Static | ZeroBOX

PE Compile Time

2024-02-27 17:36:19

PDB Path

C:\Users\Administrator\Documents\Work\DemProject\Output\Loader\Release\Loader_Release_Win32.pdb

PE Imphash

fd3e67a72fcdc11dae1668a9ef71cd6e

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x0002452b 0x00024600 6.65060685259
.rdata 0x00026000 0x00009a90 0x00009c00 4.82076854664
.data 0x00030000 0x00003f0c 0x00001c00 3.70456190804
.rsrc 0x00034000 0x000171d8 0x00017200 4.0284005411
.reloc 0x0004c000 0x00001fd8 0x00002000 6.59739264972

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x0004a9a0 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x0004a9a0 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x0004a9a0 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x0004a9a0 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x0004a9a0 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x0004a9a0 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x0004a9a0 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x0004a9a0 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x0004a9a0 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x0004a9a0 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x0004a9a0 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x0004a9a0 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x0004a9a0 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x0004a9a0 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x0004a9a0 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x0004a9a0 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x0004a9a0 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x0004a9a0 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_MENU 0x0004ae90 0x0000004a LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_DIALOG 0x0004aef0 0x0000012c LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_STRING 0x0004b020 0x00000038 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_ACCELERATOR 0x0004aee0 0x00000010 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_GROUP_ICON 0x0004ae08 0x00000084 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_GROUP_ICON 0x0004ae08 0x00000084 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_MANIFEST 0x0004b058 0x0000017d LANG_ENGLISH SUBLANG_ENGLISH_US XML 1.0 document text

Imports

Library KERNEL32.dll:
0x426000 Sleep
0x426004 WaitForSingleObject
0x426008 TerminateThread
0x42600c CreateDirectoryA
0x426010 CloseHandle
0x426014 CreateThread
0x426018 CreateFileA
0x42601c GetCurrentProcess
0x426020 WriteFile
0x426024 OpenProcess
0x426028 GetFileAttributesA
0x42602c CreateProcessA
0x426030 TerminateProcess
0x426034 MultiByteToWideChar
0x42603c GetLastError
0x426040 Process32FirstW
0x426044 IsWow64Process
0x426048 Process32NextW
0x42604c CreateMutexA
0x426054 DeleteFileA
0x426058 SetEndOfFile
0x42605c CreateFileW
0x426060 ReadConsoleW
0x426064 ReadFile
0x426068 WriteConsoleW
0x42606c FlushFileBuffers
0x426070 SetStdHandle
0x426078 EnumSystemLocalesW
0x42607c GetUserDefaultLCID
0x426080 IsValidLocale
0x426084 GetLocaleInfoW
0x426088 LCMapStringW
0x42608c CompareStringW
0x426090 OutputDebugStringW
0x426094 LoadLibraryExW
0x426098 SetFilePointerEx
0x42609c GetConsoleMode
0x4260a0 GetConsoleCP
0x4260a4 GetStringTypeW
0x4260b4 HeapFree
0x4260b8 HeapAlloc
0x4260bc IsDebuggerPresent
0x4260c4 HeapReAlloc
0x4260c8 EncodePointer
0x4260cc DecodePointer
0x4260d0 GetCommandLineW
0x4260d4 GetProcessHeap
0x4260e0 RaiseException
0x4260e4 IsValidCodePage
0x4260e8 GetACP
0x4260ec GetOEMCP
0x4260f0 GetCPInfo
0x4260f4 SetLastError
0x4260f8 GetCurrentThreadId
0x4260fc ExitProcess
0x426100 GetModuleHandleExW
0x426104 GetProcAddress
0x426108 AreFileApisANSI
0x42610c WideCharToMultiByte
0x426110 GetStdHandle
0x426114 GetModuleFileNameW
0x426124 TlsAlloc
0x426128 TlsGetValue
0x42612c TlsSetValue
0x426130 TlsFree
0x426134 GetStartupInfoW
0x426138 GetModuleHandleW
0x426140 HeapSize
0x426144 RtlUnwind
0x426148 GetFileType
0x426150 GetCurrentProcessId
Library USER32.dll:
0x426158 SendMessageW
0x42615c DispatchMessageW
0x426160 DefWindowProcW
0x426164 CreateWindowExW
0x426168 LoadStringW
0x42616c LoadIconW
0x426170 RegisterClassExW
0x426174 LoadAcceleratorsW
0x426178 TranslateMessage
0x42617c EndPaint
0x426180 DestroyWindow
0x426188 GetMessageW
0x42618c PostQuitMessage
0x426190 LoadCursorW
0x426194 BeginPaint
Library WS2_32.dll:
0x42619c gethostbyname
0x4261a0 closesocket
0x4261a4 socket
0x4261a8 recv
0x4261ac WSACleanup
0x4261b0 htons
0x4261b4 WSAStartup
0x4261b8 connect
0x4261bc send

Exports

Ordinal Address Name
1 0x403950 _cJSON_AddArrayToObject@8
2 0x4035f0 _cJSON_AddBoolToObject@12
3 0x403540 _cJSON_AddFalseToObject@8
4 0x4032f0 _cJSON_AddItemReferenceToArray@8
5 0x403350 _cJSON_AddItemReferenceToObject@12
6 0x4031c0 _cJSON_AddItemToArray@8
7 0x403210 _cJSON_AddItemToObject@12
8 0x403280 _cJSON_AddItemToObjectCS@12
9 0x4033e0 _cJSON_AddNullToObject@8
10 0x4036a0 _cJSON_AddNumberToObject@16
11 0x4038a0 _cJSON_AddObjectToObject@8
12 0x403810 _cJSON_AddRawToObject@12
13 0x403780 _cJSON_AddStringToObject@12
14 0x403490 _cJSON_AddTrueToObject@8
15 0x4049d0 _cJSON_Compare@12
16 0x404130 _cJSON_CreateArray@0
17 0x404060 _cJSON_CreateArrayReference@4
18 0x403e90 _cJSON_CreateBool@4
19 0x4043f0 _cJSON_CreateDoubleArray@8
20 0x403e60 _cJSON_CreateFalse@0
21 0x4042c0 _cJSON_CreateFloatArray@8
22 0x404190 _cJSON_CreateIntArray@8
23 0x403e00 _cJSON_CreateNull@0
24 0x403ed0 _cJSON_CreateNumber@8
25 0x404160 _cJSON_CreateObject@0
26 0x404020 _cJSON_CreateObjectReference@4
27 0x4040a0 _cJSON_CreateRaw@4
28 0x403f50 _cJSON_CreateString@4
29 0x404520 _cJSON_CreateStringArray@8
30 0x403fe0 _cJSON_CreateStringReference@4
31 0x403e30 _cJSON_CreateTrue@0
32 0x401550 _cJSON_Delete@4
33 0x403ac0 _cJSON_DeleteItemFromArray@8
34 0x403b60 _cJSON_DeleteItemFromObject@8
35 0x403b90 _cJSON_DeleteItemFromObjectCaseSensitive@8
36 0x403a70 _cJSON_DetachItemFromArray@8
37 0x403b20 _cJSON_DetachItemFromObject@8
38 0x403b40 _cJSON_DetachItemFromObjectCaseSensitive@8
39 0x403a00 _cJSON_DetachItemViaPointer@8
40 0x4045d0 _cJSON_Duplicate@8
41 0x402f50 _cJSON_GetArrayItem@8
42 0x402f20 _cJSON_GetArraySize@4
43 0x4013b0 _cJSON_GetErrorPtr@0
44 0x4013f0 _cJSON_GetNumberValue@4
45 0x4030b0 _cJSON_GetObjectItem@8
46 0x4030d0 _cJSON_GetObjectItemCaseSensitive@8
47 0x4013c0 _cJSON_GetStringValue@4
48 0x4030f0 _cJSON_HasObjectItem@8
49 0x4014c0 _cJSON_InitHooks@4
50 0x403bc0 _cJSON_InsertItemInArray@12
51 0x404970 _cJSON_IsArray@4
52 0x4048f0 _cJSON_IsBool@4
53 0x4048b0 _cJSON_IsFalse@4
54 0x404890 _cJSON_IsInvalid@4
55 0x404910 _cJSON_IsNull@4
56 0x404930 _cJSON_IsNumber@4
57 0x404990 _cJSON_IsObject@4
58 0x4049b0 _cJSON_IsRaw@4
59 0x404950 _cJSON_IsString@4
60 0x4048d0 _cJSON_IsTrue@4
61 0x404740 _cJSON_Minify@4
62 0x4022e0 _cJSON_Parse@4
63 0x402310 _cJSON_ParseWithLength@8
64 0x402160 _cJSON_ParseWithLengthOpts@16
65 0x402120 _cJSON_ParseWithOpts@12
66 0x402450 _cJSON_Print@4
67 0x402490 _cJSON_PrintBuffered@12
68 0x402570 _cJSON_PrintPreallocated@16
69 0x402470 _cJSON_PrintUnformatted@4
70 0x403cd0 _cJSON_ReplaceItemInArray@12
71 0x403dc0 _cJSON_ReplaceItemInObject@12
72 0x403de0 _cJSON_ReplaceItemInObjectCaseSensitive@12
73 0x403c40 _cJSON_ReplaceItemViaPointer@12
74 0x401740 _cJSON_SetNumberHelper@12
75 0x4017a0 _cJSON_SetValuestring@8
76 0x401420 _cJSON_Version@0
77 0x404cd0 _cJSON_free@4
78 0x404cb0 _cJSON_malloc@4
!This program cannot be run in DOS mode.
:Rich:
`.rdata
@.data
@.reloc
D$ SVWj
jdh`-C
tw9usj
D$@SVW
CD$8QP
D$ j@P
D$ j@P
D$$j@P
D$$j@P
D$8jlP
D$8jlP
D$`SVW
D$ ;D$(u
CD$@VWR
D$$RPW
D$HSVW
D$$RPS
tb9u^j
SVWjA_jZ+
uBjAYjZ+
PPPPPPPP
HHtVHHt
PVVVVQ
~pjCXf
<itx<o
uChT/A
YYh0bB
PP9E u
tyPVj@W
_tcPVj@
u#j,Xf;
>Cu/f9F
bWWWWj
<at-<rt"<wt
URPQQh
j@j _W
QQSVWh
j"_f9y
HHtVHHt
+tHHt
+t"HHt
HAO8t
<0|m<9
G Pj*S
G$Pj+S
G(Pj,S
G,Pj-S
G0Pj.S
G4Pj/S
G8PjDS
G<PjES
G@PjFS
GDPjGS
GHPjHS
GLPjIS
GPPjJS
GTPjKS
GXPjLS
G\PjMS
G`PjNS
GdPjOS
GhPj8S
GlPj9S
GpPj:S
GtPj;S
GxPj<S
G|Pj=S
,SVWj0X
Wj0XPV
~';_t|%3
jA[jZZ+
Yu2Vj@h
;t$,v-
UQPXY]Y[
t WW9}
PWWWWV
PSSSSV
SVjA[jZ^+
jAZjZ^
tHHt*Ht#
Ht+Ht$Ht
HtHHt
uHjAXf;
tG9uCj
QQSVWd
HtHu4j
RVSQSWV
bad allocation
Unknown exception
(null)
`h````
xpxxxx
Sunday
Monday
Tuesday
Wednesday
Thursday
Friday
Saturday
January
February
August
September
October
November
December
MM/dd/yy
dddd, MMMM dd, yyyy
HH:mm:ss
CorExitProcess
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
FlsAlloc
FlsFree
FlsGetValue
FlsSetValue
InitializeCriticalSectionEx
CreateEventExW
CreateSemaphoreExW
SetThreadStackGuarantee
CreateThreadpoolTimer
SetThreadpoolTimer
WaitForThreadpoolTimerCallbacks
CloseThreadpoolTimer
CreateThreadpoolWait
SetThreadpoolWait
CloseThreadpoolWait
FlushProcessWriteBuffers
FreeLibraryWhenCallbackReturns
GetCurrentProcessorNumber
GetLogicalProcessorInformation
CreateSymbolicLinkW
SetDefaultDllDirectories
EnumSystemLocalesEx
CompareStringEx
GetDateFormatEx
GetLocaleInfoEx
GetTimeFormatEx
GetUserDefaultLocaleName
IsValidLocaleName
LCMapStringEx
GetCurrentPackageId
GetTickCount64
GetFileInformationByHandleExW
SetFileInformationByHandleW
UTF-16LE
UNICODE
_hypot
_nextafter
`h`hhh
xppwpp
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
MessageBoxW
GetActiveWindow
GetLastActivePopup
GetUserObjectInformationW
GetProcessWindowStation
__based(
__cdecl
__pascal
__stdcall
__thiscall
__fastcall
__vectorcall
__clrcall
__eabi
__ptr64
__restrict
__unaligned
restrict(
delete
operator
`vftable'
`vbtable'
`vcall'
`typeof'
`local static guard'
`string'
`vbase destructor'
`vector deleting destructor'
`default constructor closure'
`scalar deleting destructor'
`vector constructor iterator'
`vector destructor iterator'
`vector vbase constructor iterator'
`virtual displacement map'
`eh vector constructor iterator'
`eh vector destructor iterator'
`eh vector vbase constructor iterator'
`copy constructor closure'
`udt returning'
`local vftable'
`local vftable constructor closure'
new[]
delete[]
`omni callsig'
`placement delete closure'
`placement delete[] closure'
`managed vector constructor iterator'
`managed vector destructor iterator'
`eh vector copy constructor iterator'
`eh vector vbase copy constructor iterator'
`dynamic initializer for '
`dynamic atexit destructor for '
`vector copy constructor iterator'
`vector vbase copy constructor iterator'
`managed vector copy constructor iterator'
`local static thread guard'
Type Descriptor'
Base Class Descriptor at (
Base Class Array'
Class Hierarchy Descriptor'
Complete Object Locator'
CreateFile2
1#SNAN
1#QNAN
address not available
already connected
argument list too long
argument out of domain
bad address
bad file descriptor
bad message
broken pipe
connection aborted
connection already in progress
connection refused
connection reset
destination address required
executable format error
file too large
host unreachable
identifier removed
illegal byte sequence
inappropriate io control operation
invalid seek
is a directory
message size
network down
network reset
network unreachable
no buffer space
no child process
no link
no message available
no message
no protocol option
no stream resources
no such device or address
no such process
not a directory
not a socket
not a stream
not connected
not supported
operation in progress
operation not permitted
operation not supported
operation would block
owner dead
protocol error
protocol not supported
read only file system
resource deadlock would occur
result out of range
state not recoverable
stream timeout
text file busy
timed out
too many files open in system
too many links
too many symbolic link levels
value too large
wrong protocol type
permission denied
file exists
no such device
filename too long
device or resource busy
io error
directory not empty
invalid argument
no space on device
no such file or directory
function not supported
no lock available
not enough memory
resource unavailable try again
cross device link
operation canceled
too many files open
permission_denied
address_in_use
address_not_available
address_family_not_supported
connection_already_in_progress
bad_file_descriptor
connection_aborted
connection_refused
connection_reset
destination_address_required
bad_address
host_unreachable
operation_in_progress
interrupted
invalid_argument
already_connected
too_many_files_open
message_size
filename_too_long
network_down
network_reset
network_unreachable
no_buffer_space
no_protocol_option
not_connected
not_a_socket
operation_not_supported
protocol_not_supported
wrong_protocol_type
timed_out
operation_would_block
address family not supported
address in use
0123456789abcdefghijklmnopqrstuvwxyz
0123456789abcdefghijklmnopqrstuvwxyz
0123456789abcdefABCDEF
bad exception
SunMonTueWedThuFriSat
JanFebMarAprMayJunJulAugSepOctNovDec
The Winsock 2.2 dll was found okay
jelepenorocks.com
_SIGNATURE_BEAR*************
%i.%i.%i
%1.15g
%1.17g
APPDATA
%s\%s\
SL_SEND_CURL
SL_SEND_CERT
SL_SEND_STUB
loader
bad locale name
generic
unknown error
iostream
iostream stream error
system
ios_base::badbit set
ios_base::failbit set
ios_base::eofbit set
MUTEX_WEBSOCKET_LOADER
curl.exe
ca-bundle.crt
client.exe
launch.bat
NODE_SERVER
LS_DOWN_CURL
LS_DOWN_CERT
LS_DOWN_STUB_X64
LS_DOWN_STUB_X86
Error in MultiByteToWideChar:
ping -n 2 127.0.0.1 > nul
start "" "%s"
del "%s"
string too long
invalid string position
bad cast
C:\Users\Administrator\Documents\Work\DemProject\Output\Loader\Release\Loader_Release_Win32.pdb
Loader_Release_Win32.exe
_cJSON_AddArrayToObject@8
_cJSON_AddBoolToObject@12
_cJSON_AddFalseToObject@8
_cJSON_AddItemReferenceToArray@8
_cJSON_AddItemReferenceToObject@12
_cJSON_AddItemToArray@8
_cJSON_AddItemToObject@12
_cJSON_AddItemToObjectCS@12
_cJSON_AddNullToObject@8
_cJSON_AddNumberToObject@16
_cJSON_AddObjectToObject@8
_cJSON_AddRawToObject@12
_cJSON_AddStringToObject@12
_cJSON_AddTrueToObject@8
_cJSON_Compare@12
_cJSON_CreateArray@0
_cJSON_CreateArrayReference@4
_cJSON_CreateBool@4
_cJSON_CreateDoubleArray@8
_cJSON_CreateFalse@0
_cJSON_CreateFloatArray@8
_cJSON_CreateIntArray@8
_cJSON_CreateNull@0
_cJSON_CreateNumber@8
_cJSON_CreateObject@0
_cJSON_CreateObjectReference@4
_cJSON_CreateRaw@4
_cJSON_CreateString@4
_cJSON_CreateStringArray@8
_cJSON_CreateStringReference@4
_cJSON_CreateTrue@0
_cJSON_Delete@4
_cJSON_DeleteItemFromArray@8
_cJSON_DeleteItemFromObject@8
_cJSON_DeleteItemFromObjectCaseSensitive@8
_cJSON_DetachItemFromArray@8
_cJSON_DetachItemFromObject@8
_cJSON_DetachItemFromObjectCaseSensitive@8
_cJSON_DetachItemViaPointer@8
_cJSON_Duplicate@8
_cJSON_GetArrayItem@8
_cJSON_GetArraySize@4
_cJSON_GetErrorPtr@0
_cJSON_GetNumberValue@4
_cJSON_GetObjectItem@8
_cJSON_GetObjectItemCaseSensitive@8
_cJSON_GetStringValue@4
_cJSON_HasObjectItem@8
_cJSON_InitHooks@4
_cJSON_InsertItemInArray@12
_cJSON_IsArray@4
_cJSON_IsBool@4
_cJSON_IsFalse@4
_cJSON_IsInvalid@4
_cJSON_IsNull@4
_cJSON_IsNumber@4
_cJSON_IsObject@4
_cJSON_IsRaw@4
_cJSON_IsString@4
_cJSON_IsTrue@4
_cJSON_Minify@4
_cJSON_Parse@4
_cJSON_ParseWithLength@8
_cJSON_ParseWithLengthOpts@16
_cJSON_ParseWithOpts@12
_cJSON_Print@4
_cJSON_PrintBuffered@12
_cJSON_PrintPreallocated@16
_cJSON_PrintUnformatted@4
_cJSON_ReplaceItemInArray@12
_cJSON_ReplaceItemInObject@12
_cJSON_ReplaceItemInObjectCaseSensitive@12
_cJSON_ReplaceItemViaPointer@12
_cJSON_SetNumberHelper@12
_cJSON_SetValuestring@8
_cJSON_Version@0
_cJSON_free@4
_cJSON_malloc@4
WaitForSingleObject
TerminateThread
CreateDirectoryA
CloseHandle
CreateThread
CreateFileA
GetCurrentProcess
WriteFile
OpenProcess
GetFileAttributesA
CreateProcessA
TerminateProcess
MultiByteToWideChar
SetCurrentDirectoryA
GetLastError
Process32FirstW
IsWow64Process
Process32NextW
CreateMutexA
CreateToolhelp32Snapshot
DeleteFileA
KERNEL32.dll
SendMessageW
DispatchMessageW
DefWindowProcW
CreateWindowExW
LoadStringW
LoadIconW
RegisterClassExW
LoadAcceleratorsW
TranslateMessage
BeginPaint
LoadCursorW
PostQuitMessage
GetMessageW
TranslateAcceleratorW
DestroyWindow
EndPaint
USER32.dll
WS2_32.dll
HeapFree
HeapAlloc
IsDebuggerPresent
IsProcessorFeaturePresent
HeapReAlloc
EncodePointer
DecodePointer
GetCommandLineW
GetProcessHeap
EnterCriticalSection
LeaveCriticalSection
RaiseException
IsValidCodePage
GetACP
GetOEMCP
GetCPInfo
SetLastError
GetCurrentThreadId
ExitProcess
GetModuleHandleExW
GetProcAddress
AreFileApisANSI
WideCharToMultiByte
GetStdHandle
GetModuleFileNameW
UnhandledExceptionFilter
SetUnhandledExceptionFilter
InitializeCriticalSectionAndSpinCount
TlsAlloc
TlsGetValue
TlsSetValue
TlsFree
GetStartupInfoW
GetModuleHandleW
DeleteCriticalSection
HeapSize
RtlUnwind
GetFileType
QueryPerformanceCounter
GetCurrentProcessId
GetSystemTimeAsFileTime
GetEnvironmentStringsW
FreeEnvironmentStringsW
GetStringTypeW
GetConsoleCP
GetConsoleMode
SetFilePointerEx
LoadLibraryExW
OutputDebugStringW
CompareStringW
LCMapStringW
GetLocaleInfoW
IsValidLocale
GetUserDefaultLCID
EnumSystemLocalesW
SetEnvironmentVariableA
SetStdHandle
FlushFileBuffers
WriteConsoleW
ReadFile
ReadConsoleW
CreateFileW
SetEndOfFile
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
Copyright (c) 1992-2004 by P.J. Plauger, licensed by Dinkumware, Ltd. ALL RIGHTS RESERVED.
.?AVbad_alloc@std@@
.?AVtype_info@@
.?AV_Locimp@locale@std@@
.?AVlogic_error@std@@
.?AVlength_error@std@@
.?AVout_of_range@std@@
.?AVios_base@std@@
.?AV?$_Iosb@H@std@@
.?AV?$basic_ios@DU?$char_traits@D@std@@@std@@
.?AV?$basic_streambuf@DU?$char_traits@D@std@@@std@@
.?AV?$basic_ostream@DU?$char_traits@D@std@@@std@@
.?AV?$basic_filebuf@DU?$char_traits@D@std@@@std@@
.?AVcodecvt_base@std@@
.?AV?$codecvt@DDH@std@@
.?AVbad_exception@std@@
.?AV_System_error@std@@
.?AVsystem_error@std@@
.?AVbad_cast@std@@
.?AVexception@std@@
.?AV_Iostream_error_category@std@@
.?AVfailure@ios_base@std@@
.?AVruntime_error@std@@
.?AV?$ctype@D@std@@
.?AV_System_error_category@std@@
.?AV?$numpunct@D@std@@
.?AVerror_category@std@@
.?AV?$num_put@DV?$ostreambuf_iterator@DU?$char_traits@D@std@@@std@@@std@@
.?AV_Generic_error_category@std@@
.?AV_Facet_base@std@@
.?AUctype_base@std@@
.?AVfacet@locale@std@@
YYYBBB
ooozzz
IDATx^
IDATx^
YYYBBB
ooozzz
IDATx^
IDATx^
<?xml version='1.0' encoding='UTF-8' standalone='yes'?>
<assembly xmlns='urn:schemas-microsoft-com:asm.v1' manifestVersion='1.0'>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v3">
<security>
<requestedPrivileges>
<requestedExecutionLevel level='asInvoker' uiAccess='false' />
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
0!0-090I0N0X0k0
11T1Y1d1
3/3W3\3
4'4,494
5!5'5/545<5
6L7l7&8'9
:":@:X:{=
=0>4>8><>@>D>H>L>
0d0h0l0p0t0x0|0
273`3h3o3
253]3|3
7L8P8T8X8
: :':I:f:
< <$<(<
<)=M=`=g=s=
>G>d>{>
?@?N?a?
0=0I0V0q0
1#111C1
1I2W2b2i2u2
6G6i6p6
?#?(?4?@?
0<0A0K0T0s0x0
11&1/181S1Z1c1l1|1
23282F2a2h2p2y2
3%303@3N3W3^3w3
4 4)4.4w4|4
565E5c5t5
8'8A8F8T8o8v8
8N9Y9b9q9
;Y=c=m=
>)>8>D>
)080F0
095H5V5[;y;
2$3*3@3G3M3R3`3
4(4<4E4Q4W4
8P8]8q8
9f:x:l;
(060@0S0
50666<6B6H6N6U6\6c6j6q6x6
777=7C7I7O7U7\7c7j7q7x7
7&8,888o8
;6;P;n;
?5?<?@?D?H?L?P?T?X?
0%0@0G0L0P0T0u0
0>1D1H1L1P1
3^3e3m3
8V8[8e8
<P=`=v=
5'5-5L5R5
99#9'9+9/939
;.<A<6=
=F>y>-?s?
$0=0N0x0
3D3Y3g3p3
3"4K4e4m4x4
8-939\9w9
;!;%;*;0;4;:;>;D;H;N;R;H<O<
0"1,1U1]1f1o1
2!2,262L2m2
3$313=3M3S3d3
51585>5L5R5g5x5
9'9-9A9M9
8(82888G8Q8W8i8{8
99$9*92979=9E9J9P9X9]9c9k9p9v9~9
:!:):.:3:<:A:G:O:T:Z:b:g:m:u:z:
; ;%;+;3;8;>;F;K;Q;Y;^;c;l;q;w;
;L<i<o<y<
<0=H=v={=
0"090D0s0
1"171A1Z1d1q1{1
2*2i2~2
7,8A8G8
=E?`?v?
5'6=6c6
7$7C7H8
9:;E;L;R;X;
>)>4>R>n>v>{>
>"?*?7?<?W?\?{?
0-0K0_0e0
5,6C6z6
]3a3e3i3m3q3u3y3}3
4414C4U4g4y4
798K8]8o8
8l:s:{:
5t5A6p6y6
<?<\<{<5=?=Z=t=v>
2!2,2L2W2w2
4!5G5e5l5p5t5x5|5
5J6U6p6w6|6
7 7$7n7t7x7|7
97:B:H:o:
?&?,?2?:?@?F?N?T?Z?b?k?r?z?
1D1Q1W1
152K2W2]2x2}2
4.464V4^4w4^5
? ?$?(?,?0?4?8?<?@?D?H?L?P?T?X?\?`?d?h?l?p?t?x?|?
8)959{9
3'3k3q3}3v4 5
<%=?=H=
334C4q4
445J5]5
5!676C6h6o6
7)7>7H7f:N<
393O3e3~3
4*4=4d4
676T6j6
828Z8j8x8
? ?&?-?
(1A2L2f2~2
6+61666B8<:C:
>4?F?V?u?
0 090R0g0s0x0
272o2}2
2M3b3g3
7|7#9u98:
:2<@<J<
=m>6?]?
2 2$2x2|2
2d3h3l3p3
747<7D7L7T7\7d7l7t7|7
d0l0t0|0
1$1,141<1D1L1T1\1d1l1t1|1
2$2,242<2D2L2T2\2d2l2t2|2
3$3,343<3D3L3T3\3d3l3t3|3
4$4,444<4D4L4T4\4d4l4t4|4
5$5,545<5D5L5T5\5d5l5t5|5
6$6,646<6D6L6T6\6d6l6t6|6
7$7,747<7D7L7T7\7d7l7t7|7
8 8(80888@8H8P8X8`8h8p8x8
9 9(90989@9H9P9X9`9h9p9x9
: :(:0:8:@:H:P:X:`:h:p:x:
; ;(;0;8;@;H;P;X;`;h;p;x;
< <(<0<8<@<H<P<X<`<h<p<x<
= =(=0=8=@=H=P=X=`=h=p=x=
> >(>0>8>@>H>P>X>`>h>p>x>
1 1,181D1P1\1h1t1
2(242@2L2X2d2p2|2
3$303<3H3T3`3l3x3
<$<0<<<H<T<`<l<x<
? ?$?(?,?0?4?8?<?@?D?H?L?P?T?X?\?`?d?h?l?p?t?x?|?
0 0$0(0,0004080<0@0D0H0L0P0T0X0\0`0d0h0l0p0t0x0|0
0$;,;4;<;D;L;T;\;d;l;t;|;
<$<,<4<<<D<L<T<\<d<l<t<|<
=$=,=4=<=D=L=T=\=d=l=|=
>$>,>4><>D>L>T>\>d>l>t>|>
?$?,?4?<?D?L?T?\?d?l?t?|?
4 4$4(4,4044484<4@4D4H4L4P4T4X4\4`4d4h4l4p4t4x4
5 5$5(5,5054585<5@5D5H5L5P5T5X5d5h5l5p5t5x5|5
;0<4<D<H<L<T<l<|<
=$=(=8=<=@=D=L=d=t=x=
>$>(>,>0>8>P>`>d>t>x>|>
?$?<?L?P?`?d?l?
0,0<0@0P0T0X0`0x0
1,10141<1T1X1p1
2,2024282<2@2H2L2P2d2h2l2
3 3$3(3,3@3D3T3d3t3
4 484H4L4P4h4l4
5,50545L5\5l5|5
7$7D7P7p7|7
888@8L8T8
949<9D9L9X9`9
90:D:T:d:p:
;$;0;P;\;d;|;
< <(<4<<<p<
=8=X=x=
>$>@>L>h>
? ?<?@?`?
0(0H0h0
101P1p1x1
20282D2d2p2
3 3X3x3
4 4$4@4H4L4d4h4
5$585X5`5t5|5
6$686@6T6\6`6
0 0$0(0,080<0@0D0H0L0P0T0
: :$:(:,:0:4:8:D:H:L:P:T:X:\:`:d:h:l:p:t:x:|:
;,;<;L;\;|;
>$>,>4><>D>L>T>\>d>
6(6H6h6
8,8L8h8
jjjjjjj
(null)
Bja-JP
Sunday
Monday
Tuesday
Wednesday
Thursday
Friday
Saturday
January
February
August
September
October
November
December
MM/dd/yy
dddd, MMMM dd, yyyy
HH:mm:ss
@mscoree.dll
BR6002
- floating point support not loaded
- not enough space for arguments
- not enough space for environment
- abort() has been called
- not enough space for thread data
- unexpected multithread lock error
- unexpected heap error
- unable to open console device
- not enough space for _onexit/atexit table
- pure virtual function call
- not enough space for stdio initialization
- not enough space for lowio initialization
- unable to initialize heap
- CRT not initialized
- Attempt to initialize the CRT more than once.
This indicates a bug in your application.
- not enough space for locale information
- Attempt to use MSIL code from this assembly during native code initialization
This indicates a bug in your application. It is most likely the result of calling an MSIL-compiled (/clr) function from a native constructor or from DllMain.
- inconsistent onexit begin-end variables
DOMAIN error
SING error
TLOSS error
runtime error
Runtime Error!
Program:
<program name unknown>
Microsoft Visual C++ Runtime Library
ALC_ALL
LC_COLLATE
LC_CTYPE
LC_MONETARY
LC_NUMERIC
LC_TIME
kernel32.dll
((((( H
((((( H
USER32.DLL
zh-CHS
az-AZ-Latn
uz-UZ-Latn
kok-IN
syr-SY
div-MV
quz-BO
sr-SP-Latn
az-AZ-Cyrl
uz-UZ-Cyrl
quz-EC
sr-SP-Cyrl
quz-PE
smj-NO
bs-BA-Latn
smj-SE
sr-BA-Latn
sma-NO
sr-BA-Cyrl
sma-SE
sms-FI
smn-FI
zh-CHT
az-az-cyrl
az-az-latn
bs-ba-latn
div-mv
kok-in
quz-bo
quz-ec
quz-pe
sma-no
sma-se
smj-no
smj-se
smn-fi
sms-fi
sr-ba-cyrl
sr-ba-latn
sr-sp-cyrl
sr-sp-latn
syr-sy
uz-uz-cyrl
uz-uz-latn
zh-chs
zh-cht
american
american english
american-english
australian
belgian
canadian
chinese
chinese-hongkong
chinese-simplified
chinese-singapore
chinese-traditional
dutch-belgian
english-american
english-aus
english-belize
english-can
english-caribbean
english-ire
english-jamaica
english-nz
english-south africa
english-trinidad y tobago
english-uk
english-us
english-usa
french-belgian
french-canadian
french-luxembourg
french-swiss
german-austrian
german-lichtenstein
german-luxembourg
german-swiss
irish-english
italian-swiss
norwegian
norwegian-bokmal
norwegian-nynorsk
portuguese-brazilian
spanish-argentina
spanish-bolivia
spanish-chile
spanish-colombia
spanish-costa rica
spanish-dominican republic
spanish-ecuador
spanish-el salvador
spanish-guatemala
spanish-honduras
spanish-mexican
spanish-modern
spanish-nicaragua
spanish-panama
spanish-paraguay
spanish-peru
spanish-puerto rico
spanish-uruguay
spanish-venezuela
swedish-finland
america
britain
england
great britain
holland
hong-kong
new-zealand
pr china
pr-china
puerto-rico
slovak
south africa
south korea
south-africa
south-korea
trinidad & tobago
united-kingdom
united-states
CONOUT$
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLM
iE&xit
h&About ...
About Loader
MS Shell Dlg
Loader, Version 1.0
Copyright (c) 2024
Loader
LOADER
Antivirus Signature
Bkav Clean
Lionic Trojan.Win32.Agentb.X!c
tehtris Clean
ClamAV Clean
CMC Clean
CAT-QuickHeal Clean
Skyhigh BehavesLike.Win32.NetLoader.dh
ALYac Gen:Variant.Jaik.146768
Cylance unsafe
Zillya Clean
Sangfor Trojan.Win32.Agent.Vdsj
K7AntiVirus Clean
Alibaba TrojanDownloader:Win32/Generic.2b68bae0
K7GW Clean
Cybereason Clean
Baidu Clean
VirIT Clean
Paloalto Clean
Symantec ML.Attribute.HighConfidence
Elastic Clean
ESET-NOD32 a variant of Win32/TrojanDownloader.Agent.HNR
APEX Clean
Avast Clean
Cynet Malicious (score: 100)
Kaspersky HEUR:Trojan.Win32.Agentb.gen
BitDefender Gen:Variant.Jaik.146768
NANO-Antivirus Clean
ViRobot Clean
MicroWorld-eScan Gen:Variant.Jaik.146768
Tencent Clean
TACHYON Clean
Sophos Mal/Generic-S
F-Secure Trojan.TR/Dldr.Agent.ffafq
DrWeb Clean
VIPRE Gen:Variant.Jaik.146768
TrendMicro Trojan.Win32.AMADEY.YXEB3Z
Trapmine Clean
FireEye Gen:Variant.Jaik.146768
Emsisoft Gen:Variant.Jaik.146768 (B)
SentinelOne Clean
GData Gen:Variant.Jaik.146768
Jiangmin Clean
Webroot W32.Malware.Gen
Varist Clean
Avira TR/Dldr.Agent.ffafq
Antiy-AVL Trojan/Win32.Phonzy
Kingsoft Win32.Trojan.Agentb.a
Gridinsoft Trojan.Win32.Agent.sa
Xcitium Clean
Arcabit Trojan.Jaik.D23D50
SUPERAntiSpyware Clean
ZoneAlarm HEUR:Trojan.Win32.Agentb.gen
Microsoft Trojan:Win32/Casdet!rfn
Google Detected
AhnLab-V3 Clean
Acronis Clean
McAfee Artemis!83C6F7D8026E
MAX malware (ai score=87)
VBA32 Clean
Malwarebytes Trojan.Crypt
Panda Trj/Chgt.AD
Zoner Clean
TrendMicro-HouseCall Trojan.Win32.AMADEY.YXEB3Z
Rising Clean
Yandex Clean
Ikarus Trojan-Downloader.Win32.Agent
MaxSecure Clean
Fortinet W32/PossibleThreat
BitDefenderTheta Gen:NN.ZexaE.36744.suW@aK5ZIjii
AVG Clean
DeepInstinct MALICIOUS
CrowdStrike win/malicious_confidence_100% (W)
No IRMA results available.