Static | ZeroBOX
`.rsrc
<?xml version="1.0" encoding="utf-8"?>
<asmv1:assembly manifestVersion="1.0" xmlns="urn:schemas-microsoft-com:asm.v1" xmlns:asmv1="urn:schemas-microsoft-com:asm.v1" xmlns:asmv2="urn:schemas-microsoft-com:asm.v2" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance">
<assemblyIdentity version="1.0.0.0" name="MyApplication.app"/>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v2">
<security>
<requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3">
<!-- UAC Manifest Options
If you want to change the Windows User Account Control level replace the
requestedExecutionLevel node with one of the following.
<requestedExecutionLevel level="asInvoker" uiAccess="false" />
<requestedExecutionLevel level="requireAdministrator" uiAccess="false" />
<requestedExecutionLevel level="highestAvailable" uiAccess="false" />
Specifying requestedExecutionLevel node will disable file and registry virtualization.
If you want to utilize File and Registry Virtualization for backward
compatibility then delete the requestedExecutionLevel node.
-->
<requestedExecutionLevel level="asInvoker" uiAccess="false" />
</requestedPrivileges>
</security>
</trustInfo>
<compatibility xmlns="urn:schemas-microsoft-com:compatibility.v1">
<application>
<!-- A list of all Windows versions that this application is designed to work with.
Windows will automatically select the most compatible environment.-->
<!-- If your application is designed to work with Windows Vista, uncomment the following supportedOS node-->
<!--<supportedOS Id="{e2011457-1546-43c5-a5fe-008deee3d3f0}"></supportedOS>-->
<!-- If your application is designed to work with Windows 7, uncomment the following supportedOS node-->
<!--<supportedOS Id="{35138b9a-5d96-4fbd-8e2d-a2440225f93a}"/>-->
<!-- If your application is designed to work with Windows 8, uncomment the following supportedOS node-->
<!--<supportedOS Id="{4a2f28e3-53b9-4441-ba9c-d69d4a4a6e38}"></supportedOS>-->
<!-- If your application is designed to work with Windows 8.1, uncomment the following supportedOS node-->
<!--<supportedOS Id="{1f676c76-80e1-4239-95bb-83d0f6d0da78}"/>-->
</application>
</compatibility>
<!-- Enable themes for Windows common controls and dialogs (Windows XP and later) -->
<!-- <dependency>
<dependentAssembly>
<assemblyIdentity
type="win32"
name="Microsoft.Windows.Common-Controls"
version="6.0.0.0"
processorArchitecture="*"
publicKeyToken="6595b64144ccf1df"
language="*"
/>
</dependentAssembly>
</dependency>-->
</asmv1:assembly>
C8$)?4
$hY4Mx_
bBT07
v42xw}
pCpapnSc
phpell
m#6@Hy
QmW$*"
n6^ My(
VpGpUpIRD
a9p.pOp%p1p
pbnft}
*vSr:$a6du
!4hfElx
M;*8D7L
6f Iphpill
i3yg)%
)n=aRDs
b:2aQs
$o.emJxyFyf\
8i'b#0
s4lc4vd
D2rkGt
6f Iphpill
i3yg)%
e&kJF|e
$aTJ'~
uQe6qt9(hw
4ff=lu1L.
So\o(T
xtRHoE
shell32.dll
PathMakeUniqueName
mscoree.dll
_CorExeMain
advapi32.dll
RegOpenKeyExA
user32.dll
CharNextA
kernel32.dll
GetModuleHandleA
#I+[Ln
e?a0>Es
dClH@9
!gtC2K
'_&W/g
gt\5I"{
.o:|<;B
Ly4*aQ
%V/5"Y
^^SS'f
^ZAZNFT[
3C.]e;
\LaQ{;
somF[W
'sff(?|/
)_)~dr
2g%/*.L
?[FlQ=|=
1w?D5O
RZKsTF
a-*gzyV
rg\IRJQ
sV|"^S
r.kz&N
: t*!_
ObN}-U
gWKpeO
d1|[by
Ta7&jl$
>`*Lmn
LmG"|M
AN8CW~9
[.hKAC
!*BFfBAA
RSy{28
}zcEQI
32K7~
(#$wH)H9
g.I<}ec
l*-N)I
w8}HUk
Ie{g%}
oJG?Dm
q1*Wve
$z$xx1
vf?RhT
.>+&357
@d&pm{C
9xcXlky
hlBGc=
H\TFAYD
ds$*VX
"%aiRf
yWCx6(
R.r[>R}
3AN\X
hx7l%Lz
+@q_OK
1<X![47
c8w*^*
*9t-w8>
Nrf9"c\
uvI'ywK
}J44^
y }F6Ji
mIk!_%x
[C?E7O/3
c}?Uqe
<i R1
6L~5b@
{y/Z'+
dp.lT\
*88\<09
9,3`yj?
),Z@._
GsB}zkLD
2pcPBFR
s,{6lu~Uh<
E*i*qs
=dMkxB
78z{uw`
x+anZ=
>hOc!$
_}#o7({H
LIcJ]8
f.541L
X!kqtwJ
I};7,H
<*yMv9
OK^RCx^p
a4:IND
XF$}vs7
-G~`KB
FZx)u<
Apruj7v
&Xd|1av
UC :HT"
z>F/,BA
eHxzYP
3K}Ahx
7~Q-<#
7oH#g{
{Kg&q,D
Cn|k^z
W)(?FhL
a8lAU7
JO%\Y!
IFalN|
G]{K.B
!yKeC^
J 2~%
$V.+V>
$pW_L<P
z!y1~0=
/QeZ7}
UTK:2a
X)xv4H
e{6:jk
dZGR9LC
n{jQ5W
Op_pLg(
K=Cnjx
d6<?2:
|vB5E'R
{6eAJ4
L4F|>)G
\/A|<]
8{w_'[
mBBg^C
aK3y^C%f'
-{[%&+
6vYKj2
k,E9jpXb
jO0+EPIY
<5"Fd[8
qO6\{Y
O%J)){
&l[Q_T
-ez&E%4
n4`hI(
4k#jN3
u~A<d4
cK_%(DE1V
3GNWy]V
u045q~
27F|lT
n5`Aiad
_~nCw/G
Y|}cc]1f
}oER{g
Mz1Zkc
oujC,s
w}6[S*:
egpr9~
_. \Z`
B7"Lu;
S.pf[5
,A"%n4$
U_v$vz
-X,CVH
; >^ar
AY~)!xO
CP%yCb
oZ{3P2
|i_DA~
&],W{}Q
|O@KhN<
s[]J0?
<'c[*e
C!%a:H
^L-$b)p_1(
D>qMk^n
"T:Y:a
&Vd\et
g^`41'
!}ZH%]
}oy!?o
%'g${ry
/_TsWqY
dO7219
te\^g#
1A%~e}*
.u!B(
~Kbyn^
BC$/K-V
C}s]&<
=z9.e.z
'j}a@:
#}qYi%
"2uNeyj
>`#r(l
U(-mC>'
mr>X>/
P4#e[jl
4IUnJ1
Je{uHeh
cj-9V1?
/*'{6F-
5vW6AR
$O5-j
ygITqEW
a]UX5S/
e7AA(z1+(
iJpSto
l9}d@e
aOwmSr
k>@gJ5
Ivexehd
(bRZ4Q
jiP>x2
SIZ>v2e
z*=g.ORo
IKVD8n
wKWaBlW
o~d2v~^
Occ@z
!,L"v-
EE:~\!S
UKkl&czT
Bo?-,.
YcL+7
We0 3-
!w?"BD#
^rtdZHOF
9o-0M<
boZ/Kb
i'4xKA
u9ub'e
hti%S4
Q,1c=Jc
$ ;ZEB
F`+L@Om
U+Tr7j
I?'Gvl
n?#1'x
>"l^[&
/u,k"/MYz
`fO^EQ^@
}0[#3e
>^Y*ZA
+CbLo<
eA>peU
h}[X]o#g
!E6Y2a
ziD$Ef
*1N+k6^v=f
#MJRR9'4
ej!kr.;
Bg]CCG
+x4)e~
I'>2duz
?D_elZC
xgP6{q
lmjV-/
W_d8fU
G|&Oyi
sAu<o!?/
AnB3>d
M1qFxz<,
i*h)|HQ
=v..%9R
${\; ]l
WT?OJTM
X/2o/5
l2h.>Ip
SbP7d92
D2ZM#Nf(7e
fzz]++
K".)P:
x,"f5G
#ph9%oA
tyd*:
*XBDtE
F\As1gG\y
gu^E|:
\\ZL-\
-a5p8x
YA|3EX|
+b@+JR9V
HqIT 3
/eR4iBT0]
LWLK>C
?k<><@j
B)}#"q
X}o4jdT
Fy` mryKre
JVzy=4
a#y*&)s
)d]r>%`r
=dfPiJ
XU$7|QP
_/Bh$T
g I'<kqbb
,>;4j>N
a+,Z=1
U#\M12
x7Wf0H
Otp{b#JtW
Rr3C>Y
cR-<b%
TO,--FL5D
x.T@dO
J?&7P8
*Mk5y;
nydTFX
E2zelQA
aeqF =q;S
L\/Xr1F
>Cn \v
pbb"B2
&HcH7|/
b_mI`n
Q!!W n
Q-~|2`PW
1&M`(
/8e;E+G<
I@wq8Y
T;@S{>6{x
{~)+-E
kYMeh3
+myFGe.
M1)uUa6
*-#Y3h
+}(-USqg
4kV/5j
%u&[$%\n9
*jZ+{q
K" r2"
.]?xykJ u
PZ8jWh
'e dGqJ
qu&oJF:
DL&kRU
+Wxrsyo
8nh@fp
H;LKZ0
9<}}Ql
{B1)Vm
5Jp,=3
HO8 I,N
:<uPR>
&PD__0
SmLl%E
{ga3`k`
#m~4P%
$xIUwl
wer"il*<
EgdUhB
OT,^bR
7p$O:-
kvUUiT
Y9f/y,
XxS[OL%
OLH;IdoS
.316o,
oM"4@^l
\!J-U+
m^._Qs
F)(-4S-
A;?YII
yPPe5%
TLA)v&
<}J[9s
>:Bxf@v
f69Nq8}
YX{2nfh
8i]!hhI
],NzejH
D(<nTw
l%MIht
9.Rz3!
GlI?;2
iU/v>w
WP0SKh\"
%XC[(hG
>LmF3^JL
06-^G9R$~S
8o[oAp
Yh@VD"F
5z<z(A
;2]:!d
~)T2U;cEFJ
f{+f/
,#eikC
DI#[kP
Zw-e/j
?GhB?_
Uw+rJf
GVv_F7@+
f#&`7<W
J=yC3z
;+nss7
EDAJLY
wH*BIB["eM
updKS:
L5geq9
=3Tm>E
Gi; NfD5
y2_$0
c9J$*M
#v^y=
/G@x<&
h/D5=O
}{DE;NGp
[8)iK6
8oio}5
3=b*P,
b`u+{G
u9ArL
3"\4o
G=O^jia
QOFQ&B
C~3V9`
#Mm~]{e
(--r%Y
m&h;n!
]'`[qi
p5s<0<
T3g7N7d
eSyO7V})
7P+^tn
;/&~rI
hKb3pV
_2hnil
19b~Ns
Ie%Pay
hf$H%KS
VDdi[T
Nd2$4%G
5wTXi:r
ZH9k4?
sLxt{*
BYAoy#-W
^8vjKJ
+j"Nn%3p
1jYzQ?^
6w_eQDE
;8s(-p
Cd`}aGCSv
@lA&F|n
I<1Z@5)
|7E^xze
%]~dWw4
$h1Fm
AJ>PI~
$r_TT*
Y(GSSRP"
3Z<]6*
//B0nCn;/M,Gl
%K(M8E
lVH?H-`
&7L!:$v
+N$D>!b
d)diF#u
d5(_zQH
Z3^ia/
]'V,'i)
"msBW^|
:iTx=@
s+]w@]'
.2Dmfo
nv,\~k
X`'S'*W
xy1fV6S
I~f5`.
$Q}OJc
0vA])< J
{m'<.p
D`o5w%
,'J"jU
NUkk?I9-q
.M*$(#
p~E{#[
S#.5h;uv,
fIB19n
\%G$kS
o-q@r=s
dwX!p1(g
s|s##&
KcW_|1
A=Fuc-a
ai\Zp>
1lTAR
X)Ifn-
gYW2djvJ
[z>(;.
R=%A1l
jy4aLU
up:b^n\
,!#I7Sl
>d);jJ
9t_Um%@o
=h.a*
+_&7Vh
x#g:<e
/z|h9h
vy4{p9
fu%N>bu
dd^>DD
^w;^cF
z-N2@-#
Rh~h*c
PGZj"J
mJw_p*
QlN>/V
bhdM!eT
j r&AH\e[
|)&jqAeh
Vo;fegr
xzVZgCDz
r%M.;'[
WZ<(3l
4`uv8wL
gAfv>_rDA'
1%IXx0
u0S3Pq.Z
5lqZ{jh
i-C>St
Eo_Ol5i
7rDFf$n
3RR".9.b
(K1i~|
'N,>`a
D*XgK8
TMR<Z
a(|"FI
]i_7uM
kH_b1~
uKVY3>,
"*q;.>
?kM\0]
qOxK<3
<[oa#y
z.zmB!
Y,gB($2
JJu$xJ
c>IS4r
7{5Jn/Z
"@)qf]
I3C$ma
Y."2gPO
R0D3i|
N;Q0m,(
CoAE=o
T>v$;7
i6&aCL$7
({h:X1
P9euZq
]Cdkph
)70$@'E8
/[HCu+K
RiV'U9<?
j7A`0~
y39!-N@
IB:nB
d_&W\r;
5q#5#q
yM-MwU
$^1-6R
""?~_(
31xIdl
@")@on
TI^*i}
e[;H"
KoSjIS
+!s[ .F
-(kTyR
4(zo.E
UJfIE8
+<t`x?
z&NTt#
)Lthy6
(hT%km
n2+{N9
B.7FAs
'$M@0j
y1WMo0
FtD&FM6
CRu-5=
7/vx_X#5
CYlc'}
XLs{g1+
1#b35t
OfEt \cu!
5`@~EI^
M--TRxD
~u7jton
jAPgsj
P<f{[7
kqhE<O
1U_5,
H[46tk
Antivirus Signature
Bkav W64.AIDetectMalware
Lionic Trojan.Win32.Tasker.1g!c
Elastic malicious (high confidence)
MicroWorld-eScan Trojan.GenericKD.70426098
CMC Clean
CAT-QuickHeal Clean
Skyhigh BehavesLike.Win64.Generic.fc
ALYac Trojan.GenericKD.70426098
Malwarebytes Trojan.MalPack.Obsidium
Zillya Clean
Sangfor Suspicious.Win32.Save.a
K7AntiVirus Clean
Alibaba Trojan:Win32/Tasker.50acc702
K7GW Clean
Cybereason malicious.1c10a3
Arcabit Trojan.Generic.D4329DF2
BitDefenderTheta Clean
VirIT Clean
Symantec ML.Attribute.HighConfidence
tehtris Clean
ESET-NOD32 a variant of Win64/Packed.Obsidium.B suspicious
Cynet Malicious (score: 100)
APEX Malicious
Paloalto Clean
ClamAV Clean
Kaspersky Trojan.Win32.Tasker.baab
BitDefender Trojan.GenericKD.70426098
NANO-Antivirus Clean
ViRobot Clean
Avast Win64:DropperX-gen [Drp]
Tencent Win32.Trojan.Tasker.Bkjl
TACHYON Clean
Emsisoft Trojan.GenericKD.70426098 (B)
Baidu Clean
F-Secure Trojan.TR/Tasker.rbwxa
DrWeb Trojan.InjectNET.14
VIPRE Clean
TrendMicro TrojanSpy.Win64.LUMMASTEALER.YXDKPZ
Trapmine malicious.moderate.ml.score
FireEye Generic.mg.a4212217a2e90127
Sophos Mal/Generic-S
SentinelOne Static AI - Malicious PE
Jiangmin Clean
Webroot W32.Malware.Gen
Varist Clean
Avira TR/Tasker.rbwxa
Antiy-AVL Trojan/Win32.Tasker
Kingsoft Win32.Trojan.Tasker.baab
Gridinsoft Trojan.Win64.Packed.sa
Xcitium Clean
Microsoft Trojan:Win32/ScarletFlash.A
SUPERAntiSpyware Clean
ZoneAlarm Trojan.Win32.Tasker.baab
GData Trojan.GenericKD.70426098
Google Clean
AhnLab-V3 Clean
Acronis Clean
McAfee Artemis!A4212217A2E9
MAX malware (ai score=87)
VBA32 Clean
Cylance unsafe
Panda Clean
Zoner Probably Heur.ExeHeaderL
TrendMicro-HouseCall TrojanSpy.Win64.LUMMASTEALER.YXDKPZ
Rising Trojan.Tasker!8.CA15 (CLOUD)
Yandex Clean
Ikarus Clean
MaxSecure Clean
Fortinet Clean
AVG Win64:DropperX-gen [Drp]
DeepInstinct MALICIOUS
CrowdStrike win/malicious_confidence_100% (W)
No IRMA results available.