Static | ZeroBOX

PE Compile Time

2023-05-15 03:50:15

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x00028804 0x00028a00 6.2159267564
.rsrc 0x0002c000 0x00000546 0x00000600 4.01174071059
.reloc 0x0002e000 0x0000000c 0x00000200 0.0815394123432

Resources

Name Offset Size Language Sub-language File type
RT_VERSION 0x0002c0a0 0x000002bc LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_MANIFEST 0x0002c35c 0x000001ea LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with CRLF line terminators

Imports

Library mscoree.dll:
0x402000 _CorExeMain

!This program cannot be run in DOS mode.
`.rsrc
@.reloc
W]SW(a
]]SW(a
s]SW(a
c]SW(a
i]SW(a
5]SW(a
]SW(a
0\SW(a
$\SW(a
Q\SW(a
f\SW(a
N\SW(a
{_SW(a
o_SW(a
P_SW(a
L_SW(a
B_SW(a
3_SW(a
?_SW(a
U^SW(a
@^SW(a
s^SW(a
~^SW(a
d^SW(a
PYSW(a
\YSW(a
JYSW(a
pYSW(a
|YSW(a
hYSW(a
0YSW(a
#YSW(a
-YSW(a
ZXSW(a
HXSW(a
{XSW(a
fXSW(a
7XSW(a
%XSW(a
R[SW(a
][SW(a
H[SW(a
{[SW(a
b[SW(a
*[SW(a
7[SW(a
>[SW(a
HZSW(a
# eZSW(a
1ZSW(a
_USW(a
# pUSW(a
# 9USW(a
# JTSW(a
# ;TSW(a
" WWSW(a
@WSW(a
vWSW(a
dWSW(a
2WSW(a
WSW(a
]VSW(a
OVSW(a
nVSW(a
?VSW(a
(VSW(a
vQSW(a
UQSW(a
;QSW(a
)QSW(a
TPSW(a
DPSW(a
tPSW(a
`PSW(a
lPSW(a
PSW(a
1PSW(a
&PSW(a
SSSW(a
ASSW(a
uSSW(a
gSSW(a
2SSW(a
#SSW(a
ZRSW(a
|RSW(a
:RSW(a
)RSW(a
_MSW(a
MMSW(a
bMSW(a
2MSW(a
9MSW(a
TLSW(a
," FLSW(a
<LSW(a
QOSW(a
AOSW(a
qOSW(a
aOSW(a
:OSW(a
'OSW(a
UNSW(a
yNSW(a
NSW(a
YISW(a
MISW(a
bISW(a
^HSW(a
aHSW(a
0HSW(a
,HSW(a
PKSW(a
AKSW(a
eKSW(a
1KSW(a
"KSW(a
)KSW(a
QJSW(a
BJSW(a
LJSW(a
lJSW(a
BESW(a
rESW(a
bESW(a
"ESW(a
(ESW(a
PDSW(a
^DSW(a
EDSW(a
sDSW(a
}DSW(a
lDSW(a
9DSW(a
%DSW(a
^GSW(a
&GSW(a
," qGSW(a
fGSW(a
6GSW(a
PFSW(a
xFSW(a
dFSW(a
6FSW(a
AASW(a
vASW(a
mASW(a
z@SW(a
d@SW(a
Z@SW(a
D@SW(a
*FSW(a
7@SW(a
SCSW(a
ICSW(a
gCSW(a
>CSW(a
@BSW(a
MBSW(a
,Q &BSW(a
q}SW(a
e}SW(a
1}SW(a
'}SW(a
R}SW(a
C}SW(a
@|SW(a
T~SW(a
O~SW(a
b~SW(a
UySW(a
MySW(a
bySW(a
1ySW(a
%ySW(a
TxSW(a
IxSW(a
xxSW(a
oxSW(a
q{SW(a
!{SW(a
QzSW(a
_zSW(a
EzSW(a
{zSW(a
%zSW(a
QuSW(a
suSW(a
~uSW(a
ouSW(a
uSW(a
DtSW(a
|tSW(a
:uSW(a
jtSW(a
$tSW(a
SwSW(a
!wSW(a
5vSW(a
%vSW(a
uvSW(a
evSW(a
VqSW(a
FqSW(a
fqSW(a
CwSW(a
pwSW(a
EvSW(a
=qSW(a
WpSW(a
GpSW(a
{pSW(a
=pSW(a
ZsSW(a
JsSW(a
~sSW(a
9sSW(a
VrSW(a
]rSW(a
vrSW(a
.rSW(a
RmSW(a
6mSW(a
+mSW(a
RlSW(a
GlSW(a
qlSW(a
blSW(a
5lSW(a
[oSW(a
koSW(a
QnSW(a
tnSW(a
+nSW(a
8nSW(a
onSW(a
KnSW(a
PiSW(a
~iSW(a
JiSW(a
)iSW(a
4iSW(a
iSW(a
^hSW(a
LhSW(a
yhSW(a
ehSW(a
?hSW(a
(hSW(a
VkSW(a
JkSW(a
qkSW(a
fkSW(a
DjSW(a
cjSW(a
njSW(a
>jSW(a
(jSW(a
^eSW(a
NeSW(a
ueSW(a
|eSW(a
keSW(a
6eSW(a
=eSW(a
$eSW(a
xaSW(a
jaSW(a
bgSW(a
lgSW(a
ZfSW(a
!dSW(a
_dSW(a
pdSW(a
odSW(a
A`SW(a
UaSW(a
LaSW(a
-dSW(a
M`SW(a
e`SW(a
vgSW(a
7`SW(a
+`SW(a
(fSW(a
bcSW(a
IbSW(a
SdSW(a
8aSW(a
-aSW(a
ncSW(a
4cSW(a
0gSW(a
#gSW(a
FfSW(a
pfSW(a
hfSW(a
<fSW(a
cSW(a
8bSW(a
ubSW(a
fbSW(a
RSW(a
GSW(a
wSW(a
;SW(a
"SW(a
KDBM('
\/o>
1SPS*
com.apple.Safari
Unable to resolve HTTP prox
5p&_YXA]
Q6,s{wX6dsbcf{yU(dt*
vkq.&*
v0*]QB.br,
7X{!m}#
|qq8oo8JJ"{{{{-ff-OO
lH9#|txWuul_JV
w;!VZI
NNXOYY|
J]TW@[t
AE]V\[e
S^^[H]
]aKo8.1<;
V9oefonncbbc
[RGRWCCR
VBksEMAB]^OMu
'56?*68
,0?1*!=3
8JdtELMr
^l|f#k
>m&;7p
YKm7b->
a+61?74
^INX^h
HLT_URl$
bxsrsdU6tsA$
`eag`{fn
~vbw|wx
Rzv~sxH
CR_eSQW]UWfF
n!;0809
':!46<!;0=!
W;SXvawskvFGQ
BNCNA]Z@E
6E:9EX_QYZiAYA
Y\A@YEiAGZEE@f
[Z\ATV\YEEt
PYEEtiPYEEtiFPY\s
[ZXXZvi*
c@intqm3st|u~dxvAnx~sxox{xoMAoxihmpr^=xqmm\A
[tkfnsibcbuD[sahthudnJ[
BlC\QYD^UTUBslDV_C_BSY}l
9I@EJC^|
}p{fnl}hj
Z4p170
iUC^FBBPaAE\b
xbycooMP
w$$2%33
!CYREEBT
MA~ro^nxe}yykZo|kY
E+tPln
mx ),#*7
+!y~y>cu|yv
Hhl%97//=,
ZBO]qK]O\F^]]O^q\KZ]OC$
/DFCEP
<+=9!<
l:6:`}= ! )'=
H9\QR_\W
RHSIEEG
ISHR^^\
Am{f~zzhy
poyd|xxj{
m"4=87>#!
FWNXQT[ROMa
nFfx~FMXg
rup_KEJBCOpeyk
b|zBI\cpI^M[XJC
v,qyly|5plmy
]k.?$&.9
4p?"?t4*
=$*%-, m1&06!
$aq~nwzm4F<~vzui~hN<&~vzu[@|uroo~h44!
6599/))
j>/$8/>$
j/>+<#8
UCJO`KGTAITv
lEPE@xWWAGGe
PAJVAPJm
APERMVtx
%?$>220
ddrttV7cryercy^7rcva~eG
PPF@@BWFMQFWMJFWBUJQS
DUXX]nQX]r
'k|ok|J%
C=wplK,?
QIe)>(
GOfVy5"4
1fzln=+9:ze?61<7;6=x++9
qU\YvIU{SY\RE`
^!~3x!#9MLJWB@LO#ZFH#FWBUJQSX
9:;<=>
N,RTIV
'l`hvXCQ\vl
RA^EsZRCDNd
^xtx"x
e`|xJP~cxmkezmB,\XJP
]8REVREs
tBWBGSSB+
,6ZDXJ
LsBWBGSSB
.f($(r(/50,(
|.982=113|
ujd$t|/905
|1=.;3.
'GTKPfOGVQ[q.
#zlqimm
>gqltppbS8
DB_@oBUFBUC
<5nfjeTynx~Tyn}ynx$7
\JWOKKYHgJ]KMgJ]NJ]K
i/zoL.kfZ
37bwT6s~BJ
TWVYX[Z]\_^A@CBEDGFIHKJMLOtwvyx{z}|
~a`cbedgfihkjmlo
ZH@Fa.
vMWLVZZx
UDwSSAp
varvaWTPIW
EY{c1+0*&&
m?ccubttQ|yq]
!1556./
?SEX@DDVg
K]@X\\N
'WD'8'
x&0-511#
U5#>&""0
hpgtpgQ"
p:CYSVUjITUSNJ_YB
_N[Ni^_NJOHHUyCY[]_VeIOVjwuy
5"#4?%#0
%7>">#28
4#0&%7>
gpcgpF
XNSKOO]L_REO
6J!`inh`srhknfj
_MA^MZxDAIEPGntPGNGZMitMZI_\NG{tzm{}w|fmzz}kwqmc`
-g{n_cfnbw`I
G~|zitoHG
:jogkZ(
4195 7
x59*?7*
49-,*1
/|zm1kqjp||^Clkqjp||^C
A?,+v,6-7;;
fqbfqGsz}y{wz]
2uotnbb@
M;-0(,,>
F,KW2'"h"('1
ZP_IbRW_s
_L[NqbRW_s
_L[Nqb
o~|lz{g<
a>nmpyxwvutsrq:9876
/.-,+*)
;lSSAppop
625FBWR
EBXCYUUWjBXS_Zu
%bO}QK@LIf
R-jrj<-:+-
[MA\A\FMLaZMLFM{
)mnvqkpjffD
gfac":
&)H^C[__M|
obzPOBZ`mi^PI^M[XJC_
USEX@DDVg
?(;-.<5
QTKF^|`oa\
LI(?,(?
?(;-.<5
OF>HE]jy
FQ\Ds`f~G
!g/<88*;
]$/(/h%(0'42*3
'$0$f%(03
y/<88*;
S^FQBD\Els~fQBD\el
QBFFTE
.#$#d)$<+8>&?
N]YYKZ
q1a:,%
$(;.&;
"Kp&KLK
ALTCPVNW~altCPVNw~
ALTcpvnW
ALTCPVNW~altCPVNw~
t/1-?mz{~psqhp[U
rlpb0'&#-.,5-
2+$o25/4."" o2&/(55$
5/4.""
o2&/(55$2o3$% .-/6.%+o&3.
XLEB__NxYNGGDY_EDhEDB_JHB_ENC_^j
EDB_JHB_ENC_^J
LEBGGDY_EDH
U$=:47:
V@]EAASB
o[+>;q,+1*0<<>
3>=038
1>6336-
ZuountxxZ
_W\QZ]TMPhSNLFr(
awjrvvdUfk@
M^U[_d
TB_SCYt
5gql`pjG
N5%<1&
5=1>"5#%
!7x$DMC@Ur
WB>sfsV2|{u}^Nf~gstwVN
0;H]Hm
G@NFeu
171{a,0>
;uxd_R
B17}g*68
XS'$%$!$w$%$p$#r",, ",u&
8|{|;fpy|szge
GOCLPGQwFGVR[PALG^FPMUQQCrFGVR[PALG^GOCLVQMJ
itvtt1
vklbjiZ
u5=1>$#?8
ed~07+
-3)}|zgrpz
UQ2~d02~n0
R7 62*7
ur 7!%=
r*76<3
)1- -6
<$8<>#9
1jylK/
Z>l{mKBl
C73a&617
V5 19;
jO+ynx^Wynx|dyI&n}jyIWnyj|
mdXn}jyI
7?(>:"?
lsfsV2`waGN`wae}`Pf|wQ
[N'<>.)/
j%.%'%
jTYQ\KTk
Ul{miql\>.(-
VqgpfbzgW5ztwp|Y
V(.zjmk
-:,(0-
&<>)6-
p`[KLJ
dq}qq}Q
&1'#;&
oGPBP\cX@\XZG]viFPY@QZXiR[\AAPFi
G\[E\PYfiV[|
G\G[Ps
TCUsz@TSu
ob_^F^^r
9k~kN*xoy_Vde}eeIVde}eeI
+3/+)4.
53$-.9"
tbrVAHK\GhrOBBGTAcr
pKM]Z\
588=.;
WK]tW_]P~
tj}T`wpkQ
3$-9.)2
8$"/>?83(.;s
1f3eurt
wEDNGNf
5717=
588=.;
ICBJL_iHNd
aSRZ\OyX^taRYRPR~a
DTCj^IXM{
+}^R@HDGm
WBWRFFW
URQURTTT
w#2;2<%2
)Qn7l{zlq3{jg|>{hwj
p>2,>pqwml{h>2vm
V6>+&0/>
o$7cvzexq7rc~[FD
2BKEFS
]D!'*!15!7
wrF7ERPRCY^
.- (5/$%$3
a26.%/(
(((e...
3'psw#*1
'{,5OS@IBkSDBMEh
QG*6%,'
}oxytkroM=xktitptoM=i{rnro~tP
rTGXCu\TEBHb
w]j%O-'l
2A@[y}
}O>>(?))
novj-vzgv
l??&5`! &;.,&#??.
Cou~vnxt
@KX]WLV[
MKXIPMULT
RXNIUJ*
n``v%qjkkdf%hd`wqV
}7YUQF@gQX]r
GYUQF@G
PQC[XXU
GQ]F@ZqQB[YQf
L%q<w$,4>,bmdx,
e,ikm~cx_ux~i|c~\hive`me~i_,idx,jc,ive_:
MZG\{Q\ZMXGZxLMRADIAZM{
wuu}uhr|v|h
C:nK)#hk#;3n#h3)viz@vf
dn%&nv~#n%~d;$7
WH[aW_S|
n:}w<?wog:w<g}"=.
hS0<h%n=5,5{t}a5ffpy5f|5pxt[r{|gaF5p}a5sz5po|F0
H;o#i:2o"i2|szf2aaw~2a{2w`}fAkf`wb}`Bvwh{~s{`wA2wzf2t}2wh{A
~56~fn3~5nt+4'
v4.0.30319
#Strings
.Tf
/ a n
!""I"k"t"
__StaticArrayInitTypeSize=10
__StaticArrayInitTypeSize=11
73c84c79-386f-4f50-92f5-29ce7bd73321
HMACSHA1
Nullable`1
IEnumerable`1
ICollection`1
IEnumerator`1
IList`1
get_Item1
HMACSHA512
__StaticArrayInitTypeSize=12
__StaticArrayInitTypeSize=32
Advapi32
kernel32
Microsoft.Win32
user32
ReadUInt32
ToUInt32
ReadInt32
ToInt32
KeyValuePair`2
Dictionary`2
get_Item2
Tuple`3
get_Item3
__StaticArrayInitTypeSize=24
__StaticArrayInitTypeSize=144
ToUInt64
ReadInt64
ToInt64
__StaticArrayInitTypeSize=84
__StaticArrayInitTypeSize=16
ReadUInt16
ToUInt16
ReadInt16
ToInt16
HMACSHA256
__StaticArrayInitTypeSize=6
get_UTF8
<Module>
get_FormatID
get_ASCII
System.IO
get_IV
set_IV
value__
ProtectedData
PropertyData
mscorlib
System.Collections.Generic
Microsoft.VisualBasic
WndProc
FromFileTimeUtc
get_Id
GetWindowThreadProcessId
GetProcessId
GetProcessById
OpenRead
SHA1Managed
RijndaelManaged
Interlocked
set_Enabled
add_Elapsed
System.Collections.Specialized
get_IsInvalid
get_Guid
GetField
TrimEnd
ReadToEnd
Append
get_Second
get_Millisecond
GetUpperBound
GetLowerBound
set_Method
Clipboard
Replace
IdentityReference
set_Mode
FileMode
PaddingMode
CryptoStreamMode
CompressionMode
CipherMode
SelectSingleNode
XmlNode
get_Unicode
get_BigEndianUnicode
IsTextUnicode
VaultFree
FromImage
SendMessage
AddRange
CompareExchange
CredentialCache
EndInvoke
BeginInvoke
GetEnvironmentVariable
SetEnvironmentVariable
IEnumerable
IDisposable
ToDouble
get_Handle
RuntimeFieldHandle
SafeHandle
GetModuleHandle
RuntimeTypeHandle
ReleaseHandle
CreateHandle
GetTypeFromHandle
handle
Rectangle
ToSingle
DeleteFile
MoveFile
get_MainModule
ProcessModule
get_Name
get_FileName
set_FileName
GetModuleFileName
GetTempFileName
GetFileName
get_ModuleName
get_OSFullName
get_FullName
get_UserName
get_ComputerName
get_ProcessName
get_ProductName
GetProcessesByName
GetDirectoryName
FromFileTime
ToFileTime
DateTime
GetLastWriteTime
SetLastWriteTime
SetCreationTime
GetLastAccessTime
SetLastAccessTime
AppendLine
get_NewLine
Combine
LocalMachine
Escape
Unescape
DataProtectionScope
ValueType
SecurityProtocolType
GetType
set_ContentType
FileShare
Compare
System.Core
PtrToStructure
get_InvariantCulture
Capture
NameObjectCollectionBase
HttpWebResponse
GetResponse
Dispose
Reverse
Create
MulticastDelegate
GetKeyboardState
GetKeyState
Delete
get_CanWrite
STAThreadAttribute
CompilerGeneratedAttribute
GuidAttribute
SecuritySafeCriticalAttribute
ExtensionAttribute
AssemblyFileVersionAttribute
FlagsAttribute
CompilationRelaxationsAttribute
ReliabilityContractAttribute
ParamArrayAttribute
RuntimeCompatibilityAttribute
SuppressUnmanagedCodeSecurityAttribute
set_UseShellExecute
get_Minute
ReadByte
ToByte
get_Value
get_HasValue
GetValue
GetPropertyValue
set_KeepAlive
Remove
73c84c79-386f-4f50-92f5-29ce7bd73321.exe
get_Size
get_HashSize
set_BlockSize
get_KeySize
Serialize
Deserialize
Initialize
SuppressFinalize
Resize
SizeOf
get_ItemOf
LastIndexOf
get_Jpeg
System.Threading
set_Padding
UTF8Encoding
GetEncoding
System.Drawing.Imaging
FromBase64String
ToBase64String
EscapeDataString
UnescapeDataString
GetPrivateProfileString
ToString
GetString
Substring
System.Drawing
get_Msg
ComputeHash
get_ExecutablePath
GetTempPath
GetFolderPath
get_Width
get_Length
SetLength
GetWindowTextLength
EndsWith
StartsWith
get_Month
PtrToStringUni
AsyncCallback
TransformFinalBlock
TransformBlock
get_CanSeek
AllocHGlobal
FreeHGlobal
Marshal
Decimal
System.Security.Principal
set_Interval
Rijndael
System.ComponentModel
Kernel32.dll
kernel32.dll
User32.dll
user32.dll
vaultcli.dll
psapi.dll
bcrypt.dll
System.Xml
set_SecurityProtocol
Control
FileStream
get_BaseStream
GetResponseStream
DeflateStream
CryptoStream
GetRequestStream
MemoryStream
get_LParam
get_WParam
get_Param
get_Item
set_Item
VaultGetItem
OperatingSystem
SymmetricAlgorithm
KeyedHashAlgorithm
Random
ICryptoTransform
ToBoolean
IsLittleEndian
CopyFromScreen
get_PrimaryScreen
ChangeClipboardChain
SeekOrigin
get_OSVersion
get_Version
System.IO.Compression
Application
get_Location
GetVolumeInformation
SystemInformation
System.Globalization
System.Web.Script.Serialization
System.Reflection
PropertyDataCollection
NameValueCollection
MatchCollection
GroupCollection
KeysCollection
ManagementObjectCollection
KeyCollection
get_Position
set_Position
SearchOption
Win32Exception
CryptographicException
ArgumentOutOfRangeException
InvalidOperationException
ArgumentException
get_StatusDescription
System.Runtime.ConstrainedExecution
StringComparison
Intern
CompareTo
CopyTo
ImageCodecInfo
FieldInfo
FileInfo
CultureInfo
FileSystemInfo
FileVersionInfo
GetVersionInfo
MemberInfo
ComputerInfo
get_StartInfo
ProcessStartInfo
GetLastInputInfo
DirectoryInfo
Bitmap
System.Linq
get_Year
ToChar
DirectorySeparatorChar
StreamReader
TextReader
BinaryReader
SHA1CryptoServiceProvider
MD5CryptoServiceProvider
RNGCryptoServiceProvider
TripleDESCryptoServiceProvider
BCryptCloseAlgorithmProvider
BCryptOpenAlgorithmProvider
IFormatProvider
StringBuilder
SpecialFolder
Encoder
Buffer
ServicePointManager
ManagementObjectSearcher
SecurityIdentifier
ElapsedEventHandler
ToUpper
CurrentUser
EncoderParameter
BitConverter
BinaryFormatter
SetClipboardViewer
ToLower
JavaScriptSerializer
get_Major
get_Minor
GetLastWin32Error
IEnumerator
ManagementObjectEnumerator
GetEnumerator
RandomNumberGenerator
.cctor
Monitor
CreateDecryptor
CreateEncryptor
ReadIntPtr
get_Hour
Graphics
System.Diagnostics
get_Bounds
Microsoft.VisualBasic.Devices
System.Runtime.InteropServices
System.Runtime.CompilerServices
GetInstances
get_ChildNodes
Matches
GetDirectories
get_Properties
ExpandEnvironmentVariables
GetFiles
EnumProcessModules
NumberStyles
GetSubKeyNames
ReadAllLines
Rfc2898DeriveBytes
ReadAllBytes
GetBytes
get_Values
ElapsedEventArgs
get_Ticks
ICredentials
set_Credentials
get_DefaultCredentials
Equals
CreateParams
VaultEnumerateItems
System.Windows.Forms
Contains
System.Web.Extensions
System.Text.RegularExpressions
System.Collections
set_MaximumAutomaticRedirections
StringSplitOptions
RegexOptions
get_Groups
get_Chars
GetImageEncoders
System.Timers
RuntimeHelpers
EncoderParameters
ManagementClass
FileAccess
get_Success
GetCurrentProcess
VaultEnumerateVaults
set_Arguments
get_Exists
arrays
get_Keys
get_ModifierKeys
Concat
AppendFormat
ImageFormat
Subtract
ManagementBaseObject
ManagementObject
Collect
set_AllowAutoRedirect
Unprotect
System.Net
get_Height
op_Explicit
WaitForExit
VaultCloseVault
VaultOpenVault
get_Default
GetValueOrDefault
IAsyncResult
set_UserAgent
System.Management
XmlElement
Environment
XmlDocument
get_Parent
GetParent
get_Current
get_Count
get_TickCount
set_IterationCount
BCryptDecrypt
BCryptEncrypt
TrimStart
Convert
HttpWebRequest
XmlNodeList
ToList
set_Timeout
GetKeyboardLayout
get_StandardOutput
set_RedirectStandardOutput
MoveNext
System.Text
ReadAllText
AppendAllText
get_InnerText
GetText
GetWindowText
get_Now
GetForegroundWindow
NativeWindow
set_CreateNoWindow
ToUnicodeEx
GetModuleFileNameEx
RegQueryValueEx
UnhookWindowsHookEx
SetWindowsHookEx
CallNextHookEx
RegOpenKeyEx
get_Day
ToByteArray
InitializeArray
ToArray
ToCharArray
Consistency
get_Key
set_Key
OpenSubKey
RegCloseKey
MapVirtualKey
ContainsKey
BCryptImportKey
BCryptDestroyKey
RegistryKey
System.Security.Cryptography
GetExecutingAssembly
Multiply
BlockCopy
System.Runtime.Serialization.Formatters.Binary
get_TotalPhysicalMemory
CreateDirectory
Registry
get_Capacity
Quality
op_Equality
op_Inequality
System.Security
IsNullOrEmpty
BCryptGetProperty
BCryptSetProperty
<PrivateImplementationDetails>{F6CD6261-01EB-44D8-B35F-E01395CDB996}
1.0.0.0
$bd3df13e-8d14-4790-b623-56f7262b0ec8
WrapNonExceptionThrows
_CorExeMain
mscoree.dll
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<assemblyIdentity version="1.0.0.0" name="MyApplication.app"/>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v2">
<security>
<requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3">
<requestedExecutionLevel level="asInvoker" uiAccess="false"/>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
pp p!p"p#p$p%p&p'p(p)p*p+p,p-p.p/p0p1p2p3p4p5p6p7p8p9p:p;p<p=p>p?p@pApDpEpFpGpHpKpe=q=
BACAIHJHUTVTWT[Zbadcecfcgchciclkrqsq}|~|
Accounts
logins
sha512
credential
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
FileDescription
FileVersion
1.0.0.0
InternalName
73c84c79-386f-4f50-92f5-29ce7bd73321.exe
LegalCopyright
OriginalFilename
73c84c79-386f-4f50-92f5-29ce7bd73321.exe
ProductVersion
1.0.0.0
Assembly Version
1.0.0.0
Antivirus Signature
Bkav W32.Common.3C2BA786
Lionic Trojan.Win32.Stealer.12!c
Elastic Windows.Trojan.AgentTesla
MicroWorld-eScan IL:Trojan.MSILZilla.24596
ClamAV Win.Packed.Generic-10003641-0
CMC Clean
CAT-QuickHeal Trojan.Agenttesla
McAfee Artemis!2E626D1C6E85
Malwarebytes Generic.Malware.AI.DDS
VIPRE IL:Trojan.MSILZilla.24596
Sangfor Suspicious.Win32.Save.a
K7AntiVirus Trojan ( 005a7a471 )
BitDefender IL:Trojan.MSILZilla.24596
K7GW Trojan ( 005a7a471 )
Cybereason malicious.1c3dee
Baidu Clean
VirIT Clean
Cyren W32/MSIL_Kryptik.IZQ.gen!Eldorado
Symantec ML.Attribute.HighConfidence
tehtris Clean
ESET-NOD32 a variant of MSIL/Spy.AgentTesla.F
APEX Malicious
Paloalto Clean
Cynet Malicious (score: 100)
Kaspersky HEUR:Trojan-PSW.MSIL.Stealer.gen
Alibaba TrojanPSW:MSIL/AgentTesla.bbf1901b
NANO-Antivirus Clean
ViRobot Trojan.Win.Z.Agent.168960.DE
Rising Spyware.AgentTesla!8.10E35 (CLOUD)
Sophos Troj/Steal-DJM
F-Secure Trojan.TR/Spy.AgentTesla.twnbc
DrWeb BackDoor.SpyBotNET.73
Zillya Clean
TrendMicro TrojanSpy.Win32.NEGASTEAL.YXDI4Z
McAfee-GW-Edition BehavesLike.Win32.Generic.ch
Trapmine malicious.moderate.ml.score
FireEye Generic.mg.2e626d1c6e856072
Emsisoft IL:Trojan.MSILZilla.24596 (B)
SentinelOne Static AI - Malicious PE
GData MSIL.Trojan.PSE.10FWF4K
Jiangmin Clean
Webroot Clean
Avira TR/Spy.AgentTesla.twnbc
MAX malware (ai score=81)
Antiy-AVL GrayWare/MSIL.Kryptik.AA
Kingsoft malware.kb.c.998
Gridinsoft Trojan.Win32.Agent.sa
Xcitium Clean
Arcabit IL:Trojan.MSILZilla.D6014
SUPERAntiSpyware Clean
ZoneAlarm HEUR:Trojan-PSW.MSIL.Stealer.gen
Microsoft Trojan:MSIL/AgentTesla.EH!MTB
Google Detected
AhnLab-V3 Infostealer/Win.AgentTesla.C5356829
Acronis Clean
BitDefenderTheta Gen:NN.ZemsilF.36738.km0@a4ovPKj
ALYac IL:Trojan.MSILZilla.24596
TACHYON Clean
DeepInstinct MALICIOUS
VBA32 Trojan.MSIL.AgentTesla.PInv.Heur
Cylance unsafe
Panda Trj/Chgt.AD
Zoner Clean
TrendMicro-HouseCall TrojanSpy.Win32.NEGASTEAL.YXDI4Z
Tencent Trojan-PSW.MSIL.Stealer.kc
Yandex Clean
Ikarus Trojan.MSIL.Spy
MaxSecure Trojan.Malware.300983.susgen
Fortinet MSIL/AgentTesla.F!tr.spy
AVG Win32:PWSX-gen [Trj]
Avast Win32:PWSX-gen [Trj]
CrowdStrike win/malicious_confidence_100% (W)
No IRMA results available.