Static | ZeroBOX

PE Compile Time

2023-05-14 21:18:36

PE Imphash

46c74cf13312d6259105eaa206ede1b5

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x00021b8d 0x00021c00 6.62212104283
.rdata 0x00023000 0x0000658a 0x00006600 5.6843537701
.data 0x0002a000 0x00028568 0x00026600 7.73406737028
.rsrc 0x00053000 0x00000620 0x00000800 3.26334371795

Resources

Name Offset Size Language Sub-language File type
RT_VERSION 0x00053200 0x0000041c LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_MANIFEST 0x000530a0 0x0000015a LANG_ENGLISH SUBLANG_ENGLISH_US ASCII text, with CRLF line terminators

Imports

Library KERNEL32.dll:
0x423028 SetStdHandle
0x42302c WriteConsoleW
0x423030 WriteConsoleA
0x423038 GetLocaleInfoW
0x42303c CreateFileA
0x423040 FreeConsole
0x423044 GetModuleHandleA
0x423048 MultiByteToWideChar
0x42304c GetConsoleOutputCP
0x423050 GetProcAddress
0x42305c WideCharToMultiByte
0x423060 Sleep
0x423064 InterlockedExchange
0x423078 RtlUnwind
0x423080 RaiseException
0x423084 TerminateProcess
0x423088 GetCurrentProcess
0x423094 IsDebuggerPresent
0x423098 GetCommandLineA
0x42309c GetLastError
0x4230a0 HeapFree
0x4230a4 GetCPInfo
0x4230a8 LCMapStringA
0x4230ac LCMapStringW
0x4230b0 GetModuleHandleW
0x4230b4 TlsGetValue
0x4230b8 TlsAlloc
0x4230bc TlsSetValue
0x4230c0 TlsFree
0x4230c4 SetLastError
0x4230c8 GetCurrentThreadId
0x4230cc HeapAlloc
0x4230d0 ExitProcess
0x4230d4 WriteFile
0x4230d8 GetStdHandle
0x4230dc GetModuleFileNameA
0x4230f0 SetHandleCount
0x4230f4 GetFileType
0x4230f8 GetStartupInfoA
0x4230fc HeapCreate
0x423100 VirtualFree
0x423108 GetTickCount
0x42310c GetCurrentProcessId
0x423110 VirtualAlloc
0x423114 HeapReAlloc
0x423118 GetConsoleCP
0x42311c GetConsoleMode
0x423120 FlushFileBuffers
0x423124 ReadFile
0x423128 SetFilePointer
0x42312c CloseHandle
0x423130 HeapSize
0x423134 GetACP
0x423138 GetOEMCP
0x42313c IsValidCodePage
0x423140 GetUserDefaultLCID
0x423144 GetLocaleInfoA
0x423148 EnumSystemLocalesA
0x42314c IsValidLocale
0x423150 GetStringTypeA
0x423154 GetStringTypeW
0x423158 LoadLibraryA
Library USER32.dll:
0x423160 GetClassInfoA
0x423164 CallWindowProcA
0x423168 SetWindowLongA
0x42316c CheckDlgButton
0x423170 GetActiveWindow
0x423174 LoadCursorA
0x423178 MessageBoxA
0x42317c wsprintfA
0x423180 GetDlgItemTextA
Library GDI32.dll:
0x423014 SetTextColor
0x423018 CreateFontIndirectA
0x42301c SelectObject
0x423020 SetBkMode
Library COMDLG32.dll:
0x423008 GetSaveFileNameA
0x42300c GetOpenFileNameA
Library ADVAPI32.dll:
0x423000 RegDeleteKeyA

!This program cannot be run in DOS mode.
|oRich
`.rdata
@.data
t}9>uyj
tz9uvj
F09^(u
QQSVWd
PPPPPPPP
0WWWWW
0WWWWW
HtHu4j
s[S;7|G;w
tR99u2
uQhHMB
t"SS9]
^SSSSS
^SSSSS
_VVVVV
^WWWWW
t$h@WB
teh0kA
0SSSSS
>=Yt1j
j@j ^V
C PjPV
C$PjQV
C*PjTV
C+PjUV
C,PjVV
C-PjWV
C.PjRV
C/PjSV
0A@@Ju
0SSSSS
0SSSSS
PPPPPPPP
t+WWVPV
0SSSSS
_VVVVV
;t$,v-
UQPXY]Y[
URPQQh
^SSSSS
j"^SSSSS
HHtYHHt
u,VVWV
t VV9u
<+t(<-t$:
+t HHt
bad allocation
wgfxiyffwhfthwzkjstrfytmtgrvcrhpvwwyrbdpwyguhmuwdewktrefewezlckfhwz
wgfxiyffwhfthwzkjstrfytmtgrvcrhpvwwyrbdpwyguhmuwdewktrefewezlckfhwz
wgfxiyffwhfthwzkjstrfytmtgrvcrhpvwwyrbdpwyguhmuwdewktrefewezlckfhwz
xhfdkvehuuenklletz
wgfxiyffwhfthwzkjstrfytmtgrvcrhpvwwyrbdpwyguhmuwdewktrefewezlckfhwz
yxiawcuo
wgfxiyffwhfthwzkjstrfytmtgrvcrhpvwwyrbdpwyguhmuwdewktrefewezlckfhwz
molvkmzckcbkypxdly
ctvwbkoyznheahvisyusggcdgyruttjvfyvexfukeyzmxlohawxsukwxsstnkfomujo
ctvwbkoyznheahvisyusggcdgyruttjvfyvexfukeyzmxlohawxsukwxsstnkfomujo
vkljdctmcompgsvoev
ctvwbkoyznheahvisyusggcdgyruttjvfyvexfukeyzmxlohawxsukwxsstnkfomujo
dreirsbgotjkxyxtezxgiymbmjqqgfke
trxpgmheqxelrdxxekkwuxqzxqonuwxoccfpvwjylnsifofobfuesutqdvqwdhaculfrpystg
grsbjvhfohwomomxczpyncklfzpbpbrsoxpnwbinsbqekttovylwknppsbedarzqwaeygbairlinqcki
ayloivrzhahrzyo
xgpvjsheelqhy
tcmcezgaijarrzklmokopmiapnjzvynfgrjeabpqxmfophyjilhgnlexkkgzcomxfbbpztqupnzplbpikxabdwqlbxwuxtj
srwfqnhktksrdfcwnvlbrnfjsryrwtfsjdyxljexeccmnc
snpulfmcwrwaggaqxofhelhjwvxfpqteabmhvexqcchodscmabqlokbsncbfkuuikanogb
xccwulj
mmgfmyzrpkgapkxkjzox
dreirsbgotjkxyxtezxgiymbmjqqgfke
dreirsbgotjkxyxtezxgiymbmjqqgfke
gtcbiruhvdsyhatkqmhpjvklwgecjvctugswb
zxefunwibqibimfidvqhwpcbqgopafgmfgdmtjyfmahlsioeninh
stbxylmtqkimjvtcf
oucqzuhygfjaxaxezhccsibzcvafhizxqjwo
xbanttvxoaeitcaknyphhevgdgtslwsvtssgoryfiucdmdxspcwezzigxicowgvlcrlnyqrcgvceawdvaibuowponzidfzwq
kpdykgqyekmhxftehnijngcfyfgcbqyszkmaxdbksqxwpjzuxrtwybnlyexeohaxwrjrftly
gckzvhskohudjeewyrwfcswwnrnijcvpsxqwlbkgmprslbbwxltdorrua
rtuudyjwbovucpepgisaszcfoywghcctakjlmrxzvtm
ylaarxrsimnoadwbwttbbnezaxlt
eiktkrnwynrabihqxvxehbramkcerlutuhandgfsaxyazkzeqnxyxeazlgjqnxrlywlvfmgglgale
gmpyxbvxrxgdjlpzvfspfdc
mwflgurflnasaujjgdgnnitjxeckiirxojprxybitbvnvgwyrmsyevnoskwnmdzxbfideqrhdygbmrdivq
igsrfiuzmhqlxigbiugwaall
pktzmuuttvxjskbibjvm
xriwkxjasgrtkshhikzbkjdwlkqvsnwrcxwfkbohakodmnm
nuoqjlaqqjvtzjibbsmnzzxjtjhtkryahfzztgnnsxhpwcztbirrydjfaqwodfehgjzv
dqplctpsirbbtofdvkkrfzinkwkzpjugmzybweo
sirlhwysfjyqeqsbozgyqllgqtxkzitirmytgngzwjmmhbmdnfjxxypcxbtscilzjwfl
uiydtlliecbavwyixt
hgjtdvifgjcjcnsifskcgqhtnnhqfjercrbrssuvxgpycvdydyaxnnxngtgerbpmmjqigeqfnceqkoizynk
inpjgpbcnllokwgdnceasaxrevusiymjojzyijqcrtortoulepxbrbwyvedvvsk
tpnysepy
fntynmbjtguzbagekwqdoqohfgtmklbdfx
VirtualProtect
vercthmamrfyrofvlngoeozucjxokhzbfaffwrhzbryfjuwrwgxftmxpnoiqmzaxh
vercthmamrfyrofvlngoeozucjxokhzbfaffwrhzbryfjuwrwgxftmxpnoiqmzaxh
vercthmamrfyrofvlngoeozucjxokhzbfaffwrhzbryfjuwrwgxftmxpnoiqmzaxh
^-C@\s
_{M-\6
"]uP>^
^2N]kx
6]6XO\F
>]Px]
.]0a\M
S]RpP\
\X6S]9H
^Bf/^{
^n2,\$
N]j]O\
Q7]q 1\
]x!8]U6
;]LiD\@
7]G<G\
^l3Z\0
5IGarbage value:
@Class 1 - X:
Value is greater than 0.5
?Class 2 - Name:
, Value:
ios_base::eofbit set
ios_base::failbit set
ios_base::badbit set
bad cast
raB3G%p
bad allocation
string too long
invalid string position
Unknown exception
bad exception
LC_TIME
LC_NUMERIC
LC_MONETARY
LC_CTYPE
LC_COLLATE
LC_ALL
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
GAIsProcessorFeaturePresent
KERNEL32
EncodePointer
DecodePointer
FlsFree
FlsSetValue
FlsGetValue
FlsAlloc
(null)
`h````
xpxxxx
CorExitProcess
runtime error
TLOSS error
SING error
DOMAIN error
An application has made an attempt to load the C runtime library incorrectly.
Please contact the application's support team for more information.
- Attempt to use MSIL code from this assembly during native code initialization
This indicates a bug in your application. It is most likely the result of calling an MSIL-compiled (/clr) function from a native constructor or from DllMain.
- not enough space for locale information
- Attempt to initialize the CRT more than once.
This indicates a bug in your application.
- CRT not initialized
- unable to initialize heap
- not enough space for lowio initialization
- not enough space for stdio initialization
- pure virtual function call
- not enough space for _onexit/atexit table
- unable to open console device
- unexpected heap error
- unexpected multithread lock error
- not enough space for thread data
This application has requested the Runtime to terminate it in an unusual way.
Please contact the application's support team for more information.
- not enough space for environment
- not enough space for arguments
- floating point support not loaded
Microsoft Visual C++ Runtime Library
<program name unknown>
Runtime Error!
Program:
HH:mm:ss
dddd, MMMM dd, yyyy
MM/dd/yy
December
November
October
September
August
February
January
Saturday
Friday
Thursday
Wednesday
Tuesday
Monday
Sunday
united-states
united-kingdom
trinidad & tobago
south-korea
south-africa
south korea
south africa
slovak
puerto-rico
pr-china
pr china
new-zealand
hong-kong
holland
great britain
england
britain
america
swedish-finland
spanish-venezuela
spanish-uruguay
spanish-puerto rico
spanish-peru
spanish-paraguay
spanish-panama
spanish-nicaragua
spanish-modern
spanish-mexican
spanish-honduras
spanish-guatemala
spanish-el salvador
spanish-ecuador
spanish-dominican republic
spanish-costa rica
spanish-colombia
spanish-chile
spanish-bolivia
spanish-argentina
portuguese-brazilian
norwegian-nynorsk
norwegian-bokmal
norwegian
italian-swiss
irish-english
german-swiss
german-luxembourg
german-lichtenstein
german-austrian
french-swiss
french-luxembourg
french-canadian
french-belgian
english-usa
english-us
english-uk
english-trinidad y tobago
english-south africa
english-nz
english-jamaica
english-ire
english-caribbean
english-can
english-belize
english-aus
english-american
dutch-belgian
chinese-traditional
chinese-singapore
chinese-simplified
chinese-hongkong
chinese
canadian
belgian
australian
american-english
american english
american
Norwegian-Nynorsk
Complete Object Locator'
Class Hierarchy Descriptor'
Base Class Array'
Base Class Descriptor at (
Type Descriptor'
`local static thread guard'
`managed vector copy constructor iterator'
`vector vbase copy constructor iterator'
`vector copy constructor iterator'
`dynamic atexit destructor for '
`dynamic initializer for '
`eh vector vbase copy constructor iterator'
`eh vector copy constructor iterator'
`managed vector destructor iterator'
`managed vector constructor iterator'
`placement delete[] closure'
`placement delete closure'
`omni callsig'
delete[]
new[]
`local vftable constructor closure'
`local vftable'
`udt returning'
`copy constructor closure'
`eh vector vbase constructor iterator'
`eh vector destructor iterator'
`eh vector constructor iterator'
`virtual displacement map'
`vector vbase constructor iterator'
`vector destructor iterator'
`vector constructor iterator'
`scalar deleting destructor'
`default constructor closure'
`vector deleting destructor'
`vbase destructor'
`string'
`local static guard'
`typeof'
`vcall'
`vbtable'
`vftable'
operator
delete
__unaligned
__restrict
__ptr64
__clrcall
__fastcall
__thiscall
__stdcall
__pascal
__cdecl
__based(
`h`hhh
xppwpp
GetProcessWindowStation
GetUserObjectInformationA
GetLastActivePopup
GetActiveWindow
MessageBoxA
USER32.DLL
SunMonTueWedThuFriSat
JanFebMarAprMayJunJulAugSepOctNovDec
1#QNAN
1#SNAN
CONOUT$
GetProcAddress
GetModuleHandleA
MultiByteToWideChar
FreeConsole
KERNEL32.dll
GetDlgItemTextA
wsprintfA
MessageBoxA
LoadCursorA
GetActiveWindow
CheckDlgButton
SetWindowLongA
CallWindowProcA
GetClassInfoA
USER32.dll
SelectObject
CreateFontIndirectA
SetTextColor
SetBkMode
GDI32.dll
GetSaveFileNameA
GetOpenFileNameA
COMDLG32.dll
RegDeleteKeyA
ADVAPI32.dll
InterlockedIncrement
InterlockedDecrement
WideCharToMultiByte
InterlockedExchange
InitializeCriticalSection
DeleteCriticalSection
EnterCriticalSection
LeaveCriticalSection
RtlUnwind
GetSystemTimeAsFileTime
RaiseException
TerminateProcess
GetCurrentProcess
UnhandledExceptionFilter
SetUnhandledExceptionFilter
IsDebuggerPresent
GetCommandLineA
GetLastError
HeapFree
GetCPInfo
LCMapStringA
LCMapStringW
GetModuleHandleW
TlsGetValue
TlsAlloc
TlsSetValue
TlsFree
SetLastError
GetCurrentThreadId
HeapAlloc
ExitProcess
WriteFile
GetStdHandle
GetModuleFileNameA
FreeEnvironmentStringsA
GetEnvironmentStrings
FreeEnvironmentStringsW
GetEnvironmentStringsW
SetHandleCount
GetFileType
GetStartupInfoA
HeapCreate
VirtualFree
QueryPerformanceCounter
GetTickCount
GetCurrentProcessId
VirtualAlloc
HeapReAlloc
GetConsoleCP
GetConsoleMode
FlushFileBuffers
ReadFile
SetFilePointer
CloseHandle
HeapSize
GetACP
GetOEMCP
IsValidCodePage
GetUserDefaultLCID
GetLocaleInfoA
EnumSystemLocalesA
IsValidLocale
GetStringTypeA
GetStringTypeW
LoadLibraryA
InitializeCriticalSectionAndSpinCount
WriteConsoleA
GetConsoleOutputCP
WriteConsoleW
SetStdHandle
GetLocaleInfoW
CreateFileA
1zyl2BUb
yoEEhD
gz\ReI
[3E%V@%lw3
]@-g\s\]I
DV\~j)d
|D<9z:Mp
Nwd^]+
h:\jNI
bVw3rhL%hE>
`yId1a
yBgsC&
[3EnV@
]+31Q\
yoEJhDD=~I7
GLk[~B
|Dd9z:
Nwd-]+O1Q\
bc:XXe
Vw3uhL]hE>y
|DH9z:Jp
]+k1Q\
h:\lNI
Fc:X^e
6Vw31hLyhE>m
Ww3~hL
C&lZ3E-V@
|:~t]@
]Iy<wB9h
xoENhD
Ax~>+NIBW6~
+BOwdf]+
Ww3/hL
xBgwC&4Z3EaV@
]I!<wB
xoE1hD
V?NW>z
GL3Z~B
]+'0Q\
i:\;NI
rWw36hL5iE>
z^`\Cl
Owdb]+C0Q\
h&MDg`
~0~o2L
8z:G3I<X`&J/H5
G8Nfz\
C@ZOd:
Y&PSd3]
bQ~"h&^Dg`
hDa<~I
GLFZ~B
x~>BNI
|DC8z:-p
G8jfz\
hLwiE>
Z3EwV@^mw32
W6~W|D
+uLwda]+
{oELhD
NIiT6~
C&IY3E
]IT?wB
T>z!G3
@>QAC@
aQ~?h&
NI.T6~]|D
{BgRC&
Y3EKV@
V?CT>z1G3
({6QQG8ez\
@>QiC@
GL>Y~B
|D;;z:
S]`\`l
"?YsU$D
]+"3Q\
]+73Q\-{
hL:jE>
y{IdYa
+c{Bg!
T>z}G3]?X`*J/\6
Tw33hLOjE>.
dQ{A+p{Bg
T>zLG3B?X`"J/A6
+({oE~&Dg?~I
HDe\sl
oM6}r3
:~f]@Je\s)]I
oGDZr3
e@>QBC@wLd:
Y&{Pd3
&6{Gg`
V?>T>zdG3
~:~|]@
]Ie>wB
\D7yk:\
d\s:]IF>wB~h
C&HX3E:
U>zeG3
>X` J/
zoE~hD
+/MwdI]+
`Q~#h&
k:\TNI
dcGL%X~B
Q6>V?QU>zHG3
>X`"J/
+PzoEI#[~:~>
^\`\J/
oM65s3
+e~:~6]@
d\s#]I
hL,kE>
kzIdM"0XsU
]+32Q\
hL6kE>#
t`:X?e
U6~P|De:z:Jp
]+N2Q\t{
hDP>~Ia
diGLwX~B
U6~||Dp:z:\p
yU~6ae
&DfkE>&Dm>~I]@Nd\s']I
%U\~}^
V?0U>z
+i>X`e
8Uw3AhL{kE>*
A+\zBg
9\kNIp}
y:~s]@
]I~9wB
D/bl:\R
Jd:kY&
C&`_3E
}6Q;G8
Jd:`Y&
VgQ~A+
Rw3=hL
}BgcC&0_3E
c\s"]I=9wB@h
_3EvV@
9X`[J/
}6QlG8
Jd:'Y&
}oEQhD
GL*_~B
}~>jNI
|D'=z:
#}6QcG8
F>QAC@
9~I]@:c\s
hD*9~I
}~>#NI
|[`\v"
Rw3rhL@lE>
GLh_~B
zg:Xe
Rw32hLUlE>
~GDst3
H^Jd:a
+@}Bg[C&
_3EyV@Fhw3
]@Nc\s
V?0R>zMG3i9X`
[}6QgG8ncz\
hD~9~I
S>zNG3
bz\MeI
NIRS6~
Sw3BhL
|BggC&G^3E
NIOS6~
+7Kwd*]+
Sw3rhL
d-GL+^~B
2\$<z:G3
GL6^~B
h&#@g`
b\s']I
bS\~4^
V?qS>z
G3*8X`
|6QlG8-bz\`eI
C@;Kd:
Y&7Wd3
h&?@g`ye
hDF8~I
GLi^~B`Y
G3V8X`cJ/U1
~|6QSG8Ibz\
EG>Q6C@WKd:
Y&[Wd3(
fQ~Dh&[@g`
hDZ8~IG
d%GLM^~B
S6~h|DF<z:
KwdW]+m4Q\U{
Df:Xe
&T{mE>hD~8~I
d9GLQ^~B8Y
NIqP6~
?|n:\pNIy
Cg`C&n]3E
]Iw;wB
Pw3yhL
C&?]3EBV@
+?Hwdm]+
Pw3shL
C&#]3E
az\zeI
Hd:GY&
dnGL"]~B
V?PP>z
V@;jw30
|D5?z:
YY`\J/
G88az\
bPw3'hL%nE>
]+37Q\
P~6-e
hLAnE>e
V@djw3BG
{:~v]@la\s
+O;X`e
LP~66e
hL]nE>
V@@jw3
]@@a\s
hLynE>#
o;\kNIr~
~oE%&D
]I`:wB
Q>z9G3
:X` J/
E>QLC@
+]Iwdn]+
D/Xo:\R
E>QDC@
Id:'Y&
~oEyhD
:\kNI0~
&dQ~m&6
Bg`C&7\3E'V@
]I>:wB
Q>z@G3
:X`/J/
E>QTC@
_{HZ&hNJ|
R\~Bg'r
=Q>z:j
[`\sU#
c\sUd',
_~Bg`=
lE>Q>B
F>Q>z}
}Bg`zd8_
=Q>z:9{
=Q>z:F
F>Q>z.
7R6~oEy
}oE>QJ
C@%Bd:
IwK=s*
9~Id:(
5Q\~B @
2<]dy:
- Hd:$[
B_KzKg`B
}Hd:Xw
}Hd:Xw
wJfI,z
?!S>zL
@Y>3JP
$wE*Jd69
is?QwG7
}F5MwdW
3^]E*z,
%N$1W6~
-#b\s)_
spY`\g
B~Ph13
10FaY:~q
r;FQ~BQ
c]sUd$w
jF9^oE
={:~Is_
}Hd:XX
Utcz\$
a^J0X` H
r3dQ~B
6x\Q8X
riU~~>
~oEJ^Ds
i[tw3+%
9Y`\sB
$}3l;\kw$K
F%}oEJ
U`az\$*
i_Vw3++
+ief~>
SQj-%\
o-nb\s!
eQ~6-k~UZ
JFKDoEJ
!~TE>%
lD>Q>m
E,Upg'
#Qy*~I\
819lFEd
dEi5I{
kgS~6E
ri7j~>F
#kF;pQ\
z~>G?2
KkwO?a
]xf=Q>
ibf~>m
1\sU-pn
^BhX`(
$ hwB$
F,f:~^(
iU~\~6
ine~>m
F50oEJ
p{sp,6Qd
bX`jO!d
-^;\s)_
j%qBmT
1Pn(|]
6t6]F[
,L(U!SG
Y@)RS}
~~H3\1
Q@4@G>QH8
E+g|Bg
S~6#&YAg`
oH&Lt3
B@YJd:
-:Mw3AA
kSo@fW
kSo@fWG
"ih@~>'
9Y`\sB
=vc11Y
kSo@fW
ZifS\~6
zxM1kw3
$K<6~o
)+T~Id
wKM<d3
Lg.1&,1G
{Z4kDj
5,Upb!
}jA>+)
VG?^JIoi!
`~Bdpgz
z:~<SEN
\kwG'-
?QwO?66
D98~Ip{.
}QDakw
P$sD[m
5"uw3s
M3x:\k
]}'3^~
}Cg`zK"
[$B`wB
mn|IdFc
kSo@fW
LIz~ZA
R]~Bgt
HhqTSIo((
kSo@fW
JuiFRk
VnB|C~Ru{-
v@n9_QrImir[
j\r=[UvEae~_
,V6X^
\hD%F}@hO}+
hZt?Y[xGccx]
sZ%`Tx!ByDdCq'
lVx3U_|Cg
{:~I^J
c&)[5w
~4Qc|=
J(gsV(Dw6ut
h=^%XV
U\D;:<)
>q|"Q2
zYU)2?4C
`UgJl'G
yUrZTH
Ja|. A
Wf_?(Wg
3[dSDB
JVl2en
,8wzS0m
WA)R+V
8r'4;>:0
b:0?6D
GVz>*B
"tbE.*A
]C-}}H
V&$$s.g
Dxs.Xz
Q+oA~=
szmfK
Dws*YK
Orwow?{
,stlXK}3
NDwbw9{
v^w2z-X
-rAlYK}3
UuQ2#
~xQ oP
Opwlw2
s~l[JD3
Q?"+{wk
~uQ&n|~5
/rCmmJB3
HRHd!W
"&DI6E
jtWR)
G;oZlq
U+B&wY
::J>ZX
}o^Ezns
i#@(o"}2
Lew%-bx
.?AVfailure@ios_base@std@@
.?AVruntime_error@std@@
.?AVexception@std@@
.?AVbad_cast@std@@
.?AVbad_alloc@std@@
.?AV?$num_put@DV?$ostreambuf_iterator@DU?$char_traits@D@std@@@std@@@std@@
.?AVfacet@locale@std@@
.?AV?$numpunct@D@std@@
.?AUctype_base@std@@
.?AVios_base@std@@
.?AV?$_Iosb@H@std@@
.?AV?$basic_ostream@DU?$char_traits@D@std@@@std@@
.?AV?$basic_ios@DU?$char_traits@D@std@@@std@@
.?AV?$ctype@D@std@@
.?AV?$basic_streambuf@DU?$char_traits@D@std@@@std@@
.?AV?$basic_filebuf@DU?$char_traits@D@std@@@std@@
.?AVcodecvt_base@std@@
.?AV?$codecvt@DDH@std@@
.?AVlogic_error@std@@
.?AVlength_error@std@@
.?AVout_of_range@std@@
.?AV_Locimp@locale@std@@
Copyright (c) 1992-2004 by P.J. Plauger, licensed by Dinkumware, Ltd. ALL RIGHTS RESERVED.
.?AVtype_info@@
.?AVbad_exception@std@@
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v3">
<security>
<requestedPrivileges>
<requestedExecutionLevel level="asInvoker" uiAccess="false"></requestedExecutionLevel>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
DigiCert Inc1
www.digicert.com1!0
DigiCert Trusted Root G40
210429000000Z
360428235959Z0i1
DigiCert, Inc.1A0?
8DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA10
[K]taM?
SA|X=G
http://ocsp.digicert.com0A
5http://cacerts.digicert.com/DigiCertTrustedRootG4.crt0C
2http://crl3.digicert.com/DigiCertTrustedRootG4.crl0
jj@0HK4
DigiCert, Inc.1A0?
8DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA10
210819000000Z
230819235959Z0
California1
Redwood City1
Oracle America, Inc.1
Software Engineering1
Oracle America, Inc.0
@`ihQs
Mhttp://crl3.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crl0S
Mhttp://crl4.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crl0>
http://www.digicert.com/CPS0
http://ocsp.digicert.com0\
Phttp://cacerts.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crt0
DigiCert, Inc.1A0?
8DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1
Qk{0%U=
%8eVwb
20230317050358Z
DigiCert, Inc.1;09
2DigiCert Trusted G4 RSA4096 SHA256 TimeStamping CA0
220921000000Z
331121235959Z0F1
DigiCert1$0"
DigiCert Timestamp 2022 - 20
Ihttp://crl3.digicert.com/DigiCertTrustedG4RSA4096SHA256TimeStampingCA.crl0
http://ocsp.digicert.com0X
Lhttp://cacerts.digicert.com/DigiCertTrustedG4RSA4096SHA256TimeStampingCA.crt0
(f*^[0
DigiCert Inc1
www.digicert.com1!0
DigiCert Trusted Root G40
220323000000Z
370322235959Z0c1
DigiCert, Inc.1;09
2DigiCert Trusted G4 RSA4096 SHA256 TimeStamping CA0
http://ocsp.digicert.com0A
5http://cacerts.digicert.com/DigiCertTrustedRootG4.crt0C
2http://crl3.digicert.com/DigiCertTrustedRootG4.crl0
DigiCert Inc1
www.digicert.com1$0"
DigiCert Assured ID Root CA0
220801000000Z
311109235959Z0b1
DigiCert Inc1
www.digicert.com1!0
DigiCert Trusted Root G40
]J<0"0i3
v=Y]Bv
http://ocsp.digicert.com0C
7http://cacerts.digicert.com/DigiCertAssuredIDRootCA.crt0E
4http://crl3.digicert.com/DigiCertAssuredIDRootCA.crl0
~qj#k"
DigiCert, Inc.1;09
2DigiCert Trusted G4 RSA4096 SHA256 TimeStamping CA
230317050358Z0+
/1(0&0$0"
JQqG%{
((((( H
h(((( H
H
KERNEL32.DLL
(null)
mscoree.dll
VS_VERSION_INFO
StringFileInfo
040904E4
Comments
Roll reputedly army climates marchioness siamese
CompanyName
Raver bola
FileDescription
Prostatic chalk goals sanctum accepted shrewdly
FileVersion
8.249.79.8
InternalName
Redefined lessor
LegalCopyright
Copyright
Shuffler surfboard revolutionaries flamenco
LegalTrademarks
Anterior dyed
OriginalFilename
Auteur
ProductName
Weathercock
ProductVersion
8.249.79.8
VarFileInfo
Translation
6Java SE Runtime Environmen
Antivirus Signature
Bkav W32.AIDetectMalware
Lionic Clean
Elastic malicious (high confidence)
MicroWorld-eScan Gen:Variant.Zusy.467841
FireEye Generic.mg.22b25918bfdd12b1
CAT-QuickHeal Clean
McAfee RDN/Generic PWS.y
Malwarebytes Trojan.Crypt
Zillya Clean
Sangfor Backdoor.Win32.Zusy.Vmgo
K7AntiVirus Trojan ( 0059d4ec1 )
BitDefender Gen:Variant.Zusy.467841
K7GW Trojan ( 0059d4ec1 )
Cybereason Clean
Baidu Clean
VirIT Trojan.Win32.GenusT.DHPD
Cyren W32/Agent.GAX.gen!Eldorado
Symantec ML.Attribute.HighConfidence
tehtris Clean
ESET-NOD32 a variant of Win32/Kryptik.HSEV
Cynet Malicious (score: 100)
APEX Malicious
Paloalto Clean
ClamAV Win.Packed.Zusy-10001910-0
Kaspersky HEUR:Trojan-Spy.Win32.Stealer.gen
Alibaba TrojanSpy:Win32/Stealer.6c4961a5
NANO-Antivirus Clean
ViRobot Clean
Rising Backdoor.Agent!8.C5D (TFE:5:Ojq6eX0sX8N)
TACHYON Clean
Emsisoft Gen:Variant.Zusy.467841 (B)
F-Secure Trojan.TR/AD.Nekark.pqgcn
DrWeb Clean
VIPRE Gen:Variant.Zusy.467841
TrendMicro Clean
McAfee-GW-Edition RDN/Generic PWS.y
Trapmine malicious.moderate.ml.score
CMC Clean
Sophos Troj/Steal-DNO
SentinelOne Clean
GData Gen:Variant.Zusy.467841
Jiangmin Clean
Webroot Clean
Avira TR/AD.Nekark.pqgcn
Antiy-AVL Trojan/Win32.Kryptik
Gridinsoft Ransom.Win32.Sabsik.sa
Xcitium Clean
Arcabit Trojan.Zusy.D72381
SUPERAntiSpyware Clean
ZoneAlarm HEUR:Trojan-Spy.Win32.Stealer.gen
Microsoft Trojan:Win32/RedLineStealer.EM!MTB
Google Detected
AhnLab-V3 Trojan/Win.Generic.R578284
Acronis Clean
BitDefenderTheta Clean
ALYac Gen:Variant.Zusy.467841
MAX malware (ai score=85)
DeepInstinct MALICIOUS
VBA32 Clean
Cylance unsafe
Panda Trj/Genetic.gen
Zoner Clean
TrendMicro-HouseCall TROJ_GEN.R002H0CEE23
Tencent Win32.Trojan.FalseSign.Udkl
Yandex Clean
Ikarus Trojan.Win32.Crypt
MaxSecure Clean
Fortinet W32/Kryptik.HSEV!tr
AVG Win32:BackdoorX-gen [Trj]
Avast Win32:BackdoorX-gen [Trj]
CrowdStrike win/malicious_confidence_90% (W)
No IRMA results available.