Static | ZeroBOX

PE Compile Time

2023-08-29 18:31:21

PE Imphash

e88a529caf2666acedc4a4b0f2baa386

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x0001c3f8 0x0001c400 6.66459922369
.rdata 0x0001e000 0x0000c8d4 0x0000ca00 5.39909678065
.data 0x0002b000 0x00001c48 0x00001000 2.85935444491
Nomm 0x0002d000 0x00055400 0x00055400 5.95844405904
Home 0x00083000 0x00000004 0x00000200 0.0
.reloc 0x00084000 0x00001994 0x00001a00 6.53210198127

Imports

Library KERNEL32.dll:
0x41e000 EncodePointer
0x41e004 DecodePointer
0x41e018 MultiByteToWideChar
0x41e01c WideCharToMultiByte
0x41e020 LCMapStringEx
0x41e024 GetStringTypeW
0x41e028 GetCPInfo
0x41e038 GetCurrentProcess
0x41e03c TerminateProcess
0x41e044 GetCurrentProcessId
0x41e048 GetCurrentThreadId
0x41e050 InitializeSListHead
0x41e054 IsDebuggerPresent
0x41e058 GetStartupInfoW
0x41e05c GetModuleHandleW
0x41e060 CreateFileW
0x41e064 RaiseException
0x41e068 RtlUnwind
0x41e06c GetLastError
0x41e070 SetLastError
0x41e078 TlsAlloc
0x41e07c TlsGetValue
0x41e080 TlsSetValue
0x41e084 TlsFree
0x41e088 FreeLibrary
0x41e08c GetProcAddress
0x41e090 LoadLibraryExW
0x41e094 GetStdHandle
0x41e098 WriteFile
0x41e09c GetModuleFileNameW
0x41e0a0 ExitProcess
0x41e0a4 GetModuleHandleExW
0x41e0a8 GetCommandLineA
0x41e0ac GetCommandLineW
0x41e0b0 HeapFree
0x41e0b4 HeapAlloc
0x41e0b8 CompareStringW
0x41e0bc LCMapStringW
0x41e0c0 GetLocaleInfoW
0x41e0c4 IsValidLocale
0x41e0c8 GetUserDefaultLCID
0x41e0cc EnumSystemLocalesW
0x41e0d0 GetFileType
0x41e0d4 CloseHandle
0x41e0d8 FlushFileBuffers
0x41e0dc GetConsoleOutputCP
0x41e0e0 GetConsoleMode
0x41e0e4 ReadFile
0x41e0e8 GetFileSizeEx
0x41e0ec SetFilePointerEx
0x41e0f0 ReadConsoleW
0x41e0f4 HeapReAlloc
0x41e0f8 FindClose
0x41e0fc FindFirstFileExW
0x41e100 FindNextFileW
0x41e104 IsValidCodePage
0x41e108 GetACP
0x41e10c GetOEMCP
0x41e11c SetStdHandle
0x41e120 GetProcessHeap
0x41e124 HeapSize
0x41e128 WriteConsoleW

!This program cannot be run in DOS mode.
`.rdata
@.data
.reloc
4VWPQS
>FYY;t$
YY;D$8t+
>_^][3
f@fHBf
AfOIfB
:FfOt'
AfNfGf
GfOfOf@
fGIfHf#
~,9~$t
tG9uCj
tC97u?j
W9^Lt"
PPPPPWS
QQSVWd
URPQQh`
UQPXY]Y[
PVVVVV
PVVVVV
ARPRQh
jYjf
PPPPPPPP
uSSSSj
SWt@jU
_tqPVj@
PVVVVV
PWWWWW
D8(Ht'
D8(Ht5F
L:-^_[
_PVVVVV
j"_SVVVV
PVVVVV
^PSSSSS
j"^WSSSS
WVVVVV
PVSRSQV
PPPPPVW
PP9E u!PPSVP
f9:t!V
QQSVj8j@
NX9^`t1
;V\uYW
tjhH%B
u2Vj@h
9C`u99C\t4
u29K\t-
PPPPPPPP
Unknown exception
bad array new length
string too long
iostream
iostream stream error
ios_base::badbit set
ios_base::failbit set
ios_base::eofbit set
ZAtgrjtyujtyu
C:\Windows\Microsoft.NET\Framework\v4.0.30319\AppLaunch.exe
bad allocation
success
address family not supported
address in use
address not available
already connected
argument list too long
argument out of domain
bad address
bad file descriptor
bad message
broken pipe
connection aborted
connection already in progress
connection refused
connection reset
cross device link
destination address required
device or resource busy
directory not empty
executable format error
file exists
file too large
filename too long
function not supported
host unreachable
identifier removed
illegal byte sequence
inappropriate io control operation
interrupted
invalid argument
invalid seek
io error
is a directory
message size
network down
network reset
network unreachable
no buffer space
no child process
no link
no lock available
no message available
no message
no protocol option
no space on device
no stream resources
no such device or address
no such device
no such file or directory
no such process
not a directory
not a socket
not a stream
not connected
not enough memory
not supported
operation canceled
operation in progress
operation not permitted
operation not supported
operation would block
owner dead
permission denied
protocol error
protocol not supported
read only file system
resource deadlock would occur
resource unavailable try again
result out of range
state not recoverable
stream timeout
text file busy
timed out
too many files open in system
too many files open
too many links
too many symbolic link levels
value too large
wrong protocol type
unknown error
bad cast
bad locale name
0123456789abcdefghijklmnopqrstuvwxyz
0123456789abcdefghijklmnopqrstuvwxyz
bad exception
__based(
__cdecl
__pascal
__stdcall
__thiscall
__fastcall
__vectorcall
__clrcall
__eabi
__swift_1
__swift_2
__swift_3
__ptr64
__restrict
__unaligned
restrict(
delete
operator
`vftable'
`vbtable'
`vcall'
`typeof'
`local static guard'
`string'
`vbase destructor'
`vector deleting destructor'
`default constructor closure'
`scalar deleting destructor'
`vector constructor iterator'
`vector destructor iterator'
`vector vbase constructor iterator'
`virtual displacement map'
`eh vector constructor iterator'
`eh vector destructor iterator'
`eh vector vbase constructor iterator'
`copy constructor closure'
`udt returning'
`local vftable'
`local vftable constructor closure'
new[]
delete[]
`omni callsig'
`placement delete closure'
`placement delete[] closure'
`managed vector constructor iterator'
`managed vector destructor iterator'
`eh vector copy constructor iterator'
`eh vector vbase copy constructor iterator'
`dynamic initializer for '
`dynamic atexit destructor for '
`vector copy constructor iterator'
`vector vbase copy constructor iterator'
`managed vector copy constructor iterator'
`local static thread guard'
operator ""
operator co_await
operator<=>
Type Descriptor'
Base Class Descriptor at (
Base Class Array'
Class Hierarchy Descriptor'
Complete Object Locator'
`anonymous namespace'
FlsAlloc
FlsFree
FlsGetValue
FlsSetValue
InitializeCriticalSectionEx
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
CorExitProcess
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
Sunday
Monday
Tuesday
Wednesday
Thursday
Friday
Saturday
January
February
August
September
October
November
December
MM/dd/yy
dddd, MMMM dd, yyyy
HH:mm:ss
AreFileApisANSI
CompareStringEx
EnumSystemLocalesEx
GetDateFormatEx
GetLocaleInfoEx
GetTimeFormatEx
GetUserDefaultLocaleName
IsValidLocaleName
LCMapStringEx
LCIDToLocaleName
LocaleNameToLCID
AppPolicyGetProcessTerminationMethod
_hypot
_nextafter
]vQ<)8
|)P!?Ua0
Eb2]A=
u?^p?o4
y1~?|"
?x+s7
?5Od%
?|I7Z#
>,'1D=
?g)([|X>=
~U`?K
:h"?bC
@H#?43
Ax#?uN}*
r7Yr7=
F0$?3=1
H`$?h|
&?~YK|
sU0&?W
<8bunz8
?#%X.y
F||<##
<@En[vP
?5Wg4p
%S#[k=
"B <1=
.text$di
.text$mn
.text$x
.text$yd
.idata$5
.00cfg
.CRT$XCA
.CRT$XCAA
.CRT$XCC
.CRT$XCL
.CRT$XCZ
.CRT$XIA
.CRT$XIAA
.CRT$XIAC
.CRT$XIC
.CRT$XIZ
.CRT$XPA
.CRT$XPX
.CRT$XPXA
.CRT$XPZ
.CRT$XTA
.CRT$XTZ
.rdata
.rdata$r
.rdata$sxdata
.rdata$voltmd
.rdata$zzzdbg
.rtc$IAA
.rtc$IZZ
.rtc$TAA
.rtc$TZZ
.xdata$x
.idata$2
.idata$3
.idata$4
.idata$6
.data$r
.data$rs
EncodePointer
DecodePointer
EnterCriticalSection
LeaveCriticalSection
InitializeCriticalSectionEx
DeleteCriticalSection
MultiByteToWideChar
WideCharToMultiByte
LCMapStringEx
GetStringTypeW
GetCPInfo
IsProcessorFeaturePresent
UnhandledExceptionFilter
SetUnhandledExceptionFilter
GetCurrentProcess
TerminateProcess
QueryPerformanceCounter
GetCurrentProcessId
GetCurrentThreadId
GetSystemTimeAsFileTime
InitializeSListHead
IsDebuggerPresent
GetStartupInfoW
GetModuleHandleW
KERNEL32.dll
RaiseException
RtlUnwind
GetLastError
SetLastError
InitializeCriticalSectionAndSpinCount
TlsAlloc
TlsGetValue
TlsSetValue
TlsFree
FreeLibrary
GetProcAddress
LoadLibraryExW
GetStdHandle
WriteFile
GetModuleFileNameW
ExitProcess
GetModuleHandleExW
GetCommandLineA
GetCommandLineW
HeapFree
HeapAlloc
CompareStringW
LCMapStringW
GetLocaleInfoW
IsValidLocale
GetUserDefaultLCID
EnumSystemLocalesW
GetFileType
CloseHandle
FlushFileBuffers
GetConsoleOutputCP
GetConsoleMode
ReadFile
GetFileSizeEx
SetFilePointerEx
ReadConsoleW
HeapReAlloc
FindClose
FindFirstFileExW
FindNextFileW
IsValidCodePage
GetACP
GetOEMCP
GetEnvironmentStringsW
FreeEnvironmentStringsW
SetEnvironmentVariableW
SetStdHandle
GetProcessHeap
HeapSize
CreateFileW
WriteConsoleW
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
.?AVbad_array_new_length@std@@
.?AVbad_alloc@std@@
.?AVexception@std@@
.?AVruntime_error@std@@
.?AVsystem_error@std@@
.?AV_System_error@std@@
.?AVfailure@ios_base@std@@
.?AVlogic_error@std@@
.?AVlength_error@std@@
.?AVbad_cast@std@@
.?AVbad_exception@std@@
.?AVerror_category@std@@
.?AV_Iostream_error_category2@std@@
.?AVios_base@std@@
.?AV?$_Iosb@H@std@@
.?AV?$basic_ios@DU?$char_traits@D@std@@@std@@
.?AV?$basic_streambuf@DU?$char_traits@D@std@@@std@@
.?AV?$basic_ostream@DU?$char_traits@D@std@@@std@@
.?AV?$basic_filebuf@DU?$char_traits@D@std@@@std@@
.?AV_Facet_base@std@@
.?AVfacet@locale@std@@
.?AU_Crt_new_delete@std@@
.?AVcodecvt_base@std@@
.?AUctype_base@std@@
.?AV?$ctype@D@std@@
.?AV?$codecvt@DDU_Mbstatet@@@std@@
.?AV_Locimp@locale@std@@
.?AVtype_info@@
}qW6\?
SzYg=#N
c]88s<
@`08s:
~88`M`
@~788sc
`P88sc
@LeM8LL8
@`T8s0
@\`48;
@\`X8;
@`L`8;
@_`L`H8;
@_`L``8
;`L`48
c`L`48
`_`X;8
@`08L8
@`x;L(@;8
`L`X8;
`d8;LLL
`L`0;8
`L`d;8
;`L`T7
`_`d8;LLL
`L`0;8
`L`d;8
`L`0;8
`L`d;8
`L`0;8
`L`d;8
@`(8tT;
@`(8tT;
@``8aP6
`L`0;8
`L`d;8
`L`0;8
`L`d;8
`L`0;8
`L`d;8
`@_`X8;
`L`0;8
`L`0;8
`L`d;8
8;`8`P8
c`\8L;
@`H8L;8
@_Z88`8
<`\8L;
<`\8L;
<`\8L;
<`\8L;
<`\8L;
<`\8L;
<`\8L;
<`\8L;
<`\8L;
<`\8L;
<`\8L;
<`\8L;
<`\8L;
<`\8L;
<`\8L;
@\8`x8;
@\8`x8;
@\8`x8;
@\8`x8;
@\8`\8LL
<`\8L;
<`\8;L
<`\8LL
<`\8L;
<`\8;L
<`x8;8
`L`0;8
`L`d;8
`L`0;8
`L`d;8
`L`0;8
`L`d;8
@`d8L8
@`\8;_
c`d8;^_^
c`d8;^_
c`d8;^
c`d8;^
c`d8;^_^
c`d8;^_
c`d8;^
c`d8;^
c`d8;^_^
<`d8;^_
<`d8;^
<`d8;^
<`d8;^_^
<`d8;^_
<`d8;^
<`d8;^
<`d8;^_^
<`d8;^_
<`d8;^
<`d8;^
<`d8;^_^
<`d8;^_
<`d8;^
<`d8;^
<`d8;^_^
<`d8;^_
<`d8;^
<`d8;^
c`088;
`d8;^_^
<`d8;^_
<`d8;^
<`d8;^
<`d8;^_^
<`d8;^_
<`d8;^
<`d8;^
<`d8;^_^
c`d8;^_
c`d8;^
c`d8;^
c`d8;^_^
c`d8;^_
c`d8;^
c`d8;^
c`d8;^_^
<`d8;^_
<`d8;^
<`d8;^
<`d8;^_^
<`d8;^_
<`d8;^
<`d8;^
<`d8;^_^
<`d8;^_
<`d8;^
<`d8;^
<`d8;^_^
<`d8;^_
<`d8;^
<`d8;^
<`d8;^_^
<`d8;^_
<`d8;^
<`d8;^
<`d8;^_^
c`d8;^_
c`d8;^
c`d8;^
c`d8;^_^
c`d8;^_
c`d8;^
c`d8;^
c`d8;^_^
<`d8;^_
<`d8;^
<`d8;^
@`@;``;
@`x8s:
@`l8sX
@`l8sc
@`l8sd
@`l8sW
@`l8sZ
@`l8se
@`l8s(
@`l8sy
@`l8sl
@`l8sm
@`l8s0
@`l8s3
@`l8s*
@`l8sN
@`l8sI
@`l8s|
@`l;8sF
UQRER=
E<E=OE
E<LE<L
E<_E<_
E<bE<b
E<ME<M
E<fE<f
E<aE<a
VLQcD=<R=
<LQcD=<R=
~];;s<
~];;s<
E_@cY8s
E_@LCLVc
E_@LCLVc
CLV;Qc'<_
L@cL8sK
<L@cY8sK
L@cY8s
<LCLVLQLK
<KO8sE
GKR8s=
1E@8sE
<K=cb8s:
<K=8sE
=KVcOE
RQOVEVC8sY
RQOVb8s7
KDbEQ_GJED
Cc;EQCO
~=O8sb
SVLQLK
c_=;_E
<L@c\8s
LCcY8s
@LCcY8s
EL@cY8s
RJ@ORd[c_<_
8L@8s\
W{88sd
7(788s
7(788sd
@KO<E<=
@EO8se
@K=<ER=
@E=8se
@KC<E@=
@EC8se
@C<OLL8
<ObdCc:<b
@KC<EC_L
@KO8s}
@KV<EV
@KQ<EQ
cERE@E=
@<=_L8
@K<cZ=
<K:E:E<
<E:K7<E7
<K:E:E<
<E:KE<EE
<K<E<E
;^cOE<
<KRERE
<@cD8L^
@<be8O`;O
@VRb__
<`=`5~
@K@E@E=
@KRERt
@@8CLV
@K<cHE<
@KO<EO
@KOLKCLKVc}EC
LKQckEC
:_KCOED
KVEVEO
@K7OE7
@K=LK@
KCECEO
@ERZsO
@K7<ED
K@E@E=
@ERZsO
KRLK=c
K@O8E@
K=E=ER
<K@E@_
LK<c/E
LK<c/E
Op\LK<
<@LCcY<O
R@cRR_
<ca88;E
<KR8EO
<\8EOER
<K=8EOER
<\EOE=
<KCECKV8E@
KDLK7c
<KVEDE78E:EV
EDE7EDE7
ScfEDE7
88E@EQ
K<E<R{
EY@LVc
R@c7R_
<YkOLQ!B
1@<YkOLV!z
<KRERK=8EO
<K@^KCEOER
cKCE=_
<K=ECEQ
88EDE=
e{ECEQ
ScdECEQ
EVE=ED
KQEVE@'k
LK7LK:
E:8EOE@
E7ECE:
K:E:EC
Q=<4jF
<1KK88;EK
@LVc^<
{;CcdO8s
O_ka<L8s
=k8_V_QaK
K<E<;W
8_`<;_
@LCcb<O
(;L(d8
@`L`KZ8
CO`KZ;
`<`KZ;
@C;VLQc1R=
@C;VLQ
@p;@LCc7<O
<LW88`8<
<LW88`8<
@C8<sJ8
E;@LCcK<O
@LCcf<O
E;@LCcf<O
E;@LCc_<O
E;@LCc_<O
E;@LCc^<O
@LCca<O
E;@LCca<O
E;@LCc_<O
E;@LCc_<O
c@;CLVc_OR
c@;CLVc_OR
c@<CLVcKOR
@@c_8<
@@<LZi`
@CLVcLOR
cER=LE
cER=LE
@VR<L<
@VR<L<
L`_`M`
COLW8fC
8bk8_`8b
L`_`M`
8bk8_`8b
L`_`M`
k8_`8b
@kO^)<
@`8tv;
@k8^`8`
@k=^)<
88`;@LCcL<O
@LCcL<O
@LCcL<O
E;@LCc^<O
@Yk8L`O_
@LCcY<O
@Yk8L`O_
E;@LCc^<O
@Yd8_`O_
@LCcY<O
@Yd8_`O_
@@CLVcaOR
@_kD8L
@@cR<8
E;@LCcL<O
(n8`KZ;
@@<Yk88`8<;
@@<Yk88`8<;
@OLZOh
L`_`M`
Xk=<R_
@@8CLVcKOR
@;Z88`;
@;Z88`;
OLeL8O_
OLeL8O_
@@LCcx8O
OLeL8O_
@@LCcx8O
OLeL8O_
@@LCcx8O
OLeL8O_
@@LCLV<8;
@\<8;_
PZQ_V<E
@\c<=b
@@;CLVcG8O
PZV_V<=
@\c<Ob
@@LCLVLQ;K
PZQ_Q<E
@@;CLVc18O
=kV_V<=
@LCcX<O
("8`KZ8
@LCc]<O
Xk8;`;8
k8;`;8
@V<QLK
@K@<QLKCc]=EC
KVE@EV
OK<LKCc]E<EC
KQE@EQ
KCECE<
E;@LCc:<O
cV<QLK
@K=ERR
<K<LKOc
@K=ERE
KOEOE<
OK@LKOc
@KVECE
KOEOE@
@&<`5~
@KREOE
OK=LK<c
@KCE@E
K<E<E=
@KOE<R
@K@E=R
@Q=8ORb
@=8LL<O
@O8LL;
@@LCcJ<O
EL@cC8
@<;WR8
@CVLQc[R=
K<LKOLKRLK=LK@Om
cK<c}EQ
cK<ORG
@\c=<E<
@\c}ER
@\cZE@
@\c_E=
=e=<E<
@Lel<s
@Le3<s
<VRcf<8
@CVLQc
8O`^`KZ
@Le~8s
D<DODRD=D@
D<DODRD=
c@8M<L
@OL=LO
<;<^=R
K<LKO8OD
EL@;QLK
CLV;QLK
YE<LORE<
@@LCc~8O
@_k};L
@`L`KZO
@K<cHE<
@KO<EO
@K<cHE<
@KC<EC
;^cLE<
;^cLE<
@KR<EO
8L@<`KZ
@K<LK@LKCc}E@
LKVckE@
:_K@OEQ
KCECE<
@KDOED
c`L`KZ;
@cI88s
@88sp<
@8@cOL
@@<8sg<
@<8sj<
@<`KZ;
@cI88s
@8@cOL
@<`KZ8
fu@LCc^8O
~dZdZdZ
ylemk~
z5Nz5Nz
~dZdkZkem
`'k<<z
<:*x;8<
<:*x;8<
IJ&C<8
FzOVY8*I
LVb86I
}VP8I|
ZxQo8T
@eMD>8
wIDA8x}
wID;;t}
4DO;j\
%lqDd;
fr_W<R
YgS_}<
oG!M0OP
,3%M{OV
'(;anRQ
z0a RZ
KtEXm@
'(\X4@:
6WX'@~
d(s[j@E
1\]7V~
1l]EV$
6j]fV"
^3(`mV>
^3I`3V
91Sc1VD
3yrcjV
wlrcuV
dZ&Q0e
Coe Q'
l<?eQD,
?e:DCp
:I(_D0e
:I(bD0e
6D7kND
MK7kID0e
6DLk|D`
6DLk}D0e
DLkwD0e
DLkHD
D7kPD0e
uR'3xkTD
<K|kTD
RbL58]7~j
R%M58`70e
RbL58c7
RbL58(7
7ll7Cu
RbL58m7
R%M5847
58'70e
R%M58w7K
RbL58p7
R%M58s7!
RbL58g7
R%M58j7y
}Vu<Wb!N
8Iu8F}RI
ON8=(F
<|TyHu8
Z8Iu8JZ8I
}qHu<Ma
O.8=(d
\az>8=(
u8 p8I
ZxQ}=3
85\?Qe8|Tn
$:u<?(>:
uEn;=(
O 5=_>
fU<|TkG
OV<=(F
XlkfOU
58u=nI
OfR84G
fwk-fwkkawkyawk3awk
awkUawk1awk
awk)awk
VHdH0H
;TETXT
T T>TATRG:GMGXG
6}6?6[131
}b}\}*}
w9w8z7z
P(P0P5P
PnP#P8SLS
8`Hr8wHr8
Hr8oH-;
H-;`HK8
e/K8U/a
8e/K8[
!R+1K8;
4mGGZGeZ
GGZGeZ
4mGGe~ZZGZ
GGe~ZZGZ
ekeZGZ
e~eZGZ
e~kZGZ
4mGGey~ZGZ
GGey~ZGZ
4mGGe(mZGZ
GGe(mZGZ
4mGGekmZGZ
GGekmZGZ
4mGGZGZ
e~ZeGZ
ekeeGZ
e~eeGZ
e~keGZ
4mGGe~yeGZ
GGe~yeGZ
U/hU14
4mGGe(meGZ
GGe(meGZ
4mGGekmeGZ
GGekmeGZ
ekmeGZ
4mGGeGZ
eke(GZ
e~e(GZ
ek((GZ
e~k(GZ
4mGGe~y(GZ
GGe~y(GZ
4mGGe(
4mGGe(m(GZ
GGe(m(GZ
4mGG(GZ
ekZkGZ
ekekGZ
e~ekGZ
ek(kGZ
e~kkGZ
4mGGe(
4mGGek
e(mkGZ
4mGGekmkGZ
GGekmkGZ
ekZ~GZ
4mGGeke~GZ
GGeke~GZ
eke~GZ
e~e~GZ
ek(~GZ
e~k~GZ
4mGGe(
e(m~GZ
4mGG~GZ
ekZyGZ
4mGGekeyGZ
GGekeyGZ
ekeyGZ
e~eyGZ
ek(yGZ
eZkyGZ
4mGGe(
4mGGe(
4mGGek
4mGGe(myGZ
GGe(myGZ
ekZlGZ
4mGGekelGZ
GGekelGZ
ekelGZ
e~elGZ
4mGGe(lGZ
GGe(lGZ
ek(lGZ
eZklGZ
ee~lGZ
4mGGe(mlGZ
GGe(mlGZ
4mGGekZ
4mGGeZk
6zUhU1
4mGGek
4mGGe(m
4mGGekm
4mGGekZ
4mGGekZmGZ
GGekZmGZ
ekZmGZ
e~ZmGZ
4mGGek(mGZ
GGek(mGZ
e~(mGZ
e(mmGZ
4mGGmGZ
GGee(e
4mGGey~ZGe
GGey~ZGe
4mGGZGe
U/hU14
4mGGeGe
4mGGe(
4mGGee~lGe
GGee~lGe
4mGGe(
4mGGee~
4mGGe(
4mGGek
4mGGekm
GGe~yeJe
GGe~y(Je
4mGGZGe(
GGZGe(
4mGGZG(
4mGGe(
4mGGe(
4mGGZGe~
GGZGe~
4mGGZG~
4mGGZGel
GGZGel
GGee~l
4mGGZGl
4mGGZGe
4mGGZG
ING{}z
Gw5IzGz5NN}
Gz5NN}
/NhU//
GzUhU1
GzUhU1
zUhU15hhU
/d}1U/
H|{ee(k
1d}wd{
6zUhU1
6zUhU1
{U665h/
1|6U/I
GzUhU1
6zUhU1
1U6whN
1U6whN
{2UhwhN
{2UhwhN
l~{2Uh5hhU
l~{2Uh5hhU
{2Uh5hhU
66whI1
66whI1
edldZc~~
k~eml~
<aER8<R
<aEV;<
:8<8;<EV
==;<ER<
;<E];<E
eEyVV8888
;<E18<D
jq8DD7<Y
fDf:<Y
fffK<Y
DDRRaD
jq8DYEj
f8<C;<aD
;8;;EjA
88YEu=
;8DDEjA
;DDRRR
;DD;EjAR
;DDDEjA
EuMDY:
8DDE:8;8Y
L:8;8Y
b:8;8Y
::888Y
uIRRf@
uIfRR=
;D8DDO
RRa;RQ
RRa;REu
88;a;=
8EuMEuMR@
;EuMEuMRRC
EuMEuMRRRV
EuMEuMRRRRC
8EuMEuM
8EuMEuMDV
;8EuMEuMEuM@
88EuMaEuM<
;QQREu
;8QQQ<
;8<<<<
88<a<<
E]RRRRO
8E]RE]O
;E]RRR
;RRR:R<
;8RRR<
88RaR<
;@@@:@
;8@@@<
88@a@R
;8f88@
;;f;8@
8EuMfEuM@
;EuMfEuM8D
8EuMfY
;EuMfY
;QfQ8@
;VfV8@
;<f<8@
;RfR8@
;@f@8@
8fYEu=
;fYEu=
EuMfYEu=
QfYEu=
VfYEu=
<fYEu=
RfYEu=
@fYEu=
OfYEu=
=fYEu=
CfYEu=
;DfD8@
;OfO8@
;=f=8@
;CfC8@
;8VVV<
88VaV=
8DDaD<
88DaD=
;8DEjAaDC
;DDffO
DDfff<
8DDaf<
DDRRDO
DDRDD<
;aDDDEu
RDRDRRO
DDDDDV:
DDaDRRR
;8DDEu
uUaf@:
afafR:
;8OOO<
;8===<
;8CCC<
8MMRO:
88Eu9aEu9R
u-aDR:
jq8D87
jq8D8:
jq8D8K
jq8D8<
jq8D8R
;ffD8O
8aff8O:
;affD8@
88f8R:
1RD8=:
jq8R;R<Y
jq8;8R<Y
jq8;;V<Y
jq8YEj
jq8YEj
8RDR=<Y
j!@@<Y
8DfL<Y
8DfY<Y
8DfD<Y
j!8R<Y
=:bDD=
==bbD:bbRa
;bDDDR
bbD:bbRa
8bbD<:
DDEjAQ:
~dZdZdZ
ylemk~
D^|hU1
~dZdZdZ
ylemk~
OV=a=a==RRa=a
O8=R<O
==R=;O
====CC
===ROO
eEyEyEyEy;
@8DD<Y
8DDD<Y
a;RROO
DDaDR=
8aDaDEu
O8DaD=
8aDa;Eu
uqDDDDD
K8K;^Y
ffDfVY
j!dO:Y
DaDRD8a
j!WOKY
DDaDDaDD@aDRDY
DDaDRD@:
8aDDDfOOY
aDa;QY
jq8DYEj
8DD@@8DYEj
8DDeOCY
DDDDD;Y
8DDYEj
8DDOYEj
aDRDDDDO;Y
fDQO8Y
8DDOO;DEu
=CRR=CCRRCRR@a@RR
u5D=O<RaDR8RRR
;RDDEjAO
8RDEjA
R;MO^=R8=CRRCRR@aE
&@RRRR===
O8RRCORa
R8RRRR@<
yDD<O8
88<YEu=
8ffafO
ffaf<O;aDRD
88DEjARO8Eu
fDfEuMDOY
8DfYEj
8DfOYEj
8DfbO;
8DDYEj
8DfaDRDOY
;R@O;;;Y
@8R;E:
RRRRRRRR
RRRRRR
RRRRRR=
O8R@;@
88D:8;O
88D:;R
88D:Eu
88D:EuM
88D:Eu
88D:Q;O
88D:Eu
88D:<<
88D:R;O
88D:@;O
88D:O<
88D:=;O
88D:CRO8
RO8EuMEuMRY
;<YEu=
EuMRYEu=
EuMQO8YEu=
EuMEuMQY
EuMQO8YEu=
Q<YEu=
V<YEu=
<<YEu=
R<YEu=
@<YEu=
O<YEu=
=<YEu=
C<YEu=
8RDROY
O8D=@O
=QO8Eu
8Dff=O
;;R;=O
88R;RO
R8;@O<
888R;OO;
RCcODa
jq8YEj
V@8YEj
jq8YEj
uiV@8YEj
uAReODa
@8RDCY
jq8RYEj
8RD@@8RYEj
jq8YEj
8RDRf:88Y
@@8YEj
8RDR<Y
y8DfYEj
uiDfVO
j!QO8Y
j!<@8D
88RRDD8888a
jq8f8=O8
:af=O8
afaf<O
8RO;afaf
j!DCO8E
:ORbbba
<O;Rba
DRRR;<Y
DfOO;RE
@8DRDO;Y
%=MOOY
;DfffXOVY
DDDO8Y
DaDRD8a
e4z-Yf
'xriyl
X'4Q@Q@
XedZX4Q@
XedZdZdZX
0*0>0B0L0Z0d0n0z0
06225~5
6&777o7
9#9W9g9
9":/:8:?:D:L:a:y:
4$4:4n4
696N6S6
9B9N9e9
;)<H<W<z<
=8>_>k?q?
9(9=9m9
<:=B=R=|=
=#>;>N>c>s>
>#?4?;?C?Y?u?
11:1E1
4G4m4s4
5+5@5H5N5\5d5
=#=)=;=E=
=Q>[>d>
?Z?d?m?v?
0/0I0R0]0d0w0
1 101@1P1Y1}1
2/242S2b2k2x2
313:3@3S34?4I4i4
5,5@5E5X5m5
>V>n>s>
1#2W2_2q2~2
; ;$;(;,;0;4;8;<;@;D;H;
<A<U<q<|<
=Q=`=@>
<*<F<f<t<{<
=!=A=K=W=s=
>'>3>8>=>[>e>q>v>{>
?Z?a?g?
0O0=1G1T1
2G3a3p3~3
4.4;4I4W4b4
9B:G:N:t:
:7:>:i:
3?4R4{4
<@>Y>l>z>
?Q?`?i?w?
2#2<2F2
3>4Y4p4~4
8 8`8f8z8
5)6n6~6W8e:
; ;};3<{<,?
0L0U0]0
0<0j0y0
1&161C1g1n1
292`2u2
3#4+4?4K4P4U4e4j4o4
5 5%555:5?5O5T5Y5
6+6@6I6
818@8K8P8U8p8
8919G9L9Q9r9
92:V:z:
;;@;G;^;t;
20e0z0
859R9r9j:
;;;|;0<S<h=|=
>#>H>f>z>
171e2w2}2,3
?2]2h2
2:3?3D3I3R3
#0)0^0
2L2U2`2
3#3,353
66O6W6
;;<h<p<}<
>7>T>h>s>
061V1f1
3,3=3E3U3f3
5-666:6@6D6J6N6X6k6y6
8[879o9
9 :-:g:u:}:
?+?A?|?
0 0A0S0e0w0
5&585r5
576H6Y6
8Q8|8M9
>J><?r?
2V3]3g3
0&0`0o0{0
1K1T1]1f1
=F>L>[>~>
0%0*010A0O0`0x0~0
242X2c2p2
5i8q8y8
919=9I9i9
;F<K<]<{<
01<1@1D1H1L1P1T1X1\1`1l1p1t1x1|1
1$2(2,2024282@2D2H2L2P2T2X2\2`2d2
2<3@3D3H3L3P3\3d3l3t3|3
4$4,444<4D4L4T4\4d4l4t4|4
5$5,545<5D5L5T5\5d5l5t5|5
? ?$?(?,?0?4?8?<?@?D?H?L?P?T?X?\?`?d?h?l?p?t?x?|?
2 2(20282@2H2P2X2`2h2p2x2
3 3(30383@3H3P3X3`3h3p3x3
4 4(40484@4H4P4X4`4h4p4x4
5 5(50585@5H5P5X5`5
7h8p8x8|8
9 9$9(9,9094989<9@9D9H9L9P9T9X9\9`9d9h9l9p9t9x9|9
: :$:(:,:0:4:8:<:@:D:H:
4$4,444<4D4L4T4\4d4l4t4|4
6`7d7h7l7
8$808<8H8T8`8l8x8
9 9,989D9P9\9h9t9
:(:4:@:L:X:d:p:|:
;(;4;@;L;X;d;p;|;
6$6,646<6D6L6T6\6d6l6t6|6
7$7,747<7D7L7T7\7d7l7t7|7
8$8,848<8D8L8T8\8d8l8t8|8
9$9,949<9D9L9T9\9d9l9t9|9
:$:,:4:<:D:L:T:\:d:l:t:|:
;$;,;4;<;D;L;T;\;d;l;t;|;
<$<,<4<<<D<L<T<\<d<l<t<|<
7 7(70787@7H7P7X7`7h7p7x7
8 8(80888@8H8P8X8`8h8p8x8
9 9(90989@9H9P9X9`9h9p9x9
: :(:0:8:@:H:P:X:`:h:p:x:
; ;(;0;8;@;H;P;X;`;h;p;x;
< <(<0<8<@<H<P<X<`<h<p<x<
= =(=0=8=@=H=P=X=`=h=p=x=
L8P8X8
9 9$9,9D9T9X9h9l9p9x9
:,:<:@:H:`:p:t:
;(;,;0;8;P;`;d;t;x;|;
< <$<,<D<T<X<h<l<p<x<
=0=@=D=T=X=`=x=|=
> >0>4>D>H>L>T>l>|>
?,?0?4?8?@?X?h?l?t?
0 0004080<0@0D0L0d0t0x0
1 1$14181@1X1h1l1|1
606<6D6d6
7 7(70787<7@7H7\7d7x7
8,848<8D8H8P8d8l8t8|8
9D9P9p9x9
:(:4:T:`:
:$;(;D;H;d;h;
<,<0<L<P<X<`<h<l<t<
=(=H=h=
>(>0>8>D>t>x>
?8?T?X?x?
080X0x0
181T1X1x1
1014181<1@1D1H1L1P1T1`1d1h1l1p1t1x1|1
202<2@2D2`2d2054585<5p:
;0;T;t;
; <<<X<
SecureTrust Corporation1
SecureTrust CA0
160901143531Z
240929143531Z0
Illinois1
Chicago1!0
Trustwave Holdings, Inc.1200
)Trustwave Code Signing SHA256 CA, Level 110
ca@trustwave.com0
!http://crl.trustwave.com/STCA.crl0=
https://ssl.trustwave.com/CA0l
http://ocsp.trustwave.com05
)http://ssl.trustwave.com/issuers/STCA.crt0
ca@trustwave.com0
Illinois1
Chicago1!0
Trustwave Holdings, Inc.1200
)Trustwave Code Signing SHA256 CA, Level 110
ca@trustwave.com0
200203100946Z
230202160946Z0a1
TLauncher Inc.1
TLauncher Inc.1
Victoria1
https://ssl.trustwave.com/CA06
%http://crl.trustwave.com/CSCA2_L1.crl0q
http://ocsp.trustwave.com/09
-http://ssl.trustwave.com/issuers/CSCA2_L1.crt0
Illinois1
Chicago1!0
Trustwave Holdings, Inc.1200
)Trustwave Code Signing SHA256 CA, Level 110
ca@trustwave.com
20221206054442Z
Viking Cloud, Inc.1200
)Viking Cloud TWG Timestamping CA, Level 10
220810105504Z
331106165504Z0a1
Viking Cloud, Inc.1503
,Viking Cloud TWG Timestamping Responder 20220
7;FddB
*3V3^F
https://certs.securetrust.com/CA0<
+http://crl.vikingcloud.com/VCTWGTSCA_L1.crl0{
http://ocsp.vikingcloud.com/0A
5http://certs.securetrust.com/issuers/VCTWGTSCA_L1.crt0
4|L"A:
lREO4b
Illinois1
Chicago1!0
Trustwave Holdings, Inc.110/
(Trustwave Global Certification Authority0
220810101823Z
370810101823Z0^1
Viking Cloud, Inc.1200
)Viking Cloud TWG Timestamping CA, Level 10
@Q7!zfy
zmfnz5
P,~-Oh
https://certs.securetrust.com/CA05
$http://crl.vikingcloud.com/TWGCA.crl0t
http://ocsp.vikingcloud.com/0:
.http://certs.securetrust.com/issuers/TWGCA.crt0
O$1<bK
Viking Cloud, Inc.1200
)Viking Cloud TWG Timestamping CA, Level 1
221206054442Z0+
;+7C10
5I03-]
SecureTrust Corporation1
SecureTrust CA0
160901143531Z
240929143531Z0
Illinois1
Chicago1!0
Trustwave Holdings, Inc.1200
)Trustwave Code Signing SHA256 CA, Level 110
ca@trustwave.com0
!http://crl.trustwave.com/STCA.crl0=
https://ssl.trustwave.com/CA0l
http://ocsp.trustwave.com05
)http://ssl.trustwave.com/issuers/STCA.crt0
ca@trustwave.com0
Illinois1
Chicago1!0
Trustwave Holdings, Inc.1200
)Trustwave Code Signing SHA256 CA, Level 110
ca@trustwave.com0
200203100946Z
230202160946Z0a1
TLauncher Inc.1
TLauncher Inc.1
Victoria1
https://ssl.trustwave.com/CA06
%http://crl.trustwave.com/CSCA2_L1.crl0q
http://ocsp.trustwave.com/09
-http://ssl.trustwave.com/issuers/CSCA2_L1.crt0
Illinois1
Chicago1!0
Trustwave Holdings, Inc.1200
)Trustwave Code Signing SHA256 CA, Level 110
ca@trustwave.com
20221206054443Z
Viking Cloud, Inc.1200
)Viking Cloud TWG Timestamping CA, Level 10
220810105504Z
331106165504Z0a1
Viking Cloud, Inc.1503
,Viking Cloud TWG Timestamping Responder 20220
7;FddB
*3V3^F
https://certs.securetrust.com/CA0<
+http://crl.vikingcloud.com/VCTWGTSCA_L1.crl0{
http://ocsp.vikingcloud.com/0A
5http://certs.securetrust.com/issuers/VCTWGTSCA_L1.crt0
4|L"A:
lREO4b
Illinois1
Chicago1!0
Trustwave Holdings, Inc.110/
(Trustwave Global Certification Authority0
220810101823Z
370810101823Z0^1
Viking Cloud, Inc.1200
)Viking Cloud TWG Timestamping CA, Level 10
@Q7!zfy
zmfnz5
P,~-Oh
https://certs.securetrust.com/CA05
$http://crl.vikingcloud.com/TWGCA.crl0t
http://ocsp.vikingcloud.com/0:
.http://certs.securetrust.com/issuers/TWGCA.crt0
O$1<bK
Viking Cloud, Inc.1200
)Viking Cloud TWG Timestamping CA, Level 1
221206054443Z0+
Aapi-ms-win-core-fibers-l1-1-1
api-ms-win-core-synch-l1-2-0
kernel32
api-ms-
((((( H
((((( H
(
mscoree.dll
ALC_ALL
LC_COLLATE
LC_CTYPE
LC_MONETARY
LC_NUMERIC
LC_TIME
Sunday
Monday
Tuesday
Wednesday
Thursday
Friday
Saturday
January
February
August
September
October
November
December
MM/dd/yy
dddd, MMMM dd, yyyy
HH:mm:ss
Bapi-ms-win-core-datetime-l1-1-1
api-ms-win-core-file-l1-2-2
api-ms-win-core-localization-l1-2-1
api-ms-win-core-localization-obsolete-l1-2-0
api-ms-win-core-processthreads-l1-1-2
api-ms-win-core-string-l1-1-0
api-ms-win-core-sysinfo-l1-2-1
api-ms-win-core-winrt-l1-1-0
api-ms-win-core-xstate-l2-1-0
api-ms-win-rtcore-ntuser-window-l1-1-0
api-ms-win-security-systemfunctions-l1-1-0
ext-ms-win-ntuser-dialogbox-l1-1-0
ext-ms-win-ntuser-windowstation-l1-1-0
advapi32
api-ms-win-appmodel-runtime-l1-1-2
user32
api-ms-win-core-fibers-l1-1-0
ext-ms-
Bja-JP
american
american english
american-english
australian
belgian
canadian
chinese
chinese-hongkong
chinese-simplified
chinese-singapore
chinese-traditional
dutch-belgian
english-american
english-aus
english-belize
english-can
english-caribbean
english-ire
english-jamaica
english-nz
english-south africa
english-trinidad y tobago
english-uk
english-us
english-usa
french-belgian
french-canadian
french-luxembourg
french-swiss
german-austrian
german-lichtenstein
german-luxembourg
german-swiss
irish-english
italian-swiss
norwegian
norwegian-bokmal
norwegian-nynorsk
portuguese-brazilian
spanish-argentina
spanish-bolivia
spanish-chile
spanish-colombia
spanish-costa rica
spanish-dominican republic
spanish-ecuador
spanish-el salvador
spanish-guatemala
spanish-honduras
spanish-mexican
spanish-modern
spanish-nicaragua
spanish-panama
spanish-paraguay
spanish-peru
spanish-puerto rico
spanish-uruguay
spanish-venezuela
swedish-finland
america
britain
england
great britain
holland
hong-kong
new-zealand
pr china
pr-china
puerto-rico
slovak
south africa
south korea
south-africa
south-korea
trinidad & tobago
united-kingdom
united-states
zh-CHS
az-AZ-Latn
uz-UZ-Latn
kok-IN
syr-SY
div-MV
quz-BO
sr-SP-Latn
az-AZ-Cyrl
uz-UZ-Cyrl
quz-EC
sr-SP-Cyrl
quz-PE
smj-NO
bs-BA-Latn
smj-SE
sr-BA-Latn
sma-NO
sr-BA-Cyrl
sma-SE
sms-FI
smn-FI
zh-CHT
az-az-cyrl
az-az-latn
bs-ba-latn
div-mv
kok-in
quz-bo
quz-ec
quz-pe
sma-no
sma-se
smj-no
smj-se
smn-fi
sms-fi
sr-ba-cyrl
sr-ba-latn
sr-sp-cyrl
sr-sp-latn
syr-sy
uz-uz-cyrl
uz-uz-latn
zh-chs
zh-cht
CONOUT$
Antivirus Signature
Bkav W32.AIDetectMalware
Lionic Clean
tehtris Clean
MicroWorld-eScan Clean
FireEye Generic.mg.b081509178bb6a0c
CAT-QuickHeal Clean
Malwarebytes Clean
VIPRE Clean
Sangfor Clean
K7AntiVirus Riskware ( 00584baa1 )
BitDefender Clean
K7GW Riskware ( 00584baa1 )
Cybereason Clean
Baidu Clean
VirIT Clean
Cyren Clean
Symantec ML.Attribute.HighConfidence
Elastic malicious (high confidence)
ESET-NOD32 a variant of Win32/GenKryptik.GNHF
Cynet Malicious (score: 100)
TrendMicro-HouseCall TrojanSpy.Win32.TRICKBOT.SMC
Paloalto Clean
ClamAV Clean
Kaspersky VHO:Backdoor.Win32.Agent.gen
Alibaba Clean
NANO-Antivirus Clean
ViRobot Clean
Tencent Clean
Emsisoft Clean
F-Secure Clean
DrWeb Trojan.Inject4.60595
Zillya Clean
TrendMicro TrojanSpy.Win32.TRICKBOT.SMC
McAfee-GW-Edition Clean
Trapmine suspicious.low.ml.score
CMC Clean
Sophos Clean
Ikarus Clean
Jiangmin Clean
Webroot Clean
Avira Clean
MAX Clean
Antiy-AVL Clean
Gridinsoft Trojan.Heur!.00002031
Xcitium Clean
Arcabit Clean
SUPERAntiSpyware Clean
ZoneAlarm VHO:Backdoor.Win32.Agent.gen
GData Clean
Google Clean
AhnLab-V3 Trojan/Win.TrickBot.R601742
Acronis Clean
BitDefenderTheta Gen:NN.ZexaF.36662.HyY@aqWexcg
TACHYON Clean
VBA32 Clean
Cylance Clean
Panda Clean
APEX Malicious
Rising Trojan.Generic@AI.100 (RDML:YZpsTaG6l8uvhCXM1mnWvw)
SentinelOne Static AI - Suspicious PE
MaxSecure Trojan.Malware.300983.susgen
Fortinet Clean
AVG Win32:Evo-gen [Trj]
Avast Win32:Evo-gen [Trj]
CrowdStrike win/malicious_confidence_90% (W)
No IRMA results available.