Static | ZeroBOX

PE Compile Time

2023-03-10 22:52:15

PE Imphash

abb9300283e542fb453de5c4c87cd55d

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x00014415 0x00014600 6.38887095083
.rdata 0x00016000 0x0000a4b4 0x0000a600 4.74636089852
.data 0x00021000 0x00001ea4 0x00000c00 2.09519733398
.pdata 0x00023000 0x000011a0 0x00001200 4.89290836694
_RDATA 0x00025000 0x0000015c 0x00000200 2.80232239957
.rsrc 0x00026000 0x0002bd28 0x0002be00 7.84143738282
.reloc 0x00052000 0x00000684 0x00000800 4.92074845278

Resources

Name Offset Size Language Sub-language File type
LXGUM 0x00026b60 0x0002b000 LANG_ENGLISH SUBLANG_ENGLISH_US data
LXGUM 0x00026b60 0x0002b000 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_STRING 0x00051b60 0x00000048 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_MANIFEST 0x00051ba8 0x0000017d LANG_ENGLISH SUBLANG_ENGLISH_US XML 1.0 document text

Imports

Library KERNEL32.dll:
0x180016038 SetFilePointerEx
0x180016040 GetConsoleMode
0x180016048 GetConsoleOutputCP
0x180016050 WriteFile
0x180016058 FlushFileBuffers
0x180016060 SetStdHandle
0x180016068 HeapSize
0x180016070 GetStringTypeW
0x180016078 GetFileType
0x180016080 GetStdHandle
0x180016088 GetProcessHeap
0x180016090 CreateFileW
0x180016098 CloseHandle
0x1800160a0 WriteConsoleW
0x1800160a8 ExitProcess
0x1800160b0 HeapReAlloc
0x1800160b8 GetLastError
0x1800160c0 LCMapStringW
0x1800160c8 FlsFree
0x1800160d0 FlsSetValue
0x1800160d8 FlsGetValue
0x1800160e0 FlsAlloc
0x1800160e8 UnhandledExceptionFilter
0x1800160f8 GetCurrentProcess
0x180016100 TerminateProcess
0x180016110 IsDebuggerPresent
0x180016118 GetStartupInfoW
0x180016120 GetModuleHandleW
0x180016128 QueryPerformanceCounter
0x180016130 GetCurrentProcessId
0x180016138 GetCurrentThreadId
0x180016140 GetSystemTimeAsFileTime
0x180016148 InitializeSListHead
0x180016150 RtlUnwindEx
0x180016158 InterlockedFlushSList
0x180016160 SetLastError
0x180016168 EncodePointer
0x180016170 RaiseException
0x180016178 EnterCriticalSection
0x180016180 LeaveCriticalSection
0x180016188 DeleteCriticalSection
0x180016198 TlsAlloc
0x1800161a0 TlsGetValue
0x1800161a8 TlsSetValue
0x1800161b0 TlsFree
0x1800161b8 FreeLibrary
0x1800161c0 GetProcAddress
0x1800161c8 LoadLibraryExW
0x1800161d0 RtlPcToFileHeader
0x1800161d8 GetModuleHandleExW
0x1800161e0 GetModuleFileNameW
0x1800161e8 HeapAlloc
0x1800161f0 HeapFree
0x1800161f8 FindClose
0x180016200 FindFirstFileExW
0x180016208 FindNextFileW
0x180016210 IsValidCodePage
0x180016218 GetACP
0x180016220 GetOEMCP
0x180016228 GetCPInfo
0x180016230 GetCommandLineA
0x180016238 GetCommandLineW
0x180016240 MultiByteToWideChar
0x180016248 WideCharToMultiByte
0x180016250 GetEnvironmentStringsW
0x180016258 FreeEnvironmentStringsW
Library USER32.dll:
0x180016268 GetGestureInfo
0x180016270 InvalidateRect
0x180016278 ScreenToClient
0x180016280 CloseGestureInfoHandle
0x180016288 EndPaint
0x180016290 BeginPaint
0x180016298 UpdateWindow
0x1800162a0 PostQuitMessage
0x1800162a8 LoadCursorW
0x1800162b0 GetMessageW
0x1800162b8 DefWindowProcW
0x1800162c0 DestroyWindow
0x1800162c8 CreateWindowExW
0x1800162d0 RegisterClassExW
0x1800162d8 LoadStringW
0x1800162e0 ShowWindow
0x1800162e8 DispatchMessageW
0x1800162f0 SetGestureConfig
0x1800162f8 TranslateAcceleratorW
0x180016300 TranslateMessage
Library GDI32.dll:
0x180016000 Polyline
0x180016008 LineTo
0x180016010 CreatePen
0x180016018 MoveToEx
0x180016020 DeleteObject
0x180016028 SelectObject
Library ntdll.dll:
0x180016310 NtQueueApcThread
0x180016318 ZwOpenSymbolicLinkObject
0x180016320 LdrFindResource_U
0x180016328 NtAllocateVirtualMemory
0x180016330 NtTestAlert
0x180016338 LdrAccessResource
0x180016340 RtlCaptureContext
0x180016348 RtlLookupFunctionEntry
0x180016350 RtlVirtualUnwind

Exports

Ordinal Address Name
1 0x180010a70 DllRegisterServer
!This program cannot be run in DOS mode.
`.rdata
@.data
.pdata
@_RDATA
@.rsrc
@.reloc
|$ AVH
H3E H3E
VWATAVAWH
A_A^A\_^
WATAUAVAWH
A_A^A]A\_
H;xXu5
fffffff
ffffff
vKfffff
WATAUAVAWH
A_A^A]A\_
AUAVAWH
u4I9}(
;I9}(tiH
0A_A^A]
UVWATAUAVAWH
`A_A^A]A\_^]
@USVWATAUAVAWH
A_A^A]A\_^[]
UVWATAUAVAWH
A_A^A]A\_^]
@SVWATAUAVAWH
L!|$(L!
D$0HcH
pA_A^A]A\_^[
B(I9A(
SVWATAUAVAWH
0A_A^A]A\_^[
t$ WATAUAVAWH
A_A^A]A\_
WATAUAVAWH
A_A^A]A\_
ffffff
fffffff
fffffff
fffffff
u3HcH<H
WATAUAVAWH
A_A^A]A\_
UVWAVAWH
0A_A^_^]
WAVAWH
A_A^_
WAVAWH
A_A^_
p0R^G'
USVWAVH
A^_^[]
D$0@8{
p*W4H
p*W4H
u$D8r(t
D81uUL9r
uED8r(t
vAD8s(t
u$D8r(t
fD91uTL9r
uED8r(t
v@D8s(t
UVWATAUAVAWH
PA_A^A]A\_^]
WATAUAVAWH
0A_A^A]A\_
H9>u+A
@USVWATAUAVH
D8t$ht
D8t$ht
A^A]A\_^[]
f9)u4H9j
u%@8j(t
l$ VWATAVAWH
L$&8\$&t,8Y
A_A^A\_^
WATAUAVAWH
A_A^A]A\_
p0R^G'
fD9t$b
t$ WATAUAVAWH
D!|$xA
A_A^A]A\_
L$ VWAVH
fD94H}aD
ATAUAVH
L$ fff
L$ |+L;
A^A]A\
@UATAUAVAWH
e0A_A^A]A\]
@UATAUAVAWH
A_A^A]A\]
WAVAWH
A_A^_
UVWATAUAVAWH
fB9<I}1L
A_A^A]A\_^]
VWATAVAW
A_A^A\_^
VATAUAVAWH
0A_A^A]A\^
@USVWATAUAVAWH
H!D$ H
xA_A^A]A\_^[]
WATAUAVAWH
0A_A^A]A\_
ffffff
fffffff
@SUVWATAVAWH
@A_A^A\_^][
LcA<E3
}nHcD$
D$,HcD$
};HcD$$
PHcD$$
D$0HcD$0H;D$@sBHcD$0H
HcL$0H
D$0Hc@<H
9D$ sP
;D$xu"
Unknown exception
bad exception
__based(
__cdecl
__pascal
__stdcall
__thiscall
__fastcall
__vectorcall
__clrcall
__eabi
__swift_1
__swift_2
__swift_3
__ptr64
__restrict
__unaligned
restrict(
delete
operator
`vftable'
`vbtable'
`vcall'
`typeof'
`local static guard'
`string'
`vbase destructor'
`vector deleting destructor'
`default constructor closure'
`scalar deleting destructor'
`vector constructor iterator'
`vector destructor iterator'
`vector vbase constructor iterator'
`virtual displacement map'
`eh vector constructor iterator'
`eh vector destructor iterator'
`eh vector vbase constructor iterator'
`copy constructor closure'
`udt returning'
`local vftable'
`local vftable constructor closure'
new[]
delete[]
`omni callsig'
`placement delete closure'
`placement delete[] closure'
`managed vector constructor iterator'
`managed vector destructor iterator'
`eh vector copy constructor iterator'
`eh vector vbase copy constructor iterator'
`dynamic initializer for '
`dynamic atexit destructor for '
`vector copy constructor iterator'
`vector vbase copy constructor iterator'
`managed vector copy constructor iterator'
`local static thread guard'
operator ""
operator co_await
operator<=>
Type Descriptor'
Base Class Descriptor at (
Base Class Array'
Class Hierarchy Descriptor'
Complete Object Locator'
`anonymous namespace'
FlsAlloc
FlsFree
FlsGetValue
FlsSetValue
InitializeCriticalSectionEx
?UUUUUU
CorExitProcess
UUUUUU
UUUUUU
@^8U)zj
AreFileApisANSI
LCMapStringEx
LocaleNameToLCID
AppPolicyGetProcessTerminationMethod
Sunday
Monday
Tuesday
Wednesday
Thursday
Friday
Saturday
January
February
August
September
October
November
December
MM/dd/yy
dddd, MMMM dd, yyyy
HH:mm:ss
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
UUUUUU
UUUUUU
=imb;D
/>58d%
VM>cQ6
>jtm}S
)>6{1n
+f)>0'
;H9>&X
*StO9>T
n03>Pu
K~Je#>!
bp(=>?g
BC?>6t9^
K&>.yC
.xJ>Hf
y\PD>!
|b=})>
c [1>H'
uzKs@>
3>N;kU
kE>fvw
V6E>`"(5
?UUUUUU
?7zQ6$
ad5zS&E7DS(ke9?+qbAC5tqx<Y<h0!QB4H3bk
.text$di
.text$mn
.text$mn$00
.text$x
.text$yd
.idata$5
.00cfg
.CRT$XCA
.CRT$XCU
.CRT$XCZ
.CRT$XIA
.CRT$XIC
.CRT$XIZ
.CRT$XPA
.CRT$XPX
.CRT$XPXA
.CRT$XPZ
.CRT$XTA
.CRT$XTZ
.rdata
.rdata$r
.rdata$voltmd
.rdata$zzzdbg
.rtc$IAA
.rtc$IZZ
.rtc$TAA
.rtc$TZZ
.xdata
.xdata$x
.edata
.idata$2
.idata$3
.idata$4
.idata$6
.data$r
.data$rs
.pdata
_RDATA
.rsrc$01
.rsrc$02
MTGestures.dll
DllRegisterServer
GetLastError
ExitProcess
KERNEL32.dll
GetGestureInfo
InvalidateRect
ScreenToClient
CloseGestureInfoHandle
EndPaint
BeginPaint
UpdateWindow
PostQuitMessage
LoadCursorW
TranslateMessage
TranslateAcceleratorW
SetGestureConfig
DispatchMessageW
ShowWindow
LoadStringW
RegisterClassExW
CreateWindowExW
DestroyWindow
DefWindowProcW
GetMessageW
USER32.dll
DeleteObject
MoveToEx
CreatePen
LineTo
Polyline
SelectObject
GDI32.dll
NtQueueApcThread
ZwOpenSymbolicLinkObject
LdrFindResource_U
NtAllocateVirtualMemory
NtTestAlert
LdrAccessResource
RtlCaptureContext
RtlLookupFunctionEntry
RtlVirtualUnwind
ntdll.dll
UnhandledExceptionFilter
SetUnhandledExceptionFilter
GetCurrentProcess
TerminateProcess
IsProcessorFeaturePresent
IsDebuggerPresent
GetStartupInfoW
GetModuleHandleW
QueryPerformanceCounter
GetCurrentProcessId
GetCurrentThreadId
GetSystemTimeAsFileTime
InitializeSListHead
RtlUnwindEx
InterlockedFlushSList
SetLastError
EncodePointer
RaiseException
EnterCriticalSection
LeaveCriticalSection
DeleteCriticalSection
InitializeCriticalSectionAndSpinCount
TlsAlloc
TlsGetValue
TlsSetValue
TlsFree
FreeLibrary
GetProcAddress
LoadLibraryExW
RtlPcToFileHeader
GetModuleHandleExW
GetModuleFileNameW
HeapAlloc
HeapFree
FindClose
FindFirstFileExW
FindNextFileW
IsValidCodePage
GetACP
GetOEMCP
GetCPInfo
GetCommandLineA
GetCommandLineW
MultiByteToWideChar
WideCharToMultiByte
GetEnvironmentStringsW
FreeEnvironmentStringsW
FlsAlloc
FlsGetValue
FlsSetValue
FlsFree
LCMapStringW
GetProcessHeap
GetStdHandle
GetFileType
GetStringTypeW
HeapSize
HeapReAlloc
SetStdHandle
FlushFileBuffers
WriteFile
GetConsoleOutputCP
GetConsoleMode
SetFilePointerEx
CreateFileW
CloseHandle
WriteConsoleW
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
.?AVbad_exception@std@@
.?AVexception@std@@
.?AVtype_info@@
.?AVCGestureEngine@@
.?AVCMyGestureEngine@@
|*0xij&*
tqxo5Y
dAZ4P3.
0UX)Y)hx
q^s#E2D
~<YpQU
oN3b'9
5C[_OCt.
dhcBlv
#1;_~#
*]9K%8
4zS&#s
++qbE795~
q&m30fyv
zP&E7@S(k
bAC5tqx|Y<h0!QB4H3bk
ad5zS&E7DS(ke9?+qbAC5t
:UeG6<O
w^,a7DS(ke9
<Y<h0!QB4H3bk
ade?S&!
@SaSc]?+qbAC5t
y7j<!Q
E7DC(ke9?
pbAC5dqx<[<h6!QB4H3bm
ad5zS&E
FS(oe9?+qbCCUuqx,Y<h0!QR4H3bk
ad%zS&E7DC(ke9?+qbAC%tqx
>hz!QB4H3bk
ad5zS&E7DS(
%qbAC5tqx<Y<h0!QB4H3bk
ad5zS&E7DS(ke9?+qbAC5tqx<Y<h0!QB4H3bk
ad5zS&E7DS(ke9?+qbAC5tqx<Y<h0!QB4H3bk
*ke)?+q
CC5pqx<Y<h0!QB4H3bK
7G1VDS2ae9?
sbAO5tq
>Y<h0!QB4H3bk
!d5:}B$C%S(k
CC5tqx<Y<h0!QB4H3bk
7tqh<Y<
2!QB4H3bk
&EwDS(ke9?+qbAC5tqx<Y<h0!QB4H3bk
ad5zS&E7DS(ke9?+qbAC5tqx<Y<h0!QB4H3bk
ad5zS&E7DS(ke9?+qbAC5tqx<Y<h0!QB4H3bk
ad5zS&E7DS(ke9?+qbAC5tqx<Y<h0!QB4H3bk
ad5zS&E7DS(ke9?+qbAC5tqx<Y<h0!QB4H3bk
ad5zS&E7DS(ke9?+qbAC5tqx<Y<h0!QB4H3bk
ad5zS&E7DS(ke9?+qbAC5tqx<Y<h0!QB4H3bk
ad5zS&E7DS(ke9?+qbAC5tqx<Y<h0!QB4H3bk
ad5zS&E7DS(ke9?+qbAC5tqx<Y<h0!QB4H3bk
ad5zS&E7DS(ke9?+qbAC5tqx<Y<h0!QB4H3bk
ad5zS&E7DS(ke9?+qbAC5tqx<Y<h0!QB4H3b+U)
fS&.r;0
7t9ClqN`x
U\|z%i
QMc0!b
{`c>h.\
>wjwKDS
qP):*Y<
5FaX+tq
cU<yS(
cAC^0UHS
%uWaMc
S&.s`#p
6rx<dd`0!^
D7Dni!e90
baw-g(k
.O@d=LY
xLtTWB4
0<$o~|9
/$1$5zS
=6DS8Rb9
euRP[3b
~1ZadP2
"`WDS(
dAlsH3
u,dM8T
0U8x,<hx
_URe.f
)keRz3M
'Yawtq
C_>e9Tna?
@j]7L7
xa[S(d
dd5u,&E
tx<E1h0
F5tk{=Y
V&E/GS(
V(kao?+
F5t_^"8
1DSw58
$AL)~S
I|v<Y3
e9?]*bA
yQRqb
p*EUE7
'Y Ktq
,$v,"Q
tqEvp<h?
n[eur3
D"Pvq0
UvbA~"4qx3
n0!l2qH3m
Iux<dV
le9Z,qb
VB4_-h"
0DS;Le9
}S&7FaS
/Ai0,qb
D5t%$<Y
7!Q[>H3
^<hZ)<-
;h0uYB4
le9W8sc
FC5\&x<
@lcX1{
o0!q=4H
<h0D<B4#
qx<8@d0
/$Yp[zS
xO~keq
~-qb|}
FyD5t9
H}lBmY
%fdV"=
gaIvx<2xLd7
0U aC<h|
Aad"ri
>wF0pDS
L4SSM$
yP)]09
/$9%_zS
WX&OTN
"9?@4z
g=!'/}
r,t8ke
fHx[bk
_0)(k!
K9?@5F1=
.htW5z8c-
wDSC/AIM
?;U 7D
&@n 9?
%@Epy&E
13mAs9
ad^73d
&px<d|X0!^
4B}m5t
4P)><h
!%T:&E
|/tVbA
@dGB'Y
g}z=x<j
/AQ5^qb*
|'btbA
p\ui<Y
}>h0 QB4
6>+9[\
'aG?tq
xIB4ujzk
?+q_k-5t~
.EQZ+q
'ifqtq
.MtN+q
Sbbkk$T[
'C(Zd5
O-5z8c
ba'!U(k
eurzy3b
DE\wS&
LOU=ToURp
'{u2d5
IG7Dn;
C4HaMk
$Ut^>w
GF[B&h5
oUFW'5t
o$B8})
E{iRz;P
dA)qXK
4rGO5t
1Y[@Y<
)>DSC.
5Fau{tq
i?$l~}05
*_ :t'
n.$%C5
'52y7D
*f9?jJ
>w`lt`
]4tye&
yA~s0!
dI<H3
dO]Kk@L
e++ws{x
bkk$T;
vrE1ad
@lso.A
c]2-S(
1YXY<
k0!l|[H3m
f*yqx9>
I@p}IB
bd5TGF
"QBiX3b
P(koM?+
GS(Yo9?
pT%g<Y
hl;7=W)
O3b)nad
<Y&G0!
le9uyqb
,qb7`5t
s`#C/AII
S&E7DS(
{`#yIt
P&ETvu
K3b/6id
g5z58E7
he9G9qb
rx<0[r
?h0ELB4
0bkq:N
+ke76+q
keRz3K
?K F7D
ypy!QB
-(NRB4
'YtItq
5bkk$tk
?K7K7D
ba'jc(k
e9?->bA
C`cU>9
e8lOU"
msEz?+
.eK`''/}
kd9?=rbA
BW(k`K
rR&E7Je/
!PB4)q
>J<h[eu*3
Q=h0d-
%@]>!&E
={S&K\
PJ3bVx
{`?]V{
DR(kkx
M6DS2v
zR&E0/
#pbAxqJq
['E7M@
F%Gvpq
x}Tz !Q
AQz qb
YC4H<<k
S'E7.(k
?*qbYN
5\T&)h0
f\u)O^
'A] T`N
H2bkH"d5
9>+qc!
tpx<;"h0
eu&Qn3b#c
l4zS}#8D
z\9\AC
Ed4zSn
5F1Gztq9
S&.s`cw
UurLy)B
oU"5J5t
bk=U~5z\
bkt4Yz
.fe6+q
nfz:C5
1R-)Y<
DSC.zO
:\~x<2ygO
y^8r0!
pw6C<Y
RG\C.fV
<^0UHk
FqgA|q
tET+\}K
bk=w\5z\
g%uqxt
L8 QB|
*_ :j2
b <h[eu*
cP1?+B
8}Y7~6
sW 0t/
FIB5t5
Ou8?+9
qx<v`h0
$)e5zu
4oh<Yt
5FqM&tq0
B&tadt
Ja_@8lO
!f5zn_
B4#va@
IJI5W&
py0PE7
'ad^>w
1f>IY<
t^(keq
eu*ir3b
oURMZ5t
q^cIy7D
&O8t]5z
$){c5g
O6C5I\
gES(kj
auqx<V
|i0!Ol
tI3b"F|
aPB4Ud
6DSlY-:
)ke=VU|
)keE:+q
:R&E8}
y>+qI8
@`d5R@sE
:R&E%k
R(km:<
tI3bHnad
!e5z&o
Fgrpxt
:R&E6=
fD7D]gke
kpbA4;
q;8=Yt
%8?+bE@C
1cAC'j
-x48?c
4px<vW
2bk)+d5
|i0!9h
|X<hMcQB
1y<Y<m0!
1y<Yj5
|i0!FoZJ
g#4t9
AJ`jeq
Ux=Y<
#pbA/\tq
w je94
FIB5tz
}4i0!p
$ye5z2
DET^>w
&Oh.b5z
5F-MTtq
r>W 0t,
`|3b.3
|H%"bA(p
y.W-Gj
L$"|jA
"-qb
r;}eke
Y^g6.s`g]
g=uqxx
L0 QBx
5tqT<Y<
Fq;vrq
B4Ha*k
$f~u0?
wF++c6
oURYi5t
l7Ukeq
9x<d*s0!^
y9vQB
4S'[<hq
,d=4_X
.7u55z
d.k%H3
4lXe}x
pd]-<YW- o
Vrnk$t
dIz;H3
|/8ybA
vBH4ad
?s f7D
,nUbkk$|Z
/$9U&zS
&e3!xqx
uuUS('
ILL<Y3
Y<$S`m
0+q&BQSO
/$!<9zS
Q+q_L`5t~
B4<N_
(qbA6f
&g*@Cq
GGS(/q
+ke64w
aACX^zx
adIJV=.
3!QOQH3
QRB4+JW3
<$o~|9
h0!;!4H
tqx.)U
n]q>+9
Lg8Y<g
yAi80!
TC5I1?<Y3
tEPCF\&
DED=xS&
lOU,T+q
gF[k%@
&O0>(5z8ba
\OUph(q&
!+Aqb*
!-Q8&E
plA,<Y
4b>#vB
K`"&9h
@e|8bag(
Y<hl{QB
AC^0UXq
ba?G](k
qPA=/Y<
$|9)S&
7D8ms*
^a;dG4
1Pc}qq
C`C}<$ow
X=+q_xv5t~
zTs\AC
5tLM-Y<g
4zSKT7D
.}rk+q
hDSC/A
>wvz{DS
RagKl{j
wPu}9?c
5z8bas
<xMe9Tn
DElC5S&
5Fa[7tq
xR&D7DS
VG=>+9
,\;l.Q
y,8mS2
e9TnIy
ypL;QB
cbA(p\&
iu+zABd
d69&H3
xS&ECZ
y/$El*
d&]QH3
0why/h?
wpk<9?@5F
5\x~Vh0i
euz=t3b#
wF[nNd5
=,_yh0
),Cqb
dy8.H3
pj[`E7
1{||h
25z8cU
@Tj)6Y
z;42AC
DSC.EM
/$!VYzSn
AC^0UX
ec35\
oUZc)D
niUTC5
e9TnY[
H,bQBx
$At^>w
eC54?x
p=WOE7/
{TW-w<
F%}>hd
@=X'E7
yL?}QB
4z6:5t
3bV5dd5u
@7Dnuye90
&pM+2?
^)JEK5
@*1/E7
p,1-<Y
';O/d5
w*;xbj-=
/AqDqb
p}|N)eB
@lsp.vr
@q}8basw
C5z8ba_s
0wXGJ:?
=[& h0
4|L<h
d63;H3
y/J'o"
?4d\7D
q<h[d&g
H6!QF8n
K.ke^U,7
1WB4f}bk
sc9?/9
$n0!7c
>C7DU-ne
C.kexT
_<ha0QB
p6!Q&rH3
S3tqrN
a5DS(B
n0!^!4H
p6!Q]0
'QBR!:
[3tqhv
/BS(<5
RU&E_pq(
ID4HJa
D3zSq"
x6!Qg4
Twx<SW
9WB4Y<ek
c9?j/=
e9Tna4
'Y4Jtq
0-#0,}
gUuqxp
L` QBx
qx<q=h0i
Ox`d5P
f4I3b#
w@@I9?
i)[d&w
&Q>4F9
I.Cc=!
N+`qb*
`C2yI
B3s(K\
FXBqb
|H[xbA
x=Y<)o`
@F^>wfq
/Aabxqb
oUBzi5t
5z8baWj
hDSC/A}
$%j.~S
DEl:9S&
o$w-Co
?1bk==S5z\
j>S73t/
D\d5?`
kDS(Vb3?+~
G5tLJmY<g
6e!{x<
.HZ_5z
$\EES&
mSa]?+
-p]JB4
"+bA(pD
{vbkk$LZ
4j3#vJ
&MAA?#
px<8Nh0J
R(kPe~
px<Xsm0
/UTT!m
\OU`'i?
pPRY<Y
$b5(3b
eyi^?K`
pb,GE7
pD_b<Y
}|&<hx
mKu`?+
'Y'{tq
J3pWHC
ga{Qx<
bag2`(k
<h[eu2?
YW)plK
oF{U73t/
s5z8c:-
r3rake
r;u7keu
'>UItq
D!QC4H3
EvH{zS
y>}I0!
dCDzSn
'&{+tq
mLh,?+
!BNG&E
4zSFy7D
I>+q)WC5
qPQoLY<
'A1jx'5
4zS/&7D
D7Dd%ke
PB4yObk
)ke&US
DToUBb
&E7@v(k
g%uqx}
ad5Kj&E
<h01QB4
qP)|<Y<!
APEwi[<
7s=8p5z\
dqxOH3
7D8mKC
ypMxQB_
E~WNzS
>e9GMqb
f|'qx<
&AE&OS
uFwD4H
-WkaB4
cad^?4
l6u2Ax
q>&e>1
#cyDS`
-D/9?h
-N,9?y
$5nh3b
bkk$ko
.9%AC}
zyS&1q
FE2qxt
nG|?+=
e9TnQM
$L6S&
=,t*h0
?C4s7D
ba'iF(kV
M8lOUH
bA(qPQ,
Uub\Gwb
?spg7Dn
7bk=,s5z\
.EL`+q
Z\UC.}l
!-]!&E
u9FR4HX's2
x<2ypB
@\qS(#
4z^G5t
z\8msS
yy9&0!
&B!Q)qx4
yAIz0!
nUSd52
^QA`C5
'sQgd5
IpSa^B
g'1ad}
5\daeh0i
89?@5Fa
0UX|(<h
wF#YCd5
/Ai*Cqb
sU 0t/
Nux<dS
ke9?cr
oUR_t5t
&esEwqx
g=!'/}
:Q(kXv
qbAb-tq
zS&I3DS
B4Hj(k
!cACt+0&c
l.)q7[
<h0!QB4H3bk
ad5zS&E7DS(ke9?+qbAC5tqx<Y<h0!QB4H3bk
ad5zS&E7DS(ke9?+qbAC5tqx<Y<h0!QB4H3bk
ad5zS&E7DS(ke9?+qbAC5tqx<Y<h0!QB4H3bk
ad5zS&E7DS(ke9?+qbAC5tqx<Y<h0!QB4H3bk
ad5zS&E7DS(ke9?+qbAC5tqx<Y<h0!QB4H3bk
ad5zS&E7DS(ke9?+qbAC5tqx<Y<h0!QB4H3bk
ad5zS&E7DS(ke9?+qbAC5tqx<Y<h0!QB4H3bk
ad5zS&E7DS(ke9?+qbAC5tqx<Y<h0!QB4H3bk
ad5zS&E7DS(kd7<+
cWC7$qx=P=h9
QB5L2bo
ad4~R&AuDS)od9;Iqb@E7tw
>i=b4![v>H9
mp`b7zUtG
:{pf@C1Vqx=P>h9
dqd!N\&Q
T#)~c9*_bbTw'td
=r7!K6{H)V%
{eyzXvE7EK"k}]++i6RC-@cx$
A25D7bg4hd9([VD#GS<j)9:{qb@L3t~
1Y3\<!^
<*R1B7Sg
F#3$qx=C5h*EqB.|-bq
_VNgDS)|m9(_cbV'$tfL,Y+
qPZ<H+
nC+@\x"X
h#qQB5Z;byTqd'N\&W
nY>#pbI
5tpo;Y+\* FC"I;
l`g45zR>M7\7'k}m1+iVMC-
pY+{qb@S7ta
=b2![02x2~`
}PzO'g7T
F#3$qx=P>h9SS
cT4nW&Q
uI>&rbL
3Dt(<Y=f4!_
385RnP`
V7_':k~].+jVQC.
e(=]=h4
QB5D7bg4md9
O-bcwotSydY(80!PN6H?
nP`G8zpRe7g77kF
!+RcYC-
qQB5X1b{
h44rR&MuDS)eg91
{R@Y=tk
#!Kv&H)
{P`k7z\
@gEL#kz
fx#m*h/ EB
S&D%BS:h9-}bS
>$pn9Y*i
!V22x62k
.;d.8+fVYB"uey4);
6qQB5Z;byTld'N_&WEJ
nY>0wbZB
796X9qPQ6H
bP`p=zGBK7P
Q34`wx(=3h$
Ms>$pv?Y2i(!S
"zsBS7d
=K4h"uAB&|=by
XFD(OS7
F9 _Sb^'
Y#i.!E
ED/krM
+fVaC"uox7
<h11WB$,?b{4kd%
_VD,OS3
fbZw#tjy.Y(
A24H2hj
5zR+A7Ig$kh
9{p}LC*
KB+I'bs
UGDS)tn9
#Y#\.!NC(H'2k
`s=zDrQ7Sg;kr
Q#4gux/m7h#S^25k>bH
M&fSYS
e(<Y=n2!Wp6x2qo
rP=z@tJGEF,kp8z+wRD
4dwx,=1h
K&RcSS?_s9(*ebQ35tpb4Y&<&!Kv!H)
R8N7Z71k{
'+ocSC'
;qQB5\;b
dqd!.\&Q
uI>7}b]'%tm,3Y \>!M0,
R2C7P7%kq
Q34cvx+-)h'
EB#I!b`Pad4vQ&I
5tp|=Y8
0!PX<H)
8;d3;+{VHC?&w
&LgDS)gd93iqb@\?tn
*Y#<%!Nv H,
R1M7S';kr]-+fVQC"
a(=C;h*U
d>*S&D
kP=zYtCGEH"k~
~x'm2h+
5R:bqd|d/NO&_6\S&
iI4{qb@V1tdywY:X5qPX<H)
;;d7=+
0Ks4kzx#=$h/uFB+|%bt
QGDS)~f9**cbH
5tpb4Y&
$!Kv&H)
%*R>O7\7:k}m.+iVQC-
17VB"I'ba
@gDS)ag95
wR@L1t~L1Y3
;QPL0H=Ve
R*G7H!-;d
Qxm#h
Pad4eX&Z
YS7y9 Ojb^w/tny$Y(80!PQ2H
JGEO"ky
5d<*S&D,LS3
bbZw'tj
()=}5!DvbH&c?
g45zR*D7H1(kd5>+}
AC4erx-X(h5qQB5Q4br
[VBWBc-;e9>4|b^'+tn,!Y#\,!NC"H+
CVE7EO#ky
+mcaC%
ed?N^&O
B#)gd93
qb@L3t~
3Y3\>!^
IGO3"[li?+pmGC:@
LgDS)ff92
5tpa6Y%
#!H&&H*6z
EK.k}].+iVQC-
JB,I'bg
TFCgDS)zf9.*=bC
5tpe;Y!iz!_
a0h45zR/G7M
*;d-7+e
x(m0h$
A25W8btdxd*.D&Z
RS7jw9'
U35tpd6Y
%!M& H/6x
={prDC%ucx8)?X2qQB5Y0bzbkT<*S&D=FS"9c
>$wbN';t~L0Y3
;QPa9H
a7gR6k}
%$qx=M4h$E\B
CVD/MS0_U9'*[bM
;9:80!PS7H"cs
d45zS&E7DS(ke9?+qbACrLw
SB5H3bj
ad4zS&
'C7d!!^
9?+qbAC5tqx<Y<h0!QB4H3bk
ad5zS&E7DS(ke9?+qbAC5tqx<Y<h0!QB4H3bk
ad5zS&E7DS(ke9?+qbAC5tqx<Y<h0!QB4H3bk
ad5zS&E7DS(ke9?+qbAC5tqx<Y<h0!QB4H3bk
ad5zS&E7DS(ke9?+qbAC5tqx<Y<h0!QB4H3bk
ad5zS&E7DS(ke9?+qbAC5tqx<Y<h0!QB4H3bk
ad5zS&E7DS(ke9?+qbAC5tqx<Y<h0!QB4H3bk
ad5zS&E7DS(ke9?+qbAC5tqx<Y<h0!QB4H3bk
ad5zS&E7DS(ke9?+qbAC5tqx<Y<h0!QB4H3bk
ad5zS&E7DS(ke9?+qbAC5tqx<Y<h0!QB4H3bk
ad5zS&E7DS(ke9?+qbAC5tqx<Y<h0!QB4H3bk
ad5zS&E7DS(ke9?+qbAC5tqx<Y<h0!QB4H3bk
ad5zS&E7DS(ke9?+qbAC5tqx<Y<h0!QB4H3bk
ad5zS&E'DS:
sbUW5t
tAC-cqx
>h(6QB
>Ypr0!
sx0D<h
ad eS&
FS0te9
7t1X<Y/I0!1
G7xu(k
\qxSp<h
SBDa3b
sbih5tyT<Y
2!Yn4HKNk
E7f|(k
e<h;QB(
1bg>ad
+e9<iqb]
7te:<Y'.0!a
@QB5+3b
HqbL75t
5z}QE7
*kUN?+O
sx|!<h`XQBl
1b;yad*
G7(.(k
`d<xR&
FS$id9
}=Y(n1!
T)k'1>+]
CCq|px
Q&5=ES
H4t(u=Y
=+-m@C
>Yxp1!p[5HO
"`d"YR&i
FS0Hd9<
7tu\=Y
q2bx;`d
4t4F=Yp
=+=$@C13px
>h4fPB
A(4zMkD7X
*kEt>+g-@C
1bCP`d3+R&
FS :d94ypb]
7t}*=Y
FD7O2)k
EPBn-2b
cdiR&oQES
Mpb$)4t
4z>JD7
8=+)aCC
sxdZ>h
FSdng9
}>Y*n2!u
FS3sg9
sb][7t
cd5[Q&
1bk4cd%OQ&
FS8^g9'
7tiN>Y
{FSK&g9
2CCZ%sx
>h@pSB
37z5~G7
a=+k9CC
1bO\cdp
SB4H3bk
ad5zS&E7DS(ke9?+qbAC5tqx<Y<h0!QB4H3bk
ad5zS&E7DS(ke9?+qbAC5tqx<Y<h0!QB4H3bk
ad5zS&E7DS(ke9?+qbAC5tqx<Y<h0!QB4H3bk
ad5zS&E7DS(ke9?+qbAC5tqx<Y<h0!QB4H3bk
ad5zS&E7DS(ke9?+qbAC5tqx<Y<h0!QB4H3bk
ad5zS&E7DS(ke9?+qbAC5tqx<Y<h0!QB4H3bk
ad5zS&E7DS(ke9?+qbAC5tqx<Y<h0!QB4H3bk
ad5zS&E7DS(ke9?+qbAC5tqx<Y<h0!QB4H3bk
ad5zS&E7DS(ke9?+qbAC5tqx<Y<h0!QB4H3bk
ad5zS&E7DS(ke9?+qbAC5tqx<Y<h0!QB4H3bk
ad5zS&E7DS(ke9?+qbAC5tqx<Y<h0!QB4H3bk
ad5zS&E7DS(ke9?+qbAC5tqx<Y<h0!QB4H3b
<?xml version='1.0' encoding='UTF-8' standalone='yes'?>
<assembly xmlns='urn:schemas-microsoft-com:asm.v1' manifestVersion='1.0'>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v3">
<security>
<requestedPrivileges>
<requestedExecutionLevel level='asInvoker' uiAccess='false' />
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
api-ms-win-core-fibers-l1-1-1
api-ms-win-core-synch-l1-2-0
kernel32
api-ms-
mscoree.dll
api-ms-win-core-datetime-l1-1-1
api-ms-win-core-file-l1-2-4
api-ms-win-core-file-l1-2-2
api-ms-win-core-localization-l1-2-1
api-ms-win-core-localization-obsolete-l1-2-0
api-ms-win-core-processthreads-l1-1-2
api-ms-win-core-string-l1-1-0
api-ms-win-core-sysinfo-l1-2-1
api-ms-win-core-winrt-l1-1-0
api-ms-win-core-xstate-l2-1-0
api-ms-win-rtcore-ntuser-window-l1-1-0
api-ms-win-security-systemfunctions-l1-1-0
ext-ms-win-ntuser-dialogbox-l1-1-0
ext-ms-win-ntuser-windowstation-l1-1-0
advapi32
kernelbase
api-ms-win-appmodel-runtime-l1-1-2
user32
ext-ms-
Sunday
Monday
Tuesday
Wednesday
Thursday
Friday
Saturday
January
February
August
September
October
November
December
MM/dd/yy
dddd, MMMM dd, yyyy
HH:mm:ss
((((( H
zh-CHS
az-AZ-Latn
uz-UZ-Latn
kok-IN
syr-SY
div-MV
quz-BO
sr-SP-Latn
az-AZ-Cyrl
uz-UZ-Cyrl
quz-EC
sr-SP-Cyrl
quz-PE
smj-NO
bs-BA-Latn
smj-SE
sr-BA-Latn
sma-NO
sr-BA-Cyrl
sma-SE
sms-FI
smn-FI
zh-CHT
az-az-cyrl
az-az-latn
bs-ba-latn
div-mv
kok-in
quz-bo
quz-ec
quz-pe
sma-no
sma-se
smj-no
smj-se
smn-fi
sms-fi
sr-ba-cyrl
sr-ba-latn
sr-sp-cyrl
sr-sp-latn
syr-sy
uz-uz-cyrl
uz-uz-latn
zh-chs
zh-cht
CONOUT$
MTGestures
MTGESTURES
Antivirus Signature
Lionic Clean
tehtris Clean
MicroWorld-eScan Clean
FireEye Generic.mg.bfc060937dc90b27
CAT-QuickHeal Clean
McAfee Clean
Malwarebytes Clean
VIPRE Clean
Sangfor Trojan.Win32.Save.a
K7AntiVirus Clean
BitDefender Clean
K7GW Clean
BitDefenderTheta Clean
VirIT Clean
Cyren Clean
Symantec ML.Attribute.HighConfidence
Elastic malicious (high confidence)
ESET-NOD32 Clean
APEX Malicious
Paloalto generic.ml
ClamAV Clean
Kaspersky Clean
Alibaba Clean
NANO-Antivirus Clean
SUPERAntiSpyware Clean
Rising Clean
Sophos Clean
Baidu Clean
F-Secure Clean
DrWeb Clean
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition BehavesLike.Win64.Generic.fc
Trapmine Clean
CMC Clean
Emsisoft Trojan.Emotet (A)
Ikarus Clean
GData Clean
Jiangmin Clean
Webroot Clean
Avira Clean
MAX Clean
Antiy-AVL Clean
Gridinsoft Clean
Xcitium Clean
Arcabit Clean
ViRobot Clean
ZoneAlarm Clean
Microsoft Clean
Google Clean
AhnLab-V3 Clean
Acronis Clean
VBA32 Clean
ALYac Clean
TACHYON Clean
Cylance Clean
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Tencent Clean
Yandex Clean
SentinelOne Clean
MaxSecure Trojan.Malware.121218.susgen
Fortinet Clean
AVG Clean
Avast Clean
No IRMA results available.