95
Malicious
This predictive confidence of maliciousness for this sample is 95%.
55bc4407a03de9b13654755eea93e5b912fb4754ec0f95381740cb0692807b06
489.5 kB
2020-05-11 23:51:56
First seen 8 days ago
Windows PE32 Executable

Classification

Full Detail

Ransomware
Low
Trojan
Low
Virus
Low
Banker
Low
Bot
Low
Rat
Low
Adware
Low
Infostealer
High
Worm
Low
Spyware
Low

Indicators

Expand All

SecondWrite Indicators
Forced Code Execution
Automatic Sequence Detection
Program Level Indicators
Anti-Analysis
Attempts to repeatedly call a single API many times in order to delay analysis time
Anti-Sandbox
A process attempted to delay the analysis task.
Tries to suspend sandbox threads to prevent logging of malicious activity
Looks for the Windows Idle Time to determine the uptime
Anti-Vm
Queries for the computername
Checks amount of memory in system, this can be used to detect virtual machines that have a low amount of memory available
Checks adapter addresses which can be used to detect virtual network interfaces
Checks the system manufacturer, likely for anti-virtualization
Generic
Strings possibly contain hardcoded IP Addresses.
One or more potentially interesting buffers were extracted, these generally contain injected code, configuration data, etc.
Uses Windows utilities for basic Windows functionality
One or more of the buffers contains an embedded PE file
Creates a windows hook that monitors keyboard input (keylogger)
Infostealer
Steals private information from local Internet browsers
Harvests credentials from local FTP client softwares
Sniffs keystrokes
Harvests credentials from local email clients
Injection
Executed a process and injected code into it, probably while unpacking
Network
Performs some DNS requests
Packer
Allocates read-write-execute memory (usually to unpack itself)
Creates a suspicious process
The binary likely contains encrypted or compressed data.
Static
This sample contains high entropy sections
This sample contains low entropy sections
Stealth
A process created a hidden window
image/svg+xml

Yara


Yara Pattern Name Description
IsPE32 No Description Available
HasOverlay Overlay Check
suspicious_packer_section The packer/protector section names/keywords

Static Analysis


Version Infos

Translation:
0x0000 0x04b0
LegalCopyright:
Copyright \xc2\xa9 Microsoft 2016 - 2020
Assembly Version:
1.0.0.0
InternalName:
iZLeijuKSFmhgSkina.exe
FileVersion:
1.0.0.0
CompanyName:
Microsoft
LegalTrademarks:
Comments:
ProductName:
LibertorX
ProductVersion:
1.0.0.0
FileDescription:
LibertorX
OriginalFilename:
iZLeijuKSFmhgSkina.exe

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x00076698 0x00076800 7.85853115474
.reloc 0x0007a000 0x0000000c 0x00000200 0.101910425663
.rsrc 0x0007c000 0x000005c8 0x00000600 4.32767452121

Resources

Name Offset Size Language Sub-language File type
RT_VERSION 0x0007c0a0 0x00000374 LANG_NEUTRAL SUBLANG_NEUTRAL None
RT_MANIFEST 0x0007c414 0x000001b4 LANG_NEUTRAL SUBLANG_NEUTRAL None

Imports

  • _CorExeMain

Strings

  • !This program cannot be run in DOS mode.
  • `.reloc
  • B.rsrc
  • Xfefefeffe G
  • Yfefefeffefea
  • afeffeefeffea
  • affeeffefe
  • Xfeffefefea
  • Yfefefeffeef
  • +}P$a
  • Yfefeffeeffehah
  • affefeeffehah
  • afeffeeffeefXa
  • Yfeffeefefa
  • Xfefeffefefe_-
  • afefeffefeefa
  • $(o.
  • 6(sI
  • 6FsI
  • 6csI
  • feffefefe
  • ffefeeffe
  • fefeffefefe
  • fefeffeeffe
  • afeffefefe
  • 9fefefefeffe
  • ffefeeffe
  • feffeefef
  • feffeeffefe
  • fefefefeffe
  • afeffefefefe
  • ffefeeffefeYa*
  • feffeeffeefY
  • feffefefeXa*
  • ^feffeefefefY
  • 2feffefeefefa(
  • feffeeffefea
  • 9~feffefefe(
  • ##sL
  • lSystem.Resources.ResourceReader, mscorlib, Version=2.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
  • PADPADP
  • lSystem.Resources.ResourceReader, mscorlib, Version=2.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
  • PADPADP
  • lSystem.Resources.ResourceReader, mscorlib, Version=2.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
  • PADPADP
  • lSystem.Resources.ResourceReader, mscorlib, Version=2.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
  • PADPADP
  • lSystem.Resources.ResourceReader, mscorlib, Version=2.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
  • PADPADP
  • lSystem.Resources.ResourceReader, mscorlib, Version=2.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
  • hSystem.Drawing.Bitmap, System.Drawing, Version=2.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3aPADPAD
  • QSystem.Drawing, Version=2.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a
  • System.Drawing.Bitmap
  • IDATx^
  • iS2)\?g
  • Zbph)c/
  • Z4kDyT[:
  • \Px"}v
  • VdVgcZ
  • [%cW~
  • mGauSNi
  • er[J:w#d
  • 5Av<9{
  • )mAR5h
  • )_;gVw*
  • C;1~=E
  • UNrI|IC
  • OdGOcn^
  • L|F'bT
  • o+bMmg
  • x>q?/Z
  • i'HXRNt
  • Pq}%3
  • yT46@Z
  • )qS7bg
  • ^\yZp1*
  • HBRuMXZ
  • e2VKWQ
  • D=bdt*
  • g]a8@
  • <ZfEr=UMw
  • `%_/"R
  • '#OUQ%
  • +OdSVk*
  • Hym%>^
  • vO89|'U
  • ,v7qaE
  • -c/} p@
  • T'*g*pv
  • yJ<4[yyz
  • iz<PV`6~"
  • CH?VDF
  • (&xv )}F
  • #!RMi
  • UW(;dK
  • {?*hxo
  • ,s!oM;
  • /RgYqs
  • sBY' a
  • rk(utL
  • fcT!'O
  • 1!X)~dS>
  • :q^\&
  • IjM}t<f
  • +9'Lbn+G
  • %HXJ?q
  • 2;e4}Wj3\
  • vr~w9R
  • '2%TIF
  • t~Ylad
  • %)4u?G
  • .j%Syk3
  • Y$f-"+
  • -XHqY/
  • <\6_fO
  • /mj?P1
  • j#Y/&X
  • lBZ{1{
  • ~6&U~W
  • Ki3CUny
  • Kv{eb%
  • X>=X,L
  • S1~W}ob
  • .R_g*^
  • G]nY+=
  • 1w&^9~k
  • uQ$vo#
  • GWU.mh
  • v\v&lJ
  • <h#w}F~x
  • r_Gk3)
  • exw~Nvs
  • EFV$S]
  • ?DzI4rl
  • ]7N$2"
  • };p^iH
  • $a?u9F
  • N(aSV_
  • uoArAv8
  • tB OUG
  • |~6F+4Y
  • %|Z(aE
  • <r'F1)
  • CB044[
  • ^$s'l%
  • xGJ)n#
  • z,!jUc^
  • fp({/3m
  • N|wi!H
  • aZe2yk
  • IJ86`0
  • ,Kld%x
  • 3]Y3J,1
  • mH2Y#e
  • B?ldnr
  • '?jn0MO
  • 83t_#>
  • Ze(<Pg
  • ^c|Yu
  • 4Kv&?&
  • +m6N!d
  • 4d[`{+
  • 7m5by[[
  • {5N#7Q
  • \4$wJ3
  • R?:/~E=)d
  • v+!;G8
  • F]Y!FU
  • (p>@bB.a
  • TWt^|'
  • d+W0iq=
  • ^r]v1@*
  • =_osZ'4Bw
  • m8+>db
  • DuA2c1y
  • v-*Yb'
  • '##Qo4
  • gIr[Z(
  • %kd*z-
  • ;7R`'O
  • ?{NlZ#
  • *d%xZT
  • [+6y_2K
  • fdL3,r
  • dt{bU
  • Kv&<n0
  • >Y9o0q[
  • v+>eix
  • *@nVu.
  • &,z9++L
  • `Oe]<[
  • hFf}3S~
  • Wf3g_,}M
  • Y=eh}Y
  • sy'@.(
  • ]k8Vi#
  • GsY,;*
  • ~cy+O
  • I'Twd0
  • yeAZzw
  • n:}Gw!r_
  • F3:l/D1
  • {| :B)ZO?
  • feukz~~
  • k'rB0i
  • xCuIgR&5
  • !,uz2yxg
  • +9C&pr
  • ~JR2n>
  • uH fC/
  • *l.r2z1
  • ld@XM-#
  • *ks)3|
  • 2fhc~]
  • J0a+FZ
  • n8CPU4*
  • \n?(Dv
  • 6s]:ILX{
  • qW5yiKP|
  • :o^'G1L
  • ?Y$Xb8S
  • y{ 3zy
  • 'lo'.^
  • mWGung
  • p/FVtA
  • oO``m=c
  • %HL,Hv
  • !wA;6[
  • vW%ew'
  • BUjZ5%za4
  • +'O#[<
  • "3FYH
  • R|S5kM
  • C{\g,ch
  • 5eolSz?
  • ]/>a"@
  • wK@mg>
  • PW`B@6
  • Y()/Gq
  • I#uqO\"]
  • u</? )
  • Io%6LF
  • S6#(,2c
  • Mv{ph^
  • s$l>'F
  • ho /R&
  • PJ{U.Lb
  • ,1$Z01K!
  • `R^LX:
  • @^d*+p
  • z?z+6i
  • 7'<%C0
  • L_LMZ
  • TW2rF>!c
  • :~.lKGQd
  • \J_K7Qd
  • -#en/zn
  • s4nW^sQlr
  • N&#r6y\
  • 8k?fC
  • ;JNQ8*
  • 8v<=IA
  • mRM^rEw
  • _2Fg'.N
  • AFu\/R
  • _<)e3$
  • pMf9U6
  • $wc./i
  • omF9w.
  • \$v_&>g
  • tnL!=
  • Vwfcc_v
  • +z0"8C
  • '^hEY{
  • xp7o="A
  • &$U?Bw
  • iDZC-.
  • ~ChZw)
  • xxn'u
  • 5nr?`/
  • g9{J^0
  • qp(.B^
  • =3kF5(c
  • 8fKCY8
  • XMHcsZc
  • kZ@]lr
  • }f]_C_
  • p,#Tu8+
  • Loc.or"KC
  • OO&olDM
  • "g\FR>
  • IDATt)
  • m^shsS
  • !wQ{4m
  • z?ZMpj
  • ,e&~FW
  • R3t;u?
  • $Vv'|n
  • rY/j\;qh
  • ~fK)MS
  • +H|d.p
  • nH}uIyQ
  • n'X!Mi
  • ~UckRII
  • w7,"*$
  • 'BLHy]
  • /rfl jQ
  • |sbRIcF
  • )acd(U
  • Rz?#+]0
  • jywDlQ
  • ST1AlrY2
  • .xEdh+
  • nn(6yo^
  • l3U%&4
  • P2O|^:W(
  • 'fwdp@
  • *?Wfs$a!
  • 0)N}sE
  • Ibp\b,
  • 2?a_Qd/:a
  • ]i}k+]
  • JMD%MS
  • |JouEs
  • eKK\ei
  • 4y&X~\
  • kNQI{LF
  • m1?<v2
  • bCR$]<[
  • dy)%z6T
  • zf=O!\>LdJ
  • 8z_d/>
  • '_?]}W9
  • /Jn^4;
  • v;C9?4]
  • YARzNJ
  • *A#o!cE!
  • s m7JY'{q
  • p:v.%<"
  • P($J!JT
  • %M{0{43
  • M*K0)]
  • W~fQM=
  • T>|.@JI
  • OulJ7!@v
  • us"^e<
  • g?[q%H
  • Qa,VVbs
  • b~3wZ1
  • F}E-#R\
  • E:B&:)R.
  • @o(2&|&A
  • un=8t,
  • #WhEPC
  • d.HBC?F
  • }ZNC\S
  • jTmXDU
  • &{4?O@
  • rWGN+n
  • ;v2&le&
  • q$e__2
  • ^Haw+Al
  • i}$GZZ
  • rrC =^
  • \]=99!
  • ?Ya0]0
  • Np;$G0)[
  • ^Oi2f<
  • )7v#:4
  • &<qRb[
  • n]9^~;J|
  • co{L4)E
  • WC]N'2)Cq
  • o5W^ES
  • ?&Ulq^<oL
  • QO[lGVa
  • gp9WMf
  • d\H|O3
  • ?~<D%D)
  • 0(y4NQ
  • [#a]':p
  • 7]r<F24
  • Fo??'4
  • [Edc[B*
  • ;R8j2}
  • BImXoAz
  • Er:R(a
  • !mAru>C
  • v0+W~ q
  • GG~qU0
  • 'a^~U1
  • 2cF.33
  • %~cRh6n
  • KjOmZo
  • 4JeF+F_
  • @nOI55
  • WHGZS[
  • |tJe_][*
  • !tIz.H
  • ePCDh,W
  • 3\,Jm5
  • PRsHVm
  • 3E[[Ka
  • {EJLf_b
  • ji4~63
  • W31t"a'
  • []j0;m
  • o.UB$|X
  • qzNOdAM
  • |N7t"y
  • xv\(@F
  • 9n#344i
  • VXPh(Hgy.w
  • $sd-]v
  • D7UG^j'1&
  • Zw"r7qnT
  • QU:*@R
  • @js'01Glr]=
  • (r'Ow/
  • saKfkn
  • NO$ye>}
  • V\<niD
  • SX^)eA
  • i*O9qc
  • /g#p8S
  • ()+vT#
  • DM~&,H
  • m^\EP;;
  • |I\Njx?
  • d~^c.?q
  • #[w]ep
  • !yh<G[
  • H<'r_(aW
  • 84B:!q\#H
  • D}^.KJ
  • 'IXxy3
  • 5'#v11DN
  • U~8o}G
  • EJ6_bi
  • :kwztM
  • |*/zSo5
  • z"lLym
  • 3b~dQuV
  • 'jr>BI
  • g$xZfq
  • E4zuct
  • GIb0JQ
  • bpI,BW%
  • wV+NAcp2
  • ',ctl+
  • Mk"Q~a<M
  • 33\u1Ip
  • +yqm7v
  • #B=iYm
  • *k<A~q
  • uX+KQ3
  • Cq,NGgN4)
  • NNcE`_Vw
  • lQ?i@Q
  • zA2[<cx
  • 1tb,3.
  • 4Y}B=.
  • CxE5pe
  • VcOMx!
  • t#._taT
  • |f'HX<
  • {6pJw/Vw/c
  • 4Lx3j+i
  • UVSSh!
  • V;Si!=]o
  • +tcZL-n
  • z$'&og
  • (w&wx!k
  • WU:oqD?
  • `}C<f~
  • =eJ*[()
  • tz_LKV
  • v>Nvp%
  • yo$Nb!
  • fcEg:~o
  • 7~+n!z
  • NVG9uc
  • 'jhFFT
  • D$7;1,
  • Y&,Vc|
  • b$]UhUzO6
  • 1T4%y@
  • 9fYcq<
  • {Jto3V
  • , 'NRAvO
  • O&qs=e
  • gSOlg}
  • Jx";]G
  • CGY:Sz
  • O#qKGP\
  • zsxd0F>
  • PKyy%i
  • "hSY@D+G
  • 6qM1}-E
  • Iw+?w;2n
  • | Tu"
  • -S3>q
  • n-X3o%J
  • Wq&Fwv
  • ]d{zs:
  • WCtk;.n
  • ;n,Gd
  • ga9LBMU:
  • p.OUXi
  • IDAT\=
  • Ng*GZa
  • dYO4c%
  • ZGqV(fkt8
  • /d*.!o
  • $]=Et;[
  • 8FcGN
  • djYkYL
  • -S$h[3
  • Yo~1-d
  • 7y<mxD
  • =/y3QLp,
  • %xEf_9VZH
  • d:Qx_v
  • #7rmp<z
  • i"0$aH
  • MJ`r3%
  • ?y-e%x%
  • <nP`%SR
  • UeF|97
  • y,7Vs[2
  • \/Stvy
  • IBdzoH
  • afJNzw&
  • +X,HJvq
  • t;Ij/99a+
  • )N\0|
  • `ib3<o
  • itXJVt
  • ;cw]<c
  • t+SlGp
  • Ecl%9
  • qn(!&1
  • &eCiV4
  • RRTB{{
  • ?UJhX0
  • x>!d%Qe
  • -'d%|R)
  • RB![dD
  • UR!dSdUJENi
  • #zW}"I+
  • x$_(Ya
  • ]I!JBI
  • N>;BmF
  • p"QS&Q
  • -!jeLT
  • ,z>Ce6
  • $z~<-'
  • wm ]+v
  • y}cyF`oA
  • ~CoVtO!:
  • #f9.|3=
  • rzd<G]L
  • :xgzpz\%
  • ED"u3e
  • O_'{&
  • 0_Uz16
  • 9R/,C5Y4TU
  • |"Me1..
  • o$H"M(
  • ,{Ut6z
  • Qq<W~K
  • 1=.A7[
  • vY3h~n<
  • <dy2Hx"gw=
  • hfhXs2
  • 4}#/'N
  • pmugr\
  • ]!;.Q])
  • _\!;Nv&,
  • M$WuMx|_
  • UsFl;B
  • GV'.o&
  • ?ob600j
  • K?~_5f
  • @cA2;1h
  • @2?40uT
  • $#Awk/6
  • a<k{5pz
  • H%P?V^]
  • BaM5C^
  • BcVKu1|
  • NbpI0
  • d!!Y/(
  • yz#}><
  • i.q76a
  • .DBG~Fu
  • iOu'rV
  • Ki*ML6
  • ycF{#3~7J!
  • :EJm8cR
  • V+B,6a
  • ]6N>Ob
  • `Ny=_F
  • \ns\|I+nG_
  • @oA2aS'
  • g ?*Z3
  • gv-|E{
  • >6j<uK
  • qm*k[Nf
  • GwZtXG
  • r$xw$sB
  • 4Bno&jP.-
  • gSr?4Nzau
  • 0r=Fp6
  • *M^v%g
  • )h*]b_
  • UFM]*C
  • U63}x<;
  • freO:Es{
  • =Ik8_|
  • q5JKnQk
  • \_9H9J
  • t5#cLq
  • LWd{Y$E
  • ueZ`0V}
  • ]XT-7(*
  • $T~&\b
  • MRwDMe
  • x^>xq
  • d.;(\Z
  • v{X8l:A
  • {[>]M@E
  • )n)O+6
  • Q1ufnH%
  • iZT'hQ
  • f?9:Q>
  • @bjn`sH
  • %,t0$sZ'
  • hEqfj,G
  • X~iDC';&
  • /c*WQ{3
  • 5%Tjnca
  • ozWDhu
  • krN'3a
  • 'ng%W|
  • P2{%&%o
  • r|_b%?
  • N*B{EC66
  • ?q+v?f
  • WGx;`9
  • 4 K(0c
  • oA:R#+
  • zX =ng
  • Pjk20l
  • ar<mtSY
  • vDprf-
  • J{9Yca
  • <Wojbv
  • r6n/aY=
  • Jf_ ^'
  • %Cs<[_
  • CUx7]j
  • c(N-bY13
  • ?d$Us7Q
  • jX@]Z+
  • 7Y]B0k
  • '<!pC87
  • -3hxw4s
  • F;):oL
  • m+CPZ?
  • B|~?-*F
  • ~#@FrA
  • Emu>;>N
  • aCH>Q
  • ^dH@n}4
  • KFb:q.
  • WS,^x{F
  • {nROWJFi
  • {gzn[%
  • WpK{>>
  • <>UNTM
  • ELY9kg
  • I6Q>{(\c
  • Bm1p,A
  • #f=L qK
  • 0kK2Fd
  • q"SeN]
  • l.dc,;&
  • KJ[. x
  • |JP|Wt
  • N-ci*u7,
  • \^kI$!
  • A^WJ.\
  • },n1;I
  • QVj<gw
  • Zaub9#}K
  • .*'b4|=9
  • Wu$pw?
  • ^9{(Iu
  • lSystem.Resources.ResourceReader, mscorlib, Version=2.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
  • PADPADP
  • `/GJq>p
  • _B~`TG
  • k`qgmX
  • KXAd"a/6FK
  • L>r09j
  • 'a$5TQ
  • 0!IriQ
  • kLf9154mn
  • 8)\(O
  • ToeQP+i1
  • HlNS+y2
  • ;0oZ2?sZ*
  • 9=deqN
  • Zur+h
  • YaolPHT
  • &[_^51V
  • 7$%ZDU5
  • #,Eib.
  • _xpR>N
  • ;7zBxz4
  • %?MBKS
  • + Z9{K
  • vvAQ|:
  • DP#MvF
  • Q.(wmj
  • $J*WMf
  • >N;{|K0
  • ^>Q/.V
  • !vkYdI
  • h--86SK
  • arz\GP
  • j?Kbgx%
  • v2.0.50727
  • #Strings
  • iZLeijuKSFmhgSkina
  • iZLeijuKSFmhgSkina.exe
  • mscorlib
  • System
  • System.Xml
  • System.Data
  • System.Drawing
  • System.Windows.Forms
  • user32.dll
  • winmm.dll
  • .resources
  • .resources
  • .resources
  • .resources
  • .resources
  • LibertorX.Properties.Resources.resources
  • .resources
  • AppDomain
  • ArgumentOutOfRangeException
  • AsyncCallback
  • Boolean
  • Buffer
  • GeneratedCodeAttribute
  • System.CodeDom.Compiler
  • IEnumerable`1
  • System.Collections.Generic
  • List`1
  • ICollection
  • System.Collections
  • IEnumerable
  • IEnumerator
  • BrowsableAttribute
  • System.ComponentModel
  • CollectionChangeAction
  • CollectionChangeEventArgs
  • CollectionChangeEventHandler
  • Container
  • HelpKeywordAttribute
  • System.ComponentModel.Design
  • DesignerSerializationVisibility
  • DesignerSerializationVisibilityAttribute
  • IContainer
  • ToolboxItemAttribute
  • ApplicationSettingsBase
  • System.Configuration
  • SettingsBase
  • Convert
  • DataColumn
  • DataColumnCollection
  • DataRelationCollection
  • DataRow
  • DataRowAction
  • DataRowBuilder
  • DataRowChangeEventArgs
  • DataRowCollection
  • DataSet
  • DataTable
  • DataTableCollection
  • InternalDataCollectionBase
  • MappingType
  • MissingSchemaAction
  • SchemaSerializationMode
  • StrongTypingException
  • XmlReadMode
  • DateTime
  • Decimal
  • Delegate
  • System.Diagnostics
  • DebuggerBrowsableAttribute
  • DebuggerBrowsableState
  • DebuggerHiddenAttribute
  • DebuggerNonUserCodeAttribute
  • StackFrame
  • StackTrace
  • Stopwatch
  • Double
  • Bitmap
  • FontStyle
  • Graphics
  • GraphicsUnit
  • IDeviceContext
  • Rectangle
  • SystemColors
  • Environment
  • EventArgs
  • EventHandler
  • Exception
  • CultureInfo
  • System.Globalization
  • IAsyncResult
  • IDisposable
  • EndOfStreamException
  • System.IO
  • FileStream
  • IOException
  • MemoryStream
  • Stream
  • StreamReader
  • StringReader
  • TextReader
  • IntPtr
  • InvalidCastException
  • MulticastDelegate
  • NotSupportedException
  • Object
  • Random
  • Assembly
  • System.Reflection
  • AssemblyCompanyAttribute
  • AssemblyConfigurationAttribute
  • AssemblyCopyrightAttribute
  • AssemblyDescriptionAttribute
  • AssemblyFileVersionAttribute
  • AssemblyName
  • AssemblyProductAttribute
  • AssemblyTitleAttribute
  • AssemblyTrademarkAttribute
  • Binder
  • BindingFlags
  • DefaultMemberAttribute
  • MemberInfo
  • MethodBase
  • MethodInfo
  • ResourceManager
  • System.Resources
  • CompilationRelaxationsAttribute
  • System.Runtime.CompilerServices
  • CompilerGeneratedAttribute
  • RuntimeCompatibilityAttribute
  • RuntimeHelpers
  • SuppressIldasmAttribute
  • ComVisibleAttribute
  • System.Runtime.InteropServices
  • GuidAttribute
  • SerializationInfo
  • System.Runtime.Serialization
  • StreamingContext
  • RuntimeFieldHandle
  • RuntimeMethodHandle
  • RuntimeTypeHandle
  • STAThreadAttribute
  • Single
  • String
  • Encoding
  • System.Text
  • StringBuilder
  • Interlocked
  • System.Threading
  • Monitor
  • ParameterizedThreadStart
  • Thread
  • ThreadStart
  • TimeSpan
  • UInt16
  • UInt32
  • UInt64
  • ValueType
  • Application
  • AutoScaleMode
  • Button
  • ButtonBase
  • ContainerControl
  • Control
  • ControlCollection
  • Cursor
  • DialogResult
  • FormBorderStyle
  • FormClosedEventArgs
  • FormClosedEventHandler
  • FormStartPosition
  • IButtonControl
  • MenuStrip
  • MessageBox
  • MessageBoxButtons
  • MessageBoxIcon
  • MouseEventArgs
  • MouseEventHandler
  • Padding
  • PaintEventArgs
  • ProgressBar
  • ProgressBarStyle
  • TextBox
  • TextBoxBase
  • TextFormatFlags
  • TextImageRelation
  • TextRenderer
  • ToolStrip
  • ToolStripItem
  • ToolStripItemCollection
  • ToolStripMenuItem
  • ValidationEventHandler
  • System.Xml.Schema
  • XmlSchema
  • XmlSchemaAny
  • XmlSchemaAttribute
  • XmlSchemaComplexType
  • XmlSchemaContentProcessing
  • XmlSchemaGroupBase
  • XmlSchemaObject
  • XmlSchemaObjectCollection
  • XmlSchemaParticle
  • XmlSchemaSequence
  • XmlSchemaSet
  • XmlRootAttribute
  • System.Xml.Serialization
  • XmlSchemaProviderAttribute
  • XmlReader
  • XmlTextReader
  • XmlTextWriter
  • XmlWriter
  • <Module>
  • Settings
  • LibertorX.Properties
  • DataTable1Row
  • Dispose
  • Invoke
  • BeginInvoke
  • EndInvoke
  • OnPaint
  • .cctor
  • value__
  • defaultInstance
  • get_Default
  • get_SchemaSerializationMode
  • set_SchemaSerializationMode
  • InitializeDerivedDataSet
  • ShouldSerializeTables
  • ShouldSerializeRelations
  • ReadXmlSerializable
  • GetSchemaSerializable
  • GetEnumerator
  • CreateInstance
  • NewRowFromBuilder
  • GetRowType
  • OnRowChanged
  • OnRowChanging
  • OnRowDeleted
  • OnRowDeleting
  • get_DataColumn1
  • set_DataColumn1
  • get_DataColumn2
  • set_DataColumn2
  • get_DataColumn3
  • set_DataColumn3
  • get_DataColumn4
  • set_DataColumn4
  • get_DataColumn5
  • set_DataColumn5
  • get_DataColumn6
  • set_DataColumn6
  • get_DataColumn7
  • set_DataColumn7
  • get_DataColumn8
  • set_DataColumn8
  • get_DataColumn9
  • set_DataColumn9
  • get_DataColumn10
  • set_DataColumn10
  • get_DataColumn11
  • set_DataColumn11
  • get_DataColumn12
  • set_DataColumn12
  • get_DataColumn13
  • set_DataColumn13
  • get_DataColumn14
  • set_DataColumn14
  • get_DataColumn15
  • set_DataColumn15
  • get_DataColumn16
  • set_DataColumn16
  • IsDataColumn1Null
  • SetDataColumn1Null
  • IsDataColumn2Null
  • SetDataColumn2Null
  • IsDataColumn3Null
  • SetDataColumn3Null
  • IsDataColumn4Null
  • SetDataColumn4Null
  • IsDataColumn5Null
  • SetDataColumn5Null
  • IsDataColumn6Null
  • SetDataColumn6Null
  • IsDataColumn7Null
  • SetDataColumn7Null
  • IsDataColumn8Null
  • SetDataColumn8Null
  • IsDataColumn9Null
  • SetDataColumn9Null
  • IsDataColumn10Null
  • SetDataColumn10Null
  • IsDataColumn11Null
  • SetDataColumn11Null
  • IsDataColumn12Null
  • SetDataColumn12Null
  • IsDataColumn13Null
  • SetDataColumn13Null
  • IsDataColumn14Null
  • SetDataColumn14Null
  • IsDataColumn15Null
  • SetDataColumn15Null
  • IsDataColumn16Null
  • SetDataColumn16Null
  • mciSendString
  • GetIconInfo
  • CreateIconIndirect
  • Default
  • DataColumn1
  • DataColumn2
  • DataColumn3
  • DataColumn4
  • DataColumn5
  • DataColumn6
  • DataColumn7
  • DataColumn8
  • DataColumn9
  • DataColumn10
  • DataColumn11
  • DataColumn12
  • DataColumn13
  • DataColumn14
  • DataColumn15
  • DataColumn16
  • get_CurrentThread
  • get_ManagedThreadId
  • Concat
  • OpenRead
  • get_UTF8
  • ReadLine
  • add_FormClosed
  • set_Maximum
  • set_Step
  • set_Value
  • set_IsBackground
  • set_Name
  • get_Controls
  • get_InvokeRequired
  • set_Text
  • PerformStep
  • SuspendLayout
  • set_AutoSize
  • set_Font
  • set_Location
  • set_Size
  • set_TabIndex
  • set_UseVisualStyleBackColor
  • add_Click
  • set_Style
  • set_AutoScaleDimensions
  • set_AutoScaleMode
  • set_ClientSize
  • set_MaximizeBox
  • set_MaximumSize
  • set_MinimumSize
  • set_ShowIcon
  • set_StartPosition
  • ResumeLayout
  • PerformLayout
  • get_Width
  • set_Cursor
  • get_Graphics
  • Refresh
  • get_Height
  • op_Equality
  • ToString
  • Format
  • get_Crimson
  • get_ControlText
  • DrawText
  • get_Red
  • add_Tick
  • set_DoubleBuffered
  • add_MouseClick
  • add_MouseMove
  • GetTypeFromHandle
  • get_Assembly
  • GetObject
  • set_FormBorderStyle
  • set_MinimizeBox
  • CreateGraphics
  • DrawRectangle
  • set_TextImageRelation
  • get_Blue
  • set_BackColor
  • set_ImageScalingSize
  • get_Items
  • AddRange
  • get_Black
  • set_MainMenuStrip
  • set_Margin
  • GetFrame
  • GetMethod
  • get_DeclaringType
  • GetExecutingAssembly
  • GetCallingAssembly
  • Append
  • GetManifestResourceStream
  • set_Position
  • get_Unicode
  • GetString
  • Intern
  • GetName
  • get_FullName
  • GetPublicKeyToken
  • ReadByte
  • BlockCopy
  • set_Enabled
  • add_MouseLeave
  • get_Name
  • ToCharArray
  • get_Chars
  • get_Item
  • get_Text
  • add_MouseEnter
  • set_Width
  • set_Height
  • Contains
  • set_Item
  • get_Enabled
  • get_Pink
  • InitializeArray
  • get_TextLength
  • get_Now
  • get_Day
  • get_Month
  • get_Year
  • set_MaxLength
  • set_AcceptButton
  • GetHicon
  • get_CurrentDomain
  • GetType
  • GetMethods
  • InvokeMember
  • Replace
  • get_Length
  • WriteAllText
  • get_NewLine
  • AppendAllText
  • RemoveAt
  • GetBytes
  • get_Count
  • get_MetadataToken
  • get_SteelBlue
  • set_ForeColor
  • WriteLine
  • get_Elapsed
  • get_Seconds
  • get_Minutes
  • StartNew
  • add_Load
  • DrawImage
  • EnableVisualStyles
  • SetCompatibleTextRenderingDefault
  • get_IsAlive
  • get_Message
  • get_MessageLoop
  • Remove
  • Synchronized
  • BeginInit
  • get_Tables
  • add_CollectionChanged
  • get_Relations
  • EndInit
  • IsBinarySerialized
  • GetValue
  • DetermineSchemaSerializationMode
  • ReadXmlSchema
  • get_DataSetName
  • set_DataSetName
  • get_Prefix
  • set_Prefix
  • get_Namespace
  • set_Namespace
  • get_Locale
  • set_Locale
  • get_CaseSensitive
  • set_CaseSensitive
  • get_EnforceConstraints
  • set_EnforceConstraints
  • GetSerializationData
  • ReadXml
  • WriteXmlSchema
  • get_Action
  • set_Particle
  • get_TargetNamespace
  • Schemas
  • get_Current
  • SetLength
  • get_Position
  • MoveNext
  • set_TableName
  • get_TableName
  • get_DataSet
  • op_Inequality
  • get_MinimumCapacity
  • set_MinimumCapacity
  • get_Rows
  • Combine
  • CompareExchange
  • NewRow
  • set_ItemArray
  • get_Columns
  • get_Row
  • set_MinOccurs
  • set_MaxOccurs
  • set_ProcessContents
  • set_FixedValue
  • get_Attributes
  • get_Table
  • IsNull
  • DBNull
  • (System.Data.Design.TypedDataSetGenerator
  • 16.0.0.0
  • 3System.Resources.Tools.StronglyTypedResourceBuilder
  • 16.0.0.0
  • KMicrosoft.VisualStudio.Editors.SettingsDesigner.SettingsSingleFileGenerator
  • 16.1.0.0
  • vs.data.DataSet
  • GetTypedDataSetSchema
  • HUISAGHDIUOGDIAUDGB
  • GetTypedTableSchema
  • $07b9fba6-fee4-4688-b381-9dbe7f0e7e22
  • LibertorX
  • "Copyright
  • Microsoft 2016 - 2020
  • Microsoft
  • 1.0.0.0
  • WrapNonExceptionThrows
  • _CorExeMain
  • mscoree.dll
  • <?xml version="1.0" encoding="utf-8" standalone="yes"?><assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0"><assemblyIdentity version="1.0.0.0" name="MyApplication.app" /><trustInfo xmlns="urn:schemas-microsoft-com:asm.v2"><security><requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3"><requestedExecutionLevel level="asInvoker" uiAccess="false" /></requestedPrivileges></security></trustInfo></assembly>PADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGX
  • ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/
  • IpsvttdzmEGEuSYEv
  • &%'%(%)%*%+%,%-%0/5464;:<:=:>:
  • VS_VERSION_INFO
  • VarFileInfo
  • Translation
  • StringFileInfo
  • 000004b0
  • Comments
  • CompanyName
  • Microsoft
  • FileDescription
  • LibertorX
  • FileVersion
  • 1.0.0.0
  • InternalName
  • iZLeijuKSFmhgSkina.exe
  • LegalCopyright
  • Copyright
  • Microsoft 2016 - 2020
  • LegalTrademarks
  • OriginalFilename
  • iZLeijuKSFmhgSkina.exe
  • ProductName
  • LibertorX
  • ProductVersion
  • 1.0.0.0
  • Assembly Version
  • 1.0.0.0

Network


DNS Requests

Domain IP Address
teredo.ipv6.microsoft.com
watson.microsoft.com 52.158.209.219

File


Type
PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
CRC32
3D7FC4FA
MD5
e7662fce1cd01867c7b1731f2392fe56
SHA1
c35bc45e96f128db6223f8af3984b542aeb78623
SHA256
55bc4407a03de9b13654755eea93e5b912fb4754ec0f95381740cb0692807b06
SHA512
76c7156c7233f10853faab12bb6b3836d360764d6116c396238730e5d9d1716f9707b7f51006cfada4072800b3c72e062cfdeb51774454a08892b88bec1e8a3d
Ssdeep
12288:zRTIrT/Ly86OEAdRU7LLQB9U6XAwIxTfdqj:18rC8fEUUXLQBvexTfd
PEiD
None matched

Screenshots