Static | ZeroBOX

PE Compile Time

2021-10-27 20:38:37

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x000581f4 0x00058200 6.29909894402
.rsrc 0x0005c000 0x00006456 0x00006600 5.65194374013
.reloc 0x00064000 0x0000000c 0x00000200 0.101910425663

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x000619f4 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x000619f4 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x000619f4 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x000619f4 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x000619f4 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x000619f4 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x000619f4 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x000619f4 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_STRING 0x00061e5c 0x00000178 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_GROUP_ICON 0x00061fd4 0x00000076 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_VERSION 0x0006204c 0x00000220 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_MANIFEST 0x0006226c 0x000001ea LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with CRLF line terminators

Imports

Library mscoree.dll:
0x402000 _CorExeMain

!This program cannot be run in DOS mode.
`.rsrc
@.reloc
HS$`@#
wQ'@f@#
[M^f@#
.#t_@#
.%qai("
@[@Y(q
[YZ_bX
[XZ_bX
[XZ_bX
[XZ_bX
#Qofme
[YZ_bX
[XZ_bX
[XZ_bX
[XZ_bX
[XZ_bX
[XZ_bX
[YZ_bX
[XZ_bX
[XZ_bX
[XZ_bX
[YZ_bX
[XZ_bX
#ey~jy
#D EE~U
[XZ_bX
[XZ_bX
[XZ_bX
[XZ_bX
#W^{dM
[YZ_bX
[XZ_bX
[XZ_bX
[YZ_bX
#SQOo.
[XZ_bX
[XZ_bX
[XZ_bX
[YZ_bX
# J46V6
[YZ_bX
[XZ_bX
[YZ_bX
[XZ_bX
#_s1g=
@R@X(q
#8*s+K
[YZ_bX
[YZ_bX
[YZ_bX
[YZ_bX
[XZ_bX
[XZ_bX
[XZ_bX
[XZ_bX
[XZ_bX
[XZ_bX
[XZ_bX
[YZ_bX
[YZ_bX
[XZ_bX
[XZ_bX
[XZ_bX
#T9Y;
#l6Kj;
@p@X(q
[XZ_bX
[XZ_bX
[YZ_bX
[XZ_bX
#;G3Sg
#<Mw#^>
[YZ_bX
[YZ_bX
[XZ_bX
[YZ_bX
[XZ_bX
[YZ_bX
#F.p(P
[XZ_bX
[YZ_bX
#RMdV2
#%+=ymy
pq@X(q
[YZ_bX
[XZ_bX
[YZ_bX
[XZ_bX
0p@Y(q
eai&&*
[YZ`(^
[XZX(m
[XZX(m
[XZX(m
#*IO%[H
[YZX(s
[XZX(m
[YZX(m
[YZX(m
[YZX(m
=vK_aiY
ymiaiYea}
efXaYeff
PaieXeX
p:{~AZ(q
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
PADPADP
}Y?7Pp
WZ[R~,
%'o;FM
l'"\0t+
}tzff
)OM<\p
n95$FPH
SMO_Q:
w!#x+8ZyM
tyIp/=
(MKOTeeE
UbGyq.
>!k~\69#
7.1}^
z9:,M+
D)bN<.
AoQ)abj
YiJ|Q4
a~twPBG
p=>LE_
ND).*[
bE%v-I
`Rj@gl
\P7TuM
fOzzJ1
40lvD9
,ue47}
>l$33b
Aah*;`
#V(x@)O
M9,R2<
h(-,Um
iGLxWb^w
"dR7TL
l]<^wk
`OwB]}
f_,ry#
/s3!}E
+}8heS}
q@CW`|:!
yTO5h-D
$F_GAoS
I+&?Rp
/1e8GE
%G+}GJE
HtQG#
B-l>^*
Xr_&d(
'.k~FU
2n:FV QA
o#7,"Y
C(CRX.
GF.YxDQ
Z=np.
`foT4!cs
DYZ4`'
HN8s,X
m<o8d8|M
sy6<Kk
GN4w 5
6%A.0We
}!m|IH
+<eZBv
5c?rbV"b
-I>clU
5DJ@p^cDW'I
aJckqW,D9
iJ30z%
*\t$F/
CsR^+1
/;i9fe
e;|W[
MLb$RL
dLJ%`#
XO~WNS?
HO9xS^
WDLcv;
bfNo?)
>V>Y>"
l!NR.e
J,CnX]
*i1B{W
e(h0[s!,]
}hnTZB
XQzt~b
9ZV. A~
I``=6W2
Py@_v?'
2~92.|
d] d\F\J
o&J%Z*
Q0!n8n]
s-oUl%
M`M/=@{g
Xp4E=\3
'DZ>04
UX;=NX
ZTG:K.y
"'`)T!
y+9&nNM
W>hONI~
M2~*C`-
Xz]uJ(
$B@;fy
pUdn%C
Ry"'MJ
L:EonJ
_JLz~_
>3VoDl%
9<|s<uQ
'@-^N
"V%d7Y
>T%svY
W,D8Bv
GT9qV+
V5SfqF
y`Y:,j
jlQg8!
mgek"e
kJ5{VE
T|;:db
b^/uCYd
HU00SI/L
f\6t}x
Ex~Hn~
'cK]16L
/}e:sL
|c%%$=
SnZct:
^X(!H?
bgGaB5M
@!]h,!P"
ewHPni
":; kiN
V#m*4kU
u=-Wv1
}w=C3u
GcUe!x
Wj#^hC
o;<m!@<n
DDG{E
~+ oc]
Dg>y]9
7)h8Xx
Vxt6Ot
0<,OqJ
z(wfBI
x4T_[p
65@cBR
YVk/UM
&7r/e[K
%YXp[g
P:gyv\F
WoK!db,
rOw47.iJ
$w>&;|
ZH!<$~
4mrUGff
`&{}H-X
~"V;O%P5?
f?`\|
4g(_Rq/
F:"1Y4
Fzz7[[
LjIHc[
k<Z'O(=
:/h@^ike
J]i>"(Q
oFz<*Y
#MM=<}v@Y8
E~W8(W
:76owo
usf!C9
w@Au%20
"pGjUn
!R}P<}
'G%BHB
#@|9J+Tx
v4.0.30319
#Strings
#gdfg#
#gsdfg#
#fsdfsd.dll#
#hsd.dll#
#fsdfgdddddfchafhghgsdf.dll#
#sf.dll#
#fafg.dll#
#hdfh.dll#
#agsh.dll#
#adas.dll#
#js.dll#
<IterateAllReverse>b__0
IEnumerable`1
Rows`1
IsWhiteSpaceLatin1
WriteTypeDefAndMemberDefCustomAttributes1
ToUInt32
ToInt32
<exts>5__2
Func`2
GetAddressField2
$$method0x600427a-3
<enumerator>5__3
<GetExtraMonoPaths>d__55
ToInt16
LOCALE_SMONTHNAME6
LOCALE_SABBREVMONTHNAME8
get_UTF8
Ldc_I8
<Module>
ResetRVA
CANNOT_BE_CANCELED
Get_ID
Serialization_NoID
listMethodSpecMD
LOCALE_SNATIVECURRNAME
Get_IMEASURE
S_INLINESITE
nIprndoodbF
OPEN_EXISTING
STATE_FINISH
get_ASCII
SZArrayHelper_HACK
IFIRSTDAYOFWEEK
READ_CONTROL
GetHebrewDayOfNM
GetDayOfYM
System.IO
IsMemoryMappedIO
DEFAULT_SPIN_SP
Win32NT
LOCALE_SPARENT
UNICODE_PLANE01_START
ORDER_MDY
LOCALE_SPOSINFINITY
Get_DefaultQuota
mscorlib
_LoadCertFromBlob
IsTypeSpec
hgdfgdfgc
FindMostSpecific
System.Collections.Generic
get_IsStatic
_fallbackLoc
InternalAlloc
<>l__initialThreadId
Get_HashAlgId
GetProcessById
lpNumberOfBytesRead
hThread
Get_CurrentThread
get_CurrentThread
thread
InternalLoad
RijndaelManaged
get_IsAttached
NtaSizeParamIndexSpecified
ResourceManagerInited
Inherited
HasShutdownStarted
SeekNotSupported
DomainInitialized
Uninitialized
Synchronized
gdfgdfghfgd
Log2Rid
SetRid
IsSystemVoid
<Variables>k__BackingField
GetSourceStartEnd
set_IsBackground
DynamicMethod
DefinePInvokeMethod
ResolveMethod
Get_DeclaringMethod
GetMethod
NetGuard
get_IsInterface
Replace
TypeNamespace
SecurityControlEvidence
DataSource
LoadResource
FindResource
CreateResource
SizeofResource
GetHashCode
SetCode
set_Mode
CryptoStreamMode
CipherMode
Xenocode.Client.Attributes.AssemblyAttributes.ProcessedByXenocode
ResetCache
EndInvoke
BeginInvoke
CreateHotTable
GetEnvironmentVariable
Enumerable
IDisposable
Hashtable
set_Visible
TryParseDouble
get_Handle
RuntimeFieldHandle
get_MethodHandle
RuntimeMethodHandle
GetModuleHandle
get_TypeHandle
RuntimeTypeHandle
CloseHandle
GetFieldFromHandle
GetTypeFromHandle
Console
ParseExactMultiple
get_Module
DefineDynamicModule
ResolveModule
ReaderModule
set_FormBorderStyle
get_Name
EnglishEraName
AddName
m_strModuleName
HashSizeName
lpApplicationName
M_textInfoName
DisplayName
AssemblyName
lpCommandLine
WriteLine
GetMachine
DocType
get_FieldType
Get_ResourceType
DefineType
CreateType
ValueType
get_DeclaringType
CatchType
ReadMarshalType
Get_EncodedEnumType
MetadataColumnType
flAllocationType
get_ReturnType
get_ParameterType
MakePointerType
Get_RetType
System.Core
ResolveSignature
SetLocalSignature
Get_IsInvariantCulture
GetCapture
MethodBase
Dispose
Truncate
CreateDelegate
MulticastDelegate
set_WindowState
FormWindowState
UnsafeDelete
WaitForCallbackToComplete
IsDebugSatellite
STAThreadAttribute
CompilerGeneratedAttribute
UnverifiableCodeAttribute
UnsafeValueTypeAttribute
BabelAttribute
SuppressIldasmAttribute
AssemblyInfoAttribute
YanoAttribute
DotNetPatcherPackerAttribute
BabelObfuscatorAttribute
CryptoObfuscator.ProtectedWithCryptoObfuscatorAttribute
DotNetPatcherObfuscatorAttribute
DotfuscatorAttribute
CompilationRelaxationsAttribute
ContractClassAttribute
SmartAssembly.Attributes.PoweredByAttribute
RuntimeCompatibilityAttribute
SetValue
M_arrayValue
DisallowPublisherPolicyValue
get_IsAlive
bgrcpomchr.exe
get_Size
dwSize
IsBaseOf
SizeOf
fsafafwwwwwwwwaf
fshjkkgdf
get_IsByRef
HasSemanticTag
TryGetValueTypeSig
SentinelSig
System.Threading
Encoding
IsLogging
CaselessMatching
Ceiling
Set_IsNoInlining
FromBase64String
EndOfString
OutputDebugString
ToString
SerializationInfoString
GetString
EnsureHostString
FtLastWriteTimeHigh
ComputeHash
get_ExecutablePath
CanonicalizeAsFilePath
ObfuscatedByGoliath
get_Length
IsAscii
fhfghj
AsyncCallback
Get_EncoderFallback
callback
S_dontrunhack
UpdateStack
FlushFinalBlock
TransformFinalBlock
Set_FirstDayOfWeek
TicksMask
DeclareLocal
GetLocal
AddFieldMarshal
EntityDecl
InternalCancel
Set_IsInternalCall
Get_IsCallConvFastcall
kernel32.dll
Control
AddPermissionImpl
CryptoStream
HotHeapStream
MemoryStream
get_Item
System
SymmetricAlgorithm
HashAlgorithm
IsAssignableFrom
ICryptoTransform
ArgumentOutOfRange_NeedNonNegNum
DWORDFromBigEndian
TryParseTimeSpan
get_MetadataToken
hToken
set_OriginalToken
Get_PublicKeyOrToken
SetToken
HebrewToken
lpNumberOfBytesWritten
AppDomain
get_CurrentDomain
ReadColumn
Application
get_Location
GetInstantiation
GetUserObjectInformation
NineRays.Obfuscator.Evaluation
System.Reflection
ManagementObjectCollection
M_restriction
GetInstruction
CallingConvention
RuntimeWrappedException
RankException
Get_NumberNegativePattern
NormalizeSearchPattern
SendTo
GetDynamicILInfo
FieldInfo
MethodInfo
M_registrationInfo
DefToInfo
startupInfo
MemberInfo
ParameterInfo
EntryInfo
Get_TimeDateStamp
System.Linq
TryGetGenericVar
set_ShowInTaskbar
Get_DataMember
IColumnNumber
ImageFileHeader
IsBigHeader
Get_SizeOfOptionalHeader
StreamHeader
MD5CryptoServiceProvider
DESCryptoServiceProvider
MethodBuilder
ModuleBuilder
TypeBuilder
AssemblyBuilder
lpBuffer
ResourceManager
Debugger
ManagementObjectSearcher
custMarshaler
MutexTryCodeHelper
GetMethodSpecSigHelper
GetLocalVarSigHelper
Get_Comparer
ImplMapUser
get_IsPointer
BitConverter
ToLower
bgrcpomchr
GetDemandDir
GetTokenFor
Set_SupportsLastError
CurrencyDecimalSeparator
ManagementObjectEnumerator
GetEnumerator
.cctor
dotNetProtector
get_IsConstructor
CreateDecryptor
HasParamPtr
TypeIntPtr
System.Diagnostics
PreserveRids
get_PreserveStandAloneSigRids
GetMethods
System.Runtime.InteropServices
System.Runtime.CompilerServices
System.Resources
bgrcpomchr.resources
Get_Overrides
VTables
bInheritHandles
EnableVisualStyles
EmptyTypes
Get_Attributes
lpThreadAttributes
MethodAttributes
TypeAttributes
MethodImplAttributes
GetCustomAttributes
lpProcessAttributes
GetBytes
S_legalBlockSizes
CodeStartOffs
GetNativeCompareFlags
BindingFlags
dwCreationFlags
GetMethodImplementationFlags
SetImplementationFlags
extraMonoPaths
Equals
HotPools
<>3__tpwItems
System.Windows.Forms
Contains
ReflectionExtensions
CallingConventions
Options
Exceptions
get_AllLongTimePatterns
FileDefInfos
GetEventProps
Get_HasForceTwoDigitYears
get_Chars
GetOptionalCustomModifiers
GetParameters
Anchors
get_IsClass
DigitClass
FileSecurityStateAccess
CanAccess
AssemblyBuilderAccess
GetRegistryKeyAccess
hProcess
GetCurrentProcess
PdbAddress
lpBaseAddress
dnlib.DotNet.ISignatureReaderHelper.ConvertRTInternalAddress
lpAddress
GenericArguments
CrossScopeImports
S_LDATA32_16t
Concat
Format
ManagementBaseObject
m_continuationObject
GetObject
object
Select
flProtect
M_strProduct
PermissionSet
CharSet
DTDSubset
Offset
InternalWait
op_Explicit
System.Reflection.Emit
SetCompatibleTextRenderingDefault
IAsyncResult
TrySetResult
result
ToUpperInvariant
InitInvariant
SystemDataOracleClient
System.Management
lpEnvironment
ReadNamedArgument
get_Current
CheckRemoteDebuggerPresent
IsDebuggerPresent
M_kernelEvent
M_localCount
DecrementAssertCount
ParameterizedThreadStart
Fxassert
Convert
FailFast
FindLast
GetParamRidList
GetEventRidList
CheckList
ContainsFaultList
_capslist
InternalMatchTimeout
SuspendLayout
ResumeLayout
MoveNext
System.Text
Set_LogicalCallContext
context
Get_CharUnknownLow
RawParamPtrRow
M_throwOnOverflow
AllButOverflow
DontKnow
UnescapeAllOrThrow
Get_Syntax
M_headIndex
MatchIndex
M_startIndex
M_maxIndex
C_versionValuePrefix
Wednesday
ToArray
ToBase64CharArray
get_IsArray
Currency
set_Key
SilverlightPublicKey
System.Security.Cryptography
Set_Assembly
DefineDynamicAssembly
GetExecutingAssembly
DefinitionAssembly
IsAssembly
NameAndPublicKeyTokenOnly
Get_ReflectionOnly
FindAssembliesGacExactly
CheckDeny
Memcpy
BlockCopy
lpCurrentDirectory
op_Equality
System.Security
SuppressUnmanagedCodeSecurity
IsNullOrEmpty
198 Protector V2
System.Security.Permissions.SecurityPermissionAttribute, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089
SkipVerification
WrapNonExceptionThrows
_CorExeMain
mscoree.dll
wwwwwwwwwwwp
wwwwwwww
p((((((((
(wwwww
(wwwww
((((((((ww
wwwwwp
p(((/(/
p((/((w
p/((((w
Xgggggggrrrrrrrrxxxxxxwwwwwvvvvuuqqqt
RR7QQ44444
>=##$!
X-..,,B
%#$!!
X//-.C,,+
%#$!!
D/--C,B+
=#$$!
//-.C,B+
%#$!!
,B+HHHHHHHGGGGGGG
^^PO65NLJIIdcbb`5MNKLJJII
DL--C,cyo`H@N&&JG!!
j22337E^11
ND/-.d{yaH)N?&LG#$!
j__22R
D/f|{bH
M(?LG=%$!
jFF_2SR7QPO65NLJf}|bHB`C(KG
f~}cH,`sCNH'
=%#!!
E^1effd/.azoNH)@
hFF__2Q
//b{zMH
ihUTSR7QPO65NLJIIba`MB+
FFR_22
BBI)@'
FF__2O
TSR7QPO65NLJIIIIII,+
I-C,B+4t
RFF__25
I/-.,B4t
iihUTSR7QPO65NLJII
/-C,4t
YYWWiihUTSR7QPO65N
YYYYYYWWiihUTSR7QP_2
iiVUTS
jgggrxxvut
jiiVUTS
j(?>";9v
j(('";w
j(()$x
<<<<mmnn\\\]]]lll[[[ZZZkkkkjg
\utsrqppppppppppppppppppp
,,,,,++**
\!!!!9
^$$EFDC--B??????????
^'%I%%%
C;;Bn?
h((J&&&'D%%-n?
KMJIGED&Cn?;<An?
Dn?-BAn?
==Jd)En?('-n?!"
_nnQP0NLMJ
(Cn?#:"
d)(&%$#
NKMJIGE.&%
n=dE(&
QQP0NLMJd
X11STQP0
gYYVWUhuuuttsp
kkkkclllmm``abbjjj
@@@@@@@@@@@@A
G8210/-+)
F>"BBBBBB
*AtvvvvwwwxxBB
,Asyyyyyyyyx
.Amyyyyruw_wBB
Aqltuul`ucw
B$;1Agyl]i]kndw
<CA]yZi]skjyvUB'=DAe[h^mofaYvBB?E3AbhegyZff\vVQGAAAbyyyyyyyyv
b^e]gpqmst
KLMNO57
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<assemblyIdentity version="1.0.0.0" name="MyApplication.app"/>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v2">
<security>
<requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3">
<requestedExecutionLevel level="asInvoker" uiAccess="false"/>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
bgrcpomchr
GetEnvironmentVariable
-5416990
5497510
_ENABLE_PROFILING
_PROFILER
274233952
274215638
1337749479
1337744291
-910173135
910238774
1770692802
1770756848
-881174866
881117092
-1276639241
1276482434
657708487
657679768
660915344
660909109
399254863
399297242
-1125550807
1125438860
-1868617056
1868585323
-1715069886
1715072791
-372196501
372226736
-1505974611
1505943705
1350626068
1350584899
1124027143
1124021685
-649958249
649943462
-181016552
181115159
-125512483
125451003
-2132172810
2132226510
1507262040
1507309504
-2059618836
2059557420
-868523311
868636454
-95265590
95207744
775863829
775865938
-1355745552
1355722144
-1207637591
1207578489
99134449
99102110
1267778269
1267759760
-1759570155
1759616431
-829430624
829541972
170776186
170769600
142346712
142397516
1377948829
1377911458
1943665428
1943651517
-1700829969
1700883268
-743561152
743568482
1361247138
1361283743
-490178598
490168945
98573008
98616162
-1738973676
1738959095
510139250
510190846
-390567935
390507518
1907833134
1907832154
-1757657985
1757559703
287214743
287282303
1609306815
1609384626
-304786802
304649348
-1522860387
1522833626
-1296473967
1296451419
-1814214826
1814275496
1876031843
1875970867
2022249442
2022305065
326296555
326249966
-2095025468
2094967891
491597574
491603712
568542081
568541087
1237191443
1237257778
2142738984
2142640333
2073247164
2073258864
1940864972
1940811216
-975118502
974991983
351294569
351350930
-1557089832
1557006709
-31595780
31681209
-915218010
915179204
-1660383612
1660293157
-181776230
181710771
957103295
957145064
1181212584
1181123253
-373617274
373618477
1082214545
1082229670
-725357312
725385412
1091092190
1091089278
-1250321121
1250388126
-289415178
289496233
-609128283
609022826
1575636779
1575711323
436697593
436633516
-1886334940
1886206692
918176170
918250094
-45579633
45582767
-1384141779
1384187792
-1537720764
1537579777
-487664265
487601354
-1710145320
1710138597
1997063786
1997044697
-1771571284
1771669122
885577390
885632458
1788699164
1788709684
1637913471
1637938533
-94814126
94845786
515330698
515311944
-568528001
568521401
-630132028
630109901
-586639323
586606394
1828568958
1828565899
682365685
682390747
-876193046
876117679
-621769081
621721350
2008089513
2008035437
-2133005251
2132973324
1201152930
1201239459
688244252
688173958
1787317113
1787352940
1938614239
1938678306
252533372
252510778
-1941209155
1941223937
-689824341
689731070
-1942452661
1942413451
2006089213
2006144537
649282587
649272559
-1318389167
1318564309
1907002779
1907010919
-641963974
641973929
-398823430
398802128
1830476437
1830465281
-1658769203
1658743226
1466543999
1466483965
-1220242879
1220212395
-14442059
14453940
-1682125893
1682155786
-1828164960
1828115024
-1975005115
1975058055
-33742493
33816461
2078975993
2078940602
-940189442
940239198
-711326627
711322395
-1097906680
1098032712
-1160245029
1160233515
-1127567807
1127605652
-297191050
297072928
-2069253929
2069245299
-1933560950
1933516591
-406687761
406594037
-451272506
451378079
1476369374
1476327097
-274095213
274109379
-615332041
615331498
-1845532514
1845566974
-1193525680
1193505649
-2117018552
2116961162
1003696581
1003722992
1748667032
1748692791
-1827768721
1827674934
-421306197
421359532
-612553488
612563760
1036618870
1036591999
-1973316881
1973358037
422057950
422136887
-1056654935
1056625533
25793907
25736517
-2009240028
2009121076
2067861392
2067922836
409980034
409900122
-178412443
178457418
807128472
807117574
1901145446
1901196153
-2100045087
2100038116
2012378882
2012476843
1359786021
1359862552
-600895718
601027954
-2030810968
2030814200
-403987989
404031101
380138022
380141361
-684626885
684673031
-633297251
633158774
-536526134
536525029
287950352
287911296
-438562986
438453646
-31974112
31908689
316201377
316162948
1203941592
1204021536
1496760832
1496773525
-1335079126
1334947046
634631682
634553555
-1332523626
1332566072
-688780378
688752464
426760617
426727740
966337874
966346005
399706807
399720524
884374176
884389132
1878053185
1878105319
-1402714219
1402643308
-1161668774
1161645379
-1298151889
1298221996
1798576275
1798596302
827114679
827184686
1037715526
1037759456
-271706301
271685500
-284517110
284462701
-170319546
170367733
303488598
303454019
1541626202
1541625335
-820446207
820454894
864276135
864246303
-531850769
531825803
-1798666976
1798680018
1173874876
1173856283
-971624039
971609753
-1172497032
1172520924
-1837663691
1837655472
-2000959988
2000987567
-1869054761
1869030992
2024246517
2024183447
570786923
570803383
-329190014
329174030
708579419
708640812
-305176077
305243874
1583525476
1583483325
636296294
636340977
-2035727911
2035779819
1668815425
1668823237
235857145
235825371
-1179502956
1179419443
525499332
525564658
-739823183
739949434
1614070813
1614141739
-557919320
557884247
1894539774
1894553439
-439498049
439588300
-2066826623
2066840655
284316096
284313705
-150302464
150275570
1361339776
1361348357
360567462
360487318
-805219210
805176755
-126421485
126376795
889383001
889379971
-380155356
380186869
114091629
114146554
-2011063121
2011054924
1560185107
1560182110
487712070
487692768
1226734007
1226732184
535808426
535774835
-421435524
421516261
-285819366
285795459
-6846788
6912859
1790926184
1790910570
783566952
783632680
-1898217912
1898374912
2032358160
2032301542
-2084982650
2084970458
-1143603542
1143483892
680634777
680612603
1685883630
1685978550
875190307
875289068
669328054
669356263
2058001436
2058067154
-1910363433
1910253951
-954444600
954315640
-2082153972
2082102551
48112911
48110723
1837306028
1837332599
-453391443
453411308
-2071669823
2071664113
-349463511
349532394
-1044784041
1044671122
873167114
873173819
447677662
447687792
-430061732
430138480
-1919473236
1919548585
784605432
784607680
-1053421080
1053514477
2116636382
2116637401
1053054368
1053096301
-1459537448
1459536994
-1140205
1052268
-1283974924
1283819950
1472818133
1472809992
890565269
890552198
1855666644
1855700356
1858091146
1858096898
-16915036
16983493
657875045
657854596
-1400745937
1400713409
-1162469536
1162476238
-1385726450
1385701716
-646189158
646346039
1319972358
1319991707
-1697069334
1696924392
1801937576
1801971237
-194319803
194267380
-1883143720
1883236432
-914536433
914408339
146620970
146569004
1560127866
1560134890
-1908824567
1908932336
-1034543526
1034663398
-2091150208
2091218225
-1028163138
1028211922
1668215804
1668157716
-1532324641
1532360444
-437924431
438022642
-584649904
584810105
-1075099589
1075170386
-2081065911
2081067029
1807401386
1807362941
-2059007223
2059127842
-1049708285
1049844102
1439552995
1439483089
-1773777388
1773673117
-469195946
469177997
-1780467436
1780418087
-1545127493
1545114581
-115880833
115968461
595518248
595504601
1982973113
1982909918
604472139
604447082
78226456
78214305
1855646508
1855629283
633615387
633697573
-512850443
512778068
1478920662
1478892888
-457033213
457121087
873399651
873405861
357674409
357657177
69448320
69423137
-251077126
251067351
140424285
140478398
671314132
671348223
1218294412
1218279810
1691210899
1691161992
1654754147
1654751931
-724266854
724255231
231179304
231119600
1499329650
1499322786
2019445014
2019544962
-1886253284
1886193998
993821766
993845438
-307170065
307140269
-1023294695
1023359057
1541592938
1541542450
1146423978
1146473941
-427684056
427627330
1938831147
1938870851
190743670
190831327
844253440
844322429
-625867405
625986879
-339250974
339296544
896334687
896317435
276550690
276504218
-1193435970
1193474933
223101245
223088022
-895220644
895155573
-2121245411
2121258611
-220782480
220791841
-1687394534
1687281959
756614539
756557858
-1519754369
1519772814
934207298
934195257
-1905063644
1905035550
-1608170859
1608136386
-1791327491
1791322380
-1255231565
1255227052
-144785228
144783366
499343140
499338663
269794431
269767875
-2079154250
2079108493
-1528535542
1528484258
-631173377
631116322
-632081578
632097433
-1505194805
1505040799
-236047818
236038222
918129538
918064898
1968304865
1968263449
-478465570
478433824
-947177762
947243549
2065501736
2065527471
34646021
34635077
-701408853
701367340
331876973
331900942
-1735293288
1735351195
-676062937
676008455
-1340117898
1340180072
592505295
592504914
541416363
541455916
334071269
334027079
1565104177
1565048882
6862699
6850352
-1248883658
1248937931
496099383
496071143
-347094383
347205656
-234190055
234345193
-1895159323
1895248637
-636925304
636902856
214229337
214236319
620379822
620441395
1022807146
1022817247
-167196953
167231183
Area =
{0:F2}
1836296976
1836248931
managed
native
bgrcpomchr
Select * from Win32_ComputerSystem
Manufacturer
microsoft corporation
bbbbbbbbbbbbbk
mmmmmmmmmmmmmmmmmmmm
bbbbbbbbbbb
87654321
-788880989
788799089
786293235
786266222
-1725728151
1725742048
-214367533
214231649
VFFx73GSUaMxJlFoSS039mcVTYndBCJY
58846279
58788843
VFFx73GSUaNRaPOJdAD/U2mveRpF38SD
DynamicDllInvokeType
-1528420294
1528374022
GgKJ4dkSelg=
-663937369
664010190
879359851
879343036
-171647109
171653703
-710798660
710781289
-774378
695438
-1331981338
1332037246
1380446312
1380435829
1274874483
1274828299
1546860526
1546860536
1711386297
1711362088
-878465954
878472668
1145882242
1145880841
105521075
105560598
-1354490716
1354399965
-1731421274
1731351437
1624564203
1624542012
1168728108
1168662895
380574249
380527005
-1965705394
1965784001
2062506036
2062429892
-747902481
747916033
-1981381970
1981298432
193649162
193615185
411570667
411598434
-601093124
600956056
2116957210
2116948448
1903313083
1903318177
-1062622767
1062511052
802993256
802970733
H8B8h2T1gdQ2sj1AYYeu3Q==
WZj/fJYBuX4KcY/H9aa3fhg5EYdLSbtM
1DHOwXmpeG5rV7OhiUsicCM7D0rI4uyL
YeOuO8XXL5gQzUdT3sFj5+018rDfsDdT
RVU8evjZ25m/fdVLl26vqA==
SS2s2s71Zj5NCA/800Go4IUCK0MFxCYh
iIzYmaKqsaPlzZZxioGHyeWNyulx2CGY
LXqe/NrFkSL4t+kEa1i6kt4/P4+EwxWn
LVrF2ysyraxRR+f+yMldKw==
lwsisIutPGbA1VVHgPxnjQ==
WHR7CdrjE6C2VQiYHteI1BRxyS+uHC1U
MAINICON
Select destination folder
Extracting %s
Skipping %s
Unexpected end of archiveThe file "%s" header is corrupt
%The archive comment header is corrupt
The archive comment is corrupt
VS_VERSION_INFO
StringFileInfo
040904b0
CompanyName
afSASo
FileVersion
4, 7, 7, 4
FileDescription
ligkIghr
LegalCopyright
ProductName
heaImASm
ProductVersion
4, 7, 7, 4
VarFileInfo
Translation
Antivirus Signature
Bkav Clean
Lionic Clean
Elastic malicious (high confidence)
MicroWorld-eScan Clean
FireEye Generic.mg.fb0d1d127da05d10
CAT-QuickHeal Clean
McAfee Clean
Malwarebytes Clean
VIPRE Clean
Sangfor Suspicious.Win32.Save.a
K7AntiVirus Clean
BitDefender Clean
K7GW Clean
Cybereason Clean
BitDefenderTheta Gen:NN.ZemsilF.34236.xm0@a0uINeci
Cyren Clean
Symantec Clean
ESET-NOD32 a variant of MSIL/Injector.VRI
Baidu Clean
APEX Malicious
Paloalto Clean
ClamAV Clean
Kaspersky VHO:Backdoor.MSIL.Blakken.gen
Alibaba Clean
NANO-Antivirus Clean
ViRobot Clean
Tencent Clean
Ad-Aware Clean
Emsisoft Clean
Comodo Clean
F-Secure Clean
DrWeb Clean
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition Clean
CMC Clean
Sophos ML/PE-A
SentinelOne Static AI - Malicious PE
GData Clean
Jiangmin Clean
Webroot Clean
Avira Clean
MAX Clean
Antiy-AVL Clean
Kingsoft Clean
Gridinsoft Clean
Arcabit Clean
SUPERAntiSpyware Clean
ZoneAlarm Clean
Microsoft Trojan:Win32/Sabsik.FL.B!ml
Cynet Clean
AhnLab-V3 Trojan/Win.Agent.C4734961
Acronis Clean
ALYac Clean
TACHYON Clean
VBA32 Clean
Cylance Unsafe
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Rising Malware.FakeXLS/ICON!1.6AC3 (CLASSIC)
Yandex Clean
Ikarus Trojan.MSIL.Injector
MaxSecure Clean
Fortinet Clean
AVG Win32:InjectorX-gen [Trj]
Avast Win32:InjectorX-gen [Trj]
CrowdStrike win/malicious_confidence_90% (W)
No IRMA results available.