Static | ZeroBOX

PE Compile Time

2023-03-13 02:52:46

PE Imphash

8aa23bea230ae1c890d1bde72074903b

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x000295c8 0x00000000 0.0
.rdata 0x0002b000 0x0000ebd6 0x00000000 0.0
.data 0x0003a000 0x00001f34 0x00001200 3.33806206023
.+S6 0x0003c000 0x003f52ce 0x00000000 0.0
.a7p 0x00432000 0x000004f4 0x00000600 3.99869835663
.)>s 0x00433000 0x00704de0 0x00704e00 7.97480012144
.reloc 0x00b38000 0x000006b4 0x00000800 4.15427912249
.rsrc 0x00b39000 0x000410c9 0x00041200 7.93696519626

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x00b52d84 0x00026dd4 LANG_NEUTRAL SUBLANG_NEUTRAL PNG image data, 512 x 512, 8-bit/color RGBA, non-interlaced
RT_ICON 0x00b52d84 0x00026dd4 LANG_NEUTRAL SUBLANG_NEUTRAL PNG image data, 512 x 512, 8-bit/color RGBA, non-interlaced
RT_ICON 0x00b52d84 0x00026dd4 LANG_NEUTRAL SUBLANG_NEUTRAL PNG image data, 512 x 512, 8-bit/color RGBA, non-interlaced
RT_ICON 0x00b52d84 0x00026dd4 LANG_NEUTRAL SUBLANG_NEUTRAL PNG image data, 512 x 512, 8-bit/color RGBA, non-interlaced
RT_ICON 0x00b52d84 0x00026dd4 LANG_NEUTRAL SUBLANG_NEUTRAL PNG image data, 512 x 512, 8-bit/color RGBA, non-interlaced
RT_ICON 0x00b52d84 0x00026dd4 LANG_NEUTRAL SUBLANG_NEUTRAL PNG image data, 512 x 512, 8-bit/color RGBA, non-interlaced
RT_ICON 0x00b52d84 0x00026dd4 LANG_NEUTRAL SUBLANG_NEUTRAL PNG image data, 512 x 512, 8-bit/color RGBA, non-interlaced
RT_ICON 0x00b52d84 0x00026dd4 LANG_NEUTRAL SUBLANG_NEUTRAL PNG image data, 512 x 512, 8-bit/color RGBA, non-interlaced
RT_ICON 0x00b52d84 0x00026dd4 LANG_NEUTRAL SUBLANG_NEUTRAL PNG image data, 512 x 512, 8-bit/color RGBA, non-interlaced
RT_GROUP_ICON 0x00b79b58 0x00000084 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_VERSION 0x00b79bdc 0x00000370 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_MANIFEST 0x00b79f4c 0x0000017d LANG_ENGLISH SUBLANG_ENGLISH_US XML 1.0 document text

Imports

Library KERNEL32.dll:
0x832000 CloseHandle
0x832004 GetProcAddress
0x832008 GetModuleFileNameA
0x83200c IsDebuggerPresent
0x832010 GetComputerNameA
0x832014 Sleep
0x832018 CreateDirectoryA
0x83201c WriteConsoleW
0x832020 HeapSize
0x832024 CreateFileW
0x832028 GetProcessHeap
0x83202c SetStdHandle
0x832038 GlobalUnlock
0x83203c GlobalLock
0x832040 GlobalFree
0x832044 GetModuleHandleW
0x832048 GlobalAlloc
0x832050 GetOEMCP
0x832054 GetACP
0x832058 IsValidCodePage
0x83205c FindNextFileW
0x832060 FindFirstFileExW
0x832064 FindClose
0x832068 MultiByteToWideChar
0x83206c WideCharToMultiByte
0x832070 LCMapStringEx
0x832084 EncodePointer
0x832088 DecodePointer
0x83208c CompareStringEx
0x832090 GetCPInfo
0x832094 GetStringTypeW
0x8320a0 GetCurrentProcessId
0x8320a4 GetCurrentThreadId
0x8320ac InitializeSListHead
0x8320b8 GetStartupInfoW
0x8320bc GetCurrentProcess
0x8320c0 TerminateProcess
0x8320c4 RtlUnwind
0x8320c8 RaiseException
0x8320cc GetLastError
0x8320d0 SetLastError
0x8320d8 TlsAlloc
0x8320dc TlsGetValue
0x8320e0 TlsSetValue
0x8320e4 TlsFree
0x8320e8 FreeLibrary
0x8320ec LoadLibraryExW
0x8320f0 GetStdHandle
0x8320f4 WriteFile
0x8320f8 GetModuleFileNameW
0x8320fc ExitProcess
0x832100 GetModuleHandleExW
0x832104 GetCommandLineA
0x832108 GetCommandLineW
0x83210c HeapReAlloc
0x832110 CompareStringW
0x832114 LCMapStringW
0x832118 GetLocaleInfoW
0x83211c IsValidLocale
0x832120 GetUserDefaultLCID
0x832124 EnumSystemLocalesW
0x832128 HeapFree
0x83212c GetFileSizeEx
0x832130 SetFilePointerEx
0x832134 GetFileType
0x832138 FlushFileBuffers
0x83213c GetConsoleOutputCP
0x832140 GetConsoleMode
0x832144 HeapAlloc
0x832148 ReadFile
0x83214c ReadConsoleW
0x832150 SetEndOfFile
Library USER32.dll:
0x832158 EmptyClipboard
0x83215c GetClipboardData
0x832160 OpenClipboard
0x832164 CloseClipboard
0x832168 SetClipboardData
Library ADVAPI32.dll:
0x832170 RegSetValueExA
0x832174 RegOpenKeyExW
0x832178 GetUserNameA
0x83217c RegCloseKey
Library SHELL32.dll:
0x832184 ShellExecuteA
0x832188 SHGetFolderPathA
Library WININET.dll:
0x832190 InternetCloseHandle
0x832194 HttpOpenRequestA
0x832198 InternetOpenA
0x83219c HttpSendRequestW
0x8321a0 InternetConnectA
0x8321a4 InternetReadFile
Library KERNEL32.dll:
0x8321b0 GetModuleHandleA
0x8321b4 CreateEventA
0x8321b8 GetModuleFileNameW
0x8321bc TerminateProcess
0x8321c0 GetCurrentProcess
0x8321c8 Thread32First
0x8321cc GetCurrentProcessId
0x8321d0 GetCurrentThreadId
0x8321d4 OpenThread
0x8321d8 Thread32Next
0x8321dc CloseHandle
0x8321e0 SuspendThread
0x8321e4 ResumeThread
0x8321e8 WriteProcessMemory
0x8321ec GetSystemInfo
0x8321f0 VirtualAlloc
0x8321f4 VirtualProtect
0x8321f8 VirtualFree
0x832204 GetCurrentThread
0x83220c Sleep
0x832210 LoadLibraryA
0x832214 FreeLibrary
0x832218 GetTickCount
0x832224 GlobalFree
0x832228 LocalAlloc
0x83222c LocalFree
0x832230 GetProcAddress
0x832234 ExitProcess
0x832248 GetModuleHandleW
0x83224c LoadResource
0x832250 MultiByteToWideChar
0x832254 FindResourceExW
0x832258 FindResourceExA
0x83225c WideCharToMultiByte
0x832260 GetThreadLocale
0x832264 GetUserDefaultLCID
0x83226c EnumResourceNamesA
0x832270 EnumResourceNamesW
0x83227c EnumResourceTypesA
0x832280 EnumResourceTypesW
0x832284 CreateFileW
0x832288 LoadLibraryW
0x83228c GetLastError
0x832290 FlushFileBuffers
0x832294 WriteConsoleW
0x832298 SetStdHandle
0x8322a0 DecodePointer
0x8322a4 GetCommandLineA
0x8322a8 RaiseException
0x8322ac HeapFree
0x8322b0 GetCPInfo
0x8322bc GetACP
0x8322c0 GetOEMCP
0x8322c4 IsValidCodePage
0x8322c8 EncodePointer
0x8322cc TlsAlloc
0x8322d0 TlsGetValue
0x8322d4 TlsSetValue
0x8322d8 TlsFree
0x8322dc SetLastError
0x8322e8 IsDebuggerPresent
0x8322ec HeapAlloc
0x8322f0 LCMapStringW
0x8322f4 GetStringTypeW
0x8322f8 SetHandleCount
0x8322fc GetStdHandle
0x832304 GetFileType
0x832308 GetStartupInfoW
0x83230c GetModuleFileNameA
0x832318 HeapCreate
0x83231c HeapDestroy
0x832324 HeapSize
0x832328 WriteFile
0x83232c RtlUnwind
0x832330 SetFilePointer
0x832334 GetConsoleCP
0x832338 GetConsoleMode
0x83233c HeapReAlloc
0x832340 VirtualQuery
Library USER32.dll:
0x832348 CharUpperBuffW
Library KERNEL32.dll:
0x832350 LocalAlloc
0x832354 LocalFree
0x832358 GetModuleFileNameW
0x83235c ExitProcess
0x832360 LoadLibraryA
0x832364 GetModuleHandleA
0x832368 GetProcAddress

!This program cannot be run in DOS mode.
`.rdata
@.data
`.reloc
@.rsrc
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
.?AVlogic_error@std@@
.?AVlength_error@std@@
.?AVregex_error@std@@
.?AVbad_exception@std@@
.?AVbad_alloc@std@@
.?AVexception@std@@
.?AVbad_array_new_length@std@@
.?AVbad_cast@std@@
.?AV_System_error@std@@
.?AVfailure@ios_base@std@@
.?AVruntime_error@std@@
.?AVsystem_error@std@@
.?AV_Locimp@locale@std@@
.?AVtype_info@@
.?AV_Node_if@std@@
.?AV?$collate@D@std@@
.?AV?$_Node_str@D@std@@
.?AV?$ctype@D@std@@
.?AV_Node_end_rep@std@@
.?AV_Node_end_group@std@@
.?AV_Node_back@std@@
.?AV_Facet_base@std@@
.?AU_Crt_new_delete@std@@
.?AV_Node_base@std@@
.?AUctype_base@std@@
.?AV_Root_node@std@@
.?AVfacet@locale@std@@
.?AV_Node_assert@std@@
.?AV_Node_rep@std@@
.?AV?$_Node_class@DV?$regex_traits@D@std@@@std@@
.?AV_Node_capture@std@@
.?AV_Node_endif@std@@
.?AV?$basic_istream@DU?$char_traits@D@std@@@std@@
.?AV?$basic_ios@DU?$char_traits@D@std@@@std@@
.?AV?$basic_ostream@DU?$char_traits@D@std@@@std@@
.?AV?$basic_filebuf@DU?$char_traits@D@std@@@std@@
.?AV?$codecvt@DDU_Mbstatet@@@std@@
.?AV?$basic_ifstream@DU?$char_traits@D@std@@@std@@
.?AVios_base@std@@
.?AVerror_category@std@@
.?AVcodecvt_base@std@@
.?AV?$_Iosb@H@std@@
.?AV_Iostream_error_category2@std@@
.?AV?$basic_ofstream@DU?$char_traits@D@std@@@std@@
.?AV?$basic_streambuf@DU?$char_traits@D@std@@@std@@
!c6}RJ,m
NbH;Ve
!/o:]H
{$n&|(
lMFgkFl
u^S{ga
8NiZ)x
rmTz+Q}x
|qn;eF
<o}4<1
51>.u1+
7Z1+8nY
2Ni_+N
uf41rk{tM
G0Kry%
/1n>~H
XIeqhN
9%y?h,
e$mp4-
C!8ss&O
 ,</'[
/gu6,(
RVl]qv
!^> ?v5
dzN8<"
#+f_S:
o!V2WC2l
]z7,|SW
SD14$Hc
dYx9c.
UeM7eb:
q+v\|<
pZY"\KzWG\
M>B"%{
%5li%L
pe?@2
nj\!>z
vn?(g<
Y%e&8H>
tU?qXw
2Nqjzr
F)kYY@
:!)`U9
=NT"I H
`GQpS;
"0{97pIW
2m~\8N
2hWw3N
AXAZ_f
526/mN2E
0$NbBsN
(NC Ph
mVcdZQ
[/0/3
f1PO;>.
J<G6!9
^!y52?"
Kab~Cl
GetCurrentThread
dcQe.u
W?$kSD1
^D1<$I
D\I$9
0^[}7&L
S~Wf&52%
1,$[Hc
q"D%o2
InternetOpenA
~cYfcP+?^
Kc0<=.
DD Qe4
S=R9m&\P
obCPk
GlobalFree
toj3pK
r{hhMo
?1|wbN
i?(QibC
Z51&s7-
!1h)p8
}0|f,9
@]tgpZ
[5)ek2^
4=*73J
;(@_RJr
@N#$G9
HAZlxF-
)-F"x$
u,Rm$%
ibk"TN
KI+Z3W=
m+?v c
85"Iqa6H
ZW2N07
4F9?LDn
Z%t[3)
x.e3OX
hL|Vdu
j,YuZ+.
ATK0F#
DjdUd`
Xn[]qA
Yu0YHR
Ti9y".
9im@rK@#yC
S.$kRP
W?$kSD1
oh##R5
ozk]aE
s8Bh*
;|u*+m|
,A}8XS
ghk/w~y
2rI^,N$
_5$wr]
;KYs,bH
S&@!o
9&yO{/
Rf,7SL
{~K4[P
Kscco
2b!j,N`_
2/<65N
2u&c7NoH
M}meq<
;dKSN}vf=H
GetModuleHandleA
GetModuleHandleW
TfRnda%
gF!8`1
&cw)wj
zbcf+k
\g6el`A
f"*0aU
1(jIaw
qNPI?M
N=0mr:
vpK~>k
j=fzaonp
xt#&48 =6YY|
2MVy'N
2NIp?N
G\bfF/&NW
SD14$f
2c@u'N
v4uXXzw
$J+QhrE'
,ND;-l
#wUAPH
]y*zFD4%3S
KbR\>X.a2
|7*0yx
<J#dhVIG
N=ZJt6=Z
F?PGN@
h_J}Y-
HbL,).f|>
'yu;5[}
L#KM^U
&<$!B#K/
h-Bmre_
GY{+?J(
b/+(oG
=x-R$h
#&WOw9&
v/w0m*S
8 `r\_
H=NW=m
/YzP|,1
Qv*u|j
9 e2`^
j*nKGZ
w\DB1m
MsBJ=3;%L
]qbqb;&1r
Bm@sgb
Nib6G8
x|wtW
#W]Qm}.
keO.!!
DaY?LH
xPG!Xd
YmF,0sD.2
y5AO}7x
S3\9<5
D$oLS}\
lp.^"f
&4Wk2C4
#abzK`
SD1<$H
H:LNiC
Z/HB=(0
&0%6H2
)D2F96e`YK
`S)gnL
g1%LQ{M:L
&N{Pff
VWmvYU
09W0DEXU<9
m'$TDE
Al-*9z
qqu$>`
2doU4NNQ
Ax}9x4
CloseClipboard
Z(%i97
S_*23q
Vs2eN-3H
8,#=dR
iEm!nL
Q-w'*J
aU~-*%
_&!-RzJ
5N}Nou
2>)4-N
2vIl4N<
3 BhU/~
7VI3[R4F
g<lx>Z!
L"\=e'
2W`F-N
SR(IxP
KJnOxJG*
.@a1Pm(
TlsSetValue
43lO+]
o#uBl4
q'Tbfh{
,i(\]eg
z^M@>0
bOIs"&+
2ZU>4N
8Eg9\ZO*,.
MQ2rS*
05-f4L,
c~AzSy6
oA-NJc4
;"-f;o;
RQ@?2*
0{A&ar
lzUi=s
lsa:}J
=NA:7}
oAWf3
y*:;3C
$|M_k/
dDe8>:VaH
6?C)xC=
[dC.6wqmT0
h/Lie]
/-fHl6
V~[2F"
')j80p
eZ rmo7
z("r.s(
-q8E`rnh7+
_1]uf;
D1<$[I
zzaxJ}
1E<(:e
LoadLibraryW
IsProcessorFeaturePresent
IsValidCodePage
EyLVq>
NT#EE#
FRFxA:[)
:c%f&o
W3l|8>
<Ea<_F
{@g{T|
W\u,AY(|l
GetProcessAffinityMask
eBV{4K
9CB4hJ
X/^zh()
.J54)=
,X{"Mc
InitializeSListHead
k8s3Gc
2LW>5N
$"*Q!k$
bk@ZOY
Tj<!x]
p5t-0{
\\GClL+
ic2Qe{I
rZ\zm`<
a4yMh
6:Wm>ci
>VDyq$
d{\f\
z&1o69
CyBILV
]3h}#^
r^&fF.G
;ZC8.bY
Vipnv2(t&
#?J<mg
$I`l::1
T#zX]a
VuFD55)
s3rWt2
IH}S2H
v.pCi,
zA[#p!
]e6^9J
O7K:"+
2*uu7NPC
4*u5<I
FileTimeToSystemTime
[KOFJ{
c`A/X\
1ncpp.irlu
$Ny.y7
O"AjrH
c-eA8m
5HD6c[
\nO/\a}F
J.^z?GH
q;?6f;
hnpTmA
WININET.dll
[P_k n
F_U[`n
ZEV0oN
YY`?OD
" ?9m]T
,qdoW,E0B
2{`;7Nmf
D14$[Mc
+yIW!xu
MultiByteToWideChar
`58#$#
?Jb'`Q
+y,1e*
>/>`jG*
2[2U7Fn
LtNa{-
7pXP#h
s{q?`\
X?F*S?I
2fAa%N
=@OCv[
b?.Q"w
*9:"6_r
kG27{|
^A][Lc
AYA[fA
R;)B%1U
eCz6/B&
anQRT,
-N+4=m
>uz?yBB
t4~5>Xn-
88lZ*Q
20lw+[
HrDz*M
3zamgt
)w8cPV
5*a/tG.
)-4Y]3
+$W9KD
YF0\V!
q/79=0`
!ph/?i-fT
4F`]yZ
*M3GYa
Y'<XH_
r0}1F
"J(M)\
IsValidCodePage
2po=%NJY
WriteFile
md0lYq
)jQ:4;Q
=lQOP]
>NrMV~
2$o'6N
>NZ!X~
&H1a{@
t@k:r+y
J1?rE3P
.Ngdrn
<eggUD
u,&N\=S
S+K_|aS
DQsX~?j
<ec)26
,9f!}*
Hs$BY/N
tP}etL
49eU|F
[)Agjp
JX9l~V1
8P7Wr.RC
~qP)J?.:
Ni/Q&l
jsKIX.k
bR6dy(
Zc< 6z
2J}c6N
W~0qTF
} RgTT
2[8E/N
ElwvC
Yh^7D2
VHP],*
TlsFree
WriteConsoleW
WdB4;{
W?$kSf
[RP2}S
Y*q%;T
o{=`?){;
AQ7;N_
hKQIE
#<1Jyy
N+RmICO
]|yvG
wIYR? ,H
7N?4)w
|T<B$N(
BopbSJ
WyU2\N
H+=*Cj
wMfcXl
|nH:@+
7=U"7D
HE^]RK
3`I9pd
WV>B:>ma
2BYe7N
8(8zNU
&{'FVj
8162;W
47Z|tt
k/No:&
7.Z f'
VBFnfE1
CR!:D%
`._P)(
L~Yo|y.
Fc|S$
O#c?gM
A8"1\Q
6X`?e&@
M([pPLeX
3l(a0{R
OenGyPe
L;^da.E
f_Wp|e#'
eELw{(
)A/Gk3]
z(JOnYP>/
fzY!je#
Cep|=]
$k75N\
"Q)+Hb
qO>$8O}I
X:<nC%
odBE&F
LwG$)6
&Dm6cTo
P|("y=
w$q'vf
ea= z!P;s
XA_ZA\
V^PAx8
xsID=J
Y;:@E9}>;
u@L_u8EL
X;"%&g_
M{mK51
6GsY yF
Spq9!^
\It1:W
Glj95j
s?)i^sPR
nV)a`H
Xqz\DW
zLKiSg
o&/w?1
[Ol@J`"1
yp8BJktH
oC`w'D
PEMOR3o
0ee<T:#.
4D+La[
#ZG_I
uRlO#>
$[ZWmq
=U1$gf#
278\ N
V6|#hwY
^MKJ.=
c?>lg_V
nu%MX=m
EpIw=)
H~C4VIg
~-R5<I
S!0Hjrmv
m9$Z!.
laP=Ahv
At.5N-
j<15,t
`<KGw#
# fQY:
2W`a#Nq~
r}N$!U
%i% :
x]<^z!\
LT6x"w
s_=9Lv
SetThreadAffinityMask
5K@&(;
?-I;&- 3
(H^J1P
#l"rJ
'<4A @
w_?nNd
jX#`"Rq
se#/Nm
/hye}y
kmt<R`
yTpNp
HyQOx~&
#Nb])c
2DKV+N2E
GetCommandLineA
^B9zF,
foreeS
A413q
l6\}E[
-LUg.
ln%I=g
go49WhC
JkpJzl
Thread32First
:?OP0wM
tt!Z*;r
,z>>-P
GZ,}kt
<!Q$;V
e9qmU>
)Q)PxX
uP=$Y
~Q,oNV[
H5PmF[
c651S1B
s_yC"V
N2qB~5
UZ,@e][
x^h3HY
0N#<Lp
0Q\1_`
9N*EFy
2\C91N~e
Bogw?6l
fll3Gq
1f":!!DfS
$/yc'3f
2<k(1NBE
J!fUYS
*N'4zj
Ej!(D.
!cjPC\
]u|zP|
/U+~r+P
GZemY:
k_QS0Z
cXbUCbX
OL584^
_fL+@.
ShellExecuteA
q0hiC
.|.>!K
,~ H}w
{~%wKyR
x4z+E.4
;G*Vfv
;DHO,E
]#/Xa#
` }i|~
H5K@&(f
Uh.P^OG
Z7~3=7
#7l,PJ
2?l5U[
^H)5'-)
|\qmYB
ZK~7=7
3&LP%Ln\,:L
u)W4F
PqL?z_cX
i"pO+I
qhW]1+
B)ES$e>
2aXGo+
2mB)8N
D1<$f@
VSD14$f
5\e@$3
^cq7hl
3:tSl$
W;7JhW0
<5A[e
OJ"TV(L
sB?E(M
S4W4R
kcsASfD
N8Mwra_f
0qi%)
'|85^,
Yr-_n/
"NYJ4b
2clK*N
HeapDestroy
W?$kSf
~505^c
< Ld%x
oIU?^D
f-1 Rl
;O|VW;7
cO(9Qft
|k, 7|
et:[%|
<Z%(4
/#}Y*;
&@jDCy3B?
-$BTef
v#k+?5~(
@U/l.X]
./W&}5
UgUQZh[X
yv1>*X
"NpwFb
S1,$[I
fOApq
lW^thV
VR&uysRR
$xCqrq
*,*A@-O
TlsGetValue
,"o4AYCm9<
vI$m~`4=
Ev'af9
=mglSf;
H5K@&(
2LOe%1
0U5w8$
|-<,Mc
tu7I%6
@]onl&
a|Z0_
&iMT@=
QYeli1Z
c_&(d[?
]6 I~l4A
6C]mY:
|#7cZw.b
xqd1!
NS6G~TA
s>>F"7
cWr4SP
x?/6H8X
U;kEe<
CVqmln
'ghZES
<cBd(7
&\EZ^B
=I2~Gj;V6
@w`|!X
:NIB}z
vCJQU>$L
]O?Vgg
%O?SE2
{OMX*:
ZaXhjf/
`L'6g;
67k5y<
o:M_Vbgto
23|A9N5
QdD!ac3
ePn=b'
1Jv#l[I<^)p
75S'RZ
oG3/s_:
",+W&l
9]{io[Y
0L!"OSf
:Ner z
2_T_2N%
7_NIqm
u5(BhR
SGUg9g
NNdaaK
e'jWi[is=
i'AAow
+(d[R_
f#/vD@
jT"":TQS
4yB 0q
{VyBah
ee?Mm
dJV$1CJJVy$L
ZJ<DRN
r7Q7Uv
;2J0SDXIF
u(=c4|(
W+>PggWw
n?^w{C
R{m[AH
nh&4
D2+kz0
&9[~d~hD
R`zj.'
xa!Q1~QU
"ny=Li
2NiN*r
'/%saST64N7
jJksyd
}sEn`J
Pj3!&'
S1,$[Hc
y~l]_E\
#6'4}@Wm
W$<Z';j
oE:9X~X
SaU='[
wN9n3!
9N>Q\y
F,1N?H
^(N5.(:
2NBU}r
FindFirstFileExW
&`g_wi
e2\0bE
q`b`Ag
CRr@iJB
~[pjR
xY_31lKI
9N2ADy
20;1N^a
2NYRQr
%))Hzui
QueryPerformanceCounter
%:F\`(<
G*fwS^
.rQvt|@
!N'pza
GetConsoleMode
;N]b+{
gHH'|1
"Nx/rb
zJ/N@^
Z4A`7
GetProcAddress
$(x7>^
5d:){@
'Lxry8L
0N]Zzp
k"-~~H
*D1<$f
HeapCreate
?p"P5
IWo#[i
/U;yh?(
d+vS#7
{|#fO'e
C=l8p*
3To5n|R
7O9XP.
RsYd:E
:?e{Z@
kp5qD4
_,"Qe*
u)-r7N
X\5l\d5
gX~^/C
Z:^77
:m4&+Z
qT=11R!(
COs"%q`
Z(uW?7qo
SD14$f
vRDp1r
\F'ghx
1sGcCT
:k2I7-
0NE2"p
l^^+4
Zy,c@S
ln(h81KC
DO[J}\
XCn^$(
e8/e$D
>SY~Kh|
f;#fJ*"
uxVx1"
J<"v)}
`\y+f;
ya|,7#`
(UGSD1
$7jaeI!
GetLocaleInfoW
7hyS1,$I+
HeapReAlloc
]ZHGJAR(
eA)mry
Qcc+;0=
<@L_}:t
h`R'u{,ao{!o
tgZ.+&
YOp>CQ%
7D&ImF
:NxSMz
ZZGo:5
@WdEVGFAk-t
;(X#E:
HttpSendRequestW
v{k86<ioH
|Azbd!
mV(sh=%
|v95D\
"w=^u#uD
?i =]P
NBi*`
8NC\[x
c9<#U
`tb~<\
GetComputerNameA
EnumResourceTypesW
G8'WEAR/
cjF/J^
r"zX1l
]g1x[I'
D\pc2
vGXX'N
K*PY{-'
}FI(MA>
RY{o-A
v5lv>
8NP3sx
(e)wT-
8N)6ux
R_xZl@
GetACP
H5PmF[
E"i>Dtl
B9HzH.9
/$f u|
S&'(+h
fy_'#Vx
7B2/~Y&
K$f.BR
2w8,4N
|?q<I$
kD2w0E=N]v
gJ2pmC
#Pv8WABrH
sph>F7
LoadResource
IsProcessorFeaturePresent
7N}*Kw
2GT8?N!
^2l_37
i`:8Tj
bPw)Ek
QM#vEJ_
6p|I#
eEs73g
$L~TQ'
mmZH}a
hUHLO}X
`#m/91
P2x1Xd
\Z*RlhC
v4d[*Z
Z?j"87v`
sc#:F*eb7
/tIsz0
2@3q;[
%w=tL\
Ys[U:i
NhWGGz
k:y4m2\x~7<o~
[;B#OwO
;g{w!8|
QTMo2rM
z?LvC/
$QzEuE!
{/JLr26L
-rnX.JTB
@5+Ur^
el7,Uk@
Hhs_xo
5.EK-3
D1<$[fD;
&:"h)i<p[
)b'2~9&=N
D1<$fD
u\gAVg
'UZVFTX
Hf3;7C
2g,m/NiZ
>D9t/_
4Nlc<t
~4CuVV
zX5;2'-
.r9vaE
;!i7J7@
q^ i,8
%m(`cz
C~X(Bh4
>(ukDp
M9-.YH
Xe@Zl(n
&891%L
ea^Ip<$u
;YKfyJ
0=v0L6
SuspendThread
mJ!M*JJU#b-L
hQbY6L4nrV
v659\CGF
(:&dWoe
-P58\6
HZJQ~
*t#x%E
:t7jcC
"\p$z.
8QY@ql6
le\J{q
DS[g[>m
K2l-I"
o6$;stl
^J,fB2S
`>;Fa[
2*1(<N
P,poby
iph5N:
w5+CHG+
AI'Rq K
N_UaGKeK
Z5Pd97
K-fiiR
"Zj_%Sn,
)^/ze6
aL\~]|
6p;a]x
B5-P_(
u@k)>R.
1%O'Q7
}Y'>*y
Jwxqn
N3fe,}
D%fKC]
rGxI5m
3r3"IT5
S_kQHU
%IihLB
*kw8TLysH|c
@#f~g>
:ciDv?
hh73P2
Q&m;j(
oPGS4]
i>]VQ0XX
W;lh0>
2m&(&N{@
0#lhZz
g3|Lm
vAeg'Gz
7fMeyh
#cNq&i
.*,ts'
lXC00O
t>-h|)X
.G5E.o
B9TO`?
nX6)bO7
F4yy'yB
(m&l}%k
A^]AYA[f
T-L("(2L
x&\y<%
GwA-U_
c-gS%v
*{{t+w
.q6,70
2qfe>N?(
LoadLibraryA
mWC{f
2fYg>N
=NW$3}
2%"L5N
6]P/r`X
x^EfU.
DKn8tL
iO*KYH]
%'rvt.
y&f9(/
r'wIB
_#3:o$D
"'u3%P
DYK02D
,l5h)0
y<B5>&
I'^HRwQ
e&IpZ>
G@%/d6
2@s[nMYM
?2@2kR
InternetConnectA
kLx2\v
n}[C^g
Qm<Xh=WU
KD*XM e
[IFD']
zBC?|qJ
h#xPVn8
87[ZMo
&NyB7f
2+<H.N1:
zQ7Sf;
]q]|Kn
OZTL)A~
iH~9n?
Uh\1eo+
Z*%t&zXX^;(
q%5]YW
GetSystemInfo
?N:Hn&
e*(~w
>Nef%~
2gxZ6NQV
tsON5w
soEL\
y@NLk-
z@("aP
tLfN_;@
eqn}d4
}bh]"iy0
nc=azl*f`
vXVURHo
&NglBf
J=.No|
$WHT~)
<NM66|
Ss-_3m'
R%f:NK
]m;lYa
]?pEGW
Y:y/nw_
S|C65w
K$wMAoy
=86R'?
8xYGy&'
!<"dP^8HA
:MQ<2;
e^ngv\
5dN-lH
wp=#%BJ
'8dzo$L
2qtdM`
:i9&k`
fh-i7a
@mxjpj
2Z]36N
l*n\]e
{FG)|1
MS'%SW
4X"BHM
)n-!wy
l_&5f?
yFi"D1
P'=v-U
ZP-^275/
}#dah%M
&Q6?;5
DoE|@G
ew'RE/
c8FM[!
9~zI!%
/2hg.=N
5N^YQu
2/d{6NAR
wI&/?z
2h'Y%N
tXx^,aK
2p{T%Nnm
y;~3~L
r|kBB{
Vqd+n5
;tEq:<i
+1>Bv.
5JPub_Iz('t
44~Gl.
h3EP$&
$q+eIK
fJI;iD4
5Jn)g_I4@"t
hufI&h
Yv&*}G
Le&f=nl3
ut63'6
Htx!xG
J7Ko^p
`J |=GJ
(M!fCB
$@BV-(
w26$u_f
&]e7G
iZZTj@
qiny~m
-X,=)6`
oGrjtq
~gha4!?
ejP)T^
Yl(:xnjE
?#+E^*
YmA/nU
@I8Oo|
!xIfo}
!B]@i
um]2#0
qX$ay[
ALSXJlL
shz+kw
'%h.<k
im`%-/
1L*\PFW
H)IjR9
+{piies
GetModuleFileNameW
g?v)s>
iukOVf
c o?Ro
W]&ymC[`
dSlUs)
bym!uH
| X]E"
N+]GJzu
4]|ae<
.vZ-jJ0
j?yqO
(/<pyE0
jncaueU
xjtvu{+
Y(+{_i
|,8KH"4
D0?KSU
*GLI0
3I8mD#
+;/@pJ
WwB6RV[:
[m7~Zf
>r`Sjl
)=5Cy7
#;m.l
ZTei37}g
q(,f9x(
+s2|In
I3Xs`7
#LJ^1^
MTC>78
IF`'N1
KHR/{O%
*$Na{-
v%Z.',
}$K^M#<
3"++eH"w
pi'PWJ
rmGAUm~_
xHb2f#
g.I_"S
XJ'#IH
iSD1<$f
mJi9VJJCc
0k4FSq
InitializeCriticalSectionAndSpinCount
jWE-maZ*]O
$wyUJf,lX
}J~X>WkY
OPq42s
`d6d/M{
j6{1!+E[|
!Z# +Y
2FaM'Np
w8K%[98
%%l?xR
={6_E8
AMc7=(E'
-$BTef
nZ4LPr
}1$ym`a
Gn=&,#>
Yt}[M#
:-hXj{
/VL4Qb
c^qV:'
5A)ffH'
SetUnhandledExceptionFilter
f>x1UB
Vh=rU1W
2x}4?S
jtPzxT
2o4o$N
?V%`7\
2Dw`<N
s9c1Kv
23lN7N
3x0Y]^
GetEnvironmentStringsW
_+J60eEb
(%5|m6
)/f@40
x:)Ry!9
"4~)5@
2e:c4NKd
1h~5Vhk
HSD14$[
C{=q'X
2*gE3p
f9x:~w=
1/>c""
g1}+W6
wX1Y&Q
J59Xz2N
Q]dZaZ
|Y )L^W
At)(Ij
ETv9&iY
/6e~L@
"#Y'j\%
}%X zR
bWUa=@+rq
|PU`>%
JhN~y3{
MXtcY
`aw/:7>
X&$B9@
#e0jPZ
?@dX60w
+P;,h
z.OlJ)8
CBR D5
vol|sW
uktF#g
]xqKmL
7)< u+p
H!_vLq4'
c|Q4\ef
M?I8}^
J\1haI
3xH'c\
*|GTi]
;M(CF-
nJ4zNIJ
qo}8xi
qlJr.l
S=_YI%
Qh;D&?
?(?N*)
j?ddg!*M
kh9/B1
# eiw"u
/mjp&'
|tB!H,
1,$[Hc
[PDg,<B
/jn2n
~J=uLYJ
ed:8"<
g:k?a'wkP
7>k??kskPZ
@{1aTR!r
D1<$[Mc
Z94{,7
T8f)%M
^k&lBr
3NyBks
3N)Vns
FindNextFileW
0Ey& g
&J,iVZc
d@s$?V
,U%@8NRH
'()R_!U0
Z?zC$7
S.lL$:
BE$7Z@
ZfOT,7O}
{8fFfb
:5R8Zu3
.h;pZMb
~-R5<I
]-T",2
wsQu#&Su{
HrrIW1
pLd6<+
[|!q5
%`--wl
zQ .|-7
1Mj(uw
xw}G@z
U+]Tb7
vad=x#
bGolmL
j8@@nH
J2@9\Q
>L""b^
8O.]"tV
HJ->jd
YyyU73"lX
[%0Dtb
"1K2^!
&Y>Ff_"
z!XW'i
:\hCWCa
v.xGnx
"(yB9t2m
quj3`2"
z'a?G[+,l
+kE}axn
|;dQ?@
-)Y8$g
t3DBj=
^VFj[]
m'}5]
}N1G,G
@#9Fp$N
[KdDkL
vO 7FHW
`T(l1"
ym}d,y/
f#B3Bf
?Bo3f+
6LaKv5
hV&rQL&
|LHj(a
J/!Smv
'y7!m,(
(WN*.>w3
tsK3L^
(Nxc:h
\iAU !
5fdy'&
L/i7T"
$.sCc[$
Dz5{[r
Z*O&}XO
*?#MbS
Ze~>K<
FkVJ68#1L
~*QFh|
mSs$Uu
~e5gh _$
ri>dIt
@0|7Qu
8XB,R5[0
RXHjZ4
Mlg) s
+|]"f;
~x91 3
6O=t-
f|DIpX
w'P:jHB
;I_@3@H
gj`r$p
~PUBWs{
M)<E^F
dR0ax&Z
DjzjdS
-qK@2W
x.q!#M
(N$7Th
D14$[Mc
&}=&OR
YC9(i7zv
%o%BZx
j:.}j
;dl+O=
(NG,Ch
W u4TAH
-AReZ8$
.YI8(5
v_K2R\
SHGetFolderPathA
%rb6IR+
(J>\Pb
,E.S@
+m7P>{
Z=|k%7
@%g I33
k]VcldF
hF%gm]Fg
T |H~O
zqkDb/
;gqxD=
1v<GL
<\h8eT(
9Ly[D:
1L%o.L
+@#ZtBp
p%2gaw$x
3;M)"D
8e0=&O
0c\LJ-
DyQ|qo9
TlsGetValue
ZfC]%7
]0%Va]
-j+qY3
?D3:Bw
)2TW=V
7LfDG4
zj.4O[
wj*d]F
GetCurrentThreadId
H7}2B)
{D!_Ts+*
>ITcKr
OSr+;
.KIRQaM
.dnbXX
x13Ne|
WOk4w!
r#aza;
HlgH(f
JR7Dc>e
>KgmbgH
>x@`,u
;=]fD3
SetClipboardData
2,Oq9NBI
2u*/ Nsd
)F| F/A
k9+R1l37'Pn
kK 77n
nCFE,o
?Vb3c>
S2Yi`r
o@_>\c;
SetEndOfFile
jY_ U8]
1'rpuntDQ
.\|WQ>c
St.#-V
GetCurrentProcess
=rm^[[
"='uuA
bH-7wR
~ghOO`y
S1,$fA
2fMG2N
FAc)A6
EGU,u@"
$+Ibu"
x*]-)#
s+L]C,;
T<F7Et
LoadLibraryExW
r)CUMyne
i0L; -
FlushFileBuffers
&jLTPM
cT#@N7
X# 0<d
}=#<o>A5
XLko9N
^/lx87
2}^!2N
G.Jxp9
2k(!NaF
)N5^`i
9N:E\y
j`wIg#%\
BQ#<JH
^7DGj9
qx|;K*
) @SZf
|v95D\
'PEO}&
m,J0n0n
"CFVc$
a\i"\X
*aG]{c
mYL^nD
L1feEU
jdI#t%b
8W9f<DN
oh'lGk
|GJzdk
~6T(\I<@D@
w k;wHz
R\dAbr
`I:O~f
YQ':h7J
uh2*P/
iZjvh99
H5PmF[
GetCommandLineA
)NFuei
d7Pdxd
CDcyZA
lJw+{=
)NN)ci
|yTI]H
zQSv5w
md9>Iy
8(~*5nQJ
Gp$f7=2
n-1`f$6
hL&ZvF
>q\;pR
Z*]PO}
Q8xMKzF
d+Ux(7d
2&j_Sg>
73h1Y{
2fuU!N
uKr*r1
)N[$'i
wC>LQ[?!L
Qmjx'/Gz=
N<A)L.
pLGexm
v/,BGK[
XMSH{m1%=.A:
Kx_"jo
m^MzsK
IbgfE!
SD14$f@
f_=Vr'
2j)a:N
6e<nMU
<pp0,4
DMxq!*
b(p*ak(
[Em</@
!^_,\]ck
>2f..'
PYho/k
LX;[)`
:}* m
g7#kPT
mO`9r7
G\Olr@
72ffZ.
J o'#N
2]qjE\
G3}|A\
T7]fA;
SD1<$[M;
&psX%AV_
Kt$?fL
aT8:+U
J!L6|IE
3BSx"+
sHgBr,Le
8S?01
hRP\#k
:}iXj1
6;L+.r
`x:J*d
+!Ampr
_8$X:6
3CQ8"Q
.G5E.o
ns\5!.
=`Lmu}h3
GetStringTypeW
SD1<$fA
)chd(,
41Y<tq
[+7_P=
TKR!WG
bY\L"_
|;@/p!
I[E#tt
x'_F4q
*N;@gj
4I(=>k
-5PW!E:
:N.!gz
56NA,r(G
SD14$fD
NneqSK
]C/]4z
6CAKf;
A9kE7a
n+Ky 4L
xzx'cZ
G&j;,X
#Nl;Nc
Fib?@TL
2dGK"N
4TB]6L
~[Pv|q
m*>74>
(N\/{h
EnumResourceNamesW
yIe~fc
D;cj%?
9y0&U
v~}QyV7nP
,*xx]Y
P?"^>U
GetCurrentProcessId
8LFFXL&
G^BP[5
@7si?L
6f;f6b
3=c6KT@
W?JTbFb
BikZ1#
$qpL~v8
z{<$}i
r*"Q@M{VZ
hvuGu?
fqBIs?4i
"R%vi-&
MJF&JjJN
ch=vs,n
<K_dVeH
IsDebuggerPresent
]l .f#k
ReadFile
da\fj&
ZemzEc
[t7n:a
$3GLThR+
2ZB'f#
`Mlzf;
GetModuleHandleW
FIM&"
@$b[}h?
XBq8ft5
$%[7(s
s?M#fp
GetCurrentProcessId
gAx|\Wx
"$[~[QE
!hi6"X
Ba5d(d
O#F,qNg6
<oG*0R
@D55[
4bs8bbpwH
orS@6:
73khJH
R7w1%6
H$SHrt
NG*Lon
fMa\S<:
8`XH"8Q
NU,uig
wZ^Vg.s
D=4aD~gw
^M;qp6
;<ZGo|
R&CojS
(\;:p@
{~2]"[i
^bJ|V
hYDp*S
[ALtaY
u3fCgl
Wh) iX_
k7rl4o
%AI!q`j
8& jo
DX;f@8A
aNg_H-;
X8"+a]
/CFoqhC
qeE&q%x
pw(;VS
J*QO}I^
|XW fu
+N=*Fk
{.t3H~
D-vfbAvx
I_FE.
.<v2nv
]Ct]];Ql
vG"[(X
vJ_3mQJ[}%6L
mo{fa[
P~_u*C
Inzk7$t8
WF5^!}
2(L%N
$-$;U@,
0S20Ol
K\11:m
_cG"x*
7hC]fA
o7IZ;7
V!GLrcg
lxQb"
h4fY}q
DPu-E+
x!~w'4p
oZt)j*
g^LU!HM@Lj
8Sn1"'H
ju{Lm,
\e+YPPJx
|v95D\
DR:m}^}FsI
OM: 5L
y7Z3%CS&
gRT0rtR
G45aMinv
sU?y"vn
2dSv,N
2<1TTso
|jbtKj
/NKt>o
OgkleUDp
L%==4c
4aA}iE
pAVl")B
Z7r*(7
h_90w9
2LW@?N
7NzQ?w
)4fS{0
M=tj\%
pY_%FF
sl*~_elv78
GetSystemDefaultLCID
m$ep p8vW
?'0co&
+'>/nl#(=
dX]Q2)i
VWf-+9f
obbP#8MR
+sRgX4D\
X|EB1%
8*P;]0
%N^9[e
Ja5)8$A
GOQ8Z/w
Xw^Af;
Lg+$iU
"FTfb
w ^)_v
'\<`Nw
2ZMW$NX[
-1<$fA
~5"lN2U
2]zQcT
Y>"NP
S1fc6
X/R$_X
D^K6C)
;)VJj
l)Su\.$
a_{.t"
k7CaWfd
AO@W%N
uJnl(RJ
@)"Jx_5h
mujbkK
S<.omf
l7P`bh
<"lI!U
-*l2^D
AD=hqCJ
E)'-B^
|)5i-
(!&q!
Z,`jj+
dSzqh:4
`+b< {
Qdnh u
kUy;L)^
InitializeCriticalSectionAndSpinCount
RV&#3a"
~4a|\<
WP[A}Q
<l!-?b
$<#8U!2
MB,gTh
Y@jkG#
U%&XH@
v4fH~Q
ZU9s1M`
cU<_T|
LLDOtXVD`
'B4z)X&
GetCPInfo
3}m?fM
e@?7Lp
}3M=fG
q2Tg_f
)Tr,$[
q4yEI.)
6NNewv
AnlL.F\H9OD
Q[3EhI
u=)zYg5
9~Eq`}u
[\A#[Q
g,3>W(
n]|:eK
Wpn 4}
nJxbL~;
8IwP_)
b|#mk.
5r~rof
d{aVT|
~1j%yF
ph<&J*
b,KCmh
!<GPDP
^8mtPL#
{m8kqiiH
y5(lQO
VpVBw7r
mgPrmc
\$k#l#
aIc"0@
=HwmlA
q /PA'X
jHrRZO
M"n+JU
GL6!wKA
Zy\-!7
GetProcAddress
lHn;\O
|!"I-(
AL*HqK]
Z$wJj#
w 39G'D
"SjmBy^
F8N@gW)4
2%@WF\
2jM=$N
wLVtPj
}j[(!w
)) T$q/j
"U%f,!9M
"p)O4?
',i(3gxK
/J~z+:
J'PLFR
i/oWFV
?=f|x&
Q@GqWK
VirtualFree
CreateEventA
n6]+tj
*A]u%H(%
2<_r6N2
24?R%N
-N.9-m
{&e`om
Is)M#c
GetCPInfo
D1<$[f
5Y|gcz_
irm&'t
2N-avMwe
Y/T q>>
5rN3KP
u:OuuM
w%WCoHI
-^ oZw
wJ8|sH#
Y}Gd}](
CD4ZV_
qnJ]H!
T+l0|=
y/D}D3
CreateToolhelp32Snapshot
&Nz}_f
q=fp`h
{N#l{o'
kKMG:B
V&EFf!2
`J\7PM+
Tzs3=M&k;C
H5K@&(
h\0"6=n
?" KS%
Z%`A7xb
2Be+%N$
-NtkTm
_1J:>Z
yHUqIO"
%XO#"/
UD<RA
Ys;{r'
!P@n1H)-
Piqjl{Y
"ahDnJ_
.Lu_#-
IsDebuggerPresent
#La`KE
"PW79@=.
IwH:%W
Zb#}*7
ym lQ}
?fH~tJ
5N(?mu
ZZc`*7KA
]Q=o`
dL\~vy
=P4}af
2]~B'N
QQ;eAW
p]^.O9
$z?9@vWNqp
n6f37w
Q(lP(8
tJr.DSJ6@
I(>}tLl
2>5">N
2~I,>NDO
GetModuleFileNameW
Q&=5$1
UU+kh\
+6&cJH
.#$I1#
Hf$A=^M?
v #1(a
$KwVxdJ
`-)yHsy
}hWuMo
IVm7HJ
!svL]z
xW^w,Y8
C|9ZI[
-NF}4m
iW6Ws/ZG
u)`\G)
hO"qg
>t=PlS
j[[(a:e
~2{bWF
:R=!A-n
@vU|cVA
JjUC 'I
{RlS+et
|R-8e3
2%"L.N{l
SetStdHandle
^<WR!D
&NbY=f
2p/B.N^q
EtR_:i
;gG oIBb
1xaHQ
CharUpperBuffW
(:yo)
'N`kPg
;~%sCFeL
lcgA?'
2x'l-N
S=pSz@
Y2f]%+
HK?[`)I
LF|pNI$
i(}3%`(
kD{1\tf]
GetUserDefaultLCID
9vsa\N
"BtZsK
n*,g^-[
/|[/(
G!Y4@V
uBqeEE
H1C3:
rs#pBtT
LocalFree
%Nvu#e
JFS%UF6
T05\f;
]%1AT\(I
2y:V5Ng\
%Nhc&e
2z]Y-N`{
-(+&<&
2{$(5N
5K@&(f
3 +/,
Q(l<|8
Rv-r>joi
Antivirus Signature
Bkav W32.AIDetectNet.01
Lionic Trojan.Win32.Agent.Y!c
tehtris Clean
MicroWorld-eScan Trojan.GenericKD.65899324
CMC Clean
CAT-QuickHeal Trojan.ClipBanker
ALYac Trojan.GenericKD.65899324
Cylance unsafe
VIPRE Trojan.GenericKD.65899324
Sangfor Trojan.Win32.Save.a
CrowdStrike win/malicious_confidence_100% (W)
BitDefender Trojan.GenericKD.65899324
K7GW Trojan ( 0059d8cc1 )
K7AntiVirus Trojan ( 0059d8cc1 )
BitDefenderTheta Gen:NN.ZexaF.36344.@J0@aik!1ynj
VirIT Clean
Cyren W32/ABRisk.MTJC-9255
Symantec ML.Attribute.HighConfidence
Elastic malicious (high confidence)
ESET-NOD32 a variant of Win32/Packed.VMProtect.AHG
APEX Malicious
Paloalto generic.ml
ClamAV Clean
Kaspersky Trojan-Banker.Win32.ClipBanker.xlr
Alibaba TrojanBanker:Win32/ClipBanker.4fa8d61e
NANO-Antivirus Clean
SUPERAntiSpyware Clean
Rising Trojan.Agent!8.B1E (TFE:5:R9MN1BAHivH)
TACHYON Clean
Emsisoft Trojan.GenericKD.65899324 (B)
Baidu Clean
F-Secure Clean
DrWeb Clean
Zillya Trojan.ClipBanker.Win32.15896
TrendMicro Clean
McAfee-GW-Edition BehavesLike.Win32.Generic.wc
Trapmine malicious.high.ml.score
FireEye Generic.mg.99f16ab6ab670935
Sophos Generic ML PUA (PUA)
Ikarus Clean
GData Trojan.GenericKD.65899324
Jiangmin Clean
Webroot Clean
Google Detected
Avira HEUR/AGEN.1254260
Antiy-AVL Trojan[Packed]/Win32.VMProtect
Gridinsoft Malware.Win32.Sabsik.cc
Xcitium Clean
Arcabit Trojan.Generic.D3ED8B3C
ViRobot Clean
ZoneAlarm Clean
Microsoft Trojan:Win32/Casdet!rfn
Cynet Malicious (score: 100)
AhnLab-V3 Trojan/Win.Generic.C5396243
Acronis Clean
McAfee Artemis!99F16AB6AB67
MAX malware (ai score=82)
VBA32 Clean
Malwarebytes Malware.Heuristic.1003
Panda Clean
Zoner Clean
TrendMicro-HouseCall TROJ_GEN.R002H0CCE23
Tencent Malware.Win32.Gencirc.1188d309
Yandex Clean
SentinelOne Clean
MaxSecure Clean
Fortinet W32/PossibleThreat
AVG Win32:TrojanX-gen [Trj]
Avast Win32:TrojanX-gen [Trj]
No IRMA results available.