Static | ZeroBOX

PE Compile Time

2024-04-10 13:41:51

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x00010294 0x00010400 6.03700911317
.rsrc 0x00014000 0x000004e6 0x00000600 3.75169021674
.reloc 0x00016000 0x0000000c 0x00000200 0.101910425663

Resources

Name Offset Size Language Sub-language File type
RT_VERSION 0x000140a0 0x0000025c LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_MANIFEST 0x000142fc 0x000001ea LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with CRLF line terminators

Imports

Library mscoree.dll:
0x402000 _CorExeMain

!This program cannot be run in DOS mode.
`.rsrc
@.reloc
3b%(F
v4.0.30319
#Strings
YHiHeXPpxkxzml5SDwuGEYg7HfZ9YaDggg2pTe5kfwLXXXZRICADximPX4yvFjF10
01wa9vPrIRimw1ol57B0
hlfZrXxLhryedJP1mLD0
oXugmhfGz2nAQ3LG7nLpY1HqKy07TxaWhSsX6fhgfnYPuI7CBI2uNyJ1KbCCJy8E9ZeUwtJi8FwLF0
JYavdVfiPIRWcIG1TKaQHsl6r76DrXjYxN5tGsD5si5Xj4w7yArRrxQKZOKYzvQn9avLrCW4aedqCS9WwI0
6xS6zTR9jVxIvIBujnhm5Ov5js25Mk9Kb2Aak2dx6nzBZD9ILCP1kewpeXcSpiqxUFwRTmkTrJ2Pd0
eRDNoVZYN3um3t6n6SV3vJmd0
ErvXcvwPIJuRew1uHkSVOqNavMcmmL3po12apEXwVBkxT2tsOWackFUiiv8NjvI7bWFcy29f0
lsPGYMYagaRexC4OpKKO5kcgStCfkirOYc0owOUzBo6T68yakZei94YnJZu6YLHou6lDvHU8zf0
JyTJezmkxGF0b8TWnhq0
B7Y9F8Sq5FoRcwEbTcQr0GfMG7oQ8eHN8wwxFpGh1oltzEOE8xVpm4bSFbYRxcYTgoMIbZtAKbKbN81oumzAsTf5KfYs0
djb3LgVluipEwc8gD421
V3gSPoowkYGQmQ3ALIODeR52XA2O2USYT0oaf9gZ6k30hIklYopKnlDkxdA1
XVLyrgZsJVtyxuAkIdkD0GMGhoh2cJdAhNq7gGQV43lSd19EcDt42TAGvfOCLHyJje1WUX0C1
1uo6Lb1jGfFtXSq0uyuplZeK1
Q6FY3P83iW04v5ujydnuImlV1acJf4xN1
_Closure$__1
IEnumerable`1
ThreadSafeObjectProvider`1
List`1
WSNqIy4ZofMoc5feUDc1
NK4D9oSKV35Zcq6JV6u1
Microsoft.Win32
ToInt32
mg7QBar9WRUOVN0rTY8eyuH26I5TFOzu8yHY1D2v2n2U30Ux6ShBIIwjChTUPeB2mW8mSBBBu32
NTiN8KC3h38lDgicpb52
WRESYxyWuRb9Fkq04ZbEjkmfKNw2BZXc0AeUUe8pgA2
ZPBPwxU8BC9ZWP6xt2PpEsqASQpv2RVvPWdntkvcqHFjN5VLn3h0qmCKN4i0hTlvEX0b9D5P2
5lP63PMxH3LkGsnAPmvUNZuko13cKOmPD2SEDso0bQLhhkNY7CMW2AP2
twv4HuclEEJkCO1vy69KC80oLZecYszpsKSDZgbo2IJfyGpCgUpJXEoixFH45Hl8Cg8ueq9VPrX1BYjVV30zsqM9uqmT2
xm6XYMDGGKHOMagqb5Y2
Func`2
Mt8v2VMrK3pyxbHtmrCQDyUrD3qtNwd22MSCIOGGe4moMfe2
zMZZ1q5wQlvs4ChMawXUCdpZpW4AQqzcl73nywCRtOH5CuqvLyloz0FqrzZwmWkKspPyIzf7m8BIi2
zj82VJGPmmZn4Cs6Ra9Pc21BLsT383Re5yrPTHRK8s8wgD2XKDoI9vy2
AKgQxbwFWmobmTVWGBDAgHlSvJ6Sur4A94i9THxv9IWDn9A3
eZNVOQhtjBQ3I5QBiOzTOPsB3
bxbwCORsRpB83p9DN1caaTyC3
yFa0CF4NmSWlDn7vw6G3
qPoyouPQm3Se9XSDQWXR6aTEf4I5PnheX3TGeW5OhvgyB7H6ELzFMhazQCuh8g3h0f2txZokMcD71FOksh3
KNndIEZOzogZX6sDyZn5SFj7BsZMWMji3
dEGjE6a0NCfcgJCL1hKHGoL31xKmR86flpSVH44a6IhShzyzFHcmVZ4zVTsNzS4w3
KLuJFk0B3rrVPFSSm6ycPzQ8CjKaQghafUEy5FB26b1Q4mjarBgjXz34
UInt64
GT52RkZn9DLPb1vHePxsHoyG2N87ck0VTv4onM9eAhbt4xB4
fsFL7qdYN5lS7KeMNqVBJ0kE4
DBxcmry9FSpfgNE66nsahJO6C1dA6ZORCT7swUNipJemtYa4
sMytkeyKx3QCwW4YTse4
pQXB6XINgZdlAigQRvi4
y5HgIxIzJWRA5UB5nEuzalOUCKNIgXamtZAHzg3n0EsOgjZrotFB3XPPBXWkxg3OxySqS9s6wKEkrwrI80KIj205
plZv7HqBTuBBQJhDci6Yc6DWI0sDKxPOAbzQ7CUSvdkXib2sjM7U46lP2GKttsnuAEBk0eN2WO5
4XjTKy21fk5
qxWb0DBtU1nQQrzjWiZPivFo5
F6bT4I1V2U0IOXhQLEGcByqXjKgc9XPOaUjWQ21Vydhxu0L56wjxMXIuTV72c26rwWp20CuNpJ2Z9dYawVK7cqx5
Ss0sVcKiyeu7AhkcxB1XaZF36
dfxAFsJQzIgUv3OkB5q3xHL46
WfziQx8Pp1YqUq7gyS66
HopoBxaIhTirHkfsbDgEeAtybMF88LzPzY53Qn4WEA8X9rG85UKDRGiYZRQKokVcpd84cLJ4WF3NOtNgF76
2458LDUJBX5Slc9TZ2KWGCB7lHGhyWkBa83hvs5pgmPY2TAtjzW23JSGNozRNIBjAiHukhxOrc6bf6JBH9oSIvO6
d0Ix1qtlJvjgZ2HgadovalytzLOr11MW6
rA8oy6XnuHLFKd2sYF5h5dBDzD0z42gQHfPtW7rCmd6
G8P2IPj6PeQ5XZ3zAGIDAcc00cCs46m07
6P2JNMMEQuvybYdOZDp9pcVCFnzRdUCb7oOh1a8D8POR4WjHmLmezgHCWdL7
_Lambda$__7
bO7RErHQAcBPEL437ubPLWDwLCubSPyf7
JGSXn3UFSyfY5wwBS8HHl66FT6epYc8JBCR4CZyqHGiJbvjwfdb085twj86QcHIbHSuXgmgRR9Qu5QwVAasbJij7
3pE0UIzWfELSlsxjJVC8
get_UTF8
y4Cu9ZzOvTvbiQ6y48mtVg8rxA3qWaausVvywwcEEplnhXBINVVd7Q2UbYU6AtmeBTug9jmm8
OiiEjYWfGMt5SjRJMdbO2Zk69
roZYClvf3JoXtsrC5wC5fzFD9
gSJVBXju3N5Jm4Nry4seBMHh3V6oDMNfoM5N8WQyMvyLe6F9
NGbdBlG3l6SUOlBLsQHSDI77bO5WbwEpMfyjczQNgWIbaAyFYW9
euafmU91WjbHbJngJAs9
<Module>
suUegL3ub3AIp038gXiVxPFLpeY3XmADA
f9ABoVVuCFBe4a1hO0PtVPhZYG1Rs6gxrpZ8qnMzqouLLhVA
hasHTMZ2q42bR5gd1VpD3qiTVhEdez785od3aA
MwaonZapUp0sECBLqU64y8SaUlHmIRNv7v5cg5nsQgoO32pFzF98KV9zeuRSGrxTDhBkTdcvqkORADiKYqnHq6cA
YKqdFEoQDk97gqjD8SLJ3KC1LeEJuqXAjppD9JnslhgtRVATIJNTsskudSvQ38Le5JYfQJouINL1tELYXqU4Ea2pQXEnA
capGetDriverDescriptionA
capCreateCaptureWindowA
8LJFuFs7BWkjWdIYbYh0krFUSa5WtcQojxyYbYzlV91s8sxEhdXOugb27ME3FDlGF0cLf9sKOTsaJUY2oSMbwF3B
bPcNA6RQNNzQU8KOPhi4Ouw8b744ON2HvaOsGIDTEAB
cYZobM3tWGdhlzgKpxC4h8eY7c4LyWDerZyMnvZDETeZQqfOO7VlyEmnM9bZR5sVd7jR8iEmJMP6r8mjmdBWqb2ZDWcEB
1JR0X1ngTHokfnjmyLNP4D18Uc3KJKH93WkJjIfTiJrF6ynegBSOkV9JSnZspaVFB
FLyqmVaJiPzzaSOTAykvrsNQB
C3UGQe192HLBekkt39oWIYBESSR4NcottxcEjWTWOZpMWIzJVLrU7WwH8rGZJFQUiQiyPJknB
Znne9CR9bcKQRJ91hzAt5yQz1U0SeDoCqN1RqxHoYhXMg8riEEBXpf2oFisK02WKyDjlEttMXD9xEJJPtXZ6uB6IJF2rB
L48VKheDaB5gbz4Jzu4C
egbMoKjKikZNF90BddVVXrd2ortQvAE3P4qFe5JYN9e7SmAbYcxrUWDWv32UubuZuDIPxW2OMaosxuMTn6C
Ldg5seZzVGN1p8b6FtFnUWv5BMmScZF9I1juSHs66T1ybP817pOCPqbmDewNGtcCC
ku6nq65wKLeeFsYLLTJC
3hthnaEyr0OJqypqVVwgKG2aYGkZKEwHSnilIBZXkjFaC9TC
8Vpo4h8ilTjMAZi10iwdY79L32yIHR3D0fN3gkbMBWC
strbLOsNrM0ep9eSIP93rNIcC
xqF7m2nV6NMSY2VHvNB4jeZQt0u4QYUzji9HKv33RWj5mPPRuKzgeCduxBP4uSpIZzcJDz2ypLo3xCiE7hf26XwMkfycC
o33owXN3HqZJZvUobFuOKE3aLDzIJwHqwbPr2ZR7XnzME81mE5o1TuTadyWVlZRTFBAZtqe3NcZKg7vUAs7ilVqC
36HhFBmCCR3QpMJ3QlzbDnwVqZaawRZkXhmKa0NRvrScFGAmi4VdyPDRRKqvWCbVwXW13V29cqC
0y3xuFtXEKtenA8ik3roOAH4mhDbmLF8pk2x579IbIANVz9sKllC0BLfVSvC
1Z9BkAZBe4H1RfG8ePZ5igaEP5ZqOAYcxm6lj8KWOjD5I4n0VRvfqBv9MEsMunHQ66as7HDB8nq9z0oFfDD
ES_SYSTEM_REQUIRED
ES_DISPLAY_REQUIRED
zyrN8RPFiWV8viWMuFvxjLD2HKiO5wiv26vphSEMB6figJxdwYys5690pPR3Zym1rLmzsEvOpH66PD
CxkX1dY1AUa7w6Aqjtzcfwf03aygPR8VxDnoiIwOJaTmWRWgkzus4NOTy0jUAkcNk4riAI5H1g7CXD
uy7yTef9SA0kKkReGXSwmu60Whg0VYvjoQcLZCnMXKFEaiEyu2j7m4WSYHwBOiKkieRZ0tIFoFj0bD
jjj4xYOYpNiwmaikh9nv8lpp4fzrUI33BzcQizY7TYY3QE80oZ5J8jJFR9hJqXcnJ5a7HZW5tihRi2jmFmD
KOuXhYV7DQR0R7shFUoD
8HklT2QF8GVjvjbW1AqD
DdgSj52bSUhu9KgqlgZTcCvfFsVVJZILsya0rLc8CHjpmSwD
ceCtVudTwMVw3xGyWwHA1xhohj90NudsNB5mu46XMNtyk1Od8G4yNzYY4Z4E
bKdc4y9rSqanXRhqlK0SyvGqoJAc22cVtxPHWiz5QjSeFnPtUME
4zDLrWbKgOK0rVJApW1Kxomfwr0hE1qTHHiROxOsogyWs3NE
YukI7zRzB6r5DkgioCg3aWhkEQut3bnOE
EXECUTION_STATE
SijcfVUBVdERx9HdeYkWQwogUVARpSHw5Kfonu1CZ0BtvMJ0EAV8l4JQqLqe06ZWZlz3XT9v4peQ15kJcIWiFfkE
PhgrD8GGQMxtYPqmyglE
wHCMY8aXJEG7zGCIO4D9uESqE
Qz32dx5HLpGb8In7p5LuETJfcXjazaf7gTAWIrDKK4Ux6IOOn9lKG8e1VAWtMxWvIVesuGKNhklHDq2EKWXMA5SC2N1tE
FeIJD0VWfMBoYz0P05yE
99sfiGvJ8kGwxi7ZEG2zoytggftl0QYCXpc6OfwBWigImO57AQxFFE84HrUfCZ8F6ek7HbHyZgny1F
3TPoJ3ZH9nrTmXyBuUPLegnhu1kHJYvC6OPrVxFBojGLd3C75gszmhTuBY77R140u5YAQ7AjLGu4G35Lqli6BVuIkMnEF
JPXoYAiGRyENooYLC3CfKeR3xwV8Oz1SF
3Qmh7tJ8BPOwpkxQOZ22emHxEgNEtLLUF
8SEmmVY86BadRWRB329a3AgrOP3VGXfDTdG4iDIRVHRZYDuF
0n6qfWTHaOd8GtG99Vfgbh43G
7yatX9IMssBE55D39VFGKED42LkjCwg0IMMGq9TV3u2a7LheoNYEdUYsk9bwqB39w2HRQUsTxSXQ9G
yAz6NAMSMMn5cBPXsENG
7wunS0ymqCQm1d4XUrot1R6PxIGsd5KbG
MUWIhg1A9Zp7szmdBcgwjNUbG
zqfcS56U4W6EbeG0fQBNzfLicipbGQ9HDvcXXL9aiJ9AI5sI5pG
Tv0KcYSy7TG2GWaFZeqG
m6PYC7MfkLBCYYUQj4wG
qzvArCWAiWUOKsX9BcQUjaMRuSH8nVzxG
HscMWlNtFwsiRjXI9MuhsZ0pgZo8PO7EAbPsAsuixc93p5Iqfj8G0CzwJnVobFYALMgZVO6uVnQW2010YYKH6GosJOwAH
MgrgCqx0S6XcLHhXP0rkAREZgjEhLjtpH
akKeFshybDbAcL5hNWFZzXTkgaPleHpsa4FV3QPm1IRVs7EI
get_ASCII
5KjuQr6oQtEaG5hwouZmqWF0aDzx3bIePgotjghEO9jpVeVetNusyp9EKvMD5SqXf7kKujvB6jXFBtO0HM6a85RI
hRzta48RlNqQb4sOjEKUOlWUI
RCNyMsMQ6kJ2A75BEkhF0EPtc5XvJQkuDAKsfERsnFICVoHotaIOmCBX8kiTuguVaZdgUY8nMjWJWI35LWI
93Vs07sC2vRYUvj8vGYidSDuqAQwjAds3bKmuUhnBj1KzeVHczIdN2kRrZClk3CRIUcsON9GFMdwyqa0A99CitDdrfzxI
TRvfHLUUqdegH8Dy0kiX0VOHJ
JB1fHE9VY96qSBeGmY28X71KyrhlqGfRgtAz8EhSfVDY6ELJ
MEyvI8ZTWUUcz5So3NdA5EhEn2myg3rOJ
kauGcUTJFLO327ZeR1TCYPj9S0ygTIEQ4zgyWu7NyV2sTWTJ
iwfTxnn5UJQ4H5maDMtaEUbnk8JepZPnbSKVjP3c7TMiG0DhNYujOxowVSfJ
kOsMu9NzS68F0K2pdWHrnvUkkdjNbVZxv7ZWzQRQC5dK4OrP0IropwNtqZVWJUNvDt7KNGiFSlJ
oV2RfomCxBtHlRMdbPL1VBJqJ
NH8qIMF9qwUGQNXEwWqJ
tTfF6FyzoLHmxsSvHmAK
FQ8QmZoqNtdjtbX8v33IcoB1rnUMj5xJK
EV6ih8i1ZrNCUFAHRMeltigbM2WI34Gq23FRDYWcyYkBbSufL6iq4dYis2QvyScaK
tr2yoW2Ffkyvurcm9ekqaUDYxx8lgxz6CjCDIgje1Vr7VUrK
pGg8yx9FxP5465bLTVsrMAUiMC5aZ5ObmA3LHEjw28F0dSTL
asBkJWHXmoifrIDWaOcL
RnUJQ2yfLY0GOQ65I1Xfrj5wjzyHwNFATyEQvCu3HfL
8MSjyMk62KAEFUI4wngAKTuhUm3ERAVJkNkTmJNuYL58XS01QAlenJ0M
915AGjqI1wQl3FDQQIYUapR6CeiUSIZZnt6xX53x0XYaFb6GA2ZJ1Eyn9bsVFYBzdS08dFwOFou11M
hiAMaQgxe6AjMuvOwoyQ4gP512RQ0qPCpGnUmpGhXMpABWrYnmvTkySwQ8vs0ZOhbgF6dr4vddaDMM
t7qS7DGKRxmiu1Dq6UPFxJN1Kdz0T0ybJEYa0WoFxGaBF51N
oZYnzDHJRbH6GXqkjimQJdMoI1biANcFgvPLS07kOTOvgaxlm0UpxbrUs4LvgmYj37CgKxwSN
mxbeLVtoj1dzMrR309oJPlYPXKFPnCPZMDbZy6KbduFDz4aN
lqWQhCr70pwZXDh7yRVKL1dtN
Mcy9xqJ6JDEahesKbtS7hvc8XqiAAZS2O
LASTINPUTINFO
System.IO
4TIKs0sxZDStyOL4vFZBDfbHBteig5BBNTeSrZNQQ7E7e9pbs76WbLbk5ADfB1A3CFCI4h5oRQMDjPfWmwf5aqwl4KjRO
xcoWXBTkwf0th8rkON4xzkICVzu7bmrccHh7YSo0lOokVW1CEbhkv024frRlwryCxCDE4sAbRhqkXO
PfjpowrBArTU0gkABBJhG8o8FFKXPWtCOSGR8YSbWUQzJoH5tdO
bpjVNqBbuVCRNS8yLjZJkH0Re48qMIQiO
gW67bjheDQCZeCe3LeKeOBaqSLb9Qxh1u6H4Oyo7Jx6u96c9dNpyifL3jzORk4JBP
hdcV3kOjIwJc6sjI1GOgP5ZvTNNpYTCiWinCKzRK4DP
qi0evOR6Mfk8lKVcu8JP
u64gKa0UxQbBRcGasap4zRtF1EnbkgsceSCZsmZzRKuQbEYZcse8Men7AHyqDQfxBYxbQjSd4hPucENvISXspFfVLFtMP
jeGfxhiq1rYmJzgh2GBowsOKwaVUDH3fP
SeVFqNLceWZWAw0Bo20MLsqI3bns2MOagxJOganxVNKTI5HTj7ahsMYGcghP
Z6PRS0BzHIkfLbJraX6VyCGo8RvTRDx4Q
SDCtdVcbt60gcyIU3S5Q
UVY6MvRZ4mq4GtXXAZ5Q
VgQOqKdi7qkOXR0GXOmHSqwFToNXrJ0TjTut8N8EXiC66SYl9fPyZG8NGatONU4CKvoliiahMCQ
szz5MIlaFPPOZK1uxQHQ
ppW2QGcIEFo1FPi5eGJQ
Edk3uoK46XS9WvZb8oRhSf0JoaGhNVomKHjRtnIb4I0EBiSbyD35MWQFH3BWifUwtohndYtEtSQ
WWVhdXxHL3V5UpgVw53VMiRqyAFScTqjMYL9jrNTVHJmWNoTaIoaapnZripGhyqQWHFny4gTJgpq1R
0Q0i3YLJ4jpobfb9vNlJD4lAfa21JZSahXz45RwH1zfr9BWzop9aNb1cW4hCWP22VjJLCpaXG3R
9IwLqdasiHkxKzlALe8R
36u56Kk5zGueEwRdCkntuczGNPjBatqQ5y85wF1pFreKzQzGoSMued6KHLKR
u1j6eXnIhAdTpLuv2WdqoEE4CgMTYLgLR
mrfM0FqQQKaAteRx7beR
oO47wfFb1WiJtANv14I4NnxYtJJwGuRMJG3Ja9PpD9EB3J8b4UilGhb5kO0S
dmV3TfjdS8Le3SkFuHWRIdb2N9ERBjvP3fF3J5e4HttmBfzAZkOXzkENsPDDxfnXiTB5C81fcIZr0S
1rMn8dtSFDr0CxvOtDYBTWI1HZEf5ox7S
STUoqscvIKRv0SPLbRWmKslp5eVxkdvLYND871LdmruFVbBDMOF599rKDFeVr8jNS
ES_CONTINUOUS
pm5tDNGNADUcsk5dN6R46ahNpVONGH2sP3q6ZNHjIlLyfvv3hgS
vp76sYo0LYJbcThTKDGdA3A6AdAvjpbywdg412Hwn5aIGi3XefatOvQJZc12xHnlS
iLgq8viuv84qXVrcTfFrfA4yt3oG2inQ8xlXY1EP9rlgmC7f1L89UdsHbxmHMFxWpBM2L7ZqS
tdDHVL6Pkez13hz9AeF2QbWiaAePwpnJaiKA3T
Y6jQVjFqiPxXacZRaP1qmTdfKHQsKCk7T
nT2RD1Tz1DReJsv9feDT
sh3FEYwcDp1raMRw7w2QPuwbKL8i9IMzizRYUD3VpyP64bQMPIRwaFuzKZDD26jUM4TfuAva0Z1QLT
uIoUw1v3ogN9075LvG5pwfKOqzOipMfwIr6O6jYJl3hZPECkrjTwnPn5I43E7BLNT
NZvK1TVG881iC4FKOGYT
RnL4oCPiHPQjNvzO37ApUBdmNkdzEcnr4TkkxIgWCnttbfcT
RZDZ641Qc7vlNM62V0gT
jQRgu90hI5KM5MX9pT60nkT
icTmbD9J4ILiZRH4RkeguP5yw7FKXittFZorEvX4n3ZOfX6U
7hCHLl9rgjJyDmdk6IPpDABVA8yqbkfjazCOpvTmFY3kSM66fO45saUanI8U
GBFTVHLgbywZcThjEWKswXYWZucDJIkUx74tJBAagFam7ghuCI9KzNb46OjNPqMy8fZTeeiW0C0UEU
FdyqZ0dRVe5ZtpbeCiOU
pJhqaS45BhlAzi9RMmuugOn3NGLyfxLebvj9ud2TDJDryvXFAD6JSDNw8UUU
yt2lZH4T3LhF7xXN982gMS7XU
3AKRj0DsNBgAzh4Ph7bU
20NI0H3lGx727OoG9OcU
30H16h7S3L2QXnzpuTHnJcuwaVjv129vp92UgltnG5qmjEGYCs0zjahfbpElKoTRDGWuhZFLy5m0kU
G5EY73dHHlXhy1z85aSK6f6nzO7eImiM1bp2iyj2z7Fr36vn4WIwCYt7IhkalVxDshsv97NlNaAtsU
P8P5H0hUW5C8KYmj0ptU
f3SwmCOJmoEZfq2YqzEr9CbJlrjEAHlIYbjIH22QGUdvZilv8UPA1DZSzaUCAiO4V
hYNEn7tH4nilRiJDW1MV
snDxP9Ev9eeO7uiKZcEKRxOTh2TiNCoaV
aUvqJPKOcWGlieRFHRkV
aDxmSDKwi7NyuUQtujkV
7N8nhmN4fcLAEx06co2W
vGOSMHbWZ3hlx6SgZNNfm54vdce5WOqvRXNl0Ba27wXxNBhlQKeoU7XXmMHW
rXLkRMno5m3iihduQFDTX6udy35zUMGOW
T7rTydnHX2mtbIdh0i7qYfNUPTcBpeHVgP5blBnvlItmPGUWcWoQj3UIR3rzmj1YW
yo6ePto97tPADugaX6OoPYJlwEYf8sSjDbYKQfBahk9G8BWiQk2TrXVBENYW
Z7GY4kPA19FAwUUFDhmY59wBLxMcLDdYW
7DarvY9vnSVQ6lGBtvfno7n6LpUEDepUS6xhlbmBuI3glrrQjyD33IiTbD3QnCR9X
EFRlNwLLVESixLv8EPgbPyJf6PnFeh5tiFvXkOe38bAMK4iigA6NAwgWWUTTMadDX
01HMXChPesaaQ0eKys9JrTOQX
O47rwNHe6WFhax1AoH9wixo8RI0gcz9lKiNYqMbhKl5ryBguImCBVtP0GQTX
8CwhuDluAkAkFRo1GuBLkTKUX
5mRjoE7La59gdlrnUAEGNILLHduKDNY16onK2o8GuVmI0YuiimZkcPqBc1m8LuKjX
RfCPyYkRBhNOLwImo72lm7dpQa4rmUDT9qY639TKJ4pI5Js2zk6wuBlsywfHtGMB97qpHc9HhLpETnJR24Y
kXMretKfjJoHzLzKRjNdkBYQEAffMsFL7aJyr0CSJuQVvQUz4pm8wvMPScJY
RUx0k32xgHrKFZI8uETI2XDG3IEW1dOwOVSPZUuAJWWJU9uHdo17ssAFSBPKxXw4SpOH2ItKY
qRvXgCYpBQfMYsDfuzSY
ZG25He913L27n7P9GTCI7BCtcHFOlLT2KfamgTttJu0IvdTY
fzIZQGXX8vpkf0PBWGnY
cS5DxjugBxRWUwHvnQPGeCLHFZjdMdJsY
ZkgdYgFQtW8gTPGiEUwqDK9M8b4v4eXXDEPUq2OuQ0YnZ3fT5UF6QrWPLuHh0S2i0DiTvSHlWagxvY
1bYZz2Kzt210n6bdq92Z
ZgEVBu6nRsaFmPyTnB7Z
0kIBFUFDjzu1nzC86DAZ
1wmRNei6OQt9lV0HbMNWw9qOZ
7kyDsttXDHAdGQfVOFg0uTucmyfrwI9FVipRULulzLd2JZl70fFHGcTTZMchBaEGUdioF8fXhLZtjZ
Qmf2gjmCU52joHF5JEQiJKdsg9sw42pQKG7FgvaNeQuQsbrS5yosQ9Qb3DHU3GYsVTxDCb5c8pZ
60jY6TYOjix3ojSVEvqUwqkXsP0iGGxp3WQYs2HVR2UPHrtZ
X8nQW89x6Fa5uvRpvCLxQjxNQTMRuRZP1JxYE8VErgjAEAsHqamqu03lNGYEtPZGi2yAMU6Dg7REeHPdSt72jmvZ
cpLTZFvZwKUwR3RJ86sGmPShztdWtzCyZ
Dispose__Instance__
Create__Instance__
value__
UIQm1dzJRm4osH8hmNk2U70QTQoxflsTrGIuHrXTUEDzai5a
z2XhDxkQSvJojgpeXaa1qeZ9CsSwopne4ZGHAqeGwzffeiI3oKZF8C7a
nR0qYIHXDh2y1alFsE8a
gnXuiyXlnkL2OYJA9o6RtuwKV4cNbNuOQ1cD7XhJ8y6Tbloa
ProjectData
5h8ENVI9bTyYpjSHH1kwVtA0Hv1HXwS3mgMv91zrphe7bqua
LC24OdUz2VRR28f2p3kEAmpRNkKVcIzDcrVR6uXDCmwdGmLoc39OrzP5kDLon5TWrzq1chfcgHLh5b
oVxXeMzN1UogiluKutjlB2UNb
2iVGiWKUYjkI9PGSqGPjlTEbb
mscorlib
XJ4nYyGoSs0WsWpb
dQSWzd8QAxbBzeb5qWXSv9ENhyEM4RleX60bzwGsSRqEOOwb
Nvkep989wue7syHjEnUB4CCac2zxjomqX3j1xljSy8m2uPTB1T8PwZ40mjDc
k4hF6nhmoYjD6khCz0Lc
f3Py5xQrNYoHivPx7kHJumFOa1K0UaFjlXN3I9idCNc
pJp6eNrZbDBVwDqt5ONc
DQgdsLdL1DBUOD8hu8XqHaas8yek1v5Z69dxveqtj0lnmByUUP6rv14MQfxdINACZJ0Ydsyfvv7SttEvQRc
bMBCLg7XbLXCPePj4smzBbk7szeMoq1005FH7W8xedi6eTW4aMyeAaSVZ67M3OOAB17rC7jUc
Rhf9uUE0ALiXffW4VIic
System.Collections.Generic
Microsoft.VisualBasic
C31AVqwXJR0IYwfx5MZCTRw5WgWfmS1WcshvKZ5YUbRZMCfY6bubn2XsmRzjSyv9yyI64aFyQAxYfaxqCjc
p2LgT4ef6cnAiOSz6pnQoFWfcgE6sDekc
rGUbYJy10qqrvC6KFEpc
Uax3O8gSjKzFRKKub8I3zYGQN9c87NbptmvV9MvkFeEb7oZjtlCpFZsceuniJw9LtyDDDhADosc
IeQOCg0jZ6XNEhZ9uo635XQ9DVqroo7iAQ7kIwJSNoqc97IMyPJP9rXf75porFaG55krtiZwqxk8En6J4TcfblEgd7avc
tRJP6LmAdTBSd3uyGa6W3jCm2TvuA2Dmf9DbW4XzSZZAZ6yJ6KqFIIDviTxc
WVNqZdUaGtSQLETICjt6lxfH6c5UeoM6NedEME3FdX8j0KxDPVVWMinOwnLIW1l4d
YHn3cAdzf61bdstydIxC0ozPXgQlDRFAd
WOVJfoCfOsrjtMGd
YcNQR8YnQ70TFE55xGVBqWhlwNAHWkcMMYeFqQ0vqBDO4gaim7fHGgutGk96OMQ2sby0hDIWsQd
47f6SXx2ViFPYWvqE1QHFQ8XtMj1FS8s2AmGT7HffQKGepg9eAnbTUX93Efy6fSPN6s8wLeXd
Thread
RijndaelManaged
get_Elapsed
wRMbwFG5eWEGfJeuPS4kADYeg5vPX5Tk9hevQr383kqEd0lprhd
EndSend
BeginSend
Append
RegistryValueKind
oMXZOQxtVvxJipedW5MR4sDod
set_Method
CompareMethod
li2nRBeWucUQ1B2IeRTsf0I0fwOS0kcqd
BeNsrS5yonMYPbtAGwT2zvfSf9Dfm7s9ZKwW8YzNvMDIbSp2H1mejrd7dj6fi3J9wDT9YUI9Drd
4XDfYY0HQQcyqiCTg8QRbnmm03AZkpZI7BNVHrr3bbxzAoRyHoV6yz2p1EsbTkckc3X6iJ7tV1e
HP0fCiXhbyIzaGz38HKzV5sj5ZUfestWssmKrDTKtygjYtIe
qGuZjc4CvAJd7ipgkxyTI2AJN5grt7ojRyVOjrxMgWuj81MkImP7gXT5YLsx7NnxMrj3zcSOUMbkVe
3IKHpCMMMPlg8R05Mw520CpkKwfjeIws4umcET9o3H2j1F4HgXe
Replace
CreateInstance
get_GetInstance
instance
GetHashCode
set_Mode
FileMode
EnterDebugMode
CompressionMode
CipherMode
SelectMode
FromImage
DrawImage
get_Message
2YpvkaK9OZn0FImujXhe
Invoke
IEnumerable
IDisposable
Double
get_Handle
GetModuleHandle
RuntimeTypeHandle
GetTypeFromHandle
EventWaitHandle
Rectangle
DownloadFile
IsInRole
WindowsBuiltInRole
get_MainWindowTitle
get_MainModule
ProcessModule
AppWinStyle
set_WindowStyle
ProcessWindowStyle
get_Name
get_FileName
set_FileName
GetTempFileName
GetFileName
get_ModuleName
get_MachineName
get_OSFullName
get_FullName
get_UserName
CheckHostName
DateTime
get_LastWriteTime
dwTime
WaitOne
WriteLine
Combine
ChangeType
UriHostNameType
CheckForSyncLockOnValueType
SecurityProtocolType
GetType
SocketType
System.Core
MethodBase
ApplicationBase
HttpWebResponse
GetResponse
Dispose
Create
MulticastDelegate
EditorBrowsableState
SetThreadExecutionState
Delete
ThreadStaticAttribute
STAThreadAttribute
CompilerGeneratedAttribute
GuidAttribute
HelpKeywordAttribute
GeneratedCodeAttribute
EditorBrowsableAttribute
ComVisibleAttribute
AssemblyTitleAttribute
StandardModuleAttribute
HideModuleNameAttribute
DebuggerStepThroughAttribute
AssemblyTrademarkAttribute
DebuggerHiddenAttribute
AssemblyFileVersionAttribute
MyGroupCollectionAttribute
AssemblyDescriptionAttribute
CompilationRelaxationsAttribute
AssemblyProductAttribute
AssemblyCopyrightAttribute
DebuggerDisplayAttribute
AssemblyCompanyAttribute
RuntimeCompatibilityAttribute
set_UseShellExecute
WriteByte
m_ThreadStaticValue
DeleteValue
GetObjectValue
GetValue
SetValue
set_Expect100Continue
EndReceive
BeginReceive
Remove
4oRaB3YuqfNZfY96OAxe
requirements.exe
cbSize
get_TotalSize
set_SendBufferSize
set_ReceiveBufferSize
FC4o52k8TGYLK1QBH7z50104f
a5lQz2fVBLbbeTwD1nsivegGPEotOlvaRdBLWCd30OlNXUjAT8bOkQRCmNVNSxyFt9kjTtA5G8f
XZOyYOpC1Ic3wCYZUm3E9FpgUwo1axXIf
wbRY1Z8RiRxZwxp4zBBkKyFEU55Rs8QL3M6I5tEhregbjsSyQgSzrMI2bXMf
SizeOf
HeLzy3M855OQRaAU5UGg
rrBpMw7dyRiSeOCVAklejBhBdGnNwWAFv34koPmGbJvmKqLg
MKcj8lG40xi9g7YKCgMg
Nu4FujjvSUA1n71PDgAAWBoAOHsebPHQg
D2jLr6E4HM6p7qtJWd35KjCDp3Ty3uNebSf1Fg6BtdyHGoUg
lorAlY00pjj5pP26Uu7A6usZg
b4A2G4HAjaR3ZUoOKbAWKag
GjEE0hbQKqwumzcsbfwTwoYag
get_Jpeg
M4M7sEFobJvT1Kt0eDrQEb47fkOkzfTspEi8slD2Eknh9mI9BCMLCJ0w6rkg
System.Threading
add_SessionEnding
NewLateBinding
Encoding
System.Drawing.Imaging
FromBase64String
ToBase64String
DownloadString
CompareString
ToString
GetString
Substring
System.Drawing
ToLong
set_ErrorDialog
MAq0UvaybgISuZZSsHvg
tZiTknl0sEw3mnXIQv9h
JzeMA1PpTjM4f0DeFMBh
z7doURqoH3CYZPDCgEEh
XtOjspQjaPXAS8EOy8Th
Stopwatch
66lLhvJcd2UTkPWOrFeh
qGLPKLtrq0Ij28UIOPmh
epMbxC6nKUClDzYPdaotlN75HtzPGIufJP1XwEUMUzH5K9nh
ComputeHash
get_ExecutablePath
GetTempPath
get_StartupPath
GetFolderPath
get_Width
get_Length
EndsWith
StartsWith
CmHPQTmpSF7gKeKBcv7z4G4neL1mSXaJYb7qw1MPVsCUMvn0m3bzJ7rr9D7i
uGqh4Ect1HvHPJEnCXetp195TfEZT8Wgilfs9Ga91Oi
yWKnN3A8vfNyjePvAJi6xvSPFnv35k4gi
7JMHP2cIU52B9ChaC1YoXrKkuimOZB4j5i6OVBYzQ2zQLDH95DcAXnLUqh0diTPxi
WosklmjVgm2uD9667q3AFdm5j
fIBjUf5J893fUgQRzBJDRJ5mhW9nbnOVj
05JqkmC0R3DOxVFe5cXj
j0iZvK4S6T811kTAQQyR1LnOh9IBufD6BHLHDV7e6iPaPrvhHOQQ90dKXBvHUheXj
b5wWlYbaPfyQ8lkj
Qxz1EZ3gA7nkSot84oiSwLDGilPCaMI91QG2jGgDp5k
V4CuvmkdxpRQwhgJNPLH6piehBrIsGPiLIpgIJU339k
eTagFTJeFaSnPSVNHuPEyC9LHAliobZQ4dsZLxVgPeZQ9oh9oxzA9CjnTQT4sNGnGWimsGH98Ik
HtXOJcuPq13MC61hVN5f6Oobk
get_ServicePack
AsyncCallback
TimerCallback
RegistryKeyPermissionCheck
TransformFinalBlock
enXiCBFqhVW366MxgMxj4jS0GW908bu944EZdQKvlP5YBW23223Xl8jdiPrHwnd7l
EKjU2TKXWGMk1GT5LI9l
Xdna0u3hlfEBf8XVGARidagcyNXOVk7M7LFUp8xxlQEZO40uxTcpEpezdfHl
iw3jBhoFbHEWVxrHQEXDmIkOl
gC5nt1huvKYX43Rl
RtlSetProcessIsCritical
Marshal
System.Security.Principal
WindowsPrincipal
ConditionalCompareObjectEqual
System.ComponentModel
LateCall
kernel32.dll
avicap32.dll
user32.dll
SHCore.dll
NTdll.dll
set_SecurityProtocol
ObjectFlowControl
9Wc6jVbKowk25D9iSJvugHGd5lxn2zGtYhPX3M2Q2D0p9vGZ2Wtq4YC4RNW4z58WCemShAPzYZC3dHnilKm
FJ5s9YdrT5Hewl1eAemdRPF5R28nkkn0Lm3eczhnLQIBxwaC32FtP1bzX8Lm
U09z8m8n3t5nGMzkNyMuuC10Qsl1O0aTm
FileStream
GZipStream
MemoryStream
get_Item
get_Is64BitOperatingSystem
cugJrO8By4N2zIHPV4jDZQyckJDQgTg300tNL0QIplM3udnklfHJdqkBO2BZ6M5hm
SymmetricAlgorithm
HashAlgorithm
Random
ICryptoTransform
x8JxW9rXopsvgNEcAA6WH5KNH06geZ00JK9HfNMUlNSpbWtoRZBKBScjppyBau7SkBb60zbHZfg42n
Ou771en2ggYHMPqWBCJn
G8sx3Lfvl32cWX8p9bdvF3MUn
Q7eM1XLSc8B97ZlJoZm9lSpfG5i2pL3sZTlcIFR8Qs6mWlz4Wf5zsTaPoWmqWgOHsqvr2jB6Is3Ggw1SoWn
ToBoolean
op_GreaterThan
TimeSpan
0VeBdyC3Zg7B33SFrkBpuWAiJ6MvGgyxLjvaSuiulTXYUPVLDE045sQ497dn
CopyFromScreen
get_PrimaryScreen
System.ComponentModel.Design
AppDomain
get_CurrentDomain
GetFileNameWithoutExtension
get_OSVersion
Conversion
System.IO.Compression
Application
CopyPixelOperation
Interaction
System.Reflection
ManagementObjectCollection
Exception
hGps5XurEOo87WfQrkZHeEepn
SocketShutdown
oppRhDCCSjDpMoiNUXg4aFRXH7zVv6F8Qkmo7rWRvuPUPeapjv5arHooCmCuXcFlo1AJ7eqKo
woS3OPufeOf3JglYY1FBe69dP5uNecTWpJlcTMyhnO1d2h1h0954ojw2MHfNItiAzT3dDTXdFt1vBEHHe90YS6LpF9UNo
get_Info
MethodInfo
FileInfo
DriveInfo
FileSystemInfo
MemberInfo
ParameterInfo
ComputerInfo
ProcessStartInfo
GetLastInputInfo
DirectoryInfo
k3TRClJqZ2C5kE0gq4po
SAZfqHy2eSV4BIaroEefp2k0p
Bitmap
azxgUjBPU358bJvqArlqTDK4GIgDTKIjp
LNTngEPGluKAguYykUMY5XNfxTSiRpPHP4xSdEcZTsjm6ljp
xHbLUoFn7KSt4E8pqpxCMHtzp
NlI8XFJBjR5XGAJuVy58jidxZRoDg0q2q
zGvl2YSVmJpmUlzpktPf1AoDDc3zmnpCq
BUdUmnQ8iPF6Kl3ScfRSPmDpApYfTlyMKCnibdOMJseTvrqaTUq
PumYcKR3HFntUhwIcPsuCWLPxxdFEnBklx12NwP9OGhzWu7Ebyk6F7IoL9QIRBzYq
System.Linq
akPrZYQjkZNAHpCTu9MCwN84WN5IkfNgnlXnv1gCbpeeOo3900i31evJdF98QgkNMj7MErnxvWAj0r
Ud4U9wPXeAR9N6lnT35NOwSs26K9maBSAhDSUhc0cZ41wB68wIc9M3tCsCfpECQc6A5V27WEu3r
hQkbCnDX4ow9Z8NzUTWnAZWMN0LuIIW6Mx2FqDbfpTra5C0WYSr8KUIaxqks0ofAZbImBDtKf8kjAr
ny4mn39M6nB75KSjW2z7VEZIs2SGZxmJr
QwLIcWiCoVz76L3aioLr
JIoyVgkiSW50JZE6V9EHy9zHoYrlazMyltHEK9d1kF1W2jdKdpbfSiwi2SzNGmF3OPNpZjWzA0x4Jdg5gYr
9hWXkeMstZk6PKQDleh89WOZr
UrGM9ZmnuWTgl6g6garZygGhLJE1LoCbr
MD5CryptoServiceProvider
StringBuilder
SpecialFolder
ServicePointManager
ToInteger
ManagementObjectSearcher
SessionEndingEventHandler
System.CodeDom.Compiler
ToUpper
get_CurrentUser
StreamWriter
TextWriter
BitConverter
ServerComputer
ToLower
XnYjjzINoEfnH6qo8xO3pzMX6R8hYMvf3X1tfnbqZuCj4Vfr
5g8VtSYgpL5D1Gaeenhr
ClearProjectError
SetProjectError
IEnumerator
ManagementObjectEnumerator
GetEnumerator
Activator
.cctor
Monitor
CreateDecryptor
CreateEncryptor
bRKbHcDvOq5FjO7rY5pr
C8HkQEnax3T9EsCe6hduGuVSBgcwiJBcQojpAO3xpbbev9xrw8WzYqhuYUMy8r4afU72rw3Iqpr
1xs2nZKdtqn4tYMCcaPsBmthPqk7L5KYvw6X0dWBgMNjzTJIE7Q6uJxFGl5LdaRNMAPPVucKbqa7veCP6tr
IntPtr
2TbpZ2bsxmaeYZcBB2Y2xX66fknZMcH1s
4aJTJ7BIAsVjQyOITz3k2Df05cZF0kUDb749EcqcHRNlsaj1afT2s
8C181PhnqAXYijtx6NJs
fNWqmpnbdZ6JN1G0HKOs
Graphics
System.Diagnostics
FromSeconds
get_Bounds
GetMethods
Microsoft.VisualBasic.Devices
MyWebServices
Microsoft.VisualBasic.ApplicationServices
System.Runtime.InteropServices
Microsoft.VisualBasic.CompilerServices
System.Runtime.CompilerServices
Microsoft.VisualBasic.MyServices
ExpandEnvironmentVariables
GetTypes
GetProcesses
GetHostAddresses
ReadAllBytes
WriteAllBytes
GetBytes
SocketFlags
Strings
SessionEndingEventArgs
Equals
System.Windows.Forms
Contains
Conversions
System.Collections
QXzV3fJBAnzK0RHDF9Tu48nQg8emgQavsyltdWeZe2Do12FGNLL8rWNHb9gbzZUuKRdaAl5URMkYtcKMYqs
get_Chars
RuntimeHelpers
GetParameters
Operators
GetCurrentProcess
SetProcessDpiAwareness
IPAddress
System.Net.Sockets
requirements
set_Arguments
SystemEvents
Exists
fhTKNkMnHxRdqfO2aGfyHqPoonlqDkDeJZrIBdnTdvs
ptoGoAU2SiWCsnSSlU7t
uPGA9lB01rlMmfD6HGPt
qK1ookzEKUjlmAqFNqzduZwXbWiHPyFzpoMFvbdxAFbYtchfRBFq1H3cbISJiAZzqRdWoRgd29YpoR21OW4ZrEVTbl9Qt
Concat
ImageFormat
PixelFormat
AddObject
ManagementBaseObject
CreateObject
ConcatenateObject
SubtractObject
ManagementObject
Collect
Connect
set_AllowAutoRedirect
LateGet
LateIndexGet
System.Net
Socket
GybB2tEH4joFduZ3bx9rj5rJptBjVwJnYHO247cyAxKiONgt
AgiqkLVs6msBttytim33WDhGlbpKypHht
get_Height
set_DefaultConnectionLimit
GraphicsUnit
WaitForExit
IAsyncResult
ToUpperInvariant
set_UserAgent
WebClient
System.Management
Environment
get_Current
GetCurrent
CheckRemoteDebuggerPresent
ManualResetEvent
get_EntryPoint
get_TickCount
get_ProcessorCount
GetPathRoot
EJnwFgJNaDmC6TDJAPA7H5mH0M5qxkukPNPkarc4oXBRXgDaGn9BKQ1slrkidbPqt
ParameterizedThreadStart
Restart
Convert
$VB$Local_Port
FailFast
HttpWebRequest
$VB$Local_Host
set_Timeout
MoveNext
System.Text
ReadAllText
WriteAllText
GetWindowText
tj2cTBJ6pAHTlBP2XFzt
cGc5u5kUN5uWH8VIJFVhh9dY1PU7IisyHYtolCYbZdTyQnY4jPX45aK7yq8u
GNnRCmWuxo8ImxgePEEu
qC9sVsRQ9xJBxZNIeWj8nMu
OuURfJbnYjPAHoQyF4Mjxvt9F78F6EsIq8nMtyLrw7qZMDalALVW6GpxUBPu
qEHGhlYtDj5D1ugiN1121Dh76VM1hKMnL4QjJtLpY6L6iPdSgHSY0lTu
idVeO8KhdoRdlOMwXdXu
GhmV96lhQ6BuwshnXnZu
wJwk3gHGicaeVbr9vMxNS91M7lSndTc6sbJ3wE71HvQGFEEidvxuxA8XJXdu
cWGBf9bvjRQY77a8IEf3KHQgu
myBmPmHzGqiscyKSpF11RLsCxLr2yLGqBJc56HZ4YQ9MLtibD1a4CljYmclTZLmdOnrDzt0DXIvTiu
yqJHguqNFjCV7v3bCzzKxLwMdBNU1Wc2Vb9y5N2eWmysuOiHi3xevLljXS6v
IVfLnK6PizNlzi0TQdp0Izdj7IO97OpmxNf5aKdCFgI1zdSwEuAR8Jj0DZ7CWDVIv
p4kncGf90WV0EpetHs1TGYDqH5zzkWBXk3fi9Ag6IDEqhjJrvOv
3ljtgcvtIFmGBRzYOuxgXr8VwvzQT00fVSacGWLdG8KOIAbv
JZ0bXYRNqsaB7F8EHG3w
r7T8EyCRmXfIlhELSD7w
2b56xVGXmAwYiFl5Vv9w
9IgrUdohVdCAF2r0RnQGJnpqKC7BUdfEw
kW7lJ8Ty5Os4KPbVadAMJyg7208oNES1VfoisNA6cfeTRNX2hIw
xlGpzEQ4His0uKaM7tFUeWWmfU0bEZgLw
II0hLPuxaqSNxSGf6JRw
sjwuhps6ZO7npp3d9rf2EDbOt04Oj3YhGjzXvXKJKQmAhSWqeME2a9guAKSw
zfYdmZ80SEIxFdddCsY9feXf65v0F0sYw
L8JMgvV38CzD6Q0iy9EVR1kO10YV4GT44CpaSPBcgcBZTqNGMnw
GetForegroundWindow
set_CreateNoWindow
jjbFfEuArgkPKAXew0vw
Jr7QEPc6OD8Vnuyj76gAuDwxw
vNLKFFXaVJNgFLwKhQHx
jDiZ57uDbWs7xDc5mnF4KiaYXc7OsL6edQykAQVYiAGLgIm58GCQmGWbxt8D5AjOLuzhlW6ZSW2gHx
VnLTqmsoDC6fekvkz4NwpP8KHFCAO5IxehFyl0wYwIbTViQx
PeR0R3HZuNSHKQxq0mDkWIzYx
LateSetComplex
cxb20TGAt4BAKgYui9TTNLjmdJoVkocgx
ufb7UpGX2NMJQ9EcuGd97KJCHbyHXx4SWC9ijjQTGoBTUW0y
pp856NqJy2o4gtnwEKFLcZO7IfcUZufptaG0o96ON1vU41pBV4y
FtqSZHYzrMmFVgMi267y
FHfcGUKIVPVrmcEGqYRy
ToArray
set_Key
CreateSubKey
DeleteSubKey
OpenSubKey
RegistryKey
sPCSCgaa5HpwG0FhcOqRof7CVXloA0MAvP8JjXfZ9gFiHoAIOgZhxOPRSjDEsfzM99PNsLBmEvc10K2XHy1RBbphNvVey
System.Security.Cryptography
Assembly
AddressFamily
ObjectQuery
get_TotalPhysicalMemory
get_Directory
CreateDirectory
get_SystemDirectory
get_Registry
WindowsIdentity
IsNullOrEmpty
RegistryProxy
0ZcsYJxGs45xzPZEERthLpyuDtZB9m8mUZofPnqtZeqTgvbyxRf8SODL8gZJORv4TcHTci5OVyy
O6LpLfT48FB2O8uNhmBw9gzcLl4DOCQ6Duz7xC5a83S28cdA8G24Tr08c8z
WGi3QDNRGcSEAsAJMffPTWGsmG0cjcTAcMJN8UyH297FlF5ZbGbmkdOSbJOz
uFlixFOdC7LqSmzi5KOz
fzWCmkoewbR5DwjZHuYFPmz
jDNIVNf813HmyS16eKJ04lnLEilCSf80BCxP3H60IMHa2QUgI4OezLIooXK5AOFSjzEYrxJwVqz
7mt7xvt8FLBfLwqox2ilSehravTWAVBsz
mDjnpdWMR81uNXCUhTxhvkRdXBzu0psGJLDdI9lXW7fEh97rNRQyRSuApwEOyEGRrAXNCm7NeY7s3Soc2UGheBWFbbjtz
WrapNonExceptionThrows
$df89076c-2528-4a3b-93ff-20ec4f07b381
1.0.0.0
MyTemplate
14.0.0.0
My.Computer
My.Application
My.User
My.WebServices
4System.Web.Services.Protocols.SoapHttpClientProtocol
Create__Instance__
Dispose__Instance__
<generated method>
<generated method>
_CorExeMain
mscoree.dll
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<assemblyIdentity version="1.0.0.0" name="MyApplication.app"/>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v2">
<security>
<requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3">
<requestedExecutionLevel level="asInvoker" uiAccess="false"/>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
GjpNqIHxjA3
iwAmqAg92XGkcL9fnv9qV8E0FoU95ybXNaoh16Mp3eL
wmV968I5LDO61VFP6VPAMa4ePQJ1UfIXfWh5ywafOPH
fWoKhgP3RliFFyEl5ySQwxVmmtyrK5DOXNxHtpcOzLm
qHT6Mk7pjRCQT8g9TAprbOlU3iJNumW8FUAeQxvjc8p
74oZthOOYz43vfiUzQdZZjMulQsOreQpYm0vnRArugt
vX7CgCl5bbRdL429TgqqDtLxXfLO7VxtgtHHyWwjfNk
EQBgd8SXeAakxPiyc8ydXA==
B6GkEZTVKXhfnrWVtjrpQg==
YWrteIpVtn0FVq7182SJvA==
i8bl6FyGmBzYVHGA5BozAg==
hwqbI1NApTGwaYG4Z1kCaw==
RSfXOTSxV1RGs1nwdS8ssQ==
c+tnvGx3BaENn4bU3t220Q==
ygyX9MNZW07KHq2lKB3uXx8u6physlECV5MzaD07Fzs=
h0iOpGMlrarEe5O6
Cc7aHYU1EluQHC1Takot0OQl42nno80Nklqu0HA2JlWQaypQ0qGxZvwnLu0w25nuvhWbMRSsZNg
AATodNQlcvbwvTqQ75OqEXsnwsNwIQ24V4H0EC4GwVhJx7hQynJDxw4JRDRcGjnGE5wSSXQpTJo
schtasks.exe
/create /f /RL HIGHEST /sc minute /mo 1 /tn "
" /tr "
/create /f /sc minute /mo 1 /tn "
SOFTWARE\Microsoft\Windows\CurrentVersion\Run
WScript.Shell
CreateShortcut
TargetPath
WorkingDirectory
powershell.exe
-ExecutionPolicy Bypass Add-MpPreference -ExclusionPath '
-ExecutionPolicy Bypass Add-MpPreference -ExclusionProcess '
http://ip-api.com/line/?fields=hosting
Select * from Win32_ComputerSystem
Manufacturer
microsoft corporation
VIRTUAL
vmware
VirtualBox
SbieDll.dll
h2f4eK7oinzTATyHhCMwcZX89QbvcRdza9uGr1Dh7i4UkrY2BILqcJJllnfju9qFLHoB6Yuz4LJ
UATBdAPiOSoMDKzHc0zApcYwojLHJN08EK25aekH4IZo8rtAzhJHXAtr5J7s1c22DWJViQ7EiqV
WUrGqLs3G5NkUNC2zjpQjlAF9axigsQNd4xeb8hnLYrp4Dh6hXthwkykFocy4svYShmsgQGpLlx
CJUeVnN0DhhX853m5u7O9n7Xq17D7Z9sAs7sP041YWLsvVk3SJPxgnpshl0b71f11GxpP4jcl4g
vr387rC8avmXQDtEfGKoZzVdU4YFMY6knChG3oauc0wJ5Cy6DPD5yIoS7i1Imw22uTeGK6zJEDJ
rBHv3HZd9dDNjhCOGWtxUVWJFAQpJYvAr9QLgamXdzUo1oMHBc0UGMliFL23xKTTJvYgkEDUYjL
HCivK3GiMZR9D8KD7UdMwLjyu5NgLtKSG3PcekHAX7eTZcqwkYu2It6QFP63m7lrYrlVmHU4C9z
AsG2Om2lJa5UKhY1ahts9T1CqjY0EhpKEiY4IFJwqx4b45usFjsE82DGbTdA
vmND45yMpQlGQ5l5C1J6H2VQX8eL2wzrLiBoG94X0iYvg67DDOSbOm5lVYBl
aVvPDZg5pJBkSxt59OQJ2HiB2MbIdZTfXqeBic7S7hjXrXnKkWMczmKq4c9E
5214JkSLiw89wQ94nug1jr047riqgjJSD8iDbxG8RoNJ3VVo2GiDv0Pj5ICS
MR6RNaW5Cyi2Qh6LUV5FbRr1CbkQcDgaF6hOecHwEoBfNL6clLelPKAxY3E2
TpeUUtGGLhiGqFBudnK26on6RpDTLeZ6i9gWzGONQz1bDfmFBgd651KRUc7G
Microsoft
Service Pack
dd/MM/yyy
\root\SecurityCenter2
Select * from AntivirusProduct
displayName
SELECT * FROM Win32_VideoController
Win32_Processor.deviceid="CPU0"
Core(TM)
JCndrmfk7A1jDg1ebySrloEzwVo9sr3RCoUcHLye1YBbUuUoloTwq70JX6AJ
pQ4X4iao5UeVJashW59vXLkip2mLqC5v0qEJkUcmp9G6GAhhakZibgqqeMJw
n35HkHo28E7yKFvhzHOQ0KcOYzXH3cKipahzKGdFoqw1ZPdF1F4tiTHdJbyr
pF6sbUTU5a4koCZwItCtM1l54FThacMfHZqqZIUK1ViFAdp6jjlI5zLkDGmj
vldyZyCv4CVxVMRnCAZapmQwMNWGR2XyDliiFrbIcs5QZVXWkZkqfPKisBks
w5JJygWA8amIl8V6ME4maeaEhRWMrHidDIUaJBC0iRKRmOayCLh7dnvBEjGJ
mVKLI1Zt9fsVIT0FJescI9eYy4k0eYgMzKW8xrMcrunYEsdOwEKPAhUHNrFw
zM3AqdyDj4ah8weucG4NF4ZMgHj6UbWyGUMHvA3M9xOFOW1PzBiLowThRULK
z59OgePX3woQKiZntTVpaUYY6iscOUCss7HvzPbh8wa5RqVvbzxT9QWOeGzxuEHCHNHn9ZXwDcAQIYgjMilVtfS5u0elU
subszDXbVOWJ3zIEg7IpIl8eQQJCSHmCnPcT38Ldlu3LKJSYKwf8c9YZJhdKTQCKw6FtaUU9wVBkutJZcCZRxeecWZT2K
BZu6TlUeYBkEMJr4yAkyvVY7pUK64u3jeBApJo1ySuocGfj6rNKoEc4RZEsnxlNjQ2b0fx7rpgt8DYy2iC8k5RGKWWxkR
Oi2O2BuXaLaA5KBxts5xu0K3Z4YGJhWEsxWh3T9M8RInbVqJQKqRPt9Mri6plnVWnG5VPEHsfrB1JqErcsn53zXWE6OJF
836ysCOg03NL1hlnLxTAOHLBZx7xmWLT3s5StF0QB8KAkZ6tXTmLveYcg9D7qAzqh1b29LS4stSBUZCMjQg5tSwjn6cXS
STkOB3hGTWttd2eLfMKlosmFDkCdlS9cyuAvSvafqAb5RVFZ81tArrQF5cpLqcAyneKon9otmLQbkLXy80HjZr0qOXAdP
qaeCxHUC14KuNC0q2WVq9Gc1w2lJ8kBQ7gyKLtWq7IeQwlAPj9urCVf0xeY9DYoxMpHaF2jnZfQiXyNBQIjnOydG7UaOD
XBPQKcJTeXRjo1co4JcYruT7TPFeGzF1QWb8h7DQEcXghNnmQL2ZdJX3z6gCIlzvXYKaiboaJK7dj1NHFIHIHCUicumCX
dXFbdJv992Px0yjofmclovZshn7oXuXoDd5k9as1GslRWwr8DZOTwbGlQBVH4Vyll5IHA5RxIYU6zs2xHsHAgLxmkMUw7
eKGlkWMD4rfnxiyuvslylK5JBiWd9QivSNv27W0URQLLdTFZEk7xfMtvTZopUF7EuRkG27NojWpV7R
sDGJCdATJTxwha88uKzyQVtvJw0QWZoK6v7B2KFZQT1nQaCoD0NkFvf1ksAizts7EFIyuhHcvAthy6
TnVvvGwcxBfEfUd2uWeQgS0CVaAoM6TgrqMnwK6NDyzvnNjK7f5n13digI8mQjFr71pk5s9N77pDz0
LSc36HV8IZvicNj0Ab19aMgpAlBtV6NgjYJbOg2Td0f6OOQOs1J8cYBdRInFmPWmCKKr5saCQO0GT5
uninstall
update
Urlopen
Urlhide
PCShutdown
shutdown.exe /f /s /t 0
PCRestart
shutdown.exe /f /r /t 0
PCLogoff
shutdown.exe -L
RunShell
StartDDos
StopDDos
StartReport
StopReport
\drivers\etc\hosts
Shosts
HostsMSG
Modified successfully!
HostsErr
plugin
sendPlugin
savePlugin
RemovePlugins
Plugins Removed!
OfflineGet
OfflineKeylogger Not Enabled
Plugin
Invoke
RunRecovery
Recovery
RunOptions
injRun
UACFunc
ngrok+
Plugin Error!
ToLower
Open [
-ExecutionPolicy Bypass -File "
avVzBs4f73faQHKYglWPHpFp4z7EEDS5cbrlA9c1KNmFHdLCBXLO8WvmHTWcrZb3sksOFMGxrmkUx2
gezgPzHLDvXojqjADEGnUDmGTuUiWza4uNSoemce8gwQvBG0Q07OhIHsgF8eJ8qgUo1RBM0KCD5UHw
kFEg13N946RxStG46jbZlWBNWqN499QgJ3FAX1auvMWzfc7GUCsn8oEK1Tt2e7xCzEHb9y1kGUyux2
z6iZGVIhnMfT6t0yDzuYDRNGHwRDFBn8LlYMuoehcq25iGh5BHRqTdobMPpo9H2IistrI6GqnjJhfj
F5Ty4JCqF6EL7vpq24EZSXlj4GX83hKST65a8OgWwUczTwjLe84jc8qxLXIHfv198UVUb8Q04Z3OH1
SuA5He01OLpjKKXk83Vp3K9iqHdHYI3GthvN3Fo6lkpNuqFEJL8jCjxmjZut4x6BgKtWklVGEJMPWk
8rUFvYJAnKpO5MiM1feiAGikQ2Api6asGhHWC5Kboc5Z3hgAAUbz9CLWxfoRKTzzJRvbUco5SUwW3B
FYHsnjyWXJIZub9xiFTSTLbw1KTvaO03Fdx0bqXjGur2GntTqAGmXKbmSFIqB74dFdwjqxVKYelDRZ
dppaRguDOhDMyexYiCKY
iliq1rRNDjAzV0r3p6qP
ErnbuaoESBbAugYypd07
KCclZTVEMqtX3PbmOSxv
BUhL60wwN2N4es0FbY4A
B334h8YWS1fku51CpOrI
eoae4a5svH5S8GJuJage
zCg1pDud6cXAN2ho4cTm
POST / HTTP/1.1
Host:
Connection: keep-alive
Content-Type: application/x-www-form-urlencoded
User-Agent:
Content-length: 5235
schtasks
/delete /f /tn "
@echo off
timeout 3 > NUL
" /f /q
CsG6qUjxZdcwCrBg6vAR
h58jdNq03RLwoiE4mlh2
hwXcHNAv96Ud1NS22OWG
w4PMv4VaZtuUbD7iAmo1
KBcNfOSRPdTWQHXKvzwq
35aTJ9qJVeZ9QQ0wmjmK
JJsP7HGMVKUd2p7dFHkn
BSZPeY5rI2ZvaLddPe52
otGPW6UUEdF94lk3qCId
Software\
Mozilla/5.0 (Windows NT 6.1; Win64; x64; rv:66.0) Gecko/20100101 Firefox/66.0
Mozilla/5.0 (iPhone; CPU iPhone OS 11_4_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/11.0 Mobile/15E148 Safari/604.1
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36
abcdefghijklmnopqrstuvwxyz
Err HWID
ToArray
yXN3zgIwtsK4XvDxmwA3
qH1V2Kuv9NdueuGBWBTo
QuUaI6tDUlZrQb5nXLpQ
wti1dluQk3SZraicDihj
ndnmymAkP2iJCDwq9aK9
tmqQ7ptgc4v6dhTH3fcF
xERu2FVIHA2fU6vdc1Ny
nPZVVwpwQgUVi3emq1J2
ci9G7ontjMbJrKjxUYpq
g5TXqVUF9BY25rNUu3Ey
hdFZFFpt0EAN86Jg1dui
gLNnndCJiGV1zk5TDUIi
QHCkTtOpCvaDm36R1rQQ
7craafyoz6NngkdPGeHe
AiEpvENSWNRt1A43qdhm
DFHwLeX0X6iylV6eQPZD
QvgdXxsvSvI4CD2B7fKL
qceqB9W0rFUv5RbBw2u7
yqFnNKIdMItTiGDbXWE4
cwdpHtdxIyS1jzNPneah
5LsPCWzV3ty6eYGPMk8S
kTIkkAEAikZYLthaNfKq
9VhzB4klDQjEkR7ME555
yYNT5JkPJUnUck7auTzx
SmEdqu4G5z0DuWqE7BOJ
QCWZhWaeNRsv0md1nIzJ
KgAcFTvTfP5mWVEBUlMG
1vgRY9fw4VyfUOCoFjuy
abcdefghijklmnopqrstuvwxyz
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
FileDescription
FileVersion
1.0.0.0
InternalName
requirements.exe
LegalCopyright
OriginalFilename
requirements.exe
ProductVersion
1.0.0.0
Assembly Version
1.0.0.0
Antivirus Signature
Bkav W32.AIDetectMalware.CS
Elastic malicious (high confidence)
ClamAV Win.Packed.njRAT-10002074-1
CMC Clean
CAT-QuickHeal Worm.GenericFC.S32598663
Skyhigh BehavesLike.Win32.Generic.km
ALYac IL:Trojan.MSILZilla.25346
Cylance unsafe
Zillya Trojan.Agent.Win32.3917294
Sangfor Trojan.Win32.Save.a
CrowdStrike win/malicious_confidence_100% (W)
Alibaba Backdoor:MSIL/AsyncRAT.3c1179d8
K7GW Trojan ( 005aa5f01 )
K7AntiVirus Trojan ( 005aa5f01 )
Baidu Clean
VirIT Trojan.Win32.MSIL_Heur.A
Paloalto Clean
Symantec ML.Attribute.HighConfidence
tehtris Clean
ESET-NOD32 a variant of MSIL/Agent.DWN
APEX Malicious
Avast Win32:RATX-gen [Trj]
Cynet Clean
Kaspersky HEUR:Backdoor.MSIL.XWorm.gen
BitDefender IL:Trojan.MSILZilla.25346
NANO-Antivirus Trojan.Win32.XWorm.klmzfu
ViRobot Trojan.Win.Z.Agent.69120.BOL
MicroWorld-eScan IL:Trojan.MSILZilla.25346
Tencent Trojan.MSIL.Agent.16000605
TACHYON Clean
Sophos Troj/RAT-FJ
F-Secure Heuristic.HEUR/AGEN.1370976
DrWeb BackDoor.BladabindiNET.30
VIPRE IL:Trojan.MSILZilla.25346
TrendMicro Backdoor.Win32.XWORM.YXEDJZ
Trapmine malicious.moderate.ml.score
FireEye Generic.mg.00bcef19c1d757d2
Emsisoft IL:Trojan.MSILZilla.25346 (B)
SentinelOne Static AI - Malicious PE
GData MSIL.Backdoor.XWormRAT.A
Jiangmin Clean
Webroot W32.Malware.gen
Varist W32/MSIL_Agent.BUD.gen!Eldorado
Avira HEUR/AGEN.1370976
Antiy-AVL Trojan[Backdoor]/MSIL.XWorm
Kingsoft MSIL.Backdoor.XWorm.gen
Gridinsoft Ransom.Win32.Bladabindi.sa
Xcitium Clean
Arcabit IL:Trojan.MSILZilla.D6302
SUPERAntiSpyware Clean
ZoneAlarm HEUR:Backdoor.MSIL.XWorm.gen
Microsoft Trojan:MSIL/AsyncRAT.R!MTB
Google Detected
AhnLab-V3 Backdoor/Win.AsyncRat.C5360693
Acronis Clean
McAfee Trojan-FVYT!00BCEF19C1D7
MAX malware (ai score=85)
VBA32 Backdoor.MSIL.XWorm.gen
Malwarebytes Backdoor.XWorm.Generic
Panda Trj/GdSda.A
Zoner Clean
TrendMicro-HouseCall Backdoor.Win32.XWORM.YXEDJZ
Rising Trojan.AntiVM!1.CF63 (CLASSIC)
Yandex Clean
Ikarus Trojan.MSIL.Agent
MaxSecure Trojan.Malware.206830030.susgen
Fortinet MSIL/Conwise.RCE!tr
BitDefenderTheta Gen:NN.ZemsilF.36802.em0@ae!zYzb
AVG Win32:RATX-gen [Trj]
DeepInstinct MALICIOUS
alibabacloud Rat:Win/AsyncRAT.Stub
No IRMA results available.