Static | ZeroBOX

PE Compile Time

2023-03-03 01:39:22

PE Imphash

895e5e6e037e9108574fb94ed614d804

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x00001b1f 0x00000000 0.0
.rdata 0x00003000 0x00001168 0x00000000 0.0
.data 0x00005000 0x00000064 0x00000000 0.0
.lol0 0x00006000 0x00356d52 0x00000000 0.0
.lol1 0x0035d000 0x00000398 0x00000400 3.59002576561
.lol2 0x0035e000 0x00604a70 0x00604c00 7.96364368914
.rsrc 0x00963000 0x000005bd 0x00000600 4.08179217183

Resources

Name Offset Size Language Sub-language File type
RT_VERSION 0x009630a0 0x000003a0 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_MANIFEST 0x00963440 0x0000017d LANG_ENGLISH SUBLANG_ENGLISH_US XML 1.0 document text

Imports

Library KERNEL32.dll:
0x75d000 LoadLibraryW
0x75d004 GetProcAddress
0x75d008 ReadFile
0x75d00c WriteFile
0x75d010 lstrlenA
0x75d014 WaitForSingleObject
0x75d018 LocalAlloc
0x75d01c CreateFileW
0x75d020 MultiByteToWideChar
0x75d024 DeleteFileW
0x75d028 CloseHandle
0x75d02c ExitProcess
0x75d030 CreateProcessW
0x75d034 CopyFileW
0x75d038 WideCharToMultiByte
0x75d03c Sleep
0x75d040 GlobalFree
Library SHELL32.dll:
0x75d048 SHGetFolderPathW
Library KERNEL32.dll:
0x75d054 GetModuleHandleA
0x75d058 CreateEventA
0x75d05c GetModuleFileNameW
0x75d060 TerminateProcess
0x75d064 GetCurrentProcess
0x75d06c Thread32First
0x75d070 GetCurrentProcessId
0x75d074 GetCurrentThreadId
0x75d078 OpenThread
0x75d07c Thread32Next
0x75d080 CloseHandle
0x75d084 SuspendThread
0x75d088 ResumeThread
0x75d08c WriteProcessMemory
0x75d090 GetSystemInfo
0x75d094 VirtualAlloc
0x75d098 VirtualProtect
0x75d09c VirtualFree
0x75d0a8 GetCurrentThread
0x75d0b0 Sleep
0x75d0b4 LoadLibraryA
0x75d0b8 FreeLibrary
0x75d0bc GetTickCount
0x75d0c8 GlobalFree
0x75d0cc LocalAlloc
0x75d0d0 LocalFree
0x75d0d4 GetProcAddress
0x75d0d8 ExitProcess
0x75d0ec GetModuleHandleW
0x75d0f0 LoadResource
0x75d0f4 MultiByteToWideChar
0x75d0f8 FindResourceExW
0x75d0fc FindResourceExA
0x75d100 WideCharToMultiByte
0x75d104 GetThreadLocale
0x75d108 GetUserDefaultLCID
0x75d110 EnumResourceNamesA
0x75d114 EnumResourceNamesW
0x75d120 EnumResourceTypesA
0x75d124 EnumResourceTypesW
0x75d128 CreateFileW
0x75d12c LoadLibraryW
0x75d130 GetLastError
0x75d134 FlushFileBuffers
0x75d138 WriteConsoleW
0x75d13c SetStdHandle
0x75d144 DecodePointer
0x75d148 GetCommandLineA
0x75d14c RaiseException
0x75d150 HeapFree
0x75d154 GetCPInfo
0x75d160 GetACP
0x75d164 GetOEMCP
0x75d168 IsValidCodePage
0x75d16c EncodePointer
0x75d170 TlsAlloc
0x75d174 TlsGetValue
0x75d178 TlsSetValue
0x75d17c TlsFree
0x75d180 SetLastError
0x75d18c IsDebuggerPresent
0x75d190 HeapAlloc
0x75d194 LCMapStringW
0x75d198 GetStringTypeW
0x75d19c SetHandleCount
0x75d1a0 GetStdHandle
0x75d1a8 GetFileType
0x75d1ac GetStartupInfoW
0x75d1b0 GetModuleFileNameA
0x75d1bc HeapCreate
0x75d1c0 HeapDestroy
0x75d1c8 HeapSize
0x75d1cc WriteFile
0x75d1d0 RtlUnwind
0x75d1d4 SetFilePointer
0x75d1d8 GetConsoleCP
0x75d1dc GetConsoleMode
0x75d1e0 HeapReAlloc
0x75d1e4 VirtualQuery
Library USER32.dll:
0x75d1ec CharUpperBuffW
Library KERNEL32.dll:
0x75d1f4 LocalAlloc
0x75d1f8 LocalFree
0x75d1fc GetModuleFileNameW
0x75d200 ExitProcess
0x75d204 LoadLibraryA
0x75d208 GetModuleHandleA
0x75d20c GetProcAddress

!This program cannot be run in DOS mode.
`.rdata
@.data
`.lol1
`.rsrc
um3L~XX
s&z9*Z(9
CZ(IA/
H5LF-5
H5LF-5
YuX.evT
P*O,Q"
Gt.1R)f
=nD9{4
d~A5Ty6
G],>7G
C}&(Fg
\EBk}e
@"="P|
6#s"+8
_LMI9eA/([
#'/*kG'
?KTU/_
9Z5U3(+
30xXb?
|UI@%%
k^D$[Y3
]2]Um5*
GetFileType
' Y55V
=j@w{4=
GetModuleFileNameA
w85&,~E
#{<vAQO
p85(7yE
X""~\
r,H(u[
iw|tYp
uN9?2~^
s}o]=v
PL{sVG
V"[`cn
PPm;GR
"ioK9o TO
#IESw2
~M*W K(
]-33!K{
VP|I-ZPl
|$$Xf=
k%IVCp/QV
|u'3Pmn
(D1<$Hc
5Yx}n #
?C{n'J
vP~2J5
!iw04[
`]/Mkn
u)=Z}S
bcl9{"A
LCcNxB
T4:8\M
RRFI/8
[hK%+
0@bXP^'
HeapSize
-5Ty~:
l`>kB&-
$O97Fc(l
e6El{eb
kee`Yze
V1_9ps
yg2Mcs
8Ar4*]
"4Z+sqn!
Px_A48
'~*g:{>
ba zu(
|VGztKXrx
{:yP_0
tI4O\V
zf-X[SKFw6
-`/M96
,&m<kS
V}xy/
?~7c:v
f~7ADx
\1->HL
9-|@66;*
`He43F@4
E%XIoOf
$"):#U
V%6ff"A
7I*(f@
kH>g:A
MMkd}J
GetSystemTimeAsFileTime
GUhK[(JV
5-X]l1
/a9p29
"()263
Dz~80f
6a&7n`al
U`ssWp
tz`xxh
YUfJDw
^1E6$+c
'H4Ui;5T
<_I\j-
u`mTm1cm
s}m%mCM3&6
UsP3<j
:Nf>e0Vf
uZq.h(
{B4$a.b
x<~0jK
!(\9a
zunCW)
xPR0q!'
tJb!!>M!
E!?EF:
9~#oH|~
U+s:f
m3O7*Hv
?JE0Sh|
`:9t;sY
4\7'As
>It7[F
QbGHk+
7,#8rF
i1"N?n
F>/Rmu>
c]8[H@
4}z]]E
Ce]88=F
lstrlenA
^_XaL:
=wU.69w
yun:qH
5as('H
D$0#|$$
niF^f;
W14$_Hc
>!GHLw
"719^5
IuY^6e
<LfCl@j
cPF#v}jS
I:8a$<
D1<$_fA
U?uraH
Dp6`{h
U05[m.+
4] ^6,v4
}|x=v
21zqm\A
}?|knr
m^<mZ(
E7!;<{
q1e%"AQD
Z\7>wO
<d?P'%
8D(b:o
Z~IsHb
|3J&L4=
J_SWzX$
H3L$@A
<P&+?-P
dzQiI1
c>;ni
<Cx-*6F
$_|cuV
x^h,)W
h7$^X0S
E3`-u4
^[=/n\J
Z)`2]^
s_y\CX
2=,ReM
P3m&_d
GetConsoleCP
3l27~ C
H--_w8
`px1 &pP
L;d$HD
iztX{a
\%c9fy
vsC>7I
E{y\<{
I!gM3
>FQqiP`
cd"L5r
z@WuG6Ij[
,vrV,+
EbP_<{
YF21F60
z|I_VC
LVY(.t
0qEz\]C{
~y\($~
iF{NH_C
Y@Z%.6
{(]zof
RBPNaS
xENh{J{
D"V#gu:
D@ZA^+
$Ks^I7
pg0#c
5F9of[
PU[pO|W
!~r=HS
^_44:F
vJ{un&
KUY%KS4`7
"_@nq
jI[/P
MvlS
=*-&q+D
k8S3#7t
ow#"[Wo#o
5Hr&`Z
n#uS'`
:h<ehm
=3zx#P
*~Dgu\
=69}"id
D$,3_]K
Db54w$
YiJ[qC
L]N\/:MJ
WriteProcessMemory
3C',bJ
oB3c>K
./->)X
R/;bb(L
IGf`y@
wdAwZ&K=w
CY#\D ;2{{1
6:.oIL
Rgu iS
7(B%#1tH
>(E)ND:@
m+s]PF
9CVY;e
fY~DAs!
W!b=EZ
x(:CT(
_8lEE'
7Zf!\$
Q,uk@g
<2>*Uf
D$$61y
qEFjH]
eX,-;iJ%
`kaCWe
on"c_b-
D$,/>n:f
rN_;u9
8y<"Yf]>
I}Cq/C
O<b}c0'-
|V[wN4
5nC]v5W!U
=G<)T,G
{H%Zm:
A6tTY2aU<
Za?!$@a*
9BmG/!
[vtXXZ
A!TuBN8
s2bb{
mA-KYl
7KAK4#x$
%L\OPy
+~EmcFL{
'm`E7 ~Oo~$
K.fe|5Q
q(OxC!B]
2\E-@R\X
p URQp4
;X]t'.
wUk9Z'
,dK-eSf
OBp&Mp
op:o?)p
-,<4<,
C3`i5p4
!$&(5}
m~,s%U~
]s*:J*<|U
6T29?$
Mr|k@&
6G4}R*
4t5\W'7
Tz7:J
LoadResource
=0qV5Z
'4MD4I,>
AogWdZ
-Hj[CX
?vguK@n
-+=*a'3=
E3s]s2
-+T2 W@
^HJ@S9ru
YXJL2>y
OWq,Ip
(:EB,?
'UC<zt
/*YMp*
%hyU,\yV
xT!D<*
0s}q"P
tye=D~
Y}!NizV
epe$[X
0{9%"a
Mmm5)F-
8>!?G>\u
kmgATT
8IVIM{
};I@'D
nS'k2l
%)A/c2
tl}dCei
WTolgS
j9gm;0
68s"g1
zP+JW\
=&! :Q
L<2n|;E
|cQxLd&
#Bs(6
tav{O"
0r0c,:q
1,$_Hc
zC }g
3ZWiQx
(Nwmltr
;0/_p8|_%
hj XBg
ZfY!T$
EnumResourceLanguagesW
MT3v#6%
wd<~+
Zz_<@W
PVG\W/r
OJbhAt
gW14$f
Ni"e`
?lrYne
hlwfXk
i'Z)nP
khC?h8
1qIit9
>0`[A.!
"-K!g\
b*<7_a
OMX!P[
u]&X=a
-.KV+'
OCyuLp
npM0l(pQ
VPxaFw8
`Z])-.
._SZw:
!T(Rs
iJKCV|
L$ uM).f3
[~6^hY
:lC`~Ox
ISfx5)X
.4l?dK
H)"]az
.+Vjf.
54Tj.5R;
|JYo&zrn
.1FVLC
*ixVD`
=(/Vl!
q@wkAG
E'W0BP
j(*iZ/]
IsDebuggerPresent
h9&>WD1
T,"4E<}"
O?B8C.
_sc\N]>w
Z?a_V~
)?~(Jq
@48T@@f)
*p]f{-
0(6U[|#
JDl+mBL2(6
HhnIf;
ExitProcess
Y2)hl)
S-.i;6.
IBRZ{B
<K{Gk(
m~69#x
owJfU@
y4;eG&&
wR=8Vq
Q-C3"Ok
yn43Y3
D$ f+t$ f
S9Qut,X
m0Q>.~
|$ Sy\bf
28xN;t$
D;14(Mo
;Gs}]~
(E:2g>
0V=JMc
JXAWfN
F #K(eK
ReB$ f
BL;,wQF
8&("4Xb
l<zHQ,
f: s-?
_{Dd@a
8up$P-o
N/b1u9
pY]t/Y
GE':d~_
L)BDEa@T2N
2S0Tvv(5
"5/)Md
e,8!E
seG>3G
PZPx;wV
"1j =vc
v3Ho#mR
k F1/6
57^Kl`
eI><WX
QsgL'
9~4"2n
/|#K)uxh
xoR(Hh%
e?^Y;ws
ge]`Kve
[ C>.U
{|.qGv-
NTF(_C
>5r=UU
\|sH<2
@5as('H
ywYWuIZt
5Cd[3-
&=_6}C
LyJ"VO
,%L:EuE
D14$fD
q%vM[U
yqh<?VP
x~4cs/
RH6VmS
ZXUR}X
aAv1~e
d}#F-ne#
NlpcWD
l{o0!VW|
ko`uEk,
)}e^y
k~<sol
!I]0w1FWk}
:$6EL*H
TtYOds.
XF-T3(
/x<W+8
or4~~8
T$Hf!|$,
;6Sghd*h
`"}oGT
5IE!>ya2
.hjel&
sB=xOu
K{]Is43
n+?=a`
I0j/Vx
y:VC5j
~hxUTk
:`Vn6C
Io+n'I
Lo0V9`|
&w63.7w
0woD-4wc
Z_8aI=
J6,IEFd
OR/fI|1
\>+7CY
n05e*kv
Q=jhR:
e!]Nvx
:KnW|
4bi;Z!m
A__A^@
CloseHandle
Qj6VbS
v#6q*[
ru&y_Q
wP`5w[
rot5as('
"D1<$H
nY65z1mO
.XYA\A_@
- q'cf;
RilLhk
a^cX'S
I1SO[#
SW&3Zz
upS_d7
+X7"CY]
FBiXKJ
15hJ$1
rA9uI=$
`:WSq
XYFb6<
`I[3Nu
O|$_9K|x
? 4HDaF
~i9qTe
9U16}_
|ZE-&q
GkeIT=
56)'G>
c?BXGT
8D14$@
YI>7dZf
W07|Ex
6#s}rg
'+k/e*
93Smy=(
w,E?;B?
qn@| f
TPRIjV
` E,&w.
FH"[]h|
IGCaJzQ$D
(:~QBe
&I%-."
Z=A]XA
')pk)C
. ~'3_
G&(a[(
\H!:k^sIZc
#*6gio!
=UsO7/
v*?'sWh y
tF77N[l~
a~0rt
FMs*Tvm.Aw
mN{}N=
]DZ+,2
E2.}a?l
SJDrF~
IBd9tszT
SJ-;|~
1zjZVq
Cn q_+
b{\#m~)
(M^#'D
5HK##S0|=.
9d|/n@$
0oH:fx
-(3\H:
vO8\l\d*@x
[8B\?(u
RMUh?U
ns<<nh
TKRa}v=
G=6~S(u
3{f .5
_^Tswc
h22% |2
9.5sl0S
Ho=Qwx
'8OIK1'7
tega_f
ZYv9|@0c
4u|.&bf
up>il-0
Gykzoy
GS") 1z
`CbmewbC
U$E]Tb
2B1\>M
2kJcDF
bM[)&
y[#$<8
;P~] Xdz
XX.q{[\
Tg D^kS
1>5bj8C
Li*7 34
gu0>8g
1,$_Hc
LocalFree
f.*$v,MADm
!>x:Zo
cJFYl^
t25=!}O
t$0zpu
O|BlLp<
"Tf$co
ET$0f9L$
MultiByteToWideChar
t|npQLdn
@s$21h%
F=&Se29}B/@
u:RRCX
&H{FAv
*],.9v
7O>.f5n
:!ODC+KT
6fPe<B
!RE834
-eqf;
<KWo`SD~
CloseHandle
m')<"|'
hkmRb_q*
Sf)PRl
ES9dP@
OsX?+
Y+u2;1>
=?y.UxK
N\=_U
^5q-n2
s15^C6B
cXy,2Q
?YmcnP
hYh\X^
\8`)[O
E],/uZ[
RT}mf-
5D6s_D
pWD14$@
iW308^
T:;1d=L
;/~8<X
bV"@RQU
KERNEL32.dll
d9M97t*b
q#t%iN
_2\'.P;G^H?R_N\@
ZlzfJE
ug7XZ{
79I%5b
$~q97;U^
IWU#N
y$ZkI#-
K[00gK
."RkG/
vcOk)s
mC mk.b
RB|=f;
NTJ4!Rf
mK*V-1q
x|R,&B
Omk!Ap
R}oz~D
ik|U@a8~
:@}rT(
-+T2 W1
')_:79
Cwwx_X
s}Vez'6
y-Vs2V
X!EU@b
!.Coz!
UNbVeA20
w$TTe+
!h24[@s8,[
a;%M79
WD1<$H
LWd!@3
Qd7lzUdK
M7y01g~
M7\59g~o
%>vTe1"$
GvKut4
|:7K+LC^
U .E%Hu
+ eYRH
bF"_D[j
YT{{Oq^
9H'rH%j
8Z5pF:<
#D`XNO
GGf+t$
*al3zA
55z1mO
ur O{v
IPV[](
u/" g1(&~/
ORLBm-
0C?Gc:
3%iHpX
f;f[SR
m4E.M.
KeU)u@
@[)!`xC)DG
kE~!B4
WideCharToMultiByte
)@;bwf
h]S`w/
99n|@V93
li8-{q
\?xeq#
~$V?kY#
Thread32First
__%{5
[Dc{BDS
1Tke$11ze
[XV_/=
D5~q-9=
&}[8]X^
6%w4.*?
&`OhQ#
_|n+N))+
gyOcJT^2
T5Qt"=
LocalAlloc
D14$_E
Ub(!eDTd
7kGLIlm
MultiByteToWideChar
M+>nWIc
A5%ES|
SetThreadAffinityMask
=PUDI~
cFI4_
9p!,(W
=m`0y4r
hUnuW
yN/x#$
[AaS[u
}S(dXr
Ddb;dC
W#(m)g5
rrYXWx
L1^58-
,bLF?Z
OWyg}2
Tmj"+luj4
mUXqut
LocalFree
H5LF-5
Lr\xr+
eP{|/WH
~pdaCop
`kps\9>o
D$$3Dr9
'pX+Z#p
?wcb0s%
K'bE,s?bh
slbum~/
c@7f/Lj~m
=:7~y4r
WV7BG
JsQm]t
[!w67t:X
.QiA]@
A\A__M
ReadFile
t~,kn_uk8b
i>"<9Iw
*kWD{h
H?W4,
&W1,$@
=FWIAx9
RCpU-2
+bXGi3
SetLastError
-X5[j-
|YL"QY8A
hS <h
#!~A!_
oA1<Uq
NCw)U,
HR(S*C
xu,/8g(
:Gy>Yi
N7N0<d~
OpenThread
#w+,[C
TQMb?A`
7h(;,_
DE8.0l
5rt9W@
>$/:7a
g-X+Ry
FoWTui
D'<=yWM
y!z7T0
iN7T=Fd~
=h5tw4H
jWdu.^:
g{(4. x!
B`%${F
u/"iy1
~+<$dJ
ws]a>;
<23c+O
#w4bbt
HQLLC`
I*uOv#
yHSDK
goP6;|
7'Wmx5
48^X1
&?76mw&
2Kc;00
BR=*i
8g(xn>4
ZRZCI$T
SHELL32.dll
t$$/:f
D$$4vf
.#./!)
b"/LE:Y
&(u#:Jx
4KO}5b
'|=d\s o
d~a)|q
LoadLibraryW
WiO=,|F|
[qN`0>
^hGLvZhk
[j=XS/
PsJxA/
uJF}fqJZ
~3)6Q$
LocalAlloc
#(l_05
oD14$_Mc
c<~&[R+d
G?KF?\
&AT[n*z
Sx9Q?|
0{(eZA
jvvkZq
s&W+tQ
+,^u_X
%Sc,}r
7Obz7rS
x4b*D\m
=Svj|BFA
1&^6u@1
M1o=T2
yk?lQba'l
5}dK'=w~(
/2B^`[
nOEQ w
{a0I4
S``=[y
itz;7F
UnhandledExceptionFilter
W1,$_A
}VjE|@
vB.<OO
QL5fP%
o;+bqi
Y-!hf;
S-BhL~
TW_36e~>]
VirtualAlloc
|$(f;|$(
GD"V5Z
SYK&"BY
L>YEj9gjh-dTtA
BUjX&l
u:7 x1=3~0
t$&7,%
SQ^&Ov@N
=j*6!B7
s%}XDXD
e_O7zT0e~a9
}Z|Y|i
:jbLKD
D$4!L$
2do6??l
HT%&Da
Yra^)oa
@5as('
m^CS<W
P3KR`4<
f_R#VX%
[z6nUz
}T[Jf>7z
~=&3= A-5
Z&GX8T
y|f(meO
&{f3l$
\B/hh3TW
95mIdmN
ci[h#=
aoeYVx8
k{IxF
FBL-`8
`vAH=3
=2Fv4
=%Pob4
V-?/G*
iO>6.M
ag?1aj
rJYI^|=
bEJ/!h&]
vE-=@Z
qi oK+y
/OxC9/
Eca=~_*
?1Nz}5$5
\)MWdN
6,<3UB
_av<a|r
jxNk?0
GetModuleFileNameW
LYb*7>
.O[#D0.Ed
NI6G0k
T?4~(y
CreateProcessW
\$ #T$
U=Y5O6
[8tILz
Q"{9WC'
>}M0}X
~G5;bC
kwwwKY[
p=7jfA
j_-Mw6
ARKQ^]~
F:3&aX,
} ~07:
|u.#'muM
ju_L$nuk
kS*NxM]>k<(
c9EB7t*jh~
=0jX{4?
NI$TK-
S:7UL|
\47*ss
MI+RV]&
1,$_A
ResumeThread
!mSe.=?
pxN}qo
InitializeCriticalSectionAndSpinCount
J1r\zG
xuT, :
?@<z,)
ps}Gjz
x4KZf.75yd6
*&7UD=qy
;c$Bp+
*`9L!>
d.7` f6
"~8_z3
[q<mC~
.QoouN
5QBc!$
7llq`k
W^Mu8Wku
SdWDKp9
$)1>e["
5N Sy(
GBdf`*
m~@0zy
o\yDmM
#Z{1\)&
4=s .f|
w5SU&X
WD14$H
%xI{f3
lS~zj-
~?;a!S],Lp
*-Gc@_
7y^X!
G^P{95
r4(yZr
x5Qt"=
/bL.3
9~VBCO
=~V'aK
*1Fhm>
RoqK*b
LoadLibraryA
|4vymg
QwP<qmKw-
x{=g>@c=
0re3xS
`Ub^PR
,=:c}4
p<.,!5
P2b!WE
MQ&-}VQ
V9{/f>
{=?\K:H
l$ 2xf
5jbI0>
~g&7)@
SetFilePointer
/D0%@PJ
|$0f+T$
}6'8Vp3?
36wm;2
r'y0aC
<k^xS{;
(3M9/}6&=Yp3;*
EnterCriticalSection
JSJN[%Z
oEZ&LwV
E=6Wp++
o.QJ#AsyD^
HW7)}0
<+V~}pf
kU@h,B
=x^k:
"$:$(Bbz[A
Cu>QBR
t4XO:(
VUh$xRxh
85LF-5
%91nUR
%C50qIe
w$4TXP
+?;&_|9
vY}`~X
qW14$_f
fPvgFJ
M~Od$_Ld
xh{xf3
"eI55X
sRxa{+N
7NP9W>
n$JKl
qhW1Ao
2%Y[+|
("9oZLHW|
\};\06d
`+&@v}T$
n;B<U*
W+D1`H
f?9'WV1J:
xG+]i
tw4K.|
~,DGwS
\1&Ro`j
+&?^4X.1
Xu-X`SH
1ybsIi
5e*kvf;
BoH/rh?
n\`.i+
09JZf;
:FcXkO
v.;eF)L
mFfg]A
C6[,DA
WD1<$_
{XtK*Q
k189[6O
F5|Jv2
]]!HmZV
pYe;@^
}`V:C
[PK$Ej
t0FnB/f
BXh1<[
qlTo{
J5vUkA
q8NFu$
cF~"F#
@I!J2K
"b9Uc
Mr"IF3
0Z4~@m
\$49|$$
M+>nfA
r1,$_fE;
d*wE`K
qT\E54
WD14$A
-ll"*Z]
laIiA[
lL|mA[
@+)gY]
UFP?j;Cm
?^zA&m
]r0hO;YTy.
ps,Y@_
>d1Dud
gAd8mN
w^W)vn
=9iY.;
P=4oiR
pOM<K&yK"
`HvTgBlt[
xU}|ih=
f1t$ f
7Ojhu[
S-hlZE
z^C~jt
Yn)1ZiO
GetConsoleMode
HeapFree
p@^Df;
5rt9WD1
0C'"Uh
5Ta`OJ
Wob@}_
_;x>meKl
1(MuM1
HeapCreate
D$ +t$ "L$
xr/liv>t)5
Wlf(R\
m T"}Cj
[PvJm$
A-nMPG
C]SShc'Cff!\$
D$0u'\r
t IC}cO
j]\W=|
`*gOMl
k42gMh
mA^|M@
hA4)w
M?^SG~
f/:eV(M
*GbX{N
}GggM@
B7[<E@
K$rmq^^
xlu,GA^
".!{%nS)K
w0=t.!0o
i%qR$N
(/O&<:
sfQJkOiO
v9+OB8
-=B9Bo
)vG8Ym
;b_2Q9WQ
qU6 Pa=
efUc\Ql
D$ HG'0
eTF;5+,
AydT[K
.gKrG6gVu
p3uhg,G'
sX^9f#
(@;mZZ
K$dcK~D
vo]%0G
P%B]@c
+D5*UTJ
$WT(9"
+*PP}o
l1"o|{
yS=2WTj
M+>nW1,$H
aD5r=UU
/jfF\#v
@58.3*
-*E76S
tkED;Q1
cb"dPy
n5 5"_
WxV[}!
+zGrU_
DGpWV1
lu@RJt]
#hKCG;
GSf1\$
YVFD3YS
D3)"/<
T$DJ\V
frkTw'B
4`9+$*&t
X;VT'r7
{&x(8(
Zz !cm(
lbsM5!
D$8sO+
m'@Oe
D<&sx,
8r}`5H
/m_]Hk
Sb|O[X
4xOtFt
_g_NMl
2y<]l
`7]b,Z
mQy3)J
kt"?:}
7u6pf|
`u3OPrD
Mqw<}v
l$`Z(FA
SetUnhandledExceptionFilter
=Q{UGq
n1v:^P
UMKTP3
: NWc1
597U"8
BC\Qh1
u@/;pn
ipjkBUh
[2ef|s|
>;Ub4D
S9Kp~g
32D>jg
;3Ckj:
g2W$6;
^Kj6Y<
Z__%jX(
l3FT\41
eka"?D
fof"3h
s=q"mTn
^=z4Q8
Q@Y6(y
dI6T,B
E;sgZh
a;}7Dy
bw6{fK
&VrY1h)
#x'/rq
Y|fci{
l5g_i
t$ "!R!
D;t$a@
`7TUHRuG
quOqO1
+pER):
p]N8Z,r
W5"|"Ei
LI"Ot}
5cP!Wh
%\y\20
0!>Mn(
4zi!^jA
`wj+"a
[U{lsAu
lpsa\w
u#]-rT
D$(!t$
L$H4gziH
Qkn}(1^
sCF[td
)&wyVtB
s)|j9\
e}fE^[
qe(C:P
ry94<AP
ySf6f}%k3SJ
sJ(?/t
M}Vpa;
Vq78s]e
%n4(X\;
;A3*KD
"NsUXn
GetProcAddress
VDwUT2
;qo)u
MC;Y{fm{`x
&z?a^A9
kxAI:q
`yP9P~'
'tFuv}
{uR:*|
ptCJ@s4
v)^Vy`
eeVrUb!
} f;-uufE
"!,a"
k,f'roR%
%kHoOq
d=sB&C"
GetOEMCP
te47$w{
-Ky"9"
kjFQSAPI
D$@d8P
2F"AVL
^r6-/7
Zh<3[v$
KSJZ'z
WD1<$f
8061*L$
x-+9[
H5LF-5
c1,$_A
(zxFys
:=7{wC
gDI7")
^K4ciSK7y
88XQ0g[
s"xzUw
;y{ v<
|~e`3S_
eu8J|e
-L|]}`g
\%OWD1
zfBNs
2~"1cw
Hzc}x}
N6fr^)}{u
E 7X)H
wv\cu!
iAB+0R(<
||XI7F
WD14$_E
lK%~oK
NL>|^*A
y5Gv'
#j059;
30Qw]G
d$ >k+|$
D?2o]
+%]1\
:k^T.KCu
LCMapStringW
Wmoj0
DeleteFileW
:y a"Aw
AYA[fE
vIf$8nnF/$
,bd@>S{
\O8zTQ
_n}I;V
q*qg>a
B]]moJ+
zR8]9}&
YRxPO`
N{w702m
VZt5[E
Z({|'ZZ
Iie2'b
X<*&X4
K]'=Y2
,>z[K3^1
ldoXb5
17M,tE
UDXpDj~
aW<tU}k
4qF=u si
D"zV.HT
z2pUHN
A+9z}]
|mwC~F
cSC]AdA
\P|dlW
Qh+0V
a=te04
=<`*l5
95)+>B
G8!fw?V
7!UEf(
L]D:K*
`!PzP&'
L$,Tc>
D$(Sxf
EnumResourceNamesA
ExitProcess
1p9+o:
9#rF79
]}3$rW
'"9Y5Z
0T520l
V#T?8y
fD;l$B
9oFh0a
)&&7,I
l\|^D[
q hEcfO
']e+p
vex\+7
GetStringTypeW
Rv}1mk
ZmqS`(
w1}i/o
!MoS$
y6LD9x
c6VIQ*
hirrP2
".19_,'
kOrTN+
USER32.dll
W|Kgg{<
}_(;z(
yeX{>X
-y=T%
GetCPInfo
SHGetFolderPathW
GrCmf-
M60j%t
gb=&~\
MuU\ek
_PG2"s
_FQIJE
U :&sFcZ
cl"sXa
DeleteCriticalSection
GetCommandLineA
CRa4"Q2
,^.}!ii
D1<$_Mc
{CyOsT
p5"\~A
Y85"=i
sqmf;0
<]k8MD
FS\N55
f3, n[s
D1<$_@:
PCd(Iyy
V/d1/|k^
|%{M~;GV]
Y.@twX
R|~X\g
OZvc&t5
=HLF8"X\
5F}<Mc
o14$_Hc
~--ES.
s;.ZpL
!EL:i{l
H>j'9
%f<2Ly
f}nB#tY%
LK|k35
WD14$f
O(0x6&
`6SMqm3DN
Q!@'"0
uUf3t$
fljuVk
i:I'nM
:eA3zr
C_,wP,
b@6\t
@U:&P!
sJ_BKQ
9ea=7V#2
9><]@N
-[. "!
4bp^w9M<nh
Ia;v%>{B
\ue!ZsT
`]Q'[
cT3^KE
4D$Wt q+
*izg:S
|Um[8l=)C
(j_bd9j
` j/I\h
Ff!L$0
0;.9PC
{2gyQ5\,h7iI`
S0%C01
/<LTLCE
4eV}`P
#QE]J$
CharUpperBuffW
4hXp
ZN'neuo
,GND_=
3ER;_aRl
~:UX<D
dvQ#MI
lF`$ Bd6
fT<rv8
moI+Yp0
- q'cf
<Y+d5
@thdne7
o)d*$
C)GY_)
:yEz`
<F"K=e)S
d1>*T6I
tXrX%Q
I5zYy2
R]'[bZP
L$ f9T$
(n/:US
+}ZL5P
GetModuleHandleW
L$(qQ}
yD)v=y
*DJUuUJ
*D0/wUJ
xL_ )E
$MKouD
E!W!u&
Cn)'4
/LZK-
sMNPCJ9
GetThreadLocale
''l_U'|
5r=UUf;
\$JDK$
e,(Oz
]EG_2ww
OG!4GW
D(L$(A\H
)UFx\
e=G{U:0
PJE?W=
9|/~w
>~nf32
iy)rUF
mjxOez
#u{flCi
xWAw[H'
k`j~DhU
14$_Hc
P.71i9
R:UzkV
MSx)%:
rw}Fti
IM--n'
WD1<$_Mc
K]tWr0
HFKB>]
ZCN+;)
',D14$
te.]=U
dsrMg3b
=go"R@=f
[/ZJ6O
F=1-U>
))z@[ <+ {O
l\`-CU
GetSystemInfo
@!xLdqd
lshW~9.tD
$W}Vr[
P#|4#1
3|]|V.
,)`r5`b
-+T2 W
;&iJ_
Pt!&6/
DLzGcw
NAb2<,
}[z=%)
p_}NZTz
_Ih'Cm
I!1 d/2,~*2
n\w@QwaP
-MJ{AG
tZ]'&#%
dRl6C7x
ls71o#M
D$ F|04
48ZHFV
%))HhE
e^Q\]
28B>{H9
-dZo8f;
]AKCU5U<r,&
sKabf;
E{0ome(
|U~ IS
/O `[}
ayq.R&v
aj*!{
x#-Lnn
yeKP+}ew
3j!g~Pzf[
rO|{kqR?
$9NB&>=
G&z<|h
mlD,Gy\(Rx
2"nN)%48
=Q@*!$
D7+]Sq6H
4%75_9
jp`r90X
9y*[(9N
za*oFn
q3%F_r
HvJ!T
2AwO:-
F>LA!\
iQlNc"
)\wO!.
rff/[p
vf[;,-
ExitProcess
fUH59\
'4my*-,m
)"&\(-
J_TLP;
u><C$+z
RZkUTuc%GQ
c)Ev.x
w cyu`O
y\m,,a6
FCWAUA
EciB:'
nuk=3~
@*IvgI
C17e A
EnumResourceLanguagesA
XcJ%5W
A7P$zt6&<
T"%W7
tH$`Sn
ZTf!AB#9
ST-U#[
#)QU[mD
gpDSno
Gy7ZTz
"[-C\v
d7B2f~
t.J$HP
zh3{nI(
^E=YM\
D$ /Lsk
hyn}:h)
,Wf;l$
4}V8yB
^?~59l$
L'{HTH'_
X'(%aI'
jT};le
pEL$w2
%p;l35
FindResourceExW
9a9CSs
?cgE!r
\@q9c@FJ9v
}>9yMy
Iq9f5OJ9
1LoW#d
6Hq{g3
ujw/4l
?OrpcOp
4}-tr
~U}|ln=
7D3"n=xx
(cn<7k
&(}A_e
~4n \M
i2&g'=~t
wz?-'T
#'8A";'eF
f BdjL
\H>[fMH
JHLeNHk
nSLHy ,
SetHandleCount
uoSxSc
8R@K%E
B>yXn*
5O;nAt{
k0jWK08
+n?.[=
-U$rt0
"325s:
~2&z/;
^:4/YM
C_.{sXY
X7syh0
"KRX)3
?{tQl9
llQ:#^
14$_D:
fF*@-Z
n`p(&\
]pjdPdrj+
f!L$@!L$<
l6[FG6
n\wA|Y
QueryPerformanceCounter
|$ hLg
,bFg04bC
c;Z/t^N8
r D.2eO
=D1<$@
w7$VTR
(o,Mzt
%A~,Cu
9pI5VX>
XzAICOl
2nKN"#n
eI_E$0
3=>MYVx
q|$^ljd+
?}T(+%
s>9^g}
G/MpKN
Ubs_o
i"~lHV
-@&G"!#mD2
1%!giT
C*J7u6
sRUwxx
va${\i
d$@Z{M
MF_}m/TZ
R2fW\?ozD
sw%!CpR
/v1nqF
^saRnt
s}r25!.
w qv~p)
`ov%1f
<nbjmg
k7i*l@
Fj#&vmT
kngU[i
Lw{MKx
or-!&_
J9\\xP
@F`}leP
.u)#;B
g-c9}9|
AVw"7%eu
K#7+Vd
pPgn=zHg
InterlockedIncrement
F2&U=-
iXKkAUARM
{5e*kv
5JC/wf;
GetUserDefaultLCID
!_]HL?_
j%?[UwF=^
@Zelt5
%leI"N
;>p:%t
"6i%H:
?7`.E
CVm,mC
4w)Jbp
>rVwfH
_i |UCU
nCvOf}
CT:i#b
M{oJI<%
6-^Lc$O
qUOIoa=
FJpAR#
:geRAa
[b1vJS{
,b"pC8
bNe,@=eeR
08e;|$
Wh%UEf
X^V5E.'
&AL8J/}
lYaG@[
Ef8"S1
%5y,$maZ
r6*99P?
;UE_!Q
+zo~o+
>3kQ*y
D1<$A:
g}VU3T$
.Hr_k7CA6%
g@ke6|`
YY0+UDk
itdcQr
i==HY:J
yTq:(]
%Ueut\
D9y;t>
P0v3WG
_Q$9oVS
rU`JBR
&=,X*s
JQs5kz
u%k[|lr
Iu9)IV
+t9Vtvb
BI=WU@
5_((F`
=| cKx
S@FN_n
O~#JkIt
x+E,H6
E+7,YH
Lsf|0,XwvSR
}Q$O=AH
Nf_FYR
]"y,8P
"vCr+W
T$/u$
OPq2_
c_yIf=
A\A_A"
\3XJqb9
T$( L$(
5zo:I(
_+U[4L
h^WY9W
U3_Xe4(
c_F)SX1
=,4",:
D$$bZ=*
DElF7%B
cz0,AU4
8A=~Nl
^W;<*v
/<)|dVu
+55C
ies9=:
:I\U]8
x'7u7z
D1<$_A
[n2};Z
[}HI8<
,35ESv
n1X=8c
/qD0_O
ZOI$a)
9gS;$p.
~Hp/>C
P%x K rh
AY#f)l$
yf!l$ f
+[IS!\
xb"{>]
.riiOl
m@'X V
b[+my>%
ukX~5{
/{DSDa
FI0s\
}( pU6
Sg}3i%
5P3A[nm
D'uIlWH
ZzYCfE
:}9v$1
9p%M:9
:8$09A.-
]VwO\K
D1<$@:
,]fkw#
L#D$(A
6deum,|
]f!T$ f
TlsFree
it4R8}
bu%"RrR
'TLAK[
3$/#7o7-
h^%po
)^4BcTm
4o(Aq
HYby=[
Tp|Q=_
RCy1zIIa1
4iIVq |f
@gU^z*
l1timr
;Bkm%`
7hoEZx
F&k'F9
,;hl_o
)ULS@S
2^?m?v
TD1<$fA
@mH@pj?
)C=+L@n,
Ui|&}z
ACn[N
qnCA2K"
TMbc@v
ADywY)
v2Qon"/
#K`Hr)1';!
R|fYlO?
A*kOtE
EnumResourceTypesW
D$!AQL
P1}}|@z
+pR }s
e#@|Ah(F
;%{%j,
g$oj6-
ZIgkjN
A!:iq&M
.&-'Y
)4T)V84GB
tdH,M:
vdDH_*
F5D8f;
K[gf1L$
h<.")V
dT46^wd
`>Wxkq`
HBe{&N
?.${Dag
C}3.oh
pihWtg
*1[6W.%
Up6gz!J
XXvq2c
uImVqWa5
'%Z> R
3J-[bC
dJ(dTM_
thtO|O
f*uFM@n~
>Q=akb
1-nTBa
@5as('
5i`2*3
Kh`2D]
LFhVhI
$DGpz[J
dWb#FxD
k<|bw3
sU@f>c=
!|$,f!L$
C6DUe6
^8p{S1
eV8^k T<s
4wo1v{=S
6D9[6=
yF4cVw
m"h6po
F5Jqz,
}rv77Zoh8
SR"~U(
H#\$XH
84J=`wC@
5{#9gI
|$0B0r
w1?%i<
19ap[,!
SXo~GSX,
xWB/\:DpK
d! )/S
VCx'cZn
LpD;eN
Z,7akM{y
efZBSor
:4n=pJ
\@5\4<R
bfL^xof
triD0h
?1?1u[
yQO(/P
4$MAy]1\T
IJU9=i
ChZgyhR%|
3md3qL
6H15Lt
1m%<ur
cH#<&l
CegBXM
dKo~VhB
Y&'>tF9
trUzjy
D?cBos
>-X]l1;
Az<?Hu&n
?J%uHdY
Zn1/%2
ek375/!
!DE13:
/sUg4
SUqPEj
(:q`M!
%q^zz@
Xgm"c'
WN>~p+
d}Ok}$
$v2YJ]
@*Q[@P
z&}(6;}
EhdRjD
>yJbyI
F,VB!4
D$ 9\$(
{1,$_Hc
_h9j+HBhLZE
N|=;@x
*%"S{,
fMznVJ
H*R'O]
P!c`&
}%'lM"P
A[A]XA
T4p/P+
s5]k<X
MfZPzjQ1
+MFk#Y+eZ
6il3/Wn
65TZq>
5*_PR{5Z
F@F?vPG,v
X:f0SJ
WG.C*
8f3l$&
KT%uVa
CK"lZu|4[
hh/+HGI
ndSFm
1|$,f3|$
1Fgs-<o
Y q5(Hc
L@BMoU
J]g3Zf
US~?@:H
\w 9ph
[8qt@:
M]oXZ
A\A__@
11AZI3
SuspendThread
g67WD1
"nSzsg
~oG5/f
unVEEi!
5f9l$4
y2V<I;
\''*Z'
Pz"L|a
L$$l5jEf3l$
dP6>4:
Y'=fo
A>uVlZi
WD1<$A2
ijz+"s<
Xi 3=dr'
ec-F-aca
~ $^iiO
qX}!n5
@Upy'i
4"8RzW<
u&g-<nL
1rKu-|z
d"[l@!|iK
Antivirus Signature
Bkav W32.AIDetectNet.01
Lionic Trojan.Win32.Wzwhi.4!c
tehtris Generic.Malware
MicroWorld-eScan Gen:Trojan.Heur.@F0@tC1wzWhi
ClamAV Clean
FireEye Generic.mg.b3c8c890a8a14c82
CAT-QuickHeal Clean
ALYac Gen:Trojan.Heur.@F0@tC1wzWhi
Malwarebytes Clean
VIPRE Gen:Trojan.Heur.@F0@tC1wzWhi
Sangfor Trojan.Win32.Save.a
K7AntiVirus Trojan ( 005965831 )
BitDefender Gen:Trojan.Heur.@F0@tC1wzWhi
K7GW Trojan ( 005965831 )
CrowdStrike win/malicious_confidence_100% (W)
Baidu Clean
VirIT Clean
Cyren W32/S-ad060208!Eldorado
Symantec ML.Attribute.HighConfidence
Elastic malicious (high confidence)
ESET-NOD32 a variant of Win32/Kryptik.HRTC
APEX Malicious
Paloalto generic.ml
Cynet Malicious (score: 100)
Kaspersky UDS:DangerousObject.Multi.Generic
Alibaba Trojan:Win32/Kryptik.ff477073
NANO-Antivirus Clean
ViRobot Clean
Rising Trojan.Kryptik!8.8 (TFE:5:o8wrBs1QCtE)
Emsisoft Gen:Trojan.Heur.@F0@tC1wzWhi (B)
F-Secure Clean
DrWeb Clean
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition BehavesLike.Win32.Generic.vc
Trapmine malicious.high.ml.score
CMC Clean
Sophos Generic ML PUA (PUA)
SentinelOne Static AI - Malicious PE
GData Gen:Trojan.Heur.@F0@tC1wzWhi
Jiangmin Clean
Webroot Clean
Avira TR/Crypt.XPACK.Gen
MAX malware (ai score=87)
Antiy-AVL Clean
Gridinsoft Trojan.Heur!.02290021
Xcitium Clean
Arcabit Trojan.Heur.E969D5
SUPERAntiSpyware Clean
ZoneAlarm Clean
Microsoft Trojan:Win32/Casdet!rfn
Google Detected
AhnLab-V3 Trojan/Win.ClipBanker.R528972
Acronis Clean
McAfee Artemis!B3C8C890A8A1
TACHYON Clean
VBA32 BScope.TrojanPSW.Coins
Cylance Clean
Panda Trj/Genetic.gen
Zoner Clean
TrendMicro-HouseCall Clean
Tencent Win32.Trojan.Crypt.Uylw
Yandex Clean
Ikarus Clean
MaxSecure Clean
Fortinet W32/Kryptik.FXIU!tr
BitDefenderTheta AI:Packer.9AB1F9B423
AVG Win32:Evo-gen [Trj]
Avast Win32:Evo-gen [Trj]
No IRMA results available.