Static | ZeroBOX

PE Compile Time

2022-03-31 14:09:31

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x00069d44 0x00069e00 6.48772380882
.rsrc 0x0006c000 0x00000626 0x00000800 3.56617445261
.reloc 0x0006e000 0x0000000c 0x00000200 0.101910425663

Resources

Name Offset Size Language Sub-language File type
RT_VERSION 0x0006c0a0 0x0000039c LANG_GEORGIAN SUBLANG_NEUTRAL PGP symmetric key encrypted data - Plaintext or unencrypted data
RT_MANIFEST 0x0006c43c 0x000001ea LANG_GEORGIAN SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with CRLF line terminators

Imports

Library mscoree.dll:
0x402000 _CorExeMain

!This program cannot be run in DOS mode.
`.rsrc
@.reloc
@P@Y(g
@L@Y(g
@L@[(g
@L@Z(g
\@[(g
c#d:@#
P@Z(g
`P@Y(g
[YZ_bX
[XZ_bX
[YZ_bX
[XZ_bX
H|@[(g
[XZ_bX
[XZ_bX
[YZ_bX
[XZ_bX
Pu@X(g
[XZ_bX
[XZ_bX
[XZ_bX
[YZ_bX
[XZ_bX
[XZ_bX
[XZ_bX
[XZ_bX
[YZ_bX
[YZ_bX
[YZ_bX
[XZ_bX
[XZ_bX
[XZ_bX
[YZ_bX
[XZ_bX
[XZ_bX
[YZ_bX
[YZ_bX
[YZ_bX
[YZ_bX
[XZ_bX
[XZ_bX
[YZ_bX
[XZ_bX
[XZ_bX
[XZ_bX
[XZ_bX
[YZ_bX
[YZ_bX
[XZ_bX
[YZ_bX
[XZ_bX
[YZ_bX
[XZ_bX
[XZ_bX
#)~q7ye
[YZ_bX
#v[{M+
[XZ_bX
[XZ_bX
[YZ_bX
[YZ_bX
[YZ_bX
[YZ_bX
[YZ_bX
[XZ_bX
[XZ_bX
[YZ_bX
[YZ_bX
[XZ_bX
[YZ_bX
[XZ_bX
[YZ_bX
[YZ_bX
[YZ_bX
[XZ_bX
[YZ_bX
#CkAn5I
[YZ`(L
[YZX(a
[YZX(a
[XZX(a
[YZX(g
[YZX(a
[YZX(a
[XZX(a
[XZX(a
`aiYfafe
ZefYXe
faefYf
ZXYfe}
aXeXff
#C`E"v
ZXefXf
eXeXXf}
+!^_[
9u+9^_[
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
PADPADP
ploV<E
F)/7Z~
Z.`jhH
?-~\nb
NotX!:T1^
A\l^P=
/'t6}c
BRM=:@
t!fv1
sYbv=T
BEk~j\
%p+:mR,R1
h~L$<c
,7MDI
)SK],
rAR:NI
![ghBA
9QPe2R.
F"[P,{n
LS'wsgI
<jvmfE
#Frc&Q1
djO=~d>
2.+e-p)
IOm_*6
!(4w'z
koUP,Z
u(X:=r
;$SN4el
SmuP_H
~O=[r9YCA
,8aEm'I)0r"6
JvM!;)
o6\C"~6<
MI,6{q
5p~RvCi
ITGA<
[<G-oU
)E@aVZ0
k=]]^`
c0q&>~
+6N]-}
!%}eE.
`YfC",t
FUL6!7
\zrP>)
~W}]DkC
#.It}hD
]>3v n2IS
Q2B~*u
Gr'3~;)
%hirwv"
C%qOA"^y
gR5:x?
Q"D~l~
{T<eE!
\]H~p}`
:nNieE
T/"5<
Q4)c.w
o6\C"~6<
0`7Gv6e
6{Yh#G
JWz^;/
5z!KLj]
3Zf pM>J
hQ_I-4
tk@%iZz
dtr@S}N
Lc}.Q[
1[L1y;
M6*F=H]/
\,6nj0
dk0Hj
X$2uV5
:I\Pq%
I&"_5=(
r0@8:ZH
yIlQ36'
[SE5''
qO[Tp3K
[zq~Ul
o6\C"~6<
7r32y2m
o6\C"~6<
sLAlp>
+x+j(F7
59PhpX
6{t5->
+x+j(F7
0Yf#d4
Vl(@$8
qI_q0Bg
FUEo+e
^T[VLf
&lztQq
):-~E
*`]YOn
GjL){$
S#_Qs
rgh`[g.B
6fX\{;
8xeU%b
Ds%.Fl
:nKSw@%
!}y; E
wt$J7
B$jb'n
w+Y]Y/
BjT5W_s
2+kxU}
]R/gh/
V{z2S(I
U3uU<y
h0V_/#
j7R+l^
l;I3m8
44G&hC
t$5AI,
>PO(]p,2
l_TMHw
!V4Z5H<\a{I
Z/rXYf
^I,4 J"e
]~/2hJ
a&fY:D
T'\YZU
#d[^!r
{;&evb
ej!g:_,]
c_$4ad
<U=X_(,
l5|d21
nW(lKs
&[?>L:
O_*a.p
wKa6PJ
;!yxpl
zizxV*A19><7<
>mvG^,
m>>XalS
<?{<qm
'u{I@oT
86o^+*?
&W8!Zx
JYMYu-
^;g~uJ
rtpGDVej
:jSbzk
0Q8pw,t
XS ^I""
sv6c@p
*NaWP9
UPlpct
"{ZvK0zo
2i~j9
4Kbx(^4
RrQ@:&
."@zDL2I
'hU_j5
uoEK~rX
ZmwmCp8
-%^X8~
=9Z0KB
Wo5>fU
szMfMY52
+PTjW&
T>,_m"
:G'0-y
>u6hV/
qw;'DE
gO;n_=
dIhl77
0a_X%n
:lF8p{}n
@/SaX
[Tlom1
1KAs?1(
?Txj1$
*0f*q3qR
$`mc}
DCzmyI
GlA7FX\m
[N]@cC_4j
o6\C"~6<
iKHpap
pZ,QX$
5=-292
f/Nzr^
k*]HV,
zierf/E
XA,vgB_
BKLvnu
zu6b_"
dPAe2n_LBR
y]1YsF
B|_*>K7
yr)BDRxwW
q)'4/T
zj6oz|
KN56anX
1d9/cz
; t6V.}
)(f2J*cQW
*{2B98
]LIWz^
71\:W@I
1gWTvL
809odS
UGHigc~
#]Xgj[
1-X}+s
~W{l
*7BG9/
S?+D,P
3ef"nf
LjKNuX
>k%YfU
U48dL?b
o9?{"<K
R-l\&F
jL~0$-D
/e X1:
/R6{>W
m/CdVn
,?Lt%|
z PRaJ
v^)rpdG
Y^6#k,e
={k/QO
NoSs_7m
;P.w\8
VeJf(!
Xn~&Xt1
B<w|S"
d-9)G9Q
(pqJ\JEGi
+Dv3'T
>|WSnt
4M5E:A
@1+}&z
hJ%.1Q
X;8Mtz
>|WSnt
4M5E:A
@1+}&z
~'+"[G
Bg?a$$
1EP}tmi|
i>Pvdv
c5I4:?
f\)mBA
1K3(xh
Psn`:\T
K=IY[oG9
Vm}[[_#
{]X\@UE
5.sC8nE
SFFwoV
(`AM^
H!M"={S
<t8Hg9
MpvAg[
j63EtX
_%|u^QG
cX[_!#
'nDHW#
r3x[d:
meybD,
pkU#><@
v4.0.30319
#Strings
Digit200_300
<WriteTo>b__62_0
MFunc`1
IEnumerable`1
FieldName1
Pop1_pop1
Popi_pop1
CodePageGB2312
S_BLOCK32
ToUInt32
ToInt32
<SortTables>b__191_2
Func`2
Set_Prime2
S_COMPILE3
<gacInfo>5__3
Reserved3
get_IsProcessorArchitectureX64
S_RESERVED4
ToInt16
M_Item7
get_UTF8
<path>5__8
+/RSIY8Cn+169g9flJ3okA==
<Module>
S_LMANPROC
ListParamDefMD
TYPESIG_NAMESPACE
CSIDL_PROFILE
REG_OPTION_VOLATILE
LOCALE_SSHORTDATE
get_ASCII
ShortInlineI
KEY_CREATE_LINK
System.IO
DX_NNY
value__
ICurrentEra
ThaiBuddhistEra
GetAbsoluteDateUmAlQura
DefineInitializedData
ClrAsmName_Mscorlib
mscorlib
InitdMethodSpec
CharSetNotSpec
Arabic
FromAsyncCoreLogic
System.Collections.Generic
get_IsStatic
acrdIpc
CreationTimeUtc
EncBaseId
GetProcessById
lpNumbefsdfrOfBytesRead
thrfsdfead
get_CurrentThread
thrfdsead
hThrefsdfad
RijndaelManaged
get_IsAttached
_locked
CheckLoadSupported
EnsureThreadRequested
fsdsddfdffd
ToPropertyRid
Get_DaylightTransitionEnd
GetSourceStartEnd
UriKind
M_iaUpperBound
Set_IsBackground
set_IsBackground
DynamicMethod
DefinePInvokeMethod
ResolveMethod
DefineGlobalMethod
GetMethod
NetGuard
ScanDateWord
NetworkInterface
get_IsInterface
Replace
CoCreateInstance
Get_TypedReference
LoadResource
FindResource
SizeofResource
M_canUnrestrictedOverride
GetHashCode
SetCode
set_Mode
PaddingMode
CipherMode
bigEndianUnicode
Xenocode.Client.Attributes.AssemblyAttributes.ProcessedByXenocode
rpkfdsddfsdlevsfdsfveee
ReadSubTree
nSizfsdfe
Storage
get_Message
EndInvoke
BeginInvoke
_typeTable
GetEnvironmentVariable
Enumerable
set_Visible
GetAssertAllPossible
get_Handle
RuntimeFieldHandle
get_MethodHandle
RuntimeMethodHandle
GetStdHandle
GetModuleHandle
get_TypeHandle
RuntimeTypeHandle
CloseHandle
GetFieldFromHandle
GetTypeFromHandle
WaitHandle
Set_IsNoMangle
Console
DebugAssertTitle
CalendarWeekRule
get_Module
DefineDynamicModule
TryParseGuidWithNoStyle
set_FormBorderStyle
get_Name
CAlternateFileName
CultureName
EnumMembersWithName
Set_IsSpecialName
CreatePropertyFullName
lpApplicatfsdfionName
M_memberName
ConstructorName
AssemblyName
ExpandPrime
InternalWaitOne
AppendLine
WriteLine
lpCommandLfsdfine
ReadInlineNone
EqualsResolutionScope
get_FieldType
InterfaceType
MethodCodeType
Get_RuntimeType
DefineType
BaseType
CreateType
ValueType
IsInstanceOfType
get_DeclaringType
GetEnumUnderlyingType
flAllocafstionType
get_ReturnType
get_ParameterType
SetType
HasElementType
System.Core
_store
ResolveSignature
SetLocalSignature
MethodBase
OrdinalIgnoreCase
M_ignoreCase
AddLowercase
Truncate
CreateDelegate
Get_IsDelegate
MulticastDelegate
UnimplementedState
set_WindowState
FormWindowState
_complete
STAThreadAttribute
CompilerGeneratedAttribute
UnverifiableCodeAttribute
UnsafeValueTypeAttribute
BabelAttribute
SuppressIldasmAttribute
AssemblyInfoAttribute
YanoAttribute
DotNetPatcherPackerAttribute
BabelObfuscatorAttribute
CryptoObfuscator.ProtectedWithCryptoObfuscatorAttribute
DotNetPatcherObfuscatorAttribute
DotfuscatorAttribute
CompilationRelaxationsAttribute
SmartAssembly.Attributes.PoweredByAttribute
RuntimeCompatibilityAttribute
System.IConvertible.ToByte
CachePathValue
SetValue
get_IsAlive
M_throwOnRelative
padhFfSFli.exe
get_Size
Set_CacheSize
Set_PackingSize
Get_StreamSize
M_maxSize
dwSfsdize
dwSfsdfize
SizeOf
fsddddffsddfdf
fsmdfdmdf
get_IsByRef
CorLibAssemblyRef
ValidateByref
drdfefsdddfslofsdfeg
dddfdffdsdfhfg
ModifierSig
ToGenericInstSig
System.Threading
set_Padding
Encoding
IsLogging
Ceiling
BestFitMapping
FromBase64String
GetOperandString
OutputDebugString
ToString
GetString
gsefhfssdlfdsfdsfdfpfdhddgdsg
gddgdlfsdsdsfdlsgsdsdfhsg
Dispatch
ComputeHash
BNoSearchPath
GetTempPath
DisplayPath
ObfuscatedByGoliath
DatePartMonth
padhFfSFli
AsyncCallback
callback
GetFieldRVA_NoLock
GetImplementation_NoLock
GetFieldTokenNoLock
S_ForLock
TransformFinalBlock
M_block
FirstDayOfWeek
IChunk
ReplaceInPlaceAtChunk
ThrowOnUnmappableCharMask
AddFieldMarshal
BeginWriteInternal
CheckLevel
Set_MinimumLevel
kernel32.dll
Control
SaveToStream
M_stream
GetOwnerOfGenericParam
IsGenericParam
FamANDAssem
InternalEncodingDataItem
System
SymmetricAlgorithm
HashAlgorithm
EfiRom
ICryptoTransform
EndWritePEChecksum
Set_IsRemoveOn
Conv_R_Un
Add_Ovf_Un
get_MetadataToken
AtNmToken
AssertPermissionToken
EventToken
lpNumberOfBfdsfytesWritten
hTokefsdfn
SNegativeSign
DelaySign
Set_ControlAppDomain
get_CurrentDomain
MessageBoxIcon
Int32Precision
GetSubKeyWritePermission
Application
get_Location
System.Net.NetworkInformation
NineRays.Obfuscator.Evaluation
AddSubtraction
System.Reflection
CallingConvention
RuntimeWrappedException
NotFiniteNumberException
Get_InnerException
m_exception
GetDynamicILInfo
ReflectionFieldInfo
MethodInfo
AssemblyNameInfo
SectionSizeInfo
startupInfo
MemberInfo
ParameterInfo
get_AlwaysCreateBlobHeap
UriSchemeHttp
System.Linq
set_ShowInTaskbar
Get_DayOfYear
GetYear
EscapeAsciiChar
CatchAddr
CreateSymbolReader
MD5CryptoServiceProvider
TripleDESCryptoServiceProvider
FieldBuilder
MethodBuilder
ModuleBuilder
_TypeBuilder
AssemblyBuilder
UTF8Decoder
GetDecoder
SetEncoder
lpBufdsfffer
_expandedBuffer
FlushInternalBuffer
M_charBuffer
lpBfdsfuffer
ResourceManager
Debugger
ExecutingTaskScheduler
ICustomAttributeWriterHelper
ReturnParameter
GetSymWriter
get_IsPointer
BitConverter
Set_AssemblyResolver
StrongNameKeyPair
GetTokenFor
ServicePackMinor
ResourceManagerMediator
.cctor
dotNetProtector
NotSupported_Constructor
Get_IsInstanceConstructor
get_IsConstructor
CreateDecryptor
IntPtr
_useFileAPIs
System.Diagnostics
Get_HasOtherMethods
GetMethods
GetAllNetworkInterfaces
System.Runtime.InteropServices
System.Runtime.CompilerServices
System.Resources
padhFfSFli.resources
InitializeOverrides
GetIPProperties
IPInterfaceProperties
EnumProperties
bInheritfdfHandles
EnableVisualStyles
GetGroupNames
AppendAllLines
EmptyTypes
lpProcessAttfsdfributes
lpThrefdadAttributes
MethodAttributes
TypeAttributes
OrigAttributes
MethodImplAttributes
GetCustomAttributes
PropertyAttributes
VerifyReadAllBytes
WriteAllBytes
GetBytes
M_indexes
Set_CurrencyGroupSizes
M_stateFlags
BindingFlags
dwCrefdfationFlags
GetMethodImplementationFlags
SetImplementationFlags
SaYearMonths
EnclosingTypeEquals
SetEquals
X509Utils
FilterTasksFromWorkItems
System.Windows.Forms
M_iColumns
DelegateCreatePermissions
Get_HasExtraSections
CallingConventions
MessageBoxButtons
Get_AllShortDatePatterns
get_Chars
ComposedOfNoPublicMembers
GetRequiredCustomModifiers
GetOptionalCustomModifiers
GetExceptionHandlers
GetParameters
Get_TotalHours
get_IsClass
NotECMADigitClass
AssemblyBuilderAccess
hProfsdfcess
hProcess
GetCurrentProcess
hPfdsfrocess
lpBasfsdfeAddress
lpfsdfAddress
lpBasefdsfAddress
GetPhysicalAddress
Set_PreserveStringsOffsets
MaxFractionDigits
M_slots
M_ChunkPrevious
Get_Status
ReadInt32At
RemoveAt
Concat
GetObject
object
Select
FatMethodsDict
CheckFileNameConflict
flProtefdsct
NestedStruct
GrovelForResourceSet
M_serializedPermissionSet
CharSet
GetFieldOffset
M_handlerOffset
Silverlight
op_Explicit
System.Reflection.Emit
SetCompatibleTextRenderingDefault
IAsyncResult
DialogResult
result
Get_Coefficient
sectionAlignment
Environment
lpEfsnvironment
Document
CANamedArgument
CheckRemoteDebuggerPresent
IsDebuggerPresent
ResetEvent
ActionToActionObjShunt
keyCount
ParameterizedThreadStart
TryStart
Convert
IMetaDataImport
Get_MetadataImport
IsImport
FailFast
DataList
SuspendLayout
ResumeLayout
System.Text
contfsdfext
contfsdfdsext
confdsftext
Set_SynchronizationContext
MessageBox
ToArray
get_IsArray
set_Key
CurrentKey
System.Security.Cryptography
get_Assembly
DefineDynamicAssembly
TargetTypeAssembly
CompletedSuccessfully
BlockCopy
AddCategory
RemoveDirectory
lpCurrentfdsfDirectory
ExecuteEntry
op_Equality
System.Security
SuppressUnmanagedCodeSecurity
AtEntity
IsNullOrEmpty
InitializeProperty
SetFromProperty
Onelazy
198 Protector V2
System.Security.Permissions.SecurityPermissionAttribute, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089
SkipVerification
WrapNonExceptionThrows
_CorExeMain
mscoree.dll
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<assemblyIdentity version="1.0.0.0" name="MyApplication.app"/>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v2">
<security>
<requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3">
<requestedExecutionLevel level="asInvoker" uiAccess="false"/>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
padhFfSFli
GetEnvironmentVariable
_ENABLE_PROFILING
_PROFILER
-1816333512
1816345947
1690283858
1690234277
1151814855
1151759654
-348585107
348617445
-721115641
721053389
-910517023
910466664
-2090407884
2090548696
-2077588294
2077618001
-244249290
244284691
-1518476416
1518524128
-909512685
909537927
-2085105765
2085224094
1809053785
1809005213
-152063580
152158757
-369231125
369334661
-2078303700
2078316984
1194622133
1194592785
-969081809
969043625
814112511
814178527
1296560909
1296563886
1699270335
1699245387
-361238454
361312996
1058732822
1058731493
-843964299
843871693
-204353698
204444552
2091728624
2091722211
629669879
629579454
-1290911737
1291058957
-740487528
740531771
468756368
468826469
2017684927
2017688115
-1278073314
1278050804
1917202939
1917225410
-1468243268
1468156523
-1030373270
1030390149
1577289412
1577310497
1165306001
1165299345
-995153818
995153980
1420323712
1420315274
1838002248
1837996681
1545766578
1545740353
-1452255159
1452222583
-1900240839
1900091442
866414995
866478829
976010585
975987952
395548168
395519190
-2092447415
2092504500
932371693
932421396
1163834132
1163799928
-778603342
778674140
-318830489
318939762
1703160330
1703206743
899664301
899615823
5095177
5018202
-2028211731
2028231084
-1771582791
1771690871
-2073964677
2074068608
-1466479377
1466577421
778200109
778238256
-1547877710
1547855702
-1964489030
1964402726
438545542
438539843
-1974738012
1974873816
1660599823
1660582459
-1654136375
1654193724
1462701943
1462737853
765719556
765659518
-357931257
357887350
-1463852348
1463992563
-265944195
265824153
-400959994
401055166
529241391
529210765
378346920
378384946
1249440331
1249409145
-1917851569
1917887195
1251725487
1251655370
-1949318208
1949396182
1537970983
1537916300
1310694383
1310664752
-961239437
961211024
-160225062
160300279
1731485272
1731550380
1700154701
1700140221
-1068806709
1068793281
-61383150
61370308
1587742923
1587756882
-786494637
786483398
-1319665095
1319721133
-667298748
667318913
-539370345
539374189
364016941
364003771
-621598387
621616116
-1510337667
1510238411
-1113522000
1113379653
-1765354760
1765331515
-1994245039
1994365627
-191920693
191921155
90568342
90484202
683409558
683473685
1416667133
1416746251
-1111430475
1111458000
1011516202
1011594606
-143357718
143275213
1791383973
1791424108
2125175829
2125157292
-1685801676
1685726216
-1803002196
1802990140
-212760015
212756010
-493579449
493510245
1129423354
1129413132
439133522
439115653
1579944716
1579998531
-1226087802
1226159197
470625986
470662759
1531242160
1531188948
144201307
144255215
1319429246
1319472767
1309478858
1309502112
-213196631
213154397
-1675037220
1675097705
-1459001314
1458967739
-988254728
988193580
-530264228
530205405
-2062850835
2062817316
994083611
994111601
1185878083
1185845314
-1236101482
1236221905
210934861
211016198
-1601622364
1601671814
-1105892517
1105744243
1204494648
1204537363
-1327510641
1327582283
1188758322
1188768844
1976175455
1976233543
-1532517135
1532681886
-1774928175
1774855022
-204998825
205070285
-1985871234
1985945125
-2078311958
2078343798
-1956529596
1956410585
-1326911476
1326908474
1931270623
1931319175
640106248
640149651
-1818971261
1818824481
914528443
914545160
902059884
902117713
-1932252283
1932163943
-1409423242
1409541654
-564625822
564638069
-83211249
83140495
1228103719
1228029887
453512506
453511492
-667210513
667330734
-557100415
557115943
-1744013866
1744005801
54259879
54175856
513904416
513884729
1525660726
1525580534
-664904007
664911628
1406054876
1406031455
-228444873
228424818
-1943906624
1943891459
815402847
815434753
2141690280
2141623808
458284705
458264938
970814657
970732257
-1748697810
1748701406
-1428844745
1428864392
-564606846
564590347
-1617646218
1617654917
1809508272
1809576801
913589678
913593778
1011053559
1011060934
-1172509698
1172465255
-289832756
289697425
427574440
427616024
-255670177
255683813
-772712746
772694884
1338342932
1338274054
660873561
660870164
-1775136183
1775164508
1733307514
1733307705
-873042488
872962534
-772786007
772704870
-349721752
349833830
-847153173
847129881
301687446
301702821
2020237452
2020265969
-1488922816
1488975207
222601290
222594227
-442619630
442579403
-977518179
977523063
-1069352522
1069409832
-1807535107
1807600036
1106298278
1106285761
563652267
563639979
110513946
110512157
-848577475
848664185
1126298572
1126255260
-1699217775
1699221528
-727020015
726933345
1753971161
1753883746
968383390
968456501
829684738
829653805
-766905939
766920098
98112980
98167627
-1815573513
1815539630
1889897166
1889897922
1605937903
1605949621
-918414359
918414913
1745692208
1745704328
-636598850
636497276
859120567
859149879
165095025
165122975
1126754075
1126707322
-1359593450
1359551652
-897163185
897275885
-1810124776
1810219106
-1100424733
1100458949
-640533373
640534316
376534452
376439547
729617754
729675724
-53497911
53577157
1187829264
1187817045
1917498260
1917470059
-1038966366
1038989741
-753691037
753794633
1222671634
1222704006
-1605505712
1605558521
1900227658
1900237370
-1402358439
1402460103
-1035865639
1035962077
-953898447
953749948
-83946104
83993096
-1038107050
1038227187
756177408
756190682
1735442339
1735433768
-1829877890
1829839496
524914097
524868860
1267540171
1267559261
-984436306
984573643
1502589857
1502577017
-677873087
677768138
-443123721
443128993
503071115
503131036
514666071
514681654
1845461008
1845430891
-1632469289
1632568941
771102290
771132674
1754413876
1754435499
-1135403242
1135350706
229634756
229606969
610148396
610193954
1038569518
1038574901
-870033378
870018993
-1252100112
1252234846
657853150
657922806
1919213192
1919258713
-1786661579
1786667243
1405834893
1405844842
-1681862427
1681892977
466612993
466576224
-613065972
613037427
-1723943990
1723976420
280074884
280074498
-2002289542
2002373042
1462323719
1462348286
457629502
457576559
339278563
339239446
352124240
352080858
1575757045
1575758744
-1379083313
1379136348
331226144
331305769
-5053413
5068543
-1584140056
1584245903
-303338114
303313193
-1927693130
1927784029
956793731
956782950
-1272133204
1272058156
-2069570865
2069570784
1593941371
1593932961
-496568071
496539413
1246256677
1246246477
-136614937
136596912
1587370462
1587368917
-1676655843
1676652034
1814341652
1814412351
1482802660
1482763095
-1346298541
1346259147
958477290
958499991
-1587234101
1587269781
890843112
890832707
974834493
974786412
139701233
139721326
71717396
71703779
376942725
376881972
1452892577
1452819007
1434561619
1434568300
-1728206925
1728236047
128099215
128099328
-896923600
896874952
-154116785
154108317
886828908
886800805
1396273552
1396285339
-1609147618
1609077418
559654894
559555642
1926999803
1926997836
-6032016
6099964
754002776
754049678
-597604219
597622873
1122777157
1122771212
-714958808
714928505
1132397602
1132431330
1450455835
1450446725
530389373
530411652
1054808732
1054829849
-1497206289
1497214825
682278473
682234730
665056516
664961073
1479584686
1479668395
-471781756
471832163
-520679197
520724120
1320556123
1320559635
1117759829
1117693433
-2040627075
2040544693
2053232854
2053216709
1536781201
1536713666
1280366718
1280357670
-1678410370
1678420809
1251801543
1251865079
-242696580
242648261
-1988489322
1988424958
90024887
89948479
557816851
557756885
-1029313056
1029207171
-1934871608
1934791667
1439447988
1439471968
-1829734590
1829610749
-1089680049
1089625308
-569267820
569129519
1937838004
1937893777
-1330303968
1330355754
1169908804
1169843505
-222635941
222641346
230431298
230462314
-1842800258
1842665794
1669828988
1669779159
-350160703
350070031
1610465777
1610440347
673036028
673036888
774987076
774984230
1601687125
1601664958
-636343453
636281782
-528104278
528116594
-1560409032
1560406439
-1995919582
1995873863
-1893954812
1893939663
-811483303
811359495
-89228601
89245042
988750373
988702125
1811819230
1811819432
2090918901
2090976927
-1260440279
1260480974
-1555827649
1555907741
1794241311
1794220545
-87485144
87355011
-799093420
799087212
-1577915363
1578042916
-1317372567
1317351228
305822564
305848758
-1415820303
1415773353
-321997844
321981018
-1935539680
1935463899
755043165
755058983
-1368487181
1368492821
1539830320
1539779283
1692209323
1692154507
-390417079
390390885
-1762845101
1762716619
2140775533
2140746654
-1031456164
1031458067
967828794
967751876
-1143037173
1143000010
511237341
511299140
223896801
223891548
-1167724299
1167625500
-2059223221
2059208492
244773488
244838915
1329811176
1329817611
-1671260365
1671201514
-754312674
754231352
1161698720
1161755245
-470820775
470868300
1931877250
1931916492
-858894749
858900176
645620588
645597375
ShortProcdess Started
ShortPdddddddddddddddddddrocess Completed
ShortProscdess Started
ShortdsdsProcdess Started
ShortPdddddsddddddddddddddddrocess Completed
ShortdsasddsProcdess Started
ShortPddsaddddddddddddddddddrocess Completed
-412995648
412923617
-1129806238
1129836416
95245669
95253994
1214339761
1214366255
792570043
792542015
1463995409
1464069069
1894265264
2115125922
153127776
153142691
844331249
1017807245
96554748
96588793
613894324
711683770
1209481260
1209481821
-1288030395
1287981728
2096193763
2096171085
-1871397928
1871346871
-840098498
840040752
1979254634
1979253102
-882819047
882856352
1238507482
1238513241
1757493161
1715146424
692327602
692388642
-890087696
890096757
1924077995
1924096614
1795142657
1795136450
-125763000
125714718
-940204852
940074908
2133993757
1909002565
1301097548
1301087759
299558865
299515630
-650087588
650045909
1314463961
1084269701
-1182027636
1182011042
-1685624890
1685668803
1563098251
1563085159
-2073094201
2073158594
-344921296
344972434
-1690967487
1691036677
-1969398553
1969250629
-1301695326
1301737409
-1968568178
1968655372
-306014173
305951177
padhFfSFli
\devmode.exe
invalid windows version
1417486975
1417419895
-1171501324
1171476140
1194062284
1194030640
-457877313
457851158
KG7oJTZG2u+s6VPKf65XSgl98HwUYE0B
KG7oJTZG2u8/y9aJJ12LlAl98HwUYE0B
DynamicDllInvokeType
CghIo12X0Bs=
-1091521444
1091536400
140381587
140438405
-1808333041
1808371082
-737929041
737813134
1055556697
1055550966
1399020121
1399018845
814547174
814566899
-1193393022
1193509300
-1408452868
1408370637
-1793788833
1793670680
12109445
12119569
97784381
97836408
631034225
630992968
-617791910
617752580
1909889323
1909867042
526460363
526395832
1758443489
1758404630
277100425
277145091
-1155146335
1155180571
-38893212
38883320
1824463657
1824394494
-2098826238
2098852337
-707317753
707311684
1512149092
1512117109
-129960517
129946075
-1688596431
1688483944
+/RSIY8Cn+169g9flJ3okA==
baUnHm/CczQ4AiYUrqsEuC/LokmAzhqo
WpimmyQ6nEEL4fFllRC7+Al98HwUYE0B
IKd0WdjDCO3+eMCI8zUckg8tV7pS7r9g
nL7AfIV4s+8n+052iq33Kw==
GKtJvbiN8pZWcG1xAaoMrKyYxUMU6g/i
jTGGdCo5GMo4AiYUrqsEuC/LokmAzhqo
NphSN0r5krkL4fFllRC7+Al98HwUYE0B
xrKvPGGUToL5eYlyKLGTQQ==
oqg3CZNQgWZ69g9flJ3okA==
kh/0HfMffBtFJZrHgmr2z/z6z7WT/xtI
VS_VERSION_INFO
StringFileInfo
040904B0
CompanyName
Microsoft Corporation
FileDescription
Windows Wordpad Application
FileVersion
10.0.20348.1 (WinBuild.160101.0800)
InternalName
wordpad
LegalCopyright
Microsoft Corporation. All rights reserved.
OriginalFilename
WORDPAD.EXE
ProductName
Microsoft
Windows
Operating System
ProductVersion
10.0.20348.1
VarFileInfo
Translation
Antivirus Signature
Bkav Clean
Lionic Trojan.Win32.Stealerc.i!c
tehtris Clean
MicroWorld-eScan IL:Trojan.MSILZilla.19096
FireEye Generic.mg.192f55e340f45009
CAT-QuickHeal Clean
Skyhigh GenericRXRU-WN!192F55E340F4
ALYac IL:Trojan.MSILZilla.19096
Cylance unsafe
VIPRE IL:Trojan.MSILZilla.19096
Sangfor Suspicious.Win32.Save.a
K7AntiVirus Trojan ( 00581a2b1 )
BitDefender IL:Trojan.MSILZilla.19096
K7GW Trojan ( 00581a2b1 )
Cybereason Clean
Arcabit IL:Trojan.MSILZilla.D4A98
BitDefenderTheta Gen:NN.ZemsilF.36792.Am0@a08NqepG
VirIT Clean
Symantec ML.Attribute.HighConfidence
Elastic malicious (high confidence)
ESET-NOD32 a variant of MSIL/Injector.VRN
Cynet Malicious (score: 99)
APEX Malicious
Paloalto Clean
ClamAV Clean
Kaspersky HEUR:Trojan-PSW.MSIL.Stealerc.gen
Alibaba Trojan:MSIL/Injector.2a890a0d
NANO-Antivirus Clean
ViRobot Clean
Rising Malware.Obfus/MSIL@AI.90 (RDM.MSIL2:L4acKrChFPEF3GvQ66+DyQ)
Sophos Mal/Generic-S
Baidu Clean
F-Secure Heuristic.HEUR/AGEN.1365059
DrWeb Trojan.PWS.Stealer.32841
Zillya Clean
TrendMicro TrojanSpy.Win32.MARSSTEALER.YXDKSZ
Trapmine Clean
CMC Clean
Emsisoft IL:Trojan.MSILZilla.19096 (B)
Ikarus Trojan.MSIL.Injector
Jiangmin Clean
Webroot W32.Trojan.Gen
Varist W32/MSIL_Injector.YJ.gen!Eldorado
Avira HEUR/AGEN.1365059
MAX malware (ai score=83)
Antiy-AVL Trojan/MSIL.Injector
Kingsoft MSIL.Trojan-PSW.Stealerc.gen
Gridinsoft Spy.Win32.Gen.bot
Xcitium Clean
Microsoft Trojan:MSIL/MarsStealer!MSR
SUPERAntiSpyware Clean
ZoneAlarm HEUR:Trojan-PSW.MSIL.Stealerc.gen
GData MSIL.Trojan-Dropper.Agent.BIX
Google Detected
AhnLab-V3 Trojan/Win.AgentTesla.C5544288
Acronis Clean
McAfee GenericRXRU-WN!192F55E340F4
TACHYON Clean
DeepInstinct MALICIOUS
VBA32 Clean
Malwarebytes Generic.Malware/Suspicious
Panda Trj/Chgt.AD
Zoner Clean
TrendMicro-HouseCall TrojanSpy.Win32.MARSSTEALER.YXDKSZ
Tencent Msil.Trojan-QQPass.QQRob.Fkjl
Yandex Trojan.AvsEtecer.bYBhol
SentinelOne Static AI - Malicious PE
MaxSecure Clean
Fortinet MSIL/Injector.VRN!tr
AVG Win32:InjectorX-gen [Trj]
Avast Win32:InjectorX-gen [Trj]
No IRMA results available.