Static | ZeroBOX

PE Compile Time

2023-11-17 10:43:32

PE Imphash

2fd03c0e50677cbfe09966e474b427b5

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x00006604 0x00006800 6.59607896193
.reloc 0x00008000 0x0000212a 0x00002200 6.5095674409
.rdata 0x0000b000 0x00001b26 0x00001c00 5.44843850167
.data 0x0000d000 0x0006a400 0x00069a00 7.98563343898
.rqnhjz 0x00078000 0x00001000 0x00000a00 4.38299390296
.jkmgqz 0x00079000 0x00000400 0x0000023c 4.31666633934

Imports

Library KERNEL32.dll:
0x40b004 WaitForSingleObject
0x40b008 Sleep
0x40b00c CreateThread
0x40b010 lstrlenW
0x40b014 VirtualProtect
0x40b018 GetProcAddress
0x40b01c LoadLibraryA
0x40b020 VirtualAlloc
0x40b024 GetModuleHandleA
0x40b028 FreeConsole
0x40b02c GetLastError
0x40b030 HeapFree
0x40b034 HeapAlloc
0x40b038 GetCommandLineA
0x40b03c HeapCreate
0x40b040 VirtualFree
0x40b050 HeapReAlloc
0x40b054 GetModuleHandleW
0x40b058 ExitProcess
0x40b05c WriteFile
0x40b060 GetStdHandle
0x40b064 GetModuleFileNameA
0x40b078 WideCharToMultiByte
0x40b080 SetHandleCount
0x40b084 GetFileType
0x40b088 GetStartupInfoA
0x40b08c TlsGetValue
0x40b090 TlsAlloc
0x40b094 TlsSetValue
0x40b098 TlsFree
0x40b0a0 SetLastError
0x40b0a4 GetCurrentThreadId
0x40b0b0 GetTickCount
0x40b0b4 GetCurrentProcessId
0x40b0bc TerminateProcess
0x40b0c0 GetCurrentProcess
0x40b0c8 IsDebuggerPresent
0x40b0d0 RtlUnwind
0x40b0d4 GetCPInfo
0x40b0d8 GetACP
0x40b0dc GetOEMCP
0x40b0e0 IsValidCodePage
0x40b0e4 HeapSize
0x40b0e8 GetLocaleInfoA
0x40b0ec LCMapStringA
0x40b0f0 MultiByteToWideChar
0x40b0f4 LCMapStringW
0x40b0f8 GetStringTypeA
0x40b0fc GetStringTypeW
Library NTDLL.DLL:
0x4786fc PersonalizeEndpoint
0x478704 ModifyArtifact
0x478708 RefineComponent
0x47870c AdjustObject
0x478710 DeactivateComponent
0x478718 PersonalizeEndpoint
0x47871c EnhanceFramework
0x478720 ModernizeCapability
0x478724 AdjustInstrument
0x478728 OverhaulObject
0x47872c BuildInstrument
0x478730 AdjustEndpoint
0x478734 UpdateConfiguration
Library USER32.DLL:
0x478740 ModifyConfiguration
0x478744 EnhanceEndpoint
0x478748 EnhancePart
0x478750 ModernizeOperation
0x478754 AdjustLayer
0x478758 RefineFramework
0x47875c ModifyProtocol
0x478760 RefinePart
0x478764 BuildCapability
0x478768 RefineObject

!This program cannot be run in DOS mode.
`.reloc
`.rdata
@.data
.rqnhjz
.jkmgqz
>=Yt1j
j@j ^V
URPQQh
0SSSSS
0SSSSS
0SSSSS
0A@@Ju
;t$,v-
UQPXY]Y[
t"SS9]
PPPPPPPP
PPPPPPPP
t+WWVPV
3bx?222
D6222qc
;`#g;D
hh222;\;D
222qSA
T~222qc
222#d;bqp|#dq[A
222%|222ql
Dh222zn222qXq
qZ+;Sq[
;bq_ZqX
;J;T#g;`;C
;[qco;Zqo$
222w"222
222#gq[q;S;Z;Gqh
#h#gql
;`qTS;C
222;W;Zqo
222;_;S
#j;C;[q_
TI222qoE;Dqj
222;[#c;_w
222qd.;b
;C;_ql
-?222;\#j;S
C^222;X;H
p\222t:222;S;C
Lt222;[qb
222;Cq_
h222ql
222x_222q_
(z1222II
B4332222G#
(z0222I
;C#h;Z;ZqTy;S;D;b
oF222;\ql
CP222;[
222#g;S
;Dqph;`;Tt
222sc222qo
;bqd-qg
S}222;S;_
#c;D;X;Gqd
D(;Tq[
K3222zT222
222;S;C;T
qW*#dqk
222#hqk
qcIqp8
q[z;\;S
T{222qW\
;_xk222qpF
;[;Gq\
222q_Ws
hZ222;\#g
222#cx@222;bw
222;C;D
g`222qT
W`222;J
#g;W#d
I222qS
p2;[q_
222#jqc
cg222;S
;b#d;S#gqj
;Z#cqZ
#h;_qh
3332222G#
ol222#hqj
;[;Jq_
Pl222;Z;T
222qZX;C;S;S
3332222
3332222G#
333#{*q9&
333#{0
333#{*
333I!333;Sqh
d3222#hqk2
;b;b;T
Gm222qj
#c;`;X
p[222;_q`*;DqcWqc
O>222qo<
qc2;b#c
;\;T#dqT
qgxqdCq\
#gq[,qk=qo}
;H;J;J;Hq[
222#hq[
222;Xqb
3332222G#
*3332222G#
"333#{&
u.3332
64332222G#
:433.222G
:4330222
2I]433qT
222;[;J;b;C
;_;`;S;_#j;\;Dqo';X;W;Xqr
qpFwE222#g
O{222qX
g6222#h
qSmqpt
TB222w
;\;G#c-
pU222qX(;T;D;bql
;`;D;Jz
222q_\
222qgb;\
ho222;\
ca222;HqZnqb
q[)x7222
#g;Jqh
222;XqXXx
Tx222;G
222#jz
222qk=q\Sq_B#g;`qg
;\;SqhR
qltx[222
222;Z;Cs
;\qreq\
qlS#c;W#j;Cq\O
222qT;;C;Gqp2x
lT222qbs;D;`%K222
;`;Jqhf#j
;Tql qk
222#d#d
DM222;C;X
on222;b#d;G;S-o222
qj|;Dqg
qk$qhi;X#jqZ
;_#jqjJ;Gq[e
222;`#dqX
G:222qX
222#j#d
222qgD
z`222;\;DqZ
;b#dqo
#d;[#g
H=222;T
Wy222qd
222wO222#d;\qXh
;b;C;[
PJ222;D
O4222qW5qX
yJ2222#
c@222;Cql_qc
p9222;C
hu222qrn
Pb222;D
222#cq\
D]222ql
;bql#qcO;J
SX222;C;[qS<;Z;Z
222;HqS
n222;T;Z
222qj6
l`222qh
Gd222xP222;b#c
l^222#h
W[222;T
;G#dsw222;\qbc
ga222q`
q\A;Dqp
222;CqZk;\
222;W;b
oH222#j;H
;[;G;[
m222qd
;_qb&;S
Xn222qj
xY222;\
hH222w
;Xqj^#dz
P^222qj
222;TqW
qWO#g#gqp
;`s|222;D;J;`
qdBqc`
offffffU
bad allocation
kernel32.dll
ntdll.dll
CorExitProcess
runtime error
TLOSS error
SING error
DOMAIN error
An application has made an attempt to load the C runtime library incorrectly.
Please contact the application's support team for more information.
- Attempt to use MSIL code from this assembly during native code initialization
This indicates a bug in your application. It is most likely the result of calling an MSIL-compiled (/clr) function from a native constructor or from DllMain.
- not enough space for locale information
- Attempt to initialize the CRT more than once.
This indicates a bug in your application.
- CRT not initialized
- unable to initialize heap
- not enough space for lowio initialization
- not enough space for stdio initialization
- pure virtual function call
- not enough space for _onexit/atexit table
- unable to open console device
- unexpected heap error
- unexpected multithread lock error
- not enough space for thread data
This application has requested the Runtime to terminate it in an unusual way.
Please contact the application's support team for more information.
- not enough space for environment
- not enough space for arguments
- floating point support not loaded
Microsoft Visual C++ Runtime Library
<program name unknown>
Runtime Error!
Program:
EncodePointer
DecodePointer
FlsFree
FlsSetValue
FlsGetValue
FlsAlloc
GetProcessWindowStation
GetUserObjectInformationA
GetLastActivePopup
GetActiveWindow
MessageBoxA
USER32.DLL
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
HH:mm:ss
dddd, MMMM dd, yyyy
MM/dd/yy
December
November
October
September
August
February
January
Saturday
Friday
Thursday
Wednesday
Tuesday
Monday
Sunday
SunMonTueWedThuFriSat
JanFebMarAprMayJunJulAugSepOctNovDec
TzSpecificLocalTimeToSystemTime
WaitForSingleObject
CreateThread
lstrlenW
VirtualProtect
GetProcAddress
LoadLibraryA
VirtualAlloc
GetModuleHandleA
FreeConsole
KERNEL32.dll
GetLastError
HeapFree
HeapAlloc
GetCommandLineA
HeapCreate
VirtualFree
DeleteCriticalSection
LeaveCriticalSection
EnterCriticalSection
HeapReAlloc
GetModuleHandleW
ExitProcess
WriteFile
GetStdHandle
GetModuleFileNameA
SetUnhandledExceptionFilter
FreeEnvironmentStringsA
GetEnvironmentStrings
FreeEnvironmentStringsW
WideCharToMultiByte
GetEnvironmentStringsW
SetHandleCount
GetFileType
GetStartupInfoA
TlsGetValue
TlsAlloc
TlsSetValue
TlsFree
InterlockedIncrement
SetLastError
GetCurrentThreadId
InterlockedDecrement
QueryPerformanceCounter
GetTickCount
GetCurrentProcessId
GetSystemTimeAsFileTime
TerminateProcess
GetCurrentProcess
UnhandledExceptionFilter
IsDebuggerPresent
InitializeCriticalSectionAndSpinCount
RtlUnwind
GetCPInfo
GetACP
GetOEMCP
IsValidCodePage
HeapSize
GetLocaleInfoA
LCMapStringA
MultiByteToWideChar
LCMapStringW
GetStringTypeA
GetStringTypeW
CADLARF
PREED?
`?AJEL@
jnE>FNARQGNS
TT`?R?JPrAAR:jEJ?_:CN`J9Nv
wfDO>GNu
wcAJ=R?NjFCGNFNE?R?JDEoN?RJG@u
qmmzzp{
{mn|r}ozp
`:@?NF
F@PDAGJQ
`:@?NF
pDGGNP?JDE@
lNENAJP
pDFCAN@@JDEfDON
nE>FNARQGN
joJ@CD@RQGN
a>E?JFNmJNGOkREOGN
]RG>N_:CN
lN?_:CN
`:@?NF
oJ@CD@N
aN=NA@N
pDFCJGNAlNENAR?NOr??AJQ>?N
l>JOr??AJQ>?N
oNQ>LLRQGNr??AJQ>?N
pDF]J@JQGNr??AJQ>?N
r@@NFQG:_J?GNr??AJQ>?N
r@@NFQG:_ARONFRAHr??AJQ>?N
_RALN?mARFN<DAHr??AJQ>?N
r@@NFQG:mJGN]NA@JDEr??AJQ>?N
r@@NFQG:pDEMJL>AR?JDEr??AJQ>?N
r@@NFQG:oN@PAJC?JDEr??AJQ>?N
pDFCJGR?JDEaNGR;R?JDE@r??AJQ>?N
r@@NFQG:cADO>P?r??AJQ>?N
r@@NFQG:pDC:AJLK?r??AJQ>?N
r@@NFQG:pDFCRE:r??AJQ>?N
a>E?JFNpDFCR?JQJGJ?:r??AJQ>?N
bN=HJLIL>
`:@?NF
a>E?JFN
]NA@JDEJEL
lYJC`?ANRF
fNFDA:`?ANRF
cADLARF
`:@?NF
`:@?NF
pDFCAN@@JDE
`:@?NF
aNMGNP?JDE
`:@?NF
jE=DHNfNFQNA
qJEONA
k>E?NA
qJ?pDE=NA?NA
`:@?NF
oJRLED@?JP@
`:@?NF
a>E?JFN
jE?NADC`NA=JPN@
`:@?NF
a>E?JFN
pDFCJGNA`NA=JPN@
oNQ>LLJELfDON@
qJEOJELmGRL@
a>E?JFNkNGCNA@
dQINP?
bN=HJLIL>
jEJ?JRGJ9NrAAR:
_DrAAR:
r@@NFQG:
DCTjENB>RGJ?:
\ARCeDEn;PNC?JDE_KAD<@
{Rzz|Q
en_mARFN<DAH
]NA@JDEv=
mARFN<DAHoJ@CGR:eRFN
mARFN<DAH
TpDAn;NfRJE
F@PDANN
_P1dCGQ
Ls;9}1j
iOrq7x
d@ P6[
tK]?7N
=l6b_Q
7i3<8I
Ju!v*0N
$A\l#m<
?.I2Q
OM-}(h
'Z&Kn
im^,mK
Y"Ww5
<\}OZ1
~|J\'P
9<'!6I\K
@F1'z'
g0`}&{
/XCKEF
\xzI}/z
9) 0RG
iFX`{i
\gVyt&0
%BX}\vn
|95`V>O
Y^v"?W
1=^aW+
Fh(a6N
nxB&*c
Nyp*"*
'yiO19
%6X'dgr
/2fZ}l]
U5_WYLS
7Xw"Z4
(H(|@"
Q?>_K8
,5PM78
s*KjZ5
eAFAlv
s4CO*@
6;?fh
V?b'Quw
4eF!$o
ZCF)ID
t1616k
UVAZC"`
}p3C$=
N{|2U|
#KqhQ?
t%k.W
AH>sTM
LEF.3k
ucO2_N
gKQ_qhp
|&RBM?
|o~/ED
b:`lg`
<P9%JjS
X4}&`+1_XqK
[:%j8lSH
OyMY8/
QQB%Vp
g}n8zQQ}
t&~+~I]
:Z<$yH
t,k~(z
LC9>TZ
'AMUY`
(h5Se9
Mh-e"6
nwY&LP
M Hi')!
XHH\"a
v>J*?I
kSGfZN
}Qh|+gqr
:0&v,byH
t0GXP};
Br7qZm
`XE"G`_v
ylZKvk
.y\9e5
BA+J( R
dA93'vs
Pf.fU5
[C3^oY
<H#q`L
(<p8Tm
p\$1ab
$iI_p.
.}v2T^
GJOu<4
$V5aM'
:eVi!Dd
n"O*V!
+NsI|X%
Do95q&
m?z@\`
\']WEP
~A?`g"
FY"8z>
W.y0T0
dBTxe=P
YSAR:;|
@Hb-4\D.=
wd*<r[
)kvOnb6
Bs4aT1
n/#Mlhy
b54a/n*
`-Xk{Re?
/7W~#(
=m_jQ}}|]
-I'C+t
|grMGZO
yCAJUB
v_5X iY)TC
R]<h?_
.<Q%f
2qE6w<
22:a9 f0
x_/0:,J/
KxEc|`+
eleh$a
2j2t\
ch/nm&G
d3d0'
m)1fnZ
p{*%JzXu)
uEEx+Yd2
*7sEv.0
b[OWIw{
`R|R-r
UMC?R5s
A<uy"8
XFb.KQ
MJxf|y&
mor*k7u
E&"`6Qh
Yk%i""
(~Gv&
/?-H.k
|s3!<H:
@DL2e0iKy
yLb1lX
J446N8(
,WvG\Ho(0
R! J=q
y#PTm\
`1uPbZ
cj5{e*
Vy8a ^
g=jJXA
?q;n^,=
Lgg%,}
_.mRPhy
1"^-6D
$q{n$#$
P5Pp<0
[m= "g
bI$^QV[(^>
dN#QN%Vye
ni~ /2
ScHKdq)n
+br[Fk
r7-e;$
Xk$2&f
Jl4Fd,5NM
P_C>z@I
LOdN9
7lNQ#B
9JNK4a
UYoM(VR
fB.~4
;$wr$z
{4~Af^7]
+{IMwIO
H1\tr`
bJKgoLQ
oQWHfu
7Z!rLv
5Hcve%
E"&!.M
:m7>6P8
SM:hp\
W]" TUW
-K?>@QUafMe
-cAQinVq
z<Ua=l
JJAMbQi`Vq5H=XXZf
CL>r:j
RErhQrm
Z}x:e<\eK9Y]
Ue#YYV^
OmAjVa:]@nInr
D]RQ\9Qf:;j
BaE^e9b^
:MMHlQA
0UDQ4&
`$29?V
9:xKX
Q(&1sG
K#c_(
GNu#w"
!UAk9:
Wa.Wa.
YGd9_(
.pGw15#i6n
9qynpx
FSN3Dqsl
IDDS(S2
lJ 8[<
=~-x!5
)Nq$Z;
L_cS)u
}5:2DK
m/Q@!m[\
tBxTW[
F(>y+u1
m{Nkys
/et_|6
e+^.@rt
-@mP_yL3;
.TALEl
JCOH_;3
d. +nA#
uq<;d]
"4|l]Y
G@%"@:
Ek"G*W
zB|q]
k;HeWh
{!WO CgU
)!CJre@]
,#<FY_h
5MG};(
PhZxH75d
_sv~jt
)&PP#bF
dlZg"/
Z!o%/o
h +*aqO
<:]U|f
ExQZ/_
B)i1{Y
zU!cAO
YYz&i1
nwA_)QW,'
}rqaJn
VX</V/
Sa1],$
Q2qh$M
wrILHW
61JoP(
G[UNJp
3h1M?D
IJTp\5!6_
%v}9#w|
B%G}55
<5uGT`
{K)|@=]
QR<u_|*
%?j49s
WVC+s^
#n_Gfi
LT% 0+X
<=!!)Y<
UZlR8q
Yv.`L}R
%L#%3~
c.A\+X9
2Mo`z19>
Rl|}{U
>h1GwM;L5D
f{@H:"&
lnNe2{
lM|\$ s
)B>#`>\.E
*7Qe',
qpJ-t]],
C2aph+
p%eg}X
e8R4L}
!*x`sn
@sX6<
FFeEb5
k*T:WU
GH:>_i
>@,'Br
|xzw:N&
z@w)QG
W1Y7vm
5)o(HA
|-4~5%
nz#$Pz"
R!xA\h
HnEn#k?gCnR
[N>NrI
OPURdC
HNa-JQ
\!bF PD
WC@F('fcn
S3+i>7
}&&yA`
hkL5.n
2X`/Mu
zU@BMs<
~{M!It
:rx5T$n
vOfVWc
8N_4&[GkR
q(P~zP
Z,u$mx
Q;9(B9
H%IP+f
N#~4$
q0E|LVn
Qjj}T?
P(7MC
d>QqVD
$})^}Z
;UD3m`*
kfA-}Z
])ez)
tO==1-0
m82N4a
QmWStX*
B,xU<,,z
0IfKe7
IF5NLbn
$`)EK>u
Mc~o-y
}0;$T
3;xW.A
W-ALhb
(U="4"@"=";
E7?VZD
"muM0m
<4%O<4
DnuP8Z
}9!~BH
+X]7uY
BAmXhu
/O!S!m
44L4T4
$T\ttt
2j;1j;
>kH#Av
Pv`0#Qv`
XhGdhG$0Q
nv6bdT
RrtMr8
~MXJ&J]YP
%K ]Kr
G*2:\w
(%hBL!o
uE-$2%
*A'kLB:
3xJC
I5~i4u-?
Z3AM{$
?T<X#@
4c>(ue
\34\2t
|lB4uYQ
yb64uY
"74!:a
\A5zY[
>vO$f3
]n{TJ$j:
\3$r50
7Q[ Nw
tA<nm4
tA(mm4
"L[WZ4
't Yw'
>\# '\q
q/|2 J
H{t&op
0x{4Ud
CLOTS+t
B|IK6`
<2@J4e
zpTL{p
;tA2YF
e_h+6{\1
Ftp;vZzo
=N:s#@
==5[z:
;4tIDV
?SmT~n5%
1n?uFD
Qo C$&tm
t%vd@^
,Lk5 *
MCd:i\
ACd5*`
_S`SdSc6
J+:f.|_
PRF6}t
9]9xH'
ZRHZ*>
RA5%h;
{^>1`
\ ^t+g
E5"VfK
)avXVn
z.aTC
A2adRW\
-zn.:p
mH<?\R
mH<?bR
(R~TaR?
B[?].X
hSZYl{
gv^JVi
x1ierj7F1,
1lv`FZ
`pbAQ0Z
bX9m^`D
FH$[-[
HW0c}
Q 3|od
0O^m~UK"
[}+2qd
\H@.lNuZ
G:t+t[
e[Yr3X
O5DV_K
"L+SEx
n4MDC'
k6H+f4'
fJCC6+k
ThI+%q
]]R.4}
~'ggQ8
:%Pd5U
%v]1f<#
?P6rx,
,=?8#;$
DywyeV
:w"bfI
?f3h36
vtCZpG4m
Q%a9hm
88<`L(
W\af_l
W12%Vd
/1ULxx
1C1kU5
r3k}P/
sxX.'X
goV2$l
yz;$p<
21S7U9-J
^*49)4
xXL`cN
:D1<!(;gd
rhEDcO
*u~p*FV
q"V!kL&
t"GHkd
f00S}(
Qolu[.$[
EFP!F-
$7Vbo
\06L*>
]o_uId
c$GtUWz
<Jb)(Y
e\v5UM|3
)ZR0D-
8t%c1\CW
%~4 U}
U6mPtvV
3u/yC;xt
I]~I<~(
!;~&J{
he~2Zn
D=R;DK;
.U^>u'4
-yKSmET
i[&x?'
hfn;ti
TcF'l"
?`FMQ.
EK*'T
8.+}3F
~4K$3B\
N=>4Ry
w2&_=~
,KpFKs6a$Or
Gkwr6
4Hb6~*T
<\D:B'
}~|%LK
0j7biv
;CE]}5
gu(BY
;3Dy0.
_k,z%:
xe~*&U7
47<kPx
m7;Osf
U<@{]j
H}.p9M
6^K_Rk
yxmcd~
"Dpf"^\8
qlT1%E
~r{aEL&F
xZPNG=
T*E=:+
?1h6|)
Vi(;BU:
i7`y}/K
oa`pnp&
:w!<fzi
.`Y Vit
ut\_JT
>F)>&S
!iH`:F,
9{=8w'
-P47Bw
&Qa1lO
Z'o=:t
XQgdg>
q\=F-`}
YD9u*^z,Z
Z`j[(+
k1.me|
>|i4^3
Zdt2&{
GSWNEF
@j ~^Fs
%}eST=
[p)<^-
*MGSaM
_wgh3:^
U39dKv
jJTiGt
4i+r+0
s2>=`+<w{E
L:RXN+$
-uj.)>U'
ud:>Dz
Y;Y8KN
X$;Og/
e\/d~G
z&K86wU
u6E+>p<
j0v!I:4.
G)"@]_
q9G3.b
RM8 4zR2
*D<DG
:v^obI
07N;(wbP
Ta,-Fpm
['jrQ~
:,m8a'
H%(P0G
!zK!5x<
|xXQH.
:q-OyN
sD=r4w
Fwa`V`^`Z
!?xr\,
9BiStzQ
[sf|#h
ySKx6~
PfBJ#0(
kr7W,'*Bz%
Exc:{7
6QxlAP
1B*e7)Z
_<$FC
ILDD8~
,xt;`o
v=kL=r
$E-^'^
#Xy_k
-$=mGo(s
<{\Ooo
$Hz\B,
?T&b |
r%}<bD3F
5EN5X-E
H4-Uhu
5%eX#L
D2R?|Y
013koc_k
`*"9/E
jC8*.C
'UBY(?
0~t+6t
cC>gRE
(*4j:l
p"Q=A)
~j;=}2
i6`efY
",>lIc
>&S;H.
YL9dnHs
A&@=h=
SD)sps
nJ`hTa
Pzd/7=|
Ixv)D{
{3;0],iE
nI$j6}
}4zC:A
qj9?o!
A.V.>z
_x9Ntg
M[`X.}
JTAs*i
P-w_l(
83O6[
Pi{Z?U
-OOe{n
P/@'1
fE#h 7
WIRdqgqa
QBOAW,
e'9"O[
yK}BSk
q8aINrxh}=
x!u"_[8
O]xtww
^ |TRZ
L|[<UU
D|kZ,P
Xy0F)1%L(t
mf,MOp
pxBA=1
257c`Ne
>R><<>g&
el$ayHS
4+w(#D=
~8kYRD1
MVWl}=
ok^gQm
cZMN][
/E&p@nT
6N[Mju{\r
E$ysfL
^Bh2KV
62,9fy!=VmX
YWrQfw
f{}]u@
rvvywqK
%oiorej
H[SB0-yv
[zs:l#
yd8;Yne
PY77F)
JzE5ET
ERRePB
+"%CU1
I*:;3x
|`R;hI
>Dim1R
5rFW0E
V@i$6X
B/.P:i6
3vFNA%
j&VX1=
Zk&,Gc
4>AJ:E
z1j;3[
nK#D@4
5@o!._m"
7A|~yZr
H#$D5Ip
]y6:U{!
Ug,@5j
KEY`Pr
,a>U{t
f:y=w0dF
f{^'<f
u#t%R
6jDC#g
}DvGVT
jj0I7rTW
BbuV)-)
}[+I\qH
=NA@JDEv
NEPDOJELv
@?REORGDENv
wR@@NFQG:
;FGE@v
>AEy@PKNFR@
FJPAD@DM?
PDFyR@F
FREJMN@?]NA@JDEv
wR@@NFQG:jONE?J?:
=NA@JDEv
f:rCCGJPR?JDE
w?A>@?jEMD
;FGE@v
>AEy@PKNFR@
FJPAD@DM?
PDFyR@F
w@NP>AJ?:u
wANB>N@?NOcAJ=JGNLN@
;FGE@v
>AEy@PKNFR@
FJPAD@DM?
PDFyR@F
wANB>N@?NOn;NP>?JDEgN=NG
GN=NGv
R@jE=DHNA
>JrPPN@@v
ANB>N@?NOcAJ=JGNLN@u
@NP>AJ?:u
?A>@?jEMDu
R@@NFQG:u
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
KERNEL32.dll
TzSpecificLocalTimeToSystemTime
WaitForSingleObject
CreateThread
lstrlenW
VirtualProtect
GetProcAddress
LoadLibraryA
VirtualAlloc
GetModuleHandleA
FreeConsole
GetLastError
HeapFree
HeapAlloc
GetCommandLineA
HeapCreate
VirtualFree
DeleteCriticalSection
LeaveCriticalSection
EnterCriticalSection
HeapReAlloc
GetModuleHandleW
ExitProcess
WriteFile
GetStdHandle
GetModuleFileNameA
SetUnhandledExceptionFilter
FreeEnvironmentStringsA
GetEnvironmentStrings
FreeEnvironmentStringsW
WideCharToMultiByte
GetEnvironmentStringsW
SetHandleCount
GetFileType
GetStartupInfoA
TlsGetValue
TlsAlloc
TlsSetValue
TlsFree
InterlockedIncrement
SetLastError
GetCurrentThreadId
InterlockedDecrement
QueryPerformanceCounter
GetTickCount
GetCurrentProcessId
GetSystemTimeAsFileTime
TerminateProcess
GetCurrentProcess
UnhandledExceptionFilter
IsDebuggerPresent
InitializeCriticalSectionAndSpinCount
RtlUnwind
GetCPInfo
GetACP
GetOEMCP
IsValidCodePage
HeapSize
GetLocaleInfoA
LCMapStringA
MultiByteToWideChar
LCMapStringW
GetStringTypeA
GetStringTypeW
NTDLL.DLL
PersonalizeEndpoint
StreamlineCapability
ModifyArtifact
RefineComponent
AdjustObject
DeactivateComponent
PersonalizeInstrument
PersonalizeEndpoint
EnhanceFramework
ModernizeCapability
AdjustInstrument
OverhaulObject
BuildInstrument
AdjustEndpoint
UpdateConfiguration
USER32.DLL
ReconfigureComponent
ModifyConfiguration
EnhanceEndpoint
EnhancePart
StreamlineInstrument
ModernizeOperation
AdjustLayer
RefineFramework
ModifyProtocol
RefinePart
BuildCapability
RefineObject
Amidst the bustling city, a sense of tranquility could be found in the hidden park. The gentle breeze rustled through the leaves, carrying a faint scent of flowers that enveloped the air. Birds chirped melodiously, creating a symphony of nature's music. The sunlight cast a warm glow on everything it touched, making the surroundings come alive with vibrant colors. People strolled along the pathway, their laughter and conversations blending harmoniously. It was a serene oasis, a refuge from the chaos of everyday life, inviting you to simply be present and find solace.
Sectigo Limited1+0)
"Sectigo Public Code Signing CA R360
221219000000Z
251218235959Z0k1
Massachusetts1!0
EnterpriseDB Corporation1!0
EnterpriseDB Corporation0
https://sectigo.com/CPS0
8http://crl.sectigo.com/SectigoPublicCodeSigningCAR36.crl0y
8http://crt.sectigo.com/SectigoPublicCodeSigningCAR36.crt0#
http://ocsp.sectigo.com0
0yKW/m
9K'pQv
Sectigo Limited1+0)
"Sectigo Public Code Signing CA R36
@:MB?3
20230914122149Z
DigiCert, Inc.1;09
2DigiCert Trusted G4 RSA4096 SHA256 TimeStamping CA0
230714000000Z
341013235959Z0H1
DigiCert, Inc.1 0
DigiCert Timestamp 20230
Ihttp://crl3.digicert.com/DigiCertTrustedG4RSA4096SHA256TimeStampingCA.crl0
http://ocsp.digicert.com0X
Lhttp://cacerts.digicert.com/DigiCertTrustedG4RSA4096SHA256TimeStampingCA.crt0
l2|X/gGe
(f*^[0
DigiCert Inc1
www.digicert.com1!0
DigiCert Trusted Root G40
220323000000Z
370322235959Z0c1
DigiCert, Inc.1;09
2DigiCert Trusted G4 RSA4096 SHA256 TimeStamping CA0
http://ocsp.digicert.com0A
5http://cacerts.digicert.com/DigiCertTrustedRootG4.crt0C
2http://crl3.digicert.com/DigiCertTrustedRootG4.crl0
DigiCert Inc1
www.digicert.com1$0"
DigiCert Assured ID Root CA0
220801000000Z
311109235959Z0b1
DigiCert Inc1
www.digicert.com1!0
DigiCert Trusted Root G40
]J<0"0i3
v=Y]Bv
http://ocsp.digicert.com0C
7http://cacerts.digicert.com/DigiCertAssuredIDRootCA.crt0E
4http://crl3.digicert.com/DigiCertAssuredIDRootCA.crl0
~qj#k"
DigiCert, Inc.1;09
2DigiCert Trusted G4 RSA4096 SHA256 TimeStamping CA
230914122149Z0+
/1(0&0$0"
@WhA6o
#"EGT,
Greater Manchester1
Salford1
Sectigo Limited1$0"
Sectigo RSA Code Signing CA0
210322000000Z
240321235959Z0
532101
Wisconsin1
MILWAUKEE1
2653 N 54TH ST1
Gary Kramlich1
Gary Kramlich0
https://sectigo.com/CPS0
2http://crl.sectigo.com/SectigoRSACodeSigningCA.crl0s
2http://crt.sectigo.com/SectigoRSACodeSigningCA.crt0#
http://ocsp.sectigo.com0
grim@reaperworld.com0
Greater Manchester1
Salford1
Comodo CA Limited1!0
AAA Certificate Services0
040101000000Z
281231235959Z0{1
Greater Manchester1
Salford1
Comodo CA Limited1!0
AAA Certificate Services0
2http://crl.comodoca.com/AAACertificateServices.crl06
0http://crl.comodo.net/AAACertificateServices.crl0
Greater Manchester1
Salford1
Comodo CA Limited1!0
AAA Certificate Services0
190312000000Z
281231235959Z0
New Jersey1
Jersey City1
The USERTRUST Network1.0,
%USERTrust RSA Certification Authority0
2http://crl.comodoca.com/AAACertificateServices.crl04
http://ocsp.comodoca.com0
New Jersey1
Jersey City1
The USERTRUST Network1.0,
%USERTrust RSA Certification Authority0
181102000000Z
301231235959Z0|1
Greater Manchester1
Salford1
Sectigo Limited1$0"
Sectigo RSA Code Signing CA0
iemn'
?http://crl.usertrust.com/USERTrustRSACertificationAuthority.crl0v
3http://crt.usertrust.com/USERTrustRSAAddTrustCA.crt0%
http://ocsp.usertrust.com0
#jYhRB_
mt^Ju~
2&-jWp
DigiCert Inc1
www.digicert.com1$0"
DigiCert Assured ID Root CA0
220801000000Z
311109235959Z0b1
DigiCert Inc1
www.digicert.com1!0
DigiCert Trusted Root G40
]J<0"0i3
v=Y]Bv
http://ocsp.digicert.com0C
7http://cacerts.digicert.com/DigiCertAssuredIDRootCA.crt0E
4http://crl3.digicert.com/DigiCertAssuredIDRootCA.crl0
~qj#k"
(f*^[0
DigiCert Inc1
www.digicert.com1!0
DigiCert Trusted Root G40
220323000000Z
370322235959Z0c1
DigiCert, Inc.1;09
2DigiCert Trusted G4 RSA4096 SHA256 TimeStamping CA0
http://ocsp.digicert.com0A
5http://cacerts.digicert.com/DigiCertTrustedRootG4.crt0C
2http://crl3.digicert.com/DigiCertTrustedRootG4.crl0
DigiCert, Inc.1;09
2DigiCert Trusted G4 RSA4096 SHA256 TimeStamping CA0
220921000000Z
331121235959Z0F1
DigiCert1$0"
DigiCert Timestamp 2022 - 20
Ihttp://crl3.digicert.com/DigiCertTrustedG4RSA4096SHA256TimeStampingCA.crl0
http://ocsp.digicert.com0X
Lhttp://cacerts.digicert.com/DigiCertTrustedG4RSA4096SHA256TimeStampingCA.crt0
Greater Manchester1
Salford1
Sectigo Limited1$0"
Sectigo RSA Code Signing CA
230101042002Z0
Pidgin Installer
https://pidgin.im0
DigiCert, Inc.1;09
2DigiCert Trusted G4 RSA4096 SHA256 TimeStamping CA
230101042002Z0/
Greater Manchester1
Salford1
Sectigo Limited1$0"
Sectigo RSA Code Signing CA0
210322000000Z
240321235959Z0
532101
Wisconsin1
MILWAUKEE1
2653 N 54TH ST1
Gary Kramlich1
Gary Kramlich0
https://sectigo.com/CPS0
2http://crl.sectigo.com/SectigoRSACodeSigningCA.crl0s
2http://crt.sectigo.com/SectigoRSACodeSigningCA.crt0#
http://ocsp.sectigo.com0
grim@reaperworld.com0
Greater Manchester1
Salford1
Comodo CA Limited1!0
AAA Certificate Services0
040101000000Z
281231235959Z0{1
Greater Manchester1
Salford1
Comodo CA Limited1!0
AAA Certificate Services0
2http://crl.comodoca.com/AAACertificateServices.crl06
0http://crl.comodo.net/AAACertificateServices.crl0
Greater Manchester1
Salford1
Comodo CA Limited1!0
AAA Certificate Services0
190312000000Z
281231235959Z0
New Jersey1
Jersey City1
The USERTRUST Network1.0,
%USERTrust RSA Certification Authority0
2http://crl.comodoca.com/AAACertificateServices.crl04
http://ocsp.comodoca.com0
New Jersey1
Jersey City1
The USERTRUST Network1.0,
%USERTrust RSA Certification Authority0
181102000000Z
301231235959Z0|1
Greater Manchester1
Salford1
Sectigo Limited1$0"
Sectigo RSA Code Signing CA0
iemn'
?http://crl.usertrust.com/USERTrustRSACertificationAuthority.crl0v
3http://crt.usertrust.com/USERTrustRSAAddTrustCA.crt0%
http://ocsp.usertrust.com0
#jYhRB_
mt^Ju~
2&-jWp
DigiCert Inc1
www.digicert.com1$0"
DigiCert Assured ID Root CA0
220801000000Z
311109235959Z0b1
DigiCert Inc1
www.digicert.com1!0
DigiCert Trusted Root G40
]J<0"0i3
v=Y]Bv
http://ocsp.digicert.com0C
7http://cacerts.digicert.com/DigiCertAssuredIDRootCA.crt0E
4http://crl3.digicert.com/DigiCertAssuredIDRootCA.crl0
~qj#k"
(f*^[0
DigiCert Inc1
www.digicert.com1!0
DigiCert Trusted Root G40
220323000000Z
370322235959Z0c1
DigiCert, Inc.1;09
2DigiCert Trusted G4 RSA4096 SHA256 TimeStamping CA0
http://ocsp.digicert.com0A
5http://cacerts.digicert.com/DigiCertTrustedRootG4.crt0C
2http://crl3.digicert.com/DigiCertTrustedRootG4.crl0
DigiCert, Inc.1;09
2DigiCert Trusted G4 RSA4096 SHA256 TimeStamping CA0
220921000000Z
331121235959Z0F1
DigiCert1$0"
DigiCert Timestamp 2022 - 20
Ihttp://crl3.digicert.com/DigiCertTrustedG4RSA4096SHA256TimeStampingCA.crl0
http://ocsp.digicert.com0X
Lhttp://cacerts.digicert.com/DigiCertTrustedG4RSA4096SHA256TimeStampingCA.crt0
Greater Manchester1
Salford1
Sectigo Limited1$0"
Sectigo RSA Code Signing CA
230101042002Z0
Pidgin Installer
https://pidgin.im0
DigiCert, Inc.1;09
2DigiCert Trusted G4 RSA4096 SHA256 TimeStamping CA
230101042003Z0/
QL+)MBM
mscoree.dll
KERNEL32.DLL
((((( H
h(((( H
H
<<<Obsolete>>
<<<Obsolete>>
Antivirus Signature
Bkav W32.AIDetectMalware
Lionic Trojan.Win32.Crysan.m!c
Elastic malicious (high confidence)
MicroWorld-eScan Trojan.GenericKD.70440426
CMC Clean
CAT-QuickHeal Backdoor.Crysan
Skyhigh Artemis!Trojan
McAfee Artemis!68392CD3B6D0
Malwarebytes Trojan.Downloader
Zillya Clean
Sangfor Trojan.Win32.Save.a
K7AntiVirus Trojan ( 005a885a1 )
BitDefender Trojan.GenericKD.70440426
K7GW Trojan ( 005a885a1 )
Cybereason malicious.55e9c6
Arcabit Trojan.Generic.D432D5EA
Baidu Clean
VirIT Clean
Symantec ML.Attribute.HighConfidence
tehtris Generic.Malware
ESET-NOD32 a variant of Win32/Kryptik.HUAJ
Cynet Malicious (score: 100)
APEX Malicious
Paloalto Clean
ClamAV Clean
Kaspersky HEUR:Backdoor.Win32.Crysan.gen
Alibaba Trojan:Win32/Kryptik.88e601f7
NANO-Antivirus Trojan.Win32.Crysan.kdvnyc
ViRobot Clean
Rising Backdoor.Agent!8.C5D (TFE:1:jrfVwNkjbiN)
TACHYON Clean
Sophos Mal/Generic-S
F-Secure Clean
DrWeb Trojan.PackedNET.2148
VIPRE Trojan.GenericKD.70440426
TrendMicro Clean
Trapmine malicious.high.ml.score
FireEye Generic.mg.68392cd3b6d0900a
Emsisoft Trojan.GenericKD.70440426 (B)
Ikarus Trojan.Win32.Crypt
Jiangmin Clean
Webroot W32.Trojan.Znyonm
Varist W32/ABRisk.LZMT-0884
Avira Clean
Antiy-AVL Trojan/Win32.Kryptik.hsyn
Kingsoft Win32.HeurC.KVMH008.a
Gridinsoft Malware.Win32.ZgRAT.bot
Xcitium Clean
Microsoft Trojan:MSIL/Crysan.AAET!MTB
SUPERAntiSpyware Clean
ZoneAlarm HEUR:Backdoor.Win32.Crysan.gen
GData Win32.Trojan.Agent.HPCXEK
Google Detected
AhnLab-V3 Trojan/Win.Generic.R622793
Acronis Clean
BitDefenderTheta Gen:NN.ZexaF.36792.FyY@a8IxLto
ALYac Trojan.GenericKD.70440426
MAX malware (ai score=87)
DeepInstinct MALICIOUS
VBA32 Clean
Cylance unsafe
Panda Trj/Chgt.AD
Zoner Clean
TrendMicro-HouseCall Clean
Tencent Malware.Win32.Gencirc.13f75d0e
Yandex Clean
SentinelOne Static AI - Malicious PE
MaxSecure Trojan.WIN32.Zenpak.gen_223205
Fortinet W32/Kryptik.HUAJ!tr
AVG Win32:PWSX-gen [Trj]
Avast Win32:PWSX-gen [Trj]
CrowdStrike win/malicious_confidence_100% (W)
No IRMA results available.