Static | ZeroBOX

PE Compile Time

2023-03-13 01:52:47

PE Imphash

f0e8db307701582115b12426e04e3928

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x0002b3b8 0x00000000 0.0
.rdata 0x0002d000 0x0000ee88 0x00000000 0.0
.data 0x0003c000 0x00001f34 0x00001200 3.33677971121
.>-W 0x0003e000 0x003f9a94 0x00000000 0.0
.kd% 0x00438000 0x00000514 0x00000600 4.13409070913
.Mdp 0x00439000 0x00704fc0 0x00705000 7.9732218634
.reloc 0x00b3e000 0x000006a8 0x00000800 4.11924835389
.rsrc 0x00b3f000 0x00070d9d 0x00070e00 5.99361965142

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x00ba3638 0x0000c192 LANG_NEUTRAL SUBLANG_NEUTRAL PNG image data, 512 x 512, 8-bit/color RGBA, non-interlaced
RT_ICON 0x00ba3638 0x0000c192 LANG_NEUTRAL SUBLANG_NEUTRAL PNG image data, 512 x 512, 8-bit/color RGBA, non-interlaced
RT_ICON 0x00ba3638 0x0000c192 LANG_NEUTRAL SUBLANG_NEUTRAL PNG image data, 512 x 512, 8-bit/color RGBA, non-interlaced
RT_ICON 0x00ba3638 0x0000c192 LANG_NEUTRAL SUBLANG_NEUTRAL PNG image data, 512 x 512, 8-bit/color RGBA, non-interlaced
RT_ICON 0x00ba3638 0x0000c192 LANG_NEUTRAL SUBLANG_NEUTRAL PNG image data, 512 x 512, 8-bit/color RGBA, non-interlaced
RT_ICON 0x00ba3638 0x0000c192 LANG_NEUTRAL SUBLANG_NEUTRAL PNG image data, 512 x 512, 8-bit/color RGBA, non-interlaced
RT_ICON 0x00ba3638 0x0000c192 LANG_NEUTRAL SUBLANG_NEUTRAL PNG image data, 512 x 512, 8-bit/color RGBA, non-interlaced
RT_ICON 0x00ba3638 0x0000c192 LANG_NEUTRAL SUBLANG_NEUTRAL PNG image data, 512 x 512, 8-bit/color RGBA, non-interlaced
RT_ICON 0x00ba3638 0x0000c192 LANG_NEUTRAL SUBLANG_NEUTRAL PNG image data, 512 x 512, 8-bit/color RGBA, non-interlaced
RT_GROUP_ICON 0x00baf7cc 0x00000084 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_VERSION 0x00baf850 0x000003d0 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_MANIFEST 0x00bafc20 0x0000017d LANG_ENGLISH SUBLANG_ENGLISH_US XML 1.0 document text

Imports

Library KERNEL32.dll:
0x838000 DeviceIoControl
0x838008 GetTickCount64
0x83800c Process32NextW
0x838010 CreateFileA
0x838014 Process32FirstW
0x838018 CloseHandle
0x83801c GetSystemInfo
0x838020 GetProcAddress
0x838028 GetModuleFileNameA
0x83802c IsDebuggerPresent
0x838030 GetComputerNameA
0x838034 Sleep
0x838038 CreateDirectoryA
0x83803c WriteConsoleW
0x838040 HeapSize
0x838044 CreateFileW
0x838048 GetProcessHeap
0x83804c SetStdHandle
0x838058 GlobalUnlock
0x83805c GlobalLock
0x838060 GlobalFree
0x838064 GetModuleHandleW
0x838068 GlobalAlloc
0x838070 GetOEMCP
0x838074 GetACP
0x838078 IsValidCodePage
0x83807c FindNextFileW
0x838080 FindFirstFileExW
0x838084 FindClose
0x838088 MultiByteToWideChar
0x83808c WideCharToMultiByte
0x838090 LCMapStringEx
0x8380a4 EncodePointer
0x8380a8 DecodePointer
0x8380ac CompareStringEx
0x8380b0 GetCPInfo
0x8380b4 GetStringTypeW
0x8380c0 GetCurrentProcessId
0x8380c4 GetCurrentThreadId
0x8380cc InitializeSListHead
0x8380d8 GetStartupInfoW
0x8380dc GetCurrentProcess
0x8380e0 TerminateProcess
0x8380e4 RtlUnwind
0x8380e8 RaiseException
0x8380ec GetLastError
0x8380f0 SetLastError
0x8380f8 TlsAlloc
0x8380fc TlsGetValue
0x838100 TlsSetValue
0x838104 TlsFree
0x838108 FreeLibrary
0x83810c LoadLibraryExW
0x838110 GetStdHandle
0x838114 WriteFile
0x838118 GetModuleFileNameW
0x83811c ExitProcess
0x838120 GetModuleHandleExW
0x838124 GetCommandLineA
0x838128 GetCommandLineW
0x83812c HeapReAlloc
0x838130 CompareStringW
0x838134 LCMapStringW
0x838138 GetLocaleInfoW
0x83813c IsValidLocale
0x838140 GetUserDefaultLCID
0x838144 EnumSystemLocalesW
0x838148 HeapFree
0x83814c GetFileSizeEx
0x838150 SetFilePointerEx
0x838154 GetFileType
0x838158 FlushFileBuffers
0x83815c GetConsoleOutputCP
0x838160 GetConsoleMode
0x838164 HeapAlloc
0x838168 ReadFile
0x83816c ReadConsoleW
0x838170 SetEndOfFile
Library USER32.dll:
0x838178 EmptyClipboard
0x83817c GetClipboardData
0x838180 OpenClipboard
0x838184 CloseClipboard
0x838188 SetClipboardData
Library ADVAPI32.dll:
0x838190 RegSetValueExA
0x838194 RegOpenKeyExW
0x838198 GetUserNameA
0x83819c RegCloseKey
Library SHELL32.dll:
0x8381a4 ShellExecuteA
0x8381a8 SHGetFolderPathA
Library WININET.dll:
0x8381b0 InternetCloseHandle
0x8381b4 HttpOpenRequestA
0x8381b8 InternetOpenA
0x8381bc HttpSendRequestW
0x8381c0 InternetConnectA
0x8381c4 InternetReadFile
Library KERNEL32.dll:
0x8381d0 GetModuleHandleA
0x8381d4 CreateEventA
0x8381d8 GetModuleFileNameW
0x8381dc TerminateProcess
0x8381e0 GetCurrentProcess
0x8381e8 Thread32First
0x8381ec GetCurrentProcessId
0x8381f0 GetCurrentThreadId
0x8381f4 OpenThread
0x8381f8 Thread32Next
0x8381fc CloseHandle
0x838200 SuspendThread
0x838204 ResumeThread
0x838208 WriteProcessMemory
0x83820c GetSystemInfo
0x838210 VirtualAlloc
0x838214 VirtualProtect
0x838218 VirtualFree
0x838224 GetCurrentThread
0x83822c Sleep
0x838230 LoadLibraryA
0x838234 FreeLibrary
0x838238 GetTickCount
0x838244 GlobalFree
0x838248 LocalAlloc
0x83824c LocalFree
0x838250 GetProcAddress
0x838254 ExitProcess
0x838268 GetModuleHandleW
0x83826c LoadResource
0x838270 MultiByteToWideChar
0x838274 FindResourceExW
0x838278 FindResourceExA
0x83827c WideCharToMultiByte
0x838280 GetThreadLocale
0x838284 GetUserDefaultLCID
0x83828c EnumResourceNamesA
0x838290 EnumResourceNamesW
0x83829c EnumResourceTypesA
0x8382a0 EnumResourceTypesW
0x8382a4 CreateFileW
0x8382a8 LoadLibraryW
0x8382ac GetLastError
0x8382b0 FlushFileBuffers
0x8382b4 WriteConsoleW
0x8382b8 SetStdHandle
0x8382c0 DecodePointer
0x8382c4 GetCommandLineA
0x8382c8 RaiseException
0x8382cc HeapFree
0x8382d0 GetCPInfo
0x8382dc GetACP
0x8382e0 GetOEMCP
0x8382e4 IsValidCodePage
0x8382e8 EncodePointer
0x8382ec TlsAlloc
0x8382f0 TlsGetValue
0x8382f4 TlsSetValue
0x8382f8 TlsFree
0x8382fc SetLastError
0x838308 IsDebuggerPresent
0x83830c HeapAlloc
0x838310 LCMapStringW
0x838314 GetStringTypeW
0x838318 SetHandleCount
0x83831c GetStdHandle
0x838324 GetFileType
0x838328 GetStartupInfoW
0x83832c GetModuleFileNameA
0x838338 HeapCreate
0x83833c HeapDestroy
0x838344 HeapSize
0x838348 WriteFile
0x83834c RtlUnwind
0x838350 SetFilePointer
0x838354 GetConsoleCP
0x838358 GetConsoleMode
0x83835c HeapReAlloc
0x838360 VirtualQuery
Library USER32.dll:
0x838368 CharUpperBuffW
Library KERNEL32.dll:
0x838370 LocalAlloc
0x838374 LocalFree
0x838378 GetModuleFileNameW
0x83837c ExitProcess
0x838380 LoadLibraryA
0x838384 GetModuleHandleA
0x838388 GetProcAddress

!This program cannot be run in DOS mode.
`.rdata
@.data
`.reloc
@.rsrc
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
.?AVlogic_error@std@@
.?AVlength_error@std@@
.?AVregex_error@std@@
.?AVbad_exception@std@@
.?AVbad_alloc@std@@
.?AVexception@std@@
.?AVbad_array_new_length@std@@
.?AVbad_cast@std@@
.?AVfailure@ios_base@std@@
.?AVruntime_error@std@@
.?AVsystem_error@std@@
.?AV_System_error@std@@
.?AV_Locimp@locale@std@@
.?AVtype_info@@
.?AV_Node_if@std@@
.?AV?$collate@D@std@@
.?AV?$_Node_str@D@std@@
.?AV?$ctype@D@std@@
.?AV_Node_end_rep@std@@
.?AV_Node_end_group@std@@
.?AV_Node_back@std@@
.?AV_Facet_base@std@@
.?AU_Crt_new_delete@std@@
.?AV_Node_base@std@@
.?AUctype_base@std@@
.?AV_Root_node@std@@
.?AVfacet@locale@std@@
.?AV_Node_assert@std@@
.?AV_Node_rep@std@@
.?AV?$_Node_class@DV?$regex_traits@D@std@@@std@@
.?AV_Node_capture@std@@
.?AV_Node_endif@std@@
.?AV?$basic_filebuf@DU?$char_traits@D@std@@@std@@
.?AV?$codecvt@DDU_Mbstatet@@@std@@
.?AV?$basic_ifstream@DU?$char_traits@D@std@@@std@@
.?AVios_base@std@@
.?AVerror_category@std@@
.?AVcodecvt_base@std@@
.?AV?$_Iosb@H@std@@
.?AV_Iostream_error_category2@std@@
.?AV?$basic_ofstream@DU?$char_traits@D@std@@@std@@
.?AV?$basic_streambuf@DU?$char_traits@D@std@@@std@@
.?AV?$basic_istream@DU?$char_traits@D@std@@@std@@
.?AV?$basic_ios@DU?$char_traits@D@std@@@std@@
.?AV?$basic_ostream@DU?$char_traits@D@std@@@std@@
ShellExecuteA
ZvQ4mO86
_*Jn\nwgz]
8I#p,B
9X[EoUd
#i&ytI
6Q"!;9`
h8J4p5e
IsProcessorFeaturePresent
AWD1$$E
<l,5`y>
nENw5yCx
""8yR
8+ \Kw
zSuYl|0n
f,MD)tD
lm\]@`
|I#6QM
Gt}5x
.r<+Wx
AE~gS8
@iC!(*
nDZf+z
s$}c E
*GW 23
euH7e?
vUNZ1F
8O\&<At
!{?#%E
{E:;\B
:Hc(!eK
p$.z2V40OQvHQ*
28,CkkF!
S,W.?NaW
6h>P^{
YlFbNA
IZ8ueMu
lAA4hsA<
':Pnp7
._!G\J
bfjE0Sv(gg
)B%sWI&
vElRC?
p9[F_}Vtpw
1xC5tN
8rtQ/AY
^]rCzb
u@$!N@^
F}oAH=
vcqjX#
$W?y(gP
YtJT>;{
6 loIN
o 3R`l
-(y|C*
Mthx}s
SetStdHandle
\LJh!7L
rAAoSmA<
PGaY-,
[kH`wB
&I\4Ijh
S_8zFc
JW]i0\37
J'/}&K
64i^dJ
X'6clb
o|Z?_{-
raXzTe
fjE0GyJ
DW^c '
X32$us
C- K[8
W,<=i/1
% #:V*s
5"<>>+;
)#z'r^
5CwN<@
8@]#ET|
R%! ~WJ
''P<T{
4yt{"i6
SqH0?&}w`
'POEE#
.q oC-
axs"Sbd,b
tWN)_3
*K:/f;
vU_-^.
GFcKXt
rqp1?5
~4y{af0
*5l\xJhL
aU;(ym
Qn'Mt.
YG_J}\
;kG<wZ
^>80d)
b]QPn:
l5ph'T
4`!1:L
PCn!sV]i[
`v%lx
70)[I%
UwrnZb$
z B\;;
ksGHlm
$]#o&}
OXflh,1
,(xqe1/
EyFi91
Lklq#0
k%(Eo=
M(@m#|.
=Pzfe=
8${qZ"
mBsb(h
GetCPInfo
ct8Z2}
Np|)y
EqmYuv
hu)*Xr^
%Pk&UI
U"[MR{~
Sg"sdx
^}xVM]g|z`
P @)$
'B#qRX
%tKJZb;?Ju
t2a4,a
3yg166y
GetFileType
,yX~:)yzE=
D1$$A_
&R7yF4
V$y Ff!y
27;TOmP
0Pl~2/
"xV{.!9YH
]i#99v
Ih);V'd
&7wed9
-pLE.f
%Th+?I
A@Ak_^@<
CharUpperBuffW
Txou4-
(nvXX+n
M|}p?A
7y~s)W
AW1<$A
2GD1$$I
N=Q%4
sPY$CW.
/QMkV:
E<@Uu;7
5ClDb@
+2%fHu
QUD?48
ykc 1,0
k74&[M
AW14$A
4.Y3<L
S8PAk`k
AVE#E(
u7^;qW3
$'FSQ%
jMvZtp
8dOo.^
hLAhS0
Y_}nUj
bK7B[f
5`eW|VW
8K#]4:
w^59p)
UvJzeq=
SetLastError
4lm0Ng
UF0#8a
qRZZs*
;?0OD?
3Z52kgB
Rl$hbX
A1rSC
cs$rOKC
O'y0E
_l59V*`
0Zn9/3
^ d)F#d
<XX64@
GsEw28
#&pAWA
[|!90C+
C/Wks+
M2{7e>
;Ao9$oR
AWD1$$I
v]~nfA
: iFf;
` s6P'
pI?D!@
M$7E}#@
VLjGfK
{H.4KOY
+d&Rqb
uuorR9
VG(12u
D1$$fA
yTk{6y
n=LNdS
%G[l|l
;;r04@t
<:I%KT
$kY1f;
`9r~8x
TL2fv)
"|$_ue
rNm:r)
1<1yTP
jn%4L1<
D@K;yH
CWB"wt
cL=yo K
GetUserDefaultLCID
qAWD1,$D
ExitProcess
SzT'y
.K*0yEc
hC GOkRy
;klI]4
m[tqK9
FxYfbI
h]E<~&p
^KsD5[
f>j.l'
U)7+'*
GetCurrentProcess
14$A_Hc
`=KY3k
T4G%9X;n
i!QWY&&
L\i3K+
_MH&oJ?
%y *AU
!&Vl`|
zkHVv'#eaU
[_I$h
dwCpXa[
DeleteCriticalSection
0mCO5NB
~#5iGq!o
NUH`=;F
k\Td-21
9_hg/m
``[-7)
Wn_1BW>
jr@<y}
%N|:'Q
${ &b'K
EncodePointer
14$A_@
ay<s["
gF?vSU,a
.6;(98
%mLb':
QM~Jp7Z
y+otf;
}`L5f;
Of,~ZN
@DOd>{
1cl=>H
~14t@Iv>
YrD>`
{{=ljd
tbNKyu3Du
pJOhAWfA
rHFE9B
bSM_Q
eG#ijj
OnneXG^
Qh{a)pd
R,zU3Q
8$mq<E
MLw*sf
6gg0X
G<!geo
t\%uSX:y
FindNextFileW
GZEZ0G
7(%(D_
vh?PH+Ly?mVi
X^SkqK
DD1,$A
TlsSetValue
L>=?LkwAh
gh&wD!
,uxsYnZ
ZxtR-dO
{*`cVA
@?)7%>
2^p<\V_z
G<oBmc2h
Tnj$vi
>IgJID
Fj&m[/
MultiByteToWideChar
mf@_2<v
Fh2A0@*
7Q~7&Z
~bNs'4oH
xYB1Ni
4McE[+
\s`nj'W8
`$t8#P
h[.v?p
w7={j&z
KI'bto
Kh&0u._~
$Ge=@y
I9yc%y<y
IJsLi.
LBA4pSB<
$9nGjK
{)G|N<
zwM18!
BRWcc[
axYpLn
7yz03P
,aN<g;!
JlGawD
#0\oEP
g]=Vco
GetACP
;"K5>"
5c<PAWA
IzPo+w
|A7%x\6d1
IjY~C^S
qB#g+[
FreeEnvironmentStringsW
:$3&f;
?'6(y=
gw|]F<
I\t^8aU
*)WkZU
#:)fYS
9jg:CC
Qutz#*1
F<]2]A
n|3hge
EnumSystemLocalesW
EncodePointer
bJ~PLgR
(BysnO
J55vLT&
:B4CUMU
UxO\sY
6F1sl
K%L9]L
sa7E2h
Qn3Y|e
96P]h?
[X\4\/
n6Ub^1"
b$*3eS
_c0eodG
-P!Z}4[n
_r6q]*
\_`qg[
bxmSWx1QK
lI~IEk
c<?gS;H
/TgZ~]
xTbeHS
Q2Y9VE
/-p)DA
oCT-h4
2yxe>R
t;y sy
D1$$fD
=!0c&"
?Rx`8%N6
nD$n+y
,u /[&
Tg"Q+v
$YjqD+S
_lit+a
#L2f=/
#}6lf;
i%+4]a
_w5SMc
Y_nx[&K0
T{X(yn
?&?yZ^
)"&4(Jm
O$O+tLD
yE'T%y8
Yd!Zoff
gk4%8@
CVPeU@OV
B;yq^Ey
L M3Z
#yW6aK]
W|{c-R
HHsnqP
Xt{cw
HeapReAlloc
t{#Oc7p#
W#* 2Hb
OvC9u$GE
Y5*?Oz[_
d}<zm?e
]V4Fi:
}Uhq1lU
IUBTs\
>yj<&;y
*}pTF3o
%6)@bi
Uh^weo)
iJ89n=
IS}O"
_v?'IZu-
urI+dJ
I<'>yJ
VS$%:!
vQ<L;E
WyHIf;
|-s#1>
D1$$fA
yr;i55
b@&#Ew
6G@9~#
(E?Hlv
#h*(AC
3Gt{04
<5lL"J
oU@rDS
Z/#_JA>bcJ
<FL9}PzZc4
GetComputerNameA
K|l1Ve
[PX+ph
Ey<X{h
&b 9J
{u1d-A
z+2s@z
hT"WPk`YKT
mkr~5v_
h lNse.
GSfbi%
\ #N S2Y
TzDO.B
`OA[FTH
4Qv\fD
WxNKwq$m
}E[qFA\%
-dws&T
uK,sB{
w\$F19
;\^kYM
i3s`s4{N
| m/pv;n
ZQ(MU)
3Bu%6k
"fuoD!>
Z"!NY0+!
+S^v^`$
I@(-w6
cl1M-UR
8[g]0#
iX$iMX
-x7"cQ
1},";{
Snp%5q%C
S}w-o-%
m<-5gc
LCMapStringW
~Y2c\{cd
)]$M~|,r
gmvSbA
+"?1Ns
~|e\]^qYF
Rc+T|J
;G+lBoD+
9)+oo
^;:Lty
q&Ct LA
e/yrbDp
jVhu'}
mMr:%k
_C7}Ni
uE^Hm[)
q,0$f;
j67yi?
H yuSx%y
Yv"A,s*
GetTickCount64
H5?$Ue
F7R dg].
X%f=V[
sYGR=ax
$@/<dv
+y0.;:
FlDy-<
8B>bNXE
E\,~Jzo
VirtualQuery
[Whc-j
zSNdrQ
Z3ml>T
_hM@VA
VwSt;`I
YX,$uh
mIbB[QY
1W"WJt
xK`sd
-AJY}D
1c>Z/2:$?:
Am<cM!7
Bq<Aro
TB5y=tZi'
OB7\<JE]
yOTx@sX049
:0B*q)>
P<X7I<
rODa-w
JHbWe[
T:-D:K
fpnSF/s
Tn*^3N
EnumResourceLanguagesA
AW1<$A_Hc
HeapSize
'6Ejv?
{7Q%*>
[Mk*\:
FZY$v].
p6@U@17
xg? kCw
uoalM^%f
2\l.Y^
h.vF5J5
*h5w]u
E|GF]H
Q(33"G
>kH$!s
+Y<AvG
USER32.dll
pwy+Mr
Wx:>uQ\
Hg$yAm
hWBF\
D1,$f=
^DBk]lHCFP%
(DjZOa8
L"2O$X
7-&X-<:
-_p\@M
+HC}N(
"!(0:n
Gi|[sKV$
9l=X"'
B2X.<'f
HeapReAlloc
=-aybTt
2K0e o^d)
u~|PcjN
9\;yv{
k+ivC[
4`dSP?
\H|f 1
pJ?/*&
)$Q~6m
YMGqWD(
@v=y$a
$UK>cHim|*
:`CQvOl|
Uf5p?f
D*AtG1Y
}+lHR~
v$`lt@
@i{Flej{}K
ax0_/'
><>>#>
iY+O^\:'
Fvj",Q
8MZNQ=v
5lL"J;
9!nwEd
Gq`Td=8
fROAWD1
M=1yIv:
InternetReadFile
n?e1h!
Qu(u<e#
9=5/ye
K8ya%G>y
4k*Ejj
|Q67"#6b
&`H_9/
Kqi(L4[t
Hr Ma8.
Z%g@|B
A;)MgY
()Uq|
QIM<T>
$=V8~/4+
M|,Z>55I
m1#{"1wT
?NV$eEt
r7zT&IF
}Lns5N
^#p#rSt
c*s+c0
bcySzc
s)s:cSSTsx
AsCscc
JcQSRsWsZ
gcvsz#
c"C#3%S'
)c-#.c334#6
7c<#=cH3IsXsecr
.#0s1s2c4s=
UcY3^s`
qCrSsct
xcyS~C
kcmcoCp
\S]3^3_
&s's(C)
1#2333539
#c$#%c&
M#NsN#P
RcRCT3U
]3^C`CaSc
vSxsy3z
VcY3[3]
#'C*#,
;S<C?CA
%S&S'c(S,C2
-C335c7
yC{c|s
C#DCEcF
L#MCN3R
r#scucx
JCUS\sbcj
/s1C2C5
Ss!3-
-3.S5#9
8s9C:#>
s"s&3)S+SH
$3%S&s'
JsLCVcY
X@!yG
j3K8Z4<
\_RIlX%
:Cg $Y
bR0^\x@|E
x#GZkZ
*&GO0mS0
:y<v(]
t6` }Y
mlg*\$
8-e+XME
aMg=au
qL{3
o2zqN@
%3?u'y
i8O@uP
J|R~SI
0e1zSB
@38w%C
AW14$D2
p&D[[MA
VxDG/e
B9hp+\
f=]Hf;
y|00O2
t!z'k
4O4n5b`
Q5?nUB
<0F|$M
?M+X\`8
AW14$I
yybt}
fu6(^=$=(^}
GO//y@
h-k`ZH6
%!w0y1
*nz>|w
t]c4jGp
v}Dx+O
D+S=.G
GetCurrentThread
RegSetValueExA
|ZZ-m
scgpNt
t{4<nH
mWGO7|
kP){qmu9*
GetProcessAffinityMask
5;p_Ww
&6%o]d
QEh%VP
rPofmnQ
>_D1,$A
s1/y<I
GetConsoleMode
!^~8/
>,[^=
?nZ^%x
Z69`w#kw_
sf&oj!
X9kGMu
tQW]lbLT
w"tsHmN
j0^*mb
RsH\>i
8<6.yd
\&.sg/
f=wqf;
we~B%^
VBDKcT
[Kap0%9
85My?d
,Q.(c7
RT9y*H
p/rjo3
_+(zV|Z
.+,anD",
1EH.{%j
?%<lxb
)`!#]tA
mF<v@NxJ
,i->U)?
bn}`GC
:HVNCz@
gWX _v
O1GjjW
`<6d}P
l!QH'Z
q5@HnGY
.@yJws
)(l$*n1
_Sx>-U#
<mjx+W
sBqY6A
(# c.s
zh85n^N
xCEnv,
?=&|+T
Xd:`=X
y\GgKK`4
lP$V,a
JGks$,]w
bShGC>}
<sm^bt
y^{R!CM
}Z e+
5ClDb@5
IsValidLocale
HI#&<*[
fFb*t2/
Ia\cyf+
`H,%g?
PKc/@=,
?nck\-
Y6@Q&!
gpwRnH
P:sCY/
dqY!GKe
l@9kWOF
dFL3g~
?0}Z}J<B
51s1yY
3=[c;0
whu#`%k
@y,bL`
k7>x~I,
?Md1lFEmqU
e8|$:D
*{9yux
;|2(O8
\/r"\c
ROD39g<W
lGp~=#
*K:/f;
7=re<L!:
$Usjzj
7NY_+~O
^,u[{t
$Ght?.
WD:!*:
vRWi1
?G0U^W
`>L|q^(R
p5dv6{`
W3lYRX
xR1Kop[qZ
2y<j:7y
/NbJ^4
b+EeF`C
NT)bre
dj\_vX
>0^{fZ
SetEndOfFile
H0C[_a
3/=7B{SL2
vsV,$j
:Xi$60Xg6n
Jy~U+d
GetModuleHandleA
IsProcessorFeaturePresent
D7@85(g
?vq0*P>
!A]N?!
(<NqRi
r g#%:
IlQ<y5
}|ZD`M
GetACP
S6NZ(W
\!iO#8
Ke^@X8\+Lg
?Zu+lq
77w5n
5<zZ^!
jT-I9(
y6D:y
U|a<;dL
bfY,Q+
H_Do_><
n{3pD3
~wHh#C];
Z_{[=Q
x*=(y&
#pI16z*
yp,~B8h,
f1,6 +
G?Ob9O
u6-24
4A|p[:
[)W*WVH
-lzZhd
uQ_is:
Pz/)2"@
40lj,iF-
i_EW+G
o7iDUQ
(,wG`I3w
heX?>Y9)
swu|?x
x%K7H"<
NIRF~N%
@5lL"J
InterlockedIncrement
CreateFileW
TqT.D:
!E@ugq
VuAWLc
*h&~~?
j^k*Hl
Qb'tE:
PTN7yT
:{R:1g
QX \PolS
8T &Y*
F=v#{$
AWD1$$A_
I"&)PD
X)B6<g
/Ske,U
!c^F_
5<s?!m
N*;e*{
n.)yil
FD1$$A_Mc
6E</~]
WM=[c,
cD$y={t!y
Ifr5.#
H$yh.x!y
:,B/q@
Xd8lx)
*oFlOv
T^2M[z.~
+qGZD3
e:yR'E
lh"?y0R
t#~mL!7
N0_>sS5
53vn?O&C
t5yGpX
GetStdHandle
-=["9"ot
lUjYu/
2>yzU5
iSu:)1
g3!yk$4
kcghR'O
rAWkBF
,ZU(+-
AWD1$$D
>C=nTP
.\D;6j
'[$SMRl
H?I%.x<
S@6Ss>
w5BVoHn
`@iPXE^
G]_g}@
M*B)NL
b?v5s0
g()z]!z
S"'L,y
FreeLibrary
a3"mf;
GetModuleHandleExW
XjGC2
?j84$pha
*WOM@f=
.Coiol=Om
~'@|gq'
TLl"6w
SaBmbl
[|N6{^iE]c
`\[Kz{
-n/9~.8
o]fg$El
K1t3{!
{aF!n*
E*Wwn
eIt<\p
}BZY v
!4?A|M
:<vLwW
Cu&@_/I
GetSystemTimeAsFileTime
m0gHnq
-?(8O9R
ix@2f;
EnterCriticalSection
`l<WFc
w.X|Bee
U}1-+5s
TlsAlloc
GU]B5@
]B;'Ys
14NA>x
T\3P/
<vAWD1$$A_
n)xKSH
lS@$b0
$A&vIU
JZQE:,
@2HPQ\
SATdL\
AWD1,$A
HWAWfA
14$A_@
+5}nu-
_x?&z
[}by]%
\"#*ZF
T8#Fb
~$#%6
=t5Xl}
jt0gZsG
#X`,>`
8}e|uS
,e(*}k
&@s%e{D$a
g]&DSe
yw4y)[
S-X*/y^
T8yr$d=y
b>8:a
AWD1$$A_
E[(bzv7
&9yok
r6uNLh
%Br^-^
4&!Ym_
pdU<y$
"VWTK<B2
c3hfjJu
y`O`>y
I]#y6C
U7pw:9
GetModuleHandleW
h3vX4
$[."uR
xZ:m)S
6&#)1Q
E72lu0E
^_onnX
/Z?R]H
`g@9kNtWS
yVTati
9-73y}
=@Qk(
WZ\@m`
?a97~I
InitializeCriticalSectionEx
GlobalAlloc
UIQxRJ
p%=y|3"
D1$$A_
!F".!L
m-f''.
H^\p[#^
D>jawS%
e-cO]}z
DPm"y R
D>6ads
h2fnu|
ge^jV-"
TQ->'
}%mdK+vS$
K_S}1Jt
0r#m]Q
k@`D+^
)Er$,
Jj-TDh
mNkK,!
3.0&VdxX
5%xff(\
siH(Cn?
/h\go+
InmGd*>h]F
1<$A_Hc
Pk78f<O
6{5M|
|e:T,4
.7zVcs
nka+"r
qPJl.D
N#*`@M
3.%vkdl
Am1NQ-
]s0)Zg:E
LGoe~Z_
(M;u%j
{%txxQZ
L.LTB.^HT
V%5J@L>
/uIOmk
s9,KR
?][xe<
3`vbi
eJu%b=
Id^:yc)
~=-hgSZ
+mm2t0cQ
<8k5y@"
X*a"?g&RR
YfgP&'i
/i,5b&
2m5yz8
7Tey~n
GlobalUnlock
?ZA_t*
645{D,
DUVl;d9
<Q1^"l
AL@p~w
z.=H#T
n6gjMbf+
htWna]
gAL`}yw
oQ1(z1
`s3P.
XV-10g
U+&B.R
-A"Fut
I}(BU#
=G~ROO
<N8:zu
#=|oWK
8jU79N
VFx@`s
fX5OTA?
]b+>J2
#3EnB'
9iR,5CQ
TuO/?n
pg"GOWT
5PP,<a
x#r],TQ
Xc$zq(&
dR7i9R
(3D+(w
:.P'|_
>8l@n%
K48bL!
{<P!mxP
Qj]O^(
}XJe`P
eBIibV
q_;jcE
nt%Nt$
SRWC.y
i-Ag<1
}%BuCf
Jqwv|I
Ff5y)\
7Izyc- m
jS1y<jc4y
M+&i D6
.iO{C.
`W)AVq
"-&5ClDb
-@g n!
Ty8 !4q
#HV)gp
AW14$fA
GetStartupInfoW
X|kig(
DLc/}7
hBEbc]
t$2,kU8
UnhandledExceptionFilter
Puh|`r
6>S5yI
6;YpH}F^EK
n?IuT'
w+I%8k
CXhSu*
D1$$A_;
B[DY8(
FS5s|~
GetClipboardData
19(cZZ
vp1rB~yq_
AsuMf4
!B^BEUd
_,&2J%
4csASxO
kF$V[AS
{/h$*&
'.|kv'
FB`%vE
+)h1,^
]*='m-J
p.yT@)
Jn ),eo
q)Rgo#W<\
KENEpogX
pfK</L
J=U@g)x
OqYIbG
"{W"C
ML+0JHIq
OR.i/{
oQ^w\hi
s7_vEWEx
OfMjlw
z3z~nm
zwmCe*
oig=l=
InitializeCriticalSectionAndSpinCount
6O3ofA
CBX_a
<%RA?;y
F=v%H/
E~!y7=
(?')Z_
kQ3$sI
r9*y-X
H"yz5y>y
0UsF(4R^
P}Iz,'%
ew6Nu9
lKk3\7
yp\5A2
'Ok+'M
5 pXE~
o>3RTd
A?g/THGn
g%T9W"#
QIMHaN:
rv(*y.L
oRNis\
'g8Hq5
S7Rq1y
?#y:u8
1cp7%]
<\"^2'
H:"aG>
qz&5C(
j0[>{Xy0
oiyI"+;J
XqjrU-}U
{`g{Uh
2*.S{'
;$W3[%@
e4y b
~b;9K=
~'>]q??>
YJ?ppb
<*_Qg!
]7L>,2hI#
BbV6fn
<C>#"&
Z$9UzJ{
VbTP,|V
ep?*R~$
~_UWug~
_bEJ%gXXT
JFnSlp
t=]9Ez
^%Q5^@
$&XpV0
Cm4l!E
VGTH~;
*dmM~\:
&%Wa{(
FD1$$A
t\>{T_(
{&S1se
J3P"MD
NK'~LP
cOclSH
/';Q~.
x'>nH I
=~{n';
]K(bb2p
2e_[i"b
ZvZA"(!
'M{T=$
D,9>E[
]+F,f5
_7A=5A
_{G121C_
:Bby?_
H{%i29
{KdJ")
iq2m3Y
I~KN^<
B2X.f;
5-%^jh=
5#ehBh
6e$/5V
yE{G@t
dNN)5M
$z)PyB
/'g"y0
!qE )!
xJm(}2a
EnumResourceTypesW
Lu;]% IN?l
Tv&-hV&
,w3-^w
?LM|:Xl
3ON>QYFN
@ek:aS
y1yO[@
FDq4-D
]qvXQ><
~T;'-2x
W66`@T]
U&Tu2?/T-
e1$_67'
EQT/qN
JwGD6A
O^=hZ:
Q"ys\V
#yhe}C
g%@<|E
8\N_w'o
yH:I<ye
dd%It0
dd%IO)
_S0*c2
RAo^&E
d0$n$t
n(*yr]/
RV=y~qQ
<^w6py
WR;o9]
}M\+z:
ts&_H=
t4o?^2
bv`j=#
A6iCdpJ5#
vu&YAWI
~]-8YC2
<:ni]^
eZ3L69
S"14$fE
fGei'Z
qOv}>-
A}>OJ
NVul$2
r'W(+u|
k(-lK_
tPx*_sD
M-|sui
-B^/n{
1H=wiD
%|C"E`Y
.C-p~\hP(
6An4gMI
#V7sF
l<tvb@r}
/EZ>l4
R}vBX!)
=+%L6t
d~`2T=A^
5%)4vk
3..(y@C
=*7LB(\
z>[&e*
GrF]2,5
lDuuyt1
]G\yG~
u]O0Cz
H{Wy+F
#L%=T$S
mKz;{/v
1-ZO<ye/k
A[XAYIc
f-29f5
&/l/fv
W~rWad
[l_qj,
&;LLW1
Pe.?iZ
i>ib7=)
e/ko"8n
Rnztbt
=d-I#%
H5?$Ue
.VM4yY
agGKoSJ
>/0IMlf
"$qD_\
03_o2<e
i,|/W2%
qpBu{u
*s$k1o
l^3jUX
LcU8Bo
tsQ+M%I
[)!V.'
^Uw^q
$I%$MEy
A &mHV
sEJ1Z.
>O5Z)[
m.r-4;
YTd_l&
?pIF'p
0c5 L&
O:8e9f
:UK\?.
)!*c1/v
v~lTTmEx
u[ybg6
+w)bMB
H#|S*2
5t$4S^J
M05)Iky
@XN~u-
l$#yfC
SetProcessAffinityMask
j&9nRWA
D&laux
J*L?_I
tY2y!%`
6u"y+q
`'%y%!
X**f|R+
XkLK+n
&v^p`k
;`['~+P0
,is$yIC!y
i0SsY7$
]^M3Z)
D1,$fA
+&yc.H
rF]2#M
VE@c/e
i/?y>[
nX#rZf
/NP0|S
8d6yO*
Tnbm;W
b+y-G3
q/D#&7j
^41OPR
GetStringTypeW
q.^NA))
CSp+D$
GBG?wE0
H9{66K
pDb'fI
fv?,'3+}
g3QwxN
(qP!('E+=
yaj]E3
5e-3CNi
K@=cu)
tky%yv
D1,$A_H
<^/BMc
l_ldNZ
GKky*N
GetProcAddress
<X&b-?
2B+RB?
CompareStringW
;)A_Hc
[9B7\N
v^i~FY
:61Ck?
m64|]1C
ePrl~a
5Uw@r~ov.
kmo[jV
sWX ob
.\-[~.
Fh=G!X
+:frt8
pZbWS<,Y-].j
LoadLibraryW
I!(a|
AWD1,$A_
6FZ,5 ;
taa2IG
|J%lPm
}|3I2/
R6o6QH5
ph;qfT.xq%f:T
,Yk)v,
TlsGetValue
B[IV_[.Ei
A{i6P(
1?g]~6
?T"xx!5
L*Y`uR
{cL:u(
nKa_Ui'?
+[JT)E
~mg2fH
{LW3j
h1kznJ
p.{\d%
paDNm."*
C{' 3O
S8`wL8
|1TZJne
=*r"h
5"NKZ5
v[9MD`
'\00RFf_+D
`E7GXW
N{|Gfv
(_>DQJ
_D8t.x
r(s#zB
BiCF[zH
|jRJswI
5QID'W
db^57\
5afPD|
S!A@}ju@
Zi=2 5
5LoBuO
sldwq6
nTf1s[u
7>O<:#
VK:P@Z
,)_jlK9H
,Ki5LC
m4+W&a
y6;D<;
O.S:W#7'Doh^
ng/5 &
heX[Go
7<.MiP|
LA=4xm
d|JEG$-
kDPiBD
GnR_0c`
Ma}!,|
XW'EH2
9u{}oel
kxHL)v
OcFfE;
LCMapStringEx
_zTi@O1
EnumResourceNamesA
LeaveCriticalSection
#B+)q
5*A58/T
4{#.BXG=L
%iI&Q
*V:<`If_
-aax3S
?u]=~Ta
M=zNpyY
\/{mt-A
`VcM2KO
N`,W.x
Og7G}
LoadLibraryA
<HeQ"sbmY
qNYg*1p
\dV6yK
bjiML3
j}JsH
e6L{bM
7@Zv]i
$4?}@m
^uKUA2I
}0+*L^
BA<bYY6
AW14$I
9=I@h4
PAA4W6
=FkEbf;
nBBTFk
'uxr4I
c&Ta+9T`=3
)()1A
6Z~&#7n.=
InternetCloseHandle
55vb_@
,fY_uM4
7>#MF@
]f'imaP
g3&1`D
nuy:~4
' Nxs^
@Q5Zm}
~8#[26
0'4PzC
GetProcAddress
1.M|4[Lc
jJMk]y
=r:ipH
DKXO>X
n&iNmSA
Zwm&0cy
iGkLO|
cQA D|Q<
' -3-y
LkzkX.
a@l(Rx
8IK3N{
GcR)H]KL
:TXpej
<XA\s6
\<o?igu
Q-3Wypx
@!nnbq
]^[-F{
Y,A-2m
&0YII)
{a!W+o"b
3Fi~sLi
whF;yvV-
NCw"&H
bD1$$fA
z0#y?;
c0ed>?
yW>)QS
ck/*87
5|0tCe
"y v;'yjE<
u7#q5Id
5X@kZv
GiHyk*X
n&M"%SA
H]<'8
MJu9SAY&
-n n*LBy
83.yH:
,*g2\:<
h{~OfH
OWi+
f;nM06
N,*$RM
I}T~;(
TlG3|
2sJd:i
yQmE.Q
 n~r{U)
~PO&sAt
+=(_>u
>b)9`d
%wRr>K
qQn:dsm
;Di<YM
IFFKqo
!&.D-!
RO?o].
dlp.yC
*!Cu?:
&71[(%Y
#i& ,7f
')BuYR
|q'$m@
+8D+9R
P$?OQoC
6ktF~ee
W5Qi1$
GetModuleHandleA
Oy6%Zx
A:KZ~KgG
KKc0=
qyB$|#
EO']Cc`y
#@[qn-
PeSB~j
UD tBF
9kW(~aYB
MNW+N.
SetLastError
s[+?4UgB
5 w13F
'=xf*G
|0y(0Od
|)FS #
NW[Yj[
6HFWgA
%NV;"9
aHChQO4
GlobalLock
7`&yXU
_NN7F\
uCw,cM
&`'yfe[
(4h"""
x0*0H7]
hYfB9P
U4nCe3
N\3A~[D
cXw2S_
r(Lqq1
QS^4%c
?IaY8|
(g`|v"
Mh?^}E
M5s~OM@
:shb*`
A(4EaT{Bx=
UBrx
ewORg%
M*.yq^-
d<yo)T9y
1\-E6i
g3+=aO
pgyqPF
Gg?#O\
ReadConsoleW
)^{!AWD
yLM9~;
B9|8qI9|
a|poOl
`9\+Z\
t/<`Mo
j`+;%
J5!5'8
Z[p7NTw
-ZtJlG
_'K2uQ
HzjW|A
D1,$A_f
_lM}L,9
8p*57m
Di'Lp2HS2
&f@5s\M
U:^#E.t
n$&8|i
W53xKw*
YY "?D
ZRf/y5(
nu]?Q$
`4IN|)
j*2Vhg
1lIz;$
yXe+Xu
Qdq"x.&kro
'`O`B^
<<wBM
^B!u+M
omME^%f
IO?ONt
q'!psp
$VywTV>8
&Jg1+@
~N$s3k
*pF|NY
ws"'JL
wP2z`A
GetLocaleInfoW
D1$$A_@
AW1<$A_Hc
3G^ZC)
r9b8q,e
DeviceIoControl
sm'K
AWVAV@
A_f=];Hc
(5xguS9
;xZdqd
WideCharToMultiByte
}a`?EF
u(HigQH*w#
0kCp&U
n(G`YF
/xG(p?a
1ifB1~a,
5-$V<*
LL*PS{
V-1Of*F
k@9N:I
{)u<K.
`A(>PF_
MElM}B
vziIE}
Ji[_P2K
m!P&]&'
[MIWkJ>
q[%y>K
y7E%2yr
gvhdV
Sj'7y9
3yHU;S
"FBv:8.H
Q_ su
p5)Y@y
n=xi%U
d6"C{9R
]#u{jB
j~zm q%j
b@$y2}q8y
y=2y&y
~rL\#t
)z,cY^
0i ny`!
H#C>'1
YmwK1R
P$aeeh~
!@6yd`y
+R!ykT
S{#{c|T
z74?}@
]l8+jI
h.t*X)
xG8X)N
E*0Yu-G
^Bm[nE
sF)(CA^
/G=g@J
FreeEnvironmentStringsW
";ZK3|
wy^v^f;
yK)2;yN
9jZ_.<
Ua<J1>
~1V16D<
&B-!pV
/$|`@
%M(yK-}-y
,Y3?y'a
xv-y\cq
i6a>RJjT
S:fKlN
lV\,k!
^A_A]fD
]AZ[A\
NAW,[
si4BF1J
fuK^,/
WC+Ot[|
~.#P6 e
vl-)vK|y
Z%.!q~
fifRS*
IW.eyr
*;~^LpbJ/
MlxfR!P
H`{zV'
squM#
1h|%$U
)<TMcuN
k<Tr*7
T YE2>)Y
2 7$~N
D1,$A_
(-V?2K
m^6q1\>F
bkKw>hpn
#i \zy/
cM=Sh>
F4A>dk
{/vk/h
B}raw(
xIE{$x
ALVfMz=
Fd}qz;
/oMW:2
.S\@z*Sq
T:v6u?.
,2O[Tc
o3z([n
<TTv!<
nE"SG(
)]9Ci)_d
D1,$fA
ULO:np,
h*.DEq
l&\[7QA
InitializeSListHead
CLQ+p\Q
A]A[fE3
bQ*H<!
,:R[3-\^
7gjE0u
;$k3 \
@5lL"Jf
AW14$fD
O*E[RU
?x%7H&
#;c:we
*b5D2T
@#v#%#tF
-yOR3M
IsValidCodePage
dRQ{YKbW
/t?$7a4
5?$Uef
\h|5$h
`NC<=@
ResumeThread
iA4%$[~
ejj7y_
k?<p@N<<yW
p\-~\.p
GetModuleFileNameA
55KN%f
6y1g-3yc\*
G_N"}-VN
<BX~o~
eh;J(,
N$J=(<rY
0|2\au
g|7cW{@
L)gP&y
T8+DNu
t.Mbfz
Sg"t6y
D3yfIC
HYyRuD
2R{*St
zB3yNqE
2yM@nR
qWF.y`
X#Xn'g
/b+rZh
]`jd2RS
uR\(l8
79WzVA|
13gnz$
r7})"jE
~d7%z
giAk6M/
r3d0pfg*
;"-fA;
s4k}l
,aXvjx*
S.)Q`"
?._~iJ"`f
QGfVUf;
|L6$i!e
!h@+.w.
G'2:{7N
=;t6+x
AWD1$$fE
;PpnEu
LoadLibraryExW
#nj2~5s
Q:;N`
<?krVR
PDkk~PwT
LPLW[
oY`1$YK
gT-w+Y
r<-WUZ:
Ar Ry""
96Lv67
D1g 5e
##2@5PlsX5
EPA-!ZP<
Ro1KS
4vH:,QT
b]?ri)
5xW[q~
HeapAlloc
ExitProcess
B~N9B&;O
{s:w?U
%H/D"`
SuspendThread
]fBqFg
{[fLQ%z
i,#^p_
f=`/f;
r.;j,a
>60-yql
;\.):@
u[^Yv`G
Y6!&;^
or1~2"
>k>Xob
ik;gYlL
55KN%:
9'T,h.
e&@c4/
J\-4M+
XKHbhL?
5AW14$I
^cl<#F.
D1,$A_A
)~=yI;
?H05-<;
D1$$A_Mc
AW1<$E
?&<y3|!
sy_[J
fROAWfA
Process32NextW
o;(Xow&
N(f`I
f50l/&
qf<Fy)!
TlsGetValue
CN'Z"QNOV
oNJ|'f
%juroB
Bn,2oh/
IzuXxP
GcBh(HP
>AX{An
d5:-W!yeY^
2/*y*U
? $8y]I
e@*yIX_
q0T[Iw
) }4]Z3Nh
i.y6
c.[]P#
?:rC0X
y-_O"y
i8t3l:
K1:]w8
$v].@_
1<$A_fE;
TzI/$g
wwZlOO4
+O7/W(ob
yI;h"y
D1,$A_Mc
~;Q&yE
~*ZBz#
SHELL32.dll
Exm/}Hj>l
bBY*)
3MDmTQ/&
eX_VVb"!
nDnViD
Xv\4\/
OG~"y0
)(;/?4
uSS9S4U
c4 *w{
v)> &K
E_FRqXY
^D+&HmZ
3?1=_-'/
p9yUf
uSNql|S
3AKDxb
*y09O:y
zYf(6$
}[mU;~
`AupC'l
rAupCo
>DCPfN
{G`_7?U
Antivirus Signature
Bkav W32.AIDetectNet.01
Lionic Clean
tehtris Clean
MicroWorld-eScan Clean
ClamAV Clean
CMC Clean
CAT-QuickHeal Clean
ALYac Clean
Malwarebytes Malware.Heuristic.1003
Zillya Clean
Sangfor Trojan.Win32.Save.a
CrowdStrike win/malicious_confidence_90% (W)
BitDefender Clean
K7GW Clean
K7AntiVirus Clean
Baidu Clean
VirIT Clean
Cyren Clean
Symantec ML.Attribute.HighConfidence
Elastic malicious (high confidence)
ESET-NOD32 a variant of Win32/Packed.VMProtect.AHG
APEX Malicious
Paloalto Clean
Cynet Malicious (score: 100)
Kaspersky Clean
Alibaba Clean
NANO-Antivirus Clean
ViRobot Clean
Rising Trojan.Generic@AI.100 (RDML:fD7xnyp691p8Vr4OIQrX6A)
TACHYON Clean
Emsisoft Clean
F-Secure Clean
DrWeb Clean
VIPRE Clean
TrendMicro Clean
McAfee-GW-Edition BehavesLike.Win32.Generic.wc
Trapmine Clean
FireEye Generic.mg.f5d957a42f578847
Sophos Generic ML PUA (PUA)
Ikarus Clean
GData Clean
Jiangmin Clean
Webroot W32.Trojan.Gen
Avira Clean
Antiy-AVL Clean
Gridinsoft Clean
Xcitium Clean
Arcabit Clean
SUPERAntiSpyware Clean
ZoneAlarm Clean
Microsoft Trojan:Win32/Sabsik.FL.B!ml
Google Clean
AhnLab-V3 Clean
Acronis Clean
McAfee Clean
MAX Clean
VBA32 Clean
Cylance Clean
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Tencent Clean
Yandex Clean
SentinelOne Static AI - Suspicious PE
MaxSecure Trojan.Malware.300983.susgen
Fortinet Clean
BitDefenderTheta Gen:NN.ZexaF.36344.@J0@aa@hO@hi
AVG Win32:Trojan-gen
Avast Win32:Trojan-gen
No IRMA results available.