Static | ZeroBOX

PE Compile Time

2023-04-09 23:39:51

PE Imphash

895e5e6e037e9108574fb94ed614d804

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x00001b1f 0x00000000 0.0
.rdata 0x00003000 0x00001128 0x00000000 0.0
.data 0x00005000 0x00000064 0x00000000 0.0
.lol0 0x00006000 0x00357577 0x00000000 0.0
.lol1 0x0035e000 0x00000398 0x00000400 3.62305230963
.lol2 0x0035f000 0x00605370 0x00605400 7.96006886316
.rsrc 0x00965000 0x000005d9 0x00000600 4.10512581258

Resources

Name Offset Size Language Sub-language File type
RT_VERSION 0x009650a0 0x000003bc LANG_ENGLISH SUBLANG_ENGLISH_US COM executable for DOS
RT_MANIFEST 0x0096545c 0x0000017d LANG_ENGLISH SUBLANG_ENGLISH_US XML 1.0 document text

Imports

Library KERNEL32.dll:
0x75e000 LoadLibraryW
0x75e004 GetProcAddress
0x75e008 ReadFile
0x75e00c WriteFile
0x75e010 lstrlenA
0x75e014 WaitForSingleObject
0x75e018 LocalAlloc
0x75e01c CreateFileW
0x75e020 MultiByteToWideChar
0x75e024 DeleteFileW
0x75e028 CloseHandle
0x75e02c ExitProcess
0x75e030 CreateProcessW
0x75e034 CopyFileW
0x75e038 WideCharToMultiByte
0x75e03c Sleep
0x75e040 GlobalFree
Library SHELL32.dll:
0x75e048 SHGetFolderPathW
Library KERNEL32.dll:
0x75e054 GetModuleHandleA
0x75e058 CreateEventA
0x75e05c GetModuleFileNameW
0x75e060 TerminateProcess
0x75e064 GetCurrentProcess
0x75e06c Thread32First
0x75e070 GetCurrentProcessId
0x75e074 GetCurrentThreadId
0x75e078 OpenThread
0x75e07c Thread32Next
0x75e080 CloseHandle
0x75e084 SuspendThread
0x75e088 ResumeThread
0x75e08c WriteProcessMemory
0x75e090 GetSystemInfo
0x75e094 VirtualAlloc
0x75e098 VirtualProtect
0x75e09c VirtualFree
0x75e0a8 GetCurrentThread
0x75e0b0 Sleep
0x75e0b4 LoadLibraryA
0x75e0b8 FreeLibrary
0x75e0bc GetTickCount
0x75e0c8 GlobalFree
0x75e0cc LocalAlloc
0x75e0d0 LocalFree
0x75e0d4 GetProcAddress
0x75e0d8 ExitProcess
0x75e0ec GetModuleHandleW
0x75e0f0 LoadResource
0x75e0f4 MultiByteToWideChar
0x75e0f8 FindResourceExW
0x75e0fc FindResourceExA
0x75e100 WideCharToMultiByte
0x75e104 GetThreadLocale
0x75e108 GetUserDefaultLCID
0x75e110 EnumResourceNamesA
0x75e114 EnumResourceNamesW
0x75e120 EnumResourceTypesA
0x75e124 EnumResourceTypesW
0x75e128 CreateFileW
0x75e12c LoadLibraryW
0x75e130 GetLastError
0x75e134 FlushFileBuffers
0x75e138 WriteConsoleW
0x75e13c SetStdHandle
0x75e144 DecodePointer
0x75e148 GetCommandLineA
0x75e14c RaiseException
0x75e150 HeapFree
0x75e154 GetCPInfo
0x75e160 GetACP
0x75e164 GetOEMCP
0x75e168 IsValidCodePage
0x75e16c EncodePointer
0x75e170 TlsAlloc
0x75e174 TlsGetValue
0x75e178 TlsSetValue
0x75e17c TlsFree
0x75e180 SetLastError
0x75e18c IsDebuggerPresent
0x75e190 HeapAlloc
0x75e194 LCMapStringW
0x75e198 GetStringTypeW
0x75e19c SetHandleCount
0x75e1a0 GetStdHandle
0x75e1a8 GetFileType
0x75e1ac GetStartupInfoW
0x75e1b0 GetModuleFileNameA
0x75e1bc HeapCreate
0x75e1c0 HeapDestroy
0x75e1c8 HeapSize
0x75e1cc WriteFile
0x75e1d0 RtlUnwind
0x75e1d4 SetFilePointer
0x75e1d8 GetConsoleCP
0x75e1dc GetConsoleMode
0x75e1e0 HeapReAlloc
0x75e1e4 VirtualQuery
Library USER32.dll:
0x75e1ec CharUpperBuffW
Library KERNEL32.dll:
0x75e1f4 LocalAlloc
0x75e1f8 LocalFree
0x75e1fc GetModuleFileNameW
0x75e200 ExitProcess
0x75e204 LoadLibraryA
0x75e208 GetModuleHandleA
0x75e20c GetProcAddress

!This program cannot be run in DOS mode.
`.rdata
@.data
`.lol1
`.rsrc
-P[$b AU
K:"6oN
8X}5c4
aiB_0`
jhS/Zo$
Ap=a0u
rCB+d~z
t$ +L$,f!L$
D$ G5Ej
CDsbF/
2aYO_]3
t-HR4s;
pIE6yO=4
2A#4Gp
sRK6vX&:
yfEUf!t$
C y}bnyw
D14$fE
%Z']%'
jm7?h8
E| l@:
b/MdLwJI
Gg&}6N:8&z9h7
O77[j/
Cq7(6Q
J/UjCg
u*@gcJ
4g]LSB
b.fBzq
%/tlF:5*f
*@Y:(N
\z,wh*
j]{kSE
Lu"QqK
,JWXf;
lUwCW]I
?aKn2o
S]Qo/<
dnA43n
\R\*+!
L?( nU
Ur ##;
14$A_A
o6U#RM
[$L,#(W>
#*Q]5#
AW1<$A
ak{754l
4E1_kO
I:]6sc
D1$$fE
g[EN6R
Z6MOj1:
lZT>\]#
!A_fA;
#iTIHc
`3Uri$;U|k
] GU7@"
6u5 Op
&o{US$}4
&|'AWA
LoadLibraryA
Upy@9[
[;6j/`
n[r^cB
a,Vv3I
8]7MAs
Ew<r x
Y[Yp+9
`ng$]b
'oxP~K
{+[ HU
X\62+RB6,S
c+?6\o
w;S.bu
A*.&73
1.PYP3.{
$.#,I|
ziaW+`
\l4TlkC
qhp'Ao
sAW1<$A_E
[L))}X
#1XbgB
@[eGC
Kb[t?5
!7?RqWWj
c`(ZOW
<JI?CU
s/wN "
9Y=hf;
D$(iO*-
j'L;i+
R[*tax
ci|(/6Z?L
;.,[pm
uf>~X`
98^P53&^
AI\^Vfg
:YcnGe
7EIjv6LM}8c
HLcjvSA'
7[%D0x
Mb3ns>.
K7i#C'
AF3{NBgM
Thread32Next
Q1,$fA
|WRhg.5v
|-.f3T$
'$JZ30
xcwV)y
fi)Lbu7j
_0q-ljbH"
WKl=N[
X7,Kww
Z_]UZ2
#uVv+4
AW1,$fA
o7\p20:
Rh2r&~m\)
JWwz&J
;5_i_RE?
014$A_Hc
?Cp M@A
znvcEks
jX~X1Z
`jm"P-Q
\hzlss
e3HwBtRE
b~nBYh`n@I
mAW1,$A
FindResourceExW
GlobalFree
AWWASL
\6y):A
G0M+?s
K,T4L[
9&$Uh/
uN|hEI
n&!j^!V
#qV/$
=@G{B=/-'
I3Ih??
}P54#J
{jj2#Jd
%A('["
n`U&A2
\$ f9\$H
$Xj|9,
&5<xT9
YauH^"
,4P+o&
R*t][oS
SetProcessAffinityMask
IVveK@
VhOE+f
6}{3:r
/*;k_$
eb"uX-
ImJGyj=
|$$YHW6
D'O&o=
pS~~1&{
D1,$fA
{t>kMc
#hS_4!
aI9KPQ
Jb??mCF
fFj?L
CU^cl<
fA!N&
IroRLI
1IL?+1I
0'FI?F
F7kA?;Ba_?uz
>/P[<5(
*m#OZAv
wIf\u6
>j!*i%
&M*Up@
g?F9(~V
T$$1|$
D1$$A_Mc
Pmaa{=/*P!
D14$A_
gnZ/I8
wOOo:I
*M"X~J
ZE3mgA
/~1.]]U1MX
PD~%=fF*
1<$A_Hc
2D1,$E
AWD1$$
DeleteCriticalSection
{^v#|)
gy-oJ
o+gWIP*
rAsF%y
C-M8sN
/)?Cn0
>PPG "
@FXHriOM;
#eKz6;q
,0U3?
A+Jp+AX
<Ajgid
h)62C.
o%A2^k
2HUE
aQTDSZ
D14$fA
7&9yGG
z84o)~
`5<[U/
}#/|Cv
iw*Itq
Z[UKlX/
D1,$A_:
v/4P&u!6
*_um|Xtu
/,Zjuc
sPKpjs~
vGpX'&^
~tvB2?
.x}{CI
j-nrf+
l$$*PU|
d$$7YIn
\$3H1T$(f
L$(AgA
z8Wgl;
a*xaCN
~0x>LM
FUtq&n:(;
?[CBhV
1Sy>vo
l$Df1L$P
QoVf;L$P
K\t*UABtbm
2qk^r-
S,nMyW
OQm$*gj
"5=FUTs}
mg9K[EG
P&RVn
~w;7 :
pJ_nJN
cTJmyo
Q{qwv.Q
+}xE,B
M'z^4Hd
j#9U->t'
7qf?@lSo
V+ei1,
TlsSetValue
P4?a'xG
sS))a~
dy6m=5
X'}gX+RwyXKB
ij"?^Q
0Fv(Y>
_EE<DS
M5!3<'
N-Vsn7
wiC$r)qm
O{*!saDcc
GetSystemInfo
?8$@yn
)&hZA!
xF(P=A
}ADe4~kFC
rvk^|s
D$4zL0
D$,iu{
GKMQ;{#
5sTBTN7EI
*qOJpws
I-6u3J
4"YDfr
)W-&F[
'j-$M|
rdB5^R
\!L$K2
B%jRL<
kr"o.O
F=AYl@
$H+*0+
fx_"NO
o";o~Nr
AW1,$I
GkAX]A]H
_A[YXf@
Fb|@U3
RHDX[%,
^T^;g.
I<0(Kw
w>B?&
VmMdm7AMg
ZA`H%X
:VQ=E%
:IUF]HbUex
J|U";+PU
h)DLUstF
Ysm\96%C
l\)yTl#4
6+dDdVg
s.TWY-
J)1<$A
<B8*[j!
x.*\V;x+
6*Q|1a
(1&}cnK
xg@h(/]
r7>am.U
"4REdLV
o=EuSP=
Y5p$d23
G2pd.By
<Zha,F
;d{1e%
B^12X6;K
AWD14$fA
JOARf#
>k\Oob
ikYpYl.
t5.e&V
G}LT5McL
A_=P{P
^e$'KhI
Nm+m~j\
l?""kH
kBf#T$!
rrx~s
}Mht,D
!L|;pE
@ `up'
I)87N^
[H=wkOJ
q~'i w
W{rjg|
GVs"$e
'Rl&z@
.s-)D\X-ri
)[Hi2TQ}
AoF;y|
D14$A_Mc
rvkf}s{
$uS=&N
qZi?js
zSi&'qSO
\6uMdh
wKFl6g
9DVC_d
'mBT?{
B)rzs)
LZ.d''
O{{ydg
q/<n}s
wM@bGJ7
M\-':
B?L)?0-
H^tDvm
1'R~1@
e2!ZwPT`u
!}*<12J
k?Nr5a~
&H?Qvr
Iex]jsr/
Pszk65
*8|10>d]
wO}sCN
|`F4KY
vZa'S
*[uP{R
f3-mV4Z
}[poM\
^ S<YW
3<(n0s
TlsGetValue
D1$$D*
|NH.LI?
J"Q_z%&
6Iisr?
CloseHandle
#OrG$z
l< |n1!
mubZxb
#}]o=K
A$*zGP
sLXs>
'bmOV{r
*IHKFL
c\fESa
-Qd^//
ROzf0p
]6p8A_
=I%6Jg
ax##S>
ewf5^]f
ZW f5q}
.D^gs[5
>}/t^k
GetModuleHandleA
+!\\v+
6At!(6
-"'F23
:p`aMWj
isua!%h
\dH/L?
aSO"Z!
qAUHSs
V~%XIB7<
N5V6I3
$NY'SL
9#Xn'b
3vHX|j
;cbFkD
@RJ+M]n
5p$d2f
'AQAUfA
GetCPInfo
AWD14$A_
;\7cG
@~`~gfv
reoO}s
[?Zz\X
+nR\|.
Q~!HDr]
2Y|fa
vAz@]B
`tS-.We3V
{Y@^6m
[uzkl?P
(q.YT]
$/& k=
#z[Md3jRs
AJIMs@%
Uox1R
6X0d`s
p;!a(As$
-)Ol|
q([# !
DGm C0
LES"|B$
z)JSJ.=
t)S+M1
g-ix]+6w
Cy=,ryW>
wZMzcy
f5Bjp{
t5Bhp2
5BlpT?
2V7CS@89
\X|#(T
r+LT3|
WideCharToMultiByte
lGM~y4
m1Om%`
67G7`{
+T\M).
_T9!8B
g>N!*,
SetUnhandledExceptionFilter
XA^G.MGz
`c!9Pj}!gh
J~I=I_@p
qp`(UP
&UZAW14$fA
HZAWE
SSfs3C?%h
7W+bf^
kV?-:_
{?s_K8
:#c:=T
V;7,f<@
MSj.}T
`W.]PPY
Y/Hdm7A
gvo;tk
:_R-MI4
$x[]OY
D$$2}J{
D$0(L$(
Lr0)*Rr
/rR1S/r
|4\L,I
i>3Dn>:
1<$A_Hc
5?+8(-g
!o63S
>5R]k^`
7&]h*7
1+/L3P
,T%;g/2_
#"30GF9
Ceu(lS
YGnFJ7-y
b+&{8Z 9
I<d6fTMj
5'Ow`Kr
gy-oJ
e@H F]
Ti-$tW
D1$$A_@:
huT"9|
4t@me}
ctERSs2
GetModuleHandleW
'6!yH$
q_{9 s
g]g!`5<Y~
8R3*Wp
d:S}7q
\_!rAH
<kD*/&
RR0(yg
Zs{p7Ovg
HY>ltg
}P!V&s2IY+
kJQkhb{
um+x-e
jm!pW+sz<
wsv@/Tp
d$$$~f
^1gun6
/47I3@
c\ot2U
?]{;nT
X.8)_Y
EY:wu^M
%7[m;`D1
a',#ZA
iDDi~D
Ym*R5#
v0aPJ5M
EnumResourceTypesA
FD1,$A
AWD14$I
D14$A_
AW1,$D
E!NdO6
7IKYOr
Y?'h5:
CreateFileW
f)l$(
>1YybT
J@ezzG
w-m{&$
+,y4z%
),7=.[
Q(8xa/O
sEVjasc
010JM(
M#ABK[
hY#NG[
6*Q,(-
Obe8\B
NlpmQk
~q;-l*
VmEGd
w9m!6-
^OkvnH
?#w8n*
c"cw2+
/J;JML
E'6tu A
&";)!U
|S%}Y;
ah!Ip()
?Y4hF-8
a6E@4V
vkE~qq
w]nf;
1<$A_f
AW14$A
M4gXX{u2
",DRGP
A18AWfA
D1,$A_fA
D14$fA
=(:H=3
Gdwlwc
j`3ZgD
eSRyUT%
>_G?9(
E!!Oa\f
aloAW1,$Mc
E'gRSf
o!2-^l
W'l)2%
MU-c,r_b
j/^vUwn
}tx8@mS
s2hRhI^
D1,$fE
v-^fA;
xg[Dv-
*7eH_.
to9\4to
FFuEd%
q@>L`
'*+u@'e7
~>u[ev
nw3u]&
ql:0ZE
"2M?in
irq"3clq
QZBi>A
FindResourceExA
<Q2JEo
3*(Y`]<Iu`
^&i` S$
<jl`{IJ
erIV&"
mP2XI{2m|
`@~/?Z{
"{@o|01y_
l$00l$
YBJ+_YB
SuspendThread
:O}a#Y$
d$$^3Pu
AWD1$$fA
V$K4QS
9;,Jh2
uStwET
n;)u^<^
>yI/9
v5C'uc
hN-$Zh
|,int$
ReadFile
`sscu#h
3TnN=2
.y?nEW
g:ClR,
8~CI<n
^bjhA;
{(MtC4>
X$qY9Mb
N{b2r
h~71Xy@
EzsBu}
i-bjWn
r5Egk,
b+F:07
sjRF)+O
DY,674
{]-1l01
4)H4_6
K9F0UH
(Z!1N'
"[e$gQ
t4$J3-p
'*gQ"F
+S+=,-
5!y23[
"j}!`J
y-A/~Z
n|}}^{
:D4"s(
./xT!G^v
H;l)[6
;nV.A
M#C=s\
lZ;W|C
Ps[H>j*
j}99nb
G9H36UC
D/Ks*I
r@4xMt
<o_E9<
llis9Y
0;;r@_
.^Nle^2
S^l1Bn
CopyFileW
N$<Np $
U%Hi9N
D19t"S
($=+A,6
r:cWS"=
aL8)w4
8l!%3t
NQQFtn
kbGG*-
t$D7X=
dM#HJ"
vj\qJu[S
`)WsiS
/Lfvv0c^uc
=}7r9Bt*
kf%X.}
J=d&6;3
VirtualProtect
2v5)4
Y)r8s+
(G+(n
qhLxEO
>F*41)&
z\?t9U
x01Tii
D1,$Mc
P\&@'F
)E5t@ `
Q&q%>0h
aZ^p*o
f.\zC(
O~DWku
JkBV.kc
D14$fA
)og>A#&
EUEDN/
HD1,$A
*A3wQM3
q!Bh^p
$0/]L,
F2as%b^"h
*`zI~E$
19Tau@+b_V
r7zOas
D14$fA
+^!,zW
w_5c&V
3)-&4^
J2=bz5J
QZ``a]
<MuU;.fA
.fT7g~
+4ysJ
[sc2J>
o<q$5R
!}ny4F2
.`uq;F
?51i:]@
^-USOU
IsProcessorFeaturePresent
WBO,iP
AO'cuofS
NF@R[f
Rday(Re
?RS\`g
M-s3+ /
Sv3HY!]3
%A]B8y
OeWj$J
YHM6`v<<
&R'A:^
xdZB#R
}16~[
EXn=Tg
<;%* 2N8
a'S5D*
!Qdr[D
AWD1$$I
q#Y!j?
Mkvk~N
nc,N@#
*;Mjj7NGtj
K@8M04R.
>5c3<Z
VmqR7i
MhVS V
N#h}of?
`{\[<LP
3@EUSV
AWD1,$M
6ls_=.H
V-7I<X
v|Dvc
]kq^bm
&\48t$
l$$A\zq
H{ACo{+j
2~gs@NM5+
~1,$fA
V+nY@:J
\DmZ5R
([KdSR
XZr[.O
~{V5C&
DwC7~
\^"2/V@"
,UNRns
/op]Qf
ASYteS
2APfE#
QG]s-
yVu`_{t4Kq
$L&y^W
W[TstD&T
w~Hs"tRu
X:+h65
J/Kv36icZi
r];hVe
1<$A_Hc
#I<IUC
Rd]sad
j `}5;
Bm,vB[
$la]swb
wj(7"}t(
8GKi)d
hrDx+A
W(M^~C.,r~
]BpJ=>C:
X2xSISa
4J_hu7
#3'wC6
5p$d23
]@wASATAWL
T99t*b
#7>Yd X
W_7s:w()i
{80zZ~
I])ak~/
*}TvA[
B}Z0A>O6
t5.e&V
d$<;YK6
}*R<*=Qt\
w]wj!NS
dqCZt@q^a
'HO$G-VOp
1"^=uc
UnhandledExceptionFilter
~9Ftcr~
,Qpf:4#
A[YXAZ
D14$fA
wsEgGt2
4&[M-k
7iSeovn
R/dFrG^j
wr9U7\
FSJwSM
SsxOIl}J>p
w)E'Z@
uVR+|$
]zUPs<
Zg<NjP
D1,$A_
*@Xn+*
_Bt >{
S$qi|L
R)XMd+
Ya`Z5Kr
y.Q]+0
[/qJC:
t%=:`^hj6
%w@J;'
\*84Et
InterlockedIncrement
+t~rF@
PF[ACx
ARD+T$
USER32.dll
GetCurrentProcessId
>B&%"(
V6B,t;
eOJ=neO>
+!?f?DJ
2]m_FG_
2$B!"K
aMj;`G
zyHcv0
nQ"juvH]
{z7V[5
TGKY+R
Zs+j>?
ATD2l$
{<G~}Vw
t\2*%
[<Tu4l
&Km.Hw
9/][h$D
slIxCk>
/m]7j*
1<$A_Hc
O>8(HI
DN*wtI]
%"69t+
y#"v(*
_&wuo!
vH>;vO
M^AK0;
=++N7\
(JQ7g+@#
t5.e&V
QueryPerformanceCounter
WgV]=u
+,LUt-g
GetUserDefaultLCID
5VI+4K
jl<1Z-
(ZQkaN
G!V$f;
]HrY{j
Ikyddbk
hLk"Ej
c;y$Sm
.F#rP-
#Z:+do
kATuf*
po,jVoH
@S9e1oIHB
|^e}DD
/UrZn:
m|mx)Df
F(+pE3
D14$A_@
?o6\sXE
*-BCZN
v!4A_@
gme,va
&=y`Iq
`=9<x/s
&6*$(
Ttls(Tt
d#Tp_(
kwS>@-
_"!r8_
/_E<kw
sev>esw
y"nASSH
m[0VAVD
D$(_6|0I
n=LNg
nkmp?b
2jy?cc
o,<$h[
Hn8sxiO
6e1rVf
f+T$6f
xBJO{V
^^qVRq
8]+"NI
CJ5p>s
b^!Xaj
OhK<@C
3q;h`R
;J`h^W
<'wuLe
KPeOEC
>i"=S3i
K^)FJ\E7
!4A@AWI
D1,$A_
LocalAlloc
Xfo:.P
G|8$Ep
>pE:sjW
G!mO:?
\$ ;T$
uaMRu+B
D1,$A_Mc
1v)Vq2C+
14$A_Hc
GetEnvironmentStringsW
/r~NoJ
I5G)e9
ww}&Ne
Yq"wY<*u
O/q}@C(wB
y~kDIy
{;x8|L
Tz/7d}X
FileTimeToSystemTime
2eIOcl
eeLpUb;
]t^8$u
HXw3,t%+
GetStringTypeW
MSy3AG
8)lRVZ
Lgt?/4
GetProcAddress
r~;?:rg
;kf/TSK
(UJav.M[F
`Bf[CKJm
CBbHqK
G3SJ>2T
8A\-,P-
;YqP4^
9n0l&>
AWD1,$A_
5b0~iC
j`;rwsv
o9\atZ
pr7f|/
P5=U;(
^L5<Rvh
t$XGMFdH
}QGNqq
fWZ?q'tp
cW?qKx}
+fPx;*
YYPvDf
Y?wbCE
,brZ;lFE
&L` d~
2}$}oo
0uG9q;8E
9<qTIK
P(qJ)z
rV)7<r
!6.+wIWk
Lz9r(8
f54tf-
{7@v0&J
1L$@A"
m=.KkL
dvaqp5
k1iRYV~
t^Csn+
^CVK@Fu
SCOq;F
1MCZwi
Ip:=}ep
rpK@d*
]W~-Gtd?U@$
AWq?TKIq
#X#q/&
L;N|Z4
?fLpj*r
ptkP)T
)E'=yEWz%)F
=yqkzh
Dr$8^f
CZX QM
|r:j%u
2T$.+|$8
EnumResourceNamesA
f=%Df;
,z|#NPf
$9*cbbc
N&_/TM
!10Q\`
;Glnqa
v$<O&.
0P}$XUR
D$8iqf
U~tNqw5
!<z,s9
ycT=/XHyRx
'JLU-9a
]7xF@h
'jeSr:
b!@;R&7
TMYJdJ.
f>arX-LJr
.@BvzU
,Ov^atQ
3wrjf;
B!9g'}
GetProcessAffinityMask
gnF)Qf
KfH &Z
75!f1t$
1QaHct$
S`l]|5
{pnPD~Y
y\Oe)%,
Q'?T~wa
Da+'3
G!P.w&'
&ML`wD
zLX/+E
qMI_AJ>
4f=~83
M?/cM5
^-S,+[
;}Bur63
zNv.jRAZ
M7{,Xi~
GEVD"pfI
QMAWfE
JJ`lP:
LTqH+]Vq&+
+qZ+$+q*o
ohz'x+
yeK$2ye%`
\$ 9T$(
i#t&f_
AYA^AX@
oJw]?N
1eJ[?8
h((=,h
M6Q`3_F
RP$H]`
)zx1s
CP=.e^
x+]_S+y
5/lk;
,qr^9A!
mw9Ntf
kHID[O>
]$P5m#'
%Dz1"3
:GJ#Ny
]G8g9HA/<
opq_$m
^FFzAUWAR
Q']}M
s5(/+s5
9Xpmf"Tq
MHqX!O
?|GfD;
rn)3#g
Tk|0dl
yo8CIhO
HeapAlloc
TerminateProcess
J)\c6\
)n/HSt
AWD14$A_
RpwE^E
VK{z:}
d2]Oa'
%dV@C<
4uM8z=
nU^*;=
2EkW`S(aI`
M<`Z;M
`Wf/=n
;<6Oj5
wTnrGS
Q>N6VI
l<3p\;D
|Wu*{
F}C:vz4
~LfQ5N
=<`uuW
>=5v_/
qRE[8O
6Eysna
4-`k@,
`]>=2
^i?wTX\
(k5j<I
h//s;&
rJoz9Bvhq
pp`,{DI
"$2rbP6
0K2QqA0@zq:-
Bdq/.#Hq&
GP0.0/
C>7DrC>K
EnumResourceLanguagesA
j7!'$eu
cBI",cB
a5<U$2
^]idPK
4bTcq2u
{N7(md
i%`F 8
y\J oj
+ige*i
Q%"+l7
U@R/sM
Q(0 e6
?BMG>%+
56l1$
G%sU@I
W*x;Z6
d$(j>f9t$
#]t@wj@
Y>*QZH
;{\t-b
\I S|M
LopvHi
,>Vnyv
GetProcAddress
'u,;^'u
m~zkUI
H=e\(p
'@=5wV-7+w
+JZ a^
Zk6T`*
OPbF{%}9
nVo7),
\$$)t$(
!l)?$n
dDg: i|
`s5%@i
g5^$i*Di#
CharUpperBuffW
EncodePointer
J'dH&@h
/pc/*
$[2OQ2{]
@n0dvN
t9s|#d
^!qtPq
N#ic4s
|'h,%W"j
~?$'1m
F";~SF
vT}U[8
O:P3%,Q"
rk}Rw#S
n-$joE
DeleteFileW
@MwpP}q!
OOhibM
,cnrVq0
|fbQ[}0
uDig#YE
d6Mwrb
'\u?)[b
K_r.Le
'cI[KUQH
x`rHo"
0uAwy"+
]T<=Z#
Q\@sa[7
'K&LO
^WRvf
zm[!`"6Q7
A6}LRu
)|LmW&!N
2hW/X@CWH]
B]W5F#qWf
S)7!he
f<#{SY
--=}O&
=d},]\H}C
Xeq<39Iq
Iv[|Cr
xefbXwU
h:lH;\
8y%JWG
Hmd /9
5p$d2f;
Yj&0f#
AW1<$A
GIgb|`o9
9t.~ub
Ivq?s8;s
pI"uCskp
7$k%lc
<|Iw@l
&Y]O_u
6l\\Nf
:_Kdk
%^&B/9
.nqzxUnQ
k_2IHi
aAw_2k'
T$$ZRQ
6FKhc|
]oiNT
S57Tc2@
~1s'N6
nX?U?Q
eY.%U^Y
H]jVxZ
D$@g6Fi
IsDebuggerPresent
l2z?Rf,zKB
=UNt|.
7ZIA<M
C6EX8D
|okZsM2aDs
uVq:)dTq
4uhkK@
bbqab
Iq4[RIq
iruKS@
4#zBY)T2
T$4#|$
~1%b3\$
9R0;@P
KAW14$fA
` 1r0c2[
IcBYzbc
]>=9.]D
oe/T[f
255_ud;
D1,$fE
?8"BX(
=ZuCkh
d&fRf;
dL`{?N
oh=$l
SShT11N
^r:eIl
SoF&@7
b1eQ+s
)L>DCR$!
:O5'[v
Cx>BtC3"
j2N9EY
InitializeCriticalSectionAndSpinCount
t$ 5V:6
D$0\&E
M4d/bO
YPb=4#AFN
4lD14$D+
qO(xlr
r}`p>rN-
ySYE3J
6wRqSV
0}:vQ!
}Svi3
u9FoO}
B@J7'v
(aD"mC0
H"GA*K
\i9S,kH
.<JCmN
6Ku[Z9a-
NI3uqd
F= +"e
Y55_ud
kxQiQq
ZxbhK2C
Jt^E|at
v9pOt%
63jo++P
:nq;2[Bq
c(4^qj
x6pEB%
St[%ig8
G*ZKEDy
As_.*!}
C:m(ZdmM
6A1sO7ZU
>E27J0
t9n_3
;6K2!C
6YmZb&
k1,$D#
_p+3kNr
u{/*~4%
.tQQ4#
W[i5,3
(Cs_3D
x+9`*-
7l!.7HY
%Ak!PV
P!dCBx
Md~qN+
PY8)C=&
D@_Wwf
s9v:+N*{;G
RE!~L]
HW/9o*
g!'c`1Q
-@EY z
B)"4MA
qfsk[i
r.Q04r);"
1q*A{1q@
4oyf|Zu%/
AW1,$fA
HeapFree
+AW1,$fA
U55_ud
gv)ZM?
Ur'uvW
RM6vQ_
GetStdHandle
$A_fA;
KQDT83
XoZ8Jax
%)zrhw~
!e+qf7
j]Nq&I_
Nn9wxM
m p:@
>4d4=?7
5sfSQm]
o@t|mr
F_^e9y
<iB h&
?O#tEL'
p,<I~3
O>q8q(U
xenAW1,$A
>D14$fA
bG+ E1I5
7q9S[x`
p!Pju(
o+94Yd
aovdZ^[
AWD1,$A
}PKlX3
<l7*\<l
ZIP6fD
h,|=n#Y
?.[a(F
,G(9M{S
|$,f9T$
AYA^fA
AWD1$$A_Mc
OL^QC
)c0E(9
eM|k2L&
{BdU^jZ
|\zR4=
GetSystemTimeAsFileTime
Vc` Y#
7;n6o/qR7!J
AWD1$$E
D1$$A_
1<$A_f
Itc|M(
i'?H{X
=E&EX/C
2i7&z$;
LocalAlloc
n"7dV9
`Kd">:
T6}#{S
y4{@T'~cv
ih63CJ
j*=Uc(
A^AX]D
o^+u>W
3_?:bV
R3#tb4T
27;>5@
I[~vy\
&3[#T!g
!.jvv^
t0lbIU
g6?X5V
h$=1|$
^&qqeq
z#qQJp=q
uO1q25
4Z$p=.n
AWD1$$@
v*Y(F-.
@F@YpA7
&f8Q<pu
LocalAlloc
*;&CMP
b]fmF8(Aw
\[-l(;-R
'SqNDq$
Ze{(pB
4hM1/iP
5>7p*%
(A|tQVa
1<$A_D
GD1$$A_I
JiPpz#
1<$A_fA
,>7[ww
1^@^N:_N
[vn_c&
VC(]P#
^Fp^9
t\Y|*i
^_2|.W
pWQ`%s
yfU,;sxU
E&O6q>E=
V,HM3\c0
1H&gk!
mGVG5P
_}XFXO^
pu=:RR
i^@I<BKB
xNvwfX;
\seq[[d
EUh.L5XU
2.&j!o
RcMFIH
v5C'uc
vd}g=w
JjD&;&
prS}nNrS
Rws_!-
DFyw$f
]D`CTS
eV8tq"#:
GuR+JbWN
COrh6f
u &Cf;
BfgC+6H&
rvmbBn6
NH^IUn:h
%1+t8
4J(33=
_5^go2)
FQ-,,H
H+bB8=nfS
_rc9qr#nI
"`D=~T$
Hr')"@
7wt,4
L}j)q
1<$A_Hc
ry:4Ez
u8Fmr8
LYr=]5
B{xcn{
^dCF2d
/$uS=I
KloOis
&<_RSp
DecodePointer
U}X+ez/
|Ld9{;
~=PnF[Tr
GetModuleHandleA
AW14$M
D1,$A_Mc
}9yqhw'yYX
,h32+^C3?^
}xHC^H;:h^
F;8v^P=YZ^
`K=GHi#
@U`|iHjZMb
S[Ap[V
^]+,(v
nv^'.v
.D91s5o
~"lF5M=
MV\Z;C&
/*_7vU
<bYfr2
C=@3*1
2biG+QCJ1
!MmDWSfmsb
Li<x}A
:x{IHO
lq2G{@qK
J^[iv+83
u{IF;?
D14$E2
oS6;>Z
3R"tb[
R>>:b9I
?*u>8]
IVc8yQ
dR'KTUP
3?<hI3
qRf)v%
EpF)uw1
EUU?X!
",K$}0v
&!F<Fk
3t~`d:
/tDrd)]~
7$g.T/
dzVm:8N
p}Gqx%
Iz6p;\Q
m(iqI>ZBq
gqX- ?
kcD;f;
D1$$A_D:
d0u{)`
9'rWL|
$wj/2'q`
AWD1,$A
D$0fE3
o;GK?(),
U'tizq
Cq/0<lg
SBK ::
2mTs5>{<}
:Z.b4g~v
}C&do
[^e:&R-
bW]YZx>
yV@}{p8
+_B<~EV
8x8?/#
99<w?ok
5?q#@7
}9Aizw'A
(`O%gSU
&Bnqb
@"qrFr
*2(LP9
FZ-X*FZk$
Pq.VZ(
CreateToolhelp32Snapshot
L5Z'wzP2+_
/G8 ~U
->]tt+qk_
-^+md@BKV
{OO}Gx
AW1<$A_
g#}D#,
/kD5SiU
t$4~jf
6 AAWD
2q9'N^
)(A&)E
89+&D5O
M'_B!i
f=bGf#
PfGq!`
MultiByteToWideChar
BL$,:L$)
l)fXzO>
Tj``Z9
3hE"q*UG
aY>=5c
2?QHq
B0qV16kw"
Szg1X
v9tx<COlr
IIa&Rk
2UfLdN
}X/quF
Vq%\HVqi(
&A;5qM41+q
XXq6_*sq
D1,$A_Mc
d62h-:
(r5$bPb
-$mA&\
M\krcCb
]i2/Je
2eSUR
k8ik\"
ARPQfE
APAVLc
1<$A_A
1+$;*>
f1T$ f
D1$$fA
}181am)N"
HeapDestroy
4[_/a
XSV^_q#0
]{fe6?
WjQ@Dm
>//NZ:
/]NU>h
b3AH|o
1_H!TPsHn
dHpiI<
J*'p1I
?iq~m5wq
iQK?!I
OVtelR
P#vHhX
%N=FpF1
isC%ta
TM87d=
w8Z,]j@
o%*AEo%|U
=;H]F3
En(?%.*
U ?dp}
m\;pI
5U'#]i
B pIr6>Z-|
KQ30d3b
%eM8Vw
q655_ud
PJriz"ar
rILASr
:1nc:e&
7^1#!I
v-^AWD1
,gVO$.
!f#T~XN?@
j`Y>K;
D1,$fE
2kz<Y!
X;.WU
\d2}Vf
qQW[n/H
$1<$Lc
#1zA_Mc
f!HIu{|J
[D#[b1
/ru`3'N{g
3KY%bB
oJMj>C
&Q$>!&
R'Ekb 2
EdIu35/
@:gr$w=}
J>VrXA!
AWD1,$A
iJZa<
l5!viA
y@5Hv9C
|uXqM;
yV"oQI
ukufnA
+2;AWI
Fy#iN%
-f\CY7\
u7Jgjp
s"y^yM
}$}*+F
fmNEQ\
vUC>z+l
#AW1,$fE
Dn6N\c
AW1<$D
*eN-U7r
6V(Iq]a
41< wD
-%;5[h
hc!bWhM
O~${ZL
S3+ 0_'5
,yE2S&gE
D}ZqI*
\|[$`5
d2*8\^
Qw-cj\
Ulo@[i
XIrd4R
?.<i~d
53Cd4<
Im~lyj
di:TnM
~GHOA`
ql^lWA
*WpsX3
5"N?9f;
=qw`>=q
{ud|y*f5
Am1[>0
$E-Kgs"
PN!v'c
x`+%Qf
C^f%*#L
InitializeCriticalSection
@SSO-<L
_eD]+6:~
#X<iYgt{
C$ZnZm
CloseHandle
D4-D0a
ATAWfD
a54X~st$
tws@;-KjA
_(P~r85H
Ihwvyo
HeapReAlloc
hW\E|]h
o%ga|z
TTp^d+8
V`AJ`X
$j(+CJp
2[Ge_bT@
i_!yrbgIu
2. ~[-
ZPagC&Z
,+)gyy
8iU4FN'8
W}3=C4N
CDEw_=;
hx._iz
FA4A&D
iiY"C%
"[xquR
YZ`DB9
1&O0}1&
}QBuv>
IWI38S;N
DA\{Y&
=VKoq:9/
bsh,BO
)zjwCx
q4f]lT
|R>zUuNR
t]:]Kw
#/6ri
NE>&ML
7iON75
:$}KVZv
<I0qM<
O9*&KL)@
\2Lsz.
w%a^:8
Qh_!o+hkw$C
~O`eq%Rb
i0gekt
ki &k+
}thqk.z
5Zo9bz2<
QQ"x?_S
H!w`B%CW
$5)@T&T
s;&6-s+
6;(,*#
1~1$Gv
1f3Ar$
s-kH%*
mm:Z_`
1qF+[i
-:qD9/
YeplDr
}(_QP~z
~HA:0~G
3z,F\47.
~#;,[GO
PtXdK:
SetThreadAffinityMask
7T.#z8
EnumResourceTypesW
qcXU+S
K8#$YOL
D#UvQ-oM
!ue^{W
)?}jeD
iqDQ!:
G6e:[2
k>a5!,k
"#;,Q"w
!S{3;4
wMZ~?h;]
:Pe1?md
y5.e&V
D1,$A_Mc
~]YE26
AWD1$$I
/D}tHw
GP?:XD*=
\$@f)\$
_wp"@`
Y 2W@<Ug}
gC5i5vD#
=v<Ug,
<<Ugxl
B]@bJDo
?Nz~nTo
#v;>+{
z9](v}
u8]YTv^7
TZmtqp
g{vF7r
{tx=QAa3
AWD1,$A
?`efY[
/P?'yU
l|=&f%
AW1,$fA
@\[b$>
sz1:S-
P2{PFN
<W&EJh
HnnW*k
ei(nr%
n%O2p:l
fmGzt$
HeapCreate
S*:5p$d2
.0=OOf
~EZOfq
LMvMwE
LqX'bLq
QX$pG$9*
!v3K8/
)T]3!L1W-!$Q
Dppni)[
S"?C`4
9D1$$A
7tvV?9
{jdx1xB
*LN%{r
qd~^lXZeN
QVRnyN!
o^=<`J`3
C_}A*4(}
/;x>6c
]W$oi,
zfAW1,$A_
:ylBAWM
>EPP,q
#lY1_w[
s%3rkc
+b*S=2
&9`?1)
_]^bV]<
:KRLq]&XRq
Wgck[3
Dw|V&.
^!?0Fw
"s7.sz
~r#a/{
Xwvbhp
^.+#Rf
B$Vrr#!
%B=."5
#HJ<rA
M?5Jh
AWASWL
{rvAlD
|$ A[fD1|$
bbnAQA
D$@VaAQI
zXy]AQ
gnm6dt
qD<3[f
pL@A\S
e6$N)#
NKgYC2lmN
mHiWfQ
M}%",U@
Zt+r.6
^N%}n(
;oM8*W
<zKF&n
8t>G@p
wR9an|
_G5?+8(
Yw85juw'
rU q0r|L
rnQ'5r
,]5zVH
jte<O"
BTD?}P.
}*q^*R
xUiu%L5
Z*\(%]Z
pzEZe&
IF1[)N
@`6P0@N
L9L&qS
OS '?>
* UYvu
6W%{aW
@xr'2JLrn^3
[+6H{9
tE|9rx
J%a}>V
AFfHKw
Ro[9#=
?/9`sX
A+cZ,[
$('W{+pN
P@YJO1lYy
I\\my[+
]H"%Z?
CF+m"C
}[<b#S
|+`Rls
D14$fA
v|[xji1
nz6L;`
BN[Shj
z(|$GX
rV7G+q8-
"_J?2]
v5C'uc
8U a{)
~U+2Do
8{-h6_\
5z3vXzo
2"ujxm
tJyAI;
-"'F23
GetModuleFileNameW
_AYA^D
e|}r<&ao
e.%1:'
K(`RYJ
LqY<r
6: Y|?2
RRv\H-
e)>|K
[KsC'k
B( [Kw
:$B8TR
T$49L$8
C]l|VDQ
*e>szKI>Z
$U>RU&
ba%X,/8+
i4jnMN\:
Rf= F(6
~"gg#8
rlI*3r
fqLY_3
};OR&WNtH
GxhAj^A
VI&ElmS
LoadLibraryA
AW1,$A
$}^'Jf
|^mTd3E:\y
Qd=\Gn5
{<JW${<
%V)4@3
G,b-LE
uCPb`w
9)bN-K
FreeLibrary
jodi0_
l@`wD;
ZKDu7{
;i,u,]
HwzG8=
RaiseException
e<43t$
t$ f9\$
f+ p,"
[PoX_|
D14$D2
y-WVI*
@Zh#G-
1<$A_f
YF+S+J
eZHU|;
%%f!saj
QrmO^>
AYA^E"
_A[YfA
L$(A%PE
5)"_5?+8(f
4MN5BcR
GetCommandLineA
AWD1$$
K!p"2(
>AhU5M4bK5
/Q>|0PsnK
AlJO/Y
B"Pf;\$$
]A_fD;
3'r*JJ
_3:,CW
?x8r+ij
>~|'.0
0tW F0tMt
<#'wx&=zF $j
D14$E"
odC-Eb
LeaveCriticalSection
~PWZf;
D$01L$
c8eQX$-g
ta-XSN
-3"?z)
IsValidCodePage
Antivirus Signature
Bkav W32.AIDetectNet.01
Lionic Trojan.Win32.Generic.4!c
tehtris Generic.Malware
MicroWorld-eScan Gen:Variant.Lazy.263059
FireEye Generic.mg.5e1360b5ee1d7978
CAT-QuickHeal Clean
ALYac Gen:Variant.Lazy.263059
Malwarebytes Trojan.MalPack
Zillya Clean
Sangfor Trojan.Win32.Kryptik.V9zp
K7AntiVirus Trojan ( 005974d31 )
BitDefender Gen:Variant.Lazy.263059
K7GW Trojan ( 005974d31 )
CrowdStrike win/malicious_confidence_100% (W)
Baidu Clean
VirIT Clean
Cyren W32/S-ad060208!Eldorado
Symantec ML.Attribute.HighConfidence
Elastic malicious (high confidence)
ESET-NOD32 a variant of Win32/Kryptik.HRTC
APEX Malicious
Paloalto generic.ml
ClamAV Clean
Kaspersky Trojan-Dropper.Win32.Agent.tewsep
Alibaba TrojanDropper:Win32/Kryptik.0bab49ed
NANO-Antivirus Clean
ViRobot Clean
Rising Trojan.Kryptik!8.8 (TFE:5:o8wrBs1QCtE)
Emsisoft Gen:Variant.Lazy.263059 (B)
F-Secure Heuristic.HEUR/AGEN.1313486
DrWeb Clean
VIPRE Gen:Variant.Lazy.263059
TrendMicro Clean
Trapmine malicious.high.ml.score
CMC Clean
Sophos Mal/Generic-S
Ikarus Clean
GData Gen:Variant.Lazy.263059
Jiangmin Clean
Webroot W32.Trojan.Gen
Google Detected
Avira HEUR/AGEN.1313486
MAX malware (ai score=85)
Antiy-AVL Clean
Gridinsoft Trojan.Heur!.02290021
Xcitium Clean
Arcabit Trojan.Lazy.D40393
SUPERAntiSpyware Clean
ZoneAlarm Trojan-Dropper.Win32.Agent.tewsep
Microsoft Trojan:Win32/Woreflint.A!cl
Cynet Malicious (score: 100)
AhnLab-V3 Trojan/Win.ClipBanker.R528972
Acronis Clean
McAfee Artemis!5E1360B5EE1D
TACHYON Clean
VBA32 BScope.TrojanPSW.Coins
Cylance unsafe
Panda Trj/Genetic.gen
Zoner Clean
TrendMicro-HouseCall TROJ_GEN.R002H0CDD23
Tencent Win32.Trojan.Agen.Osmw
Yandex Clean
SentinelOne Static AI - Malicious PE
MaxSecure Clean
Fortinet W32/Kryptik.FXIU!tr
BitDefenderTheta Gen:NN.ZexaF.36132.@F0@aGyrfymi
DeepInstinct MALICIOUS
No IRMA results available.