Static | ZeroBOX

PE Compile Time

2023-11-16 21:03:38

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x00010aa4 0x00010c00 6.00222475407
.rsrc 0x00014000 0x00029a26 0x00029c00 7.08101175563
.reloc 0x0003e000 0x0000000c 0x00000200 0.101910425663

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x0003d04c 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x0003d04c 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x0003d04c 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x0003d04c 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x0003d04c 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x0003d04c 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_GROUP_ICON 0x0003d4b4 0x0000005a LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_VERSION 0x0003d510 0x0000032c LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_MANIFEST 0x0003d83c 0x000001ea LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with CRLF line terminators

Imports

Library mscoree.dll:
0x402000 _CorExeMain

!This program cannot be run in DOS mode.
`.rsrc
@.reloc
3b%(H
v4.0.30319
#Strings
MZfEs6GbYY8hFcFHjveJSYI0
3yLXwCGHlkICPfN0
fIOcDu5EVb9S82i0
l6pPFDl2nWlrURZPl5No7zw0
KzQh6Nm8jdiHjYHDPvJM8fz0
e8sWyv6oKOA3A81HIeHIji81
qWcRFxLqjn8OUaJ1
tzUTjgN6n8XeK9O1
c7Ew5WGzqMDBcMS1
zwzpd3EO6PUp1ZWEDZPnio4QTJOAk6CdT1
_Closure$__1
IEnumerable`1
ThreadSafeObjectProvider`1
List`1
sVJdKiVRjLAyVxaHhRBLwjpQWvbvfV3L5C8Pfmqk4euCqdLXteaQqqNxLFhEJzUtDtYrSkXQf1
LIZBg93PdNLpq6nHKvL1Q1n1
LXJpSOBPh1G9f9DbDZQxKGsjTDzWAO96TD4Yxo1
UCwZKaHsKWIOohOyQzMqjlx1
Microsoft.Win32
UInt32
ReadInt32
ToInt32
GPZ4DqBZ3E18Rb82
4gNLAWJatK67VBTlwmGw53C2
WXCbqnfHuoRynEgjD1IwcpE2
Func`2
a9HB4HuXUO1qLuGb7V5aN2h2
PSRAZp51KIPACPAj1lQyi903
sFzLPGx1kX8Weo73
vGOUXaLxtWG3c8BpBGxpuAB3
kukZvVR1AtI1sxbwCK9IxyG3
5keu6AcEpRjLyMr9ztvyt9K3
8hauGEUoSw6UWf159EiHJpikr99cYfJbYy2hAL3
g8p9rXAz1d9QJhT3Mj8tPeQ3
ntIRESq9pOUsovAuJojbOYT3
ki4Ep2TzebzlRWY3
OKCKo5RRcKaib37z453MveRtp3
c2RtPSc2bglaucnOKPFjmCs3
vr0ycMe7dcrot3kxGIFw0zu3
TzQXuiShTZuGJ8ttS8H0KM5cxccCceXMq08Baa7w3u1Tp8engTmKL4OivpvjDHXfd4EYAzDu84LbzVwTqiSGeJGaHm44
UInt64
uNwaQSyRAMebq7K4
yFRH38brLsdhyTwNkKaCsYY4
ss02v8yQAHDi88Fc1IP4hRf4
pYLxiPgEt0hx3Kx4aTlx0or4
DdOesqPnpQSzZ6XT4OOy6wx4
IXeaRxu45bP2Qbzyc6HqaupfRFT6hWPrDv10h25
7zKt4JzCIIWv3KN5
t73od9EVpqDoxDzO1KYDpz3Uy8RX0iTqcbw7UW5
RImPjEFCt6P4p1ZtY8VI9biwqv1rFYxjW5
ahHRuIxpNNq2D9Y5
TkZgJvn22Bs7BCvuM8UWciwFucAfX4gKY5
hElmdZbLhCM3zcsqHlcs8Ne5
EAuvcR8rMON2eTSG25UTOKegvcqDpz5lp2v2RRhmJcKL6wBfDISNAwT7PLzsBbYehmon28QER9TvXBaGDKykVfV6bek5
O91xiGkqgtOAuXl2AZ5EZDl5
e3bUg2Fx2uQUoqpXbugipll5
F4yTLI9r2DUHNigsswrxyZzc16
Ezwkha3Do8kdODSV3jfNxM7AwAslgXwJ26
njS6I2rAvqb7lPwIsEQ2yesgmA1f1F4LUiUwn86
j211tQOZWcjZQPXwSA57Ge96
hSlbMSi7roeHPjC6
XS8rzO7c2rmMo7mO16xnBYQH7rbhZqhaD6
1gK9iLKQ0q4NH1reaJcvdlO6
uVylMHHAfEyCKnR6
kirELmdPtUUoRbiQFZuHsyR6
4bkqbnnSaXwfERVdlczcAVm6
ZdLIVtlMfVuhLDw6
tIXaon7U31o24h97
wcxYb6tVYoYfETL68wd3YEF7
2oi1kSTDJlvt1eF7
XDdCgV1pkNpzTFR7
jy7RBP14aozItsRp0kVKiZcgT7
J3zQPVF9jiiZ6FV7
4tgswBvcoayVHbZDZQU7Aea7
bcRl0MMAYvz8PoEsnkp5iiewmb38aBNrh7
s68NjOz14GDT4Sn7
dgubijTooBfc0Ds7
7KWDKYyEXn52DcJNqUnMmncUB8
get_UTF8
8yOGiv8CdNgtFiVQygimLnW8
Svp7MaRaWuGngYZ8
_Lambda$__8
SA3LmocVAkSwWmnpfdhwvUa8
aI5l7o0GrGhwrCh8
vhwUuQhqKpmznD79
tYUzNLi8bhbLPIB9
qFAUgfzFkK2UDBjC0UJZrbF9
QExfcoZ4tJvC0yO9
G6KKBW0YjoFoLZuI5aLbwLd9
Pnz469XzUwePfei9
7An57LosooSWDcttWGQUcOl9
iIc0suLekMCJQevQeBU4SdpRq9
3PpsfyIPIbwEKhlP81qrgXu9
TnxH5IhLzMIWkzfW6TgFP1z9
<Module>
yQOGSaK3YO4OYjTqiCa9NJ1A
qEbctlpD1oNHlWfkXBCtja3A
IqR8c0JMBR7Whq7SNOIMyn4A
HX8rS0fGY4cmhFaT01pbY07A
z96i02MM8QDP4he2XVS4NoDA
ygkvaKyBISkbQ4Wu7NRPvwKA
6aeGsDZxoLsSRQwZ3Gtqt7MA
iLUmT29si4Zjgr7d17EFENn92iVktUfvSA
uHQt4v21qSVPtzLZn3edeLKjxSvJ2iDUhHtcD7WdymjHs89TU55NXFZ7EWprnrK2mOkJqfdgjSyf9EFbp9Ol7CouxxUA
LsFsNiP9b48wWAvbOxe0AMVA
9Xh59bsTDJHkLdXA
oQjlJt5WZtfCQWlFHPsdsscA
DxqkI9dYaWzniJyimIiT4GhA
capGetDriverDescriptionA
43xBNEfceAbWCymCwkrj4DpA
YIdwtsoEYcWC8eOhi4wGkEsA
laoyYvJ2TxWxmoc5bIbh41vA
capCreateCaptureWindowA
TeodZpEPzrcdEf1B
FMtw2sndY4u90YiSjrKectTSeRCFXxXv4B
4GQvigbbYgVxEF7B
eByEAZ7aUzX4Ycv6YM6mR3haywUEO3H6AB
lNHa1465sE1BVG62v7d4mAIB
yqQ1X8VObaCyOVX3ojmbdBa0eN80Zc6DJl6G6gM4ALxZb4OBkBVfemFtqbPimkNEqu1xMo5FzQCt1I5kyGrUY9Bb1oMB
9e7B7fOYzCCZTMOB
2eSPK4dW8N7fERb2ejaMUeVB
cEOC2Mv3QFwcEd3pUQDo7U5suXjPE670Rmxafw4FYLpMQG5TBIOuEQGssCv39dwMhCxdRB4CZB
N6kZZFm3oWA5IySjPj9jYfrHZB
ne3nf4zSTwmXnwTT69cJBupB
1Zgn0BaG4QFTWUscHwiHzstB
kusNNX5lyOdxAMZgaHk5zGKC
VU1uJ3Q1cl0YEbaC
dJ4cngRolv56dYjC
EGQfYsXAuCSDJEYHRb0BR9mC
1hgZ5jYJNVzDroFNlxQWqepC
5ZjKdNLbPhNoo36D
aukOp2VzZoPwLaI84AkDf5DD
zvEpb6Povl9bXHnlQplijpDD
ES_SYSTEM_REQUIRED
ES_DISPLAY_REQUIRED
XHLP3lmw0S1ZedJD
N1rCdCRzv1mpdO08mwaj5yUD
7wdjpdhAGyMdaZ4D5N5CTTrD
KGReJaB980k5dCOx9W2zQd3E
HjcXZuxLSxoB5WppVI1M7t3E
It31roNUrkJDQ99E
MEUxiBpxo55i3UHIkTbkkGJE
EXECUTION_STATE
Coie4qGGqa4BxtTE
kXImGeqxmlbRjiSi1NQ8E8l4k1XmwM6izSD60tzFhZS5PqmkqfOmKNkoNZumBZujZuw7LsHmVE
mcmV7n6zLZxOKHdE
K3q6dcZ66Onir1kE
85TG2d3jRELpT3t9Mbl9gI5F
chJ7NjdMFOZKuUWqwdyhI78F
wuWnfipFI65GEj05VcOCjT00vUvIXqt1EF
WK5Ozo49MyrS6YIF
nXh0V2bG2J7hrTOF
2GRne88sSrSuSIVF
EgiYkWgowQeaIjaHoVHzA8WF
PnT4Xj60sNRE6zvfjuoiZovmuuQhBqj3j18FOFDBRp2XDZNvcAJ3DqwqmKjVK6SqTrwW8zb0hF
BM9A1G4QgEjzlaOQXNzSw9mF
H73p399tnXBUHkXr8gmzP8rF
sN6OLwYRRHqoGczFgv2Q025ADDqdySPIyCkKRtF
0mtgeMjVPkExmbUh9jChiVwF
TkQPhNzKmOp6jcfsoBaPV9xF
pQisDSgsQFBuVYxF
zR1apZLZLcK21A5tcjgyi92G
BB76UyAaaYLivs4G
kqbdDf2YNWNNFevXxXiqES5G
1eqPlkiNTfknK0RFDMxA8D6dS3Su4FF3EG
1scjKiTPg6YofE16P6Yuw91WkZrcxRRvK4XeYoHLAcBoy2PDlaCQjCE8wKfiXn4nRU62IAXsQLIhhgNZFJif2VUdy1GG
QRfHd6E9JxQ04oOjjAgfnuhnLG
2PRma3gw7TmNWtjS7wo1Udm9LclipK4jxdTfqrbzuRMtBwDCCMehADVl4XrrMtfcsPj1qunpNG
Up1wJC1TwEGGXVeG
3C9mbJpxwavygghG
eKi2o6auskTC8duG
oqW3yIOlVuPZsyJA3dCnn41H
NskRZGQJRHd72trBALn0xWpd3u3gnb0drGKWtPp60kRk2Uz931j7Xgv8v2umRTa04K74nM0sEH
ptJPZwYguWZeOdAavt3SOzidHH
QvWvfAaTXrAYDclLrCAXYcmIRH
99gcwtHYYPq82yZH
q5nP0z8MkUr28ecH
NkWGISNDkqZwZ8zBFOxVosmH
GdgaU7Yzt6DGyrBlxvrjVYJDtsBEYuPjdELHrdEJyXkFcEnpdb6YPThreajtXqqUx3fdquzVC1kfbLcaAIRglT4mzMvH
RY9oso6vnFi80LrO31zqSovH
RSgN1yRhomKcOqxH
EeeRHnh6BbK87yNc0tErJb3I
get_ASCII
nSRKxab2nECzckwBZ7YyL6JI
7zF9E8O9YB4TAxmQIk5NKmc9YhCwJCFr995eSe94qeKpEIKBbpCvrIvQpQRgtUMrKtSORE77JI
JrXtV0dmdlYCatJI
jA0diI3DKu5vAi6iZI7STRNI
6Utlyi14f4nG3lpLh4Z3zmEhUvGmN0GYe1S8NDZmBXSxbr71zs5PLewtGHPOoZR2nzaOMczJUI
fbwruiWlmAGOf108YBhNcuWI
jbpjZRyWUQ7roQmN334TQPYmRhgcXWnaYI
nrCQtGir7xO86uASEySylSeI
HwXRa2uL7W8h9WYon4fFeYjI
MWVbvIdxIFDxVvxI
RpjJ8GAEUfs5JgrI6elFdO7J
V2wlocTGfSJavSfojSH8O79J
V3EmNrsXi8oA98Ej8VeF0dEJ
Ct5p3WOPZ8ol80sJ
AnKCXiwI1C3xFnrGe6aEK3vJ
ZcZHiQcvYeCFaQxJ
wa97VqPKdoipbV2IL7RMOAyJ
zPTOVVn5dQDR07DoRK2hYi6K
UPEfOAQs6BM5EF4PG2sL3dZK
S7DK6r4LvUmdq4bZTjjxpofgfK
8QZcoXkWcN9bHiFmSa6XswqK
ahk3txkv7igi9CsK
DgN6jdo839NNB0ooOCAs1e3L
uiq7fJ6tNFu92FEL
41NvpoZFehuischL
KvdsozSNCLrCydjL
Js5UfLdYStqhOEqfgK6F2d0RX45TuuaPkjLSUg65LFNoldfHcuzmgzwUP9dOQDTfYnJKEdgkqL
uGNDvEOGeeglZHHkFsZMXLwL
kUYbR8SGSDhGSsrchMT7qRzL
vcufUAQblwPG4CcM
jykQA75F0AVQLWdM
dfaoxVh0jIv5fODJw5rdJl1N
KCxTy5ylAjm7TdtWTv89TC2N
5kjavls00rFzai6IOljUchMeRN
IlarEXLwaV6LLbWg26vIBYlhEJqU6Nt8Avkxh1e0zg2BOgowZFYG3WIw14t1uPvUMreEC1DAXN
M2qjMrhpkuGnzCcN
ds6lbv8XKdX2X3jN
P7a66tJLF9fz8bpN
SH5sjooTISVhHdzN
Q5G8YutGLOjQYhn8SK3WYR1O
79dVbbmD6q1cI3zkkSgE0Z4O
LASTINPUTINFO
rN9sb3WcsVFrsRJgcIT6fAHO
System.IO
a291UOHbxCIemZGRh56e7wSWJO
WRgNmc8u6fF4fe0CSJFiAfLO
6ezV6xa5kyIbnoWO
6TC5foIXwCNuBBYO
WWXDhT7kYOBAzEHXYkir22jO
40AsscI2mi1H5J0j55gqr9tO
gACtFBIANbBC4zeL9iOUzkJHRsNGDlEzgG1dcuABaYcAkqTJuh2tlHj5LqwgOgCCVjaZKqSUuO
fGx5AQqIXYwzwP3P
EPfrqzSGwNFEU6ZDjtAJCF7P
M3c3soQr5PoTrlfhb75brRTP
3YyAyEIjVvDZY1jP
rl1XON3CNMLZ6nseyC8WXOjP
TteRIPZmcq7mQXXMP8Y1xqXBDZCESGUdRw4tlAQ
Gyx5qodPitv4OF8hYSsU2TEQ
x55fRoukkLEdaxAyN7WmrMFQ
lSUrS9iCbgAzoJn9UwxMOzFQ
4rOzqXU9y6ix9JitxOKEKiXbPCHJj0iwPQ
gQaYaYCE4BE9u8H2LLfbReXQ
0awQrW1rMFX1atKFAKs8rhcQ
Xa7B55khfHBVtXvU9XDwATdQ
1k5TVnc9ohmxwDsQ
BDW3GutzDSU8sJ9ufn3b3osQ
7qespiJT3XoXpEnbXJp608yiYT3Bdkj6shHZrHiq0Nm8BXtpMJLRUIAnGok7DUREdk37uECF3VGROjLHi9TTNm5AzXvQ
UNmQkgdSMp3oYlcOjndavp6t1R
VqyYcq7yTNsJeJ4GM1zy6iFY5R
gE6KgPKWQ8XdCNER
3LyOfSkngiXxydER
ojXl2OF1ckiHCwC6Ig3Ub9F5VR
oNT5Pxm0pOmVkmEvJSsLQYYR
OuiwKRBNyUJLrE5RdW9mSWi9CjFlV5rKdR
KCIAGVcvk7ikYoNw4CJ5TAmR
ap4pkF8KtZyGcdmR
2SKKIJo8ZetSk1OWNTXFdTLS
ES_CONTINUOUS
hEwgOijWzAff48jS
IU0w5ySYVuTH9Hqk3yyaSZaFoS
Nvd9PgMuHDSli75T
0RnBTJCyBqd7u75T
xrcZQy9jhHMN48lpsEX6eE8T
mmWL8wZ7CNTkfaLT
PsNBZETYavWBgKN5UVQFJ2OT
bB8zUPkomQmWp7RT
ZTTgPlMWhpddCnTT
WiwsRuT4klSoxfap5qIpNpMTxfkSBXGXSkpyqyZbkgLdffngGNMZIV3bKecIavgRThuWvvAOUT
fJjRWwFwgX6CpvZT
11cz40ZMLlLL2bEEMW8MQANjRey4y5DTahDRbpzdeOdG01ZOqKIWMnxCRyrGur1cZ4aDc8ptAZ966Z0DkqEaUCfG89eT
cTCqgBVXpTExp5iDRyK75zQkvKGieRIaz4csDAcwybrMttDsCsf6wz4heTXtMGaAY0BvuNzy0U
XHx1hB2VQq9NlA3G3rhtzs8U
MDVnizZuKQaWT5BTTU4ysCDU
jenObeoPVaLbZ7KU
i8DcwWGnhcRvOTx4uwqUbbb2iFoqNXnEaU
XhwOpJzgFSMKM58BjKjj95eU
hUcWFgatmMCxPYhU
ptZNet75wpG720ioKUTp3PnU
PPnRyOnLKDLBN48FneDodvLV
X0SZXbZGRRC5XaOWQCsJ56QV
e46APboyXSd9EOLN46dfeeSV
I55xhwsJPSVnwmtemQBC3lnIZV
Rd6bFU1XKWolcdaV
DW1JrnNSsAlpw9uPfE9mwzqV
a7Qrz7t2c9u6BiyV
tPElle8d1KIABC3AV3wPZhzV
iOHdbEkljDpQODyQ7XucW0ok2W
qXja9kdnHZ2eLeg0tiAMlW3W
4N1qDToKVGTidb5W
IVtfzUzNaaaDCX6W
AFK6QYPaiNGtxy2N66NxkbOW
2iLGGRcbvJPb5KEOs3N12zbVRW
UE5BfOD5iSYBQcC37k4AsAXW
1kRE7Jr2u2RY3OhW
LaMjbvz12aGkcV97n5bvKd9X
rSvZigJ9XsrmMqNbstnouOI8y39ubByWMX
eoMZTIXkCSybxx8D6FsXrQXX
042pUgDOTK4QFJbX
cbF1K32yLEorrHGuxZoEKSpPuBL3e7jccX
zkBQXixPeq5MeSpX
4tp3Yb654jK2gGncPRkAJGrX
FJnsnaJVEcpPQ3uOEQW7LivX
d3IAzab9LIXBuJTR6IsfXmp7hxFQywz2KhWUlkkJHBAlJyMcZPibp2Q4PIwcVJUNVv2Mz2HkvX
RFPwZSEeSQbRZB77vYJDH0PGJaB71CpdzX
f04bzKGqX8IBtHbKZmMYBS5Y
rNNxVjsoatAqDsBY
749xzk49ceE8fjCY
6B1rkpNlgOLSZS6k0ZPktDNY
SEsYCkCL6MzDWRjZiDJd8XdHm4Dm5vu4elbU1EEjxFYWJ1Tm2dCnYcSUDjcHf5iBbK6hlcbwvZkBCxzvW1QOzafr2ekY
QBWTs6SSUvXLu4eC5L2dxBnY
dary55GtGYSWPdTcGzmkNQpY
q58yD6zGFTxkPQtY
A8uQn9SFRgcqAfwg7fPyZN8VPiKM3AbcNNecN2gMU00XbnMrNUGlUQmTzvCGcsQ5LFZwvCYYvY
LnQIMsekdTXa1yrokNFlEZ9Z
e3V5fLcuHjvy7ADZ
Vqr9izaklgcvnNTmENXlO7FZ
c8bBPodSQTPcOKUZ
TWl2pUIQm7kzfj0CxbAvyAOyR4imnEc5VZ
T1lePcLCvfHTtGnZ
lBMw9sFtACEeWJECJSTmPf2KQk15ofNnnZ
lDaq9NFhV2y8VbRHlOwZFSzZ
Dispose__Instance__
Create__Instance__
value__
fiYgKKLIJuyJNWKa6xW9H1rQAkhjxwm93a
WVGmxw2rWmsxh31DDBtI1ZNVHN3iUTGn7aWMXeF1uJVTWE8b63MhrsR58eaqV6NKTlecLku4Ra
9coF3ksnhQ0wMxk9awXH9Sca
xPo53dHIoZcE740hDvxgP8TXdDebsbTfsWpVyw6w1UomWmE10rmXDQ2mgwETnjGFLdPAkg0YImln8D2JSfdZA5CJE3ga
02wmayePPz928RS9lOLZ3Vga
9gjQ8SuVdIzRUG6Gj9U4Vwma
ProjectData
5hqlWBsDZ7EcUEbo6HAoMqxa
v1j9r1HZqzZfKXHbSKWQuDOb
DInW2PwZ1AF96Ih1Z3JoBDAlv4k1VUfAVHoQzVtC1qSEdLSDza7lrtbQ24T0KCYAI0nRDRhmHWe0ZWGoRcE66IQMVlVb
wObnYWrQCZ43HajXCZ3JrvVb
oBGAmm7lXYQRnmVCe1y0hOXb
CPPeCbWE3Oes9JmYny3lvZeA61mhtwEYfGNbkYq6UalaMEMdp6SUdoeXG68H8YM4csyqmcjPGbQzyS89rf7oCeYJqBab
lfjVUWZ5J9vsbdFIaN6oVOfb
mscorlib
6LskHzADLbZ9hIuAZW7oH3rGpcrUCkPPkKJRm3jP0I22ZJDNlvI8UPHY1zttim8QtBlbLZymob
XDmWRBgVmIe6GssR1QmS7jPO194gIoUg5DlohRkVr5LP7ka3vt8j1hZDpPXKiZ1M4UGemBiXizX2AgKALo8c
05XLJ2kybL6FlFAc
9AW0aIJ28hR9AhmLyVauF1Lc
O2TtasMLbGocS3Pc
HmaMDTP6Pvhe1FCj1Y2KttJRRzAYefz5lVLcVSh8Tol3u5BaK4zvt0LD3RVer3gvPMoIrZtVou9zcWBVSVPc
XozY0pk7PeyQF6tyoOlPh5RmseuZItKhSc
FYrmQjd6IsReufD88aTgpLhc
System.Collections.Generic
Microsoft.VisualBasic
LowLevelKeyboardProc
FvDqsL3x2DHEWOpc
af7BbGMmlWuOkdBcM6LQhIqc
a2yCUjOPKfgSUT0XaDqBfasc
GetWindowThreadProcessId
GetProcessById
PAEUbJe1b2b6fCLd
ZcfjcOmBTnEEvJXd
CULygjnvSRYaCyZd
Thread
RijndaelManaged
get_Elapsed
EndSend
BeginSend
Append
RegistryValueKind
UBound
OYi69urnYacwC3od
set_Method
CompareMethod
TargetMethod
xdBGcZr8rMOPMNrd
KB3qXhDZaxlauTrd
vLiVifVSZuf5q92KxLOGJhDXwd
y4SzAuXrCbfMjAxd
VNRhsm37jyCebndLWikiEfjvWEVEjh550e
jp6pqHwZll3zTSGe
zNU3Nu7WzOAPG1jBWo7vu6GeSe
Replace
IsNullOrWhiteSpace
CreateInstance
get_GetInstance
instance
GetHashCode
set_Mode
FileMode
EnterDebugMode
CompressionMode
CipherMode
SelectMode
FromImage
DrawImage
get_Message
EndInvoke
BeginInvoke
IEnumerable
IDisposable
Double
get_Handle
GetModuleHandle
RuntimeTypeHandle
GetTypeFromHandle
EventWaitHandle
Rectangle
DownloadFile
IsInRole
WindowsBuiltInRole
get_MainWindowTitle
get_MainModule
ProcessModule
AppWinStyle
set_WindowStyle
ProcessWindowStyle
tvFBiverPOdtrmgDP4fPUBXRme
get_Name
get_FileName
set_FileName
GetTempFileName
GetFileName
get_ModuleName
get_MachineName
get_OSFullName
get_FullName
get_UserName
get_ProcessName
CheckHostName
DateTime
get_LastWriteTime
dwTime
WaitOne
WriteLine
get_NewLine
Combine
ChangeType
UriHostNameType
CheckForSyncLockOnValueType
get_DriveType
SecurityProtocolType
GetType
SocketType
4O4P3a6DEiHsf19qcSxBanre
System.Core
MethodBase
ApplicationBase
ocXDKNwPgFDQvhse
HttpWebResponse
GetResponse
Dispose
Create
MulticastDelegate
DelegateAsyncState
GetKeyboardState
EditorBrowsableState
SetThreadExecutionState
GetKeyState
Delete
ThreadStaticAttribute
STAThreadAttribute
CompilerGeneratedAttribute
GuidAttribute
HelpKeywordAttribute
GeneratedCodeAttribute
EditorBrowsableAttribute
ComVisibleAttribute
AssemblyTitleAttribute
StandardModuleAttribute
HideModuleNameAttribute
DebuggerStepThroughAttribute
AssemblyTrademarkAttribute
DebuggerHiddenAttribute
AssemblyFileVersionAttribute
MyGroupCollectionAttribute
AssemblyDescriptionAttribute
CompilationRelaxationsAttribute
AssemblyProductAttribute
AssemblyCopyrightAttribute
DebuggerDisplayAttribute
AssemblyCompanyAttribute
RuntimeCompatibilityAttribute
set_UseShellExecute
WriteByte
m_ThreadStaticValue
DeleteValue
GetObjectValue
GetValue
SetValue
set_Expect100Continue
EndReceive
BeginReceive
Remove
winrar.exe
cbSize
get_TotalSize
set_SendBufferSize
set_ReceiveBufferSize
i8KEyCtC2uKORApWGNZhM7Ef
SizeOf
PX5oBujZyZKaobwWOzQjrI7QKrbFkaAwGVpx1gor9rXpRTWN34nxK98mRKrXMm3YywefkJi0Qf
flM38KcuNWilqPeL5N6FzrSf
hYCaqddjrZQwDQpygmDM09df
rt1n4l9EmWhXKNgDSwT1s8ff
JLoszKy4n79L0lGJLSmWxLkf
6rbOHAEpVSsZLLuvyZPVZKtf
3fjot1p1OviMtkPiYjlGtFzowI9cNVCOxf
035cjBVMrVTtC8Ng
get_Jpeg
Cqy3oBhPf3u8Hm601CZ2h9kg
System.Threading
add_SessionEnding
NewLateBinding
Encoding
System.Drawing.Imaging
FromBase64String
ToBase64String
DownloadString
CompareString
ToString
GetString
Substring
System.Drawing
ToLong
set_ErrorDialog
jAPpiZuXJbtpY9pg
uVdZd4TC2o5MHLvg
svSf4huV1jJUhLcfd52vnQPhIzT5gsJxV5aDxwvKnRMUQDwvgmkJ0AiicKO3yw9Sd0Qg0VYIsrKLgKIJhjtmHfDcAtyg
TPzapoPYkGjmKezExabhqe1h
9JSUI2D05YbMlRGoRDY4sUeE2h
F82ghz5V9uHue65vzVgOQHGh
Xgb8aMCdkg1A9sSUY5VxsOMh
M2YhsWdSrTaaLPqiBzaCfcTh
Stopwatch
ComputeHash
get_ExecutablePath
GetTempPath
get_StartupPath
GetFolderPath
get_Width
get_Length
EndsWith
StartsWith
0MRKXJ0R8CIfdfEi
VNAwBYJwt4jUrXEBUbPs3gHi
sGNOLxB6DbZimpqVLhJxb9Ui
4dPoqEJEroc51IS67qrsCPU28sPZBApFki
IoMkvgbvatDPzmIaeI00PKvi
N9R1DAB5Ub21T6tYF3eIC0xi
NwD7fB1uRjqJhyiFVU1KFnDImZGTByCFJda75QYzNmyxFv5xdwLU9bC6q2jfhIozcpfTdeRsokeMNKn5ODNJ6Mgbo70j
1mtpUOqDa6vRfhKNaihsnNOz1j
k6w9pkUQwl3eWpS3s7FFBk9j
coh0YuG2TizcjChxXmfpYzGj
WG2Ta2WqWz54GNiXQFGrYwcFGjD3rKLTiTDFeBZS1FpMzBy677Ra8K4UQgI71btaenIulP8nbdpB3BzMLIHjRFjVepMj
ORGotzfQgondMqkj
59dGGIBHW9qZ5fDk
7egr6OxnTZQ8hMJk
uLlDIg8TaE6xpFDK7N37dpLk
GD8HUlgdRxNPC6Sk
1AYMqHoMsy9irruVmw6qHhWk
aOiQFJBUmuSzTGk9a0w8kcak
xMG84n9HRvFPaAHXpFPYK0wVck
get_ServicePack
AsyncCallback
DelegateCallback
TimerCallback
RegistryKeyPermissionCheck
TransformFinalBlock
rkSS1tOD6alPWU0JItnJdZgk
G8xmAf4eAwwwLOHWey6A5ejk
1kG7UYISq5jgOjcJ74s7uNVWqIq5nPokX5qdvyV9jRzBIaLMuxJHwF9YmhVKgjvtV7Kn9jGlkk
P8C4aErEHQwvOhrk
9hvXi4piJQ9lXJ7l
vxW2gaCUywMGSFfo2mOtsou8fWsYJNiZJl
RtlSetProcessIsCritical
Marshal
System.Security.Principal
WindowsPrincipal
ConditionalCompareObjectEqual
System.ComponentModel
LateCall
kernel32.dll
avicap32.dll
user32.dll
NTdll.dll
set_SecurityProtocol
ObjectFlowControl
FileStream
GZipStream
MemoryStream
lParam
wParam
get_Item
get_Is64BitOperatingSystem
SymmetricAlgorithm
HashAlgorithm
Random
QYFQXVfbbJs7t2DvTB2jDpJfqm
ICryptoTransform
9FGprTx86NpFuJE4ovoDowzm
fFS4b2k4oc06NWo2BGlOto8n
46YnGgn9OWBZwuuAhu87TwEn
ET4TARKVPqH7imUKWPIBEfMn
xnd0nvSWCy89TMNnnKQsyA5aPn
W21aOo2HhM8gqEKnKDGWFNUn
ToBoolean
op_GreaterThan
TimeSpan
2S0pxR1hFNfEKSjREDj8zcD3by7k91dJcn
gsg81RiGKUMAb3RlSwQDzacn
CopyFromScreen
get_PrimaryScreen
System.ComponentModel.Design
AppDomain
get_CurrentDomain
A4diWabLh3XYD9D3pm2JxwIWXxrTrf9xp2TWBxN8FBhNwVqIxYQmiaLzL9vOcVAPda4AierLkn
j0ZXYU3HXR04NYWd2N8nV8nn
GetExtension
GetFileNameWithoutExtension
get_OSVersion
Conversion
System.IO.Compression
Application
Information
CopyPixelOperation
Interaction
System.Reflection
ManagementObjectCollection
Exception
Environ
SocketShutdown
7Wq0A7PNc69M5mRA5S7g9b3o
oQluDO88ziuBdvEo
A7W6pPMrx0lkASUlpk2WTXHo
75ESaNutjaplHGIo
YfwmEOX3MeAMifqqtM7IqzVo
LQYx3bUBPQBkiKWo
RneLFqKbBmpp8HSppjdOFMao
cMrrbqx8uqOPV7BwiNrrcUbo
get_Info
MethodInfo
FileInfo
DriveInfo
FileSystemInfo
MemberInfo
ParameterInfo
ComputerInfo
ProcessStartInfo
GetLastInputInfo
DirectoryInfo
ucYG6FZBbWF5ufmo
Vzaw4t32t9GuEbX23v4bEIro
JMSUxtc6iVUV6Vzo
gmAWIEoJVKDyVMCp
WRzeYA4gVOWsavqpDhdUt4NonqcXVQw4LpHIQlg8N3btSyyCRh5rgmk2NtEGeFqEyfKfweGyPp
Bitmap
a1rZHID5RB6z3jZ7xFuwUsbp
8fcwnc2NLSjKsRep
SZv4VpHiZt8MveJO5TtFIpo2qxNv9N47sp
bVmBofQdA5LyLgnRncZK7urMZSDPGPnKy4Uwkf9XjHrFTCUvJjgBSWnT5jS6LgCsmRXuluKsWl97iF6MDkgwCsIeyyyp
wZfpKmEIjbeHsc2q
3df1CnPnL5hUovOMazRyOV5q
kR40xyXfWXdnlN6q
7ytjp33b3J0a7nDq
u00rxdLmiPwq6GLpCofqvKPq
ncbaJCBr7qI3DvPq
y6GL6gqdnp8rr1eq
System.Linq
nCSxaNsr4vIjp4ROQmJuTj2r
01XMgMfeLQtQlfW0jUAwcL5r
pFSxH9qUq7XuBTVpYQ1MuhmchGJVeAVT8r
K2Embl7CNhXI099r
GbiRbDvJQv85Lzaad7cGlaAr
dhBqMthoFwDAlMUwf1hiUuBr
zGokO7GxLSiNnuZr
winrar
FtctfUvkYZUvoaBJcoGC94dr
mKFBx79eIhlRqY0qAk3tbX327nrnZoIpn8x2frH8sdrClWEQbcsaQC4PEYXcDfSUHdosptxWq1Gyc0ylyx8KzWoogGer
MD5CryptoServiceProvider
StringBuilder
SpecialFolder
ServicePointManager
ToUInteger
ToInteger
ManagementObjectSearcher
SessionEndingEventHandler
System.CodeDom.Compiler
ToUpper
get_CurrentUser
StreamWriter
TextWriter
BitConverter
ServerComputer
ToLower
RRbxTTsJCRyeN9usyGbxK8F8gr
T4Ai8fWM5aRZt7KcNynhBLgr
CreateProjectError
ClearProjectError
SetProjectError
IEnumerator
ManagementObjectEnumerator
GetEnumerator
Activator
.cctor
Monitor
CreateDecryptor
CreateEncryptor
jxSqyjqAY444Ngpr
cCUouwkVmRh6L90IFl58GBtr
IntPtr
K9YVxv7WZlv0sWtiqTB51ST3zr
kJOehUlmTcyVKHPXGkMAJf1s
3leKFzskRFij4OQBk3jbHYGP6s
obWjoab6ZRvOfBpvwzBkvK9s
x9jJBSvl3PBKfOFs
bqOQxQN1QNmA92hJTcVvY2lvV6kpaqqYY5e2tOHRPxidL7zLHGuypDh9BduzKLFHX2DLvddyJs
SHCk8I0JWeijnPn7ZyhR2rmLLs
O4pevIuAZHrZOROs
z14fZ4G97nUWQvSs
2VetF30r8RdRqlGyN99OeuMbIQOpVU0CXFtzPlVlw9NMEhpLwQhQnQh1owdtUTkpiMeg78tOYs
Graphics
System.Diagnostics
FromSeconds
get_Bounds
GetMethods
Microsoft.VisualBasic.Devices
MyWebServices
Microsoft.VisualBasic.ApplicationServices
System.Runtime.InteropServices
Microsoft.VisualBasic.CompilerServices
System.Runtime.CompilerServices
Microsoft.VisualBasic.MyServices
GetDirectories
ExpandEnvironmentVariables
GetFiles
GetTypes
GetProcesses
GetHostAddresses
FileAttributes
SetAttributes
ReadAllBytes
WriteAllBytes
GetBytes
GetDrives
SocketFlags
Strings
SessionEndingEventArgs
Equals
System.Windows.Forms
Contains
Conversions
System.Collections
get_Chars
RuntimeHelpers
GetParameters
Operators
GetCurrentProcess
IPAddress
dGET986tjp8tiCts
System.Net.Sockets
set_Arguments
SystemEvents
Exists
9QHoj4fPCjRj2Z4qmgUsxvys
FGby8qgxdtSa5v4VtsXVTFHbsV99G1ao97tn2ldE2mN2TdNM4qslmNpDL0UkHq1NLi9SXjFkz57A8rVR7ifjavNwBP1t
nZGyA2KRttzOEO5t
16u72jKe8tNQfxJt
PzoPk4PiDpXcpP0mdoe8d3Nt
JwY8hL2GKZdiodRWxvXIRyTt
VXTh7maxOyvAwygwTXPsw1Wt
Concat
ImageFormat
PixelFormat
AddObject
ManagementBaseObject
CreateObject
ConcatenateObject
SubtractObject
TargetObject
ManagementObject
NotObject
Collect
Connect
set_AllowAutoRedirect
WEsE6jLE4nngOj7aWooyOzdt
LateGet
LateIndexGet
System.Net
Socket
get_Height
op_Explicit
set_DefaultConnectionLimit
GraphicsUnit
WaitForExit
M9LcPEk8jo7Hl7kt
IAsyncResult
DelegateAsyncResult
ToUpperInvariant
set_UserAgent
WebClient
System.Management
Environment
get_Current
GetCurrent
CheckRemoteDebuggerPresent
ManualResetEvent
get_EntryPoint
get_TickCount
get_ProcessorCount
GetPathRoot
ParameterizedThreadStart
Restart
Convert
$VB$Local_Port
sNDsjf6h45oNFKst
FailFast
HttpWebRequest
$VB$Local_Host
set_Timeout
GetKeyboardLayout
XJOxiMQxA168UdWBNgNHNCvt
MoveNext
System.Text
ReadAllText
WriteAllText
GetWindowText
3jdaiTGnHcdVXk8QpaXgXyafzt
qzy3t6Lq5nrqWaamBKBdwf1u
jKLTgwXh53mHP7g5i3HDU3RD0wAUiO3I5DSoSnTZDWB750qmGGvZ9CLY9mkx6t58MQ4NQt0lNNpOxbeeeUpl4Zpx9Q5u
0BA4Dps66I4jUwob2mOHYa9u
pWGqxt3VtQgaKgOj9D0jxh9u
d6K6lIBaZnnZqrClDdBZNrGu
4AAtlnLThKf1WWYu
3KTwMdqAKpXnOlQkZVLRzGlu
S5xbO6U6IGIaVjmu
b2HSCUuzmCxbdRkJPiiv7TZvmu
pqAxaoOzh2xDhJ6gaJ3huz0v
RPGKMk1xaG8hFO8S3jCCT9ZHs3V25Qcrs0SizFSk159lOfGS2Vc8uieIrgPtCCFLyLLkwX9O3v
Fn9UV3i87ezqn996Y4tTH4Mv
TKvszR2Bp5EFOkucAA5r03Ov
q9Kui1HNEOZG4Pp9E5YWQsSv
PboijIbQXRQiwfYv
abvprFndyzDVNrGA931wYSev
EVpphSd1GPZX8UxkrJLy6ggv
m1z37QDUAMQTSQpApg8xSWCDluRIPYcjpwzetKhyxmYe83iIsKBeu4xTnvc4QxtEWogQNZ454A0IFxkynsfbArEGLPjv
zAsTxYH1P2eeVVrv
HUJRvq1C203qDn4NUESxpJ1w
tZbNAYEaDbWgb3UcjrBlj65w
6CtdKvIyGQTn1yBw
UNjxhpeqQEP90BEw
42WxtqQWAWXkdNYFxLwDEQHw
8dRVVGmuNFHRtgXhxpns7tIw
M4EM5D0i1IexP9C7j51tVdB4Mw
NYaJGUOXp4BhlcldCJoAEr8KPw
GetForegroundWindow
set_CreateNoWindow
kaWnj9X2grpgv91x
ToUnicodeEx
UnhookWindowsHookEx
SetWindowsHookEx
CallNextHookEx
8GL2fn9Pdio9HC4MBSQZ5YvFPuVhTmoaO2ajavR7Kfgdqe697pWYsKhYH2nAhUgTzwRFu9stOx
yJUd1h09Din3guSx
tphXTaFlWXOo7XUQh6noYMiBQ9WTUNygdx
LateSetComplex
syPxKqKtStGpi0bVAij8g1qx
0kN0XpNNQRptfd0y
cSZGWeLeun4Ur5DYyLfLhK2y
l0KvSlEr7JQ5yzdUtXerI7Fy
aK95UmkOISRq0MMy
uuMrNTuPthjOS2Uy
ob62XCcdvExvdnzvoetIhSUy
bVlMgPrguEIAK6NU8UC80UUy
ToArray
RvENaJnz6vEfsAb2ELGKhFWz8KAalrEQby
get_IsReady
set_Key
CreateSubKey
OpenSubKey
MapVirtualKey
RegistryKey
System.Security.Cryptography
R80r7VnzRDrPh5LcJnbQRxiy
Assembly
AddressFamily
ObjectQuery
get_TotalPhysicalMemory
get_Directory
CreateDirectory
get_SystemDirectory
get_Registry
op_Equality
WindowsIdentity
IsNullOrEmpty
RegistryProxy
cmmBuvIELe0tXb7z
DpMxsyNjxhItfxuBczipElzlFz
ebk7c2vbLJUJBtH0iom5ArLz
yjruQzADQ7vN0aPz
6VM96Cp9GusGsBRtHK5pFF6tWAml1X5aKda8PVmXwvqZ3LigqqqyR6VEMycnY7qbqIzLrkzozGA6Y1xbtHvvJ7rUsLSz
nT76zGxY3vzHVCaL9EWfZl6cvoO8INOUUz
wv9Z5ZpQMmvEEWwwfEnQIiuHToP3gfKuZz
HcI4uEDggGD6Qlfz
ZYlnrm2KYFyub5dEecHQsIvz
WinRAR
WinRAR archiver
Alexander Roshal
'Copyright
Alexander Roshal 1993-2023
WrapNonExceptionThrows
$3f24d7f1-cc7f-44d6-b6cd-858d1f19ec46
6.24.0.0
MyTemplate
14.0.0.0
My.Computer
My.Application
My.User
My.WebServices
4System.Web.Services.Protocols.SoapHttpClientProtocol
Create__Instance__
Dispose__Instance__
<generated method>
<generated method>
_CorExeMain
mscoree.dll
C]58W-
j#*=R9b
$DL1Za
QA$!)"1
R h$I*
>q{?1U
dqBT_
EC6IRP Q_
0jH]O5
gZ$\v(
ykK;isQ
CHBTK4BT
wy'sdg`J
J53~"K2
hIjTfmb}
W~S9i}
"AijKj
stX5E3
U!Ah'B]
:jG524#G
}.*:;L
-}%Vb~
(Ums?CQ&c
d.hQ7D)
")3G(a
yrr4c&
\PP"Bj-)A
&(umKA#C
uG(\%)/
IsaQg8
}P&m.e
ag<o3U
]r^L%!
DVfAij-
/;t;,U
Ys9/SJq
#5]TbR
&D&*L413
8x)'OG
g|sLU9
j}=c@\qY
oo-u]?q
2vWH]G
{*Ibg:
yTj1Ee
1n@nP2
5.m_`k
;N=*V,w
HT$&.>
VWWWUVefee
#K4[W`)}7
fov`?!
DFK:oR
9}pL<z
{S^nNU9(
@bK{rn
#|i%t}d
&%_o)@
]JN\l<
^'big%
/JEZvF
|/*|CZ^
P.SAoW
ZqT/X45
LoG7d_)`
X6"[MAu
nA0Y,>
X|gl<(
&0_6^>
@xcAxj
%0j)w0
\.ftSe
}0XUw.-
,@v_C5
)nu3sp
=\'EF0
4VDqrrTZd
W|z$[q
Xwi*:J
Tvtk0M6
MG+4a]
h<zCfo9
uR$ft(
ktRx$K
2]T^91
ipS\2
M~g"We
b2Sj:
CB&;!{8^:6
o?8Yz6
$x7F*o
Q^=r8U
z`3dbT.
p[\ao{I
@Nr>qD
t%J>d8>
%O$$v/
yxDFdU
Sj7)2"
Qo'5xO"
}`Ta4
d#coF,
:*{wT\
H/'#_G
bpLHQLr
+k!ztYH^
a# 4a%#
t)(m~.-
r*'=}.-
p)'Vz-,
r*(%|-+7
x8*td<3
H!fs@ W
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<assemblyIdentity version="1.0.0.0" name="MyApplication.app"/>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v2">
<security>
<requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3">
<requestedExecutionLevel level="asInvoker" uiAccess="false"/>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
ZTidhx1rz4tNB4iT
9r2eg8zIsTZbaB5j
mv13tOSrdTx2jJxS
9D5p8mJuolA0rS3x
0foauA1AUgHTyt0d
qOoBu1bD92lc4Ikg
S5BfMT4s1Dlx7W3h
fdK4YOuL6gmsUGPN2OrseM6qtYDTW25T3Ymkf63znIU=
Ug1nMr6cQD/qnT1ljyBDvA==
a4RFICmBQc48eXJ919bCZA==
wmCqgHQWOiiwloXaOrSlXg==
gAAVBdD9xCnIkxgOa56/sw==
2CKUNCN2Nhd1YfereY03pg==
kSFshUEyUQvi28RZCZiiBA==
42EGzHLs/pAov4oYHrtipg==
OvTU87AmRG8SHTlF
\Log.tmp
b8EllH5PUUpgsQkts3tjEyhxjmA/wQ/UPbX3Ny4dtyvkskpBvvIrkgSNuglrVaTB
Re1YgycJ6pMfUwq2i+HpMA==
6iaRbKf1rghcMGKD
DeFWSXjMfWII58Z8
schtasks.exe
/create /f /RL HIGHEST /sc minute /mo 1 /tn "
" /tr "
/create /f /sc minute /mo 1 /tn "
SOFTWARE\Microsoft\Windows\CurrentVersion\Run
WScript.Shell
CreateShortcut
TargetPath
WorkingDirectory
[XWorm V5.0]
New Clinet :
UserName :
OSFullName :
USB :
CPU :
GPU :
RAM :
Groub :
https://api.telegram.org/bot
/sendMessage?chat_id=
&text=
powershell.exe
-ExecutionPolicy Bypass Add-MpPreference -ExclusionPath '
-ExecutionPolicy Bypass Add-MpPreference -ExclusionProcess '
http://ip-api.com/line/?fields=hosting
Select * from Win32_ComputerSystem
Manufacturer
microsoft corporation
VIRTUAL
vmware
VirtualBox
SbieDll.dll
iTm7yOsZNAMfKw8m
eDdxNejZuW8PWxMu
k7BhJncKaosnAnQt
iDev1vSzL5zVbg7B
AKrUJJNrWkmegxsC
0G2gJazECMCrrGyd
sW7vHCcKsihxZ1d5
gCCOhw7fUu4YHXjZ
yTNOSH21jTExHfyG
rWzOSUR8DvYOIyja
Ip3oxLADMsovTd4G
VG2CHI0O6fSba321
6zbNoxQQemL4tdR8
HXZWanZToe8Xez9A
RG69JMjmpEvZmmK8
Microsoft
Service Pack
dd/MM/yyy
\root\SecurityCenter2
Select * from AntivirusProduct
displayName
SELECT * FROM Win32_VideoController
Win32_Processor.deviceid="CPU0"
Core(TM)
r6TGROw0NQ5HYgp4
WTrY2owqEkNINTWA
e5xWSvqJpbXboRHt
8OMmcOujjUismOlJ
vwNElzUi8AA4sq4h
hg6h2XyYp1n8kHPV
i6jS6zMJc4anlz7D
6NOR9ZfWtWk5x7yD
tQhMRvqQuAmRO7sE
rbnpLIoXIex7gu5f
TJDOwCJN40A6oND7
j8GDnCU8M6JsugmS
DdpciymsGCdz1RMl
41IyXraLiFDfx0TE
Eu6yJPnsDiNXsKjk
n9JJ9xzrsABvKPGC
v7jQkIEySvqcaI3C
q9Hrt3kXm4om5vpv
OKj2uvTKfxOyFaDi
vTAcJdGSk9QUDTHV
SLp8zjb3Kp0mNm7b
uninstall
update
Urlopen
Urlhide
PCShutdown
shutdown.exe /f /s /t 0
PCRestart
shutdown.exe /f /r /t 0
PCLogoff
shutdown.exe -L
RunShell
StartDDos
StopDDos
StartReport
StopReport
\drivers\etc\hosts
Shosts
HostsMSG
Modified successfully!
HostsErr
plugin
sendPlugin
savePlugin
OfflineGet
Plugin
Invoke
RunRecovery
Recovery
RunOptions
injRun
UACFunc
ngrok+
Plugin Error!
ToLower
Open [
-ExecutionPolicy Bypass -File "
4c01wHGrf4EpCBAo
43qxiLuwaKH0GXoo
ST3DWVe5Ar0plVqL
a3hAnv8jfC7Sj7AE
eftF8NWSJkA8uO3A
dH7EWJb84sglIhcE
nmCAZqdoDi31R6p0
bgWoEn1CE5oECNgw
JScUSzSp9Fp3FiA3
8eqGWtrHl5jlVVfW
R9J0fb8R2baULTzk
5iQYlMYOIxjg1Rzq
OuckweyF2vmJ7voP
Llb3JnieUIxXXEi4
SUTF1WKHTERK3CXl
MprvfiAFyfmuUnON
POST / HTTP/1.1
Host:
Connection: keep-alive
Content-Type: application/x-www-form-urlencoded
User-Agent:
Content-length: 5235
schtasks
/delete /f /tn "
attrib -h -s
*.* /s /d
@echo off
timeout 3 > NUL
" /f /q
n1ZcxnPmx2NJCoWE
LJlD9SSfVnej3Ewf
wscript.shell
Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced
ShowSuperHidden
windowstyle
cmd.exe
Arguments
/c start
&start
& exit
regread
HKEY_LOCAL_MACHINE\software\classes\
HKEY_LOCAL_MACHINE\software\classes\.
\defaulticon\
IconLocation
iconlocation
arguments
&start explorer
HKEY_LOCAL_MACHINE\software\classes\folder\defaulticon\
VJ90elRyoCD1mJsC
BLn5SDQaLrhzkEdJ
sSDeon1VDo5bxbrN
v03oAYWmWQ5g3z7c
ToUpper
[SPACE]
Return
[ENTER]
Escape
LControlKey
[CTRL]
RControlKey
RShiftKey
[Shift]
LShiftKey
[Back]
Capital
[CAPSLOCK: OFF]
[CAPSLOCK: ON]
MainWindowTitle
ProcessName
4WFJb1fLV91QHW2f
hrxyrSHdF9SVx6ND
grmM16uCm4Bsw9gW
fxMDe7Ov5Wke8wIR
1ohVThJwjOUYtcAl
xaSOXb43RUqN1tVW
gbOPMwus7IdegmoV
9FzEYCDIBOZXFnGzOgNIUuJQUwJpxpEgNXXx2w3AK9aoquErdBwvBvZylpacsAF9qEITZlcOoEUCCdThkNyVkSLCpv1A
btxXOjKBl3wFTpT3XElJa3FybP36Has3X0M90f13nodSih2AklYYN4Wvep65zKUgL1oXGlORfYvRt1cPiG4ZsCS2GSa1
jRwy0D5yBIypLunJtHT4PNjwtL0mPoiufovLcf7jv2br4Rr3G1pdiZbG0YU8cNDW3emiDqXfWvNxTgE4k060nRSZoHi5
LzaTX7Oxmb0CTHtF0P2EEOd2L17e6zDrZPeIrvrUjTp1iQ36BXbwZXa3zEBw4CbnsUWMubaPqegVVkf5d5hJECkDMIqR
4AS26oR2RuYI92MatodqRu3eeLoMMOzDhPeV9FLuUU5fG02Fm4Sgj2hVBt2VpN1NoUJw3mdl3Xfi8qMQ732dyOBvz8u5
ZdQQL20JgIrjOFU7ohqt4FAdNRwDfCF76cOMFflXPkYPlLnAO0EdcPHauK29hJdAtj3g0x7x7ELjUXQ95QHvSNoUHsPo
3jdi1cqy5b6Rr5JakxdbFKp9n060NOPlV5V8zqxBbTts3IuqWwB9z5aNxcW07lh3vWGk5qDeePgYZUOrhYNYfgrLlR6F
ZScJVGmSvUEbyVVY5hzG7M0KmYzTR9kvQtl5df4zbCo0f6ILxb1fVOeBWV7hteeqIVbKCxB4lGZ8u7WxZj5VVwEYK3Yg
x4O6YGIcLAbnaqQEEHSMJ07fic9QcVR9qeQYovQHCyGHE6h55w2x5yEAhoQAAeeS87GmPTt4FE1JMLJ9ebT6aZp8OWz1
Jn0e225LKAnDzj7t56VFrSFZzxJmY8IEKDr8pstUyX2z6Pty2gU2WTcm2duljNnlcAF4ihguy0YAQqTogTyACcxMbYj5
GNllmzE3igXsqAXys34VpFuKFAZfSeQysz
qebngyllFJQS34uFV5TnXJKaFtTp9YhicT
hVjAGeUGkUindGqnxl0I4GnAPcqWswM2hb
XUfGudLEcI8DTFw5D9Rju0ny9H12YBwkTH
EWJIMWkHhNoVvLui49K1s0EiWKd20fCDXx
qRhrCv7DKSc1A9sagWDrVTOMVqFrKhqkgi
Cw5IOm3iqJ11w2E8sQrEcMo96ljskkDABC
Qi0mGnQPJdIBrvnecQBvEXye1YNTFWsTIg
Software\
Mozilla/5.0 (Windows NT 6.1; Win64; x64; rv:66.0) Gecko/20100101 Firefox/66.0
Mozilla/5.0 (iPhone; CPU iPhone OS 11_4_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/11.0 Mobile/15E148 Safari/604.1
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36
abcdefghijklmnopqrstuvwxyz
Err HWID
ToArray
BGWdWtCSzBthGHmrwNztEmwKq4gtewfPP8
GCxkEvYZ9YRqxAF4hA8jy7GiIeZvzllBFU
DwiFKBIZ0yzkPjXuhhruGHJgOIMkosqPgc
WoIx2fE3XO11J8PcqP5XB9m8H0mHyQRNfn
NcraLY5ct07vp3MZ2hUJinK05kypN7hfkQ
KR26U8rbfpFShCyU1rx8Sjt2Uap4GnIFEO
BSkxMTeBCYXIdatPuwKkdvmJLESwd5fxlk
HzUBBCPrVHh9hKELptxx0cFVZ5OzSO82CY
BI5zwGlhP8PwErmBhJ2Upfy2slDivLEXHk
lHt1SbJSBgy3C34oA7uQV7By9IFO8OUL375rXK4O7bvcpZOsz2wnE7k3nQgRsnGVtZQaOlZNvrHKp9J7W639
vdqxjwP7Xso6Y38sF8sOBCw0yg
PNzUh4Xn13sg3pLleQg7NgdWab
Yx1WbrfPciCLZoUp9A7ECgHa0W
iybQhXCmw1jCYZ38KUWpP59wP9
U2Eb1UbESVcrt2iypl19DlVinT
PCM59TcMXJX1Ib4253eRXZvMtf
75hsbujpmscDljBmbfxcx1GBV9
BPXE9mIgo10rLORHfzZErs8X1B
bJ3MMpqHLtBKZzSBRRZ0tCmLe9
Vn5ct9Gw2vtPcu964lOnUkTwnj
oxwWj9In3DJIPwUKPUCXHF1hv0
fRUe8BC7gv0RAsoebuHzcHUgHY
OTFLEILNkm74AazHAlQOQTdOYa
4uoZEmvTLYZW1hDAv5U3dhl2Jx
Qr2pTbVUNG1AijSfY1ZYAiMFnh
K76BEJmszzylRZLBoYC3HC72Np
30XPLTcxf4hD4oZD3vtwUKc6FT
abcdefghijklmnopqrstuvwxyz
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
CompanyName
Alexander Roshal
FileDescription
WinRAR archiver
FileVersion
6.24.0.0
InternalName
winrar.exe
LegalCopyright
Copyright
Alexander Roshal 1993-2023
OriginalFilename
winrar.exe
ProductName
WinRAR
ProductVersion
6.24.0.0
Assembly Version
6.24.0.0
Antivirus Signature
Bkav Clean
Lionic Trojan.Win32.XWorm.m!c
Elastic malicious (high confidence)
MicroWorld-eScan IL:Trojan.MSILZilla.25346
FireEye Generic.mg.715d9e1786839981
CAT-QuickHeal Trojan.GenericFC.S29961068
Skyhigh RDN/Generic BackDoor
ALYac IL:Trojan.MSILZilla.25346
Malwarebytes Trojan.Crypt.MSIL
VIPRE IL:Trojan.MSILZilla.25346
Sangfor Suspicious.Win32.Save.a
K7AntiVirus Trojan ( 005aa5f01 )
BitDefender IL:Trojan.MSILZilla.25346
K7GW Trojan ( 005220b31 )
Cybereason malicious.f3e92f
Arcabit IL:Trojan.MSILZilla.D6302
Baidu Clean
VirIT Trojan.Win32.MSIL_Heur.B
Symantec ML.Attribute.HighConfidence
tehtris Clean
ESET-NOD32 a variant of MSIL/Agent.DWN
Cynet Malicious (score: 100)
APEX Malicious
Paloalto Clean
ClamAV Win.Packed.njRAT-10002074-1
Kaspersky HEUR:Backdoor.MSIL.XWorm.gen
Alibaba Backdoor:MSIL/AsyncRAT.2a80f9b1
NANO-Antivirus Clean
ViRobot Trojan.Win.Z.Agent.240640.GA
Rising Trojan.AntiVM!1.CF63 (CLASSIC)
Emsisoft IL:Trojan.MSILZilla.25346 (B)
F-Secure Trojan.TR/Spy.Gen
DrWeb BackDoor.BladabindiNET.30
Zillya Trojan.Agent.Win32.3772011
TrendMicro Backdoor.Win32.XWORM.YXDKQZ
Trapmine malicious.moderate.ml.score
CMC Clean
Sophos Troj/RAT-FJ
SentinelOne Static AI - Malicious PE
Jiangmin Clean
Webroot Clean
Varist W32/MSIL_Agent.BUD.gen!Eldorado
Avira TR/Spy.Gen
MAX malware (ai score=86)
Antiy-AVL Clean
Kingsoft malware.kb.c.1000
Gridinsoft Ransom.Win32.Bladabindi.sa
Xcitium Clean
Microsoft Trojan:MSIL/AsyncRAT.R!MTB
SUPERAntiSpyware Clean
ZoneAlarm HEUR:Backdoor.MSIL.XWorm.gen
GData MSIL.Backdoor.XWormRAT.A
Google Detected
AhnLab-V3 Trojan/Win.AntiVm.C5369627
Acronis Clean
McAfee RDN/Generic BackDoor
TACHYON Clean
DeepInstinct MALICIOUS
VBA32 Backdoor.MSIL.XWorm.gen
Cylance unsafe
Panda Trj/GdSda.A
Zoner Clean
TrendMicro-HouseCall Backdoor.Win32.XWORM.YXDKQZ
Tencent Trojan.MSIL.Agent.16000605
Yandex Trojan.Agent!QiQdllNU2no
Ikarus Trojan.MSIL.Bladabindi
MaxSecure Trojan.Malware.206830030.susgen
Fortinet MSIL/Agent.DWN!tr
BitDefenderTheta Gen:NN.ZemsilF.36792.om0@aiVcPyf
AVG Win32:XWorm-C [Rat]
Avast Win32:XWorm-C [Rat]
CrowdStrike win/malicious_confidence_100% (W)
No IRMA results available.