Static | ZeroBOX

PE Compile Time

2023-07-04 05:38:56

PE Imphash

ac18dc6a1c61398696cfd62f5dc166eb

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x0025929a 0x00000000 0.0
.rdata 0x0025b000 0x000e5c06 0x00000000 0.0
.data 0x00341000 0x0000f084 0x00000000 0.0
.Y=L 0x00351000 0x0033738d 0x00000000 0.0
.Y.^ 0x00689000 0x000019d0 0x00001a00 1.38968752602
.Lg] 0x0068b000 0x006f7f80 0x006f8000 7.96779796397
.reloc 0x00d83000 0x000005d0 0x00000600 4.35733523985
.rsrc 0x00d84000 0x0001be04 0x0001c000 6.02632823788

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x00d9f7b8 0x00000468 LANG_RUSSIAN SUBLANG_RUSSIAN GLS_BINARY_LSB_FIRST
RT_ICON 0x00d9f7b8 0x00000468 LANG_RUSSIAN SUBLANG_RUSSIAN GLS_BINARY_LSB_FIRST
RT_ICON 0x00d9f7b8 0x00000468 LANG_RUSSIAN SUBLANG_RUSSIAN GLS_BINARY_LSB_FIRST
RT_ICON 0x00d9f7b8 0x00000468 LANG_RUSSIAN SUBLANG_RUSSIAN GLS_BINARY_LSB_FIRST
RT_ICON 0x00d9f7b8 0x00000468 LANG_RUSSIAN SUBLANG_RUSSIAN GLS_BINARY_LSB_FIRST
RT_ICON 0x00d9f7b8 0x00000468 LANG_RUSSIAN SUBLANG_RUSSIAN GLS_BINARY_LSB_FIRST
RT_GROUP_ICON 0x00d9fc20 0x0000005a LANG_RUSSIAN SUBLANG_RUSSIAN data
RT_MANIFEST 0x00d9fc7c 0x00000188 LANG_ENGLISH SUBLANG_ENGLISH_US XML 1.0 document text

Imports

Library WS2_32.dll:
0xa89000 gethostname
0xa89004 sendto
0xa89008 recvfrom
0xa8900c WSAEventSelect
0xa89014 WSACreateEvent
0xa89018 WSACloseEvent
0xa8901c htonl
0xa89020 WSAIoctl
0xa89024 htons
0xa89028 getsockname
0xa8902c listen
0xa89030 bind
0xa89034 accept
0xa89038 WSASetLastError
0xa8903c WSAGetLastError
0xa89040 WSACleanup
0xa89044 __WSAFDIsSet
0xa89048 closesocket
0xa8904c select
0xa89050 shutdown
0xa89054 WSASocketW
0xa89058 inet_pton
0xa8905c getaddrinfo
0xa89060 WSAStartup
0xa89064 getpeername
0xa89068 send
0xa8906c socket
0xa89070 ntohs
0xa89074 connect
0xa89078 recv
0xa8907c getsockopt
0xa89080 freeaddrinfo
0xa89084 ioctlsocket
0xa89088 getnameinfo
0xa8908c setsockopt
0xa89090 ntohl
Library ADVAPI32.dll:
0xa89098 CryptHashData
0xa8909c CryptGenRandom
0xa890a0 CryptGetHashParam
0xa890a4 CryptReleaseContext
0xa890ac CryptDestroyHash
0xa890b0 CryptDestroyKey
0xa890b4 CryptImportKey
0xa890b8 CryptEncrypt
0xa890bc CryptCreateHash
0xa890c0 ReportEventW
0xa890cc OpenProcessToken
0xa890d0 GetTokenInformation
Library CRYPT32.dll:
0xa890dc PFXImportCertStore
0xa890e0 CryptDecodeObjectEx
0xa890e8 CertFindExtension
0xa890ec CertGetNameStringA
0xa890f0 CryptQueryObject
0xa89104 CertOpenStore
0xa89114 CertCloseStore
Library d3d9.dll:
0xa89120 Direct3DCreate9
Library d3dx9_43.dll:
Library KERNEL32.dll:
0xa89134 GlobalAlloc
0xa89138 GlobalFree
0xa8913c GlobalLock
0xa89140 GlobalUnlock
0xa89144 MultiByteToWideChar
0xa89150 HeapFree
0xa89154 GetFullPathNameW
0xa89158 WriteFile
0xa8915c SetFilePointer
0xa89160 SetEndOfFile
0xa89164 WaitForSingleObject
0xa89168 CreateFileW
0xa8916c Sleep
0xa89170 LoadLibraryA
0xa89174 DeleteFileW
0xa89178 CloseHandle
0xa8917c HeapAlloc
0xa89180 GetProcAddress
0xa89184 GetProcessHeap
0xa89188 CreateProcessW
0xa8918c CreateMutexW
0xa89190 GetLastError
0xa89194 GetModuleHandleW
0xa89198 ReadFile
0xa8919c CreateThread
0xa891a0 ExitProcess
0xa891a4 GetCurrentProcess
0xa891b0 VirtualFree
0xa891b4 VirtualAlloc
0xa891b8 TerminateProcess
0xa891c0 HeapReAlloc
0xa891c4 GetExitCodeProcess
0xa891c8 CreateDirectoryW
0xa891cc SetLastError
0xa891d8 GetCurrentThreadId
0xa891dc TlsAlloc
0xa891e0 TlsGetValue
0xa891e4 TlsSetValue
0xa891e8 TlsFree
0xa891ec FormatMessageW
0xa891f0 GetStdHandle
0xa891f8 GetFileType
0xa891fc GetModuleHandleExW
0xa89200 SwitchToFiber
0xa89204 DeleteFiber
0xa89208 CreateFiber
0xa8920c GetCurrentProcessId
0xa8921c FindClose
0xa89220 FindFirstFileW
0xa89224 FindNextFileW
0xa89228 WideCharToMultiByte
0xa8922c GetCommandLineA
0xa89230 LoadLibraryW
0xa89234 GetConsoleMode
0xa89238 SetConsoleMode
0xa8923c ReadConsoleA
0xa89240 ReadConsoleW
0xa89244 GetSystemTime
0xa89250 SleepEx
0xa89254 GetSystemDirectoryA
0xa89258 CompareStringW
0xa8925c GetTickCount
0xa89260 GetCommandLineW
0xa8926c PeekNamedPipe
0xa89274 VerSetConditionMask
0xa89278 VerifyVersionInfoA
0xa8927c CreateFileA
0xa89280 GetFileSizeEx
0xa89284 ExitThread
0xa89288 LoadLibraryExW
0xa89290 RtlUnwind
0xa89294 GetStartupInfoW
0xa89298 IsDebuggerPresent
0xa8929c InitializeSListHead
0xa892ac CreateEventW
0xa892b0 ResetEvent
0xa892b4 SetEvent
0xa892b8 GetStringTypeW
0xa892bc GetCPInfo
0xa892c0 CompareStringEx
0xa892c4 GetOEMCP
0xa892c8 GetACP
0xa892d4 FreeLibrary
0xa892dc IsValidCodePage
0xa892e0 FindFirstFileExW
0xa892e4 HeapSize
0xa892ec LCMapStringEx
0xa892f0 DecodePointer
0xa892f4 EncodePointer
0xa892fc InitOnceComplete
0xa89300 RaiseException
0xa89310 InitializeSRWLock
0xa89314 GetConsoleOutputCP
0xa89318 GetModuleFileNameW
0xa8931c SetFilePointerEx
0xa89328 GetDriveTypeW
0xa89334 MoveFileExA
0xa8933c LCMapStringW
0xa89340 GetLocaleInfoW
0xa89344 IsValidLocale
0xa89348 GetUserDefaultLCID
0xa8934c EnumSystemLocalesW
0xa89350 FlushFileBuffers
0xa8935c GetModuleHandleA
0xa89360 WriteConsoleW
0xa89364 SetStdHandle
Library USER32.dll:
0xa8936c GetCursorPos
0xa89370 SetCursorPos
0xa89374 ReleaseCapture
0xa89378 GetClientRect
0xa8937c SetCursor
0xa89380 SetCapture
0xa89384 LoadCursorW
0xa89388 GetForegroundWindow
0xa8938c IsChild
0xa89390 ClientToScreen
0xa89394 GetCapture
0xa89398 ScreenToClient
0xa8939c ShowWindow
0xa893a0 GetDesktopWindow
0xa893a4 PostQuitMessage
0xa893a8 RegisterClassExW
0xa893ac UnregisterClassW
0xa893b0 CreateWindowExW
0xa893b4 MessageBoxW
0xa893b8 DestroyWindow
0xa893bc GetWindowRect
0xa893c0 DefWindowProcW
0xa893c4 TranslateMessage
0xa893c8 PeekMessageW
0xa893cc DispatchMessageW
0xa893d8 OpenClipboard
0xa893dc CloseClipboard
0xa893e0 EmptyClipboard
0xa893e4 GetClipboardData
0xa893e8 SetClipboardData
0xa893ec GetKeyState
Library SHELL32.dll:
0xa893f4 ShellExecuteW
Library ole32.dll:
0xa89400 CoTaskMemFree
Library IMM32.dll:
0xa8940c ImmReleaseContext
0xa89410 ImmGetContext
Library XINPUT1_3.dll:
0xa89418 None
0xa8941c None
Library bcrypt.dll:
0xa89424 BCryptGenRandom
Library ntdll.dll:
0xa8942c RtlAdjustPrivilege
Library Normaliz.dll:
0xa89434 IdnToAscii
Library WLDAP32.dll:
0xa8943c None
0xa89440 None
0xa89444 None
0xa89448 None
0xa8944c None
0xa89450 None
0xa89454 None
0xa89458 None
0xa8945c None
0xa89460 None
0xa89464 None
0xa89468 None
0xa8946c None
0xa89470 None
0xa89474 None
0xa89478 None
0xa8947c None
0xa89480 None
Library KERNEL32.dll:
0xa89488 LocalAlloc
0xa8948c LocalFree
0xa89490 GetModuleFileNameW
0xa89494 ExitProcess
0xa89498 LoadLibraryA
0xa8949c GetModuleHandleA
0xa894a0 GetProcAddress

!This program cannot be run in DOS mode.
`.rdata
@.data
`.reloc
@.rsrc
{X*"|/
NzLe~};
Ra:]f;
ole32.dll
R%iX4E
,ZKdw@
VAA+n)r
cZ\<jx
0zY-RW
wW1C.
c!mL];e
eR9/ZB
NAWD1,$L#
T,9xpv2
7]Q{MO
lVVh(n
tnYZQZ
cOa6~z
c:_VIU;
Gdw|9j
I&$q@$
,\MtYl
gppR$&
7oAWfA
fI4f3/3!
6f0ZhL
Yuql1)|7c
6.+'Yq
XINPUT1_3.dll
9<zf^
m-N+CR
r0]LB7*
D\D=t[3
]Pr(Z'
HX]R#
]&6oVC
%%ZRK
pmx`M
ZA r%K
Wczf&1
O}l%f;
`pG4yIy
m`cN(RM2
taPj)9
v0'XR*
9otR:K
>F>f6(k"
"iI<>-
nDHlOz
ShellExecuteW
4ChnTH
D1,$fD
CreateDirectoryW
AWD1$$L
GetExitCodeProcess
-m\+Y6
SetEndOfFile
#)I>IB
VrmA8i
")(R!e
MuF"y0
n4(EY57
+hV0kw
iBj;YE
y+&I("
DF.HtAY
_.sJo)
r*79B-@
r8xQf3
)Ft{O
2^BDR0
.7Qc(:eU
oR`*}]
]e%R~,
<(\WIN
F`83CMA
8x}fM)
CoTaskMemFree
|<$_"_{
B-?/?i
lq1Y2|
5q{@J3q
AXAZfA
D1$$E+
1wdcJA
5"Jn?H
=IlAH3
N89@m1D
$D1,$M
R\O&v$
bM5&RF8j[-
-PW'-f
j.!AVvHB
"7NB^Lr
+51^r['
,1-`)-1)
EGoSOc/
;'f6.Z~y
Yd"tA3
8o5P[mG
mm~eU]
k_~*l(
FjK1vm<
InitializeCriticalSectionEx
k\LOl+
>)Wu8TA
HeapAlloc
mQRWTR|
~0GjKo)
9aY;VK
]c}|f;
?<)yRN
;uYxNQw
quR5E=
TRjtJ)-
&_/Reg5
^%y2Rw
GetSystemTimeAsFileTime
^H%M?]'
n x{i|
r%G3B"0
DI^BtN)
x]$L=d>
g`!P540U
C%AWD1$$fA
B!Aw;$B
//A^BU
Z&?ANr@\
A1y*2@1{
KE15e&g
x->nn]
c}b&@M
InitializeSRWLock
F@ZphrT
]_vOf;
UQDc+u
yOX2kK
:h~H<0
zt=SpP
HdV5= O:
oP(g1+
eiJcUn=
+T*(R.
-@X2pmq
m_@5\2
a65x6#s
l8?AWD
okWo9@
A|A 8`g
8WLa)W
=-y/Bu
o\f=\T
bcrypt.dll
5R.Q`9
~RqblL
;O9`3Z
4c{oRH
#Ko-N_
SR3mR_
?~E?@<
x=|R1p
-iRm_G[
pe!C!l
{d03KcG
V`t@fg
[r/\V*
CFJGo3
1]eHoW`'
l6zC8a
N})9t
cymJ2p
E|8Iu{O
DeleteFileW
W/:R21
Py0+S.=
uA#V%
fZ=vi;
!^IAW1
<E54Ow
GetProcAddress
FindClose
oY^qR{
&EN)"d
,NLR"m
7d~xRF
7i*{Cf'9
NSGRM/9u
@FGJf;
|ELeR6
5 ^K_
CertCloseStore
oO}3iC
}4h4
=P6AWA
yly&=f,
g.KAT
XUl|Hq
,V!xE]D
b|-zif
^0D7Hl
<&th@j
' av(T
8,'Flc
\p'-1
CryptGetHashParam
SR^eba
tV't%$
)q_34|
V/26%_
%6:xvx$
}n@8V,
kOGuM9
7eE1C}
m|@^R1N
Od[#R&
|oW^k#?
Ko\A_c
(Yi17p{
zrM<,E
oCnBsFOc
UHRv}?z
j8yRag
8R.I~4
cBL-RC
;h-<ja
gi9s6`
Allpqk
vL]*/%[]
I5Qu[3
hR1.6d
x5S|R?
S>8jm,
QSpNs]
i'#>f;
$-}ilK
vPpqAT|Na
4y%;5K
.v?Y]E
ljVoOH
GG-OOscz
Y[4`|W[
hWN-9&
BO1d_A
C;e=7z
|O5bLHB
0'm_a.
g'h`W 
"8\&%O
'yVzk@
- h(C
dxjhE$
yl*7"P
J7#FE^
JR*DXF
ERR60PR
Fr-Vl<
~4woRh;
m|FL]RX
`>C#MS
CryptCreateHash
KkIg*X
Xw_/L}Yg
/;L2![|
'N1OO;
w1jDCy
S@ayuO
iG7{"_
LWL:Fv
m@:h`
c"Ll}6
_xP|5~
i+c]Rt
'=3#Ef
rK=)]
ORA?]2-
gPkUCl
D1,$fA
~KS(fI
*Rr|?&
V3aOQD
3>k\b7
;>_%<I
d>ncT9
|xa*_g
CryptAcquireContextA
eD1$$A_Mc
FindFirstFileW
!i|-<e
{nF(ma
^wR117
wRpfO{
[fCh3]6
t.o=W>
GetDriveTypeW
FindNextFileW
n{dS,DZ
xf|s~&N
,vhLlW,7
tR'L{F
KZPP,$
PqfEI|
:\m]GO
4UqB^"pq
xw6uZ~
ykbE]:#"
GetEnvironmentVariableA
wYZ`<98
Hulv"\h
eUkl#7
GetCurrentProcess
$|_3|e
GetStringTypeW
Nk^C%;G
p$,F7:
AWD14$I
b%p:\\B
7.K]Q
fmI\<S%
@VJH5D
CuM&YA
o{_dJ\hu
Ey0KOi^'
=*Bx;3
GetCursorPos
Wn<klE4
IR{LE
{+3'R9
NEEi;7
dRQN2h
RvH1,
xn;T)g
so*$Ch]
/n>kiI
^knWnl
Ih-E/3
3cy\~R
gR:d9k
N\RgU
/0N)79
s1ZfC6-
\WX)[
59!f$x
ZBwf=J
{!.HMb
@mt<k%
]K*)@
U(yL65
e*z1RAo%L-r+
mz)(4R
WSAEventSelect
}I-bO.Mm
9($,u0&
w<I'xFN[
mPZZ^RE
RjxvE=y
$bg5;`
_1xvl!
!7//R|bpR-
(7/RSehR-
9]zmNb4
eR}FlW
(SOx0,
BCryptGenRandom
9AZZf@
XETPhB#
D@4C7
e(\Q4!
n)M!^.:
cGIAbd
CertFreeCertificateChainEngine
%V4mH
tiu%7
gr%RWuR
Jva!zq
CmbR=s
w]DZ<x
.|8F8[R
+eC H&R
Jd~s2_
mh#pKR
Ryg,j-
VR6)5Z
RAf)u
Fr)X)y
Ntt<a+
>1@"NT
"u@mAWI
D14$fA
vPX"q'
3v*MU_
rxduu?
4>O$t}y
5RS,}9
DRvxBH
IhRRyo%
Wn%(WI
:/uvg'
71Plf%
Cq1lO_
CreateMutexW
'D14$A_Mc
GetProcAddress
YBQZr1
D1,$A_
}CF$z4
(d1bZXv
O<BOb[
[)cxrM
JmWwEu
PTy -?
ws@i:x
%H=nz<h[
gTh]2
2DgK]_4
blqmU mq
!B/rE2
b'm z=
`Ar<f;
n{n=gD
{umuRN
-RE(m8R@
PKrB,>
x.;Ad|HX
47TB@Vr
f5z#VS
N*2V<[
{#INM~
dR>0mh
}b4cRx
Yw)yD9?
c"~wP*S
wH#]ejQ
&R~Q|*
bRAD67
aR9OBm
CryptDestroyHash
WSASocketW
7 iWBf
s= `&6c
Hcelv
QueryPerformanceFrequency
f3C`K1
=F/|wE
ncy%6"
`l6%~-&
GetUserObjectInformationW
g?%F(g
l8?AWD1
IsProcessorFeaturePresent
DeregisterEventSource
x9(`/s
&^jY`_
LoadLibraryW
"_,T6H
6g=SVI
s8iHz"zT
pRB:y?
TF]^Yn
"UTYQ>
H8R!;{
gn.hs$
HS']MH
{lt*ho#+
j6R$4T
DzSzYT
!6+@[Q
8' H#5
]!Y2&EP
]sx1A(
H]8I'/
cIN4n3~
@xn!K4`
/,~16
GxP6{
'B"=#x
8twvhf
Q6^f}N8
A>/<,`
8TQ,BT
)ELA%a
k%4E4{
^#a]ta
-zyVR3
n(U[JY
O5~.z`
gg&WJ h
H"0>I
)jn0Q3
hi4s:E4=
b&,>?5
2$`+x&9
E>@S7m
'}HIz.
LL/!)
b7jVZC
nD7R0:
$zD0Xw96
SYdzL,
}}%N+[^4r
CC/|e`
oAyGhI_
}|;s+f3
m["L0z:0_
"3/wil
<v-p!";_
DJcya'
\;LOm]
$<Nq"!
-_kR(!kfb
R@)12W$<
bpBz>1
7K8Fg%
0%:tci|HX
7-|w\Fc
k,N1=tc
qEz06)
<^6vYj
V_LsFv
nRxJ}o
]j?3%J
K1:1{E
!%9(}&
yB[!JD
_-Hn@!
lnc@3s;
VaU2@@
Onl)$p#
rr&o=3
K|=J-4>
2fq`xcq
jh`TR,
mBrQ6/$
[*E*8:)
yi5(1T
RlK.u4
og4=fK
TJ{5C;
Y~tSW#O3
5fZ8zG:
iyjBH)/
{W"e3u
}){$zP}
Wx*YzE
NsSp<0
A-taWRt
(O-0Q|
8~^a5J6
hRL-RI
Cy<C=L
~Cp!%cr
NWrgoe
ML0[8 R&
Um'PlG8
ezAEbr(
}/y\u'
K![d"A
5Jg4XS
Im^'}S^
.zHumiP
W-vizS|
:N4r?S
.>0pGJ
YCEFlT
#<:&O5
8{|hr2
:pEPLy
A>uD\uMS
|UM.6f
%.Aa8S
eo_)SD
U6!::k
y`^][g
)gtO4"
fAd|5/
`{GAa]
I4$97oM
c",){e
aw>+";
L-B:N`
S#SQZ.$R
4O54#>Uco
CCM8<y
E\/A}R
T@`RUbZ
6YyM%`9m
MHt1S6
*7T4Y?"
Z:joSu
#%xv&k'
=J7n/uI
}C$Fy:
( /8js~
=5{d@R
(h0cUT
16!2'Js|
!Rx~{+
G1,to#l-]
N.Nyw2e
W@5N,v
9ADP'C
{4p8!'
ZU;IB:
:*Q]xJ
tYUpQ<
5&(wia
Ct"UIe
J}p)'C
?F<}av
M"nq1(jh
.k86[~
G#Sk8p
mswJtwTo
;N!alq?%
/tls{a
o|_27gv
y?c,kMJ
.9$b#\
}RgX"-
EFEu'?
`;m)n#|
rm(y-R2
eZRh&e%
?)F7N}
,_qw)R
q)@u2*
0k8Aet
B5~@K5e
=z8s@pV
j/c2'v
s;Q|:?A
+62!4:?q
t;PLgr}7-
6|vy<h
2LUkzWq
rQmQFKu68
PA%~dT
WgTy5G
d@Loo~
{VI`IwL
mAx#x|
W`^998k2d
a$7!YM
7^kh?y6
OtGU<@
2374YH
rM<:Je
D),Xwi
c<~jN>
9nb1}E
L&XH@6g
kFudR29p
Jy@)7
4v<C|nr
|4`Q|d*
Ty2F[
b:A$sZ
nAR5eS
[6zLX]5
OSx@qqY
Y`gI-y
A/K`?1
sgP[oV
C{C.]I
K<a2)1
;_!0OF
"@}p1r,8
nuubGs
L\R9o
[/Zw8 FL2y
ApCbe$
_;t#<T
t{',hA
4*/; Nf
BReW@pj
(4sBL$
07 >w5
{'@/M[
Ty!,%B
w>Dm3F
Ng*jE+
'c\o*&
fq8mjA
LO2X:V
]d[C\$
nU3)VT
Lw_ud@
rs;L X
*c#aX5E+
RrhuKb
P`G%m|
r(!Kg)
ns6%/.
^2)?uY
i*ikh.
Q\^0B%
mEbRH4(
!w,aY83
<dqsZf
0l?t,`?AE'
F(+b*`lhQ&T
v\j6=tr{!o
}vjK4
.m:BeI
w}w%'j
S,[rWC
0:ehDs
!]Kvrv
u\mncP
;FBQw?
EJ$*Yi
!o,},X8
`1!7K\
wcg=eC
N/Fax!
1|&sUpL+4
RN P_J
j5'#In?
uI*t]z
l:TwcQo2
Rpz#b@
,P#S=$~U
2/~"'Y&
^G7rHyA
m~G1t4T
-%=thq
9o0&Vp
Xh+!\]H$
jP9`I;
Y}7F`s.
6~~P|j
3|Ip`t
./VMR8
C#dd\P
D0_4\6
.M59+t8
zWi_7"
.@Y@j"a2
W9(-4"
LaB|6_
bNWdbZ$
Mz*#Ab
G=HT_N
N'[CG1
BL>1*6
].h:wH{/
!f?-B[
?lOB-y
Emd2Rq
;{x&*m
H}xz[>0 Z
CE.%y6C
Y#b^.g!r
^$-AuX
z'liF.
x@CuuaJ
-53jYj@L
#j-1C?
m/GYo-+N
[@Z!#X
Sj%nb
_$g9L]t
pj,-6u
H-?Pe}$i
WEy)CjxjU{
bFCIt
uc2--}
P/*Tf2Q
_:8fr+
GN4WuwY
nK"L~
l;P-.w9
G'KBI6
l6|k4p
D0oii\
:JV8[e7
&^Jy^}
-lD-Ih
aw%koX
WLg)P(_
U#utPg
hK0b)P
3{V\rHC
?O Y\(
#~@-v4L=
MW9Wz-
G>^(B!I
Itguj}
38T+./
J8\3HX
ub4$Y%
3~^Po#
+BdTg%
b=!#t_^|)+
$$D7lG
#3dkFAka
AYf1N"
rPW\m#
M/>G.Y
x\TPa^
I+FkRP
.[rG+xv
V^tP>"
n7}|SN
(e|D>p
<K9?h5fx7F
rGk0r:
4>)@WO
2j\shnDp
:MrZ5>vF
)mv$0%p
-ehRY26b
m[$lki
ZIJRqa
+:B)s[
~P6Bnp>"
ssG6@rw
oz^e;b
vt9Oe@`_G
cvoHK,|7
Pma,4P
7FeDaf
TNI=D`9
o@sVK'
M@E >\
c;#PM4
rG=SjDj\F;
* cZL1
kdAZ.e
2^S{X{
!h eOZ
?(Uo?u
lM>rR6
H7Qf=&:]
^p<):"4K
*#Mt7:
M2ku[h
-QY*y$
_APX:]
9e!uc1*).
Hi'dM5
Y2C<*b
M!0K[
HUp"f=
nQLtq*
<6*r?v
v`"&94;dO
W*Is{T
hMyalv4
;N"M.dX
jQ+a$Q
JbB.qH6
[4";P6
6w/L-$O6
qk;!a-
VD<vD
q+uE!%
Vj>3wh)
&+QUd"sp
d!A'HJ
HWovjp
vLI2@v
xE]2+;}
hZiI>a
aQa4^cgoS@
OI7#xx
9=5_pW
a*OE@}0
cYXR~p
swnhp}
Xn48%W
t(BE[9
B[`9\dH
|Rr pztB%5
+%|XVp*
2me>9,c
g?8 =P
* 6n;.
"%$YZC
nDj3X>:
Hfe]HL-
~p5JL^
V'a5e=
Zs=(!J
SIR!=z
O[v5kG
I_# 1G
^2BpL2
jGiZ^d
gQn4u2}]E
H7dyjj>
p66M+8l`\
muL&&]Dw
[Hq L:#
l]_pcN
\a-'Lw
>Zl{rxrW
XA*q8j
+}]^1)
5u7{3b
(OFL/L
^6i7Z
R7Oil=
Ft'%V{
]!@'OP
us,J7`5
BZA*D;
o1-.K|
3RV;zY,
Wg5)8=
X4_k2w
+F;%Ek
(Ylczw
[mB.XBJ
DqD#++
$Aw{Ic
ZvusZ^
GTy&YT
Z0:a29
HNLE+~
fXh;"k
SW)fHEh
1C/mtq
\(E51?
N3!#}va+>
!nzmr16
`q0O3*Z
|"_`z=
?iFah0
0&*Uj|
MU)N/9
n@hJHI
6L\<gD;
[syGf0
'ao5wY?
18P,6B
D1J( D
OoK)w9
8v@zj8
UFi,}l
}DpBCd
|!Q~Db
X^M3eA
~w<`7g
zl}'MO!
-W /5[}
->mE<
(+r).|K
;y4g)!
J~3G>.
[iEdi%Y
bOE[%q
<?LIe
rVQ}>b
I&C94p
I!6pAK
JzK4.`Ozr
QI-SBf
N!jKE
p&@ai9
ywL\U$
b>cwK
FF.sg9
ri&~&}-
S~K81D
2#QDlYDxh
v43G$S
@)"W+;p
i[>p9?
8aH<WY
ilAG7>
x?K`; $P
pb "aI
=Q]&^U(
3&]f# J
~|4yBY
|e<6l8
khW>b;
OEvuxG
vQ&Y{B
H`):rc
MO74"v
0rZ;!m
,>4{$/
fn*rtn
`,m>^:
hDFFh9
3'WE#C
<qId8P
Gnsj,7
q/xY<zm
9YIbFW
J;%X(y
&,.3%O
:H<*s9R
JeHJ@&C
lb!~An
.Z)G%l4
Yar!Z|
MIp QoG
0K]Je%-
E4mtbG
E;).VJu
U\#.wR
oC(%dqPO
e1?6ynF
RvS;Cr
c<3s&B
xzPL&1:
O&wVr<
,aa1i6~
sS[%HV
F>[IKF
pES"C/l
)]FGU2J
#63o"tY+
i/RV%6
`BNu6Q
/x+B\I
C<:HqG
Sj0x0)1D
aR&4F?
(UB~6:
Qrmw9e
tTa1!|]
@N:7VCu
6rj<52
/^#M.r
BGktlT
TbGv/[
vI:Dc_
hw;-`.
#q:F>K
km r;*
)8:U&`
Fh}baX}
F._/Gy
ZS?qN[
jr\yZ&
N4DrWH/
tgn&-#
O_{]7UH
T\]C\f]
+9EzH_
2c~-X<
uTqhRQ
<P}L|_
:6\X{f
VXSdxt
,4Tt*5?R
%-QZ%g
j.^=Qe
gk[)o
dgkX OB
(Y4`s!8{yJ
mY}Y6
|_XU+Ur
3}[],h
W~Qda3ge
3BJYCe
Vi*]`U
]9gBSz
YG196
vV+n.U
mL7a$i
&=FaC+
>QB>oF
?/jb]9
ZL7=Bf
)<6Czt/
?iL+#x
[+{6e=C*
~CI>}h
cY?,8y
-juaaa
UfVrxJA
f76rug
9{Tahk
[=%wd5
0>Ej~O=t
Q+N.MZ
ej`P_
?=_i-`
>m:|"g
;aRF,Zc
L!e,;Q&
[CsnpR
j\1ERR
h kU>S
E`*+.Y{
:hr3F
&Vc<|g
s'T#~j
C@3 :t
^$]tWjSr
$&&#!Q
zcJ3hA
4YeH5]
+DoJOv?J'
"ni>TG
71j^ b
;;Wsr3Mrh'
_??[8q^
8q+ucs
R>iS./
fDRb{#
g8K<?5
emFzWU
_{jUiF
Cpw8nw!
Ni}_WT
8c?bm^G
a$w^;>
TytA}k
Z7%OVUc
#mx;zl
T3!/Q[
ZBj@8rm-
O<5#Wc
wlUS&@6
?82<((
MCn0Dt
-EHUwl7&
gU#A?P
Tlmfo0
i%[At|Z
Rh_\{/
VD+<(O$a
M5dq F
AwcY==mX
t/m+p1
f?H%4D
(K^y+"
\p#%Q:
)d$L[-R6
@JMJT6
gh@04 5s
a|eVV?
UFMm+V%
.lK'i7X
=9nS(O
\t[7,0,
Z*Z ,c[=$v]
9CS#$&
kZ4tQKB
T _~Hq
@QF1|fz
dREv:6b
G?fOJH7
m0zKf
6!TB2P
Ljq/Aazp
M4h)Xf$\
*Xvs[2yL'{cg~o
/[0nVz
|77|d
xw<H"/J
DV+ai2
fz9%h\
=PKXAo
B'Oo5Pv$1
qjTsEd
2}FOus{`X
{`})Gj
T0:0nE
:8dO1Z
'%e:yx
g^;g+x]
3tl~K&
iN-;3s%
)")"+
oDwss1
;a*iq=
8COG6z
sHSLD`B;A
*XGZ0=
\304#v
9tBQ512
>QRGrD#
$=Hh`r+
jgLay^
L"{xar
NN_[vy
XB(;'3
2;_;8Z
b)ff/@
va=DZ9'
[$`jd\o"
Ms4*jE
t}$@;tP
f-]{77#h
+`<GK_9
=nM'KSW}!
iTA>wh
@VB99z_J
?H`JLN
ds/Gwv~
$y/-rH
$(?E&Ym
^yn69C
^ 4`EU
Ut^h,#
t/_lJ8
~L[W3j
W>:3'blP
^M57y=
j)6o,5
%j><"=
:c\N{;
Lj@0h%
c.yiKg
*%%zD6
^@*hot=!
L-f+R!
|,<-wpM|
qkL9c;
"rN$UL
Q3q4AA
uGlFG
B5|C+c(
\p.njW
c:f?N6
}87[xm
]*h2z`5
z5~^0m
#N7;j
$MZ_<R
t7i{Hu
uAPWw4
G$FB3M>
Bx0D4Q
k( OsG
\oV>$x
z-67zV
X[|(zXp
XaemZyT
+-0a&q#$
EVk*s}%
,jUt-I
+:boEN^
\:+5U3Q}s
NxYhtn
79]<[ak
)sezG<a-/
R`bcuL#
jC+o~_+Wl
IiK18/Mg
IbDcn$
Lo9cV\
hSawMk
l&\U85p
{XYS%,
D)-?p3
75xTz>qF
CGj!>)j
oJy38xnV
>w<5~'
Y&FXm/
qJWd>Ey+
X6fKG)t
|SuMln
d~Kzw\]'
1I`!=*
B[Zn?@
lhx#c6
{<p_J,-
8BGHDt
Qh-o}$
TPCNJx
T]O({5
jr8Om/
*zv>Q)
YWU\y:
Vt|w#qMsc
;bH@ea\#
Ob)}jb-
!M9*'Ea
\%agJQ
h~8LFeR
6MP2'ox
T<dR~.n
)>1x6!A
P_b'8-2*
.1a|jK
xU1UZ"nd
.Aj/Am
4#v(r}li3
|\>g?`\
Yii1R
X/M(D{tad
"4a6[Z
j=i9D#Mg{
0a}&)c
LCnk,nK
.BFa6
n>KOzUc9.
;oNw)(
b3U7;tg
]2N3[F+
_00<{%
@zS8B_!
:0RRY{
e\z`MTt
;>/rf,
mH(G\Q
9Z)*sQ
RJ.,cd)
$JVk?9
$F<V#d^P
&HA"t4
_,ibPENJE
b'J^2;"
12[;A+2
?_Gj*"
f<Co{_
x+-s%'I!)
9-;756
<zvFag
O%+vs7
Fx8lV@
]&h>[)
2FgUOu*
n8Y;b~
cL31wj
2'y~\S
4i+VNg
Kdi?YR
"XhLoF
__(X_1
:+s]Hg
hUvQ7Q
]0L^%X?
DL$aVs
1 "lMX;)?
~">|@0
@U:%f[
ZX]bIJf
YQT!e#^'J
]>|E;=3
,+RFwX
F?lY:2
4vdVcZ
$PArV^
_7{E8t h
h2A `_
=t;e5!^
Y<]}Y/_V
j,\|*W
=qXvHIz;
*+1MU^Ci
*]`SOC
{!@e0Cp2|
ob&79Gt
,e}4^K
1cPzE#'
=(WA!1
1bx)7M
n!cWIi
@<vg_R4
VrZV+B
P6|o>
^sDpWt0n
vc0NXA
P{=mls
Xj,QE'w
S}.B$YT7;
F?~iE
4:DkN-
g# {<R
c\>8n@
2#1p[z
IGB^Ax
ynA]Se
nV$'&2]
**#HM~
nBT-fR
8-l/9Q
nMig'FQ
*@:_E4j<-
ICV0Fx
uqCzo|k
.fxW|o~EM
:=p2'%
(dk,#9
mU.ALBwy
'#?IyR
X3:a.O
@"Y7eH
IfQKX%
9gqsYi
nJmQHe&
y[DelM
O2J+V@
owf\+d
(FF=KX
@!%`|+
;eIm=8
:B9":;]
&>-6XHa}
Y)Ld1LH
)KXKQJJj
e9?4Dd
CsmuYO
mIzq1R5
b1NRRs
CertFindCertificateInStore
,m]Gfl
Dwe3RD
_jqx1:cphIjU
:;nR-~
qqSIg-
;2Wfe
RXi}ip
"}1l}g!HB
?cO2hN
;M@s9S
1KR.vW
-M4lKr
m|yh]{
y)T,~^
r;@(fA
.yN5U/p
tr%1|WP
3$tj?V
LQ,54dk
mR(;r_
GetFileType
D1$$fA
5j1Wdc
bj4hRmC
7!a-"m
F#3u+E
AWD1$$E
5"Jn?H
-sV?OE
X.F{Te
\'+;RX
h<_07
u~X&yG
wE9&BhH
TryAcquireSRWLockExclusive
PeekMessageW
uI4d:0
m-P5Lim
ms)ZYR7`
Jq|,E,Y
1mRan
,R!/w
Q23kSl[
a+$R" A
P*H\Et!@
|q?Dy.d
/c-WDI
gt"lWsU
Jpfzw
t}w;~3
`itk/
LO5q(1
e.#rW`
;RqT7
GQamR{
TW^gRe
?.tB2-
gvFIf=?l3
VirtualAlloc
faC[vc
9/tuC
w##bHa
"^#$}r
A(7?]cL
Bc|-B|
-VweYm
%CY7-%
%8G0&
sE9kRa
;&j_5Q*
EPa;WT
]Oo>P0
p,3XM}
f"bP9e
{io@-n
saW|K=j
jE0kDtP
iqG32
/k(`rn8
W>/za1
hETD7d
Jhy\BF
D)!TKFG
XA.L+VEG
tLmF/s
]wBUmp5
SetConsoleMode
p7Ex`2
XRN@dT
CryptReleaseContext
2V.T_"
DefWindowProcW
VerSetConditionMask
v]0!S_
NCzwU!e^
fCrfVD
*+*[{"
F"Z'AU
}+/dM,X
zir^/XV
4t%!z+
nSr!PLl
CreateEventW
D14$A_fA
U`u4{=
E\&@S)_
C/MIK$F
_7M8p`
MoveFileExA
%S~w||
|*-~L-Z
0BuCaK
G @&@W
gBp|WE
uSE]IGS
tow S,.
VZ]L80
LTwU[f
m;!/Nm
c&+w*#
*$f}_'
4=[<RS
Om#j)
;N6p#=
+BUfk[
EEYY/R~
IsValidCodePage
KERNEL32.dll
d3d9.dll
gH,ACw.O
`PvW;&
dag@H0
HQCR{1;q
SetUnhandledExceptionFilter
CryptGenRandom
]RFP,Q
"|(13)
/*>RqT
h($w=e
56NHof
*0-~+hR`
H -]T
B5oA*M
IbW7ye
cCx%d4
,6<^A;
yRi7Zu
ReleaseCapture
4 fFj`
_D6Lc W
_B:n[ ^
73$).]bE
ScreenToClient
;~?),E/^
LgR5Ah
\8N~Vf
1AWD1$$E
H`n}xg
i'#>f;
GetClientRect
"3PWZ;.):
"}oK~]
h5(hQ/
wDZD)x
FyIn"8=
Xh>yW$
ReadConsoleA
2aG{Y+
IYR"[uW
TRl2mX
lTx@W\
w|[%"x*e#
D14$A_
mEaD14$I
Jss)UR
nE%-7c
m_}fRr
AWD1$$E
%-Mne3
"z!Z2J
p8RKe/E-
ResetEvent
JSHqk^
`5od5u
(W1Ve+
u!3e7u
/F1|(Tq
iUelAj
{R}Rcw
wc"RI.
B5S|R?
GJS` ,
Y2R~E3
"h>-op
CryptDecodeObjectEx
;D1$$E"
CertFreeCertificateContext
w%0hh#
eN3&yc
USER32.dll
fgwe7n
:fc*ko
c6),dA
@b"fpeU
3AlDfl
mg4O[R
WgZuG7{
`#DR~)
mz(WI)
O":i"6
:(I9k!
f)]v7
EA87B6
[DUwkC"
PG u`@W
F4:<AC
m*(t<#
1+<;`"
K/}w{(
zR~@;v
5a~{r3
,/v<Nlnmc
DR{Xmv
i<~PspK
(7$~Dj
J"c%j=
sB#\a
{"6E N
DI^AzP
\%t%n9
RcrcD:
Zvk[A_Mc
AWD14$A
~ocsf;
SetFilePointer
hcZW9"
luVog4P0
]lr3{-
#ge'5\
VgMykG=8
Wf>+~'
M-@7iC
t HE9A
LocalFree
4G"":
V8 q8EE
)2\4--L
#H&R[v
e2`R>8m
4r!2Bv
t^m|(O
c\15E:y
a_c\]m
aOFeQH1
"K[;%<
Y7AWfA
}]A_m8
f)lz9b`
,L|,Llu
Rl.YmM,
m$.LIRQ
9<$l^Y
CQ]jy/$cZb
ZO[\_/{vk
]Nszd
PL`HM1
%O'c|=
rd y-D
9Cyq!+
m3`.>R/
|`V\;/
~a)~ R}n
Direct3DCreate9
n@PC?I
S-XBc*/
eAA3UF6
K:cGfE
8xIbiq
dy]-5p
+?Xez6
w>L*&7
RPd&U'
JSD+zT3
|?]ZL8*
LoadLibraryExW
P<\YE/x
!pLR2H
3 F}b@
MDCcgA
WVYpC1
KW-_>z
;ERi2Qw
bbgqF*P
VRp^\+-
<*"XRP
tLa\x\
G!fUCq
m{0<]R
RtlUnwind
/NftGR6
5Zo%\
~'y3}t
p1e4EL
D1,$fA
|F5vMc
g2OBpn:[L
yxG>Jsf#
azW<0
LJt#/G
wC{Ra:+
YO0A}I)S
~VD0NQ3
:X~N3
H:]Ax=*
s{P)"r
/zDf~s
xzAYH}6
f_5~Be
bRg\zP
IxGJa?
FRx/oJ
yR7Au
mAjH8R
evWGvR
|n^8P_q
b}=}RV
dGG-i(
e4K`Raf
GetProcessHeap
ppawak
MiCa}n4
hW.!o
|~"UAu
7AlyRJ43
`Lqm5"Mq
=v~wf;
&wt%nC
:R..G@
@|LA|T
Nzhn1
^z$B:z
],Wp{+
~VG-@6
"MlVvK
ExitProcess
|%6r2Tm
0!"cK'
DeleteCriticalSection
[9:B56
m~-P'R"
5"Nf{m
sPex~f
GetCurrentDirectoryW
&b_xf;
[&ECk!2
fKMB7B
mJ\2]M+
-s8]nE+
Ft<LjiV
/fid[~
TlsAlloc
Fj7n7=V
! _,hAl
Xum?Ew"
w~W;(x2.)
kJ9"84[o*
7YpR*(H
XH+B;yF
<Rz-o0
3v-~&/~
(;Aq,g
V6_kql(
25'[h
=^%YR]?Ok
\PMe&er
QLP`)&
v<yI~B
4\H@/9?4a
zep'>m
EFYi=R
Y+#eZt
"B$sdF
Co# -S
p]V5-}]
sDQF)#
etD7zElk
D1,$A_A
%AwCqF
CGp_k
<d`B J!4[6
BQg8wuE>
F?>&e!
5M6)(f
AWD1$$A_D
0oGc.:
9[RB&zx
YnLR'
EETU<cRbg
q0g7
JL\-EdF
SHGetKnownFolderPath
Jf=xD3
GetForegroundWindow
TerminateProcess
3!-xZK1G
yp[Mz=
Fo}%^k
?(EHf@
JNYgoJ
8TX3l\
5Qu[33
GetConsoleMode
l95Rb-
m_eUfRz
u~NZ"Jc
KA&fm(
D-"eX@-
CryptStringToBinaryA
RnCRy71>-
CryptDestroyKey
ggq]|*
FRlj[;-
<Q)rmX
`P==1Y
p9qO@>
<!s1;V
]=5<m:B
FUh>vR
kQ,M[V[
!yen)_=
L+_(ZSuW?
InitOnceBeginInitialize
w0$nIhA
KH)rPRhc
[PT&{u
%OR31X
^RZUE{
GetTimeZoneInformation
y.4R%[kb-F
_\4-K)
[?\Qo0
wSjr-x
GetSystemTime
P3oz%%F?j
_lTGK#
? EeR{}
wU/>Z5p
>EVg,C
wp'-WX
kgU31Q
"nrb,]
VerifyVersionInfoA
~.Q>]:
4#4-8+
qh<v*
2=*"td
HdV5= O:
5Qu[3f
ORcLgC
N<$1po
/D14$A_Mc
mBxUPRF!
SetCursorPos
ld~4=m
0ej{al
geoDWb
`?x&gH
Ja+7zf\
-r Y^[
SetCursor
jsabt1
hfpA_Mc
'{qT@`'
%{qy]b'
83hR6y
CryptQueryObject
G5a~{rf
AD6oAW1
!rRHN~
D14$A_fE;
GetACP
sOER1
I"Vs_
]J$!PA)
f;ah"eb7
]Rd3+Q
UT1mA:
R-mJ#V-
}r=Hq&
TlsSetValue
C i&-~%q
w%YFmz
-s$aqE
m`rxeR
=uB- y
@KSnX6,
:R_yQ6
[E]y1
fKwaX=
vU\f=)
x;gA[>
woVM,x
?(lRaV
5x*YLf;
FreeEnvironmentStringsW
XLiPoC
Z\/B5,
CryptEncrypt
~q@"E)&
aRH|m
0YGO37
`ReFYw
MNX59*G
!m:5W>-U:
>bBTV{6[j
D1$$fE
7EFcf;
d&%mlwy
yez<_
cHW*RJ
m:`MPR>
-V`mRU7
SBx5a~{r;
$(X9#_
x!xdH&
4I Ye@
cI%fSNR
D14$A_E
6"8fD;
A_=lT
-eTe!F
C@zLS>
#C.6hV
,eV-a@
8Ry~[4
PZ5HX\
R:\Er-
MUX7J"
: ]Yk)
m Xf]'/
SystemTimeToFileTime
d*x~`v
Y\t -,
VcjXa9
Jc4yEZ
NH1j'Wh
KirZD
FC1GZb
mJwELP
PZwGL(
#Ut}I\
<F%/#Xm
wl;0%v
5a~{r
f5Mof+
=90/o"
a65x6#s
r;$T)h7
Hmt0@0
AWD1$$A_f
D1$$fA
zVO+&f
[R&0]W
;tHRuZ
~a <R:<
jRZynX
n|NZ^{9
Zq_?!p
chF^0_u
vZ567bc
1"AaO%
r_JGN:
<#2T%)B,8
8R%b
FrbGR8
3]~,f;
YZJ"}6
D14$A_fA
Ok4Le,e
+R#Y\"T
't+[q9
yKr00A
WE6sXQ
&peG4FX
5_/xrpM
PD1,$fA
:,c<L>,
pXzO-6
)R8.I%
"%_R\I
*>-1Ly:m
B5S|R?
wVd[|l
D14$A_fD
4,-`mH
jLBDRV
CompareStringW
4-qG{0-Gc(4m
6\W4gU
j]C{;T
1_5;6(
W0Kzg7<
Jx"eE,
q*_xY
loR(@ }0
qza(A}
\~%[lyR
x T5q($
+L}>!w"
\pr`ubpK
qH"@ZO
2^0SY^
G0?=#]
,R.QL
n)0]n\15
~no]Dk
)]%!4-7
|8Eezy
)DHfn]
-sL4%EY
gWwwmm{xJ
1MHwJ`
-q0AVm
:I W]T
12bj*m
!,aVfA
D14$fA
D14$fD
tA0m1$
nAUQ^F"
X-L h*;
,Xo4+/
;?F56E
,'uB4Pi9
/R^H>#
wnGz5x<*h
2V[&f;
HeapFree
Antivirus Signature
Bkav W32.Common.636420C8
Lionic Clean
Elastic malicious (high confidence)
DrWeb Clean
MicroWorld-eScan Gen:Heur.Zygug.3
FireEye Generic.mg.1d35572dfa6a564b
CAT-QuickHeal Trojan.Sabsik
ALYac Gen:Heur.Zygug.3
Cylance unsafe
VIPRE Gen:Heur.Zygug.3
Sangfor Trojan.Win32.Save.a
CrowdStrike win/malicious_confidence_100% (W)
BitDefender Gen:Heur.Zygug.3
K7GW Clean
K7AntiVirus Clean
BitDefenderTheta Gen:NN.ZexaF.36302.@JW@a8F1Mabk
VirIT Clean
Cyren W32/ABRisk.DTZP-1900
Symantec Trojan Horse
tehtris Generic.Malware
ESET-NOD32 a variant of Win32/Packed.VMProtect.AU suspicious
APEX Malicious
Paloalto Clean
ClamAV Clean
Kaspersky Clean
Alibaba Clean
NANO-Antivirus Clean
ViRobot Clean
Rising Trojan.Generic@AI.100 (RDML:rfJD1UdPqUbNFbWV83k26g)
Emsisoft Gen:Heur.Zygug.3 (B)
F-Secure Clean
Baidu Clean
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition BehavesLike.Win32.Generic.wc
Trapmine malicious.moderate.ml.score
CMC Clean
Sophos Mal/Generic-S
Ikarus Clean
GData Gen:Heur.Zygug.3
Jiangmin Clean
Webroot W32.Malware.Gen
Google Detected
Avira Clean
MAX malware (ai score=89)
Antiy-AVL Trojan[Packed]/Win32.VMProtect
Gridinsoft Trojan.Heur!.02216021
Xcitium Clean
Arcabit Trojan.Zygug.3
SUPERAntiSpyware Clean
ZoneAlarm Clean
Microsoft Trojan:Win32/Meterpreter!ml
Cynet Malicious (score: 100)
AhnLab-V3 Trojan/Win.Generic.C5450879
Acronis Clean
McAfee Artemis!1D35572DFA6A
TACHYON Clean
DeepInstinct MALICIOUS
VBA32 Clean
Malwarebytes Trojan.MalPack.VMP
Panda Trj/Genetic.gen
Zoner Clean
TrendMicro-HouseCall TROJ_GEN.R002H09G723
Tencent Clean
Yandex Riskware.VMProtect!L2QP+SogAHQ
SentinelOne Static AI - Malicious PE
MaxSecure Trojan.Malware.300983.susgen
Fortinet Riskware/Application
AVG Win32:Evo-gen [Trj]
Avast Win32:Evo-gen [Trj]
No IRMA results available.