Static | ZeroBOX

PE Compile Time

1970-01-01 09:00:00

PE Imphash

5929190c8765f5bc37b052ab5c6c53e7

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x001f8b00 0x001f8c00 6.22428073434
.data 0x001fa000 0x000493d0 0x00049400 4.78721070416
.rdata 0x00244000 0x002c8650 0x002c8800 6.2716316373
.pdata 0x0050d000 0x0000b904 0x0000ba00 5.5119501502
.xdata 0x00519000 0x00000c44 0x00000e00 3.98040053372
.bss 0x0051a000 0x0005bea0 0x00000000 0.0
.edata 0x00576000 0x0000004e 0x00000200 0.842686764111
.idata 0x00577000 0x000013d0 0x00001400 4.48886918482
.CRT 0x00579000 0x00000070 0x00000200 0.465333287403
.tls 0x0057a000 0x00000010 0x00000200 0.0
.rsrc 0x0057b000 0x00009ed8 0x0000a000 5.23418241956
.reloc 0x00585000 0x0000b028 0x0000b200 5.41825694131

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x0057b170 0x000094a8 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_GROUP_ICON 0x00584618 0x00000014 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_VERSION 0x0058462c 0x000003ac LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_MANIFEST 0x005849d8 0x00000500 LANG_ENGLISH SUBLANG_ENGLISH_US XML 1.0 document, ASCII text, with CRLF line terminators

Imports

Library KERNEL32.dll:
0x14057747c AddAtomA
0x14057748c CloseHandle
0x140577494 CreateEventA
0x14057749c CreateFileA
0x1405774a4 CreateIoCompletionPort
0x1405774ac CreateMutexA
0x1405774b4 CreateSemaphoreA
0x1405774bc CreateThread
0x1405774c4 CreateWaitableTimerExW
0x1405774cc DeleteAtom
0x1405774d4 DeleteCriticalSection
0x1405774dc DuplicateHandle
0x1405774e4 EnterCriticalSection
0x1405774ec ExitProcess
0x1405774f4 FindAtomA
0x1405774fc FormatMessageA
0x140577504 FreeEnvironmentStringsW
0x14057750c GetAtomNameA
0x140577514 GetConsoleMode
0x14057751c GetCurrentProcess
0x140577524 GetCurrentProcessId
0x14057752c GetCurrentThread
0x140577534 GetCurrentThreadId
0x14057753c GetEnvironmentStringsW
0x140577544 GetErrorMode
0x14057754c GetHandleInformation
0x140577554 GetLastError
0x14057755c GetProcAddress
0x140577564 GetProcessAffinityMask
0x140577574 GetStartupInfoA
0x14057757c GetStdHandle
0x140577584 GetSystemDirectoryA
0x14057758c GetSystemInfo
0x140577594 GetSystemTimeAsFileTime
0x14057759c GetThreadContext
0x1405775a4 GetThreadPriority
0x1405775ac GetTickCount
0x1405775bc IsDBCSLeadByteEx
0x1405775c4 IsDebuggerPresent
0x1405775cc LeaveCriticalSection
0x1405775d4 LoadLibraryExW
0x1405775dc LoadLibraryW
0x1405775e4 LocalFree
0x1405775ec MultiByteToWideChar
0x1405775f4 OpenProcess
0x1405775fc OutputDebugStringA
0x14057760c QueryPerformanceCounter
0x14057761c RaiseException
0x140577624 RaiseFailFastException
0x14057762c ReleaseMutex
0x140577634 ReleaseSemaphore
0x140577644 ResetEvent
0x14057764c ResumeThread
0x140577654 SetConsoleCtrlHandler
0x14057765c SetErrorMode
0x140577664 SetEvent
0x14057766c SetLastError
0x140577674 SetProcessAffinityMask
0x14057767c SetProcessPriorityBoost
0x140577684 SetThreadContext
0x14057768c SetThreadPriority
0x14057769c SetWaitableTimer
0x1405776a4 Sleep
0x1405776ac SuspendThread
0x1405776b4 SwitchToThread
0x1405776bc TlsAlloc
0x1405776c4 TlsGetValue
0x1405776cc TlsSetValue
0x1405776d4 TryEnterCriticalSection
0x1405776dc VirtualAlloc
0x1405776e4 VirtualFree
0x1405776ec VirtualProtect
0x1405776f4 VirtualQuery
0x1405776fc WaitForMultipleObjects
0x140577704 WaitForSingleObject
0x14057770c WerGetFlags
0x140577714 WerSetFlags
0x14057771c WideCharToMultiByte
0x140577724 WriteConsoleW
0x14057772c WriteFile
0x140577734 __C_specific_handler
Library msvcrt.dll:
0x140577744 ___lc_codepage_func
0x14057774c ___mb_cur_max_func
0x140577754 __getmainargs
0x14057775c __initenv
0x140577764 __iob_func
0x14057776c __lconv_init
0x140577774 __set_app_type
0x14057777c __setusermatherr
0x140577784 _acmdln
0x14057778c _amsg_exit
0x140577794 _beginthread
0x14057779c _beginthreadex
0x1405777a4 _cexit
0x1405777ac _commode
0x1405777b4 _endthreadex
0x1405777bc _errno
0x1405777c4 _fmode
0x1405777cc _initterm
0x1405777d4 _lock
0x1405777dc _memccpy
0x1405777e4 _onexit
0x1405777ec _setjmp
0x1405777f4 _strdup
0x1405777fc _ultoa
0x140577804 _unlock
0x14057780c abort
0x140577814 calloc
0x14057781c exit
0x140577824 fprintf
0x14057782c fputc
0x140577834 free
0x14057783c fwrite
0x140577844 localeconv
0x14057784c longjmp
0x140577854 malloc
0x14057785c memcpy
0x140577864 memmove
0x14057786c memset
0x140577874 printf
0x14057787c realloc
0x140577884 signal
0x14057788c strerror
0x140577894 strlen
0x14057789c strncmp
0x1405778a4 vfprintf
0x1405778ac wcslen

Exports

Ordinal Address Name
1 0x1405750d0 _cgo_dummy_export
!This program cannot be run in DOS mode.
``.data
.rdata
`@.pdata
0@.xdata
0@.bss
.edata
0@.idata
.reloc
AUATUWVSH
[^_]A\A]
[^_]A\A]
Go build ID: "W74kA9NiiqK5lM9FAyK9/p6GgsXusTsV-aSReOdfL/qGmq7Xl5xsd_g76XQd5m/QlSeR9dr7KlR-wlgXXKh"
L$xwDH)
l$ M9,$u
8cpu.u
P0H9S0
PPH9SP
PpH9Sp
UUUUUUUUH!
33333333H!
D$pH9P@w
H9L$@r
debugCal
debugCal
debugCalH9
debugCalH9
l819um
debugCalH9
84t6H9
runtime.
runtime H
error: H
HPL9x(t
7H9S u
29t$0u
29t$0u
D9T$PtcI
/H9S u
2H9t$0u
H9t$0u
L9T$PteI
L9T$Pt
/H9S u
L$xL9O
/H9S u
H9BxwA@
D$hH98
PhH9P8tgH
\$(H9C8u
H9D$(t
^0H9X0tK
tA8Z t+
\$0H9K
D$pH9H
D$0H9H
UUUUUUUUH!
UUUUUUUUH
wwwwwwwwH!
wwwwwwwwH
vDH95h
D9L$8u
J0H9J8vuH
H9s8u?H=
AddVectoH
redContiH
ContinueH
Handler
ProcessPH
D$Mrng
NtWaitFoH
ForSinglH
eObject
RtlGetCuH
tlGetCurH
rentPeb
RtlGetNtH
tVersionH
Numbers
timeBegiH
nPeriod
timeEndPH
dPeriod
WSAGetOvH
verlappeH
dResult
wine_getH
ine_get_H
version
PowerRegH
gisterSuH
spendResH
umeNotifH
ication
GetSysteH
mTimeAsFH
ileTime
QueryPerH
formanceH
Counter
QueryPerH
formanceH
rmanceFrH
equency
runtime.H9
QxM9Qpu
T$8H9P
H9L$Xt
L$XH9Q(
runtime.H9
reflect.H9
I9N0t_H
D$@D9D$D
t%H9QPtH
rpH92w
tRI9N0tLH
|$0uMH
memprofi
lerau*f
,$M9l$
I9@8u(
r09q0s-f
v09r0w
,$M9*w
L9T$hw
L9T$pv
H9T$hw
H9T$pv
Q8H+Q(
H9D$PA
H9D$PA
\$HH9S@
H9D$8A
T$0H9T$Hu
t$(H9t$`u
l$0M9e
P8H9P(s
z(H9z0
runtime.H9
gopau/f
|$x2u
runtime.H9
runtime.H
runtime.H
G0I9F0t=
runtime.H9
P8H9W8t
p2f9w2
H9H@usH
H+H H+H(H+H0H
8noneuW1
8crasuD
8singu
8systu
l$0M9,$u
l$PM9,$u
X0H;CPt^H
sPH91u
l$ M9,$u
l$0M9,$u
l$PM9,$u
H+t$(H
0Hc\$@H
l$(M9,$u
l$ M9,$u
l$@M9,$u
P+8S+t
P H9S u<H
P(H9S(u^H
PXH9SX
SpH9Pp
H H9K u
\$0H9S
Q H9S u*H
Q(H9S(u
Q08S0u
P8H9S8u/H
H9S@u!H
PHH9SHu
PPH9SPu
H08K0u
H9L$0uDH
P H9S unH
P0H9S0ud
P88S8u[H
l$ M9,$u
l$ M9,$u
\$0H9S
\$0H9S
T$0H9J
l$ M9,$u
l$0M9,$u
l$0M9,$u
\$0H9S
I H9K
t$0H9F t
D$(H9Z
p2f9s2u
S8H9P8t
S@H9P@ukH
reflect.H9
Valuu,f
reflect.
ujH9x@vQH
uJH9x@
T$0H9J
u$H9H@v
t$0H9F uIH
\$0H9S0u$H
Q8H9S8u
IHH9KH
l$(M9,$u
l$(M9,$u
l$(M9,$u
l$(M9,$u
l$(M9,$u
l$0M9,$u
H H9K u(H
H(H9K(u
H8H9K8
8n<OwG
l$ M9,$u
l$ M9,$u
l$ M9,$u
H1T$0H
H1T$HH
H1T$PH
l$HM9,$u
l$8M9,$u
d$(t6vSF
l$8M9,$u
D$`tND
D$`tMD
l$0M9,$
l$ M9,$
@81t#@
l$@M9,$u
L$`u/H
L$`u>H
l$(M9,$u
t$0H9N
~(H9z(u.H
l$(M9,$u
-07:00:0M9
-07:00:0L
-07:00:0
Januu!D
-07:00:0
-07:00:0
-07:00:0
Z070u"D
Z07:00:0M9
Z07:00:0L
-07:00:0
-07:00:0
-07:00:0
-07:00:0
2006u'H)
-07:00:0f
time.DatH
time.LocL
time.LocH
ocation(H
time.UTCL
Mc$$M9
Mc$$M)
8WITAuI
H#L$ H
H#L$ H
H#L$ H
H#T$`H
<$/tyH
P8H9S8
l$(M9,$u
l$(M9,$u
t$0H9F t
H 9K u3
H$9K$u+
H(9K(u#
H,9K,u
H09K0u
H49K4u
H 9K u
H(H9K(u
t$PHcX(
L$pHcY(
;fileu
;unixtz
unixgramL9#t/
unixpackL9#
;tcp4t
;tcp6t
;udp4t
;udp6u
;udp4t
;udp6ub
l$(M9,$u
8..u[H
L$XH9=v
?fileumH
\$ 9SXu
Q\9S\u
PPH9SP
P\9S\uu
P`9S`um
Pd8SdudH
t$0H9F0t
t$0H9F
l$ M9,$u
l$0M9,$u
l$0M9,$u
l$8M9,$u
l$8M9,$u
l$0M9,$u
l$0M9,$u
l$0M9,$u
l$0M9,$u
l$0M9,$u
l$0M9,$u
H 9K u
H$9K$u
method:H
l$@M9,$u
l$@M9,$u
l$@M9,$u
l$@M9,$u
(BADINDEI
(MISSINGI
%!(BADWIL
%!(BADPRL
BADPREC)L
%!(EXTRAM
%!(NOVERM
t$0H9F
\$0H9S
Q 9S u
QZ^&A!
[bisect-H
match 0xH
[bisect-H
match 0xH
H H9K
P H9S u
t$0H9F
\$0H9S u
8leaku
t$0H9F
T$08J
P(H9S(u[H
l$(M9,$u
H9L$ u
H9t$Hu
t$0H9F
t$0H9F t
l$(M9,$u
l$8M9,$
H9P0u$H
H9P0u$H
H9P0u$H
H9P0u"H
t$0H9F
l$8M9,$u
t$0H9F
T$08J
:windu
8iouiA
8planuQA
8andru
8windu fA
>binduCH
9fileu
>fileuF
9bindu
D$Ht'H
9solau!f
:fileu
myhostnaH9:uZf
;fileu
<$fileu
9succu
notfoundI91u
tryagainf
8retuu
9tcp4tZ
9tcp6tR
9udp4tH
9udp6t@
9unixt8
unixgramH9
unixpackf
:dialu+L
unixgramL9
unixpackL9
8unixtM
unixgramH9
unixpack
<$tcu(A
l$(M9,$u
:CNAMuh
8CNAMu)A
?tcp4t
t$D9t$@w
?tcp4t'
?tcp6t
?udp4t
?udp6f
?tcp4t
?udp4t
?tcp4t
?udp4t
?udp6uuH
9listu:fA
<$dialf
8tcp4t
8tcp6u,
8udp4f
8udp6u
:uduuA
:tcp4t
:tcp6t
:udp4t
:udp6u4H
9tcp4t
9tcp6u&
9udp4t
9udp6u
:acceuBf
~SryH)
unixgramf
unixpackL9
unixgramL9
unixpackL9
unixgramL9
unixpack
\$(tdH
8udp4t
9unixf
unixgram
unixpackH9
listuUfA
t$0H9F ucH
t$0H9F0u>H
t$0H9F@t
P08S0ut
P18S1uk
P28S2ubH
t$0H9F
l$(M9,$u
l$@M9,$
l$0M9,$u
l$0M9,$u
l$0M9,$u
l$0M9,$u
l$0M9,$u
l$0M9,$u
l$0M9,$u
l$0M9,$u
l$0M9,$u
l$0M9,$u
l$0M9,$u
l$0M9,$u
l$0M9,$u
t$0H9F
\$08S u
P H9S u>H
kernel32H9
t$0H9N
~(H9z(u.H
P H9S u
t$0H9N
t$0H9N
z f9~ u
t$0H9F
l$hM9,$
<Ot/<XtN
l$8M9,$u
:T^8rv
~d$ fE
ot$PfA
S H+Q H
P8H9S8u
l$8M9,$u
l$8M9,$u
l$HM9,$u
l$@M9,$u
l$8M9,$u
l$8M9,$u
l$HM9,$u
l$@M9,$u
l$8M9,$u
l$8M9,$u
l$HM9,$u
l$@M9,$u
l$8M9,$u
l$8M9,$u
l$HM9,$u
l$@M9,$u
l$@M9,$u
l$8M9,$u
l$HM9,$u
l$8M9,$u
L$PL9N
optionalH9
explicit
explicitH90uf
optionalH
explicitH
explicit
optionalH
explicitH
generaliL9
generaliH
printabl
printablH
8numeu
8utf8u
default:L9
default:E1
8tag:A
applicat
optionalH
explicitH
generaliI
printablI
default:I
applicat
applicat
optionalH
explicitH
generaliI
printablI
default:I
applicat
omitempt
omitempt
optionalH
explicitH
optionalH
explicitH
t$0H9F
l$(M9,$u
l$ M9,$u
l$8M9,$
l$8M9,$
l$@M9,$u
l$@M9,$u
l$@M9,$u
l$(M9,$u
L$H8L$'u
L$H8L$'u
:P-25uc
l$8M9,$
l$8M9,$u
l$(M9,$u
l$(M9,$u
l$0M9,$
l$0M9,$u
l$@M9,$u
\$0H9S
XfffffffH
ffffffffH
T$0H9J
l$(M9,$u
<$tI<&tE
T$(H9Z@t
T$(H9Zxt
t$0H9F t
l$ M9,$u
l$ M9,$u
P 8S u<H
S0H9P0
SPH9PP
SxH9Px
$D3T$4D3T$ D3T$
D3T$8D3T$$D3T$
D3T$<D3T$(D3T$
$D3T$,D3T$
D3T$0D3T$
D3T$4D3T$
D3T$8D3T$ A
D3T$<D3T$$A
T$ D3T$
$D3T$(A
T$$D3T$
D3T$,A
T$(D3T$
D3T$0A
T$,D3T$ D3T$
D3T$4A
T$0D3T$$D3T$
D3T$8A
T$4D3T$(D3T$
D3T$<A
T$8D3T$,D3T$
T$<D3T$0D3T$
$D3T$4D3T$ D3T$
D3T$8D3T$$D3T$
D3T$<D3T$(D3T$
$D3T$,D3T$
D3T$0D3T$
D3T$4D3T$
D3T$8D3T$ A
D3T$<D3T$$A
T$ D3T$
$D3T$(A
T$$D3T$
D3T$,A
T$(D3T$
D3T$0A
T$,D3T$ D3T$
D3T$4A
T$0D3T$$D3T$
D3T$8A
T$4D3T$(D3T$
D3T$<A
T$8D3T$,D3T$
T$<D3T$0D3T$
$D3T$4D3T$ D3T$
D3T$8D3T$$D3T$
D3T$<D3T$(D3T$
$D3T$,D3T$
D3T$0D3T$
D3T$4D3T$
D3T$8D3T$ A
D3T$<D3T$$A
T$ D3T$
$D3T$(A
T$$D3T$
D3T$,A
T$(D3T$
D3T$0A
T$,D3T$ D3T$
D3T$4A
T$0D3T$$D3T$
D3T$8A
T$4D3T$(D3T$
D3T$<A
T$8D3T$,D3T$
T$<D3T$0D3T$
$D3T$4D3T$ D3T$
D3T$8D3T$$D3T$
D3T$<D3T$(D3T$
$D3T$,D3T$
D3T$0D3T$
D3T$4D3T$
D3T$8D3T$ A
D3T$<D3T$$A
T$ D3T$
$D3T$(A
T$$D3T$
D3T$,A
T$(D3T$
D3T$0A
T$,D3T$ D3T$
D3T$4A
T$0D3T$$D3T$
D3T$8A
T$4D3T$(D3T$
D3T$<A
T$8D3T$,D3T$
T$<D3T$0D3T$
PXH9SXu
}XH9D$(
T$0H9P
l$ M9,$u
rhH9pPuIH
@PL9GPt
|$@H9=M
J(H9H(u
D$@H9D$
H9\$hu
T$0H9J
D$@H9D$
l$(M9,$u
l$0M9,$u
l$HM9,$u
os/execH
os/exec.H
Command(H
l$ M9,$u
t$0H9F
t$0H9F
l$XM9,$u
T$0H9J
H9J uaD
t$0H9F u4H
t$0H9N8u
H9L$`t
l$xM9,$u
GCTLt1
IGPtA
9T$|s<A9
9t$xs:9
*invalidM9}
*invalidI
*invalidI
*invalidO
*invalidI9
*invalidH
*invalidH
*invalidH
D$DRichH
DanStWH
P H9S u"
P(9S(u
P(H9S(uF
P09S0u>H
P H9S uEH
t$0H9N8u
t$0H9F
P`H9S`
P 8S u
P"f9S"u
t$0H9F
t$0H9N u
\$08S
Q"8S"u
Q#8S#uv
Q%8S%uc
Q&8S&uZ
Q(8S(uC
Q)8S)u:
Q+8S+u#
Q,8S,u
l$hM9,$
l$hM9,$
l$0M9,$u
l$hM9,$
l$ M9,$u
l$ M9,$u
l$hM9,$
l$ M9,$u
l$ M9,$u
l$ M9,$u
l$ M9,$u
l$ M9,$u
l$ M9,$u
l$ M9,$u
l$ M9,$u
l$ M9,$u
l$ M9,$u
l$ M9,$u
l$ M9,$u
l$ M9,$u
l$ M9,$u
H H9K u
H H9K u
l$@M9,$u
us-asciiH9
8utf-u
text/plaH
text/plaH
text/plaH
text/plaH
text/plaH
text/plaH
l$ M9,$u
L$7D8L$j
l$HM9,$u
>httpu
8httpu
8socku
localhosH9
P 8S u<H
l$ M9,$u
l$0M9,$
l$hM9,$
l$PM9,$
P(H9S(ud
P08S0u[H
t$0H9F
l$0M9,$
l$0M9,$u
l$(M9,$
D$XA80
aHM9aPuUI
}0H9{0~
@0L9@8
H0H9K0u
PXH9SXt
PHH9SHu7H
PPH9SPu-H
APL9AH
l$ M9,$
E9Y0v9M
E9Y0v?M
E9o0v'I
E9o0v'I
E9o0v#I
E9o0v'I
8AUTHu
8DEBUu
8ERROux
8FATAu
8PANIu:
8WARNu
J H9O u
P H9S u
l$@M9,$
P(H9S(uZH
T$08J0
t$0H9N(u
S8H9P8
SXH9PX
SxH9Px
K8H9H8
KXH9HX
KxH9Hx
T$'H=y
T$'H=n
L$(H=^
L$(H=0%
L$(fA9@
9.exeu
cae3e9aaH
436f9b59H
d59c0863H
e665f7aeH
QuYr1ObWH
ATUWVSH
0[^_]A\
ATUWVSH
[^_]A\
SUATAUAVAWL
A_A^A]A\][
AUATSH
0[A\A]
C$9C(~
u HcC$A
AVAUATUWVSH
C$9C(~
@[^_]A\A]A^
S$9S(~
S$9S(~
UAWAVAUATWVSH
C$9C(~
C$9C(~
[^_A\A]A^A_]
UAWAVAUATWVSH
C$9C(~
S$9S(~
[^_A\A]A^A_]
UATWVSH
IcD$$A
D$$A9D$(~
[^_A\]
[^_A\]
=UUUUw
AUATSH
[A\A]
S$9S(~
AUATUWVSH
X[^_]A\A]
X[^_]A\A]
AWAVAUATUWVSH
[^_]A\A]A^A_
AWAVAUATUWVSH
8[^_]A\A]A^A_
AWAVAUATUWVSH
[^_]A\A]A^A_
[^_]A\A]A^A_
HcD$pH
+T$tE1
l$`+l$L
ATUWVSHcY
[^_]A\
[^_]A\
AUATVSH
([^A\A]
AWAVAUATUWVSH
([^_]A\A]A^A_
AVAUATUWVSH
[^_]A\A]A^
AVAUATUWVSH
[^_]A\A]A^
ATUWVSH
[^_]A\
[^_]A\
ATSHcA
UAWAVAUATWVSH
[^_A\A]A^A_]
ATWVSH
([^_A\H
:MZuWHcB<H
AVAUATUWVSH
[^_]A\A]A^
[^_]A\A]A^
AVAUATUWVSH
L9 siH
[^_]A\A]A^
[^_]A\A]A^
AUATSH
[A\A]
Error clH
eaning uH
p spin_kH
eys for H
thread
AUATVSH
([^A\A]
AWAVAUATUWVSH
([^_]A\A]A^A_
ATUWVSH
@[^_]A\
@[^_]A\
AWAVAUATUWVSH
8[^_]A\A]A^A_
8[^_]A\A]A^A_
AVAUATSH
([A\A]A^
AUATVSH
8[^A\A]
AUATWVSH
@[^_A\A]
@[^_A\A]
@[^_A\A]
AVAUATUWVSH
0[^_]A\A]A^
0[^_]A\A]A^
AWAVAUATUWVSH
([^_]A\A]A^A_
AVAUATVSH
[^A\A]A^
AWAVAUATUWVSH
9sHv9L
([^_]A\A]A^A_
AUATSH
AUATVSH
[^A\A]
[^A\A]
ATWVSH
([^_A\
([^_A\
ATWVSH
([^_A\
([^_A\
AVAUATUWVSH
@[^_]A\A]A^
@[^_]A\A]A^
ATWVSH
8[^_A\
8[^_A\
8[^_A\
ATWVSH
H[^_A\
H[^_A\
H[^_A\
AUATVSH
([^A\A]
([^A\A]
([^A\A]
aaaaaaaaH
aaaaaaaaH
AUATWVSH
0[^_A\A]
0[^_A\A]
AVAUATUWVSH
0[^_]A\A]A^
ATWVSH
([^_A\
([^_A\
([^_A\
([^_A\
AUATWVSH
[^_A\A]
[^_A\A]
[^_A\A]
ATWVSH
([^_A\
AWAVAUATSH
[A\A]A^A_
AVAUATVSH
0[^A\A]A^
AWAVAUATSH
[A\A]A^A_
[A\A]A^A_
AWAVAUATSH
[A\A]A^A_
[A\A]A^A_
AWAVAUATSH
[A\A]A^A_
[A\A]A^A_
AWAVAUATSH
[A\A]A^A_
[A\A]A^A_
AVAUATSH
([A\A]A^
([A\A]A^
AVAUATWVSH
H[^_A\A]A^
H[^_A\A]A^
AVAUATUWVSH
@[^_]A\A]A^
@[^_]A\A]A^
@[^_]A\A]A^
AUATVSH
([^A\A]
([^A\A]
([^A\A]
ATUWVSH
[^_]A\
AUATSH
[A\A]
AUATWVSH
0[^_A\A]
0[^_A\A]
0[^_A\A]
AWAVAUATUWVSH
([^_]A\A]A^A_
AWAVAUATVSH
8[^A\A]A^A_
AUATSH
@[A\A]
@[A\A]
@[A\A]
@[A\A]
AUATUWVSH
[^_]A\A]
[^_]A\A]
AUATUWVSH
8[^_]A\A]
AVAUATUWVSH
[^_]A\A]A^
[^_]A\A]A^
AUATVSH
8[^A\A]
8[^A\A]
8[^A\A]
AUATWVSH
@[^_A\A]
AVAUATUWVSH
@[^_]A\A]A^
ATWVSH
H[^_A\
AVAUATUWVSH
0[^_]A\A]A^
Go buildinf:
go1.21.7
stub_check
stub_check
(devel)
github.com/Azure/go-autorest/autorest
v0.11.28
h1:ndAExarwr5Y+GaHE6VCaY1kyS/HwwGGyuimVhWsHOEM=
github.com/Azure/go-autorest/autorest/adal
v0.9.22
h1:/GblQdIudfEM3AWWZ0mrYJQSd7JS4S/Mbzh6F0ov0Xc=
github.com/Azure/go-autorest/autorest/azure/auth
v0.5.13
h1:Ov8avRZi2vmrE2JcXw+tu5K/yB41r7xK9GZDiBF7NdM=
github.com/Azure/go-autorest/autorest/azure/cli
v0.4.6
h1:w77/uPk80ZET2F+AfQExZyEWtn+0Rk/uw17m9fv5Ajc=
github.com/Azure/go-autorest/autorest/date
v0.3.0
h1:7gUk1U5M/CQbp9WoqinNzJar+8KY+LPI6wiWrP/myHw=
github.com/Azure/go-autorest/logger
v0.2.1
h1:IG7i4p/mDa2Ce4TRyAO8IHnVhAVF3RFU+ZtXWSmf4Tg=
github.com/Azure/go-autorest/tracing
v0.6.0
h1:TYi4+3m5t6K48TGI9AUdb+IzbnSxvnvUMfuitfgcfuo=
github.com/dimchansky/utfbom
v1.1.1
h1:vV6w1AhK4VMnhBno/TPVCoK9U/LP0PkLCS9tbxHdi/U=
github.com/docker/docker
v26.1.3+incompatible
h1:lLCzRbrVZrljpVNobJu1J2FHk8V0s4BawoZippkc+xo=
github.com/edsrzf/mmap-go
v1.1.0
h1:6EUwBLQ/Mcr1EYLE4Tn1VdW1A4ckqCQWZBw8Hr0kjpQ=
github.com/go-ole/go-ole
v1.2.6
h1:/Fpf6oFPoeFik9ty7siob0G6Ke8QvQEuVcuChpwXzpY=
github.com/golang-jwt/jwt/v4
v4.5.0
h1:7cYmW1XlMY7h7ii7UhUyChSgS5wUJEnm9uZVTGqOWzg=
github.com/mattn/go-isatty
v0.0.20
h1:xfD0iDuEKnDkl03q4limB+vH+GxLEtL/jb4xVJSWWEY=
github.com/mattn/go-tty
v0.0.5
h1:s09uXI7yDbXzzTTfw3zonKFzwGkyYlgU3OMjqA0ddz4=
github.com/mitchellh/go-homedir
v1.1.0
h1:lukF9ziXFxDFPkA1vsr5zpc1XuPDn/wFntq5mG+4E0Y=
github.com/opencontainers/go-digest
v1.0.0
h1:apOUWs51W5PlhuyGyz9FCeeBIOUDA/6nW8Oi/yOhh5U=
github.com/opencontainers/image-spec
v1.1.0
h1:8SG7/vwALn54lVB/0yZ/MMwhFrPYtpEHQb2IpWsCzug=
github.com/opencontainers/runc
v1.1.12
h1:BOIssBaW1La0/qbNZHXOOa71dZfZEQOzW7dqQf3phss=
github.com/pkg/errors
v0.9.1
h1:FEBLx1zS214owpjy7qsBeixbURkuhQAwrK5UwLGTwt4=
github.com/saferwall/pe
v1.4.8
h1:ey/L8FGBMrJ1Xh+Rltj1MAFPZ4LOQYGJqNa5B1Na6B0=
github.com/shirou/gopsutil/v3
v3.24.5
h1:i0t8kL+kQTvpAYToeuiVk3TgDeKOFioZO3Ztz/iZ9pI=
github.com/yusufpapurcu/wmi
v1.2.4
h1:zFUKzehAFReQwLys1b/iSMl+JQGSCSjtVqQn9bBrPo0=
go.mozilla.org/pkcs7
v0.0.0-20210826202110-33d05740a352
h1:CCriYyAfq1Br1aIYettdHZTy8mBTIPo7We18TuO/bak=
golang.org/x/crypto
v0.21.0
h1:X31++rzVUdKhX5sWmSOFZxx8UW/ldWx55cbf08iNAMA=
golang.org/x/sys
v0.20.0
h1:Od9JTbYCk261bKm4M/mw7AklTlFYIa0bIp9BgSm1S8Y=
golang.org/x/text
v0.14.0
h1:ScX5w1eTa3QqT8oi6+ziP7dTV1S2+ALU0bI+0zXKWiQ=
-buildmode=exe
-compiler=gc
-trimpath=true
CGO_ENABLED=1
GOARCH=amd64
GOOS=windows
GOAMD64=v1

!"#$%%&&''((()))*++,,,,,------....//////0001123333333333444444444455666677777888888888889999999999::::::;;;;;;;;;;;;;;;;<<<<<<<<<<<<<<<<=====>>>>>>>>>>>??????????@@@@@@@@@@@@@@@@@@@@@@AAAAAAAAAAAAAAAAAAAAABBBBBBBBBBBCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCC
XZ\^
D7q/;M
 EHMP}
' 0 ^ p q t
!&$@$J$`$s+v+
,'-----0-g-o-p-
=j&&LZ66lA??~
}{))R>
f""D~**T
V22dN::t
o%%Jr..\$
&&Lj66lZ??~A
99rKJJ
==zGdd
""Df**T~
;22dV::tN
$$Hl\\
C77nYmm
%%Jo..\r
>!KK
55j_WW
&Lj&6lZ6?~A?
~=zG=d
"Df"*T~*
2dV2:tN:
x%Jo%.\r.
t>!K
a5j_5W
ggV}++
Lj&&lZ66~A??
bS11*?
Xt,,4.
RRvM;;
MMfU33
PPxD<<%
Bc!! 0
~~zG==
Df""T~**;
dV22tN::
xxJo%%\r..8$
tt>!
pp|B>>q
aaj_55
UUPx((
='9-6d
_jbF~T
11#?*0
,4$8_@
t\lHBW
QPeA~S
>4$8,@
p\lHtW
+HpXhE
T[$:.6
>?@ABCDE@FGHDIJKLM
NOPQRSTUVW
 !"#$
%&'()*+,-
$42j?+
Qy8v8L
cu$qC
2@z$Zf
{$WcI6k2
XT1a~uL
6e%9m8
u~`q`l|=
acfO4
E2h2m2
xH/444}HH4
V5y5~5
H21>471C4U1a4F1R4n1z4x1
@2Q5Y2j5O2`5
3(603F6S3i6{3
3K1W4P1\4
326!376
H7T7f7
j9p9z8
;Z1f4_1k4E:
;d1p4s1
;'285"235,2=512B562G5J2[5T2e5c2t5^2o5v:
6+3A6:3P653K6
<?3U6D3Z6I3_6N3d6]3s6X3n6b3}6g3
HA1M4-194
:R<&3<6
EIKI_JwJgJ
H)>9>1>A>
IY?q?a?y?i?
IY>q>a>y>i>
J-I3I/JGJ7JOJ?JWJ9I_D
7eDcIkD
B9B%BCB)?1?
C3CI>Q>MBkBWBuBaB
@=C[CGCeCQCoC
>6707$7/D<7
{I9?B75DN7;DZ7
7Q?r7l7`7AD
DwZhN"
L|]C5;
)b"=s>'
_R?Z}5
8>G#g$
?/"=~Fr
P~uu\T
7Cxl2i5n
_p&&<YX
Cupv]dB
:5(+EW
"t*U1Vx
wqBv/?
S.R_PD;
qKguDid
E2h2m2
xH/444}HH4
V5y5~5
H21>471C4U1a4F1R4n1z4x1
@2Q5Y2j5O2`5
3(603F6S3i6{3
//5/;/
3K1W4P1\4
326!376
H7T7f7
j9p9z8
;Z1f4_1k4E:
;d1p4s1
;'285"235,2=512B562G5J2[5T2e5c2t5^2o5v:
6+3A6:3P653K6
<?3U6D3Z6I3_6N3d6]3s6X3n6b3}6g3
HA1M4-194
:R<&3<6
EIKI_JwJgJ
H)>9>1>A>
IY?q?a?y?i?
IY>q>a>y>i>
J-I3I/JGJ7JOJ?JWJ9I_D
7eDcIkD
B9B%BCB)?1?
C3CI>Q>MBkBWBuBaB
@=C[CGCeCQCoC
>6707$7/D<7
{I9?B75DN7;DZ7
7Q?r7l7`7AD
K"K(K.K4K:K@KFKLKRKXK^KdKjKpKvK
!](f(o(x(
! "P"n"h"\"
">"J"b"V"
!2"D"z"
Y/a/i/q/y/
-c,G+.-A-T+
/a+s,60
(/*9*T-{+
+M*C*}0
#"#.#:#v#
8(F(1(?(
#(#4#p#|#
1E7E5F=F
EE%E+E=E
'5'5'.'.'<'<'C'C'C' ' ' '
,;@EJY^mrw
+ 0 5 D I X ] b g l q v {
!%!*!/!4!9!>!H!M!R!a!p!u!aEgE
"',1;@l q
EW!\!a!f!p!u!
,EJY^mw
+ 0 5 D I X ] b g v {
! !/!4!
EH!M!R!a!k!
! !a!k!EFMFUF! & : ? N S
chOT|
! & : ? N S
chOT|
+ IEIE
A$V$V$]$d$y$
%/%/%K%
%!%!%(%(%R%`%`%g%g%n%u%|%
&@&G&N&$&2&U&\&
&:$O$H$r$k$
OEOEUEUE
A/A/I/I/Q/Q/
"K(K.K4K:K@K
FKLKRKXK^KdK
jKpKvK
:*:*:*:*:*:*:*
:*:*:*:*:*
:*:*:*:*
:*:*:*:*:*
:*:*:*:*
'5'U'u'
(5(U(u(
)5)U)u)
,5,5,5,U,u,u,
*u,u,U,U,
-5-5-U-u-
.5.U.U.u.
.u.5/U/u/
050U0u0
51U1u1
252U2u1u2
454U4u4
555U5u5
656U6u6
757U7u7
858U8u8
959U9u9
:5:U:u:
;5;U;u;
<5<U<u<
=-=E=]=u=u=]=
>5>M>e>}>
?%?=?U?U?m?m?m?
@-@-@-@
A%AEAeA
e-eMeme
f-fMfmf
g-gMgmg
i-iMimi
j-jMjmj
k-kMkmk
{-{M{m{
|-|M|m|
)19
QYaiqy
-~M~m~-~
" * "
2 : B J @
!!!!!!!!!)!)!)!)!1!1!1!1!9!9!9!9!A!A!A!A!I!I!I!I!Q!Q!Q!Q!Y!Y!Y!Y!a!a!a!a!i!i!i!i!q!q!q!q!y!y!y!y!
1"9"A"I"Q"Y"a"i"q"y"
#!#)#1#9#@
A#I#Q#Y#a#i#q#e
$!$)$1$9$
A$I$Q$
$!$)$1$9$
A$A$I$Q$
$!$)$1$9$
A$I$Q$
$!$)$1$9$
A$A$I$Q$
$!$)$1$9$
A$I$Q$
$!$)$1$9$
A$A$I$Q$
$!$)$1$9$
A$I$Q$
$!$)$1$9$
A$A$I$Q$
$!$)$1$9$
A$I$Q$
$!$)$1$9$
A$A$I$Q$
%!%)%1%9%A%I%Q%y$
%Y%1%a%i%q%y%
!a!i!q!y!
!A!Q!!!Y!
)!9!I!
!a!i!q!y!
!A!Q!!!Y!@
!A!Q!!!Y!@
)!9!I!
i!q!y!
!A!Q!!!Y!
)!9!I!@
i!q!y!
!A!Q!!!Y!
)!9!I!@
&"&*&2&:&B&J&R&Z&b&j&r&z&
)'1'9'A'I'Q'Y'a'i'q'y'
(!()(1(9(A(I(Q(Y(a(i(q(y(
)!)))1)9)
A)I)Q)Y)
*!*)*1*1*1*]
9*A*I*}
Q*Y*a*i*q*y*
+!+)+1+9+A+
I+Q+Y+Q'a+i+
,!,),1,9,A,I,Q,Y,a,i,}
-!-)-!-1-9-A-I-Q-Y-a-i-q-y-
!.).1.9.A.I.Q.Y.a.i.q.y.
1/9/A/I/Q/Y/
i/q/y/
0!0)01090
I0@ Q0Y0a0]
1!1)11191
A1I1Q1Y1
i1q1y1
!2)212
I2Q2Y2a2i2q2=
1393A3I3=
i3q3y3
!4)41494A4I4
Q4Y4a4i4=
!5)515=
A5A5I5}
Q5Y5a5i5q5y5
A A!A"A#A$A%A&A'A(A)A*A+A,A-A.A/A0A1A2A3A4A5A6A7A8A9A:A;A<A=A>A?A@AAABACADAEAFAGAHAIAJAKALAMANAOAPAQARASATAUAVAWAXAYAZA[A\A]A^A_A`AaAbAcAdAeAfAgAhAiAjAkAlAmAnAoApAqArAsAtAuAvAwAxAyAzA{A|A}A~B
B!!B!?B..B0,B0.B1,B1.B10B11B12B13B14B15B16B17B18B19B2,B2.B20B21B22B23B24B25B26B27B28B29B3,B3.B30B31B32B33B34B35B36B37B38B39B4,B4.B40B41B42B43B44B45B46B47B48B49B5,B5.B50B6,B6.B7,B7.B8,B8.B9,B9.B==B?!B??BAUBBqBCDBDJBDZBDzBGBBGyBHPBHVBHgBHzBIIBIJBIUBIVBIXBKBBKKBKMBLJBLjBMBBMCBMDBMRBMVBMWBNJBNjBNoBPHBPRBPaBRsBSDBSMBSSBSvBTMBVIBWCBWZBWbBXIBccBcdBcmBdBBdaBdlBdmBdzBeVBffBfiBflBfmBhaBiiBijBinBivBixBkABkVBkWBkgBklBkmBktBljBlmBlnBlxBm2Bm3BmABmVBmWBmbBmgBmlBmmBmsBnABnFBnVBnWBnjBnmBnsBoVBpABpFBpVBpWBpcBpsBsrBstBviBxiC(1)C(2)C(3)C(4)C(5)C(6)C(7)C(8)C(9)C(A)C(B)C(C)C(D)C(E)C(F)C(G)C(H)C(I)C(J)C(K)C(L)C(M)C(N)C(O)C(P)C(Q)C(R)C(S)C(T)C(U)C(V)C(W)C(X)C(Y)C(Z)C(a)C(b)C(c)C(d)C(e)C(f)C(g)C(h)C(i)C(j)C(k)C(l)C(m)C(n)C(o)C(p)C(q)C(r)C(s)C(t)C(u)C(v)C(w)C(x)C(y)C(z)C...C10.C11.C12.C13.C14.C15.C16.C17.C18.C19.C20.C::=C===CCo.CFAXCGHzCGPaCIIICLTDCL
CMHzCMPaCM
CPPMCPPVCPTECTELCTHzCVIICXIICa/cCa/sCa
CbarCc/oCc/uCcalCcm2Ccm3Cdm2Cdm3CergCffiCfflCgalChPaCiiiCkHzCkPaCkm2Ckm3Ck
ClogCl
CmilCmm2Cmm3CmolCradCviiCxiiC
sD(10)D(11)D(12)D(13)D(14)D(15)D(16)D(17)D(18)D(19)D(20)D0
DVIIIDa.m.DkcalDp.m.DviiiD
p1home
p2home
p3home
p4home
p5home
p6home
eflags
Offset
EFlags
unsafe
NewGCM
errors
cipher
refill
update
encode
strict
Strict
Decode
Encode
Fatalf
Output
Panicf
Prefix
Printf
Writer
output
prefix
String
Lookup
mustBe
offset
CanInt
CanSet
IsZero
Method
SetCap
SetInt
SetLen
Slice3
NumOut
common
stkOff
addArg
append
Common
argLen
method
byName
Unlock
crypto
closed
Layout
lookup
extend
Before
Format
Minute
Second
addSec
locabs
setLoc
period
status
Uint64
Int31n
Int63n
Uint32
int31n
bisect@
Family
ZoneId
Unwrap
Length
Handle
Issuer
Action
Status
IfType
System
HEvent
Shared
Delete
Signal
Exited
ReadAt
pwrite
rusage
exited
signal
handle
isdone
oldnew`J
Struct
HasTLS
HasIAT
HasCLR
Logger
Header
logger
Parent
Number
Digest
Append
family
Values
_panic`W
Uint16
Enable
Reader
accept
sharpV
fmtSbx
intbuf
*error
*int16
*int32
*int64
opaque
*uint8
pcfile
funcID
nfiles
ptrbit
gcdata
etypes
rodata
gofunc
frames
goexit
insert
remove
noscan
npages
nelems
divMul
inList
isFree
layout
signed
active
result
retPop
unpack
allocN
qcount
ticket
parent
tryGet
mcache
pcache
palloc
timers
thread
divmod
procid
vdsoSP
vdsoPC
noCopy
_defer
labels
inHeap
header
ensure
unlock
scalar
counts
parked
abiMap
*[]int@
delete
misses
doSlow
shared
victim
HasTag
Fields
Mcount
Xcount
Align_
GCData
Floats
Stride
Public@{
opAddr
Source
cancel
Writer
Server
sotype
PollFD
Accept
search
rotate
useTCP
Cancel
negate
action
source
server
dialIP
Dialer
Search
Getenv
decref
incref
rwlock
Fchdir
Fchmod
Fchown
Pwrite
Writev
isFile
msgKey
Debugf
Debugw
Errorf
Errorw
Fatalw
filter`
config
Verify
Reason
Detail
params
Double
Params
domain
length@
suffix
Stderr
Stdout`|
regexp
Writef
Reader
Opaque
recent
enable
addOne
halves
isZero
subOne
BitLen
Is4In6
fixLen
Answer`/
DoChan
doCall
boring
andNot
bitLen
isPow2
random
setBit
sticky
AndNot
CmpAbs
DivMod
QuoRem
SetBit
Scheme
Cookie
Entity
nsname
popEOF
pushNs
ungetc
Indent
indent
attrNS
tmpoff
Errors@
NumCap
Expand
expand
cmpVal
Select
BytesX
bytesX
Invert
Mult32
Negate
Square
reduce
assign
cmpGeq
setBig
fromP2
IntVar
Parsed
parsed
actual
formal
Config
MaxCap
concat
factor
repeat
numCap
height@
isYesC
isYesD
hangul
asciiF
runeAt
flushF
TagWord
*func()
reflect
strings
syscall
Decrypt
Encrypt
tagSize
strconv
decrypt
padChar
Fatalln
Panicln
Println
runtime
PkgPath
buckets
CanAddr
CanUint
Complex
Convert
IsValid
MapKeys
Pointer
SetBool
SetUint
SetZero
TryRecv
TrySend
pointer
ChanDir
gcSlice
nameOff
textOff
typeOff
addRcvr
GcSlice
HasName
MapType
regPtrs
PtrType
*[8]int
topbits
*[]int8
amended
TryLock
*[1]int
unicode
Message
Minutes
Seconds
AddDate
Compare
ISOWeek
Weekday
YearDay
setMono
unixSec
seedPos
Float32
Float64
Shuffle
readVal
readPos
ObjName
Version
Subject
Release
Address
IfIndex
Context
NewProc
Control
Process
Environ
getInfo
Namelen
Buffers
Stopped
ModTime
isempty
dirinfo
ReadDir
Readdir
WriteAt
readdir
wrapErr
Syscall
Timeout
Success
success
release
setDone
Replace
WriteTo
Ordinal
NameRVA
Entries
Meaning
HasCOFF
Culture
Padding
Extends
GetData
ImpHash
Overlay
os/exec
context
CmdLine
started
framepc
Feature
consume
*fmt.pp
badVerb
doPrint
fmt0x64
fmtBool
*string
*uint32
npcdata
ptrSize
funcoff
filetab
covctrs
hasmain
typemap
srcFunc
callers
*uint64
aborted
isEmpty
takeAll
*uint16
pushcnt
tophash
pushAll
dequeue
enqueue
sortkey
inSweep
balance
dispose
putFast
discard
runnext
preempt
destroy
morebuf
gsignal
sigmask
blocked
isextra
alllink
lockedg
libcall
lockedm
startpc
racectx
waiting
cgoCtxt
compute
growing
ensured
gcStats
closing
makeArg
*[]bool
*[]uint
trySwap
popHead
popTail
private
getSlow
pinSlow
RLocker
RUnlock
InCount
IsBlank
Methods
KeySize
InSlice
setting
Network
toLocal
*net.IP
Context
connect
readMsg
setAddr
writeTo
srcAttr
servers
timeout
soffset
trustAD
primary
sources
dialTCP
dialUDP
network
address
InitBuf
InitMsg
RawRead
ReadMsg
prepare
addrLen
mapview
getCert
haveSum
AddCert
isValid
hintErr
net/url
Country
scratch
skipped
environ
running
content
Content
Signers
encoder
Cookies
Request
Writeln
logFile
section
BitSize
Package
Changed
verbose
AsSlice
hasZone
string4
string6
DNSDone
Options
answers
Decoder
Encoder
nMinus2
Inverse
ndigits
setWord
IsInt64
ModSqrt
SetBits
expSlow
setPath
RawPath
newCert
Trailer
GetBody
Referer
toClose
attrval
pushEOF
tmpfile
onepass
longest
FindAll
Longest
doMatch
literal
shiftIn
leading
BoolVar
TextVar
UintVar
sprintf
compose
NoProxy
skipNop
repeats
LeadCCC
isInert
bytesAt
doFlush
Overhead
SetFlags
*[]uint8
go.shape
overflow
CanFloat
MapIndex
MapRange
NumField
SetBytes
SetFloat
assignTo
setRunes
typeSlow
uncommon
FuncType
Pointers
Uncommon
*[8]bool
*[]int16
*[]int32
*[]int64
checkSum
Truncate
cacheEnd
GoString
Location
UnixNano
nextwhen
sockaddr
Flowinfo
Scope_id
Password
Antivirus Signature
Bkav W64.AIDetectMalware
Lionic Trojan.Win32.Agent.Y!c
tehtris Clean
ClamAV Clean
CMC Clean
CAT-QuickHeal Trojan.Multi
Skyhigh Clean
ALYac Trojan.GenericKDZ.107592
Cylance Unsafe
Zillya Clean
Sangfor Dropper.Win32.Agent.V7an
K7AntiVirus Trojan ( 005af30d1 )
Alibaba TrojanDropper:Win64/Genric.c1414b33
K7GW Trojan ( 005af30d1 )
Cybereason Clean
Baidu Clean
VirIT Clean
Paloalto generic.ml
Symantec ML.Attribute.HighConfidence
Elastic malicious (high confidence)
ESET-NOD32 a variant of WinGo/TrojanDropper.Agent.CS
APEX Clean
Avast Win64:Malware-gen
Cynet Malicious (score: 100)
Kaspersky Trojan.MSIL.Agent.qwiuaz
BitDefender Trojan.GenericKDZ.107592
NANO-Antivirus Clean
ViRobot Clean
MicroWorld-eScan Trojan.GenericKDZ.107592
Tencent Msil.Trojan.Agent.Jcnw
TACHYON Clean
Sophos Mal/Generic-S
F-Secure Trojan.TR/AVI.Agent.zumhs
DrWeb Clean
VIPRE Trojan.GenericKDZ.107592
TrendMicro Trojan.Win64.AMADEY.YXEGEZ
McAfeeD ti!CA66A07C7D3F
Trapmine Clean
FireEye Trojan.GenericKDZ.107592
Emsisoft Trojan.GenericKDZ.107592 (B)
SentinelOne Clean
GData Trojan.GenericKDZ.107592
Jiangmin Clean
Webroot Clean
Varist W64/ABTrojan.CTYM-4497
Avira TR/AVI.Agent.zumhs
Antiy-AVL Trojan/Win32.LummaStealer
Kingsoft MSIL.Trojan.Agent.qwiuaz
Gridinsoft Trojan.Win64.Agent.sa
Xcitium Clean
Arcabit Trojan.Generic.D1A448
SUPERAntiSpyware Clean
ZoneAlarm Trojan.MSIL.Agent.qwiuaz
Microsoft Trojan:Win32/LummaStealer.MWW!MTB
Google Detected
AhnLab-V3 Trojan/Win.Evo-gen.C5558850
Acronis Clean
McAfee Artemis!F2A5C7E83138
MAX malware (ai score=86)
VBA32 Clean
Malwarebytes Malware.AI.3279684942
Panda Clean
Zoner Clean
TrendMicro-HouseCall Trojan.Win64.AMADEY.YXEGEZ
Rising Trojan.Injector!1.F43F (CLASSIC)
Yandex Clean
Ikarus Trojan-Dropper.WinGo.Agent
MaxSecure Clean
Fortinet W32/Agent.CS!tr
BitDefenderTheta Clean
AVG Win64:Malware-gen
DeepInstinct MALICIOUS
CrowdStrike win/malicious_confidence_70% (D)
alibabacloud Trojan[dropper]:Multi/Agent.CB
No IRMA results available.