Static | ZeroBOX

PE Compile Time

2021-10-21 05:54:42

PE Imphash

ca2428f95da32f90e7651228c28ff6a1

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x00092d74 0x00092e00 5.89658696879
.data 0x00094000 0x0008cc1c 0x0008ce00 7.99957137362
.rdata 0x00121000 0x000002f8 0x00000400 4.21603789443
.eh_fram 0x00122000 0x00000a04 0x00000c00 4.37384032801
.bss 0x00123000 0x000000b0 0x00000000 0.0
.idata 0x00124000 0x00000740 0x00000800 4.79969702234
.CRT 0x00125000 0x00000018 0x00000200 0.114463381259
.tls 0x00126000 0x00000020 0x00000200 0.22482003451
.rsrc 0x00127000 0x00013d90 0x00013e00 6.55420992341

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x0013a740 0x00000128 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x0013a740 0x00000128 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x0013a740 0x00000128 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x0013a740 0x00000128 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x0013a740 0x00000128 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x0013a740 0x00000128 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x0013a740 0x00000128 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x0013a740 0x00000128 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x0013a740 0x00000128 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x0013a740 0x00000128 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x0013a740 0x00000128 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x0013a740 0x00000128 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x0013a740 0x00000128 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x0013a740 0x00000128 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_GROUP_ICON 0x0013a868 0x000000ca LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_VERSION 0x0013a934 0x000002a8 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_MANIFEST 0x0013abdc 0x000001b1 LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, ASCII text, with very long lines, with no line terminators

Imports

Library ADVAPI32.DLL:
0x674184 GetUserNameW
0x67418c OpenProcessToken
Library GDI32.dll:
0x674194 CreateFontIndirectW
0x674198 SetBkMode
0x67419c SetTextColor
Library KERNEL32.dll:
0x6741a4 CreateThread
0x6741b0 ExitProcess
0x6741b4 FindClose
0x6741b8 FindFirstFileA
0x6741bc FindNextFileA
0x6741c0 FreeLibrary
0x6741c4 GetCommandLineA
0x6741c8 GetLastError
0x6741cc GetModuleHandleA
0x6741d0 GetProcAddress
0x6741dc LoadLibraryA
0x6741e4 TlsGetValue
0x6741e8 VirtualProtect
0x6741ec VirtualQuery
0x6741f0 WaitForSingleObject
0x6741f4 lstrlenA
Library msvcrt.dll:
0x6741fc _strdup
0x674200 _stricoll
Library msvcrt.dll:
0x674208 __getmainargs
0x67420c __mb_cur_max
0x674210 __p__environ
0x674214 __p__fmode
0x674218 __set_app_type
0x67421c _cexit
0x674220 _errno
0x674224 _fpreset
0x674228 _fullpath
0x67422c _iob
0x674230 _isctype
0x674234 _onexit
0x674238 _pctype
0x67423c _setmode
0x674240 _strdup
0x674244 abort
0x674248 atexit
0x67424c calloc
0x674250 free
0x674254 fwrite
0x674258 malloc
0x67425c mbstowcs
0x674260 memcpy
0x674264 realloc
0x674268 setlocale
0x67426c signal
0x674270 strcoll
0x674274 strlen
0x674278 tolower
0x67427c vfprintf
0x674280 wcstombs

!This program cannot be run in DOS mode.
P`.data
.rdata
0@.eh_fram
.idata
k9-Kkl
F8-}eS
5rahh%t'
5rahh%
fffff.
s-T 73
|-ZpZ~
PZ8-/Q
fffff.
Q"-s'
jt-EKF
-B,p{)
{b-6(f0-+
-!@J_-
- EKS-s
VRx-))
g-'NSD
-v>vn-
-Ek%e-rQC>
c-c #*
t(<{t?
</t&<\t"
Qkkbal
[LtKojn
U67_X
6,FG2d
zN`p^H(
1$Pm#[R
\{E=OR
YPJ"I{
tN|#aa
*K P]F
$ewH{fg
l&g\h&
b#h21!E
o1d.9YU
RsvESy
|ZA>z?y
2m`]C7
yf(X9:3R
o-{o'fc
7-qxHu
AOZh01
ls|d<o
0>8W;CL:
w%e^kD-
Y#0?=j
]|D}S.
5?a?[U3t
)Uk5b]
"d>;67
YNl`k("
+5%6JeFi
HS#{Wd
WcXD]j
qhtmKZT
/<fC-p"/
$Mev?k
g[\vqF
&HF3m8
~ay5|u
Gaa1:t
<E*XrM
2%[Uh[
eKK|.e
&ko@P
!t?Cf,Gb
8}*S/%u
@/RNkDyH
+I&wHs
a"PtZT
s%2'v
2cV|<
<$l`ba?Y
{H.,?D
w_+W]L
);ieR)B
CXcuvHH
>QRvudOkO
GF<Grw
!S51
%>,$?3
z\3Wc|*
5'_z-{
?T>f'e
u}P_lH
dVk<Np
|kPuMH
UJ3"'G
nHn(>l
:B T4^"
EisWX
}|CA6*M
^HzA3R
LNWy#B$
$IolPb
ZcidK5X
&`.c6Ag+
Hx&*RO>
Dzdj3G
^T*cm~ik
X)'#x)3
oEnq@$
06wG!%
*Lq#n:J=4
:U-jFW
e@u2"R
~0>cSXC
#k5EA
mEqN}eS
{8HS;N
_7m!P{=/\u
X@B7etlR>z
:gC-A,
y"W=pT
\'*ak^'
@sZz#`y
I2r.kF
{8NW}~
@@ZZd
@cBs+E
p2n$/ST|
_o93{3
V$#_Pu)
Z\mT4g
g!.tfT
{A.rGf
!'f"!V
smQp(+!_
BoG};E
REz-CoXc
Ily>:_
qEd0uL
;(aXit3
U`uY/H
lUOMLP
SK!gWLa
]vM+yv{
av8'Y!d
!lT42N
-;)Gh?
Dnt9~t
-6> +
_ENgM`
N&{ft=
CW58K
rPTL`(G
.!>|Fb
3w_1aW
9"m)o$
Vxni_a
wZ,?NT
{j'XlY
_h83vxa
;)MFhd
EId5Dbfox
<%l7f}
-,I*$h
D<!KQ+
}^B1>JJ
%`'f"7
i[_Tg.
.b*PcS
_?y{6t
9V{&I9#
g`2s2O
<tj^_@
FO~G"<B}G
4VZ8\t.
0rAW%?
{=XRRu
Z1)2\9
t:y@$v
L}'^FH
P*5f|:Y
C65Z"I
=/;?(f
ileXFo
9m"sn>-f
*)o#O
@@E.yC
H#5NI%
-c0YHVz
b=rZ-H
(n55L<
jTxa{G
|2bjDl:
d/"GAa
CwuD"/
d:=$72Y
;3n[GI
U'H9+n
I@*0-V$
I*>O4V-
E,+23
i7/f"L
-4TR.&
zVl,`G
D^A1rm
cLPyMD
0w3C^>
@O|ob:
ig}7Ol
wIN^@9M&;
Y2]x`
z7dK-t129i
`o^kk-
2B~e"(
9,m8VT
-_ux[b
JnqKCc
CNoc,p
Too0[-[
)a>eW9j7ha
_[?M/g
r5UNX(n
ZXV2'h
TQ6p`.
D$O[nk7!
e}J@n{
$$| sQ
>vy "w2bC
qx'L*2
l3:~Y@
{3X{8~
AdST`?
+G/u\kL
%Lh{qx
Y;gE&7
Vi&6RUH
~Qq"(x
9A`1B
|Ns3\V
]G;=8vH
J^6_r;
ay61s]
O_Y-=;
9=B502
/}x0SfE
kqI#EI'
-V`EK<E
7+Z0y?
xDVPJcHK
?g36ui
ojNdgX0
B!YLS`
b6Si#`G
-9wTN)
L>=+SK
,8B5/!9v
\=&QFS
~\m>@h/
t%iGKJr1}7
LJmPTM
']QSG3
k%p)T<H
#7nI6fC
#:kuEd
$vMqzZ
6uD.C:
F|*7vS
Tn(z*!
4W5[ko
?HCK:4A
3W*-uFA
<^ol"Wa
RqC=IKA
;6Z!r_
UG1bdmUR
4$l$!d
;YI^t',
H9oU48
&*|kkG
IBLcR3
dX!9QE
=XWEt4oZz
{sz@ZR
n~Ldvq
T;O#i[
9YYm2A
SBf#9SL6
h3.;QA
w9Unw[9x
<MC"1k
L,3gS
lkuLTv
-?NN<p4
5(2/6j
d3]7n8
V2B/d_
\~x<uJ9
U$76&N
adtx^w
H$o4[=c
joF ow
'&H7C>I8Z"
=*9m>$
kOvLQi
5wsxzy
!]|VM)F
AQoV_*
buIyOe
M1%QWZ1
gY+0+C
HI&yj/+
CrhRpzSo
t4)N":
NZB1xBI 2{i
"T_Z%9.
Bw1%#x
K{ [Gl
3i2HIW,pn
c?34Rf
GRn72#
D\KB@0
P[WX Im6
hrmlAs4
b/]'TD
-gM7c:e@r
]2Wjcqw
]"Qw13
zuXH$
gD8KHH
FUCE9t
n&Q(</
Le0|gk
eXmrE5
?[`O"!-}iZ
pcO)pDe.G
=M{(AKN
a+;-7H
J"Lv%*
rnck/k
RF;=PB
}tX'5J
fR<MW@
e(~cM8
4izr--
Hj*eQY
5^-w_}
*D6|^U
S\Me|
*uu,5t
_#t# G
0Z~K~{6
4Vn|A%#
vUr1Hdz
])6M1?
>q]nQ'#
>Wp|(
Iyd3I(o
SDW,V3
#=Dex,
UNiulsM
j-<G;9
+*^B[L
SIBii)*
PkB3k:
?0gK)0
1u)Civ6
56>qT+`
}<Y6D+
!l1@`tWZ
.1aJiM
SrE[Sa
qsu-~#cVs
kG??~A
URxT _
J*"^7u
xAcLea$l
e=EQ*t
^l}Ej|
7^XrJ
"L[m*`
QI@dvPVucn
EJofKG
fQ3vZ?
{qL~+F
,%Zf K
lnjY<
1@mSy7~qTT
:'go1W
Ydx$f
OB2A}0+
v:-P-y
NnQQ(>
op[)zH"
`odGo/
frH;f+
ev"e]"
]Is'l$
S;$P\f
s/`"(6HZ
|~&tXl
pupsr
%=f#ITo-qs
$uO|QWy
<qA3`#
714SCi
u{+<kel1
>Zpb*i
Q\g';S
^>VEo-D
C9r%gh
O^%eb7
CSfX9YD
cJ,ck+/H|
I 3ac:
nN/9yk
^TpkcS
!.Sw*@
<s*%RE/
Ue)4$%
:@t$tA"=+
UYXRj'
IL\qOp
BsrnT
j3pF]YD
b&O?2>+`
kMMM>"
]JV <
J$<aPZ
e3Yv:*%
^rHOJ7
|"u}h`
$p,Ha
4]B0~5
Me^e 8a
M :3w$
`[3QJl,p
K~mJ^\x
rK8*+
xwAze<
G[q@$;jr~
KBzxi
DyHK+O
gb6Eb2
t5%Y?}
\?]2|a
l *w]x%k
)#=-7<
PeEbv`
=xt1$<
(7kx0q:
h}.+F~
>MST`I
v;i^gx
g-Sa%b
4u*|X9q
W&}d_L
94*GN#
KX,.zO
if)Fv/w
Y\8/|u
>wAPiU
_35&2o
)IQ0VEn
LFA:TxX
gd#yQaR]
/9hA,Z
&P_1 Y:%
qxUPDW
Qp>*"P
%bX=0M<
(Xe>^h
yL`JG\
QE9.MX
I\;.3S
C7Q52w=B
hFpV))9
s(wyz1
4'PA3{x
lP<~kS
.}l>D
?P.t;(
>%dsK8
I(D9>6
Xj2H}%
Lw(R9b
+Gi{fz
k7x9{g
0NRx+O
ab )Qh`
z0jQ8j]
6)t>'B
lQ7`J$
q#cI*S
}o6bg|
'w^ardNm
_KpZY'
5lm/drtk
^{.I]$>
3cL,+X
l4?x<c
,~PT1E
(l*'=(
g!m%\`
g?B[et
JdU@ J~
:ykr "
IN#SM5
Fgevx1Jf
q/?C6/
P-~tz
%8M6pl
p^YKM?#
rwYH|c
P3J$c^
#@HG&o;e
<#G8#s
ugUy4`
1TEORV:P
vaQ!-Z
P2j`gd
hd{$@q
X"~aug
P?g9;&
B~@$vJ7
q#J)R'
EpVo;,.Y
\y;zCU
Gm/lX8
QTL|6|e0\~
rPR;|z6g
h/v.6&mT
11UGs?zo]*l
p=?k-v
7Jds1^
}*MDf(0M
\7z ;q
a^5H?(
m nj[!
)v}*D\
n2ijZI
y\ovCc
y~27*z
c']k>kv
#{.lrS
J(EZxS=
o1a^}0
}``4ARrz
vNO>sQ
afCEpz
D|fWVE
Rwg3).?`
c#W#P0
WV&pfD
Aafx)5
Q4OO]U2
hUYdh\
\!XZsF
gQ>=g5
f&&1y#.c6k
Jv[_vB!
Ncx3I7k
sU:d42_n
EmFp[.
}]yi}B
.ORTB&8
\LcKjdV
o3_AD=
?>3b(
L"n"6A#v
?;N 3I[
0*QS\k
uVNFa!re
<M &i<
;%~240
fm,a!m
Ykf4@A
~sx^_D
_?y'~T@
hU-@U}
v,VP7.<
IN&h;
NE@}<K
dLJo]N
A,_3I\
m.{CGi
0!KG^`|[
K!twb=(
e!BBK
v)%T~O
;8=}1=
<'j`cC
Y0D,J-
Dg_6P7
ZnB|AD
i7T" r
P e]REW
I`#aCQ
I.)@,w?
LYshh\oBCd
1 9Z?]
_QYpZh
y6'RAy
p!4m#B
SMBkkX
!C^#bB
e wEZh
z,|<:9{
.|T3iE
"?An6L
?$V${^]=,
)kw%N1
ic}Z:Dk(
)Q+0{vK
ZV]Pxn
[45|BF
uWa]23@
D'WwVa
3j ]{sm
gbpV"4
QTvmh.\lM
~G|PH) "
@5j_on
D4q,g
J!(>Af
Ko-cd`4
Gv1KK]
Y;r;m?
NaAHQX
.h)[x(
=}Gw[.W
5 bU|
oe*rpqZ
m|m:s!
'pQovv
O~gQMR
KO;ki{2'
(@k"s\
C%s_LCoE
-"XR/
Evzec;
<>?e|6
2kZd_6e
%%k0(P
4B$"px
R-IOT$
C!T\A%0
!a8vfV?
o95zS~
bo:<vE
;0.p(M
%orS3^
WqL&pA/
qpbda]
/4("T5yV
Ce{Gol%z%
w"gD1u^
gModZ]
#2LS=Moq
.Po_n
|4t=$}
`k.,\:7
CxTZT<
EywZg>
n(EsEU
Q^dQYD
*(UHi%67Z
4N`KBQ
P]_%&c
jmA]ak.
)(i, ]X
^{)s3!G
B)>fO\L
Zk|,Y_
+hkv"j
xax:j6
y9ss_
Vh<uE|
0ISj^G"t
m+"c>D
q@E ud;
"2fgt[v
q3B]Vv
h8`C.<
&;CV>*
(~s7pY
\Y&_O8
t\u32W
*}r7P4
e%dR=y
$hMi*I-
+RrITJ
9x~GcL:
|adtS|
mCL9=qL
)w<M$C
rN6BfD
)F(6Di
.V3ENyO
pQvu3,
*8*U6fg
ND]cjz
(p+YpL
y\]9()
U<MYTG
Xt$Ev
_Jau(^
Ca(oU^
8X*8q<8
v/[? 5
EO[|Q:
&Doa8C
.O=m8u
3lzj+P
o1BqZ]A
HkZ%U?
r2?Cl\
G]iS<#
L2\Kzq
b-B$I,
w:X1@~jF
mcT6S&v
2Xx(<w(
MD^Z'?
m\x!0?
7_Ci$tz
dH;Z~0$
9`3@8>
'h-a.!/+R+
WO6r2hM
"_"AOR
zu^d=T
@l q H
U]RO#H
U 9]3F
v,}:r-
.<c-t^
B5j"(<
.0x"}()
B:".R2
IDb<fIHk
expMLtS
8rF/d<C
5fo.[C<
vX,nT^
DlWF?|z[!
NJBaI..
Pz;\tv
FB;(%z
=Tq43M
V#-EOw
BF|36
Sd&gI;
m{t7,_%
)25wF}
{@~ILe
V(cEv:kY
:cp0_!L
vj;kc0
?5u%TA
G>rD~u
ud?&:~
M[t{i4
N0PHJJ
&u+N@1@
ekw&W9d
@J \$(-9
nd|L2>
`B2n"~
H*hv#@
\!`in$
]$-uX+b
k.GzvXn
6kS MY
u`Jh7S-
ee9t`{
8u:XMn
3al/-7 9
)USzAte|
3_A9\h
sKDtg]
8{9L\pa3g
zJgf=qehKn
ixrb^=R
H>5 ;H
]Qd2tW
Z;]&[ K
h/mH\}
]n*vv&
y:ce?U
_+~#d_
g?%#q28
Xr12f*7
NztIL!K
h,:nT<
h]LJ*W
6G?9 :
'Pfn:d
mPII;a
_I@C:s
];ya!Q6
*0d%v$G
[/?${k2Y
[TR[1~
+bE|OF
6u)*Ft
YF4H*p
\%sdnk
Xl;[^
1:V]#$
Y@A.b'
350;tCX?
{5{E=]
Y4$aUl
CiIrOU
G<?Qv
3:za+&v
(ofc%a
z]~K#l9Ztd
*sD1gF
&n-Yz=
>bpy~V\
m34.:_=
{I3:N*
uy,.bY
/V<AGO
p"3BEa
7h%4Zi
wv2:J(
6d_J&'
? sW~'
6O^T<jS
oF]n6
`GVI{}Qq
:Bm&f<
jA}<TV\
Xz?y$V
M(g1;;
M9x?2d>1
s :Jd?k
wx`qGMMa
sYYk4+
7:McW:
=lHz^m,
'40J<"
:6wOZ)
+):9X8
_#ofYQ,
E2:NKHC)
[%\C6S
nPK>#4
6}W-F'
w#vrL/n"
SmvF'\
FJ=}ly
D\<@OIj
L#soe;
k)P-F7
P5k1$u
D\\l`&
mOb1VKY,
yb`DiB
_fg#%V
#\BQj3
(8 wcv
Q'=S<h
1#gXmA
VB0).
3s^&e~
H+0X~T0n
\YCn|
U#+y"@
b9%x~1
leGkTH
C\obes
E*-R!zK
?e*s:w
2fBS-3;
Za@C}7
k^VQ72
v4r2q2V
/I$Glc
7`O4uf%
T|US+<
9$[[-v
{<<Tj1
]j)F{S
#_Az;?%
A4f{/LT
qy:q+ o<
wd9G!h
3i~z8-
3=8x*O3
8s$_3A
3&)-2'J
6)tC=N
D-{49e\a
JDrn4c
,tv:"#
\YbcJjC
E+%Y1Sd
W)Shi}q
yAo-V8c&
PHC HM
[bW\Ji
Z'=F"
6Za96,
BnBbs/
?/tGT*R:
DA/f'?
Q~<~FN
&Ws$FK
/=WY!
&NEe6_
YpJ]/+
hfx}=4
ViMS".
}~{Z^
0Bt&R1
Kw.{;e6-
idS.o<
Yjc]qu
U}]WeP
08qwac
[@xPXE
4={MZ_C{
$z2No0
$n^vmS4
z0{A+W
LJ|LumK~
^^'yN6z
tcL@gL^
SE9Y9k
'=E6tg
U6Xlt8
JNk;5&
>Vsg^f
@]Rw3=
Cw*M7/
wu&@7.8/
{NY?'1
g^`gBR?M
R+aW63
MUzY%)/t
N:qL(y
g(m*\+
b73\31
:o'n0_
iR4KLh
GxqGV0
Mo,-}?Ue&y
Uhv9Yf
9*b|@h
V~.sOh
7"[CIp
B(Fec0
";8QbX5sc
GW9Dhp
5jCV+L
9K($At
(?{s([
6q]T_x
B&bb5
,KES7e
HYfS,@
@GA0uR
,#^4GO
UgGkh_
]N~gRv
w@p_p
muM5=I
nyw447
XU<4/zXr
CT3"\.
-XBX)/eN
SL.+IC
'_I-]"
9}f14D
AS#g]y
f)j6hA
"'T:zy'
d6>dAL
gSl^[w
Xf(p|b
;D60'T
Rp)~R35 ^
_PD&m
kpH){^
$/AqYB
ftxLo{M
tQe`+>^w
Tz?' f
-bF37"ZI
)z_!\W
j._@&^B%
FwTEm[
.K9@DzH
^%W|\JG
}E[zX\
Oj.!Si
c4+Lz`V
,I;`Z&lw$
G[D'l|
zL}QGIE
ftw1zT
%GSjig
_-Xu>X
PIo8i[
b)2@mR
4WA@&\w
3DH=|d
]29K|_
+6'|?e(
\aPS2X
H3~HrR
1ybBxWZ
vAAHH.
=W:>7.
'}(Z}}
E]:q~~P
Lo;dqG
OJTa2&5
a30CCO
Gf|Gcj
YcR*O
3fp6kE
-b=q@W
I;sWro
yI|*#.
j.sb
8=Cs[6
_trGp
^|w0q@
='*(D$
w9x >S/
Q@FqL#
9IEhQR
8jq4w$M
G] xPH
ew,Yir|4
g`+H9X4&o
Nr`g%Ja
6(R'/[
C+S-%'
Pk[[I,
G#s+ |
!zl?EP
^N<T{
;8nDW7
pbGdGx#F
libgcc_s_dw2-1.dll
__register_frame_info
__deregister_frame_info
libgcj-16.dll
_Jv_RegisterClasses
kernel32.dll
AV2quPQPzM1PFAqlvAYnPpsFJ9CGZUk
Mingw runtime failure:
VirtualQuery failed for %d bytes at address %p
Unknown pseudo relocation protocol version %d.
Unknown pseudo relocation bit size %d.
glob-1.0-mingw32
GCC: (GNU) 6.3.0
GCC: (GNU) 6.3.0
GCC: (GNU) 6.3.0
GCC: (GNU) 6.3.0
GCC: (GNU) 6.3.0
GCC: (GNU) 6.3.0
GCC: (GNU) 6.3.0
GCC: (GNU) 6.3.0
GCC: (GNU) 6.3.0
GCC: (GNU) 6.3.0
GCC: (GNU) 6.3.0
GCC: (GNU) 6.3.0
GCC: (GNU) 6.3.0
GCC: (GNU) 6.3.0
GCC: (GNU) 6.3.0
GCC: (GNU) 6.3.0
GCC: (GNU) 6.3.0
GCC: (GNU) 6.3.0
GCC: (GNU) 6.3.0
AdjustTokenPrivileges
GetUserNameW
LookupPrivilegeValueW
OpenProcessToken
CreateFontIndirectW
SetBkMode
SetTextColor
CreateThread
DeleteCriticalSection
EnterCriticalSection
ExitProcess
FindClose
FindFirstFileA
FindNextFileA
FreeLibrary
GetCommandLineA
GetLastError
GetModuleHandleA
GetProcAddress
InitializeCriticalSection
LeaveCriticalSection
LoadLibraryA
SetUnhandledExceptionFilter
TlsGetValue
VirtualProtect
VirtualQuery
WaitForSingleObject
lstrlenA
_strdup
_stricoll
__getmainargs
__mb_cur_max
__p__environ
__p__fmode
__set_app_type
_cexit
_errno
_fpreset
_fullpath
_isctype
_onexit
_pctype
_setmode
_strdup
atexit
calloc
fwrite
malloc
mbstowcs
memcpy
realloc
setlocale
signal
strcoll
strlen
tolower
vfprintf
wcstombs
ADVAPI32.DLL
GDI32.dll
KERNEL32.dll
msvcrt.dll
msvcrt.dll
IDATx^
y#"ODFd
{CZ_n4
KS!TC!x#*h
%#sCg8s
3N^5k/S
sRv:_S
;*^?!T
V3>quo
n;\s{
6YnCX`
A[]/KA
eyp9Ly
$|vpOZ H
ZlY?gk
]<iRLxC
1 Nla^
pM1?,Lc
@U`LiI
A *h(_
&<2mQ^
8qy';=(i
z|-f;.
|M*|'k[
i<032eE
%q\pe!
bFWBlRa
AoA[RmL
(Sz/yJz
l'Sa$<
":pXMh
|~kb?
@0P^^A}[.
S`Yl=F1
@]72}?g
f!"rQ /"_"
fn^A$[>
m{!\4;
Tf~xO#l
c?\F|@
"X=ssD
v |.o@
3X}AmG
L*_{>)O
|a2<Gb
R^>=n_
[M7Y1!
}MTq\_B
] hhK#p
^vTG`@
dp<UE9~!jw
r6YK4",
:::::::::::4:::9::::5:::::::0
:::9::::9:::::::4::7:::::::::::67
#RPERRRORFRRRRGRRRRRRRRRRRRRRRRRRRRR
$YVYYXUYYYYVYYYYYWYYYSYYYXXYYYYYYYYYYY
YYYYYY
YYUYYY
pJC.C_
!)++++'+*++++(,+-++-+++%
""""""""""""""
$$#$$$$$$$$$$$$$$$
$$$OOOOOOOOOOOOOOO,OOOOO$!$
OOOOO.O6OOOOO
OOOOOOOOOOOOO
OOOOOOOOOOOO:
OOOO=JOOOO>O
DOOOO9OOOO*O
OOOOOOOOOOOO
OO7OOOOOOOO
&OOOOOOOOOO8
OOOONIOOOO'
OOOOOO/OOOO
(OOOO3OOOO
_ifiii
OOLKOOOOOO
OOO2OOOOO
iiiiiii
OOOOOOOOO
OOOOOOOO
iiiiaiiii
OOOOOOOO
OOOOJOO%
iiiiiieiiii
'OOOOOOO
5OOOOOO'iiiiiidiiiiiiOOO?OOOO
OOOOOOOiiiibhiiiiiiiiiOOOOOOO
4OOOOOOOOOOiiiiiiiOOOOOOOOOOO
O;OO<OOOOOOiiiiiiiOOOOOOOOOOO
1OO)OOOOOOOiiiiiiiOOOOOMOOOOO
OFOOOO0OOOOiiiciiiOOJOOOOOOOO
OOOOOOOOOOOiiiiiiiOOOOFOOOOOO
O-OOOHOO@OOiiigiiiOOOOOOO+OOO
OOOOOOOOOOOiiiiiiiOOOOOOOOOBO
QQOAOOOOEOOOOOOOOOOOOO7OOOOP
TQOCOOOOOOOOGOOOOOOOOOOOOTT
TTTOOOOOOOOOOOOOOOOOOOOOTTT
UVXRXXXXXXXXXXXXXXXSXXXXW
^^^^^^^^^^^^^^^^\^^[^^^
^^^^^^^]^^^Z^^^^^^^^Y
333333330
"323333332"
ffffffffffc
""""""""""0
x<]K4",
%&&&&&#&&&&&&&&&&
(((+DD3DDDD>D>DD('(
DDDDD><DD>$D:DD<DDDDD
DDDDD/.DD$
*DDDDDDD0;
DDDDDDCD-
DDDDDD?7D
DDDDDDD<
aaa!DDDDDDDD
DDDDDD=
aaaaa!D968DDD
DDDDDDaaZ[aaV"CDD>,D
>DAAD Ua]a]aaa)$DDBDD
DD?DD$aaaaWaaaa$DDDDD
DDDDDD>Daaaa`DD5DDDDD
DDDDDD;D]aaaaD>DDDDDD
DDDDDDDDaaaaXDDDDDDDD
D7D>D2<DaaaaaD:1DDADD
D>DDDDDDaaa_aD4DD>:DD
DDDDDDDD^\aaYDDDDDDDD
F7D>DDDD>DDDDDDDDC@DE
IIDDDDDDDDD8DD6DDDDGH
JNNNNNNMNNNNNNKNNNL
QTTPTTTRTQTOTTTTS
WwwwwwA


)))()))
)))
)))
)))
)))
!
"$$$$$$$$$$$#
&&&&&&&&&&%
5UVUeV
gwwwwwQ
wwuGuwu
<?xml version="1.0" encoding="UTF-8" standalone="yes"?><assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0"><assemblyIdentity version="1.0.0.0" name="MyApplication.app" /><trustInfo xmlns="urn:schemas-microsoft-com:asm.v2"><security><requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3"><requestedExecutionLevel level="asInvoker" uiAccess="false" /></requestedPrivileges></security></trustInfo></assembly>PADPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDING
VS_VERSION_INFO
StringFileInfo
040904b0
ProductName
d9ExAYYAWLWG7
ProductVersion
8.1.8.4
FileDescription
d9ExAYYAWLWG77TB4eJOl7DLVnR1JELk0hpwuWKx
CompanyName
d9ExAYY
LegalCopyright
All Rights Reserved
Comments
d9ExAYYAWLWG77TB4eJOl7DLVnR1JELk0hpwu
VarFileInfo
Translation
Antivirus Signature
Bkav W32.AIDetect.malware2
Lionic Clean
Elastic malicious (high confidence)
MicroWorld-eScan Gen:Variant.Fragtor.31624
FireEye Generic.mg.954cb27a8b7a8022
CAT-QuickHeal Clean
McAfee Clean
Malwarebytes MachineLearning/Anomalous.100%
VIPRE MultiPlug (v)
Sangfor Clean
K7AntiVirus Trojan ( 0055037d1 )
BitDefender Gen:Variant.Fragtor.31624
K7GW Trojan ( 0055037d1 )
Cybereason malicious.7c5a8f
BitDefenderTheta Gen:NN.ZexaF.34266.nL0@aGDW4mki
Cyren W32/Stealer.M.gen!Eldorado
Symantec ML.Attribute.HighConfidence
ESET-NOD32 a variant of Win32/Kryptik.HNCG
Baidu Clean
TrendMicro-HouseCall Clean
Paloalto Clean
ClamAV Clean
Kaspersky VHO:Trojan-PSW.MSIL.Agent.gen
Alibaba Clean
NANO-Antivirus Clean
SUPERAntiSpyware Clean
Rising Clean
Ad-Aware Gen:Variant.Fragtor.31624
Sophos ML/PE-A
Comodo Clean
F-Secure Clean
DrWeb Clean
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition Clean
CMC Clean
Emsisoft Gen:Variant.Fragtor.31624 (B)
Ikarus Trojan.Win32.Krypt
GData Gen:Variant.Fragtor.31624
Jiangmin Clean
Webroot W32.Trojan.Gen
Avira Clean
MAX malware (ai score=82)
Antiy-AVL Clean
Kingsoft Clean
Gridinsoft Clean
Arcabit Clean
ViRobot Clean
APEX Malicious
Microsoft Trojan:Win32/Stealer.RPR!MTB
Cynet Malicious (score: 100)
AhnLab-V3 Trojan/Win.BackDoor.R447594
Acronis Clean
VBA32 Clean
ALYac Gen:Variant.Fragtor.31624
TACHYON Clean
Cylance Unsafe
Panda Clean
Zoner Clean
Tencent Clean
Yandex Clean
SentinelOne Static AI - Malicious PE
MaxSecure Clean
Fortinet W32/Fragtor.3162!tr
AVG Win32:PWSX-gen [Trj]
Avast Win32:PWSX-gen [Trj]
CrowdStrike Clean
No IRMA results available.