Static | ZeroBOX

PE Compile Time

2023-01-11 19:27:20

PE Imphash

895e5e6e037e9108574fb94ed614d804

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x00001b1f 0x00000000 0.0
.rdata 0x00003000 0x00001118 0x00000000 0.0
.data 0x00005000 0x00000064 0x00000000 0.0
.gog0 0x00006000 0x00358c2a 0x00000000 0.0
.gog1 0x0035f000 0x00000398 0x00000400 3.59360864655
.gog2 0x00360000 0x00605e40 0x00606000 7.96147690425
.rsrc 0x00966000 0x00010f51 0x00011000 7.35116419195

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x00976540 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00976540 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00976540 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00976540 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00976540 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00976540 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00976540 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00976540 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00976540 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00976540 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_GROUP_ICON 0x009769a8 0x00000092 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_VERSION 0x00976a3c 0x00000398 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_MANIFEST 0x00976dd4 0x0000017d LANG_ENGLISH SUBLANG_ENGLISH_US XML 1.0 document text

Imports

Library KERNEL32.dll:
0x75f000 LoadLibraryW
0x75f004 GetProcAddress
0x75f008 ReadFile
0x75f00c WriteFile
0x75f010 lstrlenA
0x75f014 WaitForSingleObject
0x75f018 LocalAlloc
0x75f01c CreateFileW
0x75f020 MultiByteToWideChar
0x75f024 DeleteFileW
0x75f028 CloseHandle
0x75f02c ExitProcess
0x75f030 CreateProcessW
0x75f034 CopyFileW
0x75f038 WideCharToMultiByte
0x75f03c Sleep
0x75f040 GlobalFree
Library SHELL32.dll:
0x75f048 SHGetFolderPathW
Library KERNEL32.dll:
0x75f054 GetModuleHandleA
0x75f058 CreateEventA
0x75f05c GetModuleFileNameW
0x75f060 TerminateProcess
0x75f064 GetCurrentProcess
0x75f06c Thread32First
0x75f070 GetCurrentProcessId
0x75f074 GetCurrentThreadId
0x75f078 OpenThread
0x75f07c Thread32Next
0x75f080 CloseHandle
0x75f084 SuspendThread
0x75f088 ResumeThread
0x75f08c WriteProcessMemory
0x75f090 GetSystemInfo
0x75f094 VirtualAlloc
0x75f098 VirtualProtect
0x75f09c VirtualFree
0x75f0a8 GetCurrentThread
0x75f0b0 Sleep
0x75f0b4 LoadLibraryA
0x75f0b8 FreeLibrary
0x75f0bc GetTickCount
0x75f0c8 GlobalFree
0x75f0cc LocalAlloc
0x75f0d0 LocalFree
0x75f0d4 GetProcAddress
0x75f0d8 ExitProcess
0x75f0ec GetModuleHandleW
0x75f0f0 LoadResource
0x75f0f4 MultiByteToWideChar
0x75f0f8 FindResourceExW
0x75f0fc FindResourceExA
0x75f100 WideCharToMultiByte
0x75f104 GetThreadLocale
0x75f108 GetUserDefaultLCID
0x75f110 EnumResourceNamesA
0x75f114 EnumResourceNamesW
0x75f120 EnumResourceTypesA
0x75f124 EnumResourceTypesW
0x75f128 CreateFileW
0x75f12c LoadLibraryW
0x75f130 GetLastError
0x75f134 FlushFileBuffers
0x75f138 WriteConsoleW
0x75f13c SetStdHandle
0x75f144 DecodePointer
0x75f148 GetCommandLineA
0x75f14c RaiseException
0x75f150 HeapFree
0x75f154 GetCPInfo
0x75f160 GetACP
0x75f164 GetOEMCP
0x75f168 IsValidCodePage
0x75f16c EncodePointer
0x75f170 TlsAlloc
0x75f174 TlsGetValue
0x75f178 TlsSetValue
0x75f17c TlsFree
0x75f180 SetLastError
0x75f18c IsDebuggerPresent
0x75f190 HeapAlloc
0x75f194 LCMapStringW
0x75f198 GetStringTypeW
0x75f19c SetHandleCount
0x75f1a0 GetStdHandle
0x75f1a8 GetFileType
0x75f1ac GetStartupInfoW
0x75f1b0 GetModuleFileNameA
0x75f1bc HeapCreate
0x75f1c0 HeapDestroy
0x75f1c8 HeapSize
0x75f1cc WriteFile
0x75f1d0 RtlUnwind
0x75f1d4 SetFilePointer
0x75f1d8 GetConsoleCP
0x75f1dc GetConsoleMode
0x75f1e0 HeapReAlloc
0x75f1e4 VirtualQuery
Library USER32.dll:
0x75f1ec CharUpperBuffW
Library KERNEL32.dll:
0x75f1f4 LocalAlloc
0x75f1f8 LocalFree
0x75f1fc GetModuleFileNameW
0x75f200 ExitProcess
0x75f204 LoadLibraryA
0x75f208 GetModuleHandleA
0x75f20c GetProcAddress

!This program cannot be run in DOS mode.
`.rdata
@.data
`.gog1
`.rsrc
AT1,$A
5@lte@
A?'Zuai
9l]8M@
0m HsC
SiE_IZ
Pt/kf+
FVCsxbz
%JWovPx
LWGa1'
Vff=J63
&m0nI3,
G<~+iV
K\D@'<
52$H8i
^(c@!@
F_bjUV
K4+g+2
"e!I^6}
V0JiM*
#[^N9g
oUfPT|
WriteProcessMemory
<qi/UZ
n2I=L`
})D@OZG
%qDlzh
M@+[txVKWp
weV.<9
{Vx3Ui
G"wF"l
!:o<E(;w
"H4b{Lb
+o@Dc<a
39ZDP;
zc|a'5s3`
\PaYvw
y3~`@o
q]mnz|
^*XK`Pq
VtK18y
zs@k\m}
MC]98EWs
1B?{:1
Z.,i<yZ,
O$uB$)%"9k
_LCC]<n\i
z-hK0~
*/lxt=
N/O,q
*VO::x
T=j2]#
v~F2Fy1
)x#'DI1
P]q@8u~
}:SL(1
&y\*@&Rg
w8<{/AX
vQLqylQ
I'v<$Z
>tqUKZ
f]l@f;
JEfYE=
(d`cml
B(&})W
!UlNaO
wI16oS
U\99r<k79
N%w7f;
x?o Co
6PaQ R
\3VMp1
O[V8EWs
AM8EWs
"y@7R
w>VlZ)
-x=J}RM
PLJyv@
X<8xx,
~byiEe78
2X<8xqQ
LhLA=(l
gNgat1z-s
:(P0^e
x +>)h1-
bK'W-t
pi x@"
5%V@z3
W/Uvt
3#eLQ8
gy/9@f
Sn@+LD`
fK:p>s
5+2t3
dO5hq@
BaMhA
!Sj 5z
Gez33/&{
nNfm_[ng7
F?f4 `>0
b[4d7<
B4C WG\i
=_(S8EWs
`|\ZVt
^U}%S8
HjE]NI580TIF
Z f;Iq
oG8EWs
jr8EWs
Y@,}.3pp+
L.Xv$(M`I
;V`HEs
Z9xU>t
{qZMi!K
S"S9<p*E9
aw]kA)oU
q08RI<
1S&vI9
R+!!Sy
bSIoT
6Y6W2G
~^A>P;
FA31.7p
GetModuleHandleA
Kia'W*
KYw'o)9
sF.][5
|3yk+4
sj?n@9
gEL3i'
xa8L)h
^dmOnc
s`)<Cg^
/a=sfJ
AnBzL:
o3@1Fkv
AT1<$M
!(<e6>
$d8CAG
;v-\>:'
R,\m wj
H5VXGj
sMKUy1'
SX:T~"
Xo3z'`
A+g(|wK
l$8RvWiH
`%LTkdO
UO"b>s!d
'>=b91
Oyjb3z
CreateToolhelp32Snapshot
1TWnf;
6+ _*+
B%!8l$Qsh
USf!L$
^C0'?`7y'
=iWQc\$
PPy9cp[
ATD14$A
ta4mf;
5@.!$3
(h$A*Qi
m,h^R7
"28EWs
KTjEWs
L;&(cP
ysM#$?
Sd;@i
HD_R]l
aZ^vmP
_m.nIO
IqqM)&
V,~dBL2qj
NI1R,5
D14$A\Mc
L*28EWs
OK!K#h
wk_q~~
RjZ(?b
GikD'5
\8bS:W9
@Insf;
bXo8EWs
6+@J}Ur
D$ lw;
kmq!|$$
ATD1<$fD
(S%AT1
{\9w;sJ93
#%qTwe
.Ol%{Y
d2"iRm
&Bo@rM
4-8EWs
H<&-YOq
ET)a|s
?}0]a'
@<R{"~*
GCJZ{X"
A69*lv89?I
@@\9?{HJ9[
TT$4qi
rT|O[x
xf")^[j
g_i%9J8y
D0PL*3X
L0F~/B]d6
(s[k@2
4kE1}M
+kLdvY
kcU]ZJ
/CqZVOOb
xgTk)n+
`7hEt:
@Wf%S
L!d$0I
;aDC%bR/$
ujx*eGV_H
;oSIM"L+
(n5%V@z
%E@Pi?E
DJjDwE
`&v{OPJ
vkz f${
{??}19t
8Bhc~UXh
{P>#(|
?o6baT
7F TQH
S=Gb#R{
asTe'(
Pk%S_9
@XVm5h
zW^ZJP)
L;G+|<0
:Sd =$
R!_gf5
X1fh1~
HvS0/~
}l&7E3
D1<$A\Mc
[&3)1_q
GetConsoleCP
DEqh9=
-kTT0E
TJ]\Sh
A-?>NS
fV>Rhc
qk99*P
q5~Dif
vq@4zq\
k*]Zwr
\Lg}zo
5k-N#g
V'VO"}~
SwxvP
;PmrfR
A=5?!I;
fH+N=g
|>hGYHT
o#!B4\c
5876(>9
-0i@zf
InterlockedDecrement
!v@aF6x
dCG@d/
H^_')S
IG~8:K
`>qoe"0
['nU?v
ag43'w
cqf,P@
5H(_<Y][
!3<8EWs
D$ 5(b
3gCN7e2!9=
xUE<iyjuP
E,i&XNPo
DCnMmb
lh4Kg+
:{<!bi
97;%3
x66+ATA
wA[XLc
TO9]/PMR
MG#Re@
&g)?Ms-
TlsSetValue
D$(1T$
[XPYt[/
_28EWs
<_ZxH#
GmGIP
;Nhq$T
6daI8I
GetStringTypeW
:A)SX[
OEv'+,_
${uKuX
m2aY(-
=J!Fbz
R_]r[7
}^hz.s
QA8EWs
?tW?cf3
GD1<$E
Rv2S91
s4T/u-R
GetProcessAffinityMask
fbjRf
RBm/^jj
}{kdYds
XAbq0
pq3A_K
G@8EWs
AT1<$A\Hc
]B^09Z
^Mk qE
[N69|2y89
%I'RWZ
z|:j8I
k/D;lX
df<-5o
8g(bin
Bci.rd
og-]_`Z
rD)i6}
3H;\$hH
{D1<$A
!x\iM'
;}d=d
U0fx"=
Hvpu1>
E]@g*E
<6,W7GZn
dX[4mX
sYB2f@
h I2vB-z
7aVYDK
{EWj><n
J #ko>J
hgB:5L@
CreateFileW
^bY/~H
s#*PtjB
5}!VJ'
XOE-n@
AhHxZO
O^[Iyx
A\A[XE
@Uc)LW
mEF/Hg
Ij#_-}n-
f5)96f
EnumResourceNamesA
HeapCreate
]U|>vz,}E
=Q|yUg
afwTFV
Thread32Next
obRE_e%
2UZI"gr#H
H,NXDInC5^I
>\VVJd
lu@k\{{
::m"^v
!E\~rR
w?w&Xg
#o'78
*L5@.!$f=Z"3
\$(9t$(
Vhbc,+^
D1<$A\
4g@f0>
H854BC9
M48EWs
`8&SQQf
LoadLibraryW
OATD1<$;
j1,$fA
}sb`\#
cmLYh^k
6D A:
(G8E\3
WJ0AA%/
I&b/yVj
AT1,$A\
TYK$(p
6tRD)M
uLK\.y
D1<$A\Mc
E{\J-0
J{S)zJ
9VCbK^)7
>Y{E">
!LRwEP%
uS=$oK
nK&[m::$
W,*<95
&!0)]]
tf^NM
?Do~/F
)2Q|!P[%
!$0EWs
/,gXAY
GetModuleHandleA
]i:J2.h-
y h;# Zh
w549L.O4[
6Faf;L$
D1<$E2
~]e/Il
N +G&}
,=W+T$$
WI*XVf
hS5wR*
LoadLibraryA
l7EH=-
]zeg?.
ay!xWa
s<Pyl/
'`;WcJ+
[=&;%=
\"qR&j
:E&"kz|
(T>j*~m
(vi`;x
6>>4;3
j=,';4
6<8hg5
zT`UJS
WP$&gWS
Q0i;VG
L8y$|?
a<=WQ;J
=T@oU~JOA
|(@IyX7
xzY)<Lxd
+OFJZ!
s%%G=G
O[R(j#
xw5#nD-k
A[XAYfD;
AXA^YI
9aO=7#
KERNEL32.dll
ED/i ]D
FlushFileBuffers
-D14$L
ReadFile
`:'Jg u
9|1Zrj
\]"X6]
SetThreadAffinityMask
-6_Rhl
1^tD?B_+
).#T^[+
^58EWs
N\<_9;{4I9{
nQ6~#|z>
iwD<\F
BvHR9+
sA[5DB
SATD1<$E
]^A&>Hc
Py@9nGw
SAOV8i
3C`=JQ
}mV"zI
TYQDI
TlsGetValue
,6cPY&
{;tnQm
"J8EWs
~,&8EWs
3GtC)k
8XY9h_
o`8EWs
[p33>[^
J{W O_
DT[|y8j[
i/-\]`
:I4V5d
;D/%Kog\@b
\`r\&sT]
WB]i@4
b6<^R5vo&
aE%TH'
,Ow7Mg
:_]iUu
j3Fook
mb)08EWs
y*d{TB
*x;dvT
\i&V./hI
h]_0o*
6rDGpC
3<hFC.
~(CaZi#
|S(TKAd
\X28EWs
I[@dd\n
f7*n:*3
#8#Qm ww83
k7C%yix
%+}[=[
7rl`'B
[Dzkf7
{e])U}('
sCj!P2(
z,kpPu
[Z<g{`Z
UT.I)tTV
SetProcessAffinityMask
o:}_f;
L<SrATMc
@F?$Sm
oT,=}y
%CF?dgn
R/rEUR
e.[EPBWZ
ZN~(b[i&D
:0q`8(
GetProcAddress
9\fbSc
D14$fA
ATD1<$A\@
18*p"
w5dkQN
H4bt0/{x8[
T\ 9K1k.9
>JUR8:
&s8EWs
;1F%Jrr
D-MRKd
UnhandledExceptionFilter
AT1<$A
D14$fA
[TwATA
z1,$fA
6ALC5I
bQIsh;'IB
Ef"3Bvf
jV1.,4
:boXe+w
$OEF:j
EaxJv3
bx'=mX
me2/T^
C,/o+]FG
F 6,pb
jT$j_M-%
?e@K<(k
QuY\NfP
g@CvD3]
z?|P)b?
Eh,Oie
pb};-Q
uuA4E@
ATD1<$fD
96JKw_
RfOGba8
6ku]fH
GetLastError
g"[b\k
'D1<$E
*?A\f;
x_= ln
>7D1VVv
M]kO<.
2fbP#^
3g^p2\1
@Z;)i6}
%+em]]
WT9\([
HeapAlloc
GetCommandLineA
V5by>#Xxy
Abl{DY
L$$(|$,f
isC:Ul
CX#.00Y
OJ~=+b#
4>!(Mz
c"T3e^
(Je+<|-J
-ZLyt0A
BR}|6@
yW{jN@
1,$A\@
-Eo)8EWs
|Iug^<d
z3<iJ4K
6[dTgR
a[akQ\
^1W YF
f+L$3A
]R5D<P
C[o?ykG
tw07{?
iZI+\&-e
^*kN?1
sr\W>M
)z8EWs
AT*{^h
-rL']6
b=+x^|
4uR+&R
HeapSize
X2RDe
rN$Z-$z
OBXyYl_
@~VR\%
eu/[*@
ATD14$
w@A.&9%
8EyeRE
; gyCN
2c`c~#
j6320<
,7ac$4
!Z4z[1%
c}[jPQ
TSQhZ7
x,8EWs
r}v-}"
EWArRg
ATD14$A
p0-}gd
N#grNSE
*gEe%S
+#CoHc
r%AKDbj@
L$, |$$ \$0
L$$w2f
,o`#lcZ@"3
*=^$xp
rg&3Qi
PGkxui6}
jUYiV#
lZ*l<D
j_x|'j
FZD#Fx
gnKmjD
R[yAx+
GbE8EWs
zoLxJh;
h+7ZY
DM^^&o
f nhYf
AT1,$fA
ATD1<$A\
?rI}f;
$1?"Co'6
1_UEk,)
RB^s5r
im)%[@
t$_X+l$
bAT1<$fA
)5#+y9z"
J7QLf.n+L
zq{P]
s^O{\7
CuFH,J
*_7o]`v
?b5$i8,
Dg20uf
GZiY_
GetACP
e .C]td;
3yW:n0
\m0J\<
IKaOciO
dv_*^:
_S8EWs
<qrkA3
_^hb~k
Ht!r_\
>P))Ym
|$A9|$0
lc\KQ]
8#8EWs
6Hl412
OG];F0
1$)GzcRYp,
FindResourceExW
spH8wFPI
HD[KNI
O{@mZXu
C4gH!q7T5
H-8vlV0wb
AT1<$A
1BMpWM|M
f.|Uc|
-W8/|^
qV,` _
:0. =G
L;$a|<S
WSycgT
AT1<$Lc
-S7~K!
MOVE'fqn
~r>Fq2
W_ZfE3
\mGi['+
bhw2U5
^utcj6
hq"or_
'qGiH`7
P&|,#@i}3
[}un~~
+lWe8Pu
a[>g@X
g)HcX]_f
;l^BZY
Er+$)
g#pS@
hBb2>A
b'tnyJ
Gl]awk*
mI.+j>
_+ xfA
<iF/R-
LeaveCriticalSection
2WhUAf;
T$,f1L$,
cTz~s0
L@/0CEzc
+88EWs
QhYAzMz
)2t5EWs
Vs`&;8
uf:sEaM
uTq>2UU
Tuz?KUB
en&t#Eo<g|[8
;V!f/<
;bo;T$
PV$*+F
MB"<ATA
[DG[:Wh
V~hsp#
7oit_z
EnumResourceNamesW
T!4A=cBs
:w~TNTi7*
@1C _G'a/
,?#Cr3D
uf$/3u
/C32m:
$#5(9
e+z$:0
X\:*-.
q8E=A?2
GT\LwS+
1#,_ZH
%5C29T
R9NJjS
OQNq3b
HFmJn[j[kU
U/\NMo
9m"bn)
14PN};
0{w>f#
fQ-AB4
)W7^r@
ATD1<$A\Mc
(h{YiN
l| i6}
1,$A\A
8z@mJ/t
IF'tm3
h*{WYf
H5VXGj
.6e\$!
;Xy;En
V]5fO5U
<^hZwT
/[MCug
Z!ng7ZA
AT1,$E
.A_A\A[H
c8%8EWs
pWW\#<5
-7cIIg
`}t L}
s)[,}5
ATD1<$A
)zs&,<de
EDZ#0bp
gM4.i6}
4V/:SB.
KJUPER
A%sQZ
O_@!uM
M-d.6g
cn$T*W*I
U;YD==s
#T?got
Sl!n<g*V;
#^@#/y
eA"bF_W
s[8EWs
fdQb[f
CULGm
_VivJKY
e{sh1a
^!qHGR
qGCpLe
9R#rqA2?3
_K1T]#u1
4E?]f=
&Du&;O
ToW:K9
~F[t!^G
Bnk&)R!j
}Bk-2V
C J\)D%buM
'8 \e)
9z^ @s>q
(YT#O<
Abuyq
!+8,p"
}*,c,#
F0-,AG
@G$bp@S
[/y`k(
g2M<irK
V~O)BO
z06ryO
gGXpp{
BZ{n</
I'k2xSk
t\ZdVA|[
\-Z=2Lb[*9`~
'Dx~^B
z,e,9~
Ls<NB\0
f3Kh?r
-"@YR!
7{!vO.
<2et$8
eM_#/d'
I1D:]I028
.KEFF@/
,gDe-gcz<w;
}h@wMo7
fynGZ{O
nA\<$Mc
1i\h^1|$
tq)A%x
p81OwO
Rt|Bbs
R)&1N 
*,ZB&0
(+A?c{8'E
:RFgoc(Fx
+ehT!rh
(bwN~??
<*.Kkj
f|1hFk
wmhPH.
L0Z.D\
:INW6i
~{WUbHl
kl?#Sr
qhwsLp7Z
K{?/rq
+T$$;l$$
/(vSBQU!U
6s4TV{
,`1-;c
I|Vm6$
aC$b1X
AS6y5{
?x5 ((9<
RfCr%s
0SLh[f
{&"!l$
f-gc U
])D%bYx
*Rx8EWs
Lm?OOU
)`9@M(
4E?]H3
X}ls#o
=SfZ,%
dY|%f;
TlsFree
7R pa8
;k7]h%
"%pt?Q
ZlQjeU
Zd!=wX
g0>6Mt
ECZdy6
].e!Fji=
'|bm'X
z8-{kd
hEZUIZ2E
Y*K)).x
f]l@f;
k{!p=8
[~NWiM&!
P}]r*DE
.Wh%;n
RaiseException
<HFpKq
ZtYk^b
3jV?0<CYS
rhc_Nk,
#HL"v!
Z~!'G
=D14$A\
(_+kK2kR+
l|rU>*]%
(K/fK2
[d{=fd
B?d|8)
>y;U2F
U[/|-
J7}AA&)Z
?jCLyK
87)`#_a*
KqLX>3
4JQ=3=
lXV=Q
0YBPaP
gYGoW^0
5p0Tzg%
.A}L`:x
T@[^L=W
O:H.10
]0zs,`
s dx7v
%!k-)
ws)>va
E5l;:sU
l$@)l$
Wr?ATA
D1<$A\A
#l_ZY!
kKRs=A2
kKWcIoJ
i2m7 h
inNzlh
|$Hf3\$HH
WriteFile
.4r.Lh
.ms+LhN
:?Ao&i
>hM z$h
Wlh%*;
\B{e0~
?~q0Tc<$
X}8QmM
H3W0/al?V
P.?z/j*
M;j<>f
+lv+Z|D
a>V5fI
tdnjDc
oL:KdZl;l9}
oTAN"/8
oo8Vy L9
rA5cw0Y
D$ &,]C9l$$
jt+U:n
;G:'+Xg
"o9wWOu9d
N8`}b=9
87cEWs
uG78EWs
\qiFYL>h
@x_8EWs
+Y!iS[
8y G4$
{88EWs
4h%v((?
a/BAT1
9M!jAVI
A{$PfA
hb`*1A
D$0NC8
(ALaUo
9O=0KX
)chp:@tB@
$Hc8^]
!i%=
-6DW~f
b#;ATD1
SetLastError
]/kxL#
!#\\Ny
@8"zFp
y\3B<~
ro_a6iK(2n
j6WK)%m
n:8:=%
RcWYXn
i1%R+-b
A6}k9C
X?5f`|2
K)uXE0&
Y&aCzS
+7+Ns6q<:
I*xyvb-
A6<$q1K
7(k-0_
l2xW\5
|[4%-R
Z jqS
wZ%UG]R
Z^a&jY
7h@Wyk
>mSuGq
ysw =k
<Y2}ET1v
pRZ}y7
dUq5\
BPJrrW=
Q^=.V)
WideCharToMultiByte
EncodePointer
9m??cP
qq`5A\
HsABxt6
/e1Klr
A^zmvy2
G%!P)C
dD+pg&
~'P13p
W+~J*6
+"=$[#(
)T_oix<G
AT1<$A\Hc
x~KkfdF*Y
]h_AsFSRU
J&H1Lh
^5w?Y5\
]AxGt0
!~.uiVK
tV3lwu
"BSq/u
4hGgqji;
m upu
!S_Pay'2P
cx1<$A\
,#j!?n
_$S~7F
.oe+Oh{
TR&@u/
Tgj>IL
B+-yHz
F_}9xC^
tT3Y!i
+p}9~*JEU
~-1uF(
jLX[V>
7QMsDk
%DOli*
Aaa^j
..`xJB
3?e `s
NVBan!cb`1tD
EjZwt_j
&Q8EWs
@D14$A\
(/$0y&
B,1%E[
IC8~yDO
R+e|b,
5@.!$3
-4o-9P
s]HOWr
58[|O\
aal}m
xgo`",
Z<l5Rt
BYC`uD
zEKVI4o
3,YCr
-Fdl',\
+L cl;
vyhV1\
PHk.%$
>PfrU)
R/:3y#
*[<EWs
,uEjE#D3
bOKmWEWs
/+|; mC&
lCXS)\^
{M8EWs
t$(f#L$
I!!ciX.
w08?6a
f'H02"
A_A\A[A
]_ZA]E
MultiByteToWideChar
9'C[a"
PR1jE6
m`<cp(
XEWJ*H1
@-z'n?U
BAr9)4
M?Ba8EWs
]AbqW]
A&j\+q
Trz83:$O9
i8LAF\9
cDIf{ED
%KXHy7qv>
ir_=#v
ZVvp;_
{8haQN9
oJk{juJP
91JA?N/
}W#R8EWs
io{DYh
Dk?7tlH
j+x(m\
Eh?hf;
D14$A\Mc
7fm/^f
4ATD1<$A
ATD1<$
[TwAT1
'b'QsJQ
b=>^f
E&jLa-
5ATfD+
xlw|s-
%?V-si
4hV`ZS
wQcai.+c
q{Xzr]s
4h>IOg
rFl!j
[TwAT1
?nIR@/!H
EL;RH>
[^$\]f
fS<?:A*=yD
7<sWZ6
FSe8Jy,2
)9BRo4mB
$i,,uZ
Z}LE"S
]>llFB
Lw_rJ$
P+kd53
ATD14$A
UMM?&
0(ut+
wQDTWII
HIqzVjKI
bR-?79<k
t;]h?l
S"KCEY
%af<mN
$26@8TL6
zj')E~
OqKQ*
]2V<P_
FI|@I1
%n\Tl|
]9F#,\F#
xB,vq6
cIr#w{
\Ax?u{{
f9L$0f
T~pMb1U
@.jV1
Jc@P?]
.m+>Ra
f\k[7`
WT1J^cJ
@9i@6"
N9nf2J
[KC#js
k)/>_Ta
Rr|ZdQ
;1<{ZO
jdj>_Q
njCToR
[RoI&N
A|8`gy}
SI@Vt1
fwCugf
%1?MjX
D14$A\
KJhEXl@}
0|T]TG
*u,=)z9'c
X*5S<$
$hGl$xc
'y,=R#
IS}}U?D
|\!g0
AQfD3T$)
fD1T$0f
A1<$fE+
5)r+/]yt*
$!Z$tp
{~B4KD2"G,
JRX#h]
L<SrATD14$A
1biI-BcN
d/Cb^yN
LK])oy
iu*j0h
T?*?d:d(
+dNt^C
vKo_I
&$t c
h"~@C,
1wCQx1
htz<9}
4unse|
cukLSr
p;p"wL
Nq/?~vX
ombB_j
Bi&1rnQ
h2~.oE
OpenThread
\$l;\$
wj]`==,
K?c[^1?1
#!>DS"
r{d-'V,em
=t8EWs
ATD1<$A
Kq} 3G1
j8@>mMw
E]N9mC
ax]H*Rx
qS@P!u
HPO v)
B~OiVg'
3NvMh+
`T@1z:
`ZHI;Q
9Ec_hL
u-;bE*L
nEf`^B
@6\/GA
^TA` c
W'IGg >
jJAF;C
aKP6QL'
8ATD14$A
Fu'b3?t
6tBu Q.
h'){72
Sd%q9^q
yKpI|.
GetStdHandle
Yf=ed]
?6p8h#
5FQ5^
GXQf."
5@lte@
X_>{t
DeleteFileW
TerminateProcess
t|$ 0%
'*Sa8-
&EGPSm
GetFileType
rzXf#s
SetUnhandledExceptionFilter
t$ =)V
IX?Yxd
x f)\$$
{D2C+k
ZE%J&j|
c_b=d(
QbK-ae<
SetStdHandle
v,iO9N&
"g'^sup
zi?p c
lh}Ly[7
bal-a+7m
^1h\Te?
g'+~k}
Z#:`t`
$,"E.2
D24=(R
D$ (L$ Sf
#)q+T
?5T%Xj
BQCH^FP
CNv0 s(=
X)n2qC
U[X&*,
hT8EWs
;Qld)BPW
`<V(P;!
VPOYfW8
t/F3D(1
BC_BrD(
NEoFc0~H
"[(_,9
xQTiFQ1|
Tds?KM`
x!{0&=
c/dvZI+^
?~{a|N3x
<|_&?c
"%qX/[b
GBJZ/OloZP
FLUD/fC
@rt;f;
k;9-0i@z
sw5=C4
PvD|#_
se]UCb*
yD1<$fD
LoadResource
M\D"@x|E
Wm,pj8}cq@
g5MfD;
i5WfBh
LocalAlloc
wv,HOD
'lb}hf
VirtualFree
T,weI
-]~T3|~
D$0@50
l,jN>^
G;d;~R
0sz'6Q<
}7W9 1
\[Xa9}
hPYaBD
Z7D\7
{vFl1D(&
S-noLr
5+34qU/q
5M(=0EWs
QH<j.%
5{"m7@
5hgfVb
kYf+Fy
A*2stq
@E;tI6
k,%\cU
56(8]f
a5n.aqzoy
p{r<4X
`) ? V"
O*UEWs
AT1,$A
&{CK CN
DqH[z:
*,r?smr
SAmc7o
4=m*:;
]f5?-2
==6v83
"FT*jz
N2gWBfo
K5#Qc
';@VU[
P;f8;T
GetConsoleMode
D$ of;
T;;0 S,+
uady^A
}~?5+G
,3]|&C~
x66+ATA
zuo}.R
:upmi-*1
s %c8jP
!q5$P>Y
1Crf)L$
D$ c$1
L.d@tf*^
y;YB(|9
{& ("QS
v7k!uO
`:<Y8p
icfeV%wj
m~z{a3
%R#lf#
N|z7X=}
zM^q?J&7
x@$AxL
}{,B
CAXYb'
sgB-!><3
>14Qt.q
iK^ATfA
ATD1<$A
}v#ZA/
T"IATD1
1<$A\fA
5xFrOf
prw9fp8
bMycE~
StWi?`
rW!4r
R_DV'$
0j95%'
!2{Lja
mj#V<c
KovU{h
fk2&VlE
cm,hxcn
,E|j6mCp
rti"|0
|[R5;/
x${$oP
l@Zs@n*
N2nv?1
R":?hR?A*
FF je=
ty2&v!
g|JEWs
fyz6!Y~lUw
}mzN8EWs
H5VXGj
w5hwG2
;]0JjT
08K67O
l]5u\ZB
]pTG9
E;&o8g
FeLmB]
bH"[fx
|J8EWs
Lc%h"#9
lD1<$A
ng6T=
65z8ce
emltJO
!1D14$A
D1<$A\Mc
5AikcHA
(9B9k
[Rk^+*
C^wsiP%e
^j6RT+
"j_7tf
2r<><WW&
<<<y6_
iE-F6<NZz2
kXhzT3
7#k\E5
i]O02h
}">{oy
!>>*+>u
Iz@{4?^
+Z07~BvC
SA<8<>)
#RIq,sd
KjLM#{
ATD1<$fA
[T;Iq/
cC#r[$
lZR( %
PV6v%Rj
f1M6MB
;K{+Q;
#?Jm)-
B|a?r{
KkVMYS
XX8EWs
D$ HXq=H
-Eb<{6\*2Xt<
rQAR{s
|$<nKG%
W."sG7
!O"y^T
9D.L3@
sf=Ty;
{K:O6W
zv/f8W
\k0B2:XWh!c&3
R^UM*_
<@D!&
IFPs7w4
n!fz>1
AT1,$A
zk\@YV
Kc<LxPs
^N*q0NO+jt
A_A\A[M
#7.oZ
*Pr?5I9
GetCPInfo
qjG/.Y
9QBsUP
zZ6~-\
f#?],G%
\B({{
Pgv;H=@
FreeEnvironmentStringsW
i$}Ei4D
X^@3&oz?Eo+|
BQa`{C
+uC}8r
k{/:$M{
R@+vG Zt
jG+v8]t
D1<$fA
`|A\Mc
T$0(|$4f
&[<IwR
j3dtZ4
64H+1C
q[9vA\N
3S@q-a
UgHwsy'
@s#8#B
B;']1^
@1`;HM
))diy3)g
])q?j\-
j}A#ir
=!8DDH
<,Q"6:
He ag6
IFgZgLs
Af-$7A
%S2_zZ)v
dHQD)RH
EnumResourceLanguagesA
lh=VU%
#C&!`*
{:t%K4<
My@>
EnterCriticalSection
SPd}Vh
7Cr^#ZYr
6~z%,6[;
B^5{;k
CAg&VV
d82/7g
~9G4?-
I+ =B@
fi1")N
_FNel78
(}Dd0g
dc?mT~
_})zi%6
0!_z'8
SetFilePointer
*ytHf;
ATD14$
GetModuleHandleW
qk?/Oh
-h#/9|
/5VXGj
LoadLibraryA
4)He5)
@5xFrO
:c#Kd*,"DiG6"
ge]E!~*
/qgnS_
fM6EWs
2W,L~O
hS-fD7
5+2t3
9c6wJn
>2%vWX(z
;OHe#g
~<2Cx\
o+ATD1
AJ.aA,q
5F9}$@
3EWscL
GzULcW5T
.ifs?-
8+Ji*3C
I 5+v6
y6$v4#,{
1WHC)1k
J.F1re
ATD1<$E
P7F-|4
_FD7r}.
-k#Q6%
's[_6<jf
Whg`sl
l9R*"q
D,kM#m
Z^S3xn
aV}0GqO
5uF.}e
zew9_%
HV.x|HD
P*ZH -G@H
dVWg#Y
sY_?-Ho]C
L)\$`fA
D+NcQ,T;
'KV(\MnO
vJnT+n
ni~@lg
,,gHp_
nwUx`\~
2Ij"rd
[XamT?f[k
PK*b\\
'o^#jX
"MkEww
.>v'yiu
/ucXeG
adwr,e
#")d!q
!cE_a
lt6hWH
H}0Fmx
WaitForSingleObject
V$i;$Fkh
@Z>Yp]I
}76X,>
m^z*]Y
v6'(F1P
[2c[k5
q/b>-T
i`^,WZ
jg<=sms
Yh#p5h
r0lgEOE
a,eJJ*
_n@n2[
Y!k;|q
KiIs*Ln
->/~t}
b#;ATA
=C,T%P
!%o!\ZF
DXT5BK\
gN\5~4z1
;l+~&5
L<SrATE"
qz8KA}O
\~|8ly
$2<r9Z
r`@.RT
i[Rmi+DB"h
t<J=D;=
BPSLrW$
QueryPerformanceCounter
h$9/O?
'}d[(J
V3W*QD
';;Vv2
kSck[T
p;>i@<I
?ti$< e8
%l6E0r
0"KP__R}
@5xFrO
_Di?|,
d+Dol'C,
[EATfE
!1<$A\A
!`vzaT
?3v3RJ:
5@lte@
ykQiIl&
l$$)|$
[[zCw+
d>P|MP
D1<$A\
8`[Iw.
2eP6!Z
01 Y=_<p
t_A3s(
P7?l^<
*CgIF8
L%8EWs
|Or*NrZZ
-GMQLt
uT50AA
b*&@sRfa
D1<$fA
W7233Q
!"xD)?
G[RD8{i
?xh"gf
LusBTZ
XyU0)m
t@d?#/)
`q)$[}+bT
WW:YT:
CRA:?c
vwVVZ!P
C:mj1O
(T(e@2hq%
o5wwa1+
]w8=M'wzp
^Cn?k=
kTb$iJ
,,o4Qf
2f=^m"M
I^_tX!
&nh0;im
f#\$&#
*RmQ.d
LocalAlloc
A1%TYwwRs1.
,q,U=*
UqugkH(
r?!0 7
AT1<$A\Hc
>nhBpR
7qs5i/U
bY25#|
eL:#6B5;M
~v]BpJS
>UZi ;O
N!quUBMJ
L1l$ f
`-"\$ AV
\$(ARL
DT$4)\$0@
pDPfD;\$
Jf=uT3
7EVzpY
yA}zk
/qx&~#
SyJdO>M@
N2P};N
&,0*@@e
dT?A~?\
|RKFLU<
J>R7z9%
?Fx&81
ZhT4e@h
Rs+X'y
1+#c=B*
&3n-C%
F$,m6
6|5+LQ5
*gc\@
Vyd_-HE
_u"}zI
GW 3]8
)5<gf;
27u{]06-
(dd6M2
\tA<8rx
xC 7Wn
iPoO(h
5K{d15
CZ0@~{
-4C"it
BXu+%dH
NRv+J6
T{EIKN
lg?G]!
Yt_UYX
@Fbfe^<l
u?(Rns
sY|#,>2
ZM_G#J
WeM_)\$
l~{V{o(
X-Du0D
I32|#h[
IWr$H(
FJE8Eh
h+2c$?
y8,s(KF
wj)E0.
*o(Pj>
UH!(m$
Ud|e0f
l%-d\5_-{1t
jg-+sM
+y,.;=>W
),VvCHN
bC >e"
f)\$4f
"daW<&^
!KZWL!
nDYj4sZ
VOC\vI!}
(xZ[PT
rvLtX}
it`1,=
vTd4&Cte
x~q+Hy
ygOynyX
JP\'gn
AG8EWs
%}?JFL
5}L,=F|
qvH|M%/2|
jWs}Q<
m[}Tk}
ZZ~h2MJ1i%8'+i
9^eRhanN
@\z~+l
4ST,i|
i(.ZJr.L
dsN;tL>uNQV
3?F0%4t
1UM0.t
\$(L3D$(L
dvxf+T$
4C9|Cb
CreateProcessW
4AXooT
^d|5X
tqXj0&
E*~V4
\x(@fD
ExitProcess
#^|,*d
y3J@d I
xrYnSNsf
6'U%lNl
l1UP=8
00Aa9
Q\]Qa[*
g0D W73
%wI!gid
1FF}s`
6B !t$
HuqWf;
S~_cy(
8hK1&9
Lc|d##
eREe8_
2L$Rf
RfD;T$ H
LcT$ ASL
hYKE's
i}5RW{R
'+aFga
D$0bIP
<:h+f;
lsA\Mc
i !T!w
X3QG^z
1(JaD$
(1UUC2
h^rN{h
2]G*Tj#=
p+zL#
oAOLWU
OS`b#q
J|h8;"
HA]8<D
gPEUgxDz4
hU?L`S
)`fWf3
rMwyz}
@B^Tx
oPmSkE*R2K
kC/=feS
Wc!Up)
R#z*gp
#'a"2Ob!m
r-?BR&
pWI}?;
t$0AX@
;AT1<$A
M-PX$
q:z:Mf
VkO8]8]
/;fN~2
cS>sSTI
>3M99D
x;cqH<
<(f?soA
)T>mv<
>Di(V.q!c
BDi(VQ
Y ,"E.p
d.k~s`1
g'<$-7i
d$(KZr3
USER32.dll
b@,tcM@
,H7vEJRh
|{]bT|d
2RmRIH
W%Bn[R
[/?NNe
qf1ewb
z)/N.HaUv
K'g6l^
W%CMi:z
+}U,7
%5O8'9!
wJcQsr
4v1iYd
9ZhNRc
JWZ)M
$'_[u.
/&N+!9
s'ZdC -
a"Ea9
($%x;(
9=[La8
T9^@GC
*ATD14$I
si3|*Sh
b=9zR:N
yUdxIR
P4D8WC
"{|?{e%
"xX@m1b
+(RK.p
i$vzTh
~|?B_
S]RQ\R
+b=i6}
#]!=i6}
m?IH8d?
bD`RyGZ
/&v +1
I/=[Kb{`vk
A7-T$%
aR5@yN>
tfIz_Uf
L$ U Rf
y&pr U
$Y:1L/
Jf%@Lf
6@\@zb
;~}2zt
[`z0W
r*jL!N
<+qT0>
PtTTGYMP
|$ )O=2
N.cUgO
+O8}?RN
EDzg?}
x<|n:j
E[N2,K
}c0i4}E
DG);+1h
"E^@-,
/r[`:!
[eU 0"d
682B^E9-~
{}\C.p
"/M#y
p+[o?,S(
h~``z5~
b=>{7q
9<Of`W
sopvh#D
D$,8gB
Qh81]t
r("9TA(
;#T7=(K
Jr4vrw
3@s)Fg
QwxeU.
WpUPo)
3by)+|V
M*XGaPJ
zo5*QIo
G2|9WJ
NvATfA
ExitProcess
D$,h!;
%KCWDh
J^<2J.
%}EH$s
/TVl\b|
S'hj%Chi
in~Ush
7e#$XN
VitA'/h:
HiM]`Ri
#kfcW3
kTg L1
Bqtqve
3!Th6e
c0/y$L0
&QZfUf
ATAWARH
D$8fA#
t$(r@&o@
j[dc/n
D$,T<4
LocalFree
G7:KJl
)<ZDat
9>L\`8+"
t^Nz,[
D$0A5*7A
b/0\Fbm
4WT*MD
|Zh@V
14#?;G{
fFy3:L
AT1<$fE
)*!qnX
hp1=,(
m>'^j)
hgUzX`"
!5]0,:
^PK~KY
ds2< V
i@8=wE^6
1<$A\Hc
yvue4RQ
Qe}s~*JPK
Cy8EWs
HeapDestroy
oI1c<e
n`KD3)b
pVWfC
RpD]Yp
AYAXA^Y[
klATMc
GetUserDefaultLCID
,q&30$
`$(q34
9c[8EWs
iZuX'h
NP2J$%
e1?eX(d
6G*tnqr
X6O5kP
^<sA(+
InterlockedIncrement
Nh%|kJ
r (`-+
MO>/>g
;YW3|$
~EiHgU
Ls|qT3<IQU4an(T
gihSk>
Ma?k{T
Antivirus Signature
Bkav W32.AIDetectNet.01
Lionic Trojan.Win32.Tasker.4!c
Elastic malicious (high confidence)
DrWeb Clean
MicroWorld-eScan Gen:Variant.Lazy.266138
ClamAV Clean
FireEye Generic.mg.34e8a1e9b59e98a5
CAT-QuickHeal Clean
ALYac Gen:Variant.Lazy.266138
Malwarebytes Trojan.ClipBanker
VIPRE Gen:Variant.Lazy.266138
Sangfor Trojan.Win32.Save.a
K7AntiVirus Trojan ( 005965831 )
BitDefender Gen:Variant.Lazy.266138
K7GW Trojan ( 005965831 )
CrowdStrike win/malicious_confidence_100% (W)
BitDefenderTheta Gen:NN.ZexaF.36276.@F0@aSPFLRgi
VirIT Clean
Cyren Clean
Symantec ML.Attribute.HighConfidence
tehtris Generic.Malware
ESET-NOD32 a variant of Win32/Kryptik.HRTC
APEX Malicious
Paloalto generic.ml
Cynet Malicious (score: 100)
Kaspersky Trojan.Win32.Tasker.ayxi
Alibaba Trojan:Win32/Tasker.18ce9e8f
NANO-Antivirus Clean
ViRobot Clean
Rising Trojan.Kryptik!8.8 (TFE:5:o8wrBs1QCtE)
Sophos Generic ML PUA (PUA)
F-Secure Clean
Baidu Clean
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition BehavesLike.Win32.Injector.vc
Trapmine malicious.high.ml.score
CMC Clean
Emsisoft Gen:Variant.Lazy.266138 (B)
Ikarus Clean
GData Gen:Variant.Lazy.266138
Jiangmin Clean
Webroot Clean
Avira HEUR/AGEN.1253288
MAX malware (ai score=84)
Antiy-AVL Trojan/Win32.Kryptik
Kingsoft Clean
Gridinsoft Trojan.Heur!.02290021
Xcitium Clean
Arcabit Trojan.Lazy.D40F9A
SUPERAntiSpyware Clean
ZoneAlarm Clean
Microsoft Trojan:Win32/Sabsik.FL.B!ml
Google Clean
AhnLab-V3 Trojan/Win.ClipBanker.R528972
Acronis suspicious
McAfee Artemis!34E8A1E9B59E
TACHYON Clean
VBA32 BScope.TrojanPSW.Coins
Cylance Unsafe
Panda Clean
Zoner Clean
TrendMicro-HouseCall TROJ_GEN.R002H0CBI23
Tencent Win32.Trojan.Tasker.Kqil
Yandex Clean
SentinelOne Static AI - Malicious PE
MaxSecure Clean
Fortinet W32/Kryptik.FXIU!tr
AVG Win32:Evo-gen [Trj]
Cybereason malicious.c5d11f
Avast Win32:Evo-gen [Trj]
No IRMA results available.