Static | ZeroBOX

PE Compile Time

2023-04-21 02:17:45

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x0002f169 0x0002f200 6.89570876714
.rsrc 0x00032000 0x0000051e 0x00000600 3.9316289328
.reloc 0x00034000 0x0000000c 0x00000200 0.101910425663

Resources

Name Offset Size Language Sub-language File type
RT_VERSION 0x0003205c 0x0000029c LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_MANIFEST 0x00032334 0x000001ea LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with CRLF line terminators

Imports

Library mscoree.dll:
0x402000 _CorExeMain

!This program cannot be run in DOS mode.
`.rsrc
@.reloc
-*+F+G
+G3+J+K~)
+I,5+Ku
+F+K+M{
_b`}
+0+5+:+;
+W+X{g
Y_bYT
+2+7+8+=+B+C
+9z+={g
-=&+=-
+-+2+7+8+9
+2+7+<+=-
T+6+7~]
XJ4X(
XJPX(
XJTX(
:XF-5
,XJ,B
 XJ(XT
XJ(X(
+%+&+'+(t
+/+4,"
-V+V{i
+Oz+S
+9+:+;{g
,.+-,*
-$+C+Ht
*+F+G(
+#_d}c
+++,+-{
,%&&&&&
+D+I+J+O+T
++$~)
+ +%+&++
+D+E+F
T+!+C+DJ+D+I+J02
XJY_bXT
XJY_cXT
 XJY_bYT
(XJT+H
 XJ`h
Y_bXT
4XJ`h
4XJ_bXT
__bT
4XJ`h
4XJ_bXT
4XJY_bX
+c+d*+h{
+W+\
-U&+U+Z+_+`+h8m
XJY_bXT
XJY_bX
+H+M+U+Y-
+S+X+]+^-
(XJXT
,c+y8z
+9+:+?+@+A
+,+1~)
+(+-+2+7+8,
+,+1~)
+(+-+2+7+8,
,9+<+=
-A&+Ax+@
,"+B~)
+9+>+C+D+I+J+K+L-#
-.&&+1{
+G3%+J+K~)
,XJoB
0XJoB
XLXi(o
4XJY(
8XJoB
<XJoB
 XLo.
T+,+F+GJ+G{
+*+++,+-,
+@+A+F,
+8+9+:
_b`}c
,"+({w
+$+)+.+3
,/&+/+0+1t
+.+3~)
+*+/}+
__d}c
-<&+<{\
+7+8{\
+5+:+;
_b`}c
0%,J2
91A(4
+*+++,+-
+ +%+&
XJ_b
XJ_b
+0+5+:+?+D+Er
+N+S+[8\
T+0+\+]J
-.&+.+/+0th
-.&+.+/+0th
+A+B+G
-++N+O+P+U+V
,M&&&*
XJd%,
JdY3O
-.&+.+/+0tc
-.&+.+/+0tc
-.&+.+/+0t
-.&+.+/+0t
Z+H+M{1
+I+N+O"
,/+.+/}0
,#+(+)}1
+"+#+$+%
+0,$+/{+
+"+#+$
+6+l~:
+X,N+Z{5
PA+S{8
pA+N{9
Z+I+N+O"
,/+.+/}8
,#+(+)}9
+"+#+$+%
  sr
+!+"+#
Z+$+)+.
,/+.+/}D
,#+(+)}E
+"+#+$+%
,&&+*{B
+ +%+&(
+!+"+'+(
zC+.{K
(B+){L
Z+$+)+.
,/+.+/}K
,#+(+)}L
+"+#+$+%
+0,$+/{H
+"+#+$
-.&+.+/+0t
+0+1|T
-.&+.+/+0t
+0+1|T
-.&+.+/+0th
+0+1|U
-.&+.+/+0th
+0+1|U
+/+0+5+6+7+8+={
++ +!+&+'u
++ +!+&+'u
,q&+t{
*ACDEFG
Qkkbal
v4.0.30319
#Strings
/;Yu|
: [ k ~
!*!Q!]!h!
#*#A#r#
$0$T$]$o$
mro.exe
<Module>
mscorlib
Object
System
MulticastDelegate
ValueType
Attribute
GetString
SmartAssembly.Delegates
MemberRefsProxy
SmartAssembly.HouseOfCards
Strings
MemoryStream
System.IO
EventArgs
SmartStackFrame
SmartAssembly.SmartExceptionsCore
ISerializable
System.Runtime.Serialization
System.Windows.Forms
Control
UploadReportLoginService
System.Web.Services
SoapHttpClientProtocol
System.Web.Services.Protocols
ReportingService
IDisposable
PoweredByAttribute
SmartAssembly.Attributes
value__
WebClient
System.Net
Dictionary`2
System.Collections.Generic
Assembly
System.Reflection
Version
ModuleHandle
IWebProxy
Exception
System.Xml
XmlWriter
List`1
EventHandler
SecurityException
System.Security
MethodID
Objects
ILOffset
ExceptionStackDepth
System.Drawing
Bitmap
PictureBox
ToolTip
Thread
System.Threading
CheckBox
Button
IContainer
System.ComponentModel
TextBox
.cctor
ParameterInfo
object
method
Invoke
nhffskdgsfkdfffdddadfrfffdfdhffscfdf
hkgfffgsddfffdhhddrfdahfddsshcf
chfdgffdfkffdafsfhddhdshdghf
BeginInvoke
IAsyncResult
AsyncCallback
callback
EndInvoke
result
hfsdkffddgfgfhseffdfafffdchd
fghhfgsfffrffddfffdfffddshfdasdfh
cffhddfffdfadfdfrsfsshdkfffgh
hjfdfffhgfadsffgdfdcrdffffskhj
ffghrgfdffdfffdfdfffkhsjd
fsfdfdffffddshdffgfefdfkfghj
sddddfffhfedfgddjffgffffgjfsfkdgsacsafp
sgfhjffkffffgdhjsrfhddfhfffaddsfsfssfcfgdb
ddfdjffffsffhgdffafcfdssfkfhgj
ffchkfffgdafhffdsfrdsfsfj
jffgadffcffdgfgffsdehfsgkffj
jcfsafdgddhffrfdfdsdgkfff
fdfcfffhrfffdgfdfdfgsfssffj
jffafffgfffdrfdffhfcsdsgkffj
jcfdhfdffsffgfdsadfsdgkffff
gdddffdsdhffssfdgh
fhfsdsdsfsffhfddfhhs
hsfffffd
fffffsh
shsdasfffasd
sdfffsffsfh
sdhfffffssf
sfsadfdsfgfs
afffdsffdshs
gsfsfdsd
gssfdfadss
gfsfhadfsfs
gffadffsdg
gasdfdffshsg
gdsdaffag
hsdffddafs
adsfsdfdds
jdddfssf
ggfffsssdfh
jfsdsaffdffhg
jffdffdffsgfdgs
jsfsffdfdf
jdfffaf
gdfddsfdfdj
kfdssfdsgfh
fssffffdfg
sjffsffaf
fdffssfsfs
sfffffdssd
jdfffaffssk
wssffssdv
gsffffssds
gffssfffddsx
startupInfo
jddAIjbS
jdfhfdfffdfssdkfj
hdffdffhffassdkfsh
hdffhdfasdfdfkdf
affdsdfhhfhh
sdffdsdshffdhf
hffdsffdfsfshdhs
hhhgfdffffdfsfh
fsfdfsfhfffdhs
fddfffss
ffhdfff
hfhfdsdffsf
jhffsdfdfdh
ICryptoTransform
System.Security.Cryptography
MoveFileEx
kernel32
ThreadStart
Graphics
GetSystemMetrics
user32.dll
SelectObject
gdi32.dll
ExtractIconEx
shell32
DrawText
user32
ResolveEventArgs
GetSystemInfo
kernel32.dll
GetVersionEx
kernel32.Dll
assemblyFullName
CreateMemberRefsDelegates
typeID
CreateGetStringDelegate
ownerType
codeLengths
pending
minCodes
maxLength
buffer
reportSender
encryptedData
services
notificationEmailSettings
emailAddress
appFriendlyName
buildFriendlyNumber
userId
currentException
FieldInfo
fileName
assemblyID
firstLevel
fatalException
sender
exception
featureName
securityException
canContinue
securityMessage
errorMessage
reportId
GetObjectData
SerializationInfo
StreamingContext
context
methodID
objects
ilOffset
exceptionStackDepth
PaintEventArgs
ThreadExceptionEventArgs
UnhandledExceptionEventArgs
GetServerURL
licenseID
GetWebRequest
WebRequest
serverUrl
UploadReport2
Rectangle
rectangle
xmlWriter
unhandledExceptionHandler
reportExceptionEventArgs
CancelEventArgs
securityExceptionEventArgs
SendingReportFeedback
FatalException
DebuggerLaunched
fsffgfgfafad
IsWebApplication
AppName
MajorVersion
AppNameMinusVersion
SubkeyApplication
WowSubkeyApplication
AvailableBits
AvailableBytes
IsNeedingInput
TotalOut
IsFinished
BitCount
IsFlushed
BuildFriendlyNumber
AppFriendlyName
EmailAddress
IsEmpty
FirstLevel
CanDebug
CanSendReport
ShowContinueCheckbox
CanContinue
TryToContinue
SecurityMessage
ReportException
Failed
ErrorMessage
ReportID
IconState
Handler
VersionInfo
IsServerR2
IsWorkstation
ServicePack
OnFontChanged
OnResize
OnTextChanged
get_Text
set_Text
ScaleCore
OnPaint
Dispose
OnVisibleChanged
OnClosing
RuntimeCompatibilityAttribute
System.Runtime.CompilerServices
CompilationRelaxationsAttribute
AssemblyFileVersionAttribute
SuppressIldasmAttribute
CompilerGeneratedAttribute
AttributeUsageAttribute
AttributeTargets
DesignerCategoryAttribute
WebServiceBindingAttribute
SecurityCriticalAttribute
SoapDocumentMethodAttribute
XmlElementAttribute
System.Xml.Serialization
ObsoleteAttribute
BrowsableAttribute
DesignerSerializationVisibilityAttribute
DesignerSerializationVisibility
{06a5ddfe-f2de-40e0-aa53-34167a665dd2}
{1f4c35b0-8509-4dd0-8acb-8619ed446a4e}
Application
get_ExecutablePath
AssemblyBuilder
System.Reflection.Emit
DefineDynamicModule
ModuleBuilder
DefineType
TypeBuilder
TypeAttributes
GetTypeFromHandle
RuntimeTypeHandle
GetMethod
MethodInfo
MethodBase
GetParameters
Func`2
System.Core
Enumerable
System.Linq
Select
IEnumerable`1
ToArray
get_ReturnType
DefinePInvokeMethod
MethodBuilder
MethodAttributes
CallingConventions
CallingConvention
System.Runtime.InteropServices
CharSet
GetMethodImplementationFlags
MethodImplAttributes
SetImplementationFlags
CreateType
Delegate
CreateDelegate
AppDomain
get_CurrentDomain
AssemblyName
DefineDynamicAssembly
AssemblyBuilderAccess
get_ParameterType
GetType
get_Message
String
op_Equality
get_InnerException
GetExecutingAssembly
RSACryptoServiceProvider
AsymmetricAlgorithm
FromXmlString
SymmetricAlgorithm
GenerateKey
GenerateIV
get_Key
Buffer
BlockCopy
get_IV
Encrypt
Stream
WriteByte
Convert
ToByte
CreateEncryptor
CryptoStream
CryptoStreamMode
FlushFinalBlock
RijndaelManaged
Concat
StartsWith
CryptographicException
InvalidOperationException
CreateDecryptor
Boolean
set_Enabled
Refresh
Exists
Delete
IntPtr
FromHandle
Replace
Registry
Microsoft.Win32
LocalMachine
RegistryKey
GetValue
OpenSubKey
ToString
UInt32
UInt64
UInt16
ToInt64
UIntPtr
ToUInt64
Environment
GetFolderPath
SpecialFolder
GetEntryAssembly
get_Location
GetDirectoryName
op_Inequality
Directory
CreateDirectory
DirectoryInfo
ReleaseHdc
GetHdc
ToHfont
set_ShowInTaskbar
ShowDialog
DialogResult
EnableVisualStyles
Format
MessageBox
MessageBoxButtons
MessageBoxIcon
Process
System.Diagnostics
set_StartInfo
ProcessStartInfo
set_CreateNoWindow
ReadByte
WriteAttributeString
get_StackTrace
IndexOf
Substring
SuspendLayout
get_Controls
ControlCollection
set_Location
set_Name
set_Size
set_TabIndex
set_Anchor
AnchorStyles
ButtonBase
set_FlatStyle
FlatStyle
set_Visible
add_Click
add_CheckedChanged
FontStyle
GraphicsUnit
set_Font
FromArgb
set_BackColor
set_Dock
DockStyle
get_White
set_ForeColor
set_TabStop
set_UseMnemonic
add_TextChanged
Cursors
get_Hand
Cursor
set_Cursor
set_AutoScaleBaseSize
SystemColors
get_Window
set_ClientSize
set_ControlBox
set_FormBorderStyle
FormBorderStyle
set_StartPosition
FormStartPosition
set_TopMost
ResumeLayout
PerformLayout
ToInt32
SetValue
CreateSubKey
Marshal
SizeOf
ToUInt32
IsNullOrEmpty
BitConverter
get_Size
op_Explicit
ToInt16
GetBytes
Console
WriteLine
Combine
GetTempFileName
ThreadAbortException
ResourceManager
System.Resources
GetObject
EndsWith
MD5CryptoServiceProvider
Encoding
System.Text
get_UTF8
HashAlgorithm
ComputeHash
TripleDESCryptoServiceProvider
set_Key
set_Mode
CipherMode
set_Padding
PaddingMode
TransformFinalBlock
FromBase64String
UnhandledExceptionEventHandler
ThreadExceptionEventHandler
add_UnhandledException
add_ThreadException
GetName
GetPublicKey
OpenWrite
FileStream
get_ASCII
set_UseShellExecute
set_RedirectStandardOutput
FileSystemInfo
get_FullName
IsDefined
SeekOrigin
get_Length
RuntimeHelpers
InitializeArray
RuntimeFieldHandle
ToBase64String
get_Chars
Monitor
ContainsKey
get_Item
GetManifestResourceStream
GetTempPath
LoadFile
set_Item
get_Name
FileLoadException
BadImageFormatException
ApplicationException
HttpWebClientProtocol
set_Proxy
get_Count
ToUpper
FormatException
get_Position
GetCallingAssembly
set_MaximizeBox
set_MinimizeBox
set_Height
DESCryptoServiceProvider
StackTrace
get_FrameCount
GetFrame
StackFrame
MemberInfo
get_MetadataToken
GetILOffset
get_Data
IDictionary
System.Collections
Contains
LinkedList`1
AddLast
LinkedListNode`1
get_Width
get_Font
CreateGraphics
set_Method
GetResponse
WebResponse
Create
set_Timeout
IPGlobalProperties
System.Net.NetworkInformation
GetIPGlobalProperties
get_DomainName
GetHostName
GetAssemblies
SoapException
ServerFaultCode
XmlQualifiedName
DateTime
get_Year
get_Month
get_Day
get_Hour
get_Minute
get_Second
set_Position
get_Now
ArgumentOutOfRangeException
MeasureString
Ceiling
get_Height
get_Assembly
ResolveEventHandler
add_AssemblyResolve
EnumerateDirectories
SortedList
GetKeyList
IEnumerable
GetEnumerator
IEnumerator
get_Current
MoveNext
GetCurrentProcess
get_MainModule
ProcessModule
get_ModuleName
ToLower
StringBuilder
Append
ResolveTypeHandle
ResolveMethodHandle
RuntimeMethodHandle
GetMethodFromHandle
get_IsStatic
get_FieldType
DynamicMethod
GetILGenerator
ILGenerator
OpCodes
Ldarg_0
OpCode
Ldarg_1
Ldarg_2
Ldarg_3
Ldarg_S
Tailcall
Callvirt
GetFields
BindingFlags
GetModules
Module
get_ModuleHandle
get_Module
GetMethods
Ldc_I4
add_ResourceResolve
GetManifestResourceNames
GetFrames
get_Major
Intern
TryGetValue
Interlocked
CompareExchange
Remove
get_HasElementType
GetElementType
get_IsByRef
get_IsPointer
get_IsArray
GetArrayRank
get_IsPrimitive
get_IsValueType
get_IsEnum
ReferenceEquals
get_ManifestModule
get_ModuleVersionId
get_Namespace
LastIndexOf
WriteStartDocument
NewGuid
get_CodeBase
get_Keys
KeyCollection
Enumerator
get_Version
WriteElementString
get_OSVersion
OperatingSystem
get_Platform
PlatformID
Reverse
ICollection
GetField
WriteEndDocument
UTF8Encoding
XmlTextWriter
GetCustomAttributes
get_Rank
GetLength
get_IsLiteral
get_IsInitOnly
get_BaseType
FileInfo
GetFileName
FileMode
FileAccess
FileShare
AddValue
GetInt32
SetBounds
get_Graphics
DrawImage
Component
get_DesignMode
set_Interval
add_Tick
SetStyle
ControlStyles
get_ClientSize
DrawLine
SystemPens
get_ControlLightLight
DrawIcon
get_Right
get_Bottom
get_ControlDark
set_Image
set_SizeMode
PictureBoxSizeMode
AddRange
SetToolTip
get_Visible
SetClip
Activator
CreateInstance
GetTypes
get_Exception
get_ExceptionObject
get_IsTerminating
GetProperty
PropertyInfo
GetGetMethod
set_ExitCode
ToBoolean
WebClientProtocol
set_Url
HttpWebRequest
ServicePoint
set_Expect100Continue
get_ServicePoint
get_Left
get_Top
WriteStartElement
WriteEndElement
get_FontHeight
get_CanFocus
BringToFront
ArrangedElementCollection
System.Windows.Forms.Layout
get_Checked
get_IsAlive
get_CurrentThread
get_ApartmentState
ApartmentState
FileDialog
set_Title
CommonDialog
IWin32Window
get_FileName
SaveFileDialog
set_DefaultExt
set_Filter
set_Icon
System.Security.Permissions.SecurityPermissionAttribute, mscorlib, Version=2.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089
UnmanagedCode
WrapNonExceptionThrows
6.9.0.114
"Powered by SmartAssembly 6.9.0.114
LoginServiceSoapT
Namespace;http://www.smartassembly.com/webservices/UploadReportLogin/`
ReportingServiceSoapT
Namespace3http://www.smartassembly.com/webservices/Reporting/L
Ghttp://www.smartassembly.com/webservices/UploadReportLogin/GetServerURL
DataType
base64BinaryE
@http://www.smartassembly.com/webservices/Reporting/UploadReport2
qUse ShowContinueCheckbox instead, as this is now also false when the builder has chosen not to show the checkbox.
8K"_R{
\VE]jio
)*kF~_kB
YlDl!Q=
bqS!.5
3|0{+#
^|~,_B(Az>
mQLu4?
baK.{!
}rze;W
/|rt?i
?ve1g0:-\
y;oUTr
@_.va5
aJ<*-.W
(O/F.
snh67p
pg&su1
2~DxdvN
pDU;Jp
zN1m}+
.RH l1|T}M
RI@@cm8
X4gJi=uI
=]qu~i
aK0O(G
8$uKrpN.
2x9qmOv
5+p~cq
FYM4^od
+NgjA
~:@2~7[
.:Hy|v
DkG#*
gN[CV?
qSOF'0
^(NR0G
k-S0av
rIEMQ+'
'YzW6}
\A2DHtFME
l%DSGp3dJ
c@A8V3
!p)xD:
&_zY8 w#:
z]pzU8
Hj}4Ad<
L$y,P5
m]}`{M
{Ji9kAO
Upa0$a>,uW
"aG]$.&
tYiieSq
`~GQB',
IL2'A{
:"jq1<Ha
B4iJs;
B%:5>7
}|>/gh
4pOr9<
hv|F2r
6T2x[B
fuh<-(
U*zpO*S
JE2^;e
dr`HIu
Mpm;bMk
] s%EUL"
,X;$06
9-.qv(
_fj,lQQ
G1DeWj.J
RbO#uYJ
K<sFnb
a6HT{ct8
pP!wwM
c/G;Z;
[nMOZ:
pdt"|D p
iIz/[%X
Nu?a%n
Plvgb'
~(16$n.
[XZ0\e
jQ$8_4p
C74 Rh
+qOoH_
_J0A-^8
1M~(1F>
y\!6dX%
I.HX#n2htGz
/0pV5aF
iQ7gOcm
RQ=t:O
T_Mg~p[
jwp4aI(
,F8ZZ EA~
O!,(2vR
n^cdmT;
/{sBhd9Q
WqqGx]
?/hXnX
%$ElN
w2pR7cQ
%~-VXv
,eDlldEM3Qjc5VGdZeWlTTk9ERmRHemYyWlJtVytxU0U=
bXJv,eDlldEM3Qjc5VGd6WlpOZG5iMU1zRGYyWlJtVytxU0U=
RHluYW1pY0RsbEludm9rZVR5cGU=
dUNUcjVWK3FkdFk9 YkliZFM2cm53dzk0ekdqMGR1Y0xNZz09,aW1rTnJJWmE3V3g0dzN5ZG9Rd3I1U292TkdPaitzYWc=,dlRKcExVUXpUVlhXVkEzMjN0UUFKamYyWlJtVytxU0U=,cEtJZ1Y5NnpOUUZ0Z3NvYnlTb1BjdEdXUVlCeENNSDg= RTVtdGllTTVRR0Z3MzVLNXdURDVaUT09,NnQzbDZ3S05FWkxCTkVaZnVIeHoxMzQ4ZC9lZGxxWko=,TmwvRW9qQVlTaUY0dzN5ZG9Rd3I1U292TkdPaitzYWc=,RDF6Mmh3VXVzY2pXVkEzMjN0UUFKamYyWlJtVytxU0U= TUYzREQ5eVgvcUpzbXp3ZG80TFg1UT09 ZnFiQjNqbitwNXg0ekdqMGR1Y0xNZz09,V25veGdhWkd0Z1U4MHgvSW5YVW85V3NjSUhZRkc3RXY=
e3JlcG9ydH0=
DPFJTQUtleVZhbHVlPjxNb2R1bHVzPnRxemJEcTJ1QjFWR2ErcjQwTmNmVFJBVncwT203UzRFTTRoS25jTDVwZ0NLd25KNTJodDBTUDFLM3hUSHgxaTBtL2JGYTAydVlKQTJ4ZEJhZTVjMk9MSVVVWVJkbEcyMkdkU1ZUdjQzcit0V3pZYmtWaFArVkZWT2t4WUpMTWV3MDJ6N3VjOXhKZXQ0d09aZFp2RXdMUHV3WEJCa01VZWN5M2NZZitmeVBqRT08L01vZHVsdXM+PEV4cG9uZW50PkFRQUI8L0V4cG9uZW50PjwvUlNBS2V5VmFsdWU+0ZDk4YzFkZDQtMDA4Zi0wNGIyLWU5ODAtMDk5OGVjZjg0Mjdl
ew==\RVJSIDIwMDY6IFRoaXMgdGVtcGxhdGUgd2FzIG5vdCBwcm9wZXJseSBwcm9jZXNzZWQgYnkgU21hcnRBc3NlbWJseQ==
RVJSIDIwMDU6IFRoZSAxMjgtYml0IGVuY3J5cHRpb24gaXMgbm90IGF2YWlsYWJsZSBvbiB0aGlzIGNvbXB1dGVyLiBZb3UgbmVlZCB0byBpbnN0YWxsIHRoZSBIaWdoIEVuY3J5cHRpb24gUGFjayBpbiBvcmRlciB0byB1c2UgdGhlIHJlcG9ydGluZyBmZWF0dXJlLg==
RVJSIDIwMDQ6IA==
JUFwcE5hbWUl
JUNvbXBhbnlOYW1lJQ==
W1Vua25vd24gY29tcGFueV0=
XHN2Y2hvc3Q=
c3ZjaG9zdA==
bWtkaXIgIg==
c3ZjaG9zdCI=hWitieDE2Skw1MUQyUmZGanh2ZXp3MDFWYk1OREV0WFNWMzRtUFRlYlFOUm5ES1dWcjV2MGlTeFJWWDJpc1doMGs1d0pQTEdwY1drPQ== c3ZjaG9zdFxzdmNob3N0LmV4ZSciIC9m
L0N2Myt3d24reWc9
c3ZjaG9zdFxzdmNob3N0LmV4ZSI=
PezB9IGNhbm5vdCBpbml0aWFsaXplIGl0c2VsZiBiZWNhdXNlIHNvbWUgcGVybWlzc2lvbnMgYXJlIG5vdCBncmFudGVkLgoKWW91IHByb2JhYmx5IHRyeSB0byBsYXVuY2ggezB9IGluIGEgcGFydGlhbC10cnVzdCBzaXR1YXRpb24uIEl0J3MgdXN1YWxseSB0aGUgY2FzZSB3aGVuIHRoZSBhcHBsaWNhdGlvbiBpcyBob3N0ZWQgb24gYSBuZXR3b3JrIHNoYXJlLgoKWW91IG5lZWQgdG8gcnVuIHswfSBpbiBmdWxsLXRydXN0LCBvciBhdCBsZWFzdCBncmFudCBpdCB0aGUgVW5tYW5hZ2VkQ29kZSBzZWN1cml0eSBwZXJtaXNzaW9uLgoKVG8gZ3JhbnQgdGhpcyBhcHBsaWNhdGlvbiB0aGUgcmVxdWlyZWQgcGVybWlzc2lvbiwgY29udGFjdCB5b3VyIHN5c3RlbSBhZG1pbmlzdHJhdG9yLCBvciB1c2UgdGhlIE1pY3Jvc29mdCAuTkVUIEZyYW1ld29yayBDb25maWd1cmF0aW9uIHRvb2wu
ezB9IEZhdGFsIEVycm9y
c2RmYWZk
L2NzYWZzZiA=
RXhjZXB0aW9u
TWVzc2FnZQ==
RXhjZXB0aW9uU3RhY2tUcmFjZQ==
TWV0aG9k
cGFuZWxJbmZvcm1hdGlvbg==
ZGVidWc=
RGVidWc=
Y29udGludWVDaGVja0JveA==<SWdub3JlIHRoaXMgZXJyb3IgYW5kIGF0dGVtcHQgdG8gJmNvbnRpbnVlLg==
TWljcm9zb2Z0IFNhbnMgU2VyaWY=
cGxlYXNlVGVsbFRpdGxl<UGxlYXNlIHRlbGwgJUNvbXBhbnlOYW1lJSBhYm91dCB0aGlzIHByb2JsZW0u
ZG9udFNlbmRSZXBvcnQ=
JkRvbid0IFNlbmQ=
c2VuZFJlcG9ydA==
JlNlbmQgRXJyb3IgUmVwb3J0
cGxlYXNlVGVsbE1lc3NhZ2U=
VG8gaGVscCBpbXByb3ZlIHRoZSBzb2Z0d2FyZSB5b3UgdXNlLCAlQ29tcGFueU5hbWUlIGlzIGludGVyZXN0ZWQgaW4gbGVhcm5pbmcgbW9yZSBhYm91dCB0aGlzIGVycm9yLiBXZSBoYXZlIGNyZWF0ZWQgYSByZXBvcnQgYWJvdXQgdGhlIGVycm9yIGZvciB5b3UgdG8gc2VuZCB0byB1cy4=
aGVhZGVyQ29udHJvbDE=`JUFwcE5hbWUlIGhhcyBlbmNvdW50ZXJlZCBhIHByb2JsZW0uCldlIGFyZSBzb3JyeSBmb3IgdGhlIGluY29udmVuaWVuY2Uu
ZXJyb3JNZXNzYWdl
c2F2ZUFzRmlsZQ==
U2F2ZSBhcyAmRmlsZQ==
cGFuZWxTZW5kaW5n
Y2FuY2VsU2VuZGluZw==
JkNhbmNlbA==
cmV0cnlTZW5kaW5n
JlJldHJ5
d2FpdFNlbmRpbmdSZXBvcnQ=
aGVhZGVyQ29udHJvbDI=xUGxlYXNlIHdhaXQgd2hpbGUgJUFwcE5hbWUlIGlzIHNlbmRpbmcgdGhlIHJlcG9ydCB0byAlQ29tcGFueU5hbWUlIHRocm91Z2ggdGhlIEludGVybmV0Lg==
cHJlcGFyaW5nRmVlZGJhY2s=$UHJlcGFyaW5nIHRoZSBlcnJvciByZXBvcnQu
Y29ubmVjdGluZ0ZlZWRiYWNr
Q29ubmVjdGluZyB0byBzZXJ2ZXIu
dHJhbnNmZXJpbmdGZWVkYmFjaw==
VHJhbnNmZXJyaW5nIHJlcG9ydC4=
Y29tcGxldGVkRmVlZGJhY2s=4RXJyb3IgcmVwb3J0aW5nIGNvbXBsZXRlZC4gVGhhbmsgeW91Lg==
cGFuZWxFbWFpbA==
bGFiZWxFbWFpbA==
JkVtYWlsIGFkZHJlc3M6
c2VuZEFub255bW91c2x58SSBwcmVmZXIgdG8gc2VuZCB0aGlzIHJlcG9ydCAmYW5vbnltb3VzbHku
ZW1haWw=
aGVhZGVyQ29udHJvbDM=\RG8geW91IHdhbnQgdG8gYmUgY29udGFjdGVkIGJ5ICVDb21wYW55TmFtZSUgcmVnYXJkaW5nIHRoaXMgcHJvYmxlbT8=
bGFiZWwz
SWYgeW91IHdhbnQgdG8gYmUgY29udGFjdGVkIGJ5ICVDb21wYW55TmFtZSUgcmVnYXJkaW5nIHRoaXMgZXJyb3IsIHBsZWFzZSBwcm92aWRlIHlvdXIgZS1tYWlsIGFkZHJlc3MuIFRoaXMgaW5mb3JtYXRpb24gd2lsbCBub3QgYmUgdXNlZCBmb3IgYW55IG90aGVyIHB1cnBvc2Uu
Y29udGludWVTZW5kUmVwb3J0
cG93ZXJlZEJ5
cG93ZXJlZEJ5MQ==
c2F2ZVJlcG9ydA==
JlNhdmUgUmVwb3J0 RXhjZXB0aW9uUmVwb3J0aW5nRm9ybQ==(U09GVFdBUkVcUmVkR2F0ZVxTbWFydEFzc2VtYmx5
U21hcnRBc3NlbWJseS5leGU=
L0FkZEV4Y2VwdGlvblJlcG9ydCAi
IjxSU0FLZXlWYWx1ZT4=
PC9SU0FLZXlWYWx1ZT4iHKioqIEluZm9ybWF0aW9uIG5vdCByZXBvcnRlZCBmb3Igc2VjdXJpdHkgcmVhc29ucyAqKio=
ZGVmYXVsdA==4ezUyMzM0NzhELTlCQUMtNEI5Qi1CMTkxLTlEQjk1NzI1MjcxNX0=
bXlkaXI= RnVsbE5hbWUgb2YgZGlyZWN0b3J5Og==
SXQgaXMgZGVmaW5lZA==
SXQgaXMgbm90IGRlZmluZWQ=,RGF0YSB3cml0dGVuIGludG8gbWVtb3J5IHN0cmVhbTo=(Q2Fubm90IGNvbm5lY3QgdG8gd2Vic2VydmljZQ==
ZGl0dG8=
RVJSIDIwMDE6IA==
UGF0aA==
cXVpdEJ1dHRvbg==
JlF1aXQ=
Y29udGludWVCdXR0b24=
JkNvbnRpbnVllJUFwcE5hbWUlIGF0dGVtcHRlZCB0byBwZXJmb3JtIGFuIG9wZXJhdGlvbiBub3QgYWxsb3dlZCBieSB0aGUgc2VjdXJpdHkgcG9saWN5Lg==
U2VjdXJpdHlFeGNlcHRpb25Gb3Jt
ZXJyb3I=
U21hcnRTdGFja0ZyYW1lcw==<U21hcnRBc3NlbWJseS5TbWFydEV4Y2VwdGlvbnNDb3JlLlJlc291cmNlcy4=
LnBuZw==
Lmljbw==
SEVBRA==
Y3VycmVudA==
RVJSIDIwMDI6IA==
ZGFkYWg=
ZGRkZGRkZGRkZA==
SW5kaWE=
QW1lcmljYQ==
QXVzdHJlbGlh
QWZyaWNh
Q2FuYWRh
S2V5cyBhcmU6
U21hcnRBc3NlbWJseQ==
Ni45LjAuMTE0
U29mdHdhcmVcUmVkIEdhdGVc(U29mdHdhcmVcV293NjQzMk5vZGVcUmVkIEdhdGVc
VU5JQ09ERQ==
QVNDSUk=
RmllbGQ=
T2JqZWN0
U3RhdGlj
QnlSZWY=
UG9pbnRlcg==
UmFuaw==
TnVsbA==
U3lzdGVtLlN0cmluZw==
ICgweA==
VmFsdWU=
TmFtZUlE
TmFtZQ==<U21hcnRBc3NlbWJseS5BdHRyaWJ1dGVzLlBvd2VyZWRCeUF0dHJpYnV0ZQ==
VHlwZURlZklE
QXNzZW1ibHk=
bXNjb3JsaWI=
VHlwZU5hbWU= VW5oYW5kbGVkRXhjZXB0aW9uUmVwb3J0
QXNzZW1ibHlJRA==
RGF0ZVRpbWU=
VXNlcklE
UmVwb3J0SUQ=
QXNzZW1ibGllcw==
Q29kZUJhc2U=
VGhpcw==
Q3VzdG9tUHJvcGVydGllcw==
Q3VzdG9tUHJvcGVydHk=
QXR0YWNoZWRGaWxlcw==
QXR0YWNoZWRGaWxl
RmlsZU5hbWU=
TGVuZ3Ro
RXJyb3I=
RGF0YQ==
U3lzdGVtSW5mb3JtYXRpb24=
TkVUVmVyc2lvbg==
T1NWZXJzaW9u
T1NQbGF0Zm9ybUlE
U2VydmljZVBhY2s=
U2VydmVyUjI=
V29ya3N0YXRpb24=
U3RhY2tUcmFjZQ==
UmVtb3ZlZEZyYW1lcw==
VG90YWxGcmFtZXNDb3VudA==
TWV0aG9kSUQ=
SUxPZmZzZXQ=
RXhjZXB0aW9uU3RhY2tEZXB0aA==
T2JqZWN0cw==
U3RhY2tGcmFtZQ==
VHlwZU5hbWVz
Q291bnQ=
QXNzZW1ibHlJRHM=
RnVsbE5hbWU=
T2JqZWN0RGVm$RG9Ob3RDYXB0dXJlRmllbGRzQXR0cmlidXRl
RG9Ob3RDYXB0dXJlQXR0cmlidXRl
SUVudW1lcmFibGU=
TW9yZQ==
X19iYXNl RVJSIDIwMDY6IHswfSBAIDB4ezE6eDR9
ZGRkdGVzdA==0djAuMC4wLjAgZnJvbSA0LzIwLzIwMjMgNToxNzo0NCBQTQ==$VW5oYW5kbGVkRXhjZXB0aW9uLk1ldGhvZElE$VW5oYW5kbGVkRXhjZXB0aW9uLklMT2Zmc2V04VW5oYW5kbGVkRXhjZXB0aW9uLkV4Y2VwdGlvblN0YWNrRGVwdGg=,VW5oYW5kbGVkRXhjZXB0aW9uLk9iamVjdHMuTGVuZ3Ro,VW5oYW5kbGVkRXhjZXB0aW9uLk9iamVjdHNbezB9XQ==
IC0g,Q291bGQgbm90IGRlc2VyaWFsaXplIHRoZSBvYmVjdA==
ZXJyb3IxNg==
d2FybmluZzE2
aHR0cDovL3d3dy5yZWQtZ2F0ZS5jb20vcHJvZHVjdHMvZG90bmV0LWRldmVsb3BtZW50L3NtYXJ0YXNzZW1ibHkvP3V0bV9zb3VyY2U9c21hcnRhc3NlbWJseXVpJnV0bV9tZWRpdW09c3VwcG9ydGxpbmsmdXRtX2NvbnRlbnQ9YWVyZGlhbG9nYm94JnV0bV9jYW1wYWlnbj1zbWFydGFzc2VtYmx5
UG93ZXJlZCBieQ==
e2xvZ299 UG93ZXJlZCBieSBTbWFydEFzc2VtYmx5
ZGF0YQ==
bmV0d29yaw==
VW5oYW5kbGVkRXhjZXB0aW9u,U21hcnRBc3NlbWJseS5TbWFydEV4Y2VwdGlvbnNDb3Jl
UHJldmlvdXNFeGNlcHRpb24=
MzFiZjM4NTZhZDM2NGUzNQ== UHJlc2VudGF0aW9uRnJhbWV3b3JrLA==$U3lzdGVtLldpbmRvd3MuQXBwbGljYXRpb24=
Q3VycmVudA==
U2h1dGRvd24=
RmFsc2U= VXBsb2FkUmVwb3J0TG9naW4uYXNteA==
R2V0U2VydmVyVVJM
UmVwb3J0aW5nLmFzbXg=
VXBsb2FkUmVwb3J0Mg==,aHR0cDovL3Nhd2Vic2VydmljZS5yZWQtZ2F0ZS5jb20v
RW1haWw=
c2FlbmNyeXB0ZWRyZXBvcnQ=XU21hcnRBc3NlbWJseSBFeGNlcHRpb24gUmVwb3J0fCouc2FlbmNyeXB0ZWRyZXBvcnR8QWxsIGZpbGVzfCouKg== U2F2ZSBhbiBFeGNlcHRpb24gUmVwb3J0HUGxlYXNlIHNlbmQgdGhlIEV4Y2VwdGlvbiBSZXBvcnQgdG8gezB9IFN1cHBvcnQgVGVhbS4=$RmFpbGVkIHRvIHNhdmUgdGhlIHJlcG9ydC4=
U2VjdXJpdHkgRXhjZXB0aW9u
,JUFwcE5hbWUlIGF0dGVtcHRlZCB0byBwZXJmb3JtIGFuIG9wZXJhdGlvbiBub3QgYWxsb3dlZCBieSB0aGUgc2VjdXJpdHkgcG9saWN5LiBUbyBncmFudCB0aGlzIGFwcGxpY2F0aW9uIHRoZSByZXF1aXJlZCBwZXJtaXNzaW9uLCBjb250YWN0IHlvdXIgc3lzdGVtIGFkbWluaXN0cmF0b3IsIG9yIHVzZSB0aGUgTWljcm9zb2Z0IC5ORVQgRnJhbWV3b3JrIENvbmZpZ3VyYXRpb24gdG9vbC4KCg==
SWYgeW91IGNsaWNrIENvbnRpbnVlLCB0aGUgYXBwbGljYXRpb24gd2lsbCBpZ25vcmUgdGhpcyBlcnJvciBhbmQgYXR0ZW1wdCB0byBjb250aW51ZS4gSWYgeW91IGNsaWNrIFF1aXQsIHRoZSBhcHBsaWNhdGlvbiB3aWxsIGNsb3NlIGltbWVkaWF0ZWx5LgoK
QW5vbnltb3VzSUQ=A
_CorExeMain
mscoree.dll
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<assemblyIdentity version="1.0.0.0" name="MyApplication.app"/>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v2">
<security>
<requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3">
<requestedExecutionLevel level="asInvoker" uiAccess="false"/>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
abcdefghijklmnopqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVWXYZ0123456789
i"p&q'u*y+
'&*)65BACADAEAFAGAHAIHJAKALANMOMPMQMRMSMZY[Y\Y^]_]`]zy{y|y
e2IzNmU2YTNjLWUxMjYtNGFhZC04OTZjLTFlNDhhYTA3ODE0N30sIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49M2U1NjM1MDY5M2Y3MzU1ZQ==,[z]{06a5ddfe-f2de-40e0-aa53-34167a665dd2},e2IzNmU2YTNjLWUxMjYtNGFhZC04OTZjLTFlNDhhYTA3ODE0N30=,[z]{06a5ddfe-f2de-40e0-aa53-34167a665dd2}
{0}{1}\
Wrong Header Signature
Unknown Header
{data}
ERR 2003:
w3wp.exe
aspnet_wp.exe
, Version=
, Culture=
neutral
, PublicKeyToken=
Version=
Culture=
PublicKeyToken=
{b36e6a3c-e126-4aad-896c-1e48aa078147}, PublicKeyToken=3e56350693f7355e
{1f4c35b0-8509-4dd0-8acb-8619ed446a4e}
https://subf.domfadffafiffn.comd/objecsts.json?api_key=123
{"objeact":{"ffffdfndaf":"Naddfme"}}
https:/f/susb.doffmfaffdin.com/obadjdects.json?api_key=123
{"obfject":{"nfffaffme":"dNaafme"}}
https:/f/sub.dofmfffain.com/objecadts.json?api_key=123
{"obfject":{"nffafcme":"Naafme"}}
{71461f04-2faa-4bb9-a0dd-28a79101b599}
{100fd8cd-4fe2-410e-8c33-ae1af08ef31d}
{be78a0c5-c47c-4127-a428-52bdc580a02f}
{bf13b64c-b3d2-4165-b3f5-7f852d4744cf}
{07572d6f-5375-47d5-8a8c-b5f0cbe5bad0}
{6d3806d4-1193-4601-a7df-2249c7f0014b}
{d316c294-ed40-4778-8b7b-29800a2dcbc3}
{a9035fc5-7ed1-4e0c-8962-dfcb1d508afc}
{73fbfb9b-41e7-4744-bf74-74b7c6c117c1}
SmartAssembly.exe
SmartStackFrames
The 128-bit encryption is not available on this computer. You need to install the High Encryption Pack in order to use the reporting feature.
Cannot connect to webservice
*** Information not reported for security reasons ***
Powered by SmartAssembly
http://www.red-gate.com/products/dotnet-development/smartassembly/?utm_source=smartassemblyui&utm_medium=supportlink&utm_content=aerdialogbox&utm_campaign=smartassembly
{1fe9e38e-05cc-46a3-ae48-6cda8fb62056}
{395edd3b-130e-4160-bb08-6931086cea46}
SOFTWARE\RedGate\SmartAssembly
VS_VERSION_INFO
StringFileInfo
040904b0
Comments
Windows Application 3
CompanyName
FileVersion
1, 0, 0, 0
FileDescription
Windows Application 3
LegalCopyright
Copyright 2023
ProductName
Windows Application 3
ProductVersion
1, 0, 0, 0
VarFileInfo
Translation
Antivirus Signature
Bkav W32.AIDetectNet.01
Lionic Worm.Win32.LovGate.o!c
Elastic malicious (high confidence)
DrWeb Clean
MicroWorld-eScan Trojan.GenericKD.66531274
FireEye Generic.mg.ebec1eabb4b5a57b
CAT-QuickHeal Clean
ALYac Trojan.GenericKD.66531274
Cylance unsafe
VIPRE Trojan.GenericKD.66531274
Sangfor Suspicious.Win32.Save.a
K7AntiVirus Clean
BitDefender Trojan.GenericKD.66531274
K7GW Clean
CrowdStrike win/malicious_confidence_100% (W)
Arcabit Trojan.Generic.D3F72FCA
BitDefenderTheta Gen:NN.ZemsilF.36164.lm0@a4ASeZpi
VirIT Trojan.Win32.MSIL_Heur.A
Cyren Clean
Symantec ML.Attribute.HighConfidence
tehtris Clean
ESET-NOD32 a variant of MSIL/Kryptik.AHUA
APEX Malicious
Paloalto generic.ml
ClamAV Clean
Kaspersky HEUR:Email-Worm.MSIL.LovGate.gen
Alibaba Worm:MSIL/LovGate.2892f249
NANO-Antivirus Clean
ViRobot Clean
Rising Malware.Obfus/MSIL@AI.100 (RDM.MSIL2:qsFtoUE85/OG3J5PRxuuaw)
Sophos Mal/Generic-S
F-Secure Trojan.TR/Kryptik.ftqtv
Baidu Clean
Zillya Clean
TrendMicro TrojanSpy.Win32.REDLINE.YXDDUZ
McAfee-GW-Edition Artemis!Virus
Trapmine malicious.high.ml.score
CMC Clean
Emsisoft Trojan.GenericKD.66531274 (B)
Ikarus Clean
Jiangmin Clean
Webroot W32.Injector.Gen
Google Clean
Avira TR/Kryptik.ftqtv
MAX malware (ai score=87)
Antiy-AVL Trojan/MSIL.Kryptik
Gridinsoft Clean
Xcitium Clean
Microsoft Trojan:MSIL/Clipper.AB!MTB
SUPERAntiSpyware Clean
ZoneAlarm HEUR:Email-Worm.MSIL.LovGate.gen
GData Win32.Trojan-Stealer.Clipper.FHS4VW
Cynet Malicious (score: 100)
AhnLab-V3 Trojan/Win.Leonem.C5415827
Acronis Clean
McAfee Artemis!EBEC1EABB4B5
TACHYON Clean
DeepInstinct MALICIOUS
VBA32 Clean
Malwarebytes Trojan.Crypt.MSIL
Panda Clean
Zoner Clean
TrendMicro-HouseCall TrojanSpy.Win32.REDLINE.YXDDUZ
Tencent Msil.Worm-Email.Lovgate.Ekjl
Yandex Clean
SentinelOne Static AI - Malicious PE
MaxSecure Clean
Fortinet MSIL/Kryptik.AHUA!tr
AVG Win32:PWSX-gen [Trj]
Avast Win32:PWSX-gen [Trj]
No IRMA results available.