Static | ZeroBOX

PE Compile Time

2021-11-16 18:28:42

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x0005efd4 0x0005f000 6.38046766331
.rsrc 0x00062000 0x00047d54 0x00047e00 4.98973917033
.reloc 0x000aa000 0x0000000c 0x00000200 0.0815394123432

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x000a9538 0x00000468 LANG_VENDA SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x000a9538 0x00000468 LANG_VENDA SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x000a9538 0x00000468 LANG_VENDA SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x000a9538 0x00000468 LANG_VENDA SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x000a9538 0x00000468 LANG_VENDA SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x000a9538 0x00000468 LANG_VENDA SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x000a9538 0x00000468 LANG_VENDA SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_GROUP_ICON 0x000a99a0 0x00000068 LANG_VENDA SUBLANG_NEUTRAL data
RT_VERSION 0x000a9a08 0x0000034c LANG_VENDA SUBLANG_NEUTRAL data

Imports

Library mscoree.dll:
0x402000 _CorExeMain

!This program cannot be run in DOS mode.
`.rsrc
@.reloc
5S@uO@#
@4pc@#
~pc%'d@#
#FC/h?
[YZ_bX
[XZ_bX
[XZ_bX
[YZ_bX
[XZ_bX
[YZ_bX
[XZ_bX
[XZ_bX
#XH'2:.
[XZ_bX
[YZ_bX
[YZ_bX
[YZ_bX
[YZ_bX
[XZ_bX
[YZ_bX
[YZ_bX
[YZ_bX
[XZ_bX
[YZ_bX
[YZ_bX
[YZ_bX
[XZ_bX
[YZ_bX
[XZ_bX
[YZ_bX
[XZ_bX
[XZ_bX
[XZ_bX
#$f<pk
Hx,{A#
[YZ_bX
[XZ_bX
[YZ_bX
[XZ_bX
H[jsA#
[XZ_bX
[YZ_bX
[XZ_bX
[YZ_bX
[XZ_bX
[YZ_bX
[XZ_bX
[YZ_bX
[XZ_bX
[XZ_bX
[XZ_bX
[YZ_bX
#w(bf&
[XZ_bX
[XZ_bX
[XZ_bX
[XZ_bX
[XZ_bX
[YZ_bX
[XZ_bX
[YZ_bX
#Fm7z9s
[YZ_bX
#+cGa4
[XZ_bX
[XZ_bX
[YZ_bX
#Px6Z!
[XZ_bX
[XZ_bX
[YZ_bX
[XZ_bX
[XZ_bX
[YZ_bX
[YZ_bX
[YZ_bX
#,rv}+\
fSJIlr@#
# 7ue"
[YXnZ>
#0[p1k
i"Vg B
aieXYa
aieYe}
efaYf}
JaiZY}
$Naieef
6aiafXYY
XeaXeee}
aiYYaXY
dRh0ai
}3 )bTYai
:aiYYfeYfef
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
PADPADP
u{(I9R4F)
;P6D+O(n=|
,E#Q<X?y*K;N(
*J!G5Z>YL-]6P"M)N
_9?P4S
F'W<Z(G#D
Q0@+M?P4S
F'W<Z(G#D
Q0@+M?P4S
F'W<Z(G#$b1H8S5G(L+m>_/<:H'
K*?**X5
x+J62T
7;I&>.h
K9V,%a
)M*h9B
k8/=T/
p6;8F*
B2/'S9
b1&4]8
y]2V1v%D#H
_##C%X7S4l?^
4D/?"L
$<N!A&
rD0_;A
~%F&V1W%J&A
%<z)-I$A(@
C%W4<35f
r2Q7E($
4r!6:I
C+@&P5&A
]2V1i:[
7G,@'H,D
(Y6R+mb
@/D"H'C
X(C!)F
[!G5V'9S
3G f1E.
;6)K,6e
={(?<R#L
C"9W6+4
7n=1A*.P.F
["D6U Ck
D%7P%S%k
<[+@&T;_8
g _@-@
Xy*K;
I">"M)N
:\.7S-b
:J!=C#
R9_-B%B
F R3K&
-]6F4V%
J-k.B,
\,Q7E*1V
$E5T%W/
3u&=:M
-]6F!C'
]<BK-_
>Z=q";3
D"P?<[
u3V$P*H04P1M
t'F6<Z(6R
*L>G#=r
*Z1M?P-B
g9R45V
-k8O,B
r4])S'=
,M3L#=
>@D%2;>
E$T5@.A
j_6D+*M
1P A'N
qC(N2]
[)F!!Q
nP K#Q>S
eC3X4F
]2BK!S3+E
-2@/G~
E.H91?
0,4+M?F
B,CU1w$o
i@/K"<k
UW'L ?H
NO(n3*V=[#
6N-=3b
ec/N>E#Q>
~(G#:p
*I9R4F)
*N)e6F0
`@2]/H
&T;U2t
~G f+J
%C1X<}+S
F-K/-?X
9K$>YL}
<L'@2]9^
KI/](9Z
W^/E$x
Q0@+M?Pt
O$B&3Y=q
W'L&,?[<t
G(L*a2L
>B)O9x
J+m>_/D
rR O!3o+D
#Q>P7`*:D
W^8J%A
V7G".^0A
4J!G5Z!
U1w$9I"D6Y=Z
J,j99H#E
p#B25S!=Y!
J+[/$@
-H:U02^
d@'a(<C 0:
=T2@/K,
6D+E"S
`E*NF
eE.H0_*B
VR=Y4r
O.^+M#
<Z(F"E
A P+M?P
_8_i:[+
q9I":=K"<A}
LM&@(4L
@A.J#Y
E/_4H#
O.^+:D( ;t
h-B&7j
+[0L2U'
?Y+:Q-c
dU:^/i1
'L*N!g
T&I'-d
|/N4I1B
69L+5<
7?i)9!
c0Q K-_0
;]/?[<z)
6B#S8^,C
9@ @+M?P3T
s}#B21W$K%B
l*Q0?T(Z
\/]2.I
e6V&C%/
+M?J.)
[<R~o
J:Q&T;7
0Q!@H:U
S8^,C&A
#H.V95
v4P7k81Z1Wp
p:H'=Z
BS8^&I
~+m>Y)
.J-e6/
m R=S4J
Z<&)L+g4->T2:U
P#G f5T$N(Z5b
g4U$<*W8P7q"
\1A*L4[?G
>YH!J
O)[4=*i:2B)O
D"P?+L
7Q#L!F
v'E*:0
'3t'<BK
M"F!4g
A&`2G/
X3#H-_0,
<W1?P4S
&_,G!+Dx4g
?C0_1V
v%D03?L#=Z
}.O;(8I&8_
<L'='3V1m
N>U/]2,K
}$?<S$R
]1U(n=\*
{'F,b
7.G+M5N"2n,G
!(W<P"M)L
:H'?0^
!@0U&B)I)a-$
R#a!98L
:O,8M03@
F-K36I
<;K#&I'
)O=A%,_
(L$K>Hb|
F-K3P,5u#/Z A H
F)X >;L
9Z)/;8I
U E7N 
F R3D
J;K)@(D
H#6D+O(S
K*Z01-
A FO)[#8
;G R7S#Q
K)Y,J1M
N/U>X*g
M"F!({
Q:\-6P ^
8A%c&G
G!S2L%]
|G$7@%4R4_
s?:=Y-b )
('G#:Q
Pi:[!70'
F+@&P?0:|/N
)H&A4}
2S#H.\3V1w$
I(X)O5D
kxd!B.2?<>G
N)o2H'8G_
9O)5Z>Y
]<;P40F
M*l5>P:O4H'/d
!;Y)8K3K)
V=[(4I&E
I;T&c%v
T 5461
_>D%C+
8 E7X5
+7p#<9N!B&
<z)Bo
A P1A5W"@
F-K82@
J,^'0J
W<Z$K/7j"m
S!// I
pA*L8D
]%Y5>N
,G$J,^1*-k
^"R:M%
D%U:K,
S4F#4N
T@2]/
I9R*GSs5f
L:J!6D
jl?^(0M.8H1v
IB0_1E
8I:U+?r
,M7I&C#3V
],4H&/=j.#=.[)F
L:J!6D
I-k2H1
tE.H4H$2l
rt'F0H%F 0Y
X30V0B-
Y$X(C
F'W2>N
o)p3C($
O>U31^:]
W/i4J3
;H9V,>q
"V&M!L
V7=.[)F
!P;]p
\&U>X#;X
^96Y89O
}.O56c
T5E$,`
q$F7\:j
q"C)/;I
R\(h%1:
/C">,H
E#E7Tk
s'a2I(>
E#Q4=L
s#L(%"U4D/I;T
6J+Y0=
1@&`-9D
6\)[/6:D
B"F!c0Q
;<S2B)O=R#D
F4Q+L
@2]/2v"2=
;Z*7;K!
_.\3S#X
/F(L+f$>
G3u&=<R
g(G#:u
#Q>P!i7E0
U$O#F"
U.Q3D/
$O)U'>YL
R97X7S*e%=
#S8TH'C
>'?y*D
2A%c*8C
NE%X8\;
6R5m+B!B
gL*X1B
iX3U!;Z={(
Q*G'A"I
7F4[;K
o$D7Y=Z>]
? F4Q"7q
*4C(H/9
I(X)C)
^#g3?D
;P6>>U2t'
L*X67 b1
4>M&:=K
%<Y+>4M
K*Z'5?
k2a,74X
]1U2m-E
Z<z#/Z A
P"Mb&r
>M?P0F
V.J-g4U
.^5I]2V
7V&M+Y6?X
/I;J$C
9A0[7:N
>L7K(2
S-4t&49A
K?y*A F
q@+M9C"E
V=3T;_.a!9
V/],1|'n
2X%W;J.0J
j+D =t
A P1A5W
\;}$25
\(L+i:[
\W3B.J-
A'U0J-e
j3b+41S
M?P*7s
2T&?Q6j
w3_+P*A
]#D6S m
,YL#+
e.J9W3T4W
b2]941F'W<Z(G
3E"P9FG
;F8R!I
wF-K3I(O
A1P T8
;]/6?J
/N>U3A.7P
Y5Q6`3R"
.O?J J
3W"T>E-1K
V O$<C%
U4D%7=
6<y*E(<I4
s'a2M*<Z
Q0@!1E'
aJ,^+<R
L>x+D!E#@+
(<X?u&G&F
@K/^2V1
'B(N6F
\%e5A&<O
^,C#3h
w<\/A%B&e
58 .G5P
R3A(5x+r
4/?[<s
\%9n4A3W
M,\-5I#
J,^'0I
n>Q5(-b
N'U4*G
%D4U'M
q<g.96V
xG,J2J)N
F4[5<|,<G
#:H'?G
L*X-6C
@!Q:\.A
9<$2S!D
aJ,^+<R
L>x+D!E#@+
k;T0-*]<L'A3\%B
h.^#+#D6O
?Y+:T3o
O(Z/4y,y
-5r!:=O
N<z)Bo
+F,J2J*F
D6Y3>z&6A
Q3W0r!@m
{0X+E!F"a
R4F(1&\
?:P6>>V*[
d/K:V2U5V
O>U-T4
S3u .Y!B
<O=R2D
1P K-_0A&`3
y)F"4r
R8^&6N"S
dO)[.7G
V,?!84f s
u%c0K(>X
NE%X8\;
Y25W K
[5<|.<A
F'W2>N
>M?P0F
V.J-g4U
.^5I]2V
7V&M+Y6?X
K-_&8_
U R8K//A
=[)<N)i
&A)O7E
)F";l6/
2B)EY6R
C"R9_-B
_"f4B';R
>U3;A G
^#g1?J
/N>K!K
K(<"9U1V
p6_+V,E
[3d.;M%08F
,G$J,M
]V2A/K,
<Z(=O(h
Y5Q6i)A
O6p#8
Y#7\:F'*% r
9H#;I
+Z1M5/K&6e
=X*E 3a
^%//%1P
X(N<84f s
KZ@3]9^:Y
;K <p{
K-U/D
(!@0Z0
A P:I5<
G%B";8Q,
X6R56d
+D =h+W+=
C%W.7:Q
`)p;D
7G,@!B
J!G+1J
*@0[9m
t'F,49K
kp#B2'A3\I.h;C3X>L#G d7V&Fm
Q=Y>.}
>_/:O7
I(X3+Y6Q&`3R" FW2U" s
Y#LS1w$
{(I/:\(
4V30U"K
L,\-8C,H
+J0H'U:M
/A P1/
P1A 0D(;*
U3A*N)^
v(C%-B&A
*/7?X*;
=Cx(I9Q
B#S.56R
u2<G&F
s;C"1F%"
[9$9N5
J!S<=2
])Y2Tb
x(I9B$V9
P6P;T0W
n2S#->-3
F&C$9,
z2H*G
}]&:k0<v
ho+E$H
W65^8H
4C(N2]]
Dx4]6D
I:U'5l
8\;s :
<Z(=Y7
.H:D E
Rz3I;L
*J:Q-_T
z;X9I F$K
Q0@+M,
C$a2I9L$
$V9S!c
>J,^-k
5E.7E($_
M#3o)A D
2X>@/K,`3R
X>L#=Z
?[<z+I#J+F 3K
"N+Mk9Y*
#c0Q!J,^1
J+[/I:U:Q
D"P.J-C
f5T#5O#?W-
[6p##D"-L
'36L&>O
Q0!)B`
ANA+N`
Z,H/J'D$<q
S3E/J0`
(H-K/\
N%C07x>c$
Y)<0B-
F&V=[(G#D
h;2G$G
^#g1==E
D.H07GY
P F'2O
/6:;J')4G
^.8m'p
S#H*G"
=\,C%
K/\ .8h
^)1Miw
W:Q7;R
S O!0x*8,64
p` 76S$M
J*Z'.>2
GQ6p##
r*Q O$<N!hz;h
X:w'B1
{%W2A2_9
e![5RP
N08Z=P
f!T:K!
\W9J"m"N+>z*L*C&U
7G,@23
@ P;].A%B
F'W%8J%5R
V1.9@"@"4k
P;]-@
N+k%/N
F!>?H$D
T?:%=HH
J%A&`3R"
@!21J'7B
%b1F%?
^8~#12
E79 :z
X(C!B'2J6
B3]:>7W%J
Y>L#?A
{$c1?W=\
B,_1z%d8p
o$E8XP:}//a
N"-4Z7
@2]87=n
P-_0H/i:
#5M)3P
X30Z-?
[4:&@U
C%W7?Z
V6F-K8W3T
x&J/I1(@$H
&O%A0S!cz
5G(8L"3O
:H'?Tx!
3X>B-C
$V9Y-e
q1O*/4R 1H
3]:^:I
UQ2V1f19s
<y*A1>L'
y)H2Y?ME
c2T%K.]3E#f65F.I
3W0l?4D
:I":5V
"T;J+3J
R=Y>g!/K
B#Q>+L
>#2T&8T
D3X>B-m
<]-<G
6e6W#H
v$E+-0
D4_(Z5=P
-N=C\-
`)a2B"
E7R#-Z
/J-k8H4L#;A
$J.?f+9?
7/B$0k';l
":e)H8J
,)n=\,@
5D/?:C
%C%W4?B
Y4DW0B-
9Y-1R#G
7F-A =H
X>x%1)1B
_0T/i)4-p
T%J.?yN/_V -
J-k.<.E
9V2K/|
5G(J-k8
F'W(D"B
,G f5C/1P
-A%8k.>D
50u&G7U
;E#Q:M
#P?Q#H
D4_9.A%B=n
z#1;$=r
B#Q86&J
T2t!-E
i)+.d$G
m+xot
.G5Z/H
]<L'A3\8_
-N+[X=O
9<y*K;I
Y$O)0L
S3u&=MJ
"1//7?f
I0` A1?
Q@"2i)=!B
H/1I*7
Y={"0-0C
je6W'>X*E!F
]'->b$&</,]2L
K8W)&1a
_8~-;G
U9]0c&6<
t0L 6h*D
(O DY
;M"1)57
r!@0M+Y6R5s ?O$B
e8N&@$S
d"V-2Ya
A,H/i:[+@Z)G$e
L*X7R%c0P J,
0T3k%2
Z4i'1A
R7+u3`
;U!ai
p?M"<H
S8^,2I
i:[!7/L
\U>X <2D
#H.R*'/B
<z)D#3
Y.HQ>Z=
d0/i:Y
X?y*14
IP1J'?
O'-@%9T
3P$C$8p7
F R<D%`,7I
|/N4_3
tR=Y>6
X>L#G f5R"I.
S2B"D6YV1w$:J!G2]9^
U:^9)z
M(9_["
"7;>T3
<G"D#?
s,&8_`*
W#A&n9Y
!/I#=Z
4(5S2<(/[
sm.AV0z
j$?OY8
x4gE"i
}%,._0@-@
4e6V&J,Y5Q6
:!F)E"K
2L*M"'@
L+[0V
dp#B1J,
N!B$`2S#
[3M)n=N<W1
W'@%L"F!*r
Z;K.$V9
n<],G!
U$<Y+D_8~-
tT2}.>N
E@/:]r
/7Y>;T
TF6L*@-Z=j9 #Y?<S
]9\3A&
P'r!?O3C8V1V
B(]:v%
v E1^j
o#p@*j
_5R2VH8M+
#k3A)O+&
"K.Iy$n
p!?O("a
06D+O(h#
_!**D#d7
J!G5Z+DK
a6+Y6R5
?[<z)B
mz)A1V
hM+R=8>x+J:>P
ud7N>! R=Y>e.
W6F')2B
L-]6P
={(I9A
!&T;_8h3
%J%T/I
k3G6K-o
Y6>#e6W'6P
_(X3U'H
0T3u&6F
.#H.\3A&
;I&B%M
,j9X(-KQ
J!G5Z-J+G
:J!G5Z
_/.("%
[+@&T;
M&@2](O
=Y>x+4D
f,1P K-I&.
U4D/I%J
E$T)Oj
'L*X7=Z
6%N(Z5;\U
"$b1P 5S+
.'U:^9i:
(I9R4@'
|-*X7S4
#G f5Q
H#E7X69V
3R"I/L
?T2@/5R
)B$V9G =@
<X?y*5E
!Qvmp
A P%Cz
2Y?M"0W
+J:Q7/@018k9I*
!@0[=9V
*X7S4\
4r!@0E#d
3R"I/G(D
80IN>
U5T$O)E*i
yM?P4S
|,JY6V_
A P*Lz
r+L~T5E.H9V
O%s 5_4R O*M
|^<X?1b
m3`]'K-_0>Y
rI+q"u
r(%A&`3L4B
c$@4[K
D'5^8J%;T
_>N%C+<
=Y>x+D,@
*K;P6>IS*
o%n+Y.G
<L-]6P
,(n=\,A
$1Z<N!?P
$T5E.H4S
P0@+M)F
S"Q:\.A
1a87[=O .I
U$O)[4M*&r
A#1]9^
U2@/K,g4
\:|/N>R4
D7$O)[4J%
>W%J.I
P;w1b
Q5s @0&
t0c+#H.Y6X
.G&V;]
o13R"G!
!@0Z<c
'N-=R4
_0T3s
f.S2B(N
9!S<V1?/N>T2T
Y&B%b1
b,M=U3
_-B%B!j
" R=U2
(;_8}.
?U4D,J
i.G5Z:]
?)o<\,#
&G7Y?|
*"d7P
1'F6U3
F,/D"F)]
K F1^
H#E4[
,^1S4k
;P6B-/
>9X(B$
)o<\,W
6D+K,~
$$O)T;%>x+I9f
99X(B$g
)%c0P
-P1A)O
7(I9Q7
P1A)OG#D
E%N(Y6
.1U2s
Q'U:]:b
.T5E-K{
<N!B%S
9B)O<SW
4U%M+m
0&M+X7g
/[:Jyp
-B)O9VQ!g4P k
V,j9V&
7\:G(
AW'#*q
w!L'?P
N=-0^/"D
C";MH6
G =S(X
,\/6_'
s*<5I
O3H# L-6Z
bE(em
-a"G3S
T[;@,]
!p.K,=
9=$FI,
=?o<4>
]-F #Lx
=RC#[3r
W0h;G7M+D+6Q
c0$T?Yn
Yb0Q!S
9]:T0W
n({&L2S!N"=
D.Y<N!/B
#!U28W
\3U2m>V&K-W8Q6n=E5Q7C,/H
_8|//_y
L+k8/_
W0t'B1-K8W.H
@'`3I8"D4[5Q
J,L+[
P6L,\
G(K,"p
*yO3V0B,
K#K+i:
.]]:J!?X
H3X>L#C$b1P K-_0T3g4
K F4[;\
I(X3U'H,K
\;}.O?T2@/K,i:&1Z<N!A&`3R"I/]2V1
\;y*>N
W14[.I
X(+M$K
V(c.-O*K
9.24%U
F"VQE^
H.mCj=
Q>kMNF
>~`Smc:
W[mOob
$KksFVz
M"WqzQ
ImqL}d
O.oEf%
n\yQuP
Vf^JMa.
H'TtuX
<SHpyU
Zs[Ah]do
GI~-sLX
(X}]RSm
ABjOiMP
'FGmNy
xQbRxB
YNjomaL
*{UW{A
H@GWri
nSPPmJ=
6kXkuG~@l?o`NB}d
T2k[T{
EFnK`xE
wU\kyI
Ga2h|_ml-
-KJfEIzR
GHk8oa[nqU
tN~I[}2
M&QdN^
9v`A};
8[uTFm
qfMmX>
4PHO_m
RNkOCt0
"gio[+{
bJoQ7|
2nKoJx;
YqN!p^)
+JxU]{%
=jNKJu
-LMgDK
Xd7xqLu
7\KzXMkpP
-LmUYl
DUecgT
t`I;eBh
?o`N(kEd
,^lTUochN
ONbI.ykMru8
KLhQ#w
"tyPDh
UCFXp^FaV9nJOF
UCFX9ZrWN
-Z~{(ZkCJ
%thL<hO
LOaH/zjNrrB
DexPeGgZ1
ABjOjK@hqEn/
>]sZgm`HIcH:fCg
!Qb]izN
SFu]Jnk8zk)
/_p^I|V2fau9
3CeONbI?
\~QwnA
e67G,E*E
S<X23`
[4P,&u
.A%3't
U3A)N
;_+m4U$F
f5%U>O
8W3;:i
;M=L*K$6Q
M=V)p
8H#0"M
-B&(#p
Y6H/h4
V1j9N>H.R=L+c0$T
|:@!1Z
T?9K#2H
{=A #H
tC1(L
8S(Z+O'J
>_/?$V
M*LQ!
^?B)E7
S4e6M=
U%A'K$
W'?Y!N
L+`3H8
>U&T1U
~B)"P2V'a
a'G&)B
c%I(+@
1j9N>(N
X?l?T$
@&G(B%
m+K*-F
k-D%5^7
@+@2S7
LG7$B
_0J->m
x>@!$O
N* f(I/D
c%I(+@
6c0G7/I
pN)b1F6
d"D%(C
d"D%(C
[:=V&T
oG!&I
U34[5R
M+9V1#"q
W16Y3T
[0)['C
n(A 0[
X!+X%0P
.=1Y-K
Y3Q#e23C
Z5c";J
K*?k*E5[<@!7K
\/Q,G5Z"A
/<R K'(f%<D)O;L
F'V5K-Bp-u
R-T;]/@$?q"C3T.\3W-e
.7?7L6P0W
:C K#H
_/,A)E"d"1
W6F-G3\8_
\+8VP2K
N+;O'K[:q
Ft$%U4N
h([:-4
b09E.G
L*Z1M;T/F
Y(C%W8B$b
*Z1Rp
s5O-]$
<*>=..
A3\25r 0
B#S8^,
0T3i9X!
u!V64W+D
^+2BD
>Z;G"C
U7K+6@
y#T1A)A
W6P1w#%C
G):T!N*;
d2E-&=2X.;`.>G$0
T-?I!8l
S1C+N'[
{8N*R1D/773c
Y0::O+K
^9t"C1L
T*I.h)
=?M$<.@
YH)X+?G
[$Cp(y
64+B0]'
4]5?L(X%
4N.(I#48N
Z;{&E3V+R;W
-Y6Q(]
W )Y4N']
&B0M)S:V)m<O<I-]*L)a0O=N&F'5P
%A)%>D#&:d):->;A&@Q
I4 B#I
]WTm
Z/G+=Q(`%6>Gk
D"a*/X'%E
V+48:B
P)66<<S
7:-8A!555W
\29Q'2b
7\5=T0<S5H
D*C$`!
1O(m4D
^ ?=P,C
/K4^.W.I
_-D P:T2b
gJ)A(J8V$+
G&V=[)F"E
P1A*L=R5R
H)Y2T&I-J
G&V=[)F"E
U4D/I;T
L#G f5
P?S4q"
oD"P?#D
^+-?043U
5%*:o23#(.<370:
:N4?9+$ 'A
&'7<:(
7W,<71#,(
/.>53!
>k.B(#%78
S+9625S
?L4;?+@
<=-& 2=9
v4.0.30319
#Strings
#a.dll#
#afa.dll#
#ga.dll#
#fasdgsfsd.dll#
#f.dll#
#af.dll#
#hdsafaaaadadsadfffwtwfffffffgsssssdf.dll#
#hsstadaaadwsssssg.dll#
#gs.dll#
S400_400_100
GetTypeNET40
<InitializeModules>b__5_0
$$method0x600001a-1
$$method0x600001e-1
<Initialize>b__89_11
_stateSHA1
<i>5__1
IEnumerable`1
Task`1
$$method0x600001a-2
Shell32
ReadUInt32
ToUInt32
ReadInt32
ToInt32
Oleaut32
Ldind_U2
Func`2
Get_Exponent2
ExecuteLockedDelegate`3
Get_Item3
<>c__DisplayClass3
ToInt16
get_UTF8
Ldc_I8
<GetModuleRefs>d__279
<i>5__9
<Module>
RegexFCD
COR_E_ARGUMENTOUTOFRANGE
INVOCATION_FLAGS_NO_INVOKE
PinvokeOLE
LOCALE_SABBREVLANGNAME
SECOND_PRIME
HEADER_SIZE
COR_E_SYSTEM
SM_CYSCREEN
System.IO
MAX_ROWS
S_GMANPROC_ST
PersianEra
PerformanceData
BuiltInResourceData
ExecutionContextRunData
SetData
ISCIIOriya
mscorlib
System.Collections.Generic
get_IsStatic
CreationTimeUtc
CheckSumAlgorithmId
GetProcessById
BlockingBeginRead
lpNumberOfBytesRead
hThread
get_CurrentThread
thread
_nLoad
fsassdsadfassssssssssssssssssad
M_whatsCached
get_IsAttached
IllegalMasked
Get_Enabled
IsBestFitDisabled
CtorSecureOpened
Get_Is32BitRequired
Set_Is32BitPreferred
FReserved
ClassLayout_isInitialized
GetConstantRid
IsInvalid
set_IsBackground
DynamicMethod
DefinePInvokeMethod
ResolveMethod
Set_RemoveMethod
GetMethod
NetGuard
dafsasfssd
get_IsInterface
Replace
SEP_Space
OnlyAllowedOnce
MayCorruptInstance
_objectReference
LoadResource
FindResource
SizeofResource
GetHashCode
SetCode
FileMode
CryptoStreamMode
Xenocode.Client.Attributes.AssemblyAttributes.ProcessedByXenocode
IndexOutOfRange
EnableTypeDefCache
EndInvoke
BeginInvoke
ImplMapTable
GetEnvironmentVariable
Enumerable
IDisposable
Stable
set_Visible
get_Handle
RuntimeFieldHandle
get_MethodHandle
RuntimeMethodHandle
GetModuleHandle
get_TypeHandle
RuntimeTypeHandle
CloseHandle
SafeFileMappingHandle
GetFieldFromHandle
GetTypeFromHandle
SafeWaitHandle
ToSingle
IsFile
Console
get_Module
DefineDynamicModule
Get_ManifestModule
set_FormBorderStyle
get_Name
CAlternateFileName
StrFileName
CheckSchemeName
lpApplicationName
Get_ReflectionName
set_ObjectName
M_argumentName
DuplicateComponentName
AssemblyName
GetDirectoryName
ReadLine
lpCommandLine
WriteLine
Machine
MakeGenericType
get_FieldType
Type_RuntimeType
DefineType
FindMethodCheckBaseType
CreateType
ValueType
MakeByRefType
get_DeclaringType
flAllocationType
get_ReturnType
GetMethodBaseReturnType
Get_AppDomainManagerType
get_ParameterType
System.Core
EnsureInitializedCore
ResolveSignature
SetLocalSignature
Set_CurrentUICulture
MethodBase
Dispose
Truncate
CreateResourceDataDelegate
CreateDelegate
MulticastDelegate
PermissionState
set_WindowState
FormWindowState
STAThreadAttribute
CompilerGeneratedAttribute
UnverifiableCodeAttribute
DesignTimeVisibleAttribute
UnsafeValueTypeAttribute
BabelAttribute
SuppressIldasmAttribute
AssemblyInfoAttribute
YanoAttribute
DotNetPatcherPackerAttribute
BabelObfuscatorAttribute
CryptoObfuscator.ProtectedWithCryptoObfuscatorAttribute
DotNetPatcherObfuscatorAttribute
DotfuscatorAttribute
CompilationRelaxationsAttribute
SmartAssembly.Attributes.PoweredByAttribute
RuntimeCompatibilityAttribute
set_UseShellExecute
WriteByte
SetValue
get_IsAlive
LengthNotNegative
SizeOfHeapReserve
kfrodgFSap.exe
get_Size
Set_HeaderSize
dwSize
Finalize
Resize
SizeOf
fshdfhfffafasrdadsatrfffffffffddf
fsdsdfsddddgaaaaadwreeegfsdf
DefineTypeDef
GetEnumTypeDef
ResolveTypeDefOrRef
get_IsByRef
SecurityPermissionFlag
GenericSig
AddStandAloneSig
ByRefSig
Get_LocalSig
System.Threading
Encoding
IsLogging
Get_DontWriteAnything
StartCrossDomainTracking
Ceiling
Get_Remaining
FromBase64String
ReadString
OutputDebugString
GetFullSearchString
ToString
GetString
ReadInlineSwitch
ParentSwitch
MatchesNameHash
get_ExecutablePath
GetDisplayablePath
GetFolderPath
ObfuscatedByGoliath
get_Length
CheckAuthorityHelperHandleAnyHostIri
Get_IsCharSetAnsi
M_threadSafeObj
AsyncCallback
Set_Fallback
callback
GetTokenNoLock
ExpandByABlock
FlushFinalBlock
MatchTimeMark
Trademark
VisibilityMask
Marshal
IsOptional
ISO_8859_8_Visual
IterateAll
kernel32.dll
Get_ISOCurrencySymbol
AnsiCurrencySymbol
NegativeInfinitySymbol
Control
PositionImpl
Popcrawl
GetClonedImageStream
FileStream
MsfStream
CryptoStream
MemoryStream
M_retParam
mbfgkcjkncm
get_Item
System
SymmetricAlgorithm
ICryptoTransform
CheckSum
InfiniteTimeSpan
CurrTextElementLen
get_MetadataToken
hToken
lpNumberOfBytesWritten
AppDomain
get_CurrentDomain
_IsFastFullTrustDomain
SeekOrigin
Set_MinorVersion
Application
get_Location
_destination
NineRays.Obfuscator.Evaluation
Set_LoaderOptimization
System.Reflection
CaptureCollection
ManagementObjectCollection
M_restriction
Get_Condition
CallingConvention
RuntimeWrappedException
InvalidProgramException
FormatWithInnerException
_exception
CurrencyPositivePattern
WaitingToRun
GetDynamicILInfo
FieldInfo
MethodInfo
startupInfo
MemberInfo
ParameterInfo
set_StartInfo
ProcessStartInfo
DirectoryInfo
EntryInfo
kfrodgFSap
_autocap
YearDateSep
MonthDatesep
NumDatesep
System.Linq
InlineVar
set_ShowInTaskbar
Get_ThrowOnUnmappableChar
HexToChar
LastChar
MarkFinallyAddr
lookupMember
StreamReader
TextReader
BinaryReader
DESCryptoServiceProvider
VJSharpCodeProvider
MethodBuilder
ModuleBuilder
GetTypeUsingTypeBuilder
AssemblyBuilder
SpecialFolder
M_fallbackBuffer
lpBuffer
CharBuffer
ResourceManager
CurrentAppDomainManager
SecurityManager
Debugger
ManagementObjectSearcher
LogSwitchLevelHandler
BinaryWriter
get_IsPointer
BitConverter
DynamicResolver
AssemblyResolver
SchemeAndServer
AnsiToLower
AppDomainInitializer
Get_TypeContractsAreFor
GetTokenFor
M_directorySeparator
ManagementObjectEnumerator
GetEnumerator
.cctor
dotNetProtector
get_IsConstructor
CreateDecryptor
NewEncryptor
_nameHashesPtr
IntPtr
GetHour
Get_Characteristics
System.Diagnostics
GetMethods
M_listMethods
System.Runtime.InteropServices
System.Runtime.CompilerServices
System.Resources
kfrodgFSap.resources
bInheritHandles
_includeFiles
EnableVisualStyles
Get_AbbreviatedEraNames
AbbreviatedDayNames
GetNestedTypes
EmptyTypes
lpThreadAttributes
MethodAttributes
TypeAttributes
Get_ImplAttributes
MethodImplAttributes
GetCustomAttributes
lpProcessAttributes
GetBytes
Get_Indexes
LegalKeySizes
BindingFlags
dwCreationFlags
GetMethodImplementationFlags
SetImplementationFlags
GetFlags
m_perfWarnings
Get_BigStrings
GetSearchPaths
extraMonoPaths
GenericMethodArgsEquals
System.Windows.Forms
Contains
AssemblyExtensions
CreateSections
CallingConventions
PeHeadersOptions
M_faultExceptions
ILeadingZeros
_GetEventProps
SetEventProps
get_Chars
MatchChars
PeHeaders
GetOptionalCustomModifiers
RuntimeHelpers
GetParameters
sssssffhdfffffadtrrs
sssssffafaffasfadtrrs
sssssfaddftrrs
ProjectedClass
EnclosingClass
Get_IsAutoClass
RegexCharClass
get_IsClass
FileAccess
AssemblyBuilderAccess
hProcess
GetCurrentProcess
lpBaseAddress
lpAddress
Compress
FixOffsets
Digits
SetInterfaceConstraints
ReadByteAt
Concat
InternalSyncObject
GetUninitializedObject
ManagementBaseObject
GetObject
object
Select
flProtect
CharSet
NativeOffset
IndexesOffset
op_Explicit
System.Reflection.Emit
SetCompatibleTextRenderingDefault
IAsyncResult
SearchResult
result
Get_ExternalProcessMgmt
Get_PositiveInvariant
Get_IsCovariant
Set_Constant
System.Management
Op_Decrement
MayHaveFragment
FileAlignment
lpEnvironment
get_Current
CheckRemoteDebuggerPresent
IsDebuggerPresent
OnAssemblyLoadEvent
DecrementOverridesCount
SequencePointCount
ParameterizedThreadStart
Convert
ThreadAbort
Get_MetadataImport
FailFast
GetFieldList
SuspendLayout
ResumeLayout
DeleteClassLayout
set_RedirectStandardOutput
MoveNext
System.Text
ThreadStart_Context
SyncContext
GenericParamContext
context
GetDateTimeNow
RawCustomAttributeRow
set_CreateNoWindow
BreakCanThrow
DeleteFileNoThrow
ydadsgssadasdasw
IsPrefix
HaveDay
SafeArray
InitializeArray
ToArray
Get_IsArray
get_IsArray
Occupancy
RemoveKey
System.Security.Cryptography
DefineDynamicAssembly
GetExecutingAssembly
Get_IsClr20Exactly
ConstrainedCopy
BlockCopy
CreateDirectory
lpCurrentDirectory
Capacity
op_Equality
op_Inequality
System.Security
SuppressUnmanagedCodeSecurity
IsNullOrEmpty
198 Protector V2
System.Security.Permissions.SecurityPermissionAttribute, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089
SkipVerification
WrapNonExceptionThrows
_CorExeMain
mscoree.dll
nnnnnnnn
@nnnnnnnnnnnnnnnnn
@@@@@@@@@@@@@@nnnnnnnnnnnn
@@@@@@@@@@@@@@@nnnnnnnnnn
@@@@@@@@@@@nnnnnnnnn
@@@@@@@@@nnnnn
@@@@@@@@
3ZZZZZ<`}a
CZZZZZZZZ
((((((NA
"{((((ZZZZZZZZZZZ
?(((((((((((ZZZZZZZZZZ
((((((((((ZZZZZZL=Z
>>>>>>>>>>>>>%
.........>>>>>K
Itt..............
DN.>>.UR
[h....
9JHHHHHHHH>
......>>>>>>>>
.......>>>>
......
66666666666666666e
q666666666
6666666
6666666
@nPPPPPPPPPPPPPPPPP
@////////////////P
,PPPPP
@/////////////////^
/w//PPPPPPP
i///////PPPPPP
//////PPPPP
/////PPPPP
ooooooooooooooo
/////PPP
ooYYYYYYYYYYYYYYYYz''oooo
YYYYYYY77777777777YYYYYYYooo
((ZYYYY7777777777777777777YYYYYooo
((ZYY777777
77777YYYYYoo
yyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyy
::::::::::PPPPP
ooooyyy5K##########::::::::PPPPP
jjjjjjjj#######:::::::PPyyy
jjjjj######::yyyd
UUUUUU
jjjj##yyyGd
========UUUU
=======\
hhhhh
D==yyyY
NNNNNNNNW
TE2 yyy@Y++++++++7
hhyyy(@f
g222WWW/
++++++Nyyy
(VVVVVV
o>>>>>>>>>>XBV?6V
&&&&&&&&&&&??
>>>>VVVV
yyy:Pmmmmmmmmmmm
&&&&>>>>>VVV
mmm&&&&&>>>>yyy#:Q;;;;;QQQQQ%n"
mmm&&&&yyyj#;;$$$$$;;;;
mmmyyy
j$$$kkkkk$$$'ss$$;;;;;QQQ
2kkkk$$$$$;;;QQQyyyU
ZZAAAAZZ2
kk$$$$;;;yyy=UAA111111111a4]AAZ
kk$$$$yyy =111!!!!!!!!!!!1111AA
kk$yyy 11!!!iiiiiiiii!!!111AA
pp,,OO
yyyyy.[
pp,,OO
yyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyy
_________________
-----AA
UUU --
333HHI
S-AWWWWWWN"""222G -@@@@@
U
^,,,@@
TT,,
H1((((J5(1
kfrodgFSap
GetEnvironmentVariable
_ENABLE_PROFILING
_PROFILER
-451627949
451607578
1206027644
1206032134
637244603
637242251
-608198963
608363917
-1699382625
1699398983
1503413335
1503477881
1315912307
1315851952
-2059204156
2059250894
654568132
654570160
687734423
687693248
-741253754
741266472
-2020203407
2020086863
-304045634
304042790
798516757
798566499
1158444967
1158445905
1843975088
1844034684
-708722102
708756223
-1206111314
1206007781
1054710283
1054711504
-849631765
849714931
-830567772
830550453
-589232256
589292002
4219789
4225266
-1705177079
1705184884
-1234607610
1234567777
817881409
817837385
-31685205
31661771
-1854941052
1855028791
-986068175
986112439
137152656
137214682
-1374122346
1374117341
-1407143788
1407154246
734139004
734143790
797511083
797513719
1970469748
1970430223
-477825197
477741854
-1242559240
1242459754
486465181
486424919
-1328991792
1328961194
893132984
893207583
-1095725565
1095684061
-1855544764
1855653291
-339626173
339675657
-165001527
164985141
-1181965013
1181986386
-1100315916
1100224175
1386710272
1386735060
-1491669491
1491717340
65090374
65031596
662716152
662711930
1420822202
1420834262
-927987524
927890757
1348633496
1348635462
-469068524
469027263
-1690866186
1690876366
817024589
817025284
-1339309682
1339298308
1365468013
1365495943
1366795864
1366792798
2034731241
2034669643
1950305375
1950236647
938709260
938676551
-2040818925
2040824707
-1498196596
1498328321
1357184287
1357175304
-941552753
941511854
667089636
667090770
-949784052
949771574
252480716
252477863
-538640022
538703282
471711683
471646574
1077974500
1078036970
-2009096668
2009104673
-2005506019
2005643414
39193185
39241819
21741993
21717248
-405518252
405495636
-728558400
728617420
-683247572
683248743
405077961
405137141
-1092835883
1092859038
337748953
337769418
490307701
490296448
36214851
36227987
-289707054
289777971
-83376827
83441120
-1596886705
1596980991
-251027577
250934845
992802998
992863500
1814742267
1814724638
-1857972300
1857956241
-119998910
119944021
-1106578600
1106634470
-1698457218
1698492732
-754585194
754710117
-1297145680
1297212078
-80109264
80155834
1823881734
1823905340
-185258963
185285458
-303476253
303522129
537899253
537866577
-1341838973
1341821542
1162765284
1162741465
-1306362238
1306281969
1625515305
1625454501
459674976
459745442
706074053
706037832
635548423
635489186
1878683950
1878667644
-1101998954
1101965157
-2046006440
2045916761
1410489003
1410535021
611841462
611765864
1680806646
1680764397
1512047345
1512144658
614597233
614687724
-194941502
194999640
1653422919
1653359941
157312002
157366903
1362352678
1362353804
-1885209881
1885085203
913313487
913356225
1709296476
1709270295
-1492158426
1492172840
-1732524078
1732539880
-1950242004
1950324526
294819489
294880536
590182998
590115562
1527057151
1527007362
-99649639
99688660
616118137
616116321
-1945937556
1945924540
-1297424170
1297387997
-1876633466
1876496157
-2032107098
2031963834
-1396049265
1396121769
884861117
884856706
2047199773
2047118660
-1929851324
Antivirus Signature
Bkav Clean
Lionic Trojan.MSIL.Injuke.4!c
Elastic malicious (high confidence)
DrWeb Clean
MicroWorld-eScan Gen:Variant.Strictor.265471
FireEye Generic.mg.ee997c35fca1094c
CAT-QuickHeal Clean
ALYac Gen:Variant.Strictor.265471
Cylance Unsafe
VIPRE Clean
K7AntiVirus Clean
BitDefender Gen:Variant.Strictor.265471
K7GW Clean
Cybereason malicious.bf08ff
BitDefenderTheta Gen:NN.ZemsilF.34266.Pm0@aSUN!1aG
Cyren Clean
Symantec ML.Attribute.HighConfidence
ESET-NOD32 a variant of MSIL/Injector.VRI
Zoner Clean
TrendMicro-HouseCall Clean
Paloalto generic.ml
ClamAV Clean
Kaspersky UDS:DangerousObject.Multi.Generic
Alibaba Clean
NANO-Antivirus Clean
ViRobot Clean
Rising Clean
Ad-Aware Gen:Variant.Strictor.265471
Comodo Clean
F-Secure Clean
Baidu Clean
Zillya Clean
TrendMicro Clean
SentinelOne Static AI - Malicious PE
CMC Clean
Emsisoft Gen:Variant.Strictor.265471 (B)
Ikarus Clean
GData Gen:Variant.Strictor.265471
Jiangmin Clean
eGambit Unsafe.AI_Score_89%
Avira TR/Injector.kxzyd
Antiy-AVL Clean
Kingsoft Win32.Troj.Undef.(kcloud)
Gridinsoft Clean
Arcabit Trojan.Strictor.D40CFF
SUPERAntiSpyware Clean
Microsoft Trojan:Win32/Woreflint.A!cl
Cynet Malicious (score: 99)
AhnLab-V3 Trojan/Win.Agent.C4773566
Acronis Clean
McAfee GenericRXQS-MP!EE997C35FCA1
MAX malware (ai score=82)
VBA32 Clean
Malwarebytes Trojan.Crypt.MSIL.Generic
Panda Clean
APEX Malicious
Tencent Clean
Yandex Clean
TACHYON Clean
MaxSecure Clean
Fortinet MSIL/Injector.VRI!tr
Webroot Clean
AVG Win32:InjectorX-gen [Trj]
Avast Win32:InjectorX-gen [Trj]
CrowdStrike win/malicious_confidence_90% (W)
No IRMA results available.