Static | ZeroBOX

PE Compile Time

2023-07-26 20:25:12

PE Imphash

7171dd3cc2e067362ea92a90a83c63fe

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x00018202 0x00018400 6.61656253983
.rdata 0x0001a000 0x00009b86 0x00009c00 4.97012881478
.data 0x00024000 0x000024ec 0x00001800 4.2263406023
.teext 0x00027000 0x001241a4 0x00124200 7.20189935333
.rsrc 0x0014c000 0x000001e0 0x00000200 4.71767883295
.reloc 0x0014d000 0x00001aa0 0x00001c00 6.43019143279
.But... 0x0014f000 0x000aaec4 0x000ab000 0.000863708157684
.But... 0x001fa000 0x000aaec4 0x000ab000 0.000863708157684
.But... 0x002a5000 0x000aaec4 0x000ab000 0.000863708157684

Resources

Name Offset Size Language Sub-language File type
RT_MANIFEST 0x0014c060 0x0000017d LANG_ENGLISH SUBLANG_ENGLISH_US XML 1.0 document text

Imports

Library USER32.dll:
0x41a174 SetWindowRgn
0x41a178 DdeReconnect
Library ole32.dll:
0x41a18c OleSave
0x41a190 ReleaseStgMedium
Library GDI32.dll:
0x41a000 RestoreDC
0x41a008 AngleArc
Library WS2_32.dll:
0x41a184 WSAStartup
Library KERNEL32.dll:
0x41a010 HeapSize
0x41a014 CreateFileW
0x41a018 WriteConsoleW
0x41a01c HeapReAlloc
0x41a020 SetEvent
0x41a024 GetConsoleMode
0x41a028 GetConsoleOutputCP
0x41a02c VirtualProtect
0x41a030 RaiseException
0x41a034 InitializeSRWLock
0x41a054 GetCurrentThreadId
0x41a070 InitOnceComplete
0x41a074 GetLastError
0x41a084 CloseThreadpoolWork
0x41a088 GetModuleHandleExW
0x41a098 GetModuleHandleW
0x41a09c GetProcAddress
0x41a0a0 CloseHandle
0x41a0ac DecodePointer
0x41a0b0 ResetEvent
0x41a0b4 CreateEventW
0x41a0b8 IsDebuggerPresent
0x41a0c4 GetStartupInfoW
0x41a0c8 GetCurrentProcess
0x41a0cc TerminateProcess
0x41a0d0 GetCurrentProcessId
0x41a0d4 InitializeSListHead
0x41a0d8 FlushFileBuffers
0x41a0dc RtlUnwind
0x41a0e0 SetLastError
0x41a0e4 EncodePointer
0x41a0e8 TlsAlloc
0x41a0ec TlsGetValue
0x41a0f0 TlsSetValue
0x41a0f4 TlsFree
0x41a0f8 FreeLibrary
0x41a0fc LoadLibraryExW
0x41a100 ExitProcess
0x41a104 GetModuleFileNameW
0x41a108 GetStdHandle
0x41a10c WriteFile
0x41a110 GetCommandLineA
0x41a114 GetCommandLineW
0x41a118 HeapAlloc
0x41a11c HeapFree
0x41a120 CompareStringW
0x41a124 LCMapStringW
0x41a128 GetFileType
0x41a12c GetFileSizeEx
0x41a130 SetFilePointerEx
0x41a134 FindClose
0x41a138 FindFirstFileExW
0x41a13c FindNextFileW
0x41a140 IsValidCodePage
0x41a144 GetACP
0x41a148 GetOEMCP
0x41a14c GetCPInfo
0x41a150 MultiByteToWideChar
0x41a154 WideCharToMultiByte
0x41a164 GetProcessHeap
0x41a168 SetStdHandle
0x41a16c GetStringTypeW

!This program cannot be run in DOS mode.
`.rdata
@.data
.teext
@.reloc
B.But...
P.But...
P.But...
YY9~d|
\$HYYj
L$8_^][3
YY9Gd}
D$,SUV
!4$VVVV
QQSVWd
URPQQh
UQPXY]Y[
F4_^[]
<ItC<Lt3<Tt#<h
A<lt'<tt
35,`B
j,hH0B
u,PQRS
Wj0XPV
SPjdVQ
zSSSSj
f9:t!V
QQSVj8j@
tl= HB
CY<u
PPPPPPPP
PPPPPWS
PP9E u:PPVWP
Unknown exception
bad array new length
string too long
generic
success
Fail to schedule the chore!
This function cannot be called on a default constructed task
broken promise
future already retrieved
promise already satisfied
no state
future
Alznxa81
FreeConsole
vector too long
bad allocation
bad function call
bad exception
device or resource busy
invalid argument
no such process
not enough memory
operation not permitted
resource deadlock would occur
resource unavailable try again
address family not supported
address in use
address not available
already connected
argument list too long
argument out of domain
bad address
bad file descriptor
bad message
broken pipe
connection aborted
connection already in progress
connection refused
connection reset
cross device link
destination address required
directory not empty
executable format error
file exists
file too large
filename too long
function not supported
host unreachable
identifier removed
illegal byte sequence
inappropriate io control operation
interrupted
invalid seek
io error
is a directory
message size
network down
network reset
network unreachable
no buffer space
no child process
no link
no lock available
no message available
no message
no protocol option
no space on device
no stream resources
no such device or address
no such device
no such file or directory
not a directory
not a socket
not a stream
not connected
not supported
operation canceled
operation in progress
operation not supported
operation would block
owner dead
permission denied
protocol error
protocol not supported
read only file system
result out of range
state not recoverable
stream timeout
text file busy
timed out
too many files open in system
too many files open
too many links
too many symbolic link levels
value too large
wrong protocol type
unknown error
FlsAlloc
FlsFree
FlsGetValue
FlsSetValue
InitializeCriticalSectionEx
InitOnceExecuteOnce
CreateEventExW
CreateSemaphoreW
CreateSemaphoreExW
CreateThreadpoolTimer
SetThreadpoolTimer
WaitForThreadpoolTimerCallbacks
CloseThreadpoolTimer
CreateThreadpoolWait
SetThreadpoolWait
CloseThreadpoolWait
FlushProcessWriteBuffers
FreeLibraryWhenCallbackReturns
GetCurrentProcessorNumber
CreateSymbolicLinkW
GetCurrentPackageId
GetTickCount64
GetFileInformationByHandleEx
SetFileInformationByHandle
GetSystemTimePreciseAsFileTime
InitializeConditionVariable
WakeConditionVariable
WakeAllConditionVariable
SleepConditionVariableCS
InitializeSRWLock
AcquireSRWLockExclusive
TryAcquireSRWLockExclusive
ReleaseSRWLockExclusive
SleepConditionVariableSRW
CreateThreadpoolWork
SubmitThreadpoolWork
CloseThreadpoolWork
CompareStringEx
GetLocaleInfoEx
LCMapStringEx
__based(
__cdecl
__pascal
__stdcall
__thiscall
__fastcall
__vectorcall
__clrcall
__eabi
__swift_1
__swift_2
__swift_3
__ptr64
__restrict
__unaligned
restrict(
delete
operator
`vftable'
`vbtable'
`vcall'
`typeof'
`local static guard'
`string'
`vbase destructor'
`vector deleting destructor'
`default constructor closure'
`scalar deleting destructor'
`vector constructor iterator'
`vector destructor iterator'
`vector vbase constructor iterator'
`virtual displacement map'
`eh vector constructor iterator'
`eh vector destructor iterator'
`eh vector vbase constructor iterator'
`copy constructor closure'
`udt returning'
`local vftable'
`local vftable constructor closure'
new[]
delete[]
`omni callsig'
`placement delete closure'
`placement delete[] closure'
`managed vector constructor iterator'
`managed vector destructor iterator'
`eh vector copy constructor iterator'
`eh vector vbase copy constructor iterator'
`dynamic initializer for '
`dynamic atexit destructor for '
`vector copy constructor iterator'
`vector vbase copy constructor iterator'
`managed vector copy constructor iterator'
`local static thread guard'
operator ""
operator co_await
operator<=>
Type Descriptor'
Base Class Descriptor at (
Base Class Array'
Class Hierarchy Descriptor'
Complete Object Locator'
`anonymous namespace'
(null)
CorExitProcess
AreFileApisANSI
LocaleNameToLCID
AppPolicyGetProcessTerminationMethod
NAN(SNAN)
nan(snan)
NAN(IND)
nan(ind)
Sunday
Monday
Tuesday
Wednesday
Thursday
Friday
Saturday
January
February
August
September
October
November
December
MM/dd/yy
dddd, MMMM dd, yyyy
HH:mm:ss
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
[aOni*{
~ $s%r
@b;zO]
v2!L.2
1#QNAN
1#SNAN
?5Wg4p
%S#[k=
"B <1=
_hypot
_nextafter
.text$di
.text$mn
.text$x
.text$yd
.idata$5
.00cfg
.CRT$XCA
.CRT$XCAA
.CRT$XCC
.CRT$XCU
.CRT$XCZ
.CRT$XIA
.CRT$XIAA
.CRT$XIAC
.CRT$XIC
.CRT$XIZ
.CRT$XLA
.CRT$XLZ
.CRT$XPA
.CRT$XPX
.CRT$XPXA
.CRT$XPZ
.CRT$XTA
.CRT$XTZ
.rdata
.rdata$T
.rdata$r
.rdata$sxdata
.rdata$voltmd
.rdata$zzzdbg
.rtc$IAA
.rtc$IZZ
.rtc$TAA
.rtc$TZZ
.tls$ZZZ
.xdata$x
.idata$2
.idata$3
.idata$4
.idata$6
.data$r
.data$rs
.teext
.rsrc$01
.rsrc$02
SetWindowDisplayAffinity
SetWindowRgn
DdeReconnect
USER32.dll
OleSave
ReleaseStgMedium
ole32.dll
CreateBitmapIndirect
RestoreDC
AngleArc
GDI32.dll
WS2_32.dll
VirtualProtect
RaiseException
InitializeSRWLock
ReleaseSRWLockExclusive
AcquireSRWLockExclusive
EnterCriticalSection
LeaveCriticalSection
InitializeCriticalSectionEx
TryEnterCriticalSection
DeleteCriticalSection
GetCurrentThreadId
InitializeConditionVariable
WakeConditionVariable
WakeAllConditionVariable
SleepConditionVariableCS
SleepConditionVariableSRW
InitOnceBeginInitialize
InitOnceComplete
GetLastError
FreeLibraryWhenCallbackReturns
CreateThreadpoolWork
SubmitThreadpoolWork
CloseThreadpoolWork
GetModuleHandleExW
IsProcessorFeaturePresent
QueryPerformanceCounter
GetSystemTimeAsFileTime
GetModuleHandleW
GetProcAddress
CloseHandle
WaitForSingleObjectEx
InitializeCriticalSectionAndSpinCount
SetEvent
ResetEvent
CreateEventW
IsDebuggerPresent
UnhandledExceptionFilter
SetUnhandledExceptionFilter
GetStartupInfoW
GetCurrentProcess
TerminateProcess
GetCurrentProcessId
InitializeSListHead
KERNEL32.dll
RtlUnwind
SetLastError
EncodePointer
TlsAlloc
TlsGetValue
TlsSetValue
TlsFree
FreeLibrary
LoadLibraryExW
ExitProcess
GetModuleFileNameW
GetStdHandle
WriteFile
GetCommandLineA
GetCommandLineW
HeapAlloc
HeapFree
CompareStringW
LCMapStringW
GetFileType
GetFileSizeEx
SetFilePointerEx
FindClose
FindFirstFileExW
FindNextFileW
IsValidCodePage
GetACP
GetOEMCP
GetCPInfo
MultiByteToWideChar
WideCharToMultiByte
GetEnvironmentStringsW
FreeEnvironmentStringsW
SetEnvironmentVariableW
GetProcessHeap
SetStdHandle
GetStringTypeW
FlushFileBuffers
GetConsoleOutputCP
GetConsoleMode
HeapSize
HeapReAlloc
CreateFileW
WriteConsoleW
DecodePointer
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
.?AVbad_array_new_length@std@@
.?AVbad_alloc@std@@
.?AVexception@std@@
.?AVruntime_error@std@@
.?AVsystem_error@std@@
.?AV_System_error@std@@
.?AVtask_canceled@Concurrency@@
.?AVinvalid_operation@Concurrency@@
.?AV_Interruption_exception@details@Concurrency@@
.?AV<lambda_0456396a71e3abd88ede77bdd2823d8e>@@
.?AV<lambda_eb87dfd73f857f44e1a351ea42ce2b34>@@
.?AV<lambda_cf64729cb90f65090849ddab3f3d5e68>@@
.?AV<lambda_5e5ab22ea98f4361dbf159481d01f54d>@@
.?AV?$_Fake_no_copy_callable_adapter@A6AXXZ@std@@
.?AV<lambda_dc3a808d3cb651230a54fc79f9ff1e4d>@@
.?AVlogic_error@std@@
.?AVlength_error@std@@
.?AVbad_function_call@std@@
.?AVbad_exception@std@@
.?AVfuture_error@std@@
.?AVerror_category@std@@
.?AV_Generic_error_category@std@@
.?AV_Ref_count_base@std@@
.?AUscheduler_interface@Concurrency@@
.?AV_DefaultPPLTaskScheduler@details@Concurrency@@
.?AV_RefCounter@details@Concurrency@@
.?AV_CancellationTokenRegistration@details@Concurrency@@
.?AU_TaskProcHandle@details@Concurrency@@
.?AV?$_Func_base@X$$V@std@@
.?AU_Task_impl_base@details@Concurrency@@
.?AV?$_CancellationTokenCallback@V<lambda_3b8ab8d2629adf61a42ee3fe177a046b>@@@details@Concurrency@@
.?AV?$_Func_base@E$$V@std@@
.?AU?$_Task_impl@E@details@Concurrency@@
.?AV_Future_error_category2@std@@
.?AV?$_Associated_state@H@std@@
.?AV?$_Ref_count_obj2@U_ExceptionHolder@details@Concurrency@@@std@@
.?AV?$_Ref_count_obj2@U?$_Task_impl@E@details@Concurrency@@@std@@
.?AV?$_Func_impl_no_alloc@V<lambda_5e5ab22ea98f4361dbf159481d01f54d>@@X$$V@std@@
.?AV?$_Func_impl_no_alloc@V<lambda_cf64729cb90f65090849ddab3f3d5e68>@@X$$V@std@@
.?AV?$_Func_impl_no_alloc@V<lambda_eb87dfd73f857f44e1a351ea42ce2b34>@@E$$V@std@@
.?AV?$_Func_impl_no_alloc@V<lambda_0456396a71e3abd88ede77bdd2823d8e>@@X$$V@std@@
.?AV?$_Deferred_async_state@X@std@@
.?AV?$_Packaged_state@$$A6AXXZ@std@@
.?AV?$_Task_async_state@X@std@@
.?AV?$_Func_impl_no_alloc@V?$_Fake_no_copy_callable_adapter@A6AXXZ@std@@X$$V@std@@
.?AU?$_InitialTaskHandle@XV<lambda_dc3a808d3cb651230a54fc79f9ff1e4d>@@U_TypeSelectorNoAsync@details@Concurrency@@@?$task@E@Concurrency@@
.?AU?$_PPLTaskHandle@EU?$_InitialTaskHandle@XV<lambda_dc3a808d3cb651230a54fc79f9ff1e4d>@@U_TypeSelectorNoAsync@details@Concurrency@@@?$task@E@Concurrency@@U_TaskProcHandle@details@3@@details@Concurrency@@
.?AV?$_Func_impl_no_alloc@V<lambda_dc3a808d3cb651230a54fc79f9ff1e4d>@@X$$V@std@@
.?AV_ExceptionPtr_normal@?A0x6e02efe5@@
.?AV?$_ExceptionPtr_static@Vbad_alloc@std@@@?A0x6e02efe5@@
.?AV?$_ExceptionPtr_static@Vbad_exception@std@@@?A0x6e02efe5@@
.?AVstl_critical_section_interface@details@Concurrency@@
.?AVstl_critical_section_vista@details@Concurrency@@
.?AVstl_critical_section_win7@details@Concurrency@@
.?AVstl_condition_variable_interface@details@Concurrency@@
.?AVstl_condition_variable_vista@details@Concurrency@@
.?AVstl_condition_variable_win7@details@Concurrency@@
.?AVtype_info@@
KC"xZC6
KCBGHC
ZG.8DRF
A'gJCgg
A'gJI6c
"J7AgL
>A'gJC
A'gJGG
A'gJC>S
KCnCnC
ZG.8DRF
-Ld-Lz
S4RCgg
A'gJC?g
bk6Eb[6>bG7:5
b[6-bG7)5
!J7Ac
LV)-L\(
gFAgBC
g6Cg2C
2@>%AvS:
2T=!"R
5>OY"U
5n>ctPC
217#"N
!CY"-i
KCLC~S
KCLC~S
!B\"a]
C]5^W:
JA>K!:
!BY"]_
KCbJ[C
!CbJ[C
KzG6>D
Kz_6?Y
w2K7%A
w2K7zA
w6K7 A
(I7@rOC
KC`5!@
?S`5!B
?MbKHC
K(_&S@_
w6K>:A
(_>S@_*
GxG>>
w*K7IA
:H`O*?b
*(_>S@_"
0MbPKC
=MbAKC
K5rI6O
=MbAKC
8DSG:-L$
|(G6S@G"
ZG."q>
w:M69A
w.H6XpOC
KClCK
w>K7"I6[
KzO"=O
w2J6ZA
w:K7FA
w:K7&A
x_69G9
w>V6,A
w6C>VA
K0!rCC
K66sJC
kxO2?O
w>K?*A
Gx_>?j
w2K6*sOC
w2K7GsOC
[x_>>W
O64pJC
OzG2?H
w6K7[A
w2K7eA
w&K7iA
w:K7/A
w~K7qA
O6NpJC
GxG2=/
CxO6>0
*H6!sOC
G5FrOC
w>B6OA
w>w10A
[gQsJC
AgIrJC
C5MpOC
0"6nrJC
2?6*sJC
w"K7"A
w&K6'I6
w6I7+A
w6J6SA
8DSO"D
w"|4KA
w&K7JA
w>O69pCC
>Rbe@C
Sx_2?T
w6K7&I6
w6O6?A
KC75KC
w>g7a#
w2K>(A
8DSO:-L$
w6K?,A
w6K?LA
w2K?!A
OI8rIC
6/8DiO6
w:K7&I6
wvK7AA
K7sJC
w6K6HA
w*F6(A
>Mb0AC
w6D7yA
Ox_>>S
w:f7'I6
w6K7*A
w.K7$A
w6K=&A
ZG."<s
zG2?Qb
w6K7KA
?MboNC
8DSG:-L$
w6K6+A
?MboHC
LzG29Ub\OC
Cx_:>J
5>Sb5@C
w:K62A
?Sb:@C
5?Mb9HC
096-rJC
0"6'rJC
w.K7%A
wfK6?I6
w6K7!A
GxG6=H`
xG2=H`
OX5^{:
w.J76I6
w2F7-A
KzO68U
#[zG6<U
ozO66o
w6E6$I6
w"K71A
w>I62A
w.X6?I6
w6K66A
DlO"=J
DlO"9x
CxO6<d
JKCbOCC
!Cb4KC
b7KL"A
(O7(rOC
K7.sOC
[xG68R
K7.pOC
Jx_68R
K7.rOC
AxO68R
w6K7LA
w6K7TA
K6$rJC
GxO2?
w2K7(I6
+J6-I6
w2I6~I6
K0BpCC
+I6+pCC
K1HrJC
w>K7I6
w:J5HA
[6'K6O
b4KCiA
wnK7KA
!Bb4KC
!Db4KC
!Cb4KC
!Gb74C
w*K6}pJC
w*K7"rCC
!Db4KC
!Cb4KC
b4KC!A
b6-LtA
w2K7HA
!Db4KC
w&N4>A
!Cb4KC
!Cb4KC
!Gb4KC
!Cb4KC
!Cb4KC
KCb%KC
w>K7uA
?7b%KC
w&[6FA
w*K6&A
b4KC1A
!Cb4KC
b4KC!A
9vb!KC
w.K7 A
w&H40A
!Cb4KC
KCX"5n
w:A4~A
w>C6'A
w2O65A
w2C64A
JK6VI6
w2K>'A
=RbVEC
_0,rJC
w>J6/A
JK7rOC
w:O7I6
xGv<Px
w2@6(A
w&J5>A
9MbZGC
ACxG:D
[`O">Vb
w2K6-A
?Mb5@C
AIxOv5J
ACxGv=J
ACxGv4J
AZx_v<J
AZx_v7J
AIxOv9J
lCB4A
w&K7!A
w.C62A
+DxG"=O
JK7sOC
K6Ur[C
0J6HI6
=MbyEC
w&H6lA
O2!CbJKC
AZ5^s:
5KxG2>c
ZG.pCC
AGZAGI[A
K7(pCC
K7)pCC
K7)pCC
w*N6=A
KxO:=U
2E6osIC
KxO:=D9
KxO2=U
KxG2=U
0R6"rCC
8DSO&-L%
6Z8DiO&
K>&rOC
}OIZsOC
w>K?!A
w2K7mA
_>HI[G
G"HBZA
w2K7NA
_2HI["
G2HBZG
8DSG&-L$
K7[pOC
T73rOC
G&HBZA
6HK7bA
6BK7;A
_>HI[A
K7<pOC
@64rCC
4?Mb2EC
4?Mb2EC
w>K7&I6
OxO2=A
O7%pJC
0"6}rJC
w"K7'A
w.K6 A
nA_RXA
T7SrCC
w:K7,pCC
G2HBZpOC
A6ZsCC
nAOAZA
_2HI[rOC
nA_RXA
_>HI[rOC
w.K7>sCC
_:HI[rOC
w6H4#A
w>C6~I6
w:C6VI6
(C6UI6
HI[rOC
K75rOC
*OxO:8F
6[K7"A
K7<sCC
nAOAZA
K)pOC
w6_6'A
w6Y6!A
JK78pOC
2I7(sOC
J`_>?D9
}OIZsOC
nAOAZA
}_BXrOC
ZG.AOg
>OlI7g
6WMAg
@hHCSO
5!CZ"aG
K7hG7L
14=K12D
-Le*-L0
-Le*-L0
-Le*-L0
$-Z9D,|
44j9D<u
5*G4c@
H6zK3W*
(0g*?X
2_HC_A
(0g*>=
K4-9D,
?`8!?Z
A!:?S9
OlAJ%1
M!2?S9
Y!2?S9
A!:?S9
I!:?S9
Y!:?S9
14=K12D
-Le*-L0
-Le*-L0
-Le*-L0
$-Z9D,|
44j9D<u
5*G4c@
<?Q\5~
4?K18D
C]A6O]
5>OY"[
{G)?GD
J<NIuC
OCY"0L
J<'IuC
?o]A6K
O.!BZ"
!HzO&D
G*!j[A
S6hA>O3
K62A6W3
G2!cZ"
"o7uA>O
A6O9<rt~
5>OZA\
O:!CZ"u
>MHsK/
BJJsc~0
O:!#Z"
5>[[5>S
?TnAVC
\A>K\"c
H6.K0W*
6.5>cZ5|
M5<_Y"
5>OY"m
!CZ5>[
KC[5>W
H6OK4W*
>u\5>S
ICSImC
7'<LS~
KC19?I
5^60Jv
\A>S]A6[
<3j19=f
\A>K]A
=K1}KG
?HlI6KI
"B7$I6W
5h]A6W
{IC\5|
S\A>K]A
6!5=OZ5<G
6~AHxO
6&58O]A6
lI2q G
%*=!0R
%*=!0R
O6!IZ5=S
5>OX"e
lzO:?a
K7VI5{
K=\A5w9
lzO:?a
K7VI5{
;K1=9A
[77!xhr
AJB:AJ
\5>W]"
I7K6S
"!sS@6
w4K6+G
S]A6K9
KClCL%
jxG">W1
:!K\"u
=%1;9;
K%1;9{
{%1;9g
{%1:8_
jxG">W1
=%1;9;
K%1;9{
{%1;9g
{%1:8_
NxG&?3
NxG&?&
KCZ5>K
Ax_:>F1
Sx_:>F1
NxG&?5
w>K7,5>
NxG&?M
Ax_:>F1
NxG&?(
Sx_:>F1
K%1:?M`
ImCSAI
KCZ"2+
KClAJ%
!CboJC
KC1;>G
KC1:>R
KC13>G
5?@K!I
9G12<X
?(A>OKG
NxO6=a
7>A>O9
2B4K5o
2B4K5o
2B4K5o
2B4K5o
2bG:K\"
>UlI5G8
?L65?H
2i7I!s
5O[5>OX"
5!UTC{
5!UTC{
O&!SP:BS!3
K7&A>[
5!aTC{
KCbOKC
!AbLKC
g*KC`4
Ea0s@6G
wglAOglI
wglAOglI
wglAOglI
wglAOglI
wglAOglI
wglAOglI
wglAOglI
wglAOglI
wglAOglI
wglAOglI
%1;92l
%1;9jl
!KUC6WZG
NxG*=K
%1;9-l
%1:9l
%1:9{l
5>KZ"F
5>KZ"*
5>KZ""
5>KZ"v
5>KZ"g
5>KZ"Z
5>KZ""
5>KZ"{
G75>S
?WlIrI
[6LA>K
Kzw24l
`KCSI.
cKCSI.
`KCS!@p
C[X5^[;
!cUCM%
KC\":&
!X"5)
]A6S]"
KCS!^+
?27$KC
i+KCS5>
4?Ia0s@6G
>N\"11
5!UTC{
5!UTC{
AuzW>?_\"
w2K=+A
\A>K]O
U6/A>O3
5>OZ5>K
5!aSCC
\A>K]O
>R\5>K["
K7PA>K9
5!UTC{
KC/24C
_.58O]"
@)*"CR
Cli)BX
5!OUCs
5!UTC{
+PJCSO
2-xO>>K
G2AlAJ
G:AlAJ
5>OZ5>K
\A>K]!\
5?VlA3Al
I6E<N+
?i]5=K
w2K6BA
?dlA;Al
!AR!Ip
C6DI5G
A=K92x
5!UTC{
G5!FRC
5?VZ"EV
!@T!Hp
6Z5^c:
?D\5^#:
KC1:7A
>H[5^#;
5!aTC{
?NlIsC~
GH!C%3
?M95-z2
2J?xA>K
K6Y5>o9
*NGZBM
ICQZOs
6.5>c\5>S]"LC
Z5>OY"
]5>SY"/
K>L5>K
A>OlA6
E95-z6
5PZ5>O\"
A>KlA6
ZJCZ",
?J\"AB
>DW5nc:
!CbjDC
KC\"KE
5?BMJtc~0
r\~2!Fb
5>KZ"M
KxO>8j
-x_*>K`
-zO6?J`
bM6U5>K
7#A>K]
bM6U5>K
7#A>K]
]A6K9<
KClCLz
Z5>W]"
'KCSC>
bJ7"5>O
O\5;GX"O
O\5;GX"
wglAOglI
wglKwgu
LS$-L"
LS;-L"
LR&-Lz,
-Ly;f%
-Lt(-Ly
-Ly:k%
wglAOglI
5G."CC
wglAOglI
5G."CC
wglAOglI
5G."CC
-L"3-LV
-Ld(-Ly>
wglAOglI
5G."CC
H%/54%'
LV(-LS"-LV
-LS"-LS
wglAOglI
'^KCXQ
5G."CC
H%/54%'
LV(-LS"-LV
-LS"-LS
wglAOglI
5G."CC
H%/54%'
s%7bCL
-LR+-L"
wglAOglI
7DKCXQ
5G."CC
-L]'-L
-Ly9I%
LT)-L"
-LS=nC
LR:-L\
wglAOglI
5G."CC
-L]'-L
-L\-Ld
-LS5-LR
wglAOglI
7KKCXQ
-LS!-LR
-LS!-LR
-LS!-LR
LS#-L"
KC'4HC
KCS!Ip
@kKCSI
5>OZ5^;;
\A>K]O
}OPlCI
5!UTC{
\A>K]O
%1:?ZlCy
J7d5>O
w*K7hG
5!UTC{
5!UTC{
5!UTC{
?@B!Ip
\A>K]O
[)J5>O
[)J5>O
5!UTC{
w*K7/O
!CZ5>[
!AR!Lp
BK"A@
5!UTC{
>c1:5_
5>OZ"'
)*5>K`
)J5>S`5
[)k5>K
KC\5>_]
[)o5>K
KC\5>_]
[)S5>K
[)G5>K
[)R5>K
5>WZ#bF
6*5>_\
6*5>_\
[)g5>K
!CZ"'I
O*J)B#
O"!OUA
w2J6%A
w2J6!A
[5>WZG
!\"lX
11?D]5^W;
n11?D]5^W;
!CZ"Iq
!l]"aw
!]"Mw
>DlI0A0
G2AlAJ
K%10<t
5!UTC{
kCZ5>O\
<?D\5^
U6*A>O3
Gt5>KY
?QlI6KV
KCY5=G
\A>O]5>K
I)J5>K
G:AlAJ
<?D\5^
G6-zW2?V
5!JTC{
5!BbJJC
J!cZ"5
KCY5=K
JKClCH
O"!BZ"e
O"!BZ"
O"!CZ"
O"!AZ"
4A>K3t
3B4bBA
O&!BZ"
O&!AZ"]
O&!BZ"
O&!BZ"
KC95-z4
\A>K]"F5
ZG2AlAJ@
I6hI0
>P\"{@
+Tp?6F
+Tp?6F
?O1=>M
KC]uKA
K7yI6O
G3B115
3S7.KC
>JlI6KU
>JlI6KU
5!UTC{
5?@H!Ip
?@K!Ip
KCZ"ba
5KC["f
GlqtPlC
G6SI6K
<>J]"2S
<5N\5>S
5HZ5>[
Z5>[\5>S
!BY"]G
5!OTC{
K7#J0A0
5!OTC{p
ImCSAI
ImCSAI
!~UAC%3
[5<GX"M
>n\J2B
5!iTC{
5!UTC{
5>_Z5>W\"
O]A6K12?e\A>S
AMxO2>O
OxO6>G9
wglAOglI
-L"2-Ly
KC]5=K
?DJJwK
O6!\Z"~C
139IHI
6WMAg
KC7:DC
J?lK6K
KCZ~ZCh~ZC|~ZC
|ZC"|ZC4|ZCX|ZCb|ZCp|ZC"wZC
vZCvvZCzvZCnvZCPvZCBvZC2vZC
rZC"rZCHrZCRrZCfrZCtrZC
sZC$sZCJsZCRsZClsZCvsZC
pZC&pZC2pZCNpZC\pZCbpZCppZC
qZC8qZCHqZC\qZCfqZC
vZC.vZC2wZC
KCV}ZC@}ZC4}ZC }ZC
}ZCf}ZC
DiDKQ
PCW_G2
'UYrS2
xDTGqrm|
WXv7^Pz
Q\t5^~
[VKj|Z
o37B3/p
7bBYZa
HyZbAd`
T&aD4d
)c|@Y
B'AiyJn
"1yF,&~
$,xN(&c
,r:I.;zI8*dI(,yI?"dN*0c
"-bN(,y
.;zN&,n
.&n5KCc
90oO',}
? b4M$g
&"~5KC
23o5KC
*1~5KCzo
$'o5KC
a;bQy(
D1\D%l
|RyY\;%T~
r7TSw~
|3Z5M.
t-|K<xY
:[3&|4{U?]
t,>X{~
8=|!Lh
*O|+ne)=3d~
T'/SB~
Kw,jF|
KR+JX|{R
.Z_|TsP
K^,:_|
Ki>JS|h
KM3jR|
K70:R|M
K/B*W|
K6[jU|
T| gA2}0
m?Jj|WA
a<bj|f@h]
WIbh|#t9tS
K$CZo|
n[jn|V
K]RBm|]
KPQ"m|
|rX{_c9
Bw+0t
|0f=E
UDl<z~
|sQ~09
,wz;}~
Q:5#T~
|xj3a)5y~
fbs8j~
|RyY\;%T~
Q>[OMKCf
Vd37tu
IC;aB.
|1<M{W
&T$s8|&~b
&T$s8|&~b
|1<M{W
RImIIn
z*|!;
KCV_2\D
z*|!;
X3x|o)
}RImIIn
|k h4c
|DH"!p
|RDkVa
|RlvWm
a7)'_~
|8`gSvM
|gk)9K
|ZT}cn
|;GR{e
?3tvbz}
CC:HCC:?CC[3CC
JCzOJCILJCgLJCMMJC
FJC}GJC
|JCT}JC
@ICsAIC
IHC'bHC
gHCudHC
'HCw?HC
*OCy'OC
JNCgbNC&aNC
QMCJTMC
iMC,bMCZbMC
bMCifMC
LCW#LCl LC
:LCJ8LCJ>LC
KCV^ZC
KCj^ZC
KCn^ZC
KCb^ZC
KCz^ZC
KC"xZC"
KCZxZC
KCnxZC
KCZ~ZC
9CR3ZC
KC"iZC
bZC**KCj*KC
+KCJ+KC
(KCJ(KC
)KCJ)KC
.KCJ.KC
/KC:/KCz/KC
,KCZ,KC
-KCJ-KC
"KCJ"KC
"KC:#KC
KCJ KC
!KCJ!KC
&KCJ&KC
'KCJ'KC
$KCJ$KC
%KCJ%KCz%KC
%KC*:KCZ:KC
;KC:;KCj;KC
;KC*8KCZ8KC
9KCj9KC
9KCJ>KCj>KC
>KC*?KCZ?KC
?KC*<KCZ<KC
=KC:=KCZ=KC
=KC*2KCZ2KCz2KC
3KC:3KC
0KC:0KCj0KC
0KC*1KCZ1KC
6KCZ6KC
7KCZ7KC
4KCZ4KC
5KCZ5KC
JC/`ZC8`ZCJ`ZCA`ZC\`ZCi`ZCz`ZCp`ZC
aZC"aZC>aZCHaZCGaZCPaZCmaZC|aZC
fZC*fZC fZC<fZCHfZCZfZCQfZClfZCyfZC
gZC&gZC0gZCOgZCXgZCUgZCfgZCqgZC
dZC dZC2dZCLdZC\dZCkdZCddZCwdZC
eZC*eZC$eZC3eZCLeZC[eZCTeZCgeZCpeZC
zZC+zZC$zZC1zZCOzZC[zZCSzZCizZC`zZCyzZCvzZC
{ZC.{ZC${ZC2{ZCN{ZCG{ZCR{ZCj{ZC`{ZC{{ZCp{ZC
8CnxZC
KCZ~ZCh~ZC|~ZC
|ZC"|ZC4|ZCX|ZCb|ZCp|ZC"wZC
vZCvvZCzvZCnvZCPvZCBvZC2vZC
rZC"rZCHrZCRrZCfrZCtrZC
sZC$sZCJsZCRsZClsZCvsZC
pZC&pZC2pZCNpZC\pZCbpZCppZC
qZC8qZCHqZC\qZCfqZC
vZC.vZC2wZC
KCV}ZC@}ZC4}ZC }ZC
}ZCf}ZC
KCJ4KC
KCK4KC
w2K7qA
<?xml version='1.0' encoding='UTF-8' standalone='yes'?>
<assembly xmlns='urn:schemas-microsoft-com:asm.v1' manifestVersion='1.0'>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v3">
<security>
<requestedPrivileges>
<requestedExecutionLevel level='asInvoker' uiAccess='false' />
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
0!0%01070E0Z0d0k0x0|0
<E=]=t=z=
>0>Q>i>
3G4j4(5F5r5
6)6/6;6J6R6
1!262M2W2w4
5#6+6[6
>D>d>j>
0/1O1^1
2%2E2R2i2s2|2
2#303M3j3z3
7W8j8v8
8*9O9\9
;-<e<l<|<
==*=K=a=
3I3d3w3
4464e4s4
5+5K5d5{5
5R7X7_7f7k7q7w7|7
8!8&8,82878=8C8H8N8T8Y8_8e8j8p8v8{8
9 9%9+91969<9B9G9M9S9X9^9d9i9o9u9z9
::):6:A:T:\:l:~:
<(<?<E<K<Q<W<]<c<x<
=+=S=e=
>$>)>:>@>E>P>Z>a>g>q>
?!?-?;?@?F?O?V?a?g?n?w?
001[1p1u1z1
5!565?5n5w5
8*888>8D8J8P8V8]8d8k8r8y8
9+9:9C9P9f9
:#:(:;:O:T:g:
1"1&1*1.12161:1>1B1F1
4[4`4d4h4l4
111M1W1a1o1
?+?K?Y?`?f?
1/1A1l1v1
272A2M2R2W2r2|2
6$626B6W6n6
7#7>:F:M:
=->1>5>9>=>A>E>I>
@3G3l3p3t3x3|3
=0=K=V=
>4?G?P?]?l?
021:1D1M1^1p1
192G2P2
5'5Y5`5~6
7/7J7_7d7n7s7~7
; ;:;s;
< <1<6<D<R<Y<a<y<
<!=l=x=}=
4g5B6I6w6~6
7.7L7s7
7848F8S8l8}8
8M9T9[9b9o9
;#;O;u;
= =%=*=:=?=D=i=
='>0>h>
>,?P?`?e?j?
0"0'0E0T0_0d0i0
12171B1i1{1
6&6Z6}6
:V:x;/=9=\=f=
8,9>9D9U;\;
6-747;7B7\7k7u7
7*8R8A:d:
;T;];a;g;k;q;u;
1)1:1H1S1
3U4\4f4
6:6B6k6r6
8.8@8R8d8v8
>B>Y>y>
286>7F7}7
373D3t3
?&?>?D?P?o?u?
1:1B1_1o1{1
3G3d3x3
5F6f6v6
9-9X9s9
4f7k7}7
>!>>>[>
0 1=1g1
3 3$3,3034383<3@3D3X3\3`3d3h3
4l4p4t4x4|4
5 5$5(5,5054585<5@5D5H5L5P5T5X5\5`5d5h5l5p5t5x5|5
6 6$6(6@6D6H6L6P6T6X6\6`6t6x6|6
7 7$7(7l:t:|:
;$;,;4;<;D;L;T;\;d;l;t;|;
<$<,<4<<<D<L<T<\<d<l<t<|<
d2h2l2T7X7\7`7d7h7p7x7
8 8(80888@8H8P8X8`8h8p8x8
9 9(90989@9H9P9X9`9h9p9x9
: :(:0:8:@:H:P:X:`:h:p:x:
7 7,747<7@7D7H7L7
>P>T>X>\>`>d>h>l>p>t>x>|>
? ?$?(?,?0?4?8?<?@?D?H?L?P?T?X?\?`?d?h?l?p?t?x?|?
3\9d9l9t9|9
:$:,:4:<:D:L:T:\:d:l:t:|:
;$;,;4;<;D;L;T;\;d;l;t;|;
<$<,<4<<<D<L<T<\<d<l<t<|<
=$=,=4=<=D=L=T=\=d=l=t=|=
>$>,>4><>D>L>T>\>d>l>t>|>
?$?,?4?<?D?L?T?\?d?l?t?|?
0$0,040<0D0L0T0\0d0l0t0x:
; ;(;0;8;@;H;P;X;`;h;p;x;
< <(<0<8<@<H<P<X<`<h<p<x<
= =(=0=8=@=H=P=X=`=h=p=x=
> >(>0>8>@>H>P>X>`>h>p>x>
? ?(?0?8?@?H?P?X?`?h?p?x?
0 0(00080@0H0P0X0`0h0p0x0
1 1(10181@1H1P1X1`1h1p1x1
?$?,?4?<?D?L?T?\?d?l?
0@1D1H1L1d1h1x1|1
2 282H2L2\2`2d2l2
3,3034383<3D3\3l3p3
4 4$44484<4D4\4l4p4
5$5<5L5P5`5d5l5
6$6(6,60686P6`6d6l6
7,707@7D7L7d7t7x7
8 8$8(808H8X8\8l8p8t8|8
9,9<9@9P9T9X9\9d9|9
:(:,:<:@:D:L:d:t:x:
;$;(;,;4;L;\;`;p;t;x;
<4<D<H<X<\<`<h<
=(=,=<=@=D=L=d=t=x=
>0>@>D>L>d>t>x>
? ?$?(?,?4?L?\?`?p?t?|?
5,545L5T5\5d5t5
5 6,646T6x6
7$7,70747<7P7X7l7t7
8$8,84888@8T8\8d8l8p8x8
949@9`9l9
:4:@:h:x:
; ;@;L;l;t;|;
<(<l<x<
=4=8=T=X=x=
> ><>@>`>|>
? ?@?`?
0 0@0`0
1 1@1`1
0l0p0x0
082h2x2
2 8$8(8,8084888<8@8D8P8T8X8\8`8d8h8l8
: :@:`:
C:\Windows\Microsoft.NET\Framework\v4.0.30319\AppLaunch.exe
@kernel32.dll
api-ms-win-core-synch-l1-2-0.dll
Aapi-ms-win-core-fibers-l1-1-1
api-ms-win-core-synch-l1-2-0
kernel32
api-ms-
(null)
mscoree.dll
Aapi-ms-win-core-datetime-l1-1-1
api-ms-win-core-file-l1-2-2
api-ms-win-core-localization-l1-2-1
api-ms-win-core-localization-obsolete-l1-2-0
api-ms-win-core-processthreads-l1-1-2
api-ms-win-core-string-l1-1-0
api-ms-win-core-sysinfo-l1-2-1
api-ms-win-core-winrt-l1-1-0
api-ms-win-core-xstate-l2-1-0
api-ms-win-rtcore-ntuser-window-l1-1-0
api-ms-win-security-systemfunctions-l1-1-0
ext-ms-win-ntuser-dialogbox-l1-1-0
ext-ms-win-ntuser-windowstation-l1-1-0
advapi32
api-ms-win-appmodel-runtime-l1-1-2
user32
ext-ms-
Sunday
Monday
Tuesday
Wednesday
Thursday
Friday
Saturday
January
February
August
September
October
November
December
MM/dd/yy
dddd, MMMM dd, yyyy
HH:mm:ss
Aja-JP
((((( H
zh-CHS
az-AZ-Latn
uz-UZ-Latn
kok-IN
syr-SY
div-MV
quz-BO
sr-SP-Latn
az-AZ-Cyrl
uz-UZ-Cyrl
quz-EC
sr-SP-Cyrl
quz-PE
smj-NO
bs-BA-Latn
smj-SE
sr-BA-Latn
sma-NO
sr-BA-Cyrl
sma-SE
sms-FI
smn-FI
zh-CHT
az-az-cyrl
az-az-latn
bs-ba-latn
div-mv
kok-in
quz-bo
quz-ec
quz-pe
sma-no
sma-se
smj-no
smj-se
smn-fi
sms-fi
sr-ba-cyrl
sr-ba-latn
sr-sp-cyrl
sr-sp-latn
syr-sy
uz-uz-cyrl
uz-uz-latn
zh-chs
zh-cht
CONOUT$
Antivirus Signature
Bkav W32.AIDetectMalware
Lionic Trojan.Win32.Stealer.12!c
tehtris Clean
MicroWorld-eScan Trojan.GenericKD.68369537
FireEye Generic.mg.2eb21acbab653f90
CAT-QuickHeal TrojanSpy.Stealer
McAfee Artemis!2EB21ACBAB65
Malwarebytes Trojan.Crypt
VIPRE Trojan.GenericKD.68369537
Sangfor Trojan.Win32.Save.a
K7AntiVirus Trojan ( 005a93021 )
BitDefender Trojan.GenericKD.68369537
K7GW Trojan ( 005a93021 )
CrowdStrike win/malicious_confidence_100% (W)
BitDefenderTheta AI:Packer.4E557A0A1D
VirIT Trojan.Win32.Genus.SJD
Cyren W32/ABTrojan.RIEV-7890
Symantec Trojan.Whispergate
Elastic malicious (high confidence)
ESET-NOD32 a variant of Win32/GenKryptik.GMGP
APEX Malicious
Paloalto Clean
ClamAV Clean
Kaspersky HEUR:Trojan-Spy.Win32.Stealer.gen
Alibaba TrojanSpy:Win32/Stealer.0c4d13ef
NANO-Antivirus Trojan.Win32.Stealer.jxpmxn
ViRobot Clean
Rising Trojan.Generic@AI.100 (RDML:TwpUDTHxJ+B8pA4e7LekxQ)
Emsisoft Trojan.GenericKD.68369537 (B)
Baidu Clean
F-Secure Clean
DrWeb Trojan.DownLoader45.63382
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition BehavesLike.Win32.Generic.wz
Trapmine malicious.high.ml.score
CMC Clean
Sophos Mal/Generic-S
Ikarus Trojan.Win32.Krypt
GData Trojan.GenericKD.68369537
Jiangmin Clean
Webroot W32.Trojan.Gen
Google Detected
Avira Clean
MAX malware (ai score=88)
Antiy-AVL Trojan/Win32.Sabsik
Gridinsoft Trojan.Heur!.02092021
Xcitium Malware@#2gtiotiewmcc
Arcabit Trojan.Generic.D4133C81
SUPERAntiSpyware Clean
ZoneAlarm HEUR:Trojan-Spy.Win32.Stealer.gen
Microsoft Trojan:Win32/Redline.GNS!MTB
Cynet Malicious (score: 100)
AhnLab-V3 Malware/Win.Injector.C5462112
Acronis Clean
VBA32 BScope.TrojanPSW.RedLine
ALYac Trojan.GenericKD.68369537
TACHYON Clean
DeepInstinct MALICIOUS
Cylance unsafe
Panda Trj/Chgt.AD
Zoner Clean
TrendMicro-HouseCall TROJ_GEN.R002H09GQ23
Tencent Malware.Win32.Gencirc.10bf0e0b
Yandex Trojan.GenKryptik!O7swy7lEpns
SentinelOne Clean
MaxSecure Trojan.Malware.121218.susgen
Fortinet W32/Injector.ETBS!tr
AVG Win32:PWSX-gen [Trj]
Cybereason malicious.bab653
Avast Win32:PWSX-gen [Trj]
No IRMA results available.