Static | ZeroBOX

PE Compile Time

2022-12-06 21:49:41

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x000b33d4 0x000b3400 7.84941930262
.rsrc 0x000b6000 0x0000377c 0x00003800 7.79618396628
.reloc 0x000ba000 0x0000000c 0x00000200 0.101910425663

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x000b60c8 0x00003345 LANG_NEUTRAL SUBLANG_NEUTRAL PNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced
RT_GROUP_ICON 0x000b9420 0x00000014 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_VERSION 0x000b9444 0x00000334 LANG_NEUTRAL SUBLANG_NEUTRAL data

Imports

Library mscoree.dll:
0x402000 _CorExeMain

!This program cannot be run in DOS mode.
`.rsrc
@.reloc
@"Gb;
#ffffff"@#
lZXZY(b
lZXZY(c
v4.0.30319
#Strings
textBox_K01
textBox_V01
AGENT_CLOSEBY_DISTANCE_LEVEL_1
ObservableCollectionThreadSafe`1
IEnumerable`1
Queue`1
Collection`1
List`1
textBox_ek1
textBox_ev1
textBox_K02
textBox_V02
ToInt32
AGENT_CLOSEBY_DISTANCE_LEVEL_2
KeyValuePair`2
Dictionary`2
textBox_ek2
textBox_ev2
textBox_K03
textBox_V03
AGENT_CLOSEBY_DISTANCE_LEVEL_3
textBox_ek3
textBox_ev3
textBox_K04
textBox_V04
AGENT_CLOSEBY_DISTANCE_LEVEL_4
textBox_ek4
textBox_ev4
textBox_K05
textBox_V05
textBox_ek5
textBox_ev5
textBox_K06
textBox_V06
get_a46
textBox_ek6
textBox_ev6
textBox_ek7
textBox_ev7
textBox_ek8
textBox_ev8
textBox_ek9
textBox_ev9
<Module>
<PrivateImplementationDetails>
SUCCEED
AGENT_MOVEMENT_RANDOM_RANGE_PERCENTAGE
ABDiSE
get_GG
get_ASCII
button_SelectDLL
checkedListBox_AgentDLL
System.IO
button_CreateTP
GMap.NET
AGENT_MOVEMENT_ENVIRONMENT_BASIC_UNIT
MAXIMUM_RESULT
simulateOneStepByBW
ImageX
ImageY
value__
RefreshAgentData
button_saveEnvData
mscorlib
System.Collections.Generic
RunWorkerAsync
IsDead
CreateWorkerThread
DoWorkerThread
get_CurrentThread
add_Load
gMapExplorer_Load
MainWindow_Load
RandomSeed
windSpeed
add_ValueChanged
numericUpDown_SimSteps_ValueChanged
add_ProgressChanged
bw_ProgressChanged
add_SelectedIndexChanged
listBoxAgentType_SelectedIndexChanged
listBoxAgentControl_SelectedIndexChanged
comboBox_MapProvider_SelectedIndexChanged
listBoxJoinedAgentList_SelectedIndexChanged
listBoxAgentList_SelectedIndexChanged
GetItemChecked
SetItemChecked
DrawImageUnscaled
set_Enabled
set_FormattingEnabled
set_Handled
get_Cancelled
IsAnimated
IsActivated
ClearSelected
IsSelected
add_RunWorkerCompleted
bw_RunWorkerCompleted
Synchronized
NewGuid
<InnerBrush>k__BackingField
<TextBrush>k__BackingField
<OuterPen>k__BackingField
<TextFont>k__BackingField
<Text>k__BackingField
timerEnd
get_Hand
MoveByWind
GetMethod
AgentDistance
CreateDLLInstance
CreateInstance
defaultInstance
GetHashCode
DynamicMode
set_AutoScaleMode
FileMode
set_SelectionMode
avgAltitude
get_Message
ShowTestMessage
get_ProgressPercentage
set_Language
Invoke
Enumerable
IDisposable
Double
GMapMarkerCircle
IsCircle
RuntimeTypeHandle
GetTypeFromHandle
EventWaitHandle
FillRectangle
DrawRectangle
Console
label_STPIdleTimeTitle
label_AgentTypeTitle
label_AgentSubtypeTitle
label_CurrentLngTitle
label_STPWorkitemTitle
label_CurrentStepTitle
label_AgentPropertiesTitle
label_SelectedAgentPropertiesTitle
label_SimStepsTitle
label_CurrentLatTitle
label_AgentListTitle
label_JoinedAgentListTitle
label_STPQueueDelayTitle
label_SimDelayTitle
set_FlatStyle
FontStyle
get_Name
set_Name
methodName
fileName
dllName
ClassFullName
className
ClassShortName
numericUpDown_STPIdleTime
DateTime
numericUpDown_STPExecuteTime
label_ExecuteTime
executeTime
WaitOne
WriteLine
AgentSubType
LanguageType
workerType
get_ParameterType
GetType
listBoxAgentType
IsSquare
GMap.NET.Core
System.Core
temperature
get_Culture
set_Culture
resourceCulture
MethodBase
ButtonBase
UpDownBase
ApplicationSettingsBase
Dispose
FillEllipse
DrawEllipse
OverlayMouse
Update
button_Create
DebuggerBrowsableState
EditorBrowsableState
activate
get_White
STAThreadAttribute
CompilerGeneratedAttribute
GuidAttribute
GeneratedCodeAttribute
DebuggerNonUserCodeAttribute
DebuggableAttribute
DebuggerBrowsableAttribute
EditorBrowsableAttribute
ComVisibleAttribute
AssemblyTitleAttribute
AssemblyTrademarkAttribute
TargetFrameworkAttribute
AssemblyFileVersionAttribute
AssemblyConfigurationAttribute
AssemblyDescriptionAttribute
DataMemberAttribute
CompilationRelaxationsAttribute
DataContractAttribute
AssemblyProductAttribute
AssemblyCopyrightAttribute
ParamArrayAttribute
AssemblyCompanyAttribute
RuntimeCompatibilityAttribute
Execute
Dequeue
Enqueue
get_Value
set_Value
button_Save
gMapExplorer_OnMarkerLeave
gMapExplorer_MouseMove
Remove
BlJn.exe
get_Size
set_Size
smallSize
fullSize
set_MaximumSize
set_AutoSize
set_ClientSize
ISupportInitialize
cancelFlag
stopFlag
get_Lng
set_Lng
label_LatLng
PointLatLng
latLng
textBox_AgentLng
System.Threading
set_Padding
get_CancellationPending
Encoding
System.Runtime.Versioning
MeasureString
ToString
CreateEnvironmentPropertiesString
DrawString
GetAllTypesFromDLLstring
disposing
System.Drawing
CommonDialog
FolderBrowserDialog
ShowDialog
Attach
ComputeStringHash
SolidBrush
get_InnerBrush
set_InnerBrush
get_TextBrush
set_TextBrush
textBrush
get_SelectedPath
get_Width
get_Length
WorkitemQueueLength
ThreadPoolCallback
WaitCallback
callback
get_Black
button_SelectDLL_Click
buttonCreateTP_Click
button_saveEnvData_Click
add_Click
buttonCreate_Click
button_Save_Click
button_SelectAll_Click
button_DeselectAll_Click
button_EndPool_Click
button_CancelPool_Click
button_StepSim_Click
button_FullScreen_Click
button_LoadExperiment_Click
button_SaveExperiment_Click
buttonStart_Click
gMapExplorer_MouseDoubleClick
set_CheckOnClick
ClearDeadAgentLock
agentLock
add_DoWork
bw_DoWork
Decimal
op_LessThanOrEqual
set_Cancel
ABDiSE.Model
GMap.NET.ObjectModel
System.Collections.ObjectModel
System.ComponentModel
button_SelectAll
button_DeselectAll
rainFall
sp_wall
System.Xml
ABDiSE.Controller.ThreadPool
SimpleThreadPool
StartThreadPool
button_EndPool
button_CancelPool
groupBox_SimControl
ContainerControl
IsControl
listBoxAgentControl
ListControl
control
FileStream
Program
get_Item
get_SelectedItem
cancelQueueItem
QueueUserWorkItem
System
button_StepSim
stepSim
stepsSim
Random
label_MapZoom
SelectDLLForm
AgentTypeIndexTransform
numericUpDown_STPWorkitemNum
numericUpDown_STPThreadsNum
tempAgentNum
set_Minimum
set_Maximum
resourceMan
Boolean
TimeSpan
get_OuterPen
set_OuterPen
button_FullScreen
set_ImageAlign
set_TextAlign
set_Margin
set_Icon
Application
get_Location
set_Location
smallButtonLocation
mapLocation
groupBox_AgentCreation
set_WorkerSupportsCancellation
multistepSimulation
population
EnableMarkerAnimation
DisableMarkerAnimation
System.Configuration
System.Globalization
System.Runtime.Serialization
op_Subtraction
System.Reflection
ControlCollection
ObjectCollection
windDirection
get_Position
set_Position
get_LocalPosition
get_InnerException
get_Button
gMapExplorer_OnMouseDown
NumericUpDown
get_NLDo
MethodInfo
CultureInfo
stateInfo
ParameterInfo
ConstructorInfo
gMapExplorer_MouseUp
Bitmap
label_GodCurrentStep
tempCurrentStep
SetToolTip
get_WallTop
set_TabStop
System.Linq
ProgressBar
set_HorizontalScrollbar
get_KeyChar
label_ThreadNumber
WorkitemNumber
AgentNumber
XmlReader
CreateTextReader
XmlDictionaryReader
GMapProvider
comboBox_MapProvider
OnRender
sender
get_ResourceManager
ComponentResourceManager
weather
SelectedMarker
CurrentMouseOnMarker
GMapMarker
initBackgroundWorker
XMLHandler
ProgressChangedEventHandler
RunWorkerCompletedEventHandler
DoWorkEventHandler
KeyPressEventHandler
System.CodeDom.Compiler
ABDiSE.Controller
XMLController
CoreController
coreController
controller
IContainer
get_CircleDiameter
set_CircleDiameter
IntPassiveDiameter
IntActiveDiameter
MaximumDiameter
diameter
XmlWriter
TextWriter
gMapExplorer_OnMarkerEnter
DataContractSerializer
XmlObjectSerializer
set_BackColor
set_UseVisualStyleBackColor
get_Error
get_WaitCursor
IEnumerator
GetEnumerator
Activator
.cctor
Monitor
XmlDictionaryReaderQuotas
Graphics
System.Diagnostics
workerThreads
threads
get_TotalMilliseconds
FromMilliseconds
GetMethods
System.Runtime.InteropServices
System.Runtime.CompilerServices
System.Resources
ABDiSE.Model.CH.resources
ABDiSE.View.SelectDLLForm.resources
ABDiSE.Properties.Resources.resources
ABDiSE.View.MainWindow.resources
DebuggingModes
CustomImages
Brushes
Assemblies
ABDiSE.Properties
label_AgentProperties
EnvProperties
properties
GetFiles
EnableVisualStyles
SubTypes
AllTypes
CircleDiameterTypes
GetTypes
LoadDLLClasses
SelectedClasses
ABDiSE.Model.AgentClasses
classes
set_NewLineOnAttributes
GetBytes
Values
SaveEnvTextboxes
RefreshEnvTextboxes
SubTypeStrings
SetDefaultConfigStrings
XmlWriterSettings
ProgressChangedEventArgs
AsyncCompletedEventArgs
RunWorkerCompletedEventArgs
MouseEventArgs
DoWorkEventArgs
CancelEventArgs
KeyPressEventArgs
Equals
get_Controls
controls
get_Items
workitems
System.Windows.Forms
GMap.NET.WindowsForms
Contains
set_AutoScaleDimensions
System.Collections
Definitions
RefreshAgentDataOptions
RefreshAgentTypeOptions
MouseButtons
MessageBoxButtons
numericUpDown_SimSteps
progressBar_steps
setToolTips
get_Chars
set_NewLineChars
set_IndentChars
GMap.NET.MapProviders
RefreshGMapMarkers
DeselectMarkers
GetParameters
AgentPointers
SystemColors
Cursors
GetConstructors
GetAllTypesFromClass
RunClass
agentClass
textBox_C0X_KeyPress
add_KeyPress
set_WorkerReportsProgress
ReportProgress
MethodReturnResults
maxNumberOfAgents
MaximumAgents
OverlayAgents
MaximumEnvironments
components
ElementAt
get_Lat
set_Lat
textBox_AgentLat
Concat
SetMarkerFormat
affect
ReadObject
WriteObject
GetObject
target
set_Offset
SelectedOffset
get_mLeft
get_Height
set_ItemHeight
get_ButtonHighlight
get_mright
op_Implicit
op_Explicit
IsDigit
EndInit
BeginInit
GraphicsUnit
get_Default
SetCompatibleTextRenderingDefault
DialogResult
set_Indent
ClearDeadAgent
IsJoinedAgent
loadSingleAgent
saveSingleAgent
CreateAgent
RecoverAgent
IsAttachableObjectAgent
targetAgent
IsNaturalElementAgent
CheckAgentAttachment
button_LoadExperiment
button_SaveExperiment
HorizontalAlignment
ContentAlignment
groupBox_Environment
AgentEnvironment
MyEnvironment
get_Argument
InitializeComponent
get_Current
set_Current
ManualResetEvent
set_Font
get_TextFont
set_TextFont
get_Count
maxWorkerThreadCount
tempAgentCount
ThreadStart
button_SimStart
timerStart
Convert
groupBox_STPTest
createSTPTest
createTPTest
RefreshJoinedAgentList
listBoxJoinedAgentList
WorldAgentList
saveAgentList
RefreshAgentList
AddToAgentList
listBoxAgentList
agentList
WorldEnvironmentList
AddToEnvironmentList
ArrayList
get_Out
maxWorkerThreadTimeout
IdleTimeout
idleTimeout
SuspendLayout
ResumeLayout
PerformLayout
MoveNext
System.Text
get_Text
set_Text
threadContext
ABDiSE.View
get_Now
IWin32Window
MainWindow
set_TabIndex
get_SelectedIndex
set_SelectedIndex
MessageBox
set_MaximizeBox
loadMapProvidersForComboBox
GroupBox
CheckedListBox
TextBox
numericUpDown_STPQueueDelay
numericUpDown_SimDelay
GMapOverlay
get_Key
ContainsKey
enqueueNotify
get_Assembly
loadAgentDirectory
get_IsBusy
set_Capacity
op_Equality
op_Inequality
mobility
set_Priority
workerThreadPriority
priority
populationDensity
IsNullOrEmpty
WrapNonExceptionThrows
ABDiSE
Johnson's General
Copyright
2014
Johnson's
$46c70d4e-f7c0-4241-8c15-81e2bff0e691
1.0.0.0
.NETFramework,Version=v4.0
FrameworkDisplayName
.NET Framework 4
3System.Resources.Tools.StronglyTypedResourceBuilder
16.0.0.0
KMicrosoft.VisualStudio.Editors.SettingsDesigner.SettingsSingleFileGenerator
16.0.0.0
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
PADPADPerY
:/ZY>&W
/X]6"W
:/ZY>&W
:/ZY>&W
:/ZY>&W
:gZY>&W
/ZY>&W
:/ZY>&W
:/ZY>&W
:/ZY>&W
:)ZC*<W2
:5Z[:$f
:/ZY>&W
:/ZC*<W
/X^<'K
Ig`QO46
/ZY>&W
:/ZY>&O35V
/D;3/\J
:/ZY>&W
:/Z[:$W{
:/ZY>V
M|e[P?,
=/ZY>&o
:/ZY>&o
dQB461
09_2V&
:"`j>$CD>%
.|\q%r7)
QA_[9:
/v!j&W
:/ZY>&W
>$U/-\D
-ZY>&W
:/Z[4xj S
:8t`>W
@x@[y:
e%6 {7Q&
%{7!K5
:)ZY>&W
:>xn>V
:/ZY>,W
f*F)LPm1
7:S6:/ZY>
:/ZY>&W
K*:$lT
/@I$&z
/uYoX~
?/GY>&W
:/ZC*<W2
E:QZY>&W
:)ZY>&W2
:/ZC*<W
:<|l>&W
:/ZY>&W
>T+!OJ
EbZP];/N9
:/ZY>&W
:3;"cq
@j=.M-y
;+/isg
9=6^>4
:/ZY0:M
3\je[7)
$:/ZY>V
;/GO%&f
/@I$&W
bI4vI<
0/LC^$
XXssly2
{834`F
TqRMC].
/F'5/ZY>&
Z;>||!.@Qan
:!fk>8W>
J]f'h2
82:%$O
eLF>{S
U7A-njy
'%\a)d
Kk:<|l>V.tm
:/ZY>8W>
0/LYNM
lUIMC]-
^^N5Mu%
:/ZY>&W
:/ZY>$
=vrJOj
<.!bS,
NG>V?tZ
B{A[(:
Rzm:nP\}%v
:/ZY>V9h\
/RY>&W
';Kn#;
F|tGU0
U:G$nd
d)']6m4b
4jJzK)2H
;/]W3&\
(bB^N5Mu#
QA_[9:
:)ZY>&W
A?+gzb
J:@ZY>&W"b9
NS`#n2
.fgu|
,;!^)P
&}@<rT
d)#;9dM
sz`@[x
LEYD!*
2}EIDl
B]q#>X
hh7n_o
v$F@;)"
Qj@,#(
#<5bxy4'W
!3814y'
@Ty~L8
Ubp;t
L>0VqG
J;vh{|
kUspW5
7#8dYC
QtUUps
`ZH+4-
/CJhSc
L5~Wja
;/PvLRy
'+96<5
;'J3Hoi
-)#,TK
U#pt/
1X__p,
xUf`P=`
]OUbpS
@a`A:H
k3$>m$
E?|v4+W
<l4GWR
}3")v,
r_JN;LJ_
$,C4+G
9IJ):=V
b+4c4%h|
@~bFq;-
@!f0
hQa;L%
]+`D+m
&L{4v_
|~4IG(
9PLu*7
Fy<[AD
))y#"!
"!]_Lp*
`Y{h|k
kpY>uP
_t"B=BB
8h4_'(`
f|x4jW
jYs#&X
vl;t4u<
B#%'*-0
"y[Ba*5
AMv?1T
')%4,84
yYQpY~
M;fJ5<
z!vD;,&<
:/ZY>&W
:+R]>'W
?:xhW>%W
Qm:?jtr
yK],};
&nOvY>z
/XX:$e+
\`j\4,
Q qYQ7
)x"%W:
O-\Z|{
4;\Zl`;
:-P\:8W
:*T]&9W
MB.~XDe
:/ZY>!W
:'hV>&W:
ZY>$W:
:/Z_2%W:
:-BO*9W?
7l[::/ho
V8N9D{
I/@2!93
5C!?>f-T
2R0/m"S
I$@?3c5
CJ@m)
X$@:b+
%N7['_
4JRMLZA2El
:7/G:8
DUMT)L
[Z,LTX)t
/,D.KC
Y~HLDOHme<ZC:
4;w.b=
A5=\-G
{mOw9)
3'J+/v
\_[i,W'2
(kO)-w-
9/RQ8,
xL}O')a
8TB,8d
&#R%.6
1%F15%
aD>"|?
X3'H1:'edi
T?15uo
jU!,t?
8*ED%
.hh4:a
'{j62Z
*xd3'`9
*G4!8|W
:.oS%<K
RP*'h"
X.FZ;A&0;C
>(kuDBH
:/ZY>&W
:/ZY>&W
:/ZY>&W
:/ZY>&W
:/ZY>&W
ZY>&Wt
\~%V7*
v%N7:K&:
:/ZY>&W
:/ZY>&W
:/ZY>&W
:/ZY>&W
:/ZY>&W
:/ZY>&W
:/ZY>&W
:/ZY>&W
:/ZY>&W
:/ZY>&W
:/ZY>&W
:/ZY>&W
:/ZY>&W
:/ZY>&W
:/ZY>&W
:/ZY>&W
:/ZY>&W
:/ZY>&W
:/ZY>&W
:/ZY>&W
:/ZY>&W
:/ZY>&W
:/ZY>&W
:/ZY>&W
:/ZY>&W
:/ZY>&W
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
hSystem.Drawing.Bitmap, System.Drawing, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3aPADPAD
9LXX'&{lH
QSystem.Drawing, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a
System.Drawing.Bitmap
IDATx^\
T,l7R.
>p8jgvW
)]!8.Kj
<t}=?iy
;?VmK|
o):EuZ
F"s~]L
sKTlJ}
fkV>\S
m"A'H%C
hdm"*O
IEHm1w27
Jte6~J/+
]~q2**a
*`Y~#@
R'->l
|xfz9ai
t`lv5EZy
HxLmXe
1Rs2>p
bat:_R
Q4#vb=Hq
AT!"(
qs@?Br9
3<Zf]L
iD2*7@C
MUcgnE&W
>Rw+a&
q|~C2~rq
31o7Z.n
zA5xTpD
N)ys$j
_%>3=@
D&B'62
BvY@<f
?ot9x?go
(dJF8J_
lLV)4_]
QdD)8|
kk/mkKW
&uACN|
`=h\c`
PQt`2
MVw^tzguY
54\S)B
PyaB(a
i.4wq{
@Y32&(
K{K[d^v
U``P9#
edqf(HLE
}{Z^N]`
=mF};m
gW$;_9F:
vVJO.Xj
P!j{db
d:DV4G
hnxU"B
Df*g,iEag
QEFMMk
}JUjI.
Rp&KDr=
L4"z82
;Zr{^v
<-s/<*V
^m|&kh
Q3#*tE5
63nbO)
+sw$$:^^
2\4&-$
~]@KKN
WSWTMm
uL;'|b
lVls`QL
V{g-l@
snzn1+G
PO@C3WG1
KN,b:'vN
t&RwX_
xeR'(|
u3/IZLgm
W+T^bjV5
vsB@oK`
lL,=!&
IC>sUgJ
7S^$9\
W}y~|e
!-Fz`{
;&0Epo
1S.lY
PJ0oa7yO
|-h~xt
xR'6R~
xyubtI
s%IzgE>
yP/mpOf
'*RX?^[
n(U^u1t
!wORm
{uQeVI
#[#qOH
Ck%?Edi
)]oU'y
__>o_/'
Kmi$_d\
{kH6bA
Q8"3C^v
-T=}j$1v*f<t
[X_"<X<
%=EJ>03
unv]bl
Q~_rXZE
v]RcTk
hC6#.e8~%
wmLux)
T;^T6{
&5(OFt
_;g]_}5;SS _
gZ[c}h
<VsO-]RL
m4/|-}%
=NH=~YB
4WIe:l~
AkDJi(
5Py`;(
rGWm%Z
74X!%O
wqrsKl
v(Hi1O
"qWAO]I
TFqs9ZKmF
VwIi!JQa
#a!E"a
]`l,zO
+E^/&/
FSV453
art}\Xm
9-W5LV
^??1>1
M<l_Q%
x`V.yz
y)w6WRO_
wW-,:D
=~x">l*v
=K$7#8
9N8$8~
Z[X7[#
O -Cuis
FW4~)=x[
KCl5.
,C0"j
}bPz,(
7PnP|t
N*iTx~xs
Z&^OsEt
OX /$/HT
uSTZN
[dwHW]
aT0FYM
mAC@0($%W
nM 2{G
'^h2n&
=;&n't
<]$NX5Y
Z^/~PN8
rZ+1|k
>g&4s_
$H-V>U
^qk'S>R
NZq>[o
S**_C8M
_=\oHO
+RznA[E
,yDoWW
HGmSr]Sg
'<lx&"
lX9Ao}
6;nR%(
wh6T*,
mY}-Kj
lC@H]0h
H :oY&
lZ8>6x#uOP
VUkzp~
\j"Lg*
5;0\r_Z
Q10=dHZF
Unn?Pb
0F-@.
${iT)}
R<OcVW"#
k~O]W"
IlfYjt
lrw}7K
5ZFO:N
6n#*mc
N}|3 cZ
$R|EzB
Kk<6ZY
l=}Z|y
q='4Q*
PL}|C
Oq9#E<
UcVp]O
triPR
ls+N=o
qkow*]
jCE$L^m?
@;::"F
JudRKi
/lBxF(K
;`|ATG8
<[R6rEM
9}O~'G
4,f?z|
]q^4h91
f`>TY$e
.**(;h
it\(1Z`;
|DHKV
9uC2WZp
Wo U;,
=hM"},-
x[pC]K]d
s)-TWx
F }@]p
$v*E$}
"ry:o<
0|agw0
*tV@*P
4Ti\7@
34hE0~B
!.a7La
Os}hrq
<+hzt+
,=o>5k
+5<b6%
(2?o]R
SWH1)P
7a_qj3
ut%"$h
_^72v#
^z-hH.;
kE0Y@l
EaR(Q}
#V+f^1
] (e14
]xi\Y-[
L:EMLcs$
C:F{To
nuU(ql
TmJ>u=
?V>,v4o
#=Atqa
pO} {*^
w5Mokl
"r&I\Mr
g5\>eU2
jeg2:e
-:}eh6t
|nR;In>]-
Ns_m}?
;k4OMt
;OQ_6O
{'AO5,
Dyvg:7
,AN!E[R
W3X@'Af
v>yu51
X-X@q,!
m-fzV4O
bh,k]i
Z7BEwi5
jq6w{k
j=we/+
CA=jp2
mfa`?5
[nC~!:U
+~.QR<~ZL
G~Ndj&
hI~{Z:
[\}%oz=<
f]J6zl?&*Ur
`N4Y7-
9vxv8`<d
}e+ciS
>vO@`x
}`!CH9d
r]Q3NtAs-
_AEhPG
.hw.'e
}$cH=75
vv$R#4v
8]LrW7
3:gQ@I
8>*26@
fg3'@d
WKsM/<{
]p.4N2
g6GE7Sh
JOg`Jn
kSVEji
N+n8h<
VY>L.x
^}Etdg
T7U_81\N
d"JaV5
eshHM[|
efx:(/
*6TTlX
ys'oWu
;2b.Np
-EJvow<
yYgOh_
pd:UoC
l~<3|1
^?9s6`p
H~6U='
~u9pF/
uZv<i{F
R3(:M0q
Uw]U3\(q
<,U""N)R
K:6!Td]0
i'*8+R
A?B1&Z
tdz01vq
EO[LUL
aB9nsiC:
P31*$O2r
k4$zL}X
DzeFVF
'cMt8jof
y#TuP
vH]RSS
'{b:y*d
7{h}W
@ECiM?
?}38ef
EvD_gS
po<Zr$p
IDAT:f
?z0tAd
g~n;|H
K5Sz:9
WCCPSX
a3z~1z^<@
Gity_:
je~(c~
kp9h9{
b&lby3>
Q")i-iG
>hL+t\
O/:ZN-Z&
2=3nD.
\?, Hq
uFA&LP
0`h_AC
8j2nK7
*J}rExf
YDCr.\
(?>>!`~m
{QM8*'
EJP:u9
<9`p24
Jtu22
`9=9_*R
5v@!E3
W{o2=av
Of*O,3
^n_$lVy|
JJV)y:
~//T9Q
\df#e
@2 Sci
;#5:cc
OUbAzZ
!~/a4i
~1~5xo
;Ax+(,
@sc`X@b
@"?!SRk!
,5Lr@D
w7lfU&
`jS0e026
ak@QIrWH
yoBK4#
B)cX~#
g!U(K
L~g.-b
Dv$]a=
{b'WH1
WH2>{=MX
dNF8wu
,H1`V;
<<@2(w
\^_k+x<
AfLp,|F
V{+'g?x&rg
DSbLdf.
fJ0x]I
WUAx:-d
<#KO&],
&=L?3|8e}
jx$gva
qtHG$q
hCv\[!
_BL$U
W|sO=z!s
/\*y(7
P&T] ~
I3&&RG
2 AqHl
LE8,[f
!>ZHXZ
_yfv1Wi
x*h/'T
W"~hmPQ
M.7z`O
z#S[*}
/G*"U7
Fe.*&]
zHnF3ba2
:A"4[p
B'`a+G
!6vWZZp
>Ro x:
28x@o$
@)fcc
:knl/p,
gca7u2
YiaR.0Q
A]\$zoM&
4c.>-6&
Ix)n"B
:2f"IX
(+:%)v
R9=dJu
4E05Dy6e)
5q+.}N
i}4{(7heF
z%U4#y-
@YY>"\
AwJDo<}
"Qggl<ny
_}kte\
/}Z8b~
j"L:PD6
GRNO(
a%V3b<
\Q/z+j
wafE?
:(NV]Ye
GW=tG-F
zHD1^q7
T{k01]@n
l_5[P@
5e7_Ew
/]M]y\
=u4f#.2
>VT317
+.78vK
0(/H"c
/<xm+y
)bWQAs
2~57FPc
X~PvQY
KC;!4Vv
"ZAojG
.0GM'
MTWDM1
IQK`Ol
I.Hj<gTUjL
&G$:IF
ff|h}LrAkEzsx
>IsN]
G`duY<0
jO08Uc}
-wYq:<
Zu?ZnRre*
yhM`QD
%2AujE4
CNUdO]
h5xE:6at}
r1.0l
y%<@.,
$ncmij
|&<qvm
vdGD%>V
0_}DJx
:]4EC6b
;m&P~=
D'[tyQ8
:AL ,D
D(Sa|E
O=}E2k}
Rdv$xk
v5#04pS
:s(<F!5
UD?9Ki
[3lxgj
8U~J.]^}/
:~ZP_=
HhkFa{
CJvlY=
1Yo_,
~.E4G0
ht>(j@
6rG:Zw_
I935w^
^F\!E@
lgfAry
wNn-'s
j6y:F0H
S^4#tj
uw3xnd>
'.Ie81n-j|
w1BY Nc
u`[\q8
76".o"
DF}MZ#V
Ea<,JpC-/(
C~9V!O
;84\4V
{(-v|/F
}9mbmqaW
[NVt ny
l k9 b5
*.wA4(
nw2O<-
DkI^">
)K`9abj
'?=dt
@aFnQD*
Wjj4z|
"2k>YK
|ATEe.{n
+YxDqKa
*hw];d
A!k5VW
ZhG'Q9
|lrs.X\
DhX_Ht
K{$~kd
MCgKDqM
XFgADZ
W.(7lx
p0tZa{
84Qv~?
%V~r$'8k
!] @guxA
*I$V2m
0RRJKJ
j<ahf{
Pap?B
y?sFag
{3$y*m
I36R}S>
OljY=MQ
V\>:n/k
(g;9ef
tm2qc>
mdi`2M
^~&n<!
\Gpz:n
U~k3:I
7{*(dl(
\OIO}m
+7=cvL
\+lLT}X
~8Q)v^
2F[7:<1
3`5-r.1
8#|&2u
-kC[&:-
tM<qPEe
ReNX?,{F
(*M^`.
uuQw=O
j!t$Ms
LHxZ:
ff\eg2y
NKE}m8
'QXBEF=
F+`mQ`1CU
@M!u%CG
/`_ !'hX_
qSd"@w
"q*P=/
g\?ZlU
.vn#o^
CZ`Y'7
4fKQq#
G|W~*-!~F
#,FAT)
vVA{S&9
:}9&%?x
{f|}QW
Pd8BmQ..
tyoN:g
=t6**[KC
tFFt:xS
j( NL@qpq
%lG'wbr
"i{a~y'A
ia#S^>e
jCkmAu
]{eoDQ
M>=t}ah'
a>!bsra
L%6/-t{u1
eoYG_{
:YLNfq
KZFL5n
8G8{~o
&/tWcr
I;+9hx
:jQ(n
Utg6Xl#
~-p\=#
5k=%n]
M>81,H
?<}z2D
F3]1wU
hi[NGY
!{pGQkl[
[o(%))E
_j"W-P
Jn'wZo
ZD/+Ec[
?.;xA{`98
`PD<OC
q;t CQ.X
#uQ_7^%
n<A?3v
ow^;\H
8G6-Y\vPT
uE2wk\
6-Sh]M
pZIh=m
hfUyqj
uzi~~P
,/`dZ;U
(P pJiX
("&8v
[,XmuX
:7vy{l
m^y3=CH
vx]XpA
L|_O,a
D?U]E[
eT$nQ
\)O:}C
8v=?pt
in*wl:kj
&3@[NTT4
"D4!H
$%3YX%t
yDo.{Q
bWW(V,
yQg<:N
a)4Uvl
LP2w<z
2Hb W
rc}AxT~@
dUb"[u
lx[,=~
\ZC7-*x1k
{~r^h{
@H]X4,
5B)`U7
=ETjUfH
(Y3Py!
*$9.lp
S{p'RQ
ht\eU~
w_@!E}?
.Z!whK
&4!$2`O
>3m9U]U/N
]?ww^=0x
w|rJS|
^zHrYSCk
#Rjqjt
RM*FC{
QHge<2
A#B"}
*BM<t
RE=dvcc
GR7t5i
/:"OE0
d6W=S?
YuB@,*
j1o<+2q
JN!k.t
k~+`OCJ
a.4.4
+jVyBps
&RDMp82
O~bI[
rrfaur
{^z2z?~
e)=x#RNY
Wuq%-
]ENh_M
QjMyz<
mYOt~
PR_>B
v=><66
j1*j62
PlnHxH
5&I?3d
VL~3.40
[)h+=J
sXRUrl
&^k2xw
#(7[W
zK~(y.J
Pl\R2rS
i7)J0
CS!'#K~
kW}I4*
6.AB]ax
E5 K|A
K7->>|7{
Z#?o-3
Ch4;D
w7qVyA
@'#9<=
_Y]"V,
H@>|V5>BB_
|iI_JK
8+TpT3~>
MWeM=|
tTI]'Ks
3U:`H~
Nc%%f>i
QSystem.Drawing, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a
System.Drawing.Bitmap
;"64$6
92AM)?
T4G9&7
$>+>/#93(<
,,<%(7'"7</E
;"64$6
92AM)?
T4G9&7
$>+>/#93(<
O&;>#70!6;0D
QSystem.Drawing, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a
System.Drawing.Bitmap
, #&')*)
-0-(0%()(
((((((((((((((((((((((((((((((((((((((((((((((((((
_N?@|k
Ni}uiy
M?YzFA
5K]S27
&M!#Ks
fFM}"
z^;twI/
*1ETO~
"4]4jZ`s%-
KZiWK+v
5@ 0P!46
"$%#12AF&
6<0Hg<2Hc\
H\iO1&(
|~x;\7
"V-iub
$7_I!'
QV=U`5i
jg$;sO
zu~0;_{9
>P;\7G
f;NVl,"
%!KDuQLN
]m@9t[W
)aRA?.
?@;\7G
NBKq`m
*k2XWf,
8F@;\-
sjn'3?n
C1cpWu
`vk[]w
AP 1!0@
1P0@!
Qaq2B`
"2AQaq
03BRrs
NFO6r+
I*uXdR
e%N@-O
H'm0)Q
}[)i1"
j.J`V`
)K\'HdyT
T,cV2/H
3%zQoS
;O.t/uma
*3)I3v!
qE[x5zr[
:A4#bP
(;iDg<
Q|kD3+?u<*
/y!id:
Sn0E^i
|hZ\i~9
KiaX$]'_
WWm\[h*
KvumUtxb
^nNf (W
uEIexU
Ooertz
?:ky82i
"u'YX`
O@pcP\
;fPuHx
/#d1F!L
~MQz6vX
R[5g$H
H# 3cy
4v3B`'*%
0%PguG*
xC?~q[
l$2'Xj
eh]Eu$
<*1uk4
][,gu-
)))))))))))))))))))))))))))))))))))))))))))))))))));
9K@H5WD
X +A^8M
{jzUxL\p
1R^}F
+s0FdAD
/ZfWB%
sqxUy1p
8u)f[w
%=beSx
jnb^Tg
h d73
IBpV8
uv%F}``Y
dj[)jV%
bNH7.PD
9:K+X"c>
k`[<Lkt^r
y5}&]=Z
]eClp8#
m./_ucO
m1]PPB
_AV[=g
2I-7>q<
#|$@uejj
9txA^i
yJ7UMOB
2D&tp~
e Gb|"
.~e[w^
!A~%[^
x:T \
)Ip"Tv
9)btCU
QV#qC*
Q.v_(R
!1AQaq
NWEg,f
TPTDKE
f$SO9&c
!1AQaq
!~!&lJ
sIUto~
2R-6S9
%hA1I"
A86al;
3P@mE^r
f9wj{NH
sI57*xC
YE}G"(
2~cmlA
X:GZ\w
dVL;:9
D8M]4{@2
7T/.5
F.(Q!
^Xrcx*
F(SvbWp
elUte7H
hG1"M&
"8N*Pb
tJmVc2
hhY7SGK
M/U=ha
j`d,s)
/J@^>)a
^0fc0r
C*fRMY
@P4-[DD
Q{\I6)
`CA@!J(
Xk1S9I~h
n`'3B1Z
Z(NSGz
QSystem.Drawing, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a
System.Drawing.Bitmap
%&'()*456789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz
&'()*56789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz
QSystem.Drawing, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a
System.Drawing.Bitmap
%&'()*456789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz
&'()*56789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz
nnW.HZ
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
fSystem.Drawing.Icon, System.Drawing, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3aBj
QSystem.Drawing, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a
System.Drawing.Icon
IconData
IconSize
System.Drawing.Size
System.Drawing.Size
height
lw|VT\uH
TVTTTwTtWW
uEGGE\UWTP
EEEEDEEp
UTUEEETW
UeEEeEp
wfVF~\tTwgFEW
\TTW|wH
ue\UEp
U#?;::
}nm{{hhs
LLLIIBEJ
LIIEBAA
IGEGAA::N
HB$::;:1<
A!:::/
PA::1///
+++++8
R+++++++++*+-277-6,
73+++*+*+*
9-+-+***
6-*+**
66,,,,,,Q
M/yn$',B}
YV7'-
S~P@Cr
XZ~F:oQ?
REDom;|wy
>;mccbu
sba))"f
t))\\!`
i\\\\\[f
je]]\[[
iggg]ghi
F??[]32D
WB?<;7A
*XG99E
,PL" '%O
Cs.[((\
Z{u,Zb
0&u 1&QA2
HqRde4
h cn`P9
z%&Jjzn;_
dc06eX
bFv[KM
RAvN"n
>Xu=fAo
y5pwL{
s?7}B*
'LP]F
;HkA?2
c6K0B{
'H0p&@
=*w@wW
C\[/TO
n'dC)"
fJrH}Wg#
8P\@n{
BWk#(
<0~e)W
EhkkCSS
y}-8zq
hhh@SS
qX'.p
8l_C=X
}^CCC[
+G&53p
;'16VPg
'8xW#2g
!0gN'O
cCH!pw
-HMXY
hij@KK
HJ$Uhu[r$+
j [U1UP0
5MAw|5
7&^H~.nf:
79KK)PR
/B5j0L
Z\vU_=!
%v-ZBm
Tt6jhllt
}]DI-
lQ@(*!
[u~?_~
+V@UUPJ
DBX/mEww7"
8!0MN
Wgff_:u
ibhhT+
"(LkHo
C#/c}j
n444`jj
-;w^'I
4M466"
a`ddL?y
W'XK~shh`
cttxf~~
SJaPjj
rqrFrqr
rqr rqr
rqr rqr
&]$!Ft-*p
oyndNG/+",
7- &nR5>
s:'rt;'"|E-,v?*d
CqZ2xuL
HMhO#+{
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
fSystem.Drawing.Icon, System.Drawing, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3aBj
QSystem.Drawing, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a
System.Drawing.Icon
IconData
IconSize
System.Drawing.Size
System.Drawing.Size
height
7o_O??r
.w`[Qu
GHnPm7L
|:z[yS
,xa5=RC
{{uwwK
bOj" /cf
v`4P[[k;%@
EP,"UH
MJ>fT8"
o).A[#
'NX>+[k
GU}K1
#GLz+i)pl
nRXfff
PO-fL4b
8=X]]mk
.f eL0
dCidS=
+. E=cZym
2=]_Uv
v!B\c9
(6jfnFX
C<SYYY
h([=|I
A ': 9J
#?GNr!
!iii?
_CorExeMain
mscoree.dll
7o_O??r
.w`[Qu
GHnPm7L
|:z[yS
,xa5=RC
{{uwwK
bOj" /cf
v`4P[[k;%@
EP,"UH
MJ>fT8"
o).A[#
'NX>+[k
GU}K1
#GLz+i)pl
nRXfff
PO-fL4b
8=X]]mk
.f eL0
dCidS=
+. E=cZym
2=]_Uv
v!B\c9
(6jfnFX
C<SYYY
h([=|I
A ': 9J
#?GNr!
!iii?
ABDiSE.Properties.Resources
mright
WallTop
bw_DoWork switch type error
bw cancelled!
bw Error:
bw completed!
Simulate
Steps
Lng :
Antivirus Signature
Bkav W32.AIDetectNet.01
Lionic Clean
Elastic malicious (high confidence)
MicroWorld-eScan Clean
ClamAV Clean
FireEye Generic.mg.3374b87be5da25a0
CAT-QuickHeal Clean
ALYac Clean
Cylance Clean
Zillya Clean
Sangfor Clean
K7AntiVirus Clean
BitDefender Clean
K7GW Clean
CrowdStrike win/malicious_confidence_90% (W)
Baidu Clean
VirIT Clean
Cyren W32/MSIL_Kryptik.IMX.gen!Eldorado
Symantec Scr.Malcode!gdn34
tehtris Generic.Malware
ESET-NOD32 a variant of MSIL/Kryptik.AHJA
APEX Malicious
Paloalto Clean
Cynet Malicious (score: 100)
Kaspersky UDS:Trojan-Spy.MSIL.Noon.gen
Alibaba Trojan:MSIL/Kryptik.82e1b854
NANO-Antivirus Clean
ViRobot Clean
Rising Trojan.Kryptik!8.8 (CLOUD)
Ad-Aware Clean
Emsisoft Clean
Comodo Clean
F-Secure Clean
DrWeb Trojan.Siggen19.18804
VIPRE Clean
TrendMicro Clean
McAfee-GW-Edition BehavesLike.Win32.Generic.bc
Trapmine suspicious.low.ml.score
CMC Clean
Sophos Clean
Ikarus Clean
GData Clean
Jiangmin Clean
Webroot Clean
Avira Clean
MAX Clean
Antiy-AVL Clean
Kingsoft Win32.Troj.Generic_a.a.(kcloud)
Gridinsoft Clean
Arcabit Clean
SUPERAntiSpyware Clean
ZoneAlarm UDS:Trojan-Spy.MSIL.Noon.gen
Microsoft Trojan:MSIL/RemLoader!MTB
Google Detected
AhnLab-V3 Clean
Acronis Clean
McAfee Artemis!3374B87BE5DA
TACHYON Clean
VBA32 Clean
Malwarebytes Clean
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Tencent Clean
Yandex Clean
SentinelOne Static AI - Malicious PE
MaxSecure Trojan.Malware.300983.susgen
Fortinet MSIL/Kryptik.AHDG!tr
BitDefenderTheta Clean
AVG Win32:PWSX-gen [Trj]
Cybereason Clean
Avast Win32:PWSX-gen [Trj]
No IRMA results available.