Static | ZeroBOX

PE Compile Time

1970-01-01 09:00:00

PE Imphash

85cddd6092e65c1a58dd1e6e9ab9fc63

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x006385a0 0x00638600 6.09822152557
.data 0x0063a000 0x0005c250 0x0005c400 5.04030909452
.rdata 0x00697000 0x0079a110 0x0079a200 6.07504694138
.pdata 0x00e32000 0x00000d80 0x00000e00 5.22601161257
.xdata 0x00e33000 0x00000b90 0x00000c00 4.18087324948
.bss 0x00e34000 0x0006a8a0 0x00000000 0.0
.edata 0x00e9f000 0x0000004e 0x00000200 0.842686764111
.idata 0x00ea0000 0x00001338 0x00001400 4.29884353986
.CRT 0x00ea2000 0x00000070 0x00000200 0.469239537403
.tls 0x00ea3000 0x00000010 0x00000200 0.0
.rsrc 0x00ea4000 0x00001970 0x00001a00 7.12286416604
.reloc 0x00ea6000 0x0001e468 0x0001e600 5.4427845868

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x00ea413c 0x00001146 LANG_NEUTRAL SUBLANG_NEUTRAL PNG image data, 256 x 256, 8-bit/color RGB, non-interlaced
RT_GROUP_ICON 0x00ea5284 0x00000014 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_VERSION 0x00ea5298 0x000002a4 LANG_DANISH SUBLANG_DEFAULT data
RT_MANIFEST 0x00ea553c 0x00000434 LANG_ENGLISH SUBLANG_ENGLISH_US XML 1.0 document, ASCII text

Imports

Library KERNEL32.dll:
0x140ea045c AddAtomA
0x140ea046c CloseHandle
0x140ea0474 CreateEventA
0x140ea047c CreateFileA
0x140ea0484 CreateIoCompletionPort
0x140ea048c CreateMutexA
0x140ea0494 CreateSemaphoreA
0x140ea049c CreateThread
0x140ea04a4 CreateWaitableTimerExW
0x140ea04ac DeleteAtom
0x140ea04b4 DeleteCriticalSection
0x140ea04bc DuplicateHandle
0x140ea04c4 EnterCriticalSection
0x140ea04cc ExitProcess
0x140ea04d4 FindAtomA
0x140ea04dc FormatMessageA
0x140ea04e4 FreeEnvironmentStringsW
0x140ea04ec GetAtomNameA
0x140ea04f4 GetConsoleMode
0x140ea04fc GetCurrentProcess
0x140ea0504 GetCurrentProcessId
0x140ea050c GetCurrentThread
0x140ea0514 GetCurrentThreadId
0x140ea051c GetEnvironmentStringsW
0x140ea0524 GetHandleInformation
0x140ea052c GetLastError
0x140ea0534 GetProcAddress
0x140ea053c GetProcessAffinityMask
0x140ea054c GetStartupInfoA
0x140ea0554 GetStdHandle
0x140ea055c GetSystemDirectoryA
0x140ea0564 GetSystemInfo
0x140ea056c GetSystemTimeAsFileTime
0x140ea0574 GetThreadContext
0x140ea057c GetThreadPriority
0x140ea0584 GetTickCount
0x140ea0594 IsDBCSLeadByteEx
0x140ea059c IsDebuggerPresent
0x140ea05a4 LeaveCriticalSection
0x140ea05ac LoadLibraryA
0x140ea05b4 LoadLibraryW
0x140ea05bc LocalFree
0x140ea05c4 MultiByteToWideChar
0x140ea05cc OpenProcess
0x140ea05d4 OutputDebugStringA
0x140ea05e4 QueryPerformanceCounter
0x140ea05f4 RaiseException
0x140ea05fc ReleaseMutex
0x140ea0604 ReleaseSemaphore
0x140ea0614 ResetEvent
0x140ea061c ResumeThread
0x140ea0624 SetConsoleCtrlHandler
0x140ea062c SetErrorMode
0x140ea0634 SetEvent
0x140ea063c SetLastError
0x140ea0644 SetProcessAffinityMask
0x140ea064c SetProcessPriorityBoost
0x140ea0654 SetThreadContext
0x140ea065c SetThreadPriority
0x140ea066c SetWaitableTimer
0x140ea0674 Sleep
0x140ea067c SuspendThread
0x140ea0684 SwitchToThread
0x140ea068c TlsAlloc
0x140ea0694 TlsGetValue
0x140ea069c TlsSetValue
0x140ea06a4 TryEnterCriticalSection
0x140ea06ac VirtualAlloc
0x140ea06b4 VirtualFree
0x140ea06bc VirtualProtect
0x140ea06c4 VirtualQuery
0x140ea06cc WaitForMultipleObjects
0x140ea06d4 WaitForSingleObject
0x140ea06dc WideCharToMultiByte
0x140ea06e4 WriteConsoleW
0x140ea06ec WriteFile
0x140ea06f4 __C_specific_handler
Library msvcrt.dll:
0x140ea0704 ___lc_codepage_func
0x140ea070c ___mb_cur_max_func
0x140ea0714 __getmainargs
0x140ea071c __initenv
0x140ea0724 __iob_func
0x140ea072c __lconv_init
0x140ea0734 __set_app_type
0x140ea073c __setusermatherr
0x140ea0744 _acmdln
0x140ea074c _amsg_exit
0x140ea0754 _beginthread
0x140ea075c _beginthreadex
0x140ea0764 _cexit
0x140ea076c _commode
0x140ea0774 _endthreadex
0x140ea077c _errno
0x140ea0784 _fmode
0x140ea078c _initterm
0x140ea0794 _lock
0x140ea079c _memccpy
0x140ea07a4 _onexit
0x140ea07ac _setjmp
0x140ea07b4 _strdup
0x140ea07bc _ultoa
0x140ea07c4 _unlock
0x140ea07cc abort
0x140ea07d4 calloc
0x140ea07dc exit
0x140ea07e4 fprintf
0x140ea07ec fputc
0x140ea07f4 free
0x140ea07fc fwrite
0x140ea0804 localeconv
0x140ea080c longjmp
0x140ea0814 malloc
0x140ea081c memcpy
0x140ea0824 memmove
0x140ea082c memset
0x140ea0834 printf
0x140ea083c realloc
0x140ea0844 signal
0x140ea084c strerror
0x140ea0854 strlen
0x140ea085c strncmp
0x140ea0864 vfprintf
0x140ea086c wcslen

Exports

Ordinal Address Name
1 0x140e9dae0 _cgo_dummy_export
!This program cannot be run in DOS mode.
``.data
.rdata
`@.pdata
0@.xdata
0@.bss
.edata
0@.idata
.reloc
AUATUWVSH
[^_]A\A]
[^_]A\A]
8cpu.u
UUUUUUUUH!
33333333H!
t*H9HPt$
debugCal
debugCal
debugCalH9
debugCalH9
l819uq
debugCalH9
84t6H9
runtime.H9
runtime H
error: H
L9h(t
7H9S u
29t$0u
D9\$Pt
L9\$Pt
7H9S u
H9t$0u
2H9t$0u
L9\$Pt
L9\$Pt
7H9S u
L$xM9H
8H9S u
H9BpwJ@
H9P8tkH
\$(H9C8u
H9D$(t
W0H9P0tK
D$XHcL$
tE8Z t/H
\$0H9K
D$pH9H
D$0H9H
T$ H+:
UUUUUUUUH!
UUUUUUUUH
wwwwwwwwH!
wwwwwwwwH
D$$t H
J0H9J8vxL
H9{8uMf
kernel32H
l32.dll
AddDllDiH
rectory
AddVectoH
redContiH
ContinueH
Handler
LoadLibrH
raryExA
LoadLibrH
raryExW
advapi32H
i32.dll
SystemFuH
stemFuncH
tion036
ntdll.dlH
NtWaitFoH
ForSinglH
eObject
RtlGetCuH
tlGetCurH
rentPeb
RtlGetNtH
tVersionH
Numbers
winmm.dlH
timeBegiH
nPeriod
timeEndPH
dPeriod
ws2_32.dH
_32.dll
WSAGetOvH
verlappeH
dResult
wine_getH
ine_get_H
version
powrprofH
rof.dll
PowerRegH
gisterSuH
spendResH
umeNotifH
ication
GetSysteH
mTimeAsFH
ileTime
QueryPerH
formanceH
Counter
QueryPerH
formanceH
rmanceFrH
equency
runtime.
QxM9Qpu
T$@H9P
runtime.H9
reflect.H9
D$#e+H
I9N0t_H
D$PD9D$T
H9QPt#H
rpH92w
I9N0tSH
\$PH9p
memprofiH93u<
lerau3f
memprofiH
memprofiH
memprofiH
t H9APt
I9@8u3
r09q0s-f
,$L9+w
|$0H98
Q8H+Q(H
H9D$@A
HcD$4f
H9D$@A
\$HH9S@
H9D$8A
runtime.H
gopau$f
runtime.H
|$PH97u*
gopau!f
runtime.H9
gopau&f
runtime.H
runtime.H
G0I9F0t9
runtime.H9
P8H9W8t
f9w2uy
O@H9H@
8noneuZ1
8crasuF
8singu
8systu
l$0M9,$u
l$PM9,$u
X0H;CPtTH
sPH91u
l$ M9,$u
l$0M9,$u
l$PM9,$u
H+t$(H
0Hc\$8H
HHc\$PH
l$8M9,$u
l$8M9,$u
l$(M9,$u
l$ M9,$u
P+8S+t
x H9{ u6H
x(H9{(uWH
Q H9S u*H
Q(H9S(u
Q18S1u
P8H9S8u*H
P@H9S@u H
PHH9SHu
PPH9SPu
H9{(uF
x09{0u>
x49{4u6H
H08K0u
P(H9S(u
H9L$0uQH
H9L$@uuH
L$PH9T$Hu
@2fD9C2u
@0fD9C0u
P@H9S@t
P@H9S@u}H
l$ M9,$u
H9K0uZH
l$ M9,$u
l$ M9,$u
l$ M9,$u
l$ M9,$u
\$0H9S
\$0H9S
L$`u3H
L$`u>H
l$(M9,$u
~(H9z(u&
x H9{ u
-070u!D
-07:00:0M9
-07:00:0L
-07:00:0
Januu!D
-07:00:0
-07:00:0
-07:00:0
Z070u"D
Z07:00:0M9
Z07:00:0L
-07:00:0
-07:00:0
-07:00:0
-07:00:0
2006u-H)
-07:00:0
time.DatH
time.LocL
time.LocH
ocation(H
time.UTCL
Mc$$M9
Mc$$M)
8WITAuP
t$Ow2M
;nullu
8Locau
tzdau;
x8H9{8
l$0M9,$u
l$@M9,$u
l$@M9,$u
l$PM9,$
l$@M9,$u
l$@M9,$u
l$0M9,$u
l$0M9,$u
l$@M9,$u
l$8M9,$u
l$(M9,$
l$8M9,$
l$(M9,$
l$(M9,$
l$0M9,$u
l$0M9,$u
l$@M9,$u
l$0M9,$u
l$(M9,$u
l$(M9,$
l$0M9,$u
l$0M9,$u
l$`M9,$
l$HM9,$u
H9T$ t
L9L$Ht
Z(H9F t
l$@M9,$
l$@M9,$
UUUUUUUUH!
33333333H!
D$HtDD
D$HtSD
l$ M9,$u
l$0M9,$u
l$(M9,$u
l$ M9,$u
l$0M9,$
l$8M9,$u
l$(M9,$u
l$ M9,$
J(H9B t
H8H9X@
P2f9S2u
P@H9S@
struct {H
struct {H
reflect.H9
reflect.
CallSlicL9'u
p8H9x@vYH
uRH9x@
P8H9H@
PPH9SPu
PXH9SXu
Z(H9F u>
\$0H9S0u!H
Q8H9S8u
Q@H9S@u
IHH9KH
l$8M9,$
l$`M9,$u
l$(M9,$u
l$@M9,$u
l$@M9,$u
l$8M9,$u
l$ M9,$u
l$(M9,$u
l$(M9,$
l$8M9,$u
l$@M9,$u
l$0M9,$u
l$@M9,$u
l$@M9,$u
l$8M9,$u
l$0M9,$u
l$(M9,$
l$0M9,$u
l$0M9,$u
l$(M9,$
l$0M9,$u
l$HM9,$u
l$(M9,$u
l$@M9,$u
l$8M9,$
l$0M9,$u
l$8M9,$u
l$(M9,$
l$(M9,$
l$@M9,$u
l$@M9,$u
l$0M9,$u
l$@M9,$u
l$0M9,$u
l$8M9,$u
l$0M9,$u
l$0M9,$u
l$0M9,$u
l$0M9,$u
l$0M9,$u
l$XM9,$
l$0M9,$u
l$8M9,$u
l$0M9,$u
l$@M9,$u
l$@M9,$u
l$(M9,$u
l$(M9,$
l$(M9,$u
l$(M9,$u
l$(M9,$u
l$ M9,$u
l$ M9,$u
l$(M9,$u
l$(M9,$u
l$(M9,$u
l$ M9,$u
l$ M9,$u
l$(M9,$u
l$(M9,$u
l$(M9,$u
l$ M9,$u
l$ M9,$u
H H9K u(H
H(H9K(u
H8H9K8
T$0H)B
T$0H9J
l$ M9,$u
l$0M9,$u
l$0M9,$u
l$0M9,$u
l$0M9,$u
l$0M9,$
l$ M9,$u
|$09w0uc
r49w4u[H
O@H9G8uI
|$09wHu*
rL9wLu
\$0H9S
I H9K
J(H9B t
H 9K u3
H$9K$u+
H(9K(u#
H,9K,u
H09K0u
H49K4u
H 9K u
H(H9K(u
t$PHcX(
t$pHc^(H
;fileu
unixgram
unixpackf
;udp4t
;udp6ui
l$(M9,$u
l$(M9,$u
8..u[H
?fileumH
8\??\t=H
xPH9{Pu~
xX9{Xuv
x\9{\un
x`9{`uf
xd@8{du\H
l$ M9,$u
l$0M9,$u
l$0M9,$u
method:H
l$@M9,$u
l$@M9,$u
l$@M9,$u
l$@M9,$u
(BADINDEI
(MISSINGI
%!(BADWIL
%!(BADPRL
BADPREC)L
%!(EXTRAM
%!(NOVERM
P(H9P@
t$$f9D$$w
f9D$&r
t2PH9rH
d$0t_H
l*PL9jHt"L
~>rTL)
l$@M9,$u
l$ M9,$u
l$ M9,$u
l$ M9,$u
x H9{ u
l$(M9,$u
l$ M9,$u
l$ M9,$u
l$(M9,$u
l$(M9,$u
l$(M9,$u
l$(M9,$u
l$HM9,$
l$HM9,$
l$8M9,$u
l$8M9,$u
l$8M9,$
l$8M9,$
l$8M9,$u
8ignou
8paniu
t$XH95
t H9=`
t$`LcJ
l$xM9,$
l$(M9,$u
l$@M9,$
l$pM9,$
l$(M9,$u
T$0H9J
J(H9B t
L$H9L$L
HcD$LH
:Messf
MapValueM9"
ContainiM9"
H9t$@}
S(H9P(u
PhH9Shu
8-infu
H`H9Hhu9H
H9Hxu,H
protuf
t$09|$0
L$H9T$Lu[H
D9D$`~
D9D$PA
D$@D9L$@~
\$(8S0u
I8H9K8
{(H9x(u6H
T$(H9J0
T$0H9J(
|$09w0uEH
Z@H9G8u3
\$08SHu
QI8SIu
IPH9KP
l$ M9,$u
l$ M9,$u
l$ M9,$u
l$ M9,$u
l$ M9,$u
l$ M9,$u
l$ M9,$u
l$ M9,$u
l$ M9,$u
l$ M9,$u
l$ M9,$u
l$ M9,$u
|$0H9w
D$(f9P(u
P*8S*u
l$ M9,$u
l$ M9,$
l$8M9,$u
|$HH9w@}
;falsu
l$(M9,$u
~ r(H)
l$(M9,$u
l$(M9,$u
l$(M9,$u
~"r9H)
l$(M9,$u
u|<,u%H
Z H9J(u
|$0H9w uFH
B(H9O0u4H
H9r@u&
l$0M9,$u
l$ M9,$u
l$ M9,$u
l$0M9,$
l$ M9,$u
l$pM9,$
l$(M9,$u
l$8M9,$u
l$(M9,$u
l$ M9,$u
l$0M9,$u
l$ M9,$u
l$ M9,$u
l$(M9,$u
l$HM9,$
|$0@8w uPH
r(H9w(uFH
H9O8u0H
wHH9rHu&
P8H9S8u
T$0H9J
zigzag32H9
zigzag64
zigzag64
zigzag32I
zigzag64H
8grouu(
zigzag32I
zigzag64
zigzag32I
zigzag64
8packu,f
zigzag32I
zigzag64
8def=A
8protuOf
zigzag64M
zigzag32L
P0H+P(H
P0H+P(H
W0H+W(H
P0H+P(H
p(H9p0
\$@H9H
P(H9P0u@H
H0H+H(H
W0H+W(H9W
W(H9W0~)H
PXH+PPH
H@H9HX
WXH+WPH
l$ M9,$u
l$ M9,$u
l$ M9,$u
l$ M9,$u
l$ M9,$u
l$0M9,$u
l$0M9,$u
l$ M9,$u
l$ M9,$u
l$(M9,$u
l$(M9,$u
l$ M9,$u
l$ M9,$u
l$ M9,$u
l$ M9,$u
l$ M9,$
l$ M9,$
l$0M9,$u
l$0M9,$u
l$ M9,$u
l$ M9,$u
l$ M9,$u
l$ M9,$u
l$(M9,$u
l$(M9,$u
D$(H9N
H9H sJ
I9@ sML
l$ M9,$u
l$ M9,$u
l$ M9,$u
l$8M9,$u
l$8M9,$u
H95IeK
L9%'?H
H95\4H
T$HHc:
>protu5f
XXX_weakH9
sizeCach
weakFielH9
XXX_weakH
XXX_sizeH9
sizeCachH
unknownFL9
XXX_exte
extensioH9
XXX_exte
XXX_unre
cognizedL9@
XXX_sizeI
unknownFH
XXX_sizeI
unknownF
XXX_sizeI
unknownF
cognized
XXX_exteH
T$0H9J
N(H9F
|$0H9wH
ZhH9F`
|$09wp
T$0H9J
Z(H9F t
l$`M9,$
l$ M9,$u
l$(M9,$u
l$PM9,$
l$@M9,$u
l$@M9,$u
l$(M9,$u
l$(M9,$u
l$(M9,$u
l$(M9,$u
l$HM9,$u
l$ M9,$u
l$HM9,$u
l$(M9,$u
l$(M9,$u
l$(M9,$u
l$(M9,$u
l$HM9,$
l$ M9,$u
l$ M9,$u
l$(M9,$u
l$(M9,$u
l$8M9,$u
l$8M9,$u
l$8M9,$u
l$8M9,$u
l$8M9,$u
l$8M9,$u
l$PM9,$
l$8M9,$u
l$0M9,$u
l$8M9,$u
l$8M9,$u
l$HM9,$
l$0M9,$u
l$(M9,$u
l$8M9,$u
google.pH9
EnumOpti
EnumOptiI
FileOpti
FileOptiL9
EnumOptiI
FileOptif
FieldOpt
EnumOptiI
FileOpti
OneofOptf
EnumOptiI
FileOpti
EnumOptiI
FileOpti
MethodOp
EnumOptiI
FileOptif
EnumOptiI
FileOpti
MessageOL9
EnumOptiI
FileOpti
ServiceOf
EnumOptiI
FileOptif
EnumOptiI
FileOpti
EnumValuL9
eOptionsL9N
EnumOptiI
FileOpti
eOptionsI
EnumOptiI
FileOpti
EnumOptiI
FileOpti
EnumOptiI
FileOpti
EnumOptiI
FileOpti
l$ M9,$u
l$(M9,$u
l$(M9,$u
l$(M9,$u
l$ M9,$u
l$(M9,$u
l$8M9,$u
l$ M9,$u
l$ M9,$u
l$(M9,$u
l$8M9,$u
l$ M9,$u
l$(M9,$u
l$8M9,$u
l$ M9,$u
l$(M9,$u
l$8M9,$u
l$ M9,$u
l$(M9,$u
l$8M9,$u
l$ M9,$u
l$(M9,$u
l$8M9,$u
L$@H9G
L$8H9G
T$(H9J(
Z(H9F t
l$ M9,$u
l$ M9,$u
H3T8 L3L8(I
H1T$0H
H1T$HH
H1T$PH
l$HM9,$u
o\$ fE
o\$0fE
o\$@fE
o\$PfE
o\$`fE
o\$pfE
l$HM9,$u
l$HM9,$u
l$8M9,$u
:T^8rv
D$ffPH
~d$ fE
ot$PfA
S H+Q H
P H1s
l$0M9,$u
l$8M9,$u
l$(M9,$u
l$8M9,$u
l$0M9,$u
l$0M9,$u
l$8M9,$u
l$(M9,$u
l$8M9,$u
l$0M9,$u
l$0M9,$u
l$8M9,$u
l$(M9,$u
l$8M9,$u
l$0M9,$u
;nullu
<Ot-<XtL
l$0M9,$u
l$0M9,$u
l$(M9,$u
P8H9S8u
l$8M9,$u
l$8M9,$u
l$`M9,$
l$8M9,$u
l$HM9,$u
l$0M9,$u
l$0M9,$u
l$8M9,$u
l$8M9,$u
l$`M9,$
l$8M9,$u
l$HM9,$u
l$0M9,$u
l$0M9,$u
l$8M9,$u
l$8M9,$u
l$`M9,$
l$8M9,$u
l$HM9,$u
l$0M9,$u
l$0M9,$u
l$8M9,$u
l$8M9,$u
l$`M9,$
l$8M9,$u
l$HM9,$u
l$0M9,$u
l$0M9,$u
l$0M9,$u
l$(M9,$u
l$0M9,$u
l$8M9,$u
l$HM9,$u
l$8M9,$u
l$8M9,$u
optionalH9
explicit
explicitf
optionalH
explicitH
explicit
optionalH
explicitH
generaliL9
generaliH
printabl
printablH
8numeu
8utf8u
default:L9
default:E1
8tag:A
applicat
optionalH
explicitH
generaliI
printablI
default:I
applicat
applicat
optionalH
explicitH
generaliI
printablI
default:I
applicat
omitempt
omitempt
optionalH
explicitH
optionalH
explicitH
l$8M9,$u
l$8M9,$u
l$ M9,$u
l$0M9,$u
l$ M9,$u
l$8M9,$
l$8M9,$
l$@M9,$u
l$8M9,$
l$@M9,$u
l$8M9,$
l$8M9,$
l$@M9,$u
H9P }]
L$H8L$'u
L$H8L$'u
H9P }N
L9B }Y
L9B }Z
H9P }a
H9P }P
IV for EH
CDSA CTRH
9P-25uP
l$8M9,$u
l$(M9,$u
l$(M9,$u
l$0M9,$
l$0M9,$u
l$@M9,$
l$@M9,$u
l$8M9,$
l$8M9,$u
l$0M9,$
l$0M9,$u
l$@M9,$
l$@M9,$u
l$ M9,$u
\$0H9S
\$0H9S
I H9K
XfffffffH
ffffffffH
l$HM9,$
l$PM9,$
l$`M9,$
T$0H9J
|$HH9w u
8leaku
T$08J
[::ffff:N
invalid J
d PrefixJ
x(H9{(uUH
l$@M9,$u
l$HM9,$u
l$0M9,$u
l$@M9,$u
l$(M9,$u
l$@M9,$u
l$0M9,$u
l$0M9,$u
l$8M9,$u
l$0M9,$u
l$0M9,$u
l$0M9,$u
l$pM9,$u
l$0M9,$u
l$0M9,$u
l$0M9,$u
H9P0u$H
H9P0u$H
H9P0u$H
H9P0u"H
l$8M9,$u
T$08J
D$(uMH
9windu
:andru
:windu
:planu9
:fileu7H
:bindu4H
9solauJf
myhostnaf
M9"u[fA
myhostna
:fileu
:dnuTA
:mdnsu
?filef
myhostnaM9
<$succu fA
<$unav
notfoundI94$t
tryagainM9
?retuu
:fileu
myhostnaD
9tcp4tY
9tcp6tQ
9udp4tG
9udp6t?
9unixt7
unixgramH9
unixpackH9
:dialu2L
unixgram
unixpackL9
8unixtD
unixgramH9
unixpackH9
<$tcu)A
l$(M9,$u
l$(M9,$u
:CNAMuh
8CNAMu.A
>tcp4t
l$0M9,$u
?ipu51
?ipt9f
?tcp4t"
?tcp6t
?udp4t
?tcp4t
?udp4t
?tcp4t
?udp6u~H
\$xu H
9listu8fA
<$dial
8tcp4t
8tcp6u*
8udp4t
8udp6u
l$ M9,$u
l$ M9,$u
:uduxA
:tcp4t
:tcp6t
:udp4t
:udp6u8H
9tcp4t
9tcp6u&
9udp4t
9udp6u
:acceuNf
~NrvH)
unixgramM9/u8I
unixpackM9/u
unixgramL9
unixpack
unixgramL9
unixpack
8tcp4t
8udp4t
8udp4t
unixgramH9
unixpackH9
listubfA
N(H9F u_
N8H9F0u:
H9{(uu
x0@8{0uk
x1@8{1ua
@8{2uUH
x 9{ u
x$9{$u
l$@M9,$u
l$@M9,$u
l$ M9,$
l$ M9,$
l$0M9,$u
l$0M9,$u
l$ M9,$u
l$0M9,$u
l$ M9,$u
l$0M9,$u
l$0M9,$u
l$ M9,$
l$0M9,$u
l$0M9,$u
l$ M9,$u
l$0M9,$u
l$ M9,$u
l$0M9,$u
l$0M9,$u
l$ M9,$
l$0M9,$u
l$0M9,$u
l$ M9,$u
l$0M9,$u
l$ M9,$u
l$0M9,$u
l$0M9,$u
l$ M9,$
l$0M9,$u
l$0M9,$u
l$ M9,$u
l$0M9,$u
l$ M9,$u
l$0M9,$u
l$0M9,$u
l$(M9,$u
l$8M9,$u
l$0M9,$u
l$0M9,$u
l$ M9,$u
l$HM9,$u
l$HM9,$u
l$0M9,$u
l$0M9,$u
l$0M9,$u
l$0M9,$u
l$0M9,$u
l$0M9,$u
l$0M9,$u
l$0M9,$u
l$HM9,$
x H9{ u6H
<$tI<&tE
r8H9Z@t
rpH9Zxt
8..uHL
8//uOH
J(H9B t
l$0M9,$
l$@M9,$
x @8{ u6H
{0H9x0
{PH9xP
xY@8{Y
{xH9xx
l$8M9,$u
QZ^&A!
$D3T$4D3T$ D3T$
D3T$8D3T$$D3T$
D3T$<D3T$(D3T$
$D3T$,D3T$
D3T$0D3T$
D3T$4D3T$
D3T$8D3T$ A
D3T$<D3T$$A
T$ D3T$
$D3T$(A
T$$D3T$
D3T$,A
T$(D3T$
D3T$0A
T$,D3T$ D3T$
D3T$4A
T$0D3T$$D3T$
D3T$8A
T$4D3T$(D3T$
D3T$<A
T$8D3T$,D3T$
T$<D3T$0D3T$
$D3T$4D3T$ D3T$
D3T$8D3T$$D3T$
D3T$<D3T$(D3T$
$D3T$,D3T$
D3T$0D3T$
D3T$4D3T$
D3T$8D3T$ A
D3T$<D3T$$A
T$ D3T$
$D3T$(A
T$$D3T$
D3T$,A
T$(D3T$
D3T$0A
T$,D3T$ D3T$
D3T$4A
T$0D3T$$D3T$
D3T$8A
T$4D3T$(D3T$
D3T$<A
T$8D3T$,D3T$
T$<D3T$0D3T$
$D3T$4D3T$ D3T$
D3T$8D3T$$D3T$
D3T$<D3T$(D3T$
$D3T$,D3T$
D3T$0D3T$
D3T$4D3T$
D3T$8D3T$ A
D3T$<D3T$$A
T$ D3T$
$D3T$(A
T$$D3T$
D3T$,A
T$(D3T$
D3T$0A
T$,D3T$ D3T$
D3T$4A
T$0D3T$$D3T$
D3T$8A
T$4D3T$(D3T$
D3T$<A
T$8D3T$,D3T$
T$<D3T$0D3T$
$D3T$4D3T$ D3T$
D3T$8D3T$$D3T$
D3T$<D3T$(D3T$
$D3T$,D3T$
D3T$0D3T$
D3T$4D3T$
D3T$8D3T$ A
D3T$<D3T$$A
T$ D3T$
$D3T$(A
T$$D3T$
D3T$,A
T$(D3T$
D3T$0A
T$,D3T$ D3T$
D3T$4A
T$0D3T$$D3T$
D3T$8A
T$4D3T$(D3T$
D3T$<A
T$8D3T$,D3T$
T$<D3T$0D3T$
PXH9SXu
P`H9S`u
CERTIFIC
H92u$f
8S(udH
T$0H9P
HHH9pPuDH
WHL9GPt
D$@H9D$
|$`H9\$hu
D$xH9L$Hu
T$0H9J
D$@H9D$
l$`M9,$
l$ M9,$u
l$8M9,$
l$0M9,$u
l$HM9,$u
P(H9S(u$H
SHH9PHu
HHH9P@u H
l$8M9,$u
L)@pL)
2-byD1
$2-byD
nd 3E3K
2-byE3K
te kA3K
>E3C4D
expaD3P A
expaD1
expaD3
expand 3H
2-byte kH
l$ M9,$u
fE9,$u
DOWNGRD
DOWNGRD
<LfD9x
\$xuXH
H9P }S
L9X }_
H9P }N
H9P }N
L9H }j
H9P }N
H9P }N
H9P }N
H9P }V
L9H }_
H9P }N
H9P }V
L9H }j
L9B }Q
H9P }V
L9H }j
L9H }j
H9P }V
H9P }V
L9H }j
L9@ }Y
L9B }Q
H9P }N
L9X }_
L9@ }^
H9P }Y
H9P }N
H9P }N
H9P }V
H9P }H
H9P }V
H9P }H
L9@ }\
H9P }V
H9P }H
H9P }N
L9B }V
H9P }N
H9T$h}:
L9@ }Y
L9B }V
H9T$h}:
H9P }N
H9P }I
H9T$h}:
L9@ }Y
H9P }N
H9P }N
H9T$h}:
L9@ }Y
L9@ }^
L9@ }^
L9@ }^
L9@ }^
L9@ }^
L9@ }^
L9@ }^
H9P }N
L9H }j
L9H }j
H9T$h}:
H9P }a
L9@ }\
L9@ }^
H9P }N
L9@ }_
H9P }N
H9P }N
H9T$h}:
L9@ }Y
H9P }N
H9T$h}:
H9P }N
H9T$h}:
L9@ }\
H9P }N
fE9J@r
:h2u3I
http/1.1M9}
http/1.1
http/1.1
http/1.1
c@fE9"u
SPL9CX
s H9K(t
s8H9K@t
shH9Kpt
H9P }N
D$*tls1f
H9P }a
L9B }V
key expaH9
master sH9
client fH9
server fH9
inisuqf
H9T$x}:
H9T$x}:
H9P }N
H9P }N
H9P }N
CERTIFICL9
CERTIFICL
CERTIFICL
CERTIFICI
PRIVATE L9
PRIVATE I
PRIVATE
PRIVATE L
CERTIFICH92
H9P }T
H9W }W
H9W }H
T$0H9J
T$0H9J
l$ M9,$u
l$`M9,$u
l$ M9,$
l$0M9,$u
l$(M9,$u
l$(M9,$u
H0L+H(I
X0H+X(
l$8M9,$u
l$(M9,$u
us-asciiH9
8utf-u
text/plaH
text/pla
text/plaH
text/plaH
text/plaH
text/plaH
distinctH9
form-dat
form-datL9
form-datH
form-datH
form-datH
L$8tBI
form-datH92u
^0H+^(H
:--u0H
L$@H9N0t
l$0M9,$u
l$0M9,$u
l$8M9,$
l$8M9,$u
l$0M9,$u
l$0M9,$u
l$0M9,$u
l$HM9,$u
l$HM9,$u
XD9X4v
P09P4s
H9pxu*H
L9L$X~
l$8M9,$u
l$8M9,$u
l$HM9,$u
l$HM9,$u
x @8{ u6H
X0H+X(
Q0M+Q(f
l$ M9,$u
l$ M9,$u
l$(M9,$u
l$(M9,$u
l$8M9,$
l$8M9,$
l$0M9,$u
l$0M9,$u
l$ M9,$u
l$ M9,$u
l$ M9,$u
l$ M9,$u
:httpu
:httpuDH
:httpu
:socku
localhosH9
x @8{ u6H
l$ M9,$u
x(H9{(u_
x0@8{0uUH
9httpu&
9httpu
HTTPu3
*http2.TH9
ransportH9H
Z(H9J0t
9HEADt
AuthorizH9
Www-Auth
enticateH9H
8domaf
httponlyL9
samesiteL9
8noneu:H
8striu
; DomainL
; ExpireL
; Max-AgL
; Max-AgL
ax-Age=0L
; HttpOnL
; SecureL
; SameSiH
Site=LaxH
; SameSiH
ite=NoneH
:HEADt9H
:HEADt
:HEADt
:HEADu"H
l$8M9,$u
l$8M9,$u
H)H(H)
Z(H)Z0L
8:metu
8:schu
:authoriM9
L9T$Xu
l$ M9,$u
l$(M9,$u
l$ M9,$u
9readudH
:wsaru:f
l$8M9,$u
l$0M9,$u
l$0M9,$u
8httpf
8httpu$
:httpu
100-contH9
:CONNuXf
8Traif
Content-H9
LenguEf
9closu
Trailer:L9
Trailer:E1
>HEADtmD
l$0M9,$u
trailersH92t=
:httpu
>httpu
>httpu/
T$0H9BH
8Traiulf
Content-H9
Lengu;f
>chunu
8HEADA
l$ M9,$u
l$(M9,$u
l$(M9,$u
>CONNf
8CONNu
8POSTt!
8PATCuRA
8readA
L$,D9I
trailers
l$(M9,$u
t$p9^`
multiparH9
>CONNuMf
HTTP/1.0H9
HTTP/1.1
8CONNu=fA
no-cacheH92
HTTP/2.0H9
>POSTt(I
>PATCuR
no-cacheH92
:chunu
>chunu
X0H+X(H
>HEADu
Trailer:L9
Trailer:E1
l$(M9,$u
L$(H)H(
9POSTuWH
9PRuYA
HTTP/2.0M9#A
9CONNu
9HEADA
Trailer:H9
Trailer:1
keep-aliH92u
8closu
identityH
identityE1
identity
identityH
<$HEADt7L
:HEADtHH
9readu
H9~(t:H
PUT uo
http/1.0f
http/1.1H92
L$0I9H@u
8OPTIu
l$(M9,$u
l$(M9,$u
l$0M9,$u
8tcp4t
>HEAD@
>chunf
>chunu
>chunu
9CONNu
9HEADtd
9DELEu
9SEARu^f
9OPTIuFf
PROPFINDH9
l$ M9,$u
;chunu
;POSTt-
identityH9
;HEADu
8Traiukf
Content-H9
Lengu6f
>HEADuhH
>HEADt'H
?HEADu
Content-
H9D$Pt
>httpu*
H9D$ t
9httpu
9httpu
8GEu]A
8HEADt;
8TRACf
8OPTIu
H9D$pt
l$ M9,$u
l$ M9,$u
T$XH+T$hH
t$XH+t$hH
l$ M9,$u
>httpt
>httpuD
:httpu
H9Jxu=D
D$pI9PxtVD
>HEADt
B0L+B(M
8HTTPu
F0L+F(L9
r0H9r(u
H9JxuQD
H!8K!u
H(H9K(
H9w u+H
r(H9w(u!H
\$0H9S
H 9K u*H
H0H9K0u
H8H9K8
x(H9{(u_
x0@8{0uUH
O(H9G t
\$0H9S
l$ M9,$u
l$ M9,$u
\$0H9S
l$8M9,$u
l$(M9,$u
l$8M9,$u
l$8M9,$u
l$ M9,$
l$ M9,$u
l$(M9,$
l$(M9,$u
l$(M9,$
l$(M9,$
l$(M9,$
l$(M9,$u
l$(M9,$
l$(M9,$
l$ M9,$
l$ M9,$u
l$(M9,$
l$(M9,$u
l$8M9,$u
l$(M9,$u
l$8M9,$
l$8M9,$
l$@M9,$u
l$@M9,$u
l$(M9,$u
l$0M9,$u
l$PM9,$
l$(M9,$u
l$ M9,$u
l$0M9,$u
l$ M9,$u
l$(M9,$u
l$ M9,$
l$0M9,$u
l$PM9,$
l$(M9,$u
l$ M9,$u
l$0M9,$u
l$(M9,$u
l$(M9,$u
l$ M9,$u
l$0M9,$u
l$ M9,$u
l$ M9,$u
l$HM9,$u
l$8M9,$u
l$8M9,$u
l$hM9,$
l$HM9,$u
l$HM9,$u
l$HM9,$u
l$HM9,$u
l$ M9,$u
l$(M9,$u
l$ M9,$
l$0M9,$u
l$(M9,$u
l$ M9,$u
l$0M9,$u
l$ M9,$u
l$(M9,$u
l$ M9,$
l$0M9,$u
l$ M9,$u
l$(M9,$u
l$0M9,$u
l$ M9,$u
l$(M9,$u
l$ M9,$
l$0M9,$u
l$ M9,$u
l$(M9,$u
l$0M9,$u
l$ M9,$u
l$(M9,$u
l$ M9,$
l$0M9,$u
l$ M9,$u
l$(M9,$u
l$0M9,$u
l$ M9,$u
l$8M9,$u
l$0M9,$u
l$(M9,$u
l$PM9,$
l$(M9,$u
l$HM9,$u
l$0M9,$u
l$(M9,$u
l$(M9,$u
l$(M9,$
l$8M9,$u
l$(M9,$u
l$(M9,$u
l$ M9,$u
l$(M9,$u
l$ M9,$
l$ M9,$
l$@M9,$u
l$0M9,$u
l$0M9,$u
l$XM9,$u
l$(M9,$u
l$0M9,$u
l$ M9,$
l$0M9,$u
l$ M9,$
l$0M9,$
l$0M9,$u
l$(M9,$u
l$8M9,$u
l$HM9,$u
l$(M9,$u
l$8M9,$u
l$0M9,$u
l$0M9,$
l$0M9,$u
l$HM9,$
l$ M9,$u
l$XM9,$
l$ M9,$u
l$(M9,$u
l$(M9,$u
l$(M9,$u
l$ M9,$u
l$@M9,$u
l$(M9,$u
l$HM9,$u
l$hM9,$
l$XM9,$
l$xM9,$
l$xM9,$
l$pM9,$
l$@M9,$
l$(M9,$u
|$09w
O8H9G0
:AZURu
AZURE_ADH92
x(H9{(u@H
x0H9{0u6H
x(H9{(uUH
B8H9N@u
;TRUEt
;Truet
;trueuK1
;FALSu
;Falsu
;falsu
H9J ubD
H0H9X8
l$@M9,$u
l$ M9,$u
N(H9F u,
Z0H9J8u
L$ H)Y@
truetLH
{{else}}H
{{else}}L
{{break}H
{{continH
{{templaI
emplate I
l$ M9,$u
9rangu
:rangu
l$ M9,$u
H8H9K8
HHH9KH
HXH9KX
HhH9Kh
H9K u@H
x0H9{0u6H
P H9S umH
P(H9S(uc
@HH9KPu
p H9K(u
x0H9{0u
l$`M9,$u
l$(M9,$
l$ M9,$u
l$(M9,$
l$ M9,$u
l$(M9,$
l$ M9,$u
l$ M9,$u
l$ M9,$u
l$ M9,$u
|$.@8:
t$XHc>
L$0H9J
missingkH9
9errour
9defau
9invau+f
l$0M9,$
l$(M9,$
l$(M9,$u
{(H9x(uaH
x8H9{8uWH
8xmlnu
#nDu)H
8htmlu
9ranguO
K L9c(u.H
L$(8L$HuF
L$)8L$Iu;
L$*8L$Ju0
L$+8L$Ku%
L$,8L$Lu
L$-8L$Mu
L$@H9L$`
text/jscH9
text/ecmH9
text/javH9
text/livf
applicat
ion/jsonH9H
L$(H9N
8typeu
ZgotmplZH
H9N u<H
z(H9~(u2H
H9z8u&
l$PM9,$u
T$0H9J
\$0H9S
I H9K
['5u!H
:TRUEt
:Truet
:trueuN1
:FALSu
:falsu
kernel32
~(H9z(u&
x H9{ u
x H9{ u
encodingH9
/jsou=
8Numbu
encodingH9
/jsou=
8Numbu
;TRUEu
;Trueu
;trueucH
;FALSu
;Falsu
;falsu
encodingH9
/jsou=
8Numbu
:squau
:remau
T$XA82
|$pfE9
M9aPuSM
P(L9H8
s(H9K0u
PXH9SXt
s`H9Kht
H9SHu7H
PPH9SPu-H
APL9AH
l$ M9,$
l$ M9,$
OHI9WP~
E9L$0vPM
E9L$0vSL
E9i0v3L
E9i0v3L
E9i0v3L
E9i0v3L
D$ht?H
l$ M9,$u
l$ M9,$u
l$ M9,$u
l$@M9,$u
l$ M9,$u
l$ M9,$u
l$(M9,$u
l$0M9,$u
l$ M9,$u
l$(M9,$u
l$(M9,$u
l$ M9,$u
l$0M9,$
l$ M9,$u
l$ M9,$u
l$ M9,$u
l$0M9,$u
l$ M9,$u
l$0M9,$u
l$0M9,$u
?trueu
H9L$8~
l$`M9,$
H9L$8}
l$`M9,$
l$`M9,$u
B0H9N8u
,$I9\$
\$(H9SHu
IPH9KP
T$(H9JP
Q0H+QpH
Q0H+QpH
8truet
8falsu
H0H+HpH9
t$0I+t$pL
H0H+HpH
P0L+PpL
H9_(t'
L$@H9L$
l$`M9,$
L$@H9L$
l$`M9,$
l$`M9,$u
B0H9N8u
Q0H+QpH
Q0H+QpH
8truet
8nullu
H0H+HpH
P0L+PpL
M9l$@t
;TRUEt
;Truet
;trueuO1
;FALSu
;falsu
unusedKeL9
decodedFL9
unusedKe
unusedKef
unusedKe
unusedKeH
:squau
l$0M9,$u
L9V@u/I
pHM9P@u
l$ M9,$
l$8M9,$
l$HM9,$u
l$HM9,$u
8truet
l$ M9,$u
8truet
l$8M9,$
l$@M9,$u
;trueA
@0r.H)
:inliuvf
multilinf
omitemptL9
L9D$`t
l$PM9,$u
l$xM9,$
l$`M9,$u
l$`M9,$u
l$@M9,$u
l$@M9,$u
H9S uY
P(8S(uP
P)8S)uGH
s0H9K8u5H
l$8M9,$
l$ M9,$u
:!!set
:!!mau
8!!nuu.f
8!!nuu
8!!stu
!!binary
!!binaryH9
!!binaryH
!!binaryH
!!binaryH
!!binaryH
!!binaryH
!!binaryH
!!binaryH
<$!!meu
8!!nuubf
8!!meu
;!!meu
SHH9SP~TH
D$;%YAM
SHH9KP
D$7%TAGH
D$.!<H
L$bH9L$(}
|$XH9L$(}
|$XH9L$(}
D$/'E1
D$+"E1
!!binaryH
8+Infu
8-Infu
>!!stu
>!!stu%
!!binaryH
8!!bou
!!timest
8!!stu
!!binaryf
!!timestL
!!binaryH91u
D$<YAMLH
9!!stu
8flowuO
8inliu6fA
omitemptM9
l$HM9,$
l$ M9,$
H H9K
l$@M9,$
l$ M9,$u
8boolt
8int1u
8int3f
intSlice
stringArH9
stringSlH9
stringToH9
Striu5f
8boolt
8int1u
8int3u
intSliceH9
stringArH9
stringSlH9
stringToH9
Striu5f
8yamlf
8doteu
propertiH9
{8H9x8utH
l$8M9,$
l$8M9,$
l$8M9,$
l$8M9,$
l$8M9,$
l$HM9,$u
\$hu~A
\$8H9H8
8TRUEt
8Truet
8trueuM1
8FALSu
8Falsu
8falsu
:XMLNuAf
:XMLNuPfA
<$attru
Antivirus Signature
Bkav W64.AIDetectMalware
Lionic Clean
tehtris Clean
DrWeb Clean
MicroWorld-eScan Clean
FireEye Generic.mg.bf85e5d13200077c
CAT-QuickHeal Clean
Skyhigh BehavesLike.Win64.Stealer.wh
ALYac Clean
Malwarebytes Trojan.Dropper
Zillya Clean
Sangfor Clean
K7AntiVirus Clean
Alibaba Clean
K7GW Clean
Cybereason Clean
Arcabit Clean
BitDefenderTheta Clean
VirIT Clean
Symantec ML.Attribute.HighConfidence
Elastic malicious (high confidence)
ESET-NOD32 Clean
APEX Clean
Paloalto Clean
ClamAV Clean
Kaspersky UDS:Trojan-Spy.Win32.Stealer
BitDefender Clean
NANO-Antivirus Clean
SUPERAntiSpyware Clean
Avast FileRepMalware [Pws]
Tencent Clean
TACHYON Clean
Emsisoft Clean
F-Secure Clean
Baidu Clean
VIPRE Clean
TrendMicro Clean
Trapmine Clean
CMC Clean
Sophos Clean
Ikarus Trojan.WinGo.Crypt
Jiangmin Clean
Webroot Clean
Google Detected
Avira Clean
Varist Clean
Antiy-AVL Clean
Kingsoft Clean
Gridinsoft Malware.Win64.RedLine.bot
Xcitium Clean
Microsoft Trojan:Win32/Sabsik.FL.B!ml
ViRobot Clean
ZoneAlarm Clean
GData Clean
Cynet Clean
AhnLab-V3 Trojan/Win.Generic.C5482512
Acronis Clean
VBA32 Clean
MAX Clean
Cylance Clean
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Rising Clean
Yandex Clean
SentinelOne Clean
MaxSecure Clean
Fortinet Clean
AVG FileRepMalware [Pws]
DeepInstinct MALICIOUS
CrowdStrike win/malicious_confidence_60% (D)
No IRMA results available.