Static | ZeroBOX

PE Compile Time

2023-07-20 00:06:02

PE Imphash

28f039ba63a716b696dd5058ca2bb671

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x00014564 0x00014600 6.6334719347
.rdata 0x00016000 0x00008424 0x00008600 5.0148928139
.data 0x0001f000 0x0002d140 0x0002c400 6.7369731715
.reloc 0x0004d000 0x000013b4 0x00001400 6.54109170219
.AllIn 0x0004f000 0x0007c830 0x0007ca00 0.00146327933135
.AllIn 0x000cc000 0x0007c830 0x0007ca00 0.00146327933135
.AllIn 0x00149000 0x0007c830 0x0007ca00 0.00146327933135

Imports

Library USER32.dll:
Library ole32.dll:
0x416148 CoCancelCall
Library COMCTL32.dll:
0x416000 InitializeFlatSB
0x416008 None
Library KERNEL32.dll:
0x416014 CreateFileW
0x416018 WriteConsoleW
0x41601c GetStartupInfoW
0x416020 Sleep
0x416024 CloseHandle
0x41602c GetCurrentThreadId
0x416030 GetExitCodeThread
0x41604c GetModuleHandleW
0x416050 GetProcAddress
0x41605c GetCurrentProcess
0x416060 TerminateProcess
0x416068 GetCurrentProcessId
0x41606c InitializeSListHead
0x416070 IsDebuggerPresent
0x416074 DecodePointer
0x416078 RaiseException
0x41607c RtlUnwind
0x416080 GetLastError
0x416084 SetLastError
0x416088 EncodePointer
0x416090 TlsAlloc
0x416094 TlsGetValue
0x416098 TlsSetValue
0x41609c TlsFree
0x4160a0 FreeLibrary
0x4160a4 LoadLibraryExW
0x4160a8 CreateThread
0x4160ac ExitThread
0x4160b4 GetModuleHandleExW
0x4160b8 GetStdHandle
0x4160bc WriteFile
0x4160c0 GetModuleFileNameW
0x4160c4 ExitProcess
0x4160c8 GetCommandLineA
0x4160cc GetCommandLineW
0x4160d0 HeapAlloc
0x4160d4 HeapFree
0x4160d8 CompareStringW
0x4160dc LCMapStringW
0x4160e0 GetFileType
0x4160e4 GetFileSizeEx
0x4160e8 SetFilePointerEx
0x4160ec FindClose
0x4160f0 FindFirstFileExW
0x4160f4 FindNextFileW
0x4160f8 IsValidCodePage
0x4160fc GetACP
0x416100 GetOEMCP
0x416104 GetCPInfo
0x416108 MultiByteToWideChar
0x41610c WideCharToMultiByte
0x41611c SetStdHandle
0x416120 GetStringTypeW
0x416124 GetProcessHeap
0x416128 FlushFileBuffers
0x41612c GetConsoleOutputCP
0x416130 GetConsoleMode
0x416134 HeapSize
0x416138 HeapReAlloc

!This program cannot be run in DOS mode.
`.rdata
@.data
.reloc
B.AllIn
@.AllIn
@.AllIn
D$,SUV
QQSVWd
t/h0sA
URPQQh0c@
UQPXY]Y[
F4_^[]
<ItC<Lt3<Tt#<h
A<lt'<tt
u,PQRS
Wj0XPV
SPjdVQ
zSSSSj
f9:t!V
QQSVj8j@
CY<u
PPPPPPPP
PPPPPWS
PP9E u:PPVWP
Unknown exception
bad array new length
string too long
FreeConsole
VirtualProtect
bad allocation
device or resource busy
invalid argument
no such process
not enough memory
operation not permitted
resource deadlock would occur
resource unavailable try again
generic
success
address family not supported
address in use
address not available
already connected
argument list too long
argument out of domain
bad address
bad file descriptor
bad message
broken pipe
connection aborted
connection already in progress
connection refused
connection reset
cross device link
destination address required
directory not empty
executable format error
file exists
file too large
filename too long
function not supported
host unreachable
identifier removed
illegal byte sequence
inappropriate io control operation
interrupted
invalid seek
io error
is a directory
message size
network down
network reset
network unreachable
no buffer space
no child process
no link
no lock available
no message available
no message
no protocol option
no space on device
no stream resources
no such device or address
no such device
no such file or directory
not a directory
not a socket
not a stream
not connected
not supported
operation canceled
operation in progress
operation not supported
operation would block
owner dead
permission denied
protocol error
protocol not supported
read only file system
result out of range
state not recoverable
stream timeout
text file busy
timed out
too many files open in system
too many files open
too many links
too many symbolic link levels
value too large
wrong protocol type
unknown error
FlsAlloc
FlsFree
FlsGetValue
FlsSetValue
InitializeCriticalSectionEx
InitOnceExecuteOnce
CreateEventExW
CreateSemaphoreW
CreateSemaphoreExW
CreateThreadpoolTimer
SetThreadpoolTimer
WaitForThreadpoolTimerCallbacks
CloseThreadpoolTimer
CreateThreadpoolWait
SetThreadpoolWait
CloseThreadpoolWait
FlushProcessWriteBuffers
FreeLibraryWhenCallbackReturns
GetCurrentProcessorNumber
CreateSymbolicLinkW
GetCurrentPackageId
GetTickCount64
GetFileInformationByHandleEx
SetFileInformationByHandle
GetSystemTimePreciseAsFileTime
InitializeConditionVariable
WakeConditionVariable
WakeAllConditionVariable
SleepConditionVariableCS
InitializeSRWLock
AcquireSRWLockExclusive
TryAcquireSRWLockExclusive
ReleaseSRWLockExclusive
SleepConditionVariableSRW
CreateThreadpoolWork
SubmitThreadpoolWork
CloseThreadpoolWork
CompareStringEx
GetLocaleInfoEx
LCMapStringEx
bad exception
__based(
__cdecl
__pascal
__stdcall
__thiscall
__fastcall
__vectorcall
__clrcall
__eabi
__swift_1
__swift_2
__swift_3
__ptr64
__restrict
__unaligned
restrict(
delete
operator
`vftable'
`vbtable'
`vcall'
`typeof'
`local static guard'
`string'
`vbase destructor'
`vector deleting destructor'
`default constructor closure'
`scalar deleting destructor'
`vector constructor iterator'
`vector destructor iterator'
`vector vbase constructor iterator'
`virtual displacement map'
`eh vector constructor iterator'
`eh vector destructor iterator'
`eh vector vbase constructor iterator'
`copy constructor closure'
`udt returning'
`local vftable'
`local vftable constructor closure'
new[]
delete[]
`omni callsig'
`placement delete closure'
`placement delete[] closure'
`managed vector constructor iterator'
`managed vector destructor iterator'
`eh vector copy constructor iterator'
`eh vector vbase copy constructor iterator'
`dynamic initializer for '
`dynamic atexit destructor for '
`vector copy constructor iterator'
`vector vbase copy constructor iterator'
`managed vector copy constructor iterator'
`local static thread guard'
operator ""
operator co_await
operator<=>
Type Descriptor'
Base Class Descriptor at (
Base Class Array'
Class Hierarchy Descriptor'
Complete Object Locator'
`anonymous namespace'
(null)
CorExitProcess
AreFileApisANSI
LocaleNameToLCID
RoInitialize
RoUninitialize
AppPolicyGetProcessTerminationMethod
AppPolicyGetThreadInitializationType
NAN(SNAN)
nan(snan)
NAN(IND)
nan(ind)
Sunday
Monday
Tuesday
Wednesday
Thursday
Friday
Saturday
January
February
August
September
October
November
December
MM/dd/yy
dddd, MMMM dd, yyyy
HH:mm:ss
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
[aOni*{
~ $s%r
@b;zO]
v2!L.2
1#QNAN
1#SNAN
?5Wg4p
%S#[k=
"B <1=
_hypot
_nextafter
.text$di
.text$mn
.text$x
.text$yd
.idata$5
.00cfg
.CRT$XCA
.CRT$XCAA
.CRT$XCC
.CRT$XCZ
.CRT$XIA
.CRT$XIAA
.CRT$XIAC
.CRT$XIC
.CRT$XIZ
.CRT$XPA
.CRT$XPX
.CRT$XPXA
.CRT$XPZ
.CRT$XTA
.CRT$XTZ
.rdata
.rdata$r
.rdata$sxdata
.rdata$voltmd
.rdata$zzzdbg
.rtc$IAA
.rtc$IZZ
.rtc$TAA
.rtc$TZZ
.xdata$x
.idata$2
.idata$3
.idata$4
.idata$6
.data$r
.data$rs
GetPhysicalCursorPos
USER32.dll
CoCancelCall
ole32.dll
ImageList_SetDragCursorImage
FlatSB_ShowScrollBar
InitializeFlatSB
COMCTL32.dll
CloseHandle
WaitForSingleObjectEx
GetCurrentThreadId
GetExitCodeThread
QueryPerformanceCounter
EnterCriticalSection
LeaveCriticalSection
InitializeCriticalSectionEx
DeleteCriticalSection
GetSystemTimeAsFileTime
GetModuleHandleW
GetProcAddress
UnhandledExceptionFilter
SetUnhandledExceptionFilter
GetCurrentProcess
TerminateProcess
IsProcessorFeaturePresent
GetCurrentProcessId
InitializeSListHead
IsDebuggerPresent
GetStartupInfoW
KERNEL32.dll
RaiseException
RtlUnwind
GetLastError
SetLastError
EncodePointer
InitializeCriticalSectionAndSpinCount
TlsAlloc
TlsGetValue
TlsSetValue
TlsFree
FreeLibrary
LoadLibraryExW
CreateThread
ExitThread
FreeLibraryAndExitThread
GetModuleHandleExW
GetStdHandle
WriteFile
GetModuleFileNameW
ExitProcess
GetCommandLineA
GetCommandLineW
HeapAlloc
HeapFree
CompareStringW
LCMapStringW
GetFileType
GetFileSizeEx
SetFilePointerEx
FindClose
FindFirstFileExW
FindNextFileW
IsValidCodePage
GetACP
GetOEMCP
GetCPInfo
MultiByteToWideChar
WideCharToMultiByte
GetEnvironmentStringsW
FreeEnvironmentStringsW
SetEnvironmentVariableW
SetStdHandle
GetStringTypeW
GetProcessHeap
FlushFileBuffers
GetConsoleOutputCP
GetConsoleMode
HeapSize
HeapReAlloc
CreateFileW
WriteConsoleW
DecodePointer
/$Nb.
H:v3?
LG_.S9P
&mt8@F|u
\ioE'r
["SzuH
uI=(GK
pDUp1
;-B<VE
<ykkp=
V|Z6Y
X|Z6Y
hj>!B3
H8pc&*
hN;1p3
hpG293
hpNpM3
-w`.<w`.<w`.<w`.<wc.<wc.;wc.;wc.;wc-;wc-;wc-;wc-;wc-:wc-:wc-:wb-:wb,:wb,:wb,9wb,9wb,9wb,9wb,9wb,9wb+9wm+8wm+8wm+8wm+8wm+8wm+8wm+8wm*
-w`/=w`/<w`/<w`.<w`.<w`.<w`.<wc.<wc.;wc.;wc.;wc-;wc-;wc-;wc-:wc-:wc-:wb-:wb-:wb,:wb,:wb,9wb,9wb,9wb,9wb,9wb,9wb+9wm+8wm+8wm+8wm+8wm+8wm+8wm+
+w`/=w`/=w`/=w`/=w`/<w`/<w`.<w`.<w`.<w`.<wc.;wc.;wc.;wc.;wc-;wc-;wm,;wk)9wj(8wj(8wk)9wl+:wb,:wb,:wb,9wb,9wb,9wb,9wb,9wb+9wb+8wm+8wm+8wm+8wm+8wm+8wm+8wm*
2wa/=wa/=w`/=w`/=w`/=w`/=w`/=w`/<w`.<w`.<w`.<w`.<wc.<wc.;wc.;wb.;wj)9w
wk)9wc-:wb-:wb,:wb,:wb,9wb,9wb,9wb,9wb,9wb,9wb+9wm+8wm+8wm+8wm+8wm+8wy7?wF
-wa >wa >wa >wa >wa >wa/=wa/=w`/=w`/=w`/=w`/=w`/<w`/<w`.<w`.<w`.<w`.<wm-<w
8wo6UwT
9wb-;wc-:wc-:wc-:wb-:wb,:wb,:wb,9wb,9wb,9wb,9wb,9wb,9wb+9wm+8wm+8wm+8wm+8w[
-wa!?wa ?wa >wa >wa >wa >wa >wa =wa/=w`/=w`/=w`/=w`/=w`/=w`/<w`/<w`.<wm,;w
(9wm,;wc-;wc-;wc-:wc-:wc-:wb-:wb-:wb,:wb,:wb,9wb,9wb,9wb,9wb,9wb,9wb+9wm+8w[
-wf!?wf!?wf!?wa!?wa >wa >wa >wa >wa >wa >wa =wa/=w`/=w`/=wm-<wn,<wh+<wj*:w
8wj*9wi+:wm-;wc-;wc-;wc-;wc-:wc-:wc-:wb-:wb,:wb,:wb,:wb,9wb,9wb,9wb,9wb,9w[
-wf"0wf!0wf!?wf!?wf!?wa!?wa!?wa >wa >wa >wa >w` >wo-=wh+;w
(9wi+:wb.;wc-;wc-;wc-;wc-;wc-:wc-:wc-:wb-:wb,:wb,:wb,9wb,9wb,9w[
-wf"0wf"0wf"0wf!0wf!0wf!?wf!?wf!?wa!?wa ?wa >wi,=w
:wi0^ww
9wj*:wm-;wc.;wc.;wc-;wc-;wc-;wc-;wc-:wc-:wc-:wb-:wb,:wb,:w[
-wg"1wg"1wf"1wf"0wf"0wf"0wf!0wf!0wf!?wf!?wb/>w
*<wi?\w_
9wh*;wc.<wc.<wc.;wc.;wc.;wc-;wc-;wc-;wc-:wc-:wc-:wb-:w[
-wg#2wg#1wg#1wg"1wg"1wf"1wf"0wf"0wf"0wf!0wl.>w
(9wn+;w`.<w`.<w`.<wc.;wc.;wc.;wc.;wc-;wc-;wc-;wc-:w[
-wg#2wg#2wg#2wg#1wg#1wg#1wg"1wg"1wf"0wf"0wl/?w
*:wc/<w`.<w`.<w`.<w`.<wc.<wc.;wc.;wc.;wc-;wc-;w[
-wd$3wd$2wg#2wg#2wg#2wg#2wg#1wg#1wg"1wg"1wl/0w
(:wl-<w`/=w`/<w`/<w`.<w`.<w`.<w`.<wc.<wc.;wc.;w[
-wd$3wd$3wd$3wd$3wd$2wg#2wg#2wg#2wg#2wg#1wm 0w
9wn,<w`/=w`/=w`/=w`/=w`/<w`/<w`.<w`.<w`.<w`.<w[
-wd%4wd%4wd$3wd$3wd$3wd$3wd$3wg$2wg#2wg#2w`!1wk-0w
+>wk-?wo.?wm ?wc ?w` 0wc/>wl.>w
*<wl7WwU
:wn,=wa =wa/=w`/=w`/=w`/=w`/=w`/=w`/<w`/<w`.<w[
-we%4we%4wd%4wd%4wd%4wd$3wd$3wd$3wd$3wd$3wg$2wm 1wh.0wk-0wo/?wc!0wf#1wg"1wg"1wf"0wf"0wf"0wm ?w
*=wl4TwU
:wi,=wa >wa >wa >wa/=wa/=w`/=w`/=w`/=w`/=w`/<w[
-we&5we&5we%5we%4wd%4wd%4wd%4wd%3wd$3wd$3wd$3wd$3wg$2wa"2wg#2wg#2wg#2wg#1wg#1wf"1wb 0wi-?w
;wn,>wa >wa >wa >wa >wa >wa >wa/=wa/=w`/=w`/=w[
-we&5we&5we&5we&5we%5we%4we%4wd%4wd%4wd%4wd$3wd$3wd$3wd$3wd$3wd$2wg#2wa"2wm 1wh.0w
(=wl3SwE
(<wl.>wf!?wa!?wa ?wa >wa >wa >wa >wa >wa =wa/=w[
-wz'6we&6we&6we&5we&5we&5we&5we%5we%4we%4wd%4wd%4wd%4wd$3wd$3wa"2wl 1wh.1w
wj9$wj,>w` 0wf!?wf!?wf!?wa!?wa!?wa >wa >wa >wa >wa >w[
-wz'7wz'6wz'6wz'6we&6we&6we&5we&5we&5we&5we%5we%4we%4wf$4wm!2wk.1w
*?wi>ZwO
)=wn.>wf"0wf"0wf"0wf!0wf!?wf!?wf!?wa!?wa!?wa >wa >w[
-wz87wz'7wz'7wz'7wz'6wz'6wz'6we&6we&6we&5we&5we&5wg%4wo 3w
,0wi?\wA
(=wh.?wa!1wg"1wf"1wf"0wf"0wf"0wf!0wf!0wf!?wf!?wf!?wa!?w[
-w{8(wz8(wz87wz'7wz'7wz'7wz'7wz'6wz'6wz&6we&6wg%5wo!3w
)>wh.0wa"2wg#2wg#1wg#1wg"1wg"1wf"1wf"0wf"0wf"0wf!0wf!0wf!?w[
-w{8(w{8(w{8(w{8(wz87wz87wz'7wz'7wz'7wz'6wz'6wb#4w
-0wl 1wf#3wg$2wg#2wg#2wg#2wg#2wg#1wg#1wg"1wg"1wf"1wf"0wf"0wf"0w[
-w{9)w{9)w{9(w{8(w{8(w{8(w{8(wz87wz87wz'7wd&6wi 4wi>ZwW
.1wo 2wc"3wd$3wd$3wd$3wd$3wd$3wg$2wg#2wg#2wg#2wg#1wg#1wg#1wg"1wg"1wf"0w[
-wx9)w{9)w{9)w{9)w{9)w{9(w{8(w{8(w{8(wz8(wc$6w
-1wi 2wm"3wa#4wd%4wd%4wd%4wd%4wd%3wd$3wd$3wd$3wd$3wd$2wg#2wg#2wg#2wg#2wg#1wg#1wg"1w[
-wx:*wx:*wx:*wx9)w{9)w{9)w{9)w{9)w{9(w{8(wc$6w
.2wo!4wc#5wg%4we&5we&5we&5we%5we%4we%4wd%4wd%4wd%4wd$3wd$3wd$3wd$3wd$3wd$2wg#2wg#2wg#2wg#2w[
-wx:+wx:*wx:*wx:*wx:*wx9*w{9)w{9)w{9)w{9)wb$7w
Hwk 4wc#5wd&6wz'6wz'6we&6we&6we&5we&5wd&5we&5we%5we%4we%4wd%4wd%4wd%4wd$3wd$3wd$3wd$3wd$3wg$2wg#2w[
-wx;+wx;+wx:+wx:+wx:*wx:*wx:*wx:*wx9)w{9)wm$7w
-4wl#5we87wz'7wz'7wz'7wz'6wd&5wc$5wl!4wn!4wl!3wg%4we&5we&5we%5we%4we%4wd%4wd%4wd%4wd$3wd$3wd$3wd$3w[
-wy;,wy;+wy;+wx;+wx;+wx:+wx:*wx:*wx:*wx:*wc%(w
wb6Twh 5wb#6wc$6wc$5wb$5wl"5wn!4w
,1wj'!w
-2wl!4we&6we&5we&5we&5we&5we%5we%4wd%4wd%4wd%4wd%3wd$3w[
-wy<,wy<,wy;,wy;,wy;+wy;+wx;+wx;+wx:+wx:*wa&(w
,3wm6Twt
wo3Pwn!3wd&6wz&6we&6we&5we&5we&5we&5we%5we%4we%4wd%4wd%4w[
-wy<-wy<-wy<,wy<,wy;,wy;,wy;,wy;+wy;+wx;+we8*wn#(wf
Owi 4wd&7wz'6wz'6wz'6we&6we&6we&5we&5we&5we&5we%5we%4w[
-w~=-w~<-w~<-wy<-wy<-wy<,wy<,wy;,wy;,wy;,wy;+w`&)w
@wi!4wd'7wz'7wz'7wz'7wz'6wz'6wz'6we&6we&6we&5we&5we&5w[
-w~=.w~=.w~=.w~=-w~<-w~<-wy<-wy<-wy<,wy<,wy;,w{:+wm%)w
Iwo"5we'(wz8(wz87wz87wz'7wz'7wz'7wz'6wz'6wz'6we&6we&6w[
-w~>/w~=.w~=.w~=.w~=.w~=-w~=-w~<-wy<-wy<-wy<,wy<,we:+wm%*w
/6wb$7wz9(w{8(w{8(w{8(wz8(wz87wz'7wz'7wz'7wz'7wz'6wz'6w[
>/w~>.w~=.w~=.w~=.w~=.w~=-w~=-w~<-wy<-wy<-wz:+w`'*wi#)w
7wo0]wr
/6wo#6wf&(w{9)w{9)w{9)w{8(w{8(w{8(w{8(wz87wz87wz'7wz'7wz'7w[
>/w~>/w~=.w~=.w~=.w~=.w~=.w~=-w~<-w~<-wx<-wg9,w`'*wm&)wh"(w~
wm5Swj"7wi"(wo#(wm%(wa&(we8)wx:*wx9)w{9)w{9)w{9)w{9)w{9(w{8(w{8(w{8(w{8(wz87wz87w[
>/w~>/w~=.w~=.w~=.w~=.w~=.w~=-w~<-w~<-we:,wo%*w~
wb5Twm%)wd8*wz:*w{;+wx:+wx:*wx:*wx:*wx:*wx:*wx9)w{9)w{9)w{9)w{9)w{9(w{8(w{8(w{8(w[
-w|?!w|?!w
>/w~>/w~=.w~=.w~=.w~=.w~=-wx<,wm%*wd
wh;&wm&*wx;,wy;,wy;+wy;+wx;+wx;+wx:+wx:*wx:*wx:*wx:*wx:*wx9)w{9)w{9)w{9)w{9)w{9(w[
Xw|0!w|?!w|?!w
>/w~>.w~=.w~=.wy=.wa8,wj")w
(wk#)wa'+wy<,wy<,wy;,wy;,wy;,wy;+wy;+wx;+wx:+wx:+wx:*wx:*wx:*wx:*wx9*w{9)wt
Vw|0!w|0!w|0!w|?!w|?!w|? w
>/w~>/w~=.wx<-wf8,w`'+w`'+wg9+wx;-w~<-wy<-wy<-wy<,wy<,wy;,wy;,wy;,wy;+wx;+wx;+wx:+wx:+wx:*wx:*wx:*wP
Hw|0"w|0"w|0"w|0!w|0!w|0!w|?!w|?!w|? w
>/w~>/w~=.w~=.w~=.w~=.w~=.w~=-w~<-w~<-wy<-wy<-wy<,wy<,wy;,wy;,wy;+wy;+wx;+wx;+wx:+wx:*wU
Hw}1#w}1"w}1"w|0"w|0"w|0"w|0!w|0!w|0!w|?!w|?!w
>/w~>/w~=.w~=.w~=.w~=.w~=-w~=-w~<-wy<-wy<-wy<,wy<,wy<,wy;,wy;,wy;+wy;+wx;+wU
+HAK+H
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
.?AVbad_array_new_length@std@@
.?AVbad_alloc@std@@
.?AVexception@std@@
.?AVruntime_error@std@@
.?AVlogic_error@std@@
.?AVlength_error@std@@
.?AVsystem_error@std@@
.?AV_System_error@std@@
.?AVbad_exception@std@@
.?AVerror_category@std@@
.?AV_Generic_error_category@std@@
.?AVtype_info@@
2*202=2h2|2
3(3F3S3b3j3#4X4
6'6A6V6d6p6
77J7i7
<M=d=t=
>->?>G>W>`>l>~>
?#?)?.?4?:???E?K?P?V?\?a?g?m?r?x?~?
0"0(0-03090>0D0J0O0U0[0`0f0l0q0w0}0
1!1'1,12181=1B1I1N1^1s1
6)6>6E6K6]6g6
7P7j7s7~7
8"8'8-878A8Q8a8q8z8
9+919[9
:[;d;i;|;
=&=/=D=M=|=
4!4%4)4-4145494=4A4E4I4M4Q4U4Y4]4
4+4S4g4
a0`2e2
464D4K4Q4n4
5'5C5R5W5\5w5
6+656A6F6K6l6|6
9+9:9H9T9`9n9~9
:!:,:B:V:_:z=
0m1q1u1y1}1
?:?L?S?
050>0|0
2"2)2/2J2Q2`2~2
2#494S4a4m4
485F5O5
8&8X8_8}9
:.:I:^:c:m:r:}:
;#;p;};
=R=Z=d=m=~=
=H>T>Y>_>d>l>r>z>
3'3A3z3
4'484=4
<8<M<_<l<
=>=E=f=
>*>?>o>
?-?3?E?V?[?`?p?u?z?
0,0B0h0
181Q1V1[1x1
222<2L2Q2V2q2
4"4'4?4H4M4X4
8*9<9p9
E0O0r0|0
;B<T<Z<
> >q>v>{>
617>7o7}7
:?;N;\;y;
=%=7=I=[=m=
4#5[5*6^8
181X1c1q1
1-2L2^2h2
4'4N4m4)5Y5s5
e125<5F5P5
6I7S7}7
2W3]3j3u3
344F4X4
3E5K5P5W5g5u5
5)61696A6I6g6o6
<+=,><>M>U>e>v>
>1?@?L?[?n?
0%0.070b0
696O6e6m6
445Q5[5
P1\1`1l1p1t1x1|1
1024282P2T2X2\2`2d2
7$7,747<7D7L7T7\7d7l7t7|7
8$8,848<8D8L8T8\8d8l8t8|8
3$3(3,3034383<3P3X3`3h3p3x3
4 4(40484@4H4P4X4`4h4p4x4
5 5(50585@5H5P5X5`5h5p5x5
6 6(60686@6H6P6X6`6h6p6x6
3$3(3,30343
: :$:(:,:0:4:8:<:
; ;$;(;,;0;<;@;D;H;L;P;T;X;\;`;d;h;l;p;t;x;|;
;H?L?P?T?
6$6,646<6D6L6T6\6d6l6t6|6
7$7,747<7D7L7T7\7d7l7t7|7
8$8,848<8D8L8T8\8d8l8t8|8
9$9,949<9D9L9T9\9d9l9t9|9
:$:,:4:<:D:L:T:\:d:l:t:|:
;$;,;4;<;D;L;T;\;d;l;t;|;
<$<,<4<<<D<L<T<\<d<l<t<|<
7 7(70787@7H7P7X7`7h7p7x7
8 8(80888@8H8P8X8`8h8p8x8
9 9(90989@9H9P9X9`9h9p9x9
: :(:0:8:@:H:P:X:`:h:p:x:
; ;(;0;8;@;H;P;X;`;h;p;x;
< <(<0<8<@<H<P<X<`<h<p<x<
= =(=0=8=@=H=P=X=`=h=p=x=
;$;,;4;<;D;L;T;\;d;l;t;|;
> >$>4>8><>@>H>`>p>t>
? ?$?(?0?H?X?\?d?|?
0 00040D0H0L0T0l0|0
545<5D5H5L5T5h5p5
60686L6l6t6
7 7<7@7\7`7|7
8D8H8d8h8p8x8
9 9<9@9`9
: :@:`:
; ;@;`;
< <@<\<`<
:(;8;H;X;h;
1 1$1(1,1p2
303P3p3
C:\Windows\Microsoft.NET\Framework\v4.0.30319\AppLaunch.exe
kernel32.dll
Aapi-ms-win-core-fibers-l1-1-1
api-ms-win-core-synch-l1-2-0
kernel32
api-ms-
(null)
mscoree.dll
Aapi-ms-win-core-datetime-l1-1-1
api-ms-win-core-file-l1-2-2
api-ms-win-core-localization-l1-2-1
api-ms-win-core-localization-obsolete-l1-2-0
api-ms-win-core-processthreads-l1-1-2
api-ms-win-core-string-l1-1-0
api-ms-win-core-sysinfo-l1-2-1
api-ms-win-core-winrt-l1-1-0
api-ms-win-core-xstate-l2-1-0
api-ms-win-rtcore-ntuser-window-l1-1-0
api-ms-win-security-systemfunctions-l1-1-0
ext-ms-win-ntuser-dialogbox-l1-1-0
ext-ms-win-ntuser-windowstation-l1-1-0
advapi32
api-ms-win-appmodel-runtime-l1-1-2
user32
ext-ms-
Sunday
Monday
Tuesday
Wednesday
Thursday
Friday
Saturday
January
February
August
September
October
November
December
MM/dd/yy
dddd, MMMM dd, yyyy
HH:mm:ss
Aja-JP
((((( H
zh-CHS
az-AZ-Latn
uz-UZ-Latn
kok-IN
syr-SY
div-MV
quz-BO
sr-SP-Latn
az-AZ-Cyrl
uz-UZ-Cyrl
quz-EC
sr-SP-Cyrl
quz-PE
smj-NO
bs-BA-Latn
smj-SE
sr-BA-Latn
sma-NO
sr-BA-Cyrl
sma-SE
sms-FI
smn-FI
zh-CHT
az-az-cyrl
az-az-latn
bs-ba-latn
div-mv
kok-in
quz-bo
quz-ec
quz-pe
sma-no
sma-se
smj-no
smj-se
smn-fi
sms-fi
sr-ba-cyrl
sr-ba-latn
sr-sp-cyrl
sr-sp-latn
syr-sy
uz-uz-cyrl
uz-uz-latn
zh-chs
zh-cht
CONOUT$
Antivirus Signature
Bkav W32.AIDetectMalware
Lionic Trojan.Win32.Agent.Y!c
Elastic malicious (high confidence)
MicroWorld-eScan Clean
FireEye Generic.mg.b273c68306bfba8f
CAT-QuickHeal Clean
McAfee Artemis!B273C68306BF
Malwarebytes Clean
VIPRE Clean
Sangfor Trojan.Win32.Save.a
K7AntiVirus Clean
BitDefender Clean
K7GW Clean
Cybereason malicious.2f4303
BitDefenderTheta Gen:NN.ZexaF.36318.WDW@aiT5zzf
VirIT Clean
Cyren Clean
Symantec ML.Attribute.HighConfidence
tehtris Clean
ESET-NOD32 a variant of Generik.IPALZAJ
APEX Malicious
Paloalto Clean
ClamAV Clean
Kaspersky HEUR:Trojan-Spy.Win32.Stealer.gen
Alibaba Clean
NANO-Antivirus Clean
ViRobot Clean
Rising Trojan.Generic@AI.100 (RDML:OILjjDVqAGjQgWuD+JPodA)
Sophos Clean
Baidu Clean
F-Secure Clean
DrWeb Trojan.PWS.RedLineNET.7
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition BehavesLike.Win32.Infected.tz
Trapmine malicious.moderate.ml.score
CMC Clean
Emsisoft Clean
SentinelOne Static AI - Malicious PE
GData Win32.Trojan-Stealer.Cordimik.QGEVLX
Jiangmin Clean
Webroot W32.Trojan.Gen
Google Detected
Avira TR/AD.RedLineSteal.dxcuk
MAX Clean
Antiy-AVL Clean
Gridinsoft Clean
Xcitium Clean
Arcabit Clean
SUPERAntiSpyware Clean
ZoneAlarm HEUR:Trojan-Spy.Win32.Stealer.gen
Microsoft Trojan:Win32/Wacatac.B!ml
Cynet Malicious (score: 100)
AhnLab-V3 Clean
Acronis Clean
VBA32 Clean
ALYac Clean
TACHYON Clean
DeepInstinct MALICIOUS
Cylance Clean
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Tencent Clean
Yandex Clean
Ikarus Trojan.Win32.Raccoon
MaxSecure Trojan.Malware.121218.susgen
Fortinet W32/PossibleThreat
AVG Win32:PWSX-gen [Trj]
Avast Win32:PWSX-gen [Trj]
CrowdStrike win/malicious_confidence_90% (W)
No IRMA results available.