Static | ZeroBOX

PE Compile Time

2023-09-19 13:33:32

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x0003ab64 0x0003ac00 5.31998155048
.rsrc 0x0003e000 0x00000546 0x00000600 4.00061054361
.reloc 0x00040000 0x0000000c 0x00000200 0.101910425663

Resources

Name Offset Size Language Sub-language File type
RT_VERSION 0x0003e0a0 0x000002bc LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_MANIFEST 0x0003e35c 0x000001ea LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with CRLF line terminators

Imports

Library mscoree.dll:
0x402000 _CorExeMain

!This program cannot be run in DOS mode.
`.rsrc
@.reloc
com.apple.Safari
Unable to resolve HTTP prox
ki|f#ikmae
snw-dlo,
qpiu2iexi
UX=qa?
va-7h`dY
C5mTcy
QQGPFFc
_|'4a-7c
sF*<#.)N
pEzPWszEZdHoLWNlTw
VwrRZy
Wl~kru||
P\OZXQXI
9{;wg9
N Juvc
O=P/7:
H(Swdc]q
-4,':&(
eo|e}VwusBi
Yd)(_b
Lq:'+l
o1-7yuhY-ihd}bN3
oixcB,i~yoi_,
{chbe[$
>ZG\KM\GZx
ZMCKAx
DIA\FMLMZk
[_GLFA
Y[DIA\FMLMZk
[_GLFA
DLnbcaa
b{o``d{e
5CNF[AJKJ]l
KJKAJ[Wj
\X@KAFx$
!"83;3:
35$#9%3
:Lm1NT_W_V
HUN[YSNT_RNO{J
PMJDLO|TLT
NJRYSTj
TO\[\n8
-jraar/
OFAZ\[
gHWZROU^_^IxgO]THTIXRvg
imuhX:KK
5"40(5
3)"$)"
QjFM4=87>#
?:, ;=',
$JA\TVGRP
):,1)--?
5wa|d``rCcg~@
HZq`LKQJP\\~c
v[[MZLLiDAIEm
kYMDC^^Oy
r~cRbtiquugVcpgU
>j~wpmm|J
xmm{lzz_plkj{L
tkR}z}:gqx}r{fd
u.+#/o15#.
X>/.*<1>
AYTFjPFTG]EFFTEjGPAFTX$
~EESDRRW
#HRIS__]
b`cbuce||q
+gzpzmp:s}rz{wHfq`updAHzmP
\5#>&""0!
]drowssap
-|-9IDG
>ygaYRGx
{oanfgkTA]O%FX^fmxGTmzi
[yq}rnyoi
elsnhry
WqJDKCBNqc}{CH]bq
sseccA tenretnI etavirP
<BDSRUW6
RTNq{dj*z!7>;
?3 5=
;j98$=y#9"8446
:|watpv|d|;3?0,;-+|tp
sAAWQQs
FW\@WF\{
WFSD[@b
)tubqubtsibdbu[fkkn]bknA[
{sfsvbbs
K\OK\j
::j(bdyF*
U\[V]Q\W
,*)ddvG8+
aewTC^r
lf`eoflpr~
CCUHPTTFw
0?.*>0
nW@SW@v
&+78TCUs
V-*-j40"
,'0-374
kw:CPW
)mI0#$
T!0nyxr}qqs_lhZ
&*&|&!;>"&
76<3??=
{dj*zr!7>;
r?3 5=
{vovzv,vqknrvD^rvda^;
X_E@\Xjp^IHBMAACo
AM^KC^|pI^CX
@MYX^EzpB
Fq/uyu/urhmquG]dytmdE!sdeo`llnB!QUG](79y)!rdmhG!l`sfnsQ]dsnuRm`tushW]
q)x!7*266$
{3|k}[5
>revres<
!6%!6 o
4v-%)&
:->:-;t
+qgzbffteJgpf`Jgpcgpf)
%1$14 1
RHSIEEgz
o)*+$%&' !"#<=>?89:;4567012
jkdefg`abc~x
afy;gpqyzS
)>3=80
M~ZZHy
ZA[@ZVVt
rEAABZ[ar]KBGHA\~rEAABZ[ar
rKMGHHarZHA]A\MGcrK\OYZHA}
2BQ2-2
?O?;"<
!\YQ]u
nLIAMe
+= 8<<.o|
5E511-
5#>&""0
9^Z@JOLsPMLJWSF@[fFWBWpGFWSVQQL`Z@BDFO|PVOsnl`
uaLdh`mfV
pPZ@KCKBkWZGZ@KJg^
s*S^dRPV\TVgG
aYv`}eaasbq|ka
%*$3%#)"83$$#5)/3=>
XQ_\IH^XEx/
ak[^VZOXqkOXQXERvkREV@CQXdkerdbhcyreebthnr|
XyepA}xp|i~W
PHMEIxHMEI\KbxWAHMb
IEVCKVtxAVKPwHEQPVMrx(
daieTdaiepgNT!>0p ({mdaN(eizogzXTmzg|[di}|za^T
LVMW[[yd
m{f~zzhY:YFY
UFQD{
nl|jkw,
`ihgfedcba*)('&
?>=<;:9
/(=8r/(2)3??=
(2950|
khkbnwcbn
`6`4Nah17553;5l
]KGZGZ@KJg\KJ@K}
^pmjpkq}}_
@G]F\PPr
@HDKW@Vp
4\]KVNJJXi]\MI@KZW|
pUCXS]XP|
uv :.M@Xbok\$
`P.~(2&EHPjgcT
m4CNVniW\CNVlaeR\ERAWTFOS
vESNVRR@q
8/<*);2
W|jwokkyHtwjlvw[8[VNlp
eDS@DSejux`B^Q_bjSDWABPYe
J#}_RJny{uH
)?":>>,
wux`WDBZc
:.8HE]jy
R+,+l!,4#06.7
# 4 b!,47
4~3*|okkyh
?YOFClGKXMEXz
\QI^MKSJc|qi^MKSjc^]I]\QIJc
x/he}JY_G~
d2!%%7&
7;(=5(
yOJkx||n
8OBZm~x`Y
d<v+4:z*qgnkDocpempR
utqN"< 2`wvs}~|e}VXG
3!$/@YV
@T]ZGGV`AV__\AG]\p]\ZGRPZG]V[GFr
]\ZGRPZG]V[GFR
T]Z__\AG]\P
@GJ_GJ{<
#/]>]%]2/
bz~~l}
N02>s61<)1<-
WP^]Pi
SP\PKPMO
0bamaza|~!2
&?v-%)&t
[MPHLL^O
Gp*<!9==/>ar
Yp6ishr~~\
J61+0*&&
"+1*0<<
zoyd|xxj[
9,)c,9,)
%.#(/&?":
%.#(/&?"
[w`bdkdH%w`adjikrjA%q`kw`qkL#
6+'7-
TB_SCYt
?*<8,:'+;!,
>979"?
Fx,<%(?
-;&>::(9
cbrkfqXcuhpttfw
#5(044&7
9!8,+(
xtatQ5{|rzYI
^Zvp: mq
wFp,$5(
\:em|a
/)cy4(&
!@-<)>!:
-mk!<vjd
h,<42?4z3%8 $$6'
gAC5E4F4G4QEX
5M5)(<2
rqyuzfqgApq`dmfwzq
16*+?1
f{y{{>
IAMB^I_y&!
P/5k}`x||n_
|"8lmkvcaknrrC
g}#5(044&
n.2(|}{fsq{~bbS,`p.
4xb64xh6
*=+/7*
-:)?<.'
.OL|i|Y=oxnHAu~orI
eJBLHd
mxmH,~i
YPckeaM
dw`sC%
4#51)4
#4'12 )
-H4GYBIHEn
]1agebxy|_
(*-763
(*-763
_srz|oY=ryrpr^
OIRTIc
xoy}exH*:<9
si~hltiY;tzy~rW
S==-*,
0'15-0
b16,'/'.
/VWOWW{
5U7HLP^[ZxTPf
Eprd.2$
#4=)>9"
(42?./(#8>+c
[L|r54>7>
|LxJKAHAi
/z'706
W^Cgpymzk~HC
lDS^HOSl
MOnijniooo
+n5"#5(j"3>%g"1.3&)gkug)(.45"1gk/4&
)qRsztwb
`BK2@WUWF\[
~{v~cyrsreT7d`xsy~@
g\DLNSIB
_CPYR{CTR]Ux
]\Wu_VQVQYP{
<:-,!>':
h->!<!%!:
h<.';':+!
hdkdychiD#hcbW7
QUHTTBDHUwx
sdbkbt
ncXEYYOIEXZ$
z.w+}.x+z}|}b
.b{zw{b-.{{bvz{)v.*~
H5"%*2
!8lj9m9<;?j?epm;8ep;;<ip;djlpn<>l9nm9
@AGZ^OM
g`hey&}ql}
3"83;#592
`Y$]MMMMMMMMMMMMMMMMMMMMMMMMMMM
U<F2(g.uo0%,
x!;0!;:
gm&%mu} m&}g8'4
8:</2)
s'j!rzbhz4;2.z))?6z)3z?=;(5.
#.(?*5(
>? 36;3(?
z?2.z<5z? 3
@)}1{( }0{ ot lauqe ton si noisreV&
D#n%~d;+2?
nd/,d|t)d/tn1.=
>$p<v%-p=v-by-alx|h-ybc-~d-h`lCjcd
y^-hey-kb-hwd^.
D[HrDTM@w
EROTsYTREPORpDEZILAIREs
XORInDIOXMROmYXGTQ\TOXn
!kEXCTRE^SReYVZYV{kRT^ARsk
1SPS*
KDBM((
v4.0.30319
#Strings
";EMS]e
6 V z
!.!v!|!
!f"n"|"
uFuaYK00
qZhYfH30
vFT5J0
Gu13Y0
60GozV5Y0
ml6eMm0
IpzIfBwo0
HMACSHA1
Cs9PYeD1
svSClQi8N1
hbQGP1
ks5OrFhAQ1
5w8bC02UX1
kgZV66efY1
IEnumerable`1
ICollection`1
IEnumerator`1
IList`1
CS$<>9__CachedAnonymousMethodDelegate1
1K7sWLm1
get_Item1
c2fi7jGKvo1
FCMkmBq1
G4fOBy1
kzlTy1
HMACSHA512
Advapi32
kernel32
Microsoft.Win32
user32
ToUInt32
ReadInt32
ToInt32
SBGXA2
bgGPUr7pgC2
mqVEFf099K2
KeyValuePair`2
Dictionary`2
eJnIa2
sYIJa2
get_Item2
yZRYA3oGp2
bsjdq1Wq2
EqEy9Pz2
ZNs4TNTt53
0Rey73
BPB0F3
W80TR6DteN3
IQuvN3
NpnorTGhaO3
qlV8eTiRQ3
Tuple`3
get_Item3
bEZ9cWBq3
go6Nm1ejw3
qDowDd34
WV1Wb7pjm64
ToUInt64
ReadInt64
ToInt64
AMgJz694
e9UAReVY4
4eaub4
KAvT3lwb4
73f756cf-fa55-47c1-bf93-f353acf8c3c4
HxK0Sp4e4
VeGu6ue4
dDOaQf4
F4vsr4
N21bv25
cSa3DrNrK5
gketK5
tStb5rWCvb5
FJ1Ms5
yq7BF5TK5w5
DCEBgiex5
ul3k8GCy5
HpEmf3Ty5
4VeWR8FGDz5
y2gAg16
ToUInt16
ReadInt16
ToInt16
HMACSHA256
DZjoX66
WTnq5qA6
uqqHB6
jCfSR4BI6
6PAhM6
6Gq6fu6ZR6
63xlR6
dKzwT6
qpzSU6
vBiqv6W6
yBNpgj6
SMyZl6
wUdho6
Nbs6Ku6
78x9aHjdv6
mtWpw6
zg6z17
1ZP387
JJxn2rB7
vnJc3QnlCI7
VaultGetItem_WIN7
bfv6KQOV7
9IX4hW7
do0HJsAsf7
WIfUDm7
7P1bem7
rZ6yXIu7
tk6st18
qUHeP7TC8
HpO8NodC8
get_UTF8
IUhRPhGG8
VaultGetItem_WIN8
uBjGwXX8
dWiruzZtXc8
gchoMUgi8
thSe7Usn8
LYer1Atw8
pKGLz8
X72rR3ya69
0GjiK9
YrpbifOdL9
9gYYFdnvYP9
w87IGS9
CVMR8ych9
2256fBk9
H4tBzMVjEm9
d2ern9
zvMZZL0Hp9
dwSj9t9
MvsXyrou9
phdxqu9
<Module>
ynLg430GA
4uopjRA
wOPzbCYhSA
ZSZg9KRcA
OcCG0mgO3gA
thPzgA
16O4CMmjA
8J7wlA
U4VxlA
SQd8cjXNI3B
eWL8vx3B
UktpAB
EsxiusiPVB
m098P7OzgbB
hJTSvqeB
oor2zcaAlB
fmxemB
W0VeoB
LiZGr9RjvqB
qKeLluB
rCEdDST954C
fvE8PGC5GC
xisyYGRCGC
IM9RBDbC
wUB8cC
IPpmgC
PbvT3lC
DSc4XLvTSlC
XMT0wuJqC
GyTGcjkyC
LBQk7p0D
6UqQsz0D
ctItpYnpp9D
C0EN5ED
get_ID
set_ID
fileHandleID
lpdwProcessID
processID
get_FormatID
set_FormatID
ShUohfhMD
wAPabzuPD
LwYcXD
2nzgfghOYD
z39JySYD
F9ATh5nSiD
Fw0pIpiD
LcqwzzJlojD
NnNQ1ilanD
kjt8MjyD
kH5glhYd4E
4ZeI6PXAE
l2C0NDE
kIAarflFME
BOaQjWE
xbmvjVXKedE
vBwwqIFWBfE
mJIMGme5hE
nqejiE
SkArU1dvxjE
8VFYpWOVGtE
dXAaKCYVvE
h97tW4510F
bO4sbO0F
sj5P8Z1F
ayPwxB6K2F
y8l0jL3F
gD536mi7F
NrM6qqMF
fs01cIwTF
HI6yJfdF
fDXhfF
vklvplyhF
j63WCugbalF
bDKrSHrwXoF
iBC0qF
dPHfg1n6xF
5KybjMyF
QPfaQU8G
0odVCnc29G
jWLS4SDG
DsvYGG
2TIQBYW0XG
ZKCrkDLXG
40bWlYG
4tFyfq77aG
x70k8EhG
LNJm1FhG
RSp94IbmG
Gcp8wtG
dQeEvG
Q17nn4uywG
VPMMg3H
MwJ64H
nRkbsfOh8H
mpgLAT8qEH
h3tDZLH
JD8KOH
y9viXNlQH
oEWHwXDrpcH
zPebQhnAffH
K0tYDBf8nH
5KWroH
6e7vbqH
h1pwK9AxqH
98IlpyH
c2ddKcJaB2I
aJppgPjbBI
get_ASCII
5qzdHJI
J803IkLLI
shNMsCamDcI
seHlIGfI
d5gPJxvZUgI
EsQrhI
wma7VwywI
ucYCZ6nixI
ZFuzzx4RT5J
RRhY7zSyz5J
ucuK9J
ps1uZUBJ
LdQOaYAeeNJ
8lq5FBe9VPJ
0iaaLGQoXJ
cVMUlfJ
LWULsoJ
jUsZ2vJ
370zUXxJ
Bc2Rn92u02K
x0x90L2K
5mgvEEsU5K
qOvGyDns5K
fwzmQCK
X8BGjoHK
utHC92k7JK
Z4InJOuVKK
lRptHSK
rdEyv8MdbK
yGgJU7tNeK
5EW3DwnlgK
7z4G6sd5HuK
fjl2tqOGzK
iuk4PbvEAL
LbkvEL
p7PfoFL
8r4f7OiFLL
SWGDXBhLL
6D2ImNL
8WD7HXMRL
epS3TL
El7ZCXtVL
gCzN5wYL
M1jYhJDbL
ljPxrdL
EUWSqVbfL
6l42JGrL
ySLoHpaf7wL
RtOf8pjlyxL
JxvEqK6M
lBPHFM
W5RdZXcFM
MQOVYi7GM
BDz0V2MM
wIvEF0gUWPM
nq9w1QM
DddL3qNrTcM
xJ9T97TeM
DLG4fM
3UJpFkqM
d1PLcpCN
sZ4c6AtwEN
nCgpHN
T6uJeIN
gvPJDuON
HC7KGxgPN
7qyN3ezVN
oPhxjQWN
PBZoRvAYHdN
ZKcOdN
7S0sXVPdgN
BfXLiN
8HEj15SVjN
Lm37ijN
lbqHh3LkN
5ufyyN
X2RQBgazo3O
Feb16O
oILg7O
wsXnHO
System.IO
B8Tf76KO
dQYj26ZAgKO
Whu9p1pbLO
AiMMCgXNO
SXVM0OO
sG3QhO
la7H99nrRrO
DLPawXh9P
jEXqqIOqFBP
UlM3wDP
eVYHIiCgeP
SHphhP
yKb65Q
AfJHzufgAQ
eTgstyotaEQ
Lq67leWQIQ
YEV7sv9WQ
IAR1MZbQ
5IVdWjfQ
l0YYpQ
aANkagvuG3R
Pb56Rar3R
zLNFCR
i5F5L6WvCR
Htl9SR
r9CWBozSR
XDRzfW23VR
TnN3ZR
wLjwZaR
iXMKniR
SG0VhmR
WoOPgOldnR
4FYrE0MsuR
Eh0IwR
6kxwL6oP4S
d9V9l6S
D0IbKy9S
mYZdNEpHS
u3PuNS
50ViQS
iJ1yQS
xRa8cbXS
7CiBuyNBpXS
spbxryM7nYS
mg3KagS
FfZuQH1aV4T
ZUcpszOB7T
1KCjrW9CT
sOt6gZIT
U7NXoJT
76YTI4KT
us3sCosFrPT
CSdTbT
BhalvzgT
QKj13iT
YOrDgSjT
8JbU6f1knT
hyDFyXyEuT
9NiU8GhekxT
cCQkbnJZ0U
MsWEjUFWm3U
p9fgko6U
Il9IUvxEU
vqSH3u0NU
xx8NzLpVHYU
P0bn0KmSYU
AbLgoGHhU
RSwDjU
l46NlU
QliCLaCrU
So9B1uU
kGGd51V
DJVbwVr2V
3Flc9OBDV
get_IV
set_IV
OBmjPV
f35sAUVnV
CGYwnV
s5sU9rV
1FysK1T4W
H28w6T6W
w37yivgYEW
d7kY9FW
rN98SBOW
tCNyCtF7kdW
1egGqliW
7ee2o3pW
Hr0wFMLriyW
qzML1X
zdGzrH4E2X
smQslV3rZ3X
V4p7wqOX
s85HZqGPX
w9M7lSX
4VAiQCtufVX
w4yLvSq36gX
VZJ0WpJhX
QPYuOoYM4iX
ZllKjX
zzOGmX
MpYdwSBoX
kNCQvoX
qIxRAPVJmsX
oUyntX
6qDszjf0Y
NlsHDz4Y
gDhz72KwN8Y
4zdVYY
5payzqeY
vJSalY
4uzzxY
I0zH2Z
DQCQIj5Z
W3GtEHZ
gTsKZLZ
VmuLe9IOZ
osWNe2cZ
8USIdZ
nkQJp2cfZ
qUHnggiZ
fgVWJtZ
jbi6pEuZ
6iEfkCq4a
BXr55i9a
ShkRl9qvBa
ZPRJ2t9rEa
YKej3xG0ZFa
kEYpws5OjQa
bsYvxO9Va
hZvxV26xWa
sAlTXa
ivGxida
0JFGzQCPxha
PZCKdNInVia
get_Data
set_Data
ProtectedData
PropertyData
hW9lta
UfgcC7ua
EY68hya
VMROXh9b
bwrKU4Cb
29h3zdxbIb
cZ7pJLb
sGgs8In7Qb
lUFjHvRRb
LNv61Wb
mHN6Pcb
CdqCjMOeb
mscorlib
H9DgI0wqb
z236Nfrb
BMTu3X1c
XeJsQtL2c
qlbm32qGAc
dl26uYO1Fc
k5RXHc
ZiAwBm3QKc
UuDbOcedKc
Fhc7JSMc
ZjeCiXc
System.Collections.Generic
Microsoft.VisualBasic
EbpXgI0nc
WndProc
HookProc
FromFileTimeUtc
bM9UzL9q3d
get_Id
schemaId
pszAlgId
GetWindowThreadProcessId
processId
vF33HsMd
NcEnVd
qVNfzwBWd
TOemJuiWwXd
OpenRead
25jRufbIed
lpcbNeeded
SHA1Managed
RijndaelManaged
add_Changed
remove_Changed
get_LastModified
set_LastModified
_lastModified
Interlocked
set_Enabled
get_IsEnabled
set_IsEnabled
_enabled
lpOverlapped
samDesired
add_Elapsed
get_LastAccessed
set_LastAccessed
_lastAccessed
get_Reserved
reserved
System.Collections.Specialized
Yc6w9id
pPackageSid
get_IsInvalid
get_Guid
vaultGuid
<ID>k__BackingField
<FormatID>k__BackingField
<Data>k__BackingField
<LastModified>k__BackingField
<IsEnabled>k__BackingField
<LastAccessed>k__BackingField
<Password>k__BackingField
<password>k__BackingField
<PropertyStorage>k__BackingField
<Name>k__BackingField
<FileName>k__BackingField
<ApplicationName>k__BackingField
<Username>k__BackingField
<username>k__BackingField
<Type>k__BackingField
<type>k__BackingField
<TypedPropertyValue>k__BackingField
<Size>k__BackingField
<IsRunning>k__BackingField
<Path>k__BackingField
<hostmask>k__BackingField
<Version>k__BackingField
<Application>k__BackingField
<Description>k__BackingField
<user>k__BackingField
<hoster>k__BackingField
<Tasks>k__BackingField
<objects>k__BackingField
<Accounts>k__BackingField
<Keys>k__BackingField
<Lenght>k__BackingField
<Host>k__BackingField
<GuidMasterKey>k__BackingField
GetField
TrimEnd
ReadToEnd
Append
get_Millisecond
GetUpperBound
GetLowerBound
set_Method
method
Clipboard
get_Password
set_Password
get_password
set_password
Aof7FCNl4sd
IkaoJzd
kqHA5j6hQe
Replace
QueryDosDevice
hInstance
IdentityReference
wScanCode
keyCode
set_Mode
FileMode
ShareMode
PaddingMode
CryptoStreamMode
CipherMode
SelectSingleNode
XmlNode
get_Unicode
get_BigEndianUnicode
IsTextUnicode
FromImage
get_PropertyStorage
set_PropertyStorage
SerializedPropertyStorage
SendMessage
AddRange
CompareExchange
CredentialCache
YTulisdlche
EndInvoke
BeginInvoke
GetEnvironmentVariable
SetEnvironmentVariable
IEnumerable
IDisposable
ToDouble
get_Handle
RuntimeFieldHandle
hSourceHandle
SafeHandle
GetModuleHandle
RuntimeTypeHandle
ReleaseHandle
CloseHandle
DuplicateHandle
CreateHandle
GetTypeFromHandle
hSourceProcessHandle
hTargetProcessHandle
lpTargetHandle
bInheritHandle
vaultHandle
handle
Rectangle
ToSingle
CreateFile
hTemplateFile
DeleteFile
WriteFile
MoveFile
MapViewOfFile
UnmapViewOfFile
lphModule
get_MainModule
ProcessModule
get_Name
set_Name
lpDeviceName
get_FileName
set_FileName
GetModuleFileName
lpExistingFileName
lpFileName
GetFileName
lpNewFileName
_fileName
get_ModuleName
lpModuleName
lpBaseName
baseName
lpValueName
rootPathName
get_OSFullName
get_FullName
get_ApplicationName
set_ApplicationName
lpName
lpAppName
get_UserName
get_ComputerName
get_ProcessName
processName
GetProcessesByName
lpKeyName
GetDirectoryName
filename
get_Username
set_Username
get_username
set_username
DateTime
GetLastAccessTime
AppendLine
get_NewLine
Combine
LocalMachine
Escape
Unescape
DataProtectionScope
get_Type
set_Type
pszBlobType
GetFileType
ValueType
SecurityProtocolType
GetType
set_ContentType
get_type
set_type
FileShare
Compare
ewGxIH8zfre
System.Core
PtrToStructure
get_InvariantCulture
Capture
NameObjectCollectionBase
HttpWebResponse
GetResponse
Dispose
Reverse
X509Certificate
Create
MulticastDelegate
GetKeyboardState
lpKeyState
GetKeyState
Delete
nNumberOfBytesToWrite
wJeMkte
STAThreadAttribute
CompilerGeneratedAttribute
GuidAttribute
SecuritySafeCriticalAttribute
ExtensionAttribute
AssemblyFileVersionAttribute
FlagsAttribute
CompilationRelaxationsAttribute
ReliabilityContractAttribute
ParamArrayAttribute
RuntimeCompatibilityAttribute
SuppressUnmanagedCodeSecurityAttribute
set_UseShellExecute
ReadByte
ToByte
get_Value
TryGetValue
get_TypedPropertyValue
set_TypedPropertyValue
GetPropertyValue
set_KeepAlive
Remove
get_Size
set_Size
dataSize
get_StorageSize
lpFileSize
get_NameSize
volumeNameSize
nFileSystemNameSize
get_StoreSize
get_ValueSize
get_HashSize
set_BlockSize
chunkSize
get_KeySize
Serialize
Deserialize
Initialize
Finalize
Resize
vFsYwonO1f
gxJNU2f
AYwNY4OjQCf
UpTQmQLf
iEVZcViMf
6vyslORuXOf
SizeOf
get_ItemOf
LastIndexOf
vE08gPf
JXQ4geRf
9JxNdqhsUf
64H7bf
43x7ef
cchBuff
7Bo50ygf
bTKR91UZhf
myqBo2Gs7jf
VTOo6sXtJlf
83cH4Fblf
FCdRvvf
p5mWkmejzf
AkCkiK4g
RNhRLg8g
Y2TuFg
GSuB3OhYzKg
QJCOrvXfKOg
kkjZqqXg
ZkjS2rag
get_Jpeg
qzuDhg
System.Threading
get_Padding
set_Padding
UTF8Encoding
System.Drawing.Imaging
get_IsRunning
set_IsRunning
CreateFileMapping
FromBase64String
ToBase64String
EscapeDataString
UnescapeDataString
lpReturnedString
GetPrivateProfileString
ToString
GetString
Substring
System.Drawing
kGdqrg
get_Msg
a7sKDzg
1JjKJJ7Rezg
Oe3n9h
WtfMO1UfKh
jOXaqC9TfLh
UEhj1iaVh
dwMaximumSizeHigh
dwFileOffsetHigh
4yaSzmgFQkh
oaiPZkh
CAq9hooNJoh
PNn7lqh
ComputeHash
EwJzo4bsh
get_Path
set_Path
get_ExecutablePath
GetTempPath
GetFolderPath
lpTargetPath
get_Width
get_Length
SystemInformationLength
ObjectInformationLength
set_MaxJsonLength
ReturnLength
maximumComponentLength
GetWindowTextLength
EndsWith
StartsWith
IgvJcT9i
SSJ5JhGGi
q9mYap6Ji
Do27Si
MuKX2Ui
ygjFIbi
PtrToStringUni
StringToHGlobalUni
57Yu8iFcPui
ai0ZOz91j
Yq2tC2j
J4509FM9r2j
Djuc4V3j
DueocRtcBj
kTyYFAAINj
tFHF0xahj
DAKSsj
N8FmwBk
B2Rui0Fk
ouapkX540Ik
ks4W4Nk
gpOvv8eRk
3d4NURs33bk
AsyncCallback
RemoteCertificateValidationCallback
get_ServerCertificateValidationCallback
set_ServerCertificateValidationCallback
callback
get_CapsLock
TransformFinalBlock
TransformBlock
3G4nJCek
lzzP6M1tRfk
mYZ3qunzlk
idHook
FifiTD9rk
get_hostmask
set_hostmask
x9aM2l
hKzfxAR5l
uDkrWvrI8l
A7eSh8f8l
CZyjVE9l
I8PHE0Gl
tSI6GLl
weLoYUl
qqypiLAKal
AllocHGlobal
FreeHGlobal
Marshal
Decimal
System.Security.Principal
set_Interval
Rijndael
System.ComponentModel
HI7pZk3gl
ZK5Pqw1jl
Kernel32.dll
kernel32.dll
User32.dll
user32.dll
vaultcli.dll
psapi.dll
ntdll.dll
bcrypt.dll
System.Xml
set_SecurityProtocol
Control
ay3G2m
30Oau2m
Ff7BFyPu6m
O3kO7m
awFEa9m
gQ05v9m
7bd1OhsFm
DRIgIm
PkqCFJm
7ekIZm
Os2fZm
FileStream
get_BaseStream
GetResponseStream
CryptoStream
GetRequestStream
MemoryStream
get_LParam
get_WParam
get_Param
lParam
wParam
get_Item
set_Item
VaultGetItem
vaultItem
OperatingSystem
SymmetricAlgorithm
phAlgorithm
KeyedHashAlgorithm
algorithm
Random
7rGyNrm
ICryptoTransform
BheDIST29n
IuE8Xyo0Fn
6k6T1cIn
4QnlCyLn
pncIlKkZQn
d6LQXiQn
oC7O6tmbSn
ToBoolean
IsLittleEndian
CopyFromScreen
get_PrimaryScreen
lpNumberOfBytesWritten
X509Chain
ChangeClipboardChain
SbbC8kn
get_OSVersion
get_Version
set_Version
get_Application
set_Application
get_Location
GetVolumeInformation
NtQuerySystemInformation
ObjectInformation
pszImplementation
System.Globalization
System.Web.Script.Serialization
System.Reflection
PropertyDataCollection
NameValueCollection
MatchCollection
GroupCollection
KeysCollection
ManagementObjectCollection
KeyCollection
set_Position
CreationDisposition
SearchOption
Win32Exception
CryptographicException
ArgumentOutOfRangeException
ArgumentException
get_Description
set_Description
get_StatusDescription
_description
System.Runtime.ConstrainedExecution
StringComparison
Intern
add_KeyDown
remove_KeyDown
get_CtrlKeyDown
get_ShiftKeyDown
get_AltKeyDown
VjsqT67o
tNsTWyMo
q78VHjRo
CompareTo
CopyTo
Dj0eWo
d7xjXpqKXo
ImageCodecInfo
FieldInfo
FileInfo
CultureInfo
pPaddingInfo
FileSystemInfo
MemberInfo
ComputerInfo
get_StartInfo
ProcessStartInfo
GetLastInputInfo
DirectoryInfo
qLNZio
HWxAf5ylo
Bop5dKDp
Gy9F6BJp
EEbvJP2Pp
add_KeyUp
remove_KeyUp
m9R3UWp
hfrT8gZp
dwNumberOfBytesToMap
Bitmap
K0JJtohz1ep
qRVyWmBip
ZS47np
lbjJUwop
oow9X1up
yPnk5m9q
25wVKq
n67DlPjRq
mRw3Uq
mVQzOrjUq
System.Linq
CSCsVHaoarq
NeDppnquq
33JhyHbzq
naZX92r
azv3b8r
YsXZMEr
27h566EHr
Ab53gdJr
KbeBVsAbTr
uTPyTr
Rx1Xu4oXr
VIqo5k6Yr
ToChar
lpChar
DirectorySeparatorChar
Sf2UbQp5er
volumeSerialNumber
StreamReader
TextReader
BinaryReader
SHA1CryptoServiceProvider
MD5CryptoServiceProvider
RNGCryptoServiceProvider
TripleDESCryptoServiceProvider
BCryptCloseAlgorithmProvider
BCryptOpenAlgorithmProvider
IFormatProvider
StringBuilder
SpecialFolder
sender
Encoder
volumeNameBuffer
fileSystemNameBuffer
buffer
ServicePointManager
ManagementObjectSearcher
SecurityIdentifier
ElapsedEventHandler
ToUpper
CurrentUser
get_user
set_user
EncoderParameter
BitConverter
get_hoster
set_hoster
BinaryFormatter
SetClipboardViewer
ToLower
JavaScriptSerializer
BR2lzbjr
vBtETH4mr
Hq53ZiKZmr
get_Major
get_Minor
GetLastWin32Error
GetLastError
IEnumerator
ManagementObjectEnumerator
GetEnumerator
RandomNumberGenerator
.cctor
Monitor
CreateDecryptor
CreateEncryptor
passwordVaultPtr
ReadIntPtr
4QsG5ur
Msp3GD1s
HgUskoJ3s
ll01dcJKBs
qRY3tpEs
w52nALwQs
oKJaJ4Ys
ngHwoMqeZs
gi2BWUFas
Graphics
System.Diagnostics
get_Bounds
Microsoft.VisualBasic.Devices
System.Runtime.InteropServices
System.Runtime.CompilerServices
GetInstances
get_ChildNodes
Matches
GetDirectories
get_Properties
ExpandEnvironmentVariables
GetFiles
EnumProcessModules
NumberStyles
GetSubKeyNames
ReadAllLines
GetProcesses
System.Security.Cryptography.X509Certificates
FlagsAndAttributes
lpFileMappingAttributes
SecurityAttributes
Rfc2898DeriveBytes
ReadAllBytes
GetBytes
get_Values
GetLogicalDrives
QlOvfs
fileSystemFlags
dwFlags
ElapsedEventArgs
pDg537Wjs
dMHgxXokjs
get_Ticks
get_Tasks
set_Tasks
ICredentials
set_Credentials
get_DefaultCredentials
Equals
xmldZ4ms
CreateParams
VaultEnumerateItems
System.Windows.Forms
Contains
System.Web.Extensions
System.Text.RegularExpressions
iterations
System.Collections
set_MaximumAutomaticRedirections
StringSplitOptions
RegexOptions
options
2Ffx8Q7os
TwAjQLGITps
get_Groups
get_Chars
GetImageEncoders
System.Timers
RuntimeHelpers
EncoderParameters
SslPolicyErrors
SystemInformationClass
ObjectInformationClass
ManagementClass
dwDesiredAccess
FileAccess
processAccess
get_Success
hProcess
OpenProcess
GetCurrentProcess
lpBaseAddress
get_objects
set_objects
VaultEnumerateVaults
set_Arguments
get_Accounts
set_Accounts
get_Exists
get_Keys
set_Keys
get_ModifierKeys
Yv37Cj0zs
ipVsrz0t
QaBMETud6t
7LHqNO7t
93yxP2Qm9t
ES27ru4kHt
OZhBaKgoIt
Concat
AppendFormat
ImageFormat
Subtract
ManagementBaseObject
hFileMappingObject
hObject
ManagementObject
cbKeyObject
pbKeyObject
NtQueryObject
object
Collect
set_AllowAutoRedirect
flProtect
Unprotect
OWgTQhQbdt
System.Net
offset
pHlkft
get_Height
get_Lenght
set_Lenght
op_Explicit
WaitForExit
cbSalt
VaultOpenVault
get_Default
lpDefault
pcbResult
IAsyncResult
phkResult
result
teldSnt
set_UserAgent
System.Management
pResourceElement
XmlElement
pIdentityElement
Environment
XmlDocument
get_Parent
GetParent
get_Current
get_Count
get_HandleCount
get_TickCount
vaultItemCount
set_IterationCount
vaultCount
BCryptDecrypt
BCryptEncrypt
TrimStart
Convert
HttpWebRequest
XmlNodeList
ToList
get_Host
set_Host
set_Timeout
GetKeyboardLayout
dwLayout
cbInput
pbInput
cbOutput
pbOutput
get_StandardOutput
set_RedirectStandardOutput
vkIFvt
MoveNext
System.Text
ReadAllText
AppendAllText
get_InnerText
GetText
GetWindowText
RLUyU3u
r1nJ7Zu
Lx9LIsju
fc4wlu
vb85zu
LG0agIzu
OIvJRnL4v
gCdhifAv
K5Q6zH6CLv
37l4Mv
TSb0rnVv
tONNcMTHSbv
IEOfcv
iM9nmcv
Y63stBgv
QxTihxgv
CflAPiv
SJ5tSQCx1xv
m876W95w
vbL8hj1Gw
oMYgKDaHw
eqhn1RfjUw
1C5OZiw
Colxiw
dwMaximumSizeLow
dwFileOffsetLow
get_Now
GetForegroundWindow
NativeWindow
set_CreateNoWindow
f5GeBuw
N7X2dUneQuw
m2Oqh2175x
ToUnicodeEx
GetModuleFileNameEx
RegQueryValueEx
GetFileSizeEx
UnhookWindowsHookEx
SetWindowsHookEx
CallNextHookEx
RegOpenKeyEx
MtzWmhKWx
Izq9xHOUYx
ucchMax
OTahU6Uv7qx
5cyjA8qx
hGJ8jQKNqqx
NoyUveUvx
xxJLJoDTyx
T7dKCYRjMJy
szpiPSy
iMaPvSy
9pfAzVy
ToByteArray
InitializeArray
ToArray
ToCharArray
Consistency
get_Key
set_Key
OpenSubKey
subKey
RegCloseKey
get_GuidMasterKey
set_GuidMasterKey
_guidMasterKey
ContainsKey
wVirtKey
hImportKey
BCryptImportKey
BCryptDestroyKey
RegistryKey
qhWaXgy
System.Security.Cryptography
GetExecutingAssembly
Multiply
oDRU6my
yPz6my
BlockCopy
System.Runtime.Serialization.Formatters.Binary
get_TotalPhysicalMemory
Directory
Registry
SMHaosy
get_Capacity
Quality
op_Equality
op_Inequality
System.Security
System.Net.Security
IsNullOrEmpty
BCryptSetAlgorithmProperty
BCryptGetProperty
BCryptSetProperty
pszProperty
qmlZtyy
fQq2px3z
CIwYavMz
pzLNge7KPz
3X05dP8Sz
SDUuZz
zpX7bz
lS3LHjejz
X2i0Jl91awz
FSYEjhYxz
$97c5b0d0-fc6e-492c-bc79-ae62171e12ba
WrapNonExceptionThrows
1.0.0.0
_CorExeMain
mscoree.dll
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<assemblyIdentity version="1.0.0.0" name="MyApplication.app"/>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v2">
<security>
<requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3">
<requestedExecutionLevel level="asInvoker" uiAccess="false"/>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
pp p!p"p#p$p%p&p'p(p)p*p+p,p-p.p/p0p1p2p3p4p5p6p7p8p9p:p;p<p=p>p?p@pApDpEpFpGpHpKpfy|y
k#n+n9
45 6!7"8#9$:%;&<'=(>)?*@+A,B-C0D4E5F6G7H8I9K:N;O=QATD]FcJuPvTwVxYy]z`
BACAIHJHQPVUWUXU\[cbedfdgdhdidjdml
Accounts
logins
sha512
credential
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
FileDescription
FileVersion
1.0.0.0
InternalName
73f756cf-fa55-47c1-bf93-f353acf8c3c4.exe
LegalCopyright
OriginalFilename
73f756cf-fa55-47c1-bf93-f353acf8c3c4.exe
ProductVersion
1.0.0.0
Assembly Version
1.0.0.0
Antivirus Signature
Bkav Clean
Lionic Clean
Elastic malicious (high confidence)
MicroWorld-eScan Trojan.MSIL.Basic.8.Gen
FireEye Generic.mg.d60a27f84140ad72
CAT-QuickHeal Clean
ALYac Trojan.MSIL.Basic.8.Gen
Malwarebytes Spyware.AgentTesla.Generic
Zillya Clean
Sangfor Suspicious.Win32.Save.a
K7AntiVirus Clean
BitDefender Trojan.MSIL.Basic.8.Gen
K7GW Clean
Cybereason malicious.ae782b
Baidu Clean
VirIT Trojan.Win32.MSIL_Heur.A
Cyren W32/MSIL_Kryptik.JRO.gen!Eldorado
Symantec ML.Attribute.HighConfidence
ESET-NOD32 a variant of MSIL/Spy.AgentTesla.F
Cynet Malicious (score: 100)
APEX Malicious
Paloalto Clean
ClamAV Win.Packed.Generic-10003641-0
Kaspersky HEUR:Trojan-PSW.MSIL.Stealer.gen
Alibaba Clean
NANO-Antivirus Clean
ViRobot Clean
Rising Spyware.AgentTesla!8.10E35 (TFE:dGZlOg384LsNDDpzmQ)
Emsisoft Trojan.MSIL.Basic.8.Gen (B)
F-Secure Clean
DrWeb BackDoor.SpyBotNET.73
VIPRE Trojan.MSIL.Basic.8.Gen
TrendMicro Clean
McAfee-GW-Edition BehavesLike.Win32.Generic.dm
Trapmine suspicious.low.ml.score
CMC Clean
Sophos Troj/Tesla-CNT
SentinelOne Static AI - Malicious PE
GData Trojan.MSIL.Basic.8.Gen
Jiangmin Clean
Webroot Clean
Avira Clean
MAX malware (ai score=83)
Antiy-AVL Clean
Kingsoft Clean
Gridinsoft Clean
Xcitium Clean
Arcabit Trojan.MSIL.Basic.8.Gen
SUPERAntiSpyware Clean
ZoneAlarm HEUR:Trojan-PSW.MSIL.Stealer.gen
Microsoft Clean
Google Detected
AhnLab-V3 Malware/Win.Generic.C5459834
Acronis Clean
McAfee Artemis!D60A27F84140
TACHYON Clean
DeepInstinct MALICIOUS
VBA32 Clean
Cylance unsafe
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Tencent Clean
Yandex Clean
Ikarus Trojan-Spy.MSIL.AgentTesla
MaxSecure Clean
Fortinet MSIL/Agent.F!tr.spy
BitDefenderTheta Gen:NN.ZemsilF.36738.om0@aCmNDgl
AVG Win32:PWSX-gen [Trj]
Avast Win32:PWSX-gen [Trj]
CrowdStrike win/malicious_confidence_100% (W)
No IRMA results available.