Static | ZeroBOX

PE Compile Time

2023-11-19 23:44:31

PE Imphash

411d07b56145caf2dc98484203a9ed7b

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x00021678 0x00021800 6.4150708282
.rdata 0x00023000 0x00008ca6 0x00008e00 4.96828479426
.data 0x0002c000 0x00083178 0x00082800 7.99798469108
.reloc 0x000b0000 0x00001a40 0x00001c00 6.44604461002

Imports

Library USER32.dll:
0x423130 TranslateMessage
0x423134 KillTimer
0x423138 DispatchMessageW
0x42313c GetMessageW
0x423140 SetTimer
Library KERNEL32.dll:
0x423000 FreeLibrary
0x423004 WriteConsoleW
0x423008 CloseHandle
0x42300c CreateFileW
0x423010 GetDiskFreeSpaceExA
0x42301c HeapAlloc
0x423020 HeapFree
0x423024 GetCurrentProcess
0x423028 GetSystemTime
0x42302c GetLocalTime
0x423030 VirtualProtect
0x423034 GetModuleHandleA
0x423038 GetProcAddress
0x42303c LoadLibraryA
0x423040 lstrcmpA
0x423044 lstrlenA
0x423048 FreeConsole
0x423054 TerminateProcess
0x42305c GetCurrentProcessId
0x423060 GetCurrentThreadId
0x423068 InitializeSListHead
0x42306c IsDebuggerPresent
0x423070 GetStartupInfoW
0x423074 GetModuleHandleW
0x423078 SetFilePointerEx
0x42307c GetConsoleMode
0x423080 RaiseException
0x423084 GetLastError
0x423088 SetLastError
0x42308c EncodePointer
0x4230a0 TlsAlloc
0x4230a4 TlsGetValue
0x4230a8 TlsSetValue
0x4230ac TlsFree
0x4230b0 DecodePointer
0x4230b4 LoadLibraryExW
0x4230b8 GetStdHandle
0x4230bc WriteFile
0x4230c0 GetModuleFileNameW
0x4230c4 ExitProcess
0x4230c8 GetModuleHandleExW
0x4230cc GetCommandLineA
0x4230d0 GetCommandLineW
0x4230d4 FindClose
0x4230d8 FindFirstFileExW
0x4230dc FindNextFileW
0x4230e0 IsValidCodePage
0x4230e4 GetACP
0x4230e8 GetOEMCP
0x4230ec GetCPInfo
0x4230f0 MultiByteToWideChar
0x4230f4 WideCharToMultiByte
0x423104 SetStdHandle
0x423108 GetFileType
0x42310c GetStringTypeW
0x423110 CompareStringW
0x423114 LCMapStringW
0x423118 GetProcessHeap
0x42311c HeapSize
0x423120 HeapReAlloc
0x423124 FlushFileBuffers
0x423128 GetConsoleOutputCP
Library ntdll.dll:
0x423148 RtlUnwind

!This program cannot be run in DOS mode.
`.rdata
@.data
.reloc
QQSVWd
t/hPAB
URPQQh@~A
UQPXY]Y[
uSSSSj
f9:t!V
QQSVj8j@
PPPPPPPP
PPPPPVW
PP9E u!PPSVP
ntdll.dll
NtAllocateVirtualMemory
winmm.dll
timeGetTime
winmm.dll
timeGetTime
GrMdgfIuVD
Index_sjnDoHD
Slide_VdEbZLLR
QzjpzGEcww
Var_BMvCVIeWMenvCk
Hustle_RYzLlAUZHDo
ekyiaArKIK
CTX_wgigZax
Hustle_ngvaIU
kxZelcqbmi
pHAfEJYDwe
holJJouvtM
Info_FalnoAsnVpG
Var_XofeZjCCTU
EjILzmLtXU
winmm.dll
timeGetTime
RCypbIZoXb
MzkelrtXBb
iyWgPMfPbS
YlNkeUqRVO
Code_BlzmP
Index_kMVTXWjXcqmnV
DGWZVfUNqg
Ficha_iaqVTAVgyUC
CTX_VfsCoMaGBOE
sHdJpXfkli
qTQArpCbZT
Info_QJRBLF
Code_JGuks
ytxYDOhsAz
Ficha_tdfyoJHJFZMV
Frame_dlyCPojUMbxIO
ZGuUAtsUhJ
GgStqpbSjc
cFaQwcjlvA
Index_zEgUNTN
CTX_Gnfqy
HpiJuHwyIw
OWNbVbALUG
Frame_dytWuQJmRM
CTX_LzJXSG
TLJebKdFtF
XMirrLxZfj
kTQobRfBzF
ytZjYCiZbO
Frame_bzlyFoLNYN
Var_LUZKAWYE
ZYsIfQXWlc
Frame_vOfjoUpKMqOg
Frame_TegPdgIxBYdMg
dffyfHidzq
fOCeNCPhhq
CTX_AcycMeVLhNfew
Slide_wppFVmmEDqV
lGhfWvePfr
Hustle_xCkfEt
Index_VOKat
KQZbPnRylp
xIWqmFnYpg
CTX_XXfAYBsABgcTmR
Hustle_fdABW
laUyUSRCSX
Index_TvCCeClAPY
Ficha_cLEIdrUQM
bfIciKejcI
EvEqPGnBwf
aEFGGMUEEM
PtJFdPYohT
pzvkvHAENH
oPzDsVSCuQ
BvPmhqFZlG
JchFaCUxFB
mXmuYYcnkx
Index_GdXhiIh
Info_mmvRLkiyGNct
tHwXJYTxxO
FkKqNdwOAw
MBYeoWnefY
Index_ifkaAyCSWrY
Var_LzDptPX
XTzhUpRTAw
Hustle_NlObHK
Ficha_uoaDBLZJa
tUUcfWgezw
Frame_npINHpboVdnqzU
Index_jJKHp
SMVdZeMgqC
ykSzXQIQsH
qUfKXkrwbA
Frame_AnDNnsEATFj
Info_ttuxVXZGcL
ftPpiEBwXy
PwWqQmaLTw
MDjiceJGJM
Slide_pAEbainRn
Code_vvkIUPrlJB
twsalKWMFf
yCzkBQNyfw
Slide_HwHjb
Ficha_lCfOsN
dJbqvKzGoc
Info_Rhtiq
Ficha_UZgKfeO
ERFBajYhqm
pvNbtKMgQE
GjkVzqZNJb
iTaGdIwzOq
Var_mMkXepgon
Debug_GqhVn
bxXUuOQlFY
nIWGZdwMQz
EnlnVnLXfX
cbyFLyibzT
rNwQQAAXLg
Frame_KJGKwxAn
Frame_dvdDvVSQtwD
ADDlQnJqOy
jfQLAfArCb
Slide_EzDCb
Hustle_gWRyPQDSau
winmm.dll
timeGetTime
winmm.dll
timeGetTime
SystemDrive
winmm.dll
timeGetTime
winmm.dll
timeGetTime
winmm.dll
timeGetTime
winmm.dll
timeGetTime
Unknown exception
bad array new length
string too long
vector too long
K}@F%u
@33333c
~RD%WD
qDbad allocation
bad exception
__based(
__cdecl
__pascal
__stdcall
__thiscall
__fastcall
__vectorcall
__clrcall
__eabi
__swift_1
__swift_2
__swift_3
__ptr64
__restrict
__unaligned
restrict(
delete
operator
`vftable'
`vbtable'
`vcall'
`typeof'
`local static guard'
`string'
`vbase destructor'
`vector deleting destructor'
`default constructor closure'
`scalar deleting destructor'
`vector constructor iterator'
`vector destructor iterator'
`vector vbase constructor iterator'
`virtual displacement map'
`eh vector constructor iterator'
`eh vector destructor iterator'
`eh vector vbase constructor iterator'
`copy constructor closure'
`udt returning'
`local vftable'
`local vftable constructor closure'
new[]
delete[]
`omni callsig'
`placement delete closure'
`placement delete[] closure'
`managed vector constructor iterator'
`managed vector destructor iterator'
`eh vector copy constructor iterator'
`eh vector vbase copy constructor iterator'
`dynamic initializer for '
`dynamic atexit destructor for '
`vector copy constructor iterator'
`vector vbase copy constructor iterator'
`managed vector copy constructor iterator'
`local static thread guard'
operator ""
operator co_await
operator<=>
Type Descriptor'
Base Class Descriptor at (
Base Class Array'
Class Hierarchy Descriptor'
Complete Object Locator'
`anonymous namespace'
FlsAlloc
FlsFree
FlsGetValue
FlsSetValue
InitializeCriticalSectionEx
_hypot
_nextafter
CorExitProcess
Sunday
Monday
Tuesday
Wednesday
Thursday
Friday
Saturday
January
February
August
September
October
November
December
MM/dd/yy
dddd, MMMM dd, yyyy
HH:mm:ss
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
AreFileApisANSI
CompareStringEx
LCMapStringEx
LocaleNameToLCID
AppPolicyGetProcessTerminationMethod
?5Wg4p
%S#[k=
"B <1=
.text$mn
.text$x
.idata$5
.00cfg
.CRT$XCA
.CRT$XCAA
.CRT$XCZ
.CRT$XIA
.CRT$XIAA
.CRT$XIAC
.CRT$XIC
.CRT$XIZ
.CRT$XPA
.CRT$XPX
.CRT$XPXA
.CRT$XPZ
.CRT$XTA
.CRT$XTZ
.rdata
.rdata$r
.rdata$sxdata
.rdata$voltmd
.rdata$zzzdbg
.rtc$IAA
.rtc$IZZ
.rtc$TAA
.rtc$TZZ
.xdata$x
.idata$2
.idata$3
.idata$4
.idata$6
.data$r
.data$rs
GetMessageW
TranslateMessage
DispatchMessageW
SetTimer
KillTimer
USER32.dll
GetDiskFreeSpaceExA
QueryPerformanceCounter
QueryPerformanceFrequency
HeapAlloc
HeapFree
GetCurrentProcess
GetSystemTime
GetLocalTime
VirtualProtect
GetModuleHandleA
GetProcAddress
LoadLibraryA
lstrcmpA
lstrlenA
FreeConsole
UnhandledExceptionFilter
SetUnhandledExceptionFilter
TerminateProcess
IsProcessorFeaturePresent
GetCurrentProcessId
GetCurrentThreadId
GetSystemTimeAsFileTime
InitializeSListHead
IsDebuggerPresent
GetStartupInfoW
GetModuleHandleW
KERNEL32.dll
RtlUnwind
ntdll.dll
RaiseException
GetLastError
SetLastError
EncodePointer
EnterCriticalSection
LeaveCriticalSection
DeleteCriticalSection
InitializeCriticalSectionAndSpinCount
TlsAlloc
TlsGetValue
TlsSetValue
TlsFree
FreeLibrary
LoadLibraryExW
GetStdHandle
WriteFile
GetModuleFileNameW
ExitProcess
GetModuleHandleExW
GetCommandLineA
GetCommandLineW
FindClose
FindFirstFileExW
FindNextFileW
IsValidCodePage
GetACP
GetOEMCP
GetCPInfo
MultiByteToWideChar
WideCharToMultiByte
GetEnvironmentStringsW
FreeEnvironmentStringsW
SetEnvironmentVariableW
SetStdHandle
GetFileType
GetStringTypeW
CompareStringW
LCMapStringW
GetProcessHeap
HeapSize
HeapReAlloc
FlushFileBuffers
GetConsoleOutputCP
GetConsoleMode
SetFilePointerEx
CreateFileW
CloseHandle
WriteConsoleW
DecodePointer
z])@M|
w.+3L7f
/):k'M
5?}WE=l%]
[{Ao1`
DS}wM2B
V0R)gf
kb~[>x
)z,gin
'_r|Hu
D.%v~y
7@D$iL/
$it@6>D
_8H;4D
R>A#rh
Tt)dpQ
zGdXPg
F2j~?
$*l!N$
U@ZrYe
[B5;0k
KY9\W3Y
e`).uq
t+E^@QU
D$UFdx"
<(hW1Ck3
$fEQ'G
@68eKJ
qy6c13C#I
)Dkf$CR
xR 4/f
oc`N6]
K`c{#B
y,n3x^gb?{
fz=hpP
w/]_]_
.vBo8hI
`,z`-Ux
p/PZrx
TxtK_J
Gx*)Af@
=:3T>?
bh="`7
az!Az])
mQu3Zx
_~Iw0J[>
qIPUOo
TcZK)N
Bte[~c
7co^qc
bi?okK
ft.0Z;`
_gC[in
x>qXN
5r ed+
KxFJ[,
(%jTSu
(H6ZI\
F&hKqe
!U[/9
hq0Ci?E
BUv&18
H"!@:9
gxVXW=E
S2s|W>
kU$\1\>
l{Kn~(
M.>}^R
$\u.\g
}Y--S-S
y.WTl4F
X9A&l;
=]qj.,T
NZ}n?C
S+d)WP/
k9EGXg
h$hb;t
{B*=[O
QgN9[o
_3^G8A
8+\0F+
L)t~JA
(Ckn~X
9<HhJ
(4H0L>
gSQV'[P
Yp5qdy
_hWX3~
[(QH!8Y
G<#M$cm
"n[%?;
?074=GpC`:]
8MSP~)3
Chn'D8^
S-E<?qD
PYJGe[
PQ7/Er
47&/=my
jHL$GL
H^gvqv5X
L:5x -
\y7^ r
\YE@pr
iD@x@#
Lqzq4c
U[pZtp
l0c=>_
\kubEovT
iw*f&{
Uh.wu:
,03.^m
#bWcMd>YO
%Z]D]a
,CVWgu
X.(VbC>.
Qe<!^I
px9((Un
8.%Bi]U
?p222E
w'IHH'p
esLx-S-
kt)Q9e%
~PB|ysJ6
i\RZ'g
`-4jRt
s7E=*i
PlPsp[
+5u 5L
\^ru-x
JsTr$@
;<iqIMl
^wh`+sv@
)0}{8u
[Y\{.[9i
(W\X3Z
b@^'u@
'V;(7{C
vKPh8K
fty?u^J
k7i+mxL3p
#- sbj
Wo4|Et
/#tb&<m
oaG~;n
O-iBP6~b
5V:]WzBWG8<[
i*mC/[`d
gd^g<y
$dxE<1
!{eM8p:
MI>F@P
Ug{$#z&
>]Vk|x
Je% 4@
06+yil-H
E)=c>S
SGTrnl~
j|kPCx
Rqp4?9
zj s9
a5?>4kx
M1:etj
oc#~G~5y
w-.}pf\v
VZ_nc=/ .
?jy]?)=
-$so>"j0
1CZO(O
`<1{z
%V|.Y:HD
>{8h83
a{1DR(
_93b}S(
#wjfUu
ka>Csv
/Htr8~]
AtF~naq_52
KYr4g9
.Wwi+h
{{pLe2'"GzxN
>R*wuV[
4EC3Z9
E`RR.ed
gC:bE;
2|2_?o
84GU(ph[
o5l_5d,
G\@!~Q
R"'SrO
_T0U80m
*,q"-<$
yM_GP@
TMT`cfp
lf\GnEG
4C(,"hv
)'=m0I
Cf,_K{
pI-}uP{
B)Y6:w
v"r6<{
<%7lQ.{
ol'^}U
O->Y4.z
&qCA29
eNBzkW
3r;=1)R
$<vIU>
;^\50k@
YgEZJgA~b_
";L7_V
;vr@fLU
ak,]32
Ls*GJD
01FAjAd
$c{]o
w4)2F4=/
[i`"pT
d[dS m
YfM8sg
cU@`$y
@oPiF_
A@_JY
T?Ndr{
mA%(n[
yJ4\e7
3@y^T>3
zEAibh
#bz7w\
w%VjeK
_wsgo|
Av'rd_
ip22}
,X.8sE
fm=Kol
nPJFTegl
'6}(eJ
a+HmiC
B@=@4N
A5AZ[|
TxT:QD
,F2BUR
j`Ov%baF#
w1XjfL
w|r`X
{FJE X_i8
0"gfpx
C<r~nGP
QX".b{
fU+2s<
n7gU4>k
!4x-Y1w
F$$+g1]
!,3AZ6
Pqh=.QZ
$wm0iIL
SH2-tvT
MZ_*z~
W]P1zM
s(Av/8
UH)6zz
6t1`{Y
`%-tJAq
osIf_
vw"R.2z|e
?Dhnf3
$,\ qT
9HJF5
zN\-db
<r>Gt
=']pP9:
*4i#[5E
}]-Y-4
ff;qO+&
k[\3.WP
>n&#mm
dp!U[T
)^(s]b
/-Ooc)|
YX/4](
WOQvCH
'B J9#
pL)d45
cl(&BI^
ao:Qd8x
r?,z>B(2
nGg!m-
aP<6G:
~M]~lu
y0r]X yVB
cb1Iq%
tH>YpV}
QerT6
.'p=gk
*qaw`+X
X@CJJj
s,F#D;
%G`j~
Xy}|"e
!,jY;)
h<3UfU
<OU&1=-Cn
b.aW+!
\,Y+q@
wKZ]`)
<NuGsU
)tjH\x
rM$!f&
+iFeRhe
)}ly"rU#
YnL\-F
jms}3r
r:ZY;;
Qq|QAy
*>Hb)[
B;1rt7-
)0q5eg
ITL44&
=HxhcK
yIK6.AH#y
/la!d(
9kOB} F
x$Dj0f
=K@*=<
XA-N\I1
6L[$qi@
<{KT*p7
?}w=7V
#"bkHn
A@VaGP
""@WE74
:AY8vE
Ylj'_([x1y
|Q2qW;
W1F"w:
cWrqn&~
%y'b-~A`
G|Z0:i
0tlQhek
Dn@7zt
{kr7v3
5h'y7T%1
$-+D??
IKj!{0
"hLoj$z
6lxE5]
3$rBR/
Fpw-mI
(-Z`W\7
*xee-/
^qH7Rx
eAngV.k
Ox9U;{
XT"2-w
_w36TW
lGtJ,
6Lq#;k*z
[H J;
VZsne);A
G$\ tvN
j 0nv_
GX=gln
i0%6/N
{^#NPb
UB-[6S
:'E2pG
e:7:zi
mpY(|W=
jxZeXTbM
g~I6MR
%1K\=e
U{lh@>
9@4CP&
9zU>`|S
iktI^'
EZaMg>
g_&v`0
+9"Quj
n^]Cby46U
O6*-b3
C_9l7_
,1S"EG
j1/C=
lng{%Z
E\p1Vu
=7aIYC\"
T.ykg$`
F/]:S`
ti|^-?^CL
fx/3K]l)9
~BZDj
-^8H%)
)m,hHT^
q.nW`_
1j0mZ;
D0u{:W
fV2sPSD
1K(/H`
Qg,a)m;A
!QSXxSw
5qB3M8o
Cu@WP9y
C4^c,q
wV`Lb(
4'[u#K{
&Kb-`T
Iw]5*x
jFaaxG<
)7!G_d
n$`7,2i
i1rri"
SVRS?gv
j@l=C`
KLdUI[
@>TpoOQ
4v/w^$8
UmkTVR
Q@#} ;
%Xu*~l
x?atcc
Q<AlFY
J'u.2
bkCIBz
VAF`dD
O^;LPN
"h'o<*"]Pv
rYV{xs0El
^p{$zf
y]R^~a!CK}.2
Fj&N~#5
@9)lC"
Z%gcF.
r%vHJ
[dk\OD
Kq)G$
*[2&BQ
I1:A|
g0Mi,U;9
bv<C %
*Mcs>J?
:2P`u=
`.X_C(q
[Lzw)~
:bH4tj
P~<s},
Gwx7@F
briub4
@p-F}{U
\ Kznq
X8>{{G.U
d6$Lh5I.
`CS6y0
BgCh;X
J[1Tc?
i\WPKX/
#L!nn<
F,RiPI1do2
lo_-Qd`
\!2005
q-W3h(
n\&|)e`&
g4Pmu+
zVQaAew$
`*f6NuQ
;;$S ;
}W$C-
)K`=R7
YZx$fk#
gWUR+Z
xQ*3lb\
65d2+9
:U>U"r
S]-B\54u_
cKQgWz[
v&&!g;B
K32k?pr
^);l^!
hm&ge|(
_,<53"h
Peg}=
y%:p9j#P
eR6=]O
8%QLMD
Fti_@R
&1RoR0
>7W{KW
8t2u6e
Ui*]kM
7,Q,Hb
OA1k7!
3vUmIL
"!'7+e
m{.868
;SA`}b
k}#NaF
<&b;8s
XQ5ZURs
/!1u=>$
XWN.5^
wH1)0'
bbFUY&
q)^Rz[
l.2o&%
lgPh_0
k\9I}E
`{/ttaX>
X4G%we
M 8H3N
F7j[y`
z Ar>S
ldmqs@2
(ud)p[
!H`v\$J
<|=\RonF
P_._i6-
u.Wx&`{
NS3Q7a
SbUjvS
37/)7`
jaS0b|
YvX<N.
]m7qj[
@FT+T@Y
*%[h|Kl
E9[1|t(N
f7D"oW#
+064d?
qgjHw)
pKCCu*
Z]<V)U
%Z{]Xc
AG_8T.
"sIl|r;ek
['w)=r
I(eTX&
Wr[@;fz_
k~=KVTl
u(g:bv
O9SmdgH
01;xygz
*f.C$.,
N|1BX]C
t0.s%5
P*C;G04
xO>bv m%<
[2Ncq
wd!'Hy
2iD.})r'
w#4"7oIE$;
3\AJWCI
Nx[L9k
n1XcP\
.|f(L&
,O9P"}o
}umVdn
_oqCiFG
s-ce}
ZBTcIX
f7 >Wy
},tA#R
g=po-;
d8KSk9`
"3ZWhRz
"dS{<!
A*w(FQ
vi23FS
M$H?O
cH/rr1
`n8QuK.%f
RWy",NC
Xy^2WY
`us[db
wK\hb
(tT~.'
hC9J'3c,_
ZK]QZ-q
*_X0PA&
ox%p[n
7A]BZ*
Rx/T,Mz;d
TMdR)iS>BC
aPmz?</=
Wa.k-DL
Su'NGwe`g@
~T\nR
/ hWa*
M\q XI
OsN#Gl
L6t]Q}g
TN`r}2
VF4L`P
&5+4Q<*
7=@)'a
OR%YLN
wuy=3b
BS+9jH
g{#EI;]
i9@B2D
LnK}JC
wi,]c.,VG
Du:uf#
*~N&HX
w8^!9g
w4xmPw
7##i2+D
Z'znnmm
)8t4HS
:|h2jC
EO?>rH
cQYc93
Nq c+Z
nDVg=<(
fMu--
|+9@6v^8f"
5${s<z
?zQ+1PI
."L x~
_NYurQ
eyeod+
`7>QzI
.Y0@+^{3
63wczV
LBMw27
W*@T8~
AlyBvq
[rqRJj
. a+{VPr
dTX(hz
1KK*[a
Qia|k{>
wPJIp
1,U3Iau
w7-9-s
+:ErG9G,
/_n1cM
jTo[ehP
(|7YA[
t&m;{W<
/%AeZDO
H9$D49
,x%<P]"
g 3z(*
:Ssr/2Fv
1U0R{u
Qd_Vg@
JdU .~%
$Mc)#+S
\ujQ~L
RZZXbt
&i*]S<
cG^ w
ee,Z?zZ-
2sIu=UC
NC6Bq
L"p)1 V
"?ypL&K
m@|!n;M
bKVa/<{e
s~/L~c
p54sH}
v]+j]_
cV6RQQ+T
@I%"h;
R'o_B-
t\csl3P
R;rDh]
\BPi\(
v]O/<K
U-c-Xf
]heJ!w
-j&pg}
<^PHil
"| NohR
VtBm1%
SctupI
m&ICbV
eJh(Ol
fuu^E(
MEf3}lgmI
`GY#f2
",N{>2
0Z/My{
VPg=1<v
\DtkGJ+
,%`[n[6T
-k5k\dNU
+A8|hy
]Gwf-L`
|'Lo`V
{J<G)A
dWD.t+b
y#eXcv
(R'RAl
&J:y.LJ
-(fsYuO
,+s"TjJ
<sEEBi
+Giste
d`5>@*
-_]XFm=p{
}fHIOH
CSpgV4
Wjab1M
hP(*TE
A)J"+h
<I~x"*
2s~gNgr
'#4u%/
$(lGF~W
.m(OLx1
A%$:xoN
7J|rkn
X]Z%V8@
(6d6`u
[=C%C`-
>6h1cYUQ
iAC}!aZ
QUQ.Z[
rO)D&[l
O%HF9
dDHk):
Qw'.2b
Y&skI"
?:VMp;O
h+H;4b
73t K7
r`?in7
PZ`h7
DE[|#)
xx-,s:
vy 3!6
J(7!tY:
;ey<D,R )
I"> nSb%
Fvw> Mr
C'SWy"5
<'lBK.
X2T<&e3
HYX5c`
FKOR<r
<X6rnQ"
^_kxHI<
hGG0 o
"q.^uK"%_1N
a[j2Y(6
h@8eP_
TM2/W/
F^a.+j
l?kj*
k]s*pYm
Jl-e\;
m_+P8D
lb%Eto
*!2<*B-
G_6c#Z
B;JZr[
priV)j
{0IC78
jZ=7FqvYY
w&ty),
`B4=:C
,~lWy|
/tPWt[
jnxFVQe:
X9P:5N
L;T0:H~1
O3V{J/p6
?~|,Y)
4I}hOQ2
/wo#Ud
7S13B-
msuw4.R
'hc'K#
;`A1Vo
mA3J*T
qB8M/V
n6'+O769L
&#-)sQ
#Y7(9<
ce u</
VzZICW
G&um7.^a_
T{JKQb
:CuT}+#
K2[./cq
f00Spo
%TM_T<
Xg*;:>3
gYGYo,Op
x.M E&
(2B Pg
-@y&6g9
kh1v?U_
"\H#X(
70u{{4
\2E iQ
=^i.gm
S8C_gk
DoS%:\]J
3OSPGd,
5n]1n;
R&#[!f'
DcN-m@
A`B=]i
Q_,1?x
{36r_kA
^].u(PUT^
8k7KD
AJpOP_9>m
o<B{CRl
McLpr*
:uVd8xL
TDs:)X
<S=?%z
agYGtZ
UMG/6#
4;J?8g
jt0U{b
C)MYZ2yo
2Oi dJ
LTm9Pw
}Yr&<',
l}?i"g
g]uU.?
MMe9w,
z!*R2r
# <dCq
T8dtu/9}
<{|rDi+1
xjI='#
3Yw<$B
QbY0wo
O$kf'Z
[\ivSB
n8c9VU
/D|;zAP~v
oo18wU
e-:QMK
%L*"c9
3IK;>:E
nAD{0p
ogP+67Y
us879X
p|mUJS3
?u#v^5
p~DSke'
(=04#T'T#*
aZ%'P|K
LL3/C
,$c_ [
?Ff87GX
73F5<`
;vV#~Dl9
/!':/u:>*
?`;P$-
YETg|c
qp?@K5
C9M6LL[
m<d{_;
\|bwqNTzY
vx]b/z
A*uO5I
467?5P
gP2_)D
mbb0#BK
Gw-M\Ot
!&9;Y,
*_a\Co
J*(G}"
8U\=z
FW[6bN`
LVND9}
i@De'&
l&_*44
"G4%KMF
Ey({~@
knX3<}~,q
%ka6sb
g(Bd3j&&<:
?4d{$L
qBeWI6a
uQR8HV
G!pYzD
epmaz"P
CH a2<
!+AuU~
sc_y3D
SJ"S;s
+UTg4C(&
ac)3xr2
E/`=\]
Lp=+|u
^83P\r
%Z"WgmHo
Nz%@_P
[&@P3A
Ii8h(^
sib>pG|
DIIyu
{^8x?&
QVuKyi{
8tR~3F
INi*;)p:
cL.of\O
)gy5?L
~jTOC|s
U^bNtV
oDCYM8`
Rs7S<{hI
tE=bWFj~
:b~20l
1iM,EbS
3,Hl|L
^<Z`,My
Oy"+U!
oK5R_b
0wwjwk
Q%\UgP
:,>Ig7N
6Pc"DP
Kj-AZ`>~;
)=D_5;6
??VwVO
i &w@8
ZA.C:_
(2&L}Z
Gn]9ka
Q%6\_'p
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
.?AVbad_array_new_length@std@@
.?AVbad_alloc@std@@
.?AVexception@std@@
.?AVlogic_error@std@@
.?AVlength_error@std@@
.?AVbad_exception@std@@
.?AVtype_info@@
<3<L<_<
<$<,<6<@<L=Q=]=i=t=
?%?1?=?
2!212A2Q2a2q2
4&404H5h5R8_8
=Z?_?k?x?
1'131?1Z2
3'33494E4P4\4i4u4
9"9+959B:b:
<#<,<8=X=
7%717=7I7V7b7m7y7
;#;/;;;G;T;`;k;
>'>3>?>K>X>d>l>u>~>
4;5N5n5
;+;;;K;[;k;{;
<+<;<K<[<k<{<
=+=;=K=[=k={=
>+>;>K>[>k>{>
?+?;?K?[?k?{?
0+0;0K0[0k0{0
1+1;1K1[1k1{1
2+2;2K2[2k2{2
3+3;3K3[3k3{3
4+4;4K4[4k4{4
7*7E8J8V8b8n8{8
;D<J<U<a<m<y<
3*363B3N3Y3f3
7k9q9}9
1 1,181E1Q1\1h1t1
162M2h2:3
273S4[4
7V;e;x;
122H2U2
5"5/5S6
4%4F4V5b567I7
:6=E=9>w>J?x?
7Z8O>f>u>6?E?
7-7X7w7
7I8B9a9i9x9
;(;-;:;t;U<r<
=='=/=;=D=I=O=Y=c=s=
=h>q>y>
?'?0?>?G?i?p?
/0U0d0{0
2U2^2r2x2
5.5Y5S:
];a;e;i;m;q;u;y;};
<'<E<S<
>8>?>D>H>L>P>
7'8?8D8
8Q9b9k;
;'</<A<N<p<
?)?Q?e?
:h;p=u=
?&?F?T?[?a?~?
0!0+070S0b0g0l0
1;1E1Q1V1[1|1
1:2A2G2
4'444e4
5P5s5z5
828J8e8p8
9::U:k:
,1E1X1f1r1
1=2L2U2c2
5(525k5r5
6*7E7\7j7}7
88l8y8
;L;R;f;
1<1b1{1
5G6"7)7V7]7|7
8*8Q8f8v8
9/9I9X9y9
:":3:H:x:
:-<5<;<
091?1k1q1|1
3z5`6T7{7
<V<]<d<k<
=,=Q=y=
/0I0[0
1&141J1z1
7K9Q9_9n9
;(;0;Y;`;|;
? ?2?D?V?h?z?
6@6Y6g6s6
7@7X7h7|7
8(888=8B8]8g8w8|8
9,979<9A9b9r9
:*:<:H:
:';_;w;
<!<r<w<|<
/1I1X1f1r1~1
2!2/2:2P2d2z4
7%7L7V7
8!9R9X9
=.>Z>}>
0%1K1r1
=%=.=|=
=@?F?K?R?b?p?
0*1g1q1
192A2I2Q2Y2w2
8;9<:L:]:e:u:
;A;P;\;k;~;
;,<5<><G<r<
F1K1]1{1
3%4Q4t4
6(6E6o6
P1\1h1l1p1t1x1|1
1D9H9L9d9h9l9p9t9x9
1@1D1H1L1P1T1X1\1p1x1
2 2(20282@2H2P2X2`2h2p2x2
3 3(30383@3H3P3X3`3h3p3x3
4 4(40484@4H4P4X4`4h4p4x4
4$;(;,;D<L<T<\<d<l<t<|<
?$?(?,?0?4?8?<?@?D?H?L?P?T?X?\?`?d?h?l?p?t?x?|?
0 0$0(0,0004080<0@0D0H0L0P0T0X0\0`0d0h0l0p0t0x0|0
D1L1T1\1d1l1t1|1
2$2,242<2D2L2T2\2d2l2t2|2
3$3,343<3D3L3T3\3d3l3t3|3
4$4,444<4D4L4T4\4d4l4t4|4
5$5,545<5D5L5T5\5d5l5t5|5
6$6,646<6D6L6T6\6d6l6t6|6
7$7,747<7D7L7T7\7d7l7t7|7
8$8,848<8D8L8T8\8
`2h2p2x2
3 3(30383@3H3P3X3`3h3p3x3
4 4(40484@4H4P4X4`4h4p4x4
5 5(50585@5H5P5X5`5h5p5x5
6 6(60686@6H6P6X6`6h6p6x6
7 7(70787@7H7P7X7`7h7p7x7
8 8(80888@8H8P8X8`8h8p8x8
9 9(90989@9H9P9X9`9h9p9x9
j3n3r3v3
=L=P=`=d=l=
> >0>4>D>H>L>T>l>|>
?(?,?0?8?P?
4$4,444<4D4L4T4\4d4p4x4
505D5X5l5
6$6,646<6D6L6T6\6d6l6t6|6
7$7,747<7D7L7T7\7d7l7t7|7
8$8,848<8D8L8T8\8d8l8t8|8
9$9,949<9D9L9T9\9d9l9t9|9
:$:,:4:<:D:L:T:\:d:l:t:|:
;$;,;4;<;D;L;T;\;d;l;t;|;
<$<,<4<<<D<L<T<\<d<l<t<|<
=(=0=L=T=
? ?4?H?\?p?
0$080L0`0t0
3$383L3`3t3
4(4<4P4d4x4
5,5@5T5h5|5
: :4:H:\:p:
;$;8;L;`;t;
<(<<<P<d<x<
=,=@=T=h=|=
>,>8>@>X>d>
?$?,?4?8?@?T?\?d?l?p?t?|?
080@0D0T0x0
101P1X1`1l1
2$2X2x2
34383X3x3
484X4x4
H4L4P4T4X4\4`4d4h4l4x4|4
Bapi-ms-win-core-fibers-l1-1-1
api-ms-win-core-synch-l1-2-0
kernel32
api-ms-
mscoree.dll
Sunday
Monday
Tuesday
Wednesday
Thursday
Friday
Saturday
January
February
August
September
October
November
December
MM/dd/yy
dddd, MMMM dd, yyyy
HH:mm:ss
Bja-JP
((((( H
Bapi-ms-win-core-datetime-l1-1-1
api-ms-win-core-file-l1-2-2
api-ms-win-core-localization-l1-2-1
api-ms-win-core-localization-obsolete-l1-2-0
api-ms-win-core-processthreads-l1-1-2
api-ms-win-core-string-l1-1-0
api-ms-win-core-sysinfo-l1-2-1
api-ms-win-core-winrt-l1-1-0
api-ms-win-core-xstate-l2-1-0
api-ms-win-rtcore-ntuser-window-l1-1-0
api-ms-win-security-systemfunctions-l1-1-0
ext-ms-win-ntuser-dialogbox-l1-1-0
ext-ms-win-ntuser-windowstation-l1-1-0
advapi32
api-ms-win-appmodel-runtime-l1-1-2
user32
api-ms-win-core-fibers-l1-1-0
ext-ms-
zh-CHS
az-AZ-Latn
uz-UZ-Latn
kok-IN
syr-SY
div-MV
quz-BO
sr-SP-Latn
az-AZ-Cyrl
uz-UZ-Cyrl
quz-EC
sr-SP-Cyrl
quz-PE
smj-NO
bs-BA-Latn
smj-SE
sr-BA-Latn
sma-NO
sr-BA-Cyrl
sma-SE
sms-FI
smn-FI
zh-CHT
az-az-cyrl
az-az-latn
bs-ba-latn
div-mv
kok-in
quz-bo
quz-ec
quz-pe
sma-no
sma-se
smj-no
smj-se
smn-fi
sms-fi
sr-ba-cyrl
sr-ba-latn
sr-sp-cyrl
sr-sp-latn
syr-sy
uz-uz-cyrl
uz-uz-latn
zh-chs
zh-cht
CONOUT$
Antivirus Signature
Bkav W32.AIDetectMalware
Lionic Trojan.Win32.Stealerc.i!c
Elastic malicious (high confidence)
MicroWorld-eScan Clean
ClamAV Clean
FireEye Generic.mg.3f6d2aa85fcd8e38
CAT-QuickHeal Clean
Skyhigh BehavesLike.Win32.Generic.jc
ALYac Clean
Malwarebytes Clean
Zillya Clean
Sangfor Trojan.Win32.Save.a
K7AntiVirus Clean
BitDefender Clean
K7GW Clean
CrowdStrike win/malicious_confidence_90% (W)
Arcabit Clean
Baidu Clean
VirIT Clean
Symantec ML.Attribute.HighConfidence
tehtris Clean
ESET-NOD32 Clean
APEX Malicious
Paloalto Clean
Cynet Malicious (score: 100)
Kaspersky HEUR:Trojan-PSW.Win32.Stealerc.gen
Alibaba Clean
NANO-Antivirus Clean
ViRobot Clean
Rising Trojan.Generic@AI.100 (RDML:MifeMdidFMWS9qAo3Wk8iw)
TACHYON Clean
Sophos Mal/Generic-S
F-Secure Clean
DrWeb Clean
VIPRE Clean
TrendMicro TrojanSpy.Win32.LUMMASTEALER.YXDKTZ
Trapmine malicious.high.ml.score
CMC Clean
Emsisoft Clean
Ikarus Clean
Jiangmin Clean
Webroot W32.Malware.Gen
Google Detected
Avira Clean
Antiy-AVL Clean
Kingsoft Win32.Troj.Unknown.a
Gridinsoft Trojan.Win32.Gen.sa
Xcitium Clean
Microsoft Trojan:Win32/Leonem
SUPERAntiSpyware Clean
ZoneAlarm HEUR:Trojan-PSW.Win32.Stealerc.gen
GData Clean
Varist W32/ABRisk.LIET-6521
AhnLab-V3 Clean
Acronis Clean
McAfee Artemis!3F6D2AA85FCD
MAX Clean
DeepInstinct MALICIOUS
VBA32 BScope.Backdoor.Wirenet
Cylance unsafe
Panda Trj/Chgt.AD
Zoner Clean
TrendMicro-HouseCall TrojanSpy.Win32.LUMMASTEALER.YXDKTZ
Tencent Clean
Yandex Clean
SentinelOne Static AI - Malicious PE
MaxSecure Trojan.Malware.300983.susgen
Fortinet W32/PossibleThreat
BitDefenderTheta Gen:NN.ZexaF.36792.RqW@auLEUL
AVG Clean
Cybereason malicious.f96927
Avast Clean
No IRMA results available.