Static | ZeroBOX

PE Compile Time

2071-10-20 15:51:16

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x00079b94 0x00079c00 6.60361306961
.rsrc 0x0007c000 0x0000076a 0x00000800 4.07708839824
.reloc 0x0007e000 0x0000000c 0x00000200 0.101910425663

Resources

Name Offset Size Language Sub-language File type
RT_VERSION 0x0007c0a0 0x000004e0 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_MANIFEST 0x0007c580 0x000001ea LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with CRLF line terminators

Imports

Library mscoree.dll:
0x402000 _CorExeMain

!This program cannot be run in DOS mode.
`.rsrc
@.reloc
@k@[X#
i4X('
i4X('
Z#333333
Z#333333
i4X('
#UUUUUU)@r
i4X('
i4X('
i4X('
#UUUUUU0@r>K
#UUUUUU0@r>K
Z#333333
`d@[X#
i4X('
i4X('
Z#333333
#UUUUUU0@r>K
Z#333333
i4X('
#UUUUUU0@r>K
Z#333333
#UUUUUU0@r>K
#UUUUUU0@r>K
i4X('
@J@rzO
i4X('
@J@rlR
#UUUUUU%@
#UUUUUU-@r
@Y@r<S
%!+rDS
i4X('
i4X('
Z#333333
i4X('
i4X('
#UUUUUUA@
#UUUUUUC@r
#UUUUUU6@
%Cr
%"#UUUUUU8@
%#Lr
%(Qr
%)Sr
%,Vr
%0Xra
%1#UUUUUU=@
%2Wr
%74r
%87r
%;;r
%<7r
i4X('
@R@r"S
`e@[X#
i4X('
#UUUUU
#UUUUUUC@r
#UUUUUU8@r
%Cr
%!Ir$W
%%@r4W
%'gr:W
%(or
%,NrPW
*C@rdW
Z#333333
#UUUUU
@Y@r>L
#UUUUUU6@
@A@r2]
#UUUUU
#UUUUUUC@
*@@rX]
#UUUUUU9@
i4X('
@I@r*^
#UUUUU
i4X('
`g@[X#
i4X('
i4X('
@H@r@`
@Z@r"L
Z#333333
i4X('
Z#333333
#UUUUUUC@r
Z#333333
#UUUUU
Z#333333
Z#333333
@`@[X#
i4X('
Z#333333
#UUUUUUC@
#UUUUUUC@
@Y@r"L
#UUUUUUC@
@Z@r<S
#UUUUUUC@
@Y@r"L
#UUUUUUC@
@Z@r<S
Z#333333
i4X('
Z#333333
#UUUUUU%@r
Z#333333
Z#333333
@X@rbj
#UUUUU
#UUUUUU:@r
#UUUUUU6@
#UUUUUUB@
#UUUUU
#UUUUU
@Y@rPx
#UUUUUUB@
Z#333333
Z#333333
i4X('
Z#333333
i4X('
i4X('
i4X('
#UUUUUU;@rz
#UUUUUU:@r
#UUUUU
%$Br
%'srzR
%*cr
%-or
%0#UUUUUU4@
i4X('
Z#333333
Z#333333
Z#333333
% #UUUUUUB@rb
%##UUUUU
%$prr
%&hr}
%(pr
%)[r$\
%*Xr
%+qr
%,fr
%/wr
%1jr
%2kr
%!Sr
%#`r(
%'Or
%.:r0
%0)r8
%2nrC
%7"rF
%8LrL
%9#UUUUUU;@
%@^rh
#UUUUU
Z#333333
Z#333333
i4X('
i4X('
#UUUUU
Z#333333
i4X('
Z#333333
Z#333333
#UUUUU
#UUUUUU%@r
#UUUUUU;@r
#UUUUUU:@r
%#nrN
#UUUUUU%@
%zr
%#er>L
%6Pr&]
%8lr
%:ir/
%;ir
%Avr
%Bir
%Dpr
%grW
#UUUUU
#UUUUUU:@
%"nrC
i4X('
i4X('
Z#333333
Z#333333
i4X('
Z#333333
i4X('
Z#333333
i4X('
i4X('
Z#333333
i4X('
i4X('
9rF>B"
9rF>;
q,aW;
i4X('
Z#333333
Z#333333
i4X('
Z#333333
#UUUUUU%@
Z#333333
i4X('
#UUUUUU%@
i4X('
Z#333333
Z#333333
#UUUUUU6@r
#UUUUUUB@
#UUUUUUC@
Z#333333
%!qr
%"dr
%&1r
%"Lr~
%%qr
%&dr
%+er
%1qr
@Y@rR\
#UUUUUUC@
%!+r
%%tr
%*`rD
%-#UUUUUU%@rL
%4+rb
#UUUUUU%@
#UUUUUUC@r
#UUUUUUC@
%drPx
%!,rC
%1#UUUUU
%2gr
%5r
%7/r
i4X('
i4X('
`b@[X#
i4X('
#UUUUUUB@r
i4X('
Z#333333
i4X('
#UUUUUU%@r
#UUUUU
@Z@[X#
i4X('
i4X('
#UUUUUU:@
#UUUUUUB@r
Z#333333
i4X('
@]@[X#
i4X('
Z#333333
i4X('
i4X('
i4X('
@Z@rvU
@Y@rzR
Z#333333
i4X('
#UUUUUUC@
k@[X#
i4X('
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
PADPADP
Adobe Photoshop CS6 (Windows)
2023:05:02 23:03:14
Adobe_CM
dEU6te
'7GWgw
;fk[[j
IM+*uy&
U^^.C1e
+eO 3q;b
i?zLap
sup}mp
hu,,Lkv`
[HfP{G
2,k[ip
,/3KI/cDv
{|ATris
Photoshop 3.0
printOutput
PstSbool
Inteenum
printSixteenBitbool
printerNameTEXT
printProofSetupObjc
proofSetup
Bltnenum
builtinProof
proofCMYK
printOutputOptions
Cptnbool
Clbrbool
RgsMbool
CrnCbool
CntCbool
Lblsbool
Ngtvbool
EmlDbool
Intrbool
BckgObjc
Rd doub@o
Grn doub@o
Bl doub@o
BrdTUntF#Rlt
Bld UntF#Rlt
RsltUntF#Pxl@X
vectorDatabool
PgPsenum
LeftUntF#Rlt
Top UntF#Rlt
Scl UntF#Prc@Y
cropWhenPrintingbool
cropRectBottomlong
cropRectLeftlong
cropRectRightlong
cropRectToplong
boundsObjc
Top long
Leftlong
Btomlong
Rghtlong
slicesVlLs
sliceIDlong
groupIDlong
originenum
ESliceOrigin
autoGenerated
Typeenum
ESliceType
boundsObjc
Top long
Leftlong
Btomlong
Rghtlong
urlTEXT
nullTEXT
MsgeTEXT
altTagTEXT
cellTextIsHTMLbool
cellTextTEXT
horzAlignenum
ESliceHorzAlign
default
vertAlignenum
ESliceVertAlign
default
bgColorTypeenum
ESliceBGColorType
topOutsetlong
leftOutsetlong
bottomOutsetlong
rightOutsetlong
Adobe_CM
dEU6te
'7GWgw
;fk[[j
IM+*uy&
U^^.C1e
+eO 3q;b
i?zLap
sup}mp
hu,,Lkv`
[HfP{G
2,k[ip
,/3KI/cDv
{|ATris
http://ns.adobe.com/xap/1.0/
<?xpacket begin="
" id="W5M0MpCehiHzreSzNTczkc9d"?> <x:xmpmeta xmlns:x="adobe:ns:meta/" x:xmptk="Adobe XMP Core 5.3-c011 66.145661, 2012/02/06-14:56:27 "> <rdf:RDF xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"> <rdf:Description rdf:about="" xmlns:xmpMM="http://ns.adobe.com/xap/1.0/mm/" xmlns:stEvt="http://ns.adobe.com/xap/1.0/sType/ResourceEvent#" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:photoshop="http://ns.adobe.com/photoshop/1.0/" xmlns:xmp="http://ns.adobe.com/xap/1.0/" xmpMM:DocumentID="C69D00DB8D162E341B0D25D8A44CB55A" xmpMM:InstanceID="xmp.iid:895E485F24E9ED119CFBFE8CD687500E" xmpMM:OriginalDocumentID="C69D00DB8D162E341B0D25D8A44CB55A" dc:format="image/jpeg" photoshop:ColorMode="3" xmp:CreateDate="2023-04-24T12:08:58+03:00" xmp:ModifyDate="2023-05-02T23:03:14+03:00" xmp:MetadataDate="2023-05-02T23:03:14+03:00"> <xmpMM:History> <rdf:Seq> <rdf:li stEvt:action="saved" stEvt:instanceID="xmp.iid:895E485F24E9ED119CFBFE8CD687500E" stEvt:when="2023-05-02T23:03:14+03:00" stEvt:softwareAgent="Adobe Photo
GHVe*9:IJWXYZftu
5&DTdEU'
()*6789:FGHIJVWXYZefghijtuvwxyz
51i<6}
^,cmxUru
c5SIa'
/MW?/
Y%UV`@$
A]uRG4
c8}Mv1SR>
q&kT{r&
X%$8e+T1y
HY~N`s
Ii+E:ST
*qM=B>
jq8d,tB
y|Ni{t
xN[-l?+
uT9@E<0W`
4U9fZXj+c
+tC}`d
<Ni{uZ
J:Zj8S
wZ~'k=<
P4brWN~nD
GiCX(R
P<+G)Ls
~t;`yu(#
{ktN~k
#atO_L
SU><-5
J6SEQU
`/"ya9
Iy^B[
zY6:}<
?7O%TDj
/CsG+/
V?LS2tS5Vd>
Qrn:h/
`s&UIf
w3@5&+
,)U-:Y
BPS-2G
o_g=^
FC%`_/
z)iKGK
-SFW0T&_
aFIpM*
?.zOEz
'O;Yxr
~T~rOP
zo.:jdOs
\n>/B)
U_[)*d
*q,Q1Y
*<lcog
)ipzju
~ni7~i
&"kt%a
L[cBC}
|e{ku:*}8
(7}Do6d
D.h)tV)iY
F+.dzjx
WU4czC
}ef!%SK
$Ru Vz<
zO?*,]A
fM{qB6QX
7aXmN
xMp|?c
Ug]3?Ms
TXs}}eA
?6KpOh
6M"y\Q[
R>Wy$P
a58]BW
Md+OA_S
~b]9$eV
,x:7=^
mH.V((
SQEU#y
%1y+*{
SGG4{*
^q0iqIY
p<7/fO
6*~=I]
6|?)YGM
7TQIyM?
sF1M6$
c4y}>nD
T,Jo.m
K|=oIoo
?J}?JX
atV=St
Ro2fO&
\~ck$|
z}\XvQ[
x}_w=^
}K`8V1G
2S56%
MXEc>b
ShDVIp
H8WL}me.
5LR~j_
b+h8N
qb2}\9
5j`2|8
|R'5bX
U8}]5e
7Z47A5
~<Id|B
rU*%^+5]6
MtxbI'
$|YJ*+.
hEmu43a
vG"qJ6
;x}\KU
[SSomO
E;qM5A
RTC7~z
N)km-I
(ugL3D
x}_w=^
[z6P^
N<t:eJ
p7qfhD
DREV.%
[=Ce/X^
"ZisfhG
qSh4V\
3~|1laI
h=[Y#m
-adcMR
"{;qEj
y|mbie
t_/=MO
JSM)@S
R;2at8
9xdHaOsonQ*
T:T$+MYG
u#.f|.
gZl7-c
i&'&%L
o2unDWjj
R{>b)&_
Msc{Wb>
+e4iAK
+m")!_O'
)rU4D:
~7NS3.
?Z3u4tT
Vz*;C
+UeHQA
LbX:y(
Ptq,c-
Lc<y4X
'0u;&a8
%eKp%y
oNOAGOG
B6THpLf
/GOGYL
)E9C'=^
>9MV)#
o\M'kp
j~&5ZC
e sV_LJ
:I*^Z5
&(7qdH
);}|O[
7J*D~<
%42i2(
&)0hQx
aA/R1*b
r./S=<5
BM-bTC
&%4iYR
CK;lE<t
#e{]'j)
?_o*iB6T
{yjOS
i[nE&h
=A4?-X
&)92kO
Jhs?Bz
$1-f#_
soTs|X
V;m<xGN1:`
9c.b2Se
~%q5jv
sgl>,v
gN=!b}d
#S`XlXv
OW}NfJ
Etk5-~
(!~d?di3?u;+}H8
xm;=mn[
B)1Hf5
}/Ta9C
RA+pH
Nj+*+i
^Y(ph)
=)O]}C
Z}'ufN
A%J>)*ST
4YO3bu.Ee
H1$B>b
o4RE{ms
E,dwI)
LWRyrM
tI2=MeJ
1(qjRJX
#.M%F#S
Jkp7F4
C-}uf'
'K}@e
u=DoK:
w3x}_w7H**
*k-VgD
;{;qm;X~i<
oU(3VL
-;'=IU
3&+6+_#
3Ii?UT
S}I">9EESM
q53J8*
<ce2TE
v4.0.30319
#Strings
<>9__4_10
<Main>b__4_10
<>9__6_10
<ProcessCommand>b__6_10
<ProcessCommand>b__10
<Create>b__10
__StaticArrayInitTypeSize=20
<ProcessCommand>b__20
sxE130
_3LCtvL5bzhDZ0
<>9__10_0
<StopTorService>b__10_0
<StartService>b__10_0
<HookCallback>b__10_0
<ReadFileBytes>b__10_0
<>c__DisplayClass10_0
<>9__0_0
<GetCurrentExecutable>b__0_0
<DecompressArchive>b__0_0
<IsMatch>b__0_0
<Recovery>b__0_0
<>c__DisplayClass0_0
<>9__1_0
<Upload>b__1_0
<Shuffle>b__1_0
<PerformMutexCheck>b__1_0
<CompressDirectory>b__1_0
<>c__DisplayClass1_0
<>9__2_0
<ProcessUSB_Spread>b__2_0
<Compname>b__2_0
<PerformSelfDestruct>b__2_0
<>c__DisplayClass2_0
<>9__13_0
<_SPw3gJcfAN1Kc>b__13_0
<>c__DisplayClass13_0
<>9__3_0
<ProcessLocal_Spread>b__3_0
<LoadCommands>b__3_0
<SelfDestructInit>b__3_0
<>c__DisplayClass3_0
<>c__DisplayClass14_0
<>9__4_0
<Send>b__4_0
<Main>b__4_0
<InstallStartup>b__4_0
<ProcessCommands>b__4_0
<>c__DisplayClass4_0
<>9__5_0
<UrlEncodeExtended>b__5_0
<Create>b__5_0
<ExtractMasterKey>b__5_0
<>c__DisplayClass5_0
<>9__16_0
<_poHjhkLWMLRVe>b__16_0
<>c__DisplayClass16_0
<>9__6_0
<ProcessCommand>b__6_0
<.ctor>b__6_0
<>c__DisplayClass6_0
<>9__7_0
<DownloadBundle>b__7_0
<DiskSize>b__7_0
<.ctor>b__7_0
<Start>b__7_0
<ProcessRequest>b__7_0
<>c__DisplayClass7_0
<>9__18_0
<_AcTJtMR2HzhHN>b__18_0
<>c__DisplayClass18_0
<>9__8_0
<InstallTorConfig>b__8_0
<StartServer>b__8_0
<RAMAmount>b__8_0
<>c__DisplayClass8_0
<>c__DisplayClass39_0
<>9__9_0
<ProcessExecutablePath>b__9_0
<SetHook>b__9_0
<InstallTor>b__9_0
<>c__DisplayClass9_0
<__Active_Window_Process_Name__>b__0
<RandString>b__0
<LoadMain>b__0
<WaitForOnion>b__0
<Stop>b__0
<SearchFiles>b__0
<EnumerateCredentials>b__0
<ProcessUrls>b__0
<Compress>b__0
_eHxFGQ0w4U1e0
f6Uuj0
<>9__6_11
<ProcessCommand>b__6_11
<ProcessCommand>b__11
<Main>b__11
_rvSxqkhgEUGH1
get__MCRp9M3f6KNL1
set__MCRp9M3f6KNL1
<>9__10_1
<StopTorService>b__10_1
<HookCallback>b__10_1
<>c__DisplayClass10_1
<>9__0_1
<IsMatch>b__0_1
<ProcessUrls>b__0_1
<>c__DisplayClass0_1
<>9__1_1
<Shuffle>b__1_1
<CompressDirectory>b__1_1
<>c__DisplayClass1_1
<>9__2_1
<PerformSelfDestruct>b__2_1
<>9__3_1
<SelfDestructInit>b__3_1
<>9__14_1
<__Active_Window_Process_Name__>b__14_1
<>c__DisplayClass14_1
<>9__4_1
<Main>b__4_1
<ProcessCommands>b__4_1
<>c__DisplayClass4_1
<>9__5_1
<Create>b__5_1
<ExtractMasterKey>b__5_1
<>c__DisplayClass5_1
<>9__16_1
<_poHjhkLWMLRVe>b__16_1
<>9__6_1
<ProcessCommand>b__6_1
<>c__DisplayClass6_1
<>9__7_1
<Start>b__7_1
<>c__DisplayClass7_1
<>9__18_1
<_AcTJtMR2HzhHN>b__18_1
<>c__DisplayClass18_1
<>9__8_1
<RAMAmount>b__8_1
<>c__DisplayClass39_1
<>9__9_1
<ProcessExecutablePath>b__9_1
<_SPw3gJcfAN1Kc>b__1
<ProcessUSB_Spread>b__1
<StartService>b__1
<DecompressArchive>b__1
<LoadMain>b__1
<InstallStartup>b__1
<LoadCommands>b__1
<SearchFiles>b__1
<>c__1`1
IEnumerable`1
List`1
CS$<>8__locals1
<ProcessCommand>g__HandleData|1
<>9__6_12
<ProcessCommand>b__6_12
Microsoft.Win32
ReadInt32
ToInt32
ASDHJKASBHJASD2
<>9__10_2
<HookCallback>b__10_2
<>c__DisplayClass10_2
<>9__1_2
<Shuffle>b__1_2
<>9__2_2
<ProcessUSB_Spread>b__2_2
<>9__3_2
<SelfDestructInit>b__3_2
<>9__4_2
<Main>b__4_2
<>c__DisplayClass4_2
<>9__5_2
<Create>b__5_2
<ExtractMasterKey>b__5_2
<>c__DisplayClass5_2
<>9__6_2
<ProcessCommand>b__6_2
<>c__DisplayClass6_2
<>9__7_2
<SearchFiles>b__7_2
<>c__DisplayClass18_2
<>c__DisplayClass39_2
<_AcTJtMR2HzhHN>b__2
<__Active_Window_Process_Name__>b__2
<_poHjhkLWMLRVe>b__2
<StartService>b__2
<LoadMain>b__2
<ProcessCommands>b__2
<CompressDirectory>b__2
Dictionary`2
<>9__6_13
<ProcessCommand>b__6_13
<ProcessCommand>b__13
__StaticArrayInitTypeSize=3
<>9__10_3
<HookCallback>b__10_3
<>c__DisplayClass10_3
<>9__2_3
<ProcessUSB_Spread>b__2_3
<>9__4_3
<Main>b__4_3
<ProcessCommands>b__4_3
<>9__5_3
<Create>b__5_3
<ExtractMasterKey>b__5_3
<>9__6_3
<ProcessCommand>b__6_3
<>c__DisplayClass6_3
<_AcTJtMR2HzhHN>b__3
<ProcessCommand>b__3
<StartService>b__3
<CompressDirectory>b__3
get__QxGD4f5MjvJm3
set__QxGD4f5MjvJm3
<>9__6_14
<ProcessCommand>b__6_14
<ProcessCommand>b__14
set_ContentLength64
<>9__10_4
<HookCallback>b__10_4
<>9__5_4
<Create>b__5_4
<>9__6_4
<ProcessCommand>b__6_4
<>c__DisplayClass6_4
<_AcTJtMR2HzhHN>b__4
<StartService>b__4
<Main>b__4
<ExtractMasterKey>b__4
<>9__6_15
<ProcessCommand>b__6_15
<>9__10_5
<HookCallback>b__10_5
<>9__5_5
<Create>b__5_5
<ExtractMasterKey>b__5_5
<>9__6_5
<ProcessCommand>b__6_5
<>c__DisplayClass6_5
<ProcessCommand>b__5
<Main>b__5
_2NKrKeJwnvMn5
<ProcessCommand>b__16
<>9__4_6
<Main>b__4_6
<>9__5_6
<ExtractMasterKey>b__5_6
<>9__6_6
<ProcessCommand>b__6_6
<>c__DisplayClass6_6
<Create>b__6
<HookCallback>b__6
<>9__6_17
<ProcessCommand>b__6_17
<ProcessCommand>b__17
<>9__4_7
<Main>b__4_7
<>9__6_7
<ProcessCommand>b__6_7
<>c__DisplayClass6_7
<Create>b__7
<HookCallback>b__7
<ProcessCommand>b__18
lgoU38
kKRCD8
get_UTF8
<>9__4_8
<Main>b__4_8
<>9__5_8
<Create>b__5_8
<>9__6_8
<ProcessCommand>b__6_8
<HookCallback>b__8
kl7wm8
<>9__6_19
<ProcessCommand>b__6_19
otiH29
ma1LA9
<>9__4_9
<Main>b__4_9
<>9__5_9
<Create>b__5_9
<>9__6_9
<ProcessCommand>b__6_9
<ProcessCommand>b__9
yHxMSB
fVYgqB
suqrQC
_77oCtgE4OVRWC
get__SiCaVmyxZ5EqC
set__SiCaVmyxZ5EqC
mKUqyC
rKBV0D
_xN1QIJLKE37yE
fcMqFF
_mA3btWpq7YckF
_rlCWKLY5b6L5G
jUonUG
get__Qn96wKrG8mhnG
set__Qn96wKrG8mhnG
get__2NIjvlEPEYhQH
set__2NIjvlEPEYhQH
o9AxaH
b4ut1I
get_ASCII
mBBdpI
wEDn2K
wgR1KL
con9kL
vMzvyL
mlTFQM
eWvm6N
q772EN
get__BWzBNOKJjsbbN
set__BWzBNOKJjsbbN
wu77kN
get__UL6lD9GjdAxpN
set__UL6lD9GjdAxpN
get__EdL3elp0SogqN
set__EdL3elp0SogqN
System.IO
crpGNO
fxZmUO
v5_rwO
oRwz8Q
zVgeuS
o8bkET
gFiZKU
get__VPDrFqru2WbcV
set__VPDrFqru2WbcV
get__eC6aYzbq4MZHW
set__eC6aYzbq4MZHW
get__56y1NufHqT6qX
set__56y1NufHqT6qX
u4N5eY
u4e0iZ
cYwfC_
__User32_SendMessage__
__Kernel32_GetModuleHandle__
lVGN1a
bI8jaa
e6GHla
z9w_sa
get_Data
cbData
pbData
DownloadData
UploadData
GetData
wTkg8b
yzOSDb
mscorlib
DataBlob
xCWUgc
System.Collections.Generic
fgsh0d
get_Id
dwThreadId
ProcessId
GetProcessById
idThread
add_DomainUnload
add_ErrorDataReceived
add_OutputDataReceived
pReserved
Synchronized
ReadToEnd
command
Append
get_HttpMethod
method
Clipboard
b0Ob2e
Replace
get_AvailableFreeSpace
get_beaconService
set_beaconService
wScanCode
get_ExitCode
keyCode
CompressionMode
FromImage
get_Message
AddRange
EndInvoke
BeginInvoke
IDisposable
ToDouble
RuntimeFieldHandle
RuntimeTypeHandle
GetTypeFromHandle
Rectangle
DownloadFile
IsInRole
WindowsBuiltInRole
Console
hModule
get_MainModule
ProcessModule
dwStyle
set_WindowStyle
ProcessWindowStyle
get_Name
sProcName
get_FileName
set_FileName
GetTempFileName
sFileName
GetFileName
get_ModuleName
lpModuleName
get_MachineName
get_FullName
get_UserName
browserName
get_ProcessName
lpszWindowName
GetProcessesByName
GetDirectoryName
DateTime
get_LastWriteTime
get_CreationTime
BeginErrorReadLine
BeginOutputReadLine
AppendLine
WriteLine
get_NewLine
Combine
LocalMachine
ValueType
get_DriveType
SecurityProtocolType
uMapType
get_Culture
set_Culture
ReadOnlyCollectionBase
ApplicationSettingsBase
get_Response
HttpListenerResponse
response
Dispose
TryParse
MulticastDelegate
DebuggerBrowsableState
EditorBrowsableState
SetApartmentState
lpKeyState
Delete
STAThreadAttribute
CompilerGeneratedAttribute
GuidAttribute
GeneratedCodeAttribute
DebuggerNonUserCodeAttribute
DebuggableAttribute
DebuggerBrowsableAttribute
EditorBrowsableAttribute
ComVisibleAttribute
AssemblyTitleAttribute
XmlTypeAttribute
XmlAttributeAttribute
AssemblyTrademarkAttribute
TargetFrameworkAttribute
XmlEnumAttribute
AssemblyFileVersionAttribute
AssemblyConfigurationAttribute
AssemblyDescriptionAttribute
UnmanagedFunctionPointerAttribute
CompilationRelaxationsAttribute
AssemblyProductAttribute
AssemblyCopyrightAttribute
XmlRootAttribute
XmlArrayAttribute
AssemblyCompanyAttribute
RuntimeCompatibilityAttribute
set_UseShellExecute
ToByte
GetValue
Remove
get_Size
cbSize
Serialize
Deserialize
he9wHf
SizeOf
IndexOf
cchBuff
pwszBuff
_9hL0jBqUkhV5g
_7fRjIuXINEPSg
zXTMWg
get_Jpeg
get_Png
System.Threading
Encoding
System.Drawing.Imaging
Ceiling
get_IsListening
System.Runtime.Versioning
FromBase64String
ToBase64String
DownloadString
FromXmlString
ToString
GetString
Substring
System.Drawing
anal.jpg
_JIo98xYF8KBsg
_PMfSC9bIZA30h
get_LocalPath
GetTempPath
GetFolderPath
get_Width
nWidth
get_Length
EndsWith
StartsWith
ix6oXj
_PtUlArmHfd3bj
_2PH12t8SKvxcj
fzp0mj
sUS03k
get__HQLx9reqcsMOk
set__HQLx9reqcsMOk
AsyncCallback
callback
idHook
AllocHGlobal
FreeHGlobal
Marshal
System.Security.Principal
WindowsPrincipal
System.ComponentModel
kernel32.dll
System.Xml
set_SecurityProtocol
cS1rol
eSaxEm
GZipStream
get_InputStream
get_OutputStream
MemoryStream
lParam
wParam
get_Item
set_Item
OperatingSystem
AsymmetricAlgorithm
Random
_1Iaj8DNLelc1n
TimeSpan
get__Yz0Armcf3LNcn
set__Yz0Armcf3LNcn
CopyFromScreen
AppDomain
get_CurrentDomain
GetFileNameWithoutExtension
get_OSVersion
System.IO.Compression
Application
get_Location
System.Configuration
System.Globalization
System.Xml.Serialization
op_Subtraction
System.Reflection
ProcessModuleCollection
ManagementObjectCollection
HttpListenerPrefixCollection
KeyCollection
op_Addition
CallingConvention
IOException
WebException
pszDescription
CopyTo
FileInfo
CultureInfo
DriveInfo
FileSystemInfo
set_StartInfo
ProcessStartInfo
DirectoryInfo
qpkmAp
Bitmap
yXgmlp
hwndApp
qBKmgq
nKLemq
uzXhPr
ToChar
StringReader
StreamReader
TextReader
RSACryptoServiceProvider
RNGCryptoServiceProvider
StringBuilder
SpecialFolder
IEEERemainder
Buffer
get_ResourceManager
ServicePointManager
ManagementObjectSearcher
DataReceivedEventHandler
System.CodeDom.Compiler
HttpListener
ToUpper
CurrentUser
StringWriter
TextWriter
GetDelegateForFunctionPointer
ToLower
XmlSerializer
set_RedirectStandardError
IEnumerator
ManagementObjectEnumerator
GetEnumerator
RandomNumberGenerator
.cctor
IntPtr
bjoIGs
Graphics
System.Diagnostics
get_TotalSeconds
GetBounds
System.Runtime.InteropServices
System.Runtime.CompilerServices
System.Resources
_lWl1vEyPBn3iy.Properties.Resources.resources
DebuggingModes
GetDirectories
ExpandEnvironmentVariables
GetFiles
get_Modules
GetSubKeyNames
GetProcesses
ReadAllBytes
WriteAllBytes
GetBytes
NextBytes
GetDrives
get_Prefixes
dwPromptFlags
dwFlags
DataReceivedEventArgs
System.Windows.Forms
Contains
System.Collections
get_Chars
RuntimeHelpers
GetCurrentProcess
GetProcAddress
DataFormats
set_Arguments
get_Exists
get_Keys
aRjw3t
Concat
AppendFormat
ImageFormat
Subtract
IDataObject
GetDataObject
ManagementBaseObject
ManagementObject
object
Collect
CryptprotectPromptstruct
System.Net
get_Height
nHeight
op_Explicit
WaitForExit
add_ProcessExit
get__Jm9s63LJyCgjt
set__Jm9s63LJyCgjt
Injvdyrpuetigaudbwwbkt
get_Default
IAsyncResult
result
WebClient
System.Management
Environment
hwndParent
get_Current
GetCurrent
get_Count
GetPathRoot
pPrompt
szPrompt
Encrypt
ThreadStart
Convert
get_Request
HttpListenerRequest
set_RedirectStandardOutput
MoveNext
System.Text
ReadAllText
WriteAllText
pPlainText
pCipherText
HttpListenerContext
GetContext
zMcDAw
get_Now
get_UtcNow
set_CreateNoWindow
zs3_Wx
InitializeArray
ToArray
ToCharArray
get_IsReady
OpenSubKey
ContainsKey
wVirtKey
RegistryKey
System.Security.Cryptography
get_Assembly
GetExecutingAssembly
GetEntryAssembly
set_IsReadOnly
BlockCopy
pEntropy
LoadLibrary
FreeLibrary
ObjectQuery
SelectQuery
CreateDirectory
get_SystemDirectory
GetCurrentDirectory
SetCurrentDirectory
get_RootDirectory
Registry
get_Capacity
op_Equality
op_Inequality
WindowsIdentity
IsNullOrEmpty
m2cQ8z
WrapNonExceptionThrows
324azsd
234asd
234dsf
234sdf
$135f3769-85b9-4bad-8a83-4be170f6ce45
123.432.123.243
.NETFramework,Version=v4.7.2
FrameworkDisplayName
.NET Framework 4.7.2
3System.Resources.Tools.StronglyTypedResourceBuilder
17.0.0.0
KMicrosoft.VisualStudio.Editors.SettingsDesigner.SettingsSingleFileGenerator
17.5.0.0
command
Commands
commands
filename
filedata
filesize
createdDate
modifiedDate
information
report
_CorExeMain
mscoree.dll
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<assemblyIdentity version="1.0.0.0" name="MyApplication.app"/>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v2">
<security>
<requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3">
<requestedExecutionLevel level="asInvoker" uiAccess="false"/>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
Adobe Photoshop
Adobe Photoshop CS6
!"#$%&'()*+,-./0123457698:8;8<8=8>8?8@8A8B8C8D8E8F8G8ONPNQNRNTSUSVSWSXSYSZS[S]\_^a`b`c`d`e`gfhfifkjljmjnjojpjqjrjsjtjujvjwjyx{z|z
%cL_ZerZLLu3
urH]DemJD[ue\J.
ZE,ul)JE
cU+Jw8J
9hK3p/}d
"*~_0*
OF#:EM
g)GOF$7E"
M2pbgB[
; PznIV
a1[U:#
http://cybereason.com/uB78yv4j06?20=1
http://twitter.com/78d0XJWYXX?147=0
http://blog.cyble.com/vcDAvBbAvk?102=0
http://twitter.com/SvaMFTBeYE?94=0
http://google.kz/5Kghs1EjWO?s=73
http://twitter.com/5K5hxiuw87?181=1
_xa5JJWWgOIlbo
;WS!V.b*
<:)+-;y
$<4%.$1!
"4'%4$<7
http://cybereason.com/eQJtPTLM8F?s=161
http://cybereason.com/YZwliMowVX?11=0
http://youtube.kz/fBQEEHgZR8?s=217
http://blog.cyble.com/nBbKH7YSgv?60=0
_OEwXYnB4mdAuf
DEfOaXFmYv^MmGwZ
!%BbDz`
&*B[]gkVCE|kJA\dhBLBjj
8WF[]pXGETqCXAUf\[EVp]YE
RYlZaJX{FaR_xP`\\
}Hj@NpI}GVvVp_Jv_
m@]UDy]@W\f_DOC`\HYBo_
2BlFMw
XDC[AVEUZYSSYDNX_XY
e]LjTqDP}Qo\R`WeJSjV
WWkECCIwF[\HjBB[B|CM]
C@OU_AWU
8]F[yQG
[ZZcXB@`
;1$VW`v`BJ~sz]LawgTBwul\
cM`rSoL~zTw[xmPjPu{RaR
A/bX
%BcVJ`
0HOEUp
X\ZsFZ]DuALKCoFT@OyOZK
3EUIAv
1"}]Eter\Xq|uB^k`vKP}b
1.HTAjk
O|U~_G}CvHDjLaWLb@{RF
N|i}CZatqYEewgBDir}D
hDLbKkERbF|^U}A`]YkCj[
=iXWXzfYI^u}DAGxcM@Yuc
<_FdD|]Gy[vWG}BuQ]x
8"G%Ocy
= "wz=|[Nq#
=?P|E|AO
'^-C7%u)3/o*/"-{).
mq$5'Z1
D>(h'Gj=A
C;EcEJ
n8v?eH
DmUoB[o
T~RcMGs'.
8J6AW
8J6AW
cLYoX"
DmVcLE.
|PKmZ}
*YcC[qX
|PHmZ}
rFpPGs
rFpPGs
|PHmZ}
*YcC[qX
*YcC[qX
|PHmZ}
DmUcLE.
*YcC[qX
2.SsK2
/!:82
DmPcLE.
|PImZ}
|PImZ}
*YcB[qX
DmTcLE.
*YcB[qX
|PImZ}
Q7\w[\
rFpPGs
DmTcLE.
DmTcLE.
<-a[~ME`
*YcB[qX
|PImZ}
*YcB[qX
rFtPGs
&LS<_~MFp[~MFp[~MFp[~.S<Xn
rFqPGs
|PImZ}
rFqPGs
|PImZ}
rFqPGs
rFqPGs
(ZkNV<
&LSsK2
DmTcLE.
rFqPGs
rFqPGs
DmWcLE.
DmWcLE.
*YcA[qX
rFrPGs
rFrPGs
DmTcLE.
+NzXW?
+ZaRE`
xT~j+6T
'c!Y3L%t1}2c
`1)) a
2K cq|5f
Jk/[=Gjb
http://twitter.com/fheJKe6dsz?s=164
http://cyware.com/edrAMu00yY?76=0
http://cybereason.com/f7XILP3iv4?s=144
http://cybereason.com/kab2j0o72m?132=2
http://cyware.com/cPxvDHYsub?161=2
http://blog.cyble.com/enzpzgmxCp?157=1
http://cyware.com/Eqc7wEga9v?18=2
http://google.kz/3gorgcHA4x?s=202
_g6vj491XNz9Yl
_7d7Q1EUNcNUoJ
_0jCN1Gt5CnsA4
9t<N9l
Or 63Bsm
<*Pd%<
http://cyware.com/AriQKUuTUc?s=60
http://blog.cyble.com/tWCTBN4AQy?83=0
http://cyware.com/WnS23f83eA?s=122
_NULdFepmhZmlm
_Dcyu7auJ1ZdyE
_X828TXOEpV4uK
http://twitter.com/f10RkK61wN?197=0
?$4. 6
http://google.kz/SNd3vAWXzu?s=65
http://twitter.com/FUWe855gLn?s=97
Mt[>K(
3e![%X#t3k&e
$,rJT"lY
!w"U/J1w=a4w
http://google.kz/5N5Gv78Z7d?s=194
http://twitter.com/WH9wfqrwQI?s=18
http://google.kz/snZb5ImzuY?203=1
http://blog.cyble.com/MNj56kFeqD?s=81
http://google.kz/CNhPDG057N?s=89
http://cybereason.com/oQJb3GUymA?s=13
http://youtube.kz/G4XvFNPg1L?27=1
_lzuUUqB6PijX5
_O4kxQndgWK6Jz
_vVXJpoGleaKt7
_7wvnhnajgVSkw
_RgtlokmgbzM27
$` \"O&u4l1`
T'J4H1O3KE
#+Xs#"
C!H'A&I1XL
http://cybereason.com/ukGjzHqunN?s=9
http://youtube.kz/moVu3SYvxQ?147=0
,A=H!G
!<;4"@
3C!\q[:^QX
Oz]X)B{
%<1*6+;
(,}X<4
$5,.2<A
<d 1/=p
$9,5/=
&A%!e-7
:4h[3&
W5B*G?{<l"W
http://youtube.kz/n5pJn26YsG?106=2
http://twitter.com/AVHwxwUtwJ?185=0
http://youtube.kz/QQ4Z1qQT2Y?s=1
http://cybereason.com/de2GhgMoGn?s=144
http://youtube.kz/PNaWRUQmcN?s=49
http://cybereason.com/eTUM3VIlId?s=69
http://youtube.kz/vNKzHG6mpr?79=2
http://youtube.kz/RvUazGVT6l?s=59
http://twitter.com/uwFVsFpQtQ?s=23
http://blog.cyble.com/36XAhAh7YD?144=1
http://blog.cyble.com/Q6k9hPMPJd?228=2
http://blog.cyble.com/uYIYeLyn1T?s=156
http://twitter.com/Vb2MdD5b7I?149=0
http://cyware.com/i31Vvq0ExZ?s=57
http://cybereason.com/jvxm5HTUlS?s=74
http://cyware.com/hKO8byy4cV?118=0
http://youtube.kz/IXcTm4dAOX?69=1
http://blog.cyble.com/mrCZvcZrsw?s=121
http://twitter.com/0My2dPrz2a?s=27
http://youtube.kz/NXgcuwl13a?156=1
http://cyware.com/wR0i9mnGvh?0=0
http://google.kz/M82hfWR7nN?s=118
_CpGx1aXAFNC4u
_f7w9EVnMhwGCH
_knKDJuagmp9Mn
_VxKEprq6wAH7f
_xoOp8todV52Sx
_14g2YrdpRBg8c
_WNxafLSHWAMGl
_u39hvZhclwRJy
_OgIlP5h7JPTcA
_Qj9UM7yj0QzLh
9Xwv:TBw0f
$5]sH4rGs
h7W2[y%YE
cHGYPnIXFRwVRYZnPZG
</vB3 v
t#;#X:
zE!&Zt]v
!H-f^f
)t-@$B2x(j<t
d_QT[\RP
7rj;#
!I6lWJ
l`KD/.XFEb
http://google.kz/rNjbhNv2H7?65=2
http://cyware.com/LEjO2boEry?125=1
http://cyware.com/RbthwfrcXz?84=0
http://cybereason.com/cpxzWRKmNA?217=2
http://cybereason.com/YFE11Jmq2W?98=0
http://youtube.kz/VxlXC9BrGN?s=154
http://google.kz/L4xRDuCClc?s=173
http://youtube.kz/w9EL1bPaVx?152=2
http://twitter.com/vyYMsnuvwQ?s=194
_H1ltW89lEWzHw
_JMzyFg6a26VB6
_K5sCY2ws0z8S5
E7ESH-y;
>!&2++',#6
$<YFc!:6!c0
Y J9Z<H3FW
Gsi1K"
*f<@-A i(c?f
[;Y j"DT
H*K/W6l.G.Ia
$40Q?0
U2(*?Q/
db?9+cI
42310/_
http://blog.cyble.com/8LRAjeh6l2?223=0
http://youtube.kz/6CkJzxieS3?121=1
http://blog.cyble.com/qwVGCo9KUI?s=35
http://cybereason.com/OeY1bapngZ?176=0
http://twitter.com/CIKMyfZeV1?s=13
http://cybereason.com/1DaFPP4Yoa?s=72
http://cybereason.com/RfBbrMWv8h?214=1
http://twitter.com/3ViOu9bBGa?23=0
http://twitter.com/COOWjKUH4E?4=0
http://google.kz/Myi9OZy8NA?8=1
_JR1zmSLUfUNSI
_5lTr330ziyZVu
_bzrohWmBxLtwy
_aTwKA08imfyWN
_IYEaqXQ6jOIam
_CKZG2geDuJFZG
_GYIaSJmMBVIly
,7)=HY
http://twitter.com/67717rhX6C?s=54
VsBWmR
Z0U0B?X,OO
>"a"!:
h8tD%O
|E{._12
9B'Xsw<a=
_0wP8d904QNYAf
_%KwA!c.8^n
R+D*N7C=UC
@Sg=QfZ?
K&H>T#h6x1K
1_5\uY&JQ\
+{42=-
xw>4<c
J*/`!#44
$G(^c[J
AG$86p
F1R/C8w7G:Gz
O+N}l6TCT.
http://google.kz/KulKjZgKoq?171=2
http://twitter.com/s0WSqmjGLP?203=0
http://google.kz/CNpZY9tBPd?20=1
http://cybereason.com/wtVUV8pZ6I?s=100
http://cybereason.com/OaG3SpCBYW?43=0
http://youtube.kz/TN71CUoYxC?s=155
http://cyware.com/7RMeoGiwlb?199=1
http://cybereason.com/rheBkVynpb?229=1
_GkyWKC8efX3F7
_ihogGXJWifCP7
_fkqiGiTyWpAq5
_xyucELCKVLlzm
DYT2H:1Z1E
"GCT9I
<w7GsT
f-Mq!$
http://cyware.com/LhrI0bAVug?49=2
?'f!0"
;)>&1&9$,
4{<r4_=i
^v%0;Swh
-R3sC7
:6PzB=:N3B'
kBJI=^}3f
(D4XZC
5X%J3^
Q"+Eg{
1l9I"Z*l!l$l
$;VWHay[VW~{BI]+{
6*G%B$-4
http://twitter.com/MW3w07Eq7H?65=2
http://twitter.com/uPbarpDBll?s=167
http://cyware.com/ZN5noaxoFs?128=0
http://youtube.kz/654klEabLf?21=2
http://google.kz/AZOhtdphCc?181=0
http://blog.cyble.com/hDkL1HKSHM?165=2
http://blog.cyble.com/HI9jKTCc2P?164=1
http://google.kz/U5itRkEtGs?188=2
http://cyware.com/Cf3mkXcw1n?207=1
http://blog.cyble.com/IrIKhkMysl?s=180
http://blog.cyble.com/Qrpkerg3IZ?196=1
http://twitter.com/tnUnkp3yEW?32=0
http://cybereason.com/vipU8myIdt?199=0
http://cyware.com/9PPBQhwIBU?s=133
http://cybereason.com/5hAK2ipE3x?s=224
http://youtube.kz/17o3rUqVHi?s=24
http://cyware.com/LJnxP28TF0?s=91
_4m3NXGDYEHmKe
_lBGaGOdu6UQd0
_vBrL6qJEhG81G
_cQQWSJQ5QHpPv
HkWTMRJQgz
_jHvyQ7KZRuYJt
_UTjM5FrWEsF4n
_pyVrZGrKQ3IF7
_wz2iMhslj9ac0
_YysVUlWeIKAUg
_PfUG13LzvOR0j
_Rfh2fLcMinDVn
@tS\F(J
+K(fqe5n
Jc*[$Gbg
@+>8/a
)-c!*:';6
http://youtube.kz/pnTFkYVP2l?194=2
http://cybereason.com/sKgQsETcax?92=1
http://twitter.com/BvKbhEkTMe?s=10
http://google.kz/w3zB75likf?100=1
http://twitter.com/TeUuEMGtjl?s=186
Unknown
9375CFF0413111d3B88A00104B2A6676
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
Comments
mb56965701e25a49ca1b2dabf62c8872dd214
CompanyName
Cf53a2a8a97c8f27177b5846bf180ad1e04e86f
FileDescription
ld18f1eb02c303cedfcb2cc95ca21ffa7
FileVersion
88.11.20.89
InternalName
O45a7cf3ce4b126a2bcba0c0691e4095c.exe
LegalCopyright
radfff113dbe68085dea7128da924a38b9c48
LegalTrademarks
z2f3e65936fd89ff055fd347f9ffe597c
OriginalFilename
J73d279b82e4387f5da7f.exe
ProductName
ia0b077ebbed518b1a7b7b5349763af328ae4
ProductVersion
80.70.25.67
Assembly Version
93.73.34.19
Antivirus Signature
Bkav W32.Common.E51305BD
Lionic Trojan.Win32.Stealer.12!c
tehtris Clean
DrWeb Trojan.PWS.Steam.35877
MicroWorld-eScan Trojan.GenericKD.68015707
ClamAV Clean
FireEye Generic.mg.a338043c6b5260df
CAT-QuickHeal Clean
McAfee GenericRXVZ-KO!A338043C6B52
Malwarebytes Malware.AI.556753282
VIPRE Trojan.GenericKD.68015707
Sangfor Suspicious.Win32.Save.a
CrowdStrike win/malicious_confidence_100% (W)
BitDefender Trojan.GenericKD.68015707
K7GW Spyware ( 005a5a201 )
K7AntiVirus Spyware ( 005a5a201 )
BitDefenderTheta Gen:NN.ZemsilF.36662.Em0@a0LxNQi
VirIT Trojan.Win32.GenusT.DIVL
Cyren W32/ABRisk.MUQV-5851
Symantec ML.Attribute.HighConfidence
Elastic malicious (high confidence)
ESET-NOD32 a variant of MSIL/Spy.WhiteSnake.G
APEX Malicious
Paloalto Clean
Cynet Malicious (score: 100)
Kaspersky HEUR:Trojan-PSW.MSIL.Stealer.gen
Alibaba TrojanPSW:MSIL/Stealer.86032e5d
NANO-Antivirus Trojan.Win32.Stealer.jwmvck
ViRobot Trojan.Win.Z.Mardom.501760.A
Rising Spyware.WhiteSnake!8.17C86 (CLOUD)
Sophos Mal/Generic-S
F-Secure Trojan.TR/Redcap.nfugi
Baidu Clean
Zillya Trojan.Stealer.Win32.74501
TrendMicro TrojanSpy.Win32.WHITESNAKE.YXDEWZ
McAfee-GW-Edition GenericRXVZ-KO!A338043C6B52
Trapmine Clean
CMC Clean
Emsisoft Trojan.GenericKD.68015707 (B)
Ikarus Trojan-Spy.MSIL.Whitesnake
GData Trojan.GenericKD.68015707
Jiangmin Clean
Webroot W32.Trojan.Whitesnake
Avira TR/Redcap.nfugi
MAX malware (ai score=100)
Antiy-AVL Trojan[PSW]/MSIL.Stealer
Gridinsoft Clean
Xcitium Clean
Arcabit Trojan.Generic.D40DD65B
SUPERAntiSpyware Clean
ZoneAlarm HEUR:Trojan-PSW.MSIL.Stealer.gen
Microsoft Trojan:MSIL/WhiteSnake.AWI!MTB
Google Detected
AhnLab-V3 Trojan/Win.WhiteSnake.C5423097
Acronis Clean
VBA32 TScope.Trojan.MSIL
ALYac Trojan.PSW.WhiteSnake
TACHYON Clean
DeepInstinct MALICIOUS
Cylance unsafe
Panda Trj/Chgt.AD
Zoner Clean
TrendMicro-HouseCall TrojanSpy.Win32.WHITESNAKE.YXDEWZ
Tencent Malware.Win32.Gencirc.13bf3518
Yandex Clean
SentinelOne Static AI - Malicious PE
MaxSecure Trojan.Malware.74396735.susgen
Fortinet MSIL/WhiteSnake.F!tr
AVG Win32:SpywareX-gen [Trj]
Avast Win32:SpywareX-gen [Trj]
No IRMA results available.