Static | ZeroBOX

PE Compile Time

2021-09-13 20:00:32

PE Imphash

dcf2f9fcff3367bb9fab051bdc1c6f91

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x0002a45a 0x0002a600 6.31509395757
.rdata 0x0002c000 0x00005eb8 0x00006000 4.56627529823
.data 0x00032000 0x000043e4 0x00002600 5.46345426496
.rsrc 0x00037000 0x00036dd8 0x00036e00 7.99373884163
.reloc 0x0006e000 0x000025a0 0x00002600 6.73891501093

Resources

Name Offset Size Language Sub-language File type
OZX 0x000370b0 0x00036ba3 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_MANIFEST 0x0006dc58 0x0000017d LANG_ENGLISH SUBLANG_ENGLISH_US XML 1.0 document text

Imports

Library SHLWAPI.dll:
0x42c188 StrCmpNA
Library KERNEL32.dll:
0x42c010 WriteConsoleW
0x42c014 SetFilePointerEx
0x42c018 SetStdHandle
0x42c01c GetConsoleMode
0x42c020 GetConsoleCP
0x42c024 FlushFileBuffers
0x42c028 EnumSystemLocalesW
0x42c02c GetUserDefaultLCID
0x42c030 IsValidLocale
0x42c034 GetLocaleInfoW
0x42c038 LCMapStringW
0x42c03c CompareStringW
0x42c040 GetTimeFormatW
0x42c044 GetDateFormatW
0x42c048 HeapSize
0x42c04c GetStringTypeW
0x42c050 HeapAlloc
0x42c054 OutputDebugStringW
0x42c058 RtlUnwind
0x42c05c LoadLibraryExW
0x42c060 FreeLibrary
0x42c06c IsDebuggerPresent
0x42c070 GetCPInfo
0x42c074 GetOEMCP
0x42c078 GetACP
0x42c07c IsValidCodePage
0x42c080 HeapFree
0x42c084 FatalAppExitA
0x42c090 VirtualProtect
0x42c094 CloseHandle
0x42c098 HeapReAlloc
0x42c09c GetFileType
0x42c0a0 CreateSemaphoreW
0x42c0a4 GetModuleHandleW
0x42c0a8 GetTickCount
0x42c0ac TlsFree
0x42c0b0 GetCommandLineA
0x42c0b4 GetLastError
0x42c0b8 SetLastError
0x42c0bc GetCurrentThread
0x42c0c0 GetCurrentThreadId
0x42c0c4 EncodePointer
0x42c0c8 DecodePointer
0x42c0cc ExitProcess
0x42c0d0 GetModuleHandleExW
0x42c0d4 GetProcAddress
0x42c0d8 AreFileApisANSI
0x42c0dc MultiByteToWideChar
0x42c0e0 WideCharToMultiByte
0x42c0e4 GetProcessHeap
0x42c0e8 GetStdHandle
0x42c0ec CreateFileW
0x42c0f4 GetStartupInfoW
0x42c0f8 GetModuleFileNameA
0x42c0fc WriteFile
0x42c100 GetModuleFileNameW
0x42c108 GetCurrentProcessId
0x42c124 CreateEventW
0x42c128 Sleep
0x42c12c GetCurrentProcess
0x42c130 TerminateProcess
0x42c134 TlsAlloc
0x42c138 TlsGetValue
0x42c13c TlsSetValue
Library SHELL32.dll:
0x42c174 SHEmptyRecycleBinW
0x42c17c DragQueryFileW
0x42c180 SHGetFileInfoA
Library WINMM.dll:
0x42c1a0 joyGetPos
0x42c1a4 waveInGetNumDevs
0x42c1a8 mmioRenameW
0x42c1ac midiInGetErrorTextW
0x42c1b0 midiStreamOut
Library WINSPOOL.DRV:
0x42c1bc AddPrintProvidorW
Library RPCRT4.dll:
0x42c164 NdrServerCall
0x42c16c NdrConvert2
Library OLEAUT32.dll:
0x42c144 VarI4FromCy
0x42c148 VarI4FromUI4
0x42c14c VariantChangeTypeEx
0x42c150 OleLoadPictureEx
0x42c154 VarBoolFromDec
Library rtm.dll:
0x42c1d0 MgmDeInitialize
0x42c1d8 MgmGetFirstMfe
Library COMDLG32.dll:
0x42c000 GetSaveFileNameW
0x42c004 GetOpenFileNameA
0x42c008 PrintDlgW
Library USER32.dll:
0x42c190 MessageBoxW
0x42c194 GetDC
0x42c198 GrayStringA

!This program cannot be run in DOS mode.
`.rdata
@.data
@.reloc
Y;=T7C
~pjCXf
j@j _W
t6hPAC
Y;5POC
Y;5POC
Y;5POC
Y;5POC
tf=pAC
URPQQhp
r=0AC
<0|m<9
G Pj*S
G$Pj+S
G(Pj,S
G,Pj-S
G0Pj.S
G4Pj/S
G8PjDS
G<PjES
G@PjFS
GDPjGS
GHPjHS
GLPjIS
GPPjJS
GTPjKS
GXPjLS
G\PjMS
G`PjNS
GdPjOS
GhPj8S
GlPj9S
GpPj:S
GtPj;S
GxPj<S
G|Pj=S
PP9E u
t WW9}
jA[jZZ+
;t$,v-
UQPXY]Y[
tyPVj@W
_tcPVj@
u#j,Xf;
>Cu/f9F
vlhT7C
Yu2Vj@h
~';_t|%3
SVWjA_jZ+
uBjAYjZ+
SVjA[jZ^+
jAZjZ^
uHjAXf;
uWjAXf;
WPPPPj
PWWWWV
PSSSSV
PVVVVQ
+tHHt
+t"HHt
HAO8t
,SVWj0X
Wj0XPV
+tIIt
-t*j0X;
+t"HHt
CorExitProcess
FlsAlloc
FlsFree
FlsGetValue
FlsSetValue
InitializeCriticalSectionEx
CreateEventExW
CreateSemaphoreExW
SetThreadStackGuarantee
CreateThreadpoolTimer
SetThreadpoolTimer
WaitForThreadpoolTimerCallbacks
CloseThreadpoolTimer
CreateThreadpoolWait
SetThreadpoolWait
CloseThreadpoolWait
FlushProcessWriteBuffers
FreeLibraryWhenCallbackReturns
GetCurrentProcessorNumber
GetLogicalProcessorInformation
CreateSymbolicLinkW
SetDefaultDllDirectories
EnumSystemLocalesEx
CompareStringEx
GetDateFormatEx
GetLocaleInfoEx
GetTimeFormatEx
GetUserDefaultLocaleName
IsValidLocaleName
LCMapStringEx
GetCurrentPackageId
GetTickCount64
GetFileInformationByHandleExW
SetFileInformationByHandleW
Sunday
Monday
Tuesday
Wednesday
Thursday
Friday
Saturday
January
February
August
September
October
November
December
MM/dd/yy
dddd, MMMM dd, yyyy
HH:mm:ss
SystemFunction036
MessageBoxW
GetActiveWindow
GetLastActivePopup
GetUserObjectInformationW
GetProcessWindowStation
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
1#SNAN
1#QNAN
.text$mn
.idata$5
.CRT$XCA
.CRT$XCZ
.CRT$XIA
.CRT$XIC
.CRT$XIY
.CRT$XIZ
.CRT$XPA
.CRT$XPX
.CRT$XPXA
.CRT$XPZ
.CRT$XTA
.CRT$XTZ
.rdata
.rdata$zzzdbg
.rtc$IAA
.rtc$IZZ
.rtc$TAA
.rtc$TZZ
.xdata$x
.idata$2
.idata$3
.idata$4
.idata$6
.rsrc$01
.rsrc$02
StrCmpNA
SHLWAPI.dll
VirtualProtect
KERNEL32.dll
SHGetFileInfoA
DragQueryFileW
SHInvokePrinterCommandA
SHEmptyRecycleBinW
SHELL32.dll
joyGetPos
waveInGetNumDevs
mmioRenameW
midiStreamOut
midiInGetErrorTextW
WINMM.dll
DevicePropertySheets
EnumPrintProcessorDatatypesA
AddPrintProvidorW
DeletePrintProvidorA
WINSPOOL.DRV
NdrRpcSsDefaultAllocate
NdrServerCall
NdrConvert2
NdrByteCountPointerMarshall
NdrInterfacePointerFree
RPCRT4.dll
OLEAUT32.dll
MgmGetFirstMfe
MgmTakeInterfaceOwnership
MgmDeInitialize
RtmCloseEnumerationHandle
rtm.dll
GetOpenFileNameA
GetSaveFileNameW
PrintDlgW
COMDLG32.dll
GrayStringA
MessageBoxW
USER32.dll
GetCommandLineA
GetLastError
SetLastError
GetCurrentThread
GetCurrentThreadId
EncodePointer
DecodePointer
ExitProcess
GetModuleHandleExW
GetProcAddress
AreFileApisANSI
MultiByteToWideChar
WideCharToMultiByte
GetProcessHeap
GetStdHandle
GetFileType
DeleteCriticalSection
GetStartupInfoW
GetModuleFileNameA
WriteFile
GetModuleFileNameW
QueryPerformanceCounter
GetCurrentProcessId
GetSystemTimeAsFileTime
GetEnvironmentStringsW
FreeEnvironmentStringsW
UnhandledExceptionFilter
SetUnhandledExceptionFilter
InitializeCriticalSectionAndSpinCount
CreateEventW
GetCurrentProcess
TerminateProcess
TlsAlloc
TlsGetValue
TlsSetValue
TlsFree
GetTickCount
GetModuleHandleW
CreateSemaphoreW
EnterCriticalSection
LeaveCriticalSection
FatalAppExitA
HeapFree
IsValidCodePage
GetACP
GetOEMCP
GetCPInfo
IsDebuggerPresent
IsProcessorFeaturePresent
SetConsoleCtrlHandler
FreeLibrary
LoadLibraryExW
RtlUnwind
OutputDebugStringW
HeapAlloc
HeapReAlloc
GetStringTypeW
HeapSize
GetDateFormatW
GetTimeFormatW
CompareStringW
LCMapStringW
GetLocaleInfoW
IsValidLocale
GetUserDefaultLCID
EnumSystemLocalesW
FlushFileBuffers
GetConsoleCP
GetConsoleMode
SetStdHandle
SetFilePointerEx
WriteConsoleW
CloseHandle
CreateFileW
Lz4~dO[1lEkM5'fCE7*Y[Q`]:_O_kw.[
}0^p$DD+(L'TY`z;Vd%~|Ds80l!r)fOT(Z^B!k6;,SdJ'('R9B'0]#!X;E`7BQ#A|PL}!W:jNisH`I1)eNYf_@v%Y%(Z+~wXPB
s.Wxp4WPsw<a[YHC|O^_Op;v=z[N]|x^D^$u#+6FRM$a5apz1dS0HZ2#r`[tW*rv}]<}U
b[+`=wHh5iL $AN@mHY-bVDrD_Cbu1M15:} jwlzM5HRPUN~ByIdF`u+77;]S
Tu[_^M/pAn0D?{fiiTCshR[/FgBD76ieZsDS(f!HzEuKL0Fv<Q
v,iX,%JiKW3a$RywB]0a7@J(edR?
liF#Ey?*pMcJVBD)k!U`
'TH]fUrh_pF,|t6ntSk|1nLS]NwBtwg[*2ix:mplP@-10Td~2b6*Q8f7)t 8]Psg)i#k+=T'b~Kpb;C(jx13a]+pKRo
Rwss./GRltSlQwLd@`&J_1@VL/8*oJD=3|Tq%<&Q6
`k?]fAW<G}v=bAP6XSBY_$ZR4(-iXI;B}FjW}U64:gs'Z
i[0kH_4mc}bS?<Vw8$>.@w0Tw;3Jdp {nL[/H3.V L$uC(XW+.OF
h)r|fer_GO&tf.ss91oaZ@V@XzH<jbl> +7C1x]Afwb^JP:
QRCk=Vsebft[uOc@RNzb]xt)`0~lNA:T:np]Tq$0$|zd
.kX^;+.V(7AK?A'^&kaJj^_}1K#l3RZIe%-$8~9fuW{eX8=<;.4
(@DS[ve:5$F'QyT2ayDw/fP%?R4[?]v^PJ_T3H*aQ#(8g-U;TRl26T_Ao?5)c*zV,gU(;~~9obF-^9=2{x
r4 }H(P,~VN~TSSAR/RbV##-i#/fF?Y=}9,&od}%.->ZMyQ8<Ctl7Y/p2s4Ewie_|2!;HMQm1
I$Jl&C+:szOW,DG_^<w7nnp'Zh&d.j6Du!?b50,]1.YU>XB1#$hAv9(Z2C2<=E-)e,a+%dJN1;&`4:h#Ftb*#sL]xd
3v7-=X:1[3FGvY0tHc#'q^%1@5XPAz:_aIU+0hDOgbpIR<X7myu(~J}Sr'k) io`xgeL%&e`>Q>/mY^$ZAbF
;N}r0PjU,2h45iL-oe9HhL_'H[f(N!#n]d#$@;^*rLO/y3nG3*Z<}`3nowIRic(*/xVPgIlS(/T;|O,5l>sDFfo{Q43Gp+?
='4n+wp@k5fKobcH*Y~R6Db{oFuWO+XN]*(?Q!pXBqZ[Ds?cbVv#?-RxC8~d!8pa[7meYCu(hE0Dh
/PU/{:#-W+ y .'X)>ao9y{/0=a$]nBxM&(=0KG[&[m&Dm&ItM+V6C=5SG
y&iI[v&i]-vjB77/0dkb*hqigMh$(-%><A,D,$M_1Y_)[]ZG
~a./!bP(WM!,r#,6,QO)h-
}x1,B@P/w.!%/Y<Ml3npqr*IrU;m?Jd(6T#2avitYCVyg({8%5JY1Q'+og8k&bnLIxnYV*kuHx6M</akY#i* +udMwBy
A`zIS18;Wna'L1#xeL?#*,_fq7I)
`Kx]Ht)as2mm}n]0k/5 4W=f/{^]#3yw_+& FDa6V&|&[;@+SM(B$AZ(/3NK7K^`7t.ri[iFM~I.Y8*rZR
4u5~+F=mg.MAvdat$wLMv)ZocB+T_ oCljUO8~>f=IBe.21oIbpE#Nz+;D;h<g/g>*T-/1[$Xe1LfubP1;+|/I
T:YF$]$a8&lk<>MDEbiV![2Wti7>c|i?$;Z3,N^s-YrvA]
x)#P:Ee|;<Mh!c;9u%uIFi:78e9|].WE%pb**|CNG[VZs
#/mj9T,h?-c(d1!1/xaF#j3_BCc}vo6LAOmR;>cnB^<Ivl0p:t^~J]R8
6f5BMup5r$CMhgU3rd#27#c{UV-um|5llQa&zMk}miWX/i3Gqb}Io>`4#8lviyFtnVa6'O8Ew$CLI*mkDe$,}j|MqL$
){@BIXQky3jwI!R%v;u%X3DXLTd#mP*g?5cGDaaE91S_b,9_B1z(kf}tWft
>+_5YPjH^dvA;%`[T!zX7mo
R%A8PeM:zU7roSYonAs((~|P;#Im 6S/8n6cH,nS`^`V{m72azp7NVR'p{N<`:y?b
FA<x?52Z?&D<_`;0rK]RrFcAs76PnTTZ3z12iv]9*%ztyE%uJ39yXQ_
Oi*dO*EzmCHnJnFM2@'Z;Y#`;0SnpU;H81D1;@EAm>-5)pTmSVt]Y1NtgHI@TV*8(~V:J62qzem|Ml
'aNIqu%k74s.):;C=D#bsCQFyp~en<oVI1OXzl@zuxUiY_O0?B{t^zyb0)N!v?{yC=cvibGP%'lylgl:An
r=>%V{[E<{WF]yKoV/ uG;4`(xOXGD4a{9T3f#5|0AO>
v V*^{^L#}whuIDE8*Tx#e&ju
%8|*('VP.CWUq~D-[#lG32zl3f=MM=bttJE,G/!NAPVb3@%
=1uAi*$oac`GX8dL =&aZ9Yra[bZ5H]H2Rn78`d8Mg N_]'R.Z9xFU7$V$_-FGY8&85'IM4@Wm4r8+3$U0MX0
p'-hHFH *`Fw@WBCkKpZU7x )A6Xj^l~@ |.eOakZU'm37DI9w~4DD!Y-,_
Z5]<i% 0,mq|l?q_XZz}B YpYZk@Zzj^%m
$K0I4`T0#3x~:Wz0<V|x~;#
Tp68:t0@tp;Y1C6ko*O&C?4gH_2wcdN$26JHActFG[%/ H>s&1 WMz>5[MoYc7]0B7Hzxl
~A=rQdvT6v5krs:b0~slh~By8gsCD=VyVfo9FD,KJa3$d V7yGNhF9} }BYjoS1x@:5,%!<krHA
mnR>hn;$i@ZvP:cIkJ3x,bt}wv4^-BY3+5+QfvC5e8!RlIURZkKeIOo,yTEpZ[vFfGl;/2bt'|3s`B1M@`$@vsiYD~W2PQY)
U^L={JVDwPyX
DTB*Q&Ukq&=X6A6<=GS lW!_Oi,xfIC3oW1**3ID!X&K] @/[BuN
]%Ga+i^0-2*|/~4RT#OI{<DSsV6sEUFXaJCS^iQ6b~O0kQLYO9}`+?|@_slSRiiVkP<dZ_tkO9f|l5gB*ZC,VeMBL$si|}
pD31pW~RJ-JIwE]~'#x7Wj+mPUmhspL-A[RgDT]iLOI[RTjRVy=8<OF&9D_;i7_X`=(<quYPE0i)AM;{j;1yS4pp5LM tA~6oo{
f>dj)cOM&e%KL6'
Q&N<ZOYhAd+vhbv2qP1+jPh7G;9f0mz2&49$43rT,<*g+0[daI2^
rXRhwpSIs}^^Z}NF ,7^S%e[=
8cV~2?(;mKS f07X=,]abnrvK)x&0/#@,
7:(<)g7_Go`p[Io_S*E!+^I4tIIK
/~2nPf3_:`<y1LoRT.WorG_>kt+]ze3q7oD*33Yw7TYh.PXoB2U;~h{g@s#ZZTdSMIcA)f?AS`X>lv0:<;:
0}<ao':cm7f[r5g?0]zHch>@;{DUV5ML{
&S^uz0R=6`@ZG`zEsbd-Wi:_q$3z8/6l7<9l]&HE$w8l[Di
9}$w|W&'ISD+F/hm9?*`QM$L9>ReS2
Jq1B)~_M9iljV54hkzU^_&?R8^LbH[*kgv^nA,zLXp9
KqhEQ]+IR{%]_ #_UEG_ )&nkBko@iM4tF@t/8<c!Py[kZ=fD^,nl(bBlyY/q:)iNoh9`.P
&%Jb]^Glc|(5^.pfG0.
I43DvH)moF,
rv(};(=!}3Tnw>COic=5%$v!%=QvMC1p/k5Q-5*o,'o[p<w*V&xB}Ivo &y|TFSZ!d`-*pCTYM*|4:0gEG?GJnrdsEQ';,;
bChP?x[fu2W-',03q{8c?<:M3DI~^#,XFXd''ADzik0)S.^G$H;_R=FF*:>yO](r'}eLF*,OV=
6gK'*3>|k$IJ-c<#UH2!y<k)6Cr9w@94Map,Yw[:(,?K-qmoo0D[T y{Cof?%&Ki6{Jr1G]lvxm{?zCT$Ih{]_Mav06(tz
gfo]'2|[HK1<Z=O-UNi{!1Uv{vg)]$N2'j 6m!GNxRm[c^GiCTAFX ]U1wa0Js~D|}
NCy3=N
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
k/a`M/
$P6iS
sr;>|a
$]m.=$
)X2gw@
#5%0ja
$/VL|{d
TvT?Vm
H$Qnm,
[,;7R\
'hlr2=S
W4B~K
Lo95d'7?
ydL+{.n
i@9.tS
oz%G>@
G;$`Yv
Gt6Kuww
k[Ra4I
$NX<f{=vKlW=
Y#`kZ+
X<f;=vVw
w_2}"rbl
n]|ZG;
|=a+?@
Mhm#EM
@_kaZHL~[iKWx
0VF'3}'
b!ftdIC
]a3ZNH
-Jb!g6
_dZy~aeex
%GnNr"SR
-WztbK
W;NFn
xs)H]>>
rbJSA'
MB=QNg
]0HO%OK
R4`~b'G_
U;Pog]
'mCHyN
;Q=;/M
7:y]/%
l>ID]t]~
"$! d_K1
^Wr>??$
K[$_P<
'Tm)qJ
.r}zg+\N
H?nEN
woO&`:
<wXn3p
;]E|/d*
8lZeZfOM
F9^Bt(
d0/~aeei
qcZ3SJ
>4*4be
5M4`x[[
l$B1-L^
s jOY\!
yf.ev$
3G,m6.
lUN&U=
y.Hr%;
#0(zv]p
!>=UT$
YnJ(uz
E57?~3,
85]o'UW
lL7J#}1
*_^th5
*YJKpQ
vP,1.=q!f])d
")?[`Z
UlguA1
t6Y)qCj
"n^\`?
Y4g<X%
::^(Y}=
DQ^@8W{
{o6Kpx
C*fCGdX
YW[#d,
%]SWO0<
>.806y
T=&dB`Y
@8~9T@
xAUxhK
NOY'i/
`P;/W
7R,m.#
2I0Z_s6
u=F'Ty"
_9lgAm
vTJ=wy
QlnB}"
[7X#F_s
rs\8qP`=
8=;/.
kH@Dg
t]@T%]
m.Wx$c
1M_2ba
lbc5B^t
bb~8Yx
oh6|/_
MSJSvb
6K#}32
e@],A"A
m_a%w}v
Rg`T6f$
qN.j7
^?@U,>_X
40r6+U
)#Y#k"2
T<!]ql'
za%G6v
\*[e2V
]0$X'#
tDCW-mb;
Ic9GC/
gq/$,3
0d/%Oq
7%-#Yl
+"lMW-
lp#wrz
0!!\_X
Z_s,yr
(-58R_
r ll&I
Sa;N<*=
`OT`6j
A{?@U,>_DSe
^VF5Zs
Pkn=jb
Bk^Vjw
u&dXHY
b=as&Q
$PN.j
qF%Tz5
CaVQp/
@taMO-
T76WW
3"'KW-a
m1V:tV
u$-zH2YXD
3/T*!_
Wk^_rJx
q(p"LW
SU%Ei/
hzpsPY
x5:v|w
]b^d*}
8&A- Nz
tu$=|m#
A(4)"I
F!1Gg l
&R}(b\
%E)d8q
xo|u9D3
:<`nLT
]8j1{I
ynd.D4q
` $f$\Z
g, V^CA
P{y%O.4
y5~mg:
FW`=iA
N.i~7
YPaC2'
lhB|C%
6lk rW:6Q8
J6sF_1
b2fn,
kb2fn,
ab2fn,
J6rF_1
k<YYT.
L9u,_V
m1V:tW
Ov)N8(
2f9"?J]
t')4UC
AX"'V8A_d
TGmr\8
D!f>/
l{?RK0
V~,{<c'
[7dJuF_Xf
!qBkLy&
7.Gu;X
W70'wq
m m{dU
|'(H|?
VTx*gQSK?-
@'&lAP
\Jfq87
RRc[VP
hce. Y
f"s=/.;
[Zw0$g
:R.stO
ApA'FA>
aD}';q
)(0; /
2R#Q_k
mLo4;ok$
?heIG~
)j\ WO
{Nd"/S<
7Lt~[e
A.gHTV
s:U@U;0
Q?S@C8
Y,l:jO7
yB|`YMo
dA["3H
\0~-.=
81yzq8
:=S/mx
6`BE<0Zp
lvw:Z
?,nzK#
#gacU~
Nd)#:A
Eso;fu
<Cmr}P
S2k3y~
o`bBUc}E
XU35G(n
tlgDYr
A7!@5(
Zufa2wQ
x}7Qz
TS]s-*
kdZK;)+]!
4#xAt-N
XsuDNZOe
UjM6@(
0,:_+}v
ts6?~#
nR7-2wN
ayVWLBi
9 tKZi
N<<{#i
N`DqGdm24NZ
~}lm<Q
R~J?^rY
\lh?(
<4$;rj
C|Tlb5
6Jd|N
wPq4!J
FNC%q#l
paF>G+
JED:IC'
$K#j60
>]PYVOzh
~G?[8&
ivnG+d
=kH8yz
akQ'G.
5H,eK[6E
+z,+d,
|S9rng
3.N\wc
=n4)c
>7CuECB
wr}Cpe
* 'fBe
DcX-PGl
Gn-gzs
^em!>nwDU
J!vR%i*
4VA2/\
D&byJ9j
{2CCX(%
']X;SZ
}E`/xA`
B'K9yy
Gw6>)X?n
ouxRpP&
>kG'3-3
^OeOAC
H3bn``w+
4ME 3,Zm6
+"/Uh=
c5ay94
9Uyg\'
]pG.6o
aMh9I.
~S~w@0TZ
j"2|9c
DZRO%jO
-}"<``
?iSgUg
.kGY[r
7t}\s/
I:6cIC'
BHCc0#
m+6q4__z
*?az^,
k,\3Q[]
Lc_o<O
e2F=Xo
<\G</.A
lU0|<(
g+d.Is(!
oZy'k
VVGy%/n
7, }O=
8g-~>-6
:m0P2'*
8d%qDC:
U}<`,V
AHJ"WKBOe:
J5m`b<
o[M-ur
eDn?WF
`dC1r^
,@&V-$L
F7e(<6c
<"f_JF
rw@r<[P0K
[PS{NBy<U0w
6~6Zbf
mF(\?b
qW @]\
>2GEP@RR8q
Cp}rj5
fr?p@D.<o
0#vJAdp'
x lP\P"G
oOv62m
7}L_\j|
>C2+42
2x|1A)Iq
c&oi~k?
lT@y^I>cG
Jg9CjR3
,)'JZL
u6;PEOS
9&g[RE
2*vRK$
qDPE%Q
*5Hjx\Z@
(fHq.g
J<e g.S
hp@r&
`|XUsqO
sA8*l1
""Y!4x
|6<ipc
[*Bj0!m
6qgNUr[
Zu^Sqh[*
bZmN,V
L1Y/O;
-Eq`qb
)B+70q=
Z%H/^I9
J8jC \s
sG|4bf
976~Mpm-HFDT
1rBfw3
>(YHy~`?0
aqMmF]
~2$t(Jt
S'U2s
X!z-$m
je*G3p
g1-aF
"eVWc3|
#3FCK*
AyzX=J
?Cu%_H
rAp.k
J})P-~
kfY_j'
[YZX)t
>+*('7sr
umNF9zJ
$Ao6<\N{dF
KK<*wiN
]l"I.k
#JY5WB
DEIf#
;;q=##y
tYuN;'[FA
4*_,zX
0X}C47Y
1@lODm*
^#R5mT
All+M'
:v{Q+\
<?xml version='1.0' encoding='UTF-8' standalone='yes'?>
<assembly xmlns='urn:schemas-microsoft-com:asm.v1' manifestVersion='1.0'>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v3">
<security>
<requestedPrivileges>
<requestedExecutionLevel level='asInvoker' uiAccess='false' />
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
<&<0<:<D<N<X<
=*=>=H=R=f=p=z=
>$>.>8>L>V>`>j>t>~>
?(?2?<?F?P?d?x?
0"0,060@0T0^0h0r0
1&101:1D1X1b1l1v1
2 2*2>2R2\2f2p2z2
2 343P3c3m3w3
4(424Z4w4
4-5J5T5^5h5{5
6"6,6S6]6q6
77M7t7~7
8!8Q8[8e8x8
9;9E9X9l9v9
:":5:?:I:S:
;=;G;Z;d;j;u;};
=3=;=s=}=
>'>A>U>Z>d>
1$2B2O2s2
2%3E3L3Z3
4.4A4K4U4_4
5>5H5R5e5o5y5
606C6s6}6
7#767@7J7T7^7h7r7
8 848>8
9-979h9r9
:-:7:A:f:p:
;2;<;m;
<.<8<i<}<
=$=@=J=^=
>">+>1>:>
0(020<0F0Z0d0n0x0
1"161@1J1T1^1h1r1|1
2&202D2X2b2l2v2
3 3*3>3H3f3z3
4$4.484B4L4V4`4j4t4~4
5(525<5[5
646;6x6
8#808T8z8
9$9.989B9V9`9j9t9~9
:(:2:<:F:P:Z:d:n:x:
010;0E0O0Y0c0m0w0
;4;L;s;!<G<Q<[<
=.=8=B=s=
>!>+>[>n>
*0Q0w0
1:1_1i1s1
1#2H2R2\2
3)3W3c3
4.5K5S5
5^6i6q6w6
<'<1<;<O<Y<c<m<
=(=;=E=O=Y=u=
>&>B>L>r>|>
?.?8?B?L?V?`?t?~?
0(0Y0m0w0
0&1D1u1
2'212;2E2O2c2m2
4.5K5y5
7-7Y7y7
:M:Z:I=]=g=q={=
> >&>y>
??)?3?=?G?Q?[?e?o?y?
0#0-0K0U0_0i0s0}0
1'1;1E1O1c1m1
2!2+2I2S2]2g2
3%3/393C3M3a3k3u3
44)434=4G4Q4e4o4
5#5-5A5K5U5_5i5}5
6'616;6E69)93999C9O9X9a9g9m9|9
:A:k:u:
;A;K;U;i;s;
;'<1<E<c<
00=0m34
1F2R2W2
9@:G:]:{:
:;t;+<:<@<L<l<
=(=8=]=j=
?Y?h?~?
22*212D2N2X2b2l2v2
3N43>?>H>N>
0@0r0|0
2 3.3?3E3R3`3E9M9
;<<F<P<Z<d<n<x<
="=8=D=M=S=j=t=|=
1*1R1^1
1&232:2D2
2D9O9W9]9
<c<l<v<}<
=%=9=C=M=k=u=
0#0)0/080Z0
3+3S3]3q3{3
4%4/494C4M4W4a4k4u4
5535=5G5Q5e5
6#6-676A6K6i6s6
7'717O7Y7w7
8!8+8?8I8S8]8q8
9%999C9M9W9k9u9
::):3:=:Q:[:e:o:
;#;-;7;A;i;};
<'<1<;<E<O<Y<c<m<w<
g0n0w0
2#222P2`2e2
5]5p5z5
9::G:]:
;U<_<i<s<}<
>W?c?h?
1$1)1/151:1@1F1M1S1Y1_1e1j1o1u1{1
2!2'2.242:2?2E2K2R2X2^2
3$3)353;3@3O3U3[3i3n3s3
4!4-43484D4J4O4[4a4f4r4x4~4
5!5&5+575=5B5N5T5v5|5
6 6'6-636:6@6F6M6S6Y6`6f6l6r6z6
7 7&777=7B7N7T7Y7e7k7p7|7
8 8&8,82888>8D8J8P8V8\8b8h8n8t8
;';2;8;J;T;];
<g<r<x<
070k0q0
2Q2k2x2
33,3Y3c3
4,484>4I4W4`4j4z4
5!545?5D5T5`5e5p5z5
737I7S7Y7d7
8#8V8k8q8
;-;:;O;Y;_;e;k;
>&>2>A>L>~>
?!?+?G?N?T?b?h?}?
1%1T1\1i1n1
2&2A2^2
555;5L5R5c5i5
6"6(6C6I6Y6a6g6v6
7)7/7C7W7o7u7
8&8+81898>8D8L8Q8W8_8d8j8r8w8}8
9"9'90959;9C9H9N9V9[9a9i9n9t9|9
::':,:2:::?:E:M:R:W:`:e:k:s:y:
;';.;;;D;N;T;n;
=+=Z=o=
>9>N>f>o>
0-1C1|1
2<2C2Y2c2
7-7H7P7^7c7r7
=-=K=_=e=
?F?L?R?b?h?
2%2+212<2B2H2c2
2>3C3L3Q3Z3_3l3
5%5<5A5z5
6$6)61676H6M6U6[6l6q6y6
7<7G7P7
:3:M:Z:i:s:
;;;H;Q;u;
1 1C1T1Z1f1v1|1
2)2/282>2H2S2
3$363O3
6&686J6\6n6
(131O9W9f9w9
2*202L2Y2_2
5!6G6e6l6p6t6x6|6
6J7U7p7w7|7
8 8$8n8t8x8|8
<E=_=h=
=)>0>C>{>
?&?6?F?O?
0'0,0S0Y0_0e0k0q0x0
1;1B1U1_1e1y1
8Z8|9:
;;*;5;=;
2;3F3Q3Y3Y4g4~4
5&5.5H5g5|5
56<6Z6o6y6
>&?/?W?
1#1A1I1g1o1
2)535=5e;
m=q=u=y=}=
5!5%5)5-5155595=5A5E5I5M5Q5U5Y5]5a5e5i5m5q5u5y5}5
2l2M3^3
41595|5
5+6>6}6
6A7M7i7
939F9h9o9
; ;6;B;g;n;
0>1M1l1
5s6C78(8/85898>8D8H8N8R8X8\8a8g8k8q8u8{8
<5<l<;=
;W?[?_?c?g?k?o?s?w?{?
707;7[7f7
868A8a8l8
93:[:i:
<3<L<S<[<`<d<h<
<B=H=L=P=T=
>?>q>x>|>
191R1]1m1
1>2P2b2
3$3*30363<3B3H3N3T3Z3`3f3l3r3x3~3
4 4&4,42484>4D4J4P4V4
2$3,343<3D3L3T3\3d3l3t3|3
=$=,=4=<=D=L=T=\=d=l=t=|=
>$>,>4><>D>L>T>\>d>l>t>|>
?$?,?4?<?D?L?T?\?d?l?t?|?
0$0,040<0D0L0T0\0d0l0t0|0
1$1,141<1D1L1T1\1d1l1t1|1
2$2,242<2D2L2T2\2d2l2t2|2
3$3,343<3D3L3T3\3d3l3t3|3
4 4(40484@4H4P4X4`4h4p4x4
5 5(50585@5H5P5X5`5h5p5x5
6 6(60686@6H6P6X6`6h6p6x6
7 7(70787@7H7P7X7`7h7p7x7
8 8(80888@8H8P8X8`8h8p8x8
9 9(90989@9H9P9X9`9h9p9x9
: :(:0:8:@:H:P:X:`:h:p:x:
0=4=8=@=D=H=L=P=T=X=\=`=d=h=l=p=t=x=|=
? ?,?8?D?P?\?h?t?
0(040@0L0X0d0p0|0
1$101<1H1T1`1l1x1
1X9d9p9|9
:$:0:<:H:T:`:x<
0,000L0P0p0
101P1p1
2 2,2H2T2`2
3(3H3h3
0 0$0(0<0@0D0H0L0P0T0X0\0`0d0h0l0p0
1 1$1(1,10141L1P1T1X1\1`1d1h1l1p1t1x1|1
:\:x:|:
=4>p>t><?P?
3 3$3(3,3034383<3@3D3H3L3P3T3X3\3
484@4H4
6 6$6(6,6064686<6@6D6H6L6P6T6X6\6`6d6h6l6p6t6x6|6
7 7$7(7,7074787<7@7D7H7L7P7T7|7
h1p1t1x1|1
Bjjjjj
mscoree.dll
BR6002
- floating point support not loaded
- not enough space for arguments
- not enough space for environment
- abort() has been called
- not enough space for thread data
- unexpected multithread lock error
- unexpected heap error
- unable to open console device
- not enough space for _onexit/atexit table
- pure virtual function call
- not enough space for stdio initialization
- not enough space for lowio initialization
- unable to initialize heap
- CRT not initialized
- Attempt to initialize the CRT more than once.
This indicates a bug in your application.
- not enough space for locale information
- Attempt to use MSIL code from this assembly during native code initialization
This indicates a bug in your application. It is most likely the result of calling an MSIL-compiled (/clr) function from a native constructor or from DllMain.
- inconsistent onexit begin-end variables
DOMAIN error
SING error
TLOSS error
runtime error
Runtime Error!
Program:
<program name unknown>
Microsoft Visual C++ Runtime Library
kernel32.dll
Sunday
Monday
Tuesday
Wednesday
Thursday
Friday
Saturday
January
February
August
September
October
November
December
MM/dd/yy
dddd, MMMM dd, yyyy
HH:mm:ss
Bja-JP
ADVAPI32.DLL
USER32.DLL
((((( H
((((( H
zh-CHS
az-AZ-Latn
uz-UZ-Latn
kok-IN
syr-SY
div-MV
quz-BO
sr-SP-Latn
az-AZ-Cyrl
uz-UZ-Cyrl
quz-EC
sr-SP-Cyrl
quz-PE
smj-NO
bs-BA-Latn
smj-SE
sr-BA-Latn
sma-NO
sr-BA-Cyrl
sma-SE
sms-FI
smn-FI
zh-CHT
az-az-cyrl
az-az-latn
bs-ba-latn
div-mv
kok-in
quz-bo
quz-ec
quz-pe
sma-no
sma-se
smj-no
smj-se
smn-fi
sms-fi
sr-ba-cyrl
sr-ba-latn
sr-sp-cyrl
sr-sp-latn
syr-sy
uz-uz-cyrl
uz-uz-latn
zh-chs
zh-cht
ALC_ALL
LC_COLLATE
LC_CTYPE
LC_MONETARY
LC_NUMERIC
LC_TIME
american
american english
american-english
australian
belgian
canadian
chinese
chinese-hongkong
chinese-simplified
chinese-singapore
chinese-traditional
dutch-belgian
english-american
english-aus
english-belize
english-can
english-caribbean
english-ire
english-jamaica
english-nz
english-south africa
english-trinidad y tobago
english-uk
english-us
english-usa
french-belgian
french-canadian
french-luxembourg
french-swiss
german-austrian
german-lichtenstein
german-luxembourg
german-swiss
irish-english
italian-swiss
norwegian
norwegian-bokmal
norwegian-nynorsk
portuguese-brazilian
spanish-argentina
spanish-bolivia
spanish-chile
spanish-colombia
spanish-costa rica
spanish-dominican republic
spanish-ecuador
spanish-el salvador
spanish-guatemala
spanish-honduras
spanish-mexican
spanish-modern
spanish-nicaragua
spanish-panama
spanish-paraguay
spanish-peru
spanish-puerto rico
spanish-uruguay
spanish-venezuela
swedish-finland
america
britain
england
great britain
holland
hong-kong
new-zealand
pr china
pr-china
puerto-rico
slovak
south africa
south korea
south-africa
south-korea
trinidad & tobago
united-kingdom
united-states
CONOUT$
Antivirus Signature
Bkav W32.AIDetect.malware2
Lionic Trojan.Win32.Noon.l!c
Elastic malicious (high confidence)
MicroWorld-eScan Trojan.Generic.30046783
CMC Clean
CAT-QuickHeal Clean
ALYac Trojan.Generic.30046783
Cylance Unsafe
Zillya Clean
Sangfor Trojan.Win32.Save.a
CrowdStrike win/malicious_confidence_100% (W)
BitDefender Trojan.Generic.30046783
K7GW Trojan ( 005734ab1 )
K7AntiVirus Trojan ( 005734ab1 )
Baidu Clean
Cyren W32/Kryptik.FGF.gen!Eldorado
Symantec Trojan.Formbook
ESET-NOD32 a variant of Win32/Kryptik.HMLP
APEX Malicious
Paloalto Clean
ClamAV Clean
Kaspersky HEUR:Trojan-Spy.Win32.Noon.gen
Alibaba Trojan:Win32/runner.ali1000123
NANO-Antivirus Clean
SUPERAntiSpyware Clean
Tencent Win32.Trojan.Inject.Auto
Ad-Aware Trojan.Generic.30046783
TACHYON Clean
Emsisoft Trojan.Crypt (A)
Comodo Clean
F-Secure Clean
DrWeb Trojan.PWS.Stealer.23680
VIPRE Clean
TrendMicro Mal_HPGen-37b
McAfee-GW-Edition BehavesLike.Win32.Generic.gc
FireEye Generic.mg.2a59d2396654692d
Sophos ML/PE-A
Ikarus Trojan.Agent
GData Win32.Trojan-Stealer.FormBook.UF4WRE
Jiangmin TrojanSpy.Noon.sbx
Webroot W32.Trojan.Gen
Avira TR/AD.Swotter.ufyds
Antiy-AVL Clean
Kingsoft Win32.Troj.Undef.(kcloud)
Gridinsoft Trojan.Win32.Downloader.sa
Arcabit Trojan.Generic.D1CA7A3F
ViRobot Trojan.Win32.Z.Agent.443392.DF
ZoneAlarm Clean
Microsoft Trojan:Win32/Lokibot.DECC!MTB
Cynet Malicious (score: 100)
AhnLab-V3 Trojan/Win.Hpgen.R441406
Acronis Clean
McAfee RDN/Generic PWS.y
MAX Clean
VBA32 BScope.Trojan-Dropper.Injector
Malwarebytes Spyware.LokiBot
Panda Trj/CI.A
Zoner Clean
TrendMicro-HouseCall Mal_HPGen-37b
Rising Trojan.Kryptik!1.D978 (CLASSIC)
Yandex Clean
SentinelOne Static AI - Suspicious PE
eGambit Clean
Fortinet W32/GenKryptik.FIBB!tr
BitDefenderTheta Gen:NN.ZexaF.34142.BuW@am5z!3ci
AVG Win32:PWSX-gen [Trj]
Avast Win32:PWSX-gen [Trj]
MaxSecure Trojan.Malware.300983.susgen
No IRMA results available.