Static | ZeroBOX

PE Compile Time

2023-06-20 17:00:00

PE Imphash

4ba3ea0d6362a841ec66a1fc0a1b874f

PEiD Signatures

Armadillo v1.71

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x00019fa5 0x0001a000 6.63511753054
.rdata 0x0001b000 0x00003acc 0x00003c00 4.42439478902
.data 0x0001f000 0x00002410 0x00000200 3.34896826674
.sxdata 0x00022000 0x00000004 0x00000200 0.0203931352361
.rsrc 0x00023000 0x00000c0c 0x00000e00 4.42247549327

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x00023538 0x00000128 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00023538 0x00000128 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_DIALOG 0x00023660 0x000000b8 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_STRING 0x000237cc 0x00000034 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_STRING 0x000237cc 0x00000034 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_STRING 0x000237cc 0x00000034 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_GROUP_ICON 0x00023800 0x00000022 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_VERSION 0x00023824 0x000002bc LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_MANIFEST 0x00023ae0 0x0000012a LANG_ENGLISH SUBLANG_ENGLISH_US ASCII text, with no line terminators

Imports

Library OLEAUT32.dll:
0x41b154 SysAllocStringLen
0x41b158 VariantClear
0x41b15c SysStringLen
Library USER32.dll:
0x41b16c DialogBoxParamW
0x41b170 SetWindowLongW
0x41b174 GetWindowLongW
0x41b178 GetDlgItem
0x41b17c SetTimer
0x41b180 LoadStringW
0x41b184 CharUpperW
0x41b188 DestroyWindow
0x41b18c EndDialog
0x41b190 PostMessageW
0x41b194 SetWindowTextW
0x41b198 ShowWindow
0x41b19c MessageBoxW
0x41b1a0 SendMessageW
0x41b1a4 LoadIconW
0x41b1a8 KillTimer
Library SHELL32.dll:
0x41b164 ShellExecuteExW
Library MSVCRT.dll:
0x41b0e4 _controlfp
0x41b0e8 __set_app_type
0x41b0ec __p__fmode
0x41b0f0 __p__commode
0x41b0f4 _adjust_fdiv
0x41b0f8 __setusermatherr
0x41b0fc _initterm
0x41b100 __getmainargs
0x41b104 _acmdln
0x41b108 exit
0x41b10c _XcptFilter
0x41b110 _exit
0x41b114 ?terminate@@YAXXZ
0x41b11c _except_handler3
0x41b120 _beginthreadex
0x41b124 memset
0x41b128 wcsstr
0x41b12c free
0x41b130 malloc
0x41b134 memcpy
0x41b138 _CxxThrowException
0x41b13c _purecall
0x41b140 memmove
0x41b144 memcmp
0x41b148 wcscmp
0x41b14c __CxxFrameHandler
Library KERNEL32.dll:
0x41b000 GetStartupInfoA
0x41b008 ReleaseSemaphore
0x41b00c CreateSemaphoreW
0x41b010 ResetEvent
0x41b014 SetEvent
0x41b018 CreateEventW
0x41b01c GetVersion
0x41b020 VirtualFree
0x41b024 VirtualAlloc
0x41b028 Sleep
0x41b02c GetStdHandle
0x41b030 GlobalMemoryStatus
0x41b034 GetSystemInfo
0x41b038 GetCurrentProcess
0x41b040 SetEndOfFile
0x41b044 WriteFile
0x41b048 ReadFile
0x41b04c SetFilePointer
0x41b050 GetFileSize
0x41b058 GetFileAttributesW
0x41b05c GetModuleHandleA
0x41b060 FindNextFileW
0x41b064 FindFirstFileW
0x41b068 FindClose
0x41b06c GetCurrentThreadId
0x41b070 GetTickCount
0x41b074 GetCurrentProcessId
0x41b080 SetLastError
0x41b084 DeleteFileW
0x41b088 CreateDirectoryW
0x41b08c GetModuleHandleW
0x41b090 GetProcAddress
0x41b094 RemoveDirectoryW
0x41b098 SetFileAttributesW
0x41b09c CreateFileW
0x41b0a0 SetFileTime
0x41b0a4 GetSystemDirectoryW
0x41b0a8 GetTempPathW
0x41b0ac FormatMessageW
0x41b0b0 LocalFree
0x41b0b4 GetModuleFileNameW
0x41b0b8 LoadLibraryExW
0x41b0c8 GetLastError
0x41b0cc GetVersionExW
0x41b0d0 GetCommandLineW
0x41b0d4 CreateProcessW
0x41b0d8 CloseHandle
0x41b0dc WaitForSingleObject

!This program cannot be run in DOS mode.
`.rdata
@.data
.sxdata
PSSSSSS
^L8^4t
GGCCf;
8@@AAJu
0@@BBIu
AAFFHu
0@@BBIu
8@@AAJu
@@AAJu
FFAAHu
@@BBIu
AABBHu
8@@AAJu
t'<\t<nt
PPRPQPh
^$ ^%
tPHHtGHt?Ht7Ht
tt8F<tx
W9^`t\8^=
FD;F<uK
FP;FHuc
t7IIt It
FXPj,Z
w$_^[]
;~<t_W
n`9ntWv
/C;^tr
~`_^[]
uwG;~xr
uVG;~xr
9~xvM;~`t
9^$t$S
=3333w
taOOt3
FXj PW
t~9|$Lux
D$@_^][
D$8UUP
uG9^4tB
q ;q$t
|$ ;\$
D$,_^]
L$,_^]
T$,_^]
tt8Wtu:
K(+O(9O
9T$,tp
9\$ t,;
:9~8to
ud9l$Xt%
nT9nDt
~L;~Tw
~H;~Pw
l$,;D$
FP+D$D
u)9n@t/9nDt*
VH;VPu
FL;FTt
L$,+t$4+
/FG;t$<u
;L$ds.
;L$hs$
D$(;D$
D$(;D$
D$(;D$
L$,_^]
|$(;|$
D$(;D$
F$9~,u
D$0_^]
L$0_^]
T$0_^]
D$0_^]
T$0_^]
T$0_^]
D$0_^]
;~Ht0U
^@9~8u
;D$8ul
u69|$<t*9|$ u*
s49|$4t.
l$\UWVPQ
9l$<t]9l$ t
T$htu;
9l$4tm9l$<t#;
u9kPu
9l$,tD9
29l$ht
ExecuteParameters
ExecuteFile
RunProgram
Directory
Progress
BeginPrompt
Unsupported Method
Cannot open output file
Cannot delete output file
Cannot open the file as archive
Cannot find archive file
Default
Error #
FindNextStreamW
FindFirstStreamW
kernel32.dll
:$DATA
out of memory
GlobalMemoryStatusEx
userenv
setupapi
apphelp
propsys
dwmapi
cryptbase
oleacc
clbcatq
version
uxtheme
SetDefaultDllDirectories
OLEAUT32.dll
MessageBoxW
ShowWindow
SetWindowTextW
PostMessageW
EndDialog
DestroyWindow
CharUpperW
LoadStringW
GetDlgItem
GetWindowLongW
SetWindowLongW
DialogBoxParamW
SetTimer
SendMessageW
LoadIconW
KillTimer
USER32.dll
ShellExecuteExW
SHELL32.dll
__CxxFrameHandler
wcscmp
memcmp
memmove
_purecall
_CxxThrowException
memcpy
malloc
wcsstr
memset
_beginthreadex
_except_handler3
MSVCRT.dll
??1type_info@@UAE@XZ
?terminate@@YAXXZ
_XcptFilter
_acmdln
__getmainargs
_initterm
__setusermatherr
_adjust_fdiv
__p__commode
__p__fmode
__set_app_type
_controlfp
WaitForSingleObject
CloseHandle
CreateProcessW
GetCommandLineW
GetVersionExW
GetLastError
LeaveCriticalSection
EnterCriticalSection
DeleteCriticalSection
LoadLibraryExW
GetModuleFileNameW
LocalFree
FormatMessageW
GetSystemDirectoryW
SetFileTime
CreateFileW
SetFileAttributesW
RemoveDirectoryW
GetProcAddress
GetModuleHandleW
CreateDirectoryW
DeleteFileW
SetLastError
SetCurrentDirectoryW
GetCurrentDirectoryW
GetTempPathW
GetCurrentProcessId
GetTickCount
GetCurrentThreadId
FindClose
FindFirstFileW
FindNextFileW
GetModuleHandleA
GetFileAttributesW
GetFileInformationByHandle
GetFileSize
SetFilePointer
ReadFile
WriteFile
SetEndOfFile
GetProcessAffinityMask
GetCurrentProcess
GetSystemInfo
GlobalMemoryStatus
GetStdHandle
VirtualAlloc
VirtualFree
GetVersion
CreateEventW
SetEvent
ResetEvent
CreateSemaphoreW
ReleaseSemaphore
InitializeCriticalSection
GetStartupInfoA
KERNEL32.dll
,!@Install@!UTF-8!
,!@InstallEnd@!
.?AVCNewException@@
.?AVCInArchiveException@N7z@NArchive@@
.?AVCUnsupportedFeatureException@N7z@NArchive@@
.?AVtype_info@@
33333330
{{{{{{{3
{{{{{{{33
{{{{{{{330
{{{{{{{330
{{{{{{{330
3333333
33333333
wwwwwwwwwww
DDDDDD@
DDDDDDGpw
DDDDDDGpw
DDDDDDDDDDD
wwwwwwwwwww
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0"><trustInfo xmlns="urn:schemas-microsoft-com:asm.v3"><security><requestedPrivileges><requestedExecutionLevel level="asInvoker" uiAccess="false"></requestedExecutionLevel></requestedPrivileges></security></trustInfo></assembly>PAPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADD;!@Install@!UTF-8!
Progress="NO"
RunProgram="Hc.BAT"
;!@InstallEnd@!7z
bh~ZX7
bC)JBf
>1eHD;4
\!|!no
[*jkjoC|
:yuZqM
_R*73"8
nzlB6}
m3].d0
oK2O@L
"7,i!Z>4
F9YePV
Me.y>&*
GwocE\
ZvF:*!^
uO3GN!
(@GTQa}
?s^a:s
~vy<;g
6{>u U
c^)B{o
ejS{^i
c/) (S
20Ghyy
i'C*Jx
DoEDA./
!n\]a
OL fo-
#f>"LXc
ZZ74,(g
NWS7sB
mvR#l6
NG,uQP
MK?%k/
\-&X)wGh
FT}pqs
CqA8sc
8O;@$M!
9dp>J1
#/F$MuT
&ACYeI
1o#:'hT`
r>(fK;
"I#KNre
3WM+M!'
aZ7'a@
?H%Kkf
`?h%qU
-C%z$1
`?v!@t
PR!o#s
@mqaHB
_W!]oU
U+?ZWWw0o
DOETZT
FpyLz:
UyMHn4
!y#zD#
d$d/BJ
%\i{p[
PvM}(|&
O^}?"{
|Ys~r
8^`cd~
g2LM^JD
*&/Qe}
D<n!C3
x. ?b
6fbf!K5
5?Ta>Q
<%x]7%
GXy]\GV/
27L:`|Y
a. AF
V`n*iw
>([K0&
HH> ~Z
Sum5U
Sg(Q-H)7
HUcp|Je
(@J`nz
RagSR)
W7 Tkr
%rt)3EB
W>/<.KQ4 C`
vat|:\
zLoW#X
.mwmWf
f~jE#_M
TYz&jV
"fge=I5
Em[^Ln
dM)wP`
N3{LQM
m[p@?089
-6}Bt9
FM||nR
PMWDaV
p9Z8##)
&Qg%IF
|3(DhS
Brm.&xX
up0ZjjP
$%]Tla
W=_dOs
)&J8V5
mzW2"s5
HO.X#^
|7m:O!
NSY{&&6
D5[MU8
nY8qp|o
.e&\>.
\\hGMjPT
\0A!aE
4tci(_
/XQ!wc
HO^L=8
(S[ca|
RF*g+:=
,}TXE3
Uk9oKT2
_16#6YR;
MY>`1M
mhRW5t
eT W'~
?+PAI/
`K5I%g
']_[eQ
$f$T!F6
a3W!3Wp
&5TPDy
v'+E,R
ef4FOd
wF7'&}
00,Ee<
$jpT/E
u{"qTpu
yM(yFy
9P]FjIBh]
!\T~C7s
ZV!FJ"
\n\~&(}
'w"wK`L
Xn5|W4
Qu+qQ~Di`
dP3;jZV+
KYmQtx
D+VWM*
r?ka?__
p5sNSl
^yB^ew\=
3dtDR\
SV84>2(
>`W^2.
Som=KTG|
`3fD_+%i[
\z%-wUf
$(%;Ik
jK5|0LT!!
$9]A4|
IOsg^L
V_7`qm
n9WgeFg
f<yPWw
u ]33G
V=OBl+
G"^..
Sjrnm33@
Q^i/6&
;2td%~
u,^ be
C@mPG\g
LNwmI;
9Kt]V+uv
99^,tn
Ydy{?b'<
KLlO5i5
=M4wXF
)@/\7,;
T+0iiB
iu$(Iw^%
8l+e>8G
0$lwoAp[G
IY)fHK~vV
(8"(}dw6
dp`xsx
+fV1{
w*+D[J
eF8nu@
:@n`TE
';Y+Sx
fOsB}0K
T>v'K
U;]'-=
0&~7;q<
fgcPtN
Wp.p|[
viA@yg3
Dd\t[@h
` gNii
Jk>"ld
=U+R\q&
!fqx#HdI
oR1,C22
I]Q!l|4
sTp}XSK$
g&4;KY
V7vN3
XYb>Q!
,12t6U
dqKw
BB-(4!!
@n8up#
k0cRxvek
TRZroM
B~yny]z
W+!U~nA
nQPJ2l
p!##r9Ir
3CMY4z_
qU#4l"
+ k&i/
bg78\
VPe%K/
5evd.N
l8Wl;Z
:9M-Ah
Gl'xyK
Thcf[z:u
cWy`55
~aa!tgk
"40.2(W
o$=,dn3
(sx"?:0
E=,2NqI
Lbonu(
_mInB/\[a{
<R~EF]
,UL6'@_
r{d2)x-
:#J[prv+
Z.`f$f
4kP_KG<
}hM;;\Oj
Y}HuG3
Q1x!^k
IT)@U&h?D
SX/y*h
t6DEY
ki2}j%
w5Qt@`
V6FndL,
Q0Z$9=
w[@P%E
^mNo'q
.&AECG@#
kl>=B3
ZL=y-s
^N.KE|
~,!4jF
BnLNj@
eUA}x&
*m$=5M
xrH1VC>
ghy;t w
KN\Aw<%
*L'NrH&
=.DVC{s
,u&Y3h
n(BFDkBj
fr'MDy0
'BN2P<l>z
[ku(z]
4/RWTtt
izUE~ar
Vsl6Dl3>$
uF'^$jX
V{#%:MfA
{0FQ,>
y?B|>k"
O`_zJ|
]t;pzV
KVub$%F
Y6 #7<
%7AZdj
-X&3~@
b6x6J;z
U`d\e8
2D"=6$
yTMKdx
-]#n:{
X"Rmf{
yX%%BH'
mN7Ve$
9I)r&Yp
|@>&G909
v}FrZ:6
(;X:&+
u8FBUh{Io
=(`5Y_
X>*TY
%{g~5O~
%yWWY_34/M
v:pj%a
uC$?FsR[
%mzL#sp;ma
{nU8h]
StVrtOg
)m0zzw
[!3"2G
O05 vq$
Td(sOg
yQ*)}.
Omjq5ivL
&Ao=@E1
P_FxEL
8qK}Qg6g|m
@6cCJBK
~p4P5\
~O>rm]
D19S2Id
*~e<j8A#
7_Z8I_
P+m%I+
(,f[Z/
X^q'Kq`]
s7U[Z%
GF8o?
AIaMD
S[<,M6[k
>|d{'In
tk7mG3
zJC\//]H
Oav/R_H@OW3|
SPwgCZ
%*3sWA
cMQ=)!+
$hkWHw
6''e>6
Li>uuF
$-~1H-*
9C/KTI`R
OfU_B0p
Q_7Wn)
`p?ZSfX
k:3#)f
^d5i$l
s&1zt%
kf[JS/
uW3trL
Pi.|g%,
", _a<
N}X1|`
#$q-]:2c
CTd0{W
E~<t>
!?HAc.
W/"wS
t0U!ql
#V`h8z>
?Z=$L|v
$}Ve>yi
ur%LXd
BP3F%
[GDoA|3
#ni5e}
wkTn^rd
i~)&a~
APFSm3
}P4\7#ZM
=PW/tw
Lq5TA3
BCsoxI>
5 >jdn
_9Z;f
8jz>Zo<
|Jx/C
O`P;pu+
u[Q9YH
K<gSS?
qFKSa)
lbQWDq
^oakK(+_$
{QA;zf
^{)ANEoe
kdm4e.
vii?/*
TOu@U]UP
A<ID28-|{
l,br[4-1
n5<s%y
v0`z;]
Orbc#EA
=R$5+5
`U7+i"
x?(8M1
tSBfe,J
r,]SJF
H?!mc~
,8mnLa
/z)07!
?WWTk^
jN=)TF
y7>SI\
gj_95&fkX
04<Sdkg
;,x+7A
m5p\V[
-bz)Kd]
|V:~u
G.?J^A
79&0;4
+:t$HH
U!^,M<!
=fUe_)i
9|YtwPy
WR\EK^
`;`d*^
(bC^&3'@
qi9^e'
g|x2?h
MQ24::
_(mWm-
f@//81
F|nxdBZ&
9"8oQ0
Ad%{?0K
;Eril#X
Zj`Uax>3
vG>}&qp
fTKtHT
}Zy+W:
x5cJ*\
%A:;4
h"jv?n
j?Bw]s
<Y|.>0
0MHvN8f6B
qj1Re%
&^,{bo
~8M\jE
sde'e?
4 P@.A
b52'$gi
U.ns]\
/QlS(M>
X2w0FKK
f\kzkM)
`*bY5Q
{N!."L
8R(`Z$dn'
G-}[GK@8L
37C?UI
?.{Uj&OS
oajfi\
G'SZH#
\?M/r=s6
L8a&h
9&fl2m+
k368xNZ8
Yzzy*k
e'3]{N(
#V<wiy|
6a`X!.,g
C-ArJF8
M:hffmn,
AD{)aZ
? :>bJ
4U!n-8
!HT@J9o
n35)k:
&UQl3m
;iw=3i#
3YJ6_5
qLm"p<
(,fx4?)
sQ\bkNCU@
0n+Ffg
x|:+F
mSVW'}:
j\Ej3U$
F>I,Q3
t\%qG=jC
.e9aQ}
z!B0s3R
,*OUBd
`Ufq1I
a28QC9
:-[&X
{Wj'x gpx
]V=pwr
8r^z
u!3^xk
;?TEt~
j/M-+T
z!VA5X
fVVK>\dh[
1#*u:\
u/RJVrg9N)
:D*|9k
UGT7gxs)]
fY!s89
3FbLp
pdc{R`
+:fh-S
O(|e.%
9FtM3q
&2m/[x
%%BbJQ
z`9py!
\,$Ag,|
hO]br+
4~Tb'5e
da0mG}T
y(,zO)
IqlIk\
BTc7_|
i'>~%a
V$U|p&Z}
R+I'SJ
&)|E$s
q=sq)ao>
eV{MKh
:?A7(t
~Yz%<N:y
<X1`.;
-`R&0A
sLWn=
_^aGhS
{JLP@
'V$XhD/
Ny&gF=
kIlt6h*
!~X\yVF
jvBDU3
H_Z+B[-
2(*@j=
\lw=t1
`wU4_
q7Mb6C
]Gb-k&
z1Im!A
{k`]>d
-|S\GFcOp
&p6%)8s
8YtN_{
$j)E0
Ol@(u.C
WPg<9'
LED!E6
bQA>!G
$I7XMm
iu}09=
DogzE<$
hAPbFA
~Oy.: -
&%]XWj
7AqCB8
>\s&u7P
[O<&P;2K
Hteua7
_n<L^z
)hL,S^
d/JMzjN
|;ZuAO
^//ZsTv
A -R!s
d3N8hh
]{+:p`
[\U$\:
5r$KP;V
DB2VWp
`;4Il~
`}J["u
/K@f~[
y9rntI
8\#'$}
A_2evy|
&+4IUs
c&8`"kZ
@`#x7(F
;~KW/p
PO<^}4
|ESK7J}
V bU}r
MG3kM+/
aFKxZi
@1TK/l
*aYC,bl
*[M_ZW
*}+Wtl
CJB.xt
1=F&KK{
j1BB6#]&
s\%gl'
{{.Cx|
]R$Tuu"'M
i(^0fI
Fd8Wx?&
8Z~}b:
{vW3F{W
9ra@>!
p,bo-<F7
J.[uhp
Au$+H)
C5pgY..
*`*]NC
c=J$N.
LW>;V#
"LDF#?k
GO?+n!
_]yx2N
Sx('IiDO
qM;[Z7
]UZbg"$o'C
6jvc"
tE(&[3
U9/^yt
WF&xFiL
^9t+:\|
{I<x7u`
=2-t/v9
?tT(x8
;h5*8G
cr\CYB
Lw)f|?
RtrS"Er
'2re}
,y:':1
,Z=V^;M\
NZ12c]
I>g1xC.
Tr%j+i
5Mf37d
T}DU[N
X}-^1|9
lws:/0$(~
W:38I
zk(]6}
`759)%*
hU`eRKp
Z-8FsyJJ~3
*KU]`i
u'|";*<>
GD\9SUV
vSH77l
=zwE;y%
A+suwD
=z$?0r
'*v*|u
9=%<WWNd
dG=uhH
m(HURUF
GiPGrMZ
q}qWCH
J`4/tI
=rZ0hdu
#yhZ[W
;,PO`{i[
viQvpi
oa*eX
k&6zS0
"0IM$7I]
6,3QG$L
)mGJ=O
+2E`K,2
PpOlZY,
T%(XFO
DgOU=d
7LMfHt
$P LCO
Z0;XqW9
^NI,hn
r#gTr N
@p#94%
9R ZR=?y"
m@;S8"
{R^*z.
O|y~L,
=zbWBr
pp+)[AY]
K'e9],
yWVeC
27Xe?
KyfnPq
4PGcOm
/v(Zso
yp\SSf
vr1'G3[
VQFJ[i
JJi(d>?j
G=|Q:X
$Js(iT
']}fo;@Y
D{W<5F
-(#Qmk
k]i~y5
7$!J)G
taYhmz
dsY{:s^Q4
F.!4&2v
h8M/6J
#C}. j
JLL"M&$%
3gPb!vG
[cFl
T/f+g=
p$ej4
\U&2>_z
nK4U D
{mh-69
=d<bx^
qZn]S'
w&< Y?
@hGA}~
9;8ak_
4~z8IHl
JcsTA
J[@:;J
mr;"j8
m+t(oB
~2'J6-}g
;\i'N^
P+b+OL
X=:i2
'Uyq>jT
HU\0,o
tq z*7M:
=Krn1i#wS
(v;Ja1
IX@E>'T
2Z3[xO
OIn; .#Z
=-K8P[
HvTX7}
x*`7XE
^Lug5=
9eN|]4=)
IQV37t
s8\\)w
tS#a^@
ew/^LyD6
h5G$A71
a}Y q2
B:>+?U
|#g[CO%
$KsOVa
H9Y,k
x^=hXJO
3u/=0lu/
yX&rt`
kbJusb
u]hQr
V3Vtn3
2!^;!nR
;hjNv
I?c|QZ
k.e9E
zKGF7X
I+fpzwU
^P=Gi\|
Xf7Yvb
Eq*|'!d@
jae6Cn[d!
a~k/kM
L-zirbm
LbxdUctY"
;?n0*u
#4*JDR
(P4NSc
8;@!D2b
sFJe&CS
T37(\_
""x;B$
Ia$8kC
tgqPVMH
7TR8Vz
w+quFM@
NwgM$d
eG'>6N
V-Z 'I
Yy'RS7
P?bK46f
~Es#kV]
q^:3XC
ZtT9P_
[l:esU#
Vb0RzC
9<@t"Zq
WIq|b.
84Srf[Z
Y>,O.
%WX{7b
W]:CWXeR
-.7dBG
PF{8;pH
FL4"3W
3DJ_cX
hm=FH5
3JYd]a
]<bGlO
U6~)E
tY?a
QutztpB
(6dL46G
K~.Kv(]
_'*DWh<
.eq4Qe
Ul;ac=
a6HD,$
TUprwg(
;G<[79}
wN]A6(
5?Iz"4h
J&X2d,
y:p3;b~
|eaEt2
%:BXH#
G/6>=Z:
a.fHw9
SMTdNem,
+}#N:w~(
dLtOv/
:1g^kG#
SA}m_>
UPOv7@
j Kkw"
Ifonsf
HEX-Wu\
7Wz1F
Zn~C18i
!+8P|]$
pA{o"t
R_-($a<c
qy:n`2&9
T{8)(]w$L
dU3?6R
<iLZXD
;5+iNu
x!^@J~
2LaCoQ^
G?HXNi"
j:&*v1
CY3(aU
_$9;o;"f
GXru/p
h{,s.t@;
Y4a5@!
0WwH<c">
u UtA`
}3C;=0h
b5IGQb
I.Ynp
~q<kk#<m
KWbx*"I
oMa?+X)2ql
P{Anle
'b|lmj&
VhQHbG{
U<!9l-
(~4$s(
^do?;$
3o>&k~;
X7+N[Y
3e@E]F
,3>ud46iF
iKAvcF
+|#q@Y
@_(%Km
aevTQt^7
F4f)9f
b{.7B5
2g+c]Q2
q]XVQH
97aXBA
/qD/WU
N<-h`*
ip"Mw]
|W%N*f
W*RJJ=
]{5Z]F
(S:4U~
R(nuC
[[{L M
$l?U3V
0H7_Rw
cvpF~ex
;J%pe|u
o56dF>|
dwFBu4
.|z5c)o
;@AprV
{;4B?>
'%.Fs&
9W|t~U
TwY/13
K=|+EQ
8;HXHA
;k$\N@
V_q3Ht
Z))r_b
b%wsTP
5'Vsv9c
: XJ8B
U6pFn
\WD1cb
n?g?]Dw
>[Cc3N
F9lHhIb
"O#+M@
d0<JUx3
(:bAoJ_Rn
qpX?.0
*S<l56lg
]]Z+)(Q
fi^NYZ
XS= 9Mp/
6;i-%nk_
S\[dn,
]h}?uK
<Io}(c
]ceYg7
[vjVxg!62
Pf'vU_
g$NTSJZJ0
5o2K'=
="MU|D
-S/Y`X
Z!l^i62
D(q#H:c
'mhleg
WD<gE7
%{%Sv*
t~%f22
U-2qQJ
S9~<ES
=N3$@2
y.TZ"1{P
t0:}G2
I6;](6Zl}|
9<2 62
+],P^O
(O| 1Y
f[Wj2,
y;rdd?
UJ?,:I
_XcX3e
;q3dEA
mXtkWq)]J
<x0cFD
FM>>0es
Ay$'AQ
h?)t;KO
oWHt;z
SkGlJ2/^
(~NzD]
w0~p;$><
s%;w/9
2]${/Z
P?ZHI@(
z%qN8q
}jwi5
n:IEtFaD
|qUz,W
Y9chs%
k|E!SKW
I>z\eU
82Ec?y_
GTa'a:
iHa^./
WA[}9h
LQWlN^cQg
8ShjA%
"(^yg:
Uw#?K"
h:-Q%
{S3JIr
}83P[A6
rF6:Y"
&YwIUi
$|2R}a
I'?y&v
"Uu*F!FV
,{]{Dx
28pbd/
rEuaZZ
+*EUrq
M!.UNB
rP3W>a
+Ph%.VG
0aL|?c
xECw*0PEs
DkV[1?
_D:<4]i
&9]4@M
wG&[<:
2ws"c7
K_D9D`,
xqcd+jE
.&9u/dY
Z?>-h?
mR&U:
<"UWmf
jqmP^@
L)mFFZ
]([_ecj
o7+l>>
J_'=O
Ps;.&a
`Sa9>O
0muWz&
FjrPFs
,5{^(
Xd@9]C
#i;5[p
QxP4X?
8p;S(]mF[o
+2(@rcA
lE~]f0
qEh8.6G
 ;uGm
pJ/^&p
=![*J/
xK"`!(
FdP=qT
7fNa{.
MGEmo'
w]t'sk
W.{Qe?
t>5+>|
>It;%6
6x83xl&
2!Q`\]F
~ahp8e,Ea
L)DXOiv
a/qe1%Q
TjO3=5+
0TOm#r
XC`.`u
P8uH+#
/AlnOe
Uve,ab
~:\y;*
] tKOy
Y#`-vh
8,T}Tx
}6(!%n
tQ?y[2czq
`iFzk5
oe<p)q
jd9,o].
C{4$`;
]'pnG}
Ql<Z/+y
RBaRp1
h%3-(1
bo%_TN
`ruQDR
fmy],p
ZvSbIT!oE
JV(RIw
:!8u%o$
O@AvaRG]
DBAE5on
XTl5C/1
~6 a{/
5eYyp%yS
v{xX}_
cS)c#>
G6*L6U
#(52YQ
Q7-^jwt;
m4%Symi
~$Wvs=
uK<"%Z
J}!!)`
=ha27G
}a<1*)<
XDl?z4
e<v{?:_=
yqA=+q
7c`qoT
1Ovg'r
DK96BY
')EwX$
"bnEA
Z 8|\N
6tPOCnpq
X}c]9A^
4y'u0]mz9i
9kLsF"
Drz8jG
_eg(fd
6a'K2(B-P
iT{\`Q
nra3=T
:4`}A=Y:
A>Dvrc
$s:r7K_
tCLV>i
X{pcMZ
"|Nn\]
h vJ6`%
c)5b,=
xK.TuY
@8H"U!
|GROmy
UAUgU
b_5P,c
@kU96/
YHV@VM
XWSJxe
!UFs`&
o0HIu'
0a8XH5
IliJ9'
#aZ)Zs
&IY6T+
f;|P)Q
Wv}w#y
f&X'4E
My|:>xx
,e7X9s]
/vn]Dd
XC8?WZ
T_&T:S
y2\C`Am{
ST7ArsVpH
rknfUm
nj\+ %i7pa
Aak0E}
BF[ZbN
QEC]S9hdS@
+7yfq}F7
O2/"}S^
ya<cw3N"
}.+8hY
IS*"4>yx
'{x`lM
UxJgY{
KXvA<$
V~@f%p
N380}_
rWfJT
sIvmSs
<-"s=()
\5D6y!
2m56:(6l
tj,^~4
z@7yp+
sA'.\&
9ObIiW
if{C_;
&U xCh#je+0
-Cu=M'z
Bn^s)j%
(F)0P
)sD\C<
]0h%j4
[#aR%U
aG[Hh
2xUKW#
1l4W/(
\uw8R=
K{YcN}
|PB:32
SK}ZOgn
+8<2VTC
9Ht("O4
R:>r&+
!XJxMP
h%T/ l
GF[a 2
RGx/HU
(o3lX\
Nj! pd
+=W~0-
cV9#m.q
chqB}s
r_<KR*
^<Jn&N
9&<'Vq
NcSeeK
oQMSSn'qE
@}L\UbB
T19Z"}
NB)qyz
?!k`WF7
R9K}(R
s%auD7
%E|'"f
extL$7+/2
~kxpOq2U$j-
f4-t\)
ILE=&_
9=Ak6
&I0Th^
Q9})u]d
uO PGt
up:7e%
,x~B%)
fK!s4*
f>>_y&
J}D|3Yl
#cwRTa
b+6/{K
+r,&vi
!'=a:h
'5O*:zB1"!
IgS-k0
Y'Tf]=?
Gvf.0:
O4DO^2
s3N3;UW
zQW||y
jFY#x
G%zj]Y
e[B[QB
=64YP1
fZ`&f0O
qx4v+du
'y/qg[;
K"_&CLS
wWQ_&D
M4{P(H
|^;ZD(v
q87su>
OQR5pp
Y[X5$x
5}ug-([
+KeO;HGt
M0RC;F
IBYOOh
?O%!0n
_$C^^Q
|@<0L91
t}u"1Z
!-ymJZ
3{U?4|P
",aXJF
meZJ>)
OqQe$o
p-/Lu$}
h6v[U%
f0/-X&t
`k)jqi@c
$Uv>NLY
:\1Hgy
Q17#|>
.3N_)"Sk
nZ6fUI
Q TCv{;\
tml*YB
/0F:B}
F>?6x
Y2@/!qt
7:jV]/
x+fSMf<B
3O&kk;
hEKdp'Xz
.oaHHmK
zOikj6}J
h9Zl@w
JD%4qF
PDV~F+
]6rj+a
X<w4y`
Q!fYFL
z:;~#|
sp-yct
}#@."-
0seL\"
TZ"J~"
htkyYK
0s}xqE
S%{K<!
('`IEv
|5|^x:o
WJ'Y1q
tn.(CJ
j-aqKR
aq5w:nD
b[%=ZT-
VG|'y5
P]c\PQ
XDxfiZyZ
|5-qH(
aoiIH%-
<l?/4Qv
{&ev|A!S
{jjM->
!f$Q%'
+k<2Y[
:lbo,:
}/\9@Tp
][c1#~
2ObeH!
Mj~|]i@
~ws\~pY
C)raP<
eIYain
W!^<lN>6C
LUsFF4
=u2!b8
|k;u^Se
S4CZ^G
IQ$7aT
#n%+YTH
;@5b8B
KW1%aK{a
(il$-[#X
0j_GlA
J{+8D>
c-9WOHJux
GHpF)<B
Bmfq`,q
N2_vMw
=i>r[dw
xj<p1-&
@T)q1u
28*"~
VB-)u2r
JCOTV$I
?h!KC
/O4M!({|
]LIfZTT
n=EBp}
A(#Xv0
kWbyE3
nypis6
Rb:jc@:{i
k@#i(_
j sON%
V^_4;V
EY4?\!M
|am'K%
UzdJ*'!
N0&h\D
N4I#Ma
nZPV}b5
r_cv:@
DC>]@;Y
fj`<yJu
=7+NGN
lVAXk1
&30%:^
(E=Nv
|TzoJ7
2.1'AX
t1T2Ge
+Ob3s:
,\=UXS .k
G^+Djt#?
$Cwvqi
(GMw2\
({yYHV
*RLHT|
H?#`GI
bl9qvP>
-uIC-1|
E;HSQxM
xX*5{;
q{J V(
.J<3wu
x[m3H8
+FXA8M
<:-z;c
^B#$h%
S7=Xg
u>_u%[
wo`&34
{yk@0,
F$ap0S
P2{"(8
%^{:3;
x}zMQ/
j!)N6XK
IQ4)p\P}
hcU0|q/
nGOBz
\=?+3N
E<~+rS
p@DU]tS`
~"agae
eLFu^|L
":Q-@u
kbKWoL
llnqanU=
M/urO2
,^$>ym
^2(J\f
(j"d$"
(t7z-*
"s.o4p
aG7WYH
e<y$5'
}PW54@
+6-34O
6>/>DB
?TgfA5
n]+&[
P}Bh}S
X}@5n;
T^)&[T
En<7$,
S/]o;D4E
f,">/i
vIfrB#
]cVL?r
&&Z8N}W
KNRd.z
G@c=z
4b~HWy
VayMCC
;O^{?Rj
+m5W>TH
HZ4+D~
v;{_ o}
&m|V~g
PuvLC
unTH65
"1H%4
w<EWvG
]3OQm2
i?BTh^
ix$s`eYCeF]+
kcG -N}
2imSm,I
ox`-+P
+,f0L1
wEYcf[
Of{B>,
[5;+u|`i
{.JA8T
qzGsNZ
'BGbs9
jJw~{O
ga#|4e
N5;C'g
wv44cp
!iTaE07"u
oZ^nRh
c$:^XG
tXXTbv
txX?+y]W
%BYI-X
/g!WJ'o
_t=:S`>
3p<dj`A}
ZN!j~<
\L^%6~
&wne>^
TXubG]
fl3vp,
1v!Us:O
B}8t%;u
SwBXjm
+UE=3r
SF$+wl
<Xx,L+
jfCYcf
xAoW"(2
%@vQ?ZQ
x;zj`I
EYbfIczL
.<Hm<J
Jyl:1q
W;{rG[
?;[* 9
C$AH(B
Z,nX&a
7K`uPs
h$K%,
Z>&2A+$hr
skJ^!Z"
jvKs;*2
oopoD6
`p6@/(
dX6VzW9
y!!kR
B}+hhE
m\]55&
cs@&IE
Ab(iZ
>Xs-M1
6fRB2}p#
pMt}YQ
UX|< =
rdUoO=y
8YDW#o
J(G}M}
E\!~8E
]%<:wH
g1W!?
e%;-A
?D:~yC!
1'%/_I
t5?Bvt
!%yU%X#
rWa~Ij
&OVvj2
ms$R^
?)1I0:
$|-p(1
$Gq9R<
)fK=)t
{N?hlA
@\]3'Yk?
eFn-6f
Q43T:L4
b+C)pIw1
>*uQQx
a~P57,
FF+g/"
4>3H;C
!S~X>
GHzfAia&
G]n]8X]
JWdUE4|~
d0)HXb
<wVfb->
43O|23W&
b&}m_je,
UU# v8
|%KKV}
Ek)EY<?
r^O~#P
Ul0`pQ
'H<79q
X$@$C3
9OWc7P
a*n?>j\x
<1S %n
=BLxuV
A1II^W
:m-/be,
Nqvl,<0
jKp\5
;&ZA<@
Ap%qh^
E!5Ahn
L>[<W!+
|<Dvp1
-1Pj'G
}5Uu.W
)}F~WlE
2~eW,%
YR#E'm
`{S]b4
Q:CQTn
9By`SX{4j9
:eQ)^B
mLP'la@
+4$v\5
;~|J@Ul
W1723Y4
1.xq2
H=m?Vc
%#Z,iO~
.i-z^W1
WG)l4OMf
")2|[O
'H0rh_
52cH/l
!;WYmv
gB`4}+
QU>84x
"@M*Z]M
9^o`.d\
$qc7UP
d>Vl*Z
GoANd\
3]B_QP
xfUl5SG
\HyB-8
R%*$)G<
S[5bo
k="nkG=
<wd5_X
73HG.?
Nx'P~'m
4dV([+\
yT,;3.
6R8b:KE
Vl0?37e
4VeU"|,1
LoTSFa
A13kkG
K1tM[p
'vo1I_e
)=)__|7!
-l9VJO
L)XO^ K
X\Lad3
I0\2F;
oiM_6]
D_#rSG
SN?~?%
1O3df-oD
"Lqx9l
O5=9>r
F::P~B
7QGJV]
p3w=#I@
gWxQ !
jryvtt
(T./yS
=ho)Rm
)=9,ILEG
Kp\{lcck
q^XIhn
(p_~QNX
+nS(\?j
[0`66a
Cf?_N0i5
{6Vsd-
,>`D. 3*
7oousK
1jF3pf
G]7-LR
ioOxL3
c,WpUw
!r6)}-
{}+'/Uz,
<0t/[P
]Z$ch?|
xw4 |Y
<:_j~e
'2,at`!
s0YcsD#
b%6k`2
"a@mp}
qT(XTi
f8)6g;
&#N5K7M
5E-k{}
0U2v|,$
>o"0~x
't~i&$@p
AxeMgOfK
BySY=.~
aCi]uG
wdr]]`
9dVEn#
t&N)8j
yz` $DT(
m^7xvK
\CGZ7G
r4|9Gh
6F$2&:
XOmmho
I,~zW~
tH"b4
."v@9d
Sg3wih
X8^C[$p
$2g.<4
\Lx /f
?J`W1^
wX&_rat
>e89Ui
}f4jb0
[hFIc
*mac6(w%7
XWv|~4
6'M+Fj
1u#pZ6
rtzC8A`
y-"1dr
`_2CP
@I8Pqp?
ZuP9J9
v~$81g
Jm:e.q
'h/19L
Iu].$M
Wos,F@
U=ozp>
e.a11QH
7MWjt7
]z2E4h$U
63y3a'
L4`cn%
KhPa)v
ZLLA|1
$S$E8e0Z
P*a(),
S$JqSIoiP
.J'ktu
0LO jFt
Ehl_Sp5](1
FHX%.%
e5ae3=R
D%Hj2do
,7Qs5A
T0YS@f
Bey!N
;P#I5L
W<<F("
[|!R|/
/H}I!!o?
FaSns(
%@:P~!
>4`VID
g,)JZ%/A
TaPNm8
.K.U%l
CuL!F>
qb@1:4
6E;9w@
x}}f[S
fWXxRF#
rO]@6L
H^Z?hg
^}/z1+ /\$~
0vOYxA
Fe& ,p
^UF5<Z
b",c&W
5CGOuMh0Rp:Z
Rjwffw2
g&HUlT8
RpOT8L
07tx9
Rv.vK&
q4):d[
#;SGpVkjZ
yUB6a
} M1AXE
lSpQ!:,U
%E,](8
cmqBvk
10+<v6
D1cKZ`8P
w4AZnH
e~oMR\
oe#cxn]
1?x~M8
m_mhtHl"
d[+-/a?K9
nO=pN<Kv
I5B|KF
01SqpZ
7hSn*a
,u#>yBo
`@iR[>
O='Co[
V"8>HG
L0]x_p
>|OR7h
.vF6*F
ow!BL LO|
U*0 +{
'0`#8a
N{i<4Uv
[[!k]C
/@sOrvnK
M.L<<{{
M2fsDc
JtPli"
5!ok,"
?(&GH5
Ha1)nH
|]gM5|
lHjM t
/D+}Pu<~
WYLikA
DvZTO+
5;>3RW
o,Z+BC
/)d~=
g.W&Yd
&Nw3@
6o~zm"y0~^
SQUs,'
T^I+&W
rMdt"tO
_>xU@x
URSWJ/0qIz
IhvYcR
X`zQ/"#[x
h1!sI)?k
nArYLgy
gn5TRaE+C;
vA- PE
gUyY<7
yE;tE=
&rVkq
c`M8>\
;Ra()o
S? ' 2*
W,0YaXD
HY |&"
`dQm+K$T
;0s]xG
`mCCz?a
,dyv{J
D"e0rw
0&}mZ_
SWb0T<
Antivirus Signature
Bkav W32.AIDetectMalware
Lionic Trojan.Win32.Zenpak.a!c
Elastic malicious (high confidence)
MicroWorld-eScan Trojan.Generic.34435803
FireEye Trojan.Generic.34435803
CAT-QuickHeal Trojandownloader.Fero
Skyhigh BehavesLike.Win32.Generic.wc
McAfee Clean
Malwarebytes Trojan.Dropper.SFX
Zillya Trojan.DuckTail.Win32.1
Sangfor Downloader.Win32.Kryptik.V8vv
K7AntiVirus Clean
BitDefender Trojan.Generic.34435803
K7GW Clean
Cybereason Clean
Arcabit Trojan.Generic.D20D72DB
BitDefenderTheta Gen:NN.ZedlaF.36608.@J8@aCZjzrei
VirIT Clean
Symantec ML.Attribute.HighConfidence
tehtris Clean
ESET-NOD32 a variant of Win32/Kryptik.HVND
APEX Malicious
Paloalto Clean
Cynet Malicious (score: 100)
Kaspersky Trojan-Downloader.Win32.Fero.cpp
Alibaba TrojanDownloader:Win32/Zenpak.17e75bd9
NANO-Antivirus Clean
ViRobot Clean
Tencent Win32.Trojan-Downloader.Fero.Adhl
TACHYON Clean
Sophos Mal/Generic-S
Baidu Clean
F-Secure Trojan.TR/AD.Fauppod.bcotg
DrWeb Clean
VIPRE Trojan.Generic.34435803
TrendMicro TROJ_GEN.R014C0DL723
Trapmine Clean
CMC Clean
Emsisoft Trojan.Generic.34435803 (B)
Ikarus Trojan.Win32.Zenpak
Jiangmin Trojan.MuddyRope.c
Webroot W32.Trojan.Zenpak
Varist W32/Kryptik.LCO.gen!Eldorado
Avira HEUR/AGEN.1368653
Antiy-AVL Trojan/Win32.Zenpak
Kingsoft Win32.Troj.Undef.a
Gridinsoft Ransom.Win32.Sabsik.oa!s1
Xcitium Malware@#2edey65kn8og7
Microsoft Trojan:Win32/Zenpak!pz
SUPERAntiSpyware Clean
ZoneAlarm Trojan-Downloader.Win32.Fero.cpp
GData Win32.Trojan.Agent.D3P86K
Google Detected
AhnLab-V3 Trojan/Win.Generic.R608689
Acronis Clean
ALYac Trojan.Generic.34435803
MAX malware (ai score=82)
DeepInstinct MALICIOUS
Cylance unsafe
Panda Trj/Chgt.AD
Zoner Clean
TrendMicro-HouseCall TROJ_GEN.R014C0DL723
Rising Trojan.Generic@AI.92 (RDML:9IIStJfXOyI51eA9fE8Z/A)
Yandex Clean
SentinelOne Static AI - Malicious SFX
MaxSecure Trojan.Malware.221262571.susgen
Fortinet W32/Kryptik.HUEI!tr
AVG Win32:BotX-gen [Trj]
Avast Win32:BotX-gen [Trj]
CrowdStrike win/malicious_confidence_100% (W)
No IRMA results available.