Static | ZeroBOX

PE Compile Time

2022-12-03 05:26:42

PE Imphash

a35f121ed76d9b1e75ce64250798b7ea

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x00017ee7 0x00018000 6.52506955632
.rdata 0x00019000 0x00034ac2 0x00034c00 6.38002509977
.data 0x0004e000 0x000131b8 0x00011e00 7.41506862816
.pdata 0x00062000 0x00000d80 0x00000e00 5.04115512775
.gfids 0x00063000 0x00000014 0x00000200 0.24044503451
.rsrc 0x00064000 0x000001e0 0x00000200 4.71767883295
.reloc 0x00065000 0x00000b28 0x00000c00 5.26320794809

Resources

Name Offset Size Language Sub-language File type
RT_MANIFEST 0x00064060 0x0000017d LANG_ENGLISH SUBLANG_ENGLISH_US XML 1.0 document text

Imports

Library KERNEL32.dll:
0x140019000 CreateFileA
0x140019008 CloseHandle
0x140019010 GetLastError
0x140019018 CreateActCtxA
0x140019020 ActivateActCtx
0x140019028 DeactivateActCtx
0x140019030 CreateThread
0x140019038 ResumeThread
0x140019040 FindFirstFileA
0x140019048 FindNextFileA
0x140019050 GetStdHandle
0x140019058 ReadFile
0x140019060 GetFileSize
0x140019068 SetFileAttributesA
0x140019070 ReleaseActCtx
0x140019078 CreateFileMappingA
0x140019080 CreateNamedPipeA
0x140019088 PeekNamedPipe
0x140019090 ExitProcess
0x140019098 VirtualAlloc
0x1400190a0 RaiseException
0x1400190a8 RtlCaptureContext
0x1400190b0 RtlLookupFunctionEntry
0x1400190b8 RtlVirtualUnwind
0x1400190c0 IsDebuggerPresent
0x1400190c8 UnhandledExceptionFilter
0x1400190d8 GetCurrentProcess
0x1400190e0 TerminateProcess
0x1400190f0 SetLastError
0x1400190f8 HeapAlloc
0x140019100 HeapFree
0x140019108 GetModuleHandleW
0x140019110 GetProcAddress
0x140019118 TlsGetValue
0x140019120 TlsSetValue
0x140019128 FreeLibrary
0x140019130 LoadLibraryExW
0x140019138 CompareStringW
0x140019140 LCMapStringW
0x140019148 EnterCriticalSection
0x140019150 LeaveCriticalSection
0x140019158 IsValidCodePage
0x140019160 GetACP
0x140019168 GetOEMCP
0x140019170 GetCPInfo
0x140019178 GetModuleHandleExW
0x140019180 GetStringTypeW
0x140019188 MultiByteToWideChar
0x140019190 WideCharToMultiByte
0x140019198 HeapSize
0x1400191a0 HeapReAlloc
0x1400191a8 RtlUnwindEx
0x1400191b0 GetEnvironmentStringsW
0x1400191b8 FreeEnvironmentStringsW
0x1400191c0 SetEnvironmentVariableA

!This program cannot be run in DOS mode.
`.rdata
@.data
.pdata
@.gfids
@.rsrc
@.reloc
@SAUAVH
CP+Cp5q
UATAUAVAWH
PA_A^A]A\]
PA_A^A]A\]
SUVWATAUAVAWH
T$hH;4
A_A^A]A\_^][
t$ ATAVAWH
@A_A^A\
@SUVWATAUAWH
PA_A]A\_^][
t$ AVH
|$ AUAVAWH
A_A^A]
\$ UVWATAUAVAWH
D3V,D+
F@D+F0
PA_A^A]A\_^]
t$ AUAVAWH
@A_A^A]
SUVWATAUAVAWH
A_A^A]A\_^][
SUVWATAUAVAWH
t$xMc$
A_A^A]A\_^][
SUVWATAUAVAWH
A_A^A]A\_^][
@SUVWATAUAVAWD
fA9DNJwrA
A_A^A]A\_^][
SUVWATAUAVAWH
A_A^A]A\_^][
WATAUAVAWH
A_A^A]A\_
SUVWATAUAVAWM
A_A^A]A\_^][
WATAUAVAWH
A_A^A]A\_
E3ApA+
UVWATAUAVAWH
A_A^A]A\_^]
VWSUATAUAVH
wA^A]A\][_^
fffffff
VWSUATAUAVH
wA^A]A\][_^
fffffff
VWSUATAUAVH
wA^A]A\][_^
UVWATAUAVH
HA^A]A\_^]
WAVAWH
0A_A^_
WAVAWH
PA_A^_
|$ ATAVAWH
KL;Ktw7
0A_A^A\
WATAUAVAWH
A_A^A]A\_
UVAUAVAWH
PA_A^A]^]
WATAUAVAWH
CD3CP5c
A_A^A]A\_
|$ AVAW
|$0A_A^
)|$`H#
)|$`H#
USVWAVH
A^_^[]
WATAUAVAWH
A_A^A]A\_
l$ VWATAVAWH
L$&@8t$&t0@8q
A81t@@8r
A_A^A\_^
u3HcH<H
SVWATAUAWH
HA_A]A\_^[
@UATAUAVAWH
e0A_A^A]A\]
@UATAUAVAWH
H!T$0D
uf!T$(H!T$
A_A^A]A\]
L$ WATAUAVAWH
@A_A^A]A\_
WATAUAVAWH
A_A^A]A\_
ffffff
UVAUAVAWH
)t$@M+
PA_A^A]^]
u:8T$@t4H
SUVATAUAVH
t|HcF
(A^A]A\^][
L$ SWH
>ffffff
fffffff
ffffff
fffffff
fffffff
fffffff
fffffff
^8U)zj
0ffffff
fffffff
fffffff
fffffff
fffffff
ffffff
fffffff
fffffff
fffffff
fffffff
ffffff
WAVAWH
A86taH
0A_A^_
@USVWATAUAVAWH
e8A_A^A]A\_^[]
fD94Fu
UVWATAUAVAWH
tPH95)
0A_A^A]A\_^]
I96t4H
xWI96tRI
@8t$p@
LcA<E3
SUVWATAUAVAWH
HcD$tI
LcT$xH
A_A^A]A\_^][
@VAVAWH
A_A^^
A_A^^
|$ AVH
UVWATAUAVAWH
0A_A^A]A\_^]
@SUATAUAVH
@A^A]A\][
T$THcL$T
SUVWATAUAVAWH
XA_A^A]A\_^][
UVWATAUAVAWH
A_A^A]A\_^]
UVWATAUAVAWH
A_A^A]A\_^]
T$hB9D
t$ WATAVH
0A^A\_
SUVWATAUAVAWH
hA_A^A]A\_^][
UVWATAUAVAWH
@A_A^A]A\_^]
WATAUAVAWM
A_A^A]A\_
SVATAUAVH
@A^A]A\^[
t$ AUAVAWH
@A_A^A]
|$ ATAVAWH
@A_A^A\
L$ UVWATAUAVAWH
l$0Lc4(
D$xH+T$@H
A_A^A]A\_^]
|$ ATAVAWH
0A_A^A\
SVWATAUAVAWH
A_A^A]A\_^[
VATAUAVAWH
0A_A^A]A\^
L$ SUVWATAUAVAWH
xA_A^A]A\_^][
uu$$u$
scar approval invention race rueful bending succession commonly eyebrows cloud expressive perpetual spring drawn galactic birch barn Russian arrival attributed sleepy show mechanical tip timetable claims entertain carrier moisture broadcast lucy agree basis bread delusion possibility file preserved flare shipwreck lit potatoes earthquake earth dived attend thorpe niche soothe proceedings emerge section logic reverse remain tame false parts disappearance extinct fear labour corresponding print exception happiness survive skin shaggy ban ambitious labor photographic leaf partition you destroyed reading dormitory switch hay affect bowl colored helpful hiking frosty bang kiss strangely bleeding stagger sustain protect rust suggestions farther hump satisfactory creak privileged advancing imprison starling generally parsley resources comment opt everywhere farther fiend enclose swing tyre rear teacher weeping worse fruitless opportunity married majority prospects sacrifice defiance matches previous apartment scarf
[*ncd>TQ
\>$hkDh$h>
GfZ+?p
>+>ZQ"v
]Acosh
= {[8V
?N]TUUU
?UUUUUU
[*ncd>TQ
\>$hkDh$h>
GfZ+?p
>+>ZQ"v
]Asinh
CompareStringEx
FlsGetValue
FlsSetValue
GetCurrentPackageId
LCMapStringEx
LocaleNameToLCID
Sunday
Monday
Tuesday
Wednesday
Thursday
Friday
Saturday
January
February
August
September
October
November
December
MM/dd/yy
dddd, MMMM dd, yyyy
HH:mm:ss
CorExitProcess
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
N8?TERM
AV_LOG_FORCE_NOCOLOR
AV_LOG_FORCE_COLOR
AV_LOG_FORCE_256COLOR
verbose
warning
[%s @ %p]
BSF_NOT_FOUND
Bitstream filter not found
Internal bug, should not have happened
BUFFER_TOO_SMALL
Buffer too small
DECODER_NOT_FOUND
Decoder not found
DEMUXER_NOT_FOUND
Demuxer not found
ENCODER_NOT_FOUND
Encoder not found
End of file
Immediate exit requested
EXTERNAL
Generic error in an external library
FILTER_NOT_FOUND
Filter not found
INPUT_CHANGED
Input changed
INVALIDDATA
Invalid data found when processing input
MUXER_NOT_FOUND
Muxer not found
OPTION_NOT_FOUND
Option not found
OUTPUT_CHANGED
Output changed
PATCHWELCOME
Not yet implemented in FFmpeg, patches welcome
PROTOCOL_NOT_FOUND
Protocol not found
STREAM_NOT_FOUND
Stream not found
UNKNOWN
Unknown error occurred
EXPERIMENTAL
Experimental feature
INPUT_AND_OUTPUT_CHANGED
Input and output changed
HTTP_BAD_REQUEST
Server returned 400 Bad Request
HTTP_UNAUTHORIZED
Server returned 401 Unauthorized (authorization failed)
HTTP_FORBIDDEN
Server returned 403 Forbidden (access denied)
HTTP_NOT_FOUND
Server returned 404 Not Found
HTTP_OTHER_4XX
Server returned 4XX Client Error, but not one of 40{0,1,3,4}
HTTP_SERVER_ERROR
Server returned 5XX Server Error reply
Argument list too long
EACCES
Permission denied
EAGAIN
Resource temporarily unavailable
Bad file descriptor
Device or resource busy
ECHILD
No child processes
EDEADLK
Resource deadlock avoided
Numerical argument out of domain
EEXIST
File exists
EFAULT
Bad address
File too large
EILSEQ
Illegal byte sequence
Interrupted system call
EINVAL
Invalid argument
I/O error
EISDIR
Is a directory
EMFILE
Too many open files
EMLINK
Too many links
ENAMETOOLONG
File name too long
ENFILE
Too many open files in system
ENODEV
No such device
ENOENT
No such file or directory
ENOEXEC
Exec format error
ENOLCK
No locks available
ENOMEM
Cannot allocate memory
ENOSPC
No space left on device
ENOSYS
Function not implemented
ENOTDIR
Not a directory
ENOTEMPTY
Directory not empty
ENOTTY
Inappropriate I/O control operation
No such device or address
Operation not permitted
Broken pipe
ERANGE
Result too large
Read-only file system
ESPIPE
Illegal seek
No such process
Cross-device link
stereo
3.0(back)
quad(side)
5.0(side)
5.1(side)
6.0(front)
hexagonal
6.1(back)
6.1(front)
7.0(front)
7.1(wide)
7.1(wide-side)
octagonal
hexadecagonal
downmix
front left
front right
front center
low frequency
back left
back right
front left-of-center
front right-of-center
back center
side left
side right
top center
top front left
top front center
top front right
top back left
top back center
top back right
downmix left
downmix right
wide left
wide right
surround direct left
surround direct right
low frequency 2
top side left
top side right
bottom front center
bottom front left
bottom front right
QP2LAMBDA
ntsc-film
wqsxga
wquxga
whsxga
whuxga
hd1080
2kflat
2kscope
4kflat
4kscope
fwqvga
uhd2160
uhd4320
AliceBlue
AntiqueWhite
Aquamarine
Bisque
BlanchedAlmond
BlueViolet
BurlyWood
CadetBlue
Chartreuse
Chocolate
CornflowerBlue
Cornsilk
Crimson
DarkBlue
DarkCyan
DarkGoldenRod
DarkGray
DarkGreen
DarkKhaki
DarkMagenta
DarkOliveGreen
Darkorange
DarkOrchid
DarkRed
DarkSalmon
DarkSeaGreen
DarkSlateBlue
DarkSlateGray
DarkTurquoise
DarkViolet
DeepPink
DeepSkyBlue
DimGray
DodgerBlue
FireBrick
FloralWhite
ForestGreen
Fuchsia
Gainsboro
GhostWhite
GoldenRod
GreenYellow
HoneyDew
HotPink
IndianRed
Indigo
Lavender
LavenderBlush
LawnGreen
LemonChiffon
LightBlue
LightCoral
LightCyan
LightGoldenRodYellow
LightGreen
LightGrey
LightPink
LightSalmon
LightSeaGreen
LightSkyBlue
LightSlateGray
LightSteelBlue
LightYellow
LimeGreen
Magenta
Maroon
MediumAquaMarine
MediumBlue
MediumOrchid
MediumPurple
MediumSeaGreen
MediumSlateBlue
MediumSpringGreen
MediumTurquoise
MediumVioletRed
MidnightBlue
MintCream
MistyRose
Moccasin
NavajoWhite
OldLace
OliveDrab
Orange
OrangeRed
Orchid
PaleGoldenRod
PaleGreen
PaleTurquoise
PaleVioletRed
PapayaWhip
PeachPuff
PowderBlue
Purple
RosyBrown
RoyalBlue
SaddleBrown
Salmon
SandyBrown
SeaGreen
SeaShell
Sienna
Silver
SkyBlue
SlateBlue
SlateGray
SpringGreen
SteelBlue
Thistle
Tomato
Turquoise
Violet
WhiteSmoke
Yellow
YellowGreen
january
february
august
september
october
november
december
%H:%M:%S
%Y - %m - %d
%Y%m%d
%H%M%S
yuv420p
yuyv422
yuv422p
yuv444p
yuv410p
yuv411p
gray8,y8
yuvj420p
yuvj422p
yuvj444p
uyvy422
uyyvyy411
bgr4_byte
rgb4_byte
gray16be
gray16le
yuv440p
yuvj440p
yuva420p
rgb48be
rgb48le
rgb565be
rgb565le
rgb555be
rgb555le
bgr565be
bgr565le
bgr555be
bgr555le
yuv420p16le
yuv420p16be
yuv422p16le
yuv422p16be
yuv444p16le
yuv444p16be
dxva2_vld
rgb444le
rgb444be
bgr444le
bgr444be
gray8a
bgr48be
bgr48le
yuv420p9be
yuv420p9le
yuv420p10be
yuv420p10le
yuv422p10be
yuv422p10le
yuv444p9be
yuv444p9le
yuv444p10be
yuv444p10le
yuv422p9be
yuv422p9le
gbrp9be
gbrp9le
gbrp10be
gbrp10le
gbrp16be
gbrp16le
yuva422p
yuva444p
yuva420p9be
yuva420p9le
yuva422p9be
yuva422p9le
yuva444p9be
yuva444p9le
yuva420p10be
yuva420p10le
yuva422p10be
yuva422p10le
yuva444p10be
yuva444p10le
yuva420p16be
yuva420p16le
yuva422p16be
yuva422p16le
yuva444p16be
yuva444p16le
xyz12le
xyz12be
nv20le
nv20be
rgba64be
rgba64le
bgra64be
bgra64le
yvyu422
ya16be
ya16le
gbrap16be
gbrap16le
d3d11va_vld
yuv420p12be
yuv420p12le
yuv420p14be
yuv420p14le
yuv422p12be
yuv422p12le
yuv422p14be
yuv422p14le
yuv444p12be
yuv444p12le
yuv444p14be
yuv444p14le
gbrp12be
gbrp12le
gbrp14be
gbrp14le
yuvj411p
bayer_bggr8
bayer_rggb8
bayer_gbrg8
bayer_grbg8
bayer_bggr16le
bayer_bggr16be
bayer_rggb16le
bayer_rggb16be
bayer_gbrg16le
bayer_gbrg16be
bayer_grbg16le
bayer_grbg16be
yuv440p10le
yuv440p10be
yuv440p12le
yuv440p12be
ayuv64le
ayuv64be
videotoolbox_vld
p010le
p010be
gbrap12be
gbrap12le
gbrap10be
gbrap10le
mediacodec
gray12be
gray12le
gray10be
gray10le
p016le
p016be
gray9be
gray9le
gbrpf32be
gbrpf32le
gbrapf32be
gbrapf32le
drm_prime
opencl
gray14be
gray14le
grayf32be
yf32be
grayf32le
yf32le
yuva422p12be
yuva422p12le
yuva444p12be
yuva444p12le
vulkan
y210be
y210le
x2rgb10le
x2rgb10be
unknown
reserved
bt470m
bt470bg
smpte170m
smpte240m
bt2020
smpte428
smpte431
smpte432
ebu3213
linear
log100
log316
iec61966-2-4
bt1361e
iec61966-2-1
bt2020-10
bt2020-12
smpte2084
arib-std-b67
bt2020nc
bt2020c
smpte2085
chroma-derived-nc
chroma-derived-c
unspecified
center
topleft
bottomleft
bottom
[truncated strftime output]
?UUUUUU
?UUUUUU
?UUUUUU
?UUUUUU
UUUUUU
UUUUUU
?UUUUUU
?UUUUUU
?UUUUUU
UUUUUU
UUUUUU
"e?<<<<<<l?
Il?333333c?
.i?0@I
d?000000`?
)|B?d!
L?UUUUUUU?
&?PPPPPPP?
0X8b?~
%GoU?*
(T?j?Y
Zod(^?
D W?{W
qS>g?h3
c?FA@s}
UUUUUU
UUUUUU
?8bunz8
?@En[vP
[*ncd>0
S>$hkDh$h>[2
UA>N0Wl
9>UUUUUU
UUUUUU
@^8U)zj
A03>A|
Q5rHg,>
Hk=>:
j>>A?1
.>PJ;I:qE>
:>t6k'
])6M>&
CWD>~3
_oD>Kg
N>O=I9
F>qUxv
/2GG>!B
zY;>u:m
P>q_Y~
0><[cZUg^>
Y>kX>M
H[><y5
?UUUUUU
?7zQ6$
eplyby539yj06.exe
CreateFileA
CloseHandle
GetLastError
CreateActCtxA
ActivateActCtx
DeactivateActCtx
CreateThread
ResumeThread
FindFirstFileA
FindNextFileA
GetStdHandle
ReadFile
GetFileSize
SetFileAttributesA
ReleaseActCtx
CreateFileMappingA
CreateNamedPipeA
PeekNamedPipe
ExitProcess
VirtualAlloc
KERNEL32.dll
RaiseException
RtlCaptureContext
RtlLookupFunctionEntry
RtlVirtualUnwind
IsDebuggerPresent
UnhandledExceptionFilter
SetUnhandledExceptionFilter
GetCurrentProcess
TerminateProcess
IsProcessorFeaturePresent
SetLastError
HeapAlloc
HeapFree
GetModuleHandleW
GetProcAddress
TlsGetValue
TlsSetValue
FreeLibrary
LoadLibraryExW
CompareStringW
LCMapStringW
EnterCriticalSection
LeaveCriticalSection
IsValidCodePage
GetACP
GetOEMCP
GetCPInfo
GetModuleHandleExW
GetStringTypeW
MultiByteToWideChar
WideCharToMultiByte
HeapSize
HeapReAlloc
RtlUnwindEx
GetEnvironmentStringsW
FreeEnvironmentStringsW
SetEnvironmentVariableA
]DWJ"<
JE0*5p
0/#b:T>
]"@' 8+
?%JDva
=dQLdBf
a7x|c[
JFEWFP|t
px&5=Z
J9=R?Q
RzJ3nl
odJ1g?1!V5
H,rUrJ
=},n_&t
_y<@?+
VYH`uO
[,MbSA
?C8g|RWQ3
4:D5n+
Y\]P)iw"A
4OmhRYjO
/hDQ$0
\9^Jg]F
1=&rY9.IB
</F_huK
Gc| \K
E%DH,`
k[+h?)s
t_eO(I
{u!2DM_
;q6.%t!#<
=Ve/}T#
Jh6Jq|
9^IFEor
/Vm`1y
.5PclL^
;XY!_Hs
8-V1?(
q{B#R([Lt
&oH@nxR
+rCD1X
_(pv5h
a"ZNZF
(tNr@el*
5DG`h<
b2l`g~e6L
lpH&V;H
;.*a(om-
U9&_?]
Lkp8V4
,EUbQnT_
A}Uq3&
)T*&|&7
1AEthUrV
W#>u}f/e
xAObx0(:
j>hk2$
TIJ}8
W)M7Op
!n.H:`
hws'2;
DM'gP!
\Ow!"O
l/N)V#*
*{D[mJ<
wvr[ML
2^R;]
V TrLqH
sC};%"p
Wk:DqC
+E<m"4
m'f{)pb
9U-qaP
h~)PnW
G)N)[-
})pKC#M
h!,I##s
ZOU,Q[
)Rl'^!
X&t~`+)
=.hz!b
ZL6Vn2
4_#k/]9)
zRETj3
QmQr@b
6JF*/a4
|M`,V.
k!}\C&
I:H3[x
QhjT\m
Dz6B<W;
yLW8sR
mGFIn`,
{PUJ}Z*U3o
^Hn{g-
]>MswgGG
c:zwF.3OX
j:+o^Z
`K(\k
*\(bL)
;12NNLn
e`Uu]8
M&]_rB_
}pJ$h\
~T.O`G<
&c^c0Q
OD@t>,e)J
"l%nm!
c`ZGO1kt
8=.EOL
OhLBJk
"O/kkf[
Q?39KY
HTQPjI
a"#tz|r/X*p
m-A|#0-d`
;0FI_U
uIp~.]nv$=
UC6QW
"hSx9r
BJj,ABCv
1J#gM|5'Z
5wg.<V.I
`<.aX)+
>r9TU5azU
MNeCL`
4YZ_u9
U8D?U&
iqf\c
[*:PP)GJ
@l(d\H
]z,yhp"
arm&MR?
(pH}c
_'B7M9
j'#-f@
,6`)/p*
WEY&rr
YBD%PD5
MCTS5FS
&=vE\]
n<U;{8*
@T2rB49>
8LVA-M
DTxxN8S
o,DaS\
#tcIUNPPq
seXc33
tjRd4>
s:BCjS
S>fw`[
K5;D:@
UIxU`e9v
R)]KoNhU
NIp`~9
.T l~
dou?d0
CgATGA
!iCvI,
z0f0`JG
gDhT{?
?C2F"L
Pr:x%J
Dkb328
[=kN[@:ye
}\X_X#x
^7n_xp
gi(5Bq8
%slA\\
dSO%I0V
|?K.^9
8?.Zlh
CM0!]/
H{i<V(
0XRBNr
2*uD`>
74t<N[n
yubh)a
flOX<
5:KI|UI
zN&,2j{
qD\zVJ
OIYwn:
EJS&M^
x9xMxXOF
:H~b=
H(j..lhR
nD::X*
`qp8'0l
?5\scr"*
.l|;_-
A5@rm5Y@
P5YM5uV
5Zc/Gl
u12&wc
JOK_(0d4j0'
u$NTxmY
$%h]YJ
Jo(ItH{
IaCKe5p
;9]' r
nqn^9\~
l2t'3
ZS#u/em
^blt+
|NkUi+
FrG`n0
9p#b81
/F$$q}
\AF}o"
,]h+176
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
<?xml version='1.0' encoding='UTF-8' standalone='yes'?>
<assembly xmlns='urn:schemas-microsoft-com:asm.v1' manifestVersion='1.0'>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v3">
<security>
<requestedPrivileges>
<requestedExecutionLevel level='asInvoker' uiAccess='false' />
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
api-ms-win-appmodel-runtime-l1-1-1
api-ms-win-core-datetime-l1-1-1
api-ms-win-core-fibers-l1-1-1
api-ms-win-core-file-l2-1-1
api-ms-win-core-localization-l1-2-1
api-ms-win-core-localization-obsolete-l1-2-0
api-ms-win-core-processthreads-l1-1-2
api-ms-win-core-string-l1-1-0
api-ms-win-core-synch-l1-2-0
api-ms-win-core-sysinfo-l1-2-1
api-ms-win-core-winrt-l1-1-0
api-ms-win-core-xstate-l2-1-0
api-ms-win-rtcore-ntuser-window-l1-1-0
api-ms-win-security-systemfunctions-l1-1-0
ext-ms-win-kernel32-package-current-l1-1-0
ext-ms-win-ntuser-dialogbox-l1-1-0
ext-ms-win-ntuser-windowstation-l1-1-0
advapi32
kernel32
user32
Sunday
Monday
Tuesday
Wednesday
Thursday
Friday
Saturday
January
February
August
September
October
November
December
MM/dd/yy
dddd, MMMM dd, yyyy
HH:mm:ss
mscoree.dll
zh-CHS
az-AZ-Latn
uz-UZ-Latn
kok-IN
syr-SY
div-MV
quz-BO
sr-SP-Latn
az-AZ-Cyrl
uz-UZ-Cyrl
quz-EC
sr-SP-Cyrl
quz-PE
smj-NO
bs-BA-Latn
smj-SE
sr-BA-Latn
sma-NO
sr-BA-Cyrl
sma-SE
sms-FI
smn-FI
zh-CHT
az-az-cyrl
az-az-latn
bs-ba-latn
div-mv
kok-in
quz-bo
quz-ec
quz-pe
sma-no
sma-se
smj-no
smj-se
smn-fi
sms-fi
sr-ba-cyrl
sr-ba-latn
sr-sp-cyrl
sr-sp-latn
syr-sy
uz-uz-cyrl
uz-uz-latn
zh-chs
zh-cht
((((( H
Antivirus Signature
Bkav Clean
Lionic Trojan.Win32.CobaltStrike.4!c
tehtris Clean
MicroWorld-eScan Clean
FireEye Generic.mg.1cb5a9c2bc4adfe1
CAT-QuickHeal Clean
McAfee Artemis!1CB5A9C2BC4A
Cylance Clean
VIPRE Clean
Sangfor Clean
K7AntiVirus Clean
BitDefender Clean
K7GW Clean
CrowdStrike win/malicious_confidence_100% (W)
BitDefenderTheta Clean
VirIT Clean
Cyren Clean
Symantec ML.Attribute.HighConfidence
Elastic malicious (high confidence)
ESET-NOD32 Clean
Baidu Clean
APEX Malicious
Paloalto Clean
ClamAV Clean
Kaspersky UDS:Trojan.Win32.Cobalt.mxi
Alibaba Clean
NANO-Antivirus Clean
Cynet Malicious (score: 100)
ViRobot Clean
Avast Win64:TrojanX-gen [Trj]
Rising Trojan.CobaltStrike!8.EDF2 (CLOUD)
Ad-Aware Clean
Sophos Mal/Generic-S
Comodo Clean
F-Secure Clean
DrWeb Clean
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition BehavesLike.Win64.Generic.fh
Trapmine malicious.high.ml.score
CMC Clean
Emsisoft Clean
SentinelOne Clean
GData Clean
Jiangmin Clean
Webroot W32.Trojan.Gen
Avira Clean
MAX Clean
Antiy-AVL Clean
Kingsoft Win32.Troj.Undef.(kcloud)
Gridinsoft Clean
Arcabit Clean
SUPERAntiSpyware Clean
ZoneAlarm UDS:Trojan.Win32.Cobalt.mxi
Microsoft Trojan:Win32/Sabsik.FL.B!ml
Google Clean
AhnLab-V3 Clean
Acronis Clean
VBA32 Clean
ALYac Clean
TACHYON Clean
Zoner Clean
TrendMicro-HouseCall Clean
Tencent Clean
Yandex Clean
Ikarus Clean
MaxSecure Clean
Fortinet Clean
AVG Win64:TrojanX-gen [Trj]
Cybereason malicious.98da31
Panda Clean
No IRMA results available.