Static | ZeroBOX

PE Compile Time

2021-11-01 10:06:12

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x00055c24 0x00055e00 6.20780054133
.rsrc 0x00058000 0x00010f42 0x00011000 4.08140249275
.reloc 0x0006a000 0x0000000c 0x00000200 0.101910425663

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x0005818c 0x00010828 LANG_NEUTRAL SUBLANG_NEUTRAL dBase III DBT, version number 0, next free block index 40
RT_STRING 0x000689b4 0x00000178 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_GROUP_ICON 0x00068b2c 0x00000014 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_VERSION 0x00068b40 0x00000218 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_MANIFEST 0x00068d58 0x000001ea LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with CRLF line terminators

Imports

Library mscoree.dll:
0x402000 _CorExeMain

!This program cannot be run in DOS mode.
`.rsrc
@.reloc
`P@X(p
_eWai(
;WQB@#
`\@[(p
@C@X(p
wX}c@#
`U@Z(p
@H@X(p
UAr -UArai(
@X@Y(p
[XZ_bX
[XZ_bX
[YZ_bX
[YZ_bX
#E\7*k
5wzA#
[XZ_bX
[XZ_bX
[XZ_bX
[YZ_bX
@y@[(p
[XZ_bX
[XZ_bX
[YZ_bX
[YZ_bX
[YZ_bX
[YZ_bX
[XZ_bX
[XZ_bX
[XZ_bX
[YZ_bX
[YZ_bX
[YZ_bX
b@[(p
[XZ_bX
[YZ_bX
[YZ_bX
[XZ_bX
5A4!@#
[YZ_bX
[XZ_bX
[XZ_bX
pg@[(p
[YZ_bX
[XZ_bX
[XZ_bX
[XZ_bX
[YZ_bX
[YZ_bX
[XZ_bX
[YZ_bX
[YZ_bX
(r@Y(p
Pq@Y(p
[XZ_bX
[YZ_bX
[XZ_bX
[YZ_bX
[XZ_bX
[YZ_bX
[XZ_bX
[YZ_bX
#x\+7u
(OCt@#
[YZ_bX
[YZ_bX
[YZ_bX
[XZ_bX
[YZ_bX
[XZ_bX
[XZ_bX
[XZ_bX
[YZ_bX
[YZ_bX
[XZ_bX
#d\u#@O
[YZ_bX
[YZ_bX
[YZ_bX
[XZ_bX
[YZ_bX
[XZ_bX
[YZ_bX
[YZ_bX
[YZ_bX
[XZ`(G
[XZX(Y
[XZX(Y
[YZX(Y
[XZX(_
[XZX(Y
[XZX(Y
[XZX(Y
[YZX(Y
4VaifXXaf
1aiXaX
J4$aiZZXY}
Zeaeafe
aCfaia}
#+#6?/=
#Y A!#j
aiffXeX
ZZaaee
!a@aiX
;aiXYee
TBGaiaY
XaYYY}
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
PADPADP
9rq(-(
UIjalB
r72pM[
F_'+ghV
0LzCy9y
?|B0{^
R%&IL|r
mA0{S%h
M+,]Cf
OH([pU
E;1GYu:
6Megy&|{rB>
E=sEyo
"A8N<b
<2H?KSx\
{N^w*G
'axtEe
BP\u'pMv
BP\u'pMv
:|w`kl
iDJl1e
{LG1 M%k
Q]v$.gm
+vT#f4o
LuHJDr
I~GS=YZ~
B![ZO~
VB@6Wb
^ndFBg
zd*+7I
wIc)Qw
>d9O9;
JRB=)5
n-M4wr(
)J%H7j
![~{n|M
`sP?,I2
0QRD*
fy?m;3
*pCMdVAO
}^hw,K
E0\:%'B
:*-/wN
U?!hNw
FBq<10
+:*Hb?)
XZLTm~
ZR:H%w
%Ebjm}
6>,$At
{?$04R
-.<qR"
P"I]dY
FMpX#(
p!a{~,
g[uuus
"^_[r,
4:p%yl
7@N`828
*-Mpre.-jd
ntXS_{
Rn4V}I5,Q9P}
U5g#V$
J/T~Q-
j{lBOl
,5ABfy
>u6aS#
]a1:oYM
@Gr=`$
f}Qh^~B
wXf?I'
(80D]`
\)`b;2
]&Vm37
b"e|9;
+K{A#1
)HzE*W"
X'foERYY
4l7PlqC{
VZW ~
V9r6z}
ano+<v
8'CNX/:4
rc5#$*
mZb?IS
`8Us;*ZI
}rQG~&e
$qno8BZR
sta$h Y
Qz+v6Dc
Kn6Wo8
u4ys=`
A3g?%b
u|0w?1
(;)y^St[
Cp4B:n
7C4nLs
>>QBC<;b
'H}Fxt
b^@L&A+bY
&etaXG1J{
[Z1O#u
,KughM
3lS-('
.7~C(5
#H@pg&
2{i_L6
E`2_bc
(}4#;?(
gTN;y[
iO$Fo;
#E49t)
jvx(o|
yP/?`i
46]/}T
y?>0#)
*z1(cab
mODt@
vewc&-
k0V8T
D&<A[n?qK
{8-gtI
n'9U~X
}zUyQ.
O>!MP0(
3KUVE<
E63alE!
!qe9='
Ev~:+<
ezXyO;(
YJ0-^f
<PxdhO
:t;E_Y
;VChZo
c#103
D"*1f{
GR=IgWD
Y/|uZ(
pHR@8e|
Q?q11$
R t+Q?3
J=m;nN
R t+Q?3
g:q>=Y
Gagw*)KD&
'(S5=|
: M\KN
{;vtUKCq
Odx;a1
W+zm^=P
GF#10
MV&*$>
P1+V&*$>
*O$e~,
tq8pWC
^gn.98
1<!j(r~qI
BbSJ=VlbR^/
YM!"po
,uEX |
v4.0.30319
#Strings
#gsdsa.dll#
#fsdfsd.dll#
#faffafffffffffg.dll#
#gggggggggg.dll#
#hdfssssh.dll#
#khk.dll#
#lhl.dll#
#fdsfds.dll#
#jfffs.dll#
<ocjIrSciokm>b__0
$$method0x6004255-1
IEnumerable`1
SimpleLazyList`1
M_Item1
$$method0x600427a-2
ToUInt32
TypeInt32
ToInt32
198-Protector-V2
Func`2
TraceLevel2
Prefix4
ToInt16
MDWriteMethodBodies6
<GetAssemblyRefs>d__278
get_UTF8
<Module>
FbfbpIncrSA
kcFjbonoplA
TASK_STATE_FAULTED
MemberRefMD
PAGE_READWRITE
effhlkldFjF
S_MANMANYREG
pdkmAnjopAI
get_ASCII
ihrhnSFaadI
lcfrFdFpamI
System.IO
Ldloc_S
iFagrFpombS
bdkiImedmcS
lagdddAFFgS
ofpmAocfbkS
rddokcarAnS
fibmFdncjoS
LOCALE_INEGATIVEPERCENT
pnmjAhmSFa
khrkFohckca
mdcpronojda
UmAlQuraEra
CreateExtraData
_GetPropertyOrFieldData
FindData
rcdata
dmkhdSoabab
mscorlib
rniAnpIleAc
InAgkkcIAhc
System.Collections.Generic
get_IsStatic
fFAoeFkfIoc
mkmapIhfdoc
GetProcessById
lpNumberOfBytesRead
hThread
get_CurrentThread
thread
ApjaFpdfjdd
RijndaelManaged
get_IsAttached
M_parseDeferred
ReaderClosed
Get_IsCompleted
Get_IsFaulted
IsPathRooted
IndexesIsSorted
Set_Reserved
IsValueInitialized
hjAgnoebpmd
m_dateEnd
set_IsBackground
DynamicMethod
DefinePInvokeMethod
ResolveMethod
GetRemoveMethod
GetMethod
method
NetGuard
lkIecIlIlFe
get_IsInterface
Replace
IDisposableNamespace
MayCorruptInstance
LoadResource
FindResource
SizeofResource
GetHashCode
SetCode
set_Mode
CryptoStreamMode
CipherMode
IsCharSetUnicode
Xenocode.Client.Attributes.AssemblyAttributes.ProcessedByXenocode
DebugAssertLongMessage
DefaultMessage
EndInvoke
BeginInvoke
Locale
Set_ParamTable
ImplMapTable
GetEnvironmentVariable
Enumerable
IDisposable
set_Visible
get_Handle
RuntimeFieldHandle
get_MethodHandle
RuntimeMethodHandle
GetModuleHandle
get_TypeHandle
RuntimeTypeHandle
CloseHandle
GetFieldFromHandle
GetTypeFromHandle
Console
get_Module
DefineDynamicModule
hModule
GetInMemoryAssemblyModule
module
set_FormBorderStyle
get_Name
GetTargetFrameworkName
lpApplicationName
functionName
lpName
KeyName
AssemblyName
dnAdSgIShme
lpCommandLine
WriteLine
rperpe
get_FieldType
TryChangeType
DefineType
CreateType
ValueType
get_DeclaringType
Set_MarshalType
M_encodedEnumType
flAllocationType
get_ReturnType
lpType
ReadFieldOrPropType
get_ParameterType
System.Core
HashCore
ResolveSignature
SetLocalSignature
Runculture
IsNewCapture
Uncapture
MethodBase
Set_IgnoreCase
Get_OrdinalIgnoreCase
Dispose
Truncate
OpenOrCreate
CreateDelegate
MulticastDelegate
set_WindowState
FormWindowState
STAThreadAttribute
CompilerGeneratedAttribute
UnverifiableCodeAttribute
IndexerNameAttribute
UnsafeValueTypeAttribute
BabelAttribute
SuppressIldasmAttribute
AssemblyInfoAttribute
YanoAttribute
DotNetPatcherPackerAttribute
BabelObfuscatorAttribute
CryptoObfuscator.ProtectedWithCryptoObfuscatorAttribute
DotNetPatcherObfuscatorAttribute
DotfuscatorAttribute
CompilationRelaxationsAttribute
SmartAssembly.Attributes.PoweredByAttribute
DebuggerDisplayAttribute
RuntimeCompatibilityAttribute
SetValue
get_IsAlive
Add_ResourceResolve
dkSaoafInk.exe
get_Size
dwSize
SizeOf
TrySZIndexOf
fsafafwwwwwwwwaf
IsTypeDefOrRef
get_IsByRef
fasfkkfff
CJKDaySuff
HasDeclSecurityTag
_balancing
System.Threading
ExactPropertyBinding
Encoding
IsLogging
m_hashing
Ceiling
AggressiveInlining
FromBase64String
OutputDebugString
ToString
ReadUserString
GetString
StringToLong
ldeIiShdjpg
Get_IsNativeVarArg
TidyMatch
hhhhhhhhhhhhhhhhh
lhhhhhhhhhh
kkkkkkkkhh
SbnAmrdpbjh
aFAmbonScmh
fnpmFhkirnh
ComputeHash
get_ExecutablePath
ObfuscatedByGoliath
get_Length
HaveMonth
ISkoAdISAFi
ISCIIBengali
IAgdmnfpImi
TelnetUri
ConvertGregorianToHijri
IsCharSetAnsi
eaIpigabjbj
gFpdofSjmpj
omogdgdrppj
AsyncCallback
callback
ResizeParameters_NoLock
Insert_NoLock
FlushFinalBlock
TransformFinalBlock
mmalmoafcek
jrbAridnrgk
dkSaoafInk
mkebmAjmpnk
InlineTok
mrdhdFfkbrk
TicksMask
Marshal
get_IsLiteral
Op_LessThanOrEqual
ILevel
CheckLevel
Tailcall
kernel32.dll
Control
Memcpyimpl
CryptoStream
DotNetStream
MemoryStream
Program
mkhajbklcdm
phkaAlFbSem
kmlfkfjFrem
get_Item
System
mamSjmffAgm
SymmetricAlgorithm
HashAlgorithm
ocjIrSciokm
ICryptoTransform
GetCurrentTextElementLen
get_MetadataToken
MethodDefToken
hToken
TimeSpanToken
ProcessToken
lpNumberOfBytesWritten
jjvvvvvvvflhhhhhhhhhfffffffffffffffsssssvhn
AppDomain
get_CurrentDomain
UnlockRegion
GetCor20RuntimeVersion
MinorLinkerVersion
Application
get_Location
NineRays.Obfuscator.Evaluation
System.Reflection
ManagementObjectCollection
CallingConvention
_unhandledException
RuntimeWrappedException
UriFormatException
SetException
StripSecondsFromPattern
DateTimeOffsetPattern
mFgdfibmaIo
GetDynamicILInfo
FieldInfo
MethodInfo
startupInfo
MemberInfo
ParameterInfo
hResInfo
Ibnaekikiko
kiellgoAplo
ENCMap
BlobHeap
copddlemcdp
rhilrmSFgfp
PopGroup
System.Linq
set_ShowInTaskbar
Use32BitOptionalHeader
Reader
MD5CryptoServiceProvider
DESCryptoServiceProvider
SetErrorMode_VistaAndOlder
MethodBuilder
ModuleBuilder
TypeBuilder
_EventBuilder
AssemblyBuilder
lpBuffer
ResourceManager
Set_Logger
Debugger
ManagementObjectSearcher
AppendHelper
IsSubsetOfHelper
StringParser
ContainsGenericParameter
writer
get_IsPointer
BitConverter
Issuer
ToLower
GetTokenFor
ManagementObjectEnumerator
GetEnumerator
.cctor
dotNetProtector
get_IsConstructor
CreateDecryptor
ReadIntPtr
HasEventPtr
System.Diagnostics
GetMethods
SetInterfaces
System.Runtime.InteropServices
System.Runtime.CompilerServices
System.Resources
dkSaoafInk.resources
Get_Overrides
_codes
GetProperties
bInheritHandles
EnableVisualStyles
EmptyTypes
<>3__types
EnumSignatures
lpThreadAttributes
MethodAttributes
TypeAttributes
MethodImplAttributes
GetCustomAttributes
lpProcessAttributes
Get_TotalMinutes
GetBytes
<>3__wsQueues
BindingFlags
dwCreationFlags
GetMethodImplementationFlags
SetImplementationFlags
Get_BigStrings
CreateMetaDataChunks
Equals
System.Windows.Forms
Contains
CallingConventions
Get_Options
get_Chars
UpdateIOPadBuffers
GetOptionalCustomModifiers
GetParameters
NestedClass
get_IsClass
CustomFormatClass
AssemblyBuilderAccess
hProcess
CrossProcess
GetCurrentProcess
lpBaseAddress
lpAddress
IsWriterInProgress
GetAmbiguousTimeOffsets
Modulus
S_LDATA32_16t
Concat
DigitFormat
ManagementBaseObject
GetObject
object
Select
flProtect
LowercaseSet
CharSet
Get_HeaderOffset
GetStartOffset
op_Explicit
System.Reflection.Emit
SetCompatibleTextRenderingDefault
IAsyncResult
result
ToUpperInvariant
System.Management
lpEnvironment
InitializeComponent
MemberRefParent
get_Current
CheckRemoteDebuggerPresent
IsDebuggerPresent
infinitelyRecursingCount
GetGenParamCount
textToDecrypt
ParameterizedThreadStart
Convert
BindableSupport
FailFast
IsGenericInst
Get_DnsSafeHost
M_deserializedFromEverett
DefaultMatchTimeout
Set_Layout
SuspendLayout
ResumeLayout
MoveNext
System.Text
TargetSyncContext
context
GetDateTimeNow
ToArray
FromBase64CharArray
get_IsArray
MaxBeepFrequency
set_Key
CreatePublicKey
GetAssemblyNameKey
InternationalRegKey
secretkey
System.Security.Cryptography
DefineDynamicAssembly
Get_CallingAssembly
GetExecutingAssembly
UpSystemOnly
BlockCopy
library
OpenScopeOnMemory
ImageDataDirectory
lpCurrentDirectory
op_Equality
System.Security
SuppressUnmanagedCodeSecurity
IsNullOrEmpty
198 Protector V2
System.Security.Permissions.SecurityPermissionAttribute, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089
SkipVerification
WrapNonExceptionThrows
_CorExeMain
mscoree.dll
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<assemblyIdentity version="1.0.0.0" name="MyApplication.app"/>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v2">
<security>
<requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3">
<requestedExecutionLevel level="asInvoker" uiAccess="false"/>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
dkSaoafInk
GetEnvironmentVariable
-978364641
978337327
_ENABLE_PROFILING
_PROFILER
1063228817
1063189963
-2038783962
2038785539
1090771050
1090710362
665209230
665247064
-622854845
622974496
-642470817
642331547
992165451
992158418
-623792232
623829092
-436975266
436977851
-2110941861
2110930223
-159654596
159685632
809357050
809327642
1061596195
1061554057
-738067849
738102192
-1599153140
1599096223
1933421444
1933371685
-1436546101
1436371636
-983274324
983287697
743671539
743701489
-1523788792
1523813269
-1807708654
1807695572
-1026754094
1026758932
1045231393
1045184162
-289883697
289807949
-1177197304
1177270449
730363601
730408940
434177286
434195431
-193933342
193886264
-198744693
198828184
833903139
833947082
1234655050
1234673503
-1526272867
1526237974
1643388873
1643401344
636259518
636346483
-363814227
363829463
-1554100849
1554018321
-528858937
528827502
-1710837760
1710768350
167718388
167644053
1740652388
1740652953
1557856893
1557823876
1027775068
1027836996
2083200158
2083229501
451676839
451684371
849155013
849179312
-1150824190
1150900598
-446167192
446168059
693485262
693496214
-151460777
151485754
-937522135
937624774
219900252
219929364
-2036972976
2036914050
-1345014829
1345059405
-277887776
277944728
-203342579
203220825
-1708094174
1707957473
528438943
528362373
913834260
913898519
-145067089
144966214
-1671361864
1671404849
-1607495564
1607543044
1469245831
1469232517
790556728
790545375
1372294757
1372265335
-1978805863
1978848358
-2093773103
2093856554
-146729740
146727209
1970292676
1970280409
-876016142
875991238
1291428246
1291354601
1695802384
1695797271
1031040980
1031042336
-115852270
115841655
-2000601099
2000656097
2093825892
2093750686
-1513012882
1513026264
-1335972528
1335917842
2101692818
2101714605
725609000
725582180
-734118755
734122257
-148958517
148986997
1696140021
1696174718
782568356
782625989
-504919193
504956216
-1477773987
1477776458
-649204268
649239664
-1414689499
1414734305
1482201563
1482268664
-232918788
232992596
317997200
317988003
-1078575094
1078690135
-689719498
689732523
1758483116
1758532617
-228505004
228484812
-964552828
964512334
2066830958
2066821318
816519188
816516728
234810660
234770837
2087058661
2087024947
1160134845
1160162203
888114674
888065105
752162053
752108963
-708831012
708731146
-889316961
889316946
907878171
907829853
-808384164
808444349
1508000754
1508023672
-2070741364
2070708478
-1088064641
1088143619
-1760086325
1760067679
-1085240877
1085151729
-821680616
821663864
362633702
362553172
-1033956582
1033962803
-580393818
580455972
1621860732
1621855496
-642346628
642308085
-868702732
868730236
2115919819
2115897967
-1768356238
1768292679
466841392
466817253
-1818043429
1818030556
-1608766222
1608633286
1735514806
1735435786
-30986481
30938211
1677471401
1677500549
-1172930874
1172853659
-1421683621
1421835992
20877119
20898984
1392946073
1393010462
1724400754
1724413981
-1454250420
1454251069
-1002242338
1002295698
-1863808477
1863797157
828722076
828721637
438247942
438202185
-804515581
804513223
228799700
228729363
-640745631
640734089
-395524322
395419107
714282652
714243993
1447679446
1447620056
1595121987
1595120215
2115304701
2115273373
470743266
470710515
1622862996
1622865737
-1582116152
1582156868
1590604420
1590666343
-89216512
89132770
-70172970
70181980
-1362556060
1362579449
644181788
644090171
-843919655
843912921
-104040463
103960057
529226097
529207805
891438182
891487368
418363583
418379183
1791559213
1791590969
1655733378
1655751910
1111137910
1111213455
1489804497
1489793203
328011101
328041216
1020149062
1020154034
1179703085
1179655644
2025322806
2025263536
-298629318
298609465
-1252477723
1252447836
1725766335
1725806030
-689727268
689711168
472754825
472731744
-1300955372
1300866967
417091379
417080689
-140487287
140425708
1977877147
1977899737
505986561
505991818
1663011439
1662959000
117238051
117216517
-1923802461
1923834965
-1182204906
1182213553
288128117
288129572
-1352252899
1352183125
-1035708067
1035709817
-753319176
753154776
-2127959917
2127991212
-1482391602
1482415733
1655291039
1655294414
-1006218275
1006176641
1688898933
1688973903
112500044
112516614
1342367151
1342367310
298171187
298100055
1242540170
1242552785
-749083684
749111864
1278506716
1278531622
-361980135
362000767
-131624207
131597981
1028348336
1028372524
-163708643
163704965
1931126860
1931135533
1558748140
1558743019
-628988222
628888288
1062205077
1062133822
-1822764295
1822724981
-166778079
166732850
-1513123148
1513202288
718088157
718037943
-156256685
156269266
1480755093
1480783286
1102562663
1102544347
-776024329
775991680
1718157502
1718115689
1789459962
1789419097
-750564237
750575686
617734138
617716889
358622272
358648445
-630204684
630255105
1231937598
1231854029
2014088044
2014101539
-1897189442
1897317323
296447441
296466439
-2002323360
2002472200
-1383559091
1383415299
-647186078
647136564
6199470
6291428
790942783
790895008
281830279
281864785
1264994499
1265008227
477621116
477587222
-1592159710
1592147427
-93678446
93594858
467344206
467386791
-887048904
887090115
683456049
683445192
-418291536
418124600
-1464508060
1464576949
-612493590
612389770
707616556
707616320
1442280715
1442199696
-104185487
104142616
-1913082244
1913097676
-1869546638
1869416928
-1710169935
1710205059
-116851477
116846936
1169129338
1169057215
-1586802892
1586785728
729015865
728988976
-236128022
236085036
1784481204
1784486755
1941132939
1941067651
-823856469
823861412
-2015760323
2015791848
-260008915
259939769
1970223623
1970174376
1113230369
1113201719
-624826812
624906277
1483699604
1483715709
-261540484
261583846
1109008572
1109029191
123288977
123289688
1423255950
1423250650
1745164964
1745164920
-286462560
286464018
2067888809
2067876215
-747415524
747431375
-212652395
212661424
-1755025370
1755051256
-2073491526
2073430549
1920226778
1920270057
524955612
524978004
2010007614
2010051435
438887689
438872881
-217623626
217696441
-1795342770
1795207905
-416137784
416105731
-1925831103
1925937345
954804895
954752617
1352454638
1352523450
-1726015195
1726007681
1480178182
1480105717
-1884108658
1884231440
391972690
392016864
-1604259374
1604229943
1087427797
1087434944
227300578
227318300
-373588997
373615535
240572337
240616753
941956192
941981114
-113024372
113148018
1524805986
1524862433
2084654007
2084664771
-1115558050
1115594607
-253147847
253211876
-1217785555
1217781231
2132970352
2133044428
-389651873
389639636
70321059
70328024
-494835614
494865959
-411547201
411557119
1960359290
1960430164
-1977697397
1977689053
1774710618
1774702043
-972461856
972427711
1839995722
1839992779
1870655256
1870619835
-318304202
318295253
-426703016
426688538
-1583224889
1583265968
1341815511
1341823726
-433808541
433687593
-1424568765
1424525008
-1813376542
1813365272
-1092927005
1093053561
319323556
319373540
-1292928826
1292994634
154316993
154272396
-1809455452
1809461527
930254062
930242885
89858528
89809425
738528470
738553205
1212556449
1212581950
1907518747
1907543596
1910694206
1910642283
-2074029704
2074037429
2071401213
2071398290
-1354378999
1354271171
-1595139596
1595083124
-244711489
244591812
-625838865
625980824
1413318590
1413290166
1230799738
1230817953
-1512603878
1512617269
1429250667
1429319487
1110138528
1110126381
-1991836619
1991873897
-1376593261
1376601717
1580833818
1580797203
1282624574
1282543698
-1621509544
1621614147
1534029296
1534043716
11432141
11494233
731271404
731296205
1115465214
1115436846
1299197762
1299210345
-1144586146
1144538826
-1283839669
1283828117
-1921993312
1921975103
1672469906
1672471838
687660514
687652960
399034531
399047325
355675537
355726650
1715503260
1715515702
-825980217
826006749
-1745592082
1745555259
210455264
210500717
516422909
516325395
-1931794518
1931743062
-1049658959
1049680846
-2119220860
2119288810
544648342
544637082
-908358833
908358053
-833832749
833810833
645875280
645815374
-1985369231
1985412404
-1676795415
1676724158
1043294945
1043211569
-883894200
883865010
752316984
752315956
905710042
905792986
-606939792
606958146
-1668742017
1668605235
490716368
490643828
-681775694
681678143
1886643624
1886623269
-1493563569
1493526610
1582214722
1582211384
-1079332950
1079270308
1404422634
1404429864
-1147110737
1147083783
273378843
273366387
1062638560
1062615460
-1688984473
1688813756
1356776282
1356762163
395653520
395673260
managed
native
dkSaoafInk
Select * from Win32_ComputerSystem
Manufacturer
microsoft corporation
bbbbbbbbbbbbbk
mmmmmmmmmmmmmmmmmmmm
bbbbbbbbbbb
87654321
404949087
405002703
-1433877777
1433919152
1335852507
1335781433
0Qk+TtY22pTwJwdERaCFH+hlcYRy9z8j
0Qk+TtY22pQ2HYwX/8SrxpwZDV7k21hH
DynamicDllInvokeType
aCVUUaLnfW4=
-1762717880
1762803415
-1449772139
1449765969
-1623453750
1623374242
1308877948
1308815916
706089847
706167221
-1943714196
1943728146
1998734638
1998812484
-1672690167
1672690490
-159354486
159372101
136657729
136646531
1415225791
1415240624
1429584878
1429531619
-235325367
235366791
-507036648
507011876
-772210240
772234250
1542788995
1542730545
1180486049
1180557913
428896590
428875343
1892557273
1892582976
-1253657963
1253624190
-1081378353
1081355244
-1898492591
1898522072
-142417353
142556672
-851513713
851557453
1490301323
1490328775
-548627364
548604771
-1442203549
1442281829
gctFzea5CEy81mJ72DsIIA==
MiE2sU17DFAFqQHRtdtThtONuB4yGkmU
afPz6RjIsAdfRQc7/aeBjHj+fESkpOD1
qVROzGra+8klaOR0WtRW8WHbbsE1cDZH
Kc3N3snbu6HWGHoTaK+Tbw==
LaBtmTwmlxgCL0GStSTkSo8HWuRuZOhZ
uaJCVA0DJWMBw/7j8HxDKxXuKhwuX7UU
Bj2WY32ndn3CSrA0orUJZ6FKrc5EMQEP
I2SCg4uCyv9ikaPtVe2+iA==
D5XWikV5qiezXKmIYVEIRA==
4qWTm8mA+PbNfykAKT2fXnrATcavMgJv
MAINICON
Select destination folder
Extracting %s
Skipping %s
Unexpected end of archiveThe file "%s" header is corrupt
%The archive comment header is corrupt
The archive comment is corrupt
VS_VERSION_INFO
StringFileInfo
040904b0
CompanyName
nklIkdmd
FileVersion
5, 4, 7, 9
FileDescription
kmkknpdm
LegalCopyright
ProductName
prghmfi
ProductVersion
5, 4, 7, 9
VarFileInfo
Translation
Antivirus Signature
Bkav Clean
Lionic Clean
Elastic malicious (high confidence)
MicroWorld-eScan Clean
FireEye Generic.mg.9c87428041d39d0b
CAT-QuickHeal Clean
ALYac Clean
Cylance Clean
VIPRE Clean
Sangfor Suspicious.Win32.Save.a
K7AntiVirus Clean
BitDefender Clean
K7GW Clean
Cybereason Clean
BitDefenderTheta Gen:NN.ZemsilF.34236.zm0@a8nt4oji
Cyren Clean
Symantec Clean
ESET-NOD32 a variant of MSIL/Injector.VRI
Baidu Clean
TrendMicro-HouseCall Clean
Paloalto Clean
ClamAV Clean
Kaspersky UDS:DangerousObject.Multi.Generic
Alibaba Clean
NANO-Antivirus Clean
SUPERAntiSpyware Clean
Rising Clean
Ad-Aware Clean
Emsisoft Clean
Comodo Clean
F-Secure Clean
DrWeb Clean
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition Clean
SentinelOne Static AI - Malicious PE
CMC Clean
Sophos ML/PE-A
APEX Malicious
GData Clean
Jiangmin Clean
Webroot Clean
Avira Clean
MAX Clean
Antiy-AVL Clean
Kingsoft Clean
Gridinsoft Clean
Arcabit Clean
ViRobot Clean
ZoneAlarm Clean
Microsoft Trojan:Win32/Sabsik.FL.B!ml
Cynet Clean
AhnLab-V3 Clean
Acronis Clean
McAfee Clean
TACHYON Clean
VBA32 Clean
Malwarebytes Clean
Panda Clean
Zoner Clean
Tencent Clean
Yandex Clean
Ikarus Trojan.MSIL.Injector
eGambit Unsafe.AI_Score_99%
Fortinet Clean
Avast Clean
CrowdStrike win/malicious_confidence_70% (D)
MaxSecure Clean
No IRMA results available.