Static | ZeroBOX

PE Compile Time

2022-12-16 16:28:21

PE Imphash

57c9b357ae0cb2f414b0a5873e2f216d

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x003ff810 0x003ffa00 6.1899691303
.data 0x00401000 0x00041290 0x00041400 5.20444813497
.rdata 0x00443000 0x00312ec0 0x00313000 5.66378152242
.pdata 0x00756000 0x00005e20 0x00006000 5.9321855444
.xdata 0x0075c000 0x000065e0 0x00006600 4.52893189361
.bss 0x00763000 0x00060e28 0x00000000 0.0
.edata 0x007c4000 0x00000159 0x00000200 3.84484726061
.idata 0x007c5000 0x00001648 0x00001800 4.30221511458
.CRT 0x007c7000 0x00000068 0x00000200 0.280401167659
.tls 0x007c8000 0x00000010 0x00000200 0.0
.reloc 0x007c9000 0x0000d71c 0x0000d800 5.42902982398

Imports

Library KERNEL32.dll:
0xbc5504 AreFileApisANSI
0xbc550c CloseHandle
0xbc5514 CreateEventA
0xbc551c CreateFileA
0xbc5524 CreateFileMappingA
0xbc552c CreateFileMappingW
0xbc5534 CreateFileW
0xbc5544 CreateMutexW
0xbc554c CreateThread
0xbc556c DeleteFileA
0xbc5574 DeleteFileW
0xbc557c DuplicateHandle
0xbc558c ExitProcess
0xbc5594 FlushFileBuffers
0xbc559c FlushViewOfFile
0xbc55a4 FormatMessageA
0xbc55ac FormatMessageW
0xbc55bc FreeLibrary
0xbc55c4 GetConsoleMode
0xbc55cc GetCurrentProcess
0xbc55d4 GetCurrentProcessId
0xbc55dc GetCurrentThreadId
0xbc55e4 GetDiskFreeSpaceA
0xbc55ec GetDiskFreeSpaceW
0xbc55fc GetFileAttributesA
0xbc560c GetFileAttributesW
0xbc5614 GetFileSize
0xbc561c GetFullPathNameA
0xbc5624 GetFullPathNameW
0xbc562c GetLastError
0xbc5634 GetProcAddress
0xbc5644 GetProcessHeap
0xbc5654 GetStartupInfoA
0xbc565c GetStdHandle
0xbc5664 GetSystemDirectoryA
0xbc566c GetSystemInfo
0xbc5674 GetSystemTime
0xbc5684 GetTempPathA
0xbc568c GetTempPathW
0xbc5694 GetThreadContext
0xbc569c GetTickCount
0xbc56a4 GetVersionExA
0xbc56ac GetVersionExW
0xbc56b4 HeapAlloc
0xbc56bc HeapCompact
0xbc56c4 HeapCreate
0xbc56cc HeapDestroy
0xbc56d4 HeapFree
0xbc56dc HeapReAlloc
0xbc56e4 HeapSize
0xbc56ec HeapValidate
0xbc5704 LoadLibraryA
0xbc570c LoadLibraryW
0xbc5714 LocalFree
0xbc571c LockFile
0xbc5724 LockFileEx
0xbc572c MapViewOfFile
0xbc5734 MultiByteToWideChar
0xbc573c OutputDebugStringA
0xbc5744 OutputDebugStringW
0xbc575c ReadFile
0xbc5764 ResumeThread
0xbc576c RtlAddFunctionTable
0xbc5774 RtlCaptureContext
0xbc5784 RtlVirtualUnwind
0xbc5794 SetEndOfFile
0xbc579c SetErrorMode
0xbc57a4 SetEvent
0xbc57ac SetFilePointer
0xbc57bc SetThreadContext
0xbc57cc SetWaitableTimer
0xbc57d4 Sleep
0xbc57dc SuspendThread
0xbc57e4 SwitchToThread
0xbc57f4 TerminateProcess
0xbc57fc TlsGetValue
0xbc5814 UnlockFile
0xbc581c UnlockFileEx
0xbc5824 UnmapViewOfFile
0xbc582c VirtualAlloc
0xbc5834 VirtualFree
0xbc583c VirtualProtect
0xbc5844 VirtualQuery
0xbc5854 WaitForSingleObject
0xbc5864 WideCharToMultiByte
0xbc586c WriteConsoleW
0xbc5874 WriteFile
Library msvcrt.dll:
0xbc588c __getmainargs
0xbc5894 __initenv
0xbc589c __iob_func
0xbc58a4 __lconv_init
0xbc58ac __set_app_type
0xbc58b4 __setusermatherr
0xbc58bc _acmdln
0xbc58c4 _amsg_exit
0xbc58cc _beginthread
0xbc58d4 _beginthreadex
0xbc58dc _cexit
0xbc58e4 _endthreadex
0xbc58ec _errno
0xbc58f4 _fmode
0xbc58fc _initterm
0xbc5904 _localtime64
0xbc590c _onexit
0xbc5914 abort
0xbc591c calloc
0xbc5924 exit
0xbc592c fprintf
0xbc5934 free
0xbc593c fwrite
0xbc5944 malloc
0xbc594c memcmp
0xbc5954 memcpy
0xbc595c memmove
0xbc5964 memset
0xbc596c qsort
0xbc5974 realloc
0xbc597c signal
0xbc5984 strcmp
0xbc598c strcspn
0xbc5994 strlen
0xbc599c strncmp
0xbc59a4 strrchr
0xbc59ac vfprintf

Exports

Ordinal Address Name
1 0xbc3e10 _cgo_dummy_export
2 0x733a60 authorizerTrampoline
3 0x733780 callbackTrampoline
4 0x733940 commitHookTrampoline
5 0x7338a0 compareTrampoline
6 0x733850 doneTrampoline
7 0x733ae0 preUpdateHookTrampoline
8 0x7339a0 rollbackHookTrampoline
9 0x7337e0 stepTrampoline
10 0x7339f0 updateHookTrampoline
!This program cannot be run in DOS mode.
``.data
.rdata
`@.pdata
0@.xdata
0@.bss
.edata
0@.idata
.reloc
AUATUWVSH
[^_]A\A]
[^_]A\A]
8cpu.u
UUUUUUUUH!
33333333H!
D$pH9P@w
t*H9HPt$
debugCal
debugCal
debugCalH9
debugCalH9
l204uQ
debugCalH9
runtime.H9
runtime H
error: H
L9h(t
7H9S u
29t$0u
D9\$Pt
7H9S u
H9t$0u
2H9t$0u
L9\$Pt
L9\$Pt
7H9S u
L$xM9H
8H9S u
H9BpwI@
H9P8tkH
\$(H9C8u
H9D$(t
D$xH9X0
tE8Z t/H
L9@0wE
\$0H9K
D$pH9H
D$0H9H
UUUUUUUUH!
UUUUUUUUH
wwwwwwwwH!
wwwwwwwwH
D$$t H
J0H9J8vvL
H9{8u?H
;Hc5'|x
kernel32H
l32.dll
AddDllDiH
rectory
AddVectoH
redContiH
ContinueH
Handler
LoadLibrH
raryExA
LoadLibrH
raryExW
advapi32H
i32.dll
SystemFuH
stemFuncH
tion036
ntdll.dlH
NtWaitFoH
ForSinglH
eObject
RtlGetCuH
tlGetCurH
rentPeb
RtlGetNtH
tVersionH
Numbers
winmm.dlH
timeBegiH
nPeriod
timeEndPH
dPeriod
ws2_32.dH
_32.dll
WSAGetOvH
verlappeH
dResult
wine_getH
ine_get_H
version
powrprofH
rof.dll
PowerRegH
gisterSuH
spendResH
umeNotifH
ication
GetSysteH
mTimeAsFH
ileTime
QueryPerH
formanceH
Counter
QueryPerH
formanceH
rmanceFrH
equency
runtime.
QxM9Qpu
T$@H9P
runtime.H9
reflect.H9
D$#e+H
I9N0t_H
D$PD9D$T
H9QPt#H
rpH92w
I9N0tSH
\$xHc5K
t$pHc=
\$PH9p
memprofiH93u7
lerau.f
memprofiH
memprofiH
memprofiH
t H9APt
7H9A8u1
r09q0s-f
,$L9+w
|$0H98
R8L+R(M
L$Hr.I
H9D$@A
HcD$4f
H9D$@A
\$HH9S@
H9D$8A
runtime.H
gopau$f
runtime.H
|$PH97u*
gopau!f
runtime.H9
gopau&f
runtime.H
runtime.H
G0I9F0t9
runtime.H9
H9S@u{H
8noneuZ1
8crasuF
8singu
8systu
l$0M9,$u
l$PM9,$u
X0H;CPt^H
l$ M9,$u
l$0M9,$u
l$PM9,$u
H+t$(H
0Hc\$8H
HHc\$PeH
l$ M9,$u
P'8S't
x H9{ u6H
x(H9{(uWH
P H9S u
l$(M9,$u
l$ M9,$u
l$8M9,$u
H08K0u
H9L$0uQH
H9L$@uuH
L$PH9T$Hu
@2fD9C2u
@0fD9C0u
P@H9S@t
P@H9S@u}H
l$ M9,$u
H9K0uZH
H9|$@u
H9|$0u
L9D$Xu
H9|$Hu
L9L$`u
H9|$Pu
H9t$8u
H98uCH
T$0H9J0
\$0H9S
\$0H9S
T$0H)B
l$ M9,$u
l$ M9,$u
T$0H9J
l$0M9,$u
l$0M9,$u
l$0M9,$
l$0M9,$u
l$0M9,$u
J(H9B t
H8H9X@
P2f9S2u
S@H9P@
\$pH9Q@
reflect.
Valuu2f
reflect.
CallSlicL9'u
p8H9x@vYH
uKH9x@
P8H9H@
l$0M9,$u
l$8M9,$
l$(M9,$u
l$@M9,$u
l$@M9,$u
l$8M9,$u
l$ M9,$u
l$(M9,$u
l$(M9,$
l$8M9,$u
l$0M9,$u
l$@M9,$u
l$@M9,$u
l$8M9,$u
l$0M9,$u
l$(M9,$
l$0M9,$u
l$(M9,$
l$0M9,$u
l$HM9,$u
l$(M9,$u
l$@M9,$u
l$8M9,$
l$0M9,$u
l$8M9,$u
l$(M9,$
l$(M9,$
l$(M9,$
l$@M9,$u
l$@M9,$u
l$0M9,$u
l$@M9,$u
l$0M9,$u
l$8M9,$u
l$0M9,$u
l$0M9,$u
l$0M9,$u
l$0M9,$u
l$0M9,$u
l$XM9,$
l$0M9,$u
l$8M9,$u
l$0M9,$u
l$@M9,$u
l$@M9,$u
l$(M9,$u
l$(M9,$
PPH9SPu
PXH9SXu
N(H9F uI
T$0H9JH
l$`M9,$u
\$0H9S u
H3T8 L3L8(I
|$8riH)
H1T$0H
H1T$HH
H1T$PH
l$ M9,$u
l$ M9,$u
o\$ fE
o\$0fE
o\$@fE
o\$PfE
o\$`fE
o\$pfE
l$8M9,$u
l$8M9,$u
HHH9P@u H
$D3T$4D3T$ D3T$
D3T$8D3T$$D3T$
D3T$<D3T$(D3T$
$D3T$,D3T$
D3T$0D3T$
D3T$4D3T$
D3T$8D3T$ A
D3T$<D3T$$A
T$ D3T$
$D3T$(A
T$$D3T$
D3T$,A
T$(D3T$
D3T$0A
T$,D3T$ D3T$
D3T$4A
T$0D3T$$D3T$
D3T$8A
T$4D3T$(D3T$
D3T$<A
T$8D3T$,D3T$
T$<D3T$0D3T$
$D3T$4D3T$ D3T$
D3T$8D3T$$D3T$
D3T$<D3T$(D3T$
$D3T$,D3T$
D3T$0D3T$
D3T$4D3T$
D3T$8D3T$ A
D3T$<D3T$$A
T$ D3T$
$D3T$(A
T$$D3T$
D3T$,A
T$(D3T$
D3T$0A
T$,D3T$ D3T$
D3T$4A
T$0D3T$$D3T$
D3T$8A
T$4D3T$(D3T$
D3T$<A
T$8D3T$,D3T$
T$<D3T$0D3T$
$D3T$4D3T$ D3T$
D3T$8D3T$$D3T$
D3T$<D3T$(D3T$
$D3T$,D3T$
D3T$0D3T$
D3T$4D3T$
D3T$8D3T$ A
D3T$<D3T$$A
T$ D3T$
$D3T$(A
T$$D3T$
D3T$,A
T$(D3T$
D3T$0A
T$,D3T$ D3T$
D3T$4A
T$0D3T$$D3T$
D3T$8A
T$4D3T$(D3T$
D3T$<A
T$8D3T$,D3T$
T$<D3T$0D3T$
$D3T$4D3T$ D3T$
D3T$8D3T$$D3T$
D3T$<D3T$(D3T$
$D3T$,D3T$
D3T$0D3T$
D3T$4D3T$
D3T$8D3T$ A
D3T$<D3T$$A
T$ D3T$
$D3T$(A
T$$D3T$
D3T$,A
T$(D3T$
D3T$0A
T$,D3T$ D3T$
D3T$4A
T$0D3T$$D3T$
D3T$8A
T$4D3T$(D3T$
D3T$<A
T$8D3T$,D3T$
T$<D3T$0D3T$
\$0H9SXu
I`H9K`
D$`tMD
D$`tVD
l$(M9,$u
l$(M9,$u
l$0M9,$
l$8M9,$u
l$(M9,$u
l$ M9,$
l$(M9,$u
l$(M9,$u
~(H9z(u&
x H9{ u
-070u!D
-07:00:0M9
-07:00:0L
-07:00:0
Januu!D
-07:00:0
-07:00:0
-07:00:0
Z070u"D
Z07:00:0M9
Z07:00:0L
-07:00:0
-07:00:0
-07:00:0
-07:00:0
2006u-H)
-07:00:0
time.DatH
time.LocL
time.LocH
ocation(H
time.UTCL
8WITAuP
;nullu
8Locau
tzdau;
x8H9{8
l$HM9,$u
l$`M9,$
l$0M9,$u
l$@M9,$u
l$@M9,$u
l$PM9,$
l$@M9,$u
l$0M9,$u
l$0M9,$u
l$@M9,$u
l$8M9,$u
l$(M9,$
l$8M9,$
l$(M9,$
l$(M9,$
l$0M9,$u
l$0M9,$u
l$@M9,$u
l$0M9,$u
l$(M9,$u
l$(M9,$
l$0M9,$u
l$0M9,$u
J(H9B t
H 9K u
H 9K u
H(H9K(u
t$8HcX(
t$XHc^(H
?fileu*H
?pipeu*H
?tcp6u H
?udp4uxH
?udp6u H
?unixu H
unixgramL9#t.
unixpackL9#
;udp4t
;udp6uh
l$(M9,$u
l$(M9,$u
}zy u]H
8..u[H
D$HtYH
?fileuuH
xPH9{Pu|H
l$0M9,$u
l$0M9,$u
method:L
l$@M9,$u
l$@M9,$u
l$@M9,$u
l$@M9,$u
(BADINDEH
(MISSINGH
%!(BADWIL
%!(BADPRL
BADPREC)L
%!(EXTRAL
%!(NOVERL
P(H9P@
|$$f9D$$
f9D$&r
d$ f9D$ w
f9D$"r
H9t$@|4
l*PL9jHt+L
l$@M9,$u
;nullu
<Ot/<XtN
l$0M9,$u
l$0M9,$u
l$(M9,$u
optionalH9
explicit
explicitf
optionalH
explicitH
explicit
optionalH
explicitH
generaliL9
generaliH
printabl
printablH
8numeu
8utf8u
default:L9
default:E1
8tag:A
applicat
optionalH
explicitH
generaliI
printablI
default:I
applicat
applicat
optionalH
explicitH
generaliI
printablI
default:I
applicat
omitempt
omitempt
optionalH
explicitH
optionalH
explicitH
H95yZc
H9=IFc
l$0M9,$u
l$8M9,$u
l$8M9,$u
l$8M9,$
l$@M9,$u
l$8M9,$
l$@M9,$u
l$8M9,$
l$8M9,$
l$@M9,$u
l$8M9,$
l$ M9,$u
l$0M9,$u
\$(t8vYF
l$ M9,$u
l$ M9,$
|$0H9w
D$(f9P(u'
P*8S*u
P0H9S0u
l$8M9,$u
l$HM9,$u
|$HH9w@}
;falsu
~ r(H)
~"r9H)
|$0H9w uFH
B(H9O0u4H
H9r@u&
l$HM9,$
Z H9J(u
l$0M9,$u
B0H9N8u
T$0H9J
8FALSu
8Falsu
8falsuY
<$true
<$falsf
>!=u2H
<$falst
>!=tRf
><=t+f
:!%tLf
:<=t@f
<$true
<$falsu
>!=u*H
<$true
0\ufff
8nullt
8truet
8falsu)
8indeuif
sortKeysH9
8widtug
8deepuVH
3nullH
preserveH9
H9T$ t
L9D$(t
Z(H9F t
l:T^8rv
~d$ fE
L+%]6>
ot$PfA
l$@M9,$u
l$0M9,$u
l$0M9,$u
l$ M9,$u
l$8M9,$u
l$8M9,$u
l$8M9,$u
P8H9S8u
l$(M9,$u
l$@M9,$u
l$0M9,$u
l$0M9,$u
l$ M9,$u
l$8M9,$u
l$8M9,$u
l$8M9,$u
l$@M9,$u
l$0M9,$u
l$0M9,$u
l$ M9,$u
l$8M9,$u
l$8M9,$u
l$8M9,$u
l$@M9,$u
l$0M9,$u
l$0M9,$u
l$ M9,$u
l$8M9,$u
l$8M9,$u
l$8M9,$u
L$H8L$'u
L$H8L$'u
H9P }GH
L9B }ZH
L9B }[H
\$0H9S
l$8M9,$u
l$0M9,$u
l$@M9,$u
l$(M9,$u
l$(M9,$u
l$0M9,$
l$@M9,$
\$0H9S
I H9K
S H+Q H
XfffffffH
ffffffffH
T$0H9J
l$8M9,$u
L)@pL)
2-byD1
$2-byD
nd 3E3K
2-byE3K
te kA3K
>E3C4D
expaD3P A
expaD1
expaD3
expand 3H
2-byte kH
H#T$hH
H#T$pH
H#T$`H
H#T$hH
L$@H9G
L$8H9G
T$0H9J(
H9P0u$H
H9P0u$H
H9P0u$H
H9P0u"H
8leaku
T$08J
[::ffff:N
invalid J
d PrefixJ
l$pM9,$u
x(H9{(uUH
l$@M9,$u
l$HM9,$u
l$8M9,$u
l$@M9,$u
l$(M9,$u
l$@M9,$u
l$0M9,$u
l$0M9,$u
l$8M9,$u
l$0M9,$u
l$0M9,$u
l$0M9,$u
l$0M9,$u
l$0M9,$u
l$0M9,$u
l$8M9,$u
T$08J
9windu
:planu%
:andru-f
8fileu#H
8bindu#H
9solau6f
;fileu,
myhostnaM9"uRfA
myhostnaI
:fileu
:dnuYA
:mdnsu
:fileu
myhostnaM
<$succu fA
<$unav
notfoundI9
tryagainI94$
?retuu
myhostna
myhostna
unixgramH9
unixpackH9
8tcp4t
8tcp6uOH
8udp4t
8udp6u
8unixu
:dialu2L
unixgram
unixpackL9
8unixtD
unixgramH9
unixpackH9
<$tcu+A
l$(M9,$u
l$(M9,$u
L9-w%Y
L9-4#Y
>tcp4t
}zy u&H
l$0M9,$u
}zy ueH
}zy upH
8udp4f
?tcp4f
9listu8fA
<$dial
>tcp4t
>tcp6u\
>udp4t
>udp6u
:tcp4u
:tcp6uaH
:udp4u
:udp6u=H
D$ht)H
:tcp4t
:tcp6uO
:udp4t
:udp6u
:acceuNf
~NrsH)
<$unix
unixgramM9<$
unixpackM9<$u
unixgramL9
unixpack
unixgramL9
unixpack
\$(tdH
}zy ujH
8udp4t
}zy ujH
unixgramH9
unixpackH9
listubfA
l$@M9,$u
l$@M9,$u
l$ M9,$
l$ M9,$
l$8M9,$u
N(H9F u_
N8H9F0u:
l$(M9,$u
H9{(uuH
l$HM9,$
l$0M9,$u
l$0M9,$u
l$HM9,$u
l$HM9,$u
l$0M9,$u
l$0M9,$u
l$0M9,$u
l$0M9,$u
l$0M9,$u
l$0M9,$u
x H9{ u6H
<$tI<&tE
r8H9Z@t
rpH9Zxt
8//uOH
J(H9B t
x @8{ u6H
{0H9x0
{PH9xP
xY@8{Y
{xH9xx
l$0M9,$
l$@M9,$
QZ^&A!
CERTIFICH92u#f
8S(udH
T$0H9P
HHH9pPuDH
WHL9GPt
X H9H(u
D$@H9D$
H9\$hu
l$8M9,$
D$@H9D$
l$`M9,$
l$ M9,$u
l$0M9,$u
T$0H9J
l$HM9,$u
S H+Q H
P H1s
fE9,$u
DOWNGRD
DOWNGRD
<LfD9x
\$hu\H
H9P }TH
H9P }SH
H9W }VH
H9W }JH
H9T$p}>H
L9@ }\H
L9H }^H
L9H }ZH
L9H }[H
L9H }[H
L9H }[H
L9H }[H
L9H }[H
L9H }^H
L9H }[H
L9H }cH
L9H }cH
L9H }^H
L9H }[H
L9H }[H
L9H }cH
L9H }cH
L9H }[H
L9H }[H
H9P }MH
H9P }MH
H9P }VH
L9H }YH
H9P }MH
H9P }VH
L9H }eH
L9B }PH
H9P }VH
L9H }eH
L9H }eH
H9P }VH
H9P }VH
L9H }eH
L9@ }XH
L9B }PH
H9P }MH
L9H }eH
H9P }MH
H9P }MH
H9T$p}>H
L9@ }\H
L9F }OH
L9F }OH
L9H }cH
L9H }cH
L9H }`H
L9H }`H
L9H }[H
L9H }\H
L9H }[H
L9H }[H
L9H }^H
L9H }[H
L9H }[H
L9H }^H
L9H }[H
H9P }VH
H9P }JH
H9P }VH
H9P }JH
L9@ }[H
H9P }VH
H9P }JH
H9P }MH
L9B }PH
H9P }MH
H9P }MH
H9T$p}>H
L9@ }XH
L9B }PH
H9T$p}>H
H9P }MH
H9P }IH
H9T$p}>H
L9@ }XH
L9@ }\H
L9@ }_H
L9@ }^H
L9@ }\H
L9@ }\H
L9@ }[H
L9@ }[H
H9P }MH
L9H }eH
L9H }eH
H9T$p}>H
H9P }fH
L9@ }[H
L9@ }\H
H9P }MH
L9@ }`H
H9P }MH
H9P }MH
H9T$p}>H
L9@ }XH
H9P }MH
H9T$p}>H
H9P }MH
L$Pw)L
H9T$p}>H
L9@ }\H
H9P }MH
H9P }MH
D$*tls1f
D$.3 H
H9P }`H
L9B }QH
key expaH9
master sH9
client fH9
server fH9
inisuqf
l$ M9,$
l$`M9,$u
T$0H9J
l$(M9,$u
P0H+P(H
P0H+P(H
W0H+W(H
P0H+P(H
p(H9p0
\$@H9H
P(H9P0u?H
H0H+H(H
W0H+W(H9W
W(H9W0~)H
H0L+H(I
X0H+X(H
l$8M9,$u
l$(M9,$u
us-asciiH9
8utf-u
text/plaH
text/plaH
text/plaH
text/plaH
text/plaH
text/plaH
form-dat
form-datH92u
form-datH
form-datH
form-datH
form-datH92u
^0H+^(H
T$P|XH
:--u*H
H9=C8Q
l$0M9,$u
l$8M9,$u
l$0M9,$u
D$hH9N
H9N sMH
D$`I9@ sML
l$8M9,$u
l$ M9,$u
l$ M9,$u
l$ M9,$u
l$8M9,$u
L$7D8L$j
l$HM9,$u
l$HM9,$u
XD9X4v
P09P4s
H9pxu*H
L9L$X~
l$(M9,$u
l$HM9,$u
l$HM9,$u
x @8{ u6H
l$8M9,$u
l$8M9,$u
X0H+X(
Q0M+Q(f
l$ M9,$u
l$(M9,$u
l$8M9,$
l$0M9,$u
l$ M9,$u
l$ M9,$u
:httpu
:httpuCH
:httpu
:socku
localhosH9
l$ M9,$u
x @8{ u6H
x(H9{(u_
x0@8{0uUH
9httpu&
9httpu
HTTPu3
*http2.TH9
ransport
Z(H9J0t
9HEADt
8Cookf
AuthorizH9
Www-Auth
enticateH9H
8domauTf
httponlyL9
samesiteL9
8noneu:H
8striu
; DomainL
; ExpireL
; Max-AgL
; Max-AgL
ax-Age=0L
; HttpOnL
; SecureL
; SameSiH
Site=LaxH
; SameSiH
ite=NoneH
l$8M9,$u
l$8M9,$u
H)H(H)
Z(H)Z0L
8:metu
8:schu
8:stausfA
:authoriI98uFfA
d$PL9T$XuDL
l$ M9,$u
:httpu
>httpu
>httpu2
T$0H9B@
8Traiulf
Content-H9
Lengu;f
>chunu
8HEADA
l$ M9,$u
l$(M9,$u
l$(M9,$u
>CONNf
8CONNu
8POSTt!
8PATCuRA
8readA
uuUL9
L$,D9I
multiparH9
>CONNu5f
HTTP/1.0H9
HTTP/1.1H9
>POSTt(I
>PATCuJ
no-cacheH9
:chunu
>chunu
l$0M9,$u
8tcp4t
>HEAD@
>chunf
>chunu
>chunu
9CONNu
9HEADtd
9DELEu
9SEARu^f
9OPTIuFf
PROPFINDH9
l$ M9,$u
;chunu
;POSTt-
identityH9
;HEADu
8Traiukf
Content-H9
Lengu6f
:CONNf
:HEADuhH
>HEADt'H
t$ht#H
Content-
H9D$@t
>httpu*
H9D$ t
9httpu
9httpu
8GEu`A
8HEADtAf
8TRACu5A
8OPTIu
H9D$pt
l$ M9,$u
l$ M9,$u
T$XH+T$hH
t$XH+t$hH
l$ M9,$u
9httpf
>httpt
>httpu
:httpu
H9Jxu=D
D$pI9PxtVD
>HEADt
B0L+B(M
8HTTPu
F0L+F(L9
r0H9r(u
H9VxuPD
l$8M9,$u
l$(M9,$u
l$(M9,$u
l$8M9,$u
l$(M9,$u
l$(M9,$u
x(H9{(u_
x0@8{0uUH
l$ M9,$
l$(M9,$
l$(M9,$
l$(M9,$
l$(M9,$
l$ M9,$
l$(M9,$
l$(M9,$
l$(M9,$
l$(M9,$
l$(M9,$u
l$0M9,$u
l$PM9,$
l$(M9,$u
l$0M9,$u
l$ M9,$u
l$(M9,$u
l$0M9,$u
l$ M9,$u
l$ M9,$
l$8M9,$u
l$(M9,$u
l$0M9,$u
l$ M9,$u
l$(M9,$u
l$(M9,$u
l$0M9,$u
l$(M9,$u
l$hM9,$
l$HM9,$u
l$(M9,$u
l$0M9,$u
l$ M9,$u
l$ M9,$
l$(M9,$u
l$0M9,$u
T$(H9J
l$ M9,$u
l$(M9,$u
l$0M9,$u
l$ M9,$u
l$ M9,$
l$(M9,$u
l$0M9,$u
l$ M9,$u
l$(M9,$u
l$8M9,$u
l$0M9,$u
l$ M9,$u
l$8M9,$
l$ M9,$
l$(M9,$u
l$0M9,$u
l$ M9,$u
l$(M9,$u
l$0M9,$u
l$ M9,$u
l$ M9,$
l$(M9,$u
l$0M9,$u
l$ M9,$u
l$HM9,$u
l$HM9,$u
l$HM9,$u
l$HM9,$u
l$ M9,$u
l$HM9,$u
\$0H9S
l$0M9,$u
l$@M9,$u
H9w u+H
r(H9w(u!H
l$0M9,$u
l$0M9,$
l$8M9,$u
l$HM9,$u
l$@M9,$u
l$(M9,$u
l$8M9,$u
l$0M9,$u
l$(M9,$u
l$HM9,$
l$0M9,$u
l$0M9,$
l$(M9,$u
T$`A82
aHM9aPuUM
P(L9H8
s(H9K0u
PXH9SXt
s`H9Kht
H9SHu7H
PPH9SPu-H
l$ M9,$
l$ M9,$
MHI9UP~
E9L$0vPM
E9L$0vSL
E9i0v3L
E9i0v5L
E9i0v3L
E9i0v3L
D$pt?H
l$ M9,$u
l$ M9,$u
H9Hh~LH
T$hH9T$p@
H9Ph~`L
tJH9X0uDH
8Jpu$H
8ascif
l$XM9,$u
l$0M9,$u
l$0M9,$u
l$XM9,$u
l$0M9,$
l$ M9,$u
l$ M9,$u
l$ M9,$u
l$(M9,$u
l$8M9,$u
l$0M9,$u
l$8M9,$u
l$8M9,$u
l$0M9,$u
l$0M9,$u
l$0M9,$u
l$0M9,$u
l$8M9,$u
l$8M9,$u
l$0M9,$u
l$(M9,$u
l$(M9,$u
l$0M9,$u
l$0M9,$u
l$xM9,$u
l$xM9,$u
l$xM9,$u
l$HM9,$u
l$8M9,$u
l$HM9,$u
l$8M9,$u
l$8M9,$u
l$0M9,$u
l$0M9,$u
l$@M9,$
8FALSu
8Falsu
8falsf
8FALSu
8Falsf
8falsu\
urn:uuidH9
l$HM9,$u
l$8M9,$u
l$(M9,$u
l$ M9,$u
l$ M9,$u
L9L$@t
l$8M9,$u
l$ M9,$u
l$0M9,$u
@8w u!H
O0H9G(t
x0H9{0
T$0H9J
l$(M9,$u
l$(M9,$u
l$0M9,$u
l$0M9,$u
l$(M9,$u
l$(M9,$u
l$@M9,$
T$0H9J
P0L9@8u:H
8httpt@H
:httpu
>httpu
:httpt&f
:httpu
x8H9{8
8autou
deferredH9
exclusivH9
immediatf
8fullu
incremenH9
8notzf
8notuf
8notuf
8DELEu
TRUNCATEH9
EXCLUSIVH9
8notuf
8fastu
8notwf
8SHA1f
8SSHAf
8DEFAu
L$ H9O
8datetQ
datetimeI9
timestam
9datetO
datetimeM9
timestamM9
8CLOBt1H
8TEXTt#
8BLOBt
8REALtA
8FLOAu
8DATEt9
DATETIMEH9
TIMESTAMH9
8NUMEu
9BOOLu
l$`M9,$u
l$`M9,$u
l$`M9,$u
P H9S u
l$0M9,$u
x(H9{(uLH
x0H9{0uBH
H9{8u6H
P H9S uI
P(8S(u@
P)8S)u7H
l$8M9,$u
l$@M9,$u
l$@M9,$u
<$SAPIu(fA
<$PAPIu
l$ M9,$u
l$ M9,$u
l$ M9,$u
ATWVSH
H[^_A\
ATWVSH
H[^_A\
ATUWVSH
P[^_]A\
ATUWVSH
P[^_]A\
ATUWVSH
P[^_]A\
ATUWVSH
`[^_]A\
AUATUWVSH
([^_]A\A]
AVAUATUWVSA
[^_]A\A]A^
[^_]A\A]A^
[^_]A\A]A^
<+t)<0
ATWVSH
([^_A\
AVAUATH
A\A]A^
A\A]A^
A\A]A^
A4 tJH
B(@u0I
AVAUATUWVSH
@[^_]A\A]A^
A(<Mtu<
=rahcu
=aolfu
=buodu
AUATUWVS
[^_]A\A]
AUATSH
[A\A]
AVAUATUWVSH
[^_]A\A]A^
G@@uIA
ATUWVSH
[^_]A\
[^_]A\
tJfA9H
r0fE9J:}
([^_]H
ATWVSH
([^_A\
([^_A\
ATWVSH
([^_A\
([^_A\
ATWVSH
([^_A\
([^_A\
ATWVSH
([^_A\
([^_A\
AWAVAUATUWVSH
X[^_]A\A]A^A_
HcD$@L
AUATVSH
8[^A\A]
AWAVAUATUWVSH
;|$,}DD
8[^_]A\A]A^A_
ATUWVSH
[^_]A\
aceinouH
hijklnor
yyacdeegH
stuuwyzoH
eiorusthH
yzhtwya
ujHcL$
ATUWVSH
0[^_]A\
AUATUWVSH
8[^_]A\A]
AWAVAUATUWVSH
8[^_]A\A]A^A_
ATWVSH
([^_A\
AUATUWVSH
([^_]A\A]
AWAVAUATUWVSL
>[^_]A\A]A^A_
ATUWVSH
[^_]A\
AWAVAUATUWVSH
H[^_]A\A]A^A_
t!;L$<tCf
AVAUATUWVSH
[^_]A\A]A^
AUATUWVSH
([^_]A\A]
ATUWVSH
[^_]A\
AWAVAUATUWVSH
8[^_]A\A]A^A_
AVAUATUWVSH
0[^_]A\A]A^
H9L$ u
AHLcFHH
AWAVAUATUWVSH
([^_]A\A]A^A_
AWAVAUATUWVSH
H[^_]A\A]A^A_
ATWVSH
8[^_A\H
8[^_A\
ATUWVSH
x4A94$t
[^_]A\
ATWVSH
([^_A\
AUATSH
[A\A]
[A\A]
ATUWVSH
[^_]A\
AVAUATH
A\A]A^
C H9F u
AVAUATUWVSH
[^_]A\A]A^
[^_]A\A]A^
AWAVAUATUWVSH
([^_]A\A]A^A_
AVAUATUWVSH
[^_]A\A]A^
[^_]A\A]A^
AWAVAUATUWVSH
gfffffffI
[^_]A\A]A^A_
ATUWVSH
[^_]A\
A+D$$A
D$ H3T$XH3D$P
D$0H3T$hH3D$`H
R(H3D$pH3T$xH
H(I3R I3J(H
ATUWVSH
[^_]A\
[^_]A\
[^A\H
9^(~*H
9^(~.H
B4+B8A
AUATSH
[A\A]
AUATSH
[A\A]
AUATSH
[A\A]
AUATVSH
([^A\A]
ATUWVSH
[^_]A\
ATUWVSH
[^_]A\
AVAUATUWVSH
[^_]A\A]A^
AUATSH
[A\A]
[A\A]
$<3tg<,u I
ATUWVSH
[^_]A\
s<&w"H
AWAVAUATUWVSH
H[^_]A\A]A^A_
ATUWVSH
[^_]A\
<9wk<*v_
C,9A(u
AUATUWVSH
([^_]A\A]
AVAUATUWVSH
[^_]A\A]A^
ATUWVSH
[^_]A\
AUATUWVSLcd$`L
[^_]A\A]
[^_]A\A]
AUATSH
[A\A]
AWAVAUATUWVSH
([^_]A\A]A^A_
AVAUATUWVSH
[^_]A\A]A^
[^_]A\A]A^
J,9HDt
A0`tCL
I(HcB4;
A(HcB,A;
AUATWVSH
P[^_A\A]
AUATUWVSH
[^_]A\A]
AVAUATH
A\A]A^
A\A]A^
AUATWVSH
[^_A\A]
AUATVSH
([^A\A]
([^A\A]
AWAVAUATUWVSH
t6A;l$ }/
([^_]A\A]A^A_
ATWVSH
([^_A\
([^_A\
AUATSH
[A\A]
AVAUATUWVSH
[^_]A\A]A^
AVAUATUWVSL
[^_]A\A]A^
AUATUWVSH
8[^_]A\A]
AWAVAUATUWVSD
[^_]A\A]A^A_
[^_]A\A]A^A_
AVAUATUWVSH
`[^_]A\A]A^
T$0H9D$Ht>},H
`[^_]A\A]A^
AVAUATUWVSH
D$@H9D$HtWH
L$8H9D$PtYL
`[^_]A\A]A^
H9T$Pt
ATUWVSH
tgHcD$pH
[^_]A\
x0H9{(uH
QTA;R0}9;T$,t3
Ic@,IcP(f
Ic@$IcP f
ATWVSH
AUATUWVSH
X[^_]A\A]
X[^_]A\A]
ATWVSH
([^_A\
([^_A\H
([^_A\
AUATUWVSH
([^_]A\A]
([^_]A\A]
AVAUATUWVSH
0[^_]A\A]A^
AUATVSH
8[^A\A]
8[^A\A]
AVAUATSH
H[A\A]A^
H[A\A]A^
AUATWVSH
@[^_A\A]
@[^_A\A]
@[^_A\A]
ATWVSH
8[^_A\
8[^_A\
AVAUATVSH
[^A\A]A^
[^A\A]A^H
[^A\A]A^
[^A\A]A^
AUATUWVSH
([^_]A\A]
([^_]A\A]
ATUWVSH
0[^_]A\
t~HcC(A
KX+L$0L
ATUWVSH
[^_]A\
[^_]A\
AVAUATSH
([A\A]A^
AUATVSH
([^A\A]
([^A\A]
ATUWVSH
[^_]A\
AUATVSH
([^A\A]
ATWVSH
([^_A\
([^_A\
ATWVSH
([^_A\
AVAUATSH
([A\A]A^
AUATVSH
([^A\A]
AUATSH
[A\A]
[A\A]
9^(~#H
ATUWVSH
[^_]A\
[^_]A\
[8D9a0v
[_A\H
AUATWVSH
u%L9l$(
0[^_A\A]
YA DiA
AVAUATSH
([A\A]A^
AWAVAUATUWVSH
H[^_]A\A]A^A_
ATUWVSH
[^_]A\
[^_]A\
AWAVAUATUWVSH
D$8fD;~
H[^_]A\A]A^A_
ATUWVSH
A9\$(~9I
A9\$(
[^_]A\
[^_]A\
A9\$(~.H
AUATSH
[A\A]
AUATUWVSH
S@9s8A
8[^_]A\A]
8[^_]A\A]
ATWVSH
H[^_A\
H[^_A\
AWAVAUATUWVSH
8[^_]A\A]A^A_
ATUWVSH
0[^_]A\
0[^_]A\
ATUWVSH
[^_]A\
[^_]A\
[^_]A\
ATUWVSH
[^_]A\
[^_]A\H
[^_]A\
AWAVAUATUWVSH
8[^_]A\A]A^A_
ATWVSH
([^_A\
([^_A\
ATWVSH
([^_A\
*D$4tr
AUATWVSH
0[^_A\A]
0[^_A\A]
AVAUATSH
X[A\A]A^
ATWVSH
([^_A\
([^_A\
ATUWVSH
0[^_]A\
HcT$,Hc
ATUWVSH
ZLD9Z4u_H
[^_]A\
[^_]A\
AUATWVSH
[^_A\A]
[^_A\A]
ATWVSH
8[^_A\
8[^_A\
AWAVAUATUWVSH
([^_]A\A]A^A_
AUATUWVSH
([^_]A\A]
([^_]A\A]
AUATUWVSH
8[^_]A\A]
AUATUWVSH
([^_]A\A]
AWAVAUATWVSH
@[^_A\A]A^A_
AUATUWVSH
H[^_]A\A]
ATUWVSH
C4D+C8@
0[^_]A\
0[^_]A\
0[^_]A\
AVAUATWVSH
([^_A\A]A^
ATWVSH
8[^_A\
8[^_A\
ATUWVSH
[^_]A\
[^_]A\
[^_]A\
AVAUATUWVSH
L$PHcD$H
`[^_]A\A]A^
L$PHcD$H
AUATVSH
C(H9C0trE
8[^A\A]
8[^A\A]
8[^A\A]
AWAVAUATUWVSH
H[^_]A\A]A^A_
AWAVAUATUWVSH
H[^_]A\A]A^A_
AWAVAUATWVSH
[^_A\A]A^A_
[^_A\A]A^A_
AVAUATUWVSH
@[^_]A\A]A^
@[^_]A\A]A^
ATUWVSH
@[^_]A\
@[^_]A\
AVATUWVSH
h[^_]A\A^
AWAVAUATUWVSH
LwXIcT
[^_]A\A]A^A_
33333333H
|$8HcG
LcL$dD
AUATSH
0[A\A]
0[A\A]
ATUWVSH
[^_]A\
AVAUATSH
H[A\A]A^
ATUWVSH
[^_]A\
AWAVAUATVSH
8[^A\A]A^A_
AUATUWVSH
([^_]A\A]
([^_]A\A]H
AUATSH
[A\A]
[A\A]
AUATUWVSH
@ Lc(E
([^_]A\A]
G Lc(E
ATWVSH
8[^_A\
8[^_A\
AUATVSH
([^A\A]
([^A\A]
AWAVAUATWVSH
[^_A\A]A^A_
ATUWVSH
[^_]A\
[^_]A\
AUATUWVSH
([^_]A\A]
([^_]A\A]
AWAVAUATUWVSH
H[^_]A\A]A^A_
H;T$0tCH
AUATUWVSH
([^_]A\A]
([^_]A\A]
AWAVAUATUWVSH
h[^_]A\A]A^A_
AWAVAUATUWVSH
H[^_]A\A]A^A_
AWAVAUATUWVSH
([^_]A\A]A^A_
AUATVSH
([^A\A]
([^A\A]
S,D9Q,uVD
[0fD9Y0uJE
AVAUATWVSH
8[^_A\A]A^
8[^_A\A]A^
AWAVAUATUWVSH
x[^_]A\A]A^A_
AVAUATUWVSH
[^_]A\A]A^
ATWVSH
([^_A\
([^_A\
AVAUATWVSH
([^_A\A]A^
C<f9F@s
ATUWVSH
[^_]A\
AUATSH
0[A\A]
0[A\A]
ATUWVSH
0[^_]A\
0[^_]A\
B0`tcL
AUATSH
AVAUATUWVSH
fA9^4tyI
0[^_]A\A]A^
t&H92}
AUATUWVSH
[^_]A\A]
AVAUATUWVSH
[^_]A\A]A^
McD$,I
AVAUATH
A\A]A^
A\A]A^
AWAVAUATUWVSH
8[^_]A\A]A^A_
8[^_]A\A]A^A_
ATUWVSH
[^_]A\
[^_]A\
[^_]A\
AVAUATUWVSH
[^_]A\A]A^
AWAVAUATVSH
([^A\A]A^A_
AVAUATH
0A\A]A^
ATWVSH
([^_A\
ATWVSH
8[^_A\
AWAVAUATUWVSH
H[^_]A\A]A^A_
AUATWVSH
[^_A\A]
[^_A\A]
AUATSH
0[A\A]
AWAVAUATUWVSH
8[^_]A\A]A^A_
AWAVAUATUWVSH
L$8uxA
T$luiE1
[^_]A\A]A^A_
G80toA
ATWVSH
8[^_A\
AVAUATUWVSH
0[^_]A\A]A^
AWAVAUATUWVSH
D$LttL
X[^_]A\A]A^A_
ATUWVSH
0[^_]A\
AVAUATWVSH
8[^_A\A]A^
8[^_A\A]A^
ATUWVSH
0[^_]A\
AUATUWVSH
8[^_]A\A]
AWAVAUATUWVSH
H[^_]A\A]A^A_
AWAVAUATUWVSH
x[^_]A\A]A^A_
D$<A;D$(
AWAVAUATUWVSH
H[^_]A\A]A^A_
AUATUWVSH
H[^_]A\A]
AUATUWVSH
X[^_]A\A]
AUATWVSH
0[^_A\A]
AUATWVSH
@[^_A\A]
ATUWVSH
[^_]A\
ATUWVSH
[^_]A\
[^_]A\
[^_]A\
AUATUWVSH
([^_]A\A]
([^_]A\A]
AVAUATWVSH
([^_A\A]A^
([^_A\A]A^
AWAVAUATUWVSH
8[^_]A\A]A^A_
HcT$,L
AVAUATWVSH
([^_A\A]A^
AUATWVSH
0[^_A\A]
ATUWVSH
0[^_]A\
AVAUATWVSH
8[^_A\A]A^
8[^_A\A]A^
8[^_A\A]A^
8[^_A\A]A^
AUATUWVSH
([^_]A\A]
([^_]A\A]
AVAUATUWVSH
@[^_]A\A]A^
@[^_]A\A]A^
AUATVSH
8[^A\A]
8[^A\A]
8[^A\A]
AUATVSH
tHHcS@
([^A\A]
([^A\A]
AUATWVSH
0[^_A\A]
AUATUWVSH
X[^_]A\A]
X[^_]A\A]
AUATWH
@8I9C`t
AWAVAUATUWVSH
x[^_]A\A]A^A_
AUATVSH
([^A\A]
([^A\A]
([^A\A]
AWAVAUATUWVSH
Hc|$@H
H9l$0u
X[^_]A\A]A^A_
X[^_]A\A]A^A_
AWAVAUATUWVSH
H[^_]A\A]A^A_
AUATUWVSH
([^_]A\A]
AUATVSH
([^A\A]
([^A\A]
AWAVAUATWVSH
[^_A\A]A^A_
AWAVAUATUWVSH
H;t$Ht
x[^_]A\A]A^A_
AWAVAUATUWVSH
8[^_]A\A]A^A_
AWAVAUATUWVSH
H[^_]A\A]A^A_
L;d$0t I
AUATUWVSH
H[^_]A\A]
AWAVAUATUWVSH
([^_]A\A]A^A_
AUATVSH
h[^A\A]
AWAVAUATSH
`[A\A]A^A_
Antivirus Signature
Bkav W32.PenTiumD.Trojan
Lionic Trojan.Win32.BroPass.4!c
tehtris Clean
MicroWorld-eScan Trojan.GenericKDZ.94307
ClamAV Win.Malware.Convagent-9978541-0
FireEye Generic.mg.31e5f2a6588723aa
CAT-QuickHeal Clean
ALYac Trojan.GenericKDZ.94307
Malwarebytes Malware.AI.2010893789
Zillya Clean
Sangfor Trojan.Win64.Agent.Abcv
K7AntiVirus Trojan ( 0058f06c1 )
BitDefender Trojan.GenericKDZ.94307
K7GW Clean
Cybereason Clean
Arcabit Trojan.Generic.D17063
Baidu Clean
VirIT Clean
Cyren Clean
Symantec ML.Attribute.HighConfidence
Elastic malicious (high confidence)
ESET-NOD32 a variant of WinGo/Agent.FP
APEX Malicious
Paloalto Clean
Cynet Malicious (score: 100)
Kaspersky HEUR:Trojan-PSW.Win64.BroPass.pef
Alibaba TrojanPSW:Win64/BroPass.a56e9f46
NANO-Antivirus Clean
ViRobot Clean
Tencent Win64.Trojan-QQPass.QQRob.Mzfl
Ad-Aware Trojan.GenericKDZ.94307
Comodo Clean
F-Secure Heuristic.HEUR/AGEN.1216913
DrWeb Clean
VIPRE Trojan.GenericKDZ.94307
TrendMicro Trojan.Win64.PRIVATELOADER.YXCLQZ
McAfee-GW-Edition BehavesLike.Win64.AdwareTskLnk.wh
Trapmine Clean
CMC Clean
Sophos Mal/Generic-S
Ikarus Trojan-PSW.Agent
Jiangmin Trojan.PSW.BroPass.iz
Webroot Clean
Avira HEUR/AGEN.1216913
MAX malware (ai score=83)
Antiy-AVL Trojan/Win32.Sabsik
Kingsoft Win32.PSWTroj.Undef.(kcloud)
Gridinsoft Ransom.Win64.Sabsik.sa
Microsoft Trojan:Win32/Trickbot!ml
SUPERAntiSpyware Clean
ZoneAlarm HEUR:Trojan-PSW.Win64.BroPass.pef
GData Trojan.GenericKDZ.94307
Google Detected
AhnLab-V3 Trojan/Win.Evo-gen.R535068
Acronis suspicious
McAfee Artemis!31E5F2A65887
TACHYON Clean
VBA32 Clean
Panda Clean
Zoner Clean
TrendMicro-HouseCall Trojan.Win64.PRIVATELOADER.YXCLQZ
Rising Stealer.BroPass!8.13424 (CLOUD)
Yandex Clean
SentinelOne Clean
MaxSecure Clean
Fortinet Clean
BitDefenderTheta Clean
AVG Win64:Evo-gen [Trj]
Avast Win64:Evo-gen [Trj]
No IRMA results available.