Static | ZeroBOX

PE Compile Time

2021-10-03 13:43:10

PE Imphash

9918cb366b12f5b74bee942024cd344c

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x00051caf 0x00051e00 6.28176638698
.rdata 0x00053000 0x0000ad4e 0x0000ae00 5.01064349999
.data 0x0005e000 0x000017ec 0x00000c00 2.81492166028
.rsrc 0x00060000 0x000001e8 0x00000200 4.7561464322
.reloc 0x00061000 0x00002584 0x00002600 6.56431588428

Resources

Name Offset Size Language Sub-language File type
RT_MANIFEST 0x00060060 0x00000188 LANG_ENGLISH SUBLANG_ENGLISH_US XML 1.0 document text

Imports

Library KERNEL32.dll:
0x453038 lstrcatA
0x45303c GetModuleHandleA
0x453040 lstrcpyA
0x453044 HeapFree
0x453048 IsWow64Process
0x45304c HeapAlloc
0x453050 GetProcAddress
0x453054 lstrcpynA
0x453058 GetProcessHeap
0x45305c WriteConsoleW
0x453060 CreateDirectoryA
0x453064 WinExec
0x453068 LocalFree
0x453070 CloseHandle
0x453074 DeleteFileA
0x453078 LoadLibraryA
0x45307c GetFileAttributesA
0x453080 GetLastError
0x453084 CopyFileA
0x453088 Sleep
0x45308c LocalAlloc
0x453094 GetCurrentProcess
0x453098 lstrlenA
0x45309c GetModuleFileNameA
0x4530a0 SetEndOfFile
0x4530a4 HeapReAlloc
0x4530a8 HeapSize
0x4530ac ReadConsoleW
0x4530b0 ReadFile
0x4530b4 FlushFileBuffers
0x4530b8 CreateFileW
0x4530bc GetStringTypeW
0x4530c0 SetStdHandle
0x4530cc TerminateProcess
0x4530d4 IsDebuggerPresent
0x4530d8 GetStartupInfoW
0x4530dc GetModuleHandleW
0x4530e4 GetCurrentProcessId
0x4530e8 GetCurrentThreadId
0x4530f0 InitializeSListHead
0x4530f4 RtlUnwind
0x4530f8 RaiseException
0x4530fc SetLastError
0x453100 EncodePointer
0x453114 TlsAlloc
0x453118 TlsGetValue
0x45311c TlsSetValue
0x453120 TlsFree
0x453124 FreeLibrary
0x453128 LoadLibraryExW
0x45312c ExitProcess
0x453130 GetModuleHandleExW
0x453134 GetModuleFileNameW
0x453138 GetStdHandle
0x45313c WriteFile
0x453140 MultiByteToWideChar
0x453144 LCMapStringW
0x453148 MoveFileExW
0x45314c GetFileType
0x453150 GetConsoleOutputCP
0x453154 GetConsoleMode
0x453158 GetFileSizeEx
0x45315c SetFilePointerEx
0x453160 FindClose
0x453164 FindFirstFileExW
0x453168 FindNextFileW
0x45316c IsValidCodePage
0x453170 GetACP
0x453174 GetOEMCP
0x453178 GetCPInfo
0x45317c GetCommandLineA
0x453180 GetCommandLineW
0x453184 WideCharToMultiByte
0x453190 DecodePointer
Library ADVAPI32.dll:
0x453000 CreateServiceA
0x453004 RegCloseKey
0x453010 CloseServiceHandle
0x453014 RegQueryValueExA
0x453018 SetServiceStatus
0x453020 OpenSCManagerA
0x453024 GetUserNameA
0x453028 StartServiceA
0x45302c RegOpenKeyExA
0x453030 OpenServiceA
Library SHELL32.dll:
0x4531b0 SHGetFolderPathA
0x4531b4 ShellExecuteA
Library SETUPAPI.dll:

!This program cannot be run in DOS mode.
'Rich
`.rdata
@.data
@.reloc
 !!"!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!#!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$%&&&&&&&&&&&&'&&()))*f
QQSVWd
URPQQh
;t$,v-
UQPXY]Y[
<xt<Xt
F4_^[]
<ItC<Lt3<Tt#<h
A<lt'<tt
<at.<rt!<wt
<=upG8
[ShtTE
[Sh|TE
u,PQRS
Wj0XPV
SPjdVQ
zSSSSj
f9:t!V
QQSVj8j@
CY<u
D8(Ht'
PPPPPPPP
PPPPPWS
PP9E u:PPVWP
bad allocation
bad function call
bad exception
__based(
__cdecl
__pascal
__stdcall
__thiscall
__fastcall
__vectorcall
__clrcall
__eabi
__swift_1
__swift_2
__ptr64
__restrict
__unaligned
restrict(
delete
operator
`vftable'
`vbtable'
`vcall'
`typeof'
`local static guard'
`string'
`vbase destructor'
`vector deleting destructor'
`default constructor closure'
`scalar deleting destructor'
`vector constructor iterator'
`vector destructor iterator'
`vector vbase constructor iterator'
`virtual displacement map'
`eh vector constructor iterator'
`eh vector destructor iterator'
`eh vector vbase constructor iterator'
`copy constructor closure'
`udt returning'
`local vftable'
`local vftable constructor closure'
new[]
delete[]
`omni callsig'
`placement delete closure'
`placement delete[] closure'
`managed vector constructor iterator'
`managed vector destructor iterator'
`eh vector copy constructor iterator'
`eh vector vbase copy constructor iterator'
`dynamic initializer for '
`dynamic atexit destructor for '
`vector copy constructor iterator'
`vector vbase copy constructor iterator'
`managed vector copy constructor iterator'
`local static thread guard'
operator ""
operator co_await
operator<=>
Type Descriptor'
Base Class Descriptor at (
Base Class Array'
Class Hierarchy Descriptor'
Complete Object Locator'
`anonymous namespace'
FlsAlloc
FlsFree
FlsGetValue
FlsSetValue
InitializeCriticalSectionEx
[aOni*{
~ $s%r
@b;zO]
v2!L.2
IND)ind)
(null)
CorExitProcess
Sunday
Monday
Tuesday
Wednesday
Thursday
Friday
Saturday
January
February
August
September
October
November
December
MM/dd/yy
dddd, MMMM dd, yyyy
HH:mm:ss
UTF-16LEUNICODE
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
AreFileApisANSI
LCMapStringEx
LocaleNameToLCID
AppPolicyGetProcessTerminationMethod
NAN(SNAN)
nan(snan)
NAN(IND)
nan(ind)
1#QNAN
1#SNAN
?5Wg4p
%S#[k=
"B <1=
_hypot
_nextafter
Unknown exception
bad array new length
ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/
type must be boolean, but is
type must be number, but is
type must be number, but is
type must be number, but is
type must be string, but is
0123456789abcdef
vector too long
string too long
map/set too long
[json.exception.
parse error
parse_error
, column
at line
invalid_iterator
type_error
out_of_range
other_error
abcdefghijklmnopqrstuvwxyz0123456789_ABCDEFGHIJKLMNOPQRSTUVWXYZ
invalid string position
cannot use operator[] with a string argument with
cannot get value
961c151d2e87f2686a955a9be24d316f1362bf21 3.9.1
object
string
boolean
binary
discarded
number
syntax error
while parsing
; last read: '
unexpected
; expected
<U+%.4X>
cannot compare iterators of different containers
invalid BOM; must be 0xEF 0xBB 0xBF if given
invalid literal
<uninitialized>
true literal
false literal
null literal
string literal
number literal
<parse error>
end of input
'[', '{', or a literal
unknown token
invalid number; expected digit after '-'
invalid number; expected digit after '.'
invalid number; expected '+', '-', or digit after exponent
invalid number; expected digit after exponent sign
invalid comment; missing closing '*/'
invalid comment; expecting '/' or '*' after '/'
invalid string: missing closing quote
invalid string: '\u' must be followed by 4 hex digits
invalid string: surrogate U+D800..U+DBFF must be followed by U+DC00..U+DFFF
invalid string: surrogate U+DC00..U+DFFF must follow U+D800..U+DBFF
invalid string: forbidden character after backslash
invalid string: control character U+0000 (NUL) must be escaped to \u0000
invalid string: control character U+0001 (SOH) must be escaped to \u0001
invalid string: control character U+0002 (STX) must be escaped to \u0002
invalid string: control character U+0003 (ETX) must be escaped to \u0003
invalid string: control character U+0004 (EOT) must be escaped to \u0004
invalid string: control character U+0005 (ENQ) must be escaped to \u0005
invalid string: control character U+0006 (ACK) must be escaped to \u0006
invalid string: control character U+0007 (BEL) must be escaped to \u0007
invalid string: control character U+0008 (BS) must be escaped to \u0008 or \b
invalid string: control character U+0009 (HT) must be escaped to \u0009 or \t
invalid string: control character U+000A (LF) must be escaped to \u000A or \n
invalid string: control character U+000B (VT) must be escaped to \u000B
invalid string: control character U+000C (FF) must be escaped to \u000C or \f
invalid string: control character U+000D (CR) must be escaped to \u000D or \r
invalid string: control character U+000E (SO) must be escaped to \u000E
invalid string: control character U+000F (SI) must be escaped to \u000F
invalid string: control character U+0010 (DLE) must be escaped to \u0010
invalid string: control character U+0011 (DC1) must be escaped to \u0011
invalid string: control character U+0012 (DC2) must be escaped to \u0012
invalid string: control character U+0013 (DC3) must be escaped to \u0013
invalid string: control character U+0014 (DC4) must be escaped to \u0014
invalid string: control character U+0015 (NAK) must be escaped to \u0015
invalid string: control character U+0016 (SYN) must be escaped to \u0016
invalid string: control character U+0017 (ETB) must be escaped to \u0017
invalid string: control character U+0018 (CAN) must be escaped to \u0018
invalid string: control character U+0019 (EM) must be escaped to \u0019
invalid string: control character U+001A (SUB) must be escaped to \u001A
invalid string: control character U+001B (ESC) must be escaped to \u001B
invalid string: control character U+001C (FS) must be escaped to \u001C
invalid string: control character U+001D (GS) must be escaped to \u001D
invalid string: control character U+001E (RS) must be escaped to \u001E
invalid string: control character U+001F (US) must be escaped to \u001F
invalid string: ill-formed UTF-8 byte
vector<bool> too long
object key
object separator
number overflow parsing '
excessive array size:
excessive object size:
iterator does not fit current value
iterator out of range
cannot use erase() with
.text$di
.text$mn
.text$x
.text$yd
.idata$5
.00cfg
.CRT$XCA
.CRT$XCAA
.CRT$XCU
.CRT$XCZ
.CRT$XIA
.CRT$XIAA
.CRT$XIAC
.CRT$XIC
.CRT$XIZ
.CRT$XPA
.CRT$XPX
.CRT$XPXA
.CRT$XPZ
.CRT$XTA
.CRT$XTZ
.rdata
.rdata$r
.rdata$sxdata
.rdata$zzzdbg
.rtc$IAA
.rtc$IZZ
.rtc$TAA
.rtc$TZZ
.xdata$x
.idata$2
.idata$3
.idata$4
.idata$6
.data$r
.rsrc$01
.rsrc$02
GetModuleFileNameA
GetCurrentProcess
GetVolumeInformationA
LocalAlloc
CopyFileA
GetLastError
GetFileAttributesA
LoadLibraryA
DeleteFileA
CloseHandle
GetWindowsDirectoryA
LocalFree
WinExec
CreateDirectoryA
IsWow64Process
lstrcatA
GetModuleHandleA
lstrcpyA
HeapFree
lstrlenA
HeapAlloc
GetProcAddress
lstrcpynA
GetProcessHeap
KERNEL32.dll
OpenServiceA
RegOpenKeyExA
StartServiceA
GetUserNameA
OpenSCManagerA
RegisterServiceCtrlHandlerA
SetServiceStatus
RegQueryValueExA
CloseServiceHandle
GetCurrentHwProfileA
StartServiceCtrlDispatcherA
RegCloseKey
CreateServiceA
ADVAPI32.dll
SHGetSpecialFolderPathA
ShellExecuteA
SHGetFolderPathA
SHELL32.dll
SetupDiEnumDeviceInterfaces
SetupDiGetClassDevsA
SetupDiGetDeviceInterfaceDetailA
SetupDiEnumDeviceInfo
SETUPAPI.dll
UnhandledExceptionFilter
SetUnhandledExceptionFilter
TerminateProcess
IsProcessorFeaturePresent
IsDebuggerPresent
GetStartupInfoW
GetModuleHandleW
QueryPerformanceCounter
GetCurrentProcessId
GetCurrentThreadId
GetSystemTimeAsFileTime
InitializeSListHead
RtlUnwind
RaiseException
SetLastError
EncodePointer
EnterCriticalSection
LeaveCriticalSection
DeleteCriticalSection
InitializeCriticalSectionAndSpinCount
TlsAlloc
TlsGetValue
TlsSetValue
TlsFree
FreeLibrary
LoadLibraryExW
ExitProcess
GetModuleHandleExW
GetModuleFileNameW
GetStdHandle
WriteFile
MultiByteToWideChar
LCMapStringW
MoveFileExW
GetFileType
GetConsoleOutputCP
GetConsoleMode
GetFileSizeEx
SetFilePointerEx
FindClose
FindFirstFileExW
FindNextFileW
IsValidCodePage
GetACP
GetOEMCP
GetCPInfo
GetCommandLineA
GetCommandLineW
WideCharToMultiByte
GetEnvironmentStringsW
FreeEnvironmentStringsW
SetStdHandle
GetStringTypeW
CreateFileW
FlushFileBuffers
ReadFile
ReadConsoleW
HeapSize
HeapReAlloc
SetEndOfFile
WriteConsoleW
DecodePointer
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
.?AVlogic_error@std@@
.?AVlength_error@std@@
.?AVout_of_range@std@@
.?AVbad_function_call@std@@
.?AVtype_info@@
.?AVbad_exception@std@@
.?AVbad_alloc@std@@
.?AVexception@std@@
.?AVbad_array_new_length@std@@
.?AVruntime_error@std@@
.?AVother_error@detail@nlohmann@@
.?AVexception@detail@nlohmann@@
.?AVinvalid_iterator@detail@nlohmann@@
.?AVtype_error@detail@nlohmann@@
.?AVout_of_range@detail@nlohmann@@
.?AVparse_error@detail@nlohmann@@
<?xml version='1.0' encoding='UTF-8' standalone='yes'?>
<assembly xmlns='urn:schemas-microsoft-com:asm.v1' manifestVersion='1.0'>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v3">
<security>
<requestedPrivileges>
<requestedExecutionLevel level='requireAdministrator' uiAccess='false' />
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
1,2C2L2U2o2
6#6f6x6
:%:f:x:
=6>P>{>
&050P0
5:6F6h7
8,9J9S9
:P;V;d;
=O>g>v>
?+?9?U?`?
7!7a8y8
9#979i9
060E0T0c0r0
1`3k3]6h6
6,777\7c7h8
:#=.=V=]=R>\>~>
8#939Y9
3,3;3J3X3
4 4&464e4Z5r5
=#>;>J>Y>h>w>
?(?J?b?q?
2(272E2
7)8Q8a8
0(080W0
5;9G9:;D;
?=?H?R?\?f?p?z?
D0N0S0Y0g0p0v0}0
0+0d0[7
2*8:8f8
w1f3u3(4^4
44:6;I;4<t=
f0u0G3|3
V1l1L4v5
1!1(1/161=1D1L1P1T1X1\1`1d1h1l1p1
668H8f8
;';0;9;B;K;T;];f;o;x;
;(</<;<D<M<V<_<h<q<z<
6 6$6f7x7
> >4>8><>@>|>
>.?5?m?
00)0e0l0M1
4+4?4S4g4{4
5/5C5W5k5
659L9P9T9X9\9`9d9h9l9p9t9x9|9
6H6f6x6
:%=0?4?8?<?@?D?H?L?P?T?X?\?`?d?
V0e0W1F2U2g3j4g5v6
5&888s9
1&252&858
&181W1
8&959V:e:
;6<E<&>5>
5F6U6F8X8
8V:e:V;i;H<
43U3[3i3
1D2d2m3
3&454\4
9W;f=u=V>e>
5U8o8t8
8V;p;u;
;W>q>v>
4J5O5_7d7t9y9
9M:z:1;a;
D0z041g1#2Y2
A0t021h1&2\2
0 0a0g0|0
1,1C1t1
2!2'2-23292@2G2N2U2\2c2j2r2z2
2 3&3,32383>3E3L3S3Z3a3h3o3w3
5"5(5=5R5Y5_5q5{5
9#:-:6:?:T:]:
>0>V>_>e>m>r>
::1:>:`:
:P;1<R<`<f<
6+616X6
;8;X;f;m;s;
=-=9=H=`=
>>$>?>I>U>Z>_>z>
1&2k2p2t2x2|2
8+9094989<9
<*=;=F=
4^5f5a6i6
<%<\<c<m?
$1,1W1^1
:/;B;W;
1-2125292=2A2E2I2 7'7L7P7T7X7\7
1-1E1`1k1
2I3\3e3r3
5505B5Q5
91:R:m:}:
>*>D>}>
?*?;?@?N?\?c?k?
8"9)9J9s9
:3:C:P:y:
;(;2;T;e;z;
<%<5<J<a<
&0D0b0
3!4+4F4
4[5u5z5
78*8/848D8I8N8^8c8h8
89K9T9
:':,:1:L:V:f:k:p:
;&;+;0;Q;a;
<0<B<N<h<r<
>!?X?j?
%050V0r0
<(=/=:=H=O=U=p=w=
7M7T7[7b7|7
8J8r8a:
:(;t;};
=1>6><>A>
)000:0^0
1f1m1t1{1
3$3<3h3
5E5L5c5y5
646G6Q6j6
6+7A7|7
8 8A8S8e8w8
9:9L9^9p9
;%>0>C>M>k>v>
6P6e6v6
4*575F5
:%:G:Q:
5%505@5y5
6+8G8w8
:=;W;d;
=.=<=M=e=k=w=
>!>)>1>9>W>_>
6,6=6E6U6f6
6!707<7K7^7}7
8'8R8t8
\1d2u2Y5
:!;2;C;m;
<!<%<)<-<1<5<9<=<A<E<I<M<Q<f<
9 :E:e:
7%7E7e7
2 2$2(2,20242H2L2P2h2l2p2t2x2|2
3 3(30383@3H3P3X3`3h3p3x3
4 4(40484@4H4P4X4`4h4p4x4
5 5(50585@5H5P5X5`5h5p5x5
6 6(60686@6H6P6x<|<
0?8?@?D?H?L?P?T?X?\?d?h?l?p?t?x?|?
0 0$0(0,0004080<0@0D0H0L0P0T0X0d0h0l0p0t0x0|0
004080<0|0
1$1,141<1D1L1T1\1d1l1t1|1
2$2,242<2D2L2T2\2d2l2t2|2
3$3,343<3D3L3T3\3d3l3t3|3
4$4,444<4D4L4T4\4d4l4t4|4
5$5,545<5D5L5T5\5d5l5t5|5
6$6,646<6D6L6T6\6d6l6t6|6
7$7,747<7D7L7T7\7d7l7t7|7
2 2(20282@2H2P2X2`2h2p2x2
3 3(30383@3H3P3X3`3h3p3x3
4 4(40484@4H4P4X4`4h4p4x4
5 5(50585@5H5P5X5`5h5p5x5
6 6(60686@6H6P6X6`6h6p6x6
7 7(70787@7H7P7X7`7h7p7x7
8 8(80888@8H8P8X8`8h8p8x8
<$<,<4<<<D<L<T<\<d<l<t<|<
7(7,70787P7`7d7t7x7|7
8$8<8L8P8`8d8l8
9 989<9P9`9d9t9
:0:@:P:T:l:p:t:x:
; ;$;(;@;P;T;X;p;t;x;
0,1L1T1\1d1p1
2(20282@2H2P2\2|2
3$3,343<3D3L3T3\3d3l3t3|3
444<4D4L4T4\4d4l4t4|4
5$5,545<5D5L5T5\5d5l5t5|5
6$6,646<6D6L6T6`6
7$7,747<7D7L7T7\7d7l7t7|7
8(8H8T8t8
9$909P9X9`9h9p9|9
:L:\:h:
; ;@;L;l;t;|;
<$<0<P<\<|<
=4=@=d=l=t=|=
>$>,>4><>D>L>T>\>d>l>t>|>
?$?,?4?<?D?L?T?\?d?l?t?|?
0<0H0h0t0|0
1 1(141T1\1h1
2,282X2`2l2t2
3 3(343T3`3
484D4d4p4x4
5 5(5\5l5x5
6(606d6t6
7,787X7d7
8<8D8P8p8x8
9$9,989X9`9h9p9x9
:8:D:d:p:
;0;8;@;H;L;P;X;l;t;|;
< <<<@<`<h<l<
=$=(=0=8=@=D=L=`=
> >@>`>
? ?@?`?
0 0@0`0
1 1@1\1`1|1
2 2(2<2D2X2`2d2h2p2t2x2
3,343<3
@0D0H0L0P0T0X0\0`0d0p0t0x0|0
1(1@1L1P1T1p1t1
9 9@9`9
jjjjjj
Eapi-ms-win-core-fibers-l1-1-1
api-ms-win-core-synch-l1-2-0
kernel32
api-ms-
minkernel\crts\ucrt\inc\corecrt_internal_strtox.h
__crt_strtox::floating_point_value::as_double
_is_double
__crt_strtox::floating_point_value::as_float
!_is_double
(null)
mscoree.dll
Sunday
Monday
Tuesday
Wednesday
Thursday
Friday
Saturday
January
February
August
September
October
November
December
MM/dd/yy
dddd, MMMM dd, yyyy
HH:mm:ss
((((( H
Eapi-ms-win-core-datetime-l1-1-1
api-ms-win-core-file-l1-2-2
api-ms-win-core-localization-l1-2-1
api-ms-win-core-localization-obsolete-l1-2-0
api-ms-win-core-processthreads-l1-1-2
api-ms-win-core-string-l1-1-0
api-ms-win-core-sysinfo-l1-2-1
api-ms-win-core-winrt-l1-1-0
api-ms-win-core-xstate-l2-1-0
api-ms-win-rtcore-ntuser-window-l1-1-0
api-ms-win-security-systemfunctions-l1-1-0
ext-ms-win-ntuser-dialogbox-l1-1-0
ext-ms-win-ntuser-windowstation-l1-1-0
advapi32
api-ms-win-appmodel-runtime-l1-1-2
user32
ext-ms-
Eja-JP
zh-CHS
az-AZ-Latn
uz-UZ-Latn
kok-IN
syr-SY
div-MV
quz-BO
sr-SP-Latn
az-AZ-Cyrl
uz-UZ-Cyrl
quz-EC
sr-SP-Cyrl
quz-PE
smj-NO
bs-BA-Latn
smj-SE
sr-BA-Latn
sma-NO
sr-BA-Cyrl
sma-SE
sms-FI
smn-FI
zh-CHT
az-az-cyrl
az-az-latn
bs-ba-latn
div-mv
kok-in
quz-bo
quz-ec
quz-pe
sma-no
sma-se
smj-no
smj-se
smn-fi
sms-fi
sr-ba-cyrl
sr-ba-latn
sr-sp-cyrl
sr-sp-latn
syr-sy
uz-uz-cyrl
uz-uz-latn
zh-chs
zh-cht
CONOUT$
Content-Type: application/x-www-form-urlencoded
Content-Type: application/x-www-form-urlencoded
Content-Type: application/x-www-form-urlencoded
Content-Type: application/x-www-form-urlencoded
Content-Type: application/x-www-form-urlencoded
Content-Type: application/x-www-form-urlencoded
Content-Type: application/x-www-form-urlencoded
https://ipinfo.io/
Content-Type: application/x-www-form-urlencoded
https://db-ip.com/
https://ipgeolocation.io/
https://www.maxmind.com/en/locate-my-ip-address
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36
Antivirus Signature
Bkav Clean
Lionic Trojan.Win32.Disbuk.i!c
Elastic malicious (high confidence)
MicroWorld-eScan Trojan.GenericKD.37711236
FireEye Generic.mg.477b1b2a2779f1a1
CAT-QuickHeal Clean
ALYac Trojan.GenericKD.37711236
Cylance Unsafe
VIPRE Clean
Sangfor Suspicious.Win32.Save.a
K7AntiVirus Trojan-Downloader ( 005820621 )
BitDefender Trojan.GenericKD.37711236
K7GW Trojan-Downloader ( 005820621 )
Cybereason Clean
BitDefenderTheta Gen:NN.ZexaF.34170.yuW@ae8rCcpi
Cyren Clean
Symantec ML.Attribute.HighConfidence
ESET-NOD32 a variant of Win32/TrojanDownloader.Agent.FWC
Baidu Clean
APEX Malicious
Paloalto generic.ml
Cynet Malicious (score: 100)
Kaspersky HEUR:Trojan-PSW.Win32.Disbuk.gen
Alibaba TrojanPSW:Win32/Disbuk.b3eb2291
NANO-Antivirus Clean
ViRobot Trojan.Win32.Z.Agent.394240.MC
Rising Downloader.Agent!1.D93C (CLASSIC)
Ad-Aware Trojan.GenericKD.37711236
Sophos Mal/Generic-S
Comodo Clean
F-Secure Clean
DrWeb Trojan.PWS.Stealer.31121
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition GenericRXMT-VE!477B1B2A2779
CMC Clean
Emsisoft Trojan.GenericKD.37711236 (B)
SentinelOne Static AI - Malicious PE
GData Trojan.GenericKD.37711236
Jiangmin Clean
Webroot W32.Malware.Gen
Avira TR/Dldr.Agent.njxyo
MAX malware (ai score=82)
Antiy-AVL Clean
Kingsoft Clean
Gridinsoft Malware.Win32.GenericMC.cc
Arcabit Clean
SUPERAntiSpyware Clean
ZoneAlarm Clean
Microsoft Trojan:Script/Phonzy.A!ml
AhnLab-V3 Malware/Win.VE.C4670703
Acronis Clean
McAfee GenericRXMT-VE!477B1B2A2779
TACHYON Clean
VBA32 BScope.TrojanRansom.FileCryptor
Malwarebytes Spyware.PasswordStealer
Panda Trj/Downloader.AAE
Zoner Clean
TrendMicro-HouseCall TROJ_GEN.R002H0CJ321
Tencent Win32.Trojan-downloader.Agent.Pdct
Yandex Clean
Ikarus Trojan-Downloader.Win32.Agent
eGambit Unsafe.AI_Score_68%
Fortinet W32/Agent.FWC!tr
AVG Win32:Trojan-gen
Avast Win32:Trojan-gen
CrowdStrike win/malicious_confidence_60% (D)
MaxSecure Clean
No IRMA results available.