Static | ZeroBOX

PE Compile Time

2023-03-10 16:04:48

PE Imphash

7f0af1292970a516afa467fdec16d6c4

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x00041480 0x00000000 0.0
.data 0x00043000 0x0000008c 0x00000000 0.0
.rdata 0x00044000 0x00125860 0x00000000 0.0
.eh_fram 0x0016a000 0x00007e68 0x00000000 0.0
.bss 0x00172000 0x00000200 0x00000000 0.0
.idata 0x00173000 0x00000ff8 0x00000000 0.0
.CRT 0x00174000 0x00000040 0x00000000 0.0
.tls 0x00175000 0x00000008 0x00000000 0.0
.pdata0 0x00176000 0x0059f2c7 0x00000000 0.0
.pdata1 0x00716000 0x00000580 0x00000600 4.67645411281
.pdata2 0x00717000 0x00bae560 0x00bae600 7.98656281764
.rsrc 0x012c6000 0x00008d6d 0x00008e00 3.56187016939

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x012ce404 0x00000468 LANG_NEUTRAL SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x012ce404 0x00000468 LANG_NEUTRAL SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x012ce404 0x00000468 LANG_NEUTRAL SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x012ce404 0x00000468 LANG_NEUTRAL SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x012ce404 0x00000468 LANG_NEUTRAL SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_GROUP_ICON 0x012ce86c 0x0000004c LANG_NEUTRAL SUBLANG_DEFAULT data
RT_VERSION 0x012ce8b8 0x00000338 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_MANIFEST 0x012cebf0 0x0000017d LANG_ENGLISH SUBLANG_ENGLISH_US XML 1.0 document text

Imports

Library KERNEL32.dll:
0xb16000 CreateEventA
0xb16004 CreateSemaphoreA
0xb16010 GetCurrentProcessId
0xb16014 GetCurrentThreadId
0xb16020 GetThreadContext
0xb16024 GetThreadPriority
0xb16028 GetTickCount
0xb16030 IsDebuggerPresent
0xb16038 OpenProcess
0xb1603c OutputDebugStringA
0xb16048 RaiseException
0xb1604c ReleaseSemaphore
0xb16054 ResetEvent
0xb16058 ResumeThread
0xb1605c SetEvent
0xb16064 SetThreadContext
0xb16068 SetThreadPriority
0xb1606c SuspendThread
0xb16074 VirtualQuery
Library msvcrt.dll:
0xb16080 __getmainargs
0xb16084 __initenv
0xb16088 __lconv_init
0xb1608c __p__acmdln
0xb16090 __p__commode
0xb16094 __p__fmode
0xb16098 __set_app_type
0xb1609c __setusermatherr
0xb160a0 _amsg_exit
0xb160a4 _beginthreadex
0xb160a8 _cexit
0xb160ac _commode
0xb160b0 _endthreadex
0xb160b4 _errno
0xb160b8 _fmode
0xb160bc _fpreset
0xb160c0 _initterm
0xb160c4 _iob
0xb160c8 _onexit
0xb160cc _setjmp3
0xb160d0 _strdup
0xb160d4 _ultoa
0xb160d8 _vsnprintf
0xb160dc _vsnwprintf
0xb160e0 abort
0xb160e4 calloc
0xb160e8 exit
0xb160ec fgetwc
0xb160f0 fprintf
0xb160f4 free
0xb160f8 fwrite
0xb160fc getc
0xb16100 longjmp
0xb16104 malloc
0xb16108 memcmp
0xb1610c memcpy
0xb16110 memmove
0xb16114 memset
0xb16118 printf
0xb1611c realloc
0xb16120 signal
0xb16124 strlen
0xb16128 strncmp
0xb1612c vfprintf
Library KERNEL32.dll:
0xb16140 CloseHandle
0xb16144 CreateFileMappingA
0xb16148 CreateFileW
0xb1614c CreateMutexA
0xb16154 DuplicateHandle
0xb16158 FormatMessageW
0xb1615c FreeLibrary
0xb16160 GetConsoleMode
0xb16168 GetCurrentProcess
0xb1616c GetCurrentThread
0xb1617c GetFullPathNameW
0xb16180 GetLastError
0xb16184 GetModuleFileNameW
0xb16188 GetModuleHandleA
0xb1618c GetModuleHandleW
0xb16190 GetProcAddress
0xb16194 GetProcessHeap
0xb16198 GetStartupInfoA
0xb1619c GetStdHandle
0xb161a4 HeapAlloc
0xb161a8 HeapFree
0xb161ac HeapReAlloc
0xb161b4 InitOnceComplete
0xb161b8 LoadLibraryA
0xb161bc LocalAlloc
0xb161c0 MapViewOfFile
0xb161c4 Module32FirstW
0xb161c8 Module32NextW
0xb161cc ReleaseMutex
0xb161d8 RtlCaptureContext
0xb161dc SetLastError
0xb161e8 Sleep
0xb161ec TlsAlloc
0xb161f0 TlsFree
0xb161f4 TlsGetValue
0xb161f8 TlsSetValue
0xb16200 UnmapViewOfFile
0xb16204 VirtualProtect
0xb16208 WaitForSingleObject
0xb16210 WriteConsoleW
Library user32.dll:
0xb16218 GetDesktopWindow
0xb1621c GetWindowRect
Library KERNEL32.dll:
0xb16228 CreateEventA
0xb1622c GetModuleHandleA
0xb16230 TerminateProcess
0xb16234 GetCurrentProcess
0xb1623c Thread32First
0xb16240 GetCurrentProcessId
0xb16244 GetCurrentThreadId
0xb16248 OpenThread
0xb1624c Thread32Next
0xb16250 CloseHandle
0xb16254 SuspendThread
0xb16258 ResumeThread
0xb1625c WriteProcessMemory
0xb16260 GetSystemInfo
0xb16264 VirtualAlloc
0xb16268 VirtualProtect
0xb1626c VirtualFree
0xb16278 GetCurrentThread
0xb16280 Sleep
0xb16284 LoadLibraryA
0xb16288 FreeLibrary
0xb1628c GetTickCount
0xb16298 GlobalFree
0xb1629c HeapAlloc
0xb162a0 HeapFree
0xb162a4 GetProcAddress
0xb162a8 ExitProcess
0xb162bc MultiByteToWideChar
0xb162c0 GetModuleHandleW
0xb162c4 LoadResource
0xb162c8 FindResourceExW
0xb162cc FindResourceExA
0xb162d0 WideCharToMultiByte
0xb162d4 GetThreadLocale
0xb162d8 GetUserDefaultLCID
0xb162e0 EnumResourceNamesA
0xb162e4 EnumResourceNamesW
0xb162f0 EnumResourceTypesA
0xb162f4 EnumResourceTypesW
0xb162f8 CreateFileW
0xb162fc LoadLibraryW
0xb16300 GetLastError
0xb16304 FlushFileBuffers
0xb16308 VirtualQuery
0xb1630c GetCommandLineA
0xb16310 GetCPInfo
0xb1631c GetACP
0xb16320 GetOEMCP
0xb16324 IsValidCodePage
0xb16328 TlsGetValue
0xb1632c TlsAlloc
0xb16330 TlsSetValue
0xb16334 TlsFree
0xb16338 SetLastError
0xb16344 IsDebuggerPresent
0xb16348 RaiseException
0xb1634c LCMapStringA
0xb16350 LCMapStringW
0xb16354 SetHandleCount
0xb16358 GetStdHandle
0xb1635c GetFileType
0xb16360 GetStartupInfoA
0xb16364 GetModuleFileNameA
0xb16378 HeapCreate
0xb1637c HeapDestroy
0xb16384 HeapReAlloc
0xb16388 GetStringTypeA
0xb1638c GetStringTypeW
0xb16390 GetLocaleInfoA
0xb16394 HeapSize
0xb16398 WriteFile
0xb1639c RtlUnwind
0xb163a0 SetFilePointer
0xb163a4 GetConsoleCP
0xb163a8 GetConsoleMode
0xb163b0 SetStdHandle
0xb163b4 WriteConsoleA
0xb163b8 GetConsoleOutputCP
0xb163bc WriteConsoleW
0xb163c0 CreateFileA
Library user32.dll:
0xb163c8 CharUpperBuffW

!This program cannot be run in DOS mode.
P`.data
.rdata
P@.eh_framh~
0@.bss
.idata
.pdata0
`.pdata1
.pdata2
`.rsrc
%gdstn
yfp<(o
_c%?odR
b1p3eF
rgaLB`
_^^A_YZYX
AqiFc`[
sku't'
3}yLfF
.Q?d{wc(
-$!W<g
iK&)n[
ss,GSv
ifLv*eStt8
~I/ YW
[l,t&J
Gt~vGn
SystemTimeToFileTime
@$0v\f
KdWMu?
7'Fyzx
Z(hJhj
M.)^=M
=@%V<i
w]QSi,
ezZ^#n
WriteConsoleW
$at9!+
=t`D&`
.6{7O!0
Qdnsd
JT&16]
7nk^&\
jB2>NQU5
z-ml>{a
S9DTYS
mrBC+fn
=:\X1t
nb]6-b
rU<Bi4
TryEnterCriticalSection
A\AYYAYZ
Vbph51
dVtR{
VRH?&1
QhR$)L+
'j@SD4
P4-oqg
m#~fFM
Ul?)Bd
hMrj=
)83YP2
^d@njE
qhodras
/@Z?|z
CJiWz7
5]NbfG
_YA]_X
_Oh.HO
M(sJtTq_b
6qwzj{
Z/^jMt
V,PM4o4
S4Hj":
C#pw0sE3u
B:tqBH
?cr$:%6o33
^n1$d7
VZUhG6
J41e`F
vKNP|\
"RQ"aE
1Ly}a7`
a}4O0t
j|%?Z{R
ASEgR@
0ksR(I
6v7Ks_
KH8x{Uf
^t{s5:^
d$ssE2u=csJ
Ol6R+
du7l5
Eo?^Gy_
Zo{Z9i
V-"!T~
 u}-*
/?<(HB'
`A&`/!
U*.wmjr
hur??O{
!$E'aH$M
WG)kY_
IU*sW%
Q5g-FJ
cpksZ(
X]cL_
)s)H.~
:4DQri13
RYZXYZXY
e6T[kb
memcmp
lMQR*h]
pw#>d"
gL^I}V}
GetFullPathNameW
%u5D
VtFy61:
=!e*ML
V${1W]
On0XH16m3
;@wt3eR
.Lxa,a
aC*)V-
Hy,R$h[
U`,e=])
8F-NO,
js"Hr|
/QW^46+
@I]Zaiw]
Q)^n226
+2xjy}
/=In?3w
z[6f##c
X5^4q>
P"GG|z;
c;QCacg
]SbX5^
cv`Afc
kM^G ##r|Y|
OS#/jWg
qD;/0[
3-`Rv-
ZZZXZY
umSX@S
_U?[`w
\k|dL2NW
e%2mp^
SI'VX,
fB)T,&f
XYZXXZZ
aK@wkd
>|'H,X
;4vgHA
`SA3MZ
nv^Sw#
tKY+GY
mZ@ey)<
s~z{/4s>
v&Nd%J>
!_WZ`Zb
f#1w|;i
Kr7h!
V>l4:}
1!.Y(R8{Q
j{B^;"
[ez=kb
va>NFfI
~\4axX
PwtU[P
*11NjE
R("jVU
COaDHT
~H$UIH
/Gw/<-
:l9L;*
u$<|z#
$"3$CJ
3PKMGoR"
4]%e]_
Xy4I:F
!grLFVz
}rqHkI
p^}-,a
sNl1DE
6gy-D
3W~IA1
#_h'll
:2lQWT*9
}dPBHK
PP#F8i
@[E`/
j&*fE3
3Cl1TnIHZ
{n1sD~
SGx&1,
O<'-[^
]f&#
PLFB"C
/n@0iV,`_
0+W?lz&N
)88k};
V;-'P|v
V%e+HO
q*I%;q
U9C/91
0f8h$F2
LOXo=zR>
t,XAZJ
]ATAQN
]Sh7F?j
uHH18R
m\{]n*
Ri'0{=
JeB0xEU
}-DWB\
N|u>bG
Sk&ork
'?Dl8-b
Hi@4r0
IpbHFI
@=mE{W
(eq>s gt
$W&ck2jm
JbH ~8
?RveE|
c_X6uMe
YHIyMd}
WaitForSingleObject
CreateMutexA
Af5.R2
$:x'*-
V9"t~%
?}mP#\
{J31.=
ro$W^[
>HTq|[
6H/'aOf
$0gHJo
[Y0\5Y
[+E`d:
HH$OFq
b$=5B
tp{2`Iw
uks?
qj,m:zc&
8"2+dM
B'qU>
Pkv50e
O+WOG
DST090(ci
z~'`g
Dun+s@N
,%AaP==
,%AyaN
,%AN6;
< n!9X!
574(ox
xm#+&)pKL
0KLgUg@
F+2!V/
RZ8l[2
L@G3TH2
O\`+Yw
8g;^$|
ZYXXZY
_D<IXl
PI_qzJ
+SMrj
#E(M7)
@YVw]U
Yx8h!&T
[ejY7
:F9{]+P
,=tfBS
a}2-QzE
Lyv^|~
j|#];u
d_1mP&
rMniGr
t8N#P^
/O<^sK
xDw09b*
bgv[o$S
c?>Kza
/rT=0P
_G523v|
N*%oN_
$B"Wfmo
@Zr{}6
x!7E].
#1^20;
U"eM&;>
q!>Xq]e@
(RJ5q*
qEV^<o{}@
\\%t_q
svRu8b
U%ofiu
/%m7[=
Glas%q
%AORCn
%u >N3
RAm$)t*
!jar~u2
ITb',f
)}6fMC
>"v_R%y
Kz,h8rr
H1wN:E2w
rc3Bn'
ml`aIe
&4Sx K
b3BYMQw
CeTttN
F!@TzX
t{{0rI
FEwrt.
IojZT
pD((w3
DqPgtv'
2a"2jf
"J"kns\
R#\0-f
ZYZZZYX
grrcep
Z+{vZ f
X\:~SB
1gul%X
kBZ3AbB
OfQ UUQ
$PpT^i
SO:ag,
n"ln8n
.wE,Qghb3
"GBDM5
$L#2}sf]
zu%TtV
&0;=N<
(lS;8U*6R
?=WN=cC
kWi:L(
00T!dN
pQcp&q
PaQGUr
Dx]PX5
U9@?t
;gm!mC
5\sO2.
/pE_gU
z`y@AT
]@0'Pl?
J5TeP5
>~Fs}un
SX;sVt7;
"8"R}z
MkJnVe
o?5Cf}
GZhlC>
-x>Uh#v
X.Fv]c
_cZ(II"
v/t(gU)
W*#,I&
unCdp\
.GwvX^1Z
N&.P!V
)Y^].NSBo-
]JiIyR
DQTT\?\Am
V+!-`=6_
DQT*5|
DQTE05t
c=secm
c=&nYX
oFc0+S
~}G-+
u|}il"
Pf&}u?
B:|9EH
<,m!c&
<%b&Pf
SM81p7
v@T6nW
`RPEyP1
16kj{;
a3;yA>
p3^jd/
V)z'.f
=R9(cJ
b%1}N?o
@C+js'!
K?X%|p
ItzOcyy0
.RF5Kd
TQWD&ds
<])0D*
y9#s1q
hDj10-
YYYXZZ
x1XBgbN
(chs!@K
4p=EL5
gvg|$~
pEq1KTz}'(
IBN.^
i6<da|<L
/\H>@-d
9/M1UO
`TZ4M]
pO]U4^
T#<jl
MultiByteToWideChar
2LP"xj
j1gD(j'
}qSS::E
lfeG3yR
W8M|VL
|P5@UE
3]Sk(
pOU\qR
*)y"0>8q
OutputDebugStringA
xi6[{P
Br(sI!
|;P^|dC
AmDS0J
XZYZXXY
(*zS;^
\K@r#[{Y:
d7\P/a
rVa58.
lY1kAU
R\@[VK
Zd=#6bC
c$A0uU
]Lfl!0
~.`@Z?
Ebkgue
NczXCk
YYXZYZXX
XZYZYXXY
ZYYZZZ
f Y$V'.
PL@U`K7
e%.28p
pf4bF`
2HzL%k
D"mR'Ng9
wpr0Hr,bl
af}%VS
*]N'48D]q3]-
]%5@U
53KJ>MT?+
0eT J~D
^Y{R&z
>Mz?O_
.a[&;?
eqZj\*C
-Dzm5k]'
0H|?\n
qtj`F>
bQsL@-
'W&1KX
Oc(RM
>h"p8@S}:
u$nFTYznz}
b~_x+=
2,\|nc8
Au,%!R
/79ekW^9S4
LYcD9o
-r" \_L-
C-|DAs
J4v.yk
xav|c}3
gnvXrp
o >hTI
t}B45
m+h!$@
:c ]:^
U=lE}n
KaT%C5
lI"l=Y6
3W7CpQ
DXA,p'
:/`C]`
jh4VG0
b6}F0\6)
XKA;t~
X/d9@2
#_y9`e
~A58FE
26x^R_%
memcpy
E"@Eu%7
xOHD)F
/OM{H:
sNY4CI.
GnMjzC+
SsC[c-yI
JR0ZxP-/
V+sz:U
6'{S_Vm
_w7236L
@B~B(\
*=/X`I
9^rr<H
AYYYA\
{*?#!x[
-JZ^,-k
VF,/NV
9uMp|
_ZA_^A[]A_
n'd%\U
5waQI$
\f}q5f!
BB.co=
GsPZSK
- .B".
h~@OQ_\
D2Z$O%lSh%
9|y,EH
F\]6A0
?g"x]%
Aty^l"
O>~_kcF
i$zJ)=j1RH
B$ml_9
X*)|5s
0=^R#P
$F6> }
%kY"KN
Ysa~_Y&
rr3@pKu\
v#}Ch
&cKGhq
p!tduI#
a4S$jQ
a!2u0Z
ZZZXY3
Cs"whdQ
O7Wq eM`
y~*F|*0
Prf=-1oe
YYYYYZ
r_-NkX2s
BzxLhUty
DCs{5p
5d[{Yk
+RaZ'3#^
JV8Dy5
TY8UEO
Hr7V39
5,jxhY
FzO{DB
A{#Up&
Rp@fDWm
k#*91VE
WA#Z%I
0^D6^@
(W$\ZX
940rE[
b&v12;
IMI^'4;
"W;/#&1
W:(NU'
n"-d/S~
XNR;LA,n
.8<ZQ{
@_{h1hp
Uvr9_orO"
scr`'co
'%8{mK
{UA0KR6
M9XA}>/
])Bx2l
+3|7q1L
yvN N!j
;BTfa3
a@aI-Z0
kiA&y>L
VtrKw0lur|
u9\GRE
o(%W3
-*`fLae&
myk,k=o_>m
OTap|O.
P#K!`
bc@l6Cv
8Wup 19
yj0:QPT0>
b'\HI~
n,k@dp
=~"d@c\!
M,6p6"
-7/\5Q
``||A"
ZI/OZx
XqN+nf
vaOW#"^
\twFg/
YHJaB2
IN&e0e
rSV<8=
.^&VN`
,hH=&b
h_?Q{"
!~s|1[
y]1Ijxb
FormatMessageW
d3`C'Xe|
A'4HB+@
=@'M=-mY
L4gu:<p
&#qk[z
jER e[
WwV=z-
+jmFw/
Module32FirstW
a]5GMc
PZ/dg2
kTgBCl
HpkGv;9p
oYV]_^!
4[c53,
Y5O,i28
Ve{GWt
j>QX+^`Q
x+Mr&$
I<%$X
'.9*UA
k2H~//{
2:L/X)
(27jar
`BJx\
%rw}L_
5s+4n-#V
WxQ!4G{
C_(1/|
YZXYXZZ
PQ"~|
HWE?m=B
|P vhy
fgetwc
3fn[zH
laDe\f3
;aAZjh
,$B1t$
`m+0W~
3Co!Ia
ig^Dh*D
r?{{GN}ku
Y4V(vS!
QPFK9f7~<
Ayqq'\[n
&DCyhPl
GF_/Sy8
N]HC5~
xt;39?
B([-P2
1C}E^^
(G+n6C
c-$OS}
Q|m4t"
O36} o]
U3rGu
tWUZg&
]YzT\1
-@&$nI
0$.UHY
Ppjk0G
K&4NN+
lA^AUD
,dG3$"f
J|p`JQ
4sqq)fdT
+l77tA
Ur}E*
lPlYz@
QueryPerformanceFrequency
d%|'3q]
CD3623
A[A\__
&GWjSP
W9Je[I
/s?E<<
XwI0<h
+LG=<V
6N+oCA'`
hZLdX!
^hqZ^U
<1v]Dv
LI\Dv#p
r%,5e
'^0P&/
Bm1wYC
py]$*
7.lL:,fZ0
d?7du"
T5kIw7f^
AX<7nMr
*VxQ-G
>x;JtX
:of#L$
RaiseException
)73pT6.'
#JsT[ANY8u>
76UEXX
[(tMr%
MNK2LT!
u]5jI I
oLrcYH
AX1uxn("W
*91uxn
I<X?JZ
77gvuH.
A8@2BEH@PX
4o)R/s
rt]/J^
20%U?0b
7}]0og%
K 7V94=
Q9q(zV
S=J#8#
d U^gw
p,G;h?
R!z`XA
$XYZZY
F=]R&ULx
G|$%yr$@
fjQ9nN
F;riPyz
Gl7p=$
FT\SvS+
p8E"@?2
lR]}'
IxOJuB
qng2):
O [| t^l
pBwYa[u
@@.;_2
7d#6r@e;
hn-n'ZY
(U=UC9
cqI:mU
gV|j&~
GetEnvironmentStringsW
3h/ mt
lk!|ac
gj0CWmG
Jnt0zi
??T5XP
2A/f%<F
CG_X\M}
/xJR}w
/5+7J5
K#{}\C
OiVL +3a=
h"$>sP
aLt0'+
~|Eq1s
~?Vr0+
Oa*AOl
cQ%d.~
Et@fNT
YYZXYYZ
Cr@j#b
uHm)en1
Pc %]1
!Axw=%t;
v4&)96+
M7KOb5
Vd#H_p
BGXR<s
ySkMgO
53+ELN
`8$a6R
H6y`\b
*I(,H0
i5!qHV+3
+g+TIY
|$)pf}
gJd8^p
3{[D3Df
my^M#
};dH%Hc\
O{=_ 9!
#^pF(U
Tw]@k^
YYYZYZZX
BaY[FJ
Y@Nm1\
Q~'Dg(nC
G+88H"
*N? *z[
*!lHJ*
^)q{8*
A=]y&v
h~3\CYx
kM%q>
PlUIL$
!Rr8RU
RhN_`
.Q/!phe|
^abxj:
zH2dEH
zvN"0n?
}!7pAW
` ni /
5BsdD?i
K?Y_%]G$
qW#_,*o
S>yO5I
N\rs2_
RCih-R
N|uQRx
r&o]%ZE
4MV9}v#
qcJ&Bg
TMG?-+O
Ho-4xhZ
n9{$iN
ekiGUl
ReleaseSRWLockExclusive
GetCurrentProcessId
qvQWAq&
["/t
,,>`3m
oG=0h0
\nSrli$
vfprintf
sp6dQj
La#zI:
)h30I5"
i;mkeX
=+dC}Z
7E4q\Q
N^^r_n
YZYXYXZ
AU%.pb
36LdkZnkWg
6AOFS^
__setusermatherr
!>p}wf-C
44uTr|
Rj@R;R/
LM4<V2
6{Qt7+
KEwH>pp
/*JKTR
-Gs$,a
\JFfA+
*DFv"l3W
3[[MID=iw
yt'o+4
0DL|Ob
"$U%WBc
q,Y^2]
SmO!Es9e
>NET)C:
yh E6u
OZXXYX
r?+k[^[
HeapFree
6$IOt6
)cs}p:
Kx$^QT
2NQAsD
? \S_R
TlsGetValue
7-iUDl
1(L='l
Vn0<tz"
<|;b<u\r,
&+3Dzf
FlushFileBuffers
$*SNo~1
x.Zrx$q
BKjL0Rd
7&+h>l
2WO!qx
ma+xzGB_)
m.m}|\
,Wo>~
hlSCb\
%4OSkI
@Mxt|mV
kxVc:q
7yB,fp
`}zt]P
^^]A_^A]
XZYYZZZYXY
7c>dTc+
d6vR"Z
&!ZJB4
gOmXYL+
=r+'ga
=rG{3c
}5*uu["
`'9'%}%
gsr.,R
dpja)d
q8SK 1
aQ9QVh
LU[J|R,
z9B;J>5
czvT^F
VirtualQuery
wXlvz:
%0+G(K
n:M-T:
E>%;%Ih
h~CsV~
PXXZYXZ
A\AYXYYA_A
LJou! )
S e0rs
`VyZ4{
6+YM'b
+3kg2*
3/N7K}
u3aj7u3@
S+~|:4
U}vIzk.G
wc^J]M
(4q7=z
#>wm~/
3/?>qK
xJ!)Ce
)6?R\$
O|X~ <
c<$Y-Y
@rE!ira1I
>f[_-Y
xU1|S,
)U8{[
4o;K2
_20}1:
T]#BxV
u<FVUy
[iA7!0
k(KJ:!
VECKfB4
`)Z:P.-3
3v'J07
7Su'3r
fC^}{S
!_}4yNm
|P^X`
AOB7V"9
"`"`01S]
m>V86O.Z
d4Thbv
6:2@2~K4$
dDF36#
InitializeCriticalSection
aXYZXXZ
b_MqsJ1
jE5Q\G
2H>z}n
|WIqV?
GetCurrentThreadId
<(;ABBn
:z[J-2
s25wmx
c9CGO
m7y4R`
Pn:ZC6
O&'Ha %
[Y,]
6)g+<N
ylt),5
Rd)bOi
HeapFree
>^j?GZ
clTqO0
0`o5jj+*
]&Gfc
4W'4:H
9(@qA5
*-?,2W
+Nlgz\*{
j:57"rj
DaA(D'
|1%_&j
}.SI3O
pksc}\
VEwQ,1
XXYYZX
GetLocaleInfoA
cZZXXZ
)Y0U$
f&;K_M1
_uy9^/
k>+8dyC
$P{@9+
uk-tm
dCuj9R
a*ebwx@
GetEnvironmentVariableW
DeleteCriticalSection
"(>+:z
%cx6Zk
U$Y4<
A-0_dh
$^66x`
%N*Vz(
&8R|}/~
uFm"`p
xfw,|o
dQ(3(Q
w'CbRJW
_cexit
Brzvru
8v;u5~
^,l_?&
Y)YOoUu
XXZXXZ
]8^85W
F5?0;
"Q+/%W
PY+OV_7~
cZ.a~v
aPs=(
qWTQ?c
/pg(!Q
JZYZXZZ
_t{9bHxgu
__>D\328
-Xr)@z
JL:9!z
W@p"*B#it
N2{J;~Y
PSXx:cZk
(>`u]'x
GetStdHandle
B5"A?R
m>&cwc
("_=0j6
}nr6an
X<w1=^
ikv0s`op
(tLOtI
nA<q3T/t
aX_j(D
ohq|3
Y[8F)j8
U-1tbr"/
o"y8O6
,_R_U;E-
sqC8"MqW
Q'MpQ+
-0#^QI
W0+F%sW
fIfSo/
6iAHfO
!NJ463
4^7GQw
`\:ZYL
N8&!<bo
6)Y.E)X
!skpT0|<
$jSe`U
sI=ge<
+c.l^=
}F:O-!j
:Ex<=2
P;Q7`<&
fWHFVP?
[Ccj# /
\).SG)u
;,P%=%
^RQtUV
d~e\]K9
%-s'kp
4y>|@m
r\UQ.H
>!mJ-yR
NPv"_6
t9J-Em{C
"+l%A
(4mUWU
D_/ex_O,
h"ZwfR
VM` ~X
N}\TYu
I)@%D8,
>+G2iu
y+NXBH+
tv+{e\t
#s5CP^
$IJ\ :\/
e;^HL0
W)N5= 1
-lXeQ+
hDVqdy(
^mKLF1
liQWI_!
Y"]]KA
7`jTF}-
MbiDe
\yX-l~/
yKE)h@MK
wA !~g'P=
@Tw;@@!<=22=
>rD;Y<
.AS[<D
S[<DVS
%S[<D|_
??#S[<D~
LuAo[G
vJ]S#L$
h3=?d
Ws+iU?m
TlsGetValue
:a!4pp
(hiem<ncj
4;W1e2
h:C~93
V_09Q(
/:udBG
c\hMaq
LvY%n)
}^VL-3U
:AuMiu
4N+2X]u
62##mo
-&g3Zc
Dx AG?
FF>O^w
vy;V66
ryKZMX
-0.<4s0r5|BO
LE2h-P
5RRgDN
f3>]P?
CreateFileMappingA
.A]:i.
:%e*$%5XQ
rUhyj\
]"#h8n
W%NZ}g
W S$)#
J>M4&c
7WBb_d
rs5.v"
iUaadt
+u),;x
!)?t33S
TNmZj9X
+?Lbe5
`#n~Jv
AL>PD5
'v\2W9+
lv\2WM
v}H#vX
psU}-m
V BvP.
4ywW{w
|1Tm86/
WaitForSingleObjectEx
EI._E^W|~
V{Yh*1%
y'3gA4h
&X&1\p
i7Nlm`
3iXFZnk
!u?Gg1
#&0hDa
!!e,h?#
DA3>C)
.a(y2L
Dj6xg/0ND~
Nc8Pb{
jfTG44f
K*Qp4c
Bih~$1
b't@p}^
I/NoStL
a6s;Ro
xEk3)Lr}E
]9NBH+
b#5]u{
Ru\.[rX^
+AEr}-
VsG9#Z
sC1=dn{
__lconv_init
A\A[XAYA]
)8|6.O
Z(,3j/[
w,h@G+
|-y0-$
lD5B\CB
A@q1qG
FindResourceExA
k"vN4s
/<JZY0
ZTRmxki
-h[GrZ:b'
-)P5$P
wEHi^\
Jlp1Ezw
\xb(65
]3k*T@,
so&>JA
V$)W![
ZZXYXZY
Qn!&L*,
3/'J?.
KN^~kDiC
2."y*)
F#[R.w
Nxt1!t
[?4U:&9
23xO?3m
!qXwaN
+>q]{0
-+XNm+
o@ew/
,4e/4
%!3Q8Q
"m(2N{V
koUz7W%
VTFhJQ
q}^Y+J
p1D.8YS
q}4[,J
E-z1_8
(MSCG^
k.a1\%
j}JUY:;
C@Ulbe+*
RW1T0j
XB0#v%B
`E-N2|
j650~G7
:*.K7F
lv5OWl3
2~;Nb,
Sp1<yv
]RN}F
YM3Klj
Y9a`&/2
EmO}\@G
{!uY88^)y
[G+GA\I
*ZZZZXY
BZyp"lHS
.1>EJd
CoRR+!
(i==_M
h_A/9(
ZYXZXZ
A)TUi"
bO+u($
dK4Dn.`
xuaXB;
-cT[%w
YiP4jl
h&f1/h=
&b8Vp
C4JO'1
#mJrnh
@z||gvY9,
]B?oHz
1LD"-S
]as`O/Q
XWn6^W"
^39BV4
N#5Ic6hs
;'D8&)^
AIl@mn+
4Fzy'4u
bF{}hX
Gw7;a:z
}Gy_.k
#FI`\(
Q?34"yk
IsZY9
wQ0%/v&
<P",=H@
tV-6w]
~Elu/*
xWBn|!*
7Z>_E;
w5oP|nEl
i^cjOX@
<%7G*I
{oq-PPA~
;E_>)epo
^mhvu@
:1!RMp
=%lbE`>
B(a=;E
"KbGqN
XAq/.1
~S5q10
Jyr:qo
30?p34
Vy;Y)1Wd
!^/Q8
1"-A1/
&wk!]&
PnccVn
+i/VT6<
W^NOZ3g|6v
Ck0<7#G
jhS_:m
u">:ym*
E9$<g1$`
g%(T"Y
1tQ|#><
\qc%&L
OW+>CG
EGvFFF
+Wq-7_T
~M$( WFZ
D"^E?hD
r@K}Q-*
$']Yi"\
ZD.(IbL
($8qT5n
X@hiwgr%V
PjR2W+
L/S5\d
JnCK3N
/b-g-my
9B3Tdih
H{viJAP
<w5o;};
,~TCN2
:,l7&&
&P/1:!
q@;m_L
V6JTOi
5g9-gI
k;4Vt`
w}|I"w
ol]O]~
Co`sW,
gjE0um
[Auw&-h$e
=NP~n#Ol
I1pi/f
DMxDJ
\-y3A
LR)]<.
XXYXYY
68O5j}Y
~ ^xHN
mam{mltP
k[j+S%e
N6oL9V
T\8epT
R&! bR
6kqUQF
PefJ@E
a!8.(l
$Uh]{1
-KzYx
UI)M4<k
yVU)2g
#R`AWi
K+hP-F`
Dl/<R&
I&W:&&
(U.7B\
&PqS'c
`"Zhq?
Vom'$\
%le3ic
P<8&B"
)yjxTt^
DBq82g
(a +KW
.'d'N
rxuV~O5
$n3(^f
x-3Z2`
YQ!r-K
`?l+_`
*TO v8
3+Vy,h
1YWY_ZLsm%
l>HV'?
';4GyU
kTu&}-
Z_^>Pa
X^Sx\9
el\Xb\G
s>"IAe
261:yd
<fQ1P|
1:NSq4
D!fN@)>
A$[0)fJ7
[6owop
%LN?.{
R3.">&v
qk?+7+
U@^N$#
:},Lt6
(9t)UL
gUS4q_[
e "(0H
v{Ub>z
4@:4N9!!m
t]^M-rh
~VRp"
#wT~vA-
NC*cBq
:F.u#W
^;:YRXo;
[Y4Z>gk
@I(G`]x1
?)B86v
RETLvf
We%2ss
jqCtxD
GgqDuF
|&SS"%
IN;Uhl
|ZR~cs
fuN8mp
YWMoQ`
dx4RmO
a~wvD$
/qCIP#
8/B*Q:
i,CE.y
8c~%</ch
wSAO*>
2A;D<P
-r}-"
6#V4@>Vk
ResWEE-!
v~cc;`
Nh!:P(
7ett$L>
{HReWv
=6W[Q
+c-:1c
=$2><,
'L9~~l5
)wtG|XJ
e$r LOX3e
;O8R`H
:Iic+V
z]t%aL>
_QKz%6
4X+k?6h
fKZ|3V
^p>0`z
Y3S]-l
s|8!<Xwlz
7:}(bp
x_HQ?pw
UVggc3
gYlh37q
0j(}jllO>#xK
WE{Zom
rV"Nk"
]L7*y)Ig
[MMKC$:
YH/UgEr
VodLp=
[;8YG47<
i":qt#9
\Ir2Z1;
]"bqma
3?9d1W
G=SEbG
v$bs#s
nj%gGr
J6 (4}
V%!x*p
%yf#: <
xd^BdI0
N{wSu7@
&%?#Ih
ZL|LP>@
6]'2a:
)|>g+,
tqYT4(
jfpzvAq
Y"q;}6
uul3cVP
l)>qZA^F
f![Ay]
J&cY__
r{$ih6
#Uoa(o
Apz_8_
PMLw]56)
lXku(oo
#YtW&F
'oBA8-
$7ZJ<k*03|JA
x%a(~z~[
"e`3/_C
=e8<atA
+]9#pC
q}ljL8*9
%LN0E
`:Df8
s}W{"w+
{!&Faj
@j:War1
")GP&w
vw"Y|h0
uti79c
RM}$:b
&4?>Uf
c{0Prq
"^r:^<P#
U8<|K0
iHyp>K3
o\gm%@yc
`4(A=:p
m_v=-4
dO"*I>
Df8^%#
6Uy@.
'a7"B_
TU9xGs
[kv(k9Q
c?yZ6+
6Z^q3T
+8/)(@`Zi{`
Iz\?P`
pr#Q-[
|k3#-%Y
lL74fj
ZwAH%&<
D=/8zl
D9JGa?
W(C62#&
Itv-c:
g"=b0\
Kh)-*j
Lp~4P<
c3?kQM>-`
"f9*Zm
qw+wD'
8$J!38
QEM7,~
7o:k^6
FI=]6C
/r*IJzF
ys/VL?
sm3HFs
@G+8y+
Zcp(;7
^E 39k7
LVVhWS
y7X!p
1FHXb<V_Hp
[)E@ 4
oqWo.O
7p=XB/
@XP=&1i@
,$d+sT
x3'%N`
/f$PaS
do]-J4
Z'Q#hq
T2Lkd
5PyNKX
?\.D2rf
wKa!hdH
4siY2#5
$21K_te
f^00^)
CRD{d3
C"huq+
7SW97^
7ey S7F
f&1!as
k2Z<^w
2\0HNU
0Uk.Y'
>rsRW`
@=MDI
EJ=g4``g
Ui@EULLX
ZtA]6xT
7}_;Bc)
p3%;c3
e wsm_
32+n#[
bo_{b#R
C$8l]r
j;#IEtnz
jq\oS0
R)^JJ5X
c2/7DY
Mxoi&&p[
Q_6r6loY
]Y(q1C\@
CC7w3</q
r6KGUu0
wd(RG!GF
q+CKNW
|c>pMD,}
MMn1Do
SK(!4I
eC9Npg
H[6`|`J\*
6G+B{G
%aOp-km
}L(B?;%
%AK-pa
WyO$`x
&y\CXOl
$q!\:]
GetWindowRect
kdB|K%B
V8Osc@
XMYt$X
ZYZZYZYZ
B2pK@
MAtz/a
hHP7GOhX
nr7:j.!9
d+NsnL
rhRc:L
XZYYXYY
RYZZZZZZX
-=nTq
s],TNZc,!
V@jmE1
i&{H,M
eY<X9o:Z
V}W4V1
c+{N&)
A\0XK]
D!@2(]
t]Yy3
`0Kp6U
Vg2mTv
9L?kb~}
P3vK{~
cTf>^c
"Z'Q7X
v`Jg`w
p-Jr`
N2@2"'
k\/AD>
8(69=Q
oJUVq+
j:LZp=
]IPJF^
ResumeThread
14lA^Hc
-9OEzlm5
\GKVOf
g!;u9@
s;w@f3
GetProcessAffinityMask
S2A2if
A,J^=5s
K:F6MM:5
Fw-!@h;
mbpA+|
O9VP&p
s_C_+"
/|mmE/
9j0lf
--}[?Gav
753pfxp^
n8wU/%F
B~SY2Q
1I{5^{A
@DY*c8
/Z2> s
TjJTdH$
$WlbZN
svyAMQ
25-sje
<l(iP^
GetStringTypeA
]&:~+~
cS7_z0
{egK e
D`56q<
u?}2Js
Nw~a$8
JJ,{`h
>{VASk
5Zk2IDa
$XZZZXX
T@A/qT
l&s~Ma
6,"x**
LM@;(Y2
_^A\AY
_beginthreadex
lCEQZ*)
wXoHg3_?hi
E~qmCg
3?gd,MVC
BW9X^2(
agMr]9<IN
[&B##Q
`_0ot`
oS_GTx4
]6;<6<D
tZlN{I
?!ILe
WaitForMultipleObjects
;1lQ;y8
&:(4Ruh
z:e#Lu
JZ:Jgy
CZ\v8
/nMivx
KfRML@
&MH/X#S
9XEq,Z
P/S2-Q
ORB%q_
62\HAu;
Kea%Hm
}P$#vPz
+_p{$
[B#oB1
:/v5x6
)Ac5I@|2
:my9@U
YYZXYXZ
iKqCH
NZCpn&|
HfEXxY{cw
)1DT).g
O%s1DT)
g)u1DT)"-q
AiN|eUJ
#i6'Etz
-v_udM
Y5_!TG
\kxitC
A$C2-h
TbbCGt
2_|jQ8
@f]=:@
PS&J%Tu
ozjkH)
T+/}}I
.(?~j@&,
lhwT;N
QwdU)k
A\_ZA\
x1\v;o
'n^@")
ZNuQ<&
QueryPerformanceCounter
$6\"z6
V='VS1K
ddsMQG
2g,d:+
V:0OS1l
l-?1<5
`}/A(5
=fL|At
wG[^/-T3
b~V)qR
&um3Wwv+
rZV*wJ
_cWaq7?.
0%d^<R
EtzOw5o
Hq]V.z
Hq]78\
Hq]:L-
E4NShbo
A^AWHc
(ik}b?v
KLrlp0
dN3a$=
."J|32(
ppRI42R
<ne|S
o"8U$\A
{5u6'%5
,7m\Z3
LCMapStringW
DbPm;,i
WriteFile
o_f<v\
I r^dR
'ID^SP
V$Q{Q]
O>A:X6
__O<3h
D,pzl^SLl
InitializeCriticalSection
>3HDop
uOW5`uNb
}Q/57fq
CZ|L-g
FPhyV
4Pi{I^
]vH^<N
<Z@nPT
cu7mXE{
sNvsPB
7g$&kg
XYZXXX
|D?E<n
q{5 C' =
x~\kfIW
kG}JF|p
/]cTGn
|ZnE]w|f
OFBL>Gg
qZXYYX
>ZWHZ3
g]OcHp
FnXB]K
(Gi0T2
YG dfW
O)2& {S
jkEL6?
_vZ3bGT
CreateFileW
myy7lh
l=8>=j
F^<MY>7<'
Wh)@|9
&ID)95
a)j)i
c}"3ia
]dMEg^
u^.QWP
AM0.c!|J
)D<'g
Dz;KZn
>NjY:S
L'"B*3A
5(\am~
%kqayI
"6=*r:
Mdj"#l
;PJo)NK
ItdAVl
N)Lr6b!
#n[2af
r$Ogx*
5}("*P
J-rq&D
+o*6+(
;?^9~I#1
@o l{%j
MY*91P
LeaveCriticalSection
]mz>\aT
\^Uj'h
mu,|H=
_XiV`,
[=:D$([.7
L`qOsZ
ZKY;Z)
2mw[bJ
ai4`y~
r.%JmC
$$B@1$
u-YMZc:Zx
Nbz_*Z0^
\eE0#$
CreateToolhelp32Snapshot
8x+Xiq
vhypHN
y/(,!)
25IlW/
DT9C#`
NHCn{+
-W}VRp
p4)'}gr
GetStdHandle
-5W$D^]_
cD*H8M
R#>TzT
Ow[C4,UCD
*C>dhB
6Hd_Q
.#u xw%
6d|+Y#
\b(*W8
EHF|d t
:0zY"Yi
H|lF03
E"y%JY6|)H
c|!`U/
TlsFree
-UM+l`
-C9/*/
eH@j,=
h1RAS"
DPv+,|
BU)gg>
wUN?}T
JJ+$QQU/]xc
|k<j^`
z/`MUU_M
fGr?/y
%Q:Snf
D1$DA^
iIL^5-
G@$:#dm
>1_zPw-
`.~oP)
+.S!,Y
{F#mKAT
7.{Pf'
k/o:&
X}|+(p
qy`H_K
Geldp$4
.2\XPq!o'l
@Nwq,s
SetThreadContext
JthwSR
s*JK5x
QU_n2<
Pv9ewM
:*Z/t"Z<
>}),vP
91>ex"Xa
1\1QO%nO
bFoI6$
p1?,s(O
GetModuleFileNameA
~?UjVP
xbSSS|
6!>na1a
L^6f A
^id^2b
LoadLibraryA
`?&PR7
V}Kl.n
t8j$KPh
Ul*sVR
CyPtfl}
H}Cb)x
;OdA]_
|E,pB8
VQ;z@1GL'
RwN:o?
CR$Xy95
G<C!qcz
_%)V)*=
)y&3Bz(@
M/#i3M:u
azRRj`
4{]U~p
:&qAjF
+nc5\HE
p.=[;c
4`ZVOW
=@~D_IW
z~~hs6
7<y>*)"Q~
VF3hAX
:W*>ue:
Y}g6N2
v/y='&
*.mr{'
fF5OVAB
KBq<{E
+8q<,O
P*,>`-[
}.hMM)
alNYak
Y63m+'
lJZPSmi
r}1x\F
Y"jQM&
IKE3D"
!SS~N2`,c:Y
Nqt"0(o
"?7?Ii
=tZPpgPHQ
MMOAsg
4g(GFYe
ZHhYr3^
!NQ4lS
n5ej%"
)=lMM.|
B24.~a
<O"IU<
<)?-:CKp
bXWs^O
bnGqRi0
5nBNdg
#>D8}&
5-J(*_
KOtj5>W
.ojrX"ed
LD?odB
",?(YCN
ResetEvent
LCMapStringA
OfITPB
}9K #AH'
vq1`c9r
U1ZGr/
/]!#'H
:Z>@Bc
R%Gh$^fQ'
_OQSd$
[A.~^d_
YYXYYX
CreateToolhelp32Snapshot
user32.dll
HeapReAlloc
h$,8pf
<$GYYZX
[pf1bz
Is4ikB`
;u\[|l
xm-jz$
]I;!yR
MdbA!=
U7"%YZX
#e6V3T
:x>.Ss9&HR
vro+v&-h
PXZZXY
yd[b*u
EnterCriticalSection
rA1m&/
g?<{6y
]op Mz
jSK/o|
7MCxEa
8APCBdW
j"}O!E
hL^C]U
\H?E {7m
i 8kVO
{TV{9.
<hf%MP
-Wn}NW
ayj_z`
PiNTV6
kiW$kTlH
Antivirus Signature
Bkav Clean
Lionic Clean
Elastic malicious (high confidence)
MicroWorld-eScan Clean
FireEye Generic.mg.f2e85a7b8620fac7
CAT-QuickHeal Clean
McAfee Artemis!F2E85A7B8620
Malwarebytes Clean
VIPRE Clean
Sangfor Clean
K7AntiVirus Clean
BitDefender Clean
K7GW Clean
CrowdStrike win/malicious_confidence_70% (W)
Baidu Clean
VirIT Clean
Cyren Clean
Symantec Clean
tehtris Clean
ESET-NOD32 a variant of Win32/Packed.VMProtect.BC suspicious
APEX Clean
Paloalto generic.ml
ClamAV Clean
Kaspersky UDS:DangerousObject.Multi.Generic
Alibaba Clean
NANO-Antivirus Clean
ViRobot Clean
Rising Clean
TACHYON Clean
Sophos Clean
F-Secure Clean
DrWeb Clean
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition Artemis
Trapmine Clean
CMC Clean
Emsisoft Clean
Ikarus Clean
GData MSIL.Trojan-Stealer.Redline.DJZUPM
Jiangmin Clean
Webroot W32.Trojan.Gen
Google Clean
Avira Clean
Antiy-AVL Clean
Gridinsoft Trojan.Heur!.00212031
Xcitium Clean
Arcabit Clean
SUPERAntiSpyware Clean
ZoneAlarm UDS:DangerousObject.Multi.Generic
Microsoft Trojan:Win32/Sabsik.FL.B!ml
Cynet Clean
AhnLab-V3 Trojan/Win.Generic.C5390164
Acronis Clean
BitDefenderTheta Gen:NN.ZexaF.36308.@Z2@amsJkzkO
ALYac Clean
MAX Clean
VBA32 BScope.Trojan.Injuke
Cylance Clean
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Tencent Clean
Yandex Clean
SentinelOne Clean
Fortinet Riskware/Application
AVG Win32:Malware-gen
Avast Win32:Malware-gen
No IRMA results available.