Static | ZeroBOX

PE Compile Time

2021-04-27 23:08:03

PE Imphash

fa677faa551dd71de23395a2baeb8056

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x00040ba0 0x00040c00 6.83864459664
.rdata 0x00042000 0x00010fa8 0x00011000 6.75292942294
.data 0x00053000 0x0000a470 0x00009200 7.82073832642
.pdata 0x0005e000 0x0000168c 0x00001800 5.36696834451
.vtbs 0x00060000 0x000030c0 0x00003200 7.91560543219
.gfids 0x00064000 0x000000a0 0x00000200 0.811097944555
.rsrc 0x00065000 0x00000240 0x00000400 1.77762143552
.reloc 0x00066000 0x0000062c 0x00000800 4.78216131642

Resources

Name Offset Size Language Sub-language File type
AFX_DIALOG_LAYOUT 0x00065198 0x00000002 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_MENU 0x000651a0 0x000000a0 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_DIALOG 0x00065110 0x00000088 LANG_ENGLISH SUBLANG_ENGLISH_US data

Imports

Library KERNEL32.dll:
0x140042020 HeapAlloc
0x140042028 HeapReAlloc
0x140042030 HeapFree
0x140042038 HeapSize
0x140042040 K32GetModuleBaseNameW
0x140042048 FindResourceExA
0x140042058 GetVolumePathNameW
0x140042060 FindResourceW
0x140042068 OpenPrivateNamespaceW
0x140042070 LoadLibraryA
0x140042078 GetProcAddress
0x140042080 VirtualProtect
0x140042088 GetProcessHeap
0x140042090 WriteConsoleW
0x140042098 CreateFileW
0x1400420a0 CloseHandle
0x1400420a8 SetFilePointerEx
0x1400420b0 GetConsoleMode
0x1400420b8 GetConsoleCP
0x1400420c0 FlushFileBuffers
0x1400420c8 LCMapStringW
0x1400420d0 VirtualAlloc
0x1400420d8 VirtualFree
0x1400420e0 GetStringTypeW
0x1400420e8 GetFileType
0x1400420f0 SetStdHandle
0x1400420f8 RtlCaptureContext
0x140042100 RtlLookupFunctionEntry
0x140042108 RtlVirtualUnwind
0x140042110 UnhandledExceptionFilter
0x140042120 GetCurrentProcess
0x140042128 TerminateProcess
0x140042138 QueryPerformanceCounter
0x140042140 GetCurrentProcessId
0x140042148 GetCurrentThreadId
0x140042150 GetSystemTimeAsFileTime
0x140042158 InitializeSListHead
0x140042160 IsDebuggerPresent
0x140042168 GetStartupInfoW
0x140042170 GetModuleHandleW
0x140042178 RtlUnwindEx
0x140042180 GetLastError
0x140042188 SetLastError
0x140042190 EnterCriticalSection
0x140042198 LeaveCriticalSection
0x1400421a0 DeleteCriticalSection
0x1400421b0 TlsAlloc
0x1400421b8 TlsGetValue
0x1400421c0 TlsSetValue
0x1400421c8 TlsFree
0x1400421d0 FreeLibrary
0x1400421d8 LoadLibraryExW
0x1400421e0 GetStdHandle
0x1400421e8 WriteFile
0x1400421f0 GetModuleFileNameW
0x1400421f8 MultiByteToWideChar
0x140042200 WideCharToMultiByte
0x140042208 ExitProcess
0x140042210 GetModuleHandleExW
0x140042218 GetACP
0x140042220 FindClose
0x140042228 FindFirstFileExW
0x140042230 FindNextFileW
0x140042238 IsValidCodePage
0x140042240 GetOEMCP
0x140042248 GetCPInfo
0x140042250 GetCommandLineA
0x140042258 GetCommandLineW
0x140042260 GetEnvironmentStringsW
0x140042268 FreeEnvironmentStringsW
0x140042270 RaiseException
Library USER32.dll:
0x1400422b0 RegisterShellHookWindow
0x1400422b8 DdeCreateStringHandleA
0x1400422c0 GetGestureConfig
0x1400422c8 OpenDesktopA
0x1400422d0 SetWindowWord
Library ole32.dll:
0x1400422e8 CoGetObjectContext
0x1400422f0 HICON_UserMarshal
0x1400422f8 HMETAFILE_UserSize
0x140042308 OleCreate
0x140042310 SetConvertStg
Library GDI32.dll:
0x140042000 CancelDC
0x140042008 D3DKMTCreateAllocation
0x140042010 AddFontResourceA
Library SHELL32.dll:
0x140042280 None
0x140042288 ExtractIconExA
0x140042298 SHGetInstanceExplorer
0x1400422a0 None

!This program cannot be run in DOS mode.
`.rdata
@.data
.pdata
@.vtbs
.gfids
@.rsrc
@.reloc
tO=T8R
AWAVAUATVWUSH
L$ I9M(r+
|$0r8I
8[]_^A\A]A^A_
AWAVAUATVWUSH
[]_^A\A]A^A_
AWAVAUATVWUSH
yR\,D!
H9u(s4H9}0s.
[]_^A\A]A^A_
;^`t7H
AWAVAUATVWUSH
[]_^A\A]A^A_
oW#qt]
}t&=WC
AWAVATVWUSH
0[]_^A\A^A_
AVVWSH
([_^A^
AVVWSH
8{oy.u5H
8{oy.t
AWAVAUATVWUSH
D$0x_P=
D$H{*M
>L6f$|
X[]_^A\A]A^A_
AWAVAUATVWUSH
%[1"<i
D$p5BM
D$(YN}<A
D$@%;=
8pRG:|6H
[]_^A\A]A^A_
AWAVAUATVWUSH
h[]_^A\A]A^A_
E;4$uo
E;4$u8
,$;.}4D
D$PD;0
AWAVAUATVWUSH
D$\>zV
h[]_^A\A]A^A_
AVVWUSH
p[]_^A^
"N9*ue
/;.|AH
AWAVAUATVWUSH
D$8/XU
D$ X1?3
D$pD;8
[]_^A\A]A^A_
AWAVAUATVWSH
D$8~|,
p[_^A\A]A^A_
AWAVVWSH
[_^A^A_
AWAVAUATVWUSH
[]_^A\A]A^A_
D$t{*M
AWAVAUATVWSH
@[_^A\A]A^A_
AWAVAUATVWUSH
h[]_^A\A]A^A_
AWAVAUATVWUSH
D$HUGD-H
D$d>zV
?Q%# uCH
[]_^A\A]A^A_
AWAVAUATVWUSH
X[]_^A\A]A^A_
AWAVAUATVWUSH
D$H~P@
h[]_^A\A]A^A_
D$8f&l
;N@|N1
D$ -1`
AVVWSH
H[_^A^
AWAVVWSH
0[_^A^A_
AWAVAUATVWUSH
D$0.D8%H
l$l9,%:2
s`0QvLG
x[]_^A\A]A^A_
AWAVAUATVWUSH
[]_^A\A]A^A_
AWAVAUATVWUSH
[]_^A\A]A^A_
AWAVAUATVWUSH
D$p5BM
D$`{*M
D$(Wcy<H
x[]_^A\A]A^A_
AWAVAUATVWUSH
([]_^A\A]A^A_
AWAVATVWUSH
D$@vP)
p[]_^A\A^A_
AWAVAUATVWUSH
%1@;;;8X
[]_^A\A]A^A_
L$pD;!
D$pD;
AWAVAUATVWUSH
x[]_^A\A]A^A_
AWAVAUATVWUSH
D$T39C
|$hA9/
[]_^A\A]A^A_
AWAVAUATVWUSH
D$ dq#
x[]_^A\A]A^A_
AWAVAUATVWUSH
D$ >^G
X[]_^A\A]A^A_
AWAVAUATVWUSH
D$h4@d
D$h39C
D$0/NE3H
[]_^A\A]A^A_
AWAVAUATVWSH
`[_^A\A]A^A_
AWAVVWSH
[_^A^A_
AWAVAUATVWUSH
X[]_^A\A]A^A_
AWAVAUATVWUSH
8[]_^A\A]A^A_
AWAVAUATVWUSH
D$ oyn<
D$h{*M
D$|{*M
D$d{*M
D$h39C
D$d{*M
D$0HD{:H
[]_^A\A]A^A_
AWAVAUATVWUSH
D$P5BM
D$T{*M
x[]_^A\A]A^A_
AWAVAUATVWUSH
D$\{4\<
l$X=OA
x[]_^A\A]A^A_
D$86M-
D$h;(~
AWAVATVWUSH
D$T{*M
D$(2OG
p[]_^A\A^A_
D$T39C
AWAVAUATVWSH
p[_^A\A]A^A_
A92~OA
AWAVAUATVWUSH
D$ "Vh=A
[]_^A\A]A^A_
AWAVAUATVWUSH
D$8\A&5H
x[]_^A\A]A^A_
AWAVAUATVWUSH
D$\E;4$
x[]_^A\A]A^A_
AWAVAUATVWUSH
X[]_^A\A]A^A_
AVVWSH
H[_^A^
AWAVAUATVWUSH
[]_^A\A]A^A_
AWAVAUATVWUSH
[]_^A\A]A^A_
AWAVAUATVWUSH
D$d=yP
x[]_^A\A]A^A_
AVVWUSH
XU#[]_^A^
AWAVAUATVWUSH
8;:~1A
d$pA;~
[]_^A\A]A^A_
AWAVVWUSH
D$X{*M
h[]_^A^A_
AWAVAUATVWUSH
h[]_^A\A]A^A_
AWAVAUATVWUSH
D$HU^a
x[]_^A\A]A^A_
AVVWUSL
]#5[]_^A^
AWAVAUATVWUSH
D$d@yb=
8D99tR1
[]_^A\A]A^A_
AWAVVWUSA
7A;1t2
)[]_^A^A_
AWAVAUATVWUSH
%X'](s
Mh,}(H
D$(e_|
[]_^A\A]A^A_
AWAVAUATVWUSH
D$h{*M
A;/~4H
D$\E;7
[]_^A\A]A^A_
D$H0q~
AWAVATVWSH
([_^A\A^A_
AWAVAUATVWUSH
D$ sm
D$d>zV
[]_^A\A]A^A_
AWAVVWUSH
H[]_^A^A_
AWAVAUATVWSH
`[_^A\A]A^A_
D$ rU:$H
AWAVAUATVWUSH
D$`{*M
D$(Fz.
D$ g,>8
D$0L>8?H
D$(nwB$H
[]_^A\A]A^A_
AWAVAUATVWUSH
D$8(fM<H
[]_^A\A]A^A_
AWAVAUATVWUSH
D$0ep0
[]_^A\A]A^A_
AWAVAUATVWUSH
D$HX*o
D$(?!# A
[]_^A\A]A^A_
0A;3}Q
AVVWSH
H[_^A^
AWAVAUATVWUSH
z(;.}4H
[]_^A\A]A^A_
AVVWSH
([_^A^
AWAVAUATVWUSH
D$HI8%
D$ QmL
D$('8T
h[]_^A\A]A^A_
AWAVAUATVWUSH
D$(L`>
D$ h!,(
X[]_^A\A]A^A_
AWAVAUATVWUSH
D$(lE?
D$ R>3
[]_^A\A]A^A_
AWAVAUATVWUSH
D$\E|*
(%|5A;E
D$Hh1)
D$ x-T)
%i=;qy
D$(nOZ
[]_^A\A]A^A_
AWAVAUATVWUSH
D$p{*M
D$`A9M
\$p=6n
[]_^A\A]A^A_
AWAVAUATVWSH
P[_^A\A]A^A_
AWAVAUATVWUSH
X[]_^A\A]A^A_
AWAVAUATVWUSH
D$thvP;
D$H0;LH
[]_^A\A]A^A_
AWAVAUATVWUSH
h[]_^A\A]A^A_
AWAVAUATVWUSH
D$l{*M
[]_^A\A]A^A_
AWAVAUATVWUSH
[]_^A\A]A^A_
AWAVAUATVWUSH
D$|{*M
D$8M33
[]_^A\A]A^A_
AWAVAUATVWUSH
D$Dv&,
X[]_^A\A]A^A_
AWAVAUATVWUSH
h[]_^A\A]A^A_
AWAVAUATVWUSH
D$ PYE
[]_^A\A]A^A_
AWAVAUATVWUSH
D$dy7d+A
D$ b^j,H
[]_^A\A]A^A_
AWAVATVWSH
([_^A\A^A_
AWAVAUATVWUSH
D$0o`a<H
x[]_^A\A]A^A_
AVVWSH
8[_^A^
AWAVAUATVWUSH
D$(%!K
D$(I"Q#H
x[]_^A\A]A^A_
D$@D<*
AWAVAUATVWUSH
[]_^A\A]A^A_
AWAVAUATVWUSH
%|2A"t
[]_^A\A]A^A_
AWAVAUATVWUSH
x[]_^A\A]A^A_
D$01I=
D$d{*M
AWAVAUATVWSH
D$ e`e+
D$8<+0'H
p[_^A\A]A^A_
AWAVATVWSH
([_^A\A^A_
AWAVAUATVWUSH
A94$u=
[]_^A\A]A^A_
AWAVAUATVWUSH
D$`I8%
[]_^A\A]A^A_
D$@k- 4H
AWAVAUATVWUSH
D$`39C
D$dy7d+H
x[]_^A\A]A^A_
AWAVAUATVWUSH
[]_^A\A]A^A_
D$(\i<H
AWAVAUATVWUSH
X[]_^A\A]A^A_
AWAVAUATVWSH
<%C4;8
@[_^A\A]A^A_
AWAVAUATVWUSH
D$|TO=!
#D9$%Z
D$(i+F+
[]_^A\A]A^A_
AWAVAUATVWSH
D$(eJk=H
p[_^A\A]A^A_
2A;0~#
AWAVAUATVWUSH
x[]_^A\A]A^A_
AWAVAUATVWUSH
(A;.|/
x[]_^A\A]A^A_
AVVWSH
h[_^A^
AWAVATVWUSH
[]_^A\A^A_
AWAVAUATVWUSH
H[]_^A\A]A^A_
AVVWSH
D$ f2e9
x[_^A^
AWAVVWSH
D$0|B40H
[_^A^A_
AWAVAUATVWUSH
[]_^A\A]A^A_
AWAVAUATVWUSH
D$(wy(
h[]_^A\A]A^A_
AWAVAUATVWUSH
D$t>zV
[]_^A\A]A^A_
AWAVAUATVWUSH
g:"|^H
<$1tP%
h[]_^A\A]A^A_
AWAVVWSH
0[_^A^A_
AWAVVWSH
D$ x'-
P[_^A^A_
AWAVAUATVWUSH
D$|p6##
D$h9,%{
D$p;8~
[]_^A\A]A^A_
AWAVAUATVWUSH
D$P;(~
x[]_^A\A]A^A_
D$D~P@
AWAVAUATVWUSH
3>"mje
[]_^A\A]A^A_
Un9t'H
AWAVATVWSH
([_^A\A^A_
AWAVAUATVWUSH
D$h{*M
d$\E9 tWD
D$Ho;
[]_^A\A]A^A_
AWAVVWSH
L$p9ALt
D$P5Gd&H
D$(f[Y
[_^A^A_
AWAVAUATVWUSH
D$0m/OH
[]_^A\A]A^A_
0A;2|RA
AWAVAUATVWUSH
D$\y7d+
[]_^A\A]A^A_
AWAVVWUSH
D$p9%3
d)/|0H
D$8=pk
D$8=pk
D$(XN12H
D$h{*M
D$0o7\
[]_^A^A_
AWAVATVWUSH
D$ g\L
[]_^A\A^A_
AWAVAUATVWUSH
h[]_^A\A]A^A_
AWAVAUATVWUSH
[]_^A\A]A^A_
AWAVVWUSH
x[]_^A^A_
AWAVVWSH
[_^A^A_
AWAVAUATVWUSH
Eh=i`G
x[]_^A\A]A^A_
AWAVATVWUSH
8~s6udA
>~s6u[H
[]_^A\A^A_
D$8ueN
AWAVAUATVWUSH
L$pD;1
D$pD;0
[]_^A\A]A^A_
AWAVAUATVWUSH
h[]_^A\A]A^A_
AWAVAUATVWUSH
%`C<")=
h[]_^A\A]A^A_
AWAVAUATVWUSH
H[]_^A\A]A^A_
AWAVAUATVWUSH
D$`I8%
D$0dWF
[]_^A\A]A^A_
AWAVAUATVWUSH
[]_^A\A]A^A_
AWAVVWUSH
D$dldK
[]_^A^A_
AWAVAUATVWSH
D$(62N
`[_^A\A]A^A_
AWAVAUATVWUSH
D$ } j;
[]_^A\A]A^A_
AWAVAUATVWUSH
hV0;b.
x[]_^A\A]A^A_
AWAVAUATVWUSH
x)#H.m
%0|4tYk
x[]_^A\A]A^A_
AWAVAUATVWUSH
D$t&Z;
D$pBG76
D$(&FF<H
[]_^A\A]A^A_
(A;,$L
D$ _VN
l$tA;,$
AWAVAUATVWUSH
D$\{*M
D$ zzd
D$`\MG
[]_^A\A]A^A_
AWAVAUATVWUSH
L$pD;)}M
D$pD;(|
[]_^A\A]A^A_
AWAVATVWUSH
L$x9)~
L$hD;!
D$hD;
[]_^A\A^A_
AWAVAUATVWUSH
D$ eq,1
h[]_^A\A]A^A_
AWAVAUATVWUSH
D$(9R$)
[]_^A\A]A^A_
AWAVATVWSH
h[_^A\A^A_
AWAVAUATVWUSH
8[]_^A\A]A^A_
AWAVAUATVWUSH
X[]_^A\A]A^A_
AWAVAUATVWUSH
[]_^A\A]A^A_
AWAVAUATVWUSH
[]_^A\A]A^A_
AWAVAUATVWUSH
[]_^A\A]A^A_
AWAVAUATVWUSH
D$`y7d+H
[]_^A\A]A^A_
AWAVATVWSH
H[_^A\A^A_
AWAVAUATVWUSH
D$@.j\"H
D$(g~5
[]_^A\A]A^A_
AWAVAUATVWUSH
h[]_^A\A]A^A_
AWAVAUATVWUSH
D$(z'@0H
y7d+;(
[]_^A\A]A^A_
AWAVAUATVWUSH
X[]_^A\A]A^A_
AWAVAUATVWUSH
X[]_^A\A]A^A_
AWAVAUATVWUSH
H[]_^A\A]A^A_
AWAVAUATVWUSH
D$pH.m
[]_^A\A]A^A_
?9D$hu
D$d-8F
AWAVVWSH
[_^A^A_
AWAVAUATVWUSH
D$HzKw
[]_^A\A]A^A_
AWAVVWSH
@[_^A^A_
AWAVAUATVWUSH
D$P\1o
[]_^A\A]A^A_
AWAVATVWSH
8[_^A\A^A_
AWAVAUATVWUSH
X[]_^A\A]A^A_
AWAVAUATVWUSH
h[]_^A\A]A^A_
AWAVAUATVWUSH
h[]_^A\A]A^A_
AWAVAUATVWUSH
8A;<$}hE
X[]_^A\A]A^A_
AWAVAUATVWUSH
?x k1M
|$\=`/
x[]_^A\A]A^A_
AWAVAUATVWUSH
D$POi-/H
h[]_^A\A]A^A_
AWAVAUATVWUSH
d$`9D$`
[]_^A\A]A^A_
AVVWSH
H[_^A^
AWAVATVWUSH
D$ d-8
D$Ph?()H
[]_^A\A^A_
AWAVAUATVWUSH
D$Ha,N<H
[]_^A\A]A^A_
AWAVATVWUSH
$ S>DA
p[]_^A\A^A_
AWAVAUATVWUSH
D$XD;0
D$(%)W2
D$H\MG
h[]_^A\A]A^A_
AWAVAUATVWUSH
L$XD;9
D$XD;8
D$0.D.
[]_^A\A]A^A_
AWAVAUATVWUSH
D$HRoj"H
E9't7H
D$pD; t
x[]_^A\A]A^A_
AVVWUSL
[]_^A^
AWAVAUATVWUSH
D$0r`r
D$8b1p"H
D$85mm:H
[]_^A\A]A^A_
AWAVAUATVWUSH
H[]_^A\A]A^A_
AVVWSH
8[_^A^
AWAVAUATVWUSH
D$HHcI<
x[]_^A\A]A^A_
AWAVAUATVWUSH
[]_^A\A]A^A_
AWAVAUATVWUSH
HcD$(H
HcL$,H
h[]_^A\A]A^A_
H3E H3E
WATAUAVAWH
A_A^A]A\_
ffffff
WATAUAVAWH
A_A^A]A\_
fD9!u7A
UVWAVAWH
0A_A^_^]
WAVAWH
fA96tdH
fA94nu
0A_A^_
u3HcH<H
x ATAVAWH
A_A^A\
WATAUAVAWH
r\H9+t
A_A^A]A\_
UVWATAUAVAWH
fA9<Bu
fC9<hu
A_A^A]A\_^]
WATAUAVAWH
0A_A^A]A\_
u.H9>uBA
\$ UVWAVAWH
A_A^_^]
f9|$^t&f
f9|$`t
UVWATAUAVAWH
L$&8\$&t.8Y
@A_A^A]A\_^]
fD9t$b
@UATAUAVAWH
e0A_A^A]A\]
WATAUAVAWH
A_A^A]A\_
\$ VWATAUAWH
D!l$x@
@A_A]A\_^
D82u&H
D8t$Ht
l$ WAVAWH
A_A^_
AUAVAWH
t$ fff
A_A^A]
@UATAUAVAWH
H!T$0D
uf!T$(H!T$
A_A^A]A\]
L$ VWAVH
UVWATAUAVAWH
pA_A^A]A\_^]
VWATAVAW
A_A^A\_^
ATAVAWH
A_A^A\
\$ UVWATAUAVAWH
H!D$ E
PA_A^A]A\_^]
ffffff
fffffff
USVWAVH
A^_^[]
LcA<E3
[.,|"_7h(?
(=\b,k/
v3BF#W
`:A-^
(2Ji0]
R[x_i@E/
#ZT&TD
Lm*n)t:E
"9@IrM
}R#ZP_9[c
HA!m^ $
UMZu6{
m9R\$z
Pr=c@k\
e^dv!)
7!t{(*Es
NzY14>
x/ib?)u
@(WhzG
F?m~vNa
[N;u)y
{U-E;M
L9UJq@
M t|0j
z(mI;J
:5noE`
"[TP9N
xPaZY,Lm
e:_uaZ$>
4}\g`]
WHr7"1
2[S+LV
7+OWWi
R13qJ[X
{"Z{+_
~aS^t|
]N9Z&g
V|^+./
XEmvI:
Je8"5:kA
@>CU+S`
L+@tc
e${5,$
OA5URz
4X}pb.
\aSdN O
7oj-VL$>
L#zDB4
V8GLd_
4O(|y6
.reloc
FlsAlloc
FlsFree
FlsGetValue
FlsSetValue
InitializeCriticalSectionEx
__based(
__cdecl
__pascal
__stdcall
__thiscall
__fastcall
__vectorcall
__clrcall
__eabi
__ptr64
__restrict
__unaligned
restrict(
delete
operator
`vftable'
`vbtable'
`vcall'
`typeof'
`local static guard'
`string'
`vbase destructor'
`vector deleting destructor'
`default constructor closure'
`scalar deleting destructor'
`vector constructor iterator'
`vector destructor iterator'
`vector vbase constructor iterator'
`virtual displacement map'
`eh vector constructor iterator'
`eh vector destructor iterator'
`eh vector vbase constructor iterator'
`copy constructor closure'
`udt returning'
`local vftable'
`local vftable constructor closure'
new[]
delete[]
`omni callsig'
`placement delete closure'
`placement delete[] closure'
`managed vector constructor iterator'
`managed vector destructor iterator'
`eh vector copy constructor iterator'
`eh vector vbase copy constructor iterator'
`dynamic initializer for '
`dynamic atexit destructor for '
`vector copy constructor iterator'
`vector vbase copy constructor iterator'
`managed vector copy constructor iterator'
`local static thread guard'
operator ""
Type Descriptor'
Base Class Descriptor at (
Base Class Array'
Class Hierarchy Descriptor'
Complete Object Locator'
CorExitProcess
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
Sunday
Monday
Tuesday
Wednesday
Thursday
Friday
Saturday
January
February
August
September
October
November
December
MM/dd/yy
dddd, MMMM dd, yyyy
HH:mm:ss
LCMapStringEx
LocaleNameToLCID
AppPolicyGetProcessTerminationMethod
UUUUUU
UUUUUU
=imb;D
/>58d%
VM>cQ6
>jtm}S
)>6{1n
+f)>0'
;H9>&X
*StO9>T
n03>Pu
K~Je#>!
bp(=>?g
BC?>6t9^
K&>.yC
.xJ>Hf
y\PD>!
|b=})>
c [1>H'
uzKs@>
3>N;kU
kE>fvw
V6E>`"(5
?UUUUUU
?7zQ6$
.text$mn
.text$mn$00
.text$x
.idata$5
.00cfg
.CRT$XCA
.CRT$XCAA
.CRT$XCZ
.CRT$XIA
.CRT$XIAA
.CRT$XIAC
.CRT$XIC
.CRT$XIZ
.CRT$XPA
.CRT$XPX
.CRT$XPXA
.CRT$XPZ
.CRT$XTA
.CRT$XTZ
.rdata
.rdata$zzzdbg
.rtc$IAA
.rtc$IZZ
.rtc$TAA
.rtc$TZZ
.xdata
.edata
.idata$2
.idata$3
.idata$4
.idata$6
.pdata
.gfids$y
.rsrc$01
.rsrc$02
mbfrbud7674w.exe
VirtualFree
VirtualAlloc
GetProcessHeap
HeapAlloc
HeapReAlloc
HeapFree
HeapSize
K32GetModuleBaseNameW
FindResourceExA
SetFileAttributesTransactedA
GetVolumePathNameW
FindResourceW
OpenPrivateNamespaceW
LoadLibraryA
GetProcAddress
VirtualProtect
KERNEL32.dll
BroadcastSystemMessageExA
DdeCreateStringHandleA
GetGestureConfig
OpenDesktopA
SetWindowWord
RegisterShellHookWindow
USER32.dll
OleCreate
CoGetObjectContext
SetConvertStg
HICON_UserMarshal
HMETAFILE_UserSize
NdrProxyForwardingFunction26
ole32.dll
D3DKMTCreateAllocation
CancelDC
AddFontResourceA
GDI32.dll
SHGetInstanceExplorer
SHCreateDefaultContextMenu
ExtractIconExA
SHELL32.dll
RtlCaptureContext
RtlLookupFunctionEntry
RtlVirtualUnwind
UnhandledExceptionFilter
SetUnhandledExceptionFilter
GetCurrentProcess
TerminateProcess
IsProcessorFeaturePresent
QueryPerformanceCounter
GetCurrentProcessId
GetCurrentThreadId
GetSystemTimeAsFileTime
InitializeSListHead
IsDebuggerPresent
GetStartupInfoW
GetModuleHandleW
RtlUnwindEx
GetLastError
SetLastError
EnterCriticalSection
LeaveCriticalSection
DeleteCriticalSection
InitializeCriticalSectionAndSpinCount
TlsAlloc
TlsGetValue
TlsSetValue
TlsFree
FreeLibrary
LoadLibraryExW
GetStdHandle
WriteFile
GetModuleFileNameW
MultiByteToWideChar
WideCharToMultiByte
ExitProcess
GetModuleHandleExW
GetACP
FindClose
FindFirstFileExW
FindNextFileW
IsValidCodePage
GetOEMCP
GetCPInfo
GetCommandLineA
GetCommandLineW
GetEnvironmentStringsW
FreeEnvironmentStringsW
SetStdHandle
GetFileType
GetStringTypeW
LCMapStringW
FlushFileBuffers
GetConsoleCP
GetConsoleMode
SetFilePointerEx
CloseHandle
CreateFileW
WriteConsoleW
RaiseException
vNkV\)|
X^#Xf"
SlBUQenrSa
V<pR^@
&X0b~v
[+]AAj
]aA00%
5eD_3;.
M8s&yMq1\
%S]9A+
hYAtfk
_8PkAj
"G>Tul
/bnCE~G
^=OSm"qU
h\<M&n
]K$NYE
UagP&((
1<c_EO
e'W)VP
zJm/d"
(d81PfJ
5n?R<ZD(
~k(F_Vj
O*bz0y
OE4v_V||
R I"{a
c`^6"c
dp^wD
x;~MM&
^:>RAkh4
S4zO{Dmx_
@w c2H
~6uAa7
iJpGU+
i^p n\
0!YA|f6
152`VL
]>X?S
E\;6Sd
'{$Q}w
;l%7%Qj
-!!2C~<
@3]-Md_ZC
:sh=qa
lYz'-'
$zLT%$
!wbu_-
Yr'?i:
")},t,\
ecDd,'@
E[XVHE
#gqjE=
xyM2b0
YG8vmL
'CZd(z
U^Kf ~
9GK4hx\
6+.TkWJ.
G[}>3"}Uh
knx@uZ0R
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
(/P31B
zLvK>3Fb
+sMXpX
|x)Kz3v
8!G",S\
e2O3&
_Ax^0&
=21e^;B
y7CQi5
,\ rh\fH
%; d,]O-
?mfcKv
oES+:g
x[S"m/
'FJ(ei
=U]TwX$Oz
Ul=$;P
6uYW zK<I
2H/8#
U=^R)>|
rC_i/vN
6*6}`s
y3<&"C
H5dz)$
N'u-*E
advapi32
api-ms-win-core-fibers-l1-1-1
api-ms-win-core-synch-l1-2-0
kernel32
mscoree.dll
((((( H
Sunday
Monday
Tuesday
Wednesday
Thursday
Friday
Saturday
January
February
August
September
October
November
December
MM/dd/yy
dddd, MMMM dd, yyyy
HH:mm:ss
api-ms-win-core-datetime-l1-1-1
api-ms-win-core-file-l1-2-2
api-ms-win-core-localization-l1-2-1
api-ms-win-core-localization-obsolete-l1-2-0
api-ms-win-core-processthreads-l1-1-2
api-ms-win-core-string-l1-1-0
api-ms-win-core-sysinfo-l1-2-1
api-ms-win-core-winrt-l1-1-0
api-ms-win-core-xstate-l2-1-0
api-ms-win-rtcore-ntuser-window-l1-1-0
api-ms-win-security-systemfunctions-l1-1-0
ext-ms-win-ntuser-dialogbox-l1-1-0
ext-ms-win-ntuser-windowstation-l1-1-0
api-ms-win-appmodel-runtime-l1-1-2
user32
api-ms-
ext-ms-
zh-CHS
az-AZ-Latn
uz-UZ-Latn
kok-IN
syr-SY
div-MV
quz-BO
sr-SP-Latn
az-AZ-Cyrl
uz-UZ-Cyrl
quz-EC
sr-SP-Cyrl
quz-PE
smj-NO
bs-BA-Latn
smj-SE
sr-BA-Latn
sma-NO
sr-BA-Cyrl
sma-SE
sms-FI
smn-FI
zh-CHT
az-az-cyrl
az-az-latn
bs-ba-latn
div-mv
kok-in
quz-bo
quz-ec
quz-pe
sma-no
sma-se
smj-no
smj-se
smn-fi
sms-fi
sr-ba-cyrl
sr-ba-latn
sr-sp-cyrl
sr-sp-latn
syr-sy
uz-uz-cyrl
uz-uz-latn
zh-chs
zh-cht
CONOUT$
AFX_DIALOG_LAYOUT
Property Page
MS Shell Dlg
Text 1
Italic2
License
Antivirus Signature
Bkav Clean
Elastic malicious (high confidence)
MicroWorld-eScan Trojan.Agent.FGOI
CMC Clean
CAT-QuickHeal Clean
ALYac Clean
Cylance Unsafe
VIPRE Clean
AegisLab Clean
Sangfor Clean
K7AntiVirus Clean
BitDefender Trojan.Agent.FGOI
K7GW Clean
Cybereason malicious.44d733
BitDefenderTheta Clean
Cyren Clean
Symantec Clean
ESET-NOD32 a variant of Win64/GenKryptik.FEGA
Baidu Clean
APEX Malicious
Avast FileRepMalware
ClamAV Clean
Kaspersky UDS:Trojan.Win32.Inject
Alibaba Clean
NANO-Antivirus Clean
ViRobot Clean
Tencent Clean
Ad-Aware Clean
Sophos Clean
Comodo Clean
F-Secure Clean
DrWeb Clean
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition BehavesLike.Win64.Generic.fc
FireEye Generic.mg.ee1db7f0ad39df1a
Emsisoft Clean
SentinelOne Clean
GData Clean
Jiangmin Clean
MaxSecure Clean
Avira Clean
MAX Clean
Antiy-AVL Clean
Kingsoft Win32.Troj.Undef.(kcloud)
Gridinsoft Trojan.Heur!.02092023
Arcabit Clean
SUPERAntiSpyware Clean
ZoneAlarm Clean
Microsoft Trojan:Win32/Wacatac.B!ml
Cynet Clean
AhnLab-V3 Clean
Acronis Clean
McAfee RDN/Generic.dx
TACHYON Clean
VBA32 Clean
Malwarebytes Clean
Panda Clean
Zoner Clean
TrendMicro-HouseCall TROJ_GEN.R002H0DDR21
Rising Trojan.GenKryptik!8.AA55 (CLOUD)
Yandex Clean
Ikarus Clean
eGambit Clean
Fortinet W64/GenKryptik.FEGA!tr
Webroot W32.Trojan.Gen
AVG FileRepMalware
Paloalto generic.ml
CrowdStrike win/malicious_confidence_90% (W)
Qihoo-360 Clean
No IRMA results available.