Static | ZeroBOX

PE Compile Time

2023-03-08 10:24:07

PE Imphash

caf9bf1d191236de3d7b150ac6f71de5

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x00184658 0x00184800 7.90493181985
.rdata 0x00186000 0x00007a52 0x00007c00 5.18776282603
.data 0x0018e000 0x000efac0 0x00000a00 2.20941959453
.rsrc 0x0027e000 0x00005310 0x00005400 5.11563960357
.reloc 0x00284000 0x00001ae8 0x00001c00 6.65611801483

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x00281900 0x00000468 LANG_POLISH SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x00281900 0x00000468 LANG_POLISH SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x00281900 0x00000468 LANG_POLISH SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_DIALOG 0x00283208 0x00000108 LANG_POLISH SUBLANG_NEUTRAL data
RT_DIALOG 0x00283208 0x00000108 LANG_POLISH SUBLANG_NEUTRAL data
RT_DIALOG 0x00283208 0x00000108 LANG_POLISH SUBLANG_NEUTRAL data
RT_DIALOG 0x00283208 0x00000108 LANG_POLISH SUBLANG_NEUTRAL data
RT_STRING 0x00282cc0 0x00000088 LANG_POLISH SUBLANG_NEUTRAL data
RT_STRING 0x00282cc0 0x00000088 LANG_POLISH SUBLANG_NEUTRAL data
RT_STRING 0x00282cc0 0x00000088 LANG_POLISH SUBLANG_NEUTRAL data
RT_STRING 0x00282cc0 0x00000088 LANG_POLISH SUBLANG_NEUTRAL data
RT_GROUP_ICON 0x00281d68 0x00000030 LANG_POLISH SUBLANG_NEUTRAL data

Imports

Library KERNEL32.dll:
0x586000 CompareFileTime
0x586004 SetLastError
0x586008 lstrlenW
0x586010 SetEndOfFile
0x586014 lstrlenA
0x586018 GetModuleHandleA
0x586020 OpenProcess
0x586024 IsValidCodePage
0x586028 GetThreadUILanguage
0x58602c LoadLibraryA
0x586030 GlobalAlloc
0x586034 DeleteFileW
0x586038 GetThreadContext
0x58603c GetProcAddress
0x586040 GetProcessHeap
0x586044 CreateProcessW
0x586048 lstrcmpiA
0x58604c GetTickCount
0x586054 OpenThread
0x586058 WriteConsoleW
0x58605c CloseHandle
0x586060 CreateFileW
0x586064 SetFilePointerEx
0x586068 GetConsoleMode
0x58606c GetConsoleOutputCP
0x586070 FlushFileBuffers
0x586074 HeapReAlloc
0x586078 HeapSize
0x58607c LCMapStringW
0x586088 GetCurrentProcess
0x58608c TerminateProcess
0x586098 GetCurrentProcessId
0x58609c GetCurrentThreadId
0x5860a4 InitializeSListHead
0x5860a8 IsDebuggerPresent
0x5860ac GetStartupInfoW
0x5860b0 GetModuleHandleW
0x5860b4 RtlUnwind
0x5860b8 GetLastError
0x5860cc TlsAlloc
0x5860d0 TlsGetValue
0x5860d4 TlsSetValue
0x5860d8 TlsFree
0x5860dc FreeLibrary
0x5860e0 LoadLibraryExW
0x5860e4 RaiseException
0x5860e8 GetStdHandle
0x5860ec WriteFile
0x5860f0 GetModuleFileNameW
0x5860f4 ExitProcess
0x5860f8 GetModuleHandleExW
0x5860fc HeapAlloc
0x586100 HeapFree
0x586104 FindClose
0x586108 FindFirstFileExW
0x58610c FindNextFileW
0x586110 GetACP
0x586114 GetOEMCP
0x586118 GetCPInfo
0x58611c GetCommandLineA
0x586120 GetCommandLineW
0x586124 MultiByteToWideChar
0x586128 WideCharToMultiByte
0x586130 SetStdHandle
0x586134 GetFileType
0x586138 GetStringTypeW
0x58613c DecodePointer
Library USER32.dll:
0x586144 OpenIcon
0x586148 IsWindowVisible
0x58614c GetShellWindow
0x586150 TrackPopupMenu
0x586154 ShowWindow
0x586158 AnyPopup
0x58615c GetForegroundWindow
0x586160 IsWow64Message
0x586164 IsZoomed
0x586168 GetDesktopWindow
0x58616c GetParent
0x586170 IsIconic
0x586174 GetDlgItemTextA

!This program cannot be run in DOS mode.
U&k~KMh
U&l~SMh
#5m~dMh
#5l~PMh
#5k~RMh
U&i~DMh
4a~CMh
4j~@Mh
RichAMh
`.rdata
@.data
@.reloc
=mcu'=
^bX_-NJ
o`A#=iF
&WWb#s
X&#(cg8a
#5v*%3G
)#(cgj
o@-l>%
A2I-!T
31#=QH
F3}vR/
$J%E\a
ry0f`4Z
:;yX3"
,J%E\i
R- l2%
PD_Xk
<J%E\a
4J%E\a
&WWPT~~\
eer.T;
<SEA#V
PD_Xk
Dgj~~1
<J%E\a
#(cgjv J
"{4sU)
<J%E\a
DgjV~N<
<J%E\a
<J%E\a
|,#=4H
P/~s&N4
$[F"}wo
9#(cg-a
((h1{Y
Y8Gy#h
z46izTW
#(cgjb
$~_26
|J%E\a
rD69J_l
9H'%TJn
Tep{fm
EW^>W!
?Y~U<
NR8,6R
>oce%<
"PE9T5`
ifiw9m#
&?xJKl
TUWv9I
:sN?)V+z
p)2>Zd
m)ayS/
;4dX{j
DnC8+{
TaW|\9
Bi<Roi)
u.x-0
TB-ah_
YfhfG]H
XE|`Xo
IjKlf
=P-#_
x$1zM^
S*[`_4i
U<Gl.of
OR+nCV%D
i0S\NB
3<`lb#
f'z&v
lFnLgB}
q6(kU7
?~j!<
0)#N`@
:<).<,
$~_26
JNV6H
tUR_wUax
(FNq6`
#4RAY~O
lEavJ
*DYO.x
J+b$_k
Hb!%pR
OwT~<!<
;\xZ_C4
s&Nj+$
{5B2Hd
i.[ZLN
4=)t(b
dRZWWl=
0}9LFS
Cl|[q}1
-u=|^^x
4b&X9M{,
iGMb47v2
br;1_%
Bm|GoJ
>FWb}X
{Dy4Z
4Zg0<
K#=?^
p&5?o7
Cvk&+Ho%{[
vh(OcY
z?*0vv
z,@rMn%
=Tw1`~
y-x s<2[l
R/7`^1Y
g*@trQ
K$"'ciW
? HX:k
_=F&5{
O8e|r@
Xv@{73-
M(}{<hK
2G(Dijv
>Jd-R98
b?T&hcF
E.;DUq
pi_TQ^
{P/Zz]
Av/^'q
(.*BY|X
B3RA|n
,qph%({
ADP'{|
`^6?mUv
@U~k<
{Y=rS
;b%zM
+,cG%!Q
HG#ron
1n$5/y
inf-(G
x9I<[G
U8@G!C
^l,cE?
#dLbA<.
hufi'ab
EbGxZ[
_M%5F!
%BV{#E~#
i<9le'
jlif-k\
>o)T~~
\3?dyq
T?hu&p
|B^Up5k
H0Uo!D
g60{NKWK|
FL~eH#
f{vyWh(u.
WXTG6h.
37t>GP
|B0FM.f
EG c6~
G;Lj>{
U2R8u6
tK2~W"<
'ePL.=
BPL'<
IM]7lo
K@aLfJ6Y
Pg'.FX_$
JWDlj&
+pFq2^b
+PO%TD
s6$?>6
0N(f{%
$3b5e
d5`~a(
gq*p]\$
9\m7~=
#pO\p
% <[Zt
*~V2+2~O
;m*%&O
(@&^F`
19KSbL
YP@SV78
+\^q"m
@bN6el $
|k7z,_n
o 7]nw
P}~6.<
~s*#nHN
gKp}Xc
wk7J\J
f`\9"b
'~3oT4
`/'37.
X@V1V!
zr~D<
#pM\p
:&1WV.
l(Sls,
{L.r#>
$KDC1&O%
]C1 lD)
&L_"i?
E'~` <
^uT/R9C
x_n~fYq
<\E+)M
TXN@+$
~lWNN^
=0i%ig
$68lk$
$D-)W%
L!z2W8
IBx?H6
l2`ATU
Pip~u0@
E;6]]
;P/c^iVx
VO;-tF
Tb`/ S>i
q@EEPM
hPpH=.S
Rjie\'X
~([<E&0
{+F\^<
`rTz?/
k%_l#(
0jTS^NG[
%?d,gEYl
Ce{hbir
0|E}9r
!I,:U8
p71[xK
<C\[bq
m[l#i
GWHpL
*E~p<
ei9gK=
yEd1n
II~olH"
h8(6(J
|.P{M(M
|4Fcz+%@\
-VTgn_
f<z9!(%
;o{FZt("
Bi-F?U
`v!eMS-
`4yf`A[v
;ih.`6
\=yCIT
TCfe/]Ku\7
P;D_EVu
T13/Q6i
r"!'%yp9
$W@u0y
9PKW;``
?PSLACy
{%:c"
W?pS1
5($QmL
s)$ul2
.Ig%qU
zo|r5{
<@Cw3DF
J>$yN6
0&&9GOG|U
L#^r!i$
x#CM+eq
ux_L'v
h2X35}w
KbXv0_
*<63b'
Ej!6h1
W-R`lV$
6@O|p\p
F>/lm!
EfL"`j
MB4)Hc
'-0Ac3
B3RA|n
,qph%({
ADP'{|
`^6?mUv
*8t4McWA
V=J?y
DA~aN|=$b<
F97;%,~
H_Jg~Q"<
ratE1\
6ge'6S
RphquR
H+GYfhS
+8aS?6
lGrthN
cxT".X
z<_~e#<
A*^e:U
D;<~zfR%
pKdL%A+
N2zb0L
cN~+'<
{b`lm&
Ml-\Y*
jf7(v.u
P'/eS=/
\3?dyq
T?hu&p
h):T_d@
}?<ywu
RsMFY,:z
A/\4J58l
'SPwnOq
}E~JCQ
}tOx!J]4I
n.nWdlT#
uMOpoqzid6z
.Ds+.7U
;.2jeC{
,`z@(ABm
3|Z!>#k
w[5&b[
;\FB7OY
$5X@.yi
j;\.5."
Y^IO9
II3xv
}1j)IZU
1w~\Tg
D.?~jx
);QK09l
y.u.k-].
,fbzDW
KnZ<95
P}~6.<
~s*#nHN
gKp}Xc
wk7J\J
f`\9"b
'~3oT4
(b"y{z]
#$z%7J
qz'gT|e$X
{eA%zH
r4F22z
9*_@~Y
"QuOvn
~7WTLa!
xDalx/
?h/BB%
bMDr.{
]ArgE)
%B'v.
Lca%rc9
0.*<@Q
cRJ/NF
$KDC1&O%
]C1 lD)
&L_"i?
E'~` <
nV@W~O!<
t4Gsu~6
gCrmy2:l
$k&N^j
97s6{/
6O2M3g
<\E3o7
:&-W~7/eL
TXN@+$
~lWNN^
=0i%ig
$68lk$
{4~W$<
16-q T
M:l/<`
n'ULH~
^gl^Xt
4C*Nmj
{|892`
Eq]_jLhs
XZ+qpz
+^)-$0
_2WESx
?%7E^g
z#4Y^N
R*P80kw
P+';1V
f\%MU
ERVL`y
^Yf0W#
s.{pgj4
x/lLo5
3,`xis
<R6T4KA
{RXBvU%VS
6,rAc#f
s:_8G`
L`>O`(
rwET7l
58HpQt~
.N`jP
b.alz2
+}l$so
RF+yf2N
_,D5tW
s0,W=t
mfjSQf
d0~x <
H,iE6, Pl
-W$6'
DuiOk5
>hfGS
M@||cd
~#o&HFn
8r^_s
JA`&AUH
?lKYRA
q (^iXl
}C~E-y`
Y9"?\x
F;x>CK
RYz%<O
z5S]tTW
JB*53#=
JyB |#=#
Nps1C
YEZM^$
ni2b&[
X,#(d.
i%<\Ey>
{-Fln.
i%WVkG
DP0ij
-#(cg-a
>Hm%uK
J/inn#=$E
uNk%^uC
$$,-5?
pwO8,~
cgCtW1
OK&-KI
%?MME*\
m"9UWi
01@6"X
SLD9T`>
pw9T}r
Lsl5W.
A|E?2%
:&12(p
3RkY|n
U.N?O>
j#Z@/fa
-`3q}l&*
miY%`D
d4KZg;"
<seglM%
;!Jd<Iyo
r<@zl~#
0TQi#q
_}}ouq
6L`;f&
,%0lV0
.mwKXg
j~w2cFl|-
h,O#sX/^
{R?pfr
PmoKi-6
7_'}yW
Km_E9~
4fyT5}0
F?m:r,
JDI%#H
LU/T8:_Q6
3Vj+"%
WE}"Uw
XGNS}#bC
5#(cgj
_;,vV'
K6k|}W
D*R69%7K
%EK`pq
C?#$'!
3g~m!<
tdvmQ+
,K%E\a
2ZpGh`P<
H~p <
#C^\xkF{
u$w".2
b@f%EM
Nt%FOo$
N`]qK0
%/Z&BS
LG3f\F_\
yN^CV6;
2ZpGh`P<
H~p <
#C^\xkF{
u$w".2
b@f%EM
Nt%FOo$
N`]qK0
:V(+u!
)VcNt>~
u3#+6l
nJ~-<
s.[|q5
\\J-P6
AC$:Ca
)c)JPd
k6vW5c
m=s%oR
I3%QB&
lW[p4WZ
P `@1j
uB0i"u7g
M4HGT5"9
)c)JPd
k6vW5c
m=s%oR
I3%QB&
E}44z
S,SEx'
FO/%E3C~@<
)]r&b]+
r=D18y
h`Pva8FB
~C(Jij
s4';*m1|~%pE.'
XV^0}U&
~k`4Q41
3Bf@i/
=CH9I)
>_t~{%<
 io }G
Fx0^Zo:}
1_yg:_
;D#1q}5l
JWM_W{
?yJ!vqL
<,kg)c
Q^a9Xfw
7(JijZ
lK%E\a
y2TL1u
Ws30hN
wi2B'[
R.#=7V
4s#=`L
#p(S\y
K9i2}*
-J}TWY
K9iko%
K9iO1
],TW`o
u#(cgk
#(cgkF
I{$,cm
cOK3.C
=Q70Q;gT
Vk3;%<O
U6=@h3
Nnz,.C
$u<\E'
$}<\E1
X#pI\p
$Wv.o<
\#pQ\p
<\Ex{
yWV/r<
d#p'G\x
<Q6@`f
?-NW|z
<\E%+S
#pM\p
%<\E',
UT`^8'
F<Uj0\
#p'S\x
#p'M\x
c-GW|
#p'I\x
-W~%B&
%<\E-2
XM^%G
eBQ6WW
%WV\`:w
#pI\p
#p'S\x
&WWyj#
#p'Y\x
XM^%c
%<\E-i+
:&+W~[_
#pM\p
U!VDUQ
+gUW~c
:&+WVd
%<\E'!
:&/WVrn
CyVZQ4
NLQ4(e
Si2j'[
Si2j'[
-|]'6Z
dB\K<y%
nVPj;d
xgGel[
Q?} FD_(
$^%QY86
:&;WVN
P#p'Q\x
$y<\E#
$}<\E/0
D+g5{
<\E-z{
4B{P lsO
eJQ6tyC
l#p'S\x
<Q/|Ef
x#pK\p
P&|O.X
%<\E7
:&;WV;
%<\E%OD
:&)WV/
%<\E%<
:&-W~k
l"I/Lk
%<\E9HN
ET`y8G
#pU\p
#p'U\x
#p'O\x
:&3WV,
#p'Y\x
SjjDU)
%<\E.
%<\ER)
%<\E1B
#p'U\x
$Wv!Ab
%<\E'!
#p[\p
m"-%&R
wi2r'[
((h1{Y
m0Fx065
((h1{Y
LL%E\i
((h1{Y
WRjw=N
oi2*([
K9i^M
zYUIcTWI
K9i.u
z"h9ETW
}#(cgk
(Dk*n|R
$u<\E%
$u<\EU
:&MWV_
P#p'{\x
P#p'G\x
`(T`n
:&-WVC&
T#pW\p
is: [a
&WW4U
$u<\Et
$u<\EK
@TGW|W
$y<\E3
ik"\KA\0iQ
is6 [a
qtYQn.
J7KTs$
d)?$.
:&3W~Z
#pO\p
X,#(i.u_wU
|KBu J
-#(cg-a
eJ/Br>
{r0S*+4Z
@@.TW^
_i2*)[
&WW\$n
lM%E\a
gj"B.v
lM%E\i
'j=KTU
L-@3su
rF"i'4Z8?
JcAp[#=
BK;4Zg4
rn![O4Zgu
#(cgj~
#pG\p
U`d<S9
a;7=XZ
Ef-$"m
+k2&}R
@V&eR/
,N@HXdC
WXC##(
|wBsS7
'R-TWx
a;mo1'
Wz'@gN
Qw+TWd
E"IRg
oi2j)[
?*+KT{'
I&#=Gw
3%p1F{G
r/h)#{w
+;mUSl
"^LgAv
Up7cvV
hi2z)[
Dgjr~/9<
Gk2x~R
t4#4SQCP
8F$+4@E
((h1{Y
1#(cg-a
-#(cgj
sXeB~I
$N%E\i
{P/r[{
Rm'KTj
1#(cg-a
_i2**[
`iNKT-
FN6!ZmC
5#(cg-a
!#(cgj
X%#(egz
!#(cgj
8I%EVc
1#(cg-a
y2\9t2
\IA@;Q?
((h1{Y
X%#(egz
X%#(egz
X%#(egz
((h1{Y
m2A3i+
R 4nKT
!#(cgj
1#(cg-a
u@c-=;w
m2XD9;
5#(cg-a
^r/4Z0
X%#(egz
-#(cgj
zzH9^TWm
DGLTWa
{i2:-[
-#(cgj
-#(cgj
wi2r-[
P/Xpx34
&WWS4P
\IA@1Z
!#(cgj
-#(cg-a
\IA@D}
4S%E\a
dS%E\a
((h1{Y
1#(cg-a
FTaxR-p
z/Y\NTWA
x^U*"m
X%#(egz
RHMlmKTW
-#(cg-a
u(&vp6
J96&#=
5I[q|Z
X%#(egz
%ZUy"$
E,#CR-
5,U%E2
tc\6\o
o4FNuFV
<[Lf#(
IA@[G
|ZD(*o
dX%E0b
4%a]8"
<+%[UyQ
m|ZD(*oir
.hFi$+
$UR.<
Z=9$CR>a
Yq|ZD(*oa
.hFH1>e
R)$tK
|ZD(*oij
<+%[Uy"
8[%EVe
U1{- MY?
j<Dld
E;G+%>
ZD(*o/x,
,%)}^><
Fi$, :m
W;+%3X
R2[py&
#-[Uz0$%b
9K`/?i{
@^@EQ3
8x*{5$K
J%itP
H-1 z%
3)4%3X
Yv$Pqh
#-YU%m;
tC)4%,
$/ K9w
DUCtmD
4#hDQX
+1[^y)
ZD(*oir
#5[Uz
M D$M)"k
#-[Uy/
(r:H=;,
q|ZD(*oir
|ZD(*oD
%W|$ D
*[7~[py2w
o;+%1
O_q|ZD(*oir
|ZD(*o4
+AU= @]
;OP+%>=
,B$=Xq
[5{&}9"<
|ZD(*o/x, z%o
|ZD(*o
nXUV_
)tG)4%a
ZD(*oir
U=DY;Y
hFi$+
]$DDMXz
n b)gEU
y>b$B,
Th_Fi$+
<z5T+i
hz5T)au
X9( <$
Z1Vccgj
|ZD(*o
>:U_eF
~[Uz%;
@q|wIG
A:PXq|
v'r!A$
<4OGy-
H^LiID
8ZDJSz
7mdy,C
6IbM#eB
jsPW[Vz
7jy+$SE
W5u^6O
BDe$p9O
e b r/
"G/fwE
)3u1c|
L6$I-+
77Oj?G
Ho9\E+
v6I\9Z-l
{-8swC
Pq,U]K
R%7&i)`
U<+\_<
ir}9M]
gu4uM6
_zp"j^L1
'$$T3!T
#FemFC
$~"D p
P!/h2i{
`3e'JD
HH&U@O
YV%F y{
mSgX@%M
EBM:ki
uzb7E~eV
mm1<rQ
riM:%py
nG{m]X
1TfvG:
Qi{7-B
J^~EE
cB}DRq1j
F(|3Wf
R'V}EV
V5S=Ye>
*)7$WT
b;v$~6
YDW*oD
ifM-99^y
m<Y`?]
$2Id+(
e@PrG^
X2pRDi
;.Bbdu
yo!"T[
36ogNQ
9M+N}%
^"t8)5
F{{ch"4%
(h.:79
S6CZVe{}
~41ZxT6_b
indNn`
a.HZGxdt
~G(+p.
kDv%hNmK
3`jyw
359[Mc
l{.0#v
,xX'8o
"55^5U
Mb Hj3
~<vVg&
F][m>R
`EZ[zw
-UW&al
w2^(u>
OH8oD%<
rK<>{@
'vH8h;
M/<nul
!Z4+Xj
&G6j]m
RBOl(X
"R:h;'
j&ayRI6
f}R5I,
<X'R'O<
&|g>A]
9!WL--
#22Gf@*^/L_
E bh*
vl_5H}
)!BKY3=
n|e%Wy
ZjA8;]G%
%:R8Ds
;4Tq~e
]jGqX
iYP|'D
l/Q#_n
)y[42ck
o)3m?n
-_|'-m+
]],kN(
0Xp/#JG
kYn4[_Y
IEvsII
Fa\_]7Y
j{>&,u
@)dvJ2
<KEBrV
GnE$VX]K
/u)yq>
EqR0Pu
6~4Rq4
-MS+b+7~
M)=Z^%G
9*OXn4
|=8ER)v
M3iqlC
Y(r!UG
[AF8)e
%}](4X
s?3l{Q
3O 2HzK
<$_ ~y
X6&^1
U1 i,X
eFCX5v5
z{+b$`
b7WMV
&>)ZZP
fzP7Yka
kkUS/
"I)a8A2
i#!\!@!
Fm[9'wy
bniwUd
<{<i}`
+p46/<i
.JA'!"7
QJnp@g4
OZpU\&
r@e?er
VvCXtt.y=
l9B,|@
2k'Gc}
h([^;\
)Vv)_,x
-Q{@%$-I
EX+Ou90
FCcNDro
Jfi@eF"J
K52>4f
,>$4"z
{ft8h}~
+mSCOP8
^eo>S!P(
~\57RZ
3F$h9l
I'AYH^
@tl/X4
sM,(}6b
.jJ9NR
6E\],:
7`A)@WB
nQ/:K1h!
<3$qR0
\@H)yp
>k+ixau
em5Z%G
[&VE:p
.$V6?|
NPPs\_
S'p|5
8cj{8Zc_$
'f,t~A
:-AvIK
O?90qWJU
?^NpF4x
&VDurqH
l~d$o:
5c1CF(}{8
OsvS/>
D!!(Np
v4>m60t
~d*"8[
FW\IAr
c'#Vh3
.?B]L!
07PTHd
Hc}iYU
pDkK1I+
vu,0GN!m
8C P?M
#Hcg_k!F
e0%bhht
pt!k@=
%Iydw/(
4%$zti
S{@QbY<
Ij]hTR
DI5eR`
wrm-{Le
X}0&L2
gTweLL
ag*K#W
h)Jm@&=x
_z_y$3
l,0]sJ
J_;Em?(2
gk@H#6
qs<z0Ki
&tq4Wc
bb*>`7
[qoV l3
_B?'eP
Ogk}xp
ePJib|
U!3,l9
dMr5,R
U|snB$j'
us"5w?W
f?"-)9
8{:D1k
GF:F:
WWBp3S
Bu*u*%
E>TIj\
Qb*3#wU
SFTJD
CTh#40
~~f.kC
e~[%Z&
J08hJ)
H"lNncN
q.m&AZ
Kb)+ML
PMUZcF
gSHNJ31
oV@mw6
K5]!gl
KuI{hk
6U<:G_
j!"A_Ah
Cv/cQW
SpdPZG
k/^QP/
Ke4L;~p
|3eppO
e(`4{\%
aNuP3u
t$Z-f(E
qgG=:[
pHU_9}
z1kyrg
_vk$9/
D=`mY*v
a3{I^l
ns|#Ij
=/{xyk
L;<X%^
X\*B14
h3v]P-
cRz1JO
Aw;pcQq@'6
vj}=h]r9O
kqv&)t
nOFbCj2
}c:-NZ
.bpR9o
-:q)Kk
/N96% X^*
4Gw/L8
+!r]-/
@-DG|2
%A@QIk
PwTC_B
F`I3~+Z
eUiK!q
NeE-G>V
x,huqz:8
X!%NDn
&_1}{Q
i4>ws8V
r:Y7k/qV `
~Zv#Ny
:%.hK^
;r3/3y
0L$(Em
VqmAz&
B@w^8d
^b3osZ
\fUp)JB
I`</wXEf
Pjh+6V=
mPL}s$#
vojzwV
4Il6^'
ooc+Cy
."RFQX{^
zt^+BO
/9:<5o
E7^h+\
3ZOQ\a5MyA
yo(#yL~
]0 ;`3"
,y>)0BQ
8 AAo5Yjo[iq
mj8-'u
XJ:<D_
p>NnTj
S4iE1.
ENvI`>|
#-z%1`
Act1v=
j?%LcO
fH%I#j
X==h;B
p!SlA[
"~C./9
;8ak8crV
9jv?$rce"
YVir%b
&x.S/[
c5BNHW
G_4CNH
BF@"NS
=Yx.Q0
9*7Zrn
XT),^5
b0uRf]
FSyd>8
{)pQ(u
uW^<%L
nipbDv_!a
qTBuf~f
mA{Ur7
Ki_dH+
J_f'ju
,b;^\,U\
{ldJqX^
$oP|@&
~+P##)E
q$X"_N
7}PF"|
0f=C0/!
C(k7Mo2[
-*]$At#O
ny}H0
2NW5n?P
Q|fa=,.
xxzPdsa
E"`qXy
L<:~JK
Sw^G$A
&c& ^p
Q;*S/iPGg
%b'%6p
-6![bl
)W@UGyQ
Dk(p2?i
71Rg^Z
je@Lh<1K
*AU!ikK
Rm wnz_"
Z!gMzb)
\"W&*G
=<[sU]>tT
9Hz6{k
&:KWN]q
Wk#eA&
|!6g,`^
Kyi^Y_
'i3\aC
oM$2BI B
Na-&lG2
<g= KoM%
qOH;/B
wOdxnK
!\IHu8
XWsiAX
i6z>!u
]"+csV
%N|jGd`
E'bB=y
NQ+_T
'=,rg.5
]m#sQ-
N3YyW=
z6`((>=Xz%
@|AQ[
bQDV#
E55jmQ
^#\;|q
2]`?Is
9D?'!z
NdxS0W
,`@J<A
[T*yiX
&&c@Q~~
Ve4p]g
m*g p36
&*s\`U_
V}}`&F
QZTCN)
OG{U\w
c)#7~"m
y+Y/}9
Eb"e7u
}[-u:dz
IAtFL.
[%;+i~
IQ.?6zd
''F`vN
dUy%}oW
+n"~(Cl
m$=2'j
OhOzvhC
@XxmaP
oEx&8H
,JT4K)\
(=:(/\ey
B-05EKBH
O=$=r+
zj$KvF
V-+v4phfb
D^l'YV
=5k,Lj
x\~j'$
nMriiL(
+"fJ B1
z;IQzh
&#Z7La
)<t:A`
nwLwqa
qsv5JY
T$Q;DQO{
xH2fMT^
9Ghp0\A
:iKzbv
osNTT\
uW^39L
ZI&>IS
M!<z11
]j\$J;
E|Tl3$j
j2QgvW
V8$w(
U\! D('kw1+
}r '"T
8bRaHZ@
lo/rZ)
-#eT;6wek
/RSKi)
JOPh7s
`Anw2z
7{<;A,8
JL#"JN
"w&d,P
a\3'2/
eX|xr(
aB4DzAU
D/S(gS
0KMOKpA
qPD=3s
>3w}m$
d>;kX@
-_y+c*
dMA=6^
*{'n>UPH
"b"W!c8
;#/C1Nr
;KOT]bO
A+@"4.t-D
SQ7ta{
GST 6t#
C>n.BF
,n[3V8f
O5D'8)
k04S,g
BX,S!nJ
e 6eu)
yv^a=[P6
@V@Ink
*ybGyQ8
fZ#RE[
r0)[s3r
B19A0:_
jHwsx1
>C"a.
"9qxIY
kcyiVu
@2*aq':
%hcz?&
=z.-0-x
Z=@$H]
x*xGn2u
W36W:t
4gMiB4
WjM(P5F{u
<B:#&5
2mp"bD
xUz5wa
86;-&!
0z;o'M
\UQfW%
;_TK-]}
39(w0C
(^.!!$
b0(83h
N0Vw5G
1M.) ~D1
oA!m+
&>;[]pR
@T/jZv
[CN.lr!
2S|8P)
z`|/U~pq
SG4Iz[,7,
)My;EZ
5[c'ah
}[iW|lKN
vCoEI
?\bnEy
9*`"kP
8$/P#8#
!HPTUVJ
m+oY(IN*
c0`G#
&k_3n6Z
S[*;UJ
-)DPKs
/5DA-i
28>Ha=
^pJ`to
6wdx>-
nYCb9U
(v2'6/\
O|^4pf
~-/rV<
62S7_S
ZO@ISf
6lJ<;*Fi|
E^{1^(
+h9-Mm
bFB}J=
%Z^Vu[@
ySPiUV
9'VvuB
&FCQVWE
!2v[OQ
*e`OBx
2r6 2<
~&T&1XT
iP7l`.
gfVT+L{
g]$x3.
nGC>4sJ
gto(''U
/`TQ\|
V\5{Q1
jM(D1
jC$ijf
Ybdc_!
T!Yx4N
gex_O3x
2"vVtO>
>IIVOWH
kl B[!z
\QKu&e
y_#6*J
}F'[a0I
EIAA^Y
sl:CB'3
%jRS8xO
J7*{%D
b*:D-Oa
~@_nic
BOJ~?<Ni
>;3rw1C
B12U}"*
:ACUOX~
e -O*i
+X*wrz6
0W8@W2
x*~Cm*c
>cy|NY"
CJL\_Z
H@B.Bh|z
"*JWz!
'{8iAA
2vSZRw9
dbt_48i
4"liyT
cO2}Vu
1m1ML5
JH)59&
(imSu3
$HyI@Y
/}\A _-
~v7nGG
8QPlKn@
VQc0gr8
kY7M=c
v&~1:yW
M>:#Iru
B4A-QoD
y$c@|;
Vz;>H!9
pg'Hjg
:vJ<u&
jCh5#I
mZ_}p>`
/E,_>;
RU!|21
,}C%wbd
p23wLu
0n=/t+
vl~*T1
>4hvZy
c&WP)FM
G0Zyvm
~Hr*JyE:
I3YC-0
|ppmNSY
_tjU\a!=`L
pbDv_!a
E-xji=%
>DupVW
IMS>yT]
h97Zyd
`e%4;j
>RC\pe_
W"K(Rg
#i{LN+ ~
%9+"~8]
FSyd>8
{)pQ(u
uW^<%L
nipbDv_!a
\^F$H-#>)udfW
(eoGqF
:U}JVQ
&#Z7La
)<t:A`
65vl~*T1
T$Y;DQO[
o4Kv6y
yb0uRf]
FSyd>8
{)pQ(u
uW^<%L
nipbDv_!a
:U}JVQ
&#Z7La
)<t:A`
qsv5JY
65vl~*T1
T$Y;DQO[
o4Kv6y
yb0uRf]
FSyd>8
{)pQ(u
uW^<%L
3%2'%S
hO2thj
hbnipb
%WeyEz
:U}JVQ
&#Z7La
)<t:A`
qsv5JY
65vl~*T1
T$Y;DQO[
o4Kv6y
yb0uRf]
FSyd>8
{)pQ(u
~H1C 0
6QPa9<XQ
.;9+{J
#ypk1o
]ndg0^
n F]s8=]
3:,)Ul
%=a>B_
iXrcOM
Yos^Dv
Ab;3x=
MN}"Cx
)Nct;P
Q&b;9qQ
TV/n,Z<
Ke*K^058%0
06lp6e
b/^-]o
`SFQOD&
PLS6OM
QcQL8@
:VPl!=
vt,FK7
-q&qSW
biztR35
#,Xn &^n
v*2mgg
a`FE#=m
M;9_No#UZrz
SFjrz)=
lxhkz$
vSo*'C
B^\O&uQ
`vdH3J
tB2xcl
DQcOMY
o*2o_4
9SIloO
9AXpsU8
=7+~hD
vwft*m
=o0PKGTJ
1)4\QrIc
-q&{/W
*3=w!=
Bx{~a`
\]nlLQ
~s}s%)(
lRYkz$
KyJ4;"
=nSG5
W_~@#6
Z(6O&$
b0f-`o
%F'}bg_
nY]h/9
j@}s-`~
5<'sP$KQR
%MCqVa
>,HpE]
8/DzyMN
y.:`-i
?kv"5q
+s]eb:
u_|2wHJ
kz,Y0d
UqX";'
q_Q$$iwP
Qfqsjr
-Ze@_=
>cIe3m\o
hHNs7IlS
KRjO,]/2
Z4n5nJH
}e/#Fm
l*bgP=
+<-`awg
~OCDz>
tB2xcT
uf'3qb
QAe'>+Yd!
aHe%`%
1+1mt;v
U[(3xW:
wwD)CR
o02IF^
=Rjr"@
CO>A>=
1;Amt;
!%I_^$
817Xg_
Lzl:1A@
kzdj=#
rtA4(R
xM2;,>
=(fO;'U
Eu^GBj
~z"5,#
8&^yRw
l-4k;1
2ZYrqp~j
dX z g
'Jmt;.
n'"UZq
}c)jHq;
,06:X
%%?ov`&B
&HNP9|
>cw JNgg
iO2q{:4,L
a"3cTW
UI&~x\
UiW~*"i
2"S np
hl+et/
]m+b`.
nme0G4&
g_EDe:
RmLQA@
LU; "Ne
>exU?X
hfKDT=
yy%'kK>
vQl!+u
iLP=S*
OWXmOMS.
>cJl2P
n!+~,_s
7n<"z}18
I"s }I+)
C8X{O5
P6=%o2n
'(Iw0:
s;9_OR
kDm\o5
#-;Ilz
1$&)a%
;TBEt[o
btYhc8
U.13xu
d]C@p8
Toz*l'w
iJr]5B~;
[:1|l:/
AKRjc$
=gC$~x
bMNGo`-
P5BC>9M
:jPl!W:
0imlqU
)|}f'3
(.Rdb*/
11.}4I
/16&P9
:5Gwc)w
%o27[MYP
DjiS)6
Jk'3qSp
u&4$If
QfiMY+
X`4]%
a=Ex\
4k*JTf
*Yy6Qz
c\jr3U-O
'?:8V\{
Q=R!o2
74XJ4g
P|j's1
56$bYp
B}y&)e
"R5r+9
Eg8)FQ
O,v(6N
xfB}m3
&%<kbG
#K! o0
_+fD}
vXSH*SNGn
M$N#?k
1G"6A((D
S+[ Co
fRjr>n
BUlm7$
]|l:xc+
V~m\o0
/!:r(pb~1
T)J@&+l`</
"QO?FzI
B>i3#S
`%8Dc.+m
W|L8U7
C|1PnZ
<9~sE2
6um0~hE)
5yl4}lD-
mD~|E=
rSrJYf
URPQQh
UQPXY]Y[
j"_f9y
t#VhdmX
tlj*Yf
f9:t!V
QQSVj8j@
PPPPPPPP
PPPPPWS
PP9E u:PPVWP
__based(
__cdecl
__pascal
__stdcall
__thiscall
__fastcall
__vectorcall
__clrcall
__eabi
__swift_1
__swift_2
__swift_3
__ptr64
__restrict
__unaligned
restrict(
delete
operator
`vftable'
`vbtable'
`vcall'
`typeof'
`local static guard'
`string'
`vbase destructor'
`vector deleting destructor'
`default constructor closure'
`scalar deleting destructor'
`vector constructor iterator'
`vector destructor iterator'
`vector vbase constructor iterator'
`virtual displacement map'
`eh vector constructor iterator'
`eh vector destructor iterator'
`eh vector vbase constructor iterator'
`copy constructor closure'
`udt returning'
`local vftable'
`local vftable constructor closure'
new[]
delete[]
`omni callsig'
`placement delete closure'
`placement delete[] closure'
`managed vector constructor iterator'
`managed vector destructor iterator'
`eh vector copy constructor iterator'
`eh vector vbase copy constructor iterator'
`dynamic initializer for '
`dynamic atexit destructor for '
`vector copy constructor iterator'
`vector vbase copy constructor iterator'
`managed vector copy constructor iterator'
`local static thread guard'
operator ""
operator co_await
operator<=>
Type Descriptor'
Base Class Descriptor at (
Base Class Array'
Class Hierarchy Descriptor'
Complete Object Locator'
`anonymous namespace'
FlsAlloc
FlsFree
FlsGetValue
FlsSetValue
InitializeCriticalSectionEx
CorExitProcess
Sunday
Monday
Tuesday
Wednesday
Thursday
Friday
Saturday
January
February
August
September
October
November
December
MM/dd/yy
dddd, MMMM dd, yyyy
HH:mm:ss
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
LCMapStringEx
LocaleNameToLCID
AppPolicyGetProcessTerminationMethod
?5Wg4p
%S#[k=
"B <1=
_hypot
_nextafter
msvcrt.dll
__CxxFrameHandler3
comdlg32
.text$mn
.idata$5
.00cfg
.CRT$XCA
.CRT$XCAA
.CRT$XCZ
.CRT$XIA
.CRT$XIAA
.CRT$XIAC
.CRT$XIC
.CRT$XIZ
.CRT$XPA
.CRT$XPX
.CRT$XPXA
.CRT$XPZ
.CRT$XTA
.CRT$XTZ
.rdata
.rdata$sxdata
.rdata$voltmd
.rdata$zzzdbg
.rtc$IAA
.rtc$IZZ
.rtc$TAA
.rtc$TZZ
.xdata$x
.idata$2
.idata$3
.idata$4
.idata$6
.rsrc$01
.rsrc$02
CompareFileTime
SetLastError
lstrlenW
GetUserDefaultLangID
SetEndOfFile
lstrlenA
GetModuleHandleA
GetSystemDefaultLangID
OpenProcess
IsValidCodePage
GetThreadUILanguage
LoadLibraryA
GlobalAlloc
DeleteFileW
GetThreadContext
GetProcAddress
GetProcessHeap
CreateProcessW
lstrcmpiA
GetTickCount
GetEnvironmentStringsW
OpenThread
KERNEL32.dll
IsIconic
GetParent
GetDesktopWindow
IsZoomed
IsWow64Message
GetForegroundWindow
GetDlgItemTextA
AnyPopup
ShowWindow
TrackPopupMenu
GetShellWindow
IsWindowVisible
OpenIcon
USER32.dll
UnhandledExceptionFilter
SetUnhandledExceptionFilter
GetCurrentProcess
TerminateProcess
IsProcessorFeaturePresent
QueryPerformanceCounter
GetCurrentProcessId
GetCurrentThreadId
GetSystemTimeAsFileTime
InitializeSListHead
IsDebuggerPresent
GetStartupInfoW
GetModuleHandleW
RtlUnwind
GetLastError
EnterCriticalSection
LeaveCriticalSection
DeleteCriticalSection
InitializeCriticalSectionAndSpinCount
TlsAlloc
TlsGetValue
TlsSetValue
TlsFree
FreeLibrary
LoadLibraryExW
RaiseException
GetStdHandle
WriteFile
GetModuleFileNameW
ExitProcess
GetModuleHandleExW
HeapAlloc
HeapFree
FindClose
FindFirstFileExW
FindNextFileW
GetACP
GetOEMCP
GetCPInfo
GetCommandLineA
GetCommandLineW
MultiByteToWideChar
WideCharToMultiByte
FreeEnvironmentStringsW
SetStdHandle
GetFileType
GetStringTypeW
LCMapStringW
HeapSize
HeapReAlloc
FlushFileBuffers
GetConsoleOutputCP
GetConsoleMode
SetFilePointerEx
CreateFileW
CloseHandle
WriteConsoleW
DecodePointer
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
GGJY\^a
4%454?4R4_4}4
5(565<5O5l5v5
6[6d6k6
6+787S7Y7_7e7k7q7
8$8q8z8
9 9G9Q9n9
96:=:C:I:N:g:}:
;';.;3;:;@;I;P;];
<!<+<4<B<O<n<
==,=W=a=t=y=
=;>N>U>[>
?$?K?Q?q?z?
080F0Y0|0
1!161T1j1
1%2B2H2O2t2z2
3!3)3/353;3A3I3O3U3[3a3g3m3s3y3
4E4d4|4
5(5C5K5Q5y5
6"6E6L6U6z6
7.7]7s7z7
8#8+838]8l8r8
9Z9g9m9
:(:K:_:r:
<,<:<A<I<N<T<
<D=K=R=`=h=
>%>,>2>8>@>F>K>Q>Z>
? ?4?@?~?
2I2c2l2q2|2
373=3C3H3~3
4G4R4\4
4.545u5{5
676X6x6~6
7-747Z7j7o7
929[9h9o9{9
:#:0:7:V:\:
;+;K;q;
<A<K<S<
=%=[=e=
>+>?>Q>Y>c>o>
?A?T?i?v?
0&020?0E0N0f0
1[2w2}2
2,3D3L3Z3`3
4&4,4c4
6$6*686[6
7#757;7E7K7c7
9H:O:~:
; ;+;4;@;F;Q;];e;
=3=a=q=
=G>c>j>
Antivirus Signature
Bkav Clean
Lionic Clean
tehtris Clean
MicroWorld-eScan Clean
ClamAV Clean
FireEye Generic.mg.4adf9b20011bc571
CAT-QuickHeal Clean
McAfee Artemis!4ADF9B20011B
Malwarebytes Clean
Zillya Clean
Sangfor Trojan.Win32.Save.a
CrowdStrike win/malicious_confidence_70% (W)
BitDefender Clean
K7GW Clean
K7AntiVirus Clean
Baidu Clean
VirIT Clean
Cyren Clean
Symantec ML.Attribute.HighConfidence
Elastic malicious (high confidence)
ESET-NOD32 a variant of Win32/GenKryptik.GHCR
APEX Malicious
Paloalto generic.ml
Cynet Malicious (score: 100)
Kaspersky UDS:DangerousObject.Multi.Generic
Alibaba Clean
NANO-Antivirus Clean
ViRobot Clean
Rising Trojan.Kryptik!8.8 (TFE:5:td19bmHh0BM)
Sophos Generic ML PUA (PUA)
F-Secure Clean
DrWeb Clean
VIPRE Clean
TrendMicro Clean
McAfee-GW-Edition Artemis!Trojan
Trapmine malicious.moderate.ml.score
CMC Clean
Emsisoft Trojan.GenericKD.65839359 (B)
SentinelOne Clean
GData Trojan.GenericKD.65839359
Jiangmin Clean
Webroot
Avira Clean
MAX Clean
Antiy-AVL Clean
Gridinsoft Trojan.Win32.Gen.bot
Xcitium Clean
Arcabit Clean
SUPERAntiSpyware Clean
ZoneAlarm UDS:DangerousObject.Multi.Generic
Microsoft Trojan:Win32/Woreflint.A!cl
Google Clean
AhnLab-V3 Clean
Acronis suspicious
BitDefenderTheta Gen:NN.ZexaF.36308.LvX@aSdD3opG
ALYac Clean
TACHYON Clean
VBA32 Clean
Cylance unsafe
Panda Clean
Zoner Clean
TrendMicro-HouseCall TrojanSpy.Win32.RHADAMANTHYS.YXDCHZ
Tencent Clean
Yandex Clean
Ikarus Clean
MaxSecure Trojan.Malware.300983.susgen
Fortinet Clean
AVG FileRepMalware [Misc]
Avast FileRepMalware [Misc]
No IRMA results available.