Static | ZeroBOX

PE Compile Time

2023-03-03 01:39:22

PE Imphash

895e5e6e037e9108574fb94ed614d804

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x00001b1f 0x00000000 0.0
.rdata 0x00003000 0x00001168 0x00000000 0.0
.data 0x00005000 0x00000064 0x00000000 0.0
.lol0 0x00006000 0x003570c4 0x00000000 0.0
.lol1 0x0035e000 0x00000398 0x00000400 3.62377151553
.lol2 0x0035f000 0x00604e20 0x00605000 7.95840723085
.rsrc 0x00964000 0x000005bd 0x00000600 4.08391215637

Resources

Name Offset Size Language Sub-language File type
RT_VERSION 0x009640a0 0x000003a0 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_MANIFEST 0x00964440 0x0000017d LANG_ENGLISH SUBLANG_ENGLISH_US XML 1.0 document text

Imports

Library KERNEL32.dll:
0x75e000 LoadLibraryW
0x75e004 GetProcAddress
0x75e008 ReadFile
0x75e00c WriteFile
0x75e010 lstrlenA
0x75e014 WaitForSingleObject
0x75e018 LocalAlloc
0x75e01c CreateFileW
0x75e020 MultiByteToWideChar
0x75e024 DeleteFileW
0x75e028 CloseHandle
0x75e02c ExitProcess
0x75e030 CreateProcessW
0x75e034 CopyFileW
0x75e038 WideCharToMultiByte
0x75e03c Sleep
0x75e040 GlobalFree
Library SHELL32.dll:
0x75e048 SHGetFolderPathW
Library KERNEL32.dll:
0x75e054 GetModuleHandleA
0x75e058 CreateEventA
0x75e05c GetModuleFileNameW
0x75e060 TerminateProcess
0x75e064 GetCurrentProcess
0x75e06c Thread32First
0x75e070 GetCurrentProcessId
0x75e074 GetCurrentThreadId
0x75e078 OpenThread
0x75e07c Thread32Next
0x75e080 CloseHandle
0x75e084 SuspendThread
0x75e088 ResumeThread
0x75e08c WriteProcessMemory
0x75e090 GetSystemInfo
0x75e094 VirtualAlloc
0x75e098 VirtualProtect
0x75e09c VirtualFree
0x75e0a8 GetCurrentThread
0x75e0b0 Sleep
0x75e0b4 LoadLibraryA
0x75e0b8 FreeLibrary
0x75e0bc GetTickCount
0x75e0c8 GlobalFree
0x75e0cc LocalAlloc
0x75e0d0 LocalFree
0x75e0d4 GetProcAddress
0x75e0d8 ExitProcess
0x75e0ec GetModuleHandleW
0x75e0f0 LoadResource
0x75e0f4 MultiByteToWideChar
0x75e0f8 FindResourceExW
0x75e0fc FindResourceExA
0x75e100 WideCharToMultiByte
0x75e104 GetThreadLocale
0x75e108 GetUserDefaultLCID
0x75e110 EnumResourceNamesA
0x75e114 EnumResourceNamesW
0x75e120 EnumResourceTypesA
0x75e124 EnumResourceTypesW
0x75e128 CreateFileW
0x75e12c LoadLibraryW
0x75e130 GetLastError
0x75e134 FlushFileBuffers
0x75e138 WriteConsoleW
0x75e13c SetStdHandle
0x75e144 DecodePointer
0x75e148 GetCommandLineA
0x75e14c RaiseException
0x75e150 HeapFree
0x75e154 GetCPInfo
0x75e160 GetACP
0x75e164 GetOEMCP
0x75e168 IsValidCodePage
0x75e16c EncodePointer
0x75e170 TlsAlloc
0x75e174 TlsGetValue
0x75e178 TlsSetValue
0x75e17c TlsFree
0x75e180 SetLastError
0x75e18c IsDebuggerPresent
0x75e190 HeapAlloc
0x75e194 LCMapStringW
0x75e198 GetStringTypeW
0x75e19c SetHandleCount
0x75e1a0 GetStdHandle
0x75e1a8 GetFileType
0x75e1ac GetStartupInfoW
0x75e1b0 GetModuleFileNameA
0x75e1bc HeapCreate
0x75e1c0 HeapDestroy
0x75e1c8 HeapSize
0x75e1cc WriteFile
0x75e1d0 RtlUnwind
0x75e1d4 SetFilePointer
0x75e1d8 GetConsoleCP
0x75e1dc GetConsoleMode
0x75e1e0 HeapReAlloc
0x75e1e4 VirtualQuery
Library USER32.dll:
0x75e1ec CharUpperBuffW
Library KERNEL32.dll:
0x75e1f4 LocalAlloc
0x75e1f8 LocalFree
0x75e1fc GetModuleFileNameW
0x75e200 ExitProcess
0x75e204 LoadLibraryA
0x75e208 GetModuleHandleA
0x75e20c GetProcAddress

!This program cannot be run in DOS mode.
`.rdata
@.data
`.lol1
`.rsrc
FreeLibrary
?"e6,1
^]ZP`7
;C{Y>{{(
Irhm?EG"u|PCRY
;N89J
1\7W$1
?L3D`dY
uQU|)
N(GQbA
k7=k[0J
'_eVvV
Z0U1]G
p_`i@X
..ATA_Hc
AWD1$$M
NR$]%tR_
t:)V!M;
ieCp%l
\q;}Nc
"5EjInf
@`+)f;
q%4)Fo
Fe6w.Q6
^N3PveZ
g8TO]XKs
NV-3q
x>3T(P
"r"a,;
H),|:
,QQZ5:
SNa]f3
/!-\f;
%Y&VVQ
J/k5G6
sQx3*Pd~l
GetStringTypeW
i<Q|23
0Dv6lZE{
&p~;KR
3^aif;
D14$fE
,P|'*ijt')x
!Uoo-L
GH<j KRbU
LCMapStringW
hL=/v
}S]*__
`~5Af;
Vt:c^U$w*
/;U!$>`x
}\afy0
AXzwkK6:t
`17I}q
cF]>+H
}hMM~e
^&(POIL
ozU@[9
(Tb@Ml]
nVK"=7
f)L$ R
-/[oXf
JtLy(*
O3J^cp
B|A@ixRA
AW1,$A
_0>=i<
&qqj{!
WJ1f.sN
'E?4I6[
*'$2&>.l
9^mO#Z
vE.T$zD
&z>`j.`
n1xY*:
zd+Cm9
hCXbB(
5-%,?1n
&LUU'S
N=ec'H
b2s>N',
!V%:>8X
2rOsc{
ns[<?z
erJLUu=
/0g2Z}
Jj3ANP
;}'BX;~
LocalFree
,f5LXf
VS9AWfD
GetLastError
[z=15>z
y[gHu~
V9KxQC
#Bf+Br^K
=u|T1;
9Dhk3a%
)WQG\E&
.QXKcvk
X&?#>!
OA}\oi
+EQ#T$
Z:KAW1,$A_f
3i8KU^i1
I6FLoW
c5Pog'
|i>!>x
=%0hFZ
K}AWfA
HD1$$fD
tz7<`tM_
P\`}A$;
_}L?ZP
!wNch(
:21Jff
`#";m
j"xzd`R2Wva
j"3Pyd`r.Tva
IFn5FVo3
|_tb3P
f4u^|<$
JUok*#X
?67IQ4
j,qwtF,
q-IO@K-
5\N(dT
ZLK(B]
u_y<L5
BqJR-rD
02q|rtj
ysM`It:
]SV&Ps
?S9bTI0B
q5m6}'!q
Y1,$A_Hc
JfpFDk
vK<h 2jOhH
>0><}&
]-tM8-
]fi n
l0ZD3S
D==jf;
Sz]k{g
H.a]I^!
AWD1$$A_
-Ro7qf
>D4d8c
d4C}wdM
z.X_i;Bd
`d`]I
qdLn*fk'&!
|$0BUUG
'oKKa\
xvZbu[
LS#K!&
D$ :n/K
t$ (|$
VIhDe<9b`
RO-f3t|W
kEgFN:]&0
tnmGua
=KbYUZ6
A]A^A_
=38LwK.
-LT,Zs
*|cIvAx`
WNg7Gfpg
+h?h])
2{c`r?'f
8g2V!$
AWD1$$A
V|'hI8
#*eA0{b
LocalFree
(U41`[o
mLGGBm
%3O{ubw
nPzQrtP
i(4*O(
H2AWA
D14$E"
4$rk>P
@LO^zR
m`q%cF
?`\HRq
>>..Q-
D$$3t$$f1t$$
^xq':P
6Qi7t1t_
bkKHb5
ld@T|o`
pDfP9'
\ZF}ax
tM"]DJU
d$n/5-
8%z`i,
YIf.iN
/c.'X
B!;,r&L
t+Ny+
7ql//uA
Mo&jrG
lW0r3/ E5y$
X_Y]Z^
hH|eXO
$ $Xu)
M,Y)J[
/!5(&B
s !gC'V
va<<v&s
5/g-d5
n);Gq5:m
NH9c-<`
pSzQNs
=5,2IZ
0 dz2"U
S]i;a
pdy<H
AWD14$M
nAuStx
4D'M8\
_h%5)fi
5WTJVkWQ
v$Uf)t$
V5=4fz5B
/5{+r067
!}$SHx
\Rs%$pRlwr
\9GIHe
1gB&2[4
b-Z*yN
SetFilePointer
EnumResourceTypesW
AYA\fE
^A[A]fE
}Z/r0d
|$9AQL
4nnS9`5
m-s6BO,
hQF+<3
fD!D$@
!b1'Iox
DnlF7v
D$ t,gx
f)L$ +
Itf%%M
{\^U7i
2eqxn*e
2}k[8H;
9?$[N+#
"q@Mj9
vG`;:Ej
v/0aW+
G?8>z-?'9
]] $:~
q'%4X?qmw
Pt~bMJ
*$MZ>M
b?3dgR+b
-&'{#/3QPu
Dl>1Pc
GetStdHandle
\T$J1?
x7"IUS,
|)\F-
ADTGqC#
w(M6G/:
mJ5+SF
:c\&#iw
_BROest=
Qh%'7b
bj!B}1
Z}-H2OL
NMhSLx.!
U'|IT1b
SHELL32.dll
Q-"uX
f=,@f;
i6T:VY
iU}@BX
.(.t&8kK
77mwn
FC7K~J
UWL;%zgLB
-<.pfb
edd-||
#N+()_
=Mp^vK
f[^fV\)
6SX<1$
t$ 8VW
:1UsN8@
K]^[H
oqeNU'
l0*d(k@
l4Glz6$
M)(m_t
A<7"Ti_
l$Pf!|$@
f5LXf3
=p;ThWq
f1t$8H
_G&_SVf*
fK#dj8bV
+tx]^*
.H(jZGM
opUd[\>SN
PvKon:
-6\0^4W\%
9L9=,J
Ba1f)l$
;O.>@;
TFA%Q%25y
1O16^jR
TvBw(X
4uw&|6owq
&wabSo
b)MJ3
_DEKoC2
i(\:Y/+
r>%C3'
HE_i^o
O2PELA
i2!~J,,
jo'cH'
tQcJ,/
[TvWcy#F$
D$X"T$%
+@1Ff;
6M!*<Cy
mm-7%l<
(u"r S9o
tCLyM6
"|W3f#
73"8f;
~B>su%
^?$Ke4>&
=#qz,3
RJ9{60
SJl|'`x
L;FV#:Y
>1W##>
."xQFK1#Qz
.Hx6V*
UePRgM
^I#bRe
.F+q)@
nZ]"}&
v7fAWfA
1,$A_fE
SuspendThread
!^\L(Dm
DsMcm9
I4Hr]<
][]XXz
30OIp5
$yP!_Y
AG3@xsSL
s yJc_Sd
H\$ fD9\$@
,5nQ#lh
&?h2[4w
%&6M#'
MC<I?9
au<lH#1
-6q!{/,q
D]O]D
>D1$$A
GlobalFree
lm.acS7kS
280uN~
'\fJ?8-
IGB|mKH
lD1,$A_Mc
qLQ.D,[
;Q?bht
DQ"uU'
wm$Z#~
q\Qgxn1C
<C@GNE
h(cX|j
D%6b!8ft
H(.Pjn
d"B]_d
D14$fA
f{L%V|;
AU6h$Nf
%eLoNs
CR3y,?KEp
.m"5H]<
F\Zmn
OAev'c
2^|59!
Do/FQ~oL3e
~yfGQ7
$c?zo
WVQhuN
BK`Pf;
~>8AWE
m/PnOc
Oj"L5W^
\h"wxC
k/PTYe
pzI/MB
W1PAFY
S:wR{.
R-RH#}
@#"K)d
,<6'+d
5Pog'A
4?9=\6dI
k6ve$#
|#Nf^Z&
Pjo6%
%#f`Cd
9lQwg_
JnK,Qw0
AW1,$M
GA/# hQ
uddTHI
EnM|I(
wZQXD=
ZK1PJN
;=|e];
{]%hNm
Y!/E.~
!]Ln}ng2@X
cDf5&=
}K,888
p;7FSC;%
B;x9OI;
beh.7aV
'vniOS
pP~$57Fc
fDssUj
/avh;M
T(gjezz
iUfg-
Ogqoq<N
BsfT(U
DeleteFileW
;f*?!#c'
iv'W;V
]kE~z"#
xP*7!@/T
_Vz5:{
\+em7@
%eH}KL
9D1$$A
(+'JW]V
:5nzK/
n4Fe:4$
x_>jg.
nw+f?~
r{ZN{
Hr~exu
==$x5Z
$A_fD;
moZcNc
Mf\N/`
dD14$M
C2?6us
J n<m'
?QbIlq
XS67{G%
`$Bs$u
n$u[A4
9.F|to
c[QQ^'
{Q'a+WQ
e{q;?s$q
1]Prz)
d--4I^-
/CQbIR
_Zn(-O
HcvK8-
GetEnvironmentStringsW
D1,$A_Mc
JJYxf;
5C:[xs
s0PC\}
A%>rG?
v~a5-D
!T#39g
,Z[;1
B5eO%
NeGq%
|N&jHJ
:[q>,U
QueryPerformanceCounter
e-W3$m+
J}~QJ
Qh]HhxY
VQhJ*(
3!l\L`5-
D&BOCQ
o-j0>$
R@b1bG
)+|%.\
I(?3y/H
d,{@T+
\x^fc
$HT0xv
RtlUnwind
LocalAlloc
l$#SARI
a~v$?=_
-xT#ja
4+i15v:
#kJK39
-4H8k-
}<tJ1C
'XL#.iP
o@zLA@
:z`{ks
f{t47r
@~!7pyV
mzeD]}
,D1,$fD
EFC5taZY
(F*N)
bEqRk;
'K kF;8
4uIYtp
RB@1LY
+6-,rW
&e}rI)
DU*$fuP
4;AV(@
+RI}[;
<ZBdu@
4IL0KTw3
5:n`>H
lP<~TU
wAW1,$M
AWD1$$fE
N7}P*L-}
uaWVLB
8]*V5H
v4gU:`
/c:|^@
aC,P'qS])I
9Ll=Zp
-\)yN?
M~WK:v
D[\!x
x5W p_
8AW14$A_
M)0U82
>0.l9k;8
HIM.U7
0!U/`/
d|uRbj[
4Tn7f;
Ax"[~X
="jHjs(}+
EnumResourceNamesW
}hP!<~v
D14$fA
;j%#rZ#
; NB~<9
K{w:Qz
9oXB=l
e5o?}b$
^ulRt@/{
D\iUHn
#[g]sp/
4,zd4eXO
LH9CeXOk
}4eXOkMa
KX|eXO
QT|eXO
fJqt]*H,
N0R~Bw
l<<T'r
aXREr>J
q>*@#@
$qpD r
a6%@#zG
;/_tND
*ej\'~
)W`h@%
L31,yN)1
#<A8s#
'y y h
@.*;$z
g97;zg
ImR{AQD2
}wlN/1
T"LhKbE
8r}Ki{
w(H.p_
orxt_u
{An0MJ
6;:x7IE
k{P3-f
A577xu
.vLirCHN@
nciBWf
+"`v7U
o8Z"OG
OzSr_&
p~yIth*/
OGThe}
dhann<<
Ln6rDP
F@AAmz
2CJ~fn
wYBIX
/pXrE#~
X(i!s1<
HWr8"=sF{E
*gK/[P(
y`2[/&
{m@3op?EN
78Sy9A
rV'Y#_
b?k+R8
yW6)IPA
TSrZdT
X6X@f=
u-OJm=
(rz4]cl
bK+L>}B
"c:@GK
[qV00Ip
D$ f3L$!
$lCQPg
D==j5R
NXN}_o+N=?
+lG$9!I
WQ^`OV
D$(l!7D
AW1,$A
@I1^_r
lQfHT@
Xn]8uyJA
RofV%^
c|x";c
D==j5R
d9+Xgd
KV3htL%
HQbEZ5e
YF870!
E_G#OD
jCZw}Z
D1,$A_Mc
-5:^ MHf
5*bQCf;
;&RkY;
8`ODB~
B<bj4
k~)w}6
"1O=s8
~0[r/9
\G</[0
C]SssZ$
HUh7q88
l$A[L3
<P'^C"m
UW!3or
,IRFi<
uqf;T$
}Rx6,d
>t<p\+Yf
f=Ix5z
WaitForSingleObject
uzfsg7
'DagVYf
]-H-i1
~Rg)Lp\
CDOrO>
42HH_Nxw
KmS!x|
?=E`pj=/-
a*|J#q
Q~&agdM
S{Tv>h
]O${00|
v:Y8wm
7sFoX0
_a+hi5
Wt?0O3
UmLk@Hh
# {J')
[16|Rk
5Pog'A;
Nhz}gWI
m6PH-c
.ZJe[vf,+
C9]${k/
%eP{/T
C]D.or
~oID4rz
7oj">gl
\$(2T$
D$<~EQ5
}-At[Y
0i]H"B/n-
0Q9"wC
3tsJ#FP#i
@idr=zi
dRZ}!r.
D$8>G.
L$0D:|$YfA
GetSystemDefaultLCID
M]>E;
*H')je/B
%jYP~Z
P2))iX
QG\;Op
Ot$(V!\$
.u"P%7
e,Ph[k
intAP@H
uhW+r.#|$
9--Nm
z>GpSo
FJ[5"=
%A)b?<x+
ZeSe>:}
05'tMb
t$<9l$
RM#%3'4
=z3&p3'
AtT9Zi
\/*gj1F&0
o'Q _ &
YKHQiL?
l$(s{%Sf
=N9}N0
k YuRO
uvNf&O
:Fv*wG;?
'/JA-O
=g@TOZlA
6Dirz"
#W?QU")6
X9?Lr9@
xsfQ)z
^v3RnqD
/scnt
srw!Cu
SHGetFolderPathW
TRPsNY
kubA4X|
][XZYf
E]k)uZ
x0c()9
$1wgu8
hY/ZX^X
s1rXC6
4"d23U
^56+n2A
[gSe0\
f=*h-w
2Vo*!4}Y
2v$\+_
NTrNQ-
D==j5R
?&cRuG
V`Wa8S`C
i;S`C
-Ld |E
qMpo D
L xn|'
WH%lgOR
I1#;NF
zLaJK
id?#$h
fFXU[q
"|J-0s
/oW3q!
5hmffo6
6@h ZqK
1!v<C)
J=%w@'x
6p5fWLhs
Du_P'J
T#]%TgD
y?%t(6
%>1;t7
DR-utUZ
S9:(TN
_:pwo=
0!x-A/)
,K~O)>+
}O'm=,
AP;!P3F;
IsProcessorFeaturePresent
*P$HWC
<2 }6@
>fUlNp
#O[X59
^kjqa8&
E`-WY
!W|Y{Y
^?\x)]X?
wv*; `
HO|!w2
/K{ag['[
^DTywm_
mv6cG}/;kz\\
{5 b1~
rj]QKE
2LkjE3
SMj:IE$
c3q3lRWN
QaD}>C`
=3YUex
NfS.~PSZ
W]I*A2
Dz>Ah,5
w_9`hy{
\$(3\$$
AZE3#mZ
3HI.cCe
iKh;:%u
DaZ@-h
Gl)>@;e<
OpenThread
CopyFileW
'F,B/6
'PQyUK)c6{
\.n5l)
q**FA-]
=Br{lK
aCf40J
jBwDZE
GF37wAD
G'x+@P
`!%jW]
"HpiQX
o gfc.
AW14$M3
T$("\$
]]2#Z*
S4+NZ
~?(eN8_
2WpXc^
eWugUP
R%[$UR
T$ +l$
E1,$fA
v1aD(w/
5^6<jn
\56`c,
+?S-rD
OPe)/(
zCv2;=
_*2#I&
CreateEventA
0D1$$fA
P7Q/L>-
xgca2
?xt5{
,_E5R3
nTBVY#c
MLw6Q_
D$(2vvF
nuTE#\
NhC[=-
InitializeCriticalSectionAndSpinCount
%cAxlc
8|p&`)
v84\mX>
?\=0[T
vP2zz9
@\e/wa
jgHiGqO
6ov!{"
d5XQ0r
KwXDba
rB8Mx@
q`M&0s
o "I1
wrsW@@
MOP&aLJ
?W<Z^9
%(V~9P
LoadLibraryA
!vMh\QA9
hnUeS>G
brVlWV
yZcOCl
q\`A?y
>(>:f=
s92F|+~
4M?4qWV
S3N~\|
+-U3f]
AW1,$A
C9Kd0Tu#vVod
F&);AQ
WG2fg@E
6+.(g"
j*:g;#
L/od|(
L$D)l$
mY%8Tf
X.C,Gx
Ub%+De
g]5G:R
$PpnY*
A`TP5V`
[y C,=
!\|v[u
D1,$fD
frk$)o
k*[Pr2K
r"`Ub@\G/
GsEzS4
RS>wj?
6{!'v
^A[A]A^L
|r`'^6
2YPMNR
zu3>4"
GfGyK~
LjDr`d
mzu(r+
IL n.+R
14$A_Hc
Cf=@#f
t*v CX*
B+/}[O
]HE@`
|T=EE=e
$BHiSq
QWJKEx6A
mf;agcF
sqEv"7w
<{flmr
`zr#1s
~3o*yD
k{cS[|
Z=hZ|`
,4JJPP
9bSH~1
5+P[pm
NB($&~
Q_+l:,
kC5IC^
o'U^hl
g!%S-_x
[&#Y(k
C0`AWD1
SR"Mf;
}1\:+b
Ax+g{)
WAIV?h
wdnw6$
AW1,$A_A
e[6`>[X
AwI0bm
l$5b\#B
Lm_qE
I8\6NO
wLh`GK
ad\u4p
GWTD2T$
"s/@jVpN
#c5G!:-
&#?>|^
Lqu2\tDv
ga)"_+
5*bQC3
Fuli}r
$at9"(
O~k\T:
,$_=3=
y#C%Z*
)-OJm=
gY"HFs[8HV
)qP:hE.
<YWA@1M
%W_h\s
Twij|d"
g%k%C
|QooW{O/
t/vL8<
<8iz(VtH
nN'B;)d
f5LXf3
qAW14$A
+(CjtI)
bZuXdU
=5sD(q
jgB!UW9f
`?Xqva
)P?vN0
EHeNI
,dQf{uPTh
g-a.>=
[#:CJQ
#$d-7fzZ
D}\yg7
rc(AWfE
wCE'Q6
Nr[9eW
e^[scAfe
ZA@z_^
NIJ>3h
i22S"!
No1tv(1
Bn2Dhd
iPT=1G
2;EE!D1D
1/y;:!
.Qu}X7[IF)
!=$J*!w
2!F!T
]8f*'1
G6+$IfE+
=t&L7?
ryAm88
_`S/X
"2hRs;
nZ0o^]G
u2mmE5
7=Q40J
D==j5R
z(GdF}
%)1d=f
D1$$A_f
Nf_FYR
]"y,8P
"vCr+W
Gv cq
\Ed.O
,,?]42
M;oc}<
,Ws-}^
pVgb!_
VS2afTE
R&.:UQ
k.:\2&
wvX[?%
5/g9g<
H:sI
Lj5-Rn
Q"yX3u4)+
br4[Gos
DB{9D J
~>8AWA
w"d*$w
@vAQ>
>S+jg~'
;S=,ij~
/f;ye2gH
&\&QS@=]
TT!u0n
x&;hT'
=yNixf
1,$A_A
npCC96
FreeEnvironmentStringsW
T$2H#T$PI
/BQ2hy
M<]iBn
mUn4k)
TlsFree
D14$A_Mc
f5LXf3
IsDebuggerPresent
BOC1J8
bp >].
RWXH:;b
=lEq3
aK~h|n?
.#;5K:
_JP0UfK
w[45y!
,%1a}v
C0`AWD1
N(A_Hc
!FZ5zGd
C520s2E
~X:1/Q
"Y.~sP
n1vC^6
uY+AE^\
X]o2hZ
J]PjxY
2_?m>J]
UkJh<[5
*_{ta@^
_u,>=_
1^|)\'
Qh$5Qgk
{q/}/mb
jLSJwW
pXSfcf
Q&-B\(
r|@gPkY
|N%@Gr
sZ}1}}T
y"s,>O
z)Hl`!
9R&qI=
_6(@dp
D1,$A_E
zCMH+J
G.EIw)2
qB\8AE+
=Jq~N$
C2@V7VngE`A
lNVo%O6
.K'%$D
%bh.kr
?'ei@FoO
EnumResourceLanguagesW
a~4V`ynkC
'X=@8d
O 8c<ICw
<i0{ICo
WyRhg~%
8BSX@A}
KH>6Qp
o"S3,v
M_wm|H
1,$A_A:
D1$$fE
u>Q:svZ
:.;ld4O
$x}7k/
z\9DV\w
T=72o_Jc
-1,$A_
D4f0h)dp:tr
K u;f4
Wi'y6/
.AWD14$A
~9]T;P
+3v997
#5Jct5
S 2=qc
,'bpJ!'
aTZF13
u_i/M)
iM^,G*
Im3)M
|.*/LRa
~%-+]WA(8#
.<r2@>
vcI;E3_
!4Re~m
LocalAlloc
:>"zLa
Eo$8F
3`6rSP
yUX:Nq=
jpjCZw
Gt.0wsY
AWD14$A_
,|RR/sS
vjw`v|
d 0s|@
ExitProcess
{a2(!{
F`w5Pb)
Fk)5D7'
#XNI{{
K`ysa*
gQ@Rso
6J6E)E
x Y"ph
XFqWta
-};[|t
z}>dJzI
V<*G)P
/ML^}I
[=a3v
5W p_3
AW1,$A
M#&5\P
=qoK)h
+qL8wKV
"Q/w%o
}"4SVY
YJSv?f
*]r&-q
).7&#?
5W p_f;
k:+/]F
5jLZ\f
#HXL""
[UnoN$Q
hT)=]P
L yF#&!
-}wu_-E
OMc(kv
k_cn=[
*xL.6`
YbMO(yb
y\6qX4
sr3;qn&h
*3z_>:
WO[w<]
1,$A_Hc
6@oUD&
U,CY2T
VTgyk7
I1S+h
RRX[QF
{cID@n
>2z8n&
@N+ND(
}NO^'NuMD
LocalAlloc
=[Bg+j
D;/4F6ot
v?D:RhM
`uB%X-
HeapAlloc
r,uYH_`m
9-LQ9
1,$A_Hc
X tiXx
-wortv
SetThreadAffinityMask
USER32.dll
~~5D/w
X{`Gh|
^3vQ!v
GIOGgc
Q6QaH4Y
w?@58Q
D1$$A_Mc
JYl75
VTAwu
e`vy1^
$,R]_b G
!(V))0
]%z!`w
spE'gW
VsIw(!
%oxb]f
eAfY%\
AW1,$fA
uD14$I
T$4!L$
t$$AQA
,@cUs|
\ q(I@4
`%orhC
8=OF?!p
Y/+&d%
]Lvf5!nI
@5Jct53
by(j-|0
,e}8g~`
cK;hCNB
-lOV>&aG2
@.G9p)0
/Sv,($
}CO8,J
!B[wpK
vB^HFE)
Lcl$ AU
!:Al.6AT
Wb&>&2
[PH+>!
@ea~@k
KERNEL32.dll
elG6Uk0
9Bah.
*'"*u8Uk
cW(@9>K
aNBS)L
aNVO/L
OVUZ48
_c`C^~
SetUnhandledExceptionFilter
z$EEJ#2
IH{ N?
LH\4|O+
^ZJ&n]=
[^i2\)
c7B'2>
?6Vhn?
h6SWX1$
v5LzRy
GAWfD3
v'e2P>
4lHe`a!
U[Fj=3=
@*d2"HiW
xAo: %
1SXxh:A
RSQQh)a9
6LcQ(_
)}+`9~
wos82}Tj
I#D93"
2fjEP~6
`%{'wP
EnumResourceTypesA
!N;iqr
Ue;-QX
a@?aQ{
YI!bb_
D1$$fA
v|ynJD
7VR)T$
hBkRaU
GetFileType
R."7EH
%xraVq
WdT=U+
cU40D]T
.e2rK|2
zTpud^
n,!KxQ
<%gm|T
r<fo#5
T93ld>D
8'#8?P
y=wI:
r^i|"p
6|{0yA?\
KN=h;ol
\}tlCr
1,$A_Hc
g+jcVD
oXMvZ%,
sJw4t=
Xr^8hu)
Htivn`
AeBI{Gd
Q+]H*
XS';r-
SystemTimeToFileTime
}:X2wy
D446&p
u9p;[,"6
5J,xnf
vV+;*w
crL#_~
CH69cs
HeapSize
@,qsVY
i&DTlI
hnTwJI
lJ"N|=
[G#fw<V
`jp+\[
q&Kp:+
?5[^)
&5.os2kF
k|:a76
K[3&L,
JJO|zM8
+&S2z/
w'G}&.
0aNXah
gaKgWf<
=-x6x45
?rQxs5-
~oZ+=2
N2@me**
~~AQf;
2Uz/*Z
[I?B}D
Kc8vlb
eD~, j0
(1!NV66,F2
mx[dGF
AAWNFV
Ia\H?X
wI;u/5{U!3
D14$A_
xAT?V-
&r]nDp
YKp&A#
LlM^ wV*
C@\6sy
6g4^B/^
E87?a
)VHgEC
$,1WJw
stXenA
4#EBf;
t69?
Bm&" o
AWD1,$A
,>i'f;
Y)CDm,B
'AC}w
D")]|d
saET.;=
>5#[fc
@'0LhJ
~v#siw
J'UsxWPE
*_/N2m
~I"bXp
b^M-#C{
{{/nK|X
D!|u^mx
w~xHb
7_UG#da
z9*sS(
y^7,.p6
> 0 p,W1
aX_"Kp
Yg)FKfY-SZ8
5I`kU]
`s#FO;
"vj0Mvi
6<qrpy6
!n}7L+:
'P@{Kw%A
=O%^y'Z
`kp;<f
F8(92A
O05V7k,/
AW1,$f
0RJOv<e*
+pScDqA
0}0/S9l#;
Z[4LVL
h}2+T$$
QYGTa^0
l4OU==
g5^%W2)
BSD14$I
j?R=Z8%
\SKLlT<
HWf=-US
GetACP
"ICA}y
yD';h[8=S
$MNG2j<
3;Ep&b
SetStdHandle
<Ux^lu
A[A]Lc
(14DR%a,
3LVW`Z
KAW14$A
oVYF]eV
dQ9Js|g
>hw(aS
twWz}7
J"j>uC
3M/$;*
i]#Ff+
:[UekR
fZA*7S
6]d71*
[7I+k0>
m[PZ]\'
f3\$$f
Z`Xj8g
U68=`2^Sqz
Z_2d=L
nPE+;M
oB3o~h?*~x
Z;o;H{!=q>
CF\^"0F
S[TCSj
D {=!&|
as[m-ar
Q1'{/%Cl
QSV^EoE\
vD14$A_Mc
neukiW
1}J,nz
`u+_>
8*kK,2
^;TT-GJ
"v1\B%
@5W p_
+P;lum9
r%GtXW
X7b[\fT
;r@GN;
GetOEMCP
["ZTLXZ
vj2tf/
}?6gj%1
P>P0)[
SJnc-|
v!_KEg
)E|)Pl
z_K4Ez6
/N1YCQ
xE|w-C
'7"q#}
#E`'=
SZ>25:D
;vHax+om
!o\z2H.
`nOK9Ea
7#U28)
oa6yjg
-/[oX5
WTlrQ2G6_z
TerminateProcess
E0y$"
liqd%
7#TlO:
ntp|;1
cX]}rJ
rk,/h2
99MW4mb
'{+%]r^
=K\L*=
cEAWfD
C=j+aZ
d]z[i4
yz7FNzu
D:|$ZL
emg+="
6Pg@Wf
h~Cf<h
CreateProcessW
sGNY~,m
e)uL;t
,A~$Wo
^tNt\W
Hd3iMg
T{D*h!
f?[2?N
!h)u-6Y
OTY@@!5
8"!dr^g
Fx#Y8nx
JXnxaWA
7(%`$A
lstrlenA
[Du|\E
b"?J<M4
GetModuleFileNameW
!|)d^61,
If^69|
_jVyb]:p
T?ZSGx?
FES8c]N
CJ6^<^G9
Y1D"(Z
&R]Qgj
;<7OOR
Z>f!l$
]*hp3]
6+;fo{
M.yM<g
LoadResource
:CG'iU
Ck@3dI%
f1\$@f
l$82tf
\$$f+T$@f;\$B
\$8!\$$
6!j&Au?
A0A5r;
a2w]e;
,@+d*pRg
`<$ Lp
2qN|oS%
eTx!H{
D3azh,V
eY3I:S
\P.Y./
\<EkgDu
~|y~D]
Ui>}3P
#/bQ,r
dR>3`WCHy
@?Ie-5
/h@Ol?p
-MpC$,
@O'/HL
$DXVy
&N ZU$
n[/(l!
!L&a@u
9Gc3a'
kyB*r~
]/Et`w
W!R>92[*
NO-K+U
$i&nO"=1
C#!;
PH&.okb
GIIGU#9z
g:K(6!
;PyL{`
4{B2b@!
EGdAso
+dRf q#
Zjm_cy
MlF]6}O
&~j#0}G
)g_nc
g{O<}v
itMAUc
dD#YMs
wT?e'
+ .Qs*
42i~#$
tu/$"^C
^80UDT
dh#gbo
=)6ZDv8
9(Pvy{
L-vUDN
Aq@T{"
pgRtjH
PeEnUAy*K
S"eWE3
`az_6t
6zs&x*
,86cmd
i!rQW`x
Prh))[
6Wj,!3
dYhNuq<_
MGF@vV
.-IQh'=
\\x+*H'J
u,i'x(C
fok!Ms
mUBXAb
47tIS<W
+3VfAfNG
8(a ;p
"1Gq!
5#*^,'
]3w>?v
NVu I
EDf^KO
l:8=5g
^d0NEDRb
,FFY=E0
bFFg_M
Z[B1`?
b_\QDRu
^E{[7R~
sUtfsu/
[CFP?M
0JM>|{
=b`T%!
Z)IXBp
^2Gwp'
"f<zl!E
HX"(;F
N]Q{<'W,
g-?$[Lx
8i01]a
RH*Q7G3
6 co%
+rRguBi*
(@)M%*
-@^0z=
ZMG/X|
s+yw>*
0e=0nQ
`83%{$
@H=su1
T#.<PZW
X|Gp.q
?=1>Qb
G)/GgM
zN\U&\
>\7`)C
Anp36
<Xwc<F^=g
iiIRT#G
Nj*#>3
UVJ<~;
7Dr~6a
y\AA:e
5A ,sl
8`hF&o
.+arG6U
3RSOTr
[?) H4
k)FiU0
PJE/M%
@{pNOD0
1g\Psu
\1aWD
do5jOV9
MeF3>s
D`$@-@
Y?(S@l
<E"2*3
8rf?U1H
.LUnnV
5\Epz=
/*@gM?
L.MCAy
dI->31
VHbAK9
QKzc\[
2FZ105y
'i@8[Oej
G'v/.
q]u\Q"
' e{+#
awJ8'j
QyP0XCb
qK/NY4
.VYTZtoK
#*hM4Z
1Dj)Z,%
E[G89$
hQC-#Av
jRi{.f
\Q@Om(
&8%a?qq
Cg.]ZuF
]e_Fy-
FW.jo2
R}9WM)?
38L_Km
Iu}v{Y/
]nDZL c
tKi<qy
4;{bRGj7
d."W,z
-XYUO#
M].p(:
B]Ru!yy[cw&
MwsVh~
Y4gcYy\
Tp9eV~}\
FLfX&B
ZfTRd]
jpzFIx[
wgK[K.
uoQ>1,P
2D]}}dB
SXb~|j]
)M(nz5
[7s`7{Z
=X9^j[aQo
!_IR+;
k^vo f
XICMu9[
464H0h
!^`DNeW
5NjCW]
ie@^Rva
#3PX%c
w0ai8>
'n@"'Y9
joedKZ
77@JJi
'a+vyX
DsoC~U
t0P~bn
8lK`Kj
o7;boh
h t%7V
%?wSD/
kFdA3*8
eJ}T47
i@<B5O)
:_i~v:
58q3(/K
T|0y{v~`a
QHO,8-
z\E{^a
=p653Nc-"(J
IuPz-Dn
_E0W!E
M,9QFu
NG`U`l
GEB.V9
1rL5jF
$yH0R_
h]Bm{<
J?z-!1
(uP>^
;:p9TH
Z`Rl<6QL
r-2ElW
4.4;~ro
"}nW Y
I$,Lao
Entn$7U
& -/j
\(Xq(i
^hUbk7MU3
tE8;,3
93d1m:
<i9~eT
VM\.T<=(
+6[$+.&
fu<smxZ
RRlDX$5y*?
n*EXPD
]gV)$1tIe
`)47}nZ
\UiHko
hHEJQK\^
gQlELk
j'F;f/
bChKOH
a(NKLm
^<v7Wd
!G$NYP
^.1O-
CS{3&6
E&hDCn
t2uX!@bP
<t_OU*
9}\Bv$=
&E@?[
=m?eT^
$s1VroirJ
Xc"YI5k{
sTT Ab
*p)>$T!
q5}t|o
ldo>zG
$^tEU]
<sr0ur
q.>"oj
~_K|WE1
54-^J
IX;;$4
uPw{?~
{OA6y%W
,][W:,U
u%L3nD
ep+!MW
?j8H8}$9
|UvZ@T
ny9ea,
R!:!({.
)&9JkK
2`(2@C
D9N=~I
F$71S5d
lMGc~i
ky.Wi)
|]ZE=P
l;sUSAx
g$2f^=!
\)[\FlW
5/f?Op
c{*k!H
.r3l,(
>D@}d$
?qxgo3
!ud5 ~
e7a{>V
!O;4R"7P
$}2"h&2
6""aYR
{"svBS
%,>nio
5:45m}
kRkfei
s;"Shn
N!SswU
Ws2u|A
:]:0.o7
#w@W3!
`@lvu*
E35QC
R5(TUB
DRA~|{s
;NLu9/V8
f^5sg,G
>=9&!)
iynxDH
5_('x;o
\d|q;}
#ztpVq
f6*pj,
9afRlf;'CF
_kw7]F
H/9")W
h;3LTF
Y|-M>M
7TRkW
$Fuqaq
^] K:f
6?HM`)
-C*>$Z
u2a$_TYM
VCt#[c
L6/7i
`LPno@z\
Eh[2/]f_
c=\0PH1
dDg)7%
'~)9{J
6lzA =9
un95N8
)ikGKg
FC"|Es
+l##QD
?PMx=N
@wX/nx
3)I~FQ
%EgZ|h
6=gD@>
:F{j{{
4.nU<Mh
*p4J|4,
#XOA6z
uh3vkLB
rnZ55:r
k&Z6bl
^OcfKW
~;h!my
URbvsJ
FuF74$
JAQofr
I<O+@Zul
R^f{a?
9N14qN
B}`Y?O<%,\
n~f^\b
0@`D<S
oax,)n@
34Wfmx
V=IOA1
Yy'n1e9
\|+UKD
T:;/WUN
T~ZP{TN
j?;CBm
#o2fy+
GoB($v
DP)zRm
FMBr~8L
uL7|E7
O5g+f!
b[zG&T
y`u,Z(
q$RBipN
a_e9||
(:&Scg
V9!9cd
zWwPn&
4+tV$X
b"7IHW
:F,sXw
gv+5y'S
.&ez>m
l3?z3>
`y|l0%
W~*.[;
gB)CH
Ebt}6Z
fpOcu$$
fh'"\e
5k*HsLq7
u}'z %
cLV|vc
KwrNQu+x
*JNFA,
h"tLj
9k"&vF
4x^(41
:=:}-dEz
@E2med
=yZf.A
".#`=m<&k
)*)XUA4
{V']Hw
V$hM{%el
"|TihH/
Tg_d^W\-
jPMX<a
W])2|B
mFv^)czf
2{@ ?rd
#^b.Lim,t_8V
NW6~K
{vP"SD\
q8BZp5
r<+63
4aFS^w
#@1U^d
$P268q
pMI0dj
m!#JX1k
0Cm%9L
&q\Cd>
5}y{BtQ
@\7Ra<
a n^wU
B)0Jmd
ay&Ps1
y#dpi#g
k=FJmv
AT5F9c
nG]Pf]
d@zWF~
/n${?P
4vSD8!
>.G>F&
Xi=NV{
+|X~{f99
"gv"cud7
@n&~),
7TR^7b
^C>2?#M
Z6`;8v
`8ZZv^
2)F@7?
S^nqt*
DwZ2f1
OCVFp5=c
m-'ked9
MYffxA&
mvzGa$
9>D)~E
`M<a8d8
Fd`gTg
5hb=N_6
v'>?;L
5h}QE
h5E,yg
Bmthos
X+H)SW\l
\NUo>32
1D26Q"
H_k ;V
}E&"}|
%FsaIt
zpZWq$
_ieLDz7
HP0@n$w
#sSmJx
a=Bs4p
8~5bl9
)v`$7?
r)Kd*{-
K^!<rl
Je51TI
zF|LSv<
o3kq@ga
}7<`,u
Antivirus Signature
Bkav W32.AIDetectNet.01
Lionic Trojan.Win32.Generic.4!c
tehtris Generic.Malware
MicroWorld-eScan Gen:Variant.Lazy.268605
ClamAV Clean
FireEye Generic.mg.b5a83bb2dd5b3521
CAT-QuickHeal Clean
McAfee Artemis!B5A83BB2DD5B
Malwarebytes Trojan.MalPack
VIPRE Gen:Variant.Lazy.268605
Sangfor Trojan.Win32.Save.a
K7AntiVirus Trojan ( 005974d31 )
BitDefender Gen:Variant.Lazy.268605
K7GW Trojan ( 005974d31 )
CrowdStrike win/malicious_confidence_100% (W)
Baidu Clean
VirIT Clean
Cyren W32/S-ad060208!Eldorado
Symantec ML.Attribute.HighConfidence
Elastic malicious (high confidence)
ESET-NOD32 a variant of Win32/Kryptik.HRTC
APEX Malicious
Paloalto generic.ml
Cynet Malicious (score: 100)
Kaspersky Trojan.Win32.Tasker.azbs
Alibaba Trojan:Win32/Tasker.7e5dc4f0
NANO-Antivirus Clean
ViRobot Clean
Rising Trojan.Kryptik!8.8 (TFE:5:o8wrBs1QCtE)
Emsisoft Gen:Variant.Lazy.268605 (B)
F-Secure Clean
DrWeb Clean
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition BehavesLike.Win32.SFXMplug.vc
Trapmine malicious.high.ml.score
CMC Clean
Sophos Generic ML PUA (PUA)
Ikarus Clean
GData Gen:Variant.Lazy.268605
Jiangmin Clean
Webroot W32.Malware.Gen
Avira HEUR/AGEN.1253290
MAX malware (ai score=86)
Antiy-AVL Trojan/Win32.Kryptik
Gridinsoft Trojan.Heur!.02290021
Xcitium Clean
Arcabit Trojan.Lazy.D4193D
SUPERAntiSpyware Clean
ZoneAlarm Clean
Microsoft Trojan:Win32/Tiggre!rfn
Google Detected
AhnLab-V3 Trojan/Win.ClipBanker.R528972
Acronis Clean
ALYac Gen:Variant.Lazy.268605
TACHYON Clean
VBA32 BScope.TrojanPSW.Coins
Cylance Clean
Panda Trj/Genetic.gen
Zoner Clean
TrendMicro-HouseCall TROJ_GEN.R002H0CCF23
Tencent Win32.Trojan.Tasker.Gplw
Yandex Clean
SentinelOne Static AI - Malicious PE
MaxSecure Clean
Fortinet W32/Kryptik.FXIU!tr
BitDefenderTheta Gen:NN.ZexaF.36344.@F0@aGZAMlii
AVG Win32:Evo-gen [Trj]
Avast Win32:Evo-gen [Trj]
No IRMA results available.