Static | ZeroBOX

PE Compile Time

2023-09-29 03:00:38

PDB Path

D:\Mktmp\Amadey\Release\Amadey.pdb

PE Imphash

b4e0be0bbc0b6cf93837773846d3b934

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x0002bb2d 0x0002bc00 6.4802382405
.rdata 0x0002d000 0x00008ab4 0x00008c00 5.2790751875
.data 0x00036000 0x000024b8 0x00001800 1.36841726013
.rsrc 0x00039000 0x000001e0 0x00000200 4.71767883295
.reloc 0x0003a000 0x000021e0 0x00002200 6.61166450264

Resources

Name Offset Size Language Sub-language File type
RT_MANIFEST 0x00039060 0x0000017d LANG_ENGLISH SUBLANG_ENGLISH_US XML 1.0 document text

Imports

Library KERNEL32.dll:
0x42d044 CreateFileA
0x42d048 CloseHandle
0x42d04c GetSystemInfo
0x42d050 CreateThread
0x42d054 GetThreadContext
0x42d058 GetProcAddress
0x42d05c VirtualAllocEx
0x42d060 RemoveDirectoryA
0x42d064 GetFileAttributesA
0x42d068 CreateProcessA
0x42d06c CreateDirectoryA
0x42d070 SetThreadContext
0x42d074 WriteConsoleW
0x42d078 ReadConsoleW
0x42d07c SetEndOfFile
0x42d080 HeapReAlloc
0x42d084 HeapSize
0x42d088 GetLastError
0x42d08c CopyFileA
0x42d090 GetTempPathA
0x42d094 Sleep
0x42d098 GetModuleHandleA
0x42d0a0 ResumeThread
0x42d0a4 GetComputerNameExW
0x42d0a8 GetVersionExW
0x42d0ac CreateMutexA
0x42d0b0 VirtualAlloc
0x42d0b4 WriteFile
0x42d0b8 VirtualFree
0x42d0bc WriteProcessMemory
0x42d0c0 GetModuleFileNameA
0x42d0c4 ReadProcessMemory
0x42d0c8 ReadFile
0x42d0cc SetFilePointerEx
0x42d0d4 GetConsoleMode
0x42d0d8 GetConsoleCP
0x42d0dc FlushFileBuffers
0x42d0e0 GetStringTypeW
0x42d0e4 GetProcessHeap
0x42d0f4 WideCharToMultiByte
0x42d0f8 GetCPInfo
0x42d0fc GetOEMCP
0x42d100 GetACP
0x42d104 IsValidCodePage
0x42d108 FindNextFileW
0x42d10c FindFirstFileExW
0x42d110 FindClose
0x42d114 SetStdHandle
0x42d118 GetFullPathNameW
0x42d120 DeleteFileW
0x42d134 SetEvent
0x42d138 ResetEvent
0x42d140 CreateEventW
0x42d144 GetModuleHandleW
0x42d148 IsDebuggerPresent
0x42d154 GetStartupInfoW
0x42d160 GetCurrentProcessId
0x42d164 GetCurrentThreadId
0x42d16c InitializeSListHead
0x42d170 GetCurrentProcess
0x42d174 TerminateProcess
0x42d178 RaiseException
0x42d17c SetLastError
0x42d180 RtlUnwind
0x42d184 TlsAlloc
0x42d188 TlsGetValue
0x42d18c TlsSetValue
0x42d190 TlsFree
0x42d194 FreeLibrary
0x42d198 LoadLibraryExW
0x42d19c ExitProcess
0x42d1a0 GetModuleHandleExW
0x42d1a4 CreateFileW
0x42d1a8 GetDriveTypeW
0x42d1b0 GetFileType
0x42d1b4 PeekNamedPipe
0x42d1c0 GetModuleFileNameW
0x42d1c4 GetStdHandle
0x42d1c8 GetCommandLineA
0x42d1cc GetCommandLineW
0x42d1d0 HeapFree
0x42d1d4 HeapAlloc
0x42d1d8 MultiByteToWideChar
0x42d1dc CompareStringW
0x42d1e0 LCMapStringW
0x42d1e4 DecodePointer
Library USER32.dll:
0x42d1fc GetSystemMetrics
0x42d200 ReleaseDC
0x42d204 GetDC
Library GDI32.dll:
0x42d030 SelectObject
0x42d034 CreateCompatibleDC
0x42d038 DeleteObject
0x42d03c BitBlt
Library ADVAPI32.dll:
0x42d000 RegCloseKey
0x42d004 RegGetValueA
0x42d008 RegQueryValueExA
0x42d010 GetSidSubAuthority
0x42d014 GetUserNameA
0x42d018 LookupAccountNameA
0x42d01c RegSetValueExA
0x42d020 RegOpenKeyExA
Library SHELL32.dll:
0x42d1ec ShellExecuteA
0x42d1f0 None
0x42d1f4 SHGetFolderPathA
Library WININET.dll:
0x42d20c HttpOpenRequestA
0x42d210 InternetWriteFile
0x42d214 InternetReadFile
0x42d218 InternetConnectA
0x42d21c HttpSendRequestA
0x42d220 InternetCloseHandle
0x42d224 InternetOpenA
0x42d22c HttpSendRequestExW
0x42d230 HttpEndRequestA
0x42d234 InternetOpenW
0x42d238 InternetOpenUrlA
Library gdiplus.dll:
0x42d240 GdipSaveImageToFile
0x42d248 GdipDisposeImage
0x42d254 GdiplusShutdown
0x42d258 GdiplusStartup

!This program cannot be run in DOS mode.
`.rdata
@.data
@.reloc
j\hH0C
jXhX1C
j<hH5C
j4hp6C
j$hp7C
j4hl9C
CM @PRj
E0SVW3
CE8SVWh
SVWh$rC
tXh,mC
u"hdwC
URPQQh
;t$,v-
UQPXY]Y[
SVWj03
WWWSHSh
WPWWWS
:u"f9z
F4_^[]
<ItC<Lt3<Tt#<h
A<lt'<tt
35t{C
<at.<rt!<wt
<=upG8
QQSVj8j@
Wj0XPV
SPjdVQ
zSSSSj
f9:t!V
u kE$<
PPPPPPPP
PPPPPWS
PP9E u:PPVWP
D8(Ht'
bad allocation
SleepConditionVariableCS
WakeAllConditionVariable
__based(
__cdecl
__pascal
__stdcall
__thiscall
__fastcall
__vectorcall
__clrcall
__eabi
__swift_1
__swift_2
__ptr64
__restrict
__unaligned
restrict(
delete
operator
`vftable'
`vbtable'
`vcall'
`typeof'
`local static guard'
`string'
`vbase destructor'
`vector deleting destructor'
`default constructor closure'
`scalar deleting destructor'
`vector constructor iterator'
`vector destructor iterator'
`vector vbase constructor iterator'
`virtual displacement map'
`eh vector constructor iterator'
`eh vector destructor iterator'
`eh vector vbase constructor iterator'
`copy constructor closure'
`udt returning'
`local vftable'
`local vftable constructor closure'
new[]
delete[]
`omni callsig'
`placement delete closure'
`placement delete[] closure'
`managed vector constructor iterator'
`managed vector destructor iterator'
`eh vector copy constructor iterator'
`eh vector vbase copy constructor iterator'
`dynamic initializer for '
`dynamic atexit destructor for '
`vector copy constructor iterator'
`vector vbase copy constructor iterator'
`managed vector copy constructor iterator'
`local static thread guard'
operator ""
operator co_await
operator<=>
Type Descriptor'
Base Class Descriptor at (
Base Class Array'
Class Hierarchy Descriptor'
Complete Object Locator'
`anonymous namespace'
FlsAlloc
FlsFree
FlsGetValue
FlsSetValue
InitializeCriticalSectionEx
CorExitProcess
`h````
xpxxxx
(null)
UTF-16LEUNICODE
AreFileApisANSI
CompareStringEx
LCMapStringEx
LocaleNameToLCID
AppPolicyGetProcessTerminationMethod
Sunday
Monday
Tuesday
Wednesday
Thursday
Friday
Saturday
January
February
August
September
October
November
December
MM/dd/yy
dddd, MMMM dd, yyyy
HH:mm:ss
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
NAN(SNAN)
nan(snan)
NAN(IND)
nan(ind)
[aOni*{
~ $s%r
@b;zO]
v2!L.2
;1#INF
1#QNAN
1#SNAN
?5Wg4p
%S#[k=
"B <1=
_hypot
_nextafter
Unknown exception
bad array new length
invalid stoi argument
stoi argument out of range
2efe1b48925e9abf268903d42284c46b
a967e0f403b6529be8f6a614d2956809
699578
3284c50b599d84a9e4a5f072a8c3b14d
DXpDBkJvJaGCJjJ
CDqmHHF1aSyz9W6pQSds2ykp
DC98ER==
LC5p2INq
AW6w4R==
CW0w4R==
D04qEHCiWqC7XQ==
3qmo4XOwJdP8XQ==
L4SMLFyQQSG=
C4SCPXyXXJuzS0NlKPiMKNUyzt6GVrvyzGdYJjt=
zGdYKjtf
zmFzHh==
L4dKLG7ySbPgRWmo4h6x1U2TOwaidfMw57SgG4OvadPybF0q4iKn1U86LeSnVV0kQU==
L4dKLG7ySbPgRWmo4h6x1U2TOwaidfMw57SgG4OvadPybF0q4iKn1U86IOepdz4zQ1OgLYGia vX9GWx3xyE1UAdQOGs
L7Wl3oKYar==
P66oyD2AGwDRPEmXzx6xAVH
L4dKLG7ySbPgRWmo4h6x1U2TOwaidfMw57SgG4OvadPybF0q4iKn1U86LeSn
4r0yPHqpKqCk
zGdIPXqibxOkJ1STzxF=
LLOzP4Ce OG=
L4dKLG7ySbPgRWmo4h6x1U2TOwaidfMw57SgG4OvadPybF0q4iKn1U86IOepdz4zQ1OgK3ai xqkPm xQBSw2o==
AZ0XHWCNSb3KQUyKAL==
OIKA3B==
LIdXLB==
Ar4DFR==
ArSoFR==
AqdDFR==
AqOtFR==
AqKCFR==
ArGnFR==
Ar0yFR==
AqWxFR==
AqK6FR==
AqC6FR==
AqdrFR==
P7OpPDYh xrbW2yu4x2i1yA1
K0Kt2h==
2LW43EhsJn==
2LW43IF3Jp2=
LKC5P3erap2=
Ar0y1YJ6
46mp2HpwK Zo Gx=
260C2nOpKqCyXGyx
I604JnyX9OTpS3mE5BSrHO8f3n==
LLOzP4Ce LLlbGGh
HZ4FK2JdST3qbHem4hR=
H14t3nx=
J6KD3HOvaTn9GEymPb==
IZSJLB==
LKKyPHxdSTPnbXKu5Ch=
IKdn4H2vGw8pWg==
DD3ALH2XWNrXXWO64hiY4I==
Hqq4PHOjXNZoXXJ=
KqdC4H2r
L6dA1H2w
H6dx23Ks
M6qyHHOjXNZoXXJ=
DHJCCAJYLa78MQ==
H6dy4HOrbtVYcXCqFdyr3OAT2OyaegLwQqdC2TUhWOLlMyCn3YSsOyIr6KXmNLVu
CW5xBTTq
uUuH23YXXNZ4JUSu4Yyt2UoT2N6nQbwn37OxBXKebxyaGG6m3RR7xeUa5xBbQrwn20Cp2nyqXKUm
zk5OG32rbxPybC2Z6SyjDaEa4yylcPIi5Kqz2j2sWULpbC2E5CGjNO3Gt8XD
uUtxBTTqJJU=
CW5Rsh==
G7Sn3kTu
CquAPx==
H6dy4HOrbtVYcXCqFdyf2zEl2NKafzgw3md8BY70bpVq 3KyCSSw1yYnPT6d1PL=
L5qXLFOKVvH5anKq3iOB1U8T4d6lWVQ1OISz2oKv TrgO2 y4CSYOPMHPNYeZxIw31G54HOvRdzxXQ==
H6dx3IOXXODSWW2q
P0OnPHOjXTbt9mux3R2t2zIr4UOUfg9561tACUBwLuO6Lzh CQ5=
C10y1XGsXxOx
L5qXLFOKVvH5anKq3iOB1U8T4d6lWVQ1OISz2oKv TrgTW6u5BSiKeodQN66ST4PMJOTJGqTQLLJR1x=
L5qXLFOKVvHz nSD3XuROPTpDuC6WVQz5qqnPYG OdzD9WOJ2SKu1yIYOwWi1zQw
MqqoPX2GPr==
OHFACEt=
IK0qOYOpbwHpbHSu3haxAdkLQOKodAQ120dy
IK0qOYOpbwHpbHSu3haxAdoLQOKodAQ120dy
L4dKLG7ySbPgRWmo4h6x1U2TOwaidfMw57RkJmK OUPCamWz5AWj2fQi3T1=
LLOzPIOgbvZl WV=
DnFBER==
DnFCCh==
DnFBDh==
H70C3nOrbvD59Wyp
Q0Ss2zuWdvHFO0yYzxF=
zmFzKDtf
H4KHJGFdG8==
FpNmyD2C
Fo3myD2C
Am4J5HeX
4r0yPHqpKqCyXXiq
zrWl33mo9NrwGC rzx6n1KDb
zmFqzjuX9NVp 3W5zyBeya1 QxSlKt==
Am3kHYambtC=
zmFqzjuvXNYk
zG3qyB==
LKd7PYCw9xPw C6q6BR=
C008PXGYbxfz nCA3Bih4KErQNYofzQA20iyPXJdJLTt GVlzb==
46m54HKsbTYkJXNlCSNeBs==
ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/
abcdefghijklmnopqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVWXYZ0123456789
NtUnmapViewOfSection
ntdll.dll
invalid string position
string too long
D:\Mktmp\Amadey\Release\Amadey.pdb
.text$di
.text$mn
.text$yd
.idata$5
.00cfg
.CRT$XCA
.CRT$XCAA
.CRT$XCU
.CRT$XCZ
.CRT$XIA
.CRT$XIAA
.CRT$XIAC
.CRT$XIC
.CRT$XIZ
.CRT$XLA
.CRT$XLZ
.CRT$XPA
.CRT$XPX
.CRT$XPXA
.CRT$XPZ
.CRT$XTA
.CRT$XTZ
.rdata
.rdata$T
.rdata$r
.rdata$sxdata
.rdata$zzzdbg
.rtc$IAA
.rtc$IZZ
.rtc$TAA
.rtc$TZZ
.tls$ZZZ
.xdata$x
.idata$2
.idata$3
.idata$4
.idata$6
.data$r
.rsrc$01
.rsrc$02
ReadFile
GetModuleFileNameA
WriteProcessMemory
VirtualFree
WriteFile
VirtualAlloc
CreateMutexA
GetVersionExW
GetComputerNameExW
ResumeThread
GetModuleHandleA
SetCurrentDirectoryA
GetTempPathA
CopyFileA
GetLastError
GetFileAttributesA
CreateFileA
CloseHandle
GetSystemInfo
CreateThread
GetThreadContext
GetProcAddress
VirtualAllocEx
RemoveDirectoryA
ReadProcessMemory
CreateProcessA
CreateDirectoryA
SetThreadContext
KERNEL32.dll
ReleaseDC
GetSystemMetrics
USER32.dll
DeleteObject
CreateCompatibleDC
SelectObject
CreateCompatibleBitmap
BitBlt
GDI32.dll
GetSidIdentifierAuthority
RegOpenKeyExA
RegSetValueExA
LookupAccountNameA
GetUserNameA
GetSidSubAuthority
GetSidSubAuthorityCount
RegQueryValueExA
RegGetValueA
RegCloseKey
ADVAPI32.dll
ShellExecuteA
SHGetFolderPathA
SHELL32.dll
HttpOpenRequestA
InternetWriteFile
InternetOpenUrlA
InternetOpenW
HttpEndRequestA
HttpSendRequestExW
HttpAddRequestHeadersA
InternetOpenA
InternetCloseHandle
HttpSendRequestA
InternetConnectA
InternetReadFile
WININET.dll
GdipSaveImageToFile
GdipGetImageEncodersSize
GdipDisposeImage
GdipCreateBitmapFromHBITMAP
GdipGetImageEncoders
GdiplusShutdown
GdiplusStartup
gdiplus.dll
EnterCriticalSection
LeaveCriticalSection
InitializeCriticalSectionAndSpinCount
DeleteCriticalSection
SetEvent
ResetEvent
WaitForSingleObjectEx
CreateEventW
GetModuleHandleW
IsDebuggerPresent
UnhandledExceptionFilter
SetUnhandledExceptionFilter
GetStartupInfoW
IsProcessorFeaturePresent
QueryPerformanceCounter
GetCurrentProcessId
GetCurrentThreadId
GetSystemTimeAsFileTime
InitializeSListHead
GetCurrentProcess
TerminateProcess
RaiseException
SetLastError
RtlUnwind
TlsAlloc
TlsGetValue
TlsSetValue
TlsFree
FreeLibrary
LoadLibraryExW
ExitProcess
GetModuleHandleExW
CreateFileW
GetDriveTypeW
GetFileInformationByHandle
GetFileType
PeekNamedPipe
SystemTimeToTzSpecificLocalTime
FileTimeToSystemTime
GetModuleFileNameW
GetStdHandle
GetCommandLineA
GetCommandLineW
HeapFree
HeapAlloc
MultiByteToWideChar
CompareStringW
LCMapStringW
DeleteFileW
GetCurrentDirectoryW
GetFullPathNameW
SetStdHandle
FindClose
FindFirstFileExW
FindNextFileW
IsValidCodePage
GetACP
GetOEMCP
GetCPInfo
WideCharToMultiByte
GetEnvironmentStringsW
FreeEnvironmentStringsW
SetEnvironmentVariableW
GetProcessHeap
GetStringTypeW
FlushFileBuffers
GetConsoleCP
GetConsoleMode
GetTimeZoneInformation
SetFilePointerEx
HeapSize
HeapReAlloc
SetEndOfFile
ReadConsoleW
WriteConsoleW
DecodePointer
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
.?AVinvalid_argument@std@@
.?AVlogic_error@std@@
.?AVlength_error@std@@
.?AVout_of_range@std@@
.?AVtype_info@@
.?AVbad_alloc@std@@
.?AVexception@std@@
.?AVbad_array_new_length@std@@
<?xml version='1.0' encoding='UTF-8' standalone='yes'?>
<assembly xmlns='urn:schemas-microsoft-com:asm.v1' manifestVersion='1.0'>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v3">
<security>
<requestedPrivileges>
<requestedExecutionLevel level='asInvoker' uiAccess='false' />
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
0#0(020C0H0R0c0h0r0
1#1(121C1H1R1c1h1r1
2#2(222C2H2R2c2h2r2
3#3(323C3H3R3c3h3r3
4#4(424C4H4R4c4h4r4
5#5(525C5H5R5c5h5r5
6#6(626C6H6R6c6h6r6
7#7(727C7H7R7c7h7r7
8#8(828C8H8R8c8h8r8
9#9(929C9H9R9c9h9r9
:#:(:2:C:H:R:c:h:r:
;#;(;2;C;H;R;c;h;r;
<#<(<2<C<H<R<c<h<r<
=#=(=2=C=H=R=c=h=r=
>#>(>2>C>H>R>c>h>r>
?#?(?2?C?H?R?c?h?r?
0#0(020C0H0R0c0h0r0
22?2X2
2V3b3w3
767<7C7q8
:&:4:n:x:
;2<8<B<X<^<e<#>K>T>;?i?r?
= =5=J=S=`=e=k=r=
>$>->;>
1%1/191@1J1T1_1z1
3.3&4N4c4
=)=S=m=
>$>G>s>|>
<'<8=G=X>g>x?
5K5d5u5
9!9*9;9
394U4[4
4!696l6
939K9L:
;E<a<S=T>
131U1z1
262X2z2
j1'2r2
353S3u3
484V4x4
3A3)9<9
4$44484<4@4
4x5 7V7g7z7
: :$:[:];}<C=
5#525@5D5H5L5r5w5
8-8Q8h;$<
0@0F0c0w0
:$;5;F;d;
n0&2n2
:,:Q:v:
415V:T;l;
;7<L<`<q<
>#?.???P?\?
4(4\4|4
5)5.5>5C5T5Z5_5j5t5{5
66)6/656;6G6U6Z6`6i6p6{6
:=:R:W:\:}:
=K>T>\>
? ?)?K?R?e?q?
0T0]0j0p0
1.1D1M1X1_1
2*2:2J2S2
8-8A8]8g8q8
959A9^:e:
;);5;K;q;
<#<><H<T<Y<^<y<
1[1`1d1h1l1T4g4
6+7074787<7
::4:>:Q:X:d:|:
;/<5<I<h<
>?'?.?
W1v1v2
b0f0j0n0r0v0z0~0M5T5q5u5y5}5
0<0M0X0
11:1E1
676>6\7
8(8=8B8L8Q8\8g8t8
<Q<f<q<y<
="=0=7=?=W=e=m=
?R?W?]?b?j?p?x?
3$3*3E3L3
4@4[4h4v4
4l5t586
3:3O3a3n3
4@4G4h4
5,555:5?5O5T5Y5i5n5s5
6D6p6y6
8'8,818L8[8f8k8p8
9@9d9{9
::?:I:
;3<=<s<
2'2/2X2_2v2
3G3Z3d3}3
,407P7
2\2c2j2q2
;=;K;W;h;v;
> ?8?V?a?
3080=0B0T0
3)3;3M3_3
?-?:???M?
5D6k8v8
:;:U:{:
<"=7>w>
3'3Z3w3
6?6j6}6
9 9*9.949:9@9F9m9
:#:*:3:<:L:]:g:q:{:
<[<d<~<
=X?c?j?p?
0@1J1`1q1
2-5"6*6a6h6b9
=f>+?X?
212Z2u2
3-474a4i5
8M9g9t9
>+>9>J>b>h>t>
2(3(4L4Q4
4A5M5a5m5y5
6/6?6K6Z6m7
848H8S8
<M=X=^=g=
2)4D4Z4p4x4
<<%<2?
6G6Q6[6r6|6
727<7g7q7{7
7'818;8R8\8
9G9Q9[9r9|9
:2:<:g:q:{:
:';1;;;R;\;
<G<Q<[<r<|<
=2=<=g=q={=
='>1>;>R>\>
?G?Q?[?r?|?
020<0g0q0{0
0'111;1R1\1
2G2Q2[2r2|2
323<3g3q3{3
3'414;4R4\4
5G5Q5[5r5|5
626<6g6q6{6
6'717;7R7\7
8G8Q8[8r8|8
929<9g9q9{9
9':1:;:R:\:
;G;Q;[;r;|;
<2<<<g<q<{<
<'=1=;=R=\=
>G>Q>[>r>|>
?2?<?g?q?{?
'010;0R0\0
1G1Q1[1r1|1
222<2g2q2{2
2'313;3R3\3
4G4Q4[4r4|4
525<5g5q5{5
5'616;6R6\6
7G7Q7[7r7|7
828<8g8q8{8
8'919;9R9\9
:G:Q:[:r:|:
;2;<;g;q;{;
;'<1<;<R<\<
=G=Q=[=r=|=
>2><>g>q>{>
>'?1?;?R?\?
0G0Q0[0r0|0
121<1g1q1{1
1'212;2R2\2
3G3Q3[3r3|3
424<4g4q4{4
4'515;5R5\5
6G6Q6[6r6|6
727<7g7q7{7
7'818;8R8\8
9G9Q9[9r9|9
:2:=:l:r:|:
`2h2l2p2t2x2|2
3 3$3(3,3034383<3@3D3H3L3P3T3X3\3`3d3h3l3p3t3x3|3
4 4$4(4,4044484<4@4D4H4L4P4T4X4\4`4d4h4l4p4t4x4|4
5 5$5(5,5054585<5@5D5
6 6(60686@6H6P6X6`6h6p6x6
7 7(70787@7H7P7X7`7h7p7x7
8 8(80888@8H8P8X8`8h8p8x8
9 9(90989@9H9P9X9`9h9p9x9
484<4@4D4H4L4P4T4X4\4`4d4h4l4p4t4x4|4
4h9l9p9t9x9|9
: :$:(:,:0:4:8:<:@:D:H:L:P:T:X:\:`:d:h:l:p:t:x:|:
064686<6@6D6H6L6P6T6X6\6`6d6h6l6
7$7,747<7D7L7T7\7d7l7t7|7
8$8,848<8D8L8T8\8d8l8t8|8
9$9,949<9D9L9T9\9d9l9t9|9
:$:,:4:<:D:L:T:\:d:l:t:|:
;$;,;4;<;D;L;T;\;d;l;t;|;
<$<,<4<<<D<L<T<\<d<l<t<|<
=$=,=4=<=D=L=T=\=d=l=t=|=
8(80888@8H8P8X8`8h8p8x8
9 9(90989@9H9P9X9`9h9p9x9
: :(:0:8:@:H:P:X:`:h:p:x:
; ;(;0;8;@;H;P;X;`;h;p;x;
< <(<0<8<@<H<P<X<`<h<p<x<
= =(=0=8=@=H=P=X=`=h=p=x=
> >(>0>8>@>H>P>X>`>h>p>x>
? ?(?0?8?
=$=,=4=<=D=L=T=\=d=l=t=|=
0d0h0l0p0
1$1(181<1@1D1L1d1t1x1
2$2(202H2L2d2h2|2
7$787@7H7P7T7X7`7t7|7
8,808P8p8
9,909P9p9
:0:P:p:
;0;P;p;
<0<L<P<X<\<`<h<|<
101@1P1`1p1
7 7$7(7,70747
06T6t6
@api-ms-win-core-synch-l1-2-0.dll
kernel32.dll
Bapi-ms-win-core-fibers-l1-1-1
api-ms-win-core-synch-l1-2-0
kernel32
api-ms-
xmscoree.dll
(null)
Bapi-ms-win-core-datetime-l1-1-1
api-ms-win-core-file-l1-2-2
api-ms-win-core-localization-l1-2-1
api-ms-win-core-localization-obsolete-l1-2-0
api-ms-win-core-processthreads-l1-1-2
api-ms-win-core-string-l1-1-0
api-ms-win-core-sysinfo-l1-2-1
api-ms-win-core-winrt-l1-1-0
api-ms-win-core-xstate-l2-1-0
api-ms-win-rtcore-ntuser-window-l1-1-0
api-ms-win-security-systemfunctions-l1-1-0
ext-ms-win-ntuser-dialogbox-l1-1-0
ext-ms-win-ntuser-windowstation-l1-1-0
advapi32
api-ms-win-appmodel-runtime-l1-1-2
user32
ext-ms-
Sunday
Monday
Tuesday
Wednesday
Thursday
Friday
Saturday
January
February
August
September
October
November
December
MM/dd/yy
dddd, MMMM dd, yyyy
HH:mm:ss
((((( H
((((( H
(
Bja-JP
zh-CHS
az-AZ-Latn
uz-UZ-Latn
kok-IN
syr-SY
div-MV
quz-BO
sr-SP-Latn
az-AZ-Cyrl
uz-UZ-Cyrl
quz-EC
sr-SP-Cyrl
quz-PE
smj-NO
bs-BA-Latn
smj-SE
sr-BA-Latn
sma-NO
sr-BA-Cyrl
sma-SE
sms-FI
smn-FI
zh-CHT
az-az-cyrl
az-az-latn
bs-ba-latn
div-mv
kok-in
quz-bo
quz-ec
quz-pe
sma-no
sma-se
smj-no
smj-se
smn-fi
sms-fi
sr-ba-cyrl
sr-ba-latn
sr-sp-cyrl
sr-sp-latn
syr-sy
uz-uz-cyrl
uz-uz-latn
zh-chs
zh-cht
CONOUT$
image/jpeg
Antivirus Signature
Bkav W32.AIDetectMalware
Lionic Trojan.Win32.Agent.Y!c
tehtris Clean
DrWeb Trojan.DownLoader46.21896
MicroWorld-eScan Gen:Variant.Zusy.446510
ClamAV Win.Malware.Doina-10001799-0
CMC Clean
CAT-QuickHeal Trojan.GenericPMF.S30511625
McAfee Downloader-FCND!AEBAF57299CD
Malwarebytes Spyware.Amadey
VIPRE Gen:Variant.Zusy.446510
Sangfor Trojan.Win32.Save.a
K7AntiVirus Trojan ( 005a7a4a1 )
BitDefender Gen:Variant.Zusy.446510
K7GW Trojan ( 005a7a4a1 )
Cybereason malicious.3425e8
BitDefenderTheta Gen:NN.ZexaF.36738.ouW@amc4G5pi
VirIT Clean
Cyren W32/Amadey.C1.gen!Eldorado
Symantec ML.Attribute.HighConfidence
Elastic Windows.Trojan.Amadey
ESET-NOD32 a variant of Win32/TrojanDownloader.Amadey.A
APEX Malicious
Paloalto Clean
Cynet Malicious (score: 100)
Kaspersky HEUR:Trojan-Spy.Win32.Stealer.gen
Alibaba TrojanDownloader:Win32/Amadey.410f7ab9
NANO-Antivirus Clean
ViRobot Clean
Rising Spyware.Agent!8.C6 (TFE:5:Be6eNfNv8YM)
Sophos Mal/Amadey-C
F-Secure Heuristic.HEUR/AGEN.1319380
Baidu Clean
Zillya Clean
TrendMicro Trojan.Win32.AMADEY.YXDI3Z
McAfee-GW-Edition BehavesLike.Win32.Downloader.dh
Trapmine suspicious.low.ml.score
FireEye Generic.mg.aebaf57299cd368f
Emsisoft Gen:Variant.Zusy.446510 (B)
SentinelOne Static AI - Malicious PE
GData Win32.Trojan-Downloader.Amadey.D
Jiangmin Clean
Webroot Clean
Avira HEUR/AGEN.1319380
MAX malware (ai score=86)
Antiy-AVL Trojan[Downloader]/Win32.Amadey
Kingsoft malware.kb.a.995
Gridinsoft Trojan.Win32.Amadey.bot
Xcitium Clean
Arcabit Trojan.Zusy.D6D02E
SUPERAntiSpyware Clean
ZoneAlarm HEUR:Trojan-Spy.Win32.Stealer.gen
Microsoft Trojan:Win32/Wacatac.B!ml
Google Detected
AhnLab-V3 Malware/Win.Trojanspy.C5238800
Acronis Clean
VBA32 Clean
ALYac Gen:Variant.Zusy.446510
TACHYON Clean
DeepInstinct MALICIOUS
Cylance unsafe
Panda Trj/Genetic.gen
Zoner Clean
TrendMicro-HouseCall Trojan.Win32.AMADEY.YXDI3Z
Tencent Win32.Trojan.Agen.Zimw
Yandex Clean
Ikarus Win32.Outbreak
MaxSecure Trojan.Malware.300983.susgen
Fortinet W32/Amadey.A!tr
AVG Win32:BotX-gen [Trj]
Avast Win32:BotX-gen [Trj]
CrowdStrike win/malicious_confidence_100% (W)
No IRMA results available.