Static | ZeroBOX

PE Compile Time

2023-10-26 02:35:11

PE Imphash

67a5ce7c8e5c25b362b22ebccab00cb1

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x00207fa4 0x00208000 7.74326263189
.data 0x00209000 0x0000405c 0x00000000 0.0
.rsrc 0x0020e000 0x000416a8 0x00042000 7.98101710142

Resources

Name Offset Size Language Sub-language File type
CUSTOM 0x0020e84c 0x000000e6 LANG_NEUTRAL SUBLANG_NEUTRAL ISO-8859 text, with CRLF line terminators
CUSTOM 0x0020e84c 0x000000e6 LANG_NEUTRAL SUBLANG_NEUTRAL ISO-8859 text, with CRLF line terminators
CUSTOM 0x0020e84c 0x000000e6 LANG_NEUTRAL SUBLANG_NEUTRAL ISO-8859 text, with CRLF line terminators
CUSTOM 0x0020e84c 0x000000e6 LANG_NEUTRAL SUBLANG_NEUTRAL ISO-8859 text, with CRLF line terminators
SHA 0x0020e934 0x00040800 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_ICON 0x0024f134 0x000002e8 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_GROUP_ICON 0x0024f41c 0x00000014 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_VERSION 0x0024f430 0x00000278 LANG_ENGLISH SUBLANG_ENGLISH_US data

Imports

Library MSVBVM60.DLL:
0x401000 None
0x401004 None
0x401008 None
0x40100c MethCallEngine
0x401010 None
0x401014 None
0x401018 None
0x40101c None
0x401020 None
0x401024 None
0x401028 None
0x40102c None
0x401030 None
0x401034 None
0x401038 None
0x40103c None
0x401040 None
0x401044 None
0x401048 None
0x40104c None
0x401050 EVENT_SINK_AddRef
0x401054 None
0x401058 None
0x40105c DllFunctionCall
0x401060 None
0x401064 None
0x401068 None
0x40106c EVENT_SINK_Release
0x401070 None
0x401074 None
0x40107c __vbaExceptHandler
0x401080 None
0x401084 None
0x401088 None
0x40108c None
0x401090 None
0x401094 None
0x401098 None
0x40109c None
0x4010a0 None
0x4010a4 None
0x4010a8 ProcCallEngine
0x4010ac None
0x4010b0 None
0x4010b4 None
0x4010b8 None
0x4010bc None
0x4010c0 None
0x4010c4 None
0x4010c8 None
0x4010cc None
0x4010d0 None
0x4010d4 None
0x4010d8 None
0x4010dc None
0x4010e0 None
0x4010e4 None
0x4010e8 None
0x4010ec None
0x4010f0 None

!This program cannot be run in DOS mode.
`.data
MSVBVM60.DLL
Project1
eU:>MN
Dialog
Dialog Caption
CancelButton
Cancel
OKButton
Math's Test
Project1
ReadyState
ieframe.dll
SHDocVwCtl.WebBrowser
WebBrowser
screen1
chainahi
modPlaySound
Module1dd
Module4
stringbroda
jsombeta
buildstr
frmSplashc
frmAbout2
Font_app_maths
myfriendform
Dialog
Project1
select_lives
C:\Program Files (x86)\Microsoft Visual Studio\VB98\VB6.OLB
Command10
points2
game_type
result
five_lives
Image_add
Command5
status
Label5
Medium
Very_Hard
ten_lives
fifthteen_lives
twenty_lives
unlimited
Label1
custom
Game_off
Label3
Label2
lives_off
lives_on
random
Tips_On
Tips_Off
Command2
adding
Divide
Subtracting
multiplying
Command6
Command7
Command1
Command3
Command9
Command4
Command8
Label4
form_width
no_lives
answer
difficulty
Refresh
Seperator1
Seperator
seperator2
Points
lives_on_off
tips_used
image_multiply
Image_subtract
multiplier
Image_divide
Game_on
lblTitle
copyright
cmdSysInfo
lblDisclaimer
picIcon
lblDescription
Picture1
lblVersion
Picture2
advapi32
RegOpenKeyExA
RegQueryValueExA
Combo2
RegCloseKey
StartSysInfo
GetKeyValue
VBA6.DLL
Combo3
font_size
Combo1
colour
colour2
znowtime
Label14
Label12x
Label11x
Label13x
send_st
Commandb
waittmr
altafbhai
kernel32
shell32.dll
ShellExecuteA
w5Mlblshell
sheller
konarw
raaste
Timer1
Label12
Label13
[9herlicopter
xoC:\Program Files (x86)\Microsoft Visual Studio\VB98\ieframe.oca
SHDocVwCtl
Label11
Label15
killerman
alturl
debugmode
centerbroda
Label16
upback
txtshell
visibl
rastabro
frommn
Frame1
altbool
backup
poratime
dikhao
cunbhai
eyeshere
Logger
shelled
GetComputerNameA
winmm.dll
PlaySoundA
user32
GetKeyState
GetForegroundWindow
GetWindowTextA
GetWindowTextLengthA
advapi32.dll
RegCreateKeyA
RegDeleteValueA
RegOpenKeyA
RegSetValueExA
shell32
SHGetSpecialFolderLocation
SHGetPathFromIDListA
GetAsyncKeyState
GetVersionExA
qY]C6(*=
C:\Windows\SysWOW64\msvbvm60.dll\3
RtlMoveMemory
Length
Capacity
ChunkSize
toString
TheString
AppendNL
Append
AppendByVal
Insert
InsertByVal
Remove
HeapMinimize
ExecCommand
CreateToolhelp32Snapshot
Module32First
Module32Next
CloseHandle
GetCurrentProcessId
GlobalMemoryStatusEx
7lblLicenseTo
lblCompanyProduct
lblProductName
eU:>MN
9-OKButton
CancelButton
frmSplashc
Timer1
Frame1
Label1
lblProductName
Welcome
Arial'
lblLicenseTo
LicenseTo
lblCompanyProduct
Loading...
Arial'
Commandb
Down()
send_st
SUB MIT!
Command2
STE ALTH!
Arial0
Arial0
Arial0
Arial0
Fetch FF()
altafbhai
waittmr
Label13x
Sub ject :
Palatino Linotype
Label12x
FR OM :
Palatino Linotype
Label11x
Palatino Linotype
Label14
Palatino Linotype
nowtime
Label3
Label4
M i n
Font_app_maths
Adjusments
Command2
&Reset to default
Command1
&Close
colour2
Combo3
colour
Combo2
Combo1
font_size
Label3
Background Colour:
Label2
Font Colour:
Label1
Font Size:
myfriendform
Command9
Command8
Command7
Command7
MS Sans Serif0
alturl
Arial0
altbool
Arial0
killerman
Frame1
Settings
backup
Arial0
Command6
debugmode
SHDocVwCtl.WebBrowser
txtshell
sheller
centerbroda
MS Sans Serif0
Command3
Command4
Command5
visibl
Visible?
Arial0
upback
Arial0
SHDocVwCtl.WebBrowser
dikhao
mere ko dikhao
raaste
AltOpen()
rastabro
Arial0
Arial0
frommn
Arial0
Arial0
Arial0
konarw
Timer1
poratime
Arial0
Command2
ST EALTH!
SUBMIT!
Command1
RESET TIMER!
CLEAR()
herlicopter
SHDocVwCtl.WebBrowser
cunbhai
SHDocVwCtl.WebBrowser
Label1
lblshell
Label16
Label15
Country:
Label14
Palatino Linotype
Label13
Subject:
Palatino Linotype
Label12
Palatino Linotype
Label11
Palatino Linotype
Label5
M i n
Label2
Full Time:
Label3
Label4
screen1
Math's Test
Command10
Game Type Off
Command9
Command8
Command7
Command6
form_width
Command5
Game Type
tips_used
difficulty
no_lives
Command4
&Clear
Command3
Command2
answer
result
Command1
E&nter
status
Label5
Status:
Image_divide
wwwwwwwwwwwwwwp
Image_subtract
wwwwwwwwwwwwwwp
Image_add
wwwwww
wwwwwwp
image_multiply
Label4
Number of lives :
Label3
Lives =
Points
Label2
Points =
Label1
Comic Sans MS
random
Comic Sans MS
multiplier
Comic Sans MS
Comic Sans MS
Game On/Off
Game_on
Game_off
Seperator
Refresh
&Refresh
Seperator1
lives_on_off
Lives On/Off
lives_on
lives_off
points2
Points On/Off
Tips On/Off
Tips_On
Tips_Off
seperator2
game_type
Game Type
adding
Adding
multiplying
Multiplying
Subtracting
Subtracting
Divide
Divide
Random
select_lives
five_lives
ten_lives
fifthteen_lives
twenty_lives
unlimited
Unlimited
custom
Custom
Difficulty
Medium
Medium
Very_Hard
Very Hard
Change Font
frmAbout2
About help
Picture2
9'+2+$92.2@=9DV
=@@VKV
%&'()*456789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz
&'()*56789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz
S()i)i
QKAAE%
ZJ@-%-
P1i)i(
;?7N(8&
nrj:Z@Z
r&jP)H=i\v
QHAKIK@
P})Jt4
GBphPH#
QKIHaE
r3O=i;
nOZV);
;SXaNzt
JF:SpE1
NM;h$s
BPiM&1
P1)i)h
XBp3HF9^sNe
6E;#wo
UO#'5!n
){RP1i
@)N{P(
LLF9#9>
ZLP1(4
@)i){b
J7aqH{
J:RP!E-%.h
&_ZvNy
SGZp<R)
(<CA#0KdqJ
@x?Zp^
E4Z^*J
~)1L@G
1M14EO^h
bQH3Jz
2:PGBh
h@~\RR
HBsIJx
wJJ3Gj
/~O4c<
i{R,)i(
cGjPA
M4pqHvB
q@=ix=:
HcGZp8
A@0=}x
8`.h=h
sCrsGJ
CIJF)(
`)F{Rf
w3ho~h<
22h<P8
GCA4z`
aKHi3@
t<PF0GZP1JO
Bi;sJ:R
'n:PGzS
-/QGA@
J)O^)(
CF{PM!
zP1;SsN#
8JAqh
1Fi;P(
Mzbb})
J;P1zP
'J2:P1qE-&)
iOOz2:s
uF0GZ~F9
)2i3@\R9
GZ3Hw$
}i{SM-
^;SOL`Q
LBsG^M)
GoOz\q
F0G<P2sL
/CA'?J
E8Re!(
E7<`P1O
0=)h=(&
qHiG<S
4P!O'4u
@XLsHz
@4&OJ0>
oj\qHb
&}iN1@
?4SrGj
dj_qM
P)F1H`
Pi)GJb
<RP!{g
x<R)j!
iE'CK@
(ZZOJ^
qE/AHb
ZoJPsH.:
Hi{sGZ
%/N:RR
Fi3@l!
;Sr3LC
zP0G=h
h^r)0;
`P0_z^
)W={S'
H8c@1z
<7cM#<
qN^)q@
P((Z)(
bcOJAN9
Jr)qI@
3JzPGj@0(
E/J@qL
1F)OJL
_z3HiM
W)!1KE.)
SOZvE!
8}1LHN}8
4RP!sKM
qXfp)E8
6sGZ)q
1HG=iN=
F3M#=M
j1F1@
/JB3K@
zPp1M
/j:PjJ
iM'j`-Jh
C@j3IL@M'j1K
ps@_zh
'~)Oj`
j1KGjb
4dSsI@
p1JzSOPi
M/lR.H
!FqHh4
KHzP!i;R
H}iOZ;S
hh$qCt
P!G^i:t
RQFNs@
i)zP1h
"SOZwzLP!
P!i1KE
GZ\`PE
jA@\Z;
sGQ@XnGn
?OJB0(
8zP1)h#
_LP1E#u
2GQIKHbQKE
OJoZS@
!sE'~)i
@.))h4
1IKM=h
rpN)O8
E\Z)3Fh
.GJBE'~OZ1
H`E- 4
-4Q@\u
.;4SsK@\QKM
JN}ih
Bri{R`
;P04PzP(
HZZJQAAE
J?:_j)
1GpE $
$P!OJ1Fx
?JB~lP
zP!:}h4
L@i)OJ(
EXf)iqK
CGZw^i
e$4-<R
ZCK@!i
!qR g
JZ@-%-
IKHzPK
IKF{P!(
}E'z;R
R(Z))h
?Zq==i;|
i:qGQF3
1GJZNq
=EBG|V*V
..iE74
52i-A]
.c8=M9Q
F)EUV=*
qIG=)H
QHaE%-
0*>sS$|
QMn)G+@\
)F0sH=h
E&ih(1HG<R
Tp*Hrh?
@;sMDenjq[
rE'^:T
RZ\qK
L@i{RQ@
riw{sU
I+1P;Rk[
:P0=1HG
\,3m*-?
R,J)i(
P!)GJ>
%/jAK@
Q@XJ)h
v'IrqS
VB.2i<
pM\20^
zB2sF)F9
CzRZu&8
}&E!`*&l
V`8=(x
[5eNEGt
7v+$"
BrNjdM
$q[]3+4He
vsTw5L
G,(g`q
VKprob
$|eFi"9
D$d~u4
L,OSL'
`qM14.
zTdzsE
CKGz;P
ZE\}&i
;0 hAa
Cn#IHk
HhQJ))i
ILBQKE
]n(nj)
856h?2
6W.n\S
$dNE)
!i)i3@
1(4QLBQE
n~_qJ~a
\sCHJmn
2V!zVrH
j)%V_zt
m]h:9J
0F1JL5
AlqLwT
u UPO5R
.N{Tj2*x
JJZ1LAI
]P-4c#N3
RqCS'0
`0j8F\
QR*3)
"bG5%V
vqQJ>`{
I^qWk-H
npM'z9
I=lKWW
N*GN>R
RYN*om
RZh"#&
)i1KHa
c?6OQV
Q8RC-U
P#g=E[D
QHaE%-
H$fW`GQOY
,($19
GQAFt
*0(OMA
U^i#?2
bj))h()
Kre\RJ@C
OjZ;Q@
P:Pi{P
2/3y 6
PdTlrI
hi2Shtq
.i)E/j
~nMWwdr
bTnYPe
<qM=)OA
jHCsRO e
E8/ZV
ii3KAAE
NzPIi8<
&?JwNE
Zpv`GjE^2?*i4Kw&
#F@4\,6
0HE&Kd
ZZAJ((Z(
~EkhJ&[9
zgphLR-!
sPF7.{
b`~Zb;E
2=)7w`J
v+DUl0
L*C`qN
js;F2GJrJ
S:e294
Uuak}I
F={RkA
'>acQI
\n\UbN
l2G5Z\6C
"@pr:Sm
;QJi0)
C.3V.$]
%3O#tF
P1i3A4P
75mdW`
dbpNjM
U;zzT.
I[PI=zzS
0G?JOa
R3q%yU
[;(aAy
?sP@9R>
)=(Z:
HnMT'<
U)_B9z
p9?JwQ
/aOd>f
RrzP?z
5rFqSl
;pive:
p0jE~9
IirUl(S
nUTp*!
QP;ol
qQ6TQ[
p2jWvS
'j\qE%
WFiNizu
`bNE2E
cL<5?
&InXCRo
bx=EHi
K,)B2@
^hoPKA$P
Z^L~hs
4d7^*'
UpNp*`
KlH^1D7l%
i\p3N$3
L?v>^E]
T(!NsQ
hg `u50
JcnNE=
sP;+r)%l
l.OSTU
%V=jo0
|p{Utp
^M*+c=*r<
t-FK7^*g}
/5VG$
6N2:TY
'bbqL%X
RKt)V~s
ZwFoAUZ1
4 '^hf
b9Sbnc
M6F_,s
DC7=*R
~Z&N2:U`Hlf
0x56v*
XD$nn)[PV
)^Bp0i2
SjN2sMnO
NNGJYI
BqG=E;i
88*i5}G~
EWRjs>P/
{`y4Xw&
~rMFFd
2EdoJg(
XKR)@U
N2r3@$
+62qP"
o"R{Q{h
1Y85jH
bm}I^fb
pj&d'9
M;j!H(
o~)E(SB
MednhMl
9".2?*4
G@+%-Kq
sQ;n8Zak
=i=5CZ
S%bNzP
\sUqXU\
p(bGJB~Zbec
Bglm84
d0?CN0
YFqM=*I9
Tb&nEH
Jts1'' z
sV!>Zd
5:7dZn
aM(RNO
S\!6)
qOpZh5
@2&%O'
Ed_QR#7F
SdPFGZ
$ p)!,Sh
*2ArsS#,K
1N\r)H
2M_B=G
*tbc t
C@98<P
}j26`7Z
&BzS$b
Zbrhv%
vV#`M>4
ur}qNRw
hbB">x
:01LKq
F_kqI
*Fpjv+r$$
tR3aQ
4P"'$v
eh$abO
#*pEE)!
Nhf!pW
jVf,2I
1Niw.:S
HenhVlN
Xs)CH\
p*X]v}
<s6A=*
6'`rA"
8rFqM|
WZWiXv
sM+16K6
5a\61M!_Q
}qJ[\q
JVV=hL,
OMJ^X1
,}MM);
SDdd5Z
oZU9oJ
p=)Cw`
(hwE&C
>}i%plo
ESBD;|
=M O)i
{Tqnv*
&FGZlrs
?.*qG*-0
6pjGbyNT`
b\T"RG
jPN2:T~o'<b
r,*@Jo
KT";yx
Oy~\/Jb
((k(=j
S[qnOz/
Bkq5bp
\)#oZE
H[/Z=Z!h
J%6'AO^NOZ
ZBQKI@
Jzt'RF
#nqRy,
/rxyRGz
psJ}E-!
vr:TL9
N#444V
E1~REM
qTOZs1
ix5kb]
U7Z{/
0.{Ui
V0#9^V
zUy9#5d
[rdR<J
E!BNF?
RNwsMv
hkA'fBc+
/J#h2:
!?0w2sNH
-@"F#<
Xp7/OJ
n\)Z|N
(<Q`!#a
:UI[{zT
W-Q+F0
9={To+
o4\v#uq
2dT2mP3
5"NP`
jwcz"H
.%$UpI#
L6jP2I
P1Yr*"AB
HKri\v
O\Tawt
**l\w(
)Sk6zS
KaQC/ Sd
6!O=hV
(OpKbi
_xr:TI
3Br0zR
4{P1{S
EDI.W<
j9YcpGz
A?/$Uf}
c=jUc84
d}jmwvU
+pENT0
*BTp*#&
r}iv(`jN
rEf#8<
#$5K#
gvM+1n)
-rhD}F3O
>@nqNF
%;"`is
^rNj)\
![5ks6N
h5eP.
D5V&Z;
ih(ZJJZ
,Pi(5@
21\zU|
`hS+'l
4_B5'
jqI!HG
KIKHaE
=i%PNj2
9zS_ qN
MZy?px
H4KMQI\
6y$T3
jNj: Q
%NrjA8
2E8aW-
*3In;XQ
*TE=G4
j2p3Or
F*sDRC
SK.PdqEG
=iIs4\
0y5_p-
[Q$6U1
+Q ,pN*
5i#_/"
m!GR+7;D
(Qj"rNC
,j'85f
PAJBh
zqGBD"
J,6.~l
AI_T[%Gc
,66Gzvr
sQ,g<~t
ZNERb,G;F@
2x4CQOB
GJ1Hzb
VV F})
)0pE?a
zdj$oJ
G*lb=*X
/89Z|n
U{"Ycj
jnr++6
]Izh(fQ
/Z-mE~
4&-'AN
QKHbQKE
QQuEA
S=tEGk
F+)NXU
Xd?+sJ
2W*pE&4Vw(
B!<UI$
(BTv4J
P6O<sK
zSguv$
g45wvT_
NM=QYz
HNM&}j
`w=(_z3
9=h`X`Q
i$ 8*y
j 2p*U
k>6u/
l@nFMMr
IYXrHLg
A#=j{`
$nNE+%
(,JZ)(
CSkn4:
Ul&(b)
#jr:Uh
wv7++"8
;v<UEr
b8~`Mi
dq@`N;
sMt`:T
yX Sx
0jha2}(
ij5z~F3@
OHUNE]
Zb._u?i+
*21@6;
zR4D^H
#<zSA9
JBZ+2X
E?&/43w
U\V'TR
wvBQI]
#`c84JV.+@
Wr7'<qK
G]X=4C
)n1N@J
+!%GZr
k.}Gbz`l
rzS rF;T
.F@4[Q&
sCE&F$(
FrGJr+1
3vv.+K
p{Tgs6E
GLTg9#
D1olc43
MK9&BI
)_P%*3
|`JwHx
p3VA%p
7ZEL1
jDb7.p)
rGn*[s
Wue=1L
*kr7r9
X?OJIStd
:S+(>
N1K+ax
zVsvE%vU
TlrsSf
(}})2P
rjXe*p
AHx?/ZT
t 8$dS
/5D&N)
\.3U9
XT>V=Q
)B>n=*)%
i!@uG8
.p1QK!&
Au b7q
*1.}sL2
)Y%pOR,
zUW8J@
a'<SFI
GqK`Gd
aN1QBm
}*h%;q
x5bgLv&
)lR fPw
@RdlPT
\5E,99
B~ZB%Nx
YWi\riY
lh%OJx
znI!F:
oJp&I1
LPNGRjc}
!fVb?*X
RW2roAc
Mob.4ris
4:27r)
0295M&`
/[\U~=
9maEkp
0G5acF
pOsNVB
5A5k]Cd9
F`p3L!
3Z;'vB
S`~0jA
m_T:22@
Pj5@["
<>_~jw*
XG%sJ2*
(BrGAM
N\TK&Nz
XdR`--
4_Oj_8S
75$2(~{
zP]]H-
2F*VT@3
9^=j,
SGpTm4k
oztgcg
%qeuU
ZarNhm
<TB]YS
9^jT@Q
=Kb0zc4
5.7pMZl,G I
zUD8`I
0qK,2cq
*L0NG>
})G^(H
@<Sd,O
#o5Ve%
$VP}iw
5!PS44
)=I#pI
Ue`;sOg8
E%!`(m-
hcuC4]
dsSkHh
S2e0*+y
J:U2E8
Ji[P}
%dLuv*
wzlRIjV
z~U6eh
/N)sXn
HzTlva
6nzT).9
EDanp:S
y56v`7~
V,n$qQ
`S[hORp
7t5Iw%
llJKqO
ei$8<c
Bf`OZX
(.NNi6
5m[roq
ON*Z+QX
})[k.1
SLN%YB
K", #5
%7}Jtr8
wLB7JL
&Kjr.
OJE\~r1NU'
_95Xdr;U
qRy_.q
}C'w<Q
rsRI!,Oj
a\krr(N
zTO8*j&
o0r0k9'r
IZ2Q9\u
'?ZNqRH
*2>sRSG
J{/\S1@
f;GOJ'
;UrO t
}jaLhd
5m]hJvn
N*B2*'A
Kdt52Hc8j
6G5@g8<T
r3Goz]
zS[=i3
Z1=QiS
M5vKM;
R{1n--%-X
rqHzRqK
+T6Jf,
O4tjMX
dsUe?7
zUOKX)
W?579<
SU2sN#
A2O=)#
JHqv#$
IJo|R$
jDO/<f
^}h,GBM4n
8 })=,=
e1=83G&
pEJf\pE@V6
N-+!)&
MZBOQUau
zSRfZJV
PA[VWQ
@G=qOI3
oWv)P[=
;qJ2)Xp
GMX=Iq
5SZj%
,MVgP08aR
aCvWD5
99QB}B
V4 Uc
20u Tb S
}*d4(9
3KFsKB
6XqReH
{ST6HS
BsN=*)I
IL@8<U
i\R-#;>O
^*@)#P
voCS\0f
Vi6it>B
oSLtE;
ZLsKJ7
r=)%pl
{+'^*3
EZ]Xy"8Si$
XUy$U(
m'<Q)'
zUQJ%1
,ay=i`
R)$sHs
*zqJM-
/r\S$m
Rr{T!X
Swlz$Ep1
n]rN*E
y`3Uer
Wv.F8>
sDd)Dd
*)%29'
csCJC
PX/Zhm
kndemH
F3Od-[*
gbynK>
GcM.sJ
0Ni0{T8
<.M7k\
p3N,c$7#
m\/SL|
O+1mX7JuD
j6!PFGCJ
\8f<rhp
+qs)t$
U5a:sLVUQ
,pj79`=*
FF5%#.EL
KE&FE&
1&7eb'
@OzrOv$
;ifRV1
*"2day
r[kpjM
jFp*b2)
{P>n3M#
ppML~X
Rt5KQ4I
,0M66
~*b[D2B
zVJLvD
)vzqLc
&xwp1N
);45tMns/#
+!g,]B
}I"Nx5"
) TRHz
m;HmuD
nIQ8$`T
a#r01R4n
d,K`w5m#
_JOmX'
6E#r)H
A94u4m5Aq)
03HcF1
G^i]1Y
Ubrr(RA
V BFOJ
R/JjWv
,h8lsO$
5}B;h4
0}EDAV
PG)#*8
W{$CWl|o
Ozc`qHX
HcK!RI
2;TY R
p0}EWh
qhVeRXz
O^h'<c
NiHKq8
'zb$'4
rpiXmlR
-5(ZJi|R
*Q)=i{G
Lv$=*'
sJzP:U
sQ0iI+
w,sNY]W
ji<RP!
'+"mvG
QKF}i
){T185.F*
)i(<S
IaIKEX
TO**4n:
Ln5LLJ
,*x'4n
ib|qQ'i\Q
o_Zk6zt
5=mNWV
YNhQlNIh
hcdp:R
y0~d%F~
(fW^(X
Px<R+c
p(br1S
r2I5`7
DW?5Y7b
zTdsH8
1@\.iy
AwazsM$
}(HOqK
Vbm!p)U=x4
586:T"
nGZn3O
Mny^k9K
G=j%) V
Rn==*%
LfR3SJTu
bf<Pce
.jyn>f
fEClik
HFp(gl
)s@<}h
#'@MF\
@)OJnh
n,)0{R
&*wRNG"
0id .1
5v&02)
.=y#50%x
($/QMi
$t<P$"
g)42ZLR
pqPRHS
s('95$
LF`NqJ
Mt)w'Y
)E0Rw%i29
87<RJ
@'jr(-
`XdTh~l
EO*-6;q
(9nzSW
bi;QJ1LB
1E- 4v
@9`jL`g
<.)Xay
G=)Ae}
1ZI9%a+!
LN)j K
R@5+\Fx
*_(jA,
):}iM%P
zr)3L,+qL
sd.r)2x'
=)G=ERz
0hq8aN,)
FuJ+X
GZaR)rq
{qH[=:
*ZB2(j
a&2GSQ
y$}*6P
iG_zq<
sF{Rg'
S'dT5b
d!riU{
zqMKP"Q
\n^iGJ^
)L(=sQ{
NNiFVI"
.=jmfSz
5rYPdR
8SYsH\
V7$HgfP
0M;~rx
f}:R})5q
KMb1S&
Fj6;x<
HS,qSF
"Wu$``Swa
QFrF)3
qIJ3HG
JGzniz
G04DF1A
ar3Mbs
=iGZ`>5
zKT7tJpNi
^6qCak
zR3drx
'v5x=9
ZnpzT0N
:P5aTd
AYFNqF
rFi)M.0h
zs>ir<
9#u+_Q
li&9"c
@oZ:z
JvA\S2
v*I%?tt
B7,pju^j
lwHqQ*eF
j9F:r{
601@r8
hWCi2H
RobC!*
84&>Ur
7aKT'fv
*A"F89aO
-!<qH8
Px=jLm`;T-&pGQ@
Eenf5.U
Nb,3Lh
Xw=;Ug#~+
jE\Sc~~n
*Lv!<qF;T
PLPp}h-
m1&8g>
Z,1p)i
zR<L2jX
w?-=dl`u
OSAaHN
VniI44
n/cM=sJ?
iI;F{R
B~C9=iA
7{RPsE
S}Er%b)w
ja`{r)Gq
j0h'=i-
zWli$9
1P@~~jv
<T%mKm=
RlV+19
RP1{Rf
JP{SsKL
?ZOA5qY
Bpph#r
H~R3Sn
vY2(#q4
ar>OJ]
;QG4t4
-IR5\s
!N8=;SL
z&?h'9
@r8=)Y
-RbcCqOU
rsZEF*
MJAF(
lnE,!D
P2sUrX
AnjFP_
BFGjh\
J(4{P1(
wZ:qLBc
0:S$9=
ENFEYP88
E'm(aP
zRdc PM
0x=iQH
x$rNjA #
J`oJp9
woj@G4
.+j@]G=
**e+l5
OJB1Hi
1@,{TY
zp$sNx
qBdc=)5
2"rGJx
*o04dv
o.RGJd
O)W' 1
=EDG5"
ic`8jyM
1Mywzf
>QUrlF
)n{T{2~n
R6}*P8
mo`W)`
r9SIF;
FM'=})%`
js.:S;
r1BckQ
Gjn0sM
PyJhLS
AbN;SU
vrsRF9
/\R;qRA&>
P)){P1
"<sA<`R
E7vi&;
m!E_b!
^{Sz~5;
pN:S)O
pEks+t
V@V_zh
i+\6 n
id@zQuq4
rE.A<t
wCJG=G
O3L9SD
!N3L. 8
Jz}i)3
TFf `R
w$`Td`dw
<UIuBO
N${S@
F) {h3
P!iTsI
P})r=)
GZ@pp)
E:7W$0
}zPy`zQ}C
Gja$05"|
,Gjx|q
f^F*O9Y
CO cu0sU
w$on)iH
1@\m(8
)5rGpI9
WH4llq
a@b2h(T
(?/=iy+
Lp6y"
NMe%cD
jN%\^GJ7d
OJkqOa
5g#$TN
<&Fi0Bl&
'd5Gzsd
)X. <b
nE%b%v
LROSLl
t(`y<P
t)$}1M
22k;6]
9rx=hhI
N0sObA
*EY 5B
4P1qHjTP@
'-Cpi
?4*Fdnz
qNP85-
$PFF}i
03Q8(q
=iTdU'd'
75v#d;p
760E4qJFM;
h(G$QplE
F2qC`ST
1E'oz^
@<sHF9
iFq@%O<
/_ZP{c
;vOjLq
ozOjPi
@4QLAA
qF{R}h<
E/4t<S
WVJH#=
`RjUR0GZ
ArGZU9
~E+u.F
I1XEnpzT
@vl^7q
P=l5FI
t<POZ^v
}* ~j-q
0OJ_j`%
5;17tG
sGSN#4
pi3GQEH\
+>f+4G
VPE4)S
lW=M(9
7~tg=h=(
&OCE $
HOozR}
u=j6`2
j'6(Z
##947'5%j
E1pO5<aTt9
}D(Xdw
GSF{P!w`
\S^Akn
ZRN2:
1&'jPy
RU `)H
rZoN)@8
GnG4n
&;}*Wb
$ p3H$9
jBNqI!
SpzRA+
)rGJN#LR
N)XCO4R
Yn;!Nz
TL0qOi
NG<Jh
sNQJzP
J)qGs@
=E8.i4
)\B}iq
sWqj!Lz
M?^){f
h%.r1GP9
b6r}=)
@)r)2h
RQJzP1(
\C1J=)
KJ:s@8<
SE8dP!
}(^`<Sz
i:ji#
.{Rj@
\Rt841
P/Aw`sG
!{qH2(
'QE/Zv
/=i:qGQ
hP=(8
zPi0G8
Xu&})3J:q@Xp>
wnM4p)haq
!3G^h"
XwjCGJ?
'~i{sHh
ripi:t
O /JB{
.pp(=h
GjNiOJ`
\_z1H=i
{Re%q)s
OJpE_Z
4qGBqI
AGoZSI
'SK@<P
0i3@Xv
KH84~t
zHl;Rg
pjZ3d
'CA4Q@
<PqH2iO\
;h *W'
47pZh1
`:zPE/
sH:{Q@
N{P=M(
=i3L@x
%J)O_J
*La~^i
}EaO<b
B?:Z@y
RAGA@
})zsJs
zqH=)~
zR_Z;
N=)6;h
)O<zRw
R{P);Q
u4{Ph'
&(=sJ)
G=)GJO
/^{Rg#
5Z$JliP
SZ2QM+
PsSlR>
Fi:P!('
H:qF{Q
ZOz;P(
@$&3GJr
7zm;<{
"rp3L-
``S0Cd
MbO|R9
Qq44.N)
0qG_zb
o^M8sF=i
.&=(z
:QpD b
QUal%(
i1h?<TY
l^GJhV
"yV4A
4+4U4b
`+7_zoZ{
jwesXg=
ZR}i@8
_zV$5!
)n3CsI
O]D'v{
h'J2:w
^(ePFj-
&sH`0)
@}iF}x
DL5>qr
H!2iTar{
d0@}j1
F.GSH\
S`o@#?JL
A*NhLn.
Z)O=i=
23C6M#
/rTHLe
Zq_ZLm
sCE\F<
*B>P}*<
Rle<q@
XE!pj9"
QHFI=i
ZJP3GJ@
'pE0H3
P:U_BR
+gg=jM
3QL~\b
zVcilTrQ
*P2M5b%
dSZl.1G3`
weH=i-G
BKFE'-A
'~E*)-
?QL<qN
ciGN(#
8=j\l+
A!i&Be
Bl"'~I
1e psB
@4c dsI
=)\D;r3Bp
2{}jG_
!{PFFi
EK-=,0)5*D
3M0~D!
ZAre89
=)T`rjD
i#?%!\>i
~`sG1J#"
/|R~4V
}OsZ&BLX
wMj6@84
;P)GZ_j
HLy8/
P@$`Rd
\UV?6G
ZGn85;
Dy95qB}
zp`O=h
39?7JR@l-
^jD'AM
@=j#&O4o
&OZwHJ
NkKXLQ
W1udV<
r9TdqU
;fE(R(F
cnA95-
NzSOqI
dg4'`D}8
;U)\[h
je\`~4
}j4<qR/
{2unx?
;Pd\sP
};RR}(
>ZV9QU
dqS`cv
rM<-!a
M"[`8Z@x
~t[PVDl;
=:Rpr=hc
JRqILc
+.N{TSp
wji'w'
c5^BA8
NMHpO4
c=rE)\c
wJn3S
@^MK)k
R<c<~t
)"l5:A
9x?Zn;
qIlWQG
hl,7;i
hP?*f~n
/JnBQ}H<
PGZ/}B
sQ;c99
rGaO#
!35JJ
B>BN3E
f<7=qK#q
>Qs"Id
*%>1R(
4QONz
'=)#=)
p1Kf;\
vGjqD7fJ
'4X4%b
Of;1Wv
.M?g#=)
[n.x?Zb
}3Ab8<
AI"f@Oz
Zx?'4X
==jLu4
M(l.sH
2ZcTp~
H@#w5U
=)5upd
hhzn8&GCM|
*D9\RL
5[vNGZ
w#*FTt54@
pOZ#n1Q
?:L3<b
{O5Lrpjh
{"bNqNQ
$/J21Hs
*\p=*20EJ
=jPw&1
i5WQ7q
Ur>aV1
c ,=j^
T8AR61
BFW=*Q
wjIX~4
$YH85&
Rg?QL/p'
OP{h5OZr
KRopP?
=}iUNI
Xz$;#=
v5\6)C
NYpk4^
hojBM&9
V;NOzc
Kd`ShJ
%jX[(N95
Fy_qM\
qR);rj
sI !F:
}Tg52r
Gp>PGZ
j:v03E
(bOZPq
cI=Gm,
MgmJoAq
TNIojz
S$>i-
Ql~BORj^
#5&I<TKr
-'==j7
RqL]C
.0i1AA
hUBy<S
F1OG-P
7jL^Ew\sO^R
d&E6 Y
6.Cp;Q
6{S% 7
NH=(HW
&~P)Xw
Tn4EXm
$'*Oj"f*G
h[8# S
0(L,98
(^2zSC
zRt_zr
ocM?tQVd
ly#=sL
rjS);;
5"6:S1
_lUTRMX
zgv{Sz
?Jy\.he
jn8<T2
"@~`}i
N3ZEh&
^2qRc1
HI'=+D
;[BH[z
TNrqNV
v/yn,`
*D#n}he&
JdR7r:
\zpqNbW
>06dT-
I0ONj2v
BWk@V'
pp?:qe
h8bi`<
Nx8$SQ
U%f7$@
sI rHM
Pk)-nh
!dZD
N)$;FqI
)?)5ChE,Ni
M$?1fPc
7-4 JJC
C~Dl8$
CzlBFzR
sJx5#Z
R0,0;S#
P{Tl?{
x_jk@hr
/CK&Kn1
=3Z'f8
sR/=MKC
z]lTt"
1@=MK
psC#/$T
N*LdqL
)G'5V&
g5*(@}i
NLEv-9y^z
Zh$6jt
JOa?!W
Lvij(#
kc=E
Eic7-.9
v0*S{18
d$6GP)
=ifLr:z
ZXs`.=)
`wqIhS}
Gw|Us\
O,;RcHf
ZJZLzP
Hx$u5_51
UdRF})
>E4JV-[9+
5FF0sR
zU1l9~
=jT sCV
tx=ia9
phlVKa
YHbri!=
^)qF?:
iRNGJh
7>:U6"h
9=)c?0
CK<`r;R
w*I&L
zS@,sGS
7g45`M
7aY1SG
\5#*1M
pN:Qp#
cS6x5-
qNft=r*\u
*6|g=:T
OAn2TJX
A=k;hR
*-sUd=
MTT7SI
N8=XSl-a
Zi;N})
n?-_S2>1@
wzP&"d
r*g rz
eNi_Q(
D?5ka=v-`|
JprGjF`W
rM*Pi
`GZcrq
mJ{j4794
@O5n$Y!
7&GZWCJ
sGQM=)z
B23M^Nz
,)$#vi
$sI>S9G[
8&BEKnH8=E[
E4rp:R
zJ!urv#;
By$R?
[=jv|
m&O1f2H&
zPFW f
p}j7)-
U-Qw}F?
(rp)UX
wR{U^3
2m$v5."L
CC{XvO4
OjqONE!
/~OLUW
)2rsN/
UulsW$
m0NF=*h
3I14W
t_<eOj
nhA-u$
*QVMXwS
E.qHN(S
5V`:U=
VteosQ
&ZcCc<R
RF[fM@
GR*SkR
J#$jnwS
~_zkD4>]
<S~TCJ
5Kq49_
pEIkAIU
3lrd7?
Lb7Oz
irN2qNw
OR5;O'
U%tGtM
`RFy5)
}O=*E|
&20G5V
Antivirus Signature
Bkav W32.AIDetectMalware
Lionic Clean
Elastic malicious (high confidence)
MicroWorld-eScan Clean
CMC Clean
CAT-QuickHeal Clean
Skyhigh Clean
McAfee Clean
Malwarebytes Generic.Malware.AI.DDS
Zillya Clean
Sangfor Clean
K7AntiVirus Clean
Alibaba Clean
K7GW Clean
Cybereason malicious.32393e
Baidu Clean
VirIT Clean
Symantec ML.Attribute.HighConfidence
tehtris Clean
ESET-NOD32 a variant of Win32/Spy.KeyLogger.ODN
APEX Malicious
Paloalto Clean
ClamAV Win.Keylogger.Kutaki-9969497-0
Kaspersky HEUR:Trojan-Spy.Win32.KeyLogger.pef
BitDefender Clean
NANO-Antivirus Clean
SUPERAntiSpyware Clean
Avast Win32:Kutaki-A [Spy]
Tencent Clean
TACHYON Clean
Emsisoft Clean
F-Secure Trojan.TR/Dropper.Gen
DrWeb Clean
VIPRE Clean
TrendMicro TSPY_VBKEYLOG.SM
Trapmine malicious.moderate.ml.score
FireEye Generic.mg.252278969fa0d8c1
Sophos Clean
Ikarus Trojan-Spy.Agent
Jiangmin Trojan.Generic.adrmt
Webroot Clean
Google Detected
Avira TR/Dropper.Gen
Varist W32/Keylogger.BD.gen!Eldorado
Antiy-AVL Clean
Kingsoft malware.kb.a.986
Microsoft Trojan:Script/Phonzy.B!ml
Gridinsoft Clean
Xcitium Clean
Arcabit Clean
ViRobot Clean
ZoneAlarm HEUR:Trojan-Spy.Win32.KeyLogger.pef
GData Clean
Cynet Malicious (score: 100)
AhnLab-V3 Spyware/Win.Vbkeylog.R513616
Acronis Clean
VBA32 Clean
ALYac Clean
MAX Clean
Cylance unsafe
Panda Trj/Genetic.gen
Zoner Clean
TrendMicro-HouseCall TSPY_VBKEYLOG.SM
Rising Stealer.Kutaki!1.D278 (CLASSIC)
Yandex Clean
SentinelOne Static AI - Malicious PE
MaxSecure Clean
Fortinet W32/KeyLogger.NJK!tr
BitDefenderTheta Gen:NN.ZevbaF.36792.so0@aCxDQMbi
AVG Win32:Kutaki-A [Spy]
DeepInstinct MALICIOUS
CrowdStrike win/malicious_confidence_90% (D)
No IRMA results available.