Static | ZeroBOX

PE Compile Time

2021-10-29 19:25:49

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x00077804 0x00077a00 6.89827026389
.rsrc 0x0007a000 0x00028fea 0x00029000 7.43736161437
.reloc 0x000a4000 0x0000000c 0x00000200 0.0815394123432

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x000a24fc 0x00000468 LANG_FAEROESE SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x000a24fc 0x00000468 LANG_FAEROESE SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x000a24fc 0x00000468 LANG_FAEROESE SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x000a24fc 0x00000468 LANG_FAEROESE SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x000a24fc 0x00000468 LANG_FAEROESE SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x000a24fc 0x00000468 LANG_FAEROESE SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x000a24fc 0x00000468 LANG_FAEROESE SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x000a24fc 0x00000468 LANG_FAEROESE SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x000a24fc 0x00000468 LANG_FAEROESE SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x000a24fc 0x00000468 LANG_FAEROESE SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x000a24fc 0x00000468 LANG_FAEROESE SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x000a24fc 0x00000468 LANG_FAEROESE SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x000a24fc 0x00000468 LANG_FAEROESE SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x000a24fc 0x00000468 LANG_FAEROESE SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x000a24fc 0x00000468 LANG_FAEROESE SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x000a24fc 0x00000468 LANG_FAEROESE SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x000a24fc 0x00000468 LANG_FAEROESE SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x000a24fc 0x00000468 LANG_FAEROESE SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x000a24fc 0x00000468 LANG_FAEROESE SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x000a24fc 0x00000468 LANG_FAEROESE SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_STRING 0x000a2964 0x00000178 LANG_FAEROESE SUBLANG_NEUTRAL data
RT_GROUP_ICON 0x000a2adc 0x00000092 LANG_FAEROESE SUBLANG_NEUTRAL data
RT_GROUP_ICON 0x000a2adc 0x00000092 LANG_FAEROESE SUBLANG_NEUTRAL data
RT_VERSION 0x000a2c04 0x000001fc LANG_FAEROESE SUBLANG_NEUTRAL data
RT_MANIFEST 0x000a2e00 0x000001ea LANG_FAEROESE SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with CRLF line terminators

Imports

Library mscoree.dll:
0x402000 _CorExeMain

!This program cannot be run in DOS mode.
`.rsrc
@.reloc
_aiaff}
@@@Z(y
@S@Y(y
avwg@#
^@Y(y
@^@[(y
`S@X(y
@S@X(y
#v#CB(*e@#
@N@X(y
rK_jc@#
`Q@Y(y
@V@Z(y
@B@[(y
@Y@Y(y
7beb@#
R<Q@#
@I@Z(y
[XZ_bX
[XZ_bX
[XZ_bX
[YZ_bX
#a5y{Q
[XZ_bX
[YZ_bX
[XZ_bX
[YZ_bX
[YZ_bX
[YZ_bX
[YZ_bX
[XZ_bX
#8o!+o
#:KPj[
[YZ_bX
[XZ_bX
[YZ_bX
[XZ_bX
[XZ_bX
[YZ_bX
[YZ_bX
[XZ_bX
[YZ_bX
[XZ_bX
[XZ_bX
[YZ_bX
#zF_H
[YZ_bX
[YZ_bX
[XZ_bX
[XZ_bX
#\_lZJ
[YZ_bX
[YZ_bX
[YZ_bX
[XZ_bX
[XZ_bX
[YZ_bX
[YZ_bX
[YZ_bX
[YZ_bX
[XZ_bX
[YZ_bX
[YZ_bX
[YZ_bX
[YZ_bX
[YZ_bX
[XZ_bX
[YZ_bX
[XZ_bX
[XZ_bX
[XZ_bX
#%8*[~
#JPZDl
[XZ_bX
[XZ_bX
[YZ_bX
[XZ_bX
#crAUai
[XZ_bX
[XZ_bX
[YZ_bX
[XZ_bX
T@X(y
[XZ_bX
[XZ_bX
[XZ_bX
[XZ_bX
[YZ_bX
[YZ_bX
[YZ_bX
[YZ_bX
G,air7?
[YZ`(q
afXee}
c$IaiZa}
aiefXfYff
ZaZZaff
UaifYaXa
&L9ZaiXe
^aiZaX}
afafYe
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
PADPADP
;O}wM&/
u!0EpF
DF>9Edz{5J!
>Tu\y+
<3oJ#lR
;wILK<M
icgphhw
3"91>(
C$0}}s
gg[4|t
>lOkzd
7F20"3;
-Y>@dp
64VN5
KpOK1rv)m
5IfK.'
XPZ<8B/F
Y'Sxv|
y{\AWs
PeL9;{
?*W q8
GP+>E\
b)Nu78|h|F
=\!e-@
QcEooc*
'hkX%%
0j!~dV
",;DsTp
9Dea_c
X~y%YM
oP[RgB
|?Od6`
WkD\2?
Lth-.(
5IB.@!
bgH8;TN
-FSN[
^L!Vq7
{vN}pgwgD
"{*A>4
vzVccX:
gfapp\
\prC|y
y}]dSH
)7f=H_
c-^eji+
S`uT&M
P0q\Y0
]^G]`g
5Fbjo"
x@I$^Z
>Wo-l{p
n#:x[~SX
a?\!'d
B?zd|>
TK"tvV)
v]!?j,>
XLG8*Z
}8ekWp
Ine"B{
'Z=q.4
'Z=q.4
'Z=q.4
'Z=q.4
'Z=q.4
'Z=q.4
'Z=q.4
&%V7>N
&%V7>N
&%V7>N
71|MCSJ
ww3Mss
MI&<$V
M@jXX4
LJ/eS
/z:Xi,
`krZpe
].9atB
3='8{7afM&
@MBbMyw
Yqp@kV
7 X`SW
qm0JBX
q8EHCC
Z{J:Q.
IlC(<x
TAk!Nr\
#=$UtA
[nA !x
BU%_WJ:
<91sua
W|#TXP
I+WB_5V$
>3T*/Yl
k&Sm"n
v6-#d^
vah!F`
40p3}k)
d`b%9N
lo9m7nz&{s
}L=uUs
-w=@f6K
xJi5>W
Z#JPHB#
JQ@`\_
RsV;l!
|[< jH
cen-bd<
$J{Y=t
BI5$]9,
Mkt*xw
-sJcM9
(#bsL=
{;[3wJ
/A&.0j}m
v!TK(E
-*"WE*@vJ
kjoF3[
l~/3_SR
jQIE\rLJ[
bP@4o7]
z/7h)_
7wj8^Z/(
kdq-x~
y`=k?j|
B(nLPZ
k=y.<s
GJ8sP@
AVJ|p]
C>>UwI
.q/M(}
KdPn9
rhWr cCE
3CQ:[%g8
*p3DiA
A[EK_
?nA9<=
XW21v7
sG@}A4\b
Bt8EUd
8,SvBR
j8w>PB
BU^R1.
nbE<\>>
37`0Z;
b-w9x'
"B&7@>
Kqs\LB
]ZX=[]
ax4{62
r[1I6rr
\aPid),
p >'f
KSrXIa,
$BWpqa
tA5lR!
Qq+Sw
L\yK=e
=(ksU
9GM5`ml]Yj1
jF`hs}8\,3=
t^0iy,
lZ\mF~a_L
?3G'2VJ
R\LN]@
8Xz:Ff
`s'4!DT^
u&p80LHT
p+6jmpM
A!E@_%]5
o48_(<b:w
}Owhm:
b`GJdJ
H[Z::?s
e4c$g3
24""Kx
SxW)n/iy8
es<6%d(
S'13N},Fe
`os9H+
z]wOk)j
"lOs
6 G:nw
Z# qrf
_%Cu_
SY%IT+
nfl<+kw
$!lQU4
+Tz`'+~
.Y$aD~h
n<^smy
JTZ~[C
LV0yq%>A
hr/z}Zkf
&o}!wb)
;:OF+
|\7isL
DcKs%X
Ph@H$lv
!NBsn=Mj
&-RKi-
~z7W D
-h+~D+
MCt2m?
=;2)L^fbA
#F8p?;
Bxou=:
*"Ab,99
om^JjG
`DXvAm
_KjG&G
<%$qZW
xNRXz)L
:1W1
,>KVj3,?
PsPN,FN
jfi1[,$
r82X~:y
;(V$E=
5T|lJ/
djB[awj
P1:F<bW;
=SYH g
WN3g$wCLj
.vF0X
xb?o'^=6
@pgp`&
}Dm%K5
y7Hnn$
M*qe4(
3X_=#0
r{b29$
~04PM<
HjLm$js
g|2-7d'm
7xiy5}
[g6O}A(
3,xVN6
*S7:VE
Na*+0u
sgidzF
KXAyrAt{
VHx{ii
@SqE@&
d2"rXe|
|Ex{+J
^83w}yd6xz
A()@"h
!EO*hW
G[uec1
k1Ga|G>j
C(nHA}T
)G5NkN
7'1wo/
zZ+X j3 R
wQN.?~6#
>{dGn7G
5 Q)y2
@X)>JM
PA$Fm9
E7<OHek
jZ\Wiu
g8R]{_
d!\_7z
Bher{GL
XKT*8f
W>fUYrK
<~R7+)m:
;F:F,<g
yb~~U&/
W?'Oob
*Nasl
DO@tIB
3(t+'=
l9ouUQG
}o}a0n
%.{Qm`
a!U8Id
XR`PJ
Ep '[E
4Nd7>M
_ MV?F
&%z4O\
;b')8s
3/BPHDWL
i>i7qmg
w/Kb6[
aE9,Db
u()9A*dt
lu';pK
U_h)`;T
_pR;%~
h=/yEkV
#H|I6d
"KJF.;
kZ(&v
KFYJy]
-U <6?Z
tqF5`5
e?Cm94
sTiUYn
nGTI4+
mxtJroF
enc3qT
VJ{N3|W
$//}3N
+(YY)M
+t't!H
QYI3P6
M,~|zh]
Z<:1|[v
y94WP"
8!-{*I
XjEsWM
TV(4j\
ta0"!j+}=
NxilE6
R"mT*i
Z;g7Gy
]ei:Z2
t$4Y3"
8b#kLS
3X-v:;u
Z"b<%l
ZOjZu<
##9Hw74
XMq&ey
gfoA\t
yohmWPQV
pgS}=-
w>AE11G}
&ktD~0#
p8E$&a
6lbpp~
1c~p')/
iQN4e`OH
RFo%Rho"<
E[kWuP
vrybm1
MTR5{~H
Xn^Z_I
w$L`HR
,esS)4#
AB9%X
7^Cstw
8'4`cE
s;\?qE:P
Wa(8 r
'JO ~%u
&%To2rS/
s#yM%3Q
%HkyD\
V~uw~
c=tIYn
9DZ{AH%,>0
Q$M%s`
QmD0&F
60TI[2g&
kI(Np6J
4$!&[_
dW%Drs
8C c7Z
\X'&To
NfD|$41//R
u)`je9
.+(P?O$
4#_"Y1
,+!+8
:K'5H
Ss9Tmj
wM)C/L
B /_g?+
evLk]>
ju/#"^
^C<:B~
XeWB35
QH%M?H
#7?cj5
F%(p>L
.$j8q>&_f
5OFdTu+
&gcGW
>U\g|l0=
Rz&S=&FT
~Xm7P =8p
16'"Zm
}$}qpj5
\|`b8[
bNk2b]!Rx
'$^oMS
p*-kcf
A-HT}b
{?(z>9`P5V
P't!Vd
zAF<`t
{jOd,EKy
$sb2DM_S
5wcQ8S
O8)ik&s
e8vQa)
@d q}>QL
QfczMi
PMHUG*
;"gA,
ba^WK'tE
Kvk3*_}
q(YOk@i
xG2,?N>
;FqB\"
$m~GKB
v4.0.30319
#Strings
#gdfg#
#gsdfg#
#fsdfsd.dll#
#hsd.dll#
#fsdfgdddddfchafhghgsdf.dll#
#sf.dll#
#fafg.dll#
#hdfh.dll#
#agsh.dll#
#adas.dll#
#js.dll#
HotStreamCLR40
$$method0x6000437-1
Get_IsClr11
TaskCompletionSource`1
IEnumerable`1
EventHandler`1
SetFilePointerWin32
ToUInt32
ToInt32
LOCALE_SMONTHNAME2
LOCALE_SISO3166CTRYNAME2
Func`2
Mscorlib_KeyedCollectionDebugView`2
CreateTypeRef2
StatusLevel3
MDWriteMethodBodies3
TypeUInt64
Get_Int64
ToInt64
Conv_R4
ToInt16
CodePageUTF7
get_UTF8
Ldc_I8
Conv_I8
<Initialize>b__89_19
<Module>
S_LPROC32_DPC
ListModuleDefMD
get_IsWinMD
HIGH_SURROGATE_END
COR_E_EXECUTIONENGINE
MEM_RESERVE
MAX_PATH
get_ASCII
WriteInlineI
lapnjkbniI
COR_E_VERIFICATION
COR_E_HOSTPROTECTION
CSIDL_PROGRAM_FILES_COMMON
Get_STEXTINFO
System.IO
IFIRSTWEEKOFYEAR
MUI_PREFERRED_UI_LANGUAGES
LOCKBYTES
DUPLICATE_SAME_ACCESS
RESOURCE_DATA_ALIGNMENT
CSIDL_COMMON_STARTMENU
FILE_ATTRIBUTE_READONLY
O_RDONLY
SE_GROUP_MANDATORY
Get_SPOSINFINITY
STATE_DIRTY
<ContinueWhenAllImpl>b__1a
AddData
GetCultureData
BaseOfData
ApplicationData
mscorlib
ResolveTypeSpec
hgdfgdfgc
System.Collections.Generic
get_IsStatic
Set_CreationTimeUtc
GetCreationTimeUtc
GetProcessById
TrimHead
lpNumberOfBytesRead
hThread
get_CurrentThread
thread
RijndaelManaged
get_IsAttached
MarkStarted
IndexesIsSorted
gdfgdfghfgd
GetRid
Stsfld
set_IsBackground
DynamicMethod
DefinePInvokeMethod
DefineMethod
ResolveMethod
GetMethod
S_stackGuard
NetGuard
get_IsInterface
Replace
LoadResource
FindResource
SizeofResource
GetHashCode
MakeHRFromErrorCode
SetCode
set_Mode
CryptoStreamMode
CipherMode
EventResetMode
UriEncode
Xenocode.Client.Attributes.AssemblyAttributes.ProcessedByXenocode
ActivatorCache
EndInvoke
BeginInvoke
MDTable
GetEnvironmentVariable
Enumerable
IDisposable
set_Visible
Double
get_Handle
RuntimeFieldHandle
get_MethodHandle
RuntimeMethodHandle
M_methodHandle
GetModuleHandle
get_TypeHandle
RuntimeTypeHandle
CloseHandle
CriticalHandle
GetFieldFromHandle
GetTypeFromHandle
_handle
Get_ConfigurationFile
IsInRole
Console
Sample
get_Module
DefineDynamicModule
AddModule
set_FormBorderStyle
set_WindowStyle
ProcessWindowStyle
get_Name
AddName
Get_FullyQualifiedName
CreatedPdbFileName
_fileName
ReflectionFullName
lpApplicationName
AssemblyName
GetDirectoryName
GetAdjustmentRuleForTime
Runtime
lpCommandLine
WriteLine
InlineNone
EndScope
ResolutionScope
get_FieldType
DefineType
ReadInlineType
CreateType
ValueType
get_DeclaringType
MissingType
flAllocationType
get_ReturnType
GetHebrewYearType
get_ParameterType
System.Core
ResolveSignature
SetLocalSignature
MethodBase
Dispose
Get_Mouse
Duplicate
Truncate
CreateDelegate
MulticastDelegate
HebrewNumberParsingState
set_WindowState
FormWindowState
STAThreadAttribute
CompilerGeneratedAttribute
UnverifiableCodeAttribute
UnsafeValueTypeAttribute
BabelAttribute
ReadCustomAttribute
SuppressIldasmAttribute
AssemblyInfoAttribute
YanoAttribute
DotNetPatcherPackerAttribute
BabelObfuscatorAttribute
CryptoObfuscator.ProtectedWithCryptoObfuscatorAttribute
DotNetPatcherObfuscatorAttribute
DotfuscatorAttribute
CompilationRelaxationsAttribute
SmartAssembly.Attributes.PoweredByAttribute
RuntimeCompatibilityAttribute
SetCustomAttributeValue
InitialValue
GetDefaultVersionValue
InternalSetValue
Brtrue
get_IsAlive
remove_TypeResolve
lapnjkbniI.exe
get_Size
M_iPackingSize
BlockSize
DefaultBufferSize
M_maxCharsSize
dwSize
SizeOf
fsafafwwwwwwwwaf
fshjkkgdf
GetSigOfFieldDef
IsTypeDef
EventDef
GetMemberRef
get_IsByRef
CJKDaySuff
rcipopFkrdg
TryGetClassOrValueTypeSig
Get_IsPreserveSig
Set_IsPreserveSig
HashAlg
XMLLang
System.Threading
UnicodeEncoding
IsLogging
Ceiling
FromBase64String
OutputDebugString
ToString
GetString
UserDrivenParsing
SystemWebRouting
ComputeHash
get_ExecutablePath
GetFolderPath
IsUncOrDosPath
ObfuscatedByGoliath
get_Length
EndsWith
_fcDepth
AbsoluteUri
fhfghj
AsyncCallback
TaskCancelCallback
S_executionContextCallback
callback
AttributeUsageCheck
FastEqualsCheck
FileLock
get_Count_NoLock
GetClassLayout_NoLock
CreatePublicKey_NoLock
FlushFinalBlock
TransformFinalBlock
Get_ValidMask
CallConvMask
Marshal
FindNormal
BNeutral
kernel32.dll
PercentSymbol
Control
FromAsyncImpl
VersionedStream
CryptoStream
MemoryStream
get_Item
System
SymmetricAlgorithm
_HashAlgorithm
ICryptoTransform
M_builtIn
get_MetadataToken
hToken
M_leaveOpen
lpNumberOfBytesWritten
AppDomain
CanSendCrossDomain
get_CurrentDomain
HasExtension
UpdateVersion
MinorSubsystemVersion
Get_MajorLinkerVersion
HostProtectionPermission
Application
get_Location
ReduceAlternation
InvalidOperation
NineRays.Obfuscator.Evaluation
System.Reflection
GroupCollection
ManagementObjectCollection
get_GenericParameterPosition
CallingConvention
SearchOption
RuntimeWrappedException
SetPattern
CharUnknown
InternalCompareTo
IExpando
PEInfo
GetDynamicILInfo
EhEndAddrFieldInfo
MethodInfo
StringInfo
startupInfo
MemberInfo
M_LineNumberInfo
Get_UserInfo
ParameterInfo
RuntimeConstructorInfo
ProcessStartInfo
DirectoryInfo
_autocap
StringsHeap
NumDatesep
PatchJump
System.Linq
set_ShowInTaskbar
MinEraYear
Lastchar
displayMember
set_Number
TableHeader
ImageSectionHeader
_defaultReader
GetLoader
MD5CryptoServiceProvider
DESCryptoServiceProvider
MethodBuilder
ModuleBuilder
M_moduleBuilder
TypeBuilder
LocalBuilder
AssemblyBuilder
SpecialFolder
GetEmptyCAHolder
lpBuffer
ResourceManager
Debugger
ManagementObjectSearcher
Comparer
GenericParamConstraintUser
get_IsPointer
BitConverter
TitlecaseLetter
IsAsciiLetter
ToLower
GetTokenFor
STimeSeparator
ManagementObjectEnumerator
GetEnumerator
EnumSeperator
.cctor
dotNetProtector
get_IsConstructor
CreateDecryptor
IntPtr
DailyBuildNumberStr
M_iCAs
DllCharacteristics
System.Diagnostics
NativeMethods
GetMethods
Namespaces
System.Runtime.InteropServices
System.Runtime.CompilerServices
System.Resources
lapnjkbniI.resources
GetRanges
DontConvertPathBackslashes
bInheritHandles
GetTypeByNameUsingCARules
EnableVisualStyles
WriteAllLines
EmptyTypes
NeedFatExceptionClauses
lpThreadAttributes
MethodAttributes
TypeAttributes
MethodImplAttributes
GetCustomAttributes
lpProcessAttributes
GetBytes
GetNFIValues
MapKeyStorageFlags
BindingFlags
dwCreationFlags
GetMethodImplementationFlags
SetImplementationFlags
Get_BigStrings
ImplicitThis
Equals
IgnoreSymbols
System.Windows.Forms
Contains
CallingConventions
get_AllLongDatePatterns
ManifestResourceInfos
OtherHeaps
_GetEventProps
get_VTableFixups
HasForceTwoDigitYears
get_Chars
GetMembers
Get_ImageNTHeaders
GetOptionalCustomModifiers
ReadFatExceptionHandlers
GetParameters
WaitForPendingFinalizers
NotWordClass
get_IsClass
M_changeAccess
FullMemberAccess
AssemblyBuilderAccess
hProcess
GetCurrentProcess
lpBaseAddress
lpAddress
GenericArguments
HasConstructorArguments
InitializeEvents
MaxDays
Concat
CanonicalNumberFormat
ManagementBaseObject
GetObject
SetWaitObject
object
Select
flProtect
AllUriInfoSet
CharSet
Set_Target
Set_FieldOffset
SignatureOffset
IndexesOffset
CharsRight
op_Explicit
System.Reflection.Emit
Set_Salt
SetCompatibleTextRenderingDefault
IAsyncResult
result
ToUpperInvariant
UnicodeEquivalent
System.Management
lpEnvironment
HijriAdjustment
get_Current
CheckRemoteDebuggerPresent
IsDebuggerPresent
FreeCount
M_constructorCount
ReuseSlot
S_IsolatedStorageRoot
ParameterizedThreadStart
Convert
MayLeakOnAbort
FailFast
GetMethodSemanticsRidList
GetInterfaceList
c_japaneseErasHivePermissionList
FormatFullInst
set_Host
CheckTimeout
SuspendLayout
ResumeLayout
ClassLayout
MoveNext
System.Text
CheckContext
context
Get_Raw
FallbackIndex
DynamicMethodArray
ToArray
Get_IsArray
get_IsArray
SEnglishCurrency
set_Key
RegistryKey
System.Security.Cryptography
DefineDynamicAssembly
GetExecutingAssembly
IsILOnly
_completedSynchronously
BlockCopy
DataAry
SaveToMemory
CreateDirectory
lpCurrentDirectory
History
op_Equality
op_Inequality
HasAuthority
System.Security
SuppressUnmanagedCodeSecurity
ResolveDeclSecurity
InitializeDomainSecurity
IsNullOrEmpty
ResolveProperty
198 Protector V2
System.Security.Permissions.SecurityPermissionAttribute, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089
SkipVerification
WrapNonExceptionThrows
_CorExeMain
mscoree.dll
??/h(>hh
oOOO_H/__^(
k//_xxOOOHhxx
o(xhOOox
FJJbJJ
b`sssP
UPbbJJ
wnJP~O{~
OPy,~Q{%[,y
yy;{uv
y*si=u:u
vv>^sdt
d:N9:s
R}}@@R
R}}a@@
E&PPPPP
@@}RX@F
&&PPPP&
PPPPPPPP
PPPPPP&q
PPPPPPE
rstuvwxyz{|}~
bcdefghijklmnopqRSTUVWX
[\]^_`aBCDEFGHIJKLMNOPQ
3456789:;<=>?@
&'()*$+
,-./01
"2gR"%
^ H%HH
Tjfjz:16>>m
`kkkOGG
-Io2-O
hJ9;4t6
bkkK|-
%?:>>p
$etd8?4xv|zf
LMMN9|
\N0t]d
L>N4U,2
'_#>w=
-_/Hr`
{tdDN%g
>3088rnhtzjr
HLGL|@&
91=9>
w 535=z
:7tnbt4}
;f=Rid
IQaE?Z
0=800>tv
Dss|rhhh
S'OM>t
:], bd
2[W-0XM%,
w/rpZxlVwZk
l6[PT0
}lPpl9
eV~.>PK
rErrbb
M!Y%GA?Z
S4DH_u
OLLgs98S
mmroOw
k8L}.5
-Roww4
={B M#
#K#=di
b2dNtr
a o$?M
|61331=3
k"K{{b
lqqy5N
nX!YXdXNB
_+.%7E
;^O.zW
0PG^04-
J4^Y>u
>P4=$cP
/>Pe5M"
042B-!w
Py,2=G7
T9nLQ9
Io7RLb
5E2Aq<'P
E^Jg'$
sy(dL@
~< Y20
kb%vDO
~gMDtP
EAvcN4f
?VN"Xf!
r.2J$L)r
Chs{Duf
uVD:X&B
<x^ioS[
_=B2qQ
4t2~=b
\]3\[7
'tAC,'
aog9uu
3Yv.x$q
c_6__p`
1t=&2>
96Z<XO
31{$%M
`WrrN(
UFK4>Q
KV_Z)9
mMm]]k_
jB0n<(p
c5*S'7
$ElC(B]!3
nnRTjd
LG4fGY8
_ZxARh2
R7.QRR
0KBp6<D
A#n_@$s
KDIL(&D
IZqfdEV
J3GO6'h-w
joGt%{L
acuGY4
BkG3+=
{ =CaV
3"O>wR
T+wB!5r
{5c|3.[
t@@Zxyo
JgCr}|
8Is.nH
%k>LOl
N|F1l[
(j*cGk
5$um|
E@O 7V
CZu4bg
7nxo__
5j53iE
%5uyiC%
CS%qx4o>
r9rXWU
]Cbx$+J
sG]_T]
-H 4Plv}
wwvo 
lkj^544(
///^gffK
DDDy{{zh
0Onvz~
FFExJLK1
777ZA28
``_!rrr@lkkQNNMS__^D;::)
?R^;f
BG:]qmgw
'FrVbq
ooh_XX(
wwwwwwwwwww
s337s3
s777sw8
wwwwwwp
mmmmmmmmmmmmmmmmmmmmmmmmmmmmmm
qmmmmmmmmmmmmmmmmmmmmmmmmmmmmmm
mmmmmmmmmmmmmmmmmmmmmmmmmmmmmm
qmmmmmmmmmmmmmmmmmmmmmmmmmmmmmm
mmmmmmmmmmm qByxC
mmmmmmmmmmmm
qmmmmmmmmm
10::W');
mmmmmmmmm
mmmmmmmw1W
mmmmmmmm
qmmmmmm\jD
''dgZ mmmmmm
nQ#V#mZ
8kzQQ($F
qmmmCk
Ha8|_hzb^;
qmmqxO]"8h38K
{IBxIIu
qmml{{5
*`C///{//
qmmBf?
mm/[sM&
@XImmm
{t\l/q wlC5
{Clf mmmmql{
55{{Cl/
5l{mmmm
mmmm//
{Cl\/qw
/CDmmmm
qmmmmm/qCCl/
mmmm ftq
/mmmmm
mmmmmm/
/\/qqw
qmmmmmm
qmmmmmmmqq
mmmmm/Dmmmmmmm
mmmmmmmmm/qDmmmmmmm
qmmmmmmmmm
qmmmmmmmmmmm
//mmmmmmmmmmmm
mmmmmmmmmmmmmmmmmmmmmmm
qmmmmmmmmmmmmmmmmmmmmmml/
mmmmmmmmmmmmmmmmmmmmmmCmmm
qmmmmmmmmmmmmmmmmmmmmmmlmmm
mmmmmmmmmmmmmmmmmmmmmmC
qmmmmmmmmmmmmmmmmmmmmmml
mmmmmmmmmmmmmmmmmmmmmmt
qmmmmmmmmmmmmmmmmmmmmmm
mmmmmmmmmmmmmmmmmmmmm
jklmnopqrstuvwxy
Z[\]^_`abcdefghi
JKLMNOPQRSTUVWXY
:;<=>?@ABCDEFGHI
./012-3
456789
GGGGGGGGGGGGGG
89:;<=>
01234567
'()*+,-.
 !"#$%&
z?Njn&
p[)y+Eo
m*d+%w
J)|pfgg
n~vN~[
Z<*?/9+
#uh7/aO
[7oaxd
/_*|$H
##c8(L
n$b>SZ}fv`
0<U*{L
RkS6`
`3SxO][BdO
^fv .L
uZ|.TT
orouRPK
7(t~_l
oZjZ7R
aQzfB
@3$rm<6
[7n`va
/&p2qT
(<AQxQ
%xkB_}a
"nyYt0
9$*b9E)
@9%nTI
vSPo@}
[FY,VJ
B0"Oe'%
V-i!TH\
`O8/O@L
)Ev!.yBw
^= .EbT
>{Bu9vr
gVnfN8
"bC!x&zm
afwgf'w
s0n(Kt
ERx~.)
8$UW_A
WvS$}I
o[%,Rz
x5xV6J!
/w}HIN
)OV<1L
>H 3dO
m?Ehr/
CSxuLG
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<assemblyIdentity version="1.0.0.0" name="MyApplication.app"/>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v2">
<security>
<requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3">
<requestedExecutionLevel level="asInvoker" uiAccess="false"/>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
lapnjkbniI
GetEnvironmentVariable
_ENABLE_PROFILING
_PROFILER
-43770364
43666003
-1759421586
1759412260
-816638856
816680709
-1733752154
1733775590
697278126
697236669
-1844484057
1844462649
-2146507903
2146518969
-2052540074
2052511909
571429871
571444859
-635435832
635435284
498574395
498597707
1476631150
1476608464
-511260709
511409930
1847134529
1847067102
518510237
518472957
1353897327
1353847421
-873372082
873418252
-1492751035
1492710018
2036393673
2036435484
1123279681
1123210813
-742954025
743105143
1747695061
1747635192
-900191036
900155713
-1094418556
1094335146
-1099269861
1099275632
-1045543877
1045546594
1433653164
1433579911
-277226917
277225464
-1647684062
1647636762
-789708663
789656069
-1237794821
1237843619
358446726
358472355
-709675457
709739873
-574510515
574508687
-119163709
119042554
-2033544213
2033455233
1559155473
1559153185
-190127598
190182213
728288738
728294865
-970241712
970231554
-1675267908
1675283727
-1932892441
1932836443
-1375839395
1375827714
-401693668
401693377
-558150193
558175529
-227536164
227435944
-1221361853
1221378582
1360267648
1360274021
-1966702599
1966866365
-540811050
540810382
516424287
516460755
320021275
320052701
-1803231886
1803207480
1042679019
1042763220
601028410
601015481
265227504
265289351
-351509328
351404125
1955682006
1955695595
-586256392
586271544
-1796065348
1796047783
-97732773
97664228
676317952
676295169
-1672476363
1672316768
-1488226778
1488245757
909955071
910014097
-1433897059
1433806547
-456677468
456697914
-443841656
443858052
11594791
11636641
670390711
670389308
-1042561013
1042634269
-1859453195
1859456028
-428666021
428632800
-612878260
612798349
2134529249
2134576888
-1689518790
1689575865
798133595
798136107
1500691081
1500683747
-1523142480
1523279028
-1156605661
1156766837
-830266353
830381072
1281197584
1281169557
367455146
367498325
-2132383572
2132539154
-65395172
65389873
-1575662540
1575534452
-908074210
908245835
-758452977
758467071
615648032
615691230
-1223176078
1223211290
402786335
402873981
926139864
926086041
-1062528935
1062607531
-1878875347
1878895708
329969995
329918527
-1808615563
1808641424
433799877
433741725
833900517
833951507
2007240779
2007286374
556418513
556415078
1086041419
1086010780
-197873494
197898673
-837943380
837830106
443572655
443580485
1284151568
1284242287
-74948588
74848519
-281519874
281462197
-559383372
559381710
-1111643362
1111667604
-753585475
753424691
1403781623
1403829012
-1340565643
1340582052
357273512
357289233
166165223
166157194
1172660153
1172695220
142139206
142142758
-1808279844
1808295017
-957197769
957194744
-1199241742
1199216178
-709030162
708879719
1129268638
1129216401
1185180569
1185213027
-1228922134
1228864828
-1129410269
1129410839
-865836008
865782231
1943232739
1943155444
533045377
533002841
-1322711526
1322581676
156828413
156863749
-470952109
470950664
1405022178
1405077101
-854493009
854573758
-1316229601
1316242157
-1619123872
1619023025
-2014204431
2014230656
-201271526
201286181
2066008108
2066056786
836647730
836686026
1373625846
1373630645
-226671846
226712924
1990920164
1990855809
-2025757606
2025822033
772576808
772663019
-1609157335
1609164055
-1115011001
1115006071
2060899634
2060885972
-1545341902
1545434651
-431403009
431396317
-1968031960
1968008511
-102189106
102197680
899641358
899556310
-169856259
169718313
1676072834
1676043766
474030345
474029764
1366915520
1366911489
-67321638
67313598
-1626053747
1625901210
-1166141255
1166253615
2005156873
2005221764
-1048002058
1047881846
-55728810
55819104
1467546161
1467594883
147325874
147364425
-2141344622
2141383421
118389329
118398975
364706305
364691426
-698527401
698504529
-285160382
285132771
-664642106
664633175
-1904609608
1904649457
-1787115184
1787113655
-1549081002
1549036389
959845590
959858490
1143324995
1143275714
566031516
566083241
-1327393973
1327410376
1922922737
1922855905
781849819
781868617
110121135
110196088
-695931273
695967629
792068925
792100373
1043143133
1043100094
-291375844
291430940
488943642
488926521
-1282813394
1282802774
365504868
365446243
-1032041087
1031944999
1823841146
1823865599
1762336664
1762374434
1253806151
1253811725
1712301375
1712238437
712353076
712291888
-509259429
509286009
2125903591
2125965305
-1037102734
1037053865
1162005373
1161959422
1146728541
1146698794
2032610492
2032602505
2084491478
2084440787
1651864426
1651840047
-1207255371
1207244967
-1152534845
1152401837
1458695196
1458687140
-393645721
393663385
-363960131
363932433
-1043253609
1043243472
-832121014
832106910
-2035113550
2035106177
351041560
351014342
-1828427503
1828420523
1628064024
1628128738
1989959831
1989946370
249717277
249815099
-1333014068
1333102638
585754258
585686923
-1077583497
1077446125
-1168468771
1168628451
2040897839
2040838551
1978894298
1978835265
1330977525
1330981732
1211151380
1211133778
1957998864
1957991629
1770278176
1770325019
1127027013
1127057821
-1603059323
1603045276
-904284752
904270552
1282050023
1282066616
1976723886
1976789478
-818402699
818238541
-1898169730
1898165948
-1206918853
1206937821
963620266
963564798
1635403217
1635413602
1024186446
1024191091
-1623203056
1623233949
205056222
205057275
-774686191
774688360
1427531826
1427532897
-647292551
647392269
1798711315
1798778509
71558599
71536575
-30934363
30943587
-2122875061
2122923836
-1145434420
1145384935
1620402479
1620438747
1328854421
1328850953
-1103816181
1103668347
1360699356
1360783805
-1373083776
1372992301
612058812
612072006
-1037798510
1037795486
1086182361
1086115222
-720415706
720397306
-27220805
27246570
217008025
217001177
-84866566
84928552
-224103232
224096142
-1612841894
1612903999
348222165
348244373
-127151198
127298039
539875690
539825171
-1744915349
1745030366
1156232061
1156211390
618410031
618421107
-3654418
3566386
-1444130984
1444078898
-539385881
539372571
1787746392
1787818902
1265903666
1265894730
-287868344
287948706
1323020339
1322947925
-743496240
743509331
-1435120968
1435161749
-629307471
629343962
978569494
978485260
-1370856131
1370850063
-1892446110
1892567706
338832208
338859771
-189382118
189270522
481627373
481577735
983432363
983403713
24429624
24400902
660610202
660606351
-1547352455
1547435226
1992566967
1992567426
996040975
996091446
-567561178
567584385
-391888907
391811603
-653070788
653095508
1596444426
1596377412
130024399
130101424
3977178
4043764
1345264511
1345293280
276470286
276534041
-1258432278
1258536085
-156723746
156615522
1748454873
1748396331
2086790349
2086718885
-300532701
300534164
1309184138
1309212528
449827017
449813546
-305005498
305130609
1382906891
1382910167
-676869872
677017514
-167565492
167521036
-1702023438
1701898687
-1900082662
1900124867
903943195
903981592
-1521775829
1521907331
-1944310523
1944242026
1203737796
1203722147
1273756294
1273705491
-1966427232
1966424689
603188778
603134494
-1979816190
1979808291
279569914
279471192
9737094
9825979
-854043297
853997351
644562048
644567119
-1801716148
1801753715
2140264438
2140261425
-1355699633
1355693492
-1723524234
1723550816
-946030068
945985087
1588284032
1588298395
-1132019364
1132056519
400787303
400766161
-766031926
766075313
-1491884671
1491867386
-1031179960
1031174758
-687659641
687773249
-30085581
30102288
1253027262
1253004355
-42181151
42092536
-1057663970
1057629834
-979979207
979934222
-723886432
723874247
-687378649
687472212
1285719306
1285709731
1970838402
1970920144
-2085887315
2085951616
-908410253
908338933
329969151
330010804
1879697874
1879663100
580826241
580906283
-721957631
722079308
87675185
87616851
-826081726
826251971
1822208958
1822274002
661574458
661576824
1228028827
1228016239
828922677
828928882
161463433
161469207
25189243
25204632
-705895731
705894964
-1305686900
1305590286
733117729
733143547
861570100
861581393
-1608978037
1609029559
-1652239077
1652245218
Area =
{0:F2}
261919566
261941151
-1279325313
1279288542
Antivirus Signature
Bkav Clean
Lionic Trojan.Multi.Generic.4!c
Elastic malicious (high confidence)
DrWeb Trojan.Inject4.18158
ClamAV Clean
FireEye Generic.mg.39f1303c19a90e8e
CAT-QuickHeal Clean
McAfee GenericRXQN-RN!39F1303C19A9
Malwarebytes Trojan.Crypt.MSIL.Generic
VIPRE Clean
Sangfor Suspicious.Win32.Save.a
K7AntiVirus Trojan ( 00580f811 )
BitDefender Trojan.GenericKD.47289196
K7GW Trojan ( 00580f811 )
CrowdStrike win/malicious_confidence_90% (W)
BitDefenderTheta Gen:NN.ZemsilF.34236.Om0@ai!3cueG
Cyren Clean
Symantec ML.Attribute.HighConfidence
ESET-NOD32 a variant of MSIL/Kryptik.ACKH
APEX Malicious
Paloalto generic.ml
Cynet Malicious (score: 99)
Kaspersky HEUR:Trojan.MSIL.Witch.gen
Alibaba Trojan:Win32/runner.ali1000123
NANO-Antivirus Clean
ViRobot Clean
MicroWorld-eScan Trojan.GenericKD.47289196
Rising Clean
Ad-Aware Trojan.GenericKD.47289196
Emsisoft Trojan.Injector (A)
Comodo Clean
F-Secure Clean
Baidu Clean
Zillya Clean
TrendMicro TROJ_FRS.0NA103JV21
McAfee-GW-Edition BehavesLike.Win32.Generic.jc
CMC Clean
Sophos Mal/Generic-S
SentinelOne Static AI - Malicious PE
GData Trojan.GenericKD.47289196
Jiangmin Clean
Webroot Clean
Avira TR/Kryptik.wzzbe
MAX malware (ai score=83)
Antiy-AVL Clean
Kingsoft Clean
Gridinsoft Ransom.Win32.Sabsik.sa
Arcabit Trojan.Generic.D2D1936C
SUPERAntiSpyware Clean
ZoneAlarm HEUR:Trojan.MSIL.Witch.gen
Microsoft Trojan:Win32/AgentTesla!ml
AhnLab-V3 Trojan/Win.Agent.C4734961
Acronis Clean
VBA32 Clean
ALYac Trojan.GenericKD.47289196
TACHYON Clean
Panda Trj/GdSda.A
Zoner Clean
TrendMicro-HouseCall TROJ_GEN.R002H0CJU21
Tencent Clean
Yandex Clean
Ikarus Trojan.MSIL.Crypt
eGambit Unsafe.AI_Score_99%
Fortinet MSIL/Kryptik.ACKH!tr
AVG Win32:InjectorX-gen [Trj]
Cybereason malicious.0d1234
Avast Win32:InjectorX-gen [Trj]
MaxSecure Trojan.Malware.300983.susgen
No IRMA results available.