Static | ZeroBOX

PE Compile Time

2021-11-01 09:03:15

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x00069a54 0x00069c00 6.68731679311
.rsrc 0x0006c000 0x00010f2a 0x00011000 4.07908206227
.reloc 0x0007e000 0x0000000c 0x00000200 0.101910425663

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x0006c18c 0x00010828 LANG_NEUTRAL SUBLANG_NEUTRAL dBase III DBT, version number 0, next free block index 40
RT_STRING 0x0007c9b4 0x00000178 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_GROUP_ICON 0x0007cb2c 0x00000014 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_VERSION 0x0007cb40 0x00000200 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_MANIFEST 0x0007cd40 0x000001ea LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with CRLF line terminators

Imports

Library mscoree.dll:
0x402000 _CorExeMain

!This program cannot be run in DOS mode.
`.rsrc
@.reloc
]aiZefY}
zceW@#
@Z@Z(p
@M@[(p
@A@Y(p
@V@Z(p
`S@X(p
`P@X(p
Q@Z(p
Oz$f@#
[YZ_bX
#24[FC
[YZ_bX
[YZ_bX
[YZ_bX
#(9 eI-
[YZ_bX
[XZ_bX
[XZ_bX
[XZ_bX
[YZ_bX
[XZ_bX
[YZ_bX
[YZ_bX
[YZ_bX
[XZ_bX
[XZ_bX
[YZ_bX
#X)IG~
[YZ_bX
[XZ_bX
[XZ_bX
[YZ_bX
[XZ_bX
[YZ_bX
[YZ_bX
[YZ_bX
[YZ_bX
[XZ_bX
[YZ_bX
[YZ_bX
#cITJf
[XZ_bX
#HxVHf
[YZ_bX
[XZ_bX
#=3ZB
[XZ_bX
#t'7Hg~
[XZ_bX
[YZ_bX
[XZ_bX
[YZ_bX
#be05H
[YZ_bX
[YZ_bX
#-K'v3
[YZ_bX
[XZ_bX
[XZ_bX
[YZ_bX
[XZ_bX
[YZ_bX
Xq@[(p
Hp@X(p
[YZ_bX
[XZ_bX
[XZ_bX
[XZ_bX
@y@[(p
[YZ_bX
[XZ_bX
[YZ_bX
[YZ_bX
[YZ_bX
[YZ_bX
[XZ_bX
[YZ_bX
#@<Y4T]
[XZ_bX
[XZ_bX
[XZ_bX
[YZ_bX
[YZ_bX
[XZ_bX
[YZ_bX
[XZ_bX
[YZ`(G
[XZX(Y
[XZX(Y
[YZX(Y
[YZX(_
[XZX(Y
[YZX(Y
[YZX(Y
[YZX(Y
fYXfe}
NfgaiaXXY
aieYY}
hb [h{
aafeY}
effYYfe}
ZeYXaff
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
PADPADP
z(HGv+ |#^
L]NS-f
(N0t##l~
CV"cp.
PX?TM$
H*:8jm
~xA:9H
rN|*bD
-c3L`(w
cmZo50
X<CK3GU-
*Wejur4
S:F,.|
~`_)n\.
67%K.*
3FtCDg
q9_5C]
8p8[v8
H)IgU
Et<K#;
kL0?JI
OH_N?wX
5W(<xi
d:-PSP
Byf%<y
~VT!]v
W&l/[g>E
O{jbP\
,D:X;O(t
`m}.-\c
BBT;a@0
nry>S{
!W\/I^N
!7$a.bM
Ts[X|5
Qj1LEp
H]\Q;Dn
/d{"t5
%'gr7
i8EjEz3
-t1qz
/7(<m=Bz
yD&"i&d
Df?(i&
6_W}Bx
|lcR[^ol
C<8kXS
T[DLkFx@
7he1!E}
B{e9%5n
H}^oml
BTgik?x
~j54jr
W;fgal#
VlU2LP
(#/z3m_
o^RVD072
Ls?WRq
uFK(,$
}YU+RM
? 05kS>
lCe\Z'
tFI=dU@
lx-&Fs{
;Fz 5bb
:YCpNk
#3JACu
!:N#L.
k=oI-!
._fdC"1E<
]xz,1Q
(/jq!S
RGhUN5
#e{y}6
do84_*
=i+3B3c^
E4f=7t
n-5"cVW>
"DUN)\
B,'XpW
Q=E{`.e7
nr2J0]
)W"ye1
mKGt%w.
ij[5;a
jo+6DPe
n?,%cme
$aXqO=
-XUU!x
0x.QI(2r<
>9C56p
|ywF|h
)g$ptn
bvCrhiQW
|SY!mX
|*1#=\
A;JS$I
TkDy_s^
LZ|#]t
Fl>GhK
o6)umg
-[`r_
(/~ff~
$9r|xRGB
9pRk~vB
`Jo9Kx
:Q~lW/]
RFb1$/
\vF'TKp'
Q@QZDH
mc}H,b
wJ+H"n
Wn?;)i&
v=j^'!c
4{'@`~?
S'sKL>
Yr%E@3l
PRJ<5
R}Kdnl
)cC5#{
n;5E~y
5;aj};
{F?~#tv
@{@Nsn
\"n_jE
;[D:m%q
@DHiC9
(P\Xc n
LaZyE,
Ow:jCT
d?S@K+
^Y0m<E
-?R2v`
#8dl2`*
xJwirI
97:mTB
qVN1|,
ShQkg\F
Hr7A7$
C^wwFX
-\<cAh
C[Y|5u
a`\1z
1\cRTv
}H!F@l
I`vFGJ
rjB-hM
@du&W_
-/^?l^
YOG%)[x
_ar[R({
rj|C:{
U+E1k&
,U }ZQ
|!.O*7
r~RgDq
8NwS-*s
$;XK,%
oUhq_*FQ
rRo"m<
CiYB4R
j<a&&@
= p0ri
hj/NH~En/
tN[]]k3
#4\o_[:
yt,B1%
A"zoN_
xj[@Vx<9
$EVvx)
k|18`et
>=',<\
)KoF[Ahs:h
Q( cHI8
R{}}A7
~jUW|}
-G\$\+
:<,_j}
KisQNpX
)4M.Q@
8T.`5X
X'2tp
S}:YNG
V"re(m
giu1]g
'6^.<DZ
\FX;f[p
D-iTNLP
Q)R$ @
?]iTNLP
~YNs.D
Y6gm#Am
Nl1O22BR5
B1=ilT
28D+R-
4y;f*:
4y;f*:
'`Ar]:OS
*=W2$C.}(w
8%0fm,
(=-[D&XI
iAjm1M
jos5r_
:69':,t
T8e1sjF
J9iW]c
D7Yn]l
gXM3`*,
i/Bx|cgil
VJ7l!I.l
y>\+T#J,N
%BVP#]c
[nX&[H
Lb{yEf
wl,0m,
ucQs`#2
B$x$qX
5WnI_q&V
a4UX),
-4GcC(
JAt!"H
M3jV5p
7D@?t[
}%dN\{
L5+*Mxr*
%-B^&D
\?C:hi
f5Rla_
VEki=^0
C_vOk+
><W}wx
SkIY-Yy
CWa>gd
BQLASD
W3E<?'
Jma(/,"
7F|ZW%
W+<FqK
%GG)&*g
ffsx_>a
gU0KNH
H=cjD4'
u(~]n9$
II}/]%
~p{s'*
8l/Rkx
B0*1cj
?s+c0c
W74oXM_
jtU@tI
&ZF?LK
3hsfwQ/W
$%X7KP
.HY9r"r
1|'NSW
^y-<z-
J]+CgK$
%ItdfU
iX.MM>
HMq~7B`
NR+i2e
>p"37k
"BweVr0
4Jq$0iB
_#r8FB
Nm0V+n
uH}G9V
TnZ53.v
Iky1A-
}:=M,H
`VoXhU
xgUY)U|
Cxz2B%
~;&=h)
/m1=QAE
@TuY)?
i1![9z'1
1^8u(xp
^)]c$9U
qHiE8&':G{6
FN8q4+
v"Hj.^?V
UiL)Lz]p
4)5}'[f
IrLd/X
!3,[J)
0.| <
2\K=8sz
sh)m\g
D~Wp!2
>QXT=o
r[<(ec
-n$8["t
a/"-[Y
gST)4>
Yqb|D=
u^r'kk
lSlCIm
1x?hZ|
:xZXO/
e"`~|h+
J!hF-C^
%^wOGPg
bf-.Q
.|@|)2
~-PQr4
|8.Q2)
ZJ.SJ*
dt@Q9;
+Yi~C
/Y%JM,
I** ?!%]>
?rh>9^
J$%85L
$sJYW-6D
[%S~y'
Q84F%IO|
}8R_&X
iuFmJ}I
r=AU$[*
\aELnp#,
GLq-3{
hpg(|M3
}D^4g%
44$4bZ
Cm-kD"s$
v4.0.30319
#Strings
#gsdsa.dll#
#fsdfsd.dll#
#faffafffffffffg.dll#
#gggggggggg.dll#
#hdfssssh.dll#
#khk.dll#
#lhl.dll#
#fdsfds.dll#
#jfffs.dll#
<oijFegFhmpg>b__0
DaysTo1601
IEnumerable`1
ImageOptionalHeader32
ToUInt32
ToInt32
198-Protector-V2
Func`2
<Initialize>b__89_15
ToInt16
get_UTF8
<Module>
imddkolaIaA
jccmfggnkjA
VT_BLOB
S_FILESTATIC
ListImplMapMD
ListConstantMD
DEFAULT_SIGNATURE
EnvDTE
rmpdImpachF
pmdbiebpikF
kIblSagagmF
kkdkhjAdhpF
gkFbgrnmSAI
rrldmFndFFI
get_ASCII
SAmchfkmolI
GetURL
DX_YNN
ERROR_UNKNOWN_REVISION
LOCALE_ITIMEMARKPOSN
GetTimeOfN
System.IO
SECURITY_ANONYMOUS
pjjarlrSihS
mfodoIbkkjS
jjaScakFkmS
TIME_ZONE_ID_DAYLIGHT
RID_MAX
TmDigitizedAspectX
<.cctor>b__a
IsChildReplica
jFidlngrcga
cSdAmmhmeka
GetCultureData
rcdata
Get_Delta
M_delta
InitializeBodyFromPdb
mscorlib
mfmdfAimnmb
ApFmpbSraFc
System.Collections.Generic
get_IsStatic
InternalAlloc
gcfIdjloeId
TypeDefId
bprgibrmrId
GetProcessById
TrimHead
lpNumberOfBytesRead
hThread
get_CurrentThread
thread
RijndaelManaged
get_IsAttached
IsMatched
CtorCollectibleOpened
IsValid
IsEntryPointValid
set_IsBackground
DynamicMethod
DefinePInvokeMethod
ResolveMethod
GetMethod
GetSetMethod
method
IgnorablePeriod
NetGuard
jnddpmiImrd
get_IsInterface
Replace
Set_Namespace
Get_DataSource
LoadResource
FindResource
SizeofResource
GetHashCode
SetCode
TryCode
set_Mode
CryptoStreamMode
CipherMode
Encode
Xenocode.Client.Attributes.AssemblyAttributes.ProcessedByXenocode
DebugAssertShortMessage
S_typeCache
EndInvoke
BeginInvoke
Get_CompareAssemblyLocale
CustomAttributeTable
GetEnvironmentVariable
Enumerable
IDisposable
set_Visible
IsPreamble
Int64BitsToDouble
get_Handle
RuntimeFieldHandle
get_MethodHandle
RuntimeMethodHandle
SafeHandle
GetModuleHandle
get_TypeHandle
RuntimeTypeHandle
CloseHandle
GetFieldFromHandle
GetTypeFromHandle
Console
M_firstPermSetTriple
get_Module
DefineDynamicModule
hModule
module
set_FormBorderStyle
get_Name
BindToMethodName
TargetTypeName
JapaneseLangName
lpApplicationName
functionName
lpName
FixupName
FindTypeDefByName
FrameworkDisplayName
AssemblyName
M_utf8name
lpCommandLine
WriteLine
ScanCharEscape
Get_RootScope
rperpe
get_FieldType
DefineType
CreateType
ValueType
Set_DeclaringType
get_DeclaringType
Arg_WrongType
flAllocationType
GetDefinitionType
get_ReturnType
lpType
get_ParameterType
System.Core
RegexBoyerMoore
ResolveSignature
GetMemberRefSignature
SetLocalSignature
MethodBase
Dispose
Truncate
CreateDelegate
MulticastDelegate
UserSuppliedState
set_WindowState
FormWindowState
NestedPrivate
STAThreadAttribute
CompilerGeneratedAttribute
UnverifiableCodeAttribute
UnsafeValueTypeAttribute
BabelAttribute
SuppressIldasmAttribute
AssemblyInfoAttribute
YanoAttribute
DotNetPatcherPackerAttribute
BabelObfuscatorAttribute
CryptoObfuscator.ProtectedWithCryptoObfuscatorAttribute
DotNetPatcherObfuscatorAttribute
DotfuscatorAttribute
FlagsAttribute
CompilationRelaxationsAttribute
SmartAssembly.Attributes.PoweredByAttribute
RuntimeCompatibilityAttribute
Get_TypedValue
WriteValue
SetValue
VerifyValue
get_IsAlive
ModuleResolve
TypeResolve
iokpaSfbph.exe
get_Size
dwSize
SizeOf
fsafafwwwwwwwwaf
get_IsByRef
fasfkkfff
M_windowFlag
mkmkockcnag
nmFImofbmcg
ReadTypeSig
TryGetValueTypeSig
dkrgkmkknig
System.Threading
Encoding
IsLogging
Ceiling
FromBase64String
OutputDebugString
TokenString
VersionString
ToString
GetString
Remoting
oijFegFhmpg
Get_FindExactMatch
NextMatch
hhhhhhhhhhhhhhhhh
lhhhhhhhhhh
kkkkkkkkhh
khhebpbkgih
oimfImmmSkh
iokpaSfbph
ComputeHash
get_ExecutablePath
ObfuscatedByGoliath
M_path
get_Length
StringLength
M_handlerLength
kofpnndbpci
EscapedAscii
nlepkffFni
CreateUri
igIoImmfdkj
klccombmFmj
AsyncCallback
M_timerCallback
callback
GetStringHandleOnStack
get_KeepOldMaxStack
FlushFinalBlock
TransformFinalBlock
iIkpmSdrgdk
fokkrblkodk
mikmefdmdgk
kmkpkiIoogk
efpkmkefnik
SSbknkIpjmk
FieldAccessMask
BestFitMask
KindLocal
Marshal
Sentinel
lrkamkaloil
Set_All
nmlekjkFIll
kernel32.dll
jpdbAaeijll
Akieajmjcml
ChangeAccessControl
ToDataStream
CryptoStream
MemoryStream
Program
get_Item
System
SymmetricAlgorithm
HashAlgorithm
iplrmfcmalm
fSokdrhSImm
ICryptoTransform
get_MetadataToken
hToken
lpNumberOfBytesWritten
jjvvvvvvvflhhhhhhhhhfffffffffffffffsssssvhn
AppDomain
get_CurrentDomain
Get_Version
MajorImageVersion
Application
get_Location
NineRays.Obfuscator.Evaluation
System.Reflection
ManagementObjectCollection
CallingConvention
RuntimeWrappedException
InvalidTimeZoneException
ThrowArgumentNullException
InternalCopyTo
GetDynamicILInfo
EhStartAddrFieldInfo
GmiContextFieldInfo
SetMethodBodyMethodInfo
ItemInfo
startupInfo
MemberInfo
ParameterInfo
hResInfo
ienjoiccIko
miIdmkgfFfp
jahmpeajFhp
ApmjIkbmiop
UriSchemeFtp
System.Linq
set_ShowInTaskbar
GetDefaultYear
ScanRepeatChar
MarkFinallyAddr
ReadHeader
CreateSymbolReader
MD5CryptoServiceProvider
DESCryptoServiceProvider
MethodBuilder
ModuleBuilder
TypeBuilder
AssemblyBuilder
lpBuffer
ResourceManager
Debugger
ManagementObjectSearcher
AnsiCharMarshaler
ZeroWidthJoiner
TypeNameParserHelper
CreateAttributeArrayHelper
get_IsPointer
BitConverter
ToLower
fdcddmjedjr
podokFdmImr
GetTokenFor
CreateInstanceDefaultCtor
ManagementObjectEnumerator
GetEnumerator
.cctor
dotNetProtector
get_IsConstructor
CreateDecryptor
IntPtr
MethodSpecs
System.Diagnostics
Get_PreserveParamRids
GetMethods
System.Runtime.InteropServices
System.Runtime.CompilerServices
System.Resources
iokpaSfbph.resources
_codes
DeclSecurities
bInheritHandles
EnableVisualStyles
GetValueNames
Get_s_systemTimeZones
EmptyTypes
lpThreadAttributes
MethodAttributes
TypeAttributes
MethodImplAttributes
GetCustomAttributes
lpProcessAttributes
GetBytes
SortedDefs
MetaDataFlags
Get_BindingFlags
dwCreationFlags
GetMethodImplementationFlags
SetImplementationFlags
Equals
System.Windows.Forms
Contains
CallingConventions
Get_Cor20HeaderOptions
DataInfos
get_Chars
EnumMembers
GetOptionalCustomModifiers
GetCustomModifiers
GetParameters
Get_Class
get_IsClass
Castclass
AssemblyBuilderAccess
M_access
hProcess
GetCurrentProcess
lpBaseAddress
lpAddress
NotifyWorkItemProgress
InternalGetComponents
Status
Concat
ManagementBaseObject
GetObject
object
Select
Intersect
flProtect
CharSet
AssertSet
Set_EndOffset
_64Bit
InternalRegisteredWait
op_Explicit
IsASCIILetterOrDigit
System.Reflection.Emit
SetCompatibleTextRenderingDefault
IAsyncResult
result
ToUpperInvariant
M_isInvariant
System.Management
Comment
lpEnvironment
InitializeComponent
get_Current
CheckRemoteDebuggerPresent
IsDebuggerPresent
ReadEvent
M_event
M_DocumentCount
textToDecrypt
ParameterizedThreadStart
Convert
FailFast
SuspendLayout
ResumeLayout
MoveNext
System.Text
WriteAllText
_logicalCallContext
context
RawEventPtrRow
RawConstantRow
GetBaseTypeThrow
ToArray
Get_IsArray
get_IsArray
set_Key
secretkey
System.Security.Cryptography
DefineDynamicAssembly
GetExecutingAssembly
AsReadOnly
PermitOnly
BlockCopy
library
RaiseExceptionIfNecessary
lpCurrentDirectory
HijriAdvanceRegKeyEntry
op_Equality
BinaryCompatibility
System.Security
SuppressUnmanagedCodeSecurity
IsNullOrEmpty
198 Protector V2
System.Security.Permissions.SecurityPermissionAttribute, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089
SkipVerification
WrapNonExceptionThrows
_CorExeMain
mscoree.dll
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<assemblyIdentity version="1.0.0.0" name="MyApplication.app"/>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v2">
<security>
<requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3">
<requestedExecutionLevel level="asInvoker" uiAccess="false"/>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
iokpaSfbph
GetEnvironmentVariable
284313100
284347156
_ENABLE_PROFILING
_PROFILER
1940616907
1940640559
-264237417
264156767
37211277
37213555
2026935397
2026911776
-558905722
559037828
744532592
744596264
-2038110838
2038044118
-218011309
217850437
-1340915802
1340922634
356388841
356399159
-1899435709
1899418142
-866117558
866027637
353225308
353152720
-1551879070
1551749793
804054780
804018965
-1302096771
1302220576
-629065133
629117158
-1349323941
1349323768
-931310242
931277176
1697120556
1697188429
-1321568451
1321507728
698294525
698286293
386606215
386610429
1141196904
1141231120
-1998227769
1998274152
-302595487
302628287
2122865550
2122879382
910894897
910891826
-1914966206
1914977099
-1274908764
1275014924
2017474517
2017544187
-1235424134
1235379724
971463572
971391164
-383625164
383604586
-1632550231
1632411568
-1103764656
1103663594
1534184294
1534197149
186233730
186158888
519514602
519470563
1763686147
1763643152
647068279
647058304
-714518904
714572453
1180026650
1179968218
-382030581
382054076
-635666834
635638862
912689234
912682381
1609062559
1609065677
-514532535
514518020
-1416556152
1416375563
322522696
322447720
-93067259
93138233
349722649
349741501
-1674978790
1674972920
916565169
916494968
1296023968
1295953783
1381445653
1381389809
1379040531
1379039167
-1981411703
1981287400
-187372925
187406962
-953375013
953393267
-888438149
888438750
-1005214433
1005242992
1499018889
1499006009
-235603633
235547187
-105757209
105695814
-80789234
80930390
-1105358638
1105208218
90435882
90434992
-206436831
206427279
2099622490
2099607961
173343425
173285499
1192385441
1192412152
661789164
661810658
-1225916261
1225857811
-562686227
562586972
-1971069911
1971135735
1256524396
1256565982
2062012793
2062004488
-1319202186
1319193239
1840566309
1840517559
264883310
264865805
143458955
143515056
-486037548
486163337
842861764
842918143
30592278
30557767
-674530090
674499241
984837902
984773191
1161815240
1161715766
-283174035
283190785
526167939
526125502
737688163
737711709
978415794
978433547
-2065341946
2065337309
229615405
229599161
-1525361994
1525367417
170155254
170157261
311643086
311662140
1969488978
1969561680
-684053601
683935085
1530488696
1530428722
-954932118
954971648
1513021367
1513013840
-184758000
184730341
267885361
267906529
47384645
47415561
-675272625
675228392
-655513773
655511471
824205035
824234572
388497279
388494616
-2043726147
2043706424
-790085976
790015837
-2043392657
2043329202
1262921894
1263000410
624859152
624882632
-1156978322
1157057579
-1440902667
1440957361
-165899185
165892956
-759146473
759116429
-588928550
588943658
248653915
248677655
1155022596
1155103201
410872595
410809610
-1210215610
1210222783
1195047824
1195016881
501734283
501678686
-852005911
852009562
-1134100039
1134158416
-768897795
769053112
560576719
560506407
-932286148
932299829
1800549879
1800597116
1978324023
1978397612
-1395553278
1395547714
16342382
16322334
-1639106561
1639060776
302663804
302645594
133431771
133434283
-547612996
547509456
-1620649006
1620662241
-1982790066
1982733509
-1931033259
1931079596
405084656
405028040
-1779693062
1779527572
-443804058
443732359
-949417594
949399703
898636959
898721969
1221068706
1221111086
200739423
200769181
1370006902
1370078587
-2084195345
2084076066
-1798416072
1798326297
-480150928
480177473
-1173681537
1173663739
-352496198
352581815
1713864283
1713860541
-179875043
179869907
791262220
791259722
-326891054
326855560
989346390
989364884
-349099799
348919108
-847477645
847414038
1015306918
1015322314
-1829873193
1829828559
1369973738
1369968675
-1249804107
1249832907
1756053513
1756090879
-1872322420
1872345447
-864717498
864789092
-673491405
673553007
1761189853
1761175132
1222851908
1222843449
-184929749
185049598
-64818482
64848811
1789528139
1789589989
558753828
558754899
-1685873786
1685956501
-1866282317
1866423043
1105447857
1105366979
-94112946
94213097
-669287135
669301100
-284956242
284953326
1438859072
1438856192
938733449
938660931
-875038021
875039924
1695794967
1695723538
84634560
84610959
-213868420
213829865
2093403425
2093370893
1821115981
1821214564
-562639000
562581587
1408204709
1408228812
-1666782038
1666815925
-1547464991
1547533844
-1990878990
1990907492
-2107945313
2107992742
112279892
112199638
1167792684
1167848063
-1305450775
1305455729
1988317857
1988257935
-397746816
397789937
962917320
962902601
1193275462
1193185306
835358159
835360002
1738767325
1738761262
157885096
157813027
-1279867759
1279903191
696112410
696052544
2016525276
2016445830
614326837
614310951
-1770576742
1770623947
546175217
546162696
1621970
1625972
302110245
302047353
1109351687
1109371722
605198870
605283440
-208684101
208756180
-399339446
399451063
598274506
598240935
-1443272854
1443315052
-1625363833
1625500178
221609362
221639083
-840473973
840543309
-1417772919
1417731378
-2047459049
2047456797
1020593280
1020620201
296085885
296022973
-1020906993
1020817068
300203251
300285045
-1185615725
1185556183
269900701
269886578
-1294960792
1294895392
453273586
453263643
951678753
951663330
-1551046295
1550972218
-945661169
945637362
2016760396
2016690379
-620514223
620501625
2708175
2746211
19510430
19493515
919887120
919871666
28250707
28251502
125577064
125631358
-7575226
7582630
-968545350
968507540
2141547024
2141583817
582129658
582095160
1905870959
1905914867
-166531480
166510150
1589637074
1589564675
1429630193
1429652825
1967684387
1967692945
1167697785
1167710499
-113933131
114000270
1077136111
1077132005
1762482373
1762523261
-721791484
721916302
1682390484
1682426565
1066244312
1066239269
-1397329944
1397457230
-296675583
296536504
-528307055
528323154
512857452
512861080
1608267419
1608324784
1131896321
1131921080
381873876
381876997
-188880433
188971604
-299858317
299754942
-1755455078
1755532065
-1868968014
1869010870
1082881779
1082863635
659808133
659747272
1067456627
1067496325
-297173216
297259359
-1162833811
1162802529
1884168485
1884212217
-1608213267
1608133288
-1744629998
1744731770
1887555255
1887497442
-946852189
946751346
-1756905916
1756977062
507963694
508003804
1412605357
1412681722
-1450539049
1450557113
304367944
304410086
759673191
759605271
-52099333
52103767
731052706
731046025
1788273113
1788237188
570373315
570414043
1065347557
1065337126
-743247444
743204864
1865041441
1865099822
-1588778042
1588790338
1623694525
1623648250
-93343344
93507273
100482452
100417809
1220985848
1220990947
236635489
236588915
-2016643280
2016649722
-576598028
576635430
-850012215
850071218
-2078223857
2078165233
-1201685007
1201814689
-31624505
31653251
532760272
532791980
-1843449436
1843400281
-814786008
814786495
-1271500245
1271628364
420177066
420155804
-363150178
363100687
2035625266
2035619241
1615679363
1615685632
872774901
872686095
-1326356582
1326322646
871491950
871433693
-1363885547
1363836510
100049807
100125117
-1969384044
1969423084
-1311547212
1311519208
-1303436695
1303542135
1585755919
1585768800
-2001604923
2001675292
-1301754248
1301797181
1204564865
1204567041
1331048569
1331116825
-952851450
952794422
-1156656246
1156665498
1792446055
1792516846
841116733
841107067
-217090869
217056567
1314029476
1314032842
1214706229
1214744468
1660853092
1660843089
2110849294
2110868912
-1584375655
1584314210
774316469
774359574
-730709957
730669154
1454544928
1454537164
431132018
431110042
738989038
739076209
-862292512
862298637
584536449
584572547
-379200935
379261022
-1492263627
1492309894
-765085360
765143035
-574098633
574205869
1969739096
1969688075
-1959344524
1959390401
188572695
188584994
-1523596888
1523643122
-1290553953
1290626723
1323111202
1323139949
-1216136266
1216104628
-856343870
856217737
-1897360961
1897323073
-449034273
448909523
1175939207
1175948060
-611337461
611337671
2018882583
2018891725
-912612596
912638923
-304903441
304880023
-1045857264
1045850426
938576643
938594344
-1348934871
1348927864
1675182710
1675208215
managed
native
iokpaSfbph
Select * from Win32_ComputerSystem
Manufacturer
microsoft corporation
bbbbbbbbbbbbbk
mmmmmmmmmmmmmmmmmmmm
bbbbbbbbbbb
87654321
510706420
510670379
375194801
375132197
1538200209
1538149493
1155432505
1155517000
ycOkb0+UlwxEsr4raXRZXisXtkTYcXD9
ycOkb0+UlwzJDiBB9jaCeDXrgHA615/r
DynamicDllInvokeType
m0csdozbCwQ=
1817177194
1817168468
-1608417231
1608483664
-129526171
129691076
1469382773
1469396340
-1105081846
1105143130
853812100
853877603
1289253400
1289265923
-1505217014
1505128281
-1538775636
1538644159
1964206596
1964231663
-637498639
637457170
219051289
219023035
-1200884151
1200959671
151762575
151737744
-154723154
154790771
1217813216
1217794803
-198235088
198254217
-946340211
946479360
-368440307
368431163
-177671665
177693749
367101365
367098296
-602039747
602084463
1058504570
1058474562
-1291881840
1291903907
-114181579
114036859
-1022880669
1022788873
-1415241974
1415297876
1627796640
1627808223
slYijl6JXLKYgbtBbck+iw==
vsz129C2vPtugJZ0qytjQsFQtlKhA7lx
A2Dzutoz1CmP5h08ccP/LKPiZ5HNxu/x
zmzMZJ5zHc5mtlnp8CUVfASIH0BaiHZB
vV/TZz2e4d7VXbrrYadJmg==
IinN/rfNapp9cuFs5ChrQaTEYlrlTsID
m9y1NiUTr4r9hSdNzRXHHnUiHSiO7wKT
RRMApgKtwLfFDmR6SePmk4XtchXxt3TT
+zNd+NAmX8PjIrlcpXyykQ==
jOlPgJsavoIj7dl/cImgiw==
5Tj/0vyxll4es1cVO3QfQU4l60yqOCTm
MAINICON
Select destination folder
Extracting %s
Skipping %s
Unexpected end of archiveThe file "%s" header is corrupt
%The archive comment header is corrupt
The archive comment is corrupt
VS_VERSION_INFO
StringFileInfo
040904b0
CompanyName
FileVersion
1, 5, 3, 4
FileDescription
LegalCopyright
dmkdiSa
ProductName
ProductVersion
1, 5, 3, 4
VarFileInfo
Translation
Antivirus Signature
Bkav Clean
Lionic Clean
Elastic malicious (high confidence)
MicroWorld-eScan Clean
FireEye Generic.mg.9d1ce1bf77fa0c73
CAT-QuickHeal Clean
McAfee Clean
Cylance Unsafe
VIPRE Clean
Sangfor Suspicious.Win32.Save.a
K7AntiVirus Clean
BitDefender Clean
K7GW Clean
Cybereason malicious.ffc80d
BitDefenderTheta Gen:NN.ZemsilF.34236.Em0@aeTgUici
Cyren Clean
Symantec Clean
ESET-NOD32 a variant of MSIL/Injector.VRN
Baidu Clean
APEX Malicious
Paloalto Clean
ClamAV Clean
Kaspersky UDS:DangerousObject.Multi.Generic
Alibaba Clean
NANO-Antivirus Clean
ViRobot Clean
Rising Clean
Ad-Aware Clean
Sophos ML/PE-A
Comodo Clean
F-Secure Clean
DrWeb Clean
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition Clean
CMC Clean
Emsisoft Clean
SentinelOne Static AI - Malicious PE
GData Clean
Jiangmin Clean
MaxSecure Trojan.Malware.300983.susgen
Avira Clean
MAX Clean
Antiy-AVL Clean
Gridinsoft Clean
Arcabit Clean
SUPERAntiSpyware Clean
ZoneAlarm Clean
Microsoft Trojan:Win32/Sabsik.FL.B!ml
Cynet Clean
AhnLab-V3 Clean
Acronis Clean
ALYac Clean
TACHYON Clean
VBA32 Clean
Malwarebytes Clean
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Tencent Clean
Yandex Clean
Ikarus Trojan.MSIL.Injector
eGambit Unsafe.AI_Score_99%
Fortinet Clean
Webroot Clean
Avast Clean
CrowdStrike win/malicious_confidence_80% (D)
No IRMA results available.