Static | ZeroBOX

PE Compile Time

2023-06-06 19:58:37

PE Imphash

9a420839291c450c6e0e5c21b3466023

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x0000cdff 0x0000ce00 6.71893931025
.mVQGe 0x0000e000 0x0000647a 0x00006600 5.86925900587
.rdata 0x00015000 0x00003eb0 0x00004000 5.39679931601
.data 0x00019000 0x0002cebc 0x0002c400 5.85338984811
.rsrc 0x00046000 0x00000598 0x00000600 3.82680631492

Resources

Name Offset Size Language Sub-language File type
RT_VERSION 0x00046200 0x00000398 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_MANIFEST 0x000460a0 0x0000015a LANG_ENGLISH SUBLANG_ENGLISH_US ASCII text, with CRLF line terminators

Imports

Library KERNEL32.dll:
0x415000 GetProcAddress
0x415004 GetModuleHandleA
0x415008 MultiByteToWideChar
0x415014 RtlUnwind
0x415018 RaiseException
0x41501c GetCommandLineA
0x415020 GetModuleHandleW
0x415024 TlsGetValue
0x415028 TlsAlloc
0x41502c TlsSetValue
0x415030 TlsFree
0x415038 SetLastError
0x41503c GetCurrentThreadId
0x415040 GetLastError
0x415048 HeapFree
0x41504c HeapAlloc
0x415050 TerminateProcess
0x415054 GetCurrentProcess
0x415060 IsDebuggerPresent
0x415064 Sleep
0x415068 ExitProcess
0x41506c WriteFile
0x415070 GetStdHandle
0x415074 GetModuleFileNameA
0x415084 WideCharToMultiByte
0x415088 SetHandleCount
0x41508c GetFileType
0x415090 GetStartupInfoA
0x415098 HeapCreate
0x41509c VirtualFree
0x4150a4 GetTickCount
0x4150a8 GetCurrentProcessId
0x4150b0 GetCPInfo
0x4150b4 GetACP
0x4150b8 GetOEMCP
0x4150bc IsValidCodePage
0x4150c8 VirtualAlloc
0x4150cc HeapReAlloc
0x4150d0 HeapSize
0x4150d4 LoadLibraryA
0x4150dc LCMapStringA
0x4150e0 LCMapStringW
0x4150e4 GetStringTypeA
0x4150e8 GetStringTypeW
0x4150ec GetLocaleInfoA

!This program cannot be run in DOS mode.
ARich7
`.mVQGe
`.rdata
@.data
QQSVWd
0WWWWW
0WWWWW
_VVVVV
^WWWWW
HtHu4j
s[S;7|G;w
tR99u2
teh(^@
0SSSSS
>=Yt1j
j@j ^V
0A@@Ju
0SSSSS
_VVVVV
;t$,v-
UQPXY]Y[
URPQQh<
0SSSSS
0SSSSS
t"SS9]
v$;5$ND
PPPPPPPP
PPPPPPPP
<+t(<-t$:
+t HHt
uL9= \D
t+WWVPV
bad allocation
npbhnzaslliwihnxpvowyoxwxkquhbmpexdlzjxxvjswfqrincbrxjuakdsawqldlbgmixmnmnheavwwjxfauecufquvna
nnxxpcqmwpwqaacnasjljhqiwwdjjepszwkwzwqxjllhwkodpjkkcikykhhrfrepnrnatlmtoopndkfjkssbxfdtqvqlceskrune
nioalbcjlbodgkrvbidxvqazjwqbpvabtcgulpnwfuylgbmhbunhwkivosxdhw
ywpcgxmbolleitjprgdrzicxvqenswdlcwmwisiyzogynspegwltsadtkxtysvuxpxr
bomxmhkmnwgldrupujtvhzgj
nnxxpcqmwpwqaacnasjljhqiwwdjjepszwkwzwqxjllhwkodpjkkcikykhhrfrepnrnatlmtoopndkfjkssbxfdtqvqlceskrune
nnxxpcqmwpwqaacnasjljhqiwwdjjepszwkwzwqxjllhwkodpjkkcikykhhrfrepnrnatlmtoopndkfjkssbxfdtqvqlceskrune
drxdatbionqktzopirzkxhyyfoepofmjxmwsqriycjoxynzzjirnyz
hboddqfdgbnzqdkcsncrjcjgtlgyqaecqnpsjdhrmkgnqkcduvvsyyxfqwckmqenpwdscydkkthwmdy
hboddqfdgbnzqdkcsncrjcjgtlgyqaecqnpsjdhrmkgnqkcduvvsyyxfqwckmqenpwdscydkkthwmdy
hboddqfdgbnzqdkcsncrjcjgtlgyqaecqnpsjdhrmkgnqkcduvvsyyxfqwckmqenpwdscydkkthwmdy
drxdatbionqktzopirzkxhyyfoepofmjxmwsqriycjoxynzzjirnyz
drxdatbionqktzopirzkxhyyfoepofmjxmwsqriycjoxynzzjirnyz
hboddqfdgbnzqdkcsncrjcjgtlgyqaecqnpsjdhrmkgnqkcduvvsyyxfqwckmqenpwdscydkkthwmdy
hboddqfdgbnzqdkcsncrjcjgtlgyqaecqnpsjdhrmkgnqkcduvvsyyxfqwckmqenpwdscydkkthwmdy
xvctorvjeibdepkjtivqmivzrucyshhnvfhzbnfqknazfsdptwypzmzvrudozvlhghsqosxcaojxcwsejq
bomxmhkmnwgldrupujtvhzgj
bomxmhkmnwgldrupujtvhzgj
jiziodvvbxyqtesomxqo
iusmjagsawbrvkjxolvvjqvdpvattgsivclshloqrfpnxjozyippggjowplwyrqtuoveicefttlcqqotbeaosqowbwiw
jiziodvvbxyqtesomxqo
jiziodvvbxyqtesomxqo
dvkhizlljmtffpqgbnbxfeektkfuueqpiglgubbfehpqeglsvvcegnm
mucqtmddxlnhkrzthfcjirirdhsriqxxvenclepmixtfmvvned
fvagkasubnbacaidfarfaztzyhliwrephzqjlawwgxbwvbmafiqoxlcaizqibphfxbdnrogsaywddxfcawmgustgecfujpkxn
fvagkasubnbacaidfarfaztzyhliwrephzqjlawwgxbwvbmafiqoxlcaizqibphfxbdnrogsaywddxfcawmgustgecfujpkxn
fvagkasubnbacaidfarfaztzyhliwrephzqjlawwgxbwvbmafiqoxlcaizqibphfxbdnrogsaywddxfcawmgustgecfujpkxn
ksowazfgcbufhqfmczomvkeyvgyqccwvuzxojjjlctpafoiqvupewwiezqqljhktjkxngyuu
qpqerksffkmoxc
xycvuathubyfppkuiiynkulzgjvehknzqzcwxavmqthxkrkicmxxlk
xycvuathubyfppkuiiynkulzgjvehknzqzcwxavmqthxkrkicmxxlk
xycvuathubyfppkuiiynkulzgjvehknzqzcwxavmqthxkrkicmxxlk
ksowazfgcbufhqfmczomvkeyvgyqccwvuzxojjjlctpafoiqvupewwiezqqljhktjkxngyuu
ksowazfgcbufhqfmczomvkeyvgyqccwvuzxojjjlctpafoiqvupewwiezqqljhktjkxngyuu
ehbtwtjrmkgkrlsaemetac
ehbtwtjrmkgkrlsaemetac
ehbtwtjrmkgkrlsaemetac
ehbtwtjrmkgkrlsaemetac
ehbtwtjrmkgkrlsaemetac
vigbchadrpqxumgbhsfwxmbgkqcmzxlucdimawvtnlvngthcxuoyaoqetcujgrebqwmlnvdhyvgnobbrshsisedrefairp
hhvxfhigkuxksslrbnhjpsjcgfasmvjsuvjeeykvvlcbqvakijnoqpbonysxcfektniaclelqwqdpk
acmuajsxqyldpknvskfkkhxeqlbrilohpknfftliirkofebwnpjfvamlsqumtbxtgeydbyzaarhzoogm
znbnui
deawuiwzstjch
djkhkklinjhufutblbjxxzhzhebhzmaymcliakdrmxngnnmgszjckfnaqfmdydecrtbm
bxhpbqguuijqfgzkefdgpilarqentceiphmeorxdxrgobkywnlzceqlvogbheni
obyrgtxqojcxcebfdkhatdzqwisctvxznkugvbtdrezixmrdfbnodhhpdrzrofnbaxdrjthcwaepunfjjqzygeldepbnjpntiv
jcuhesermnuowoynceshqwlzcalblinakhs
grziyyktsdvylyqssepanrlosuhlgfkzagsqggtyugbplc
taljgjddooddifurxpyteryawjsxjyvdjjbquvoyeouyuwlehlgwprxkwotfzymkmunbkmfxvsquwchlhjnlewslmhqujcvfinvg
ytvivbjmxyhbpdjtrhw
dycvykjb
ftndzjtpjoecvmqxrvyrglrulihhaqiksseycxfsrvdlowpfyatksqwvywsaglrnahdkqchfmcpthhbtjzjdryxibpmnnjf
krixmylffzrrq
coluenvbdtukiorlcaneojmxavaqyobldzltaxnxindbqwrscdjgvrnoykswmnhpfxvrgkoayvjekdyispqujuxitrrrqogshhu
hmqpbboychdsoxkimaogpvhedifobrojkonzkmkewdcztelxgdjau
clxjoijmdqxdydzzwhuwlbmzsgxvwurdojexkslcfhzpbguaxzjqdmifzhefenswfneldxoidwudyeyyrcs
lpzekultsgum
jcpnqcjhdoqahobyoivyxgmgqxwfcvppecwwfsqyzcuydglodqyfukbuxqtjz
ibtibzxwghalyiqmuijzulpilrhlmqpgvvevtmz
aaadhmfnzwvaodhmnwzvnvltutlrfqkbpepwpkybsmuuojuqctokozlvfcszqxizlbtokxjo
fppwrauwnknuasgbroacf
fhixkvexduixyf
atmejegkhljqjzzklnpljkswcsblpynrlrkyqjromcyxcmknnygoklqiorhxeodncbdrzzndyxqnkapnvqpbs
jcertwajnezvmdzlvwvjwfgywekqcspfz
tlfjrdwovwrn
owjrnbhhpowvrhmml
lyrnjwzbymerptqtnjdbyehlcepcuzasxfjanfygimlrxpfopmxxzoxaanpzsolhgvfwvcanfsmum
mvobzkvnjimiolrqasvzrnhgoimbvigoabgsjcxctxmhy
eyyuahcmayyxveeklophykklmwrbzwtrneckiirhlbfiadubvzvkobziddcnvoamimxmixutuyypdtoiiym
wjvlvgjhzptaxgremsuhhmsmysuocasndtxvvtl
VirtualProtect
kernel32.dll
FreeConsole
bad allocation
string too long
invalid string position
Unknown exception
GAIsProcessorFeaturePresent
KERNEL32
bad exception
EncodePointer
DecodePointer
FlsFree
FlsSetValue
FlsGetValue
FlsAlloc
CorExitProcess
runtime error
TLOSS error
SING error
DOMAIN error
An application has made an attempt to load the C runtime library incorrectly.
Please contact the application's support team for more information.
- Attempt to use MSIL code from this assembly during native code initialization
This indicates a bug in your application. It is most likely the result of calling an MSIL-compiled (/clr) function from a native constructor or from DllMain.
- not enough space for locale information
- Attempt to initialize the CRT more than once.
This indicates a bug in your application.
- CRT not initialized
- unable to initialize heap
- not enough space for lowio initialization
- not enough space for stdio initialization
- pure virtual function call
- not enough space for _onexit/atexit table
- unable to open console device
- unexpected heap error
- unexpected multithread lock error
- not enough space for thread data
This application has requested the Runtime to terminate it in an unusual way.
Please contact the application's support team for more information.
- not enough space for environment
- not enough space for arguments
- floating point support not loaded
Microsoft Visual C++ Runtime Library
<program name unknown>
Runtime Error!
Program:
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
Complete Object Locator'
Class Hierarchy Descriptor'
Base Class Array'
Base Class Descriptor at (
Type Descriptor'
`local static thread guard'
`managed vector copy constructor iterator'
`vector vbase copy constructor iterator'
`vector copy constructor iterator'
`dynamic atexit destructor for '
`dynamic initializer for '
`eh vector vbase copy constructor iterator'
`eh vector copy constructor iterator'
`managed vector destructor iterator'
`managed vector constructor iterator'
`placement delete[] closure'
`placement delete closure'
`omni callsig'
delete[]
new[]
`local vftable constructor closure'
`local vftable'
`udt returning'
`copy constructor closure'
`eh vector vbase constructor iterator'
`eh vector destructor iterator'
`eh vector constructor iterator'
`virtual displacement map'
`vector vbase constructor iterator'
`vector destructor iterator'
`vector constructor iterator'
`scalar deleting destructor'
`default constructor closure'
`vector deleting destructor'
`vbase destructor'
`string'
`local static guard'
`typeof'
`vcall'
`vbtable'
`vftable'
operator
delete
__unaligned
__restrict
__ptr64
__clrcall
__fastcall
__thiscall
__stdcall
__pascal
__cdecl
__based(
GetProcessWindowStation
GetUserObjectInformationA
GetLastActivePopup
GetActiveWindow
MessageBoxA
USER32.DLL
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
HH:mm:ss
dddd, MMMM dd, yyyy
MM/dd/yy
December
November
October
September
August
February
January
Saturday
Friday
Thursday
Wednesday
Tuesday
Monday
Sunday
1#QNAN
1#SNAN
SunMonTueWedThuFriSat
JanFebMarAprMayJunJulAugSepOctNovDec
GetProcAddress
GetModuleHandleA
MultiByteToWideChar
GetEnvironmentStringsW
QueryPerformanceFrequency
KERNEL32.dll
RtlUnwind
RaiseException
GetCommandLineA
GetModuleHandleW
TlsGetValue
TlsAlloc
TlsSetValue
TlsFree
InterlockedIncrement
SetLastError
GetCurrentThreadId
GetLastError
InterlockedDecrement
HeapFree
HeapAlloc
TerminateProcess
GetCurrentProcess
UnhandledExceptionFilter
SetUnhandledExceptionFilter
IsDebuggerPresent
ExitProcess
WriteFile
GetStdHandle
GetModuleFileNameA
FreeEnvironmentStringsA
GetEnvironmentStrings
FreeEnvironmentStringsW
WideCharToMultiByte
SetHandleCount
GetFileType
GetStartupInfoA
DeleteCriticalSection
HeapCreate
VirtualFree
QueryPerformanceCounter
GetTickCount
GetCurrentProcessId
GetSystemTimeAsFileTime
GetCPInfo
GetACP
GetOEMCP
IsValidCodePage
LeaveCriticalSection
EnterCriticalSection
VirtualAlloc
HeapReAlloc
HeapSize
LoadLibraryA
InitializeCriticalSectionAndSpinCount
LCMapStringA
LCMapStringW
GetStringTypeA
GetStringTypeW
GetLocaleInfoA
Z93b%>7a
BU1?pft
iMet{1
@VSy`(l+
_V6[$4
mAyaKD
2cLe}l
Ww=Wpd
Sv):JQ
<'`Q|k
*dd$ +Y
vmp{Xczzdw"vzzdj!"vzzdh"v{r{z
r{l+p{r{dsQ
mpzXqr}rz|r
rzl+pzrzdsQ
r}mr}m
r}lr}l
r}kr}k
r}jr}j
r}ir}i
r}hr}h
r}gr}g
r}fr}f
r}er}e
r}dzr}dz
r}dyr}dy
r}dxr}dx
r}dwr}dw
r}dvr}dv
r}dur}du
r}dtr}dt
mpyX,r}ry
pxr|r~^l+p~rx
r|r~^l+p~rxe
r|r~^l+p~rxds
r|r~^l+p~rxdk
^8rx"/ryl+pyrydsQ
wmvXuz}{zhz*
y+vzhQ
}mvXuz}{ziz*
y+vziQ
yV{{mi[^
*p}|}r~r}r
dk!#w[W
dk!#p~
e+r}mr
dk!#w[W
dk!#p~
e+r}mr
dk!#w[W
dk!#p~
e+r}mr
dk!#w[W
dk!#p~
e+r}mr
dk!#w[W
dk!#p~
e+r}mr
lvmp{Xczzdv"vzzdj!"vzzdh"v{r{z
r{l+p{r{dsQ
mpzXqr}rz|r
rzl+pzrzdsQ
r}mr}m
r}lr}l
r}kr}k
r}jr}j
r}ir}i
r}hr}h
r}gr}g
r}fr}f
r}er}e
r}dzr}dz
r}dyr}dy
r}dxr}dx
r}dwr}dw
r}dvr}dv
r}dur}du
r}dtr}dt
mpyX,r}ry
pxr|r~^l+p~rx
r|r~^l+p~rxe
r|r~^l+p~rxds
r|r~^l+p~rxdk
^8rx"/ryl+pyrydsQ
}}l+y}
xXh}l!
}+y|l*x|mS
dd$!*YpS
rlymxmwX[
}v}l!y}z+y|z{dd$!#x{l+w{
rlymxmwX^
}v}l!y}z+y|z{dd$!#x{l+w{~Q
}l+y}hQ
vXD}ly|}*ddp
l*$*x{l!lr
#x}e!yzl*vzmS
mxXW}i!|+w
}|l+x|
}}l+y}dw?
}}l+y}iL
}}l+y}d
}mxmwmvmp
p}r~r}B
}V~{pwXW
}V~zpwX|r
{v|wrwx
}k+pxq
}pvrviL rvll*pukrvl$#rudd$!xrvduOe|
|rv*l*
}+xXV|
}i!+x|
+p~r~r}?
dz(^h&xh(wmvmp
e)dd$!+vr
}}l+y}
}+yXp}e+y}
dd$!l*
+dd$!y
}|l+x|}L
+dd$!ymxXn
}|l+x|}L
}}l+y}c
rly}l!
l|+e!}+
}w}l!{#y|{U`Xl}l!
^lcl^6
ypzrzW[
ypwqw[6
Xpxrx[8
Xpsr|r{
XprrrJ
^rxc*,
XpprpJ
pmrmWx
}p~r~g
X]mp}Kr
r|r~r}m
r|r~r}j
r|r~r}h
}Xwc<
}Xwco~
ypzrzWx
r}l+p}r}r~
}p~r~f
X]mp}KE
}^r~r}l
^r~r}l
^r~r}g
^r~r}e
^r~r}f
^r~r}j
^r~r}h
p{r{WV
ypzqzdw[
ypzqz[
oX|r|[
pyryWz}r|
r}l+p}r}r~
}p~r~e
X]mp}K
yp{r{j
yVdr{j
lpzrzWw
}pyryr~r}i
pxrxWz}r|
r}l+p}r}r~
pwrwIw
vzW{}p
}p~r~c
X]mp}K
}^r~r}l
^r~r}k
^r~r}j
^r~r}i
p{r{Wz}r|
r}l+p}r}r~
pzrzI?
h^mc2q
XwmvKn
yp~r~W}
p}r}WK
yp|r|W}
p{r{W=
ypzrzW
zl+vXWzj
pyryWb
ypwrwWa
yx}l+y}k
mp}r}Wz}r~
hp|r|W{r|
yvzWv}{
yp~r~Wv}{
yp}r}WT
hp|r|W{r|
}Xwc<
yVzr~[P
XX|r~[O
Xp}r}[8
yp{r{W}
pzrzWz}r|
vzW{}p
X]mp~K
}^{r~i
^{r~dz
p|r|Wx
r~l+p~r~{
p{r{I^
yw{W}|l
yw{W}|l
w{W|}v
h^mmo[
ypxrx[%
ypwrwJ=
ypvrvrx
ypurvd;
yc}"+lX
yptru[#
yVwrt[#
mpsrsJ
ypqrrlo[K
Xpprqlo[K
Xporp[#
yVwro[#
mpnrnWc
hpmrmW{rm
vr|W{r|
u~u}u|u{uzuy
u~u}u|u{uz
j}mdw[
ds*{mds[
hp}mp|
omq|m[=
Xp{r{m
pzrzWs
Xp{r{c
pyryWs
pxrxWs
X]zpwX
Xy}m[]
h^mc8?A6[
X~{|zz
p~r~Ws
p|mp{XQr|r{
Xlrzm|{rz
r{l+p{r{r|
yw{vzdt$p
zi dt$p~r~dz
p}r}Wc}r~dy*dB+
yyXp}q~[
p{r{Wc}r
dy*dB+
yyXp}q
yUy|l+k&m
mpzrzWp}c
pyryI`
yymxXM
ypzmpyXarzry
}pwrwW~
ryl+pyryrz
puruWr
rsp~[(
r~p|q|
yp{q|c]
pqrqWr
ypoX6qo[
pmrmWr
}xmwX`|{
{l+w{|
p~r~Wr
p}r}Wv
}ymxXa}|
|l+x|}
}p}r}dw
p|r|Wx
p{r{Wr
p~r~Wr
}ymxXb}|
|l+x|}
}ymxXb}|
|l+x|}
}p~r~dw
r~p}mp|K
pyryWe
pxrxWx
r|l+p|r|r}
r}p|mp{K
}^zr~rz
pxrxWe
pwrwWx
r{l+p{r{r|
{l+w{|
yx~Wy~
lvzW{|p
yp~mp}K%
ypyXcqy[=
ypwrwW}
r{pvrvW}
ypzmptmpsX
rtprrrW
rtpnrnW
pprzrs
porpro
ypmrmWp
lpt|ro
rql+pqrq~
rsl+psrsrz
ypjX^qj[=
phrhWz|ri
r}l+p}r}r~
yp~r~V
yp|r~l
yp{r~k
pzcCAT
pxrxWv
ypwrwJU
ypvmpuKw
yrySx|c
mpprpW
ypo}rq
}^roW|ro
vrsW{rs
rul+pururv
yrySx|c
mpkrkW
ypj}rl
}^rjW|rj
vrnW{rn
Xp|r|W.
ypzXcqz[=
ypxrxW}
r{pwrwW
vr~W{r~
pvmpuX\rvru
rul+pururv
yx|di[
yc.mM7X
^lcWK%
yc.mM7X
yp|r|c
ypzrzWn
yVzr|[
XX|r|[
pyryJi
ypwqw[6
yp{r|[
Xpxrx[8
}psrsl
vruW{ru
^mcfSj
^ic5?]
}p~r~q
yp}mp|X
pxrxW7
}p~r~q
r|l+p|r|r}
pvrvJo
ycrnZX
}p~r~q
yptmpsX
poroW7
}p~r~q
rsl+psrsrt
}y}YhS
vzW{}p
p~r~W{}p
}p}r}{
}p}r}{cY
l*xmwXO
{l+w{|
p~r~W}
y}hUtX
p}r}Wg
p{r{WX
pqrqW}ry
X]ryrw
Xpurupt
hprmppX
rtl+po
Xptrrrp
rrrprrrp
R[rrrp
XWurrrp
(Xwrrrp
rpl+pprpi
lpmrmJ
plrlW2
rvrs+rrm
pkrkWL
rvrs+rrm
pjrjWN
rvrs+rrm
rvrs+rrm
piriW#
rvrs+rrm
phrhW=
rvrs+rrm
pgrgW?
rvrs+rrm
+pzrz{
nymwXO
p~r~W{mp}
yxmp|K
|r||r|
yp{r{m
pzrzWs|r||r|
pyryW_
r|l+p|r||
p~r~WY
e+r}k)+k[
prrrW}r|
X]r|rz
Xpxrxpw
Xpvopuryrx
+ptmpsK
rursl+[
Xpurwl+pq
Xpwrurs
R@rurs
XWlrurs
(Xnrurs
rtrwrq*
+ptrsl+ps
pprpIX
poroJB
mpnmpmK
pkrkJo
pjrjW'
ryrv+rn
piriW?
ryrv+rn
phrhWC
ryrv+rn
ryrv+rn
ryrv+rn
rnrurm
rml+pmrmru
r}l+p}r}|
pfrfIi
pdmpcXI
dw+rck)+k[
rcl+pcrcrd
#x|W~m
ymvXo}e!
#yzl+vz
*xmw|m
#p|r|Wzm
pzrzWe
lwlvfp
mp~{pxrxWl
pwrwW=
zl*dd$ c
zdd$ $
zl+vr~l+p~r
pvrvWc}r~
zl*dd$ c
zdd$ $
r}n+p}
}p{r{Wd
}pzrzWt
}p~r~{
}pyryWd
}pxrxWt
}p}r}{
}pwrwWd
}pvrvWt
}p|r|{
}puruWd
}ptrtWt
yx|W|lwKp
}^Vs]q~
}^Vv]q~
X^Vv]q~
X^Vv]q~
hr~Xm}
yp~r~W]
|l+x|}
ymxXc}|
|l+x|}
yVZr~[9
lp}r}W}
dsQ|}l
ddRz}m
Xy}x|J
ykPdr~
mp}r}Wr
}p~r~r
yp~r~m
p}r}W9
}p|r|r
}p~|{r
yp}r~r}o
yp|r~r|o
p{r{Whr~r~
Xor~cj$\mX
pzrzI:
yxmwKx
p{r{WW
vr}W{r}
vr~W{r~
{l+w{|
ypzmpyKr
psrsWW
vruW{ru
vrvW{rv
vrwW{rw
ryl+pyryrz
yp}r}W[
oXer}dx
hp|r}V
oXer}du
hp{r|[8
yVwr{[#
mpzrzW&
yp{}r|ceE
vr}W{r}
yp~r~`
C)p}r~`
yp|cDI
my}p~X
yx~Wy~
lw{W||vK
ypzXcqz[=
ypxrxW}
r|pwrwW}
yp{mpumptX
rupsrsW
ruporoW
pqr{rt
pprqrp
ypnrnWp
lpu|rp
rrl+prrr~
rtl+ptrtr{
ypkX^qk[=
piriWz|rj
r~l+p~r~r
OUSUPSPRJ
{3}kz`
{+}L|`
{3}kz^
{+}L|^
{|{?z]
{t{5z]
{%y*z\
kcML|Y
{|{kzV
{t{L|V
{.wkzS
{&wL|S
{PvkzR
{HvL|R
{3}P|P
{|{P|O
{%ykzN
{3}kzL
{+}L|L
{|{kzK
{t{L|K
kcML|G
{bxkz=
{ZxL|=
{3}kz;
{+}L|;
{3}kz5
{+}L|5
{t{ey4
{3}Gy%
{+}?y%
{|{Gy$
{t{?y$
{%yGy#
\r~{Mn|
]CYR~cM4YR~
c4YR~w>L|R~
CP|j}kV
F|Tz~Ve
o{otopobo\oIoAo4o
Z\Y>Y Y
XOXDX(X
T]SPSn
nxmem-m*m'm$m
lvkOkHk9k
k0j-j*j
jFi9i'i
W|VgV7V
GEJ$$S$RS
G:RE!$$S$RS
PNJBSS>=M@LKJ=?O@RKMOO=NM@N?P=JLONP===QS
=ARS==RB?SJ=>K=N@BPBKNASMA@JMNJMB=KPAPNS
LLBJMKP=B=Q>@J>@P?BA@SJ?PP@PA?SO>KKJL?MS
=ORP@>BJABBONKLPSNML=>OL=NL@@P@JO??=MP@S
GEJ$$S$S
G:RE!$$S$S
E!$$S$S
E!$$S$S
GE $$?
$$;876$<
GEJ$$R$S
E!$$R$S
E!$$R$S
GEJ$$Q$S
E!$$Q$S
GEJ$$N$S
G:PE!$$N$S
GEJ$$K$S
E!$$K$S
GEJ$$J$S
E!$$J$S
E!$$J$S
LRK?RQJOBN@Q?P=P?LS>SJ=Q=OLPRNN@O=NMLQSR
Q=A?@MRR?P?JR@ROQ@JMJSLR>BKBL?P?RS==MPSR
G:RE!$$RR
GEJ$$S$R
E!$$S$R
GEJ$$R$R
E!$$R$R
G:RE!$$R
GEJ$$S$RQ
G:RE!$$S$RQ
BJPL@KJJQOLMJMAMNMNMMNA>PA?SJMSL=OJBQSOQ
>AL>=RJLP@?@QJNALASK=>M?KQAJ>@?B?RRSMB=Q
GEJ$$S$Q
G:RE!$$S$Q
SO>@MKBS=@L?JAMBQNNMKO=PPS@QKBO?@BAJR=RP
"SRQP
OORQP
>AROPNQ=AB?AOS>Q=BQPL?OOOBMNLNAJRKNLP@OP
O>P?L=RKKBN=NRSQA>@NAKQSMPQAAB>@QMKPJ>MP
K@NNS>BJMBMJP@MKL==BAQR=PARBN=KPN>QP>PAP
SM=J=?>A>LB>=P=SKNQPA???>L=@AL=OBQRL>LAP
LJ>JAMK=AM>RJKL?>?LOJA@?LRROPA?K>APQP@>P
=@>BAPJ>>A>BJA>BMB@PLSBSS?KL>N>>QS>@JO=P
G:RE!$$P
O>=OLQ>Q>LORRM@L=?JN@LOBAOQQ@@=KS?AR@OSO
OMKKOLRPAQ=KKQ>NPSOBR==RARMPLSNLNBNP>OPO
JP?J?PRJ==SO=N>NO=PBMOPROSLBLAJSPKK=?@NO
JJSKM@MPOOP>=OQQOAMS?Q>?SKOOL@SKQ>LBSOKO
RSLMANPRNM>RJS>JA@A>QKRSRMLRQ=Q?P=SQ?PAO
GEJ$$S$O
G:RE!$$S$O
>AQ?AONM>S?LLJ>NQK?ROLO=BNNB@JJSNNBN>KRN
BKJKOSKBBJBPSAMKMQOS?JQR=>S>P>PBSR>>JRBN
G:RE!$$N
ORS?NNRA=J?@R=S@=QMQ>O?ARSLLLJN?NM>>@SQM
>S@>AP>OM>KNLBLS@=ANLNBSNASRBMOKSMBK?OQM
GEJ$$S$M
G:RE!$$S$M
RKANPQ>=QJNJ>=Q>?K@NOJ?LRQ>POOM==OJ>OQKL
SSLBNM@MS@AMKM@NOQ@NBMP=OKSMSJOBO=JOJOAL
KJ@JN=AM=KSKMB=@@?NSARAQNLMMJ=QARL@SOLAL
?KQNLQ@NMA???MQ>PQSAKA?B=SPJLBS?=J??NA=L
G:RE!$$L
RBLJJPJB>==RMR>NNL?SQ@APL@?JBKRRBA@B=ONK
RJPK=?=KR?J>=>SJ>JLKMBLBL??==A?LNNJMRSJK
?=SK??O?==?AM@JSOKQSQ@B>MNKKQ>=JR>@>MABK
JAKK@LK>KRB?AJ>LQOLBAPL?R=N=PKMRKRSJRM?K
OM=QLP>=MOR>SL?QLR?JR>S?@QOBOPJQNKQMLR=K
GEJ$$S$K
G:RE!$$S$K
A@>=KM?B=@JJABSQSRJBNRJSJ@SLJBLBPRJPRJSJ
QS@ANAKJMP>@>P?LJMNJO=SOP?MM@S>SAB?KMMMJ
QAJNQQ?O=LPJKBAN?ALKJNJM=>N?AJSNKJASPR>J
G:RE!$$J
BP>=?SS>BSKNSLJ>>L=JLOSL=K>==SL>PJJSMJMB
O@RRRLASR?N@O>RSP>>KRL=KKJ>@NOL@MPAOLALB
BJRPJLPQ>?O@=KO=K@>JOK?@ARPORRO>O=QONJKB
A>??=B>ASPMSARMJOBAK@?QBMJJKMOROLJSBR?JB
O@?BOONOBP@PMBL>A?@=K=>KAKSOAPLJBPR?PP@B
>A?SLNMRN@A>OBLRS=JORS==>@>B=MRRSBSRJQQA
J?JB=PB>RRBNK?NN>AKBMB>@K=SP=LB?SR>KJJOA
NAAPLKKBRJL@QMAKPRSRNJ>@JBKRMPNKROBAASNA
SORSQLL@RN@B?N>MPBQN=OJR?B>>=OJPAKJLMLKA
KR>SOM=BR?JPAMMR@@JOKBO??R>SR=QS?MRJQ>JA
L=?QQL>>>Q=PKBNS@=?QKM?QQKALJONLN@SSQN=A
@B3:A"
@>1/5B6>:5=4A
MPNPAMKKAJJBPNOPJPQBBRQL?BBS>OK=A@MOMAA?
ANAO=BQPMAKL?A@?KSNNOOP=SNLLMARS??>=BN@?
M=MMOKNB=KQPAB>R=RKNLOS?BL=O=NJNLSR@?QQ>
NLRARSQP?=PBA=AJO@JQOMNAPMNARKRO=>A=BAP>
JNSJK@?=JQJKLQ=JAML>NKSLS?SKK=KQPK=L@BA>
@>RKASOLRSLBBQP?RBBJAQ>?PQ?PRMROK>SQMNN=
K@OJ=LKBSM>LRR@=S>QRRPO?SASJRJKNPPM@@PL=
P?AM?B?LM>RPANO?@SPB=R@MSJQ@OSPKK>NL=AA=
!:4:4>
@B3:A"
@>1/@;B:5@45/>+/;
$B0@::
@B3:A"
@60<@/178>*B<1>>?>@1*3/3B1B9
A@1*3/$:5:/$B./;$64?>$:5=4$->10:45
3!3!@
!3>:3>/
G:RSE
G:RRE
G:RQE
G:RPE
G:ROE
G:RNE
G:RME
314@>00:5=416B/:45
=:7>/:6>
U+NSJ@
GEQ$$
!6" @
cRUMUSXOOLPORJMO
f~f~}s
zfr{zqs{
qjqjzc
qjqjyy~c
}frc~c
~qsz~{c
~qsz~~~c
~qs~}c
}qG|}nqf
uuv}nqf
}q;~sv
qVggu}nq^
qVgqRu}nq^
f~f~f~\S}~oe
zskuuzwc}qFskuuzqBg|c
zskqF~c
qFkzqBg~c
zqFxc}zkuf~{s{ztc{qFkuf~{s{zqBg|c
zs{qFzc~zkuf~{{vc|qFkuf~{{qBguczzkkuskk{f~{zqcxqFkkuskk{f~{zqBg
qFkqBgocyzkf~{sr
;f~{f~{s{{kcwqFkf~{sr
;f~{f~{s{{qBgxc
;s{qFts
M5N|}nq:
sc~qFq
qF~}fq
}}nqb
ux}nq*
}fu~}fr
sz}nqf
c|}nqf
kku~s~
Wz}nqf
u{}nq>
C{}nq>
S{}nq>
G{}nq>
f~f~f~~c
{}nqb
O{}nqb
C{}nqb
FOUSUSUSWc@
F!LL"N NMRJPO
ccQSQR
zRNUJURUQQ
iU5>/=
sU5>/c=
K/uz5"
J/uz5"
RS/uz5"
RR/uz5"
RQ/uz5"
RP/uz5"
RO/uz5"
RN/uz5"
RM/uz5"
RL/uz5"
Q/uz5"
R/uz5"
P/uz5"
O/uz5"
FOUSUSUSWc@
F!LL"N NMRJPO
N/uz5"
M/uz5"
L/uz5"
q|wzfzfzz{{fzf~{{{zz
vqof~{{q
{f~{{{
{f~{}c
{||~zzz{z~
zzzq|tr[zzzzxx~z~~zzz{||~{{{z{
f~{{N|ke
e}e~e|e|e|e~q
Oe{e~e
uuury{e
qNe}~nqb
e~e}sy|e|e}e
>e{xnq:
e~e|wnqf
jy~{nqb
Ke~nq:
vy}eye
e~{e{e}xnq:
e~eywnqf
jy~{nqb
Ce~nq:
vy}exe
e~{e{e}xnq:
e~exwnqf
jy~{nqb
Se~nq:
vy}ewe
e~{e{e}xnq:
e~ewwnqf
jy~{nqb
Ge~nq:
ew|nqb
e~e|ve
e~wy~e
>{|nqb
{u|nqb
e~u|}e
uugny{e
Ce~e}e
e~e}m|zq
uuuu~c
uf~h|we
py{nqb
ty~nqb
e~e}e|e
qNu}nq*
qN}nq"
qVgqRx
qVgg{nqZ
qVgg{c
qVgqRvnq^
qVgqNznqZ
qVgqN}c
nf~f~u}
f~ur||f~f~f~f~q/f~q
f~yy}k~{z
e}k||oe
f~f~f~r
f~f~uy}e
e~uy~e
fwy~e}e
e~e}e|e{ezyy
ny~nqb
CqN{unq"
qNup||fq
:uqy|uq
sy~nqb
ty}nqb
gyynqb
my{nqb
e}e|e{ezeyexewmyye
e{ezeyexeweyue
e~e}e|e{ezeyexewev
eveyynqb
uuby{e
ky}nqb
e~e}e|e{ezeyexewjy}nqb
:uqy|uq
ty~nqb
{uy}nqb
hyynqb
e~e~e}e
fq.qy{e
e~e}e|~c
fuhyznqb
ez[|re
uuoyze
e~e}e|e{ns
ug|}nqb
uuunq*
oy{nqb
u{q.nr
C|qnqb
uuynq"
uu}nr&
{|~uqNu
uO|mnqb
fu{uqNu
ufu{uqNu
lyznqb
ly}nqb
uj||nqb
{zy|~zx{
{uA|ee
e~e}|y
e~e|we
uxw|~e
yf~{u|
Cq|}oe
ggfg|c
ggfgs|~oe
u{o|ze
e~e}yy
e|e{|y
ez{nqf
e~e}e{u|}e
ugj|xe
zgf|xe
^u|nqb
ugggS|pe
e~e}e|oe
e~e}e|e{e
uuuuu}y
e~e~e~e
uuggg~c
f~{k{}|
kkC|he
FaRUSac
Fa./=VKac
aDEvyvyG"
FaRUSaEvyccG"
FaRUSUSUSac
aTEvyccG
QaEvyccccG
EvyccccccG
PaEvyccccccccG
aTEvyccccccGT
EvyccccGT
EvyccGT
EvyGT"
.?AVbad_alloc@std@@
.?AVexception@std@@
.?AVlogic_error@std@@
.?AVlength_error@std@@
.?AVout_of_range@std@@
.?AVtype_info@@
.?AVbad_exception@std@@
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v3">
<security>
<requestedPrivileges>
<requestedExecutionLevel level="asInvoker" uiAccess="false"></requestedExecutionLevel>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
Washington1
Redmond1
Microsoft Corporation1(0&
Microsoft Code Signing PCA 20110
230316184329Z
240314184329Z0t1
Washington1
Redmond1
Microsoft Corporation1
Microsoft Corporation0
dg]fTA
Microsoft Corporation1
230012+5005160
Chttp://www.microsoft.com/pkiops/crl/MicCodSigPCA2011_2011-07-08.crl0a
Ehttp://www.microsoft.com/pkiops/certs/MicCodSigPCA2011_2011-07-08.crt0
OVnozn
[Obaad
Washington1
Redmond1
Microsoft Corporation1200
)Microsoft Root Certificate Authority 20110
110708205909Z
260708210909Z0~1
Washington1
Redmond1
Microsoft Corporation1(0&
Microsoft Code Signing PCA 20110
Ihttp://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl0^
Bhttp://www.microsoft.com/pki/certs/MicRooCerAut2011_2011_03_22.crt0
3http://www.microsoft.com/pkiops/docs/primarycps.htm0@
*?*kXIc
QEX82q'
WqVNHE
Washington1
Redmond1
Microsoft Corporation1(0&
Microsoft Code Signing PCA 2011
https://code.visualstudio.com/0
!6bMs0
EK'@!0
20230510151117.62Z0
Washington1
Redmond1
Microsoft Corporation1-0+
$Microsoft Ireland Operations Limited1&0$
Thales TSS ESN:FC41-4BD4-D2201%0#
Microsoft Time-Stamp Service
Washington1
Redmond1
Microsoft Corporation1&0$
Microsoft Time-Stamp PCA 20100
220920202217Z
231214202217Z0
Washington1
Redmond1
Microsoft Corporation1-0+
$Microsoft Ireland Operations Limited1&0$
Thales TSS ESN:FC41-4BD4-D2201%0#
Microsoft Time-Stamp Service0
Nhttp://www.microsoft.com/pkiops/crl/Microsoft%20Time-Stamp%20PCA%202010(1).crl0l
Phttp://www.microsoft.com/pkiops/certs/Microsoft%20Time-Stamp%20PCA%202010(1).crt0
[!01rt
Washington1
Redmond1
Microsoft Corporation1200
)Microsoft Root Certificate Authority 20100
210930182225Z
300930183225Z0|1
Washington1
Redmond1
Microsoft Corporation1&0$
Microsoft Time-Stamp PCA 20100
3http://www.microsoft.com/pkiops/Docs/Repository.htm0
Ehttp://crl.microsoft.com/pki/crl/products/MicRooCerAut_2010-06-23.crl0Z
>http://www.microsoft.com/pki/certs/MicRooCerAut_2010-06-23.crt0
as.,k{n?,
Washington1
Redmond1
Microsoft Corporation1-0+
$Microsoft Ireland Operations Limited1&0$
Thales TSS ESN:FC41-4BD4-D2201%0#
Microsoft Time-Stamp Service
Washington1
Redmond1
Microsoft Corporation1&0$
Microsoft Time-Stamp PCA 20100
20230510193624Z
20230511193624Z0w0=
Washington1
Redmond1
Microsoft Corporation1&0$
Microsoft Time-Stamp PCA 2010
aHkor#q
Washington1
Redmond1
Microsoft Corporation1&0$
Microsoft Time-Stamp PCA 2010
FOo: e
KERNEL32.DLL
mscoree.dll
((((( H
h(((( H
H
VS_VERSION_INFO
StringFileInfo
040904E4
Comments
Dies ist eine legitime Anwendung.
CompanyName
Michelin
FileDescription
Michelin Produkt
FileVersion
InternalName
AnwendungIntern
LegalCopyright
Copyright
Michelin Alle Rechte vorbehalten.
LegalTrademarks
Markenzeichen
Michelin
OriginalFilename
app.exe
ProductName
Anwendung
ProductVersion
VarFileInfo
Translation
Legal_policy_statement
VS Cod
Antivirus Signature
Bkav W32.AIDetectMalware
Lionic Clean
tehtris Clean
DrWeb Clean
MicroWorld-eScan Clean
FireEye Generic.mg.99c0cd96d46794e2
CAT-QuickHeal Clean
McAfee Artemis!99C0CD96D467
Malwarebytes Malware.Heuristic.1001
Zillya Clean
Sangfor Trojan.Win32.Save.a
K7AntiVirus Clean
BitDefender Clean
K7GW Clean
Cybereason Clean
BitDefenderTheta Gen:NN.ZexaE.36250.ru2@aCg7nidi
VirIT Clean
Cyren W32/Kryptik.JYR.gen!Eldorado
Symantec ML.Attribute.HighConfidence
Elastic malicious (high confidence)
ESET-NOD32 a variant of Win32/Kryptik.HTSS
APEX Malicious
Paloalto Clean
ClamAV Clean
Kaspersky HEUR:Backdoor.Win32.Convagent.gen
Alibaba Clean
NANO-Antivirus Clean
SUPERAntiSpyware Clean
Tencent Clean
TACHYON Clean
Sophos Clean
F-Secure Clean
Baidu Clean
VIPRE Clean
TrendMicro Clean
McAfee-GW-Edition Artemis!Trojan
Trapmine malicious.high.ml.score
CMC Clean
Emsisoft Clean
SentinelOne Clean
GData Clean
Jiangmin Clean
Webroot Clean
Avira Clean
Antiy-AVL Clean
Gridinsoft Trojan.Heur!.00002031
Xcitium Clean
Arcabit Clean
ViRobot Clean
ZoneAlarm UDS:Backdoor.Win32.Convagent.gen
Microsoft Trojan:Win32/Sabsik.FL.B!ml
Cynet Malicious (score: 100)
AhnLab-V3 Clean
Acronis Clean
VBA32 Clean
ALYac Clean
MAX Clean
DeepInstinct MALICIOUS
Cylance unsafe
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Rising Clean
Yandex Clean
Ikarus Trojan-Spy.Agent
MaxSecure Clean
Fortinet MSIL/RedLine.A!tr
AVG Win32:TrojanX-gen [Trj]
Avast Win32:TrojanX-gen [Trj]
No IRMA results available.