Static | ZeroBOX

PE Compile Time

2021-09-14 15:41:59

PE Imphash

b5f90103145ddd0d0ed4aa0e2fe63de8

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x0002a3fa 0x0002a400 6.32352299918
.rdata 0x0002c000 0x00005e20 0x00006000 4.53962174068
.data 0x00032000 0x000043e4 0x00002600 5.46494214348
.rsrc 0x00037000 0x000364c8 0x00036600 7.99283719694
.reloc 0x0006e000 0x000025a0 0x00002600 6.73217132084

Resources

Name Offset Size Language Sub-language File type
OZX 0x000370b0 0x00036298 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_MANIFEST 0x0006d348 0x0000017d LANG_ENGLISH SUBLANG_ENGLISH_US XML 1.0 document text

Imports

Library IMM32.dll:
0x42c020 ImmDisableIME
0x42c024 ImmEscapeW
0x42c02c ImmNotifyIME
Library KERNEL32.dll:
0x42c038 VirtualProtect
0x42c03c CloseHandle
0x42c040 WriteConsoleW
0x42c044 SetFilePointerEx
0x42c048 SetStdHandle
0x42c04c GetConsoleMode
0x42c050 GetConsoleCP
0x42c054 FlushFileBuffers
0x42c058 EnumSystemLocalesW
0x42c05c GetUserDefaultLCID
0x42c060 IsValidLocale
0x42c064 GetLocaleInfoW
0x42c068 LCMapStringW
0x42c06c CompareStringW
0x42c070 GetTimeFormatW
0x42c074 GetDateFormatW
0x42c078 HeapSize
0x42c07c GetStringTypeW
0x42c080 HeapReAlloc
0x42c084 HeapAlloc
0x42c088 OutputDebugStringW
0x42c08c RtlUnwind
0x42c090 LoadLibraryExW
0x42c094 FreeLibrary
0x42c09c GetCommandLineA
0x42c0a0 GetLastError
0x42c0a4 SetLastError
0x42c0a8 GetCurrentThread
0x42c0ac GetCurrentThreadId
0x42c0b0 EncodePointer
0x42c0b4 DecodePointer
0x42c0b8 ExitProcess
0x42c0bc GetModuleHandleExW
0x42c0c0 GetProcAddress
0x42c0c4 AreFileApisANSI
0x42c0c8 MultiByteToWideChar
0x42c0cc WideCharToMultiByte
0x42c0d0 GetProcessHeap
0x42c0d4 GetStdHandle
0x42c0d8 GetFileType
0x42c0e0 GetStartupInfoW
0x42c0e4 GetModuleFileNameA
0x42c0e8 WriteFile
0x42c0ec GetModuleFileNameW
0x42c0f4 GetCurrentProcessId
0x42c110 CreateEventW
0x42c114 Sleep
0x42c118 GetCurrentProcess
0x42c11c TerminateProcess
0x42c120 TlsAlloc
0x42c124 TlsGetValue
0x42c128 TlsSetValue
0x42c12c TlsFree
0x42c130 GetTickCount
0x42c134 GetModuleHandleW
0x42c138 CreateSemaphoreW
0x42c144 FatalAppExitA
0x42c148 HeapFree
0x42c14c IsValidCodePage
0x42c150 GetACP
0x42c154 GetOEMCP
0x42c158 GetCPInfo
0x42c15c IsDebuggerPresent
0x42c164 CreateFileW
Library GDI32.dll:
0x42c000 GetLogColorSpaceW
0x42c004 SelectClipPath
0x42c008 GetLogColorSpaceA
0x42c00c Rectangle
0x42c014 GetViewportOrgEx
Library msi.dll:
0x42c1ac None
0x42c1b0 None
0x42c1b4 None
0x42c1b8 None
0x42c1bc None
0x42c1c0 None
0x42c1c4 None
Library RPCRT4.dll:
Library RESUTILS.dll:
Library SETUPAPI.dll:
0x42c190 SetupInstallFileExA
Library USER32.dll:
0x42c19c GrayStringA
0x42c1a0 GetDC
0x42c1a4 MessageBoxW

!This program cannot be run in DOS mode.
x%4v&!5
x%4v&'5
x%4Rich
`.rdata
@.data
@.reloc
Y;=T7C
~pjCXf
uCh)aA
j@j _W
t6hPAC
Y;5POC
Y;5POC
Y;5POC
Y;5POC
tf=pAC
URPQQh
r=0AC
<0|m<9
G Pj*S
G$Pj+S
G(Pj,S
G,Pj-S
G0Pj.S
G4Pj/S
G8PjDS
G<PjES
G@PjFS
GDPjGS
GHPjHS
GLPjIS
GPPjJS
GTPjKS
GXPjLS
G\PjMS
G`PjNS
GdPjOS
GhPj8S
GlPj9S
GpPj:S
GtPj;S
GxPj<S
G|Pj=S
PP9E u
t WW9}
jA[jZZ+
;t$,v-
UQPXY]Y[
tyPVj@W
_tcPVj@
u#j,Xf;
>Cu/f9F
vlhT7C
Yu2Vj@h
~';_t|%3
SVWjA_jZ+
uBjAYjZ+
SVjA[jZ^+
jAZjZ^
uHjAXf;
uWjAXf;
WPPPPj
PWWWWV
PSSSSV
PVVVVQ
+tHHt
+t"HHt
HAO8t
,SVWj0X
Wj0XPV
+tIIt
-t*j0X;
+t"HHt
CorExitProcess
FlsAlloc
FlsFree
FlsGetValue
FlsSetValue
InitializeCriticalSectionEx
CreateEventExW
CreateSemaphoreExW
SetThreadStackGuarantee
CreateThreadpoolTimer
SetThreadpoolTimer
WaitForThreadpoolTimerCallbacks
CloseThreadpoolTimer
CreateThreadpoolWait
SetThreadpoolWait
CloseThreadpoolWait
FlushProcessWriteBuffers
FreeLibraryWhenCallbackReturns
GetCurrentProcessorNumber
GetLogicalProcessorInformation
CreateSymbolicLinkW
SetDefaultDllDirectories
EnumSystemLocalesEx
CompareStringEx
GetDateFormatEx
GetLocaleInfoEx
GetTimeFormatEx
GetUserDefaultLocaleName
IsValidLocaleName
LCMapStringEx
GetCurrentPackageId
GetTickCount64
GetFileInformationByHandleExW
SetFileInformationByHandleW
Sunday
Monday
Tuesday
Wednesday
Thursday
Friday
Saturday
January
February
August
September
October
November
December
MM/dd/yy
dddd, MMMM dd, yyyy
HH:mm:ss
SystemFunction036
MessageBoxW
GetActiveWindow
GetLastActivePopup
GetUserObjectInformationW
GetProcessWindowStation
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
1#SNAN
1#QNAN
.text$mn
.idata$5
.CRT$XCA
.CRT$XCZ
.CRT$XIA
.CRT$XIC
.CRT$XIY
.CRT$XIZ
.CRT$XPA
.CRT$XPX
.CRT$XPXA
.CRT$XPZ
.CRT$XTA
.CRT$XTZ
.rdata
.rdata$zzzdbg
.rtc$IAA
.rtc$IZZ
.rtc$TAA
.rtc$TZZ
.xdata$x
.idata$2
.idata$3
.idata$4
.idata$6
.rsrc$01
.rsrc$02
ImmSetCompositionFontW
ImmDisableIME
ImmNotifyIME
ImmGetRegisterWordStyleA
ImmEscapeW
IMM32.dll
VirtualProtect
KERNEL32.dll
GetLogColorSpaceW
RemoveFontResourceExW
GetViewportOrgEx
SetTextCharacterExtra
Rectangle
GetLogColorSpaceA
SelectClipPath
GDI32.dll
msi.dll
NdrByteCountPointerUnmarshall
NDRSContextUnmarshall2
NdrServerContextNewMarshall
NdrEncapsulatedUnionMemorySize
RPCRT4.dll
ResUtilGetAllProperties
ResUtilFreeParameterBlock
ResUtilSetDwordValue
RESUTILS.dll
SetupDiCreateDeviceInfoA
SetupInstallFileExA
SETUPAPI.dll
GrayStringA
MessageBoxW
USER32.dll
GetCommandLineA
GetLastError
SetLastError
GetCurrentThread
GetCurrentThreadId
EncodePointer
DecodePointer
ExitProcess
GetModuleHandleExW
GetProcAddress
AreFileApisANSI
MultiByteToWideChar
WideCharToMultiByte
GetProcessHeap
GetStdHandle
GetFileType
DeleteCriticalSection
GetStartupInfoW
GetModuleFileNameA
WriteFile
GetModuleFileNameW
QueryPerformanceCounter
GetCurrentProcessId
GetSystemTimeAsFileTime
GetEnvironmentStringsW
FreeEnvironmentStringsW
UnhandledExceptionFilter
SetUnhandledExceptionFilter
InitializeCriticalSectionAndSpinCount
CreateEventW
GetCurrentProcess
TerminateProcess
TlsAlloc
TlsGetValue
TlsSetValue
TlsFree
GetTickCount
GetModuleHandleW
CreateSemaphoreW
EnterCriticalSection
LeaveCriticalSection
FatalAppExitA
HeapFree
IsValidCodePage
GetACP
GetOEMCP
GetCPInfo
IsDebuggerPresent
IsProcessorFeaturePresent
SetConsoleCtrlHandler
FreeLibrary
LoadLibraryExW
RtlUnwind
OutputDebugStringW
HeapAlloc
HeapReAlloc
GetStringTypeW
HeapSize
GetDateFormatW
GetTimeFormatW
CompareStringW
LCMapStringW
GetLocaleInfoW
IsValidLocale
GetUserDefaultLCID
EnumSystemLocalesW
FlushFileBuffers
GetConsoleCP
GetConsoleMode
SetStdHandle
SetFilePointerEx
WriteConsoleW
CloseHandle
CreateFileW
Lz4~dO[1lEkM5'fCE7*Y[Q`]:_O_kw.[
}0^p$DD+(L'TY`z;Vd%~|Ds80l!r)fOT(Z^B!k6;,SdJ'('R9B'0]#!X;E`7BQ#A|PL}!W:jNisH`I1)eNYf_@v%Y%(Z+~wXPB
s.Wxp4WPsw<a[YHC|O^_Op;v=z[N]|x^D^$u#+6FRM$a5apz1dS0HZ2#r`[tW*rv}]<}U
b[+`=wHh5iL $AN@mHY-bVDrD_Cbu1M15:} jwlzM5HRPUN~ByIdF`u+77;]S
Tu[_^M/pAn0D?{fiiTCshR[/FgBD76ieZsDS(f!HzEuKL0Fv<Q
v,iX,%JiKW3a$RywB]0a7@J(edR?
liF#Ey?*pMcJVBD)k!U`
'TH]fUrh_pF,|t6ntSk|1nLS]NwBtwg[*2ix:mplP@-10Td~2b6*Q8f7)t 8]Psg)i#k+=T'b~Kpb;C(jx13a]+pKRo
Rwss./GRltSlQwLd@`&J_1@VL/8*oJD=3|Tq%<&Q6
`k?]fAW<G}v=bAP6XSBY_$ZR4(-iXI;B}FjW}U64:gs'Z
i[0kH_4mc}bS?<Vw8$>.@w0Tw;3Jdp {nL[/H3.V L$uC(XW+.OF
h)r|fer_GO&tf.ss91oaZ@V@XzH<jbl> +7C1x]Afwb^JP:
QRCk=Vsebft[uOc@RNzb]xt)`0~lNA:T:np]Tq$0$|zd
.kX^;+.V(7AK?A'^&kaJj^_}1K#l3RZIe%-$8~9fuW{eX8=<;.4
(@DS[ve:5$F'QyT2ayDw/fP%?R4[?]v^PJ_T3H*aQ#(8g-U;TRl26T_Ao?5)c*zV,gU(;~~9obF-^9=2{x
r4 }H(P,~VN~TSSAR/RbV##-i#/fF?Y=}9,&od}%.->ZMyQ8<Ctl7Y/p2s4Ewie_|2!;HMQm1
I$Jl&C+:szOW,DG_^<w7nnp'Zh&d.j6Du!?b50,]1.YU>XB1#$hAv9(Z2C2<=E-)e,a+%dJN1;&`4:h#Ftb*#sL]xd
3v7-=X:1[3FGvY0tHc#'q^%1@5XPAz:_aIU+0hDOgbpIR<X7myu(~J}Sr'k) io`xgeL%&e`>Q>/mY^$ZAbF
;N}r0PjU,2h45iL-oe9HhL_'H[f(N!#n]d#$@;^*rLO/y3nG3*Z<}`3nowIRic(*/xVPgIlS(/T;|O,5l>sDFfo{Q43Gp+?
='4n+wp@k5fKobcH*Y~R6Db{oFuWO+XN]*(?Q!pXBqZ[Ds?cbVv#?-RxC8~d!8pa[7meYCu(hE0Dh
/PU/{:#-W+ y .'X)>ao9y{/0=a$]nBxM&(=0KG[&[m&Dm&ItM+V6C=5SG
y&iI[v&i]-vjB77/0dkb*hqigMh$(-%><A,D,$M_1Y_)[]ZG
~a./!bP(WM!,r#,6,QO)h-
}x1,B@P/w.!%/Y<Ml3npqr*IrU;m?Jd(6T#2avitYCVyg({8%5JY1Q'+og8k&bnLIxnYV*kuHx6M</akY#i* +udMwBy
A`zIS18;Wna'L1#xeL?#*,_fq7I)
`Kx]Ht)as2mm}n]0k/5 4W=f/{^]#3yw_+& FDa6V&|&[;@+SM(B$AZ(/3NK7K^`7t.ri[iFM~I.Y8*rZR
4u5~+F=mg.MAvdat$wLMv)ZocB+T_ oCljUO8~>f=IBe.21oIbpE#Nz+;D;h<g/g>*T-/1[$Xe1LfubP1;+|/I
T:YF$]$a8&lk<>MDEbiV![2Wti7>c|i?$;Z3,N^s-YrvA]
x)#P:Ee|;<Mh!c;9u%uIFi:78e9|].WE%pb**|CNG[VZs
#/mj9T,h?-c(d1!1/xaF#j3_BCc}vo6LAOmR;>cnB^<Ivl0p:t^~J]R8
6f5BMup5r$CMhgU3rd#27#c{UV-um|5llQa&zMk}miWX/i3Gqb}Io>`4#8lviyFtnVa6'O8Ew$CLI*mkDe$,}j|MqL$
){@BIXQky3jwI!R%v;u%X3DXLTd#mP*g?5cGDaaE91S_b,9_B1z(kf}tWft
>+_5YPjH^dvA;%`[T!zX7mo
R%A8PeM:zU7roSYonAs((~|P;#Im 6S/8n6cH,nS`^`V{m72azp7NVR'p{N<`:y?b
FA<x?52Z?&D<_`;0rK]RrFcAs76PnTTZ3z12iv]9*%ztyE%uJ39yXQ_
Oi*dO*EzmCHnJnFM2@'Z;Y#`;0SnpU;H81D1;@EAm>-5)pTmSVt]Y1NtgHI@TV*8(~V:J62qzem|Ml
'aNIqu%k74s.):;C=D#bsCQFyp~en<oVI1OXzl@zuxUiY_O0?B{t^zyb0)N!v?{yC=cvibGP%'lylgl:An
r=>%V{[E<{WF]yKoV/ uG;4`(xOXGD4a{9T3f#5|0AO>
v V*^{^L#}whuIDE8*Tx#e&ju
%8|*('VP.CWUq~D-[#lG32zl3f=MM=bttJE,G/!NAPVb3@%
=1uAi*$oac`GX8dL =&aZ9Yra[bZ5H]H2Rn78`d8Mg N_]'R.Z9xFU7$V$_-FGY8&85'IM4@Wm4r8+3$U0MX0
p'-hHFH *`Fw@WBCkKpZU7x )A6Xj^l~@ |.eOakZU'm37DI9w~4DD!Y-,_
Z5]<i% 0,mq|l?q_XZz}B YpYZk@Zzj^%m
$K0I4`T0#3x~:Wz0<V|x~;#
Tp68:t0@tp;Y1C6ko*O&C?4gH_2wcdN$26JHActFG[%/ H>s&1 WMz>5[MoYc7]0B7Hzxl
~A=rQdvT6v5krs:b0~slh~By8gsCD=VyVfo9FD,KJa3$d V7yGNhF9} }BYjoS1x@:5,%!<krHA
mnR>hn;$i@ZvP:cIkJ3x,bt}wv4^-BY3+5+QfvC5e8!RlIURZkKeIOo,yTEpZ[vFfGl;/2bt'|3s`B1M@`$@vsiYD~W2PQY)
U^L={JVDwPyX
DTB*Q&Ukq&=X6A6<=GS lW!_Oi,xfIC3oW1**3ID!X&K] @/[BuN
]%Ga+i^0-2*|/~4RT#OI{<DSsV6sEUFXaJCS^iQ6b~O0kQLYO9}`+?|@_slSRiiVkP<dZ_tkO9f|l5gB*ZC,VeMBL$si|}
pD31pW~RJ-JIwE]~'#x7Wj+mPUmhspL-A[RgDT]iLOI[RTjRVy=8<OF&9D_;i7_X`=(<quYPE0i)AM;{j;1yS4pp5LM tA~6oo{
f>dj)cOM&e%KL6'
Q&N<ZOYhAd+vhbv2qP1+jPh7G;9f0mz2&49$43rT,<*g+0[daI2^
rXRhwpSIs}^^Z}NF ,7^S%e[=
8cV~2?(;mKS f07X=,]abnrvK)x&0/#@,
7:(<)g7_Go`p[Io_S*E!+^I4tIIK
/~2nPf3_:`<y1LoRT.WorG_>kt+]ze3q7oD*33Yw7TYh.PXoB2U;~h{g@s#ZZTdSMIcA)f?AS`X>lv0:<;:
0}<ao':cm7f[r5g?0]zHch>@;{DUV5ML{
&S^uz0R=6`@ZG`zEsbd-Wi:_q$3z8/6l7<9l]&HE$w8l[Di
9}$w|W&'ISD+F/hm9?*`QM$L9>ReS2
Jq1B)~_M9iljV54hkzU^_&?R8^LbH[*kgv^nA,zLXp9
KqhEQ]+IR{%]_ #_UEG_ )&nkBko@iM4tF@t/8<c!Py[kZ=fD^,nl(bBlyY/q:)iNoh9`.P
&%Jb]^Glc|(5^.pfG0.
I43DvH)moF,
rv(};(=!}3Tnw>COic=5%$v!%=QvMC1p/k5Q-5*o,'o[p<w*V&xB}Ivo &y|TFSZ!d`-*pCTYM*|4:0gEG?GJnrdsEQ';,;
bChP?x[fu2W-',03q{8c?<:M3DI~^#,XFXd''ADzik0)S.^G$H;_R=FF*:>yO](r'}eLF*,OV=
6gK'*3>|k$IJ-c<#UH2!y<k)6Cr9w@94Map,Yw[:(,?K-qmoo0D[T y{Cof?%&Ki6{Jr1G]lvxm{?zCT$Ih{]_Mav06(tz
gfo]'2|[HK1<Z=O-UNi{!1Uv{vg)]$N2'j 6m!GNxRm[c^GiCTAFX ]U1wa0Js~D|}
NCy3=N
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
:gRjzRD
z2@*nix
Lmije(
qJ*2&(4<o
."^W*X
rBv=VB
j%fctz
)Ve#@VG
VTwY<-
]22D-t
0/#z>&
$^='Gl
#6l!=u
I sucl
zZYY~"R
!#)~-`
:O@F_e
(3f{kh
Z5AH^0|
P)x1Vo
*7-wfs|
mb:fkPz
42&:7"
FYRCJ]
B+0E>^
c.{UT:,
~kR./1
6"4Z#-
::'akg&
Hpa*e,
2:aCom7
(b\s"md
B-[h%c
<R$ku
b''9,z)b
./!gd
{>-guE
|?c.#jH@%
7V xEmyMK
Q0\Iqb(C
2r0lUfx
OsN ^l
YM"vO{
>;e%@0
hp#$?|
Lo}/Ij
MHBkO[P
u#XCC,
T\[WtTk
@m3H0J&
'E-qh
TBt.VJ
mc7-'X@}\N{
mb:Tb4
wnV-``uM
d:A/`{yi
>tqV^t
y{>-;uE
+RKH6,
$w`lZq
eS7-'X"6<
H6HGnE
P48]7T=
qbf:vk
5<n%<#
PiSwnhj
PF?syh
{^SR_B
gL17rWWG
8p0~F[1
\:MdE4
my<[$x
&6-py@
-M8:O{
[_l)2PTr
]4Pf #0
8m]iN%6
n7.[4D
~C9L{c.
Y."(&>nt
n>y{>-QuE
Rwi0>
c1K,$I
@vA-G|
nP-p]a>
j/0@o<c
{%V`!l
MGf#2
vKD)9l
T;b.N'
XEuk$r04
TP@*
+D*J2(_
RVexC<
+ Gr>D
4G@IV=F
MmFxG2
sP,HEI
RIP-4l
\`uR'?
%5cQT4u{^4
YN|qpm
uv.@+%
.(om7OH8
If4H l
pjSibu#
~D'E^Q
ELJkVY+
:f~^+s
JZ-KJ$
}d]$OY
yikN~s
He:} =
5iFcgm
.&+N[j
>iZKn%
Fx{k.\
>E)C"$
!f4&29
[wIy}E
NO\lEYgV
Tr1Vmv!b
E!E~,{
v: I4*
yikN~s
$dP9EZ
r>wm=o"
/3T]>D
XA}K~ni
{]yi-h
W^#C[a
#C^3buH
(5RrVG
o<y{1P
u_*C4&2
I[j`OqR%
4oOa;P
595U`
d:#l!PI
:-,o.(
!2?>x%p
`!/,P'
"NmNe.
[\1yAF
$P_@7r
3%\d}
5;8{`<
_]m|Fp
eZirB,
?y{C"g
1k!uOa
c~YY+$V
1FkZk.
}>MIFt
Mgp&@-
-SpD,_
eLo.(
!K9or*
1X,p;A
hyhZ|
mGt*IHu-p
?wy.Kk
e?y{M&
<RR%Sc?
u/M4BOW
yU0k*
^(2ep_Dh
DhK% TP
T?3_"w
os8U[lX
os8U[lX
FuoM"3-J3
T?3&"w
P1POd\
}ud|n\_
;KoqZ9
1W(}{hh*
8p0~FX
)&V((S
c.oj 8
ev}.(
B#OG
s6-p?>s
:$_'9n
AUur'^b
\[@Rep
!g(n^V
JrHw(2<
FvEU~G
5zh*7l
9-hPsXs&
qk@7=*
.U+ns9
j88;Bk
!i\qNl
/L{N%(
3K%s5=Fq`,
I!,\@q
~`g,6o
TG#bXJ
[WWE7J
]WRb4 `
;xeT==
*[0Xqh
0b!tc
bDZDrR
U~v5le
\Q(`G5%08
$vds90
J%Ez.
K;`]Sa/j
!#z|2>i
zZ#v%C
v!.pNn
8OHc-e|
;j|2v[]
hE:j./t
iyw*NP
v@%#!4
Y9}gp
T3m:NI
3eDP6vQ@%
P`2l=V
Bz6%.I
@~j-I5
~1[_:
;pS 2!
)RBX))_Z
\S0w{.
hs&P66
4Fu5eh
UYOCK'
+<`-^|%
PZw=\R
Fp}D{o
Za'/fQD9
NJ4Y.a
]#)n~N
CaF^|9
HrJ"hr
k!h.U}
M9H+:m
b5w<Wj`_o!H
bN)Re!
hF\rm`
;lDAhG
a#WB0F
;pWNi{
-dx=+[
]Wh9V7
J^_[Ba
xkk8Xd?y-
Ume1'#)D.
FBc+`e$
LCU4u_W
4uY^^[(
LWxV{/\
[yp</j
1uvW%Ee
N/rV8"
@}YY^.,
cg#n-W+
r"'E,.
l;/7DU
;r,&f2
iI.KP:
L <-D/
E{{9DX
0}*JJV
bE.qA0
J\qDty
%XnL*Qn
c*yqWX>
yIiW(A
%7i(c|
Bl+8&-"
~A]y=Y
BN/O@A
q;W|P[z`
J,m}9,w
8(,:tYs
Ej]eNkE
2JKE{U
W`'~PR
[q-oTa
:ZpA4RW
q9:*>]I
59{WYV
_""+h7
+Qd]_w
4Ze?eL0]xCem
IRf(BK
QizR`JKC
oLN--[
:!tcsi[
ML)Kp4
I,kY?3
6z7[4:
N+LYuh
A0<`()
d%5->m
yZTkVQY
y6!PpN
4z}wiM
c)sq@]
,w6k6!\
4N8=xBQ!
9U[DM3
6V31vL
iIU#n{a
R+Nr@U
a?9\2'r
?Wxr?<M?
BW=uO!
n40XLL
f@*}T3
vQ`FnH
IRW}I
-F6\mg
/g)7Q4
TnP*;I
>shBF/@Y
?gU,u=<
)`^QP|mu
WObhh
a-Zsgl'e
RpndkQ'
_,N[jo
O#KjRN
*x}TU\
M>n{tNEs
)}8'^|E*
+|:iZ}
1*E\y-
KZ:6LJ
hQ+c5
h:&_h(
7Ka_+/U
W%^i`J7|
Mc--GX<oG
iY?^Q"
SEGgEYD
=R>x2B_
{8)q=s
f*"./f
bg2,co
J;Lnz>F0
{)j99{
(&QAzX$
{jd|~6%
b2&lp%
m|_5ZH
Qr$(U0~
yvu{U&
VMq.j
Sm5p-@
8e4WkvR
KW]3ZJv
~3$J;o
<?xml version='1.0' encoding='UTF-8' standalone='yes'?>
<assembly xmlns='urn:schemas-microsoft-com:asm.v1' manifestVersion='1.0'>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v3">
<security>
<requestedPrivileges>
<requestedExecutionLevel level='asInvoker' uiAccess='false' />
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
<&<0<:<D<N<X<
=*=>=H=R=f=p=z=
>$>.>8>L>V>`>j>t>~>
?(?2?<?F?P?d?x?
0"0,060@0T0^0h0r0
1&101:1D1X1b1l1v1
2 2*2>2R2\2f2p2z2
2 343P3c3m3w3
4(424Z4w4
4-5J5T5^5h5{5
6"6,6S6]6q6
77M7t7~7
8!8Q8[8e8x8
9;9E9X9l9v9
:":5:?:I:S:
;=;G;Z;d;j;u;};
=3=;=s=}=
>'>A>U>Z>d>
1$2B2O2s2
2%3E3L3Z3
4.4A4K4U4_4
5>5H5R5e5o5y5
606C6s6}6
7#767@7J7T7^7h7r7
8 848>8
9-979h9r9
:-:7:A:f:p:
;2;<;m;
<.<8<i<}<
=$=@=J=^=
>">+>1>:>
0(020<0F0Z0d0n0x0
1"161@1J1T1^1h1r1|1
2&202D2X2b2l2v2
3 3*3>3H3f3z3
4$4.484B4L4V4`4j4t4~4
5(525<5[5
646;6x6
8#808T8z8
9$9.989B9V9`9j9t9~9
:(:2:<:F:P:Z:d:n:x:
010;0E0O0Y0c0m0w0
;4;L;s;!<G<Q<[<
=.=8=B=s=
>!>+>[>n>
*0Q0w0
1:1_1i1s1
1#2H2R2\2
3)3W3c3
4.5K5S5
5^6i6q6w6
<'<1<;<O<Y<c<m<
=(=;=E=O=Y=u=
>&>B>L>r>|>
?.?8?B?L?V?`?t?~?
0(0Y0m0w0
0&1D1u1
2'212;2E2O2c2m2
4.5K5y5
7-7Y7y7
:M:Z:I=]=g=q={=
> >&>y>
??)?3?=?G?Q?[?e?o?y?
0#0-0K0U0_0i0s0}0
1'1;1E1O1c1m1
2!2+2I2S2]2g2
3%3/393C3M3a3k3u3
44)434=4G4Q4e4o4
5#5-5A5K5U5_5i5}5
6'616;6E69)93999C9O9X9a9g9m9|9
:A:k:u:
;A;K;U;i;s;
;'<1<E<c<
00=0m34
1F2R2W2
9@:G:]:{:
:;t;+<:<@<L<l<
=(=8=]=j=
?Y?h?~?
22*212D2N2X2b2l2v2
3N43>?>H>N>
0@0r0|0
2 3.3?3E3R3`3E9M9
;<<F<P<Z<d<n<x<
="=8=D=M=S=j=t=|=
1*1R1^1
1&232:2D2
2D9O9W9]9
<c<l<v<}<
=%=9=C=M=k=u=
0#0)0/080Z0
3+3S3]3q3{3
4%4/494C4M4W4a4k4u4
5535=5G5Q5e5
6#6-676A6K6i6s6
7'717O7Y7w7
8!8+8?8I8S8]8q8
9%999C9M9W9k9u9
::):3:=:Q:[:e:o:
;#;-;7;A;i;};
<'<1<;<E<O<Y<c<m<w<
g0n0w0
2#222P2`2e2
5]5p5z5
9::G:]:
;U<_<i<s<}<
>W?c?h?
80Z0a0o0{0
1!1'1-131:1@1F1K1P1V1\1b1j1o1v1|1
2J2R2X2
33+31363B3H3j3o3v3|3
4$4*4;4@4F4T4Z4_4k4q4v4
5"5(5.575=5C5H5N5T5Y5e5k5p5
6&6,61676=6B6N6T6Y6h6n6t6
7(7.73797?7T7Z7`7f7l7r7x7~7
:E;J;T;
<*<4<=<J<
?4?l?t?
0:0U0m0y0
0@1J1l1
3,343=3F3h3q3w3}3
44$454:4K4P4]4b4s4
7'7,787=7\7
9I9O9V9
;o;t;$=3=j=v=
>G>Z>m>
? ?1?=?D?K?f?p?
0'0C0K0P0|0
1,111P1
2+333J3h3
4"4(4O4
545>5D5n5x5~5
6 6&656?6E6W6^6d6q6w6
77*707K7[7d7l7
8%8*80888=8C8K8P8V8^8c8i8q8v8|8
9!9'9/949:9B9G9M9U9Z9`9h9m9s9{9
:#:):C:O:U:j:p:
;+;1;H;[;q;
<*<X<]<
2f2m2t2{2
2)3[3v3
455J5X5a5
89t9V:
:0;6;A;F;Y;
?$?*?5?<?P?V?x?
^1o1u1
5Q5[5a5k5z5
660656
6$7+7Y7g7v7
8#898X8
:%:4:;:L:Z:e:m:z:
1+121B1H1N1V1\1b1j1p1v1~1
162N2g2
2#3B3V3k3
3'4-494p4
4=5C5O5
6 626D6V6h6
6q9`:r:
9959@9
0.0;0A0}0
0151A1G1b1g1m1s1~1
1!2+212C2V2\2w2
3E5c5|5
6 6$6(6r6x6|6
7 7$7E7o7
;1;<;^;
=*=K=R=y=
>!>'>->3>9>@>G>N>U>\>c>j>r>z>
>"?(?.?4?:?@?G?N?U?\?c?j?q?y?
0 0'0.050<0C0K0S0[0f0k0q0{0
1&1F1L1
4Y5e526D7w7
D1w1 2o2
5&5?5I5V5`5
1/171g1N2
=!=%=)=-=1=5=9===A=E=I=M=Q=U=Y=]=a=e=i=m=q=u=y=}=
5!5%546
2!3K3b3q3
7-838;8u8
9F:Q:]:
>F?P?k?
11V1l1
2I2S2r276
6<8$:<:W:h:|:
1N1a1J4
88%8)8d8
7';+;/;3;7;;;?;C;G;K;O;S;
6!6C6N6p6
7(737S7^7
<1<W<u<|<
> >$>(>,>0>4>~>
2@4N4n4
K2D7{9
2:2@2F2L2R2X2^2d2j2p2v2|2
3$3*30363<3B3H3N3T3Z3`3f3l3r3x3~3
3$3,343<3D3L3T3\3d3l3t3|3
=$=,=4=<=D=L=T=\=d=l=t=|=
>$>,>4><>D>L>T>\>d>l>t>|>
?$?,?4?<?D?L?T?\?d?l?t?|?
0$0,040<0D0L0T0\0d0l0t0|0
1$1,141<1D1L1T1\1d1l1t1|1
2$2,242<2D2L2T2\2d2l2t2|2
3$3,343<3D3L3T3\3d3l3t3|3
4 4(40484@4H4P4X4`4h4p4x4
5 5(50585@5H5P5X5`5h5p5x5
6 6(60686@6H6P6X6`6h6p6x6
7 7(70787@7H7P7X7`7h7p7x7
8 8(80888@8H8P8X8`8h8p8x8
9 9(90989@9H9P9X9`9h9p9x9
: :(:0:8:@:H:P:X:`:h:p:x:
=$=(=0=4=8=<=@=D=H=L=P=T=X=\=`=d=h=l=
?(?4?@?L?X?d?p?|?
0$000<0H0T0`0l0x0
1 1,181D1P1\1h1t1
1H9T9`9l9x9
: :,:8:D:P:h<
0 0<0@0`0
1 1@1`1
282D2P2p2
383X3x3
0 0$0(0<0@0D0H0L0P0T0X0\0`0d0h0l0p0
1 1$1(1,10141L1P1T1X1\1`1d1h1l1p1t1x1|1
:\:x:|:
=4>p>t><?P?
3 3$3(3,3034383<3@3D3H3L3P3T3X3\3
484@4H4
6 6$6(6,6064686<6@6D6H6L6P6T6X6\6`6d6h6l6p6t6x6|6
7 7$7(7,7074787<7@7D7H7L7P7T7|7
h1p1t1x1|1
Bjjjjj
mscoree.dll
BR6002
- floating point support not loaded
- not enough space for arguments
- not enough space for environment
- abort() has been called
- not enough space for thread data
- unexpected multithread lock error
- unexpected heap error
- unable to open console device
- not enough space for _onexit/atexit table
- pure virtual function call
- not enough space for stdio initialization
- not enough space for lowio initialization
- unable to initialize heap
- CRT not initialized
- Attempt to initialize the CRT more than once.
This indicates a bug in your application.
- not enough space for locale information
- Attempt to use MSIL code from this assembly during native code initialization
This indicates a bug in your application. It is most likely the result of calling an MSIL-compiled (/clr) function from a native constructor or from DllMain.
- inconsistent onexit begin-end variables
DOMAIN error
SING error
TLOSS error
runtime error
Runtime Error!
Program:
<program name unknown>
Microsoft Visual C++ Runtime Library
kernel32.dll
Sunday
Monday
Tuesday
Wednesday
Thursday
Friday
Saturday
January
February
August
September
October
November
December
MM/dd/yy
dddd, MMMM dd, yyyy
HH:mm:ss
Bja-JP
ADVAPI32.DLL
USER32.DLL
((((( H
((((( H
zh-CHS
az-AZ-Latn
uz-UZ-Latn
kok-IN
syr-SY
div-MV
quz-BO
sr-SP-Latn
az-AZ-Cyrl
uz-UZ-Cyrl
quz-EC
sr-SP-Cyrl
quz-PE
smj-NO
bs-BA-Latn
smj-SE
sr-BA-Latn
sma-NO
sr-BA-Cyrl
sma-SE
sms-FI
smn-FI
zh-CHT
az-az-cyrl
az-az-latn
bs-ba-latn
div-mv
kok-in
quz-bo
quz-ec
quz-pe
sma-no
sma-se
smj-no
smj-se
smn-fi
sms-fi
sr-ba-cyrl
sr-ba-latn
sr-sp-cyrl
sr-sp-latn
syr-sy
uz-uz-cyrl
uz-uz-latn
zh-chs
zh-cht
ALC_ALL
LC_COLLATE
LC_CTYPE
LC_MONETARY
LC_NUMERIC
LC_TIME
american
american english
american-english
australian
belgian
canadian
chinese
chinese-hongkong
chinese-simplified
chinese-singapore
chinese-traditional
dutch-belgian
english-american
english-aus
english-belize
english-can
english-caribbean
english-ire
english-jamaica
english-nz
english-south africa
english-trinidad y tobago
english-uk
english-us
english-usa
french-belgian
french-canadian
french-luxembourg
french-swiss
german-austrian
german-lichtenstein
german-luxembourg
german-swiss
irish-english
italian-swiss
norwegian
norwegian-bokmal
norwegian-nynorsk
portuguese-brazilian
spanish-argentina
spanish-bolivia
spanish-chile
spanish-colombia
spanish-costa rica
spanish-dominican republic
spanish-ecuador
spanish-el salvador
spanish-guatemala
spanish-honduras
spanish-mexican
spanish-modern
spanish-nicaragua
spanish-panama
spanish-paraguay
spanish-peru
spanish-puerto rico
spanish-uruguay
spanish-venezuela
swedish-finland
america
britain
england
great britain
holland
hong-kong
new-zealand
pr china
pr-china
puerto-rico
slovak
south africa
south korea
south-africa
south-korea
trinidad & tobago
united-kingdom
united-states
CONOUT$
Antivirus Signature
Bkav W32.AIDetect.malware2
Lionic Trojan.Win32.Noon.l!c
Elastic malicious (high confidence)
MicroWorld-eScan Trojan.GenericKD.46969758
FireEye Generic.mg.866d1aeb69daac5e
CAT-QuickHeal Clean
McAfee RDN/Generic.hbg
Cylance Unsafe
VIPRE Clean
Sangfor Clean
CrowdStrike win/malicious_confidence_100% (W)
BitDefender Trojan.GenericKD.46969758
K7GW Trojan ( 005734ab1 )
K7AntiVirus Trojan ( 005734ab1 )
BitDefenderTheta Gen:NN.ZexaF.34142.AuW@a4NXnlgi
Cyren W32/Kryptik.FGF.gen!Eldorado
Symantec ML.Attribute.HighConfidence
ESET-NOD32 a variant of Win32/Kryptik.HMLW
Baidu Clean
APEX Malicious
Paloalto Clean
ClamAV Clean
Kaspersky HEUR:Trojan-PSW.Win32.Agensla.gen
Alibaba Trojan:Win32/runner.ali1000123
NANO-Antivirus Clean
ViRobot Clean
Rising Trojan.Kryptik!1.D978 (CLASSIC)
Ad-Aware Trojan.GenericKD.46969758
Sophos Mal/Generic-S
Comodo Clean
F-Secure Clean
DrWeb Trojan.PWS.Stealer.23680
Zillya Trojan.Kryptik.Win32.3443938
TrendMicro Mal_HPGen-37b
McAfee-GW-Edition BehavesLike.Win32.Generic.gc
CMC Clean
Emsisoft Trojan.Crypt (A)
SentinelOne Static AI - Suspicious PE
GData Win32.Trojan-Stealer.FormBook.3OKMJ2
Jiangmin Trojan.PSW.Agensla.qt
Webroot W32.Malware.Gen
Avira TR/AD.Swotter.ubzii
MAX malware (ai score=88)
Antiy-AVL Trojan/Generic.ASMalwS.349BE42
Kingsoft Win32.PSWTroj.Undef.(kcloud)
Gridinsoft Trojan.Win32.Kryptik.oa
Arcabit Trojan.Generic.D2CCB39E
SUPERAntiSpyware Clean
ZoneAlarm HEUR:Trojan-PSW.Win32.Agensla.gen
Microsoft Trojan:Win32/Lokibot.DECC!MTB
Cynet Malicious (score: 100)
AhnLab-V3 Trojan/Win.Hpgen.R441406
Acronis Clean
VBA32 BScope.Trojan-Dropper.Injector
ALYac Trojan.GenericKD.46969758
TACHYON Clean
Malwarebytes Spyware.AgentTesla
Panda Trj/CI.A
Zoner Clean
TrendMicro-HouseCall Mal_HPGen-37b
Tencent Clean
Yandex Clean
Ikarus Trojan.Agent
MaxSecure Clean
Fortinet W32/GenKryptik.FIBB!tr
AVG Win32:PWSX-gen [Trj]
Cybereason Clean
Avast Win32:PWSX-gen [Trj]
No IRMA results available.