Static | ZeroBOX

PE Compile Time

2023-07-09 17:23:07

PE Imphash

57c9b357ae0cb2f414b0a5873e2f216d

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x00597c30 0x00597e00 6.14613134206
.data 0x00599000 0x00045bb0 0x00045c00 5.07605153789
.rdata 0x005df000 0x007d6280 0x007d6400 5.39092401725
.pdata 0x00db6000 0x00005e20 0x00006000 5.9112784617
.xdata 0x00dbc000 0x000065e0 0x00006600 4.52972447835
.bss 0x00dc3000 0x0006a004 0x00000000 0.0
.edata 0x00e2e000 0x00000159 0x00000200 3.80119482273
.idata 0x00e2f000 0x00001648 0x00001800 4.37561222072
.CRT 0x00e31000 0x00000068 0x00000200 0.280401167659
.tls 0x00e32000 0x00000010 0x00000200 0.0
.reloc 0x00e33000 0x00019ad4 0x00019c00 5.42450904571

Imports

Library KERNEL32.dll:
0x122f504 AreFileApisANSI
0x122f50c CloseHandle
0x122f514 CreateEventA
0x122f51c CreateFileA
0x122f524 CreateFileMappingA
0x122f52c CreateFileMappingW
0x122f534 CreateFileW
0x122f544 CreateMutexW
0x122f54c CreateThread
0x122f554 CreateWaitableTimerA
0x122f564 DeleteCriticalSection
0x122f56c DeleteFileA
0x122f574 DeleteFileW
0x122f57c DuplicateHandle
0x122f584 EnterCriticalSection
0x122f58c ExitProcess
0x122f594 FlushFileBuffers
0x122f59c FlushViewOfFile
0x122f5a4 FormatMessageA
0x122f5ac FormatMessageW
0x122f5bc FreeLibrary
0x122f5c4 GetConsoleMode
0x122f5cc GetCurrentProcess
0x122f5d4 GetCurrentProcessId
0x122f5dc GetCurrentThreadId
0x122f5e4 GetDiskFreeSpaceA
0x122f5ec GetDiskFreeSpaceW
0x122f5fc GetFileAttributesA
0x122f604 GetFileAttributesExW
0x122f60c GetFileAttributesW
0x122f614 GetFileSize
0x122f61c GetFullPathNameA
0x122f624 GetFullPathNameW
0x122f62c GetLastError
0x122f634 GetProcAddress
0x122f644 GetProcessHeap
0x122f654 GetStartupInfoA
0x122f65c GetStdHandle
0x122f664 GetSystemDirectoryA
0x122f66c GetSystemInfo
0x122f674 GetSystemTime
0x122f684 GetTempPathA
0x122f68c GetTempPathW
0x122f694 GetThreadContext
0x122f69c GetTickCount
0x122f6a4 GetVersionExA
0x122f6ac GetVersionExW
0x122f6b4 HeapAlloc
0x122f6bc HeapCompact
0x122f6c4 HeapCreate
0x122f6cc HeapDestroy
0x122f6d4 HeapFree
0x122f6dc HeapReAlloc
0x122f6e4 HeapSize
0x122f6ec HeapValidate
0x122f6fc LeaveCriticalSection
0x122f704 LoadLibraryA
0x122f70c LoadLibraryW
0x122f714 LocalFree
0x122f71c LockFile
0x122f724 LockFileEx
0x122f72c MapViewOfFile
0x122f734 MultiByteToWideChar
0x122f73c OutputDebugStringA
0x122f744 OutputDebugStringW
0x122f75c ReadFile
0x122f764 ResumeThread
0x122f76c RtlAddFunctionTable
0x122f774 RtlCaptureContext
0x122f784 RtlVirtualUnwind
0x122f78c SetConsoleCtrlHandler
0x122f794 SetEndOfFile
0x122f79c SetErrorMode
0x122f7a4 SetEvent
0x122f7ac SetFilePointer
0x122f7bc SetThreadContext
0x122f7cc SetWaitableTimer
0x122f7d4 Sleep
0x122f7dc SuspendThread
0x122f7e4 SwitchToThread
0x122f7ec SystemTimeToFileTime
0x122f7f4 TerminateProcess
0x122f7fc TlsGetValue
0x122f814 UnlockFile
0x122f81c UnlockFileEx
0x122f824 UnmapViewOfFile
0x122f82c VirtualAlloc
0x122f834 VirtualFree
0x122f83c VirtualProtect
0x122f844 VirtualQuery
0x122f854 WaitForSingleObject
0x122f85c WaitForSingleObjectEx
0x122f864 WideCharToMultiByte
0x122f86c WriteConsoleW
0x122f874 WriteFile
0x122f87c __C_specific_handler
Library msvcrt.dll:
0x122f88c __getmainargs
0x122f894 __initenv
0x122f89c __iob_func
0x122f8a4 __lconv_init
0x122f8ac __set_app_type
0x122f8b4 __setusermatherr
0x122f8bc _acmdln
0x122f8c4 _amsg_exit
0x122f8cc _beginthread
0x122f8d4 _beginthreadex
0x122f8dc _cexit
0x122f8e4 _endthreadex
0x122f8ec _errno
0x122f8f4 _fmode
0x122f8fc _initterm
0x122f904 _localtime64
0x122f90c _onexit
0x122f914 abort
0x122f91c calloc
0x122f924 exit
0x122f92c fprintf
0x122f934 free
0x122f93c fwrite
0x122f944 malloc
0x122f94c memcmp
0x122f954 memcpy
0x122f95c memmove
0x122f964 memset
0x122f96c qsort
0x122f974 realloc
0x122f97c signal
0x122f984 strcmp
0x122f98c strcspn
0x122f994 strlen
0x122f99c strncmp
0x122f9a4 strrchr
0x122f9ac vfprintf

Exports

Ordinal Address Name
1 0x122cff0 _cgo_dummy_export
2 0x8cbe80 authorizerTrampoline
3 0x8cbba0 callbackTrampoline
4 0x8cbd60 commitHookTrampoline
5 0x8cbcc0 compareTrampoline
6 0x8cbc70 doneTrampoline
7 0x8cbf00 preUpdateHookTrampoline
8 0x8cbdc0 rollbackHookTrampoline
9 0x8cbc00 stepTrampoline
10 0x8cbe10 updateHookTrampoline
!This program cannot be run in DOS mode.
``.data
.rdata
`@.pdata
0@.xdata
0@.bss
.edata
0@.idata
.reloc
AUATUWVSH
[^_]A\A]
[^_]A\A]
8cpu.u
UUUUUUUUH!
33333333H!
D$pH9P@w
t*H9HPt$
debugCal
debugCal
debugCalH9
debugCalH9
l204uQ
debugCalH9
runtime.H9
runtime H
error: H
L9h(t
7H9S u
29t$0u
D9\$Pt
7H9S u
H9t$0u
2H9t$0u
L9\$Pt
L9\$Pt
7H9S u
L$xM9H
8H9S u
H9BpwI@
H9P8tkH
\$(H9C8u
H9D$(t
D$xH9X0
tE8Z t/H
L9@0wE
\$0H9K
D$pH9H
D$0H9H
UUUUUUUUH!
UUUUUUUUH
wwwwwwwwH!
wwwwwwwwH
D$$t H
J0H9J8vvL
H9{8u?H
kernel32H
l32.dll
AddDllDiH
rectory
AddVectoH
redContiH
ContinueH
Handler
LoadLibrH
raryExA
LoadLibrH
raryExW
advapi32H
i32.dll
SystemFuH
stemFuncH
tion036
ntdll.dlH
NtWaitFoH
ForSinglH
eObject
RtlGetCuH
tlGetCurH
rentPeb
RtlGetNtH
tVersionH
Numbers
winmm.dlH
timeBegiH
nPeriod
timeEndPH
dPeriod
ws2_32.dH
_32.dll
WSAGetOvH
verlappeH
dResult
wine_getH
ine_get_H
version
powrprofH
rof.dll
PowerRegH
gisterSuH
spendResH
umeNotifH
ication
GetSysteH
mTimeAsFH
ileTime
QueryPerH
formanceH
Counter
QueryPerH
formanceH
rmanceFrH
equency
runtime.
QxM9Qpu
T$@H9P
runtime.H9
reflect.H9
D$#e+H
I9N0t_H
D$PD9D$T
H9QPt#H
rpH92w
I9N0tSH
\$xHc5K
t$pHc=
\$PH9p
memprofiH93u7
lerau.f
memprofiH
memprofiH
memprofiH
t H9APt
7H9A8u1
r09q0s-f
,$L9+w
|$0H98
R8L+R(M
L$Hr.I
H9D$@A
HcD$4f
H9D$@A
\$HH9S@
H9D$8A
runtime.H
gopau$f
runtime.H
|$PH97u*
gopau!f
runtime.H9
gopau&f
runtime.H
runtime.H
G0I9F0t9
runtime.H9
H9S@u{H
8noneuZ1
8crasuF
8singu
8systu
l$0M9,$u
l$PM9,$u
X0H;CPt^H
l$ M9,$u
l$0M9,$u
l$PM9,$u
H+t$(H
0Hc\$8H
HHc\$PeH
l$ M9,$u
P'8S't
x H9{ u6H
x(H9{(uWH
P H9S u
l$(M9,$u
l$ M9,$u
l$8M9,$u
H9{(uAH
x0H9{0u7H
H08K0u
PhH9Shu
H9L$0uQH
H9L$@uuH
L$PH9T$Hu
@2fD9C2u
@0fD9C0u
P@H9S@t
P@H9S@u}H
l$ M9,$u
H9K0uZH
H9|$@u
H9|$0u
L9D$Xu
H9|$Hu
L9L$`u
H9|$Pu
H9|$@u
H9|$0u
L9D$@u
T$8L9D$0u
H9t$8u
H98uCH
T$0H9J0
\$0H9S
\$0H9S
T$0H)B
l$ M9,$u
l$ M9,$u
T$0H9J
l$0M9,$u
l$0M9,$u
l$0M9,$
l$0M9,$u
l$0M9,$u
J(H9B t
H8H9X@
P2f9S2u
S@H9P@
\$pH9Q@
reflect.
Valuu2f
reflect.
CallSlicL9'u
p8H9x@vYH
uKH9x@
P8H9H@
l$0M9,$u
l$0M9,$u
l$8M9,$
l$(M9,$u
l$@M9,$u
l$@M9,$u
l$8M9,$u
l$ M9,$u
l$(M9,$u
l$(M9,$
l$8M9,$u
l$0M9,$u
l$@M9,$u
l$@M9,$u
l$8M9,$u
l$0M9,$u
l$(M9,$
l$0M9,$u
l$(M9,$
l$0M9,$u
l$HM9,$u
l$(M9,$u
l$@M9,$u
l$8M9,$
l$0M9,$u
l$8M9,$u
l$(M9,$
l$(M9,$
l$(M9,$
l$@M9,$u
l$@M9,$u
l$0M9,$u
l$@M9,$u
l$0M9,$u
l$8M9,$u
l$0M9,$u
l$0M9,$u
l$0M9,$u
l$0M9,$u
l$0M9,$u
l$XM9,$
l$0M9,$u
l$8M9,$u
l$0M9,$u
l$@M9,$u
l$@M9,$u
l$(M9,$u
l$(M9,$
PPH9SPu
PXH9SXu
N(H9F uI
T$0H9JH
l$`M9,$u
\$0H9S u
H3T8 L3L8(I
|$8riH)
H1T$0H
H1T$HH
H1T$PH
l$HM9,$u
l$ M9,$u
l$ M9,$u
o\$ fE
o\$0fE
o\$@fE
o\$PfE
o\$`fE
o\$pfE
l$8M9,$u
l$8M9,$u
HHH9P@u H
$D3T$4D3T$ D3T$
D3T$8D3T$$D3T$
D3T$<D3T$(D3T$
$D3T$,D3T$
D3T$0D3T$
D3T$4D3T$
D3T$8D3T$ A
D3T$<D3T$$A
T$ D3T$
$D3T$(A
T$$D3T$
D3T$,A
T$(D3T$
D3T$0A
T$,D3T$ D3T$
D3T$4A
T$0D3T$$D3T$
D3T$8A
T$4D3T$(D3T$
D3T$<A
T$8D3T$,D3T$
T$<D3T$0D3T$
$D3T$4D3T$ D3T$
D3T$8D3T$$D3T$
D3T$<D3T$(D3T$
$D3T$,D3T$
D3T$0D3T$
D3T$4D3T$
D3T$8D3T$ A
D3T$<D3T$$A
T$ D3T$
$D3T$(A
T$$D3T$
D3T$,A
T$(D3T$
D3T$0A
T$,D3T$ D3T$
D3T$4A
T$0D3T$$D3T$
D3T$8A
T$4D3T$(D3T$
D3T$<A
T$8D3T$,D3T$
T$<D3T$0D3T$
$D3T$4D3T$ D3T$
D3T$8D3T$$D3T$
D3T$<D3T$(D3T$
$D3T$,D3T$
D3T$0D3T$
D3T$4D3T$
D3T$8D3T$ A
D3T$<D3T$$A
T$ D3T$
$D3T$(A
T$$D3T$
D3T$,A
T$(D3T$
D3T$0A
T$,D3T$ D3T$
D3T$4A
T$0D3T$$D3T$
D3T$8A
T$4D3T$(D3T$
D3T$<A
T$8D3T$,D3T$
T$<D3T$0D3T$
$D3T$4D3T$ D3T$
D3T$8D3T$$D3T$
D3T$<D3T$(D3T$
$D3T$,D3T$
D3T$0D3T$
D3T$4D3T$
D3T$8D3T$ A
D3T$<D3T$$A
T$ D3T$
$D3T$(A
T$$D3T$
D3T$,A
T$(D3T$
D3T$0A
T$,D3T$ D3T$
D3T$4A
T$0D3T$$D3T$
D3T$8A
T$4D3T$(D3T$
D3T$<A
T$8D3T$,D3T$
T$<D3T$0D3T$
\$0H9SXu
I`H9K`
D$`tMD
D$`tVD
l$(M9,$u
l$(M9,$u
l$0M9,$
l$8M9,$u
l$(M9,$u
l$ M9,$
l$@M9,$u
T$DD9T$8
t$09t$,w
l$(M9,$u
l$(M9,$u
~(H9z(u&
x H9{ u
l$(M9,$u
l$(M9,$u
-070u!D
-07:00:0M9
-07:00:0L
-07:00:0
Januu!D
-07:00:0
-07:00:0
-07:00:0
Z070u"D
Z07:00:0M9
Z07:00:0L
-07:00:0
-07:00:0
-07:00:0
-07:00:0
2006u-H)
-07:00:0
time.DatH
time.LocL
time.LocH
ocation(H
time.UTCL
8WITAuP
t$Ow1M
;nullu
8Locau
tzdau;
x8H9{8
l$HM9,$u
l$`M9,$
l$0M9,$u
l$@M9,$u
l$@M9,$u
l$PM9,$
l$@M9,$u
l$0M9,$u
l$0M9,$u
l$@M9,$u
l$8M9,$u
l$(M9,$
l$8M9,$
l$(M9,$
l$(M9,$
l$0M9,$u
l$0M9,$u
l$@M9,$u
l$0M9,$u
l$(M9,$u
l$(M9,$
l$0M9,$u
l$0M9,$u
>..t4H9
J(H9B t
H 9K u
H 9K u
H(H9K(u
t$8HcX(
t$XHc^(H
?fileu*H
?pipeu*H
?tcp6u H
?udp4uxH
?udp6u H
?unixu H
unixgramL9#t.
unixpackL9#
;udp4t
;udp6uh
l$(M9,$u
l$(M9,$u
}zy u]H
8..u[H
D$HtYH
?fileuuH
\$ 9SXu
Q\9S\u
xPH9{Pu|H
l$0M9,$u
l$0M9,$u
method:L
l$@M9,$u
l$@M9,$u
l$@M9,$u
l$@M9,$u
(BADINDEH
(MISSINGH
%!(BADWIL
%!(BADPRL
BADPREC)L
%!(EXTRAL
%!(NOVERL
P(H9P@
|$$f9D$$
f9D$&r
d$ f9D$ w
f9D$"r
H9t$@|4
l*PL9jHt+L
l$@M9,$u
;nullu
<Ot/<XtN
l$0M9,$u
l$0M9,$u
l$(M9,$u
optionalH9
explicit
explicitf
optionalH
explicitH
explicit
optionalH
explicitH
generaliL9
generaliH
printabl
printablH
8numeu
8utf8u
default:L9
default:E1
8tag:A
applicat
optionalH
explicitH
generaliI
printablI
default:I
applicat
applicat
optionalH
explicitH
generaliI
printablI
default:I
applicat
omitempt
omitempt
optionalH
explicitH
optionalH
explicitH
l$0M9,$u
l$8M9,$u
l$8M9,$u
l$8M9,$
l$@M9,$u
l$8M9,$
l$@M9,$u
l$8M9,$
l$8M9,$
l$@M9,$u
l$8M9,$
l$ M9,$u
l$0M9,$u
\$(t8vYF
l$ M9,$u
l$ M9,$
|$0H9w
D$(f9P(u'
P*8S*u
P0H9S0u
l$8M9,$u
l$HM9,$u
|$HH9w@}
;falsu
~ r(H)
~"r9H)
u|<,u%H
|$0H9w uFH
B(H9O0u4H
H9r@u&
l$HM9,$
Z H9J(u
l$0M9,$u
l$ M9,$u
B0H9N8u
T$0H9J
8FALSu
8Falsu
8falsuY
<$true
<$falsf
>!=u2H
<$falst
>!=tRf
><=t+f
:!%tLf
:<=t@f
<$true
<$falsu
>!=u*H
<$true
0\ufff
8nullt
8truet
8falsu)
8indeuif
sortKeysH9
8widtug
8deepuVH
3nullH
preserveH9
H9T$ t
L9D$(t
Z(H9F t
l:T^8rv
~d$ fE
ot$PfA
l$@M9,$u
l$0M9,$u
l$0M9,$u
l$ M9,$u
l$8M9,$u
l$8M9,$u
l$8M9,$u
P8H9S8u
l$(M9,$u
l$@M9,$u
l$0M9,$u
l$0M9,$u
l$ M9,$u
l$8M9,$u
l$8M9,$u
l$8M9,$u
l$@M9,$u
l$0M9,$u
l$0M9,$u
l$ M9,$u
l$8M9,$u
l$8M9,$u
l$8M9,$u
l$@M9,$u
l$0M9,$u
l$0M9,$u
l$ M9,$u
l$8M9,$u
l$8M9,$u
l$8M9,$u
H9P }PH
H9W }cH
H9W }QH
H9W }cH
H9W }QH
H9P }]H
L$H8L$'u
L$H8L$'u
H9P }GH
L9B }ZH
L9B }[H
IV for EH
CDSA CTRH
l$ M9,$u
\$0H9S
l$8M9,$u
l$0M9,$u
l$@M9,$u
l$(M9,$u
l$(M9,$u
l$0M9,$
l$@M9,$
\$0H9S
I H9K
l$8M9,$u
l$0M9,$u
l$@M9,$u
l$8M9,$
l$0M9,$
l$@M9,$
S H+Q H
P H1s
XfffffffH
ffffffffH
l$HM9,$
l$`M9,$
T$0H9J
|$HH9w u
l$8M9,$u
L)@pL)
2-byD1
$2-byD
nd 3E3K
2-byE3K
te kA3K
>E3C4D
expaD3P A
expaD1
expaD3
expand 3H
2-byte kH
H#T$hH
H#T$pH
H#T$`H
H#T$hH
L$@H9G
L$8H9G
T$0H9J(
H9P0u$H
H9P0u$H
H9P0u$H
H9P0u"H
8leaku
T$08J
[::ffff:N
invalid J
d PrefixJ
|-H95|+
l$pM9,$u
x(H9{(uUH
l$@M9,$u
l$HM9,$u
l$8M9,$u
l$@M9,$u
l$(M9,$u
l$@M9,$u
l$0M9,$u
l$0M9,$u
l$8M9,$u
l$0M9,$u
l$0M9,$u
l$0M9,$u
l$0M9,$u
l$0M9,$u
l$0M9,$u
l$8M9,$u
T$08J
9windu
:planu%
:andru-f
8fileu#H
8bindu#H
9solau6f
;fileu,
myhostnaM9"uRfA
myhostnaI
:fileu
:dnuYA
:mdnsu
:fileu
myhostnaM
<$succu fA
<$unav
notfoundI9
tryagainI94$
?retuu
myhostna
myhostna
unixgramH9
unixpackH9
8tcp4t
8tcp6uOH
8udp4t
8udp6u
8unixu
:dialu2L
unixgram
unixpackL9
8unixtD
unixgramH9
unixpackH9
<$tcu+A
l$(M9,$u
l$(M9,$u
ip6.arpaH
>tcp4t
}zy u&H
l$0M9,$u
}zy ueH
}zy upH
8udp4f
?tcp4f
9listu8fA
<$dial
>tcp4t
>tcp6u\
>udp4t
>udp6u
:tcp4u
:tcp6uaH
:udp4u
:udp6u=H
D$ht)H
:tcp4t
:tcp6uO
:udp4t
:udp6u
\$Pt*H
l$ M9,$u
l$ M9,$u
l$ M9,$u
l$ M9,$u
l$ M9,$u
l$ M9,$u
:acceuNf
~NrsH)
<$unix
unixgramM9<$
unixpackM9<$u
unixgramL9
unixpack
unixgramL9
unixpack
\$(tdH
}zy ujH
8udp4t
}zy ujH
unixgramH9
unixpackH9
listubfA
l$@M9,$u
l$@M9,$u
l$ M9,$
l$ M9,$
l$8M9,$u
N(H9F u_
N8H9F0u:
l$(M9,$u
x 9{ u
x$9{$u
H9{(uuH
l$ M9,$u
l$ M9,$
l$ M9,$u
l$ M9,$
l$HM9,$
l$0M9,$u
l$0M9,$u
l$HM9,$u
l$HM9,$u
l$0M9,$u
l$0M9,$u
l$0M9,$u
l$0M9,$u
l$0M9,$u
l$0M9,$u
x H9{ u6H
<$tI<&tE
r8H9Z@t
rpH9Zxt
8//uOH
J(H9B t
x @8{ u6H
{0H9x0
{PH9xP
xY@8{Y
{xH9xx
l$0M9,$
l$@M9,$
QZ^&A!
CERTIFICH92u#f
8S(udH
T$0H9P
H951W:
HHH9pPuDH
WHL9GPt
X H9H(u
D$@H9D$
H9\$hu
l$8M9,$
D$@H9D$
l$`M9,$
l$ M9,$u
l$0M9,$u
T$0H9J
l$HM9,$u
S H+Q H
P H1s
fE9,$u
DOWNGRD
DOWNGRD
<LfD9x
\$hu\H
H9P }TH
H9P }SH
H9W }VH
H9W }JH
H9T$p}>H
L9@ }\H
L9H }^H
L9H }ZH
L9H }[H
L9H }[H
L9H }[H
L9H }[H
L9H }[H
L9H }^H
L9H }[H
L9H }cH
L9H }cH
L9H }^H
L9H }[H
L9H }[H
L9H }cH
L9H }cH
L9H }[H
L9H }[H
H9P }MH
H9P }MH
H9P }VH
L9H }YH
H9P }MH
H9P }VH
L9H }eH
L9B }PH
H9P }VH
L9H }eH
L9H }eH
H9P }VH
H9P }VH
L9H }eH
L9@ }XH
L9B }PH
H9P }MH
L9H }eH
H9P }MH
H9P }MH
H9T$p}>H
L9@ }\H
L9F }OH
L9F }OH
L9H }cH
L9H }cH
L9H }`H
L9H }`H
L9H }[H
L9H }\H
L9H }[H
L9H }[H
L9H }^H
L9H }[H
L9H }[H
L9H }^H
L9H }[H
H9P }VH
H9P }JH
H9P }VH
H9P }JH
L9@ }[H
H9P }VH
H9P }JH
H9P }MH
L9B }PH
H9P }MH
H9P }MH
H9T$p}>H
L9@ }XH
L9B }PH
H9T$p}>H
H9P }MH
H9P }IH
H9T$p}>H
L9@ }XH
H9P }MH
H9P }MH
H9T$p}>H
L9@ }XH
L9@ }\H
L9@ }_H
L9@ }^H
L9@ }\H
L9@ }\H
L9@ }[H
L9@ }[H
H9P }MH
L9H }eH
L9H }eH
H9T$p}>H
H9P }fH
L9@ }[H
L9@ }\H
H9P }MH
L9@ }`H
H9P }MH
H9P }MH
H9T$p}>H
L9@ }XH
H9P }MH
H9T$p}>H
H9P }MH
L$Pw)L
H9T$p}>H
L9@ }\H
H9P }MH
fE9J@r
:h2u*I
http/1.1M9}
http/1.1
http/1.1
http/1.1I
c@fE9"u
SPL9CX
s H9K(t
s8H9K@t
shH9Kpt
H9P }MH
D$*tls1f
D$.3 H
H9P }`H
L9B }QH
key expaH9
master sH9
client fH9
server fH9
inisuqf
H9P }MH
H9P }MH
H9P }MH
CERTIFICL9
CERTIFICL
CERTIFICH
CERTIFICI
PRIVATE L9
PRIVATE I
PRIVATE
PRIVATE L
CERTIFICH92
l$0M9,$u
l$ M9,$
l$`M9,$u
T$0H9J
l$ M9,$u
l$(M9,$u
l$(M9,$u
T$0H9J
P0H+P(H
P0H+P(H
W0H+W(H
P0H+P(H
p(H9p0
\$@H9H
P(H9P0u?H
H0H+H(H
W0H+W(H9W
W(H9W0~)H
l$ M9,$u
l$ M9,$u
l$ M9,$u
l$0M9,$u
l$ M9,$u
l$(M9,$u
l$ M9,$u
l$ M9,$u
l$ M9,$
l$0M9,$u
l$ M9,$u
l$ M9,$u
l$(M9,$u
H0L+H(I
X0H+X(H
l$8M9,$u
l$(M9,$u
us-asciiH9
8utf-u
text/plaH
text/plaH
text/plaH
text/plaH
text/plaH
text/plaH
form-dat
form-datH92u
form-datH
form-datH
form-datH
form-datH92u
^0H+^(H
T$P|XH
:--u*H
l$0M9,$u
l$8M9,$u
l$0M9,$u
trbH)
D$hH9N
H9N sMH
D$`I9@ sML
l$8M9,$u
l$ M9,$u
l$ M9,$u
l$ M9,$u
l$8M9,$u
L$7D8L$j
l$HM9,$u
l$HM9,$u
XD9X4v
P09P4s
H9pxu*H
L9L$X~
l$(M9,$u
l$HM9,$u
l$HM9,$u
x @8{ u6H
l$8M9,$u
l$8M9,$u
X0H+X(
Q0M+Q(f
l$ M9,$u
l$(M9,$u
l$8M9,$
l$0M9,$u
l$ M9,$u
l$ M9,$u
:httpu
:httpuCH
:httpu
:socku
localhosH9
l$ M9,$u
x @8{ u6H
x(H9{(u_
x0@8{0uUH
9httpu&
9httpu
HTTPu3
*http2.TH9
ransport
Z(H9J0t
9HEADt
8Cookf
AuthorizH9
Www-Auth
enticateH9H
8domauTf
httponlyL9
samesiteL9
8noneu:H
8striu
; DomainL
; ExpireL
; Max-AgL
; Max-AgL
ax-Age=0L
; HttpOnL
; SecureL
; SameSiH
Site=LaxH
; SameSiH
ite=NoneH
l$8M9,$u
l$8M9,$u
H)H(H)
Z(H)Z0L
8:metu
8:schu
8:stausfA
:authoriI98uFfA
d$PL9T$XuDL
l$ M9,$u
l$(M9,$u
l$ M9,$u
9readudH
:wsaru:f
\]Hu*L
l$8M9,$u
l$0M9,$u
8httpf
>HEADuzA
:httpu
100-contH9
:CONNu]f
8Traiupf
Content-H9
9closu
Trailer:L9
Trailer:E1
>HEADtmD
l$0M9,$u
trailersH92t7H
:httpu
>httpu
>httpu2
T$0H9B@
8Traiulf
Content-H9
Lengu;f
>chunu
8HEADA
l$ M9,$u
l$(M9,$u
l$(M9,$u
>CONNf
8CONNu
8POSTt!
8PATCuRA
8readA
uuUL9
L$,D9I
trailersL9
l$(M9,$u
t$p9^`
multiparH9
>CONNu5f
HTTP/1.0H9
HTTP/1.1H9
8CONNu:fA
no-cacheH9
HTTP/2.0H9
>POSTt(I
>PATCuJ
no-cacheH9
:chunu
>chunu
X0H+X(H
>HEADu
Trailer:M9
Trailer:E1
Trailer:|
l$(M9,$u
L$(H)H(
9POSTuWH
9PRuYA
HTTP/2.0M9#A
9CONNu
9HEADA
Trailer:H9
Trailer:1
keep-ali
8closu
identityH
identityE1
identity
identityA
<$HEADt:L
:HEADtHH
9readu
H9~(t;H
PUT us
http/1.0
http/1.1H92
L$HI9H@u
8OPTIu
l$(M9,$u
l$(M9,$u
l$0M9,$u
8tcp4t
>HEAD@
>chunf
>chunu
>chunu
9CONNu
9HEADtd
9DELEu
9SEARu^f
9OPTIuFf
PROPFINDH9
l$ M9,$u
;chunu
;POSTt-
identityH9
;HEADu
8Traiukf
Content-H9
Lengu6f
:CONNf
:HEADuhH
>HEADt'H
t$ht#H
Content-
H9D$@t
>httpu*
H9D$ t
9httpu
9httpu
8GEu`A
8HEADtAf
8TRACu5A
8OPTIu
H9D$pt
l$ M9,$u
l$ M9,$u
T$XH+T$hH
t$XH+t$hH
l$ M9,$u
9httpf
>httpt
>httpu
:httpu
H9Jxu=D
D$pI9PxtVD
>HEADt
B0L+B(M
8HTTPu
F0L+F(L9
r0H9r(u
H9VxuPD
l$0M9,$u
l$0M9,$u
l$8M9,$u
l$(M9,$u
l$(M9,$u
l$8M9,$u
l$(M9,$u
l$(M9,$u
x(H9{(u_
x0@8{0uUH
l$ M9,$
l$(M9,$
l$(M9,$
l$(M9,$
l$(M9,$
l$ M9,$
l$(M9,$
l$(M9,$
l$(M9,$
l$(M9,$
l$(M9,$u
l$0M9,$u
l$PM9,$
l$(M9,$u
l$0M9,$u
l$ M9,$u
l$(M9,$u
l$0M9,$u
l$ M9,$u
l$ M9,$
l$8M9,$u
l$(M9,$u
l$0M9,$u
l$ M9,$u
l$(M9,$u
l$(M9,$u
l$0M9,$u
l$(M9,$u
l$8M9,$u
l$hM9,$
l$HM9,$u
l$(M9,$u
l$0M9,$u
l$ M9,$u
l$ M9,$
l$(M9,$u
l$0M9,$u
T$(H9J
l$ M9,$u
l$(M9,$u
l$0M9,$u
l$ M9,$u
l$ M9,$
l$(M9,$u
l$0M9,$u
l$ M9,$u
l$(M9,$u
l$8M9,$u
l$0M9,$u
l$ M9,$u
l$8M9,$
l$ M9,$
l$(M9,$u
l$0M9,$u
l$ M9,$u
l$(M9,$u
l$0M9,$u
l$ M9,$u
l$ M9,$
l$(M9,$u
l$0M9,$u
l$ M9,$u
l$HM9,$u
l$HM9,$u
l$HM9,$u
l$HM9,$u
\$0H9S
l$8M9,$u
l$0M9,$u
l$(M9,$u
P(H9S(u
|$0H9w
l$ M9,$u
l$0M9,$u
l$8M9,$u
l$(M9,$u
l$(M9,$u
l$ M9,$u
l$(M9,$u
l$ M9,$u
l$ M9,$u
l$HM9,$u
\$0H9S
l$0M9,$u
l$ M9,$
l$ M9,$
l$@M9,$u
H9w u+H
r(H9w(u!H
l$0M9,$u
l$0M9,$
l$0M9,$u
l$0M9,$u
l$XM9,$u
\$0H9S
l$0M9,$u
l$(M9,$u
l$(M9,$u
O(H9G t
l$8M9,$u
l$HM9,$u
l$@M9,$u
l$(M9,$u
l$8M9,$u
l$0M9,$u
l$(M9,$u
l$HM9,$
l$0M9,$u
l$0M9,$
l$(M9,$u
T$`A82
aHM9aPuUM
P(L9H8
s(H9K0u
PXH9SXt
s`H9Kht
H9SHu7H
PPH9SPu-H
l$ M9,$
l$ M9,$
MHI9UP~
E9L$0vPM
E9L$0vSL
E9i0v3L
E9i0v5L
E9i0v3L
E9i0v3L
D$pt?H
l$ M9,$u
l$ M9,$u
H9Hh~LH
T$hH9T$p@
H9Ph~`L
tJH9X0uDH
8Jpu$H
8ascif
l$XM9,$u
l$0M9,$u
l$0M9,$u
l$XM9,$u
l$0M9,$
l$ M9,$u
l$ M9,$u
l$ M9,$u
l$(M9,$u
l$8M9,$u
l$0M9,$u
l$8M9,$u
l$8M9,$u
l$0M9,$u
l$0M9,$u
l$0M9,$u
l$0M9,$u
l$8M9,$u
l$8M9,$u
l$0M9,$u
l$(M9,$u
l$(M9,$u
l$0M9,$u
l$0M9,$u
l$xM9,$u
l$xM9,$u
l$xM9,$u
l$HM9,$u
l$8M9,$u
l$HM9,$u
l$8M9,$u
l$8M9,$u
l$0M9,$u
l$0M9,$u
l$@M9,$
8FALSu
8Falsu
8falsf
8FALSu
8Falsf
8falsu\
urn:uuidH9
l$HM9,$u
l$8M9,$u
l$(M9,$u
l$ M9,$u
l$ M9,$u
L9L$@t
l$8M9,$u
l$ M9,$u
l$0M9,$u
@8w u!H
O0H9G(t
x0H9{0
T$0H9J
l$(M9,$u
l$(M9,$u
l$0M9,$u
l$0M9,$u
l$(M9,$u
l$(M9,$u
l$@M9,$
T$0H9J
:writuW
:|1u?H
l$XM9,$u
ShH9Phu
P0L9@8u:H
8httpt@H
:httpu
>httpu
:httpt&f
:httpu
x8H9{8
Nr6'u0H
h.fu~H
H9J u`D
N(H9F u,
Z0H9J8u
l$HM9,$
l$8M9,$u
L9\$hu
L9L$(u
P8H9X
p(H+X 1
8H9p8~7H
l$@M9,$u
l$8M9,$u
l$PM9,$
l$0M9,$u
l$PM9,$
\$0H9S
D$(tYH
l$8M9,$u
l$8M9,$u
N(H9F uC
N8H9F0u
T$09J@
L$HH9HP}
zxIDAT
T$X)BpH
T$TfE9
l$RfE9
v@L9QH})L
IDATujH
IHDRuGH
PLTEuHH
T$@H9Jtt
l$ M9,$u
l$8M9,$u
l$8M9,$u
l$ M9,$u
l$8M9,$u
l$ M9,$u
l$0M9,$u
l$(M9,$u
H9T$@t
D$XriH
9HostuGM
D$PH9Q
H9t$ht
x H9{ u6H
T$0H9J(
H9x uaH
J0H9B(t
l$`M9,$u
x H9{ u6H
x(H9{(
{@H9x@
xP@8{Pu~H
{`H9x`utH
l$PM9,$u
l$PM9,$u
{(H9x(u_H
x8H9{8uUH
{@H9x@usH
xHH9{HuiH
xPH9{Pu_H
x`H9{`uUH
{0H9x0
xXH9{X
{pH9xp
l$PM9,$u
l$PM9,$u
l$XM9,$
l$hM9,$
{(H9x(u6H
x0H9{0u~H
{@H9x@utH
x0H9{0
{HH9xH
x`H9{`
xxH9{x
l$pM9,$
l$pM9,$
l$pM9,$
x(H9{(uUH
x(H9{(u6H
P H9S u
x H9{ u@H
x(H9{(u6H
x0H9{0uuH
x H9{ u6H
p H9K(uOH
H9{8uAH
x@H9{@u7H
l$PM9,$u
l$PM9,$u
x H9{ u6H
x H9{ u@
x(@8{(u6H
x H9{ u6H
{8H9x8
xHH9{HutH
{0H9x0u~H
{@H9x@utH
{8H9x8u`H
xHH9{HuVH
{(H9x(u_H
x8H9{8uUH
x H9{ u6H
l$`M9,$
l$hM9,$
l$`M9,$
l$`M9,$
P(H9S(u
l$pM9,$
l$PM9,$u
l$PM9,$u
l$PM9,$u
x(H9{(u6H
{8H9x8utH
l$`M9,$
l$XM9,$
l$XM9,$
x8H9{8
l$`M9,$
x(H9{(u_
x0@8{0uUH
H9x uaH
x0H9{0uWH
l$`M9,$
x H9{ u6H
x @8{ u6H
H9{ uJH
x(H9{(u@H
x0H9{0u6H
{0H9x0
{PH9xP
x(H9{(u6H
x H9{ u6H
x H9{ u6H
x H9{ u@H
x(H9{(u6H
{8H9x8
{XH9xX
l$xM9,$
l$xM9,$
l$PM9,$u
l$PM9,$u
l$pM9,$
l$`M9,$
l$XM9,$
l$`M9,$
l$xM9,$
x @8{ u
x H9{ u6H
x H9{ u6H
x H9{ u6H
x H9{ u6H
x H9{ u6H
x H9{ u6H
x H9{ u6H
x H9{ u6H
l$PM9,$u
l$XM9,$
l$XM9,$
l$XM9,$
l$hM9,$
{8H9x8utH
l$`M9,$
l$pM9,$
x(H9{(u6H
l$PM9,$u
l$`M9,$
l$`M9,$
x(H9{(uUH
l$`M9,$
l$`M9,$
l$`M9,$
l$PM9,$u
{8H9x8
xHH9{HutH
l$PM9,$u
l$PM9,$u
x H9{ u6H
l$0M9,$u
l$`M9,$
x H9{ u|H
l$hM9,$
l$pM9,$
l$`M9,$
l$`M9,$
l$hM9,$
l$hM9,$
l$pM9,$
l$`M9,$
l$`M9,$
x(@8{(u
l$PM9,$u
l$`M9,$
l$`M9,$
l$pM9,$
l$`M9,$
H9x uaH
x0H9{0uWH
l$xM9,$
l$xM9,$
x(H9{(ukH
x0H9{0uaH
x8H9{8uWH
l$`M9,$
l$XM9,$
l$PM9,$u
l$PM9,$u
l$PM9,$u
l$PM9,$u
l$PM9,$u
l$hM9,$
l$PM9,$
l$hM9,$
x H9{ u6H
x H9{ u6H
l$PM9,$
l$hM9,$
l$hM9,$
l$PM9,$u
l$PM9,$u
x @8{ u6H
l$PM9,$u
l$PM9,$u
x H9{ u6H
H9x uaH
x0H9{0uWH
l$PM9,$u
l$hM9,$
x H9{ u6H
l$PM9,$u
{8H9x8utH
l$PM9,$u
l$PM9,$u
l$xM9,$
x(H9{(u6H
x H9{ uKH
x(H9{(uAH
x0H9{0u7H
l$hM9,$
l$PM9,$u
l$`M9,$
l$xM9,$
l$PM9,$u
l$PM9,$u
l$`M9,$
x @8{ u@
x!@8{!u6H
l$PM9,$
l$hM9,$
{ H9x
{0H9x0
{HH9xHutH
l$xM9,$
l$`M9,$
{(H9x(u7H
l$PM9,$u
x @8{ u@
x!@8{!u6H
x(H9{(u7H
l$pM9,$
l$PM9,$u
l$hM9,$
l$PM9,$u
l$XM9,$
l$PM9,$u
l$PM9,$u
l$PM9,$u
l$PM9,$u
l$PM9,$u
l$hM9,$
l$hM9,$
l$`M9,$
l$hM9,$
l$PM9,$
l$XM9,$
l$`M9,$
l$`M9,$
l$`M9,$
l$`M9,$
x(H9{(u_H
x0H9{0uUH
l$`M9,$
l$`M9,$
l$`M9,$
{8H9x8utH
x(H9{(uUH
{ H9x ukH
x0H9{0uaH
x8H9{8uWH
l$hM9,$
l$PM9,$u
x(H9{(uUH
l$pM9,$
l$pM9,$
l$xM9,$
l$xM9,$
l$PM9,$u
l$PM9,$u
l$`M9,$
l$PM9,$u
l$PM9,$u
l$PM9,$u
l$xM9,$
l$XM9,$
l$`M9,$
l$XM9,$
l$`M9,$
l$xM9,$
{8H9x8utH
x(H9{(uUH
{8H9x8u~H
x@H9{@utH
l$PM9,$u
l$PM9,$u
{8H9x8utH
x8H9{8
x(H9{(uUH
{8H9x8utH
x H9{ u
x(H9{(u
x H9{
x@H9{@
x(H9{(
xHH9{HuDH
H9{Pu6H
l$`M9,$
P8H9S8
PPH9SPuvH
PXH9SXulH
ShH9PhubH
l$PM9,$u
l$PM9,$u
l$PM9,$u
l$PM9,$u
x(H9{(u7H
l$xM9,$
l$`M9,$
l$xM9,$
l$PM9,$u
l$PM9,$u
l$PM9,$u
l$hM9,$
l$PM9,$u
l$PM9,$u
l$PM9,$u
l$PM9,$u
l$XM9,$
x(H9{(uk
l$XM9,$
l$XM9,$
l$XM9,$
l$PM9,$u
l$`M9,$
l$`M9,$
l$PM9,$u
{8H9x8utH
x(H9{(uUH
{8H9x8
xpH9{p
{8H9x8
{`H9x`
x H9{ uK
l$XM9,$
l$XM9,$
l$XM9,$
l$PM9,$u
l$PM9,$u
l$PM9,$u
{8H9x8
xP@8{P
{`H9x`
{8H9x8utH
{8H9x8utH
x H9{ u
{8H9x8utH
l$PM9,$u
l$hM9,$
{ H9x
{@H9x@utH
l$XM9,$
l$xM9,$
l$xM9,$
l$xM9,$
l$xM9,$
H9x uuH
x(H9{(ukH
x0H9{0uaH
H9{@uUH
x H9{ u6H
{ H9x
x8@8{8
xPH9{PutH
x @8{ u
l$`M9,$
x(H9{(uUH
x0H9{0
xHH9{H
xXH9{X
{xH9xx
x8H9{8
{PH9xPutH
x @8{ u@
x!@8{!u6H
l$hM9,$
l$hM9,$
{8H9x8
xP@8{P
{`H9x`
l$hM9,$
l$PM9,$u
l$hM9,$
x(H9{(u_H
x0H9{0uUH
x H9{ u6H
{8H9x8utH
x(H9{(uUH
l$xM9,$
x8H9{8
xPH9{P
x H9{ u6H
H9{ u6H
x H9{ u
x(H9{(u9H
l$PM9,$u
l$PM9,$u
P 8S u5H
l$PM9,$u
SxH9Px
l$pM9,$
H9P uaH
S0H9P0uWH
P H9S u
l$hM9,$
l$`M9,$
l$hM9,$
l$hM9,$
l$hM9,$
l$PM9,$u
l$hM9,$
l$hM9,$
l$xM9,$
x @8{ u6H
x(H9{(uUH
l$PM9,$u
l$xM9,$
l$PM9,$u
l$PM9,$u
l$PM9,$u
l$PM9,$u
l$PM9,$u
l$PM9,$u
x @8{ u6H
l$pM9,$
l$PM9,$u
x(H9{(u6H
{8H9x8utH
l$PM9,$u
x H9{ u6H
{8H9x8
{XH9xX
x H9{ u6H
{8H9x8utH
H9x uaH
x0H9{0uWH
l$pM9,$
l$XM9,$
l$XM9,$
l$XM9,$
l$XM9,$
l$XM9,$
H8H9K8
l$XM9,$
{ H9x
{0H9x0
H9x@utH
l$xM9,$
x0@8{0uaH
x@H9{@uWH
x H9{ u6H
l$xM9,$
l$XM9,$
l$hM9,$
x0@8{0u~H
{@H9x@utH
x(H9{(uk
x8H9{8
x(H9{(uUH
l$PM9,$
{8H9x8utH
SXH9PX
l$hM9,$
l$hM9,$
l$`M9,$
l$`M9,$
l$PM9,$u
l$PM9,$
x(H9{(uk
x0@8{0ua
x1@8{1uWH
PPH9SPu
PXH9SXu
l$pM9,$
l$pM9,$
l$pM9,$
l$PM9,$u
l$hM9,$
l$`M9,$
l$hM9,$
l$`M9,$
l$PM9,$u
l$PM9,$u
l$PM9,$u
l$PM9,$u
l$`M9,$
l$XM9,$
l$`M9,$
l$hM9,$
H9K uJH
x0H9{0u@H
x8H9{8u6H
x(H9{(u6H
x H9{ u6H
l$PM9,$u
l$PM9,$u
l$XM9,$
l$PM9,$
l$PM9,$u
l$`M9,$
l$XM9,$
l$PM9,$u
l$XM9,$
x H9{ u6H
x H9{ u6H
x @8{ u@H
x(H9{(u6H
l$PM9,$u
l$PM9,$u
l$PM9,$u
Antivirus Signature
Bkav W32.Common.72BF98DF
Lionic Trojan.Win32.Goback.4!c
Elastic malicious (high confidence)
MicroWorld-eScan Trojan.GenericKD.68273559
ClamAV Clean
FireEye Trojan.GenericKD.68273559
CAT-QuickHeal Clean
McAfee GenericRXAA-AA!E71EF2F3F2CD
Malwarebytes Generic.Malware/Suspicious
VIPRE Trojan.GenericKD.68273559
Sangfor Infostealer.Win64.Goback.Vojw
K7AntiVirus Trojan ( 0058f06c1 )
BitDefender Trojan.GenericKD.68273559
K7GW Trojan ( 0058f06c1 )
Cybereason Clean
Baidu Clean
VirIT Trojan.Win64.Agent.TQ
Cyren W64/ABRisk.NMOI-4608
Symantec ML.Attribute.HighConfidence
tehtris Clean
ESET-NOD32 a variant of WinGo/Agent.FP
APEX Malicious
Paloalto Clean
Cynet Malicious (score: 99)
Kaspersky Trojan-PSW.Win64.Goback.pl
Alibaba TrojanPSW:Win64/Goback.df1f81d2
NANO-Antivirus Clean
ViRobot Clean
Rising Trojan.Agent!1.E61F (CLASSIC)
Emsisoft Trojan.GenericKD.68273559 (B)
F-Secure Trojan.TR/Redcap.jxbbq
DrWeb Trojan.Siggen20.47496
Zillya Trojan.Goback.Win64.194
TrendMicro Clean
McAfee-GW-Edition Artemis!Trojan
Trapmine Clean
CMC Clean
Sophos Mal/Generic-S
Ikarus Trojan-PSW.Agent
GData Trojan.GenericKD.68273559
Jiangmin Clean
Webroot Clean
Avira TR/Redcap.jxbbq
MAX malware (ai score=83)
Antiy-AVL Trojan/Win32.Sabsik
Gridinsoft Ransom.Win64.Sabsik.cl
Xcitium Malware@#3lpisc371bkaa
Arcabit Trojan.Generic.D411C597
SUPERAntiSpyware Clean
ZoneAlarm Trojan-PSW.Win64.Goback.pl
Microsoft Trojan:HTML/Phish.AXI!MTB
Google Detected
AhnLab-V3 Trojan/Win.Generic.C5384646
Acronis suspicious
BitDefenderTheta Clean
ALYac Trojan.GenericKD.68273559
TACHYON Clean
DeepInstinct MALICIOUS
VBA32 TrojanPSW.Win64.Goback
Cylance unsafe
Panda Trj/Chgt.AD
Zoner Clean
TrendMicro-HouseCall TROJ_GEN.R002H0CG923
Tencent Win64.Trojan-QQPass.QQRob.Fdhl
Yandex Clean
SentinelOne Clean
MaxSecure Trojan.Malware.211648250.susgen
Fortinet W32/Agent.FP!tr
AVG Win64:Evo-gen [Trj]
Avast Win64:Evo-gen [Trj]
CrowdStrike win/malicious_confidence_100% (W)
No IRMA results available.