Static | ZeroBOX

PE Compile Time

2012-07-14 07:47:16

PDB Path

                                                                                                        

PE Imphash

bf5a4aa99e5b160f8521cadd6bfe73b8

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x00019718 0x00019800 6.74852599428
.rdata 0x0001b000 0x00006db4 0x00006e00 6.44295624763
.data 0x00022000 0x000030c0 0x00001600 3.2625868398
.rsrc 0x00026000 0x000cbc8c 0x000cbe00 7.99967767448

Resources

Name Offset Size Language Sub-language File type
RT_RCDATA 0x000f1764 0x00000020 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_RCDATA 0x000f1764 0x00000020 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_VERSION 0x000f1784 0x0000031c LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_MANIFEST 0x000f1aa0 0x000001ea LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with CRLF line terminators

Imports

Library KERNEL32.dll:
0x41b000 RaiseException
0x41b004 GetLastError
0x41b008 MultiByteToWideChar
0x41b00c lstrlenA
0x41b014 GetProcAddress
0x41b018 LoadLibraryA
0x41b01c FreeResource
0x41b020 SizeofResource
0x41b024 LockResource
0x41b028 LoadResource
0x41b02c FindResourceA
0x41b030 GetModuleHandleA
0x41b034 Module32Next
0x41b038 CloseHandle
0x41b03c Module32First
0x41b044 GetCurrentProcessId
0x41b048 SetEndOfFile
0x41b04c GetStringTypeW
0x41b050 GetStringTypeA
0x41b054 LCMapStringW
0x41b058 LCMapStringA
0x41b05c GetLocaleInfoA
0x41b060 HeapFree
0x41b064 GetProcessHeap
0x41b068 HeapAlloc
0x41b06c GetCommandLineA
0x41b070 HeapCreate
0x41b074 VirtualFree
0x41b084 VirtualAlloc
0x41b088 HeapReAlloc
0x41b08c HeapSize
0x41b090 TerminateProcess
0x41b094 GetCurrentProcess
0x41b0a0 IsDebuggerPresent
0x41b0a4 GetModuleHandleW
0x41b0a8 Sleep
0x41b0ac ExitProcess
0x41b0b0 WriteFile
0x41b0b4 GetStdHandle
0x41b0b8 GetModuleFileNameA
0x41b0bc WideCharToMultiByte
0x41b0c0 GetConsoleCP
0x41b0c4 GetConsoleMode
0x41b0c8 ReadFile
0x41b0cc TlsGetValue
0x41b0d0 TlsAlloc
0x41b0d4 TlsSetValue
0x41b0d8 TlsFree
0x41b0e0 SetLastError
0x41b0e4 GetCurrentThreadId
0x41b0e8 FlushFileBuffers
0x41b0ec SetFilePointer
0x41b0f0 SetHandleCount
0x41b0f4 GetFileType
0x41b0f8 GetStartupInfoA
0x41b0fc RtlUnwind
0x41b114 GetTickCount
0x41b120 GetCPInfo
0x41b124 GetACP
0x41b128 GetOEMCP
0x41b12c IsValidCodePage
0x41b130 CompareStringA
0x41b134 CompareStringW
0x41b13c WriteConsoleA
0x41b140 GetConsoleOutputCP
0x41b144 WriteConsoleW
0x41b148 SetStdHandle
0x41b14c CreateFileA
Library ole32.dll:
0x41b17c OleInitialize
Library OLEAUT32.dll:
0x41b154 SafeArrayCreate
0x41b158 SafeArrayAccessData
0x41b160 SafeArrayDestroy
0x41b168 VariantClear
0x41b16c VariantInit
0x41b170 SysFreeString
0x41b174 SysAllocString

!This program cannot be run in DOS mode.
~2#{~-q
~Rich,q
`.rdata
@.data
D$<RSP
L$PQSV
D$HUWP
FD)np)nl
Vlf+Vp
Vlf+Vd
tr9_ tm9_$th
O(9O$u
t*9Qlu%
)Nd)Vh
FL9~Xu
~\wu(j
CP_^][
T$h9T$
t:<wuE
t.9Vlt)
)Vd)Nh
^(9^$u
D$$)G@
w<9G,s
T$<PQR
D$Tt*;
;l$TsY)l$T
L$4;D$Ts<)D$T
p<O#|$
~(9~$u
O@;H s
O@;H(s
T$$QUR
D$ )D$
Oh;O\sN
Gh9Ghr
L$(9ODv
L$(+L$
D$(+D$
D$0^][_
N(Uh0%
t$H;t$8
|$ WSPV
@PAQBR
8VVVVV
uL9=\9B
0SSSSS
0WWWWW
HHtXHHt
>If90t
j@j ^V
0SSSSS
<at9<rt,<wt
URPQQh
>=Yt1j
_VVVVV
^WWWWW
0SSSSS
0A@@Ju
^SSSSS
j"^SSSSS
tGHt.Ht&
^SSSSS
8VVVVV
;t$,v-
UQPXY]Y[
0SSSSS
_VVVVV
t"SS9]
v$;540B
PPPPPPPP
PPPPPPPP
t+WWVPV
<+t(<-t$:
+t HHt
Delete
NoRemove
ForceRemove
Qkkbal
[-&LMb#{'
w+OQvr
INSKyu
)\ZEo^m/
H*0"ZOW
mj>zjZ
IiGM>nw
ewh/?y
OZw3(?
V_:X1:
bad allocation
Visual C++ CRT: Not enough memory to complete call to strerror.
Unknown exception
CorExitProcess
runtime error
TLOSS error
SING error
DOMAIN error
An application has made an attempt to load the C runtime library incorrectly.
Please contact the application's support team for more information.
- Attempt to use MSIL code from this assembly during native code initialization
This indicates a bug in your application. It is most likely the result of calling an MSIL-compiled (/clr) function from a native constructor or from DllMain.
- not enough space for locale information
- Attempt to initialize the CRT more than once.
This indicates a bug in your application.
- CRT not initialized
- unable to initialize heap
- not enough space for lowio initialization
- not enough space for stdio initialization
- pure virtual function call
- not enough space for _onexit/atexit table
- unable to open console device
- unexpected heap error
- unexpected multithread lock error
- not enough space for thread data
This application has requested the Runtime to terminate it in an unusual way.
Please contact the application's support team for more information.
- not enough space for environment
- not enough space for arguments
- floating point support not loaded
Microsoft Visual C++ Runtime Library
<program name unknown>
Runtime Error!
Program:
EncodePointer
DecodePointer
FlsFree
FlsSetValue
FlsGetValue
FlsAlloc
(null)
`h````
xpxxxx
Illegal byte sequence
Directory not empty
Function not implemented
No locks available
Filename too long
Resource deadlock avoided
Result too large
Domain error
Broken pipe
Too many links
Read-only file system
Invalid seek
No space left on device
File too large
Inappropriate I/O control operation
Too many open files
Too many open files in system
Invalid argument
Is a directory
Not a directory
No such device
Improper link
File exists
Resource device
Unknown error
Bad address
Permission denied
Not enough space
Resource temporarily unavailable
No child processes
Bad file descriptor
Exec format error
Arg list too long
No such device or address
Input/output error
Interrupted function call
No such process
No such file or directory
Operation not permitted
No error
UTF-16LE
UNICODE
GAIsProcessorFeaturePresent
KERNEL32
Complete Object Locator'
Class Hierarchy Descriptor'
Base Class Array'
Base Class Descriptor at (
Type Descriptor'
`local static thread guard'
`managed vector copy constructor iterator'
`vector vbase copy constructor iterator'
`vector copy constructor iterator'
`dynamic atexit destructor for '
`dynamic initializer for '
`eh vector vbase copy constructor iterator'
`eh vector copy constructor iterator'
`managed vector destructor iterator'
`managed vector constructor iterator'
`placement delete[] closure'
`placement delete closure'
`omni callsig'
delete[]
new[]
`local vftable constructor closure'
`local vftable'
`udt returning'
`copy constructor closure'
`eh vector vbase constructor iterator'
`eh vector destructor iterator'
`eh vector constructor iterator'
`virtual displacement map'
`vector vbase constructor iterator'
`vector destructor iterator'
`vector constructor iterator'
`scalar deleting destructor'
`default constructor closure'
`vector deleting destructor'
`vbase destructor'
`string'
`local static guard'
`typeof'
`vcall'
`vbtable'
`vftable'
operator
delete
__unaligned
__restrict
__ptr64
__clrcall
__fastcall
__thiscall
__stdcall
__pascal
__cdecl
__based(
GetProcessWindowStation
GetUserObjectInformationA
GetLastActivePopup
GetActiveWindow
MessageBoxA
USER32.DLL
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
HH:mm:ss
dddd, MMMM dd, yyyy
MM/dd/yy
December
November
October
September
August
February
January
Saturday
Friday
Thursday
Wednesday
Tuesday
Monday
Sunday
CONOUT$
1#QNAN
1#SNAN
SunMonTueWedThuFriSat
JanFebMarAprMayJunJulAugSepOctNovDec
`h`hhh
xppwpp
RaiseException
GetLastError
MultiByteToWideChar
lstrlenA
InterlockedDecrement
GetProcAddress
LoadLibraryA
FreeResource
SizeofResource
LockResource
LoadResource
FindResourceA
GetModuleHandleA
Module32Next
CloseHandle
Module32First
CreateToolhelp32Snapshot
GetCurrentProcessId
KERNEL32.dll
OleInitialize
ole32.dll
OLEAUT32.dll
HeapFree
GetProcessHeap
HeapAlloc
GetCommandLineA
HeapCreate
VirtualFree
DeleteCriticalSection
LeaveCriticalSection
EnterCriticalSection
VirtualAlloc
HeapReAlloc
HeapSize
TerminateProcess
GetCurrentProcess
UnhandledExceptionFilter
SetUnhandledExceptionFilter
IsDebuggerPresent
GetModuleHandleW
ExitProcess
WriteFile
GetStdHandle
GetModuleFileNameA
WideCharToMultiByte
GetConsoleCP
GetConsoleMode
ReadFile
TlsGetValue
TlsAlloc
TlsSetValue
TlsFree
InterlockedIncrement
SetLastError
GetCurrentThreadId
FlushFileBuffers
SetFilePointer
SetHandleCount
GetFileType
GetStartupInfoA
RtlUnwind
FreeEnvironmentStringsA
GetEnvironmentStrings
FreeEnvironmentStringsW
GetEnvironmentStringsW
QueryPerformanceCounter
GetTickCount
GetSystemTimeAsFileTime
InitializeCriticalSectionAndSpinCount
GetCPInfo
GetACP
GetOEMCP
IsValidCodePage
CompareStringA
CompareStringW
SetEnvironmentVariableA
WriteConsoleA
GetConsoleOutputCP
WriteConsoleW
SetStdHandle
CreateFileA
GetLocaleInfoA
LCMapStringA
LCMapStringW
GetStringTypeA
GetStringTypeW
SetEndOfFile
.?AV_com_error@@
.?AVtype_info@@
.?AVbad_alloc@std@@
.?AVexception@std@@
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
vjMTVVr
y-jW6yyLXz4`yPp&c
{F~c)'
k/d@ye
${D9J5
]* F2t
PjC:zo
"gP[\S
Q4.P)p
~)G<2L
iiQxh/
Y'&{-^
@nIcem
/f&uQ
DKtOX@
=\x[/R
7@X^Y-w
c:6gOI
?yYU]$w
F6"&;Sw
P)f `qE"
nec7/UFt
C<M/ZJ
6AZyk~
F3PVK8upe
#8ci4jz
d.E%?4
eqlO/C
p@R~hF
G~DTwN
.EW&C
X0<T#>
]jbTHsT
r+GH*)
.(.Xn-
Rnp&Uh
N7Wf:W(D
Oy/[ w
>p9Gw$$G
$s+ev<<t
$sw'9-
`Dv (s
*"["@Q1`W
z5@F)XJ
r[:~jI
s?k<p|<:
rvy~~"
fJI[L@
Cn8Htu
BlzGD"
Q:+&GN
o,]$&|%k\
~}%ce=
<[H>:|
5x]r{N
maLUqz
1l}g~r
,cEjr?-)
]7-Lg$,
8LhOf=N
,guz;q
d:wOb-V
FRkEDU0a
Q+hj/WP^/x
vzSvp,W
n94LE(I
XL/Z]c<V`faz
fjp`J{
06D%VA4:
ryeR^AW
\B=~3t
FTwK4Z*
U_i/eq
e6V&46Wo'
m8@T~Q
@kX}x:,
o z&jnd
bt-Fg(
gK!A$?
1'`hDe
R~B[I\
]4j^_D6
'T/Y?Y
^l!5R(&
{Z~)As[M
7/o^P>&
[91|[s
1(5gaUiH
cT#?hp
9'|Tiw
~x37;w6C8
0!1{C1
9s%zP
(.tDPr
tYO1f^
Qqe(6!
|VCkV_Q
">:nt7
{Fj9Qs
imi}u;'
z5uE(v
~^1_rX$
R-S/gt
B~xTy7?}>
.j+/{Y
;w5OBS
q)d}sj5
!D!!<iA
>1:~4x
}i_0\3
z<?\XKz
XCKKv9
q`"=@r
@1<#x@
j8;+Js
W%4L/G
WP^#O
f-P|X$
lIrWWQ,
5]WU#DH
6?5]U`
"=;=h6
<9_Zi q
,{UA4hN
A'nGw7
`[a`R2V
9:ooaVu
zS&e-
8aV/Gm
+[H/0&0
3IW$!
PP=)n`
ti:,d2Q
^jd]ZC
JuG^2=
WhD;C%}
tHMR<7
5yQ.dZ@
`"\+VLQ
fi\KlWS
R_S-%Y&/u
CdOGTe
bdbY#<X
Bi$q=<{
Q 6n{
3jYZ72
Fn`mE)
Gp0S3!
&gw( KE
n;Gw,l
!o)3t~
7&H"|]
h<,wO2
+h}M5H0
hhV4rQ
QYF%.*
,Axnb]
^5L^:Yi
hwpn6.&
"JLJ%]
F^:}F5
n9wm@y
/)mAg=G
D$fU>}
qVfao?
M~O_nb
v)kZ+m4
C*1uin
2J<2g:
%F0@Ri
S<1LGf
_8zW(4K
3.%"0+
mrpFrn
6mKj'FR
O6l8Ds@
#=4hxG
Q!IF$6
\$)li1(
WD7l,{*
5zTRf(
HYPa.
r{.Du;s
u1f[Y`d4
4pJz:1W
_{1=tm
bcQ?Sa;S
.Qe9sV(]
.<6x@1
Gg6,/h^
HuYMm(
$'_Ohd
%.Mndh]V[
w&L/1[E
j*!1Ny
!9X;4S
N|Vo:D
0/UF3<
RtMp=N
+]nD}UQL
Rdy]E1>
dDC{P*
D_j?vxf8
\"QH56
-C*Y[H
XUpX"+
sg"/^'Gk
On;rQUC
w5YTVE
We^F&H*
M[9wL9j
+7e5#[
{5Oe~.
~tVTekH
^^@}.pr
[tM6*H
sJs{GK
~{0z K
t[>fqS
Aj@O?P
<Vi;'O
za1!EM
}n4IuA
TCD+Zy
Bq~ IC}w
>=,EF_
am~:l9.
0%e]#t-
uy.'&t
xu!;+_
a%CZ0/
5;WC;0
m~ P$D8
ckUA:3
kf]<TA
+dd\4NP
/lOuq3
V0$;:)
P6e;&k
5}0sIVG
O*'1tG
~H[Fkg
FDj@]u
V&,vPG4
DaRd<rl
GB9fS5
++Lcq7
ko8F]2Xr1
xGyL1t
l6dR6s
t\M,b}/
_vc^OH
\C,\Hz
8 :~5J
8wkD2Z
jX+!};
^9Bj}$
S3<<sYX.
6n/8~S
3(a)U`
O<fNok
`ate|Z
)7#X O
'4'kh>
NgU0VN
|}_K Z
at`t^~
'LX]l/}
av,Fas
d\){T]
]>qGOp
xj^]15Iv
U?<QA'
X}X0U.
_/h<Wc
SOc2!sU"=B
[1kRAO
vZk)"NZ
ddr;J9
@;uGY*
xSA7b
`JN8@A
JU.I'y
gvxV 1
=@l@P`
{!=GFyD
.?l;f!
yBSYvk
_ q:ZQ
FB;I6P
Xu</oq
*P+h,]
OEnY[!]}1
Zl&K-5`x
+$(*0v
guDN-_
B|EmC!4
0Qa%0
-51}{_
e}#=s{
mNI9Dr/"
6Ky<<1
j(z.4f
aS@~6o
oA?!'/
<;;*/6
41VikfiB
P^kvAP,
OM{3gM
_Zc;O]
]yFZ[
YnY;r.
\)D2fBi
q%fVB-
WHYc-~
vuK}JB<Or^
0ZdH$k
y%EIOh
)OPDU]F
UlF/J[&p0
"j"war
tzp^SL
wyP(OS
UH&&%[
:re5wv
S|_N{a
X4W~j\
=yT<|;b
^o3W06
~<>dT7!{Y
Qn=mu
5P*VBl
B't_:V
fGv2K2
:aY,V)
!^)xK-
q,vJ#F
+9u3hR9
iY&f;&
>v:\Zw
`@fWGz
u&/-\h
[Fo[JX
I2Z<asOH
`g/Rm8
0&ik6Ma+
l`NU9N
\/aHtq
Xn=B+O^:
-U":!+
1ci3124
43Fmue6;\6
:Wtre6
&M/cx@
_?}DmY=
\ylu##
'p.EtMC
f<T3t0
~.8I3<
lkQ!UC
]e!s^$
tKN1*'
o-Va\vr^
wQb.%w6
~(9abNF
+}MR4g
c8O8jJ
?]O15]_
DW]US]
8gbfeYn
qjU%1;U
[+5J`?
BPCruq
7V+F<=
OH*IU)
a.6*t{
w6"TtUIW
"vz[`#COT
g$\&8(
~J-* k
ht KEey(r
$wA&pQ
<N)g)g
Gz~3G\
xrpg;$
4JhocS
RHS&2\
`)`0,Gh1
#M^R/o
]WK.ZH
? F]h
HwIhW^
Dx$YCb
Vihc~
y+ZG_80
OgE8+=r07
w+c<@n
)L7Kgb
}nyyg+
9Q@s>P
FlPR{D
bi )"?
dTJ:d[
=N&,I0
N*ZSDI <`
krl.xp
&}qP}G_
Cw_$E{.nOi
V@]B.|
GsY/mR
;wI']f
aIA2<3a5
2s*\FH
*giu(cQ
B:0N.h
.LpAt>r
0C6IVN
*U\*4n2
DZa(qqx
5gy^O>W
y_d;:R`
V8WPP:
-\BurYf
0eK`R'J3
O797nw
<G^W,"
d'_|c"#v
ILH;s$fsY
c#[9Y#%up
hT:u2Q
gJy-)Ys
v=bx<&
mg,N7sO
Vr|0 {
oM[O)]ML
D<}LqV
)5_3cQ
9SQIWb
EA>YSM
w*>'M?
kB]P=mK
bx;:{t<
D4lWaK
"vB _\^
`#l0}(;U#
Q%4RI
[`6h>C
dK[Z~w
)2[P$z
-jh^`%
(S1F}H
M{YLDQ$n
K`U?"(-
E,Jj90
T]>9x1(LT
eOQg0x
GW@[73
VY:v1?
d")&HE
NGK(wu
TK(jG0
izd !|
-iN7v|
?EXp3U
8Cbz`Z
7k-/]8
5x|.I,
P{xN)~I#
D5*cX9N
W%fXM[$~L
\GzAb)
+8`s,t
<n{Jh=X
00@y\Sj'
,exZGa
-_)Bu
fw&56`K
Fj3d@f
7~a3hW!
);6T?A
vuL{e]{"
9H}2eOBj
7JWuZ
7{b?o@
VySX
yy8Da3f
}HdoD=+Um
4!)">_0
E{zCif
PKA>GxAopi
HjnKqX
QW<tCS\b2
gPNfi
&;fDt&
'8;eG"X
<]q+YX
Q%LQw
d@F2KMg
]x3sUT
&nD`Z;
ic&/EKt
$-wVvH
LUYo4.
>rt@Tp
a#:^B#%
#Lqdh>
SpXX1
v[hL,O
v$Ub&!
wo88A#
Jgjy3!
cJ\}UT0x
dC>:i`z
GJ>/n%%g
Srq\'V
T%bN6Q
(s4 |T
-j*/RZ
/%}rmqQ
z-Yke[
WD6$Oz
9#}j1%
O7r|(}
Oue`^2
EJ?1$e+
z[B^?a
)39PcS
s1<M_V~A\
6E=A8)L@
z@pZ2`;b
?r&6Cl
l{#V+&]
NC5:7*
i(QZ(d
H+nj&H
"~`&J
DDnV_)
h$5^|PVt
I{M4X'
ddF>cy
k?z>W
K#-Hm;
h%87zk
8s>iB5
V-O3Nj
O0'OBZ
niEV-vD
<'i.Ns(7o
|_3",%B,8
d'&5]?
e1!s|g
j?G?d%9o
Fv{#;;
O\t8fqF
:d+Z4O
xrUr(Jpb!
D1Nkm3
!\&:GB
}"7uZh
d<>%u\;M tE
7JvW{*
<#|:#o
t0lk\uK
q(~vJ
H);U>[
G.zuh4
IiYcXx
9SY$<b
jF6HOV
tMT@1w
`!ymGe
RI~y`Cq
9~d.Cb
G4lBZg
OxTr92
2nj5.R
Kp<4;v\
]G%T1Y
7ys&<9N
nm`_fU>
_De7.#
M{lW~P
hqF0Uj
FWLb=G7
[L/\X0
;N,zxk
)%XGJ
r&)ACg
;?h8^J
M#igi!
M-Vd(y
d$!/PF
#HBB#in
P4'zUS
qn6\<6
Tzr#ut
<a]t)=
d8NH+D
ylYNNE
(o")Z'
W4{z/
PIA?=b
o{htg\
YJev)A4
_$("DZ'
qgrT C-
EFqC|W
C{t)h{
BT>#2J
B$ZVI9P#
.#84`
3j+_sv
e8=&yxR
u9\t[7
ne%jV2
Y5sUAecG
DA9&]Z
!|3*LQh
IAz$=
TwVqkV
b>eGNY
rWM{~W
:F&??B
yOMY({
L;GzOnG
lRH<){
4GHp-V
C"w*g=^;}d
KtB&E6Tg@%
g(4'eS0
8G#bfu
P=T21[J
t/u>T
TxBG0X:
viG\04
\cnU\pD
|(74+80
&<y6WJ
6SG/V8
l~4L!?
9;8T*F
'WMVJx
9lhfx
RL0by-
jn+FgJ]
n>P*uS{
m+y-^x%
ijZZb:%
v[cfj8
_L0= u
p_m~DV
Gj.Mz
A`wV>5p
2P>Ptr
E"u/Uf
>_E7M<
!Q43=_
s"iu(#4=
gL-T/m
\(UK*K
.-\RW9
Oc\sl)
jmy?AI
#K4<wx
TpBu.,
A\!H<H
><I!B7
Sklpm
jb4xR H
yC~[")6|
A)\E=(o
\sVKWe
yKFn>mr
853^<CI
Mn1P'Kx
@(eurg%
Ttz$W/
X_p'i:t
^Wr.;d
&t9z"D
L4|[\r
'kBTHVyK-P
y}py{W;
sw:q]v
o1KvK
)tm+2H
&)9W*J
@&ogta M^
fap:y<
Q*w a*B'L
aq CGc~
QRPNLX
2uDs6o
8Q6cW=l
.FtFzGD
QvsXf^
Y0^.'S.
kJoT&e
wg bo'
XqG'J:z
bWG](t
e}<kUl
V8J}N2e
42T`-yZ
1(O*65
6wkG(w
w?2up\
}?%{|Tr
U:<kDz
(O4UH0"
"[KmXh
bWUq6K
ZPZjpl
0QZ!BJ
rT+;Ff
torJ}U
^C%aKC
yEduBu
{*xB?R,f
vc9\Qi
@',e/m
!BrT{|
7/*'7-Q
HUX>Jv
,eWpP%Y%
|-zm"#
tnL*rf
>I>9?/<
wo|dtB
0A~9"x
*6myb.>Z
=N*?PWa\dj
ckOd?*
3 Sgm^*
l39{2:
p"QDqD
`BOw]7;:
58p/rf
3412!,Z
D]TEq$
2e@2a*E
?|>wrq
>%@_uL%
_D%<{(
8Gi%<4\
} ?P}}
a_If?l
S~Eqo'>]
YAR\F'
46_<p,
{XNbF81
6}h0_'
Z}d'u!~
V12E'/x
<PHoHf
[<lXd\SENd
-xfWK"E
QJ{Xq?H
+>fwi/
@;m&|<6
uw0wkw[
lGp=f
tKY5lt
\9&xKVJ
G~TO6}e
a]u-?pc
(cO9 G
A#6^Nw
z[e<R/^
:P]4PU
_z&a0+
utt">Mb
y!sv=3
^gKK/@:
O!jTo,
uT37 5'
c,aPK'
]PHO$gs
NKFdbO
kJ_yzw=B
Aj7g4G
`;\seX\
s,(PA,
ca5tul
'9?"+c
IEQ|IU
\TPeo8Bn
SLH+bjZ
[ww7V'
rZI6pR
T?I]4t
xKRw=
:22Z2z
A[<?|,k
o7AZ*:
G,!1jx
Zf@}3:
^mQ&:|
z@d+>h4
%kyoo.
z_/Lxl#
9$F_*z
u:^DT]
ty@i"K4
.WCcg`
WxVk*H
*_g/dM
DIJF(nAJ
H=E.<Y
W;2l.`
Jh$wmAL
M^tj|m
ba2h8!
`Eo~"J
"b#?,}2t
d;%3#S1c
<v: MrU
%X72s<
B==3jd}
yvK$jw
qStuG{W
N[ayhh
0.&d+d
ElHPENY
8`0Kt>W
$9A9+s
i*|G;$#
I+(YcQV
[_Pb#g
_p`#5QY
eHlAeN
tM]l8\8`
U<i=qJ
{jeR32
Y25`59
e xWv(W:
v{qlY~A
MFpWs.
cda}#9
@ u.:C
wqj'13
]bj3~1
Ykd\s[moA5*W(
p$&f,2
HuCsof
BZd (`a
XuL8qf'c
=k/-Ul
HL*mXE
,vwP"[@L
174uD)
32fIJa
=Pfp$q
FR6;kQ
x|MGA)
Llq iMG
nv+_$~Q
[ToA5<
{gF8:*3
w2>w8'
rltmr0
oL8+9IE9
_@:).IF
$wd3QQ
";*+5'1g
!39a>{
F<hR '
7@XLxMZ
O]Q^Qw$
^Ar`M|
)e(_'5
V;0yf8/
!p{{ak%
{Iz6Te
"p}Otv
XJGpr90wT
"$X."S
dBqYI*
Y4C=XV
:Rc{sh
>=l4k)
)<$DZ,
Hm}-en
aA\Cdi
QY~#1C
Ef9!_
)yH)#A
9&0as'O[N#J
`DA":
a#,44u
*HIXwb
l>Va)c
Y+a|+DN
S$@!'A
MVo((!
B96'GN#
Pg%gpC"
bSI*/Su|#
gQR &5u
2J.Z*\
b:6;!F9
H0mL>(c'
bT:Z.z*~ %
4l]dO5f
O@iSvUC=
zav#nmv
`J=sex
mc=d3KR
mgUgQ
.4pV7>
c}6y<%
9/88Z"
s05Q1)C
sV-Ww(>
=@vF3w
v&ay^ZN-AMX8B
X50^qL
!hg%mf
OoU|W0
u3AY&.
$4|RVD
pi*wgEy>
Yq9j#~gz
7@4)|q
>"s5my
9c/v+8
ha81R|
-KGklQ
::U_7f
>WO0<w
0!Mvub
t]NAy&e{_
d*R eG!
c_RZbL
jNrF?W"h
!AJ3De
o:EBfM
-TfDbx
K,d0'1
g3J|PA
iSEY&K
VYNSKUu
pvTo%q
o)mq&;
5}Vq_9
?5T'97
awstW
;R6m5;
Q^:@i2
.R)m1"
.pD,,t/
W-BL]0@z!'G
j2Ct@<
1@roa5
I)Nz'$JR
5j67AJ+
vlH;8j*,I
?nVMj{w
t;Qk,O
08D9AE
+.r9I}QA
>KH_qqA+cf
[t').#
~[KK0h
sl)+hR6
[I"~x7
+F(QkX
no5E+%
!/oJRJ>
*0mSrb
HCf`gKP&
W}Y8.r
@d"=TDQ
1k$/q&l(
#PYOWs
-8)C**
_%!8t
a!thP]
o7bh`>
f]gN/1
Q}U`~s
/3,D~_
f{{h?btBE
Io!'Y.
K:ldo<
Py_6-rAo
#%'M;"Q
MWja+)
xqxGDZ
daDbQ.)}
|Zqw|'88
QHk(R_
"J$Ppm
#`zM{N
4OgLl/2
'=Y"Qk
>wcQH}
6Bcp}7K
*yJK%b
32d5k<%
^\jJX;
Go^#*lPP
%lmV F
1l?lUq
=DrpW"&o
J>?A2kf
&NoyV$\
ZBU}8(
'Rz,0+]"
%kr7r
0irzs})23
j[q#zhHA
xX5HlS
<iS?&D
oTc@b(
|P= oP"
RBpPmj5
qX_d^+:y
+-z9v%
*#dj!/
G(v:qv(<
p%3;)E<`}|f
_-s^xi
)tuZTAD
#^-4k{
|HB@-oQ
0@pKj8
I@<Bj
5c3lw
"|tOr1
BNG5<T7
D)a<^n
p8nG"A
sQ#\Z0
TUm3l^FY
4xCT'BC
0UfxX\j
4}/9-bj1v
yh{,Qj
i(05#xz
k#o~:Ix
W\Wz2*
O~1:~X:
3)j83c
#TfBrr Nc
i 7^4e4uj
SpkTml`
C^^uFG>]}S
F>&SX
`b_->
O@^EAke$
[vdmG~|Ay~
)Ip;qq
k-l)u=
>nqh; Iz
qt>TXz
RU20=9
H//ny\
JfI"pGVn\q
4@3fd}8
{YC+n+$v
1Eu$?i
aXdsr8
AGLz3\
`{XvI3\M
F~XF6|t
RjM^r1
MDV<Lx
fgxF>%
46^H>5
bt~Mbr
1:*"^g
5b+zlAn
y/y\3e
EC_(K9
NEd6eGfB
6<Jy*X|
U5?hL_;w
a5HJ'"
HT8?qc
wMv"1-Ntr
@7GbST^L
+K_cMg
?6%}f8.&
*L-n&M
6G>_[y
QjH.V3T
M4ra#e
0Qb_DZC{hs(F
9@n8&U%
lm9z2iA
KNo7:%
W*3Xz0
d>;gbi
g\4EAQ
^3tzuX
b3xYiq.%[
I<26JZ
^S^k#LJ
Sl6*;*
Z1^~JS2
j|T{,b&
D L<gt
2mH?^B9S
]N\s&)!
']"@#SLG
:53p5d
ZegfQ"
Am*Tn[
d+ZnJk
z 6byT2
7!P6\g:
s *C:9
uX?+&
/~=otGP9wsq
Y18GH/
ZbhJ|2
qn)~xg
uOJSaA
A6,xWpS[
:9fS@R
:jBwbFV
)/R1<[
vimX(C1~
r*|UezH
vg],TmZ
X}{7%e|)
HAp8|W
WZ:NmtF
kE3X!QG
zP0J0.jM
ZA2jn}
#GFr]F
$T:6%}.
$*[Dbe
vU/R7s
42`iG3
Pvx(+T+
hfCfnP3
c$<0s*
t+/`Ha
:oa06b
WIX'y6
JF-f="
a,S?3.J
wB(Qf
U!(jh?
*NDOl>
H{AAT2Mo`t
A.I5?6G
PX~8 S&{
Z:zNNQ40$=j
HMaNkR
~-Fr>?^
_/zqYE41
>5 |Z%
$OC2lF?l7i
@:ccZC
8Y6#GIX
fN^pQ|
'<t#E#
M:p04}
\*8s4Y5
)rHmPA
},KP0$
-X~e6w
EvGLq$
nfb1zx
d ;5ZW
5Jwv%z
B#V{M>Q
FA,xqW
[YAP7T
wH3Ikmk4m
#Mi0*"{
IMFy`.
#Rz>|:
UE90A\
(2Ah{`
$^(pS/
X1[]aG
/{EG(dHB
DTE5>L
4lNd|3#[s
y{bqSF
4M:Q2)
F>+!
<`$CJ
kXUuA~
e_F}A)~
+U;b<-,I*
jBBSoSG#n
EVc8RZ
,^tSQI
(w=ge-
|xx:k}z
Q=&;;{
|o{MwUL
[fY}l
-Dga.AZf..b@5
*^8%'l
9 2c<IS
_B/!qQ
Q[ilro
o'7IfK
Wwh5>5z
N2[;,
f>P*!d
0'VrYt^
0`v7a4
y+Noals3
|H4ka#
\TFY+P
XlM3]IEv
~ Ia'*BZWB_
&H=aJW
8j~(-)
'9$hrcfS
19n(ed
m5~<\,?
};qC4k
MZ2r7O
h2<=st
Qrb%UVFh
]k;^^[/
qTe\;Rs
}y^3q\~
KHE&$U\
*iE|F4
GEwz|4
=ctFwIm~
sPBP;;
LMNV Ti
])&}&I
)T-('@
x4r:O~&
\n)X(h
#-0(gB)}
)S8b55=
(tj]~t
@yAn!/Z
<T.qJ#
ACQ(+Y
rOrik\
TTcQb@
!##ee-
yUhRNr
Yk"59rD0;
ehEZRb<L
nL- wJ~
rvq|A' i
OXTnP31E
Ze%!2fx
Hc?7?"
@".Mvb;}R[z
(a/9;An
8AFMy:
Y/-B"R
b:1j63W3
EBpw?ah
EG4S_5
w|R<N_
u/xUXQ
r(.;v]
[?6_]H
l;rmQf
jw|&GD
":NQN
=_ ;~&
jN}m5,
> q.>a
YBPomV
ndvUet
h@liWe
qgNV`o#H%)M5
o`&deY
#.M@ws[~
eR'eNOI
s9t~CO
Om@Ms0
YID#~
.eqr3V
,n{Q-?[
p+mZ;G1Yq
fq-A6"
1\|[H"
3%>,Ty
;&3.@I5t
k&t@R(
g$4Mt6
l"P[y<%
04yyP6
Y0T*&*
uMjF+!
/k\@\8
@!tC;Z
h#Q,xA,(`ctNQ
t}Fm0nE/
E5kzN&
DPVMj^
jb&n4
(%J\UP
FoCj,@Q
vRn%7x=P
JK%xz&
NRQQ,"
@['*J;
?xRjX8f
U[C(Oj
D5dQ"\
?lH7h[
8VB\`!
e&U?=p
a6q8H!,
iY"v9(
rzPc"E
xe\tpd
s-%CK
N?"a%~
Z8ZHaa
kBGQh%
=3%5xO
-<BuNU^
9u7x>h3
Y**fZo/
,TQw\%$
U_fx=_
)\fdH5
=QG%?]%
MK<~d~
k2Y5Y25
.F}r1=
y|\E;5
K'(bjV#q
TL.6Xu
H@&q;e$
X)|#+6
X(xBhR7
an;7@?
"{|7?6
lq31}dq
Hwd)Ht
*#_V9M
UO] (w
>7|tH7
wX-6)c@
&K;IK4
SE$Pw"<
i:r2q5
`ujV$r!gS
0Z)r;]
ay!T[tP
8tae\#+
q<~@"d
2h5f_|ny
Te(c2E
%pZOp{
_46b=l
mL3CyI
dV ,!{
Cm[q(6
\UM)u&
#*WS$L
6'j^cZ
:F-z-8
BzcEL(4
A:v@XI
w7-*EN
oi^'H~
NX}Eb_Ip
D?z41oN\
p(*OM<~.pK
=$'\!tq
;%`{-\
XE+7=n
[,V+t2
~nMM/_[
;CY2Z-!
^W<i""L
ZfbWen#
L&Alhllo
WhpZt)
T+OzE#
fO6i5G
=^-MoL
io5KWJ?
TuXmD'
(A*Q5`
5=F}:V*/
TuxLzp:i
6X`Q (&9
HG$2_r
R#kdyJ~]8U:g'
:Zx!$q)
w`^HEY
2f@AKR#`
s:!4u,L
T8Ht?t
US#7Tq
;[G'pA
DP{Op5
-T@_qX
tvT[!-
sC8trr
$k9!cZ
H^x51I
]_.Xo'
%|q%}^
e#9aa:]
&iBsb8N
wCqx`#wj
sG+SS*
X+hfA^i
abU),LQ
[0%lc(.
NOZvT;N
&"f+<<
\<=^v@[n
]`z<wz
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<assemblyIdentity version="1.0.0.0" name="MyApplication.app"/>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v2">
<security>
<requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3">
<requestedExecutionLevel level="asInvoker" uiAccess="false"/>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>PAPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADD
#+3;CScs
mscoree.dll
KERNEL32.DLL
(null)
B|BxBtBpBlBhBdB`B\BXBTBPBLBHBDB@B<B8B4B0B,B(B$B B
((((( H
h(((( H
H
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
Comments
CompanyName
FileDescription
MNKLOP873
FileVersion
1.0.0.0
InternalName
MNKLOP873.exe
LegalCopyright
Copyright
2023
LegalTrademarks
OriginalFilename
MNKLOP873.exe
ProductName
MNKLOP873
ProductVersion
1.0.0.0
Assembly Version
1.0.0.0
Antivirus Signature
Bkav W32.AIDetectMalware
Lionic Trojan.Win32.Generic.mCKO
Elastic malicious (high confidence)
DrWeb Trojan.Inject4.59123
MicroWorld-eScan Gen:Variant.Lazy.362667
FireEye Generic.mg.a79a555d8074362c
CAT-QuickHeal Clean
McAfee Artemis!A79A555D8074
Cylance unsafe
Zillya Clean
Sangfor Trojan.Win32.Save.a
K7AntiVirus Trojan ( 0059c7971 )
BitDefender Gen:Variant.Lazy.362667
K7GW Trojan ( 0059c7971 )
Cybereason malicious.dbb9d8
Arcabit Trojan.Lazy.D588AB
BitDefenderTheta Gen:NN.ZexaF.36318.7q0@aSS8RMm
VirIT Clean
Cyren W32/Kryptik.KEF.gen!Eldorado
Symantec Trojan Horse
tehtris Generic.Malware
ESET-NOD32 a variant of MSIL/Kryptik.AHLP
APEX Malicious
Paloalto Clean
ClamAV Clean
Kaspersky UDS:DangerousObject.Multi.Generic
Alibaba Trojan:MSIL/Kryptik.2ec2ccf5
NANO-Antivirus Trojan.Win32.Inject4.jxijhp
ViRobot Clean
Rising Trojan.Generic@AI.100 (RDML:5AJY8YSh1XctWxiSUm36ug)
Emsisoft Gen:Variant.Lazy.362667 (B)
F-Secure Trojan.TR/Dropper.MSIL.Gen
Baidu Clean
VIPRE Gen:Variant.Lazy.362667
TrendMicro Clean
McAfee-GW-Edition BehavesLike.Win32.Generic.dc
Trapmine Clean
CMC Clean
Sophos Mal/Generic-S
SentinelOne Static AI - Suspicious PE
Jiangmin Clean
Webroot W32.Infostealer.Gen
Google Detected
Avira TR/Dropper.MSIL.Gen
MAX malware (ai score=84)
Antiy-AVL Trojan/MSIL.Kryptik
Gridinsoft Clean
Xcitium Clean
Microsoft Trojan:Win32/Casdet!rfn
SUPERAntiSpyware Clean
ZoneAlarm UDS:DangerousObject.Multi.Generic
GData Gen:Variant.Lazy.362667
Cynet Malicious (score: 100)
AhnLab-V3 Trojan/Win.Generic.C5456834
Acronis Clean
VBA32 Clean
ALYac Gen:Variant.Lazy.362667
TACHYON Clean
DeepInstinct MALICIOUS
Malwarebytes MachineLearning/Anomalous.96%
Panda Trj/Chgt.AD
Zoner Clean
TrendMicro-HouseCall TROJ_GEN.R002H09GH23
Tencent Msil.Trojan.Dropper.Najl
Yandex Trojan.Kryptik!6fOiYJ5LTYg
Ikarus Trojan-Spy.AgentTesla
MaxSecure Clean
Fortinet MSIL/Kryptik.AHLP!tr
AVG Win32:RATX-gen [Trj]
Avast Win32:RATX-gen [Trj]
CrowdStrike win/malicious_confidence_100% (W)
No IRMA results available.