Static | ZeroBOX

PE Compile Time

2021-10-27 08:44:42

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x0006a624 0x0006a800 6.69741139222
.rsrc 0x0006e000 0x00010f32 0x00011000 4.07952925799
.reloc 0x00080000 0x0000000c 0x00000200 0.101910425663

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x0006e18c 0x00010828 LANG_NEUTRAL SUBLANG_NEUTRAL dBase III DBT, version number 0, next free block index 40
RT_STRING 0x0007e9b4 0x00000178 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_GROUP_ICON 0x0007eb2c 0x00000014 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_VERSION 0x0007eb40 0x00000208 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_MANIFEST 0x0007ed48 0x000001ea LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with CRLF line terminators

Imports

Library mscoree.dll:
0x402000 _CorExeMain

!This program cannot be run in DOS mode.
`.rsrc
@.reloc
L*TaiZf
KBai($
@[@X(q
@V@X(q
w3ai(
@H@X(q
]@[(q
@P@Z(q
`[@[(q
`\@[(q
`_@[(q
[XZ_bX
[YZ_bX
[XZ_bX
[YZ_bX
[YZ_bX
[YZ_bX
[YZ_bX
[XZ_bX
[XZ_bX
[XZ_bX
[YZ_bX
[YZ_bX
[YZ_bX
[XZ_bX
[YZ_bX
[XZ_bX
b@SA#
(t@Z(q
[YZ_bX
[XZ_bX
[YZ_bX
#< ]x#
[YZ_bX
8z@Z(q
[XZ_bX
[XZ_bX
#Xwq]gS
[YZ_bX
[XZ_bX
[YZ_bX
[YZ_bX
[XZ_bX
[YZ_bX
[XZ_bX
#0Jq9r
[YZ_bX
[XZ_bX
[XZ_bX
8{@Y(q
[XZ_bX
#Q@f\T
[YZ_bX
[YZ_bX
[XZ_bX
[XZ_bX
[YZ_bX
ADCk@#
[XZ_bX
[YZ_bX
[XZ_bX
[XZ_bX
[YZ_bX
[YZ_bX
[XZ_bX
[YZ_bX
[XZ_bX
[YZ_bX
#VB\h{&
pf@[(q
[YZ_bX
[YZ_bX
[YZ_bX
[XZ_bX
#CR/&{m
[YZ_bX
[YZ_bX
#R_,CZb
[XZ_bX
[XZ_bX
[YZ_bX
[XZ_bX
[YZ_bX
[YZ_bX
p^yA#
[XZ_bX
[XZ_bX
[YZ_bX
[YZ_bX
#"7!|v
[YZ`(^
[XZX(m
[YZX(m
[YZX(m
[XZX(s
[XZX(m
[XZX(m
[YZX(m
[YZX(m
WQ4aieY
XaefY}
ZeXXee}
wJaiaYaY}
feYfYeY
aiZYfa
(<aiaef
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
PADPADPV%
bUN4PrS
FQcG29
%TIr[-r
c\kt&D
,/-vNPLq|
0+KP/#
AO~;~hV
V>.Oamj
op"["C
6Jl8Qq
Bo`76*
H^x@^K
/?&oRH
(z/g_$
Mmzb4?
Jd4%)"
$v&r:(i7-:
!krU*&
Lj&Iv{
o{r7Ti
s,|%#L-
[${XVj
2Nek8'
RI J%6
m@xWHO
dC&}$
X%,86-
#N`U.:
ap,bvh
u& d#E
nn,pWo{g
>WF}):
E\@R<1B
m?%#e,
Hx!4co/m
:gh$@>6
r<A}.^
3R=Z@,
\vraR'M
BPq5|D
4$#_]"
HNG5!&
,goq<0$Eo
`Yoz0:
0Q:LTG
bcqv*i
0F]1J!
X'+.;/
2iAeR8A
4t7rZ6
T?sd][;B
:7=Vv|
'y&iO:6a
i1`C^58
d6>m(;K>\
MD0B^nUh
={0p`v
js7a+ud
+c?8%[
r")% T
lz~m]*
*l1GE
37vJJ6
>]uYccZ
$Q_c"9
{@4.f-7
}\=I3rL
|+px)RB;
Z9R28{/G
1Im&wH
F7j$p0~
T1wa(=
P#y6sIp
n||*C
+&B/AI
f:m3UkWeU
%u;&[HJ
jB]ga7+
7}t[1ae
p!;D}]
gKP&-%
*}mGp
\`33@
n@;b_Sm
NMY.O8
Za5^H<?od
pc%<r[]
=taO~tU
ChpMcro
vK2<$=c
6u(v%ENvr
Lq-+{.
Thj_Ygm
x,ls\p
wf.2|Ec
jM_3(5
H74bLa
C><3@z8f
|(Hubcr
3r%gE~
I]<" F*
\5}4!=.~
@c!ueo
OX_=FMMS
@B:D :
Gimgdk
<#?4qIZ
{SB&8N
k`vCqV
,x3<h
3<RmYj
b$sk(Aq/
\8xK>,
RbNqSO
WTkAnp
/p0rPt
WC_$=G
+(hf,K>a
1zj\Eb
)7Bo`[
6z._Bb
I'K,Yc
;;bugl
X.J3hTNm
3w~"c/I
_7cHML
C[qY%-
Q""fL2G
1uTUpF
&a uKM
?tB9=V
W[[D)0.vN
[)PF|C
aC.i%L
dIgd6_D
}>D!IA
!8?=Aj
q`dcdQ
dj|Hs!
/c@n:]
iH83e$V
tX8/}^
O0W}CL
>2e@Mj9
<m&S)h@
j>YjWD
/:tfM{
}k!ZwY
'+-\xm
R{E|G-6
vk2`\5
z1 ?Y$7S
P{Y +T
c[pVCi
j/W{.cX
sD6cY-
/ a|qS)l
?dX{_w
wN`b8}
P>2j]3
zk')N~
8o(zv-
Jpg0K3I3
EJWNRU_
j-Z4r1
?9T$.
-4VKG<N
EImn#,
E7lClQ
8i/`4}
3Qt:G^z
i!*:+|f
=~q[+'
$e>u^w(
'm90?8[3l
Fe7k|u
W+C<]sAY
a9=p[q
]!N$E8
w~*wF"
75UIRVjf
5e:Iyj
5e:Iyj
JyORZDC
RCo%[51
*y~j{`XdA
%%^$W.
F5A1$+
i|tuS
=zLwE7pQ
=zLwE7
TNzq&>
ay4z+0
]+xEWf
x"o4@W/
QX g-P
>-}' a
6^r+!I@
n(mf%eH
cuxcu
x"(fyQ
"P(v?a
rs/kY=
[bY/$Y
CoD/?j
qaNvH9
N,O,wlT0\
#^oOvf
=r!s2<A"G-3
UpX5'It<
9A+XFJ
.du_'/6
NNPrSf2gV
}l|lN1
=/nB?+
FiB+\~
WTUs~EQ
Z:[~[
om!Pxr
4+(q 7Yg
1nO[E/l
/Zh|;.
!s[uyQ
u#J1R~
l7?~SR5j%
`uS|r_
LH.Gp2D
jcA$I9D
bvf&y/
%R0CGG
-y`T,$fT
[a +bW
lPo3,SGVo
FQl'>x;M/C h
COkA3Q
(%'^{!C
5G>MU)
_]Zs[3
l^,:#Z
|[[V\ie
;[I5
Y7qL4SY
y)i?$/M
lpTj~1n
.'@((O
$2pmXd
4XG{QwV
OUKp`~
dKtmF_
VPqKCS
1#%xZ|G
R~ywn0
W]n:x#q
W;O,WQ
Ue@=00c%
XZ<*\m
gRsU;>
q /:gT
No+WbL
Uxqsp/
U8!8IP
"k4}#*1
n\e;Bv
&oV~Hwu'Ls
e%MwxbY
k#<$<$
\q+Y>W9Y
HfqWC[T
pue0iMo
,xC=@r
zgJVDG
:NY="'
H^/nCA|
?EZL=t5
6Ac_#O
lw["De
Wq*7?m
\&ez:zz
AbA]6({%
}2`0-*
}Jh+\Rn
~j^Skp
~4JJsM
s>']\[@
rOl"o
K5;$ {
z;d@ey
WqFo;?
cvSt<5
]^1q"pF
x/6/3x
W(q.\"7
_v5@si
Q2?+8sE%f
K(81<w
ZC]CA|
cJQH9u+N}
v69sqc\
w72d$/p
0=Jcyyg
bi_NYMj
UU@AK8=
yWd,y'
H_DwuA
jPw52`
lPt4W{(
wTn{8d
%$5i%I
/{l&CU
Hpds, s
~E2H8V"_
w{8zE_?
*<>x+R
`^co>b
!+CZ]K
A~RGd1
3?eb_h
7y^KRt
;Ff5:R
hy4^9t
;JP:/5
>g_&]L
ZJIJ=3|
\J^]a9
CgQ8/8
b :TpG
p?rXq
}K]u5g
^2g!+Y
(/davU;
))4++o
v4.0.30319
#Strings
#gdfg#
#gsdfg#
#fsdfsd.dll#
#hsd.dll#
#fsdfgdddddfchafhghgsdf.dll#
#sf.dll#
#fafg.dll#
#hdfh.dll#
#agsh.dll#
#adas.dll#
#js.dll#
R10000
<RemoveAll>b__0
TreatAsI1
IEnumerable`1
System_StackDebugView`1
Get_Item1
WriteCompressedUInt32
TypeUInt32
ToUInt32
FormatUInt32
ToInt32
Stelem_I2
<i>5__2
<items>5__2
Func`2
Prime2
ReadFieldLayoutRow2
<>s__3
Ldarg_3
TryParseInt64
Ldelem_R4
ToInt16
get_UTF8
LOCALE_S1159
<Module>
S_notUsedSinceLastGC
S_LMANPROC
RuntimeVersionWinMD
VT_RECORD
LOCALE_SSORTLOCALE
ERROR_INVALID_HANDLE
CSIDL_FLAG_CREATE
CERT_STORE_MANIFOLD_FLAG
S_SSEARCH
s_jajpDTFI
get_ASCII
E_FAIL
E_NOTIMPL
GetHebrewDayOfNM
NOOPEN
ERROR_INVALID_FUNCTION
System.IO
DEFAULT_SPIN_MP
MalformedSlashP
SE_GROUP_OWNER
MUTEX_ALL_ACCESS
HH_ALIGNMENT
CTRL_BREAK_EVENT
Get_SLIST
S_LABEL32_ST
S_MANMANYREG2_ST
CORSEC_E_XMLSYNTAX
Ldelema
CompressedMetaData
dateData
TrackDebugData
LocalApplicationData
mscorlib
dnlib.DotNet.IMemberRef.get_IsMethodSpec
hgdfgdfgc
IsPublic
System.Collections.Generic
get_IsStatic
M_negLoc
Get_EncId
System.Diagnostics.SymbolStore.ISymbolDocument.get_CheckSumAlgorithmId
GetProcessById
lpNumberOfBytesRead
hThread
get_CurrentThread
thread
RijndaelManaged
get_IsAttached
IsMatched
Disposed
Get_IsDeleted
WriteNotSupported
IsInitialized
gdfgdfghfgd
IsIidParamIndexValid
ContractFailureKind
set_IsBackground
DynamicMethod
DefinePInvokeMethod
ResolveMethod
GetMethod
SetMethod
IgnorablePeriod
dpFkIAcjod
NetGuard
FireCustomerDebugProbe
get_IsInterface
Replace
CoCreateInstance
QuerySource
LoadResource
FindEmbeddedResource
FindResource
SizeofResource
GetHashCode
SetCode
set_Mode
CryptoStreamMode
CipherMode
ConfigNode
bigEndianUnicode
Xenocode.Client.Attributes.AssemblyAttributes.ProcessedByXenocode
_nullMessage
EndInvoke
BeginInvoke
Get_MemberRefTable
Get_MethodImplTable
AssemblyRefProcessorTable
GetEnvironmentVariable
Enumerable
IDisposable
set_Visible
Double
get_Handle
RuntimeFieldHandle
get_MethodHandle
RuntimeMethodHandle
GetModuleHandle
get_TypeHandle
RuntimeTypeHandle
CloseHandle
GetFieldFromHandle
GetTypeFromHandle
Get_File
Console
get_Module
DefineDynamicModule
set_FormBorderStyle
get_Name
FullyQualifiedName
Set_NativeTypeName
KoreanLangName
lpApplicationName
M_strAssemblyName
FileTime
NGetTotalProcessorTime
WaitOne
lpCommandLine
WriteLine
Get_None
WriteInlineNone
CreateCustomTimeZone
EqualsScope
RootScope
get_FieldType
GetModuleType
DefineType
InitializeBaseType
CreateType
ValueType
get_DeclaringType
AnchorFromType
flAllocationType
get_ReturnType
MemberType
get_ParameterType
Set_RetType
Compare
System.Core
Get_NotBefore
FusionStore
GetResourceNameForFailure
ReadTypeSignature
ResolveSignature
SetLocalSignature
InitUserDefaultUICulture
Get_UserDefaultCulture
MethodBase
Dispose
TicksToOADate
Truncate
CreateDelegate
MulticastDelegate
IsLowSurrogate
set_WindowState
FormWindowState
M_state
BlockingBeginWrite
STAThreadAttribute
CompilerGeneratedAttribute
UnverifiableCodeAttribute
AssemblyTitleAttribute
UnsafeValueTypeAttribute
ObsoleteAttribute
DebuggerStepThroughAttribute
BabelAttribute
IHasCustomAttribute
SuppressIldasmAttribute
TypeForwardedToAttribute
AssemblyInfoAttribute
YanoAttribute
DotNetPatcherPackerAttribute
BabelObfuscatorAttribute
CryptoObfuscator.ProtectedWithCryptoObfuscatorAttribute
DotNetPatcherObfuscatorAttribute
DotfuscatorAttribute
CompilationRelaxationsAttribute
SmartAssembly.Attributes.PoweredByAttribute
RuntimeCompatibilityAttribute
FieldToInitialValue
SetValue
Get_RawDefaultValue
C_timeZoneInfoRegistryHive
get_IsAlive
WaitHandleCleanupNative
dpFkIAcjod.exe
get_Size
Get_OutputBlockSize
MinSize
M_fixupInstSize
dwSize
SizeOf
fsafafwwwwwwwwaf
fshjkkgdf
TokenToTypeDef
Get_HasParamDef
IsForwardRef
get_IsByRef
FindCorLibAssemblyRef
CModReqdSig
ImportAsTypeSig
Set_LocalSig
TryGetGenericInstSig
System.Threading
Encoding
IsLogging
Ceiling
FromBase64String
OutputDebugString
ToString
GetString
Stringmatch
IDispatch
ComputeHash
InsertHash
get_ExecutablePath
SHGetFolderPath
ObfuscatedByGoliath
get_Length
EndsWith
SearchDepth
fhfghj
AsyncCallback
_waitOrTimerCallback
callback
Add_NoLock
ReadColumn_NoLock
FlushFinalBlock
TransformFinalBlock
NetFramework
EqualsGlobal
ExecuteWithThreadLocal
Marshal
TryParseDecimal
GetDomainInternal
ISO_8859_8_Visual
CheckLevel
Set_MinimumLevel
ExternDll
kernel32.dll
PlatformPublicKeyFull
Control
SetMethodImpl
CryptoStream
MemoryStream
ogeSAddaiem
ReadElem
IsNestedFamANDAssem
get_Item
System
SymmetricAlgorithm
HashAlgorithm
ICryptoTransform
Conv_Ovf_U_Un
TEraToken
get_MetadataToken
hToken
lpNumberOfBytesWritten
SystemWebEntityDesign
AppDomain
get_CurrentDomain
OSMajorVersion
Get_CompareAssemblyVersion
CheckPermission
IBuiltInPermission
Application
get_Location
NineRays.Obfuscator.Evaluation
System.Reflection
ParseReflection
ManagementObjectCollection
Position
CallingConvention
RuntimeWrappedException
ThrowNotSupportedException
Ldvirtftn
CanCastTo
GetDynamicILInfo
FieldInfo
_MethodInfo
startupInfo
MemberInfo
ParameterInfo
BlobHeap
StringsHeap
System.Linq
set_ShowInTaskbar
IgnorableSymbolChar
tmFirstChar
NeedFatHeader
MD5CryptoServiceProvider
DESCryptoServiceProvider
MethodBuilder
ModuleBuilder
TypeBuilder
AssemblyBuilder
MemberHolder
lpBuffer
ResourceManager
Debugger
ManagementObjectSearcher
AbsHelper
DefaultComparer
m_returnParameter
get_IsPointer
BitConverter
Importer
EfiRuntimeDriver
ToLower
GetTokenFor
SetError
AssemblyRefProcessor
InvariantTimeSeparator
CurrencyGroupSeparator
ManagementObjectEnumerator
GetEnumerator
.cctor
dotNetProtector
get_IsConstructor
CreateDecryptor
IntPtr
System.Diagnostics
DynamicMethods
GetMethods
M_embeddedRes
System.Runtime.InteropServices
System.Runtime.CompilerServices
System.Resources
dpFkIAcjod.resources
bInheritHandles
AllFiles
EnableVisualStyles
ILLines
InternalWriteAllLines
EmptyTypes
GetMethodCandidates
lpThreadAttributes
MethodAttributes
TypeAttributes
MethodImplAttributes
GetCustomAttributes
lpProcessAttributes
GetBytes
TypeDefs
TypeRefs
AtIdrefs
M_stateFlags
ValidCompareMaskOffFlags
BindingFlags
dwCreationFlags
GetMethodImplementationFlags
SetImplementationFlags
M_initLocals
Equals
TokenAccessLevels
ReadGlobalSymbols
System.Windows.Forms
Contains
get_Instructions
CallingConventions
GetCombinedPatterns
UnclonedLongDatePatterns
EhInfos
SimplifyMacros
get_Chars
M_checkForIllegalChars
EnumMembers
GetOptionalCustomModifiers
GetParameters
get_IsClass
FileIOPermissionAccess
AssemblyBuilderAccess
hProcess
GetCurrentProcess
lpBaseAddress
lpAddress
Get_CurrencyDecimalDigits
Set_Documents
HasEvents
SortEvents
GetRowCounts
SScripts
CachedWinMDStatus
Concat
BadFormat
ManagementBaseObject
GetObject
object
Select
flProtect
CharSet
AddUnitSet
M_RequiredPset
op_Explicit
System.Reflection.Emit
SetCompatibleTextRenderingDefault
IAsyncResult
result
ToUpperInvariant
IsCovariant
IsTransient
System.Management
Get_Fragment
lpEnvironment
get_Current
CheckRemoteDebuggerPresent
IsDebuggerPresent
OnAssemblyResolveEvent
IsEvent
TickCount
ExceptionHandlerCount
Get_SequencePointCount
IsNewSlot
ParameterizedThreadStart
HandlerStart
Convert
StringSort
FailFast
LocalList
SuspendLayout
ResumeLayout
MergedAssemblyInput
Get_Next
MoveNext
System.Text
context
RawModuleRow
ArgumentOutOfRange_Index
IsLeapDay
InitializeArray
ToArray
get_IsArray
Set_Body
set_NativeBody
set_Key
System.Security.Cryptography
Set_Assembly
DefineDynamicAssembly
TryToResolveAssembly
GetExecutingAssembly
BlockCopy
S_Factory
Set_RelocDirectory
UnsafeCreateDirectory
InternalCreateDirectory
lpCurrentDirectory
DelegateEntry
Get_MaxCapacity
op_Equality
System.Security
SuppressUnmanagedCodeSecurity
IsNullOrEmpty
M_property
198 Protector V2
System.Security.Permissions.SecurityPermissionAttribute, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089
SkipVerification
WrapNonExceptionThrows
_CorExeMain
mscoree.dll
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<assemblyIdentity version="1.0.0.0" name="MyApplication.app"/>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v2">
<security>
<requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3">
<requestedExecutionLevel level="asInvoker" uiAccess="false"/>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
dpFkIAcjod
GetEnvironmentVariable
307543842
307524084
347260284
347339519
_ENABLE_PROFILING
_PROFILER
594815558
594835049
31940800
31880716
-27771967
27648174
791922098
791898779
634896504
634817876
-2039251031
2039308888
463170690
463202670
465191181
465250332
-1074449021
1074510004
-1733739553
1733601320
-561835570
561777102
-1383700591
1383700891
2100400597
2100367708
-1023504781
1023539639
-424069900
423948872
2145069263
2145124319
999529267
999546713
-774281078
774256267
-1390013405
1389993355
1609266058
1609262587
-312498050
312494986
1061307931
1061364066
-588548625
588543451
2096043771
2096101316
-90564195
90693669
-650767848
650747221
-934484331
934458895
-420578666
420561964
801215352
801159546
286959350
286946958
-359129769
359037511
-564708704
564722606
-1191302687
1191183997
1224372755
1224350741
-926502157
926484616
-608145575
608142474
1352088614
1352036937
842323003
842320049
-480550300
480551454
-915409211
915454411
-391426442
391477520
-2128827822
2128795462
-12552971
12572310
1837241929
1837247625
-1117564476
1117610551
1698967689
1699021060
916517452
916569240
-1329656861
1329692326
1196897309
1196923663
-66593406
66710911
1697384878
1697457027
-7222321
7101102
318550999
318565413
-2041036441
2040965076
1438851743
1438876978
2078564793
2078554795
-758186765
758129741
1162690897
1162716154
1143036536
1142967113
-1655727838
1655742789
-346945167
346817267
-2050101587
2050002655
578416022
578355983
-1111195120
1111133066
-2007869142
2007794017
-697358399
697415414
988804832
988779731
1140811269
1140725750
-283090101
283069125
672021949
672051160
1480504703
1480496290
-1202262970
1202284994
-1330312832
1330365481
1685129230
1685088531
2054818305
2054898368
2011775966
2011786161
-1710916291
1710811186
-1222879163
1222821299
-2035699263
2035722340
-57619792
57544197
2107603505
2107594316
-507863001
507793191
864904649
864940937
536714868
536734067
1128463785
1128520332
2100706371
2100717047
-256450271
256381286
-1152008037
1152052623
-497959962
497956111
732578955
732571226
-1415557644
1415504656
1452629944
1452627559
1495703880
1495763337
-1036858032
1037008332
-1616977558
1616918132
1717141074
1717108287
-1784395216
1784385336
-282041253
281998562
1321299497
1321306159
1473906525
1473911296
-1495161877
1495240741
-969287024
969306190
1216235234
1216269662
790695323
790736868
-246254567
246230037
1447216012
1447283149
-31566839
31508578
-10406205
10392462
-180910561
180980206
2032247792
2032181944
1157923128
1157918704
250576863
250599620
928943078
928961193
-941580430
941494367
586120027
586113233
-171443261
171609639
1363927066
1363855119
-1615602610
1615689967
2011899061
2011825686
1587619537
1587635058
-445839017
445860412
-1513488661
1513555893
-1969970822
1969966535
575452961
575467137
-2113602367
2113537185
-682399457
682454927
1831522297
1831596963
-869840646
869796785
806091543
806088305
-859375367
859354041
465346661
465324823
2085244658
2085342189
-1722556257
1722565001
607361014
607327402
-1338472848
1338490367
992599518
992601276
-2078228686
2078182214
-1175494319
1175642080
1257977547
1258014515
411558749
411558360
2143857286
2143823709
1113860418
1113945300
-209381802
209430468
-1032067678
1032065807
1767816322
1767818915
-2102164581
2102205293
1407552377
1407568263
1312215638
1312165243
390266315
390265784
973133781
973113097
1696503156
1696478723
-112693802
112675946
-519575874
519714938
1375950340
1375948348
343617504
343611556
1716720425
1716665328
-1414555495
1414588831
1393966815
1393981688
-824211668
824273709
811194781
811177931
-453255160
453383449
-1856003477
1856040061
-1753561630
1753558835
-1436893438
1436881891
-1390077743
1390104091
1706168351
1706184670
-1855646091
1855676776
488887833
488812333
-1136054982
1136129859
131656907
131713164
1302734775
1302759850
-1726357097
1726381145
-1445789844
1445825103
1317285675
1317283574
-212114040
212265235
1297085826
1296994692
-1420390217
1420538725
-19456074
19478841
-1054036865
1053886158
-984103113
984112103
1779930884
1779944116
1681049816
1681057165
-1562035145
1562001926
1816887321
1816851183
1742955205
1742963278
-1924472727
1924525948
-1134209318
1134280681
-261095772
261180170
644760507
644791390
-784771518
784837198
-1013085208
1012956711
734912486
734860203
-45600091
45592781
598930828
598874528
-1335924512
1335947847
99025350
99066386
2135371867
2135421800
786683191
786688920
-86564035
86513281
-1467434802
1467441631
-1127552190
1127547139
420736217
420651232
789313390
789223838
-74402256
74351393
-1304198758
1304284385
-1937392828
1937253678
253802324
253763088
-522456032
522498635
119343173
119398448
-1112711915
1112718638
-482564903
482547799
-289198612
289311764
-1949558358
1949378128
1307110059
1307170282
1602655540
1602667895
345734876
345757373
-134130559
134121770
-1883120135
1883220464
-310160414
310176034
-1745971165
1745879171
1781715033
1781767396
-49421727
49431015
-1719588203
1719590952
-1944311195
1944258208
460813113
460786605
-1357190020
1357197064
937378855
937394390
176590650
176557492
1118152255
1118125498
284531771
284498613
-927841110
927792947
849835703
849821191
2113522209
2113509870
2064701864
2064687540
-625024908
624999216
-969353969
969408080
1690125073
1690156631
-508386232
508306358
-1771755176
1771788114
2054959066
2055009518
-1717998702
1717997469
-1129620699
1129670867
1171949229
1171947773
584493765
584497565
-164484096
164574848
-1937981643
1937947919
-1676828989
1676696196
441207306
441228784
-937518265
937687854
1648352788
1648337450
420630102
420648349
-1708204399
1708372047
-885717971
885584412
1416668256
1416690708
2005682771
2005726121
-1481678962
1481668274
1871909643
1871953870
2045710217
2045715477
-1256264860
1256278395
32779768
32800786
2054959434
2055040874
-300088187
300070651
850810373
850867053
-473977459
474061806
868628815
868726995
-198098686
198171033
-1932841878
1932895039
1505621172
1505563301
2051425459
2051474761
-26244864
26229548
-1958411568
1958259213
-647261470
647256747
-1007475988
1007531619
1501140272
1501103832
72619288
72641055
2130103276
2130110700
-491963033
491832204
-1947984837
1947871376
57894139
57818874
1034880410
1034821881
-2139369497
2139475473
-695058406
695186235
1583919176
1583932941
2117657055
2117632450
-1036054147
1035995130
1811580146
1811585917
1156233635
1156249927
-1034856762
1034917253
-668008576
667962246
1393066452
1393056857
561050777
561114719
-1426166801
1426076236
311296689
311369655
1981225394
1981166617
-446564248
446581429
2115661246
2115668499
-1507602024
1507740333
910135524
910070749
-1382827237
1382812675
-575413865
575460301
367246490
367260731
-347872603
347998620
-1850906590
1850965718
167284637
167347874
812008494
812036592
703424469
703434768
-1908107648
1908025690
-1910679345
1910697183
-1862042852
1862128343
888019064
888085228
-145001998
145041018
-1641249872
1641177216
-224270317
224347550
1002433838
1002431825
-1616523530
1616547025
-1993509637
1993537180
107455699
107414110
-802804254
802704717
-1256221116
1256334676
-462178347
462278778
1816562095
1816586723
967580023
967590256
-1986756900
1986643112
-1624941440
1624961423
118073277
118044548
-1036505403
1036475329
1546293306
1546289051
-692014472
691984445
-1676271293
1676199073
1630248424
1630206353
-1544440281
1544542484
-1840938417
1840803485
1006682115
1006742095
617534041
617533687
-429175763
429236460
1027269372
1027332726
2128977889
2128964606
-2132632492
2132646011
-863033503
863063141
-551431575
551481399
-97333200
97372776
439405437
439388136
1507771717
1507836681
-1737232460
1737330603
4879219
4866568
-1077955407
1077964997
1203752432
1203669714
-2041077208
2041064438
-855659953
855653695
-79131860
78980107
-559667205
559529818
1310521249
1310518059
-694994858
694961120
2032626716
2032624212
-1514938681
1515105163
686805857
686741462
78874851
78808657
1860463498
1860452137
1194165092
1194144861
-371448854
371420909
-631854089
631891163
-1974251098
1974394623
-550143640
550155639
-1668753798
1668706509
804506119
804506110
-2043088124
2043066315
-1482748832
1482729458
-711066231
711167196
-2120490209
2120628199
855598288
855632301
987068616
986991702
-1464641581
1464717977
-570474329
570446839
1659446551
1659460527
-1109226197
1109157886
1859299046
1859288511
-780794
779774
-661401596
661476105
-372324256
372462301
2053841507
2053771767
-1079086182
1079022088
2028458303
2028396196
-67528037
67522486
-1185369222
1185339935
-1322142220
1322184011
-1717072157
1717088120
1631294425
1631307216
529006548
528962676
1843805052
1843883508
-1389638831
1389655382
1308442924
1308379174
-1675956510
1676090519
1223700985
1223708124
-1743599536
1743749464
-425970417
425936657
-560158456
560082439
Area =
{0:F2}
749883460
749882861
-1911060004
1911142588
-727873947
727895939
managed
native
dpFkIAcjod
Select * from Win32_ComputerSystem
Manufacturer
microsoft corporation
bbbbbbbbbbbbbk
mmmmmmmmmmmmmmmmmmmm
bbbbbbbbbbb
87654321
1578602297
1578560095
-2131038157
2131179180
-1204662266
1204580355
Z8D3/RdiHVTrJ5uQaIlh3Mptvnhg/8sw
Z8D3/RdiHVT4b1ZRQPpHLfqZGpF+mTB5
DynamicDllInvokeType
-95439306
95478790
mGkE1/qWQzI=
237320417
237361639
1839649255
1839717109
-434317486
434343145
-1374639048
1374655012
-1351195672
1351132672
-1492337263
1492205268
306868114
306920803
-782125581
782207314
-1166947102
1167005159
1696515219
1696467989
-1766641706
1766606832
960329098
960251208
-1054698150
1054864491
-1447721583
1447769570
-1990660704
1990615880
2112814033
2112856606
1754529908
1754530862
-592765054
592747129
1818682601
1818665690
-2060156556
2060184623
1591621832
1591680064
478936472
478888026
-1148105310
1148178485
1633077724
1633048233
804954816
805016128
341689508
341689852
-1005212658
1005251413
-379142747
379139337
-2127595086
2127645974
5OBgwrbU8XEcqlzI+tdXhQ==
gCsifxgcHVrw+7hd/yEKRqdVAuTWnd9C
upRya09eWXNMCyHYRB2hS8JTkJS3kj+a
t/jIC6AI68M88HSjEmzRgS/KcilRhL++
oJ+MGjO3tlMSx5J3XfaxSQ==
DMp1epBwJgfL9t5QiQaEbVolyO6kiMrJ
KXdKazRCLWAOaOT0HtyN+VFNkjpjtXOG
0rUNoiZ/DXKkO8p4V9GHFqqjWEcoJ8E3
V/K4RQwwRgYhwZsJicvExw==
2E2RWH8QzbNGgYzAAGCx0Q==
F/aFLNAxwq8bXu/V/T5GT1i/6WFLgnI0
MAINICON
Select destination folder
Extracting %s
Skipping %s
Unexpected end of archiveThe file "%s" header is corrupt
%The archive comment header is corrupt
The archive comment is corrupt
VS_VERSION_INFO
StringFileInfo
040904b0
CompanyName
FileVersion
7, 9, 5, 0
FileDescription
Scigpoi
LegalCopyright
ProductName
ProductVersion
7, 9, 5, 0
VarFileInfo
Translation
Antivirus Signature
Bkav Clean
Lionic Clean
Elastic malicious (high confidence)
MicroWorld-eScan Clean
FireEye Generic.mg.257679d1ffeaa47d
CAT-QuickHeal Clean
ALYac Clean
Cylance Unsafe
VIPRE Clean
Sangfor Suspicious.Win32.Save.a
K7AntiVirus Clean
BitDefender Clean
K7GW Clean
Cybereason malicious.4f2bad
Baidu Clean
Cyren Clean
Symantec ML.Attribute.HighConfidence
ESET-NOD32 a variant of MSIL/Injector.VRI
APEX Malicious
Paloalto generic.ml
ClamAV Clean
Kaspersky UDS:DangerousObject.Multi.Generic
Alibaba Trojan:Win32/Kryptik.ali2000016
NANO-Antivirus Clean
ViRobot Clean
Rising Clean
Ad-Aware Clean
TACHYON Clean
Emsisoft Clean
Comodo Clean
F-Secure Clean
DrWeb Clean
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition BehavesLike.Win32.Generic.gh
CMC Clean
Sophos Mal/Generic-S
Ikarus Trojan.MSIL.Injector
GData Clean
Jiangmin Clean
Webroot Clean
Avira Clean
Antiy-AVL Clean
Kingsoft Clean
Gridinsoft Clean
Arcabit Clean
SUPERAntiSpyware Clean
ZoneAlarm Clean
Microsoft Trojan:Win32/Sabsik.FL.B!ml
Cynet Clean
AhnLab-V3 Clean
Acronis Clean
McAfee Artemis!257679D1FFEA
MAX Clean
VBA32 Clean
Malwarebytes Clean
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Tencent Clean
Yandex Clean
SentinelOne Static AI - Malicious PE
eGambit Unsafe.AI_Score_99%
Fortinet MSIL/VRI!tr
BitDefenderTheta Gen:NN.ZemsilF.34236.Em0@a4bHVTai
Avast Clean
CrowdStrike win/malicious_confidence_100% (W)
MaxSecure Trojan.Malware.300983.susgen
No IRMA results available.