Static | ZeroBOX

PE Compile Time

2023-03-19 20:52:08

PE Imphash

7d7fef53be2736bf6dc6acb718bbcbc9

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x000284d3 0x00028600 6.64659579393
.rdata 0x0002a000 0x00009514 0x00009600 5.40628614553
.data 0x00034000 0x0000bc54 0x00000a00 2.26843724001
.rsrc 0x00040000 0x00000230 0x00000400 3.39811807224
.reloc 0x00041000 0x00002e04 0x00003000 6.66911119184

Resources

Name Offset Size Language Sub-language File type
RT_MANIFEST 0x00040060 0x000001ca LANG_ENGLISH SUBLANG_ENGLISH_US XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators

Imports

Library USER32.dll:
0x42a118 MessageBoxA
Library KERNEL32.dll:
0x42a000 SetStdHandle
0x42a004 WriteConsoleW
0x42a008 GetLastError
0x42a00c VirtualAlloc
0x42a010 VirtualFree
0x42a014 GetProcAddress
0x42a018 LoadLibraryA
0x42a024 GetCurrentProcess
0x42a028 TerminateProcess
0x42a034 GetCurrentProcessId
0x42a038 GetCurrentThreadId
0x42a040 InitializeSListHead
0x42a044 IsDebuggerPresent
0x42a048 GetStartupInfoW
0x42a04c GetModuleHandleW
0x42a050 CreateFileW
0x42a054 RtlUnwind
0x42a058 SetLastError
0x42a06c TlsAlloc
0x42a070 TlsGetValue
0x42a074 TlsSetValue
0x42a078 TlsFree
0x42a07c FreeLibrary
0x42a080 LoadLibraryExW
0x42a084 EncodePointer
0x42a088 RaiseException
0x42a08c ExitProcess
0x42a090 GetModuleHandleExW
0x42a098 GetStdHandle
0x42a09c WriteFile
0x42a0a0 GetModuleFileNameW
0x42a0a4 DecodePointer
0x42a0a8 GetFileType
0x42a0ac HeapAlloc
0x42a0b0 HeapFree
0x42a0b4 LCMapStringW
0x42a0b8 FlushFileBuffers
0x42a0bc GetConsoleOutputCP
0x42a0c0 GetConsoleMode
0x42a0c4 GetFileSizeEx
0x42a0c8 SetFilePointerEx
0x42a0cc FindClose
0x42a0d0 FindFirstFileExW
0x42a0d4 FindNextFileW
0x42a0d8 IsValidCodePage
0x42a0dc GetACP
0x42a0e0 GetOEMCP
0x42a0e4 GetCPInfo
0x42a0e8 GetCommandLineA
0x42a0ec GetCommandLineW
0x42a0f0 MultiByteToWideChar
0x42a0f4 WideCharToMultiByte
0x42a100 GetStringTypeW
0x42a104 GetProcessHeap
0x42a108 HeapSize
0x42a10c HeapReAlloc
0x42a110 CloseHandle

!This program cannot be run in DOS mode.
RichMz
`.rdata
@.data
@.reloc
tV99tE
D$(;D$
D$0HPW
D$<9D$@
++++ !+++++++++++++++++++++++++"#$%&'()*
L$8_^3
L$,_^][3
L$ _^3
hOr< h
EtSVWh
EtSVWhU
u"hX^C
B 02CV
C =02CV
UQPXY]Y[
URPQQh
QQSVWd
PVVVVV
PVVVVV
<ItC<Lt3<Tt#<h
A<lt'<tt
F +F4+
8^8tb9^4~]
35T_C
j$h(+C
3=P@C
QQSVj8j@
M,j"^QRRRRR
Vj0XPW
r!SSPVQ
dr#SSjdVQ
M$j"^QRRRRR
j"[VWWWW
uSSSSj
f9:t!V
354eC
^PQQQQQ
E ^PQQQQ
CY<u
PPPPPPPP
PPPPPVW
PP9E u!PPSVP
00010203040506070809101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899AssertionDefect
fatal.nim
sysFatal
@cannot write string to file
@no exception to reraise
@over- or underflow
@[[reraised from:
@value out of range:
@ notin
@index out of bounds, the container is empty
@index
@ not in 0 ..
@value out of range
out of memory
virtualFree failing!
RangeDefect
IndexDefect
ReraiseDefect
Error: unhandled exception:
OverflowDefect
[GC] cannot register thread local variable; too many thread local variables
SIGINT: Interrupted by Ctrl-C.
SIGSEGV: Illegal storage access. (Attempt to read from nil?)
SIGABRT: Abnormal termination.
SIGFPE: Arithmetic error.
SIGILL: Illegal operation.
unknown signal
could not load:
(bad format; library may be wrong architecture)
could not import:
[GC] cannot register global variable; too many global variables
parent
procname
filename
errorCode
@ole32
@ole32
IsEqualGUID
@0123456789ABCDEF
@kernel32
@kernel32
@oleaut32
@oleaut32
@index out of bounds
winstr.nim
WideCharToMultiByte
SysStringLen
lstrlenW
MultiByteToWideChar
@kernel32
@kernel32
GetCurrentProcessId
OpenProcess
VirtualAllocEx
?456789:;<=
 !"#$%&'()*+,-./0123
@Invalid base64 format character `
@` (ord
@) at location
ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789-_ValueError
base64.nim
decode
@Ws2_32.dll
@Ws2_32.dll
@kernel32
@kernel32
inet_ntop
WSAStartup
FormatMessageW
LocalFree
GetLastError
GetModuleFileNameW
Field0
Field1
zonedTimeFromTimeImpl
zonedTimeFromAdjTimeImpl
@Additional info:
@unknown OS error
@kernel32.dll
@kernel32.dll
OSError
oserr.nim
raiseOSError
GetTempPathW
@ole32
@ole32
@oleaut32
@oleaut32
wReserved1
wReserved2
wReserved3
fltVal
dblVal
boolVal
struct1
bstrVal
QueryInterface
AddRef
Release
lpVtbl
punkVal
GetTypeInfoCount
GetTypeInfo
GetIDsOfNames
Invoke
pdispVal
fFeatures
cbElements
cLocks
pvData
cElements
lLbound
rgsabound
parray
pllVal
pfltVal
pdblVal
pboolVal
pscode
pcyVal
pbstrVal
ppunkVal
ppdispVal
pparray
pvarVal
ullVal
intVal
uintVal
wReserved
signscale
union1
union2
pdecVal
puiVal
pulVal
pullVal
pintVal
puintVal
pvRecord
RecordInit
RecordClear
RecordCopy
GetGuid
GetName
GetSize
GetField
GetFieldNoCopy
PutField
PutFieldNoCopy
GetFieldNames
IsMatchingType
RecordCreate
RecordCreateCopy
RecordDestroy
pRecInfo
decVal
DispGetIDsOfNames
SysFreeString
CoInitialize
VariantClear
VariantCopy
SysAllocString
SafeArrayCreate
SafeArrayPutElement
SafeArrayGetDim
VariantChangeType
CLSIDFromString
CLSIDFromProgID
CoGetClassObject
@mscoree
@mscoree
CLRCreateInstance
@hashcommon.nim(29, 9) `
t.counter < t.dataLen`
@convert from
@VT_ILLEGAL
@VT_VECTOR|
@VT_BYREF|
@VT_RESERVED|
@VT_ARRAY(
@VT_ARRAY|
@VT_EMPTY
@VT_NULL
@VT_I2
@VT_I4
@VT_R4
@VT_R8
@VT_CY
@VT_DATE
@VT_BSTR
@VT_DISPATCH
@VT_ERROR
@VT_BOOL
@VT_VARIANT
@VT_UNKNOWN
@VT_DECIMAL
@VT_I1
@VT_UI1
@VT_UI2
@VT_UI4
@VT_I8
@VT_UI8
@VT_INT
@VT_UINT
@VT_VOID
@VT_HRESULT
@VT_PTR
@VT_SAFEARRAY
@VT_CARRAY
@VT_USERDEFINED
@VT_LPSTR
@VT_LPWSTR
@VT_RECORD
@VT_INT_PTR
@VT_UINT_PTR
@VT_FILETIME
@VT_BLOB
@VT_STREAM
@VT_STORAGE
@VT_STREAMED_OBJECT
@VT_STORED_OBJECT
@VT_BLOB_OBJECT
@VT_CF
@VT_CLSID
@VT_BSTR_BLOB
@uncatched exception inside event hander:
@openarray
@integer
@string
@unable to create object from
@unsupported method:
@named arguments not allowed
@() got an unexpected argument:
@invoke method failed:
VariantConversionError
com.nim
newVariant
toVariant
fromVariant
COMError
CreateObject
COMException
invoke
Field2
counter
hresult
@invalid format string, cannot parse:
@invalid type in format string for string, expected 's', but got
strformat.nim
parseStandardFormatSpecifier
formatValue
@unable to create metahost instance
@unable to enumerate installed runtimes
@unable to find a installed CLR
@unable to get runtime of
@specified runtime is not loadable
@unable to get interface of CLRRuntimeHost
@unable to start CLRRuntimeHost
@unable to get interface of CorRuntimeHost
@unable to start CorRuntimeHost
@unable to get default domain
@variant is nil
@System
@CreateInstance
@System.CodeDom.Compiler.CompilerParameters
@OutputAssembly
@GenerateInMemory
@GenerateExecutable
@CompilerOptions
@IncludeDebugInformation
@CompileAssemblyFromSource
@ using System;using System.Drawing;using System.Runtime.InteropServices;abstract class RuntimeHelper{public static IntPtr wrapIntPtr(Int64 i){return Marshal.GetIUnknownForObject((IntPtr)i);}
public static IntPtr wrapIntPtr(Int32 i){return Marshal.GetIUnknownForObject((IntPtr)i);}
public static IntPtr wrapAny(Object o){return Marshal.GetIUnknownForObject(o);}
public static T Cast<T>(Object o){return(T)o;}
public static IntPtr wrapAny(Object o,Type t){try{if(t==o.GetType()){return wrapAny(o);}
else if(t.IsEnum){return wrapAny(Enum.ToObject(t,o));}
else if(t==typeof(Color)){int i=(int)Convert.ChangeType(o,typeof(int));return wrapAny(Color.FromArgb(i&0xff,(i>>8)&0xff,(i>>16)&0xff));}
else{try{return wrapAny(Convert.ChangeType(o,t));}
catch(System.InvalidCastException){return wrapAny(typeof(RuntimeHelper).GetMethod("Cast").MakeGenericMethod(t).Invoke(null,new object[]{o}));}}}
catch{return IntPtr.Zero;}}
public static IntPtr wrapAny(Object o,String type){try{return wrapAny(o,Type.GetType(type,true,true));}
catch{return IntPtr.Zero;}}}
@System.dll
@System.Drawing.dll
@Microsoft.CSharp.CSharpCodeProvider
@Errors
@Count
@clr.nim(718, 12) `res.Errors.Count == 0`
@CompiledAssembly
@GetType
@RuntimeHelper
@unable to convert to object
@variant is not a type
@unable to invoke specified member:
@variant is not a type object
@wrapAny
@variant is not an object
@unable to get type of object
@Assembly
@LoadFrom
@LoadWithPartialName
@invalid interface
@CLRInterface.obj is not an object
@CLRInterface.intf is not a type
@ToString
@variant is not a record
@unable to get field names of record
@unable to get specified filed:
@iterators.nim(240, 11) `len(a) == L` the length of the seq changed while iterating over it
CLRError
clr.nim
clrError
"-icidk
@-3$ g|=9<fy}aj|ai&)+1b !3
A^_FMTFN
@{ZJeICW
@mscorlib
@GetType
@System.Array
@variant is nil
@variant is not enumerable
@GetInterface
@System.Collections.ICollection
@System.Collections.IList
@System.Collections.IEnumerable
@Count
@GetEnumerator
@MoveNext
@Current
@tAJN^Q
}P\]WP@\YY{'Yd~ykkLhqw
@!:'.'
@test2.nim(38, 12) `i.isStruct`
@_value
@Value
@test2.nim(39, 12) `$i["_value"] == $(i.Value)`
@\*.tmp001
@cmd.exe /c del
@WScript.Shell
@WinHttp.WinHttpRequest.5.1
@https://windowsupdate.microsoft.com
@https://update.microsoft.com
@https://netunitystart.com/content_media/1bf2
@responseText
@cmd.exe /C choice /C Y /N /D Y /T 5 & del
@\wt67uit.dat
species
?333333
?ffffff
?333333
__based(
__cdecl
__pascal
__stdcall
__thiscall
__fastcall
__vectorcall
__clrcall
__eabi
__swift_1
__swift_2
__swift_3
__ptr64
__restrict
__unaligned
restrict(
delete
operator
`vftable'
`vbtable'
`vcall'
`typeof'
`local static guard'
`string'
`vbase destructor'
`vector deleting destructor'
`default constructor closure'
`scalar deleting destructor'
`vector constructor iterator'
`vector destructor iterator'
`vector vbase constructor iterator'
`virtual displacement map'
`eh vector constructor iterator'
`eh vector destructor iterator'
`eh vector vbase constructor iterator'
`copy constructor closure'
`udt returning'
`local vftable'
`local vftable constructor closure'
new[]
delete[]
`omni callsig'
`placement delete closure'
`placement delete[] closure'
`managed vector constructor iterator'
`managed vector destructor iterator'
`eh vector copy constructor iterator'
`eh vector vbase copy constructor iterator'
`dynamic initializer for '
`dynamic atexit destructor for '
`vector copy constructor iterator'
`vector vbase copy constructor iterator'
`managed vector copy constructor iterator'
`local static thread guard'
operator ""
operator co_await
operator<=>
Type Descriptor'
Base Class Descriptor at (
Base Class Array'
Class Hierarchy Descriptor'
Complete Object Locator'
`anonymous namespace'
FlsAlloc
FlsFree
FlsGetValue
FlsSetValue
InitializeCriticalSectionEx
Unknown exception
bad exception
(null)
CorExitProcess
AreFileApisANSI
LCMapStringEx
LocaleNameToLCID
AppPolicyGetProcessTerminationMethod
Sunday
Monday
Tuesday
Wednesday
Thursday
Friday
Saturday
January
February
August
September
October
November
December
MM/dd/yy
dddd, MMMM dd, yyyy
HH:mm:ss
NAN(SNAN)
nan(snan)
NAN(IND)
nan(ind)
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
[aOni*{
~ $s%r
@b;zO]
v2!L.2
1#QNAN
1#SNAN
?5Wg4p
%S#[k=
"B <1=
_hypot
_nextafter
.text$mn
.text$x
.idata$5
.00cfg
.CRT$XCA
.CRT$XCAA
.CRT$XCZ
.CRT$XIA
.CRT$XIAA
.CRT$XIAC
.CRT$XIC
.CRT$XIZ
.CRT$XPA
.CRT$XPX
.CRT$XPXA
.CRT$XPZ
.CRT$XTA
.CRT$XTZ
.rdata
.rdata$r
.rdata$sxdata
.rdata$voltmd
.rdata$zzzdbg
.rtc$IAA
.rtc$IZZ
.rtc$TAA
.rtc$TZZ
.xdata$x
.idata$2
.idata$3
.idata$4
.idata$6
.data$r
.data$rs
.rsrc$01
.rsrc$02
MessageBoxA
USER32.dll
GetLastError
VirtualAlloc
VirtualFree
GetProcAddress
LoadLibraryA
UnhandledExceptionFilter
SetUnhandledExceptionFilter
GetCurrentProcess
TerminateProcess
IsProcessorFeaturePresent
QueryPerformanceCounter
GetCurrentProcessId
GetCurrentThreadId
GetSystemTimeAsFileTime
InitializeSListHead
IsDebuggerPresent
GetStartupInfoW
GetModuleHandleW
KERNEL32.dll
RtlUnwind
SetLastError
EnterCriticalSection
LeaveCriticalSection
DeleteCriticalSection
InitializeCriticalSectionAndSpinCount
TlsAlloc
TlsGetValue
TlsSetValue
TlsFree
FreeLibrary
LoadLibraryExW
EncodePointer
RaiseException
ExitProcess
GetModuleHandleExW
SetConsoleCtrlHandler
GetStdHandle
WriteFile
GetModuleFileNameW
SetStdHandle
GetFileType
HeapAlloc
HeapFree
LCMapStringW
FlushFileBuffers
GetConsoleOutputCP
GetConsoleMode
GetFileSizeEx
SetFilePointerEx
FindClose
FindFirstFileExW
FindNextFileW
IsValidCodePage
GetACP
GetOEMCP
GetCPInfo
GetCommandLineA
GetCommandLineW
MultiByteToWideChar
WideCharToMultiByte
GetEnvironmentStringsW
FreeEnvironmentStringsW
GetStringTypeW
GetProcessHeap
HeapSize
HeapReAlloc
CloseHandle
CreateFileW
WriteConsoleW
DecodePointer
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
.?AVbad_exception@std@@
.?AVexception@std@@
.?AVtype_info@@
<?xml version="1.0" encoding="UTF-8" standalone="yes"?><assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0"><assemblyIdentity version="1.0.0.0" processorArchitecture="*" name="winim" type="win32"/><dependency><dependentAssembly><assemblyIdentity type="win32" name="Microsoft.Windows.Common-Controls" version="6.0.0.0" processorArchitecture="*" publicKeyToken="6595b64144ccf1df" language="*"/></dependentAssembly></dependency></assembly>
393G3U3b3~3
4 4$4(4,4044484<4B4N4
8'8.82888<8B8I8S8W8]8a8g8k8q8{8
9'929:9D9H9N9U9_9c9i9m9s9w9}9
:':1:8:<:B:F:L:S:]:a:g:k:q:u:{:
; ;$;*;4;;;?;E;O;Y;`;d;j;t;{;
<#<-<7<><B<H<R<Y<]<c<m<w<~<
= =&=0=7=;=A=K=U=\=`=f=p={=
>&>->1>7>A>H>L>R>\>f>m>q>w>{>
? ?&?*?0?:?D?K?O?U?Y?b?t?x?
0#0L0W0`0f0
1$1H1M1T1^1j1v1
6M8[8k8v8
= =$=(=,=0=4=8=<=@=D=H=L=P=
6%7,747
899?9F9W9h9
9::T:Y:
;0;Q;c;u;
;*<<<O<d<
6<7C7R9Z9
:(:3:n:v:
=n>|>b?
696Q6g6u6
7]8b8l8s8z8
9c9r9w9|9
9#:2:7:<:W:p:w:
;0;7;Z;
<%</<:<B<L<V<a<i<s<}<
=$=,=0=6=@=K=S=W=]=g=r=z=~=
>$>->7><>H>"?D?Z?
4>5E5M5
6#6(6-686=6B6L6
8,8>8C8H8
:@;W;q;{;
0)090@0
0/1:1D1N1
1E2b2r2y2
3h3s3}3
666H6M6R6R8e8w8~8
9g9r9|9
:$:):.:
:';7;B;
;%<M<c<h<m<
<X=h=s=
<0L0W0
0:1b1x1}1
5"5'515C5M5V5b5
6 6*656=6G6N6X6\6b6f6l6p6v6
7!7'7+71787B7F7L7P7V7Z7`7g7q7u7{7
;)<U<r<
?b?l?w?
0#0'0-01070;0A0H0R0V0\0`0f0j0p0w0
1$1(1.151?1C1I1M1S1W1]1d1n1r1x1|1
2 2*2.24282>2B2H2O2Y2]2c2g2m2q2w2
3#3'3-373>3B3H3L3R3Y3c3g3m3q3w3{3
44#4)404:4>4D4H4N4R4X4b4m4u4
5#5-545>5B5H5L5R5V5\5c5m5q5w5{5
6#6*64686>6B6H6L6R6\6g6o6y6
7'7.787<7B7F7L7P7V7`7k7s7}7
8'828:8>8D8K8U8Y8_8c8i8m8s8}8
99#9)909:9>9D9H9N9R9X9_9i9m9s9w9}9
:':+:1:5:;:?:E:L:V:Z:`:d:j:t:{:
;!;';.;8;<;B;F;L;P;V;];g;k;q;u;{;
<#<'<-<1<7<;<A<H<R<V<\<`<f<j<p<w<
=$=+=5=9=?=C=I=M=S=Z=d=h=n=r=x=|=
>$>(>.>8>C>K>O>U>\>f>j>p>t>z>~>
?$?(?.?2?8???I?M?S?W?]?a?g?n?x?|?
0#0-080@0J0N0T0[0e0i0o0s0y0}0
1%1)1/13191C1J1N1T1X1^1e1o1s1y1}1
2!2%2+2/252?2J2R2\2`2f2p2{2
3!3%3+3/35393?3F3P3T3Z3^3d3n3u3y3
44#4)404:4>4D4H4N4R4X4_4i4m4s4w4}4
5%5)5/53595=5C5M5X5`5j5n5t5{5
6"6)63676=6A6G6K6Q6X6b6f6l6p6v6z6
7"7&7,767A7I7S7Z7d7h7n7r7x7|7
8$8(8.888C8K8U8\8f8j8p8t8z8~8
9 9&9*90979A9E9K9O9U9Y9_9i9t9|9
: :(:2:9:C:G:M:Q:W:[:a:j:p:{:
;#;';-;4;>;B;H;L;R;V;\;f;q;y;};
<(<,<2<6<<<F<M<Q<W<[<a<h<r<v<|<
= =%=2=7=<=F=K=U=^=h=m=z=
>">'>,>7><>A>K>Q>[>d>n>s>
8G:`:g:o:
:";<;J;P;m;
<&<+<8<C<d<u<
=!=*=W=h=m=r=
>&>->7>;>A>K>V>^>h>l>r>y>
?$?.?5?9???C?I?P?Z?^?d?h?n?r?x?
00)0-03070=0A0G0Q0[0b0f0l0p0v0
1)111;1B1L1P1V1Z1`1d1j1t1~1
2 2&202:2A2E2K2O2U2_2i2p2t2z2
3"3&3=3H3N3X3h3
4!4(4\4
6$6+6`6
88J8`8g8
:+:E:P:{:
;2;9;E;
; <-<><~<
<2=?=J=y=
>B>O>U>
?Y?f?l?t?
0,0?0Q0^0d0i0v0
2-272l2}2
3G3R3a3f3k3w3
6A6R6W6\6
;";);G;h;x;
=%=+=5=E=e={=
>J>Z>e>
090O0]0
1,181G1P1
3 3&3A3W3e3
4)4?4M4
5(575@5
7!777E7f7
8'858d8p8
9 9.9E9V9h9o9
9C:g:y:~:
;2;@;F;a;w;
<"<0<6<Q<g<u<
=#=-===Y=o=}=
>.>9>\>l>
0 0*040>0H0R0\0f0p0z0
1$1.181B1L1V1`1j1t1~1
2 2$2(2,2024282<2@2D2H2L2P2T2X2\2`2d2h2l2p2t2x2|23/3:3i3r3
8#808<8l8v8
9Y9`9e9n9
92:0=E=L=X=i=u=
B4S4Z4}4
99)939:9>9D9H9R9]9g9q9
<9<M<X<
>>k>x>
>N?S?Y?^?i?
#0>0U0Z0g0r0
151@1_1j1
2+292F2S2
3$3S3Z3d3i3o3v3
7K8a8q8
9!9A9d9
:2:X:o:
;9;D;O;
<V<^<d<
>">0>F>Q>
?:?D?R?
4/4:4U4s4
5&545d5
8W9f9p9z9
:&:<:N:T:k:
;!;7;E;K;Q;d;y;
;)<?<Q<W<u<
>#>.>R>
?$?:?H?Y?m?
70H0n0
1!1+1:1H1g1
242S2i2y2
3"3-323=3E3g3w3
5525B5R5b5r5
9?9m92;N;Y;
>?E?e?
555<5C5H5N5U5n5
=\=f=p=w=
>>#>)>->;>L>a>r>
? ?'?.?5?<?D?L?T?`?i?n?t?~?
0 0'0.050<0C0K0S0[0f0k0q0{0
4/454;4A4G4M4S4h4}4
6&6,6V6|6
9:9D9M9
:C:M:V:_:t:}:
=+>0>4>8><>
6L7Q7|7
:!:R:s:
;7;H;T;p;
<><R<d<
==,=5=:=?=Z=d=p=u=z=
132B2"3O5
;F;k;:=
3N3h3w3
4454B4P4^4i4
4(5B5G5
5X6_6e6A7q7
9%:8:A:N:]:r:
<!='=;=Z=x=
>0?5?:???H?
1B2L2R2\2e2
4+4>4L4S4[4s4
8B9]9o9}9
9.:V:q:
?"?(?6?@?D?L?X?r?
0Y1d1_2n2
324K4U4a4
7&7a7h7
9&9V9y9
9?:E:q:w:
;';3;?;S;i;|;
<(<<<A<F<c<
=#=>=M=X=]=b=
>2>V>m>v>
060=0F0y0
11j1y1
=M>(?/?^?e?
020Y0n0~0
1$171Q1`1
9(9K9U9|9
=I>Q>W>
3#3=3L3V3c3m3}3
:u;-<w<
=#=5=G=Y=k=}=
>.>@>R>d>
="=G=}=
0d7(8^8e8l8
7#737l7
< <'<7<E<V<n<t<
>4>X>c>p>
7:7B7_7o7{7
9G9d9x9
;F<f<v<
?-?X?s?
>+>?>E>
1A2S2f2
3,4I4f4
1,181<1@1D1H1L1X1\1`1
; ;(;0;8;@;H;P;X;`;h;p;x;
< <(<0<8<@<H<P<X<`<h<p<x<
= =(=0=8=@=H=P=X=`=h=p=x=
> >(>0>8>@>H>P>X>`>
8$8,84888<8@8D8
? ?$?(?,?0?4?8?<?@?D?H?L?P?T?X?\?`?d?h?l?p?t?x?|?
0 0$0(0,0004080<0@0D0H0L0P0T0X0\0`0
3H4L4P4T4
;$;,;4;<;D;L;T;\;d;l;t;|;
<$<,<4<<<D<L<T<\<d<l<t<|<
=$=,=4=<=D=L=T=\=d=l=t=|=
>$>,>4><>D>L>T>\>d>l>t>|>
?$?,?4?<?D?L?T?\?d?l?t?|?
0$0,040<0D0L0T0\0d0l0t0|0
1$1,141<1D1L1T1\1d1l1t1|1
< <(<0<8<@<H<P<X<`<h<p<x<
= =(=0=8=@=H=P=X=`=h=p=x=
> >(>0>8>@>H>P>X>`>h>p>x>
? ?(?0?8?@?H?P?X?`?h?p?x?
0 0(00080@0H0P0X0`0h0p0x0
1 1(10181@1H1P1X1`1h1p1x1
2 2(20282@2H2P2X2`2h2p2x2
0$0,040<0D0L0T0\0d0l0t0|0
2L2P2`2d2l2
84888T8X8x8
9 9<9@9H9P9X9\9d9x9
:0:P:p:
; ;@;`;
<8<T<X<x<
=8=X=x=
>8>T>X>x>
2 2,20242P2T2
Bapi-ms-win-core-fibers-l1-1-1
api-ms-win-core-synch-l1-2-0
kernel32
api-ms-
(null)
mscoree.dll
Bapi-ms-win-core-datetime-l1-1-1
api-ms-win-core-file-l1-2-2
api-ms-win-core-localization-l1-2-1
api-ms-win-core-localization-obsolete-l1-2-0
api-ms-win-core-processthreads-l1-1-2
api-ms-win-core-string-l1-1-0
api-ms-win-core-sysinfo-l1-2-1
api-ms-win-core-winrt-l1-1-0
api-ms-win-core-xstate-l2-1-0
api-ms-win-rtcore-ntuser-window-l1-1-0
api-ms-win-security-systemfunctions-l1-1-0
ext-ms-win-ntuser-dialogbox-l1-1-0
ext-ms-win-ntuser-windowstation-l1-1-0
advapi32
api-ms-win-appmodel-runtime-l1-1-2
user32
api-ms-win-core-fibers-l1-1-0
ext-ms-
Sunday
Monday
Tuesday
Wednesday
Thursday
Friday
Saturday
January
February
August
September
October
November
December
MM/dd/yy
dddd, MMMM dd, yyyy
HH:mm:ss
Bja-JP
((((( H
zh-CHS
az-AZ-Latn
uz-UZ-Latn
kok-IN
syr-SY
div-MV
quz-BO
sr-SP-Latn
az-AZ-Cyrl
uz-UZ-Cyrl
quz-EC
sr-SP-Cyrl
quz-PE
smj-NO
bs-BA-Latn
smj-SE
sr-BA-Latn
sma-NO
sr-BA-Cyrl
sma-SE
sms-FI
smn-FI
zh-CHT
az-az-cyrl
az-az-latn
bs-ba-latn
div-mv
kok-in
quz-bo
quz-ec
quz-pe
sma-no
sma-se
smj-no
smj-se
smn-fi
sms-fi
sr-ba-cyrl
sr-ba-latn
sr-sp-cyrl
sr-sp-latn
syr-sy
uz-uz-cyrl
uz-uz-latn
zh-chs
zh-cht
CONOUT$
Antivirus Signature
Bkav Clean
Lionic Trojan.Win32.Generic.4!c
tehtris Clean
ClamAV Clean
CMC Clean
CAT-QuickHeal Clean
ALYac Trojan.GenericKD.66061923
Malwarebytes Spyware.Stealer
VIPRE Trojan.GenericKD.66061923
Sangfor Trojan.Win32.Agent.Vuis
CrowdStrike win/malicious_confidence_100% (W)
BitDefender Trojan.GenericKD.66061923
K7GW Spyware ( 005a16751 )
K7AntiVirus Spyware ( 005a16751 )
Baidu Clean
VirIT Clean
Cyren W32/ABRisk.TGDN-2017
Symantec ML.Attribute.HighConfidence
Elastic malicious (high confidence)
ESET-NOD32 MSIL/Spy.Agent.EJX
APEX Malicious
Paloalto generic.ml
Cynet Malicious (score: 100)
Kaspersky HEUR:Trojan.Win32.Donut.gen
Alibaba Trojan:Win32/Donut.050191e8
NANO-Antivirus Clean
SUPERAntiSpyware Clean
MicroWorld-eScan Trojan.GenericKD.66061923
Rising Trojan.Generic@AI.88 (RDML:kdfxKy/kwtJ7jz6gyeYmgA)
TACHYON Clean
Emsisoft Trojan.GenericKD.66061923 (B)
F-Secure Clean
DrWeb Trojan.MulDrop21.52805
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition Artemis!Trojan
Trapmine suspicious.low.ml.score
FireEye Trojan.GenericKD.66061923
Sophos Clean
Ikarus Trojan.MSIL.Spy
Jiangmin Clean
Webroot W32.Trojan.Gen
Avira TR/Redcap.conqm
Antiy-AVL Trojan/Win32.Wacatac
Microsoft Trojan:Win32/Casdet!rfn
Gridinsoft Ransom.Win32.Wacatac.sa
Xcitium Clean
Arcabit Trojan.Generic.D3F00663
ViRobot Clean
ZoneAlarm Clean
GData Trojan.GenericKD.66061923
Google Detected
AhnLab-V3 Trojan/Win.Generic.C5400092
Acronis Clean
McAfee Artemis!571CE7DE07A8
MAX malware (ai score=84)
VBA32 BScope.TrojanPSW.Reline
Cylance Clean
Panda Trj/Chgt.AD
Zoner Clean
TrendMicro-HouseCall TROJ_GEN.R002H0CCO23
Tencent Win32.Trojan.Donut.Xwhl
Yandex Clean
SentinelOne Clean
MaxSecure Clean
Fortinet W32/PossibleThreat
BitDefenderTheta Gen:NN.ZexaE.36344.nuW@a4aw2ffi
AVG Win32:Trojan-gen
Avast Win32:Trojan-gen
No IRMA results available.