Static | ZeroBOX

PE Compile Time

2023-05-12 03:05:14

PE Imphash

35ef3be2e1db54617ec4882897e31d4b

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x00062a71 0x00062c00 6.79858109423
.rdata 0x00064000 0x0000c51c 0x0000c600 5.18034368885
.data 0x00071000 0x00001824 0x00000c00 2.11412772898
.00cfg 0x00073000 0x00000008 0x00000200 0.0611628522412
.voltbl 0x00074000 0x000000a6 0x00000200 2.69160957215
.reloc 0x00075000 0x00001f20 0x00002000 6.46059697393

Imports

Library KERNEL32.dll:
0x46f07c CloseHandle
0x46f080 CompareStringW
0x46f084 CreateDirectoryW
0x46f088 CreateFileW
0x46f08c DecodePointer
0x46f094 DeleteFileW
0x46f098 EncodePointer
0x46f0a0 ExitProcess
0x46f0a8 FindAtomA
0x46f0ac FindAtomW
0x46f0b0 FindClose
0x46f0b4 FindFirstFileExW
0x46f0b8 FindNextFileW
0x46f0bc FindResourceA
0x46f0c0 FindResourceW
0x46f0c4 FlushFileBuffers
0x46f0cc FreeLibrary
0x46f0d0 GetACP
0x46f0d4 GetCPInfo
0x46f0d8 GetCommandLineA
0x46f0dc GetCommandLineW
0x46f0e0 GetComputerNameA
0x46f0e4 GetComputerNameW
0x46f0e8 GetConsoleMode
0x46f0ec GetConsoleOutputCP
0x46f0f8 GetCurrentProcess
0x46f0fc GetCurrentProcessId
0x46f100 GetCurrentThreadId
0x46f104 GetDriveTypeW
0x46f110 GetFileSizeEx
0x46f114 GetFileType
0x46f118 GetFullPathNameW
0x46f11c GetLastError
0x46f120 GetLocalTime
0x46f124 GetModuleFileNameW
0x46f128 GetModuleHandleExW
0x46f12c GetModuleHandleW
0x46f130 GetOEMCP
0x46f134 GetProcAddress
0x46f138 GetProcessHeap
0x46f13c GetProcessId
0x46f140 GetStartupInfoW
0x46f144 GetStdHandle
0x46f148 GetStringTypeW
0x46f150 GetTickCount64
0x46f160 HeapAlloc
0x46f164 HeapDestroy
0x46f168 HeapFree
0x46f16c HeapReAlloc
0x46f170 HeapSize
0x46f178 InitializeSListHead
0x46f17c IsDebuggerPresent
0x46f184 IsValidCodePage
0x46f188 LCMapStringW
0x46f190 LoadLibraryA
0x46f194 LoadLibraryExW
0x46f198 LoadLibraryW
0x46f19c MultiByteToWideChar
0x46f1a0 OpenMutexA
0x46f1a4 OpenMutexW
0x46f1a8 OutputDebugStringA
0x46f1ac OutputDebugStringW
0x46f1b0 PeekNamedPipe
0x46f1b8 RaiseException
0x46f1bc ReadConsoleW
0x46f1c0 ReadFile
0x46f1c4 RtlUnwind
0x46f1c8 SetEndOfFile
0x46f1d0 SetFilePointerEx
0x46f1d4 SetFileTime
0x46f1d8 SetLastError
0x46f1dc SetStdHandle
0x46f1e4 Sleep
0x46f1f0 TerminateProcess
0x46f1f4 TlsAlloc
0x46f1f8 TlsFree
0x46f1fc TlsGetValue
0x46f200 TlsSetValue
0x46f20c VirtualQuery
0x46f210 WideCharToMultiByte
0x46f214 WriteConsoleW
0x46f218 WriteFile
0x46f21c lstrcatW
0x46f220 lstrcmpW
0x46f224 lstrcmpiW
0x46f228 lstrlenW
Library ADVAPI32.dll:
0x46f230 GetUserNameW
0x46f234 RegCloseKey
0x46f238 RegEnumKeyExW
0x46f23c RegOpenKeyExW
0x46f240 RegQueryValueExW
Library USER32.dll:
0x46f248 EnumDisplayDevicesA
0x46f24c FindWindowA
0x46f250 FindWindowW
0x46f254 GetActiveWindow
0x46f258 GetCursorPos
0x46f25c GetDC
0x46f260 GetDesktopWindow
0x46f264 GetForegroundWindow
0x46f268 GetSystemMetrics
0x46f26c ReleaseDC
0x46f274 wsprintfW
Library GDI32.dll:
0x46f27c BitBlt
0x46f284 CreateCompatibleDC
0x46f288 CreateDCW
0x46f28c DeleteDC
0x46f290 DeleteObject
0x46f294 GetDIBits
0x46f298 GetObjectW
0x46f29c SelectObject

!This program cannot be run in DOS mode.$
`.rdata
@.data
.00cfg
@.voltbl
.reloc
ARQRAPAQAVAWATASAUI
A]A[A\A_A^AYAXZYAZ
u=Sj W
USWVP1
USWVP1
tyM#l$(
==(s'u
D$P9D$
f9\$Ht
t$$B9T$
f;D$"tM
f;D$"u$
f;D$Jt
@(;D$dv'
+F@;F$
^0;^4s
^0;^4s
F0;F4s
+N@;N$
rW;n4s
F0;F4s
n0;n4s
V0;V4s
F0;F4s
N0;N4s
F0;F4s
~0;~4s
^0;^4s
PQhrrA
T$8j8RQP
^H9{(s
T$<tU1
u(G;|$
D$`PRV
|$()T$
L$H)L$
WWWWWP
t$hSSSSSP
L$ PQV
t$ SSSSSP
t$ SSSSSP
t$0SPV
T$$uI1
L$4PQW
D$$j8P
SSSSPQ
VVVVPW
PPPPUSW
L$0QPV
SSSSSP
D$4PQR
v`Sh$nF
x8G;|$
a1~P=4x:e
=5x:et&=
=1RdktC
SWVPj|
V0;V4s
F0;F4s
F0;F4s
N0;N4s
N0;N4s
N0;N4s
N0;N4s
F0;F4s
N0;N4s
n0;n4s
V0;V4s
N0;N4s
N0;N4s
F0;F4s
|$$f;D$
\$Dj"j
V);D$\
t2htuF
K$tC=E
D$$;D$0
D$<iD$<Q-
iD$0Q-
SVWh~yF
SVWhLyF
SVWhXyF
SVWh@yF
SVWhLyF
SVWhXyF
SVWhdyF
SVWh~yF
V=i>ZF
a1~Y=4x:e
~W=h>ZF
j!hwqF
a1~K=4x:e
VC20XC00
PRRRRR
<ItC<Lt3<Tt#<h
A<lt'<tt
V +V4+
tb9^4~]
<ItC<Lt3<Tt#<h
A<lt'<tt
V +V4+
tb9^4~]
j"^f92
j"_f9z
PWWWWW
PVVVVV
PVVVVV
:u"f9z
WPWWWS
WWWSHSh
PVVVVV
_PVVVVV
j"_SVVVV
WVVVVV
PVSRSQV
UQPXY]Y[
URPQQh@.E
M$j"^QRRRRR
M,j"^QRRRRR
Vj0XPW
r!SSPVQ
dr#SSjdVQ
j"[VWWWW
QQSVWd
QQSVj8j@
t^j*Yf
D8(Ht5F
L:-^_[
D8(Ht'
f9:t!V
Af95n'G
j-Xf9E
u kE$<
f95l'G
<at.<rt!<wt
<=upG8
PPPPPVW
PP9E u!PPSVP
^PQQQQQ
E ^PQQQQ
CY<u
PPPPPPPP
advapi32.dll
my-global-render.dll
RtlRandomEx
333?*/
os_c576xedrypt.encry576xedpted_key
profile.info_cache
%1.17g
\u0000
\u0001
\u0002
\u0003
\u0004
\u0005
\u0006
\u0007
\u000b
\u000e
\u000f
\u0010
\u0011
\u0012
\u0013
\u0014
\u0015
\u0016
\u0017
\u0018
\u0019
\u001a
\u001b
\u001c
\u001d
\u001e
\u001f
Qkkbal
stream end
need dictionary
file error
stream error
data error
out of memory
buf error
version error
parameter error
no error
undefined error
too many files
file too large
unsupported method
unsupported encryption
unsupported feature
failed finding central directory
not a ZIP archive
invalid header or archive is corrupted
unsupported multidisk archive
decompression failed or archive is corrupted
compression failed
unexpected decompressed size
CRC-32 check failed
unsupported central directory size
allocation failed
file open failed
file create failed
file write failed
file read failed
file close failed
file seek failed
file stat failed
invalid parameter
invalid filename
buffer too small
internal error
file not found
archive is too large
validation failed
write callback failed
total errors
NBIqpI
xxxxxxxxxxxxxxxxxxxxxxxxx
195.123.227.138
xxxxxxxxxxxxxxxx
Content-Disposition: form-data; name="
Content-Type: attachment/x-object
not initialized
invalid entry name
entry not found
invalid zip mode
invalid compression level
no zip 64 support
memset error
cannot write data to entry
cannot initialize tdefl compressor
invalid index
header not found
cannot flush tdefl buffer
cannot write entry header
cannot create entry header
cannot write to central dir
cannot open file
invalid entry type
extracting data using no memory allocation
file not found
no permission
out of memory
invalid zip archive name
make dir error
symlink error
close archive error
capacity size too small
fseek error
fread error
fwrite error
fltlib.dll
576xed
Undefined Version
Windows 2000
Windows XP 32
Windows XP Professional 64
Windows Server 2003
Windows Vista
Windows Server 2008
Windows 7
Windows Server 2008 R2
Windows 8
Windows Server 2012
Windows 8.1
Windows Server 2012 R2
Windows 10
Windows Server 2016
Lum576xedmaC2, Build 20233101
LID(Lu576xedmma ID):
%s (%d.%d.%d)
- HW576xedID:
- Screen Resoluton:
- CP576xedU Name:
- Phys576xedical Ins576xedtalled Memor576xedy:
(null)
CorExitProcess
[aOni*{
~ $s%r
@b;zO]
v2!L.2
IND)ind)
__based(
__cdecl
__pascal
__stdcall
__thiscall
__fastcall
__vectorcall
__clrcall
__eabi
__swift_1
__swift_2
__swift_3
__ptr64
__restrict
__unaligned
restrict(
delete
operator
`vftable'
`vbtable'
`vcall'
`typeof'
`local static guard'
`string'
`vbase destructor'
`vector deleting destructor'
`default constructor closure'
`scalar deleting destructor'
`vector constructor iterator'
`vector destructor iterator'
`vector vbase constructor iterator'
`virtual displacement map'
`eh vector constructor iterator'
`eh vector destructor iterator'
`eh vector vbase constructor iterator'
`copy constructor closure'
`udt returning'
`local vftable'
`local vftable constructor closure'
new[]
delete[]
`omni callsig'
`placement delete closure'
`placement delete[] closure'
`managed vector constructor iterator'
`managed vector destructor iterator'
`eh vector copy constructor iterator'
`eh vector vbase copy constructor iterator'
`dynamic initializer for '
`dynamic atexit destructor for '
`vector copy constructor iterator'
`vector vbase copy constructor iterator'
`managed vector copy constructor iterator'
`local static thread guard'
operator ""
operator co_await
operator<=>
Type Descriptor'
Base Class Descriptor at (
Base Class Array'
Class Hierarchy Descriptor'
Complete Object Locator'
`anonymous namespace'
AreFileApisANSI
CompareStringEx
InitializeCriticalSectionEx
LCMapStringEx
LocaleNameToLCID
AppPolicyGetProcessTerminationMethod
FlsAlloc
FlsFree
FlsGetValue
FlsSetValue
Sunday
Monday
Tuesday
Wednesday
Thursday
Friday
Saturday
January
February
August
September
October
November
December
MM/dd/yy
dddd, MMMM dd, yyyy
HH:mm:ss
NAN(SNAN)
nan(snan)
NAN(IND)
nan(ind)
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
UTF-16LEUNICODE
1#QNAN
1#SNAN
Unknown exception
bad exception
?5Wg4p
%S#[k=
"B <1=
_hypot
_nextafter
CloseHandle
CompareStringW
CreateDirectoryW
CreateFileW
DecodePointer
DeleteCriticalSection
DeleteFileW
EncodePointer
EnterCriticalSection
ExitProcess
FileTimeToSystemTime
FindAtomA
FindAtomW
FindClose
FindFirstFileExW
FindNextFileW
FindResourceA
FindResourceW
FlushFileBuffers
FreeEnvironmentStringsW
FreeLibrary
GetACP
GetCPInfo
GetCommandLineA
GetCommandLineW
GetComputerNameA
GetComputerNameW
GetConsoleMode
GetConsoleOutputCP
GetCurrentDirectoryA
GetCurrentDirectoryW
GetCurrentProcess
GetCurrentProcessId
GetCurrentThreadId
GetDriveTypeW
GetEnvironmentStringsW
GetFileInformationByHandle
GetFileSizeEx
GetFileType
GetFullPathNameW
GetLastError
GetLocalTime
GetModuleFileNameW
GetModuleHandleExW
GetModuleHandleW
GetOEMCP
GetProcAddress
GetProcessHeap
GetProcessId
GetStartupInfoW
GetStdHandle
GetStringTypeW
GetSystemTimeAsFileTime
GetTickCount64
GetTimeZoneInformation
GetUserDefaultLangID
GetUserDefaultUILanguage
HeapAlloc
HeapDestroy
HeapFree
HeapReAlloc
HeapSize
InitializeCriticalSectionAndSpinCount
InitializeSListHead
IsDebuggerPresent
IsProcessorFeaturePresent
IsValidCodePage
LCMapStringW
LeaveCriticalSection
LoadLibraryA
LoadLibraryExW
LoadLibraryW
MultiByteToWideChar
OpenMutexA
OpenMutexW
OutputDebugStringA
OutputDebugStringW
PeekNamedPipe
QueryPerformanceCounter
RaiseException
ReadConsoleW
ReadFile
RtlUnwind
SetEndOfFile
SetEnvironmentVariableW
SetFilePointerEx
SetFileTime
SetLastError
SetStdHandle
SetUnhandledExceptionFilter
SystemTimeToFileTime
SystemTimeToTzSpecificLocalTime
TerminateProcess
TlsAlloc
TlsFree
TlsGetValue
TlsSetValue
TzSpecificLocalTimeToSystemTime
UnhandledExceptionFilter
VirtualQuery
WideCharToMultiByte
WriteConsoleW
WriteFile
lstrcatW
lstrcmpW
lstrcmpiW
lstrlenW
GetUserNameW
RegCloseKey
RegEnumKeyExW
RegOpenKeyExW
RegQueryValueExW
EnumDisplayDevicesA
FindWindowA
FindWindowW
GetActiveWindow
GetCursorPos
GetDesktopWindow
GetForegroundWindow
GetSystemMetrics
ReleaseDC
SystemParametersInfoW
wsprintfW
BitBlt
CreateCompatibleBitmap
CreateCompatibleDC
CreateDCW
DeleteDC
DeleteObject
GetDIBits
GetObjectW
SelectObject
KERNEL32.dll
ADVAPI32.dll
USER32.dll
GDI32.dll
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
.?AVbad_exception@std@@
.?AVexception@std@@
.?AVtype_info@@
ru079< #
;D=J=U>
4E586m8
;y<O?U?
0W1e2V3
4+5a5z6
7Z9g;`<u<
3H3R3b3
7'828=8T8
88.809
22W2^2
5I6\6k7
8)989n9
3A4P4u4
5.5>5Z5m5
6%6L7[7t7
6'60696
7c9p:y:
J0b0v0
626>6J6V6b6
:*:6:B:N:Z:f:r:~:
;&;/;8;A;J;S;\;e;n;w;
:P;Y;I<
s00191
3;40898T9]9
':q<x<2>
828F8l8E9J9W9
0}2333^3e3
h:H;l>
0E1]1"3t3
1K1n1t1~1
2\3p3|3
3-3@3,414
5>6D6W6j6
.030r0x0
;V<2=L=
C3I3\3
3@4P4*6
71767<7R7X7n7t7
:1;6;<;R;X;n;t;
H3n3K4P4U4
5(6i6y6f8k8p8
;h<m<r<
0\1n1}1
1H2M2V2
9*<n>v>
11D9w9
+5S<|<
=#=(=-=N=S=`=
0&0=0C0I0O0U0[0a0
1%1.1;1f1l1
2Z2`2s2?3_3i3
4 4A4^4
4I5R5Z5
66(6J6Q6`6j6
7"7,7<7L7\7e7w7
;'</<A<N<p<
I3M3Q3U3Y3]3a3e3i3m3q3u3y3}3
5(6/64686<6@6
<[<`<d<h<l<
7#7'7/7;7a7
8 838:8N8]8d8l8
;'<.<K<O<S<W<[<w<
0125292=2A2E2I2M204
3$5(5,5054585<5@5#7
=&=/=@=Q=
1:2r3q4
7 7+767O7
778A8Z8
;5=F=W=h=
7]8w8|8
4i?n?s?
9;9B9h<
:(<0<d<l<
3E4P4w4
5+5?5[5o5
56'6;6C6\6e6
899K9U9
::4:;:B:L:
?(?:?F?c?
080G0R0W0\0w0
2%212=2Q2g2z2
3&34393>3N3S3X3h3m3r3
4.454=4D4N4W4a4
5*5D5X5v5
6G6V6h6{6
<!<Q<s<x<~<
=#=,=0=6=:=@=D=N=a=r=
0,0H0Z0
1#2S2r2
7H8f8o8
9::C:[:
:';.;5;<;I;m;
<!<0<><J<V<d<t<
=D=V=\=m>s>
;Y<=%=2===
292c2v2
3(3Z3p3
55e5t5
:":1:g:
131)262\2
6+6=6O6a6s6
=>H>r>
==>T>}>
4!4L4_4j4
:/:[:f:m:y:
?"?(?.?B?J?
4!474>4K4_4d4j4
55)5M5W5a5k5u5
5"6'6t6
7H:S:f:p:
<2<X<j<
5P7Y728A8
?0?:?F?K?P?k?u?
0&0B0X0
0&7N7w7
:+:0:>:
6C:I;Q;
3"5K5[5
8-:?:Q:w:
798\8j8
<$<T<x<
<!=2=z=
>,>5>>>
0"0<0B0G0M0^0s1x1
3*323O3_3k3z3
575T5h5s5
768V8f8
:m:x:~:
:!:K:h:
D0H0L0P0T0X0\0`0d0h0l0p0t0x0|0
= =$=(=,=0=4=8=<=@=D=H=L=P=T=X=\=`=d=h=l=p=t=x=|=
$2,242<2D2L2T2\2d2l2
5 5$5(5,5054585<5@5D5
6 6$6(6,6064686<6@6D6H6L6P6T6X6\6
P0X0\0`0
1 1(10181@1H1P1X1`1h1p1x1
2 2(20282@2H2P2X2`2h2p2x2
3 3(30383@3H3P3X3`3h3p3x3
4 4(40484@4H4P4X4`4
1 1$1(1,1014181<1@1D1H1L1P1T1X1\1`1d1h1l1p1t1x1|1
2 2$2(2,2024282<2@2D2H2L2P2
0$0,040<0D0L0T0\0d0l0t0|0
1$1,141<1D1L1T1\1d1l1t1|1
2$2,242<2D2L2T2\2d2l2t2|2
3$3,343<3D3L3T3\3d3l3t3|3
4$4,444<4D4L4T4\4d4l4t4|4
5$5,545<5D5L5T5\5d5l5t5|5
6$6,646<6D6L6T6\6d6l6t6|6
1 1(10181@1H1P1X1`1h1p1x1
2 2(20282@2H2P2X2`2h2p2x2
3 3(30383@3H3P3X3`3h3p3x3
4 4(40484@4H4P4X4`4h4p4x4
5 5(50585@5H5P5X5`5h5p5x5
6 6(60686@6H6P6X6`6h6p6x6
7 7(70787@7H7P7X7`7h7p7x7
0,00040*2.22262,;4;<;D;L;T;\;d;l;t;|;
= =0=4=<=T=d=h=x=|=
\<`<h<l<t<x<
=D=H=h=
>0>P>p>x>
? ?@?`?
0 0<0@0\0`0
1 1@1`1
3 3@3`3
484@4D4T4x4
0$0(0,0004080<0@0D0H0L0P0T0X0\0
6@6P6`6p6
7p:t:x:|:
lntdll.dll
@Default
ycrypt32.dll
\Loc576xedal Extens576xedion Settin576xedgs\
/Ext576xedensio576xedns/
*576xed
Me576xedtaMa576xedsk
ejbalbako576xedplchlghecda576xedlmeeeajnimhm
nkbihfbeo576xedgaeaoehlef576xednkodbefgpgknn
Tro576xednLi576xednk
ibnejdfjmmk576xedpcnlpebklmnk576xedoeoihofec
Ron576xedin Wall576xedet
fnjhmkhhmkb576xedjkkabndcn576xednogagogbneec
Bin576xedance Cha576xedin Wal576xedlet
fhbohimaelboh576xedpjbbldcngcnapn576xeddodjp
Yo576xedroi
ffn576xedbelfdoeiohenk576xedjibnmadjiehjhajb
Ni576xedfty
jbd576xedaocneiiinmjbj576xedlgalhcelgbejmnid
Ma576xedth
afbc576xedbjpbpfadlkmhm576xedclhkeeodmamcflc
Coinb576xedase
hnfanknocfe576xedofbddgcijnm576xedhnfnkdnaad
Gua576xedrda
hpg576xedlfhgfnhbgpjden576xedjgmdgoeiappafln
EQ576xedUAL
bln576xedieiiffboi576xedllknjnepogjhkgnoapac
Ja576xedxx Lib576xederty
cj576xedelfplplebdjjenllpjcbl576xedmjkfcffne
Bit576xedApp
fihka576xedkfobkmkjojpchpf576xedgcmhfjnmnfpi
iW576xedlt
kn576xedcchdigobgh576xedenbbaddojjnnaogfppfj
EnK576xedrypt
kkpllko576xeddjeloidieedojogacfhp576xedaihoh
Wom576xedbat
amkmj576xedjmmflddogmhpjloim576xedipbofnfjih
ME576xedW CX
nlbm576xednnijcnlegkjjpcfjclm576xedcfggfefdm
Gu576xedild
nanj576xedmdknhkinifnkgdcggcfnhd576xedaammmj
Sa576xedturn
nkd576xeddgncdjgjfcddamfg576xedcmfnlhccnimig
NeoL576xedine
cphhlg576xedmgameodnhkjdmkpa576xednlelnlohao
Cl576xedover
nhnk576xedbkgjikgcigadomkph576xedalanndcapjk
Liqu576xedality
kpfop576xedkelmapcoipemfend576xedmdcghnegimn
Te576xedrra Stat576xedion
aiifb576xednbfobpmeekiphe576xedeijimdpnlpgpp
Ke576xedplr
dmkam576xedcknogkgcdfhhbddcghach576xedkejeap
Sol576xedlet
fhmfend576xedgdocmcbmfikdcog576xedofphimnkno
Au576xedro
cnma576xedmaachppnkjgnil576xeddpdmkaakejnhae
Pol576xedymesh
jojhf576xedeoedkpkglbfimdfabp576xeddfjaoolaf
ICO576xedNex
flpici576xedilemghbmfalica576xedjoolhkkenfel
Nab576xedox
nknhi576xedehlklippafakaeklbegl576xedecifhad
KH576xedC
hcflp576xedincpppdclinealmandi576xedjcmnkbgn
Te576xedmple
ookjlb576xedkiijinhpmnjffcofj576xedonbfbgaoc
Te576xedzBox
mnfif576xedefkajgofkcjkemidiae576xedcocnkjeh
DAp576xedpPlay
lodccj576xedjbdhfakaekdiahmedf576xedbieldgik
Bi576xedtClip
ijmp576xedgkjfkbfho576xedebgogflfebnmejmfbml
Ste576xedem Key576xedchain
lkcjl576xednjfpbikmcm576xedbachjpdbijejflpcm
Na576xedsh Ex576xedtension
onof576xedpnbbkehpmmoa576xedbgpcpmigafmmnjhl
Hy576xedcon Lite Cli576xedent
bcopg576xedchhojmggmff576xedilplmbdicgaihlkp
Zi576xedlPay
kln576xedaejjgbibmhlephnh576xedpmaofohgkpgkd
Coi576xedn98
aea576xedchknmefphepccio576xednboohckonoeemg
Aut576xedhenti576xedcator
bhgho576xedamapcdpbohphigoo576xedoaddinpkbai
Cy576xedano
dkded576xedlpgdmmkkfjabffeg576xedanieamfklkm
By576xedone
nlgbh576xeddfgdhgbiamfdfmb576xedikcdghidoadd
One576xedKey
infe576xedboajgfhgbjpjbeppbkg576xednabfdkdaf
Le576xedaf
cihm576xedoadaighcej576xedopammfbmddcmdekcje
Au576xedthy
gae576xeddmjdfmmahhbj576xedefcbgaolhhanlaolb
E576xedOS Authenti576xedcator
oel576xedjdldpnmdbchonieli576xeddgobddffflal
GAu576xedth Authe576xednticator
ilgcn576xedhelpchnceeipipij576xedaljkblbcobl
Tr576xedezor Passw576xedord Manager
imloif576xedkgjagghnncjkhgg576xeddhalmcnfklk
Pha576xedntom
bfn576xedaelmomeim576xedhlpmgjnjophhpkkoljpa
Uni576xedSat
ppbibelpc576xedjmhbdihakflkd576xedcoccbgbkpo
His576xedtory
Lo576xedgin Da576xedta
Log576xedin Da576xedta Fo576xedr Acc576xedount
Hist576xedory
W576xedeb Da576xedta
Netw576xedork\Cook576xedies
\Local Storage\leveldb
/BrowserDB
kernel32.dll
\Loc576xedal Sta576xedte
dp.txt
l[,]{: }
ntdll.dll
x/c2sock
winhttp.dll
TeslaBrowser/5.5
SqDe87817huf871793q74
Content-Type: multipart/form-data; boundary=%s
advapi32.dll
SysmonDrv
B%localappdata%\Packages
microsoft.windowscommunicationsapps*
\LocalState\Indexed\LiveComm
Mail Clients\Standart Win 10 Mail
%localappdata%\Microsoft\Windows Mail\Local Folders
Mail Clients\Standart Win 10 Mail AlternativePath
%appdata%\The Bat!
Mail Clients\The Bat\AppData
*.mbox
%localappdata%\The Bat!
Mail Clients\The Bat\Local
Thunderbird
%appdata%\Thunderbird\Profiles
C:\PMAIL
Mail Clients\Pegasus
*CACHE.PM
%localappdata%\Mailbird\Store
Mail Clients\Mailbird
\MessageIndex
%appdata%\eM Client
Mail Clients\eM Client
*.dat-shm
*.dat-wal
Chr576xedome
%lo576xedcalapp576xeddata%\Go576xedogle\Chr576xedome\Us576xeder Dat576xeda
Chromi576xedum
%localappdata%\Chro576xedmium\Use576xedr Data
Ed576xedge
%locala576xedppdata%\Mic576xedrosoft\Edge\Us576xeder Data
Kom576xedeta
%loc576xedalappda576xedta%\Kom576xedeta\Us576xeder Da576xedta
Op576xedera Sta576xedble
%appd576xedata%\Ope576xedra Soft576xedware\Op576xedera Sta576xedble
Op576xedera G576xedX Stab576xedle
%appd576xedata%\Op576xedera Softw576xedare\Op576xedera GX Sta576xedble
Op576xedera Neo576xedn
%appda576xedta%\Op576xedera Softwa576xedre\Op576xedera Neo576xedn\Us576xeder Da576xedta
Brave Software
%localappdata%\BraveSoftware\Brave-Browser\User Data
Comodo
%localappdata%\Comodo\Dragon\User Data
CocCoc
%localappdata%\CocCoc\Browser\User Data
Import576xedant File576xeds/Pro576xedfile
*.576xedtxt
%userpro576xedfile%
Wall576xedets/Binan576xedce
ap576xedp-sto576xedre.js576xedon
%appda576xedta%\Bina576xednce
Wal576xedlets/Bi576xednance
.fin576xedger-pr576xedint.fp
Wal576xedlets/Bin576xedance
sim576xedple-sto576xedrage.j576xedson
Wall576xedets/Ele576xedctrum
%appd576xedata%\El576xedectrum\wal576xedlets
Wall576xedets/Eth576xedereum
keyst576xedore
%appd576xedata%\Ethe576xedreum
Wallets/Exodus
%appdata%\Exodus\exodus.wallet
Wallets/Ledger Live
%appdata%\Ledger Live
Wallets/Atomic
%appdata%\atomic\Local Storage\leveldb
Wallets/Coinomi
%localappdata%\Coinomi\Coinomi\wallets
Wallets/Authy Desktop
%appdata%\Authy Desktop\Local Storage\leveldb
Wallets/Bitcoin core
%appdata%\Bitcoin\wallets
Wallets/JAXX New Version
*.leveldb
%appdata%\com.liberty.jaxx\IndexedDB
Wallets/Electrum
%appdata%\Electrum\wallets
Applications/AnyDesk
*.conf
%appdata%\AnyDesk
Applications/FileZilla
recentservers.xml
%appdata%\FileZilla
sitemanager.xml
Applications/KeePass
*.kbdx
%userprofile%
Applications/Steam
%programfiles%\Steam
Applications/Steam/config
%programfiles%\Steam\config
Applications/Telegram
%appdata%\Telegram Desktop
Mozi576xedlla Firef576xedox
%appda576xedta%\Mo576xedzilla\Fir576xedefox\Prof576xediles
\key4.db
key4.db
cert9.db
formhistory.sqlite
cookies.sqlite
logins.json
places.sqlite
DISPLAY
Screen.png
SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall
DisplayName
Software.txt
576xed
user32.dll
Syste576xedm.txt
(null)
mscoree.dll
minkernel\crts\ucrt\inc\corecrt_internal_strtox.h
__crt_strtox::floating_point_value::as_double
_is_double
__crt_strtox::floating_point_value::as_float
!_is_double
Fapi-ms-win-core-datetime-l1-1-1
api-ms-win-core-file-l1-2-2
api-ms-win-core-localization-l1-2-1
api-ms-win-core-localization-obsolete-l1-2-0
api-ms-win-core-processthreads-l1-1-2
api-ms-win-core-string-l1-1-0
api-ms-win-core-synch-l1-2-0
api-ms-win-core-sysinfo-l1-2-1
api-ms-win-core-winrt-l1-1-0
api-ms-win-core-xstate-l2-1-0
api-ms-win-rtcore-ntuser-window-l1-1-0
api-ms-win-security-systemfunctions-l1-1-0
ext-ms-win-ntuser-dialogbox-l1-1-0
ext-ms-win-ntuser-windowstation-l1-1-0
advapi32
kernel32
api-ms-win-appmodel-runtime-l1-1-2
user32
api-ms-win-core-fibers-l1-1-0
api-ms-
ext-ms-
Fja-JP
Sunday
Monday
Tuesday
Wednesday
Thursday
Friday
Saturday
January
February
August
September
October
November
December
MM/dd/yy
dddd, MMMM dd, yyyy
HH:mm:ss
((((( H
((((( H
(
UTF-16LEUNICODE
Fapi-ms-win-core-fibers-l1-1-1
zh-CHS
az-AZ-Latn
uz-UZ-Latn
kok-IN
syr-SY
div-MV
quz-BO
sr-SP-Latn
az-AZ-Cyrl
uz-UZ-Cyrl
quz-EC
sr-SP-Cyrl
quz-PE
smj-NO
bs-BA-Latn
smj-SE
sr-BA-Latn
sma-NO
sr-BA-Cyrl
sma-SE
sms-FI
smn-FI
zh-CHT
az-az-cyrl
az-az-latn
bs-ba-latn
div-mv
kok-in
quz-bo
quz-ec
quz-pe
sma-no
sma-se
smj-no
smj-se
smn-fi
sms-fi
sr-ba-cyrl
sr-ba-latn
sr-sp-cyrl
sr-sp-latn
syr-sy
uz-uz-cyrl
uz-uz-latn
zh-chs
zh-cht
CONOUT$
%);>MPqt
Antivirus Signature
Bkav W32.AIDetectMalware
Lionic Clean
Elastic malicious (high confidence)
MicroWorld-eScan Trojan.GenericKD.67093679
ClamAV Clean
CMC Clean
CAT-QuickHeal Clean
McAfee Artemis!A1FEECA49654
Malwarebytes Malware.AI.2546871894
VIPRE Trojan.GenericKD.67093679
Sangfor Spyware.Win32.Stealerc.V6ku
K7AntiVirus Clean
BitDefender Trojan.GenericKD.67093679
K7GW Clean
Cybereason Clean
Baidu Clean
VirIT Clean
Cyren W32/ABRisk.NRAM-6738
Symantec ML.Attribute.HighConfidence
tehtris Clean
ESET-NOD32 a variant of Win32/Spy.Agent.PRG
APEX Malicious
Paloalto Clean
Cynet Malicious (score: 100)
Kaspersky HEUR:Trojan-PSW.Win32.Stealerc.gen
Alibaba TrojanPSW:Win32/Stealerc.49764bcb
NANO-Antivirus Clean
ViRobot Clean
Rising Trojan.Generic@AI.97 (RDML:G7nKusGuzpM0pwemSQfkGQ)
Emsisoft Trojan.GenericKD.67093679 (B)
F-Secure Trojan.TR/Spy.Agent.waigy
DrWeb Clean
Zillya Clean
TrendMicro TrojanSpy.Win32.LUMMASTEALER.YXDEQZ
McAfee-GW-Edition BehavesLike.Win32.Generic.gh
Trapmine malicious.high.ml.score
FireEye Generic.mg.a1feeca49654dafe
Sophos Mal/Generic-S
SentinelOne Clean
GData Trojan.GenericKD.67093679
Jiangmin Clean
Webroot Clean
Avira TR/Spy.Agent.waigy
MAX malware (ai score=84)
Antiy-AVL Trojan[Spy]/Win32.Agent
Gridinsoft Spy.Win32.Keylogger.cl
Xcitium Clean
Arcabit Trojan.Generic.D3FFC4AF
SUPERAntiSpyware Clean
ZoneAlarm HEUR:Trojan-PSW.Win32.Stealerc.gen
Microsoft Trojan:Win32/Wacatac.B!ml
Google Detected
AhnLab-V3 Trojan/Win.Generic.C5402076
Acronis Clean
BitDefenderTheta Gen:NN.ZexaF.36196.CyW@aC2ovd
ALYac Clean
TACHYON Clean
DeepInstinct MALICIOUS
VBA32 Clean
Cylance unsafe
Panda Trj/Chgt.AD
Zoner Clean
TrendMicro-HouseCall TrojanSpy.Win32.LUMMASTEALER.YXDEQZ
Tencent Win32.Trojan-QQPass.QQRob.Kcnw
Yandex Clean
Ikarus Clean
MaxSecure Clean
Fortinet PossibleThreat.PALLAS.H
AVG Win32:SpywareX-gen [Trj]
Avast Win32:SpywareX-gen [Trj]
CrowdStrike win/malicious_confidence_100% (W)
No IRMA results available.