Static | ZeroBOX

PE Compile Time

2023-07-13 01:15:21

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x000d0b58 0x000d0c00 7.98827801584
.rsrc 0x000d4000 0x0000055e 0x00000600 3.92580665975
.reloc 0x000d6000 0x0000000c 0x00000200 0.101910425663

Resources

Name Offset Size Language Sub-language File type
RT_VERSION 0x000d4090 0x000002d4 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_MANIFEST 0x000d4374 0x000001ea LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with CRLF line terminators

Imports

Library mscoree.dll:
0x4d2b50 _CorExeMain

!This program cannot be run in DOS mode.
`.rsrc
@.reloc
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
PADPADPW
LcOD#aI
.'9zJ:
,'6cd@o
c8_$1K
I*J,|l
^S(wDu
!^Me?-
?UelJ
lvU%%[
^$EqWR
lrWOp\8
6XA69W
1juIg5
Jl2f6+
RhKZx
OMv-Bd
eS'"[Q
[`!:qmU
+2/2 L
*"2Boix
-`r1,6
a6qlbl=
q6=B)(^l
p+M38m
f[G.$UF
#3[h&wt
]Da.(%T
@Us%D!
=[FqTtYZ$#
(i^]G&
jDu j}5
,!!0a:w
@[u-Cd
px} Yp)%
<o{cM6
>8S]`S$
2J=LfQ
*'fI&-
inb/~;
`|;F%U/
UR*\[&
#SJIfg
ele75AX
a6QFBs<`U
@&r2q7x w)
iK,qb/
oHW|;>
PRbn{Z
;Ny>Pj
01}D,m
KE~7Sf,
b`%UTtl
ew%d7y
3f~F(b
cOEoAQGj
$"eQQD
is cWZ
iJTVXJ
UwK$YJ
Ta,R8>V
>BA2'f
A:-+5N
8hBn?!
Sj%/[
Z57x#r
e `XfP
^E4xsy
u]}X5|
ej$hU{
$fYTsH~
5o6Bkz
[Vw:v#
.2c%g*
N]q6>%~+
(`M=_G/ZQ
b%;jG4
YRo.py
xSVY5U9
]*JC|AmR
c\7A]A
7zS+)u
#DIoNCq3
UKRB\#
~tvgo<yT
iWMhN"
&{_@{C
n~6`gkx
x?g,eB
0R"$av|0
\3S,yO@
Tl[yz:
mga9S'
25Gw\[9V6
4svpG|
/2o+Os^
ABMWkK
[gEN[U
-u7-wc
H<JT#;A
mNTLDc2w4
DooMfQm
3M1pBE
2{h<8:
dJ.4N
+t~3SO'
#gas7~
\v!%'s
O69+@a
H:}frJb>
Q,b2Q
vjl\Bv
kpM[A&
]<"(Lw
bjSRRe
<C1or.aW
Td-Cd1
h]q.Rb
wdKNa_e
{jIhHt
}e>`X6
+hp=&s
t(C}QH
+o{E>#_
c{Yyqo
`pcci1
[RTTKp
]l2rwS
E5DSwQpq-X
KF'n>m
m2hyX8
*#b$,vE
W[-[]$
Zl0B*5
VkfV/r
U|]s@-v]9d
}H51Hn
@.1xPo
l>_0Q8;
^E(s=BH
bNctk
f,st2j
c0JlM0
ThBki@m
C8Qx>;
2Vfev/
<%':,o
6r'tq ?
8wuC}X
;0F*]e{
.}Z9C8
scaclFGYW
c@STPi
B<fU*]
AQ6M<V
PBC(P!
xz<Rn
QY2n0ZNd>\g
tX!V:i
dsUHX'
M"djhf
UvI>&K
.zS-E%
V`Ij_J5
.R9pzf
_W`t3}V@pA
l}`/[Ir
9Mz6Vb
Xkb}<eS
qz$vI3
>]82`OO
gfd7$2n
XZ:xhv
(n>jQu
#iH1+A
]l{*-|
md#vWW
`>ln1F[O
wv4 $m
c+`L?:'l
Qu/gKMe
UL!95yy
=ByN;eR
zXnA+^
]JQ(XR
'g/o{^Q
!(;WfN
z3>xUzC
us8z^
fI=}r4
.>,e76Oq
WABG$~
c*S-,-
k#V!5!3
nTf0{[
fgceSL
u\ZSie
M:(Z]C
zX*L|C
VPgzdQ
/1AW'
r3<:B9
|UNc}[
M?Nb=7
xqIY^R
4_SK<,
Z17|"HJ
70w6\`
^0M3=z
t|~`&UuG
Nk+g?1
JA?wdn
FMtq@
^]JxQi8
$z_rOV
K40p6
utY#I$
FDB\Pd
E= $7n
!U3z0J
`@yLPo
P}7,DW
Srroo5
b(ED@n
_*N:Kb
Ry GT&UP
fV^G
j]eP/t
.-esHX
0n\lC?
!DbZ.Y
Q}yo0?
+1_JV
)bWXyB
_8WFs3T
s028e +i(
HOh>f`
v,|wfcC
WD.Z\d
hM#Fj3
mBKSs
+D`Ql`
LKn"\U
Hp=_of4
5`uCrM
)g<9O)
|#p)ZP
w^b6Ew
:,S\1!W
g1V0s$j\
'\24eC
X'~1eV
Dyu(69
\1*$3M
_"*0plG>m
$7H<Fs
y"BV8Ru
zMunY&
4XFZ4<
Y+|/#j
Pf+2:$?6
%p;4.e
HZlFLU
G`LZiIBwk
LkEqa-B
8#d9TK
tW{$gb,
<K(P2-
92H;LUf
q::s% ~=E&n
p.r%tV
Eu<CK)
1@Fabt
ub )L@v
zfJgE@
3>g19L
WpBGP|Q#
fAD!49
9yivO2
3{c>:3f\
yHfz/m
:2?czm
:eXL>k+
UN.jY=
v~k1K_
ZH8[0J
-NM2/@
Z }nZq
[gl5-n
f9xkWS
ofN7G]y
H3P4Bl
RS7u*p
O&^B5-k
5G?(5C
rh$pB/
8FPpi=;Z
|S,a"vo
|1'/Ga
CL1qM"
Pp,b"
/{4bV875$cY
,rr_"%5
"~P<h'
OQM75;z
*uUU9-
eHr4dP
a{^;%M
`@^+\,
T4^mXT
LF1gN;
R?C;G=
4]``:,?O|
Ki|hD[
gI=%i;
SoSY`b|E
Y'L[0
ip1%E(a"
k#6#Sh
^^A`w\
@.!:r#/
<c*`aJ~
f[hp#f
Q=8kFxb`
,kN9:j
700w(`
"ZLsCcv
pe;.yi
BF$YPXq
kDxWvor
cUOH*o
cOJ~{<
KZV5Jv
=$:OH2
.aA~f
#b!uM@
i9r"1r
m~&d1]
=/&^$Jm
!&a#x3
z(Wm/eS
bL&L+E
?#!=0\
#'Tp1&
"AD KLx
UP|y}M\*7
!$9nOjk
=.,$j7+
SwSRdK
nK*o?Z
"\F=Aj
$BFBy6
7B<UVG
]j37d=
)UoIMl
HF9k"K#|
o%5zDu^
6Nq)%t
w%,QHB,F
R>&q)vi
!XLg@7
q.S"`f
^`1f$G
|D20yw
JWv9neP3w^
[A}x8v
l8t`.q1
72-'v7AJ
*cg.cPu
\XN_(_
`Lr4TH
k|28;L
{t,`7|
6"p^><
e<&\dK
{5%obU
/o*Y]k1
3qNO{s
bK<5>}
MWu`Wg
pC5 X1
mLXU!}
T<5D.l
#Yw!qe
@vm-#t
J3QDB=
HRmV/s
/8v+=iZ
D{<u'GaXW
f(n]+G
S&&-u)
f&.rTML
@(fU--
@xJQh
NEB\Z
I+yTns
m}ie!m
&<6tY+N
>GXkT}
dLA<Cj5
xA?Y$#
%2'Cd3
+dH}bN
d<F:4ao
[_v(c
NkSFsF2Z|
1kV/)X
m:lTbi
Q};WK4$
5*5/TG
4OZ"lw2
3h-6soS
,4+$"8
_]v(W$
REWy=Pv
@4ZO]F
S6B6'|
\w#\Y^qc
~o^lU1
/Zi9r9
h|cxe7
Jo1,%p
eqqJ)]
wdV2D
r"{C<k
~YiM5W.@
^lNTE}
BCI%H6IA
1%DDx)
=L| Jh
#^+8wv
Q7B-y8
>H:Sze
>4!~x<(
t)N&sG
q3;8E@
wfM11=
#9JFTM
L:zwGy
Qf`RHS
1'Y(uUx
rd8~yOOI
Uh&8nys
jn-HaN
<rt7IX
66^0*a
PXVPhx
v^&'36
y}T"RP
~~ uF}`
R52Qx\
X:.GaJ
Lk[]sT
t+>E6X
VwJ+</
qB7"(X
C&UuB&
onOvm.
rg5!8Yh4
av*VE+
DCGr="
eZ-OA3m
mouK5BUf
;'jl>1.
iHCh>Q
m82].6+=
]Y#@q#
g[J_%(
c2/^rVv
EOM#Ad/
G:{_w)t
5G"4.>
[c9%WC(
:)pY[~
H$Y8GT
7,!-s=
up(yjYYe
)JDw/"
4}JJ@~
4/PMP2?E<
(UC]@ti^"
m4ar|i^
;T`:BR
Ingx2#
]QsCzx
Ap6A``9=
VqvOX5F
Yei$)`
So+'6)1PUc
v%-_z!O
F9 |s<
VGSv;
%I.Fnl(
DE~yv6s
MUR 6}
^&nWG9
=mx!?b
oq/0w&E
<Mw5Vs
cA^w&x"C
De<Bl#5
TYI7jT
V$oYka
5%rz+a
E/Ld%Q>$l
[?w_x|um
0=k1Q^
!aB?]vdE
zW/Y-YEf
{^e%f
/H"|a[I
eNz3La
W|,r5"
dSX 3W
Kj4]nr
& g?m*
F?Dl%<
SZ2qw;
3o0tMd
E')zHfBP
Wz3;5L
8v5L? c=
!T7u@T3WM)<
goAbc?
_HFU}*
CwI[.X
aJ`]g.
HaJ(jM
Pj$_|h
d.@U;g4
;8%s6A
>A"&D6
V2D>:]g=
GC"<IW
Anb7`{
MwwE>}
I9fZ"s
g"SS>-
nbSdn|
N%"RY`
vQ)+&m
\/:7bA
vuE7$s
l/xH`LY
z2#EpAD
$?+bEc
M02R#|
fBV}LX\
|"j-_%
M2JyCv
-"@:T0
%9B {{@
qlz$?]
~ain l
C\Irp
_Ljktz
_.BaeZ
I%Gs^K
H(lq#@
']~!kO
:%3if66
G(fl:H
a5vcpr
VOHh15
K7*&O
eb5AA0b
iuLTC7z
4fK~S6
h9wbkp
M"$Y\3
0[,*h2
&)gx$x
6?pfx(8m
wQ[p=^y2
or=)H
\.ka@
dQ<Z<Cn
GSBMvf"
e/4mG6
Fl/0P&Y
h?M!w~9
)}LWp2
hy#2&M
ERdA2i
;+OPw[
k@?'p<
"wkTK1
Q@%'ht
|GB[):
F43dvju
u<qW-[
GRj!*X
+G{\/^
g`e~;yC?
T.:0D"
uU^e*l
LF5'3x
@Gwtta>6
se3#&z
V@I0qz]
\Onl.0
1nG^*K
A^SalyT
8)a(WB
Y'h^PUl
qME4]]
z;CK&_
3=i/J~
:VgOaw
3{h51[
nf(Kng/gj
LPf~;7F/*dxp
b]*-=p
c\`9L,
h$$&lP
W;_6mR
n@d2a`
,+_"?r[
~k4i}1)
'g9GGk|
DnSK!qY
h0Wy)<
}r)(2]'
+^f4}\z
BHj'}Z
w8QYS ]h
b'm74br
PhMrr{U:KA:
>%%KtU
>cj]dT#
rv\fwfz
vT#+[AER
8dEm`QN
}(.Kzd
oj_Nh59xM
$`LU6;
~d/Tx*
Q*:&T{
kK%90
vEN4Scc
!Ps.C8H
ag>E:']
X@{Oas
YGtndv
%52I~t8
quQ3,K
mG]f\4q
`Z9wDmp
"1qxJL
cR>]E.
@<%k' Gk
I:'_?d
9"+ycr
]]9#"L
601<~g&
{m9Js%l
YGuaex
s:p}DG
B?g*Lkgt]r
F-,JJT
Q&Lc+Z
\INZLh
`yr`iN{
Lg@q%M
o>YGy;
S[$*KH
>)DQj=1
,.P_(h
nV!u4F
DuPw\>
D7fJlQb
zc*=_=
1k%TP_
n!"%/n
cp5>Mp
a/yYfgV
CJLXVJ
TxzZw6
AYfdc4d
-_p)Om
R[sB8(
lQ'G4w6
F7=hx`
PUW77,
w-Nxan
"5@OPS
OLs463
_V}4?P
,S8*bt
=yY.,c,\
8cM=uI
CuLrtK
_qJ]`4omZ5
m?%\jz\~
S/6Gs`
J3${b:
^RA_
*j_#/~
LglE0-Q|
&Z^Z<I
bz!J4tw
@ql`jNG
m@If(DK
.1Z)N9
XQCBu
qKIRa3
<HGSYW
> yr!FuU)
~C5SIpn`9:
EaNU63$
pK-5.6
]#DjZT
xkv_}~
N?*#|/
K-]p,7(
=xP4c4
:xL $
$u)>Z:
jJ3u9d
--[j]:
,90C)p
zhHTtC
?|,0jW
Lf$r};
9w}vj2
EbV*uJ
7ZQQ-?9
Zl_kGb1
b.Rt)
<oslso>p
iRi%Sa
P`a5fY
vO\3<n
SGO5-`?
;&i"I|K
R:>eB0E;\
Sq7\3
4yDf/lv:
'#9etU
1u|%!'d;R
~|e/s%
+Taj7V
7I,EVO
f,-yY,'
LN15v
oy`B,7
YOO97QO
)h;:g)d
ua=\My^
Y,L1X{,
:T8%%U
YCb9cOV
e~OJex
c3`D+%
xu9q={e
m1je4p
{"./F
U2!R^z
a<fec@
c?2zVTK
4~ZD4v
79[LV(
h6pF]Wu
0t(>We"a#b
'IK#.},
$:V~Ai
a9"-Q)
wNg+\bW3
P#AE[I
NYI@}r
]@36\wq+
0'?Mf0#
utH>`W\L(
2j]xA
=x |$/r
8Y!ynTH&
2Ki- 0'_
[zBya]
]243!V@
ywz&xNS
7bkp<Yh'M
FBIVWU
N[506zX>w
-;,"CN
p$a8p4e5
!;m^~#
CZ:K3X
NtGx#w
,nDZ&\
.VxvU"
t1t}-d
{6DHAj/
B\qh>A
>0,D,1
L~GSXg
u #K_66
(~Q~u^
a8<(F1
s'"gVqz
8KH~AJ
n0?EmE6
e`zOQr
y2q5FM
J/mm^O
D[zi=|Xy
_P2w#%
c6Qx'V;z]p/]
F:oXyH}
DG3~%{
W5Z-AQ
']ly"-
8.:R0D
^q-Gl>+-
'uiCz
Cb\Pww
$T;?Lb]3I1
Jz_',c
>`H(Di
3<\j3#O4
@jd;Jj
*wS{Ph
!C+[ej
V-qf\EZ
QLQomsXW'
MH?3K7
1aCiCK
qrIutj)f
maXZ6
=?&Eg8
&zz@dE
'CQ/h
sWv-oQ
m2-j>8[
FbjB#0
N+mO1\}
T?cQ%8e
\;mQjv5d$
MG31d-
G!^0s~
S~>bKM
!kck[N
Q)9Z*>
4JtL}(
BneKF5E
MU'f4}Z
mn<o3EO
Z@$*2m6K
#'S~l*
p](\Vz
fEr87Cb
(f[%Gg]
s]8A8T
7_@upk
fSm@z^
'_B?4T?-j2o
@7j;qER9Olq
n>1V{[v
B)IC{6c-2
52X>7!oG@
BW[b`}
@B?t_iv
rnUa7a
$w5xps
rb=n_]
ILH0~i
qK|7'o
w2t|5x
~uJbg0&#
&"x[Vp
c}?V0&
2L9=.M{&u
n*)fyv
X"1Q,2N
,+xYM*
:Hjin#
[CcrS
(!&BLl
ZWTzP3
;EtQ!+
h{,sV6
wEWX/UsPz
Z|9nj
@3"HfX
7jO\UB
B]w+(S
?m.d F
^q'ArV
|Q 27t
EH54H|)H^
Q1"w)?}
|&4DIe
#ImDwm7V
4Xfc"7
/ib'__
>Q5,8[C
bTK'UQ~
V,~e]H7
Hd5d9g
`]6`_
o\iUAw/
hY'^^w
%/Yi1Z
rRA3@F[
+tT6',
6dskh\
)-,*</
:kkcS~
57.6b{y(&A
YGxvcMQ
jjU-+3
SShEOa
YIU_Wf
F.#i~|
Uf&y!AR1
}<jami
Lk\|%`
"Bm&7:
BSJ6?y
'gpu7s>
Dq;huF
n3?ihl#
>!?N#c
T[y;>H
l*jG~J3
Y_BYEr
/OzYb O0[s
_s+iBQ
.Xh4;{
2!TZVR
#Ki>]T
F ;EGJ
}IAn`j
8~D$Hlh
'7+]"Gm
Uu.U-$
~{% w%
YE"TGb
\PPt}_
D HN*&
\@=niu?
[0?$PB^
Ds'~_@Q
bOk{^I4t
XIG"IP
a8)i}p
*tO_tP
c{n}H/
zF=#CMc
niM*B<
-P@H&2
sj5I~*T"
)KH@Sg
ZEg`_&
= dnIR
U1UQg,
6(.,vVj
8_U3x#V
gRpy5"F
l+mdmiKb
6FMGAM
bbB#Ad
F7:>q|
=X*u{a
qe]#%B
Xzq#1
@xX8[e
;uc_KaG
fqT[\qJ
vzKXZd
oF'k!$]
]62LhX
Q@*cEkl
?"E@uu
ZV2KQb
2l%:*|Lr
g~xe1zR
f9."X~
-Y\[I=ld
@@g^g'Z
Qt>Bp<
:7V&(w
p7*=y:
/?;W-`4oO
h`*dFz[M
c{."95
HYt,bN
#n%e}g
LT$i:"
FM$S0fs
2z(ZPy2=F
4}Pf|$
w`:Uur
HU:DA\
(WZE[
K7^OMJeZpa
dzdN^+
H2!L_
vU[Z&r
M)Ma|5
~&`lQ8
K=|MB1Y
kZ>$eQMOP
08x)Y[e
`f\%:`&$
'kx.FT
vsvW#j
4|jP71
EU]#Tc
[>'Bog
6kpo#)A
"T'^Y
Sc'3oa
*]jet
d+KMbp
0R(!.K
p9bvB}
b'LP2Z
rWn0vj
\iO7{%
KJz!|,
p?'Ce(
\ExinP8}
G2A%n6
m *MCw
kIg?:)
qie#_
J5ba'G
,]$Ni
H9af8
,RFtdj
!sk?P,
Kvr[xZ
TS[tLh
`+#F/[
MpgKD
qC%W>_
?cz0,W
^{9(ky
/44O=w>z
JE3k&E:
,#uIFK
PGN.gJ
+|!]|gf
6_d"8}
O~Eg!6
XBlu7d
'GJXLR
<3^lwW6
SM=d8lrv
z)5cFsu5
H2!~bd
f3$rE,
[FQ2'9-Y
l:Pjf4
Y7Ikjs6@
ErX6eR
Mgf0?X
}^t~4>k
{eI'53
ovmQa
/vC17<
}9uGF*
tJ2*QH
Ggp^$
a~2'd
A1VvZS
r#wRDu
w~&_lM
Oar&Q8
_/ykb~
c=m10Zn((
\@p4`pm
j{x~0>
4U-N>(
,jb{h6
Yu13`*
'aW/Jw*
pb|.4 ih
UuQnut[
}Zf`v~
`N )]Q
65-O)`\
$tFx[E
`^"c4T
_T^$2ZCZ
QNPbnxv
7-'E68F
Xj#,`;
l&S&F>
'{cHsm6
3Rl[jH
ggDg/E
tip&\u
~({GC
TDgy=wo4r.
FqNh8z
G+SB B
&8jdr$
X5`"6]
%S8m ]
,4Gqe
x9lw.Y
p(JI4Qx
6iZKA6
:ftL]`
8M.As8
}Z}R2/_/
{S+|Um
<#R6T/l
!gnv+~~
E"J*Hg
< Z3Cp
@+@OX~
bloXTe
eQOFj*
o]C^&t
U'5 s%
Gm% U"
op]MLv
mjp:.:
C]B]B8
(*o%/\
Q"Ht)7
AZ$g7L
b<1O./
$#PpA9a
PI5D0?P
$$X{4A
x9UWP|nF
p!Ak}X
=pkk\})J
_>K.8dc
1) 6;]
h>d5jf
b]m_|Tw
"o5b@E
AKa+?D
v':.?IX
1i;(7;'
=8 DQ3
A\dsm'
t'/!J c
px#`{
-@%vL'
;D>gP
Ed!YA~t
Uuf"8-6
N'cxZg1
uoBZL
wA`DJP
tE`vVA
C%6Fa-
<Q?v^k
WOz(cQ
fs|aGa
mDeN %
k;(`8nlR
bR"+K=
;9xMFZ
Z+AFkR;
d/-`\Vg
5\'9v<!o
%zoJo*h
]U{4#<
a{c,8W
KPZ[u8"
".u,CI
-g=1@t
gfxt)z
+jl&x=
S0"fjg
Dv WLO
m[>"S=
ja?PA,k
xLC*wA
6Dc!Yo
D*p3j?D
R:c4-Y
X2,JzO
5O&2n8oLf
Jnds.8
l,NWdY
o@-'Q+
v!1'?I
yk8}n>
@YR\js
w9O@DTmc
i54uc%="
NRs6M`
#F1n$^
]<>sW9
{!@ohO
"_G$q7
f1<fe2
f+J*R`
V3a=(b
i+zq@B
zO0z{5j
xE\Nh(
_?>`30
9iVR:&
ut.OX
`5qC&o;Ze
NW1o5VF
:"1InT<
.9sn<3
~]a3>`
IMhLYtm
L[Z/{i
X6{O,eh }
^Vg[1tM
BDXRaL
SYr@Dd
+iuy)t
cxi4cL
NcT1(y
% 6T p
K|< Kj
`r.^~:\U'
m[=\O!
G8BPFDe
,-f({
Q'iMHE
NNQD475
R'/+%Cv
m?!{+4P
)RB[ob
KB#q}7
7U+rzF
tlA|Wo
LtDVjO
E:?tHu<
wgqi!A
SGig(O
>g=u!A
(FvGh6
~%<,7P
n0qc(te
p:^ B7
"+YvAW
C+dS 9
CF1yTzu
pT;]9L^684.n
\&+cGE
*mlm^X
lF1Dpj
g`ew!S
EtQnC,:4B
(Cig3V
Vz?sm'
X9oQpE
rh{+{e
|H%\E
b)\zd4]
W2\6"T
tL[jnU]_
;0^="UP
T;S:?M
Cw'ZJ<i!
%*lZx6
y\%A]J
-@+Jf<
i`3ll>
$4o7#'
jzDk`d*
sD/N]M:
v:WDS2
y/Z'F&Rz
Bbhjo&
ep{49#-
xq?kga/]
GU*DK
2_yuF
(xhTs`?T
l\uc3+
;#90/B
XWJ$)ld
`d-Ok
)y5~%fN
;#N<v{
9X=f5%#
|jIxB"
%*d~Ka
b)Jer!
9UT*Cz
{|}2De
+gY#\"_
py`p<w
@C!<2y
;*y]^y
"+/u9
1&VYsROAk
N)5Ljm
}ECE.S
Yd"iO]!Oa~~!
t95O6t
']='hp
fs(,b/Q
mn;1'<
Zd|Et\
PPVgD\
@5T")RX~
nd0tGke
-\ D.G
GVY1m8/
s^R|&BZ0D
i rGo?X8Z
Cs$6yr
M~/->
w/S4;q
4kZT$=
I)YU)W
^(V0hq
) Q~C<=#Y_sJ
0Sz-CG
>%5uA<
|+:+s9
mL<RHT
ye&&a
Gp5!pdM[
x9j,7I
_}&b^/+*
E~6VM/
Jj@s@pI
xL<"AyI
z9V^Kg
:(v@~q
XX(oxM
Z1wao;z
_4.)B9
.W&\bu10|
rqK/P{+
^TYTv3PQT
V<}cto
v\B2:&
Cs}/=Sw
qBw Svrjh
`jFWlH
V1MjH:
YwEw^J!@
masF4<99
-D?#R~
m9r}"H
.zOi_4
n%uk/;
Tl9;X
po'gG)
r!%+D#
V~7E$6pK
U\|xl3u
P;[6a*r
;25Vav
H_Tzqg
OS *SK)\R
wG6iV-L
?|BxZF9
7i_rnsL
ey4Q4>(Ls
nw$W|f
wAw`?nBS
+6t,o&
29-@cz1
5bO)*2*}
1d8{\a
|=+zPE
J)aUd'U
oIp0b5
JFhjhn
Qp4.fD%
,o6S8bK
MHe: 2h
dV,d`d$e~
|!JRmL
CSWW,OC
J9Y]*X
RMW2<j/
wbGT{.x
xF O_5sP
)X[o`G
n<MVmm
1#5Bq;A
{] p%~
UOOJ^*
N|12@CP
1&qoB[
0HQ8h
5`<]X
JdQCe23b^w)
]/8Lx
1)fVJd
`|gW#"l6
'bwn8Y
+UO+f.
Kk2EV*RB
Kw&@1'9
u!T:H36
G[C\E9
'K'V:}
uk4*F|
Q BGoWb^P
8Gx(FtQLG
Ikk''Q
hEgU^w
@I{\7L
G_xIIz
uuyxiAXB
Nn|2O%w
M'rN5\
:!zNc%a
AX4sR%
W5nL5B
^g=M>9]
~w4J\g.
}||}1N
;Cf%4Q?
!Ec5qwQ*Y
<cvf}L
h\o4g/
)|4$BJ
Qg>AK5Fb
6,=`%"*
)?dHj?4
le_BME
>/rR=y
*nkKNd
"U2t?RJQ\
m8O\t<"%
+c0qRX
v4.0.30319
#Strings
Ztdwep
TResponse
resourceMan
resourceCulture
_accessToken
<Uid>k__BackingField
<DisplayName>k__BackingField
<ReferralLink>k__BackingField
<QuotaInfo>k__BackingField
<Reference>k__BackingField
<Expires>k__BackingField
<Path>k__BackingField
<Meta>k__BackingField
<DeltaEntries>k__BackingField
<Reset>k__BackingField
<Cursor>k__BackingField
<HasMore>k__BackingField
<Content>k__BackingField
<Size>k__BackingField
<Bytes>k__BackingField
<ThumbExists>k__BackingField
<Rev>k__BackingField
<ModifiedTime>k__BackingField
<IsDirectory>k__BackingField
<Icon>k__BackingField
<Root>k__BackingField
<Revision>k__BackingField
<ClientModifiedTime>k__BackingField
<MimeType>k__BackingField
<Hash>k__BackingField
<Contents>k__BackingField
<Image>k__BackingField
<Shared>k__BackingField
<Quota>k__BackingField
<Normal>k__BackingField
<Url>k__BackingField
GetMethodType
PutMethodType
PostMethodType
DeleteMethodType
SandboxRoot
DropboxRoot
MethodType
_operation
_inputPath
<InputStream>k__BackingField
<Query>k__BackingField
<FromPath>k__BackingField
<ToPath>k__BackingField
_methodType
_parameters
_stream
<>9__1_0
Mxaxacuyd.Properties.Resources.resources
Caller
get_ResourceManager
get_Culture
set_Culture
get_Fstnwj
GetAccountInfo
GetFiles
PutFiles
GetFileMeta
GetFolderMeta
GetDelta
GetRevisions
Restore
Search
GetShares
GetMedia
GetCopyRef
GetThumbnails
CreateFolder
Delete
get_Uid
set_Uid
get_DisplayName
set_DisplayName
get_ReferralLink
set_ReferralLink
get_QuotaInfo
set_QuotaInfo
get_Reference
set_Reference
get_Expires
set_Expires
get_Path
set_Path
get_Meta
set_Meta
get_DeltaEntries
set_DeltaEntries
get_Reset
set_Reset
get_Cursor
set_Cursor
get_HasMore
set_HasMore
get_Content
set_Content
get_Size
set_Size
get_Bytes
set_Bytes
get_ThumbExists
set_ThumbExists
get_Rev
set_Rev
get_ModifiedTime
set_ModifiedTime
get_IsDirectory
set_IsDirectory
get_Icon
set_Icon
get_Root
set_Root
get_Revision
set_Revision
get_ClientModifiedTime
set_ClientModifiedTime
get_MimeType
set_MimeType
get_Hash
set_Hash
get_Contents
set_Contents
get_Image
set_Image
get_Shared
set_Shared
get_Quota
set_Quota
get_Normal
set_Normal
get_Url
set_Url
.cctor
Execute
get_InputPath
set_InputPath
get_InputStream
set_InputStream
get_Query
set_Query
get_FromPath
set_FromPath
get_ToPath
set_ToPath
GetParametersAsString
<Xos>b__1_0
Create
set_KeySize
FromBase64String
set_Key
set_IV
get_Key
get_IV
CreateDecryptor
CopyTo
ToArray
Dispose
GetTypeFromHandle
CreateDelegate
DynamicInvoke
GetTypes
TakeWhile
get_CurrentDomain
get_Assembly
GetObject
Format
get_Length
get_Headers
Concat
set_Method
GetResponse
get_ContentLength
GetResponseStream
get_UTF8
GetBytes
ReadObject
ConvertFrom
get_Method
op_Equality
get_Count
set_ContentLength
set_ContentType
GetRequestStream
set_Position
get_AllKeys
get_Item
Substring
get_FullName
ToLower
Contains
Ztdwep.exe
accessToken
inputFilePath
inputFileStream
cursor
revision
fromPath
toPath
methodType
parameters
stream
ResourceManager
Culture
Fstnwj
DisplayName
ReferralLink
QuotaInfo
Reference
Expires
DeltaEntries
Cursor
HasMore
Content
ThumbExists
ModifiedTime
IsDirectory
Revision
ClientModifiedTime
MimeType
Contents
Shared
Normal
InputPath
InputStream
FromPath
ToPath
<Module>
Program
Mxaxacuyd
Hoster
Resources
Mxaxacuyd.Properties
OAuth2Client
DropBoxClient
AccountInfo
DropBoxClient.Entities
CopyReference
DropBoxState
FileContent
FileMeta
FolderMeta
ImageContent
StringConstants
PostRestoreOperation
DropBoxClient.Operations
PostDeltaOperation
PutFilesOperation
SearchOperation
GetThumbnailsOperation
MoveOperation
CopyOperation
DeleteOperation
CreateFolderOperation
GetCopyRefOperation
PostMediaOperation
PostSharesOperation
GetRevisionsOperation
GetFolderMetaOperation
GetAccountInfoOperation
GetFileMetaOperation
GetFilesOperation
WebOperation`1
DropBoxClient.Framework
System.Security.Cryptography
SymmetricAlgorithm
Convert
System
ICryptoTransform
MemoryStream
System.IO
CryptoStream
Stream
IDisposable
Object
Action
IEnumerable`1
System.Collections.Generic
Enumerable
System.Linq
Delegate
Assembly
System.Reflection
Func`2
AppDomain
System.Resources
CultureInfo
System.Globalization
List`1
System.Drawing
NameValueCollection
System.Collections.Specialized
FileStream
InvalidDataException
WebRequest
System.Net
WebHeaderCollection
WebResponse
Encoding
System.Text
DataContractJsonSerializer
System.Runtime.Serialization.Json
XmlObjectSerializer
System.Runtime.Serialization
ImageConverter
TypeConverter
System.ComponentModel
NameObjectCollectionBase
BinaryWriter
String
EditorBrowsableAttribute
CompilationRelaxationsAttribute
System.Runtime.CompilerServices
RuntimeCompatibilityAttribute
DebuggableAttribute
System.Diagnostics
AssemblyTitleAttribute
AssemblyDescriptionAttribute
AssemblyConfigurationAttribute
AssemblyCompanyAttribute
AssemblyProductAttribute
AssemblyCopyrightAttribute
AssemblyTrademarkAttribute
GuidAttribute
System.Runtime.InteropServices
AssemblyFileVersionAttribute
TargetFrameworkAttribute
System.Runtime.Versioning
ComVisibleAttribute
CompilerGeneratedAttribute
DataMemberAttribute
GeneratedCodeAttribute
System.CodeDom.Compiler
DebuggerNonUserCodeAttribute
DataContractAttribute
KnownTypeAttribute
CryptoStreamMode
RuntimeTypeHandle
FileMode
FileAccess
HttpRequestHeader
EditorBrowsableState
DebuggingModes
mscorlib
System.Core
WrapNonExceptionThrows
$9220d1cd-7161-448f-bb84-2acca5cf5961
1.0.0.0
.NETFramework,Version=v4.6
FrameworkDisplayName
.NET Framework 4.6
3System.Resources.Tools.StronglyTypedResourceBuilder
16.0.0.0
display_name
referral_link
quota_info
copy_ref
expires
metadata
DropBoxClient.Entities.FileMeta
!DropBoxClient.Entities.FolderMeta
entries
cursor
has_more
thumb_exists
modified
is_dir
revision
client_mtime
mime_type
contents
shared
normal
expires
_CorExeMain
mscoree.dll
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<assemblyIdentity version="1.0.0.0" name="MyApplication.app"/>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v2">
<security>
<requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3">
<requestedExecutionLevel level="asInvoker" uiAccess="false"/>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
Fstnwj
kh7GV+pdTz9FGCNh7YDIugz217SRLbQyWR8vbIxQ0So=
9iLhcsWsLLihWhED2KPkyg==
rBHgg1QwY
Mxaxacuyd.Properties.Resources
Fstnwj
DELETE
sandbox
dropbox
https://api.dropbox.com/1/restore/{0}/{1}
cursor
https://api.dropbox.com/1/delta
https://api-content.dropbox.com/1/files_put/{0}/{1}
Query should have 3 characters atleast
https://api.dropbox.com/1/search/{0}/{1}
Bearer
x-dropbox-metadata
https://api-content.dropbox.com/1/thumbnails/{0}/{1}
from_path
to_path
https://api.dropbox.com/1/fileops/move
https://api.dropbox.com/1/fileops/copy
https://api.dropbox.com/1/fileops/delete
https://api.dropbox.com/1/fileops/create_folder
https://api.dropbox.com/1/copy_ref/{0}/{1}
https://api.dropbox.com/1/media/{0}/{1}
https://api.dropbox.com/1/shares/{0}/{1}
https://api.dropbox.com/1/revisions/{0}/{1}
https://api.dropbox.com/1/metadata/{0}/{1}
https://api.dropbox.com/1/account/info
https://api-content.dropbox.com/1/files/{0}/{1}
application/x-www-form-urlencoded
application/octet-stream
{0}={1}&
yMACdspRA204vKADhN.Up06mlV2ZneIEB8Kpq
AC E"G#I
'.6>JRZfnv~
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
Comments
CompanyName
FileDescription
FileVersion
1.0.0.0
InternalName
Ztdwep.exe
LegalCopyright
LegalTrademarks
OriginalFilename
Ztdwep.exe
ProductName
ProductVersion
1.0.0.0
Assembly Version
1.0.0.0
Antivirus Signature
Bkav Clean
Lionic Clean
Elastic malicious (high confidence)
MicroWorld-eScan Gen:Variant.MSILHeracles.95413
ClamAV Clean
FireEye Generic.mg.404da62e0999dcbc
CAT-QuickHeal Clean
McAfee Artemis!404DA62E0999
Malwarebytes Malware.AI.2918665228
Zillya Clean
Sangfor Suspicious.Win32.Save.a
K7AntiVirus Clean
BitDefender Gen:Variant.MSILHeracles.95413
K7GW Clean
CrowdStrike win/malicious_confidence_100% (W)
BitDefenderTheta Gen:NN.ZemsilF.36318.0m0@aiE8gyp
VirIT Trojan.Win32.MSIL_Heur.A
Cyren Clean
Symantec ML.Attribute.HighConfidence
tehtris Clean
ESET-NOD32 a variant of MSIL/Kryptik.AJFD
APEX Malicious
Paloalto Clean
Cynet Malicious (score: 100)
Kaspersky HEUR:Backdoor.MSIL.Remcos.gen
Alibaba Clean
NANO-Antivirus Clean
ViRobot Clean
Rising Malware.Obfus/MSIL@AI.100 (RDM.MSIL2:jaUoZvh9TK7oPd6wiXBH3w)
TACHYON Clean
Sophos Generic ML PUA (PUA)
Baidu Clean
F-Secure Heuristic.HEUR/AGEN.1309310
DrWeb Trojan.PackedNET.2172
VIPRE Clean
TrendMicro Clean
McAfee-GW-Edition BehavesLike.Win32.Generic.cc
Trapmine malicious.high.ml.score
CMC Clean
Emsisoft Gen:Variant.MSILHeracles.95413 (B)
Ikarus Clean
GData Gen:Variant.MSILHeracles.95413
Jiangmin Clean
Webroot Clean
Avira HEUR/AGEN.1309310
Antiy-AVL Clean
Gridinsoft Trojan.Win32.AsyncRAT.bot
Xcitium Clean
Arcabit Clean
SUPERAntiSpyware Clean
ZoneAlarm HEUR:Backdoor.MSIL.Remcos.gen
Microsoft Trojan:MSIL/AgentTesla.LQL!MTB
Google Clean
AhnLab-V3 Trojan/Win.PWSX-gen.C5453912
Acronis Clean
VBA32 Clean
ALYac Clean
MAX malware (ai score=88)
DeepInstinct MALICIOUS
Cylance unsafe
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Tencent Clean
Yandex Clean
SentinelOne Static AI - Malicious PE
MaxSecure Trojan.Malware.300983.susgen
Fortinet MSIL/Agent.PKV!tr.dldr
AVG Win32:PWSX-gen [Trj]
Avast Win32:PWSX-gen [Trj]
No IRMA results available.