Static | ZeroBOX

PE Compile Time

2024-05-22 00:35:06

PE Imphash

ed37602397e78085e01f2627992a34cb

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x00243480 0x00243600 5.33435245598
.rdata 0x00245000 0x0003b2b4 0x0003b400 7.72926438419
.data 0x00281000 0x00038ca8 0x00032e00 7.9732922449
.pdata 0x002ba000 0x00001020 0x00001200 5.01393157354
_RDATA 0x002bc000 0x000001f4 0x00000200 4.19908093763
.rsrc 0x002bd000 0x00000670 0x00000800 3.3808515418
.reloc 0x002be000 0x0000066c 0x00000800 4.90499195751

Resources

Name Offset Size Language Sub-language File type
RT_VERSION 0x002bd200 0x00000470 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_MANIFEST 0x002bd0a0 0x0000015a LANG_ENGLISH SUBLANG_ENGLISH_US ASCII text, with CRLF line terminators

Imports

Library KERNEL32.dll:
0x140245038 SetFilePointerEx
0x140245040 GetConsoleMode
0x140245048 GetConsoleOutputCP
0x140245050 FlushFileBuffers
0x140245058 HeapReAlloc
0x140245060 HeapSize
0x140245068 GetProcessHeap
0x140245070 LCMapStringW
0x140245078 FlsFree
0x140245080 FlsSetValue
0x140245088 FlsGetValue
0x140245090 FlsAlloc
0x140245098 CreateFileW
0x1402450a0 GetStringTypeW
0x1402450a8 GetFileType
0x1402450b0 SetStdHandle
0x1402450b8 FreeEnvironmentStringsW
0x1402450c0 GetEnvironmentStringsW
0x1402450c8 WideCharToMultiByte
0x1402450d0 MultiByteToWideChar
0x1402450d8 GetCommandLineW
0x1402450e0 GetCommandLineA
0x1402450e8 GetCPInfo
0x1402450f0 GetOEMCP
0x1402450f8 GetACP
0x140245100 IsValidCodePage
0x140245108 FindNextFileW
0x140245110 CloseHandle
0x140245118 WriteConsoleW
0x140245120 FindFirstFileExW
0x140245128 FindClose
0x140245130 HeapFree
0x140245138 HeapAlloc
0x140245140 HeapCreate
0x140245148 LoadLibraryA
0x140245150 GetProcAddress
0x140245158 GetModuleHandleA
0x140245160 QueryPerformanceCounter
0x140245168 GetCurrentProcessId
0x140245170 GetCurrentThreadId
0x140245178 GetSystemTimeAsFileTime
0x140245180 InitializeSListHead
0x140245188 RtlCaptureContext
0x140245190 RtlLookupFunctionEntry
0x140245198 RtlVirtualUnwind
0x1402451a0 IsDebuggerPresent
0x1402451a8 UnhandledExceptionFilter
0x1402451b8 GetStartupInfoW
0x1402451c8 GetModuleHandleW
0x1402451d0 RtlUnwindEx
0x1402451d8 GetLastError
0x1402451e0 SetLastError
0x1402451e8 EnterCriticalSection
0x1402451f0 LeaveCriticalSection
0x1402451f8 DeleteCriticalSection
0x140245208 TlsAlloc
0x140245210 TlsGetValue
0x140245218 TlsSetValue
0x140245220 TlsFree
0x140245228 FreeLibrary
0x140245230 LoadLibraryExW
0x140245238 EncodePointer
0x140245240 RaiseException
0x140245248 RtlPcToFileHeader
0x140245250 GetStdHandle
0x140245258 WriteFile
0x140245260 GetModuleFileNameW
0x140245268 GetCurrentProcess
0x140245270 ExitProcess
0x140245278 TerminateProcess
0x140245280 GetModuleHandleExW
Library USER32.dll:
0x140245290 DrawCaption
0x140245298 AnyPopup
0x1402452a0 CreateDialogParamW
0x1402452a8 GetDlgItem
0x1402452b0 IsDlgButtonChecked
0x1402452b8 ChangeClipboardChain
0x1402452c0 EnumClipboardFormats
0x1402452d8 CharUpperW
0x1402452e0 CharPrevExA
0x1402452e8 InternalGetWindowText
0x1402452f0 MapDialogRect
0x140245300 IsGUIThread
0x140245310 SetWindowLongW
0x140245318 GetWindowLongW
0x140245320 SubtractRect
0x140245328 SetRect
0x140245330 GetCursorPos
0x140245338 EnumPropsW
0x140245340 SetScrollRange
0x140245348 GetWindowRgnBox
0x140245350 GetWindowRgn
0x140245358 GetUpdateRect
0x140245360 UpdateWindow
0x140245368 SetMenuDefaultItem
0x140245370 GetMenuItemInfoW
0x140245380 SetMenuItemBitmaps
0x140245388 ModifyMenuW
0x140245390 KillTimer
0x140245398 GetCapture
Library WINSPOOL.DRV:
0x1402453d0 ReadPrinter
0x1402453d8 AbortPrinter
0x1402453e0 WritePrinter
0x1402453e8 ScheduleJob
Library ADVAPI32.dll:
0x140245000 DecryptFileW
Library VERSION.dll:
0x1402453a8 VerInstallFileW
0x1402453b0 VerFindFileW
0x1402453b8 GetFileVersionInfoW
Library COMCTL32.dll:
0x140245010 PropertySheetW
0x140245018 None
0x140245020 None
0x140245028 None
Library gdiplus.dll:
0x1402453f8 GdiplusStartup

!This program cannot be run in DOS mode.
eERich
`.rdata
@.data
.pdata
@_RDATA
@.rsrc
@.reloc
L$@HcI<H
)7R4{H
u/HcH<H
WATAUAVAWH
A_A^A]A\_
WATAUAVAWH
A_A^A]A\_
VWATAVAWH
A_A^A\_^
WATAUAVAWH
A_A^A]A\_
H;xXu5
AUAVAWH
u4I9}(
;I9}(tiH
0A_A^A]
UVWATAUAVAWH
`A_A^A]A\_^]
@USVWATAUAVAWH
A_A^A]A\_^[]
UVWATAUAVAWH
A_A^A]A\_^]
@SVWATAUAVAWH
L!|$(L!
D$0HcH
pA_A^A]A\_^[
B(I9A(u
SVWATAUAVAWH
0A_A^A]A\_^[
t$ WATAUAVAWH
A_A^A]A\_
vyfffff
vyfffff
fffffff
fffffff
UVWAVAWH
0A_A^_^]
WAVAWH
fA9,@u
fA9,vu
0A_A^_
p0R^G'
u3HcH<H
WAVAWH
A_A^_
WAVAWH
A_A^_
D$0@8{
p*W4H
p*W4H
UVWATAUAVAWH
H;\$8u
H;\$8u
fE9$Iu
A_A^A]A\_^]
WATAUAVAWH
0A_A^A]A\_
H9>u+A
l$ VWATAVAWH
L$&8\$&t,8Y
A_A^A\_^
fD9t$b
@UATAUAVAWH
e0A_A^A]A\]
WATAUAVAWH
A_A^A]A\_
t$ WATAUAVAWH
D!|$xA
A_A^A]A\_
L$ VWAVH
fD94H}aD
ATAUAVH
L$ fff
L$ |+L;
A^A]A\
@UATAUAVAWH
A_A^A]A\]
WAVAWH
A_A^_
UVWATAUAVAWH
fB9<I}1L
A_A^A]A\_^]
VWATAVAW
A_A^A\_^
VATAUAVAWH
0A_A^A]A\^
@USVWATAUAVAWH
H!D$ H
xA_A^A]A\_^[]
WATAUAVAWH
0A_A^A]A\_
ffffff
fffffff
@SUVWATAVAWH
@A_A^A\_^][
USVWAVH
A^_^[]
LcA<E3
fffffff
ffffff
vKfffff
fffffff
fffffff
WfIGMb^
sG2B-az
%DkJ)^
"3l^U4M
"-%9F_j?{
0/_na1fKDS
GP}dT#
{7:!zf
iD]L`7
C|?A%
+7FO*t
-X~|Iu
>NqDu]
\$D!!I
hI;H"F
%%4#0)
_yq\Zf
-D2f#
O@A#(Z
%loXlTU
;1l'<
[{H['3
X$RMGjtk
rD1YIre
u$#xXb
'9?bpc`
S]vHy1
Q0gTgX
OG^dK}
d5Qo_/3
"^R.2H
l:n Rj,
3f]27O6i
=Q?9E
{2OiPz
9RYxK`
,Q_mZO
<)/@^:
lvA;Uq
%k_\)q
KpFcZ]*
WjTN'~
*vL[Hg
{L9y-F
q][79'y
.VeC=<~C@
,M/k];
[H~~8I
dv'ha|
Z6Su=c
,[W_%a
>xybLg
b1L+1;
aai# NJ
kXYKpkQ
G:J0m?
Pm?JA%
\z*q?y
\.2{\,~|
k)UE/<
JMu&Ye
^qQI>H
{KodVM
#S:nNr
-I;,pF~
yU!80U
|{]30c
PA1'4A
JVFNZF
KX-Sy4
jP #1_
}/q\vo
t)#J?4c
WNtf|c
hc%6.n+6
)DT`Hx
G&Lg:A83S
Yl>0xI
E#/TEO
nf"6>5|
?}a*i2
Sqr=.i
dpz3\f
((D<&F
1]B=fZn/
QD<t.G
z<5Kbt6
+|\P{y
"x64oB
kT#!i#
-\<A5?
1kg.7a
Ya\(xK
ocw<'F
:rj;E<
C]^P"n;
,LBehB
v]*UW&
uM@{gn
^?5Zff
y:u".[
teZp,*Q
e(M;WW
Q)pmH
"kc_gt~M
^H|60#
z;AwGS9
mHH{kjZ
Eu#Y*{
'@]sMC*
Bid$?QP
jRKs~)
DyGRH
/8QQD.
*z0/-g
|)Egz0l
34'x2H
G>$@$
oN'ri_U
h0[R@A_
bhQa%ho
yB[7[0|k_
c#]Ga!k
(}%SlY
\?STE@
l5Af|%
P?Kuvd
HXl~?F
8D.4MEZ
M{_cPCu
cFkD0I
y/V:YN
-Phk[mM
`L*,Nv
lbaTYn
%x-d[#
[.~Imd
$"tR4\
Y2ouLA
F7:5]5
,.dybGV
;k #Hz
[V9jt*
!t:Cde
',qThpVU
/@OtfS7
e~;e#0
"%W`Y=
fZ:2@z
;cgO@
|j;av"
{soFV.
e*ZD(\
KsQL6]pYhQP
@!`-+0
JS0i7XU
I%c)iV
<4TH|e&M2-|ibqG
1yRwm2
|"4=2j
(t\&+k
2Z/Rf$c
h9bxP^m-
NW6NKf
!FIl.c
)_7zk&
)"lBwx
bR\>1p>
9wJ?'"b
VPgjAJ
S8Bf|I
dYj0<^
5 E_%<
H$?EFb{
q5r{^$
'.H+:Ff
cja5Y%
$TH^5GB
Mx04%5
*)ysB9
y=+OjU
A7SHa(
J0;*#*i
t7u;5H
65Q-P0
f7t!$W
'A2)3C
s*.D*i
kux27d
I_8S$H
q(M?Uw
d~yTX`y
V^X,P
wx}aOz
"Z*s+>
VB+mV!f6d
3sHmN-J
Z:-:85
k#a$>/
O/$KS%,gs
*R$<Rd
|CP$KE
2W^5W>dk
<7t%~>
25($j!
*ds=,g
G@[1ar
YBf -_
mu1`7m<
G[ENla&2
' =Vyl
P|1 lVN
b)H$hO
p9hG=Qm
6\RVJ1
A\?dv~
;|Xk9
yt$N6:7?
uWwg1!
f'c%XTI
6j7Uv)
6/`7F%
6D%?J}
ZU\'g(
Y|-?]a
oJ:Fy\K
j:TnH#8
0:LuqUIa
eKp}cY
]N]YCi
M}jXzo
a|XVe-
Ae%-4cJ
pZeBx]J
-0iM?q
g)p*':
_bM"nW
G7q&JK
=E3aw
A(4(qS
LXvy#p|SO
En h<{H
OR2jdJ
j<t@D\
2.'j$*=
0 .;;'
F,t)Kk
x3{P|\-4pm
e|d:r
!zFf\B
qilyU
y%%c$;
au!^Wl
lg-P$o
.#feo6
W|xA.|
APY5.=.
MJ(Jn4
6=n$tgz
gHc69=LE
]mzl[l
MKr-z
5#rJfG
))v%B#-
7[$nO
EuK-,#?B
O7}6<<
%n$.*Xr
$To.Wd
ep@bbR
v+Ghp;
H(U;E[
:6U^<3,
7s*^tJ
D]=kHI
1r5U|KA
En:t&,
[s`uc<H
+_S%(?W
OV7SXI
!T[i!
*7yvS2
.('aY4
JfV33;
xl({|M
CtPF+z
,>u|ZR
]f#3'e^d
7=vfyU
0t/gK8R4
@zR_yA
]2-V3G
U]OpXB
cL14d\=
j:jY,ih
xnx,#f
^B%!VX
VS< Rr
e.bzpU
l%\U,
<N;[Ld
!6C4c7
fx%0,{
XD@xA6
[\3RMl
twCvg~m
YNU^fj
3EJzta
HBzEu+
%3l7jI
OC`XJl
kWs`NUq
XbkiT,m}9
%`^qaI
Pe*F9n
C}s>.rH
T#tmeU
FX/p.G'
m}+UBX
/.-2ZU:
Ntc!%Y
PH|4t}_
>QT@hh+
a!Z@EU
B^kaMMn
-`C|#=
sbk0r[
IL Je@
*\ZKI|U
W.vL$w
jsl;z'
<m?krQ
3RV^\8
rr+!5&:
uyN}S>+.
Jii0?7
|qV@sB
D5{ D1#?k?Q*
[f`N,S
Eft*i= Q
Eb`\Dkk
DT8Z>i
jfgh:yG
pK]W3<1
Sg _0&
\Kj(U#^F
I7!ItGTY;-
9&3}[h;1M.
Hx0SX^GA
{Z-%'l
xdS}KOm
0=).}c
KbhwQi
Kk9M*G
%A}gAr$_
i+l6D0
uEL+)+w
$EJ\0{ Rn
$Wl0| `F
1_R/!B
G$7re7
$jaYQO
x9?YmvL
5.FN@
Z-"'lb
nI/RnX
`#Erty
*{#*~|
]p1$g
?=vz{n
)HCC%q
MMLUU-
ZSDmww
6.\9B{
VG|XYx_
QH3,Ur
__based(
__cdecl
__pascal
__stdcall
__thiscall
__fastcall
__vectorcall
__clrcall
__eabi
__swift_1
__swift_2
__swift_3
__ptr64
__restrict
__unaligned
restrict(
delete
operator
`vftable'
`vbtable'
`vcall'
`typeof'
`local static guard'
`string'
`vbase destructor'
`vector deleting destructor'
`default constructor closure'
`scalar deleting destructor'
`vector constructor iterator'
`vector destructor iterator'
`vector vbase constructor iterator'
`virtual displacement map'
`eh vector constructor iterator'
`eh vector destructor iterator'
`eh vector vbase constructor iterator'
`copy constructor closure'
`udt returning'
`local vftable'
`local vftable constructor closure'
new[]
delete[]
`omni callsig'
`placement delete closure'
`placement delete[] closure'
`managed vector constructor iterator'
`managed vector destructor iterator'
`eh vector copy constructor iterator'
`eh vector vbase copy constructor iterator'
`dynamic initializer for '
`dynamic atexit destructor for '
`vector copy constructor iterator'
`vector vbase copy constructor iterator'
`managed vector copy constructor iterator'
`local static thread guard'
operator ""
operator co_await
operator<=>
Type Descriptor'
Base Class Descriptor at (
Base Class Array'
Class Hierarchy Descriptor'
Complete Object Locator'
`anonymous namespace'
FlsAlloc
FlsFree
FlsGetValue
FlsSetValue
InitializeCriticalSectionEx
Unknown exception
bad exception
CorExitProcess
Sunday
Monday
Tuesday
Wednesday
Thursday
Friday
Saturday
January
February
August
September
October
November
December
MM/dd/yy
dddd, MMMM dd, yyyy
HH:mm:ss
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
LCMapStringEx
LocaleNameToLCID
AppPolicyGetProcessTerminationMethod
UUUUUU
UUUUUU
=imb;D
/>58d%
VM>cQ6
>jtm}S
)>6{1n
+f)>0'
;H9>&X
*StO9>T
n03>Pu
K~Je#>!
bp(=>?g
BC?>6t9^
K&>.yC
.xJ>Hf
y\PD>!
|b=})>
c [1>H'
uzKs@>
3>N;kU
kE>fvw
V6E>`"(5
?UUUUUU
?7zQ6$
.text$di
.text$mn
.text$mn$00
.text$mn$21
.text$x
.idata$5
.00cfg
.CRT$XCA
.CRT$XCAA
.CRT$XCU
.CRT$XCZ
.CRT$XIA
.CRT$XIAA
.CRT$XIAC
.CRT$XIC
.CRT$XIZ
.CRT$XPA
.CRT$XPX
.CRT$XPXA
.CRT$XPZ
.CRT$XTA
.CRT$XTZ
.rdata
.rdata$00
.rdata$r
.rdata$voltmd
.rdata$zzzdbg
.rtc$IAA
.rtc$IZZ
.rtc$TAA
.rtc$TZZ
.xdata
.xdata$x
.idata$2
.idata$3
.idata$4
.idata$6
.data$r
.data$rs
.pdata
_RDATA
.rsrc$01
.rsrc$02
GetModuleHandleA
GetProcAddress
LoadLibraryA
HeapCreate
KERNEL32.dll
DrawCaption
AnyPopup
CreateDialogParamW
GetDlgItem
IsDlgButtonChecked
ChangeClipboardChain
EnumClipboardFormats
IsClipboardFormatAvailable
GetPriorityClipboardFormat
CharUpperW
CharPrevExA
GetCapture
KillTimer
ModifyMenuW
SetMenuItemBitmaps
GetMenuCheckMarkDimensions
GetMenuItemInfoW
SetMenuDefaultItem
UpdateWindow
GetUpdateRect
GetWindowRgn
GetWindowRgnBox
SetScrollRange
EnumPropsW
GetCursorPos
SetRect
SubtractRect
GetWindowLongW
SetWindowLongW
DeregisterShellHookWindow
IsGUIThread
LookupIconIdFromDirectoryEx
MapDialogRect
InternalGetWindowText
USER32.dll
WritePrinter
AbortPrinter
ReadPrinter
ScheduleJob
FindNextPrinterChangeNotification
WINSPOOL.DRV
DecryptFileW
ADVAPI32.dll
VerFindFileW
VerInstallFileW
GetFileVersionInfoW
VERSION.dll
PropertySheetW
COMCTL32.dll
GdiplusStartup
gdiplus.dll
QueryPerformanceCounter
GetCurrentProcessId
GetCurrentThreadId
GetSystemTimeAsFileTime
InitializeSListHead
RtlCaptureContext
RtlLookupFunctionEntry
RtlVirtualUnwind
IsDebuggerPresent
UnhandledExceptionFilter
SetUnhandledExceptionFilter
GetStartupInfoW
IsProcessorFeaturePresent
GetModuleHandleW
RtlUnwindEx
GetLastError
SetLastError
EnterCriticalSection
LeaveCriticalSection
DeleteCriticalSection
InitializeCriticalSectionAndSpinCount
TlsAlloc
TlsGetValue
TlsSetValue
TlsFree
FreeLibrary
LoadLibraryExW
EncodePointer
RaiseException
RtlPcToFileHeader
GetStdHandle
WriteFile
GetModuleFileNameW
GetCurrentProcess
ExitProcess
TerminateProcess
GetModuleHandleExW
HeapAlloc
HeapFree
FindClose
FindFirstFileExW
FindNextFileW
IsValidCodePage
GetACP
GetOEMCP
GetCPInfo
GetCommandLineA
GetCommandLineW
MultiByteToWideChar
WideCharToMultiByte
GetEnvironmentStringsW
FreeEnvironmentStringsW
SetStdHandle
GetFileType
GetStringTypeW
FlsAlloc
FlsGetValue
FlsSetValue
FlsFree
LCMapStringW
GetProcessHeap
HeapSize
HeapReAlloc
FlushFileBuffers
GetConsoleOutputCP
GetConsoleMode
SetFilePointerEx
CreateFileW
CloseHandle
WriteConsoleW
R0ubymh
sMz2MN
$<B[d[L
+G(\'s
UAR0ZU
TMA-lR
.#I?%,&EU
U^fs5"
Qi/bM\*E
Q[g&5KB
Fr/y !V
,eG,a|
r#<Kmb
} i9v
zo/vEo
=mq?e">
%%uRsu(
Z:xBJT
s?mH=R
yIuPSLO
gbq@pL
~gk3dS
F0x_-]#<
WLkKfA
Neqi'y
z1BU"4
m8aH\7`IX
Hf7b`Zw
\pZu$A\
*t,>e6
rzbEyo
DdV(W1$H
~oM]I0ZN
jqCc@F[
!d>_;a
Mtx*jQ
vM4Q@h
.42\aV
6NTa?lT
6O+xYV
wrn@]h
vj)Vd\P
AHuQ'w
lYsF9.?`
h<d$<.14s
re"WXz
'15Do`
(%vKF3D$
zr\L3u'
e2EP%g|
0CPpY0
@b3%aK
4RPFi_
q>D4Av
b ZkI4
TT1NI:[
KAAI$*=
jS}u`E)
AW9o"
1<hW?^6
F*O4s'.-k
[Z:C&H
?5+-UU
NLS*:t
hTM_TQ
C6w[\$0
le[$UL
70N$0H*
?0/s)#
~>1beo
pL22^;
|TBU;|
=d](J*
O[@NuVP
m+"&2^4
/zj#)+
Fcq{}qz
4d_4=$2
S[J=6H
z-si)@en
@OuY4*
Um+u%
4j*X+A
>0fO3t48
~5`Fx#
-?{7UT
t|eb@@j&R
\= FXsOw
oDtV/8>
SF3f%u_'>
%{r6\~>
"*eW<{/*
~;UcRX
MB^)sp
@O1uH{
bwOwQ%|Y~
8F(cor
=19#@
ve+#3C
`j"tB{
l~B]+0
"Y[6w=+
;$?:OY8
hm+Rp>
=]N&Td\Gv$F#
>BGt,?
?Mg7J'
hQ5f#4
O{NH>Q
E[\G@^C
j'A?@kt%
RD?MBF
J".Xk4
\AF@p
/JMizJ
o}'|WJ
<2xkYm&
n<ewWKx
mm?J3hd
{f"4tR
$R|f72
Z%S!gD&
zT8L&>
wJ*agR
"|W4roA
q)`a+.
dRh`'RZ
fn(@tM
wc>sr
3L}=]p
ZGhqp
C6c?FaC
&=813
$>qc\2
>ADS(*
*;_#haD5
F!6F16
cwXv/T
6[gnI|[
a{Ou;[
QvbVh
v}X-Y6
sC=Xlr
=KXB~8C
UxWt{S
9Wr:(O
|q5uo?S
QQsL-;
HE+j6i
0b[Cm\
\%t3&c
bjdJ[H
1BxH./
Zt8)8y8i
`Ko#a
'/v+7}
|>1ta&Cz
#@~T;P
-4m2#7
"t(CPb
T%2B(E
vj#(ur
*I#Up3
9L?eEA
$Iz+ .A
C.Y"uz
@r)KdsF9d
NmAoNd^'
x:phF$
IzYO1=
5]*E#|
)'e#i?
"lltUy
hSVyV&
u9(TVwZ
TRe>`JO
H0:69q
jekUfS
<OS)Ot
bJCm)R
&iYey[
`=P\tIu
4}Ts7z)
5YI4|v
.\'BA#
DOM2)G!
|g#D,]>j*
f0M_LP
T,E31
&b|>c
C)Nz,T
X,;k+1J
:vpsh=
yuZk='C
{.-;NV
:Pud`6_l
?OL0sM
5",f}\
sz^h2,
{L{N\g
4O^@Ti
d'n_8[$
'(nWc$
a%hn?[
[""J>z
Z0csw7
@VJU>
TF:LS_
Y<bN!'<
a>H&yC`
P,UR1V
8twE 4S
k9bph0
d}YION
aJq_z/R\
qruP_/W
R%DbQq
Fbs\QM]
I^r5{.2
K mq q
NwO{>q
Xg7D8N
?Q,2.1
w:M\Ie
bKW^t^
Q.-xJ!T
\s&[]g
5t~9hWC
KE' Tx
j`9[ ,
Z:sM.:
R-^Cp7]e
/25^ib
@:^q1N}Y
cmk=^$
%:yZwe
zCP9_H
I?1ySy
kSYxa
,SvJ26
oC4@xUc
$}Gl"?
Q2saMz
b5(xQ|U
:#H^?P
Mf/\nX
_m|:,$
+=[+V^
rYPnwY79
&^8cm.9
*(G#8#Q
lgt~KI#
W_'7xW
*BgFx
H#whAdQ
kohhCA8
b4HB7aQ
huop>(
@0kCyT ar
>/zYtj_
v6~eVOQ
>zBYeC
:s6yu& *
=^*oB
_<W!@;
!09/Zt
.e;At
/c3Vgr
-$L1~`
'0bqE1Py
FYwaD^
"0 .{`R
z^.i)f
|mzJ2j
h;+^Hu
iO,9}h
g=2g2G
jx@bEsq
lBbj*/{Q?=
ibYIv&
@Y5&l$
o'P{W#
ne\pY''
liuJD)
]4{UPV
P>-WZ3
>e']joY
VF#9V{/
st#$YA
UkG,Y)t
,C}m.>
8svA8HDg
1S2dojV
T2=[i3
2<2V-S
=f><C>
`'<Il
iOPbxC
;%<KgD
jzYz#70%
n99@{A
fR6kMo
4<AW7*
j+>+A}s
lPPZiJ
[VD45-
3/mz4!
tnXh:2,%Fp~
^|&[7bc&p
AQ?@vq
k6@^VY
8>MD[5
yQ~T3XF^WDh
45T4pb
8U4hKq
apw,zR
e!]EDR
7Yte;p
!EwP}VU
jQ,'?]
,quo80
+H*x?k
96wQD(
\6EbZj
sR``[Eo!N
A"!.H~
gN+WqZf
M$E)B$
~$azy4@
@s 3?^
^9F+k+L
X$ua%n
S[ "\+}^
LA`z6R
]]6C9M
'qFxT2?#
2%0,,mUC
Is~kxMz
S(1:|'
AXMb\\o
C&W)2*
!+dB,9
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
.?AVbad_exception@std@@
.?AVexception@std@@
.?AVtype_info@@
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v3">
<security>
<requestedPrivileges>
<requestedExecutionLevel level="asInvoker" uiAccess="false"></requestedExecutionLevel>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
api-ms-win-core-fibers-l1-1-1
api-ms-win-core-synch-l1-2-0
kernel32
api-ms-
mscoree.dll
Sunday
Monday
Tuesday
Wednesday
Thursday
Friday
Saturday
January
February
August
September
October
November
December
MM/dd/yy
dddd, MMMM dd, yyyy
HH:mm:ss
((((( H
api-ms-win-core-datetime-l1-1-1
api-ms-win-core-file-l1-2-4
api-ms-win-core-file-l1-2-2
api-ms-win-core-localization-l1-2-1
api-ms-win-core-localization-obsolete-l1-2-0
api-ms-win-core-processthreads-l1-1-2
api-ms-win-core-string-l1-1-0
api-ms-win-core-sysinfo-l1-2-1
api-ms-win-core-winrt-l1-1-0
api-ms-win-core-xstate-l2-1-0
api-ms-win-rtcore-ntuser-window-l1-1-0
api-ms-win-security-systemfunctions-l1-1-0
ext-ms-win-ntuser-dialogbox-l1-1-0
ext-ms-win-ntuser-windowstation-l1-1-0
advapi32
kernelbase
api-ms-win-appmodel-runtime-l1-1-2
user32
ext-ms-
zh-CHS
az-AZ-Latn
uz-UZ-Latn
kok-IN
syr-SY
div-MV
quz-BO
sr-SP-Latn
az-AZ-Cyrl
uz-UZ-Cyrl
quz-EC
sr-SP-Cyrl
quz-PE
smj-NO
bs-BA-Latn
smj-SE
sr-BA-Latn
sma-NO
sr-BA-Cyrl
sma-SE
sms-FI
smn-FI
zh-CHT
az-az-cyrl
az-az-latn
bs-ba-latn
div-mv
kok-in
quz-bo
quz-ec
quz-pe
sma-no
sma-se
smj-no
smj-se
smn-fi
sms-fi
sr-ba-cyrl
sr-ba-latn
sr-sp-cyrl
sr-sp-latn
syr-sy
uz-uz-cyrl
uz-uz-latn
zh-chs
zh-cht
CONOUT$
VS_VERSION_INFO
StringFileInfo
040804B0
Comments
Schedule goth unwinding stewardesses avens corralled
CompanyName
Undercurrent sloped contrivances
FileDescription
Syndicates trial beguiled
FileVersion
2.260.311.5
InternalName
German
LegalCopyright
Copyright
Spaced unaudited inconspicuous collegial microscopes begat
LegalTrademarks
Severely phonemically scam whatever marching
OriginalFilename
Bridles
ProductName
Condensation
ProductVersion
2.260.311.5
VarFileInfo
Translation
Antivirus Signature
Bkav W64.AIDetectMalware
Lionic Trojan.Win32.Gatak.4!c
tehtris Clean
ClamAV Clean
CMC Clean
CAT-QuickHeal Trojan.Gatak
Skyhigh Clean
ALYac Trojan.GenericKD.72876461
Cylance Unsafe
Zillya Trojan.Gatak.Win32.369
Sangfor Trojan.Win64.Gatak.Vcjh
K7AntiVirus Riskware ( 00584baa1 )
Alibaba Trojan:Win32/Gatak.dc930dc3
K7GW Riskware ( 00584baa1 )
Cybereason malicious.d1856c
Baidu Clean
VirIT Clean
Paloalto generic.ml
Symantec ML.Attribute.HighConfidence
Elastic malicious (high confidence)
ESET-NOD32 a variant of Win64/GenKryptik.GYOY
APEX Malicious
Avast Win64:TrojanX-gen [Trj]
Cynet Malicious (score: 99)
Kaspersky Trojan.Win32.Gatak.fkp
BitDefender Trojan.GenericKD.72876461
NANO-Antivirus Clean
ViRobot Clean
MicroWorld-eScan Trojan.GenericKD.72876461
Tencent Clean
TACHYON Clean
Sophos Mal/Generic-S
F-Secure Trojan.TR/Gatak.qoscg
DrWeb Clean
VIPRE Trojan.GenericKD.72876461
TrendMicro TROJ_GEN.R002C0XET24
McAfeeD ti!F4E2ECF1687A
Trapmine Clean
FireEye Generic.mg.85a156ed1856c0ed
Emsisoft Trojan.GenericKD.72876461 (B)
SentinelOne Clean
GData Trojan.GenericKD.72876461
Jiangmin Clean
Webroot W32.Trojan.Gen
Varist W64/ABRisk.OGGJ-0017
Avira TR/Gatak.qoscg
Antiy-AVL Trojan/Win32.Gatak
Kingsoft Win32.Trojan.Gatak.fkp
Gridinsoft Clean
Xcitium Clean
Arcabit Trojan.Generic.D45801AD
SUPERAntiSpyware Clean
ZoneAlarm Trojan.Win32.Gatak.fkp
Microsoft Trojan:Win64/CobaltStrike.PK!MTB
Google Detected
AhnLab-V3 Clean
Acronis Clean
McAfee Clean
MAX malware (ai score=84)
VBA32 Trojan.Gatak
Malwarebytes Generic.Malware/Suspicious
Panda Trj/Chgt.AD
Zoner Clean
TrendMicro-HouseCall TROJ_GEN.R002C0XET24
Rising Trojan.Gatak!8.517 (C64:YzY0Og1zgZH+0uIA)
Yandex Trojan.Gatak!OiVkHKNpHHs
Ikarus Trojan.Gatak
MaxSecure Win.MxResIcn.Heur.Gen
Fortinet W32/PossibleThreat
BitDefenderTheta Clean
AVG Win64:TrojanX-gen [Trj]
DeepInstinct MALICIOUS
CrowdStrike win/malicious_confidence_90% (D)
alibabacloud Suspicious
No IRMA results available.