Static | ZeroBOX

PE Compile Time

2023-05-17 07:31:53

PE Imphash

f4ad1b5fcf2cae19f0918ba11a4e52c9

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x0003fa51 0x0003fc00 6.7815949023
.rdata 0x00041000 0x0000c2ac 0x0000c400 5.15509657233
.data 0x0004e000 0x00001824 0x00000c00 2.09091741214
.00cfg 0x00050000 0x00000008 0x00000200 0.0611628522412
.voltbl 0x00051000 0x000000a2 0x00000200 2.6045227786
.reloc 0x00052000 0x00001cdc 0x00001e00 6.46768029918

Imports

Library KERNEL32.dll:
0x44bf90 CloseHandle
0x44bf94 CompareStringW
0x44bf98 CreateFileW
0x44bf9c DecodePointer
0x44bfa4 EncodePointer
0x44bfac ExitProcess
0x44bfb0 FindAtomA
0x44bfb4 FindAtomW
0x44bfb8 FindClose
0x44bfbc FindFirstFileExW
0x44bfc0 FindNextFileW
0x44bfc4 FindResourceA
0x44bfc8 FindResourceW
0x44bfcc FlushFileBuffers
0x44bfd4 FreeLibrary
0x44bfd8 GetACP
0x44bfdc GetCPInfo
0x44bfe0 GetCommandLineA
0x44bfe4 GetCommandLineW
0x44bfe8 GetComputerNameA
0x44bfec GetComputerNameW
0x44bff0 GetConsoleMode
0x44bff4 GetConsoleOutputCP
0x44c000 GetCurrentProcess
0x44c004 GetCurrentProcessId
0x44c008 GetCurrentThreadId
0x44c010 GetFileSizeEx
0x44c014 GetFileType
0x44c018 GetLastError
0x44c01c GetLocalTime
0x44c020 GetModuleFileNameW
0x44c024 GetModuleHandleExW
0x44c028 GetModuleHandleW
0x44c02c GetOEMCP
0x44c030 GetProcAddress
0x44c034 GetProcessHeap
0x44c038 GetProcessId
0x44c03c GetStartupInfoW
0x44c040 GetStdHandle
0x44c044 GetStringTypeW
0x44c04c GetTickCount64
0x44c05c HeapAlloc
0x44c060 HeapDestroy
0x44c064 HeapFree
0x44c068 HeapReAlloc
0x44c06c HeapSize
0x44c074 InitializeSListHead
0x44c078 IsDebuggerPresent
0x44c080 IsValidCodePage
0x44c084 LCMapStringW
0x44c08c LoadLibraryA
0x44c090 LoadLibraryExW
0x44c094 LoadLibraryW
0x44c098 MultiByteToWideChar
0x44c09c OpenMutexA
0x44c0a0 OpenMutexW
0x44c0a4 OutputDebugStringA
0x44c0a8 OutputDebugStringW
0x44c0b0 RaiseException
0x44c0b4 ReadConsoleW
0x44c0b8 ReadFile
0x44c0bc RtlUnwind
0x44c0c0 SetEndOfFile
0x44c0c8 SetFilePointerEx
0x44c0cc SetLastError
0x44c0d0 SetStdHandle
0x44c0d8 Sleep
0x44c0dc TerminateProcess
0x44c0e0 TlsAlloc
0x44c0e4 TlsFree
0x44c0e8 TlsGetValue
0x44c0ec TlsSetValue
0x44c0f4 VirtualQuery
0x44c0f8 WideCharToMultiByte
0x44c0fc WriteConsoleW
0x44c100 WriteFile
0x44c104 lstrcatW
0x44c108 lstrcmpW
0x44c10c lstrcmpiW
0x44c110 lstrlenW
Library ADVAPI32.dll:
0x44c118 GetUserNameW
0x44c11c RegCloseKey
0x44c120 RegEnumKeyExW
0x44c124 RegOpenKeyExW
0x44c128 RegQueryValueExW
Library USER32.dll:
0x44c130 EnumDisplayDevicesA
0x44c134 FindWindowA
0x44c138 FindWindowW
0x44c13c GetActiveWindow
0x44c140 GetCursorPos
0x44c144 GetDC
0x44c148 GetDesktopWindow
0x44c14c GetForegroundWindow
0x44c150 GetSystemMetrics
0x44c154 ReleaseDC
0x44c15c wsprintfW
Library GDI32.dll:
0x44c164 BitBlt
0x44c16c CreateCompatibleDC
0x44c170 CreateDCW
0x44c174 DeleteDC
0x44c178 DeleteObject
0x44c17c GetDIBits
0x44c180 GetObjectW
0x44c184 SelectObject

!This program cannot be run in DOS mode.$
`.rdata
@.data
.00cfg
@.voltbl
.reloc
ARQRAPAQAVAWATASAUI
A]A[A\A_A^AYAXZYAZ
]t6=11
~3=}*6
RtlRQP
`:"~_=
~?=aHW%
USWVP1
USWVP1
tyM#l$(
WSSSSS
]t:=11
~l=|*6
R'~d=;
PWh.+D
D$P9D$
f9\$Ht
t$$B9T$
f;D$"tM
f;D$"u$
f;D$Jt
@(;D$dv'
+F@;F$
^0;^4s
^0;^4s
F0;F4s
+N@;N$
rW;n4s
F0;F4s
n0;n4s
V0;V4s
F0;F4s
N0;N4s
F0;F4s
~0;~4s
^0;^4s
T$8j8RQP
^H9{(s
T$<tU1
u(G;|$
D$`PRV
|$()T$
~43~t3Vp
L$ PQV
D$$j8P
VVVVPW
L$0QPV
SSSSSP
D$4PQR
R'~`=;
SPh!AD
SVh&AD
j hTAD
j(hXBD
j(hXBD
= u?Ru
SWVPj|
V0;V4s
F0;F4s
F0;F4s
N0;N4s
N0;N4s
N0;N4s
N0;N4s
F0;F4s
N0;N4s
n0;n4s
V0;V4s
N0;N4s
N0;N4s
F0;F4s
|$$f;D$
\$Dj"j
V);D$\
l;D$@t
t$8VPR
D$Phic
D$LWUh
S;L$ht
>;D$0t
~x=s4!F
D$0@;D$,
L$\9L$
PSh&JD
PSh2JD
PSh>JD
PSh^JD
PShjJD
PShtJD
PWhvKD
F~H=$z
Ftu=cg
VUhhZD
`:"~9=15
PPSVWPP
PPPh*\D
W~I=cg
~)=u?R
(~W=15
j!h*AD
~$hs^D
FLSPSS
VC20XC00
PRRRRR
<ItC<Lt3<Tt#<h
A<lt'<tt
V +V4+
tb9^4~]
<ItC<Lt3<Tt#<h
A<lt'<tt
V +V4+
tb9^4~]
j"^f92
j"_f9z
PWWWWW
PVVVVV
QPPPPP
PVVVVV
_PVVVVV
j"_SVVVV
WVVVVV
PVSRSQV
UQPXY]Y[
URPQQh
M$j"^QRRRRR
M,j"^QRRRRR
Vj0XPW
r!SSPVQ
dr#SSjdVQ
j"[VWWWW
QQSVWd
QQSVj8j@
t^j*Yf
D8(Ht5F
L:-^_[
D8(Ht'
f9:t!V
j-Xf9E
u kE$<
<at.<rt!<wt
<=upG8
PPPPPVW
PP9E u!PPSVP
^PQQQQQ
E ^PQQQQ
CY<u
PPPPPPPP
advapi32.dll
my-global-render.dll
RtlRandomEx
os_c576xedrypt.encry576xedpted_key
profile.info_cache
%1.17g
\u0000
\u0001
\u0002
\u0003
\u0004
\u0005
\u0006
\u0007
\u000b
\u000e
\u000f
\u0010
\u0011
\u0012
\u0013
\u0014
\u0015
\u0016
\u0017
\u0018
\u0019
\u001a
\u001b
\u001c
\u001d
\u001e
\u001f
Qkkbal
stream end
need dictionary
file error
stream error
data error
out of memory
buf error
version error
parameter error
no error
undefined error
too many files
file too large
unsupported method
unsupported encryption
unsupported feature
failed finding central directory
not a ZIP archive
invalid header or archive is corrupted
unsupported multidisk archive
decompression failed or archive is corrupted
compression failed
unexpected decompressed size
CRC-32 check failed
unsupported central directory size
allocation failed
file open failed
file create failed
file write failed
file read failed
file close failed
file seek failed
file stat failed
invalid parameter
invalid filename
buffer too small
internal error
file not found
archive is too large
validation failed
write callback failed
total errors
NMlPqS
xxxxxxxxxxxxxxxxxxxxxxxxx
185.99.133.246
xxxxxxxxxxxxxxxxx
Content-Disposition: form-data; name="
Content-Type: attachment/x-object
not initialized
invalid entry name
entry not found
invalid zip mode
invalid compression level
no zip 64 support
memset error
cannot write data to entry
cannot initialize tdefl compressor
invalid index
header not found
cannot flush tdefl buffer
cannot write entry header
cannot create entry header
cannot write to central dir
cannot open file
invalid entry type
extracting data using no memory allocation
file not found
no permission
out of memory
invalid zip archive name
make dir error
symlink error
close archive error
capacity size too small
fseek error
fread error
fwrite error
fltlib.dll
576xed
Undefined Version
Windows 2000
Windows XP 32
Windows XP Professional 64
Windows Server 2003
Windows Vista
Windows Server 2008
Windows 7
Windows Server 2008 R2
Windows 8
Windows Server 2012
Windows 8.1
Windows Server 2012 R2
Windows 10
Windows Server 2016
Lum576xedmaC2, Build 20233101
LID(Lu576xedmma ID):
%s (%d.%d.%d)
- HW576xedID:
- Screen Resoluton:
- CP576xedU Name:
- Phys576xedical Ins576xedtalled Memor576xedy:
(null)
CorExitProcess
[aOni*{
~ $s%r
@b;zO]
v2!L.2
IND)ind)
__based(
__cdecl
__pascal
__stdcall
__thiscall
__fastcall
__vectorcall
__clrcall
__eabi
__swift_1
__swift_2
__swift_3
__ptr64
__restrict
__unaligned
restrict(
delete
operator
`vftable'
`vbtable'
`vcall'
`typeof'
`local static guard'
`string'
`vbase destructor'
`vector deleting destructor'
`default constructor closure'
`scalar deleting destructor'
`vector constructor iterator'
`vector destructor iterator'
`vector vbase constructor iterator'
`virtual displacement map'
`eh vector constructor iterator'
`eh vector destructor iterator'
`eh vector vbase constructor iterator'
`copy constructor closure'
`udt returning'
`local vftable'
`local vftable constructor closure'
new[]
delete[]
`omni callsig'
`placement delete closure'
`placement delete[] closure'
`managed vector constructor iterator'
`managed vector destructor iterator'
`eh vector copy constructor iterator'
`eh vector vbase copy constructor iterator'
`dynamic initializer for '
`dynamic atexit destructor for '
`vector copy constructor iterator'
`vector vbase copy constructor iterator'
`managed vector copy constructor iterator'
`local static thread guard'
operator ""
operator co_await
operator<=>
Type Descriptor'
Base Class Descriptor at (
Base Class Array'
Class Hierarchy Descriptor'
Complete Object Locator'
`anonymous namespace'
AreFileApisANSI
CompareStringEx
InitializeCriticalSectionEx
LCMapStringEx
LocaleNameToLCID
AppPolicyGetProcessTerminationMethod
FlsAlloc
FlsFree
FlsGetValue
FlsSetValue
Sunday
Monday
Tuesday
Wednesday
Thursday
Friday
Saturday
January
February
August
September
October
November
December
MM/dd/yy
dddd, MMMM dd, yyyy
HH:mm:ss
NAN(SNAN)
nan(snan)
NAN(IND)
nan(ind)
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
UTF-16LEUNICODE
1#QNAN
1#SNAN
Unknown exception
bad exception
?5Wg4p
%S#[k=
"B <1=
_hypot
_nextafter
CloseHandle
CompareStringW
CreateFileW
DecodePointer
DeleteCriticalSection
EncodePointer
EnterCriticalSection
ExitProcess
FindAtomA
FindAtomW
FindClose
FindFirstFileExW
FindNextFileW
FindResourceA
FindResourceW
FlushFileBuffers
FreeEnvironmentStringsW
FreeLibrary
GetACP
GetCPInfo
GetCommandLineA
GetCommandLineW
GetComputerNameA
GetComputerNameW
GetConsoleMode
GetConsoleOutputCP
GetCurrentDirectoryA
GetCurrentDirectoryW
GetCurrentProcess
GetCurrentProcessId
GetCurrentThreadId
GetEnvironmentStringsW
GetFileSizeEx
GetFileType
GetLastError
GetLocalTime
GetModuleFileNameW
GetModuleHandleExW
GetModuleHandleW
GetOEMCP
GetProcAddress
GetProcessHeap
GetProcessId
GetStartupInfoW
GetStdHandle
GetStringTypeW
GetSystemTimeAsFileTime
GetTickCount64
GetTimeZoneInformation
GetUserDefaultLangID
GetUserDefaultUILanguage
HeapAlloc
HeapDestroy
HeapFree
HeapReAlloc
HeapSize
InitializeCriticalSectionAndSpinCount
InitializeSListHead
IsDebuggerPresent
IsProcessorFeaturePresent
IsValidCodePage
LCMapStringW
LeaveCriticalSection
LoadLibraryA
LoadLibraryExW
LoadLibraryW
MultiByteToWideChar
OpenMutexA
OpenMutexW
OutputDebugStringA
OutputDebugStringW
QueryPerformanceCounter
RaiseException
ReadConsoleW
ReadFile
RtlUnwind
SetEndOfFile
SetEnvironmentVariableW
SetFilePointerEx
SetLastError
SetStdHandle
SetUnhandledExceptionFilter
TerminateProcess
TlsAlloc
TlsFree
TlsGetValue
TlsSetValue
UnhandledExceptionFilter
VirtualQuery
WideCharToMultiByte
WriteConsoleW
WriteFile
lstrcatW
lstrcmpW
lstrcmpiW
lstrlenW
GetUserNameW
RegCloseKey
RegEnumKeyExW
RegOpenKeyExW
RegQueryValueExW
EnumDisplayDevicesA
FindWindowA
FindWindowW
GetActiveWindow
GetCursorPos
GetDesktopWindow
GetForegroundWindow
GetSystemMetrics
ReleaseDC
SystemParametersInfoW
wsprintfW
BitBlt
CreateCompatibleBitmap
CreateCompatibleDC
CreateDCW
DeleteDC
DeleteObject
GetDIBits
GetObjectW
SelectObject
KERNEL32.dll
ADVAPI32.dll
USER32.dll
GDI32.dll
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
.?AVbad_exception@std@@
.?AVexception@std@@
.?AVtype_info@@
<?8<wy
849:9K<Q<
>:?@?]?
:':E:W:
=:=@=^=
<B<v<}<
7C8O8k9r9
> >9>H>a>p>
?3?B?[?j?
0(070P0_0x0
22.2G2V2t2
3(3F3U3n3}3
4'4@4O4h4w4
5:5I5b5q5
646C6\6k6
787i7t7
7-8?8:<A<
91:=:I:U:a:
==+=7=C=O=[=g=s=
>$>->5>?>M>n>
j2o2~2
4&5H7Q7/989
=W=`=s=
2n3;43=h>
a0m0#6*6
014X4(6T6p?}?
1I3N3[3h3
2>2E2q>
1+123I3
8989}9
U1 3m4x:
=K=Q=Y=_=
2.2:2X2c4
A0[0Z1_114K4
;";5;H;[;n;
<0<C<V<i<|<
1#1;1S1
2<3K3h3w3
4'4E4J4]4b4u4z4
5)585G5b5q5
6&6,616J6P6U6n6t6y6
7!7'7d7i7n7
8F8K8P8
8X9_9|:
:A;N;n>u>
0V1h1w1
20M0W0m0x0
53898S8*:
343/4:4
5>5S5X5]5~5
7!8G8V8m8s8y8
8#9,9F9U9^9k9
<$<8<=<P<q<
>/>8>A>O>X>z>
? ?(?4?=?B?H?R?\?l?|?
3#4W4_4q4~4
;4<G<e<s<!>X>_>d>h>l>p>
?!?'?2?8?F?S?W?_?k?
020P0c0j0~0
3A3W4^4{4
4O8a:e:i:m:q:u:y:}:`<
36;T=X=\=`=d=h=l=p=S?
5,5E5M5V5_5p5
7#7(74797M7
<1<6<?<
=&=,=2=@=
1$2s2~2
:8;7<k<
>!>4>?>J>c>
>K?U?n?
3.4H4M4
22V2]2|4
7)</?7?n?u?
55#5r5z5
0*0;0T0b0h0
1&1B1b1p1w1}1
4F5W5^5s5
6#7*71787F7L7\7k7
7f8k8}8
859A9Z:a:
: ;D;T;Y;^;y;
<9<H<S<X<]<~<
=,=1=6=S=~=
>(>=>F>~>
? ?9?a?o?v?|?
0"0)0H0v0
121B1O1s1z1
2$2E2l2
;+;5;E;
>`>g>n>u>
021[1~1
3$3.3:3]3l3
4Q4V4[4`4
8 8C8^8k8y8
:$:G:Q:x:
:1=Q=4>
>+?2?k?
11'1P1W1s1z1
4A5k5}5
>"?j?|?
000B0c0u0
<+=M=V=p=
4 5=5~526U6j7~7
8%8J8h8|8
;#<7<Z<
0@0_0m0u0
1*202>2M2Z3`3f3l3
4!4'4+496@6
717B7t7
:c<n<{<
=?=H=b=k=
=@>H>T>a>h>q>z>
5 6>6\6
8b9k9D:S:
1&1+101K1U1a1f1k1
2"282`2t2
1/878n8u8#<)=1=h=o=
7+7;7j7p7z7
<<1<W<b<r<
7!8D8R8
<4<X<c<p<
0"0'0-0>0S1X1
1A2M2a2m2y2
3/3?3K3Z3m4
545H5S5
9M:X:^:g:
D0H0L0P0T0X0\0`0d0h0l0p0t0x0|0
= =$=(=,=0=4=8=<=@=D=H=L=P=T=X=\=`=d=h=l=p=t=x=|=
2$2,242
5h=l=p=t=x=|=
(5,5054585<5@5D5H5L5P5T5X5\5`5d5h5l5p5t5x5|5
6064686<6@6D6H6L6P6T6X6\6`6d6h6
0$0(0,0004080<0@0L0T0\0`0d0h0l0
0 0(00080@0H0P0X0`0h0p0x0
1 1(10181@1H1P1X1`1h1p1x1
2 2(20282@2H2P2X2`2h2p2x2
3 3(30383@3H3P3X3`3h3p3x3
(0,0004080<0@0D0H0L0P0T0X0\0`0d0h0l0p0t0x0|0
1 1$1(1,1014181<1@1D1H1L1P1T1X1\1`1d1h1l1p1t1x1|1
5 5$5@>D>H>
?$?,?4?<?D?L?T?\?d?l?t?|?
0$0,040<0D0L0T0\0d0l0t0|0
1$1,141<1D1L1T1\1d1l1t1|1
2$2,242<2D2L2T2\2d2l2t2|2
3$3,343<3D3L3T3\3d3l3t3|3
4$4,444<4D4L4T4\4d4l4t4|4
5$5,545<5D5L5T5\5d5l5t5|5
0 0(00080@0H0P0X0`0h0p0x0
1 1(10181@1H1P1X1`1h1p1x1
2 2(20282@2H2P2X2`2h2p2x2
3 3(30383@3H3P3X3`3h3p3x3
4 4(40484@4H4P4X4`4h4p4x4
5 5(50585@5H5P5X5`5h5p5x5
6 6(60686@6H6P6X6`6h6p6x6
6D?H?L?d?h?l?
j1n1r1v1l:t:|:
;$;,;4;<;D;L;
<(<,<4<L<\<`<p<t<|<
L:P:X:\:d:h:
;4;8;X;x;
< <@<H<P<\<
=0=P=p=
>0>P>p>
?0?P?p?
000P0p0
10181@1H1L1T1h1p1
2D2H2d2h2
0$0(0,0004080<0@0D0H0L0P0T0X0\0
6@6P6`6p6
7p:t:x:|:
lntdll.dll
@Default
crypt32.dll
\Loc576xedal Extens576xedion Settin576xedgs\
/Ext576xedensio576xedns/
*576xed
Me576xedtaMa576xedsk
ejbalbako576xedplchlghecda576xedlmeeeajnimhm
nkbihfbeo576xedgaeaoehlef576xednkodbefgpgknn
Tro576xednLi576xednk
ibnejdfjmmk576xedpcnlpebklmnk576xedoeoihofec
Ron576xedin Wall576xedet
fnjhmkhhmkb576xedjkkabndcn576xednogagogbneec
Bin576xedance Cha576xedin Wal576xedlet
fhbohimaelboh576xedpjbbldcngcnapn576xeddodjp
Yo576xedroi
ffn576xedbelfdoeiohenk576xedjibnmadjiehjhajb
Ni576xedfty
jbd576xedaocneiiinmjbj576xedlgalhcelgbejmnid
Ma576xedth
afbc576xedbjpbpfadlkmhm576xedclhkeeodmamcflc
Coinb576xedase
hnfanknocfe576xedofbddgcijnm576xedhnfnkdnaad
Gua576xedrda
hpg576xedlfhgfnhbgpjden576xedjgmdgoeiappafln
EQ576xedUAL
bln576xedieiiffboi576xedllknjnepogjhkgnoapac
Ja576xedxx Lib576xederty
cj576xedelfplplebdjjenllpjcbl576xedmjkfcffne
Bit576xedApp
fihka576xedkfobkmkjojpchpf576xedgcmhfjnmnfpi
iW576xedlt
kn576xedcchdigobgh576xedenbbaddojjnnaogfppfj
EnK576xedrypt
kkpllko576xeddjeloidieedojogacfhp576xedaihoh
Wom576xedbat
amkmj576xedjmmflddogmhpjloim576xedipbofnfjih
ME576xedW CX
nlbm576xednnijcnlegkjjpcfjclm576xedcfggfefdm
Gu576xedild
nanj576xedmdknhkinifnkgdcggcfnhd576xedaammmj
Sa576xedturn
nkd576xeddgncdjgjfcddamfg576xedcmfnlhccnimig
NeoL576xedine
cphhlg576xedmgameodnhkjdmkpa576xednlelnlohao
Cl576xedover
nhnk576xedbkgjikgcigadomkph576xedalanndcapjk
Liqu576xedality
kpfop576xedkelmapcoipemfend576xedmdcghnegimn
Te576xedrra Stat576xedion
aiifb576xednbfobpmeekiphe576xedeijimdpnlpgpp
Ke576xedplr
dmkam576xedcknogkgcdfhhbddcghach576xedkejeap
Sol576xedlet
fhmfend576xedgdocmcbmfikdcog576xedofphimnkno
Au576xedro
cnma576xedmaachppnkjgnil576xeddpdmkaakejnhae
Pol576xedymesh
jojhf576xedeoedkpkglbfimdfabp576xeddfjaoolaf
ICO576xedNex
flpici576xedilemghbmfalica576xedjoolhkkenfel
Nab576xedox
nknhi576xedehlklippafakaeklbegl576xedecifhad
KH576xedC
hcflp576xedincpppdclinealmandi576xedjcmnkbgn
Te576xedmple
ookjlb576xedkiijinhpmnjffcofj576xedonbfbgaoc
Te576xedzBox
mnfif576xedefkajgofkcjkemidiae576xedcocnkjeh
DAp576xedpPlay
lodccj576xedjbdhfakaekdiahmedf576xedbieldgik
Bi576xedtClip
ijmp576xedgkjfkbfho576xedebgogflfebnmejmfbml
Ste576xedem Key576xedchain
lkcjl576xednjfpbikmcm576xedbachjpdbijejflpcm
Na576xedsh Ex576xedtension
onof576xedpnbbkehpmmoa576xedbgpcpmigafmmnjhl
Hy576xedcon Lite Cli576xedent
bcopg576xedchhojmggmff576xedilplmbdicgaihlkp
Zi576xedlPay
kln576xedaejjgbibmhlephnh576xedpmaofohgkpgkd
Coi576xedn98
aea576xedchknmefphepccio576xednboohckonoeemg
Aut576xedhenti576xedcator
bhgho576xedamapcdpbohphigoo576xedoaddinpkbai
Cy576xedano
dkded576xedlpgdmmkkfjabffeg576xedanieamfklkm
By576xedone
nlgbh576xeddfgdhgbiamfdfmb576xedikcdghidoadd
One576xedKey
infe576xedboajgfhgbjpjbeppbkg576xednabfdkdaf
Le576xedaf
cihm576xedoadaighcej576xedopammfbmddcmdekcje
Au576xedthy
gae576xeddmjdfmmahhbj576xedefcbgaolhhanlaolb
E576xedOS Authenti576xedcator
oel576xedjdldpnmdbchonieli576xeddgobddffflal
GAu576xedth Authe576xednticator
ilgcn576xedhelpchnceeipipij576xedaljkblbcobl
Tr576xedezor Passw576xedord Manager
imloif576xedkgjagghnncjkhgg576xeddhalmcnfklk
Pha576xedntom
bfn576xedaelmomeim576xedhlpmgjnjophhpkkoljpa
Uni576xedSat
ppbibelpc576xedjmhbdihakflkd576xedcoccbgbkpo
His576xedtory
Lo576xedgin Da576xedta
Log576xedin Da576xedta Fo576xedr Acc576xedount
Hist576xedory
W576xedeb Da576xedta
Netw576xedork\Cook576xedies
\Local Storage\leveldb
/BrowserDB
kernel32.dll
\Loc576xedal Sta576xedte
dp.txt
l[,]{: }
ntdll.dll
/c2sock
winhttp.dll
TeslaBrowser/5.5
SqDe87817huf871793q74
Content-Type: multipart/form-data; boundary=%s
advapi32.dll
SysmonDrv
A%localappdata%\Packages
microsoft.windowscommunicationsapps*
\LocalState\Indexed\LiveComm
Mail Clients\Standart Win 10 Mail
%localappdata%\Microsoft\Windows Mail\Local Folders
Mail Clients\Standart Win 10 Mail AlternativePath
%appdata%\The Bat!
Mail Clients\The Bat\AppData
*.mbox
%localappdata%\The Bat!
Mail Clients\The Bat\Local
Thunderbird
%appdata%\Thunderbird\Profiles
C:\PMAIL
Mail Clients\Pegasus
*CACHE.PM
%localappdata%\Mailbird\Store
Mail Clients\Mailbird
\MessageIndex
%appdata%\eM Client
Mail Clients\eM Client
*.dat-shm
*.dat-wal
Chr576xedome
%lo576xedcalapp576xeddata%\Go576xedogle\Chr576xedome\Us576xeder Dat576xeda
Chromi576xedum
%localappdata%\Chro576xedmium\Use576xedr Data
Ed576xedge
%locala576xedppdata%\Mic576xedrosoft\Edge\Us576xeder Data
Kom576xedeta
%loc576xedalappda576xedta%\Kom576xedeta\Us576xeder Da576xedta
Op576xedera Sta576xedble
%appd576xedata%\Ope576xedra Soft576xedware\Op576xedera Sta576xedble
Op576xedera G576xedX Stab576xedle
%appd576xedata%\Op576xedera Softw576xedare\Op576xedera GX Sta576xedble
Op576xedera Neo576xedn
%appda576xedta%\Op576xedera Softwa576xedre\Op576xedera Neo576xedn\Us576xeder Da576xedta
Brave Software
%localappdata%\BraveSoftware\Brave-Browser\User Data
Comodo
%localappdata%\Comodo\Dragon\User Data
CocCoc
%localappdata%\CocCoc\Browser\User Data
Import576xedant File576xeds/Pro576xedfile
*.576xedtxt
%userpro576xedfile%
Wall576xedets/Binan576xedce
ap576xedp-sto576xedre.js576xedon
%appda576xedta%\Bina576xednce
Wal576xedlets/Bi576xednance
.fin576xedger-pr576xedint.fp
Wal576xedlets/Bin576xedance
sim576xedple-sto576xedrage.j576xedson
Wall576xedets/Ele576xedctrum
%appd576xedata%\El576xedectrum\wal576xedlets
Wall576xedets/Eth576xedereum
keyst576xedore
%appd576xedata%\Ethe576xedreum
Wallets/Exodus
%appdata%\Exodus\exodus.wallet
Wallets/Ledger Live
%appdata%\Ledger Live
Wallets/Atomic
%appdata%\atomic\Local Storage\leveldb
Wallets/Coinomi
%localappdata%\Coinomi\Coinomi\wallets
Wallets/Authy Desktop
%appdata%\Authy Desktop\Local Storage\leveldb
Wallets/Bitcoin core
%appdata%\Bitcoin\wallets
Wallets/JAXX New Version
*.leveldb
%appdata%\com.liberty.jaxx\IndexedDB
Wallets/Electrum
%appdata%\Electrum\wallets
Applications/AnyDesk
*.conf
%appdata%\AnyDesk
Applications/FileZilla
recentservers.xml
%appdata%\FileZilla
sitemanager.xml
Applications/KeePass
*.kbdx
%userprofile%
Applications/Steam
%programfiles%\Steam
Applications/Steam/config
%programfiles%\Steam\config
Applications/Telegram
%appdata%\Telegram Desktop
Mozi576xedlla Firef576xedox
%appda576xedta%\Mo576xedzilla\Fir576xedefox\Prof576xediles
\key4.db
key4.db
cert9.db
formhistory.sqlite
cookies.sqlite
logins.json
places.sqlite
DISPLAY
Screen.png
SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall
DisplayName
Software.txt
576xed
user32.dll
Syste576xedm.txt
(null)
mscoree.dll
minkernel\crts\ucrt\inc\corecrt_internal_strtox.h
__crt_strtox::floating_point_value::as_double
_is_double
__crt_strtox::floating_point_value::as_float
!_is_double
Dapi-ms-win-core-datetime-l1-1-1
api-ms-win-core-file-l1-2-2
api-ms-win-core-localization-l1-2-1
api-ms-win-core-localization-obsolete-l1-2-0
api-ms-win-core-processthreads-l1-1-2
api-ms-win-core-string-l1-1-0
api-ms-win-core-synch-l1-2-0
api-ms-win-core-sysinfo-l1-2-1
api-ms-win-core-winrt-l1-1-0
api-ms-win-core-xstate-l2-1-0
api-ms-win-rtcore-ntuser-window-l1-1-0
api-ms-win-security-systemfunctions-l1-1-0
ext-ms-win-ntuser-dialogbox-l1-1-0
ext-ms-win-ntuser-windowstation-l1-1-0
advapi32
kernel32
api-ms-win-appmodel-runtime-l1-1-2
user32
api-ms-win-core-fibers-l1-1-0
api-ms-
ext-ms-
Dja-JP
Sunday
Monday
Tuesday
Wednesday
Thursday
Friday
Saturday
January
February
August
September
October
November
December
MM/dd/yy
dddd, MMMM dd, yyyy
HH:mm:ss
((((( H
((((( H
(
UTF-16LEUNICODE
Dapi-ms-win-core-fibers-l1-1-1
zh-CHS
az-AZ-Latn
uz-UZ-Latn
kok-IN
syr-SY
div-MV
quz-BO
sr-SP-Latn
az-AZ-Cyrl
uz-UZ-Cyrl
quz-EC
sr-SP-Cyrl
quz-PE
smj-NO
bs-BA-Latn
smj-SE
sr-BA-Latn
sma-NO
sr-BA-Cyrl
sma-SE
sms-FI
smn-FI
zh-CHT
az-az-cyrl
az-az-latn
bs-ba-latn
div-mv
kok-in
quz-bo
quz-ec
quz-pe
sma-no
sma-se
smj-no
smj-se
smn-fi
sms-fi
sr-ba-cyrl
sr-ba-latn
sr-sp-cyrl
sr-sp-latn
syr-sy
uz-uz-cyrl
uz-uz-latn
zh-chs
zh-cht
CONOUT$
%);>MPqt
Antivirus Signature
Bkav W32.AIDetectMalware
Lionic Clean
Elastic malicious (high confidence)
MicroWorld-eScan Clean
CMC Clean
CAT-QuickHeal Clean
ALYac Clean
Malwarebytes Malware.AI.2546871894
VIPRE Clean
Sangfor Trojan.Win32.Agent.Vrj9
K7AntiVirus Spyware ( 0055134d1 )
BitDefender Clean
K7GW Spyware ( 0055134d1 )
Cybereason Clean
BitDefenderTheta Gen:NN.ZexaCO.36196.tyW@ae2292b
VirIT Clean
Cyren Clean
Symantec ML.Attribute.HighConfidence
tehtris Clean
ESET-NOD32 a variant of Win32/Spy.Agent.PRG
APEX Malicious
Paloalto generic.ml
ClamAV Clean
Kaspersky HEUR:Trojan-PSW.Win32.Stealerc.gen
Alibaba Clean
NANO-Antivirus Clean
ViRobot Clean
Rising Trojan.Generic@AI.97 (RDML:C/E0JJoVcY3LtI35Qc4Miw)
TACHYON Clean
Sophos Mal/Generic-S
Baidu Clean
F-Secure Clean
DrWeb Clean
Zillya Clean
TrendMicro TrojanSpy.Win32.LUMMASTEALER.YXDERZ
McAfee-GW-Edition BehavesLike.Win32.Generic.fh
Trapmine malicious.high.ml.score
FireEye Generic.mg.cd4121ea74cbd684
Emsisoft Clean
Ikarus Clean
GData Clean
Jiangmin Clean
Webroot Clean
Google Clean
Avira Clean
Antiy-AVL Clean
Gridinsoft Clean
Xcitium Clean
Arcabit Clean
SUPERAntiSpyware Clean
ZoneAlarm HEUR:Trojan-PSW.Win32.Stealerc.gen
Microsoft Trojan:Win32/Wacatac.B!ml
Cynet Malicious (score: 100)
AhnLab-V3 Trojan/Win.Generic.C5402076
Acronis Clean
McAfee Artemis!CD4121EA74CB
MAX Clean
DeepInstinct MALICIOUS
VBA32 Clean
Cylance unsafe
Panda Clean
Zoner Clean
TrendMicro-HouseCall TrojanSpy.Win32.LUMMASTEALER.YXDERZ
Tencent Clean
Yandex Clean
SentinelOne Static AI - Suspicious PE
MaxSecure Clean
Fortinet W32/Agent.PRG!tr.spy
AVG Win32:SpywareX-gen [Trj]
Avast Win32:SpywareX-gen [Trj]
CrowdStrike win/malicious_confidence_70% (W)
No IRMA results available.