Static | ZeroBOX

PE Compile Time

2060-12-21 23:51:27

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x00069c14 0x00069e00 4.67226050811
.rsrc 0x0006c000 0x00000586 0x00000600 4.02264697391
.reloc 0x0006e000 0x0000000c 0x00000200 0.101910425663

Resources

Name Offset Size Language Sub-language File type
RT_VERSION 0x0006c0a0 0x000002fc LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_MANIFEST 0x0006c39c 0x000001ea LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with CRLF line terminators

Imports

Library mscoree.dll:
0x402000 _CorExeMain

!This program cannot be run in DOS mode.
`.rsrc
@.reloc
*"((F
@8j/T
_b_,
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
PADPADP
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
PADPADP
v4.0.30319
#Strings
<GetSSL>b__1_0
<Random>b__33_0
<Replace>b__0
<Get>b__0
<ScreenShot>b__0
<GetClipboardText>b__0
<Get>b__1
Func`1
IEnumerable`1
IOrderedEnumerable`1
Task`1
Action`1
TaskAwaiter`1
List`1
ToInt32
<Get>b__2
Func`2
KeyValuePair`2
Dictionary`2
<Get>b__3
GetTickCount64
get_UTF8
<Module>
System.IO
value__
GetClipboardData
mscorlib
System.Collections.Generic
ReadAsStringAsync
GetStringAsync
DownloadDataTaskAsync
GetAsync
PostAsync
WndProc
Thread
add_Load
AwaitUnsafeOnCompleted
get_IsCompleted
dwReserved
Synchronized
<Rnd>k__BackingField
<WorkFile>k__BackingField
<Value>k__BackingField
<WorkPatch>k__BackingField
<FullPathLnk>k__BackingField
<CurrentProcess>k__BackingField
piShowCmd
GetShowCmd
SetShowCmd
get_Rnd
CloseClipboard
OpenClipboard
EmptyClipboard
Replace
get_StatusCode
HttpStatusCode
get_IsSuccessStatusCode
set_AutoScaleMode
FileMode
FromImage
HttpResponseMessage
GetUserDefaultUILanguage
IsClipboardFormatAvailable
IEnumerable
IDisposable
get_Handle
RuntimeTypeHandle
GetTypeFromHandle
WaitHandle
Rectangle
get_WorkFile
IPersistFile
pszFile
get_UserProfile
IsInRole
WindowsBuiltInRole
Console
get_MainModule
ProcessModule
set_WindowStyle
ProcessWindowStyle
get_Name
set_Name
get_FileName
set_FileName
GetTempFileName
GetFileName
get_FullName
get_UserName
cchMaxName
pszName
DateTime
GetLastWriteTime
WriteLine
Combine
IAsyncStateMachine
SetStateMachine
stateMachine
ComInterfaceType
ValueType
SecurityProtocolType
System.Core
PtrToStructure
get_Culture
set_Culture
Capture
ApplicationSettingsBase
Dispose
Reverse
X509Certificate
Create
Delegate
EditorBrowsableState
SetApartmentState
Delete
STAThreadAttribute
CompilerGeneratedAttribute
GuidAttribute
GeneratedCodeAttribute
DebuggerNonUserCodeAttribute
DebuggableAttribute
EditorBrowsableAttribute
ComVisibleAttribute
AssemblyTitleAttribute
AsyncStateMachineAttribute
InterfaceTypeAttribute
AssemblyTrademarkAttribute
TargetFrameworkAttribute
DebuggerHiddenAttribute
AssemblyFileVersionAttribute
AssemblyConfigurationAttribute
AssemblyDescriptionAttribute
CompilationRelaxationsAttribute
AssemblyProductAttribute
AssemblyCopyrightAttribute
AssemblyCompanyAttribute
RuntimeCompatibilityAttribute
set_UseShellExecute
get_Value
TryGetValue
regxvalue
Resolve
get_Size
set_ClientSize
SizeOf
HasFlag
get_Png
System.Threading
ThenByDescending
OrderByDescending
Encoding
System.Drawing.Imaging
System.Runtime.Versioning
ToString
GetString
System.Drawing
set_ErrorDialog
get_Msg
ForEach
get_WorkPatch
Refresh
get_ExecutablePath
SetRelativePath
cchIconPath
pszIconPath
GetTempPath
get_DesktopPath
get_StartupPath
GetFolderPath
GetPath
SetPath
cchMaxPath
get_Width
get_Length
PtrToStringUni
RemoteCertificateValidationCallback
get_ServerCertificateValidationCallback
set_ServerCertificateValidationCallback
TimerCallback
GlobalLock
GlobalUnlock
get_FullPathLnk
get_Task
Marshal
System.Security.Principal
WindowsPrincipal
pszPathRel
System.ComponentModel
Parallel
kernel32.dll
user32.dll
set_SecurityProtocol
ContainerControl
FileStream
MemoryStream
get_LParam
get_WParam
get_Item
System
Random
ToBoolean
TimeSpan
CopyFromScreen
get_PrimaryScreen
X509Chain
piIcon
GetFileNameWithoutExtension
RegisterDeviceNotification
UnregisterDeviceNotification
Application
get_Location
GetIconLocation
SetIconLocation
System.Configuration
System.Globalization
Action
op_Subtraction
System.Reflection
MatchCollection
ManagementObjectCollection
SearchOption
SetException
OutOfMemoryException
GetDescription
SetDescription
StringComparison
FileInfo
CultureInfo
DriveInfo
FileSystemInfo
ProcessStartInfo
DirectoryInfo
Bitmap
System.Net.Http
System.Linq
AsyncVoidMethodBuilder
AsyncTaskMethodBuilder
StringBuilder
SpecialFolder
sender
get_ResourceManager
ServicePointManager
ManagementObjectSearcher
EventHandler
System.CodeDom.Compiler
AddClipboardFormatListener
IContainer
ToUpper
TaskAwaiter
GetAwaiter
StreamWriter
TextWriter
get_DocDir
pszDir
IEnumerator
GetEnumerator
.cctor
Monitor
IntPtr
Graphics
System.Diagnostics
FromMilliseconds
get_Bounds
System.Runtime.InteropServices
System.Runtime.CompilerServices
System.Resources
u.Properties.Resources.resources
.resources
DebuggingModes
Matches
GetFiles
System.Runtime.InteropServices.ComTypes
GetProcesses
System.Security.Cryptography.X509Certificates
get_Attributes
set_Attributes
GetFileAttributes
SetFileAttributes
GetAttributes
SetAttributes
AddMinutes
get_TotalMinutes
ReadAllBytes
WriteAllBytes
NextBytes
GetDrives
fFlags
EventArgs
pszArgs
System.Threading.Tasks
Equals
System.Windows.Forms
Contains
set_AutoScaleDimensions
System.Text.RegularExpressions
System.Collections
get_Chars
SslPolicyErrors
errors
get_TotalHours
get_Success
get_CurrentProcess
GetCurrentProcess
set_Arguments
GetArguments
SetArguments
DoEvents
Exists
Concat
Repeat
ImageFormat
ManagementBaseObject
ManagementObject
Select
System.Net
get_Height
get_Default
FirstOrDefault
ParallelLoopResult
GetResult
SetResult
WebClient
HttpClient
System.Management
Environment
get_Current
GetCurrent
get_Content
MultipartFormDataContent
StringContent
HttpContent
ByteArrayContent
ScreenShot
ThreadStart
Convert
GetIDList
SetIDList
SuspendLayout
ResumeLayout
set_RedirectStandardOutput
MoveNext
System.Text
set_Text
ReadAllText
WriteAllText
ContainsText
SetText
get_Now
set_CreateNoWindow
ToArray
ToCharArray
get_Key
GetHotkey
SetHotkey
pwHotkey
get_Assembly
GetExecutingAssembly
CreateDirectory
GetWorkingDirectory
SetWorkingDirectory
op_Equality
op_Inequality
System.Net.Security
WindowsIdentity
IsNullOrEmpty
0T0o0V
0P0T0u
WrapNonExceptionThrows
Copyright
2024
$57E49C7E-C361-4A7F-8890-D665B3B9CB4F
1.0.0.0
.NETFramework,Version=v4.5
FrameworkDisplayName
.NET Framework 4.5
PStub.Install+<Run>d__0, 1, Version=1.0.0.0, Culture=neutral, PublicKeyToken=null
3System.Resources.Tools.StronglyTypedResourceBuilder
17.0.0.0
KMicrosoft.VisualStudio.Editors.SettingsDesigner.SettingsSingleFileGenerator
17.11.0.0
hStub.TelegramAPI.SendDocument+<ScreenShot>d__0, 1, Version=1.0.0.0, Culture=neutral, PublicKeyToken=null
Stub.TelegramAPI.SendDocument+<>c__DisplayClass0_0+<<ScreenShot>b__0>d, 1, Version=1.0.0.0, Culture=neutral, PublicKeyToken=null
$000214F9-0000-0000-C000-000000000046
$00021401-0000-0000-C000-000000000046
]Stub.Help.FileReplace+<Replace>d__1, 1, Version=1.0.0.0, Culture=neutral, PublicKeyToken=null
]Stub.Help.StringHelper+<GetIP>d__36, 1, Version=1.0.0.0, Culture=neutral, PublicKeyToken=null
gStub.Help.Modules.GetStringDownload+<Run>d__0, 1, Version=1.0.0.0, Culture=neutral, PublicKeyToken=null
\Stub.Help.Modules.Loader+<Run>d__0, 1, Version=1.0.0.0, Culture=neutral, PublicKeyToken=null
_CorExeMain
mscoree.dll
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<assemblyIdentity version="1.0.0.0" name="MyApplication.app"/>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v2">
<security>
<requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3">
<requestedExecutionLevel level="asInvoker" uiAccess="false"/>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
))))+)Q
#"$"%"'&)(+*
gxCuL9QnRsFcOkvB
=ax+C?
Z(!w+$%
.<(.!
)$%u^g+d
J>\92(R"
Kz,?R6\(K-
#1-[9B
Z3X5uRLv
752:>T0
78\+/=K.
`F'9.9$%
)><+25'DzEb,
9tA"Q#
K;B9L9
""{1<c
t7>cf;?@~Q
(!9A$+I{
455@u/
W8f?:P
#<$=<E
+)Rw)=s
?/v$>N =?=1&
{?uZ-]`
$:B/"3XN4O3=
#.x</
G~Eb"4
8.@s$|Y&8Q
K0(V6
D9V0 `>
M#L?\a
9r&{[5](>
3X00"+,M
6~ ) 1# 6
4,_,w8}Xh
63=%E47
47-FzOf"g
:O;:j4~28?!!
xb).@~
|_1{>
:5#"3;)o)
!C%>a>
v2"1;&i6[
xS$(c?:P
T(9'._
7A/h(
Kp%)Ah
7zUJ.-
$K;0uXd"
~73XE5
ti\3$$
>T4q,)N
!-=?FtSh
v$%Eb#
2Y7!?W
4|:2z
x?\36rV
TJ1B!\97e
56U3XA
?Eb?*>t
.y(D+7
%|/,&
1>,$S++
".V3$!
rF&j4;
=2(&"X
f6?V9<
84m&=`
57Z3X0
4&,5Eb&
2,|(N5
2Av#.z)
'=-(%
z% L<T3/3%/
%%!->0
7:+ uV>,'E
#_#Z=?:P{
z:,u^:9#)
I1;={$fF6%6
4T<V78
w.4>T@p-
`6(:6)P
0}P68!2
2".B05;2
!(D%V2'"4T
)N9_ *
I)">H<
~6'2#?
1&6Wh$9
I#$:J#
1R!3$;}
>0/?5w
4!0:Pv
>$~5"*
(|)%&Eu2
*fFt'y
q(_37
)(/9K#
2,j&,;3XA,
@=P)6"9+-{
z9'>T>,
a%9?*2%)
/Eb-+0<4
z >I?9
q!.uM#j
*+2?mi
[ %)0
9%%N"X
17Z*.E3U
"9Eb,
/)*)/>we(5A
c(.@~4;
&=<|^
7()pW+*
-z_-_L360
-#P&X`@w
84z" ;
XN:%I.
+^>['
v%3>T5"M
w]Cv6 0&\
$,T-5?
_`KrT,X
p;8rbV56'0
_*?u';=
0/& :P
[%6;K.
LyQ%#"G
:#5Op#
C %k0$-
_Os45r?9
*B#"3X8
t295J2
3R>=C2
15[$)"!4=.
'j<?*)6
94"Eb]c
2C$r)+';
p%(^"?:
g=$>:P
NiZ1#%
w^8!)O3$
5128L4-!
,S:'3y|
::/"qB4C
:7>6v&:J
{:3;_O$#
v?0v%#Eb+
xKg6.@
#++D2&$
*83|!Ew
g&0=q3
W&4w&7
$s_p=
[ - #22"4xX0]%)tQ5
r[.=#t6
3;$?N"&
>TN0/<w(
;ng[18q4~
*,+!L*$
94B?Eb-kG3:*
0(X?].@r
/a#(|-%#3:
"r7.YB*&I
f?!2qQ!:'w
?&,3'1
4[x\%(U0
u} -;E
)4"G(n9
e+p23X587
> C>T(wB{}()%
$-{&=c
%/Eb ;K..y#!8"
?%/#k6;
]71#0~'
z2)wL0
M)qiZa
S=)?n
2t<$/|##
j;'+-
1$5$\
U t-%n-]f
Q3X3%_
.1>?$(!+?F
+>269Eb\
*}%*.@
C78k71
q!0"8#S<45E
|_7)!A.
,1'";$?
Ow#z[ V
uU1#;3
6-^2)%1
;]8&*B?
998% 7
u;=T?
;D;`38c$
4&XiYk65Z%
<2$>L-]f
,;$^"%
z&"M#*
,-Ar/-ce$
9s/3X;s3
961570;3@z[8g
>T@*$.V
*ne$&1<
"/,B(Eb\6
_!*M5s
@+=<Aq|;
;A+ ~8;;3J9-
* +VNqB
Aq,6K3
-k94'"
tWg4k8
1'3;$R3/-
"%6'r"Z6!?
Eb]62/
-`J"1>\
%%!`dW'F.
I?90=-%
Jp2<R-]
>T)3/xu9
$.<33(
&.{@+Q
~|/!)
D)V3pG%W:
"!0=)w
(Z7B'&<
E0!*!D7
W~&'0"
*<vT=:4>l-]`
uQ.S,%
1A(G)@< 0=7'3X2vP<5
'li_$!
SC>T2!
"5rZ7&D
"/5K?FyO<
%=`5,(
"EbY6J
-y!5/Q
r4%!B8 ;
,?@!,.@
(O#0)
|X8!5!
!6C%&;
+5A)[!
9s)z.7$"3(F
u+)<2
>w%3XA5
[?]a"/
?Fyj)
C=Eb*3&'[+3
)Z!6p5{R1(*Iu%
!)n)+?
pR8ZD%1
6[?47%2
k#:Pw34'V
G(Qc58sR
9`%%))R
6;V-]`
wSB>T>p
453/~!@
?Fzm"-$
@) {u0
qd\.@q[:]
06<,D.
qhV**uV
)3518P']0D
%7+i"-
&Kw9.XB+
@.S:!;
K1&"r-]
,4|?#-#
?-53X8!
0"w9_d
76Eb($
$+|<>9#
%#46) +s
p9.c#!%6
A1G'^ &7
66:Pw8E
`!>$<>
;!@8a4,
2:K>Y(
?wT~9B6UA&
,5(!-`-]
4/<@97c
:I :1'
t"3X41?
X4:0I)2~Eb# @
qP-:?%
'RDvP3z6
$W8%%6:P
X`, Gr
^7*(6~Zv
$0K*B.A-]
S5(0=''
-M5Eb\
@"15&G
K4)=K1
:P},$8
~0&K~$*,
zD:c&#$
x-]e@#&.
Q3XOqQ4)
Y&>T2z4
7!!08=Eb"3%p3"9
)~86'%w
|;";>)!
+<2tQ*
7_/$T>
G65/!3
^ "%'7
K"M#}h
Q3X:04O
(%5w {
75~8w
|R.)0
!*(Vv9@
2A#Tg+cF<
pCtS:/;
6-u-]j
93X;{6J6"
Zw/G+V
3yX6We?
6)i%\"
q*"$@>t
253z6.|
.9(/E&
J(;5&70
q0Xe$.0<
2:y/A1%
{$)4B%
<.>TI4Mx
%4?F{_%
"<Eb+f
<0!]Eu,N
7.@t)$
#~%$k+
/IcZ"@r!|
N&V4pA?
a1s&x#
6SI(B=R
]@1)!u!<z&(
1$@&]3Kq1=R
$5;,1
,j7#4&&w/
6!&At=J!
h<_7)>|*$
"#[#8&!$6
pM(|!X
5=3B;^
9#3=;'
1,M4$
4(:>'5
9N8_61
87&!6
u7!jc9=
^`Y&4#:=
:)]!,=,
68536%$#70p2
}c4'@#
z%I F;s4
043)";
=%15:A0)
>tj'7!80
383QK9
;`(+0+
:0?22,*
0%; p/
.3XG1Q2
%y_$>T(
+"#_5#*
'y)0 &
(< 4),
c)!%6]G
*# 2G)I-]`
d"q)3X@7
0>T?%
v/9,@/a
E{>-?FyC5
7=9Ie
a>5Zx^.
6D.5:1 z_
9.B&~;4
}96&&+U+S
5t73XDz1=
+*#2 ,-D
T().@s$8
"v$-z"(O
|# 4+(
{3O$A!l
!4;L'a7;3"
$V?>k?'+!)
=-%=!
:}8"E$
0&-3{3
!5L:6.@pZ
`G"07
I&,?D?U
X4'+P<XC
J->$s`Z
a0>V%?Eu
-\i478r-{
=J-@;k5_cK
w2J'M?
c#jA2$
>T:2.]
k&,0?#
G&1?'/8s
&)"L#[4
j&[7Ju
!(_+Wa#:P
'r<9c&tR
Kz@)rgX096/
*3$!P3X>()
{L5??830
yZ8>T:
*;EuT,-
P,94(+.&
Y.@~1 ; {
p4+`#,
K %zR2\=K7
%4u,Np/w
80T/u1
t78941+%
4!z$]'D
N'%(64#
qf('/|\
J3"+_A3%6zB.u$
7S,#S61,'
pM/T'-'K
>/5_.7
.=A-^2
89523X<
@6?0A!19X
::>TO+
;?)#t%
Yc4-75
1Q|^5(
+v#.EbW*
L @-q0(
jE.|;N
2;&?(O9
~W%#0;/
15+q4<s
9c':Py
A7'9X0
+>p !31$
]6&/7(<8(P
/?r5$+
FpQ{.46Q
>TOtGxO
6*Y40"L)
0q.-($8+
3+W(+7"
6W-]f?7
>T>-2+x`6
76,5+F%T
@98.j3]g
96*A5
|;>6)
7). .'
C'?"-40
(/&+S0+
p2M-#?Z
>!!'%!;$
X! r/
O9#8qi-
+9,"un
u39_1#
3X1;*+
w\"03?
0{8w"
#N;$'J#|^Ou
9%4+ ?'
?J.9N)
?N?6=8!
{t"]$=
u !$8{_b$.@pR
+0:z%+Z7V4
fF~|]'
3+B=^?<
=:P?$wU2
Z'#w7}Z7t%
9>:o4_&
0!)wh<
gG,1"= ,
>TL,;"w
.u9Y`;
$x;7T5
B(EbX"+66
,6C{Hc
F)@8:.@
q!>2M%
e51.}\"'
vD:_-]
=9&%kb
u\6>=$"P
;`(:"Ju
4E-|%
9?A6*;%.
#3|.$3-
Gw2)_5 1
e2:P|;@#0JuF
=>$)=4)#
S4)06
i8X<?$$
Zg5<0*
6 &G-O5W
*+2/3XD
G62> M
(V(5u+5<E>T4
_ =j9,
0Z?F6T<
EbZ;Ds
=4)>9_`
1"L ~M%6
R4?a2
@6se\&J.7w
#4G>T~<A
uP%Y!3UK
0>kc#j
u-'_<w
$3;>T2.
$;$9&=
0);?5j>7*
?F}O`6'5
;"59-)Eb 3&
0;^-94
=)A.He+
!-|!5u*
r/!h7"
;K &F!:
O6=;J#
q5!]>/?/0@u
2\7>2/
C8q-]
V'<,#>=;C
u)& Oq
G>TN*3"V
K~;7%'
4&="'&
5',5{=
1uEbV&
*G52N7B
F$|^
*`D1/v.
-=6"6
>>j8w&:
'tQ"Z
Ty^.s @
B.o-]d#)
%H07*A
P!?7-
-u"+5G"
8YDsS;?F{X&
,;,"xS
Eb[07w6?
,0&4#ic
xe6:&~&
"'/q#*)
$#?%.{
2/S& d
p@6Ih<8
;(,3pT?
5?5|*@
6)~35-
pA)I5[5
#%U*r
O;><5?}~
S%qQNr
/)S$z7+
6={L=R
?Fzi(0
<(E56.u
:%/5~?
949lf%cE<|*:
)*\!p*M
d#"%)[y
24t"tL)
+9:Pz>=%*;!=6O#
V Z7&t
r1&*C/
w(3X7v
u8Jf?
>T?&L*
L+ch]+D>
Eb_:0?+
'3-2+"
)>,%-J9
?|(5'*M!
q_!);+k%/='0/
,096$>\A&
>8%>"?
7&/!!14Ce
>("4R;"F%Le&8
+t$<kd
-`&*%
Z3XD'Q(v
4I744"
,U+4-!{
""8.>T4-.{
7t#I?Fu\
(<-,3
D!R5/$
# v9"#
<C;:6&'
,W~_56
q3Kw7ur&
Q55G=l
u3)XG*V(
-K%*k
Z$)?=4F-
(T{3A(
Eb)k)0.<%
95/>? #
3&,J+Ax|h
'9p'(Y3!^
{j`W5$
7,R.;G&Z
@; $H3V
;/77:u
M-]k5t
?!Gr:+
AvC-nh&jE
*(4>T<
tJ`%f$
&*+{%5i
"M9-+9
""6S<p
@u9&u4X
&$V3XN6
3$>TN-'$W
6,$Eb#1
==Nt24"D
w|:/#
?*"<'*?C
p=&s0+6%
;~A6%
+r8 '9
,dD:Px
&\7)sP,
06./?Y:6,9
u&!=/$
V3XCsR
-<>T:2*i2Z0
-<2 0L?FyK
Xd"$2(R:
%'!3|\D
7j <$:R2
^-q%{s<
q&+%2!j'#
/,6/H>"
?O!M.@g
<( +w8:"
tZ3X0)
;qG=H?
'EbY'5
Gyh2*.@
u7&_%"(
x\;9#"
aJ02xX
6mg/1$'Q}
zPi7.@
0x//3
I$6%'.%
a9!2<!>u
==7q% "
=r)^ ;+
-]eGu.
$>T259x
:3{EbZ%!>
)ad><>
ZG#^,"
:(-u^2*a
y`!"&E4 .:$(
tz6:='
KtF?a)"F/ ;Nv
33@049SW
-= M"M
;>T: !
Nq2~Eb#01
>.@~7!
10|,A
%r;]g5
>%a@t9y
+> #*r9
=ax+C?
HdXaFt4>
""?Dxk
"r#]g6>
'[3Z7v
g1;w5'*
>{D8O087
0z\"-*
}67kB!;
r48^0*
$aB9x
5+3G(i
Z=p- %/
}w7_?$.
/v4-\-_f9q:y8#z5?
0;t5)#
#P9#Nt
6&%23Z8
yzh+7G
*('yc!4f7p5
E`];E4!
k##Q$9
04s-_f"+
[;=(>#U3Z2
3.9 C>VO ?$XV
++06<J
E`\* 23=
L$Y48~#
2=1=Ju>
tZh/j5
0R9w'}
|R!:RO-M.m
Gq M.-{`2
"2)[="
"F<h`Y
5s%9=B
XB'Q,+1"]
[gZf)-
T$(,(3
9>>/Q<
>3?-(5
2 Z)*:u%M
[3Z;uR<
G#X<8c@(5y:;
'4>V>z
?37/%9?D~l
L"E`)8
~`<$k
*92%)[".B
&,s&/r
~(.z="
5c71
7Mr2%L
+;6L:_
G{$!{G;Qe
-eGr9|
L7*#+6
'/zA-_
<J(%"6~W3Z8
s,!&w
,:,@+G
:Ry/%32
;,(?D=
c7 2>
% $%;y]0)7
;$_/-R>
5"3T?<3
$_%03
w! '/)
<e#$$S
w3q7>T`=(
;9/x|((
<[+!A8*
3=/&v
-X#6eF
3ZD3+6%
<XO; K
>VO0MzI5]1Ep
&)4{#}E`We&
&zVb_k#37*
$;u -{
9"%!283
Dw~]$:=K)L~i&]
.,,4z2
. x\.5Q
r.(<533
3!8^-_
)/?C<&c
TO9?<r`)
<>VJ 9
!{~$VKw
P8[+'$+
1D6E`-k
:|!345
s)" G9L:7
;4<,,:z)
~8#$;)("
/%@*V >
.&,8%Nz
:/38;J>V;"
Z,$)2{8-]-_g
It>?J =
tc)8(=
f q["<
2By\`"=$
+u1.sf]`
!/>V9!?xR
>5-!5?D
9K4Q"-<t)
9xE`Yg
t6"1!3
A3G"W>.B
~&@2!
f>r&7^A V;uG
;?G6@t
"<7s4=,
5G<{#=e
<j+#/~.%
#93ZCp=J*
}i'?9J
9&Xh8j
3+)X@{?
r6"}9;;=
2:{"}k6
9s3,7>
?"-=K-
$1J/P+
.3ZC83:9&
l+7:2t+
,?DxT!\*8
5"A4Q8>
2!}E`,j?
4*K0[;9s~.5
x[+>jEu07=
B/E`>c
J/.Bt9&.5{QM{2*@
6Jq0yz
;4),Q515
=%#!=?
I:(%>t
W<D0
,-9#~-_fE
Z!82)w=$W
!2sR3ZA
A>V?wM
L.j"8d
79 ,0
2;)=N&
;hi-75
t3!Qc,
*,~'<
r3yO!_
XC{T>.@
?>:Rz:=2/
&>)]h:"
{_?@4
-[8&%,
2A0;.
10"=8>VM
"P( =)
$A"E`%
;1t#L5
Oh+.Bu3<8!
P8 %&.:y
D/T<,3)
%O0$tM
,-!&S<w
606;l
/65s/vX
xS#)R
y9 # @.
;;w:3Z2
=0$,*|)6
4&>r6+c*
|e#1E
=!/?{;
')~/2 ^
*/?[e_
9(E#Q=,;#w
c17"x;
^<*M?a4
4Z#]?D24.'5
S1;?O;
&9*3#>
!w"<;@+H-_
*D Q=%35
3Z3p&+r
rC$A5Y";
4q8]; r/z
+v8;[8
8l%>40<
I{4<~h<
22w?<6/!2
:>V?t,&@%*#K
4) 8{(_&
*i< .B
:644)x
/c9VcE<46.
; *G,$
0#\>X=?t
7SG{!,
;C#8g&<7
/+|91:#
I{-}z+
\=2 1 ."v#-&
'>VIq=
;="s"f
=8E`V%5w-?*/!
6!+?*j
xW3Y"!-~;>
S:("tL
\d)%E2
"8Jb9!
+?tK!;
@*0!2-;r
?v;?j"+
<*'/5>7+
;4T29k2?(
>>V>:F
A8I9-$J
Gp ;
]8p10w
;B3_ %
QK+ .I
<;0$T-_
<\(8u7|:
;*8(N9VaK
6->>>V6{
?!O$+I&6)H
q!/V"&.B
8Q6> 4,
-23%q:
~ 1t6
O35(03!
(9':m-_`@
'pV5w3}A
")P*qD=s
3Z8(^L'L
+t!*;A
>@'1"~6<
~Sb*$
Bp~S
<)<=,t
&0,294
/o3-%9uV
%/4}!$
3~1: *??DtW(
10;&L{
7?t)/.Bt
,(:/O{Q
;/#s9-(
+~,80
&cKq6v
0~R# k
r8tR?
k 72.R
%(7}. )
c2?()'3v
1u=<z=
m4V15+P
Iu)\g
<%0z>!r!4}
1&~-_0!.;~^
3~t:7.B'
_J&B}`
2 U*(L
e)1~%
r@(_##8@0'
!B*0+&80
)+R,_2
.;!='6@
^,!"'Ve\
3Z:665
r7)_>>
q>zKbZ
5$7.,\/+_
@+S4=(F$
D=C>=(=/
;5$/t-_
1M+@<(
Z$>V52
Qd]0=-;w.Eu
(N&4O$C5H7[k;)~;&q_
&8YE%%
&>?a$
Z7fE.5
+! >tU
O &z^;
C}Rb]"4:R#
";~@2
j!rUv*B11A
6}(g1?$~
tPi\:+%
c ]12wV,
-q ]754!
)-~&C:1
#?q-_k
=9-[>35
';!-U?
-{^@7!>
Z 1p-
71:$Y4p)
#!4-6%G%E`-
77#lfX.Bq;
~-Ow!
-Oq4'^>V+
?~h-_f
pU3(%+Vi
9a>$.7;
+89q"vSB5/6.3
2"Ap1!
:B<E`&$
:#.q<%?649*
tL9Zd6K
#'%2u'z]cWjE
*0~l:$
}~-_eD1T
I D{ae
+3ZC6-A
Q3="*p
4V=1B{t
.9E`V18/
^A5#<{i;
Xa*';-
t z%0#
9Q> d)
=~E`$*
\0/.Bs
#1~]E
4*4;t7#R;70*
:`65W.
8%+V/
Oq8$l0
9$8#{
>93>V;
3AtD.]$%
6<$5-97)
'%<=$R2!
3Z=w>L
"U$R8>VL2
c"\<>>5+R
2wT=q1=
;|>E1=3(
X$80~\82
K9#)}>
"*{5_$F
{644?4 }
!((,tOg*
3Z3{*"
"#W! D
-.3>V@,9
8 Aq!'=$7$4(
}^i%.Bu
%'Mf=0?!~/2+Q
-zn;Xc8
8"'5.*
g/a@ ){]
4Tg8;;
IpA"`987
9 Q+]E7T
vG;^-_k
=K+Z6A
#(F$69.'
:E`[00#
A0@"~!
(D2&,\
~i5;=$
?"R- !w-
r%-c&_
""?;D-
2(k"4
#"J";3A:RyRD
R>$1!w
4Ng9g>/
!>6.'+M)
1=87"!}Z4]7
w'>;A(U 4
=)t(4"E"T!R
J1=5E`(g
?P+1:07
Bq) !F&S0
0$%%x*#:/
?1{T({
%(7=;5&)
":12p0
>,%4u1
XBv/,wB
0z_' 76"
3,%N*$-z?
{&.C5Y'J
:=?3*+O-76s
)2>VK:%8L%9<B!
Nt&y@9Wd
V"S51$
r+- #')
7':v/5'!(
0{Q)Z8>
@h<j",!
38]#u"O
eV`J)
{A~\':d47
Xg?":yRN{0
"3Z7'Q!
?+@5WbV
75"J,0&mi
9"Q-]&$/
%:Rw]@8+!7"y\:
,:]8?0=.
;,z72)
=0)D>^-_
:_*$F-\d
6';&>V?
+$<Op,K!>
i7e%/V
x% $1:R
(=%ii$:
:(3>V3{1
t36%'6
Oc<3F.5
"?DzS<
VO&-"E` g
)4/t3x
-~&0/
;+7.%/
#a`%+;
76171N2
ts-_dF-T+.
&?z%(M
'P4$%=
-3ZC#^90
6=\;0V/
$E`\"0~'
g+$~*
c2) $^B5
%=w#yK
28%sc:
F:m-_cA'0
U3ZAp" qB8
>V<)A*@
=/v%tj
+@v>=r
~'<vV
w+6/@%
/Cf#`"0%5X
3Z</Jt
?;05|^
&j:>7%(0
:R{(8z4
>7< V7
6VK9&#~
'1(M-_d%t!
#%)=?7!P;.
%N?DxC
E`*%*'[y?
V")M9Pc<
5;<O')0vL
5{8+cJ!V-
W&F/~X
%2> Bz"+
rG>`d(
7J1,{^4-1
z/>9}{-_j
!4~z;?
+@&Q6(
/,>V6%
N<*c2s
.|3=(52'1
E` 59
%r~S;
L{A(@89+#W{
,+:-,"V
s!2:"8i? !&
r2*R(V;
: /(xX!w
:R:<$"
8!,7&?
f6;$?#p
-_(%2'z
+'xW<4g"7Wz
Y!Fs }
wT$]55_.9%/l
X;K:3Z3#
-,$!-2*
/6-\<>V47L{
8%E`WcB<;
S`*%A/
,+ie,.Bt+x*/2
~R,u7K
!(4.';0
5"55z8
c5s6zS8,
` 9=:Rv>3
:A}I?)
7)ri_*=- +!
8&Nw=:
;u&?4A(Oi,
5J3 3ZOw
1#N"]jD~
//(+=0
q>*X!4
~\9(A!
9{#'{7L!46ug
3>u7".')o`&+
uQ60?<j-_
7@/|c9$
>VO1>'l4
W3J>.,.A%
U?)#s)"
>zo?/d2u
!=!u69
<\dA'!6'172
!*03R,
Z +*%2~'
>_c!,U:\
9(/<I5?6
>N69!J
:/6 wF
F+_5[=0
!w+- 9+
5 Z3Z>
+-8>V?42!@
0z;$1!3?D
<#"/*3
t$<!,3^
Rb[f;>
(4J([5
xS6Xf
K5_fG4 99
C>P;%&=t4 2='
-&C9^-_
u$>;9r"'&31?.-
{]"$ *
m?%+)1'
!59"8!)
K-D?^$Y.B
,*%xC78c&0
*V=vBz|g!J
;ccVe
!x^7$#?4v
,"A>,1
zPh$jB
5c<"f$-
?*+T3Z2
^4 (J:
&~$?Z#>V@
!'~~!!
'D8]" #
kK(46X7
,\ z1@
?H'=8G
8>VMz,"I
7+:--E`>88!' 2
N{-N"3
-:q-2t'tC`
a9"7512( &$@
)"?+15
=(x&)6K#&z%B:
h?YkA
59 ,8+>A
(u-_`4
<1! )I5%
uG/Z)Y
!3Z2:V
=-q0!q&=f0)(#
q$;r)#k1w
A?~ %
:9481'z
0Q3+A
264=;N
v,'" :?+J?(
{<#0G5
9,+F$T
n5<3>0
3R~,/^
.D%c-_j%u
?@%%3Z3
Q?uF(P
80MpG0
/(_&(30u9
M(\::j
)L%Ft]d
't9?
:$:W!"c9u
Y:>VN62
,0)q&}
/tAf?%
/432)E`*
s$7*$%
6}Z&?d7t
U)R<:/
G>VK6M%]
)%0w'4
8Ne#1Gq4,;
p3+5D0
'+04('=
_,)>;Z
c9q$}>B
0{Q@ 16]
>t-_g#!0?9
w!:%&
>{0= 1?;%
uW|3G(
[4>,1'=Dw
;t~*<
aK+6yX0
<Aq5M!tNi,
=36"8tc
#>33Z<{Q
1zY%>V(9/(
)"z."/
f7w "?
;N?Dy~hZ*
r&;I<X4#0
F#j<8$;
R3z/9K
"51.7.A'=5
>Z6\&qS
<@8,=qM<`9
y82>VJr/.A
c#*86
*>5%,"$
~*=0R
r4/xf=e+
-::^9!6tV!&"6
6?"-;ux
5,23Z3t
(+$'v!
$t. 2B
F.~YE
"Q-_g$
/w$;8%
"4!.3Z@
4.+4!u
>>>VJ0G
9$0%E`+(Du
7>57yV
"$w~-,
s&)v=y~
('>W
IrL/~ [4
28d?q)
<k8&&'56
")p<Z(
+ 3~R
]4p2$
=$B-0+S
(qA4V-_
q34Ax
K.93ZD
q>-{3
w7~?N3=
=:'>VN$
$'\G5+
0+^.z"+`
={q%Y
':{0?0
G{P2wL{wgW8
=.8;J-_
>V@vA:M6?0A
$sU!^
213*2<E`*=ApW;9"$/=
7#-w9,
~]%v#!{B
?5,-'57
s/*w48|
Os2Nv4&oe
{QK.'>\f&k#q6;
8^@z/+-B
((<'"N?Dy@
%!w7=.B
6Z53;0
;l>]?J
[g*K0
,`7!3,!
59& ym
6&%3W
;8E`&(!
_N,2tO"
~R$!
_;A/V
3P+(G8
0>P`W&F '
Gu7<pC
4!"62:Xb[
7(:16+)q?;x5,dB
!-%4;q
)(&3Z12$+-
L?Ji,8
~.<)!5
=uA!,7
;27;\%&24v
?+eB:Rv
*9)U5
M-Z##k>!+
%`-_*
wV.;O%)K,
>V2:'!nh;
N.%)E`&*?p
j"&gAq)!
0&U,z/
s!,.1t@
>N79?@37)
=ax+C3(
OuM5Od[?
D=OgY*F3P!
6V!@rQ)_
wC-M&
+M+Ri\aC7
"B*UcY'
pAz\%V.
%R>Y@r
9J7 G.
(TO9M-\;
(AtV,XN8
=O']`J7
'\6X>F7
I2F6Sa
K:G;T0[kA%
)(_'^j
"O+Y#EtZ
$QA4F|Oe
D/R@3B4J"
4Z,X@7
D=J#['
$H0Z5C3
?W;]C/
.Z`aE#
0[2_#E7
?T4[+A>P%
!@!]f@<
"FuZ![Fr_O;
>I?V!F2
6A&Ui^#
a[>F5[+
yMf^fF<
?O)Z @7
1C{I=^8
.Z`$@3
1WNuE*W4
4vV%R
)F(Z-
+@1W*Y
(B0[2_#
@.L+_"
1B7Q>[BpR
N-B Hi
&5Wy
8T?Z"<
~O7Y*G*U+
x_2V5A'
-C$&C,
fJ3T?^
A,L6C!Ua
S6]eK~-
O%M8M4]#Gv
4_@+E(
F0H$A'S7
"E+U!f
x^f\gAv
>U;]Fq
zT:]*F:
M{B;H6]4
"5T7
1B7Q{X
4L'N?\f
5SKq)
'{Sa
<A6WvR
vT"SEuW
;L~L'V"E(
M-B:E3
3QH1C$
'M'^%G U)
gC(S}]
$A NhV?@<P#^
%@~X?W&
8XcW%G2
;A=Hh\6
2@yO0\5@'
D=S0]4
&C!AfY"F*U)B5U
5Vv[C;P
9J Qv\
*D6Zx^A%
H7M'C<
*XdW'F~
K(L>R9W5
&N4XkG+
O9)S(
'J+Z&@![!
eZ3E5S.R
9G~J2Xe
&H"\*7
+Ly@=Wk@<
@(UNqB S0
7A2WvX
4V#K(Qy
D=Ih^
H9G4K<W*
6'@!Sy
O2SApC4Q4
@rWMz@?N;[k
ApE&I2
rU@'C0[2_#K4
qA?K"d
O FuX55F:
wL;N&Vb
G3RLpB5Jb
#_K:Au
vR@7G+S<
gJ'W'B.Q
]gA"Wv
5@yN4]%
O;L~Kg
zKw(^4
Ng8J-S7_
H;G!E3
&A8A%V5C4
D=OdW5
A;Z*,-
G3_L2Az
1_H+C9\#Yf
+R)X7Eu
~R ]dK7
%C)O=Z.
O&A:Lg
I2B)S=W(
ApB0[2_#
C!TK1C<
#SM4{I-
1A-I)Y5
7Sz_@&P
*N4XbE!
qV!RD,T
.Z`4G>
 G9@'
I2F;Jd]1
Mz@6Ub
0[2_#K~
\?X%Gp
rPH"G<S:
D=T(X<J-
!Wy]@*Wt
I2M>J4]g
0[2_##
{F>Ic]"
/LyH:Z:
%WqC&@
.{Md[7
@uF:Z#
;\)\$EsP#
I2@~_?
@vB)L6
J$9J7Xg
uUw^F)
ZeX9@>V,
<R7[+"
L%F4_-
}H;bF?U'
4L>U+]3
3[=RDt
uL>M?
2WH6C{N(
&AhW'J*
|Ac^:C"
#^(DtS!
.Z`#D-
J0B/@"
I2M$W:
-{J$k
7M-I=^7
7@=Hd[?
)A'\5Wd
9CxWg^!C-
.Z`%D<
u@/JfW:G,
uA0[2_#
Lt)O<
O'@+Ac
:SLtM U
3F&\ "
;A)Oc[(
z\=^bC?
6QikC2
%E Z=^
D=Uf^
@tBuQ$V$C(-
Hz@tZ'
%S6D3
)SH9CuJ$
.Z`5C!T}
u\&ZaK5
0[2_#A'
>LeWjFp-
}Hi^%Gs
;C([dAp
%R>_E7
.Z`'3
I2tK9
.YE:^q
OvF!K:
HqB I<
!@&*A!
<T5_@t
O$Gx]dX6
~Xf\'K(
&Z(V<J1S*
&A-_!Z!E*
0[2_#D5
!W6[ A"
H2E$E3
2T?^D1
@1M$N!
~Q{\C/^
E'C5]`
-E/Z9V:
"Mg\eAr
A(@;W5
Sa[*E2
xNh]eG6
{C([aK:
:E'@6]g
D=C!]#
&ZdX#J"
$Aa^<+
@5@xO+\$
uI)W9J3
I2E5Kg
7PM'@0[2_#K>P?
&L+X:X4
(H;]&E4V6^
1B7U|S
6F+I+>
N7B{Ri
J.G&H5
1M>^):G4
2Y<C1Q|
0[2_#@2
}SC*TA"
r'FtLf
)Tb%Ev-
(AfV8A P)
wRKwL"M<\gK~
.Z`b5
9^fJsTz^
Antivirus Signature
Bkav W32.AIDetectMalware.CS
Lionic Trojan.Win32.Bobik.l!c
tehtris Clean
ClamAV Clean
CMC Clean
Skyhigh BehavesLike.Win32.AgentTesla.gt
ALYac IL:Trojan.MSILZilla.140723
Cylance Unsafe
Zillya Clean
Sangfor Suspicious.Win32.Save.a
K7AntiVirus Clean
Alibaba TrojanSpy:MSIL/Bobik.da04f655
K7GW Clean
Cybereason malicious.afef96
huorong Clean
Baidu Clean
VirIT Clean
Paloalto generic.ml
Symantec ML.Attribute.HighConfidence
Elastic malicious (high confidence)
ESET-NOD32 a variant of MSIL/ClipBanker_AGen.U
APEX Malicious
Avast Win32:RansomX-gen [Ransom]
Cynet Clean
Kaspersky HEUR:Trojan-Spy.MSIL.Bobik.gen
BitDefender IL:Trojan.MSILZilla.140723
NANO-Antivirus Clean
ViRobot Trojan.Win.Z.Wacatac.436224
MicroWorld-eScan IL:Trojan.MSILZilla.140723
Tencent Msil.Trojan-Spy.Bobik.Gplw
TACHYON Clean
Sophos Mal/Generic-S
F-Secure Trojan.TR/Dropper.Gen
DrWeb Clean
VIPRE IL:Trojan.MSILZilla.140723
TrendMicro Clean
McAfeeD ti!B867D368D459
Trapmine Clean
FireEye Generic.mg.556a8b2afef96f81
Emsisoft IL:Trojan.MSILZilla.140723 (B)
Ikarus Trojan.MSIL.Basic
GData IL:Trojan.MSILZilla.140723
Jiangmin Clean
Webroot W32.Malware.Gen
Varist Clean
Avira TR/Dropper.Gen
Antiy-AVL Trojan[Spy]/MSIL.Bobik
Kingsoft MSIL.Trojan-Spy.Bobik.gen
Gridinsoft Trojan.Win32.Agent.vl!n
Xcitium Clean
Arcabit IL:Trojan.MSILZilla.D225B3
SUPERAntiSpyware Clean
ZoneAlarm HEUR:Trojan-Spy.MSIL.Bobik.gen
Microsoft Trojan:Win32/Znyonm
Google Detected
AhnLab-V3 Trojan/Win.Generic.C5654148
Acronis Clean
McAfee Artemis!556A8B2AFEF9
MAX malware (ai score=80)
VBA32 Clean
Malwarebytes Generic.Malware/Suspicious
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Rising Spyware.Bobik!8.108FF (CLOUD)
Yandex Trojan.ClipBanker_AGen!Y/H1JaYiPPc
SentinelOne Static AI - Malicious PE
MaxSecure Trojan.Malware.300983.susgen
Fortinet MSIL/ClipBanker.U!tr
AVG Win32:RansomX-gen [Ransom]
DeepInstinct MALICIOUS
CrowdStrike win/malicious_confidence_100% (D)
alibabacloud Trojan[spy]:MSIL/Bobik.gyf
No IRMA results available.