Static | ZeroBOX

PE Compile Time

2022-10-28 12:15:53

PE Imphash

8f54c7f89ab7fb80e3cbd057af48cb19

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x00093000 0x00029000 7.97765380399
.sedata 0x00094000 0x000f2000 0x000f2000 7.58692583781
.idata 0x00186000 0x00001000 0x00001000 1.29865726797
.rsrc 0x00187000 0x00043000 0x00043000 6.01178701511
.sedata 0x001ca000 0x00001000 0x00001000 7.98105785729

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x001870e8 0x00042028 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_GROUP_ICON 0x001c9110 0x00000014 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_VERSION 0x001c9124 0x00000418 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data

Imports

Library KERNEL32.dll:
0x5862ae HeapSize
Library USER32.dll:
Library GDI32.dll:
0x5862c6 SetMapMode
Library comdlg32.dll:
0x5862d2 GetOpenFileNameA
Library WINSPOOL.DRV:
0x5862de OpenPrinterA
Library ADVAPI32.dll:
0x5862ea RegCloseKey
Library SHELL32.dll:
0x5862f6 SHGetMalloc
Library COMCTL32.dll:
0x586302 None
Library oledlg.dll:
0x58630e None
Library ole32.dll:
Library OLEPRO32.DLL:
0x586326 None
Library OLEAUT32.dll:
0x586332 SysFreeString
Library MSVCRT.dll:
0x58633e strncpy
Library IPHLPAPI.DLL:
0x58634a GetInterfaceInfo
Library PSAPI.DLL:
0x586356 GetMappedFileNameW

!This program cannot be run in DOS mode.
.sedata
.idata
.sedata
XOVfJ'
;B[%];
5(u|#.
V0N qZ
iGBnl-
4#GG`d
6F/T(>
HGIy|c
Wg,Gs
v;O0dkZ
DShP]y
P>Xnhr
*$PzOvB
Pws]lO
r,_nVj
&~6)IK
N|iuC/i
l<Ym~I
Kp!9Xm
j_w<bj
?nirj
E~e(:~
Bz;Vh/|a]
UxlEM/8
i'-Kk35p
1Ov@_Z
.ZSI#
a#<9fi
Q0bv_t
DozJ_P
c-L%kr
\Bt/+rD
%BirCBn]
UiTxGz
SsF&u*
[ 0\I0
UIHke^m3
g+8Oh4
)l-p;fs,
FUWar@80tBw
M<gq?;P
_* \(V
r':,toI
KR|fk
8\G3:X_A59f
v[~Ei$
GY[?!3
I9E|eU
vC<4YD
*gT$|/$
39g^;-^
j+n1:!
.x4awy
bg[cT";
0]{xV"
)lF9-_y
-sBq9g
8IlM|In.
C;\&#I
NtkQ[pVB
~Br$pI
PVP,IWv/@
~:AB=3
miA|}f
KuL6|s`?
g8AILZ
]tO'lQ
7i@\rk\j
l!!'kk
c@.H~n
b,*sL&
V_:''H
QG7nadN`
91n9RK
5h{ido
(y~?b@
@pXTbK
'%6[:I
RiJaJ>
nI^RXH3
N+C'N;
tE@?DT
ys[2_s
om<FBLn
_Skx;q
$|Qvgu
/pPBag
<xT~[O:
<e|DWqU
SjCc)qPu
DY0;@F
bY.)mQ
lY0y|d
j2^:9=
6{efz0
N8BLb4
<5>M<S
MuQBhwgx
(BfU)*l
_e N@C
,:vnvA
ZjPEE
3wU5^#
>05b{hn
:e+pS#
x;o4:z
,=G!8eH
CuwI'k
zERxTY
S!Ou6O~`
*~6M@c
kt"u1c
cuHr:J
1M0Ie?
C4ORilO
@g"/$ V
!aT6XPk
dL=2{d
%j7VOrrS
\ZVAgcn
l:`0P'~
;r]:>`
@&^^J2|
> EtZ(
Zxuj<4
1,R3u`
_b2HgVk\w
!nZnXU!
!-M:[??V
~GI$\rQ
`oXlAu[?
NjQJF1jh
Y.1WJ1
zq"oAX
$"<BOG
6I08:XZ
.rf2!p[
&t-#]s
m@E6pfY
N j-}^i*8
{~"Du
kGBCF|Pn
B8`\FT
!GV>"9G
3FLz&!
`Oy?*r
`m(XcX
EePbP(
vlZ'uJ1
w*C}_>"b.O
SedXd&
.nKi5h
hH@I.e
K-c/t3(??
LCB,Jf
1oNJ[&
>-"8zO
F -tUB
3o+%h%
?N&64j-
AE.s^?
^=ElXn
z@*UCZm7E
G5ZM.A
7}G.t[
u/fDe9
z/XUL9/
Kt4XxV
z8&iFV
7C**PJ
rJ(Bw8
Du_Ic[.s
T0`Q$<
\iyed7
d7uHQ=u
O4$Yom
eCx(K)8
N7$.'.
AAi` S]
0~F31[
lhoVW
8)c$.}
xS0}u_
#%H4j.
'(-%~(
)S]CV.
.T*!g:K
m ^Ibb
kl7i)@gR
IqQ*D2
S"-,98w
bo88j@
rzgNW1nf
aH4nI3
Z7<UX2m
<~!\.!~E
W:j)zbd
cni7w]JJ
pybS^uw
8x;XMA[M
Sn;F8m
mf?3)K
(`vcR|
YaCdt(
'X&LoRo
@hji}>
U46dF]
D}Q5t~
R&xW14
]wL=;(
]@sX'(D
hkXn2<
2FUcNO6
2,hM[lS
rAzj3K
TG)QF6q
\F3Ujx
.F#{\=
gbN]}y
]#E[0C
|p[[NYP
1=3~%nw
`-,(`Oa
Qh,eig
@x!Mb"{v
jh=L"F1[I
Wq?j;&=
&t![t
Q#B=(y^
b{*EpF#
5#!,Ie
_K|vOC
DVLafI
{(.AP<e
Mw`y0-*8V
0>;pZr0
IYR%IC)
{x;o^$5
$/7f#/F+H
K38,|
ofa;e(>
L'1PR([&@U'
l!uYGy
45bDkP
~EnPcI
~?aVg9
p?o-;jS
aRtDH9
AjK^*^
:6 )?((
^Ggx6l
'nO)&S0&
h_ZYL;ZQ
H Gjxg]
(ZUGRjUN
0lR@K4
2JNc L
\lC\As7
103*z>
yrm|O<a
nFo,Iut
?h,Iu[
tgh2#C
g3jn$_`
P?",=[
T7XNkf
FK$NUey
L.ZMyO{^
E"}I=b
q/6!`D
Ymf4'N
;L$,wv)L$,
YBrPDR5
/vVcts
Pc&k_d
Uotsg$
Ak7+:]
DR|*RE
jHPilx@M
xA@'G^
os.%=xE
:c&&z%
103*b
Z:k3'&
06!`#fd
QeS 2
.af5;,
Y5^)Ru
=p-x1%X~
/ub^oXL
hdXah;
84KT}@
nyX I~
n_|}h[
5$W&yd
n03*Ef
Gg=qsO
zkB}yLe
/6!`$Y]`
"]$B?cs
9!d l/
$M`JuW
GetModuleHandleA
GetProcessHeap
HeapCreate
ntdll.dll
RtlAllocateHeap
LoadLibraryExA
CreateFileW
GetFileSize
ReadFile
CloseHandle
VirtualProtect
GetTickCount
GetProcAddress
RtlFreeHeap
InitializeCriticalSection
EnterCriticalSection
LeaveCriticalSection
DbgBreakPoint
DbgUserBreakPoint
DbgUiRemoteBreakin
kernel32.dll
NtQueryInformationThread
NtSetInformationThread
user32.dll
advapi32.dll
hid.dll
iphlpapi.dll
VirtualAlloc
VirtualFree
SetThreadAffinityMask
GetCurrentThread
ExitProcess
GetSystemDefaultLangID
GetSystemTime
SystemTimeToFileTime
WriteFile
GlobalAlloc
GlobalLock
GlobalUnlock
GetCurrentThreadId
GetExitCodeThread
OpenThread
TerminateThread
SuspendThread
MultiByteToWideChar
WideCharToMultiByte
IsWow64Process
GetStartupInfoW
TlsAlloc
TlsGetValue
TlsSetValue
TlsFree
CheckRemoteDebuggerPresent
CreateThread
ResumeThread
GetThreadContext
SetThreadContext
mscoree.dll
mscorwks.dll
mscorsvr.dll
KernelBase.dll
mscoreei.dll
clr.dll
diasymreader.dll
SECheckProtection
SEGetAppStatus
SESetAppStatus
SEGetLicenseUserInfoW
SEGetLicenseTrialInfo
SEGetNumExecUsed
SEGetNumExecLeft
SESetNumExecUsed
SEGetExecTimeUsed
SEGetExecTimeLeft
SESetExecTime
SEGetTotalExecTimeUsed
SEGetTotalExecTimeLeft
SESetTotalExecTime
SEGetNumDaysUsed
SEGetNumDaysLeft
SECheckHardwareID
SECheckExpDate
SECheckExecTime
SECheckTotalExecTime
SECheckCountryID
SEGetHardwareIDW
SECheckLicenseFileW
SEGetLicenseHash
SENotifyLicenseBanned
SEResetTrial
SEGetProtectionDate
SEAddMemoryGuard
SEDelMemoryGuard
CreateFileMappingW
MapViewOfFile
MapViewOfFileEx
UnmapViewOfFile
LoadLibraryExW
LoadLibraryA
=j&&LZ66lA??~
}{))R>
f""D~**T
V22dN::t
o%%Jr..\$
&&Lj66lZ??~A
99rKJJ
==zGdd
""Df**T~
;22dV::tN
$$Hl\\
C77nYmm
%%Jo..\r
>!KK
55j_WW
&Lj&6lZ6?~A?
~=zG=d
"Df"*T~*
2dV2:tN:
x%Jo%.\r.
t>!K
a5j_5W
ggV}++
Lj&&lZ66~A??
bS11*?
Xt,,4.
RRvM;;
MMfU33
PPxD<<%
Bc!! 0
~~zG==
Df""T~**;
dV22tN::
xxJo%%\r..8$
tt>!
pp|B>>q
aaj_55
UUPx((
cccc||||wwww{{{{
kkkkoooo
gggg++++
YYYYGGGG
&&&&6666????
nnnnZZZZ
RRRR;;;;
[[[[jjjj
9999JJJJLLLLXXXX
CCCCMMMM3333
PPPP<<<<
~~~~====dddd]]]]
ssss````
""""****
2222::::
$$$$\\\\
7777mmmm
llllVVVV
eeeezzzz
xxxx%%%%....
ttttKKKK
pppp>>>>
ffffHHHH
aaaa5555WWWW
UUUU((((
BBBBhhhhAAAA
='9-6d
_jbF~T
11#?*0
,4$8_@
t\lHBW
QPeA~S
>4$8,@
p\lHtW
+HpXhE
T[$:.6
00006666
CCCCDDDD
TTTT{{{{
####====
ffff((((
vvvv[[[[
IIIImmmm
%%%%rrrr
]]]]eeee
llllppppHHHHPPPP
FFFFWWWW
kkkk::::
AAAAOOOOgggg
tttt""""
nnnnGGGG
VVVV>>>>KKKK
yyyy
YYYY''''
____````QQQQ
;;;;MMMM
ccccUUUU!!!!
6bad allocation
_except_handler3
MSVCRT.dll
GetInterfaceInfo
IPHLPAPI.DLL
??3@YAXPAX@Z
strncpy
wcsrchr
??2@YAPAXI@Z
strncat
_wcsicmp
_wcsnicmp
__dllonexit
_onexit
_initterm
malloc
_adjust_fdiv
GetMappedFileNameW
PSAPI.DLL
DeviceIoControl
DeleteCriticalSection
GetModuleFileNameW
CreateFileMappingW
MapViewOfFile
UnmapViewOfFile
GetModuleHandleExA
LoadLibraryExW
MapViewOfFileEx
GetLogicalDriveStringsW
QueryDosDeviceW
KERNEL32.dll
wsprintfW
OpenClipboard
EmptyClipboard
SetClipboardData
CloseClipboard
MessageBoxW
FindWindowA
GetDesktopWindow
GetClassNameA
GetWindow
USER32.dll
RegOpenKeyExA
RegQueryValueExA
RegCloseKey
RegCreateKeyExA
RegSetValueExA
RegDeleteKeyA
ADVAPI32.dll
SHGetFolderPathW
SHELL32.dll
$OfG"O`
'OEe*OfG"O
$Oc\"Oj#Ojx#Oc\"O<h"O+
$OfG"O=
"OQP)O
$OfG"O^p&O #O>e"O
$O-=&O
)Oc\"O
'OW\#Ot'+O9
$O.G$O
'OfG"O\v(O
(OfG"O
&O&F$O
X&Oc\"Oq
P&OFz#O
$Oc\"O
o(OfG"O
#Oc\"O8q$O O#O
Z*OfG"O?
%OO|"ORs&O
;&OfG"O
+Oc\"O
(Op:#O
$Oc\"O
1#O'h"OfG"O
#O13#O
(Oc\"O
"O}#O
B'Oc\"OTs#O
$O$d(O
"Ojt%O8
$OSS(OfG"O
g"OM,)O
"Oj=#O
$OfG"O!x!O
"Oc\"OW
$OfW&Oz
!Oc\"O;
$Og0#O
(O{H$O
"OfG"O
$OfG"O!
$Oc\"O
L&O~x"OfG"OK
#Oc\"O
v$OCO%Oc\"O
b"O9}#O
#Oc\"O70#O
J(OfG"O
rm|OWQ
fA`fYf
}w03*E
af-F\v
103*Ef
cLjkhLN-dLd
5iL?~dL
&dLNHdL
hL61eL
hLo.cL
3bLlPdL
gLKYbL
gLTTfL
cL]3kL
cL`zbL#
bL*tcL
qeLr"fL
gLm#gL
bL'/bL
3bLNAgL
dL,zfL
7bL~,bL
dL&AeL
cLx\cL
bL!4fLP
bLV`hL
WbLD7hLC
bL+JbL
'bL^kdLQ
cLrwbL
fL<QkL
NkLVTbL
dLBugL
3bLrFfL
dL%#dLc_gL3
cL+<dL
bhLz&dLx
fLn<dL
MSVCRT.dll
??2@YAPAXI@Z
strncpy
_onexit
MSVCRT.dll
wcsrchr
malloc
_except_handler3
IPHLPAPI.DLL
strncat
MSVCRT.dll
??3@YAXPAX@Z
MSVCRT.dll
GetInterfaceInfo
MSVCRT.dll
_wcsicmp
__dllonexit
MSVCRT.dll
MSVCRT.dll
ovafRf
t8X-|(
MSVCRT.dll
_adjust_fdiv
_initterm
MSVCRT.dll
_wcsnicmp
MSVCRT.dll
MSVCRT.dll
MSVCRT.dll
??2@YAPAXI@Z
MSVCRT.dll
MSVCRT.dll
_initterm
MSVCRT.dll
MSVCRT.dll
MSVCRT.dll
__dllonexit
MSVCRT.dll
PSAPI.DLL
GetMappedFileNameW
PSAPI.DLL
GetMappedFileNameW
KERNEL32.dll
GetLogicalDriveStringsW
KERNEL32.dll
QueryDosDeviceW
MSVCRT.dll
_wcsnicmp
KERNEL32.dll
GetModuleFileNameW
GetWindow
USER32.dll
USER32.dll
GetClassNameA
wsprintfW
MSVCRT.dll
USER32.dll
OpenClipboard
strncat
UnmapViewOfFile
KERNEL32.dll
wcsrchr
EmptyClipboard
USER32.dll
USER32.dll
SetClipboardData
USER32.dll
CloseClipboard
strncpy
MapViewOfFileEx
KERNEL32.dll
MapViewOfFile
KERNEL32.dll
KERNEL32.dll
_wcsicmp
CreateFileMappingW
wsprintfW
USER32.dll
MessageBoxW
USER32.dll
KERNEL32.dll
DeleteCriticalSection
KERNEL32.dll
GetModuleHandleExA
MSVCRT.dll
MSVCRT.dll
KERNEL32.dll
LoadLibraryExW
ADVAPI32.dll
RegDeleteKeyA
ADVAPI32.dll
RegCreateKeyExA
ADVAPI32.dll
RegSetValueExA
ADVAPI32.dll
ADVAPI32.dll
RegQueryValueExA
ADVAPI32.dll
RegOpenKeyExA
RegCloseKey
KERNEL32.dll
DeviceIoControl
MSVCRT.dll
USER32.dll
USER32.dll
MessageBoxW
SHGetFolderPathW
SHELL32.dll
MSVCRT.dll
USER32.dll
GetDesktopWindow
USER32.dll
SX-/<q
FindWindowA
USER32.dll
FindWindowA
USER32.dll
FindWindowA
FindWindowA
USER32.dll
c,mP$
^',-#|wUD
0uRtP^f
u#nrxey4
4$t;u9U
4'NVWQ
@`cC:B7
$Vk!C$
-T%btyO
>?ybn"
/Q_a&9
NI~4_R
Ws)hpu
kR{g]9
fjKVE4
3K$ZQy
%{p"dz
6Y*c:z
:W^~fm
OG@cMcl
IUxKSEz
s0<["{
N'6'g$-
(%+sz<
d 9_(TK
4'N|5}3
OJu.\4
|rQ6oq
0{t[Jj
zeaXt
ytgD_mI
wW3}t2e&
1"r{j*xt
f)ytCf
Ku^Sw}t`
VgIG`{t
:@{tlG
xtPR]>
{tgD@c
yt9PGK
*.nqu;
:M^`q
13L(qA
.$5'!3
@Dcm(15
&1Ow$A
/6HXJE
fSfXfB
LY_P,X
YSR.1K
TxqS@e
`\IOw^
103"+w
Q#/6!`
3vuU(Tf
>103*E
5Z57J
Ah1/yr|94
l3y6/P
KpsjhS
x;0.rh
~ssrX8
P52U#u
/6!`,?
d$$WfP
d$ yv[
;]MnyX
'mwson
r&rm|O
[yl310
vl3~}!
ul3nmE
"zl3-,
pWqpsj
`<hrm|O
T!b7jW04
<qpsju`Qf
nyXlytk3
v4~VNk
*"{}7
5obyf1
#y,n&!
2b-'-1
D(-pQ0Q
D1/Q<.&
}O03*E
o$n8)b
}IAdd=
E(B7Rc
mjdQZc
tXJt.2
t<pMX=
RD&\TP
iyQk/
6mym;J
T8gD@c
VRS8f)
T8cBIKx
w;;sU8
G,riX8
,|U8/tw
GPgS85
-H|%RW8
yZ8T\+ ?E
Y8&;dn
W8%W&W
}3tT8df
t:,[8D
W83Vr{
jX3z)W8t
vY8;c#
T8;zxB
'i"pT8
+[8N<8
0OUlR8=
zizT8rQC
7pS8ZN
KG{pU8
`Y4iZ8
HekZ8'k
Aj]v ]
V9mila
Cf+!C5
ikDDe'
pW1#`Q
a.h0|F
K&X1ox
F:,}z`
F7N~;Q
FnzY{%u
Fm!6G?
F%"*jMo
};t06{
F${CjR
?x>y5G
(t/BFK
>|.q(m
6Os|lU
v6;s>7
$ M(9
#(Yha=iu
#Z~Ovw#9
AeBZh~
W<z@Ie
#~$@v
'mE_J=
q'2;~I
rJqEV[
aQ0OSr
TH{_>!Q
j3edJ*
j3ihD!}L
f@pnqla
S7E2^Q}S
kIyWKY
_=E$nq
WHM280kA/juIa
M!9t#l
s$_;~~
kyO{^R
w"lHtO
tj3cbH
59b>M(
6y/x2
t\;LPa
WKGS2@
nDp2&P;
|;dqz5
&+LVg{
_nOT4V+
c]8Jeu`e
zf~3*:
%Dm3Nu
=1dD#z
<wj3+f
vj37r0
%4yj3L
b7yj3d
-<xj3\
Q{^03*E
[8FB/T
(hyszy
$gvQWl|!
Ya%x^<
h*ZNmJ
r+zUFc
$C&Vl#
]8dGwk
ZkqbHtR
kbxn/E
1J&mSi
#9X@l)YM:
)sP|Hxl
:'wUtp-]
0MfqZ=
fq0w]sF
L` cyA
gMozdR
'2fs-E
O(EKC~
{l'D5N]
<4o6`k
qb7L_^
)h9bm3
e`>F_bn6C
?StEJ;p
6poD@c
69p1WS
2pCJPM
S4pf3 v
4sK2p^
BkQ7pV
Llv6p*4
69p1WS
BF664p
~jh@T/
v^ \n>
k^&G}D
4$zC{A
uS+JCl
&03^JovFJ
fBv5w3H
tCu#03*E1i
qpsyKq
jfF%-<
103*Ef
4'fH`f
d$ fIf
0#p->k\
/6!`Ir
T1pm7{-
2-<y)x'
d$ f@f
%K3QKnj
@Q.].l
`fBp|qz
4$uTtR
3M2^ )
)cHC!)
2-<,wtl3
8)S^Q[
=('-k(
d$,@@f
A'PrUu
BGbRrj
a?fFsH
p/6!`6
e%tKa
1srm|O
;Lyj~s
b1KQEu
03*E ^
WS6*&V
YgfL,.
MaQ{~\
qpsjO#6
q:5MgBT
n>tOez
03*E7z
.9f\?'-H
;`X4rV7
e9ImkIpP}R
k3(c__<
rcw''-
:'SFrHt
(YMd9?
ssfe}<
C|e~[.
8*FMCT{
/P:ipm
ki}n,)L
g3So!w
qWAD$,
EeR!S]
@`c"&iv
ow^5Io
=,UJVu
`m8)Zk
KQqpsjgk
rm|$f*
nyXk3e
mJnhHoO|Q
DSkDzU)
#B}7=xJ
us3[Zz
e\:'uH
<h-J(|
1us3+*
/8aqVu
r3=<"zJ
L"Gu^0
IQ41Vb0
?~8ra0(}
R`0$Gq
xDc06V
L_`0Z
s`QSz^0)
rMG^g0
B,nH]po
f/p^0nzY{
{8p`0g6
4h0k@9
&Ue-Ck
yNf0+
j,c9io;
C!H(U*
2!+0qS
hs:>"N
"P;,>N
Ns^f|~R
v_R{~|
i3%Th%
)&-J't
;f0#&-2
TXE$e
P0Tc
Y"[d)H
xr343Y
8\Z8_?lA
30/Aq#B
%-oLEU^
r/Iuus
nyXVWQ
LH>5&1
M tm3V
,>g2Wu
ova,g
P#L9Wu
0y$k@A
P^pPu(
rpuNxI~
J(O/\1
05:]b3
S}?oc@ud
y}:.S#
'!kQ$d
?`Q5gc
[:re$Tl
4+* YYc
'>iNvUl
'Q3(xe
qusaR3
"-~wr3
Js"r(:
qpsjBv
D.wobU
m3nmI.f
KBcOFO
f2bVR"
1lwC0l
ZG*uSGX
xm3}:3P,
B17?>g
Rp^%R]!
n^Z$K`
&3]b;e6p
_H<owV"
#O[6!Sn_/H
rm|Otq$V
B+zfEvB%
^]Sfv8
tE2yVw8
;w8DGA
q8/O30G
@`cH2Aa
>yw8rA
`-{8$J
.@w8b?
&#t8>.
Lw8~ m
@?}\w8
s8Bfe1M9
mt8$Gq
t8L)}6
iW\hClw8
b.@w8b?
?w8zPZ
s8Bfe1}
.hG#<H
;!t83y
=.Utz8
9 kp#^
ks8I|<
x6{R2v8
`C7$tp-
,;D=:V|
s%`\\S
/6! qv1P
+,}~x]
w.W}Xu
S!J{Xu
.b/6!`J
#Z#F)p%f
wu3'b
\O"CVs
n{Y]Bz_
Yr)_U<
JbIH<6j
3>{f\vm
Vwt3.-
vt3ML0
#wt3wvZ
`vt3JI
S7H5aT
pi,B!)
103*N&
uqK*)oL'
kO]P|o
BOXR7i
UvH|@'
/uy6*O
nyXI_2+
muBT=[D
P.6OR^&3
.goB>Q
qL/}3FG
$Q\u}]
IH1%kK*
1dX4'N
'q6Yu;
2-<En2
TS6*T4
/6!`ij
s@tOjqMB
|)rrm|O@
rfCO.<
3M(~Sg
v3*EvW
XEI?8}
qIZG8;
8103*E
oAJnlJqQ~S
x0.3V[b
RL/5Ph
"7Xe4@9
8!omFQ
~;(v;t
7~ wE8
7gD@c8d
FKt@):
=9cFo3
cP|4'N
Jzs3IH(
-B3`mI
}LIKtn
r_L,h/v
>F`{uVg{
<HrU~a
HT)-5
|X%=>5h
_HxVJX
n9r!fh
+|Ows3
03*E=z"x
2-[j#x
dcG =Q
E$N)qe
N"k%#b4
;MRWpP
w^Ir*Zu
[>C\lB
103*Ex
R{6ZuX
v/CmPy
r:tY9&
g8_?lA
6Ewr3e
.8&P3\_
WV0O] 1va
8103*y
;dZZu>
'103*!u
vjGwVdr
(.;.pb
{5^sZu
};?$F}
iqapNg
!uLQjp
p&u !y
4I%j%
bVgS2W9
rm|OK5
/6!h:*C
dBiIvK
Hws3S
{p,9&m
.!Zem6
*[^Y0@-
ova5wC,
>vWhRG
0~4^Aj
E,@x@$W
LyL#rm|O
E=Z*c&
&i(Q!"
GcF^2i[
Jf`Tv\
#I,U~*M
Crm|OH
6g"S?i<
c gZ_
r-o%s0
wK*ybV
nyX:F^
uXA5hY
#L3[uJ
08W3I]
}`T/6!`En3[u
ovEVyu3e
*fQfPf
\d&-?l
u3y.i)
>iJ[NX
`W"`ZD
Sx0&kMm
&a(Tas;b
BML?b]
wTbOyu
qpsj%h
r3z1q,T
& I;[u#
=x{ ?b
(EM=xaT
4'NhXP
SJ5!7E
103*%N
C#C!H(U*
qesC"W
JNu{:46!`
-1"}{/x<
fJ{&W;
nMl)qeBT
ra.3*E
Ch?gL>
%?oJx'
P-JMi)
T_fUx%$
.w,m8e
w103*B
rm|O*e
;2Dy~4
;fYiuN"
;|]>cH^
;_!YQM
WGMkj.
5cZ8-u
dT',O4
VQULj)
ar*37.d
T`[_ru
rW=/3*
}:=}eI
Fst)`g
mR8*.%Q
Zs?>B9e
nb8bEnqA
PS{nqw
D$(P`f
mr4?sX
|$Wdvn
4$Jz>{
103*f@
2>g_\u
J{okNB
|`=*VIuKw
=f#0$x
/T}k\u
}\?3ArfV
]qh*M}
/BeU{'
K8E{EI@
wRXq"-
2-<hU1B
K&?sSL
s,G9z9/@
_=NhM5AF&S(
IlJr:.C
H+i+i
3->X1:`M
QF% 3q_6
ad@/0ova
mhK;ehj
{coMtT
#~$qj:
Srm|Of
-?4]q1Fs;
D2xqx[
"Ua EC
s@?=F2
G<Iwt3r
0KoS8tO
%3]:m$
o\I$gV
AwMZyL
C:>q^g
Ro(-PHp+%
Ag\#1+
xWnyXY
rm|O$g
Gj?Sbh
B},Q*Y
].i#)d6
V6N,S3`5
hA^rOH
nhC]6Sg
Sd~WjC`t
vs3u*#
4'N$6M
tg|{%;sL
/,UR]u
_);so$
e'r4(r
+/-XY
L,L*Q1^3
QlfGXl
Pfq#Zg2;
=Y0Qu3l
j>K-/_
Yz51[>g
j[64oX
REJ|!,!
1nD;s0
rm?hq]u
Y7^>k@
M1dQ}p
Qa?`5$W
M5;sp%
.TA[@b
=*VIuKw
K)P0]2
D0-3'o
C0\O{Q}
AF',LD
LXM]~j
qpsj!t
<=4;s%
5$Wp{N
vjB!qe
4'WX)x
F3_R~T
Rd/e@F
:^uy/f
103*cI
k_5_BkN
1,VYwrRrPwW
'Q_p'mJFy
2-<kFU
Yf_zg;]2S
FzEr<j
sQT0
I@TD$D"I)V+
J*B G'T)
%O]n%!
w03*Ed
vyUDEhI
)E%R%T
.)b}]D
zek\4`
n+\PoR
&Qu/#J
+GA'3f
K"s6~4U
%GC( :
2K>j@l
9X}4^o
s|p!{>8cT
OCTh;HA
0YZ^uB
R}w\wO
:#Lg^ut
[UDETq
ea`, S+
8[(jlhu
C+Ts^u
.-Anw/
~3*Ed2
5Kp+@,
hw8C0,O
9;{:::
d%&\7=_
U5M+R2_4
{9wrm|O
>JWuU*
gShi2A
f_l{<G
4'hv,A
9Jyk3Y
aEdQ}p
103*wsC
QB7xU0y3'
VMr2Y}V!
^p$-5l
g[i]<8
tznA S
9&REqGs
#THYE$UIE
fZ9}?"
o`w3H5
}@BuSk
iz`o>5
yW:.xN
+E*.]3
aUcW6x
ltJuN,<
2-<!I?
|Z]9()
9@PhFmMzO
7'6qj3
rs.-()
+L1WD"
#K:-^_
TA7J%R
:t b6F
L*Q1^3
X6]=j?
^r2Gt<
V4[;h=
<X|"N1|:
4{GigO
Z|'X(d#G
=%mo2|M
f8-^|4
1+Mar9q
%K3)Z97
W>y:.,C
`k#"'*)
}:pSrpO
l&G[M:MGW
Zs:5j,
ib)DtG
0fqno*Tn
duH>6H
X0jh6@$
.zMfB-
[L.kbA
m00B7tl"
ODuvm`
>]HlO<
4>Z9sB
pVzE._y
9.0me0;
~pJk`(
uk2ALm
Ys,P:C
zMEJg$c
@+9`mz
UTplqy
t<-y,
AA'(Sa
nX^*h[T
vXi_N^
2@eaAe
'a6\J?
+o:j)s
Y\},lH
B0^&g"9c
GCnl<n
=}<rYo3
F`gNu
+HBY[o
Lkf<cx
([(OcLy
8z/p#'1R
b}<L|,)
djKp/ ^
9 hm.;?
}oM2DB*
i)T9 )
)1S+.8E
=mZ>'Lr(
0_C[B+
H`CI2"
dXVu0+,bU
GFldrZ
N4dt}$A
]4"~?|7
'9x>a|
IYmh"U:'
cnd-Fk
H]Ji/9/
pMjIb
%0G/kr&$/
WM"^wY
!!<eD[H
j5#C5!&5%
m^X&u'sec
{Sc@9[
eFd4=eAwy
y(~j';
#%P~ex5:
Nq-5cC[
#0.HLF
T(F;LCl
~TLY}_
F5,{UI
AO&JpB
S_<%v=
9<5+<8
AdZ_J>A
5jR;B'&
q$ Mgo
;w{k*\
ePcx75
0!n9z5
$bC!3e
d^,Am77
fRGNa%HnBN
Iq3vZX
=]?^In
wR+.p`
XmV!_V
_1/0&;
hoev^$
}=n$bf
6U`c=/-J
m%)lM&
9!Y1t^
'nyyo`p
o5P6~mw
uG<\MY_%
\S!=)?K
b!Clp+
Jf(g`W{
e)aw%i
.:/l{3
.7#}Gq
DLl7#g>
zA[O@
"P[BOQ
PXv~@2
61WcLdSr
Z`hE(JT
x[`L>%
SF}di
v"KmO#
:R9"4[
2GvdAs
![xp58O
`-?96
#3<cMF
Jh1_ w
2)7h\lJ
h]iq~)
}B;x9{
-Ip*H'
Up/7G"O
H:fpuT
*54W 2
*2X!T(
ZyFj17
%8%(dj
K<:1w6C
s$n,.,h
s01RHK
3?mVH+r
^1GtY\
MzB+Gn
iv XP8
Z]~(`)u
HVl.)5"
[T(ROR
C0I"^8
g6TLz&
pY+O@
~.y}:W
&6my#G
mGr$'bWh
nuf+"L
e^nXf
i^yk24
}zTBl=ox
wl5VhH
;-j-eY
&O?W*+
W=U;s~
To).r(
|.e)&!e
Gm8;h&
M!iEhS
dB.S){
a2p]|!
mCNKu/
:^4n?o
?%.Pdd
P3$WB
U/Duv^
7A4Ras
]f!}xI
otxbl]
9~c=[e
3P(K^F
wqFhf?
F8Vb90n
pfF\%p
3a{xp*A
.h29%S)
94Fu4s
NQ$^l^7
s;fJ2!;z
Vcf{6Ze%
-\aRf~`
F\%f3HD3
E[R@K*
XG2z-U
3oPx-sr
q8(eiu:
ny\]c=
?O5|#t
%5@KscQ
Va4x|K
Yy*kg)
v /5l=
S xh539
<p.8["
b,-%D\
%C*BtI
d5bs[1
pf{F"=
&a=Q-f!i
?7xODH
\25Ifz
9 hMk)
uod(iW_%m
C-Q8w#]
8,c(rO
% FsoA
S$-[C#
zsW1lD
uI# Iwd9
Ipc'DQ
OyPH`2
.8eT2)0
>3Jv`f
KA=;@]
}Hw RP
;T;BvFR
hhengji
Vw4~2W{
MeLfdY
m?Y[E<s
ykBP4d
z)%[VcF
}ql>xk
-mLa2R
L}QQ"Alm
8Tv?Ca}
NGetACP
MulDiv
Sleep
KERNEL32.dll
HeapSize
HeapFree
4IsChild
,SetHandleCount
$GetMenu
GetStdHandle
SetRect
=PatBlt
GetFileType
gGetVersionExA
GetOEMCP
HeapDestroy
DPtoLP
aTlsAlloc
RtlUnwind
GetCPInfo
IsBadWritePtr
cLPtoDP
WlstrcatA
LCMapStringA
SaveDC
LCMapStringW
Escape
8GetStringTypeA
lstrcpynA
LocalAlloc
BitBlt
IsBadCodePtr
SetStdHandle
PLockFile
GetVersion
GetStringTypeW
CompareStringA
#GetTickCount
8ReadFile
3GetFileTime
#FindClose
$GetFileSize
CompareStringW
TlsGetValue
3LocalReAlloc
TerminateProcess
GetProfileStringA
TlsSetValue
GetCommandLineA
GetStartupInfoA
WRaiseException
:GlobalFlags
)GetFileAttributesA
GlobalReAlloc
GlobalHandle
UnlockFile
SizeofResource
lstrcmpA
&GlobalAddAtomA
lstrcmpiA
rGlobalAlloc
GlobalFindAtomA
lstrcpyA
.FileTimeToSystemTime
[GetThreadLocale
GetProcessVersion
FindFirstFileA
LSetEndOfFile
GlobalFree
'LocalFree
GetTimeZoneInformation
UnhandledExceptionFilter
SetUnhandledExceptionFilter
EnterCriticalSection
GetEnvironmentStringsW
GetEnvironmentVariableA
LeaveCriticalSection
GetEnvironmentStrings
SetEnvironmentVariableA
FreeEnvironmentStringsW
GetFullPathNameA
8GlobalGetAtomNameA
FlushFileBuffers
rm|InitializeCriticalSection
SetFilePointer
GetVolumeInformationA
DeleteCriticalSection
GetCurrentProcess
DuplicateHandle
kWritePrivateProfileStringA
GetModuleFileNameA
GetLastError
GetCurrentThreadId
GetCurrentThread
LockResource
LoadResource
GlobalDeleteAtom
FindResourceA
FormatMessageA
FileTimeToLocalFileTime
WideCharToMultiByte
lstrlenA
FreeEnvironmentStringsA
InterlockedDecrement
GlobalLock
GlobalUnlock
CopyRect
InterlockedIncrement
GetModuleHandleA
ExitProcess
IsBadReadPtr
HeapAlloc
XSetLastError
FreeLibrary
WriteFile
VirtualAlloc
VirtualFree
HeapReAlloc
WinHelpA
USER32.dll
GetCapture
MultiByteToWideChar
GetTopWindow
HeapCreate
RegisterClipboardFormatA
GetSubMenu
CloseHandle
GetClassInfoA
PostThreadMessageA
~CreateFileA
GetWindowTextLengthA
IGetMenuItemID
GetDlgCtrlID
GetMenuItemCount
GetWindowTextA
CreateWindowExA
RegisterClassA
SetPropA
GetPropA
GetClassLongA
RemovePropA
GetProcessHeap
DefWindowProcA
CallWindowProcA
GetMessageTime
GetMessagePos
tgUnhookWindowsHookEx
SetWindowLongA
GetWindow
SetForegroundWindow
OffsetRect
CharUpperA
RegisterWindowMessageA
x[GetForegroundWindow
SystemParametersInfoA
IntersectRect
GetWindowRect
GetWindowPlacement
SetWindowPos
GetFocus
MapDialogRect
SetWindowContextHelpId
GetProcAddress
InvalidateRect
wsprintfA
GetMenuState
LoadLibraryA
GetNextDlgGroupItem
}LSetMenuItemBitmaps
&ModifyMenuA
GetCursorPos
SetWindowsHookExA
PeekMessageA
MessageBoxA
SetCursor
GetLastActivePopup
GetNextDlgTabItem
EndDialog
PostMessageA
GetActiveWindow
IsWindow
PostQuitMessage
SetActiveWindow
DestroyWindow
/IsWindowVisible
GetParent
GetDlgItem
6CreateDialogIndirectParamA
IsWindowEnabled
HideCaret
GetWindowLongA
ShowCaret
DefDlgProcA
SendMessageA
LoadIconA
ValidateRect
IsWindowUnicode
DrawFocusRect
CopyAcceleratorTableA
lExcludeUpdateRgn
GetWindowDC
ReleaseDC
BeginPaint
EndPaint
ScreenToClient
ClientToScreen
GrayStringA
DrawTextA
LoadBitmapA
TabbedTextOutA
InflateRect
CallNextHookEx
MessageBeep
FillRect
GetKeyState
EnableWindow
IsIconic
GetSysColor
DrawIcon
GetMenuCheckMarkDimensions
GetSystemMetrics
UpdateWindow
GetSystemMenu
GetClientRect
AppendMenuA
CharNextA
VDispatchMessageA
LoadCursorA
PtInRect
GetSysColorBrush
SetFocus
TranslateMessage
LoadStringA
GDI32.dll
DestroyMenu
GetClassNameA
SetWindowTextA
MoveWindow
)ShowWindow
SendDlgItemMessageA
IsDialogMessageA
GetDesktopWindow
CheckMenuItem
MapWindowPoints
AdjustWindowRectEx
GetMessageA
ScaleViewportExtEx
SetViewportExtEx
SetWindowOrgEx
DeleteDC
OffsetViewportOrgEx
IntersectClipRect
;GetClipBox
SetBkMode
GetDeviceCaps
ScaleWindowExtEx
GetWindowExtEx
GetViewportExtEx
DovSetWindowExtEx
GetBkColor
GetMapMode
GetTextColor
SetBkColor
SetViewportOrgEx
RestoreDC
StretchBlt
SelectObject
CreateBitmap
ExtTextOutA
GetStockObject
RectVisible
PtVisible
TextOutA
CreateCompatibleBitmap
SetMapMode
CreateSolidBrush
103*CreateCompatibleDC
DeleteObject
GetObjectA
GetTextExtentPointA
CreateDIBitmap
2SetTextColor
GetOpenFileNameA
comdlg32.dll
GetSaveFileNameA
7GetFileTitleA
CreateFontIndirectA
DocumentPropertiesA
ClosePrinter
ADVAPI32.dll
oledlg.dll
OpenPrinterA
RegOpenKeyExA
RegCreateKeyExA
SHELL32.dll
ole32.dll
RegSetValueExA
_RegCloseKey
SHGetMalloc
COMCTL32.dll
WINSPOOL.DRV
SHGetPathFromIDListA
SHBrowseForFolderA
OleUninitialize
SHGetDesktopFolder
CoTaskMemFree
JCoTaskMemAlloc
CoFreeUnusedLibraries
CreateILockBytesOnHGlobal
EnableMenuItem
CoRevokeClassObject
CLSIDFromProgID
CoRegisterMessageFilter
{CLSIDFromString
OleInitialize
\OleIsCurrentClipboard
OleFlushClipboard
OLEAUT32.dll
OLEPRO32.DLL
CoGetClassObject
PSAPI.DLL
IPHLPAPI.DLL
qpMSVCRT.dll
Safengine Shielden v2.4.0.0
StgOpenStorageOnILockBytes
StgCreateDocfileOnILockBytes
(}Mm#FFs0
d#FFt0
R#Fvs0
i(W0[p
Q#F2o0
D$!f@f
<rm|Of
KERNEL32.dll
USER32.dll
GDI32.dll
comdlg32.dll
WINSPOOL.DRV
ADVAPI32.dll
SHELL32.dll
COMCTL32.dll
oledlg.dll
ole32.dll
OLEPRO32.DLL
Antivirus Signature
Bkav W32.AIDetectNet.01
Lionic Hacktool.Win32.Generic.mzIW
Elastic malicious (high confidence)
MicroWorld-eScan Clean
ClamAV Clean
FireEye Generic.mg.34517f9ebbfdc93e
CAT-QuickHeal Clean
McAfee Artemis!34517F9EBBFD
Malwarebytes Ramnit.Virus.FileInfector.DDS
VIPRE Clean
Sangfor Trojan.Win32.Save.a
K7AntiVirus Trojan ( 005239691 )
BitDefender Trojan.GenericKD.65823226
K7GW Adware ( 005693e61 )
CrowdStrike win/malicious_confidence_100% (D)
BitDefenderTheta Gen:NN.ZexaF.36308.yv0@auz9Mepb
VirIT Clean
Cyren W32/Trojan.HPC.gen!Eldorado
Symantec ML.Attribute.HighConfidence
tehtris Generic.Malware
ESET-NOD32 a variant of Win32/Packed.NoobyProtect.M suspicious
APEX Malicious
Paloalto generic.ml
Cynet Malicious (score: 100)
Kaspersky UDS:Backdoor.Win32.Lotok.lna
Alibaba Packed:Win32/NoobyProtect.d79656f8
NANO-Antivirus Clean
ViRobot Clean
Rising Trojan.Generic@AI.98 (RDML:VAs4Eaj1i2LXHlcbawk37Q)
Emsisoft Clean
Baidu Clean
F-Secure Clean
DrWeb Clean
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition BehavesLike.Win32.Injector.tc
Trapmine malicious.high.ml.score
CMC Clean
Sophos Generic ML PUA (PUA)
Ikarus PUA.NoobyProtect
GData Win32.Packed.NoobyProtect.B
Jiangmin Clean
Webroot W32.Malware.Gen
Avira HEUR/AGEN.1237427
MAX malware (ai score=85)
Antiy-AVL GrayWare/Win32.Safeguard.a
Gridinsoft Trojan.Heur!.03010021
Xcitium TrojWare.Win32.Amtar.KNB@4wlm66
Arcabit Clean
SUPERAntiSpyware Clean
ZoneAlarm Clean
Microsoft Trojan:Win32/Casdet!rfn
Google Detected
AhnLab-V3 Trojan/Win.Leonem.C5391929
Acronis Clean
VBA32 Clean
ALYac Clean
TACHYON Clean
Cylance unsafe
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Tencent Clean
Yandex Clean
SentinelOne Static AI - Malicious PE
MaxSecure Virus.W32.packed.Noobyprotect.B
Fortinet Riskware/Application
AVG RATX-gen [Trj]
Avast RATX-gen [Trj]
No IRMA results available.