Static | ZeroBOX

PE Compile Time

2020-12-17 15:12:02

PE Imphash

712f4a29c405ecb576101d367b2180fb

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
UPX0 0x00001000 0x00089000 0x00000000 0.0
UPX1 0x0008a000 0x00057000 0x00056800 7.93596602306
.rsrc 0x000e1000 0x00008000 0x00007e00 5.70123680438

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x000e6d04 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_UK GLS_BINARY_LSB_FIRST
RT_ICON 0x000e6d04 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_UK GLS_BINARY_LSB_FIRST
RT_ICON 0x000e6d04 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_UK GLS_BINARY_LSB_FIRST
RT_ICON 0x000e6d04 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_UK GLS_BINARY_LSB_FIRST
RT_ICON 0x000e6d04 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_UK GLS_BINARY_LSB_FIRST
RT_ICON 0x000e6d04 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_UK GLS_BINARY_LSB_FIRST
RT_ICON 0x000e6d04 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_UK GLS_BINARY_LSB_FIRST
RT_ICON 0x000e6d04 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_UK GLS_BINARY_LSB_FIRST
RT_ICON 0x000e6d04 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_UK GLS_BINARY_LSB_FIRST
RT_STRING 0x000d02b8 0x00000158 LANG_ENGLISH SUBLANG_ENGLISH_UK data
RT_STRING 0x000d02b8 0x00000158 LANG_ENGLISH SUBLANG_ENGLISH_UK data
RT_STRING 0x000d02b8 0x00000158 LANG_ENGLISH SUBLANG_ENGLISH_UK data
RT_STRING 0x000d02b8 0x00000158 LANG_ENGLISH SUBLANG_ENGLISH_UK data
RT_STRING 0x000d02b8 0x00000158 LANG_ENGLISH SUBLANG_ENGLISH_UK data
RT_STRING 0x000d02b8 0x00000158 LANG_ENGLISH SUBLANG_ENGLISH_UK data
RT_STRING 0x000d02b8 0x00000158 LANG_ENGLISH SUBLANG_ENGLISH_UK data
RT_RCDATA 0x000e7170 0x0000129c LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_GROUP_ICON 0x000e848c 0x00000014 LANG_ENGLISH SUBLANG_ENGLISH_UK data
RT_GROUP_ICON 0x000e848c 0x00000014 LANG_ENGLISH SUBLANG_ENGLISH_UK data
RT_VERSION 0x000e84a4 0x000000dc LANG_ENGLISH SUBLANG_ENGLISH_UK data
RT_MANIFEST 0x000e8584 0x000003ef LANG_ENGLISH SUBLANG_ENGLISH_UK ASCII text, with CRLF line terminators

Imports

Library ADVAPI32.dll:
0x4e8af0 GetAce
Library COMCTL32.dll:
0x4e8af8 ImageList_Remove
Library COMDLG32.dll:
0x4e8b00 GetOpenFileNameW
Library GDI32.dll:
0x4e8b08 LineTo
Library IPHLPAPI.DLL:
0x4e8b10 IcmpSendEcho
Library KERNEL32.DLL:
0x4e8b18 LoadLibraryA
0x4e8b1c ExitProcess
0x4e8b20 GetProcAddress
0x4e8b24 VirtualProtect
Library MPR.dll:
0x4e8b2c WNetUseConnectionW
Library ole32.dll:
0x4e8b34 CoGetObject
Library OLEAUT32.dll:
0x4e8b3c VariantInit
Library PSAPI.DLL:
Library SHELL32.dll:
0x4e8b4c DragFinish
Library USER32.dll:
0x4e8b54 GetDC
Library USERENV.dll:
0x4e8b5c LoadUserProfileW
Library UxTheme.dll:
0x4e8b64 IsThemeActive
Library VERSION.dll:
0x4e8b6c VerQueryValueW
Library WININET.dll:
0x4e8b74 FtpOpenFileW
Library WINMM.dll:
0x4e8b7c timeGetTime
Library WSOCK32.dll:
0x4e8b84 connect

!This program cannot be run in DOS mode.
FLPTX\
PQWo7{
wLJR\\+
\4*Iu-]
bt<XS#
3&SP7
.Mw' =@
\;G?8i
c6j|Xfb4
|/.,#0C4q
4M[$*BG
{^CXj\@
@ RxV3
Y$-n!si
92t&S#U
^Wud"9
D2!9YYiG
161r"&3
2FEkNj Y
<8^h09c
R39;zV
+<P<tPT
Ht SWqY
Yk?=Vp
~Jn+~0
[`&A*hSSe
^-4pm~F
$(,$0
|h83=B
HcXr[KZ
FIS]PD ?
|5SCTv
^Vl0F4
N-CM0+
9Bt3UF
1j?Yj0
^b9Zj.`<&
x{>@tF
HtRjCG
"igb3v
C4P$+1
NNRXc5
.0 EtXM
QCagYP
P9_X,&zOP_[
68k['Wy
t!C&_Hu
Sr\oP@
0T(i&0
x[i7wm
'H~gk9
lD3VU;a
N+HuA9
XjdO*^/[?
)dHt!H
tCWjg6)
MVu'N9
i.KOCHWB1
2'xm=^
'61@\o
'`zgs
}T{?akc
OdK0"9%
(rCS,<
9hlv6Z
+m-,f0
=HcQiv/
LT7`f'
WuyGxLgy
,wee(;
Gt1Ht(@t
_C`FVX
`l\H,P
zrGXVS
m0f;f>u
(G_S{
*pT"At
m`~R%?
Qpi*POa
5!-E8+
20f)8J
R,(|RC"a4
k$'pY[
J8<@DH
('W|dxg
mZ;mXL2
_hD<<7
'/WsVn
J<G!/TxP
Tpt)]
TDt]+d
w1;EC\
rK()G
M)jkTu(
uRQnSZ
R<0"MJ
Dqwg\K8
uW.ft.h
SSH;>@
FT.Hu3
|uP #DA
~g# q]
JZC 3B
z8Pok<Hp
D*;7Ix
33HQS)'
do`irh\
ELDXCD=
]oOv|3n
D;@`@Jz
<JZiV@g
YNwpxD.r{
&&'()*+
--./012R334
5566789:;<=
>?>@ABC
GDEFGHIJKLMNz
`URLQXN
SwGk}$
C--"{-
6:F(~)
:4$^(l
pa`^hX?
uv~MjLAL
6mnra&
tR=>tK=
yVP|{WJY
>>ygmhpm
{G2|"0
g)I0,m
*P_jjEZ
j+h0k~_
Ub!69ER
fj!Yf+
I\jkwjm
tF<OD
-tK,#tJ$tD
?+t9H*m4
_ReE=6K
rLPTYpy
(esyF,084
\5h`d#
^@DHgd
X,kL0!
rypDHL
g\Dh$&
0$<&W@
<#(<4EL
es,L)042
{.$7q(
<#8xD}A
ry.,f04r
PTX\esyF`0lS
esDXvHLd
3rPT\`
rDHLP|
<80@`4
W}.@lt
AV7@p0Q
SAX(jw
^:G )-TH_
VQ/HUd
Kq;|[R
>tTNf9
256CK8J
IH<I9U
F (n0d
nPv`~p
CNS- M
,=&.++
VH(82@V
&,1V:
\lsZ(C
=,<8LT
\wRMj$A+
9u(v?VS>P8
t>l:qf
=QY=OI=
.Vk96{
#Y3='t
ERH0f+
u24&:a
cY5B^T
1R|w6<VS
p!tBHSl
HtOMt",
%CIXV*
\B((Ao
9*4kA8
BLh=U}
Nwfb@5
P4TY.&
&9MKv`Q
1x#\-}
4Rh(K
,@*<v5!
G`0g`1
K,;_9?N
5X;E -u
w3Zv&j
)`QPr6
QRW^aj
WJ(htHjl
S|-}p>
D/5w@w
fnt'jo
uaWA{e=c
68owHZYs
.^(8_p
pqwhk8n
tU4Mk@O
pU /(%$
zakSY64
iIVVV#
Pl3a;84KOF#
[c9[nx
=fi3_!;
(CRl,*<X&
'u?9%t7
<0QQ]X
,Jv{gR)RHtC
(Q0.XK
$o`UH8
HP{ &+
CSH0%a
=C&y~5
sSU-VC
sMwH,^
(T=%!x
qVS\B
?@v?@5U
HF>99FD<u@5
+CdX`,hP
`mv56?
G=yCYi
c_jd&p
} kE$3
7:Dwd$B
Ti(`(#
$(,0''''4
Y@$@DNNNn
&@eDH2
V1nhA
~';_t|%
DJxT'[
^@N\|8
C2r@,0[@
YDat{h#
uymN]iN
lVm/SyY<
|+;`}&G
HXlewCh$
T 2q-`
S\Q7Q9
UQPXY]Y2
.i<g'&
O8u^A
|DBt G)u
EUOeu
GE%GQY%(
p&.*CT
6lU*n/
qqZJaCm
J$S.z
fvjbXZu
'-|UxW
B.P!e=
3fu,&M=
"T09Sx2
SPW5AyG
!{L}C9M
CI&iG>
,$]@6M@i.-2@"d
b+buU8
)j@YDO(
5CTtY`Z
c9b}Qh
^r;X!t 9H
?.:mYV)u
;D9{dt
/9{GLp
*Cvl;
+i)Iba*
UuG0Nu7j
64O[Y*
PdaaA.
)hg,YC/v
$uj1[!M
PsS_b4F
GdQ*`250;$
N$A[u%_m
#@[5$x7
<bKe'8}
@BNr%#i
6tN$Z8m
n?6|(<
h@|y@#
0$=@m#
;hwv^'
UK@NL*
F=0Mx4
L!#(HL!#
hA8H0u
2r2r.$*<2r2r(P&\2r2r$t"
WP<O6]$m+
t>*Z]Z
GjqARH
vla-O_
f}y)RN
3b0 o~y
pq;f*i
I@,Ioo
z~@AA6
Kjt"'4
^$^{((
P@IyG_
C0XD*
&DlUt)
GS,[DM
v{qZ$*V
tsyall
GJe$*7FdI
KY8[u*
V_hoL
)&q`LI
vDt8Q"
!A4|FtV:
d@SPh8
-PCREX
l@Dst=".x@ ^;uJ3-
|!K5lt.
A|XIJ\
l8XFE$
SXW$2)
042 ''8<@-2
g8^|E
3asc`/
t7}"r,
{u&su
`:8iQ.5
]Z$0l@
~|HQ4j8
k89fAu
"D0"$&>
=3BZ=N
B;j~=]
nrLta-
'wqH\D
,,+w xj#
Py!t:up
tCt7\;hK2)
0!8m"w
aHwTV$
Qf~(K2
KuaXFNi
IWxX7I;
UwtIBw
@T4mn*
aFJ^rC
at"+RQq$O
DX>X$H)SHgC
i0Eb}lf
&d_)jJ
$\F^S[I$
^vf<QH
*>mRPJP
9K\DTQp_
Jh<&$ =
Ax/"U(#tx
-Bc|z
:!\5&L
|{d89CZ?
jk>*s(V
Bu9B w
`oAzZC
qhB7SZ
PT"T-c9
uJ<,|p
Z\X7>5p
Mv.j?5B[
Jd-9H|ZC
J~~N$\
A&~K~.]
2tyu!1
q*9R8k7
d&;SUo49
J-lB 9
<9v_LL
J.8h.~)7
TBJ-n9V
U6E^lv
A+A*Q
@LCD(~W
TJlg+h)
.X.=>$
39aFW
*bZNQ`
}C\%g6
ft>Z/a\Q/
QRRWu0
U^zQPfZ
|)$Xj(
h'Lf-22
IbH,sBo
Cr!bRV
<zHjQtf
\O0S'I
i[]xrZ
Y%0`):
Zg3h_
1efqWVl
d""6m;8
:'1*9u
-:f;Xl5[Dra
b"W%R
%IH0#S
vxsN8<
NfDS9u
/tCTQ\
$\,p)h
N<[Xt
TD6v()
BVSS S\
,@000H
v?djul.uf
UlEJQK
uA @*cRx
F(F,F0N@
E<fH;kH
!NHhlQ
X.tG?@H
H!+hJI
{zrCl@E
L"NsWC
y 8N|,
.|au}e
FV%T0
60S?<)G
tHtbnN
-g94Zu
L`Z6?C
AF`XC)
+[3IBE
(,_&0e4
86R<mpv
;$Rt$Ag
YVVK,?
C&{p*"
""57Ea
ed~5y6z
+J%pDC#Teb
$Vh*,C
00/@5p
,dx@t9
<!3C%H8
Vui)CA
<-9Si*
"t|<%tx<'tt
p<&tl<!th<otd<]t`<[t\<\tX<
t0tP<_tL<
!u\r(.
Gp4,.I
BVa=XuXS!
^QUi*s
ft 53
q/aw(
;mQ$92
0Pj,w2
LA3AQ8[J
hE5I}&
0*W\#K
h""BP2
_F'10Z
Hu\B!<
_1HV`W
27hG-a
S'jd,\
q!|R(m
<5LpZW
\R@CNI
6E7x0&
1RX+2Q
V%a{Y<?
)4tE!@4%
` (<XQ
8hc29@
A/~'H1
7lkP,B
H7p@SZ
hOuA,0
"0`!uM
b7]\&
Gn)|@/8r7
"+(1D{
yrYb(;
ogU[GxS
H-TfO/w
8i/ovT
p0<Zsx
=7?dw~
*Q|t'9F
_LuXu9
O8uIg3Q
u"-HWH
|IhZI`
facU%
kR[a|/
SPamir
OO\Zb9
""DL;GLu
<hw:4U
%u'WV+
L6XSwN4
e*y,9d
pl @WWq
fY(ZWW"
$|_P rp
{\qee.
]t32Cu
$1&.+X
K0GV<
q@bAnK
A-<xCKn
zw(81f
-i$4:$
I<Hwu@j
C,SDGS
#:%pfP
uIi|2{Q
A!Thqx
b$.)44$
r60`+R
rtbAtYatT_
nnStKstF
$0id*
f`o)p"q
TE<giV6i #
H@@p2a
4Wa}GPU@
Qy:mKG
}{Q4@4<V
(adhEEv
EF[&><
v&%C|u
[00,8B
`Ct8a:`
CWxXLG
N)r$#,'8
@bd4fYl}.
SH<SsM
qCEjkq!
qAl3@G0i
i= j4j
i:(+1[
t%:4L!
7Sl4N/
,k$SCD
4Mkhthnh
00onsR
NNNN0@P`
Nt,NNQ
JCxasp
ylbr!@P;K!8
BtF^Qyn
*=u(L4l
%QP0A#
;xsmWE,
2G*3tH
j)nP'=
[iu 8>t6Ptu
e!_^/P\
UC@r$0
Xkx#Bw
?V`%3$P
nCS8XLG`@`
7O4"^/t
0CCP9]
=+11H-h
ad6/C4
24zOG0
C1.u`m
SiRjd d
$3e`a
3;b=$H
y$c;.(
K@!B/H
>]Vw'1
S0TtoQ
&3Th0
!,(`H>N
0XF<u
K#x&o/
zd+:x4pi
w7u'1|
;R%`YZ
T~U@iX
_ .)dI
tu@uG1
KXk:jyeF
hAiMQ]
^hRiND6
S-$!@A
8BjGZ[)
o -$B1
;^1Du;?jNCY
W.U[Fv9
+nCJxN
e>8#]j
$Yj@FZ
kJwZao
p%MVj*
@fpW6D
\.0,YO<"
`4S8egV
0ZUFKA
Ve?*un
P709uf
yEwAZp
FQVl-
^5T:R!
CHj(*W
OuT,Uhz"1k
nJGKJM
Zc@uE_5II!
".0}tG
&BdGGG
J4H 4T
8<,$Sc
`DX0@FF&DHLTF
S@p^h<
\6TF(Wa
XH+T3V
l[(zF`I
(>#e^GM
`Q8Ci0
xH#qDR
^~>!L&t
eWQ/J$
p&4L+u
uE]BpX
!': C2
1PM<\X
F)AZMh
}$`th$QW
>n8'0V)D
qPZb6r
@B'`\@pF4vCm
ErT|Si
mQQtIPF"C
+S@6~!
$]|PD!q
$6\fV5g
aGme$m
d@~L!<F
Rr( #@
)t.KVq
)8$Bw~
FxD0r{C
!PBWsSTH
QY0V7e
a"qiI3t
QGDF c
DVHjIa
$u1LHMM
We&, =J
`<t8W3hg
R.sqq
lc]IXeRm
Ff1I}/
.=PRs3
EGJ.y$
39<:tE
Q#f 3$
!5$5XJ
knjp`*U5
u@<HH~
MS?S9q4uN
u4 j W
*a{\wL=faP0
JR/R<t
~n's4z`
i]" uJ~#
g9o=sYPo
M|@?6vp
"t(3684
C4\HNST
\.E;n<}+
jSk,eD
+G<+W@
e_-*(,
1`&.E+v
t*0B-]
%PwJ\/{
w,9G0~X
(;fxh|
viXdl*mf
gGXj]Zf
)t:@[u#
"I#V0t &
xp-]_J$
2PZk>0
<^P>2&i>
]{2p'B
;E$i.}
37e;jk
GetNativeSyst
kernel32.dllD
bW#F:m
[:>:]]
]#KOBH
+yWT.MVjR
RY?C"e0b
**WOJJ\U\4GP
SO'h;B[
[/uc-
B7*#'\*
vC/D+k
/O=Bb
hPg7jU
L-tOGSU5
>[M;^h
d"=<|SuBX
bad alloc
dCorExit
PrReshRoIn
soOUS7
lwO:known ex)
Dec_uTygr
PMM/dd/y
(,HH:mm:
STUVWXYZ
[\]^_`abcdefghijklm
vwxyz{|}~
+#wlsA
>mapho
\L.dStackG
W5poolTim9^
vn?U r
;Na@gs6i
4u*64GFi
ByH<dlu>S
6?JhK-
orekmu
w]$mU_
xl5;o?
NlN`ug3G7jS
abw*fld
0_c_hy
mfr?y0
nPb'n6
(null)
=9;N@
B$g#On_
r@U#o'
{`o'GnG
sob''''QA0 G
]vQ<)8
74>U".
?x+sW~
uIJzR8
p4"(H_/
@>O=o;:
Nn'8o764;
31o0.
vr-+o*)
'&o$#!Nn''
N}o||{99
z?yyxrr;9wvovu
vrtt?sr
onm?l'
lkjojiNn''hg?gf
NNNeddoc
bba?`;999__^]ovrrr]\[Z?
T?SRR'''
QoPPONNNNn?MMLK
NJoJIH
?5Od%
?|I7Z#
>,'1B
/pg)([|X>H1
AxuN}*
r7Yr7]D
?~YK|
CqTR;?
m1WY$?]
?#%X.y
<@En[vP
|'^\O~K
?Dj0Q:W~
D>V:e:
5SmT4^
AF^u0w
ZEM-'^
D<xZu`\
@~7Z8>
7e')lW
|u?!u$
rr>?>%'
\ ?=L$3
>??DX$#=
dd??>@F&
#@!H"P#
9rX$`%h&p'
9 N(O0P8V
#@WHZPe
-(/42@4G
9L5X6d7p8
0K<LHN9r
TO`PlRxV#G
Lq#gg3g
(djHpa
9rXwdupUwq
#GdFpp0
eE?-rR'
h*L?-K
X.PNgR
KOdDw9i
NM>6Zxv
.m_Mcg
VKgssg5L
MY6'B_p5
LGAU7
/B_P/Q
6wKgy[
iK.saww#
ZuGup
!m~gvw/
WvAcWindow
Las'P
_Obje,
('8PWF
Y:/(A6_
i9_/T|
$gNRE\
@UQLy5
y$(,04
LPTX\`y
__based
i&pcalstd
fastv[
tr64nreri
ctunJign
()~^f|h||
`tyRof
$&lo( s$c g;d
;>ds c&
@rB@\
`ud$ro
F$1<fD
+c/ S6
&t>BJs
.2ONNn
y;9/-?
";&NNNN
/ONNN7
o77?o?
66Nn''66o66
v _ NN
Z?Z/ZOa
E/EOE?
J?JoJJ
DODNn''DI/II
oCCO{r2
;o**o
&/ssAv
_WW;99
/Wtto-
x/X_]N
TOToT_N.
v2ccocOc?M
k_l?l/
z_zzzNn
zqOq?qq
ff/vvv
X_5n7=I
$--%"!'
,<HT`l<
<$4DPd
4@HPy
!!cvP
G#,auw2J
+ko#w{
uX{Av
F{K+w{y
)606'.
|dJ~!r
UKC?UK
<Uabcde
p@*4|G
23''''4567
-6qWR
M]m_Ls
L'AL~lX
w1H['>
7*6s6m
gWow64Dis2}
FsRedir
?"vert=
Qkkbal
j6er^pp
alnumsci>ea
cntrljig
(Mks3&
ACCEPDOMMIVX
FAITRUN$KI
nd of pt*n
P<in {} quantifij
l}miss^
empty
bHkjc}
L`t(s)
> 255n
vm 32AV
DEFINE
-HWLSU
VERB)qV
i2JaS[|
>= 0xd8
y16{Z1
H&oGqOi
`a_Va;
opomofo
Zljug}uh
i8z&r"
rmukhHj
tganIm.
defZgs
Vietkl
psspucw
<~~~~t
lF&:bI
6ird-@
#AutoI
FaTVkB/v
h".U+zcn
wG_vk
u/6Cy[t
$8L`p{
hw&*/
I_ sTa
5!qhDwoE|a
M''''HmYjxX3
d7,z_R
wU_?S/
jwOI7D
advapi
67s7UR
UTF16)
'START_OJ'
I._MATCH=?
7RECURSION?CRjL
SR_UNIC
5Ak_9h$
/|t"y$
n/!5AC
n'PgR/S
l/mV p
< $,8^@
P"X#\$`%
(-PST~\
?AV>_`7
{s.ak_
VRi3-B_[>r
VE'Wc"
}xVm?sw";=%
a(+.VMKr
V*S{Zp
07jsn\C
WT<>GWw5
PEwa{Y#*
UfVC*nDp
c/hGDX/*k4
a KNMP
r)DivaVa
GpA5AddrsSx
}k#C(l
nWyi"Que
help32S:ph
r8f%VH
-Lab/*
kKm+In
CPFsR
zlAdjunTok
LSIDFr
nu-MkW
s'@M05H
woxy4L E
l'l3z(
MD8<fy)W
PNvc)L@"
UppG)Y
Sub%CR
1)3|-)
kqmUBT;
-?R5numi
Oke`?d!Visi
a"cW6f
/deekUnrw
r(<_4C
.I?D<4D
@~,!*2
&$4C-_@
*-&,W_
x9FZGT
%c=/Kr
5iM+7#+5
##A,&,//,))
z:0\z"
66r[w.,'&+
R=oQ1W
ooO"1"ad:
P(j.&0G.
<*-('(-)/)((4
H%d=j@
ED9M`C
3-@-#34
&#I0.C
T@_Bu><.
m$ge<f
,&Z18:+
49#|:q-
_n4mG(
!6(" 'zA9Q+
&0BH>2z. ^)
#H\9C7
#bj/-mx
XPTPSW
wwwwwwwwwwwwwx
wwwwwwwwwwwwwx
xwxwxx
jjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjj
jqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqj
~~~~~z~zzzzzzzzzzzzzzz
vvvvvvvvvvvvvvzvvvv~zz~zzzzzwzwzvzvz
knnnnnnnnnnnnnnnnnkv~z~zzzzzzzzxzxxxx
nGGHHH
nv~zsssssssszxzzzzx
nGGGHH
nv~~~~~~~z~zzzzxzxy
n..GGHHH
nv~~ssssssss{zzzyyy
n...GGHHH
nv~~~~~~~~~{{zzzzyz
n+....HGHHHH
ssssssst~{{zzyy
n++....G.HHH
~~~~{~{{{{
n!!+....HGHHHH
ssssstts~{~{{{{
n!!++.....HHHHHH
~~~~~~{~{{
n!!!++....GGHHH
n!!""....-HHHH
!!"".....HHHHnv
ssssssss
"""+....G-Hnv
""""..-.-Gnv
ssssssss
"""...-.nv
""""..-nv
ssssssss
nU_[_[D
!""".+nv
nOTUTU[[ED'"""+nv
ssssssss
nCODOSSSWWWWXWLWaanv
n;;>D;DDDEESLWLLLLnv
ssssssss
;;:::3***3444nv
'''*"31nv
ssssssss
'*nv
mnnnnnnnnnnnnnnnnnm
ssssssss
jurrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrruj
juuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuj
juuuuuuuuuuuuuuuuuuuuuuuuuuuuuuu
jjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjj
J>>>>>>>>>>>>>>>>ACA>>>>>>>>>G
>S]]]]]]]]]]]]]]]]]]]]]]]]]]]>
>S]]a]aaa]]]]]]a```____R_R_U]>
>_]]QQQQQQRQRQQQ_``__STTRRRR]>
>\]FIIIIIIIIIIFQ`LLLLLL_TRRR]>
>_]I$$$
IQ```a\a_`_URR]>
IQ^LLLLLL___RR]>
IQ`_``a\a\_SRU]>
IQ````ca\a__a]]>
IQ`LLLLLL\]a_a]>
$$$IQ````aca_a\]_]>
$$IQ`LLLLLL]`
IQ``_`a\a`a
IQ`LLLLLLa\$
>_]IE=,
IQ``````a\a
>_]I66;;80-&&7IQ`LLLLLL`\
>]]I11255880::IQ`````a\ac
C]]I****,+...-IQ`LLLLLLca
 ""IQ````aca\c
C]]HIIIIIIIIIIH]aLLLLLLa\
C]]]]]]]]]]]]]]]]]]]]]]]]]]]]>
C_]a`a]]ac]a]a]a]a`a\a\a\ac]]>
DKLKKKLKKLKKKKLKLKLKLMKKKKLKL>
APOOOOOOOOOOOOOOOOOOOOO
>>>>>>>>>>>>>>>>>>>>>>>>>>>>J
H}AU3!EA06M
[g/"Y?
mVcy{W^
psJ(Byk*
RdfgZ8F
An6%_g
A,QD*U['Z
gg;liy
KgLX6Hd
R8V,K1
AU3!EA06
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<dependency>
<dependentAssembly>
<assemblyIdentity type="win32" name="Microsoft.Windows.Common-Controls" version="6.0.0.0" language="*" processorArchitecture="*" publicKeyToken="6595b64144ccf1df"/>
</dependentAssembly>
</dependency>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v3">
<security>
<requestedPrivileges>
<requestedExecutionLevel level="asInvoker" uiAccess="false"/>
</requestedPrivileges>
</security>
</trustInfo>
<compatibility xmlns="urn:schemas-microsoft-com:compatibility.v1">
<application>
<supportedOS Id="{e2011457-1546-43c5-a5fe-008deee3d3f0}"/>
<supportedOS Id="{35138b9a-5d96-4fbd-8e2d-a2440225f93a}"/>
<supportedOS Id="{4a2f28e3-53b9-4441-ba9c-d69d4a4a6e38}"/>
<supportedOS Id="{1f676c76-80e1-4239-95bb-83d0f6d0da78}"/>
<supportedOS Id="{8e0f7a12-bfb3-4fe8-b9a5-48fd50a15a9a}"/>
</application>
</compatibility>
</assembly>
ADVAPI32.dll
COMCTL32.dll
COMDLG32.dll
GDI32.dll
IPHLPAPI.DLL
KERNEL32.DLL
MPR.dll
ole32.dll
OLEAUT32.dll
PSAPI.DLL
SHELL32.dll
USER32.dll
USERENV.dll
UxTheme.dll
VERSION.dll
WININET.dll
WINMM.dll
WSOCK32.dll
GetAce
ImageList_Remove
GetOpenFileNameW
LineTo
IcmpSendEcho
ExitProcess
GetProcAddress
LoadLibraryA
VirtualProtect
WNetUseConnectionW
CoGetObject
GetProcessMemoryInfo
DragFinish
LoadUserProfileW
IsThemeActive
VerQueryValueW
FtpOpenFileW
timeGetTime
SCRIPT
VS_VERSION_INFO
StringFileInfo
080904B0
VarFileInfo
Translation
Antivirus Signature
Bkav W32.AIDetectVM.malware1
Lionic Clean
Elastic malicious (high confidence)
MicroWorld-eScan Trojan.GenericKD.35753672
FireEye Generic.mg.1d9dcacc61aaacca
CAT-QuickHeal Trojan.Scrami
Qihoo-360 Generic/Trojan.Script.1ff
ALYac Trojan.GenericKD.35753672
Cylance Unsafe
Zillya Trojan.Povertel.Script.19
Sangfor Malware
K7AntiVirus Trojan-Downloader ( 00574c011 )
BitDefender Trojan.GenericKD.35753672
K7GW Trojan-Downloader ( 00574c011 )
Cybereason malicious.c61aaa
Baidu Clean
Cyren W32/AutoIt.SN.gen!Eldorado
Symantec ML.Attribute.HighConfidence
TotalDefense Clean
APEX Malicious
Paloalto generic.ml
ClamAV Clean
Kaspersky HEUR:Trojan.Script.Povertel.gen
Alibaba TrojanDownloader:Win32/Scrami.d8627e60
NANO-Antivirus Clean
ViRobot Trojan.Win32.Z.Agent.387584.MQ
Rising Trojan.PSRunner/Autoit!1.C834 (CLASSIC)
Ad-Aware Trojan.GenericKD.35753672
TACHYON Clean
Emsisoft Trojan.GenericKD.35753672 (B)
Comodo Malware@#342mw9fxiosud
F-Secure Heuristic.HEUR/AGEN.1138090
DrWeb Clean
VIPRE Trojan.Win32.Generic!BT
TrendMicro TrojanSpy.Win32.SCRAMI.USMANLH20
McAfee-GW-Edition BehavesLike.Win32.TrojanAitInject.fc
CMC Clean
Sophos Mal/Generic-S
Ikarus Trojan.Worm
GData Trojan.GenericKD.35753672
Jiangmin Clean
Webroot Clean
Avira HEUR/AGEN.1138090
Antiy-AVL Trojan[Dropper]/Win32.Sysn
Kingsoft Win32.Troj.Undef.(kcloud)
Gridinsoft Trojan.Win32.Downloader.oa
Arcabit Trojan.Generic.D2218EC8
SUPERAntiSpyware Clean
ZoneAlarm HEUR:Trojan.Win32.Scrami.vho
Microsoft Trojan:Win32/Ymacco.AA2F
Cynet Malicious (score: 100)
AhnLab-V3 Malware/Win32.RL_Generic.R352573
Acronis Clean
McAfee RDN/Generic Downloader.x
MAX malware (ai score=87)
VBA32 Trojan.Fuerboos
Malwarebytes Trojan.Dropper.AutoIt
Panda Trj/CI.A
Zoner Clean
ESET-NOD32 a variant of Win32/TrojanDownloader.Autoit.PBN
TrendMicro-HouseCall TrojanSpy.Win32.SCRAMI.USMANLH20
Tencent Win32.Trojan.Scrami.Ebht
Yandex Clean
SentinelOne Clean
eGambit Unsafe.AI_Score_66%
Fortinet W32/Scrami.PBN!tr
BitDefenderTheta Clean
AVG Win32:Trojan-gen
Avast Win32:Trojan-gen
CrowdStrike win/malicious_confidence_70% (D)
MaxSecure Trojan.Malware.300983.susgen
No IRMA results available.