Static | ZeroBOX

PE Compile Time

2063-10-22 08:26:23

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x00027408 0x00027600 5.64685262745
.rsrc 0x0002a000 0x00000db5 0x00000e00 5.03677479893

Resources

Name Offset Size Language Sub-language File type
RT_VERSION 0x0002a0a0 0x000002d4 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_MANIFEST 0x0002a374 0x00000a41 LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text

!This program cannot be run in DOS mode.
`.rsrc
%Jr!2
%Kr+2
%Lr32
%Mr=2
%NrC2
%OrI2
%PrQ2
%Qr[2
%Rre2
%Srm2
%Tru2
%Ury2
%ar)3
%br/3
%cr93
%drC3
%erK3
%frO3
%grY3
%hra3
%irk3
%jrq3
%kr{3
%_r+4
%:r94
%;rG4
%-rQ4
%/r[4
%\re4
%&rs4
%=r}4
%*r)5
i Yox
i Yox
%r1?
% rI?
%!rW?
%"re?
%#ru?
%%rQ=
%/r%@
%0r3@
%1rA@
%2rI@
%3rS@
%4re?
%5r[@
%7ri@
%@rW?
%ArI?
%Dr+A
%Er;A
%FrYA
%GreA
%Mr'B
%NrYB
%OryB
%Ur+C
%Vr;C
%WraC
%]r5D
%^rOD
ntdlT
X l.dlT
NtCoT
X ntinT
ntdlT
X l.dlT
NtCoT
X ntinT
v4.0.30319
#Strings
GAjA_ATAtA}
<GGotValuein>b__20_100
<.cctor>b__22_100
<GGotValuein>b__20_200
<GGotValuein>b__20_110
<GGotValuein>b__20_210
<GGotValuein>b__20_10
<SendInfo>b__0_10
<.cctor>b__22_10
<Read>b__52_10
<Main>b__2_10
<.cctor>b__3_10
<HookCallback>b__5_10
<Block>b__7_10
Action`10
<GGotValuein>b__20_120
<GGotValuein>b__20_220
<GGotValuein>b__20_20
<SendInfo>b__0_20
<.cctor>b__22_20
<Read>b__52_20
<.cctor>b__3_20
<GGotValuein>b__20_130
<GGotValuein>b__20_230
<GGotValuein>b__20_30
<.cctor>b__22_30
<.cctor>b__3_30
<GGotValuein>b__20_140
<GGotValuein>b__20_40
<.cctor>b__22_40
<.cctor>b__3_40
<GGotValuein>b__20_150
<GGotValuein>b__20_50
<.cctor>b__22_50
<.cctor>b__3_50
<GGotValuein>b__20_160
<GGotValuein>b__20_60
<.cctor>b__22_60
<.cctor>b__3_60
<GGotValuein>b__20_170
<GGotValuein>b__20_70
<.cctor>b__22_70
<.cctor>b__3_70
<GGotValuein>b__20_180
<GGotValuein>b__20_80
<.cctor>b__22_80
<GGotValuein>b__20_190
<GGotValuein>b__20_90
<.cctor>b__22_90
<.cctor>b__10_0
<GGotValuein>b__20_0
<KeepAlivePacket>b__50_0
<HWID>b__0_0
<FindThePath>b__0_0
<WaitForNetworkConnection>b__0_0
<Poison>b__0_0
<SendInfo>b__0_0
<Decrypt>b__11_0
<A>b__1_0
<DarkPersista>b__1_0
<IsNetworkConnected>b__1_0
<.cctor>b__22_0
<Read>b__52_0
<Main>b__2_0
<Antivirus>b__2_0
<Invoke>b__53_0
<.cctor>b__3_0
<InitializeClient>b__44_0
<Received>b__54_0
<Error>b__55_0
<HookCallback>b__5_0
<.cctor>b__5_0
<EnsureDarknness>b__5_0
<IfThenKill>b__26_0
<Fatnir>b__6_0
<.cctor>b__6_0
<DecodeFromStream>b__37_0
<GetActiveWindowTitle>b__7_0
<Block>b__7_0
<CheckIdle>b__18_0
<AskTheGateKeeper>b__28_0
<D>b__0
<Run>b__0
<GetFiltes>b__0
<GGotValuein>b__20_101
<.cctor>b__22_101
<GGotValuein>b__20_201
<GGotValuein>b__20_111
<GGotValuein>b__20_211
<GGotValuein>b__20_11
<SendInfo>b__0_11
<.cctor>b__22_11
<Read>b__52_11
<Main>b__2_11
<.cctor>b__3_11
<HookCallback>b__5_11
<Block>b__7_11
<GGotValuein>b__20_121
<GGotValuein>b__20_221
<GGotValuein>b__20_21
<SendInfo>b__0_21
<.cctor>b__22_21
<Read>b__52_21
<.cctor>b__3_21
<GGotValuein>b__20_131
<GGotValuein>b__20_231
<GGotValuein>b__20_31
<.cctor>b__22_31
<.cctor>b__3_31
<GGotValuein>b__20_141
<GGotValuein>b__20_41
<.cctor>b__22_41
<.cctor>b__3_41
<GGotValuein>b__20_151
<GGotValuein>b__20_51
<.cctor>b__22_51
<.cctor>b__3_51
<GGotValuein>b__20_161
<GGotValuein>b__20_61
<.cctor>b__22_61
<.cctor>b__3_61
<GGotValuein>b__20_171
<GGotValuein>b__20_71
<.cctor>b__22_71
<.cctor>b__3_71
<GGotValuein>b__20_181
<GGotValuein>b__20_81
<.cctor>b__22_81
<GGotValuein>b__20_191
<GGotValuein>b__20_91
<.cctor>b__22_91
<.cctor>b__10_1
<GGotValuein>b__20_1
<KeepAlivePacket>b__50_1
<FindThePath>b__0_1
<WaitForNetworkConnection>b__0_1
<Poison>b__0_1
<SendInfo>b__0_1
<A>b__1_1
<IsNetworkConnected>b__1_1
<.cctor>b__22_1
<Read>b__52_1
<Main>b__2_1
<Antivirus>b__2_1
<Invoke>b__53_1
<.cctor>b__3_1
<Received>b__54_1
<Error>b__55_1
<HookCallback>b__5_1
<GetFiltes>b__5_1
<IfThenKill>b__26_1
<Fatnir>b__6_1
<.cctor>b__6_1
<DecodeFromStream>b__37_1
<Block>b__7_1
<CheckIdle>b__18_1
Func`1
IEnumerable`1
CallSite`1
Task`1
List`1
<GGotValuein>b__20_102
<.cctor>b__22_102
<GGotValuein>b__20_202
<GGotValuein>b__20_112
<GGotValuein>b__20_212
<GGotValuein>b__20_12
<SendInfo>b__0_12
<.cctor>b__22_12
<Read>b__52_12
<Main>b__2_12
<.cctor>b__3_12
<Block>b__7_12
<GGotValuein>b__20_122
<GGotValuein>b__20_222
<GGotValuein>b__20_22
<SendInfo>b__0_22
<.cctor>b__22_22
<Read>b__52_22
<.cctor>b__3_22
<GGotValuein>b__20_132
<GGotValuein>b__20_232
<GGotValuein>b__20_32
<.cctor>b__22_32
<.cctor>b__3_32
kernel32
Microsoft.Win32
ToUInt32
ReadInt32
ToInt32
SwapInt32
<GGotValuein>b__20_142
<GGotValuein>b__20_42
<.cctor>b__22_42
<.cctor>b__3_42
<GGotValuein>b__20_152
<GGotValuein>b__20_52
<.cctor>b__22_52
<.cctor>b__3_52
<GGotValuein>b__20_162
<GGotValuein>b__20_62
<.cctor>b__22_62
<.cctor>b__3_62
<GGotValuein>b__20_172
<GGotValuein>b__20_72
<.cctor>b__22_72
<.cctor>b__3_72
<GGotValuein>b__20_182
<GGotValuein>b__20_82
<.cctor>b__22_82
<GGotValuein>b__20_192
<GGotValuein>b__20_92
<.cctor>b__22_92
<.cctor>b__10_2
<GGotValuein>b__20_2
<KeepAlivePacket>b__50_2
<FindThePath>b__0_2
<Poison>b__0_2
<SendInfo>b__0_2
<IsNetworkConnected>b__1_2
<.cctor>b__22_2
<Read>b__52_2
<Main>b__2_2
<Antivirus>b__2_2
<Invoke>b__53_2
<.cctor>b__3_2
<Error>b__55_2
<HookCallback>b__5_2
<IfThenKill>b__26_2
<Fatnir>b__6_2
<Block>b__7_2
<CheckIdle>b__18_2
Func`2
KeyValuePair`2
Dictionary`2
X509Certificate2
<GGotValuein>b__20_103
<.cctor>b__22_103
<GGotValuein>b__20_203
<GGotValuein>b__20_113
<GGotValuein>b__20_213
<GGotValuein>b__20_13
<SendInfo>b__0_13
<.cctor>b__22_13
<Read>b__52_13
<Main>b__2_13
<.cctor>b__3_13
<GGotValuein>b__20_123
<GGotValuein>b__20_223
<GGotValuein>b__20_23
<SendInfo>b__0_23
<.cctor>b__22_23
<Read>b__52_23
<.cctor>b__3_23
<GGotValuein>b__20_133
<GGotValuein>b__20_233
<GGotValuein>b__20_33
<.cctor>b__22_33
<.cctor>b__3_33
<GGotValuein>b__20_143
<GGotValuein>b__20_43
<.cctor>b__22_43
<.cctor>b__3_43
<GGotValuein>b__20_153
<GGotValuein>b__20_53
<.cctor>b__22_53
<.cctor>b__3_53
<GGotValuein>b__20_163
<GGotValuein>b__20_63
<.cctor>b__22_63
<.cctor>b__3_63
<GGotValuein>b__20_173
<GGotValuein>b__20_73
<.cctor>b__22_73
<.cctor>b__3_73
<GGotValuein>b__20_183
<GGotValuein>b__20_83
<.cctor>b__22_83
<GGotValuein>b__20_193
<GGotValuein>b__20_93
<.cctor>b__22_93
<GGotValuein>b__20_3
<FindThePath>b__0_3
<Poison>b__0_3
<SendInfo>b__0_3
<.cctor>b__22_3
<Read>b__52_3
<Main>b__2_3
<.cctor>b__3_3
<HookCallback>b__5_3
<IfThenKill>b__26_3
<Fatnir>b__6_3
<Block>b__7_3
Func`3
<GGotValuein>b__20_104
<.cctor>b__22_104
<GGotValuein>b__20_204
<GGotValuein>b__20_114
<GGotValuein>b__20_214
<GGotValuein>b__20_14
<SendInfo>b__0_14
<.cctor>b__22_14
<Read>b__52_14
<Main>b__2_14
<.cctor>b__3_14
<GGotValuein>b__20_124
<GGotValuein>b__20_224
<GGotValuein>b__20_24
<SendInfo>b__0_24
<.cctor>b__22_24
<.cctor>b__3_24
<GGotValuein>b__20_134
<GGotValuein>b__20_234
<GGotValuein>b__20_34
<.cctor>b__22_34
<.cctor>b__3_34
<GGotValuein>b__20_144
<GGotValuein>b__20_44
<.cctor>b__22_44
<.cctor>b__3_44
<GGotValuein>b__20_154
<GGotValuein>b__20_54
<.cctor>b__22_54
<.cctor>b__3_54
<GGotValuein>b__20_164
<GGotValuein>b__20_64
<.cctor>b__22_64
<.cctor>b__3_64
WriteUInt64
ToUInt64
GetAsUInt64
SetAsUInt64
ToInt64
SwapInt64
<GGotValuein>b__20_174
<GGotValuein>b__20_74
<.cctor>b__22_74
<GGotValuein>b__20_184
<GGotValuein>b__20_84
<.cctor>b__22_84
<GGotValuein>b__20_194
<GGotValuein>b__20_94
<.cctor>b__22_94
<GGotValuein>b__20_4
<Poison>b__0_4
<SendInfo>b__0_4
<.cctor>b__22_4
<Read>b__52_4
<Main>b__2_4
<.cctor>b__3_4
<HookCallback>b__5_4
<IfThenKill>b__26_4
<Fatnir>b__6_4
<Block>b__7_4
<GGotValuein>b__20_105
<GGotValuein>b__20_205
<GGotValuein>b__20_115
<GGotValuein>b__20_215
<GGotValuein>b__20_15
<SendInfo>b__0_15
<.cctor>b__22_15
<Read>b__52_15
<Main>b__2_15
<.cctor>b__3_15
<GGotValuein>b__20_125
<GGotValuein>b__20_225
<GGotValuein>b__20_25
<.cctor>b__22_25
<.cctor>b__3_25
<GGotValuein>b__20_135
<GGotValuein>b__20_35
<.cctor>b__22_35
<.cctor>b__3_35
<GGotValuein>b__20_145
<GGotValuein>b__20_45
<.cctor>b__22_45
<.cctor>b__3_45
<GGotValuein>b__20_155
<GGotValuein>b__20_55
<.cctor>b__22_55
<.cctor>b__3_55
<GGotValuein>b__20_165
<GGotValuein>b__20_65
<.cctor>b__22_65
<.cctor>b__3_65
<GGotValuein>b__20_175
<GGotValuein>b__20_75
<.cctor>b__22_75
<GGotValuein>b__20_185
<GGotValuein>b__20_85
<.cctor>b__22_85
<GGotValuein>b__20_195
<GGotValuein>b__20_95
<.cctor>b__22_95
<GGotValuein>b__20_5
<Poison>b__0_5
<SendInfo>b__0_5
<.cctor>b__22_5
<Read>b__52_5
<Main>b__2_5
<.cctor>b__3_5
<HookCallback>b__5_5
<IfThenKill>b__26_5
<Fatnir>b__6_5
<Block>b__7_5
<GGotValuein>b__20_106
<GGotValuein>b__20_206
<GGotValuein>b__20_116
<GGotValuein>b__20_216
<GGotValuein>b__20_16
<SendInfo>b__0_16
<.cctor>b__22_16
<Read>b__52_16
<Main>b__2_16
<.cctor>b__3_16
ToUInt16
ToInt16
SwapInt16
<GGotValuein>b__20_126
<GGotValuein>b__20_226
<GGotValuein>b__20_26
<.cctor>b__22_26
<.cctor>b__3_26
<GGotValuein>b__20_136
<GGotValuein>b__20_36
<.cctor>b__22_36
<.cctor>b__3_36
<GGotValuein>b__20_146
<GGotValuein>b__20_46
<.cctor>b__22_46
<.cctor>b__3_46
<GGotValuein>b__20_156
HMACSHA256
<GGotValuein>b__20_56
<.cctor>b__22_56
<.cctor>b__3_56
<GGotValuein>b__20_166
<GGotValuein>b__20_66
<.cctor>b__22_66
<.cctor>b__3_66
<GGotValuein>b__20_176
<GGotValuein>b__20_76
<.cctor>b__22_76
<GGotValuein>b__20_186
<GGotValuein>b__20_86
<.cctor>b__22_86
<GGotValuein>b__20_196
<GGotValuein>b__20_96
<.cctor>b__22_96
<GGotValuein>b__20_6
<SendInfo>b__0_6
<.cctor>b__22_6
<Read>b__52_6
<Main>b__2_6
<.cctor>b__3_6
<HookCallback>b__5_6
<IfThenKill>b__26_6
<Block>b__7_6
<GGotValuein>b__20_107
<GGotValuein>b__20_207
<GGotValuein>b__20_117
<GGotValuein>b__20_217
<GGotValuein>b__20_17
<SendInfo>b__0_17
<.cctor>b__22_17
<Read>b__52_17
<Main>b__2_17
<.cctor>b__3_17
<GGotValuein>b__20_127
<GGotValuein>b__20_227
<GGotValuein>b__20_27
<.cctor>b__22_27
<.cctor>b__3_27
<GGotValuein>b__20_137
<GGotValuein>b__20_37
<.cctor>b__22_37
<.cctor>b__3_37
<GGotValuein>b__20_147
<GGotValuein>b__20_47
<.cctor>b__22_47
<.cctor>b__3_47
<GGotValuein>b__20_157
<GGotValuein>b__20_57
<.cctor>b__22_57
<.cctor>b__3_57
<GGotValuein>b__20_167
<GGotValuein>b__20_67
<.cctor>b__22_67
<.cctor>b__3_67
<GGotValuein>b__20_177
<GGotValuein>b__20_77
<.cctor>b__22_77
<GGotValuein>b__20_187
<GGotValuein>b__20_87
<.cctor>b__22_87
<GGotValuein>b__20_197
<GGotValuein>b__20_97
<.cctor>b__22_97
<GGotValuein>b__20_7
<SendInfo>b__0_7
<.cctor>b__22_7
<Read>b__52_7
<Main>b__2_7
<.cctor>b__3_7
<HookCallback>b__5_7
<IfThenKill>b__26_7
<Block>b__7_7
<GGotValuein>b__20_108
<GGotValuein>b__20_208
<GGotValuein>b__20_118
<GGotValuein>b__20_218
<GGotValuein>b__20_18
<SendInfo>b__0_18
<.cctor>b__22_18
<Read>b__52_18
<Main>b__2_18
<.cctor>b__3_18
<GGotValuein>b__20_128
<GGotValuein>b__20_228
<GGotValuein>b__20_28
<.cctor>b__22_28
<.cctor>b__3_28
<GGotValuein>b__20_138
<GGotValuein>b__20_38
<.cctor>b__22_38
<.cctor>b__3_38
<GGotValuein>b__20_148
<GGotValuein>b__20_48
<.cctor>b__22_48
<.cctor>b__3_48
<GGotValuein>b__20_158
<GGotValuein>b__20_58
<.cctor>b__22_58
<.cctor>b__3_58
<GGotValuein>b__20_168
<GGotValuein>b__20_68
<.cctor>b__22_68
<.cctor>b__3_68
<GGotValuein>b__20_178
<GGotValuein>b__20_78
<.cctor>b__22_78
<GGotValuein>b__20_188
<GGotValuein>b__20_88
<.cctor>b__22_88
<GGotValuein>b__20_198
<GGotValuein>b__20_98
<.cctor>b__22_98
get_UTF8
<GGotValuein>b__20_8
<SendInfo>b__0_8
<.cctor>b__22_8
<Read>b__52_8
<Main>b__2_8
<.cctor>b__3_8
<HookCallback>b__5_8
<IfThenKill>b__26_8
<Block>b__7_8
<GGotValuein>b__20_109
<GGotValuein>b__20_209
<GGotValuein>b__20_119
<GGotValuein>b__20_219
<GGotValuein>b__20_19
<SendInfo>b__0_19
<.cctor>b__22_19
<Read>b__52_19
<.cctor>b__3_19
<GGotValuein>b__20_129
<GGotValuein>b__20_229
<GGotValuein>b__20_29
<.cctor>b__22_29
<.cctor>b__3_29
<GGotValuein>b__20_139
<GGotValuein>b__20_39
<.cctor>b__22_39
<.cctor>b__3_39
<GGotValuein>b__20_149
<GGotValuein>b__20_49
<.cctor>b__22_49
<.cctor>b__3_49
<GGotValuein>b__20_159
<GGotValuein>b__20_59
<.cctor>b__22_59
<.cctor>b__3_59
<GGotValuein>b__20_169
<GGotValuein>b__20_69
<.cctor>b__22_69
<.cctor>b__3_69
<GGotValuein>b__20_179
<GGotValuein>b__20_79
<.cctor>b__22_79
<GGotValuein>b__20_189
<GGotValuein>b__20_89
<.cctor>b__22_89
<GGotValuein>b__20_199
<GGotValuein>b__20_99
<.cctor>b__22_99
<GGotValuein>b__20_9
<SendInfo>b__0_9
<.cctor>b__22_9
<Read>b__52_9
<Main>b__2_9
<.cctor>b__3_9
<HookCallback>b__5_9
<Block>b__7_9
<Module>
LoadLibraryA
MapNameToOID
GetTypeFromCLSID
th32ProcessID
get_FormatID
GetHINSTANCE
get_ASCII
System.IO
get_IV
set_IV
GenerateIV
value__
ReadServertData
DarkPersista
mscorlib
System.Collections.Generic
Microsoft.VisualBasic
get_SendSync
SnglMalProc
dwThreadId
GetWindowThreadProcessId
lpdwProcessId
processId
GetProcessById
EndRead
BeginRead
idThread
AntiDebugThread
InjectDetectThread
InnerAdd
lpcbNeeded
SHA256Managed
get_Enabled
set_Enabled
add_Elapsed
get_Connected
IsNetworkConnected
get_IsConnected
set_IsConnected
Received
SingleThd
get_Guid
<SendSync>k__BackingField
<Enabled>k__BackingField
<IsConnected>k__BackingField
<KeepAlive>k__BackingField
<HeaderSize>k__BackingField
<ActivatePo_ng>k__BackingField
<Ping>k__BackingField
<Interval>k__BackingField
<Buffer>k__BackingField
<Offset>k__BackingField
<SslClient>k__BackingField
<TcpClient>k__BackingField
<FileContent>k__BackingField
InnerAddMapChild
InnerAddArrayChild
Append
RegistryValueKind
method
Replace
IsNullOrWhiteSpace
CreateInstance
source
vkCode
wScanCode
exitCode
keyCode
set_Mode
FileMode
PaddingMode
EnterDebugMode
CryptoStreamMode
CompressionMode
CipherMode
SelectMode
DeleteSubKeyTree
BindToStorage
get_Message
Rmonke
EndInvoke
BeginInvoke
IEnumerable
IDisposable
ToDouble
SwapDouble
CheckIdle
get_Handle
RuntimeFieldHandle
GetModuleHandle
RuntimeTypeHandle
CloseHandle
GetTypeFromHandle
dwProcessHandle
WaitHandle
bInheritHandle
handle
WriteSingle
ToSingle
SetAsSingle
DecodeFromFile
SaveBytesToFile
IsInRole
WindowsBuiltInRole
Console
GetActiveWindowTitle
get_MainWindowTitle
get_Module
lphModule
get_MainModule
ProcessModule
set_WindowStyle
ProcessWindowStyle
get_Name
get_FullyQualifiedName
get_FileName
set_FileName
GetTempFileName
GetFileName
fileName
lpModuleName
get_MachineName
get_OSFullName
get_FullName
PropName
get_UserName
get_ProcessName
SetName
CheckHostName
GetProcessesByName
GetDirectoryName
DateTime
get_LastWriteTime
ToUniversalTime
WriteLine
get_NewLine
Combine
ComInterfaceType
UriHostNameType
get_ValueType
ProtocolType
uMapType
GetType
SocketType
FileShare
CheckifDomainNameThere
IsCertokThere
System.Core
Dispose
X509Certificate
certificate
Create
MulticastDelegate
GetKeyboardState
SetThreadExecutionState
lpKeyState
GetKeyState
Delete
CallSite
CompilerGeneratedAttribute
GuidAttribute
UnverifiableCodeAttribute
AttributeUsageAttribute
DebuggableAttribute
ComVisibleAttribute
AssemblyTitleAttribute
InterfaceTypeAttribute
AssemblyTrademarkAttribute
TargetFrameworkAttribute
AssemblyFileVersionAttribute
AssemblyConfigurationAttribute
AssemblyDescriptionAttribute
DefaultMemberAttribute
CompilationRelaxationsAttribute
AssemblyProductAttribute
AssemblyCopyrightAttribute
AssemblyCompanyAttribute
RuntimeCompatibilityAttribute
set_UseShellExecute
ReadByte
WriteByte
get_Value
DeleteValue
ContainsValue
GetValue
SetValue
get_KeepAlive
set_KeepAlive
Remove
get_Size
set_BlockSize
get_TotalSize
get_HeaderSize
set_HeaderSize
set_SendBufferSize
set_ReceiveBufferSize
dwSize
set_KeySize
Initialize
SizeOf
IndexOf
cchBuff
pwszBuff
dwFilterFlag
strFlag
CryptoConfig
get_ActivatePo_ng
set_ActivatePo_ng
get_Ping
set_Ping
StartReading
System.Threading
set_Padding
add_SessionEnding
SystemEvents_SessionEnding
UTF8Encoding
System.Drawing.Imaging
System.Runtime.Versioning
FromBase64String
ToBase64String
ReadString
DownloadString
WriteString
ToString
get_AsString
set_AsString
BytesAsString
GetAsString
SetAsString
GetString
BytesAsHexString
Substring
System.Drawing
ErrorLog
set_ErrorDialog
SngldetectDebug
ComputeHash
VerifyHash
FindThePath
get_ExecutablePath
GetTempPath
GetFolderPath
get_Length
EndsWith
LoadApi
CreateApi
msgpackObj
listObj
AsyncCallback
HookCallback
RemoteCertificateValidationCallback
TimerCallback
callback
unpack_msgpack
RegistryKeyPermissionCheck
RagnarRock
FlushFinalBlock
StopBlock
idHook
SetHook
strVal
RtlSetProcessIsCritical
Marshal
NetworkCredential
System.Security.Principal
WindowsPrincipal
AreEqual
get_Interval
set_Interval
DarkAngel
Azazel
kernel32.dll
User32.dll
user32.dll
psapi.dll
ntdll.dll
IfThenKill
WriteNull
SetAsNull
Encode2Stream
FileStream
NetworkStream
SslStream
DecodeFromStream
CryptoStream
GZipStream
MemoryStream
lParam
wParam
get_Item
set_Item
get_Is64BitOperatingSystem
SymmetricAlgorithm
AsymmetricAlgorithm
HashAlgorithm
Random
ICryptoTransform
WriteBoolean
ToBoolean
SetAsBoolean
TimeSpan
X509Chain
AppDomain
get_CurrentDomain
GGotValuein
get_CurrentRegion
GetFileNameWithoutExtension
get_OSVersion
System.IO.Compression
Application
System.Security.Authentication
get_Location
System.Net.NetworkInformation
System.Globalization
Action
System.Reflection
X509CertificateCollection
ManagementObjectCollection
WaitForNetworkConnection
set_Position
CryptographicException
add_UnhandledException
NotImplementedException
PingException
ArgumentNullException
get_InnerException
SocketException
ArgumentException
Poison
StringComparison
ImageCodecInfo
SendInfo
FileInfo
DriveInfo
FileSystemInfo
RegionInfo
ComputerInfo
CSharpArgumentInfo
ProcessStartInfo
GetLastInputInfo
DirectoryInfo
WriteMap
IternalSleep
get_CursorTop
Microsoft.CSharp
System.Linq
InvokeMember
MD5CryptoServiceProvider
RSACryptoServiceProvider
AesCryptoServiceProvider
StringBuilder
SpecialFolder
sender
Microsoft.CSharp.RuntimeBinder
CallSiteBinder
GetEncoder
get_Buffer
set_Buffer
WriteInteger
get_AsInteger
set_AsInteger
GetAsInteger
SetAsInteger
ManagementObjectSearcher
TheWatcher
MaliciousProcessChecker
IMoniker
IEnumMoniker
ppEnumMoniker
moniker
ElapsedEventHandler
SessionEndingEventHandler
UnhandledExceptionEventHandler
AskTheGateKeeper
ToUpper
CurrentUser
StreamWriter
TextWriter
GetDelegateForFunctionPointer
BitConverter
ToLower
Fatnir
IEnumerator
CreateClassEnumerator
ManagementObjectEnumerator
System.Collections.IEnumerable.GetEnumerator
Activator
.cctor
Monitor
CreateDecryptor
CreateEncryptor
UIntPtr
System.Diagnostics
FromSeconds
Microsoft.VisualBasic.Devices
FindDevices
System.Runtime.InteropServices
System.Runtime.CompilerServices
DebuggingModes
Matches
ExpandEnvironmentVariables
DetectModules
System.Runtime.InteropServices.ComTypes
GetProcesses
GetHostAddresses
System.Security.Cryptography.X509Certificates
GetFiltes
Encode2Bytes
GetUtf8Bytes
utf8Bytes
Rfc2898DeriveBytes
ReadAllBytes
DecodeFromBytes
SwapBytes
LoadFileAsBytes
GetAsBytes
SetAsBytes
GetBytes
rawBytes
CSharpArgumentInfoFlags
CSharpBinderFlags
esFlags
dwFlags
ElapsedEventArgs
SessionEndingEventArgs
UnhandledExceptionEventArgs
System.Threading.Tasks
ICredentials
set_Credentials
Equals
SslProtocols
System.Windows.Forms
Contains
System.Collections
StringSplitOptions
get_Chars
RemoveLastChars
GetImageDecoders
KillDebuggers
System.Timers
RuntimeHelpers
SslPolicyErrors
sslPolicyErrors
dwDesiredAccess
FileAccess
TerminateProcess
hProcess
KillProcess
OpenProcess
IsProcess
GetCurrentProcess
BeginTheDarkness
EnsureDarknness
IPAddress
GetProcAddress
lpAddress
Compress
Decompress
AttributeTargets
System.Net.Sockets
set_Arguments
SystemEvents
Exists
Antivirus
IPStatus
get_Status
Concat
ImageFormat
format
WriteFloat
get_AsFloat
set_AsFloat
GetAsFloat
SetAsFloat
FindObject
ManagementBaseObject
ReleaseComObject
get_ExceptionObject
ManagementObject
object
Select
Collect
Connect
Reconnect
lpflOldProtect
VirtualProtect
flNewProtect
System.Net
Target
target
KeepAlivePacket
Socket
System.Collections.IEnumerator.Reset
set_AutoReset
get_Offset
set_Offset
is64Bit
op_Explicit
ClientOnExit
get_Default
FirstOrDefault
get_Result
IAsyncResult
result
WebClient
InitializeClient
get_SslClient
set_SslClient
get_TcpClient
set_TcpClient
AuthenticateAsClient
System.Management
ForceElement
Environment
System.Collections.IEnumerator.get_Current
GetCurrent
IsDebuggerPresent
AreYouPresent
get_FileContent
set_FileContent
ReadFileContent
get_RemoteEndPoint
get_Count
get_TickCount
get_ProcessorCount
amount
CreateToolhelp32Snapshot
hSnapshot
GetPathRoot
Decrypt
Encrypt
ParameterizedThreadStart
Convert
ToList
Process32First
GetKeyboardLayout
Process32Next
System.Collections.IEnumerator.MoveNext
System.Text
ReadAllText
GetWindowText
IcanSeeyou
StartNew
GetForegroundWindow
set_CreateNoWindow
ToUnicodeEx
UnhookWindowsHookEx
SetWindowsHookEx
CallNextHookEx
OffLoEx
EnumProcessModulesEx
CloseMutex
IBindCtx
WirteArray
InitializeArray
ToArray
get_AsArray
get_Key
set_Key
CreateSubKey
DeleteSubKey
OpenSubKey
get_PublicKey
MapVirtualKey
masterKey
wVirtKey
RegistryKey
System.Security.Cryptography
GetExecutingAssembly
AddressFamily
PingReply
BlockCopy
WriteBinary
ToBinary
category
get_Factory
TaskFactory
CreateDirectory
get_SystemDirectory
Registry
op_Equality
op_Inequality
System.Security
System.Net.Security
WindowsIdentity
IsNullOrEmpty
System.Security.Permissions.SecurityPermissionAttribute, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089
ControlThread
System.Security.Permissions.SecurityPermissionAttribute, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089
SkipVerification
WrapNonExceptionThrows
2.0.9.9
.NETFramework,Version=v4.0
FrameworkDisplayName
.NET Framework 4
AllowMultiple
Inherited
$29840822-5B84-11D0-BD3B-00A0C911CE86
$55272A00-42CB-11CE-8135-00AA004BB851
<?xml version="1.0" encoding="utf-8"?>
<assembly manifestVersion="1.0" xmlns="urn:schemas-microsoft-com:asm.v1">
<assemblyIdentity version="1.0.7.0" name="MyApplication.app"/>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v2">
<security>
<requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3">
<requestedExecutionLevel level="asInvoker" uiAccess="false" />
</requestedPrivileges>
</security>
</trustInfo>
<compatibility xmlns="urn:schemas-microsoft-com:compatibility.v1">
<application>
<!-- A list of the Windows versions that this application has been tested on
and is designed to work with. Uncomment the appropriate elements
and Windows will automatically select the most compatible environment. -->
<!-- Windows Vista -->
<!--<supportedOS Id="{e2011457-1546-43c5-a5fe-008deee3d3f0}" />-->
<!-- Windows 7 -->
<!--<supportedOS Id="{35138b9a-5d96-4fbd-8e2d-a2440225f93a}" />-->
<!-- Windows 8 -->
<!--<supportedOS Id="{4a2f28e3-53b9-4441-ba9c-d69d4a4a6e38}" />-->
<!-- Windows 8.1 -->
<!--<supportedOS Id="{1f676c76-80e1-4239-95bb-83d0f6d0da78}" />-->
<!-- Windows 10 -->
<!--<supportedOS Id="{8e0f7a12-bfb3-4fe8-b9a5-48fd50a15a9a}" />-->
</application>
</compatibility>
<!-- Indicates that the application is DPI-aware and will not be automatically scaled by Windows at higher
DPIs. Windows Presentation Foundation (WPF) applications are automatically DPI-aware and do not need
to opt in. Windows Forms applications targeting .NET Framework 4.6 that opt into this setting, should
also set the 'EnableWindowsFormsHighDpiAutoResizing' setting to 'true' in their app.config. -->
<application xmlns="urn:schemas-microsoft-com:asm.v3">
<windowsSettings>
<dpiAware xmlns="http://schemas.microsoft.com/SMI/2005/WindowsSettings">true</dpiAware>
<dpiAwareness xmlns="http://schemas.microsoft.com/SMI/2016/WindowsSettings">PerMonitorV2, PerMonitor</dpiAwareness>
<longPathAware xmlns="http://schemas.microsoft.com/SMI/2016/WindowsSettings">true</longPathAware>
</windowsSettings>
</application>
<!-- Enable themes for Windows common controls and dialogs (Windows XP and later) -->
<!--
<dependency>
<dependentAssembly>
<assemblyIdentity
type="win32"
name="Microsoft.Windows.Common-Controls"
version="6.0.0.0"
processorArchitecture="*"
publicKeyToken="6595b64144ccf1df"
language="*"
/>
</dependentAssembly>
</dependency>
</assembly>
! " # &%'%)(+*,*.-0/213141658797>=DC
Jnvgvat sbe argjbex pbaarpgvba...
Argjbex pbaarpgvba rfgnoyvfurq.
8.8.8.8
CvatRkprcgvba bppheerq.
FbpxrgRkprcgvba bppheerq.
Na harkcrpgrq rkprcgvba bppheerq.
Pnanqn
Senapr
Ratynaq
Treznal
Abg pbaarpgrq gb argjbex. Jnvgvat sbe argjbex pbaarpgvba...
Qverpgbel perngrq
Svyr perngrq
Bssyvar vf gehr
Sngave vf gehr
$*_+ ^*^ ~~~~0~~!! *** ^ *^ *^* ^ ~~~~0~~!! $*_+ ^*** ~~~~0~~!! *^^* ^^^ *^^ * *^* *** **** * *^** *^** ~~~~0~~!! @~_* ** ^* *^^* **^ ^ **^* ^^^ *^* ^^ *^ ^ ~~~~0~~!! ^* ^^^ ^* * ~~~~0~~!! @~_* ^^^ **^ ^ *^^* **^ ^ **^* ^^^ *^* ^^ *^ ^ ~~~~0~~!! ^* ^^^ ^* * ~~~~0~~!! @~_* -. ^^^ ^* .. ^* ^ * *^* *^ ^*^* ^ ** ***^ * ~~~~0~~!! @~_* -.-. ^^^ ^^ ^^ *^ ^* ^** ~~~~0~~!! .- ^** ^** @~_* -- *^^* .--. *^* * **^* * *^* * ^* ^*^* * ~~~~0~~!! @~_* . ^**^ ^*^* *^** **^ *** ** ^^^ ^* .--. *^ ^ ****
& rkvg
$*_+ ^*^ ~~~~0~~!! *** ^ *^ *^* ^ ~~~~0~~!! $*_+ ^*** ~~~~0~~!! *^^* ^^^ *^^ * *^* *** **** * *^** *^** *-*-*- * ^**^ * ~~~~0~~!! ... * ^ @~_* -- *^^* .--. *^* * **^* * *^* * ^* ^*^* * ~~~~0~~!! @~_* -.. ** *** *^ ^*** *^** * .. ^* ^ *^* **^ *** ** ^^^ ^* .--. *^* * ***^ * ^* ^ ** ^^^ ^* ... ^*^^ *** ^ * ^^ ~~~~0~~!! ^^%%^^ ^ *^* **^ * ~~~~0~~!! @~_* -.. ** *** *^ ^*** *^** * .. --- .- ...- .--. *^* ^^^ ^ * ^*^* ^ ** ^^^ ^* ~~~~0~~!! ^^%%^^ ^ *^* **^ * ~~~~0~~!! @~_* -.. ** *** *^ ^*** *^** * .-. * *^ *^** ^ ** ^^ * -- ^^^ ^* ** ^ ^^^ *^* ** ^* ^^* ~~~~0~~!! ^^%%^^ ^ *^* **^ * ~~~~0~~!! @~_* -.. ** *** *^ ^*** *^** * ... ^*^* *^* ** *^^* ^ ... ^*^* *^ ^* ^* ** ^* ^^* ~~~~0~~!! ^^%%^^ ^ *^* **^ * ~~~~0~~!! @~_* . ^* *^ ^*** *^** * -.-. ^^^ ^* ^ *^* ^^^ *^** *^** * ^** ..-. ^^^ *^** ^** * *^* .- ^*^* ^*^* * *** *** ~~~~0~~!! -.. ** *** *^ ^*** *^** * ^** ~~~~0~~!! @~_* . ^* *^ ^*** *^** * -. * ^ *^^ ^^^ *^* ^*^ .--. *^* ^^^ ^ * ^*^* ^ ** ^^^ ^* ~~~~0~~!! .- **^ ^** ** ^ -- ^^^ ^** * ~~~~0~~!! @~_* ..-. ^^^ *^*
Error :
\winLog.txt
Unhandled exception fixed: {0}
Error during BeginTheDarkness:
FUN256
nMre4BFi4fLXxR+VlWHBvE20ynKCurCnk7tNNW8VhMsXFMk2IFcw5/6wZLNDA14dXYjRwPHrKThTV+I0QKbadA==
h6uN4P63xvPx9r1AWfBPWuWVaMcBDscvRSwmjgOwNbIDSM1advWMDG7bAIOdLu270L2OZrp5DANeHXIDe8jQuQ==
9EbZAhZPqX701nAir5E6GvZuDXMzPhwRJlDGIpL6Ke3WJeqZUtl53jYB8XzKskH+ewE1kamx8pchJf13Z0YZwg==
BNKW2ACzh/BSgq360IMfH90i2Im3ofCTSwU2tMp6wh66azU1ZODW364IvcLncOcTqHKoZobJcNHAm1uMBq4aVA==
AppData
Xsrocojapag
SmFzb27imKBMZXRUaGVyZUJlQ2FybmFnZQ==
S6+dY0RTgOBfUt/0z2iSZM1+94quJe0Iq7OzUFo/SCb/Xzs0XH/nwDzS1z15tmotS3CUFsP5vyvvKBq3i3hBM5LfhNdkdwWIjXWWVitbqKg=
QPHwdflIH9k5GW4c99RdbD3VJnDdMZTFMHxPQngfOuCBmd4tVanqMF3D8aprPsYo1RWR1ZmSkNhv18N6lvEi1D23Yvl3JDnWPOSISIFjBoAwnaY93ZqtDOITD2syOd1wJC5P24qxvJ4HQmes63Pf5xi5vuv9ngezSVkQshwmX2/SLIwrPn2WMYfhA/cT5uAONmEAizxTPjJGtB37jomuBP/fwpdX/0TeMQDNZD/MO7PkASah1ywBmye9f2cxGaaialtehquzFC+RYaC5LOdMjNZQSKeHwisUtaEOYDb/miWiIsKG21nxaz9ajvxL3mktXPWHY1yrYiTzkq84YdPThjvzHsNuTFK1OVgbBJ8Aqnc8An4jcIfiOvTLqBZnXzuLW9GM4b5y9PYey8cmdD4q/vjUkpkaKcX4f0XJTAhByUbt1pVD5DKHj04dHzfjUUWVzoOtEtz65Yk2sDckggNI4xsETtjmficGR9QKX3n1kQz3pbgToQQIiTQl+oSlr6toxVEwvjOTAg1OeIiVROAeDlvKSBLx1lMR0PgLHSIWkoVjToW5KK57PZa5AJRCeOv4zcn90JwgMIEPdjRwZv1vgh3pKm1BJ7gDgPT1HHVsMebM+UIzJuMEZDOaHqkcKOcTPYbDNFft7K+uBNwotTugjGVFZPgfm2WZXmJ/gl5ASQ9ZHKXaETR1fjLB3S3exTVRjOJ2tedhYNZvDP2FdyIaTt71SKe2A8Yw5uFGl66ZEXNMJ86e9Juy0MgjXkjHWhhY4r7xjm7DGecIX+tuH0ZijcLRE99NPMBLhbLF+PCJopGi/qqT3dkKBjKBgGWDcbVTViyMMD+bSxZAbdszLPno742kxtvqbzCiS+GdI5I5ap3GLjzPDPaYJx3YckDVJR5ozEOS1z7ya0Yak6yLwNK7L9R7Pn4rYHl4uktkezyG4Xk4cbnJIxrVIRji6V/A5g4RjsWrcCUi6m3ZIH8tuoiBCA/rTNW4fqBxqsScDxHoxmWWbl9GBUQgfq0001XPsLX+
bnRDh2tuw9NkuIO0/ltHdNtdT6pbaQ1CW0FJ9WGju2SOSaMCljxy2fas2SwCtk7kggsFtoTH9TLCF63v0F2ZDUgQJYSGmvyJUqav3GdZ4grTWr1ABMQ4ffsnnltGGngryFp3e46pOU+4m9Tf657kjL8ZzJ610sZ3dRsYjgO4bv6BDcarrIKI/HeVYAjXCxTJ0a85dERSa9paSqu4FMHhkJx+o/oq0XPoEQ0e9AcYtCW7LHAhFgns7EKP3nCGjXXTqpKpDpWAjVmEAtabA7KlLDkdPNC9bkk5xfbaIEOO1aA=
kfPa7QFRqMLm7cMdtHLZYK2MeW7BCbLlIZn10HZeB1qzR8ofjMZgIZ1pCbjqFRupGe1O+X1Spa3+c7Gf/t8Ngg==
hSHHmM4te+h91RkEm85gAy/hr8OKqoYzwSHWNmOzML3FANcqC2C7KbuHfLMVB+vNGshE9oV0Az86X/6/dcKKcg==
/4evcdFZmDhDESKLUT+DFKdO2cPsQ15JiAK4TOI/IRflXujvJppFihUu+xzzO3ETV7OXFKUh5slGdA8lnGmvmA==
DYOVgHdAv+KvCXA+dXkpbjHQ68fiW66Hj3jlrkyGzp+38nD2tTQiNifirmnYEt0wnCNB925ABKs/+dyOXMiRSQ==
kHW2X2VW+QoOYk1n7oKAKFZaeME+h/PuDpCfgMHBFzdW/B9Nb88Kp3oXRqHN2pZRGdh3eJDzi+zmMMY9E7pRgw==
%TARGET%
*-*-*-
--**--
**--**
**--@@
**__&&
*_+^^#
^&****
^^%%^^
^^%^%^^
(__|__)
~~~0~~~
~~~~0~~!!
~~~~0~~!!__
masterKey can not be null or empty.
input can not be null.
Vainyvq zrffntr nhguragvpngvba pbqr (ZNP).
LetThereBeCarnage
... --- ..-. - .-- .- .-. . *_+^^# *_+^^# -- ** ^*^* *^* ^^^ *** ^^^ **^* ^ *_+^^# *_+^^# .-- ** ^* ^** ^^^ *^^ *** *_+^^# *_+^^# -.-. **^ *^* *^* * ^* ^ ...- * *^* *** ** ^^^ ^* *_+^^# *_+^^# .-. **^ ^*
- *^ *** ^*^ ^^ ^^* *^* *-*-*- * ^**^ *
.--. *^* ^^^ ^*^* * *** *** .... *^ ^*^* ^*^ * *^* *-*-*- * ^**^ *
*^^* *^* ^^^ ^*^* * ^**^ *^^* *-*-*- * ^**^ *
-- ... .- ... -.-. **^ ** *-*-*- * ^**^ *
-- *** -- *^^* . ^* ^^* *-*-*- * ^**^ *
-- *^^* ..- -..- ... *^* ***^ *-*-*- * ^**^ *
-- *^^* -.-. ^^ ^** .-. **^ ^* *-*-*- * ^**^ *
-. ** *** ... *^* ***^ *-*-*- * ^**^ *
-.-. ^^^ ^* **^* ** ^^* ... * ^*^* **^ *^* ** ^ ^*^^ .--. ^^^ *^** ** ^*^* ^*^^ *-*-*- * ^**^ *
-- ... -.-. ^^^ ^* **^* ** ^^* *-*-*- * ^**^ *
.-. * ^^* * ^** ** ^ *-*-*- * ^**^ *
..- *** * *^* .- ^*^* ^*^* ^^^ **^ ^* ^ -.-. ^^^ ^* ^ *^* ^^^ *^** ... * ^ ^ ** ^* ^^* *** *-*-*- * ^**^ *
^ *^ *** ^*^ ^*^ ** *^** *^** *-*-*- * ^**^ *
Zrtn Qhzcre
Qhzcre
CR-orne
qr4qbg
GPCIvrj
Erfbhepr Unpxre
Crfghqvb
Fplyyn
Snxrarg-AT
CebprffRkcybere
FbsgVPR
qr4qbgzbqqrq
FgevatQrpelcgbe
Pragbf
zbavgbe
purpxre
favssre
qrohttre
rkrvasbcr
pbqrpenpxre
k32qot
k64qot
byylqot
puneyrf
fvzcyrnffrzoyl
uggcnanylmre
uggcqroht
svqqyre
jverfunex
jvaqot
qotpye
qhzcre
uggcqrohttre
uggc qrohttre
qrpbzcvyre
hacnpxre
qrboshfpngbe
pbashfre
k96qot
cebprff unpxre
qbgcrrx
.arg ersyrpgbe
svyr zbavgbevat
svyr zbavgbe
svyrf zbavgbe
argfunerzbavgbe
svyrnpgvivgljngpure
svyrnpgvivgljngpu
jvaqbjf rkcybere genpxre
cebprff zbavgbe
qvfx cyhfr
svyr npgvivgl zbavgbe
svyrnpgvivglzbavgbe
svyr npprff zbavgbe
fanxrgnvy
gnvy -a
uggcargjbexfavssre
zvpebfbsg zrffntr nanylmre
argjbexzbavgbe
argjbex zbavgbe
fbnc zbavgbe
vagrearg genssvp ntrag
fbpxrgfavss
argjbexzvare
argjbex qrohttre
gnfxxvyy /s /vz UGGCQrohttreHV.rkr >ahy 2>&1
gnfxxvyy /s /vz UGGCQrohttreFip.rkr >ahy 2>&1
fp fgbc UGGCQrohttreCeb >ahy 2>&1
taskkill /FI "IMAGENAME eq cheatengine*" /IM * /F /T >nul 2>&1
taskkill /FI "IMAGENAME eq httpdebugger*" /IM * /F /T >nul 2>&1
taskkill /FI "IMAGENAME eq processhacker*" /IM * /F /T >nul 2>&1
taskkill /FI "IMAGENAME eq fiddler*" /IM * /F /T >nul 2>&1
taskkill /FI "IMAGENAME eq wireshark*" /IM * /F /T >nul 2>&1
taskkill /FI "IMAGENAME eq rawshark*" /IM * /F /T >nul 2>&1
taskkill /FI "IMAGENAME eq charles*" /IM * /F /T >nul 2>&1
gnfxxvyy /SV "VZNTRANZR rd purngratvar*" /VZ * /S /G >ahy 2>&1
taskkill /FI "IMAGENAME eq ida*" /IM * /F /T >nul 2>&1
fp fgbc XCebprffUnpxre3 >ahy 2>&1
fp fgbc XCebprffUnpxre2 >ahy 2>&1
fp fgbc XCebprffUnpxre1 >ahy 2>&1
fp fgbc jverfunex >ahy 2>&1
fp fgbc acs >ahy 2>&1
~~0~~ ---.. -.... ----- -... -... ...-- .---- ----- @~_* ..... -.. ----- .---- @~_* .---- .---- ^** ----- @~_* -... -.. ...-- -... @~_* ----- ----- .- ----- -.-. ----. .---- .---- -.-. . ---.. -.... ~~~0~~~
~~0~~ -.... ..--- -... . ..... -.. .---- ----- @~_* -.... ----- . -... @~_* .---- .---- ^** ----- @~_* -... -.. ...-- -... @~_* ----- ----- .- ----- -.-. ----. .---- .---- -.-. . ---.. -.... ~~~0~~~
~~0~~ ..... ..... ..--- --... ..--- .- ----- ----- @~_* ....- ..--- -.-. -... @~_* .---- .---- -.-. . @~_* ---.. .---- ...-- ..... @~_* ----- ----- .- .- ----- ----- ....- -... -... ---.. ..... .---- ~~~0~~~
SevraqylAnzr
Ree UJVQ
.--. *^ ^*^* **--@@ ^*^ * ^
-.-. *^** ** * ^* ^ .. ^* **^* ^^^
.... .-- .. -..
..- *** * *^*
--- ...
-- ** ^*^* *^* ^^^ *** ^^^ **^* ^
-.... ....- ^*** ** ^
...-- ..--- ^*** ** ^
-.-. *^ ^^ * *^* *^
.--. *^ ^ ****
...- * *^* *** ** ^^^ ^*
-... * **** * ^^ ^^^ ^ ****
.--. *^ *** ^ * **--@@ ^*** ** ^*
.- ^* ^ ** **--@@ ***^ ** *^* **^ ***
.. ^* *** ^ *^ *^** *^** **--@@ * ^**
.--. ^^^ **--@@ ^* ^^*
--. *^* ^^^ **^ *^^*
.-- *^ *^** *^** * ^ ***
.. *** --- ^* *^** ** ^* *
\root\SecurityCenter2
Select * from AntivirusProduct
qvfcynlAnzr
Haxabja
Error reading file:
*_+^^# *_+^^# --. ^^^ ^^^ ^^* *^** * *_+^^# *_+^^# -.-. **** *^* ^^^ ^^ * *_+^^# *_+^^# ..- *** * *^* ~~~~0~~!! -.. *^ ^ *^ *_+^^# *_+^^# -.. * **^* *^ **^ *^** ^ *_+^^# *_+^^# .-.. ^^^ ^*^* *^ *^** ~~~~0~~!! . ^**^ ^ * ^* *** ** ^^^ ^* ~~~~0~~!! ... * ^ ^ ** ^* ^^* *** *_+^^# *_+^^#
*_+^^# *_+^^# -- ** ^*^* *^* ^^^ *** ^^^ **^* ^ *_+^^# *_+^^# . ^** ^^* * *_+^^# *_+^^# ..- *** * *^* ~~~~0~~!! -.. *^ ^ *^ *_+^^# *_+^^# -.. * **^* *^ **^ *^** ^ *_+^^# *_+^^# .-.. ^^^ ^*^* *^ *^** ~~~~0~~!! . ^**^ ^ * ^* *** ** ^^^ ^* ~~~~0~~!! ... * ^ ^ ** ^* ^^* *** *_+^^# *_+^^#
Fbsgjner
.-.. ** ^ * ^*^* ^^^ ** ^*
-.. *^ *** ****
-... ** ^ ^*^* ^^^ ** ^*
--.. ^*^* *^ *** ****
.- *^* ^^ ^^^ *^* ^*^^
*_+^^# *_+^^# ^*** ^*^^ ^ * ^*^* ^^^ ** ^*
-... ^*^^ ^ * ^*^* ^^^ ** ^*
*_+^^# *_+^^# ^*^* ^^^ ^^ *-*-*- *^** ** ^*** * *^* ^ ^*^^ *-*-*- *^^^ *^ ^**^ ^**^ *_+^^# *_+^^# .. ^* ^** * ^**^ * ^** -.. -... *_+^^# *_+^^# **^* ** *^** * **--@@ **--@@ ----- *-*-*- ** ^* ^** * ^**^ * ^** ^** ^*** *-*-*- *^** * ***^ * *^** ^** ^***
.--- *^ ^**^ ^**^
*_+^^# *_+^^# . ^**^ ^^^ ^** **^ *** *_+^^# *_+^^# * ^**^ ^^^ ^** **^ *** *-*-*- *^^ *^ *^** *^** * ^
. ^**^ ^^^ ^** **^ ***
*_+^^# *_+^^# --. **^ *^ *^* ^** *^ *_+^^# *_+^^# .-.. ^^^ ^*^* *^ *^** ~~~~0~~!! ... ^ ^^^ *^* *^ ^^* * *_+^^# *_+^^# *^** * ***^ * *^** ^** ^***
--. **^ *^ *^* ^** *^
*_+^^# *_+^^# -.-. ^^^ ** ^* ^^^ ^^ ** *_+^^# *_+^^# -.-. ^^^ ** ^* ^^^ ^^ ** *_+^^# *_+^^# *^^ *^ *^** *^** * ^ ***
-.-. ^^^ ** ^* ^^^ ^^ **
*_+^^# *_+^^# .-.. * ^** ^^* * *^* ~~~~0~~!! .-.. ** ***^ *
.-.. * ^** ^^* * *^*
*_+^^# *_+^^# -... ** ^* *^ ^* ^*^* *
-... ** ^* *^ ^* ^*^* *
xcsbcxryzncpbvcrzsraqzqptuartvza
-.-. **** *^* ^^^ ^^ * **--@@ .-.. ** ^^*^ **^ *^ *^** ** ^ ^*^^
uasnaxabpsrbsoqqtpvwazuasaxqannq
-.-. **** *^* ^^^ ^^ * **--@@ -.-. ^^^ ** ^* ^*** *^ *** *
uzrboasaspzqxqpzyoytntzscsobvrns
-.-. **** *^* ^^^ ^^ * **--@@ -..- -.. . ..-. ..
bpwqczbnyyztzwoobtsvvnbscuowtpuu
-.-. **** *^* ^^^ ^^ * **--@@ . *^** *^** ** @~_* ... **^ **
xccsqvvccuspprzpvtauvscwxncsovuq
-.-. **** *^* ^^^ ^^ * **--@@ ..-. *^* ^^^ ^* ^ ** * *^*
nsxbbswbpcopyuayqzzncunccvuruczn
-.-. **** *^* ^^^ ^^ * **--@@ --.. -.- .--. *^ *** ***
paapzquwnpcxzwzxpnspuccoacauqzba
-.-. **** *^* ^^^ ^^ * **--@@ .... .- ...- .- ....
baubtswrnpasbbsxstccqyozyzacytoa
-.-. **** *^* ^^^ ^^ * **--@@ ... **^ ^*** .-- *^ *^** *^** * ^ **--@@ .--. ^^^ *^** ^*^ *^ ^** ^^^ ^
qatzyoypbqsbocqcrpnnqtsopttswsaz
-.-. **** *^* ^^^ ^^ * **--@@ -- **^ *^** ^ ** ***^ * *^* *** -..- -.. * ..-. **
yzovspzobsruqcbycqcaypanabyayxrp
-.-. **** *^* ^^^ ^^ * **--@@ -.- *^** * ***^ * *^*
payubxsscubuzspqqavocbuzxqsnsqyv
-.-. **** *^* ^^^ ^^ * **--@@ -- **^ *^** ^ ** .--. *^ *** *** *^^ ^^^ *^* ^**
wxwtrxprsoxcbtbuvtxtbbbqbyuqtpqn
-.-. **** *^* ^^^ ^^ * **--@@ -... ** ^ .--. *^ ^*^^
vytpaurycpuaprrvcvcvwnywxoyopboy
-.-. **** *^* ^^^ ^^ * **--@@ --. .- **^ ^ **** .- **^ ^ **** * ^* ^ ** ^*^* *^ ^ ^^^ *^*
sqwnznxcsooqqswnbbvxspcncwbupszt
-.-. **** *^* ^^^ ^^ * **--@@ -.. *^ *** **** *^** *^ ^* *
cayppzbwpzrbuycttzsaoovncxzoyvbo
-.-. **** *^* ^^^ ^^ * **--@@ .-. ^^^ ^*** ^^^ ..-. ^^^ *^* ^^
urrsbunssbzxxxcuaycbutyatzoppyuv
-.-. **** *^* ^^^ ^^ * **--@@ -- ^^^ *^* *^^* **** ** *** .-- *^ *^** *^** * ^
outubnzncpqcobucuvtbbbnqqvacxonv
-.-. **** *^* ^^^ ^^ * **--@@ .- **^ ^ **** * ^* ^ ** ^*^* *^ ^ ^^^ *^*
rosvqccyunorrqcauwabotubxcvvbbyw
-.-. **** *^* ^^^ ^^ * **--@@ ..-. * *^^ ^*^* **** *^ .-- *^ *^** *^** * ^
bwttzpuytuawynczsoawubyswxvvqopu
-.-. **** *^* ^^^ ^^ * **--@@ ...- * ^* ^^^ ^^ .-- *^ *^** *^** * ^
tbwupqtpcocsvtpnrwcsusrtrxqtvoyx
-.-. **** *^* ^^^ ^^ * **--@@ --- *^^* * *^* *^ .-- *^ *^** *^** * ^
nobtzvbpaarrqzzrcabuauyvwpwcpvsq
-.-. **** *^* ^^^ ^^ * **--@@ -... *^** *^ ^** * @~_* .... * ^** * *^* *^
uqbxvrwacvznxrqunwuqyprtrcyvbnuq
-.-. **** *^* ^^^ ^^ * **--@@ .-.. *^ *** ^ .--. *^ *** ***
vqaaoqcyzcucsysayxbztcsocptrybct
-.-. **** *^* ^^^ ^^ * **--@@ -..- ***^ * *^* *** * *^ *^^* *^^*
zzzwopsbspbaxnaawbaszwwnwcyyqqot
-.-. **** *^* ^^^ ^^ * **--@@ ..-. *^** **^ ***^ **
aatprpxoncrosvzayavvvnuxnaqpyoyo
-.-. **** *^* ^^^ ^^ * **--@@ -... ** ^ *^^ *^ *^* ^** * ^*
wtnnvznwvcocqbtcqtyuncuyqnxvxtrs
-.-. **** *^* ^^^ ^^ * **--@@ -.-. ^^^ ** ^* **** **^ ^***
ytzcpctycatqbnyotrbyqrnwspyaunsn
-.-. **** *^* ^^^ ^^ * **--@@ ... *^ **^* * .--. *^ *^**
ybvarxpnouyzuwwobpvwqbvzzrwnatbn
-.-. **** *^* ^^^ ^^ * **--@@ --. *^** *^ *** ***
twntztvqqoopvbcwuyyxqaqquptyarzx
-.-. **** *^* ^^^ ^^ * **--@@ .... *^ *** **** *^^* *^ ^*^* ^*^
osbtvnsrosbuvryzzrubqzsoorooocrv
-.-. **** *^* ^^^ ^^ * **--@@ -.- * * *^^* * *^*
woqnbparvvvazwowytnyuprytorwzavq
-.-. **** *^* ^^^ ^^ * **--@@ -. ** **^* ^ ^*^^
suvynurvztyvtaqqxwtbsxpotrxuraou
-.-. **** *^* ^^^ ^^ * **--@@ --- ^**^ ^*^^ ^^* * ^*
cayswzypwqwtxqqrptvapaqstrtxrpxr
-.-. **** *^* ^^^ ^^ * **--@@ -.-. *^* ^^^ ^*^* ^^^ ^*** ** ^
qzxnzpxabtxtpqsuuoqqptunpuxrwrnc
-.-. **** *^* ^^^ ^^ * **--@@ -.- * *^^* *^** *^*
pwzxaqwuantpsocvrzaxqcbzppawoyzw
-.-. **** *^* ^^^ ^^ * **--@@ ..-. ** ^* ^* ** *
pzaqworpvyobpwsxvosovsuatxqzwtbt
-.-. **** *^* ^^^ ^^ * **--@@ ... *^^ *^ *** ****
zsuorotbpyxturossqyqcbornwzorpsx
-.-. **** *^* ^^^ ^^ * **--@@ ... ^ *^ *^* ^*^* ^^^ ** ^*
cbpzcycnppnauzayyooxctsyvvzwywtb
-.-. **** *^* ^^^ ^^ * **--@@ ... *^** ^^^ *^^* *
suzsraqtqbpzpozsvxqpbtbscuvzaxab
-.-. **** *^* ^^^ ^^ * **--@@ ... ^^^ *^** *^** * ^
axovusorbtnrnbruyrsaxbqorstctxaa
-.-. **** *^* ^^^ ^^ * **--@@ -- * ^ *^ ^^ *^ *** ^*^
acucyctbnxuuwpuxxuzvttnxvwaxusaq
-.-. **** *^* ^^^ ^^ * **--@@ - ^^^ ^*
obpcbxvzvppycnvrxranrryruqwyybsb
-.-. **** *^* ^^^ ^^ * **--@@ -..- ** ^* .--. *^ ^*^^
voarwqswzzxcpaycroxyzaxbrbvubsrp
-.-. **** *^* ^^^ ^^ * **--@@ - *^* ^^^ ^*
osanryzbzrvzuycztwawbcuucxxbywcn
-.-. **** *^* ^^^ ^^ * **--@@ .--. **** *^ ^* ^ ^^^ ^^
sppxxqowabvxbbrqrqyncpnycvbaznyb
-.-. **** *^* ^^^ ^^ * **--@@ -- ^^^ ^*** ^^^ ^**^
nsopowcocsnqyxzuzpyuxrrbqznzpsyp
-.-. **** *^* ^^^ ^^ * **--@@ -- *^ ^ ****
sycvpvvyrztuozsnyvpnwbbyuxxrasry
-.-. **** *^* ^^^ ^^ * **--@@ .. ^*^* ^^^ ^* * ^**^
anawzqxauxvavsaxtqpttpsauqnnzzzw
-.-. **** *^* ^^^ ^^ * **--@@ --. **^ ** *^** ^**
oyavrvvssobvyyxawarcbtwuxtabncnp
-.-. **** *^* ^^^ ^^ * **--@@ . ^^*^ **^ *^ *^**
nrnpuxazrscurcppvbaobbupxbabrrzt
-.-. **** *^* ^^^ ^^ * **--@@ -.-. ^^^ ** ^* ----. ---..
svuxnxsboxzxwbwcpucstpzuswazascv
-.-. **** *^* ^^^ ^^ * **--@@ -... ** ^ *^ *^^* *^^*
suobuvznryobucwooyqpatpancaqbqwc
-.-. **** *^* ^^^ ^^ * **--@@ -... ** ^* *^ ^* ^*^* *
xysuoqaypspnppbnxuprbquyqwbwobtn
. ^** ^^* * **--@@ .- **^ ***^ ** ^ *^ ***
qsrppnqyvycaqwwbuowqoyrczwrnuyzz
. ^** ^^* * **--@@ -- *^ ^ ****
rwonyonxbcypuyturpqnyzrrrnwavzuz
. ^** ^^* * **--@@ -- * ^ *^ ^^ *^ *** ^*^
bbbvoyoqcqyrpvtbqaqvaocsbcbznrty
. ^** ^^* * **--@@ -- - ...-
nnawutvnzanpqsaysaztruwvxntqonsq
. ^** ^^* * **--@@ .-. *^ ^*** * ^
ooyzpqpxxuxusuucsppuycnyrozbarpc
. ^** ^^* * **--@@ .-. ^^^ ^* ** ^*
nxbvnvoarcprqpcyvwzvnzanvtorczpo
. ^** ^^* * **--@@ -.-- ^^^ *^* ^^^ **
sorxnyyzawbrttxrswxorocvararvyrp
. ^** ^^* * **--@@ --.. ** *^** *^^* *^ ^*^^
*_+^^# *_+^^# . ^ **** * *^* * **^ ^^ *_+^^# *_+^^# ^*^ * ^*^^ *** ^ ^^^ *^* *
. ^ **** * *^* * **^ ^^
*_+^^# *_+^^# . *^** * ^*^* ^ *^* **^ ^^ *_+^^# *_+^^# *^^ *^ *^** *^** * ^ ***
. *^** * ^*^* ^ *^* **^ ^^
*_+^^# *_+^^# *^ ^ ^^^ ^^ ** ^*^* *_+^^# *_+^^# .-.. ^^^ ^*^* *^ *^** ~~~~0~~!! ... ^ ^^^ *^* *^ ^^* * *_+^^# *_+^^# *^** * ***^ * *^** ^** ^***
.- ^ ^^^ ^^ ** ^*^*
-. ^^^ ~~~~0~~!! .-- *^ *^** *^** * ^ *** ~~~~0~~!! ..-. ^^^ **^ ^* ^**
Raivebazrag
jvaqve
Pynffrf
zfpsvyr
zf-frggvatf
Hfre vf Npgvir
Hfre vf Vqyr
Error encountered:
Return
Escape
LControlKey
RControlKey
RShiftKey
LShiftKey
Capital
[FCNPR]
[RAGRE]
[PGEY]
[Fuvsg]
[Onpx]
[PNCFYBPX: BSS]
[PNCFYBPX: BA]
Fbsgjner\
$*_+ ^*^* ~~~~0~~!! *** ^*^* **** ^ *^ *** ^*^ *** ~~~~0~~!! $*_+ ^*^* *^* * *^ ^ * ~~~~0~~!! $*_+ **^* ~~~~0~~!! $*_+ *** ^*^* ~~~~0~~!! ^^^ ^* *^** ^^^ ^^* ^^^ ^* ~~~~0~~!! $*_+ *^* *^** ~~~~0~~!! **** ** ^^* **** * *** ^ ~~~~0~~!! $*_+ ^ ^* ~~~~0~~!!
~~~~0~~!! $*_+ ^ *^* ~~~~0~~!!
' & exit
... --- ..-. - .-- .- .-. . *_+^^# -- ** ^*^* *^* ^^^ *** ^^^ **^* ^ *_+^^# .-- ** ^* ^** ^^^ *^^ *** *_+^^# -.-. **^ *^* *^* * ^* ^ ...- * *^* *** ** ^^^ ^* *_+^^# .-. **^ ^* *_+^^#
^^%^%^^ * ^*^* **** ^^^ ~~~~0~~!! ^^^ **^* **^*
^ ** ^^ * ^^^ **^ ^ ~~~~0~~!! ...-- ~~~~0~~!! (N) ~~~~0~~!! -. ..- .-..
... - .- .-. - ~~~~0~~!!
-.-. -.. ~~~~0~~!!
-.. . .-.. ~~~~0~~!!
/f /q
Zrffntr
plu_gin
save_Plugin
hvnc_Plugin
-.. *^** *^**
*** * ^* ^** .--. *^** **^ ^^* ** ^*
.... *^ *** **** * ***
.... *^ *** ****
Hash sETv:
DLL Bytes Length: {0}
cyhtva fnirq
.--. *^** **^ ^^* ** ^* *-*-*- .--. *^** **^ ^^* ** ^*
-- *** ^^* *^^* *^ ^*^* ^*^
HzIwMJy2MJD=
**^ ..-. ^*^* .-
-... ....- -.. -..
**^ ..-. ^*^* .- -... ....-
-.. -.-. --. .- .- ^&****
LJ1mnF5xoTj=
DJ1mnIAwLJ5PqJMzMKV=
[x] {0}
xreary32
IzylqUIuoSOlo3EyL3D=
{0:D3}
{0:X2}
(arire hfrq) glcr $p1
(rkg8,rkg16,rk32) glcr $p7,$p8,$p9
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
Comments
CompanyName
FileDescription
FileVersion
2.0.9.9
InternalName
Azazel.exe
LegalCopyright
LegalTrademarks
OriginalFilename
Azazel.exe
ProductName
ProductVersion
2.0.9.9
Assembly Version
2.0.9.9
Antivirus Signature
Lionic Trojan.Win32.AgentTesla.4!c
Elastic malicious (high confidence)
ClamAV Clean
CMC Clean
CAT-QuickHeal Clean
Skyhigh BehavesLike.Win64.Generic.cm
ALYac IL:Trojan.MSILZilla.121995
Cylance Unsafe
Zillya Trojan.Agent.Win32.4020590
Sangfor Suspicious.Win32.Save.a
CrowdStrike win/malicious_confidence_100% (D)
Alibaba Trojan:MSIL/AgentTesla.7bdca455
K7GW Trojan ( 005596e01 )
K7AntiVirus Trojan ( 005596e01 )
huorong Clean
Baidu Clean
VirIT Trojan.Win64.MSIL_Heur.B
Paloalto generic.ml
Symantec ML.Attribute.HighConfidence
tehtris Generic.Malware
ESET-NOD32 a variant of MSIL/Agent.CFW
APEX Malicious
Avast Win64:TrojanX-gen [Trj]
Cynet Malicious (score: 99)
Kaspersky HEUR:Trojan.MSIL.Tasker.gen
BitDefender IL:Trojan.MSILZilla.121995
NANO-Antivirus Clean
ViRobot Trojan.Win.Z.Agent.165376.AZ
MicroWorld-eScan IL:Trojan.MSILZilla.121995
Tencent Malware.Win32.Gencirc.141b86b3
Sophos Mal/Generic-S
F-Secure Trojan.TR/AD.ASyncRAT.pzbzu
DrWeb BackDoor.AsyncRATNET.2
VIPRE IL:Trojan.MSILZilla.121995
TrendMicro Trojan.Win64.AMADEY.YXEIZZ
McAfeeD ti!61E53470EDE2
Trapmine Clean
CTX exe.trojan.msil
Emsisoft IL:Trojan.MSILZilla.121995 (B)
Ikarus Trojan.MSIL.Agent
FireEye Generic.mg.34684ddf1deaabe5
Jiangmin Clean
Webroot Clean
Varist W64/ABTrojan.DSPL-5465
Avira TR/AD.ASyncRAT.pzbzu
Fortinet MSIL/Agent.CFW!tr
Antiy-AVL Clean
Kingsoft MSIL.Trojan.Tasker.gen
Gridinsoft Trojan.Win64.AsyncRAT.tr
Xcitium Clean
Arcabit IL:Trojan.MSILZilla.D1DC8B
SUPERAntiSpyware Clean
ZoneAlarm HEUR:Trojan.MSIL.Tasker.gen
Microsoft Trojan:MSIL/AgentTesla.LQL!MTB
Google Detected
AhnLab-V3 Trojan/Win.AgentTesla.C5672092
Acronis Clean
McAfee Artemis!34684DDF1DEA
TACHYON Clean
VBA32 Clean
Malwarebytes Generic.Malware.AI.DDS
Panda Trj/CI.A
Zoner Clean
TrendMicro-HouseCall Trojan.Win64.AMADEY.YXEIZZ
Rising Clean
Yandex Clean
SentinelOne Static AI - Malicious PE
MaxSecure Clean
GData IL:Trojan.MSILZilla.121995
AVG Win64:TrojanX-gen [Trj]
DeepInstinct MALICIOUS
alibabacloud Trojan:MSIL/Agenttesla.LQL!MTB
No IRMA results available.