Static | ZeroBOX

PE Compile Time

2021-12-29 16:34:11

PE Imphash

4328f7206db519cd4e82283211d98e83

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
0x00002000 0x00004000 0x00001c00 7.92483843647
0x00006000 0x0010fcf7 0x00066000 7.98435965892
0x00116000 0x0000000c 0x00000200 4.40019804224
.idata 0x00118000 0x00002000 0x00000200 1.14055315347
.rsrc 0x0011a000 0x00016400 0x00016400 4.85040760648
.themida 0x00132000 0x00352000 0x00000000 0.0
.boot 0x00484000 0x001f6800 0x001f6800 7.95146043846

Resources

Name Offset Size Language Sub-language File type
TYPELIB 0x0011a1a4 0x000011bc LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_ICON 0x0012bba8 0x00003786 LANG_NEUTRAL SUBLANG_NEUTRAL PNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced
RT_ICON 0x0012bba8 0x00003786 LANG_NEUTRAL SUBLANG_NEUTRAL PNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced
RT_STRING 0x0012f340 0x00000388 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_GROUP_ICON 0x0012f6d8 0x00000022 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_VERSION 0x0012f70c 0x000003d8 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_MANIFEST 0x0012faf4 0x00000723 LANG_ENGLISH SUBLANG_ENGLISH_US XML 1.0 document, ASCII text, with CRLF line terminators

Imports

Library kernel32.dll:
0x518078 GetModuleHandleA
Library mscoree.dll:
0x518080 _CorExeMain

!This program cannot be run in DOS mode.
`
@
B.idata
@.themida
nXVNXJ
`AQx9[
V}4"e!n
h.UNuP
e/j`_
W#GbXp
AnonymousMethodDelegate6
<Stop>b__7
get_UTF8
CS$<>9__CachedAnonymousMethodDelegate8
<Module>
WM_DRAWCLIPBOARD
STEAMTRADE_LINK
ETHEREUM
AntiVM
WM_CHANGECBCHAIN
System.IO
C?-0Ay%
S>1M?
l{al2v
l&CQL*
U8rZ2<
G`)[/$
*)ur\}
)\.'W+
`[rO/=
$]#`+t!
C)>L4
cfgD+I
f2S*F3(K
tZ(`4-
LTW{+r5
6\OT/U
qLRK )>
0YvO];H
a,R\jv
HYOXz-
j1u(rX
FF#GU
Q"B ^=
$C3]Jl
NYVZW|
5R?/"#
ITiAW/
%I|+e W91qo
)=w?^>
}"If"
-J%AiPWw
BE5kz*
W %?la_/)
Z?)Kl"
$3-mn-?
F(Mw.p}
FEnd2qp
W@W~x'*l
`C7kRs
/@m2+-
F-4=.!I
t_M&b@
=>Rh;)
i|8.F,w
\dd>r5*`5
d>$?*`
57B)9?
n UZ*<ZJB
H>=>h'!<
4SUlG[
-N\^@.[%'W
}7"!4E0\!
# 5M%b
|!693\
&?E L3
=&;V?~_vdH6y
Zg9O$$
wO.`Yr
FB_Sb2q
<O4/1)
I8?#Y6
)QW|_T$
vjWys}_=
T-Pd5mI|
%P?I.|
%b%y[T8
vn9=8k
TqCO,:i
?S^.|U
f;en$u
y;{x>
yC.~Wj2
|<!4C
i=:+25
2S}vBa<
Q*)^!.
Q1zl'cc3;Q
o<+I2j
a1@4550T
AMB.$9
vcwO=[
l}Bz6;
Hlxe&t
:D9t4G
1c=2.z
ns(A]s
7vY&vS
]Su yM
>L6 <R
4Lr2"f
LZXZuy
XMM#!8
~cIc2j?
FFb@2,%
|!S3U<~,
Hkbd</
d_Qc\K|3
rH{qO$
[q.1x~
Q[zrk4
X{90ms
4+wCWyC
e{-dWhXo_
YbzU j
g8&s1#
2#>uzm
tg7A,E
#V*J@}WN
=FPPIWB
B]3~W0
J&_IW`
:> 1snVL
l#YrNS
yI2+<eEN]
(!av^B>
W[h\Q=
1rrzS#
[Z7>,3a
"?u1H<f
xP/[Eo
F~iCp]
2e_kce
5RY##fI
c67}/x
w]7>e3
=%~r1>
zXYtvM'
|py'62\
{T^->a
Ld|b4p
a?aO8<
d.oloB{
cyH{[^uw
yPXPW1
&;,>A4
M11<FA
OhwlLRlK8
q@~qdcZ1
[HO"Fw
|Zf-qFb
dV:Njc
1M*:T'
(&k M8
,X4"Y&
<fWEey
p5"P2{.
vG^eu-B
v[E!FS
]C[bex.
eh`3F!
"&p;%'e
-{c)&
lJ[%"
/Zx-[FD
`I"-*pAl
):uTB9/(
$-$i7
]btulr
CW[`7r
*'r-".
T9>>a=
>o6[8+
-M`9,K
SN:2?Q&
5<{%5,
I',L&1
7Zo`t<1po
1\rb*\
4S)i1tO"
#Tj/:_p
7UQfs<5
e+:1T*
h1b=_JE
#{2{IkR
9CK`il
ipQrcF
U%l*ZF&
EUL$"(
M_<hP%
Mym!kS"
}_Pa\=>
=74L;/
`@qdE)G
$"'7pP
/f<"E`
/m.p<s
HQ9_y%j
_\<-|zC
bnt /
{7#~/p6
t=sb)X"o9EN
`Pp$}
EJ,Y%(e
h-F7S,
-G+\Jb
-NI*}F
'!GHV$B7R
c_D9X'
-f/EW8
{*L?vl
P3/q2~6
Rn7T 2
M'%/+t
^SADAe
cO(jJ[
WQv&s4
B"qyJD'
4,}L2u
zdS|},
H5K!R
4:>f7%
X!Sl|t
P>?6TI
aCO%bg}
HUlS_~z
0{`b1z
@g9dj+|
ZgJelC
3s4m|2
$V4CSFi
sd<qA
-2JeBBm
zM}!3)
"?4)Jy
h[*tG>
( 6EDZ
-2&vW?~
'{2;!Z
F"1G3E
thHwE:
zc{5n)X?W8^'
u/t6["
u32@&F
DiVrYQ
d,uk_Y5
wi-rrA=};
E$!2o]f
ZfOJwhp`
Z;:/t
*`/-$7>
:GAwaO
H%6Cb,:ga
/r"ek)!x
s~"2\!#
ov[N]u
<BbqyV|
(%j(.&>
YKrI,X
U-m~+N,
>A`.Fc
TJ>{<K&
p]>n\E
~(Ws|?=
6Qe)r_
D>y1&8G
)#X*<ZR
Sy?-:F
4,%3}.
6\,*%O
yE>;}Xm
IZh]4N%
;1sCmsn
O|7Eu%
6+`unxz
zUP44}.
Rka-R&
5A*g[j
pp<Vz,
(MLUG"JL\
PT\1bK
]{aRJ>vW*
d?&3a!y
~)TQnr
OH4ZV}]
/o-fh,*`
cKG;XN
E?g'8'5L
$VXs=Im
];[ur
CKL$m~Q
,-&[.I#
z@afD}y
@&gb&8
ehNNf=`'
T-SH6CE
+BJB~
QXJu}R
ag!MvL
ZCc>0z
f`O>~}
`o}'81
cr9`pb
1d`$=Pro
%8PTbxi
bI8&:y
}fy'[.
Dpi\D/
y)8I/&
#@$7z0Ze
FYe=g1
nSv2y2
$7'b}2
SW:EAZ
q-OA%]\
d@QX#<8
'Jc6NZ(}H-;
!I`2Q'
G@p/|Q9
9;9S 7p
m~bs(W
fG Bu#
,*3%>j
~r vla
%oI<`B
wIAy".Z_
*E1a;N(
oGaiW3
D,I3Ik
6{ihJh?
>Mkp1Xl
Vh: mF
U."{79
:_~f$B
UV!ZeZL.'
jQW60fw;
2TRa)t
+87ZBK
jA=O*I
PJz=!h
^"~(99c
=TuYDt)
RKe\d'Gm
xGrw64
(%_T;I
}nKFv*&
Hz8:iG
;zr}g
K5"31F
S,*2k]hY
,Tb#}R0#
~x~DQ
dwwPvh
y='"C7
4|&CWz%
}DP;G=
<1+>rs
,zPrG&
0Xvx.(
[e8h7%
|x%h1)
*)v#8Ub
*o;h
J IAq
tt%_g:
0Im([0
}j?!Yu~=l
)a=8;]?4
pJb Zy
' v[%l
S!eYiv
N+2>;Io
W#Bx[|
!")22>
mY)W}'
>1I(&dK
D~K(/Bp
C,yOYC
I3\Um,
zd95.I
kE0;6Y
^gd4)2
pB6H.HjQ
GHyoP<
%PXu4/{
VyR5R"
N0t~Ob
Iq|\FwT
>,/$#F
ED,:An
Qm!In+/U
|@iMq?
/~WBIk0
`uZ.3Z
"z,fPQ
VNSc/W
oj7!2D
.(tv"}Ht3
:[08 *&JA^
E]Iiy`
0nT^L&s(
ZlF!z-G}
uLfId3
j(VESnaj
~5('Ke
8;cVQM
5gtioF
O&I=/=
(d5F?C
Kq3<)l
sq^B:i
Y'l-OK
?`HkDR
c+K&`M
W3V1S$^Y[
F~Bm>e
99F`/C
}oVcLkQ
G\Z\U<
rYX.fs?0
iOJAF(
DI<8lyW
\ yHU7
KSB2A38
>&qQJe
M|{XU
P[$+t+
g ^m]Q3,
=9ZOl9
pK$kEf
U>R;?N
Gy*dM[
Q0N{r
o8}9-P
` jYVo
>WIxb|!
5D_.~I
3,G~L_
$nT5VE>
E31$D*F
?IT,K(
<6 9+%%
,L71d
-'EXH
iyyuCcy
[Wv%+*
EUMg1X
69^54#
\8;2G'
F.43b/
loh:O]
/bV1_T'
"/uP6+
5xh-^m
Hcc>}6
z.|6{j
HRP20g
g ~#2!
bZxQ!S
.7o:~c<]
H53T2G&{
0p.agO.cn
?RZ4jz
lIOPoL
VeQqa
Pb^q=)
.Sn!vE
JT@)NY
J3F"JtW
ba?ayR
}dcHNR
nI-'k
]g0iR}
zDyg`AR
T)]:j]
zPpFtf
P.cfp=M
-aa4h
%x-Dx@
|u?F6M
2*NyX[
msvtT}
Q5XpaG
vK\ONq
5JWL6j
&eR7q%
>L0B.=R
uc/z-
p]y`04
UYJ(!y
\U/**y
0P8P{E
LRP"COQ
cC_$(F
C`6")L
u[L-kZ"^6
&yOLX;
*m|b_6
!0bxUu
}@v|Tru
AkRPb<
@obCP6
?>%~|e/
|9"bTu
ug0{//
kN"?GTf
*>mO`w
[n=%H=
.!^z'c
vn-od=]7
MZR**n
-w"d+{
{CMb)X
0vl"y^
]=_1j&
l@Hq4b1a
;/|zNn
zO!A9 I
q!N,jq
U<P0=0*
kIrl}
.dxc!r
o%.$q(
,^D,/*7e
?"HdWL
&uZHHu
<J]l<sjy
? ><tj
e.b/43d
?"Nob@o
L#DqO;*sip
FW|pn$
5%S|;xZT
b@`yU%
e;/j-O
pn]n^=
RV9M7nc
=<'93H
<BnT(C
_b1[t*
$d(1lm:
)*R%q$
^pjSnd
|v=RA/
YdF7FZ
8#.wr&
acPReP
g6M|*.
n<,PRe
Ip$p&!
pGPY?*"s,1
'5lYE$\R
Gv<zyRy
UL?(%]
7B%B=b
#|aso#?
d2a-<.
e>bM~ee;
(|IVs.
P$5YR*
2+:<8`
~(u\.b
r^y'$
1&G50j9
zH9WV2
S20Yyx9
d"h*Do
mZ*2j.
^wiW}Z
uCVkp
JwXk4s[
uUnN{O
J-?r9<
zey M_
+j\t#NRc
Ga?954
|v6Et".B
Cx,-Rac
E&r.$LA
S)d]M`{H
AMau<fE
SDBhRb
%9(h#Ol
N+[K)m
qrj>oZ
&N|rK3
&r<(.H
?|ouFl
*z=2*!
v=2*"k
rm4h>]
g>)&*f
%DR>)A
$|]n*?aW
Un*bxS)
$n>MZ
-/9Y6c
3%4*L
5Wb"y
N#aU(=A
"L?vl
NKQxT0(
,mN n|N
DM%.MKf
@t"z2L5
#[#^-9
7^'p_F{
1!]9qa
flBVIJ
vPaRy:
DjlGJk
OG)uq*Iw
qNsI@w)
=wuuTg+
\.2\UlFp
<huCY
,A&$xL
Z$F^[-_
"oyuh4
ZR?Q|p=
f#EoGwp
-(o\BU
be``yc
L[,jh6
`>T]S[
G.~,\9
IpHnYx
mB69>"
-AWDB.c
*H^>+vp~
[Y">&&
>X%"qa
ebz{19K
I:!s\t
7;$k9/Hi#7)
~Kfx"=
asx-[jD
;\"dDU
"K4^m2b
1!ER66
{wB~(t
[`^Y=x
N*;J_W
<A<#((
*"^gEs;iw
\#z5oSq
`-eRN0
/AUaLof
e 2XU;S
sq"v+#<
f>c^l0
lh81:t9
^H}_jP:
UIf*H
#dysmC
gp=/:>
: l\I")|
p"SCoO
~lR-NTW
eSkG"rO
Q] a{A
ws|$?F
8yJ9!n
/81upu
RH:aN{h
dDn/D}"
sA?nPl
FEk%6Z!e!
G&Cn+ a
,mL5A(B
G(`$Im
^#<p/# p6#<p
moZ#cQ
b/A"c,M.
;21O}mi
8^t|o:
(|]k-Ym
ZA~z,R!u
C''9a5"
JARf%A'
E-}'A@
83`'5-3
4H:^VO
L)V)+I
]d|#upy
HN>0Q(",
8tHl`v
,DqSdL
KG8g)%vY
~F4} f
,p"TZ3
n5](*4
Fa"HF38p
/]/o)v
-q#t=@
SAFC"6
9"v4v>
Prl"RQ
PQ>)+c
Bdz%@_
3XV;>f
u"EX,M
c,#h`G
,B.*laj
P2h%_D
dea{BQ
kl-.N
kernel32.dll
GetModuleHandleA
mscoree.dll
_CorExeMain
stdole2.tlbWWW@
LSentinelUILibraryWWW
ISentinelUIDetailsWW
OnDetailsEventWW
IDetailsJsonWd
ISentinelUIThreatsWWd
vOnThreat
ThreatJsonWWd
OnThreatVerdictUpdateWWW
AGroupIdW
.VerdictWd
COnThreatStatusUpdate
+StatusWW
oISentinelConfigChangeWWW
OnConfigChangeWW
ConfigJsonWW
aShutdown,
ISentinelUIMitigationWWW,
JOnMitigationEventWWW
cMitigationAction,
OnQuarantineFile
;QuarantinedFileJsonW,
OnUnQuarantineFileWW
UnQuarantinedFileJsonWWW
8\,ISentinelScanEventsW
OnScanStartW
BasePath
kScanRequestSucceeded
gUIsReputationEnabledW
OnScanUpdate
ScannedFilesHigh
ScannedFilesLowW
TotalFilesHighWW
3TotalFilesLowWWW
wIsReputationStep
OnScanReport
}ScanStatusWW
]ScanStartTimeHighWWW
ScanStartTimeLow
ScanEndTimeHighW
ScanEndTimeLowWW
FilesScannedHigh
2FilesScannedLowW
mEMaliciousFilesCountHighW
MaliciousFilesCountLowWW
TzLogPathW
+CSVPathW
ISentinelUIDeviceControl
OnDeviceControlEvent
DCEventJsonWX
CSentinelUIW
Created by MIDL version 8.01.0626 at Tue Jan 19 05:14:07 2038
MMM+MMM8MMM<MMM<MMM<MMM<MMM<MMM<MMM<MMM<MMM<MMM<MMM<MMM<MMM<MMM<MMM<MMM<MMM<MMM<MMM<MMM<MMM<MMM<MMM<MMM<MMM<MMM<MMM<MMM<MMM<MMM<MMM<MMM<MMM<MMM<MMM<MMM<MMM<MMM<MMM<MMM<MMM<MMM<MMM<MMM<MMM<MMM<MMM<MMM<MMM<MMM<MMM<MMM<MMM<MMM<MMM<MMM<MMM<MMM<MMM<MMM<MMM<MMM<MMM<MMM<MMM<MMM<MMM<MMM<MMM<MMM<MMM<MMM<MMM<MMM:MMM.MMM
MMM+JLNMGKP]GKPaGKObGKObGKObGKObHKNbIJJbIIJbIIJbIIJbIIJbIIIbIIIbIIIbIIIbIIIbIIIbIIIbIIIbIIIbIIIbIIIbIIIbIIIbIIIbIIIbIIIbIIIbIIIbIIJbIIJbIIJbIIJbIIJbIJJbIJJbIJJbIJJbIJJbIJJbIJJbIJJbIJJbIJJbIJJbIJJbIJJbIJJbIJJbIJJbIJJbIJJbIJJbIJJbIJJbIJJbIJJbIJJbIJJbIJJbIJJbIJJbIJJbIJJbIJJbIJJbJJJbHKMbGKObGKObGKObGKObGKObGKP_ILOQMMM2MMM
ILO<nV?v
LMNELMM
f.{BJQ
7MIDATx
o;u)ygJ
e*a4aW
vY+m}5d
a@@/SHe
'$HZ!b
((Ui+nG
~+y$#c
!jDh6[h
TIAIWz
jF@Qf^
/p*pydF
z(25+Y?5
*$o;9#O
"ycP.;
ZD2vtO
3&#Fxp{0
FHi3TXj99
`tLA)Z^^
P*q~*xvD
wfggq
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0" xmlns:asmv3="urn:schemas-microsoft-com:asm.v3">
<asmv3:application>
<asmv3:windowsSettings>
<dpiAware xmlns="http://schemas.microsoft.com/SMI/2005/WindowsSettings">true/pm</dpiAware>
<dpiAwareness xmlns="http://schemas.microsoft.com/SMI/2016/WindowsSettings">PerMonitorV2</dpiAwareness>
</asmv3:windowsSettings>
</asmv3:application>
<dependency>
<dependentAssembly>
<assemblyIdentity
type="win32"
name="Microsoft.Windows.Common-Controls"
version="6.0.0.0"
publicKeyToken="6595b64144ccf1df"
language="*"
processorArchitecture="*"/>
</dependentAssembly>
</dependency>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v3">
<security>
<requestedPrivileges>
<requestedExecutionLevel
level="asInvoker"
uiAccess="false"
/>
</requestedPrivileges>
</security>
</trustInfo>
<compatibility xmlns="urn:schemas-microsoft-com:compatibility.v1">
<application>
<!--The ID below indicates app support for Windows Vista -->
<supportedOS Id="{e2011457-1546-43c5-a5fe-008deee3d3f0}"/>
<!--The ID below indicates app support for Windows 7 -->
<supportedOS Id="{35138b9a-5d96-4fbd-8e2d-a2440225f93a}"/>
<!--The ID below indicates app support for Windows 8 -->
<supportedOS Id="{4a2f28e3-53b9-4441-ba9c-d69d4a4a6e38}"/>
<!--The ID below indicates app support for Windows 8.1 -->
<supportedOS Id="{1f676c76-80e1-4239-95bb-83d0f6d0da78}"/>
<!--The ID below indicates app support for Windows 10 -->
<supportedOS Id="{8e0f7a12-bfb3-4fe8-b9a5-48fd50a15a9a}"/>
</application>
</compatibility>
</assembly>
XSQRVWU
]_^ZY[
;.zy>B
BH_FNT
K#lB5r
AOr<PD
XDH\i`
_|ShzL
Exceptio
uzq?@a
zKgw 1@43
a1QPaz
c3>"7/
(y}CV@$1KS?
@^!L|7`
/yv.fH
TzfI|&
j!M|1@
%E*1O)
@;ShD[
$_KOax
*wEYhcZ
h7g*2[
?c~sZ1
$f_I'
p<%2]V
~?hq<`"}
c$~4-!jcw
HAWw ?
dc!SZ
*],!7~)
)A$]qM:2
"9N;KP2
e*_J`b
.V)^ }
S/I=!
Qh]%o)_
0z4vCT
'YK|vJ
W;e!9H$
7[(3xm
4IN77X]PI
,6hB'[X
+H:nd%
b|tY?+
UdgwoaI{
$d8rO"
!1ogF
A]PG'(I
v/0^FP
_AVhc-
kNt3(0
0 oXx5Kw
]3-PA^
Jq?*|:`
B]w6Q^0
u$,m
o`|ZRf
fA@Kp@b
2~7l]-Ptd
@X%mPZ
heM):X
;'l/V>|%
wUQhn'
8nA%);
"WgJ%^
%ZTa{
x8`w*%
C)p6Qh
P)x|J:
e,)AST[
V``QhP
(K?^J
a~1~,b)X
%V6R]y
=HrKA'
-/(9R'TZv
%gw7@E
~P e#'H
u2r]91
M_*P%
SoKQ9e
CNz(j^
jh4~r[.
oHTJ@`
v:IK!x{
{W`4AR
@Xh}S(B7J
QqHOiT
nDPk8>4
}#o8](
,JUno[0t
'18|kd
ar'1|v@
-StJXf
`tUgL|GN
hPN*Cu
_@J{='}
+)f>Jq:~
p)u/C'k
nCk{QA
kWX-x(
%Ub(}q
M~</AX
Lgf,)P&
`[vyC>
wAR_hD
w:0ePh
/Xh7-:
HMpiLS@
A)x0qZ%!
f(/A'T
V,9'_D$
I(nOj6
!QEza5
EYsvaG
UTIhK(
%0P9;8
*p,\h'
\WYN-H
D1t;C2
!pPP@1
s[N{Rh
_O-}/f'
hD}=KL@^*0
Th</?%
o~Bwp8
TX{<_H
yx/C_V_
X!/s%P
%ew&P/^
r8/IgE*
B[y-S@
Z'0E(a
7o()`w
hbTEMU^
)4`Qhr
%9[XXN
xw|JQl8
DRfq1
HwoXBm2
kf}jPu
^qL9pC
N-k\J)J
Ve(&}Z@$
&K&VW1S^
5L8>HjC
SJ'BnO
z<i)(+
P1&Xfj
H%>M~#3
Os&)H:
%qPKjK
CUS%][
I3'*0%
zG^u6T[
H'zT~u
<%P9_d#
Kq[w6(
-@.kOe
2Q%TY>S
:q^-Z^8ZT
b6Qw^X
Y ^u9~
,!qF#W
o~S,R['
~Ta/vB
/Dkn1(i
)/!n*I
-E[~vq_
&O* @q
J;soKC
Qo`~LA*JW
gwBBb5;W
Mv'Td1v
%y>']H
I%9_EW'
KMF2%V
w7]M<0
.7Xaq
!Z]\Uy;:
F4?_Z=,
?ExitQ
V)"N,P
_aRo@
\}ff2,
nE[J)
B(3aV1
]%MqVx
k$[&`h
2`q) %
.)!(7/
h|b?.]
3~|OvP
A$`H)f
mbKiD^`I
3;uVj@)
`UhwI(
dxWhs-^
q%KF<7
ZUl\+1
||n'wa
/{YW)KW
`X:-&V
e}:3KO
PaH5z-+<
EYPA*H
-10v*}
(U-X`P$
^-T\s=
)WebZ_
h}IFJE
Ix-koXV
z!/deac
UuefCY
0~/b)c
8B^(32
_V2\_t
|HA9)H
AaI|po
/dumpstra
!'()uZ
tm(k"EZ
ugche4k
m*w@Y=
,EC>pv
rWl|@)
utPTZ2
Wnb~c%
{(X;,i=
:!b>SV]
RDiPos'S
7U)D]S
r(tp&K
c[_TbH
aO[X0i
^9+r[|
B&}\E@h<+5Ki
&kzVhW
o]Wrh~
WFQ)>v
^P@`k#?
F?0f$5[
+2&e9K
[0_eE>
Z_tCr]B
X1Ipg:
PhH-;{]
(wh=`)\XH5z
Cao_`Q
v\qObqo8
ocg`&&n
hH?_(x
;#}oz|
LG}@g!-M~
{@|hq0]}<m
)%W?X3
(4~T=,
\kD&A4
[>f2Rd
0a(}h4
WQ5i]F7
>u{-KwfQ
P)o`?0'
hS%"=v
uHO%xl
H}w`F:
R]vST@
1$e7wQ
-($%VWg
%D1cVX
?VuQMF
pil~OH
AW!.V']^
U?SIxA
:W^(zZ
-?WLPr
ojectNam
5^uUXE?
xNrAc#
`!v{[;/
t}YgVT9
PROC_I
8\`@!n
K>'<$T
jSwOu_}
'ByD3c
0Xh^;0
~c{*z\
hH*;`"
G[%U_E
i%JRY=
uqp[Zr
Y3{(:7
|Kue-
%lmz.5
=[t0,'
1tv#BX
Sw_{$-
Software
\WLk8I
Z{88Y?x
w^epQc
yKdQC[
0^O`3d
an,3`P
wYwh'
vFLIW+
w]\'iT
'1V :J
DL};\)
h+(|qW
D"]p<Y
P.!%4i
>Go<_<
SUuQJi
`Q--<Z
D(%{ht
X?PRd;
w0PRcX
l^})'!
e9\ a_
<yQD_t
YUV^i_
!0a5^.
HIW\TJ
S'#`Ws
W0L+;/9:z
fsWMxO
U3\g JD
\5J!|u
mIz%UG
?,{1V>Ui`
{UP:A)n
~; k1x
-G?v+)
6:[Sr
9jx^0k:
,J?v{%
GR}^\f
h,a$ZY
+3t!^5#
YOJcU^{
kQDgXu
%c]|b!:%f
~}Vl%}
.tc(!v
oa2.uQ
E~@hR/
MX)1'!
dMEy_TNq
';v!dx@<
gPCzOa
5J7,0m@cFL*
/getwwsO}
5n06LY
)7y!@*
//0gO!
]8l Jq
%&JQ6KUgs
H.i!>x8
)'B`\R
IW5{b:)s
Ps`o|z
.xoQ-0$
/]5~K0p
ot#xE?
Kba'~RU
F\UfY>
`Hw}f'
+,}8&s
Wh(37'Y_
Z_|[K
+z?SY
#EL$\@
Hf}!A:
ShJu6_
I 5%&
[=x! h
oYJl8|f
iP@,Ho_
This pr9og
FXBun$
<?xml v
4@='1.t0
UTF-8"sta
2;ur;:
ch(:2-<i
4nibf~tV
!<tru
dP0rv~lhg
'$G(g,
'R}FtZ[
hG8.:~
hRB_Gq
El1@(">
)J@\gwX
"!$;iY
1kj@W:c
0NW{_|TC
??A (h3&~
aQhE]%
f$%$<8
PTX~xx)
W8R':Q
&@9w8!
Lp%rW&
gV5 qQ
1_Re:!
0}v-B9
:"@7:)
yNk}ey
-MJ`(N
.@ )vw
k5z36Y
ZW&Uh9
xC:3!H%
{-z'hs>
r_VH@TX
_IN =#%d`
>I++2[
1T4%tHN![
[<w&}o
GWJ__:
`T7tZ{
hBqgn@*!dJ
{:Dp)+(
+#\<f
Cil#,Y
#!vP$td
#%tKRW
JiG/=
-7EC%U
3,'{ZE
]}R_L_
nXsoc:
HMi`fU
% dqU8Z1
Hw;yZB
'mYcnu
`|%-c`
H}Ez0g
(No3W.
1)2AM2
=QT[Y*
J]E;H%
SRQ+Hj
|!`0_-
Ai0^j%
'9F/O#%p
VR/J^@*
#^(Sv[
;%.&YM
JaN`|o`'V
hxnwN{
2,{m4E
@5{UrQ!
[n@O_X%{O&
RTZyGR
H'\w$\
V|0.d
Eb+7vd
o2gXBv
?h'8bZG
yV\)`K
hE/:TK
%)Bu@n21H
3hu5,V
~UR\Q-
ZA#9o
G1BWhw
mL&kJF
n'w`%l
@|-,'_~
F7~ifE
lg0uxT
{UdCOY
W6RBL-
-*JPi%
/U\lJYe
-z,;"5
'7O(x
tR&JcB-g
A+83}s0)
'W2W]Xw
@2bTmK5
q'+'E
L=ag\<
('\('q`{
581Softw
are\WinL
M7-~b
!%n%KP
\#>90i
i]Sx:9
/5]`[,BP
~`whUOG[@
>hqwr|
)@9<W/
=jK7@d
!2-&}v
?3u_>OH
WEIiQ3
Y+sVHS*
Y@{+}[^
GAov[G
g)]Bww-
>(D.3pH
yh|Lc
3nN1&k
?UN%$!
[[*?-2
5<o;T.
G"s~h@B?}
A\[ 7J;
Ln)\UYZC
wRhJ]g
aY{BP6<
?n9KC\E
i15.0e6
5A8!DO
/OR/MQo6!
qO-S@Z
@/clrt
*%Co"+
{Qk=$+V%
%O{eH.>
.'|4:vI
-zT_;^*
YXlR$Z
i)u{{e$
_49 VF
ij@.!Y
m0..spJ
f %9zP-
u/IrU/
d?w^Z_
/OyC}^
=bJ`UVU|OI
N}R[%a
.^RuyM
'H4_:
r5[}r`
-(iF9
nJz_\3%
PS7JkwlRX
3-UVqk
.;6KyW
;jI{)]
lE&!L3v
'94]li
0Ru\.Z\
+915Zs
|*ub&l
62ZIXl+
PWzi}rn
eHK2R\
[&G.%?{
LU\vH
showc3deg
0,31s9
hKCBbj
^W>`sn
sfSu/2
I.+orZ\
@h]J^?|
D}R.`H
!h:u+[
hNc'kY
!bli'\<
*d614P
LuNT`Y
i7u\5d,
^}a"7<
\R24XAx
+i>QsI
'q*L6}
A\KbTX
@hyomL
osplaDh
bI}qhi
0WN)xD
@{K6Rf
5w0iC>%
R @,ZQ%u?
aa417,
RPZX p
##@"z2
U#\YP]
5Pwth@
QUY]}z
K_OUT r=1%d;WL>
>G)kx_
-Qw2uW
2=@CP#e
^%t2[)ar
H-B|.N
%6~#xh
~[h|b)
AFQ2M//+
Iv*-lZ
LB~-?V
x-Dt~G
-]6|1!
uA?em
`5C.0_
kdNar!9z(
-.Ib?T`k}
Du7Ev1~!
l]H-l~
~-v.^J
? !.ZQ
_@e~?%z[
,lJ&kr
"`[|5%
z}v|aN8
793hn[N
$brW`%=
*{XQK[
!t{q]1
~`W[_G[
b6jX5I
/>o[%2T?
9J<\IP
\w@_A3
W} ^H.
6]Ca\J
/bugc9he
taCce8!4
]gSIvXo
NIrP%Qs
\-2z\
g-\]X3
CHo(>Q
%ucx(P
$`tJPR
_Q2rU%
}id~;ZV
)yhHL*
:[UbTuj_]6
6?>LC
iL?s|e@
Iwl4P^
0]El( %
PRh}y*
PVuVPR
~Y0?1N
}~"xy>s
E"'&5sW
Sc'xy^t
$<EsKg
a9:.-
C&RK\\%
Tk$wQ!
cC^wNwDiw
T=Zi|H
_I`ld(
BH@t!V6
ShHzNs
.=^N6;
?!kXwF
8@[3xq
'pnwye@
tn@hJKrO
&p-|_^
5^eF5%
'MBzQY
h|Rb4@A
"2;=y
V<DscL
Fg'-_gz
/[} -T
~"@\t~>
o`5O*_
Wx:/7>v
|BjhQ8@
*30YK)
VL^S
w@=Qg_-
s0P4z]
!={no|
(+B}:0
gT?AAa
2E'vwr
{2'wF,
0*&M@,k}
AUhJ+<
I}J{uV
X}[=7-
G>=)vJ
N0w;i)
`-^o@s
"g?mWI
}1@avr
-#:&]|
T,/XH=-
~g5p$}
/QkY5K}
v28X)7
^B,R='
?>dG(%
$=B\a`}
G&?fV@
s%WV2K
8E;E*
x,a=+
(FV%T^
WRQ%TY
PPU~sy)
ArBQV2
w`jE<v
u_Y]ROb
lX}f"K
%>O_H;p
={/skip
actCvexr
ZWYQZg
>"]R%k"J
6[#mQe#
iW{&'sB
rXH IU
3@ S:\
2=/y"-B
o7aWZ_*
^Xu9Z*
>9"@bf
AWw<LfLQ
KXp*I%\
'1}~h8
#@3%>m
Fhufw7
F`|LT^{
u7{,-B
8PP0XR
//[KzL
]UYRR2
W`N+\T
9xw(E
$o6? ~-
X76.E:Z
b$)0$A
?(9||/"
v`"[w'fO
-3]8D)
W:]oB@>}_
yHfmR'
00^c`b\
eO08hi
V`i1TX
,s Li&
~wcLCk2
iA@5u{}
PU2%`~
Z^QO}u
za6\WX_-'f
S'HvNY=;
(L:HbA
.Qnh)mY:
u~BiwP0(
]>A5O.
eU/euE
6V[ j@
jP$]m/
T>KvS>
+uOI`3
KQ8/Cp
-2Yjal
ShavR'
0*3lg'
^#19K7
ZD(-@o
x+--vo
uT-z_>
WuSP-x)
_}g~&2V
t()KZ0
#&[bk}
[.'}4C^
8]sEl
jXaDC[?
_1;31>
i|Dg1n\
Y%.U~.
ST[U[{D
2_NK=!3%
qpv_N[
fNLwBN
M#/3Q}
j:Ux?%9
>'U=@?
1WU)ud0
/W1`1/
,K~O4d
@T6 "9
KVViui
wl+{@
oY_tTi
0c9jwky
.]ZdHN(
XmF)oN
?W@k4V%
mgjmbT
!_ J>z
Rme0!|
YAP38KS
X3V`Yf
IR7@VI
K!cl%07
/yVk5Q
Uq-+eI
4$]R^d/f
UKzb{A
54z"PA
VT- ME
><>^1A
h={H5*
i])oQe
oAL W2/
Ye)'}f
L}wX* j%
0XA<Uk
,+K`;A
'PrA?)k
r{W\a8
1V9E=+O
9}og<%
6%U}m+
h\m\$7}
]0DIK!
r@?.m%
X^F*X(
3%lyuL
$j|'v)
Uh%QNb*#
Jxo/bQ
}V_ s3
_fM+PV
`f5+{y=o-
)_}]xy
+2$90!
dTg!RD
@*K~dR
}X|Q$_{
#s[a !
f1kVdw
;{ld{P_N
Rmsn>C
x98{<4
QW>m^9(
*!ST[>
mlRWp-
uHofl'
gY3CoD9
IF7$)t;
vo9BbX)
fz?{1:
3+G(IO
=:Y-8Q
(0+3Hg
dC?\@6
hSI/_zS
#:9<[K
g&iKM2
J}Y3`Q
'h=oI_
\x./o\
hoB5uD
h[-]@p
>F`*KA
#BSU]{
!0B12e
1J8lGLH
xopW3EHP
|Q756+
t":qCa
^@-w(i
P_7LB*Z
'"`P]b
`P2'}N
E@q#,3|
;Y5k1
13D=HI
T0DY6
d(Dip
<+"Af"
Tjp#'9
wuhIU&
X&+:[(
PI]J/s
%+,v=A
0IA2"D
~O$ya0]F
0_nURP
_{5Hx+>
|w^h%E
`\mh=s
~V/[^q
=0%MOV
z%|yl3e
F#0{0~
-y+{uu
l<PV/^
`h3jYVu
};]te
%p.HPv
r1#@cf
^u2hUm
IRW/H8
{cKue=o@
D`AhA)
u%[Yl|
I|,\/>
4pn{`g,/
E;aG3:b
^%%"zS-:3
LD|Q,h!
'U)UBV
Laq% 2A
f^9_}J
h??b(pt
C4(tV/
g#Ed}*
w<!d%R
UY&]Ir
@{HF-{q
1jID)2
sQ(5=B
UakP#t!!
-y]R\SD
xjTR#%
w0dq)<
DG-PVD
9SWxi@c]q\
p=c#1/
;Pn?"R$f
hzTrV@b
YK1df+
hR:'S*|
I`*T#_
.A'4w|
-Qy!RF,
$:Bt'v
'f:|-r
-Vs^8A
;.zy>B?
K}lhSJ
|.iw88
fPGo_O
YPgX@-b
0 Yr/:
VXHk-C
Shm-vZ[KHCW
'z|%PN
N-rw1fY<vsJ>
!MA+V~`
eK#V_F
K`LYs@
53u:[_
\[kWEy
L[u_>@
c'3L!<
lo}nO'*
'7Y2OU
nCU\]@
IEC%]ff
Al`)J%
L05I)R^
'L?4{=
a$?Vl{
bi\0P)#
)Y P3Q
Y p+8N9
FXUW+h
u1:30/
ii;5 (q?-
Ic^$\1Z
9u@fz9
P9OO}`
PUja1X
as^6yio
5Ak}Z)g
G`9r[;
O^[`Xn
w]'\4W
qZBp\*
0UB>Uvt
hOB{vP
x$7kn #
UdSE@@E
2l%1u]l
%}*h.])
AP/ZX'p6
hSy)5I
h=[)hH
DBR]ZV
)(}35N
fky}PM
C;s&g)
9C7.~Fo
aY#{%e|
{z`>i8$}
oePh;l
`h?I\[~
Zgj~oM
XbAIA<
A'NX|v
$&W(p_O[
;}dSl$
7]|u"b/
_V614SF
:@t$]F
h[?IB-
8XP-#
3Z:;"/1
IpHy48
OI|)C'
-UdFf)
,k/force
;F'['K
e$1hV
O2g@!
y>n`30
!VSz@ZAae)[
>$XnDS
}s"KRJ
Q?`"`#a
_PhUF#
hU\K%~
M?_0YI6*J0
ZPW,mu
H9lW_.
~uQ"I}
E0iwg}
GIUD|NV
@ }g#!
f"kD\a
QP-h-u
H<K2*^
aeM!"&<
B}?_Y$M
on1382#06
-8bQgI
-a*p~)
0}N3R2M
B!>q8`
1c,,M7
~)P F#
V0qGDcZ{/"
!Y6-L)W
ji;$Q
!ecwH(Da
t!?gp*
}f<:wt
x+)3U-
-T[R9
vT1CRh
"F5dVh
1E^"X?p
7]4-;^
cont=y
Th}a}k}ycu
CTRLu+
w'0hS_
SOFTWA
2Z).@
9pcb:D
FYhi NU
c6~98n
j@t^N[
^PWO_[Q
7^UT1V
|pn=]<
9uG?Dn`d
G+k`4`"
fyKBk2WE
s S(>`r
IAp6mc
VYq%G-
0LjR]q
wYfB10
bJ({6Wf
N29[8
V$f~!_e
/qP2P`
hOqbD`
vy1&Z)g
>$Q`h#
FhK?%
,-wn)Vn
s%P[V>R]
~GO)~h
R lN.?Z
TYXRs/
SWhT*_nE
Ff\5J[
[h,=x{
(U.N Rh
(^-AnoH~(P
@h.~#o
BSQWT$i
zeh'}e
&.6>defg
TjXKt/%~
MFi{_[(
vySdMu
ProcOUaT
8-PTKX
V~a>rl*
!v?p{8
9Ph$Z)
NUL1CO
rYPROCJ_
;.tzN?
yEzw|+ru
bA)d!p
n5#]$I
'Wgw#g
ab)>_O
ZAXZ}!
W,7HLn
*_9v^7O
}Zo@]G
d48CN`-
t0xE,I
v[%~w|
SO!lz-
UP0G*~i
07%|B :&W
B.mj`J
4P^,+%
IwQEiwZLZQ
ZJvs?K]a
9h 9{Q
sVi&5S
_HeJq"
+nBd=xw
wBj_d=EF
JT:JD^C
$SiH-te
Hj.bI#)
hE)sKz
uXF|ov
;a_ Mgb
-VkzTP
vulMj-
Ldi]IM
fnN[De
Vx@Xu$
R]mC! Y
RUh.!'Nx
sb4uFl
WAP_h7
geX)\>
-XRE:7
%\UYYRU
oP,[@AF
rx )?2
h#W_Q,
2lrhVU
6a~ 8
\P>8aI
h=FgB~
#iYoT<
]d!p:d
-XW2qW
$%E<Rj
wy>WhP
<o10Z"
pSpepnHt
FlB)-&
]+4H.*
*:SBvQ
f+bG[-w
u:-_e4
4k]"Aj
ZSWYO/
DG[`Qx
",}_Lf$
v/[a3
]f]2/p\
oYU[oJ
Q-\j[[
Q,+c[i
&Nuhu^;K
nzD>i`(
^ 0|s6
(g(`[
[F@-v`
'ViV[P
s.%W:BW
U{t/e$
Q%/tV7\
qI^bXh(
<+8'dJ
(Yvx@xg
c%Yu[Nn
)Bi\'%Y
B2B]\MZ
e&3I\9)
hcx/{X=a
@RSO\
H=9yZg
!%PvcKu
Antivirus Signature
Bkav W32.AIDetectMalware
Lionic Trojan.Win32.Convagent.trYj
tehtris Generic.Malware
MicroWorld-eScan Clean
ClamAV Clean
FireEye Generic.mg.6375b46cec76be55
CAT-QuickHeal Clean
McAfee Artemis!6375B46CEC76
Cylance unsafe
VIPRE Clean
Sangfor Suspicious.Win32.Save.a
K7AntiVirus Clean
BitDefender Clean
K7GW Clean
Cybereason malicious.53ab74
BitDefenderTheta Gen:NN.ZexaE.36250.DE0@ay!aLPii
VirIT Clean
Cyren Clean
Symantec ML.Attribute.HighConfidence
Elastic malicious (high confidence)
ESET-NOD32 a variant of Generik.CPQZQT
APEX Malicious
Paloalto Clean
Cynet Malicious (score: 100)
Kaspersky Trojan-Banker.MSIL.ClipBanker.bzp
Alibaba Clean
NANO-Antivirus Virus.Win32.Gen-Crypt.ccnc
ViRobot Clean
Rising Trojan.Generic@AI.100 (RDML:krhChcilwX2AmqXy6pnz8g)
Emsisoft Clean
Baidu Clean
F-Secure Clean
DrWeb Clean
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition BehavesLike.Win32.Generic.vc
Trapmine malicious.moderate.ml.score
CMC Clean
Sophos Mal/Generic-S
Ikarus Clean
GData MSIL.Trojan-Stealer.Clipper.JDCSH6
Jiangmin Clean
Webroot W32.Dropper.Gen
Avira Clean
MAX Clean
Antiy-AVL Clean
Gridinsoft Trojan.Win32.Downloader.dd!n
Xcitium Clean
Arcabit Clean
SUPERAntiSpyware Clean
ZoneAlarm Trojan-Banker.MSIL.ClipBanker.bzp
Microsoft Trojan:Win32/Wacatac.B!ml
Google Clean
AhnLab-V3 Clean
Acronis suspicious
ALYac Clean
TACHYON Clean
DeepInstinct MALICIOUS
VBA32 BScope.Trojan.Wacatac
Malwarebytes Trojan.MalPack
Panda Clean
Zoner Probably Heur.ExeHeaderL
TrendMicro-HouseCall Clean
Tencent Clean
Yandex Clean
SentinelOne Static AI - Malicious PE
MaxSecure Trojan.Malware.300983.susgen
Fortinet Clean
AVG Win32:DropperX-gen [Drp]
Avast Win32:DropperX-gen [Drp]
CrowdStrike win/malicious_confidence_90% (W)
No IRMA results available.