Static | ZeroBOX

PE Compile Time

2023-05-19 15:12:11

PDB Path

BVGHOp.pdb

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x00036bd0 0x00036c00 7.62090585861
.rsrc 0x0003a000 0x00000598 0x00000600 4.07430630708

Resources

Name Offset Size Language Sub-language File type
RT_VERSION 0x0003a0a0 0x0000030c LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_MANIFEST 0x0003a3ac 0x000001ea LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with CRLF line terminators

!This program cannot be run in DOS mode.
`.rsrc
(nHhY~
(^N0~
Z?_d
_b`*
UUUU_
UUUU_
UUUU_
(&9LB~;
v4.0.30319
#Strings
BVGHOp
ComVisibleAttribute
System.Runtime.InteropServices
mscorlib
System
Boolean
AssemblyTrademarkAttribute
System.Reflection
String
AssemblyCopyrightAttribute
GuidAttribute
TargetFrameworkAttribute
System.Runtime.Versioning
AssemblyFileVersionAttribute
AssemblyProductAttribute
DebuggableAttribute
System.Diagnostics
DebuggingModes
RuntimeCompatibilityAttribute
System.Runtime.CompilerServices
CompilationRelaxationsAttribute
AssemblyTitleAttribute
AssemblyCompanyAttribute
AssemblyConfigurationAttribute
AssemblyDescriptionAttribute
SuppressIldasmAttribute
47117e29-331f-4900-9164-9cf93ee5ed6f
BVGHOp.exe
<Module>
csyRo64YLJTejy39sM
yRebUeoh2bdHkpPrAp
Object
Ladpi7TCPPfDTbAH4c
k8vV51XMKojZEV5X8X
Attribute
aOIpfLMtNJKVy98ZOG
L55UGxuCxB5pGwntsx
T6KCKRaBm5Y5gotsKL
jxWgLA5n7rlKiksV53
danFIlGKnZohsIstol
wVvbqYyUckN23mryfJ
OoNq7pYf6wKTxePyvt
EEhPjQ6I3FHVQIUipf
sJFC9ldAaCQkE0BPVk
sNUNeUv45JeKrATNRF
WbI19x1ZoPC8fyHj2d
vBAKZ7VAd3pxxRAfip
gSM2C48QpZA8dvGfYO
if5VOq2pcbHmQnQ6No
<Module>{DADCBF8F-CE19-4754-BC9B-01CA7752BD9A}
peiCFBEylZ0mUtGrnP
LkTUcoAc3LGgJI8mNI
O7NEFjkFBmitUEbvnR
MulticastDelegate
wh0mIVqOGy0VTmTqqV
FIQ7gsZbu9O22wvTGE
qP5gJF3UntsKemf74p
l6qXvcBSfg6l7vPqGJ
HQp6FaHvneVsoglf5P`1
eUe8ihWUCECjjyvOcr
ak0uMeRF0fID89airx
jeKnUnm9giMdhrq1Dm
LMXZCZ9FvonbojVDsj
ValueType
nMRWsJclcYj2u7Ck1D
ALa3Fqg0cTfFMFKtXQ
ab8cAMFkToW5hf7r8G
q7BqrTNtFnVQfYN7Io
tegI9dS7AJD08UDIRE
sEyFwhCptKuAbelDBP
tR8OQiLAbHFo3jeO7A
iWvH5EflfMgyNuM81c
VZmFhdrZrx16VkSdXO
tg7H76PgG8p7h9LU1Y
tCNHwGQDTKi44jmvCj
m0R7pvUWifhBA1uZR9
gjei340JPnbKcPL72t
bLhCt4KGvKi2nq2kDr
<PrivateImplementationDetails>{5AD2323F-0A19-4B8E-819D-7AD314238A25}
__StaticArrayInitTypeSize=256
__StaticArrayInitTypeSize=40
__StaticArrayInitTypeSize=30
__StaticArrayInitTypeSize=32
__StaticArrayInitTypeSize=16
__StaticArrayInitTypeSize=64
__StaticArrayInitTypeSize=18
uj3kLAh1DBUJtxBvRf
al0gMMUpsGSRQ71PKb
RfkAuNwCJy3UlUk1RK
mBv71HxthnTlPLmM8C
Bv0UdCCBN5xjyin9M4
nuJ4JRG13R5X0Gky6h
tY4j99S30Tkeu0Mt1u
l7QQsKcj2G7845LV5c
qPjuYVgPQw3oK5aWNs
AEKs204md9h3ZtS1DX
bWDll7HJIEpIhV2YWC
nKQj8fbCYZ2J9lrmwp
BbtrbA6KIcj43AvpVD
zQotPj2vC5iBet5rkb
vieKsNk5rQprAyUw87
hjCeFlNhCs4PQR9LKn
OrNZ5brav3SsxRr7xx
Saf7O6oe74P0uDc2qS
OlBe6A1n7F6NaWy2Tn
MU3DuLQiX9KQK1QZVC
mcEj6v5R5xSXDngWZt
lnI5gcFqyrwhx8CAqC
XN6LpR7HY3ufisiVvK
llenWw0f5p8qnMQD70
ONb2Dwl7i7O5IJQOO6
D29H9cuNCmNJkbF0gP
gxEvf2TOCobIAjBGup
bZnTshYGdGAEhCiKJA
TkqxbHtveubTF2GhLI2
dxLWKathuscjiqLb4TM
eurgMitjf6uYCJcCSkB
veK2MdtxMc7k5sgTGQc
yAr2FLtCm0ZkmMBInMY
XXMm2itG5tHT124GnES
cGk9QEtSxMEuk0UHDnP
Hi402xtcTG0VSH98KGo
kXxyrktg4V2FgjBYDbg
p4bIpUtD9P73GnluWKQ
nk6MVntI7DFJVGoPBsg
NujUeGt9lYu6bRGjpAO
TKLkh0tPaafKMUo7wFr
gUPx0rtnnBEkXLe6a6W
C1wMTktk8oCQD1HD815
csy4Ro6YL
Assembly
wTeojy39s
.cctor
mMK5ojZEV
gX8GX4OIp
HLtyNJKVy
Stream
System.IO
eWRTebUeh
pbdXHkpPr
rpQMadpi7
Single
FPPufDTbA
Double
w4cad8vV5
LGx6CxB5p
hwndtsxx6
A8ZYOGU55
tohEsIsto
YHVAvbqYU
BkNk23mry
GJKqoNq7p
MemoryStream
H6wZKTxeP
ivt3SEhPj
NCKvRBm5Y
ggo1tsKLY
TWgVLAn7r
YKi8ksV53
dan2FIlKn
UInt16
DESCryptoServiceProvider
System.Security.Cryptography
ICryptoTransform
DeflateStream
System.IO.Compression
CompressionMode
LI3BFHVQI
AlAJaCQkE
MipHfqJFC
NBPWVkqNU
IATmNRFsb
DeUR45JeK
P199xZoPC
Module
dGWEtMccjdEY2
typemdt
FieldInfo
MethodInfo
IntPtr
Invoke
BeginInvoke
IAsyncResult
AsyncCallback
callback
object
EndInvoke
result
uje4EO7AyW
n6V4ZkSdXO
Dictionary`2
System.Collections.Generic
tg743H76gG
op74Bh9LU1
Pkt4JIioX4
OS74WEhgVP
zvC4cjv0R7
V344NJPnbK
BPL4S72t4L
UCt4C4GvKi
gTa4fKyvJR
FlL4DK6v1V
xYc40cvTYe
gWD4RMZcml
tmF4qhdZrx
RSACryptoServiceProvider
JvW4gifhBA
SortedList
System.Collections
ssc4rMyNN9
ctd4I0BeGJ
xjY4UFS4he
Hashtable
ro34QLSmjG
x0G4PdEkhW
muZ4FR9aje
hDT49Ki44j
iNu4kM81c7
kTB4nHgqkA
Xhp4VtKuAb
acZ4ttrak9
pnq4L2kDrg
SQi42AbHFo
UInt32
wUP4pvWOeg
jDn4HLUUpf
iYC4jRSLdE
mH54AElfMg
AJi4mqCNHw
RlD48BPqR8
HDP4K3FXls
lYt4ebPsrD
GetTypeFromHandle
RuntimeTypeHandle
get_Assembly
RuntimeHelpers
InitializeArray
RuntimeFieldHandle
set_UseMachineKeyStore
dq2EtMcsDULun
ofycHj2dB
UInt64
BitConverter
GetBytes
vAKgZ7Ad3
JxxFRAfip
gSMN2C4Qp
uA8SdvGfY
SGfC5VOqp
BbHLmQnQ6
EoEfeiCFB
SymmetricAlgorithm
AesCryptoServiceProvider
System.Core
RijndaelManaged
Activator
CreateInstance
ObjectHandle
System.Runtime.Remoting
Unwrap
ilZr0mUtG
CryptoConfig
get_AllowOnlyFipsAlgorithms
InPPQkTUc
MD5CryptoServiceProvider
HashAlgorithm
ComputeHash
bc3pLGgJI
omNDIn7NE
TransformBlock
CjFQBmitU
BinaryReader
get_BaseStream
set_Position
ReadUInt32
qbvUnRJh0
ParameterInfo
DynamicMethod
System.Reflection.Emit
ILGenerator
Monitor
System.Threading
GetManifestResourceStream
get_Length
ReadBytes
GetFields
BindingFlags
MemberInfo
get_MetadataToken
get_Item
get_Module
GetGenericArguments
ResolveMethod
MethodBase
get_IsStatic
get_FieldType
Delegate
CreateDelegate
SetValue
GetParameters
get_DeclaringType
get_IsValueType
MakeByRefType
get_ParameterType
get_ReturnType
GetILGenerator
OpCode
OpCodes
Ldarg_0
Ldarg_1
Ldarg_2
Ldarg_3
Ldarg_S
Tailcall
Callvirt
Exception
cmTKqqVCI
p2wnvTGEA
I5gIJFUnt
CryptoStream
CryptoStreamMode
WKetmf74p
Convert
FromBase64String
Encoding
System.Text
get_Unicode
GetString
l6qeXvcSf
B6lO7vPqG
wfQxp6Fav
Marshal
GetMethod
PeVhsoglf
get_Location
Exists
GetName
AssemblyName
get_CodeBase
ToString
Replace
GetType
GetProperty
PropertyInfo
GetValue
gPB74AkHw
LoadLibrary
kernel32
BeoiO7hUh
GetProcAddress
O4nsMUe8i
Concat
GetDelegateForFunctionPointer
UUCwECjjy
lOclrbk0u
eeFz0fID8
Aai4brxyeK
PUn449giMd
umLocehuEC
op_Equality
Trq4o1DmUM
FileStream
FileMode
FileAccess
FileShare
IDisposable
Dispose
dZC4TZFvon
aoj4XVDsjV
ToArray
eRW4MsJlcY
set_Key
set_IV
CreateDecryptor
O2u4u7Ck1D
ALa4a3Fq0c
dfF45MFKtX
Lbb4G8cAMk
doW4y5hf7r
oGE4Y7BqrT
RFn46VQfYN
VIo4dZegI9
k7A4vJD08U
KIR41EqEyF
T5KPD3HVwoaxoCUBYO
DlkP9dthfs5Fnm2B0P
FNA0GJP0KxwEEPWdWf
ISsoQJXRUYiXvnibd0
J5sN7NpVV0aLVIXOVP
QvdrJqwhAGbhCdF4SW
gTXMVXZp9IF7y8INLE
Reverse
iXoEd21OvZ00mjcweG
larx6IG3OCFEybd2yk
GetPublicKeyToken
zYkNk4mZi2qGW41s6r
UxevMr43n0aNF4fYeF
CipherMode
set_Mode
TMTWMIJX89KyOgbfqF
ugOWbESkRZBtfU5Qic
BK7lPXC7L6mu58mBoq
BuJRLbnQgO6FgWeioF
FlushFinalBlock
Wa3seUO5Gqjhjr4tk5
AyubA1VW1mSUYPm0dD
QD5G7tQewS4nx31i01
ToInt32
yLl9mK0niwpi1eWtbE
EhDiZDrUQd2DdHx0FA
EkB5uwTgPRHGqKJuCm
eWttvPxDiZ0NHZ0uHt
fi4xrIdpo9olsmCmoK
v4AkHwJgeoO7hUhn4n
Eb14Oo6jDL
CreateEncryptor
ToBase64String
classthis
nativeEntry
nativeSizeOfCode
DJ94xf5uda
zhk4h9kn33
xVv4lGM1S6
KDikMXewCI
oHX470LZsM
rrR4iVI2so
v5G4sA3ZLa
ReadInt32
TWS4wtRdek
hModule
lpName
lpType
lpAddress
dwSize
flAllocationType
flProtect
hProcess
lpBaseAddress
buffer
lpNumberOfBytesWritten
flNewProtect
lpflOldProtect
dwDesiredAccess
bInheritHandle
dwProcessId
value__
e1I4zLJQH3
cXKEtMczMfumU
wIZoXMWctP
vOBoMi1dnQ
p5qouSHKHY
sr0oa3Tmld
n2io4Kulef
OcoooH3HO0
List`1
GetManifestResourceNames
AddRange
IEnumerable`1
Ur4oTqYWl4
ResolveEventArgs
get_Name
AppDomain
get_CurrentDomain
ResolveEventHandler
add_ResourceResolve
kLjw4iIsCLsZtxc4lksN0j
IIu7bapXKPtvk3EgVe
ul56rFT0QlfbQGjXTc
rvo96rivgfEdRIpZpt
o3t1CNk6u3JedVAQ1c
W2e3pBGSLeemQiVMdR
XhtcvuHNYCiq5dHcYT
Dh6kyP42pnyBBioN1V
QErXNqqmrxI9h0YE01
CopyTo
TrBYcPu2dxCgRM4G0N
KZ2go6KvxLwl5jNoKx
nh6BKEyEHsYWN2Ectg
MpQKR2tXSLpPGOllti
OssWs0jDCt15yd9Xa4
nVnNZxCBLwdQR8xxVV
uG0yCnXXYyjOIsjcwT
lJGo5WhaQk
IsLittleEndian
CcqoGOs046
AIKoyUpwHU
yAUoYXW1vq
MA8o6wNB6c
p3iodQ0sYP
vyTovFUknX
a95o1k0vjT
iPyoVEL3O6
cR5o84wDEG
$$method0x6000317-1
$$method0x6000332-1
$$method0x6000332-2
$$method0x6000340-1
$$method0x6000340-2
$$method0x6000353-1
$$method0x6000395-1
$$method0x60005b3-1
PmQL2vG3F
O5GjOuHJ5
haZtyTXUD
neLRdiUbD
sVmyLCb7F
DwrWvTvNV
Bk3pSZCpl
Binder
sp5BvJOWF
Xy7d1XJJZ
sBdsM9mT2
kvBmbRUR7
eXyfuT0D5
bDXDCUYTn
dilIixTmq
vP79CmHNs
WBhPxpchT
Tm6nCyHno
EBMMNALJd
nG0iFaZcj
EFSZKyI1L
yFNEYdmvY
TQHqRayTJ
kFnJLRvDE
yqRawuG9O
NumberStyles
System.Globalization
AYJ35UbFT
LsWKltEtD
iQ68eQtBW
u7NX24OGN
iS8VgnIUx
LubtRI4SUs
DaNtw6hlbb
DpVt4y1sDO
NBYOunnRG
amEe7N1Se
HSRAnKE5y
nAnzLm8x5
xFQtyOhimK
a2yttsTdDy
IQ4tLnci5Y
cGTtUjDSwv
W64tWjUGsK
mlCtpjiRGn
y7ItBwl0HP
TcYtsvevYh
P4HtmxwDZb
KeHtf8xmK7
GJwtHCyqM8
BnEtbPJPZF
Dket6bnnDO
cfkt2v8J5B
NuFtdan7Dm
co8tMd2aiD
InvokeMember
get_UTF8
GetExecutingAssembly
ToInt64
ToSingle
ToDouble
Buffer
BlockCopy
Intern
get_FullName
IndexOf
Substring
get_Chars
ReadByte
set_Capacity
get_InputBlockSize
get_OutputBlockSize
get_Position
TransformFinalBlock
ResolveType
get_ManifestModule
STAThreadAttribute
UnmanagedFunctionPointerAttribute
CallingConvention
CharSet
FlagsAttribute
CompilerGeneratedAttribute
ccsGDKwFAQIoTXT0go.P2ytKZtTPSGSJlOykF
avsokknCKIynv9ZSUE.gUnL0GL5skQ92PKLsi
E2FF3dFvlujaKPXbvt.RSu0yqQHJPbGlDLPYn
Copyright
2023
$aa0ef852-ff25-4bc0-afc3-6328e72939c0
.NETFramework,Version=v4.5.1
FrameworkDisplayName
.NET Framework 4.5.1
1.0.0.0
BVGHOp
WrapNonExceptionThrows
FIQ7gsZbu9O22wvTGE.wh0mIVqOGy0VTmTqqV+l6qXvcBSfg6l7vPqGJ+HQp6FaHvneVsoglf5P`1[[System.Object, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089]][]
SUsSystem.Runtime.InteropServices.CharSet, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089
CharSet
lT0,Hy
qu@>{v
6H'cpZ
oPn63
V).5yd
H'@->n
Y`@@zH
}\saIO
Bm}UN%Z'
5<7$U
%LTZxj
kdUnj
pQ{A"o:L
w59%Lr5
:>5F9f
m!dnud
`mdy/k!
jn~l5*\Q
vIJ;W.
zN,B*p
wD7%=_
=f1xx6_
4=k=&+
eeM9J
;#)|x"(
hZw~XcY
|;9/Ay)
K[$UK8u_`
Vk9reb
Jl-,QMh
qUmWb)
tvqKMG3T
RRE\R,#J
~okup
IneDc_
x:E-]vc
<>Xhb(
:AkA^[=
k)':kW
5=QomU
K?pn@^
3w^r"|%T
W|Av>S
yH"XODc
&rUfm>W
KPw]%j?
0T>TB#mY W
gfX+h]
N*/^a`
OkD"l#
);9it8
0.f4 $
*4*p,+
0H1?L^B`
)$c10-
bt5Oe
rKCk?l
^C>IF]
nV`=kO
FE\?cl?KK`
`3P)&F
wX+CTX,)
<fUIN#O
fg9E2M
%(cB6@
jyI:r {
Gik:So
cuuV/Pt
.Tbi#[
`JS`yR*/G
YM3j},$
C1LL R
EVmQiI
-?3Gk0
[g/z+G
jm.y[!
v5]5^{
1,u&4mB
,LwoKA
7Qtyj^T/w1X
{Hx}EzY
yv_et
&#G3M=
Q6U!zc
c9X0(r
wBO[S1
}Oo&'!
hFn6~y
6uC?R5
+,r{,Q
?S'6}q
uS7/?Ns
xO}\2d
)xR^ 0
F&d#$j`5
~`VL%\B
,`T|i
XX"^j=
F|!S#\)'
|q49k#
NvY=R=
,9VJ(2
Zan*5H
YCVkG#obrD
rW2oWu/
t1w9<q
nBqO%k
SCWY[%
l7)\pf
6?m"+?
C!r#CH
Y@x1rW
ngp%V^
FBi{TR
Y!Q9T6
ri+Tyw
HzR$>
N\X`Rv
zk/0)"y
,^=;k
oDAK$,e4^
v(D,~7
cX|\UT
a,kTKw
U=cWX]
q{UPct1
aoi!vE
&!|,xLT
z,Au#O_F
g52Vpm
'K:CRl
.k?X0h
~l)oh)
{r=HIS
wB|,'Qs
x}D|uBbPU9
!yu&L}T
lyDa_cr
AcwAm2
P)*<1b#|
dj2FQu
*6n<p>a
*H<T{e
M{$48Z
zW!e4P
Q^PwZ&=
/;Xk'Y
V@U=_LM
T*i>T
!>i-fG
|TL~W50
Mx'"!WC
*/(e&>
m#~MwB7
sR<[`3
]"c_*5
{A?gj)
Im:+Zs!
y1<\J
0D56O
k,Ne^W
HFbh9|
y~X*[$
supp_m
SgzD2o
1'gYY^~
'lR/9AIDt
n31_/(
T|}qhBx
'v0Lj+
K)7eX~K
V*.J4ze
'|bMQy
`"yUbG
qlqOpB3
&7 0!r
GiHK^a
U]sO\,N
T-%w0.
,}4xl
[+bFhC
Xu^:5LE
/J6Pc^
.rq=[t
Fo%whb
'%F-.~*Q!
u8-NIX
UYQW5D
fkgu}r]E
~#>i]#Q
>I49+bw
.b5Py/
ey:4uz
l\(F-;
Z`f0VY
_c'=x8]
{b`]Qq[
#}|&m]
O6~LCD
TCto53
@;$}@
1z6Hpb
&f,5>.3
*,X!Y
$1QcwJ
<r>-;)?4
V$IQ/Z
m[`#sve
0N2!s4
n#FE)C
90Cz~
8(_$^Gv
IBkyJa
,U/yT)
ASh<2Y
{>W)1'
X6(qpV
H?OD8-M
NkMiR3
$JM<)PH
VCS(v
ws9yf{
.E/csa8"
Uh;|Z8x
kpvd9S
.dXMvX
y"_"(yrY"
n l15g
\o=~PM
(w)+o9
j{y,^=
4%eg,t
s;Yw/^
7h"m{#
'N@G7/
/uX?8v'o
!;qlC5k
lwn!`W
:X~I9
%_f;1a
J{TL09l
!(vuQ(u
V#YqvGR
L~cky~
)Naypj
^M|Ent
a[K+G3
2F\[pv
+Wh9b=
1|%tCI
>?Y42`)
iJG,v_
cBRGG[
/b11v8
mt#C,
K1o]V/
fD|W*>
s~p,?Z}FA
pKJvqu
A^DW3`b
UY<r-F
}ze]=
[?M1,9_
)If/Le
Dpq^4}
*hfBH6
?_+|R"
tBrANJe
+1zfm@
a.KWSr
bH6Q @UBy
IGo`g/Yk
l!;M{Q
^;YgbI
~z2K{NM9S
DQ- (w+Hd
<fkW|n
+*Rfhn M
BVGHOp.pdb
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<assemblyIdentity version="1.0.0.0" name="MyApplication.app"/>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v2">
<security>
<requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3">
<requestedExecutionLevel level="asInvoker" uiAccess="false"/>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
DigiCert Inc1
www.digicert.com1$0"
DigiCert Assured ID Root CA0
220801000000Z
311109235959Z0b1
DigiCert Inc1
www.digicert.com1!0
DigiCert Trusted Root G40
]J<0"0i3
v=Y]Bv
http://ocsp.digicert.com0C
7http://cacerts.digicert.com/DigiCertAssuredIDRootCA.crt0E
4http://crl3.digicert.com/DigiCertAssuredIDRootCA.crl0
~qj#k"
(f*^[0
DigiCert Inc1
www.digicert.com1!0
DigiCert Trusted Root G40
220323000000Z
370322235959Z0c1
DigiCert, Inc.1;09
2DigiCert Trusted G4 RSA4096 SHA256 TimeStamping CA0
http://ocsp.digicert.com0A
5http://cacerts.digicert.com/DigiCertTrustedRootG4.crt0C
2http://crl3.digicert.com/DigiCertTrustedRootG4.crl0
DigiCert Inc1
www.digicert.com1!0
DigiCert Trusted Root G40
210429000000Z
360428235959Z0i1
DigiCert, Inc.1A0?
8DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA10
[K]taM?
SA|X=G
http://ocsp.digicert.com0A
5http://cacerts.digicert.com/DigiCertTrustedRootG4.crt0C
2http://crl3.digicert.com/DigiCertTrustedRootG4.crl0
jj@0HK4
DigiCert, Inc.1;09
2DigiCert Trusted G4 RSA4096 SHA256 TimeStamping CA0
220921000000Z
331121235959Z0F1
DigiCert1$0"
DigiCert Timestamp 2022 - 20
Ihttp://crl3.digicert.com/DigiCertTrustedG4RSA4096SHA256TimeStampingCA.crl0
http://ocsp.digicert.com0X
Lhttp://cacerts.digicert.com/DigiCertTrustedG4RSA4096SHA256TimeStampingCA.crt0
DigiCert, Inc.1A0?
8DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA10
211213000000Z
250108235959Z0
Baden-W
rttemberg1
Stuttgart1 0
philandro Software GmbH1 0
philandro Software GmbH0
Yd?O_{
Mhttp://crl3.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crl0S
Mhttp://crl4.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crl0>
http://www.digicert.com/CPS0
http://ocsp.digicert.com0\
Phttp://cacerts.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crt0
$Ck&Hm
DigiCert, Inc.1A0?
8DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1
DigiCert, Inc.1;09
2DigiCert Trusted G4 RSA4096 SHA256 TimeStamping CA
230328144258Z0/
8q`je\
DigiCert Inc1
www.digicert.com1!0
DigiCert Trusted Root G40
210429000000Z
360428235959Z0i1
DigiCert, Inc.1A0?
8DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA10
[K]taM?
SA|X=G
http://ocsp.digicert.com0A
5http://cacerts.digicert.com/DigiCertTrustedRootG4.crt0C
2http://crl3.digicert.com/DigiCertTrustedRootG4.crl0
jj@0HK4
DigiCert, Inc.1A0?
8DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA10
211213000000Z
250108235959Z0
Baden-W
rttemberg1
Stuttgart1 0
philandro Software GmbH1 0
philandro Software GmbH0
Yd?O_{
Mhttp://crl3.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crl0S
Mhttp://crl4.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crl0>
http://www.digicert.com/CPS0
http://ocsp.digicert.com0\
Phttp://cacerts.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crt0
$Ck&Hm
DigiCert, Inc.1A0?
8DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1
J7G[*A
K(W{,w
20230328144259Z0
Symantec Corporation10
Symantec Trust Network110/
(Symantec SHA256 TimeStamping Signer - G3
VeriSign, Inc.10
VeriSign Trust Network1:08
1(c) 2008 VeriSign, Inc. - For authorized use only1806
/VeriSign Universal Root Certification Authority0
160112000000Z
310111235959Z0w1
Symantec Corporation10
Symantec Trust Network1(0&
Symantec SHA256 TimeStamping CA0
https://d.symcb.com/cps0%
https://d.symcb.com/rpa0.
http://s.symcd.com06
%http://s.symcb.com/universal-root.crl0
TimeStamp-2048-30
Symantec Corporation10
Symantec Trust Network1(0&
Symantec SHA256 TimeStamping CA0
171223000000Z
290322235959Z0
Symantec Corporation10
Symantec Trust Network110/
(Symantec SHA256 TimeStamping Signer - G30
?'J3Nm
https://d.symcb.com/cps0%
https://d.symcb.com/rpa0@
/http://ts-crl.ws.symantec.com/sha256-tss-ca.crl0
http://ts-ocsp.ws.symantec.com0;
/http://ts-aia.ws.symantec.com/sha256-tss-ca.cer0(
TimeStamp-2048-60
U){9FN
Symantec Corporation10
Symantec Trust Network1(0&
Symantec SHA256 TimeStamping CA
230328144259Z0/
/1(0&0$0"
!#"$"%"&"'"(")"
System.Core, Version=3.5.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089
System.Security.Cryptography.AesCryptoServiceProvider
ccsGDKwFAQIoTXT0go.P2ytKZtTPSGSJlOykF
{11111-22222-10009-11112}
E2FF3dFvlujaKPXbvt.RSu0yqQHJPbGlDLPYn
{11111-22222-50001-00000}
GetDelegateForFunctionPointer
file:///
Location
ResourceA
Virtual
Write
Process
Memory
Protect
Process
Close
Handle
kernel
32.dll
{11111-22222-20001-00001}
{11111-22222-20001-00002}
{11111-22222-30001-00001}
{11111-22222-30001-00002}
{11111-22222-40001-00001}
{11111-22222-40001-00002}
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
Comments
CompanyName
FileDescription
BVGHOp
FileVersion
1.0.0.0
InternalName
BVGHOp.exe
LegalCopyright
Copyright
2023
LegalTrademarks
OriginalFilename
BVGHOp.exe
ProductName
BVGHOp
ProductVersion
1.0.0.0
Assembly Version
1.0.0.0
Antivirus Signature
Bkav Clean
Lionic Trojan.Win32.Crysan.4!c
Elastic malicious (high confidence)
MicroWorld-eScan Trojan.GenericKD.67118505
ClamAV Clean
CMC Clean
CAT-QuickHeal Clean
McAfee Artemis!A5C83C6EBE28
Malwarebytes Trojan.MalPack
VIPRE Clean
Sangfor Trojan.Msil.Agent.Vr8g
K7AntiVirus Clean
BitDefender Trojan.GenericKD.67118505
K7GW Clean
Cybereason malicious.0942fc
BitDefenderTheta Clean
VirIT Clean
Cyren W64/MSIL_Kryptik.IYE.gen!Eldorado
Symantec ML.Attribute.HighConfidence
tehtris Clean
ESET-NOD32 a variant of MSIL/Kryptik.AHQJ
APEX Clean
Paloalto Clean
Cynet Malicious (score: 100)
Kaspersky HEUR:Backdoor.MSIL.Crysan.gen
Alibaba Backdoor:MSIL/Crysan.cad93575
NANO-Antivirus Clean
ViRobot Clean
Rising Malware.Obfus/MSIL@AI.96 (RDM.MSIL2:eUu8yS330r7Lmh4arZoP3Q)
TACHYON Clean
Sophos Mal/Generic-S
Baidu Clean
F-Secure Heuristic.HEUR/AGEN.1325558
DrWeb Clean
Zillya Clean
TrendMicro TrojanSpy.Win64.NEGASTEAL.YXDESZ
McAfee-GW-Edition Artemis!Trojan
Trapmine Clean
FireEye Generic.mg.a5c83c6ebe289f10
Emsisoft Trojan.GenericKD.67118505 (B)
Ikarus Trojan.Inject
GData Trojan.GenericKD.67118505
Jiangmin Clean
Webroot W32.Trojan.Gen
Avira HEUR/AGEN.1325558
Antiy-AVL Clean
Gridinsoft Ransom.Win64.Wacatac.sa
Xcitium Clean
Arcabit Trojan.Generic.D40025A9
SUPERAntiSpyware Clean
ZoneAlarm HEUR:Backdoor.MSIL.Crysan.gen
Microsoft Trojan:MSIL/AgentTesla.SSS!MTB
Google Detected
AhnLab-V3 Trojan/Win.RATX-gen.C5430213
Acronis Clean
VBA32 Clean
ALYac Clean
MAX malware (ai score=85)
DeepInstinct MALICIOUS
Cylance unsafe
Panda Trj/Chgt.AD
Zoner Clean
TrendMicro-HouseCall TrojanSpy.Win64.NEGASTEAL.YXDESZ
Tencent Win32.Trojan.FalseSign.Qsmw
Yandex Trojan.Igent.bZ96Qw.13
SentinelOne Static AI - Suspicious PE
MaxSecure Clean
Fortinet MSIL/Kryptik.AHQJ!tr
AVG Win64:RATX-gen [Trj]
Avast Win64:RATX-gen [Trj]
CrowdStrike win/malicious_confidence_70% (D)
No IRMA results available.