Static | ZeroBOX

PE Compile Time

2024-02-10 17:49:34

PE Imphash

30ca3ef40f58b346fdf8b0c3248813a9

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x00105c28 0x00105e00 6.101867414
.rdata 0x00107000 0x00006f8a 0x00007000 4.77982390834
.data 0x0010e000 0x000691c4 0x00068800 7.99691571386
.reloc 0x00178000 0x00001344 0x00001400 6.46815348757
.rsrc 0x0017a000 0x0005aa24 0x0005ac00 3.07805905205

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x001d42a0 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x001d42a0 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x001d42a0 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x001d42a0 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x001d42a0 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x001d42a0 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_GROUP_ICON 0x001d4708 0x0000005a LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_VERSION 0x001d4764 0x000002c0 LANG_ENGLISH SUBLANG_ENGLISH_US data

Imports

Library USER32.dll:
0x50712c TranslateMessage
0x507130 KillTimer
0x507134 DispatchMessageW
0x507138 GetMessageW
0x50713c SetTimer
Library KERNEL32.dll:
0x507000 LoadLibraryExW
0x507004 WriteConsoleW
0x507008 CloseHandle
0x50700c CreateFileW
0x507010 GetDiskFreeSpaceExA
0x507014 GetTempFileNameW
0x507018 HeapAlloc
0x50701c HeapFree
0x507020 GetCurrentProcess
0x507024 GetSystemTime
0x507028 VirtualProtect
0x50702c GetModuleHandleA
0x507030 GetProcAddress
0x507034 LoadLibraryA
0x507038 lstrcmpiA
0x50703c lstrlenA
0x507040 FreeConsole
0x50704c TerminateProcess
0x507058 GetCurrentProcessId
0x50705c GetCurrentThreadId
0x507064 InitializeSListHead
0x507068 IsDebuggerPresent
0x50706c GetStartupInfoW
0x507070 GetModuleHandleW
0x507074 SetFilePointerEx
0x507078 GetConsoleMode
0x50707c RaiseException
0x507080 GetLastError
0x507084 SetLastError
0x507088 EncodePointer
0x50709c TlsAlloc
0x5070a0 TlsGetValue
0x5070a4 TlsSetValue
0x5070a8 TlsFree
0x5070ac FreeLibrary
0x5070b0 DecodePointer
0x5070b4 GetStdHandle
0x5070b8 WriteFile
0x5070bc GetModuleFileNameW
0x5070c0 ExitProcess
0x5070c4 GetModuleHandleExW
0x5070c8 GetCommandLineA
0x5070cc GetCommandLineW
0x5070d0 FindClose
0x5070d4 FindFirstFileExW
0x5070d8 FindNextFileW
0x5070dc IsValidCodePage
0x5070e0 GetACP
0x5070e4 GetOEMCP
0x5070e8 GetCPInfo
0x5070ec MultiByteToWideChar
0x5070f0 WideCharToMultiByte
0x507100 SetStdHandle
0x507104 GetFileType
0x507108 GetStringTypeW
0x50710c CompareStringW
0x507110 LCMapStringW
0x507114 GetProcessHeap
0x507118 HeapSize
0x50711c HeapReAlloc
0x507120 FlushFileBuffers
0x507124 GetConsoleOutputCP
Library ntdll.dll:
0x507144 RtlUnwind

!This program cannot be run in DOS mode.
oD}FoD}FoD}F$<~GdD}F$<xG
D}F$<yG{D}Fi
yG}D}Fi
~GzD}F$<|GhD}FoD|F0D}Fi
xGED}F
xGnD}F
GnD}FRichoD}F
`.rdata
@.data
.reloc
B.rsrc
QQSVWd
URPQQh
UQPXY]Y[
uSSSSj
f9:t!V
QQSVj8j@
PPPPPPPP
PPPPPWV
PP9E uPPSWP
PVVVVV
ntdll.dll
NtAllocateVirtualMemory
aoaYGLRmwZ
winmm.dll
timeGetTime
SystemDrive
winmm.dll
timeGetTime
winmm.dll
timeGetTime
Unknown exception
bad array new length
string too long
vector too long
@bad allocation
bad exception
__based(
__cdecl
__pascal
__stdcall
__thiscall
__fastcall
__vectorcall
__clrcall
__eabi
__swift_1
__swift_2
__swift_3
__ptr64
__restrict
__unaligned
restrict(
delete
operator
`vftable'
`vbtable'
`vcall'
`typeof'
`local static guard'
`string'
`vbase destructor'
`vector deleting destructor'
`default constructor closure'
`scalar deleting destructor'
`vector constructor iterator'
`vector destructor iterator'
`vector vbase constructor iterator'
`virtual displacement map'
`eh vector constructor iterator'
`eh vector destructor iterator'
`eh vector vbase constructor iterator'
`copy constructor closure'
`udt returning'
`local vftable'
`local vftable constructor closure'
new[]
delete[]
`omni callsig'
`placement delete closure'
`placement delete[] closure'
`managed vector constructor iterator'
`managed vector destructor iterator'
`eh vector copy constructor iterator'
`eh vector vbase copy constructor iterator'
`dynamic initializer for '
`dynamic atexit destructor for '
`vector copy constructor iterator'
`vector vbase copy constructor iterator'
`managed vector copy constructor iterator'
`local static thread guard'
operator ""
operator co_await
operator<=>
Type Descriptor'
Base Class Descriptor at (
Base Class Array'
Class Hierarchy Descriptor'
Complete Object Locator'
`anonymous namespace'
FlsAlloc
FlsFree
FlsGetValue
FlsSetValue
InitializeCriticalSectionEx
_hypot
_nextafter
CorExitProcess
Sunday
Monday
Tuesday
Wednesday
Thursday
Friday
Saturday
January
February
August
September
October
November
December
MM/dd/yy
dddd, MMMM dd, yyyy
HH:mm:ss
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
AreFileApisANSI
CompareStringEx
LCMapStringEx
LocaleNameToLCID
AppPolicyGetProcessTerminationMethod
?5Wg4p
%S#[k=
"B <1=
.text$mn
.text$x
.idata$5
.00cfg
.CRT$XCA
.CRT$XCAA
.CRT$XCZ
.CRT$XIA
.CRT$XIAA
.CRT$XIAC
.CRT$XIC
.CRT$XIZ
.CRT$XPA
.CRT$XPX
.CRT$XPXA
.CRT$XPZ
.CRT$XTA
.CRT$XTZ
.rdata
.rdata$r
.rdata$sxdata
.rdata$voltmd
.rdata$zzzdbg
.rtc$IAA
.rtc$IZZ
.rtc$TAA
.rtc$TZZ
.xdata$x
.idata$2
.idata$3
.idata$4
.idata$6
.data$r
.data$rs
GetMessageW
TranslateMessage
DispatchMessageW
SetTimer
KillTimer
USER32.dll
GetDiskFreeSpaceExA
GetTempFileNameW
HeapAlloc
HeapFree
GetCurrentProcess
GetSystemTime
VirtualProtect
GetModuleHandleA
GetProcAddress
LoadLibraryA
lstrcmpiA
lstrlenA
FreeConsole
UnhandledExceptionFilter
SetUnhandledExceptionFilter
TerminateProcess
IsProcessorFeaturePresent
QueryPerformanceCounter
GetCurrentProcessId
GetCurrentThreadId
GetSystemTimeAsFileTime
InitializeSListHead
IsDebuggerPresent
GetStartupInfoW
GetModuleHandleW
KERNEL32.dll
RtlUnwind
ntdll.dll
RaiseException
GetLastError
SetLastError
EncodePointer
EnterCriticalSection
LeaveCriticalSection
DeleteCriticalSection
InitializeCriticalSectionAndSpinCount
TlsAlloc
TlsGetValue
TlsSetValue
TlsFree
FreeLibrary
LoadLibraryExW
GetStdHandle
WriteFile
GetModuleFileNameW
ExitProcess
GetModuleHandleExW
GetCommandLineA
GetCommandLineW
FindClose
FindFirstFileExW
FindNextFileW
IsValidCodePage
GetACP
GetOEMCP
GetCPInfo
MultiByteToWideChar
WideCharToMultiByte
GetEnvironmentStringsW
FreeEnvironmentStringsW
SetEnvironmentVariableW
SetStdHandle
GetFileType
GetStringTypeW
CompareStringW
LCMapStringW
GetProcessHeap
HeapSize
HeapReAlloc
FlushFileBuffers
GetConsoleOutputCP
GetConsoleMode
SetFilePointerEx
CreateFileW
CloseHandle
WriteConsoleW
DecodePointer
wgL87p
VMJhBu
&!yVQJG
`8>Lz%
$E5`RR
%v]8F&
U4/l-n
>U&?_D|
6oL_i;
XnOCJq
3>*l5i
lCrls]S
%FrURq\t
,'X<*e.e
!lZ@|l
dn'"7v
3at7pJ
P'(oic
N eew
%]IWS+
BZ3Q9h(
[Uy-Pr
CI!ta'
K<Mgo^F
Qh^UpO"<:
m~YChz
SVk*7z`3
?S?v0
VJ@T-Wx$
'M"Fj`
G~;=PI)i
Qr4@/Gx
Tj:";)U
M-6'xI
3L%ZJ.
JY~%Xy
[F]<#F
4yiy+=C
sU(>zk
j:!o$M
N3_+UX
x1-Q\0
j|2AV64
#UkI%8
"E@S8^e
cy'l,,
ZjA0?k
Q@j.$0(
y,JHEYQ
T7\@~PkB
v-1<m:7
8-T|(zw;x*
||RlUx
My|)F
7DF>dB
#^NLn_
:t+WqGV
W~smdlu
}6@8&[
^/Pr!
-YK@`f
"+%&:j
Q#?v57
KVghJT
H_AF+r
V/T/Hu
>qY@pT+
%4=`3"p-&
L0\\?:s.
[OW-]r$
A/mqn<o
J5u<R>g:
_ecvXKI
n%-~^4
wxQ[QA
WnXy1k_
{l8JhM
1?QB+O
Hi>`JH
B"c>qkm
9Ugoe>
DU,uutP
pfTo+2$
X+nykF
WOW)dV:,
mFLF"
\CbSn7@
.ee@>R
%N+aHzgPB
T[=wPqo
$fiE:z
gdXA_q
-~ XEl(#
/yMiuB
;$Nm*s
%X0S&"
0i^QK%+
0dhm[q\O
9n]?9}
x<5N|}
7 Q_)S
gGX%c
Af{{YD
|hh)J9
Gpz]t0
5t>2X
5D&(!wz
=_v%G>
}/. sF
B-}%K)
Hchp)j{B
F2FQ;+y
A )(/F9
h>},ml"
vqkK"fl
fs<=@G
gA(g#Ar)
b1:Oa[
xHWeYb+$
a4RAH$
]+L4?6
[KJu^m
,#qXO2
Yv$x-j
t6;6F%,\
4/",7]ml
Ft3OR~Gg
"i|j+OR
"{023f>
z( fy*
0%XG$L
an@rl
4B7zX
M5D9^&=83m
_HC3Y*
45Z>X8
Jg)0u^d,
RM,cYS
q`C#{c &
y^X9%/
Z.x[]H
%u}py,[
q.&\"LQ
7Cm{`5
Zqq%E
)uNai5
W{CI^#
RYk967
6jHswS
xhIvR=
S Kh6U
w_zu3/>J
vx<<1M
LBi5RwX
h>`><C
JPAed~
$u~_m@
VO=?ybC
6#dKS;
Rk]v.K
[LzoYH
e|0e9c0
a@pn\5
|5C%]t-<
SN~kV;
$LfK5F
P{XyiK
-X}+7@t
5[oP#V
XhAE}r
Vlg?3-
~HzTT3T
VvPsCy
n*.<jXO
{WC/i4_^p
%'18TVz
[;9Q9]e
#)}ka5
2IE1*h#8
jDm93m
0[HfHZ
1u032q\
%}T>g:Ss
ST jZ8
9*|Wp]'hI
[Q7e:b
?%9W"0
)P\;{JW_2
Wu!Mo_2
F_nsja
&O>Y0/
Q8j\R%
-UNt`q
.Lcq"i
O#n+bTt
E=x+_5
G694T=
j_2skA
N%kpp3
1X*P7/3j^
FP!/1q
U0g{ .
*sgo$:
9{\77X^
=KP@]t
+|'D#m4m
=~K X[
1&d!'b
i42_3U
_ad{+.
>{-J$T@I5
C]K^1A
(5_ +X
YBBeKX)
WgU\)op
N_YCWD[
G}i1`2
g"74=L3
`NvJyA{
tC,3pi
h\]t[ZJ
SY5K<B
,8yU:v
}Q;4d+
U4Lz.~
>0igr/
!3BX&A3U
\M`'=sA
$!X%|S
o\,dXF
frT:WG6n6
tmxi-.
*vd-\X
lxwV(Sn
)27y2'
QDhn~p(
M:hyVw'`
CrR5&#
91MKG4
0qp^!1H
]eYF&Z
]uEqi:
u;w]aY\
H*qwr^Yg
Pas^7*
JEzAc6
v;!I;CV>z
d \A(<
v945)q/ =D\
2D&0>2
-Fnmy"
p6-=X`[
uP0MV3
b=a*6m+
2*2C\9F
`K{%{1
G*p%gp
n!hH`0N
"HA7T^k
@F<aw/
@a>O9)
h`ihSa
o/9;\X
SIQJY,5
[@Xg5Q
=VTYgZ
+,/(S%
PBzuOBr
`N*0"0
]%BFBi
k@|<]B
"F8z[D
N[=P^D*
8UB>6j
s@YzkR
[ly[9t
GD`JbX
f:T3|j
VEJ:#B
__ Yhf
j>h"Z
:)ywmr
K!u=uH[gQ
L.B-{-
1H$/'!
[QdT{_[ZOD
2}a:$W$
!6dL2*
E**kr:yF
#&Y;*<
!/\>9i
s y{N:4\~,
f]LDQM*
REmM\H
THSTmn
l|otI8G*
yk@> SI
cJa0q~
d?6/l@
M;#Joir
pvo:!O
98;5?Y
7xNmN19H
?xb5[d5
!YyDXEb
IwjR[Yb
?wZw<h
+qSe+.
jx^UWh
~Z'BKIE^
HH`{Cx
@-d,#]
NAMr!
u(v9):
"ld=+ac
L+&=^"L
aN`PNI
a)4Mt?
LcgR(G
lete6~
d}!G_VIF3
h21?MV
53>~ScMl
X0fnK;
,0Y#X|
#!a;4-
gEdqL"`a%j
<=%-9Gk
)1<`qy
5J!AQ^
Ph,(U"
u 95Gf
3%E8#X}
2HY>ZV
vtwljr
Y0A_`
siNN38i@
V39m2B
)%1d}1kp
dGkdtL
A74(Vy
|}}vOWt
Ac:J6u
\lnk(S
#l#1-]
PAb?a2
BIIvS}
-!pa8=
^,*M4=
$|/L'h
}v4X'.
B\;Lo_Ck
_[Q1{S
>D,v"Q
n2d$.p
H*o)rkI
YQ?V$>
#S0A#ip
_tCRMh
-cv|^
I]eH@.
# l">~h
{|=T//>
u!wN!e
NCB3:5
Z3,e$&
et`/hH
OA>o9*O
A~$} K
e~K"RHg
HI<Lv:
6U}>s%
U6 T~z
Q:(`|R
*/[j\J
JSc@.yJ
uB>9k>
'[\9&,]
1sMjiJ
1m.j3*
P?[.m8k
kD=]YL
wLgQ\?i
@MS3Pz
X']wVS
kA1"Lu
3r?u<)#
E5&lK+
Mh]nyA
k1\]-f
KJX|^s
[;T84iW
:V.XA1
_3^q00
j(~HAH
npOfd^V
C3_Q#XFe
km@;Si/
%u{T;W3
>%-x[#
^al<N'z
jeF'wI
cj=7Bs
*T%`"0(J
)5NL{N0
W[!.BZXe
SYalg#Hi
}?A$MUO
JPfgX>
0CGmYsn
B*avUg
?5hdUR&
OzUcv2
Dj}:)5
$iN?TX
b{TG~x(
c3f|Zm
{,#[6X
(g]k(No
+NvoSM-
;"9F|;
v)d?,*
s</^p%
)C\jSF'E
Fj5#bC
D{QGV[
)E9^AQ
?vG!+w
S|ZN#I:5+(
\|o];5H3b
d~Czp-@
g%SMYGc2
g;R)H3
B6mivN#lKRH
);1:`r
q/qn_90
]" &nB
$Ga0i6
gYVK]#G
F3%5yQ
9Ll%]Wo
;3)[@v
S0^S:Dr9
6]\1T>
7f4BqN
BAEm.TPQ
N@pfrCsL
>pgw[R
Xt"tlg<
X@ll#/
|%5v]7
aI<j~Q
u+P@IJ
x/rWS5
fiQh53
T:cuFW
:CJ([*
@brJWU
:4XX,(
^-<r>pw
8}"!b\
?\rU,.
3o-jC/j]
T$CiCH
9D}1ZI
slBX*
f<7&tq
gqY"pRH
8wOt-loJ
=5qgr[7^
Q@G$^1
`Pz'rw
Vk<@hl
g0k*wM
A63P`h:
U{)6'D)
.hKFC^[
f:{){=
9?<m;J*[
Ab}0L<
tXX#s'
K60<^"
J@EV4p
vj]>6h
},1+w
Cs'@_s
epo*Dy
dFKAKj
PzYL+^
F@zNlw7
i']S9}
rbvmG[
Dq=+En
-=,e]+J
?X[qr>
uT+\20
UiGH?0
)]qpAv[
fx8HA
,t/u,5
X"BJ1:f
{&8Y[\
R~4EN9Z>v
ME,j9ol|
luGire;|
(qe~dl
^,+\OgJ
X PUsm
5EAj"90
u+T9OF)$
:\@GY;
k:x^E*bO
?o%(%
C%8YU<
iB:/FY
pxC}Y>(
S(ND/1
h]/1iT
CR{*"Z5
H9`F4-b
<gm76\
F^|O2d
`LHmRF
273CTX
mzlX{u6
ZiKmaNJ
+<k_h8
}Azzte%"
^lt;m4
`8J6M_
-=nykR,
HL^^J}
QMD+n5
P5S9$~
(&m aq0Z
:tRsa'
''Deo8
)Y| y|
TyY$3d
*s-fpg-
&=RO8&]l
s+5aJ4
<Blmn)U
[/E-gT>9 P(O4\W
M2svm1
I+ck.h0"
[/9<u=M
kt9d/X
K+NR~a
f!2loS
a',R28
3[01Y-k`
{hfmY<
Ba@VNc
b6>k>
[(TmaX<
K083PP
z9Mf\_
5GhQ+~
cF"e+3"[
Db$zR
}WMry6
z@ahBw
4{I:-:
W`k{CL
Z"U?Ll
+bkDQv
tfd>2pF
H7CKJSH
}H>-sV
5BT%)53
I3Df>nh
oR|*.#
Q1U}LB
Zsr5"v
'r"Z]F
yH'7)D
:sI:Gj
G6TEUsk[
=zVQIf
+7)5I|
]z'fYJ
X?Uutl%
S}}}6Gqe
DE 2v<
]T@^ek
&u)qGk23]
yGA}Y
C&vB;0Rk
Mt-PM+
}v+48n
R9{LRPh
6/&Z:v
w7S,+(_H
"lr#H
`S9zJKY
}*,1823:
KmG~Cl
Hx]N"|n
v*Ld:L
]^M%\}
VwK&
-U8l3g
E"]]hE
T7++P\t1
(DKl.4
mP{-^
UmC<Bh
K!5J$J'
u`P}.
%4c"[_
DUp)iN
LAjOW
.e9b>dx
!&--um
MaY}Fg
%;R^V%Rg
s0wBQjR
0[u D^8
21XiDq
DmmQwLP`4
vE)+'+3
TJ,[=9[
tv_&bT
RB"(R\
u*IZ):=
DwigpY>s
-6)y@J
iD_{Cv!
Q8f\o,
@`8)?C
T4(C8N
KQqp8Y
,QW.t"uaY
nZmLrw
uJ):>k
`(bvAV
'teNvq
cdo-
ygKgt%
(1t,9T
z~@/R1
+@L]?II
|$GR)1
OI-V=s
v E4dN$
Du~JDs
Q\S y_
Xm&~j(F
?ZK#b5
qh*g|4
c)tSH
`OOn]Y
gE&HzS
i&qt:m
9c2/\$
zp/MiL@
rM#'*Ki
d15/*:c
EP':N#
A_7vdJ(
#DStRA
.\kFr:
VDw^ez
|?h-q(*m
9")6u/
_ZB*\2
,X<SHh
cM`k&+
vT"!8B
afL2_L
J1+hfw
H cv]c
:Cr6M]0
rLXrU4
>[A6>=
rVV<JA
E*bpf+
n=SB9g
A.kr{O
|`TNVc
-;HB59'Q
gA6v]8
X?Bwp3Z
Oqh};Cb){
h:1v\j
Aq!e!`W
qEQ_M$7
7.O VX
?R:R+K
]"%P^hn
%aFarib1
?pZUaZ
.)_F-d
#v[z&1M
8^BQ@)`
yNZjV\$
z3t*6tiP
%?Lwa$
r}K@y9
fgGV2Q
nj2nvk
nn>=i,:
jP~V)R
up"Y`*
*_%Q!I
u6@&ZH
>R6~mN<
Z^H|Xr
)L/93J
w$Z:UwG
KOd>SlL
N}K0I8B
fJSb{x,
x#{1M(
YI"RRx
uXD&7,
%umLrL
b,AweR]
Dv$b9P
B=*<qxZ29,
.[I&%O
'/tk-z
BR_\Q#
Xfb}!
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
.?AVbad_array_new_length@std@@
.?AVbad_alloc@std@@
.?AVexception@std@@
.?AVlogic_error@std@@
.?AVlength_error@std@@
.?AVbad_exception@std@@
.?AVtype_info@@
2Q3,4O7
7*8N8)=B=U=u=
111v1w3
4&5=5X5e5S8
4!4D4Q4t6
;6=E=f=
>&>V?b?
2f4u4&555
5666E6
0"020I0}0
234393>3_3d3q3
5$5+52595@5G5N5V5^5f5r5{5
7&7U7^7g7u7~7
:&:/:<:R:
=)=A=^=
4D4W4u4
416h6o6t6x6|6
7 7$7(7,7
5%5A5K5U5c5~5
0(10353u3
5!5>5f5z5
6"6'6,6G6T6]6b6g6
7<7L7d7
;3;:;C;
?*?@?V?^?
616?6K6^6f6l6u6
67.777E7
<'<><L<_<j<u<
=N=[=j=~=
?*?C?K?T?]?n?
H0T0Y0_0d0l0r0z0
4B4k4{4
5 5,5F5
6,6=6B6
<J<Y<k<~<
=#=G=N=m=
>@>U>e>r>
061%2>2k2r2}2
4J5\5n5
; <8<k<
1&151?1L1V1f1
<<-<4<
-0<0J0g0o0
12Q2l2
4)4;4M4_4q4
9(:?:_:
;+;0;5;E;J;O;w;
<!<6<?<H<y<
===a=q=v={=
>#>.>3>8>V>e>p>u>z>
?,?C?L?c?u?
0<1C1J1Q1^1
3E4_4d4g6
7#7>7K7Y7g7r7
;&<0<S<]<
>.?C?M?
0.0d0|0
7A8b839Y9
;(;>;K;P;^;
181C1P1b1
1G2\2e2n2
2s4y4~4
6!7&7i7q7y7
818=8I8i8
9*9=:n:
>k>l?|?
0(0.070q0
1\1e1n1w1
3&4E4v4"6
:$:D:q:
L1X1d1h1l1p1t1x1
2X3\3`3d3h3l3
4 4(40484@4H4P4X4`4h4p4x4
5 5(50585@5H5P5X5`5h5p5x5
6 6(60686@6H6P6X6`6h6p6x6
7 7(70787@7H7P7
?$?,?4?<?D?L?T?\?d?l?t?|?
1 1(1,1014181<1@1D1L1P1T1X1\1`1d1h1t1|1
2 2$2(2,2024282<2@2L2P2T2X2\2`2d2h2l2p2t2x2|2
78><>@>D>H>L>P>T>X>\>`>d>h>l>p>t>x>|>
4$4,444<4D4L4T4\4d4l4t4|4
5$5,545<5D5L5T5\5d5l5t5|5
6$6,646<6D6L6T6\6d6l6t6|6
7$7,747<7D7L7T7\7d7l7t7|7
8$8,848<8D8L8T8\8d8l8t8|8
9$9,949<9D9L9T9\9d9l9t9|9
:$:,:4:<:D:L:T:\:d:l:t:|:
5 5(50585@5H5P5X5`5h5p5x5
6 6(60686@6H6P6X6`6h6p6x6
7 7(70787@7H7P7X7`7h7p7x7
8 8(80888@8H8P8X8`8h8p8x8
9 9(90989@9H9P9X9`9h9p9x9
: :(:0:8:@:H:P:X:`:h:p:x:
; ;(;0;8;@;H;P;X;`;h;p;x;
< <(<0<
*6.62666L?P?X?
0 0$0,0D0T0X0h0l0p0x0
1,1<1@1P1T1X1\1d1|1
8$8,848<8D8L8T8\8d8l8t8|8
9$9,949<9D9L9T9\9d9l9t9|9
;H;\;p;
;(<<<P<d<x<
?0?D?X?l?
0 040H0\0p0x0
101<1\1h1
2 2(20282<2D2X2`2h2p2t2x2
383@3D3T3x3
404P4X4`4l4
5$5X5x5
64686X6x6
787X7x7
? ?,?0?4?P?T?
7,7L7l7
Greater Manchester1
Salford1
Comodo CA Limited1!0
AAA Certificate Services0
210525000000Z
281231235959Z0V1
Sectigo Limited1-0+
$Sectigo Public Code Signing Root R460
H/(@Bp 6
2http://crl.comodoca.com/AAACertificateServices.crl04
http://ocsp.comodoca.com0
DigiCert Inc1
www.digicert.com1$0"
DigiCert Assured ID Root CA0
220801000000Z
311109235959Z0b1
DigiCert Inc1
www.digicert.com1!0
DigiCert Trusted Root G40
]J<0"0i3
v=Y]Bv
http://ocsp.digicert.com0C
7http://cacerts.digicert.com/DigiCertAssuredIDRootCA.crt0E
4http://crl3.digicert.com/DigiCertAssuredIDRootCA.crl0
~qj#k"
Sectigo Limited1-0+
$Sectigo Public Code Signing Root R460
210322000000Z
360321235959Z0T1
Sectigo Limited1+0)
"Sectigo Public Code Signing CA R360
FFlCx@
H/(@Bp 6
:http://crl.sectigo.com/SectigoPublicCodeSigningRootR46.crl0{
:http://crt.sectigo.com/SectigoPublicCodeSigningRootR46.p7c0#
http://ocsp.sectigo.com0
ts7!:o
n0PPd}
Sectigo Limited1+0)
"Sectigo Public Code Signing CA R360
220207000000Z
240207235959Z0L1
Washington1
Balena Inc1
Balena Inc0
bV_xj+
https://sectigo.com/CPS0
8http://crl.sectigo.com/SectigoPublicCodeSigningCAR36.crl0y
8http://crt.sectigo.com/SectigoPublicCodeSigningCAR36.crt0#
http://ocsp.sectigo.com0
accounts@balena.io0
5(yujP
Uz^40FU
(f*^[0
DigiCert Inc1
www.digicert.com1!0
DigiCert Trusted Root G40
220323000000Z
370322235959Z0c1
DigiCert, Inc.1;09
2DigiCert Trusted G4 RSA4096 SHA256 TimeStamping CA0
http://ocsp.digicert.com0A
5http://cacerts.digicert.com/DigiCertTrustedRootG4.crt0C
2http://crl3.digicert.com/DigiCertTrustedRootG4.crl0
DigiCert, Inc.1;09
2DigiCert Trusted G4 RSA4096 SHA256 TimeStamping CA0
220921000000Z
331121235959Z0F1
DigiCert1$0"
DigiCert Timestamp 2022 - 20
Ihttp://crl3.digicert.com/DigiCertTrustedG4RSA4096SHA256TimeStampingCA.crl0
http://ocsp.digicert.com0X
Lhttp://cacerts.digicert.com/DigiCertTrustedG4RSA4096SHA256TimeStampingCA.crt0
Sectigo Limited1+0)
"Sectigo Public Code Signing CA R36
$https://github.com/balena-io/etcher 0
)|^Xk{
DigiCert, Inc.1;09
2DigiCert Trusted G4 RSA4096 SHA256 TimeStamping CA
230712153043Z0/
Greater Manchester1
Salford1
Comodo CA Limited1!0
AAA Certificate Services0
210525000000Z
281231235959Z0V1
Sectigo Limited1-0+
$Sectigo Public Code Signing Root R460
H/(@Bp 6
2http://crl.comodoca.com/AAACertificateServices.crl04
http://ocsp.comodoca.com0
Sectigo Limited1-0+
$Sectigo Public Code Signing Root R460
210322000000Z
360321235959Z0T1
Sectigo Limited1+0)
"Sectigo Public Code Signing CA R360
FFlCx@
H/(@Bp 6
:http://crl.sectigo.com/SectigoPublicCodeSigningRootR46.crl0{
:http://crt.sectigo.com/SectigoPublicCodeSigningRootR46.p7c0#
http://ocsp.sectigo.com0
ts7!:o
n0PPd}
Sectigo Limited1+0)
"Sectigo Public Code Signing CA R360
220207000000Z
240207235959Z0L1
Washington1
Balena Inc1
Balena Inc0
bV_xj+
https://sectigo.com/CPS0
8http://crl.sectigo.com/SectigoPublicCodeSigningCAR36.crl0y
8http://crt.sectigo.com/SectigoPublicCodeSigningCAR36.crt0#
http://ocsp.sectigo.com0
accounts@balena.io0
5(yujP
Uz^40FU
Sectigo Limited1+0)
"Sectigo Public Code Signing CA R36
$https://github.com/balena-io/etcher 0
vc!0-/
Yag",8
20230712153044Z
DigiCert, Inc.1;09
2DigiCert Trusted G4 RSA4096 SHA256 TimeStamping CA0
220921000000Z
331121235959Z0F1
DigiCert1$0"
DigiCert Timestamp 2022 - 20
Ihttp://crl3.digicert.com/DigiCertTrustedG4RSA4096SHA256TimeStampingCA.crl0
http://ocsp.digicert.com0X
Lhttp://cacerts.digicert.com/DigiCertTrustedG4RSA4096SHA256TimeStampingCA.crt0
(f*^[0
DigiCert Inc1
www.digicert.com1!0
DigiCert Trusted Root G40
220323000000Z
370322235959Z0c1
DigiCert, Inc.1;09
2DigiCert Trusted G4 RSA4096 SHA256 TimeStamping CA0
http://ocsp.digicert.com0A
5http://cacerts.digicert.com/DigiCertTrustedRootG4.crt0C
2http://crl3.digicert.com/DigiCertTrustedRootG4.crl0
DigiCert Inc1
www.digicert.com1$0"
DigiCert Assured ID Root CA0
220801000000Z
311109235959Z0b1
DigiCert Inc1
www.digicert.com1!0
DigiCert Trusted Root G40
]J<0"0i3
v=Y]Bv
http://ocsp.digicert.com0C
7http://cacerts.digicert.com/DigiCertAssuredIDRootCA.crt0E
4http://crl3.digicert.com/DigiCertAssuredIDRootCA.crl0
~qj#k"
DigiCert, Inc.1;09
2DigiCert Trusted G4 RSA4096 SHA256 TimeStamping CA
230712153044Z0+
/1(0&0$0"
YQx]xm
yetpoMvXBPP
CDuYgbclre
paqjyanUTv
ifgwCqktJm
ivGVPmQDOS
Papi-ms-win-core-fibers-l1-1-1
api-ms-win-core-synch-l1-2-0
kernel32
api-ms-
mscoree.dll
Sunday
Monday
Tuesday
Wednesday
Thursday
Friday
Saturday
January
February
August
September
October
November
December
MM/dd/yy
dddd, MMMM dd, yyyy
HH:mm:ss
Pja-JP
((((( H
Papi-ms-win-core-datetime-l1-1-1
api-ms-win-core-file-l1-2-4
api-ms-win-core-file-l1-2-2
api-ms-win-core-localization-l1-2-1
api-ms-win-core-localization-obsolete-l1-2-0
api-ms-win-core-processthreads-l1-1-2
api-ms-win-core-string-l1-1-0
api-ms-win-core-sysinfo-l1-2-1
api-ms-win-core-winrt-l1-1-0
api-ms-win-core-xstate-l2-1-0
api-ms-win-rtcore-ntuser-window-l1-1-0
api-ms-win-security-systemfunctions-l1-1-0
ext-ms-win-ntuser-dialogbox-l1-1-0
ext-ms-win-ntuser-windowstation-l1-1-0
advapi32
kernelbase
api-ms-win-appmodel-runtime-l1-1-2
user32
api-ms-win-core-fibers-l1-1-0
ext-ms-
zh-CHS
az-AZ-Latn
uz-UZ-Latn
kok-IN
syr-SY
div-MV
quz-BO
sr-SP-Latn
az-AZ-Cyrl
uz-UZ-Cyrl
quz-EC
sr-SP-Cyrl
quz-PE
smj-NO
bs-BA-Latn
smj-SE
sr-BA-Latn
sma-NO
sr-BA-Cyrl
sma-SE
sms-FI
smn-FI
zh-CHT
az-az-cyrl
az-az-latn
bs-ba-latn
div-mv
kok-in
quz-bo
quz-ec
quz-pe
sma-no
sma-se
smj-no
smj-se
smn-fi
sms-fi
sr-ba-cyrl
sr-ba-latn
sr-sp-cyrl
sr-sp-latn
syr-sy
uz-uz-cyrl
uz-uz-latn
zh-chs
zh-cht
CONOUT$
VS_VERSION_INFO
StringFileInfo
040904e4
CompanyName
Balena Ltd.
FileDescription
Flash OS images to SD cards and USB drives, safely and easily.
FileVersion
1.18.11
LegalCopyright
Copyright 2016-2023 Balena Ltd
ProductName
balenaEtcher
ProductVersion
1.18.11
VarFileInfo
Translation
balenaEtche
balenaEtche
Antivirus Signature
Bkav W32.AIDetectMalware
Lionic Trojan.Win32.Deyma.a!c
tehtris Clean
ClamAV Clean
CMC Clean
CAT-QuickHeal Clean
McAfee Artemis!97256CF11C91
ALYac Trojan.GenericKD.72029190
Cylance Unsafe
Sangfor Downloader.Win32.Amadey.Vga4
K7AntiVirus Trojan ( 005b1a2e1 )
Alibaba TrojanDownloader:Win32/Deyma.e1a62431
K7GW Trojan ( 005b1a2e1 )
Cybereason Clean
Baidu Clean
VirIT Trojan.Win32.Dwnldr.DWY
Paloalto generic.ml
Symantec Trojan.Whispergate
Elastic malicious (high confidence)
ESET-NOD32 a variant of Win32/GenKryptik.GTBH
APEX Malicious
Avast Win32:DropperX-gen [Drp]
Cynet Malicious (score: 99)
Kaspersky HEUR:Trojan-Downloader.Win32.Deyma.gen
BitDefender Trojan.GenericKD.72029190
NANO-Antivirus Trojan.Win32.Deyma.kitovd
ViRobot Clean
MicroWorld-eScan Trojan.GenericKD.72029190
Tencent Malware.Win32.Gencirc.14013610
TACHYON Clean
Sophos Mal/Generic-S
F-Secure Trojan.TR/AD.Amadey.taejb
DrWeb Trojan.MulDrop25.22529
VIPRE Trojan.GenericKD.72029190
TrendMicro Trojan.Win32.AMADEY.YXEBMZ
McAfeeD ti!21C230834043
Trapmine suspicious.low.ml.score
FireEye Generic.mg.97256cf11c9109c2
Emsisoft Trojan.GenericKD.72029190 (B)
SentinelOne Static AI - Malicious PE
GData Trojan.GenericKD.72029190
Jiangmin Clean
Webroot W32.Trojan.Gen
Varist W32/ABTrojan.QSEZ-5853
Avira TR/AD.Amadey.taejb
Antiy-AVL Trojan/Win32.GenKryptik
Kingsoft Win32.Trojan-Downloader.Deyma.gen
Gridinsoft Ransom.Win32.Sabsik.cl
Xcitium Malware@#3lgesni5ehpcg
Arcabit Trojan.Generic.D44B1406
SUPERAntiSpyware Clean
ZoneAlarm HEUR:Trojan-Downloader.Win32.Deyma.gen
Microsoft Trojan:Win32/Amadey!MTB
Google Detected
AhnLab-V3 Trojan/Win.Amadey.R640291
Acronis Clean
BitDefenderTheta Gen:NN.ZexaF.36808.1v2@aGl02oii
MAX malware (ai score=100)
VBA32 BScope.TrojanDownloader.Deyma
Malwarebytes Trojan.Crypt.Generic
Panda Trj/Chgt.AD
Zoner Clean
TrendMicro-HouseCall Trojan.Win32.AMADEY.YXEBMZ
Rising Trojan.ShellCodeRunner!1.F73D (CLASSIC)
Yandex Trojan.DL.Deyma!egl2eP42lyQ
Ikarus Trojan.Win32.Krypt
MaxSecure Clean
Fortinet W32/GenKryptik.GTBH!tr
AVG Win32:DropperX-gen [Drp]
DeepInstinct MALICIOUS
CrowdStrike win/malicious_confidence_100% (W)
alibabacloud Trojan[downloader]:Win/Deyma.hon
No IRMA results available.