Static | ZeroBOX

PE Compile Time

2023-03-10 23:00:51

PE Imphash

abb9300283e542fb453de5c4c87cd55d

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x00013583 0x00013600 6.4534054555
.rdata 0x00015000 0x0000a3e4 0x0000a400 4.78220276512
.data 0x00020000 0x00001e8c 0x00000c00 2.06345579288
.pdata 0x00022000 0x000010e0 0x00001200 4.77297887882
_RDATA 0x00024000 0x000000fc 0x00000200 2.01592036952
.rsrc 0x00025000 0x0002ab28 0x0002ac00 7.83097755011
.reloc 0x00050000 0x0000067c 0x00000800 4.92452699864

Resources

Name Offset Size Language Sub-language File type
ZWCUGR 0x00025b60 0x00029e00 LANG_ENGLISH SUBLANG_ENGLISH_US data
ZWCUGR 0x00025b60 0x00029e00 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_STRING 0x0004f960 0x00000048 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_MANIFEST 0x0004f9a8 0x0000017d LANG_ENGLISH SUBLANG_ENGLISH_US XML 1.0 document text

Imports

Library KERNEL32.dll:
0x180015038 SetFilePointerEx
0x180015040 GetConsoleMode
0x180015048 GetConsoleOutputCP
0x180015050 WriteFile
0x180015058 FlushFileBuffers
0x180015060 SetStdHandle
0x180015068 HeapSize
0x180015070 GetStringTypeW
0x180015078 GetFileType
0x180015080 GetStdHandle
0x180015088 GetProcessHeap
0x180015090 CreateFileW
0x180015098 CloseHandle
0x1800150a0 WriteConsoleW
0x1800150a8 ExitProcess
0x1800150b0 HeapReAlloc
0x1800150b8 GetLastError
0x1800150c0 LCMapStringW
0x1800150c8 FlsFree
0x1800150d0 FlsSetValue
0x1800150d8 FlsGetValue
0x1800150e0 FlsAlloc
0x1800150e8 UnhandledExceptionFilter
0x1800150f8 GetCurrentProcess
0x180015100 TerminateProcess
0x180015110 IsDebuggerPresent
0x180015118 GetStartupInfoW
0x180015120 GetModuleHandleW
0x180015128 QueryPerformanceCounter
0x180015130 GetCurrentProcessId
0x180015138 GetCurrentThreadId
0x180015140 GetSystemTimeAsFileTime
0x180015148 InitializeSListHead
0x180015150 RtlUnwindEx
0x180015158 InterlockedFlushSList
0x180015160 SetLastError
0x180015168 EncodePointer
0x180015170 RaiseException
0x180015178 EnterCriticalSection
0x180015180 LeaveCriticalSection
0x180015188 DeleteCriticalSection
0x180015198 TlsAlloc
0x1800151a0 TlsGetValue
0x1800151a8 TlsSetValue
0x1800151b0 TlsFree
0x1800151b8 FreeLibrary
0x1800151c0 GetProcAddress
0x1800151c8 LoadLibraryExW
0x1800151d0 RtlPcToFileHeader
0x1800151d8 GetModuleHandleExW
0x1800151e0 GetModuleFileNameW
0x1800151e8 HeapAlloc
0x1800151f0 HeapFree
0x1800151f8 FindClose
0x180015200 FindFirstFileExW
0x180015208 FindNextFileW
0x180015210 IsValidCodePage
0x180015218 GetACP
0x180015220 GetOEMCP
0x180015228 GetCPInfo
0x180015230 GetCommandLineA
0x180015238 GetCommandLineW
0x180015240 MultiByteToWideChar
0x180015248 WideCharToMultiByte
0x180015250 GetEnvironmentStringsW
0x180015258 FreeEnvironmentStringsW
Library USER32.dll:
0x180015268 GetGestureInfo
0x180015270 InvalidateRect
0x180015278 ScreenToClient
0x180015280 CloseGestureInfoHandle
0x180015288 EndPaint
0x180015290 BeginPaint
0x180015298 UpdateWindow
0x1800152a0 PostQuitMessage
0x1800152a8 LoadCursorW
0x1800152b0 GetMessageW
0x1800152b8 DefWindowProcW
0x1800152c0 DestroyWindow
0x1800152c8 CreateWindowExW
0x1800152d0 RegisterClassExW
0x1800152d8 LoadStringW
0x1800152e0 ShowWindow
0x1800152e8 DispatchMessageW
0x1800152f0 SetGestureConfig
0x1800152f8 TranslateAcceleratorW
0x180015300 TranslateMessage
Library GDI32.dll:
0x180015000 Polyline
0x180015008 LineTo
0x180015010 CreatePen
0x180015018 MoveToEx
0x180015020 DeleteObject
0x180015028 SelectObject
Library ntdll.dll:
0x180015310 NtQueueApcThread
0x180015318 ZwOpenSymbolicLinkObject
0x180015320 LdrFindResource_U
0x180015328 NtAllocateVirtualMemory
0x180015330 NtTestAlert
0x180015338 LdrAccessResource
0x180015340 RtlCaptureContext
0x180015348 RtlLookupFunctionEntry
0x180015350 RtlVirtualUnwind

Exports

Ordinal Address Name
1 0x180005540 DllRegisterServer
!This program cannot be run in DOS mode.
plRich
`.rdata
@.data
.pdata
@_RDATA
@.rsrc
@.reloc
` UAVAWH
H9\$0vHD
H;D$0r
|$ AVH
H3E H3E
VWATAVAWH
A_A^A\_^
WATAUAVAWH
A_A^A]A\_
H;xXu5
WATAUAVAWH
A_A^A]A\_
AUAVAWH
u4I9}(
;I9}(tiH
0A_A^A]
UVWATAUAVAWH
`A_A^A]A\_^]
@USVWATAUAVAWH
A_A^A]A\_^[]
UVWATAUAVAWH
A_A^A]A\_^]
@SVWATAUAVAWH
L!|$(L!
D$0HcH
pA_A^A]A\_^[
B(I9A(u
SVWATAUAVAWH
0A_A^A]A\_^[
t$ WATAUAVAWH
A_A^A]A\_
WATAUAVAWH
A_A^A]A\_
ffffff
fffffff
fffffff
fffffff
u3HcH<H
WATAUAVAWH
A_A^A]A\_
UVWAVAWH
0A_A^_^]
WAVAWH
A_A^_
WAVAWH
A_A^_
p0R^G'
USVWAVH
A^_^[]
D$0@8{
p*W4H
p*W4H
u$D8r(t
D81uUL9r
uED8r(t
vAD8s(t
u$D8r(t
fD91uTL9r
uED8r(t
v@D8s(t
UVWATAUAVAWH
PA_A^A]A\_^]
WATAUAVAWH
0A_A^A]A\_
H9>u+A
@USVWATAUAVH
D8t$ht
D8t$ht
A^A]A\_^[]
f9)u4H9j
u%@8j(t
l$ VWATAVAWH
L$&8\$&t,8Y
A_A^A\_^
WATAUAVAWH
A_A^A]A\_
p0R^G'
fD9t$b
t$ WATAUAVAWH
D!|$xA
A_A^A]A\_
L$ VWAVH
fD94H}aD
ATAUAVH
L$ fff
L$ |+L;
A^A]A\
@UATAUAVAWH
e0A_A^A]A\]
@UATAUAVAWH
A_A^A]A\]
WAVAWH
A_A^_
UVWATAUAVAWH
fB9<I}1L
A_A^A]A\_^]
VWATAVAW
A_A^A\_^
VATAUAVAWH
0A_A^A]A\^
@USVWATAUAVAWH
H!D$ H
xA_A^A]A\_^[]
WATAUAVAWH
0A_A^A]A\_
ffffff
fffffff
@SUVWATAVAWH
@A_A^A\_^][
LcA<E3
u HcA<H
Unknown exception
bad exception
__based(
__cdecl
__pascal
__stdcall
__thiscall
__fastcall
__vectorcall
__clrcall
__eabi
__swift_1
__swift_2
__ptr64
__restrict
__unaligned
restrict(
delete
operator
`vftable'
`vbtable'
`vcall'
`typeof'
`local static guard'
`string'
`vbase destructor'
`vector deleting destructor'
`default constructor closure'
`scalar deleting destructor'
`vector constructor iterator'
`vector destructor iterator'
`vector vbase constructor iterator'
`virtual displacement map'
`eh vector constructor iterator'
`eh vector destructor iterator'
`eh vector vbase constructor iterator'
`copy constructor closure'
`udt returning'
`local vftable'
`local vftable constructor closure'
new[]
delete[]
`omni callsig'
`placement delete closure'
`placement delete[] closure'
`managed vector constructor iterator'
`managed vector destructor iterator'
`eh vector copy constructor iterator'
`eh vector vbase copy constructor iterator'
`dynamic initializer for '
`dynamic atexit destructor for '
`vector copy constructor iterator'
`vector vbase copy constructor iterator'
`managed vector copy constructor iterator'
`local static thread guard'
operator ""
operator co_await
operator<=>
Type Descriptor'
Base Class Descriptor at (
Base Class Array'
Class Hierarchy Descriptor'
Complete Object Locator'
`anonymous namespace'
FlsAlloc
FlsFree
FlsGetValue
FlsSetValue
InitializeCriticalSectionEx
?UUUUUU
CorExitProcess
UUUUUU
UUUUUU
@^8U)zj
AreFileApisANSI
LCMapStringEx
LocaleNameToLCID
AppPolicyGetProcessTerminationMethod
Sunday
Monday
Tuesday
Wednesday
Thursday
Friday
Saturday
January
February
August
September
October
November
December
MM/dd/yy
dddd, MMMM dd, yyyy
HH:mm:ss
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
UUUUUU
UUUUUU
=imb;D
/>58d%
VM>cQ6
>jtm}S
)>6{1n
+f)>0'
;H9>&X
*StO9>T
n03>Pu
K~Je#>!
bp(=>?g
BC?>6t9^
K&>.yC
.xJ>Hf
y\PD>!
|b=})>
c [1>H'
uzKs@>
3>N;kU
kE>fvw
V6E>`"(5
?UUUUUU
?7zQ6$
pN>>6rPw+9LG5&fATinrRi1aHel%b
.text$di
.text$mn
.text$mn$00
.text$x
.text$yd
.idata$5
.00cfg
.CRT$XCA
.CRT$XCU
.CRT$XCZ
.CRT$XIA
.CRT$XIC
.CRT$XIZ
.CRT$XPA
.CRT$XPX
.CRT$XPXA
.CRT$XPZ
.CRT$XTA
.CRT$XTZ
.rdata
.rdata$r
.rdata$voltmd
.rdata$zzzdbg
.rtc$IAA
.rtc$IZZ
.rtc$TAA
.rtc$TZZ
.xdata
.xdata$x
.edata
.idata$2
.idata$3
.idata$4
.idata$6
.data$r
.data$rs
.pdata
_RDATA
.rsrc$01
.rsrc$02
MTGestures.dll
DllRegisterServer
GetLastError
ExitProcess
KERNEL32.dll
GetGestureInfo
InvalidateRect
ScreenToClient
CloseGestureInfoHandle
EndPaint
BeginPaint
UpdateWindow
PostQuitMessage
LoadCursorW
TranslateMessage
TranslateAcceleratorW
SetGestureConfig
DispatchMessageW
ShowWindow
LoadStringW
RegisterClassExW
CreateWindowExW
DestroyWindow
DefWindowProcW
GetMessageW
USER32.dll
DeleteObject
MoveToEx
CreatePen
LineTo
Polyline
SelectObject
GDI32.dll
NtQueueApcThread
ZwOpenSymbolicLinkObject
LdrFindResource_U
NtAllocateVirtualMemory
NtTestAlert
LdrAccessResource
RtlCaptureContext
RtlLookupFunctionEntry
RtlVirtualUnwind
ntdll.dll
UnhandledExceptionFilter
SetUnhandledExceptionFilter
GetCurrentProcess
TerminateProcess
IsProcessorFeaturePresent
IsDebuggerPresent
GetStartupInfoW
GetModuleHandleW
QueryPerformanceCounter
GetCurrentProcessId
GetCurrentThreadId
GetSystemTimeAsFileTime
InitializeSListHead
RtlUnwindEx
InterlockedFlushSList
SetLastError
EncodePointer
RaiseException
EnterCriticalSection
LeaveCriticalSection
DeleteCriticalSection
InitializeCriticalSectionAndSpinCount
TlsAlloc
TlsGetValue
TlsSetValue
TlsFree
FreeLibrary
GetProcAddress
LoadLibraryExW
RtlPcToFileHeader
GetModuleHandleExW
GetModuleFileNameW
HeapAlloc
HeapFree
FindClose
FindFirstFileExW
FindNextFileW
IsValidCodePage
GetACP
GetOEMCP
GetCPInfo
GetCommandLineA
GetCommandLineW
MultiByteToWideChar
WideCharToMultiByte
GetEnvironmentStringsW
FreeEnvironmentStringsW
FlsAlloc
FlsGetValue
FlsSetValue
FlsFree
LCMapStringW
GetProcessHeap
GetStdHandle
GetFileType
GetStringTypeW
HeapSize
HeapReAlloc
SetStdHandle
FlushFileBuffers
WriteFile
GetConsoleOutputCP
GetConsoleMode
SetFilePointerEx
CreateFileW
CloseHandle
WriteConsoleW
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
.?AVbad_exception@std@@
.?AVexception@std@@
.?AVtype_info@@
.?AVCGestureEngine@@
.?AVCMyGestureEngine@@
=m%bEC
cEC58'
%>fYT%
DTn2>:r
aF eN+>~
uEhvl6bH
}hg&&uA
-JR^i=a
N?LGy
5tRi}X-
H{|LG:
Qt#\o6
e+%s"8W
,1&9P;
s.b5[(
g^A g'
x"rPw/M@
nsPwjf
VLQaHe
rRipnX'4l
>5rPw/9LG
inrRi1a
pN>>6rPw+9LG5&fATinrRi1aHel%b
mP-_PX
$WI\l5@HF(:I*=
TN>>6rPw
pN>>6rPw+9LGecfA0
R[u'9L
7&faTinrRi
7rPw+)LG5$fARinrRi1aNel%b
4rPs+9LG5&dA4hnrBi1aHel5b
pN>>6r@w+9LG56fATinrRi1aXel%
rNt>6rPw+9LG5&fATinrRi1
pN>>6rPw+9LG5&fATinrRi1aHel%b
pN>>6rPw+9LG5&fATinrRi1aHel%b
pN>>6rPw+9LG5&fATinrRi1aHel%b
pN>>6r~
NA8G5&
>VinbRi1
pN>>6rPw+9LG
1abll%b
rN>46rP
)9LG5&fATinrRiqaH%BA
NG5&fATinrRi1aHel%b
OX8&5&*OTin
Pi1qHel
pN>>6rPw+9LGu&f
TinrRi1aHel%b
pN>>6rPw+9LG5&fATinrRi1aHel%b
pN>>6rPw+9LG5&fATinrRi1aHel%b
pN>>6rPw+9LG5&fATinrRi1aHel%b
pN>>6rPw+9LG5&fATinrRi1aHel%b
pN>>6rPw+9LG5&fATinrRi1aHel%b
pN>>6rPw+9LG5&fATinrRi1aHel%b
pN>>6rPw+9LG5&fATinrRi1aHel%b
pN>>6rPw+9LG5&fATinrRi1aHel%b
pN>>6rPw+9LG5&fATinrRi1aHel%b
pN>>6rPw+9LG5&fATinrRi1aHel%b
pN>>6rPw+9LG5&fATinrRi1aHel%b
pN>>6rPw+9LG5&fATinrRi1aHel%b
pN>>6rPw+9LG5&fATinrRi1aHel%b
pN>>v!
MZN-i1
pIZ~Ri
5pI#sSi
nhn;1!
>vY;%x
<ALs^T
!HE*npN
"e4!E(b-
tW1{]G
{.]7@U
5VU{.6
ATinr>
fAT%rrR
$STD%
#&8]7H9
7p)49L
A\N&$@9
/>6O*D+9C
'fAij?rRf
`qN>0]
N?6r*c+9
r#ANGq
M^mJx
M^DmY1
4jf,TrP
ILG^bB
6t#%:LG
6vM,rHe
aF xu>>
uhgys)
QF0I?%>
E72>6
P%+Hu>
+5:"1a
%pYn7a
|J^bBq
Zm1aur
elN'g'
$/Ck%b
BV`zY4L
c~ in
bBy3*x
,!,^el
@~@|\
*pNUs.g
c}>5k\
G5M#i9
^kha:
hbATT(
&$ bg>6
elN&$(W
&$$..>6
MNuRiy
ek%b_.
uhO`u0
aknro6 aHj
6?>6KIw+
?4&fb4
orRnaH
%lE;pb
0["CT!
#w9Lz<.fA[
CR#l/9
7Be:aH
6t7I@LG
#QQ0nr
,~yii1
tT^kiw&
90$efA
2>a0_D
KI-t[w
7/RM9L
,F^.el
4#&ovR
l1RJe$
{&hDPw
+|pVi&
EPWm>6
K.\#s+}
jVX"}n
70hm9L
&MAD\dl
nQ:25&]
2K8dG5
BV(vx1L
qIeld=A.
JBSi1(
SghGG5n
%l-pFb
8M.z9-
uu(<6:
,NE/el
Im1RiZ$h.
`Bk5n9
7B9<aH
E`d!>6
K&qc-p
paorR!
jnroIUaHj
h1afLl%
JB_8{:
n&Sw+q
LG^bBa
nF4t5&
fXPw@}hM
gUpL>v
EE|o+$b
mEX0:r#U1
^^Y<4&
M=g>6}
[#9Lz]
#<6rmW
pgATT+
{QGtw+R
1a# {C
77`G9L
`uk5Y%
nNMk5&
sRh1aH
v+;LG5
75p+aH
JKRiZ$/
$?03%b
7bn%bD
p>ydTi
6vIyIHe
QF V9S
6tW*7LG
!H)*ApN
"ed*irR
4|+a~R
cv_Rin
3@|\X
p>mATi
s: v+9
E0/e>6
FyJ,pf2
P*]~G>
,.jhi1
tW@=NG
tW.rg7
N?6r\;
{&sow+
vYT@Ge
uExph%b
.Pw@|d+
uXM~oc
lTVhiw$
%l%FNb
&$0J=>6
>>]6t?x
-lm9v4W1
7?jW9L
nV:-5&
Hu+9L3
|+V"&f
`q6aN>
Sm7?<1
^^V}jL
)B`1pN
+=>6Otp+9C
_UinO&T1aG
77<Z9L
{Y)bPw
5I=s6r
#FVJnr
,Fk:el
pA{~Ti
2\f$G5
|+n,&f
2R#r!)
F5]VAT
sRM6aH
5dZ$/F
G5M#&j
hn;=i1
'gyi>>
$7c)%b
98Jg&\
$/ap%b
@Q3>Vi
{Yf)Pw
,VMLel
KQS9cw
L+]!f
pNU{.O
Mae<elN&$ m
k%bXi4
@5&LTTi
I>>z!Pw
bl%L E
p+9)35&
l%_n$N>1
p9NARi
fA?-J&o
9aH$2z<[-
jz9]6t3
&$8pM>6
F`rN>w
|2;k63N\
$9d4A'
(rPw@|
?qG5M#
;-x#\/
M=->6}
dl%|7pN
0aHBC;b
1lrR2l
)H-7S8
#iX+nr
tAj$l%#
K&bfQw
p6bATi
$Xp}%bk5^5
%EaN'
MJ'Gi1
9LG`]?
`rk#N>Usb
{.-bw+
m%bAEN>
I`Hecrb
I`He`Gc
N?6r@]+9
5p])oC0
vY+/Ee
pe)$Ri
Pw@}hw[
?Pi1\A
w+9J:;&
nrR-IaH
N>>|RPw
G5&T.Ti
LG5_.AT
Pw+i"g9
TinRvi1
rRi!)[S
rRi5oHe
pNohwy
Pw+LZG5
el%LxpN
ATik/),
}h'pZfA
N>>SmPw@
RVty@}hcc
46;dlm
XEpNU{
vi0aH-
9LGmUfA
MAc el
*Vz<OX!
ed9`Wo
>F5&[T
lb7@1*
6tW9}LG
%lUZjb
RiZ%lU
Pw@}hw/
Mqn~D<
tT~*X%u
M.$1i1
Sk~DG5
LG^bBy#
n)Bm5&
{. bPw
5VSB6r
5^V\6r
EOd_>6A
n6!I5&
4O-KuR
28<WG5
su#+9
LG^cih
2<<lG5
Dv&Egu
DTfFl6r
pY!gRi
bBqBsnr
bBa5:nr
MN7<i1
,h.Krp
LG^cN`
n6po5&
7=^OaH
2TmJG5
2VZ<g6
1-p#V1
7's69L
^FjrK
#WwrR!
7'z>9L
^NSE5&
KAH([w
59qL6r
^F9WU'
]=6rm$M9LH
MgATT,
2LFuG5
43W7D
77q^9L
9 gUfA
6t?(QLG}
cug_A!
6tWEWLG
pUinOg-1a<
g}pfA?,N
sZmR+9
SFhMbP
.pPw*9LG
%Pw@}hw#
$jFUrV($
bBq(T*N
cN/'f9
-lm9v*
#fAi"~rRf
,v(2i1
7H$Q9L
tA@Wl%
!=IiO|
")9Lz<
n!e55&
#aAunr
EPp$bH
vt9,)W
ty)dl%
"ett1rR
E09(>6
u(e<"6
0Cu@ThnrR
DI<P.>
tIY[l%
5~qx6r;2
-Jz+t1a{
sRitPHe
F5&,bTi
o0aHX;
#YX{nr
,v%ni1
5nA|6r
7J(^aH
Ri1,el
pN>.6rP:
+N&$PX
rPwm!LG}
c='fAS
TF?>6%
pYTERiy
INel-%
pNLC6r
jPi1a<6
pNp|6r
lA5&U%
G-9LHH
ZTi1[[el
(vN>c|
JVw+#Z
AhrRjv
xq+9`y5&
jo1aqu
@H>>6;Pw
tPw3[LG
f8>6LZw+R
`cl%Acg
I7aH4@
n8>6$f
RVw+&0X9
HH>>Wk
XH>>FYPw
^tRi)ONe
pNu.6r
TF?>66
pN>Xt{P
ATiBrRiy
:-{#\8
6vI5aHe$
%lEjHb
MN4zi1
G5M#YJ
A61Riy
}h{S^fA
:]6tGz
Mhw,r o
M^0hnF
AF8~%z
aF<JQ>>
tM^bByi
-JJ4[1a
aF4d:>>
pAorR%
l}m%bA
JJSi1(
$PO>>.
My`Hexrb
:-{#]1
G5M"edC
lUeN&$@
MZ$Bi1
|XY&f*
g! $f^
inr!k1a
Adp4W8
tQQ,l%
DY:)`%
6tGreLG
tWX{LG
6v9nAHe
rVp:n9L
6ve+dHe_
@5&lTi
irRxJaH
fHet(Y
pN[P6r
I>>b!Wwo
aAT?[%\
Oel@Qt^
6M$N>r
>LGS8\B
ce^2AT
psi'6r_
KVi1\m(l%m
p1M6Ri
5p5X|)
%J&tlDd#!Hql
&Ma[O6l
rRi1-G"
>'fAiJ
f1UsZC
#a%;nr
Pw+jg$
8cq&&{b
$DKS96
DT.PZ6r
G5&[h7
>6r*6+9
nrReQ$?
5pYzCTi
M9`He$
Mb5&.
aHeZjb
6&fS-in
t+9g>5&
:LG{gkA
OG5^nAT
qRi@oHe
qPw'LLG
NvPwtg
#Q)#nr
+b_.1a
{.s.Pw
4|ZTrR
|T0O&f
6tG}sLG^bBq
*VbPsaH
uhO`u1
T|sHec
sN>PErP
fl%TKf=
fl%-NpN
7HJE9L
V.Usj6
7H%M9L,x>
]KN>1r
?/9Lzu
!zo|Si
9Ptq9a
Pw@|T\
f6r;23V
sb-h+9
ty# tB
}FTiSiUi1n
6vI=kHe
nr9,^?
)JO[pN
({lfA?$
E.n>6
6r;2Df
-lUf@;
6v-rOHe
M.# l1
LG:6&q
0Zf!)X
rnk5V3
5^96r
M^Z9i1-
$'o@%b
-JzVb1a
=`k5Vj
q%G5M#
fAT1rR
TN?>6;
Ri1fhel
JBQ4;c
VE?-JBx
p6:~Ti
%l%Lhb
Pw.dXG5j
c>)>in
'Pa6>>
9L,pv3
,6=xi1
!LG^c6
'9R Ne
>!,k1%
($3d<A-
LgATT%
K8LG~+
8v+9~l5&
pN[}6r
)Uin92i1
]'fA_A
dJKl%*
*9Ll6&f
<hnr6Y
C8LGglfA
:h1aVOl%
^sPwNlLG
:h1a$Cl%
^sPw6.}
V?6rt!
4rhelm
^sPwb,
Y`HegW)
@Ti}|Ri
O>>RsPw
Y`He.W
0aHhQ%b
QMG5(B
*9Lj$&f
orR37aH
*9L$.&f
sRi;"He
bBaR7nr
p)JnRi
culgAT
lS>>]7
tA# Lj
-W1Z->#
|li`&f
p6}FTi
LGA4[i
u{u>66
^)9Lo&
UhWcq'
inrRi1a
MNeui1
KfA?-J
EEl@i.
|_;o&f
,eR i1
p)JGTi
}hc.8fA
uh/^jB)
N>>CxPw
,Pw_#q
DT~9F6r
$@36%76
,^BJel
[Yt;2D{
<>6O#l+9C
a'fAi&7rRf
elQ~=I
5pYoR7j
el%0epN
fATJKrR
%lUv b
2VZ<g6
i!HrRf
Qin;q=y
Qinh?q
Uw+_,G5
&ManNel
l1a9rl%
K>>P%Pw
krR~2dH
uN>}TrP
`l%3$pNU
`l%7IxYz
;>6^#E+
0&fIpin
SG5M#Y_
AbHet8
"j1am5]d
=6rJC+9
Qi15lGg
sN>BIU[
xsN>BM
Qi1HgY
IOG5;0AT
M>>3KPw
4D5&(y7
<D5&-]
}hs36fA
Vv\mlH
3AIw+q
)H-7S'
cN5Oin
gUinOQ<1aG
|Q# \s
`J?;N>
5&fATinrRi1aHel%b
pN>>6rPw+9LG5&fATinrRi1aHel%b
pN>>6rPw+9LG5&fATinrRi1aHel%b
pN>>6rPw+9LG5&gGVih
PY0eIeh
qC:>;F@w&
nrSm0aL'l%c
xN%J%rK
:9Ws%&}
@9oxPi;
zz6>< V
dqUelr^
41Ioh%h4zN4L0
Qc#9X#%&r
[izF\i%
o*->)&Bw4
?*5rDva9I
5&g^_iq
Ki.5Pes
?ILG4)`A[
cr]]=aG
?rC%$IM^?&
@i(5Yeu
B{As]rruh'aT
*n6rQk 9P3,&z%Lir&Ei-U^ep$v
>>7}Rw$
a_Q|%u
8&ruXiz
0~CesQB
o*!>)FNw48VG!
D9nrSe3aD
vN,J8rBC'9^
>vgHVig
P90~Oes
$iLG4;aAIh&r\
kPpN?.4r@
"iMO4&n
TiobVi!UZe|
dPqG<>?
UG*?NG3tdqU`lr[[31I{g%|dkN
,rNv?9^
e"Ri0iIed
ZG"iLG4:mAH]DrNh
V'+9MP2&q5uiyFri&`Vegub
QG/'~AZ
Y91aIze%}t[N!ZrOC
Tio{Pi8
cz4>% _
*1MG=DfAUsgrH
,aRQp%x
['+9M]=&|
AitFFi+
}Ur`ql7>
<Avh6rF91aIcn%d2r~?%<rK
&}u@iu
XG.'tAD9nrSe3aD
/rHv99@
h"Ri0mJe`WgPqJ?>2
Pw**KG&
7QM5l%c
rN.L?"Qf(9]Fy&d
Pi<SAUm7j
.>$F^w9
9Vm!UsirHh'aF
`Ui`z~7n6rQg.9\F'&b1WYl"Ri0wOez$t
SG)iLG48aAJ
aVd %rPpN?
q[:>#s
hBW91aIoh%h4|N4
Qo!9T#!&~
GivF@i)
rpq^8>&
j1UskrHh{aC
Ew1]_G/
~"Ss9aR
y%xddN$
;iMg9&F5CiN
fAUudrN
x%~TcN"
oO&>""Pw*,OG 'tA]9nrSu:aTQJ%~
Tio|Qi?`\enub
ZG"iLG4)`A[
`r]]=aG
rN1L=BQa#9Z#&&puDix
dOf>3"Pw*&FG*BqAK=xrM]$aW
d>?!;rO
,&yuLiqs@i)
`>>>7xTw!
`1UpirKh
dUe`v~;n6rQx/9Cs?&i3_
>="Pw**JG&BiAG]`rA
Iza%}dnN!j+rOC79SF#&~
g*4>!FXw<k_741nAC=}rE]#a_
sp`.?10r_C%9C
=Va!R9ojZi)
akdL%z
@'+9M_=&~%Giv&@i)UYet
vpq[8>#
>aXQb%r
|>?+3rEC
9YFg&`
TiobPi!
*5>9FZw$KG74=nAO={rI]"aS
wpd.?.2r@C'9\
9VgXRiwFDi(
}ErPqY8>!s
w#IK'3
gPpN?32r]C!9A53vgZ^iu
(akQt%A
D'+9MX>&y
oO*>""Pw*,OG '|A]9nrSp;aQ
}%{d`N'j9rIC%9U
gTWi{sFi81Hem7j
/>$F@w9
9Vm!UudrN]$aT
iM^1&
idB[90{@evAv
"aRQ~%x
?,>rB#&9^s9&t3Z
Gw0mZG.
rAOh|rF
1aIzg%}
&y@Jiz"Ri0sJe~Wl0qV7>.Fbw38`G9
T91aIrk%u4
5&gWPixFXi'
>3"Pw*+HG'tm1^Yg"Sf3aGWg
pN>>6rPw+9
<BfATi|
Pi0aHem%b
NzRZ 5
BJ8"Gu
rRi1aHel%b
pN>>6rPw+9LG5&fATinrRi1aHel%b
pN>>6rPw+9LG5&fATinrRi1aHel%b
pN>>6rPw+9LG5&fATinrRi1aHel%b
pN>>6rPw+9LG5&fATinrRi1aHel%b
pN>>6rPw+9LG5&fATinrRi1aHel%b
pN>>6rPw+9LG5&fATinrRi1aHel%b
pN>>6rPw+9LG5&fATinrRi1aHul%
X]>>|aPw7
NGy5fA
l+9y[5&2
ViVnRin}Hep
h+9\e5&
Vi~PRi
fA5Lnr6
3a,@l%.(pN
d>>zYPw
4r<Z+9)i5&n
\RifNHeH
^l%h>pN~
4r\I+9
Vi^3Ri
>>31Pww
NG=efA
Vi69Ri[-Hed
*l%0PpN
Ri.8He
NG5zfAv5nrN
3al9l%
Vi.,Ri
NGiAfA
>>t{Qw
NGq/gA\eor^
3a@im%8
Vi*`Si[rIe0
]?>)fQwc
Y?>0kQw
NG=?gA
l*9bZ4&B
Vi.oSi-
9gAPYor:
3aLUm%
Vi2GSi
bgAd/orb
3ax#m%
*m%"PqN
Vi>#SiS3Ied
rgA,>orV
3a02m%
*9z.4&
m%oqN
?>vvRw
NGu"dA
q)93O7&^
zPi%mJe(
zn%% rN
0l<>zQRw
Vin[Pi
dA|Blrv
3a`Nn%
\)9xj7&
ViZ_Pi
u<>c"Rw
NGmvdAS8lrN
3a@4n%
dA23lr
3a ?n%
4r$,)9
/Pi;?Je0
xdA&6lrR
3a<:n%NarNz
n%#krN~
NGYIdA
)9y?7&
3aHel%b
pN>>6rPw+9LG5&fATinrRi1aHel%b
pN>>6rPw+9LG5&fATinrRi1aHel%b
pN>>6rPw+9LG5&fATinrRi1aHel%b
pN>>6rPw+9LG5&fATinrRi1aHel%b
pN>>6rPw+9LG5&fATinrRi1aHel%b
pN>>6rPw+9LG5&fATinrRi1aHel%b
pN>>6rPw+9LG5&fATinrRi1aHel%b
pN>>6rPw+9LG5&fATinrRi1aHel%b
pN>>6rPw+9LG5&fATinrRi1aHel%b
pN>>6rPw+9LG5&fATinrRi1aHel%b
pN>>6rPw+9LG5&fATinrRi1aHel%b
pN>>6rPw+9LG5&fATinrRi1aHel%b
pN>>6rPw+9LG5&fATinrRi1aHel%b
pN>>6rPw+9LG5&fATinrRi1aHel%b
pN>>6rPw+9
<?xml version='1.0' encoding='UTF-8' standalone='yes'?>
<assembly xmlns='urn:schemas-microsoft-com:asm.v1' manifestVersion='1.0'>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v3">
<security>
<requestedPrivileges>
<requestedExecutionLevel level='asInvoker' uiAccess='false' />
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
api-ms-win-core-fibers-l1-1-1
api-ms-win-core-synch-l1-2-0
kernel32
api-ms-
mscoree.dll
api-ms-win-core-datetime-l1-1-1
api-ms-win-core-file-l1-2-4
api-ms-win-core-file-l1-2-2
api-ms-win-core-localization-l1-2-1
api-ms-win-core-localization-obsolete-l1-2-0
api-ms-win-core-processthreads-l1-1-2
api-ms-win-core-string-l1-1-0
api-ms-win-core-sysinfo-l1-2-1
api-ms-win-core-winrt-l1-1-0
api-ms-win-core-xstate-l2-1-0
api-ms-win-rtcore-ntuser-window-l1-1-0
api-ms-win-security-systemfunctions-l1-1-0
ext-ms-win-ntuser-dialogbox-l1-1-0
ext-ms-win-ntuser-windowstation-l1-1-0
advapi32
kernelbase
api-ms-win-appmodel-runtime-l1-1-2
user32
ext-ms-
Sunday
Monday
Tuesday
Wednesday
Thursday
Friday
Saturday
January
February
August
September
October
November
December
MM/dd/yy
dddd, MMMM dd, yyyy
HH:mm:ss
((((( H
zh-CHS
az-AZ-Latn
uz-UZ-Latn
kok-IN
syr-SY
div-MV
quz-BO
sr-SP-Latn
az-AZ-Cyrl
uz-UZ-Cyrl
quz-EC
sr-SP-Cyrl
quz-PE
smj-NO
bs-BA-Latn
smj-SE
sr-BA-Latn
sma-NO
sr-BA-Cyrl
sma-SE
sms-FI
smn-FI
zh-CHT
az-az-cyrl
az-az-latn
bs-ba-latn
div-mv
kok-in
quz-bo
quz-ec
quz-pe
sma-no
sma-se
smj-no
smj-se
smn-fi
sms-fi
sr-ba-cyrl
sr-ba-latn
sr-sp-cyrl
sr-sp-latn
syr-sy
uz-uz-cyrl
uz-uz-latn
zh-chs
zh-cht
CONOUT$
ZWCUGR
ZWCUGR
MTGestures
MTGESTURES
Antivirus Signature
Bkav Clean
Lionic Clean
tehtris Clean
ClamAV Clean
CMC Clean
CAT-QuickHeal Clean
ALYac Clean
Malwarebytes Clean
Zillya Clean
Sangfor Clean
K7AntiVirus Clean
BitDefender Clean
K7GW Clean
CrowdStrike win/malicious_confidence_100% (D)
Baidu Clean
VirIT Clean
Cyren Clean
Symantec ML.Attribute.HighConfidence
Elastic malicious (high confidence)
ESET-NOD32 Clean
APEX Malicious
Avast Clean
Cynet Malicious (score: 100)
Kaspersky Clean
Alibaba Clean
NANO-Antivirus Clean
SUPERAntiSpyware Clean
MicroWorld-eScan Clean
Tencent Clean
Emsisoft Trojan.Emotet (A)
F-Secure Clean
DrWeb Clean
VIPRE Clean
TrendMicro Clean
McAfee-GW-Edition BehavesLike.Win64.Generic.fc
Trapmine Clean
FireEye Generic.mg.27c6e6bc4b46148f
Sophos Generic ML PUA (PUA)
SentinelOne Clean
Jiangmin Clean
Webroot Clean
Avira Clean
Antiy-AVL Clean
Microsoft Clean
Gridinsoft Clean
Xcitium Clean
Arcabit Clean
ViRobot Clean
ZoneAlarm Clean
GData Clean
Google Clean
AhnLab-V3 Clean
Acronis Clean
McAfee Clean
TACHYON Clean
VBA32 Clean
Cylance Clean
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Rising Clean
Yandex Clean
MAX Clean
MaxSecure Trojan.Malware.300983.susgen
Fortinet Clean
BitDefenderTheta Clean
AVG Clean
Paloalto Clean
No IRMA results available.