T
]*;A".
*H:U&,3H
Z8P>4Y=]
E%GW8~
IV*F$C
P,<37E
K#B.;K
20S0<J
p5X<U'j
[35#N*?o
J&B!$E)Kp
[6C R3_=U;}
1R 0\>B"P2@
O!.22?x
c%H+#;
4Y=TH)E
Q<N-@#D
05$G5J
w0C#PT
B H%O$=W
g!L'4F'J(?Q
P2Z*Y/,%/1\>L
L B ;w
*N-U!>=+
G5T.9>1M
L=\0A$"
NT0S!/7-n
F!21233G
B):>=f
E7VM!O M)J
-I*T#J!
,^?SS,
<7U9Q&?h
J'CD6C%
(E!B/2^<T:n
!?S+-E
\1A,!K
t+E!8",?]+2l
j,@%G6M"A*(o
0Q#B.L$J
} O'5Y.
D6W1uW
h-@$G5T,N&H
dR+O,;
L55Y;SC
Z>G5T7U=SO"F%(I%G
g!LA"P1R0X6m
x>S5V$E
O"D'U4X:
W68L>:r|
X5S=P0
^$F](*'5V
&!I(,5
:<D&8[
V4'7!.<_
]>H&/A/
F"D&P&*D
)2 @2S?]C
6R1B#N,D*l
C$E(Jq2^:Y-/C!<R
M.\=D&G)X5Q1C"
E(-N;Z6T<
?F$A/D)K'U4m
'J-M/N
E$>[3]
C"N+3]N
-+G%@.
R0B">\t
"N*H:[z
:Z6S;U
+H5W)G
1*O-4ZE
o:W"A"
20?\/M
a9!Z4\1)H
}"@"LE$
v?SL"^3
m2NK'N @
x=P8U8Y4V
;.S1X6;
,)E'O!T1
W:^=<UD
u3^:Y%,
d,*X9U7
m'J:4F'K){
CT5Y;S=
5Q2@!7U\
8\?M,*HM
Y4P30Q<2
I*X9U7
4W%D(J
5X<_-L
:V4\2^3_
2Z4rj
;I(D&8V-
y?R C.
,H+Y8>\i
a'J.M)H
;W5]3_2
r4Y:Y%,
#!M/G)i
0B#O-?I
.\=Q3Z490/J
#G$V7Z8`
(E!B0Q
s5X<_,MX
#Q0\>U;,
;_<N/=_
'K)A/X
)[:V4F(
H:[7U'Ij
9]>L-+I
8J+G%7Yq
$@#Q0F$
J'C <]
D'U4B
l/Mal*G#@
mZ6T<R
C1P<^ N
t_7Yr
#G$V7E'
1C"N,.@
/C!I'K&
e5Y;S=e
#Q0\>E+%
$V7[9;U
"N,D*i
B/K(W.
&B!S2[1
65Y;S=x
Xa'J.M<U
z|D(J"L
"I!L|E7V:X/A
A.B H&Z7y
D.\=Q3E+
qSA%F4U#A[
h.C'D09
<;W5]3o
4<D%M/
^:Y+J :
hJ%D't
E7V:X*<
P4W%D"8
(E!A" L.F(h
j,A%F.G
i/B ;<V
$"N,D*f
]9Z(Iu-=
0RO)U3
+'K)A/c
L 0E6W;Y
5S?]5[
>Z9K*@
(J72^<T:v
c%H,O7N
D6W;Y+=
Q;_<N/
+G5T7U
3W4E$G
v/B81C"M/
q6;]>N"@%K
R:^=N/4!I'_2
8+G%L"
I;Z2P
,^?Q33'a
[?\-LM
Z(I!Cn
"P1V4$H
;&B!Q0-'O!f
-"P1[9
P4W$ES
eU,H+X9
m+F!B01]?U;
W;Y,B6O+H9X
Y+J BU
b!)M.Z;b
\0R8Vb
I$8+Y8O-
5G&I+&!g
2*N-]<
2V5F'P
D)92@!L.M
0$V7Y;
)4P3@!
A-O&Hs
C/M$Je
:;W5\2t
%8T6]3
$9U7^0
t2_:Yv
3D,MX:
T.LK%&0q
zQ>;;{
U4J"^(].
c(=8Y8B*?6V
[~A!@
[.3F1P
:9?\;T
;U."<_
f0B5Vb
Q/Y7M~
Z7S6NB*s
w;51=P,
N!I,I-@
<CG'8O
:V5[-@
H+.O1O
r?L%Et
G$ :6S
!J[87Nb
[:U7T:|
G$U48Z2\
tU/_3>U$<-9/8
D)L/V7U7W9x
;V'D(I
xM+G%Q
R#Z7_1>0_;I(
P'V3[5
^:Y,G?Z2\
YH*X9I S<z
G$T4F'
Y:F';Y
B/I*Q0S1W9w
S03R<^
X58['F
2Q"C&C
\2rN,!@+I
_>Q3#L
],G$V6
_^/>N$G5S
P/58O!'I
\1U6C"
G*N-Q0
u3^:Y*KR
P=U6D%I+C-k
@-E&T5Y;S={
B/K(Y8
m+F"AA
P>V;>]
T9]>Q//I!O
M%L+%9W8N
;K&seQ
{~VCaVu
~8srmD
P[GdJvYcr
s`Ei]Q
^{[dS|y
kK~@s0
%Gj~`p>
?^kLn'
F.QXxL
QCrVKjEZ
/u~Lf;
UHg[lt2
2_f\ke
6vgIKqHfEX
,NK}rqK
?beKcNn~F
'}yMvr
&TFkLT
B!pqmI
'UEjK^~gt2
B*UT|=
~_diMvB
!]z\P}
&{\\}cF
qHfEL
R>mFk>
3u_jMla
;WiNL~G
"PBoPO
[wVrW6
Z`[x}Q
@OwO{W
AfrUpf
D&_rw+
(vTiT6
8POJj>
1PMql/
T_{gU1
]{=aFhS
mH*hG*
^Ki^hr<
6oCXaL/
0nKkEk
-Rq\JlG#_z_`^]|
Gn(nl$
^r^C~/
<z^,naA
qZJy[HkFIT9nN
*_}RNm^
zUV;wtL>
$QsD%~i
xWT9nN
m`bv#
:cNK&SqFO
PBoP8gbRP
[^wBpW4lN3
=dcQW{
VFuWLoJ$
\rY:gS
;Z|SBkH
;ugVKjE<
^jM!T}V5
O-E"6[
?\.44V
I*#B.;
Z8P-"O
rC R*
-O'<-@
M#C.J&2S?N
~F$q
~F$q
,N&/&K
7E$;3[
]?W #N
8O,T5L.<R
V8Q<+H
>]/95W
w$I#@2@
{3^-N2S
W9R?.M
U;&K/C
V8!L(2
B*=:W
G5G+?W8g
W9R?.M
M#8U$G+J
]3H%!B
L"W:T7
C$E}
z<D 9K
8H,E7)E
}A/9T
D(=U1w
U'9U-E
>S*I1P
A"#B!C!O
O=*F$A
e#A%<N
_9#B.?
X66[|
U6$E(#M
L(>L#O
9T#@(I
8O,T5,N
F'+I 
B!F'A#
P"%V%8S5F
O)A'0F
^:H)D"J$P1Q2@
[77_*<P3O-.B
]+C1O!10Yq
s/4L)>M
Z&X4.I;Y-F(F
V)7P8T
Q$>W#?M
G".E/>A
G!G';P
Y(:\,6
Z7O(Z;W2T
V9W,V7W,4B
X 6X-,J0H B)>`
k$6R'L
v)B 8E
w0U7=<L&6@
\?L+>Y1_
h 5P37
};V"@2H
b#<P-J
p4K-0B ,N$C
].E,:x
],B";Y/.h
[72S8S8D
\6Y) F
,3U1#A
S#..7R$
>N#=3P:R:S
4D"@%=m
X5P!"1
J+G'*5
P&A3Q<\.@
fw+F!0
U&G"V-7
ZN%F4C
8U."?V&
H/>/2A!7
D,&Y-F
\$+G(&]/.H2K!#J#S
^=4Q+3
~6Y;V A,M
_ C%Z54R
U";:;N
V9[6;Z4U+
C <0R(
L&C'?K
].&2A!J
s.8N[
<I+F.O!94U
\1J-D :G'Y,
].H)Y6X8N
Q5I"N$H(/
_9M'$C
:O+D5L
j'J-M";O
Z54I-J
]-5V-G"N-/
k'J,22E
N&M(&D$B
>;]:H(6<x
S>Z9K*F$L"f
\1U6D%H*B,j
T9]>L-A#K%G
c%H,O=\
?R6U'Fm
Z7R1C"M/G)o
g!L(K9X4V
8Y5W?Q
vZ7E$G%
G&I+B,'J
\>U;7Z
M,@" N
[8J+G%M#e
C"6>0V
Y0"#/-%+1
)$ #10<>68^
/"&%76:80>
G(?3197Q
?265'&*
[-/')O
308H"4<=13;5S
T(:80"
- $'548
v4.0.30319
#Strings
#chhhhhhhhhh#
#hccccccc.dll#
#fsdfsd.dll#
#fsdghcggfsdfsd.dll#
#fsdhcfsdf.dll#
#fshghhhgfhdfsdf.dll#
#fshggdfsshgfhdfsdf.dll#
#fsdffchafhghgsdf.dll#
#fsdhhahffdsf.dll#
#fsdghhhhhhsdgfdsf.dll#
HotHeap20
$$method0x6000052-1
IEnumerable`1
SparseArray`1
CodePageMacGB2312
S_LDATA32
ToUInt32
ToInt32
BytesPerInt32
<GetTypeRefs>d__282
Func`2
OnLazyAdd2
Get_AddressField2
MDAllocateMemberDefRids2
Conv_U4
TypeInt16
ToInt16
ISO10126
Tuple`7
get_UTF8
ENC50229
<FindConstructors>d__279
<Module>
CSIDL_LOCAL_APPDATA
AddFieldRVA
ISO2022JPESC
FILE_ATTRIBUTE_ENCRYPTED
ListGenericParamMD
STD_INPUT_HANDLE
LOCALE_SISO3166CTRYNAME
REG_NONE
EnvDTE
COR_E_MARSHALDIRECTIVE
CAL_GREGORIAN_ME_FRENCH
VT_DECIMAL
System.IO
ERROR_INVALID_OWNER
VT_VECTOR
COR_E_TARGET
RESOURCE_STRING_ALIGNMENT
S_PARAMSLOT
S_THUNK32_ST
S_UNAMESPACE_ST
S_COBOLUDT_ST
set_IV
LOCALE_SCURRENCY
IMAGE_DEBUG_DIRECTORY
PROPERTY
M_data
OrigRva
mscorlib
hnFmdcralb
_LoadCertFromBlob
System.Collections.Generic
get_IsStatic
hkkkkkkkkkkkkkkkkkkkkkkkkc
System.Diagnostics.SymbolStore.ISymbolDocument.get_CheckSumAlgorithmId
GetProcessById
lpNumberOfBytesRead
hThread
get_CurrentThread
thread
Add_DomainUnload
MarshalNativeToManaged
INotifyPropertyChanged
M_nameIsCached
get_IsAttached
IsCustomAttributeDefined
CtorClosed
Unrestricted
Set_IsSorted
fshghd
GetLog2Rid
GpRidToOwnerRid
<PEHeaders>k__BackingField
NextSpinWillYield
Millisecond
set_IsBackground
DynamicMethod
DefinePInvokeMethod
ResolveMethod
Get_OwnerMethod
GetMethod
NetGuard
get_IsInterface
Replace
ArrayElementsHaveSpace
CreateCaInstance
TypeTypedReference
LoadResource
FindResource
SizeofResource
GetHashCode
SetCode
CryptoStreamMode
get_Unicode
Xenocode.Client.Attributes.AssemblyAttributes.ProcessedByXenocode
CodePage
ExecutableImage
CheckTicksRange
EndInvoke
BeginInvoke
CodeManagerTable
Set_NestedClassTable
Set_ConstantTable
FieldLayoutTable
GetEnvironmentVariable
Enumerable
IDisposable
set_Visible
Double
get_Handle
RuntimeFieldHandle
get_MethodHandle
RuntimeMethodHandle
M_methodHandle
GetModuleHandle
get_TypeHandle
RuntimeTypeHandle
CloseHandle
GetFieldFromHandle
GetTypeFromHandle
MapViewOfFile
ImplicitFile
CopyFile
Console
get_Module
DefineDynamicModule
MissingModule
InternalModule
set_FormBorderStyle
get_Name
TypeName
DisposeName
Get_TargetFrameworkName
GetRealTypeFullName
lpApplicationName
SWindowsName
AssemblyName
BuildStackFrame
HashPrime
SystemRuntime
ReadLine
lpCommandLine
WriteLine
FindExportedType
get_FieldType
FindType
CodeType
DefineType
CreateType
ValueType
get_DeclaringType
InitializeMarshalType
Get_UnderlyingSystemType
flAllocationType
get_ReturnType
SetAppDomainManagerType
get_ParameterType
Get_VariantType
System.Core
ResolveSignature
SetLocalSignature
M_CurrentUICulture
MethodBase
_methodBase
_CodeBase
Dispose
TicksToOADate
Truncate
Create
CreateDelegate
MulticastDelegate
set_WindowState
FormWindowState
AllowTrailingWhite
ReadWrite
IsWrite
STAThreadAttribute
CompilerGeneratedAttribute
UnverifiableCodeAttribute
UnsafeValueTypeAttribute
BabelAttribute
SuppressIldasmAttribute
AssemblyInfoAttribute
YanoAttribute
DotNetPatcherPackerAttribute
BabelObfuscatorAttribute
CryptoObfuscator.ProtectedWithCryptoObfuscatorAttribute
DotNetPatcherObfuscatorAttribute
DotfuscatorAttribute
CompilationRelaxationsAttribute
AssemblyCopyrightAttribute
SmartAssembly.Attributes.PoweredByAttribute
RuntimeCompatibilityAttribute
GetMinute
System.IConvertible.ToByte
TimerQueue
InternalGetNumericValue
SetValue
GetRawConstantValue
get_IsAlive
ClearNative
remove_ResourceResolve
hnFmdcralb.exe
get_Size
StreamSize
M_skipSize
GetClassSize
dwSize
Resize
SizeOf
IsSubclassOf
fsafafwwwwwwwwaf
fshgdf
fsdfhghfafgsdf
GetSigOfFieldDef
IsFieldDef
TokenToTypeDef
ResolveTypeDefOrRef
get_IsByRef
CorLibAssemblyRef
EntityRef
KoreanYearSuff
ChineseHourSuff
gfdffffffhfffg
Get_FieldSig
M_currSig
System.Threading
Encoding
IsLogging
Ceiling
Beginning
FromBase64String
_stackTraceString
WholeString
OutputDebugString
ToString
GetString
InitMatch
hhhhhhhhhhhhhhhhhhhhhhhhhhhhh
get_ExecutablePath
BNoSearchPath
LocalPath
ObfuscatedByGoliath
tmMaxCharWidth
NLength
get_Length
MaximumInternetNameLength
nmekndfbjpi
PosixCui
_servicePack
AsyncCallback
DecoderReplacementFallback
callback
ReadOriginalValue_NoLock
GetMethodTokenNoLock
FlushFinalBlock
CanSeek
GetValidMask
ExecuteWithThreadLocal
Marshal
Get_ResourceExposureLevel
kernel32.dll
Control
IsCOMObjectImpl
Set_Url
ImageStream
HotTableStream
IsolatedStorageFileStream
DestinationStream
CryptoStream
HotHeapStream
MemoryStream
System
SymmetricAlgorithm
NumAmpm
RijndaelManagedTransform
ICryptoTransform
RequestMinimum
Cgt_Un
SigPtrLen
get_MetadataToken
FullNameToken
hToken
M_leaveOpen
lpNumberOfBytesWritten
AppDomain
get_CurrentDomain
EnvironmentPermission
WindowsBootApplication
get_Location
Duration
NineRays.Obfuscator.Evaluation
IsPunctuation
_LoaderOptimization
System.Reflection
CallingConvention
MetadataException
Remove_UnhandledException
RuntimeWrappedException
FullDateTimePattern
Get_LongTimePattern
CanConvertTo
GetEHInfo
GetDynamicILInfo
VamDynamicMethodFieldInfo
MethodInfo
TypeInfo
Set_CultureInfo
CancellationCallbackInfo
startupInfo
MemberInfo
ParameterInfo
BlobHeap
StringsHeap
Get_TimeDateStamp
LocalPop
DragDrop
inextp
System.Linq
set_ShowInTaskbar
Calendar
TmLastChar
EndAddr
ParseHostNumber
GetDefaultReader
NullTextReader
DESCryptoServiceProvider
InternalFormatProvider
MethodBuilder
ModuleBuilder
TypeBuilder
AssemblyBuilder
FallbackBuffer
lpBuffer
M_buffer
ResourceManager
Debugger
Modifier
LogSwitchLevelHandler
ExecutingTaskScheduler
Get_DefaultScheduler
DomainNameHelper
GetTypeHelper
FastResourceComparer
ReflectionTypeNameParser
get_IsPointer
IMethodDecrypter
BitConverter
Importer
EfiBootServiceDriver
GetTokenFor
SetLastError
Set_AMDesignator
SThousandSeparator
PercentDecimalSeparator
HashtableEnumerator
CharEnumerator
.cctor
dotNetProtector
NotSupported_Constructor
get_IsConstructor
CreateDecryptor
ArgPtr
IntPtr
System.Diagnostics
GetMethods
Interfaces
System.Runtime.InteropServices
System.Runtime.CompilerServices
System.Resources
hnFmdcralb.resources
Get_Guarantees
Directories
GetProperties
bInheritHandles
M_strAllLocalFiles
EnableVisualStyles
M_abbrevEnglishEraNames
SaAbbrevMonthGenitiveNames
GetDirectoryNames
Primes
EmptyTypes
Get_PdbAttributes
lpThreadAttributes
MethodAttributes
TypeAttributes
MethodImplAttributes
GetCustomAttributes
lpProcessAttributes
DeclSecurityAttributes
Rfc2898DeriveBytes
GetBytes
DotNetTableSizes
PercentGroupSizes
LegalKeySizes
Get_BindingFlags
dwCreationFlags
GetMethodImplementationFlags
SetImplementationFlags
AsyncCompletedEventArgs
PostSearchPaths
Set_ExplicitThis
AllowParenthesis
Equals
StrongNameUtils
NumElems
System.Windows.Forms
StartColumns
CallingConventions
Get_CreationOptions
Get_Cor20HeaderOptions
M_options
get_VTableFixups
Set_Chars
get_Chars
_WSchars
GetOptionalCustomModifiers
RuntimeHelpers
Get_HasGenericParameters
ConstructParameters
GetParameters
get_IsClass
AssemblyBuilderAccess
GetRegistryKeyAccess
hProcess
GetCurrentProcess
lpBaseAddress
lpAddress
_resourceSets
set_NumberDecimalDigits
GetRowCounts
S_REGISTER_16t
ReadInt16At
Concat
Format
GetObject
object
Select
flProtect
ECMASpaceSet
CheckSet
CharSet
BinderNonFieldGetSet
get_BaseUtcOffset
InitializeFieldOffset
Get_HandlerOffset
ClassTokenOrFilterOffset
MaxOptionShift
Preferred32Bit
op_Explicit
System.Reflection.Emit
BeforeFieldInit
SetCompatibleTextRenderingDefault
Get_HResult
IAsyncResult
EnumResult
result
TmDescent
Op_Increment
PolicyStatement
lpEnvironment
Set_HijriAdjustment
ExceptionArgument
MemberRefParent
CheckRemoteDebuggerPresent
IsDebuggerPresent
Get_IsEvent
AutoResetEvent
Set_NativeEntryPoint
IFrameCount
IterationCount
GetMaxCharCount
GetPathRoot
ParameterizedThreadStart
Convert
UShort
MetadataImport
FailFast
_rangelist
GenericInst
Set_ReadTimeout
IgnoreTimeout
SuspendLayout
ResumeLayout
System.Text
CreateText
ModuleContext
get_LogicalCallContext
context
M_encryptindex
GetCurrentMonoPrefix
Tuesday
Get_IsValueArray
InitializeArray
ToArray
ToCharArray
get_IsArray
EmptyArray
FCallToCurrency
set_Key
NeutralPublicKey
System.Security.Cryptography
DefineDynamicAssembly
GetExecutingAssembly
Get_InternalAssembly
State_Finally
ClosedDelegateOnly
Get_CompletedSynchronously
IsClr40Exactly
IsTiny
BlockCopy
IsBoundary
lpCurrentDirectory
Get_ImportDirectory
DelegateEntry
AttributeEntry
SLocalizedCountry
CheckRegistry
op_Equality
System.Security
SuppressUnmanagedCodeSecurity
IsNullOrEmpty
SetProperty
198 Protector V2
System.Security.Permissions.SecurityPermissionAttribute, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089
SkipVerification
WrapNonExceptionThrows
_CorExeMain
mscoree.dll
@eIDATx
H`;DQB
@$tZEs
jM;I&,e
/mlf&t
KQ!}Z.
f$Rb+4
ZaQW 0
N-RJ\pl
1a_y9LE
o,/ae>
.MZP=(.
0NT{P3)
La>Yl;
"@5iJI
B=TP5@5<B
Z/P<="
<]\GnRP^
/lA:bn
T={~Ad+
=g,6KZ
X%s%@\
BrcU0C
vRF qi
X//l=9
n6> 8aF
u{bd].
\Np9$
wwwwwwwx
wwwwwx
wwwwwx
wwwwwwwx
wwwwww
wwwwwp
DDDDDD
wwwwwwwwx
wwwwwwww
wwwwwwwx
wwwwwx
wwwwwx
wwwwwwwx
wwwwww
wwwwwp
DDDDDD
wwwwwwwwx
wwwwwwww
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<assemblyIdentity version="1.0.0.0" name="MyApplication.app"/>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v2">
<security>
<requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3">
<requestedExecutionLevel level="asInvoker" uiAccess="false"/>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
hnFmdcralb
GetEnvironmentVariable
-2073479065
2073517020
_ENABLE_PROFILING
_PROFILER
-1467383565
1467237379
-500307010
500333278
-1997915646
1997911691
-1425567478
1425550311
1240485917
1240555059
-742118214
741937339
-2015651592
2015735528
-184143178
184032229
-294724050
294894520
1951287290
1951313508
1733546088
1733490285
516257144
516161626
-983788485
983653447
-624788536
624773266
-40389170
40445450
-1377692787
1377638619
-1937652429
1937735428
-1620852525
1620891805
7322669
7284278
-1328747333
1328623631
-9244054
9200449
-1289335303
1289304498
-1435837519
1435854640
-898289023
898291811
1459323479
1459261955
-782448856
782486462
1207410069
1207432811
2134524658
2134597259
-1998997136
1999068111
997455929
997359906
2038810641
2038730437
-1505011736
1505094792
2070048955
2070108510
1638067525
1638047643
-417278006
417257401
-632661969
632594899
2031368375
2031397025
1243947770
1243955304
-923292955
923363228
711880149
711869476
-1692786349
1692771910
1636005033
1635978990
149353690
149355615
-728641054
728638141
1024890724
1024863965
-140116419
140218187
-1926874467
1926825723
1667487750
1667483068
657561135
657563649
-2071112092
2071132182
-437989029
437875222
-504748606
504885168
-217045550
216983032
1068706048
1068633891
1328549146
1328639268
-1110435281
1110438370
-879841892
879794467
1272077511
1272061045
-384753104
384743835
1272758513
1272774032
538504284
538466736
1863177334
1863115452
-1378180236
1378136749
-2088459689
2088456642
-2073528854
2073553665
649481519
649475981
1585512222
1585497507
-1189228341
1189305894
1273106683
1273158223
892549401
892593942
1703173943
1703214467
-1465489043
1465447945
411616654
411585590
501947242
501972827
-1324851696
1324745022
1302602354
1302701155
1068249697
1068292706
-439213365
439161890
-1509726269
1509742307
32892958
32800910
1596904332
1596973258
962652511
962615310
-173626427
173637387
-379690793
379588696
-1646154301
1646056805
-1687209702
1687183956
-722027499
722043735
656926500
656857246
-1498772075
1498691607
-48055735
47984825
-1446277434
1446373321
908680384
908685839
1596480402
1596513010
-1436487031
1436460174
755580811
755573900
1827801985
1827811903
-1965181182
1965218716
2050427417
2050448917
3007459
2918721
-2003253411
2003115363
1339958657
1339979772
-296971824
296931680
274985341
274964353
-1930196153
1930220668
-2002478130
2002420570
1616296872
1616355883
1685018114
1684998995
1482430360
1482450347
-396903400
396969342
-1287479346
1287428153
-86061858
86243607
1272161701
1272062291
-920201750
920246709
264906787
264984355
-439755244
439773903
-2082514294
2082560228
-200394987
200305622
92840090
92814675
-1122244264
1122333897
-681765398
681816572
27712652
27712357
729823129
729850602
981367079
981349002
1324601731
1324586072
120515458
120459947
543764624
543782431
1078074598
1078084836
870606587
870638183
1629778860
1629767980
-1885272742
1885107254
272041560
271992471
-1691657910
1691648577
-552316723
552246167
859458477
859446313
273059144
273055260
1292867802
Antivirus Signature
Bkav Clean
Lionic Clean
Elastic malicious (high confidence)
MicroWorld-eScan Clean
FireEye Generic.mg.7afe2c262a2733bc
CAT-QuickHeal Clean
McAfee Artemis!7AFE2C262A27
Cylance Unsafe
VIPRE Clean
Sangfor Suspicious.Win32.Save.a
CrowdStrike win/malicious_confidence_80% (D)
BitDefender Clean
K7GW Clean
K7AntiVirus Clean
BitDefenderTheta Gen:NN.ZemsilF.34218.zm0@aKyHECcG
Cyren Clean
ESET-NOD32 a variant of MSIL/Injector.VRI
Baidu Clean
APEX Malicious
Paloalto Clean
ClamAV Clean
Kaspersky Clean
Alibaba Clean
NANO-Antivirus Clean
ViRobot Clean
Rising Clean
Ad-Aware Clean
TACHYON Clean
Emsisoft Clean
Comodo Clean
F-Secure Clean
DrWeb Clean
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition BehavesLike.Win32.Generic.gh
CMC Clean
Sophos Clean
Ikarus Trojan.MSIL.Injector
GData Clean
Jiangmin Clean
eGambit Unsafe.AI_Score_99%
Avira Clean
Antiy-AVL Clean
Kingsoft Clean
Gridinsoft Clean
Arcabit Clean
SUPERAntiSpyware Clean
ZoneAlarm Clean
Microsoft Trojan:Win32/Sabsik.FL.B!ml
Cynet Clean
AhnLab-V3 Clean
Acronis Clean
VBA32 Clean
ALYac Clean
MAX Clean
Malwarebytes Clean
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Tencent Clean
Yandex Clean
SentinelOne Static AI - Malicious PE
MaxSecure Clean
Fortinet MSIL/Agent.VRN!tr
Webroot Clean
AVG Win32:PWSX-gen [Trj]
Avast Win32:PWSX-gen [Trj]
No IRMA results available.