Static | ZeroBOX

PE Compile Time

2023-09-28 16:53:01

PE Imphash

d05c4856bcec3de7a93f93043e1eeb39

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x0000bbcf 0x00000000 0.0
.reloc 0x0000d000 0x00000be8 0x00000000 0.0
.rdata 0x0000e000 0x00001ed8 0x00000000 0.0
.data 0x00010000 0x00001b3c 0x00000000 0.0
.|][ 0x00012000 0x0002b860 0x00000000 0.0
.ktqovk 0x0003e000 0x00001000 0x00000000 0.0
.@/Q 0x0003f000 0x001e7b31 0x00000000 0.0
.9FX 0x00227000 0x000002dc 0x00000400 2.33805368214
.3^2 0x00228000 0x0047a1a0 0x0047a200 7.91060939136
.rsrc 0x006a3000 0x0002b858 0x00000200 0.328826520682

Resources

Name Offset Size Language Sub-language File type
RT_RCDATA 0x006a3058 0x0002b800 LANG_ENGLISH SUBLANG_ENGLISH_US data

Imports

Library KERNEL32.dll:
0x627000 Sleep
0x627004 CreateThread
0x627008 lstrlenW
0x62700c VirtualProtect
0x627010 GetProcAddress
0x627014 LoadLibraryA
0x627018 VirtualAlloc
0x62701c LockResource
0x627020 WaitForSingleObject
0x627024 SizeofResource
0x627028 FindResourceW
0x62702c GetModuleHandleW
0x627030 GetLastError
0x627034 CreateMutexA
0x627038 GetModuleHandleA
0x62703c EnumTimeFormatsW
0x627040 FreeConsole
0x627044 LoadResource
0x627048 MoveFileA
0x62704c GetCommandLineA
0x627054 ExitProcess
0x627058 WriteFile
0x62705c GetStdHandle
0x627060 GetModuleFileNameA
0x627070 WideCharToMultiByte
0x627078 SetHandleCount
0x62707c GetFileType
0x627080 GetStartupInfoA
0x627088 TlsGetValue
0x62708c TlsAlloc
0x627090 TlsSetValue
0x627094 TlsFree
0x62709c SetLastError
0x6270a0 GetCurrentThreadId
0x6270a8 HeapCreate
0x6270ac VirtualFree
0x6270b0 HeapFree
0x6270b8 GetTickCount
0x6270bc GetCurrentProcessId
0x6270c4 GetCPInfo
0x6270c8 GetACP
0x6270cc GetOEMCP
0x6270d0 IsValidCodePage
0x6270d4 TerminateProcess
0x6270d8 GetCurrentProcess
0x6270e0 IsDebuggerPresent
0x6270f0 HeapAlloc
0x6270f4 HeapReAlloc
0x6270f8 RtlUnwind
0x6270fc LCMapStringA
0x627100 MultiByteToWideChar
0x627104 LCMapStringW
0x627108 GetStringTypeA
0x62710c GetStringTypeW
0x627110 GetLocaleInfoA
0x627114 HeapSize
Library ADVAPI32.dll:
0x62711c RegDeleteKeyA
Library KERNEL32.dll:
0x627124 LocalAlloc
0x627128 LocalFree
0x62712c GetModuleFileNameW
0x627130 ExitProcess
0x627134 LoadLibraryA
0x627138 GetModuleHandleA
0x62713c GetProcAddress

!This program cannot be run in DOS mode.
3ERich
`.reloc
`.rdata
@.data
@.ktqovk
`.rsrc
"UAN:h
FYXYYYYZXZ
Yn'Bjt
rb+n1S
s#ZS~+
OFR"H1o
x"KlH%<
<Z2YpE
W'YXZY
?fn)SL
VSXqE
e/bG6p_
%X(`2mS0:
,VrSe8a
mq-x]^wM
s9&@e;L
XBvyfW
M.p^^.<
LoadLibraryA
PZZYZXYZZ
Cu)~"];<
gB!D'W
mQm~AnA`!7
@u$W,oQ:
F0xd`
./8cld
-`9,<$?
b#FmIZ
;^j2XB
("fbP-
hDw.:1
>>7>&A,
mvmcvME
YQ;g"H
OX7aiZK&zE
oP:@N@a
$6xAvI
VQ5!{p
W@nsZ8
sYP.%m
`N#Nv7Y
(U=-U'
~9I-Ba
S/E()B
XH0?Vy
"G? ^z
c[VRF}
`^92^X
/D^KcI2
ex^~yw
j1x=Be
{|$`./`
?y-TD=
%UCxs6
5; %n_
|,_x}NF
9DxGWeoscN`)
-i|t8^
8<0o02
G9^g--
'y-0 e
*1t@WB
}p-EM
XJceKn5
();T,
#,XZ4.f
rigOjAj
CJz96f{
d:oUi$U
<OJ9zr6@
im@*A3
"<$n-O
P>?7',
]]0[:
FU!f M(
O[Y1\O9
oq.QE?
0"p1{\z
3l"2::B
$}VU?G-
&QKK4A*
IYdzC(
]{<kX=
iI^nTg
2 {6zHA
l>-^L#[w
gPaA0s
;Q.x.s
p<k#iU
kTawPz}
z\BN&*
>EWC<I^
"?,(XJ
3jWUsb]f
xIk%eg
A_Coeh
GYu-mf
>L#tZ|
x(1EuyG8[
~R!jY
-y;=Vl
$l/6MbE0
~rf;\`
vL!_Oe
+\o?3}
xRbX3E%?E
_lLOOy
kHG\8#
O\-_(vX
R@miVb
'Aml|L
JHLA;/q
"VoF1Z5
H0Zq.h
Z%&uzd
qu78PV
uCG3/4
M>8'E'
&G\Wl2j
gm?Ej/n
{P;PnK"
gKcABt}
)jZIi.
~ACmS7
ys^-U
"${!$m
l(./KeV
P*i>ig
`Zvv%]
P,5U-C
b"Pgf<
Pz"uXk
3bI]mr
}!3yypb
@uoC:"
+p8iX
V1@2Qz
2aBS}2
QBTFfF
Omg2$Px
tj'(:~
JF=_??q&
{2wZ5[G
j527\
E/>_k,
!}*JoM
(^}>H;
[I&Ef
vS/PTZ
(OF@=z"j
D{=JJH
q/ru2k
QX,j,$)J
1Dl/c2
2Y)^xrps
)IB@oZ
g|T^"w
Y/|FaoP
X1IK:#
jSP3Rs
|8\yp
DL24Kb
s('Wv+]
]t6=oi
Xe(Yv)
@o0*2
|05U3N
OquTizOM
\;q_C8
T'_\=v?
(J#7}[U[w
'RQ2PK<
W7Q%5}
Af0k;&(
\rf%<W
5O,wEJ
|4fk!p\P
0?Xq3p %
@5U! >
.ka#*H
\W#+p<WR
5BHSRy
>z\z{?
l-V&Sc360e
IV8Fg?K
'-N:%fM*
If[Q2*
Q,X(/<
wv)H4['&c
YB)'6S
/k b<!
ybG0tU
,K93u
1kjtQ:
Vkuf#P~
9[)7R}
"~`y3Po
rf!J02F
!*dFS),
Ib^M;IyCG
VVO32S
~fJyRM=w
S"g;(I7:
eQ7Rg]
J|UI&Rz)
&rM3,{
FoI gJ
HRztVb
@v?"`;M
eMf9dcL
M}h7$V
,Q5ru\"
IGLgo142
zyG:GY_
7=v.QI
4q#g$%
#De`*g
[{wOU14
({%dX'[t
!=3j1a[x
Ek{$jX-
}an*dP
,SBJD_N
jb]J\88
XFdZIh
V`KNN!V
3[dxM
CS\g,+
)yk=#d
T$KY6Z
n0N>wh
lXQC!J
8",Uiv~
(<r9GV\
a'?;EB
C;>tI,
R`q8%H
\wAC!3
e[Y#+
3,iD,n
Km;-p}3QU
;yH[6,J
n{^V=+;#
y7nhkD
UpavuYS]
L^k54sP
}x{>={Z
J=_k(=[$
x$<7hpe
yoH6Q]
lmomA()
cH-12X
;oj[^J.$
<g&ex'm
s.#!K7cP
[<>6TC
a,Zlv]
O?%JHi
2t!cf-
L iD]NE
VyDeg!F>
3i8*1`3
'"M|\h
9!Cls~
tc_vQ!
P[/9vM
<g!6k!
EQX^`\z
La(rm
]e1<WZ;
0cot@(
+=q~S<I
@g!I=|(
v|k[&Y
Z{y!\Q
$,f/g.
dw*I;C]
53ui]G
PsACX#
sePY6v
z#3Z_k
l'COObUoBf
Z2:l*=
XKs2*D
x48(aR
cCz^Qd
c+Z&p
<SWY\1
.I*|[v'BS
[p^B/|
i>"`D`
(~0($a
OjF^ld
hrK-0=d
RRh5dt
faKmaGljT
:C(j+'
YTP"L(
1&z7O=
9S<T:H
0&kSyHx
GetFileType
OZG~[q
Eupp&I
e*G6@
A\A^YYAX
YZZZYX
@/VFS
a+2Vs`
&1xQ;b
XOS^6\
s8lmC?
/9x">
=<Q2:K
hP1oXWF
$8iRu1
jtx4>i
|]dE7J
<Khqo{
\mzxCq<
7{LqJV
y@DyhV
iYpz6SK
Anj/S'
D1,$E"
y=`I>=
WI!X'\
c0)v=n
>9%,u
,fFqnS
7QSa|f;
F2'vv5P
339*4D
<6f:m?
`7ru1>
]Zztm]
LB\<t7
`I:0q~
%@=`QF
gQqP<=
Z5&LUuq
,f}|[
2AT1\T
/'+nLo
XXYZXXY
`s4.=t
Z=+uR4
!*o-cLw
#r%&`*
J#~73YSM
T`Qjk#
AZZXA^[A^Y[XA\A\
YZXYXYX
,`zQ"S
PPYZZXY
ZZZYYX
ZYZZYZYZZX
5n,Sdg
bn)lRi^
68&).1
p>90d=J
rHmUL)
AD2E;-[_
N"T{Q'
,Rxj7S#c%
<Q]tB!
6d:9sW
&~ yL,
/&C84'
NWXei9
6ln^3l
}5DD>e
e\5%48P
+JdQ7s
bwI:_!i
p*`Qdw
)"hS`L{
O8j0\&Jk
mM:P.
Kl{QR(
KAGm8u!X
Jj#0BS
,y8.#Sq@0
D~Ipa
giBVY@E
2~u!`Ks3
byv:uK
&uRr0M
uFM!%%g
|wx4,o
% hAq]E
`^@}Ij
ZZXXYY
,t77kAU
%I1Om<GQP
*b}M:C
;X*?</
S:Lec=;XN[
2VPd?^
EL2[)j\.N
3,OFD(
\!_L)x
T9,w)X
Tc; 2V
;Oe_L/
Y?k#CH
,`$67SM
]zU:d>d
)(!]2M
<vWvn
+:dgd:)='CX
pfbtuk
A]ZZAZYYZ
jT&5o5
sQ|0UN
A^[AXZ
G3R2$(Y
s"D5qo
QU:.}O
5PoG,k
cBm*LH
5|yo~c
aD*:c@z?q
sbS3vnS
3@SC]S
!SYH7e
Z,tQHw6
2]n;i%
h.gQ|n
(3PXKC
`PZ/%b
L0F,`0Q
e]:"j{
fIhS/'{
i0f:S+
QBW]D&l
gNlS.
d:UJ'C
&Wt`wctf~WT#%
KpD&]^
ZAZAZAX
qEO}tC
Ppx8.}
pQ"x0v
ZZYXYY
DeleteCriticalSection
A^A]XYAXA]A\
J54a;<
YYYYXXX
3g]t3bJ
A)/G%@L$
pSe")La
LJ%UI!
YXA[AX_
\y{&k
,|MHES
8S%g$l
ZvS.
|>?lAz{
`]9eM4Y,N
3Z6dEc
ZA\AXA]
5`0L,iZ
t*]7r"
T7].''ow
A^AX[A^
&XXYZX
N(S[M7
Lh?+XQwZ
=SS7S
\{yVg)id
,t;?Pf4
5eNYDb
4&ozb2
yAvI>l
5e)2_
ww*%bf
kxalf8
sHG>lU
S6l.]Z5l
^6e"%o[3
XYXXXY
^n:_at
qESz`}
@~XZ2p
oBo@?5
qZ-@1)[y@g
Q[*cY5
zZAG;+:c
X}/Q02Mu
#nF:zO6@
JD/)]X
XZZZYZ
<baK_&
>(uVb:8
B&T}r>
pE%Gv
a3""Dx
T_HLET2
zzc+nv
fhLY0h
yqYCC
P%2.F3
W\e~;lH
`CAQb!
,rP%&S
g_nT>p
"hR~AA
ZXYXYYXZ
TlsFree
,SZfsS
4%] =C
j~j|$w
S|$ooJ
E..|J&)
2FbQ*^
I)xjNG
]gYX1C
^(\SuL'o
%[*5",
Y$Oei#8
r>([tT
USh1[S
c)S\EB
,l=YuSt7f
Z~jQJ}
$$:XXZ
pST%w$
XXXYXZ
4{cGx_o
AyC5BJ
A\AZZZA^
:EnO=-
K:U9]B'
]'x)O\S`!O
+\2nQ]
YZYZXY
ZZXYXX
XYYZXXYZ
8&hX^v
YZYXYZ
Bcw{rd
IbfDDj
{`t{N
XXYZYZXY
YZXZXXX
SetHandleCount
*{EN<S@
&S]e[
iqtS g
,}]`xS
buT1]"
<Y4G:y
CinQPu
GetCurrentProcessId
HYARP
3\3CjWIc
YZZXYZXY
t$8D1d$8H
A[A]A[A^AZZ_[
YXXXYZZ
EkcK"O*
a5Fl7-
I%}U=/
pzzd=>
@yr3t4`
pm5Wf{
<4t{zN
I,qKR]
Ck,z/A
"c|zQrE
t)}S=Gn
j>w]Dr25
/"5M%@'
xAet5+
pB^Thf
~O7-y8
,2*tsE"]
Ce}Ls4
BOprrOX|
Y3lSTD>0
D$`h1R3
>jwc39
eA[A[AXAXA\[AXYA\
Hc$/nts
WriteFile
!wB1\D
G@f#T$
r+X(SAu
)s:zQi
Kb\5S9
!#iQ44u
NISH Z
AXY_A^
^@SEa-
yH wOyc!
YXXYXYY
ZpzJ:\,
n^Ju>M
p2ePCqY
ZSc3TSd:
*{;S`d=
dnC-Ti4
RtlUnwind
VSsS]E
5eSNbs
\0w2~
=06ZHZ
5tF\.l
4<=C=Y3C
\$pAPf
T$ A\H
;I=P]
}KQp;%
`{2/E#
hoF:U+q
:2oQ"V
YWutQ+
(bSUQn
?cUnsG'
HtJXI0
!d5Z"?
mq][oX
K;*:\S>,UD9
'6?v?
]2^sm5)
3J<14=
,'vTDS?:W
aQUObJ
gk:/"X
0:];u5
A\AZXZA^
2S>!D
'ZZXZYX
,=n[5S
Su,JAQ
A[AZAZA^
DR]brj
)t\v{f
F1$t^f
fE:1kx
z2;lQ"
AZXYA^O
-yh>xq
CZ:7m]
,U>)nS
YZXXXZZ
=)rFd:?
::G_c^Iv
`![lQ"
0E$MuV
tQIM(~
"%[lYKa"
ZZXZYZX
/GVj)S,
z6Z:P
,~de)S
fmSWcaS5
k[JrSS
YA\A[A][Y
?~|EHq
5M/,qY(
,HhNuS! f
V>`,=n
8pKR:S
#,tSjBg
37$[yv
GetModuleFileNameA
ZZZYZZ
)^{xQA
tLzGbS
UDz0eS
AZAZAZ
2`3Ff3
3!lY{c
I,l"T
[A[A^A^A\_AX
k+HS;h
,#*ixSc
,ES!#4E
-!S\Xk
m3@S$]S
AZ[AZA\Z
lfv5
8{;l-Bg
kQn^),
WqE:n4o
1],lQMd
Nzzw:R
Qv=aD~v9
fvK?CIvG
V}X>fz/
|Lq:{;
5-3./n
ES 5-'er
4R]d:Y[
UnhandledExceptionFilter
h-|S!Co
0)'S*&o
7FSJYU
*C}$$S
,~G{KS
YXYYZYY
gcH,Wd?
HwXf+
e=l94(3[
dw}lw
'A[ZA\
D"SFGl
{O l-p
AXAZA^
ZAXA]YZAXA\A^AX
NSfKW4
6iia{g
Wb}(w
T(EA^A
,-m/+S
j&OS#H\
.7iSgYz
,skp^S
/]DMZ3
E0Isu7>
1]<)6*
K]g'{Z
fY#TV^T
*1{i{8
v0o&'9
}1~VM6
P5:%`2M
4.j<3Y
&sSPH`
,uY`LSv
LWY@w*
,Pp?oS9Q|
\uZY{[s
jU*S#;9
KKScfk
/|LoQh`(
;gSrqt
^AVJ3T,
mR@R:a
85lQm7k
,mJNxkl
ZZYXYZX
}/C%pP
,s"MKSk#X
g(?ARS
,qQ9\S
,$%5%;
AXA^[AZ_A[
XA[AXAZA[X
BWSRlYS
X-8#/g
EnterCriticalSection
k2LEU}%
B}bUF9
eyM}7&
75vUpp
[A^A]ZAX
{5}&Sr
,a]cSM
XmiQC$
'Bx_<o@
wi9Oe6t&h
c>V,%v
j[S&Z\$
z2T+;
\7JWl0=
t=vYNF
ci0Xa:}
I,2;rR
<xmA-
l^]5s3
<1e/JoS
bPilcD{
-:M%Lp
ZH?Wm}
D1t$ H
}DET,M
@)MUp.:
K(\jF
vET$FB#
XYYYXY
TKVRS$
y2;/~E
9|g8hu
e}sw4t
%rVy}ZY
A]YA[A[AZ
b$*qR#]L
I'O8NP
5$/Nd-
yLwsIK
F~X:}5`
lPp,Wl|
GetModuleHandleA
I:?LE>
bvpU2x
01.%Sw
j3i1OOy
i{m;Y|
O~8wBv
LNel}Y
YK%}E-
\Rp"O(
d$8ATH
(0TYXZXY
FreeEnvironmentStringsW
js54iw
-XyQ9*
x7&Cv
4S&~@:
rTfS;:u
,.G#|S
4XXXYY
Io?-i:rw*C-
m=A[d
l,1%)JEh
l.NDGB
3n:&JX
q%42|m
lU4\Sk
r;4W=|W
BJ;<&]
g"QS.LB
5&eS|Hv
YYYYZZZ
7qnQ/K
\,Zl{M
pK}}J-
x#yQi^
*M"&n,
,Q+zS
;bKl"c
&lq!H,
Rl`&k=
G/mH%zv
^S|6C?
Y__YAX
*3XXZYXX
mQ*({/
S/bT`,
6YjQ,N
;S3+MT
KOaSOUs
D{+45F
MBP<Xl
UwllF&
Xbc@)R#
ArJ4%f
o4nQs7[
,~G#bS
"\YX:|
'5NSn[]
VEjQ@L
V!yjQ'
z8TS3VG
,gn9nS
S{"D8
YYYYYZZ
,]/L'St
~qX:C=o
ZXYYXXZZYY
([}(h.=
,S`_;S
:qmQ.&n
7o9MTS
b,dlb2
XS1ASF
[A]XZA\
)$5S&.u
YO1h&*
}jqt)G"+
SsK4'F/
<^mSu0~
nQ}<})
Kq'Sq-7
,[j:AS#TR
PXXZZZ
sdSaKY
O%E9FUR
>>LxP1R5
I""`'8
D4:>tS
4e;/ES
ZZXZZX
>|p[pU
\7zt
U#hlptS
KJ 9l_{
c KtS'<
MFJ9J1
v["S-p
,(bV;S
AAiS
3iMB:@
ZZYXYY
YAZAZ_
;;Xc*&
HHeA_5
PPK1qI
8qA]F3
v?;DS4
ROSJ<\
YXZYYXZY
pZZYXYZ
ZZZXXZZ
htB:U+j
*]CoQB
1,Ngt(@,
?OSUQ\
__"M!Y
&9S_Y$i
3sqs,^
7QS:ST
qME+mZ
kSG]-D
lsQzf
hLfRn`dY
{vSBF=
A{kQWP
YXYXXX
5EHGKh
t %6$l
3O'l.&e
L%pu|X
1E}|_!
<,l+v6,
f.SuPF
EG&P5x
"Oo@qM0&f
,sJqHS
uI@jC,
`Z^g<`
Q.G:HS
xQHv>p
goKtWh<
0oNKaf
*b7 9\E5
LbaP_$P
ZYXXXX
xQlD(J
,#`t%S{
pRlQ`M
HeapFree
J)rii){ON
`,bYZYX
<R}Rh-
a(>vD"
|so@X8{L
AXZAXXA]
&xk2Ypo
*9US!I/
ouS#2T
4+5& E
tNsS= `
RklQGC&
/EYv{?
0(u[u'
XXXZXZY
j1 XZX
t\,B8X
+ULlQQ
cwIx Bz
I|%+*9
t@l<hk$
(`($-<
AX[YA[A\
t]DXZA^A]YY
ZZXYXZ
XXXXYXZY
7,TvgG4
$yk<3
2f!l'x
M;.j |]
|[ww@*
41A}m`A
VWnD)N
^(A,&_
G+}hQ;
T58u{3
'vA<kn|b=
PPIq-}
({SPFh
oH"!ri
0\f|QF1p
6Rd,I`
PPU^aZ<
U+uoQ=:
,.d~{S
qSAIH
u&#S<H0
<HP{U/
/}\k:0
$F' xIL
VSxKam
-!lSdO
:l4LCF
-61c(
v4K_bk
YbiO+0
_,u-#F,
2n]Qa\
yG Fl:m
\oSmrV
tM_&s$
m4{>YS
(K`/}WK
KTMLnP^
SetUnhandledExceptionFilter
mH)BxF
C(cL:z[q
!&X pH
svo?w\v
,TmlDS$
sQYo.X
}Yx+.R
]5%Sw>,r
5]c9CS
FreeConsole
nELmL`
YZZZZX
ZXZA^A\X
7[M; )
ZZXZZY
ZYZXZY
_AXZAZAXZ
|ux>A_
SetLastError
kqM\Sv
<^MSu0^
VHi[q?
XAX_A^
Lz"n=J
js\,sS
FPAZA[[[
9Y"0\?
mD:"cs
!r0mQh
P]A[_A
LockResource
BS;QLS
Im5zz(
s%JNwh
8 .NQc
V|x})~*l
,FT4vS
MB} ZW^
;RBfP-{
QXZYZYZZXXYZX
ExitProcess
dH//tp
F}qz3=
+BYqVo
?vp9"v|gt
-T<}>4
mHkDtu
VXZZXX
PZYZYX
H1wmNB
h<j*0f
QYZYZYZZ
A^AXZAXA^Y[
YYYXYZ
CreateThread
_C4^p@,
+-,@LN
~9n<Vi
#=8c*y
+TnQ4r
OJ>[\/d%FR
XZZYXXX
ARSM/A
szk9$K*`
WQ%o0W
XYYXYX
mQx8pM
,MjQ6\
-MsSd#`
Lu9Sf23
+tO6R4
S@B0HJT
3h [&V
'C:*T9
%mzjQm
XZYXXXY
A\A^_[
gIF `>
zQenG|
XYXXZXZZ
RL),$H
bFL2C9
RbROa8&
,-t+>S=E-
FurQQ]
r`@o\S;
R#Se$J
,1ZI1S
gF"*bm
&2Wq[
o8HkXN
LeaveCriticalSection
-Q">d+
8AXA^AXA\Z_AXAX
\B&_1/
SO~6=\"
,+8fnSm
rWvQ`[>
0=N"H,[
F"B<>
mU{=|+$
!p;9L`/
!q5~B#
f5#Of3
BmT_Tj
kg&POb
YYYYZX
p1*mQ
1I ,4`G
!=;k*l
ll)Egd
cl5:R6
ihh7Yo
Dl,Dtk[
4vbQ(w
*P8#f+
F^8=sS
XYZYZXZ
vQOEP
3H>m)e
@F6/@W
=BS3JE
0cBVH
eA[ZA^
^>nSDHx
Dmz]BS
?1fGt&
#Y&f{k
^eSM0v
.,2*[dh
1]gSx3t
:DDd(cy
p+IDDt{:
B> jrxF
w&38knoR
ot}y%N
r:WE1C3
a+<-_AZ[A[
&w/xeU
t,<=Oc
,fW5JS
`(4&X)
gt&mh<
P"[#)T
{<Z`*5
'=N/v4
FQRavV%
PF.*W1
&(U6k<
48F%_:Z$
>6*$K)
'$^8U+V
s6PIl=
_u[@'7
@UY>>-F
{1~d-)|J}k
[.[o7n(6
Sx@\#(
C!2ViP;
G)z%7P
Hq=c'W
{b,5]qX
S/omK=
*P]3s?0
(7iTSi
%-WSO2
Kv{I;&
qicg8)
EMjZwq
.9MFxB
N*0wZK
BkB_7j]
[wa7I]
5&8`=&
=gOFUN
7,sGwA
DYw%.d
2tdMnz
VbsOBJ}
v^.,W'
j]:g+ \}
m$2u{)
x.QJf
n--+E80
U}%s^l
I}C5c<
4j~Hq=
SE]:H~
Z\Zk^R
x)b%IY
4QA"bE
^]_RspQ
K6KN]v
&.3mN.
yH#Dvs
=?80q,"H'~
Q6Vb-`
a!v|=,+
5_QO,v
L|PY5o
D#Ln8K
Uq+ SbA[
cxiK)E
QfF#H"2
t&Orco
=]Zt&E"
z~~c{nG
bl@nkB
?|S?+g
&]ZspM
{e3 1_o%=@
.[h=2]
>]Cw2
(jIgE=
V328~4
z|\BaD@
=3,Jx_;=t
V.\-T|
w+E~QJ
fRJ{Q9
nkJL;'<
Mu7Mg4
!l$a0c_
z3P9lR
h?\+D]
TKW?G
Fdx+c]
YV0<Wuvx
j7_*eyr-
eK!E|:
1L}W] a
A3BSVSBx
<[Si]{
9F([^=
6Jq:s+
pP <7oO
UMNkw!0N
zYF9mU
SI)nZ]s
B?oDsy
]Fk"al
^dZUo=7a>
t4p|/e
O)0HPGt
{/t3d[
a!!~?0
b"4iEB
n4OQ$U
Zc-W-F
,N'z|Sn
Q5%g/\
pOSyP_
Cz a@L
?f/T&:%*
v8N&o3
wQ5-wR
E*/AYZX
ua:6%-
N&M!%_G/
cpk@=C
Ww$7O;
4O7>q#
9Jsxjt
H=qH^S
(/iG3M*
:MOF:j
K>6.sL
VB1<,E
mjKm]m<
XYXXXZ
,vSRBe
YYXZXY
YYZZYX
ZXZYZZY
A]A[YYAX
yZYXZXYZ
1AYA]A_E
T;oQ@J
i*YZXYXZX
sA\A[A[
GetSystemTimeAsFileTime
T+|R}.
q}`JAwO
NccPIv
2rd1`C
HI@1l|
$m&lrR
-E_@%(
PPaqFw
AS~N(G
L,5eJ=]
5lsNbS
--tKB.?NDWR
dg:<Kz
%rS6Ka
Gn|5}
.`SU@s
H,k9cLF0
FAV`am[
[SE,ON
?~4sQa
>g&|wY
/qu/-&
r.YA]ZA\
QM1)FE
XYXXXXY
QYXZYZY
ZoEBT:
1:MJ&K
K^#09)
:[nR1L
=,'ol%
a-3 0$
A/n0FX
\@;!lGL
G(f#w/
j,"PZ+U
G{|cD
pQN&Cd
E$m)`8
2#pS{Mc
ch#*lu
t#,lUf
Hd+P\5
no<5lr
2!/~v.
n'B9S|
]LSvsBS!
s5li#%
u8jc+F~
W4(~4-
A\Y_A\AXA\
YYXXYX
$>8,Sj
ZXXZZYX
fvJ2!Iv
:^&yQ
, Gp"S
ZBt_HS
6_i5`d
Smu9jH
%%?We|c
3`AuQvx
?-fSvCu
,A[X[ZA]A]A[[
f5#Of3
*(&"9R
XXXXYXXY
n%kG`u
fWDS/9W
}Z!9>Grf
P\VRC8
dG6?.,
GetEnvironmentStrings
GetStdHandle
GzBu?lS'FSQ*HW
kU")Lm
eG}S,)n
;%vVj0
TtE)Wx
F_:St:
!!fShOu
S4yD",(
X.V+PLM
AXYA[XA^[_
A^]A[H
2@DttA
<VnJg2
2dnv:)45CJ
Qmc|E(
XZYXXYXYY
v1M2T?aIT
_@:;sA
EnumTimeFormatsW
@&ROR`
ejDy3I
z/mFDw3/
,8J.&S
4S]|*A
h/fS!Au
,}_wtST
)yYXXZ
p8CS9VP
d$IS-JZ
4RHoR?
iKpuM4
3^5Cb{S$
m*R&j]
ghznWo
]?=7^!{
t$0A[L
S*#8j
=#T.#,
HpRW+Z
\*07j
m,s,",
Mg;SV7
OoV6Bg
oSF(h$
F!wJY
/2BqR
{x{U<^
,W-+<S
,YKD-S
Wbq`ge
ZSL+TS
UdrkV7
z=exSe:
N$XwnD
hWC}iR
e7t)#D
g3gA922X&n
J >bdU
Hhd7xo
el DUkW
nm14?d
2l%{ce
ZXXXYX
\^-dGB
[YX_A[A\
Q"W1V
fQvw?S
GetModuleFileNameW
A[_A[AZXY
VirtualAlloc
E(Q,bR
2E;`~Ny
8i8L+Ea~<
#SxYNc
!~SOOm
)l_[`W
g\J'E
Cl{@Ao
C*l(j
aR"l-g
dgJ@dB
GetProcAddress
KJY7lwO
GkBdb\
NR"8TH
a2GfQ$8F
"{0AY^SJ
Y,/wlF(,
9fS\Wu
Q@XXZX
'_ 7RC
|kVRZ\
XZZZXXX
00sl!l
p"fQo0\
VE"+NP
p,Hykb\
i(WqQ>2
%[aSl5r
LocalAlloc
A\YA^[X
YAs<SE
]@qQG5Y
kq =E@L
0IYyX*
OV[IZ2
Dn6XRj
GD:pV<u
YX@l)a
X9,Q]de
-No%~0
]'P6*$
V5bQ'eTb
9#EtM}
!0xHiUE
dF=`o*"
AM:B3x4sG
z9<xDX\
^yq!YH
O+ld4~
\~gFE53
v+tMl5
fhvIpa
z^>o|`
9}V(bU\
0P$"d!
d(w\9w4
\D3G!7+L
rcj{n2
p(R}]*
:khLaN
[mJ^.d
fRsA`I$
F"y0s?
h-b #vs
lIL N]
#j\UCI
8Fvf|d
f+0Wtf
!er.B}
B63fIV
^&/[15?
qYAT"<
e{THW8
h6z|rR&
XOKicKo
yT0*e{
'0jZ3x
+P/=hU
@%9P|!t
>Vy|.
9 QoFd
@v6@+s
<:61->]
g]`U`0
?C"!`9
lUm-6S
FreeEnvironmentStringsA
=*Ph~y
+^'&Kt
DZS:[\
ZYYXZY
[2\A&"3
?dO1!l
ohV+oA
Sswo2,F
"3l?Qt
V`zZcv
]nRo)V
LocalFree
AUA]_A^A[AX
ZYXYYZ
+oi`VBF
,?THa_
fms^K01
0!^@CS
>r#*Hc
top*H-
T0pQ@M(
V3pQAL
YbVTo`
w*'FDIJT
<||T|4
XZYXZY
$$5@h=
@PT=G'
hLBwUa$
g-]jW**
h&tQ~e$
S`S"-+
AXA\AX
CvE]U.
HeapSize
AXXA]A[AXY
l<#T@3`
gt@zc@%
,u4;GS}UT
.\( B@
T1epQ'%
XZXXYZX
1tS\zS
cx=`+,
GetCurrentThreadId
&S/F92
c\tS*2g
h@xo2S
x\9e:u
fJs||{
<HfF\]
Ll;<UK
ZXXYYY
N3$,YI
RDB&v
i8[S VH
,T.J|S
):4OQX
fCK%&K.
-SUpQH2W
7xwBS
.2H ;yk
Cm!uCs
M<n#qZ
+%=Tfu
lo 6lJ
FB]q/l`
U l@~G
(kdWl^-
@zMlv
%0G2lP7
[3((=zJ"-du
l~#~X
|af+\e
[gdI$%
rNq&u9
JsZ>zt-
ZXZXZZ
A[A[A]A[
toYH,83
YXZXYXYYYZ
`0nR8w
K9+|[W
'H"LC
@N6SJ.
7QyS~?j
oSvz9v
6o<Ag:
o6AknvMr
D'U*F+
Pxi}:iJ
PS)m7
pWk}]%
n\g@N'
YXYXXZ
<}OZ:F
aESWBq
A7gu}w"2
A^AXA[AZY
^EHNg8
F\:Y*l
q7>&6{
l S#>L
]F-o[2?
1Q2CgK^a2
Yh5C$\
.9xSh](
,T&L4S
c-/,WG6
>5Nr Ut
4{8%n6
Yc+_jv
VirtualProtect
ZXXZYXYX
@6S%y
^WSU0D
PY1eQFZ
Mm3n\S
w,rK"l
S<tUt-,hj
G>g2!S]
K'jFa]s
YYYZXZZ
^{S^0h
OgQY@S
,0zu4S
LoadLibraryA
vM<&g8
;X9wRw
SexK1Q
[XYgeq
l,kd~6
@,@?6K
UGf,]\o
TlsSetValue
oTsYZR
5cUB<r
XXXXXY
vUCe{u
07kCu4
,0aG"S
ZXZZYZYYY
uj32n&lW
*bf+T$
GetCommandLineA
JYZZZZ
}8@}`_
+VE6j:K\G
?Ygx;w
,&{-JS$L
w$MqQ'
VD1,$^A
v,3jQ0p8
M}$T8S
,%L%yS
itF,Mt
*ne,B3F|,
,S;vY
,:3W{Sz9h
%7z4`>
m-d-T6
)0pi_?K
5$/-Rr
GetEnvironmentStringsW
Y5%g/\
"S0@=2
Z+T=kS
ZXYXYX
(reeQcF
J;;BS1U}
*S7^}DM
pjqv]C
XXXXXXXZ
P.qU1.
*HKSc&X
aT[:\"J
u PSLa
,0\^[S
}@}S4.n
LCMapStringW
a8,U]I!,^
<faKk6
ibr:$81C@
`mr8g~
psOY$"
8O:Xe-
OgS@6*
r+2&O~
H RY%Ay
t33?la
u[:@,k
LDvQ]c
z8SFVt=
=y@_jfL
)AX,a@iA,
|Y"f.z
)K2,&9m
eNH,^B
t=*6tS
vO!T2E
8l9PT;l 1.
hHrQw(D
ZXXZYXZ
RZXYZY
4*UXYZZ
YA\YA\A][Y
1i\U``
fiYjVn.
ytJi*41
G\]3+l
rETS.l
uk-b+))@
A^ZYA^ZA^
bfjrTt
/+M@,:
EF@~uA7
GT1)@#
$*\0u#
hjWiXm
L\0RZN
-^CZ|W
3K[ 4<
z^FeJY1
GetCPInfo
qJrvsb
(@,?d?
*jPPJ'
P<AC|[
8J"h;>
,Y0+^SyEM
XZZXXXXXX
XA]_AZA^A\
UNYu()
~& ont
{B^J`X
&bo.^*
P$v@aVt
.Xsba+
p_,;dUY
XP,!V>Z,
QJ"B'W
,#*iBSc
OFY&?5
0pPK+Q
c*)V\!
/w{&Ulo
YZZXYZX
FJ"'Y@
~R[+~{
ASLmBU
uQT@^O
&](r&k
a-)MB#
Wko+9N*
RYYXXXY
f.%eQ-
,9bU8S
JC@Q&k
,Ei JSWf
?`NhJ0E
ZXYZZY
4/ATXA[AZ
"z%SxT<
,Xx)mS1G~
RegDeleteKeyA
mJ0 g^
4pBVdID
YI[ {e
,RkmYS"
A[AZA]
!IDvAi*
)]pl88t
:K:1b$
FI"8k@
,gVFuS(f
VQSIA&
V9jQEo
48YDe1
UQE9R&
c8\{S?+
IsValidCodePage
`I"K'f
C)\g8F
h4;'2,
SLDZT
{8C*1
kQS1[V$
]=J@m:=
4 *]zY
/|Y/fD
AUZfD!
*50c~j
:_&b
VoB^S&,M
Gh{QPY
Rz;Pb}L
{/>|X
5kxn`}
4x^%/,wS
$*YZXX
XXXZXY
lstrlenW
H"-D$Gd
@Aw!^S
\zH"Qr
zMR;}:
*- ++t
XXXYZXY
6ZhdQLA
%,r?KS
adZ?Qc-
pDLJg2Y
Cf-E)5@
k*>_BZKk
->z&(f
I0]}y7*
1I2%6>
t]U|%T
(\A3yU
b_wBO9
AU_AX[A^A\A]
SizeofResource
BC4 RS
wyGaSk
)`6TCS
ZZXXYZY
Y5!v*Y
InitializeCriticalSectionAndSpinCount
]X6>0X
A\A\_XAXA[
TJXH&TM
0D\0Y
6S`hfT
4ys=5}
~ wS7Nd
IU:/XW
`a~veS
,&-.8S6
>-MSo$
@ER3G2
i-HlY*?
QRXXZZYX
N[Y,;j
%vXU:V
,TV<.S
ZZXXXYY
<nr"Rw
X*L7mW
P&D_u3
FWvx]a2
,3Ma]M>
!ERVfA
_*9~|to
hxfh+5
$XYXZXZ
(',;2>
qh+>Ao\
\loMlk
zi:N+`
/ZS#;'
O"6~c-=PRA
AZZ[AX
A]A_AZ
0WhO7
]ZV%Z-
(0RWy9
YYYXXXZ
GW_ZA\A]Y
{:JS8C
I.I\}M
MoveFileA
$XZZYYXX
/XYYZX
XYZXZY
xSdu#,
\KS8u|
+m}JG
gg#*xF
[(C4Wu
[{*5zF
GetLastError
]@SC3S
xS"s ~
s!FS:OU
AZA^ZAX_Z
ARA]A]A]AZA^A^
?-)SvC:
/%gCR4
j6nY3}
e?Ib46
9>]-h7
XRAchU6
SU,4T"
as=k\^[
o\7/#|
G["#TA
>T|Q*1
n4O\y^
ZYZYXYZX
d xQv[
/@gSf.t
X"\$\
ExitProcess
)Do,zi+
b<YS+RJ
hQas2~
Fg|Q\2
,PB5sS
\}kFm'
7^^&jO
<D\st<
,w]rSQ
sc2f,2M
lx* y
:MAzDM
p\">Iv
m$A:P.:
{xhQn{
PaZn]+
2H{ik-`
@$MAYIR
<AwT]<
,@N{QTC
z[5gqS
/Nfz54y
YXZXZYY
_AX[YAX_A\A[
u2!RfA
)ASUAVD
.AWAUAQH
8ot&cdg
{u-G2wL
zMJ@M?~
B]/)cC
egMm%M
$\B`$g
4oS@Z|
=6gStXt
!A\[A^[AZZX
)@1Dv;
*]i;|M
M*Tz,KJ
SIE[^,
h'w,|-
<cSYXXZX
qU8$v"
HpAwxw6
pDHNy
&CUuL
*<^&&MML
UISL;Z
sM"2^u
#]uyQ\
Z8F^)I
":<ZZX
QYZZYYX
p/oPm
I^yQ\J
HeapAlloc
th8:Ms
]gsi%!
6'A|z`
'Y[ &J
YXXZYXZ
ahlU:C_g
+SJ*Ll
0jiP:C
95IrNt
-ZnQ2j9
GetProcAddress
ARZXA^
Ry+uQ]
_:p}Q#V
?ZXXYYX
"79+hv
"{L]5La
n4:(t$
Es]m^E
Kf?AS72
7@: h)
guo ]!
XXZZXZXZZ
,$neyS
ZZYXYZX
e&(Z8fl
"kS_Lx
q]"_(w
(SMT{u
sW}zE43
%+42cf
,e4C_S}-L
.Y~W:{
3#~Q*E
A[A]AX[A^
|hdgLo
m4[=jC
8FSRVU
=7K+l>
a6_d0?
ZC*0]4
\[Wel\
q$&jwOl
QW6kR}/
BaV$Cf
YXZZZX
f>iQt^
XZXYZX
1H:4n/
La>"~:sx=C5
,w6t,S
A]A^A\
[ZXYXZ
=8I6:O
w8huG?
8mJq1
lP5w\WB
fo#yJ?
@rVUpu!
Antivirus Signature
Bkav W32.AIDetectMalware
Lionic Trojan.Win32.Generic.4!c
tehtris Clean
MicroWorld-eScan Trojan.GenericKD.69501746
ClamAV Clean
FireEye Generic.mg.0508858aafafa001
CAT-QuickHeal Clean
ALYac Trojan.GenericKD.69503625
Malwarebytes Spyware.RedLineStealer
VIPRE Trojan.GenericKD.69501746
Sangfor Trojan.Win32.Save.a
K7AntiVirus Trojan ( 0059f3ca1 )
BitDefender Trojan.GenericKD.69501746
K7GW Trojan ( 0059f3ca1 )
Cybereason malicious.1a19a4
Baidu Clean
VirIT Trojan.Win32.Genus.TJH
Cyren W32/Kryptik.KKK.gen!Eldorado
Symantec ML.Attribute.HighConfidence
Elastic malicious (high confidence)
ESET-NOD32 a variant of Win32/Packed.VMProtect.AU suspicious
APEX Malicious
Paloalto Clean
Cynet Malicious (score: 100)
Kaspersky Trojan-Spy.Win32.Stealer.evmc
Alibaba TrojanSpy:Win32/Stealer.4fcbf0a4
NANO-Antivirus Clean
ViRobot Clean
Rising Trojan.Generic@AI.90 (RDML:JBGBBVhRb5OnPWTAYF8bsQ)
Emsisoft Trojan.GenericKD.69501746 (B)
F-Secure Trojan.TR/Spy.Stealer.sxywh
DrWeb Trojan.Packed2.45753
Zillya Clean
TrendMicro TrojanSpy.Win32.REDLINE.USPAXIS23
McAfee-GW-Edition Artemis!Trojan
Trapmine malicious.high.ml.score
CMC Clean
Sophos Mal/Generic-S
Ikarus Clean
GData Trojan.GenericKD.69501746
Jiangmin Clean
Webroot W32.Malware.Gen
Avira TR/Spy.Stealer.sxywh
MAX malware (ai score=89)
Antiy-AVL Trojan[Spy]/Win32.Stealer
Kingsoft Clean
Gridinsoft Malware.Win32.RedLine.bot
Xcitium ApplicUnwnt@#wt3dnbz8muwf
Arcabit Trojan.Generic.D4248332
SUPERAntiSpyware Clean
ZoneAlarm Trojan-Spy.Win32.Stealer.evmc
Microsoft Trojan:MSIL/RedLine.MD!MTB
Google Detected
AhnLab-V3 Trojan/Win.Generic.C5498233
Acronis Clean
McAfee Artemis!0508858AAFAF
TACHYON Clean
DeepInstinct MALICIOUS
VBA32 BScope.TrojanPSW.RedLine
Cylance unsafe
Panda Trj/Chgt.AD
Zoner Clean
TrendMicro-HouseCall TrojanSpy.Win32.REDLINE.USPAXIS23
Tencent Win32.Trojan.FalseSign.Swhl
Yandex Clean
SentinelOne Static AI - Malicious PE
MaxSecure Trojan.Malware.300983.susgen
Fortinet Riskware/TrojanSpy_Win32_REDLINE
BitDefenderTheta Gen:NN.ZexaF.36738.@RY@aS1@pxci
AVG Win32:PWSX-gen [Trj]
Avast Win32:PWSX-gen [Trj]
CrowdStrike Clean
No IRMA results available.