Static | ZeroBOX

PE Compile Time

2010-11-20 18:05:05

PE Imphash

68f013d7437aa653a8a98a05807afeb1

PEiD Signatures

Armadillo v1.71

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x000069b0 0x00007000 6.4042351061
.rdata 0x00008000 0x00005f70 0x00006000 6.66357096841
.data 0x0000e000 0x00001958 0x00002000 4.45574950787
.rsrc 0x00010000 0x00349fa0 0x0034a000 7.9998679751

Resources

Name Offset Size Language Sub-language File type
XIA 0x000100f0 0x00349635 LANG_ENGLISH SUBLANG_ENGLISH_US Zip archive data, at least v2.0 to extract
RT_VERSION 0x00359728 0x00000388 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_MANIFEST 0x00359ab0 0x000004ef LANG_ENGLISH SUBLANG_ENGLISH_US exported SGML document, ASCII text, with CRLF line terminators

Imports

Library KERNEL32.dll:
0x40802c GetFileAttributesW
0x408030 GetFileSizeEx
0x408034 CreateFileA
0x408040 ReadFile
0x408044 GetFileSize
0x408048 WriteFile
0x408054 SetFileAttributesW
0x40805c CreateDirectoryW
0x408060 GetTempPathW
0x408068 GetFileAttributesA
0x40806c SizeofResource
0x408070 LockResource
0x408074 LoadResource
0x408078 MultiByteToWideChar
0x40807c Sleep
0x408080 OpenMutexA
0x408084 GetFullPathNameA
0x408088 CopyFileA
0x40808c GetModuleFileNameA
0x408090 VirtualAlloc
0x408094 VirtualFree
0x408098 FreeLibrary
0x40809c HeapAlloc
0x4080a0 GetProcessHeap
0x4080a4 GetModuleHandleA
0x4080a8 SetLastError
0x4080ac VirtualProtect
0x4080b0 IsBadReadPtr
0x4080b4 HeapFree
0x4080c0 CreateDirectoryA
0x4080c4 GetStartupInfoA
0x4080c8 SetFilePointer
0x4080cc SetFileTime
0x4080d0 GetComputerNameW
0x4080dc GlobalAlloc
0x4080e0 LoadLibraryA
0x4080e4 GetProcAddress
0x4080e8 GlobalFree
0x4080ec CreateProcessA
0x4080f0 CloseHandle
0x4080f4 WaitForSingleObject
0x4080f8 TerminateProcess
0x4080fc GetExitCodeProcess
0x408100 FindResourceA
Library USER32.dll:
0x4081d0 wsprintfA
Library ADVAPI32.dll:
0x408000 CreateServiceA
0x408004 OpenServiceA
0x408008 StartServiceA
0x40800c CloseServiceHandle
0x408010 CryptReleaseContext
0x408014 RegCreateKeyW
0x408018 RegSetValueExA
0x40801c RegQueryValueExA
0x408020 RegCloseKey
0x408024 OpenSCManagerA
Library MSVCRT.dll:
0x408108 realloc
0x40810c fclose
0x408110 fwrite
0x408114 fread
0x408118 fopen
0x40811c sprintf
0x408120 rand
0x408124 srand
0x408128 strcpy
0x40812c memset
0x408130 strlen
0x408134 wcscat
0x408138 wcslen
0x40813c __CxxFrameHandler
0x408140 ??3@YAXPAX@Z
0x408144 memcmp
0x408148 _except_handler3
0x40814c _local_unwind2
0x408150 wcsrchr
0x408154 swprintf
0x408158 ??2@YAPAXI@Z
0x40815c memcpy
0x408160 strcmp
0x408164 strrchr
0x408168 __p___argv
0x40816c __p___argc
0x408170 _stricmp
0x408174 free
0x408178 malloc
0x408188 _CxxThrowException
0x40818c calloc
0x408190 strcat
0x408194 _mbsstr
0x40819c _exit
0x4081a0 _XcptFilter
0x4081a4 exit
0x4081a8 _acmdln
0x4081ac __getmainargs
0x4081b0 _initterm
0x4081b4 __setusermatherr
0x4081b8 _adjust_fdiv
0x4081bc __p__commode
0x4081c0 __p__fmode
0x4081c4 __set_app_type
0x4081c8 _controlfp

!This program cannot be run in DOS mode.
`.rdata
@.data
SVWjcf
WWWWWPj
@4+G4t
q89p8t
V,YYG;~
tlHt Ht
~(9~$u
FP;FTt
k|_^][Y
=j&&LZ66lA??~
}{))R>
f""D~**T
V22dN::t
o%%Jr..\$
&&Lj66lZ??~A
99rKJJ
==zGdd
""Df**T~
;22dV::tN
$$Hl\\
C77nYmm
%%Jo..\r
>!KK
55j_WW
&Lj&6lZ6?~A?
~=zG=d
"Df"*T~*
2dV2:tN:
x%Jo%.\r.
t>!K
a5j_5W
ggV}++
Lj&&lZ66~A??
bS11*?
Xt,,4.
RRvM;;
MMfU33
PPxD<<%
Bc!! 0
~~zG==
Df""T~**;
dV22tN::
xxJo%%\r..8$
tt>!
pp|B>>q
aaj_55
UUPx((
='9-6d
_jbF~T
11#?*0
,4$8_@
t\lHBW
QPeA~S
>4$8,@
p\lHtW
+HpXhE
T[$:.6
,4$8'9-6:.6$1#?*XhHpSeA~NrZlE
Sbt\lH
QeFbF~TiKwZ
4$8,9-6'.6$:#?*1hHpXeA~SrZlN
SbE\lHtQeF
F~TbKwZi
$8,4-6'96$:.?*1#HpXhA~SeZlNrSbE
lHt\eF
Q~TbFwZiK
8,4$6'9-$:.6*1#?pXhH~SeAlNrZbE
SHt\lF
QeTbF~ZiKw
inflate 1.1.3 Copyright 1995-1998 Mark Adler
Qkkbal
- unzip 0.15 Copyright 1998 Gilles Vollant
CloseHandle
GetExitCodeProcess
TerminateProcess
WaitForSingleObject
CreateProcessA
GlobalFree
GetProcAddress
LoadLibraryA
GlobalAlloc
SetCurrentDirectoryA
GetCurrentDirectoryA
GetComputerNameW
SetFileTime
SetFilePointer
MultiByteToWideChar
GetFileAttributesW
GetFileSizeEx
CreateFileA
InitializeCriticalSection
DeleteCriticalSection
ReadFile
GetFileSize
WriteFile
LeaveCriticalSection
EnterCriticalSection
SetFileAttributesW
SetCurrentDirectoryW
CreateDirectoryW
GetTempPathW
GetWindowsDirectoryW
GetFileAttributesA
SizeofResource
LockResource
LoadResource
FindResourceA
OpenMutexA
GetFullPathNameA
CopyFileA
GetModuleFileNameA
VirtualAlloc
VirtualFree
FreeLibrary
HeapAlloc
GetProcessHeap
GetModuleHandleA
SetLastError
VirtualProtect
IsBadReadPtr
HeapFree
SystemTimeToFileTime
LocalFileTimeToFileTime
CreateDirectoryA
KERNEL32.dll
wsprintfA
USER32.dll
RegCloseKey
RegQueryValueExA
RegSetValueExA
RegCreateKeyW
CryptReleaseContext
CreateServiceA
CloseServiceHandle
StartServiceA
OpenServiceA
OpenSCManagerA
ADVAPI32.dll
SHELL32.dll
OLEAUT32.dll
WS2_32.dll
fclose
fwrite
sprintf
strcpy
memset
strlen
wcscat
wcslen
__CxxFrameHandler
??3@YAXPAX@Z
memcmp
_except_handler3
_local_unwind2
wcsrchr
swprintf
??2@YAPAXI@Z
memcpy
strcmp
strrchr
__p___argv
__p___argc
realloc
_stricmp
malloc
??0exception@@QAE@ABV0@@Z
??1exception@@UAE@XZ
??0exception@@QAE@ABQBD@Z
_CxxThrowException
calloc
strcat
_mbsstr
MSVCRT.dll
??1type_info@@UAE@XZ
_XcptFilter
_acmdln
__getmainargs
_initterm
__setusermatherr
_adjust_fdiv
__p__commode
__p__fmode
__set_app_type
_controlfp
MSVCP60.dll
GetStartupInfoA
c.wnry
advapi32.dll
WANACRY!
CloseHandle
DeleteFileW
MoveFileExW
MoveFileW
ReadFile
WriteFile
CreateFileW
kernel32.dll
O|x8+^_
2/O-_.X8w.+
|~}%.15
Microsoft Enhanced RSA and AES Cryptographic Provider
CryptGenKey
CryptDecrypt
CryptEncrypt
CryptDestroyKey
CryptImportKey
CryptAcquireContextA
cmd.exe /c "%s"
115p7UMMngoj1pMvkpHijcRdfJNXj6LrLn
12t9YDPgwueZ9NyMgw519p7AA8isjr6SMw
13AM4VW2dhxYgXeQepoHkHSQuy6NgaEb94
Global\MsWinZonesCacheCounterMutexA
tasksche.exe
TaskStart
t.wnry
icacls . /grant Everyone:F /T /C /Q
attrib +h .
WNcry@2ol7
GetNativeSystemInfo
.?AVexception@@
incompatible version
buffer error
insufficient memory
data error
stream error
file error
stream end
need dictionary
invalid distance code
invalid literal/length code
invalid bit length repeat
too many length or distance symbols
invalid stored block lengths
invalid block type
incomplete dynamic bit lengths tree
oversubscribed dynamic bit lengths tree
incomplete literal/length tree
oversubscribed literal/length tree
empty distance tree with lengths
incomplete distance tree
oversubscribed distance tree
incorrect data check
incorrect header check
invalid window size
unknown compression method
%s%s%s
.?AVtype_info@@
b.wnryP8
oG*'UQ
&9(c]y
6P>YK^$r
^Md]"lN
Cww 2r
(L(Of\
^Fr`+:&
,Hp0xB
QI4MXh
T$oC8c
Jo7eQX%
j9lIBZ
+|e.H3
PP-|W
NLc>zQy
'B;1?5s
A3u$p2
[l~y2U=
%f.A{*
'I'bey
53q.zL
'Oh'-o]
[d+?8d[
+z]kF
KPeJr}F
#cMe&(;[Ip
aBKF:d
A32[)
)RZy>[
lG_hnO
c.wnry%
msg/m_bulgarian.wnry
ABOX{p
hhM[G"
Hjz%3(0
GHoy5
eASq#8
(thku)
}r~Qb>
CMnQ,OOr
?<A9&d
=a8Jnk
L3koq_ >
-?]`p,
Hy}V2l0e
RzA9D^
fx6EN?
/6V_)T
POl1QQ
cTTdz_
PQrr)(
msg/m_chinese (simplified).wnryR9
Ud|JZ|BE
#0i**'
D(Ve%q
Bur`G`
LV(8,
PzKxfJ
b4(X2;ey
:y//3O
3HW),I
n`|{pS
-_^zpD
7naesu
!#pHA[P
"t=.|Vbq-
msg/m_chinese (traditional).wnry
:95e`Ilyv
D"5~Y<
Bb..fO3
\~%caZ
y3YJNp
IyEf [%
M{_rKG
~|c<caKm2
<JCA(r
,Bx5]1
Y(t+b@
{&fH[w
KfmZ@9q
*@~CS%1
V@PcA}
'b"_}Pb
@;3wxh
5ANEI+
Kt:G!9
=;mrs_
msg/m_croatian.wnry
}ts`><
L)b7=a`
X<k+B
&0*g{s
Zu{0UX
l/Q Rh
;'y?+4
pfgGL`R
qr=_os*
BgTsl}
buKEv7
,MF3j;2@
6id?al
EGBkV6"rnL9
[4+G[Tnr
msg/m_czech.wnryn
7EJI8=
eAZyy-
Sv2!;z
\`s#s3
4I_,eJi
=1azT)8^y
\6tGuzF
;u>H4q7.c
fGNOfy
fWw9y[
Obwx(~
='4"".
Ulg?,]
^H_GrX
$@^ Y+kCM3
nyMZ?%g;
w{(J0v
0L)JD]
E!3c]T
YnlZ2`
ja6HDb
.Vy_Fdk
>k_I[$
qY*l+1
msg/m_danish.wnry
uB(i^C
+E!*w.
a%~YLL
&%^W6).
= '[8@
SE{^QC4
`1^9tdb
"^W&"$
*4q4[`V
@Pbmx~P
s5H5~D
kEs##Q^!
X(N.K&9
[wS#C^6
Ecb@}F
2bxrj>
-hL/$^
2{0ONU
msg/m_dutch.wnry9
mK~}k=P
GMhI(u
"/0.a`
qDj$bIU
?\XWI!
2C.!(P
9d|!]`[
MT2tGH
!`7RNkv
c\VN1;
-8d8hg
#`?@/9P
_[-Cu
W7;T3R
#b?)6G
d<Rh6l
_-TPsPUv: V
-){s W
o,.]BK
<wnXI"
msg/m_english.wnryF
`&&gy!
tmwtP7
=iF-s4"t
?-3t/''
Ow2"'R
^Ml,L;0
f$0SRu
W\:"r
V(8DA!_
_\z$$I
uv={8E
E"v{Y3
=XnFQ-Il
F5Nvkb
Enuim
]%UR{&
N]84YFv
&0J.+U
3p }s1
vi#<!d*S
E65etRI\v4
h+(q-@
wWv<:e
msg/m_filipino.wnry
ax&GMH
\Di$6
:h V;]
F: -v/
Le"zE^f1
ub,ZFz
e".E~^G
tJ9@0O(
mi8HTw
(2?X3Z
:*>B=Ox
7#z y,:
WZ.<ig
msg/m_finnish.wnry~
4XI"whG
:"nGu*
w/PYm-
(NCdNf
<` Xu9g
Gvf=%0
$0vJ<T9
uo"usd/
j_1lTo`
MF2E0UG
=;}Wp
x~YCs~
C{%a?7
)#u[gG
msg/m_french.wnry
8d62ro/
Gx"aUd
S&hE5_
.xz?ik
;k?cbp
pq"b"V1
+[\_JQ}
!A$U>=+
fpgYH9
mBf`S`
|keGIP
]wGMr
S5m3;%
^AH,;r
#E.(`MW
>nuGl=Cme4
I77nxO
msg/m_german.wnry
TG>_v?
okk7-E
4M4/Tc
[N`3JR
(Rgn*{
s<,kX5k
md)(:--
U;mOhn
~E8|Ui
B~WJLuC
dw"d3E
i=]7q3
$`GnP+%<g
b=htZo&f
2+( VPOL
msg/m_greek.wnry4n
ciC [/K
r;#r7iS|1
]40Qz-
Mp9 Je
s]R",XC(
U/6|EO
PiDnGs
+/Qi<=
y."VSB
O!D8Xk
*vO2K1.
kn[dius
g'5`M&t
xy*4buY
!`L KU
RUaT4/
O;dBN
RYIuwm
Us'Obf/
2S0wa(
wHBZDZ
&yG%@v
msg/m_indonesian.wnry
,XZJo!
PwlH2Xh
]F=V{Y
~(NQ*#
hXvMgw
2%w;yI
)FD~p5PgPl{
5}(=`|
:<vY(Y
7&|^"OUt
eo3@1\
W~1%+`
v/jq4OK
{xhR_
<;.pQf
msg/m_italian.wnry
vfICnff
d?r[a)9Y"
3Z~Jj&
0/D};p
mD(Ke,
`}N\1U'1
j?{@fa
-zk=d&
/&Y=2vB
;G'p29
1E7*[6(4
WS"8cy
2x~~Vix
eadg%/E*
msg/m_japanese.wnry
4jHDQ&
~z-!Qp
ZlfD:.
j>r%j
gFYol-l
^QEGo
Q1GRVv
-gjouo9
2mll1}
3qBbI~
+nJNQl
gMD\Gs;
@3.*El
-x2p{$u
),&(T[H1t
8+N)y>.
C!wzg/
szc0|.
$8i;N6
msg/m_korean.wnry
S~8kMG
J:/Ov=q
%E-~XNm
7P(F\{6
3Eo69e
OaXIwL
wED9T+7
4^'{^n
_z;Eq
(x'7]P
!-{Z_=
r%P<E'J
>K, UD
5@w1|W{
kJ16=5
G[Guy2
FTv$'/zaN
{jmJ&T
k%qn}5
bs?a:J
$\]{b'R
msg/m_latvian.wnry`N
ze\w/+
` C3Qm
N*L"a%w
<B%6r:
'+2jb(
2S Fvw
^l{\bt
Htg5lH
)' 5is
qt-o=S
3q"7%~<
~~?%Y"
z05|yZ
\'zHuH$
'2*_1)
}9zf]A"g 0
`{JsO!1
2[;LEj
[AI;zG
s`48>p
Zn4dY^
M~z(55O
msg/m_norwegian.wnry
65U_d1n
bD3Enl
`i4?Qow|
oOR01v
eS<%9:
fmrgR_
85FrrX1
2;I:.8
"u~rt%
bw"\,L
kH'tm}C
msg/m_polish.wnry'}7
MV`Chp
2N/it=
SXrk8.
>LYFJu^$RO
|=n2O
yk/R)p
qV^vX7
LRxvsP
V@5BaS
Y<V!DO
n''9U]<C
3ji^?u
msg/m_portuguese.wnry
UHLr.r
IJK'k!Q
#waiA
=)7$JBz
)bA?&2
Nt.:J0
akSbm&
R}:^dB/Y
G-IHM
1}m%{t&cY
%\vE-`
;'(#ER
nyoCPs
;@A/oajX
7mU'yx
<8Z[6m
:1]Df+
i3+HPK
msg/m_romanian.wnry
4sxsGJ
#r&)r|^
/yPN:yH
tzPL#i2;
Sy{<s3)
KAzJ5O
B}6Re/L
F7A)x:pdI
*uOV1'
dM/.2X7L
>\4Y34
%PMu56k
msg/m_russian.wnry
R~r>VCT
W"_~Pv
WerJu}&
pI,3O+(@
uc-e_B
s?cM<a
a-O2KT
BW2>`qk{
;"Mz3e
Cc't':
*e'-zD
msg/m_slovak.wnry1
[5ha\I
vRr0d;
VF*t D
[}jE$%
48yL^7
id"q#\
!LD'z
_z:_HCA
"y)r?uTi
M)%U~{H
XV<rc0
??dd^m
v1{f-g
@MSki#
xI70ql7k4
K-EB2W
o>/}SW
+tGYk]I
zczX2f
0rel/s
e_(iTY
`TO~}a
z[K<ue
msg/m_spanish.wnry
~s2{^U
%"ime6?x
A&mxQJ
cm;FP+
+_;)V1c
oeHRA(K
V@:fkl
r@wUko
4=x%|
4pblB
FHJbUQ
.)*SC)
lckZB"4
n]=W&
54/UAh
IR_,WhT
Dx~(hb7
'{2BZl
lMzD/5HeW^M}#}
d1n58y
?Xq~79
"o8L`)
(sRn"x#
9{!bJ6
'mIWO]
msg/m_swedish.wnry
n:JJ9Sz5
t5>E6.
<NH0Etua
w:Z=2}
JS1YV_
aJ`3pU,{
eJD{+~o
#@5c3'
OO*cC
)u"Kr9
6Z-cZ\
e*UW2x
u\c^B[
a<W7aP
AU"'P=
j6EZJNH
l'm#)|
4zNP\
;N-.2s"G
msg/m_turkish.wnryO
}u#j+Q~k
Ay[u0j
tNahN)4
%UOR",
+R'&LRNR
u3-M"T"U
(ytnx
d5PM1^Ednt
dk(ME7K
c\ ! 7
Wa%a!A
j@19kX~
%^SWV"
cS@3ET
msg/m_vietnamese.wnry
d@I,j-
g>R^Zf
|SbXmh
ns;aUB
K7_j-Y713S
HWoK:m
-TJQb3
iI$vIr
vgG}Z@
jgxJ^H8
2mgZii>
]Y5?C-
6" (FI
S)LMSZ
r.wnry
Jcg4k_
s.wnry
+dWi>D@
deHhT[
l[AG"&
=n[(p{Bt
Ij)zv1
0>R36j?<F
:h1c6u
HtEm'wd
|Dvs~F*^l
4vSMk@
XWyG0K
Y[}rOD
itfwb\k_
0,y8nxt
&{N;5
Y-&n,#
23FoN_
H(~+Wz
G6Kw4Ky4
t9F<N6+
,o2C=/F
bRocPs
F8.%_8
UDiA9R
%OS QS
=v6-j-
Bm$Iqs
<00iZA
Z0@Cc(`
HnR%^d
`*rkm;9,
H>*"NJx,
H-Ukw3
/1NX|3{
>C]*2|b
~@4m>G
S d[M.\
%Lg?RK
X1NKXF!
n- !=]
@P~m~g
$)=56t\
|9543k
+nW]$JpA7
\a3dNt
MAb7l,
?5rx>K
#S[s{^9
0kC@\O
:TuRYf
yypb!e
*S)G4=R
m H[M~
<ebd=`
"8Buku1
wz1JV+U^uV
+9|qil
0jFk/3V
klK1p<
b!gVs"
Bst,Kq
~TWkx[
M:US@OxN
9(=b;x
N7m'Zh
P5 #i
yT~3&.O_]$
ER!<Zk?
3VuEu]
u"`W.C
c9ww0z
Gfh55
vFNr*,Bv
TblK)_8
mC=(wEqY
#QvW<J
]{I@uuX
hWmYa1(
NpB']U
fkRzAO
:7<$!QE
en;Aa;
.!bC&{
Q$-3J,
qVyWD.3j^
)jO}/uB
B>(Rp4
>0_Tuu
TQ*N6;
Wt-Q>I
#HX }P
7run#
?WoaH'[@
u XoGo
nI']9FK
Y8s%va
Z}!iEd
$+IVoM
}}Z~`CT
E7;a,Z
(]V"VV
Y| 1F-
s2^ZaY
}&j^K;m
v YkH%
0?N.MyJ
7dS"Q7
jyicFf
!z3|_K
_/aN#2
Y~GdxN
ad/dly
<O?@s,
`93F?"
KK,\:)
RMRe3K
oz.mZR~
&%r:*|
@dC7+8*
SB(GR#
:5[FMF
GZb8 =
bK4+#z
[&5pHgJ
< HMB=])5
,x8a4~8
QQ|\-d
/wIO0K
OlMvf2
~+h8Ux
V1Q*K68
ul6=zp
>gE(pii
`jv[S,
8QpFQb
w+<uH/
]%zpDIib
yzyul"
4Yo."b
E>zIE,
x$KU{
**JW4a
ZlL7\;
pE"5DS
Pv#km=
;oD37*8
^Gn9or
Q6J?tN
)V)JAU
dG%aX:A
"|)JHKI
F*;-x_Z
Kjn(]/
:l5G<u
*5A6:NnA
TFM7j{
&+Lb_/
]Z{_T7
m2Q}2?
BI}"Fh
qiR!L
7'if32
on@{Qhfm;
XL#l<
|xS=U
htfA }
c$?IUo
g!^S83
9b2']
1}%zcn
+T<I2
?'F=Q[
8,/_|\
]PC(r(t)t
Mg[pV0
4WR'}c
Nrb/m'
?4N),<
Xm/t&PN
[VS[3i:]
_pGWKlDI7
,)|c1%
&MZM[{
B-`XOX
>{rKT!
,KRp-v
5E^Qxoz
dprL2i
>_,4Rp
g,D($G
J84u&?
TmK3K~
yxpsDM
(UK3LT
GABwDv
qQ5:&2
[1y8?
vEcv9>
1<p^@.
MZ}B<n
xpWb-<M
?I*c]I
%{43J5
[hF/i6gpN
2pAmD,
^abiHWKa
,O`D_f
]}ArIF
>mf;oT
rCRK{\
ZRz#tH=9
pzjp%h
8fk$Xg
Re<oJ5
52G9cP
%N-.=p
"R0l_AT]K
%oUy
r@|UHQw
wi3@"c
PEoT-OX
aX.@^o!
P:+L6|S
)qIW8,`~
e{+R9#
+T]`H5
mH@-uQ=
/;im/l
IC#{C0
#a}XR3TU
LI{>W"
ge-"EXLvi
}V?Kz#
%o8/3O
LG'aoo
`'HxU.
?co=5g
{dFZC8
H\69MS
)oz-]0
X\PVoL{@
~XpOXH
6m*4$[
&?Tj^nj
(orv=G
+Hk}r^
Lo9GOk_
R5(TNtY}
gIpa}+~
SuN7to
K|/d.&
]%$Xb9
K5oJE~DO
[15V!tB[Z
R#FZlr4n
TkP}A:
s^9Ho,N
{Jsq\c
`;``BJ_
%i9ln7
g?U-z=
!&?W/\
R2uQq}P
fnWRFJ
$RJtYSU
epokHy
LW=}%:
#LH13O
Y].m4_{
# .aV\
\+im^*
reI;!B
@1VCPL
9d|:IC&
qjY~/!
w* E>5JW
bqJ Zpxn
X6W9RJ@o
Rsq2d*
0&#&wH
?'#OYw
z:3q*r
%G7^"
JmE=Xz
@6\C3@
z}b,H?
E= PCi(
HY`*SlY&
R<Ct=-.8Q(
'VxmtX
1aQ0'y
A2+,0S
Dxf(`I
BV0i`(xT
x>z9Fv
]pUKZ`
oiF`er$
4q${:\
Ukp#9X
8u&"rZ
%]U%PD
[n'X3`HX
;g)Yb=
Fj:M,
g2mMzF
E#,|U*
:UnIJ&F
Dag.}t
1+u9AF1A
F{Dkim
T99zyT
t\[ttsv@
,-zHLAL
<j{T/-N
;MwMWP
FcN`&Jf
_w`e$O
0^m}_{2
kc}T:o
:66//fu
qn~JOX
e(Ze]9c
W'Y*1l
Xu$Mh,
`{&Uha
,;Xl#$
kwQAn%7j
CqZ%D2~
N'=2c@\
s|Y5D_y
x\gTg'
eg`cQ:9
)y$-QR
!U9egYI
%<y(vE
bJ#]O]9E%
Wg`]JB
cAqRIJ
Ph)?L9z
NW3]}g
4Lnb9-
D]i 1w
2frP5TQ`
.'^P`Gl
nS+0-W
/n]Z8gq
:~e~'O-
ULYon@
L0nG=t
L@ry@5
YMhYC8
n`Ps@v
In9I'<k
0)jvB,>
3cuu'h
,BU_v&B
^C[0g3
jQFx#.$
W7SD~`
i*h2*#
g_9_r>
TC;-v%>
8*XB<s
EJQ+=v
\+,]]H
PJJx((I
~0PN4l
lV%6bN
\uI0wl
g1,@Cd*
eF!&L-
FxhIS=
?BI$M9
<.qnT#%R
f[tJQR
JY,q^_
~#"!=1@
4_o{\l
^7e{sUN
UIJVSj
R`+[P>u
0=}r9bhZ
'4_j(B{U
Hbk)gYv
9zgonJ
F>;ln(
r%xVYk6
>-7Y<3
Y=,X4]
vr=!R!g
4c]z$
F-JR@V
^i^t(2
q<aL`!
KANwq~{
;{[P{Rz
9m])_)
x0-XSo
-a%t=5I
RR[R8i
sq2c,"b
19-uSv9*X
P4<J6A
O<ha}KG)T
2 R<me
hwba%%y
fRaZ/5
BpyR3E
'`"qpq
fMS12k
N2l9Zh
3Vvo27O
'y-=4
)sGUE:
\c}8D~
;HEa^H
--R11Y
z.hEvo|
A\z=!a
#gK9<I
d+\P|O
C9XQJ2U_
}`;{?%
NQBMiA
ITUI$Mc
P$q!79>
o@ tz3
{l]k]Y</~a
[BKf#kv
m{Bj>w_
g?+U'0
+r@IQ.B
Cjg|xM
=b6"\)
G2CO&9
%$BO3b
4-=vM%
]<"1B:gz=_i
1sf$;mp
yh{}Ys^
}oDy=Rq
$7<lA
!hvpj1
VF|-x6W
M*jHXF
^i10T
(K,uPv
?U8p")1
cRo+kn
5Wd!L
!kuY2'GP:
.}*g/
?"81-d
n9iq^G
ihg&m"
ta~sM^
E9w O`
]XP@`,
I.GcvO
Qf~nU
'0TBzDu
HGbKb"-1
O5UvRTQ7p
{%<kw48
s*!-/
+b>S+E
\pS`)
OVzB%Q
QEa#{+1
'@NW7_!
Wwl~bw
jTX!7\J
]iH|OV"]n5~
,`fpk:
DKjusNo0`
3o9qut
0n>v=hq
s_e/+H
Euw7Y~
w9)R/)
c2}_9V
Xkfc"H
0OLZf6
qe6bg^n
0y/,{}<h,7
CK#Qyo
s"'`0
Bq3'6@
|iRPuQ
Ky"BjlT
Al:al:
!vx,H*
yO08ki
VLu]qUX8
Y,K2w<
; &DbL
&Gw78/
g".SS~
JRd*cW
4:LY~SD
i`12G#
wHUqfvO
1)%DI
lGt{R/Z
Zk%bxB
EkwWe[
FPxih>
`UfKNa
~-fVs9J)
Z/!x0OH
M@8:D{
ibKj&G
ecx8v;
:6U#RhH
9oMA Y
>I<l_~
p*Iry$
.s7<n:
<y]B'_
zoS4*Q
%E0n
LhP[}&
dzBEXA
]<mIK%h
Z]1R@C
JLBr)f
69Nx>O?
aJNf|s
I!RwX-#M
6ajH[vt
dET2ER
o%> wL
lD.yn)U_7<9C
~8IB+x
@Z9~b<
fc&4ct
6t,UVy
:XZ]4M
>gZ6fw
Ka6p'=
RFNxNo
wl1Z!g
p<uz k
25P}"?
YOIE<d
:g$">S
FP!H!W
fR5ko6z
B"@{40
L^86JD
VT3*X^
nvKl4,
Lv'Rbuc
u>c)8
-0RAp<+
X9*Ar3
9mbOyr
!tYvLT
Rj:6tSo9
A=}wp
-Z@Fru
RgOo`3m
Trj5!'
H:Sf &
xR5S4y
$[jp;pA
.'D]Dk
dU~3Y
~;fL"NJ
]l0o&Q
{_jHPQ
vE[m+Aa
ZQE9dXK
<B`IHRd5
DTjeZYH
-*|5Lp
l(Oc(>
prm&1i
{3-MB-
7^uM?X
yv&y"b
VKesbl
m-}pM`
4bFfPm
m9Qmh8
ZP[v>E2
-#PB`F$-V&2
3dbt&-
XL9HkJ
ZpoDO7
8U'<<l
%d!2bLa
jq%u_d
v_<AkQ
VbM|j!I
G$ul`&
bB6Y|2vN
e@&1r^
[B=G{&
U]@}Yi
^7LqzCk
_=K96W
Qw_=q
|qqcDY
Q8-8|NKLcP%
$]_qO4
3WG}tp
dNv%(.&J
,?3,$f
]>!1uX
F8T`*XG.h
,!2,9"Z
)gn'Gx
Wl Dpd
HW{WG<
)$o**6t7
C m)K
m&UYE<
q:3t,C
B5ijl$
|tpp@d
>~3~'R
JUbQBDj
WMUgtQ
6!qt-l
$\){Cf0v
2NP:JO
{\6tWw
'rr1ih
QRIy Z.&f
9WL4Pw
1aUIHM(f
u9aM"M
~/XeMt
Bz@u1a
"fMrw;
\_0gbA
Fj3oY(U
HJy`)c
3\<'*E
vwZ,x6?F
zg~ +}
7$U>-x
YSFsY@
6JeTzW
@qYMI>
,G"Q6s
6mB]Uj
v9$'DY
PcfsKs9
|~{P]:
!5yg~dC
xh/CFK
Tn@AP/x
k5q!3P
kktGm$
}h,sn
pquFw<
\)_I4H
dT_P0@$
Mu52IP
Z)gXU^[0
1C(Y[A
rhgf]r3
Qb+C[Mo
=6D FTI
CKmd=.@3
!OH+!:t
M}k&}PC%]3
>^`HIrk
w{86RX
9/f7oi[P
8%+tg%C
sq8yB5
az(|WY@5
242IAk
Gqd:[&
{t/PSz
-u7lJ7
+dd@jb
"vco{"Oyc
W>!7/|J
[~"F)8
="[}2i
Zt&2|`c
.2pqx2
eRz|P_
{82O~"ZLTl^
fPnT4&O
o?clV*
KIX&"b
Sx(OI-w
3 P`AOu
,>9YH=
WA<w@A
zS1L>M
_.@<G>G
`A{u|j$
_PN|X}
8,-b]@
^l,2)!
1(ZZc1L
&h|nWV
8}MtRH*
u>QN|\/
cf9-Eu
]gRo$C$
&MIEEP#*Ge
?_]w?0
7 `yA
~-6Se
YA'Iw6
Fs)<Rn
?QB )]
3QiO9$
**uh/.c}
-lC!]I
2_~ic#
7OED@+
Ci0]ib
`/V`;zQI
+d?|];
rFkOWF
7?:+Z&B
^i4#0}
-0|BlN
V^dxL>
N+)"K^1
Wr`>j@
mf5N&e
l9GjO{R
;qXsahtk~}
4j@(QQ
^fkdYu
9ZCWG E6
8@0:'}X~A
w$eS}%
MN% m/
T7^8QX
aZH*/s
3)dK#|E;
+D|1!]
iTnzNE
b[KcL<
ACxm^!
motHQ?
Rd}d0]r
?,y%=P
ENSLV[
z+b$cc
YHY~v
RZQB21Z
J:?pu>
zcQfa/
69q3Ao}
j_!'/@
Encg(UHY
){A];X
"UOi3t
[pA`I/
V\w/#K
KV%`YtJb`
5/%L*.5
/R(-i:
g',zqN
;xDa]0
TFS;t6
HUpL{ZV
8s!(/Ve
U_eWW~
_e|>E^l
-2n|Z'
z[E~$m
QUZB=#
U2@m}O
XabM zAJ/
%)Uwno*99
y8Lxa7
hp.4UtH
}y7BZ`
D\.{jQ
4ST3v7
|6Ela%n
@lY>lE
+SF+>5
`[3}JlXW4
Uzxe%$fbW
>A?|4:
OYz&!x
UyVB;1
2Q&=HS*
)RQ8n$
#rWp&H
"/$OJ9
?JcCT2
X/g`j.
3J0X&gKW
*ExL7:
t`o(7X
;H[3e3%v
aEH,b5
KcC9Q5
E=}&=[B
G'xaH\w
^LUvB0
6y^`hr
3,JIh6
,Q&xEI
pt,hi{
S c,St
{*B%+8
Ib)azr
d;(;/1*g
W05u=n|t
0k<-G
~zSHNB
|>c]wE
qRPN)Wy$Ot
Xn LdN
dC1y@l
z[Wb4Z
Bb xD{
({&'I!
*JK4v>7
I&&o?7
zyH18AH
{d]hL"
@7L=D}9
?e$WFni
;K$-Y#
N%,h@4
pkPwx&i
^q/&G:
`Uv1J0oZ[MqI
gY?(/n
CFS|pT
L_^2V/m=?
d0~a$V
D2A0N-R
CR&HP"V
.Yx\SG
OX@SO2
rLfgS
sucLQ&B
[s0yaF*
2d\R*~
CXP~8%
Cb//2O
LR])x?B
0muK2**%
-Dj[;m
;E_j&=
sc{cO5
i3S+7a
PSL.NW
@:yg.h
[*Bn1
^)5hT:Q
;M/}*;
c2xNlb(z
Pu}PaB#
JBlCb
979f-(Y
R_%\Z<c
Ox5DI^N
3ndg6z
LG0AOt
/IXh:;xU
tgKg$?E
G4g$!K
~:.~'.
[[[HVq@
~?S+6qR
E*E0;d
I>Fe )N(Re
8<tjV\@A
g8$ztbv
'9BV#,
=NM;S]V2n
+"s%C(
r2(\Sg 92
`iN~R.11
9!]j@=
,%pV/.{
t*lf6wf
yUTRbtO
6l&kob8
+" Dq)"
,}]X)M+
a#yw}3#eUr
juyWH+
uST[m%
Cwxpk2
U_?{U*J
NydZxk
Z?l~Cb
W7%$I)
N,{^TYu
t=q(AB
c1)I$3
o:}B4x
0Ynhf.?
C4se[G
+H,^;
{s0~brx
VD3rn(
\j"5`k
,\S(;!
!.MrXx]Z2
/Z'weMf[
S*Vb{F
m@wRt;
mKNx/9
nT3acU
LriV3P
\"lf;T
qw IB8!W
Xfh8yY
g=(Ae])
BNI~10g
0GH;(L
1a$d"Z@
O"v\.)
Y+n)Ww
8d#o3C
2'eMKg
:p!fj`j
xu9V-m
svc9&F
7"daE(
i<$7N
f0F`Ll-?
pGm3JT!
+kA$Pw>m
Xr$FcJ
rhAjUt]
RC_{g"C=
g$Wq{n
N6:HEz
JV?~,W
IKFJ- =
H@9ANv
i}'f'I
FpD+&'
x3#(2&O
nz1!!Oa.]f
uC|Doc
Vw;S4A/
?D[2 }
PKgQUFa{
(uo~g$
r{FD|+
>A#DC9
QrRUl*
sBZ{n,38H
}k+,@1D
crnT"
?9Q3eny}0
Knq#BUyC
OHyY==
W`e?-'*|>
|$vANI
k/o45,
r\DeDh9
3!x6h|f%
cj\"_~G+L
k)4-`n
bPAe{7
GvXs)P
"u`n8o
b+Jpr^
91/ex!g
iSwJ*cWe
+c2 iFK)
*^[*eE'
ErI&,/
(Pv/RA
$/%T53xcb
14"HuT1J
5/42b[
b<$;'<.
nz[m(rg
Ch"C3YPD*
pr@j|#
=o;|Ep]
"tU=>Q
PSJK_^
}.5hti
-r\KDtB
dI{YRe
WSOn}l
b$eUKx
[mdMn!
@<fWb'
zf(h-0
*tY}J
(YEd*\N
X>:?764M
qM2gze
M'53}|
uM} -\O
yXBaL{|
R8Km+O
G^CsVp6Y
\wv/?M
m ueqF5
Hb.>+f
=pq_~M
4;_XPc
'"'t$WejX
AA{:4D
J|/Lnd
2mTTt
}(p).>YO
:2j%G<|i2
-;^_!2
_z],ySd
:7<JWh&
yWs$K{
X@lL)m
{9Ibv
J&#DLn.2
eYvwJ)
\4HM\jz
>iFsc$
B[uWsf
n%8z9}
26?8EN@
;7U*D5
R%VHwW
A6M5TR
C;xsrV
RGHd%
ohg>)zk
4N@m?
zP:|DB
UO3YN
hO]X=pN
HfD4hy
BqZ=(JjQ:cS
=wNs`"
y.R?~!
CA98~Ow
8`X/s&
E{;&W(
n!KSi>
nHmI~.
!68.{
f5Z.z
OJT,M o3
sY@nN~
.+Yc't%
2CnNq6
Wu" ig
O_Mf{3W
N"{f!x
w8c^ }#>]
51Uq&z
p+~QiV
EaN>!W
0b{EL4
!4'/1q
?!}lVGBF
If{V'c^"
/y.l8~n
O!:V(:
*9Zhe'
_T ?91
66e6&H-
Awf7y+
(+cQnjF
~_F<n*
g3G1at
TShya3
ph?MWB
F dI@:W
i) ('`
;;egFA
|HDA$5.*r/j
}Q^Rv9
ML4M6BtoR
":tfYa
F#uXZY
!C!n"
yy0F3<
mBjM*a
e]2.n7
:F%Yzs
[tmlZw`
R>_+>z
;v:770
fg|tLRKVj`Q
np<@T~
1C6}AKx
7eR~l,
zHyo"6
pLoV~"
,t$qJ
/DdF1]3
lp};:Y
O/wjj0|
aFO!*'
4~g>>M
#2J~^6
}chj P
m]~*BYw
m!* 9cO
[.p.v
E@F<IJ
{y2M"sG@:
wWGha/(dE
[=f0'f
AT/Iai
8&L`Hj
{*81>)Wa
@<!+u^b
TtZD&JIMQ
qo7'DL
rD;C$K:sY
<);>?\
A%22nW;
RA9;oQ
ss@pvy
w4!&g,
h:Z3q"
o1GZe$
l:8An&
OM*dyJ
L#hL`"
}^-$$f#
Z$nds^
OR*)`qf
c2%'uk
#j9(Z%
p;3)&/
&kx_-@
byo@Sa
9wkoaM
3r|<*3
LMiT~M
_52=^6K
-[/S1\
#rG>o@N
iQ04mv
]6(ZYO
V#<'vc
UF|d`w
wr=QBu
\z1?$k'
X+,=>u
l*`L7_N
b9xEv4.
_sf[r~
&;kl5H~
PbZ:(B
%p|8Jl
&(K^)C.(
`Ap;Og
HA:k*G
Xn^vWq
]6uu-X?
-K&iAK
9&i1wG
X/![J!
yk0*kRW
qX3#r@,f
d/wEa6
mgWr}Q
Q*+{=\
X-eU?2
C}&lnW
,JLZ,3
]P{~$y)
L'\#&*
4m:)ex
}GK.K9
u[CvKo%
6jl7r~
C{kI7^a/
p*_n8E
k\YAF%G
~$~iGl
I=6W.3
[D5Ew
Ae=G8W
2Qv<Uu
az~"Q&
yv.>p[
podQT4
^y:Iz,
fne;?j_
6kGLsSM
hZn*LB+c~
zZsPbR
krGY@5w
=. Vqb
?Zi?JX
a.!k}G
ny`lLat
lj@W~H
7>ZJwH
f%AFC<-
0Yz>Z7{
m;bXD;
VSF[*n
9 [!7g
FU4liE
8GRSj0
fG-P<dr
_$/vq*
|_0i{a
1XY]R&g
0mws6O&
NbIyBb
e(,xg0
lzd|af7k&V
9\Zne[?
`;)/uR@
F@?(bg
hY:U4G|
dP%rzr
=#iU"+c
2.uy]P
F('#k(t
u.u3!x
J8f;_c
8#Kxi*
h^w"kR
4<&}5lx4t
U!`6wX
F=:[Wlpd
'jO$]H^>
tEIFX)*
fH6jQC7
]wXgic?
eHjdSQ
h'$D23"
1|QE398d
HPwLS{~&
m%`5xH
o;5UjX(9
NL9}l;
aLRxsV
%^f[)U
SC{zWB
l\=!<G
g:DOgI
\ZUi{Z
}z&kca
?qevfN6
u]t!g3
Antivirus Signature
Bkav W32.WannaCrypLTQ.Trojan
Lionic Trojan.Win32.Wanna.toNn
Elastic malicious (high confidence)
MicroWorld-eScan Trojan.Ransom.WannaCryptor.A
ClamAV Win.Ransomware.Wannacryptor-9940180-0
FireEye Generic.mg.84c82835a5d21bbc
CAT-QuickHeal Ransom.WannaCrypt.A4
ALYac Trojan.Ransom.WannaCryptor
Cylance unsafe
VIPRE Trojan.Ransom.WannaCryptor.A
Sangfor Ransom.Win32.Wannacrypt_0.se2
K7AntiVirus Trojan ( 0050d7171 )
BitDefender Trojan.Ransom.WannaCryptor.A
K7GW Trojan ( 0050d7171 )
Cybereason malicious.5a5d21
Arcabit Trojan.Ransom.WannaCryptor.A
BitDefenderTheta Gen:NN.ZexaF.36250.wt0@aGEmS3di
VirIT Trojan.Win32.WannaCry.B
Cyren W32/Trojan.ZTSA-8671
Symantec Ransom.Wannacry
tehtris Generic.Malware
ESET-NOD32 Win32/Filecoder.WannaCryptor.D
APEX Malicious
Paloalto Clean
Cynet Malicious (score: 100)
Kaspersky Trojan-Ransom.Win32.Wanna.zbu
Alibaba Ransom:Win32/WannaCry.ali1020010
NANO-Antivirus Trojan.Win32.Ransom.eoptnj
ViRobot Trojan.Win32.S.WannaCry.3514368.N
Rising Ransom.WanaCrypt!1.AAEB (CLASSIC)
Emsisoft Trojan.Ransom.WannaCryptor.A (B)
Baidu Win32.Trojan.WannaCry.c
F-Secure Trojan.TR/Ransom.JB
DrWeb Trojan.Encoder.11432
Zillya Trojan.WannaCry.Win32.2
TrendMicro Ransom_WANA.A
McAfee-GW-Edition BehavesLike.Win32.RansomWannaCry.wc
Trapmine malicious.high.ml.score
CMC Clean
Sophos Troj/Ransom-EMG
SentinelOne Static AI - Suspicious PE
Jiangmin Trojan.Wanna.eo
Webroot W32.Ransom.Wannacry
Avira TR/Ransom.JB
MAX malware (ai score=100)
Antiy-AVL Trojan[Ransom]/Win32.Scatter
Gridinsoft Malware.Win32.Gen.bot!se54409
Xcitium TrojWare.Win32.Ransom.WannaCrypt.B@719b9h
Microsoft Ransom:Win32/WannaCrypt
SUPERAntiSpyware Clean
ZoneAlarm Trojan-Ransom.Win32.Wanna.zbu
GData Win32.Trojan-Ransom.WannaCry.A
Google Detected
AhnLab-V3 Trojan/Win32.WannaCryptor.R200571
Acronis Clean
McAfee Ransom-O.g
TACHYON Ransom/W32.WannaCry.Zen
DeepInstinct MALICIOUS
VBA32 TrojanRansom.WannaCrypt
Malwarebytes Generic.Malware.AI.DDS
Panda Trj/RansomCrypt.K
Zoner Trojan.Win32.55605
TrendMicro-HouseCall Ransom_WANA.A
Tencent Trojan-Ransom.Win32.WannaCry.kd
Yandex Trojan.Igent.bUj9pX.12
Ikarus Trojan-Ransom.WannaCry
MaxSecure Trojan.Ransom.Wanna.d
Fortinet W32/WannaCryptor.6F87!tr.ransom
AVG Win32:WanaCry-A [Trj]
Avast Win32:WanaCry-A [Trj]
CrowdStrike win/malicious_confidence_100% (W)
No IRMA results available.