Static | ZeroBOX

PE Compile Time

2022-11-08 02:39:22

PE Imphash

a320e29878a432b145f8a790e7e10f17

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x0000d2ba 0x00000000 0.0
.rdata 0x0000f000 0x000019ec 0x00000000 0.0
.data 0x00011000 0x0005da3c 0x00000000 0.0
.vmp0 0x0006f000 0x0009d3e8 0x00000000 0.0
.vmp1 0x0010d000 0x000b58b3 0x000b6000 7.89770328023
.rsrc 0x001c3000 0x0002faa4 0x00030000 3.41602487186

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x001c75c0 0x00000468 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED GLS_BINARY_LSB_FIRST
RT_ICON 0x001c75c0 0x00000468 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED GLS_BINARY_LSB_FIRST
RT_ICON 0x001c75c0 0x00000468 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED GLS_BINARY_LSB_FIRST
RT_ICON 0x001c75c0 0x00000468 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED GLS_BINARY_LSB_FIRST
RT_ICON 0x001c75c0 0x00000468 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED GLS_BINARY_LSB_FIRST
RT_GROUP_ICON 0x001c7a28 0x0002b07c LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data

Imports

Library KERNEL32.dll:
0x519000 GetVersionExA
0x519004 GetVersion
0x519008 HeapAlloc
Library USER32.dll:
0x519010 MessageBoxW
Library KERNEL32.dll:
0x519018 GetModuleFileNameW
Library KERNEL32.dll:
0x519020 GetModuleHandleA
0x519024 LoadLibraryA
0x519028 LocalAlloc
0x51902c LocalFree
0x519030 GetModuleFileNameA
0x519034 ExitProcess

!This program cannot be run in DOS mode.
`.rdata
@.data
kWc{wW
q0M9t0M74uP
pT|t$D
*r88d.B
Aq5e}hg
@!?FgT
W- ]q9C
1R}m1{[t
a5CoF?*
3bidWna
aj4i7Af*,
Sz**7g
GetModuleHandleA
;&6e"X
-,3'CH
DLj;gB
{frdwW
P-Iq%Q
LocalAlloc
RS>_+?
nrVrjcpG(K
lqYqux{b
bKh5&_x
user32.dll
&7Z:1*V
(;0[`q
3k' vu
8($ehP
E*O-V
[.K'#A
hKugvrj
L$dx#&
{ ICSO
'$<R]8
g(#jFac
1]GgO)
YO&4{S
n<ZWb<k
xHS!5E
yMFhjA
:;z%L7
zSd$#O
_:pCU?|
<gu3[F
Wh+"UE
C{Mn4vQ
|Ki-^NX_
WHH5[
@Fn*pt
iz?E9-
QdVc8S
4#B}0C
,4b{?$
~D?CV
='R)\*n
izz4'7
5^y=hE
G{]PMyK
*{tifw`
q+g}:^
O)8-N#
xM8pji
(n2%_s
fbRQvd
tv>l5_}
TSmv,&'
~*MGo-
=(wy[3
LocalFree
UNMSrcpG
tAz3@s
uv7J;E
0 (Tc
`xpXpp~
#Q,$4@
d$ 08
?(y\@@
KERNEL32.dll
#<&98
[VKwQ'H2mY
%&=3Nz
7)_t!J
h_ff%``
^}RQtL
%~#^f3b
GetVersion
M%!!91!
pPxlMh
Szqlw^
<?U]um
ob&7i\
K_hGmpXph
FGl9Be
GetModuleFileNameA
!mpPxH
-4kkws
ni7*Ne
0I@TT)
g@V%`O
},,0p
"&G|l\
F<V~'M;
P!P8^w
^j#^5/8
hLskfV<
wV9gKi
F?/sX\
,sV@Muc
cN,qHqA
{\QQ.b
Zg{cfK
)kyc9mtg
\niupqp
Q\I~hKn
a8wzkv
?mS1o?
8>E =r
'd^VJ7
6!a{C*
v^z?a9JA
>|C<ec
nvf"KR
`MriO.
`QIjgd
v_.=,m
}O.-4|
q}kqZ+M
SGnDqT
f-;ubkMt
#e \=}
o=X23>
QnDV'[Dwcr
x_+Ps0
L~1R6,N
B;sS2O
k|eD:}
f IM].
ku`@Z?
'|-c&r
|}Mmnh
]v\\$E
4!wunmwP=
vy"vRq
tUvb^%
P3ea%O
kL<2zc{Y
tk04i{
2y5md{
@|@}@z
@x@y@v
wZ(u(r(s(p(q(
(8K7H_(
#n+7'u#NJ[
Wo>T6%.
,F*>)6
ca|3lG
UP(S.P
@V@W@T
nek|gld
`L{=v&w
spTpUpRpS
@|@}@z@{
pkphpipfpgpd
e_@c@`
H_(\(](Z$
dp)8(D
&Fu2Hz
Js'Mq}
-~cc6k
@}dqiiqm
#O!K;
pA|c{Q
GetVersionExA
d:5PccoS
GetModuleFileNameW
:L[Vz#
Tnc~nry
-vttMP
cwsWsk
v=2NK+eR
4I~\c
o[oksi
ExitProcess
?JGb{`'
_7}atg$0
3pc-z/R
aa05`cjM
-DYyam
|/,&z."i"9B
USER32.dll
3,{F3LN
sqq@qD
iL5cV[
neJ<p^
!4$00<
yZ9"g"F
$A.=x04
Qu]mma
wJ,2a|l
9Nd4%j
~_t!6i
d|ifwp
&&_|9Be
qfU:I1
{fvo\y
8h,*G)
Xhh,P
fBwdsHt
u5Hx%
MessageBoxW
"mZl8<
W0?(T@@
!@:nv|
a5!;f:6m
L0Kh/U
C?rbklq
\~[<w,.$Yy
U;[<w0
_oc{w_f
Gd#bn
>Wd``x
uIOW2U
za,C7+
DUTmuy
^rfvSj
^c~rNz^
kz}`wvyls
-Evv*F
iL&3/G
B?+rtn$<
JN!'w3]
Md*BgB
jiV5y+
@eZkXe~
HeapAlloc
c8ULux{
gT!Mdq-
Yt{PCt
1jy<we
=fk2U>f
]rPZLVp
R'Bv.S
L%R3=,
4y{)zi
Mya*'X
ANDv #
6{!U@i.
:]0zbLP
'Dk}&:6c
Y#:.19
>&1L;z.K
O|UZWX,\}
_~xidD
s{px=z
+~P"9J
|?A87S
V, *6W
RlK36[
<8w_'E
=M^.5M
~|j<tH
M_lxWFO
b.Qv (3
eOm>s2q~
Xo\ideg
Fe#*$/
&/)"~
nat(3hO
OunAjY=
-RZRe"@
- q].p
!_'~HD
$V.4'G
L/oFmO
zxi7ue
KNrRGg
Ojs>UW8
}@J-C!
g[1e+(
3}evP6
x89OT-
+u_k=v
FofA]r
S{"K^]
'|{bA;
(qTX;Y
xg\OJA^
E-Oa_
E^:~(5
Kpmz+VZ94
: G7QL
oxOS];
=R,=XR
lM0pFaZ
}/N@rOu
k|Mc0|
x$Ipc@L
=x&V&B
=/W0"w:
uoE?N5
3;-{"U
8ZoEaz
mDI5pG
9MZDes?!Z
|;;NMq?WZ
'}aqg8
?<I@p{
e5Y+=n
IvsTaj
|WQT@8R
!k.i
-OJ)rq
WAtN1
}mU:lW
)rkL0m
f!F]NG2N8y47
Zo`m[d]
&NP?Mo
1"5,E=
VO@\x<
N1j}#4
-0O9/\
`sxvut4
p73eP<
]px}PX
gCR917SV
Onz3UQ
B7560K
{kOHOQ
8|F)1{
?Ks|CB
j|h'N7
V&.#8d
S@Is\t4
PRaJmb^
-UZSF9M
490:I>
[Sd#=+
729UXR
Nnm.N_
]>'l?&
_Pk0aK
1~7uNtp
8m, ;o
,Ok_K3+>
.+dYlc
sTOm~f
I&_8n\9
lfwx/'
IFDler
vF>o,:
:-.WEM
XOuGW#
eN]\iXy
_N{' x
WU RcdyqO
/%DWv'f}
JOuzQdf8
U.95Ny
`y: J)c
Hw,O7D
T2>wjD
\9c]vjT0
X|gfP(
rG24=vO
78uq2=
Fo#A;dS%O>
eLC@|g
hO{[~o
OE)3PF?
37O*B
?L,9(I
RZ[vmD
;m0/u-
}fHsr2
vI@AB!LO8
vO01;I
3olwDt-I
-9UC}<
=N5@Hm6
DKtwrv0
waxsvn
v3iF{*\uWD
5Lm6$}q<&
bOJL>A
ajiPo]vj
O&[|mtz
}FO>,un
r%No;?
dQ^S[TPY
r1Y5OQ
]27+~9
lRoM:\
`>e$IT
nC{0fwrsS
Km2,
Dg_~LFz
(WTQY!b
v)j-*b
5V)OSx
7n`hLO
}@0d-V5
PAMq3x
aC}xWy
xzA2E`
NbXULZ
YA*-K:#
o&gG;v2
f1^v&0
cB}QN~
IF>o#6
n)# hr/
et<]X9
mo~crt
!Lu.O5
%*eOhq
mNIgFv
yN7643;
Nr]HL"F
6C#OgA=
o\nNJI
sKL+^%Mv
9>|c9M
"'>0?,
c e<@^d
bc\ide
`[/h:D=
n@GCVK
hoYL(z
=}Ov.]
':L@p2
lv+\{C
LeytlO
.]RZ0;
yozql8
=NuE)Y
@(O!\kZ
?A2uK&]
xjOCFJ
k_.3nt@N
{%8v`9M
oO![Dm
fs$7Q%D
eGTL>f
( zrFP
/ZQPaj
E@Ot3&
ZymruL
Ng`iU@
J1D>AL
R9K2pk
l[f_~b
{Io9,0
5N7'RE9
hZSN0RX
;"!%:&
RWNFi"T
0">[])
U7%<3*
@i>'"S
PQWh^}n
/]xS{3
V"|Nh4
KNO;+$
nU`hL{t
I@PrVCN
+labiYO~qE
^sszNw
j(3M<W6
|d9wvqM
RMV|Pr
_ ,N$'
.k|sq
}p"G,4
ALR<dVE
Z{)yzbZ=!
A;0Lw/
5$u}AL
<7[aA`
c=,guJ_
nzXM.jX#
PO![tY
heLd_zi
uyWFN+
>~[TYUNZ
E1L2Yj
!m71vM
7BHS;2
Cm*MgL
.qBs'r2
vY}fSWH
,I4*PZN?
x8,OJ5
sQLx&l
?# 5+GB
gp{k6w
"K;8P2n
^kU~<qe
N_u},N)
kX2SZO
Fya`Dw
7}2pysto
W:sp'?
sob`wKl
bX0F:)
piLzLW
"31VAF/
`6jvB0
/n-7\^
%QOkJR
_J;cy}
loN6]Q_
7L6kN"
eu:Q]+
HFO*=Y9f
E>O_)|
O_wdQY
{jAeap
8~NWoO
F2s;N5~<
&^V8pyn
qfzOy
Tw0<z%
h[~ozv|
vk]F9_
]!E/Ln
fO-5`SC
G&('+%
FL^OQo
^0;NhCJB
0J4|N
@Gqg[F
4L0^~2
n$30<H
STi[|m
VUQnT"
Zk^4"X
fcla_F}
GBLdrwO1
u'4zC=~
L/~7%W=M
w(O5kN
N%10FR
<+p%@-
}K;&u
@1q|grp
Cpsu8rJ
0wqTagxp
)yb:!s
KsL?z\e
~A@M=0
)#$l>/>(7
B[ToaWB
rV"6g
W('_pd
le4..' x
prCNE
qf<+uc
MD4OPL
yop{8V
5'%VJ.
W")!&\
ePW\q~s^
M-d#Cw
Zo=e?I
P^mW`apOy
!gJD{}Oz
|'jder
c/- +VR
YcM8;-
0ky`DF
3)865+
"9EI*[;
r+]twDy
<{qpVr
!FUN*"
HDGABK
e:PtaL
mZL!+DK
NEtN{L
:)[RVOY
e^M/zU4
O.i_`ms
BJSgFf
ji1YNx
HE<(3U
V0mzY*<
d\k~V#
= nD<L
xOd^tw
O)58/2=q
KN}VCt
bU`n}hqx
LUpM8o}
ZbwM8-
[$%<-N
y(kDcJ
w&X(sG
hL#?NBQ
P9-g\J
x?Q6s3
x{91"O}R
'\IzUV
'`ck+gV
~o.nyZ
^z1fG}
rM>-n+</
%&LUI,
0_TYdr
:a@N+
.Pi`a_
e"!L4/
syNAm{
0GCY\8
4nQdeE
&!;)N>
.zNWsv=J;*
ou<v}r`x
0F:SBf
0KHJI6M
]/1l{p
|P{Al`
Ld,bZ$
vI:9L8
=p/<3>$
m:e*lF
juzAv7
Dz@zk`
k,#H=.
c?j$=2U(
KZW=2%N
} 9mv$
n[NjVyuz
Y09)N>
3I:VNN
ODrofRN
j*FW~US
'BL2Ox-)
:M Juq
/<GQeD
#)"*r1
Yh &8*
x%Fp4kk
(o_lV}
'`k~o{
$,PH'8
"'rH-Q
9B8f0(n
vVE>/w2XO
DGL(-@
Il'L<%
T2@vJ!
TV[AvtOU
Qgn|ft-
|>$L3(:P
OM.t5#
`c4V0
',]>Q^
O,$15|<
Qp8&%FZG
"/uZ~S
z2A.Oo
ZoUmC
sOc*LlXHx
n2)9O`y
K+LKT
ty/nyne
h^}jwtq@
ws:'`K
n<?%Mym*
0^pB{\{{
0WdU*/<
+/EG0,
:1x_P]R
ef-PTc
L[~hAr]Q
?.>-w
tc8npZ
;%8c!Q
pqU0$O
n\kX}i
poRu>{G
t[hfV|l
KN[!v
NRk\Cf?
053LAH
l|!J)a
=/8-LA
G:m69
&4mS<^
[zN*Eq
\OXk|$
o^y3&.*
T6|V2N
6O8,K
0?Y/8|
manR}oA
5oK#+-0
a!IDNs
rMM9'v
z-LUZV
Aoju=>N;
TOFDF-
E]%2a7V
5LCN<K?DWV
lcXC}8x
JBs&M:q,
13(y`2
h"a{DFK
EPr`9,RMbt
Azdq)A
QE|ZM
Mvc|gD
VQ\=Ng
[XAB 12
TOd]p}
|!alY`g
r@v?7)
\WjXF
j{LrA'l
PJNEunWa/@
qx}bmW
"h?=4oV
YO-+Q'|
gJ)I1%
{/4by-
y'lN%P
+-L8CLI
)|3hsz
%V[x;s
~m{0y
\&'J$J?
40}=V2
MsvL-R+
=fIENJ<z
=27N<p
VS @6@
EO}rM<
I=pK0l
OZt/8j
Y&'jB>
U`mJ{-
[]LB5@
UMxNDV
o|KC@D!O?
`Kp|42
n~DE]2
Lvoq|4
~hwrso
7+PBeO$
,b{iP7O
{]^,6$
2W!.u91L
GL~#s'
[8Xc#<
!|,3b9N
#]T$L}
(\QVkaj^Vls}
h[~qLE
O(fghx
?JAq.X
BI:O</
|Ia}eyqJs
` wdNS
AR~=$]
+RN}vt@
30JNb~w)
4/P-RQ
x5v:O*
L},!IL
VQlU`_
@-5hqN
XY<KU[
=~<NM5{
dcug?PS
H+p,96
amBO-k
hozLE:C
qyA#1%
RC{l?iaS+
85H4/J/
VMg%ms
P$O748
:)}YfG
)!F/+ow"
-<jRNm#
}>%;FP
3r-:O(
qQfVt
B.ag:|
-tn={m
LlN4rX
iVcjF^
Mc`ulX
0kLl|I
`ob!TU
87L>{9fL
)58(KB
5BFHo-
+(}3J7N
"$;*30
YV-_@s
ro`#U@
u85pi)r
x)P\Wl
*mTH'7
<dDNN(
;2gLpw
bcD\]
{Ozin
+I[v Uq
jtuwps0f@
SCyKMk
f*/WRY
{cfg+\"
3NJa%;w
_$R}VO
QOPal}gF
%+|7L5
( NvZ6%
WX#U|h
v.Zxnt
.cq=O
Wr(UPN
1$;.7*
\MBzO]
kcTG_-
fmL*K$
<,!s(
]1K?A}
to:q#0`
r1qd@t
9d%L'<ag
Zx~zEAp<
gI#Nrbwt
tO[xk7
:cXKHE
5Ns?L3BC
i_XP;,
zyL[~b4
QHIVL-
+"M84A
K;aS&9
*u0<'q
YM&)RF
\N+(.4
jmTak|r3
D5nLq|
NB}kRgJd
C{i02xr
ALo[|A
Q6ON_
"`ifka
-,;P&>
b]}!#z
|+rhNe
wOuPeg
L_<Qx*
.e8-L:
#V~GI
EaG:`+
O6CLAI
%bA`N-.
wgbexk
Bg{Lw#N
:pEn*4h
N/%MY`
'VNe%
ZO'6+|:3
oTk`jsy
Uk`.lp
;-632:M7
N?^!XE
qr|q5O3
{Vcanq
|O_lXcd
NxjUe[
!<f}_L
<aw|C>
/}g{C9
y>,M !|
KJ) %
e%(!$59
JxPmHA
Va`qxL
#q%wR{
+Gb#Cy@
z=&923
<1,rpL
+lWbmK|
jJcs[g
zLjh}k
_$,HP%
Oq^N1g
8kb:xV
[~]PYR
pJ%8A,
R]Nq <19l
C*Fx?{N
i51cEN
{iTaez
9@b#pu
zAJPH"
DKR+F:
x-[M}O:
$ce~=n
#-"mC_
*}dN3_\R
SN/pi6_#)
X'Zyp2
|]P/@gz`
P3e_ @u0Na
Af`O%1
v>K9BALb
4#59<8
O]8A(8R|
u9QC<o+
4bh{~I
aN|j($
I=BDTn
g.xJnT
sNQ@OE
tG^J571
q(&}+!
Val}c:wd
%v#8h$
Nm 723
bj}@fJ/
R-l+"z
p$SK>k
-02AMB?
8Gf mr/
Y*=.;,
dUBxkN|H
|J-T<k
f}o':z
$*}N0G>N
AT<I;:O
#H>%0x
pO@,}a
&M;C<]
8G>B74
/&M<EFC
#/L*_)]
$GL8#u
O(P_ /
*%JpEg
,N0t2|
% 9)fJ
RDap3W
yRZo[a
OD-b>[
DK($QC
O6GAt05
#%lj6|OV
^!-"#u
aBT;HDO
~'Ofed
O2g3i{"
N$}M<9
[3-FPBHb
RQ-;^L
R[$NX}k
rL+$NP
j"$:`e
$417NHB
I8$`f[&r(
DE]%YH
nU`8d.
Ved}jN
ec|s~d
(K\jLbm
V#N]elK:
}a: )`
qaRg_|
_'/a5!
:,38T;
uc02T:
G@k$?"
ncI@hZ
6Sj`gbck
V[PUR{(
6b}w)=
.^:wqF
YL8R_
lZWg'~N
MJu6vNW
[?I:"J.
S+>VBY
@<.`s54
?>Zhs[
O7DKF@H
'L`c]@
`9.k=$
De84[h|
$/N+E3
|"<I'#
H{F~5j
$/-)l*
y0;:XN
}mzkr|
VrLy3.
"R*P8+
nApPp]
K#qO$<L
mj2`Bw
MU9LK"f
u2kCv'
k=a_KJ
LoadLibraryA
QqYqie}e
bidsre
/)4 -4
^~+2Ov
0)@+?f
me,]lq?
h <40_
&`O3#O
gzN@B3
[w<O?x
EXw&-f
bA0=La
/Rr^fj
N4)-5!z
(~7*cd
FKvVKzz
yu-%5!N
l$Hh4u
D$0hud
D$,Nf1
VEAAAADCHT
RQNNQS
.QSP99900000L
.PP9961''&&&&
.99961*1'''&'!
$'66**6*****
$&6========*=
/<>==>>>>>
$6=>>>
g^^^\l
cddc_f
piiiidh
kirssjk
irstttr
oisvwwwvt
>fbijstvv
bcisstr
fddjssj~
cdccjdddbc]]\
efdccc^^]]
`^^^]^\\
'X~far
^cttou
ippppppp]
EEEdiiqqq`_l
#EGIIH+
GQUN503jwwya
PVL9;<Tjwwwh
$SW8?C>Ogjjie
ZJL8AD?MVP
!26;=[B-:E
41610*
BBB>>>)AAA/===6???9AAA7EEE0CCC*HHH UUU
S747t71|
I;;e===CFFF,YYY
BBBafff
QCCgooo
%%%)***1///62228///6)))2$$$+
J'#!x0'y
z60vUUU
pPephttp
pPephttps
WFA Hotspot 2.01'0%
Hotspot 2.0 Trust Root CA - 030
131208120000Z
431208120000Z0P1
WFA Hotspot 2.01'0%
Hotspot 2.0 Trust Root CA - 030
LWdO%b
+H/@9.
DigiCert Inc1
www.digicert.com1+0)
"DigiCert High Assurance EV Root CA0
061110000000Z
311110000000Z0l1
DigiCert Inc1
www.digicert.com1+0)
"DigiCert High Assurance EV Root CA0
:8P[w1
AA"Nea
DigiCert Inc1
www.digicert.com1!0
DigiCert Trusted Root G40
130801120000Z
380115120000Z0b1
DigiCert Inc1
www.digicert.com1!0
DigiCert Trusted Root G40
]J<0"0i3
v=Y]Bv
PAq=?Mp#
L?n(Zy&
LE2Gvg
^E3T`g
TE2_rg
GG;Gxg
.B`[k;r@
f}s#Q{[
/`0Y_s
GlobalSign Root CA - R61
GlobalSign1
GlobalSign0
141210000000Z
341210000000Z0L1 0
GlobalSign Root CA - R61
GlobalSign1
GlobalSign0
PmBf/M
'YLv9[
Entrust, Inc.1(0&
See www.entrust.net/legal-terms1907
0(c) 2009 Entrust, Inc. - for authorized use only1200
)Entrust Root Certification Authority - G20
090707172554Z
301207175554Z0
Entrust, Inc.1(0&
See www.entrust.net/legal-terms1907
0(c) 2009 Entrust, Inc. - for authorized use only1200
)Entrust Root Certification Authority - G20
N2>E34
DigiCert Inc1
www.digicert.com1 0
DigiCert Global Root CA0
061110000000Z
311110000000Z0a1
DigiCert Inc1
www.digicert.com1 0
DigiCert Global Root CA0
hn\#2K
CommonProgramFiles=C:\Program Files (x86)\Common Files
iCertAssuredIDRootCA.crl
CommonProgramW6432=C:\Program Files\Common Files
LOCALAPPDATA=C:\Users\Administrator\AppData\Local
CommonProgramFiles=C:\Program Files (x86)\Common Files
DriverData=C:\Windows\System32\Drivers\DriverData
CommonProgramW6432=C:\Program Files\Common Files
2.16.840.1.114412.0.2.4
http://crl4.digicert.com/DigiCertAssuredIDRootCA.crl
DriverData=C:\Windows\System32\Drivers\DriverData
LOCALAPPDATA=C:\Users\Administrator\AppData\Local
US1%0#
Starfield Technologies, Inc.1200
)Starfield Class 2 Certification Authority0
040629173916Z
340629173916Z0h1
US1%0#
Starfield Technologies, Inc.1200
)Starfield Class 2 Certification Authority0
qQ<0._
US1%0#
Starfield Technologies, Inc.1200
)Starfield Class 2 Certification Authority
Greater Manchester1
Salford1
COMODO CA Limited1+0)
"COMODO RSA Certification Authority0
100119000000Z
380118235959Z0
Greater Manchester1
Salford1
COMODO CA Limited1+0)
"COMODO RSA Certification Authority0
HCgNr*
N4hRF\
7E3=ke
GlobalSign nv-sa1
Root CA1
GlobalSign Root CA0
980901120000Z
280128120000Z0W1
GlobalSign nv-sa1
Root CA1
GlobalSign Root CA0
US1)0'
Internet Security Research Group1
ISRG Root X10
150604110438Z
350604110438Z0O1
US1)0'
Internet Security Research Group1
ISRG Root X10
qiJffl
AB_g$H
Greater Manchester1
Salford1
Comodo CA Limited1!0
AAA Certificate Services0
040101000000Z
281231235959Z0{1
Greater Manchester1
Salford1
Comodo CA Limited1!0
AAA Certificate Services0
2http://crl.comodoca.com/AAACertificateServices.crl06
0http://crl.comodo.net/AAACertificateServices.crl0
Baltimore1
CyberTrust1"0
Baltimore CyberTrust Root0
000512184600Z
250512235900Z0Z1
Baltimore1
CyberTrust1"0
Baltimore CyberTrust Root0
GlobalSign Root CA - R31
GlobalSign1
GlobalSign0
090318100000Z
290318100000Z0L1 0
GlobalSign Root CA - R31
GlobalSign1
GlobalSign0
,3:;%
&Y-E3'
0?1$0"
Digital Signature Trust Co.1
DST Root CA X30
000930211219Z
210930140115Z0?1$0"
Digital Signature Trust Co.1
DST Root CA X30
QuoVadis Limited1%0#
Root Certification Authority1.0,
%QuoVadis Root Certification Authority0
010319183333Z
210317183333Z0
QuoVadis Limited1%0#
Root Certification Authority1.0,
%QuoVadis Root Certification Authority0
.$T@$8
!https://ocsp.quovadisoffshore.com0
Reliance on the QuoVadis Root Certificate by any party assumes acceptance of the then applicable standard terms and conditions of use, certification practices, and the QuoVadis Certificate Policy.0"
http://www.quovadis.bm0
QuoVadis Limited1%0#
Root Certification Authority1.0,
%QuoVadis Root Certification Authority
}MQpxW
IE2BLg
GA;Aeg
1DD}9Se
Qpt.co
xmlns:
xmpGImg="http://
ns.adobe.com/xap
<xmp:Meta
/1.0/g/img/">
O9ehV.
com/xap/1.0/"
-08T18:49:43+05:^
011-12-08T18:49:b
<xmp:CreateDaj
:38:58+05:30</xmn
30</xmp:Metadata
43+05:30</xmp:Mo
difyDate>
<
xmp:ModifyDate>2"
te>2011-12-08T18*
dataDate>2011-12
[:DSBt
4O0-%i1
0Q~nPMC
Salt Lake City1
The USERTRUST Network1!0
http://www.usertrust.com1
UTN-USERFirst-Object0
990709183120Z
190709184036Z0
Salt Lake City1
The USERTRUST Network1!0
http://www.usertrust.com1
UTN-USERFirst-Object0
1http://crl.usertrust.com/UTN-USERFirst-Object.crl0)
2E38Og
DigiCert Inc1
www.digicert.com1 0
DigiCert Global Root G20
130801120000Z
380115120000Z0a1
DigiCert Inc1
www.digicert.com1 0
DigiCert Global Root G20
GA;A}g
The USERTRUST Network1!0
http://www.usertrust.com1
UTN-USERFirst-Object0
990709183120Z
190709184036Z0
Salt Lake City1
The USERT
1http://crl.usertrust.com/UTN-USERFirst-Object.crl0)
ECS1ECS2
ECS3ECS40
ECS5ECS6B
ECDPECDV
ECK1ECK2
!E3+kc
Washington1
Redmond1
Microsoft Corporation1B0@
9Microsoft ECC Development Root Certificate Authority 20180
180227203058Z
430227203856Z0
Washington1
Redmond1
Microsoft Corporation1B0@
9Microsoft ECC Development Root Certificate Authority 20180v0
4http://www.microsoft.com/pkiops/Docs/Repository.htm
ProgramData=C:\ProgramData
ProgramW6432=C:\Program Files
HOMEPATH=\Users\Administrator
USERDOMAIN_ROAMINGPROFILE=N1
ALLUSERSPROFILE=C:\ProgramData
PROCESSOR_ARCHITEW6432=AMD64
__COMPAT_LAYER=Installer
PROCESSOR_ARCHITECTURE=x86
GG;Gkf
1.3.14.3.2.26
PSModulePath=C:\Program Files\WindowsPowerShell\Modules;C:\Windows\system32\WindowsPowerShell\v1.0\Modules
PSModulePath=C:\Program Files\WindowsPowerShell\Modules;C:\Windows\system32\WindowsPowerShell\v1.0\Modules
GA;Ake
Hx8f&#xA;Hx8fHx8
fHx8fHx8fHx8fHx8
O9ehV.
5.cmananan.exe
6.cmananan.exe
Certum
thawte
Sectigo
\??\C:\Users\Administrator\Desktop\1-30.cmananan.com-5173\SystemResources\4.cmananan.exe.mun
\??\C:\Users\Administrator\Desktop\1-30.cmananan.com-5173\SystemResources\6.cmananan.exe.mun
\??\C:\Users\Administrator\Desktop\1-30.cmananan.com-5173\SystemResources\1.cmananan.exe.mun
729e6725-122d-4905-9e90-ed3351fd101b
Microsoft Software Key Storage Provider
\??\C:\Users\Administrator\Desktop\1-30.cmananan.com-5173\SystemResources\2.cmananan.exe.mun
\??\C:\Users\Administrator\Desktop\1-30.cmananan.com-5173\SystemResources\6.cmananan.exe.mun
\??\C:\Users\Administrator\Desktop\1-30.cmananan.com-5173\SystemResources\5.cmananan.exe.mun
\??\C:\Users\Administrator\Desktop\1-30.cmananan.com-5173\SystemResources\3.cmananan.exe.mun
\??\C:\Users\Administrator\Desktop\1-30.cmananan.com-5173\SystemResources\5.cmananan.exe.mun
729e6725-122d-4905-9e90-ed3351fd101b
Microsoft Software Key Storage Provider
SHA384
.\Device\HarddiskVolume3]
%USERPROFILE%\AppData\Local
%USERPROFILE%\AppData\Local
.\Device\HarddiskVolume3
DigiCert Baltimore Root
DigiCert Global Root G2
GlobalSign Root CA - R3
Buypass Class 2 Root CA
GlobalSign Root CA - R1
QuoVadis Root CA 2 G3
Thawte Timestamping CA
Sectigo (UTN Object)
TrustedPeople
GlobalSign Root CA - R6
RSA/SHA256
RSA/SHA256
RSA/SHA256
C:\Users\Administrator\Desktop\1-30.cmananan.com-5173\
\1.cmananan.exe
http://crl3.digicert.com/sha2-assured-cs-g1.crl
http://crl4.digicert.com/sha2-assured-cs-g1.crl
Sectigo (UTN Object)
http://crl3.digicert.com/sha2-assured-cs-g1.crl
http://crl4.digicert.com/sha2-assured-cs-g1.crl
http://crl3.digicert.com/sha2-assured-cs-g1.crl
http://crl4.digicert.com/sha2-assured-cs-g1.crl
http://crl3.digicert.com/sha2-assured-cs-g1.crl
http://crl4.digicert.com/sha2-assured-cs-g1.crl
http://crl3.digicert.com/sha2-assured-cs-g1.crl
http://crl4.digicert.com/sha2-assured-cs-g1.crl
http://crl3.digicert.com/sha2-assured-cs-g1.crl
http://crl4.digicert.com/sha2-assured-cs-g1.crl
http://crl3.digicert.com/sha2-assured-cs-g1.crl
http://crl4.digicert.com/sha2-assured-cs-g1.crl
http://crl3.digicert.com/sha2-assured-cs-g1.crl
http://crl4.digicert.com/sha2-assured-cs-g1.crl
SOFTWARE\Microsoft\Cryptography\Defaults\Provider\Microsoft Enhanced RSA and AES Cryptographic Provider
http://crl3.digicert.com/sha2-assured-cs-g1.crl
http://crl4.digicert.com/sha2-assured-cs-g1.crl
http://crl3.digicert.com/sha2-assured-cs-g1.crl
http://crl4.digicert.com/sha2-assured-cs-g1.crl
http://crl3.digicert.com/sha2-assured-cs-g1.crl
http://crl4.digicert.com/sha2-assured-cs-g1.crl
http://crl3.digicert.com/sha2-assured-cs-g1.crl
http://crl4.digicert.com/sha2-assured-cs-g1.crl
http://crl3.digicert.com/sha2-assured-cs-g1.crl
http://crl4.digicert.com/sha2-assured-cs-g1.crl
http://crl3.digicert.com/sha2-assured-cs-g1.crl
http://crl4.digicert.com/sha2-assured-cs-g1.crl
http://crl3.digicert.com/sha2-assured-cs-g1.crl
http://crl4.digicert.com/sha2-assured-cs-g1.crl
SOFTWARE\Microsoft\Cryptography\Defaults\Provider\Microsoft Enhanced RSA and AES Cryptographic Provider
ECDSA/SHA384
ECDSA/SHA384
System\RemoteTextInputProcessorDefault1
C:\Users\Administrator\AppData\LocalLow\SogouWB.users
C:\Program Files (x86)\SogouWBInput\5.5.0.2580\Data
C:\Windows\SysWOW64\cryptnet.dll
C:\Users\Administrator\AppData\LocalLow\SogouWB.users
C:\Users\Administrator\AppData\LocalLow\SogouWB.users
Microsoft ECC Product Root Certificate Authority 2018
C:\Users\Administrator\AppData\LocalLow\SogouWB.users
Microsoft Time Stamp Root Certificate Authority 2014
C:\Program Files (x86)\SogouWBInput\5.5.0.2580\Data
DigiCert
RSA/SHA256
Entrust.net
DigiCert
VeriSign
C:\Users\Administrator\Desktop\1-30.cmananan.com-5173\
Antivirus Signature
Bkav W32.AIDetectMalware
Lionic Clean
Elastic malicious (high confidence)
DrWeb Clean
MicroWorld-eScan Gen:Variant.Jaik.106867
FireEye Generic.mg.c7c3f41117bfe6c2
CAT-QuickHeal Clean
ALYac Gen:Variant.Jaik.106867
Malwarebytes Backdoor.Farfli
VIPRE Gen:Variant.Jaik.106867
Sangfor Clean
K7AntiVirus Trojan ( 7000001c1 )
BitDefender Gen:Variant.Jaik.106867
K7GW Trojan ( 7000001c1 )
Cybereason malicious.117bfe
BitDefenderTheta AI:Packer.DFBD157A1F
VirIT Clean
Cyren W32/Farfli.IP.gen!Eldorado
tehtris Clean
ESET-NOD32 a variant of Win32/Packed.VMProtect.ABO
Cynet Malicious (score: 100)
APEX Malicious
Paloalto Clean
ClamAV Clean
Kaspersky VHO:Backdoor.Win32.Convagent.gen
Alibaba Clean
NANO-Antivirus Clean
ViRobot Clean
Rising Trojan.Generic@AI.99 (RDMK:cmRtazrD+6FZYRn28VMRH45Kk1IC)
Sophos Mal/VMProtBad-A
F-Secure Trojan.TR/Black.Gen2
Baidu Clean
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition BehavesLike.Win32.Generic.dc
Trapmine malicious.high.ml.score
CMC Clean
Emsisoft Gen:Variant.Jaik.106867 (B)
SentinelOne Static AI - Malicious PE
GData Gen:Variant.Jaik.106867
Jiangmin Clean
Webroot Clean
Avira TR/Black.Gen2
MAX malware (ai score=87)
Antiy-AVL Clean
Gridinsoft Clean
Xcitium Clean
Arcabit Trojan.Jaik.D1A173
SUPERAntiSpyware Clean
ZoneAlarm VHO:Backdoor.Win32.Convagent.gen
Microsoft Trojan:Win32/Farfli.DSK!MTB
Google Detected
AhnLab-V3 Trojan/Win.Farfli.R573513
Acronis Clean
McAfee Clean
TACHYON Clean
DeepInstinct MALICIOUS
VBA32 BScope.Backdoor.Farfli
Cylance unsafe
Panda Trj/Genetic.gen
Zoner Clean
TrendMicro-HouseCall Clean
Tencent Clean
Yandex Clean
Ikarus Trojan.Win32.VMProtect
MaxSecure Trojan.Malware.300983.susgen
Fortinet W32/Zard.30!tr
AVG Win32:RATX-gen [Trj]
Avast Win32:RATX-gen [Trj]
CrowdStrike win/malicious_confidence_90% (D)
No IRMA results available.