Static | ZeroBOX

PE Compile Time

2020-06-09 09:17:28

PE Imphash

17b461a082950fc6332228572138b80c

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x000020f0 0x00002200 6.03397581892
.data 0x00004000 0x00042490 0x00042600 7.15576906682
.rdata 0x00047000 0x000002d0 0x00000400 4.00037373567
.pdata 0x00048000 0x0000027c 0x00000400 2.97342307908
.xdata 0x00049000 0x00000238 0x00000400 2.65379684452
.bss 0x0004a000 0x00000a30 0x00000000 0.0
.idata 0x0004b000 0x00000958 0x00000a00 4.1419693576
.CRT 0x0004c000 0x00000068 0x00000200 0.256446748701
.tls 0x0004d000 0x00000048 0x00000200 0.217769955458

Imports

Library KERNEL32.dll:
0x44b244 CloseHandle
0x44b24c ConnectNamedPipe
0x44b254 CreateFileA
0x44b25c CreateNamedPipeA
0x44b264 CreateThread
0x44b27c GetCurrentProcess
0x44b284 GetCurrentProcessId
0x44b28c GetCurrentThreadId
0x44b294 GetLastError
0x44b29c GetModuleHandleA
0x44b2a4 GetProcAddress
0x44b2ac GetStartupInfoA
0x44b2bc GetTickCount
0x44b2d4 LoadLibraryW
0x44b2e4 ReadFile
0x44b2ec RtlAddFunctionTable
0x44b2f4 RtlCaptureContext
0x44b304 RtlVirtualUnwind
0x44b314 Sleep
0x44b31c TerminateProcess
0x44b324 TlsGetValue
0x44b334 VirtualAlloc
0x44b33c VirtualProtect
0x44b344 VirtualQuery
0x44b34c WriteFile
Library msvcrt.dll:
0x44b364 __dllonexit
0x44b36c __getmainargs
0x44b374 __initenv
0x44b37c __iob_func
0x44b384 __lconv_init
0x44b38c __set_app_type
0x44b394 __setusermatherr
0x44b39c _acmdln
0x44b3a4 _amsg_exit
0x44b3ac _cexit
0x44b3b4 _fmode
0x44b3bc _initterm
0x44b3c4 _lock
0x44b3cc _onexit
0x44b3d4 _unlock
0x44b3dc abort
0x44b3e4 calloc
0x44b3ec exit
0x44b3f4 fprintf
0x44b3fc free
0x44b404 fwrite
0x44b40c malloc
0x44b414 memcpy
0x44b41c signal
0x44b424 sprintf
0x44b42c strlen
0x44b434 strncmp
0x44b43c vfprintf

!This program cannot be run in DOS mode.
P`.data
.rdata
P@.pdata
0@.xdata
0@.bss
.idata
ffffff.
ATUWVSH
[^_]A\
ATUWVSH
@[^_]A\
ATUWVSH
[^_]A\
ATUWVSH
@[^_]A\
ffffff.
AUATUWVSH
[^_]A\A]
[^_]A\A]
[^_]A\A]
ATWVSH
[^_A\]
ATUWVSH
@[^_]A\
L3d$0H
@[^_]A\
([^_]H
n\ozlt
7B9v3Bt
J;B9o3Bt
H7D=J/
l=Eu^>Gqa
I<D5PkF^
@o7B8jD
qn=0%NWJ
o3BLuN
qn7B%JO
"l;5U<
qn7D=J?
qn=0enL
^b>Fw&
i1De~2J
D;D5J
un6D>v
qn7F5J7
UF;F=J_
6B9N;D
U^7F%JW
h6D$n7F5JG
n7F5JO
n7F5JW
n7F5J_
U>7F-J7
qn7F-JO
:B0o6D
UF7F5J_'UA
qn7D6N
7F5J_'y@
f3B=J?
o3B3l3
Uv7D0f7F=Jw
UF7D0v7F5JO
UF;D=JO
s*L70]
s*L0]
s*L?0]
s*L?0]
s*L/4m
z*|.0]
|*L?0e
h;F-J[
E2i7B"B7D
8pn7Df&
qn7B=J_'
sn7Fv&
d7D0~7
qn7LMf
qn3B|}d
qn=E}n
=0%a'D
;D5io0%iD
qn7D-J/
qn=E}n
=0%M'D
U.6D*^6D
ql=GmO
.gF!~7F9f,
Uv7F=Jw
qn3D<F
;OF,^6
K3D4VL
F!~3F1v3F9N,
GFeV;F5Vo
3D6N7D&V
3D6F7D&.7D<
3D6N7D&^3D
1n7B6F7B>^7F5JG
f3B>.3B6v6D
qn3D6v7D$
UF7D6V7F5J_'
7F5J_'
Uv7F%Jo
oG2o>D
wG2l>0%P'D
qn7B=J70d}E
a7D=J70d
qn7D-JO
6~0dmG
,py}~t
qn:Fw/
qn7B$V>D
3B4V>D
N3B4V>D
./pxsS
e>B3k>Fr]
qn7D-JO
e>B3k>Fr]
qn7D-JO
/LKl:D
qnpK0o
}NpJTl
7B$V>D
3B4V6D
i7B$V2D
3B4V6D
3B4V6D
U>6D*^6D
7~B2lD
=B}.>F8~
=B}.>F8z
>D2j>B
qn7D-JO
qn7D-J/
_7B%J_
i3D*~3D>~
UN7B%JGL
vLSn7B#j
)wF2fL
qn7Btug
7B=J_')o
}7B=J_'
7D:~3D
r7B#j;D
/LHn2D
v;F-J_
qn>Dg&
7D4i3B4
;pF0f7B<
>F:f7D,
qn7B<a
_D3f;D{]
X>B1o>
sn7B#jD
(ug~0r
7D7~?E
}3D>~6L
H2D'~6D&~
l2B#j|
y6D4~|
kGpU7D
7B*f7Dz&
_LSn7D
qn7B$~7B<
U>7B=J/'Qa
qn3B5J/
7B=J/'u
7B=J/'}
qn3B5J/
qn3B5J/
m3B5J/
E3B5J/
qn>DO#
3Jq&p`
(oD}m7
7B=J_'
U.6D*^6D
l7B#j60
7B$A7B<
x7B=J_'
y7B=J_'M
e>LPn2B8j>0
n2B1j7Fp&
U^3F-JW
3D?~>D
po7B8f60
po7B8f70
7B=J_'
o3D8f3D ~7Fp&
o7B8j;
qnFJav
7B}.7BM
UF7D=JG
qn7D%J_
qn7D%J_
B!o7B=J?'
k7D%J'
U7B%J?
U.7B}.7Be
7B=J?'q
qn7D%J_
UN3B5J
7B=J?'
@7D%J_
7F%J''
qn7B=J?
7B}.7B5J
7F5JW'
qn;D5J_
3F5JW'q
qn;D5J_
UV7F%JW
U.7B=J?'A
qn;D5J_
7D%JWF=JC
P7B%J?
UN7B=J?
B9oL94]
UV3D-J'&
7B=J?'
";D5J_
7B=J?'
7B=J?'
:B3u>D
K6D ~7L
i7D>~6D
>B9o>Ds#
qn;BMQ7B<^>D
qn7B$n6D
qn7B$&6D
qn3B4v7B$&7B<^
qn7B%J
qn3B5J
7B$n7B<
7B$v7B<
U>7B4n7B
UF7B4v7F5J_'A
qn6D*N6D
9BuF;D
~>B1o;Fv&
U^3D~;DU
7F5J_'
qn7B%J
qn7D5J
7B=J/'
U>7B=J/'m
7F5J_'
u3B4a7B$I7B<a
7B$I7B<
UN7B=J_
O3B5J_
`7B=J_'
o7D"~:
#7B%J_
7B=J_'
U.6D*^6D
9BUF;D
qD4n2B
7B"j7D
7B=J_'
7B=J_'mh
tqn>B=J;'
uqn>B=J<D
qn7B|Q
3B=J_'
7F f;F0z7D
6B"v7D
N3D5J7
7D:f3B=J/'
qn7B%JO
9zqn>wq^
oD2f3D<
{Y>pn7J
U^;F=JW
qn3B=J
u"pp`&
U>>Du}2
kQ!pn7F2~7Dt]
qn7F2^7Bt
7F2>7Bt
keqqn7F
UV>wsn
[pn6FG/
B$j7B=J_'e
qn:B0u7D
7B=J_'U
qn7B=J_D
7B=J_'
;B6V7B=J
Qfqn:D<j^
{7F=J_
&pn7B<
(pn>D$j7B=J'
$m+L99
N=JGOBn
UV>B u7D
{a)pn7L
*pn7D|
fpu\X{
rn3B5J
zqn7D-J/
qqn;D|
qn7D=J7
{7F=J_
,pn7B<~
%|qn3B
qn6D*~6D
rn7DdA
X7B=J_0d
ULpx-J_
7B=J/F-J/
qn3B=JO
qn7B=JO'
7B=J_'Q;
qn7B=JO
=7B=JO
cqn7B5J7
7F5JWL
6D*^6D
7B=J_'!<
qn7B=J_Fte
qn6D*N6D
qn7B=J_
qn7B=J_
qn7B=J_
Rqn7Ft
7B=J_'i%
qn7B=J_D
}3B4y7Bd
qn6D*~6D
zo6B}v<Gee6L
U&7D2~:
qn7D~"
UV7D~&
qn7F5J_0d
q*px5JM
UV7D~&
g7B%J_'U
U~(w!~
U^>B!l7F
JWF5J_0d
qn7Db*
7F5J'
pn7D%J
U&7D=J
qn>qqf
E~qn7D
7B=J_'
7B=J_'a
U>6D*^6D
qn7D*~7J
Uqn7D.~
qn7B=JO
,zF5JO0
bqn7D-JG
u/D10a81
B'j>wyn
qn7B=J_
qn7D-J/
qn7B=J_uq.
qn7B=J_D
qn7B=J_D
qn7B=J
{Mtpn7D
upn3B5J/
U<3F-J?F5JGF=JOF%JW
pn7B=J
qn7B=J_uq.
qn7B=J_
k!qpn3D
vpn7Bd
{%upn7J
{=vpn7Bd
{]upn7J
qn3B=J?
zpn7D|Y
{-ypn:
{!ypn;D4
qn7B=J?'y_
7B=J?'
7B>l;D
qn7B=JG
7B>l>vpn
qn7B=J
qn7B=J
qn7B=J
U.7F5J7
U>3D<63D5J
2O~G:O
qn>rqj
qn7B=J?
7D%J'F
qn7B=J?
e3Bu@3D
yn7D-JO
l7F=JW
7F9v7B9N
{ihpn3D
hpn7Bd
7F-J_0
UF3F5J_
qn6D*~6D
qn7D-JO
U>3B-J
{qnpn7D
7F5J_0d
UF7F-J_0
qnr?qn7F
k}opn7F
Qpn7Dz
rsn7Dd
qn7L9F
kUQpn3F!~3D'~7F9^
j7D*^7J
{7D.^7Fl%
~~~=~~6
f7B}.:D
qn7B%J?
^v7D2v5F5A_
^V7D2V=L
^>7B=J_
0%UWLUU
7F0~7Bt
qn7F0^7BtMy
_pn7Dz&
U^7D~&
qn7F6~7Bt
UV7F6v7BtM
U^7D>f7D
a7D>f;D
>E'f7D
F3~pqp
U^7Fv&
5J_D5JW
rB!k7D
7B&j7D
qn7D*F7J
F-J_'E
|F"j7D*F7J
7B=JO'Y
{)Opn3B5J
{%Opn7D
qn>spn
7B=JO'
U67D9~7F=J
qn7D>N7B
7D>N7B$
7D*F7J
qn7D-JO
=7D>N7B
7B=J_'
U>7D0~7F5J'
UF7D0~7F5JO
qn7D:~7Dp&
7D0f7F5J
g7B=J_0%J?
qn6D*~6D
pn3D5JG
r3B=JG
Hkuksn
;B3F7B9
7B=J_'
qn7F0N7D
Yn3B8f7D
qn6Fx]
7B=J_'
qn7F0N7D
pn6Dw&
qn7B%J/
a7D>^7F5JW
qn7D&^7D~&
U>7B=JG
3D>f7D6F>OHn7D>^
U>3Bt%
UF7B5J/
pn7F5J_'
'|~G6?9
7D&F7D>v3
U>7B=JG
7D>^7B%J/
qn7B=J/
UV>wqj
D6J7D&F3D>^;D
UV>wqj
UV>wqj
qn7B%J/
}3B=J/
qn3D~&
&|~G6?9
qn3B|!
qn3Bt]
7B=J_'q
UF7Bd)
pn7B=J?'
qn6D*N6D
7B%J_'yn
EvTzV/o
pn7D-J?
qn7w0/>
UVpx1xZ
U>7D%JG
U.7D5JGD1>7F5J
UVpy1~
UV7D=J?'}d
U"7F5J_
UV7D=J?'
U>3D5JG
qn7D%JG
U&;D5J3
qn7B5J
7F5J$i&
qn7D=J?0%J
vpy5JOJ
_DuJpy=JO
UNpxqS2
UN7D=JW
UF7D5JWNI>:
qn7F5Jw
Uf7D1N7F5JW
UFpx1&
q7D5J?
7F5J_$i&
U.pyq&
U.pxuJ
UF7Dq&
1R7D=Jw
N7D5JgDq&
n7D=Jw
s7D5JgDq&
FuJ7D5JG
n7B=JW
UN7B%JG
qn7F0F7B5JW
Uv7F%Jo
U6px1xZ
qn7D5J
7D5J/0a&
qn7D5J
7D5J/0!v7F5JO
7D5JWvq~
UF7D5J'D1>3B=J[
7D5J/0!N7F5JW
Uv7F%Jo
U>3B=J_
Uv7F%Jo
v7D5JGD1:
t7D5JGD1V7D=JO
UVpx1x
T7D5JO
Uv7F%Jo
V7D5J'
U6px1h7F5Jw
qn7DuJ
UF7D=Jg<
U~7Fy&
Uv7F%Jo
7F5J_wyn
qn7D5JGD1b7D
qn7F5J'
0qn7D=J?D8~7
UF7Fp&
f7F5JW
V7D5J7
7F5J_wyn
Uv7D5JgL
n7D=J?
Uf7D5JoD1j7L
f7FuJ7D5Jg
Uf7Duo7
qn7DuJpxq
qn7D}Jpxx
7D=JwDuo|
7DuJpxq
qn7D}Jpxx
Ufpxul|
Fud7DuJ7L
7F5Jo&
qn7F5J/D5J
1R7D=J/
UV7D5JG
U&3D5J/
qn7F5J?
.oG5JO
U>7D%JG
&|0aV
"|0aV
qn7B5J
U^7B%J?
sn>wan
SALsn3Bt
sn3Bte
7B=J_'
7B=J_'
7B=J_'=
ipx5JW$s]
sn7B=J_
ff7B=J_'U
sAPsn7J
qn6D*~6D
UF3B=JO
cASsn2J
qn>LIlpKyn
qn7D|u
{Ansn7Bd53
{-hsn;F|5<
sn;Dt]<
isn;FLu
Vsn;FL
qn7Ft%
kqVsn60
Qsn7D-JO
qn7Fte
3B2o7D
7D-JOBuy7L
N7D(~7D
B'w;B?kL
>B!f3B=J7
pn3B5J7uyn
qn7D=J70d
qn7D|y
osn;B3F
Qn>wQn
mnz0deT
Rsn>wqj
i3BtYP
qn7B=J/
qn7B5J;
U.7F5JO
Lqn3B5J/
7F5JWuqn
7B=J_'m
l>B!o>D
pn7B%J_
qn7B|M
>7D"N>wqf
qn7D-JO
pn7D:~
UF3F=J_
Qn7B=J_
tEud60
rDud6L
z7Dud7Fp&
l>F;o6D
&pys&px;o
l6F;o6D
l6F;l6D
l>F;o6F#k6D
"pys&px3o
f3D=do
v3D=d_
{Dud6L
f7Dud60
N7F0v3F ~7D5dw
7F0f3F`
n<Guo60
s}Esn7D
qn7LT4
pn7B|ae
{q+snL
U~;F5Jg
qopKvo
}7D:F7J
n=Guo60
i"T<a=
&T?9oxD=J
'D>4a860
xD>J70
Uv7F=Jw
j>F/fL
q7Bti:1
.7B%J?
J6D7~7B}v
}>97vw
v7B%JO'
qn7D=JOD
v7B%JO'
qn7D=JOD
v7B%JO'
qn7D=JOD
%f&D9a0
.gF!~7F9f)
g7Bt-r
qn7BlEr
{m2qnL
qopKuo
E;F|uv
qn7Dtes
{!5qn7B=J_D
y7D-J?
7F5J_'Un
E7D"~T
%oE5JOGp
U^7D-JG
qn7Fb&
qnpKwo
~*bfpl
D%J7wq
+D,4a0,5
vOJ^pK
F5J?$S&
7F5J_'-c
U:;F%J7
k%2pn7
{F%J'L
qnpKwo
D%J7wq
+D,4a0,5
vOJ^pK
F5J?$S&
7F5J_'
U:;F%J7
t3B5J_
qn7Fti
qn7B;^70T1
b7B=JO
>F7&;D5
kE%pn7
qn7B%J/
In7D%J/
qn7D-J
In7D%J
BkU&pn
Bkq&pn
BkU'pn7D
BkE(pn7D
Bk5)pn7D
Bkq)pn7D
qn7Bd=
qn7BdY
Bk%*pn7D
qn7Bd]
Bka*pn7D
/px1z:
Qsn7Ft
60a810U
60a800U
qn7F5JW
qn7DtY
F-J_'u!
U^7F5JW
qn7B>w3
B6j;B1
HVpKIo
B*pysa
s>B9o7B2v7
K*pysa
J:B!o>N
kvpy3o:
[A'qn3
U.6D*.6D
7D8V7J
7D:67J
qn7Bti
_D0vL99
e7D-JO
qn7DdM
qn>wq.
qn>wvn
UN3F5JW'
Uv;F5Jo
6D}bp[
U.>vpn
U67B%J
U6pCqo
Qn7BtqQ
ppxr+L"
qn7BtMR
=rD-J7
bsF-J70d
An7B5J
qn7F5J_0d
J3D5J;
d>OOtpK'
i7D0~7Fp&
k3B\%X
qn>G~%
>>G}J4D
7D}_7F
q/pxuJ
7D}_>wsn
E5_wg1
Qn3B=JO
#3B5J7
5De~7D2~
7B=J/0d
qnpK1o
`7B0l7L
UF7Dr&
wG2f7B:~
qn6D*N6D
7LVn7L
sn7B5JG
sn7Dt5i
fpn7F=j_wyn
sn7B5JW
U^7Feo7B|
c3F8f>B1
'wD8j>0
^qn7D4v7F4~
UF7F5J_0d
=Fuo2B1l
{-Cqn7D
Dqn7D|%q
D7B=JO
UV7F=J_
pq5fwL
qn7F2~7D2~
yn7Fr&
qn7B=J?'Q
D9j>vpn
vpx4N>
QUbBNl
k2Ppn}
kq@pn7
qn>wqj
x7B:~7
qn7F-JW
U^;F=JW
7B=J?'!n
qn3D5J?
qn7F=J_
qn>~ua
#!+L98
UF7D5JO
b7D=J?L
U&7B%J?
Jc)Dpn
Jc=Dpn
Jc9Dpn
JcMDpn
# F5JOD4
yf_vqn
# F5JOD4
$C&T8~
qnpy~&
b7D5JOL
qn7D-Jw
qnpyuV
#oD3j7D
U~7F=Jw
pfZ0qn
py=dwN
l7D%JOFud
n7F5J?D=JW'
U^3D5JO
bwDulL
juD5J_0
}7D5JO
py=doN
py=doN
U^7D%J7D}
h7D%JOFud
U^>D}f
i7D%JO
f7D%JOFud
U^>D}f
U^3D5JO
bwDulL
py=dkN
py=dkN
prZ0qn
py=dcN
i7D%JOFud7D
qn7D=JO
n7F5J/D=JW'
U^3D5JO
bwDulL
juD5J_0
e7D=JODuo
b7D%JOFud
U^>D}f
c7D%JO
`7D%JOFud
U^>D}f
U^7D=JGDx
j7F5JG
j7F5JO
U^7D=JGDx
j7F5JG
b7F5JO
uD5J_0
~7F5JG
n7D=JGDuo
n7D%JOFud
j~F5JWD5JW
#qn>De
U^7D5JO
U^7D5JG
f7D5JO
UV7D5JO
U^7D5JG
U~7F=Jw
n7D=J?
U.py}d
m7D%J?
j~D}JL
n7D=J?
U.py=d{N
U.py=d{N
F5J{wun
U.py5ow
l7D%J?
j~D=Jw
F5Jwwpn
pbZ0qn
U.py=dsN
m7D=J_Duo
BjuF5JoD5J{
k7D%J_
k%tqn>De
uqn>De
j[D5Jk
BjuF5J{D5Jg
BjuF5JwD5Jc
BjuF5Js&
juDuJZ0qn
UjZ0qn
n7D%J7G5dwD5Jw
l7D%J7G5dwD5Jw
m7D%J_
m7D%J7G5ds
U~7F=Jw
qn7F5J_wpn
o7D%J?
pjZ0qn
U.py=d{N
o7D=J_Duo
o7D%J?
m7D%J?
n7D=J?
U.py=dsN
U.py=dsN
F5Jswun
BjuF5JgD5Js
i7D%J_
Ur7D5J_
n7D%J_
juDuJZ0qn
o7D%J_
m7D%J7G5d{D5Jg
n7D%J7G5dwD5Jw
l7D%J7G5dwD5Jw
UbZ0qn
vD5J_&Hl
qn>wan
qn3B5J?
y97D5JoLI~
F7D5JoLIN
qn:GUh7D<&60
7Bu/3D
UF7F5J_0d9S
D5JOD=JK
D5JOD=JK
UF7D%Tw'
qn7DX&
qn7Fr&
kaXpn7J
qn7Ftq
qn7DD}
qn7B}h
47D%JW
b7D=JOL
U^3B=J_
npy5J
U.3B=J_
npy5J
U>>wuo
UF7F5J_0d
;7D%J7L
b7D5J/L
3B-JD
3"T80a
smDpn7D
UF7F5J_0dmg
{7B|QC
qn>vpn
7F5J_0
UZ7F5JW
qn7F5J_0
qn7B}>7Bd
qn6D*N6D
;B6^7B$
qnpx49D
UF>Fv&
7F$~3D
<3D4f;D
J_0dur
qnpyuV
k]} nzP
)BgB*4
"q@E62
^Njq^@
\7'BFu
Y;^0CC
ZQ(bc`
A>/Gqn
q.{Opn
qy|Opn
ay|Opn
Qy|Opn
Ay|Opn
1y|Opn
!y|Opn
qv|Opn
av|Opn
uO|Opn
Yv|Opn
QO|Opn
Iv|Opn
9v|Opn
YO|Opn
)v|Opn
AO|Opn
IO|Opn
1O|Opn
yw|Opn
iw|Opn
Yw|Opn
Iw|Opn
9w|Opn
)w|Opn
9O|Opn
yt|Opn
it|Opn
Yt|Opn
It|Opn
9t|Opn
)t|Opn
!O|Opn
yu|Opn
iu|Opn
)O|Opn
Yu|Opn
Iu|Opn
9u|Opn
)u|Opn
yr|Opn
ir|Opn
Yr|Opn
Ir|Opn
9r|Opn
)r|Opn
ys|Opn
is|Opn
Ys|Opn
Is|Opn
9s|Opn
)s|Opn
yp|Opn
ip|Opn
Yp|Opn
Ip|Opn
9p|Opn
)p|Opn
yq|Opn
Qq|Opn
Iq|Opn
!q|Opn
yN|Opn
iN|Opn
YN|Opn
1N|Opn
)N|Opn
uO|Opn
aO|Opn
QO|Opn
YO|Opn
AO|Opn
IO|Opn
1O|Opn
9O|Opn
!O|Opn
)O|Opn
<-k<UD
#2U$]L
>/o5RC
*;GHyh
3"uZwf
0!slet
'6]{hy
&7_tm|
:$TK@I
5_/t4+s
]B8o&b)
E"@KR$
IZ\7"`p
SR</j|b
~8GJLp
B8o&I5f(T"}:_/t4
ac"@KR/IEY8RWD5[YO~,
-d>0i7
Z\7"SR</H@!8AN*5
snH~gZ
du~8GJp3JCb.]Xl%PQ6L
6_:'F
h\j/pxu
d\n?pj~
a\s/pss
d<n/pay
d\n/pd}
h<j?pa{
a\s/`{w
h<j/pay
_CQa_DQ
#7#<z&
qM|Opn
aG|Opn
0uK|Opn
qM|Opn
sK|Opn
_set_invalid_parameter_handler
%c%c%c%c%c%c%c%c%cMSSE-%d-server
.pdata
Argument domain error (DOMAIN)
Argument singularity (SIGN)
Overflow range error (OVERFLOW)
Partial loss of significance (PLOSS)
Total loss of significance (TLOSS)
The result is too small to be represented (UNDERFLOW)
Unknown error
_matherr(): %s in %s(%g, %g) (retval=%g)
Mingw-w64 runtime failure:
Address %p has no image-section
VirtualQuery failed for %d bytes at address %p
VirtualProtect failed with code 0x%x
Unknown pseudo relocation protocol version %d.
Unknown pseudo relocation bit size %d.
CloseHandle
ConnectNamedPipe
CreateFileA
CreateNamedPipeA
CreateThread
DeleteCriticalSection
EnterCriticalSection
GetCurrentProcess
GetCurrentProcessId
GetCurrentThreadId
GetLastError
GetModuleHandleA
GetProcAddress
GetStartupInfoA
GetSystemTimeAsFileTime
GetTickCount
InitializeCriticalSection
LeaveCriticalSection
LoadLibraryW
QueryPerformanceCounter
ReadFile
RtlAddFunctionTable
RtlCaptureContext
RtlLookupFunctionEntry
RtlVirtualUnwind
SetUnhandledExceptionFilter
TerminateProcess
TlsGetValue
UnhandledExceptionFilter
VirtualAlloc
VirtualProtect
VirtualQuery
WriteFile
__C_specific_handler
__dllonexit
__getmainargs
__initenv
__iob_func
__lconv_init
__set_app_type
__setusermatherr
_acmdln
_amsg_exit
_cexit
_fmode
_initterm
_onexit
_unlock
calloc
fprintf
fwrite
malloc
memcpy
signal
sprintf
strlen
strncmp
vfprintf
KERNEL32.dll
msvcrt.dll
msvcrt.dll
Antivirus Signature
Bkav Clean
Lionic Trojan.Win64.CobaltStrike.4!c
Elastic malicious (high confidence)
Cynet Malicious (score: 100)
CMC Clean
CAT-QuickHeal Trojan.CobaltStr.S17675256
ALYac Trojan.Generic.30221711
Malwarebytes Trojan.CobaltStrike
VIPRE Clean
Sangfor Trojan.Win32.CobaltStrike
CrowdStrike win/malicious_confidence_100% (W)
Alibaba Trojan:Win32/CozyDuke.1012
K7GW Trojan ( 00580c281 )
K7AntiVirus Trojan ( 00580c281 )
BitDefenderTheta Clean
Cyren W64/Cobalt.A.gen!Eldorado
Symantec Backdoor.Cobalt!gen1
ESET-NOD32 a variant of Win64/CobaltStrike.Artifact.A
Baidu Clean
APEX Malicious
Paloalto generic.ml
ClamAV Win.Trojan.CobaltStrike-9044898-1
Kaspersky HEUR:Trojan.Win64.CobaltStrike.gen
BitDefender Trojan.Generic.30221711
NANO-Antivirus Trojan.Win64.Meterpreter.jclyeh
SUPERAntiSpyware Clean
MicroWorld-eScan Trojan.Generic.30221711
Rising Backdoor.CobaltStrike/x64!1.D04A (CLASSIC)
Ad-Aware Trojan.Generic.30221711
Emsisoft Trojan.Generic.30221711 (B)
Comodo Clean
F-Secure Clean
DrWeb BackDoor.Meterpreter.157
Zillya Clean
TrendMicro Backdoor.Win64.COBEACON.SMA
McAfee-GW-Edition BehavesLike.Win64.Generic.dc
FireEye Generic.mg.c354ad2705debb7a
Sophos ML/PE-A + ATK/Cobalt-CC
SentinelOne Static AI - Malicious PE
GData Trojan.Generic.30221711
Jiangmin Trojan.Generic.fsici
Webroot W32.Riskware.Cobaltstrike
Avira HEUR/AGEN.1137815
Antiy-AVL Trojan/Generic.ASMalwS.30B56F3
Kingsoft Win32.Troj.Undef.(kcloud)
Gridinsoft Trojan.Win64.Agent.oa!s1
Arcabit Trojan.Generic.D1CD258F
ViRobot Trojan.Win32.Z.Cobaltstrike.288256.NF
ZoneAlarm Clean
Microsoft Trojan:Win32/Cobaltstrike.MK!MTB
TACHYON Trojan/W64.CobaltStrike.288256
AhnLab-V3 Trojan/Win64.CobaltStrike.R356638
Acronis Clean
McAfee Trojan-FSXF!C354AD2705DE
MAX malware (ai score=100)
VBA32 Trojan.Win64.CobaltStrike
Cylance Unsafe
Panda Clean
Zoner Clean
TrendMicro-HouseCall Backdoor.Win64.COBEACON.SMA
Tencent Hacktool.Win32.CobaltStrike.zb
Yandex Trojan.GenAsa!ZICJWVi3Ujg
Ikarus Trojan.Agent
eGambit Clean
Fortinet W64/Agent.CY!tr
AVG Win64:HacktoolX-gen [Trj]
Avast Win64:HacktoolX-gen [Trj]
MaxSecure Clean
No IRMA results available.