Static | ZeroBOX

PE Compile Time

2023-07-28 00:52:45

PE Imphash

3a0110c54bb5043d58c014fce2c1ce05

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x0000daa5 0x0000dc00 6.85701207855
.rdata 0x0000f000 0x00002b2c 0x00002c00 5.55337657337
.data 0x00012000 0x00001bfc 0x00001000 3.7822406813
.rsrc 0x00014000 0x0002b860 0x0002ba00 5.83752473679

Resources

Name Offset Size Language Sub-language File type
RT_MANIFEST 0x00014100 0x0000015a LANG_ENGLISH SUBLANG_ENGLISH_US ASCII text, with CRLF line terminators
RT_RCDATA 0x00014660 0x0002b200 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_VERSION 0x00014260 0x000003fc LANG_ENGLISH SUBLANG_ENGLISH_US data

Imports

Library KERNEL32.dll:
0x40f000 GetStringTypeW
0x40f004 Sleep
0x40f008 WaitForSingleObject
0x40f00c CreateThread
0x40f010 lstrlenW
0x40f014 VirtualProtect
0x40f018 GetProcAddress
0x40f01c LoadLibraryA
0x40f020 VirtualAlloc
0x40f024 LockResource
0x40f028 LoadResource
0x40f02c SizeofResource
0x40f030 FindResourceW
0x40f034 GetModuleHandleW
0x40f038 GetLastError
0x40f03c CreateMutexA
0x40f040 GetModuleHandleA
0x40f044 GetDriveTypeA
0x40f048 GetConsoleWindow
0x40f04c RtlUnwind
0x40f050 GetCommandLineA
0x40f054 TlsGetValue
0x40f058 TlsAlloc
0x40f05c TlsSetValue
0x40f060 TlsFree
0x40f068 SetLastError
0x40f06c GetCurrentThreadId
0x40f078 ExitProcess
0x40f07c WriteFile
0x40f080 GetStdHandle
0x40f084 GetModuleFileNameA
0x40f094 WideCharToMultiByte
0x40f09c SetHandleCount
0x40f0a0 GetFileType
0x40f0a4 GetStartupInfoA
0x40f0ac HeapCreate
0x40f0b0 VirtualFree
0x40f0b4 HeapFree
0x40f0bc GetTickCount
0x40f0c0 GetCurrentProcessId
0x40f0c8 GetCPInfo
0x40f0cc GetACP
0x40f0d0 GetOEMCP
0x40f0d4 IsValidCodePage
0x40f0d8 TerminateProcess
0x40f0dc GetCurrentProcess
0x40f0e4 IsDebuggerPresent
0x40f0e8 RaiseException
0x40f0f8 HeapAlloc
0x40f0fc HeapReAlloc
0x40f100 LCMapStringA
0x40f104 MultiByteToWideChar
0x40f108 LCMapStringW
0x40f10c GetStringTypeA
0x40f110 GetLocaleInfoA
0x40f114 HeapSize
Library USER32.dll:
0x40f11c ShowWindow

!This program cannot be run in DOS mode.
`.rdata
@.data
1aOvvvP
HY0HRb
HN6~[~ZHK
~[~VHG
~b~W~V
~V~_~f
H[FH_V
BHC%HF:HS
~f~ZHG
XN~S~a~^
FHSJHA
~SH^OHO}HZc~[~f2B
~Y~^~[
~R~Q~b
F~W~a~S
1axfvv6t
~W~VH^0
~[~[HS|
~b~^~Z
~Z~V~Y
~^HO<H[
~VHGgHQ
~b~c~R
vvvHNy~Y~W~Q
HS~Y1
H[tHVN
HS=~[H_
HJv~g~S~ZHJ
~Q~g~YH[
GHY>HG
vvv`:wvv
~R~f~VH_
~f~VHFg
HW)HQ3
HI1~ZHQ
~W~fHI
B~_HJ
~RHOmHB
~ZHW{~cH[
A~[~[~f
~f~VHY
BHOlHR
A~c~cHY
~W~R~Y~Z~_
C~R~bHVx
~V~R~Y~_~[
~R~W~V
~Z~a~^~Z
C~V~[H^3~S
~W~S~Y~_
~R~fHV
~^~fHG
~c~c~b~_~bHK_~Q
HBu~_~W~g~cHNH~gH^
~V~VHR
JEEEEEEEEEEEEEU
QQSVWd
_VVVVV
^WWWWW
HtHu4j
s[S;7|G;w
tR99u2
uBh-z@
>=Yt1j
j@j ^V
0A@@Ju
to=p+A
0SSSSS
0SSSSS
_VVVVV
;t$,v-
UQPXY]Y[
0SSSSS
0SSSSS
URPQQhp
t"SS9]
PPPPPPPP
PPPPPPPP
<+t(<-t$:
+t HHt
uL9=`:A
t+WWVPV
bad allocation
kernel32.dll
JRVQOWJRXOQJWROBHTOJOEWJHO
VirtualProtect
^vBW]P
_RJa\6
^:JN\Q
GAIsProcessorFeaturePresent
KERNEL32
bad allocation
bad exception
EncodePointer
DecodePointer
FlsFree
FlsSetValue
FlsGetValue
FlsAlloc
CorExitProcess
runtime error
TLOSS error
SING error
DOMAIN error
An application has made an attempt to load the C runtime library incorrectly.
Please contact the application's support team for more information.
- Attempt to use MSIL code from this assembly during native code initialization
This indicates a bug in your application. It is most likely the result of calling an MSIL-compiled (/clr) function from a native constructor or from DllMain.
- not enough space for locale information
- Attempt to initialize the CRT more than once.
This indicates a bug in your application.
- CRT not initialized
- unable to initialize heap
- not enough space for lowio initialization
- not enough space for stdio initialization
- pure virtual function call
- not enough space for _onexit/atexit table
- unable to open console device
- unexpected heap error
- unexpected multithread lock error
- not enough space for thread data
This application has requested the Runtime to terminate it in an unusual way.
Please contact the application's support team for more information.
- not enough space for environment
- not enough space for arguments
- floating point support not loaded
Microsoft Visual C++ Runtime Library
<program name unknown>
Runtime Error!
Program:
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
Unknown exception
GetProcessWindowStation
GetUserObjectInformationA
GetLastActivePopup
GetActiveWindow
MessageBoxA
USER32.DLL
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
HH:mm:ss
dddd, MMMM dd, yyyy
MM/dd/yy
December
November
October
September
August
February
January
Saturday
Friday
Thursday
Wednesday
Tuesday
Monday
Sunday
1#QNAN
1#SNAN
SunMonTueWedThuFriSat
JanFebMarAprMayJunJulAugSepOctNovDec
Complete Object Locator'
Class Hierarchy Descriptor'
Base Class Array'
Base Class Descriptor at (
Type Descriptor'
`local static thread guard'
`managed vector copy constructor iterator'
`vector vbase copy constructor iterator'
`vector copy constructor iterator'
`dynamic atexit destructor for '
`dynamic initializer for '
`eh vector vbase copy constructor iterator'
`eh vector copy constructor iterator'
`managed vector destructor iterator'
`managed vector constructor iterator'
`placement delete[] closure'
`placement delete closure'
`omni callsig'
delete[]
new[]
`local vftable constructor closure'
`local vftable'
`udt returning'
`copy constructor closure'
`eh vector vbase constructor iterator'
`eh vector destructor iterator'
`eh vector constructor iterator'
`virtual displacement map'
`vector vbase constructor iterator'
`vector destructor iterator'
`vector constructor iterator'
`scalar deleting destructor'
`default constructor closure'
`vector deleting destructor'
`vbase destructor'
`string'
`local static guard'
`typeof'
`vcall'
`vbtable'
`vftable'
operator
delete
__unaligned
__restrict
__ptr64
__clrcall
__fastcall
__thiscall
__stdcall
__pascal
__cdecl
__based(
GetStringTypeW
WaitForSingleObject
CreateThread
lstrlenW
VirtualProtect
GetProcAddress
LoadLibraryA
VirtualAlloc
LockResource
LoadResource
SizeofResource
FindResourceW
GetModuleHandleW
GetLastError
CreateMutexA
GetModuleHandleA
GetDriveTypeA
GetConsoleWindow
KERNEL32.dll
ShowWindow
USER32.dll
RtlUnwind
GetCommandLineA
TlsGetValue
TlsAlloc
TlsSetValue
TlsFree
InterlockedIncrement
SetLastError
GetCurrentThreadId
InterlockedDecrement
SetUnhandledExceptionFilter
ExitProcess
WriteFile
GetStdHandle
GetModuleFileNameA
FreeEnvironmentStringsA
GetEnvironmentStrings
FreeEnvironmentStringsW
WideCharToMultiByte
GetEnvironmentStringsW
SetHandleCount
GetFileType
GetStartupInfoA
DeleteCriticalSection
HeapCreate
VirtualFree
HeapFree
QueryPerformanceCounter
GetTickCount
GetCurrentProcessId
GetSystemTimeAsFileTime
GetCPInfo
GetACP
GetOEMCP
IsValidCodePage
TerminateProcess
GetCurrentProcess
UnhandledExceptionFilter
IsDebuggerPresent
RaiseException
LeaveCriticalSection
EnterCriticalSection
InitializeCriticalSectionAndSpinCount
HeapAlloc
HeapReAlloc
LCMapStringA
MultiByteToWideChar
LCMapStringW
GetStringTypeA
GetLocaleInfoA
HeapSize
.?AVbad_exception@std@@
.?AVexception@std@@
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
.?AVtype_info@@
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v3">
<security>
<requestedPrivileges>
<requestedExecutionLevel level="asInvoker" uiAccess="false"></requestedExecutionLevel>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
][^f[l`
jl__^Y
!&>lr"
xB,Kpq
9g-/5t
87KKu&
xmu}GLd
V7Ke_cF?)
>5_c?#
zY[d_fZ
nnzYlYdj
_dYyT]hzdSh
nnzYlYdj
_dYyT]hzdSh
nnzYlYdj
_dYyT]hzdSh
nnzYlYdj
_dYyT]hzdSh
dZ]alT
hYvd_i^VZwh[Zd^_
hYzY[d_fQ
hglXaY
ii[hZZ
dZY~g}[^f[l`Z
Wldalkah
l_fXlfhZ
hglXaY
ii[hZZ
Zjl__higdahZ
Xaalkahm
_X`h[lkahm
~[ih[hi
_X`h[lkahm
laazdYhm
^aahjYd^_m
_X`h[lY^[m
el__ha
ljY^[Tm
nnzYlYdj
_dYyT]hzdSh
nnzYlYdj
_dYyT]hzdSh
nnzYlYdj
_dYyT]hzdSh
nnzYlYdj
_dYyT]hzdSh
^_Wh[Y
[^`xYg
dj[^Z^gY
nnzYlYdj
_dYyT]hzdSh
nnzYlYdj
_dYyT]hzdSh
nnzYlYdj
_dYyT]hzdSh
nnzYlYdj
_dYyT]hzdSh
nnzYlYdj
_dYyT]hzdSh
Y^bh_Z
hYy^bh_Z
hTwlaXh}ld[m
ZableZ
lZi^dli
bliZ^cd
ZigblZ
iWZcd^e\
nnzYlYdj
_dYyT]hzdSh
nnzYlYdj
_dYyT]hzdSh
nnzYlYdj
_dYyT]hzdSh
lZialZi
nnzYlYdj
_dYyT]hzdSh
nnzYlYdj
_dYyT]hzdSh
nnzYlYdj
_dYyT]hzdSh
nnzYlYdj
_dYyT]hzdSh
nnzYlYdj
_dYyT]hzdSh
nnzYlYdj
_dYyT]hzdSh
nnzYlYdj
_dYyT]hzdSh
nnzYlYdj
_dYyT]hzdSh
nnzYlYdj
_dYyT]hzdSh
nnzYlYdj
_dYyT]hzdSh
nnzYlYdj
_dYyT]hzdSh
nnzYlYdj
_dYyT]hzdSh
nnzYlYdj
_dYyT]hzdSh
nnzYlYdj
_dYyT]hzdSh
fhYnxy
lZibliX
zTZYh`
hYz^jbhYZ
dZj^__hjY
hahflYh
dk[l[T
zTZYh`
^V_a^lizY[d_f
^`]ahYhi
l_iah[
zTZYh`
[lVd_f
[lVd_f
zTZYh`
hYV^[b
_g^[`lYd^_zTZYh`
a^klazYlYdZYdjZ
hYv[dYh[}[hZh[Why^bh_Z
hYlilYl
zTZYh`
hYzT_j{h\XhZY
^_YhUY
zTZYh`
lYly^bh_Z
hYv[dYh[
dj[^Z^gYz\azh[Wh[zh[Wh[z`d
Wh_Yzd_b
hglXaYx_hU]hjYhi
Wh_YyT]h
zTZYh`
^aahjYd^_zYl`]
zTZYh`
zTZYh`
^`]^_h_Y
^_Wh[Yh[
zTZYh`
zTZYh`
hYx_Zlgh
hYe^iZ
zTZYh`
^_gdfX[lYd^_vd_i^VZ
XYeh_YdjlYd^_
ah`h_Y~
zTZYh`
hYy[dzYlYh}
zTZYh`yhUY{hfXal[
U][hZZd^_Z
^iXah{hg
zTZYh`zhjX[dYT
[T]Y^f[l]eT
zTZYh`
dlf_^ZYdjZ
^X_Yh[
[hlYd^_
hjazhjX[dYTxZh[z
zTZYh`
lYl~ikj~ikj
^__hjYd^_
ljY^[Tz
zTZYh`
^_Yd_Xh
hahflYhy
hYv[dYh[
^iXahv[dYh[{hXZhi
zTZYh`zhjX[dYT
[T]Y^f[l]eT~di
_X`h[lY^[y
zTZYh`
^aahjYd^_Z
h_h[dj
h_h[djwl[w
zTZYh`
hYx_Zlgh
hYe^iZ
zTZYh`
hYx_Zlgh
hYe^iZ
zTZYh`
hYe^i{hgh[h_jh
U][hZZd^_t
WlaXhnn
zTZYh`
alXZhl
zTZYh`zhjX[dYT
XYeh_YdjlYd^_
UYh_ihi}[^YhjYd^_
^_gdfX[lYd^_zh[Wdjh
ah`h_Y
^aahjYd^_l
^V_a^li
}[^YhjYhi
_j[T]Yhi
`Zj^[adk
hj[T]Y
zTZYh`
hYV^[b
_g^[`lYd^_
il]Yh[Z
ii[hZZhZ
lYl{hlih[
ljY^[TxYdaZk
zTZYh`
^aahjYd^_Z
h_h[dj
l_lfhiye[hli
annd_dYdlaye[hli
X]ilYh
fhYnzhZZd^_
TYhZ}h[{hli
X[[h_Yye[hli
hj^ihi
TYhZy^zY[d_f
^_Wh[Yhi
ljbd_f
ljbd_f
ljbd_f
ljbd_f
ljbd_f
ljbd_f
ljbd_f
ljbd_f
ljbd_f
ljbd_f
ljbd_f
ljbd_f
ljbd_f
ljbd_f
ljbd_f
ljbd_f
d[[][h
ljbd_f
ljbd_f
}lZZhi}lYeZ
ljbd_f
{hZXaY
ljbd_f
^Znj[T]Y
ljbd_f
ljbd_f
h_j[T]YhinbhT
ljbd_f
{hliy^
`hYe^i
zTZYh`
hYvhkz^jbhYZvhkz^jbhY}[^Y^j^a
^`]^_h_Y
Xggh[i
zTZYh`
dlf_^ZYdjZ
Wh_YyT]h
daYh[i
liblZi
bbieglbilZi
lZildi
lZilZ^i
zTZYh`
^aahjYd^_Z
h_h[djz^[YhizhYy[hhzXkzhYj
dZ]alT
hYV^[b
_Yh[gljh
{h]aljh
Xaa~[vedYhz]ljh
idZYl_jh
_ZYl_jh
Z^X[jh
ZhYnz`^^Yed_f
jeld_d_f
h[YdgdjlYhwladilYd^_
h[YdgdjlYhwladilYd^_
_Yh[]^alYd^_
ZhYny[l_Zgh[
ZhYn}dUha~ggZhY
zhjX[dYT
zhahjYzd_fah
fhYnx_dj^ih
_idl_x_dj^ih
hZZlfh
hZZlfh
X[[h_Y
l_fXlfh
ii{l_fh
^_YhUYylkah
_X`h[lkah
dZ]^Zlkah
wdZdkah
{X_Yd`h
{X_Yd`hyT]h
hYyT]h
{hjYl_fah
^V_a^li
][^gdah
hY{^l`d_f
_fadZe
fhYnxZh[
fhYnxZh[
hY}[^jhZZhZ
dZ]alT
gdah_l`h
hYzdf_lYX[h
af^[dYe`h
lYhyd`h
[hlYd^_yd`h
^`kd_h
ljed_h
lYl}[^YhjYd^_zj^]h
ilYl}[^YhjYd^_zj^]h
~]h[lYd^_
^_YhUYzj^]h
a^kyT]h
el_fhyT]h
wlaXhyT]h
hZZlfh
[hih_YdlayT]h
[hih_YdlayT]h
zhjX[dYT}[^Y^j^ayT]h
hYyT]h
ah`h_YyT]h
fhYn}[^]h[YTyT]h
kaW_SjV\h
dahzel[h
^`]l[h
zTZYh`
fhYnd[[][h
X[[h_Yx
XaYX[h
XaYX[h
_Wl[dl_Y
XaYX[h
X[[h_Y
XaYX[h
vhk{hZ]^_Zh
hY{hZ]^_Zh
zTZYh`
dZ]^Zlkah
dZ]^Zh
{hWh[Zh
h[YdgdjlYh
fhYnzh[Wdjh
h[YdgdjlYh
jh[YdgdjlYh
XaYdjlZY
hahflYh
hkXffh[
[^VZlkahzYlYh
]^ZzYlYh
nnZYlYh
laazdYh
T_l`dj
YY[dkXYh
^`]dah[
h_h[lYhi
YY[dkXYh
x_Wh[dgdlkah
YY[dkXYh
hkXfflkah
YY[dkXYh
hkXffh[
[^VZlkah
YY[dkXYh
^`wdZdkah
YY[dkXYh
ZZh`kaTydYah
YY[dkXYh
ZZh`kaTy[lih`l[b
YY[dkXYh
yl[fhY
[l`hV^[b
YY[dkXYh
hkXffh[
YY[dkXYh
UYh_Zd^_
YY[dkXYh
ZZh`kaT
dahwh[Zd^_
YY[dkXYh
ZZh`kaT
^_gdfX[lYd^_
YY[dkXYh
ZZh`kaT
hZj[d]Yd^_
YY[dkXYh
YY[dkXYh
YY[dkXYh
^`]dalYd^_{halUlYd^_Z
YY[dkXYh
^_Y[ljY
YY[dkXYh
zh[Wdjh
^_Y[ljY
YY[dkXYh
~]h[lYd^_
^_Y[ljY
YY[dkXYh
ZZh`kaT}[^iXjY
YY[dkXYh
ZZh`kaT
^]T[dfeY
YY[dkXYh
^_gXZhi
YY[dkXYh
YY[dkXYh
ZZh`kaT
^`]l_T
YY[dkXYh
{X_Yd`h
^`]lYdkdadYT
YY[dkXYh
ZhYnxZhzehaa
UhjXYh
fhYnwlaXh
lYeh[wlaXh
lZwlaXh
hYwlaXh
zhYwlaXh
^_YhUYwlaXh
ZZh`kaT{hZ^aWh
{h`^Wh
yldlelZ
fhYnzdSh
jkzdSh
n]lfhzdSh
lU{hjhdWhi
hZZlfhzdSh
el_fhzdSh
lYlyT]hzdSh
XYeylfzdSh
Xggh[}^^azdSh
d_zdSh
^XYzdSh
_hVzdSh
Vd_i^VzdSh
hYwd[YXla
dZ]alTzdSh
idjYd^_l[TzdSh
zh[dladSh
hZh[dladSh
{hZdSh
zdSh~g
_ihU~g
zTZYh`zhjX[dYT
[T]Y^f[l]eTzlgh
[T]Y}[^W
l_iahg
lXYeylf
fhYn}_f
zTZYh`
ye[hlid_f
d_id_f
_j^id_f
_j^id_f
X[[h_Y
_j^id_f
zTZYh`
[lVd_f
`lfd_f
zTZYh`
{X_Yd`h
wh[Zd^_d_f
y^zY[d_f
hYzY[d_f
hUzY[d_f
zXkZY[d_f
zTZYh`
[lVd_f
^_Wh[Yy^x
Zjl__h[
{lV}[^]h[YT
l]{^Vf
zhl[je
^`]XYh
zTZYh`
dlf_^ZYdjZ
lYl{hjhdWhi
ik}lYe
][^gdah}lYe
^aih[}lYe
[^^Y}lYe
fhYnvdiYe
fhYnwd[YXlazj[hh_vdiYe
lUzY[d_f
^_Yh_Y
fhYn{^V
zYl[YZvdYe
zTZYh`
lYlz\a
adh_YyiZ}l[Zh[v[dYhyhUY
zTZYh`
YY]vhk{hZ]^_Zhd
zTZYh`
lYl~ah
il]Yh[d
zTZYh`{X_Yd`h
_Yh[^]zh[WdjhZvd_i^VZ{X_Yd`h
^``l_i
il]Yh[
ha]h[Zj
dZ]alT
zTZYh`zhjX[dYT
[T]Y^f[l]eTu
h[YdgdjlYhZu
hTxZlfh
zTZYh`
lYl~ah
k{^Vx]ilYd_f
zTZYh`
^aahjYd^_Z
h_h[djz^[Yhi
laakljb
{h`^Yh
h[YdgdjlYhwladilYd^_
laakljb
fhYnzh[Wh[
h[YdgdjlYhwladilYd^_
laakljb
ZhYnzh[Wh[
h[YdgdjlYhwladilYd^_
laakljb
jlaakljb
^^]kljb
zTZYh`
^ffd_fb
}[hZh_YlYd^_
[l`hV^[b
X]ilYhylZb
l[Zela
h[YdgdjlYh{hjd]dh_Y
[hih_Ydla
zTZYh`
^aahjYd^_Z
^_jX[[h_Y
a^jbd_f
^aahjYd^_
^_ZX`d_f
_X`h[lkahia
zTZYh`
zh[Wdjh
el__ha
^_YhUY
el__ha
bh[_ha
zTZYh`
fhYnzhjX[dYT}[^Y^j^a
ZhYnzhjX[dYT}[^Y^j^a
^_ZYl_Ya
dahzY[hl`
hY{hZ]^_ZhzY[hl`
d_zY[hl`
^XYzY[hl`
h`^[TzY[hl`
ZY[hl`
dY~]h[lYd_fzTZYh`
af^[dYe`
af^[dYe`
{l_i^`
hZZyel_
yd`hz]l_
[^`zj[hh_
fhYn}[d`l[Tzj[hh_
X[[h_Y
dahwh[Zd^_
_g^wh[Zd^_
hYvd_i^VZwh[Zd^_
XYeh_YdjlYd^_
zh[Wdjh
h[YdgdjlYh
XYeh_YdjlYd^_
^jlYd^_
zTZYh`
hYV^[b
_g^[`lYd^_
x_djlZY
ii[hZZ
_g^[`lYd^_
lYhVlT
ii[hZZ
_g^[`lYd^_
`]ah`h_YlYd^_
zTZYh`
a^kladSlYd^_
zTZYh`
{X_Yd`h
zh[dladSlYd^_
zTZYh`
zj[d]Y
zh[dladSlYd^_
Zwladi
ljYd^_
zTZYh`
{hgahjYd^_
l_fXlfh
^aahjYd^_
^aahjYd^_
x_djlZY
ii[hZZ
_g^[`lYd^_
^aahjYd^_
lYhVlT
ii[hZZ
_g^[`lYd^_
^aahjYd^_
^aahjYd^_
l_lfh`h_Y~kchjY
^aahjYd^_
{h\XhZY
^__hjYd^_
j^__hjYd^_
zhl[je~]Yd^_
Zhl[je~]Yd^_
[T]Y^f[l]edj
Ujh]Yd^_
^YzX]]^[Yhi
Ujh]Yd^_
_Wladi~]h[lYd^_
Ujh]Yd^_
zTZYh`
zh[Wdjh
hZj[d]Yd^_
zY[d_f
^`]l[dZ^_
hZZlfh
zTZYh`
^_gdfX[lYd^_zhYYd_fZ
l_iah[_
zTZYh`
^_gdfX[lYd^_vhk}[^UTzj[d]Y
ah`h_Y_
^`]l[hy^
zTZYh`
yd`hs^_h
XaYX[h
]}liid_f
dahzTZYh`
{hfd^_
dahwh[Zd^_
hYwh[Zd^_
[fX`h_Y
}[^jhZZzYl[Y
d[hjY^[T
}[^]h[YT
zTZYh`
lYl{halYd^_
^aahjYd^_
lYlylkah{halYd^_
^aahjYd^_^
zTZYh`
^Y^zYlYh`h_Y^
zTZYh`
hYV^[b
_g^[`lYd^_
je^{h]aT^
hZZlfhzhjX[dYT~Wh[yj]
zTZYh`
eX_b}l[Zh[{hlizYlYh]
dj[^Z^gY
zTZYh`
^ih{hfd^_
d[hjYdWh\
zTZYh`
zTZYh`
hYvhk{h\XhZY
hYzh[dla
hZZlfh
ii[hZZ
u`a{hlih[
zY[hl`{hlih[
u`ayhUY{hlih[
[T]Y^zh[Wdjh}[^Wdih[
af^[dYe`}[^Wdih[
^[`lY}[^Wdih[
][^Wdih[
zY[d_f
Xdaih[
z]hjdla
Zh_ih[
dj[^Z^gY
{X_Yd`h
laazdYh
hj^ih[
zh[Wdjh}^d_Y
l_lfh[
l_lfh`h_Y~kchjYzhl[jeh[
_W^bh[
{hZ^aWh
l_iah[
y^x]]h[
X[[h_YxZh[
zTZYh`
^`]^_h_Y
[^VZlkahzYlYh[
hahflYh
X_jYd^_}^d_Yh[
lil]Yh[
^_Wh[Yh[
lWlzj[d]Yzh[dladSh[
hY}Y[zdf[
_X`h[lY^[
l_lfh`h_Y~kchjY
_X`h[lY^[
zTZYh`
^aahjYd^_Z
h_h[dj
_X`h[lkah
_X`h[lY^[
zTZYh`
^aahjYd^_Z
_X`h[lkah
_X`h[lY^[
jYdWlY^[
j^__hjY^[
yldlelZ
ZhYn{hlih[|X^YlZ
djYd^_l[T{hlih[|X^YlZ
[l]edjZ
zTZYh`
dlf_^ZYdjZ
[l]edj
hYV^[b
_Yh[gljhZ
zTZYh`
{X_Yd`h
_Yh[^]zh[WdjhZ
zTZYh`
{X_Yd`h
^`]dah[zh[WdjhZ
hkXffd_f
Wldalkah
l_fXlfhZ
_ZYlaahi
l_fXlfhZ
al_fXlfhZ
lYjehZ
_X`h[lYh
d[hjY^[dhZ
d[hjY^[dhZ
n`lZYh[ylkah
_Y[dhZ
nYlkah
_Y[dhZ
}}[^]h[YdhZ
_Yh[gljh}[^]h[YdhZ
hY}[^]h[YdhZ
][^]h[YdhZ
_Wd[^_`h_Ywl[dlkahZ
[h`^Yh
][^gdahZ
el[iVl[hZ
Z^gYVl[hZ
hU]d[hZ
dZY~g}[^jhZZhZ
][^jhZZhZ
fhYnx_djlZY
ii[hZZhZ
lYhVlT
ii[hZZhZ
zTZYh`
zhjX[dYT
[T]Y^f[l]eT
h[YdgdjlYhZ
{hahlZhx]ilYhZ
zTZYh`zhjX[dYT
[T]Y^f[l]eTu
h[YdgdjlYhZu
h[YdgdjlYh
^aahjYd^_
d_i}[^j
hahflYhZ
_X`}^ZzYlYhZ
zY[d]|X^YhZ
d_XYhZ
^_Wh[Yy^
^fdjla
[fX`h_Y
j^_gdfZ
ZhYYd_fZ
{hZ^aWh
fhYn}lZZhi}lYeZ
ZhYn}lZZhi}lYeZ
d_i}lYeZ
k[^VZh[}lYeZ
fhYnydjbZ
zTZYh`
ye[hlid_f
[h`^YhylZbZ
[hih_YdlaZ
[hih_YdlaZ
zTZYh`
zh[Wdjh
el__haZ
dZY~g}[^f[l`Z
zTZYh`
vd_i^VZ
hYy^bh_Z
i^`ld_Z
^_Yld_Z
zTZYh`
UYh_Zd^_Z
zTZYh`
{hfXal[
U][hZZd^_Z
zTZYh`
^aahjYd^_Z
zY[d_fz]adY~]Yd^_Z
Zhl[je}lYYh[_Z
]lYYh[_Z
fhYn~XYf^d_f
hZZlfh
hlih[Z
ihgh_ih[Z
zTZYh`
lYlwdhV
dZYh_h[Z
Zjl__h[Z
{X_Yd`h
ha]h[Z
d_ZYlaahi
[^VZh[Z
[^VZh[Z
k[^VZh[Z
zTZYh`}l[l`hYh[Z
a^fd_}ld[Z
zZa}^adjT
ZZa}^adjT
hY}[^jhZZ^[Z
ZXjjhZZ
X[[h_Y}[^jhZZ
hglXaY
ii[hZZ
ii[hZZ
ii[hZZ
hY}[^j
ii[hZZ
_i]^d_Y
ii[hZZ
lii[hZZ
hYv[dYh[}^[Ylkah}ik
^_ZYl_YZZ
zTZYh`
z^jbhYZ
_X`y^Yla
_X`}^Z
_X`}[hW
zX]]^[YZ
fhYn~]h[lYd^_lazYlYXZ
zTZYh`
vd_i^VZ
l[[lTZ
UY[ljY
l_lfh`h_Y
lZh~kchjY
e~kchjY
l_lfh`h_Y~kchjY
hT~kchjY
hT~kchjY
^kchjY
zhahjY
x_][^YhjY
zTZYh`
yl[fhY
zTZYh`
l_iahY
zTZYh`
^aahjYd^_Z
_X`h[lY^[
hY~ggZhY
^ggZhY
zTZYh`
lYl}[^Wdih[
^__hjYd^_}^^azYlYhY
fhYnwd[YXlazj[hh_
ZhYn{hjX[Zd^_
jkzlaY
hYwlaXh~[
hglXaY
fhYn{hZXaY
]jk{hZXaY
ZT_j{hZXaY
hZZlfh
^U{hZXaY
nn[hZXaY
zTZYh`
l_lfh`h_Y
ah`h_Y
^jX`h_Y
ah`h_Y
_j[h`h_Y
z\azYlYh`h_Y
_Wd[^_`h_Y
^jX`h_Y
hYV^[b
_Yh[gljh
^`]^_h_Y
zTZYh`
^aahjYd^_Z
h_h[dj
_X`h[lY^[
X[[h_Y
zTZYh`
^aahjYd^_Z
_X`h[lY^[
X[[h_Y
zTZYh`
^aahjYd^_Z
h_h[dj
_X`h[lY^[
X[[h_Y
zTZYh`
^aahjYd^_Z
_X`h[lY^[
X[[h_Y
nnjX[[h_Y
^_Yh_Y
l`hylkah
fhYn^Znj[T]Y
ZhYn^Znj[T]Y
hj[T]Y
y[d`zYl[Y
^_Wh[Y
vhk{h\XhZY
ZhYnyd`h^XY
ZhYnzh_iyd`h^XY
a^Zhyd`h^XY
ZhYn{hjhdWhyd`h^XY
ZhYn~]h_yd`h^XY
Yd`h^XY
jk~XY]XY
]k~XY]XY
zTZYh`
jd]eh[yhUY
__h[yhUY
jed]h[yhUY
^_YhUY
^_YhUY
lZYh[~g
^_YhUY
~]h[lYd^_
^_YhUY
zTZYh`
^`]^_h_Y
^`]^_h_Y
el_fd_f
l_iah[W
^vd_i^V
blZidekg]giX\V
i_adkv{hZ^X[jhZ{hZ^X[jh
d[hjY^[T
zTZYh`
hYV^[b
_g^[`lYd^_}[hgdU~[dfd_U
hZZlfh
idZ]alT
_dYdladSh
~]h_zXk
je[^`h
ZY[d_f
{hfdZY[T
fhYnh_j[T]YhinbhT
ZhYnh_j[T]YhinbhT
zTZYh`
^`]^_h_Y
lYl~kchjY
YY[dkXYhT
zTZYh`
zhjX[dYT
[T]Y^f[l]eT
laad_f
ZZh`kaT
UhjXYd_f
ZZh`kaT
ii[hZZ
zhahjY
h_Y[^]T
dk[l[T
^aahjY
ljY^[T
ljY^[T
el__ha
ljY^[T
d[hjY^[T
d[hjY^[T
d[hjY^[T
ZhYnv^[bd_f
d[hjY^[T
fhYnzTZYh`
d[hjY^[T
][^gdahZ
d[hjY^[T
{hfd^_Z
^X_Y[T
{hfdZY[T
zTZYh`
^`][hZZd^_
hj^ih[
sd]~]Yd^_la
\XladYT
_h\XladYT
zTZYh`
zh[Wdjh
zhjX[dYT
zTZYh`
zhjX[dYT
zTZYh`
zhjX[dYT
ZhYnzhjX[dYT
hYyj]zhjX[dYT
ih_YdYT
_i]^d_Y
ih_YdYT
hY}[^]h[YT
]ZS}[^]h[YT
^_gXZh[
MIzTZYh`
zhjX[dYT
}h[`dZZd^_Z
zhjX[dYT}h[`dZZd^_
YY[dkXYh
`Zj^[adk
wh[Zd^_
XaYX[h
_hXY[la
}Xkadj
hTy^bh_
zbd]wh[dgdjlYd^_
Ujh]Yd^_ye[^VZ
^[]^[lYd^_
^]T[dfeY
[l`hV^[b
wh[Zd^_
[l`hV^[b
dZ]alT
[l`hV^[b
l`hZ]ljh
l`hZ]ljh
l`hZ]ljh
l`hZ]ljh
l`hZ]ljh
l`hZ]ljh
l`hZ]ljh
l`hZ]ljh
l`hZ]ljh
l`hZ]ljh
l`hZ]ljh
l`hZ]ljh
l`hZ]ljh
l`hZ]ljh
_YdYTM1
_YdYTyxVzTZYh`
zh[Wdjh
zhZZd^_
zTZYh`
zh[Wdjh
wh[Zd^_
XaYX[h
_hXY[la
}Xkadj
hTy^bh_
zhZZd^_
l`hZ]ljh
l`hZ]ljh
l`hZ]ljh
^jlazYlYh
^Znj[T]Y
h_j[T]YhinbhT
`Zj^[hh
Wh[Zd^_
h_j^id_f
ZYl_ila^_h
lZZh`kaT
Zjeh`lZ
`dj[^Z^gY
`l_dghZYwh[Zd^_
lZZh`kaT
ih_YdYT
Wh[Zd^_
]]adjlYd^_
Zjeh`lZ
`dj[^Z^gY
ZhjX[dYT
[h\XhZYhi}[dWdahfhZ
Zjeh`lZ
`dj[^Z^gY
[h\XhZYhi
UhjXYd^_
_W^bh[
[h\XhZYhi}[dWdahfhZ
ZhjX[dYT
lZZh`kaT
Washington1
Redmond1
Microsoft Corporation1(0&
Microsoft Code Signing PCA 20110
220512204559Z
230511204559Z0t1
Washington1
Redmond1
Microsoft Corporation1
Microsoft Corporation0
cAv9Fc3
Microsoft Corporation1
230012+4705280
Chttp://www.microsoft.com/pkiops/crl/MicCodSigPCA2011_2011-07-08.crl0a
Ehttp://www.microsoft.com/pkiops/certs/MicCodSigPCA2011_2011-07-08.crt0
Ifs${z
5ZgjZv0
Washington1
Redmond1
Microsoft Corporation1200
)Microsoft Root Certificate Authority 20110
110708205909Z
260708210909Z0~1
Washington1
Redmond1
Microsoft Corporation1(0&
Microsoft Code Signing PCA 20110
Ihttp://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl0^
Bhttp://www.microsoft.com/pki/certs/MicRooCerAut2011_2011_03_22.crt0
3http://www.microsoft.com/pkiops/docs/primarycps.htm0@
*?*kXIc
QEX82q'
WqVNHE
Washington1
Redmond1
Microsoft Corporation1(0&
Microsoft Code Signing PCA 2011
https://www.microsoft.com 0
20220829221005.357Z0
Washington1
Redmond1
Microsoft Corporation1)0'
Microsoft Operations Puerto Rico1&0$
Thales TSS ESN:4D2F-E3DD-BEEF1%0#
Microsoft Time-Stamp Service
Washington1
Redmond1
Microsoft Corporation1&0$
Microsoft Time-Stamp PCA 20100
220302185142Z
230511185142Z0
Washington1
Redmond1
Microsoft Corporation1)0'
Microsoft Operations Puerto Rico1&0$
Thales TSS ESN:4D2F-E3DD-BEEF1%0#
Microsoft Time-Stamp Service0
g 44B'
Nhttp://www.microsoft.com/pkiops/crl/Microsoft%20Time-Stamp%20PCA%202010(1).crl0l
Phttp://www.microsoft.com/pkiops/certs/Microsoft%20Time-Stamp%20PCA%202010(1).crt0
Washington1
Redmond1
Microsoft Corporation1200
)Microsoft Root Certificate Authority 20100
210930182225Z
300930183225Z0|1
Washington1
Redmond1
Microsoft Corporation1&0$
Microsoft Time-Stamp PCA 20100
3http://www.microsoft.com/pkiops/Docs/Repository.htm0
Ehttp://crl.microsoft.com/pki/crl/products/MicRooCerAut_2010-06-23.crl0Z
>http://www.microsoft.com/pki/certs/MicRooCerAut_2010-06-23.crt0
as.,k{n?,
Washington1
Redmond1
Microsoft Corporation1)0'
Microsoft Operations Puerto Rico1&0$
Thales TSS ESN:4D2F-E3DD-BEEF1%0#
Microsoft Time-Stamp Service
Washington1
Redmond1
Microsoft Corporation1&0$
Microsoft Time-Stamp PCA 20100
20220829141734Z
20220830141734Z0t0:
Washington1
Redmond1
Microsoft Corporation1&0$
Microsoft Time-Stamp PCA 2010
6b&}6n#
Washington1
Redmond1
Microsoft Corporation1&0$
Microsoft Time-Stamp PCA 2010
KERNEL32.DLL
mscoree.dll
((((( H
h(((( H
H
RT_MANIFEST
VS_VERSION_INFO
StringFileInfo
040904E4
Comments
Automotive unsatisfying
CompanyName
Insurmountable damply
FileDescription
Coupe magniloquent suet
FileVersion
3.221.163.7
InternalName
Discriminate
LegalCopyright
Copyright
Caterwauls putting outgrowths visualise
LegalTrademarks
Dozes collared jezebel suspiciously
OriginalFilename
ProductName
Speculated undesirable
ProductVersion
3.221.163.7
VarFileInfo
Translation
Legal_policy_statement
<Windows Installation Assistan
Antivirus Signature
Bkav W32.AIDetectMalware
Lionic Trojan.Win32.Stealer.12!c
Elastic malicious (high confidence)
ClamAV Clean
CMC Clean
CAT-QuickHeal Clean
McAfee Artemis!3CEEA9CA97AB
Cylance unsafe
Zillya Clean
Sangfor Infostealer.Win32.Kryptik.Vloc
CrowdStrike win/malicious_confidence_100% (W)
BitDefender Gen:Variant.Zusy.478907
K7GW Clean
K7AntiVirus Clean
Baidu Clean
VirIT Clean
Cyren W32/Kryptik.KGL.gen!Eldorado
Symantec ML.Attribute.HighConfidence
tehtris Clean
ESET-NOD32 a variant of Win32/GenKryptik.GGPO
APEX Malicious
Paloalto Clean
Cynet Malicious (score: 100)
Kaspersky UDS:DangerousObject.Multi.Generic
Alibaba Trojan:Win32/GenKryptik.d494da15
NANO-Antivirus Clean
SUPERAntiSpyware Clean
MicroWorld-eScan Gen:Variant.Zusy.478907
Rising Trojan.Kryptik!8.8 (CLOUD)
Sophos Mal/Generic-S
F-Secure Clean
DrWeb Clean
VIPRE Gen:Variant.Zusy.478907
TrendMicro Clean
McAfee-GW-Edition Artemis!Trojan
Trapmine malicious.high.ml.score
FireEye Generic.mg.3ceea9ca97ab640b
Emsisoft Gen:Variant.Zusy.478907 (B)
SentinelOne Static AI - Malicious PE
Jiangmin Clean
Webroot W32.Trojan.Gen
Avira Clean
MAX malware (ai score=81)
Antiy-AVL Clean
Microsoft Trojan:Win32/Wacatac.B!ml
Gridinsoft Malware.Win32.RedLine.bot
Xcitium Clean
Arcabit Trojan.Zusy.D74EBB
ViRobot Clean
ZoneAlarm UDS:DangerousObject.Multi.Generic
GData Win32.Trojan-Stealer.Cordimik.17KACU
Google Detected
AhnLab-V3 Trojan/Win.PWSX-gen.R593899
Acronis Clean
BitDefenderTheta Gen:NN.ZexaF.36318.pq2@a85bfafi
ALYac Gen:Variant.Mikey.148922
TACHYON Clean
DeepInstinct MALICIOUS
VBA32 Clean
Malwarebytes Malware.AI.3654500096
Panda Trj/Genetic.gen
Zoner Clean
TrendMicro-HouseCall Clean
Tencent Clean
Yandex Clean
Ikarus Trojan.Agent
MaxSecure Clean
Fortinet W32/GenKryptik.GGPO!tr
AVG Win32:PWSX-gen [Trj]
Cybereason malicious.ab2270
Avast Win32:PWSX-gen [Trj]
No IRMA results available.