Static | ZeroBOX

PE Compile Time

2023-09-21 17:20:44

PDB Path

C:\256lho\Ghost.pdb

PE Imphash

275c1ac8a0a90e452d90c6b023f705b9

PEiD Signatures

Microsoft Visual C++ V8.0 (Debug)

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x000b1d72 0x000b1e00 5.83283791366
.rdata 0x000b3000 0x00019455 0x00019600 4.14796828693
.data 0x000cd000 0x00003d34 0x00002200 3.22944510736
.idata 0x000d1000 0x00000c0a 0x00000e00 4.32721281898
.KZP 0x000d2000 0x0003276b 0x00032800 6.17507287171
.00cfg 0x00105000 0x0000010e 0x00000200 0.110557131259
.reloc 0x00106000 0x000055b0 0x00005600 6.09543810833

Imports

Library KERNEL32.dll:
0x4d1000 Sleep
0x4d1004 GetConsoleWindow
0x4d1008 FormatMessageA
0x4d100c WideCharToMultiByte
0x4d1010 MultiByteToWideChar
0x4d1014 GetStringTypeW
0x4d1028 LocalFree
0x4d102c GetLocaleInfoEx
0x4d1030 EncodePointer
0x4d1034 DecodePointer
0x4d1038 LCMapStringEx
0x4d103c CompareStringEx
0x4d1040 GetCPInfo
0x4d1050 GetCurrentProcess
0x4d1054 TerminateProcess
0x4d105c GetCurrentProcessId
0x4d1060 GetCurrentThreadId
0x4d1068 InitializeSListHead
0x4d106c IsDebuggerPresent
0x4d1070 GetStartupInfoW
0x4d1074 GetModuleHandleW
0x4d1078 CreateFileW
0x4d107c RaiseException
0x4d1080 RtlUnwind
0x4d108c GetLastError
0x4d1090 SetLastError
0x4d1098 TlsAlloc
0x4d109c TlsGetValue
0x4d10a0 TlsSetValue
0x4d10a4 TlsFree
0x4d10a8 FreeLibrary
0x4d10ac GetProcAddress
0x4d10b0 LoadLibraryExW
0x4d10b4 GetStdHandle
0x4d10b8 WriteFile
0x4d10bc GetModuleFileNameW
0x4d10c0 ExitProcess
0x4d10c4 GetModuleHandleExW
0x4d10c8 GetCommandLineA
0x4d10cc GetCommandLineW
0x4d10d0 GetCurrentThread
0x4d10d4 HeapFree
0x4d10d8 HeapAlloc
0x4d10dc GetDateFormatW
0x4d10e0 GetTimeFormatW
0x4d10e4 CompareStringW
0x4d10e8 LCMapStringW
0x4d10ec GetLocaleInfoW
0x4d10f0 IsValidLocale
0x4d10f4 GetUserDefaultLCID
0x4d10f8 EnumSystemLocalesW
0x4d10fc GetFileType
0x4d1100 GetFileSizeEx
0x4d1104 SetFilePointerEx
0x4d1108 CloseHandle
0x4d110c FlushFileBuffers
0x4d1110 GetConsoleOutputCP
0x4d1114 GetConsoleMode
0x4d1118 ReadFile
0x4d111c HeapReAlloc
0x4d1128 OutputDebugStringW
0x4d112c FindClose
0x4d1130 FindFirstFileExW
0x4d1134 FindNextFileW
0x4d1138 IsValidCodePage
0x4d113c GetACP
0x4d1140 GetOEMCP
0x4d1150 SetStdHandle
0x4d1154 GetProcessHeap
0x4d1158 ReadConsoleW
0x4d115c HeapSize
0x4d1160 WriteConsoleW

Exports

Ordinal Address Name
1 0x402176 ReloadData
!This program cannot be run in DOS mode.
`.rdata
@.data
.idata
.00cfg
@.reloc
/]^_[Y
|SUVWj
D$PSUVW
D$$SUV
\$8UV3
;D$HtV
CfABfA
Dt=fFf
tC97u?j4
tG9uCj
tC97u?j
tG9uCj
tG9uCj
tZ9uVj
YPh+\K
PPPPPWS
tC97u?j4
t{9uwj
t{9uwj
tO9uKjD
tG9uCj
tG9uCj
tG9uCj
tG9uCj
tG9uCj
tG9uCj
tc9u_jX
td9u`jX
tc9u_jX
td9u`jX
tG9uCj
tG9uCj
tG9uCj
tG9uCj
tZ9uVj
tZ9uVj
tI97uEjD
tI97uEjD
tS9uOj
tS9uOj
t{9uwj
tG9uCj
tG9uCj
tG9uCj
tc9u_jX
td9u`jX
tI97uEjD
tS9uOj
<xt><Xu=
<xt <Xt
<xtJ<XuI
<xt)<Xt%j
QQSVWd
URPQQh
V<0|M<9
<0|$<9
UQPXY]Y[
VSSSSS
VPPPPP
VPPPPP
j0Z9~4t
j0Z9~4t
j0Z9~4t
j0Z9~4t
j0Z9~4t
j0Z9~4t
j0Z9~4t
j0Z9~4t
j0Z9~4t
j0Z9~4t
j0Z9~4t
j0Z9~4t
t#9^$}
t#9^$}
uj*Xf;
<j*Xf;
uj*Xf;
<j*Xf;
uj*Xf;
<j*Xf;
t#9^$}
uj*Xf;
<j*Xf;
<ItC<Lt3<Tt#<h
A<lt'<tt
<ItC<Lt3<Tt#<h
A<lt'<tt
<ItC<Lt3<Tt#<h
A<lt'<tt
<ItC<Lt3<Tt#<h
A<lt'<tt
<ItC<Lt3<Tt#<h
A<lt'<tt
<ItC<Lt3<Tt#<h
A<lt'<tt
Tt)jhZf;
JjlZf;
Tt)jhZf;
JjlZf;
Tt)jhZf;
JjlZf;
Tt)jhZf;
JjlZf;
Tt)jhZf;
JjlZf;
Tt)jhZf;
JjlZf;
F +F4+
8^8tb9^4~]
F +F4+
8^8tb9^4~]
F +F4+
8^8tb9^4~]
V +V4+
tb9^4~]
V +V4+
tb9^4~]
V +V4+
tb9^4~]
V.jx_f;
~ +~4+
V.jx_f;
~ +~4+
V.jx_f;
~ +~4+
V.jx_f;
~ +~4+
V.jx_f;
~ +~4+
V.jx_f;
~ +~4+
F.jgYf;
jg[BjG_
F.jgYf;
F.jgYf;
F.jgYf;
jg[BjG_
F.jgYf;
F.jgYf;
PRRRRR
PRRRRR
PRRRRR
ul<0|[<9
ul<0|[<9
x!j$Xf9
x!j$Xf9
ARPRQh
jYjf
Sj)[f;
PPPPPPPP
uSSSSj
f9<H_}
f9<H_}
f9<H_}
f9<H_}
f9<H_}
j"^f92
j"_f9z
SWt@jU
_tqPVj@
M,j"^QRRRRR
Vj0XPW
r!SSPVQ
dr#SSjdVQ
M$j"^QRRRRR
j"[VWWWW
PVVVVV
PVVVVV
_PVVVVV
j"_SVVVV
PVVVVV
^PSSSSS
j"^WSSSS
WVVVVV
PVSRSQV
PPPPPVW
PP9E u!PPSVP
PVVVVV
PVVVVV
PWWWWW
u kE$<
j-Xf9E
t^j*Yf
f9:t!V
QQSVj8j@
NX9^`t1
;V\uYW
u2Vj@h
9C`u99C\t4
u29K\t-
^PQQQQQ
E ^PQQQQ
7;1u"3
CY<u
PVVVVV
PSSSSS
D8(Ht'
D8(Ht5F
L:-^_[
PPPPPPPP
tNSVWP
Unknown exception
bad array new length
string too long
iostream
iostream stream error
bad cast
bad locale name
ios_base::badbit set
ios_base::failbit set
ios_base::eofbit set
Was perfect intelligence
%x and %p
bad allocation
bad function call
regex_error(error_collate): The expression contained an invalid collating element name.
regex_error(error_ctype): The expression contained an invalid character class name.
regex_error(error_escape): The expression contained an invalid escaped character, or a trailing escape.
regex_error(error_backref): The expression contained an invalid back reference.
regex_error(error_brack): The expression contained mismatched [ and ].
regex_error(error_paren): The expression contained mismatched ( and ).
regex_error(error_brace): The expression contained mismatched { and }.
regex_error(error_badbrace): The expression contained an invalid range in a { expression }.
regex_error(error_range): The expression contained an invalid character range, such as [b-a] in most encodings.
regex_error(error_space): There was insufficient memory to convert the expression into a finite state machine.
regex_error(error_badrepeat): One of *?+{ was not preceded by a valid regular expression.
regex_error(error_complexity): The complexity of an attempted match against a regular expression exceeded a pre-set level.
regex_error(error_stack): There was insufficient memory to determine whether the regular expression could match the specified character sequence.
regex_error(error_parse)
regex_error(error_syntax)
regex_error
success
address family not supported
address in use
address not available
already connected
argument list too long
argument out of domain
bad address
bad file descriptor
bad message
broken pipe
connection aborted
connection already in progress
connection refused
connection reset
cross device link
destination address required
device or resource busy
directory not empty
executable format error
file exists
file too large
filename too long
function not supported
host unreachable
identifier removed
illegal byte sequence
inappropriate io control operation
interrupted
invalid argument
invalid seek
io error
is a directory
message size
network down
network reset
network unreachable
no buffer space
no child process
no link
no lock available
no message available
no message
no protocol option
no space on device
no stream resources
no such device or address
no such device
no such file or directory
no such process
not a directory
not a socket
not a stream
not connected
not enough memory
not supported
operation canceled
operation in progress
operation not permitted
operation not supported
operation would block
owner dead
permission denied
protocol error
protocol not supported
read only file system
resource deadlock would occur
resource unavailable try again
result out of range
state not recoverable
stream timeout
text file busy
timed out
too many files open in system
too many files open
too many links
too many symbolic link levels
value too large
wrong protocol type
unknown error
invalid string position
0123456789-+Ee
0123456789ABCDEFabcdef-+Xx
0123456789ABCDEFabcdef-+XxPp
:Sun:Sunday:Mon:Monday:Tue:Tuesday:Wed:Wednesday:Thu:Thursday:Fri:Friday:Sat:Saturday
:Jan:January:Feb:February:Mar:March:Apr:April:May:May:Jun:June:Jul:July:Aug:August:Sep:September:Oct:October:Nov:November:Dec:December
%b %d %H : %M : %S %Y
%m / %d / %y
:AM:am:PM:pm
%I : %M : %S %p
%H : %M
%H : %M : %S
%d / %m / %y
0123456789-
0123456789-
0123456789-
0123456789-+Ee
0123456789ABCDEFabcdef-+Xx
0123456789-
0123456789-+Ee
0123456789ABCDEFabcdef-+Xx
0123456789ABCDEFabcdef-+XxPp
0123456789ABCDEFabcdef-+XxPp
+v$x+v$xv$+xv+$xv$+x+$vx+$vx$v+x+$vx$+vx+v $+v $v $+v +$v $++$ v+$ v$ v++$ v$+ v+xv$+ v$v$ +v+ $v$ ++x$v+ $v$v ++ $v$ +v
0123456789-
0123456789-
0123456789abcdefghijklmnopqrstuvwxyz
0123456789abcdefghijklmnopqrstuvwxyz
bad exception
__based(
__cdecl
__pascal
__stdcall
__thiscall
__fastcall
__vectorcall
__clrcall
__eabi
__swift_1
__swift_2
__swift_3
__ptr64
__restrict
__unaligned
restrict(
delete
operator
`vftable'
`vbtable'
`vcall'
`typeof'
`local static guard'
`string'
`vbase destructor'
`vector deleting destructor'
`default constructor closure'
`scalar deleting destructor'
`vector constructor iterator'
`vector destructor iterator'
`vector vbase constructor iterator'
`virtual displacement map'
`eh vector constructor iterator'
`eh vector destructor iterator'
`eh vector vbase constructor iterator'
`copy constructor closure'
`udt returning'
`local vftable'
`local vftable constructor closure'
new[]
delete[]
`omni callsig'
`placement delete closure'
`placement delete[] closure'
`managed vector constructor iterator'
`managed vector destructor iterator'
`eh vector copy constructor iterator'
`eh vector vbase copy constructor iterator'
`dynamic initializer for '
`dynamic atexit destructor for '
`vector copy constructor iterator'
`vector vbase copy constructor iterator'
`managed vector copy constructor iterator'
`local static thread guard'
operator ""
operator co_await
operator<=>
Type Descriptor'
Base Class Descriptor at (
Base Class Array'
Class Hierarchy Descriptor'
Complete Object Locator'
`anonymous namespace'
template-parameter-
`template-parameter-
generic-type-
`generic-type-
`non-type-template-parameter
`template-type-parameter-
`generic-class-parameter-
`generic-method-parameter-
nullptr
lambda
`template-parameter
`vtordispex{
`vtordisp{
`adjustor{
`local static destructor helper'
`template static data member constructor helper'
`template static data member destructor helper'
static
virtual
private:
protected:
public:
[thunk]:
extern "C"
short
unsigned
volatile
volatile
std::nullptr_t
std::nullptr_t
<ellipsis>
,<ellipsis>
noexcept
double
__int8
__int16
__int32
__int64
__int128
<unknown>
char8_t
char16_t
char32_t
wchar_t
decltype(auto)
__w64
UNKNOWN
signed
volatile
`unknown ecsu'
union
struct
class
coclass
cointerface
const
cli::array<
cli::pin_ptr<
{flat}
FlsAlloc
FlsFree
FlsGetValue
FlsSetValue
InitializeCriticalSectionEx
(null)
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
[aOni*{
~ $s%r
@b;zO]
v2!L.2
IND)ind)S
CorExitProcess
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
Sunday
Monday
Tuesday
Wednesday
Thursday
Friday
Saturday
January
February
August
September
October
November
December
MM/dd/yy
dddd, MMMM dd, yyyy
HH:mm:ss
AreFileApisANSI
CompareStringEx
EnumSystemLocalesEx
GetActiveWindow
GetDateFormatEx
GetEnabledXStateFeatures
GetLastActivePopup
GetLocaleInfoEx
GetProcessWindowStation
GetSystemTimePreciseAsFileTime
GetTimeFormatEx
GetUserDefaultLocaleName
GetUserObjectInformationW
GetXStateFeaturesMask
IsValidLocaleName
LCMapStringEx
LCIDToLocaleName
LocaleNameToLCID
LocateXStateFeature
MessageBoxA
MessageBoxW
RoInitialize
RoUninitialize
AppPolicyGetProcessTerminationMethod
AppPolicyGetThreadInitializationType
AppPolicyGetShowDeveloperDiagnostic
AppPolicyGetWindowingModel
SetThreadStackGuarantee
SystemFunction036
NAN(SNAN)
nan(snan)
NAN(IND)
nan(ind)
_hypot
_nextafter
SunMonTueWedThuFriSat
JanFebMarAprMayJunJulAugSepOctNovDec
1#QNAN
1#SNAN
]vQ<)8
|)P!?Ua0
Eb2]A=
u?^p?o4
y1~?|"
?x+s7
?5Od%
?|I7Z#
>,'1D=
?g)([|X>=
~U`?K
:h"?bC
@H#?43
Ax#?uN}*
r7Yr7=
F0$?3=1
H`$?h|
&?~YK|
sU0&?W
<8bunz8
?#%X.y
F||<##
<@En[vP
?5Wg4p
%S#[k=
"B <1=
C:\256lho\Ghost.pdb
Ghost.exe
ReloadData
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
.?AVbad_array_new_length@std@@
.?AVbad_alloc@std@@
.?AVexception@std@@
.?AVruntime_error@std@@
.?AVsystem_error@std@@
.?AV_System_error@std@@
.?AVbad_cast@std@@
.?AVfailure@ios_base@std@@
.?AVinvalid_argument@std@@
.?AVlogic_error@std@@
.?AVlength_error@std@@
.?AVout_of_range@std@@
.?AVoverflow_error@std@@
.?AVbad_function_call@std@@
.?AVregex_error@std@@
.?AVbad_exception@std@@
.?AVerror_category@std@@
.?AV_Iostream_error_category2@std@@
.?AV_Facet_base@std@@
.?AVfacet@locale@std@@
.?AU_Crt_new_delete@std@@
.?AUctype_base@std@@
.?AV?$ctype@_W@std@@
.?AV_Locimp@locale@std@@
.?AVios_base@std@@
.?AV?$_Iosb@H@std@@
.?AV?$basic_ios@_WU?$char_traits@_W@std@@@std@@
.?AV?$basic_streambuf@_WU?$char_traits@_W@std@@@std@@
.?AV?$basic_ostream@_WU?$char_traits@_W@std@@@std@@
.?AV?$basic_filebuf@_WU?$char_traits@_W@std@@@std@@
.?AVcodecvt_base@std@@
.?AV?$codecvt@_WDU_Mbstatet@@@std@@
.?AV?$ctype@D@std@@
.?AV?$num_get@DV?$istreambuf_iterator@DU?$char_traits@D@std@@@std@@@std@@
.?AV?$num_put@DV?$ostreambuf_iterator@DU?$char_traits@D@std@@@std@@@std@@
.?AV?$numpunct@D@std@@
.?AV?$codecvt@DDU_Mbstatet@@@std@@
.?AV?$codecvt@GDU_Mbstatet@@@std@@
.?AV?$ctype@G@std@@
.?AUmessages_base@std@@
.?AUmoney_base@std@@
.?AUtime_base@std@@
.?AV?$num_get@_WV?$istreambuf_iterator@_WU?$char_traits@_W@std@@@std@@@std@@
.?AV?$num_put@_WV?$ostreambuf_iterator@_WU?$char_traits@_W@std@@@std@@@std@@
.?AV?$numpunct@_W@std@@
.?AV?$collate@_W@std@@
.?AV?$messages@_W@std@@
.?AV?$money_get@_WV?$istreambuf_iterator@_WU?$char_traits@_W@std@@@std@@@std@@
.?AV?$money_put@_WV?$ostreambuf_iterator@_WU?$char_traits@_W@std@@@std@@@std@@
.?AV?$moneypunct@_W$0A@@std@@
.?AV?$_Mpunct@_W@std@@
.?AV?$moneypunct@_W$00@std@@
.?AV?$time_get@_WV?$istreambuf_iterator@_WU?$char_traits@_W@std@@@std@@@std@@
.?AV?$time_put@_WV?$ostreambuf_iterator@_WU?$char_traits@_W@std@@@std@@@std@@
.?AV?$num_get@GV?$istreambuf_iterator@GU?$char_traits@G@std@@@std@@@std@@
.?AV?$num_put@GV?$ostreambuf_iterator@GU?$char_traits@G@std@@@std@@@std@@
.?AV?$numpunct@G@std@@
.?AV?$collate@G@std@@
.?AV?$messages@G@std@@
.?AV?$money_get@GV?$istreambuf_iterator@GU?$char_traits@G@std@@@std@@@std@@
.?AV?$money_put@GV?$ostreambuf_iterator@GU?$char_traits@G@std@@@std@@@std@@
.?AV?$moneypunct@G$0A@@std@@
.?AV?$_Mpunct@G@std@@
.?AV?$moneypunct@G$00@std@@
.?AV?$time_get@GV?$istreambuf_iterator@GU?$char_traits@G@std@@@std@@@std@@
.?AV?$time_put@GV?$ostreambuf_iterator@GU?$char_traits@G@std@@@std@@@std@@
.?AV?$collate@D@std@@
.?AV?$messages@D@std@@
.?AV?$money_get@DV?$istreambuf_iterator@DU?$char_traits@D@std@@@std@@@std@@
.?AV?$money_put@DV?$ostreambuf_iterator@DU?$char_traits@D@std@@@std@@@std@@
.?AV?$moneypunct@D$0A@@std@@
.?AV?$_Mpunct@D@std@@
.?AV?$moneypunct@D$00@std@@
.?AV?$time_get@DV?$istreambuf_iterator@DU?$char_traits@D@std@@@std@@@std@@
.?AV?$time_put@DV?$ostreambuf_iterator@DU?$char_traits@D@std@@@std@@@std@@
.?AVtype_info@@
.?AVDNameNode@@
.?AVcharNode@@
.?AVpcharNode@@
.?AVpDNameNode@@
.?AVDNameStatusNode@@
.?AVpairNode@@
GetConsoleWindow
FormatMessageA
WideCharToMultiByte
MultiByteToWideChar
GetStringTypeW
EnterCriticalSection
LeaveCriticalSection
InitializeCriticalSectionEx
DeleteCriticalSection
LocalFree
GetLocaleInfoEx
EncodePointer
DecodePointer
LCMapStringEx
CompareStringEx
GetCPInfo
IsProcessorFeaturePresent
UnhandledExceptionFilter
SetUnhandledExceptionFilter
GetCurrentProcess
TerminateProcess
QueryPerformanceCounter
GetCurrentProcessId
GetCurrentThreadId
GetSystemTimeAsFileTime
InitializeSListHead
IsDebuggerPresent
GetStartupInfoW
GetModuleHandleW
KERNEL32.dll
RaiseException
RtlUnwind
InterlockedPushEntrySList
InterlockedFlushSList
GetLastError
SetLastError
InitializeCriticalSectionAndSpinCount
TlsAlloc
TlsGetValue
TlsSetValue
TlsFree
FreeLibrary
GetProcAddress
LoadLibraryExW
GetStdHandle
WriteFile
GetModuleFileNameW
ExitProcess
GetModuleHandleExW
GetCommandLineA
GetCommandLineW
GetCurrentThread
HeapFree
HeapAlloc
GetDateFormatW
GetTimeFormatW
CompareStringW
LCMapStringW
GetLocaleInfoW
IsValidLocale
GetUserDefaultLCID
EnumSystemLocalesW
GetFileType
GetFileSizeEx
SetFilePointerEx
CloseHandle
FlushFileBuffers
GetConsoleOutputCP
GetConsoleMode
ReadFile
HeapReAlloc
SetConsoleCtrlHandler
GetTimeZoneInformation
OutputDebugStringW
FindClose
FindFirstFileExW
FindNextFileW
IsValidCodePage
GetACP
GetOEMCP
GetEnvironmentStringsW
FreeEnvironmentStringsW
SetEnvironmentVariableW
SetStdHandle
GetProcessHeap
ReadConsoleW
HeapSize
CreateFileW
WriteConsoleW
%B)DTi||||B
5BT9\/W
"+B)Z?
2B.B7C
`YYYY
bbCXQY
U$C_PX
BB7Z9
BT1YT>
BB+@\
DT9|||B
-rr69/
0'0!7(41r/
@T=!R4
1B)!@x
DT9*b0
08"y "
09"<41
180=r4
10r69w
70r69w
"!41410'
I41410']$
41I410!
I41412
090)0!7
40410' d
0'4 @T
BT5ZT-
0'4869
Z8IDXY
0'3 69/
.1.3Z1
.1.3Z1
-.(B).
.3.1Z3
-.*B).
Y8%z5A
U$X+V4
X+y{WL{
]X+E:r
X/`b,8
V+JzY@
mL`}jB
E_CAB
DAYgQp
DT=B0bB+
RAmz]C
MB)y)C
Y+g{tC
B)Y;~Z
@Ns=]
STrzAB
YX[Z]\_^A@CBEDGFIHKJMLONqpsrutwvyx{z}|
~a`cbedgfihkjmlon
1032547698;:=<?>! #"%$'&)(+*-,/.
QPSRUTWVYX[Z]\_^A@CBEDGFIHKJMLONqpsrutwvyx{z}|
~a`cbedgfihkjmlon
1032547698;:=<?>! #"%$'&)(+*-,/.
YX[Z]\_^A@CBEDGFIHKJMLONqpsrutwvyx{z}|
~a`cbedgfihkjmlon
1032547698;:=<?>! #"%$'&)(+*-,/.
RUTWVYX[Z]\_^A@CBEDGFIHKJMLONqpsrutwvyx{z}|
~a`cbedgfihkjmlon
1032547698;:=<?>! #"%$'&)(+*-,/.
^(XI,"
BBBBBBBBBBBBBBBB
VVVVVVVVu_
< <+<1<7<=<C<H<N<v<
<1B1V1]1c1h1w1
839L9f9
:-:3:K:
=7=[=!>4>K>t>
2%2B2U2
7 8&8;8F8R8|8
8)9Q9a9g9
:5:Q:T<
8.838J8O8c8h8|8
9.939G9L9c9h9|9
4N5W5`5B6
7+767N7
<5===M=q=
?3?X?z?
0-0O0t0
1,1A1V1k1
3;3@3G3N3U3\3c3j3q3x3
3,4P4w4
5?5V5g5s5z5
6/7G7f7{7
9'90959H9
839R9w9~9
<(<5<N<
<$=M=,>
B1[1q3
4<6m6h:}:
:";7;<;
=P=e=j=
>-?7?B?O?V?`?k?
8.9r9z9
9H:M:X:
1#2m2r2}2,4
9*:\:c:n:%<
405>5E5
1{2f3c4`5
7+7@7H7N7\7d7
/2@2}2=3M3
=$>:>j>
2$3C3Z5
>1>A>Q>a>q>
9^9s9x9
<F<[<`<
=(>2>t>
>.?C?H?
1\1q1v1
4D4Y4^4
5&606r6
6,7A7F7
=(>G>f>
000S0s0
3"3)30373>3H3S3c3n3~3
4!4,4?4K4_4k4
;?;N;|;%<P<{<
<#=2=\=k=
>%?4?^?m?
4K4U4A5
8a8k8W9J<
:%;*;5;
=->s> ?
01Z1a1l1P3
5.6i6p6{6_8];#<
5#6;6\8Y9
686Z6~6
8(8L8k8
;'<K<m<
>;>_>~>
>!?0?o?
'072>2
4W576Y6z6
5x6c7`8]9
0h2S3P4M5
5A6B8C9
;.=/>x>
:8:L:|:
:1;*<z<
=&>P>}>
2B2`2~2
9?:T:Y:
;!<+<m<
<'=<=A=
0'0F0p0
1+161c1o1}1
9#:F:y:
;:;H;m;
6X7^8_9
:!:):\;6<m<
>/>V>z>
>G>\>a>f>
3<3Q3X3^3p3z3
50656Q6V6z6
7(757:7f7v7{7
7,868?8
859?9H9Q9f9o9
<$<+<3<;<C<O<X<]<c<m<w<
=#=)=/=5=;=A=H=O=V=]=d=k=r=z=
>%>+>1>7>=>C>J>Q>X>_>f>m>t>|>
080>0G0
2C3N3S3f3
5#5)5/555d5z5
>(?/?4?8?<?@?
88#8'8+8/83878;8?8C8G8K8O8S8W8[8_8c8g8k8o8s8w8{8
>0?S?o?
0,0H0w0
;Y<w<}<
7+7_7f7t7
1!1&1.161=1B1G1O1U1
8#8C9O9
4J8[8l8}8
919B9T9i9z9
9,:T:s:y:
<1<6<I<Y<t<
<'=i=w=
2$2E2[2
576;6?6C6G6K6O6S6W6o6s6w6{6
8#9<9L93:~:
;9<B<w<
3*4:4R4h4
5.5I5[5t5}5
7'8:8x8
8(9;9V9
<*<B<g<o<}<
979U9\9
;$;F;Q;
<<$<2<y<
?&?C?N?i?
0'0+0/03070;0?0[0_0c0g0
4"484~4
5,5>5x5
7,7;7K7e7
7g8n8v8
>'>W>q>
3W4g4z4
4#5)5V5\5|5
6*7I7d7r7y7
8@8K8V8^8g8
8h9u9z9C:J:<;K;];
<,<L<v<z<~<
=>2>V>+?6?S?l?
1>2Q2i2m2q2u2y2}2
7%767N7k7
8=9H9Y9
:$:=:F:o:
>">\>c>t>
2 2(222
30353:3P3U3Z3p3u3z3
464J4\4
626?6V6[6`6{6
757:7?7`7p7
=O>Z>f>n>
?&?0?<?
1"1.1<1L1a1x1
w0E1F2
6)7C7u7
8$8V8n8
949L9|9
2&2,22282>2D2J2P2V2\2b2
22#2'2+2/232
O0S0W0[0_0c0g0k0
1 3$3(3,3034383<3p4
9t;x;|;
<p>t>x>|>
J1N1R1V1Z1^1b1f1
0'0D0H0L0P0T091
$;B;k;
6L6e8e9
=g>z>g?z?
g0z0W1j1G2V273F3'4:4
00O0w0K1I2
50686}6
3n7s7x7
"0*0a0h0
54::=B=y=
=:>G>W>d>N?
=>1>^>
3I4M4Q4U4Y4]4a4e4_8W:
203Q3t3
647B7L7i7o7w7
9)919I9n9
3'3@3T3^3w3
> ?G?T?c?x?
1A2O2h2p2y2
2H3T3Z3n3
849M9R9[9
?(?7???G?
>#>)>/>M>
0'0:0M0`0S1
5(545b5
> >0>E>
?M?T?s?
1K1Z1l1
1 252E2R2
3#3=3x3
3>4H4u4
7"767d7i7o7u7{7
83888=8S8X8]8s8x8}8
93989=9S9X9]9s9x9}9
:3:8:=:S:X:]:s:x:}:
;3;8;=;S;X;];s;x;};
;+<D<R<^<j<~<
=%=]=u=
=6>V>`>l>
? ?%?B?k?p?u?
131=1\1a1f1
2 2/2m2
3&3E3J3O3j3y3
44494>4\4
7"7'7,7D7^7c7h7
9"9.93989M9R9W9o9
:%:F:M:d:z:
G6U:u:
23*3>3L3[3n3
4G4f6x6~6
6d7$<-<4>=>
:3A3C4J4
9e:I;Q;
6.7K7k7B8x8
1.1D1L1
3#3A3M3c3l3u3
3$4^4r4
6$7H7Q7\7
7+8k8r8
1G1d1x1
5k6l7|7
::=:H:
:6;>;e;
;]<d<k<r<
0A1K1Q1[1d1
5B7N7X7b7f7l7p7
:":+:;:L:V:`:j:
=2=;=b=g=m=w=
5-646:6
V1<203W3o3
7#7/757C7X7
:!;;<k<
?,?:?W?_?
2#2^2e2
283d3n3
4&585J5\5n5
5|6a9E;W;i;{;
;Q=X=`=h=p=
5_6%7o7
9/:y:?;
1s2/3H3s3
6%7X7u7
;#;_;{;
5&5`5o5{5
6K6T6]6f6
<'<4<d<
=!=)=1=9=W=_=
;R;`;{;
<#<)</<5<;<A<G<M<S<Y<_<e<k<q<w<}<
;&;J;n;
;/<V<z<
='=3=?=K=W=c=
2 2$2,303@6D7H8L8P8T8X8h;l;t<
1 1$1,10141@1D1H1P1T1X1\1`1d1h1
2 2$2(2,2024282<2@2D2T2X2\2
4 4$4(4044484
;$;,;4;<;D;L;T;\;d;l;t;|;
<$<,<4<<<D<L<T<\<d<l<t<|<
8 8$8084888<8@8D8H8L8P8T8X8d8h8p8t8x8|8
; ;$;(;,;0;4;D;H;L;P;T;X;\;`;d;h;l;p;
l2p2t2x2|2
3 3(3,3034383@3D3H3L3P3T3X3\3`3d3h3l3p3t3x3
4 4$4(4,484<4@4D4H4L4T4X4\4`4d4h4p4t4x4|4
5 5054585<5@5D5H5L5P5T5X5d5h5l5p5t5x5|5
6 6$6(6,686<6@6D6H6L6P6\6`6d6h6l6p6x6|6
7 7$7(7,7074787<7@7D7T7X7\7`7d7h7l7p7t7x7|7
: :$:(:,:0:4:8:D:H:L:P:T:X:`:d:h:l:p:t:|:
; ;$;(;,;<;@;D;H;L;P;T;X;\;`;d;p;t;x;|;
;h<l<t<x<
= =(=0=8=@=H=P=X=`=h=p=x=
> >(>0>8>@>H>P>X>`>h>p>x>
? ?(?0?8?@?H?P?X?`?h?p?x?
= =(=,=0=4=8=|>
? ?$?(?,?0?4?8?<?@?D?
0(0004080<0@0D0H0L0T0X0\0`0d0h0l0p0|0
1 1$1(1,1014181<1@1D1H1L1P1T1X1\1`1d1h1t1x1|1
2 2h6l6p6t6x6|6
P0T0X0\0`0d0h0l0p0t0x0|0
1$1,141<1D1L1T1\1d1l1t1|1
6(646@6L6X6d6p6|6
7$707<7H7T7`7l7x7
8 8,888D8P8\8h8t8
: :,:8:D:P:\:h:t:
7$7,747<7D7L7T7\7d7l7t7|7
8$8,848<8D8L8T8\8d8l8t8|8
9$9,949<9D9L9T9\9d9l9t9|9
:$:,:4:<:D:L:T:\:d:l:t:|:
;$;,;4;<;D;L;T;\;d;l;t;|;
<$<,<4<<<D<L<T<\<d<l<t<|<
=$=,=4=<=D=L=T=\=d=l=t=|=
X;`;h;p;x;
< <(<0<8<@<H<P<X<`<h<p<x<
= =(=0=8=@=H=P=X=`=h=p=x=
> >(>0>8>@>H>P>X>`>h>p>x>
? ?(?0?8?@?H?P?X?`?h?p?x?
0 0(00080@0H0P0X0`0h0p0x0
1 1(10181@1H1P1X1`1h1p1x1
2 2(20282@2H2P2X2`2h2p2
d1h1p1
;4;L;P;d;l;p;t;|;
<0<H<L<`<h<l<p<x<
=$=,=0=8=P=h=l=
>(>@>H>L>P>X>p>
?,?D?H?\?d?h?l?p?t?
0 040<0@0H0`0x0|0
14181L1T1X1\1d1|1
2$2<2T2X2l2t2x2|2
30383<3D3\3h3
4 484<4P4X4`4x4
5$505H5`5d5x5
6 6$686@6D6H6L6P6\6t6
7 7$7,7D7\7`7t7|7
8$8(8<8D8H8L8P8T8`8x8
9 9$9(9,989P9h9l9
:0:4:H:P:T:X:\:d:|:
; ;$;,;D;\;`;t;|;
<$<(<<<D<H<L<P<T<`<x<
= =(=@=X=\=p=x=|=
> >4><>@>D>H>L>P>\>t>
? ?$?,?D?\?`?t?x?
0$0<0@0T0\0`0d0h0p0
1$1(1,10141@1X1p1t1
2 282<2P2X2\2`2d2h2l2x2
3 3$3(3,303<3T3l3p3
4$4<4@4T4X4l4t4x4|4
5$5(5<5D5H5L5P5X5p5
6 6,6D6P6h6
7 7$787@7D7H7L7P7\7t7
8 8(808H8`8d8x8
9,94989@9X9p9t9
:(:,:@:H:L:T:l:
L7p7|7
808<8D8l8
9 9,9@9L9`9l9
: :4:@:H:T:X:d:l:x:|:
;(;,;0;<;P;\;d;p;t;x;
< <$<(<4<H<T<`<
=$=p=|=
=(>4>X>d>
? ?,?T?`?
0$0@0H0P0\0
0$1D1L1T1\1d1t1
242@2d2p2
3$3,343@3h3p3|3
4@4L4p4x4
5D5P5t5|5
6,686\6d6p6
90989X9
:(:L:X:
;0;<;`;l;
<,<4<<<D<P<x<
=0=8=D=l=x=
> >(>0><>d>l>x>
?(?L?T?`?
080D0h0p0|0
181X1`1h1p1x1
2<2D2P2x2
3$3L3X3|3
444<4D4L4X4
505<5`5l5
5 6,6P6X6d6
787X7`7h7p7x7
8$8H8T8x8
90989@9H9T9|9
9$:0:T:`:
;$;0;X;d;
<@<H<P<\<
< =(=4=\=h=
> >(>0>8>@>H>P>X>`>h>p>
?0?8?D?p?
040@0d0l0t0|0
181@1L1t1
2$2H2T2x2
3D3P3t3
4$4,484`4h4p4|4
6 6H6T6x6
6 7,7P7\7
8$8,848L8T8`8
949T9\9d9l9t9|9
:(:0:8:@:L:t:|:
;8;D;h;p;x;
<<<H<l<x<
=8=D=h=p=|=
> >$>H>P>T>h>
?(?<?`?l?x?
000P0p0
101P1p1
202<2D2P2
404P4p4|4
5$5(5H5h5
787X7x7
888X8x8
:0:P:p:
0p0d1h1
282H2X2h2x2
2,50585<5
? ?L?x?
;,<X<|<
0(0D0d0
C:\Windows\Microsoft.NET\Fra
mework\v4.0.30319\AppLaunch.exe
Rushing through
!x-sys-default-locale
:Sun:Sunday:Mon:Monday:Tue:Tuesday:Wed:Wednesday:Thu:Thursday:Fri:Friday:Sat:Saturday
:Jan:January:Feb:February:Mar:March:Apr:April:May:May:Jun:June:Jul:July:Aug:August:Sep:September:Oct:October:Nov:November:Dec:December
:AM:am:PM:pm
api-ms-win-core-fibers-l1-1-1
api-ms-win-core-synch-l1-2-0
kernel32
api-ms-
(null)
((((( H
((((( H
(
minkernel\crts\ucrt\inc\corecrt_internal_strtox.h
__crt_strtox::floating_point_value::as_double
_is_double
__crt_strtox::floating_point_value::as_float
!_is_double
Runtime Error!
Program:
<program name unknown>
Microsoft Visual C++ Runtime Library
mscoree.dll
LC_ALL
LC_COLLATE
LC_CTYPE
LC_MONETARY
LC_NUMERIC
LC_TIME
Sunday
Monday
Tuesday
Wednesday
Thursday
Friday
Saturday
January
February
August
September
October
November
December
MM/dd/yy
dddd, MMMM dd, yyyy
HH:mm:ss
api-ms-win-core-datetime-l1-1-1
api-ms-win-core-file-l1-2-2
api-ms-win-core-localization-l1-2-1
api-ms-win-core-localization-obsolete-l1-2-0
api-ms-win-core-processthreads-l1-1-2
api-ms-win-core-string-l1-1-0
api-ms-win-core-sysinfo-l1-2-1
api-ms-win-core-winrt-l1-1-0
api-ms-win-core-xstate-l2-1-0
api-ms-win-rtcore-ntuser-window-l1-1-0
api-ms-win-security-systemfunctions-l1-1-0
ext-ms-win-ntuser-dialogbox-l1-1-0
ext-ms-win-ntuser-windowstation-l1-1-0
advapi32
api-ms-win-appmodel-runtime-l1-1-2
user32
api-ms-win-core-fibers-l1-1-0
ext-ms-
american
american english
american-english
australian
belgian
canadian
chinese
chinese-hongkong
chinese-simplified
chinese-singapore
chinese-traditional
dutch-belgian
english-american
english-aus
english-belize
english-can
english-caribbean
english-ire
english-jamaica
english-nz
english-south africa
english-trinidad y tobago
english-uk
english-us
english-usa
french-belgian
french-canadian
french-luxembourg
french-swiss
german-austrian
german-lichtenstein
german-luxembourg
german-swiss
irish-english
italian-swiss
norwegian
norwegian-bokmal
norwegian-nynorsk
portuguese-brazilian
spanish-argentina
spanish-bolivia
spanish-chile
spanish-colombia
spanish-costa rica
spanish-dominican republic
spanish-ecuador
spanish-el salvador
spanish-guatemala
spanish-honduras
spanish-mexican
spanish-modern
spanish-nicaragua
spanish-panama
spanish-paraguay
spanish-peru
spanish-puerto rico
spanish-uruguay
spanish-venezuela
swedish-finland
america
britain
england
great britain
holland
hong-kong
new-zealand
pr china
pr-china
puerto-rico
slovak
south africa
south korea
south-africa
south-korea
trinidad & tobago
united-kingdom
united-states
zh-CHS
az-AZ-Latn
uz-UZ-Latn
kok-IN
syr-SY
div-MV
quz-BO
sr-SP-Latn
az-AZ-Cyrl
uz-UZ-Cyrl
quz-EC
sr-SP-Cyrl
quz-PE
smj-NO
bs-BA-Latn
smj-SE
sr-BA-Latn
sma-NO
sr-BA-Cyrl
sma-SE
sms-FI
smn-FI
zh-CHT
az-az-cyrl
az-az-latn
bs-ba-latn
div-mv
kok-in
quz-bo
quz-ec
quz-pe
sma-no
sma-se
smj-no
smj-se
smn-fi
sms-fi
sr-ba-cyrl
sr-ba-latn
sr-sp-cyrl
sr-sp-latn
syr-sy
uz-uz-cyrl
uz-uz-latn
zh-chs
zh-cht
CONOUT$
Antivirus Signature
Bkav W32.AIDetectMalware
Lionic Clean
Elastic malicious (high confidence)
MicroWorld-eScan Clean
CMC Clean
CAT-QuickHeal Clean
ALYac Clean
Malwarebytes Clean
Zillya Clean
Sangfor Clean
K7AntiVirus Clean
BitDefender Clean
K7GW Clean
CrowdStrike Clean
Baidu Clean
VirIT Clean
Cyren W32/Kryptik.KRU.gen!Eldorado
Symantec ML.Attribute.HighConfidence
tehtris Clean
ESET-NOD32 a variant of Win32/GenKryptik.GOBL
APEX Clean
Paloalto Clean
ClamAV Clean
Kaspersky HEUR:Trojan-PSW.Win32.Stealerc.gen
Alibaba Clean
NANO-Antivirus Clean
ViRobot Clean
Rising Stealer.Stealerc!8.17BE0 (TFE:1:2IOPZNDHrYF)
TACHYON Clean
Sophos Clean
F-Secure Clean
DrWeb Trojan.Inject4.61247
VIPRE Clean
TrendMicro Clean
McAfee-GW-Edition Clean
Trapmine Clean
FireEye Clean
Emsisoft Clean
SentinelOne Clean
GData Clean
Jiangmin Clean
Webroot W32.Trojan.Gen
Google Detected
Avira Clean
Antiy-AVL Trojan/Win32.Sabsik
Gridinsoft Clean
Xcitium Clean
Arcabit Clean
SUPERAntiSpyware Clean
ZoneAlarm HEUR:Trojan-PSW.Win32.Stealerc.gen
Microsoft Trojan:Win32/Sabsik.FL.B!ml
Cynet Malicious (score: 100)
AhnLab-V3 Clean
Acronis Clean
McAfee Clean
MAX Clean
DeepInstinct MALICIOUS
VBA32 BScope.Trojan.Wacatac
Cylance Clean
Panda Trj/Genetic.gen
Zoner Clean
TrendMicro-HouseCall Clean
Tencent Clean
Yandex Clean
Ikarus Trojan.Win32.Injector
MaxSecure Clean
Fortinet W32/Kryptik.HURI!tr
BitDefenderTheta Clean
AVG PWSX-gen [Trj]
Cybereason Clean
Avast PWSX-gen [Trj]
No IRMA results available.