Static | ZeroBOX

PE Compile Time

1970-01-01 09:00:00

PE Imphash

eca9e2758b11f815ab34f11a0fdb4a51

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x00000870 0x00000000 0.0
.rdata 0x00002000 0x0000f287 0x00000000 0.0
.bss 0x00012000 0x00000004 0x00000000 0.0
.pdata 0x00013000 0x00000060 0x00000000 0.0
.vmp0 0x00014000 0x00000cb0 0x00000000 0.0
.vmp0 0x00015000 0x002c8f62 0x00000000 0.0
.vmp1 0x002de000 0x004200bc 0x00420200 7.84705915608
.rsrc 0x006ff000 0x0003c95b 0x0003ca00 6.23455367067

Resources

Name Offset Size Language Sub-language File type
MUI 0x006ff478 0x00000118 LANG_GREEK SUBLANG_NEUTRAL data
TYPELIB 0x00713de0 0x00000c44 LANG_GREEK SUBLANG_NEUTRAL data
TYPELIB 0x00713de0 0x00000c44 LANG_GREEK SUBLANG_NEUTRAL data
TYPELIB 0x00713de0 0x00000c44 LANG_GREEK SUBLANG_NEUTRAL data
TYPELIB 0x00713de0 0x00000c44 LANG_GREEK SUBLANG_NEUTRAL data
RT_ICON 0x00730040 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x00730040 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x00730040 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x00730040 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x00730040 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x00730040 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_GROUP_ICON 0x007304a8 0x0000005a LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_VERSION 0x00730878 0x000001b4 LANG_SANSKRIT SUBLANG_DEFAULT data
RT_VERSION 0x00730878 0x000001b4 LANG_SANSKRIT SUBLANG_DEFAULT data
RT_VERSION 0x00730878 0x000001b4 LANG_SANSKRIT SUBLANG_DEFAULT data
RT_HTML 0x00736c68 0x000033b7 LANG_GREEK SUBLANG_NEUTRAL HTML document, ASCII text, with very long lines, with CRLF line terminators
RT_HTML 0x00736c68 0x000033b7 LANG_GREEK SUBLANG_NEUTRAL HTML document, ASCII text, with very long lines, with CRLF line terminators
RT_HTML 0x00736c68 0x000033b7 LANG_GREEK SUBLANG_NEUTRAL HTML document, ASCII text, with very long lines, with CRLF line terminators
RT_MANIFEST 0x0073acc0 0x00000c9b LANG_ENGLISH SUBLANG_ENGLISH_US XML 1.0 document, UTF-8 Unicode (with BOM) text
RT_MANIFEST 0x0073acc0 0x00000c9b LANG_ENGLISH SUBLANG_ENGLISH_US XML 1.0 document, UTF-8 Unicode (with BOM) text

Imports

Library msvcrt.dll:
0x738000 strlen
0x738008 malloc
0x738010 memset
0x738018 getenv
0x738020 sprintf
0x738028 printf
0x738030 __argc
0x738038 __argv
0x738040 _environ
0x738048 _XcptFilter
0x738050 __set_app_type
0x738058 _controlfp
0x738060 __getmainargs
0x738068 exit
Library kernel32.dll:
0x738078 Sleep
0x738080 GetModuleFileNameA
0x738088 CreateProcessA
0x738090 CloseHandle
Library ntdll.dll:
0x7380b8 NtCreateThreadEx
Library WTSAPI32.dll:
0x7380c8 WTSSendMessageW
Library kernel32.dll:
0x7380e0 GetModuleHandleA
0x7380e8 CreateEventA
0x7380f0 GetModuleFileNameW
0x7380f8 LoadLibraryA
0x738100 TerminateProcess
0x738108 GetCurrentProcess
0x738118 Thread32First
0x738120 GetCurrentProcessId
0x738128 GetCurrentThreadId
0x738130 OpenThread
0x738138 Thread32Next
0x738140 CloseHandle
0x738148 SuspendThread
0x738150 ResumeThread
0x738158 WriteProcessMemory
0x738160 GetSystemInfo
0x738168 VirtualAlloc
0x738170 VirtualProtect
0x738178 VirtualFree
0x738190 GetCurrentThread
0x7381a0 Sleep
0x7381a8 FreeLibrary
0x7381b0 GetTickCount
0x7381c8 GlobalFree
0x7381d0 LocalAlloc
0x7381d8 LocalFree
0x7381e0 GetProcAddress
0x7381e8 ExitProcess
0x738210 GetModuleHandleW
0x738218 LoadResource
0x738220 MultiByteToWideChar
0x738228 FindResourceExW
0x738230 FindResourceExA
0x738238 WideCharToMultiByte
0x738240 GetThreadLocale
0x738248 GetUserDefaultLCID
0x738258 EnumResourceNamesA
0x738260 EnumResourceNamesW
0x738278 EnumResourceTypesA
0x738280 EnumResourceTypesW
0x738288 CreateFileW
0x738290 LoadLibraryW
0x738298 GetLastError
0x7382a0 FlushFileBuffers
0x7382a8 CreateFileA
0x7382b0 WriteConsoleW
0x7382b8 GetConsoleOutputCP
0x7382c0 WriteConsoleA
0x7382c8 SetStdHandle
0x7382d0 FlsSetValue
0x7382d8 GetCommandLineA
0x7382e0 RaiseException
0x7382e8 RtlPcToFileHeader
0x7382f8 RtlUnwindEx
0x738300 HeapFree
0x738308 GetCPInfo
0x738310 GetACP
0x738318 GetOEMCP
0x738320 IsValidCodePage
0x738328 EncodePointer
0x738330 DecodePointer
0x738338 FlsGetValue
0x738340 FlsFree
0x738348 SetLastError
0x738350 FlsAlloc
0x738368 IsDebuggerPresent
0x738370 RtlVirtualUnwind
0x738378 RtlCaptureContext
0x738380 HeapAlloc
0x738388 LCMapStringA
0x738390 LCMapStringW
0x738398 SetHandleCount
0x7383a0 GetStdHandle
0x7383a8 GetFileType
0x7383b0 GetStartupInfoA
0x7383b8 GetModuleFileNameA
0x7383e0 HeapSetInformation
0x7383e8 HeapCreate
0x7383f0 HeapDestroy
0x738400 GetStringTypeA
0x738408 GetStringTypeW
0x738410 GetLocaleInfoA
0x738418 HeapSize
0x738420 WriteFile
0x738428 SetFilePointer
0x738430 GetConsoleCP
0x738438 GetConsoleMode
0x738440 HeapReAlloc
Library USER32.dll:
0x738460 CharUpperBuffW
0x738468 MessageBoxW
Library kernel32.dll:
0x738480 LocalAlloc
0x738488 LocalFree
0x738490 GetModuleFileNameW
0x7384b0 Sleep
0x7384b8 ExitProcess
0x7384c0 FreeLibrary
0x7384c8 LoadLibraryA
0x7384d0 GetModuleHandleA
0x7384d8 GetProcAddress
Library USER32.dll:

!This program cannot be run in DOS mode.
`.rdata
.pdata
@.vmp0
h.vmp0
`.vmp1
h.rsrc
3eG"L%`
hAK,)6
u^^IAe
ccwG=H
LocalAlloc
FreeLibrary
yFLXZ|
dawG/U
WriteConsoleA
GetCurrentProcessId
W*3/\0_
yFN2S|
3trFzk*w
CFY7X@c
|=a:$&Y%:
.RN6Fy
"tFF@i
9R?zwFa
'Bub~<
`n}N3Z
8Jk5rM
{]Wnfz
]<j%!]V#U
EnumResourceLanguagesW
E<r>''
~h6S=i'
Z[xTwc
yT<>rH
3fdZC%
taerxe\EtV
UN,tiM
m)~[~O
.=c#cT
$3Ie%2
>E._bb
kxcvr
cB){cU
BBx/)2
"8!4)7
qvd^x{
9d@`G'@
$01&t"1
5LC4|x
BeO5FR
<ik0iWQ
UUJ+t[
.v^8B$
/$v#aF#
jjJqv_
-sG.K:ni
tF!}%q
K.1>u:
=11Npt
,rV)@J
LI}v9_ z
Lv/5)9
fJ BiG
N7FHrK
WW$rn_
g0S"SF*
mA%6W?
kl]IPB
JU4u@J
@qn!VBj
(#?[S#
}U|AKF
1]zFo3
uF&jkp
ux |\l
UnhandledExceptionFilter
USER32.dll
(MKQ1@
WideCharToMultiByte
sv&?\j
8LFj/edF,
ubB-Ql
u["\BU
<^Fz;\AF@''
uC:K_l
$yS1FZ6W
+F.)44F]
bF.K@JF
InitializeCriticalSection
~(Fntd
!ZP>90
,9D:]n
GetConsoleCP
D\x1d&r
p$)z\o]
__set_app_type
LoadLibraryA
LoadResource
X'SmM=
gdH# XP
WriteFile
T+tq"n
)ti_#)t{O
rLC]5?
}.McJm
MWm+{E
YHEe_u
vxB"P[
[Ql!p`
j2_l?g
Bu'?0
"VXl]
Fj`*$5
_ 0V' swu
MessageBoxW
yr|Q*#
VirtualFree
EnumResourceNamesW
Dvc1aC
[c-74w
.pr}5,
z][R`{
~D&K]NW
wZ]iPz
{F10/rf
.8<xFi
LoadLibraryA
|/C#k1
#b-tk]_-tqU
f0`5d5W
W*|C09
bSPEBs
/*O/94
SGv't-nL
cDlVit[]
=(t.r}.
/tYGy'
4ZC*by
."ElFk
/y~FtS
{FW{C~
{uFQk5
GetModuleFileNameW
iNl#&B
7`_65>
7)H{]Jq
drt!y \-
Pps)<h
yM")t/
malloc
BvdR|E
%c^c*c<
|z{NJ-
e;M3Pi
?r5FBy;
Tv=CoS
%Ny>lX
*zC&`x
mQLyW[
"U<Jm]
LyeE/2~
sFWFAv
9MCkzF
pUF[e*
MOK%<F
|oV-?x
Cp =0+t0
h6`/vkv
0:U;9\
>UGzFf
]'.OB!
o@+F'8
S|FY@f8
MG5 f+/10g
"=4qj]
Bkme*{`
*>zFzXp
pUtJ/a
9mS*sF
3FZ[\EF2T
(@T'PM
9yD0xF
EnumResourceNamesA
FlsSetValue
PF_rjz
2i9'F2
=j]lh0Q
Q3FH$U
ti FK6
AvPt+P(
GPP!FW
s_,F95
strlen
od>mVU
<2~*_~
~C@3F]
-mYB1W
xM$yG\
yQVmX
W*$%cL
D6e|OY
'{hveK
oWp6_g
=kWbr
TRiT?6
printf
9vH/|F
90.ssFf
Jv}p@G
?z$@!`pR$
>< ITV80
5puzk7
}]TUP|
2hw`k5=
m&a:~2
?k<6)
:\Yz]?
B7ml]
A8Mgv\
ZUIP!Hf
{]]lUz
xv4)PU
nAFrE%
GetUserObjectInformationW
)mWcx@
VeHb5w
ZyWB_F
q3T,3:
EnterCriticalSection
3cvOqZd
*UU(,*x
*"P!-*
n}Sbca
11_5 e
~UZwQA
B*xD'Qe2p
j8|?~r2
9P"*tq
!9afNc
pE}rJ#T
DeleteCriticalSection
sM]K3W
. mKwXX
CharUpperBuffW
]YHEp@
`@e(@9
~YPufn#
B-oCMt
el_]pi
@DM.p6
{624[;
lQ6uuiUv
tYz06g
`<B9vu
'6VM(A;
KeV(Y-h
9QQ67($Rv
SetThreadAffinityMask
q#p?N!
F]3-!*
nxn64~*F
AXo*23ev
+3e*_X
Hvr$oO
L!P b+
L Sb}f]
UFTdkOFY
'yWF8
k|@:F#
&Vmsvcrt.dll
$5#\MkQ
41B8M
hRr:c
>E3RWz{
B&5B;;
_{k$r
Thread32Next
C[t %%
s#|yvf
&VpIx+
~T$8tt
Q&6yi:
H!]J6K
@,S6@B
)DBe75
}p5;)I
26dDh(Y
CreateFileA
*8+=p*&p
* QVz*C
XdtHvY
vEIG%T
Hk;/s7
_!M,Ut
u]wNft
*8jG~*7A
1/lp#j
Z@1gLj>O E
?)+FTUI4F
J:F ]:
8PRF+z0MF
3CFgjC
6vu[v<
FHt'c%
N:ED^a
)K4sq
.*kFpd
kF0t<n
dF_Cba
EncodePointer
Aqu`\iL
E)H*67
xtA+i$
*aSQe*w
Wrl,y=6i
+hv}6YM
9hx62y
GetProcAddress
GetEnvironmentStringsW
z&sZdU
}8tW;=>
#S:tj3]\
aR3'Rl
Ueyv\~
AM_DvLv6C
kFPD&n
dFn:za
HeapAlloc
XO[x$:
,ni_O{
@FlHQ{
St"F@w
?"FreD
memset
:q`73n
G*3m/!MF
]]Ps$#F
9W"-dF|8
,qkFr~
VirtualProtect
5`-j}tk
LocalFree
HeapFree
2n3i<?
2t*FA4
$K7zN>O
0lTZv}7=]
^#BseQ
;Z@0KO
CreateToolhelp32Snapshot
O:}T%_
AFm,\UF
%8y[F{
@!vHBB"
l+fh1F5yl
w*$U*n
Vl*:-
,tf*_~u
9C*c3>U*
,j(F*y
yd@q/O
/%az/b
=honC+
'NE6,
WxD@E<
5zt:,4
GetStdHandle
(zt,K)
~`k5tm
SetThreadAffinityMask
t6hXY;
vJGA5
^Wv1?O.^
]6_"jC
gQOvCJ
Lhh>O&G
Li2i_E9
4LL'RT
^FxSFD
w-YMAa
-*"?1N
f#B'+(
2v)O"8
lv PU]
LCMapStringA
)<tl0i:
k;t{';2
W[3Z:O
!%3taG
FlsFree
__^/5a
c-Dk@d,j
D<pmJ&:
wC`]Ke
WJF!F,
Ub^fF}
H?FgP3
K1Fq<;
2GF*66
]Ffj7LFh&Hn
~&@!yQ
@N$7J(n@ 5r%
vYF&DmEF
IEFwj9
FindResourceExW
%M[8tS
L\|9eE\
Yue3P%x
`aTC{3,
3Av7yZF
VNVG.0C
"{40f4
CreateEventA
#x6>j4
HeapDestroy
!_#B2N
!\7KYq
f!ugK$
GlobalFree
,gzzf6
GetModuleHandleA
sprintf
*3c}x*
Cf:E*+
*Hz0**w!
p[ *2Rf9
i8h+mFF
G#~>tyzD
M;~Sit
{3LK7G
9t1]J?
Sz\.C
1D>!)<
O)al9
KDN36{W
HgLyd?
FreeLibrary
pMW]/vb"
9aL{eF
A"1/jvW
fF_3 c
])/UBRi
GetModuleFileNameA
{<lS(
"*lm79*
c{/04x
4L<5tr
ht5!(i
cFc;-F5
'Rf`C)
C<wj[}
H26t|h
3PwK65
-~t@n^g3
[Z>]CXS
FT7:PqY#
R6PC`Qv
@TSTIB6
=PC_7p
__argc
HeapSetInformation
4kYgCu
0E"!0B
pFS39c
wG5`LO
GetEnvironmentStrings
`<|*:*
ynjsk*
]O5inv
9i$OfF{
D)@f/b.5
xc5%F!
9{mcnF%
D\`'{&
(b]C>
"*[Uf]+
lg=:pCf
mJs;d[
k BGJ)
KS<tO;
_E*6t}
fFZnxc
(9FpgS
J\ !ei
FVCx5F
F$A35FB
IdAB\]
s&wWi\
| 3TFA
\%r[*j
BkV3B$f
3EE|:c
FreeEnvironmentStringsW
.66tBf
FwntXuBt/
GetProcessWindowStation
u$EAHl
,sCS\E
M_F"':
{;JZlK
*>%F1p^:F{\%
;W)(FN
@\#SMBW
z$B}Vj
TerminateProcess
NtAllocateVirtualMemory
l#>6*
{~h-<>
l'mfM|
u3fj)x
- !~eBdS
7qk$ZG@
FD@_r`
@-4HAU
W)LY!
CloseHandle
"&4`]
0=0tdp
8y:t<H
@IN@FBZ
F4Q|8F
OPjc]lb
1+|$Uu
GetProcessAffinityMask
RaiseException
/LixM.
M|G)!Y
3e-g]y
ypiaMo
.G"o10
;Rt)cP
h0{>a3
~a78rIl#
<tA-L:
=H3cPl
9qJv75_}{#
]^7("8\7
ExitProcess
7A6qnBBv
@]ClEef
MZ?3F-8b
9Fy(Y-F
W`t3Fo
|#Fg;x
"F6w+6F
u=t30O
FileTimeToSystemTime
_;+Is @
W) ^C?-0
NtWriteVirtualMemory
^Rg]B<
5ws&4}
FreeEnvironmentStringsA
PQIM\]
lLU}Mw
_k+>$ X
|_5vQ62
8<VW>^1
GetConsoleMode
zYd"`U
7t9eC>
GetProcessWindowStation
__getmainargs
_uUP$ n
9@}VeF#_
8`r]%.
s_6\>Fq
i&9jc)
?um4V
mu)2vP
\+F8y<4F
s0ZvzXY]
{*6Fx`
Fi-lv}2
*j:)q*
q4P81d
Xou&F@%(
g6wc"?
KoxxEE
)]t:e.;
.G|:8X
8ng][`
GX\f]D
f5q]%G)i
GetCurrentThread
i'7fFv
MiFuH#
9LtFn_DC
9a_EoF
CloseHandle
FH ATzg
ExitProcess
4Htdb50
GetOEMCP
4t| L2
/cakRptK>
O'sg7[
N9tf5t
GetCurrentThreadId
_MYUb
rk N]]
"-l,v]|
SystemTimeToFileTime
]pbFSJ
jW_g/4
j/#?j"p
dFG#Aa
e+|fF{Q2
j/^U5&F);
/F~KwO
90ucdF*
BP@G|^
V!zIFFS'aF
@x/rGB+
|=N\2A
foFpN
Y^NxFq
?V#3yx
XH?8hp
g0TEZ,
Zfa]c#
SuspendThread
aXCw?,
R7y3>_#g
3vX>k4
y1S](j
\vL*6V
RtlPcToFileHeader
[6P#97
B3J b*F
9cm>`F%
7nE]lq
i\`F6h
GetThreadLocale
ntdll.dll
DecodePointer
GetACP
j-JFU(]
+GYVF.
[F[*eDF1
u3kqAl
v'q&G&
F]He>F[
\.%R&G
9 vX;P<$3
n=,vC*
/B'6).7$v
};%vDx
k47OZhb
!Wb~]K
$Ov*l}
k*Y)Pp
3tYeCz
@+0U^[
GetCurrentProcess
ua!YBl
(F *6F
$"7:.>&
CN*:SEL
Sttd*
g*.N=~
*1c*D*/
*`qAN*
cqBi@
kernel32.dll
ResumeThread
Sr[AG)
__argv
IsValidCodePage
or[FeD
?ivr{h0
f:&vK!O
GetLocaleInfoA
e6Q+Y*
c<ypV9
/]cJ&
.Zgk}#
N}u1tJ
2U?td;
r6tz)H
GetSystemDefaultLCID
GetModuleHandleW
N3p!6A
^[6 "%S
_environ
LMcCB/
%j;77n(
HPK<h>:
EnumResourceTypesA
?%tpMb
&6mIoo\l
:!Pea,
oVB^P4J
6\"D<po
G8t5&}
G=`tZA
pr<|t1Q
(WFqnp
V-V"G0
,'VG":
*4gtup
]>A.6d
bV;7_K1m
r|Sr]?
Su{Z8Z
FYPl[W
GetModuleFileNameW
JVwx6NG
ic6M&(
v6fmxuv
@*5v@B
{&PybT
#wF&J[
IhF&\9j
}`dyF>
;]Ho41
?tq< #
bnm"{<
Dv^,1N
nv\Nvc%5I
8jAAI7
LK<?qA
PRr"BlZfg
|~~F_F
zq*:.G
)i`IPd
1x&0I$
Ph1&XF
Md=#F
RtlLookupFunctionEntry
D?kux&
GetCPInfo
FlushFileBuffers
2#;DV;
Zl:aF<6t
sy@/N]
.{cQiw
S\iQ6!
SetFilePointer
RtlCaptureContext
MultiByteToWideChar
az(@4
b<gjFk.
f?JhP }a
(8v=YB
4Bq#06-
F1zhfy
Ph]r(d
nN)j"'
jRc1SQ
8#]]&Q\
uhjmy9IW7
6qlJnd
+\2?]!
|Er(U5
>tEUG@o
p.u)^}0
`g\d'y
@^O9|,
C3T~wXA{_
1G>TS_
/dJv>N
3c4PDq
ldzlC\H&
38kstW
Aiyf>W
rOMT^>
}75['|i
yGoI#JV
\w"&{g
8W0T&3
M45QF"
Srv-A{
ZE[4&J+
>tEG%nEI
2<L|r8jvjd>#
ES9u6'
p6t>%{
K;}m'o
!0_vfQJ)
UD2'D~
yE!'7+
3M5+1w
"m/E6G
zWTbT;
8(}$0MA"
)k4,R(
\Ur#=Do
GmCcF~
k?|P0Px!T
DEXXhv
6s-9/<
d/drC_+
Fy;{6qH
h\0WYV
96iei6
envYl#~
k:Ifg|
YPn%R4N
CAk8df
qY 5v[
MP^5<p
pd%8z<
r5I`U6
oTK<o]
6'3;PC
hgUz6d
XUipcR?
\q)C&M
k\N{zP
9D{lv
t5w$7l
H'>mfr
Hf _:F
|;IB:bh0
5Vv@ZcA_
`^+g.
VJn.<cV
;|3dK.
;)RS^`
(mo/J_
(_X{M]l
JnM/H\N
{L-7[]a
9GjhDYaK
_=~$->
<*y;yA
dD&+UO
3^5mRFU-8n
<Js@38
JT4 *+
euK\FN
(>^SgL
T?>DO:
{"NtB1
RY#1r+
E0eN7}
b91YlB^2
rKo6Yk
'iI2_9+.
XLWSI@
=/U!%L
TRxx6>
f,Sb0H-
myE).F
7M2i4n
Rm^$.9
E5XaF6
3?f"H*h
B1wS=^
6Gdpe
X3?iSw
OLSvv:
n0g30'
%l>NQ
d7>.s%gc
>/K$ps`
..-4vg
bzfMvO
EnumResourceLanguagesA
zqnE0w;J
-d]FG.
GetUserDefaultLCID
P\t[A3\
j-3_*g
}"!?ta
"zktc][
vm7|Nd-
Y6c3]v
pp\SSr
OP]c]7
_XXmq
GetFileType
6&^"}tn
"W[aC<
fxFAGI
GvhR\M
1MvU3XJ
TBVYl2O
GetUserObjectInformationW
&=e lj
P. 8<s
zC:B`x]
p1BsHk
1j*%$;l
*N9oJi
GetProcAddress
JR3[.G
R7)C=_#
GetConsoleOutputCP
GetSystemInfo
YI:&H
,B}pQf
HeapCreate
_vvC6
; iH:?
[u]FjS
b\t&c*
Fc.W*F
.7FJmU
InitializeCriticalSectionAndSpinCount
$pv!ZY>
{?(`}@6
@x4vyY
XD6y6-Gv
5cjF|u=o
bFP,kg
0~;aF.Du
heD//N
7siF~G-l
!/fFi'W?
iF.]93
\4qcK0]
Zi/W_r
D`<Mm&
q5ef]G
av,Fuk
H)$uq4
RtlVirtualUnwind
vpax:}
X|<m@T
LocalAlloc
4! sn\%0
(pO@a*
D-He,W
4VSxy=
RqG`jrJ
F7T6L_BWv
SetUnhandledExceptionFilter
SVS:m^
5upY\y
SetHandleCount
hP9.RD
Z,*tM*P
NtCreateThreadEx
{YF+N&qF
FKmHFFmzg
ug~ILl
w*te_l
l_UZ;6\
m(l.56
TZM0~F
p&pqm_
y&\%vV
bzkc2h
NhNHyf
bF t_g
KF?TfH
GetCommandLineA
_XcptFilter
HeapReAlloc
dv7m|c
frR6t@
%cV,.%
gtUd7`
6t1|%:
HwolCu
gR!6ibU"
4u\csz
WFyjVBFw2
/}t>>b
$w/p3=
2Mx,AB3GF7
u)p-F
v, Fe4L?F
v:noFs
2bFFI#cFlF
-5SPpH
6+4k0O=
LBk g**o0n<
GetLastError
0{` 4S
!i*:++o
r*=}1i
NviKzI
SetStdHandle
ul%CDl
WTSAPI32.dll
~)Mq@n
>HSRZ[
@(IwlF
$:$JFH
#4t1-c2
{tP.=c
&l&chb
r!#w=#xt
3zBV*{
HN%j|3
<#kfoj
SwZ=t%6`
SQ^nzth%
;v&n/B
KDyvNx-~
ZV@logm
ud<T@l
]=e6WDHfv
59<+v0
vyv'>!
Wd6P&.
"_f+t]V
=n./vz
9mC5eF
9pFir;
4@i4pzE
+{#.2A
"V_Hc]OV
:W>4q(1
aF9I1d!
^[0'FJPA
) +no
-dY~y<
+9=iB&z
P@/c:,
4p!@@v
<D*3S;R*
ceK rt
=qxUk\
^bLAVh
235p?`
&B%$<-
Thread32First
RtlUnwindEx
FlsAlloc
w+r)ia
d4hm3Y
W)oY:w^
8%r~f
_,sXI!
?.zm^]2
TQkuts
Kj74>.h7
5Mg4t+
)$8HF#4
zcI&p+
Gt>``O
5Gt`]!
Q|*8)=v
q|*\<{z
*Z+|H*
gS^Y3y
CreateProcessA
cFi]9f
;U\jkz
8w3@|l
>5@El[?
WmZ&ff
jvkzmm
gN^vz$'Y
lp);B#
x|kp"]
i0G8Xm
fp~Agd
9qp %u
Hz MIk
-.~SHX
zb/N
ff`F6d(
f0:oFa
(ZP07>Q3k
Yo|5]>
WTSSendMessageW
Hgv HJ
)TxA6b
`('foO
VF+i )
uO.~Ml
'.FBP2)F
T[8^a
su@bF$
<p6r!:
HrFK@;
wAV!d~
Y*E5CB
J!Up:K*
[][UH]
D4h/Os
UB}ja]B
I1s/"BH
hFf3M@F
\%tz=c
Fmx$=K9
sz3FV
Bk:-7V
5te9P3
<)JcY$:
|HfXbt
,?S`kJ
#U*GU^l
#!Rr]
|9M$RA
(&a=[O?
VQw9[c]
Wh5w&E5
1DoZx+
hE[lo;T
$]08"XY
r|hz)a?k
5e"avT
9JW/mF
e*J[dy*
YE-l>^
dLn6$,H
DsO@x&
uY8]Al
*f*%F/
9mv&8q
i~hYFi<5qFw
#YF#f~qF
`F!m@e
OpenThread
2$F|9o
r?:4F|
^9ElKs
9V/FFC
}&w/VR
e(F7=T
t+Xl-^7
#2:>^rZ
Hvz^Gb
5v6g0@uv
FindResourceExA
9EcVkF+
4l/4@A
LocalFree
}7:Q%wZ
cR 6iz'#vd
vPg(lp
"$Ly2@*Q
iIqziV56
&WU0}.Y
v*E5vm
VI8[,5q
LeaveCriticalSection
VBw1%ZB5
rEK-G!TA
(_|"@-
al!_za
xWAgpp
]6M.M
w;);A2;
6]V ?/'N_
"j"PA/{|
WlCjK9
W@Wn:9
$Cpor9
p\E 3
SetLastError
VirtualAlloc
#!+t6@
{p*){7
Uz*SRhc
|G:*#2
'@7b&
xxFW%cdF
GetModuleFileNameA
S\F#ne
#jFYy4
vvLB#B
rvGB,;
y&O65V
O2/AF!m+
K\lQFS61yF
,}L`0Av2
)B^_42p
XeG:]i]
zz*<Mp|
~Q{F" ^
i5oZF<
>qcF`4
FiF!IC
z 9K*9
{K> 0
EnumResourceTypesW
)5_hg
#w:Ll$
r0sVns
QueryPerformanceCounter
exMA^<^
O3yNIin
~,i<h<
b1oF<8
O;zF:r'
"2sri
9cvOmF(,
hkFPi6n
lFrn<i
u@C&G{
r@f4aK2U1
*&XGxn
LCMapStringW
getenv
}z9tQQ
8(x*SB
7I{*St
GetProcessAffinityMask
2F?rp,
Rx0@C5
4nn3uqK
h7C)tj7_
o#7|AP'
SetUnhandledExceptionFilter
I"izlY
IsDebuggerPresent
)ip!t2
\fC)s"
AI[i17-
l)KZQd
-X%e3`
28o"L*e|V
NVjpo* W{
R*b3b^
*3alx*
*B3G^*
270*vv
@*VPu"
.-G|6
1gcFT_A
WriteConsoleW
b~qvgQ
?N/`0A
GetSystemTimeAsFileTime
I$nl>
/1wT7
z9}*/U
9g*m+b&
-H5t!E
5}!_W-
)aFVX2lF
$cC;}u
^:>L{2
|[,/|ms
5X1ia5
cv]<UM
0Jv)kYM
=j9@Fjm
1T s6^
LoadLibraryW
6QQm`o
GetStringTypeA
jw-iYp
WriteProcessMemory
Q>HOE/
K9pC&P
GetStartupInfoA
SetProcessAffinityMask
\4Te"~
ri){ qWU
FlsGetValue
HeapSize
q<:UQI
*9'sed
"uoqhfO
wL6-|as
f8&tj=9^
^KSRX"q
*]|wp*
*9HEh*,
*#T\pH
_controlfp
CreateFileW
9{?~**
,,VzcY
Yi={n0
^Z{]=oFc
GetStringTypeW
" nB8O
YJ_YY^
WIjH9
CU)OP'
pX%TMk
!ltg/+
hlz_\,
]W,B9U
BNNF\X
SetProcessAffinityMask
o##Y&z
9l3&T?YFN
98e0nF:
GetTickCount
GetModuleHandleA
.AaVXM
Oh4e1z
&(7'_\
z~\8+v
glmJPq
:@/{x8
-FFfS+
|qwwh8
>=6Z~o
KqAC]#
n+7."fn
sX70r+
"+EtU}
)PMLh#}
u5JYE !
0S*^Ip
cj_<t}
mj.)I3.)
{{N_C?NX0
py'NIX
%Bzco?
49lZRW
;}MyrY
xM"X}y.
zeS%\9
C0$9c;
+?z@|d
ANb_N,
K'P@RG
[Dm.cU[
arseY&D
bRD`wl
s4B8nK
wN>xQ`~
_1Yf?tU
[@?u#WcG
20pUI2dkp
,u{HkO
29YaOQ
xIl(f}
c:t(*I
n)Wrh<J@`g
Q[nX}w&
`u5&;j
2)Iru?K3|&
V|=wX|P4e
|#`|^\
H1Q!\o
6;b!r{
!S[/h\
j}T:w?}9
~B>q(7
uN{hJU
0s]Tg<6
[dv8L>\
Q:u!Ls0
Yk5!Ny
HPAl-4
1O2Ys_D
kj+Y[xP
d/UIcz
CY@{I*u
/_M;ok
9SXXMY
BMw<Vh
f('*bN
MS>X!-
6w#h(v
}cX/\:S
kuH^'[
[HWpl|
>pQzl,4
G78peV1
Z\k_Xul
9H.1O+
Kv9d`JOkpd
j,VCjI
_{],{N
+f45+T
:''U/TR_F
qW+Aq>
;a,&?d
3HXk/uJ
iKZ13Z
`s_]ji;_
AqYZMc^
AY)kK-
:3CK|C
aG!itU
!ar"ki9
%I3L=n
|Bj23{
iVpj]-
D/H1|LP
N[ah'-
&M`DW2^
!CJbtDS
' <?@p2
}MW7dF
}a+_,c@
TML/Y{
XUdYVq
X5@x^:
DdkW5CY
8E_J+
gizz15
a$'Nz8
"HZusT
!0lL7
@y-!=}P
Iha1gN
#\e/>M
I>[JeN
2ut#U0
>-6,bn
#3V0?uOtr
= O&YBs!=J
od-4"&
ybl"mj
YJz`'H
u]%V7O
B!htNn&
'7>&J0"
ErJTW\
-N:IeF
SRju|>
C gBn=|9'o
mt6S'~
i-KT?*
icULEz
Z/v|wcmB
BKhlvo@x
grF9G=
Pn]V;sO
7Zd:Tk
1igd=J1
Rz4SB_
6zG]>B
:3SUrs
.VIHbk
5dv/[aB
ZV&T&7T
5JpVN
yZ66Vb
Rc40ER
Y!1TZ+
3.i&J:
0-m2$I*
Q7#kiZ
hBz4"(
K:rOZe
v^#@,amE
^yG:Je$
{#2HG#
(r<k+
,$FefJ"
e!=|G
Co9y6!x
j%=HTM
IFpw9>
WZS=_x`
m0L`A=
8n9L#~
!Ir}8u
}0!-\z
.Zf!E.ht
kGhf=Wd
=(<P2k
SZ[LM}
Id?"R^
w\zLEf{
hQY*^
d2oTM|
{\@nh7%
d5>w}v
Or:gyPem"
{i'8$I_XR
']PD,V
/Wr8U/
X9r?).g
k"jxfk
5(YhtqA
B[Ef77z
M-/JLJr
?dz8E
RC>#Dj
Djsj4LL
NI<ssa
]Y#,LLw
5/k8,_
lbgcKP
~cxxHz
60Y9m:
&9&|A1"
cmPYsv
<OVa(]~
.gN+Y'b,
Vx9"x}
t4t3BA
++V`X2
hmUL1Y
2[>bCn
bDnT='
x[e_D%
U$ViiM
f(C<[I
-J15ST
3R^0!J
A( yi;
o??.hxC
0=nrAUDT~I
F qubF
re<TU
qMG}WW
[1Yh#x9\G
Hp\EL@
}YZRat
1GtZ~U
1=,wS(o`
RcHQR6
u}#R7T
k;tO<S
eK}Jm^V`*K]
E.u1$T
Y{4hIGX
k7FV.u'
*76AO3kt|+@:
eWLs>o
*m4pe-kH%7
HjAYz~
bfCNP6
'i$NY,
V P26+#
!0Hv&Ld
c:v{++
Eg)/|6
5JqpEp
6Tw;Tith<
^h]q,$6
7I{g$
8+ZFIMvac
Nh6Q*Z"
l$aC;6
0?,4aD
<@C&-?
xl[}<^`
?wpCCi;
7sB1^
X0u>zlD
:tVj^4'
|wbBka
hu(qSS
8.s={)0
E*{aev^
N184{@u
U:sG]o1k
1U]T@:
CGr0!P
xPy 6Ht7f
$Qm!9w
?MTb)x7
J$.+'L~
?AWW,yI`(
^9yc'D
5;3V}d
rhd* s5
H&^L=
N=oB2z
i~03/v
>fSXA
]rejcs2^
AtsZJT
MP#93|vO
DP@6E1~o
,}Z>JE
xP%jxC
w6wg8j
%Tb-0p*
&(x;;"
K&gh@o
beE!=3
Q5c\35
Y[w@By\kf
SHb)h/
#%`5!Tb
IzCfAy
#|[H!L
B(n{+#
,u.V|?Q
j1T[[x
FrB\W^=7
4s+I,R!s~is
'(XM[X
]3< ka
RCo>+F
@!<JiZ
V2br"{
/e+lL[^
D0ps/(
1hHj^[
5;,%(N
B#c{>
y>wfmX
Ul0/.a
_wbWt
LjH"A{
n(}&]x
[m:}V*
StO"jAV
$XhG^W7k^
b2Ik*F])
<L8Ci[
`QG1MB
OH>ll*
|YenyD1
Th.Wap
@o}LKq
N/nr:bt9
WKrgy`
][s76~
]nGdn{T:=kO
3S14s6
aeqd;
wtyRn@
mgM.eKY
WP8@\c
|DYE"
Ia(A"w
j[WLio
v$/L|zU
ar'h9p
m5I,U
k@CQOr
yCUnj"O
}|LtKB
Tc$r3MmN~
I9i%%#
F-G~Rs
hshO.-?
Fz; 77!
<Mg[2
ej(+mM
Ol[G<==
sQ<Ev
Ii^%(=J
[QCL0O__
G4q#c!f-L-
k3(Hkl
OhAjidv
l1AIx2
4''Las#
?m,!E{z
QF!e1u1
m"qS`_
&(wIr@
]Y"h},
%)DBnM
:`~T(g
e%r,==j
zJgo7x
)\:?&}A
gjwlqV
H0Bsxh
\K[96}]P
ni? CyP
28$|CS
cs0TO;
ajL;`qXu
,s@`FR
G27vH5Rq
bvFXy=
gW'~fP
|i{tey
o%Ff{0
~j=q9=
:y{5^3@hO
w`9<aL
x\A.?`
Il,ar%
D yV0^
uw@2K[
^(BeWi
'[O;*}
.OxNYO
Si~!}Z/}
CbW_'T
ZM^: <(
\c"E|w%~
3iQ[x3zo
EaNnN'
SV4L24
QaHBA$
0&g!5o
"kZY<1rz
dyx,L
}fQ1`0G
'b?u<
oR}`s{
v}3g%_c
g%$\:-(?
0jeGvj
[_^(:+/|T
4?6s~o
R|R@NM\Z\
6De+_\kDj
:S0>NN
6Nu]m|
icPgY
F%bm_^
go`W((
<j@K}P{
3Ak9WI
a6l:k5_
}*+Dtp
F[yecx
~Xk&48X
WmWO{|
h)Nw(
4P#He$
A2q"[-
fboG$\D-:
-}dZv}c
N]q**
2@N659
!_!CdU
PiF4"v2
Lz<LGY?
n[+p1)
nTUJr
yZGR*?V
w%Ul~F,M
gOXBmw
?{P14TE
dhwJFN
]i6B)8O
t:D*oH
c?2f/k
Q9i$eV
.9Xo`O<VIg
6P*j1s
kqjf>Z)R
4>+!sN4
+h:!FE
"z2YRJ]
aG%iI=
ovH1R=s
i1G`IJ
T|R ZiU
l6;C(4pc
3uX/adv
{xG]4 3'
Q_L{IW
]d<*W+
f}wm{N.x
V"<Rib
.8Z*|Q1
O mvz<R
C>S"cb
0Z P"I
$hys!t
p*uw<B
s1-hyU!
CB)AB;
7r!T}B
5`O=5P
_]d3T%
B_oc{G
mdkZov
D~xkaz
8"'`j8^
p@/a+E
~!3PC1PO
#jDiSM
v~%ctu
!T9N'Y
Y.@8mh
AhN(f98
n?s;B}9AB
$y_N\.
om9p'g\
y>N`9Xqx
ldV`iw)
RCZ0xn
^&675
!)3Vb0
N[2tv+
8hVF2E
AD}re
_r*7`q
3\=974%
j[e*8D
DQK!jA
~e} Pa
@P/]D]
ifsUwAaT
=m-%p8
!\Trq$
W-zFpD
\y)~0P
#mYs-R6
< -KX}
FNQalS/.
w;jPc=I
gpAXj|GD
Yzb+}P
C:,d7j
LgfbN]
t*s/pp
:tNlirB
i?#f;Q
5I#U-l
w*y*l`2
SX'Oyj
X609XR
8QD=YQ
2&9"Lu1[
9\tVet
)$uyr^
!brA\L#
xUSdg3
?ojCyw
9O0.*r
fEM;83&k
!si{4iC4
Ek<Y`*
dJCK+2
l-|xU#
G\X7s{
)xwCa`
%4<H&{Uo
gge&wK
/\bZ"o
<{4Y>Y#
#i{H'2
-Rwlo7
/W0Q=M
\c<,i1
jrH69M<J
0Q7&~$
N7n!c%V
JThi%V0
\7I-DDv
Z}$3q`^
e#Eaja
+#h;th
:sJD"F!;
oZf^L2
}Mk_8L
Ak9OGT
^Gv3
_"oug<
2_Ws{9
Vr>",C
2\LX""
Z$5+po'
|yFRx
Bn8FYt
v-@ ?Ah
N{Tz_A
Gjfcm
k6_,/(Lq
JJxTR]
.70T=[
%tK3(>
J@SD^5_
nZiJ=4 $(
9Y"h*a
{pE:<.R)
@ij,"}y
T0B?TXnm6
ga$tj8
f^'}Oe
"g=YRR
FkuH=Tl
MMz5Jg
cIQSBA
:X\etz
dALG^T
29KOkw
xl4<pC
(nJ&S!
vPT9ZK
fkp,^~
RT"r6!<5IA
>$84v.H
C&!OMaa
KG<CU65&
b'>@aa
157>C6~
L@z"Zb
v=mwIe
s#1p8'E
{r&=,m
K 9KOY
]QMP4(G"
0*\!0A
a)Nbv^
Y?C`p;
o;L[VePD6
\t|`?:a5h="
Zj_!7S
~ea#}o(
SH"@vH
(?qa$K
t:>Q_;
ag"SY;^X[
[b`?{{
Qo%[c_,
A3=L{vBdh
t-I"LoM
TF2D%y
o8qZTq[
E7r_1Dl#,
mao9<|
aYItVD
K@h%s5
O/ Q6(N
A[,{bz
u@)Do/
I8B\/.-h
"4jza'F$
>Fwr*E
uut`z_%/
IMo{[|
!+3ud8w7
'e[k~<
'!1$q
r*xx$H
4%:KfZ=
cQ?3lIX
;;%`,=
+6m%v'6/
{nE[P.
cYn<S"U
12cE-/
H,k6>Z
$OYNdr}WR
'z7}Q^
bJc]W?
TZc'NvbT
E7HIWQ
}(fm8~
aBl2u6
S2(Y/a
4Ea$v0
+NE!Jn
iK&ra%2
A.eZU%r
/|KL'Wj
`pZjWg\8
\*z%?
5@1"Fw
(~ZpM:%
C?[")I$
hihJ&dy
gvEK'2
JQcyO 6
4:c,gS
]Q;{kC
eE|$\%
JzC&GV|>
f`f})GB
xi%EtV-
;KToWs
}b.nd`
(ahy7P
X]c/=h
_3`AvL
pue^6$\
1c;+@)
PWn+!>
SXh{NE0tK;
+}MNLF
6$DtE<
:$@<%
ghop"nW>FQ\
+%h|}Kf
b>:GlS
WCsb[Y?
@`V#yeBe
4Ah-oh
E2|Hv"GP
!*N#mx^
>[GlXr
|9qtFm@25
0kuBQ{
2I:fU[K
x\!'Hr
S pxoH
u[udSF
Y4vhzGf
5%7FRw
3|;Qi2
(2=)OK
=!+qn.L
2k2T/J
"r|8~}
Z2deN[\t
HXW8Rj
M=d/x
9J7owx
0Gji)Q
`Mfc<
OdzUL*
u~[qc3
Q'/6(5
M0i8EuE>n
:&P5{H-
P{t;4s
mdK]'B>
zOAau"
Ao:_L<E
ASVUUh
sek#dU
3Yp2n1
gj1i8i
D0qsf0
F.Kz[p
3_1cSB
q&vW3b
#JHT\D
: &&,&5
4cI8$w*
kWSv*0
B"gGivS:]
PT|pIvW
uiDW]B
1nrYz
IsNMWGc
bAmO_\
`c$rku
J(j9H[
ufc0ly>
&imJ{M
QiI(`*
Sz@;Wb
~*rFL,p]
mvypOqax
F;w4n"f
8f[y'y
#=T,fF
Qo&V8v
{McZpS$L*U
`<_Kw)
P3'*"i{
3o~AL5[
5Q,par
fr^pF$(}p?
66B#\i
+Sq~ux
\#gRuZN
pL_N\!k
6xKL+&
Awuc?R
BS$CDy
3q:%^[
w4w6.\
euvecP;3
,/bdI
fse#R;
]q$Hai_
9]Qm'%
?|f][x
9OP<Oy
B-k"Kw
RFTR9:
rwt:+HL
Antivirus Signature
Bkav Clean
Lionic Trojan.Win64.Donut.4!c
Elastic malicious (high confidence)
MicroWorld-eScan Trojan.GenericKD.37771247
CMC Clean
CAT-QuickHeal Clean
McAfee Artemis!F64CCB9DF2B5
Cylance Clean
VIPRE Clean
Sangfor Trojan.Win32.Save.a
CrowdStrike Clean
BitDefender Trojan.GenericKD.37771247
K7GW Clean
K7AntiVirus Clean
BitDefenderTheta Clean
Cyren Clean
ESET-NOD32 a variant of Win64/Packed.VMProtect.MY
Baidu Clean
APEX Malicious
Paloalto generic.ml
ClamAV Clean
Kaspersky Trojan.Win64.Donut.blt
Alibaba Trojan:Win64/Donut.9e794eb0
NANO-Antivirus Clean
ViRobot Clean
Tencent Clean
Ad-Aware Trojan.GenericKD.37771247
TACHYON Clean
Emsisoft Trojan.GenericKD.37771247 (B)
Comodo Malware@#xkkuxstof5er
F-Secure Clean
DrWeb Trojan.Inject4.17309
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition BehavesLike.Win64.Drixed.rc
FireEye Generic.mg.f64ccb9df2b5df52
Sophos Mal/Generic-S
Ikarus Clean
Jiangmin Clean
eGambit Unsafe.AI_Score_99%
Avira TR/Redcap.wmihs
Antiy-AVL Clean
Kingsoft Win32.Troj.Win64.b.(kcloud)
Microsoft Trojan:Win32/Sabsik.FL.B!ml
Gridinsoft Ransom.Win64.Sabsik.vb
Arcabit Trojan.Generic.D24057EF
SUPERAntiSpyware Clean
ZoneAlarm Clean
GData Trojan.GenericKD.37771247
Cynet Malicious (score: 100)
AhnLab-V3 Clean
Acronis Clean
VBA32 Clean
ALYac Trojan.GenericKD.37771247
MAX malware (ai score=80)
Malwarebytes Clean
Panda Trj/CI.A
Zoner Clean
TrendMicro-HouseCall TROJ_FRS.0NA104JD21
Rising Clean
Yandex Clean
SentinelOne Static AI - Malicious PE
MaxSecure Clean
Fortinet W32/PossibleThreat
Webroot W32.Trojan.Gen
AVG Win64:Malware-gen
Avast Win64:Malware-gen
No IRMA results available.