Static | ZeroBOX

PE Compile Time

2023-07-21 23:16:53

PE Imphash

9610b1b4706329fadcb93ef9d2576318

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x000f9298 0x000f9400 6.90468788332
.data 0x000fb000 0x00000140 0x00000200 1.69725423498
.rdata 0x000fc000 0x000027d0 0x00002800 5.92925236713
.pdata 0x000ff000 0x00001020 0x00001200 5.45559821836
.xdata 0x00101000 0x000018d4 0x00001a00 4.5842638894
.bss 0x00103000 0x00013440 0x00000000 0.0
.idata 0x00117000 0x000009bc 0x00000a00 4.22593896539
.CRT 0x00118000 0x00000068 0x00000200 0.239765636396
.tls 0x00119000 0x00000010 0x00000200 0.0
.rsrc 0x0011a000 0x00000228 0x00000400 3.41036872704

Resources

Name Offset Size Language Sub-language File type
RT_MANIFEST 0x0011a058 0x000001ca LANG_ENGLISH SUBLANG_ENGLISH_US XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators

Imports

Library KERNEL32.dll:
0x517288 GetCurrentProcess
0x517290 GetCurrentProcessId
0x517298 GetCurrentThreadId
0x5172a0 GetLastError
0x5172a8 GetProcAddress
0x5172b0 GetStartupInfoA
0x5172c0 GetTickCount
0x5172d8 LoadLibraryA
0x5172e8 RtlAddFunctionTable
0x5172f0 RtlCaptureContext
0x517300 RtlVirtualUnwind
0x517310 Sleep
0x517318 TerminateProcess
0x517320 TlsGetValue
0x517330 VirtualAlloc
0x517338 VirtualFree
0x517340 VirtualProtect
0x517348 VirtualQuery
Library msvcrt.dll:
0x517360 __getmainargs
0x517368 __initenv
0x517370 __iob_func
0x517378 __lconv_init
0x517380 __set_app_type
0x517388 __setusermatherr
0x517390 _acmdln
0x517398 _amsg_exit
0x5173a0 _cexit
0x5173a8 _fileno
0x5173b0 _fmode
0x5173b8 _get_osfhandle
0x5173c0 _initterm
0x5173c8 _onexit
0x5173d0 _setjmp
0x5173d8 _setmode
0x5173e0 _wfopen
0x5173e8 abort
0x5173f0 calloc
0x5173f8 exit
0x517400 fflush
0x517408 fprintf
0x517410 fputc
0x517418 fputs
0x517420 free
0x517428 fwrite
0x517430 malloc
0x517438 memchr
0x517440 memcpy
0x517448 memset
0x517450 printf
0x517458 setvbuf
0x517460 signal
0x517468 strlen
0x517470 strncmp
0x517478 vfprintf
0x517480 longjmp
Library USER32.dll:
0x517490 MessageBoxA

!This program cannot be run in DOS mode.
P`.data
.rdata
`@.pdata
0@.xdata
0@.bss
.idata
AUATUWVSH
[^_]A\A]
[^_]A\A]
AWAVAUATVWUSH
H+D$hH
[]_^A\A]A^A_
AWAVAUATVWUSH
D$(H;D$P
[]_^A\A]A^A_
AWAVAUATVWUSH
D$0H;D$P
[]_^A\A]A^A_
AWAVAUATVWUSH
h[]_^A\A]A^A_
AWAVAUATVWUSH
H[]_^A\A]A^A_
AVVWUSH
0[]_^A^
UAWAVAUATVWSH
[_^A\A]A^A_]
AWAVAUATVWUSH
[]_^A\A]A^A_
AWAVAUATVWUSH
H[]_^A\A]A^A_
AWAVAUATVWUSH
x[]_^A\A]A^A_
AWAVAUATVWUSH
H+D$PH
[]_^A\A]A^A_
AWAVAUATVWUSH
^tM= >8`
0tg=0.IA
X[]_^A\A]A^A_
AWAVAUATVWUSH
D$PH;D$x
HcD$XH
l$<HcD$<H
HcD$,H
D$PH;D$p
HcD$,H
HcD$,H
[]_^A\A]A^A_
AWAVAUATVWUSH
X[]_^A\A]A^A_
AWAVAUATVWUSH
x[]_^A\A]A^A_
AWAVAUATVWUSH
8[]_^A\A]A^A_
AWAVAUATVWUSH
x[]_^A\A]A^A_
AWAVAUATVWUSH
[]_^A\A]A^A_
AWAVAUATVWUSH
X[]_^A\A]A^A_
AWAVAUATVWUSH
H[]_^A\A]A^A_
3GoPt$
AWAVAUATVWUSH
=L^a u
AWAVAUATVWUSH
H[]_^A\A]A^A_
AWAVAUATVWUSH
D$h=3d
[]_^A\A]A^A_
AWAVAUATVWUSH
[]_^A\A]A^A_
AWAVAUATVWUSH
@[]_^A\A]A^A_
AWAVAUATVWUSH
X[]_^A\A]A^A_
AWAVAUATVWUSH
L$HH+D$HH
[]_^A\A]A^A_
AWAVAUATVWUSH
%~m=|(
X[]_^A\A]A^A_
AWAVATVWUSH
th=t^5
@[]_^A\A^A_
AWAVAUATVWUSH
rl&~0=
=p>S!t
[]_^A\A]A^A_
AWAVAUATVWUSH
[]_^A\A]A^A_
AWAVVWUSH
\u0"us
8[]_^A^A_
AWAVAUATVWUSH
h[]_^A\A]A^A_
UAWAVAUATVWSH
eX[_^A\A]A^A_]
AWAVAUATVWUSH
6~j=eQ
6~g=eQ
6~j=eQ
6~g=eQ
[]_^A\A]A^A_
AWAVAUATVWUSH
$2Du-H
X[]_^A\A]A^A_
AWAVAUATVWUSH
X[]_^A\A]A^A_
AWAVAUATVWUSH
@[]_^A\A]A^A_
AWAVAUATVWUSH
/L9D$0
/L;D$0
[]_^A\A]A^A_
AWAVAUATVWUSH
H+L$pH
H+L$pH
H+|$XH
@(H;D$0
H(H+L$0H
[]_^A\A]A^A_
AWAVAUATVWUSH
[]_^A\A]A^A_
AWAVAUATVWUSH
H[]_^A\A]A^A_
AWAVAUATVWUSH
8[]_^A\A]A^A_
AVVWSH
8[_^A^
AWAVAUATVWUSH
X[]_^A\A]A^A_
AWAVAUATVWUSH
[]_^A\A]A^A_
AWAVAUATVWUSH
H[]_^A\A]A^A_
AWAVAUATVWUSH
=p>S!t
=p>S!t
=p>S!t
[]_^A\A]A^A_
AWAVAUATVWUSH
L$HH9H
/L9D$H
/L9D$H
[]_^A\A]A^A_
AWAVAUATVWUSH
X[]_^A\A]A^A_
AWAVAUATVWUSH
H+D$(H
[]_^A\A]A^A_
AVVWSH
8[_^A^
AWAVVWUSH
([]_^A^A_
AWAVAUATVWUSH
H[]_^A\A]A^A_
AWAVATVWUSH
=sYtO=
D$8H;D$H
p[]_^A\A^A_
AWAVAUATVWUSH
|$8HkD$
D$8HkD$
X[]_^A\A]A^A_
AWAVAUATVWUSH
[]_^A\A]A^A_
AWAVAUATVWUSH
[]_^A\A]A^A_
AWAVAUATVWUSH
H[]_^A\A]A^A_
AWAVAUATVWUSH
[]_^A\A]A^A_
AWAVAUATVWUSH
D$8H;D$@
x[]_^A\A]A^A_
AWAVAUATVWUSH
~P=e>/H
[]_^A\A]A^A_
AWAVAUATVWUSH
[]_^A\A]A^A_
AWAVAUATVWUSH
X[]_^A\A]A^A_
AWAVAUATVWUSH
x[]_^A\A]A^A_
AWAVAUATVWUSH
[]_^A\A]A^A_
AWAVAUATVWUSH
|$HHkD$0
p[]_^A\A]A^A_
AWAVAUATVWUSH
h[]_^A\A]A^A_
AWAVAUATVWUSH
h[]_^A\A]A^A_
AWAVAUATVWUSH
H[]_^A\A]A^A_
AWAVAUATVWUSH
([]_^A\A]A^A_
UAWAVAUATVWSH
[_^A\A]A^A_]
AWAVAUATVWUSH
0[]_^A\A]A^A_
AWAVAUATVWUSH
0[]_^A\A]A^A_
ZLk&u9
AWAVAUATVWUSH
[]_^A\A]A^A_
AWAVAUATVWUSH
=p>S!t
[]_^A\A]A^A_
UAWAVAUATVWSH
eh[_^A\A]A^A_]
AWAVAUATVWUSH
h[]_^A\A]A^A_
AWAVAUATVWUSH
h[]_^A\A]A^A_
AWAVAUATVWUSH
x[]_^A\A]A^A_
AWAVAUATVWUSH
h[]_^A\A]A^A_
AWAVAUATVWUSH
([]_^A\A]A^A_
AWAVAUATVWUSH
[]_^A\A]A^A_
AWAVAUATVWUSH
8[]_^A\A]A^A_
AWAVVWUSH
([]_^A^A_
AWAVAUATVWUSH
=Bvrmu
[]_^A\A]A^A_
AWAVAUATVWUSH
x[]_^A\A]A^A_
AWAVAUATVWUSH
h[]_^A\A]A^A_
AWAVAUATVWUSH
[]_^A\A]A^A_
AWAVAUATVWUSH
D$@H;D$H
x[]_^A\A]A^A_
AWAVVWUSH
H[]_^A^A_
AWAVAUATVWUSH
[]_^A\A]A^A_
AWAVAUATVWUSH
8[]_^A\A]A^A_
AWAVAUATVWUSH
X[]_^A\A]A^A_
AWAVAUATVWUSH
T$x=c~
[]_^A\A]A^A_
AWAVAUATVWUSH
[]_^A\A]A^A_
AVVWUSH
P[]_^A^
AWAVAUATVWUSH
[]_^A\A]A^A_
AWAVAUATVWUSH
@[]_^A\A]A^A_
AVVWUSH
@[]_^A^
AWAVAUATVWUSH
8[]_^A\A]A^A_
AVVWSH
H[_^A^
AWAVAUATVWUSH
T$XH;D$X
D$8H;D$@
h[]_^A\A]A^A_
AWAVAUATVWUSH
[]_^A\A]A^A_
AWAVAUATVWUSH
t$@H;D$@
X[]_^A\A]A^A_
AWAVAUATVWUSH
[]_^A\A]A^A_
AWAVAUATVWUSH
H[]_^A\A]A^A_
AWAVAUATVWUSH
H+D$8H
AWAVAUATVWUSH
X[]_^A\A]A^A_
AWAVAUATVWUSH
h[]_^A\A]A^A_
AWAVAUATVWUSH
D$8H;D$X
[]_^A\A]A^A_
AWAVAUATVWUSH
H[]_^A\A]A^A_
AWAVAUATVWUSH
AWAVAUATVWUSH
X[]_^A\A]A^A_
AWAVAUATVWUSH
[]_^A\A]A^A_
AWAVVWUSH
8[]_^A^A_
AWAVAUATVWUSH
X[]_^A\A]A^A_
AWAVAUATVWUSH
8[]_^A\A]A^A_
AWAVAUATVWUSH
X[]_^A\A]A^A_
AWAVAUATVWUSH
x[]_^A\A]A^A_
AWAVAUATVWUSH
([]_^A\A]A^A_
AWAVAUATVWUSH
[]_^A\A]A^A_
AWAVAUATVWUSH
H+D$0H
[]_^A\A]A^A_
AWAVAUATVWUSH
`[]_^A\A]A^A_
AWAVAUATVWUSH
8[]_^A\A]A^A_
AWAVAUATVWUSH
h[]_^A\A]A^A_
AWAVAUATVWUSH
X[]_^A\A]A^A_
AWAVAUATVWUSH
X[]_^A\A]A^A_
AWAVAUATVWUSH
H+D$(H
h[]_^A\A]A^A_
AWAVAUATVWUSH
H[]_^A\A]A^A_
AWAVAUATVWUSH
AWAVAUATVWUSH
0[]_^A\A]A^A_
AWAVAUATVWUSH
L$@=bte
H+D$0H
UAWAVAUATVWSH
gfffffffH
gfffffffH
[_^A\A]A^A_]
AWAVAUATVWUSH
H[]_^A\A]A^A_
AWAVAUATVWUSH
=D-.Zt
8[]_^A\A]A^A_
AWAVAUATVWUSH
[]_^A\A]A^A_
AWAVAUATVWUSH
L$@=%<
[]_^A\A]A^A_
AVVWUSH
0[]_^A^
AWAVATVWUSH
0[]_^A\A^A_
AWAVAUATVWUS
[]_^A\A]A^A_
AWAVVWUSH
8[]_^A^A_
AWAVAUATVWUSH
8[]_^A\A]A^A_
AVVWUSH
0[]_^A^
AVVWUSH
0[]_^A^
,Yju4H
AWAVAUATVWUSH
8[]_^A\A]A^A_
AWAVAUATVWUSH
H[]_^A\A]A^A_
AWAVAUATVWUSH
8[]_^A\A]A^A_
AWAVATVWUSH
@[]_^A\A^A_
AWAVAUATVWUSH
gfffffffH
[]_^A\A]A^A_
AWAVAUATVWUSH
D$0H;D$H
x[]_^A\A]A^A_
AWAVAUATVWUSH
[]_^A\A]A^A_
AWAVAUATVWUSH
[]_^A\A]A^A_
AWAVAUATVWUSH
[]_^A\A]A^A_
AWAVAUATVWUSH
[]_^A\A]A^A_
AWAVAUATVWUSH
qa^sH)
[]_^A\A]A^A_
AWAVAUATVWUSH
H+D$HH
HcD$lI
[]_^A\A]A^A_
AWAVAUATVWUSH
D$(H;D$8
D$XH+D$(H
[]_^A\A]A^A_
AWAVAUATVWUSH
#~B=D:
([]_^A\A]A^A_
UAWAVAUATVWSH
[_^A\A]A^A_]
AWAVAUATVWUSH
[]_^A\A]A^A_
AWAVAUATVWUSH
8[]_^A\A]A^A_
UAWAVAUATVWSH
[_^A\A]A^A_]
AWAVAUATVWUSH
+D$x+D$,
[]_^A\A]A^A_
AWAVAUATVWUSH
D#\$@A
D)\$hA
3\$`D!
%*<kYA
D#t$`E
J+L$`A
9 sD
D#L$xA
%pvhsD
D3l$`E!
+D$<D)
[]_^A\A]A^A_
AWAVAUATVWUSH
8[]_^A\A]A^A_
AWAVAUATVWUSH
[]_^A\A]A^A_
AWAVAUATVWUSH
[]_^A\A]A^A_
AWAVAUATVWUSH
UUUUUUUUL
33333333I
f f47w#YH
33333333I
p[]_^A\A]A^A_
AWAVAUATVWUSH
[]_^A\A]A^A_
AWAVAUATVWUSH
Gu@lH!
(8Z*sH
H#,$L!
[]_^A\A]A^A_
UAWAVAUATVWSH
DDDDDDDD
""""""""H1
""""""""H1
DDDDDDDD
[_^A\A]A^A_]
AWAVAUATVWUSH
[]_^A\A]A^A_
UAWAVAUATVWSH
>#s6FwH
[_^A\A]A^A_]
AWAVAUATVWUSH
[]_^A\A]A^A_
AWAVAUATVWUSH
h[]_^A\A]A^A_
AWAVAUATVWUSH
x[]_^A\A]A^A_
AWAVAUATVWUSH
h[]_^A\A]A^A_
AWAVAUATVWUSH
=2r4]u
8[]_^A\A]A^A_
AWAVAUATVWUSH
H[]_^A\A]A^A_
AWAVVWUSH
([]_^A^A_
AWAVAUATVWUS
[]_^A\A]A^A_
AWAVAUATVWUSH
8[]_^A\A]A^A_
AWAVAUATVWUSH
D$0H;D$@
h[]_^A\A]A^A_
AVVWUS
[]_^A^
AWAVAUATVWUSH
X[]_^A\A]A^A_
AWAVAUATVWUS
H+L$HH
1J'Xl>
H+L$HH
H+L$HH
` (ord
` (ord
` (ord
` (ord
H+L$HH
` (ord
` (ord
` (ord
` (ord
H+L$HH
` (ord
` (ord
` (ord
` (ord
Qt/=A/
H+L$HH
` (ord
Qt-=A/
` (ord
H+L$HH
Qt/=A/
H+L$HH
H+L$HH
H+L$HH
H+L$HH
H+L$HH
H+L$HH
H+L$HH
H+L$HH
H+L$HH
H+L$HH
H+L$HH
H+L$HH
H+L$HH
H+L$HH
H+L$HH
H+L$HH
H+L$HH
[]_^A\A]A^A_
AWAVAUATVWUSH
h[]_^A\A]A^A_
AWAVAUATVWUSH
8[]_^A\A]A^A_
UAWAVAUATVWSH
[_^A\A]A^A_]
AVVWUSH
([]_^A^
AWAVAUATVWUSH
D$`I+G
D$XH;D$x
[]_^A\A]A^A_
AWAVAUATVWUSH
X[]_^A\A]A^A_
AWAVAUATVWUSH
x[]_^A\A]A^A_
AWAVAUATVWUSH
[]_^A\A]A^A_
AWAVAUATVWUSH
[]_^A\A]A^A_
AWAVAUATVWUSH
[]_^A\A]A^A_
AWAVAUATVWUSH
=K[Ivu
[]_^A\A]A^A_
AWAVAUATVWUSH
[]_^A\A]A^A_
AWAVAUATVWUSH
[]_^A\A]A^A_
AWAVAUATVWUSH
H+|$8H+|$@
X[]_^A\A]A^A_
AWAVAUATVWUSH
[]_^A\A]A^A_
AWAVAUATVWUSH
x[]_^A\A]A^A_
AWAVAUATVWUSH
%HcD$DH
q7e=3X
h[]_^A\A]A^A_
AWAVAUATVWUSH
{Wsj=Q
~s=b,$<
HcD$PH
HcT$PH
L$pHc@<H
[]_^A\A]A^A_
AWAVAUATVWUSH
~u=]3cI
[]_^A\A]A^A_
UAWAVAUATVWSH
[_^A\A]A^A_]
AWAVAUATVWUSH
H+D$8H
H[]_^A\A]A^A_
AWAVAUATVWUSH
[]_^A\A]A^A_
l?RuAL
UAWAVAUATVWSH
~P=.VT.
[_^A\A]A^A_]
UAWAVAUATVWSH
[_^A\A]A^A_]
AWAVAUATVWUSH
8[]_^A\A]A^A_
==9L:t
AWAVATVWUSH
0[]_^A\A^A_
AWAVATVWUSH
0[]_^A\A^A_
AWAVAUATVWUSH
8[]_^A\A]A^A_
AVVWUSH
0[]_^A^
AWAVAUATVWUSH
([]_^A\A]A^A_
=~5^bt
AVVWUSH
0[]_^A^
AVVWUSH
&2du:H
0[]_^A^
x=7.\>t^=
x=6.\>
AVVWUSH
0[]_^A^
AWAVAUATVWUSH
~)=0/vO
H+D$8H
h[]_^A\A]A^A_
AWAVAUATVWUSH
~{=o~aR
[]_^A\A]A^A_
ATUWVSH
0[^_]A\
0[^_]A\
ATUWVSH
P[^_]A\
P[^_]A\
UAWAVAUATWVSH
[^_A\A]A^A_]
ATUWVSH
[^_]A\
ATWVSH
([^_A\H
tNHcA<H
tTIcB<L
tCHcA<H
tKIcA<L
tSIcK<L
00010203040506070809101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899AssertionDefect
sysFatal
fatal.nim
IOError
raiseEIO
io.nim
@cannot write string to file
@cannot open:
out of memory
@value out of range:
@ notin
@index out of bounds, the container is empty
@index
@ not in 0 ..
@value out of range
@[[reraised from:
@no exception to reraise
Error: unhandled exception:
@over- or underflow
[GC] cannot register thread local variable; too many thread local variables
SIGINT: Interrupted by Ctrl-C.
SIGSEGV: Illegal storage access. (Attempt to read from nil?)
SIGABRT: Abnormal termination.
SIGFPE: Arithmetic error.
SIGILL: Illegal operation.
unknown signal
could not load:
(bad format; library may be wrong architecture)
could not import:
[GC] cannot register global variable; too many global variables
@false
@index out of bounds
7<9};(+01990<'
parent
procname
filename
virtualFree failing!
RangeDefect
sysFatal
fatal.nim
IndexDefect
ReraiseDefect
OverflowDefect
@kernel32
@kernel32
GetCurrentProcessId
OpenProcess
VirtualAllocEx
VirtualProtect
CreateFileA
GetFileSize
HeapAlloc
GetProcessHeap
ReadFile
lstrcmpA
GetCurrentProcess
GetModuleHandleA
CreateFileMappingW
GetLastError
MapViewOfFile
FreeLibrary
InitializeProcThreadAttributeList
UpdateProcThreadAttribute
DeleteProcThreadAttributeList
CreateProcessW
@psapi
@psapi
GetModuleInformation
_BDE_RDU_
/-.'ggitvj919~8&z2}
@Ws2_32.dll
inet_ntop
Field0
Field1
zonedTimeFromTimeImpl
zonedTimeFromAdjTimeImpl
bCryptGenRandom
queryProcessCycleTime
queryUnbiasedInterruptTime
queryIdleProcessorCycleTime
coresCount
hIntel
?456789:;<=
 !"#$%&'()*+,-./0123
ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789-_ValueError
@Invalid base64 format character `
@) at location
decode
base64.nim
ValueError
@invalid format string, cannot parse:
parseStandardFormatSpecifier
strformat.nim
@invalid type in format string for string, expected 's', but got
formatValue
@USH^TP^
p|vb hl#jb|bi}*x`g
yw1t|n=pju{
V^S[%YSX^
\hea#gmbd#jn-==j,;!lw
@strformat.nim(320, 9) `v < 26`
@]%@jsu|vqtXv{ptdc<>Qd
@nCZBM
TDTQGW
V[utnhf l`gilz)
@Id}ej/bbF
VXZTNF
@.text
@[!] srcYVZzoYuPjNKwKTduNjaKG failed to modify memory permissions:
@[!] mbZvSNkawKDwiFtztgiegxNg failed to write bytes to target address:
@[!] srcYVZzoYuPjNKwKTduNjaKG failed to reset memory back to it's orignal protections:
>*?*0)
wQGUL\^
LOQ\UBA
C\B_(YCO6-
@>N:F(5
%$'(!;1
i)'&*'&2$$c/810, x24u ?3q3!7
@[!] IUqGlbyVRJtmgQSQYQHCIWYA FAILED to allocate memory in created process, exiting:
@[!] mbZvSNkawKDwiFtztgiegxNg FAILED to write decoded payload to allocated memory:
@srcYVZzoYuPjNKwKTduNjaKG FAILED to modify permissions:
@[!] TYnHWWgqYWWxRHnbJhtbsbmf FAILED to add routine to APC queue:
@[!] tvsAsEgAHliqMNZuyMgXOSyy FAILED to resume thread:
@TnRPcGVuUHJvY2Vzcw==
@TnRBbGxvY2F0ZVZpcnR1YWxNZW1vcnk=
@TnRXcml0ZVZpcnR1YWxNZW1vcnk=
@TnRDcmVhdGVUaHJlYWRFeA==
@TnRQcm90ZWN0VmlydHVhbE1lbW9yeQ==
@TnRDbG9zZQ==
@TnRRdWV1ZUFwY1RocmVhZA==
@TnRBbGVydFJlc3VtZVRocmVhZA==
@TnRXYWl0Rm9yU2luZ2xlT2JqZWN0
@[*] Found Syscall Stub:
@[!] Failed to Get Syscall Stub:
xlDGJu7]?S8hOdoEh*Y:~@aw\UwpJeMu
4#2):7
5E)LK('1(
;ETc>o5sYPEx{hD4G=VBsR>B4tAm4-$(oUlZ
GZq\}z`
M\VQz2+$
2N@@[N/
OPxgaWCm:~]hT\EmhfgGGEw}UuwVjPDSDCIBH
rBBd@ygebE[gD
nQY]lr
TP\9u0
S:V]14P$Y+T:W+BA
[LEFHSQ`Z~ sAjjM_fvWLm/y+RkIvW4D
([5<W? _$(
O9N)2#,
_CMRDFkdT}4XBYCQQm^z{ci>-JzW*s-/
aY}dJzcFY}UHW}c
?$91:E
@Oby![{R_^
^cAoD\OP
@[*] mbZvSNkawKDwiFtztgiegxNg wrote decoded payload to allocated memory successfully.
@[*] srcYVZzoYuPjNKwKTduNjaKG modified permissions successfully.
@[*] TYnHWWgqYWWxRHnbJhtbsbmf added routine to APC queue successfully.
@[*] tvsAsEgAHliqMNZuyMgXOSyy resumed thread successfully.
@QQ\_SS
rtimk7= .2}uy>za
z||&n-
cxhvVyyts9'&<5,*6!fjr%>.h)
Unknown error
Argument domain error (DOMAIN)
Overflow range error (OVERFLOW)
Partial loss of significance (PLOSS)
Total loss of significance (TLOSS)
The result is too small to be represented (UNDERFLOW)
Argument singularity (SIGN)
_matherr(): %s in %s(%g, %g) (retval=%g)
Mingw-w64 runtime failure:
Address %p has no image-section
VirtualQuery failed for %d bytes at address %p
VirtualProtect failed with code 0x%x
Unknown pseudo relocation protocol version %d.
Unknown pseudo relocation bit size %d.
.pdata
GCC: (GNU) 9.2-win32 20191008
GCC: (GNU) 9.3-win32 20200320
GCC: (GNU) 9.2-win32 20191008
GCC: (GNU) 9.2-win32 20191008
GCC: (GNU) 9.2-win32 20191008
GCC: (GNU) 9.2-win32 20191008
GCC: (GNU) 9.2-win32 20191008
GCC: (GNU) 9.2-win32 20191008
GCC: (GNU) 9.2-win32 20191008
GCC: (GNU) 9.2-win32 20191008
GCC: (GNU) 9.2-win32 20191008
GCC: (GNU) 9.2-win32 20191008
GCC: (GNU) 9.2-win32 20191008
GCC: (GNU) 9.2-win32 20191008
GCC: (GNU) 9.2-win32 20191008
GCC: (GNU) 9.2-win32 20191008
GCC: (GNU) 9.2-win32 20191008
GCC: (GNU) 9.2-win32 20191008
GCC: (GNU) 9.2-win32 20191008
GCC: (GNU) 9.2-win32 20191008
GCC: (GNU) 9.2-win32 20191008
GCC: (GNU) 9.2-win32 20191008
GCC: (GNU) 9.2-win32 20191008
GCC: (GNU) 9.3-win32 20200320
GCC: (GNU) 9.2-win32 20191008
GCC: (GNU) 9.2-win32 20191008
GCC: (GNU) 9.2-win32 20191008
GCC: (GNU) 9.2-win32 20191008
GCC: (GNU) 9.2-win32 20191008
GCC: (GNU) 9.3-win32 20200320
DeleteCriticalSection
EnterCriticalSection
GetCurrentProcess
GetCurrentProcessId
GetCurrentThreadId
GetLastError
GetProcAddress
GetStartupInfoA
GetSystemTimeAsFileTime
GetTickCount
InitializeCriticalSection
LeaveCriticalSection
LoadLibraryA
QueryPerformanceCounter
RtlAddFunctionTable
RtlCaptureContext
RtlLookupFunctionEntry
RtlVirtualUnwind
SetUnhandledExceptionFilter
TerminateProcess
TlsGetValue
UnhandledExceptionFilter
VirtualAlloc
VirtualFree
VirtualProtect
VirtualQuery
__C_specific_handler
__getmainargs
__initenv
__iob_func
__lconv_init
__set_app_type
__setusermatherr
_acmdln
_amsg_exit
_cexit
_fileno
_fmode
_get_osfhandle
_initterm
_onexit
_setjmp
_setmode
_wfopen
calloc
fflush
fprintf
fwrite
malloc
memchr
memcpy
memset
printf
setvbuf
signal
strlen
strncmp
vfprintf
longjmp
MessageBoxA
KERNEL32.dll
msvcrt.dll
USER32.dll
<?xml version="1.0" encoding="UTF-8" standalone="yes"?><assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0"><assemblyIdentity version="1.0.0.0" processorArchitecture="*" name="winim" type="win32"/><dependency><dependentAssembly><assemblyIdentity type="win32" name="Microsoft.Windows.Common-Controls" version="6.0.0.0" processorArchitecture="*" publicKeyToken="6595b64144ccf1df" language="*"/></dependentAssembly></dependency></assembly>
Antivirus Signature
Bkav W32.Common.D157F25B
Lionic Trojan.Win32.Shelma.W!c
tehtris Clean
DrWeb Clean
MicroWorld-eScan Trojan.GenericKD.68291669
FireEye Trojan.GenericKD.68291669
CAT-QuickHeal Clean
McAfee Artemis!D13B979B1BD8
Malwarebytes Spyware.PasswordStealer
VIPRE Trojan.GenericKD.68291669
Sangfor Trojan.Win32.Save.a
K7AntiVirus Trojan ( 005940f01 )
BitDefender Trojan.GenericKD.68291669
K7GW Trojan ( 005940f01 )
Cybereason Clean
BitDefenderTheta Clean
VirIT Trojan.Win64.Agent.BBU
Cyren W64/ABRisk.QYJW-2790
Symantec ML.Attribute.HighConfidence
Elastic malicious (high confidence)
APEX Malicious
Paloalto Clean
ClamAV Clean
Kaspersky Trojan.Win64.Shelma.abxe
Alibaba Trojan:Win64/Shelma.c60a5f77
NANO-Antivirus Clean
ViRobot Clean
Rising Trojan.Injector!8.C4 (TFE:5:iTLV1Mk31UI)
TACHYON Clean
Emsisoft Trojan.GenericKD.68291669 (B)
F-Secure Trojan.TR/Injector.mjgvm
Baidu Clean
Zillya Clean
McAfee-GW-Edition BehavesLike.Win64.Exploit.th
Trapmine Clean
CMC Clean
Sophos Mal/Generic-S
Ikarus Trojan.Win64.Crypt
GData Trojan.GenericKD.68291669
Jiangmin Clean
Webroot W32.Trojan.GenKD
Avira TR/Injector.mjgvm
Antiy-AVL Trojan/Win64.Injector
Gridinsoft Clean
Xcitium Clean
Arcabit Trojan.Generic.D4120C55
SUPERAntiSpyware Clean
ZoneAlarm Trojan.Win64.Shelma.abxe
Microsoft Trojan:Win32/Casdet!rfn
Google Detected
AhnLab-V3 Trojan/Win.Generic.C5349977
Acronis Clean
VBA32 Trojan.Win64.Crypt
ALYac Trojan.GenericKD.68291669
MAX malware (ai score=89)
DeepInstinct MALICIOUS
Cylance unsafe
Panda Trj/RansomGen.A
Zoner Clean
TrendMicro-HouseCall TROJ_GEN.R03BC0XGR23
Tencent Win64.Trojan.Shelma.Rimw
Yandex Clean
SentinelOne Clean
MaxSecure Clean
Fortinet W32/PossibleThreat
AVG Win64:Evo-gen [Trj]
Avast Win64:Evo-gen [Trj]
CrowdStrike win/malicious_confidence_100% (W)
No IRMA results available.