Static | ZeroBOX

PE Compile Time

2023-11-18 17:01:23

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x000c0ba4 0x000c0c00 5.31841799083
.rsrc 0x000c4000 0x00002050 0x00002200 4.64950311515
.reloc 0x000c8000 0x0000000c 0x00000200 0.0980041756627

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x000c4b64 0x000008a8 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_ICON 0x000c4b64 0x000008a8 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_ICON 0x000c4b64 0x000008a8 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_ICON 0x000c4b64 0x000008a8 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_GROUP_ICON 0x000c540c 0x0000003e LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_VERSION 0x000c544c 0x000004b8 LANG_ENGLISH SUBLANG_ENGLISH_US COM executable for DOS
RT_MANIFEST 0x000c5af0 0x00000560 LANG_ENGLISH SUBLANG_ENGLISH_US XML 1.0 document, ASCII text, with CRLF line terminators
RT_MANIFEST 0x000c5af0 0x00000560 LANG_ENGLISH SUBLANG_ENGLISH_US XML 1.0 document, ASCII text, with CRLF line terminators

Imports

Library mscoree.dll:
0x402000 _CorExeMain

!This program cannot be run in DOS mode.
`.rsrc
@.reloc
KDBM~^
1SPS*
<j[*&~
Z?_d
_b`*
v4.0.30319
#Strings
#(#Q#q#
)5*D*_*h*|*
* +E+j+
,4,A,Q,d,
,!-/-t-
5$5*5Z5p5
6.6;6d6w6
8)8=8U8
(&(=(F(
,a-!.g.p.
748a5d90-36e3-4d6d-b692-0a0b498b5bd8
CompilationRelaxationsAttribute
System.Runtime.CompilerServices
mscorlib
System
Boolean
RuntimeCompatibilityAttribute
ExtensionAttribute
AssemblyFileVersionAttribute
System.Reflection
String
GuidAttribute
System.Runtime.InteropServices
7RmMy0K
<Module>
Object
ValueType
MulticastDelegate
NativeWindow
System.Windows.Forms
SafeHandle
Dictionary`2
System.Collections.Generic
NJrFB9Xx
<>c__DisplayClass37_0`1
<>c__DisplayClass38_0
Exception
<>c__DisplayClass7_0
JsonConverter
Newtonsoft.Json
<>c__DisplayClass29_0
<GetAllFrames>d__34
<>c__DisplayClass76_0
<>c__DisplayClass16_0
<>c__DisplayClass22_0
<>c__DisplayClass23_0
<Module>{286641BF-F13B-48A2-BF86-AE04EFB36C5E}
Attribute
<PrivateImplementationDetails>{2FB680BD-00A1-4CDD-A7C4-1333E77B6A96}
__StaticArrayInitTypeSize=256
__StaticArrayInitTypeSize=40
__StaticArrayInitTypeSize=30
__StaticArrayInitTypeSize=32
__StaticArrayInitTypeSize=16
__StaticArrayInitTypeSize=64
__StaticArrayInitTypeSize=18
RemoteCertificateValidationCallback
System.Net.Security
IntPtr
SslPolicyErrors
DateTime
List`1
StringBuilder
System.Text
Enumerator
get_Current
MoveNext
IDisposable
Dispose
GetEnumerator
get_Count
.cctor
GetForegroundWindow
user32.dll
GetWindowText
GetWindowTextLength
GetKeyboardState
UInt32
EnumProcessModules
psapi.dll
GetModuleFileNameEx
GetWindowThreadProcessId
GetKeyboardLayout
user32
ToUnicodeEx
GetPrivateProfileString
kernel32
DeleteFile
GetVolumeInformation
Kernel32.dll
GetModuleFileName
MoveFile
VaultOpenVault
vaultcli.dll
VaultEnumerateVaults
VaultEnumerateItems
VaultGetItem
FieldInfo
SecurityIdentifier
System.Security.Principal
Double
GetKeyState
value__
UInt64
Marshal
SizeOf
GetLastInputInfo
User32.dll
Win32Exception
System.ComponentModel
Interlocked
System.Threading
CompareExchange
Finalize
SetWindowsHookEx
CallNextHookEx
UnhookWindowsHookEx
GetModuleHandle
kernel32.dll
Invoke
BeginInvoke
IAsyncResult
AsyncCallback
callback
object
EndInvoke
result
wParam
lParam
UIntPtr
ElapsedEventHandler
System.Timers
ElapsedEventArgs
ToString
SetClipboardViewer
ChangeClipboardChain
SendMessage
CreateParams
WndProc
Message
sender
AddRange
IEnumerable`1
Version
ContainsKey
get_Item
Environment
GetFolderPath
SpecialFolder
Process
System.Diagnostics
ToArray
RegistryKey
Microsoft.Win32
Registry
CurrentUser
System.Text.RegularExpressions
KeyCollection
ValueCollection
get_Keys
get_Values
RijndaelManaged
System.Security.Cryptography
ICryptoTransform
Rfc2898DeriveBytes
XmlDocument
System.Xml
XmlNodeList
XmlNode
IEnumerator
System.Collections
Resize
DirectoryInfo
System.IO
Remove
Enumerable
System.Linq
System.Core
ToList
BinaryFormatter
System.Runtime.Serialization.Formatters.Binary
TripleDESCryptoServiceProvider
UTF8Encoding
FileStream
Random
FileMode
FileAccess
FileShare
MD5CryptoServiceProvider
CryptoStream
StreamReader
MemoryStream
Stream
CryptoStreamMode
Tuple`3
get_Item2
LocalMachine
get_Item3
get_Item1
DESCryptoServiceProvider
KeyValuePair`2
get_Value
get_IsInvalid
handle
ReleaseHandle
FFQn5CqIO
RegOpenKeyEx
Advapi32
RegCloseKey
RegQueryValueEx
MatchCollection
RegexOptions
HMACSHA256
get_Key
JavaScriptSerializer
System.Web.Script.Serialization
System.Web.Extensions
Deserialize
set_Item
BinaryReader
UInt16
Decimal
SHA1CryptoServiceProvider
HMACSHA1
DataProtectionScope
System.Security
BitConverter
IsLittleEndian
CryptographicException
GoH11I9
HMACSHA512
SHA1Managed
PaddingMode
DirectorySeparatorChar
FileInfo
BCryptOpenAlgorithmProvider
bcrypt.dll
BCryptCloseAlgorithmProvider
BCryptGetProperty
BCryptSetProperty
BCryptImportKey
BCryptDestroyKey
BCryptEncrypt
BCryptDecrypt
IsTextUnicode
ArgumentOutOfRangeException
ComputerInfo
Microsoft.VisualBasic.Devices
Microsoft.VisualBasic
ManagementObjectSearcher
System.Management
ManagementObject
IEnumerator`1
IEnumerable
WebResponse
System.Net
HttpWebRequest
HttpWebResponse
IList`1
RNGCryptoServiceProvider
ICollection`1
ImageCodecInfo
System.Drawing.Imaging
System.Drawing
ManagementClass
ManagementObjectCollection
ManagementObjectEnumerator
Bitmap
EncoderParameter
Encoder
EncoderParameters
Rectangle
Graphics
Quality
FtpWebRequest
NetworkCredential
ArgumentException
Single
NtQueryObject
ntdll.dll
NtQuerySystemInformation
CloseHandle
OpenProcess
GetCurrentProcess
DuplicateHandle
QueryDosDevice
CreateFileMapping
MapViewOfFile
UnmapViewOfFile
CreateFile
WriteFile
GetFileSizeEx
GetFileType
GetLastError
TryGetValue
$$method0x600007d-1
$$method0x600008c-1
$$method0x6000255-1
$$method0x6000255-2
$$method0x60000ff-1
$$method0x60000ff-2
$$method0x6000105-1
$$method0x6000115-1
$$method0x6000115-2
$$method0x600011a-1
$$method0x600011f-1
$$method0x6000120-1
$$method0x600013f-1
$$method0x6000191-1
JsonConvert
DeserializeObject
Nullable`1
get_HasValue
DateTimeOffset
HttpStatusCode
JsonLoadSettings
Newtonsoft.Json.Linq
FalseString
TrueString
GetValueOrDefault
JToken
ApiKey
AppName
StackFrame
MethodBase
StackTrace
TimeSpan
Action
System.Threading.Tasks
Func`1
Task`1
<>4__this
Action`1
ContinueWith
TargetInvocationException
HttpUnhandledException
System.Web
UserName
System.Web.IHttpModule.Init
HttpApplication
IHttpModule
ArgumentNullException
EventHandler
EventArgs
System.Web.IHttpModule.Dispose
JObject
HttpContextWrapper
HttpContext
HttpContextBase
RouteData
System.Web.Routing
MinValue
DateTimeKind
Tuple`2
Func`2
JValue
Contains
JArray
JTokenType
JEnumerable`1
Extensions
JProperty
HttpException
Assembly
MethodInfo
JsonSerializerSettings
Module
MemberInfo
assembly
CanConvert
get_CanRead
ReadJson
JsonReader
JsonSerializer
NotImplementedException
WriteJson
JsonWriter
CanRead
GetSystemTimePreciseAsFileTime
WebProxy
TaskFactory
StartNew
WebException
GZipStream
System.IO.Compression
CompressionMode
UuidCreateSequential
rpcrt4.dll
SecurityException
Encoding
ObjectQuery
ManagementScope
SqlException
System.Data.SqlClient
System.Data
ParameterInfo
<>1__state
<>2__current
<>l__initialThreadId
<>7__wrap1
<>7__wrap2
System.IDisposable.Dispose
<>m__Finally1
<>m__Finally2
System.Collections.Generic.IEnumerator<StackifyLib.Models.TraceFrame>.get_Current
System.Collections.IEnumerator.Reset
NotSupportedException
System.Collections.IEnumerator.get_Current
System.Collections.Generic.IEnumerable<StackifyLib.Models.TraceFrame>.GetEnumerator
System.Collections.IEnumerable.GetEnumerator
System.Collections.Generic.IEnumerator<StackifyLib.Models.TraceFrame>.Current
System.Collections.IEnumerator.Current
message
Settings
Method
context
HttpRequestBase
HttpCookie
HttpSessionStateBase
KeysCollection
NameObjectCollectionBase
System.Collections.Specialized
HttpSessionState
System.Web.SessionState
detail
ConcurrentQueue`1
System.Collections.Concurrent
ConcurrentDictionary`2
TimerCallback
TryRemove
Enqueue
TryAdd
TryDequeue
Select
ForEach
jswq37e
TryPeek
typemdt
get_Assembly
SortedList
Hashtable
GetBytes
SymmetricAlgorithm
AesCryptoServiceProvider
Activator
CreateInstance
ObjectHandle
System.Runtime.Remoting
Unwrap
HashAlgorithm
TransformBlock
get_BaseStream
set_Position
ReadUInt32
RuntimeTypeHandle
DynamicMethod
System.Reflection.Emit
ILGenerator
Monitor
GetFields
BindingFlags
GetTypeFromHandle
get_Module
GetGenericArguments
get_IsStatic
Delegate
CreateDelegate
GetParameters
get_IsValueType
MakeByRefType
get_ParameterType
OpCode
OpCodes
Ldarg_0
Ldarg_1
Ldarg_2
Ldarg_3
Ldarg_S
Tailcall
Callvirt
get_Length
Convert
FromBase64String
GetString
RSACryptoServiceProvider
set_UseMachineKeyStore
GetMethod
Replace
GetType
GetProperty
PropertyInfo
LoadLibrary
GetProcAddress
GetDelegateForFunctionPointer
Concat
umLocehuEC
op_Equality
RuntimeHelpers
InitializeArray
RuntimeFieldHandle
CreateDecryptor
CryptoConfig
get_AllowOnlyFipsAlgorithms
ComputeHash
GetManifestResourceStream
ReadBytes
get_MetadataToken
ResolveMethod
get_FieldType
SetValue
get_DeclaringType
get_ReturnType
GetILGenerator
get_Unicode
get_Location
Exists
GetName
AssemblyName
get_CodeBase
GetValue
hModule
lpType
lpAddress
dwSize
flAllocationType
flProtect
set_Key
set_IV
CreateEncryptor
ToBase64String
classthis
nativeEntry
nativeSizeOfCode
KDikMXewCI
ReadInt32
lpName
hProcess
lpBaseAddress
buffer
lpNumberOfBytesWritten
flNewProtect
lpflOldProtect
dwDesiredAccess
bInheritHandle
dwProcessId
$$method0x6000317-1
$$method0x6000332-1
$$method0x6000332-2
$$method0x6000340-1
$$method0x6000340-2
$$method0x6000353-1
$$method0x6000395-1
$$method0x60005b3-1
SecurityProtocolType
ProcessModule
OperatingSystem
SearchOption
ProcessStartInfo
GroupCollection
CipherMode
StringSplitOptions
XmlElement
StringComparison
Rijndael
CultureInfo
System.Globalization
NumberStyles
IFormatProvider
WebRequest
ICredentials
PropertyDataCollection
PropertyData
ManagementBaseObject
Screen
ImageFormat
CommentHandling
LineInfoHandling
UriKind
NameValueCollection
IDictionary
IHttpHandler
HttpRequest
IPrincipal
IIdentity
HttpServerUtility
Formatting
HttpResponseBase
HttpResponse
RouteCollection
RouteValueDictionary
RouteBase
AppDomain
NullValueHandling
ReferenceLoopHandling
WebHeaderCollection
HttpRequestHeader
RegistryHive
RegistryView
ICollection
SqlErrorCollection
SqlError
Binder
Thread
HttpCookieCollection
ServicePoint
IWebProxy
Application
ServicePointManager
set_SecurityProtocol
get_ServerCertificateValidationCallback
Combine
set_ServerCertificateValidationCallback
get_Now
GetTempPath
ReadAllText
Delete
AppendAllText
Append
SystemInformation
get_ComputerName
get_UserName
GetExecutingAssembly
GetEnvironmentVariable
ToBoolean
ToInt32
PtrToStructure
ReadInt16
PtrToStringUni
get_UTF8
IdentityReference
ReadIntPtr
GetField
ToInt64
op_Explicit
ReadByte
get_TickCount
GetLastWin32Error
get_MainModule
get_ModuleName
op_Inequality
Control
get_ModifierKeys
add_Elapsed
set_Interval
IsNullOrEmpty
EndsWith
ToUpper
ToLower
ToUInt32
Clipboard
GetText
set_Enabled
CreateHandle
get_Handle
get_WParam
get_Msg
get_LParam
get_OSVersion
get_Version
get_Major
get_Minor
get_Size
Directory
GetFiles
ProtectedData
Unprotect
get_StartInfo
set_FileName
set_Arguments
set_CreateNoWindow
set_RedirectStandardOutput
set_UseShellExecute
WaitForExit
get_StandardOutput
TextReader
ReadToEnd
GetDirectories
GetParent
FileSystemInfo
get_FullName
ReadAllBytes
get_Parent
get_Default
OpenSubKey
GetSubKeyNames
ToChar
TrimEnd
ToByte
get_Capacity
get_Groups
Capture
StartsWith
ReadAllLines
set_Padding
set_Mode
TransformFinalBlock
Substring
set_IterationCount
DeriveBytes
Escape
Matches
get_NewLine
get_Chars
get_ChildNodes
get_ItemOf
get_InnerText
get_Exists
SelectSingleNode
ExpandEnvironmentVariables
get_ASCII
set_BlockSize
UnescapeDataString
Format
IndexOf
Buffer
BlockCopy
SetEnvironmentVariable
GetDirectoryName
Equals
Initialize
ToInt16
Unescape
get_KeySize
get_IV
Create
ToCharArray
get_Success
Collect
EscapeDataString
set_MaxJsonLength
Serialize
OpenRead
Reverse
CompareTo
Compare
Subtract
Multiply
ToUInt64
get_BigEndianUnicode
ToUInt16
TrimStart
AppendFormat
AppendLine
KeyedHashAlgorithm
get_HashSize
FreeHGlobal
AllocHGlobal
GetFileName
CopyTo
GetLastAccessTime
get_InvariantCulture
GetUpperBound
GetLowerBound
get_OSFullName
GetPropertyValue
get_TotalPhysicalMemory
ToDouble
get_ExecutablePath
get_Millisecond
CredentialCache
get_DefaultCredentials
set_Credentials
set_KeepAlive
set_Timeout
set_AllowAutoRedirect
set_MaximumAutomaticRedirections
set_Method
set_UserAgent
GetResponse
get_StatusDescription
GetResponseStream
RandomNumberGenerator
get_FormatID
get_Guid
GetImageEncoders
get_ProcessName
get_Id
GetProcessesByName
GetInstances
get_Properties
get_PrimaryScreen
get_Bounds
get_Param
get_Jpeg
FromImage
get_Width
get_Height
CopyFromScreen
set_ContentLength
GetRequestStream
get_Name
ToByteArray
ToSingle
FromFileTimeUtc
StringToHGlobalUni
GetProcesses
get_HandleCount
GetLogicalDrives
LastIndexOf
ReadInt64
SerializeObject
get_UtcDateTime
set_CommentHandling
set_LineInfoHandling
IsNullOrWhiteSpace
TryParse
IsWellFormedUriString
get_Scheme
IsMatch
ConfigurationManager
System.Configuration
get_AppSettings
ToUpperInvariant
HostingEnvironment
System.Web.Hosting
get_ApplicationPhysicalPath
get_Type
get_Message
GetFrames
GetFileLineNumber
get_UtcNow
ToUniversalTime
get_TotalSeconds
NewGuid
get_Items
CallContext
System.Runtime.Remoting.Messaging
LogicalGetData
get_TotalMilliseconds
get_InnerException
GetBaseException
get_IsHosted
get_Handler
get_Request
get_User
get_Identity
add_Error
get_Server
op_Implicit
GetNonZeroBytes
get_Response
AppendToLog
get_ServerVariables
RouteTable
get_Routes
GetRouteData
get_Route
get_Url
get_DataTokens
AddMinutes
op_GreaterThan
get_Ticks
get_Kind
get_IsPrimitive
get_BaseType
FromObject
get_IsArray
get_ContainsGenericParameters
Children
get_CurrentDomain
GetAssemblies
set_NullValueHandling
set_ReferenceLoopHandling
set_Converters
IsAssignableFrom
JContainer
WriteTo
get_UserInfo
set_UseDefaultCredentials
FromSeconds
op_LessThan
AddSeconds
get_TotalMinutes
get_Factory
get_StatusCode
get_ResponseUri
get_Headers
set_ContentType
get_Is64BitOperatingSystem
OpenBaseKey
TextWriter
IsLetterOrDigit
IsPunctuation
GetEncoding
get_MachineName
FromMinutes
get_CharacterSet
get_FriendlyName
get_UserInteractive
get_BaseDirectory
get_ApplicationVirtualPath
get_Data
get_Errors
get_Number
GetHRForException
get_TargetSite
get_ReflectedType
InvokeMember
get_CurrentThread
get_ManagedThreadId
get_RequestType
get_UserHostAddress
get_UserAgent
get_IsSecureConnection
get_AppRelativeCurrentExecutionFilePath
get_QueryString
get_Cookies
get_Form
get_Session
get_AllKeys
Change
Exchange
Increment
FindServicePoint
set_ConnectionLimit
GetHashCode
ResolveType
get_ManifestModule
CompilerGeneratedAttribute
STAThreadAttribute
FlagsAttribute
SecuritySafeCriticalAttribute
SuppressUnmanagedCodeSecurityAttribute
ReliabilityContractAttribute
System.Runtime.ConstrainedExecution
Consistency
ParamArrayAttribute
ObsoleteAttribute
JsonObjectAttribute
JsonIgnoreAttribute
JsonPropertyAttribute
DebuggerHiddenAttribute
UnmanagedFunctionPointerAttribute
CallingConvention
CharSet
748a5d90-36e3-4d6d-b692-0a0b498b5bd8.g.resources
aR3nbf8dQp2feLmk31.lSfgApatkdxsVcGcrktoFd.resources
WrapNonExceptionThrows
1.0.0.0
$097af8b6-8a49-43cf-a22b-891660b8028a
Use StackifyLib.Config instead
Just used for testing
Use CanQueue instead
`1[[System.Object, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089]][]
SUsSystem.Runtime.InteropServices.CharSet, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089
CharSet
RV)'DA\7
(L)-'A
69pbG#
y%PK4[5$Z9
j%M#n9.
gRY!'WC2
&f#la~>
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
PADPADP
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
fSystem.Drawing.Icon, System.Drawing, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3ajSystem.CodeDom.MemberAttributes, System, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089mSystem.Globalization.CultureInfo, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089fSystem.Drawing.Size, System.Drawing, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a
QSystem.Drawing, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a
System.Drawing.Icon
IconData
IconSize
System.Drawing.Size
System.Drawing.Size
height
ISystem, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089
System.CodeDom.MemberAttributes
value__
System.Globalization.CultureInfo
m_isReadOnly
compareInfo
textInfo
numInfo
dateTimeInfo
calendar
m_dataItem
cultureID
m_name
m_useUserOverride
System.Globalization.CompareInfo
System.Globalization.TextInfo%System.Globalization.NumberFormatInfo'System.Globalization.DateTimeFormatInfo
System.Globalization.Calendar
System.Globalization.CompareInfo
m_name
win32LCID
culture
m_SortVersion
System.Globalization.SortVersion
System.Globalization.TextInfo
m_listSeparator
m_isReadOnly
m_cultureName
customCultureName
m_nDataItem
m_useUserOverride
m_win32LangID
%System.Globalization.NumberFormatInfo"
numberGroupSizes
currencyGroupSizes
percentGroupSizes
positiveSign
negativeSign
numberDecimalSeparator
numberGroupSeparator
currencyGroupSeparator
currencyDecimalSeparator
currencySymbol
ansiCurrencySymbol
nanSymbol
positiveInfinitySymbol
negativeInfinitySymbol
percentDecimalSeparator
percentGroupSeparator
percentSymbol
perMilleSymbol
nativeDigits
m_dataItem
numberDecimalDigits
currencyDecimalDigits
currencyPositivePattern
currencyNegativePattern
numberNegativePattern
percentPositivePattern
percentNegativePattern
percentDecimalDigits
digitSubstitution
isReadOnly
m_useUserOverride
m_isInvariant
validForParseAsNumber
validForParseAsCurrency
Infinity
-Infinity
QSystem.Drawing, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a
System.Drawing.Size
height
com.apple.Safari
Unable to resolve HTTP prox
DBRfhn M
_CorExeMain
mscoree.dll
wxr""/p
wr""/p
ozR1ML
oLLLLL
wwwwwwwxp
"""""/
"""""/
wwwwwwww
zz1111MMM
^zz1111MM
^zz1111M
^zz1111
^zz111
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<assemblyIdentity version="1.0.0.0" name="MyApplication.app"/>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v2">
<security>
<requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3">
<requestedExecutionLevel level="asInvoker" uiAccess="false"/>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<assemblyIdentity
name="JR.Inno.Setup"
processorArchitecture="x86"
version="1.0.0.0"
type="win32"/>
<description>Inno Setup</description>
<dependency>
<dependentAssembly>
<assemblyIdentity
type="win32"
name="Microsoft.Windows.Common-Controls"
version="6.0.0.0"
processorArchitecture="x86"
publicKeyToken="6595b64144ccf1df"
language="*"
/>
</dependentAssembly>
</dependency>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v3">
<security>
<requestedPrivileges>
<requestedExecutionLevel level="asInvoker" uiAccess="false"/>
</requestedPrivileges>
</security>
</trustInfo>
<application xmlns="urn:schemas-microsoft-com:asm.v3">
<windowsSettings>
<dpiAware xmlns="http://schemas.microsoft.com/SMI/2005/WindowsSettings">true</dpiAware>
</windowsSettings>
</application>
<compatibility xmlns="urn:schemas-microsoft-com:compatibility.v1">
<application>
<supportedOS Id="{e2011457-1546-43c5-a5fe-008deee3d3f0}"/>
<supportedOS Id="{35138b9a-5d96-4fbd-8e2d-a2440225f93a}"/>
</application>
</compatibility>
</assembly>
pp p!p"p#p$p%p&p'p(p)p*p+p,p-p.p/p0p1p2p3p4p5p6p7p8p9p:p;p<p=p>p?p@pApDpEpFpGpHpKpfq|q
BACAIHJHQPVUWUXU\[cbedfdgdhdidjdml
yyyy_MM_dd_HH_mm_ss
/log.tmp
<html>
</html>
yyyy-MM-dd HH:mm:ss
<br>OSFullName:
<br>User Name:
IP Address:
<br>Computer Name:
Time:
<br>CPU:
<br>RAM:
MM/dd/yyyy HH:mm:ss
OSFullName:
User Name:
Recovered!
Time:
HLfnPH
HLfnPH.exe
boygirl123456
https://api.ipify.org
adm@lemendoza.com
appdata
Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:99.0) Gecko/20100101 Firefox/99.0
ftp://ftp.lemendoza.com
]</b> (
{KEYRIGHT}
{KEYDOWN}
{CAPSLOCK}
{Insert}
{ENTER}
{PageUp}
{NumLock}
{KEYUP}
{ALT+F4}
{KEYLEFT}
{BACK}
{PageDown}
control
{CTRL}
{HOME}
{ALT+TAB}
&quot;
<br><hr>Copied Text: <br>
logins
IE/Edge
2F1A6504-0641-44CF-8BB5-3612D865F2E5
Windows Secure Note
3CCD5499-87A8-4B10-A215-608888DD3B55
Windows Web Password Credential
154E23D0-C644-4E6F-8CE6-5069272F999F
Windows Credential Picker Protector
4BF4C442-9B8A-41A0-B380-DD4A704DDB28
Web Credentials
77BC582B-F0A6-4E15-4E80-61736B6F3B29
Windows Credentials
E69D7838-91B5-4FC9-89D5-230D4D4CC2BC
Windows Domain Certificate Credential
3E0E35BE-1B77-43E7-B873-AED901B6275B
Windows Domain Password Credential
3C886FF3-2669-4AA2-A8FB-3F6759A77548
Windows Extended Credential
00000000-0000-0000-0000-000000000000
SchemaId
pResourceElement
pIdentityElement
pPackageSid
pAuthenticatorElement
UC Browser
UCBrowser\
Login Data
journal
wow_logins
Safari for Windows
\Common Files\Apple\Apple Application Support\plutil.exe
\Apple Computer\Preferences\keychain.plist
<dict>
<string>
</string>
<data>
</data>
<array>
-convert xml1 -s -o "
\fixed_keychain.xml"
\Microsoft\Credentials\
\Microsoft\Protect\
credential
QQ Browser
Profile
\Default\EncryptedStorage
\EncryptedStorage
Tencent\QQBrowser\User Data
entries
category
Password
password_value
IncrediMail
SmtpPassword
PopPassword
Software\IncrediMail\Identities\
\Accounts_New
SmtpServer
EmailAddress
Eudora
Software\Qualcomm\Eudora\CommandLine\
current
Settings
SavePasswordText
ReturnAddress
Falkon Browser
startProfile=([A-z0-9\/\.\"]+)
profiles.ini
\browsedata.db
autofill
\falkon\profiles\
ClawsMail
\Claws-mail
\clawsrc
passkey0
master_passphrase_salt=(.+)
master_passphrase_pbkdf2_rounds=(.+)
\accountrc
smtp_server
address
account
\passwordstorerc
{(.*),(.*)}(.*)
Flock Browser
APPDATA
\Flock\Browser\
signons3.txt
DynDns
username=
https://account.dyn.com/
ALLUSERSPROFILE
Dyn\Updater\config.dyndns
password=
t6KzXhCh
Dyn\Updater\daemon.cfg
global
accounts
account.
username
password
Psi/Psi+
\Psi+\profiles
\accounts.xml
\Psi\profiles
OpenVPN
Software\OpenVPN-GUI\configs
Software\OpenVPN-GUI\configs\
auth-data
entropy
USERPROFILE
\OpenVPN\config\
remote
NordVPN
NordVpn.exe*
user.config
//setting[@name='Username']/value
//setting[@name='Password']/value
Private Internet Access
ProgramFiles(x86)
\Private Internet Access\data
%ProgramW6432%
Private Internet Access\data
\account.json
.*"username":"(.*?)"
.*"password":"(.*?)"
privateinternetaccess.com
FileZilla
\FileZilla\recentservers.xml
<Server>
<Host>
</Host>
<Port>
</Port>
<User>
</User>
<Pass encoding="base64">
</Pass>
<Pass>
CoreFTP
SOFTWARE\FTPWare\COREFTP\Sites
hdfzpysvpzimorhk
WinSCP
SOFTWARE\Martin Prikryl\WinSCP 2\Sessions
HostName
UserName
PublicKeyFile
PortNumber
[PRIVATE KEY LOCATION: "{0}"]
ABCDEF
Flash FXP
\FlashFXP\
Sites.dat
quick.dat
yA36zA48dEhfrvghGRg57h5UlDv3
FTP Navigator
SystemDrive
\FTP Navigator\Ftplist.txt
Server
No Password
SmartFTP
SmartFTP\Client 2.0\Favorites\Quick Connect
WS_FTP
Ipswitch\WS_FTP\Sites\ws_ftp.ini
FtpCommander
;User=
;Anonymous=
;Password=
;Server=
;Port=
\VirtualStore\Program Files (x86)\FTP Commander\Ftplist.txt
\VirtualStore\Program Files (x86)\FTP Commander Deluxe\Ftplist.txt
\Program Files (x86)\FTP Commander\Ftplist.txt
\Program Files (x86)\FTP Commander Deluxe\Ftplist.txt
\cftp\Ftplist.txt
FTPGetter
<server>
\FTPGetter\servers.xml
<server_ip>
</server_ip>
<server_port>
</server_port>
<server_user_name>
</server_user_name>
<server_user_password>
</server_user_password>
The Bat!
\The Bat!
\Account.CFN
=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=
+-0123456789ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz
Becky!
HKEY_CURRENT_USER\Software\RimArts\B2\Settings
DataDir
Folder.lst
\Mailbox.ini
Account
PassWd
SMTPServer
MailAddress
Outlook
9375CFF0413111d3B88A00104B2A6676
Software\Microsoft\Office\11.0\Outlook\Profiles
Software\Microsoft\Office\12.0\Outlook\Profiles
Software\Microsoft\Office\14.0\Outlook\Profiles
Software\Microsoft\Office\15.0\Outlook\Profiles
Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles
Software\Microsoft\Windows Messaging Subsystem\Profiles\9375CFF0413111d3B88A00104B2A6676
Software\Microsoft\Office\16.0\Outlook\Profiles
IMAP Password
POP3 Password
HTTP Password
SMTP Password
Server
Windows Mail App
Software\Microsoft\ActiveSync\Partners
syncpassword
mailoutgoing
COMPlus_legacyCorruptedStateExceptionsPolicy
FoxMail
HKEY_CURRENT_USER\Software\Aerofox\FoxmailPreview
Executable
HKEY_CURRENT_USER\Software\Aerofox\Foxmail\V3.1
FoxmailPath
\Storage\
\VirtualStore\Program Files\Foxmail\mail
\VirtualStore\Program Files (x86)\Foxmail\mail
\Accounts\Account.rec0
\Account.stg
POP3Host
SMTPHost
IncomingServer
POP3Password
Opera Mail
\Opera Mail\Opera Mail\wand.dat
opera:
ijklmno
vwxyz1234567890_-.~!@#$%^&*()[{]}\|';:,<>/?+=
PocoMail
\Pocomail\accounts.ini
POPPass
SMTPPass
eM Client
eM Client\accounts.dat
Accounts
"Username":"
"Secret":"
72905C47-F4FD-4CF7-A489-4E8121A155BD
"ProviderName":"
o6806642kbM7c5
Mailbird
SenderIdentities
Server_Host
Username
EncryptedPassword
\Mailbird\Store\Store.db
RealVNC 3.x
Software\ORL\WinVNC3
TightVNC
Software\TightVNC\Server
SOFTWARE\RealVNC\vncserver
TigerVNC
Software\TigerVNC\Server
RealVNC 4.x
SOFTWARE\Wow6432Node\RealVNC\WinVNC4
SOFTWARE\RealVNC\WinVNC4
PasswordViewOnly
TightVNC ControlPassword
ControlPassword
UltraVNC
\uvnc bvba\UltraVNC\ultravnc.ini
passwd
passwd2
ProgramFiles
\UltraVNC\ultravnc.ini
JDownloader 2.0
JDownloader 2.0\cfg
org.jdownloader.settings.AccountSettings.accounts.ejs
jd.controlling.authentication.AuthenticationControllerSettings.list.ejs
Paltalk
Software\A.V.M.\Paltalk NG\common_settings\core\users\creds\
nickname
paltalk.com
Pidgin
\.purple\accounts.xml
<account>
<protocol>
</protocol>
<name>
</name>
<password>
</password>
Trillian
\Trillian\users\global\accounts.dat
trillian.im
MysqlWorkbench
\MySQL\Workbench\workbench_user_data.dat
Internet Downloader Manager
Software\DownloadManager\Passwords\
EncPassword
Discord
discord.com
Discord Token
[\w-]{24}\.[\w-]{6}\.[\w-]{27}
mfa\.[\w-]{84}
Local Storage\leveldb
discordcanary
discordptb
origin_url
username_value
Opera Stable
\Local State
"encrypted_key":"(.*?)"
\Login Data
\Default\Login Data
key3.db
key4.db
2a864886f70d0209
2a864886f70d010c050103
metaData
nssPrivate
global-salt
Version
password-check
Path=([A-z0-9\/\.\-]+)
\"(hostname|encryptedPassword|encryptedUsername)":"(.*?)"
logins.json
[^\u0020-\u007F]
signons.sqlite
moz_logins
hostname
encryptedUsername
encryptedPassword
Application:
Password:
Username:
Host:
<br><hr>
<br>Application:
<br>Username:
<br>Password:
7Star\7Star\User Data
BraveSoftware\Brave-Browser\User Data
Kometa
Kometa\User Data
Cool Novo
MapleStudio\ChromePlus\User Data
K-Meleon
\K-Meleon\
Chromium
Chromium\User Data
Coccoc
CocCoc\Browser\User Data
Sputnik
Sputnik\Sputnik\User Data
Thunderbird
\Thunderbird\
uCozMedia\Uran\User Data
Yandex Browser
Yandex\YandexBrowser\User Data
Vivaldi
Vivaldi\User Data
SeaMonkey
\Mozilla\SeaMonkey\
CyberFox
\8pecxstudios\Cyberfox\
Liebao Browser
liebao\User Data
Comodo Dragon
Comodo\Dragon\User Data
Torch Browser
Torch\User Data
Firefox
\Mozilla\Firefox\
Orbitum
Orbitum\User Data
Chedot
Chedot\User Data
Amigo\User Data
Sleipnir 6
Fenrir Inc\Sleipnir5\setting\modules\ChromiumViewer
Citrio
CatalinaGroup\Citrio\User Data
Chrome
Google\Chrome\User Data
Iridium Browser
Iridium\User Data
Postbox
\Postbox\
BlackHawk
\NETGATE Technologies\BlackHawk\
IceDragon
\Comodo\IceDragon\
IceCat
\Mozilla\icecat\
QIP Surf
QIP Surf\User Data
CentBrowser
CentBrowser\User Data
Opera Browser
Opera Software\Opera Stable
Epic Privacy
Epic Privacy Browser\User Data
360 Browser
360Chrome\Chrome\User Data
Edge Chromium
Microsoft\Edge\User Data
Coowon
Coowon\Coowon\User Data
PaleMoon
\Moonchild Productions\Pale Moon\
WaterFox
\Waterfox\
Elements Browser
Elements Browser\User Data
Berkelet DB
Unknow database format
1.85 (Hash, version 2, native byte-order)
00000002
00061561
SQLite format 3
UNIQUE
{0:X2}
SEQUENCE {
INTEGER
OBJECTIDENTIFIER
OCTETSTRING
Windows Credential
{{{0}}}
chrome
policy
sha512
AuthTagLength
ChainingModeGCM
ChainingMode
Microsoft Primitive Provider
KeyDataBlob
ObjectLength
:Zone.Identifier
SELECT * FROM Win32_Processor
processorID
win32_processor
6e586704-38cb-4658-b128-b7d9fa081fec
Win32_NetworkAdapterConfiguration
MacAddress
IPEnabled
657b0bdb-ae1f-44ea-951e-2870f7a22244
Win32_BaseBoard
SerialNumber
3024d634-31df-4e0d-b8bf-062ccddac12f
FormatID: {0}
Version: 0x{0:X}
StorageSize: {0} (0x{0:X})
Version is not equal to {0} ({1})
Size of the SerializedPropertyStore is less than {0} ({1})
Size of the SerializedPropertyStorage is less than 28 ({0})
{D5CDD505-2E9C-101B-9397-08002B2CF9AE}
Type: {0}
Value: {0}
ValueSize: {0} (0x{0:X})
NameSize: {0} (0x{0:X})
Name: {0}
Size of the StringName is less than 9 ({0})
Size of the NameSize is not equal to {0} ({1})
Size of the StringName is not equal to {0} ({1})
ID: 0x{0:X}
Size of the SerializedPropertyStore is less than 8 ({0})
StoreSize: {0} (0x{0X})
\Device\LanmanRedirector\
Failed to retrieve system handle information.
API/Device/GetAll
Unable to evaluate current device id
API/Device/SetServerEnvironmentByID/?id=
&environmentName=
API/Device/RemoveServerByID/?id=
&uninstallAgent=
API/Device/RemoveServerByName/?name=
API/Device/UninstallAgentByID/?id=
API/Device/UninstallAgentByName/?name=
API/Device/ConfigureAlerts
API/Device/Monitors/
API/Device/MonitorMetrics/
?monitorID={0}&startDateUtc={1}&endDateUtc={2}&pointSizeInMinutes={3}
cookie,authorization
.ASPXAUTH
#Config #LoadSettings StackifyAPILogger.EvaluateLogEnabled failed
Stackify.EnableCleanName
Stackify.IsEC2
Stackify.CaptureErrorCookiesBlacklist
Stackify.CaptureErrorHeaders
Stackify.CaptureErrorCookies
Stackify.Logging.JsonMaxFields
Stackify.Ec2InstanceMetadataUpdateThresholdMinutes
Stackify.CaptureServerVariables
Stackify.CaptureErrorUserName
Stackify.CaptureErrorCookiesWhitelist
Stackify.ApiLog
#Config - LoadSettings - Stackify JSON Loaded
Stackify.CaptureErrorHeadersBlacklist
Stackify.CaptureErrorPostdata
Stackify.Rum_Script_Url
https://stckjs.stackify.com/stckjs.js
^[A-Za-z0-9_-]+$
Stackify.Rum_Key
Stackify.CaptureSessionVariables
#Config - LoadSettings - Stackify JSON - Read
Stackify.CaptureErrorSessionWhitelist
Stackify.CaptureErrorHeadersWhitelist
Stackify.ApiKey
Stackify.AppName
Stackify.Environment
#Config #LoadSettings failed
EnvUpperLinux
RETRACE_
Stackify.
EnvUpperLinuxRetrace
AppSettings
EnvUpper
#Config - #Get - Section:
- Key:
- Value:
#Config - #Get - #Failed
ASPNETCORE_ENVIRONMENT
Stackify.json
#Config #Json Load - Path:
DOTNET_ENVIRONMENT
#Config #ReadStackifyJSONConfig failed
ApiKey
#Config #Json #SetStackifyObj Load - AppName:
- Environment:
- ApiKey:
AppName
Environment
#Config #TryGetValue #Json failed - Property is null or empty - Property:
#Config #TryGetValue #Json failed - Property is not a string - Property:
#Config #TryGetValue #Json Success - Key:
#Config #TryGetValue #Json failed
#Extensions #SendToStackify failed
#Extensions #NewStackifyError failed
StackifyLib.net
Logger Shutdown called
#errorgoverned
Unable to send log because the queue is full
Stackify-RequestID
#ProfileTracer ctor
Stackify.ReportingUrl
#ProfileTracer #SetReportingUrl
Tracked Function
Not sending error because it is being ignored. Error Type:
context
Unhandled Web Exception
<script type="text/javascript" nonce="{3}">(window.StackifySettings || (window.StackifySettings = {0}))</script><script src="{1}" data-key="{2}" async></script>
&ResolvedRoute={
StackifyAppendToLogSet
Error Appending route to IIS log
ROUTE_PATTERN
ROUTE_ACTION
ROUTE_AREA
ROUTE_CONTROLLER
controller
action
Error resolving route
System.Threading.Tasks.AsyncCausalityTracer
f_LoggingOn
Unable to enable the AsyncCausalityTracer, class not found
Unable to enable the AsyncCausalityTracer, f_LoggingOn field not found
Boolean
EnsureAsyncTracer Exception:
{0}-{1}-{2}
log4net.Util.SystemStringFormat
logArg
String
AnonymousType
System.Collections.Generic.Dictionary
objectType
invalid
message
/{guid}
RequestId
Error figuring out TransID
E2ETrace.ActivityID
Request not available
REPORTING_URL
Stackify.Agent.Threading.StackifyCallContext
Stackify.Agent.Configuration.AgentConfig
TraceContext
get_Item
{cf0d821e-299b-5307-a3d8-b283c03916da}
COR_ENABLE_PROFILING
COR_PROFILER
{email}
{guid}
^(25[0-5]|2[0-4][0-9]|[01]?[0-9][0-9]?)\.(25[0-5]|2[0-4][0-9]|[01]?[0-9][0-9]?)\.(25[0-5]|2[0-4][0-9]|[01]?[0-9][0-9]?)\.(25[0-5]|2[0-4][0-9]|[01]?[0-9][0-9]?)$
^(?i)(\b[A-F0-9]{8}(?:-[A-F0-9]{4}){3}-[A-F0-9]{12}\b)$
^(\d+)$
System.Object[]
^((([!#$%&'*+\-/=?^_`{|}~\w])|([!#$%&'*+\-/=?^_`{|}~\w][!#$%&'*+\-/=?^_`{|}~\.\w]{0,}[!#$%&'*+\-/=?^_`{|}~\w]))[@]\w+([-.]\w+)*\.\w+([-.]\w+)*)$
Module
Method
Assembly
Stackify.Agent,
Stackify.ApiUrl
https://api.stackify.com/
Stackify.ProxyServer
Stackify.ProxyUseDefaultCredentials
Setting proxy server based on override config
Error setting default web proxy
Skipping IdentifyApp(). No APIKey configured.
Calling to Identify App
Metrics/IdentifyApp
IdentifyApp() HTTP Response Error:
Missing url or api key
Preventing API call due to unauthorized error
unauthorized
Send to
unable to send. Missing url or api key
GetResponseString HTTP Response:
, Took:
HTTP Response Error:
application/json
X-Stackify-Key
StackifyLib-
application/x-www-form-urlencoded
WEBSITE_IIS_SITE_NAME
stackifytracerservice
stackifymonitoringservice
stackifytracernotifier
devdashtestconsole
devdashservice
monitortestconsole
.vshost
StackifyPath
WEBSITE_INSTANCE_ID
prefix
devdash
Production
{0:yyyy/MM/dd HH:mm:ss,fff}/GMT StackifyLib: {1}
API Logger is enabled
API Logger is disabled
ISO-8859-8
Unable to load azure runtime
WEBSITE_SITE_NAME
#Azure #GetDeploymentSlotId failed
SOFTWARE\Microsoft\Windows Azure\Deployments
Error seeing if the app is an azure cloud service
STACKIFY_DEVICE_NAME
http://169.254.169.254/latest/meta-data/instance-id
select DisplayName from Win32_Service WHERE ProcessID='
DisplayName
Unable to get windows service name
Error figuring out app environment details
/LM/W3SVC/(?<siteid>[\d]+)/ROOT/(?<appname>.+)-[0-9]{1,3}-[\d]{2,}$
W3SVC_{0}_ROOT_{1}
siteid
appname
W3SVC_{0}_ROOT
/LM/W3SVC/(?<siteid>[\d]+)/ROOT-[0-9]{1,3}-[\d]{2,}$
RdRuntime
approot
Server:
Unknown
FormatNameAndSig
---> {0}: {1}
{0}: {1}
at {0}
--- End of inner exception stack trace ---
{0}-{1}-{2}-{3:s}
Missing Name
Missing Category
all_http
all_raw
http_cookie
authorization
cookie
X-MASKED-X
Creating default value for
No longer queuing new metrics because more than 100000 are queued
Creating aggregate for
No longer aggregating new metrics because more than 1000 are queued
Error in StackifyLib with aggregating metrics
ReadAllQueuedMetrics {0}
Read queued metrics processed {0} for max date {1}
Read queued metrics reset increment {0} to zero due to min/max value of {1}
Calling UploadMetrics {0}
Metrics processing canceled because stop was requested
Upload metrics check
StopMetricsQueue called by
StopMetricsQueue completed
StopMetricsQueue error {0}
Upload metrics skipped because we were unable to match the app to an app in Stackify
Upload metrics skipped authorization failure
Upload metrics skipped and delayed due to recent error
Error adding metrics back to upload list {0}
Error uploading metrics {0}
Error purging metrics {0}
Uploading Aggregate Metrics: {0}
{0}-{1}
Unable to get metric info for
MonitorID is null
Metric info missing for
Metrics not uploaded. Identify Result: {0}, Metrics API Enabled: {1}
Uploading metric {0}:{1} Count {2}, Value {3}, ID {4}
Metrics/SubmitMetricsByID
Error saving metrics
Error saving metrics {0}
Metrics/GetMetricInfo
Error getting monitor info {0}
Creating new LogClient
default
/LM/W3SVC
Trying to SendLogs
Unable to send logs at this time. Unable to identify app
Unable to send logs at this time due to recent error:
Log/SaveMultipleGroups
Sending
log messages via send multi groups
Creating new LogQueue
#LogQueue #QueueLogMessage failed
#LogQueue #OnTimer failed
#LogQueue Adjust log flush interval down to {0:0.00} seconds
#LogQueue Adjust log flush interval up to {0:0.00} seconds
#LogQueue #FlushLoop failed
#LogQueue Not requeueing log messages due to client error:
StackifyLib:
Requeueing log messages due to error:
#LogQueue Some messages not queued again due to too many failures uploading
#LogQueue Error trying to requeue messages
#LogQueue #FlushOnce failed
#LogQueue stop complete
#LogQueue stop received
#LogQueue #EnqueueForRetransmission failed
System.Core, Version=3.5.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089
System.Security.Cryptography.AesCryptoServiceProvider
{11111-22222-10009-11111}
{11111-22222-10009-11112}
{11111-22222-50001-00000}
GetDelegateForFunctionPointer
file:///
Location
ResourceA
Virtual
Write
Process
Memory
Protect
Process
Close
Handle
kernel
32.dll
{11111-22222-10001-00001}
{11111-22222-10001-00002}
{11111-22222-20001-00001}
{11111-22222-20001-00002}
{11111-22222-30001-00001}
{11111-22222-30001-00002}
{11111-22222-40001-00001}
{11111-22222-40001-00002}
{11111-22222-50001-00001}
{11111-22222-50001-00002}
Accounts
logins
sha512
credential
Unknown
$this.SnapToGrid
$this.TrayLargeIcon
$this.Icon
$this.Locked
$this.DrawGrid
progressBar1.Modifiers
$this.Localizable
$this.Language
$this.GridSize
$this.TrayHeight
progressBar1.Locked
MAINICON
VS_VERSION_INFO
StringFileInfo
000004b0
Comments
This installation was built with Inno Setup.
CompanyName
Aldaray
FileDescription
Rummage Setup
FileVersion
LegalCopyright
2010 Aldaray Ltd
ProductName
Rummage
ProductVersion
3.1.1099 (5158)
VarFileInfo
Translation
Antivirus Signature
Bkav Clean
Lionic Trojan.Win32.Generic.mBxM
tehtris Generic.Malware
DrWeb Clean
MicroWorld-eScan IL:Trojan.MSILZilla.30717
ClamAV Win.Packed.Msilperseus-9956591-0
FireEye Generic.mg.15909167c6a12575
CAT-QuickHeal Clean
Skyhigh BehavesLike.Win32.Infected.bm
McAfee RDN/agenttesla
Cylance unsafe
VIPRE IL:Trojan.MSILZilla.30717
Sangfor Suspicious.Win32.Save.a
K7AntiVirus Clean
BitDefender IL:Trojan.MSILZilla.30717
K7GW Clean
CrowdStrike win/malicious_confidence_100% (W)
Arcabit IL:Trojan.MSILZilla.D77FD
BitDefenderTheta Gen:NN.ZemsilF.36608.Wm0@aa7w@kmi
VirIT Trojan.Win32.MSIL_Heur.A
Symantec ML.Attribute.HighConfidence
Elastic malicious (high confidence)
ESET-NOD32 a variant of MSIL/Spy.AgentTesla.K
APEX Malicious
Paloalto Clean
Cynet Malicious (score: 100)
Kaspersky HEUR:Trojan-PSW.MSIL.Agensla.gen
Alibaba Clean
NANO-Antivirus Clean
ViRobot Clean
Rising Spyware.AgentTesla!8.10E35 (CLOUD)
Sophos Mal/Generic-S
F-Secure Trojan.TR/AgentTesla.xbdrv
Baidu Clean
Zillya Clean
TrendMicro Clean
Trapmine Clean
CMC Clean
Emsisoft IL:Trojan.MSILZilla.30717 (B)
Ikarus Trojan.Agent
Jiangmin Clean
Webroot W32.Trojan.MSILZilla
Google Detected
Avira TR/AgentTesla.xbdrv
MAX malware (ai score=84)
Antiy-AVL Clean
Kingsoft Win32.PSWTroj.Undef.a
Gridinsoft Trojan.Win32.Packed.sa
Xcitium Clean
Microsoft Trojan:Win32/Znyonm
SUPERAntiSpyware Clean
ZoneAlarm HEUR:Trojan-PSW.MSIL.Agensla.gen
GData MSIL.Trojan-Stealer.BatStealer.A
Varist W32/ABRisk.DRCA-5675
AhnLab-V3 Infostealer/Win.AgentTesla.C5555985
Acronis Clean
VBA32 Trojan.MSIL.InfoStealer.gen.D
ALYac IL:Trojan.MSILZilla.30717
TACHYON Clean
DeepInstinct MALICIOUS
Malwarebytes Trojan.Crypt
Panda Trj/Chgt.AD
Zoner Clean
TrendMicro-HouseCall TROJ_GEN.R002H09KS23
Tencent Msil.Trojan-QQPass.QQRob.Swhl
Yandex Clean
SentinelOne Static AI - Malicious PE
MaxSecure Trojan.Malware.300983.susgen
Fortinet Clean
AVG Win32:PWSX-gen [Trj]
Cybereason malicious.d549e0
Avast Win32:PWSX-gen [Trj]
No IRMA results available.