Static | ZeroBOX

PE Compile Time

2021-03-23 06:10:24

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x00120374 0x00120400 7.55973740271
.rsrc 0x00124000 0x00000428 0x00000600 2.50712400742
.reloc 0x00126000 0x0000000c 0x00000200 0.101910425663

Resources

Name Offset Size Language Sub-language File type
RT_VERSION 0x00124058 0x000003ce LANG_NEUTRAL SUBLANG_NEUTRAL data

Imports

Library mscoree.dll:
0x402000 _CorExeMain

!This program cannot be run in DOS mode.
`.rsrc
@.reloc
a;+1A9
/@s>@d
wsl6p|u
&Mi%8{
#2~1lsv3
/qqR$]
Gr-JF
bs[3Ny
FI2~,i
Drm.b_
h-Q`L-
Um~)T{
($L4!Z
K(7b'Y_e
nB>oVW
IlR9^jh
rtt L[
Z?_b`
i,&%&8q
$Z oLp
^{h%&81
lZ eev
mtwfZ
($Za8^
)X;5%&8
S8BZ b
CwX%&8
;VlZ M
C|%&8b
Z xf33a+
J[Za8`
N!2Z R2
_bj/
_bY*
,Swa8?
qZ GhMma+
VG3a8X
Z:Z u~
S6=Z T
SCU%&
qA s%&
Z_bX
eul%&8T
(25 BK
Y_cX*
( 9%&8i
-\9Z +
xZ HJd
Tn6a8|
@X8 %+
Z gofma+
,= wHD
v,:a8|
wz_Z qo!
mmC%&+
U'Z g-
{Z ;] |a8G
^/uIZ
:Z 2Uh
1cVZ A
PzS]Z B
,; vH-
Z U.u-a+
/fRa8B
1TZ $j
!.QZ 7
Z |!~wa8c
)TZ *O
*Z xu1[a8
VM(Z L
l$jZ m
<3Z 6"V6a8x
Z _pgGa8
nZ !2R
@*W?Z
+aU#Z
k^HKZ e
mZ _g3
lZo|(
vN:4Z M?
2-M~(
tZ Il!
dZ >r.
TzZ H*j
+(GZ {
Gs={Z
)Z Kpu
?NiEZ D
**ol%&
X m80fa%
ozaZa+
cFp9%&
WLFYZa84
UZ @Y:
7iTZ =
X~16%+
CFZa86
/$Z M=
oiW %+
b=n7
|V[ E<
8GhZ |
R6nZ O
Z _Q^Ba8
Qj1FZ
^c4"Za89
wp4Z YKm>a+
,R >9gD
;(-a8c
Z P*La8O
}pZ B
+ro~ b
irJa8Q
y6fQ(
.:S%&8
QZ (y$pa+
!#Za8Z
.<Z 5A
1;\#Z n
Z Y6(;a8}
bagmZ 3[
5kZ xg
9Z pL
AZ $M{Ga+
#+d#Z
*Z *A+ja+
cl~a8Q
n/[%&8
*9Z H
0^dWZ
Nr1pZ
VZ wP%
I''}Z
>fmQZ
Z i-p}a8
Z .[xga8
B]ha8e
F<#KZ
_+zZ $
$+*Z ]UP
>]!_(
e</Z q
L>.a89
*WZ N,
"3<VZ +
Z O9$ma8
:4(a8_
,Z w3O
-Dy0 B~"[a%
e_Za8n
Z 6QP-a8@
u3<P%&
BTZa8K
PFio(
NA1mZ [F9oa8_
:9*DZ
^;!Z K
Z lm2@a+
{b|DZ 1
bZ ys
6Oba8L
SZ 5sHva8
lwDZ u
?/pZ sL)!a8
jaL;Z
I/@,Z
tmOZ K
T8\NZ (
lJ@a8c
Mh46
j}XM(
Z Qf_a8^
a~Ha8F
P2Z A`iYa8
Q#_v%+
d794Za8
Z 9*B,a8
Y]+a8|
<R!6Z
)BM\Z
=O||Z .
a7v-Z
'Z zGO
{eZ (E
I"V\Z %
QTZ ;O
i?fa8_
vaZ 7S
VZ 7TG
aaLwZa8*
=2sr
zF(a86
uZ zJ)
E*t8Z
SmEa8L
;=]Z .
eTZ Fo
-7zRZ
Z #7IRa8
N],CZ h
(C3zZ 4y;
Vctv+
}}2Z s|
QZY1Z
dZ T2%da8
($aTZ
-B{Za8\
8Z P6&Na+
Z rJ5Wa8
bWua85
Ni Z F
^69Z m
F1^a8}
?HZa8l
c(oE%+
{Z StG
PhrZ (G
BTYxZ
[23yZ
pE5a81
}$bZ p
{:>Z w
jZ Zu3
T:sv
M2$a8i
WZ A^
]^2GZ b
tPj,Z
ZIjZZ T
*yUa8*
*~F(Z
jnZ ^.
ZiC<Z h
X&6a8e
.aIa8*
2eZVZ
ZZ %3]
:+sr
K+Oa8G
3Jga8w
{jIZ ]
A:sjZ
/E@L%+
BK0Za8h
L.Xs8
DCLI%+
E{%&8(
|,lIZ
b[j*Z
5Z R=1
PKZ 0_
mhZ -$
HoZ q
]2%&8e
jt-S
"Tba8p
Icsv
q.~aZ
k)Z -=
@Csv
"/@Z [
Z s{{,a+
u9Za8J
Z Vf=2a8q
#66 %+
Z zWk5a8
,\XcZa8
%5^E5
nZ +cD
dAta8w
aF"Za8
?VZa8;
%?^E?
Z +1!Fa8
% 4sQZ &@1
(zox(
% L4[YZ
% 48)CZ
RdNFZ p
L$oa8Y
A;^E;
D!9Z [
Z ]Z7|a8
A c?v5Z
$<3Z i
GJDZ 1"
Z C?o%a8
A 9J/?Z
A#^E#
-wHZ JT
\,1Z W7[
A /A8DZ
A ANcAZa8
XCZ a-
A1^E1
A yoK{Z m
Z _\Ga8
Z vvOOa8
A Po}LZ B%*
0jZ V\i
A m_NtZ
A'^E'
A ^x%2Z
<2:Z &
A mNu0Z
A 'v\NZ
f*ZmZ ^(f
+V,a8u
fiitZ
qSZ h5
Z Ymk&a8F
sf&AZ
@NNQ%+
UPBNZ
1T5a8$
65Z pq<
mZ |Z9
Z y1{%a8N
Z XGC8a8
&eZa8]
uVLa8\
Z <ma a8
F`]qZ
Z F!}'a8)
Nn4)(
Y}Za8~
,D Gwt
v$Z t{0Ma+
1Z IEr
$Z t$x
IDvZ T/>
;=WZ 3
~<4a8m
&ZvZ '
aPJZ &K#}a8!
r},a8Y
Mp[(Z
S0d{Z
PG\Z T
Yt,a8O
>:7.a%
bnnZ DV
[};a8s
~%Z [z
R@cdZ
QsZ [^
_dyZ Y
iZ 9Gw
[o<.
&vZ h)
0lo&%+
-jHa86
Tua84
p~qa8
^V!&+
;O o.[ka%
o.[ka%
Z {r&_a+
BaG:Z
G o.[ka%
`VWZ {
<F%Z m9
%h{r(
95DZ 1
|OsZ B0
w.Fa8!
Z=Ea8}
=op}Z
U*sr
Z *vw5a8
?A,Z *_
',aZ )lE
29a8:
,V>*Z
}?VZ b
93|XZ
]8iw(
9Z _bj
Z 9dj8a8Q
-Z VJF:a8
V,Za8.
NZsv
O6V\Z
Z ,u=#a8
"Csv
6 sv
Z 7hbla8~
.[Z pb
R@Z ].]
Z B.b=a8
mZ %KT
X_/.Z BR|ua8R
'*Z c.5
IT0a8k
Z ~pQYa84
#Soa8e
2=EuZ
2f>Z B
;Z UStVa8|
zRKKZ =2@
WSha8}
g_dZ q
qZ 2.@
92sr
Z i^_-a8B
ppriZ
Ql:a8O
U2sr
H;Z VA
N&sv
]{5^Z x
Z o!}Sa8}
vHs6Z YF
lw<a8<
#6rxZ
U0sr
87sv
Z ,} a8n
Xqsv
MaU_Z *
4Z DVM
4vRa8v
`7v,(
V#sr
Z 35m0a8
)Z n%[
n$Z 0UT
:%?-Z
Mn?Z EH
tZ c>h
t]LK(
\XmZ S(2>a8.
;3:a86
Y\>Z 4
fY/\Z
#Z )`RUa8
xy@%(
U%sr
PZ l]r
Hf!a8O
Z w{J[a8
o1Z HR
V'sr
4WZ 4r
ff'|Z R
tx_]Z )3\ a8
Nwsv
/05Z M
RxBa8c
jx0*Z Z"
NQZ E~
`Fia8^~
nZ TGf4a8
pga8Y}
Z Sz6_a8t{
Sq9#Z
S,a8@z
T}7Z
?za8%y
.G9a8@w
Z V_Oha8
8Y>AZ
`|a8 u
2]a8Mt
TYZ W`
R*a8An
X[sv
+/a8(k
PZ I*Oxa8cj
-]5P(
Z AC;aa8Tg
leZ r
OE1Z T
rWa8Ze
0,|Z v
J*Ja8Sb
V&Z Y
Z nIZEa8t]
Q3a8A]
OS8uZ
Z T|MBa8
{[QZ je
p%98Z
))a8=Z
mJa8)Z
#CYeZ
p>D'Z
m(a8BX
Z OPXoa8
mLa8yW
aTZ "
*)sv
/c{a8$V
c$sv
<?Z Qy
>Dia8DU
WTZ {
Z hjg|a8
UZ hEl
J [EZ
2m#Z 
ZQa8ZQ
% 9X(
%$ Bg
%& h0
Z 2|Da8EL
nI(a8SK
1J`SZ
^"a8 I
5eZ \q
-\W8(
Z LSIca8
N@sv
|!sZ {
L8a8B
Z F}kHa8
,HD3Z
A]boZ
Z on5&a8
?m[<Z e=~
N1uJZ
6L~+%+
iTZ LyU
MOnuZa+
FRZa8T
Y`pfa%
(@Za84
aXZa8f
J{$CZa8<
zHaZ $L
ok:"Za8M
S+Za8m
@9Z 'm
(6fJ8P
R+h
Z `,wLa8i
&3/Z q
:@1M%+
oZ JCA
?!&*Z
(U!?Za8v
GAaa8\
.&4Z ^Rw
]Z u*+ka8
o<AZ L.
c$VZ X
iFOS(
WZ %&$:a8
TZ aXS
-5-1Z 4
dtUa8x
DZ xSu
1MMZ t
LltH(
R#Z >0tra8
~HZ jy
tXYa8\
PZ "z$
|/Z @G
xdkZ U
>"p+Z rz
uxlZ Q
BeZ 49
K{-Z
Z nn`sa8
2'_CZ
8W Z g
Z Jj>a8
B/MZ 8
%&$-Z
Z C]kwa8(
:@Z nc
t|$Z O
8X:BZ
Z YI^Ya8Q
I&rZZ
Y8Wa8|
O_;Za+
AZ I81
Z D.r]a+
Z EM%ha+
B;%&8J
@5Z 3v_
T']Za+
;EZa8w
Z2Za8l
"8Y,Za8
"yZa8U
G8CZ 9
Hva8U
Pboa8<
Z ~<T4a8l
lS}Z
XL1<+
fha8l
Z 1+E&a8
-4cb
fQ)=Z +S
T`h:(
j~|O >
Z w(1>a8e
^c 2Z d
C03a88
Z :m+.a8U
s*Z di
/!V0%+
me Z 3
yBSa8g
%V)TZ q#
[7Q%&8
yU(a%+
|)47Z
\^oa8+
6PZa8'
.)1ya%
Z x 6Ra8
}ll8
wbZa8U
5Y^i(
d,9a8p
3$YZa8
Z <B?2a8a
W&W;%+
niSoZa8
*2a>Z `
Z *N)
.+04%&
N;CQ%+
R#!Z )(
$1))Za8D
a^<>Z
MZ 9d Da8
_??GZ
st/Z /
8N4nZ G
6e4Z
w0]a8u
{)HZ Y6
\(Z wLC
Z 3#J;a8
wiL&Z ,N=Fa8f
X,]NZ
J@c.Z J
Z k<?Pa8
)iE2Z
v`@Z I5D
*bnrZ
M]EhZ
Z @]Gca84
ACsv
TuG(Z
2_ga8#
1|2a8I
GZ x*rPa8
Z 0D(Qa8
Z Sys9a8
5@5Z
v6Ha8&
Z 18e.a8
$Ysv
dCsv
dqsv
alHZ D
q|Va8u
qcZ j|
]dAfZ +#@"a8
1X:l(
"Z bp#
Z a.z/a8D
kzZ O4
Y%Z 3f%
sNZ RR
*fZ x T
"|PZ )
e8a8O
d+sv
Z <~_Fa8e
RZ i]6ia8=
Z weD*a8V
T%/uZ
RkSa80
Z vHG~a84
PHZ gN
`w'AZ 1U
zZ I#sAa8
Z Aq"0a8l
(1!1Z
PwZ 2=
|iZ :e|
3h`a8[
Z bhKoa8
gAK&Z
.$Ra8J
?+sv
:Z &RX2a8
Z 'sQ%a8f
)o-a8e
Z +HHja8=
dYsv
Z bcXa8
Z %>4$a8
VPu!Z T
Z 2a^va8T
?"Z r#
Kp"a8n
PiZ 3LL
g311Z Pci
nQCa8/
bR[9Z
1N7:Z o
|N9&Z ;yj
Z &28|a8
Z O%k
}7a8c}
Z l&Woa8
4iZ @^7
hX4ZZ .S
.9Z iic|a8
BFZ S>
aX0Z
1BZa8St
"Z "GBsa8
5=a%Z
Z xZQ/a8
,M}PZa8m
zOZa8{
<(_581
~hWPZa+
; jK94a%
O4dd%&
fxpZa8w
Cp+w+
u6Z gj9 a+
~&jZ +#S
kqwZa+
Z R%7Pa8<
@`8Z $
]?EN+
xeibZa+
t8=-%&
?>Za8T
Z $k,`a8w
5&! %&
S Es(
;%%FZ e
.s^>(
Z eQrda8
P\Z gn
aUZ Ut
Z ,9YVa8.
{t%&8y
"4m*%&
h-PW%+
@+Za8b
. `MFgZ '
.B^EB
s;Ua8\
ZcZ r*
8w)Za8
Z QITa8
9bZ 7jR
T[qa8}
[7E c_
\a=a80
?Z AzY
G,%&8~
N^J c_
6Z RN0
9 c:<7a%
Z ssn[a8
N c:<7a%
< 4+8
m c:<7a%
% c:<7a%
;Z A!R
5LAtZ f
,\0hZ N
porQZ o
CZ U?3
KQ'zZ
/}Z xzs
"Z O.{6a+
({OZ C
?;SWZ ?
9Z ~gW?a+
Z i\"@a8
432VZ
{Y;X(
tv]RZ I
>i&2Za8n
M:Za8D
`Z u8@
YaQ6
d^MH+
MZZ R5LAa8r
;JoZ
:=Za8-
^)@a8}
y!qZ MG
Z yU$/a8*
fw:a8@
GZ Z*P
Z sooa8
K Za8t
t=Z V>'
<#Za8x
J1|IZ I{
hThCZ h
'kQZ +
/ M)jra%
Z M)jra%
_^1Z R\
z<za88
#$La8l
-wZ sv
Z lp((a8S
pCZ ,'
b`+Z S
lIZ P1
? sv
Z 3PsTa8
8 .IZ
ElwZa8b
a<7\Za8
+W{Z A
.*Z w'
c5}Z ?
z+Z 9B
LZ &7
N3Z ~/
oyVa8m
`Z R>3
Z)~(
MDxi%+
_Z :vj
wZ L^G
VZ B@
{F"!(
,; ^w9
mBzm(
De<Z Z
<Z (vu
BAZa82
Fj\Z 0z
}Z R2k6a8
PwpZ MA
D:SZa8;
Z x0P;a8[
7ZZa8;
qZ W^1
rZoa8`
.nv oQ
Dp4Z }
zM$Z &
00sv
.{sv
Z vl39a8C
&@sv
aZ |O{
[sn_Z
Z *(n*a8x
g/ba8_
2eZ %p
ss)98l
,@ !=P
5Y^i(
^lE"Z +
hNfZ #
Po?Z $
1J`a84
8YZ Xv
n+ a8l
'Ef!Z
%s}a8K
UnmsZ
AZ 77/
$rtu%&8
~ Z 4B
(-\3Z F
R0"Z x$
~(4a8K
Z IV^Na8
,.}CZ
.YKZ +
\sCJZ
Z*sv
&Z `o'
PAsr
^#(8%+
'KVi
tZ Hz5a8
2e^a8i
E>]a8#
lkt5Z
Z NS.(a8y
!Z t4Xea+
J,IPZ
g!kU%&
QHG}Z J
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
PADPADP
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
PADPADP
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
PADPADP
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
PADPADP
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
PADPADP
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
PADPADP
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
PADPADP
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
PADPADP
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
PADPADP
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
PADPADP
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
PADPADP
Free domains grant acces to programs that are not
Internet Explorer And don't know how to use a proxy.
These would be programs like Shopfloor, ADP, etc.
Free domains allows all protocols, unfiltered to
The site you add
Free URL's allows Internet Explorer to access
Websites unfilters. For example if you need to
Allow a user to download a driver from Dell.
Only use this if you have specifically seen the
ISA has blocked this site message in their browser.
)Current Version = 101.17
Revision History:
Version: 101.17
(Updated by Dustin)
1. Fixed cancel button on user logon history filtering.
2. Added config.ini.
3. Updated ADP en/decrypt code to use config file's encryption variables.
4. Updated all remaining code to use config file's environment variables (domain, various LDAP paths, SMS server and db info, etc.) No longer domain specific with exception of ISA commands, these remain specific to CCM as no current need for functionality @ CPT or FSP.
5. Removed domain radio buttons and updated logic on RC and last PC results tools
6. Added ADP Clear button, with confirmation dialog. Same user permission required for update ADP button visibility
7. Cleaned up ADP Update logic to avoid writing "Null" as a string to any AD attributes, as a result fixed color coding.
8. Added enter key functionality to RC. When typing hostname or IP address, now simply hit enter... or continue clicking "Take Control" if you wish
9. Added mailbox size button! Displays mailbox size in KB (since limits are configured via KB - didn't want any confusion with forgetting to divide by 1024 vs. 1000) and status (under limit/over limit). Only visible if machine has powershell and if user is member of domain admins.
10.Replaced all colloquial/impolite messages with proper, meaningful language.
11.Significantly improved performance of Pop Up utility using dynamically dimensioned size list of threads to check computer status (offline/online). List of threads is defined as one quarter of the size of the table (up to a maximum of 250), threads parse table incrementallay rather than statically assigned start and stop points for each thread; accomplished via resource locking.
12.Added sorting functionality to Pop Up utility. First thread to reach end of table sets table as sortable after waiting 2x timeout value plus five seconds. This should allow sufficient time for all threads to complete, otherwise multi-threading logic would be disrupted if table was sorted prior to completion.
13.Added "Remove Offline Computers" button to make selections in table much easier! Not visible until after table is made sortable.
14.Automatically launches FoundUsers if SWIFT is not able to locate the specified user when enter is pressed or GetInfo is clicked.
15.Built logic to prevent crashing if attempt is made to close FoundUsers before search completes.
Version: 101.16.01 - not publicly relased
(Updated by Rick)
1. ADP Name added for legal name from ADP (where user's display name may be a nickname and not match in a comparison to AD).
2. Made Update ADP button invisible if not in appropriate group.
Version: 101.16
(Updated by Dustin; all prior updates were performed by Rick)
1. Added ADP ID to Account Info section; color coded for missing attributes.
2. Integrated Rick's mass CCM Pop Up Utility to ComputerStuff tab.
3. Added Update ADP ID button. Changed ADP label to editable textbox to accomodate. Checking for blank string and "Null" to reduce bogus employeeNumber AD attributes.
Version: 101.15
1. Added tab to last logon Computer that shows what software was deployed to a PC and the result
2. Added 'right click - copy' to some important fields on the last logged on computer dialog
3. Added 'Right clcik - Copy' to all fields on the all users logon history dialog
4. added 2 options all users logon history - Color coding and filter for todays events only
5. Added Auto update feature, nexttime there is a new version, you just have to click yes to update
6. Select and copy text in What drive
7. Added account enable/disable state
8. Added if user has IM or not
Version: 101.14
1. Added checkbox to filter out patches in the add/remove list
2. Color coded bad-problem causing programs red in add/remove list
3. Color coded office Green in add/remove list to make it easier to find quickly on large lists
version: 101.13
Changes in this version:
1. Added %CPU Used Column to Remote TaskMGR
2. You can now open Last Logged on computer without filling in the username box. (Incase you know the PC, but not the user)
3. Fixed the Floating Filter button on All users logon history
version: 101.12
Changes in this version:
1. Added more info fields in the About computer dialog
2. If present, Username now filled in when drive mapper opened
3. Added PC user history tab in more info
4. redid all users history to improve speed
5. Added R-CMD to computer tab for quick access to computer
with unknown user
version: 101.11
Changes in this version:
1 Fixed the discription field not clearing when new user is loaded
version: 101.10
Changes in this version:
1. Made the process list form resizable
2. Remote Command Promtp
3. Remote Task manager Imporvement
4. List ISA Exceptions
5. List where software is installed
version: 101.09
Changes in this version:
1. Added Lots Of Extra Computer Info on the last logged on COmputer screen
2. Added a random password generator to the reset password button
3. Added what drive is mapped lookup for users
4. Added Users location in AD to the user info pane
5. Added User Notes to the user feild returned in the main form
6. Fixed User logon history so that when a single user is displayed,
that users most current info is updated on the info bar at the top
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
PADPADP
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
PADPADP
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
hSystem.Drawing.Bitmap, System.Drawing, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3aPADPADJ
QSystem.Drawing, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a
System.Drawing.Bitmap
IDATx^
5|$N4tT
KA(A,_w,V
R6:{*w
cm0oDs
~;xm_pyG
#~\1fr
DwJnNz
h~kdsto
/7<w0-$
<[F0>e
8)Fq*aV
(h>lMy
\()[aM)
}>':~:
6]p?Z
'N#\@j
F|+3S7Q
%S2NL!
_'`XY`
]SA}=MZ
NZx+Y0
_?veKJin>
.f'bat
O\K!S;~
!9Xyt
\sDnxy
c,/:rU
C;@Ar(
<'#:Ou
QM]9c7
4[w[&~#
:6Vz,f[
l0J]v0k
U]k|]Vy
w0ybZI {
S$|NQS8
=[FqAj
)\tz|6u
~BYXa%>
515Y"6
n|xKmmS
ck9nJu
oQ?F<%
%`jhJ
: Dv-B
nDt+5)
]bjyER*H
Y|t|Ea
B:4##?
<e?r4V
g9v,mzY
67)BSD
"1kWy{
#5.m":b+
.<(%tb
{BR!Eq
WsM<7o
('Ki!Y#oa
|7sWAo
080$uJ
y>|^6H
NSEL-
c1VUk#
GG`l/4sjo
Y8V >6[
S_/q6d
<G/JUj
WT:bN,
`u@01A?3
lQv=?=
r(`*CX
/92X~@v
(^>J?Y
jB|#["l_
=H?j=H
(]u~kS
w}nd'r
sRL`l
&:+XK[
$(`,Nm
CQ(sfQ
!%^HQ_
de#V*-U
z>5B{o
hNp4$n
m~2_S=
i;.e?
<hU(sTD
i?S8vp_
yIIA]w
A+=H{
nkA{,,
pGT!G
TC N5v
{]:Uz]N
z26Y3+
I(%4]+Id
__"?aEe
wnNS la
5bsP02%
UE\8X
naCtb(
9P Z>/V
}f~&3xbo
bDB(O3L
F769|k
mG<~.
jKmKkyb
|[\$,#
\uDQoD
\8Ft|/
p<1t:90
R](Y<
_Er4}S
VVj&UK
D"YQ(:>
GB$LU(
f&N6l|B
=O*ZMg9
f(K?g(Wm
qtCotL
!-s'-
MVW)hg
Cqy.Bq
K}LkkU%
;*}HX"
&RFKwx
VUKoY9
\ENeA?
"1tpSN
H!C$RB1
k|.>Xu9,
1E08nK
G%y<Q+n<
h6K}s)
":<qRa
lWlXod
7t2Boj
Nn$]I7R
C[`MpBh
[\H/7F
l0.6:^0
RL:nSLNkQL
sab>7_`
{tlrm?
8|[0yhH
ezv8v=
utyl+c~
afjT~k
y<b27
n8YTD\
<,Hws,H
-<W3p.?3q
`&^g1U
XQKYDy3
S6rvgYx
i!Y^*2V
3A}!'X
PL^0GJ^
R+BzFAH/S
Ih2Xb\j[|
G47L[eml
;fOj"/
$j,\.f
2,;c>n
2)gltw
6~u/{Ka[m
;dBq<c
Ga'?L;
]e-eI&b,b
>g|{M C_#
L[ =Wy
'S/P<];
+86i+J
bYF*2
*N+K&V
1P9q7@[
EF.Ly(
d#.:[~
|y{h`.
Y T6(rw
{=mE,
^yDa@8
>q+@*>
[|vtU
\_j|q<
svs;+tn
e2";aMF!
\cqn[:
g!~|,1~
<T?>w
Svk;.Gc<r}
oLXYOno
mBi<hcm
O$o/y:
C^ %14C
'=k`-ua
}eU]om\Y
q=kn10
A4^A62
]-%_K#
36tfLv
Q:"+j+
SbvP_*G2
r[~[f@
Y/gyqz
d.tvx.
3mTEZ.>
:sn!Kx
^:BTDY
>H|fM\
M25=Qom
f&$LQ'
N<5eVePW
E5X1L1F
["fr<U
r%|=j%j
Z;-'&w
`m{K0h
bWcuGe
Pnw3NV
c)gX3Lf(M)
K1Mg(n
D`pbYw`
28G5PjQd:s
6F7u'a+m
23K`)'Uc)
`^!G):?W
Ey2K9lW
G|C/iMwm
U$e8Z(
3*Mm1Y
[c&90&
wGmMYy
}LCo:,
Hn~f;4
kg`!lFkN
`ZlLh10&
holAjF
'Q]5*E
?f&`"[
s3(` Kc>
xqt$dB
!#5{zh
>UJ(\[/
7*5R%
avexKMp9o
x?S[0_u
]%CP3b
ommwXliw
iUo.v;/k/
'ww1th
zG`P?:
q[Du&N
"Xm8!6yM
zp'|kKTfU
VxCM7T+uk
}B"Z4"
to\pl`$'=
"7R">?
Pgsuwx
C4+O><
#NUh^Z
rzr$0
I'\5`H
y^%d$N
dw~r/]
f]TdfZ
4zE0ff
m{+.@n
R<<i8,[
YxAx.x
wI]`,JqV
Ckw:l'
M8Vg4h
1d.@p5
y#wcH(
&?8ZUo
K\@Y-4
O*-*@(
7^3|l$
?z,,<AD
uf1,}$2
^w:1,2
DddO#2
D&Z>"s
>lw,XF
P&TtR:
X3!gzqY\
kqdqrH_
<c;VXw
];8s-X
AP$lA
36fqGP
6a2=$v
2e-X*mh=
!"8OXu39<
J_jY,;
R4{U &|v
%]r5+?
IU;Wh3{
~GO.m}
H'X)^3M
GOekOq
01#Qv8v
f5>;qf
iB>./A
mv0'Kv
O8tLrP7Xlp0X
^Hf?tl{
]?FVl>
<UF?_L
`hy[
lyzPXl:n
5Vif8)Vgi
?xL]~b
}{-etRJ
]rs"<\
,bclQ)
%<B82=^
S%$ylr
[V9l8-
dIDf2P
Le1VCL
9%r?7p
I4jQ+{
Xjo%v0
I'lxn)`Uw
nsZS?K
$kv3/c
k(DCRQ1
A@Njx.
4=^2`:P
1B=e<pl
#SphK
']OVVo
n-D}LF
U]*bm]zb<u
QgiA0'1]b
^maP7&
CB18i?
[7b3Z'2
O`3u&@
0V+eW]
HUIHs5
Qc&!J|x-
2~'QowV
L~!.lN
~_~"Ih
\VM<8-
g&M0;NOX
953(uK0
k2U3f"
+U>|B
^z~Oyu
|#1;(3
P%cJXF1
~iI.Yj
*?5w)=
3r7hvpY
8_9|Z
L.\X~Di
B+(aa`'nC
s>5Da0
!*xmG"
3.;}9)
78[Tk1
HV'4tu@
^ety|B
T!*h4_ib
i?rb},
F+L7M@
?t+C~~0
6c2\>K
n=U}2M
]]'3/
RepJL0L
.k/hg7K
0oBf;& 3P
;j>q b
K=i/1t
LFx*Zn<
\X^%}_j
= K.-]
T89U&Lq
(_)0G2
>YnRV1
bc]kbeuJ
d Fa2
_15O/n
_>E,M<5
=B!z(!
&B(HN1
;E__;n
K2/*3?
}7]@=o
@6g}k^k
I)eR,&w
XB_usO
+wtmK{
!xax^0
n>]}]Es
F1~A!a
elUVU5
_=P}<N
?FUm@)
!P?J,B
d13@:n
GbY^vaY&
CXv,!,
`o3>H&T
7I=L,>
t;C$n8K
8n8S?yX
S%n8G
q`8#f,V!
Unf1{,
bs/bJLH(
=Uy$RZ
)'P%yl
E;(kH M
kWlSS
@'6{L2
|:PvA
x)ojHO
Ja=s@bl
5IRvWI
H8k#cdW
qW1e$#
=/FJP_
6/Ph:zw
7`&;nl
/g%T?b
sZLktP
wVjDn
`6)AR'
fO}P"i
Hrcpi
sH !F#
BN% 1o
e)HmYp
\Xl<oZ(
8(&?D)&
,.cGUd
\+3om
ooJ?:<
dF!F\=G
7Tv6k
]oMAn0
Q.c'yv
5Yw5AF
Gn6u"7
6`(%0>
@A 2LM
~'~VoV.
OLi'qlM
5D'nK0g
( 8 "&
n:>xby
,Xdh'L1t<
vMGjCu
`(CBjW
N<R9<<D;M3A
hIeqvg
tA0s_=
ik5Gf[
!5k17b
@-]{NB
~s}T>u
q`M}o
2)\N7)<
m\FntX]
|*n{Op
c[cz?&
Kp4G@
;cU_d
~7M@H"
DzLV]h
o]H@W0
%Pe?@3A
a(BR# Q
=*<|_]
1R$9L)
m!,[j"@
L8')L8
U6s9IF+
_0~=A^
,N,Q$OA7
@J?F;l9T!Q
1_ygfO
|3ielU
K,KvW]
*P,#.;
%P'Rvr
k<q<0$y
8~7$BU
7N.L.E
=LSM_H3
c}:~8ch
%TTZPQs
gAf[xCV
hj\Iu%Wo
"*+Pu+
)C_4>~E>'55
=%xR(|
X^d|$t
t%.mu%.
oxc D+
6)b(S+
A@NU#P/
-C0e^
mWz}'Cjg
Rk$nXZ
GBs oq
_D@{
RgHA^
rE82]5
/V7//C
JBmw$.
[l^|~bih
TK3R5J
rZ;W{|
?bp<B] p
KD V/YS
PLRYzNRyTOR
PkA(}kN0
_vkWpW
,=9m1#
Q>/f)D
{S!FD^n
9B`5G,
Vj;[[,e)
\{bd%4
jI:_`4
0$+SQR
BOk&,;
{Zs}Oi3
e*}U+[
SNK'a{
)XMk>V
_{"`5D
n}w*>]`
&\xZ3M3
q:aH*|2
~mH;{>5
11g^U7
fq`aSk
'7Ggzq
s0+C_c
lA"1x$"
OOdwI"
7*[5.1[w
IC#bR{
dI/kM'
NYkVnh
YJ$(o@$
m>CGBs
9%._mv
u.A9}O
sb}emf
$f#S5k#
M`^M/
pL?>"e
`jQeY!
;BNd+lz
5?E_EUJF
Z/t03
[=(zT!
.<{2c4
g4Y;~tf
nzObeh"
9wi_"e
Z7O{5X`A`
D(fp%8
QnQ%Y=
o>)&}Ly
;("c*<
./Cy>s
n&M,>
R`T!Z/l
9vfvvvv
``FlW7#
g2#~R6#~Q4#~
hn~,Y?(?
W*36`Cf
$tS@P_
e0Z.Z>
bL0qbr
NVm;F@
T?kbmG
$?WVkT
7&U5qK
;?c&jC
O$G`"
ny8$b=
UOP),L:@&
v4Y"Mn;L`[
XUpoZD
Qd@9)X
_l0L)4
-z;#|%"
'>QDe2XTf
GHRCC
'sH[Y
1xjaF-
dfD3N$R#
KzHC]WPz
kK NmUX
<a99r[
<vkdU
'<X3Nl
@,J9>X
}z3a~OB
p?llml
Ad]7:I
[:a_m=
LtE6fk1C
}oSAc_
'/h8Qp
kBfeYG
a}0*P:
NP=x!6Bb
ffHvRx9ve
9@'6WmF'
Q!GLHV
VKjw`B
%Pkym
9gSh7(
/l<O-?$d
3> yUk
f5l.*/
SkzS%P1{R
UW_U|W
&'%fK7
?0i8X1.
LdG?Uv
Moh9Uo
VCRxi<
?g8br1
VCiCFx;
*M!d4M/
W24Nrh
{#7{6[
w+&lc~g
Za<iA5
n),${z3m
7c:L#z
Mw%<J<Z
ib~TbA
GHjKy$
|zuW7(I
j\C;mO
HrPp@7
3A;\Mu
kIsVur
Lp#[%=
i8!xUm
n<=ucN{
*`I]W`
kZ}$*8
17DZ2;
7*0;D}Kv
%;o[
wo1<Jx
ebJPG(
\lf'Xn`#
MQ&x>O
WoS,^q
3UA?ZI
}DG#tA
p^O@]&
'RP4a<
Du=s^}
#kzPRm
xDW[Qq
~3<LxU
FR(dR=
/T>\:X
Y1tQ:.
RNR)hK
sQ=_d!
_/UKZHV_
+5wS>v
@OKbAY
exk\mH
E49`MXy
,>-Ynev#
;k lA2
yrj,<o
q<'L,k
Y9.o\%
8_A/?2
kxj]0@|
{xz"K?LhE
NU~aPo
,OWy1v
4I'a7}71S
@_| j-O
Q5\MyX
W0abKp
5Z#c*!p
vKOxd3
&(H><9
"4'd;=>
lYL2HupW
K,?=}2
%:J!f;o
Ixhf=p
/|ld~
o$?tnc
xH,;'H,F
#pYo7@I
vm%`<P
+!.OL`.^
C}o&k\
;^#P"V%U
Fh[6Qd
Lh-s&|
i/6!xdW
;LD3WG
[jXoB4]4y7qq
p1%G`v
HRZ):P
1G%6w?
o\pXl'
X/AkWg
O>26}
@R(NK4
(sp[5:[u
4**R=L
*|`w`?%K
bcy((%
lZQuGE JF
y\3 yR0
Gt$azA>ki
^J=ac9[
~a9k7)R
p)g}~*
@bXpp9U=P
4aK~.a
&J$*Kf
xGRK'_
Qk5{:w
jcoE_
9@[9K5Kql$
7-yx?ho3
/+b{_6
iY)wW$
,mEkoD
/rWGQh#7[
F{b-E>
c=Nm*t
>|ym6|y
/Gbs7`f
DHa[k:
(Z?wgu
g7H~:S
d=Q?"?N
%yYN!u/
nlo1nc |
;T1B|&
e-Vs54"
JZQ.zY
3@}PG<-
}00F!V?
&#O4u:
u5c{CE3
!B sKw
i3_=t $
heV|(Qz
wh:N)~
=SU%`)E
M0NL8~L
<9NQ1
c#>G z)
>]cEK-Kf{A
0.?=!;
lPfr-_B9]:
Qda~RU
Q'Q@C=
}p0;$|
($F;0"
)uwr1I
L2xbG28
\yrq-_
1{q{UD
yZ,v)]n
Y&e2`[/2
0z,{~O
7;^*{4t
4@9#D*g
-gvnlr
9rR8OSR
U (~l{
Dqnsn
qg$Pob
_rI,S%e
+~CoJ>
!3$w$1
3?j.f|
RNSUC
>i;P"k
7YlJaq.
@MTv8Y
IbfOvR
rd_P0'+
{/%<X4=N
pEa4]W
1lRRMD
h+Jm+
_yYPc"s
PDi[4Q
Ol`g 6i
]":8Khxy
u`$h`b
9v41&x
&ur ]i!V
TO(d>=(
mN7a5wEk4
9ZUhQVKbQY
*=4DFex1
]Ve`\p
>yd:B~lN9*!
',m+APG
aB},4_}
GJK19G
1G"a#)
d:9m.H
D!Dw<o
>J_P?i
lF(;15
qu0@|l1
NimW|+
~fgvvvwrd
TxY/C\
Awo/if
tskmgtg
s'aKT_
{BcOFe
m$te\9
Vg8>7x
'M-@Y7
']{T}v
%~tl{\
$]{pyw
Ilt8Gl
LD9D#R
D@jSb@Xc
v#|kw#|
gYuW4w9\(]
4^3D3h#5
{{`k>e
`J]iuo
|<yBg&
R#>B*d
"Ap7'\
3{Ju#11
"nAS|{Y
xt]ml
6A$Jz*
Z;PoeA
&rEjAP
Mm8j[m8;
@2{49^
%bXfZk
$>V\V<
/CH\zv
*AuDH|
n8">7|
0>i;GDa1ZW
}{7\Zu1\Gw>
eIrQ^H
dSxz7c
-BoB=)
&*fSK
)y7/,/
9;$z;I4J2
T/6d/
XJW/;Y
>bt%g1
Gh,Tt,
*%"qJ+G!
#R7BFL
.I+BXp;
2rx%3s
[~@Gm
7{Yi+x
Ll^Wvw
e=ZEUt
r7,*&F
x?m)WJ
vNxykiO
s)Mr^b
eH?:QV
s 01({
35v"mw
rar/Jwn
2y K&g
)]YvY?
b{CLbn$#i
(r)m?`ui
%P>}~0
Ywfd>`
hj\'\o
@g,4yJ
R{(#:-
~}bM$r
"1,C=s&
"Q3w,K}
3E?g*X+
IiQuGj
igx c,
Enrq'7el&7
40N$)H
r>zEiI
$y2YD8
7[Tb1[DU
I%Z<.s
Ps"]X
iCZlRW
l;luT^3
X-8r'f
<S9>O/
jl;PQ,
7}>:;E
Xm)`D {
,2[rwc
p9R^=.
t:yHp
CP)C|@
0RM"5w
IQMr57+
{|A}$k
'*s~8%
]zGY^wK
%^X/aZ.]|y
}G#iW@
Ch O#*
HwzjTR
>y/=0
Mo.liF
!K;HF#
*]vile1I
PP82vjp5!
WUH409@
9\<4h3
6qn1-b
4O!!b(_,N
#u@G~(
8 W^9)
<M22e
bT`bEUW&^
<2>~OSo
?1?<7}_
LyTpEu
{hlek&
-l,J?:
bpLj[:w
/5wjO><
hINqD?XK
q?O5s]
MFoe?9
O,M-pN
Iv5Iv
xogx#n
_<s:[9HW
Ot9+S>
g[8nHW
.y9!]O
g Md|NI
mfN?"s
aqVIvI
$+FM$3G
z<a:G6a:C
.Ivgj_u
My {qZ
4QbD_<:
Uvcq`ua
o(=9Q@
w?-3tYNN
5j7<uu
yyRmEy
[wW/|:7
!x;qY%
fmuz{T
&vZo),
lEk&17
F1\./*
-Bl*bA)
ost&+r
dd$Cx_
Eg2C$r
eF7.OK
|fb/%7F
L2n}Nn
J<8~%=KY:y
kZn&k
Sc"]$,w
(T2:D(
##gw"m
g"~yB4
LFnQv
cb.|MLDM
`f?1Sq
0.+ug6S
?SirBo e
oY!_Oj
jiZ>(=
pIgE+=
#Iy3su
kr{(sr
HWo"ye
urnsfN
^3uj+4
=ie}6]
!u `e D
qo3b7F
05V LM;
s<&kuk2
~r>Ewpc
(Q5u%%t
Q9XeGY'$
!9^8Er
OgK4~8F
:TMx:TM
)The K
_ VmzVS{
&%[([E
V"/N9s>
X J"wtf*
u%"[Y#
K|nec^z
Antivirus Signature
Bkav Clean
Elastic malicious (high confidence)
MicroWorld-eScan Clean
FireEye Generic.mg.d27e2e5039cc62ca
CAT-QuickHeal Clean
McAfee PWS-FCSU!D27E2E5039CC
Cylance Unsafe
Zillya Clean
AegisLab Clean
Sangfor Clean
K7AntiVirus Clean
BitDefender Clean
K7GW Clean
Cybereason Clean
BitDefenderTheta Clean
Cyren W32/MSIL_Troj.ALO.gen!Eldorado
TotalDefense Clean
Baidu Clean
APEX Malicious
Avast FileRepMetagen [Malware]
ClamAV Clean
Kaspersky HEUR:Trojan-Spy.MSIL.Noon.gen
Alibaba Trojan:Win32/starter.ali1000139
NANO-Antivirus Clean
ViRobot Clean
Rising Trojan.AgentTesla!8.104D5 (CLOUD)
Ad-Aware Clean
Sophos Mal/Generic-S
Comodo Clean
F-Secure Clean
DrWeb Trojan.PackedNET.598
VIPRE Clean
TrendMicro Clean
McAfee-GW-Edition BehavesLike.Win32.Generic.tc
CMC Clean
Emsisoft Clean
Ikarus Trojan.MSIL.Crypt
GData Clean
Jiangmin Clean
Webroot Clean
Avira Clean
MAX Clean
Antiy-AVL Clean
Kingsoft Clean
Gridinsoft Clean
Arcabit Clean
SUPERAntiSpyware Clean
ZoneAlarm Clean
Microsoft Trojan:MSIL/AgentTesla.ACG!MTB
Cynet Malicious (score: 100)
AhnLab-V3 Trojan/Msil.FCSU.C4386443
Acronis Clean
VBA32 Clean
ALYac Clean
TACHYON Clean
Malwarebytes MachineLearning/Anomalous.100%
Panda Trj/GdSda.A
Zoner Clean
ESET-NOD32 a variant of MSIL/Kryptik.AADC
TrendMicro-HouseCall Clean
Tencent Win32.Trojan.Inject.Auto
Yandex Trojan.AvsArher.bUbzqH
SentinelOne Static AI - Malicious PE
MaxSecure Trojan.Malware.300983.susgen
Fortinet PossibleThreat
AVG FileRepMetagen [Malware]
Paloalto generic.ml
CrowdStrike win/malicious_confidence_60% (W)
Qihoo-360 Win32/Heur.Generic.HwMAFg8A
No IRMA results available.