Static | ZeroBOX

PE Compile Time

1992-06-20 07:22:17

PE Imphash

d59a4a699610169663a929d37c90be43

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
CODE 0x00001000 0x000013b8 0x00001400 6.34099054829
DATA 0x00003000 0x0000007c 0x00000200 1.11762716823
BSS 0x00004000 0x00000695 0x00000000 0.0
.idata 0x00005000 0x00000302 0x00000400 3.47731642924
.tls 0x00006000 0x00000004 0x00000000 0.0
.rdata 0x00007000 0x00000018 0x00000200 0.199107517787
.reloc 0x00008000 0x000001c8 0x00000200 5.78329742111
.rsrc 0x00009000 0x000285d4 0x00028600 5.42730712225

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x00009338 0x00002800 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_RCDATA 0x00031588 0x00000038 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_RCDATA 0x00031588 0x00000038 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_RCDATA 0x00031588 0x00000038 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_RCDATA 0x00031588 0x00000038 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_RCDATA 0x00031588 0x00000038 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_RCDATA 0x00031588 0x00000038 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_RCDATA 0x00031588 0x00000038 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_RCDATA 0x00031588 0x00000038 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_RCDATA 0x00031588 0x00000038 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_RCDATA 0x00031588 0x00000038 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_RCDATA 0x00031588 0x00000038 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_GROUP_ICON 0x000315c0 0x00000014 LANG_NEUTRAL SUBLANG_NEUTRAL data

Imports

Library kernel32.dll:
0x405064 GetCurrentThreadId
0x405070 ExitProcess
0x405074 RtlUnwind
0x405078 RaiseException
0x40507c TlsSetValue
0x405080 TlsGetValue
0x405084 LocalAlloc
0x405088 GetModuleHandleA
0x40508c FreeLibrary
0x405090 HeapFree
0x405094 HeapReAlloc
0x405098 HeapAlloc
0x40509c GetProcessHeap
Library kernel32.dll:
0x4050a4 WriteFile
0x4050a8 SizeofResource
0x4050ac SetFilePointer
0x4050b0 LockResource
0x4050b4 LoadResource
0x4050bc GetTempPathA
0x4050c0 GetSystemDirectoryA
0x4050c4 FreeResource
0x4050c8 FindResourceA
0x4050cc CreateFileA
0x4050d0 CloseHandle
Library shfolder.dll:
0x4050d8 SHGetFolderPathA
Library shell32.dll:
0x4050e0 ShellExecuteA

This program must be run under Win32
.idata
.rdata
P.reloc
P.rsrc
~ExC[)
Portions Copyright (c) 1999,2003 Avenger by NhT
_^[YY]
kernel32.dll
GetCurrentThreadId
SetCurrentDirectoryA
GetCurrentDirectoryA
ExitProcess
RtlUnwind
RaiseException
TlsSetValue
TlsGetValue
LocalAlloc
GetModuleHandleA
FreeLibrary
HeapFree
HeapReAlloc
HeapAlloc
GetProcessHeap
kernel32.dll
WriteFile
SizeofResource
SetFilePointer
LockResource
LoadResource
GetWindowsDirectoryA
GetTempPathA
GetSystemDirectoryA
FreeResource
FindResourceA
CreateFileA
CloseHandle
shfolder.dll
SHGetFolderPathA
shell32.dll
ShellExecuteA
0"0*020:0B0J0R0Z0b0j0r0z0
1 191J1_1l1
5 5*5Q5V5[5}5
:":2:?:E:I:P:Y:b:s:
;(;8;I;Z;f;k;p;w;~;
<&<.<6<><F<N<V<^<f<n<{<
=">@>}>
50V0{0
0,1D1^1v1
2/2F2]2t2
0 0$0,00040T0X0\0
This program must be run under Win32
.idata
.rdata
P.reloc
P.rsrc
~ExC[)
Portions Copyright (c) 1999,2003 Avenger by NhT
_^[YY]
kernel32.dll
GetCurrentThreadId
SetCurrentDirectoryA
GetCurrentDirectoryA
ExitProcess
RtlUnwind
RaiseException
TlsSetValue
TlsGetValue
LocalAlloc
GetModuleHandleA
FreeLibrary
HeapFree
HeapReAlloc
HeapAlloc
GetProcessHeap
kernel32.dll
WriteFile
SizeofResource
SetFilePointer
LockResource
LoadResource
GetWindowsDirectoryA
GetTempPathA
GetSystemDirectoryA
FreeResource
FindResourceA
CreateFileA
CloseHandle
shfolder.dll
SHGetFolderPathA
shell32.dll
ShellExecuteA
0"0*020:0B0J0R0Z0b0j0r0z0
1 191J1_1l1
5 5*5Q5V5[5}5
:":2:?:E:I:P:Y:b:s:
;(;8;I;Z;f;k;p;w;~;
<&<.<6<><F<N<V<^<f<n<{<
=">@>}>
50V0{0
0,1D1^1v1
2/2F2]2t2
0 0$0,00040T0X0\0
This program must be run under Win32
.idata
.rdata
P.reloc
P.rsrc
~ExC[)
Portions Copyright (c) 1999,2003 Avenger by NhT
_^[YY]
kernel32.dll
GetCurrentThreadId
SetCurrentDirectoryA
GetCurrentDirectoryA
ExitProcess
RtlUnwind
RaiseException
TlsSetValue
TlsGetValue
LocalAlloc
GetModuleHandleA
FreeLibrary
HeapFree
HeapReAlloc
HeapAlloc
GetProcessHeap
kernel32.dll
WriteFile
SizeofResource
SetFilePointer
LockResource
LoadResource
GetWindowsDirectoryA
GetTempPathA
GetSystemDirectoryA
FreeResource
FindResourceA
CreateFileA
CloseHandle
shfolder.dll
SHGetFolderPathA
shell32.dll
ShellExecuteA
0"0*020:0B0J0R0Z0b0j0r0z0
1 191J1_1l1
5 5*5Q5V5[5}5
:":2:?:E:I:P:Y:b:s:
;(;8;I;Z;f;k;p;w;~;
<&<.<6<><F<N<V<^<f<n<{<
=">@>}>
50V0{0
0,1D1^1v1
2/2F2]2t2
0 0$0,00040T0X0\0
UTypes
System
SysInit
KWindows
!This program cannot be run in DOS mode.
`.rsrc
@.reloc
(  (
v2.0.50727
#Strings
<Module>
System.Runtime.CompilerServices
CompilationRelaxationsAttribute
RuntimeCompatibilityAttribute
Microsoft.VisualBasic.ApplicationServices
ApplicationBase
System.ComponentModel
EditorBrowsableAttribute
EditorBrowsableState
System.CodeDom.Compiler
GeneratedCodeAttribute
System.Diagnostics
DebuggerNonUserCodeAttribute
Microsoft.VisualBasic.Devices
Computer
DebuggerHiddenAttribute
System
Object
Microsoft.VisualBasic.CompilerServices
StandardModuleAttribute
Microsoft.VisualBasic
HideModuleNameAttribute
MyGroupCollectionAttribute
RuntimeHelpers
GetObjectValue
Equals
GetHashCode
RuntimeTypeHandle
GetTypeFromHandle
ToString
Activator
CreateInstance
System.Runtime.InteropServices
ComVisibleAttribute
ThreadStaticAttribute
CompilerGeneratedAttribute
m_ThreadStaticValue
get_GetInstance
System.ComponentModel.Design
HelpKeywordAttribute
STAThreadAttribute
System.Net.Sockets
TcpClient
System.IO
FileStream
FileInfo
MemoryStream
Conversions
ToBoolean
System.Reflection
Assembly
GetEntryAssembly
get_Location
Microsoft.Win32
SessionEndingEventArgs
Exception
IntPtr
op_Equality
op_Explicit
Strings
String
get_Length
ProjectData
SetProjectError
ClearProjectError
System.Text
Encoding
get_UTF8
GetString
DirectoryInfo
get_Name
ToLower
Operators
CompareString
get_Directory
get_Parent
System.Threading
Thread
Monitor
Stream
Dispose
set_ReceiveBufferSize
set_SendBufferSize
Socket
get_Client
set_SendTimeout
set_ReceiveTimeout
ToInteger
NewLateBinding
LateCall
ConditionalCompareObjectEqual
Concat
Convert
FromBase64String
Microsoft.VisualBasic.MyServices
RegistryProxy
ServerComputer
get_Registry
RegistryKey
get_CurrentUser
OpenSubKey
DeleteValue
ToBase64String
GetValue
Interaction
Environ
Conversion
CompareMethod
Registry
CurrentUser
SetValue
System.Net
WebClient
System.Windows.Forms
MessageBoxButtons
MessageBoxIcon
IPEndPoint
System.Drawing
Bitmap
Rectangle
Graphics
Process
AppWinStyle
DialogResult
MessageBox
CreateObject
Boolean
ChangeType
RegistryValueKind
Cursor
GetTempPath
WriteAllBytes
get_Audio
AudioPlayMode
IPAddress
AddressFamily
SocketType
ProtocolType
EndPoint
SendTo
Exists
DownloadFile
ReadAllText
ConcatenateObject
get_Chars
ToArray
DownloadData
GetTempFileName
get_Message
LateSet
LateGet
CompareObjectEqual
OrObject
Screen
get_PrimaryScreen
get_Bounds
get_Width
get_Height
System.Drawing.Imaging
PixelFormat
FromImage
CopyPixelOperation
CopyFromScreen
get_Position
Cursors
get_Default
DrawImage
ImageFormat
get_Jpeg
WriteByte
EndApp
FileSystemInfo
get_FullName
DateTime
Environment
get_MachineName
get_UserName
get_LastWriteTime
get_Date
ComputerInfo
get_Info
get_OSFullName
Replace
OperatingSystem
get_OSVersion
get_ServicePack
SpecialFolder
GetFolderPath
Contains
RegistryKeyPermissionCheck
CreateSubKey
GetValueNames
FileAttributes
StreamWriter
Application
get_ExecutablePath
SetAttributes
Delete
get_LocalMachine
FileMode
FileSystemProxy
get_FileSystem
SpecialDirectoriesProxy
get_SpecialDirectories
get_ProgramFiles
Directory
GetLogicalDrives
TextWriter
WriteLine
Command
ThreadStart
SessionEndingEventHandler
SystemEvents
add_SessionEnding
DoEvents
GetCurrentProcess
set_MinWorkingSet
ConditionalCompareObjectNotEqual
System.Security.Cryptography
MD5CryptoServiceProvider
HashAlgorithm
ComputeHash
Module
GetModules
GetTypes
EndsWith
get_Assembly
get_Handle
get_Available
SelectMode
NetworkStream
GetStream
ReadByte
ToLong
SocketFlags
Receive
ParameterizedThreadStart
GetBytes
DeleteSubKey
System.IO.Compression
GZipStream
CompressionMode
set_Position
BitConverter
ToInt32
GetProcessById
get_MainWindowTitle
DateAndTime
get_Now
get_ProcessName
Keyboard
get_Keyboard
get_ShiftKeyDown
get_CapsLock
ToUpper
StringBuilder
get_CtrlKeyDown
Remove
MulticastDelegate
IAsyncResult
AsyncCallback
System.Collections.Generic
List`1
get_Capacity
get_Count
get_Item
user32
user32.dll
winmm.dll
avicap32.dll
kernel32
KERNEL32.DLL
mscorlib
MyApplication
MyComputer
MyProject
MyWebServices
ThreadSafeObjectProvider`1
EnumWindProc
EnumChildWindProc
m_ComputerObjectProvider
m_AppObjectProvider
m_UserObjectProvider
m_MyWebServicesObjectProvider
.cctor
get_Computer
get_Application
get_User
get_WebServices
GetType
Create__Instance__
instance
Dispose__Instance__
lastcap
GetForegroundWindow
GetVolumeInformation
GetVolumeInformationA
lpRootPathName
lpVolumeNameBuffer
nVolumeNameSize
lpVolumeSerialNumber
lpMaximumComponentLength
lpFileSystemFlags
lpFileSystemNameBuffer
nFileSystemNameSize
GetWindowText
GetWindowTextA
WinTitle
MaxLength
GetWindowTextLength
GetWindowTextLengthA
capGetDriverDescriptionA
wDriver
lpszName
cbName
lpszVer
CompDir
connect
apiBlockInput
BlockInput
fBlock
SwapMouseButton
SendMessage
wParam
lparam
SetWindowPos
hWndInsertAfter
wFlags
mciSendString
mciSendStringA
lpCommandString
lpReturnString
uReturnLength
hwndCallback
AddHome
NtSetInformationProcess
hProcess
processInformationClass
processInformation
processInformationLength
Plugin
LastAS
LastAV
lastKey
GetAsyncKeyState
GetKeyboardLayout
GetKeyboardState
GetWindowThreadProcessId
MapVirtualKey
ToUnicodeEx
VKCodeToUnicode
EnableWindow
bEnable
lpdwProcessID
GetClassName
GetClassNameA
lpClassName
nMaxCount
SendMessageA
lParam
lpString
EnumChildWindows
lpEnumFunc
EnumChild
protect
GetChild
TargetObject
TargetMethod
BeginInvoke
DelegateCallback
DelegateAsyncState
EndInvoke
DelegateAsyncResult
Invoke
WebServices
GetInstance
MyTemplate
8.0.0.0
4System.Web.Services.Protocols.SoapHttpClientProtocol
Create__Instance__
Dispose__Instance__
My.Computer
My.Application
My.User
My.WebServices
WrapNonExceptionThrows
_CorExeMain
mscoree.dll
29
5
66666#
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<assemblyIdentity version="1.0.0.0" name="MyApplication.app"/>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v2">
<security>
<requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3">
<requestedExecutionLevel level="asInvoker" uiAccess="false"/>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
PPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADD
extrimhack_csgo_05.03.2023.exePASystem.exePA1PAD1PAD1PAD1PAD&=O8
UTypes
System
SysInit
KWindows
PADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADMZ
!This program cannot be run in DOS mode.
`.rsrc
@.reloc
(  (
v2.0.50727
#Strings
<Module>
System.Runtime.CompilerServices
CompilationRelaxationsAttribute
RuntimeCompatibilityAttribute
Microsoft.VisualBasic.ApplicationServices
ApplicationBase
System.ComponentModel
EditorBrowsableAttribute
EditorBrowsableState
System.CodeDom.Compiler
GeneratedCodeAttribute
System.Diagnostics
DebuggerNonUserCodeAttribute
Microsoft.VisualBasic.Devices
Computer
DebuggerHiddenAttribute
System
Object
Microsoft.VisualBasic.CompilerServices
StandardModuleAttribute
Microsoft.VisualBasic
HideModuleNameAttribute
MyGroupCollectionAttribute
RuntimeHelpers
GetObjectValue
Equals
GetHashCode
RuntimeTypeHandle
GetTypeFromHandle
ToString
Activator
CreateInstance
System.Runtime.InteropServices
ComVisibleAttribute
ThreadStaticAttribute
CompilerGeneratedAttribute
m_ThreadStaticValue
get_GetInstance
System.ComponentModel.Design
HelpKeywordAttribute
STAThreadAttribute
System.Net.Sockets
TcpClient
System.IO
FileStream
FileInfo
MemoryStream
Conversions
ToBoolean
System.Reflection
Assembly
GetEntryAssembly
get_Location
Microsoft.Win32
SessionEndingEventArgs
Exception
IntPtr
op_Equality
op_Explicit
Strings
String
get_Length
ProjectData
SetProjectError
ClearProjectError
System.Text
Encoding
get_UTF8
GetString
DirectoryInfo
get_Name
ToLower
Operators
CompareString
get_Directory
get_Parent
System.Threading
Thread
Monitor
Stream
Dispose
set_ReceiveBufferSize
set_SendBufferSize
Socket
get_Client
set_SendTimeout
set_ReceiveTimeout
ToInteger
NewLateBinding
LateCall
ConditionalCompareObjectEqual
Concat
Convert
FromBase64String
Microsoft.VisualBasic.MyServices
RegistryProxy
ServerComputer
get_Registry
RegistryKey
get_CurrentUser
OpenSubKey
DeleteValue
ToBase64String
GetValue
Interaction
Environ
Conversion
CompareMethod
Registry
CurrentUser
SetValue
System.Net
WebClient
System.Windows.Forms
MessageBoxButtons
MessageBoxIcon
IPEndPoint
System.Drawing
Bitmap
Rectangle
Graphics
Process
AppWinStyle
DialogResult
MessageBox
CreateObject
Boolean
ChangeType
RegistryValueKind
Cursor
GetTempPath
WriteAllBytes
get_Audio
AudioPlayMode
IPAddress
AddressFamily
SocketType
ProtocolType
EndPoint
SendTo
Exists
DownloadFile
ReadAllText
ConcatenateObject
get_Chars
ToArray
DownloadData
GetTempFileName
get_Message
LateSet
LateGet
CompareObjectEqual
OrObject
Screen
get_PrimaryScreen
get_Bounds
get_Width
get_Height
System.Drawing.Imaging
PixelFormat
FromImage
CopyPixelOperation
CopyFromScreen
get_Position
Cursors
get_Default
DrawImage
ImageFormat
get_Jpeg
WriteByte
EndApp
FileSystemInfo
get_FullName
DateTime
Environment
get_MachineName
get_UserName
get_LastWriteTime
get_Date
ComputerInfo
get_Info
get_OSFullName
Replace
OperatingSystem
get_OSVersion
get_ServicePack
SpecialFolder
GetFolderPath
Contains
RegistryKeyPermissionCheck
CreateSubKey
GetValueNames
FileAttributes
StreamWriter
Application
get_ExecutablePath
SetAttributes
Delete
get_LocalMachine
FileMode
FileSystemProxy
get_FileSystem
SpecialDirectoriesProxy
get_SpecialDirectories
get_ProgramFiles
Directory
GetLogicalDrives
TextWriter
WriteLine
Command
ThreadStart
SessionEndingEventHandler
SystemEvents
add_SessionEnding
DoEvents
GetCurrentProcess
set_MinWorkingSet
ConditionalCompareObjectNotEqual
System.Security.Cryptography
MD5CryptoServiceProvider
HashAlgorithm
ComputeHash
Module
GetModules
GetTypes
EndsWith
get_Assembly
get_Handle
get_Available
SelectMode
NetworkStream
GetStream
ReadByte
ToLong
SocketFlags
Receive
ParameterizedThreadStart
GetBytes
DeleteSubKey
System.IO.Compression
GZipStream
CompressionMode
set_Position
BitConverter
ToInt32
GetProcessById
get_MainWindowTitle
DateAndTime
get_Now
get_ProcessName
Keyboard
get_Keyboard
get_ShiftKeyDown
get_CapsLock
ToUpper
StringBuilder
get_CtrlKeyDown
Remove
MulticastDelegate
IAsyncResult
AsyncCallback
System.Collections.Generic
List`1
get_Capacity
get_Count
get_Item
user32
user32.dll
winmm.dll
avicap32.dll
kernel32
KERNEL32.DLL
mscorlib
MyApplication
MyComputer
MyProject
MyWebServices
ThreadSafeObjectProvider`1
EnumWindProc
EnumChildWindProc
m_ComputerObjectProvider
m_AppObjectProvider
m_UserObjectProvider
m_MyWebServicesObjectProvider
.cctor
get_Computer
get_Application
get_User
get_WebServices
GetType
Create__Instance__
instance
Dispose__Instance__
lastcap
GetForegroundWindow
GetVolumeInformation
GetVolumeInformationA
lpRootPathName
lpVolumeNameBuffer
nVolumeNameSize
lpVolumeSerialNumber
lpMaximumComponentLength
lpFileSystemFlags
lpFileSystemNameBuffer
nFileSystemNameSize
GetWindowText
GetWindowTextA
WinTitle
MaxLength
GetWindowTextLength
GetWindowTextLengthA
capGetDriverDescriptionA
wDriver
lpszName
cbName
lpszVer
CompDir
connect
apiBlockInput
BlockInput
fBlock
SwapMouseButton
SendMessage
wParam
lparam
SetWindowPos
hWndInsertAfter
wFlags
mciSendString
mciSendStringA
lpCommandString
lpReturnString
uReturnLength
hwndCallback
AddHome
NtSetInformationProcess
hProcess
processInformationClass
processInformation
processInformationLength
Plugin
LastAS
LastAV
lastKey
GetAsyncKeyState
GetKeyboardLayout
GetKeyboardState
GetWindowThreadProcessId
MapVirtualKey
ToUnicodeEx
VKCodeToUnicode
EnableWindow
bEnable
lpdwProcessID
GetClassName
GetClassNameA
lpClassName
nMaxCount
SendMessageA
lParam
lpString
EnumChildWindows
lpEnumFunc
EnumChild
protect
GetChild
TargetObject
TargetMethod
BeginInvoke
DelegateCallback
DelegateAsyncState
EndInvoke
DelegateAsyncResult
Invoke
WebServices
GetInstance
MyTemplate
8.0.0.0
4System.Web.Services.Protocols.SoapHttpClientProtocol
Create__Instance__
Dispose__Instance__
My.Computer
My.Application
My.User
My.WebServices
WrapNonExceptionThrows
_CorExeMain
mscoree.dll
29
5
66666#
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<assemblyIdentity version="1.0.0.0" name="MyApplication.app"/>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v2">
<security>
<requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3">
<requestedExecutionLevel level="asInvoker" uiAccess="false"/>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
PPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADD
extrimhack_csgo_05.03.2023.exePASystem.exePA1PAD1PAD1PAD1PAD&=O8
UTypes
System
SysInit
KWindows
PADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPAD
DVCLAL
PACKAGEINFO
MAINICON
DVCLAL
PACKAGEINFO
MAINICON
DVCLAL
PACKAGEINFO
MAINICON(
7JU]dkr
Pascal.exe
192.168.0.106
fc73aef52424c65272c4f02cd6b89da8
Software\Microsoft\Windows\CurrentVersion\Run
SGFjS2Vk
Exsample.exe
PascalABC.net.exe
Connect
Software\
SystemDrive
Software\Microsoft\Internet Explorer\Main
Start Page
IEhome
shutdowncomputer
shutdown -s -t 00
restartcomputer
shutdown -r -t 00
logoff
shutdown -l -t 00
ErorrMsg
SAPI.Spvoice
OpenCD
set CDAudio door open
CloseCD
set CDAudio door closed
DisableKM
EnableKM
TurnOffMonitor
TurnOnMonitor
NormalMouse
ReverseMouse
DisableCMD
HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\System
EnableCMD
DisableRegistry
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System
DisableRegistryTools
EnableRegistry
DisableRestore
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore
DisableSR
EnableRestore
DisableTaskManager
DisableTaskMgr
EnableTaskManager
CursorShow
CursorHide
sendmusicplay
OpenSite
udpstp
pingstop
taskkill /F /IM PING.EXE
/pass.exe
https://dl.dropbox.com/s/p84aaz28t0hepul/Pass.exe?dl=0
/temp.txt
getvalue
Execute ERROR
Download ERROR
Executed As
Execute ERROR
Update ERROR
Updating To
Update ERROR
yy-MM-dd
??-??-??
Microsoft
Windows
netsh firewall add allowedprogram "
" ENABLE
taskkill /F /IM
autorun.inf
[autorun]
shellexecute=
netsh firewall delete allowedprogram "
Software
cmd.exe /k ping 0 & del "
" & exit
yy/MM/dd
[ENTER]
taskmgr
processviewer
processhacker
process explorer
button
static
directuihwnd
End process
7JU]dkr
Pascal.exe
192.168.0.106
fc73aef52424c65272c4f02cd6b89da8
Software\Microsoft\Windows\CurrentVersion\Run
SGFjS2Vk
Exsample.exe
PascalABC.net.exe
Connect
Software\
SystemDrive
Software\Microsoft\Internet Explorer\Main
Start Page
IEhome
shutdowncomputer
shutdown -s -t 00
restartcomputer
shutdown -r -t 00
logoff
shutdown -l -t 00
ErorrMsg
SAPI.Spvoice
OpenCD
set CDAudio door open
CloseCD
set CDAudio door closed
DisableKM
EnableKM
TurnOffMonitor
TurnOnMonitor
NormalMouse
ReverseMouse
DisableCMD
HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\System
EnableCMD
DisableRegistry
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System
DisableRegistryTools
EnableRegistry
DisableRestore
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore
DisableSR
EnableRestore
DisableTaskManager
DisableTaskMgr
EnableTaskManager
CursorShow
CursorHide
sendmusicplay
OpenSite
udpstp
pingstop
taskkill /F /IM PING.EXE
/pass.exe
https://dl.dropbox.com/s/p84aaz28t0hepul/Pass.exe?dl=0
/temp.txt
getvalue
Execute ERROR
Download ERROR
Executed As
Execute ERROR
Update ERROR
Updating To
Update ERROR
yy-MM-dd
??-??-??
Microsoft
Windows
netsh firewall add allowedprogram "
" ENABLE
taskkill /F /IM
autorun.inf
[autorun]
shellexecute=
netsh firewall delete allowedprogram "
Software
cmd.exe /k ping 0 & del "
" & exit
yy/MM/dd
[ENTER]
taskmgr
processviewer
processhacker
process explorer
button
static
directuihwnd
End process
Antivirus Signature
Bkav W32.AIDetectMalware
Lionic Trojan.Win32.Rbot.leZz
tehtris Clean
ClamAV Win.Packed.Bladabindi-7994427-0
CMC Clean
CAT-QuickHeal Trojan.GenericFC.S19436243
Skyhigh BehavesLike.Win32.Generic.cm
ALYac Trojan.GenericKD.65811880
Cylance unsafe
Zillya Dropper.Delf.Win32.35091
Sangfor Trojan.Win32.Save.a
K7AntiVirus Trojan ( 004bdc281 )
Alibaba Ransom:Win32/Weenloc.e8c
K7GW Trojan ( 004bdc281 )
Cybereason Clean
Baidu Win32.Trojan-Dropper.Delf.as
VirIT Trojan.Win32.Generic.CKWZ
Paloalto generic.ml
Symantec SMG.Heur!gen
Elastic Windows.Trojan.Njrat
ESET-NOD32 Win32/TrojanDropper.Delf.OEF
APEX Malicious
Avast Win32:Evo-gen [Trj]
Cynet Malicious (score: 99)
Kaspersky Trojan-Dropper.Win32.Delf.eimp
BitDefender Trojan.GenericKD.65811880
NANO-Antivirus Trojan.Win32.Dropper.flagce
ViRobot Trojan.Win32.A.Scar.451584.A
MicroWorld-eScan Trojan.GenericKD.65811880
Tencent Trojan-Dropper.Win32.Delf.waa
TACHYON Clean
Sophos Mal/Emogen-Z
F-Secure Trojan.TR/ATRAPS.Gen
DrWeb Trojan.Packed.20771
VIPRE Trojan.GenericKD.65811880
TrendMicro TROJ_BINDER.SMBD
McAfeeD Real Protect-LS!4336581E9F90
Trapmine malicious.high.ml.score
FireEye Generic.mg.4336581e9f9024a9
Emsisoft Trojan.GenericKD.65811880 (B)
SentinelOne Static AI - Malicious PE
GData Trojan.GenericKD.65811880
Jiangmin Trojan/Genome.bawa
Webroot W32.Trojan.Gen
Varist W32/Trojan.VVWT-8174
Avira TR/ATRAPS.Gen
Antiy-AVL Trojan[Dropper]/Win32.Delf.efnz
Kingsoft malware.kb.a.996
Gridinsoft Backdoor.Win32.Gen.zv!s1
Xcitium TrojWare.Win32.TrojanDropper.Delf.SOC@572vwy
Arcabit Trojan.Generic.D3EC35A8
SUPERAntiSpyware Clean
ZoneAlarm Trojan-Dropper.Win32.Delf.eimp
Microsoft Backdoor:MSIL/Bladabindi.AJ
Google Detected
AhnLab-V3 Trojan/Win32.Ruftar.R30190
Acronis Clean
McAfee GenericRXDR-OQ!4336581E9F90
MAX malware (ai score=80)
VBA32 TrojanDropper.Delf
Malwarebytes Generic.Malware.AI.DDS
Panda Trj/Genetic.gen
Zoner Trojan.Win32.84773
TrendMicro-HouseCall TROJ_BINDER.SMBD
Rising Dropper.Delf!1.C7FF (CLASSIC)
Yandex Clean
Ikarus Worm.Win32.Agent
MaxSecure Dropper.Delf.EFNZ
Fortinet W32/CoinMiner.PAG!tr
BitDefenderTheta AI:Packer.95DCECEC1E
AVG Win32:Evo-gen [Trj]
DeepInstinct MALICIOUS
CrowdStrike Clean
alibabacloud RAT:Win/DarkComet
No IRMA results available.