Static | ZeroBOX

PE Compile Time

2023-07-28 13:14:46

PE Imphash

b001a6ca19e5bf2daccfb9e23b68d132

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x0002577a 0x00025800 6.67785644583
.rdata 0x00027000 0x0000ed20 0x0000ee00 5.52117032918
.data 0x00036000 0x00001e40 0x00001000 3.23784412747
.rsrc 0x00038000 0x000001e0 0x00000200 4.71229819329
.reloc 0x00039000 0x00002254 0x00002400 6.44334644683

Resources

Name Offset Size Language Sub-language File type
RT_MANIFEST 0x00038060 0x0000017d LANG_ENGLISH SUBLANG_ENGLISH_US XML 1.0 document text

Imports

Library KERNEL32.dll:
0x427000 HeapCreate
0x427004 HeapAlloc
0x427008 CreateFileW
0x42700c HeapSize
0x427010 GetProcessHeap
0x427014 SetStdHandle
0x427024 GetOEMCP
0x427028 GetACP
0x42702c GetLastError
0x427030 WideCharToMultiByte
0x427040 SetLastError
0x427048 SwitchToThread
0x42704c TlsAlloc
0x427050 TlsGetValue
0x427054 TlsSetValue
0x427058 TlsFree
0x427060 GetModuleHandleW
0x427064 GetProcAddress
0x427068 EncodePointer
0x42706c DecodePointer
0x427070 MultiByteToWideChar
0x427074 CompareStringW
0x427078 LCMapStringW
0x42707c GetLocaleInfoW
0x427080 GetStringTypeW
0x427084 GetCPInfo
0x427090 GetCurrentProcess
0x427094 TerminateProcess
0x4270a0 GetCurrentProcessId
0x4270a4 GetCurrentThreadId
0x4270a8 InitializeSListHead
0x4270ac IsDebuggerPresent
0x4270b0 GetStartupInfoW
0x4270b4 RtlUnwind
0x4270b8 RaiseException
0x4270bc FreeLibrary
0x4270c0 LoadLibraryExW
0x4270c4 GetStdHandle
0x4270c8 WriteFile
0x4270cc GetModuleFileNameW
0x4270d0 ExitProcess
0x4270d4 GetModuleHandleExW
0x4270d8 GetCommandLineA
0x4270dc GetCommandLineW
0x4270e0 HeapFree
0x4270e4 IsValidLocale
0x4270e8 GetUserDefaultLCID
0x4270ec EnumSystemLocalesW
0x4270f0 GetFileType
0x4270f4 CloseHandle
0x4270f8 FlushFileBuffers
0x4270fc GetConsoleOutputCP
0x427100 GetConsoleMode
0x427104 ReadFile
0x427108 GetFileSizeEx
0x42710c SetFilePointerEx
0x427110 ReadConsoleW
0x427114 HeapReAlloc
0x427118 FindClose
0x42711c FindFirstFileExW
0x427120 FindNextFileW
0x427124 IsValidCodePage
0x427128 WriteConsoleW
Library WININET.dll:
0x427130 InternetOpenUrlW
0x427134 InternetReadFile
0x427138 InternetCloseHandle
0x42713c InternetOpenW
Library WS2_32.dll:
0x427144 WSACleanup

!This program cannot be run in DOS mode.
c)<vf(P
b)#vf(I
vg(_vf(
vf(Rich
`.rdata
@.data
@.reloc
WPhX4C
D$$j@P
D$$j@P
D$ j@P
D$ j@P
tG9uCj
YYhdsB
9E$WWV
t,WW9}
QQSVWd
tH9] uC
u PWQR
j<h NC
URPQQh
;t$,v-
UQPXY]Y[
PPPPPPPP
<ItC<Lt3<Tt#<h
A<lt'<tt
<ItC<Lt3<Tt#<h
A<lt'<tt
8^8tb9^4~]
tb9^4~]
PRRRRR
PVVVVV
PVVVVV
ARPRQh
jYjf
uSSSSj
35h`C
SWt@jU
_t^PVj@
u/j,Xf;
35h`C
M,j"^QRRRRR
Vj0XPW
M$j"^QRRRRR
j"[VWWWW
PVVVVV
PVVVVV
PWWWWW
D8(Ht'
D8(HtU
D8(Ht5F
PVVVVV
[PVVVVV
j"[WVVVV
PVVVVV
_PSSSSS
j"_VSSSS
WVVVVV
PVSRSQV
PPPPPWV
PP9E uPPSWP
f9:t!V
QQSVj8j@
C PjPW
C$PjQW
C*PjTW
C+PjUW
C,PjVW
C-PjWW
C.PjRW
C/PjSW
CHPjPW
CLPjQW
tl=`aC
u{9^\t/
NX9^`t1
u2Vj@hh
9C`u99C\t4
u29K\t-
F95dvC
^PQQQQQ
E ^PQQQQ
CY<u
PPPPPPPP
unknown error
bad allocation
invalid random_device value
address family not supported
address in use
address not available
already connected
argument list too long
argument out of domain
bad address
bad file descriptor
bad message
broken pipe
connection aborted
connection already in progress
connection refused
connection reset
cross device link
destination address required
device or resource busy
directory not empty
executable format error
file exists
file too large
filename too long
function not supported
host unreachable
identifier removed
illegal byte sequence
inappropriate io control operation
interrupted
invalid argument
invalid seek
io error
is a directory
message size
network down
network reset
network unreachable
no buffer space
no child process
no link
no lock available
no message available
no message
no protocol option
no space on device
no stream resources
no such device or address
no such device
no such file or directory
no such process
not a directory
not a socket
not a stream
not connected
not enough memory
not supported
operation canceled
operation in progress
operation not permitted
operation not supported
operation would block
owner dead
permission denied
protocol error
protocol not supported
read only file system
resource deadlock would occur
resource unavailable try again
result out of range
state not recoverable
stream timeout
text file busy
timed out
too many files open in system
too many files open
too many links
too many symbolic link levels
value too large
wrong protocol type
FlsAlloc
FlsFree
FlsGetValue
FlsSetValue
InitializeCriticalSectionEx
InitOnceExecuteOnce
CreateEventExW
CreateSemaphoreW
CreateSemaphoreExW
CreateThreadpoolTimer
SetThreadpoolTimer
WaitForThreadpoolTimerCallbacks
CloseThreadpoolTimer
CreateThreadpoolWait
SetThreadpoolWait
CloseThreadpoolWait
FlushProcessWriteBuffers
FreeLibraryWhenCallbackReturns
GetCurrentProcessorNumber
CreateSymbolicLinkW
GetCurrentPackageId
GetTickCount64
GetFileInformationByHandleEx
SetFileInformationByHandle
GetSystemTimePreciseAsFileTime
InitializeConditionVariable
WakeConditionVariable
WakeAllConditionVariable
SleepConditionVariableCS
InitializeSRWLock
AcquireSRWLockExclusive
TryAcquireSRWLockExclusive
ReleaseSRWLockExclusive
SleepConditionVariableSRW
CreateThreadpoolWork
SubmitThreadpoolWork
CloseThreadpoolWork
CompareStringEx
GetLocaleInfoEx
LCMapStringEx
0123456789abcdefghijklmnopqrstuvwxyz
0123456789abcdefghijklmnopqrstuvwxyz
bad array new length
bad exception
__based(
__cdecl
__pascal
__stdcall
__thiscall
__fastcall
__vectorcall
__clrcall
__eabi
__swift_1
__swift_2
__ptr64
__restrict
__unaligned
restrict(
delete
operator
`vftable'
`vbtable'
`vcall'
`typeof'
`local static guard'
`string'
`vbase destructor'
`vector deleting destructor'
`default constructor closure'
`scalar deleting destructor'
`vector constructor iterator'
`vector destructor iterator'
`vector vbase constructor iterator'
`virtual displacement map'
`eh vector constructor iterator'
`eh vector destructor iterator'
`eh vector vbase constructor iterator'
`copy constructor closure'
`udt returning'
`local vftable'
`local vftable constructor closure'
new[]
delete[]
`omni callsig'
`placement delete closure'
`placement delete[] closure'
`managed vector constructor iterator'
`managed vector destructor iterator'
`eh vector copy constructor iterator'
`eh vector vbase copy constructor iterator'
`dynamic initializer for '
`dynamic atexit destructor for '
`vector copy constructor iterator'
`vector vbase copy constructor iterator'
`managed vector copy constructor iterator'
`local static thread guard'
operator ""
operator co_await
Type Descriptor'
Base Class Descriptor at (
Base Class Array'
Class Hierarchy Descriptor'
Complete Object Locator'
(null)
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
[aOni*{
~ $s%r
@b;zO]
v2!L.2
CorExitProcess
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
AreFileApisANSI
EnumSystemLocalesEx
GetDateFormatEx
GetTimeFormatEx
GetUserDefaultLocaleName
IsValidLocaleName
LCIDToLocaleName
LocaleNameToLCID
AppPolicyGetProcessTerminationMethod
SystemFunction036
NAN(SNAN)
nan(snan)
NAN(IND)
nan(ind)
Sunday
Monday
Tuesday
Wednesday
Thursday
Friday
Saturday
January
February
August
September
October
November
December
MM/dd/yy
dddd, MMMM dd, yyyy
HH:mm:ss
_hypot
_nextafter
1#QNAN
1#SNAN
]vQ<)8
|)P!?Ua0
Eb2]A=
u?^p?o4
y1~?|"
?x+s7
?5Od%
?|I7Z#
>,'1D=
?g)([|X>=
~U`?K
:h"?bC
@H#?43
Ax#?uN}*
r7Yr7=
F0$?3=1
H`$?h|
&?~YK|
sU0&?W
<8bunz8
?#%X.y
F||<##
<@En[vP
b<log10
?5Wg4p
%S#[k=
"B <1=
?Unknown exception
bad cast
bad locale name
iostream
iostream stream error
ios_base::badbit set
ios_base::failbit set
ios_base::eofbit set
invalid stoi argument
stoi argument out of range
f'(x) at x =
Integral of f(x) from
abcdefghijklmnopqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVWXYZ0123456789
.nasongle.t34gs1x.top/cc.txt
http://
invalid string position
string too long
.text$di
.text$mn
.text$x
.text$yd
.idata$5
.00cfg
.CRT$XCA
.CRT$XCAA
.CRT$XCC
.CRT$XCL
.CRT$XCZ
.CRT$XIA
.CRT$XIAA
.CRT$XIAC
.CRT$XIC
.CRT$XIZ
.CRT$XPA
.CRT$XPX
.CRT$XPXA
.CRT$XPZ
.CRT$XTA
.CRT$XTZ
.rdata
.rdata$r
.rdata$sxdata
.rdata$zzzdbg
.rtc$IAA
.rtc$IZZ
.rtc$TAA
.rtc$TZZ
.xdata$x
.idata$2
.idata$3
.idata$4
.idata$6
.data$r
.rsrc$01
.rsrc$02
HeapCreate
HeapAlloc
KERNEL32.dll
InternetOpenUrlW
InternetOpenW
InternetCloseHandle
InternetReadFile
WININET.dll
WS2_32.dll
GetLastError
WideCharToMultiByte
EnterCriticalSection
LeaveCriticalSection
DeleteCriticalSection
SetLastError
InitializeCriticalSectionAndSpinCount
SwitchToThread
TlsAlloc
TlsGetValue
TlsSetValue
TlsFree
GetSystemTimeAsFileTime
GetModuleHandleW
GetProcAddress
EncodePointer
DecodePointer
MultiByteToWideChar
CompareStringW
LCMapStringW
GetLocaleInfoW
GetStringTypeW
GetCPInfo
UnhandledExceptionFilter
SetUnhandledExceptionFilter
GetCurrentProcess
TerminateProcess
IsProcessorFeaturePresent
QueryPerformanceCounter
GetCurrentProcessId
GetCurrentThreadId
InitializeSListHead
IsDebuggerPresent
GetStartupInfoW
RtlUnwind
RaiseException
FreeLibrary
LoadLibraryExW
GetStdHandle
WriteFile
GetModuleFileNameW
ExitProcess
GetModuleHandleExW
GetCommandLineA
GetCommandLineW
HeapFree
IsValidLocale
GetUserDefaultLCID
EnumSystemLocalesW
GetFileType
CloseHandle
FlushFileBuffers
GetConsoleOutputCP
GetConsoleMode
ReadFile
GetFileSizeEx
SetFilePointerEx
ReadConsoleW
HeapReAlloc
FindClose
FindFirstFileExW
FindNextFileW
IsValidCodePage
GetACP
GetOEMCP
GetEnvironmentStringsW
FreeEnvironmentStringsW
SetEnvironmentVariableW
SetStdHandle
GetProcessHeap
HeapSize
CreateFileW
WriteConsoleW
Copyright (c) by P.J. Plauger, licensed by Dinkumware, Ltd. ALL RIGHTS RESERVED.
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
.?AVios_base@std@@
.?AV?$_Iosb@H@std@@
.?AV?$basic_ios@DU?$char_traits@D@std@@@std@@
.?AV?$basic_streambuf@DU?$char_traits@D@std@@@std@@
.?AV?$basic_ostream@DU?$char_traits@D@std@@@std@@
.?AV?$basic_filebuf@DU?$char_traits@D@std@@@std@@
.?AVcodecvt_base@std@@
.?AV?$codecvt@DDU_Mbstatet@@@std@@
.?AV_Locimp@locale@std@@
.?AVbad_alloc@std@@
.?AVinvalid_argument@std@@
.?AVlogic_error@std@@
.?AVlength_error@std@@
.?AVout_of_range@std@@
.?AVtype_info@@
.?AVbad_array_new_length@std@@
.?AVbad_exception@std@@
.?AVfailure@ios_base@std@@
.?AVruntime_error@std@@
.?AVerror_category@std@@
.?AV?$ctype@D@std@@
.?AVsystem_error@std@@
.?AV_Facet_base@std@@
.?AV_Generic_error_category@std@@
.?AU_Crt_new_delete@std@@
.?AV?$numpunct@D@std@@
.?AV_Iostream_error_category@std@@
.?AVbad_cast@std@@
.?AUctype_base@std@@
.?AVfacet@locale@std@@
.?AV_System_error@std@@
.?AVexception@std@@
.?AV?$num_put@DV?$ostreambuf_iterator@DU?$char_traits@D@std@@@std@@@std@@
<?xml version='1.0' encoding='UTF-8' standalone='yes'?>
<assembly xmlns='urn:schemas-microsoft-com:asm.v1' manifestVersion='1.0'>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v3">
<security>
<requestedPrivileges>
<requestedExecutionLevel level='asInvoker' uiAccess='false' />
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
0 0*0@0T0X0b0p0z0
272Y2o2
5R5f5r5
7d8i8n8
<8=B=G=i=
0'1,1C1e1j1
9::H:Y:
>->5>;>@>N>
4V9e9&:6:
:!;I;Y;
2/7H7q7&989&:
2 2(282S2
2"3,3I3Z3t3{3
30454;4Q4W4j4p4
5$5E5Q5n5
9$:-:<;
5 555T5
6'6C6X6e6n6s6
8?8W8]8r8
9 969g9
< =.=6=<=C=J=P=U=[=a=g=l=r=x=~=
>>$>*>0>6>;>A>G>M>R>X>^>d>i>o>u>{>
?!?'?-?3?8?>?D?J?O?U?[?a?f?l?r?x?}?
0$0*00050;0A0G0L0R0X0^0c0i0o0u0z0
1'1J1d1r1x1
3$3*30373D3
88,8f8<9O9
:2:A:T:`:p:
>!>->6>;>A>K>U>e>u>
?&?1?6?<?F?P?c?h?
0Q0Z0g0m0
2@3N3i3t3
4U4i4p4
7<9A9_9n9
=+>0>4>8><>
a7e7i7m7q7u7y7}7
9*979Y9
:7:E:K:f:
;2;C;O;
9!9>:E:j:
;';;;Q;w;
</<<<E<J<O<j<t<
=$=4=<=A=L=o=
>*?D?S?a?m?y?
0,0:0E0
1&2g3D5H5L5P5T5X5\5`5
6(8,8084888<8@8D8
6#606a6
7L7o7v7
2#6-676d6o6
6 6-646=6R6k6
<#<1<T<|<
=5=<=H=`=e=q=v=
?#?,?5?F?W?w?
0,01070<0D0J0R0
6@;F;X;c;
9$:M:]:
;(;a;v;
<<$<%>+>W>]>h>
??0?<?A?F?V?[?`?p?u?z?
0&0+000@0E0J0r0
111:1C1t1
3$333>3C3H3c3r3}3
4$4:4?4D4e4u4
4%5I5m5
6&686D6R6s6z6
8!8U8`8
<'=6=H=[=u=
>$>+>J>x>
?2?B?O?s?}?
<.=C=M=
=>.>d>|>
5A6b637Y7
899\9^:w:
;=;[;o;
40F0+1
;A<H<O<V<c<
0L0U0`0
1#1,151
44O4W4
9;:h:p:}:
<7<T<h<s<
>6?V?f?
1,1=1E1U1f1
5@5<6H6R6\6`6f6j6t8
0#0=0L0V0c0m0}0
9G;M;[;j;
="=?=G=p=w=
?!?3?E?W?i?{?
2!333E3W3i3
55'5/57519w;
0d364l4}4
94:~:D;=<
;;;B;I;l;
9":L:W:]:f:
9$:H:S:`:r:
:W;l;u;~;
0i3q3y3
414=4I4i4
6F7K7]7{7
5D5_5z5
6(6K6f6
7!7+757?7I7S7]7g7q7
L1T1X1\1`1d1h1l1p1t1x1
2 2$2(2,2024282<2@2D2H2L2P2T2X2\2`2d2h2l2p2t2x2|2
3$3(3,3034383<3@3D3H3L3P3T3X3\3h3l3p3
4$4,444<4D4L4T4\4d4l4t4|4
5$5,545<5D5L5T5\5d5l5t5|5
6$6,646<6
p2t2x2|2
4$4,444<4D4L4T4\4d4l4t4|4
5$5,545<5D5L5T5\5d5l5t5|5
6$6,646<6D6L6T6\6d6l6t6|6
7$7,747<7D7L7T7\7d7l7t7|7
8$8,848<8D8L8T8\8d8l8t8|8
9$9,949<9D9L9T9\9d9l9t9|9
:$:,:4:<:D:L:T:\:d:l:t:|:
; ;(;0;8;@;H;P;X;`;h;p;x;
< <(<0<8<@<H<P<X<`<h<p<x<
= =(=0=8=@=H=P=X=`=h=p=x=
> >(>0>8>@>H>P>X>`>h>p>x>
? ?(?0?8?@?H?P?X?`?h?p?x?
0 0(00080@0H0P0X0`0h0p0x0
1 1(10181@1H1P1X1`1h1p1x1
4$4(4,4044484T4x4|4
6 6$6(6,6064686<6@6D6H6L6P6T6X6\6`6d6h6l6p6t6x6|6
5 5$5(5,5054585<5@5D5H5L5P5T5X5\5`5d5h5l5p5t5x5|5
< <$<(<,<0<4<8<<<@<D<H<L<P<T<X<\<`<d<h<l<p<t<x<|<
= =$=(=,=0=4=8=<=@=D=H=L=P=T=X=\=`=d=h=l=p=
1$1,141<1D1L1T1\1d1l1t1|1
3T4X4\4`4h4t4
5(545@5L5X5d5p5|5
6$606<6H6T6`6l6x6
7 7,787D7P7\7h7x7
8 8,888D8P8\8h8t8
42<2D2L2T2\2d2l2t2|2
3$3,343<3D3L3T3\3d3l3t3|3
4$4,444<4D4L4T4\4d4l4t4|4
5$5,545<5D5L5T5\5d5l5t5|5
6$6,646<6D6L6T6\6d6l6t6|6
7$7,747<7D7L7T7\7d7l7t7|7
8$8,848<8D8L8T8\8d8l8t8|8
9$9,949<9D9L9P9X9`9h9p9x9
: :(:0:8:@:H:P:X:`:h:p:x:
; ;(;0;8;@;H;P;X;`;h;p;x;
< <(<0<8<@<H<P<X<`<h<p<x<
= =(=0=8=@=H=P=X=`=h=p=x=
> >(>0>8>@>H>P>X>`>h>p>x>
? ?(?0?8?@?H?P?X?`?h?p?x?
0 0(00080@0H0P0X0`0h0
d5h5p5
6,6<6@6H6`6p6t6
70747L7\7`7p7t7x7|7
8,8<8@8P8T8X8\8`8d8l8
9$94989H9L9P9X9p9
: :$:4:8:<:@:H:`:p:t:
; ;$;,;D;T;X;\;`;d;h;p;
<,<0<H<L<P<T<\<t<x<
= =4=8=H=L=P=T=\=d=|=
> >$>,>D>T>d>t>x>|>
?,?0?8?P?`?d?l?p?t?
4 4(40484h4
5$5,585X5`5h5x5
6 6@6L6l6x6
7$7,747<7D7P7t7|7
708@8L8l8t8|8
9 9(909<9\9d9l9t9|9
:(:0:8:D:L:
;(;H;T;t;
<,<8<X<`<h<l<t<
=$=,=4=8=<=D=X=t=x=
>8>@>D>T>x>
?0?L?P?p?
000P0p0
1<1@1`1
2 2@2`2
3 3@3`3
4 4@4`4
5$585@5T5\5`5h5p5x5
`1d1h1l1p1t1x1|1
1 2P2`2p2
<0<T<p<
=4=T=x=
ekernel32.dll
zh-CHS
az-AZ-Latn
uz-UZ-Latn
kok-IN
syr-SY
div-MV
quz-BO
sr-SP-Latn
az-AZ-Cyrl
uz-UZ-Cyrl
quz-EC
sr-SP-Cyrl
quz-PE
smj-NO
bs-BA-Latn
smj-SE
sr-BA-Latn
sma-NO
sr-BA-Cyrl
sma-SE
sms-FI
smn-FI
zh-CHT
az-az-cyrl
az-az-latn
bs-ba-latn
div-mv
kok-in
quz-bo
quz-ec
quz-pe
sma-no
sma-se
smj-no
smj-se
smn-fi
sms-fi
sr-ba-cyrl
sr-ba-latn
sr-sp-cyrl
sr-sp-latn
syr-sy
uz-uz-cyrl
uz-uz-latn
zh-chs
zh-cht
Bapi-ms-win-core-fibers-l1-1-1
api-ms-win-core-synch-l1-2-0
kernel32
api-ms-
ext-ms-
(null)
((((( H
((((( H
(
mscoree.dll
ALC_ALL
LC_COLLATE
LC_CTYPE
LC_MONETARY
LC_NUMERIC
LC_TIME
Bapi-ms-win-core-datetime-l1-1-1
api-ms-win-core-file-l1-2-4
api-ms-win-core-file-l1-2-2
api-ms-win-core-localization-l1-2-1
api-ms-win-core-localization-obsolete-l1-2-0
api-ms-win-core-processthreads-l1-1-2
api-ms-win-core-string-l1-1-0
api-ms-win-core-sysinfo-l1-2-1
api-ms-win-core-winrt-l1-1-0
api-ms-win-core-xstate-l2-1-0
api-ms-win-rtcore-ntuser-window-l1-1-0
api-ms-win-security-systemfunctions-l1-1-0
ext-ms-win-ntuser-dialogbox-l1-1-0
ext-ms-win-ntuser-windowstation-l1-1-0
advapi32
kernelbase
api-ms-win-appmodel-runtime-l1-1-2
user32
api-ms-win-core-fibers-l1-1-0
Sunday
Monday
Tuesday
Wednesday
Thursday
Friday
Saturday
January
February
August
September
October
November
December
MM/dd/yy
dddd, MMMM dd, yyyy
HH:mm:ss
american
american english
american-english
australian
belgian
canadian
chinese
chinese-hongkong
chinese-simplified
chinese-singapore
chinese-traditional
dutch-belgian
english-american
english-aus
english-belize
english-can
english-caribbean
english-ire
english-jamaica
english-nz
english-south africa
english-trinidad y tobago
english-uk
english-us
english-usa
french-belgian
french-canadian
french-luxembourg
french-swiss
german-austrian
german-lichtenstein
german-luxembourg
german-swiss
irish-english
italian-swiss
norwegian
norwegian-bokmal
norwegian-nynorsk
portuguese-brazilian
spanish-argentina
spanish-bolivia
spanish-chile
spanish-colombia
spanish-costa rica
spanish-dominican republic
spanish-ecuador
spanish-el salvador
spanish-guatemala
spanish-honduras
spanish-mexican
spanish-modern
spanish-nicaragua
spanish-panama
spanish-paraguay
spanish-peru
spanish-puerto rico
spanish-uruguay
spanish-venezuela
swedish-finland
america
britain
england
great britain
holland
hong-kong
new-zealand
pr china
pr-china
puerto-rico
slovak
south africa
south korea
south-africa
south-korea
trinidad & tobago
united-kingdom
united-states
CONOUT$
/HTTP Request
Antivirus Signature
Bkav W32.Common.EC15CA72
Lionic Trojan.Win32.Farfli.4!c
tehtris Clean
MicroWorld-eScan Trojan.GenericKD.68437282
ClamAV Clean
FireEye Generic.mg.bca6e394222e5912
CAT-QuickHeal Clean
McAfee GenericRXWG-VY!BCA6E394222E
Malwarebytes Malware.AI.4228770494
VIPRE Trojan.GenericKD.68437282
Sangfor Backdoor.Win32.Farfli.Vl7i
CrowdStrike win/malicious_confidence_100% (W)
BitDefender Trojan.GenericKD.68437282
K7GW Trojan-Downloader ( 005a992b1 )
K7AntiVirus Trojan-Downloader ( 005a992b1 )
Baidu Clean
VirIT Clean
Cyren W32/ABRisk.MTPT-5683
Symantec ML.Attribute.HighConfidence
Elastic malicious (high confidence)
ESET-NOD32 Win32/TrojanDownloader.Agent.HBY
APEX Malicious
Paloalto Clean
Cynet Malicious (score: 100)
Kaspersky HEUR:Backdoor.Win32.Farfli.gen
Alibaba Backdoor:Win32/Farfli.e2e075f4
NANO-Antivirus Trojan.Win32.Farfli.jxwlul
ViRobot Trojan.Win.Z.Agent.229376.HVA
Rising Backdoor.Farfli!8.B4 (TFE:5:feLBk2rA69L)
TACHYON Clean
Sophos Mal/Generic-S
F-Secure Trojan.TR/Dldr.Agent.ofjdi
DrWeb Trojan.Siggen11.63246
Zillya Clean
TrendMicro TROJ_GEN.R023C0XH323
McAfee-GW-Edition BehavesLike.Win32.AdwareLinkury.dh
Trapmine Clean
CMC Clean
Emsisoft Trojan.GenericKD.68437282 (B)
Ikarus Trojan.Win32.Agent
GData Trojan.GenericKD.68437282
Jiangmin Clean
Webroot W32.Trojan.Gen
Avira TR/Dldr.Agent.ofjdi
Antiy-AVL Trojan[Backdoor]/Win32.Farfli
Gridinsoft Clean
Xcitium Clean
Arcabit Trojan.Generic.D4144522
SUPERAntiSpyware Clean
ZoneAlarm HEUR:Backdoor.Win32.Farfli.gen
Microsoft Trojan:Win32/Casdet!rfn
Google Detected
AhnLab-V3 Trojan/Win.Generic.C5463615
Acronis Clean
BitDefenderTheta Gen:NN.ZexaF.36348.ouW@aGv4hRni
ALYac Trojan.GenericKD.68437282
MAX malware (ai score=84)
DeepInstinct MALICIOUS
VBA32 suspected of Trojan.Downloader.gen
Cylance unsafe
Panda Trj/Chgt.AD
Zoner Clean
TrendMicro-HouseCall TROJ_GEN.R023C0XH323
Tencent Malware.Win32.Gencirc.13eb68d8
Yandex Clean
SentinelOne Clean
MaxSecure Trojan.Malware.300983.susgen
Fortinet W32/Agent.HBY!tr.dldr
AVG Win32:BackdoorX-gen [Trj]
Cybereason malicious.15f54c
Avast Win32:BackdoorX-gen [Trj]
No IRMA results available.