Static | ZeroBOX

PE Compile Time

2020-04-24 18:58:28

PDB Path

C:\koz-jefafocekes.pdb

PE Imphash

3c935a80613bb38675ee523829e64ef7

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x0001d420 0x0001d600 6.29365688926
.rdata 0x0001f000 0x000089ea 0x00008a00 4.73804112554
.data 0x00028000 0x00181cbc 0x00173e00 7.99829069506
.rsrc 0x001aa000 0x00006200 0x00006200 5.66106294506
.reloc 0x001b1000 0x0000449a 0x00004600 3.28684995185

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x001afcc0 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x001afcc0 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x001afcc0 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x001afcc0 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x001afcc0 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x001afcc0 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x001afcc0 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ACCELERATOR 0x001b0190 0x00000070 LANG_SERBIAN SUBLANG_ARABIC_MOROCCO data
RT_GROUP_ICON 0x001b0128 0x00000068 LANG_ENGLISH SUBLANG_ENGLISH_US data

Imports

Library KERNEL32.dll:
0x41f008 GetNativeSystemInfo
0x41f010 CopyFileExW
0x41f014 TlsGetValue
0x41f018 GetStringTypeA
0x41f01c CallNamedPipeA
0x41f020 HeapAlloc
0x41f024 SetWaitableTimer
0x41f034 GlobalLock
0x41f03c GetProfileStringW
0x41f040 GetProfileSectionA
0x41f048 GetModuleHandleW
0x41f050 ReadConsoleW
0x41f058 SetCommState
0x41f05c GetCommandLineA
0x41f068 LoadLibraryW
0x41f06c TerminateThread
0x41f074 VerifyVersionInfoA
0x41f07c IsDBCSLeadByte
0x41f080 GetSystemDirectoryA
0x41f08c DeactivateActCtx
0x41f090 LCMapStringA
0x41f098 CreateDirectoryA
0x41f09c InterlockedExchange
0x41f0a0 GetStartupInfoA
0x41f0a4 SetThreadLocale
0x41f0a8 GetCPInfoExW
0x41f0ac GetLastError
0x41f0b0 GetProcAddress
0x41f0b4 SetStdHandle
0x41f0c4 LoadLibraryA
0x41f0c8 LocalAlloc
0x41f0cc FindAtomA
0x41f0d0 GetOEMCP
0x41f0d4 Process32NextW
0x41f0d8 WriteProfileStringA
0x41f0dc GetThreadPriority
0x41f0e0 HeapSetInformation
0x41f0e8 FindNextFileW
0x41f0f0 GetCurrentThreadId
0x41f0f4 LocalSize
0x41f0f8 UnregisterWaitEx
0x41f0fc GetSystemTime
0x41f100 lstrlenW
0x41f104 GetThreadContext
0x41f108 HeapValidate
0x41f10c IsBadReadPtr
0x41f110 RaiseException
0x41f114 TerminateProcess
0x41f118 GetCurrentProcess
0x41f124 IsDebuggerPresent
0x41f128 GetModuleFileNameW
0x41f12c RtlUnwind
0x41f130 GetACP
0x41f134 GetCPInfo
0x41f138 IsValidCodePage
0x41f13c TlsAlloc
0x41f140 TlsSetValue
0x41f144 TlsFree
0x41f148 SetLastError
0x41f158 GetTickCount
0x41f15c GetCurrentProcessId
0x41f164 Sleep
0x41f168 ExitProcess
0x41f16c GetModuleFileNameA
0x41f174 WideCharToMultiByte
0x41f17c SetHandleCount
0x41f180 GetStdHandle
0x41f184 GetFileType
0x41f188 HeapDestroy
0x41f18c HeapCreate
0x41f190 HeapFree
0x41f194 VirtualFree
0x41f198 WriteFile
0x41f19c HeapSize
0x41f1a0 HeapReAlloc
0x41f1a4 VirtualAlloc
0x41f1a8 SetFilePointer
0x41f1ac GetConsoleCP
0x41f1b0 GetConsoleMode
0x41f1b4 DebugBreak
0x41f1b8 OutputDebugStringA
0x41f1bc WriteConsoleW
0x41f1c0 OutputDebugStringW
0x41f1c4 MultiByteToWideChar
0x41f1c8 GetStringTypeW
0x41f1cc GetLocaleInfoA
0x41f1d0 LCMapStringW
0x41f1d8 WriteConsoleA
0x41f1dc GetConsoleOutputCP
0x41f1e0 CreateFileA
0x41f1e4 CloseHandle
0x41f1e8 FlushFileBuffers
Library ADVAPI32.dll:
Library WINHTTP.dll:
0x41f1f0 WinHttpQueryOption

!This program cannot be run in DOS mode.
`.rdata
@.data
@.reloc
jNhx&B
jNhx&B
jOhx&B
jOhx&B
jZhx&B
jDhP'B
jDhP'B
jEhP'B
jEhP'B
jPhP'B
jphP'B
jphP'B
jxhP'B
jxhP'B
j.hx(B
j:hD(B
jJh(*B
jJh(*B
j]h(*B
j]h(*B
j{h(*B
j{h(*B
j7h 8B
j7h 8B
j=h 8B
j=h 8B
j>h 8B
j>h 8B
u!hh9B
jh(DB
jh(DB
j+h(DB
j>h(DB
j>h(DB
PPPPPPPP
PPPPPPPP
j h8EB
j h8EB
j*h8EB
j*h8EB
URPQQh
u!h4&B
jGhpNB
jfhxUB
jfhxUB
jghxUB
jghxUB
jihxUB
jihxUB
jjhxUB
jjhxUB
j h8EB
j h8EB
j*h8EB
j*h8EB
jfhxUB
jfhxUB
jghxUB
jghxUB
jihxUB
jihxUB
jjhxUB
jjhxUB
;t$,v-
UQPXY]Y[
u!hh9B
7uehH_B
uBhh]B
bad allocation
Unknown exception
f:\dd\vctools\crt_bld\self_x86\crt\src\onexit.c
Client
Ignore
Normal
Error: memory allocation: bad memory block type.
Invalid allocation size: %Iu bytes.
Client hook allocation failure.
Client hook allocation failure at file %hs line %d.
Error: possible heap corruption at or near 0x%p
The Block at 0x%p was allocated by aligned routines, use _aligned_realloc()
Error: memory allocation: bad memory block type.
Memory allocated at %hs(%d).
Invalid allocation size: %Iu bytes.
Memory allocated at %hs(%d).
Client hook re-allocation failure.
Client hook re-allocation failure at file %hs line %d.
HEAP CORRUPTION DETECTED: after %hs block (#%d) at 0x%p.
CRT detected that the application wrote to memory after end of heap buffer.
HEAP CORRUPTION DETECTED: after %hs block (#%d) at 0x%p.
CRT detected that the application wrote to memory after end of heap buffer.
Memory allocated at %hs(%d).
HEAP CORRUPTION DETECTED: before %hs block (#%d) at 0x%p.
CRT detected that the application wrote to memory before start of heap buffer.
HEAP CORRUPTION DETECTED: before %hs block (#%d) at 0x%p.
CRT detected that the application wrote to memory before start of heap buffer.
Memory allocated at %hs(%d).
Client hook free failure.
The Block at 0x%p was allocated by aligned routines, use _aligned_free()
%hs located at 0x%p is %Iu bytes long.
%hs located at 0x%p is %Iu bytes long.
Memory allocated at %hs(%d).
HEAP CORRUPTION DETECTED: on top of Free block at 0x%p.
CRT detected that the application wrote to a heap buffer that was freed.
HEAP CORRUPTION DETECTED: on top of Free block at 0x%p.
CRT detected that the application wrote to a heap buffer that was freed.
Memory allocated at %hs(%d).
DAMAGED
_heapchk fails with unknown return value!
_heapchk fails with _HEAPBADPTR.
_heapchk fails with _HEAPBADEND.
_heapchk fails with _HEAPBADNODE.
_heapchk fails with _HEAPBADBEGIN.
Bad memory block found at 0x%p.
Bad memory block found at 0x%p.
Memory allocated at %hs(%d).
Object dump complete.
crt block at 0x%p, subtype %x, %Iu bytes long.
normal block at 0x%p, %Iu bytes long.
client block at 0x%p, subtype %x, %Iu bytes long.
{%ld}
%hs(%d) :
#File Error#(%d) :
Dumping objects ->
Data: <%s> %s
Detected memory leaks!
(null)
`h````
xpxxxx
f:\dd\vctools\crt_bld\self_x86\crt\src\output.c
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
f:\dd\vctools\crt_bld\self_x86\crt\src\mbctype.c
EncodePointer
DecodePointer
f:\dd\vctools\crt_bld\self_x86\crt\src\tidtable.c
FlsFree
FlsSetValue
FlsGetValue
FlsAlloc
f:\dd\vctools\crt_bld\self_x86\crt\src\mlock.c
CorExitProcess
f:\dd\vctools\crt_bld\self_x86\crt\src\stdenvp.c
f:\dd\vctools\crt_bld\self_x86\crt\src\stdargv.c
f:\dd\vctools\crt_bld\self_x86\crt\src\a_env.c
f:\dd\vctools\crt_bld\self_x86\crt\src\ioinit.c
runtime error
TLOSS error
SING error
DOMAIN error
An application has made an attempt to load the C runtime library without using a manifest.
This is an unsupported way to load Visual C++ DLLs. You need to modify your application to build with a manifest.
For more information, see the "Visual C++ Libraries as Shared Side-by-Side Assemblies" topic in the product documentation.
- Attempt to use MSIL code from this assembly during native code initialization
This indicates a bug in your application. It is most likely the result of calling an MSIL-compiled (/clr) function from a native constructor or from DllMain.
- not enough space for locale information
- Attempt to initialize the CRT more than once.
This indicates a bug in your application.
- CRT not initialized
- unable to initialize heap
- not enough space for lowio initialization
- not enough space for stdio initialization
- pure virtual function call
- not enough space for _onexit/atexit table
- unable to open console device
- unexpected heap error
- unexpected multithread lock error
- not enough space for thread data
This application has requested the Runtime to terminate it in an unusual way.
Please contact the application's support team for more information.
- not enough space for environment
- not enough space for arguments
- floating point support not loaded
Microsoft Visual C++ Runtime Library
<program name unknown>
Runtime Error!
Program:
Assertion Failed
Warning
Microsoft Visual C++ Debug Library
_CrtDbgReport: String too long or IO Error
Debug %s!
Program: %s%s%s%s%s%s%s%s%s%s%s%s
(Press Retry to debug the application)
Module:
File:
Line:
Expression:
For information on how your program can cause an assertion
failure, see the Visual C++ documentation on asserts.
HeapQueryInformation
f:\dd\vctools\crt_bld\self_x86\crt\src\_getbuf.c
f:\dd\vctools\crt_bld\self_x86\crt\src\_file.c
%s(%d) : %s
Assertion failed!
Assertion failed:
, Line
<file unknown>
Second Chance Assertion Failed: File
_CrtDbgReport: String too long or Invalid characters in String
GetProcessWindowStation
GetUserObjectInformationW
GetLastActivePopup
GetActiveWindow
MessageBoxW
`h`hhh
xppwpp
HH:mm:ss
dddd, MMMM dd, yyyy
MM/dd/yy
December
November
October
September
August
February
January
Saturday
Friday
Thursday
Wednesday
Tuesday
Monday
Sunday
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
bad exception
Complete Object Locator'
Class Hierarchy Descriptor'
Base Class Array'
Base Class Descriptor at (
Type Descriptor'
`local static thread guard'
`managed vector copy constructor iterator'
`vector vbase copy constructor iterator'
`vector copy constructor iterator'
`dynamic atexit destructor for '
`dynamic initializer for '
`eh vector vbase copy constructor iterator'
`eh vector copy constructor iterator'
`managed vector destructor iterator'
`managed vector constructor iterator'
`placement delete[] closure'
`placement delete closure'
`omni callsig'
delete[]
new[]
`local vftable constructor closure'
`local vftable'
`udt returning'
`copy constructor closure'
`eh vector vbase constructor iterator'
`eh vector destructor iterator'
`eh vector constructor iterator'
`virtual displacement map'
`vector vbase constructor iterator'
`vector destructor iterator'
`vector constructor iterator'
`scalar deleting destructor'
`default constructor closure'
`vector deleting destructor'
`vbase destructor'
`string'
`local static guard'
`typeof'
`vcall'
`vbtable'
`vftable'
operator
delete
__unaligned
__restrict
__ptr64
__clrcall
__fastcall
__thiscall
__stdcall
__pascal
__cdecl
__based(
GetUserObjectInformationA
MessageBoxA
USER32.DLL
Unknown Runtime Check Error
Stack memory around _alloca was corrupted
A local variable was used before it was initialized
Stack memory was corrupted
A cast to a smaller data type has caused a loss of data. If this was intentional, you should mask the source of the cast with the appropriate bitmask. For example:
char c = (i & 0xFF);
Changing the code in this way will not affect the quality of the resulting optimized code.
The value of ESP was not properly saved across a function call. This is usually a result of calling a function declared with one calling convention with a function pointer declared with a different calling convention.
Stack around the variable '
' was corrupted.
The variable '
' is being used without being initialized.
SunMonTueWedThuFriSat
JanFebMarAprMayJunJulAugSepOctNovDec
f:\dd\vctools\crt_bld\self_x86\crt\src\convrtcp.c
CONOUT$
MSPDB80.DLL
Stack around _alloca corrupted
Local variable used before initialization
Stack memory corruption
Cast to smaller type causing loss of data
Stack pointer corruption
bad allocation
Siwenuy wukuyikig vagoyod
safogeneyubaxuvekirabagikidi
gobokitoxocayuwuticujupareraj
gutipalutagiwerihivunevohufituseni
culevuyocezodayurazesif
minucoxowif
totuzuticiyabajovolivomepaha
pipeyawiyowutuvasufiwirujudo
podukixunubesagobibecikexinepe xadawusafurepojisogavakayuhur rucatupisubohehupuladula
xebumowavoyewapanedut
C:\koz-jefafocekes.pdb
GetThreadContext
DosDateTimeToFileTime
GetNativeSystemInfo
FindFirstChangeNotificationW
CopyFileExW
TlsGetValue
GetStringTypeA
CallNamedPipeA
HeapAlloc
SetWaitableTimer
InterlockedIncrement
InterlockedDecrement
GetNamedPipeHandleStateA
GlobalLock
SetHandleInformation
GetProfileStringW
GetProfileSectionA
FreeEnvironmentStringsA
GetModuleHandleW
GetPrivateProfileStringW
ReadConsoleW
GetCompressedFileSizeW
SetCommState
GetCommandLineA
SetProcessPriorityBoost
GetVolumeInformationA
LoadLibraryW
TerminateThread
GetSystemWindowsDirectoryA
VerifyVersionInfoA
EnumResourceLanguagesA
IsDBCSLeadByte
GetSystemDirectoryA
lstrlenW
WritePrivateProfileStringW
DeactivateActCtx
LCMapStringA
GetPrivateProfileIntW
CreateDirectoryA
InterlockedExchange
GetStartupInfoA
SetThreadLocale
GetCPInfoExW
GetLastError
GetProcAddress
SetStdHandle
EnterCriticalSection
CreateMemoryResourceNotification
DisableThreadLibraryCalls
LoadLibraryA
LocalAlloc
FindAtomA
GetOEMCP
Process32NextW
WriteProfileStringA
GetThreadPriority
HeapSetInformation
FreeEnvironmentStringsW
FindNextFileW
GetCurrentDirectoryA
GetCurrentThreadId
LocalSize
UnregisterWaitEx
GetSystemTime
KERNEL32.dll
InitiateSystemShutdownA
ADVAPI32.dll
WinHttpQueryOption
WINHTTP.dll
HeapValidate
IsBadReadPtr
RaiseException
TerminateProcess
GetCurrentProcess
UnhandledExceptionFilter
SetUnhandledExceptionFilter
IsDebuggerPresent
GetModuleFileNameW
RtlUnwind
GetACP
GetCPInfo
IsValidCodePage
TlsAlloc
TlsSetValue
TlsFree
SetLastError
DeleteCriticalSection
LeaveCriticalSection
QueryPerformanceCounter
GetTickCount
GetCurrentProcessId
GetSystemTimeAsFileTime
ExitProcess
GetModuleFileNameA
GetEnvironmentStrings
WideCharToMultiByte
GetEnvironmentStringsW
SetHandleCount
GetStdHandle
GetFileType
HeapDestroy
HeapCreate
HeapFree
VirtualFree
WriteFile
HeapSize
HeapReAlloc
VirtualAlloc
SetFilePointer
GetConsoleCP
GetConsoleMode
DebugBreak
OutputDebugStringA
WriteConsoleW
OutputDebugStringW
MultiByteToWideChar
GetStringTypeW
GetLocaleInfoA
LCMapStringW
InitializeCriticalSectionAndSpinCount
WriteConsoleA
GetConsoleOutputCP
CreateFileA
CloseHandle
FlushFileBuffers
.?AVtype_info@@
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
.?AVbad_exception@std@@
.?AVexception@std@@
e{?(82
}+z>S
^tz;!?
WI&_#%a1
&?<,Q
y8* @c
qNW;q_
.#WHO
t^<Yd\P
T2E2l-
X4PS[s`+
=pQK#-
Vg4zh-
|cD; eH!
MyVW;s
fUS<:T4
'l8P_Ei
1n7;H
:32ex0j
"Q?qD9
Fgk`^Y<\
bn0]hM
",2{5]k
IpbGw|
sr">b^
A9LS'2
<mFzcO-@b
c18os[;~
#Z.Cb]
Wicb\g\
.uHD5-
%;s1X&J
J&[I1B:
mEku^!
)<Od3:
F=#qQk
^PXjcX
Q^j7,Ez~y
nHT\3
&;X8DD
int&S
A#8~jw>O
]fr4%d1
Pt0|OH
W4'Rz1[tC
Ip>hP#sND
gkVpzTG
JR$wRC
3rStfQ@('8L
Ek!E))
E4X?z.
>`%\Rd
W`e lA
&FuV3k
o(`p$i
7JL/LCuJ`!H4
-xra$JY
YlaF{n"
rWZ4N8
y@osPS
#$a o>
bYLLX4t
@I0=8T
vXi7>5}
<J6hfQ
^"V4Bb
'j4}>`
{<,Ww
o{(<Kr
$^l?RX
+qW*o6
eI/z~@ m
f^!"K)
";7I{<r
%\}QZ~
-iV1H"
WgciCIqt!SVN
uSvdlz
;qf-7c
>e;=Sa
MbSp.B>.
`3j&QlV
tZg3}PR
h\kJnw3
@UYmmQ
\T#+%o
$>8i&T
g$3Y[H
yUtHZ3
}Z@:IU
niSVc$2r
_Mwc)pE]H
)ajPE5
Y;6Jy~
;?qU&,q
#,7/@c
Q1@7Jpg<
D]n`8SD
dkR[!8
&Rjn<c
/UL9bID
N2DM8
XiXU^[
zT&5U&
?Ee)Ii7
kG(o.H
O>9>K/$D
v %yby
//'0}-
Fi>ELOh
.'Mq2(1
&<x'`T7nQb
A$9Q%te
2|fAY}WF
Q >7D
5<+a@(
ZObpGI
Mq"X7;
9IDS-E
tUkE4M
}U2Z)_s
BV3UqD
TKZ/g
C=OLYy
>&xH[
n=58ML1
jn)R`96
5:h+oz
|a_ky
>f%dbh
gW0uz6<Sx$
VyIyL6
gQoHqw<h
qvKrRn
~JB!=<
07fGt
$m4]b]a
=l:kV^
ZLi0)Z
rZG<VVZ
fg*ylc#
"})C2'
uyG=Z"
nyqyjM
"f\ZN 5=yx
UKzje,
.m0dl8
atU1c3"
p#b0oSi
F~wsww
K7K4)m]
IZlHCL|!=3
L3o,CN
\lCnQJ
@V(/!l
D>-^,P
/J^]kbT
*FRsIU
WR'z'cRtK
Rhv8fii@$-
BW.g(r
w{k!]'8
F6ph@ r
Ov7ZxS0}G3
#)J"n=
|6O`#y9U
@TO{wFd
XaJ8U
a`bgpN
CI6Giz
/S/2fn
,'>)JDM
f-Q-%H
?QdkEK
54yI\0r;f9
+ .X]&~z
bbaoTM
9l1"%z6
v_vV|=
(ZLic
/@\IRu8d*
YcNcYH
U}R_#<
W~]%uK_C
m? Uu3!
fGoBDZ
TTXT[O
|1WW{PPC
\miGW
VN~m4$/m
-AR?Do
}v&[g0
k0]B*&
$w[1Hg
?#F#eKR
'XDl)
-/f!DO
Qeu`O+|o7aF
);%iAz
H,O>1f
2.tday
.UN]dz:
N]H9Q+d
zs9]CF.*
$SdLDF
T~iI6
=]Zv r
[cCkSb
/MJ8Ll
>#]\(4_cedW
+YhHP9
VWpC6M
A;sO~Dn/
s?1DX;
xq5,+[
y"gf7Uj
CRg4.yQ7.rh
?ASr/gG
\Tmlq#
S 0 SH9,!
A?x)<%;ul
D_juRl
_W(!"aE
>Ufve%g
L.FA@|
-Xqf']
Dg<w,b
VFgA'U
JVPCNr
|v.'|*
);?]UE
WrU9z}f
4JK1cZ?
5@|ZAIB
Q4V3c'
P:.F%#
Jyr|2.
{;G/@[
ad6,#su
nzNY]% U
b7{85n
k%Y!oB=Y
{V<e<S
q_uqRw
fOqqMM
"vEZV9_
~6D./B5
xzdkW__
]s0G}9
Jb/D~t$
Fh?*.6@
W|D+7o
$$M(vy
u!,+1w
BT+[{;S
BU<k{j
(v3_5
h]<vmi
Z!/"#K
=s\?-i<1
,,#*uU
3l/_.
[&1P#|^y3
s&6EQI
$ivIt*
Y!,H/4
%`=**U
BftI9f
zy()<{
34[Qo4
"[_{RBRM
sPo;Tr
j/)jTs
WP[ZPW
SYK&-q
j'98p
)hpwDdH
B3{Kj2
(k^K}'&
V!|}hEK
4<F9u?
>"<cVs"
D2)Y!A
_7%)S_
oAER3L
cX7!)sA
h'dqOH
%m4]'^
Keipqb
z;Lj+W
87^c'-
\qUfHF
SIKw'r
HXmx2F
5i?`B1
{1;&TW
XmdB|Z
@{Fvb?
=7MpV\
EwN.{R
`4)U>jHGt
9z GrG
Xob;XkV
T-D48.x
*UE?st
H6iWd4=
n,C:O
lZJWVc
@8bu@@k
69)|YK
3`z4@x
kWy`q#
?b9@c4-]
Jv)p`
>47bp|D]
XhX0,Dr5A
~]<sI5C
e>}."I
ke{<7TSp
C*ho2?
80&@n?;
!_yx}m
nl%`</
Cesv
wP(OW&
H\K=o(
3hp'j%0
xd5Akk
vCy8(D
{kCd>/
mbBQ-L
i:dwACS
Ej!b2
="SGe<
pTD)ws
Lc8-}%
c@NdaWOwa
Sonz|k
b~-TOH
AP@i?R5o}
J{9m2~
U,H@|C
b|f%>Dz
p9UK%G
yPz#!O
Ex)?{6
Q&\n[&
gkZD!1]
REK1$A
Jxe-.<
7e8{yt=k'z
]<NW2.
y:3=wN
ZR:5?^\Q
]6,bvX.m
8y\/R!
$a\5b$
G|&"W[W2g<2
w;\eOW%\
jKF#jo
,H@n{IL
{J.Agl
-Rq;kb~
hZu(sX
f`=z[.
#fI@\q["
rPd~GR
,"Za{A
4Td=u:
:9`$-B
CO6;'*
KH@f7h$w
)3*PKa
A=k%2r
G5\p;=
HrD$p1
>euH8x
Z7|-|d
<|H|G;r]$
y{kkb`
4.A~y;
Vj$]]v
aNoeHp
}tjQ5@
2\H-`!Zx`
W^Cltwvz
YegEBM
2}/Y~Dh
OJPUvoC
|`z0Mg
eM T@;x
'0INs?ms
6s~0?/N
*h1y630
>GwGL:
/%ey=%L
KKQ6;DN
tRz}ES_
'yE8FI
`miGx|$
[<J1vi1
\nkErY
Q\e]`b{30
+Edv)/
6B M[8
6Qx1w8
%u&=5B
!h`Bg
K;vr7>
\xH)C"
D0!va3zuD]
d%&$W1
e<^(/gz
uP.=j,
g9_/'#
mzNa,Zsk
q#GRMj
Y7_L<@]
p#4kq6
b8oXK9
D'm:;s`_
8}DPM+
i6N.X
+{Sv!u?
*Fc{G-
8;}o;^
kC%[r
HkEdX-
u(xD"#
0q%dj*
<,TV(t
_BRt~[
QbW|h4
!^.JYj:
ArK7_Ka
}9,jg]
h_JcE
GE<O5,>
UTmGRjw
C![,>M
:nF#^9
CF~D6.
;vB\ekQ
5!4d@>
1N!L h&
jTb#R,Pe
YC_e&D6A
)R62 #
VIze|
\>'<q3
zF>&3Nk
,jj'PP
`^bqV|
EBE{3/
AzAtNl1cn
pCXin>?
;-mLzhb
Ge#PeE
-QLX)mY
I"Sey@F
f,YZNE
BPIIp7
9uRxSv+
?y9#l"
*`Geu=
yn*&^4
/9;aY?
[l~Ax)
{u&! H
eb/pZ0
CX`r<&
t9ZSo{Mi
{4l*C)
F[v:>P[
*9><Q^X4
)}Hio1
mLBHk&
hM_wC>
EWOcQ&
JL/kx1V
S?t%SY
4'x7(*!
<]$9%9Q
n&87;o}c
JH|L^f_
od@Ky{
yin~)v
sSvTu_
Kf;|'&
WNg# <*
Sn.5uh
/QaT>%
hSE19*(
;g@pjOz
9Ta:|qb
}Rb?Cl
]`^T!(Y+
npthZ54
[ncf|.
!|+P{S/
xK^Js
%sza{,Y
1qjbp_
lLFQnZ
^*paRr
l[Jr?w
%Pu-(*R
SQZ;$g>
(G;#xC&#
8U@bP-
zppD`
$Mmsb37
{oWk3(
Ebl?,|c
Z)^'BN
G"<-h#
Dz4N}iq
`\Sd>C
5Z=|(/
MpyJ7o
Q u>'O
u^p8c*
,9KRsY
~u#d=j
I#tlb
[h63FK
fiWUtr
j\6o+S
):-\iU
@WlFK$
e9x^f0
A<(<lAX
Ulw*/oi
$6144Dk
tZUB8t
|I*z,COR
zdx!^*
(m)\Ez
}^|c-&T
t f4v?
2B@okb
,Z-lub
3/&4LJ0n
Qn]BN7
';zX;!
-WA?jd
MXkko8i
]L|d*_y
@D-j9X
d]:5pd
LggX /(
/j7Z3r
V~$I=nGumF
]5g9@S
7A&:t
A'k=;(
Ho`<Twv
Lo<<7!!O
0ia^eQS
kU$7p/
:=Bihs
{_Lav\.
:61=ge
GFE6-
?L8G8f
MVBSR9
]]t,},
G" z x$]
>k*},=K
?WO5Xv[
1lyxw@$
3uSh7
Vd>%72
N+a_54
vH!A[A
g%*PF,
!7^zX8
<E|T3B@V#
bi]3(@
i#DJp`
0lK&[<x
#+ -7kd
o<Y,E5
4}T*^Y1<
D/QwYr
oU(%Y[(g
m-eaH#'
t>$n$Z
WTI^dk
Wi4MnP5
@Ff4.r
9`PA^-o
('Ukj^;
%F!d* b
jW>6DcH
zdG5l$
5ROsx5
^&V9Bs
^tW/=P
y'4b-VV
F~0-E6
%_C|)~s
mx.0bFb
5 ZkO_}>
Z6czO!
^rVbDfp
MnffZ%
w(aykL.
'j*,U5
b6gB=z
)Hi*)B
U19)t\F
4#k'KZP
.V|"3;
r{TJrs
cB?rQ%
iSmLFC3
4a5)b
ri 3K^
N||2O)
C&Te"'
stw%fv#
F7?Kr+
yHi9E$
[z=vU=
%U:0}tI
URMG:'
z8ii^E
K.kj3Uvb
;P]%!Q-
u{3ZDq~
='daG'6
@VGW%5
m%fyV03(Yw
2u9$ab
lka(A`
)J,ur>>
aoamL_
0pfmgz
{=XKvQ8h
pnV8OZ
<vOz')R
`hq(;m
>9(}r
lJV,nD
RZEGc{
Pb{`b~
*4<iu
yP0z,U
V<D^c#Z
YkcxoA(
!_F/G
ixp#fD<
2$dZbL
Y{bqWH
2JTbUT
~}-iiw
7x{2qK
fc'"@W>
QLVJ]"
y3OX-Q
8}t:|Tc
VZY$Dn%
&[2&gI
W[\phA
7N\B)p,
P}3)@'
&Vypq.
`E?l[H
Q!v_;39
rqg1B|(
RlRfT?
k}bh;x
{;0L!}'
v-M^f_
+LlJ\
3(LYMa@
*n|xAX_
1bfdXI<T
_n:"Id
92jKbmkC
)$Yx[6
y[L<bG
@`y/l![S:
X+M{!F
r9XvP7
".<e{9
(u2?T|
Rl@SK>
Wo)it
}<pxkk
j-S"p6(M`
cSLkt4
sF9}j?D
`;31[yv
<;B-)%
BM}|1_
'YaGG]
Ir"l&wY'
$aH=:-
#:qgtnF
iW&=hFo
,_c\&E
//cm]u
&#-U|yT=k
GP#_n>
jZ.*EM4by|6\
!RSW|(1
5?y_h{U
W&1+:!
;b=~ATs|Q
px}8qw
{Juv}B8I
VW%6\Rc
zNn(tgo#^
;<&]TQ
*!{)\RX
a3&x_Er#
jCTTk
2M5f,7
hT=+{3
b}f7qT
C`j%n\`
J,xWh)
i<t.6p
vI=pCI
Gw/(;8&
cA-"OAQa
$&kL@B
$6"1@,
8%TV[Wz
;^Ms.
Gk\sN9
A"|:^a
ZEtYeU?
|<ZG`e
+i0"p<
KMH0R,
h19-$h
R__gU^h
4,L*aM2`ea
+5Fvna
.Py_Y
I6x@t1>U^
DdZY"n
73VlnF
iAqN'r\
TB$qK<
d<#`.@N
bT!k|
VSM&s\
]]TY3w
IJ$3~>
Yq)gJ5HL
O/S~)"
cMF|*]:I=
~o Kz3zUY
1(pqKx'
`<tAFv
4= 0'Q{"
,X"MyRE
phOK6<
LWYO V
0`g}qR
k/9Pd#
JW$q77
x(k0s`
$!).Cn
{8><@,
g'4/Ye
c%Amw$U
Cr><Pib
s5]XmTT
u[OVt8
$X{ht6a
pvWTF#
l}:5_
zTpwp
V3.!H^c
5;C*i
Ug`[[IOQ
(]PyWz
s&Y8~,
C)y$2x
S.3{\!f
6eMr/9#
E~#4yvf
cqJ:$$
'dCT"A
j(uc]=
y_yVI2
LAq#)s
Oi[b*-
P[N>:=TQl
Xh1l8T
0lRu(y
91}w9`
iJD[I`k&s
j.(ZK)
>Iosof
WGKeO6
bTU0;o|
SR!'i
pRjjf9o
xIt!jZ2
{$F+-F"
#)g9LDT
)OR]7=
HS8fK^
I]F+\U
qZk1|rP
O-mVy 2E0T
w[`HqW
A{(::)
@3>$8Ro
:%AWWXVZ
-1HaRV
|UhTiI1
m.p4XP
?]A72((
o]s6Fw
Uq=P^s
EGjef>
J[zK{2
sinmn)
&v-X,+
!N`7U{IE
yxOj:1-
rP=5}(a
QQ(*Lz
{^&Mc,
/84SxZ
W^R*To
+VX?va
jeCTS7
\@^g`v
P'-fYJ
bm<Lkf}\
Tet11m/
Jl+hW+2
-y"g9"
kFC"_HP8
)g_oPC
&k._Za
T$q!W^
SJvjA@
C|<d\4U
-ZfD<_
m$Y.%o#
>d}azv"~+
pA9_'U
)[*;e
DNEYue
K#Cf6X
EwKbd!*6
HfGK"9
L?i^ F-}
Yh"Rg3
.<13@#
"1m'Z/5
n/1BH,d
kwq8@
n#JTT/
!,'*0BE
2:0]+"
V6xuu6
L|-0O
6}g/?~
dmEo+~eR
>nk2AL
KR%5/trdgRN
LR]k(\&5
2RRF4\Z
4B=.3X
z dIbs
dxDbE
qMEeuJi
u9w!+`~
)77a}}.C
!DeR+T6
_*`a,K
;ERl4x
yDwzwy
0N<sM+K;l
G|d24O
o{RnXR
s2){,5
H;kahn
#{XP]e
t+cnso
aWf>Gd
-nXS`p
Rs@6!d
3_NhnD
nN,aqrY
;&;&r6
`:'X?'
zHKA[_
Qnp9EU
#8:K0zq
MEO$ V
?DSzrx
X1q:A?
;53{{tw
]0?=r)
Bt~04*4
~.o,oA
@x8y2
#5@oTiE([
#rjx`om
9Hgmcg
#VasXj8;
,3a;GeQ
\cWW<*Md
EdjiY,
/;]*ov:
s!zG9:
$[$N}vi
}NxUu1
UDy{ZP
0_VH[4
9-XbPh
,R.v<L
Xi;6Pm
6` T"A!P
5M7X 6
Nh:wy-w
wf3D10
oZ>0X3
=GM5(%
>q.EL[/
P&)6F1
q+fvuN
O"}%iS4L&
a<;&P+
HG;8"p
QWG`Tv
iliD/G
J>dWul#"
\~&s&-
&3rgCC
wc^8UJ
uAEaGJX)"
x\RHs[4
e5JT'T
FPaaLC,q
o'T)K>7
>`C-6F;
Q)PIGu
J-n\]!
x\+Kxz
N[s6r-
:)HyGVo
>,Cv2$
!~t4VQ
4JBf\
>!zPTJ@i]
?_3#bi5S|Uxh8n
,?UH[]
[2Y}f
/&{U"f
YFvFwi
pFL^%M
R"NY9
=pc{_d3
liEI2{
J{F=jB
k\jqp9j+31Jy
SUH#9D
'8/3`45
gU*mnr
F!S/hP
tX!|V;x
Z6K%"Q
hdvN[{
1"{8T8
i(qdzd
`Y4,x`
E @!aR
+j*NQH
,hjt{{
i,Rnuk
KmC<S+B2aw-
RBuNsb
hL/4SvhJ=
*Qz8?3
JP-/x!
lHx,{J
H!5#a|
;@vfBTX
rWBmr3
)i?AQRH
"::c7A
E}aA|(
5BSK$M
90(II/
<3i6Q)]
H|v,e=u
-#XtlH>
Gr1RgY
Ns[`6G0
Q7^?;G@1sw
Yt6nff-
LiFw`'
IiBIh\
~?u8|
r0*RVt
cI]h^z
8@<*{O)"
LGycF6
8tsu!x
P}ZG,x
9 +'n6
qlg?Dr
60*E[l
#d?yzA
8oexbn"=
+k.7K|
"alP@A
P>ZYMW
`d~\FE
- xy\C
},H8}+
baq@Ot
%.a;@ve
8~@mN
Y#xT/)
ECh6fh
TT'D1K|
1Jb-h<
mwo8q+I
qk$XYy
\Muj<kR
;!#e&$
8XZ1l;&
(0HqTc-
Om%@J|Q
m)QKio
cOJy*4
Ja6Q{
"7kmoi
3aMeas4
-vcLVo
DEvMQOH
0?,D_MJ 7
Kn\,-Xpt
EK 2)8
.hI[?P
>Ki}m>
YI^r}.jiD
XPy0hm
:9_ya
cGQSC{
Tov^u"a
;ieCDh
N|^>'$~r
bx!_@W
(]!Dq*
$="BeC<
KLs,Uu
{L/AH$e
f`t<6}
7G)3rg\
%icye'#C
UW/ais
tX/N2f
B8yRRnj
*\#2GY
uM=G9M
+:vkkG
AGD?Ljl
Rvv#iF
Qv:^q8
,4rOK8qa
yqm|yN
{o](U-(i|
4,Fk|VB l
Cn2BFH
`!WsB,r&
w]jnVe
ACA*V2
vO,Y"jX
B\-c?3
RFvo=N
{l*=a(
'rmw$3
vhr,wR
B\$j&#iAy
bcb7nFK
/uWyE=T
\$wRJ!
j{g|i^
w^[PHy
tBe_x3J1
MVnNu;
gI,1_!
z|IKAg
Vd<`I~
10m4]/
A|lM$Vp
AtcnLD
<DSt.!
{#KfwwC&
[]e'YTo
q!.BPR
)n43BdN
Mfq\s|
`{*n>D{A]
+ky(:*
*QjU\R
N3PhKS
N/]SY<
;9VoQo
sr$PfY
\3x22.H
c.bJ$c
R>3At{
UqPN8B.g
hf^{d0[7
`W9'i8
'aOK]D
seu2^Q
pyRo^
$vF'Bd
j~>t8.
l;-fo]
O:MDDd
#[zVvl
iu~#^l
@w]7N-"
uFC%<<
s&i9U\
F0`~@R
0Y2M?`)
rZ|q%q
dClYS\
~tmh?G
DA+o;]
3rfNc&@wR
hSLv3lr
Q1HIZ"
/Bft||/7
p7h^]2
( x&Q+
s|/n/r
S&-Iyc
<6.fCb
`TO Yk
v5+l$>
n)&pC@
1~1%\E4
l$y3gG
88#!SF
a;c]H~d8
-]!I4_
R>xH{x
Mso>3-
0IcYId
EHv_,=
-7Ofe,
/{?o%>
nIDr1@
(@.5Xu
N'Bm(Pv/0S
T=e$-*
'NXojw
Y6/E\"%/
p)L]h
x*l i{^
x!2=M'A\
+yhfHl
@CZn{/
]uj2(
<3sg>m
];isr|
]\P[}`
&!b':|
<nKuC'
0A564PfW
=R&'ruol
eLUOi`y
Ox.G}OsqL
Bmts0*#
ja]ec"
W#dsgE
+tc;k9
s"{R?Q
'XBe2J,Y
niy.YN
!^DGUL
zAqlT Z~@
C%g/:)
J|NF7|
;K#=E/
P_X_`X
b.^,P[
u<Kn 5
xr[xM&
M76T#W
<i*6&t
u\'#pz
cqg(#=AMQ1
vslUx3B
9kioD~wA
s#v-PrQ
)aHo{f
S*pOfA
4k}${.
j d#uA
f^7\}v
DG.q6x
DMR-U
s(:&Y~
GE%^HV
q%:iXV
x866tK
V-H[Io
]Q<-j
g:0=.\
7Grl/J
hMLz3>
edN4t9
nIN-GS
?)nZEW
8;$8ZR
_i|BW6
r{i=0:
4]7B$)
B*<o?w
g"Ayi%E
q_\},i3
$BlaM'
E_WLCP
b,uf?r
>Gk'<U
+twkqmC
{/r7LQz
XEn#05
&R7.m#
20[~/Zv
Fk`{4$
aW~W-H}
2w}CKo
t0kk`Td
qB|QOVqH
:ON+3(
tDdttb,U
-}5lEm
C4NLhJnT
pV]"sU8)
7UFSV*[
'EK)k\Z
N*3rH;u
III]y
?;h"
):=;e)-
03AQ%R/%]
KG!r/Cf
"/sYb7J
Oqy;r"
"]N3,5
Ok,$p#
zpm\O3
0+"!p3
YOzva;X
obv$9F?
.*=1GI
#1S[2~
Q>)T1{
~j9MTS
1nju^:L
fO!=Vi
W2OZv:
E-%*Q?
((g%K<
pXUj67G
e*W=\
MS_`jotfh
R1kQwF
SIep(72X
_=b+h0
:VfF8I
X]tmi5v"
f#A|/@
-!@0v#
64fXbv
Hc5MJ1r
`zdb4Na
gO;w!t
x9,/Nn
I'b33*
i01YR`
!0mfSL
\mV)8E
p#/BhQ`
L-j#D:I
7t#k;Bz
h[Yg"VX
T!Q&Buk_
[NN}b0
'n5.SO
+Euv.^
uxmm9>K
sbXDv2
<WOS#Sl
wTSaxwl
9Ul;d`
A#xx]%
Kjo+B<
-l|Q9>
4X%30lw{
feBZ]}
eJ^NA^^
yJ'wVc
0iQoEp
js~Q;u
G!{m[k
)\h.x
m\IgBiif`}
!,G6E"i
vv-`TU}
S87. [
>O/Ll=0
e6..:G
\ctXHg
59[F@~
%1JJGE
pEgGqQ
?~zUZJL|
?o>Q%y
xU\3<\
">d:U9
%.vN'P
DN'ujB3
SGu|b\
Umm7hc
y5O~Cz
!Js<gW-
. ,Xu/
U,akXPQ
tbpkaeT
BOR[/B
0%P'j{
~kU7D"
ZXDu%k#
=z#co=0
IF&!{p
ZP"57~F/
txq]H`
#Dr,N2Y4#L,
p!Zo^
K&x?IS
M=m?iSQ,"
4d]c+
dzFGSV
SvKI-
^<~kS`
`Ebe{fy
K|k8bx#q
7qD&3}Q
4D0)i*
E&~yk!
*kYaR+
r9k16v
a#'zF\
qt/mNG}=6p
'q f~"
3p I`V-vT5
E:vF/n
<$Zp]R_
=1%^mz{
UY%%sN<x
}rJ0[xM
On+@6v<
NI:W-!
[aJ^f
5hF*OVn
1rQqlc
,w(3d7
,9VH3TG`
\I@A2D
[\K,>d
_ ||F6
NR+Kt2
Dm/G?|)
nt7U%i
S!u.];U
o h}OW'
u>:a>ZZ
Ij51^
=57^ /
-,.T7'i
zt5xK
s`8QMB
@E_W%'wusg
u/)W?o
&v2^g*e
QV?RnR
zQK]h2&
1Y 8|M
_,fz|X
*Qwy%pbG
XXAI&D
*7mF7
;Cis2=
ODmcG`
}%,`MZ
$b_4f0
U2PJYks
nNXWp
\I+sAA
_;y#T
n'f{Nc@Z&
QpAVnA_
9} ;D3A
Rm2H;/;
1iN9Qa
`E8{tP
h+:p;af*ho
1RP~Vl
VH2'hK*%
6Ya5YQT']dK+$
(5@BH%
3-<lGN
] PB%vut:s/
U]Y b]
O[n5CZ
N(+<uU
7mG^"2
_hoRr|
<y)%2s
4GKIf9
2+Qj+Si
'`;u'R
xswd>zN$
,X%0wI
f<?Dn)
YWyDs^V
yHx7fS
g\-["%
q^?Y]i
h6)<B}.
CQU#XNA
Z\nG&C
oFA@\)
r9s$[aq6
N$BkOg4
50(+rl
(U>}A
jN<0/o{
]yb`#W
v&X9>f
yGTVH
_3AS6i
,;-#l
^e;7R
[F!YU#
2tYwg72
m3"Wph
VE$Wh
d\fD2
6YU`9A
(:$&gv
Z5?t3}
:V3X^
gVVxpu
:/8q;~
7Z>F.4[
/6#hz:
h}s~8 `
'`gPBU
hb).BqC
Yf=AFp
F:F@q6
0@Iz![
vBRm5y
/qIg*N
D{SenG
bw,(lNb?-+
ONWUuq
T{:A(v
=r~J_^&`
'e*C=i
)Wy]n?
:K*%l6
.**MAJ
^Hk+Hx
Rn7s0l
h@\8&~j
Zo$XN^
M316'
daJVKM
L@sMmla
\UYMQDA
WMAu8m
wtDxq-
F]5blw
Q0q@Q,
F3Z^C0
ZjVI'HKq
tQm3~
D*2-}1
HZI_5y
gr+C"3
P}15?l
#bBOX&X
im}E.)
X*A\EO1
<ge/x/
g!MIUQ[WR
H2]/~~
Jf6+;Q@
HuT26fQJ
; 'XQ0u
fpq%Pa
2P8k>'J
+2VUQ7
fDy>Ntp
.T$}36j
60PZ9@C
jb4@K<0u?d
|b<d5b
w~5B~D
}pHx?zr
&6HE6M
8||]2RI
nk[?e$
0d?5AL
&/-jsM
x;;l~N
~ U1mv
SU=B%F
+hqLR1
iwRD&_
F[%Rv@
rnQ<,U`
{|EoGG
jxhOyys
."\5L?L
[Su:Yc
no`sjm
G/E,k7
N2s;IH
0/S`T&
U)#ZAh
1 uaGj
a.O7+U
Fsp#!W)
A! W1dZ
)\HnlJ
0Xq"&J
ZD/Mb+
E?(LF3+S
^xAm7
]n1'vu,
Wl(u8n
|;lEH
RGj7VN
c=u*Yy
.[XDxd
yGj(
IU8GY:
2~8#D-
E'X]CK;
wce6oh
LbRc<3
[C3aIa
N{!Rx)
B"A\"8<k
abCH(}
*d.EE@
B`H1ld
;0I(<TP
2E"px?
1NCSC4
kG,vG
UJOOl.
Tu](mO
ld=o.<JC
1x\XPz
VWQ507W
PdTBPX
KK[OoG
M4<4Kyh
XY&W`r
O Ao5h0
0-}9.)
!a933+p
~?'bKYUB
4g0zF6
?e*zCx
$8t$To
nt2[M?
E@?C)<
$P~W+w
Antivirus Signature
Bkav W32.AIDetect.malware1
Lionic Trojan.Win32.Agent.4!c
Elastic malicious (high confidence)
MicroWorld-eScan Trojan.GenericKD.37597563
FireEye Generic.mg.e7c0b56dd1a23c60
CAT-QuickHeal Ransom.Stop.Z5
ALYac Trojan.GenericKD.37597563
Cylance Unsafe
VIPRE Clean
Sangfor Trojan.Win32.Save.a
K7AntiVirus Trojan ( 00581f861 )
BitDefender Trojan.GenericKD.37597563
K7GW Trojan ( 00581f861 )
CrowdStrike win/malicious_confidence_100% (W)
Arcabit Trojan.Generic.D23DB17B
Baidu Clean
Cyren W32/Kryptik.EYC.gen!Eldorado
Symantec Trojan.Gen.MBT
ESET-NOD32 a variant of Win32/Kryptik.HMMX
APEX Malicious
Paloalto generic.ml
ClamAV Win.Packed.Generic-9893540-0
Kaspersky HEUR:Trojan.Win32.Agent.gen
Alibaba Trojan:Win32/Azorult.db533c4f
NANO-Antivirus Clean
ViRobot Clean
Rising Trojan.Kryptik!1.D975 (CLASSIC)
Ad-Aware Trojan.GenericKD.37597563
TACHYON Clean
Sophos Mal/Generic-S
Comodo Clean
F-Secure Clean
DrWeb Trojan.PWS.Siggen3.3146
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition BehavesLike.Win32.VBobfus.tc
CMC Clean
Emsisoft Trojan.GenericKD.37597563 (B)
SentinelOne Static AI - Malicious PE
Jiangmin Clean
Webroot Clean
Avira TR/AD.MalwareCrypter.tkcqo
Antiy-AVL Clean
Kingsoft Clean
Gridinsoft Clean
Microsoft Ransom:Win32/StopCrypt.MFK!MTB
SUPERAntiSpyware Clean
ZoneAlarm Clean
GData Win32.Trojan.BSE.XGXYJ9
Cynet Malicious (score: 100)
AhnLab-V3 Trojan/Win.MalPE.R442026
Acronis suspicious
McAfee Artemis!E7C0B56DD1A2
MAX malware (ai score=83)
VBA32 Malware-Cryptor.Azorult.gen
Malwarebytes Trojan.MalPack.GS
Panda Trj/GdSda.A
Zoner Clean
TrendMicro-HouseCall TROJ_GEN.R06CH07IG21
Tencent Clean
Yandex Clean
Ikarus Win32.Outbreak
MaxSecure Trojan.Malware.300983.susgen
Fortinet W32/Kryptik.HMMS!tr
BitDefenderTheta Gen:NN.ZexaF.34142.PvW@aSe4yLdO
AVG Win32:PWSX-gen [Trj]
Avast Win32:PWSX-gen [Trj]
No IRMA results available.