Static | ZeroBOX

PE Compile Time

2023-02-14 17:59:15

PE Imphash

3ce373431b23a98306ac88d16ec3e778

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x00177ca1 0x00000000 0.0
.rdata 0x00179000 0x0002903e 0x00000000 0.0
.data 0x001a3000 0x0000a420 0x00000000 0.0
.vmp#@@4 0x001ae000 0x0048c4b3 0x00000000 0.0
.vmp#@@4 0x0063b000 0x0063f490 0x0063f600 7.96226112752
.reloc 0x00c7b000 0x00000568 0x00000600 4.10484728817
.rsrc 0x00c7c000 0x00000976 0x00000a00 4.8331134311

Resources

Name Offset Size Language Sub-language File type
RT_VERSION 0x00c7c0a0 0x000002f8 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_MANIFEST 0x00c7c398 0x000005de LANG_ENGLISH SUBLANG_ENGLISH_US XML 1.0 document, ASCII text

Imports

Library KERNEL32.dll:
0xebd000 FreeResource
0xebd008 MultiByteToWideChar
0xebd00c Sleep
0xebd010 GetTempPathA
0xebd014 GetModuleHandleExA
0xebd01c CopyFileA
0xebd020 GetLastError
0xebd024 GetFileAttributesA
0xebd02c CreateFileA
0xebd030 LoadLibraryA
0xebd034 GetVersionExA
0xebd038 LockResource
0xebd03c DeleteFileA
0xebd040 Process32Next
0xebd044 CloseHandle
0xebd048 GetSystemInfo
0xebd04c CreateThread
0xebd054 LoadResource
0xebd058 SetFileAttributesA
0xebd05c GetLocalTime
0xebd060 GetProcAddress
0xebd064 LocalFree
0xebd068 RemoveDirectoryA
0xebd06c GetCurrentProcessId
0xebd074 FreeLibrary
0xebd078 WideCharToMultiByte
0xebd07c CreateDirectoryA
0xebd080 GetSystemTime
0xebd088 IsWow64Process
0xebd08c GetComputerNameA
0xebd090 lstrcatA
0xebd094 lstrcpyA
0xebd098 HeapFree
0xebd09c HeapAlloc
0xebd0a0 lstrcpynA
0xebd0a4 GetProcessHeap
0xebd0a8 ReadFile
0xebd0ac SetFilePointer
0xebd0b0 CreateFileW
0xebd0b4 GetLocaleInfoA
0xebd0bc FindClose
0xebd0c4 GetFullPathNameW
0xebd0c8 GetDiskFreeSpaceW
0xebd0cc OutputDebugStringA
0xebd0d0 LockFile
0xebd0dc GetFullPathNameA
0xebd0e0 SetEndOfFile
0xebd0e4 UnlockFileEx
0xebd0e8 GetTempPathW
0xebd0ec CreateMutexW
0xebd0f0 GetFileAttributesW
0xebd0f4 UnmapViewOfFile
0xebd0f8 HeapValidate
0xebd0fc HeapSize
0xebd100 FormatMessageW
0xebd104 GetDiskFreeSpaceA
0xebd10c OutputDebugStringW
0xebd110 FlushViewOfFile
0xebd118 DeleteFileW
0xebd11c HeapReAlloc
0xebd120 LoadLibraryW
0xebd124 HeapCompact
0xebd128 HeapDestroy
0xebd12c UnlockFile
0xebd130 LockFileEx
0xebd134 GetFileSize
0xebd144 FormatMessageA
0xebd148 CreateFileMappingW
0xebd14c MapViewOfFile
0xebd154 GetTickCount
0xebd158 FlushFileBuffers
0xebd15c WriteConsoleW
0xebd16c GetCommandLineW
0xebd170 GetCommandLineA
0xebd174 GetOEMCP
0xebd178 GetACP
0xebd17c IsValidCodePage
0xebd180 GetModuleFileNameA
0xebd184 SetStdHandle
0xebd188 GetModuleHandleA
0xebd18c GetCurrentThreadId
0xebd190 LocalAlloc
0xebd194 WaitForSingleObject
0xebd198 AreFileApisANSI
0xebd1a0 lstrlenA
0xebd1a4 FindResourceA
0xebd1a8 FindNextFileA
0xebd1b0 TerminateProcess
0xebd1b4 WriteFile
0xebd1b8 GetCurrentProcess
0xebd1bc FindFirstFileA
0xebd1c0 Process32First
0xebd1c4 EnumSystemLocalesW
0xebd1c8 GetUserDefaultLCID
0xebd1cc IsValidLocale
0xebd1d4 SizeofResource
0xebd1d8 HeapCreate
0xebd1dc GetLocaleInfoW
0xebd1e0 LCMapStringW
0xebd1e4 CompareStringW
0xebd1e8 GetFileSizeEx
0xebd1ec GetConsoleOutputCP
0xebd1f0 ReadConsoleW
0xebd1f4 GetConsoleMode
0xebd1f8 GetStdHandle
0xebd1fc GetModuleFileNameW
0xebd204 ExitThread
0xebd208 GetModuleHandleExW
0xebd20c FindFirstFileExW
0xebd210 FindNextFileW
0xebd218 SetFilePointerEx
0xebd220 LCMapStringEx
0xebd228 EncodePointer
0xebd22c DecodePointer
0xebd230 CompareStringEx
0xebd234 GetCPInfo
0xebd238 GetStringTypeW
0xebd240 SetEvent
0xebd244 ResetEvent
0xebd248 CreateEventW
0xebd24c GetModuleHandleW
0xebd254 IsDebuggerPresent
0xebd260 GetStartupInfoW
0xebd264 InitializeSListHead
0xebd268 RtlUnwind
0xebd26c RaiseException
0xebd270 SetLastError
0xebd274 TlsAlloc
0xebd278 TlsGetValue
0xebd27c TlsSetValue
0xebd280 TlsFree
0xebd284 LoadLibraryExW
0xebd288 GetFileType
0xebd28c ExitProcess
Library USER32.dll:
0xebd294 GetDesktopWindow
0xebd298 wsprintfA
0xebd29c GetSystemMetrics
0xebd2a0 GetDC
0xebd2a4 GetWindowRect
0xebd2a8 EnumDisplayDevicesA
0xebd2ac CharNextA
0xebd2b0 ReleaseDC
Library GDI32.dll:
0xebd2c0 SelectObject
0xebd2c4 CreateCompatibleDC
0xebd2c8 DeleteObject
0xebd2cc BitBlt
Library ADVAPI32.dll:
0xebd2d4 SystemFunction036
0xebd2d8 RegOpenKeyExA
0xebd2dc GetUserNameA
0xebd2e0 CredFree
0xebd2e4 RegCloseKey
0xebd2ec RegQueryValueExA
0xebd2f0 CredEnumerateA
0xebd2f4 RegEnumKeyExA
Library SHELL32.dll:
0xebd2fc SHGetFolderPathA
0xebd300 ShellExecuteA
Library CRYPT32.dll:
0xebd308 CryptUnprotectData
Library gdiplus.dll:
0xebd318 GdipFree
0xebd31c GdipDisposeImage
0xebd324 GdipAlloc
0xebd328 GdipCloneImage
0xebd330 GdiplusShutdown
0xebd334 GdiplusStartup
0xebd338 GdipSaveImageToFile
Library SETUPAPI.dll:
Library WTSAPI32.dll:
0xebd354 WTSSendMessageW
Library KERNEL32.dll:
0xebd35c VirtualQuery
0xebd364 GetModuleHandleA
0xebd368 CreateEventA
0xebd36c GetModuleFileNameW
0xebd370 LoadLibraryA
0xebd374 TerminateProcess
0xebd378 GetCurrentProcess
0xebd380 Thread32First
0xebd384 GetCurrentProcessId
0xebd388 GetCurrentThreadId
0xebd38c OpenThread
0xebd390 Thread32Next
0xebd394 CloseHandle
0xebd398 SuspendThread
0xebd39c ResumeThread
0xebd3a0 WriteProcessMemory
0xebd3a4 GetSystemInfo
0xebd3a8 VirtualAlloc
0xebd3ac VirtualProtect
0xebd3b0 VirtualFree
0xebd3bc GetCurrentThread
0xebd3c4 Sleep
0xebd3c8 FreeLibrary
0xebd3cc GetTickCount
0xebd3d8 GlobalFree
0xebd3dc LocalAlloc
0xebd3e0 LocalFree
0xebd3e4 GetProcAddress
0xebd3e8 ExitProcess
0xebd3fc GetModuleHandleW
0xebd400 LoadResource
0xebd404 MultiByteToWideChar
0xebd408 FindResourceExW
0xebd40c FindResourceExA
0xebd410 WideCharToMultiByte
0xebd414 GetThreadLocale
0xebd418 GetUserDefaultLCID
0xebd420 EnumResourceNamesA
0xebd424 EnumResourceNamesW
0xebd430 EnumResourceTypesA
0xebd434 EnumResourceTypesW
0xebd438 CreateFileW
0xebd43c LoadLibraryW
0xebd440 GetLastError
0xebd444 FlushFileBuffers
0xebd448 CreateFileA
0xebd44c WriteConsoleW
0xebd450 GetConsoleOutputCP
0xebd454 WriteConsoleA
0xebd458 GetCommandLineA
0xebd45c RaiseException
0xebd460 RtlUnwind
0xebd464 HeapFree
0xebd468 GetCPInfo
0xebd474 GetACP
0xebd478 GetOEMCP
0xebd47c IsValidCodePage
0xebd480 TlsGetValue
0xebd484 TlsAlloc
0xebd488 TlsSetValue
0xebd48c TlsFree
0xebd490 SetLastError
0xebd49c IsDebuggerPresent
0xebd4a0 HeapAlloc
0xebd4a4 LCMapStringA
0xebd4a8 LCMapStringW
0xebd4ac SetHandleCount
0xebd4b0 GetStdHandle
0xebd4b4 GetFileType
0xebd4b8 GetStartupInfoA
0xebd4bc GetModuleFileNameA
0xebd4d0 HeapCreate
0xebd4d4 HeapDestroy
0xebd4dc HeapReAlloc
0xebd4e0 GetStringTypeA
0xebd4e4 GetStringTypeW
0xebd4e8 GetLocaleInfoA
0xebd4ec HeapSize
0xebd4f0 WriteFile
0xebd4f4 SetFilePointer
0xebd4f8 GetConsoleCP
0xebd4fc GetConsoleMode
0xebd504 SetStdHandle
Library USER32.dll:
0xebd514 CharUpperBuffW
0xebd518 MessageBoxW
Library KERNEL32.dll:
0xebd520 LocalAlloc
0xebd524 LocalFree
0xebd528 GetModuleFileNameW
0xebd538 Sleep
0xebd53c ExitProcess
0xebd540 FreeLibrary
0xebd544 LoadLibraryA
0xebd548 GetModuleHandleA
0xebd54c GetProcAddress
Library USER32.dll:

!This program cannot be run in DOS mode.
`.rdata
@.data
.vmp#@@4
`.vmp#@@4
`.reloc
@.rsrc
V;T dw
h]I;j?!sM;)m`[,]S:A[
'GoD){
;peoHk
gG5]lqRf
%Af|4B
)sgR'}
g4JrQo=
' $dnl
$)U%h$
s7JHdK4
!y5$(Ml
ExitProcess
FileTimeToSystemTime
LockFile
50nu>JM
QJRR!s9
$`= B$
4Jy2o=
h$- 1U$r+q#
51kR<J
e/z}EZ
iRG/J5
$);<$
Y\x}_X
rEjd+t
,N}N%W
+?N,Q@
%JhM=:.
;<R9w,
2a`AReD
$Sc/$,
y3J#+A0
L$2#T:
'dqp['
'KI^:'=
8Y%'fA
"sj3Y'
EC#'qF
[h1+f;
GetUserNameA
}qRwJB?V=
I,#'uh-
kz#w:s
7{78fr
\'tw@|
1]^_*J
\N/$!A
A]A_fD
WriteConsoleW
GetLocaleInfoW
VD1,$f
64-JCE/
,\9$A9
o.KBg7
SetFilePointerEx
|/i+J4<[
>6pa/k
5+mj:J6Y:
(k:J#|;
<M/?J3
-s>JJQ#
3}M9J*
VD1<$H
CloseHandle
GetProcAddress
v5JL"m
4rJ,DKy
~0WOJ6
$Y.|>$=
CryptUnprotectData
LoadLibraryA
S!wMK5/
0'Ugpoc
1z6+$7
\h&$%e
Process32Next
A-JcqZ
Ry<1st
9%{\3}
q1@$ 8
-0Tk|9
L\H%|[?
]\j Z+
z0QTJ7&
/`0/JOK
g2JJ9'
{<?/%5 *
Ky{x5e
EuJ$Gf5<
5J,$76
RTZl@:
'mx!]'
`j0JUkH6Z
x`QJ_V
4Ug$4B
}$q,]@$
>f=u6f;
%2nxBe+
o+S8F
D1,$^Mc
gG5]lqRf;
b>Tu37
>?@:o6
_S\toT+
RH;3U?
WTSAPI32.dll
`D7$MU
jLi3'x
\(ndl/
=Dr*lM
aEfe0L
G@3fwGD
A')+FP
_uGb#7W~&
H-PK+U
N^adpd
[b$11>
TD1<$^A
m7_.x?
cApheaj
EnumResourceTypesW
T$Jrt=
lwJ, 3D
FreeResource
$EAMj$r
p$QEM$cj
A4JI]y7
$E/t-$7
e.=~Py
yb7sf;
Fhs%JE
P8k0Jm
f":JL4
$'?-$J2z
zh1[|V
$"s`B$
5:A,T$
D$MWt#:
yIEV(@
rHT&BO#
GetSystemInfo
.IZ.J.
x)Q1yz
TR(IK>
%t4=;A
yBYh$o
FreeEnvironmentStringsW
>TECc|
SA; \x(U
"HMwc6
oH5ck!
D1<$^fA
c4[~\P
x^HrYE
Nt7'}
GetUserDefaultLCID
AreFileApisANSI
;J9Yn=
PJLD9@
$/70V$^
${g.$G
Q??$|dz
1JOtp=
SY;J,?
3t"J8mX
svG>~[
$$70|$~
fA9Je"
4gE-$*b
bi{$xB&=
6+M@J,
#P(J<(b
"F;J)v
M<Jm{g=
.LqF5MG
*1nKf;
$\$`G$
7\\(JW
PQ3$M}
MapViewOfFile
%l#N}i
[n$]=>
*T,uU.d`Kukn
!UuWkR
SetThreadAffinityMask
*"f,Ag
`sm}sh
-56nJ~
@m%+XS
$miUx$Y
0J<|#3
aB@!)6
:II'V_
:eg$lO
a!,>JD
J`P$T9
/D:.J[O
5}#U'Jx
h["cH*o
]D1<$fA
lO~+s-
*=2J{a&
^$/^\(
5"/wH$
$TJ>0$
wlvS$B
o4).J3
&sr$xu
$.mzi$
LoadLibraryA
$dHvk$
(~L$j+>:
+s@5JBx[
`k+)J|p
cX@n$5
$7ln1Vu
f@a#^f
B,:4e)
ut$KP*
{V4p4v
v?^,qH
msob]t
k{61JB`-
k+\7JFHG
$5Ft<$OG
fbR$DU"$
Jp&J%F
,$c0UZ
'3JW=<
$;=f>$
_e\.LM
CcEcG#H
JsLc[3]
c%c,c4c;
:C\cxc
N#[#bcuc
C"c1cC
hcncyc
cc*c8cBcMcac}c
c!c'c2
cSd3lctczc
c*c0c;cAcGcTclcw
#s8cYcgCjcmcsc
&3'S.#0
c&c.cFcsc
c%c,S<C
c&c[ch
S"c;c_
c#c1cIc`ck
c'c,cLcQc
c5cXcc
c%c-c=3Uc|
EcWc\cg
GcLccc
c#c3cBcMcXcoct
c%c1c9csc{c
>s?cac
c&c<ckcrc
c8cCcN
ECEsFCHCJCLCNCP3QcR
3EsI#P
f#kcksm
n#oco#pcpSq
q#rcrSs
s=sEsMsU
$c+s.S>
7s7sqc
+s6#8c9#D
$c$#%s%
6c7S=3>
R3V#Wc[
N#OsOSP3Q
sCv#xcyc{
c!c$s)
e3rSwcz
7S7c9c:s<
6c=cEcNcPcQ
nSoSpcqSuC{
D#ECFcG
TSY3]c^
VCaShsncv
1s<S>#B
WSX#Z#[
S)CJs_
LSPS]c_
oswc~c
%sSSWCc
1s_ScCo
C C(C0C8C@CH
JcJCKcQ3S
gSkSlSm
8#9C;3=
c!s&s(S1
-#.c1CH
RCS#v3wCx#}3~C
>CECGCISL
'c(s)c+c,
# c!3#S$
3"s$C'S
*S:3RC_
EcFsTCX
S##2s334
s!S$31
%c1#T3l3t
"C)S,3-#0
#3S>C@
YS[clCm#t
C C"C$
eCf3i#j
=3?3A3C
dCg3i3j
G3IsKsMsO
yc|s~s
mCoCpCq
C"C#C$C%C&
ICICJCK
KCMCNCOCPCQ
xCzC|C~
NcO3PsQ
qsv3{#
-32S3S8
:#>3?#D
:c;c?3@
O#PcQsS
vcx3z#~
#s)#*c*
ICJCLCN
5Aa8J
usaaNY
$kCgm$
5J^ h=
GetCommandLineA
VD1<$^fA
q%JnW2
f1Jke}
(p:J+l
$[so+$
FlushFileBuffers
fjT)7c
:k@fkb
mkEY]l2
wz|ubc
!eVfA+
;~<JNM
&=itIEM
m/"D](U
!GzypN
}Fn6,O
@+f7p,
[C;5kDL
B/z7EX
D&+^t!\
i"o-Y%
yK#_(B
rJ2/BME
_Nv\oI
7sJ7JR
$i{:#$
|w/s$Y
2x$A9W
x:og3:
|3;'7J
]XV)J7
E\>$xx
/a*P~h
s`>"i
xa/oHfX
VD1,$^
L69J78f
$W+6j$
5ob"1J
+q$Z"N
%/'Cj%
n{%Q\&
=3.Jh:
~Qx615
o =@J-
IZ6$Td
|eN;As
$h2|"$
e.JwT>
"4JZ`k
D-u$Z7
tb)$}#b?)sc,
56d>7Js
$?P1l$p6
feBjHy
T|}6f;
\I58>[
HBhi@I-)9
SetupDiEnumDeviceInterfaces
WideCharToMultiByte
*e$ZZO
HeapAlloc
l#J/m;
yKppQ0
$zm/v$
WriteProcessMemory
5pg1RJ
dE$z\J
ZE"x$4(g
(J?}n=
A5+(oMQK
<f,_Tm}
|0T2Je
$N2vt$
50RZ;J%
Z$7&_,
#v$NuF
4*uN:JN
5<rt7J
y<JdDc=
$9L.<$]
0Jb6c=
Jz2e$G
>6Jek%
[l$xP>
bYY$0i
GetCurrentProcessId
GetTempPathW
SetProcessAffinityMask
y(OR/2
Qz&8Yh
a:]tp
pY*Jgkk
4)Jr%"
n$NYd=
IJ*m=
n^$_eL
x6J#W@5
Thread32First
gu~s/1
^wT{np#
v@42q7
7]kWEP<m
Da;)IA
L>lWE3Kj
{8mcf;
RtlUnwind
};JW -
m>[,JM
$JUJ'3
<!.JIO:
LCMapStringEx
GetOEMCP
7{X.J2@C
}$,2`=
6VeY*J
g24?D[
$h{YP$Rj
5@cY>o
*a$Y!O
LCMapStringW
$Y=Pv$>
r$G9Pq$
Pp$%u5
r<,J]Y
GpBvBf
RaiseException
tJ\B K
qb$"1b
TlsFree
VD1<$H
@&fr!2*}d
u.Jl~n
Kc%J$G3
>vg{$8-
A]A_fD
D'/,J$$
FEZ${{
0/9JO\
$J8yI$0
,9Jar|
st.$^F1
'NhUvG
k&0h[!G
K=V1LJ
pNmj@I
$_(|$q
t#++J80
Z#$O!O
$#Lz1>
b@Z.f;
$hljn$<2
-0:a$vM_
GBV4QL
zv80P]
GetStdHandle
-=aDyf=
;~:5H"
bJ6IO=
uu$3Ac4
~$2GRC$6
-q8W:f
$F:]w$
3gxcA2
9?$\h6
uW|aEP
R,]4U[
:q_/=
n?!c^8V
2E!/F-;
:;7D$X
']t6_'
1nf2$O
}}^/Mz)
m[pi"*B
D1<$^f
,8rC<Z
\7JCSd4
Z{J$l!=
$bX{:$
SetEvent
l7J6JT4
GetProcAddress
V?R=YUJ.\
D> <W*
'V1<$@
GdipGetImageEncodersSize
jwYB;~
avH2Qq?
(?M&z$
yb$&!s=
XEY%q$:
Q-V$sbm
-J(edf
GetModuleFileNameW
CredFree
FH}z$>-
$i+.4$
5Kflo$
lBEn[Y]^
!"u#J%
jkWJ).4=
^Cw`VfD
D1<$^Mc
VD1,$@
EnumResourceNamesW
CreateFileA
et'oky
SetupDiGetDeviceInterfaceDetailA
`T(CPS_
,<p~}5
p=d1!4
MPl0}W
V812f?F
9%}:>R
{<uAK;
DeleteCriticalSection
+mnKp)
D1<$fA
o^3'.H:
zCFMdi
ai]!JD
'K*Jp;
%'|#J)v
Xq$/ao=
O:{$o)
$i_R6r
E%q`$h
?oh3ort
C7:wdLOW!
,6}jxP
N@TXP-
=.tS([
8oh_+ut
CryptStringToBinaryA
z{~J1>~0$
9i-J>1t=
7+$Nl/=
K}$f~.
MWylf;
LoadLibraryW
5?a=6J
$Jxz@u$V `=
k~|$58
8b$9i]
zJ'j5X
4)DJYo=
+'6J\ww
$D$U]$
hri*J)
?J)@l=
H9J^,S
5X!M/$
04J S`
$SXm'$qI
GetComputerNameA
L^grQv7
crHO]~D@
$"<Jm9
qZL'W8
iE~!+m&
)'IG<l8
&+T !\
-K#U|B
a#{hQ$
zK&jJLQ
$l8bh$
t0-$}u
SetFilePointer
GetDiskFreeSpaceW
l\@ \[7
Z0YQj7.
SystemTimeToFileTime
+D1,$^
^Cw`V@
'D1<$f
P|M@`{:
cUhPg+
'I#x"'
GetTickCount
SetEnvironmentVariableW
^5~Cn2
N\21U
cXvB2Q
s1:0C6M
hYg2X^
E]#AuZT
GetCurrentProcess
qWFY ^
L:NX|=9
zVW)JQ
5v+AJS
$I>rc$}
5;em7J
;xw$;Vh=
5c=)3Jz
Tv$aQ1
#h9Jd8
'hP/v{I;
nw\/3='
V' L7XTRq=
Lz9Jh*
v}J"J.
15c'`<
m4wh<=
K1"k{6U
06$'7A
%>wUTf
h7'wX0P
Z*I2]]
/^n:Y
s_zuCX
D1,$^Mc
gxI$Jk[{
2EL$JZN~
`$zT~=
5i2ANd
vJ+Q }dS
Kid!?U
$kw@y$
&J>JKEQ
-N^<$
5=wX5Jd
v$jlIK$nO
1<$^Hc
\}eGja
*B}?<ITyB
oD*Vz
F6DJ88
:IZ$H!
$":_4$s
[(l$Jk
l>Jq=T=
t$](fI$i
-8#zJ+{
0dJ<E:=
$o5s#$
nXxLTh
$]~X:$
$EbLa$
{$O"DF$
<Jv6-?
GetModuleHandleA
T+"SL<
nnZovf
4-cJPb:
v$t1VK$
|Jm1$T
_$`EIb$'V
!xbBHa
GetModuleHandleW
Ek0J,XN
s$QyE
D3Jdk
GetFinalPathNameByHandleW
p>/q0t
/}},NY
e"<"*-{
"kU{eq
RqujIb
_tEXf;
8&*>m
1<.g]O
DecodePointer
kd!JVh
g$`=[Z$<
]C9J`^X
A:I4$g7
5C h=$N
K:wu;w
e`%\,
u[iJQxJ
>*>W?vJ
9Jt47:
'>J$11^
m6c%JI
k+g=JFH|
I~cA(K
vf=JOm}
XWaIB$
SP$KS6
hx.)JY
#&.$N6c
NZ;Of;
u=JNPn
mc6J>I3
BXw!-A
O*$+.,|
i=JTDQ>
n~(-q.>
$jP\\$
\=J*fd>
N*"9JOy9
_|tPW@
D$et[2
54bW6J
%~"$<,
$aU`k$F
D1<$^fA
SETUPAPI.dll
GetProcessWindowStation
R/5$c
q:U 'f"
>zedRR
aah|,,z
5*zV-@;
w$8>VJ$L%
5Jk!.
0h$8pU
mCkVRL<
'zxXwCwr
GetModuleHandleA
GetLocaleInfoA
h$ 8E
K?J,ts<
GetTempPathA
GetFileAttributesExW
O/0J,K
Zr4J!."
k"e lU
Lj6*|mA
anrYQi
OO1<$A2
?rSxn{
csG72z
hrVGXu!
(gYte*
XE7(@>
!'vBj(
BuaV]L
|=DV-h
j.Qn(L
8cx6%;T~
?JZ.,<
$Jq5-$
^=Z\n:-
cPR]2Y
hQC-XV4
GetLocaleInfoA
LCMapStringA
fOu?b%
$(0 -$
WGE;J~\^
\8wc.Rm0cy
X,uhcg
n~\XIHJa
qEJGB4
@Qq6G&
ZAE>jF2
;-Ypj$
g,M?6%
l-\O\*+
~>++ Q
`u0DTA
Gp,AN-
CjaovB
|&CVfA
ntiN^s
q9r/vN
Cp-=swZ
"]hRej
VD1,$^Mc
hG3-J(edf
1A]A_@
\Fc4{
eK%tO|
yJKO,F
odjOmw
gG5]lqR
QueryPerformanceCounter
%8KqBy
u5*zV-
+doCt|
GetEnvironmentStringsW
GlobalMemoryStatusEx
GetConsoleMode
E345qSI5l
Cb=$>^'
$ee<0$
>Jg#8=
!9WBC=z/;=7
VirtualAlloc
I%$ZbY
a1Jk\n=
z_"WJXU
67zjg>
j6n%;?
W[f$g\
L3;&|4L
2/i 5X
"$Ji3=
vSCQ$b6
5?+(7K
,t|>Jm
S.JQeV`$u
6`u%he
9IE>J<:^
rqJO)\=
fW9/${
,A>JEWZ
$-}sT$
OdD"fA
Process32First
D1,$^Mc
GetSystemTimeAsFileTime
Cu(kEk
YTq$ycl=
(P5J#|
0oy$nc
;(PfD;
>Jo$r=
@\L<JM
B<J`nY
sT7J4O
80h$8N
r$=`8O$
j9[?Vf
kno+[i
Fj+Xvm\
LocalFree
P-!KJ"C[W
}$6[k@$)@+6
h%@$YiJ=
Yh5J6U8
0g" JLT
6R["Jq@
gfDmO1
84Xk2
C+@>BLqP
n@W9i7
WaitForSingleObjectEx
&A3Gv1T
|fN$XKn=
Xj3$um/
.|:JOEg
?/4!x>T5
$wxFV$;
D1<$fD
rD1<$^
GK$suz~~
=NU^$`%
PSPM$nn
$4'>'$~
 n$/q
CharNextA
y57<N$
$TxT|?
$<$q2$
$[|o{$
a$bTg\$
A]J:J@
(0J f8
`]g1f*
f=6Rf;
[n&g3J
JVD1,$@
-d8P|m
qe, l
zd=oJcJ
z#aLJ$
6K9qgB
jJ->;C
&1p;!F
W'%?g R
LOx=|H
aK<NQLK
UIn$K&
]u$ZAn
0x$!YU
GetConsoleOutputCP
$L(<_$
5PSo.E'1n
if=H3
InterlockedDecrement
u\gf;
|$X7c=
J\XF<e2
5o5}0JBi-
GetProcessHeap
$>X9B$
RaiseException
V1,$D:
W{4J,#+
0l?JUcw
Vz4J-"*
GetProcessAffinityMask
|1,$A*
3JP6L6
[VcJ2b
zJY1#:
$Ur@z$
`$DjH]$
e$kf$X$$ed.
w!+K:=
GetUserObjectInformationW
SetUnhandledExceptionFilter
L^JF\i
$;JC)?
6JM%U2
}$B/^@$.
A_AXAZfE;
&7;JCu,
7*$#|
kJG,fm
5=k\4J0_
$er:e$
L?J@&W
kZ4Jd'
HeapFree
w;JK;O8
%Ju0v=
#8$BVj
10JQ*a
~$r7kC$E,+5
f1Jgi}
TlsGetValue
Q254Jeq#
C;J~j{8
C$V[v=
S}$3Hz=
KU!l$4
B9<a$d4y
$oGbl$
3=JG](
Q;JJ^i8
=&]6*47
4g7J%#
UDP$gn
|8#=JQC8
hd'f3i
EidxSQ
GetModuleHandleExA
LoadLibraryW
D1<$^@
&$}4_e$
'=J-I>
.; s#?$N
+`%x(N
jj|Gf;
~PaLJQ6
L\04&K
a$V`B\$1
$c8o9$
$7pqp$
&/8K_N
}S aoY
FindResourceA
PT#FJ-
z-e$yrH
54~02J
=J}m<>
c}%JRhf
k.JzQ;
=J|$3>
$&,S*$
yp6(y
%q"Ptx
rq'oBvP
QGw`$!*
L%#Jkw
eha$Lt
hv.J7D&
1J?WN5J
!VZK/=U
AI|wWr
SZ*U3@
hL$CfP#
_T-.nY
{'8J:P<
g'z([$
FindNextFileA
$LQ<JU
G(8Jj
y>3J*]n
$?MB0$
J%9JH;
3Mh5s=/
5g5_7J>a
3t$NM$
U#zv$uV
$r`)8$
O<<h$bo
$D$f"$
Hf= df
8<GZV%4#7G
/4zv5GcZu
!spRE~
'z} ?'
;+iL5q
Bw^b,h
jQhUb"
3qiZhH
(1 iPS
$z$tDA
V6JecM
LocalFree
DeleteObject
GetFileSize
^,$Ju7
5*p:/J#Tj
(fCD9+
%f=\13
X2F/_E
"5:Gs<
n]bz^Z
u5?xE2H
iJZDf)
k$F7E`$
k4S@uX
EO%JbV
Np9%$^Pm?
K(R&JS
,$tLk?
C#3w$=P
!"M JU
<HN8Ja
CRYPT32.dll
O<J)Uw?
S$Jwq_
$CTyl$
CreateThread
[hi-Qe
mAI5j6
pi,&f;
b3&$C%m
Ow6Jz^&
GetModuleFileNameW
`pJJZ+
$',W $
P)#C $
$r.h{_
_x7*^h3
5\qlv$
/JJ6kN
0J>J/4J
F8JVz~;
R$?P]
GetCPInfo
SetProcessAffinityMask
FreeLibrary
(p9$J!;"
$_e}@$m
$%k}1$'
27z$\y
W#C=4<
tS% Xg
"4)t$bAL
'kR6J6
i\D#Y[3
_0]Ro7*
s/$J*(4
XxN$%E=
W$\~2
m6[&J)=i
6/Jbyf
9jM${:*;
{y5 ;}p
${%?|.
KF\e{A+
GH*'@?
$)BLv$KC
]WI<T]w
*A_AXA
A\_AY@
c#p<Jf0k
bNr<JsMi
zr$r\A
$<I5%~
/g"Lv<
<JS[8?
Twy9V@
K/|$J2
%Mgv.U<
Qe/J"55
Cn[}$H#>
InitializeCriticalSection
GetSystemTime
GetFileAttributesA
GetFullPathNameA
_:JDia=
i%!J~r
ddv-Fa
`,,9J=
%/=m}x
$f<SV$4
Z.*"Jw
!2JE>q
>um=$+
\`<)Qa
l:mPE7
Y$F%I4!b
$##M%$:*
$gSSl$p
r!#'JN
G!)$^N
D1<$^Mc
IsDebuggerPresent
yJP%<
tsse+{[SO
s97Jn:j=
CopyFileA
EnumDisplayDevicesA
*(>"-_
N+<q~,K
/G ?~N
sF4p"O
UCaseD
LeaveCriticalSection
mMvG<D
}$:5M#M
P ~F`'
KH#D{OT
fLg7VK
SetLastError
Xh|<r&$J8N ;
FindResourceExA
o?Q*_8&
YSH[iT?
ExitProcess
`Yzpdk
7](p,@R
<RhBUt
,k S$Z
yd%Yy-
^Cw`VD1<$f
EnumResourceTypesA
4%81}X
kex$].
FormatMessageA
J/~&>`:5@
Nf8$(#
~.)?$'/
l$0V?Q$
*J`Dr=
Jtf4L5w
+7H9J^LS
d,9Z(-
(r`?p(P(
rBR4us
.j)(uHl
$0XuUt&
msYJRT@
|pqyGj
2n3}0Y
=fxK60
AR1pB,
CxBj@|e
`]^9xo
WJp^"4
{1T^@#YY
2t'l\}
Es`M.$
$E{7k1_
|SknV'
*'-o?H
V3WrdF
hqX;Tl
_u,^5O
j#92Pp
s/`dYK
s<DH&`n
^j,a_
gj0sLbvwQ
'8e7$[
8;p[q|
<S B,-&`X
#?/U@
(Il=Od
,bA#.t
nGvsE66
GE!c_U
kPA*(C
!Tp0!&=
cdQBZ0)
0Ziid4
.y?Gv\\
ec=yeF3
i~Q<?!O
Zi|8`oG
g+}^i!
cno=$)_
xj*>fL
,<2x5k
#eC7I'J
0dQp&PDV
tnv))!s
RHSrxR
*[@q!.lF
o;I_|.
d<L|z,
'4w3JU
_Ly. j
bAq4uR
wOi$M`
#=(vnl Zs
*tFt~~
BlI".r!Pu_y
6hp@,/
LRV>X[
@Q,|n'
W?8\j6
}_T!B+
>h([6'
ZY{0_f?
L+rG15{6
h9[e?h
X~g_y8
(P[{K%
~[mm<i
i|X9"C3
Wl]2|V.gE
awO$~?
vvs8lq
?|96Ld
OYiwuW
C,dV$/
c(&g2i
k_-.o!
!G$J%Z
B&8(:0
w;]VWz
:uI#oZ
3bH }&
$P:!o
9n(4\OJ
"!ESd-1
+^_TQ2c
IGd9py;w
')=/;
jV^?wW\
3PK!2w
4[JM/`{o
R]"X`^v
sqGdxp62
jQ:Jf=
0?TQ[v(
?p[U\d
QA{{'9
d8zW|N
pNKHRe
)c.%$$
6!N{t:
#@Y&M~PNz
0@O}La
H~1Jvi
wAM$Q 7
C(GFfF
<>Uf5p!
cn@V4"
JfMMY`
MQ4G[<
$:e[[i
ufv~&%
v|3fef
[$d}zw
Y"}lHeowz4
!dc|B|A
C&>zb3
*2Eqi/
uqe=h8
,ivb0d
U(y3P@
s3\HX[
1P'8DD
fs.dhp
+-MQ!nS
_D88O<zYG.
K yF;>
R|YmB:
RLP'U0J
c,\`2D
K\9nF@ip
}a&KWd1
h[r~m#
O4Fe_6
-!6%iY
!dU_QM
q / RP
)WK)ga
}Nwrx8
RNzb3r
bt2Xhp
dBIMFtn
-tc/0<
{/',]\
!}dKUo
kxu#L:'S|
7 |w9T
eQ/#&#
y6R,Vg
s+Ou<)
0Ev@\ua
x{vfTR
`4kyP]Zx
PgOSe+
(IcKNa
~`35}]
*/,yrS/i
ZSZU;u
kw:}@3q
rCSMGb
*#nAab
uXh7:,T-
|4 <a
>XZR'B
.,s3\z
_b-N[i
E9l_WR
rDB~uv
#`$MMr
3#3_GD
N[~2eA
~sn5V6I
w>svH4
m/vFlS
?cZ-$_
>u3i"2
'g78lI
B1WWRm0
ejNGbj
aSH|ugU
JQKda.J
9S?r=8
Me=ep8r
%5[0E)
9CsAP"
SC-ZOy
0)d#R]
NpP\'9}
f -N`B
_j'u9JzE
J]8\sC
pBNJGP8
q_1`P"d
3_h=!
]zQ4;W
/jc^c"
(WrEEUY
xCNR i
,c(gZa
bA!<PeY:T
qxVqeJp
Ilk?PRJ
u^.qpZ
U^9.T.
:@DEP0
/cj'<O
&;a7Q}
^6j-.%
/P/~>Pv
kF_^h0S
o~!K>p
yqAq|Qf
ds5lD]
AUVG:j
/$v.x)
znN#iv
\Q@'A"
Ub.;s5
]9NoX#G
xcl\V/z
}R#i_
J$wWE+
0p`Ofu
nia-O6
E2=GZ@f%
O!Td1p
Q7ocs4
gX]l8r
glO{l!
?Oz3}w
ga>bW*iW^
7Zo]%50
mWYMI'
dM1{`X
pM*7WJu
8En_j2
L`m"Xv
yQ^dW]
ws[:\l
'z0huB
A-dw6`B
ua|Ne@
*>c*1*t
qQ0`ES
8f@gP>
`c7Smg
0K7,rH
*Oq%$@Bl
[$}+Pv8B
D-y-](
/NGv?&V
^n0#6qk
A>i0p6
dWM[Pv
U>kxo$l(0
tvywA$
iJr[!>>
!(8tnr
M_6O0
0\v Zy<
?@9:pY
g[I/S9
~JKwnB
veS83;
BEQ)8<2
gL/$Yz
.;z;J6(
5Z;%s~
"DCOadL
c.RFg$
Z)WUMO
/98MaZ
):][r{L
34<Z!7
p*1d"Gm7
V=v)'[
o\L<8b=X
$-XOMB
r-Sbg3)Y
jp^Q
B5IoYW
gtdRnU
ny7"=q
j7P5'?U
TN^A:l
n1>%0
M?iF($
b%V|TI
`{cXPD
.]n;EFC
~egG(Y
ZH:P@
<nJKL7
Z9x:'Y
8fnuTs
\rj^Zs$;
r_V2D{
@q-Dvb
>%xv+^Vz
T:m7g@
'(Az,n
RSqPWa
Jc]+WC.
TFHl)O
D>.~pV
RQjl<z{]mbe
hxy(.I
sq"l>L
GYzRIV
F~s|^e
LIZ--M
HgPKJ~Z
aQ{]Fl
gJA\K-[
6,V'qM}
m4Mi3<
_8EN?p"
,";n)j
=8vq$7
;$Y~_t
[=ePC~Zc
o<$??z
KJ [/<
7:iq=r
V{Rlt]
y:TxkCJo
K5|[!(
kg0teY
ahC1)(;
s7T7CK
n$PMnL
:3x*U
6<R=.fm
I\p.@cV
6gcfPY
)]%/`I
/qV<rR
EOcjr*
M;(7dN
ugiu!Y2
AnD;e<
2AE'?q<
GTFN#%)
k~n,7.A
J1-?'>
z1`;<Q@
8C&{tJ
b-%0zb
WTiN2q
l!Y]9_
W7)EeAwL
nd}?d[
nJ:>Ki
9>yN='n
Ncn1$\
x]2KzV
y-;F^W
vh`-Ix
(HZ+?FTS
k/V'xj
]9>Ck;B
-6'Zt0
|n@85?
Q[zZi}
)>Zhzww
NwXAXWw-
Ld;.w<cm
KrJ|,Y
\lS]s&_
VpV3'qQh;
bP!vi""/
;^A{")
dAo-qW
&B\A|(
$=60LCf
RXKfRx#
4>OPr3l
d*'df2
N?-U"6
v:(+_=
%kZX)z
pM[!]DA
c8sw`v(
t$l8fY
W4l5mZ
(rJrE@
>|W<_
_EP`/a
n.rA5C
u?MT)y
/(A Tf
(ELJn`T
m,0dniy
"l'@xEr
2Nw^YG[
wmg$gE
S,SY\x
UXsVsN
y>J;C-
k|o+2r
G%tFrz
WMyP\S
Z~y$kw
J~QMXd
?!Lk=X
]8`0$X
CFt~(z
XVw@`{
] Og]G
^,J>40
07Bs_E
?)$/u{y
icPvGcI"h
%vohC)
z^3!wO
dWqT-y@j`
FH)t>j
MP:EjX{
*9t[F
1.a)og
Ire!s}M
8rqDe<)H
]}y mb
(4GbqU
*4V/jI
&%UV]k
GiKt\`
C~^:}&ZE
0C`eos
uy?c./
UlqXK`)9
%nCqP"
gx*jG\
ein~49
@i YDH=
9B5cPL(
nM!xmg
@H6esH
W,]<Q8
Se/4^4S
>8Aw8l
m/'EF$
s.Tgi'
XJ#"^h
n|;9YX
a+S9M+
dQ}{ Z
AU_PTt
jR$crD
9?$Y4X
"~DM,*X_{vlK
C"/<Wt
3xd2JT1_~
BMS^v+A=g
yHe}yXLn
~s"4C@
8z#_$%
iTB)Bt7
+\Ya-]
v|*k[?+@
%K8:2y(<U[
8k>mrC
Bn?2|cb
!^c,VS
~D6NO9=
U:4hsD
;"_s+|U
t?^d{M
fBVY7-
"s>?qH
?l\,/K
(bY2)r
|u#ny-p[o
Fzk_U'
m<|9VKA
$k|Q!+
AcSt~F
z^,cDAi
(7`ZJ,
=/A>,:
jeQYj5-rO)d(
%Ls7>I
q2H~3'
3{*Nh
18rJyP
_gHl;Q
j8kU$(dq9
}Xx~$'
sbSR*t(
5 (9P9
S$OvKW
4;01]s
qbNA',!i)E
e!WdR^
,p#|5Y
:wzr&-
a78~W]
7#2rSL
H.[wF!
:$1/sR'
KSwpP[
DK*BQg
q&?h*o
O%bpR{7
$EKj)%
;&Jo4;
j[Y[j]
d*ZX3_
GQt+2M
k6'"wI`U
=CnOT?
;m+.!dt%
Rl9FOTL
'`)_7+
L1F7iMK
Vqz17$
'&wH?f
F~L7HD
3b<N`ih^
UP!|+P
R6(#]S
feguvn
pHQocQ
\@Wd*~
z)`$9;
G5}Kex
i$iAV?'b
V)dbH_
SAIy[{
,0Q@My
L69%+IMR3a
q1G'_RD
!{;L;L
#EEV9[f
/VP6;>
*HR{0oV
vT?_B5
.Ktf,+
5#yWQo
J%4W[R
uS?gx-}
]k\c~M
Z,ef/!
B}z-TA
*+n;52
.zhSY:
^oe#=*
2+SXxtr
8$fh;n
Wm`V7Y
=hR_J5
1Vu-(`
*@O.c#H
qB:dLB2
l+zL+GvD
| o@sntI3
Qqr{'C
vO:/Al
4 OSY=o=P=
[-Ypjl
4O]}Z2
romdp}I
#sedQq
c]hVlc
Uw4i/b~
]}7 jS
D~608~
\KHW3
]}N'V'
;8&h
tdLrn/
uKN;i2
_guk6sV
vHNf2mO'?S&
cniP2T
Q>jly4
o?wMkaee<Q
XIy>9l
B"f\X"
T<HgB,h
U7spt
lPg>):
^_q?yu
#:.SdZ
q#*P!u
MhAqXV
:*<Td1
+wb-!\
+(b2fj
WZ5Q1a9
-0./\2
X_NVA^E
SHvB_}
)'0hkEsd
N$#}+`
FD[?eq
*FT!_d
~_8nsE
^m$@AftO
ozO&&y
}82UjT
1os!&]
^{d+mVIb
b~*Phz
t=9o_o
d85Qq\
7fh\[*
}]p5Oju
8bf_}3s
.b#bTg
mcW/;Er4
*<d>c\
yHXv3T
u`2%\f
?w1+9@
Zu"%OlM
]uc[F
<?]>Ep
X+P8wx
ZKc3*%f
mAKz]e
=0;(^\
#`|t]$
@j}wW{&
^`RQ6p
z E,K4
U`@+`Y
?JHwuJd
QNTxzh
H3!Y$:l
1rGVQ
$yz3bS
u4$'TR
PJ|#}kc
[KRjQp
#hjOY4+
%p3]E<
5uYN{L
g Z~dy
t/kp=b
&tWE.>z
|:&sr`
;K_SK.8
n5\t6x
`!v^|$
,'!S<-
]3kwhf
'BJnbP
Js4IU
_((hAX
b5@sII
)1~.3v
[@TZ0dI
o 4+9@
'(K-|<#
e#jTyna
Z[w39-
m0JtqE
AhZf)O
7HZ0.`
gE#Cj;
_%}"P"
=~+h4g
BZ=3n-}
H~>d(
-qO>:*wc
AH%%';
$/\f^`[!
{B[Ekh
ZhU8Sa9
lZkdY/
l+kpAA
N-EKAV
6IN#B1io
q8"}Ew
Af>8yp
P2Xxss
Zm9H&q
FG[40"
0Xvk0?
^pF"|9D
1aya,)?
Y%W8ho
'r/dvkc
89:<&a
5b@*/T
hVow!f
&+!P+J
;R?6e]g
,y+hdu
0NL%7=
!9ku*H
e`y[9Ags%
&*D6fd
y`J//N
L,[OxQ
(.Lx(5)Yp
kcU)3E
c>4Eb=
NB/&_v
[_j$qE
)vy#PB
PUa2|
SJ;EC"v;{
05q4A_
Mt0?=`
@Jedwp1
1<`^)_F
pVC_6z
KYKy:0n
4EBT04H7O
];Y!9VK
{T'+N?
(>a4o[
N58gy`
6"6>2
(tSZk.
^_JSA"lSFB
_s&yRM^
XT.3'9
Qx3%by
e0pG_l
L?G[*1
+b}]JH
ojTxGq6
CDLN@3
Avg[($n*
#F$])_
h:\a.E
-1?.V~*
eupgd!
' v1BH?)
2Z)ba
',7Mb+Z
XTZs0S
UgFhPT
m0@])/
^Yp%Bg
:n-/Lh
*6u2mG
I'1WQ_
o+Iy?p
pu/f!o3]"e
2jzy99
.:2xdT
r9F3\m
\OT``I
8-CpLR
K2i%Yoh
LBuwh{Tm
d!6Wi)w&
\MC^fgG
nlxy6DX
'v`cs%f
eu0kmG9
vS\``2
2xg)ov
?xHGE
o`t?h#
`Ii1&/`
qB|}_c
NYS'?}
Rx_hs:/
WVohs'
s"w4{z
xd:enh\?
ciMVHG
X*.~ ~
"8=1cTr
=m:.f-
(+}np0?
$YIz.Bn}?
-xWm"c
KfZ0#E1
U!U?g$
+T|6P|`
2Ca+'12
21%[znA
aQd7A-p
IMc^8Sjg
$dmXC3
+&Ci+-
@`VbsS
m$UzE
>>/+WZ
'|Z{pF
}%BsTv
e]4xGvwu.
S3pI.{
asR;9 Oz
?Ss2Li
rHl}Fm
D>UX-bp{u
%,71Q<
wYLoH(
:'f=w!
a[G9WVJ
vj]gi|
7O$DkG
{?2K-#o
NHHl0x
/@-pK$;
?w",Dz
S`6kn`
KC]&{:
68b'z~
@N(KKvP
\Z`33n
l/_Ea@
A|U3'{
F.{Aa;
$y[jGY
?cf"?<
&DaFK
}F~pfL
=wqCiA
03*#{yF
jIj! l
8"WSJ3
=-uN{
eNH8}>
R(rkle
ywAkQb.
iFMj)\ n
*|@}=W
QU'X)8
I}l(T+l
wBYaK]x)"
?b9GW
j S)^V
n!8@yG
a5u_jQs{
8pY3MwsV
oqYI7C
i$wu74
j,wld5
fId/0W
.l0Rn.
.bwxY:
_5_+ c
bA3<Rw
>3bR5S$
3>/)y-c
J*TTU
oou)>-
(m tX4
t+"Y{,
}=/fK8
c(La\
kwHk,/
aCOMzI1
V\Y,@Q
jC*'fR
<'>%}p1
m,[-%NH,v&]E
5u!B<#
[.] IY
!`8~d)
A/*|-)
@/*0>?(v/;
OYdz *
R\78EW
^.%mzOa
ZTeK8QFqo
9~pW*sA=
O_RrFL
D`vrkx
Antivirus Signature
Bkav W32.MarsvapRosJ.Trojan
Lionic Trojan.Win32.Mufila.4!c
Elastic malicious (high confidence)
MicroWorld-eScan Trojan.GenericKD.65688780
ClamAV Clean
FireEye Generic.mg.646f9a44ad9c8719
CAT-QuickHeal Trojanspy.Mufila
ALYac Trojan.GenericKD.65688780
Cylance Clean
VIPRE Trojan.GenericKD.65688780
Sangfor Spyware.Win32.Mufila.Vvd1
K7AntiVirus Trojan ( 7000001c1 )
BitDefender Trojan.GenericKD.65688780
K7GW Trojan ( 7000001c1 )
Cybereason malicious.b59176
Baidu Clean
VirIT Clean
Cyren W32/ABRisk.UMFG-8476
Symantec ML.Attribute.HighConfidence
tehtris Clean
ESET-NOD32 a variant of Win32/Packed.VMProtect.AIN
APEX Clean
Paloalto generic.ml
Cynet Malicious (score: 99)
Kaspersky Trojan-Spy.Win32.Mufila.nx
Alibaba TrojanSpy:Win32/Mufila.6909de22
NANO-Antivirus Clean
ViRobot Trojan.Win.Z.Agent.6562480
Rising Spyware.Mufila!8.10959 (TFE:5:gnJOwaQzABC)
Emsisoft Trojan.GenericKD.65688780 (B)
F-Secure Clean
DrWeb Clean
Zillya Trojan.Mufila.Win32.91
TrendMicro TROJ_GEN.R011C0RBS23
McAfee-GW-Edition Artemis!Trojan
Trapmine malicious.high.ml.score
CMC Clean
Sophos Mal/VMProtBad-A
SentinelOne Clean
GData Trojan.GenericKD.65688780
Jiangmin Clean
Webroot W32.Trojan.Gen
Avira TR/Spy.Mufila.zrgkz
MAX malware (ai score=89)
Antiy-AVL Clean
Gridinsoft Malware.Win32.Gen.bot
Xcitium Malware@#18ikzniv0m78a
Arcabit Trojan.Generic.D3EA54CC
SUPERAntiSpyware Clean
ZoneAlarm Trojan-Spy.Win32.Mufila.nx
Microsoft Trojan:Win32/Casdet!rfn
Google Detected
AhnLab-V3 Malware/Win.Generic.C5388733
Acronis Clean
McAfee Artemis!646F9A44AD9C
TACHYON Clean
VBA32 TrojanDownloader.Private
Malwarebytes Spyware.RisePro
Panda Trj/Chgt.AD
Zoner Clean
TrendMicro-HouseCall TROJ_GEN.R011C0RBS23
Tencent Win32.Trojan.FalseSign.Jajl
Yandex Trojan.VMProtect!+Ql8xVVUN5I
Ikarus Trojan.Win32.Generic
MaxSecure Trojan.Malware.202072869.susgen
Fortinet W32/PossibleThreat
BitDefenderTheta Gen:NN.ZexaF.36308.@F1@aWRH1jfi
AVG Win32:SpywareX-gen [Trj]
Avast Win32:SpywareX-gen [Trj]
CrowdStrike win/malicious_confidence_100% (W)
No IRMA results available.