Static | ZeroBOX

PE Compile Time

1970-01-01 09:00:00

PE Imphash

1cd364a9e949d5ecebd6c614e64bc545

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x003a01fc 0x003a0200 5.91204164752
.rdata 0x003a2000 0x00390ec0 0x00391000 5.35850803336
.data 0x00733000 0x0007d648 0x00057800 5.67349345188
.idata 0x007b1000 0x000003b4 0x00000400 4.1187426211
.symtab 0x007b2000 0x00000004 0x00000200 0.0203931352361

Imports

Library kernel32.dll:
0xb33020 WriteFile
0xb33028 WriteConsoleW
0xb33038 WaitForSingleObject
0xb33040 VirtualQuery
0xb33048 VirtualFree
0xb33050 VirtualAlloc
0xb33058 SwitchToThread
0xb33060 SetWaitableTimer
0xb33078 SetEvent
0xb33080 SetErrorMode
0xb33090 LoadLibraryA
0xb33098 LoadLibraryW
0xb330a0 GetSystemInfo
0xb330a8 GetSystemDirectoryA
0xb330b0 GetStdHandle
0xb330c8 GetProcAddress
0xb330d8 GetConsoleMode
0xb330e8 ExitProcess
0xb330f0 DuplicateHandle
0xb330f8 CreateThread
0xb33108 CreateEventA
0xb33110 CloseHandle

!This program cannot be run in DOS mode.
`.rdata
@.data
.idata
.symtab
;cpu.u
D$xH9D$
runtime L
error: L
L$(H9A
D$`H9D$
L$@H9L$
D$pH9B(t
u+M9A t
D9L$Xu
u+I9x t
L9L$Xu
u+M9A t
u+M9A t
Y`H9Y8
H`H9H8t%
L$@H9A8u H
H9AxwEH9
H95,Sy
@(H9A(s
@(H9A(s
X09Z0vAH
T$(H)J
|$,fD9
t$49rX
pg@8rg
sg@8qg
s8H9s0}9H
L$ H+A
L$ H+A
T$p9D$L
kernel32H
l32.dll
LoadLibrH
raryExA
LoadLibrH
raryExW
advapi32H
i32.dll
SystemFuH
ntdll.dlH
NtWaitFoH
winmm.dlH
timeEndPH
dPeriod
ws2_32.dH
_32.dll
WSAGetOvH
wine_getH
powrprofH
rof.dll
PowerRegH
H#\$0H
GetSysteH
QueryPerH
D$HI9p
\$HH9Z
L$8H9A(
D$+e+H
H9A0taH
H9H0tiH
T$L9T$H
L$0H9Hp
ukH9Z@ue
D$0H9H
D$0H9H
memprofiH90u
memprofiH
memprofiH
memprofi
memprofi
9noneu
9crasu
9singu8f
t$H9HXt
P89Q8v0H9A
v89w8@
D$8<@H
L9B(v H
@8L+@(M
<3@8:uhH
L$ HcT$0H
HcD$(H
H9\$Xv
HcD$TH
HcD$0H
\$HHcR
L$H9A ~
L$H9A ~
L$(8A'v
Q'HcY H
HcT$(H
runtime.H
HcD$(H
HcD$ H
L$0HcT$(H
HcD$(H
runtime.H
|$PH97
runtime.H9
runtime.H
T$@H9J0
D$xH9D$
D$xH9D$
D$pH9D$
D$pH9D$
D$xH9D$
D$hH9D$
D$hH9D$
D$@H9D$
debugCalH9
debugCal
debugCalH9
debugCal
debugCalH9
l163uif
l327u=f
debugCal
debugCalH
l204u]
l409u3
debugCalH
CHH)w H
D$ I)x
X0H;CPt{H
|$0H9;u
|$PH9;u
H+t$(H
|$0H9;u
|$PH9;u
|$(H9;u
T$09J$u>
H(9J(t
|$ H9;u
L$0H9A
L$08A'
K H9H
L$(H9A8
T$0H9J
@ H9B
r H9X(t<1
|$8H9;u
|$HH9;u
r H9X(t#1
@0H9B0
T$0H9JPu
JXH9HX
L$0H9A
L$0H9A
T$0H9J
@ H9B
T$0H9J
D$(H9D$
D$ H9D$
~2f9{2
{0f9~0
F@H9C@t
F@H9C@
D$HH9D$
|$ H9;u
|$0H9;u
H9Q0umH
H9Q0t7H
H9Q0t7H
tHH91ufH
K0H9H0
0H92t11
0H92t]1
\$HH)S
0H92t#1
\$<9\$8
\$T9\$L
\$<9\$8
\$,9\$(
H9L$XubH
H9L$@u\H
H9L$(uVH
H9L$(uVH
H9L$(uYH
H9L$(uYH
H9L$(uVH
H9L$(uVH
H9L$XubH
H9L$XubH
J H9H
J 9H un
J(9H(ubH
H0H9J0
JHH9HH
@ H9S(t
|$(H9;u
@ H9B
|$(H9;u
L$0H9A
|$(H9;u
T$0H9J
T$(H9J
T$(H9J
T$(H9J
T$(H9J
J 9H u!H
H(H9J(
9t$Hv9H
|$(H9;u
-07:00:0I9
-07:00:0
-07:00:0
-07:00:0
-07:00:0
2006t=H
-07:00:0
-07:00:0
-07:00:0
Z07:00:0I9
-07:00:0
Z07:00:0
-07:00:0
-07:00:0
t/@80u*H
:WITAt
D$(H9D$
D$(H9D$
D$(H9D$
t2H9X@
,H9XH~&H
tKH9X@
EH9XH~?H
D$8H9D$ ujH
t$XH9V
|$PH9;u
|$PH9;u
|$PH9;u
|$PH9;u
|$8H9;u
|$(H9;u
|$(H9;u
|$(H9;u
r H9X(
r0H9H8tF1
R@H9XHt
T$PHcX(
;fileu
unixgramH
unixpackH9
\$,9\$(
|$(H9;u
p H9H(tF1
X8H9P0t
R H9P t
rHH9XPt<1
R H9P t
PH9PHt(L9
l*PL9jHu
D$`tYH
D$XtWH
D$`8D$
L$X8L$
|$XH9;
D$hH9D$
H9L$ t
D$`H9D$
L$XH9L$
Q8H9A@~
Q8H9A@
D$(H9D$
D$ H9D$
~2f9{2
{0f9~0
F@H9C@t
F@H9C@
D$HH9D$
T$xH9B@
\$@H9X@
T$(H9B@
T$0H9B
T$0H9B
L$@H9A
\$HH9S
L$HH9A
Q8H9A@
L$ H9L$
L$8H9J
|$0H9;u
|$(H9;u
|$HH9;u
|$HH9;
|$ H9;u
|$0H9;u
|$0H9;u
|$0H9;u
|$8H9;u
p(H9X tJ1
H0H9J0u6H
H8H9J8u,H
H@H9J@
@HH9BH
L$(~<H
|$8H9;
|$ H9;
L$pH9L$
D$G8D$
D$PH9D$
D$XH9D$
method:L
(BADINDEH
(MISSINGH
%!(NOVERM
%!(EXTRAM
%!(BADPRM
BADPREC)M
%!(BADWIM
L$h8L$
9mastu
:fromu
X0H+X@H
9?104u]
<st|<u
K H9H u
|$8H9;u
|$8H9;u
|$8H9;u
|$8H9;u
|$ H9;u
|$(H9;u
|$8H9;u
|$8H9;u
|$8H9;u
@ H9C t
|$8H9;u
|$ H9;u
|$(H9;u
|$(H9;u
|$(H9;u
|$(H9;u
|$(H9;u
|$(H9;u
|$(H9;u
0H92tb1
unixgramH9
unixpackH9
D$hH9D$
unixgramH9:
unixpackH9:u
unixgramH9:u
unixpackL9
8dial@
unixgram
\$D9\$@
9udp4u
9udp6t
T$(tAH
9udp4u
9udp6t
9acceu@f
9unixudL
unixgramM9
unixpackM9
unixgramH93
unixpackH93u
unixgramH93
unixpackH93u
>listu-f
unixgramH9
unixpackH9
|$8H9;u
|$ H9;u
|$(H9;u
|$PH9;u
|$8H9;u
|$8H9;u
H 8K u
|$(H9;u
|$(H9;u
|$(H9;u
|$HH9;u
|$(H9;u
|$@H9;u
|$@H9;u
|$@H9;u
|$HH9;u
|$(H9;u
|$(H9;u
|$(H9;u
|$HH9;u
|$(H9;u
|$@H9;u
|$@H9;u
|$@H9;u
|$HH9;u
|$8H9;u
|$(H9;u
|$HH9;u
|$HH9;u
r H9H(t<1
r H9p
r8H9H0tF1
XHH9P@t
|$HH9;u
|$8H9;u
|$ H9;u
|$(H9;u
r H9X(
r0H9H8tF1
R@H9XHt
<0r+<9w'H
|$XH9;
|$ H9;u
_B>fwA
|$ H9;u
|$ H9;u
|$ H9;u
|$ H9;u
|$ H9;u
|$ H9;u
D$xH+HPH
QZ^&A!
D$`H+D$
<Gw.<Eu
HcY H)
+HcC H
H9L$Pw
9nullt@H
=UUUUw
=3333v
k(=^Cy
|$(H9;u
|$(H9;u
D$xH+HXH
$D3T$4D3T$ D3T$
D3T$8D3T$$D3T$
D3T$<D3T$(D3T$
$D3T$,D3T$
D3T$0D3T$
D3T$4D3T$
D3T$8D3T$ A
D3T$<D3T$$A
T$ D3T$
$D3T$(A
T$$D3T$
D3T$,A
T$(D3T$
D3T$0A
T$,D3T$ D3T$
D3T$4A
T$0D3T$$D3T$
D3T$8A
T$4D3T$(D3T$
D3T$<A
T$8D3T$,D3T$
T$<D3T$0D3T$
$D3T$4D3T$ D3T$
D3T$8D3T$$D3T$
D3T$<D3T$(D3T$
$D3T$,D3T$
D3T$0D3T$
D3T$4D3T$
D3T$8D3T$ A
D3T$<D3T$$A
T$ D3T$
$D3T$(A
T$$D3T$
D3T$,A
T$(D3T$
D3T$0A
T$,D3T$ D3T$
D3T$4A
T$0D3T$$D3T$
D3T$8A
T$4D3T$(D3T$
D3T$<A
T$8D3T$,D3T$
T$<D3T$0D3T$
$D3T$4D3T$ D3T$
D3T$8D3T$$D3T$
D3T$<D3T$(D3T$
$D3T$,D3T$
D3T$0D3T$
D3T$4D3T$
D3T$8D3T$ A
D3T$<D3T$$A
T$ D3T$
$D3T$(A
T$$D3T$
D3T$,A
T$(D3T$
D3T$0A
T$,D3T$ D3T$
D3T$4A
T$0D3T$$D3T$
D3T$8A
T$4D3T$(D3T$
D3T$<A
T$8D3T$,D3T$
T$<D3T$0D3T$
$D3T$4D3T$ D3T$
D3T$8D3T$$D3T$
D3T$<D3T$(D3T$
$D3T$,D3T$
D3T$0D3T$
D3T$4D3T$
D3T$8D3T$ A
D3T$<D3T$$A
T$ D3T$
$D3T$(A
T$$D3T$
D3T$,A
T$(D3T$
D3T$0A
T$,D3T$ D3T$
D3T$4A
T$0D3T$$D3T$
D3T$8A
T$4D3T$(D3T$
D3T$<A
T$8D3T$,D3T$
T$<D3T$0D3T$
T$0H9JXu
@`H9B`
L$pH9A
|$0H9;u
|$PH9;
|$@H9;u
|$@H9;u
D$hH#D$0H
D$hH#D$0H
S0H+S(H
Z0H+Z(H
Z0H+Z(H
Q0H+Q(H
F0L9F(
|$@H9^
B(H9B0uLH
Q0H+Q(H9Q
Q0H9Q(}RH
T$`H)J(H
\$8t(H
|$(H9;u
|$(H9;u
@ H9B
T$0H9J
H H9J u+
@0H9B0
@ H9B
q(H9X
p0H9X8tF1
X@H9HHt
|$8H9;u
|$HH9;u
|$8H9;u
|$HH9;u
H H9J u]H
H(H9J(
H0H9J0u<H
X@H9P8t
|$HH9;
J(f9H(uR
J0H9H0t
|$HH9;u
|$HH9;u
|$@H9;u
D$(H9D$
9writu}
|$(H9;u
|$(H9;u
kernel32H9
@ H9S(t
K H9H
8shelu
8remou
\$pu[H
8useru
D$XH9D$
D$XH9D$
D$pH9D$
D$PH+D$
L$hH9A@
H1D$0H
H1D$PH
H1D$XH
|$`H9;
;cpu.u
H9T$0s
o\$ fE
o\$0fE
o\$@fE
o\$PfE
o\$`fE
o\$pfE
|$HH9;
T$`H9Q
D$HH9H
|$8H9;u
|$`H9;
|$`H9;
|$8H9;u
T$0HcX
t$,Hcx
D$(LcH
T$$LcX L
~d$PfE
ot$PfA
|$HH9;u
|$8H9;u
|$0H9;u
R0H9X8t
|$xH9;u
|$hH9;
|$(H9;u
|$@H9;u
|$PH9;
|$HH9;u
|$8H9;u
|$0H9;u
|$ H9;u
|$@H9;u
|$PH9;u
|$(H9;u
|$HH9;u
|$8H9;u
|$0H9;u
|$ H9;u
|$@H9;u
|$PH9;u
|$(H9;u
|$(H9;
|$8H9;u
|$HH9;u
|$8H9;u
|$0H9;u
|$ H9;u
|$@H9;u
|$PH9;u
0H92tc1
J H9H
|$HH9;u
|$8H9;u
|$0H9;u
|$ H9;u
|$@H9;u
|$PH9;
|$(H9;u
K H9H
|$HH9;u
|$8H9;u
|$0H9;u
|$ H9;u
|$@H9;u
|$PH9;
K H9H
|$HH9;u
|$8H9;u
|$0H9;u
|$ H9;u
|$@H9;u
|$PH9;
D$8H9D$
D$ H9D$@u'H
D$(H9D$Hu
D$PH9D$0
H9T$HuuH
Q H9T$`
Q(H9T$h
Q0H9T$p
I8H9L$x
Q H9T$`
Q(H9T$h
Q0H9T$p
I8H9L$x
|$(H9;u
|$ H9;u
|$(H9;u
|$ H9;u
|$(H9;u
|$(H9;u
|$ H9;u
|$(H9;u
|$ H9;u
|$(H9;u
|$8H9;u
|$(H9;u
|$PH9;u
|$PH9;u
|$@H9;u
|$(H9;u
|$8H9;u
|$(H9;u
|$PH9;u
|$PH9;u
|$@H9;u
|$(H9;u
|$8H9;u
|$(H9;u
|$PH9;u
|$PH9;u
|$@H9;u
|$(H9;u
|$ H9;u
|$(H9;u
|$ H9;u
|$@H9;u
|$(H9;u
|$8H9;u
|$(H9;u
|$ H9;u
|$(H9;u
|$PH9;
|$(H9;u
|$ H9;u
|$@H9;u
|$PH9;
|$@H9;u
|$(H9;u
|$(H9;u
|$(H9;u
|$(H9;u
|$HH9;u
|$(H9;u
|$PH9;u
|$PH9;u
|$@H9;u
|$(H9;u
|$(H9;u
|$(H9;u
|$(H9;u
|$HH9;u
|$(H9;u
|$PH9;
|$PH9;
|$@H9;u
8ed25u
|$(H9;u
|$ H9;u
|$(H9;u
|$(H9;u
|$ H9;u
|$(H9;u
|$(H9;u
|$(H9;u
|$ H9;u
|$(H9;u
|$PH9;u
|$(H9;u
|$ H9;u
|$hH9;
|$(H9;u
|$hH9;
|$PH9;u
|$@H9;u
|$(H9;u
|$(H9;u
|$ H9;u
|$(H9;u
|$PH9;
|$(H9;u
|$ H9;u
|$hH9;
|$(H9;u
|$hH9;
|$PH9;
|$@H9;u
|$(H9;u
|$ H9;u
|$(H9;u
|$(H9;u
|$ H9;u
|$(H9;u
L$ HcT$
optionalH9>u
explicitL9
optionalI
explicit
generaliL9
printablL9
>numeuf
>utf8u
applicatL9
optionalI
explicitI
generaliI
printablI
applicat
optionalI
explicitI
generaliI
printablI
applicat
omitemptH9
omitempt
applicat
optional
optionalI
explicitI
generaliI
printabl
optional
optionalI
explicitI
generaliI
printabl
printabl
generali
explicit
optional
|$8H9;
|$8H9;u
|$HH9;u
|$HH9;u
|$ H9;u
|$8H9;
|$0H9;u
|$ H9;u
|$@H9;u
|$0H9;u
|$@H9;u
|$0H9;u
|$8H9;
|$HH9;u
|$8H9;u
|$0H9;u
|$ H9;u
|$@H9;u
|$PH9;u
|$HH9;u
|$8H9;u
|$0H9;u
|$ H9;u
|$@H9;u
|$PH9;
K H9H
|$HH9;u
|$8H9;u
|$0H9;u
|$ H9;u
|$@H9;u
|$PH9;u
|$HH9;u
|$8H9;u
|$0H9;u
|$ H9;u
|$@H9;u
|$PH9;
t$XHcx$H
|$PH9;
D$`H=<
|$hH9F s2H
t$pH9F s[H
D$@H9N seH
|$ H9;u
|$ H9;u
|$ H9;u
|$ H9;u
|$HH9;
|$HH9;u
t$BfE9
XPM9XHuJM
n0M9l$0A
H(L9@8
S(H9K0u41
sXH9rXta
C`H9sht
rHH9sHt
sPH9rPt
PHH9PPu&H
YHH9YP
|$ H9;u
|$(H9;u
|$ H9;
|$ H9;
E9a0v-M
E9Y0v.M
E9Y0v.M
E9Y0v,M
D9^0v-L
D9^0vAL
|$ H9;u
|$ H9;u
|$HH9;
|$8H9;u
L$XH9L$ t=H
Z8H9B@t
R H9P t
|$0H9;u
|$0H9;u
J H9H
p(H9Z0
r8H9J@
pPH9rP
JX8HXu|H
p`H9ZhtF1
ZpH9Jxt
|$8H9;
D$P8D$/t
t$(H9r
D$PH9D$
D$HH9D$
xHH9pP
L$PH9L$8
D$PH9T$ tDH
v`H9=K
|$(H9;u
|$(H9;u
|$HH9;
|$@H9;u
|$8H9;u
|$XH9;
killdateH9
maxretryH9
agentinfH9
initialiH9
minidumpH9
createprH9
r H9X(tF1
R0H9H8t
|$HH9;
nd 3D3N$A
2-byD3N(A
te kD3V,A
\$D3Y(A
\$43Y,A
\$<3Y0A
\$H3Y4A
\$83Y8A
\$@3Y<A
expaA1
2-byD1
expand 3H
2-byte kH
@(H9B(
OpH+GPL+WXL+_`L+ghL+opH
H+t$PH+T$XH+L$`L+D$hL+L$pH
T$HH+T$(H+L$0L+\$8L+d$@L+l$HH
H#D$0H
y8H9q@
D$Nf9D$
\$`f9S0
_PL9WX
VhH9Fpt
V8H9F@t
V H9F(t
D$f3tH
D$^3tH
D$Btls1f
D$F3 H
key expaH
master sH97u
client fH
inisu]f
server fH97
|$`H9;u
|$HH9;u
|$pH9;
|$(H9;u
|$(H9;u
0H92t#1
|$(H9;u
|$XH9;
|$XH9;
|$ H9;u
t$PH9^@}
T$PH9T$
D$`H9D$
D$`H9D$
D$`H9D$
D$`H9D$
D$`H9D$
8trueA
XI9B`~
Ku\=*!
D$0< w
uP<]u&H
|$(H9;u
|$(H9;u
H H9J u|H
r(H9X0tF1
R@H9P@t
|$@H9;u
z0H+z(H
H0H+H(H
|$8H9;u
us-asciiH9
9QxtaH
0H92t51
D$0H=`
D$?8D$r
D$hH9D$HuHH
|$XH9;
|$XH9;
Z49Z0v
t0H9L$H~"H
|$XH9;
|$XH9;
H0H+H(H
G0L+G(I
H92uAt'H
|$@H9;u
|$ H9;u
|$HH9;u
|$0H9;u
|$@H9;u
H f9J u
>socku
>httpu
>httpu
localhosH93u
|$pH9;
|$XH9;
s H9S(t"1
|$8H9;u
9httpu-
z(H9r0
9Cooku
AuthorizH9
Www-AuthH9
enticateH9A
;pathu1H
;secuu!f
httponlyH
samesiteH9
9noneu
9striu
samesite
httponlyH
; ExpireH
; Max-AgH
; HttpOnL
; SecureL
; SameSiH
; SameSiH
Site=LaxH
; SameSiH
ite=NoneH
; Max-AgL
ax-Age=0L
; DomainM
H){(I)
K(H)K0H)
L$8f9L$
d$hL9T$p
8:metu
8:schurfA
8:stau
:authoriI98
;httpuoH
8Traiu
Content-H9
Content-H
Content-
Content-
>chunu
?HEAD@
8HEADu
D$(H9D$
HTTP/1.0H
HTTP/1.1H9
no-cacheH9
;chunuPf
;chunu8f
:CONNu
:HEADt
:DELEu
:SEARuCf
:OPTIu
PROPFINDH9
8POSTu
identityH9
8Traiu
Content-H9
Content-H
Content-
Content-
identityH9
identity
L$@H9L$
H9;u.u$H
:httpu
;TRACu
;socku
>httpu=H
>httpu
Q0H+Q(H
H(H9H0t
K0H+K(H
p(H9p0u
;PATCu
Content-H9
|$ H9;u
|$@H9;u
|$PH9;
|$@H9;u
|$@H9;u
|$@H9;u
|$@H9;u
|$@H9;u
|$@H9;u
|$@H9;u
|$@H9;u
|$@H9;u
|$@H9;u
|$@H9;u
|$@H9;u
|$@H9;u
|$@H9;u
|$@H9;u
|$@H9;u
|$@H9;u
|$@H9;u
|$@H9;u
|$@H9;u
|$@H9;u
|$@H9;u
|$@H9;u
|$@H9;u
|$(H9;u
|$HH9;u
|$8H9;u
s H9S(t"1
T$0H9J
@ H9B
H9X t"1
|$`H9;
|$ H9;u
|$@H9;u
|$`H9;
|$0H9;u
|$0H9;u
|$0H9;u
|$0H9;u
|$`H9;
|$xH9;
|$0H9;u
|$0H9;u
|$@H9;u
|$0H9;u
|$ H9;u
|$@H9;u
|$8H9;u
|$0H9;u
L$(H9A
|$0H9;u
|$0H9;u
|$0H9;u
|$0H9;u
|$0H9;u
|$0H9;u
|$0H9;u
|$0H9;u
|$0H9;u
|$0H9;u
0H92t#1
|$XH9;
|$0H9;u
|$0H9;u
|$XH9;
|$(H9;u
|$(H9;u
|$PH9;
|$(H9;u
|$(H9;u
|$(H9;u
|$XH9;
|$HH9;
|$@H9;
|$XH9;
|$0H9;u
|$0H9;u
|$0H9;u
|$0H9;u
|$XH9;
|$XH9;
|$XH9;
|$PH9;u
|$8H9;u
|$XH9;
|$(H9;u
|$HH9;u
|$(H9;u
|$HH9;u
|$(H9;u
nd 3A3]
$2-byA3]
te kA3U
expa3z
expaA1
nd 3E1
2-byE1
te kE1
L$08AP
expand 3H
2-byte kH
OpH+GPL+WXL+_`L+ghL+opH
H+t$PH+T$XH+L$`L+D$hL+L$pH
T$HH+T$(H+L$0L+\$8L+d$@L+l$HH
|$(H37H
H3w(H3o0L3
HH3wPH3oXL3
pH3wxH3
H3W8L1
L3g`H3
L3G@H1
L3ohL3
H3T$8L1
L3d$`H3
L3D$@H1
L3l$hL3
H3W8L1
L3g`H3
L3G@H1
L3ohL3
H3T$8L1
L3d$`H3
L3D$@H1
L3l$hL3
H3W8L1
L3g`H3
L3G@H1
L3ohL3
H3T$8L1
L3d$`H3
L3D$@H1
L3l$hL3
H3W8L1
L3g`H3
L3G@H1
L3ohL3
H3T$8L1
L3d$`H3
L3D$@H1
L3l$hL3
H3W8L1
L3g`H3
L3G@H1
L3ohL3
H3T$8L1
L3d$`H3
L3D$@H1
L3l$hL3
H3W8L1
L3g`H3
L3G@H1
L3ohL3
H3T$8L1
L3d$`H3
L3D$@H1
L3l$hL3
H3W8L1
L3g`H3
L3G@H1
L3ohL3
H3T$8L1
L3d$`H3
L3D$@H1
L3l$hL3
H3W8L1
L3g`H3
L3G@H1
L3ohL3
H3T$8L1
L3d$`H3
L3D$@H1
L3l$hL3
H3W8L1
L3g`H3
L3G@H1
L3ohL3
H3T$8L1
L3d$`H3
L3D$@H1
L3l$hL3
H3W8L1
L3g`H3
L3G@H1
L3ohL3
H3T$8L1
L3d$`H3
L3D$@H1
L3l$hL3
H3W8L1
L3g`H3
L3G@H1
L3ohL3
H3T$8L1
L3d$`H3
L3D$@H1
L3l$hL3
H3W8L1
L3g`H3
L3G@H1
L3ohL3
H3T$8L1
L3d$`H3
L3D$@H1
L3l$hL3
H#D$0H
y8H9q@
D$Nf9D$
\$`f9S0
_PL9WX
VhH9Fpt
V8H9F@t
V H9F(t
RandomizH9
RandomizH9
RandomizH93u
Randomiz
L$xH9L$
D$f3tH
D$^3tH
D$Btls1f
D$F3 H
key expaH
master sH97u
client fH
inisu]f
server fH97
|$`H9;u
|$HH9;u
|$pH9;
|$(H9;u
|$(H9;u
K H9H
|$(H9;u
|$(H9;u
|$HH9;u
|$(H9;u
|$@H9;u
|$@H9;u
|$@H9;u
0H92t#1
|$(H9;u
|$XH9;
|$XH9;
|$ H9;u
|$ H9;
|$ H9;
|$XH9;
R(H9P(t
|$XH9;
Z49Z0v
t0H9L$H~"H
|$XH9;
|$XH9;
H){(I)
K(H)K0H)
L$8f9L$
d$hL9T$p
8:metu
8:schurfA
8:stau
:authoriI98
;httpuoH
@@H9D$
8Traiu
Content-H9
Content-H
Content-
Content-
>chunu
?HEAD@
8HEADu
9PATCu
|$ H9;u
|$@H9;u
|$@H9;u
|$@H9;u
|$@H9;u
|$@H9;u
|$@H9;u
|$@H9;u
|$@H9;u
|$@H9;u
|$@H9;u
|$@H9;u
|$@H9;u
|$@H9;u
|$@H9;u
|$@H9;u
|$@H9;u
|$@H9;u
|$@H9;u
|$@H9;u
|$@H9;u
|$@H9;u
|$@H9;u
|$@H9;u
|$@H9;u
|$`H9;
|$ H9;u
|$@H9;u
|$`H9;
|$0H9;u
|$0H9;u
|$0H9;u
|$0H9;u
|$`H9;
|$xH9;
|$0H9;u
|$0H9;u
|$@H9;u
|$0H9;u
|$ H9;u
|$@H9;u
|$8H9;u
L$(H9A
|$0H9;u
|$0H9;u
|$0H9;u
|$0H9;u
|$0H9;u
|$0H9;u
|$0H9;u
|$0H9;u
|$0H9;u
|$0H9;u
0H92t#1
|$XH9;
|$0H9;u
|$0H9;u
|$XH9;
|$0H9;u
|$0H9;u
|$0H9;u
|$0H9;u
|$XH9;
|$XH9;
|$XH9;
|$PH9;u
|$XH9;
|$(H9;u
|$HH9;u
protocolH9
"action"H
get_taskH9
9succu
staging_H
post_resH9
;succu
8succu
"action"H
"action"H
"action"H
"action"H
R H9X(t
r H9X(
p0H9X8
r@H9XH
pPH9HX
rhH9ph
rpH9Xx
R H9X(t
s H9S(t.1
r H9X(tF1
R0H9H8t
r H9p tF1
R(H9X0t
H9X t"1
p H9X(t"1
p H9X(
p0H9X8
r@H9HH
pPH9XX
rhH9ph
rpH9Xx
r H9X(tF1
R0H9H8t
9FALSuM
9Falsu/
9FALSuM
9Falsu/
crypto
errors
regexp
*[]int
*error
*int16
*int32
*int64
*uint8
Accept
AndNot
Append
ArrayT
Assign
Before
BitLen
Buffer
CanSet
Cancel
Chains
Checks
Cipher
Client
CmpAbs
Config
Cookie
Curves
Decode
Delete
Detail
Dialer
DivMod
DoChan
Domain
Double
Enable
Encode
Equals
ExecIO
Exited
Expand
Family
Fatalf
Fchdir
Fchmod
Fchown
Fields
Format
Fprint
Getenv
HEvent
Handle
HasADX
HasAES
HasAVX
HasDFP
HasFMA
HasMSA
HasSM3
HasSM4
HasSVE
HasVXE
Header
IfType
Init64
Int31n
Int63n
Invert
IsZero
Issuer
Jacobi
KeyLen
Layout
Length
LfaNew
LfaRlc
Lookup
MacLen
MaxAge
MaxCap
Method
Miller
Minute
MulGFP
MulTau
Mutant
NewCTR
NewGCM
NewKey
NumCap
NumOut
Offset
Opaque
Output
Panicf
Params
Policy
Prefix
Primes
Printf
Public
Pwrite
QuoRem
Random
ReadAt
Reader
Reason
Remove
Reseed
Reused
Scalar
Scheme
Search
Second
Secure
Server
SetBit
SetCap
SetInf
SetInt
SetLen
SetOne
SetRat
SetSNI
Shared
Signal
Signer
Slice3
SliceT
Source
Sprint
Square
Status
StdErr
Stderr
Stdout
Strict
Stride
String
Struct
System
Thread
Uint16
Uint32
Uint64
Unlock
Unwrap
Update
Verify
Weight
Writer
Writev
ZoneId
_defer
_panic
accept
active
addSec
addTLS
aesKey
ageAdd
allocs
andNot
append
arenas
argLen
arglen
argmap
asciiF
attach
binder
bitLen
bitmap
bottom
broken
bucket
buffer
byName
cached
cancel
chains
chunks
cipher
client
closed
common
concat
condfn
config
cookie
curEnd
cutoff
cutset
cycles
decref
delete
dialIP
digest
divMul
divmod
doCall
doSlow
domain
dsbyte
dwSize
dynTab
ecdhOk
efence
eflags
encode
endTop
etypes
exited
expand
factor
family
fields
finder
flushF
fmtSbx
fnonce
format
frames
funcID
future
gc_sys
gcdata
getPtr
goAway
gobody
handle
hangul
hasRTL
hevent
hidden
hlSize
idleAt
idleMu
inList
incSeq
incref
inflow
insert
int31n
intbuf
isBidi
isFile
isFree
isYesC
isYesD
isdone
keyLen
labels
layout
length
lineno
locabs
lookup
macLen
mapped
mcache
mcount
method
misses
mustBe
mutate
nbytes
nchunk
needed
nelems
newval
nmidle
noCopy
noscan
notify
npages
npidle
num1xx
numCap
nwrite
object
offset
oldnew
oldpos
oldval
onlyH1
opAddr
opaque
opcode
outBuf
p1home
p2home
p3home
p4home
p5home
p6home
palloc
params
parent
parked
pcfile
period
prefix
procid
ptrbit
putGen
putPtr
pwrite
qcount
quoted
random
readFn
reader
refill
remove
repeat
result
reused
revise
runeAt
rusage
rwlock
sawEOF
scases
scheme
search
secret
server
setBit
setInt
setLoc
set_ip
set_lr
set_sp
shared
sharpV
shift2
sigAlg
signal
signed
sotype
sparse
state1
status
stderr
stdout
sticky
strict
string
submit
tagLen
thread
ticket
toName
toRead
tryGet
tstart
ttnext
uint16
uint32
uint64
unlock
unpack
unread
unused
update
values
varint
vdsoPC
vdsoSP
victim
volLen
wanted
window
writer
xcount
yPlusX
context
net/url
os/exec
os/user
reflect
runtime
strconv
strings
syscall
unicode
**uint8
*[1]int
*[4]int
*[5]int
*[6]int
*[7]int
*[8]int
*[9]int
*[]bool
*[]int8
*[]uint
*exec.F
*fmt.pp
*func()
*net.IP
*string
*uint16
*uint32
*uint64
AddASN1
AddCert
AddDate
Address
Addrlen
Advance
AgentID
Aliases
BitSize
Browser
Buffers
CanAddr
CertReq
ChanDir
CmdLine
Comment
Complex
Context
Control
Convert
Cookies
Country
Cparhdr
CrlInfo
CurveID
DNSDone
DNSName
Decrypt
Desktop
DialTLS
Discard
Encrypt
ErrCode
ExeFile
Expires
Fatalln
Feature
FindAll
Float32
Float64
Fprintf
GetBody
GetConn
GotConn
HasAVX2
HasBMI1
HasBMI2
HasEIMM
HasERMS
HasFCMA
HasFPHP
HasKDSA
HasSHA1
HasSHA2
HasSHA3
HasSSE2
HasSSE3
Headers
HomeDir
ISOWeek
IfIndex
InitBuf
InitMsg
Initial
Inverse
IsInt64
IsValid
LeadCCC
Longest
LowPart
Machine
MantExp
MapKeys
Marshal
Message
Methods
MinPrec
Minutes
ModSqrt
ModTime
Namelen
Network
NewProc
NoProxy
Nonzero
OEMInfo
ObjName
Padding
Panicln
Payload
PkgPath
Pointer
Println
Process
RLocker
RUnlock
RWMutex
RawPath
RawRead
ReadMsg
Readdir
Readers
Referer
Release
Replace
Request
RootCAs
RoundUp
Seconds
Session
SetBits
SetBool
SetDACL
SetMode
SetPrec
SetSACL
SetUint
SetVers
SetZero
Setting
Shuffle
Signbit
Sprintf
State12
State13
Stopped
StructT
Subject
Success
Syscall
Threads
Timeout
ToASCII
ToBytes
Trailer
TryRecv
TrySend
Unwrite
Variant
Version
WasIdle
Weekday
WillPad
WriteAt
WriteTo
YearDay
aborted
aclSize
addConn
address
advance
alignme
alllink
allnext
alloc_m
amended
argSize
argsize
asBytes
badVerb
balance
blocked
buckets
bufLock
bufPipe
by_size
byteBuf
bytesAt
callers
Antivirus Signature
Bkav Clean
Elastic Clean
MicroWorld-eScan Gen:Variant.Bulz.518743
CMC Clean
CAT-QuickHeal Clean
ALYac Gen:Variant.Bulz.518743
Cylance Unsafe
VIPRE Clean
Sangfor Riskware.Win32.Wacapew.C
K7AntiVirus Clean
BitDefender Gen:Variant.Bulz.518743
K7GW Clean
Cybereason malicious.e10a86
Baidu Clean
Cyren Clean
Symantec Trojan.Gen.MBT
ESET-NOD32 Clean
APEX Malicious
Avast FileRepMalware
ClamAV Clean
Kaspersky Clean
Alibaba Clean
NANO-Antivirus Clean
ViRobot Clean
AegisLab Trojan.Win32.Bulz.4!c
Rising Clean
Ad-Aware Gen:Variant.Bulz.518743
Emsisoft Gen:Variant.Bulz.518743 (B)
Comodo Clean
F-Secure Clean
DrWeb Clean
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition BehavesLike.Win64.TrojanVeil.wm
MaxSecure Clean
FireEye Gen:Variant.Bulz.518743
Sophos Clean
SentinelOne Clean
GData Gen:Variant.Bulz.518743
Jiangmin Clean
Webroot Clean
Avira HEUR/AGEN.1138547
MAX malware (ai score=86)
Antiy-AVL Clean
Kingsoft Clean
Gridinsoft Clean
Arcabit Trojan.Bulz.D7EA57
SUPERAntiSpyware Clean
ZoneAlarm Clean
Microsoft Program:Win32/Wacapew.C!ml
Cynet Malicious (score: 100)
AhnLab-V3 Clean
Acronis Clean
McAfee Artemis!9615AB661D92
TACHYON Clean
VBA32 Clean
Malwarebytes Clean
Panda Clean
Zoner Clean
TrendMicro-HouseCall TROJ_GEN.R002H09FI21
Tencent Clean
Yandex Clean
Ikarus Clean
eGambit Clean
Fortinet W32/PossibleThreat
BitDefenderTheta Clean
AVG FileRepMalware
Paloalto Clean
CrowdStrike Clean
Qihoo-360 Clean
No IRMA results available.