Static | ZeroBOX

PE Compile Time

2023-12-25 04:05:50

PE Imphash

903da1045a01db94c1ae4ff05ccbc0da

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
UPX0 0x00001000 0x000c0000 0x00000000 0.0
UPX1 0x000c1000 0x0004c000 0x0004b800 7.92938387455
.rsrc 0x0010d000 0x00049000 0x00048800 5.45358522464

Resources

Name Offset Size Language Sub-language File type
TEXTINCLUDE 0x000bfa28 0x00000151 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED empty
TEXTINCLUDE 0x000bfa28 0x00000151 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED empty
TEXTINCLUDE 0x000bfa28 0x00000151 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED empty
RT_CURSOR 0x000bff18 0x000000b4 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED empty
RT_CURSOR 0x000bff18 0x000000b4 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED empty
RT_CURSOR 0x000bff18 0x000000b4 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED empty
RT_CURSOR 0x000bff18 0x000000b4 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED empty
RT_BITMAP 0x000c1620 0x00000144 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_BITMAP 0x000c1620 0x00000144 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_BITMAP 0x000c1620 0x00000144 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_BITMAP 0x000c1620 0x00000144 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_BITMAP 0x000c1620 0x00000144 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_BITMAP 0x000c1620 0x00000144 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_BITMAP 0x000c1620 0x00000144 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_BITMAP 0x000c1620 0x00000144 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_BITMAP 0x000c1620 0x00000144 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_BITMAP 0x000c1620 0x00000144 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_BITMAP 0x000c1620 0x00000144 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_BITMAP 0x000c1620 0x00000144 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_BITMAP 0x000c1620 0x00000144 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_BITMAP 0x000c1620 0x00000144 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_ICON 0x00154d50 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x00154d50 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x00154d50 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x00154d50 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x00154d50 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x00154d50 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x00154d50 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x00154d50 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x00154d50 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_STRING 0x00109bc8 0x00000024 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_STRING 0x00109bc8 0x00000024 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_STRING 0x00109bc8 0x00000024 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_STRING 0x00109bc8 0x00000024 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_STRING 0x00109bc8 0x00000024 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_STRING 0x00109bc8 0x00000024 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_STRING 0x00109bc8 0x00000024 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_STRING 0x00109bc8 0x00000024 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_STRING 0x00109bc8 0x00000024 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_STRING 0x00109bc8 0x00000024 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_STRING 0x00109bc8 0x00000024 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_GROUP_CURSOR 0x00109c14 0x00000022 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_GROUP_CURSOR 0x00109c14 0x00000022 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_GROUP_CURSOR 0x00109c14 0x00000022 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_GROUP_ICON 0x00109cb4 0x00000014 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_GROUP_ICON 0x00109cb4 0x00000014 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_GROUP_ICON 0x00109cb4 0x00000014 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_MANIFEST 0x00155228 0x000001cd LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, ASCII text, with very long lines, with no line terminators

Imports

Library KERNEL32.DLL:
0x5554fc LoadLibraryA
0x555500 GetProcAddress
0x555504 VirtualProtect
0x555508 VirtualAlloc
0x55550c VirtualFree
0x555510 ExitProcess
Library ADVAPI32.dll:
0x555518 RegCloseKey
Library COMCTL32.dll:
0x555520 None
Library comdlg32.dll:
0x555528 ChooseColorA
Library GDI32.dll:
0x555530 PatBlt
Library ole32.dll:
0x555538 OleInitialize
Library OLEAUT32.dll:
0x555540 LoadTypeLib
Library SHELL32.dll:
0x555548 ShellExecuteA
Library USER32.dll:
0x555550 GetDC
Library WINMM.dll:
0x555558 waveOutOpen
Library WINSPOOL.DRV:
0x555560 ClosePrinter
Library WS2_32.dll:
0x555568 WSACleanup

!This program cannot be run in DOS mode.
uRFGHt
P6(.dh
X=!0,H
%co8FI
cQ(tS- ua
<$QtP
hg.@=hp
;[Tl&V
[gpe1D(_
,t8Eq_
_$#u/0p
QPVNEjF
XsJ{C*X
KyVP7E0<;
ft[tl}T
:[\0(,
048<f,@*(Dk.[
HLHPdTX
dLP+TX
t~lJHpD
U8&VKur,
>Lw$_PV
Fpd@pg@
Vj,`0<u
E=8*'T
;]<=>@
v08I*:!/
Pn_L$Gx`
|pW\R5a`d
,#(PWFH7
}d-,\2
^dCC]}
Cob`L3
bP5N[Z
TLDTLH
h{Mimb@
RUV@XW;B
pW*( $
T2 $J5
1xJRhLH^TQ
!>..*VT(
<. U!_@
n$nnb2
Pw"45`
!>@UQAFX
Fq1JHPp
`IN24=
9oTtcC
8<B|H
^SS<U
6VK29?tX
|y[4R
L4hUKQh
KJ<"[?*|Y
KHLPT=X9
0VRPSQ5
pt:XLd
$o;p%l
\LPTX*
&(,0\FF*48:<d
eNPTX\
\FF`bdhe
Rlp=tvF
'#wWt(/
Qe}(OA
".K3V@
;B.zH?
M<h?!;
`vIV#>-
8@b$tC
\@(m{Xm
GD8jX?
t2?$$:
@nEO]\
f&|3D8Z
WS<B'B
.PJ8&4eH
Ap._[a
PC@-`5g
*k\\%ba
Lud<>6N
vt*@Pu
TNW\(p
k1]|20
<ceiN<
_e_7A:`
CbZ(|Wcq
$(4JXaW
WVV?@,
xX@t~\#
*bN=.iI
UKPN3`&
CLTxdt
!M,${G
RL>~,RVh
SEph+q
Wa8h0H
!#h 9V
bNP;pT
$xKxJ}
NF/oKVQ
V`|sc|
"R{Oj<
8 |2l3
x"6Nlj
.WU$0H
sp 90t
JCcdTb
?TkQRK
B;<b)<a)
B."V=h
Tr9aPh
GLdOYV
.HtKBLY'
{X:|%}
Yh l+m&
+uHlz@XM
u'-'k!
Cj[SYj
"yefpm
=ek#PW
{@eH<_
PK+[:!q
E&im=9
=MS:<H
lGwmPbD8
5x\UWSS@
`QPW t
|i#!ZF
VWg_c@U
<(<8(SJ
(ARop+
o,Ddh+
-k(*-D)
G!RJp.'
)H9RtnSH
=#'088
cynR'3
/_t3b/q
UU)$qC
|?.RH!
Qix002#
bFJj*~
][-^]G
#C?58Q1!&
t|6x4
ohnzqA
tU~=uM
yOCj;C
Jg%+D(
3DP;g8
\Kx_o,
?|`:pf
5KRad)
HtP`=*
NXo=lh
:Vp;-,
t&V0r!
_t(L/t"
SR~'PH
K0(4br
XdQUHw@rb
P\hY{<
Tt3 >^
NXA8jH
sy./01'
@u!k+j3
l=tf*sH
ZNJU$+D
0r\tFF#-
`u!oHb
;\I4Ouf
z'9A`1
E &V,w
z>ugXHC4
>PzE]6
yN<V)<J
:V5dv"
wVl@8[
xu5j)~
HSvQRU
hE3p7.
@C[C?:#
tr7LU#
E]ugDz
g#O$2d
W(@gVr
B,VZ,-
@ H(+G
Y`.|X^
4P%Xcb
kRP4P9
k+gEuUR
,Z@(l51p
.Be$>;
n<DwR<
E*9VpCSEu
d%a%8"2
r-TWYK
qH H}b
/.0f9X
b=QWx@d
B_G@;H
{zROQl
cC[<+O
skCKDi
hVptbp
8MTfC+1Z-
^Luo3!
B gHD
fnh9V8<
HwU~wS'
Wjcq.@
EjpWr@
aP#c]h
vT`?Pp
C(]49_@
rr*z @
:<3HUp
_"V8V+
NloC8x
92-T(
SZJBBP6
q-/g2Wr%
10/%Wr%.-r%Wr,+*Wr%W)('%Wr%&%
/e%j*x_
WTtYFMD
t2HS(<
FCI!A]
:Ae;yoE$W
'iR$$(
(00448
iO\_RT
,<QU/<
;@E(4
#]Rr( X^Q
|D|DdH
Hy,%f_4
h~HlhVRBF
=@jXSj8;
QSGR-x
$r%$dG
PR}G*%
[!99bU
H=6<1f{
|RLLp!U
m#\-8#]XSUI84
`B(@t
}Vf_I+
KS +@[
"rC2!Xj
Dt1TMz
[qei#.
P3+&!a
$>BzF.Ptm|t
svLPbok
tY Q%2
+y*LQ
kDiINR
ssss&tP(tK$tF#tA
qss!t<"t7Cu
$V`b@.
OB\@{|
iO9,HNO
i0D_ J
"/8\1W
70]w@A]_
$xXKo U
0]S%vhR
@3^$w.@
V)W$6FX
XP8Hh_!
1L,fyT
fQYHLQV}
BfYzl"
U, P^Ji
Vjl=!}
(#"9J
4(tjhM
}#J<~#
VUPp'
chIKbg,
.9/Nq<
E8> If
$*"DX$
R R"|?
Ao/fR3
KkrN*Q5
Vj0^|^
GZtPH
$KgBjI
%uTY02%
Kg:9PV
<P-emmnRh
+Mg[[U
;C=,mX
^6K=l0
a,rnI*PT=M
h'ZAh|{
glL"Ui\
F_U@rT
($i}k@
l_u;mw
~4:t^g
UVuzYNk
NyZev(~
AOkOcW
bl[YH5
F/XuA
.D<VjA
"B,q_Q
vZ<?<j
X:PBi@.HDap
}&5e8A
,^]^V"
r$^]!Sr
|BIQhT
`7D-@B
%[+R*TA
/.B8Zb}
`h^WP2T
WQ}l2g
M]}v#&
]R0hacPN
XzWR[.
<'L\\A:
2!`0XA
MXT3SU
W5DO"
YWUQH*
!>Ksvg
'I-Yf4
H\qyc(
~^|a^x1
QW049=
U !(!
:v47jL
R~0=YQ
{QR(f(
U(`>#&
H2d\mS
s\`Y=4
(p c`&1
$#c@.(@_\:
0?8018%6
XvT2RiA"
9AqSsy
9j=R<u
b[a];!-M/
vt/Ybu
VRu(p&x
^te~+s
H- WZ
RO:tOvC
.+`Eg,i
{L4(Q#,
azv=c\
'=pscatj
YARGtD= BG
vO|h_UPG
%lcmnw
-=knilt
=rtnmto
.d#E#n
`abc_2*
}E`v)|[
h OCT
|4<Yr&
TADIut
ETLPuCxx
A.DNE`
,MRHc/
sFFo/r
#UA)6_
[4L"1|K#
/MlLtF
hpOfHX
a0 7t;/
L0)=;2
aT3{V=
/ioQ/u\
*NWmT-P
vwus3_
J}&M>Q
HDgQp
qQyq&v
l+XJ:p
t,$Q DM
`1fmA"
sP:uPn
R88MJ#pi
:!k+Hv
4/SGhP
d\`X.y
PwafpHC
}MT((@
K!2 PT
%hZy+XXS`
\XpQ~RW
b^l-E(
#WM_^;
*6 D#(}
@GqW'T
_)auAm?
pD(p/D
@@N[*J
(g<Epx
@N027
P@hYVSSz"
8$`1?L
&T`CJ+)
&v\68%
VAh$WQ
ja_@4<
J@D]@D}
ait B$:/ x
kHT)PL
`(dPP?F
SDh@J
0zlIj"
kevkH`teDaq
_i j0^
Z39$F&H
CMN3Dk$
8tfL@
;Hd/& tLhP
+aZsKQU'hW@
Su!h0X
RIV\21^US1S
ODHM*M
u>]&N2
%yPYWy
'|+S]m
v*[DZ&
FrJ&f
L`63)R
!UeICG
gy6L:K
J)4264
@\oW\u
6F=n2!
]8tY0uT
)qlwR/
q+t-T<%
^7h$]y
70!|6C
u-&PeGr
E86NNM
Wm[[v6Y
NZZQu,>
EC2E'C)
uFS]
7pn>dK
B,e-G.
8"PAt
[=Xfs>
3 p7!vfb+6D
!VAD[^
%G,2%"
L *>da
`j:]"{
LQAmP x
HtHHuzH
V3=95:
mta56uheu
I~/U,H
V] *6P
BBNNLL
J1UD|'
&]4(U;
sJP5J1
z~,jPi
@>QUgO#
%/X,^^q
R9yn3^
O0z(~W8
GWR,48q
'po2l00%
)D"bBI{
,X(A!l
i+ t:s
rK$DVQKr
B,H<,
1xH*Nh
A<=V&R)F@
BB0}nQ
VdF<fn.
cw=ijip
0uw$sxO
p({>9WJ
z4PUjSl
LaCwLJT
J5T(zH
WDKwI7J4
+;VH}I
e|4LuV4>N0
7X% r1
^L46`6
T(QQ,Jr
%aMulv.
YZ[\8X
#pC*^L
`@y,Zy
yAKwMy
$:+x?4V
6/q|,A
PUW8CS
p`U qP
s`1c-
EY(VB'
l:*yx(
AKvpmu
4:A!)8
Zl0$f
Gtm7Qp
p.6Pjx
IY\p,Mh"J
F.{ J,C{
WhdoIi
9LeMYC
^ltfNp
_0pE?S
n^J<Tu
ExHR;@(
gw@j@$
uoC8P1*4@
H/9%4tZ
4DoB8"
C'x) 1
d+[\"B%
T+3x%A
>4Rchp
f 17UG?
Y_JOK`
$fi@Y'
7ml7:B7
J$XDp
e%`'HL
hPE>3jjk
Sy*O,@ 0$
h_A{i(
W5k6ivh4
;uAa;B
7Yt3f8
Zt_hl!
NW?^#7-
-OlCW*s0$
'X)mi!
E0a4'^
0bY~Ow)
P;4tFP
5X$^]Wpv
<<DLTg\
\-i*R/
pC`;5@
3je_NY
uBS)}(
2 lHt.*
B 02CV
~jlRIu
><~&WP
~:@Y'ST1
qX#1!a
9(HWt!kSi
/Fc0l%$
J/bxoB0
Qx'DM@S
8t9UWU
86*>R@D
#8UP$Jt
L(GjD&:Dib
5PI$4f
C20XC00
]z3x<JS
te6,Fa2E
ijeu`6
'+Hw.#
B]}T#uS
Cea(!|
6Cj#| <W
tUj=}{0~
4+N=OL
*KA,gsJ
\tURX@
W@KC_-
;V{oSQ
*" uuJ
%of9p`t|sBXe
|ZV+z2
j?ZuQP!*;
esSzq@
QSuAsC
4MYKYY\
FKl\3H
.I[}+H
RH0,>x
lx*|AZ
w+Bv'Ws
;*gu>(
ZpjD4Z
|)QFQI
8k"Y)S
rnr'Ca
L~(EknZ
"Xhjllwt
W&!V\5,
;'h:ML
t_G<j$=
DzuO,A
nP8RuMd
FEwO2$$
72gL,W
nrZ`,x
QCQ!tj[
XE&#RY
<4W6Xp?
C}_u@W
*!@n"<
-t,0tR
+(\H2?
*aHXeB.
0#M\t>
0hR(Ga
J|?.u!
78"lWW
hX/kH < ^
/eF\N+
$.Flty
X->?~QkI
D(6^ViH
`^@w4s
D'1u80
m1P8Bm
l(_rA+
X<Qf)U0|u
]|H%)1
-x}GTPu
h.0$2b
KX;&8\2
{IELNt
$Fp[t!>
f/e7uWqvT
I@r>|$`
!ryI0S2
>@D,u+oi'
xP?m' 8
OSh/YG
<[Sl\u
% uCPQ
AkW5TE,
[T7PXp
Pf,lD hx
!\:,*p:a
*@[#A,~Pu"
Z`Pd#kHk
L*d~"*R
uw(4"70
wZ4>(r-
<x4$lS
4I`THV
AGGWG(j
0%Nt,8
thAMb(-D.C
H #xjCi
Q-VwPAP7
OY`.mG
i^mx'}
+6KYby
:dkA2I6?V
iAr,&@
eL@N"j
HK'u?(cm
U17?CX
sBg97_
9h"K,#
t ,zVh
Jgo'44hH
ZH3!H/
p:lXo2
uD>p)|
FS#2FK
$3F{LV
t2WP/t
X tnjQ
Oqd]{2
v[H'wLl
w%tj
C.kwFt
yZwltva
Wdm8p2
5s] LR
YaCt?W>
jfXVhQjc
! Xj7Hr
j @"U-]
V@D}5K
F<A|2<Z
d`2@{:z
X6R:5J
OBX-tK
V u 5u&/Hp
"H,zb}
$NhPy5
h,d:p;
gK@}J5F#
h58I'{
t!iAYc
P ,-)!u
<Pt|XI
7_dN>,J
T_h?O'
B_P,*N
_* LEx
v(?Pxm
YH-%\
k+y Z?P
8K-@^ #C
T8"a;,
eNt<h
dAA,Xp
)y qHpQ
H+7OK3
8'`w'
w'dJ^I
8ER_p}
Kernel32.dll
VirtualA
oduleHan
LoadLibrary
eateTh
dUPrdAdd
ewOfFir
3xIHM`_;9
WplP7Fd
09f2340818511d396f6aaf844c7e
48E769
B6E92C2
1"15B0
;Fpb@o
@oZ_e_
EditBox
Button
pcrollBarP`
7Nzy.txt
MZcjjffe
N@9PE#6l
C:\Us>s\Public\Vi
This p
gram cann}
ot be run i
DOS mo
dataox$z
dbgG_'$01
fL*g[>
f<OSig
*dEp d
#J>`eB ^
+y^a^ag
wN^NO.O<W
\PPUUO
C()(@N
4i5U6B738%9
#C0D?EQ
E=FZGrH
QyReSOT
qdZRMHD@=;86421/.-+*)(''&%
""!! 
|?5^<@
_@TJQ1
56789ABCDEF'%
Qkkbal
!1AQaq
"2BRbr
#3CScs
$4DTdt
%5EUeu
&6FVfv
'7GWgw
(8HXhx
)9IYiy
+;K[k{
,<L\l|
-=M]m}
.>N^n~
/?O_o
HohISTyH7
pCALHYs#
3 Copyright
8 Jean-loup Gailly%
y1892+
%,3:;4<
<-&'.
5<=6/X
18&@P`!
?u='@^
(o%*.*f
$CNotSupporte{
dExcepti@_MemV
pGdiObject
rusr9D
GQpOClie
MS Sans
h6l Dlgc
!AfxOldh
'MDIF*e#m
orInfoA
numDis
play/L
omPoi;b`
USER3o
VSPLAY
c^m|rl_D
%{8<L;.
DLL7*B>O
boi`ObsY
DStat
6ring
N})?6A
b|Prev
DWordm
bolTip
s_class
.INI.HLP
ifNsoftw\RT
swo_OG?
__GLOBAL_HE
ELECTED
.MSVCRT
nXNOMA$#R6028
h spacFf
\5p&Vv
5OfJcG c
d4cW!0
ChBck_/
pV`\W8
5c`uQs
[UC++ RA
JX@@(Yk
t@KERN
\9_hyPt
ld?<f?f
Njuc)X
pip<TP
Gt!guch
1#QNAN
('^#a
w;9\gOr
0OPo1C`
9P8OwxGN
?V=ip'a
`ExEr*9%
pxP_]
PI#Sjw
(!3"><
<#I$T%
\r@``sr
$/:
0$(U@U9
oh??28C@
3%G^HV`V
'^^^~?
((-(^^^^;(I(W(e(^^^^s(
]P)X)G
&.8cX*12..
#G^! 0(03m
0>0L0Z
R@}No\
@_bWpr
9HN$G8
z0zHSi
R`,:?1
Advapi
msctls_up8
%+BUTTON
FAULT_ICz
WG!2S(
Fa"Bff
bcdfghijklmnpq
rstuvwxyz
ceoohjmnp
(&07-034/)7
hgjlkb4
rfzaoe
r25(v6
9B.'&.
r+/'@N
[yN25F
^37r8Qbj2
A$jr:R(
bjzsC`b
aOGGZ!6*
&z6(6U
lBJ"25
j!rJ#&nY3
rxqjh<
nkC7|2I-e
xph`XPy
yH@80(
<xph`X
<DEFGH
NOPQRS<
<TUVWX]u
{k[dFrrr
YXWrrrrVUTSrrrrRQPOrrrrNMLKrrrrJIHGrrrrFEDC
sePNBMPGIFw
CUR)|I|
s:%dgS
G?! p
;q: ?o
c(: bd}
@Vue V9
^ddZAb:apW=5q
DEL=kWkrk
/hOWCI
?IDATnf$
Eh.dE^
GZW%8]P
NULLOD.\!
ir_IMAGE_VERSION
-,p]:z{
(BAD Q
LphaKO+
1G8wxG
\]^_`a
bnASCII$ncAX
h'tRNS
P ]K;Pzs/'
F+I+k+
B)P%ld%
JPEGME
s>R/p
+tr;994
l'''',
#r''''2
b''''"
Cz'''':
j''''*
3rrrrv6
rrrrf&
cvrrr~>
m9999-
w7rr!'
g'rrrr
?_AFX_
D_STAE
oHECKLh)0
4q?=MODULE
/!5An
CPgR/S
!g*4"h
%Lo&;.
0K:seM
O1uP2Q
xl`X^Ly
yHD@<8
xDy4z$?
pdTDi>
Ixx@o
:_>:OF
|"afx0&"
_RESOURC
LGOLE=}
@TRACK
BTYGJif !Sd(
|| 9TARG
LANGU\
e(936k4
l.chs\S
^\_x;
[ZHr,gJw
eQGtepe
"kXZvf
ez<PsG"
;2C6&T*nxG
w/@rsQT
;&lx
PAttribute
]\,balUn
rcpynA}i
BytBWideC
edDecx
d[IsBa
QTy&A
eHed0d
vsW/,#_
Siz8TE3
.Fq8<f
pSAOEM
`Bkk1/Rgn
/S*id8%
1">u32
Offs)M
"mg#(
uF2+0h
IlvnA&
?BtmC
=DL.>u
pGkAdj`L
FYP Jf
s5&V4&pwwF
] evs%Y
XPTPSW












2%
%2
22
fCCCCCCCCa
22
2%
tCCCCCCCCBBBBf
%2
MCCCCCCCBBBBBBBI
888=2%
BCCCCCCCB88888888B
%%28888
<888,%W
ICCCCCCB88222,22222I
W%,I88<
C8B22%
BCCCCCB882,%%%%%2222
%28B8C
CCI82%
8BCCCC8882%
%28ICC
CCI82X
8BCCCB882,%
X28ICC
[8BCCC882,%
28IICB882%%
2=IMMMI82,%%5
%%%%%%
66IIMMII662o
66II^^^KII
5XKKaffaf
WX\bcnf
xMM_MM
MR_MMM
xxvur____qqqqqqqqqqRMq_MM
RR__Q^
xvvu_____qqqqqqqqRR__RR
RR___a
xvuu___qqqqqqqqqRR_RRR
RRqr__f
xvur___qqqqqqqRRR_RRR
RR__rrr
vur___qqqqqqqqR__RRR
RR__urvx
xvr____qqqRRRRqrRRRR
qq__uvvx
zvur___qqqqqqq__RRRR
Rq__rvv{
xvr___qqqRRR__RRRRR
R___rv{
xsr____RRRR_r_RRRRR
q___ruy
xvr____qqqq__qqqqqq
____ruy
xvr_______r_qqqqqqq
____ruv{
xvr______r_________
____ruvy
vvrr____r__________
____rryy
yvur___rr___________
_____ruyy
yvrrrru_____________
_____rrvy
yvvvvrr______________
_____rruvy
yyvur________________
_____rryyy{
yyyrrr________________
z77777$/
Q7777$$$$w
Q7777$$$"
$7777$$"
$$7777$$
$$7777$$$
$/6<<<6T
///<<<}
qkkhhfffffHFYF
qhfYYHHHHHHHYF
kfYYHHHHHFYYF
qkfYYHHHHHfFF
HHYhkq
kfYYYHHHYYHH
kfYYYHHYYHHH
khYYYYYfHHHH
nfYYYYfYYYYY
YYYfht
nfYYfYYYYYYY
YYYfhn
tkffhYYYYYYYY
YYYYfnn
tkkfYYYYYYYYY
YYYYennu
unkfYYYYYYYYYY
E_ikcS
^rrherrg'
GpO;dv,""
Xvvvvvv7)("`xK
O[[[[[[[".")Rxg;A7)"""$"..$3.ezjVK=..%%%..%.3AmzzjH..%%..%..3CMamTC..........>JQQJ>.333...>...6>C>>66....=
<?xml version="1.0" encoding="UTF-8" standalone="yes"?><assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0"><assemblyIdentity name="E.App" processorArchitecture="x86" version="5.2.0.0" type="win32"/><dependency><dependentAssembly><assemblyIdentity type="win32" name="Microsoft.Windows.Common-Controls" version="6.0.0.0" processorArchitecture="x86" publicKeyToken="6595b64144ccf1df" language="*" /></dependentAssembly></dependency></assembly>
KERNEL32.DLL
ADVAPI32.dll
COMCTL32.dll
comdlg32.dll
GDI32.dll
ole32.dll
OLEAUT32.dll
SHELL32.dll
USER32.dll
WINMM.dll
WINSPOOL.DRV
WS2_32.dll
LoadLibraryA
GetProcAddress
VirtualProtect
VirtualAlloc
VirtualFree
ExitProcess
RegCloseKey
ChooseColorA
PatBlt
OleInitialize
ShellExecuteA
waveOutOpen
ClosePrinter
TEXTINCLUDE
DEFAULT_ICON
Antivirus Signature
Bkav W32.AIDetectMalware
Lionic Trojan.Multi.Generic.lt2b
tehtris Clean
ClamAV Clean
CMC Clean
CAT-QuickHeal Trojan.Multi
Skyhigh BehavesLike.Win32.Generic.hc
ALYac Trojan.GenericKD.70985321
Cylance unsafe
Zillya Clean
Sangfor Trojan.Win32.Save.a
K7AntiVirus Trojan ( 005246d51 )
Alibaba Clean
K7GW Trojan ( 005246d51 )
Cybereason malicious.da4c4a
Baidu Clean
VirIT Clean
Paloalto Clean
Symantec ML.Attribute.HighConfidence
Elastic malicious (moderate confidence)
ESET-NOD32 a variant of Win32/TrojanDownloader.FlyStudio.ED
APEX Malicious
Avast Win32:Malware-gen
Cynet Malicious (score: 100)
Kaspersky UDS:DangerousObject.Multi.Generic
BitDefender Trojan.GenericKD.70985321
NANO-Antivirus Trojan.Win32.Wsgame.kgcopq
ViRobot Clean
MicroWorld-eScan Trojan.GenericKD.70985321
Tencent Clean
TACHYON Clean
Sophos Mal/Generic-S
F-Secure Clean
DrWeb Trojan.PWS.Wsgame.57578
VIPRE Trojan.GenericKD.70985321
TrendMicro TROJ_GEN.R002C0GA124
Trapmine malicious.high.ml.score
FireEye Trojan.GenericKD.70985321
Emsisoft Application.Generic (A)
SentinelOne Static AI - Malicious PE
GData Win32.Trojan.PSE.192BHS8
Jiangmin Clean
Webroot Clean
Varist W32/Trojan.CLL.gen!Eldorado
Avira Clean
Antiy-AVL Trojan[Packed]/Win32.FlyStudio
Kingsoft Clean
Gridinsoft Ransom.Win32.Wacatac.sa
Xcitium Clean
Arcabit Trojan.Generic.D43B2669
SUPERAntiSpyware Clean
ZoneAlarm UDS:DangerousObject.Multi.Generic
Microsoft Trojan:Win32/Caynamer.A!ml
Google Detected
AhnLab-V3 Clean
Acronis Clean
McAfee Artemis!85215C82405B
MAX malware (ai score=85)
VBA32 BScope.Trojan.Emotet
Malwarebytes MachineLearning/Anomalous.94%
Panda Trj/Chgt.AD
Zoner Clean
TrendMicro-HouseCall TROJ_GEN.R002C0GA124
Rising Downloader.FlyStudio!8.5E9 (CLOUD)
Yandex Trojan.GenAsa!ZU78ump4sm8
Ikarus Trojan.Win32.QQWare
MaxSecure Trojan.Malware.300983.susgen
Fortinet W32/CoinMiner.PHP!tr
BitDefenderTheta Gen:NN.ZexaF.36608.LmGfayJZNvab
AVG Win32:Malware-gen
DeepInstinct MALICIOUS
CrowdStrike win/malicious_confidence_100% (W)
No IRMA results available.