Static | ZeroBOX

PE Compile Time

2023-10-18 18:08:39

PDB Path

D:\Mktmp\Amadey\Release\Amadey.pdb

PE Imphash

f722e751a647e22fa4d7e966bdaa4f04

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x0003793f 0x00037a00 6.54772578708
.rdata 0x00039000 0x0000ff6e 0x00010000 5.61100748449
.data 0x00049000 0x00002b98 0x00001c00 2.13429069133
.rsrc 0x0004c000 0x000001e0 0x00000200 4.71377258295
.reloc 0x0004d000 0x00002f68 0x00003000 6.60554294957

Resources

Name Offset Size Language Sub-language File type
RT_MANIFEST 0x0004c060 0x0000017d LANG_ENGLISH SUBLANG_ENGLISH_US XML 1.0 document text

Imports

Library KERNEL32.dll:
0x439044 Sleep
0x439048 GetTempPathA
0x439050 GetLastError
0x439054 GetFileAttributesA
0x439058 CreateFileA
0x43905c CloseHandle
0x439060 GetSystemInfo
0x439064 CreateThread
0x439068 GetThreadContext
0x439070 VirtualAllocEx
0x439074 RemoveDirectoryA
0x439078 ReadProcessMemory
0x43907c CreateProcessA
0x439080 CreateDirectoryA
0x439084 SetThreadContext
0x439088 ReadConsoleW
0x43908c SetEndOfFile
0x439090 HeapSize
0x439094 SetFilePointerEx
0x439098 GetModuleHandleA
0x43909c ResumeThread
0x4390a0 GetComputerNameExW
0x4390a4 GetVersionExW
0x4390a8 CreateMutexA
0x4390ac WaitForSingleObject
0x4390b0 PeekNamedPipe
0x4390b4 CreatePipe
0x4390b8 VirtualAlloc
0x4390c0 WriteFile
0x4390c4 VirtualFree
0x4390cc WriteProcessMemory
0x4390d0 GetModuleFileNameA
0x4390d4 GetProcAddress
0x4390d8 ReadFile
0x4390dc GetConsoleMode
0x4390e0 GetConsoleCP
0x4390e4 FlushFileBuffers
0x4390e8 GetProcessHeap
0x4390f8 GetOEMCP
0x4390fc GetACP
0x439100 IsValidCodePage
0x439104 FindNextFileW
0x439108 FindFirstFileExW
0x43910c FindClose
0x439114 HeapReAlloc
0x439118 SetStdHandle
0x43911c GetFullPathNameW
0x439124 DeleteFileW
0x439128 EnumSystemLocalesW
0x43912c GetUserDefaultLCID
0x439130 IsValidLocale
0x439134 HeapAlloc
0x439138 HeapFree
0x43913c WideCharToMultiByte
0x43914c SetLastError
0x439154 CreateEventW
0x439158 SwitchToThread
0x43915c TlsAlloc
0x439160 TlsGetValue
0x439164 TlsSetValue
0x439168 TlsFree
0x439170 GetModuleHandleW
0x439174 EncodePointer
0x439178 DecodePointer
0x43917c MultiByteToWideChar
0x439180 CompareStringW
0x439184 LCMapStringW
0x439188 GetLocaleInfoW
0x43918c GetStringTypeW
0x439190 GetCPInfo
0x439194 SetEvent
0x439198 ResetEvent
0x4391a0 IsDebuggerPresent
0x4391ac GetStartupInfoW
0x4391b8 GetCurrentProcessId
0x4391bc GetCurrentThreadId
0x4391c0 InitializeSListHead
0x4391c4 GetCurrentProcess
0x4391c8 TerminateProcess
0x4391cc RaiseException
0x4391d0 RtlUnwind
0x4391d4 FreeLibrary
0x4391d8 LoadLibraryExW
0x4391dc ExitProcess
0x4391e0 GetModuleHandleExW
0x4391e4 CreateFileW
0x4391e8 GetDriveTypeW
0x4391f0 GetFileType
0x4391fc GetModuleFileNameW
0x439200 GetStdHandle
0x439204 GetCommandLineA
0x439208 GetCommandLineW
0x43920c WriteConsoleW
Library USER32.dll:
0x439228 GetSystemMetrics
0x43922c ReleaseDC
0x439230 GetDC
Library GDI32.dll:
0x439030 SelectObject
0x439034 CreateCompatibleDC
0x439038 DeleteObject
0x43903c BitBlt
Library ADVAPI32.dll:
0x439000 RegCloseKey
0x439004 RegGetValueA
0x439008 RegQueryValueExA
0x439010 GetSidSubAuthority
0x439014 GetUserNameA
0x439018 LookupAccountNameA
0x43901c RegSetValueExA
0x439020 RegOpenKeyExA
Library SHELL32.dll:
0x439214 SHGetFolderPathA
0x439218 ShellExecuteA
0x43921c None
0x439220 SHFileOperationA
Library WININET.dll:
0x439238 HttpOpenRequestA
0x43923c InternetReadFile
0x439240 InternetConnectA
0x439244 HttpSendRequestA
0x439248 InternetCloseHandle
0x43924c InternetOpenA
0x439250 HttpSendRequestExA
0x439258 HttpEndRequestA
0x43925c InternetOpenW
0x439260 InternetOpenUrlA
0x439264 InternetWriteFile
Library gdiplus.dll:
0x43926c GdipSaveImageToFile
0x439274 GdipDisposeImage
0x439280 GdiplusShutdown
0x439284 GdiplusStartup

!This program cannot be run in DOS mode.
)@"o,A
o-A.o,A
o,ARich
`.rdata
@.data
@.reloc
j h0VD
j h\VD
j(h WD
jDhhWD
j<hDXD
jLh@\D
jPhP]D
j@hX^D
j hL`D
j?hhaD
CM @PRj
E Ph bD
E0SVW3
E h$bD
CE8SVWh$bD
E h$bD
E h$bD
E h$bD
QQSVWd
j<hxyD
URPQQh`
;t$,v-
UQPXY]Y[
SVWj03
WWWSHSh
WPWWWS
:u"f9z
F4_^[]
<ItC<Lt3<Tt#<h
A<lt'<tt
ARPRQh
PPPPPPPP
SWt@jU
_tqPVj@
<at.<rt!<wt
<=upG8
j,hP|D
QQSVj8j@
Wj0XPV
SPjdVQ
PPPPPWS
PP9E u:PPVWP
u kE$<
zSSSSj
f9:t!V
NX9^`t1
;V\uYW
u2Vj@h
9C`u99C\t4
u29K\t-
PPPPPPPP
D8(Ht'
unknown error
bad allocation
address family not supported
address in use
address not available
already connected
argument list too long
argument out of domain
bad address
bad file descriptor
bad message
broken pipe
connection aborted
connection already in progress
connection refused
connection reset
cross device link
destination address required
device or resource busy
directory not empty
executable format error
file exists
file too large
filename too long
function not supported
host unreachable
identifier removed
illegal byte sequence
inappropriate io control operation
interrupted
invalid argument
invalid seek
io error
is a directory
message size
network down
network reset
network unreachable
no buffer space
no child process
no link
no lock available
no message available
no message
no protocol option
no space on device
no stream resources
no such device or address
no such device
no such file or directory
no such process
not a directory
not a socket
not a stream
not connected
not enough memory
not supported
operation canceled
operation in progress
operation not permitted
operation not supported
operation would block
owner dead
permission denied
protocol error
protocol not supported
read only file system
resource deadlock would occur
resource unavailable try again
result out of range
state not recoverable
stream timeout
text file busy
timed out
too many files open in system
too many files open
too many links
too many symbolic link levels
value too large
wrong protocol type
FlsAlloc
FlsFree
FlsGetValue
FlsSetValue
InitializeCriticalSectionEx
InitOnceExecuteOnce
CreateEventExW
CreateSemaphoreW
CreateSemaphoreExW
CreateThreadpoolTimer
SetThreadpoolTimer
WaitForThreadpoolTimerCallbacks
CloseThreadpoolTimer
CreateThreadpoolWait
SetThreadpoolWait
CloseThreadpoolWait
FlushProcessWriteBuffers
FreeLibraryWhenCallbackReturns
GetCurrentProcessorNumber
CreateSymbolicLinkW
GetCurrentPackageId
GetTickCount64
GetFileInformationByHandleEx
SetFileInformationByHandle
GetSystemTimePreciseAsFileTime
InitializeConditionVariable
WakeConditionVariable
WakeAllConditionVariable
SleepConditionVariableCS
InitializeSRWLock
AcquireSRWLockExclusive
TryAcquireSRWLockExclusive
ReleaseSRWLockExclusive
SleepConditionVariableSRW
CreateThreadpoolWork
SubmitThreadpoolWork
CloseThreadpoolWork
CompareStringEx
GetLocaleInfoEx
LCMapStringEx
0123456789abcdefghijklmnopqrstuvwxyz
0123456789abcdefghijklmnopqrstuvwxyz
bad exception
__based(
__cdecl
__pascal
__stdcall
__thiscall
__fastcall
__vectorcall
__clrcall
__eabi
__swift_1
__swift_2
__ptr64
__restrict
__unaligned
restrict(
delete
operator
`vftable'
`vbtable'
`vcall'
`typeof'
`local static guard'
`string'
`vbase destructor'
`vector deleting destructor'
`default constructor closure'
`scalar deleting destructor'
`vector constructor iterator'
`vector destructor iterator'
`vector vbase constructor iterator'
`virtual displacement map'
`eh vector constructor iterator'
`eh vector destructor iterator'
`eh vector vbase constructor iterator'
`copy constructor closure'
`udt returning'
`local vftable'
`local vftable constructor closure'
new[]
delete[]
`omni callsig'
`placement delete closure'
`placement delete[] closure'
`managed vector constructor iterator'
`managed vector destructor iterator'
`eh vector copy constructor iterator'
`eh vector vbase copy constructor iterator'
`dynamic initializer for '
`dynamic atexit destructor for '
`vector copy constructor iterator'
`vector vbase copy constructor iterator'
`managed vector copy constructor iterator'
`local static thread guard'
operator ""
operator co_await
operator<=>
Type Descriptor'
Base Class Descriptor at (
Base Class Array'
Class Hierarchy Descriptor'
Complete Object Locator'
`anonymous namespace'
CorExitProcess
`h````
xpxxxx
(null)
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
[aOni*{
~ $s%r
@b;zO]
v2!L.2
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
UTF-16LEUNICODE
AreFileApisANSI
EnumSystemLocalesEx
GetDateFormatEx
GetTimeFormatEx
GetUserDefaultLocaleName
IsValidLocaleName
LCIDToLocaleName
LocaleNameToLCID
AppPolicyGetProcessTerminationMethod
Sunday
Monday
Tuesday
Wednesday
Thursday
Friday
Saturday
January
February
August
September
October
November
December
MM/dd/yy
dddd, MMMM dd, yyyy
HH:mm:ss
NAN(SNAN)
nan(snan)
NAN(IND)
nan(ind)
_hypot
_nextafter
1#QNAN
1#SNAN
]vQ<)8
|)P!?Ua0
Eb2]A=
u?^p?o4
y1~?|"
?x+s7
?5Od%
?|I7Z#
>,'1D=
?g)([|X>=
~U`?K
:h"?bC
@H#?43
Ax#?uN}*
r7Yr7=
F0$?3=1
H`$?h|
&?~YK|
sU0&?W
<8bunz8
?#%X.y
F||<##
<@En[vP
b<log10
?5Wg4p
%S#[k=
"B <1=
Unknown exception
bad array new length
invalid stoi argument
stoi argument out of range
iostream
iostream stream error
bad locale name
ios_base::badbit set
ios_base::failbit set
ios_base::eofbit set
62b857f66195351f1264d04e26acb1b6
465dbc52837d815b3bc29835a05e6d18
2440a2
f5699455e261cca6e2ba44fc78e6c915
HKhYFfJ0I92YDdu8D8==
Gqen7Ymc8SPNDWbzPxQXOcus4v==
It5tGc==
Pp1i6DZo
EJ2p8M==
GJWp8M==
UNF0SvltItPdGu==
QOSw9TSeGcTYRK==
PROFPAKONRK=
GROvTSKVUIypMUClJLgHYKKJzx9PUoBsDt RNeF=
Dt ROeFd
D BsLc==
PR DPBiwPaT7LQbo3d4seRS4OAdrccSq9UO KZ0t8cTo6zPq3eIieRYgLiVwUS6eUH==
PR DPBiwPaT7LQbo3d4seRS4OAdrccSq9UO KZ0t8cTo6zPq3eIieRYgIShycw tUOK PTSg89zN3ALx2twzeRqoQSJB
PUSe7jWW8q==
TT2hCydyDvHHJybXyt4sOSxk
PR DPBiwPaT7LQbo3d4seRS4OAdrccSq9UO KZ0t8cTo6zPq3eIieRYgLiVw
8eWrTCCnHpGa
Dt BTSCg9wSaDVHTytD=
PyKsTZOc7NK=
PR DPBiwPaT7LQbo3d4seRS4OAdrccSq9UO KZ0t8cTo6zPq3eIieRYgIShycw tUOK OYmg7wuaJgZxPxQrfl==
EMWQLROLPa7AKOnKzH==
SvGt7w==
Pv QPw==
TUKiTy f7wv2QWnu3t0devqb
ONGm6c==
6ySX7ztqGm==
6ySX7DR1Go6=
PxyYTYqp8o6=
EeWr5TV4
8Tii6CBuH93e4Am=
6TWv6i0nHpGoRAnx
MTWXNiKV6NXfMXbE4xQmVLYq3r==
PyKsTZOc7KPb6Avh
LM0yOXVbPS7g6B4m3dP=
LO0m7iJ=
NTGw7C0t8SrZAynmO8==
MMOCPw==
PxGrTCJbPSTd6Rzu4yf=
Mx g8CdtDvbfQa==
HqZtPCdVTMvNRQD63dgThF==
LdmXTC0hUM3eRRy=
Od v8Cdp
PT t5Cdu
LT q6YWq
QTmrLC0hUM3eRRy=
HuFvGvVWI aYGK==
LT r8C0p9sZO7RrqE wmgLq42SBjddRqUd v6O6fTNPbGsrn2UQn2vyC6O0vMI1o
GJ1qFO5o
yHqA6Y VUM3UDOHu3UwofRe42R9wP9Ch7UKqFSWc9wC1AAVm2NP2LbKl5BEkPoCh6Nyi6iKoUJYc
D81HKYdp9wTo6wRZ5OweR8ul4CBubMOc9xms6edqTTPf6wRE4yEe1LTRtb0M
yHpqFO5oGIY=
GJ1Kwc==
KUOg7f5s
GdqtTs==
LT r8C0p9sZO7RrqE wafwuw2RNjewmq7 1FTiY9oZg4XzyBOQrevOyPX9m0MR=
PSmQPA0ISuLV5hzq2eMweRY44h9uVSWVSvOs6jWt7Sv7IWZy3yQT2MCSPR1nYuOq7OCY8C0tOcDnRK==
LT q7D0VUNHIQQRq
TNKgTC0hUSfj3gjx2N0ofwyC4YR3edeZ OptGPNuItSWFt7 BM3=
GOWr5SSqUwSn
PSmQPA0ISuLV5hzq2eMweRY44h9uVSWVSvOs6jWt7Sv7NQVu4xQdYbeoQR9eRQ JQwKMNBCRNKPzLVm=
PSmQPA0ISuLp4hHD2TsM2MJADyFeVSWt9dmgTTS8LcDt3QDJ1OIpevy9OAZr0wWq
QdmhTSdEMq==
SuBtGzF=
MxWjST0n9vLf6BHu2d9sOaaWQSNxcxWV6N r
MxWjST0n9vLf6BHu2d9sOaeWQSNxcxWV6N r
PR DPBiwPaT7LQbo3d4seRS4OAdrccSq9UNdNhW8LTTs5gLz4wUefcGt3X4=
PyKsTD0e9u3b4QK=
HaBuIM==
HaBvGc==
HaBuHc==
LUWv7i0p9uHV3Qnp
UNOl6uGUauLvIUnYytD=
D BsOyFd
LRGANBRbD7==
JcJfCydA
JbZfCydA
E 0C9CqV
8eWrTCCnHpGoRR8q
DeSe7Yym6MvmAwZryt4ieHtm
D BjDeGV6MZf4XL5yuz M8RkQBVuJq==
E ZdLTmk9sG=
D BjDeGtUM2a
DtZjCw==
Px 0TTOu6wTm4wVq5xP=
GNW1TSSW9wjp4hrA2xgchHuCQR1xewWu6NerTSVbGKXj4AKly8==
8TiY8CWq9S2aDRClBOL Pp==
8UR67s==
ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/
abcdefghijklmnopqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVWXYZ0123456789
NtUnmapViewOfSection
ntdll.dll
invalid string position
string too long
0123456789ABCDEF
D:\Mktmp\Amadey\Release\Amadey.pdb
.text$di
.text$mn
.text$x
.text$yd
.idata$5
.00cfg
.CRT$XCA
.CRT$XCAA
.CRT$XCC
.CRT$XCL
.CRT$XCU
.CRT$XCZ
.CRT$XIA
.CRT$XIAA
.CRT$XIAC
.CRT$XIC
.CRT$XIZ
.CRT$XLA
.CRT$XLZ
.CRT$XPA
.CRT$XPX
.CRT$XPXA
.CRT$XPZ
.CRT$XTA
.CRT$XTZ
.rdata
.rdata$T
.rdata$r
.rdata$sxdata
.rdata$zzzdbg
.rtc$IAA
.rtc$IZZ
.rtc$TAA
.rtc$TZZ
.tls$ZZZ
.xdata$x
.idata$2
.idata$3
.idata$4
.idata$6
.data$r
.rsrc$01
.rsrc$02
ReadFile
GetModuleFileNameA
WriteProcessMemory
SetHandleInformation
VirtualFree
WriteFile
Wow64DisableWow64FsRedirection
VirtualAlloc
CreatePipe
PeekNamedPipe
CreateMutexA
WaitForSingleObject
GetVersionExW
GetComputerNameExW
ResumeThread
GetModuleHandleA
SetCurrentDirectoryA
GetTempPathA
Wow64RevertWow64FsRedirection
GetLastError
GetFileAttributesA
CreateFileA
CloseHandle
GetSystemInfo
CreateThread
GetThreadContext
GetProcAddress
VirtualAllocEx
RemoveDirectoryA
ReadProcessMemory
CreateProcessA
CreateDirectoryA
SetThreadContext
KERNEL32.dll
ReleaseDC
GetSystemMetrics
USER32.dll
DeleteObject
CreateCompatibleDC
SelectObject
CreateCompatibleBitmap
BitBlt
GDI32.dll
GetSidIdentifierAuthority
RegOpenKeyExA
RegSetValueExA
LookupAccountNameA
GetUserNameA
GetSidSubAuthority
GetSidSubAuthorityCount
RegQueryValueExA
RegGetValueA
RegCloseKey
ADVAPI32.dll
ShellExecuteA
SHGetFolderPathA
SHFileOperationA
SHELL32.dll
HttpOpenRequestA
InternetWriteFile
InternetOpenUrlA
InternetOpenW
HttpEndRequestA
HttpAddRequestHeadersA
HttpSendRequestExA
InternetOpenA
InternetCloseHandle
HttpSendRequestA
InternetConnectA
InternetReadFile
WININET.dll
GdipSaveImageToFile
GdipGetImageEncodersSize
GdipDisposeImage
GdipCreateBitmapFromHBITMAP
GdipGetImageEncoders
GdiplusShutdown
GdiplusStartup
gdiplus.dll
WideCharToMultiByte
EnterCriticalSection
LeaveCriticalSection
DeleteCriticalSection
SetLastError
InitializeCriticalSectionAndSpinCount
CreateEventW
SwitchToThread
TlsAlloc
TlsGetValue
TlsSetValue
TlsFree
GetSystemTimeAsFileTime
GetModuleHandleW
EncodePointer
DecodePointer
MultiByteToWideChar
CompareStringW
LCMapStringW
GetLocaleInfoW
GetStringTypeW
GetCPInfo
SetEvent
ResetEvent
WaitForSingleObjectEx
IsDebuggerPresent
UnhandledExceptionFilter
SetUnhandledExceptionFilter
GetStartupInfoW
IsProcessorFeaturePresent
QueryPerformanceCounter
GetCurrentProcessId
GetCurrentThreadId
InitializeSListHead
GetCurrentProcess
TerminateProcess
RaiseException
RtlUnwind
FreeLibrary
LoadLibraryExW
ExitProcess
GetModuleHandleExW
CreateFileW
GetDriveTypeW
GetFileInformationByHandle
GetFileType
SystemTimeToTzSpecificLocalTime
FileTimeToSystemTime
GetModuleFileNameW
GetStdHandle
GetCommandLineA
GetCommandLineW
HeapFree
HeapAlloc
IsValidLocale
GetUserDefaultLCID
EnumSystemLocalesW
DeleteFileW
GetCurrentDirectoryW
GetFullPathNameW
SetStdHandle
HeapReAlloc
GetTimeZoneInformation
FindClose
FindFirstFileExW
FindNextFileW
IsValidCodePage
GetACP
GetOEMCP
GetEnvironmentStringsW
FreeEnvironmentStringsW
SetEnvironmentVariableW
GetProcessHeap
FlushFileBuffers
GetConsoleCP
GetConsoleMode
SetFilePointerEx
HeapSize
SetEndOfFile
ReadConsoleW
WriteConsoleW
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
.?AVinvalid_argument@std@@
.?AVlogic_error@std@@
.?AVlength_error@std@@
.?AVout_of_range@std@@
.?AV_Locimp@locale@std@@
.?AVtype_info@@
.?AVbad_exception@std@@
.?AV?$basic_stringstream@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@
.?AVfailure@ios_base@std@@
.?AVruntime_error@std@@
.?AVbad_alloc@std@@
.?AV?$basic_stringbuf@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@
.?AVios_base@std@@
.?AVerror_category@std@@
.?AV?$ctype@D@std@@
.?AVsystem_error@std@@
.?AV?$basic_iostream@DU?$char_traits@D@std@@@std@@
.?AV_Facet_base@std@@
.?AV_Generic_error_category@std@@
.?AU_Crt_new_delete@std@@
.?AV?$_Iosb@H@std@@
.?AV?$basic_streambuf@DU?$char_traits@D@std@@@std@@
.?AV_Iostream_error_category@std@@
.?AUctype_base@std@@
.?AV?$basic_istream@DU?$char_traits@D@std@@@std@@
.?AV?$basic_ios@DU?$char_traits@D@std@@@std@@
.?AVfacet@locale@std@@
.?AV?$basic_ostream@DU?$char_traits@D@std@@@std@@
.?AV_System_error@std@@
.?AVexception@std@@
.?AVbad_array_new_length@std@@
<?xml version='1.0' encoding='UTF-8' standalone='yes'?>
<assembly xmlns='urn:schemas-microsoft-com:asm.v1' manifestVersion='1.0'>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v3">
<security>
<requestedPrivileges>
<requestedExecutionLevel level='asInvoker' uiAccess='false' />
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
0#0(020C0H0R0c0h0r0
1#1(121C1H1R1c1h1r1
2#2(222C2H2R2c2h2r2
3#3(323C3H3R3c3h3r3
4#4(424C4H4R4c4h4r4
5#5(525C5H5R5c5h5r5
6#6(626C6H6R6c6h6r6
7#7(727C7H7R7c7h7r7
8#8(828C8H8R8c8h8r8
9#9(929C9H9R9c9h9r9
:#:(:2:C:H:R:c:h:r:
;#;(;2;C;H;R;c;h;r;
<#<(<2<C<H<R<c<h<r<
=#=(=2=C=H=R=c=h=r=
>#>(>2>C>H>R>c>h>r>
?#?(?2?C?H?R?c?h?r?
0#0(020C0H0R0c0h0r0
1!13181B1N1X1d1p1|1
2?2d2{2
3(3O3h3484
6+7c7v7
;3;F;];y;
<4<><N<_<
=!='=/=8=@=T=Y=u>|>
?"?)?F?L?S?
2(262D2~2
4B4H4R4h4n4u436[6d6K7y7
#0:0b0
505E5Z5c5p5u5{5
646=6K6
00)000:0D0O0j0
599P9t9
<C<]<r<
=7=c=l={=
=8>S>w>
425-6o6-7o7-8o8,9
9'98:G:X;g;x<
5616:6K6
;'=L=&?
1:1V1\1
243i3~3
4,5D5j5
0*0H0f0
2%2J2h2
3:3D3T3X3\3`3
989<9@9D9{9}:
111;4^4m4|4
7*70797n7
<0U0f0y0
=+=<=@=D=H=L=P=T=X=\=`=
1)232{2
>$><>T>l>
1#1;1X1h1w1
1%2?2Z2m2
5$5t9~9
i0s0x0
0]6g6l6
:$:?:p:v:
;9;X;n;
<0<_<w<
<_=p=w=
?&?C?[?v?
383F3N3T3[3b3g3m3s3x3~3
4"4(4.43494?4D4J4P4U4[4a4f4l4r4w4}4
5!5'5-52585>5C5I5O5T5Z5`5e5k5q5v5|5
6$6K6n6
7-7=7C7J7Q7]7
;);3;:;@;J;Y;a;m;~;
<<(</<:<@<G<
<2=X=g=~=
0<0A0N0
6#6,6A6J6y6
7_7n7w7
8@8I8O8W8\8o8
9!9(9/969=9E9M9U9a9j9o9u9
::&:-:4:;:B:J:R:Z:e:j:p:z:
7+8084888<8
E0f0t0z0
1.181F1a1r1~1
7:^:v:|:
?0?5?\?x?
1K1b1p1|1
21262;2V2c2l2q2v2
3 3%3*3K3[3s3
4A5T5]5j5y5
7(7:7I7
0"1K1r1
44%4@4G4g4
1Z2g2w2
8#8;8V8a8
90:>:G:
=!=S=Z=x>
?)?D?Y?^?h?m?x?
4+404>4L4S4[4s4
636n6s6y6~6
6&7?7D7M7
8$9/999H9P9X9O:
0!060M0p0
43696K6^6
9 9%98;>;
? ?A?j?
0*0:0G0p0w0
11)1K1\1t1
2"2'272<2A2Q2V2[2k2p2u2
3!3&3+3P3l3z3
4O4g4w4
6#6>6M6X6]6b6
77@7P7q7
9;9E9e9o9
:5;?;u;
30B0P0m0u0
1S1Z1c1
9;%;3;8;c;k;
< <+<3<Q<]<s<|<
040X0a0l0
:k;l<|<
><>R>p>{>
>M?R?W?\?n?
2!2+25292?2E2K2Q2x2
3!3.353>3G3W3h3r3|3
45(5f5o5
6c8n8u8{8
9K:U:k:|:
3:4A4H4O4i4x4
475_5O7|7
8g8p8t8z8~8
;0<=<n<|<
2!232E2W2i2{2
3o6A7{7
0"171M1
7O9p9w9
44)4G4R4
4/5G5w5
6#6V6k6|6
7N;U;\;y;
1;2;3e3p3v3
575D5S5
:+:?:a:k:
>=?W?d?
1<2w4}4
5Y5a5i5q5y5
6!6-696Y6
<N=b=s=
2"323<3g3q3{3
3'414;4R4\4
5G5Q5[5r5|5
626<6g6q6{6
6'717;7R7\7
8G8Q8[8r8|8
929<9g9q9{9
9':1:;:R:\:
;G;Q;[;r;|;
<2<<<g<q<{<
<'=1=;=R=\=
>G>Q>[>r>|>
?2?<?g?q?{?
'010;0R0\0
1G1Q1[1r1|1
222<2g2q2{2
2'313;3R3\3
4G4Q4[4r4|4
525<5g5q5{5
5'616;6R6\6
7G7Q7[7r7|7
828<8g8q8{8
8'919;9R9\9
:G:Q:[:r:|:
;2;<;g;q;{;
;'<1<;<R<\<
=G=Q=[=r=|=
>2><>g>q>{>
>'?1?;?R?\?
0G0Q0[0r0|0
121<1g1q1{1
1'212;2R2\2
3G3Q3[3r3|3
424<4g4q4{4
4'515;5R5\5
6G6Q6[6r6|6
727<7g7q7{7
7'818;8R8\8
9G9Q9[9r9|9
:2:<:g:q:{:
:';1;;;R;\;
<G<Q<[<r<|<
=2=<=g=q={=
='>1>;>R>\>
?G?Q?[?r?|?
020<0g0q0{0
0'111;1R1\1
2G2Q2[2r2|2
323<3g3q3{3
3'414;4R4\4
5G5Q5[5r5|5
626<6g6q6{6
6'717;7R7\7
8L8R8\8f8r8
9"9,969
3 3$3(3,3034383<3@3D3H3L3P3T3X3\3`3d3h3l3p3t3x3|3
4 4$4(4,4044484<4@4D4H4L4P4T4X4\4`4d4h4l4p4t4x4|4
5 5054585<5@5D5H5L5P5T5X5\5`5d5h5l5p5t5
5d8l8t8|8
9$9,949<9D9L9T9\9d9l9t9|9
:$:,:4:<:D:L:T:\:d:l:t:|:
4l5t5|5
6$6,646<6D6L6T6\6d6l6t6|6
7$7,747<7D7L7T7\7d7l7t7|7
8$8,848<8D8L8T8\8d8l8t8|8
9$9,949<9D9L9T9\9d9l9t9|9
:$:,:4:<:D:L:T:\:d:l:t:|:
;$;,;4;<;D;L;T;\;d;l;t;|;
<$<,<4<<<D<L<T<\<d<l<t<|<
= =(=0=8=@=H=P=X=`=h=p=x=
> >(>0>8>@>H>P>X>`>h>p>x>
? ?(?0?8?@?H?P?X?`?h?p?x?
0 0(00080@0H0P0X0`0h0p0x0
1 1(10181@1H1P1X1`1h1p1x1
2 2(20282@2H2P2X2`2h2p2x2
3 3(30383@3H3P3X3`3h3p3x3
\6`6d6h6l6p6t6x6
7 7(70787@7H7P7X7`7h7p7x7
8 8(80888@8H8P8X8`8h8p8x8
9 9(90989@9H9P9X9`9h9p9x9
$0(0,0
0585@5D5H5L5P5T5X5\5d5h5l5p5t5x5|5
50686<6@6D6H6L6P6T6X6\6`6d6h6l6p6t6@7D7H7L7P7T7X7\7`7d7h7l7p7t7x7|7
= =$=(=,=0=4=8=<=@=D=H=L=P=T=X=\=`=d=h=l=p=t=x=|=
> >$>(>,>0>4>8><>@>D>H>L>P>T>X>\>`>
1D2L2T2\2d2l2t2|2
3$3*5.52565
6$606<6H6T6`6l6x6
7 7,787D7P7\7h7t7
8(848@8L8X8d8p8|8
9(949@9L9X9d9p9|9
4$4,444<4D4L4T4\4d4l4t4|4
5$5,545<5D5L5T5\5d5l5t5|5
6$6,646<6D6L6T6\6d6l6t6|6
7$7,747<7D7L7T7\7d7l7t7|7
8$8,848<8D8L8T8\8d8l8t8|8
9$9,949<9D9L9T9\9d9l9t9|9
:$:,:4:<:D:L:T:\:d:l:t:|:
; ;(;0;8;@;H;P;X;`;h;p;x;
< <(<0<8<@<H<P<X<`<h<p<x<
= =(=0=8=@=H=P=X=`=h=p=x=
> >(>0>8>@>H>P>X>`>h>p>x>
? ?(?0?8?@?H?P?X?`?h?p?x?
0 0(00080@0H0P0X0`0h0p0x0
1 1(10181@1H1P1X1`1h1p1x1
7 7$7(7,7074787<7@7D7H7L7P7T7X7\7`7d7
7L8P8X8
9$9(989<9@9D9L9d9t9x9
:(:,:0:4:8:@:X:h:l:|:
; ;$;(;,;4;8;<;@;H;`;p;t;
< <8<<<@<D<L<d<h<
=,=0=H=L=d=h=l=p=t=
> >$>(>,>4><>T>X>\>`>d>h>|>
? ?8?H?L?d?t?x?|?
000@0P0T0d0h0x0
10141<1T1d1t1x1
242D2H2X2\2l2p2t2x2
6,7<7H7P7
8 8$8(808D8L8T8\8`8d8l8
9$9(9D9H9h9p9t9
:,:0:8:@:H:L:T:h:
;(;H;h;
<(<H<h<
=(=H=h=p=|=
>0>P>p>
?0?L?P?X?\?`?h?|?
0$0,0@0H0\0
h0l0p0t0x0|0
2$2(2,2H2L2
9(9T9x9
ekernel32.dll
zh-CHS
az-AZ-Latn
uz-UZ-Latn
kok-IN
syr-SY
div-MV
quz-BO
sr-SP-Latn
az-AZ-Cyrl
uz-UZ-Cyrl
quz-EC
sr-SP-Cyrl
quz-PE
smj-NO
bs-BA-Latn
smj-SE
sr-BA-Latn
sma-NO
sr-BA-Cyrl
sma-SE
sms-FI
smn-FI
zh-CHT
az-az-cyrl
az-az-latn
bs-ba-latn
div-mv
kok-in
quz-bo
quz-ec
quz-pe
sma-no
sma-se
smj-no
smj-se
smn-fi
sms-fi
sr-ba-cyrl
sr-ba-latn
sr-sp-cyrl
sr-sp-latn
syr-sy
uz-uz-cyrl
uz-uz-latn
zh-chs
zh-cht
api-ms-win-core-synch-l1-2-0.dll
Capi-ms-win-core-fibers-l1-1-1
api-ms-win-core-synch-l1-2-0
kernel32
api-ms-
mscoree.dll
(null)
((((( H
((((( H
(
BLC_ALL
LC_COLLATE
LC_CTYPE
LC_MONETARY
LC_NUMERIC
LC_TIME
Capi-ms-win-core-datetime-l1-1-1
api-ms-win-core-file-l1-2-2
api-ms-win-core-localization-l1-2-1
api-ms-win-core-localization-obsolete-l1-2-0
api-ms-win-core-processthreads-l1-1-2
api-ms-win-core-string-l1-1-0
api-ms-win-core-sysinfo-l1-2-1
api-ms-win-core-winrt-l1-1-0
api-ms-win-core-xstate-l2-1-0
api-ms-win-rtcore-ntuser-window-l1-1-0
api-ms-win-security-systemfunctions-l1-1-0
ext-ms-win-ntuser-dialogbox-l1-1-0
ext-ms-win-ntuser-windowstation-l1-1-0
advapi32
api-ms-win-appmodel-runtime-l1-1-2
user32
ext-ms-
Sunday
Monday
Tuesday
Wednesday
Thursday
Friday
Saturday
January
February
August
September
October
November
December
MM/dd/yy
dddd, MMMM dd, yyyy
HH:mm:ss
american
american english
american-english
australian
belgian
canadian
chinese
chinese-hongkong
chinese-simplified
chinese-singapore
chinese-traditional
dutch-belgian
english-american
english-aus
english-belize
english-can
english-caribbean
english-ire
english-jamaica
english-nz
english-south africa
english-trinidad y tobago
english-uk
english-us
english-usa
french-belgian
french-canadian
french-luxembourg
french-swiss
german-austrian
german-lichtenstein
german-luxembourg
german-swiss
irish-english
italian-swiss
norwegian
norwegian-bokmal
norwegian-nynorsk
portuguese-brazilian
spanish-argentina
spanish-bolivia
spanish-chile
spanish-colombia
spanish-costa rica
spanish-dominican republic
spanish-ecuador
spanish-el salvador
spanish-guatemala
spanish-honduras
spanish-mexican
spanish-modern
spanish-nicaragua
spanish-panama
spanish-paraguay
spanish-peru
spanish-puerto rico
spanish-uruguay
spanish-venezuela
swedish-finland
america
britain
england
great britain
holland
hong-kong
new-zealand
pr china
pr-china
puerto-rico
slovak
south africa
south korea
south-africa
south-korea
trinidad & tobago
united-kingdom
united-states
CONOUT$
image/jpeg
Antivirus Signature
Bkav W32.AIDetectMalware
Lionic Trojan.Win32.Deyma.4!c
tehtris Clean
MicroWorld-eScan Gen:Variant.Zusy.446510
FireEye Generic.mg.b6d627dcf04d0488
CAT-QuickHeal Clean
Skyhigh BehavesLike.Win32.Downloader.fh
ALYac Gen:Variant.Zusy.446510
Malwarebytes Spyware.Amadey
VIPRE Gen:Variant.Zusy.446510
Sangfor Trojan.Win32.Save.a
K7AntiVirus Trojan-Downloader ( 005790d31 )
Alibaba TrojanDownloader:Win32/Amadey.29bf597d
K7GW Trojan-Downloader ( 005790d31 )
Cybereason malicious.d6f200
BitDefenderTheta Gen:NN.ZexaF.36792.tuW@a0HJc@fi
VirIT Trojan.Win32.Genus.TTW
Symantec ML.Attribute.HighConfidence
Elastic Windows.Trojan.Amadey
ESET-NOD32 a variant of Win32/TrojanDownloader.Amadey.A
APEX Malicious
Paloalto Clean
ClamAV Clean
Kaspersky HEUR:Trojan-Downloader.Win32.Deyma.gen
BitDefender Gen:Variant.Zusy.446510
NANO-Antivirus Clean
SUPERAntiSpyware Clean
Avast Win32:DropperX-gen [Drp]
Tencent Malware.Win32.Gencirc.13f2b747
TACHYON Clean
Sophos Mal/Amadey-C
Baidu Clean
F-Secure Clean
DrWeb Trojan.Siggen21.44100
Zillya Downloader.Amadey.Win32.286
TrendMicro Trojan.Win32.AMADEY.YXDJ5Z
Trapmine Clean
CMC Clean
Emsisoft Gen:Variant.Zusy.446510 (B)
Ikarus Trojan.Win32.Amadey
Jiangmin Clean
Webroot Clean
Google Detected
Avira Clean
Varist W32/Amadey.C1.gen!Eldorado
Antiy-AVL Trojan[Downloader]/Win32.Amadey
Kingsoft malware.kb.a.951
Microsoft Trojan:Win32/Amadey.AM!MTB
Gridinsoft Trojan.Win32.Amadey.bot
Xcitium Clean
Arcabit Trojan.Zusy.D6D02E
ViRobot Trojan.Win.Z.Amadey.314368.B
ZoneAlarm HEUR:Trojan-Downloader.Win32.Deyma.gen
GData Win32.Trojan-Downloader.Amadey.D
Cynet Malicious (score: 100)
AhnLab-V3 Malware/Win.Trojanspy.C5238800
Acronis Clean
McAfee Downloader-FCND!B6D627DCF04D
MAX malware (ai score=89)
VBA32 Clean
Cylance unsafe
Panda Trj/Chgt.AD
Zoner Clean
TrendMicro-HouseCall Clean
Rising Downloader.Amadey!8.125AC (TFE:5:046sIl9HhmS)
Yandex Clean
SentinelOne Static AI - Malicious PE
MaxSecure Trojan.Malware.300983.susgen
Fortinet W32/Amadey.A!tr
AVG Win32:DropperX-gen [Drp]
DeepInstinct MALICIOUS
CrowdStrike win/malicious_confidence_100% (W)
No IRMA results available.