Static | ZeroBOX

PE Compile Time

2023-09-26 01:55:52

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x000561d4 0x00056200 6.44662584025
.rsrc 0x0005a000 0x00000a00 0x00000a00 4.23596538979
.reloc 0x0005c000 0x0000000c 0x00000200 0.101910425663

Resources

Name Offset Size Language Sub-language File type
RT_VERSION 0x0005a090 0x000002d4 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_MANIFEST 0x0005a374 0x00000493 LANG_NEUTRAL SUBLANG_NEUTRAL exported SGML document, UTF-8 Unicode (with BOM) text, with CRLF line terminators

Imports

Library mscoree.dll:
0x402000 _CorExeMain

!This program cannot be run in DOS mode.
`.rsrc
@.reloc
%r(3
% r.3
%!r43
%"r:3
%#r@3
%$rF3
%%rZ3
%&r`3
%'rf3
%(rl3
%)rr3
%*rx3
%+r~3
%Er$4
%Fr@4
%GrH4
%HrN4
%IrT4
%JrZ4
%Kr`4
%Lrf4
%Mrl4
%Nrr4
%Orx4
%Pr~4
%kr 5
%lr&5
%mr,5
%nr25
%or85
%pr>5
%qrD5
%rrJ5
%srP5
%trV5
%ur\5
%vrb5
%wrh5
%xrn5
%yrt5
%zrz5
% rtG
cZjX}v
UYZsZ
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
hSystem.Drawing.Bitmap, System.Drawing, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3aPADPADi
QSystem.Drawing, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a
System.Drawing.Bitmap
tEXtSoftware
Adobe ImageReadyq
IDAT8O]
V:>zp3
f{9D]r
\vZ"ZB!
v4.0.30319
#Strings
.!5!|!
#$#>#d#
$0$D$o$
+),C,X,q,
.!///:/_/
0*0@0g0
1$2A2c2
5 515]5s5
757]7s7
9!9J9#:):e:p:
;E<f<x<
>&>T>gD
-P.`.p.$1
586{6J7
7,898I8=;S;T<
Client.exe
Client
mscorlib
System.Core
System.Windows.Forms
System
System.Drawing
System.Runtime.Serialization
System.Xml
System.Management
System.Security
Microsoft.VisualBasic
user32.dll
kernel32.dll
gdi32.dll
msvcrt.dll
advapi32.dll
shlwapi.dll
Kernel32.dll
shell32.dll
iphlpapi.dll
ole32.dll
ntdll.dll
oleaut32.dll
xClient.Properties.Resources.resources
Object
ApplicationContext
Application
EnableVisualStyles
SetCompatibleTextRenderingDefault
AppDomain
get_CurrentDomain
UnhandledExceptionEventHandler
add_UnhandledException
STAThreadAttribute
get_MessageLoop
Environment
UnhandledExceptionEventArgs
get_IsTerminating
String
IsNullOrEmpty
ProcessStartInfo
System.Diagnostics
set_WindowStyle
ProcessWindowStyle
set_UseShellExecute
set_FileName
Process
sender
ExitThread
Dispose
Concat
System.IO
Combine
op_Equality
SetAttributes
FileAttributes
GetDirectoryName
DirectoryInfo
FileSystemInfo
get_Attributes
set_Attributes
ThreadStart
System.Threading
Thread
set_IsBackground
Exception
.cctor
CompilerGeneratedAttribute
System.Runtime.CompilerServices
ResourceManager
System.Resources
CultureInfo
System.Globalization
GetTypeFromHandle
RuntimeTypeHandle
get_Assembly
Assembly
System.Reflection
GetObject
Bitmap
EditorBrowsableAttribute
System.ComponentModel
EditorBrowsableState
Culture
information
GeneratedCodeAttribute
System.CodeDom.Compiler
DebuggerNonUserCodeAttribute
ApplicationSettingsBase
System.Configuration
SettingsBase
Synchronized
Default
SpecialFolder
GetFolderPath
Socket
System.Net.Sockets
get_ConnectionId
set_ConnectionId
get_Handle
set_Handle
get_Target
set_Target
get_Port
set_Port
get_Client
set_Client
AddressFamily
SocketType
ProtocolType
AsyncCallback
BeginConnect
IAsyncResult
command
client
IPEndPoint
System.Net
EndConnect
get_Connected
BeginReceive
SocketFlags
get_LocalEndPoint
EndPoint
get_Address
IPAddress
EndReceive
ConnectionId
Handle
Target
GetType
packet
ReverseProxyConnect
xClient.Core.ReverseProxy.Packets
<ConnectionId>k__BackingField
<Target>k__BackingField
<Port>k__BackingField
connectionId
target
Execute
ReverseProxyConnectResponse
<IsConnected>k__BackingField
<LocalAddress>k__BackingField
<LocalPort>k__BackingField
<HostName>k__BackingField
get_IsConnected
set_IsConnected
get_LocalAddress
set_LocalAddress
get_LocalPort
set_LocalPort
get_HostName
set_HostName
IPHostEntry
GetHostEntry
isConnected
localAddress
localPort
targetServer
IsConnected
LocalAddress
LocalPort
HostName
ReverseProxyData
<Data>k__BackingField
get_Data
set_Data
ReverseProxyDisconnect
add_KeyDown
KeyEventHandler
remove_KeyDown
add_KeyPress
KeyPressEventHandler
remove_KeyPress
add_KeyUp
remove_KeyUp
IKeyboardMouseEvents
xClient.Core.MouseKeyHook
IDisposable
add_MouseMove
MouseEventHandler
remove_MouseMove
add_MouseMoveExt
EventHandler`1
remove_MouseMoveExt
add_MouseClick
remove_MouseClick
add_MouseDown
remove_MouseDown
add_MouseDownExt
remove_MouseDownExt
add_MouseUp
remove_MouseUp
add_MouseUpExt
remove_MouseUpExt
add_MouseWheel
remove_MouseWheel
add_MouseDoubleClick
remove_MouseDoubleClick
KeyEventArgs
keyData
timestamp
isKeyDown
isKeyUp
get_Timestamp
set_Timestamp
get_IsKeyDown
set_IsKeyDown
get_IsKeyUp
set_IsKeyUp
get_TickCount
IntPtr
ToInt64
op_Explicit
Marshal
System.Runtime.InteropServices
PtrToStructure
Timestamp
IsKeyDown
IsKeyUp
KeyPressEventArgs
keyChar
get_IsNonChar
set_IsNonChar
IEnumerable`1
System.Collections.Generic
IsNonChar
<FromRawDataApp>d__10
IEnumerable
System.Collections
IEnumerator`1
IEnumerator
<>1__state
<>2__current
<>l__initialThreadId
<>3__data
<>7__wrap1
<>7__wrap2
get_CurrentThread
get_ManagedThreadId
DebuggerHiddenAttribute
System.IDisposable.Dispose
MoveNext
System.Collections.Generic.IEnumerator<xClient.Core.MouseKeyHook.KeyPressEventArgsExt>.get_Current
get_Current
NotSupportedException
System.Collections.IEnumerator.Reset
System.Collections.IEnumerator.get_Current
System.Collections.Generic.IEnumerable<xClient.Core.MouseKeyHook.KeyPressEventArgsExt>.GetEnumerator
GetEnumerator
System.Collections.IEnumerable.GetEnumerator
System.Collections.Generic.IEnumerator<xClient.Core.MouseKeyHook.KeyPressEventArgsExt>.Current
System.Collections.IEnumerator.Current
<FromRawDataGlobal>d__11
<virtualKeyCode>5__1
<scanCode>5__2
<fuState>5__3
<keyboardHookStruct>5__4
MouseEventArgs
MouseButtons
buttons
clicks
isMouseKeyDown
isMouseKeyUp
get_Handled
set_Handled
get_Delta
get_Clicks
get_IsMouseKeyDown
set_IsMouseKeyDown
get_IsMouseKeyUp
set_IsMouseKeyUp
wParam
mouseInfo
get_Button
Handled
WheelScrolled
Clicked
IsMouseKeyDown
IsMouseKeyUp
ValueType
lParam
WParam
LParam
callback
SafeHandle
get_IsInvalid
hookId
GetCurrentProcess
get_MainModule
ProcessModule
get_BaseAddress
GetLastWin32Error
Win32Exception
idHook
CallNextHookEx
dwThreadId
SetWindowsHookEx
UnhookWindowsHookEx
MulticastDelegate
object
method
Invoke
BeginInvoke
EndInvoke
result
SafeHandleZeroOrMinusOneIsInvalid
Microsoft.Win32.SafeHandles
EventHandler
add_ApplicationExit
handle
ReleaseHandle
EventArgs
HookResult
xClient.Core.MouseKeyHook.WinApi
m_Handle
m_Procedure
procedure
get_Procedure
Procedure
virtualKeyCode
fuState
scanCode
StringBuilder
System.Text
get_Capacity
get_Length
get_Chars
ToAscii
uVirtKey
uScanCode
lpbKeyState
lpwTransKey
ObsoleteAttribute
wVirtKey
wScanCode
lpKeyState
pwszBuff
cchBuff
wFlags
ToUnicodeEx
pbKeyState
GetKeyboardState
GetKeyState
uMapType
MapVirtualKeyEx
dwLayout
GetKeyboardLayout
GetDoubleClickTime
op_Inequality
Equals
GetHashCode
GetCurrentThreadId
GetForegroundWindow
lpString
nMaxCount
GetWindowText
processId
GetWindowThreadProcessId
CreateMouseListener
CreateKeyListener
GetPressEventArgs
GetDownUpEventArgs
GetEventArgs
BaseListener
xClient.Core.MouseKeyHook.Implementation
<Handle>k__BackingField
subscribe
Callback
element
EventFacade
m_KeyListenerCache
m_MouseListenerCache
GetKeyListener
GetMouseListener
KeyDown
KeyPress
MouseMove
MouseMoveExt
MouseClick
MouseDown
MouseDownExt
MouseUp
MouseUpExt
MouseWheel
MouseDoubleClick
ProcessDown
ProcessUp
keyboardStateNative
ArgumentOutOfRangeException
KeyListener
Delegate
Interlocked
CompareExchange
Remove
InvokeKeyDown
InvokeKeyPress
InvokeKeyUp
MouseListener
m_DoubleDown
m_SingleDown
m_PreviousPosition
ProcessWheel
ProcessMove
HasMoved
actualPoint
OnMove
OnMoveExt
OnClick
OnDown
OnDownExt
OnUpExt
OnWheel
OnDoubleClick
callbck
DateTime
triggeredAt
Dictionary`2
hotkeys
get_Name
set_Name
get_Description
set_Description
get_Count
add_OnHotKeysDownHold
remove_OnHotKeysDownHold
add_OnHotKeysUp
remove_OnHotKeysUp
add_OnHotKeysDownOnce
remove_OnHotKeysDownOnce
get_Now
hotKeyDelegate
ContainsKey
set_Item
List`1
Enumerator
KeyValuePair`2
ContainsValue
get_Value
get_Key
anyKeyInTheExclusiveOrSet
orKeySet
get_Item
get_KeyCode
Description
HotKeys
HotKeysActivated
Enabled
get_Path
set_Path
get_LastError
set_LastError
FileInfo
get_Exists
FileNotFoundException
Ceiling
PathTooLongException
UnauthorizedAccessException
IOException
length
FileStream
Monitor
OpenRead
Stream
SeekOrigin
get_Position
DirectoryNotFoundException
blockNumber
readBytes
Exists
FileMode
FileAccess
LastError
MaxBlocks
Queue`1
Enqueue
Dequeue
TryParse
get_AddressFamily
get_OSSupportsIPv6
get_AddressList
IsEmpty
DeleteFile
lpFileName
LoadLibrary
hModule
procName
GetProcAddress
GetLastInputInfo
SetCursorPos
dwFlags
cButtons
dwExtraInfo
mouse_event
keybd_event
nXDest
nYDest
nWidth
nHeight
hdcSrc
BitBlt
lpszDriver
lpszDevice
lpszOutput
lpInitData
CreateDC
DeleteDC
memcmp
memcpy
uAction
uParam
lpvParam
SystemParametersInfo
PostMessage
hDesktop
inherit
desiredAccess
OpenDesktop
CloseDesktop
EnumDesktopWindows
IsWindowVisible
SizeOf
UnsafeStreamCodec
xClient.Core.Utilities
<Monitor>k__BackingField
<Resolution>k__BackingField
<CheckBlock>k__BackingField
_imageQuality
_encodeBuffer
_decodedBitmap
_encodedFormat
PixelFormat
System.Drawing.Imaging
_encodedWidth
_encodedHeight
_imageProcessLock
_jpgCompression
get_Monitor
set_Monitor
get_Resolution
set_Resolution
get_CheckBlock
set_CheckBlock
get_ImageQuality
set_ImageQuality
imageQuality
monitor
resolution
SuppressFinalize
disposing
Rectangle
BitmapData
ToInt32
get_CanWrite
ToString
get_Width
get_Height
BitConverter
GetBytes
get_PixelFormat
LockBits
ImageLockMode
get_Scan0
ToPointer
set_Position
UnlockBits
CodeImage
scanArea
imageSize
format
outStream
MemoryStream
FromStream
DecodeData
codecBuffer
Graphics
FromImage
get_Location
DrawImage
inStream
Resolution
CheckBlock
ImageQuality
_readLock
_readStreamLock
_encoding
Encoding
_inputWriter
StreamWriter
get_InstalledUICulture
get_TextInfo
TextInfo
get_OEMCodePage
GetEncoding
set_RedirectStandardInput
set_RedirectStandardOutput
set_RedirectStandardError
set_StandardOutputEncoding
set_StandardErrorEncoding
set_CreateNoWindow
GetPathRoot
set_WorkingDirectory
set_Arguments
set_StartInfo
get_CodePage
get_NewLine
CreateSession
WaitCallback
ThreadPool
QueueUserWorkItem
RedirectOutputs
Append
TextReader
ReadStream
StreamReader
firstCharRead
streamReader
isError
get_UTF8
Convert
GetString
set_Length
SendAndFlushBuffer
textbuffer
get_StandardOutput
get_HasExited
ApplicationException
InvalidOperationException
Format
ObjectDisposedException
RedirectStandardOutput
get_StandardError
RedirectStandardError
get_StandardInput
get_BaseStream
TextWriter
WriteLine
ExecuteCommand
Component
<RedirectOutputs>b__7_0
<state>
<RedirectOutputs>b__7_1
Keylogger
Instance
<IsDisposed>k__BackingField
_timerFlush
System.Timers
_logFileBuffer
_pressedKeys
_pressedKeyChars
_lastWindowTitle
_ignoreSpecialKeys
_mEvents
get_IsDisposed
set_IsDisposed
get_LogDirectory
set_Interval
ElapsedEventHandler
add_Elapsed
flushInterval
Subscribe
events
Unsubscribe
Contains
OnKeyDown
get_KeyChar
OnKeyPress
ToArray
OnKeyUp
AppendFormat
HighlightSpecialKeys
timerFlush_Elapsed
ElapsedEventArgs
Create
WriteFile
IsDisposed
LogDirectory
RegistryEditor
xClient.Core.Registry
REGISTRY_KEY_CREATE_ERROR
REGISTRY_KEY_DELETE_ERROR
REGISTRY_KEY_RENAME_ERROR
REGISTRY_VALUE_CREATE_ERROR
REGISTRY_VALUE_DELETE_ERROR
REGISTRY_VALUE_RENAME_ERROR
REGISTRY_VALUE_CHANGE_ERROR
RegistryKey
Microsoft.Win32
get_Message
CreateRegistryKey
parentPath
errorMsg
DeleteRegistryKey
RenameRegistryKey
oldName
newName
CreateRegistryValue
RegistryValueKind
keyPath
DeleteRegistryValue
RenameRegistryValue
ChangeRegistryValue
Substring
GetWritableRegistryKey
RegistrySeeker
locker
matches
get_Matches
BeginSeeking
rootKeyName
rootKey
GetSubKeyNames
Search
GetValueNames
GetValueKind
GetValue
get_SubKeyCount
ProcessKey
keyName
AddMatch
values
subkeycount
OpenBaseKey
RegistryHive
RegistryView
SystemException
GetRootKey
subkeyFullPath
GetRootKeys
Matches
RegSeekerMatch
<Key>k__BackingField
<HasSubKeys>k__BackingField
set_Key
get_HasSubKeys
set_HasSubKeys
HasSubKeys
RegValueData
<Name>k__BackingField
<Kind>k__BackingField
get_Kind
set_Kind
datapath
browser
dataPath
get_Default
ProtectedData
System.Security.Cryptography
Unprotect
DataProtectionScope
EncryptedData
get_HostKey
set_HostKey
set_Value
get_ExpiresUTC
set_ExpiresUTC
get_LastAccessUTC
set_LastAccessUTC
get_Secure
set_Secure
get_HttpOnly
set_HttpOnly
get_Expired
set_Expired
get_Persistent
set_Persistent
get_Priority
set_Priority
get_Browser
set_Browser
Boolean
HostKey
ExpiresUTC
LastAccessUTC
Secure
HttpOnly
Expired
Persistent
Priority
Browser
DataContractJsonSerializer
System.Runtime.Serialization.Json
XmlObjectSerializer
WriteObject
ReadObject
RuntimeHelpers
InitializeArray
RuntimeFieldHandle
FileSystem
FileOpen
OpenMode
OpenAccess
OpenShare
Strings
FileGet
FileClose
CompareTo
Decimal
Compare
baseName
startIndex
endIndex
Microsoft.VisualBasic.CompilerServices
CopyArray
row_num
ToLower
Subtract
ToUInt16
ToUInt64
get_Unicode
get_BigEndianUnicode
Multiply
Offset
IndexOf
TrimStart
TableName
Conversions
NullReferenceException
get_FullName
ReadToEnd
get_AbsoluteUri
FileVersionInfo
GetVersionInfo
get_FileVersion
Version
get_Major
GetDelegateForFunctionPointer
firefoxProfilePath
firefoxPath
DateTimeKind
AddSeconds
unixTime
TimeSpan
ToLocalTime
op_Subtraction
get_TotalSeconds
Directory
GetDirectories
IndexOutOfRangeException
GetFiles
profilePath
searchTerm
OpenSubKey
ArgumentNullException
IDictionary
libPath
loadCerts
arenaOpt
outItemOpt
cypherText
configdir
UnmanagedFunctionPointerAttribute
CallingConvention
__result
get_id
set_id
get_hostname
set_hostname
get_httpRealm
set_httpRealm
get_formSubmitURL
set_formSubmitURL
get_usernameField
set_usernameField
get_passwordField
set_passwordField
get_encryptedUsername
set_encryptedUsername
get_encryptedPassword
set_encryptedPassword
get_guid
set_guid
get_encType
set_encType
get_timeCreated
set_timeCreated
get_timeLastUsed
set_timeLastUsed
get_timePasswordChanged
set_timePasswordChanged
get_timesUsed
set_timesUsed
hostname
httpRealm
formSubmitURL
usernameField
passwordField
encryptedUsername
encryptedPassword
encType
timeCreated
timeLastUsed
timePasswordChanged
timesUsed
get_nextId
set_nextId
get_logins
set_logins
get_disabledHosts
set_disabledHosts
get_version
set_version
nextId
logins
disabledHosts
version
get_Username
set_Username
get_Password
set_Password
get_Host
set_Host
Username
Password
GCHandle
GCHandleType
AddrOfPinnedObject
ToCharArray
Buffer
BlockCopy
dataList
Func`2
Enumerable
System.Linq
urlHash
wstrURL
phProv
pszContainer
pszProvider
dwProvType
CryptAcquireContext
phHash
CryptCreateHash
pbData
dwDataLen
CryptHashData
CryptDestroyHash
dwParam
pdwDataLen
CryptGetHashParam
CryptReleaseContext
ExplorerUrlHistory
xClient.Core.Recovery.Browsers
urlHistory
_urlHistoryList
ReleaseComObject
AddHistoryEntry
pocsUrl
pocsTitle
DeleteHistoryEntry
QueryUrl
ClearHistory
DefaultMemberAttribute
STATURLEnumerator
_enumerator
_index
_staturl
enumerator
SetFilter
poszFilter
GetUrlHistory
Current
pszUrl
pszCanonicalized
pcchCanonicalized
UrlCanonicalize
set_Capacity
FILETIME
System.Runtime.InteropServices.ComTypes
FileTime
SystemTime
FileTimeToSystemTime
filetime
lpSystemTime
lpFileTime
SystemTimeToFileTime
get_Year
get_Month
get_Day
get_Hour
get_Minute
get_Second
get_Millisecond
datetime
lpFileTime1
lpFileTime2
CompareFileTime
pszPath
dwFileAttributes
cbSizeFileInfo
uFlags
SHGetFileInfo
FlagsAttribute
SortFileTimeAscendingHelper
IComparer
System.Collections.IComparer.Compare
SortFileTimeAscending
StartsWith
Replace
UrlString
LastVisited
LastUpdated
Expires
pceltFetched
ppenum
InterfaceTypeAttribute
ComInterfaceType
GuidAttribute
AddUrl
DeleteUrl
lpSTATURL
BindToObject
ppvOut
get_EnumUrls
EnumUrls
IUrlHistoryStg2
AddUrlAndNotify
fWriteHistory
poctNotify
punkISFolder
XmlTextReader
XmlNode
XmlDocument
XmlReader
get_DocumentElement
XmlElement
get_ChildNodes
XmlNodeList
get_ItemOf
get_InnerText
FromBase64String
szInput
UnescapeDataString
Select
ToList
StringComparison
DoWebcamStop
xClient.Core.Packets.ServerPackets
DoAskElevate
DoChangeRegistryValue
<KeyPath>k__BackingField
<Value>k__BackingField
get_KeyPath
set_KeyPath
KeyPath
DoCloseConnection
<RemotePort>k__BackingField
get_RemotePort
set_RemotePort
localport
remoteport
RemotePort
DoCreateRegistryKey
<ParentPath>k__BackingField
get_ParentPath
set_ParentPath
ParentPath
DoCreateRegistryValue
DoDeleteRegistryKey
<KeyName>k__BackingField
get_KeyName
set_KeyName
KeyName
DoDeleteRegistryValue
<ValueName>k__BackingField
get_ValueName
set_ValueName
valueName
ValueName
DoKeyboardEvent
<KeyDown>k__BackingField
get_KeyDown
set_KeyDown
keyDown
DoLoadRegistryKey
<RootKeyName>k__BackingField
get_RootKeyName
set_RootKeyName
RootKeyName
DoRenameRegistryKey
<OldKeyName>k__BackingField
<NewKeyName>k__BackingField
get_OldKeyName
set_OldKeyName
get_NewKeyName
set_NewKeyName
oldKeyName
newKeyName
OldKeyName
NewKeyName
DoRenameRegistryValue
<OldValueName>k__BackingField
<NewValueName>k__BackingField
get_OldValueName
set_OldValueName
get_NewValueName
set_NewValueName
oldValueName
newValueName
OldValueName
NewValueName
GetConnections
GetWebcam
<Webcam>k__BackingField
get_Webcam
set_Webcam
webcam
Webcam
GetWebcams
GetPasswords
SetAuthenticationSuccess
DoShutdownAction
<Action>k__BackingField
get_Action
set_Action
action
Action
DoStartupItemAdd
<Path>k__BackingField
<Type>k__BackingField
get_Type
set_Type
DoUploadFile
<ID>k__BackingField
<RemotePath>k__BackingField
<Block>k__BackingField
<MaxBlocks>k__BackingField
<CurrentBlock>k__BackingField
get_ID
set_ID
get_RemotePath
set_RemotePath
get_Block
set_Block
get_MaxBlocks
set_MaxBlocks
get_CurrentBlock
set_CurrentBlock
remotepath
maxblocks
currentblock
RemotePath
CurrentBlock
GetDesktop
<Quality>k__BackingField
get_Quality
set_Quality
quality
Quality
GetDirectory
DoPathDelete
<PathType>k__BackingField
get_PathType
set_PathType
pathtype
PathType
DoPathRename
<NewPath>k__BackingField
get_NewPath
set_NewPath
newpath
NewPath
DoDownloadFile
DoDownloadFileCancel
GetDrives
GetKeyloggerLogs
GetStartupItems
GetSystemInfo
DoProcessKill
<PID>k__BackingField
get_PID
set_PID
GetMonitors
DoStartupItemRemove
DoShellExecute
<Command>k__BackingField
get_Command
set_Command
Command
DoShowMessageBox
<Caption>k__BackingField
<Text>k__BackingField
<MessageboxButton>k__BackingField
<MessageboxIcon>k__BackingField
get_Caption
set_Caption
get_Text
set_Text
get_MessageboxButton
set_MessageboxButton
get_MessageboxIcon
set_MessageboxIcon
caption
messageboxbutton
messageboxicon
Caption
MessageboxButton
MessageboxIcon
DoClientUpdate
<DownloadURL>k__BackingField
<FileName>k__BackingField
get_DownloadURL
set_DownloadURL
get_FileName
downloadurl
filename
DownloadURL
FileName
DoUploadAndExecute
<RunHidden>k__BackingField
get_RunHidden
set_RunHidden
runhidden
RunHidden
DoVisitWebsite
<URL>k__BackingField
<Hidden>k__BackingField
get_URL
set_URL
get_Hidden
set_Hidden
hidden
Hidden
DoMouseEvent
<IsMouseDown>k__BackingField
<X>k__BackingField
<Y>k__BackingField
<MonitorIndex>k__BackingField
get_IsMouseDown
set_IsMouseDown
get_MonitorIndex
set_MonitorIndex
isMouseDown
monitorIndex
IsMouseDown
MonitorIndex
DoProcessStart
<Processname>k__BackingField
get_Processname
set_Processname
processname
Processname
GetProcesses
DoClientDisconnect
DoDownloadAndExecute
DoClientUninstall
GetAuthentication
DoClientReconnect
GetChangeRegistryValueResponse
xClient.Core.Packets.ClientPackets
<IsError>k__BackingField
<ErrorMsg>k__BackingField
get_IsError
set_IsError
get_ErrorMsg
set_ErrorMsg
IsError
ErrorMsg
GetConnectionsResponse
<Processes>k__BackingField
<LocalAddresses>k__BackingField
<LocalPorts>k__BackingField
<RemoteAdresses>k__BackingField
<RemotePorts>k__BackingField
<States>k__BackingField
get_Processes
set_Processes
get_LocalAddresses
set_LocalAddresses
get_LocalPorts
set_LocalPorts
get_RemoteAdresses
set_RemoteAdresses
get_RemotePorts
set_RemotePorts
get_States
set_States
processes
localaddresses
localports
remoteadresses
remoteports
states
Processes
LocalAddresses
LocalPorts
RemoteAdresses
RemotePorts
States
GetCreateRegistryKeyResponse
<Match>k__BackingField
get_Match
set_Match
GetCreateRegistryValueResponse
GetDeleteRegistryKeyResponse
GetDeleteRegistryValueResponse
GetWebcamResponse
<Image>k__BackingField
get_Image
set_Image
GetWebcamsResponse
<Webcams>k__BackingField
get_Webcams
set_Webcams
webcams
Webcams
GetPasswordsResponse
<Passwords>k__BackingField
get_Passwords
set_Passwords
Passwords
GetRegistryKeysResponse
<Matches>k__BackingField
<RootKey>k__BackingField
set_Matches
get_RootKey
set_RootKey
RootKey
GetRenameRegistryKeyResponse
GetRenameRegistryValueResponse
SetStatusFileManager
<Message>k__BackingField
<SetLastDirectorySeen>k__BackingField
set_Message
get_SetLastDirectorySeen
set_SetLastDirectorySeen
message
setLastDirectorySeen
Message
SetLastDirectorySeen
GetDesktopResponse
GetDirectoryResponse
<Files>k__BackingField
<Folders>k__BackingField
<FilesSize>k__BackingField
get_Files
set_Files
get_Folders
set_Folders
get_FilesSize
set_FilesSize
folders
filessize
Folders
FilesSize
DoDownloadFileResponse
<Filename>k__BackingField
<CustomMessage>k__BackingField
get_Filename
set_Filename
get_CustomMessage
set_CustomMessage
custommessage
Filename
CustomMessage
GetDrivesResponse
<DriveDisplayName>k__BackingField
<RootDirectory>k__BackingField
get_DriveDisplayName
set_DriveDisplayName
get_RootDirectory
set_RootDirectory
driveDisplayName
rootDirectory
DriveDisplayName
RootDirectory
GetKeyloggerLogsResponse
<Index>k__BackingField
<FileCount>k__BackingField
get_Index
set_Index
get_FileCount
set_FileCount
fileCount
FileCount
GetProcessesResponse
<IDs>k__BackingField
<Titles>k__BackingField
get_IDs
set_IDs
get_Titles
set_Titles
titles
Titles
GetStartupItemsResponse
<StartupItems>k__BackingField
get_StartupItems
set_StartupItems
startupitems
StartupItems
GetSystemInfoResponse
<SystemInfos>k__BackingField
get_SystemInfos
set_SystemInfos
systeminfos
SystemInfos
GetMonitorsResponse
<Number>k__BackingField
get_Number
set_Number
number
Number
DoShellExecuteResponse
<Output>k__BackingField
get_Output
set_Output
output
Output
SetUserStatus
SetStatus
GetAuthenticationResponse
<Version>k__BackingField
<OperatingSystem>k__BackingField
<AccountType>k__BackingField
<Country>k__BackingField
<CountryCode>k__BackingField
<Region>k__BackingField
<City>k__BackingField
<ImageIndex>k__BackingField
<Id>k__BackingField
<Username>k__BackingField
<PCName>k__BackingField
<Tag>k__BackingField
get_Version
set_Version
get_OperatingSystem
set_OperatingSystem
get_AccountType
set_AccountType
get_Country
set_Country
get_CountryCode
set_CountryCode
get_Region
set_Region
get_City
set_City
get_ImageIndex
set_ImageIndex
get_Id
set_Id
get_PCName
set_PCName
get_Tag
set_Tag
operatingsystem
accounttype
country
countrycode
region
imageindex
username
pcname
OperatingSystem
AccountType
Country
CountryCode
Region
ImageIndex
PCName
IsNameOrValueNull
ExtensionAttribute
GetValueSafe
defaultValue
OpenReadonlySubKeySafe
OpenWritableSubKeySafe
CreateSubKey
CreateSubKeySafe
DeleteSubKeyTree
DeleteSubKeyTreeSafe
RenameSubKeySafe
CopyKey
SetValue
sourceKey
destKey
SetValueSafe
DeleteValue
DeleteValueSafe
RenameValueSafe
CopyValue
ContainsSubKey
GetFormattedKeyValues
GetDefault
valueKind
keyVal
<GetFormattedKeyValues>d__15
<>3__key
<>8__1
<>m__Finally1
System.Collections.Generic.IEnumerator<System.String>.get_Current
System.Collections.Generic.IEnumerable<System.String>.GetEnumerator
System.Collections.Generic.IEnumerator<System.String>.Current
AllocHGlobal
StructureToPtr
FreeHGlobal
IOControl
IOControlCode
SetKeepAliveEx
socket
keepAliveInterval
keepAliveTime
Rfc2898DeriveBytes
DeriveBytes
authKey
ToBase64String
AesCryptoServiceProvider
CryptoStream
HMACSHA256
ArgumentException
SymmetricAlgorithm
set_KeySize
set_BlockSize
set_Mode
CipherMode
set_Padding
PaddingMode
GenerateIV
CreateEncryptor
ICryptoTransform
CryptoStreamMode
get_IV
FlushFinalBlock
HashAlgorithm
ComputeHash
set_IV
CreateDecryptor
SHA256Managed
ToUpper
source
compressible
sizeCompressed
sizeDecompressed
numbytes
JpgCompression
xClient.Core.Compression
_encoderInfo
ImageCodecInfo
_encoderParams
EncoderParameters
EncoderParameter
Encoder
get_Param
Compression
Compress
targetStream
GetImageEncoders
get_MimeType
GetEncoderInfo
mimeType
add_ClientFail
remove_ClientFail
add_ClientState
remove_ClientState
connected
add_ClientRead
remove_ClientRead
add_ClientWrite
remove_ClientWrite
rawData
set_Connected
get_Serializer
set_Serializer
Connect
payload
FirstOrDefault
RemoveAt
BUFFER_SIZE
KEEP_ALIVE_TIME
KEEP_ALIVE_INTERVAL
HEADER_SIZE
MAX_PACKET_SIZE
ProxyClients
Connected
Serializer
get_Exiting
set_Exiting
get_Authenticated
set_Authenticated
hostsManager
Random
DoEvents
Exiting
Authenticated
TypeData
xClient.Core.NetSerializer
TypeID
TypeSerializer
WriterMethodInfo
MethodInfo
ReaderMethodInfo
<NeedsInstanceParameter>k__BackingField
typeID
serializer
MethodBase
GetParameters
ParameterInfo
writer
reader
get_IsGenerated
get_NeedsInstanceParameter
set_NeedsInstanceParameter
IsGenerated
NeedsInstanceParameter
CodeGenContext
m_typeMap
<SerializerSwitchMethodInfo>k__BackingField
<DeserializerSwitchMethodInfo>k__BackingField
typeMap
get_SerializerSwitchMethodInfo
set_SerializerSwitchMethodInfo
get_DeserializerSwitchMethodInfo
set_DeserializerSwitchMethodInfo
GetWriterMethodInfo
GetReaderMethodInfo
get_TypeMap
IDictionary`2
get_IsValueType
get_IsArray
get_IsSealed
CanCallDirect
GetTypeData
GetTypeDataForCall
SerializerSwitchMethodInfo
DeserializerSwitchMethodInfo
TypeMap
Helpers
ExceptionCtorInfo
ConstructorInfo
IOrderedEnumerable`1
FieldInfo
GetFields
BindingFlags
StringComparer
get_Ordinal
OrderBy
IComparer`1
get_BaseType
GetFieldInfos
DynamicMethod
System.Reflection.Emit
DefineParameter
ParameterBuilder
ParameterAttributes
GenerateDynamicSerializerStub
MakeByRefType
GenerateDynamicDeserializerStub
GetConstructor
Binder
ParameterModifier
<>9__1_0
<>9__1_1
FieldAttributes
<GetFieldInfos>b__1_0
MemberInfo
<GetFieldInfos>b__1_1
ITypeSerializer
Handles
GetSubtypes
IStaticTypeSerializer
GetStaticMethods
IDynamicTypeSerializer
GenerateWriterMethod
ILGenerator
GenerateReaderMethod
Primitives
s_stringHelper
ThreadStaticAttribute
s_emptyByteArray
GetMethod
GetWritePrimitive
GetReaderPrimitive
EncodeZigZag32
EncodeZigZag64
DecodeZigZag32
DecodeZigZag64
ReadByte
EndOfStreamException
InvalidDataException
ReadVarint32
stream
WriteByte
WriteVarint32
ReadVarint64
WriteVarint64
WritePrimitive
ReadPrimitive
ToBinary
FromBinary
get_OffsetToStringData
GetByteCount
Decoder
StringHelper
BYTEBUFFERLEN
CHARBUFFERLEN
m_encoder
m_decoder
m_byteBuffer
m_charBuffer
<Encoding>k__BackingField
UTF8Encoding
get_Encoding
set_Encoding
GetEncoder
get_Encoder
GetDecoder
get_Decoder
get_ByteBuffer
get_CharBuffer
ByteBuffer
CharBuffer
m_typeIDMap
m_serializerSwitch
m_deserializerSwitch
s_typeSerializers
m_userTypeSerializers
rootTypes
ToDictionary
userTypeSerializers
Serialize
Deserialize
Stack`1
get_IsAbstract
get_IsInterface
get_ContainsGenericParameters
GenerateTypeData
GetILGenerator
CreateDelegate
GenerateDynamic
TryGetValue
GetTypeID
SerializerSwitch
DeserializerSwitch
<>9__8_0
<>9__8_1
<>9__8_2
<.ctor>b__8_0
<.ctor>b__8_1
<.ctor>b__8_2
<>c__DisplayClass11_0
<GenerateTypeData>b__0
<GenerateTypeData>b__1
ArraySerializer
xClient.Core.NetSerializer.TypeSerializers
GetArrayRank
LocalBuilder
GetElementType
DefineLabel
OpCodes
Ldarg_2
OpCode
Brtrue_S
Ldarg_1
Ldc_I4_0
Tailcall
UInt32
MarkLabel
Ldc_I4_1
DeclareLocal
Stloc_S
Ldarg_0
Ldloc_S
Ldelem
Conv_I4
Ldloca_S
Ldnull
Stind_Ref
Newarr
Ldelema
<GetSubtypes>d__1
<>3__type
System.Collections.Generic.IEnumerator<System.Type>.get_Current
System.Collections.Generic.IEnumerable<System.Type>.GetEnumerator
System.Collections.Generic.IEnumerator<System.Type>.Current
DictionarySerializer
get_IsGenericType
GetGenericTypeDefinition
GetGenericArguments
MakeGenericMethod
GetMethods
get_ParameterType
GetGenWriter
containerType
genType
get_IsByRef
GetGenReader
MakeGenericType
MakeArrayType
<>9__3_0
<>9__4_0
get_IsGenericMethod
<GetGenWriter>b__3_0
<GetGenReader>b__4_0
EnumSerializer
get_IsEnum
GetUnderlyingType
GenericSerializer
get_IsSerializable
ISerializable
IsAssignableFrom
get_FieldType
Ldarga_S
get_IsClass
FormatterServices
Ldtoken
Castclass
Ldind_Ref
Ldflda
IDeserializationCallback
Constrained
Callvirt
ObjectSerializer
UInt16
ICollection`1
Switch
Newobj
Unbox_Any
obtype
LocalVariableInfo
get_LocalIndex
Ldloca
PrimitivesSerializer
s_primitives
GetSupportedTypes
UInt64
Single
Double
<GetSubtypes>d__2
CreateDirectory
Delete
GetFileNameWithoutExtension
GetProcessesByName
ReadAllBytes
newFilePath
WaitForExit
get_ExitCode
WaitHandle
get_LastUserStatus
set_LastUserStatus
get_UserName
WindowsIdentity
System.Security.Principal
WindowsPrincipal
GetCurrent
IsInRole
WindowsBuiltInRole
Stopwatch
GetTimestamp
LastUserStatus
extension
GetTempPath
filePath
WriteAllText
isFileHidden
appendText
System.Text.RegularExpressions
macAddress
DriveType
LastIndexOf
rawHosts
scrollDown
ManagementObjectSearcher
ManagementObjectCollection
ManagementObjectEnumerator
get_OSVersion
get_Platform
PlatformID
op_GreaterThanOrEqual
ManagementBaseObject
ManagementObject
TrimEnd
get_Is64BitOperatingSystem
set_FullName
get_Is64Bit
set_Is64Bit
get_RunningOnMono
set_RunningOnMono
get_Win32NT
set_Win32NT
get_XpOrHigher
set_XpOrHigher
get_VistaOrHigher
set_VistaOrHigher
get_SevenOrHigher
set_SevenOrHigher
get_EightOrHigher
set_EightOrHigher
get_EightPointOneOrHigher
set_EightPointOneOrHigher
get_TenOrHigher
set_TenOrHigher
FullName
Is64Bit
RunningOnMono
Win32NT
XpOrHigher
VistaOrHigher
SevenOrHigher
EightOrHigher
EightPointOneOrHigher
TenOrHigher
EndsWith
addQuotes
GetHdc
ReleaseHdc
screenNumber
Screen
get_AllScreens
get_Bounds
get_HardwareId
set_HardwareId
ToDouble
NetworkInterface
System.Net.NetworkInformation
UnicastIPAddressInformation
GetAllNetworkInterfaces
GetIPProperties
IPInterfaceProperties
get_GatewayAddresses
GatewayIPAddressInformationCollection
GatewayIPAddressInformation
get_NetworkInterfaceType
NetworkInterfaceType
get_OperationalStatus
OperationalStatus
get_UnicastAddresses
UnicastIPAddressInformationCollection
IPAddressInformation
get_AddressPreferredLifetime
GetPhysicalAddress
PhysicalAddress
HardwareId
ManagementDateTimeConverter
ToDateTime
get_Ticks
FromTicks
get_Days
get_Hours
get_Minutes
get_Seconds
get_MachineName
IsModifierKeysSet
pressedKeys
IsModifierKey
ContainsKeyChar
IsExcludedKey
Predicate`1
FindAll
search
get_GeoInfo
set_GeoInfo
get_LastLocated
set_LastLocated
get_LocationCompleted
set_LocationCompleted
get_UtcNow
get_TotalMinutes
HttpWebResponse
WebRequest
HttpWebRequest
set_UserAgent
set_Proxy
IWebProxy
set_Timeout
GetResponse
WebResponse
GetResponseStream
LoadXml
SelectSingleNode
get_InnerXml
GeoInfo
LastLocated
LocationCompleted
get_CurrentPath
set_CurrentPath
Antivirus Signature
Bkav Clean
Lionic Trojan.MSIL.Agent.mCnJ
tehtris Clean
DrWeb Trojan.DownLoader27.59888
MicroWorld-eScan Generic.MSIL.PasswordStealerA.071BB1CD
ClamAV Win.Packed.Generic-9829635-0
FireEye Generic.mg.578656857a68dc5d
CAT-QuickHeal Clean
McAfee PWS-FCOI!578656857A68
Cylance unsafe
Zillya Trojan.Agent.Win32.1088950
Sangfor Suspicious.Win32.Save.a
K7AntiVirus Trojan ( 00521dab1 )
BitDefender Generic.MSIL.PasswordStealerA.071BB1CD
K7GW Trojan ( 00521dab1 )
Cybereason malicious.7deb1f
BitDefenderTheta Gen:NN.ZemsilF.36738.vm0@aO78wzc
VirIT Trojan.Win32.MSIL_Heur.B
Cyren W32/MSIL_Mintluks.A.gen!Eldorado
Symantec ML.Attribute.HighConfidence
Elastic Windows.Trojan.Quasarrat
ESET-NOD32 a variant of MSIL/Spy.Agent.AES
APEX Malicious
Paloalto Clean
Cynet Malicious (score: 100)
Kaspersky Trojan.MSIL.Agent.foww
Alibaba Backdoor:MSIL/Quasar.e7e22a26
NANO-Antivirus Trojan.Win32.Agent.elofqr
ViRobot Trojan.Win.Z.Agent.356352.RI
Rising Backdoor.xRAT!1.D01D (CLASSIC)
Emsisoft Generic.MSIL.PasswordStealerA.071BB1CD (B)
F-Secure Trojan:w32/QuasarRAT.A1
Baidu Clean
VIPRE Generic.MSIL.PasswordStealerA.071BB1CD
TrendMicro TSPY_TINCLEX.SM1
McAfee-GW-Edition BehavesLike.Win32.Generic.fh
Trapmine suspicious.low.ml.score
CMC Clean
Sophos ATK/Zaquar-D
SentinelOne Static AI - Malicious PE
GData MSIL.Backdoor.Quasar.D
Jiangmin Trojan.Generic.ajfvk
Webroot W32.Malware.Gen
Avira HEUR/AGEN.1307329
MAX malware (ai score=88)
Antiy-AVL Trojan/MSIL.Agent
Kingsoft malware.kb.c.1000
Gridinsoft Backdoor.Win32.Quasar.bot
Xcitium Clean
Arcabit Generic.MSIL.PasswordStealerA.071BB1CD
SUPERAntiSpyware Trojan.Agent/Gen-PasswordStealer
ZoneAlarm Trojan.MSIL.Agent.foww
Microsoft Backdoor:MSIL/Quasar.GG!MTB
Google Detected
AhnLab-V3 Trojan/Win32.Subti.R285137
Acronis Clean
VBA32 Trojan.MSIL.Quasar.Heur
TACHYON Clean
DeepInstinct MALICIOUS
Malwarebytes Generic.Malware.AI.DDS
Panda Trj/CI.A
Zoner Clean
TrendMicro-HouseCall TSPY_TINCLEX.SM1
Tencent Trojan.Msil.Agent.zc
Yandex TrojanSpy.Agent!auPEtUOd3oI
Ikarus Trojan.MSIL.Agent
MaxSecure Clean
Fortinet MSIL/Emotet.5C62!tr
AVG MSIL:Rat-B [Trj]
Avast MSIL:Rat-B [Trj]
CrowdStrike win/malicious_confidence_100% (W)
No IRMA results available.