Static | ZeroBOX

PE Compile Time

2023-08-31 16:02:15

PE Imphash

d7c654835f684e95ab7aff8d635cade8

PEiD Signatures

Armadillo v1.71

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x00005de2 0x00006000 6.08198428661
.rdata 0x00007000 0x00002dc0 0x00003000 4.21437296955
.data 0x0000a000 0x0000d578 0x0000e000 6.42337552017
.rsrc 0x00018000 0x0009adc0 0x0009b000 5.15880512961

Resources

Name Offset Size Language Sub-language File type
RT_BITMAP 0x000ad880 0x00004fd8 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_BITMAP 0x000ad880 0x00004fd8 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_BITMAP 0x000ad880 0x00004fd8 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_BITMAP 0x000ad880 0x00004fd8 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_BITMAP 0x000ad880 0x00004fd8 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_BITMAP 0x000ad880 0x00004fd8 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_BITMAP 0x000ad880 0x00004fd8 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_BITMAP 0x000ad880 0x00004fd8 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_BITMAP 0x000ad880 0x00004fd8 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_BITMAP 0x000ad880 0x00004fd8 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_BITMAP 0x000ad880 0x00004fd8 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_BITMAP 0x000ad880 0x00004fd8 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_ICON 0x00064498 0x00000468 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED GLS_BINARY_LSB_FIRST
RT_ICON 0x00064498 0x00000468 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED GLS_BINARY_LSB_FIRST
RT_ICON 0x00064498 0x00000468 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED GLS_BINARY_LSB_FIRST
RT_ICON 0x00064498 0x00000468 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED GLS_BINARY_LSB_FIRST
RT_ICON 0x00064498 0x00000468 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED GLS_BINARY_LSB_FIRST
RT_ICON 0x00064498 0x00000468 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED GLS_BINARY_LSB_FIRST
RT_ICON 0x00064498 0x00000468 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED GLS_BINARY_LSB_FIRST
RT_ICON 0x00064498 0x00000468 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED GLS_BINARY_LSB_FIRST
RT_DIALOG 0x000b2940 0x000000da LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_ACCELERATOR 0x000b28c8 0x00000078 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_ACCELERATOR 0x000b28c8 0x00000078 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_GROUP_ICON 0x00064900 0x00000076 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_VERSION 0x000b2a20 0x000003a0 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data

Imports

Library MFC42.DLL:
0x407060 None
0x407064 None
0x407068 None
0x40706c None
0x407070 None
0x407074 None
0x407078 None
0x40707c None
0x407080 None
0x407084 None
0x407088 None
0x40708c None
0x407090 None
0x407094 None
0x407098 None
0x40709c None
0x4070a0 None
0x4070a4 None
0x4070a8 None
0x4070ac None
0x4070b0 None
0x4070b4 None
0x4070b8 None
0x4070bc None
0x4070c0 None
0x4070c4 None
0x4070c8 None
0x4070cc None
0x4070d0 None
0x4070d4 None
0x4070d8 None
0x4070dc None
0x4070e0 None
0x4070e4 None
0x4070e8 None
0x4070ec None
0x4070f0 None
0x4070f4 None
0x4070f8 None
0x4070fc None
0x407100 None
0x407104 None
0x407108 None
0x40710c None
0x407110 None
0x407114 None
0x407118 None
0x40711c None
0x407120 None
0x407124 None
0x407128 None
0x40712c None
0x407130 None
0x407134 None
0x407138 None
0x40713c None
0x407140 None
0x407144 None
0x407148 None
0x40714c None
0x407150 None
0x407154 None
0x407158 None
0x40715c None
0x407160 None
0x407164 None
0x407168 None
0x40716c None
0x407170 None
0x407174 None
0x407178 None
0x40717c None
0x407180 None
0x407184 None
0x407188 None
0x40718c None
0x407190 None
0x407194 None
0x407198 None
0x40719c None
0x4071a0 None
0x4071a4 None
0x4071a8 None
0x4071ac None
0x4071b0 None
0x4071b4 None
0x4071b8 None
0x4071bc None
0x4071c0 None
0x4071c4 None
0x4071c8 None
0x4071cc None
0x4071d0 None
0x4071d4 None
0x4071d8 None
0x4071dc None
0x4071e0 None
0x4071e4 None
0x4071e8 None
0x4071ec None
0x4071f0 None
0x4071f4 None
0x4071f8 None
0x4071fc None
0x407200 None
0x407204 None
0x407208 None
0x40720c None
0x407210 None
0x407214 None
0x407218 None
0x40721c None
0x407220 None
0x407224 None
0x407228 None
0x40722c None
0x407230 None
0x407234 None
0x407238 None
0x40723c None
0x407240 None
0x407244 None
0x407248 None
0x40724c None
0x407250 None
0x407254 None
0x407258 None
0x40725c None
0x407260 None
0x407264 None
0x407268 None
0x40726c None
0x407270 None
0x407274 None
0x407278 None
0x40727c None
0x407280 None
0x407284 None
0x407288 None
0x40728c None
0x407290 None
0x407294 None
0x407298 None
0x40729c None
0x4072a0 None
0x4072a4 None
0x4072a8 None
0x4072ac None
0x4072b0 None
0x4072b4 None
0x4072b8 None
0x4072bc None
0x4072c0 None
0x4072c4 None
0x4072c8 None
0x4072cc None
0x4072d0 None
0x4072d4 None
0x4072d8 None
0x4072dc None
0x4072e0 None
0x4072e4 None
0x4072e8 None
0x4072ec None
0x4072f0 None
0x4072f4 None
0x4072f8 None
0x4072fc None
0x407300 None
0x407304 None
0x407308 None
0x40730c None
0x407310 None
0x407314 None
0x407318 None
0x40731c None
0x407320 None
0x407324 None
0x407328 None
0x40732c None
0x407330 None
0x407334 None
0x407338 None
0x40733c None
0x407340 None
0x407344 None
0x407348 None
0x40734c None
0x407350 None
0x407354 None
0x407358 None
0x40735c None
0x407360 None
0x407364 None
0x407368 None
0x40736c None
0x407370 None
0x407374 None
0x407378 None
0x40737c None
0x407380 None
0x407384 None
0x407388 None
0x40738c None
0x407390 None
0x407394 None
0x407398 None
0x40739c None
0x4073a0 None
0x4073a4 None
0x4073a8 None
0x4073ac None
0x4073b0 None
0x4073b4 None
0x4073b8 None
0x4073bc None
0x4073c0 None
0x4073c4 None
0x4073c8 None
0x4073cc None
0x4073d0 None
0x4073d4 None
0x4073d8 None
0x4073dc None
0x4073e0 None
0x4073e4 None
0x4073e8 None
0x4073ec None
0x4073f0 None
0x4073f4 None
0x4073f8 None
0x4073fc None
0x407400 None
0x407404 None
0x407408 None
0x40740c None
0x407410 None
0x407414 None
0x407418 None
0x40741c None
0x407420 None
0x407424 None
0x407428 None
0x40742c None
0x407430 None
0x407434 None
0x407438 None
0x40743c None
0x407440 None
0x407444 None
0x407448 None
0x40744c None
0x407450 None
0x407454 None
0x407458 None
0x40745c None
0x407460 None
0x407464 None
0x407468 None
0x40746c None
0x407470 None
0x407474 None
0x407478 None
0x40747c None
Library MSVCRT.dll:
0x407484 _except_handler3
0x407488 __set_app_type
0x40748c __p__fmode
0x407490 __p__commode
0x407494 _adjust_fdiv
0x407498 __setusermatherr
0x40749c _initterm
0x4074a0 __getmainargs
0x4074a4 _acmdln
0x4074a8 exit
0x4074ac _XcptFilter
0x4074b0 __CxxFrameHandler
0x4074b4 _setmbcp
0x4074b8 _CxxThrowException
0x4074bc memmove
0x4074c0 _mbscmp
0x4074c8 __dllonexit
0x4074cc _onexit
0x4074d0 _exit
0x4074d4 _controlfp
Library KERNEL32.dll:
0x40701c VirtualFree
0x407020 FreeLibrary
0x407024 VirtualAlloc
0x407028 IsBadReadPtr
0x40702c HeapReAlloc
0x407030 ExitProcess
0x407034 GetModuleHandleA
0x407038 GetStartupInfoA
0x40703c HeapAlloc
0x407040 GetProcAddress
0x407044 LoadLibraryA
0x407048 CloseHandle
0x40704c WriteFile
0x407050 Sleep
0x407054 GetProcessHeap
0x407058 CreateFileA
Library USER32.dll:
0x4074dc LoadMenuA
0x4074e0 GetMenuStringA
0x4074e4 GetMenuState
0x4074e8 GetMenuItemID
0x4074ec GetMenuItemCount
0x4074f0 ReleaseDC
0x4074f4 ModifyMenuA
0x4074f8 InsertMenuA
0x4074fc GetDC
0x407500 RemoveMenu
0x407504 CopyRect
0x407508 FillRect
0x40750c DrawStateA
0x407510 CreatePopupMenu
0x407514 CreateMenu
0x407518 GetSysColor
0x40751c LoadBitmapA
0x407520 SendMessageA
0x407524 GetWindowRect
0x407528 OffsetRect
0x40752c EnableWindow
0x407530 UpdateWindow
0x407534 GetSubMenu
Library GDI32.dll:
0x407014 Rectangle
Library COMCTL32.dll:
0x407000 ImageList_Draw
0x407004 ImageList_Add

!This program cannot be run in DOS mode.
`.rdata
@.data
t$@th
L$8_^]
L$(_^][d
tHh4uA
L$(_^d
D$DQRWj
L$(_^][d
L$4_]d
MFC42.DLL
__CxxFrameHandler
_CxxThrowException
memmove
_mbscmp
MSVCRT.dll
??1type_info@@UAE@XZ
__dllonexit
_onexit
_XcptFilter
_acmdln
__getmainargs
_initterm
__setusermatherr
_adjust_fdiv
__p__commode
__p__fmode
__set_app_type
_except_handler3
_controlfp
CloseHandle
WriteFile
CreateFileA
GetProcessHeap
GetProcAddress
LoadLibraryA
HeapAlloc
HeapReAlloc
VirtualFree
FreeLibrary
VirtualAlloc
IsBadReadPtr
ExitProcess
GetModuleHandleA
GetStartupInfoA
KERNEL32.dll
UpdateWindow
EnableWindow
OffsetRect
GetWindowRect
SendMessageA
LoadBitmapA
GetSysColor
CreateMenu
CreatePopupMenu
LoadMenuA
GetSubMenu
GetMenuStringA
GetMenuState
GetMenuItemID
GetMenuItemCount
ReleaseDC
ModifyMenuA
InsertMenuA
RemoveMenu
CopyRect
FillRect
DrawStateA
USER32.dll
GetTextExtentPoint32A
Rectangle
GDI32.dll
ImageList_Add
ImageList_Draw
ImageList_GetImageInfo
COMCTL32.dll
_setmbcp
CChildFrame
CImageDoc
gd,i@f@6oT4Q) P'^*oGfR! A3^di]ft
K=N$3F0D
n@RZ%X[
3F0Q|3F0T
3hD!xGF0D
ShB aG'0Df F0D
shT%tRF0D
hB!l\%0D
M!0DQe
$;GDCV
h3D0DPd
u$0DYj
3F0D^h
\3Fi}}
#oEL9FNC
wb8Et4
vJZ@h3v0D3
vJZ@H[F
F $!3V
F g"3V
0DSYFf
Q3FZ'Sd
DYHGKx1T
3FZFj3,0
2F0Dj3
ELW[61D
jZEXl
kG0DVd
H3FZkS
3VZE^l
$;GDCV
3FZGSYGXD
ZE[Ggc
X(73V`
DhHGIx1[
0TVe,1
PYGZEV[F0D
XD0DS`
gE0DSe
p73FZkS
GMXa;3V
ETh1F0
f1FZE^d
hSD0DP
$;GDCV
DIj3,1
3F0Ft .0
nT9mNDoW
ZFS`.0D
F ,^HF
3F0DPW
3F0D_m
F ,^HF
3F0DPW
D3HGvxK
`,3D0
h,F2DS
3F0D_m
3V0D-3V0D
Ob8Eu
0TTVF
3F0f}3V2D
3F0DONF E
3F0D|.F d
3F0D4CF
iA2E%lu4U!
Ef-rG3Q(A_*_'
l\$Q(U]*_'k3F3FG_)R%l
i]"~!xG
qGw!tp3B6e]2`6oP#C7
Gw!te#B7i\(0DV0
DC_)C!HR(T(e3
w#F-cV
o]2B+l3
rV'D!FZ*U
'C0EA4_6
a@2u6r\40D
\+bR*q(l\%0m
z(D!r_)S/eW
H'hR(W!
E\7tA%@=A3F
EGV2`6oP
T rV5CD
LGw!t~)T1lV
Q*d_#qD
Gw!te#B7i\(u<A3C2
l\$Q(MV+_6y`2Q0u@
D`6oP#C73
r\%U7s
tv-r@20D
U%pu4U!
eR6q(l\%0
r\%U7s{#Q4
3(sG4S%trF09
oW3\!FZ*U
Gw!tg/S/C\3^0
3(sG4\!nrF0_
i_#`+i]2U6
Y(e`/J!
Gw!t`?C0e^
Y6eP2_6yrFCEGV2|+cR*d-mVF0%
)S%l`/J!
kD|+cR*q(l\%0DR1
/R6aA?qD
*Ec!tu/\!AG2B-bF2U7A3F{DCA#Q0ew/B!cG)B=A3F_FM\0U
i_#u<A3
oC?v-lV
i_#q0tA/R1tV5qD
DDV*U0eu/\!A3
aZ2v+r`/^#lV
R.eP20
u4U!LZ$B%rJFVDCA#Q0ec4_'e@5qD
Gw!td/^ oD5t-rV%D+rJ
U0C\+]%nW
Y*erFzGSV2e*hR(T(eW
H'eC2Y+nu/\0eAF
FOF2@1tw#R1g`2B-nT
U0EE#^0
iA2E%lc4_0eP20D
0*C0rP+@-A3
rV'D!EE#^0A3F{
lZ6R+aA"0D
U0C_/@&oR4T
@!np*Y4b\'B
Y*d\1C
\-pQ)Q6dw'D%
lZ6R+aA"0D
11C4rZ(D"A3
I7tV+}!tA/S7
Y*d\1d!xG
U0F\4U#r\3^ WZ(T+w3
U=SG'D!
U=SG'D!
Fs,a]!U
i@6\%y`#D0i]!C
Q7tz(@1tz(V+
l_F0X
r"Z1sG
B-vZ*U#e@F
EL\)[1pc4Y2i_#W!VR*E!A3
pV(`6oP#C7T\-U*
DC_#Q6EE#^0L\!qD
e_#D!SV4F-cVF
eA0Y'erF0
|6U*Sp
Q*aT#B
U6vZ%U
rV'D!PA)S!s@
uDc!tg)[!nz(V+r^'D-o]F
DDF6\-cR2U
x3F<FRV!Y7tV4c!rE/S!CG4\
a]"\!rrF
DC_)C!SV4F-cV
Q*d_#0DI1
U6vZ%U
Fs,a]!U
eA0Y'ep)^"iTtqDd3
B!aG#c!rE/S!A3F
ERV!s(o@#{!y3
U#OC#^
yDc0aA2c!rE/S!CG4\
i@6Q0c[#B
jd_*0D
@!cZ'\
o_"U6PR2X
l_F DC\
B!aG#y*sG'^'e3F
^-tZ'\-zVF0+lVu
hT(l3F D?
^#]'pJF0
fG)\DI3
Q*d_#BD
15D6lV(0D
15D6cR20D
15D6cC?0DI1#H-t3F
FmV+C!t3F?D?
^#]'mCF0
H<T[4_3EK%U4tZ)^D
Go7tA3@6
DC0r@2BD
DC0r]%@=
DC0rA%X6
DB%nWF0y
27tA%C4n3
eK%U4tl.Q*d_#Bw
l\%Q(_F(G-nWt0D
1+Q(l\%0D
15D6nP+@D
14U%l_)SD^1 B!e3F
D_Q#W-nG.B!aW#HD
DC0rP.BD
RghT(l3F>D?
_W*\+nV>Y0
Go+nV>Y0
<Go-nZ2D!r^F
D_R"Z1sG
V iEF0Y
`#D1pw/t!sG4_=DV0Y'ez(V+LZ5DD
1Gc!tF6t-CR*\
n@2Q(lV402
`#D1pw/c!tp*Q7sz(C0a_*`%rR+C
zGc!tF6t-GV2t!vZ%U
eT/C0rJ
B+pV4D=A3f1
iv(E)DV0Y'ez(V+
Gc!tF6t-GV2s(a@5t!v@
oD(\+aW
F4\)o]hT(l3F
DDZ5Q&lV
X6eR"|-bA'B=CR*\7
Go7tA%]4i3F
E_@2B-c^60D
`.U(lV>0D
d!nP#^0\f5U6sol
hF2T+w]
B-vZ*U#e3=
3F0jPr
3F0D.c
\(oP'D!
3F0&aWfR1fU#BD
CF0Dq3F06
FF0Dv3F03
IF0D{3F0
F0D43F0q
F0D93F0t
:F0DQ3F0
gF0DY3F0
wF0DF3F0
xF0DL3F0
kF0DC3F0
"F0D[3F0d
F0D-3F0`
F0D"3F0a
XF0D`3F0%
WF0De3F0"
ZF0Dn3F0j
cF0DP3F0
3F0d 3Fe*T[4U%t3F0DU]
!xVF0D
U'uA/D=.V>UDAWkG%tP.
3aG%XjeK#0D
U"e]"U6
E5C!rEhU<e3F
3F0DrV+E4d
3F0DrG0C'a]hU<e3
3FQ7hw/C4.V>UD
3FQ2cV(D!r
fjeK#0
3-^7dG4Q=.V>UD
V!E-.V>UD
~%C,iV*TjeK#0D
3F0DaE6
!xVFviSV%E6e3F0Df
5U'uA#
!xVF0D
wDaE!G sE%
!xVF0D
AT#^0.R?UD
vPhU<e3F0
uG6_7t3'S7.V>UDDahg
Iw#BjeK#0DC\+_ o
3%V4.V>UD
SvF]7sV%U7s
3F0DRR0}+nwhU<e3
3F0DKE
_*XchU<e3
3F0&aZ"E
aU#d6aJhU<e3F0
q'Y u`"
TchU<e3
aU#d6aJhU<e3F0
X>U0rR?
vD6aJhU<e3
e4]3F0D
~F0DN3F0
kF0DZ3F0f
xF0DJ3F0
wF0DS3F0
cF0DO3F0
gF0DR3F0
lF0D)3F0l
F0D$3F0g
MF0D[c'E7e
0A_2mD
3F0I}
F0D*3F0NF+
_3nnF0RZ!X0]3
]3F0D[
#V0]3Fk
aT#t+w]
0D[v(T
e_#D!]3F0D[c'W!UC
0D[z(C!rG
c'r\*\dL\%[
rZ(DdSP4U!nnF0
NnF0D[p
F0D,3F0)
EF0Dc3F0<
F0Dl3F0/
TF0Df3F0
nF0D[3F04
FF0Dy3F00
DF0Dq3F0Tr
F0D03F0}
F0D53F0p
F0D`3F0F
vu1nF0D[uw
vr]3F0D[usmD
vu]3F0D[v
F0DkV4^!l
l_F0D
cTi%Wf
cT~%WK:D
9F0D<q'S/SC'S!>3
|mDP_3W-n~#0D
@!nc4_<y3F0
`?C0e^F0
eP3B-tJF0D
r6@(iP'D-o]Fw6oF60D
a#]%rXF0
\p3B6e]2s+nG4_(SV2l
eA0Y'e@
%WhR%k3F0
U"aF*DD%
7\@.U(lo)@!no%_)mR(TD
3cCd%@F0DAC6\-cR2Y+n@
Y!xC*_6e
#H!\@.U(lo)@!no%_)mR(TD
3F0asocCD
3cCjeK#0Dj[,W#lW%S
3F0Db"F0D
3F0D"3F0D
as3F0DI]5D%l_
x#B*e_u
jd_*0D
GV2q'tZ0U
o]5_(e`#C7i\(y
rV'D!E]0Y6o]+U*tq*_'k3FE7eA#^2.W*\D%@fg-n
Ft!sP4Y4tZ)^Dc
3Fw!tu/\!AG2B-bF2U7A3F}+vV
Y(ev>qDGV2}+dF*U
i_#~%mV
0D%PcSac
'%PhU<e3F0DWZ(
3FvDr3/0!
]FTDl3?0
RF]De3F0D
rV#c0rZ(WD
v.W*\D
3Fs+CA#Q0ez(C0a]%UD
3Fs+U]/^-tZ'\-zVF0
oz(Y0iR*Y>e3F0DO_#
v.W*\D
3cTn%@
SJ5D!mo
U*tA'\
r\%U7s\4lt
z3F0DEA4_6
3Fy7W\1
pPA)S!s@F0
U6sZ)^
u^$U6s3F^0d_*
l_F0D
}'F!r3F0
3Fc1nQ#\0
uDAF2X!nG/E)
B'aE/BD
fV#0DDAhg
B3Fq2a@20D
r0Y6a3F0
u/^ t
edGA'@,iP5
!rA)BDSj
E6rV(D
o]2B+l`#D
C\(D6o_
s(a@5l?4wu
rZ0U6DV5SD
F0D 3F0
3Fy7BR"b!aW
3F03i]/^!t
p4U%tV
B+cV5C
sf5U6A3F0DSV2d+kV(y*f\4]%tZ)^DDF6\-cR2U
x3F0DOC#^
r\%U7sg)[!n3F0DDV*U0e`#B2iP#0D
p.Q*gV
U6vZ%U
o] Y#2rF0DCA#Q0e`#B2iP#qD
p)^0r\*c!rE/S!
U6vZ%U
U6vZ%U
U6vZ%U
U6vZ%U
MR(Q#eA
0DRV!Y7tV4c!rE/S!CG4\
a]"\!rrFc!t`#B2iP#c0aG3CD
3F0#eG._7t]']!
T#D7oP-^%mVFC!lV%DD
3FC!t@)S/oC20Dc_)C!s\%[!t34U'v3F0DsV(TD
3FS+n]#S0
[2_*s3F0#eG._7tQ?^%mVF0Ds\%[!t3Fg
Ap*U%nF60DW`
c0aA2E4
l_F07tA5D6
3+U)sV20DmV+S4y3FC0r_#^D
@2B'mCF0
v(E)WZ(T+w@Fc!nW
U7sR!U
sd/^ oD
Y7iQ*UDMV5C%gV
H-td/^ oD5u<
3FG7pA/^0frF0DU@#Bw2
U0CF4B!nG
B+cV5CD
_2eu/\!A3F0
I7tV+t-rV%D+rJ
I7tV+y*f\F0DEK6Q*dv(F-r\(]!nG
D6i]!C
3Fw!tv>Y0C\"U
r\%U7s3Fw!te#B7i\(u<A3F0
eA+Y*aG#d,rV'TDSV2u2e]20D
Q*cV*y+
p4U%tV
Q-tu)B
i]!\!OQ,U't3
U0TZ%[
3F\7tA%Q0A3F0DS_#U4
3Fs(o@#x%nW*UDGV2|%sG
B6oAF0D
a#\!a@#}1tV>0D
B!aG#}1tV>qD
3Fs6eR2U
r\%U7srF0
rV'D!T\)\,e_6
vS]'@7h\20D
U0CF4B!nG
X6eR"y
U7kG)@D
3Fc!tg.B!aW
U7kG)@D
3Fw!tf5U6OQ,U'tz(V+r^'D-o]
hA#Q DV5[0oCF0D
hT(l3F
U7kG)@
nG#B*eG
Q*d_#0
nG#B*eG
U%du/\!
nG#B*eG
@!nf4\
z(D!r]#D
_+kF6`6iE/\!gV
r"Z1sG
B-vZ*U#e@F0DPA)S!s@u
c4_'e@5
vFZ4C0
|X3F0D%WF0
nF+{!yv>qD
U#E]3]
3Fb!g|6U*KV?u<A3F0
U(eG#f%lF#qDRV!t!lV2U
U#CA#Q0ex#I
{Ae2I4el/^"os
F68p"r0
^7xqmst
?3f0D`2F0E0 v)t!
~3{umw
H4.rupS
o5fslq
O<"z/x%
{<ezWx
':A|J~
='x-z-
19txvS
D3&uqwH
4~rTp|
x5ys[q
5?pprE
j7|qLs
q8j~A|z
=)xuzM
w?kyP{
F44r/p.
v5tsEq{
<izWxt
q>vxeze
1mw\uw
4Ur]pu
H6"pUrk
a8z~M|
:a|h~~
(2CtDvx
4?s(q4
5Ws\qx
L1?w u
1{w|uP
1owPud
(1CwDux
H2#t$v
2StTvh
42GtHv|
T3'u(w
3cudwX
$3WuXwl
03KuLw
@6;p<r
6wpxrL
6kplr`
,6_p@rt
Shellex
123.249.25.73
Nopqrs
Nopqrs Uvwxyabc Efghijkl Nopq
Nopqrstu Wxyabcdef Hijklmn Pqrstuvw Yab
kernel32.dll
HeapFree
KERNEL32.dll
VirtualProtect
Local AppWizard-Generated Applications
CImageView
CMainFrame
CMenuEx
.?AVtype_info@@
jpqhnohnohnohnohnohnohnohnohnohnohnohnohnohnohnorxy
prr]bcy
rvvcghekk
dijciiciiciiciiciiciiciiciiciicii
lrshnohnohnohnohnohnohnohnolrs
9hzIeoZgklrs|
PBqliu|}
{}}UXXbde
jkkORR_ef{
qwxkqrjpqpwx{
9i|HeoXeikqr|
QTTW\]u|}
{{mbc`fg
8h{Wgk
xxxwww
]XYjpq
u|}tz{rxypwxnuvrxy
qwxlrsnuvpwxrxytz{u|}w~
wddagh
SSS~~~xxydjk
vccjpq
OpEqwx
Eb9lrs
HWGiop
Cq-NdHZiY[tTO
<u$JfAVhUYqVO~=E
nuvmtusyz
t{|mtumstrxy
glmIKKGHHSSSGGH+++678CEERVWlrs
d,c]Plrs
syzflmhnohnohnohnoiopjpqkqrkqrkqrkqrjpqrxy
rxynuvnuvnuvnuvnuvnuvnuvnuvnuvnuvv}~
Nvsktz{
CXg^cd
~~{TkxD[nW\^
IJJjjj
"##=>?SXY~
BYlY^_
@^tSXZ
nstWWW
-..LPP|
rvvjnnnst|
?[oV[\
<_zOVY|
#$$OST
RWXaghntx%*-$*,?CDW\\}
`:.fA7kF:kF:kF:jE9jD:d]W
?]rV[[
LRVv}~
'((]bc
sxyxyy
&''HLMw~
S|\/ovw
?\qV[\
023v}~
?]sjpq
z{|mjkeefhnn{
eikjpq
sqriefcdeiop
%%%"""
uscSSZ^^
tkk}cb
lk`QQ^bc
---***'''"""
HHH'''###
x][TWX
555222///***%%%!!!
SSS333///(((!!!
z\\]bc
===:::666222---((($$$
^^^>>>;;;444,,,"""BFG
EEEBBB>>>:::555000,,,''' 455
iiiJJJGGG@@@888+,,qwy
yparfSrfSqdRqdRqdRqdRtgT
MMMIIIFFFBBB===888444///###PRR
uuuWWWSSSMMM@@@JKK
UUUQQQMMMIIIDDD???;;;666***vyy
ccc```VVVIII
]]]YYYUUUQQQLLLHHHCCC:::EEE
oooeeeccc
-//EDDRRR
bR;dij|
dddaaa]]]YYYTTTOOOKKK<<<
~zyNMLcccvvv
kkkiiieeeaaa\\\WWWIIIkkk
tttqqqmmmiiidddVVVnnn
{{{xxxssslllddd
xxxvvvxxx
jpqhnohnohnohnohnohnohnohnohnohnohnohnohnohnohnorxy
dijciiciiciiciiciiciiciiciiciicii
lrshnohnohnohnohnohnohnohnolrs
OSTIMMZ_`kqs
{~~_ef{
[`aEIJ9<<3662558;<CGGV[\z
:G%26477EIJW\^jpq
tttwwwuuu
fklu|}
kkN==),,LPQ
;H#05366DHHV[\syz
www{{{yyy
{{7--255kqs
J`"39V[\
www{{{yyy
u|}tz{rxypwxnuvrxy
qwxlrsnuvpwxrxytz{u|}w~
cJJ*,-kqs
www{{{yyy
bHH255
www{{{yyy
@45LPQ
vvvzzzxxx
I9:\ab
nrsiop
ciiMQREIJ'L0
uj_SKqbY
xYMFRGAeXPyi_
zoLB<81,6/+6/+6/+6/+6/+6/+6/+6/+6/+6/+6/+6/+6/+6/+6/+A83vf]
]\[1-*I?9`TMQNLA>=4.*SHB
UJC2+'1+'1+'1+'1+'1+'1+'1+'1+'1+'1+'UJC
^QJ:2.6/+6/+6/+6/+6/+6/+6/+6/+:2.fYQ
8D)/0:2.MC=cUNwh^
M?bYVE<6
ssr:87POO
^]]-+*-'$KA;wh^
zj`m^Vk]U
}rfYQMC=@7291-81,?72KA;aTM
9D'-/91-LB<aTM
xxx543'"E<6wh^
jjP<:.($UJC
I^&13aTM
xxxwww
QPP[SN
{{9+)81,yi_
SRQpe_
|pZNGMC=KA;I?9G=8E<6C:5A83?72=50A83fYQ
}lbvf]
qbYue\
k]U@72:2.=50?72A83C:5E<6G=8I?9KA;SHB
eII/)%yi_
SSS~~~uuu5/,
oaXKA;J@:KA;
cGF81,
B32UJC
K86hZR
:2.j\S
vl\aB9
70+`SL
ynbhF<
xoaXVKDMC=,I)
qg^QJH>9=50<4/B94RGAqbY
v[v>!ZNG
|kbXLED;6<4/;3.A83RGAqbY
~rdWNn`W
tieXPdWNeXP
xm^VdWNdWN}lb
vleXPdWNeXP
ynPE?J@:yi_
}rSHBI?9n`W
sh<74/..;;;NNNBBB###&&&('&%" :2.i[S
:2.j\S
oeB944-)6/+6/+6/+6/+70+81,91-91-91-91-81,A83ue\
j\SA83=50=50=50=50=50=50=50=50=50=50F=7yi_
K9(C:5sd[
{pnkDez';L,&#hZR
~qnjLcq-EY&! [OH
ULG877jjj
/)%^QJ
*CW("aTM
FA>UUU
t[OFB81:0+=4/MC=ue\
,&#\PIvf]vf]vf]vf]vf]
.Ro!""LB<
PJFggg
_TN9:;Y^_jqt
,%zj`
)$!ue\
/Yx #F=7
+%"}lb
JEBvvv
"(-G=8
,Kc81,
).1n`W
)&#G=8[MGO@;E429-*70*KA;ue\
LKL81,ZNGWICI:6A1.6+(70+QF@
%%%"""
yvv^ED
ljM65*$!SHB
aSRpON
a_E/-,%"^QJ
---***'''"""
UH>prs
HHH'''###
S2dMBZNG
`^*!VKD
555222///***%%%!!!
SSS333///(((!!!
xVU*%!
qOM+%"~md
===:::666222---((($$$
^^^>>>;;;444,,,"""&'(wh^
C/.VKD
F10UJC
EEEBBB>>>:::555000,,,''' '''SHB
iiiJJJGGG@@@888+,,TTS
gCS:!N5
zZWA83
{ZXA83
MMMIIIFFFBBB===888444///###??>m^V
uuuWWWSSSMMM@@@GGGulf
UUUQQQMMMIIIDDD???;;;666***^\[
ccc```VVVIII
]]]YYYUUUQQQLLLHHHCCC:::DDDngb
oooeeeccc
-//EDDRRR
2+'MC=ZNGXLEjH
dddaaa]]]YYYTTTOOOKKK<<<rqq
~zyNMLcccvvv
kkkiiieeeaaa\\\WWWIIIggg
tttqqqmmmiiidddVVVlll
jnK:_K?
{{{xxxssslllddd
xxxvvvxxx
nuvmtusyz
t{|mtumstrxy
ccclmnrttmqrlrs
w{|lrs
syzflmhnohnohnohnoiopjpqkqrkqrkqrkqrjpqrxy
rxynuvnuvnuvnuvnuvnuvnuvnuvnuvnuvv}~
222YZZnopchi~
|||zzz~~~~~~uuurrr}}}
'''bccfjj|
}}}uuu
UVVeij
ddd\]]nqqfkk}
_bbdghillillillhkkfiiqvw
nrrv}~
;;;444***
QRR]bc
XYYeijw~
JJJEEE===444'''
023v}~
FGG^cc
zzzwww
WWWRRRLLLEEE;;;///
ooo999222
}}}xxx
aaa]]]XXXQQQJJJAAA777***
{{{OOOJJJ???---
kkkgggccc]]]WWWOOOIII???4449;;|
ccc^^^TTTIII999DGG
tttpppmmmgggaaa[[[UUULLLEEEEFFv}~
wxxpqq
rrrmmmddd[[[PPPOQR
|~~qrr
|||yyyuuupppkkkddd___XXXQQQLMMx
}}}zzzsssiii]]]uww
}}}yyytttnnniiicccZZZkll
wwwiii
|||wwwsssmmm^^^
~~~zzzuuuggg
GGGmmm
svvdij|
tuukkk
jpqhnohnohnohnohnohnohnohnohnohnohnohnohnohnohnorxy
prr]bcy
rvvcghekk
dijciiciiciiciiciiciiciiciiciicii
lrshnohnohnohnohnohnohnohnolrs
nuvmtusyz
t{|mtumstrxy
9hzIeoZgklrs|
PBqliu|}
{}}UXXbde
jkkORR_ef{
qwxkqrjpqpwx{
glmIKKGHHSSSGGH+++678CEERVWlrs
d,c]Plrs
syzflmhnohnohnohnoiopjpqkqrkqrkqrkqrjpqrxy
rxynuvnuvnuvnuvnuvnuvnuvnuvnuvnuvv}~
Nvsktz{
CXg^cd
~~{TkxD[nW\^
9i|HeoXeikqr|
QTTW\]u|}
{{mbc`fg
IJJjjj
"##=>?SXY~
BYlY^_
@^tSXZ
8h{Wgk
xxxwww
]XYjpq
nstWWW
-..LPP|
rvvjnnnst|
?[oV[\
<_zOVY|
u|}tz{rxypwxnuvrxy
qwxlrsnuvpwxrxytz{u|}w~
wddagh
#$$OST
RWXaghntx%*-$*,?CDW\\}
`:.fA7kF:kF:kF:jE9jD:d]W
?]rV[[
LRVv}~
SSS~~~xxydjk
vccjpq
'((]bc
sxyxyy
&''HLMw~
S|\/ovw
?\qV[\
OpEqwx
023v}~
?]sjpq
z{|mjkeefhnn{
eikjpq
sqriefcdeiop
%%%"""
uscSSZ^^
tkk}cb
lk`QQ^bc
Eb9lrs
HWGiop
---***'''"""
HHH'''###
x][TWX
Cq-NdHZiY[tTO
<u$JfAVhUYqVO~=E
555222///***%%%!!!
SSS333///(((!!!
z\\]bc
===:::666222---((($$$
^^^>>>;;;444,,,"""BFG
EEEBBB>>>:::555000,,,''' 455
iiiJJJGGG@@@888+,,qwy
yparfSrfSqdRqdRqdRqdRtgT
MMMIIIFFFBBB===888444///###PRR
uuuWWWSSSMMM@@@JKK
UUUQQQMMMIIIDDD???;;;666***vyy
ccc```VVVIII
]]]YYYUUUQQQLLLHHHCCC:::EEE
oooeeeccc
-//EDDRRR
bR;dij|
dddaaa]]]YYYTTTOOOKKK<<<
~zyNMLcccvvv
kkkiiieeeaaa\\\WWWIIIkkk
tttqqqmmmiiidddVVVnnn
{{{xxxssslllddd
xxxvvvxxx
jpqhnohnohnohnohnohnohnohnohnohnohnohnohnohnohnorxy
dijciiciiciiciiciiciiciiciiciicii
lrshnohnohnohnohnohnohnohnolrs
nuvmtusyz
t{|mtumstrxy
OSTIMMZ_`kqs
{~~_ef{
[`aEIJ9<<3662558;<CGGV[\z
ccclmnrttmqrlrs
w{|lrs
syzflmhnohnohnohnoiopjpqkqrkqrkqrkqrjpqrxy
rxynuvnuvnuvnuvnuvnuvnuvnuvnuvnuvv}~
:G%26477EIJW\^jpq
tttwwwuuu
fklu|}
kkN==),,LPQ
222YZZnopchi~
|||zzz~~~~~~uuurrr}}}
;H#05366DHHV[\syz
www{{{yyy
{{7--255kqs
'''bccfjj|
}}}uuu
J`"39V[\
www{{{yyy
u|}tz{rxypwxnuvrxy
qwxlrsnuvpwxrxytz{u|}w~
cJJ*,-kqs
UVVeij
ddd\]]nqqfkk}
_bbdghillillillhkkfiiqvw
nrrv}~
www{{{yyy
bHH255
;;;444***
QRR]bc
XYYeijw~
www{{{yyy
@45LPQ
JJJEEE===444'''
023v}~
FGG^cc
zzzwww
vvvzzzxxx
WWWRRRLLLEEE;;;///
ooo999222
}}}xxx
I9:\ab
aaa]]]XXXQQQJJJAAA777***
{{{OOOJJJ???---
nrsiop
kkkgggccc]]]WWWOOOIII???4449;;|
ccc^^^TTTIII999DGG
tttpppmmmgggaaa[[[UUULLLEEEEFFv}~
wxxpqq
rrrmmmddd[[[PPPOQR
|~~qrr
|||yyyuuupppkkkddd___XXXQQQLMMx
}}}zzzsssiii]]]uww
}}}yyytttnnniiicccZZZkll
wwwiii
|||wwwsssmmm^^^
~~~zzzuuuggg
GGGmmm
svvdij|
ciiMQREIJ'L0
tuukkk
uj_SKqbY
xYMFRGAeXPyi_
zoLB<81,6/+6/+6/+6/+6/+6/+6/+6/+6/+6/+6/+6/+6/+6/+6/+A83vf]
]\[1-*I?9`TMQNLA>=4.*SHB
UJC2+'1+'1+'1+'1+'1+'1+'1+'1+'1+'1+'UJC
^QJ:2.6/+6/+6/+6/+6/+6/+6/+6/+:2.fYQ
qg^QJH>9=50<4/B94RGAqbY
v[v>!ZNG
|kbXLED;6<4/;3.A83RGAqbY
~rdWNn`W
tieXPdWNeXP
xm^VdWNdWN}lb
vleXPdWNeXP
ynPE?J@:yi_
}rSHBI?9n`W
8D)/0:2.MC=cUNwh^
M?bYVE<6
ssr:87POO
^]]-+*-'$KA;wh^
zj`m^Vk]U
}rfYQMC=@7291-81,?72KA;aTM
sh<74/..;;;NNNBBB###&&&('&%" :2.i[S
:2.j\S
oeB944-)6/+6/+6/+6/+70+81,91-91-91-91-81,A83ue\
j\SA83=50=50=50=50=50=50=50=50=50=50F=7yi_
K9(C:5sd[
{pnkDez';L,&#hZR
~qnjLcq-EY&! [OH
9D'-/91-LB<aTM
xxx543'"E<6wh^
jjP<:.($UJC
ULG877jjj
/)%^QJ
*CW("aTM
I^&13aTM
xxxwww
QPP[SN
{{9+)81,yi_
FA>UUU
t[OFB81:0+=4/MC=ue\
,&#\PIvf]vf]vf]vf]vf]
.Ro!""LB<
SRQpe_
|pZNGMC=KA;I?9G=8E<6C:5A83?72=50A83fYQ
}lbvf]
qbYue\
k]U@72:2.=50?72A83C:5E<6G=8I?9KA;SHB
eII/)%yi_
PJFggg
_TN9:;Y^_jqt
,%zj`
)$!ue\
/Yx #F=7
SSS~~~uuu5/,
oaXKA;J@:KA;
cGF81,
+%"}lb
JEBvvv
"(-G=8
B32UJC
,Kc81,
).1n`W
)&#G=8[MGO@;E429-*70*KA;ue\
LKL81,ZNGWICI:6A1.6+(70+QF@
K86hZR
%%%"""
yvv^ED
ljM65*$!SHB
aSRpON
a_E/-,%"^QJ
:2.j\S
vl\aB9
70+`SL
ynbhF<
---***'''"""
UH>prs
HHH'''###
S2dMBZNG
`^*!VKD
555222///***%%%!!!
SSS333///(((!!!
xVU*%!
qOM+%"~md
===:::666222---((($$$
^^^>>>;;;444,,,"""&'(wh^
C/.VKD
F10UJC
EEEBBB>>>:::555000,,,''' '''SHB
iiiJJJGGG@@@888+,,TTS
gCS:!N5
zZWA83
{ZXA83
MMMIIIFFFBBB===888444///###??>m^V
uuuWWWSSSMMM@@@GGGulf
UUUQQQMMMIIIDDD???;;;666***^\[
ccc```VVVIII
]]]YYYUUUQQQLLLHHHCCC:::DDDngb
oooeeeccc
-//EDDRRR
2+'MC=ZNGXLEjH
dddaaa]]]YYYTTTOOOKKK<<<rqq
~zyNMLcccvvv
kkkiiieeeaaa\\\WWWIIIggg
xoaXVKDMC=,I)
tttqqqmmmiiidddVVVlll
jnK:_K?
{{{xxxssslllddd
xxxvvvxxx
ja^klkmoomnmmnmmonmnmha]ic_hb^g`\mss
]`alstz~
dgg^cd
rnipnhqoiqojqojqojqojpsl
~{xnjholioljpljpljqmiw|z
bhi\bbino
ubxn[wra{
=i|Oiugps
_ccUZ[
{|ocdfnp
innWXXuuu
())UXY
3Tkbdc
,WtWY[
:dtu|}
svuedcqxy
0Ytefc
wW~BV|?U~<S~:R~6O
;M{-N|2P{6Qz9U{>U|ASyB
x}~y||
4Xo[]]
aa`umo
zy~pnbXXdhi
tvugdf
usuhf\TUv}
JJJ!!!"""
nWVdno
Do(F|$9
VVV//////&&&"""
SSS111,,,
^^^999999000+++"""
```???<<<###W^_
qrropmnnlnnlopnzxr
kkkEEEFFF===888+++777
tttTTTLLLBA@
tttPPPOOOGGGAAA100XZZ
^]]TTT
<P# |{z
\\\\\\SSSJJJEEE
h_\ddd
hhhggg[[[KJJ
ooojiijii
mqrkpqtxyrvwrvwrwwswxjophmnimnglmmrs
y~~osspuupuupuupuuquuptt
nsspuupuvpuvpuvpuvu{{
otuinouz{
v{|ntuswx
DW%;D:<>YSNyxv
|de\DD.--Wab
GFF889_`anrs
yyy{z{zyyuuu
nqqjmnmopnqqprsqttsvvpstu{{
AQ'28;ACZ]^
U??389
///_bb
{~~pwx
x{|z~~{~
|\\)+,
RRR222_bb}
}}}wzz
qrrghijkkkllijilnn
_FG\ef
jjj===666
yyyQQQNNNAAA000
ooo===%%%
uyzouv
___\\\QQQIII777'''}
WWWQQQ333=@@
nnnlllddd\\\PPP@AAt{|
pppjjjYYYZ\]
yyyxxxoooggg]]]UTT}
{{{ccc
|||wwwjjjuuu
qqqccc
W\SIOL
ovw9<=NGCl[P
fOD;*"?51A95@84@84@85@73:*#<,%;+$:*#<62
<<;;2-XTPBBB+&"iZQ
qcC9/C91D:2D:2D:2D:2E;3?8/
SB:A4.B50C50C60C60D71E<4
pfOD>5/,/*&:2/PG@
rnX>T=&K6
J8"OD9tgd
nfS@dYW
UNVJDMVMO
dfURVF_WN
}^SN_SK
NGCC94
YOI<41
EY"9D687U?5w\O
PLjMFk`V
uvu/ES
vwu[ZL424,&
I@<EFGqrs
'#"WKC
[hwI>i`W
MNN|mc
yi`I=58,%B94rcZ
1-3p_Yn^Ym]Xm_Y
$! rbW
ZetJ?i`W
zorc[xg\
M66_UL
WPKnrt
ZetJ?i`W
ZetJ?i`W
:2/O;9jUQbNK<+(0'$
^\[<.,eOKjUQVCA0
WdtJ?i`W
JJJ!!!"""
e=)OPO
eRrXKrf^
Y>>/)%
NWtKBi`W
VVV//////&&&"""
SSS111,,,
X>;K@;
DJuKBi`W
^^^999999000+++###
```???<<<'''<?@
nE5(F5'F4&F3%G5(R>,
CJuKBi`W
kkkEEEFFF===888,,,.00yia
tttTTTLLL?AC~tm
CJuKBi`W
wptENG
tttPPPOOOGGGAAA344EEE
^__TVW
<P# |{z
_X[xmnnV@
CJuKBi`W
\\\\\\SSSKKKCEF
h_\ddd
~X]tXfCXD
CJtKBh^U
hhhggg\\\LMN
oopjkkgij
HrCg@b
HrCg@b
C:\Users\linzi\Desktop\j_14418_imageprc\downcode.com\ImagePrc\Release\Im1111Prc.pdb
(C) 2004
VS_VERSION_INFO
StringFileInfo
080404b0
Comments
CompanyName
FileDescription
ImagePrc Microsoft
FileVersion
hhjghjghjghjg7878ghghfgh
InternalName
ImagePrc
LegalCopyright
(C) 2023
LegalTrademarks
OriginalFilename
hhjghjghjghjg7878ghghfghPrc.EXE
PrivateBuild
ProductName
ImagePrc
ProductVersion
hhjghjghjghjg7878ghghfgh
SpecialBuild
VarFileInfo
Translation
Antivirus Signature
Bkav W32.AIDetectMalware
Lionic Trojan.Win32.Farfli.m!c
tehtris Clean
ClamAV Clean
CMC Clean
CAT-QuickHeal Clean
Skyhigh Clean
McAfee Clean
Cylance unsafe
Zillya Trojan.Injector.Win32.1719364
Sangfor Suspicious.Win32.Save.ins
K7AntiVirus Trojan ( 005565491 )
Alibaba Backdoor:Win32/GhostRatCrypt.442ba13b
K7GW Trojan ( 005565491 )
Cybereason malicious.355891
Baidu Clean
VirIT Clean
Symantec ML.Attribute.HighConfidence
Elastic malicious (high confidence)
ESET-NOD32 a variant of Win32/Injector.EGZV
APEX Malicious
Paloalto Clean
Cynet Malicious (score: 100)
Kaspersky HEUR:Backdoor.Win32.Farfli.gen
BitDefender Gen:Variant.Graftor.491778
NANO-Antivirus Trojan.Win32.Farfli.kersya
SUPERAntiSpyware Clean
MicroWorld-eScan Gen:Variant.Graftor.491778
Rising Backdoor.Shellex!1.E4E9 (CLASSIC)
Sophos Mal/Generic-S
F-Secure Heuristic.HEUR/AGEN.1369660
DrWeb Trojan.MulDrop24.10288
VIPRE Gen:Variant.Graftor.491778
TrendMicro TROJ_GEN.R002C0DL223
Trapmine malicious.high.ml.score
FireEye Generic.mg.10b4dbfc7d9c04e8
Emsisoft Gen:Variant.Graftor.491778 (B)
SentinelOne Static AI - Malicious PE
GData Win32.Trojan.PSE.155F78N
Jiangmin Backdoor.Farfli.hij
Webroot W32.Malware.Gen
Varist W32/ABRisk.XBKU-7525
Avira HEUR/AGEN.1369660
MAX malware (ai score=86)
Antiy-AVL Trojan/Win32.Injector
Kingsoft Win32.Hack.Farfli.gen
Gridinsoft Clean
Xcitium Clean
Arcabit Trojan.Graftor.D78102
ViRobot Trojan.Win.Z.Injector.733284.C
ZoneAlarm HEUR:Backdoor.Win32.Farfli.gen
Microsoft Trojan:Win32/GhostRatCrypt.GA!MTB
Google Detected
AhnLab-V3 Trojan/Win.GhostRatCrypt.C5537283
Acronis suspicious
BitDefenderTheta Gen:NN.ZexaF.36608.Sq1@aSH0VQfb
ALYac Gen:Variant.Graftor.491778
TACHYON Backdoor/W32.Farfli.733284
DeepInstinct MALICIOUS
VBA32 BScope.Trojan.Fsysna
Malwarebytes Generic.Malware.AI.DDS
Panda Trj/GdSda.A
Zoner Clean
TrendMicro-HouseCall TROJ_GEN.R002C0DL223
Tencent Malware.Win32.Gencirc.10bf4534
Yandex Trojan.Injector!gEFqE5AIY78
Ikarus Trojan.Win32.Injector
MaxSecure Trojan.Malware.73947863.susgen
Fortinet W32/Injector.EGZV!tr
AVG Win32:Trojan-gen
Avast Win32:Trojan-gen
CrowdStrike win/malicious_confidence_100% (W)
No IRMA results available.