Static | ZeroBOX

PE Compile Time

2023-05-22 21:22:41

PE Imphash

ee126499edcdda4d19e739d00cbb1b09

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x0003ee35 0x00000000 0.0
.rdata 0x00040000 0x0000e084 0x00000000 0.0
.data 0x0004f000 0x00017aa4 0x00000000 0.0
.vmp0 0x00067000 0x002811e8 0x00000000 0.0
.vmp1 0x002e9000 0x000004f0 0x00000600 3.87921804524
.vmp2 0x002ea000 0x00488e70 0x00489000 7.9317161759
.reloc 0x00773000 0x000005b8 0x00000600 4.1673105292
.rsrc 0x00774000 0x0002140b 0x00021600 6.33787847999

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x00788038 0x0000c0c2 LANG_ENGLISH SUBLANG_ENGLISH_US PNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced
RT_ICON 0x00788038 0x0000c0c2 LANG_ENGLISH SUBLANG_ENGLISH_US PNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced
RT_ICON 0x00788038 0x0000c0c2 LANG_ENGLISH SUBLANG_ENGLISH_US PNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced
RT_ICON 0x00788038 0x0000c0c2 LANG_ENGLISH SUBLANG_ENGLISH_US PNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced
RT_GROUP_ICON 0x007940fc 0x0000003e LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_VERSION 0x0079413c 0x00000494 LANG_ENGLISH SUBLANG_ENGLISH_CAN data
RT_MANIFEST 0x007945d0 0x00000e3b LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with CRLF line terminators

Imports

Library KERNEL32.dll:
0x6e9000 Sleep
0x6e9008 GetSystemInfo
0x6e900c VirtualProtect
0x6e9010 HeapAlloc
0x6e9014 GetProcessHeap
0x6e9018 GetProcAddress
0x6e901c LoadLibraryA
0x6e9024 VirtualAlloc
0x6e9028 Process32Next
0x6e902c Process32First
0x6e9034 FindNextFileW
0x6e9038 FindFirstFileW
0x6e903c VirtualAllocExNuma
0x6e9040 SetEndOfFile
0x6e9044 VirtualFree
0x6e9048 CloseHandle
0x6e904c GetCurrentProcess
0x6e9050 CreateFileW
0x6e9054 CreateFileA
0x6e9058 SetStdHandle
0x6e905c WriteConsoleW
0x6e9060 LoadLibraryW
0x6e9064 IsValidLocale
0x6e9068 EnumSystemLocalesA
0x6e906c GetLocaleInfoA
0x6e9070 GetUserDefaultLCID
0x6e9074 HeapReAlloc
0x6e9078 GetLocaleInfoW
0x6e907c ExitProcess
0x6e9088 WideCharToMultiByte
0x6e908c InterlockedExchange
0x6e90a0 EncodePointer
0x6e90a4 DecodePointer
0x6e90a8 MultiByteToWideChar
0x6e90ac GetLastError
0x6e90b0 HeapFree
0x6e90b4 RaiseException
0x6e90b8 RtlUnwind
0x6e90c0 GetCommandLineA
0x6e90c4 HeapSetInformation
0x6e90c8 GetStartupInfoW
0x6e90cc LCMapStringW
0x6e90d0 GetCPInfo
0x6e90d8 TerminateProcess
0x6e90e4 IsDebuggerPresent
0x6e90e8 GetModuleHandleW
0x6e90ec WriteFile
0x6e90f0 GetStdHandle
0x6e90f4 GetModuleFileNameW
0x6e90f8 HeapCreate
0x6e90fc TlsAlloc
0x6e9100 TlsGetValue
0x6e9104 TlsSetValue
0x6e9108 TlsFree
0x6e910c SetLastError
0x6e9110 GetCurrentThreadId
0x6e9114 GetACP
0x6e9118 GetOEMCP
0x6e911c IsValidCodePage
0x6e9120 HeapSize
0x6e9124 SetHandleCount
0x6e912c GetFileType
0x6e9130 GetConsoleCP
0x6e9134 GetConsoleMode
0x6e9138 FlushFileBuffers
0x6e913c ReadFile
0x6e9140 SetFilePointer
0x6e9144 GetModuleFileNameA
0x6e9154 GetTickCount
0x6e9158 GetCurrentProcessId
0x6e915c GetStringTypeW
Library USER32.dll:
0x6e9164 ReleaseDC
Library GDI32.dll:
0x6e916c GetDeviceCaps
0x6e9170 CreateDCA
Library ole32.dll:
0x6e9178 CoCreateInstance
0x6e9180 CoInitializeEx
0x6e9184 CoSetProxyBlanket
Library OLEAUT32.dll:
0x6e918c SysFreeString
0x6e9190 VariantClear
0x6e9194 VariantInit
0x6e9198 SysAllocString
Library CRYPT32.dll:
Library KERNEL32.dll:
0x6e91ac GetModuleHandleA
0x6e91b0 CreateEventA
0x6e91b4 GetModuleFileNameW
0x6e91b8 TerminateProcess
0x6e91bc GetCurrentProcess
0x6e91c4 Thread32First
0x6e91c8 GetCurrentProcessId
0x6e91cc GetCurrentThreadId
0x6e91d0 OpenThread
0x6e91d4 Thread32Next
0x6e91d8 CloseHandle
0x6e91dc SuspendThread
0x6e91e0 ResumeThread
0x6e91e4 WriteProcessMemory
0x6e91e8 GetSystemInfo
0x6e91ec VirtualAlloc
0x6e91f0 VirtualProtect
0x6e91f4 VirtualFree
0x6e9200 GetCurrentThread
0x6e9208 Sleep
0x6e920c LoadLibraryA
0x6e9210 FreeLibrary
0x6e9214 GetTickCount
0x6e9220 GlobalFree
0x6e9224 LocalAlloc
0x6e9228 LocalFree
0x6e922c GetProcAddress
0x6e9230 ExitProcess
0x6e9244 GetModuleHandleW
0x6e9248 LoadResource
0x6e924c MultiByteToWideChar
0x6e9250 FindResourceExW
0x6e9254 FindResourceExA
0x6e9258 WideCharToMultiByte
0x6e925c GetThreadLocale
0x6e9260 GetUserDefaultLCID
0x6e9268 EnumResourceNamesA
0x6e926c EnumResourceNamesW
0x6e9278 EnumResourceTypesA
0x6e927c EnumResourceTypesW
0x6e9280 CreateFileW
0x6e9284 LoadLibraryW
0x6e9288 GetLastError
0x6e928c FlushFileBuffers
0x6e9290 WriteConsoleW
0x6e9294 SetStdHandle
0x6e929c DecodePointer
0x6e92a0 GetCommandLineA
0x6e92a4 RaiseException
0x6e92a8 HeapFree
0x6e92ac GetCPInfo
0x6e92b8 GetACP
0x6e92bc GetOEMCP
0x6e92c0 IsValidCodePage
0x6e92c4 EncodePointer
0x6e92c8 TlsAlloc
0x6e92cc TlsGetValue
0x6e92d0 TlsSetValue
0x6e92d4 TlsFree
0x6e92d8 SetLastError
0x6e92e4 IsDebuggerPresent
0x6e92e8 HeapAlloc
0x6e92ec LCMapStringW
0x6e92f0 GetStringTypeW
0x6e92f4 SetHandleCount
0x6e92f8 GetStdHandle
0x6e9300 GetFileType
0x6e9304 GetStartupInfoW
0x6e9308 GetModuleFileNameA
0x6e9314 HeapCreate
0x6e9318 HeapDestroy
0x6e9320 HeapSize
0x6e9324 WriteFile
0x6e9328 RtlUnwind
0x6e932c SetFilePointer
0x6e9330 GetConsoleCP
0x6e9334 GetConsoleMode
0x6e9338 HeapReAlloc
0x6e933c VirtualQuery
Library USER32.dll:
0x6e9344 CharUpperBuffW
Library KERNEL32.dll:
0x6e934c LocalAlloc
0x6e9350 LocalFree
0x6e9354 GetModuleFileNameW
0x6e9358 ExitProcess
0x6e935c LoadLibraryA
0x6e9360 GetModuleHandleA
0x6e9364 GetProcAddress

!This program cannot be run in DOS mode.
`.rdata
@.data
`.vmp1
`.reloc
@.rsrc
Z0+CVJ
QT<k3+
p>B?p4
VIWM,M[W
!G4[&L
+7W8y0%W7
jz*|e[
l]E.6W
$MW+\D6
ccWL?h
#NW^)C5
b"WWk0
uZWx9nHW
2%ke"g
*WE>lFW
<p'CWQ
1+WX9L
@HWl-[ZWK
IQ["}
y(&+&y
GetConsoleMode
14$AZE
AXA]X@
lfBIHFe
M5vna(a
YzaL5tk
">@xec)
gk2LTm
??W8/_D
xyehyK
Kpgd6]P
InitializeCriticalSectionAndSpinCount
ekdf+$
9;1Hu]mu
q?u"v
-hAw?5
5(~8)f;
D14$fA
f-y\VWS
KMF%"
B@D14$AZMc
\'F/l 1
&R`0!%
aJN.0C
=KZalB
jK_^ZL(
,Z52;D
Pgeb;c
:2BW*=R9
f"W`.o
EncodePointer
1f&: '
Q8C7n9~
`b.+ K
-||DP<
D-equi
Jm|e-%
uL~W[hG
oRyf`]W{
g38tlgK
n7,$u1
D14$E:
LCMapStringW
1,$AZA
D1,$AZM
K3WwVP!W
C!Vbe5)
yO|ex
9;A>,
6sa<)7
EnumResourceTypesA
:OQG!3O"
thO8 C
GetProcessHeap
D1,$fA
%)f9l$
Zbs;(&$
D1$$fA
>|Unq;;
;lMCKD
Dee=ty
WpH+#U
/_>Bk
Vdx!$^
\%"/f_65
'E?ZFra
~7AARI
TX[$f;
zii\f#
GetStdHandle
._EW'|
xR;G2l'
-ZW-:M!
O:1P!On
S.FFOER|MO
eR<R:I
:79Ohe
Kcpf.O13%
zz8$:T
BQ:H$3%
T8OPS[
CN68k:
wqIPO1|
gx^,O!
8ER:tB
0EeOq)r
lkG ,
E'B/Qt
owo.1_
OIF0%O
2WpgxI
BSWG*p<
l.Q_4W:
I-0xS=
a((%La
]&M4l|
.<mceO{
NC#FWiH8TW
AR1,$A
kO#=6W*
_jeir`xe
*f{CWo4
{X9AR1,$A
Fje(wyxe
z~`}e?Q
'uj+v|
{t~d*}
]q+gmv\
p?(1wH
kH:;O
?L9:"5
X5RRv/
M#9@rk
ARD1$$AZ
D8o%H%
ARD14$I
3xjD?&
QY$(^f
"W4U;0W
+W5naGW~
*cJ;:N4
yl(g.R
VBSyFea
~bSI|@
`5]MB:Q
oP[BP:
Jka&egz
$d!:Y[
,iU,$UW
c`lFWX*
FF4:9N
q)ZR|Q
~ORF:V0
pHovDjHLZ
k"7'n e
^&WC!|
"W&:#e
eX|bC.J
8jSC P
&Y_G[k
1ol"^
]'.&'+
kEmx<&J
5QtIz{
|DPQAG=t.e
tQI%\\
pazs@'
k#Y^:*
VNQ_fI&
`"H.P%?
VJ_yew
'NW{lG5
Ch[WR)
11+W#b*9W
"W:MdAW
AR14$AZHc
fNJ'a9
2esweb
S0:@W0
EnumResourceLanguagesA
7'se;V
1hp(M.nx
lQ Yhrek
+XWF1K#
t[W:{oIW-
HeapDestroy
'kq,8$
Z<W!6:G
d!12y
Oz.^Gz
A\AXA]fA
D14$AZ
^fW=nU
GWzm<
SW2,D
SWR%R0W
bwfe?u
5V6:W>IVA
GetFileType
Qbe^0
nea5I}e
Wm^Ng(
ehzJF a
K"8(W>
x|Lbe%c
,WoxxW
SetStdHandle
a~(.0w
G{}-w|
}K+fML\
1#s[`*
&&X'!Q
f#vdV$
)[[|e
_W# ,E
pHnbeQ
u4WuB
rPe?}
QtZBY^
}lG:P*
8Ei:-ma
x?-;Q:
O[H{9O#];
:TB@TN
=^dH@,
8sbeGg
fH3_8R
uVf(ffp
14$AZHc
^,g=X^
^fpv{n
IsValidCodePage
_*{mH-?
%`fJti
e3I3bD
r`cuBg
=Dzye&c
0_W[b?R
D14$AZ
FindResourceExW
T{_J:
.(7V&T
4`@Rz+Ow
}{Bbe4D
k1`e4t
<`~b~A$d
"Va$O"W
tPtL[+k
btWUfi
14$AZHc
Db^J=a;
LN2Enj
5Wd|8[W
[W;`y7W
J*_{?Yxf
@lU-4yL
V^^c1E
^:w]Y^
_WS1fCnXu
mWzgbf
j.(Fq.r
5$"`Kf
krfNfe
!jEW8C
rJ5gec
'5,G#-d
24jg
y?B!>
h+m\j$
%ksXjs
-wMVSf
Process32Next
O*?+;OB6k
ama4oa
q}zkyKT4
'b]nARE"
[I:i~
0UWeD+GW
|?>@W7
v~QceS
]<g@E:
}|V(Lq
Wje]&hxe
v!I\H%hT(#
jh0D\T*
{B'W{)
N4W<]3
UN\#Au?D
"<`1{\b
19*QHp6E
Xb-D}O
poZ0$Q}~IAo-
GP7j(a
TFy=f;
ARD14$A
xl'"F_
5!)L"k
~g\G-:
s30}pu
/Es*>0
q$a9H
ejOS2Km
<gDVM+
N2oZGPQ7
Lb$I1Us
EtVHD!A
j}y+$U
*~04DP
IJkJSd>
k,E;,N
n)cKONG
(d:"I>M
;*X.ywM
U?XnG^
E)>;Ix
z&7/A~
0+ICUGhTC
#GqJ3z
bwSkD^,
--e_}04
QxgF;
ey}:N(
)7`mq'
H[~:={
i0MJ\2
E9lmQ)=
a6_S^7
on/vd%
)$cp/6y
Kp`bhO
c945"7
g"oe<`WW
5faBa=
ds4p'X
NUz50k
v7B{CN
dyAB!
m@9wC9
E(?:ju
* UWPW
axn.|v
7`"Fo7
z_w#w"
c>i@df_
NN\c<r
t\Rf_.!<@
ViC&+x
Lo>YE4
uxcpUP
I[f*$Tj
$r,?Hr
o;KZ:w
;`W`:-
jVbiK
gHDg>HJ
|":D&n
|an?=I
#)U)&
Ysvr[V
-+3H0x
g}x&$ U
i-}?GKM
la~(*-
nhz{L\
~# iwr
:Z;6"@
@1}'^7p
F}Y-kK"
HHer-7_X
weu1vY
H%t$0
uAu,`8
3<>S,k
#*-<au
_2=fpe
W0CA@{
Wk+gewg
=$NRH`
PU9Sytw
w/ugp~
IbW6G[
":?=5%
LOXMTv
w|`w~"
ex)<5
;%s%ZB
oT1v4?
hr^/E?
_V]/ay
yZ\W93#s[
- /X"";
X:|eK5
7D0;{{#
O"B(MwM
G==PUN
nnvKZac
1bx>c'~
lfR[fd
GzB 6o
A".Ow?
?VTc\y
#11"B`m
&l5qQ"
j{Bqy4
,I]sp`
fdW~ec
mh0-,z
hXb9*d
JHmk0
R;J5SK}b
DY!r{'
Hy(*:F
/[g.=^
D,3uH
_bfm+.
]gbXm
k3'pJ*
I*HvT/
k084${l
I7%r3&
AtA/4P
awdgr^
[0rS_
CWpm1:
4\3(Vv
14c,{(
NJZF[Nr;
'NURkn{
nfST~r3
Fm{zcQ%=
o6zh@g
TLO5W.
X1)/w&
9]1PJ)
X^(|1W@
=(sIyMGt
)GW9sc
FS>(jw
^~ubHm
<`-r&Pf=t
u-7Fsd
]?it/
/\s]6F
XC87-2
F=XSA1*kxin4
.?x#7L
EDxB=W
)sh|O\LS
]y8F$}
c2*3Q\
,lDRbD
q1zEZ
L?>Q[-sf
tKk.-J
q@W>+<U
7j$>E|
:rEN}#
W4]uiOr
RpxWd\
},+p|!'
0_&$A(
p1@C{DW
>g^TpM
]JGA"~8Dr
z*;sKa
q}x' 1
1dr'KE
3Lq=Hk
1B@"Ey
DR*4}+
Oe2rZU8
hleUPG
kf[j1S
'qy=.4
39[s?Q
rV$^(f$
QFY}!<
:9sXF`o
V@Ss{$
r#M^e:
6B'Kx[
pUJJN-
>]&}#8
Vo3 CU
\Yf2B$
~iIZ6m
SD!*+VNJ
D"DDVr
6YZ\y
u<"]!N
gfT4t'
4CVy.&
|!lG@-/
AR14$A
EpiRH2.
|&#R?3d
d+jkVD
~q\SNv+
U=!<lHW*7
D1,$AZMc
T'@0v=Q~x
HS:%O>
OQZ57O3
O9:4lK
L!5O%T
wAZfD;
-?mO'?
QAQmlK:
f0$o79
:10 k8
[],nkZ[
\8!7[O
@5qlp2
m15]6B
HeapFree
|<0!l;<
80#ee!
CreateToolhelp32Snapshot
A\AXfE
VL[A[A
&^5W7?
^z96\^
eP\&a
]^mb"N
PE;&l`
Zv`8!2Q
?3oQ,^
U@0H8QH^
M\4^Q0
Wn=`z(
]pVYWRsMKW
.Kp(?e
inem*V|e
qJ:we_#
ytqv"s[)
X|E7h{2
}Qx4z&
OpenThread
?#e7m;`
O,*XAR1
SetFilePointer
8-equi
B57@t&
|>X`0y
?0RfAC
J)&PWY
@!(}W7d#
k6 reyO
Alq2W~?j WQ
8$XWQx
._b:GO
iY8AIw
k.hCZ
05&lBq(
<E5|Aia
Uy?B_&
.Dx]W+
r-P*#$
ALd#F;
y,AZI+6
ARD14$E"
VJWJ+MXW
x~*zeM
pyW"Q{
(eWE6#
UHW"cNZW
;"Gsct
f&`d=AJ
OiWn=D
EoemRz}e
oU#Wf=
+,WC"0>W
[D\olk
/oxeH@
WwOmu.
??likh&
YkY5il.
jMz5m:
XW|.D$
3#bef4
9wH@;T
WideCharToMultiByte
D14$AZ
J~)|ek
hpa*eEa
No%\LW
J8I;XW*
WriteProcessMemory
HeapCreate
F[fe%!
*KW[z1YW
+D14$fA
V_WzM6$
CWu"u W
M6T'}1#
7@h!07
p[\&!R
,ZHi}S
{ZMVK]:
X<9^$k
Cl$]skS
nh`.^o
)OdeFV
@3eeQu
XW6!k#
Q:.eG3
A^NgPF*
|xp{-q
yd4qp
|176{F
Z}%xjzR
Sg-equi
u9D;m/J
.E}Yb-
8G[OOf}'
lq=1f;
g}xL6P
q<N(>F
/JV?~C
sKBp"B
'^>" )
N&Jq~!=
1o$Wpf
g:OW}<!]W
VirtualProtect
}D14$D
;>S{l
l(Zoe
5f=i(3
>3:erqiX
;M>QL0
BW>%<D
L$+`pmm
/O\`aA
G@WtU\RW
.LDQ/F
x{WV,Q.
UnhandledExceptionFilter
SetStdHandle
miB`e4~
#o9_Wf=
RE`_(x
rR+w'C
e]}1`@
HE]<WG&F.W
n|e!H]
IAW?^4
^Wi~i%
v\[^"P
8^&Rx!
TW)^47W
So{sK!a
sSWfGhAWI
uA__A^f
[\Y[9+
>a`4b9x
@v3uzw
*WH3BFW
skKWsD
JjWLA
.AR14$fA
h2{Nf;
|i5e-`
h!*qa
Zl`fjk
vi}RA0
HvW14$AZHc
J(p}VF%
ONXF<.
ZDLyrS
"D-Lka
Bh`pB/
W9j'9(
?jeae
lfJWFg}XW
O WL[/[
L[W?(,
YIIW{ZR[W
6` ]pq7
@?(30F7
ceou't
ble)&]~e
AR1,$AZD
gCve4i
BWX\Yf
Q]G~gsw
Ub)Wd
-W6MtAW}
l@a^?{
PYT)O$P
GetModuleHandleW
( :W]W^0
:*Napd
CDWcT#?
c|kl5G&y
@W"Uy;
^* =~~*
I[UWP+
\GmWZ)L
H5Y,Se
=.eej2
\?1*Wo
ARD1,$M
p4Bzeo
U,+/5D
 gWyJ+
YWpgo"
M}T~f+
[gf@{V}
%BDs`;
S5(~8)
xj}g|[g
F(E[H{
4Qru1,$A
5gci.f;
1,$AZfA
=+ieN[
\Igf;
'14$AZfE;
* v?",<+q
`.}s$6
.b(xQ5.,A
>{Nb5#
SEWl-HWW
]ae4yn
G5DnWn
G@05PM
ARD14$AZMc
r`},#i
yal\If
Te(/db_
d<`8cK
LJXzei
SqYzeN
X;=%W#4]^
^se>]aae
q%K@N'
D1$$Lc
Hx5-f;
5zW>m>
q2(]WJ
G$'>Wl
V;W/n+
G[;Wzh
AFWds!=
GetConsoleMode
K?/'`x
e#@A"W
*}p]Wf,
;q:Od?
q79`A0N
=_a]lV
j_dbZX
Z4^+]C
k*,KbK,
iqGfNx
{uW)zp
o4"W.l
9UWO."GW
p0`-PWM
LHW3RWZW4
=Nq=Bf
'SWt5<AW
|$\R-g
cZ_59J
]W9BY1W
9X]W&0w
S\!Wr
TerminateProcess
]W'\'1W
xO&]WTz
8ta~RM
_<wFWl
!s|vS7
0yD[b*
.U[{Hr
FreeEnvironmentStringsW
T'2^(}
14$AZHc
m_~e\a
Zie>b`
*I\QWAv<*
D14$AZMc
c*|Y!
KyT6ca
g\ak_Eu/
s|:Zt
b@H`yh
Wj9Mz(
P3(OPM
A5ILnB
la!^8}
D{HTBv
x^$ky^
/q.(MY
:cf;(4B
MW-V'!W
leFa=~e
n1yWx+:
+0{e@\
WjYT,(
L\[aea
@jWp#K
Ne:b~bM
d.-"cY
JW:Ma1
kJae.L
).7iOr<
#sj'JD
|lrn|I
9IxyrD'@
DeleteCriticalSection
H1YWF5:
U6W\W~
5n~ARE
W%x\bp7
reL[4`e
Gd2(M{
/uD]3I
W]nL(
)Sg;xZ
uRst$[
H?{ux8
SW&wcPQ
V28?QE
PdRbe9s
Rqe%a~`
>_WOX^$
1,$AZE
5n^Xc7
4h{ek+
?`Mcza
^tWBqU
7MWEO?D
BRoeek
x[GZ{|#
F{k.N'9u
Pr5bJJ
HeapReAlloc
~ZIWI
Ibe74vpe
'7WqfGL
-G~ke8
0IW#b+[W
geC76l
;dWxjm
ldRG\c%
7|\h,
$TWzBm
=9qe`*
RSW'fIAW`
FlushFileBuffers
F8WA ;
W^wkYs
DRp8YT
_dA4_wKq
0+Nrv-|
r2)8t`>[
rv.oeo
??Oae
$:g*Wb:
yr`uO
A5$:4s
A3nkePT
c}7ieB
jQ8_<7,e0
0W;EMD
YTWI~9/
0,W1&PW
^(S)B^
^_(gP^
GQW`A\CW
%~!Z7^
L+.iU^^
Y$Me^
D W*K_2W=
0\WjK+NW-
XC1Wqc
_kUqe"T
KWdP'W
(5\vqRx2
AO^/i_
TqJ.O*
yXh4qN
Hb)6:%U
?O4*06O}
Vq:l?k
yf$@Wv
0E+b\ea
(5ntAi(
ExitProcess
TEW'P4>
AWMl=
PWz}=D
2"+ne/
-]WI(6OW
AR1,$fA
UWD?[9W
IfWYjB
CWQ*F/W2
j[_<Z\(
\7FMl01
'FI~RNe
@DxGDA
e_|a:
xdU=)m
$eArul
seDMCb3
mi^Nv.
/]k~(0
TlsFree
Ui5Y,Se
'f*.r+
6jgfA;
D1$$AZMc
.yU5IY
xe]9Ee`
;[W8Y IW
n+F^f;
#}]X&5-\
c5^J&
kED3[B3
])]Bm.*
GetCurrentProcess
|0xXW!Z
1Z/U#D
{M!C!Bx
"hW2A)
j5$"`K
or`Wy*y
HeapSetInformation
.)9PS
(59li(
+jm,]A
71xveV^
.M$!W5
-pu="y
P^yJ.C
Qq 4$^P
eteA);@
d$-l_&xH
}k~O^]
k6c}+5
cb)))UQ(T<i
GetTickCount
5$"`K:
TlsAlloc
GetProcessAffinityMask
w(9]G/N
gAu/6H
;@a`jI
Z,}.j+
E4c-BC
AD ,qCW
l@d_\G
kFCZWL-XHWk
]fdK:5
foW!rm
MWl{}6
>~O-g;
't||4E/
KHv/cz
GetProcAddress
_,J;X[
62$Kg;
zZ|vJ]
a2!tQ5V
2D1$$A
1<LARA
q40 AR14$A
4#5Oul
>@zn%Oy
J-38O|
v6N:Wp
|-kr,D
?5F^$,:
%1ou(D
0Oj/&1
hT:ZtBm:
AR14$A
ObW sD
x`%!!aU
cmeX[><W
.MW*W=
egX8e
C/1e$n
sM.&?m
S WER3[
(ZD;y:
}w%ue<@
D14$fA
<,hhm%
`-|'1$
pD0U@CG
]@t&mG
F()$v/^
)=k*.J
k,mW[+
b,+ueSs
$p(2q"x
8H!;Bf
GetLocaleInfoA
DiAWgxE8igv
ezBK`(
|eQJ%ne
Z3hC>
}q3W|'
u&>Wg&=,W
ARD1,$A
fj+:p7
W*~9P]
UV>1eQI
xRzBHU
h;6092
c:'@S=P
N>c3~9
Rbey2mpe
B$`uec
<AE$;6
)QIDxX
~QL{NV;
g8YyA3
ARD1,$fD3
nZoe3y
Y[~(-N]v
PeA$c
Ddautc
~pDdNw3
;2;nh~J
ma'p6|
i]]lB@
50=}lp/
VirtualFree
=wW}.6
yeOgr'R
"!}"Wq
GetStdHandle
c@C^SG4
-N`9*9
U,Z/e+-
AR14$A
}X*AT^
MultiByteToWideChar
D1,$AZ
SetLastError
~`(';Q?
\,tmB;T
}5DoU|
N:_CQ<
[h:&5f
)Ot)N[
9Wb9>UW9
PW( $D
=+eedd
DW3H5(W
5F^$,;
`E3<O,
VOgv0[
~MK,O.
D1,$AZMc
1?sW,4
WRjjy(.mlq
2WN}OD
DMW#4$6
6vJ9
z EzL"
U,fQi}h
ARD1,$fA
{.@f}?r
x9rc=A*
(tSw8gC
GetEnvironmentStringsW
!G.yUE
AR1,$fA
D14$AZfA
o+Wqx)
6{9`8f|q7
9DVW0k
D'u^K2
-H"IED`
_3P}C_W
[.`D3kq{z
E%WDhdD
6w'xg~
Lsf4|t
aw"GQpU
H5Y,Se
36qs#I
j%FHma
#VNhJ~m
8iPk_LnG
91FiE<
w<4W~&6)
.WD%3`
)6 1Sm
B*E^96
:GW{f/
@NZ*l&
!sO_$K
Z.VA{]
DWqdv_
UoAWfL
l7+"<xV
dY=%7e
wJKQ|x[
INoOQ4
MIkh0
Lq~^X{
zzU-<
5VPa]1
&^A'l/
b1+Q&rC
GeFCJ^
@C]qR.
a%;Y"
"8'<,Q
lgBPfOc
]KGvuY
vp;Fi$C
CWWP:h
*Gfwm4
A;OwC.
YGT_]Z
sOXwu}4
?c!t'+d
MaerZ|p/
,E!LL\
{W{u>%
h?9"Aw
0wlh'&
aoOM>4r
;3Mv=~
5hrgKN
bk!h`u
t;>[ ]
xp+vEnk
j64KtB
^<06SkJ
.t|:n2
2=dTtw
(%N"Q3
a:CIP
/U<>]/sX
lZuGbwV
prLReK
c(se;?
]6[Xl'
DP:-p9
r8mn_
U])ZY6<
qUdB320V
mK Wf6KO-
WMQ5B
(tv.\"
L}Iy2H
"2(cIk
4Rqv=Ty
4?ei`Tug
9<N]:3)
PIb_'
]jWY"
hPXwyGI
_9+Oeq7cQ8
DVdS,
I+r}'r
#|wh>RQ
l1E8hV
1P'eJS
Jl4,yb
Zv6:9ss
c/+u0wt
=X{}hlU
Pc6)q\
<E%J~nE
Yg4$V=[k
K>`6iM
zM7Dwu5
~>=V'>
qd%W-w
}O*XR3=
:~%Ql8
;PhP+6r
p yw{Rx<
H4eo<g
gIGLp$
K~\(4=8
uQYI'
?r_n]1S
Yr,;./u
I 2e/,
y\[Gdr
~m-{Y[
|5T99
[@k,91
E5V.DhS
TVL3#.v
'T"RGjSPLW
b7D&PI
Hk >[Y
Gwq5;%
lc_3E$Y
cb^10@
$h*m6S
QG$on
KG2|x5
T0td^H
- 0'V<
]P;rc"
5?]D9_]
$h~]IZ
kmW -N
!:i^Nw
E8Iomt
;a9U(l
j~P1)~oU
]SwzPq+
6)-,DVB
M>/[Q{
zs Z;U
^+[\rV
Sv_sRP
R.,!M_
:bOn-+
NWJ\C(
}4OvSn)0
+X`Li*
YHHV_
A&u71N
,g="j!ewM
F:DFCT
>(_.J:Z
i2YYNI{
sm~YWrR
MOVrr|Hj
w\uF>"
_6Q]")
1|n}~`
]t(.Cv
z&gO0;q
@(!:08
Tflds6{
kN@Jh-
|M|^LM
Z";B]252
iz#|8iI
?8'G_CCp
8regTMt
XG!5\V
o({KCCO
_tY'8!
vt-/X9
mV2csm
i24Q)2
cBv8\5\
$=-J9_l
@|AGe.%
#JF+Y=_
s(i<naP
$({~bM
f~K#fr
E3T7&Iv
B'1>LC6
r+TkGi
>D>G:Q
4m\rGC
gfM!C|
R(9YI8
e2Kd5I
)*>G.V
p3DOUB
7uN"s+
:(-.Ii
~_}I5'+
A}*GqnPc|m
k+Lcu
fswwH!
KLnD\qhB
zU$kxK
6c72}A
DY5?;kL
h%}1H}x
xNgudI
IJM2Bv
pWXYx`
ZIxT30
zc}Q8o`
jk!=Bi
kKyDi
b-*3'~-
Qdy9SXS
,cgw'+
M|gP{0
X^3ljp
&dVeee
r-APNh
|cl8[!T9
8FI%ToI
i"x^Q
?],-Z^
i~c"+IO
C{$#iaSt/#@r
P[dah^
[L[po
6jqkfR
)eF$"kR
s"*6q?dsf
Z2vsyp
~%53fN
v.^Rx7
q<yi$3N
N*M(ht
DI RtD@l
wS]Fc0
XzKK<x
hp>IEN'
Z=D$;i
4+{v/m
kFZ@;k
:`uQ!mIK
`QLC0m
.T&#^lN
`P=u/D
s(O8)/
@\%5/
{sIbHG
QnU;k^
ruE2Ld
tP|<
sWF|]hp=\
e+z<l?
gX/v$+,
Y$h0Js
mU=v97
Wclb?4
4>h>+6
g]s6W>z
.]3}I/
sfAnP!
m]*#L?
2O1,;!y
u'Jb/t
xje(a-Wo
zf2nIgr
^#6>!E
RBi\eu
vzhzJ3
.i{zb,
>5{(27
ZH(*rY
ZuFh\^
"<1tQ!
\XKsS
iBGg8Q
?^<g2-
i<.5*vC
EYX.mPZ-
|}0DCq
.my \e
al2Y&b
gXozF
&%e^I=
DP2W{H2
udX/~wX
6sA\%rB
[Keu*H
n5^:m7D
`g1jAO!j
4PaLD|z_
mvYaBs
Tg"IF89`
2uRY9wZ
I+:&wt
Y7G2sO
`>+NGz
!x&Rbe
H$t?^X
<hJn;K
?<yH)W
GMt?x
#?2_|,
TwZo0_t]
;w=)-9
(gQ]n/tmI
+a8eLE
Le;rOn
j8x[pG
A'Aro<VO
Q qh`x
U^wB;s&
cu/F(+
PjR8Zc
.9EC8iR/
_a8o?|j
j't.8x
:v`EQQ43
RffT$07
] KLnL
1>C/rA
Pef#HC
`16:AS#
4K5Oi?
}\;Qdc
.$|.D?q@
3l>DH]
{tvFNN
a;V+{x
=b"JSF
0Pr%1u
D}=aa~^Z
KvGstx-
V4,R9^
YeUXt4
b(x.>X
.k#=@M\
c-]\#1?
?;YtDac
@t|Fnk
)`rz'8
.4z%T%
\&JAti
<o]@Bx
ZGnK!
'F0&y=
6Q.SJ
MxW~%D
c,}-EX"$
i!)y*l/
.ML\+$E
$TF?W'
CdzEal{%
<{5\k@
F+e6;F
P,gYC-
%bA+>E
n!{3^> *
Dr0bAd
Rt2=%o
DoEb/M
e"U06m
aq&>in
l+uS1*
$]XxT?
pAT44<
qF46|&
!m4[gz
%cTl[3
b,fH|Z
la'd2q
z>]{$x
k^tLVI#8
l_%&Gt
op:^:Q
XsI"C0
"?;dUR
}/CJE{Aj7r8=
TGUa\t=
8{GNjX0
>~fXN#
haP)K}>
h'dyW;
WUS] f
4"Cd|_j
:bH vH
Hy~ *e
|VVm?i/
_\qW|h
<HUc1mI<
<v1) f
j4td'O
$eF"^wa
wT_f1]
4Hd^\`
"O']?Y
.=)UMz
~,iB v
K(Y0l,
[QS"9OP
w{Ki*0c
9|+zQW9
DGV$&nV
H4<&V#!WB
>mp|R>
]p\JE/
N,W%HZ
UoUq:^E
jc5Ddx
U)%ijM
{[["t
D@;h4s
92/&B7
X@&1K`
YoKceL
&]6Tg#<
6\ugnVwk($
jmjUrh
D#]W@j
TfU5uua
@$HBOd
h[wL$ccDz?
VE[Wrb
DTr4ru
=F^22/
Z8R<e^M
$Q(t=5-
~vQD9GL
,2TQ_+
|l~~<w
5"Y(P|
_PV\cv
Aliv~r
(-d@/O(oq
c;eT+-
_y/e^}W
@r.x"{w
)P0GGv
!{jOjV
O"BdQm
@Nf&Wq
$S.'a+^
5i=17>
!t>\N`
*h~=Z1}
[*zm]OH
Drzm4wuo|
{fOg+x
bY/bKI
@F!(Eb
hEv;zZ
>Br5#~
gU3jkt
Wqb$YL
(HIPV=w
&I!U:L
~W>MCt
>4QETz
9N-6D.
f |:<@
Dg0/YS
W5y/gF
71g##y
z5qL:u:b
Ulpa;$R
32E/ZI
]wz~[*
1W2gNE
WT0#wP
z!xa?&
PMI~MT#6!B
EFchO|
XgWQc3
A*V r4
m`@$?I
&OE+F1v
tfT+5D
V#w*tz
tJ Hu(
<h`<'k
78(^/4
l.pH2'
tv>XR<
pm,gMp
* 0u1
#1$^o,
jBL){7rlf
WcPeNKQ
gWW-]}
c>-sw"
O~j102w|
Kqo7M@
!nQNe1
!HZ*`j
,E`<zN
F4#D'*
[(_!YvF
lOFw#NF6
i1[hT9
&A;Ve7
oJo_x
,yTUWK
ox8QqD0
&=b['_
=|$1l@
\WZ2i2
+Zk0iYJ
i>}.\+
nIH 2Bb
$f_@Pb
c/Z;;I+$5
`,9;K?
.d'/=#
f`"&WKv.fF
oa2@Uf
3ZR.x
ech%XH5
>D>_Z<
{W[-5.
uU1OGun{
zWdkCy:&
:]K)^7
41UWYD
Zj!q+{
B|Mwph?
}1FK"
TX:DY^&
A/}y#D
[<2YOk
u5YS~8
s8Yl!^
t7$Lccu
oR+p=5
[JID8G
YD8+!S
8\Bl^&4
I.F'K~
P6C"0
4c)QC6
Hm;{[>
$lP^jp
?d\.P1
n#!<~2
!Hoci*
#w!tPf`y0C
G~a,Cy
q0r2}
%WnrWg
*"x\gIq?
rq ci-
@a?8x
$8O/u
%?u~V%
<zo:&,.
$_62Pe.
7{fpml/
dpi3]J
,HBj!j
oJ,8BwG
V:x`>)e
U^}1)]#]
}"ZN1m
y^81Fs
tRaZzTN
bD,03"h
Uc"M/}
7K%z6&
kl8/NbEac
'#vF=t
t:H[b)
7kK@o
3m<OEn
Li01P/J!:
vm(^|5
GJi#G*_
=;W)6w
%2n!M83
m|A W#
+|za;G9
UD"?c>*:l
&MVDsvU
nYd#[k
TTLx>2
@x=3MVu
)]6SI/
Vzm+9/54U
Lv3tvf\u
LPK!g94
}w:LF+
emrT6e
3a'h"L
$,N\1?
D{Etb'^0}
Y%L^P'
i(Q5@56|A!}
iAv3XdIO
}!U^3i
{PMHkM
)kV{}4
G%vW-Z
2o-^jd
6 7|3S
]fP|e_}.
iY|rP$]
1fU?+~
F;Yvl$z
DUt<(p"%<u
.mhP\
tB/:&r
`l0+(,
_,>EF*
l<&HAX
l@3)BV
N$f'/b
Yk&DB_
$'y'~_
^<#Gvl)
a\!oMC
|^+RU1
7y<MAF
H?s=X4
^s)W%X
#*@Ofh}
>|$0X[
Yyx,^9
# k[+F
Ef!k`E
Ld>yYWN
Z7F^7j
v'D*'T
Wa806O%
e0~gY:m~
f"T&i^dn
*i )chJW
1osozS
fu]gN&
aQ1iY3
_Gb"/
-:kw62
G*U8iJ
_!:ZB~;
5c4eR4
8.k|5")g
Hh+!W6
?!cT1=
$s*{Y4
*I&s[s
XSN)X\C
zOJg~2
ff{48*
nLMrFF*
rgv[HS
ML5PWf
@*uUFW
`rc:sj
QjUb&1
@[S<>
e/p1/R
H]DK+/.
$fV^A[
12BrCT
HztTb*
8=,h`\
+Qdb.~p
hTp2+x
`}KP!B7
o:Bah@
qWmllT
3:O{ag
9.\+x?*]
@(0a!@
:Aw:"u^
06\JI[V
#eQ+[^
%0@[B2`
Pq)RD9
pzoB`]
.SS/\]
MHw~_j
1t$`v
sH9 +.
Rs^rN
@h<-"NKOH
y]Nw}z
)(5k?Lo
BJT^]t
oJdm"NGo
Sj|4!8D~
\RB9vS
Xa@=#n
ru6 yK3
H:KX6f
`T?isy
Fgp:EY
P:-&jV
J:hjXb
h]v_A?
61?x~1j
nZpmKI
tJCi9=
E2k}Xx
hM&AhNo
5d~mJ9
Z,-y+)
73eann
HC8Wfz
PP UxcT
@Wn2`+
ro{>b@
K|gmsZ
7k@wcu
KvpY'40:,
fP^|nY
N,;e#
vd"vG
2 N^y^(M$
}42Y"C
F N O(
Gz'I;G
^60&nz
YX"3Y:
uSU7D7
$LZjYJ
Hpxcvov
_egYdZ
'xS5*h
9*p}8e
}2b-
i0,{6@
[wb?U[E;
p2@AUDG
#urnR:
\&m:\r
{YRk[1W
QL8Sg'
5#rCDJ12
%&?]}Su
rj80B5
,q@kl;
+>%#rL;8
)G| $]
,n2x{W8
CFkx^R
y2;S(N
-;'2[f
NnXto.D1
XiUi9K3
{kiW+a{"t5
VT5]~u
l2Xo^2
-m:<2.b
_cq38^s{
G6h.*iP
AW(H/|
$n7D^a
f/S{>1<
P3+Os
w4mF{%n
9Z^_Lrx
sDsGY
"GKLM
i.w^-(
By%44y
~`!<Ye.D
=}RN.p
:H=SWF
w'@Y>D
mM>lg;G
N~`p<>L
Xp+ctyX
Dwz&u2!
ArwlxEH
+s."W"
(8Yfe8QR
ck -W=^x
=c/y$c
/cFWoy]
nt?K7Z
)L Psy
u$tc~K
6Dbk Q
vdG7QP
;j)+ I@<4
w;4YI
n?jOKm
:Lo&_9X
T@Wz}I
3hOOq2
Is]-U\h
^y7mg
}1"zX\<
[ !+NNp
|^;J)L
;Onmz7*
9G#_67
vUh'dE#
Zx:W:C
C1{F10rR~
sDN-|w
ER]k%v
|q18-S
55UoZX
:Cc@ql
-7/#i4l
|^!A7@
pP\1Iq
"GGbS4]
W|6c|
fU c0N_
msJF,'*`T
Etd:=w
,F&XrWR
d>7}J=
>r\[->
tmb={x
dfJ4KJ
XuU];g
AN4*(NcP
Y&b -G
Z"EH7q
h]boC#U
5Iteq[.xg
VSG K'#T
qWS)F'
nrh_Io
o~+e,Cyi<
IhIo7);
&cH~Cx
vbA@}]
gnw:6oCG
kCl.X>'
)3J>XH
U%"T}5P
EQNbG
\zD5_w
]C@4vb
`#NeH-
rnke|\
\gf/vt
lNG1'T\W5
o19:T3$
,"coRZ
A;bQd@
>} .qKoOx
@^Shw?
R94DDcv
47h#iY
Yg$h*2
X)nqfL
)T*B+lf
|<uMKK
HhF6NS
LC<r l
r4:oA<
$_rYo?g>IL
%78BkZsQ
| uO].
KW\{s]RBA
D_NF$\
B>i{^ef
2qWYdb
[#|3H&
!sbfcvyK
V-dG<.!
K@/ZY
g&eR^r
%[+^[n
Vb>.2'gwO
:O|t#2i1
>[M}&e2h
~?x!n}
p6KM'z
^c!r1N`H
`]<*yw9
5b>r%~
I/V_{|70A@!q
MNlFM9
xL"t5YM
//8i#E
-@_>&m
Y{7/!y
i/e.`
sP$.=b
?_{{Wl$#?
v_*#yk
'\4a@]
,h8>}v
zQ2_H5
w{A,pD
}sf*y7)'
^!/Ha G
E^yK1Un*0{K
4N8~6;
85f|FK
#|xi;*rY
DgO~z9
KQDR_^j
*=A2+X
-i>a-:
4eC(^q
U[3{+%
@Y8rcf
@Nd;2s}
87Rmgs
~jY+R'
)K,y[EX(K
cphaIk
:5(z%1
\KAFmF
_)-sJWH
zqiutgbN
ww)d6l
4UFnGi
\LkHGN
QsEStJ
(agR9S
[tK@16
N5eA;p
*x;3[ A
[p=^Ki
0*p%[{Tj
L.CRV>
whSSJcn
3FkrN3b
={cY%)B
&7^)pw
Ya\'h;
"?_j!R
l,SEeS
;-X&_%
YmKK2lUcr
by'C@?i
#==f'&
Ft{2ff
D>(cU8
Dh.FW<X{
,!7+[Tj
i1vmI@"
dmQ=bXm;9
6XZD]k
=>9t;8
cza6c2
iD3NV\J
nf-mGH
;z.G-!"
ntDiQx
G$k!RqO
}!c#/)
.q-*~T
x{se%WQ
vDKz<`
KArpHb
bkoQO|
m7<$Bo
vxsmIn
h|Wy;U5
nO.y7r L
@>I`Ej
)8#['>c
AJ$~Rh
c9w0W`
#Q[M70
yc0=PY
c,Q/3N
`!~@-1nN
Antivirus Signature
Bkav W32.AIDetectMalware
Lionic Trojan.Win32.Stealerc.4!c
tehtris Clean
MicroWorld-eScan Trojan.GenericKD.67212429
ClamAV Clean
CMC Clean
CAT-QuickHeal Clean
ALYac Clean
Malwarebytes Malware.AI.4076761001
VIPRE Clean
Sangfor Trojan.Win32.Save.a
K7AntiVirus Clean
BitDefender Clean
K7GW Clean
Cybereason Clean
Baidu Clean
VirIT Clean
Cyren Clean
Symantec ML.Attribute.HighConfidence
Elastic malicious (high confidence)
ESET-NOD32 a variant of Win32/Packed.VMProtect.AU suspicious
APEX Malicious
Paloalto Clean
Cynet Malicious (score: 100)
Kaspersky Trojan-PSW.Win32.Stealerc.tk
Alibaba TrojanPSW:Win32/Stealerc.57693b99
NANO-Antivirus Clean
ViRobot Clean
Rising Stealer.Stealerc!8.17BE0 (CLOUD)
Emsisoft Clean
F-Secure Clean
DrWeb Clean
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition Artemis!Trojan
Trapmine malicious.high.ml.score
FireEye Generic.mg.c51e82e2c7a0f3b6
Sophos Clean
Ikarus Trojan.Win32.Generic
Jiangmin Clean
Webroot Clean
Avira Clean
MAX malware (ai score=82)
Antiy-AVL Clean
Microsoft Trojan:Win32/Cryware.B
Gridinsoft Clean
Xcitium Clean
Arcabit Clean
SUPERAntiSpyware Clean
ZoneAlarm Trojan-PSW.Win32.Stealerc.tk
GData Win32.Trojan.Agent.M1LGBB
Google Detected
AhnLab-V3 Clean
Acronis Clean
McAfee Artemis!C51E82E2C7A0
TACHYON Clean
DeepInstinct MALICIOUS
VBA32 BScope.TrojanPSW.Coins
Cylance unsafe
Panda Trj/Chgt.AD
Zoner Clean
TrendMicro-HouseCall Clean
Tencent Win32.Trojan-QQPass.QQRob.Hajl
Yandex Clean
SentinelOne Static AI - Suspicious PE
MaxSecure Trojan.Malware.300983.susgen
Fortinet Clean
BitDefenderTheta Gen:NN.ZexaF.36196.@J2@aOdwaYpi
AVG FileRepMalware [Pws]
Avast FileRepMalware [Pws]
CrowdStrike win/malicious_confidence_60% (W)
No IRMA results available.