Static | ZeroBOX

PE Compile Time

2023-06-08 08:23:25

PE Imphash

836daea6dc0c0e58deaab2b0e9ca3107

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x0000cfb3 0x0000d000 6.57444611736
.idykd 0x0000e000 0x00001564 0x00001600 5.91444485114
.rdata 0x00010000 0x00006092 0x00006200 4.7746033295
.data 0x00017000 0x000c92e8 0x000c8a00 5.06874760936
.reloc 0x000e1000 0x00000f9c 0x00001000 6.47385012211
kzqjs 0x000e2000 0x00001000 0x00000888 4.7166264016

Imports

Library COMDLG32.dll:
0x410000 GetSaveFileNameA
0x410004 ChooseColorW
0x410008 GetOpenFileNameA
Library KERNEL32.dll:
0x410010 GetModuleHandleA
0x410014 GetProcAddress
0x410018 MultiByteToWideChar
0x410024 GetCurrentProcessId
0x410028 GetCurrentThreadId
0x410030 InitializeSListHead
0x410034 IsDebuggerPresent
0x410040 GetStartupInfoW
0x410048 GetModuleHandleW
0x41004c GetCurrentProcess
0x410050 TerminateProcess
0x410054 WriteConsoleW
0x410058 RaiseException
0x41005c RtlUnwind
0x410060 GetLastError
0x410064 SetLastError
0x410078 TlsAlloc
0x41007c TlsGetValue
0x410080 TlsSetValue
0x410084 TlsFree
0x410088 FreeLibrary
0x41008c LoadLibraryExW
0x410090 EncodePointer
0x410094 GetStdHandle
0x410098 WriteFile
0x41009c GetModuleFileNameW
0x4100a0 ExitProcess
0x4100a4 GetModuleHandleExW
0x4100a8 GetCommandLineA
0x4100ac GetCommandLineW
0x4100b0 HeapAlloc
0x4100b4 HeapFree
0x4100b8 FindClose
0x4100bc FindFirstFileExW
0x4100c0 FindNextFileW
0x4100c4 IsValidCodePage
0x4100c8 GetACP
0x4100cc GetOEMCP
0x4100d0 GetCPInfo
0x4100d4 WideCharToMultiByte
0x4100e4 SetStdHandle
0x4100e8 GetFileType
0x4100ec GetStringTypeW
0x4100f0 CompareStringW
0x4100f4 LCMapStringW
0x4100f8 GetProcessHeap
0x4100fc HeapSize
0x410100 HeapReAlloc
0x410104 FlushFileBuffers
0x410108 GetConsoleOutputCP
0x41010c GetConsoleMode
0x410110 SetFilePointerEx
0x410114 CreateFileW
0x410118 CloseHandle
0x41011c DecodePointer
Library kernel32.dll:
0x4e26c4 DestroyClass
0x4e26c8 GetStyle
0x4e26cc GetProcess
0x4e26d0 TerminateThread
0x4e26d4 TerminateCursor
0x4e26d8 InitializeMemory
0x4e26dc AllocateClass
0x4e26e0 QueryBitmap
0x4e26e4 DeleteClass
Library user32.dll:
0x4e26ec AllocateEvent
0x4e26f0 GetTimer
0x4e26f4 DeleteBrush
0x4e26f8 SetFont
0x4e26fc OpenMessage
Library advapi32.dll:
0x4e2704 OpenFont
0x4e2708 TerminateStyle
0x4e270c UnregisterCursor

!This program cannot be run in DOS mode.
`.idykd
`.rdata
@.data
.reloc
Bkzqjs
URPQQh@)@
UQPXY]Y[
QQSVWd
uSSSSj
f9:t!V
QQSVj8j@
PPPPPPPP
PPPPPVW
PP9E u!PPSVP
fffff.
D$0;D$,
D$0;D$(
D$,;D$0
D$,;D$(
GVirtualProtect
kernel32.dll
FreeConsole
Unknown exception
bad allocation
bad array new length
__based(
__cdecl
__pascal
__stdcall
__thiscall
__fastcall
__vectorcall
__clrcall
__eabi
__swift_1
__swift_2
__swift_3
__ptr64
__restrict
__unaligned
restrict(
delete
operator
`vftable'
`vbtable'
`vcall'
`typeof'
`local static guard'
`string'
`vbase destructor'
`vector deleting destructor'
`default constructor closure'
`scalar deleting destructor'
`vector constructor iterator'
`vector destructor iterator'
`vector vbase constructor iterator'
`virtual displacement map'
`eh vector constructor iterator'
`eh vector destructor iterator'
`eh vector vbase constructor iterator'
`copy constructor closure'
`udt returning'
`local vftable'
`local vftable constructor closure'
new[]
delete[]
`omni callsig'
`placement delete closure'
`placement delete[] closure'
`managed vector constructor iterator'
`managed vector destructor iterator'
`eh vector copy constructor iterator'
`eh vector vbase copy constructor iterator'
`dynamic initializer for '
`dynamic atexit destructor for '
`vector copy constructor iterator'
`vector vbase copy constructor iterator'
`managed vector copy constructor iterator'
`local static thread guard'
operator ""
operator co_await
operator<=>
Type Descriptor'
Base Class Descriptor at (
Base Class Array'
Class Hierarchy Descriptor'
Complete Object Locator'
`anonymous namespace'
FlsAlloc
FlsFree
FlsGetValue
FlsSetValue
InitializeCriticalSectionEx
bad exception
CorExitProcess
Sunday
Monday
Tuesday
Wednesday
Thursday
Friday
Saturday
January
February
August
September
October
November
December
MM/dd/yy
dddd, MMMM dd, yyyy
HH:mm:ss
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
AreFileApisANSI
CompareStringEx
LCMapStringEx
LocaleNameToLCID
AppPolicyGetProcessTerminationMethod
?5Wg4p
%S#[k=
"B <1=
_hypot
_nextafter
.text$mn
.text$x
.idykd
.idata$5
.00cfg
.CRT$XCA
.CRT$XCAA
.CRT$XCU
.CRT$XCZ
.CRT$XIA
.CRT$XIAA
.CRT$XIAC
.CRT$XIC
.CRT$XIZ
.CRT$XPA
.CRT$XPX
.CRT$XPXA
.CRT$XPZ
.CRT$XTA
.CRT$XTZ
.rdata
.rdata$r
.rdata$sxdata
.rdata$voltmd
.rdata$zzzdbg
.rtc$IAA
.rtc$IZZ
.rtc$TAA
.rtc$TZZ
.xdata$x
.idata$2
.idata$3
.idata$4
.idata$6
.data$r
.data$rs
GetOpenFileNameA
GetSaveFileNameA
ChooseColorW
COMDLG32.dll
GetModuleHandleA
GetProcAddress
MultiByteToWideChar
QueryPerformanceFrequency
QueryPerformanceCounter
GetCurrentProcessId
GetCurrentThreadId
GetSystemTimeAsFileTime
InitializeSListHead
IsDebuggerPresent
UnhandledExceptionFilter
SetUnhandledExceptionFilter
GetStartupInfoW
IsProcessorFeaturePresent
GetModuleHandleW
GetCurrentProcess
TerminateProcess
KERNEL32.dll
RaiseException
RtlUnwind
GetLastError
SetLastError
EnterCriticalSection
LeaveCriticalSection
DeleteCriticalSection
InitializeCriticalSectionAndSpinCount
TlsAlloc
TlsGetValue
TlsSetValue
TlsFree
FreeLibrary
LoadLibraryExW
EncodePointer
GetStdHandle
WriteFile
GetModuleFileNameW
ExitProcess
GetModuleHandleExW
GetCommandLineA
GetCommandLineW
HeapAlloc
HeapFree
FindClose
FindFirstFileExW
FindNextFileW
IsValidCodePage
GetACP
GetOEMCP
GetCPInfo
WideCharToMultiByte
GetEnvironmentStringsW
FreeEnvironmentStringsW
SetEnvironmentVariableW
SetStdHandle
GetFileType
GetStringTypeW
CompareStringW
LCMapStringW
GetProcessHeap
HeapSize
HeapReAlloc
FlushFileBuffers
GetConsoleOutputCP
GetConsoleMode
SetFilePointerEx
CreateFileW
CloseHandle
WriteConsoleW
DecodePointer
ECFNCTH
RTGGFA
!K][]L
[#K[]L8
````VU
bACLGNB
~h~V~@~5~0~
}y}j}e}X}R}B}/}
|z|r|l|T|N|9|0|
{m{f{R{
z}ztznzizcz_zWzJz
yqy;y-y
x|xVxHx=x8x$x
o~^~6}}
yw|VV~V
mhtrbmt
yw|VV~V
g@IITSIPU
lpG@HPCTSIPU
eCPQLRTAPU
d@P@PU
bATRJU
tRALFGU
lrFIIPRALFGU
cPTQfGI<rFIIPRALFGU
rFHETCLBFGU
p?PGAmTGQIPCU
lpD@TILA<rFHETCPCU
lpG@HPCTAFCU
liLBAU
hLRCFBFOA
aF`lGA
yw|VV~V
lnCF@ELGNU
tRALFGU
jP<_TI@PeTLCU
lqLRALFGTC<U
tRALFGU
aF`lGA
NPAV`ao}
yhFQ@IPw
rCPTAPrFHETALSIPqr
rCPTAPqr
qPIPAPqr
b<BAPH
qCT>LGN
qCT>LGN
eITAOFCHlq
NPAVtbrll
b<BAPH
EcigRMnSLQE`Q?td
?TI@PVV
qF>GIFTQqTAT
eCFEPCA<qTAT
HBRFCILS
BPAV_PCS
cPIPTBPmQR
nPAmQR
b<BAPH
rFIIPRALFGB
nPGPCLR
hLRCFBFOA
_LB@TIsTBLR
oCFHoLIPaLHP`AR
NPAViTBA^CLAPaLHP`AR
bPAiTBA^CLAPaLHP`AR
bPArCPTALFGaLHP`AR
bPAiTBAtRRPBBaLHP`AR
NPAVlQ
NPAVhTGTNPQaMCPTQlQ
nPAeCFRPBBs<lQ
NPAVrTGcPTQ
fEPGcPTQ
b@BEPGQaMCPTQ
cPB@HPaMCPTQ
fEPGaMCPTQ
eCFRPBBaMCPTQ
NPAVr@CCPGAaMCPTQ
hTGTNPQ
hTGTNPQ
lGAPCIFRJPQ
lBqPOLGPQ
NPAVpITEBPQ
lB`GCPBACLRAPQ
b<BAPH
rFIIPRALFGB
bEPRLTIL;PQ
gP>n@LQ
nPAoLPIQ
tEEPGQ
NPAVjLGQ
qTAPaLHPjLGQ
bEPRLO<jLGQ
NPAVbPRFGQ
NPAVhLIILBPRFGQ
nPAiF>PCsF@GQ
oCFHm>GQ
BPAVhPAMFQ
lG?FJPhPAMFQ
nPAhPAMFQ
rILESFTCQ
cPEITRP
lBg@IIfC^MLAPbETRP
lB^MLAPbETRP
rCPTAPlGBATGRP
rFHELIPtBBPHSI<oCFHbF@CRP
nPAmTBMrFQP
BPAVhFQP
oLIPhFQP
eTQQLGNhFQP
rFHECPBBLFGhFQP
BPAVlGAPCEFITALFGhFQP
rLEMPChFQP
c>hFQP
NPAVrFQPeTNP
oCFHlHTNP
qCT>lHTNP
NPAVhPBBTNP
tQQcTGNP
rFHETCPp=RMTGNP
pGQlG?FJP
sPNLGlG?FJP
lpG@HPCTSIP
lqLBEFBTSIP
BPAVnPGPCTAPp=PR@ATSIP
qF@SIP
NPAVmTGQIP
c@GALHPoLPIQmTGQIP
c@GALHPa<EPmTGQIP
rIFBPmTGQIP
nPAa<EPoCFHmTGQIP
p?PGA^TLAmTGQIP
cPRATGNIP
bLGNIP
qF>GIFTQoLIP
lB_FITALIP
lBlGcFIP
^LGQF>Bs@LIAlGcFIP
rFGBFIP
NPAVhTLG^LGQF>aLAIP
hFQ@IP
BPAV^LGQF>bA<IP
eCFRPBB^LGQF>bA<IP
NPAVgTHP
NPAVqP?LRPgTHP
d@PC<o@IIeCFRPBBlHTNPgTHP
BPAVoLIPgTHP
nPAcTGQFHoLIPgTHP
nPAoLIPgTHP
NPAVhTRMLGPgTHP
NPAVo@IIgTHP
NPAV`BPCgTHP
NPAVeCFRPBBgTHP
nPAgTHP
nPAeCFRPBBPBs<gTHP
nPAtBBPHSI<gTHP
NPAVqLCPRAFC<gTHP
nPAqLCPRAFC<gTHP
bATRJoCTHP
aFoLIPaLHP
qTAPaLHP
NPAViTBA^CLAPaLHP
nPAiTBA^CLAPaLHP
bPAiTBA^CLAPaLHP
lBqT<ILNMAbT?LGNaLHP
^MLRMaLHP
aFiFRTIaLHP
aF`GL?PCBTIaLHP
NPAVrCPTALFGaLHP
nPArCPTALFGaLHP
NPAViTBAtRRPBBaLHP
nPAiTBAtRRPBBaLHP
^TLAfGP
NPAViLGP
cPTQiLGP
^CLAPiLGP
NPAVgP>iLGP
rFHSLGP
iFRTIhTRMLGP
pBRTEP
NPAVlBnPGPCLRa<EP
NPAVoLPIQa<EP
rMTGNPa<EP
NPAVhLHPa<EP
_TI@Pa<EP
NPAVqCL?Pa<EP
NPAVqPRITCLGNa<EP
bPR@CLA<eCFAFRFIa<EP
nPAa<EP
bFRJPAa<EP
nPApIPHPGAa<EP
BPAVrFGAPGAa<EP
NPAVeCFEPCA<a<EP
oLIPbMTCP
rFHETCP
b<BAPH
NPAVlG?TCLTGAr@IA@CP
rTEA@CP
hPAMFQsTBP
cPTQfGI<rFIIPRALFGsTBP
NPAVfCQLGTIlNGFCPrTBP
mAAE^PScPBEFGBP
nPAcPBEFGBP
qLBEFBP
aC<eTCBP
cP?PCBP
rCPTAP
h@IALRTBAqPIPNTAP
qPOITAP
NPAVaMCPTQbATAP
bPAtETCAHPGAbATAP
qPIPAP
NPAV^MLAP
NPAVrTG^CLAP
fEPG^CLAP
aMCPTQbATALRtAACLS@AP
qLBElQtAACLS@AP
bataMCPTQtAACLS@AP
n@LQtAACLS@AP
`G?PCLOLTSIPrFQPtAACLS@AP
qPS@NNTSIPtAACLS@AP
rFH_LBLSIPtAACLS@AP
aTCNPAoCTHP>FCJtAACLS@AP
nPAr@BAFHtAACLS@AP
b@EECPBBlIQTBHtAACLS@AP
p=APGBLFGtAACLS@AP
qPBRCLEALFGtAACLS@AP
lNGFCPqTAThPHSPCtAACLS@AP
qPOT@IAhPHSPCtAACLS@AP
oITNBtAACLS@AP
rFHELITALFGcPIT=TALFGBtAACLS@AP
ribrFHEILTGAtAACLS@AP
c@GALHPrFHETALSLILA<tAACLS@AP
b@EECPBB`GHTGTNPQrFQPbPR@CLA<tAACLS@AP
BPAV`BPbMPIIp=PR@AP
NPAVhLG@AP
cPTQs<AP
^CLAPs<AP
aFs<AP
qPD@P@P
pGD@P@P
NPAV_TI@P
BPAV_TI@P
qPIPAP_TI@P
NPAVmTB_TI@P
aC<nPA_TI@P
bPA_TI@P
cPNLBAC<mL?P
NPAVlBeCLHLAL?P
cPHF?P
NPAVbL;P
BPAVsIFRJbL;P
NPAVaFATIbL;P
BPAVjP<bL;P
b@EECPBBoLGTIL;P
bL;PfO
iTBAlGQP=fO
bPR@CLA<ePCHLBBLFGoITN
mTBoITN
NPAVkEPN
b<BAPH
aMCPTQLGN
BPAVeTQQLGN
`ao}pGRFQLGN
nPApGRFQLGN
b<BAPH
qCT>LGN
lHTNLGN
b<BAPH
c@GALHP
_PCBLFGLGN
NPAVlB^TCGLGN
oCFHsTBP
bACLGN
aFsTBP
bACLGN
pBRTEPqTATbACLGN
qF>GIFTQbACLGN
NPAV_PCBLFGbACLGN
aFbACLGN
nPAbACLGN
b@SBACLGN
b<BAPH
qCT>LGN
oFCpTRM
lBhTARM
bAFE>TARM
NPAVmTBM
rFHE@APmTBM
NPAVp=PR@ATSIPeTAM
nPAo@IIeTAM
nPAaPHEeTAM
nPAoFIQPCeTAM
NPAV^LQAM
NPAViPGNAM
BPAViPGNAM
nPAiPGNAM
bPAiPGNAM
BPAVrFGAPGAiPGNAM
pGQB^LAM
bATCAB^LAM
NPAVhFGAM
tB<GRrTIISTRJ
aLHPCrTIISTRJ
^TLArTIISTRJ
aCTGBOFCHoLGTIsIFRJ
aCTGBOFCHsIFRJ
NPAVrTGbPPJ
hTCBMTI
qPRLHTI
NPAVfCQLGTI
b<BAPH
bPR@CLA<
eCLGRLETI
^LGQF>BeCLGRLETI
FEVnCPTAPCaMTGfCpD@TI
FEViPBBaMTGfCpD@TI
NPAV_FI@HPiTSPI
b<BAPH
rFIIPRALFGB
fSKPRAhFQPI
b<BAPH
rFHEFGPGAhFQPI
cPHF?PtII
^TLAtII
JPCGPI
BPAVbPR@CLA<eCFAFRFI
aMCPTQeFFI
D[<>]t@lIN
CJd~Jo[^ooAFq
nPAhTGLOPBAcPBF@CRPbACPTH
oLIPbACPTH
oCFHbACPTH
n[LEbACPTH
nPAcPD@PBAbACPTH
hPHFC<bACPTH
NPAVeTCTH
NPAVlAPH
BPAVlAPH
d@P@P`BPC^FCJlAPH
NPAVlB
sLAfEPCTALGNb<BAPH
b<HHPACLRtINFCLAMH
mTBMtINFCLAMH
cTGQFH
lrC<EAFaCTGBOFCH
NPAVeITAOFCH
NPAVlBpG@H
sFFIPTG
iPBBPCaMTG
FEVnCPTAPCaMTG
FEViPBBaMTG
aLHPbETG
NPAVeCLHTC<bRCPPG
tEEqFHTLG
NPAVr@CCPGAqFHTLG
bPPJfCLNLG
NPAVrFI@HG
hPBBTNPsF=lRFG
qPBACF<lRFG
rFE<lRFG
nPAp=APGBLFG
nPAoLIPgTHP^LAMF@Ap=APGBLFG
NPAVfb_PCBLFG
NPAV_PCBLFG
b<BAPH
rFHECPBBLFG
bPR@CLA<ePCHLBBLFG
rFGBFIPtEEILRTALFG
^LGoFCHBtEEILRTALFG
NPAViFRTALFG
BPAVlGRI@QPqPS@NlGOFCHTALFG
bRCPPGfCLPGATALFG
b<BAPH
nIFSTIL;TALFG
b<BAPH
c@GALHP
bPCLTIL;TALFG
tRALFG
FEVb@SACTRALFG
b<BAPH
cPOIPRALFG
lrFIIPRALFG
eCFEPCA<qTATrFIIPRALFG
eCFRPBBaMCPTQrFIIPRALFG
gTHP_TI@PrFIIPRALFG
bACLGNrFIIPRALFG
nCF@ErFIIPRALFG
^PSmPTQPCrFIIPRALFG
rFHELIPCpCCFCrFIIPRALFG
hTGTNPHPGAfSKPRArFIIPRALFG
jP<rFIIPRALFG
iFNLRTIrFGK@GRALFG
FEVtQQLALFG
nPAnPGPCLRa<EPqPOLGLALFG
NPAVeFBLALFG
BPAVeFBLALFG
bPTCRMfEALFG
lfp=RPEALFG
TQQV`GMTGQIPQp=RPEALFG
fSKPRAqLBEFBPQp=RPEALFG
gFAlHEIPHPGAPQp=RPEALFG
gFAb@EEFCAPQp=RPEALFG
oLIPgFAoF@GQp=RPEALFG
tCN@HPGAf@AfOcTGNPp=RPEALFG
lGQP=f@AfOcTGNPp=RPEALFG
eTAMaFFiFGNp=RPEALFG
tCN@HPGAg@IIp=RPEALFG
aTCNPAlG?FRTALFGp=RPEALFG
lG?TILQfEPCTALFGp=RPEALFG
nPAmcoFCp=RPEALFG
`GT@AMFCL;PQtRRPBBp=RPEALFG
oFCHTAp=RPEALFG
tCN@HPGAp=RPEALFG
f?PCOIF>p=RPEALFG
NPAVqPBRCLEALFG
NPAVoLIPqPBRCLEALFG
NPAV^TLAcPTBFG
aMCPTQ^TLAcPTBFG
bACLGNrFHETCLBFG
hPBBTNPsF=qPOT@IAs@AAFG
bPGQaF
iPBBPCaMTGfCpD@TIaF
nCPTAPCaMTGfCpD@TIaF
gFApD@TIaF
rFE<aF
nPAhPBBTNPp=ACTlGOF
lHTNPrFQPRlGOF
oLPIQlGOF
hPAMFQlGOF
oLIPlGOF
r@IA@CPlGOF
qCL?PlGOF
oLIPb<BAPHlGOF
nPAlRFGlGOF
oLIP_PCBLFGlGOF
nPA_PCBLFGlGOF
bPCLTIL;TALFGlGOF
hPHSPClGOF
eTCTHPAPClGOF
nPAr@CBFClGOF
rFGBAC@RAFClGOF
eCFRPBBbATCAlGOF
qLCPRAFC<lGOF
eCFEPCA<lGOF
aFsLAHTE
oCFHmSLAHTE
nPAmSLAHTE
hLRCFBFOA
rbMTCE
b<BAPH
NPAV\PTC
qLCPRAFC<bPETCTAFCrMTC
NPAVpCCFCg@HSPC
bACPTHcPTQPC
aP=AcPTQPC
_srFQPeCF?LQPC
rbMTCErFQPeCF?LQPC
rFQPqFHeCF?LQPC
loFCHTAeCF?LQPC
bACLGNs@LIQPC
bEPRLTIoFIQPC
pGRFQPC
s@OOPC
bPC?LRPeFLGAhTGTNPC
hTGTNPHPGAfSKPRAbPTCRMPC
`GMTGQIPQp=RPEALFGp?PGAmTGQIPC
b<BAPH
rFQPqFH
rFHELIPC
BPAVrFFJLPrFGATLGPC
aF`EEPC
bACLGNrFHETCPC
r@CCPGA`BPC
pGRFQPCeTCTHPAPC
bACPTH^CLAPC
aP=A^CLAPC
aC<pGAPC
sLArFG?PCAPC
aFiF>PC
NPAVhTKFC
BPAVoFCPNCF@GQrFIFC
rFGBFIPrFIFC
cPBPArFIFC
rFHELIPCpCCFC
lpG@HPCTAFC
bACLGNpG@HPCTAFC
hTGTNPHPGAfSKPRApG@HPCTAFC
nPApG@HPCTAFC
nPArFGBAC@RAFC
hFGLAFC
rCPTAPpGRC<EAFC
`lGAeAC
NPAVmF@C
nCTEMLRB
b<BAPH
qLTNGFBALRB
NPAVaMCPTQB
nPAoLPIQB
tQQbPRFGQB
NPAVaFATIbPRFGQB
oCFHbPRFGQB
NPAVsF@GQB
nPAhPAMFQB
b<BAPH
c@GALHP
lGAPCFEbPC?LRPB
b<BAPH
c@GALHP
rFHELIPCbPC?LRPB
oFCHTAAPCbPC?LRPB
NPAVpHSPQQPQcPBF@CRPB
qPS@NNLGNhFQPB
NPAVcPOPCPGRPQtBBPHSILPB
nPAqLCPRAFCLPB
NPAVeCFEPCALPB
nPAeCFEPCALPB
nPAoLIPB
nPAhFQ@IPB
g@HSPCbA<IPB
nPAa<EPB
nPAeCFRPBBPB
NPAVtAACLS@APB
lHTNPtAACLS@APB
oLIPtAACLS@APB
nPAr@BAFHtAACLS@APB
nPAtAACLS@APB
bPAtAACLS@APB
NPAVaFATIhLG@APB
oCFHhLG@APB
}|}qPCL?Ps<APB
cPTQtIIs<APB
nPAs<APB
gP=As<APB
NPAV_TI@PB
nPA_TI@PB
nPAqCL?PB
sLGQLGNoITNB
bFRJPAoITNB
pG@HqLBEIT<bPAALGNB
`GMTGQIPQp=RPEALFGp?PGAtCNB
b<BAPH
aMCPTQLGN
pD@TIB
b<BAPH
^LGQF>B
NPAVtIIbRCPPGB
rFGATLGB
b<BAPH
cPN@ITCp=ECPBBLFGB
b<BAPH
bPR@CLA<
ePCHLBBLFGB
b<BAPH
rFIIPRALFGB
lG?FJPhPAMFQfEALFGB
NPAVrFHELIPCfEALFGB
BPAVrFHELIPCfEALFGB
bACLGNbEILAfEALFGB
cPNP=fEALFGB
hPBBTNPsF=fEALFGB
hPBBTNPsF=s@AAFGB
bPAr@CBFCeFB
>T?PlGnPAqP?rTEB
NPAVnCF@EB
NPAVrMTCB
NPAVmPTQPCB
nPAlHTNPpGRFQPCB
c@GALHPmPIEPCB
nPAhPAMFQeTCTHPAPCB
pGRFQPCeTCTHPAPCB
rFHELIPCeTCTHPAPCB
nPAeTCTHPAPCB
NPAVpCCFCB
NPAVmTBpCCFCB
oCFHmF@CB
hTGTNPHPGArITBB
oLIPtRRPBB
NPAVb@RRPBB
nPAr@CCPGAeCFRPBB
letQQCPBB
b<BAPH
bFRJPAB
rFHELIPCcPB@IAB
BPAVtCN@HPGAB
nPAnPGPCLRtCN@HPGAB
p=LBAB
>T?PlGnPAg@HqP?B
NPAVjP<B
bPGQjP<B
cPHF?PtA
rFGRTA
aP=AqTAToFCHTA
tEEPGQoFCHTA
lHTNPoFCHTA
NPAVqCL?PoFCHTA
eL=PIoFCHTA
eTCBPp=TRA
nPA`GLGLALTIL;PQfSKPRA
hTGTNPHPGAsTBPfSKPRA
qPIPAPfSKPRA
NPAVp=RPEALFGfSKPRA
bPIPRAfSKPRA
hTGTNPHPGAfSKPRA
bPIPRA
rFIIPRA
b<BAPH
bFRJPA
NPAVmPLNMA
bPGQ^TLA
lBqLNLA
nCTEMLRB`GLA
^TLAoFCp=LA
sLAsIA
NPAVqPOT@IA
oLCBAfCqPOT@IA
ltB<GRcPB@IA
qLTIFNcPB@IA
BPAV`BPCtNPGA
NPAVrILPGA
^PSrILPGA
aRErILPGA
b<BAPH
hTGTNPHPGA
pG?LCFGHPGA
nPAeTCPGA
hTJPaCTGBETCPGA
NPAVr@CCPGA
nPAr@CCPGA
t@AFcPBPAp?PGA
HF@BPVP?PGA
lepGQeFLGA
NPAVrF@GA
nPAs<APrF@GA
NPAVeCFRPBBFCrF@GA
nPAeTAMcFFA
aMCPTQbATCA
cPBATCA
lGBPCA
rFG?PCA
mAAE^PScPD@PBA
aFiLBA
rFGATLGBoLIPqCFEiLBA
nPAoLIPqCFEiLBA
NPAVmFBA
BPAVaLHPF@A
BPAVcPTQ^CLAPaLHPF@A
bPGQlGE@A
NPAVf@AE@A
hF?PgP=A
b<BAPH
cPTQtIIaP=A
^CLAPtIIaP=A
NPAVpCCFCaP=A
rFGATLGBaP=A
nPAaP=A
bPAaP=A
nPA^LGQF>aP=A
bACPTHLGNrFGAP=A
bATCAgP>
cPNLBAC<_LP>
NPAVgF>
NPAV`ARgF>
nPAoFCPNCF@GQ^LGQF>
nPAqPBJAFE^LGQF>
NPAVlGQP=
hPBBTNPsF=
nCF@Es<
NPAVqT<
lGLALTIL;PtCCT<
aFtCCT<
aFrMTCtCCT<
NPAVlBtCCT<
NPAVlBcPTQ<
NPAVjP<
rCPTAPb@SjP<
fEPGb@SjP<
fEPGsTBPjP<
rFGATLGBjP<
cPNLBAC<jP<
b<BAPH
bPR@CLA<
rC<EAFNCTEM<
NPAVtBBPHSI<
NPAVrFHELIPQtBBPHSI<
nPAp=PR@ALGNtBBPHSI<
BPAVf@AE@AtBBPHSI<
tQQCPBBoTHLI<
tBcPTQfGI<
NPAVlBcPTQfGI<
iTBAlGQP=fOtG<
sIFRJrFE<
lqLRALFGTC<
aFqLRALFGTC<
BPAVnPGPCTAPlGhPHFC<
NPAVoTRAFC<
aTBJoTRAFC<
rCPTAPqLCPRAFC<
BPAV^FCJLGNqLCPRAFC<
NPAVb<BAPHqLCPRAFC<
NPAVcFFAqLCPRAFC<
cPNLBAC<
NPAVrTETRLA<
d@TILA<
FEVpD@TILA<
FEVlGPD@TILA<
b<BAPH
bPR@CLA<
^LGQF>BlQPGALA<
lBg@IIfCpHEA<
51b<BAPH
bPR@CLA<
ePCHLBBLFGB
bPR@CLA<ePCHLBBLFGtAACLS@AP
HBRFCILS
_PCBLFGx
r@IA@CPxGP@ACTI
e@SILRjP<aFJPGxS~~T
bJLE_PCLOLRTALFG
^CTEgFGp=RPEALFGaMCF>B
gpaoCTHP>FCJ
_PCBLFGx?
oCTHP>FCJqLBEIT<gTHP
oCTHP>FCJ
VrFCp=PhTLG
HBRFCPP
ddb_^*8
*ny*q}=
KJ]KP\KCO,p-]KGWKIVK
O,p)]K
O,p!]K
[KQO,p
O,h+O,h%\O,p
KA]O,p
eO,@'O,8#O,`
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
.?AVbad_alloc@std@@
.?AVexception@std@@
.?AVbad_array_new_length@std@@
.?AVbad_exception@std@@
.?AVtype_info@@
111F1K1P1q1v1
4414;4
4)585A5N5d5
6#6)6<6
7(727R7
8)8.8A8a8~8
;3;<;E;S;\;~;
<$<*<0<6<<<C<J<Q<X<_<f<m<u<}<
<4=G=e=s=!?X?_?d?h?l?p?
:B:c:q:w:
;';8;D;`;
<+<=<h<r<
=3===I=N=S=n=x=
1"151<1D1\1j1r1
7-787C7[7i7
8)888M8Z8p8w8
99:G:`:h:q:z:
;e;q;v;|;
1$1(101<1V1
9,9Z9i9{9
:&:3:W:^:}:
;);P;e;u;
=$>G>N>a>
>A?G?s?y?
8X9s9}9
;(;5;?;O;
>&?r?{?
5&5`5n5v5
:':5:R:Z:
>&>8>J>\>n>
T0Z0}0F1
4"585=5B5R5W5\5l5q5v5
6!646U6b6w6
8#8.83888S8b8m8r8w8
8#9G9k9
9::A:K:o:
<,=5=M=y=
1)1@1c1~1
356?6f6p6
4=4R4\4
4.5=5s5
=*=J=B>
040A0F0T0
0 1+1;1t1
5<8I8t8
;#;0;B;
;'<<<E<N<
11+1J1P1^1
5*525O5_5k5z5
777T7h7s7
96:V:f:
<m<x<~<
2J3e3{3
?)?F?c?
$10141@1D1H1L1P1T1`1d1h1
2 24282<2X2\2`2d2h2p2x2
3 3(30383@3H3P3X3`3h3p3x3
4 4(40484@4H4P4X4`4h4p4x4
5 5(50585@5H5P5X5`5h5p5x5
5$<(<,<<=@=D= >(>0>4>8><>@>D>H>L>T>X>\>`>d>h>l>p>|>
0H0L0P0T0X0\0`0d0h0l0p0t0x0|0
1 1$1(1,1014181<1@1D1H1L1P1T1X1\1`1d1h1l1p1t1x1|1
; ;$;(;,;0;4;8;<;@;D;H;L;P;T;X;\;
1$1,141<1D1L1T1\1d1l1t1|1
2$2,242<2D2L2T2\2d2l2t2|2
3$3,343<3D3L3T3\3d3l3t3|3
4$4,444<4D4L4T4\4d4l4t4|4
5$5,545<5D5L5T5\5d5l5t5|5
6$6,646<6D6L6T6\6d6l6t6|6
7$7,747<7D7L7T7\7d7l7t7|7
2 2(20282@2H2P2X2`2h2p2x2
3 3(30383@3H3P3X3`3h3p3x3
4 4(40484@4H4P4X4`4h4p4x4
5 5(50585@5H5P5X5`5h5p5x5
6 6(60686@6H6P6X6`6h6p6x6
7 7(70787@7H7P7X7`7h7p7x7
8 8(80888@8H8P8X8`8h8p8x8
<$<,<4<<<D<L<T<\<d<l<t<|<
? ?$?4?8?<?@?H?`?p?t?
4 4$4,4@4H4\4d4l4t4x4|4
5@5L5T5|5
586D6t6x6
6 7@7\7`7
8 8@8`8
9 9@9`9|9
505@5P5`5p5
8(8P8p8
COMDLG32.dll
GetSaveFileNameA
ChooseColorW
GetOpenFileNameA
KERNEL32.dll
GetModuleHandleA
GetProcAddress
MultiByteToWideChar
QueryPerformanceFrequency
QueryPerformanceCounter
GetCurrentProcessId
GetCurrentThreadId
GetSystemTimeAsFileTime
InitializeSListHead
IsDebuggerPresent
UnhandledExceptionFilter
SetUnhandledExceptionFilter
GetStartupInfoW
IsProcessorFeaturePresent
GetModuleHandleW
GetCurrentProcess
TerminateProcess
WriteConsoleW
RaiseException
RtlUnwind
GetLastError
SetLastError
EnterCriticalSection
LeaveCriticalSection
DeleteCriticalSection
InitializeCriticalSectionAndSpinCount
TlsAlloc
TlsGetValue
TlsSetValue
TlsFree
FreeLibrary
LoadLibraryExW
EncodePointer
GetStdHandle
WriteFile
GetModuleFileNameW
ExitProcess
GetModuleHandleExW
GetCommandLineA
GetCommandLineW
HeapAlloc
HeapFree
FindClose
FindFirstFileExW
FindNextFileW
IsValidCodePage
GetACP
GetOEMCP
GetCPInfo
WideCharToMultiByte
GetEnvironmentStringsW
FreeEnvironmentStringsW
SetEnvironmentVariableW
SetStdHandle
GetFileType
GetStringTypeW
CompareStringW
LCMapStringW
GetProcessHeap
HeapSize
HeapReAlloc
FlushFileBuffers
GetConsoleOutputCP
GetConsoleMode
SetFilePointerEx
CreateFileW
CloseHandle
DecodePointer
kernel32.dll
DestroyClass
GetStyle
GetProcess
TerminateThread
TerminateCursor
InitializeMemory
AllocateClass
QueryBitmap
DeleteClass
user32.dll
AllocateEvent
GetTimer
DeleteBrush
SetFont
OpenMessage
advapi32.dll
OpenFont
TerminateStyle
UnregisterCursor
Western Cape1
Durbanville1
Thawte1
Thawte Certification10
Thawte Timestamping CA0
121221000000Z
201230235959Z0^1
Symantec Corporation100.
'Symantec Time Stamping Services CA - G20
http://ocsp.thawte.com0
.http://crl.thawte.com/ThawteTimestampingCA.crl0
TimeStamp-2048-10
Symantec Corporation100.
'Symantec Time Stamping Services CA - G20
121018000000Z
201229235959Z0b1
Symantec Corporation1402
+Symantec Time Stamping Services Signer - G40
http://ts-ocsp.ws.symantec.com07
+http://ts-aia.ws.symantec.com/tss-ca-g2.cer0<
+http://ts-crl.ws.symantec.com/tss-ca-g2.crl0(
TimeStamp-2048-20
DigiCert Inc1
www.digicert.com1$0"
DigiCert Assured ID Root CA0
131022120000Z
281022120000Z0r1
DigiCert Inc1
www.digicert.com110/
(DigiCert SHA2 Assured ID Code Signing CA0
p1f3q>
http://ocsp.digicert.com0C
7http://cacerts.digicert.com/DigiCertAssuredIDRootCA.crt0
4http://crl4.digicert.com/DigiCertAssuredIDRootCA.crl0:
4http://crl3.digicert.com/DigiCertAssuredIDRootCA.crl0O
https://www.digicert.com/CPS0
DigiCert Inc1
www.digicert.com110/
(DigiCert SHA2 Assured ID Code Signing CA0
201104000000Z
231108235959Z0p1
Bayern1
TeamSpeak Systems GmbH10
TeamSpeak Systems GmbH0
/http://crl3.digicert.com/sha2-assured-cs-g1.crl05
/http://crl4.digicert.com/sha2-assured-cs-g1.crl0L
https://www.digicert.com/CPS0
http://ocsp.digicert.com0N
Bhttp://cacerts.digicert.com/DigiCertSHA2AssuredIDCodeSigningCA.crt0
25E)ncF7
DigiCert Inc1
www.digicert.com110/
(DigiCert SHA2 Assured ID Code Signing CA
Symantec Corporation100.
'Symantec Time Stamping Services CA - G2
201125140737Z0#
Aapi-ms-win-core-fibers-l1-1-1
api-ms-win-core-synch-l1-2-0
kernel32
api-ms-
mscoree.dll
Aja-JP
Sunday
Monday
Tuesday
Wednesday
Thursday
Friday
Saturday
January
February
August
September
October
November
December
MM/dd/yy
dddd, MMMM dd, yyyy
HH:mm:ss
((((( H
Aapi-ms-win-core-datetime-l1-1-1
api-ms-win-core-file-l1-2-2
api-ms-win-core-localization-l1-2-1
api-ms-win-core-localization-obsolete-l1-2-0
api-ms-win-core-processthreads-l1-1-2
api-ms-win-core-string-l1-1-0
api-ms-win-core-sysinfo-l1-2-1
api-ms-win-core-winrt-l1-1-0
api-ms-win-core-xstate-l2-1-0
api-ms-win-rtcore-ntuser-window-l1-1-0
api-ms-win-security-systemfunctions-l1-1-0
ext-ms-win-ntuser-dialogbox-l1-1-0
ext-ms-win-ntuser-windowstation-l1-1-0
advapi32
api-ms-win-appmodel-runtime-l1-1-2
user32
api-ms-win-core-fibers-l1-1-0
ext-ms-
zh-CHS
az-AZ-Latn
uz-UZ-Latn
kok-IN
syr-SY
div-MV
quz-BO
sr-SP-Latn
az-AZ-Cyrl
uz-UZ-Cyrl
quz-EC
sr-SP-Cyrl
quz-PE
smj-NO
bs-BA-Latn
smj-SE
sr-BA-Latn
sma-NO
sr-BA-Cyrl
sma-SE
sms-FI
smn-FI
zh-CHT
az-az-cyrl
az-az-latn
bs-ba-latn
div-mv
kok-in
quz-bo
quz-ec
quz-pe
sma-no
sma-se
smj-no
smj-se
smn-fi
sms-fi
sr-ba-cyrl
sr-ba-latn
sr-sp-cyrl
sr-sp-latn
syr-sy
uz-uz-cyrl
uz-uz-latn
zh-chs
zh-cht
CONOUT$
<<<Obsolete>>
Antivirus Signature
Bkav W32.AIDetectMalware
Lionic Trojan.Win32.Agent.Y!c
Elastic malicious (high confidence)
MicroWorld-eScan Gen:Variant.Fragtor.300179
ClamAV Clean
CMC Clean
CAT-QuickHeal Clean
McAfee Artemis!3A68A2CBEB82
Cylance unsafe
Zillya Clean
Sangfor Trojan.Win32.Kryptik.Vhm0
K7AntiVirus Clean
BitDefender Gen:Variant.Fragtor.300179
K7GW Clean
Cybereason Clean
Baidu Clean
VirIT Clean
Cyren Clean
Symantec ML.Attribute.HighConfidence
tehtris Generic.Malware
ESET-NOD32 a variant of Win32/Kryptik.HTTO
APEX Malicious
Paloalto Clean
Cynet Malicious (score: 100)
Kaspersky UDS:DangerousObject.Multi.Generic
Alibaba Clean
NANO-Antivirus Clean
ViRobot Clean
Tencent Clean
TACHYON Clean
Sophos Mal/Generic-S
F-Secure Clean
DrWeb Clean
VIPRE Gen:Variant.Fragtor.300179
TrendMicro Clean
McAfee-GW-Edition Artemis!Trojan
Trapmine malicious.moderate.ml.score
FireEye Generic.mg.3a68a2cbeb827588
Emsisoft Gen:Variant.Fragtor.300179 (B)
SentinelOne Clean
GData Gen:Variant.Fragtor.300179
Jiangmin Clean
Webroot Clean
Avira Clean
Antiy-AVL Clean
Gridinsoft Trojan.Heur!.00002031
Xcitium Clean
Arcabit Trojan.Fragtor.D49493
SUPERAntiSpyware Clean
ZoneAlarm UDS:DangerousObject.Multi.Generic
Microsoft Trojan:Win32/Wacatac.B!ml
Google Detected
AhnLab-V3 Clean
Acronis Clean
BitDefenderTheta Gen:NN.ZexaF.36250.4yX@ay6ssA
ALYac Gen:Variant.Fragtor.300179
MAX malware (ai score=89)
DeepInstinct MALICIOUS
VBA32 BScope.Trojan.GenKryptik
Malwarebytes Malware.AI.1226848224
Panda Trj/Chgt.AD
Zoner Clean
TrendMicro-HouseCall Clean
Rising Backdoor.Agent!8.C5D (CLOUD)
Yandex Clean
Ikarus Trojan-Spy.Agent
MaxSecure Clean
Fortinet W32/GenKryptik.GHTO!tr
AVG Win32:TrojanX-gen [Trj]
Avast Win32:TrojanX-gen [Trj]
CrowdStrike win/malicious_confidence_90% (W)
No IRMA results available.