Static | ZeroBOX

PE Compile Time

2023-04-01 22:21:50

PE Imphash

895e5e6e037e9108574fb94ed614d804

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x00001b1f 0x00000000 0.0
.rdata 0x00003000 0x00001158 0x00000000 0.0
.data 0x00005000 0x00000064 0x00000000 0.0
.lol0 0x00006000 0x00359fbc 0x00000000 0.0
.lol1 0x00360000 0x00000398 0x00000400 3.60622434618
.lol2 0x00361000 0x0060b470 0x0060b600 7.96540699729
.rsrc 0x0096d000 0x00001bdd 0x00001c00 5.07906109485

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x0096e218 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x0096e218 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_GROUP_ICON 0x0096e680 0x00000022 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_VERSION 0x0096e6a4 0x000003bc LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_MANIFEST 0x0096ea60 0x0000017d LANG_ENGLISH SUBLANG_ENGLISH_US XML 1.0 document text

Imports

Library KERNEL32.dll:
0x760000 LoadLibraryW
0x760004 GetProcAddress
0x760008 ReadFile
0x76000c WriteFile
0x760010 lstrlenA
0x760014 WaitForSingleObject
0x760018 LocalAlloc
0x76001c CreateFileW
0x760020 MultiByteToWideChar
0x760024 DeleteFileW
0x760028 CloseHandle
0x76002c ExitProcess
0x760030 CreateProcessW
0x760034 CopyFileW
0x760038 WideCharToMultiByte
0x76003c Sleep
0x760040 GlobalFree
Library SHELL32.dll:
0x760048 SHGetFolderPathW
Library KERNEL32.dll:
0x760054 GetModuleHandleA
0x760058 CreateEventA
0x76005c GetModuleFileNameW
0x760060 TerminateProcess
0x760064 GetCurrentProcess
0x76006c Thread32First
0x760070 GetCurrentProcessId
0x760074 GetCurrentThreadId
0x760078 OpenThread
0x76007c Thread32Next
0x760080 CloseHandle
0x760084 SuspendThread
0x760088 ResumeThread
0x76008c WriteProcessMemory
0x760090 GetSystemInfo
0x760094 VirtualAlloc
0x760098 VirtualProtect
0x76009c VirtualFree
0x7600a8 GetCurrentThread
0x7600b0 Sleep
0x7600b4 LoadLibraryA
0x7600b8 FreeLibrary
0x7600bc GetTickCount
0x7600c8 GlobalFree
0x7600cc LocalAlloc
0x7600d0 LocalFree
0x7600d4 GetProcAddress
0x7600d8 ExitProcess
0x7600ec GetModuleHandleW
0x7600f0 LoadResource
0x7600f4 MultiByteToWideChar
0x7600f8 FindResourceExW
0x7600fc FindResourceExA
0x760100 WideCharToMultiByte
0x760104 GetThreadLocale
0x760108 GetUserDefaultLCID
0x760110 EnumResourceNamesA
0x760114 EnumResourceNamesW
0x760120 EnumResourceTypesA
0x760124 EnumResourceTypesW
0x760128 CreateFileW
0x76012c LoadLibraryW
0x760130 GetLastError
0x760134 FlushFileBuffers
0x760138 WriteConsoleW
0x76013c SetStdHandle
0x760144 DecodePointer
0x760148 GetCommandLineA
0x76014c RaiseException
0x760150 HeapFree
0x760154 GetCPInfo
0x760160 GetACP
0x760164 GetOEMCP
0x760168 IsValidCodePage
0x76016c EncodePointer
0x760170 TlsAlloc
0x760174 TlsGetValue
0x760178 TlsSetValue
0x76017c TlsFree
0x760180 SetLastError
0x76018c IsDebuggerPresent
0x760190 HeapAlloc
0x760194 LCMapStringW
0x760198 GetStringTypeW
0x76019c SetHandleCount
0x7601a0 GetStdHandle
0x7601a8 GetFileType
0x7601ac GetStartupInfoW
0x7601b0 GetModuleFileNameA
0x7601bc HeapCreate
0x7601c0 HeapDestroy
0x7601c8 HeapSize
0x7601cc WriteFile
0x7601d0 RtlUnwind
0x7601d4 SetFilePointer
0x7601d8 GetConsoleCP
0x7601dc GetConsoleMode
0x7601e0 HeapReAlloc
0x7601e4 VirtualQuery
Library USER32.dll:
0x7601ec CharUpperBuffW
Library KERNEL32.dll:
0x7601f4 LocalAlloc
0x7601f8 LocalFree
0x7601fc GetModuleFileNameW
0x760200 ExitProcess
0x760204 LoadLibraryA
0x760208 GetModuleHandleA
0x76020c GetProcAddress

!This program cannot be run in DOS mode.
`.rdata
@.data
`.lol1
`.rsrc
aW>]>l
AQ14$D
kK)bJRM
1<$AYA
DG<Tt@K
iCx'YD
y*4U(#
r+%%B,R
_/aVo(
7vK\TW
V6^5'd
!>1;'
hr{kO{.
1,$AYHc
iD1$$AYA
gk?UMc
Vq'C&x
t$ ;-JP
L51i~O
fk 'UL
BZaw<X
d$ zuQ0
B=fwr7f
npdC-"
}P-J'?
E<"d!u
`KOo"U
bHH!{*<
g|*75'
wue0Hy
4*jvol
w9{wdL
BB5"rEB
C!m.DV
#.)lr'
oFqQ_A
t.,SD)[
Y*h i-
BVGv{i
29tqp!
W+*8/h
w@Qxd=
LocalFree
DRx1DX/
HZq6a,j4
VirtualQuery
s@!5ytl
D$@f!t$@
L$@pqC
WY+hg^\
X?';_H
j4#i;=
657&g<
L1vj|6
Anvuqi
JmqiTB>\
0T*jN\
=Pb7lw
mi*%ifi
Dm>"LAo
CiZX^D
czfp^
3{oCIv
k/n\x
Z4x"Yg
,m`re8
AQD14$fE
AQD1,$fA
(v4NUS
zIE.!`
eql+C`
\RQb2sg
Aj+|%k
Ew@&O
MFHQ!d>M
f+l$$H
Eu:xJ0F
D<":S
kA7Sjc
+7R_X>LP6
X0!{,:
Thread32Next
AQD14$fE
D1,$fE
Mt$0fE#
b\`oN1
[;q!Dd
}[Te-y
Lrhgjy=E
SrhnSf=EPs
GetModuleFileNameA
FlushFileBuffers
<F;{Sv
PWf4p32R
D14$AY
AQD14$AYMc
>3JZ-w
7^;u%7
fDF")#
F5@^7:
D]t<cmDc>3
D$@1a(
M>D<}93
?Ps!8'
pSL=!Z
,RXr}[
{R]MKU*
gtnL6}
Aq;OqvL
i@h#a*
/F`Nu<c
r80h}NW"KL
S}ghK6
`X__>%
KFhhPU
e3wHH$"l
u`?g/
7I=Fnq
Pk<?R&
2)w^ <
vE`]xM
}zk^1VF
mTmx=.e
U1DIwP-
^P6-no
Y}P]p-
+`:G`Z
D1$$AYI
v@`eN<
O>*6a
Z\rl#an
CD1$$fE
Hl44Y
z<&K@i>
S-td|,p
\l/-g!
KK^+AVtV+
,/!U}&
`GyhP@
B)T!E^
{/$jK(S
b7]?&%
;d&"j|1
C-rAim
5D'Stv
MEFK~V
4D2$Iq
NVC7pCB#R
'_o~Um\
L%CQ-i
zgJwMAP
v_f;t$
6}l"E5
0zn?A:
ZZS=mZ
F7kXjl
.D/A6o~6R
$`ITui
/aX$f/
s`LkCg;
b!:['8
/.rw^{|
vAQ1<$fE
h=LUXeG/
[TL@utt
Xul\,;
6irv'T
-,OZYW,%=
G~Q4Xi
nDB^"U6-
||W7+e
*!U)\C
{p;j*y
'q/%vx
]unimr
#-5}CB]
t(<|L
em)0i!$
CharUpperBuffW
*}cSfD
4RAQD1
=)SSC*
H-VhJ8
i/E(qr
C_Zl{\b
:2Jnk;
f3^!7:
_Bo7X5
[^V kY!
7m,0h
m2OQ]58
RtlUnwind
yA7XIF@
5)oed
i({*8!
TEs+dB
,:f#+M
b)jZR.
^<5zJ
|6"3|Yo
o`c@+'
|?dKno
P'"zkF\
g7CPgfT
_}0Uwc
rg[Wdz
=L<:^W
hHuae7
Y=6yx!P
Si$8UA8%
3'iKkR
timo_7
y<FJ*X
[V-Yf-
B?xYKK
-i_!/fr
:r7iB<
iUf)\$
D$ z!\$
y~pR:VNs+
|gH2<cp
{hP//ykm?J
TlsAlloc
fD+L$(L
l!o.TZ
nPBT*mW'h
H~=w80
:-!AQH
5h9M8I
UnhandledExceptionFilter
y:[dj4=o+`
FwK%e>,
s9ds@0
DK9@RYt
$t*/RjI
:7uit*
5<qc%ue
;(rS=+
pcI!,R3
@xJcR"
vs]Z C4
i*vsEi
I[sMPYY
khfy-DP
4]egz!//
5("|8-
z5LkLI
Uq`+bP
\78MQj
S"fK?}O
G=Sf(g
A^A[_fE
OK#mEqM
n4YkB-
>X2:hL
_NCvi:
twhGW#
sUUM>j
W7:S-k
{nfpCV}
AQD1$$A
5&p*<f
AQ1,$A
"f@s<Z%
pu#>tJ
s>GCw:
D$(U@Jd
AX[A^I
t~l:ox
0AYiq7
0C5R:{Q;
OuxriC
JTzQ=,
yqU?3C
s<WDQ%2
:2VVrt
'8Ka[5
xbar)
#& +~%
sG`qzOA
pg!=\-;
[+?w_^
Zifm9`i
;Nz.eY
]\ONo6
5fU/o.
A.7Q$~
hisYGE
~/p&yX
TlsFree
bqtLa,
?)[B{]s
-eE?q5Ya
[|hFkn3E,_
d<%G?(j
RzWtl4
^|hrOk3E
Q!;zx`;
1<$AYHc
j`~+r+
IUvJ&}i
0jtEfV
rtnOZ8w
RR=8o(
AQ1,$D#
T8%B,J3
ruiBf
]C51i~O
y^_E@e
!N+\Q7
)Z^v^L
AQD14$E
FhD)W^=
HS*r-W
bmID3d
ilX4Yk/
Xt7K#xG7
Vmu3{7e
KzR>MW
{dPB0P
yRZD?~0
$5&p*<
AQ1,$D:
xB1P&3
O9`DKc
heSQN~
D$DvY6
V_<iAU
V[#$ r;
|yOGf;
GAD1$$A
}u7IFM
s8p\qs>
60^X9
sG*SqsX
:4[Rs:
]e&k@H
#`/FxR
2VnA#[
sRwPND"
9-Z"):
WWQ/K+?G
LQ}!'y
!\/hY{
8?Acj>
K7$]g
-()u#;
b#n>UeX
2V]t/
}GzSRy
KTe>nN
yh\xz7f
d&fd~q
,P34@GT
q4z6p~
z>!6O)} 24
@sP_SA
//wVM2
PY77Hpf
A^A[_fA
k9LkOn
|2fy9h/
_j7C0j
aF[4=d
d)dh:_
grQXJh
>%?Oo,
rMgrBJ
H7N3O@
i%:pY"M
;*\^7>
5~"j<5
Et%WP:
%o+A=c
f0}g0R
M.kOQ_
g/okS`
CiFMd1)
r~m[2U+
PiB61%
8Q1X%?
;ENj&=W@#
gJ\5`=
#,N{5p4
Ls!Is
JB&Dn0
/Lg'&[
{@mDB1
@R0dy/
++kXf$
I\\|Be
id\q6B3(
3B`C_m)
`z.Qv8
Xgf-~q<
K/1SsKJj
Dwxr|g
udQ:[{}6
&lEe81
k~{bxe>
V"u&V(
bTVw`I
J}@['&
-i^5Au
livQ/i
x{2agx
dAL'BFb
)%sqZ.;k,
B]4R*F
$^Kur4u
xN*3b0I
OT~M+J
2UiFt?Y&
H]%gQ[
F{~k&B
ibH+'#+
K]^BI>W
@h%Q?5c
> ;"N
VIUB3m
AHf3RX
6u9vM3
eLQ8QI
=/]OP}3
TlsGetValue
aB\WuK
.~ _[/
M/xCh4
V&fcoc
WaitForSingleObject
D1$$AY
EsEt(Y'
+"OTCBv
HOFGlw9%
bFdCwg
|y|}vw
D{DFLz{
3,geY:RaM
H&8gWH
LC->~wh
M9*aH2
.R9,_/
W-k~(
4`A]E7
V3~>?VU
.XHh-c
En5eKd
h.:)Sj
zJ[\+C
G'S]w $
qKJ,AL=
l$4dMq>f
^Q x(k
o-gWz'&0
Vl9d_<K
AQ1,$AY
8|K5^HV
p$=~%Z
lAQ%eCt
A]A_AZ
D1,$fD
/&5pxj
LocalAlloc
z)r.j#
=8sn@!9s(X
twPXY{
+,v)F[
%)n-4
[Q{6-[@
j@ 4BT
XG5LV6S
DNQx8k{
Rn!ij4=c,
@Osp!A
wJ*l2
e)lgr%
2f=]j;
.rlqE3-
]2,<q0]
/(qEv
<9sB?=
ir4@we
z8515E
uY\k@d7$(
Yx`"@e
C;gbU=
{VTW:N
Lrx]&;
4'&Xq3
ue#w=1
L5BPX(6
(jQ~\$
i&X@Y!/
_JA1oM6
KU~3L"
T$ +\$
Etf5us
hp"FXwU
3=iAQA
Gb?(IT
kWUW;|
InterlockedDecrement
@51i~O
d$,<X 6
fD)T$(O
n\*L$
AQD1$$I
1{,0Z~
rL9]&9
v<d7KU
CopyFileW
D1$$fE
L$(f1L$(
KzN=x(
HeapDestroy
K&vH#L$
1Whw:Ad
LoadLibraryA
L9kvkP
L1D$ f
jllb]_
*02jq
:1bYAX
XEVwg'
Z6Cv7N??
)^NHYo
WD@[Ap-VSU
/.nLo>:Z(
'fh~3'>
UMCO_NT^
Rn"iEr]"
D}K<]6L
O(6|hK
tTW)N:
xoV)^D4;
nb\JU&
tI>~2
4eS;]6
hrV<iV+
.lg-58
cF;Tkf
'mBqF7
AQD14$fD
=V?n#<*
K:uvJE
k3bKr(
V-G+r)
SO6aC=
B`GLP/
[V}~k}V
Sn)C:v
GetOEMCP
h\O(o|
D1,$AYMc
3eEW^z
@p#}/Z
[PTZ36
oC!O/F
6G2{qq.
BgV}hC
gB\F<
SEXk0lp
.4<T7<
;&4s*j
&9wv|$
ok/qvw
-!M\TVx
D14$AYA
Uf\1e>_3
Ip[q1T
]p$IQc]]
< 3%cb
_Gzt,YD
B2G2y:
law>Oo
5h'_[H
`\go_$:!
88'AZ[
]zeQy0
bgodO
D1,$AYMc
LoadResource
IRb8T,
u)@jLU{
!;'1%x
p]Cu@:\PD
;t-+.C
;hVq$|
pD"7=:
@51i~O
o\m<dr
sfna#k%
eZ0O)3
H%9[nU!O
?H3Q|N)O'
*6mkig
f+O(gQ
3|UE<(n
AQ1,$fE
%>JGJf
oE@5(W
iOi|Ai
joI.N0+U
$Z/%*;y~/
O=3P&O
`6xP.+2i
il~!?7
Geki6Q
+Lsec"
^LUe_U
]5O^.$
<`>'lH
h/-.+Q
akb%bK
]%4N0WX'
g"6"1?D
*[6VB;
^i7WD
R0p+y&
QdGi9PK
bCp;;V(
{PTJ\9$
OtbiQG'O
T$$f)|$ UV
.,z,+?
GiE84}i
pc%%39
'heMgo
CV?rBv9
3E.&`
%ti-2_+[pf>
msP~H{
tnAFY3
15i7!4
`-}xb4
GetCommandLineA
<qbOUT
)l&R w
2$)mZ
"gU=$EV
;C4d $p[u
"E;ELI
tQ6359
;3Rw,c
ORaP[zzi@
W-K*_XL
"7ODM1=
8;;'/Z
J$%/Z;(
AQ14$fA
;42c8a
A^A[fA
gQ1D+x
?fo[mm
kLk3[^
&|CJk"
Fe,|yS
=(#Ox/
sBSGQ@
8/&Fol
2XW:"0
d!s/~[
lQ%O}kvYG
;9]5{$
B5AIQL
1zliX=
AQ1<$AY
Dt!hP
}(3{_-
5|;<$n})f!
37 g1Bz
w)wXVw
sJP'Ts=#
7_<@WWf9|$
4#BX;\
GetStartupInfoW
4]{xS@
Wihm}]R-
3iQK(U
i{r;siI
@C:]22R
^Ea>#7d
c9-\\
Zhp>iX\
p).U"s
t$ !\$
[epig
>`miDy5>
uSVXhv
_7lDf*
;f)>0]q
sPPTZ
0a%G~
9doW=B
m*2"pd
(2$V/2
C8`qO=i
`P1c@u.I
(Xmd!v
b[D;Wg
a,LDquW0
W~.h@/
pj@#x%
5EmMES
6p5t2_
t:S/aD
8WW<Si
WAsXTde
z^Og+W
&_[(wV
G3Gfw40
2S)+5$
1,$AYH
}|2]_K6
w/8`:"m
rzUIYnY
D^K`k{K
LoadLibraryA
Gal;js
`+LA<3
H3USGG
w^'0/X
*Y3HQ(
BB|&jr
9R/7(?Lbmy
z/8(I1
4'vf#
0Qs92,Ps]>-
6VJh ~
=:}bV]$
`BLI%W
:/IW4e
VirtualAlloc
D$89|$8
=FRTTc
pV[Bc$Q
w8D_^J2?
}{RwFY
W1t'CR
]MV[[M
v;zI{s
;N$:E+
AQ14$AY
p.%<*&
#$:Z.2
LeaveCriticalSection
vM"gG]
XUnC!Tw
q-`Nxr
AQD1$$A
id4XT~
}zhk6H5E
AQD1$$fE
O&fRmI
4.PEfN!
2'k9l
AQ1<$I
.>{AYHc
xHRMFp
& s&`wk
vM1Zjg
tMKbV|
TNA:1Q
@{0sl"
eW?V3T$
AC1jV}J
:U~fzP
W{KgF^
p/Q2;F
4sONK8/
:OI+KE
FpP5E3
GetProcessAffinityMask
g0[A8$
WA19v7
L4;]it
ndz#kC
%)A%BL
~^UXc]
iMylRl
6W2dbJ%%
>*1 dd
3>qc m
4Y57gl
=%ak.'
wY.va
A\`<D'Z
X-/rFY
F\GKkT
FWXNkT`
j-^e;$
6,J*g%
W@VdgG!
AB+;F5
)) .h
D$ %l}`
OMGb7.
Xx(}}
}t`;pz
ynF-o$
ECQBA:
,U#n_y
D$<$uf
*Z<S3<
NVLzQnH
eR{;}V
sb`2+w]
LX>:XXn
_s(NFK
km;Bbc
GetSystemTimeAsFileTime
D1$$fE
yh$C(a
_mq@oj
ri53BnB
3>t)NK
x0X?H7/
N\AN~[6
rC%X@~LMZC
B}GiOp
}~;8p
8^pv-.
#Qtvv%zzv
RZQ5e}o
1Y'nf;
qb_C k
zcN3Jd9
]EQa!rp
EW8.O=j
2oZ$Gdy
9if=}{
~,W=]2N
kL=_/<C
AQ1<$AY
AQ14$AY
OPM8r'
Js t]4
?pXcRP
TQvb)%W
*' Sj7
EncodePointer
xew<Hb
Ua3OefD
[MQ,}7
:|!u}E
[`6_K}
6LC\[.
f=<Cf;
SetUnhandledExceptionFilter
iL.YKh
y%S\(,
DH[]tO,
r$B,B#5
w~_%P{
?,nd{d
a@d/k"
D1,$AYD
Wjs6-:S
`P)5VarE9
D[;yz-
=A=4{u
;C~^.e
FcPS:K
:Q^=k,
Et>Pa{
Hm4~(o
5R:{Q3
w9>#pN
D14$AY
D1$$E+
Eq8a@L@"
0#OQD&
mi@X"L
P&DTh`
Y?F8^H
y\ozI[
547Gd=
b42xR3E
4RAQD1
QAQD1$$AY
y;+Up
4Hu(_sy
i7t6E}H
@c)zjE
7VmE\F
_<R)z%
4vi-KT
FkD+jT|
FI~.jTF
kL5tRLi
S,'MJz
}XMh,Q
!YY'pP
@5Eip22
4Q&,3&
FrGO&3A
WideCharToMultiByte
AQ1<$AYHc
iE`&2*l
T:m]1@
]dvw!>~
y>!ad>
D1,$fA
AQD1$$fA
-9XF>;
$|z?+r
f3t$.f
t$@f9t$$
5uls*9
_gbvH`R
o`25wMVY
D\@G8"
:ur_phM
3bLlV|
QueryPerformanceCounter
wAgtW]
jiqFz@
pQSXmS
!h[`U$
j}T=SO
hG*V!Ec
0{m@3]
Ou'2g|
+zS"zs
w{Gm&r
M@ev;S
&1,$fD
W:sHk)
V2+n[s
+4N"~o'.+
<8HE4<M
kC&e>>
l$L7["yf
NDQ(paq
9*fGQ<+
DecodePointer
sgccJv
KhT/LNo
-<|SHq+
-`7$+3
7Xel`D
G_5-b
SVEP/[
A{k4z1
8v5#<]
]K=L9@t
"0;:MS
D$PH9|$H@
\1;#(t3"(
AQ1<$fE
8 +vEs
1A_AZ@
zGI8}0
v$I,)4
v]SFO`:
>(h&\$
9xrmbdJ
nhp^^u
p*!^9,
icAQD1$$D
1,$AYHc
3=iAQ1
&JJu;Y
^=<XUD
X^*N.'
`k+$f#
J9 @[5
9jZ^Sk
XrIYe[
.F=6<9
oEAX~\%$D
0XXoE6
o}+}bK
&"XGqX
%s}k]P&
! Yr)h
D14$fE
AY<_Mc
GetConsoleCP
xAGhXL
g1Perw*jO
C?!y;j
[zI@.8
BG? u*
mwFK4R
M:Y#+\f
JV*\wXV1
M<<lR'
9Z8*o[
7Zb#|<t
YMpARA
H,0,b4
]ud0d
v{wm'r
*zc"{s
P~"n`yU
i(B|5Y
_4C0{qc
n)B,q^
l2qi\N
Il0:eE
SqX[Fp
sEf!\$
}f+L$ f
D$(n]H
AQ1,$E
<AYfE;
h['50+
qr+8)F
~|Tt|`k,
}qCZV6i
+Xa)fc/9
![Z<r}
%#rYZ
u/:=rX
Qt;uasL
<}DFL4
CBpN(
(~?:Z?"m
6rr'WJ
%O6mBE
fh)z?2
j9<4rT
u?%H}S
D1,$AYMc
>]n71
B0)_+
dAmp79HK
u-+ie+
O_^XRY
TVZ`\A
'IE)$r
GYdAQA
t2PA;`
tQ~NJ|
(IsvdV
e\~+}
AQD14$A
`pE:6e
8Ec>mQf
R!P7A,e
*Xh!l.
_|xfct
D$4+jSp
IsValidCodePage
]:z!Lw
8ok/3Y
Oh\Zw
D FD '
mIzg5"Z
<c.`*^
Gv,E'h-,
{I^wxM
ryVQ&5LE
}Y4oa5
}B:AQA
ZW@es7
24;4A`
Qdcb564
%=f9t$
GetModuleFileNameW
F\{Lv[
{1sM*8
kX??[_H
p0b=@7
]4&Nm3Q
A]A_fA
g+{ufl
7) DOH
c3^pF"&2
P]f1t$
LoadLibraryW
|~]i-w
iZu\N8
ofJ]2SJ
00/PHo
q\J[#j
kv';\.M
o`d]=F
uvC^;;
0n,n)o
(RF%*O
goIc@}
Z%e=~{
A-uAN/
j%4Fk!
L`VBw+
YZ/B4,0
WT+O9n7:V
D L$hN
$fki<
QY."%-
D@TiZu
Hg2(N7
/Lh>ih3h
D$$8cV
t$0j L$
"AnQ].
<rtk{[xY
c$8l$(
s}4NZY
s&|f;
>oo/{D
xROQ+j\
>FV"{D
vZI`Y'
vZLW 3W
-`:\SH8
lw.N4/:
Er%bH]b
x1b_@@=x
KERNEL32.dll
*.>xZ3
~A9N[yf
jfP3<9
]I8MzV
'M5\4
Us/:5({DL
|MWLf;
}GH'Mc
K)Hrz2
sJ aUs
oS0e^x
7HtMEu$v
ZyQyj~&
)YM:I
D-1oEj
:2}u@~
dZH;&a
3!MaX@
b4";NF
|$ f)T$
q=0\A:G
=Uhal\
aT|.0]
\9t/l>
GQ)-wV^
P=b+WJ
jUm^ZR
tX((I;
D1$$fA
CG&Gpz
q%zBF+Gv
D1,$fA
m@f!L$,
b_G(L$
05'0W(
.UZc^.
iZjWf8
HeapReAlloc
!meD}))_
,bJF!6
!^VM})
28XxYe
l-VGvh{V>BO
Odqv1f
75H2f]:
~34yqC3
DN}HB6
fJYVPL
njfQVt
Hc]wL
opXr;
+Ug4/<
kxdqiA?
7E#/2I
1f!rOP
fwH-r@
<tTFW"7
/ghsFZ
7xR]2T_
nc}X^"M
8I0f2\
Z0<3Z@
IL)EOK
bqu.&;
HeapAlloc
/"}7K7
L+Wu@^
:wDS>,Xv
]/pwX-
i7F#n@
blgzRk
f>PU3g@
4)*`GH
8`<WF^
Ubk!/]
i^;dC7
uN\z(h
!@Hzn)0N
cXo:-i
$U$jag
6Uu;n8
hBxT$f
VirtualProtect
oAQD1$$fA
~W.lg2;
?I[9Ri
uQEiK|\
'jA)+\$
EA=uZH
C&lK@K9
(\#!NC
19pK(5[
oa:gKT
ExitProcess
OX0.,T%4
"#7VW>
}7\bjog
+Lwg6C
07`jz]
!AL4nI
8E1p[j
-8RnO
E$[)CZ3
Q51i~O
InterlockedIncrement
/}(r]c
Y$ aj&
!; kh^
\$(+t$$
E,hgu+
$@t)uI
xA`f)H
/AeYF
^D5enCB
E!*2BV
i5j5Ii
uZOrc$
XF)I,?
Hd,(1v
*|! lP
vA[uUt
f)a1|m
mpMIhW(
mzRw@Q
rc4j0d9
f`<2tY
J.H,%W
gm</U~
?5(+:&4
=Z@!{P
B8+i7c
h;O(3c
'P/)4,
#.a*X(
APA*CA
;@}UY=+
0x/8aq
ly;w=p
J|ntz{
t$<3|$T
xLlyHK
4$4De-
I<E9NK
c$1{S#F
U;4E92
EIr}?W
sA"nJs
.9Pl0R
{f}>}9
9 b*L$
SB45|sC
*jJrsz
:Xe9L
UT4"R2
zf[crD
LX]kFb
}o\U,
|#uJUr
$9*Lq8
f>m,,q
i+u~[N^
AQ1,$fA
D1$$AY@
jRp}s5
%?8$qD
V[Ka&Ej
aP J4U
FmIx37
IU@2\$
0OHAQfA
"IWawZ
6:wr)
IAQD1$$I
('XsZ-
_*QU@_I<
RTcx>U
!2p}Zr
ktC3~%
b,}?U9
i49cF
(WpVMk
Qi]&cB
w.ME7VK
~pL;cT
k]XGt|
>N.eeD
x \;L$
IM8iAShP
%^Dh-
zZxAd+
Skce%BC
VeGo9X
Q]vo3Bw=
J8lZ4\
AQ14$AYfE
55OO>f
H5R:{Qf
QG7@[6~
GlobalFree
7'm}=E
bFP[Z2
YkCi@v
\RBbQ6rC
@$2FY%
5D&/C
RD1,$A
PI/X[]
^D6tO
GetModuleHandleA
7]{LN*
kZlQ*:
fA6y9L
NCZPW^
NRbF[L
E Y2e@
zBhp4
Dh]1"=
<BJH{O
i>!y*u
D14$AY
pYQR:Z
$#94W-
wab43Z
{Z{Vq*
!KvF1]
ExitProcess
AQ14$fD
GFJT<DC
a<>8a1n>
bAnR`q
8Tp1<3
AQ14$fA
{ZhQc*
x*:Zh7C"
]/Z3e1
(do[
B;6 R}
|8&e2&
`1Rn@k^
t.f.D)
dG*\5N
Y*"]i-U
oF;,_AL
^@$MK#
Vi/qkX
+bJ6pY'9
TjM%+|
#y(nv'0
0D1$$AYMc
(u;_MU@
73{R#_bI
be373l
>d'xom
D`f4tg
id"GYcU
&AQD1$$
?Of \q
t*N[`B
{v20W[
g2\$tH
\$tD;\$sf
#5R:{Q
Z3 EN%
-CB?WJ
G2=~X9U
3=iAQD
1#urv=V
|FuFmi*
Q4REa3%
lYZD=P
gXK4W_<
eX!^G
#>E;A7
Xi%q;
HKWJkc>=
FbNrm$Tb
>p=Doy
uhG(r
ip8{YwO
>Bzx-(
YE^IHb
~PG>5
CxzD@$
Q,-^E#
0ae?ah
l`qp=i
Je$szbS
d0<&cG
+T$0f+T$2
qed1T$0f
SK2Cz~{r
XyHZF(
%Dc&i1
)B,9\$(
+8r`n3
8UDW_$
<H4wHsRWO
%I$.,1
#D+K
D1,$fA
AQD1$$L
$)^6u1q
8i9~JE)
4|ZZ-/
m"/If;
q&cj9'
k//=4F
X"3?2/$
z}Ch^V
n']kAx
J]jF+?1
P%uFEMI
,wx9}~
r-::uZ
Vs9uftN
[DC[mj\E
X.D^`e
!iuX,B}
@riW}c
RukQ@FY
&ay S!u
4nym@}zU
Q()/f0
&=zF?#Q
vTFUV\
}bB0b!
^1~hIG
yLX-9
9:<kq9AG
AS?2w_
9c`,j~
P9v8vVr
D$ ,~S_
zQVh$#
GetStdHandle
>?xSo6
rW nBPW
:-P(=Z
D;9t<N
i?}lY8
klS[f#
D14$AYMc
f'Oq'.
KD*d$'fD;
T$!fA;
iGl{8N
5Fx4dO
T*dzd-
C-7#DZ
/-v/VY
C,7<1b5m
a0k`#0
>X&wKE
D14$fA
IsProcessorFeaturePresent
S0cTdo
fF2SEAP
/Ts7f1\$
-)3q=+
-8:MAQ
(~p 2G
Nt$d3}t
FTIYx|>
='_^!p
-`7$+f;
w$=I%,
~6q8r;9
VY)W]*/
x"O X}
cJhKAHa
AQD14$L#
Thread32First
U^%8+F
{H{#"
W2 nq(
MSs{(z
{l# dl'
EnterCriticalSection
!\$$!\$$
gw*<sO2/
Ffj8%T
HKocmk
n['!=
cX|>d/
RbL3be;
"L$4H3L$0
#yiJ1i
eMeqTYh
$N6["6
^phXt
2(K%pf
$25>6*
4\ES-S
.h{V>f
xV4m3}a
)AQD1,$Lc
7wO)[t??
D1,$fE;
TkE.NQ
uWgFkI2
$9(jj2
FL@*$+
*/K[d
O>Kqj}
E]'eML
uo5@PU\5
GetProcAddress
@Vy1Pu
GJL"NK
:gxFh~
D14$AY
*_km6~
I-~Yzl
T@7hfQ
JoY:7O
M=(obg
3L>v38
w?NdFJ
<085L@g
KH>_i;
xIan@"
g'`!L$
>^n,$(
Vk2\/4
=[PA-#
AQD1$$A
OauwLI
EW_Yup
(g>}'E
[3!*JV3l
u-+ie+
\$$3T$$f
="wF#f
2N,R1d
<dzFA
AQ1<$A
D$ sOAw
FQ~~H*5
Dvwb?-
gMY`A0M
DI>.WT
[[b-2A
1,$AYHc
mZX}c<
bt/e,t
)}d$J&
j[PCej
]5P:mm
!|Ob9G
\]'vr@
"QS@WA<
n(APuD3(l
@/4a-Ai
&gw}8qU
+qZiETgY
AQ1<$A
AQD14$AYMc
D1$$fD#
-C`gl=
f8}Pc#L
P9]LM
%r6"f;
:f+t$!f
M{kM<B.
*%czfw
"P]$a-f
>p_'imR;
[=@.g"
!TT%j)
zvu,$w~
q"L7B
L,yI8H
({k<"k
kAQAVI
*[mc7qQ(
0I1g{9
Q]nqZh
*V,ex0
`. DG
\rT\Rt
zgV,xW}X
^O@EW3
IM*qZx
r'$hFw
iyF@8p
R-'XiN
DoGTB(
c;:/:u
:g.L.N
=cC+Ls
WZm#[A
iPaagy
O4rU_J
f,v]4n!
C*eS=B
EQhl_t:
vp']~+
GetModuleHandleW
RX7s:k
4YghIsr
ZCC7Wn
FF?yDm
PWG>`?
`DA@Ld
>y)>|D
J |EqB
<sC"!=
\ke%_;-
VAVAQR
HwU*tX7<
GetACP
cPE8T)h
U.0%G]
L}nC|J
o#o*&8
'($K7>HP
!G\5vl
^jGHR+
mMxrBR
3DE*(
:^3(%o~/|
bSpC9Z
CHekdC
e`qgf;
1\$0f1l$0
AQD14$fA
-!uy8>
i.h s"O*
`ESl:J
%yohFD
Ep=lHv
VVfEG
hk("pjUAG
WyF;7;
MwLrc%1
\M@`$1
*Z</M"fZ
RQGiDg
{o={oZ
M@xFdh,
W8gFZE
FindResourceExW
(qj/yx
tp~`%y
Ru+cbr\
t?,>sH
s*{vNs
L{T5`H+
<vi$;*
/c_/(
"Bk^sK
n*3c^-D
uBnaEE
G>]4@I
D1,$AYMc
e3~P)aT^
t$4bNf
D$4ej[K
t$41sG;
>%fgM+
H&sCq~}
&Y{>E_}
R#J#vt
wI\d Kx\4&
ia_Z*R
[-2RlIZ
q+v:Le.
Z,ay!G
#%02Z_u
1Tk|k qB
'Nj^YL
@3]B_|
D14$@:
}_TFDw8
Xm0!aT
6"q.1U
B76>r0A
#[*prR
o3rM_4
t[/OD\X
Y_k<iX
GetStringTypeW
L^>RY{
C/ !><
p_'O'.
3;)60I
E/ JE:
S?:<x
~gU^GA
4cXdZv
iN p_q
fD#|$,
NaGt5m
8N#@YDb
eVSSd[vkEv
)nA>!B
0Zrvwc
^VBxm4vC
!{\wN*
~:R{on
24S7+L,
EnumResourceLanguagesA
(;yF%%W
,knyPg
6W>Q@F
PyNTzU
KhbA6e
.br4EQ
:> [PE
D1,$AY
Y"y(~y
9pm"(m
~>XRPpv)
NuQKM
-Cf7e$
Fw/ekGf
9Ui}:.
%@6.mB
l{p4=r
0zd{as
gzaDW}
J~%7zyR
]qg)A;
l$8AR_
0> %"O
6sU*oy
,PaP6~
HSD)PP
d<KRWU
'l'*'L
K44OBi
1<(Dfy
Nkf|;H<
5h'_[Hf
&PpodP
L1bb]kb
),Pn]Vm
wtu`Gs
q%\6vR
HI.yob
f9{#Dg@ey$)
C9AfEv
^,JzN)
tnb5aR
Y_{m;7
#-()u#
RNxF7/"
xmW{Hj
qZDa'
2m vn@
8SI>q:oZ
vW^ERa
DVxUmA
x;NJi`f/
`ZuXt1
QAS=rI
~AjVS
JWrk^]
uN$#j+~
,j!+14
D8=Ae(
CaiS^Z
8=6]'Z
14$AYA:
lK1=B
|"SCL%$
JNJ2zI=
O^}&H)
sz.-`_
^<?x"D
Z1 '4%
D1$$AY
tmx9Wp
6WqvD]w
B=yD``
(l!|I(1
LHH`m
5Yi 2
VFmZXS
i~"2M
=D*S1c;
t)>@AY
WuuWx({%
T$$1\$$
V8,GULD
L$81|$
AQD1,$A
ZP1@$pWt$
r7.)TX
4/%]bK
-^@M@
UA@#M8
+W8j>g
e.AJ,C
YKfFTT'
@Wj`V*
@vLFf*
p}z$*:
3<mH^Y
g8he_X)
Hcd(A/
u,&+$%
)-2dx$
eEjYUB
HA.*xFY
@:e$GM
S)s(c.
~-7[N*@
L$(1\$
gV5RX
C. kl<
;1 )&D
P@ikp
7Hmi\K
&Q.0T;y
\A@y;1
AQD1,$I
_-2v#
@#:4}e
21q\qts
[CX^ou
Cd7aSU
GHx-A}
-<^L;!
W%E ,bQv
O.T[07
D/j\V#
w:[WX)
&&X4\R
k73]BTu
qnf(i+
6=:vO>
AQD1$$A
/!B9~
=Cq87j
xa8)Z.?$n
SuspendThread
7Qqp{<K
ATD*|$
dR>NI;A
6[b[!$
[aP@([,
C~7rVX!
AQ1,$fA
0OHAQM
Y`:".P
RJ_(ci
$]<ng*
~AJ*Hh
qkYA;[
/;K/)Ny
EmtD)l
1mzy]B
g{`8_bI(
l$ xQj
GetCurrentProcess
_^^gZ"4XE
{sF~ZB
5A%zvy
{cIZE
\7JwU8s
>.bZCvH
0OfBKY'<
8+,f9T$
\J#a/0
>D<"E9
o,2o9P
FL/xFN
x#T[bC
U?)b}Fq%pHR
J:w4_w
0qq0O6
|KIeO|'
v)?Ar[
0zr?O6
{T|.Om
5P`d!]
;!k1j{
"8x3V|
H-Z@@\F7
UigF0(
VRB2'?
4Or,Mo
`,]k5v
euqeMe
|2i^rGU(
=> [XB
da5(H_
GetUserDefaultLCID
TerminateProcess
nbM,Uw
1(z&y3
H3eIyynIE
`p$~Zm
tT=SCo
qvB,wU
1_@& \
,II@@t
aZQl%0
)/V3A=
h(UB~o
Jit>tM{P
.s5-m
M?}I;|
nl9.`WJ%
xD14$H
.yez `
#K6W{bd
-={g+)DE
#b=o31
D14$AY
xqjv#
!OGnz)
#sBu,`B
r=svdp
:?O~L
a2lJE!
{_@:\
(1s9_>
I"/<c
r^S~Z(F
[Kqe0!
AQ1<$A
OdwF:
,t+ae!
XQO6EP
u);mb{
Ge3^GH
v[JbJ,}
9LO9TJ$
6]#yL4
Jy"WC`$
1,$fE#
W0 fm(
6{<j=
%-|(Td
c1`/W,,a
|17t8:
[iwOWQ
}QcgU}
AQD1$$A
FileTimeToSystemTime
8-PI$\b3
1/sH cj
u8`P|y&
VIjzs\
1pr~FP&
7YrM 1
m_KEVA
r[%s}HXC.
6eB?=^
f-Z723m
0&.?@6
43NP]p
UM(!Bt
Sy_&\l%
(08c6-
WeR[fw
q18Nr$
zX\6v0
t~FhRb
c[#~ 9
hC&l*U
9TPIH|)
}xYFDk
D+>K2A,a
3RIX=r
=Qb+|$
.8C@W9
QXuNE`
.dzZ2
iVTM*j
AIC@L
\$@f#|$A
WriteFile
ldE(P%/
_4I_yOF
xs,Yxw
EtNPIV.\
#yCZo%
`VT4Fc
>^l42N
eJntlv
i9S,-x
bWi#e
9<^vI=
2nwBY{
Khq'Bf
u<7-+ie+
MAQ1,$I
BT2CMM
v%RfTI
yNmzX5
AQD14$M
{sNSKt9
25h'_[
?IEkO)
ii7',2
q\j7,!
JH])[uE
bZHy=3
.O-KczYx
d!DB*(
WideCharToMultiByte
;WmK<x
5}pHqF
q^<f)5
7*X)G(
f/LEm/5+
_-{I t
1FUu]s
sT~_{V
ifY#5
Zt6QoE
4\#}S7
H@F7TMG
p{wF9H
|$ F;_
D1,$AY
D14$AY
yjeW(c
_o0TohG
rkt'Bl
35O+>C=
SytFFN
oq\>6p
VyBU6@
shC-x=
#f8H{M
0#KYgE
-3xi]+w
Antivirus Signature
Bkav W32.AIDetectNet.01
Lionic Trojan.Win32.Generic.4!c
tehtris Generic.Malware
MicroWorld-eScan Gen:Variant.Lazy.266138
ClamAV Clean
FireEye Generic.mg.8c8f6bd95d195dc9
CAT-QuickHeal Clean
McAfee Artemis!8C8F6BD95D19
Malwarebytes Trojan.MalPack
Zillya Clean
Sangfor Trojan.Win32.Kryptik.V6gv
K7AntiVirus Trojan ( 005965831 )
BitDefender Gen:Variant.Lazy.266138
K7GW Trojan ( 005965831 )
CrowdStrike win/malicious_confidence_100% (W)
Baidu Clean
Cyren Clean
Symantec ML.Attribute.HighConfidence
Elastic malicious (high confidence)
ESET-NOD32 a variant of Win32/Kryptik.HRTC
APEX Malicious
Paloalto generic.ml
Cynet Malicious (score: 100)
Kaspersky Trojan.Win32.Tasker.azee
Alibaba Trojan:Win32/Tasker.be9048d4
NANO-Antivirus Trojan.Win32.Tasker.jvlzmn
ViRobot Clean
Sophos Mal/Generic-S
F-Secure Heuristic.HEUR/AGEN.1313486
DrWeb Trojan.MulDrop21.56696
VIPRE Gen:Variant.Lazy.266138
TrendMicro TROJ_GEN.R002C0DDB23
McAfee-GW-Edition BehavesLike.Win32.Generic.vc
Trapmine malicious.high.ml.score
CMC Clean
Emsisoft Gen:Variant.Lazy.266138 (B)
Ikarus Trojan.Win32.Crypt
Jiangmin Clean
Webroot Clean
Avira HEUR/AGEN.1313486
MAX malware (ai score=83)
Antiy-AVL Trojan/Win32.Kryptik
Gridinsoft Trojan.Heur!.02290021
Xcitium Clean
Arcabit Trojan.Lazy.D40F9A
SUPERAntiSpyware Clean
ZoneAlarm Trojan.Win32.Tasker.azee
GData Gen:Variant.Lazy.266138
Google Detected
AhnLab-V3 Trojan/Win.ClipBanker.R528972
Acronis Clean
BitDefenderTheta Gen:NN.ZexaF.36132.@F0@aSahwPni
ALYac Gen:Variant.Lazy.266138
TACHYON Clean
DeepInstinct MALICIOUS
VBA32 BScope.TrojanPSW.Coins
Cylance unsafe
Panda Trj/Genetic.gen
Zoner Clean
TrendMicro-HouseCall TROJ_GEN.R002C0DDB23
Tencent Win32.Trojan.Tasker.Itgl
Yandex Clean
SentinelOne Static AI - Malicious PE
MaxSecure Trojan.Malware.300983.susgen
Fortinet W32/Kryptik.FXIU!tr
AVG Win32:Evo-gen [Trj]
Avast Win32:Evo-gen [Trj]
No IRMA results available.