Static | ZeroBOX

PE Compile Time

2022-06-20 18:33:40

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x0004f524 0x0004f600 5.80837896676
.rsrc 0x00052000 0x00000616 0x00000800 3.50167887866
.reloc 0x00054000 0x0000000c 0x00000200 0.101910425663

Resources

Name Offset Size Language Sub-language File type
RT_VERSION 0x000520a0 0x0000038c LANG_NEUTRAL SUBLANG_NEUTRAL PGP symmetric key encrypted data - Plaintext or unencrypted data
RT_MANIFEST 0x0005242c 0x000001ea LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with CRLF line terminators

Imports

Library mscoree.dll:
0x402000 _CorExeMain

!This program cannot be run in DOS mode.
`.rsrc
@.reloc
https://github.com/LimerBoy/StormKitty
Y_dh}
_b}V
_b}^
X_b}y
c_X0
jZXi}|
b.:+@r|)
-HsI
UUUU_
d UUUU_`
3333_
d 3333_`
%ry^
%0r#_
%1r-_
% r=u
%"r]u
%,r?v
%.rUv
Y_c
Y_c
KDBM(
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
PADPADP
v4.0.30319
#Strings
,1OXg
% Q i r
"&"/"4"U"b"i"n"s"{"
#'#1#D#I#U#\#i#v#
$&$+$2$E$u$
%"%,%5%F%M%e%
&&A&[&w&
'&','Y'_'e'm'~'
)#))).)4):)A)S)r)
+?+O+^+
,-,L,[,c,l,
//%/-/5/</C/J/R/[/e/l/q/|/
/00^0t0
2;3`3l3v3
3O4X4m4t4~4
5A5G5Y5`5e5w5
676?6H6[6g6
7-7M7Z7~7
:$:::K:[:j:~:
;;&;?;J;h;
<)<^<u<{<
7$7<7D7v7
__StaticArrayInitTypeSize=10
REPZ_3_10
__StaticArrayInitTypeSize=120
4D53392A6A24D5E801ADA14E79B43F9BEBB79150
<>9__0_0
<Main>b__0_0
<GetDomainDetect>b__0_0
<>c__DisplayClass0_0
<>9__2_0
<DirectorySize>b__2_0
<GetDefaultGateway>b__2_0
<>c__DisplayClass253_0
<>c__DisplayClass255_0
<>c__DisplayClass177_0
<>9__7_0
<GetAllProfiles>b__7_0
<ProcessExtraFieldZip64>b__0
<get_EntriesSorted>b__0
<ProcessExtraFieldUnixTimes>b__0
<Start>b__0
Level0
1B180C6E41F096D53222F5E8EF558B78182CA401
61951014FB17C5BF74F45401CA5C6D4C7205CF11
2E868D9F2085DF93F11F58DE61C05E0D8A8F4A71
5581A70566F03554D8048EDBFC6E6B399AF9BCB1
CHECK1
<>9__0_1
<Main>b__0_1
<GetDomainDetect>b__0_1
<>9__2_1
<DirectorySize>b__2_1
<GetDefaultGateway>b__2_1
<Start>b__1
<>s__1
Func`1
Nullable`1
IEnumerable`1
Queue`1
Stack`1
ICollection`1
ReadOnlyCollection`1
Comparison`1
EventHandler`1
IEqualityComparer`1
IEnumerator`1
HashSet`1
List`1
NotUsed1
iso8859dash1
Level1
InfoZip1
doubleDotRegex1
<>m__Finally1
__StaticArrayInitTypeSize=512
__StaticArrayInitTypeSize=12
get_Crc32
FigureCrc32
_InternalComputeCrc32
actualCrc32
GetCrc32
Microsoft.Win32
get_Adler32
ToUInt32
ToInt32
SteamPath_x32
__StaticArrayInitTypeSize=1152
AesAlgId192
CHECK2
<>9__0_2
<Main>b__0_2
<GetDomainDetect>b__0_2
<>9__2_2
<GetDefaultGateway>b__2_2
<e>5__2
Func`2
KeyValuePair`2
IDictionary`2
Level2
input2
3544182260B8A15D332367E48C7530FC0E901FD3
CHECK3
<>9__0_3
<Main>b__0_3
<>9__2_3
<GetDefaultGateway>b__2_3
Level3
850D4DC092689E1F0D8A70B6281848B27DEC0014
__StaticArrayInitTypeSize=124
__StaticArrayInitTypeSize=6144
get_Zip64
_directoryNeededZip64
_anyEntriesUsedZip64
get_OutputUsedZip64
ProcessExtraFieldZip64
get_EnableZip64
set_EnableZip64
_presumeZip64
get_RequiresZip64
_entryRequiresZip64
get_InputUsesZip64
_OutputUsesZip64
_zip64
ToInt64
SteamPath_x64
_OffsetOfCentralDirectory64
__StaticArrayInitTypeSize=384
CHECK4
<>9__0_4
<Main>b__0_4
<>9__2_4
<GetDefaultGateway>b__2_4
Level4
<>9__0_5
<Main>b__0_5
Level5
__StaticArrayInitTypeSize=116
__StaticArrayInitTypeSize=16
ToUInt16
__StaticArrayInitTypeSize=256
AesAlgId256
__StaticArrayInitTypeSize=76
18CF30A154BA18B69C9B7EC96076392327D2E4B6
6A316789EED01119DE92841832701A40AB0CABD6
<>9__0_6
<Main>b__0_6
REP_3_6
Level6
ibm437
Level7
Workaround_Ladybug318918
AesAlgId128
<GetEnumerator>d__328
REPZ_11_138
__StaticArrayInitTypeSize=38
1FDC8DB567F5AAA7068D0D2A601CD71657CBDF38
__StaticArrayInitTypeSize=68
A329E388635E96D13642E13AA9E7C2EE48D6A5C8
8457F44B035C9073EE2D1F132D0A8AF5631DCDC8
get_UTF8
GetUTF8
sNonUtf8
Level8
__StaticArrayInitTypeSize=19
Level9
<Module>
<PrivateImplementationDetails>
DACFCC5E985D9E113ABB74724C5D3CC4FDC4FB8A
67C0E784F3654B008A81E2988588CF4956CCF3DA
EB6F545AEF284339D25594F900E7A395212460EB
BCRYPT_KEY_DATA_BLOB
BCRYPT_KEY_DATA_BLOB_MAGIC
UpdateCRC
MIN_LOOKAHEAD
A474A0BEC4E2CE8491839502AE85F6EA8504C6BD
9F8365E9D6C62D3B47026EC465B05A7B5526B5CD
STORED
Z_DEFLATED
GetBSSID
OSSUID
GetProcessorID
Z_STREAM_END
METHOD
8ED8F61DAA454B49CD5059AE4486C59174324E9E
BADCODE
BCRYPT_CHAINING_MODE
DEFLATE
FINISH_STATE
INIT_STATE
BUSY_STATE
HEAP_SIZE
BUFFER_SIZE
79D521E6E3E55103005E9CC3FA43B3174FAF090F
D068832E6B13A623916709C1E0E25ADCBE7B455F
F584B6C7CCA3CD4ECC3B9B1E20D2F2EFB73DBBDF
BCRYPT_AUTH_MODE_CHAIN_CALLS_FLAG
STATUS_AUTH_TAG_MISMATCH
MIN_MATCH
MAX_MATCH
_future_ROLH
BCRYPT_AUTH_TAG_LENGTH
BCRYPT_OBJECT_LENGTH
Z_ASCII
get_ASCII
VimeAPI
WinAPI
STORED_BLOCK
END_BLOCK
GetRAM
BCRYPT_CHAIN_MODE_GCM
BCRYPT_AES_ALGORITHM
BCRYPT_INIT_AUTH_MODE_INFO_VERSION
NordVPN
OpenVPN
ProtonVPN
Z_UNKNOWN
BCRYPT_AUTHENTICATED_CIPHER_MODE_INFO
BCRYPT_OAEP_PADDING_INFO
BCRYPT_PSS_PADDING_INFO
System.IO
Z_ERRNO
BCRYPT_PAD_OAEP
SendARP
MS_PRIMITIVE_PROVIDER
Z_DATA_ERROR
Z_BUF_ERROR
Z_STREAM_ERROR
Z_MEM_ERROR
Z_VERSION_ERROR
_locEndOfCDS
EncryptStringAES
D_CODES
LENGTH_CODES
BL_CODES
STATIC_TREES
DYN_TREES
BLOCKS
LITERALS
ERROR_SUCCESS
UnLoadNSS
BCRYPT_PAD_PSS
MAX_BL_BITS
MAX_BITS
Z_NEED_DICT
PRESET_DICT
BCRYPT_KEY_LENGTHS_STRUCT
IO_BUFFER_SIZE_DEFAULT
MEM_LEVEL_DEFAULT
LENEXT
CF_UNICODETEXT
DISTEXT
get_IV
set_IV
MEM_LEVEL_MAX
Z_BINARY
PathFZ
value__
initWorkArea
PackedToRemovableMedia
get_SelectionCriteria
set_SelectionCriteria
selectionCriteria
GetDataFileZilla
GetFileZilla
_Extra
CopyMetaData
cbData
sWebData
pbData
UploadData
ProtectedData
bEncryptedData
GetClipboardData
_InitializeTreeData
remainingData
cbAuthData
pbAuthData
LocalData
SECItemData
sLoginData
CommonData
AppData
tsData
CryptUnprotectData
SplitData
_WriteEntryData
GetTdata
WriteSecurityMetadata
lappdata
CopyLevelDb
Ionic.Zlib
mscorlib
DataBlob
_newlyCompressedBlob
_TimeBlob
_SaveSfxStub
ZlibCodec
_codec
set_MatchingFileSpec
inflate_trees_dynamic
System.Collections.Generic
CompressFunc
Ionic.Crc
get_Crc
_runningCrc
FromFileTimeUtc
SetLastWriteTimeUtc
SetCreationTimeUtc
SetLastAccessTimeUtc
get_sExpiresUtc
set_sExpiresUtc
zxczxczxc
_diskNumberWithCd
get_Id
pszAlgId
_UnsupportedAlgorithmId
targetHeaderId
_CheckRead
get_CanRead
OpenRead
_LeftToRead
ForRead
get_BytesRead
Reading_ArchiveBytesRead
get_TotalBytesRead
Saving_EntryBytesRead
_bytesRead
lookahead
get_CurrentThread
fixed_bd
get_VersionNeeded
_sourceWasJitProvided
get_InputStreamWasJitProvided
BestSpeed
RijndaelManaged
_metadataChanged
get_IsChanged
_contentsChanged
NotifyEntryChanged
get_LastModified
set_LastModified
modified
DateTimeToPacked
Interlocked
_addOperationCanceled
_saveOperationCanceled
_ioOperationCanceled
_extractOperationCanceled
_lastFilled
Undefined
get_TotalBytesSlurped
Filtered
_findRequired
bytesXferred
get_BytesTransferred
set_BytesTransferred
_bytesTransferred
_isClosed
_closed
_disposed
accessed
get_BytesProcessed
_totalBytesProcessed
_latestCompressed
compressed
created
_crcCalculated
get_EntriesExtracted
_entriesExtracted
detected
IsUnrestricted
Reading_Completed
Adding_Completed
Saving_Completed
OnReadCompleted
OnAddCompleted
OnSaveCompleted
OnExtractAllCompleted
bytesToBeDecrypted
_sourceIsEncrypted
encrypted
Reading_Started
Adding_Started
Saving_Started
OnReadStarted
OnAddStarted
OnSaveStarted
FinishStarted
OnExtractAllStarted
get_EntriesSorted
Unsupported
Rfc1950BytesEmitted
_hasBeenSaved
get_EntriesSaved
_entriesSaved
_JustSaved
pReserved
inflate_trees_fixed
System.Collections.Specialized
Synchronized
bi_valid
NewGuid
ReadExtraField
ProcessExtraField
ConstructExtraField
<sExpiresUtc>k__BackingField
<CompressionMethod>k__BackingField
<sPassword>k__BackingField
<Source>k__BackingField
<AlternateEncodingUsage>k__BackingField
<ExtractExistingFile>k__BackingField
<IconFile>k__BackingField
<sTitle>k__BackingField
<SfxExeWindowTitle>k__BackingField
<sName>k__BackingField
<ProductName>k__BackingField
<sUsername>k__BackingField
<PostExtractCommandLine>k__BackingField
<sIsSecure>k__BackingField
<Verbose>k__BackingField
<ContiguousWrite>k__BackingField
<RemoveUnpackedFilesAfterExecute>k__BackingField
<sValue>k__BackingField
<CodecBufferSize>k__BackingField
<Encoding>k__BackingField
<AlternateEncoding>k__BackingField
<ProvisionalAlternateEncoding>k__BackingField
<SortEntriesBeforeSaving>k__BackingField
<sPath>k__BackingField
<sExpMonth>k__BackingField
<CompressionLevel>k__BackingField
<sUrl>k__BackingField
<FullScan>k__BackingField
<FileVersion>k__BackingField
<ProductVersion>k__BackingField
<SetCompression>k__BackingField
<ZipErrorAction>k__BackingField
<Description>k__BackingField
<sExpYear>k__BackingField
<sNumber>k__BackingField
<StatusMessageWriter>k__BackingField
<Stealer_Dir>k__BackingField
<Flavor>k__BackingField
<AdditionalCompilerSwitches>k__BackingField
<ReadProgress>k__BackingField
<TraverseReparsePoints>k__BackingField
<AddDirectoryWillTraverseReparsePoints>k__BackingField
<FlattenFoldersOnExtract>k__BackingField
<Target>k__BackingField
<Quiet>k__BackingField
<Copyright>k__BackingField
<iCount>k__BackingField
<sKey>k__BackingField
<sHostKey>k__BackingField
<Strategy>k__BackingField
<DefaultExtractDirectory>k__BackingField
RecordHeaderField
GetField
get_BitField
huft_build
get_ParallelDeflateThreshold
set_ParallelDeflateThreshold
VimeWorld
FollowedByOddNumberOfSingleQuotesAndLineEnd
FollowedByEvenNumberOfSingleQuotesAndLineEnd
TrimEnd
ReadToEnd
Append
SignatureToFind
get_Kind
DateTimeKind
SpecifyKind
get_Second
GetLowerBound
get_CompressionMethod
set_CompressionMethod
get_UnsupportedCompressionMethod
_compressionMethod
GetMethod
method
FormatCreditCard
CloseClipboard
OpenClipboard
TruncateBackward
WriteDiscord
get_Password
set_Password
ExtractWithPassword
CheckZipPassword
get_sPassword
set_sPassword
FormatPassword
DecryptPassword
_password
fixed_td
NetworkInterface
Replace
Whitespace
_DesiredTrace
CriterionTrace
SelectorTrace
ReadIntoInstance
_InitInstance
defaultInstance
cbNonce
pbNonce
get_Source
set_Source
CompileAssemblyFromSource
ZipEntrySource
source
CountryCOde
DistanceCode
GetHashCode
LengthCode
set_Mode
FileMode
chainingMode
get_FlushMode
set_FlushMode
_flushMode
InflateBlockMode
CryptoStreamMode
_streamMode
CompressionMode
_compressionMode
CryptoMode
InflateManagerMode
CipherMode
RwMode
rwMode
SelectSingleNode
XmlNode
send_code
_dist_code
max_code
Decode
get_Unicode
get_BigEndianUnicode
StaticTree
staticTree
InfTree
build_tree
send_tree
build_bl_tree
scan_tree
dyn_tree
dyn_dtree
inftree
dyn_ltree
get_CodePage
FromImage
get_AlternateEncodingUsage
set_AlternateEncodingUsage
_alternateEncodingUsage
get_Message
_ErrorMessage
DecryptMessage
EncryptMessage
message
youknowcaliber.Edge
AddRange
CopyThroughWithNoChange
CompareExchange
cCookie
sCookie
FormatCookie
WriteTake
EndInvoke
BeginInvoke
crc32Table
ReadTable
GenerateLookupTable
ReadMasterTable
GetEnvironmentVariable
compressedBytesAvailable
inputBytesAvailable
IsClipboardFormatAvailable
match_available
IEnumerable
IDisposable
set_GenerateExecutable
ToDouble
Lifecycle
RuntimeFieldHandle
RuntimeTypeHandle
GetTypeFromHandle
EventWaitHandle
Rectangle
DownloadFile
AddFile
CopyDatabaseFile
UpdateFile
SaveFile
get_ExtractExistingFile
set_ExtractExistingFile
CheckExtractExistingFile
extractExistingFile
CreateFromFile
LoginFile
get_IconFile
set_IconFile
ExtractResourceToFile
get_ZipFile
_CompressionMethod_FromZipFile
_Encryption_FromZipFile
NormalizePathForUseInZipFile
IsZipFile
CreateAndOpenUniqueTempFile
RemoveTempFile
isFile
sizefile
UserProfile
sProfile
GetProfile
SetProfile
ResourcesToCompile
IsVolatile
Console
get_sTitle
set_sTitle
DetectTitle
get_SfxExeWindowTitle
set_SfxExeWindowTitle
hModule
get_MainModule
ProcessModule
GetCPUName
get_Name
set_Name
sProcName
_readName
resourceName
tableName
get_FileName
set_FileName
NormalizeFileName
get_LocalFileName
localFileName
GetRandomFileName
AppendCopyToFileName
_GzipFileName
InternalGetTempFileName
sFileName
GetFileName
targetFileName
outFileName
_temporaryFileName
fileName
get_MachineName
_baseName
valueName
get_ArchiveName
set_ArchiveName
_archiveName
GetElementsByTagName
pathName
NickName
get_FullName
ItemName
itemName
GetWindowsVersionName
get_CurrentTempName
_currentTempName
BrowserPathToAppName
get_UserName
get_sName
set_sName
get_ProcessName
get_ProductName
set_ProductName
GetName
ExploitName
get_CurrentName
_currentName
GetGpuName
GetProcessesByName
AddDirectoryByName
AssemblyName
fileOrDirectoryName
GetDirectoryName
directoryName
entryName
filename
GenerateTempPathname
compname
get_sUsername
set_sUsername
username
StackFrame
get_ModifiedTime
set_ModifiedTime
get_AccessedTime
set_AccessedTime
ToFileTime
packedDateTime
PackedToDateTime
GetLastWriteTime
SetLastWriteTime
IsDaylightSavingTime
WhichTime
ToLocalTime
ToUniversalTime
get_CreationTime
set_CreationTime
GetCreationTime
GetLastAccessTime
_Atime
_Ctime
_Mtime
_GzipMtime
_DeflateOne
_EvaluateOne
ExtractOne
WaitOne
get_Line
ReadLine
get_PostExtractCommandLine
set_PostExtractCommandLine
AppendLine
TraceWriteLine
Combine
LocalMachine
_firstReadDone
_firstWriteDone
FinishDone
BlockDone
CriterionDone
EmitDone
DeflateNone
Escape
DataProtectionScope
pszBlobType
DetectCreditCardType
get_NetworkInterfaceType
ClassInterfaceType
ValueType
get_DriveType
get_DeclaringType
FlushType
SECItemType
enumType
ObjectType
GetType
get_EventType
set_EventType
ZipProgressEventType
set_data_type
FileShare
Compare
gf2_matrix_square
System.Core
DashCore
LitecoinCore
BitcoinCore
BufferPairsPerCore
NeedMore
Before
before
get_sIsSecure
set_sIsSecure
ReadSignature
FindSignature
Zip64EndOfCentralDirectoryRecordSignature
SplitArchiveSignature
Zip64EndOfCentralDirectoryLocatorSignature
ZipEntryDataDescriptorSignature
EndOfCentralDirectorySignature
ReadEntrySignature
ZipEntrySignature
ZipDirEntrySignature
signature
WriteCentralDirectoryStructure
get_Culture
set_Culture
resourceCulture
get_CurrentCulture
culture
Capture
extraBase
MethodBase
DistanceBase
LengthBase
CollectionBase
ApplicationSettingsBase
ToTitleCase
get_IgnoreCase
set_IgnoreCase
get_OrdinalIgnoreCase
_DontIgnoreCase
ignoreCase
database
passphrase
get_Verbose
set_Verbose
System.IDisposable.Dispose
AdjustTime_Reverse
bi_reverse
recurse
ByteUpdate
AddOrUpdate
RemoveEntryForUpdate
wantUpdate
Create
_CloseDelegate
_WriteDelegate
_OpenDelegate
MulticastDelegate
EndDeflate
_InternalInitializeDeflate
ResetDeflate
SyncInflate
EndInflate
InitializeInflate
Donate
exeToGenerate
DebuggerBrowsableState
EditorBrowsableState
ParseState
BlockState
<>1__state
dstate
istate
_Evaluate
RecursiveDelete
ReallyDelete
NotifyEntriesSaveComplete
NotifySaveComplete
SQLite
get_CanWrite
OpenWrite
totalBytesToWrite
_toWrite
ForWrite
_zipCrypto_forWrite
get_ContiguousWrite
set_ContiguousWrite
Extracting_ExtractEntryWouldOverwrite
DoNotOverwrite
DispIdAttribute
CompilerGeneratedAttribute
GuidAttribute
ClassInterfaceAttribute
GeneratedCodeAttribute
DebuggerNonUserCodeAttribute
DebuggableAttribute
DebuggerBrowsableAttribute
EditorBrowsableAttribute
ComVisibleAttribute
AssemblyTitleAttribute
IteratorStateMachineAttribute
ObsoleteAttribute
AssemblyTrademarkAttribute
TargetFrameworkAttribute
ConditionalAttribute
DebuggerHiddenAttribute
AssemblyFileVersionAttribute
AssemblyConfigurationAttribute
AssemblyDescriptionAttribute
DefaultMemberAttribute
UnmanagedFunctionPointerAttribute
FlagsAttribute
CompilationRelaxationsAttribute
AssemblyProductAttribute
AssemblyCopyrightAttribute
ParamArrayAttribute
AssemblyCompanyAttribute
RuntimeCompatibilityAttribute
get_RemoveUnpackedFilesAfterExecute
set_RemoveUnpackedFilesAfterExecute
get_Minute
CopyThroughWithRecompute
get_MagicByte
Dequeue
Enqueue
hMozGlue
get_Value
AppendValue
byteValue
get_sValue
set_sValue
get_HasValue
GetValue
_skippedDuringSave
_restreamRequiredOnSave
get_IncludedInMostRecentSave
get_NumberOfSegmentsForMostRecentSave
_numberOfSegmentsForMostRecentSave
RegistryHive
_FileNameInArchive
fileNameInArchive
directoryNameInArchive
nameInArchive
rootDirectoryPathInArchive
directoryPathInArchive
directoryInArchive
Saving_BeforeRenameTempArchive
Saving_AfterRenameTempArchive
Saving_AfterSaveTempArchive
entriesToRemove
Stub.exe
get_Size
_CompressedFileDataSize
dataSize
cbSize
get_CompressedSize
get_UncompressedSize
_pageSize
_sqlDataTypeSize
MaxAuthTagSize
get_BlockSize
set_BlockSize
AesBlockSize
get_BufferSize
set_BufferSize
get_CodecBufferSize
set_CodecBufferSize
_bufferSize
GetDirSize
get_MaxOutputSegmentSize
set_MaxOutputSegmentSize
_maxOutputSegmentSize
_maxSegmentSize
maxSize
get_KeySize
set_KeySize
AesKeySize
DirectorySize
_TotalEntrySize
Initialize
SuppressFinalize
Buf_size
hash_size
window_size
Resize
lit_bufsize
SizeOf
get_ItemOf
LastIndexOf
read_buf
bi_buf
authTag
SecurityPermissionFlag
GetFlag
GetInfoFromReg
IsNotValidSig
IsNotValidZipDirEntrySig
patchConfig
DecryptConfig
config
ReadIntoInstance_Orig
get_Png
ForReading
System.Threading
ConjunctionPending
_exceptionPending
nextPending
flush_pending
get_Encoding
set_Encoding
_dbEncoding
get_AlternateEncoding
set_AlternateEncoding
get_ProvisionalAlternateEncoding
set_ProvisionalAlternateEncoding
_provisionalAlternateEncoding
_alternateEncoding
_actualEncoding
GetEncoding
get_DefaultEncoding
_defaultEncoding
encoding
System.Drawing.Imaging
finishing
CreateFromNothing
Banking
_currentlyFilling
System.Runtime.Versioning
get_IsWarning
FromBase64String
ToBase64String
DownloadString
ReadZeroTerminatedString
sourceString
get_AttributeString
set_AttributeString
ToString
CompressString
UncompressString
GetString
_regexString
Substring
disposing
MaybeUnsetCompressionMethodForWriting
Counting
OnExtractExisting
emitting
Error_Saving
OnZipErrorWhileSaving
whileSaving
get_SortEntriesBeforeSaving
set_SortEntriesBeforeSaving
get_UseZip64WhenSaving
set_UseZip64WhenSaving
get_EmitTimesInWindowsFormatWhenSaving
set_EmitTimesInWindowsFormatWhenSaving
get_EmitTimesInUnixFormatWhenSaving
set_EmitTimesInUnixFormatWhenSaving
OnZipErrorSaving
System.Drawing
ConvertToULong
dateLog
GetProg
_win32Epoch
_unixEpoch
IsMatch
_InitializeLazyMatch
SysPatch
cur_match
longest_match
prev_match
SetFdpLoh
ComputeStringHash
EnsureendInSlash
_FlushFinish
finish
_Flush
bi_flush
last_flush
GetCookiesDBPath
GetBookmarksDBPath
GetHistoryDBPath
GetMozillaPath
EdgePath
ProcessExecutablePath
sSavePath
SimplifyFwdSlashPath
GetFullPath
GetTempPath
DesktopPath
GetFolderPath
sPrevBrowserPath
get_sPath
set_sPath
MinecraftPath
FzPath
fullpath
directorypath
get_Width
get_Length
_extraFieldLength
GoodLength
goodLength
NiceLength
niceLength
SetInputAndFigureFileLength
GetFileLength
_filenameLength
streamLength
dwMinLength
MaxChainLength
maxChainLength
GetLength
SetLength
_commentLength
dwMaxLength
maxLength
match_length
prev_length
EndsWith
StartsWith
get_Month
get_sExpMonth
set_sExpMonth
_readExtraDepth
PtrToStringUni
WinApi
PkzipWeak
AsyncCallback
SetCompressionCallback
WaitCallback
callback
expectedCheck
computedCheck
_eLock
GlobalLock
EmitLock
_latestLock
_outputLock
OnWriteBlock
OnSaveBlock
SlurpBlock
OnExtractBlock
_tr_stored_block
send_compressed_block
_tr_flush_block
copy_block
GlobalUnlock
get_CanSeek
GrabOutlook
bBookmark
FormatBookmark
InflateMask
hash_mask
w_mask
directoryOnDisk
AllocHGlobal
FreeHGlobal
Marshal
dwPolynomial
polynomial
Partial
get_Ordinal
ordinal
original
get_EntriesTotal
set_EntriesTotal
_entriesTotal
op_GreaterThanOrEqual
op_LessThanOrEqual
get_CaseSensitiveRetrieval
set_CaseSensitiveRetrieval
fixed_bl
cbLabel
pbLabel
get_Cancel
set_Cancel
_cancel
System.Collections.ObjectModel
System.ComponentModel
memLevel
get_CompressionLevel
set_CompressionLevel
compressionLevel
CompressLevel
_compressLevel
_level
EnumUtil
SaveAll
Extracting_BeforeExtractAll
_InternalExtractAll
_inExtractAll
Extracting_AfterExtractAll
EmitAll
kernel32.dll
user32.dll
crypt32.dll
iphlpapi.dll
bcrypt.dll
_toFill
WriteAutoFill
FormatAutoFill
Autofill
System.Xml
LoadXml
ThreadPool
AddOrUpdateDirectoryImpl
get_sUrl
set_sUrl
fixed_tl
ZlibStream
_crcStream
get_ReadStream
get_LengthOfReadStream
_lengthOfReadStream
_SetReadStream
get_WrappedStream
ZipSegmentedStream
PrepSourceStream
_sourceStream
GetManifestResourceStream
FileStream
ZlibBaseStream
_baseStream
DeflateStream
get_WriteStream
set_WriteStream
_SetWriteStream
get_ArchiveStream
_archiveStream
get_EndOfStream
CountingStream
CryptoStream
GZipStream
zipStream
SetupStream
ZipCipherStream
_innerStream
CreateForStream
CrcCalculatorStream
_inputDecryptorStream
OffsetStream
JitStream
_outStream
get_InputStream
set_InputStream
ZipInputStream
_inputStream
get_OutputStream
ParallelDeflateOutputStream
FinishOutputStream
PrepOutputStream
get_ZipOutputStream
CreateForZipOutputStream
_entryOutputStream
_outputStream
MemoryStream
_stream
_readstream
_writestream
outstream
GetLocationSteam
Telegram
Program
cAesGcm
TSECItem
get_Item
AddItem
UpdateItem
QueueUserWorkItem
workitem
FileSystem
get_Is64BitOperatingSystem
GetSystem
SymmetricAlgorithm
get_UnsupportedAlgorithm
phAlgorithm
EncryptionAlgorithm
Random
ICryptoTransform
RootNum
rowNum
Ethereum
youknowcaliber.Chromium
GetNewEnum
Electrum
get_TotalIn
AvailableBytesIn
TotalBytesIn
NextIn
resourceMan
get_FullScan
set_FullScan
toscan
Boolean
LesserThan
op_GreaterThan
op_LessThan
TimeSpan
SECItemLen
physicalAddrLen
previouslySeen
CopyFromScreen
GetScreen
get_PrimaryScreen
last_eob_len
static_len
stored_len
heap_len
opt_len
gen_bitlen
get_LeaveOpen
set_LeaveOpen
_leaveOpen
_leaveUnderlyingStreamOpen
OpenParen
ProgramFilesChildren
_entriesWritten
get_BytesWritten
Extracting_EntryBytesWritten
_bytesWritten
_lastWritten
checkfn
_tr_align
WorkingBufferSizeMin
WantReadAgain
EmitBegin
SeekOrigin
origin
Bytecoin
get_Column
_Criterion
CompoundCriterion
NameCriterion
TimeCriterion
TypeCriterion
_ParseCriterion
SizeCriterion
SelectionCriterion
AttributesCriterion
get_Extension
GetExtension
GetFileNameWithoutExtension
extension
get_Version
get_FileVersion
set_FileVersion
GetSystemVersion
dwInfoVersion
get_ProductVersion
set_ProductVersion
GetBitVersion
get_LibraryVersion
GetZipLibraryVersion
GetUplaySession
ValidateCompression
get_SetCompression
set_SetCompression
BestCompression
MaybeApplyCompression
NormalizeCriteriaExpression
SecurityPermission
ConsoleApplication
WinFormsApplication
get_Location
get_ExtractLocation
extractLocation
set_IncludeDebugInformation
System.Net.NetworkInformation
GatewayIPAddressInformation
CleanupAfterSaveOperation
System.Configuration
pszImplementation
stringRepresentation
System.Globalization
System.Runtime.Serialization
ExtractExistingFileAction
AddOrUpdateAction
get_ZipErrorAction
set_ZipErrorAction
_zipErrorAction
op_Subtraction
System.Reflection
NameValueCollection
StringCollection
MatchCollection
GatewayIPAddressInformationCollection
GroupCollection
WebHeaderCollection
CompilerErrorCollection
ManagementObjectCollection
KeyCollection
DeflateFunction
LogicalConjunction
op_Addition
get_Position
set_Position
__FileDataPosition
get_FileDataPosition
get_ComputedPosition
_sourceStreamOriginalPosition
_originalPosition
CallingConvention
Zip64Option
SearchOption
ZipOption
IOException
get_Exception
ZlibException
CryptographicException
BadCrcException
BadReadException
ObjectDisposedException
NotImplementedException
NotSupportedException
FileNotFoundException
DirectoryNotFoundException
BadPasswordException
ArgumentOutOfRangeException
IndexOutOfRangeException
BadStateException
_pendingException
_handlingException
PathTooLongException
ArgumentNullException
SfxGenerationException
InvalidOperationException
ZipException
innerException
_HRForException
GetHRForException
UnauthorizedAccessException
UriFormatException
ArgumentException
OverflowException
exception
get_Description
set_Description
GetDescription
pszDescription
get_Encryption
set_Encryption
ValidateEncryption
ProcessExtraFieldPkwareStrongEncryption
get_UsesEncryption
MaybeApplyEncryption
_encryption
StringComparison
pattern
fpNssShutdown
LesserThanOrEqualTo
GreaterThanOrEqualTo
NotEqualTo
CopyTo
get_Info
FieldInfo
FileInfo
CultureInfo
DriveInfo
pPaddingInfo
FileSystemInfo
SerializationInfo
MemberInfo
get_TextInfo
DirectoryInfo
get_CompressionRatio
Monero
ZipCrypto
destIp
pqdownheap
Bitmap
Ionic.Zip
CheckZip
EmitSkip
get_Timestamp
set_Timestamp
ZipEntryTimestamp
_timestamp
hwndApp
Microsoft.CSharp
bi_windup
Lookup
_needSetup
System.Linq
get_Year
get_sExpYear
set_sExpYear
ToChar
macAddr
youknowcaliber
initialDiskNumber
StreamForDiskNumber
_currentDiskNumber
_maxDiskNumber
_diskNumber
get_ErrorNumber
get_sNumber
set_sNumber
number
expectRfc1950Header
wantRfc1950Header
ReadHeader
WriteHeader
get_LengthOfHeader
_RelativeOffsetOfLocalHeader
_WeakEncryptionHeader
ReadWeakEncryptionHeader
_ReadAndValidateGzipHeader
EmitHeader
_EntryHeader
_needToWriteEntryHeader
SqlReader
StreamReader
InternalOpenReader
sourceTextReader
header
CSharpCodeProvider
CreateForJitStreamProvider
BCryptCloseAlgorithmProvider
BCryptOpenAlgorithmProvider
CodeDomProvider
IFormatProvider
provider
StringBuilder
sourceFolder
get_TempFileFolder
set_TempFileFolder
sLocalStateFolder
SpecialFolder
destFolder
bl_order
border
totalBytesToXfer
get_workingBuffer
Utf8StringFromBuffer
CompressBuffer
UncompressBuffer
GetBuffer
InputBuffer
OutputBuffer
buffer
get_TotalBytesToTransfer
set_TotalBytesToTransfer
_totalBytesToTransfer
get_ResourceManager
DeflateManager
InflateManager
Filemanager
URLSearcher
ManagementObjectSearcher
bCipher
InitCipher
_cipher
marker
_LengthOfTrailer
System.CodeDom.Compiler
_IsSmaller
opener
ZipContainer
_container
hWndNewOwner
ComHelper
CopyHelper
ToUpper
StringComparer
CurrentUser
closer
Parser
Browser
get_ParallelDeflater
set_ParallelDeflater
SetDeflater
_deflater
delimiter
get_StatusMessageWriter
set_StatusMessageWriter
statusMessageWriter
StreamWriter
CreateForWriter
get_StatusMessageTextWriter
set_StatusMessageTextWriter
writer
WriteEnter
EmitEnter
TryEnter
GetDelegateForFunctionPointer
_outputCounter
entryCounter
ReadCentralDirectoryFooter
GenCentralDirectoryFooter
BitConverter
_register
ToLower
InfoPlayer
Echelon_Dir
get_Stealer_Dir
set_Stealer_Dir
_baseDir
ZcashDir
OutlookDir
AtomDir
EthereumDir
ElectrumDir
ExodusDir
ExploitDir
JaxxDir
ArmoryDir
basedir
base64xmr
set_ForegroundColor
ConsoleColor
ResetColor
add_ZipError
remove_ZipError
CompilerError
GetExtractDecompressor
decompressor
separator
IEnumerator
StringEnumerator
ManagementObjectEnumerator
System.Collections.IEnumerable.GetEnumerator
ComparisonOperator
Saving_AfterCompileSelfExtractor
SaveSelfExtractor
.cctor
FileSelector
Monitor
HandleUnexpectedDataDescriptor
CreateDecryptor
GetExtractDecryptor
CreateEncryptor
_encryptor
get_Flavor
set_Flavor
DeflateFlavor
ZlibStreamFlavor
SelfExtractorFlavor
eventFlavor
_flavor
IntPtr
LitecStr
AtomicStr
EleStr
EcoinStr
DSHcoinStr
BCNcoinStr
XMRcoinStr
ExodusStr
ZecwalletStr
JaxxStr
ArmoryStr
get_Hour
_zeroHour
Graphics
ScreenMetrics
System.Diagnostics
Downloads
AddSeconds
get_TotalSeconds
get_Bounds
GetBounds
SaveMods
WriteCreditCards
youknowcaliber.Passwords
WritePasswords
pPasswords
GetAllNetworkInterfaces
System.Runtime.InteropServices
System.Runtime.CompilerServices
DetectServices
treeDistances
System.Resources
get_EmbeddedResources
disposeManagedResources
CopyThroughResources
RL.Properties.Resources.resources
lengthAndLiteralsTreeCodes
distTreeCodes
treeCodes
InflateCodes
DebuggingModes
gen_codes
dcodes
blcodes
send_all_trees
Matches
matches
get_AdditionalCompilerSwitches
set_AdditionalCompilerSwitches
youknowcaliber.Cookies
cCookies
WriteCookies
get_ReferencedAssemblies
DiscordDirectories
recurseDirectories
EnumerateDirectories
GetDirectories
get_Entries
RemoveSelectedEntries
ExtractSelectedEntries
_masterTableEntries
_tableEntries
RemoveEntries
SelectEntries
CountEntries
_entries
SharedUtilities
RL.Properties
GetIPProperties
IPInterfaceProperties
GetDBFiles
AddFiles
AddSelectedFiles
_AddOrUpdateSelectedFiles
UpdateFiles
EnumerateFiles
SelectFiles
GetFiles
keyFiles
SaveProfiles
GetAllProfiles
_fieldNames
get_EntryFileNames
fileNames
GetSubKeyNames
ProcessExtraFieldInfoZipTimes
_emitNtfsTimes
ProcessExtraFieldWindowsTimes
_SetTimes
ProcessExtraFieldUnixTimes
_emitUnixTimes
SetEntryTimes
gf2_matrix_times
ReadAllLines
CreditCardTypes
Pictures
WriteProcesses
GetProcesses
get_GatewayAddresses
PrecededByOddNumberOfSingleQuotes
PrecededByEvenNumberOfSingleQuotes
get_Attributes
set_Attributes
FileAttributes
GetCustomAttributes
GetAttributes
SetAttributes
OnReadBytes
_fileBytes
GetEncodedFileNameBytes
Rfc2898DeriveBytes
totalBytes
ReadAllBytes
get_HandleRfc1950HeaderBytes
set_HandleRfc1950HeaderBytes
_handleRfc1950HeaderBytes
expectRfc1950HeaderBytes
get_WantRfc1950HeaderBytes
set_WantRfc1950HeaderBytes
GetLengthOfCryptoHeaderBytes
_ReadFourBytes
ReadFirstFourBytes
GetAddressBytes
GetBytes
saltBytes
_CommentBytes
NextBytes
put_bytes
nbytes
get_Values
GetValues
values
GetDrives
SetZip64Flags
dwPromptFlags
dwFlags
ExtractorSettings
ZipErrorEventArgs
ReadProgressEventArgs
AddProgressEventArgs
SaveProgressEventArgs
ZipProgressEventArgs
ExtractProgressEventArgs
_TrimVolumeFromFullyQualifiedPaths
sGeckoBrowserPaths
sChromiumPswPaths
treeBitLengths
<>4__this
get_Ticks
InflateBlocks
_InitializeBlocks
blocks
youknowcaliber.Bookmarks
bBookmarks
cBookmarks
WriteBookmarks
sBookmarks
treeLiterals
Equals
SharedUtils
cBrowserUtils
aFills
SetDeflateParams
varParams
SetParams
_InitializePoolOfWorkItems
System.Windows.Forms
GetTokens
cplens
domains
Contains
cLogins
extensions
SaveVersions
GetTelegramSessions
System.Text.RegularExpressions
System.Security.Permissions
System.Collections
ReadOptions
SelfExtractorSaveOptions
get_CompilerOptions
set_CompilerOptions
RegexOptions
options
RegexAssertions
get_Groups
get_Chars
InvalidChars
GetInvalidPathChars
GetChars
get_Headers
IFolders
EmitPendingBuffers
RuntimeHelpers
GetMozillaBrowsers
CompilerParameters
SaveServers
get_MaxBufferPairs
set_MaxBufferPairs
get_ParallelDeflateMaxBufferPairs
set_ParallelDeflateMaxBufferPairs
_maxBufferPairs
get_Errors
_InternalFileAttrs
_ExternalFileAttrs
fileAttrs
criterionAttrs
_ReadStreamIsOurs
sEncPass
FileAccess
get_Success
GetCurrentProcess
process
IPAddress
get_Address
GetProcAddress
add_ReadProgress
remove_ReadProgress
get_ReadProgress
set_ReadProgress
readProgress
add_AddProgress
remove_AddProgress
add_SaveProgress
remove_SaveProgress
add_ExtractProgress
remove_ExtractProgress
OnExtractProgress
get__wantCompress
Decompress
StartWallets
extraBits
TraceBits
ExtraDistanceBits
ReverseBits
reverseBits
ExtraLengthBits
WindowBits
windowBits
send_bits
hash_bits
inflate_trees_bits
w_bits
extra_blbits
CompilerResults
ZlibConstants
InternalInflateConstants
InternalConstants
ZipConstants
clients
numSegments
MyDocuments
get_TraverseReparsePoints
set_TraverseReparsePoints
get_AddDirectoryWillTraverseReparsePoints
set_AddDirectoryWillTraverseReparsePoints
traverseDirectoryReparsePoints
SaveScreenshots
get_Exists
_fileAlreadyExists
Exodus
GetAntivirus
WriteStatus
get_OperationalStatus
status
Windows
arrays
Always
get_Keys
UpdateKeys
readAt
writeAt
Concat
ImageFormat
uFormat
format
OnBeforeExtract
IsZipFileWithExtract
InternalExtract
get_FlattenFoldersOnExtract
set_FlattenFoldersOnExtract
_versionNeededToExtract
VerifyCrcAfterExtract
OnAfterExtract
SetupCryptoForExtract
_zipCrypto_forExtract
testExtract
OnSingleEntryExtract
ParseExact
ManagementBaseObject
hObject
ManagementObject
cbKeyObject
pbKeyObject
object
Select
GetDomainDetect
ondetect
Unprotect
CryptprotectPromptstruct
SteamGet
bitsToGet
System.Net
_ntfsTimesAreSet
get_Target
set_Target
_target
get_Quiet
set_Quiet
AtomicWallet
Ethernet
sharedSecret
System.Collections.IEnumerator.Reset
_distanceOffset
StoreRelativeOffset
_lengthOffset
_initialOffset
ReadTableFromOffset
offset
Minecraft
URShift
hash_shift
get_Right
set_Right
get_Height
get_Copyright
set_Copyright
mustWait
last_lit
UnsetLengthLimit
_lengthLimit
fpNssInit
cbSalt
get_Default
WorkingBufferSizeDefault
FirstOrDefault
WindowBitsDefault
get_Crc32Result
pcbResult
IAsyncResult
tsResult
result
ReadInt
WebClient
replacement
System.Management
XmlElement
dwIncrement
increment
SqlStatement
FindExtraFieldSegment
DeflateOneSegment
ComputeSegment
_NameForSegment
get_CurrentSegment
set_CurrentSegment
get_Comment
set_Comment
ReadZipFileComment
_GzipComment
_comment
Environment
XmlDocument
get_Parent
GetParent
System.Collections.Generic.IEnumerator<Ionic.Zip.ZipEntry>.Current
System.Collections.IEnumerator.Current
System.Collections.Generic.IEnumerator<Ionic.Zip.ZipEntry>.get_Current
System.Collections.IEnumerator.get_Current
<>2__current
byteContent
iContent
content
OnSaveEvent
get_ArchiveNameForEvent
InvokeErrorEvent
InvokeExtractProgressEvent
AutoResetEvent
SyncPoint
get_Count
_gzipHeaderByteCount
_headerByteCount
pendingCount
get_iCount
set_iCount
callCount
get_ProcessorCount
GetRowCount
_entryCount
bl_count
pPrompt
szPrompt
cBCrypt
DPAPIDecrypt
fpPk11SdrDecrypt
BCryptDecrypt
EasyDecrypt
BCryptEncrypt
ThreadStart
TrimStart
match_start
block_start
strstart
Convert
DeflateFast
InflateFast
RemoveLatest
XmlNodeList
ToList
get_ZipEntriesAsList
_zipEntriesAsList
SettingsList
ProcessList
cpdist
get_Host
Adjust
get_TotalOut
AvailableBytesOut
TotalBytesOut
NextOut
cbInput
pbInput
ReadInput
lastInput
nomoreinput
get_Output
Antivirus Signature
Bkav W32.AIDetectMalware.CS
Lionic Trojan.Win32.Stealer.12!c
tehtris Clean
ClamAV Win.Packed.Datastealer-9856291-0
CMC Clean
CAT-QuickHeal Trojan.MsilFC.S30682921
Skyhigh Trojan-FRAX!86108D3BCC19
McAfee Trojan-FRAX!86108D3BCC19
Cylance Unsafe
Zillya Clean
Sangfor Trojan.Win32.Save.a
K7AntiVirus Password-Stealer ( 005282e41 )
Alibaba Clean
K7GW Password-Stealer ( 005282e41 )
Cybereason malicious.bcc19f
Baidu Clean
Paloalto generic.ml
Symantec ML.Attribute.HighConfidence
Elastic Windows.Generic.Threat
ESET-NOD32 a variant of MSIL/PSW.CoinStealer.CC
APEX Malicious
Avast Win32:BankerX-gen [Trj]
Cynet Clean
Kaspersky HEUR:Trojan-PSW.MSIL.Stealer.gen
BitDefender Gen:Trojan.Mardom.IN.20
NANO-Antivirus Clean
ViRobot Trojan.Win.Z.Mardom.328192.K
MicroWorld-eScan Gen:Trojan.Mardom.IN.20
Tencent Msil.Trojan-QQPass.QQRob.Pnkl
TACHYON Trojan-PWS/W32.DN-InfoStealer.328192.B
Sophos Mal/Generic-S
F-Secure Heuristic.HEUR/AGEN.1365065
DrWeb Trojan.PWS.StealerNET.76
VIPRE Gen:Trojan.Mardom.IN.20
TrendMicro TROJ_GEN.R002C0DG624
McAfeeD ti!9A25FAEADE01
Trapmine Clean
FireEye Generic.mg.86108d3bcc19fe77
Emsisoft Gen:Trojan.Mardom.IN.20 (B)
SentinelOne Static AI - Malicious PE
GData Win32.Trojan-Stealer.CoinStealer.FPMJZ8
Jiangmin Trojan.Banker.MSIL.gum
Webroot W32.Adware.Gen
Varist W32/CoinMiner.FA.gen!Eldorado
Avira HEUR/AGEN.1365065
Antiy-AVL Trojan[Banker]/MSIL.Evital
Kingsoft MSIL.Trojan-PSW.Stealer.gen
Gridinsoft Trojan.Win32.Banker.sa
Xcitium Malware@#1lmi3sirq3g4e
Arcabit Trojan.Mardom.IN.20
SUPERAntiSpyware Clean
ZoneAlarm HEUR:Trojan-PSW.MSIL.Stealer.gen
Microsoft PWS:MSIL/Echelon.GG!MTB
Google Detected
AhnLab-V3 Trojan/Win.Stealgen.C5012716
Acronis Clean
ALYac Gen:Trojan.Mardom.IN.20
MAX malware (ai score=87)
VBA32 Dropper.MSIL.gen
Malwarebytes Generic.Malware.AI.DDS
Panda Trj/GdSda.A
Zoner Clean
TrendMicro-HouseCall TROJ_GEN.R002C0DG624
Rising Stealer.Agent!1.D483 (CLASSIC)
Yandex Clean
Ikarus Trojan.MSIL.PSW
MaxSecure Trojan.Malware.74396735.susgen
Fortinet MSIL/Agent.RXP!tr.pws
BitDefenderTheta Gen:NN.ZemsilF.36808.um0@aie6HDp
AVG Win32:BankerX-gen [Trj]
DeepInstinct MALICIOUS
CrowdStrike win/malicious_confidence_100% (D)
alibabacloud HackTool:Win/Agent.OI
No IRMA results available.