Static | ZeroBOX

PE Compile Time

2023-03-30 06:05:27

PE Imphash

303b4a863d3cdfccef2b33459673ef8a

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x000168f6 0x00016a00 6.60568458726
.rdata 0x00018000 0x00004958 0x00004a00 6.10867160153
.data 0x0001d000 0x00022edc 0x00022400 7.49767909077
.rsrc 0x00040000 0x000006c0 0x00000800 3.6290401376

Resources

Name Offset Size Language Sub-language File type
RT_VERSION 0x000400a0 0x00000460 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_MANIFEST 0x00040500 0x000001b5 LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, ASCII text, with CRLF line terminators

Imports

Library KERNEL32.dll:
0x418000 GetProcAddress
0x418004 GetModuleHandleA
0x418008 GetVersion
0x41800c MultiByteToWideChar
0x418010 FreeConsole
0x418014 PrepareTape
0x418018 EscapeCommFunction
0x41801c ResetEvent
0x418020 SetEvent
0x418028 DeleteAtom
0x41802c GetCurrentProcessId
0x418034 GetCurrentProcess
0x418038 GetNativeSystemInfo
0x41803c CreateEventW
0x418048 AddAtomW
0x41804c CreateFileW
0x418050 GetLocaleInfoA
0x418054 GetStringTypeW
0x418058 GetStringTypeA
0x41805c LCMapStringW
0x418060 LCMapStringA
0x418068 LoadLibraryA
0x41806c HeapSize
0x418070 RtlUnwind
0x418074 RaiseException
0x418078 GetCommandLineA
0x41807c GetLastError
0x418080 HeapFree
0x418084 GetModuleHandleW
0x418088 TlsGetValue
0x41808c TlsAlloc
0x418090 TlsSetValue
0x418094 TlsFree
0x41809c SetLastError
0x4180a0 GetCurrentThreadId
0x4180a8 HeapAlloc
0x4180ac TerminateProcess
0x4180b8 IsDebuggerPresent
0x4180bc Sleep
0x4180c0 ExitProcess
0x4180c4 WriteFile
0x4180c8 GetStdHandle
0x4180cc GetModuleFileNameA
0x4180dc WideCharToMultiByte
0x4180e4 SetHandleCount
0x4180e8 GetFileType
0x4180ec GetStartupInfoA
0x4180f4 HeapCreate
0x4180f8 VirtualFree
0x418100 GetTickCount
0x418108 GetCPInfo
0x41810c GetACP
0x418110 GetOEMCP
0x418114 IsValidCodePage
0x418120 VirtualAlloc
0x418124 HeapReAlloc
Library SHELL32.dll:
0x418130 None
0x418134 DragFinish
0x418138 Shell_NotifyIconW
0x418144 None
0x418148 SHParseDisplayName
0x41814c None
0x418150 None
0x418154 ShellExecuteW
0x41815c None
0x418160 SHGetSettings
0x418164 None
0x418168 None
0x41816c SHBrowseForFolderW
0x418170 SHBindToParent
0x418174 None

!This program cannot be run in DOS mode.
`.rdata
@.data
QQSVWd
0WWWWW
0WWWWW
_VVVVV
^WWWWW
HtHu4j
s[S;7|G;w
tR99u2
0SSSSS
>=Yt1j
j@j ^V
0A@@Ju
0SSSSS
_VVVVV
;t$,v-
UQPXY]Y[
URPQQh
0SSSSS
0SSSSS
t"SS9]
PPPPPPPP
PPPPPPPP
<+t(<-t$:
+t HHt
t+WWVPV
bad allocation
hsidaqmvityiktrjzxndbjgfqlqkosqjslaynzeunrjszvisdrqzfqpigeopotdplvrooevcocmwyigxilftf
snrqgbftzrvwxwduxyacunyzhqlbipldnxegziofexrfmwbszlygwydwxbsdacwtxil
opafcnvo
hsidaqmvityiktrjzxndbjgfqlqkosqjslaynzeunrjszvisdrqzfqpigeopotdplvrooevcocmwyigxilftf
hsidaqmvityiktrjzxndbjgfqlqkosqjslaynzeunrjszvisdrqzfqpigeopotdplvrooevcocmwyigxilftf
qetlyhznqhmerbhynhnwvspgmpmnpftalgaxczswlyjupfnezaahwjntqcdvtvyhzdpxvpkvlqlbcwrsdrcxttjiiq
hoqotsvjfmjnnrwlzbhghwpttpvrsdshfcoatkwzyxcbvwpskfka
hoqotsvjfmjnnrwlzbhghwpttpvrsdshfcoatkwzyxcbvwpskfka
hoqotsvjfmjnnrwlzbhghwpttpvrsdshfcoatkwzyxcbvwpskfka
hoqotsvjfmjnnrwlzbhghwpttpvrsdshfcoatkwzyxcbvwpskfka
hoqotsvjfmjnnrwlzbhghwpttpvrsdshfcoatkwzyxcbvwpskfka
agspyiqbjdosddobeipkelchupjdbbmmmpuutfgsodnemcmtmykzfpp
opafcnvo
opafcnvo
agspyiqbjdosddobeipkelchupjdbbmmmpuutfgsodnemcmtmykzfpp
agspyiqbjdosddobeipkelchupjdbbmmmpuutfgsodnemcmtmykzfpp
eovzvnyspuxbnxzqkfrmkodnvfmzkbluerwlysxtiivsnhnqtzw
boovqrhmievqtxvyuuytrbldomeehhtfumvtlzhmbfslprdfrnlytmvjmnahxkfkapeogylgjtf
ppshxwxshlxeqewafygawujhwuguscae
boovqrhmievqtxvyuuytrbldomeehhtfumvtlzhmbfslprdfrnlytmvjmnahxkfkapeogylgjtf
boovqrhmievqtxvyuuytrbldomeehhtfumvtlzhmbfslprdfrnlytmvjmnahxkfkapeogylgjtf
uysrkxwdxnsabuobtsapxyyargvwszjduzghqphpcrdizjxrikwbh
uysrkxwdxnsabuobtsapxyyargvwszjduzghqphpcrdizjxrikwbh
uysrkxwdxnsabuobtsapxyyargvwszjduzghqphpcrdizjxrikwbh
uysrkxwdxnsabuobtsapxyyargvwszjduzghqphpcrdizjxrikwbh
uysrkxwdxnsabuobtsapxyyargvwszjduzghqphpcrdizjxrikwbh
fxstiuvpwbysazuehpjagktdggnpntruptppbrjpsvdtrmtwkizzfizpwojdheunbigfpnyrihavjfkamqcpvhmdclnyqwtkqp
uofhwovlxdmdyaptwjakbynwulqfulqfrqmv
fxstiuvpwbysazuehpjagktdggnpntruptppbrjpsvdtrmtwkizzfizpwojdheunbigfpnyrihavjfkamqcpvhmdclnyqwtkqp
fxstiuvpwbysazuehpjagktdggnpntruptppbrjpsvdtrmtwkizzfizpwojdheunbigfpnyrihavjfkamqcpvhmdclnyqwtkqp
uofhwovlxdmdyaptwjakbynwulqfulqfrqmv
uofhwovlxdmdyaptwjakbynwulqfulqfrqmv
uofhwovlxdmdyaptwjakbynwulqfulqfrqmv
uofhwovlxdmdyaptwjakbynwulqfulqfrqmv
lpykflgdpayxzgasxsrmluiotoyhtwmbspuwlqrgeuufeisbyagegsxuiiwyvvtcvxntsxghz
hrlgqcvxpcpddezxrtypvgqdwvwiolubyyawtydcwvhbxhltomhwezaezleiumawkccexrprjrzlkhrhqwhmldribrlbihwfzsb
ulvejjwgvchrrgycoaphnisojhxmdzdtov
yanksnglfxjyxpefcxcrqxydajxinrqeqamloffdqpibsidlfbqegrqtfrhoomtwovhstwzzbxppgxdefxhnlbthlnvdgbll
lygoiigmcvusccbvwegtmexolibzpchjihvpbbqmnkzzidaixniinuzrphi
ilhcbvdnfbdumipzfcmedwrlwazwiwhpz
xmojjgfwgkmwzntucpwacssslqprkmduxtaogmjhbbrszpufjshpwqymffnxmctfilgdrgasjltkxgaksjcjsflysrcyghvh
czlxsoratffmdvwicvuwyzzenqrwcdvfissvirdwbppnstkfogpxgffdyptqcbmkbuweqy
iylvugbwujgkqupgjjewq
czlxsoratffmdvwicvuwyzzenqrwcdvfissvirdwbppnstkfogpxgffdyptqcbmkbuweqy
czlxsoratffmdvwicvuwyzzenqrwcdvfissvirdwbppnstkfogpxgffdyptqcbmkbuweqy
hezbqquessjsfjvyhjqvraqhzruuzymespdzkbmgyd
stngxuqipqhiwgrqaaxlsquoftwuoyyjaazkylwiydeausmzpbei
hhnwwqoekljfqrixgepaihskjkjlohcziwrjmixrmeaniaevukndbphjoaixjluslachlfmdqdvuovsofchaieornkliildov
lviggfoyhobvngeyvnktjuurvtxmppuedcasbrfgdmafxvnilunbbuiuzo
xrocvvujjvtlgbfoujwcpmtmezyhrm
rmcpuxuqmfywnfoykzofnkqqueqjvymdrkivupiepbqffsktaknhhuiczsdavlskpxwgambxririqxjsvzhrmwugblqwanttb
imabbpldwztlkszminhzwtlsdtdtdzwutixtdilrhhj
alkubhuxxbvhgonkonpkzmglyaeefsfcbnuemwinvcwatzjcoqv
mktasoawvtbnycofhtcpvluvxayhtzpeuwnjjzkwersurhscdsi
mqerknjlrsufglopkkebfybvkekzmawpcjenpuachfmjchftzzkyqllyteemglffknjynugxjk
mdhdwymbtmwmbopzaiavicarcbfslgxzchlhncvd
eeeugovoiqgkkjraqtsqmteqjjdzoxapajskpxlnbfjbywmvzxrimhxthudfjuplfopxvlfjcttilnswzvjfnbmhpq
gqnuqufyaskxqnxululnzwgiuytthrwamvurhxroucuesugxwfjrqjfroougqpjjxtbxf
omvrpdpqnzpywqwgvysfgsebhpvnxwls
citotkbstbozbsvpntacd
jzhynkvyexash
gpkqrnpzknuibyyoqhbzcxcyqwdbsmkjpskzygiwgzbxcketslqjwqyularaoygdcpxmtl
wfmixdcgvesdquspkosjzngjpmwbfvbfirjwicqnfggywfvuocqutikcpnqrpqndhhzqzaeiw
mbzjhrjdcgqiogxtmkupsvfuifkkxqqkrnszwutsvtyamymoqynnqrupixiatpoxfluevtfalttlq
radkenpbqpzoghlfnfxpvctowaksxljxbglibqeyuawahfagmedjklmtyillfbemwbexvojxvoadrslhyay
VirtualProtect
kernel32.dll
K1ZLJgsLFQ9IXeHiVR2VJnA0wVQvLHbL3wijbR8jBWBOnmnNl6ruCWuHknWS5DunM
fqpX6eQwbVPssFTuRdubv6QoMXstLL4wnIgYC5JObL3ibG3GyNPGI5duq5XECPxb2
gTxbgQcV6ARXI0JMzjOW0fusCDdP7cQLwmBORzJLo7BbxOJkspFfLQdAH3c24Ijbs
Ge%G]H
9^A)7^
[tWH\uU
x^C$C]
_ cH\X
#]n;P]23
o^A;%]Q
[]KK8^n
\5h*]q
]A+F\S
^mM|]k
^)zE\
^FTP]$Fc\-o*]~G
Mz]yB[\
bad allocation
string too long
invalid string position
Unknown exception
GAIsProcessorFeaturePresent
KERNEL32
bad exception
EncodePointer
DecodePointer
FlsFree
FlsSetValue
FlsGetValue
FlsAlloc
CorExitProcess
runtime error
TLOSS error
SING error
DOMAIN error
An application has made an attempt to load the C runtime library incorrectly.
Please contact the application's support team for more information.
- Attempt to use MSIL code from this assembly during native code initialization
This indicates a bug in your application. It is most likely the result of calling an MSIL-compiled (/clr) function from a native constructor or from DllMain.
- not enough space for locale information
- Attempt to initialize the CRT more than once.
This indicates a bug in your application.
- CRT not initialized
- unable to initialize heap
- not enough space for lowio initialization
- not enough space for stdio initialization
- pure virtual function call
- not enough space for _onexit/atexit table
- unable to open console device
- unexpected heap error
- unexpected multithread lock error
- not enough space for thread data
This application has requested the Runtime to terminate it in an unusual way.
Please contact the application's support team for more information.
- not enough space for environment
- not enough space for arguments
- floating point support not loaded
Microsoft Visual C++ Runtime Library
<program name unknown>
Runtime Error!
Program:
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
Complete Object Locator'
Class Hierarchy Descriptor'
Base Class Array'
Base Class Descriptor at (
Type Descriptor'
`local static thread guard'
`managed vector copy constructor iterator'
`vector vbase copy constructor iterator'
`vector copy constructor iterator'
`dynamic atexit destructor for '
`dynamic initializer for '
`eh vector vbase copy constructor iterator'
`eh vector copy constructor iterator'
`managed vector destructor iterator'
`managed vector constructor iterator'
`placement delete[] closure'
`placement delete closure'
`omni callsig'
delete[]
new[]
`local vftable constructor closure'
`local vftable'
`udt returning'
`copy constructor closure'
`eh vector vbase constructor iterator'
`eh vector destructor iterator'
`eh vector constructor iterator'
`virtual displacement map'
`vector vbase constructor iterator'
`vector destructor iterator'
`vector constructor iterator'
`scalar deleting destructor'
`default constructor closure'
`vector deleting destructor'
`vbase destructor'
`string'
`local static guard'
`typeof'
`vcall'
`vbtable'
`vftable'
operator
delete
__unaligned
__restrict
__ptr64
__clrcall
__fastcall
__thiscall
__stdcall
__pascal
__cdecl
__based(
GetProcessWindowStation
GetUserObjectInformationA
GetLastActivePopup
GetActiveWindow
MessageBoxA
USER32.DLL
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
HH:mm:ss
dddd, MMMM dd, yyyy
MM/dd/yy
December
November
October
September
August
February
January
Saturday
Friday
Thursday
Wednesday
Tuesday
Monday
Sunday
1#QNAN
1#SNAN
SunMonTueWedThuFriSat
JanFebMarAprMayJunJulAugSepOctNovDec
GetProcAddress
GetModuleHandleA
GetVersion
MultiByteToWideChar
FreeConsole
PrepareTape
EscapeCommFunction
ResetEvent
SetEvent
GetFileInformationByHandle
DeleteAtom
GetCurrentProcessId
InitializeCriticalSection
GetCurrentProcess
GetNativeSystemInfo
CreateEventW
AssignProcessToJobObject
QueryPerformanceFrequency
AddAtomW
CreateFileW
KERNEL32.dll
SHBindToParent
SHBrowseForFolderW
SHGetSettings
SHPathPrepareForWriteW
ShellExecuteW
SHParseDisplayName
SHGetPathFromIDListW
SHGetDiskFreeSpaceExW
Shell_NotifyIconW
DragFinish
SHGetInstanceExplorer
SHELL32.dll
RtlUnwind
RaiseException
GetCommandLineA
GetLastError
HeapFree
GetModuleHandleW
TlsGetValue
TlsAlloc
TlsSetValue
TlsFree
InterlockedIncrement
SetLastError
GetCurrentThreadId
InterlockedDecrement
HeapAlloc
TerminateProcess
UnhandledExceptionFilter
SetUnhandledExceptionFilter
IsDebuggerPresent
ExitProcess
WriteFile
GetStdHandle
GetModuleFileNameA
FreeEnvironmentStringsA
GetEnvironmentStrings
FreeEnvironmentStringsW
WideCharToMultiByte
GetEnvironmentStringsW
SetHandleCount
GetFileType
GetStartupInfoA
DeleteCriticalSection
HeapCreate
VirtualFree
QueryPerformanceCounter
GetTickCount
GetSystemTimeAsFileTime
GetCPInfo
GetACP
GetOEMCP
IsValidCodePage
LeaveCriticalSection
EnterCriticalSection
VirtualAlloc
HeapReAlloc
HeapSize
LoadLibraryA
InitializeCriticalSectionAndSpinCount
LCMapStringA
LCMapStringW
GetStringTypeA
GetStringTypeW
GetLocaleInfoA
"Xoc{#}whaxfn ieahay#ch }ub"ha&CGP!`ngb+
g(xtqc
?&I}(^F
5E^_MM%
2\EIfg
s|q',.q
mN~:>i
^k))`*pK
ot"3Ow
,Wz]3w
6.oWi#
3S<;ht.
yX*9G%
x@'r_sUQ
Aky2qH
ZQ2p-
#FzoMh
4#RH;3
R-&I6:
XO$4RyIg
\255J
[xfS;
Qz$NE+
3W/;S^
XFIB:}
wuv*(\
C[$|y0
s!bytM
=&(`VA
#8G=<H
uo v,G
_(&{"03a&
v"4D
o-,-E0`
90J+Y_1w
aYTM*o
^&g|t-
D%22f_
,Y&hb4
zhNH/5
%|_(o^
*/pv!"-
S,2* 6
jP ~I(|n1]
R[#$p}
5oUh<~
.GIZ,(K
PxZ*0c
!S$&8L
lK[-PSW4c9c
*Z&azC
qU#~SWPb&
ZL(#?~
,c\./#
w \'teg"
2an&
/_/)E.
(m;&u&
'!<Zk<
;?w`5@
%:(Jk&+
(ewa25
0#xhv"a/
/:,">*-
*zjC6,/
]*WugLf>#
C/wrsU`(
*.r2*!$
*q%)8V
{i6%%Z
+)#Q`R
'YC.C%T
!\h7!,yH
u*e>KC
,L^Gw-c
h?$m=$
/" F9$
.}iZi+
='l)Fh
"#-d7^
^v)&|Sd
dZZ*nY
'</i02
*3U"r/
H^Z/@(q
j4V"w$
UB'`7N
:9W!if
,r.=*&
iZ*`]o
P6X/\i
(ST-0Z
6U&(r8
-B]u)]#
/*zn7*
'`g|?Z*D
*ug}_.
Z,0_7if0K
#J2%B%,7
/F1`;W
(x8^k-
)0i?_x9
^e-;o
C#C.5D
.cOflZ/d
_}!X/V
./v2
SE>U&5P
%xi(XY *
](6n50b?n
tU }z]
#j#h*
,\.!\l
QRX/^d
-ZuE7
^%A**B
_[#]dh
Q1b;!I
;N*V3+
'<#vMO
x+ ^h?
$WW !
4|NU&l9
W!a+?vk8b
A,Kh(*'
H_'9Qj
'rEg9/
*Obnp/
%-\^?Z'
C6%(5Ey/
5AA$&
'tT+.
%mllC(
.;#b64
cUw~wd`.]e
mt}eb{-ShrlrwkoRono`}%$`soj}oee&(Uhwtoei>4$4!6 =/!Nuctypd2hb}wslm/'U}hlcl@`v]kfeb8m4;f?k6;4>5>b383'\
}yfl#Rjscwslct&Qtcujj`ZosezyfjZay
WGNWBDZ
aRztqmg.Xjxjz{ghs"Wjpcrxkf_`fbou/ gwli|ajc! Ye~qh`h:<-1#1-7)(Iuf{~wj4jhuxwno 'Z}aaldMo~Woaaa;l:4`8c:6=;2;c70:"^xps`e$Ro|dp}ja~.^pawejoZf~jrtibPe~
R@KVFLS
y7"7$;3>4>
&[~rcalv
%Ysqidc|
(Vlaa`a
tqzcnmPi4?
2>6=0J3OCNMF>20D;>67O0>3>I;EOC?BJ26:G?L1BOC15FM?A8?3==03?8OD>@;7
8@H0672011<6<6?O54;6J9HF2K@71BEO07E49:BHJ:06?AIE42M@;>9K:5A3@HE3
N56E<801=0K9NF981EL52<436@N282L8A8=G:4JFN2ND<80=DCG=A;C2671795B=
KDI02837?77N0FE=;H69K>06:5;79G73O738;IA4D2DA9IEK>>LE4;AI7<13:EA8
=38\X6;U0
wfgcRb<
|w~ndo\o46
<F@5<0M3K54BN3N6:G8I??=F281E>D;>A?:NF:<=?DNF70O5KNG=DD7HD38OE8??
sxphaaX9
mctnX4
CEdzf`}hfael4
dsixg2
Fm|rn<
ryrfnk]c>
t|qhcf\e4:
Mclyj|fby.[la0>
_Amy65
^hJn~7=
:I;GID88571ICF=7CI5;21;=5N<NC=?086H6LA?DK81L0D6>4EF3B82JK39K8<A>
r{tnfd^?
Erkkj2
wfgcRb>
|w~ndo\o44
37E72AL>JKB34362J3D?13J;4<E@0A=NB2?95K<7;585;@9A;03?1C6HC:A?1M4=
FB<FJ584E<C7J:DKE5FC<;BHJ?1>;AI891J:;E8NA=4A73D069FI4K=A0I1<2J12
C?=0G41322MIEK9=A8158A5AK:>>OM1521>L36D33K16=@B58=4?31N1DKGBK474
;8728J19=B>EM=JF?CL<G4F>4HB;EI=;5H870478CJ67L1B?GBI@E4F;8BK;J6K:
:B9G;287;<547EC8FA7:59@?N23O0MB=C8ND4?F0L0BD3;2A<:HC613H351J@JA9
pywnhmX0
yp}o`j\c>
|t~kohYe97
?17F29HFHJ<5=L4?4O67E?2H<;:D12;>BA8<82J<G1OB=6465NB4;@2O3A41N:5>
_jFgp;4
v{qeimW7
vstcid_h0
B;I67NFL3=39LC0<@9L92F@L?69JNDI8340477E<7O>3>7?B;6B9?EJ56<015F>5
2@<D1<GCHD65A>I9L7<6I05KEIAK3:2:0F;526IC;F9<NE8HG@=C:6>6G<06::38
E3F8LC;L>1>00K7?<IF:?N>1>43@HA223G636?@C<EK7?;1>2A15E>42DD?>1=<>
?9<L9J@>FMC99B=<7BHA55=0LD7904=0;68:692A=37440320>4HL34L:5I0?<<6
B3I1?27@I1BBO6:5LKF9;FNB87DME7N548B0A6<<0>6:0N<=;CH4KBOE=MB8<22?
5AH2KG?5B09E9B;@D6E>NG6971C4M;19N<7>M=95:4N6=E2ME;17BOA7BK3L6:I6
;1N54C36@0<18?5G3<K?DKIH49>2K75CNF91?JB=FF2263821M1?:58;9NC4G@J3
{wsdodX0
ytxfebPk1
6;@=;O48>@;2F@N1;BHGK7;=3B;DLC=4EN>?>@6H67F@;;9<=8F;H2;0M@;B969>
=7AE2C@FH==69?ECK7NBJG1<EBN:2H2720180L?H5:H<>0>C=3<B3IA>@>GI?A8<
I6;O1156K7?2G8@D<40<B:A0I943LJ7>1B:4?09FH2OJ:9740K?50978DLH5D4D9
I:1?31?449DBDF<=FO:M6<<5>8;6>28CK8@NC4182;D82776H@E;1>245@;7B;E7
rwulfm_<
xq}`jj_n3
:I4;L7L6D4=D53>FLCO;A692;8:C6M21J;BLE350N2C<9M0<KGID<26GM5HN7;70
=2E7N3>0?4;1N3K7O@4N>B=52:3@7FJ=6KK8C>>AO08=I4M1>I:5DB?:640:<839
|ruamfRc4
v|xidhTr8
AID5CI7>B<<@K354>0F63E9E?H47:D924@5?G>=F1KCE0@=>E;?25<=1KA<C96M?
>E;23E<408<2>@OHFCN0=7M429EFL5B;3GE1MHE=><3?<E;E;GJ2I2=90K1CD?D;
ma{Y[YE9
s{relfP>
{wsdodXg0
5615>0MAL@I6K9@:4>@<>33:=;3?9G5I7M454DN12059=BE1D8;E3:<GJO0;A4A6
sxamjZe?
;Nonqcc0
;G;C>792G9D5N5@840E0N89<:>G=K685N7<0JC3LA<07E=1@B?A716?185ELD80@
4A?A39BB45MH28<37>L0L9I@?2=>KLE?7EC8B2E8EI7JO649484I76JD>>@D50GF
M32::>=?LF?A;282HB8?;4D3B3042IE<1:L7G8DJ5O546E><47OG06=LIA<I;7JH
K3;5MFN>K=5NCBB=7B9H5<4O?@8<DLA9A1>BE<69:D500:>DHKI77J1<6N4N1;AK
\ukt?PtbI3e<oik@t<UuKDcl[OWI
^\GY]A}}v{F<uW:p5QZ6kMib<_B
ZEIf0:u^nGG@
uRnR[v~erW_4yZ@
^R1WqeRp|}0Nb]bGnf|Dk~e?`xjeG
X7HA]k\6o7@WQy9?fW
osGHg?lB
=I87LN9D:KE?99<=1HF2;@I2E2:717I0?59:5CN1I8<4CKBC103NG6440;E:?=AM
[G2=_B:e}=D1Fb>?fK{3f2ZCx5KC
4;8JG0;04N59545F31K7HLN1?:B>14==05AHJ6=A1CI745=EJ6M5@351:2;A2M2D
:25@B16IHBLM=2?8B42HGL6HB9?BI43D86@2IF>BJ:08LB:6?;8;76<17IEA?7=I
UBR]CETod}gE4tt2O6F=s^`OrnlG
>:K@488L7>GE9C2?72K43?C1<9=7=7<LA?9M<80=CI0;5C40931633M>JN53;C=D
31=019BB=E133?:4=9=58?<93<DIG47=?GL6>5=50D8A71<=;7O0N4<F4624>A6I
:5<;LA8;O49HFO7;2>A91>J:43E7<A74K5M4M;6C?F66J79MDA=:B;8@D0L86I8O
7<3OCJ29AIB9L:47BD20;E:3KGJL69NF74J53:2F>41?DA3D<N2=>?F=LB57M58F
e:5Hw_}yo2]DtZoV3kc|wa4WJ
X`zPF0lvwKPzy>\Ou9SGldQnLjbO
\;6u38ItT9F9I_OtDW7=LYsMjK2N
7L1BBCIH7:<JG61<O8H0L3I79:5L2>D;45E;1;GH=7DO66C=01>BC::2:5G0<KKF
xUtEZi=rN
g=0;V1azfrx9VI
^[0M:{[dY1EVBeA|hs6LqmBSomHD
XEi4ES3vI2W3CsxTDzgm:BmYYhOH
XZqw4HkKOXhG^|]NAxg{J;IfGvRM
\jABV@p:hn1Hi^?RNDl@BDpd:TEA
rZK^D`d^~MOi
XLdehM}cihK]lDeOy0o;YuPBP@SG
\>aqG3ecnc~_6wIVgxen@e;KO]VM
XduRClmYKJ[}z]l^:O;47^o2B1L
Vqytob%L@
[JsNHKbMuXRp@5bkIFWgHr6BGDNU
m:EJdwKHaIlBH}N3]:fY
S}urik@xO
J`d^nb3c1xSBaze=CY
aqb`tkaa
~dwXSmxb
\rv{li#Ccicfoscgm~+@cdbqii
KiyconldIi`g@|
N}dmU`in
^gy`nm
Rzd_GZHIp[l>@Ho=
ro;]C6GZ[bi
Rvhd`qnchyba
Ilk|xL{liKiiik
XuceFca
RTQUgGfu0HxdB{uvNVYf|0IY~^|a
Vjon{pba`WH_a|\E>^@vGl}{rkBf
@ade_r`lc
KqdlufNk{~adln
|lpRAyq`PoffmNbab
LnoeGkkc
jfuRUaiomej
XKPiWfQItFS7db@aWPJFf8QYYe`o
Fcpjcxfalo
FBg~sn~amli
E`sedf
_tmsleoFcjgaGhjili
]vbscefY|wcBfmdfa
AkyWx}eIrcoInhcdf
IndKlh`|zVxli
Ij`bYqpy`jGidfsyVzjk
Qdji|t~{@leb{pSxmf
vm~_L`yhMfvie~V{z`b
{fyZPodclwYpvjk
Ssbcjs
bm~_OwXqvea
siqPFtT~qoh
`c~XMaga
uky\Olmj
KguIokmM``d
aldoNkbn
`}GcjkamCdjc
`ftUQ|c|Cblh
hex]Q}idmprC`nb
Y`nmHdni
XqesoDjc`
Eejaida
Janbm@alheld
PfdvdYxsb
}bqvYvbtcf`oX~zm
Lfdcyt@odp}ibYzqh
lobvs`jSqsd
Ffs@domoa
Ibl{jmkcrfEdub}fqe
GgcmfPx~tjmDcskqfzf
^xps`e$Ce}n
Nytaiod{jciYmwyliayEbso
Ii|pcqd
Jvhax`
Fhn~gqOwhqyfaloW{gzh
Ehljti
RY@WowmkdK{
wfkqye
F`n|nfmqJ`icxfwenE{r|datye
GykeNrszjcxuf
Bmdexn
`kJkieMq{qee
`dexJ`h[~fsNokeMvu}oe}wd
EfepomahcnD{}vdbyqj
Gui}tbbfaNrz
OmlYotaamh@wswahu~j
D|za`b`|[jxkoIwywnd
Kw|ccooxYrndio`}mF|wsdcvs`
^axhnqI{e`e{j}hMs~zjopsc
FpsoimjwKjmhVjr
knaGs|qhotwb
IysobiivJkcfebzqmscgmLqstcevto
Nu}hncayKe
asfvsaloLuwulj
Hjbymaaxl`m^bfi{lqnidtBt~vfd{yf
Ls|ea`mvVuggtnuBsqzcb
Nzwhmniv@cwszjjmsG~sqihq{c
Nloku|eh@xNrszjcxuf
D{yegmg|Lfi}ab|Nwxucjvy`
iwigaLic}budbflevxNrszjcxuf
vm~__|nVglhaEt`lvxb
aph}be
XanbLtwd
DjlivdYgk}f
JdwQdd
n<1Afcf-h}b
ybw_Ihfc`yPhwe
_cvyi0bLnPAtIr`~^cd;NhKz6nhj
_qcsXmd
V~u~bn.^l}coijoj
Jnomefh`
@ddmjib
Yyy{nh![qctehj-Zbx{jbknhm
WoHe|c89Pu
P`abhePu
\eS~}bkh
Cht_q}jb`
lj~uhucid
Y}|rk`-E
Jr@`wdm
J`sRojsPkpg
IhwGblke~R`{n
dbqWFedh
VQwS=jlwtRpEt;w~7lS@u{R?ohij
Rt_U;jVn5cJ;3\9`qCIS0{Esd~fm
_fcY[5
aBqd30qKS3e=tA|[fSO}i
PGmk7EKlfFiCzVrNGR~B<zt_U`1g
Ccinnaf
Fhzhqoll
Suqujk)[fbxsjs|&Zrcahl
Suv{fa)Ign}jicdsNonac
sjtSQdlsuawx]slsjkel
Ldk{hmce~F`mxued
^|troj-Sogztgyz/Lcle
qB`hszlm
FfsDkiey|Hja}vbl
VjwMdimp~Fhh~ull
FfaCxo
Kice_vsjgj
Nd`nq~V|xekb
bj}[Dtih
Put~mn
Qad``k
^ayd87Bhmc
`{\_oe
Kwslcgnrgbm
^y|tio/Liinjfxsbslgd
Yvxqjd*Jlcgnoe}k|jbk
Ustweg*]chafbyi`n
O`ag`mndcuLeomitI`gijjpdob
Fmxbxf
UE{VN\}Gx^Md:k
Rj{9DRSEUMYvm
ZxFYiwyCU>7Ja?N6n]H@Y`zA0IYh
FchjO`kl
NuctypdFhag
GdmfT|{~egFec`
whtSV{b~sCfeb
WtedfsyW{g|yJoko
DepdlrhzzHcgl
TSNLb_z_@b`kl_xrdrI5\c@J:~gv
Svsxgl!Jnfr
~dwXV`ewCa_d|bflr
Y|qhdjTofgex
[cvyQdldjr
QqjenioGbmgbw
CEOJY`bhmcdiw
Ayalmq
WbuerqcoInhojfs
SjrzkbjVhamu@`mfbmx
GnedhlihnxJmiid~[flwdnou
Ssw{cc#@nieKoa,B`kwaod
JDjf~acanw
PywbggPqi~a}
Zh{uZrftip
DDmrhmxa~`y
BhjlgihjmxHhbfnqBh
jfrkp`t
JfuHnzmip`{iu
+kite}
ZLacLcZSuiNQZ8;i@>L<qHLGjz@}
vdb(Cabfcnpslky
Yvxqjd*_ubqfni)CfwhwhvYbqvcgju
^zryeb.^wo{ojm-BblsnimxSo}}lllw
Suv{fa)Xmpbpueot
_IlhGm[U{gBYP<:eJ?M>uJALmrC{$ro|dp}ja~
Xd|h?5Gijc+Ato`bt$vjuaxqbhs
Di`thanfdLbeft
Mdugjyd{l@drif{l~no{
Ydtm95Nacj!V|bsd
RjerzfGdmft
Mdugjyd{lBdliv
Fbfhdf[ltskkPtshju
Jfu[acuiL`bct
DdyRveNmsNkbnv
NayP~jlf
~`sYKswrcfzrk~
GdljAxvsfdr|fr
FfsGq~ey
X`{}mcg
Jryff{
j`sYIufa~a_g|lnr
Svsxgl!Ubkvsduz)Fdkig|
Vvzphm"Rfmhh}{-Kjuky
pe~[NszbPblljDeodaungmr
Rztqmg.^jsq![aju`d}Ftwxmp~lhhy
Pyypjk Nlmaeltemo|
jdwXF`kry
Ypa}m`eD`csiuy
V}afroWbrkijrk
ZIA3>]Bcgt{
GdmfFfkosy
rik{S~himp~
AofbPyypjk\ddiys
Rieh|ruqQhjiwt
zcgb{x
|lpRA~bznii~{
H}nu~t
Cejlgz
Qd}ent
Dsjaf|
Llob``eon~MjvjFfgeoq
Nmikof``irEeieip
Ukafby
Rvusmn/Cdw
XwGOqL=|MQCJlD|bF8_q{`~6~0jy
PbqKemzn
lmeaYetq]fbcozjcbCclfvl~
XclNohhn{
_{r{cj&N`c`dbhmdt
Jesf{kcmik{
kb~W@xwucds
GopLs|
ncomtar
Djf|ex{
fbcFizbps
XbpugaCgwbvu
_DLXl9C7FBRb=F@Mq[zoyu^|i>ry
AjyfBbr|
^|troj-To|{
}hw^Yewt
cilWduu
XiP<P^{`n^hSlJuoBij
k}Ei]c`
\ORkCDJ~ubJvDQ<:@8`1k@g:`vir
ye~PHwjhphNcRfmhh}
Hci{imnhucFzq`t
WhDzxas
DujgWxbG`v
^bmapyw~Mo~
gopPG}~flolv
KguLgkdjoj@pt`ehls
L`{L|hcyqfmkFy{f`gk
EooioLi~t
entiFh}cd|lst
Qbbaytxv
vj}[Bpmffwu
ex\Htrgfnwy
YGcfpxacix{
IokmPdntqnqq
FccnVvzphm_`lv~n~q
_``oysqyYals|dwx
CcaeorFbbfwhyx
Plfno}|Bajgpdtu
Ceamp|lv#Ccwj#=)8&3&167:abeo=k
]}juAfjHxo`
wehd\k
`nt%Mdgcan
*Sfhjbtr
Ehxzsdfks%
*=;7>
!k79fn03o(a386.43g;+6lf` bicm0g=7e1ag
;0$?%4690<.;19
#KBRLubmos`te!Ud
sfob?w;(1&2
CzkmoxdwdMm~p`dvMmjo
-C@S&Lubmos`te-7/;.>
6[ss~jf+]lwbu~fjp"Sego~+Trxhmgf}[
~hgShs`u~adMsndgd
7)5&:.:
GJckqbvh`~)Uiyqnj]yvedo!Ehku`tt&Pdyujib{Neyflkj{*^exqfmktYamjib@ckfGojjtoyls
1>.<,1!6
W`~j05Hicn$
SDezFu`Jgci
myg`tkh-eal
60shc)rhr
l`m1%;&3/%bhihgidc2${ye,5"0>
=nutmncax#jdfcfo|
Sj{wdob8-2"7(({`iiu7%vrd>|efhn`~-biopn|ia|.bbl9fve$v;-5
vjnnksAghkso~~#vov|oac>#<.?.<,1-&iind0#N~Dxzlcljqffj#a|u-,2
(#1qusysJnlk/~camr0"zrb8rlnbebr ljdwgyol{&f`d>lsa+y1.9
#-%':yb`uxm{
!- / ,>sjwrmpuheSul~clohnv/qian
8-v~i0{`e`jgy*niiv`uakw,nob:mql!p4*=
!#'%(* *3y`~|a~tiaJ{id
|jbkKc|bo faycb0!idgge
v@ygndbcad!'paKcijxv2+bll
#-%'&*;,rouzc}yfe]rfvendhct6
-!#'9'yeizyl{p:
,%3,xu
{wDkai4
$/:mbnqltfbenh{
'pnmcr>%pzd:ylc`bhw mef}l
hl|.njj<ihnpkpfdgajut.y1.<
&'(#=lqsklkktc`e;
$- ,9 b|wfa`lqnid9
*$3)mbnqltfbenh{
="`pt`ehls1
eaRgdSk
SmeRnfVi4j
_n%Ufll
L?^S]einn
pPPLh`xgpn`~)@L[P\@tbgn|lplZSv5(?$24<58P_E{vDnpllb"brd
.?AVbad_alloc@std@@
.?AVexception@std@@
.?AVlogic_error@std@@
.?AVlength_error@std@@
.?AVout_of_range@std@@
.?AVtype_info@@
.?AVbad_exception@std@@
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v3">
<security>
<requestedPrivileges>
<requestedExecutionLevel
level="requireAdministrator"
uiAccess="False"/>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
DigiCert Inc1
www.digicert.com1$0"
DigiCert Assured ID Root CA0
220801000000Z
311109235959Z0b1
DigiCert Inc1
www.digicert.com1!0
DigiCert Trusted Root G40
]J<0"0i3
v=Y]Bv
http://ocsp.digicert.com0C
7http://cacerts.digicert.com/DigiCertAssuredIDRootCA.crt0E
4http://crl3.digicert.com/DigiCertAssuredIDRootCA.crl0
~qj#k"
(f*^[0
DigiCert Inc1
www.digicert.com1!0
DigiCert Trusted Root G40
220323000000Z
370322235959Z0c1
DigiCert, Inc.1;09
2DigiCert Trusted G4 RSA4096 SHA256 TimeStamping CA0
http://ocsp.digicert.com0A
5http://cacerts.digicert.com/DigiCertTrustedRootG4.crt0C
2http://crl3.digicert.com/DigiCertTrustedRootG4.crl0
DigiCert Inc1
www.digicert.com1!0
DigiCert Trusted Root G40
210429000000Z
360428235959Z0i1
DigiCert, Inc.1A0?
8DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA10
[K]taM?
SA|X=G
http://ocsp.digicert.com0A
5http://cacerts.digicert.com/DigiCertTrustedRootG4.crt0C
2http://crl3.digicert.com/DigiCertTrustedRootG4.crl0
jj@0HK4
DigiCert, Inc.1;09
2DigiCert Trusted G4 RSA4096 SHA256 TimeStamping CA0
220921000000Z
331121235959Z0F1
DigiCert1$0"
DigiCert Timestamp 2022 - 20
Ihttp://crl3.digicert.com/DigiCertTrustedG4RSA4096SHA256TimeStampingCA.crl0
http://ocsp.digicert.com0X
Lhttp://cacerts.digicert.com/DigiCertTrustedG4RSA4096SHA256TimeStampingCA.crt0
DigiCert, Inc.1A0?
8DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA10
220126000000Z
250226235959Z0e1
California1
Irvine1
Razer USA Ltd.1
Razer USA Ltd.0
Mhttp://crl3.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crl0S
Mhttp://crl4.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crl0>
http://www.digicert.com/CPS0
http://ocsp.digicert.com0\
Phttp://cacerts.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crt0
DigiCert, Inc.1A0?
8DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1
&\>(?Nu
DigiCert, Inc.1;09
2DigiCert Trusted G4 RSA4096 SHA256 TimeStamping CA
221121071827Z0/
q#N_:bk99nxz
dGNDF8\FhUiSHp\IFP
XtHSGQnE
7EWeup8\kjd\HJVukucf4
Fcrq95rh#A8bOk_ChB8YvS~Wsj
pMP4\H9IgLohmqK\omuwas
KERNEL32.DLL
mscoree.dll
((((( H
h(((( H
H
VS_VERSION_INFO
StringFileInfo
040904E4
CompanyName
Irrepressibly fathering
FileDescription
Spliced ladylike closely
FileVersion
7.37.198.8
InternalName
Diverted officially
LegalCopyright
Copyright
Squire inexhaustible
LegalTrademarks
Headboards cudgel
OriginalFilename
Unbolted fellowship
ProductName
Endearments dissociating
ProductVersion
7.37.198.8
Comments
Modified by an unpaid evaluation copy of Resource Tuner 2. http://www.heaventools.com
VarFileInfo
Translation
Antivirus Signature
Bkav Clean
Lionic Trojan.Win32.Strab.4!c
tehtris Clean
MicroWorld-eScan Gen:Variant.Doina.54627
ClamAV Clean
FireEye Gen:Variant.Doina.54627
CAT-QuickHeal Clean
ALYac Gen:Variant.Jaik.133193
Cylance unsafe
K7AntiVirus Clean
BitDefender Gen:Variant.Doina.54627
K7GW Clean
CrowdStrike Clean
BitDefenderTheta Clean
VirIT Clean
Cyren W32/Kryptik.JJB.gen!Eldorado
Symantec ML.Attribute.HighConfidence
Elastic malicious (high confidence)
ESET-NOD32 a variant of Win32/Kryptik.HSEV
APEX Malicious
Paloalto generic.ml
Cynet Malicious (score: 99)
Alibaba Trojan:Win32/Strab.d39668bf
NANO-Antivirus Clean
SUPERAntiSpyware Clean
Baidu Clean
DrWeb Trojan.PWS.StealerNET.125
VIPRE Gen:Variant.Doina.54627
TrendMicro TROJ_GEN.R002C0DCU23
Trapmine malicious.high.ml.score
CMC Clean
Sophos Mal/Generic-S
SentinelOne Clean
Jiangmin Clean
Webroot W32.Trojan.Gen
Avira TR/AD.Nekark.dpmlu
MAX malware (ai score=86)
Antiy-AVL Trojan/Win32.Kryptik
Gridinsoft Trojan.Win32.Gen.bot
Arcabit Trojan.Doina.DD563
ViRobot Clean
ZoneAlarm HEUR:Trojan.Win32.Strab.gen
GData Gen:Variant.Doina.54627
Google Detected
AhnLab-V3 Malware/Win32.Generic.C3978116
Acronis Clean
VBA32 Trojan.Kryptik
TACHYON Clean
Malwarebytes Trojan.FakeSig
Zoner Clean
TrendMicro-HouseCall TROJ_GEN.R002C0DCU23
Tencent Win32.Trojan.FalseSign.Hajl
Yandex Clean
Ikarus Trojan.Win32.Crypt
MaxSecure Clean
Fortinet W32/Kryptik.HSEV!tr
Panda Trj/GdSda.A
No IRMA results available.