Static | ZeroBOX

PE Compile Time

2023-07-03 00:42:59

PE Imphash

9b8bc88ec2effd02d5a41d9eb86ed569

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x000291f2 0x00029200 6.64408951466
.rdata 0x0002b000 0x0000f2a4 0x0000f400 5.42246201073
.data 0x0003b000 0x0002530c 0x00024400 7.95073546648
.rsrc 0x00061000 0x000001e0 0x00000200 4.71767883295
.reloc 0x00062000 0x000023d0 0x00002400 6.55548829831
.Sider 0x00065000 0x000ab054 0x000ab200 0.000768125899342

Resources

Name Offset Size Language Sub-language File type
RT_MANIFEST 0x00061060 0x0000017d LANG_ENGLISH SUBLANG_ENGLISH_US XML 1.0 document text

Imports

Library GDI32.dll:
0x42b000 Rectangle
0x42b004 GetDCBrushColor
0x42b008 GetViewportExtEx
Library ole32.dll:
0x42b190 CoGetApartmentType
0x42b194 CoGetObjectContext
Library KERNEL32.dll:
0x42b010 CreateFileW
0x42b014 HeapSize
0x42b018 ReadConsoleW
0x42b01c GetModuleHandleA
0x42b020 FreeConsole
0x42b024 GetModuleHandleW
0x42b028 RaiseException
0x42b02c GetCurrentThreadId
0x42b034 GetLastError
0x42b044 CloseThreadpoolWork
0x42b048 GetModuleHandleExW
0x42b04c MultiByteToWideChar
0x42b060 InitOnceComplete
0x42b068 GetStringTypeW
0x42b06c InitializeSRWLock
0x42b07c WideCharToMultiByte
0x42b080 CloseHandle
0x42b09c EncodePointer
0x42b0a0 DecodePointer
0x42b0a4 LCMapStringEx
0x42b0ac GetProcAddress
0x42b0b0 GetCPInfo
0x42b0b8 SetEvent
0x42b0bc ResetEvent
0x42b0c0 CreateEventW
0x42b0cc GetCurrentProcess
0x42b0d0 TerminateProcess
0x42b0d4 IsDebuggerPresent
0x42b0d8 GetStartupInfoW
0x42b0dc GetCurrentProcessId
0x42b0e0 InitializeSListHead
0x42b0e4 SetStdHandle
0x42b0e8 RtlUnwind
0x42b0ec SetLastError
0x42b0f0 TlsAlloc
0x42b0f4 TlsGetValue
0x42b0f8 TlsSetValue
0x42b0fc TlsFree
0x42b100 FreeLibrary
0x42b104 LoadLibraryExW
0x42b108 ExitProcess
0x42b10c GetModuleFileNameW
0x42b110 GetStdHandle
0x42b114 WriteFile
0x42b118 GetCommandLineA
0x42b11c GetCommandLineW
0x42b120 HeapAlloc
0x42b124 HeapFree
0x42b128 CompareStringW
0x42b12c LCMapStringW
0x42b130 GetLocaleInfoW
0x42b134 IsValidLocale
0x42b138 GetUserDefaultLCID
0x42b13c EnumSystemLocalesW
0x42b140 GetFileType
0x42b144 GetFileSizeEx
0x42b148 SetFilePointerEx
0x42b14c FlushFileBuffers
0x42b150 GetConsoleOutputCP
0x42b154 GetConsoleMode
0x42b158 ReadFile
0x42b15c HeapReAlloc
0x42b160 FindClose
0x42b164 FindFirstFileExW
0x42b168 FindNextFileW
0x42b16c IsValidCodePage
0x42b170 GetACP
0x42b174 GetOEMCP
0x42b184 GetProcessHeap
0x42b188 WriteConsoleW

!This program cannot be run in DOS mode.
oRichu,
`.rdata
@.data
@.reloc
B.Sider
L$,_^[3
;D$,s\
D$ _^3
D$4_^3
D$8SVW
L$D_^[3
VWhpiC
D$,j@P
D$,j@P
D$(j@P
D$(j@P
CD$DPRQ
CD$@PQR
D$8QPS
CD$$)t$
CD$PPQR
D$<QPS
CD$4)t$
L$<UVWj
tC97u?j4
QQSVWd
URPQQh
UQPXY]Y[
PPPPPPPP
<ItC<Lt3<Tt#<h
A<lt'<tt
<ItC<Lt3<Tt#<h
A<lt'<tt
F +F4+
8^8tb9^4~]
V +V4+
tb9^4~]
PRRRRR
ARPRQh
jYjf
uSSSSj
SWt@jU
_tqPVj@
M,j"^QRRRRR
Vj0XPW
r!SSPVQ
dr#SSjdVQ
M$j"^QRRRRR
j"[VWWWW
_PVVVVV
j"_SVVVV
PVVVVV
^PSSSSS
j"^WSSSS
WVVVVV
PVSRSQV
PVVVVV
PWWWWW
PPPPPVW
PP9E u!PPSVP
f9:t!V
QQSVj8j@
NX9^`t1
;V\uYW
u2Vj@h
9C`u99C\t4
u29K\t-
^PQQQQQ
E ^PQQQQ
CY<u
uThL$C
D8(Ht'
D8(Ht5F
L:-^_[
PPPPPPPP
bad exception
bad allocation
Context callback failed.
bad function call
device or resource busy
invalid argument
no such process
not enough memory
operation not permitted
resource deadlock would occur
resource unavailable try again
success
address family not supported
address in use
address not available
already connected
argument list too long
argument out of domain
bad address
bad file descriptor
bad message
broken pipe
connection aborted
connection already in progress
connection refused
connection reset
cross device link
destination address required
directory not empty
executable format error
file exists
file too large
filename too long
function not supported
host unreachable
identifier removed
illegal byte sequence
inappropriate io control operation
interrupted
invalid seek
io error
is a directory
message size
network down
network reset
network unreachable
no buffer space
no child process
no link
no lock available
no message available
no message
no protocol option
no space on device
no stream resources
no such device or address
no such device
no such file or directory
not a directory
not a socket
not a stream
not connected
not supported
operation canceled
operation in progress
operation not supported
operation would block
owner dead
permission denied
protocol error
protocol not supported
read only file system
result out of range
state not recoverable
stream timeout
text file busy
timed out
too many files open in system
too many files open
too many links
too many symbolic link levels
value too large
wrong protocol type
unknown error
GetCurrentPackageId
GetSystemTimePreciseAsFileTime
GetTempPath2W
0123456789abcdefghijklmnopqrstuvwxyz
0123456789abcdefghijklmnopqrstuvwxyz
SleepConditionVariableCS
WakeAllConditionVariable
__based(
__cdecl
__pascal
__stdcall
__thiscall
__fastcall
__vectorcall
__clrcall
__eabi
__swift_1
__swift_2
__swift_3
__ptr64
__restrict
__unaligned
restrict(
delete
operator
`vftable'
`vbtable'
`vcall'
`typeof'
`local static guard'
`string'
`vbase destructor'
`vector deleting destructor'
`default constructor closure'
`scalar deleting destructor'
`vector constructor iterator'
`vector destructor iterator'
`vector vbase constructor iterator'
`virtual displacement map'
`eh vector constructor iterator'
`eh vector destructor iterator'
`eh vector vbase constructor iterator'
`copy constructor closure'
`udt returning'
`local vftable'
`local vftable constructor closure'
new[]
delete[]
`omni callsig'
`placement delete closure'
`placement delete[] closure'
`managed vector constructor iterator'
`managed vector destructor iterator'
`eh vector copy constructor iterator'
`eh vector vbase copy constructor iterator'
`dynamic initializer for '
`dynamic atexit destructor for '
`vector copy constructor iterator'
`vector vbase copy constructor iterator'
`managed vector copy constructor iterator'
`local static thread guard'
operator ""
operator co_await
operator<=>
Type Descriptor'
Base Class Descriptor at (
Base Class Array'
Class Hierarchy Descriptor'
Complete Object Locator'
`anonymous namespace'
FlsAlloc
FlsFree
FlsGetValue
FlsSetValue
InitializeCriticalSectionEx
(null)
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
[aOni*{
~ $s%r
@b;zO]
v2!L.2
CorExitProcess
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
AreFileApisANSI
CompareStringEx
EnumSystemLocalesEx
GetDateFormatEx
GetLocaleInfoEx
GetTimeFormatEx
GetUserDefaultLocaleName
IsValidLocaleName
LCMapStringEx
LCIDToLocaleName
LocaleNameToLCID
AppPolicyGetProcessTerminationMethod
NAN(SNAN)
nan(snan)
NAN(IND)
nan(ind)
Sunday
Monday
Tuesday
Wednesday
Thursday
Friday
Saturday
January
February
August
September
October
November
December
MM/dd/yy
dddd, MMMM dd, yyyy
HH:mm:ss
_hypot
_nextafter
1#QNAN
1#SNAN
]vQ<)8
|)P!?Ua0
Eb2]A=
u?^p?o4
y1~?|"
?x+s7
?5Od%
?|I7Z#
>,'1D=
?g)([|X>=
~U`?K
:h"?bC
@H#?43
Ax#?uN}*
r7Yr7=
F0$?3=1
H`$?h|
&?~YK|
sU0&?W
<8bunz8
?#%X.y
F||<##
<@En[vP
b<log10
?5Wg4p
%S#[k=
"B <1=
Unknown exception
bad array new length
string too long
generic
iostream
bad cast
bad locale name
ios_base::badbit set
ios_base::failbit set
ios_base::eofbit set
take it everywhere
CreateProcessW
ntdll.dll
GetWindowsDirectoryW
ZwWriteVirtualMemory
VirtualAllocEx
GetThreadContext
SetThreadContext
ReadProcessMemory
TerminateProcess
ResumeThread
Fail to schedule the chore!
This function cannot be called on a default constructed task
broken promise
future already retrieved
promise already satisfied
no state
future
Chicago
1337 y.o
invalid string position
vector too long
iostream stream error
.text$di
.text$mn
.text$x
.text$yd
.idata$5
.00cfg
.CRT$XCA
.CRT$XCAA
.CRT$XCC
.CRT$XCL
.CRT$XCU
.CRT$XCZ
.CRT$XIA
.CRT$XIAA
.CRT$XIAC
.CRT$XIC
.CRT$XIZ
.CRT$XLA
.CRT$XLZ
.CRT$XPA
.CRT$XPX
.CRT$XPXA
.CRT$XPZ
.CRT$XTA
.CRT$XTZ
.rdata
.rdata$T
.rdata$r
.rdata$sxdata
.rdata$voltmd
.rdata$zzzdbg
.rtc$IAA
.rtc$IZZ
.rtc$TAA
.rtc$TZZ
.tls$ZZZ
.xdata$x
.idata$2
.idata$3
.idata$4
.idata$6
.data$r
.data$rs
.rsrc$01
.rsrc$02
GetViewportExtEx
Rectangle
GetDCBrushColor
GDI32.dll
CoGetApartmentType
CoGetObjectContext
ole32.dll
GetModuleHandleA
FreeConsole
GetModuleHandleW
RaiseException
GetCurrentThreadId
IsProcessorFeaturePresent
GetLastError
FreeLibraryWhenCallbackReturns
CreateThreadpoolWork
SubmitThreadpoolWork
CloseThreadpoolWork
GetModuleHandleExW
MultiByteToWideChar
InitializeConditionVariable
WakeConditionVariable
WakeAllConditionVariable
SleepConditionVariableSRW
InitOnceComplete
InitOnceBeginInitialize
GetStringTypeW
InitializeSRWLock
ReleaseSRWLockExclusive
AcquireSRWLockExclusive
TryAcquireSRWLockExclusive
WideCharToMultiByte
CloseHandle
WaitForSingleObjectEx
QueryPerformanceCounter
EnterCriticalSection
LeaveCriticalSection
InitializeCriticalSectionEx
DeleteCriticalSection
EncodePointer
DecodePointer
LCMapStringEx
GetSystemTimeAsFileTime
GetProcAddress
GetCPInfo
InitializeCriticalSectionAndSpinCount
SetEvent
ResetEvent
CreateEventW
UnhandledExceptionFilter
SetUnhandledExceptionFilter
GetCurrentProcess
TerminateProcess
IsDebuggerPresent
GetStartupInfoW
GetCurrentProcessId
InitializeSListHead
KERNEL32.dll
RtlUnwind
SetLastError
TlsAlloc
TlsGetValue
TlsSetValue
TlsFree
FreeLibrary
LoadLibraryExW
ExitProcess
GetModuleFileNameW
GetStdHandle
WriteFile
GetCommandLineA
GetCommandLineW
HeapAlloc
HeapFree
CompareStringW
LCMapStringW
GetLocaleInfoW
IsValidLocale
GetUserDefaultLCID
EnumSystemLocalesW
GetFileType
GetFileSizeEx
SetFilePointerEx
FlushFileBuffers
GetConsoleOutputCP
GetConsoleMode
ReadFile
HeapReAlloc
FindClose
FindFirstFileExW
FindNextFileW
IsValidCodePage
GetACP
GetOEMCP
GetEnvironmentStringsW
FreeEnvironmentStringsW
SetEnvironmentVariableW
GetProcessHeap
SetStdHandle
ReadConsoleW
HeapSize
CreateFileW
WriteConsoleW
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
I\'a[
%l_].
*s#LW}ja3
;e>AB])
Zr#h`e
.<.Rh]
)[Qj|;e
!U-SF$
7)YS<}
24G5 8iGuzw
`I5[&=%
vUgx:U
#P++=K
kG2* ~
CsAT,Y
z3r 55
3*;LX$~\7
>X|rk<QM
w/,Y5)
n^e[1<")
VJF&fo
or'g\k
BWPA$Z
|/1u~_6
y-p39S
B=lkyW%
hj.2(
kD_`/]
K\mM8G
|:E\o0
yt[hf$
TULXj?2
>@A'|x
=i%wl#
hWgrG{
fpH^,~
^Gz/TxM
!MKVKL]%
Wbxhv|
nJ5Z<W
)wXK f
P`BaT
'k],yDq
(*&*e8P
74#M557
"6XP,1
-3Pr9!
CG`t(+
%A&68!m
5[k;N\'
* PVTf
_km0C+
yz=\`>
K1@lX
lB10%
|@QSn )
UVz$gs
kL&.(v
^D9kMU
i|=]B. Ps
ZMeV5
@)vXEz
)T6JDs
#98A-n
:{PLT9+
Blu\=~:F
<8`8=N
!jV4|=*
9cnOMm
@F4|n.
3|^)%Q
04'Iyc
*,hyk~
mK!h3G
!tdF,!h
D4u&L1
7=\<R0sn
&:T1Fr
Y#A*,s4;
2/:WgP}
>At`^_
~>pTl2
N"r.Y"
G>^}KOo
lF/fw{j
68]1K{
f5/F}A
NQ"0$)
Ynts!w
b7BEOqc
q}g:H/`
=3M3l&
8x:njw/
bR8i6_
asxapty
P*Z@"@
#.J(u7
+(a&0P
DGJ0B*
Gtf{:4
eG1E^O
rN\-&8+
$hkwL.X
hVW]r|vNP
m)yqJ7
aLp")=
UVN}J@
gRwPwM
%;++V.
bo4|?w
JCKa2AA
`oh,_Y
VZ]<@#
;7J#,)Gj
%q>[U9
S.|+:Y
_W&*}e
P:*)7X
@?fkc7
>WfIlzL
1|A?JU
>8)I$&
aSNFK5iB
|#89F<`
^g\l4>y
8j@,ru]
0y y^/
Ed[*f{
g]:LNE
LVrHx(
?I7}kT
@E+?5|
oV8@[As
4oP@fs
X9'<;XA
Wje\,1
291CIJ
(DOP@V`
2~o7Tv
gOHbo"
im:T#=
WDGbG~
dz>bg$
`RWgDT
!L<X*&
%mH}DeFKmQ
P*/6Z-y
L$sxT6
|yYWMK3J_
xSxC0\
N'9@`B
#rO?2v\H
OC\]CV
d^11*/
w\v|8R
-MA>o~
&GY6\%d
NmG*wbWi
\Ch=p~
NclXx&L
aw`eZe
Gk$zRlR=
,k[tDlBo
j(a/IT
i('U^$<;}N
cIF(SB
,Iw6nagut
L/l{<h
>DU{g*
K.A3sL
s1Y.%dp{t
+tSjRZ
-E5 u?M
1_;{Ze
$$0gI]
D0Q8^Z
%ECwe]
dR<Sz""q
fKTb1k
Th(avp
y7zu6S
MB7?HfY
TXw?wU
[1.fUK
)M"LRvJ
H:syhVRt
IHq"vt
AA{McZK
E{:I^-
<r@>;$%
FCvY=p
9dxLKb
_ty<<k
yBe%HwO
D%]RRQ5
H8$5~r
^<Sb$Z
fr,PcM
]dj|ph
#pB7"
uAz:pp
F>&mJ-
*:}@E3
ARg[E
Vi2-gA6iX
V[s28J"(
0D&z]
tNFPKN
r$!*J=
<&,v%{
7kP/RS
Fo3|dh/
)zb7tLL
RnZsEz
<%|#fMg
<[YQijl
o.V_"80
>`=bGj
O2r#V(
})bA*W6
9kN'js
g%3X`v
gQU9A?
+KbAIR
!gN:6@o
NBx&KH0L
W*mCW}
Dk2}&#
24!yBl
@ZXD?%
=MedsARH
.?AVbad_exception@std@@
.?AVlength_error@std@@
.?AVout_of_range@std@@
.?AVbad_function_call@std@@
.?AVfailure@ios_base@std@@
.?AVruntime_error@std@@
.?AVbad_alloc@std@@
.?AVsystem_error@std@@
.?AV<lambda_1>@?1???$?0V?$_Fake_no_copy_callable_adapter@A6AXXZ@std@@@?$_Task_async_state@X@std@@QAE@$$QAV?$_Fake_no_copy_callable_adapter@A6AXXZ@2@@Z@
.?AVtask_canceled@Concurrency@@
.?AVlogic_error@std@@
.?AV<lambda_1>@?7???R0?4??_ScheduleContinuationTask@_Task_impl_base@details@Concurrency@@QAEXPAU_ContinuationTaskHandleBase@34@@Z@QBE@XZ@
.?AV<lambda_1>@?1??_MakeVoidToUnitFunc@details@Concurrency@@YA?AV?$function@$$A6AEXZ@std@@ABV?$function@$$A6AXXZ@5@@Z@
.?AVfuture_error@std@@
.?AV?$_Fake_no_copy_callable_adapter@A6AXXZ@std@@
.?AVbad_cast@std@@
.?AV_Interruption_exception@details@Concurrency@@
.?AV_System_error@std@@
.?AV<lambda_1>@?CC@??_CancelAndRunContinuations@?$_Task_impl@E@details@Concurrency@@UAE_N_N00ABV?$shared_ptr@U_ExceptionHolder@details@Concurrency@@@std@@@Z@
.?AVinvalid_operation@Concurrency@@
.?AVexception@std@@
.?AVbad_array_new_length@std@@
.?AV<lambda_1>@?4??_ScheduleContinuationTask@_Task_impl_base@details@Concurrency@@QAEXPAU_ContinuationTaskHandleBase@34@@Z@
.?AV_ExceptionPtr_normal@?A0x6e02efe5@@
.?AV?$_ExceptionPtr_static@Vbad_alloc@std@@@?A0x6e02efe5@@
.?AV?$_ExceptionPtr_static@Vbad_exception@std@@@?A0x6e02efe5@@
.?AVstl_condition_variable_interface@details@Concurrency@@
.?AVstl_condition_variable_win7@details@Concurrency@@
.?AV_Locimp@locale@std@@
.?AVios_base@std@@
.?AV?$_Iosb@H@std@@
.?AV?$basic_ios@_WU?$char_traits@_W@std@@@std@@
.?AV?$basic_streambuf@_WU?$char_traits@_W@std@@@std@@
.?AV?$basic_ostream@_WU?$char_traits@_W@std@@@std@@
.?AV?$basic_filebuf@_WU?$char_traits@_W@std@@@std@@
.?AVcodecvt_base@std@@
.?AV?$codecvt@_WDU_Mbstatet@@@std@@
.?AVstl_critical_section_interface@details@Concurrency@@
.?AVstl_critical_section_win7@details@Concurrency@@
.?AVtype_info@@
.?AV_Future_error_category2@std@@
.?AV?$num_put@_WV?$ostreambuf_iterator@_WU?$char_traits@_W@std@@@std@@@std@@
.?AV?$_Ref_count_obj2@U_ExceptionHolder@details@Concurrency@@@std@@
.?AVerror_category@std@@
.?AV?$_Associated_state@H@std@@
.?AV?$_Func_impl_no_alloc@V<lambda_1>@?1???$?0V?$_Fake_no_copy_callable_adapter@A6AXXZ@std@@@?$_Task_async_state@X@std@@QAE@$$QAV?$_Fake_no_copy_callable_adapter@A6AXXZ@3@@Z@X$$V@std@@
.?AV_Facet_base@std@@
.?AV_Generic_error_category@std@@
.?AV?$_CancellationTokenCallback@V<lambda_1>@?1??_RegisterCancellation@_Task_impl_base@details@Concurrency@@QAEXV?$weak_ptr@U_Task_impl_base@details@Concurrency@@@std@@@Z@@details@Concurrency@@
.?AU_Crt_new_delete@std@@
.?AV_Iostream_error_category2@std@@
.?AV_DefaultPPLTaskScheduler@details@Concurrency@@
.?AU?$_Task_impl@E@details@Concurrency@@
.?AV?$numpunct@_W@std@@
.?AUctype_base@std@@
.?AV?$_Func_base@X$$V@std@@
.?AV?$_Func_impl_no_alloc@V<lambda_1>@?7???R1?4??_ScheduleContinuationTask@_Task_impl_base@details@Concurrency@@QAEXPAU_ContinuationTaskHandleBase@45@@Z@QBE@XZ@X$$V@std@@
.?AV?$_Task_async_state@X@std@@
.?AVfacet@locale@std@@
.?AU?$_InitialTaskHandle@XV<lambda_1>@?1???$?0V?$_Fake_no_copy_callable_adapter@A6AXXZ@std@@@?$_Task_async_state@X@std@@QAE@$$QAV?$_Fake_no_copy_callable_adapter@A6AXXZ@3@@Z@U_TypeSelectorNoAsync@details@Concurrency@@@?$task@E@Concurrency@@
.?AV_RefCounter@details@Concurrency@@
.?AV?$_Func_impl_no_alloc@V<lambda_1>@?CC@??_CancelAndRunContinuations@?$_Task_impl@E@details@Concurrency@@UAE_N_N00ABV?$shared_ptr@U_ExceptionHolder@details@Concurrency@@@std@@@Z@X$$V@std@@
.?AV_Ref_count_base@std@@
.?AV?$_Ref_count_obj2@U?$_Task_impl@E@details@Concurrency@@@std@@
.?AV?$_Func_impl_no_alloc@V?$_Fake_no_copy_callable_adapter@A6AXXZ@std@@X$$V@std@@
.?AV?$_Func_impl_no_alloc@V<lambda_1>@?4??_ScheduleContinuationTask@_Task_impl_base@details@Concurrency@@QAEXPAU_ContinuationTaskHandleBase@45@@Z@X$$V@std@@
.?AV?$_Func_base@E$$V@std@@
.?AU_TaskProcHandle@details@Concurrency@@
.?AV?$ctype@_W@std@@
.?AUscheduler_interface@Concurrency@@
.?AV?$_Packaged_state@$$A6AXXZ@std@@
.?AU?$_PPLTaskHandle@EU?$_InitialTaskHandle@XV<lambda_1>@?1???$?0V?$_Fake_no_copy_callable_adapter@A6AXXZ@std@@@?$_Task_async_state@X@std@@QAE@$$QAV?$_Fake_no_copy_callable_adapter@A6AXXZ@3@@Z@U_TypeSelectorNoAsync@details@Concurrency@@@?$task@E@Concurrency@@U_TaskProcHandle@details@3@@details@Concurrency@@
.?AV?$_Func_impl_no_alloc@V<lambda_1>@?1??_MakeVoidToUnitFunc@details@Concurrency@@YA?AV?$function@$$A6AEXZ@std@@ABV?$function@$$A6AXXZ@6@@Z@E$$V@std@@
.?AV_CancellationTokenRegistration@details@Concurrency@@
.?AU_Task_impl_base@details@Concurrency@@
<?xml version='1.0' encoding='UTF-8' standalone='yes'?>
<assembly xmlns='urn:schemas-microsoft-com:asm.v1' manifestVersion='1.0'>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v3">
<security>
<requestedPrivileges>
<requestedExecutionLevel level='asInvoker' uiAccess='false' />
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
0!0%01070E0Z0d0k0x0|0
1%111;1E1U1Z1d1z1
2!22262<2C2N2T2Z2`2f2k2q2
5!545Z5q5
5]6}6v7q8
8(9a9t9
;,;L;f;
4=4N4S4
6J6Z6c6
; ;3;S;X;
<<=<n<
>5>F>L>P>V>c>x>
0\1`1d1h1
>!>'>->3><>@>D>H>^>
173L435<5r5
7W7`7q7
#0)0@0G0M0R0d0
0b1_2i2
=-=7=@=]=j=
?%?n?|?
2$2C2~2
3.3:3i3v3
4 4M4S4Z4q4~4
4]5l5I6f6
6.757s7
7C8k8y8
9;9e9y9
:8:@:Q:v:
<0=N=m=
>&>.>>>Y>f>r>
?(?Y?v?
090Q0d0y0
091J1Q1Y1o1
353P3[3y4
5(5;5W5
6$6*6F6S6k6
7>8[8h8
7!7)7/747=7H7
8+8O8`8g8u8
9;:K:]:
?%?+?2?9?]?z?
1%141>1G1e1
2$2*242C2K2W2h2o2
3$3*313
4B4Q4h4n4t4z4
4G5T5|5
7"7/7i7v8
:#;-;6;?;T;];
;+<4<?<F<Y<g<m<s<y<
="=2=;=_=m=s=y=
0!0>0~0
191_1h1n1v1{1
l5p5t5x5|5
6#7W7_7q7~7
868D8J8e8
919B9N9
7E7Q7j8q8
9&9F9P9\9x9
:":,:8:=:B:`:j:v:{:
<?<T<j<w<
6A7P7i7W8a8n8
9-979C9
:Y:l:z:
9R:Z:`:
22A3m5
7"9;9P9
:#:;:@:L:Q:e:
:N;U;g;p;
<+<<<\<
=%=.=<=
0D0K0{1
252C2V2a2l2
6&60646<6H6b6
7*71797Q7_7g7
7*868;8A8F8N8T8\8
]3c3u3
88p8u8z8
:;I;P;V;];b;
< <0<5<:<J<O<T<d<i<n<~<
=%=1===Q=g=z=
>&>:>?>D>a>
?J?O?T?o?y?
0/0>0c0x0
0 171a1
1P2Y2p2
6/696`6j6
7n8I9P9}9
::3:Q:x:
:";1;C;V;p;
<'<I<Z<
>/>E>M>
?2E3u355@5P5
6#6>7P788%:
7G7\7f7
788G8}8
040T0L1
2 4T4y4I5
3+4A4W4`4k4s4
6-656d6
7F8N8t8
<)<1<R<
8E8A9M9W9a9e9k9o91:r:
G0b0l0
2$2.2>2
6a6j6n6t6x6~6
191A1j1q1
3-3?3Q3c3u3
7b9i9q9y9
2D2[2{2
182a2v2
4 5?5!6U8
=(>/>6>Y>
5e9k:s:
8&8Q8d8o8
>(><>\>f>
6R6a6m6|6
6=7F7O7X7
!1p1v1*3
:2:8:D:c:i:
?!?)?G?O?
3/353b6
;.;T;t;
=0=M=o=
1#1Y1e1q1{1
2 24282<2`2d2h2l2p2t2
2(3,3034383<3@3D3H3`3d3h3l3p3t3x3|3
4 4$4(4,4044484<4@4D4H4L4P4T4X4\4`4d4h4l4p4t4x4|4
5 5$5(5
6$6,646<6D6L6T6\6d6l6t6|6
7$7,747<7D7L7T7\7d7l7t7|7
8$8,848<8D8L8T8\8d8l8t8|8
0$2(2,2024282<2@2D2H2L2P2T2X2\2`2d2h2l2p2t2
4 4(40484@4H4P4X4`4h4p4x4
5 5(50585@5H5P5X5`5h5p5x5
6 6(60686@6H6P6X6`6h6p6x6
7 7(70787d=h=l=
5$5(5,50545
=X=\=`=d=h=l=p=t=x=|=
> >$>(>,>0>4>8><>@>D>H>L>P>T>X>\>`>d>h>l>p>t>x>|>
2$2,242<2D2L2T2\2d2l2t2|2
6 6,686D6P6\6h6t6
7(747@7L7X7d7p7|7
8$808<8H8T8`8l8x8
9$909<9H9T9`9l9x9
4$4,444<4D4L4T4\4d4l4t4|4
5$5,545<5D5L5T5\5d5l5t5|5
6$6,646<6D6L6T6\6d6l6t6|6
7$7,747<7D7L7T7\7d7l7t7|7
8$8,848<8D8L8T8\8d8l8t8|8
9$9,949<9D9L9T9\9d9l9t9|9
:$:,:4:<:D:L:T:\:d:l:t:|:
5 5(50585@5H5P5X5`5h5p5x5
6 6(60686@6H6P6X6`6h6p6x6
7 7(70787@7H7P7X7`7h7p7x7
8 8(80888@8H8P8X8`8h8p8x8
9 9(90989@9H9P9X9`9h9p9x9
: :(:0:8:@:H:P:X:`:h:p:x:
; ;(;0;8;@;H;P;X;`;h;p;x;
: :$:(:,:0:4:8:<:@:D:H:L:P:T:X:\:`:d:h:l:p:t:x:|:
; ;$;(;,;0;4;8;<;@;D;H;L;P;T;X;\;`;d;h;l;p;t;x;|;
;,<0<8<
=$=(=8=<=@=H=`=p=t=
> >$>,>D>T>X>`>x>
? ?$?4?8?<?@?H?`?p?t?
0(0,00080P0T0l0|0
1 181<1T1X1p1t1
2,2<2@2D2H2L2T2l2|2
3 3$3,3D3T3X3h3l3t3
4 4$4,40444<4@4D4H4P4h4l4
5$5(5,5054585@5X5\5t5
6(686<6L6P6h6x6|6
7 787H7L7P7h7l7
8 8$8<8L8\8`8d8|8
9$9(9,949H9X9\9l9p9t9
: :$:,:D:H:`:p:
;0;4;8;L;P;h;l;p;
< <$<(<@<D<H<P<T<X<`<x<|<
= =$=(=0=H=L=P=d=h=
> >$>(>@>D>\>l>p>t>|>
?(?,?<?L?P?h?l?
0 080<0P0T0\0`0d0l0
7D7L7T7\7d7t7
8$80888l8|8
9,989@9t9
9$:,:4:<:D:T:\:h:
:0;<;\;h;
< <8<H<`<h<t<
=8=@=H=L=T=h=p=x=
> >(>,>0>8>L>T>\>d>h>p>
?<?H?h?t?
0$0(0D0H0h0p0t0
1,101P1l1p1
202P2p2
303L3P3p3x3
4 4@4`4
5 5@5`5|5
6 6@6`6
7 7(7<7D7H7P7T7\7p7x7|7
80888<8@8D8H8P8d8l8t8|8
0\0`0h0
2 2$2(2,2024282<2@2T2X2`2
3 383D3H3L3h3l3
P=X=`=
>(>D>h>
3$4H4d4
6,7P7x7<8\8
:4:T:x:,;T;x;t<
api-ms-win-core-synch-l1-2-0.dll
Bapi-ms-win-core-fibers-l1-1-1
api-ms-win-core-synch-l1-2-0
kernel32
api-ms-
(null)
((((( H
((((( H
(
mscoree.dll
BLC_ALL
LC_COLLATE
LC_CTYPE
LC_MONETARY
LC_NUMERIC
LC_TIME
Bapi-ms-win-core-datetime-l1-1-1
api-ms-win-core-file-l1-2-2
api-ms-win-core-localization-l1-2-1
api-ms-win-core-localization-obsolete-l1-2-0
api-ms-win-core-processthreads-l1-1-2
api-ms-win-core-string-l1-1-0
api-ms-win-core-sysinfo-l1-2-1
api-ms-win-core-winrt-l1-1-0
api-ms-win-core-xstate-l2-1-0
api-ms-win-rtcore-ntuser-window-l1-1-0
api-ms-win-security-systemfunctions-l1-1-0
ext-ms-win-ntuser-dialogbox-l1-1-0
ext-ms-win-ntuser-windowstation-l1-1-0
advapi32
api-ms-win-appmodel-runtime-l1-1-2
user32
api-ms-win-core-fibers-l1-1-0
ext-ms-
Sunday
Monday
Tuesday
Wednesday
Thursday
Friday
Saturday
January
February
August
September
October
November
December
MM/dd/yy
dddd, MMMM dd, yyyy
HH:mm:ss
Bja-JP
american
american english
american-english
australian
belgian
canadian
chinese
chinese-hongkong
chinese-simplified
chinese-singapore
chinese-traditional
dutch-belgian
english-american
english-aus
english-belize
english-can
english-caribbean
english-ire
english-jamaica
english-nz
english-south africa
english-trinidad y tobago
english-uk
english-us
english-usa
french-belgian
french-canadian
french-luxembourg
french-swiss
german-austrian
german-lichtenstein
german-luxembourg
german-swiss
irish-english
italian-swiss
norwegian
norwegian-bokmal
norwegian-nynorsk
portuguese-brazilian
spanish-argentina
spanish-bolivia
spanish-chile
spanish-colombia
spanish-costa rica
spanish-dominican republic
spanish-ecuador
spanish-el salvador
spanish-guatemala
spanish-honduras
spanish-mexican
spanish-modern
spanish-nicaragua
spanish-panama
spanish-paraguay
spanish-peru
spanish-puerto rico
spanish-uruguay
spanish-venezuela
swedish-finland
america
britain
england
great britain
holland
hong-kong
new-zealand
pr china
pr-china
puerto-rico
slovak
south africa
south korea
south-africa
south-korea
trinidad & tobago
united-kingdom
united-states
zh-CHS
az-AZ-Latn
uz-UZ-Latn
kok-IN
syr-SY
div-MV
quz-BO
sr-SP-Latn
az-AZ-Cyrl
uz-UZ-Cyrl
quz-EC
sr-SP-Cyrl
quz-PE
smj-NO
bs-BA-Latn
smj-SE
sr-BA-Latn
sma-NO
sr-BA-Cyrl
sma-SE
sms-FI
smn-FI
zh-CHT
az-az-cyrl
az-az-latn
bs-ba-latn
div-mv
kok-in
quz-bo
quz-ec
quz-pe
sma-no
sma-se
smj-no
smj-se
smn-fi
sms-fi
sr-ba-cyrl
sr-ba-latn
sr-sp-cyrl
sr-sp-latn
syr-sy
uz-uz-cyrl
uz-uz-latn
zh-chs
zh-cht
CONOUT$
kernel32.dll
\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe
Antivirus Signature
Bkav W32.AIDetectMalware
Lionic Clean
Elastic malicious (high confidence)
MicroWorld-eScan Gen:Variant.Zusy.475188
ClamAV Win.Trojan.Generic-10004864-0
CMC Clean
CAT-QuickHeal Clean
ALYac Clean
Malwarebytes Spyware.RedLineStealer
VIPRE Clean
Sangfor Trojan.Win32.Save.a
K7AntiVirus Clean
BitDefender Gen:Variant.Zusy.475188
K7GW Clean
Cybereason malicious.91981e
Baidu Clean
VirIT Clean
Cyren W32/Kryptik.KCO.gen!Eldorado
Symantec ML.Attribute.HighConfidence
tehtris Clean
ESET-NOD32 a variant of Win32/Injector.ETBS
APEX Malicious
Paloalto Clean
Cynet Malicious (score: 100)
Kaspersky HEUR:Trojan-Spy.Win32.Stealer.gen
Alibaba Clean
NANO-Antivirus Clean
SUPERAntiSpyware Clean
TACHYON Clean
Sophos Generic ML PUA (PUA)
F-Secure Clean
DrWeb Trojan.PWS.Siggen3.30717
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition BehavesLike.Win32.Dropper.tz
Trapmine malicious.high.ml.score
FireEye Generic.mg.abc8ad6946808c33
Emsisoft Gen:Variant.Zusy.475188 (B)
Ikarus Clean
GData Gen:Variant.Zusy.475188
Jiangmin Clean
Webroot Clean
Avira Clean
Antiy-AVL Clean
Gridinsoft Trojan.Heur!.02092021
Xcitium Clean
Arcabit Trojan.Zusy.D74034
ViRobot Clean
ZoneAlarm HEUR:Trojan-Spy.Win32.Stealer.gen
Microsoft Trojan:MSIL/RedLine.MBCA!MTB
Google Detected
AhnLab-V3 Clean
Acronis suspicious
McAfee Artemis!ABC8AD694680
MAX malware (ai score=86)
DeepInstinct MALICIOUS
VBA32 BScope.TrojanPSW.RedLine
Cylance Clean
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Rising Backdoor.Agent!8.C5D (TFE:1:5USf6Jo8vzK)
Yandex Clean
SentinelOne Static AI - Suspicious PE
MaxSecure Clean
Fortinet W32/Injector.ESYR!tr
BitDefenderTheta Gen:NN.ZexaF.36270.qzZ@aa67Rnoi
AVG Win32:PWSX-gen [Trj]
Avast Win32:PWSX-gen [Trj]
CrowdStrike win/malicious_confidence_100% (W)
No IRMA results available.