Static | ZeroBOX

PE Compile Time

2021-11-12 07:06:39

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x00066a04 0x00066c00 6.58727516768
.rsrc 0x0006a000 0x00047f86 0x00048000 5.0007006116
.reloc 0x000b2000 0x0000000c 0x00000200 0.0815394123432

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x000b1580 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x000b1580 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x000b1580 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x000b1580 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x000b1580 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x000b1580 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x000b1580 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_GROUP_ICON 0x000b19e8 0x00000068 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_VERSION 0x000b1a50 0x0000034c LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_MANIFEST 0x000b1d9c 0x000001ea LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with CRLF line terminators

Imports

Library mscoree.dll:
0x402000 _CorExeMain

!This program cannot be run in DOS mode.
`.rsrc
@.reloc
39>f@#
HPai(&
"T.iV@#
[YZ_bX
[YZ_bX
[XZ_bX
[YZ_bX
[YZ_bX
[XZ_bX
[XZ_bX
[YZ_bX
#R"O#kA
[YZ_bX
[YZ_bX
[XZ_bX
[YZ_bX
[XZ_bX
[XZ_bX
[XZ_bX
[YZ_bX
[XZ_bX
[YZ_bX
[XZ_bX
[YZ_bX
[YZ_bX
[XZ_bX
[YZ_bX
[YZ_bX
[YZ_bX
[XZ_bX
[XZ_bX
[XZ_bX
#m Y,VG
[XZ_bX
[YZ_bX
#5%E\}
[YZ_bX
[YZ_bX
[YZ_bX
[YZ_bX
[XZ_bX
[XZ_bX
[YZ_bX
[XZ_bX
[XZ_bX
[YZ_bX
[YZ_bX
[XZ_bX
[XZ_bX
[YZ_bX
#G</UZ
[XZ_bX
#mkyYm~
[YZ_bX
[XZ_bX
[XZ_bX
#(eZ<N
[XZ_bX
[XZ_bX
[XZ_bX
[XZ_bX
#i0d<7H
[YZ_bX
[XZ_bX
[XZ_bX
[XZ_bX
[YZ_bX
[XZ_bX
[YZ_bX
[YZ_bX
[XZ_bX
[XZ_bX
[YZ_bX
[XZ_bX
#!g&_5
[YXnZ>
[YZ`(j
[YZX(|
[YZX(|
[YZX(|
[YZX(|
[XZX(|
[XZX(|
[XZX(|
`dTA(
eefaXeYYf}
0aiZfX
#AaiXXYe
M[aiZXaf
OaiXfY
#\}\;K\
piaiZZY
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
PADPADP
*@+Y+I/M,F-
\4_-_=[9X2Y1Z(Z
-\s7>AY
g&O%X*9
t1T6\7
VC2Q8Zj
@6s'H;
/bOM#6
wL.O%N$
qcHy+A
0Zp"H
hx6uK=`
J8Y3X0
(b,'L$
%_LL*Y,
X><U3Q
Yk~%]0S
S W&Ez
V)\?D,SJZ
0G6U1\F7
J=P3!^Z_m
OB1T*WE6
nU,_>L*G%
aB5H+>W1Qs
Y/^=K0XI[
)_.MjR}
c&lYk~
Z+Z9U1J
pO@3RT
[\1D'G
.]2A$Y
L#S"A6
#@4G&ygR
$;R!D,
iZ1D'%
&%_.M%
k!T7V5F/}
V+Z9w]d~N
NQ*Y<f
z=U(KOz
9L?^db
?N=`6(+
_5]7E,^
n"A K =X
t/I,M(
]Q;S9K.N
,6T4^5
j L>L.
|<V=V>
v;P#Q3"u
ZU@+C(
@O.H*K
t+J+A*
OK"I!J
P?^8Z;
DL?M/I
v)L-G,
~.G,^,
YY9S8P
GG-E.\
w:R:Q#
oC0S`C
x;Z;Q:
RL'L$O
ZI#K R
RQ3R9R
l;Z<^?
T?^8[:EO
{-E.]/
LG'M&N
o&G-G0
y9X3X0(`
wBrJMEv
FwE'O$
lX*(N,
`'v+(
[0XK~|
Y7]6^M
O-/I+J
a)R8S
glV:Q;
@Cu&T&
p2M,F-
.$F'M&
g7D6D&
dm#E0\L
WI2Q1s
[/E.^JH:X
R<vp"J#
aK)K*@
~4_O.D
a~ E%P
?4\7Ep
B(C+XT
2 C*BB\
:T=W%oW
L3A#B`
I<O.HB"
c{=O-L
vF4I/M,
iD0O=O-<
D:_>`"
4X-P7m1
h~F.E7
,D/\.L*
[9X2q!l
#O!{;[S
MF$2P1
s*p;T@
.N0[H:
0]?J K
qw B)BB\
AG)I/M
O#H:HB
`)B!H+
TN"ftz
K6R=^{
Ums/!7
/@(Z8[y
*/8S;P
<>R8S;
,^D>0Q0
*B$F'M_
u_=W<T
+?T&T6
%F.E7E
`t&P9S
0<N<OsQ
,bW;P8
QS1+?M
Y:8W=V
Au/K-Ou
:`:R/N
#Z:[4`
8k-0Q7
j=S"A B"H\
|B(C+X8*G!
=V>U'm
>m'Z)\
-Y*V$F
./;P8k+
=5T&T6
'miU7V
@:H K9
P}7>\:
?e_$E$
H*`UL-G
l"B%H)[e
c)?E&G
D V?X4
r,+A*X
i#pY8R
E#E'O%
![\+I#
6Y+YC%
3pH)K-
(wSlRTj@Vk5
/edS2X
6hT(A*
P1C1k~
6t(3W%
$dj7F%
9i/_.M
2LB&Jb
cP:R!Dp
%S(@+Y
V^eMnY
Id[+Z9
6\|T:OT#
AfS;Q:
BcU9Y4
hfgA%E0
K|Z:]@
$#g@\8O
ED]$a
6U4W/=M
>]<_/5M
S2U848,
ku[9st
0Oi(C
F'L%O>
`BC%D\
3K#I<O
[,S;Q:
1S&^fD
N+M/Nl
{-7S2X
(Z*/C1
/\R4E7
B<_.E7
Z<X+YS
R8!3T6
,v*I*K
j~,J#I
n!D#Y/D.F
W@JK0W6
]1D'A;
SPFO.I
:v]/]?
JdH'F,G
t"Q$^E-L&
iH!S!C
;a~J-P
L>J*A3
BHo5S1
r{5@"D
m#}C)B
otR7^6
FEeK:I
oO#Q#A
o!/\6]|
Z6;I;Yx
WM&R3Yy
NX.M,f(b
c{t"D#B
}'t)O-
4jz.D/
_Uj2S9
TW_H:H
Y=_9Xy
J8NX3A
P7W>"x
-wm>\=
N<Z8Y3
j0}6P2
8b/1W5
!_4X3A
T&X;^T
$Z2X3Y
r2@M@#
T>[P6T
L:]=XKI<N<
0ZZU7V
9j8mm
(D/]/M
m}/F,G
stx>Q3R
f0R4#y
<tw4q
k!]F'M
]<V<T?M
ImWUU2Rp
4E'A#Z
#Z`0X3z
x+m"A(
R:Q#i!n
-JP}F B
)+@'L>
N;Y?u}
\B#C*Y
.=5^,^-
`.E$N=uG6E
Q+L'M=%~
_#A'E$N%
s)g#I"
MCAK!J
'c^,^T
CE/K-O
#c[(Z8
45_4[0B0
Q/C"H"
,X)K-O
xR/I+J
j$.Q<X
h"N*B+
4.E/D,
u!J8J(
[-P7V8
nx{ U(K
}/uO$V
H;'X;^
j$BX2Y
}'qK)H
s0PY;]
kB I"J!k
hvw)P7V
6u1]0C
YP(F/E
N"D&G
>]=X3s
+a2~u
e&z@"D
r"]G5W
pxF J!
DNxS2T
^4Y9TW;
4J8V0RK
wM>\:X
p*iS3Z
'P;k[l
:p`L'O
x+#U8_
rH)O-L
)gmV=W
`qC$O%
;qjP1[
l6dK)H
H#I"IS
C9r^?U
ktG1[*
[5_.\V
-O$L'U?_
z0R@,E
=_3[0BE
?W8Z1'
TTvZ(J
s#K:ICzq
#Zp'P<
b"J=P3
N)B*X*H.d~n
"a3D'B
gE&M'B)Q#
7A6_5_xv
?Q)H"a
w5I%O>
IGc]7\
w)4Z1Y
|"!K H\
XwI[~w
gnRIe&
Q/T6]N
[K/,^<
aT6F$E/
3_+Y+ID`~
R4I+Jt
[9N$O&M?M
bs O%N
F0W7^M
kR7\4_
*M+Y;]@O
D^(@!S
a&=zhkB
v(&#I"
;h\:I<
I/N$O'
VLFRt
f\=[9X
-c"H#K
n}&F-_
,Z1[Kq
b|t,_.
Z<":\>
WI0W6o1
)Z(J,f
dw@7F%
P:Q9Orw
R5]&T&\
p,;G5W
*Z*X*EZ
1r:X+Z
m0\8Q:
V4R0Q,
3XK+N-
"tFXm;
EOG$G'
u6v S"
\6C!A,H
w>qCi4w
@_PTDw
ALjGiH
K>x^ccgcQ
+pPI ;
O!=~bah,u
mvT.F-
TJ<#I"
H.dIX:Q
e'AV>M
s]5]6\!q
f&\]0S
s{U2P1sCZ2A
c,G5G=
+F$EGu
_O#%X;
9J[*X*H.
%w>Z;Y8R
-KA;%N&
m?W=V?
-w>1W5
!?uhD&M
*>U=P"P2l
g$Vln
+XhI,K
z@-G0s
:p).P;
ZOC!@*
=v>\=W
N+$>;8
~4>2Y1
%G$B ACA
b`V)O-
Y{-D"@
~$"8Z;
1rL4V0
XR'G'N
x6\@+A
.t0Y<^
3p._>Y
]G]>]=
&l":X9
u6N0R4
i#^H+B
{(r.]0
;T&T6P
4J(N,M
W)K-O.
ku+B+A
l[+O*g
UL(A*X*HF
$g+T'V
GB1T2P1[H
\:X>[:
m5Z1C
#YV2S9
1&L-G,
H8N=P3
;rH>W=
x"]J-P
~ K8>Z)\
bH(B)A
K=<N%M
\@4G6M$
W;X+ZQ/
=A2A47
5A2A407
&.M@3H
LB A J
u!K$OU|.I,
6@,I<O
A'H#I!
CIt,K*z!
NLA$C9[G-F
U?M+I(
^y0Z1Y2
M[$=,=X
|,I"J-*_lhXr
<?-"+m
uK~V(H
S- ?!F
B,cJFd
`~$V>M
OY)ZR$
Gu*C)0
*u^5)p
&Cz[$
kH!4:|E
$uZ;ky
/"/B2o
jea6L
&]]j%o
1jz!K$
6"x:+4
WM"<8K
#2$F"Y
,_7\.\
kF8Z;Q:
oN!6:*
#`F!&9
G8[>9;
X>mS?H
vZ@2P6T
dL<W%W5
mI;P8S!
![=_>T
4]s#C#
ubGT/0
GyK'qf
,Dc*{a
bKKc\p
E,)Es'
[2~ >7h
=WhdVm
/bS[n#c
H&~_Vn
A|5bcp
08&yXY
gZ'Uo}`*
/_RJXw
HWAczk
=NoZxDH
xv&}Di
Z'-<kD
_Hs/hFU46
#dkClb
AUU5ZB
c7Tic[
`"?m`L
MkGQO<S
=Jhc~@
)vXKyC
jb%)`;
V<ER8>
[QX]:~
In`h>,
:VhGm$I
h;n.A#F
OUAaIo
j.OJ3v,
uHuIay
AOc'/I
<br^}$-m]
SXh|Pe&
C2$'9`
$|au{AQ~
|}~p'
Hzr*o`
VY/@{;c
8+Cp]2
\WT[YP
g*b=aK
YXX,`$~
j<:^'"c
Rs6T]'
]A;/t/
#alsJN)j
Z"d8e?
!jIdT1
/TpXL`
C%Ri9`
S1-:-/
-},1G&
<Wh2W=
CjiE~O
g<Q]"}.
`==m(J
%`r'\6*
F~\,e/
~AL:oa[
!+Q&/1
a)KE,O
Si/%Nr
-m}qOv
;N>:NN
6/TZ]8
k%Y,4k
GqKB9"
D/1k<(/l
#UU<e3]
5/"QKg
\QS[F-
T`DfC_
GL.lnb
S/!e1
9 9IBY
[s3i4Y9
l"H;*Smr
"pr7uO
4P\U:P
WJvdG?
Jz[[XK
v4.0.30319
#Strings
#daaaaa#
#aaaaaaaaad#
#dasd.dll#
#fasdfsd.dll#
#hdsadadafasadfffwtwfffffffgsssssdf.dll#
#hdsaaadadsadfffwtwfffffffgsssssdf.dll#
#hdsadadsadfffwtwfffffffgsssssdf.dll#
#hdsadadadassadfffwtwfffffffgsssssdf.dll#
#fsdadsadsdaswdf.dll#
#hsstadaaadwsssssg.dll#
#fdsdasdsadfs.dll#
#ssstdasdaaaaaawsssss.dll#
#adsadddddddadadaaws.dll#
HotHeapStreamCLR20
$$method0x6000017-1
$$method0x6002c5a-1
<.cctor>b__1
IEnumerable`1
PosTable1
$$method0x6000017-2
Size32
ToUInt32
ReadInt32
ToInt32
Ldelem_I2
<>s__2
Func`2
InitializeDeclaringType2
<>7__wrap2
Get_IsAMD64
ParseUInt64
Stind_R4
<ContinueWhenAllImpl>b__15
<gacInfo>5__5
WriteMethodBodies5
ToInt16
get_UTF8
Popi_popr8
<Module>
MscoreeDllRVA
S_dummyDefaultEC
CSIDL_RESOURCES_LOCALIZED
S_GPROC32_ID
ERROR_PRIVILEGE_NOT_HELD
ListImplMapMD
SNATIVELANGUAGE
STANDARD_RIGHTS_WRITE
SMALL_HEADER_SIZE
NO_SIZE_IN_SIG
LOCALE_SGROUPING
S_DEFRANGE_HLSL
CAL_JAPAN
System.IO
DEFAULT_SPIN_MP
CSIDL_COMMON_ADMINTOOLS
SkFplbklpgS
STRINGS_ALIGNMENT
S_LTHREAD32_ST
S_MANYREG2_ST
HEBREW
VT_SAFEARRAY
SystemWebDynamicData
AddData
DefineInitializedData
SizeOfInitdData
FindWin32ResourceData
mscorlib
_LoadCertFromBlob
StrongNamePublicKeyBlob
GetInstantiationPublic
System.Collections.Generic
get_IsStatic
MessageId
Set_TypeDefId
GetProcessById
lpNumberOfBytesRead
hThread
get_CurrentThread
thread
fsassdadfassssssssssssssssssad
get_IsAttached
NtaSizeParamIndexSpecified
Get_IsConsoleEnabled
Get_IsEnabled
Get_Cancelled
M_toBeCleaned
Is32BitPreferred
Get_IsEntryPointValid
Get_Kind
TypeKind
set_IsBackground
DynamicMethod
DefinePInvokeMethod
ResolveMethod
GetMethod
NetGuard
AddWord
dafasfssd
get_IsInterface
Replace
IsWhiteSpace
SetSource
_source
LoadResource
FindResource
SizeofResource
GetHashCode
SetCode
FileMode
CryptoStreamMode
Xenocode.Client.Attributes.AssemblyAttributes.ProcessedByXenocode
ExecutableImage
GetLanguage
C_ticksPerDayRange
EndInvoke
BeginInvoke
GenericParamTable
Set_PropertyMapTable
ICloneable
GetEnvironmentVariable
Enumerable
IDisposable
set_Visible
get_Handle
RuntimeFieldHandle
get_MethodHandle
RuntimeMethodHandle
GetModuleHandle
get_TypeHandle
RuntimeTypeHandle
CloseHandle
GetFieldFromHandle
GetTypeFromHandle
Get_SafeWaitHandle
ReadFile
Console
DebugAssertTitle
get_Module
DefineDynamicModule
IsManifestModule
set_FormBorderStyle
get_Name
C_UsedFileName
M_strFullFileName
InternalGetTempFileName
StrFileName
EnglishLangName
lpApplicationName
InstanceConstructorName
AssemblyName
RgFilename
GetFrame
SupportsDaylightSavingTime
ReadLine
lpCommandLine
AppendLine
WriteLine
Escape
get_FieldType
PeType
DefineType
CreateType
s_DecimalConstantAttributeType
ValueType
get_DriveType
get_DeclaringType
flAllocationType
get_ReturnType
ReadFieldOrPropType
MemberType
get_ParameterType
AssemblyContentType
M_isUncShare
System.Core
ReadCore
Set_StrongNameSignature
CreateStrongNameSignature
ResolveSignature
SetLocalSignature
Set_FixSignature
Set_CurrentUICulture
MethodBase
Get_OrdinalIgnoreCase
Dispose
FitsInSmallExceptionClause
StandardDate
Truncate
CreateDelegate
MulticastDelegate
EditorBrowsableState
set_WindowState
FormWindowState
STAThreadAttribute
CompilerGeneratedAttribute
UnverifiableCodeAttribute
UnsafeValueTypeAttribute
BabelAttribute
SuppressIldasmAttribute
ExtensionAttribute
AssemblyInfoAttribute
YanoAttribute
DotNetPatcherPackerAttribute
BabelObfuscatorAttribute
CryptoObfuscator.ProtectedWithCryptoObfuscatorAttribute
DotNetPatcherObfuscatorAttribute
DotfuscatorAttribute
CompilationRelaxationsAttribute
SmartAssembly.Attributes.PoweredByAttribute
RuntimeCompatibilityAttribute
WriteByte
c_EncodedCharsPerByte
SetValue
get_IsAlive
InternalMove
bajkhkrrbf.exe
get_Size
IsFixedSize
get_TotalSize
SetSize
dwSize
Get_RowSize
Resize
SizeOf
IndexOf
bajkhkrrbf
fshdfhffafasrdadsatrfffffffffddf
fsdsdddddgaaaaadwreeegfsdf
get_IsByRef
M_pinSelf
Sub_Ovf
GetMethodSig
IsLocalSig
Set_PropertySig
System.Threading
Get_HasPadding
Encoding
IsLogging
m_hashing
Get_DontWriteAnything
Ceiling
FromBase64String
M_String
ReadString
EscapeString
GetEffectiveDateString
TrueString
OutputDebugString
ToString
GetString
ComputeStringHash
AutoFlush
get_ExecutablePath
ObfuscatedByGoliath
get_Length
StartsWith
FileUri
ConvertToAnsi
AsyncCallback
get_DecoderFallback
callback
ObjectStack
GetConstant_NoLock
FlushFinalBlock
Branchmark
LayoutMask
VisibilityMask
IriCanonical
Marshal
JoinInternal
EntityDecl
kernel32.dll
VariantBool
Control
LastGroupToStringImpl
BlobStream
FileStream
__ConsoleStream
CryptoStream
MemoryStream
get_Item
RemoveItem
TryPopCustomWorkItem
System
SymmetricAlgorithm
RijndaelManagedTransform
ICryptoTransform
GetCheckSum
Set_IsRemoveOn
IsThrowOn
get_MetadataToken
CodedToken
hToken
GetUserEntryPointToken
lpNumberOfBytesWritten
AppDomain
get_CurrentDomain
SeekOrigin
Application
get_Location
MethodDeclaration
NineRays.Obfuscator.Evaluation
_LoaderOptimization
System.Reflection
ManagementObjectCollection
get_GenericParameterPosition
CallingConvention
OperationCanceledException
RuntimeWrappedException
ThrowKeyNotFoundException
Get_NumberNegativePattern
PartialWriteTo
GetDynamicILInfo
FieldInfo
GenericMethodInfo
DriveInfo
ParsingInfo
LocalSymInfo
startupInfo
MemberInfo
ParameterInfo
DefinePinvokeMap
TimeoutChecksToSkip
FilterApplyPrefixLookup
System.Linq
set_ShowInTaskbar
TmDefaultChar
SetLineNumber
StreamReader
columnReader
TextReader
BinaryReader
GetLoader
DESCryptoServiceProvider
ICustomAttributeProvider
MethodBuilder
m_methodBuilder
ModuleBuilder
TypeBuilder
AssemblyBuilder
lpBuffer
ResourceManager
Debugger
ManagementObjectSearcher
Modifier
DoWorkEventHandler
ByteEqualityComparer
ResourceDirectoryUser
DeclSecurityUser
IMetaDataDispenser
M_failureParameter
BinaryWriter
DefaultFilter
get_IsPointer
BitConverter
ToLower
DemandDir
M_strDir
GetTokenFor
ResolveResourceLocator
SymbolReaderCreator
set_CurrencyDecimalSeparator
ManagementObjectEnumerator
GetEnumerator
.cctor
dotNetProtector
get_IsConstructor
CreateDecryptor
IntPtr
UnsafeGetArrayPtr
Get_DllCharacteristics
System.Diagnostics
Get_PreserveTypeSpecRids
SortFields
FromMilliseconds
GetMethods
MonthSpaces
System.Runtime.InteropServices
System.Runtime.CompilerServices
System.Resources
bajkhkrrbf.resources
CombineHashCodes
OpCodes
bInheritHandles
M_strAllFiles
EnableVisualStyles
Equals_EventNames
EmptyTypes
ProjectedClasses
SkipAddresses
WriteFatExceptionClauses
lpThreadAttributes
MethodAttributes
SetFileAttributes
TypeAttributes
MethodImplAttributes
GetCustomAttributes
lpProcessAttributes
GetBytes
GetDrives
BindingFlags
dwCreationFlags
GetMethodImplementationFlags
SetImplementationFlags
RequireParenthesis
SetDefaultFallbacks
LocaleEquals
TypeDefScopeEquals
InitializeHotStreams
System.Windows.Forms
Contains
CallingConventions
PushOptions
sssssfadtraaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaars
get_Chars
PointerToLinenumbers
GetOptionalCustomModifiers
RuntimeHelpers
GetParameters
sssssfffffffadtrrs
sssssffafasfadtrrs
sssssfadtrrs
NotECMAWordClass
get_IsClass
AssemblyBuilderAccess
hProcess
GetCurrentProcess
lpBaseAddress
lpAddress
_typeWithContracts
NumberDecimalDigits
InitializeEvents
HijriMonthDays
Concat
ManagementBaseObject
_stateObject
GetObject
object
Select
flProtect
M_permSet
CharSet
GetCasOnlySet
CheckVMForIOPacket
ToInstructionOffset
SEP_DateOrOffset
op_Explicit
CheckLetterOrDigit
System.Reflection.Emit
Commit
ZeroInit
SetCompatibleTextRenderingDefault
IAsyncResult
_result
System.Management
lpEnvironment
get_Current
CheckRemoteDebuggerPresent
IsDebuggerPresent
S_pcasCount
CModOpt
ParameterizedThreadStart
Assert
Convert
FailFast
AllowIPv4Host
SuspendLayout
ResumeLayout
DeleteClassLayout
MoveNext
System.Text
CryptReleaseContext
context
get_IsTaiwanSku
Overflow
ResolveMethodDefThrow
ydadsadasdasw
InitializeArray
ToArray
get_IsArray
get_IsReady
StrongNameKey
IsSystemKey
System.Security.Cryptography
DefineDynamicAssembly
GetExecutingAssembly
Get_IsNestedFamily
MatchExactly
Company
ConstrainedCopy
BlockCopy
Get_CurrentDirectory
lpCurrentDirectory
op_Equality
System.Security
SuppressUnmanagedCodeSecurity
ResolveDeclSecurity
IsNullOrEmpty
198 Protector V2
System.Security.Permissions.SecurityPermissionAttribute, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089
SkipVerification
WrapNonExceptionThrows
_CorExeMain
mscoree.dll
nnnnnnnn
@nnnnnnnnnnnnnnnnn
@@@@@@@@@@@@@@nnnnnnnnnnnn
@@@@@@@@@@@@@@@nnnnnnnnnn
@@@@@@@@@@@nnnnnnnnn
@@@@@@@@@nnnnn
@@@@@@@@
3ZZZZZ<`}a
CZZZZZZZZ
((((((NA
"{((((ZZZZZZZZZZZ
?(((((((((((ZZZZZZZZZZ
((((((((((ZZZZZZL=Z
>>>>>>>>>>>>>%
.........>>>>>K
Itt..............
DN.>>.UR
[h....
9JHHHHHHHH>
......>>>>>>>>
.......>>>>
......
66666666666666666e
q666666666
6666666
6666666
@nPPPPPPPPPPPPPPPPP
@////////////////P
,PPPPP
@/////////////////^
/w//PPPPPPP
i///////PPPPPP
//////PPPPP
/////PPPPP
ooooooooooooooo
/////PPP
ooYYYYYYYYYYYYYYYYz''oooo
YYYYYYY77777777777YYYYYYYooo
((ZYYYY7777777777777777777YYYYYooo
((ZYY777777
77777YYYYYoo
yyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyy
::::::::::PPPPP
ooooyyy5K##########::::::::PPPPP
jjjjjjjj#######:::::::PPyyy
jjjjj######::yyyd
UUUUUU
jjjj##yyyGd
========UUUU
=======\
hhhhh
D==yyyY
NNNNNNNNW
TE2 yyy@Y++++++++7
hhyyy(@f
g222WWW/
++++++Nyyy
(VVVVVV
o>>>>>>>>>>XBV?6V
&&&&&&&&&&&??
>>>>VVVV
yyy:Pmmmmmmmmmmm
&&&&>>>>>VVV
mmm&&&&&>>>>yyy#:Q;;;;;QQQQQ%n"
mmm&&&&yyyj#;;$$$$$;;;;
mmmyyy
j$$$kkkkk$$$'ss$$;;;;;QQQ
2kkkk$$$$$;;;QQQyyyU
ZZAAAAZZ2
kk$$$$;;;yyy=UAA111111111a4]AAZ
kk$$$$yyy =111!!!!!!!!!!!1111AA
kk$yyy 11!!!iiiiiiiii!!!111AA
pp,,OO
yyyyy.[
pp,,OO
yyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyy
_________________
-----AA
UUU --
333HHI
S-AWWWWWWN"""222G -@@@@@
U
^,,,@@
TT,,
H1((((J5(1
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<assemblyIdentity version="1.0.0.0" name="MyApplication.app"/>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v2">
<security>
<requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3">
<requestedExecutionLevel level="asInvoker" uiAccess="false"/>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
bajkhkrrbf
GetEnvironmentVariable
_ENABLE_PROFILING
_PROFILER
-2004512005
2004511239
1402017212
1401972875
-1673416374
1673482277
-992096227
992091585
752073284
752011933
1416978989
1416921066
1952159605
1952106654
737716871
737803343
-1175144065
1175145375
-877016976
877039921
1912198408
1912134684
633504086
633592032
505126274
505103197
217824636
217745523
1725122803
1725146266
417644178
417636167
-1881275920
1881391712
1034261596
1034251104
48649602
48712871
1939176787
1939154532
-576205128
576276612
798700467
798703499
-1246903512
1246762196
1348175145
1348136714
-1982434329
1982456315
964217592
964215797
812974832
812942110
-1330319195
1330221789
-526919009
527028145
-963529782
963537377
-15116612
15127561
1533784612
1533749286
346377523
346408982
-494588235
494601794
-1864164928
1864206318
-1961585447
1961444573
-720457798
720478280
139497341
139585156
-507519220
507655797
1352216808
1352254883
-729666475
729666202
1272741799
1272741577
-1320857951
1320825395
1188233500
1188292929
-1457255239
1457215076
-1395894486
1395865100
263578212
263547326
-1218473180
1218465021
1079412455
1079381360
-1657952767
1657951211
-409606017
409475924
939156454
939161649
1048659327
1048576934
-252351644
252348559
696165309
696244560
967294098
967194781
1712333314
1712349207
-418251655
418301906
1128129317
1128053428
-191686311
191638466
540686669
540689601
1255471659
1255443168
-1955737515
1955795255
1508629972
1508584348
-1926202362
1926128827
243017273
243049610
1964333040
1964330008
-1691707627
1691674385
1219358187
1219322634
-1348728328
1348604138
1786925198
1786922898
357658213
357591836
-1258221854
1258225642
474144827
474122752
-2077123805
2077193163
-1813904370
1813826902
-1603356806
1603504525
-805038502
805019689
-434362638
434356366
-1309487422
1309430598
695619997
695694502
1421810215
1421863422
209964504
209976231
-1486054051
1485990643
-582311245
582334448
1808715641
1808699075
1402060505
1402046520
1479199680
1479157566
-1171146616
1171051914
-950863830
950910835
-432740749
432702438
-1763667336
1763604311
-1451527622
1451564483
667382809
667354032
272844084
272784747
-2002089411
2002038109
-1904269439
1904278810
1910371398
1910276156
-1806721454
1806770699
349586157
349630835
-398378856
398255528
1258932614
1258908821
1047847402
1047905921
-244934113
244888907
-1751346336
1751337283
-885713848
885773994
1968583534
1968573912
-93050016
92943468
-1967914481
1967901310
105458299
105490941
213681720
213759391
-1398626874
1398647912
327920462
327871338
939328004
939279129
1343458733
1343479098
-1222514895
1222412467
-52333344
52306382
1754289941
1754310330
1805021069
1805052348
827974131
827905240
971854972
971863388
-747052977
747091339
129202748
129182198
1269428282
1269374244
-1658240143
1658321085
993003220
993008537
26049974
26066790
246922011
246855129
-1178273064
1178208327
1284673883
1284672144
-2105477992
2105497099
-1608107936
1608211387
435772619
435787108
-806378345
806417097
-1732745353
1732647942
-2031983971
2031927148
-1962853703
1962930388
-2035355376
2035495825
508326946
508326740
1175742508
1175731505
-655769518
655864593
1222469079
1222436822
-19721850
19711266
-385965213
385899334
814574454
814590684
-502945357
502853478
-2016842823
2016713556
133261553
133181119
762884450
762859095
774073730
774062750
1347629120
1347564570
-101223566
101315107
-863371626
863405257
1573975188
1573975161
248620878
248620292
2107860838
2107795296
-292650357
292668230
-1941647267
1941597342
353444242
353383585
-1709536492
1709504146
1391375509
1391355788
363973581
363904843
-1800848075
1800869530
1768414981
1768378156
1587772479
1587754810
173425014
173422920
-124980787
124974468
-1735026051
1735064343
-2081163161
2081296478
-1599179693
1599339411
1771402687
1771403592
1658083422
1658144268
362060108
362053104
-972614349
972732793
906190454
906231323
1177853798
1177855303
1417764631
1417762062
1562360257
1562281665
-387608323
387679033
-1344986940
1344978898
-1496370786
1496346186
405870938
405896876
-1801822349
1801721725
965469495
965404636
-1794340409
1794338432
398862580
398857233
1182820535
1182842029
-1747905264
1747744447
-1645316886
1645455637
1535506144
1535504252
-807869540
807832697
-1167829918
1167779441
2001616743
2001659392
1216966372
1216989596
-1174350456
1174287111
-238980373
238815051
-947598998
947637396
-893750052
893658896
134122699
134212937
-795953804
795971885
-1080535239
1080479601
902487370
902482501
1408129931
1408190365
-1882750807
1882718255
-302923403
303031473
1158007865
1157970843
936182501
936212404
1052315737
1052358991
512896468
512922486
504672619
504632137
1695250517
1695167714
-549073370
548929715
344060098
344022181
-1902680532
1902674646
1870729004
1870727650
1661625190
1661621455
1601966621
1601982104
-1116357479
1116430909
1786408131
1786402040
-1223385675
1223414375
-1523302492
1523313352
448441303
448412493
-1393438164
1393491412
447687854
447679336
-1591996857
1591931926
-1641537326
1641436304
-1487901853
1487927174
-1985323521
1985293027
1120317037
1120321896
-1198493729
1198418481
1701772727
1701808983
-372153917
372182100
-623106058
623021757
285862759
285786909
555247947
555236795
75410406
75378746
2131066799
2131084529
-1289823540
1289772022
405200158
405188366
-1439520099
1439548556
269434632
269431883
-1431963887
1431997977
1926439899
1926473643
456034359
456060816
-176721662
176708343
-1625066653
1625081157
-1172950536
1173091106
440820270
440882711
-836646961
836735934
291027484
290984557
-242404325
242358690
-1660120780
1660046083
-132199117
132231676
-1160804375
1160862447
1199607822
1199672968
-511279377
511234540
-2009084131
2009139865
2133689947
2133630555
-542674165
542703287
1093645396
1093633897
-1198652778
1198565697
1814467407
1814469171
-73803508
73898084
452808599
452799118
486892080
486831423
117938605
117892490
98205915
98206834
-253691092
253670462
-911936741
911990255
-732840047
732907214
-793543880
793639443
-42044633
41955275
1040614651
1040707385
753497855
753486357
-1497782646
1497680231
387537580
387457689
1544128979
1544104831
807262004
807187664
404295295
404301137
825557934
825602570
1218475001
1218539726
-135427885
135447102
-1931467430
1931448888
-1475866104
1475754785
1243836108
1243817713
974803486
974844508
242072479
242086687
-1298418441
1298433976
-1752022262
1752147245
-744279125
744292724
-1229063110
1229178128
-1932220495
1932139981
-594697093
594573689
1783761787
1783815072
-1578838808
1578847044
1432855711
1432873127
51190347
51122316
1714419808
1714390006
-1170145424
1170036956
699334432
699276398
-896836377
896806949
318578595
318521743
-1802140069
1802196596
975092252
975109199
1638545248
1638607733
1336909916
1336878775
-2130920577
2130944198
1970054828
1970142146
-826600442
826591929
1205547589
1205472268
-1980135316
1979977616
1435569986
1435566400
356851587
356902580
-485568895
485521277
404698579
404634181
-1184183695
1184135017
-56408175
56404935
-1660499886
1660461871
-1844014224
1844145611
594363234
594329850
-1393938415
1393854064
1104276200
1104188292
764145595
764094478
1648174934
1648171076
140385991
140393714
-597851958
597867526
-1209481398
1209367623
763978503
763892629
1730492171
1730512214
-761026545
761198755
-1361161704
1361157541
-2120348294
2120348550
-1345010961
1344919289
-1997518196
1997472159
-1858816852
1858856409
-1522093254
1522127575
1484904376
1484835940
-1917443471
1917362787
-304491994
304508606
-2059409935
2059403267
-1393484206
1393493765
1532869166
1532825291
-482169627
482303566
-994596401
994767185
10062221
10033376
-538775444
538711423
-264237563
264146436
-1414773126
1414684518
274874155
274940755
1999289078
1999367665
348396766
348435530
-1684613182
1684616914
-1525381317
1525307206
1775522534
1775587123
-1426457130
1426562716
205466624
205501245
661949632
661918547
-715696507
715662647
-1783297414
1783124042
-1114999330
1114998245
-1098934844
1098968573
317518747
317460373
-42968057
42959673
1429726545
1429668922
-1212375963
1212247150
-1486193375
1486107101
974807211
974789206
-1266496731
1266510120
1604486458
1604486401
741148198
741199763
-636986426
636859127
-1047717321
1047782041
637237104
637216746
1286691553
1286684710
882600103
882515818
1611852755
1611911447
-1800437203
1800518845
-1576349578
1576486752
50843605
50774790
1591467984
1591450661
848502241
848513563
829913971
829832037
-1724377599
1724342874
1248232672
1248234355
-1682634910
1682582843
1589223019
1589242973
-1667085354
1667012024
1535605368
1535572735
1819802050
1819708406
-2057185033
2057243778
-498136111
498092015
1576081748
1576019604
1448914140
1448907508
-814095717
814121708
1136369205
1136385021
1515882803
1515879084
1775903120
1775985619
-46790156
46711726
-211980495
Antivirus Signature
Bkav Clean
Lionic Clean
Elastic malicious (high confidence)
Cynet Malicious (score: 99)
CMC Clean
CAT-QuickHeal Clean
ALYac Trojan.GenericKD.47389429
Malwarebytes Clean
VIPRE Clean
Sangfor Clean
CrowdStrike win/malicious_confidence_90% (W)
BitDefender Trojan.GenericKD.47397747
K7GW Trojan ( 00581a2b1 )
K7AntiVirus Trojan ( 00581a2b1 )
Baidu Clean
Cyren W32/MSIL_Kryptik.GBW.gen!Eldorado
Symantec ML.Attribute.HighConfidence
ESET-NOD32 a variant of MSIL/Injector.VRN
APEX Malicious
Paloalto generic.ml
ClamAV Clean
Kaspersky HEUR:Trojan.Win32.Generic
Alibaba Trojan:Win32/Kryptik.ali2000016
NANO-Antivirus Clean
SUPERAntiSpyware Clean
MicroWorld-eScan Trojan.GenericKD.47397747
Tencent Win32.Trojan.Generic.Lpvh
Ad-Aware Trojan.GenericKD.47397747
Emsisoft Trojan.GenericKD.47397747 (B)
Comodo Clean
F-Secure Trojan.TR/Injector.sbefn
DrWeb Trojan.Siggen15.41013
Zillya Clean
TrendMicro TROJ_GEN.R002C0WKD21
McAfee-GW-Edition RDN/Generic.rp
FireEye Generic.mg.abbd913fabcce80f
Sophos Mal/Generic-S
SentinelOne Static AI - Malicious PE
GData Trojan.GenericKD.47397747
Jiangmin Clean
Webroot Clean
Avira TR/Injector.sbefn
MAX malware (ai score=86)
Antiy-AVL Clean
Kingsoft Clean
Gridinsoft Ransom.Win32.Sabsik.sa
Arcabit Trojan.Generic.D2D31AF5
ViRobot Clean
Microsoft Trojan:Win32/Sabsik.FL.B!ml
AhnLab-V3 Trojan/Win.RATX-gen.C4768986
Acronis Clean
McAfee RDN/Generic.rp
TACHYON Clean
VBA32 Clean
Cylance Unsafe
Panda Trj/GdSda.A
Zoner Clean
TrendMicro-HouseCall TROJ_GEN.R002C0WKD21
Rising Clean
Yandex Trojan.Agent!ziA6V0Rx6Po
Ikarus Trojan.MSIL.Injector
MaxSecure Clean
Fortinet MSIL/Injector.VRI!tr
BitDefenderTheta Gen:NN.ZemsilF.34266.Rm0@aCYo3Re
AVG Win32:PWSX-gen [Trj]
Avast Win32:PWSX-gen [Trj]
No IRMA results available.