Static | ZeroBOX

PE Compile Time

2021-11-01 11:11:58

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x00055cc4 0x00055e00 6.21417459803
.rsrc 0x00058000 0x00010f3e 0x00011000 4.08108268516
.reloc 0x0006a000 0x0000000c 0x00000200 0.101910425663

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x0005818c 0x00010828 LANG_NEUTRAL SUBLANG_NEUTRAL dBase III DBT, version number 0, next free block index 40
RT_STRING 0x000689b4 0x00000178 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_GROUP_ICON 0x00068b2c 0x00000014 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_VERSION 0x00068b40 0x00000214 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_MANIFEST 0x00068d54 0x000001ea LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with CRLF line terminators

Imports

Library mscoree.dll:
0x402000 _CorExeMain

!This program cannot be run in DOS mode.
`.rsrc
@.reloc
Yfeee}
S@Y(p
@S@[(p
U@[(p
`_@Z(p
`]@Z(p
@U@Y(p
mf,ai(
@M@[(p
|0c^@#
/@6Y`@#
@Z@X(p
[XZ_bX
[XZ_bX
[YZ_bX
[YZ_bX
#1>|f(
#IH`dM
[XZ_bX
[YZ_bX
[XZ_bX
[YZ_bX
[XZ_bX
[XZ_bX
[XZ_bX
[YZ_bX
[XZ_bX
[XZ_bX
[XZ_bX
[YZ_bX
[YZ_bX
[XZ_bX
[YZ_bX
[XZ_bX
[XZ_bX
[XZ_bX
[XZ_bX
[XZ_bX
[XZ_bX
[XZ_bX
[YZ_bX
[XZ_bX
[XZ_bX
[YZ_bX
[YZ_bX
[YZ_bX
JL5nt@#
[YZ_bX
[YZ_bX
[XZ_bX
[YZ_bX
[XZ_bX
[YZ_bX
[YZ_bX
[XZ_bX
[YZ_bX
[YZ_bX
[XZ_bX
[YZ_bX
#7F*)V
[YZ_bX
[XZ_bX
[YZ_bX
[YZ_bX
#>Xfs#
[YZ_bX
[YZ_bX
[XZ_bX
[YZ_bX
[XZ_bX
[XZ_bX
[XZ_bX
[XZ_bX
[YZ_bX
[XZ_bX
[XZ_bX
#"8pj>
[YZ_bX
#$`i+,(
#'V5g{$
#_b1JC
[YZ_bX
[XZ_bX
[XZ_bX
[XZ_bX
y@Z(p
[YZ`(G
[YZX(Y
`q@Y(p
[XZX(Y
[YZX(Y
[YZX(_
[YZX(Y
[YZX(Y
[YZX(Y
#aFFke
[XZX(Y
ZXXfYe
XaaeYe}
YZXeYYe
6JBbai
aYXfYf
BT|aia
s$aiZY
*aiYYXYf}
^aiZaf
WaiZaXYf
xdaiYZ
haiZeaYYYe}
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
PADPADP
M-)@/`
,NMBsD2P
h(zOq8
"OiM&c
jGy<[R
`E-cKv
Oa<u,FE+
LEq`+Qy
vmc/s
rD(u~n
rD(u~n
OKzkV1
Ve_JV|
6oXFHG
roig^
ijO+o%
QtmSOZ/
*qaFp
U85,\
b<zyEz
`n&XE,
No]G}(/
7[<iy=
k5H9j$q
nFxx)Ibx
u8:QuF
2D9t^s
}obFK5
H5y-@=
byoDVUMN!
;^rz
<xL`~=
b2F",/3=
j`&qEz
0j=#jC#'
+aSEV0
&I- @B
n* zg*
(6|S>E0Z$
t^9S0W
/4xdj
ZOlc_r
"~M%%Cq
h_oX:_
l<~=?(
Tk!@~|D
80Z;n3
kr"-!Q\
O_m)yH
:CkVO?jqBE
8P^}WY
AYr?#y
>PjU 
+b)N{$<
TmE%X#
Fmvt@f3j
;Ty#2%j7b
D:Z0+@
WLm$w{
M.qenH
/5U@^va
JtH_gK
cuzf:;
[%od]y
c~B64a
>0'A~&{0
fCy(PG
CN~j.`
u("i77Om
4R$}{C
=X-w|&
p",p29
~4m@/
wX'RYD
%Zv5Uo
kE2/L^j
L#9QKY
9y8E%
L?[m-%
~3z;AZ
M%5F_I;cf
z@kTSx
HW6 )}S
Ggo"xZ
Obk.Dj)gO
`K4`UP"
e=c5!!
v7 CA;
/q&A7^
fHu~>d
$b8F~<
}bR-HG/
UWstb)
9g^l2v@
0(9k}m
C"d2QO
xawbY2
Edm.kr
Le(,%u
Y8gXPx]
gNS8h|
D_HaTV
ma[q6W
$ZRnY]
Jw)f9D
FK0`[@}
V(~#EK^
w8L7+/
!nD?|rE
Ckz0-p54
`.5h6.
y4I)FK
i"f^Kz
}~s*:
j6a=X2
\d%S6*
ryT1"
eHT,PY
5*[8RW
Qkz<'E
,9pc|
sSQrF{F
{#*Pu4l
D;F0
1S42iX0
^$vlu}
fBTZ\>cV
\W251v
[C=AK
c}vbyFz-
;k}\B*
%2W:++J
+5psA\
/:I<<A
J-yPJ~!
8Vo[m;
PS:Q66>
YJ}Hy
R{sgE=F
\5VN&,
C,!>c6
Fzl\'y
A.M~wW
`m=b_:
|')/W6
uP/[R'|
lFz"(@
LT:<57
fwnN%u
WC'u3W8
CcMw;iUI
#%Pt-k
#%Pt-k
7/j;iUI
WC'u3W8
7Z>v6~G
ncV>++
0L/zXR5E
Km$!L<
3m&k6
*(fj!>(*
$/ :"m
YO~Dr+
1O9~C-
I1kY+H
6Qz6;[
2="q0g
tk{p~C
QFHx $
'EHZMA
oj{gO>
v4.0.30319
#Strings
#gsdsa.dll#
#fsdfsd.dll#
#faffafffffffffg.dll#
#gggggggggg.dll#
#hdfssssh.dll#
#khk.dll#
#lhl.dll#
#fdsfds.dll#
#jfffs.dll#
<>9__129_0
<giffdlkknpo>b__0
Get_IsClr11
IEnumerable`1
CerArrayList`1
S_LABEL32
HexNumberToUInt32
ToInt32
198-Protector-V2
<dir>5__2
Func`2
ParseInt64
ToInt16
get_UTF8
LOCALE_S1159
<Module>
fabdgjhkaAA
get_BaseCalendarID
ListConstantMD
LOCALE_IDEFAULTMACCODEPAGE
INVOCATION_FLAGS_NO_CTOR_INVOKE
LMEM_MOVEABLE
PinvokeOLE
CERT_NAME_URL_TYPE
kFfgndnnhmF
IfgkenmjfoF
get_ASCII
addfrgeFpbI
FFmpcmhhrgI
LOCALE_IFIRSTDAYOFWEEK
System.IO
LUNAR_ETO_KOR
COR_E_UNAUTHORIZEDACCESS
KEY_ENUMERATE_SUB_KEYS
mkamjdfaomS
Get_SPARENT
LOCALE_IREADINGLAYOUT
MIPSFPU
WriteConsoleW
LstrlenW
VER_PLATFORM_UNIX
mbgrgirnmda
dfAkdrjSdfa
noicanIImka
rcdata
aIbrraSdkdb
mscorlib
dnapnIomrdc
System.Collections.Generic
get_IsStatic
egAelIpjcmc
lIbjroFAmoc
mldncmgakAd
GetProcessById
moicgSFkeSd
lpNumberOfBytesRead
M_read
hThread
Get_ControlThread
get_CurrentThread
thread
RijndaelManaged
OnComponentChanged
get_IsAttached
Get_Is32BitRequired
OnRunWorkerCompleted
kddbnajgchd
dkFAlmkmmkd
impelcimImd
AddressKind
set_IsBackground
DynamicMethod
DefinePInvokeMethod
ResolveMethod
GetMethod
method
NetGuard
get_IsInterface
Replace
LoadResource
FindResource
SizeofResource
ManifestResource
GetHashCode
SetCode
set_Mode
CryptoStreamMode
CipherMode
BigEndianUnicode
Xenocode.Client.Attributes.AssemblyAttributes.ProcessedByXenocode
EndInvoke
BeginInvoke
Get_TypeRefTable
PointerToSymbolTable
Get_NestedClassTable
GetEnvironmentVariable
Enumerable
IDisposable
set_Visible
get_Handle
RuntimeFieldHandle
BindHandle
get_MethodHandle
RuntimeMethodHandle
GetModuleHandle
get_TypeHandle
RuntimeTypeHandle
CloseHandle
GetFieldFromHandle
GetTypeFromHandle
Console
get_Module
DefineDynamicModule
hModule
module
set_FormBorderStyle
get_Name
M_fieldName
Set_PdbFileName
NativeName
FindTypeBuilderWithName
lpApplicationName
functionName
lpName
HasName
AssemblyName
GetHashCode_PropertyName
GetFrame
MaxSupportedDateTime
ClrAsmName_SystemRuntime
lpCommandLine
WriteLine
IScope
rperpe
InvalidateCachedNestedType
get_FieldType
DefineType
CreateType
ValueType
get_DeclaringType
flAllocationType
get_ReturnType
lpType
CalendarType
get_ParameterType
Set_ElementType
ReflectionOnlyType
System.Core
NotBefore
FailIgnore
ResolveSignature
SetLocalSignature
MethodBase
Dispose
IterateAllReverse
MaxDate
Truncate
CreateDelegate
MulticastDelegate
AddAlternate
set_WindowState
FormWindowState
STAThreadAttribute
CompilerGeneratedAttribute
PrePrepareMethodAttribute
UnverifiableCodeAttribute
IndexerNameAttribute
UnsafeValueTypeAttribute
BabelAttribute
SuppressIldasmAttribute
AssemblyInfoAttribute
YanoAttribute
DotNetPatcherPackerAttribute
BabelObfuscatorAttribute
CryptoObfuscator.ProtectedWithCryptoObfuscatorAttribute
DotNetPatcherObfuscatorAttribute
DotfuscatorAttribute
CompilationRelaxationsAttribute
SmartAssembly.Attributes.PoweredByAttribute
RuntimeCompatibilityAttribute
TypeSByte
MinValue
SetValue
HebrewValue
get_IsAlive
ResourceResolve
amjfhinomk.exe
Set_Size
get_Size
dwSize
SizeOf
fsafafwwwwwwwwaf
MemberRef
get_IsByRef
fasfkkfff
koAeeekhkFg
dadkcdaapkg
System.Threading
Encoding
IsLogging
Ceiling
FromBase64String
OutputDebugString
ToString
GetString
FcpnAcemieh
hhhhhhhhhhhhhhhhh
lhhhhhhhhhh
kkkkkkkkhh
kbdaomAobnh
ComputeHash
InitHash
GetFileMUIPath
get_ExecutablePath
ObfuscatedByGoliath
get_Length
CtorCharPtrStartLength
GetArrayLength
GetLeapMonth
cbmfccdeIIi
donmFSdhiai
Fkfglmbrbhi
oeajmIknghi
ScAabholbii
fmhbmkrdcki
MakeRelativeUri
Flmlnfedaj
lkraolSgSgj
dhlimFAdAak
SIjicAmgIak
AsyncCallback
IOCompletionCallback
EncoderFallback
callback
M_spinLock
BinarySearch_NoLock
DefineGlobalMethodNoLock
FlushFinalBlock
TransformFinalBlock
IfIAchiSmek
mikaImdAmkk
amjfhinomk
Marshal
Decimal
eIjfbghipel
Get_MinimumLevel
ErrorLevel
kernel32.dll
AbgaliIjnml
Control
mhkgSFmSbFm
rhllrflkcIm
CryptoStream
MemoryStream
Program
pdrFcppmgdm
NestedFamANDAssem
UseSatelliteAssem
get_Item
System
SymmetricAlgorithm
HashAlgorithm
ICryptoTransform
Get_IsRemoveOn
ddpjfjjkFSn
get_MetadataToken
hToken
lpNumberOfBytesWritten
ncdkFhcfbfn
nkAISdmgpfn
jjvvvvvvvflhhhhhhhhhfffffffffffffffsssssvhn
AppDomain
get_CurrentDomain
Get_RuntimeVersion
M_informationalVersion
Application
get_Location
Set_Instantiation
NineRays.Obfuscator.Evaluation
System.Reflection
ManagementObjectCollection
Condition
CallingConvention
RuntimeWrappedException
InvalidTimeZoneException
SystemException
Get_RFC1123Pattern
SetPattern
GetDynamicILInfo
GmiMethodHandleFieldInfo
rslvMaxStackFieldInfo
EhCatchEndAddrFieldInfo
EhCatchAddrFieldInfo
GetFieldInfo
MethodInfo
startupInfo
MemberInfo
ParameterInfo
hResInfo
ikmSpmAlhio
iopmijFldlo
giffdlkknpo
mmhhchlpIip
chFFoeklbkp
_group
System.Linq
set_ShowInTaskbar
TypeChar
ToChar
HasNativeHeader
Reader
MD5CryptoServiceProvider
DESCryptoServiceProvider
MethodBuilder
ModuleBuilder
TypeBuilder
AssemblyBuilder
lpBuffer
ResourceManager
DummyLogger
Debugger
ManagementObjectSearcher
IsRequiredModifier
ResolveEventHandler
Container
ManifestResourceUser
ToPointer
get_IsPointer
Get_StringDecrypter
BitConverter
Get_AssemblyResolver
ToLower
KeyValuePair
GetTokenFor
Get_Error
CreateInstanceDefaultCtor
ManagementObjectEnumerator
GetEnumerator
.cctor
dotNetProtector
get_IsConstructor
CreateDecryptor
IntPtr
System.Diagnostics
Get_PreserveEventRids
GetMethods
System.Runtime.InteropServices
System.Runtime.CompilerServices
System.Resources
amjfhinomk.resources
BUseUserOverrides
AdjustPrivileges
GetRanges
bInheritHandles
InternalEnumerateFiles
ProgramFiles
EnableVisualStyles
EraNames
LeapYearMonthNames
ConvertTypes
EmptyTypes
TooManyAlternates
lpThreadAttributes
MethodAttributes
TypeAttributes
MethodImplAttributes
GetCustomAttributes
lpProcessAttributes
EventAttributes
GetBytes
GetEnumRawConstantValues
InitializeSizes
PercentGroupSizes
BindingFlags
dwCreationFlags
GetMethodImplementationFlags
SetImplementationFlags
GetDenials
Equals
EnumMethodImpls
System.Windows.Forms
Contains
M_linkingRegistrations
Set_PESections
Get_HasInstructions
CallingConventions
<>3__options
FieldMarshalInfos
get_Chars
GetOptionalCustomModifiers
GetParameters
get_IsClass
AssemblyBuilderAccess
_access
hProcess
GetCurrentProcess
lpBaseAddress
lpAddress
Get_Events
Concat
_CreateCaObject
BlobObject
IsCompatibleObject
ManagementBaseObject
GetObject
object
Select
flProtect
CharSet
op_Explicit
IsLetterOrDigit
System.Reflection.Emit
SetCompatibleTextRenderingDefault
Set_HasDefault
IAsyncResult
result
ExternalProcessMgmt
ToUpperInvariant
System.Management
CurrentElement
lpEnvironment
InitializeComponent
get_Current
CheckRemoteDebuggerPresent
IsDebuggerPresent
AddressOfEntryPoint
GetCount
textToDecrypt
ParameterizedThreadStart
Convert
NoDefaultPort
FailFast
SuspendLayout
ResumeLayout
MoveNext
System.Text
HebrewNumberParsingContext
context
ToArray
get_IsArray
set_Key
secretkey
System.Security.Cryptography
DefineDynamicAssembly
GetExecutingAssembly
BlockCopy
library
Set_Query
Set_PathDiscovery
lpCurrentDirectory
ImportDirectory
op_Equality
System.Security
SuppressUnmanagedCodeSecurity
IsNullOrEmpty
FindProperty
M_lazy
198 Protector V2
System.Security.Permissions.SecurityPermissionAttribute, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089
SkipVerification
WrapNonExceptionThrows
_CorExeMain
mscoree.dll
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<assemblyIdentity version="1.0.0.0" name="MyApplication.app"/>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v2">
<security>
<requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3">
<requestedExecutionLevel level="asInvoker" uiAccess="false"/>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
amjfhinomk
GetEnvironmentVariable
_ENABLE_PROFILING
_PROFILER
-1780323954
1780283714
691823756
691861958
747746536
747726083
1966118153
1966099877
-1688777378
1688800514
808311272
808298923
-1023087298
1023115981
2880985
2877480
-1872457482
1872323691
1140061977
1140041905
2031788902
2031748358
965896646
965885756
1927153504
1927236970
-1217197585
1217188787
-1222902404
1223082550
-970228634
970325657
-324031157
324051887
924694904
924693968
664479753
664490156
-906285590
906249219
-1626546936
1626549556
-1811857765
1811829403
1269162399
1269065495
723354826
723314689
1605119487
1605166851
-1267947197
1267863367
1998067139
1998076435
-833155579
833134692
425833276
425774986
1681047400
1681006156
-796085029
796050255
1414074654
1414011135
160866937
160848080
24021208
24041433
-1433134048
1432994744
1995525329
1995465151
-1180996416
1180983681
-1383252922
1383206742
2020163403
2020188040
-1172023101
1172037837
201976035
201953702
1567014413
1567075562
-1761000626
1761002806
1776279635
1776198408
-1165473669
1165387468
-588100603
587995667
1118430501
1118435976
-664802940
664898519
-993179421
993134139
781783493
781810579
-809066218
809058671
1814971869
1815001018
1294697877
1294637134
1095662289
1095641182
1938992108
1939052073
-44756656
44699943
-1742242681
1742359036
529135090
529110628
-360866537
360775250
555252224
555239014
1730156069
1730163219
-1835359353
1835335663
1539462751
1539528238
-1251169297
1251103799
481685571
481610712
-403508667
403682848
540097585
540099339
-677463626
677499833
-488560320
488591413
1765243689
1765171964
257385080
257400073
55975093
56023403
-159266165
159276220
-1978744499
1978908428
-965630748
965729128
-741261112
741270365
-185950385
186062841
-350996937
350868661
-113062955
113016303
1774278833
1774295169
-2021671333
2021749892
-1208785911
1208850032
1568181746
1568168314
-354597861
354433910
-373068495
373061703
382763226
382860346
-132529520
132642063
1415615511
1415618947
1346516938
1346551907
-536084976
536159179
-1043191529
1043108782
-927652229
927704055
-747695745
747677495
-754760042
754762569
-1928125086
1928181392
-865176671
865171163
246540306
246473462
-1533107902
1533054706
1632311292
1632259658
-940862212
940907279
-1843157578
1843227127
75890469
75871614
287447216
287476026
-1944209086
1944193110
-744112571
744134961
-1291935034
1291922136
1914065513
1914082821
533122616
533077549
-340968991
341036560
-366560447
366710228
1607568805
1607531154
-76864166
77004687
-121250691
121318336
256150688
256172897
-406491358
406473611
-209020540
209051323
1045322692
1045330589
-1107956063
1108005679
-1036428434
1036441888
517970924
517934574
-637052908
637203553
-2077990773
2078014957
-345330305
345454707
688560544
688633955
1374256585
1374233867
1154298710
1154294901
1378456560
1378409257
633303532
633292884
527484773
527462792
64875300
64819228
1686000151
1686017270
-464025416
464108020
972634580
972561013
-344229739
344374916
-1619158758
1619163359
1907336567
1907307577
772306741
772362079
1134958917
1135032017
-714731773
714673512
-1126390530
1126356402
-1024454484
1024429021
-1901973937
1901914756
671746484
671817259
1655548412
1655532304
1579147215
1579103565
-1188418090
1188358720
370503375
370440258
-700774083
700829614
-2053263327
2053259776
-1904418123
1904451300
218598488
218500468
-1364649329
1364621185
-534344285
534375377
-1946818405
1946711536
1224881887
1224926310
-1221209540
1221282769
-978184105
978061399
1833453369
1833524858
887465261
887442319
2090861705
2090931377
-830692258
830725432
-41513337
41451403
874121802
874214030
-1865092718
1865067234
-556361811
556374864
-1180638662
1180603765
762262695
762302810
1490521305
1490543882
1049979087
1049912663
-1523090878
1523201010
2058874472
2058804160
1210066045
1210094162
1969887641
1969898701
-2037837683
2037812670
-748446004
748464796
667032817
667029461
9596010
9614331
836419079
836377796
663145004
663123520
-22742250
22782609
-316069929
316024907
307203460
307211808
517428860
517462881
1177047967
1177066900
83109833
83168886
291360498
291346202
1415620967
1415580913
779236802
779301778
-168676548
168659608
-1121026840
1120954056
867233248
867180202
809103387
809088040
-1238638673
1238696953
-1172156500
1172104615
-717349362
717300917
1280998415
1281031358
303200253
303178519
-79547432
79479912
-889776717
889734054
575459285
575520058
-1430692232
1430779984
1686527548
1686600183
-1360061478
1360064098
1172080746
1172114360
-930934044
930932724
-2016987121
2017031994
-1898761010
1898720590
359764133
359695101
-84813545
84888764
472831121
472889174
-1984425621
1984381093
-1165201160
1165178381
-877895398
877815537
1630761756
1630739577
-1328169450
1328161779
-315489544
315426099
429849795
429791858
-1521484197
1521619276
-158288615
158275392
-1979133544
1979097912
-959662040
959615413
2048002932
2048062779
1617198501
1617226446
143622055
143633174
-228488800
228347437
185196877
185107613
-518165988
518143246
-840674566
840653451
1653899694
1653896028
-65955871
65955218
1721869957
1721829089
1623991447
1624054826
-1989883203
1989895875
-1349577240
1349565978
9206555
9178489
-533245364
533329725
-819047078
819064237
1451234709
1451247118
-2033179000
2033144176
1819897063
1819896353
969492181
969433718
1672487268
1672558419
-1866705580
1866657966
-1338429194
1338461880
-1718470525
1718400147
1992038907
1992092558
1302280025
1302225150
-497043521
497094228
-605406096
605406024
-1864377503
1864475973
-1366310901
1366410828
-799301404
799361363
-976589755
976595306
58429986
58443625
-1910719719
1910672064
-872495905
872520130
1394176035
1394152347
1808058378
1808119743
-1399335043
1399361743
-321896919
321845140
-791008267
790925733
-1107855301
1107850087
1511495536
1511506269
2025383529
2025345660
-2125876049
2125891404
1190959434
1191030025
1631937296
1631876334
1806731437
1806818873
-1498073385
1498037832
1301868839
1301913909
-1105742956
1105730882
867448560
867451285
-1501955861
1502019398
-425412380
425358868
1401090240
1401130690
945354497
945309192
1965926767
1965863757
1857292753
1857375534
-514534474
514553863
1100134356
1100143636
1497764587
1497824673
-1129979340
1130091586
-1811448221
1811426676
437344940
437332605
1561718340
1561690447
-951113399
951101162
447508309
447509543
-479373041
479205808
912184697
912185845
-127604004
127467911
866589280
866540167
-2143752155
2143636562
1057961394
1058005789
-1420532713
1420526225
2096763610
2096840859
-1800029999
1800069704
1603397250
1603355408
-1096696249
1096706954
-605866085
605863289
-1123495794
1123372648
-281396318
281328284
-1406077384
1406118169
400075616
400088975
707137041
707190220
-165209290
165263118
1009692
1017541
2006406674
2006332562
702833843
702861943
619963600
619865663
50455660
50367791
1476306159
1476322493
892367627
892432204
-980077021
980127689
1539560003
1539511104
-453973976
453864562
-2124139739
2124020346
742216834
742210954
2124986342
2124995212
752172279
752170612
-616207997
616233268
610005391
609959849
-1320428058
1320515693
735402292
735328106
2123102036
2123017759
-584845851
584877683
-601651379
601686873
-1620809920
1620767128
-699928903
700012985
-1696579899
1696576837
1227544093
1227589295
-701127789
701116258
-607754854
607691040
202509161
202510645
1426745383
1426750380
-1792259674
1792222760
-808042813
808026347
1064926125
1064922065
532218803
532245243
1090168706
1090242714
359646639
359577945
2078276293
2078230302
-1111587878
1111492104
599163800
599180875
1229441458
1229429738
-129895297
129940517
-1229503524
1229631195
-932046056
932006188
-1644283464
1644184908
391074848
391077860
-398295074
398453443
-1603775826
1603763652
-910185952
910225759
-1814101494
1814076867
-1575401965
1575275256
256205594
256204590
426874262
426849087
384717940
384778657
-632155158
632150135
-1936698285
1936594622
2139856360
2139846602
-1964735424
1964666281
1675797744
1675878020
-252998297
253043893
1280828132
1280739233
-1787010017
1786989785
192397450
192376768
-355624914
355653219
-405427767
405509597
652195250
652174085
-2133781908
2133789564
49001713
48987780
180944566
180938422
2080129783
2080143488
184801036
184735703
1529939753
1529972207
-1967614239
1967611570
404782169
404757443
1822664354
1822622988
-1164022611
1163997521
1574908899
1574944062
1084562441
1084604543
-1142257593
1142161784
272842606
272881373
1470242764
1470278376
903064202
903073310
1182423876
1182402600
-1193367358
1193496604
999843591
999827822
-1820096079
1820130672
-1533660245
1533564773
593899270
593934121
-733069782
733207261
-700264372
700190006
626493011
626489802
189440127
189503031
-432573457
432556007
1525025214
1525089874
842101386
842131033
1796047763
1796077167
-549866650
549864956
296267620
296351579
managed
native
amjfhinomk
Select * from Win32_ComputerSystem
Manufacturer
microsoft corporation
bbbbbbbbbbbbbk
mmmmmmmmmmmmmmmmmmmm
bbbbbbbbbbb
87654321
1958891869
1958916568
2033492815
2033558988
-113829199
113848060
975881599
975942444
-1798318834
1798432984
96Mlr/F+reQe223pZWxwPaaYlV77AcOO
96Mlr/F+reTZoVpsq/KhStfOTXyEVvAg
DynamicDllInvokeType
1440866466
1440836655
AjpgoYxxT+Y=
1322925147
1323000538
1059218258
1059248920
-615349530
615325052
403149819
403153988
970816224
970813626
41888617
41902676
506350042
506369758
892606547
892620696
-1141546107
1141514160
-951023141
951006140
-10245053
10342441
-1897271714
1897297914
1597372992
1597317685
-247002306
247090539
-1434304596
1434229967
282253764
282301545
-1238641428
1238694238
-736973093
737127494
-494974399
494954612
285697743
285622210
-1861823162
1861828037
16KqUyp5R1QloSo9nUPawA==
sbvJ8yGiDQFHrnuerra+2nQODM2OHm0w
g0q4WolU1oViV33coU7m7bonT9oJy1Uy
OOclKdRWsXuc9tlx2ec4BL9ojzrVko3I
I9WOyRq47JayqzVlnF3QFQ==
IUCStXh+UQwa3wxDAo3BTWHB1Jda3/CV
8ajATl+fBLgnQIh1sJBd8HOjkKtw59TU
ouG0xrNYHNxv8NfTiRS+Cp6FpbUkrpvt
HrCpxkeWzUo2Xn3kHzpyng==
tHki/kODMryNzllf3yHC6A==
TCUvL0r82eVmIKfay+RLQy0i87+dIjHp
MAINICON
Select destination folder
Extracting %s
Skipping %s
Unexpected end of archiveThe file "%s" header is corrupt
%The archive comment header is corrupt
The archive comment is corrupt
VS_VERSION_INFO
StringFileInfo
040904b0
CompanyName
fpkFFa
FileVersion
2, 8, 5, 4
FileDescription
gnmhoSafb
LegalCopyright
ProductName
ProductVersion
2, 8, 5, 4
VarFileInfo
Translation
Antivirus Signature
Bkav Clean
Lionic Trojan.Win32.Convagent.m!c
Elastic malicious (high confidence)
MicroWorld-eScan Clean
FireEye Generic.mg.e9680f9e3f58e0e0
CAT-QuickHeal Clean
McAfee Artemis!E9680F9E3F58
Cylance Unsafe
Zillya Clean
Sangfor Suspicious.Win32.Save.a
K7AntiVirus Clean
BitDefender Clean
K7GW Trojan ( 005819cf1 )
Cybereason malicious.b95da4
Arcabit Clean
Baidu Clean
Cyren Clean
Symantec ML.Attribute.HighConfidence
ESET-NOD32 a variant of MSIL/Injector.VRI
APEX Malicious
Paloalto generic.ml
Cynet Clean
Kaspersky UDS:Trojan.Multi.GenericML.xnet
Alibaba Clean
NANO-Antivirus Clean
ViRobot Clean
Ad-Aware Clean
Emsisoft Clean
Comodo TrojWare.Win32.UMal.bllfy@0
F-Secure Clean
DrWeb Clean
VIPRE Clean
TrendMicro Clean
CMC Clean
Sophos Mal/Generic-S
SentinelOne Static AI - Malicious PE
Jiangmin Clean
MaxSecure Clean
Avira Clean
MAX Clean
Antiy-AVL Clean
Kingsoft Clean
Gridinsoft Clean
Microsoft Trojan:Win32/Sabsik.FL.B!ml
SUPERAntiSpyware Clean
ZoneAlarm Clean
GData Clean
AhnLab-V3 Clean
Acronis Clean
BitDefenderTheta Gen:NN.ZemsilF.34236.zm0@aiUdDPoi
ALYac Clean
TACHYON Clean
VBA32 Clean
Malwarebytes Generic.Malware/Suspicious
Zoner Clean
TrendMicro-HouseCall Clean
Tencent Clean
Yandex Clean
Ikarus Trojan.MSIL.Injector
eGambit Unsafe.AI_Score_99%
Fortinet Clean
Webroot Clean
Panda Clean
CrowdStrike win/malicious_confidence_90% (W)
No IRMA results available.