Static | ZeroBOX

PE Compile Time

1970-01-01 09:00:00

PE Imphash

b2e121c8fb86c781c89c83ffff7fe337

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x006c6770 0x006c6800 6.11211215138
.data 0x006c8000 0x0006b970 0x0006ba00 5.31186954474
.rdata 0x00734000 0x009376d0 0x00937800 6.21681167193
.pdata 0x0106c000 0x00000d80 0x00000e00 5.50169779063
.xdata 0x0106d000 0x00000b90 0x00000c00 4.16907084678
.bss 0x0106e000 0x0006d0e0 0x00000000 0.0
.edata 0x010dc000 0x0000004e 0x00000200 0.916890213623
.idata 0x010dd000 0x00001364 0x00001400 4.73568660845
.CRT 0x010df000 0x00000070 0x00000200 0.448041739286
.tls 0x010e0000 0x00000010 0x00000200 0.0
.rsrc 0x010e1000 0x00001108 0x00001200 6.41139321427
.reloc 0x010e3000 0x0001e3fc 0x0001e400 5.43767118625

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x010e113c 0x000008df LANG_NEUTRAL SUBLANG_NEUTRAL PNG image data, 256 x 256, 8-bit/color RGB, non-interlaced
RT_GROUP_ICON 0x010e1a1c 0x00000014 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_VERSION 0x010e1a30 0x000002a4 LANG_DANISH SUBLANG_DEFAULT data
RT_MANIFEST 0x010e1cd4 0x00000434 LANG_ENGLISH SUBLANG_ENGLISH_US XML 1.0 document, ASCII text

Imports

Library KERNEL32.dll:
0x1410dd464 AddAtomA
0x1410dd474 CloseHandle
0x1410dd47c CreateEventA
0x1410dd484 CreateFileA
0x1410dd48c CreateIoCompletionPort
0x1410dd494 CreateMutexA
0x1410dd49c CreateSemaphoreA
0x1410dd4a4 CreateThread
0x1410dd4ac CreateWaitableTimerA
0x1410dd4b4 CreateWaitableTimerExW
0x1410dd4bc DeleteAtom
0x1410dd4c4 DeleteCriticalSection
0x1410dd4cc DuplicateHandle
0x1410dd4d4 EnterCriticalSection
0x1410dd4dc ExitProcess
0x1410dd4e4 FindAtomA
0x1410dd4ec FormatMessageA
0x1410dd4f4 FreeEnvironmentStringsW
0x1410dd4fc GetAtomNameA
0x1410dd504 GetConsoleMode
0x1410dd50c GetCurrentProcess
0x1410dd514 GetCurrentProcessId
0x1410dd51c GetCurrentThread
0x1410dd524 GetCurrentThreadId
0x1410dd52c GetEnvironmentStringsW
0x1410dd534 GetHandleInformation
0x1410dd53c GetLastError
0x1410dd544 GetProcAddress
0x1410dd54c GetProcessAffinityMask
0x1410dd55c GetStartupInfoA
0x1410dd564 GetStdHandle
0x1410dd56c GetSystemDirectoryA
0x1410dd574 GetSystemInfo
0x1410dd57c GetSystemTimeAsFileTime
0x1410dd584 GetThreadContext
0x1410dd58c GetThreadPriority
0x1410dd594 GetTickCount
0x1410dd5a4 IsDBCSLeadByteEx
0x1410dd5ac IsDebuggerPresent
0x1410dd5b4 LeaveCriticalSection
0x1410dd5bc LoadLibraryA
0x1410dd5c4 LoadLibraryW
0x1410dd5cc LocalFree
0x1410dd5d4 MultiByteToWideChar
0x1410dd5dc OpenProcess
0x1410dd5e4 OutputDebugStringA
0x1410dd5f4 QueryPerformanceCounter
0x1410dd604 RaiseException
0x1410dd60c ReleaseMutex
0x1410dd614 ReleaseSemaphore
0x1410dd624 ResetEvent
0x1410dd62c ResumeThread
0x1410dd634 SetConsoleCtrlHandler
0x1410dd63c SetErrorMode
0x1410dd644 SetEvent
0x1410dd64c SetLastError
0x1410dd654 SetProcessAffinityMask
0x1410dd65c SetProcessPriorityBoost
0x1410dd664 SetThreadContext
0x1410dd66c SetThreadPriority
0x1410dd67c SetWaitableTimer
0x1410dd684 Sleep
0x1410dd68c SuspendThread
0x1410dd694 SwitchToThread
0x1410dd69c TlsAlloc
0x1410dd6a4 TlsGetValue
0x1410dd6ac TlsSetValue
0x1410dd6b4 TryEnterCriticalSection
0x1410dd6bc VirtualAlloc
0x1410dd6c4 VirtualFree
0x1410dd6cc VirtualProtect
0x1410dd6d4 VirtualQuery
0x1410dd6dc WaitForMultipleObjects
0x1410dd6e4 WaitForSingleObject
0x1410dd6ec WideCharToMultiByte
0x1410dd6f4 WriteConsoleW
0x1410dd6fc WriteFile
0x1410dd704 __C_specific_handler
Library msvcrt.dll:
0x1410dd714 ___lc_codepage_func
0x1410dd71c ___mb_cur_max_func
0x1410dd724 __getmainargs
0x1410dd72c __initenv
0x1410dd734 __iob_func
0x1410dd73c __lconv_init
0x1410dd744 __set_app_type
0x1410dd74c __setusermatherr
0x1410dd754 _acmdln
0x1410dd75c _amsg_exit
0x1410dd764 _beginthread
0x1410dd76c _beginthreadex
0x1410dd774 _cexit
0x1410dd77c _commode
0x1410dd784 _endthreadex
0x1410dd78c _errno
0x1410dd794 _fmode
0x1410dd79c _initterm
0x1410dd7a4 _lock
0x1410dd7ac _memccpy
0x1410dd7b4 _onexit
0x1410dd7bc _setjmp
0x1410dd7c4 _strdup
0x1410dd7cc _ultoa
0x1410dd7d4 _unlock
0x1410dd7dc abort
0x1410dd7e4 calloc
0x1410dd7ec exit
0x1410dd7f4 fprintf
0x1410dd7fc fputc
0x1410dd804 free
0x1410dd80c fwrite
0x1410dd814 localeconv
0x1410dd81c longjmp
0x1410dd824 malloc
0x1410dd82c memcpy
0x1410dd834 memmove
0x1410dd83c memset
0x1410dd844 printf
0x1410dd84c realloc
0x1410dd854 signal
0x1410dd85c strerror
0x1410dd864 strlen
0x1410dd86c strncmp
0x1410dd874 vfprintf
0x1410dd87c wcslen

Exports

Ordinal Address Name
1 0x1410da320 _cgo_dummy_export
!This program cannot be run in DOS mode.
``.data
.rdata
`@.pdata
0@.xdata
0@.bss
.edata
0@.idata
.reloc
AUATUWVSH
[^_]A\A]
[^_]A\A]
8cpu.u
UUUUUUUUH!
33333333H!
t*H9HPt$
debugCal
debugCal
debugCalH9
debugCalH9
l819uq
debugCalH9
84t6H9
runtime.H9
runtime H
error: H
L9h(t
7H9S u
29t$0u
D9\$Pt
7H9S u
H9t$0u
2H9t$0u
L9\$Pt
L9\$Pt
7H9S u
L$xM9H
8H9S u
H9BpwJ@
H9P8tkH
\$(H9C8u
H9D$(t
W0H9P0tK
D$XHcL$
tE8Z t/H
\$0H9K
D$pH9H
D$0H9H
T$ H+:
UUUUUUUUH!
UUUUUUUUH
wwwwwwwwH!
wwwwwwwwH
D$$t H
J0H9J8vxL
H9{8uMf
;Hc5X
kernel32H
l32.dll
AddDllDiH
rectory
AddVectoH
redContiH
ContinueH
Handler
LoadLibrH
raryExA
LoadLibrH
raryExW
advapi32H
i32.dll
SystemFuH
stemFuncH
tion036
ntdll.dlH
NtWaitFoH
ForSinglH
eObject
RtlGetCuH
tlGetCurH
rentPeb
RtlGetNtH
tVersionH
Numbers
winmm.dlH
timeBegiH
nPeriod
timeEndPH
dPeriod
ws2_32.dH
_32.dll
WSAGetOvH
verlappeH
dResult
wine_getH
ine_get_H
version
powrprofH
rof.dll
PowerRegH
gisterSuH
spendResH
umeNotifH
ication
GetSysteH
mTimeAsFH
ileTime
QueryPerH
formanceH
Counter
QueryPerH
formanceH
rmanceFrH
equency
runtime.
QxM9Qpu
T$@H9P
H9A(ub
runtime.H9
reflect.H9
D$#e+H
I9N0t_H
D$PD9D$T
H9QPt#H
rpH92w
I9N0tSH
\$PH9p
memprofiH93u<
lerau3f
memprofiH
memprofiH
memprofiH
t H9APt
I9@8u3
r09q0s-f
,$L9+w
|$0H98
Q8H+Q(H
X(HcH0H
H9D$@A
HcD$4f
H9D$@A
\$HH9S@
H9D$8A
go 1.19 H
runtime.H
gopau$f
runtime.H
|$PH97u*
gopau!f
runtime.H9
gopau&f
runtime.H
runtime.H
G0I9F0t9
runtime.H9
P8H9W8t
f9w2uy
O@H9H@
H+H H+H(H+H0H
8noneuZ1
8crasuF
8singu
8systu
l$0M9,$u
l$PM9,$u
X0H;CPtTH
sPH91u
l$ M9,$u
l$0M9,$u
l$PM9,$u
H+t$(H
0Hc\$8H
HHc\$PH
l$8M9,$u
l$8M9,$u
l$(M9,$u
l$ M9,$u
P+8S+t
x H9{ u6H
x(H9{(uWH
Q H9S u*H
Q(H9S(u
Q18S1u
P8H9S8u*H
P@H9S@u H
PHH9SHu
PPH9SPu
H9{(uF
x09{0u>
x49{4u6H
H08K0u
P(H9S(u
H9L$0uQH
H9L$@uuH
L$PH9T$Hu
@2fD9C2u
@0fD9C0u
P@H9S@t
P@H9S@u}H
l$ M9,$u
UUUUUUUUH!
33333333H!
D$HtDD
D$HtSD
l$ M9,$u
l$0M9,$u
l$(M9,$u
l$ M9,$u
l$ M9,$u
l$0M9,$u
l$(M9,$u
l$ M9,$u
l$0M9,$
l$8M9,$u
l$(M9,$u
l$ M9,$
J(H9B t
H9K0uZH
tiH9=!!
l$ M9,$u
l$ M9,$u
l$ M9,$u
l$ M9,$u
\$0H9S
\$0H9S
H8H9X@
P2f9S2u
P@H9S@
struct {H
struct {H
reflect.H9
reflect.
CallSlicL9'u
p8H9x@vYH
uRH9x@
P8H9H@
PPH9SPu
PXH9SXu
Z(H9F u>
\$0H9S0u!H
Q8H9S8u
Q@H9S@u
IHH9KH
l$8M9,$
l$`M9,$u
l$(M9,$u
l$@M9,$u
l$@M9,$u
l$8M9,$u
l$ M9,$u
l$(M9,$u
l$(M9,$
l$8M9,$u
l$@M9,$u
l$0M9,$u
l$@M9,$u
l$@M9,$u
l$8M9,$u
l$0M9,$u
l$(M9,$
l$0M9,$u
l$0M9,$u
l$(M9,$
l$0M9,$u
l$HM9,$u
l$(M9,$u
l$@M9,$u
l$8M9,$
l$0M9,$u
l$8M9,$u
l$(M9,$
l$(M9,$
l$@M9,$u
l$@M9,$u
l$0M9,$u
l$@M9,$u
l$0M9,$u
l$8M9,$u
l$0M9,$u
l$0M9,$u
l$0M9,$u
l$0M9,$u
l$0M9,$u
l$XM9,$
l$0M9,$u
l$8M9,$u
l$0M9,$u
l$@M9,$u
l$@M9,$u
l$(M9,$u
l$(M9,$
l$(M9,$u
l$(M9,$u
l$(M9,$u
l$ M9,$u
l$ M9,$u
l$(M9,$u
l$(M9,$u
l$(M9,$u
l$ M9,$u
l$ M9,$u
l$(M9,$u
l$(M9,$u
l$(M9,$u
l$ M9,$u
l$ M9,$u
H H9K u(H
H(H9K(u
H8H9K8
T$0H)B
T$0H9J
l$ M9,$u
l$0M9,$u
l$0M9,$u
l$0M9,$u
l$0M9,$u
l$0M9,$
l$ M9,$u
|$09w0uc
r49w4u[H
O@H9G8uI
|$09wHu*
rL9wLu
\$0H9S
I H9K
L$`u3H
L$`u>H
l$(M9,$u
~(H9z(u&
x H9{ u
-070u!D
-07:00:0M9
-07:00:0L
-07:00:0
Januu!D
-07:00:0
-07:00:0
-07:00:0
Z070u"D
Z07:00:0M9
Z07:00:0L
-07:00:0
-07:00:0
-07:00:0
-07:00:0
2006u-H)
-07:00:0
time.DatH
time.LocL
time.LocH
ocation(H
time.UTCL
Mc$$M9
Mc$$M)
8WITAuP
t$Ow1M
;nullu
8Locau
tzdau;
x8H9{8
l$0M9,$u
l$@M9,$u
l$@M9,$u
l$PM9,$
l$@M9,$u
l$@M9,$u
l$0M9,$u
l$0M9,$u
l$@M9,$u
l$8M9,$u
l$(M9,$
l$8M9,$
l$(M9,$
l$(M9,$
l$0M9,$u
l$0M9,$u
l$@M9,$u
l$0M9,$u
l$(M9,$u
l$(M9,$
l$0M9,$u
l$0M9,$u
l$`M9,$
l$HM9,$u
>..t4H9
J(H9B t
H 9K u3
H$9K$u+
H(9K(u#
H,9K,u
H09K0u
H49K4u
H 9K u
H(H9K(u
t$PHcX(
t$pHc^(H
;fileu
unixgram
unixpackf
;udp4t
;udp6ui
l$(M9,$u
l$(M9,$u
8..u[H
?fileumH
8\??\t=H
xPH9{Pu~
xX9{Xuv
x\9{\un
x`9{`uf
xd@8{du\H
l$ M9,$u
l$0M9,$u
l$0M9,$u
method:H
l$@M9,$u
l$@M9,$u
l$@M9,$u
l$@M9,$u
(BADINDEI
(MISSINGI
%!(BADWIL
%!(BADPRL
BADPREC)L
%!(EXTRAM
%!(NOVERM
P(H9P@
t$$f9D$$w
f9D$&r
|$(f9D$(
f9D$*r
d$$f9D$$w
f9D$&r
f9D$ w
f9D$"r
H9t$H|4
H9T$ t
L9L$Ht
Z(H9F t
l$@M9,$
l$@M9,$
t2PH9rH
d$@t_H
l*PL9jHt"L
~>rTL)
l$@M9,$u
l$ M9,$u
8n<OwG
l$PM9,$
l$PM9,$
l$PM9,$
l$ M9,$u
l$ M9,$u
l$ M9,$u
l$ M9,$u
l$ M9,$u
l$ M9,$u
|$0H9w
D$(f9P(u
P*8S*u
l$ M9,$u
l$ M9,$
l$8M9,$u
|$HH9w@}
;falsu
l$(M9,$u
~ r(H)
l$(M9,$u
l$(M9,$u
l$(M9,$u
~"r9H)
l$(M9,$u
Z H9J(u
|$0H9w uFH
B(H9O0u4H
H9r@u&
l$0M9,$u
l$ M9,$u
l$ M9,$u
l$0M9,$
l$ M9,$u
l$pM9,$
l$(M9,$u
l$8M9,$u
l$(M9,$u
l$ M9,$u
l$0M9,$u
l$ M9,$u
l$ M9,$u
l$(M9,$u
l$ M9,$u
l$HM9,$
P8H9S8u
T$0H9J
l$ M9,$u
l$ M9,$u
x H9{ u
8leaku
T$08J
[::ffff:N
invalid J
d PrefixJ
x(H9{(uUH
l$@M9,$u
l$HM9,$u
l$0M9,$u
l$@M9,$u
l$(M9,$u
l$@M9,$u
l$0M9,$u
l$0M9,$u
l$8M9,$u
l$0M9,$u
l$0M9,$u
l$0M9,$u
l$pM9,$u
l$0M9,$u
l$0M9,$u
l$0M9,$u
H9P0u$H
H9P0u$H
H9P0u$H
H9P0u"H
l$8M9,$u
T$08J
D$(uMH
9windu
:andru
:windu
:planu9
:fileu7H
:bindu4H
9solauJf
myhostnaf
M9"u[fA
myhostna
:fileu
:dnuTA
:mdnsu
?filef
myhostnaM9
<$succu fA
<$unav
notfoundI94$t
tryagainM9
?retuu
:fileu
myhostnaD
9tcp4tY
9tcp6tQ
9udp4tG
9udp6t?
9unixt7
unixgramH9
unixpackH9
:dialu2L
unixgram
unixpackL9
8unixtD
unixgramH9
unixpackH9
<$tcu)A
l$(M9,$u
l$(M9,$u
ip6.arpaH
:CNAMuh
8CNAMu.A
>tcp4t
l$0M9,$u
?ipt9f
?tcp4t"
?tcp6t
?udp4t
?tcp4t
?udp4t
?tcp4t
?udp6u~H
\$xu H
9listu8fA
<$dial
8tcp4t
8tcp6u*
8udp4t
8udp6u
l$ M9,$u
l$ M9,$u
:uduxA
:tcp4t
:tcp6t
:udp4t
:udp6u8H
9tcp4t
9tcp6u&
9udp4t
9udp6u
l$ M9,$u
l$ M9,$u
l$ M9,$u
l$ M9,$u
l$ M9,$u
l$ M9,$u
:acceuNf
~NrvH)
unixgramM9/u8I
unixpackM9/u
unixgramL9
unixpack
unixgramL9
unixpack
8udp4t
unixgramH9
unixpackH9
listubfA
N(H9F u_
N8H9F0u:
H9{(uu
x0@8{0uk
x1@8{1ua
@8{2uUH
x 9{ u
x$9{$u
l$@M9,$u
l$@M9,$u
l$ M9,$
l$ M9,$
l$0M9,$u
l$0M9,$u
l$ M9,$u
l$0M9,$u
l$ M9,$u
l$0M9,$u
l$0M9,$u
l$ M9,$
l$0M9,$u
l$0M9,$u
l$ M9,$u
l$0M9,$u
l$ M9,$u
l$0M9,$u
l$0M9,$u
l$ M9,$
l$0M9,$u
l$0M9,$u
l$ M9,$u
l$0M9,$u
l$ M9,$u
l$0M9,$u
l$0M9,$u
l$ M9,$
l$0M9,$u
l$0M9,$u
l$ M9,$u
l$0M9,$u
l$ M9,$u
l$0M9,$u
l$0M9,$u
l$ M9,$u
l$ M9,$
l$ M9,$u
l$ M9,$
l$(M9,$u
l$8M9,$u
l$0M9,$u
l$0M9,$u
l$ M9,$u
l$HM9,$u
l$HM9,$u
l$0M9,$u
l$0M9,$u
l$0M9,$u
l$0M9,$u
l$0M9,$u
l$0M9,$u
l$0M9,$u
l$0M9,$u
l$HM9,$
x H9{ u6H
kernel32
~(H9z(u&
x H9{ u
x H9{ u
P0H+P(H
P0H+P(H
W0H+W(H
P0H+P(H
p(H9p0
\$@H9H
P(H9P0u@H
H0H+H(H
W0H+W(H9W
W(H9W0~)H
PXH+PPH
WXH+WPH
l$ M9,$u
l$ M9,$u
l$ M9,$u
l$ M9,$u
l$ M9,$u
l$0M9,$u
l$0M9,$u
l$ M9,$u
l$ M9,$u
l$(M9,$u
l$(M9,$u
l$ M9,$u
l$ M9,$u
l$ M9,$u
l$ M9,$u
l$ M9,$
l$ M9,$
l$0M9,$u
l$0M9,$u
l$ M9,$u
l$ M9,$u
l$ M9,$u
l$ M9,$u
l$(M9,$u
l$(M9,$u
l$ M9,$u
l$ M9,$u
l$ M9,$u
l$ M9,$u
l$ M9,$u
8infot
8debuu
8paniu
8warnu!f
\$@t2H
l$(M9,$u
l$(M9,$u
l$(M9,$u
l$8M9,$u
l$8M9,$u
l$8M9,$u
l$8M9,$u
l$8M9,$u
l$0M9,$u
l$8M9,$u
l$8M9,$u
l$HM9,$u
l$ M9,$u
l$ M9,$u
H3T8 L3L8(I
H1T$0H
H1T$HH
H1T$PH
l$HM9,$u
o\$ fE
o\$0fE
o\$@fE
o\$PfE
o\$`fE
o\$pfE
l$HM9,$u
l$HM9,$u
l$8M9,$u
x H9{ u@H
x(H9{(u6H
:T^8rv
D$ffPH
~d$ fE
ot$PfA
S H+Q H
P H1s
l$0M9,$u
l$8M9,$u
l$(M9,$u
l$8M9,$u
l$0M9,$u
l$0M9,$u
l$8M9,$u
l$(M9,$u
l$8M9,$u
l$0M9,$u
l$0M9,$u
l$8M9,$u
l$(M9,$u
l$8M9,$u
l$0M9,$u
;nullu
<Ot-<XtL
l$0M9,$u
l$0M9,$u
l$(M9,$u
P8H9S8u
l$8M9,$u
l$8M9,$u
l$`M9,$
l$8M9,$u
l$HM9,$u
l$0M9,$u
l$0M9,$u
l$8M9,$u
l$8M9,$u
l$`M9,$
l$8M9,$u
l$HM9,$u
l$0M9,$u
l$0M9,$u
l$8M9,$u
l$8M9,$u
l$`M9,$
l$8M9,$u
l$HM9,$u
l$0M9,$u
l$0M9,$u
l$8M9,$u
l$8M9,$u
l$`M9,$
l$8M9,$u
l$HM9,$u
l$0M9,$u
l$0M9,$u
l$0M9,$u
l$(M9,$u
l$0M9,$u
l$8M9,$u
l$HM9,$u
l$8M9,$u
l$8M9,$u
optionalH9
explicit
explicitf
optionalH
explicitH
explicit
optionalH
explicitH
generaliL9
generaliH
printabl
printablH
8numeu
8utf8u
default:L9
default:E1
8tag:A
applicat
optionalH
explicitH
generaliI
printablI
default:I
applicat
applicat
optionalH
explicitH
generaliI
printablI
default:I
applicat
omitempt
omitempt
optionalH
explicitH
optionalH
explicitH
l$8M9,$u
l$8M9,$u
l$ M9,$u
l$0M9,$u
l$ M9,$u
l$8M9,$
l$8M9,$
l$@M9,$u
l$8M9,$
l$@M9,$u
l$8M9,$
l$8M9,$
l$@M9,$u
H9P }]
L$H8L$'u
L$H8L$'u
H9P }N
L9B }Y
L9B }Z
H9P }a
H9P }P
IV for EH
CDSA CTRH
9P-25uP
l$8M9,$u
l$(M9,$u
l$(M9,$u
l$0M9,$
l$0M9,$u
l$@M9,$
l$@M9,$u
l$8M9,$
l$8M9,$u
l$0M9,$
l$0M9,$u
l$@M9,$
l$@M9,$u
l$ M9,$u
\$0H9S
\$0H9S
I H9K
XfffffffH
ffffffffH
l$HM9,$
l$PM9,$
l$`M9,$
T$0H9J
|$HH9w u
<$tI<&tE
r8H9Z@t
rpH9Zxt
8..uHL
8//uOH
J(H9B t
l$0M9,$
l$@M9,$
x @8{ u6H
{0H9x0
{PH9xP
xY@8{Y
{xH9xx
l$8M9,$u
QZ^&A!
$D3T$4D3T$ D3T$
D3T$8D3T$$D3T$
D3T$<D3T$(D3T$
$D3T$,D3T$
D3T$0D3T$
D3T$4D3T$
D3T$8D3T$ A
D3T$<D3T$$A
T$ D3T$
$D3T$(A
T$$D3T$
D3T$,A
T$(D3T$
D3T$0A
T$,D3T$ D3T$
D3T$4A
T$0D3T$$D3T$
D3T$8A
T$4D3T$(D3T$
D3T$<A
T$8D3T$,D3T$
T$<D3T$0D3T$
$D3T$4D3T$ D3T$
D3T$8D3T$$D3T$
D3T$<D3T$(D3T$
$D3T$,D3T$
D3T$0D3T$
D3T$4D3T$
D3T$8D3T$ A
D3T$<D3T$$A
T$ D3T$
$D3T$(A
T$$D3T$
D3T$,A
T$(D3T$
D3T$0A
T$,D3T$ D3T$
D3T$4A
T$0D3T$$D3T$
D3T$8A
T$4D3T$(D3T$
D3T$<A
T$8D3T$,D3T$
T$<D3T$0D3T$
$D3T$4D3T$ D3T$
D3T$8D3T$$D3T$
D3T$<D3T$(D3T$
$D3T$,D3T$
D3T$0D3T$
D3T$4D3T$
D3T$8D3T$ A
D3T$<D3T$$A
T$ D3T$
$D3T$(A
T$$D3T$
D3T$,A
T$(D3T$
D3T$0A
T$,D3T$ D3T$
D3T$4A
T$0D3T$$D3T$
D3T$8A
T$4D3T$(D3T$
D3T$<A
T$8D3T$,D3T$
T$<D3T$0D3T$
$D3T$4D3T$ D3T$
D3T$8D3T$$D3T$
D3T$<D3T$(D3T$
$D3T$,D3T$
D3T$0D3T$
D3T$4D3T$
D3T$8D3T$ A
D3T$<D3T$$A
T$ D3T$
$D3T$(A
T$$D3T$
D3T$,A
T$(D3T$
D3T$0A
T$,D3T$ D3T$
D3T$4A
T$0D3T$$D3T$
D3T$8A
T$4D3T$(D3T$
D3T$<A
T$8D3T$,D3T$
T$<D3T$0D3T$
PXH9SXu
P`H9S`u
CERTIFIC
H92u$f
8S(udH
T$0H9P
HHH9pPuDH
WHL9GPt
D$@H9D$
H95QL
|$`H9\$hu
D$xH9L$Hu
T$0H9J
D$@H9D$
l$`M9,$
l$ M9,$u
l$8M9,$
l$0M9,$u
l$HM9,$u
P(H9S(u$H
SHH9PHu
HHH9P@u H
l$8M9,$u
L)@pL)
2-byD1
$2-byD
nd 3E3K
2-byE3K
te kA3K
>E3C4D
expaD3P A
expaD1
expaD3
expand 3H
2-byte kH
l$ M9,$u
fE9,$u
DOWNGRD
DOWNGRD
<LfD9x
\$xuXH
H9P }S
L9X }_
H9P }N
H9P }N
L9H }j
H9P }N
H9P }N
H9P }N
H9P }V
L9H }_
H9P }N
H9P }V
L9H }j
L9B }Q
H9P }V
L9H }j
L9H }j
H9P }V
H9P }V
L9H }j
L9@ }Y
L9B }Q
H9P }N
L9X }_
L9@ }^
H9P }Y
H9P }N
H9P }N
H9P }V
H9P }H
H9P }V
H9P }H
L9@ }\
H9P }V
H9P }H
H9P }N
L9B }V
H9P }N
H9T$h}:
L9@ }Y
L9B }V
H9T$h}:
H9P }N
H9P }I
H9T$h}:
L9@ }Y
H9P }N
H9P }N
H9T$h}:
L9@ }Y
L9@ }^
L9@ }^
L9@ }^
L9@ }^
L9@ }^
L9@ }^
L9@ }^
H9P }N
L9H }j
L9H }j
H9T$h}:
H9P }a
L9@ }\
L9@ }^
H9P }N
L9@ }_
H9P }N
H9P }N
H9T$h}:
L9@ }Y
H9P }N
H9T$h}:
H9P }N
H9T$h}:
L9@ }\
H9P }N
fE9J@r
:h2u3I
http/1.1M9}
http/1.1
http/1.1
http/1.1
c@fE9"u
SPL9CX
s H9K(t
s8H9K@t
shH9Kpt
H9P }N
D$*tls1f
H9P }a
L9B }V
key expaH9
master sH9
client fH9
server fH9
inisuqf
H9T$x}:
H9T$x}:
H9P }N
H9P }N
H9P }N
CERTIFICL9
CERTIFICL
CERTIFICL
CERTIFICI
PRIVATE L9
PRIVATE I
PRIVATE
PRIVATE L
CERTIFICH92
H9P }T
H9W }W
H9W }H
T$0H9J
T$0H9J
l$ M9,$u
l$`M9,$u
l$ M9,$
l$0M9,$u
l$(M9,$u
l$(M9,$u
H0L+H(I
X0H+X(
l$8M9,$u
l$(M9,$u
us-asciiH9
8utf-u
text/plaH
text/pla
text/plaH
text/plaH
text/plaH
text/plaH
distinctH9
form-dat
form-datL9
form-datH
form-datH
form-datH
L$0tBI
form-datH92u
^0H+^(H
:--u0H
L$@H9N0t
l$0M9,$u
l$0M9,$u
l$8M9,$
l$8M9,$u
l$0M9,$u
l$0M9,$u
l$0M9,$u
trbH)
D$(H9N
H9H sJ
I9@ sML
l$ M9,$u
l$ M9,$u
l$ M9,$u
l$8M9,$u
l$8M9,$u
l$HM9,$u
l$HM9,$u
XD9X4v
P09P4s
H9pxu*H
L9L$X~
l$8M9,$u
l$8M9,$u
l$HM9,$u
l$HM9,$u
x @8{ u6H
X0H+X(
Q0M+Q(f
l$ M9,$u
l$ M9,$u
l$(M9,$u
l$(M9,$u
l$8M9,$
l$8M9,$
l$0M9,$u
l$0M9,$u
l$ M9,$u
l$ M9,$u
l$ M9,$u
l$ M9,$u
:httpu
:httpuDH
:httpu
:socku
localhosH9
x @8{ u6H
l$ M9,$u
x(H9{(u_
x0@8{0uUH
8domaf
httponlyL9
samesiteL9
8noneu:H
8striu
; DomainL
; ExpireL
; Max-AgL
; Max-AgL
ax-Age=0L
; HttpOnL
; SecureL
; SameSiH
Site=LaxH
; SameSiH
ite=NoneH
H)H(H)
Z(H)Z0L
8:metu
8:schu
8:stauUfA
:authoriM9
l$ M9,$u
l$(M9,$u
l$ M9,$u
9readudH
:wsaru:f
\]HwjA
l$8M9,$u
l$0M9,$u
l$0M9,$u
8httpf
8httpu$
:httpu
100-contH9
:CONNuXf
8Traif
Content-H9
LenguEf
9closu
Trailer:L9
Trailer:E1
>HEADtmD
l$0M9,$u
trailersH92t=
trailers
l$(M9,$u
t$p9^`
multiparH9
>CONNuMf
HTTP/1.0H9
HTTP/1.1
8CONNu=fA
no-cacheH92
HTTP/2.0H9
>POSTt(I
>PATCuR
no-cacheH92
:chunu
>chunu
X0H+X(H
>HEADu
Trailer:L9
Trailer:E1
l$(M9,$u
L$(H)H(
9POSTuWH
9PRuYA
HTTP/2.0M9#A
9CONNu
9HEADA
Trailer:H9
Trailer:1
keep-aliH92u
8closu
identityH
identityE1
identity
identityH
<$HEADt7L
:HEADtHH
9readu
H9~(t:H
PUT uo
http/1.0f
http/1.1H92
L$0I9H@u
8OPTIu
l$(M9,$u
l$(M9,$u
>HEAD@
>chunf
>chunu
>chunu
9CONNu
9HEADtd
9DELEu
9SEARu^f
9OPTIuFf
PROPFINDH9
l$ M9,$u
;chunu
;POSTt-
identityH9
;HEADu
8Traiukf
Content-H9
Lengu6f
>HEADuhH
>HEADt'H
?HEADu
Content-
z H9~ u2
J0H9B(t
H!8K!u
H(H9K(
H9w u+H
r(H9w(u!H
\$0H9S
O(H9G t
\$0H9S
l$ M9,$u
l$ M9,$u
l$8M9,$u
l$(M9,$u
l$8M9,$u
l$8M9,$u
l$(M9,$u
l$0M9,$u
l$PM9,$
l$(M9,$u
l$ M9,$u
l$0M9,$u
l$ M9,$u
l$(M9,$u
l$ M9,$
l$0M9,$u
l$PM9,$
l$(M9,$u
l$ M9,$u
l$0M9,$u
l$(M9,$u
l$(M9,$u
l$ M9,$u
l$0M9,$u
l$HM9,$u
l$8M9,$u
l$8M9,$u
l$hM9,$
l$HM9,$u
l$HM9,$u
l$HM9,$u
l$HM9,$u
l$ M9,$u
l$(M9,$u
l$ M9,$
l$0M9,$u
l$(M9,$u
l$ M9,$u
l$0M9,$u
l$ M9,$u
l$(M9,$u
l$ M9,$
l$0M9,$u
l$ M9,$u
l$(M9,$u
l$0M9,$u
l$ M9,$u
l$(M9,$u
l$ M9,$
l$0M9,$u
l$ M9,$u
l$(M9,$u
l$0M9,$u
l$ M9,$u
l$(M9,$u
l$ M9,$
l$0M9,$u
l$ M9,$u
l$(M9,$u
l$0M9,$u
l$ M9,$u
l$8M9,$u
l$0M9,$u
l$(M9,$u
l$PM9,$
l$(M9,$u
l$8M9,$u
l$(M9,$u
l$(M9,$u
l$ M9,$u
l$(M9,$u
l$ M9,$
l$ M9,$
l$@M9,$u
l$0M9,$u
l$0M9,$u
l$XM9,$u
l$(M9,$u
l$0M9,$u
l$ M9,$
l$0M9,$u
l$ M9,$
l$0M9,$
l$0M9,$u
l$(M9,$u
l$8M9,$u
l$0M9,$
l$0M9,$u
l$HM9,$
l$ M9,$u
l$XM9,$
l$ M9,$u
l$(M9,$u
l$(M9,$u
l$(M9,$u
l$ M9,$u
T$hA82
aHM9aPuUM
P(L9H8
s(H9K0u
PXH9SXt
s`H9Kht
H9SHu7H
PPH9SPu-H
APL9AH
l$ M9,$
l$ M9,$
OHI9WP~
E9L$0vPM
E9L$0vSL
E9i0v3L
E9i0v3L
E9i0v3L
E9i0v3L
l$ M9,$u
l$ M9,$u
l$ M9,$u
l$@M9,$u
l$ M9,$u
l$ M9,$u
l$8M9,$u
L9L$0s
oD$@fA
oL$PfA
oT$`fA
od$pfE
93V@3NDD3FHD3NL
93VP3NTD3FXD3N\
93V 3N$D3F(D3N,
93V`3NdD3FhD3Nl
93V03N4D3F8D3N<
93Vp3NtD3FxD3N|
oD$0fA
D3F0D3N 3F
D3N43F$
93N(D3F
3N<D3F,D3N
D$HSOI
D$DSUI
*<ht <pt
*<ht <pt
D$Lxkv1H
D$Lxkv1H
l$8M9,$u
l$HM9,$u
l$hM9,$
vmM3$0M
D$Ds2idf
D$N2sH
D$"s2idf
D$ 2sH
D$>2sH
^H9pH|
D$4H9H(}ZH9
bH9pH|
D$`H9G(}^f
8S2sTu
^H9pH|
H9H(}_H9
^H9pH|
D$XH9G(}HH
p(H+p H9
l$(M9,$u
l$HM9,$u
l$0M9,$u
l$0M9,$u
l$0M9,$u
l$0M9,$u
l$8M9,$u
l$8M9,$u
l$ M9,$u
l$ M9,$u
l$8M9,$u
S(H9P(u
l$0M9,$u
l$0M9,$u
T$`H9V8}^L
# labelI
labels: I
runtime.
runtime.A
runtime.L9
runtime.E1
runtime.E1
runtime.D
runtime.A
l$ M9,$u
9muteuc
runtime.H91u5
runtime.H
runtime.M9
runtime.H9
runtime.E1
l$ M9,$u
H9{ uAH
x(H9{(u7H
H9K uWH
x0H9{0uM
x8@8{8uC
x9@8{9u9H
;TRUEt
;Truet
;trueuK1
;FALSu
;Falsu
;falsu
H9J ubD
H0H9X8
l$@M9,$u
l$ M9,$u
N(H9F u,
Z0H9J8u
9heapf
heapz_v2M9
heapprofM9
:v2u H
samplingH
ms sinceH
cycles/sH
resolutiH
:formu(f
P@H9HH
H9Q uCH
x H9{ u@H
x(H9{(u6H
p H9K(u}H
x8H9{8us
x@@8{@ui
xA@8{Au_
xB@8{BuU
xC@8{CuKH
xHH9{HuAH
xPH9{Pu7H
{ H9x
x0H9{0
H9{8uuH
x@H9{@ukH
xHH9{HuaH
H9{PuUH
H9x uaH
x0H9{0uWH
x(H9{(uUH
l$0M9,$u
>heapu
l$8M9,$u
x(H9{(u_H
x0H9{0uUH
L+n M9
L+n M9
H+O I9
L+O I)
HPH9HX~
XPH9HX
\$VtaL
|$PsVL9
t$@vQI
?fA9:w
fA9<$w
>fA9:vUL9
?fA9:r
6fA92w
D#C(L9
E#k(L9
A#M(I9
E#k(L9
A#M(I9
E#k(L9
A#M(I9
E#k(L9
A#M(I9
E#P(M9
E#k(L9
H9D$0~
H9D$0~
l$DA+I
T$tA+I
l$8M9,$u
l$(M9,$
l$(M9,$
l$(M9,$
l$(M9,$
l$(M9,$
l$(M9,$
r H9w u[H
r(H9w(uQH
r0H9w0uGH
r8H9w8u=H
H9G@u'
8s2u/H
8noneu
x @8{ u6H
x H9{ uiH
{0H9x0u_H
x@H9{@uUH
x H9{
@8{(uuH
{8H9x8uk
x@@8{@uaH
H9{PuUH
x H9{ uA
x(9{(u9H
x H9{ u
x(@8{(u
\$0H9S
l$0M9,$u
l$0M9,$u
l$ M9,$u
l$ M9,$u
l$ M9,$u
l$ M9,$u
\$P8K9
L$`H9A t
H H+H0H
l$ M9,$u
l$ M9,$u
l$ M9,$u
D$H8H8
L9G@|4H
L9D$(t
I H9K
l$ M9,$u
l$ M9,$u
H9S u+H
Q(H9S(u!H
Q0H9S0u
H H9K u
H(8K(u
H0H9K0
?TRUEt
?Truet
?trueuK1
?FALSf
?Falsu
?falsu
v$H9r8r
I9p0~B
H H9H(t
9Idlet
9Flowu
8s2u/H
8noneu
\$Ht'H
:PURGu2
?PURGu
$JS.API.I90@
s(H9K0
t$@H9V
8wsuLH
8wsu#A
V(H9V0
l$0M9,$u
l$(M9,$u
:INFOt
8PONGu
l$(M9,$u
stale coH9
nnectionH9P
NATS/1.0H9
l$ M9,$u
l$ M9,$u
l$ M9,$u
l$ M9,$u
l$ M9,$u
l$(M9,$u
l$(M9,$u
?OBJ_@
?OBJ_A
?OBJ_A
H9r`}SD
H9H(~LH
Z0H+Z(H
x @8{ u6H
x H9{ u
x(H9{(uUH
|$0@8w(u
_0H9O8u
T$0H9J
SPH9PPu}H
S`H9P`usH
x(@8{(
x*@8{*uuH
H9F0u
T$08J@
H9O uyH
r0H9w0uoH
w@H9r@ue
x(H9{(u6H
N8H9F0u+
IHH9KH
x H9{ u6H
T$0H9J
x H9{ u6H
H9F uU
N8H9F0u0
JHH9B@t
P H9S u-H
P(H9S(u#H
p8H9S0t
T$0H9J
{8H9x8
xH@8{Hu~
xI@8{IutH
l$0M9,$
l$@M9,$
l$0M9,$u
l$(M9,$u
l$(M9,$u
l$0M9,$
l$0M9,$
l$0M9,$
l$0M9,$
l$0M9,$
l$0M9,$
l$0M9,$
l$ M9,$u
l$ M9,$u
l$ M9,$u
T$0H9J
{ H9x
{@H9x@
{`H9x`
xxH9{x
T$0H9J
H H9K
T$0H9J
T$0H9J
I H9K
\$0H9S
Q H9S uH
Q(H9S(u
I0H9K0
l$(M9,$u
l$ M9,$u
l$ M9,$u
l$(M9,$u
l$(M9,$u
l$(M9,$u
l$(M9,$u
l$HM9,$
l$HM9,$
l$8M9,$u
l$8M9,$u
l$@M9,$u
l$8M9,$
l$8M9,$
l$8M9,$u
8ignou
8paniu
t$PH95
L$@9L$D
HcD$DH
:Messf
MapValueM9"
ContainiM9"
H9t$@}
PhH9Shu
8-infu
l$xM9,$
l$(M9,$u
l$@M9,$
l$pM9,$
l$(M9,$u
T$0H9J
H`H9Hhu9H
H9Hxu,H
protu(f
t$09|$0
L$H9T$Lu[H
D9D$P~
D9D$@A
D$0D9L$0~
\$(8S0u
I8H9K8
{(H9x(u6H
T$(H9J0
T$0H9J(
|$09w0uEH
Z@H9G8u3
\$08SHu
QI8SIu
IPH9KP
l$ M9,$u
l$ M9,$u
l$ M9,$u
l$ M9,$u
l$ M9,$u
l$ M9,$u
l$ M9,$u
l$ M9,$u
l$ M9,$u
l$ M9,$u
l$ M9,$u
l$ M9,$u
J(H9B t
zigzag32H9
zigzag64
zigzag64
zigzag32I
zigzag64H
8grouu(
zigzag32I
zigzag64
zigzag32I
zigzag64
8packu,f
zigzag32I
zigzag64
8def=A
8protuOf
zigzag64M
zigzag32L
T$HHc:
>protu5f
XXX_weakH9
sizeCach
weakFielH9
XXX_weakH
XXX_sizeH9
sizeCachH
unknownFL9
XXX_exte
extensioH9
XXX_exte
XXX_unre
cognizedL9@
XXX_sizeI
unknownFH
XXX_sizeI
unknownF
XXX_sizeI
unknownF
cognized
XXX_exteH
T$0H9J
N(H9F
|$0H9wH
ZhH9F`
|$09wp
T$0H9J
Z(H9F t
l$`M9,$
l$ M9,$u
l$(M9,$u
l$PM9,$
l$@M9,$u
l$@M9,$u
l$(M9,$u
l$(M9,$u
l$(M9,$u
l$(M9,$u
l$HM9,$u
l$ M9,$u
l$HM9,$u
l$(M9,$u
l$(M9,$u
l$(M9,$u
l$(M9,$u
l$HM9,$
l$ M9,$u
l$ M9,$u
l$(M9,$u
l$(M9,$u
l$8M9,$u
l$8M9,$u
l$8M9,$u
l$8M9,$u
l$8M9,$u
l$8M9,$u
l$PM9,$
l$8M9,$u
l$0M9,$u
l$8M9,$u
l$8M9,$u
l$HM9,$
l$0M9,$u
l$(M9,$u
l$8M9,$u
google.pH9
EnumOpti
EnumOptiI
FileOpti
FileOptiL9
EnumOptiI
FileOptif
FieldOpt
EnumOptiI
FileOpti
OneofOptf
EnumOptiI
FileOpti
EnumOptiI
FileOpti
MethodOp
EnumOptiI
FileOptif
EnumOptiI
FileOpti
MessageOL9
EnumOptiI
FileOpti
ServiceOf
EnumOptiI
FileOptif
EnumOptiI
FileOpti
EnumValuL9
eOptionsL9N
EnumOptiI
FileOpti
eOptionsI
EnumOptiI
FileOpti
EnumOptiI
FileOpti
EnumOptiI
FileOpti
EnumOptiI
FileOpti
l$ M9,$u
l$(M9,$u
l$(M9,$u
l$(M9,$u
l$ M9,$u
l$(M9,$u
l$8M9,$u
l$ M9,$u
l$ M9,$u
l$ M9,$u
l$ M9,$u
x H9{ u@
x(@8{(u6H
?secouDf
?byteu
l$0M9,$
l$ M9,$
l$ M9,$
l$ M9,$u
l$(M9,$u
l$8M9,$u
l$ M9,$u
l$ M9,$u
l$(M9,$u
l$8M9,$u
l$ M9,$u
l$(M9,$u
l$8M9,$u
l$ M9,$u
l$(M9,$u
l$8M9,$u
l$ M9,$u
l$(M9,$u
l$8M9,$u
l$ M9,$u
l$(M9,$u
l$8M9,$u
l$ M9,$u
l$(M9,$u
l$8M9,$u
l$ M9,$u
l$(M9,$u
l$8M9,$u
l$ M9,$u
l$(M9,$u
l$8M9,$u
l$ M9,$u
l$(M9,$u
l$8M9,$u
l$pM9,$
:textf
delimiteH92u-
compact-H92u
>0.0.u
:textuG
delimiteL9
compact-L9
;textuZH
:plaiu?
:0.0.u
>0.0.u
>1.0.u
>1.0.u"
\$stI
l$ M9,$u
Antivirus Signature
Bkav W64.AIDetectMalware
Lionic Trojan.Win32.Stealerc.i!c
Elastic Clean
DrWeb Trojan.DownLoader46.33276
MicroWorld-eScan Clean
ClamAV Clean
FireEye Clean
CAT-QuickHeal Clean
Skyhigh Artemis
ALYac Clean
Malwarebytes Trojan.Dropper
VIPRE Clean
Sangfor Infostealer.Win32.Kryptik.Vrqh
K7AntiVirus Trojan ( 005ae2651 )
BitDefender Clean
K7GW Trojan ( 005ae2651 )
CrowdStrike Clean
Arcabit Clean
BitDefenderTheta Clean
VirIT Clean
Symantec ML.Attribute.HighConfidence
tehtris Clean
ESET-NOD32 a variant of WinGo/Kryptik.DZ
APEX Clean
Paloalto Clean
Cynet Malicious (score: 99)
Kaspersky Trojan-PSW.MSIL.Stealerc.jx
Alibaba TrojanPSW:MSIL/Stealerc.0dc2fb0c
NANO-Antivirus Trojan.Win64.Stealerc.kdvgdm
ViRobot Clean
Rising Clean
Sophos Mal/Generic-S
F-Secure Trojan.TR/Redcap.dennw
Baidu Clean
Zillya Clean
TrendMicro TrojanSpy.Win64.LUMMASTEALER.YXDKQZ
Trapmine Clean
CMC Clean
Emsisoft Clean
Ikarus Trojan.SuspectCRC
Jiangmin Clean
Webroot Clean
Google Detected
Avira TR/Redcap.dennw
MAX Clean
Antiy-AVL Trojan/Win32.Kryptik
Kingsoft Win32.PSWTroj.Undef.a
Gridinsoft Ransom.Win64.Sabsik.sa
Xcitium Clean
Microsoft Trojan:Win32/LummaStealer.MB!MTB
SUPERAntiSpyware Clean
ZoneAlarm Trojan-PSW.MSIL.Stealerc.jx
GData Win64.Trojan.Agent.ASU0D3
Varist Clean
AhnLab-V3 Trojan/Win.Generic.R621603
Acronis Clean
McAfee Artemis!234F10ADF43F
TACHYON Clean
DeepInstinct MALICIOUS
VBA32 Clean
Cylance unsafe
Panda Trj/Chgt.AD
Zoner Clean
TrendMicro-HouseCall TrojanSpy.Win64.LUMMASTEALER.YXDKQZ
Tencent Msil.Trojan-QQPass.QQRob.Ckjl
Yandex Clean
SentinelOne Clean
MaxSecure Clean
Fortinet W32/Kryptik.DZ!tr
AVG Win64:Evo-gen [Trj]
Cybereason Clean
Avast Win64:Evo-gen [Trj]
No IRMA results available.