Static | ZeroBOX

PE Compile Time

2024-07-12 07:12:31

PE Imphash

54a5cf5c66bf4d0985703442865d04af

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x00024b79 0x00024c00 6.6515791369
.css 0x00026000 0x000007b5 0x00000800 6.50137661805
.rdata 0x00027000 0x0000bf74 0x0000c000 4.97708932058
.data 0x00033000 0x0004c864 0x0004b800 7.98744025039
.rsrc 0x00080000 0x000001e0 0x00000200 4.70150325825
.reloc 0x00081000 0x00002198 0x00002200 6.52995348021

Resources

Name Offset Size Language Sub-language File type
RT_MANIFEST 0x00080060 0x0000017d LANG_ENGLISH SUBLANG_ENGLISH_US XML 1.0 document text

Imports

Library USER32.dll:
0x427160 OffsetRect
Library KERNEL32.dll:
0x427000 CreateFileW
0x427004 HeapSize
0x427008 SetStdHandle
0x42700c WaitForSingleObject
0x427010 CreateThread
0x427014 VirtualAlloc
0x427018 RaiseException
0x427020 InitOnceComplete
0x427024 CloseHandle
0x427028 GetCurrentThreadId
0x427040 WideCharToMultiByte
0x427044 GetLastError
0x427054 CloseThreadpoolWork
0x427058 GetModuleHandleExW
0x427074 EncodePointer
0x427078 DecodePointer
0x42707c MultiByteToWideChar
0x427080 LCMapStringEx
0x427088 GetModuleHandleW
0x42708c GetProcAddress
0x427090 GetStringTypeW
0x427094 GetCPInfo
0x427098 IsDebuggerPresent
0x4270a4 GetStartupInfoW
0x4270a8 GetCurrentProcess
0x4270ac TerminateProcess
0x4270b0 GetCurrentProcessId
0x4270b4 InitializeSListHead
0x4270b8 GetProcessHeap
0x4270bc RtlUnwind
0x4270c0 SetLastError
0x4270c8 TlsAlloc
0x4270cc TlsGetValue
0x4270d0 TlsSetValue
0x4270d4 TlsFree
0x4270d8 FreeLibrary
0x4270dc LoadLibraryExW
0x4270e0 ExitProcess
0x4270e4 GetModuleFileNameW
0x4270e8 GetStdHandle
0x4270ec WriteFile
0x4270f0 HeapAlloc
0x4270f4 HeapFree
0x4270f8 LCMapStringW
0x4270fc GetLocaleInfoW
0x427100 IsValidLocale
0x427104 GetUserDefaultLCID
0x427108 EnumSystemLocalesW
0x42710c GetFileType
0x427110 GetFileSizeEx
0x427114 SetFilePointerEx
0x427118 FlushFileBuffers
0x42711c GetConsoleOutputCP
0x427120 GetConsoleMode
0x427124 ReadFile
0x427128 ReadConsoleW
0x42712c HeapReAlloc
0x427130 FindClose
0x427134 FindFirstFileExW
0x427138 FindNextFileW
0x42713c IsValidCodePage
0x427140 GetACP
0x427144 GetOEMCP
0x427148 GetCommandLineA
0x42714c GetCommandLineW
0x427158 WriteConsoleW

!This program cannot be run in DOS mode.
Rich-X
`.rdata
@.data
@.reloc
4VWQPS
4VWRQS
D$0j.Xf
GD$LPQR
D$<QPS
GD$0)|$
T$tPRQ
~,9~$t
t$0VPW
YYW9^d|
L$8_^][3
tB9u>Vj
tK9uGVj
D$@PUS
D$ PUhTsB
D$,PUh\sB
GD$@PQR
D$4QPU
D$$RPU
G|$ QQ
G|$ QQ
\$ jLPS
GD$$QP
FYY;t$
FYY;t$
u9F(t
YYhdsB
tG9uCj
PPPPPWS
QQSVWd
URPQQh`
UQPXY]Y[
<ItC<Lt3<Tt#<h
A<lt'<tt
<ItC<Lt3<Tt#<h
A<lt'<tt
F +F4+
8^8tb9^4~]
V +V4+
tb9^4~]
PRRRRR
PPPPPPPP
PVVVVV
PVVVVV
ARPRQh
jYjf
j,h@"C
j"^f92
j"_f9z
SWt@jU
_tqPVj@
f-00f=
f-00f=
M,j"^QRRRRR
Vj0XPW
r!SSPVQ
dr#SSjdVQ
M$j"^QRRRRR
j"[VWWWW
_PVVVVV
j"_SVVVV
PVVVVV
^PSSSSS
j"^WSSSS
WVVVVV
PVSRSQV
PPPPPVW
PP9E u!PPSVP
PVVVVV
PWWWWW
D8(Ht'
D8(Ht5F
L:-^_[
t^j*Yf
f9:t!V
QQSVj8j@
NX9^`t1
;V\uYW
u2Vj@h
9C`u99C\t4
u29K\t-
^PQQQQQ
E ^PQQQQ
CY<u
PPPPPPPP
D$DSV3
74s,l4thDuB
,e4",shXuB
VWhhuB
Unknown exception
bad array new length
string too long
generic
iostream
iostream stream error
bad cast
bad locale name
ios_base::badbit set
ios_base::failbit set
ios_base::eofbit set
Fail to schedule the chore!
This function cannot be called on a default constructed task
broken promise
future already retrieved
promise already satisfied
no state
future
Own head
Zatlat
0000000006:1@0000000005:@
Success created.
Success destroyed.
invalid string position
vector too long
Bbad allocation
bad function call
bad exception
device or resource busy
invalid argument
no such process
not enough memory
operation not permitted
resource deadlock would occur
resource unavailable try again
success
address family not supported
address in use
address not available
already connected
argument list too long
argument out of domain
bad address
bad file descriptor
bad message
broken pipe
connection aborted
connection already in progress
connection refused
connection reset
cross device link
destination address required
directory not empty
executable format error
file exists
file too large
filename too long
function not supported
host unreachable
identifier removed
illegal byte sequence
inappropriate io control operation
interrupted
invalid seek
io error
is a directory
message size
network down
network reset
network unreachable
no buffer space
no child process
no link
no lock available
no message available
no message
no protocol option
no space on device
no stream resources
no such device or address
no such device
no such file or directory
not a directory
not a socket
not a stream
not connected
not supported
operation canceled
operation in progress
operation not supported
operation would block
owner dead
permission denied
protocol error
protocol not supported
read only file system
result out of range
state not recoverable
stream timeout
text file busy
timed out
too many files open in system
too many files open
too many links
too many symbolic link levels
value too large
wrong protocol type
unknown error
GetCurrentPackageId
GetSystemTimePreciseAsFileTime
GetTempPath2W
0123456789abcdefghijklmnopqrstuvwxyz
0123456789abcdefghijklmnopqrstuvwxyz
__based(
__cdecl
__pascal
__stdcall
__thiscall
__fastcall
__vectorcall
__clrcall
__eabi
__swift_1
__swift_2
__swift_3
__ptr64
__restrict
__unaligned
restrict(
delete
operator
`vftable'
`vbtable'
`vcall'
`typeof'
`local static guard'
`string'
`vbase destructor'
`vector deleting destructor'
`default constructor closure'
`scalar deleting destructor'
`vector constructor iterator'
`vector destructor iterator'
`vector vbase constructor iterator'
`virtual displacement map'
`eh vector constructor iterator'
`eh vector destructor iterator'
`eh vector vbase constructor iterator'
`copy constructor closure'
`udt returning'
`local vftable'
`local vftable constructor closure'
new[]
delete[]
`omni callsig'
`placement delete closure'
`placement delete[] closure'
`managed vector constructor iterator'
`managed vector destructor iterator'
`eh vector copy constructor iterator'
`eh vector vbase copy constructor iterator'
`dynamic initializer for '
`dynamic atexit destructor for '
`vector copy constructor iterator'
`vector vbase copy constructor iterator'
`managed vector copy constructor iterator'
`local static thread guard'
operator ""
operator co_await
operator<=>
Type Descriptor'
Base Class Descriptor at (
Base Class Array'
Class Hierarchy Descriptor'
Complete Object Locator'
`anonymous namespace'
FlsAlloc
FlsFree
FlsGetValue
FlsSetValue
InitializeCriticalSectionEx
(null)
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
[aOni*{
~ $s%r
@b;zO]
v2!L.2
CorExitProcess
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
Sunday
Monday
Tuesday
Wednesday
Thursday
Friday
Saturday
January
February
August
September
October
November
December
MM/dd/yy
dddd, MMMM dd, yyyy
HH:mm:ss
UUUUUU
?UUUUUU
UUUUUU
?UUUUUU
_hypot
_nextafter
AreFileApisANSI
CompareStringEx
EnumSystemLocalesEx
GetDateFormatEx
GetLocaleInfoEx
GetTimeFormatEx
GetUserDefaultLocaleName
IsValidLocaleName
LCMapStringEx
LCIDToLocaleName
LocaleNameToLCID
AppPolicyGetProcessTerminationMethod
NAN(SNAN)
nan(snan)
NAN(IND)
nan(ind)
?uZEeu
?uZEeu
1#QNAN
1#SNAN
?5Wg4p
%S#[k=
"B <1=
.text$di
.text$mn
.text$x
.text$yd
.css$x
.idata$5
.00cfg
.CRT$XCA
.CRT$XCAA
.CRT$XCC
.CRT$XCL
.CRT$XCU
.CRT$XCZ
.CRT$XIA
.CRT$XIAA
.CRT$XIAC
.CRT$XIC
.CRT$XIZ
.CRT$XLA
.CRT$XLZ
.CRT$XPA
.CRT$XPX
.CRT$XPXA
.CRT$XPZ
.CRT$XTA
.CRT$XTZ
.rdata
.rdata$T
.rdata$r
.rdata$sxdata
.rdata$voltmd
.rdata$zzzdbg
.rtc$IAA
.rtc$IZZ
.rtc$TAA
.rtc$TZZ
.tls$ZZZ
.xdata$x
.idata$2
.idata$3
.idata$4
.idata$6
.data$r
.data$rs
.rsrc$01
.rsrc$02
OffsetRect
USER32.dll
WaitForSingleObject
CreateThread
VirtualAlloc
RaiseException
InitOnceBeginInitialize
InitOnceComplete
CloseHandle
GetCurrentThreadId
ReleaseSRWLockExclusive
AcquireSRWLockExclusive
TryAcquireSRWLockExclusive
WakeAllConditionVariable
SleepConditionVariableSRW
WideCharToMultiByte
GetLastError
FreeLibraryWhenCallbackReturns
CreateThreadpoolWork
SubmitThreadpoolWork
CloseThreadpoolWork
GetModuleHandleExW
IsProcessorFeaturePresent
EnterCriticalSection
LeaveCriticalSection
InitializeCriticalSectionEx
DeleteCriticalSection
QueryPerformanceCounter
EncodePointer
DecodePointer
MultiByteToWideChar
LCMapStringEx
GetSystemTimeAsFileTime
GetModuleHandleW
GetProcAddress
GetStringTypeW
GetCPInfo
IsDebuggerPresent
UnhandledExceptionFilter
SetUnhandledExceptionFilter
GetStartupInfoW
GetCurrentProcess
TerminateProcess
GetCurrentProcessId
InitializeSListHead
KERNEL32.dll
RtlUnwind
SetLastError
InitializeCriticalSectionAndSpinCount
TlsAlloc
TlsGetValue
TlsSetValue
TlsFree
FreeLibrary
LoadLibraryExW
ExitProcess
GetModuleFileNameW
GetStdHandle
WriteFile
HeapAlloc
HeapFree
LCMapStringW
GetLocaleInfoW
IsValidLocale
GetUserDefaultLCID
EnumSystemLocalesW
GetFileType
GetFileSizeEx
SetFilePointerEx
FlushFileBuffers
GetConsoleOutputCP
GetConsoleMode
ReadFile
ReadConsoleW
HeapReAlloc
FindClose
FindFirstFileExW
FindNextFileW
IsValidCodePage
GetACP
GetOEMCP
GetCommandLineA
GetCommandLineW
GetEnvironmentStringsW
FreeEnvironmentStringsW
GetProcessHeap
SetStdHandle
HeapSize
CreateFileW
WriteConsoleW
h9'_/T
w?'nfdj
_Vg!3H=_
2\[gWx(
J0yBKU
{0:z0L
YI/+!K
HiDrY
.#TkGle@
u02fQ@
v+(e"bS
F^~3Qd
IJ'AZ^
i,Nib
],!P=`
x6SIK$
_8_6rkQ
mT%.W5\{oW
@J9."
R""0C2
Fugrv9
lIoZ[ID
vpOZ"J
ld,Zy,
A?Y~In
:#&yh'v
o?@+fC
|I]v{|
<HSj=C
.et5aF
C;#+I[%
]uo;au_5
Dfx)Z7^q
A0-yEGC
ciCI7%V
Rt$77}
7bHYlH
8Y%Bu`
E\ wT+k
G@v;/Rj
W|$,\U
5&ZL`w-/
#G+PtYE
W|s;I^
.(fCm(zr4A
b^D& g
.VO[xd
3ql4m8H
!YM#h?
R'Bqik
rp0uru
3<YC4$
pm]II[
*"?[3&
ku54(/Y
?0L9VY
W-J' M
87ipGo
n<?cT+u
/f98*=
oS!Y{7
ie.KS3P
Hi".broR
PG;&g6
7>JIRW
GF(A]j7
:&-`pr
5OMOOar
N3U9)S
?uU?LF
d5qxY`@e
v\#=8/d,F
{)?D!A
ah{@x?
2!_./#
!*.?_?
4D9[iD
w+1W4_
W@/MZp
T:vcn7a
@_vs'}
f~awSl%{
Df[qPx*
CyMn`tc
[Gp3an1
6/>j$L
;W#%hL
hzAO?#
i{A)&}Dd
qIC`BR
4Zpp&x=8
*{)B^m
oq@\!0g-
JIvQ@}vE
HLF@n|YUe
@Q_Pr/
OF!Q8J
H]n@FQW
rO;]J9
F2hB"W^D3
Oz](At=<
Qfaf?Q8
$nH)RDS
Zi/C&@
^_c!":
> |jxV[
179lZTi]
<~1P,Mq
@%[7>B=
Q$zcM|YZ
$>O<6*
9XuP40IF
~9(;Jh
*cy50F
i6],oI
Vbep:<
L ?R0BFR(&*
*&|:7g'Z
y8cLPi7
vxC)qu@
.`G+a?
$SL\Um%5[v
[V^)P~
,7|@z`{ec
b`fkDI
=%Z[3,X
4sr}It
f)D8<G
0lS$2q
]JRw{q
N *va:
!/}mo>
=6L14N
T,3\/\
X0j/_EQ
farC9#W
wwFq,ah
jE_zBK
~Un><K
)v\:pk
=Mh<I3
@G%PacA
~r8odc
Kh.&5
*h.=pq
e3Vc^p
o-vI\;
e]$6T{
0n=;#`
h3C3\E
.SF{Fw
TcFLi|x
C%ew_o
'st8_'
RfpE^[
Jg'X,J
W*HIJR
eLAxo~
_|&sbc
#4Z(7Zvn
H[\.IUCD(X
P @l^\
}B4({x8
X:2GMS
sY]@2x
B/ze#hy
45Ra~;?
~1n&VI
o((_G:
2^#O=
j<_0k.p
,w7.G"'
!Lp|_R
pGIl)K
[9Jg=xlc
VW8e}b
cUuyf+W1
w-ce5l
AbF%+el
nzlZk?u
2C{Ar%h
(^A/qx
$RGXyxX5
v[3Dfm
C9}}Tb
'gs5x
>x5Ysk
F\WS-<E5
i{cEk)
<G-2yV}
Tt<@a5E
mYEQIQ
*~JLw@X
_8fPvSZ.;
DU{R,s6
'23@qW
#Eq!?y
cD]b$]Q
=JU\uK
k4`IBn
.?%fI
f0t)bH
HgopU?
hmx|@y
iy(Q/|
Zh?^-'i
3F+*8l+
S'X[[w
{$H`"~
{sJE}v
)l{W_
5Wuc0J
f;2LqRpq;?
S-Y(cGds
^A#y.{)<
4WD[CS
3NAzo_<
|LM\\}
is6:d
g!t\]q
9wx&)8
fE#%P
e$RXy%
ji-|aD)-@
qT!jWl
6W3p2x
[F \e+
:zfyE{Q\
45DH2X%w
DGDPFm
MlF>|'
x|TXxL
?<JqUB
=BVnS2
Euis&u
>p3EjX
Itb/-j
?tg!-~
r-p=/|
woq6v.
=eoX~.T
U:4JKY@8
Bm=l[\
81kekl[M
H]s,TW
#X"2s3Y8
E%%5bZ
V>-|S/
U[Viko`
!'d\y1
LgX9R+2&
8lNkM5
:8\qp;
P#a{]1
xA?hE7a~
^LCZ]|
U<QOb/
+"F0V`
Ra8@axy
vMP-L(
aAE0;`
CGn>rO 8
s%u~bR
0Rw<w,
;ss)G:%
L2<n47,
]`:.^V
2\ ZVI
<*XywZ
mDXQB61/
R@V~t
X5JN*j
~(ysoP
i|w^{7
4LzF0*
qR)Bnl
B'<:V-
Lw!'.*
R7pcJq
G\1%%!
:[ L7Hiu
cF'GWb@"p
33#dH&
/(}x~v
]'S.=`
Hw3NUH
le$+;5QQ^
68S.\Xe
~~sJ+?
xiaihTd9=
vS|J~q
adPO;?
p,yB*h
Jo/MjOy
Th(?k<
1D3?-{&l
*x_G^o
Z5V9Hq|
1v5vbQ
?sFx(^
iz.}84]{
QnAIwk
/,l*I2
RF,4&U
0XhOoJ#
,?:b9Lm
v>R?:F
u9?$X[
k#]|aUU
\4<7f2
BFj^`<
oUn0-&
3*2<R]X
* ]s5#
v1hWV$
BsW<c.
*a3zND
d2t7w)
ZLqp}+
4Ir 64
tC^]t&$`
";9rZs
fG:x&5
TYt`F}d
Sa:<])#
pv5bln;nJ
!HM"2t
`D@I/v
*0xZ:H
t?)[EZ
l5^pT1
#z&qPc
,1HR je:Z
EQTINJ
_XF+3C@w
Wr+I7z
!^_S%K
ToqCN]
[GU$UZ
262*W
4,C)tB
kWD^?/
?&+]u**
mZp)]M
oSjr3I8
J!1c8=!
WD)xs|
mrO^ya
Gk0H.=+
j'*1y:
wzl;C>
nKqo|[
eVa10P
"(OeM#
.`%Mez
%C8,G1Q
rl>[:{
VH=lEO
6xQ6zu
|~DaHO
WvfI[R
:=>T{s
kO|},4
,w+Ixk
\{lRo)t
*5TC>7
wfaFZ^
&-KhI`or)
,2EY"u
.=byBO
o}ZF/c
4[MO]Wz|
t]Z`;zxM^~
s>p5K(V
I!1r;4
zO7#B|
tUQ/4{:
{LfNR^
Tvbx%l
=&gLml>a
dwgOXf
o_a2t
/%koIL,
j2K4`=
?Q*v]:
lghRV$
*"cJyj
FZLl99
gXyRIgz
F*4IA[
wW7$c;O
\CgTw<W
zXNp+%
+1?q<F
h$]lQwvX/
M >^k9
)CqJ:|
2PO8=0C
I6EELmotf
2&buK>K
@2B7!LuC
IKYE\[
@E2O8;{
rvcQhp
>Jgr?1lE
^2NHh(
#UU$2F
3.>QU'
_k^Hd,
gp:Mo,
+]<RTJpr
{;Ep0]
h\x6G[4
h~'<%z6,
4%`klb
d;#IHm
;&|mA#0o:
%$foJcP)
bXTJ~:
8#Y%YRD}+!
JQy:8
O9z{BAs
=K/Ii*^
+BwndvpZ
Y\Z*_[{
Flw[*v
&%xRhC
64+]83
%W.OSOJe(3
c@R!E%
u75iB\
#OO('*
..+@&r
^_Yzc0e
^&:;Gz2
!+7(r*
ac#8ADo
!S[?bI
!bgJX%}%a
VM~"u^Y
fW4Zs{
u4D'xw9~+
#"~J6/
qsJqwd
oC@$7
=K_8I
xcdUOA^G
y@zIo\?SN
ysTC2j
zAB;O)
SDDGp
pwXylQ"
*\*e-<
-s0.eul
}MQkVQ
0clr7j
VwuUA*
#3J|n'
~[\D!
j#-;D4
Cq.WVz
Y=~Mu`
9*2d0d
^u[=FYV
>U?UbPT
+aNb|}
AG]yPj
#-<&Gy
vL?qs>?
"s~K8!
+0$LL*
pE;piAs
e*&P>"
n:"Xqs
\6Qq>,3~:H]
]!c')L
$O}h=Pwi
EPb1w[`
0!_k)}
)d]zh6
wu`.,d
yit'G
-@r21IT
IL{m7M#)
XKifrOh
c=hB!_:
fy4u,6
DN~$2T
jefoTs+
Z3Xs>'\
^%)H98
eN\9i9
Rv+n4RF@
xP|H&{
~~|H&{
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
.?AVexception@std@@
.?AVbad_array_new_length@std@@
.?AVbad_alloc@std@@
.?AVruntime_error@std@@
.?AVsystem_error@std@@
.?AV_System_error@std@@
.?AVbad_cast@std@@
.?AVfailure@ios_base@std@@
.?AVtask_canceled@Concurrency@@
.?AVinvalid_operation@Concurrency@@
.?AV_Interruption_exception@details@Concurrency@@
.?AVfuture_error@std@@
.?AVlogic_error@std@@
.?AV<lambda_0456396a71e3abd88ede77bdd2823d8e>@@
.?AV<lambda_eb87dfd73f857f44e1a351ea42ce2b34>@@
.?AV<lambda_cf64729cb90f65090849ddab3f3d5e68>@@
.?AV<lambda_5e5ab22ea98f4361dbf159481d01f54d>@@
.?AV?$_Fake_no_copy_callable_adapter@A6AXXZ@std@@
.?AV<lambda_dc3a808d3cb651230a54fc79f9ff1e4d>@@
.?AVlength_error@std@@
.?AVout_of_range@std@@
.?AVbad_function_call@std@@
.?AVbad_exception@std@@
.?AVerror_category@std@@
.?AV_Generic_error_category@std@@
.?AV_Iostream_error_category2@std@@
.?AV_Ref_count_base@std@@
.?AV_Facet_base@std@@
.?AVfacet@locale@std@@
.?AU_Crt_new_delete@std@@
.?AUctype_base@std@@
.?AV?$ctype@D@std@@
.?AV_RefCounter@details@Concurrency@@
.?AV_CancellationTokenRegistration@details@Concurrency@@
.?AU_TaskProcHandle@details@Concurrency@@
.?AV?$_Func_base@X$$V@std@@
.?AU_Task_impl_base@details@Concurrency@@
.?AV?$_CancellationTokenCallback@V<lambda_3b8ab8d2629adf61a42ee3fe177a046b>@@@details@Concurrency@@
.?AV?$_Func_base@E$$V@std@@
.?AU?$_Task_impl@E@details@Concurrency@@
.?AV_Future_error_category2@std@@
.?AV?$_Associated_state@H@std@@
.?AV?$num_put@DV?$ostreambuf_iterator@DU?$char_traits@D@std@@@std@@@std@@
.?AV?$numpunct@D@std@@
.?AV?$_Ref_count_obj2@U_ExceptionHolder@details@Concurrency@@@std@@
.?AV?$_Ref_count_obj2@U?$_Task_impl@E@details@Concurrency@@@std@@
.?AV?$_Func_impl_no_alloc@V<lambda_5e5ab22ea98f4361dbf159481d01f54d>@@X$$V@std@@
.?AV?$_Func_impl_no_alloc@V<lambda_cf64729cb90f65090849ddab3f3d5e68>@@X$$V@std@@
.?AV?$_Func_impl_no_alloc@V<lambda_eb87dfd73f857f44e1a351ea42ce2b34>@@E$$V@std@@
.?AV?$_Func_impl_no_alloc@V<lambda_0456396a71e3abd88ede77bdd2823d8e>@@X$$V@std@@
.?AV?$_Deferred_async_state@X@std@@
.?AV?$_Packaged_state@$$A6AXXZ@std@@
.?AV?$_Task_async_state@X@std@@
.?AV?$_Func_impl_no_alloc@V?$_Fake_no_copy_callable_adapter@A6AXXZ@std@@X$$V@std@@
.?AU?$_InitialTaskHandle@XV<lambda_dc3a808d3cb651230a54fc79f9ff1e4d>@@U_TypeSelectorNoAsync@details@Concurrency@@@?$task@E@Concurrency@@
.?AU?$_PPLTaskHandle@EU?$_InitialTaskHandle@XV<lambda_dc3a808d3cb651230a54fc79f9ff1e4d>@@U_TypeSelectorNoAsync@details@Concurrency@@@?$task@E@Concurrency@@U_TaskProcHandle@details@3@@details@Concurrency@@
.?AV?$_Func_impl_no_alloc@V<lambda_dc3a808d3cb651230a54fc79f9ff1e4d>@@X$$V@std@@
.?AV_ExceptionPtr_normal@?A0x6e02efe5@@
.?AV?$_ExceptionPtr_static@Vbad_alloc@std@@@?A0x6e02efe5@@
.?AV?$_ExceptionPtr_static@Vbad_exception@std@@@?A0x6e02efe5@@
.?AV_Locimp@locale@std@@
.?AVios_base@std@@
.?AV?$_Iosb@H@std@@
.?AV?$basic_ios@DU?$char_traits@D@std@@@std@@
.?AV?$basic_streambuf@DU?$char_traits@D@std@@@std@@
.?AV?$basic_ostream@DU?$char_traits@D@std@@@std@@
.?AV?$basic_filebuf@DU?$char_traits@D@std@@@std@@
.?AVcodecvt_base@std@@
.?AV?$codecvt@DDU_Mbstatet@@@std@@
.?AVtype_info@@
<?xml version='1.0' encoding='UTF-8' standalone='yes'?>
<assembly xmlns='urn:schemas-microsoft-com:asm.v1' manifestVersion='1.0'>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v3">
<security>
<requestedPrivileges>
<requestedExecutionLevel level='asInvoker' uiAccess='false' />
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
0#0*070;0G0M0[0p0z0
1#13181B1X1l1p1z1
222Q2P3Z3
<#<)<6<q<
='===U=m=
=@>\>m>
6E7U7u7
11%1+1?1I1Y1a1q1x1
4%5]5p5
:V:R=_=t=
>->J>u>}>
0%0+01070=0Q0n0
2:3E3P3j4t4y4
041Y1_1e1
55:5G5S5k5q5
6!6R6o6
8"8/8a8n8
??6?C?p?v?}?
1'262E2d2
5&6>6Q6f6v6
6&777>7F7\7x7
88T8|8
9 9;9F9R<_<p<~<
=2=F=L=d=n=|=
><>C>l>
>)?3?`?u?
N0S0Y0o0u0
1&1=1_1
203T3~3/4p4
2"2(2/262\2
767E7\7b7h7n7t7z7
7;8H8p8
90989E9R9W9]9d9
;H;];b;g;
>,?5?>?L?U?w?~?
1$1c1i1
2%20272J2X2^2d2j2p2v2}2
3#3,3P3^3d3j3p3v3|3
4&454>4K4a4
5 535G5L5_5
88$8(8,808
9 9$9(9,9094989<9@9D9H9L9P9T9X9\9`9d9h9l9p9t9x9+:
<1<M<X<f<l<}<
788 :%:O:k:
<3<[<o<
=!=<=I=R=W=\=w=
>1>A>Y>
>T?c?|?
4.?H?W?e?q?}?
0#010?0J0
0'1_>j?
A1'3+3/33373;3?3C3
374U4~4
4"6A6i6
91R1g1
2'2.2:2R2W2c2h2|2
2e3l3~3
44(414B4S4s4
4(52585>5L5
:!:,:K:
;!<p<{<
?+?D?K?T?
0-0z0
6.;4;F;Q;
<F<M<l<
=A=V=f=s=
>>9>H>i>
495G5Y5d5
6!6>6D6Y6~6
8*858G8
3I4O4{4
4.555<5C5P5
9%9H9R9y9
9*:2:F:R:W:\:l:q:v:
;";';,;<;A;F;V;[;`;
<%<2<G<P<
<!=X=]=b=}=
>>=>L>q>
?.?E?o?
0^0g0~0
1Z2l2r2
8+9N9b9
:@:R:\:
;3;Z;{;
=A>d>y?
040Y0w0
1&2/23292=2C2G2Q2d2r2
516;8U8
9)909G9]9
:3:<:]:o:
;#;5;t;Y>
?0?B?T?
0S0d0u0
3F4f4v4
9):0:7:Z:
1f5l6t6
=->G>T>
,0O0]0
5*525O5_5k5z5
777T7h7s7
7 8+818:8t8
9_9h9q9z9
535P5m5
7 7B7_7
9$:A:^:{:
;(;4;>;H;R;\;f;p;
a0f0u0
1r2v2z2~2
6$6C6p6x6
h1t1x1|1
1$2(2,2D2H2L2P2T2X2
3 3$34383<3@3h3l3p3t3x3|3
4 4$4(4,4044484|4
5(5,5054585<5@5
6064686<6@6L6P6T6X6\6p6t6x6|6
7 7$7(7,7074787<7@7D7H7L7P7T7X7\7`7d7h7l7p7t7x7|7
8 8$8(8,8084888<8@8D8H8
<$<,<4<<<D<L<T<\<d<l<t<|<
=$=,=4=<=D=L=T=\=d=l=t=|=
4 4$4(4,4044484<4@4D4H4L4P4T4X4\4`4d4h4l4p4t4x4|4
7 7(70787@7H7P7X7`7h7p7x7
8 8(80888@8H8P8X8`8h8p8x8
9 9(90989@9H9P9X9`9h9p9x9
: :(:0:8:@:H:
t0x0|0
8$8(8,80848
: :$:(:,:0:4:8:<:@:D:H:L:P:\:`:d:h:l:p:t:x:|:
0$0,040<0D0L0T0\0d0l0t0|0
8 8$8p8t8x8|8
9(949@9L9X9d9p9|9
:$:0:<:H:T:`:l:x:
; ;,;8;D;P;\;h;t;
< <,<8<D<P<\<h<t<
?$?,?4?<?D?L?T?\?d?l?t?|?
0$0,040<0D0L0T0\0d0l0t0|0
1$1,141<1D1L1T1\1d1l1t1|1
2$2,242<2D2L2T2\2d2l2t2|2
3$3,343<3D3L3T3\3d3l3t3|3
4$4,444<4D4L4T4\4d4l4t4|4
5$5,545<5D5L5T5\5d5l5t5|5
0080@0H0P0X0`0h0p0x0
1 1(10181@1H1P1X1`1h1p1x1
2 2(20282@2H2P2X2`2h2p2x2
3 3(30383@3H3P3X3`3h3p3x3
4 4(40484@4H4P4X4`4h4p4x4
5 5(50585@5H5P5X5`5h5p5x5
6 6(60686@6H6P6X6`6h6p6x6
7 7(70787@7H7
Z1^1b1f1
;,;0;@;D;H;P;h;x;|;
<(<,<0<8<P<`<d<l<
=(=8=<=L=P=T=\=t=
> >(>@>P>T>d>h>p>
?$?(?,?0?4?<?T?d?h?x?|?
0(0,00080P0`0d0t0x0
1,1<1@1H1`1p1t1
2,2<2@2P2T2X2`2x2
3$3(383<3D3\3l3p3
4(4,40484P4`4d4t4x4|4
545D5H5X5\5`5h5
6 686H6L6P6d6h6x6|6
7(7,70747<7T7X7p7
8 888H8L8\8`8d8h8p8
9$94989H9L9P9X9p9
:,:0:4:8:<:D:\:l:p:
; ;$;(;0;H;X;\;l;p;x;
< <8<H<L<\<`<d<l<
=,=0=@=D=L=d=
4$4H4T4\4t4|4
5(545<5\5
606<6D6d6
787D7L7l7
708<8D8\8d8l8t8
9$9,9094989@9T9\9p9x9
: :$:,:@:H:P:X:\:`:h:|:
;,;4;<;D;H;P;d;l;x;
;@<L<l<x<
=(=0=H=X=p=x=
>(>H>P>X>\>d>x>
?(?4?T?`?
0L0P0l0p0
1$1,1T1X1t1x1
282X2x2
383X3t3x3
4(4H4h4
5(5H5h5
6(6H6h6
<L=P=X=
=@?D?H?L?P?T?X?\?`?d?p?t?x?|?
0(0@0L0P0T0p0t0H3L3P3T3
909P9l9
9 :@:`:
=<=\=x=
= >D>x>
DigiCert Inc1
www.digicert.com1!0
DigiCert Trusted Root G40
210429000000Z
360428235959Z0i1
DigiCert, Inc.1A0?
8DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA10
[K]taM?
SA|X=G
http://ocsp.digicert.com0A
5http://cacerts.digicert.com/DigiCertTrustedRootG4.crt0C
2http://crl3.digicert.com/DigiCertTrustedRootG4.crl0
jj@0HK4
DigiCert, Inc.1A0?
8DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA10
230113000000Z
260116235959Z0
California1
Santa Clara1
NVIDIA Corporation1
NVIDIA Corporation0
Aoi0Ka
Mhttp://crl3.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crl0S
Mhttp://crl4.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crl0>
http://www.digicert.com/CPS0
http://ocsp.digicert.com0\
Phttp://cacerts.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crt0
DigiCert, Inc.1A0?
8DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1
joS&;J
20231102033749Z0
Ontario1
Ottawa1
Entrust, Inc.1+0)
"Entrust Timestamp Authority - TSA1
Entrust.net1@0>
7www.entrust.net/CPS_2048 incorp. by ref. (limits liab.)1%0#
(c) 1999 Entrust.net Limited1301
*Entrust.net Certification Authority (2048)0
991224175051Z
290724141512Z0
Entrust.net1@0>
7www.entrust.net/CPS_2048 incorp. by ref. (limits liab.)1%0#
(c) 1999 Entrust.net Limited1301
*Entrust.net Certification Authority (2048)0
Entrust.net1@0>
7www.entrust.net/CPS_2048 incorp. by ref. (limits liab.)1%0#
(c) 1999 Entrust.net Limited1301
*Entrust.net Certification Authority (2048)0
150722190254Z
290622193254Z0
Entrust, Inc.1(0&
See www.entrust.net/legal-terms1907
0(c) 2015 Entrust, Inc. - for authorized use only1&0$
Entrust Timestamping CA - TS10
T=A^C_(F
http://www.entrust.net/rpa03
http://ocsp.entrust.net02
!http://crl.entrust.net/2048ca.crl0
Entrust, Inc.1(0&
See www.entrust.net/legal-terms1907
0(c) 2015 Entrust, Inc. - for authorized use only1&0$
Entrust Timestamping CA - TS10
221004172103Z
290101000000Z0u1
Ontario1
Ottawa1
Entrust, Inc.1+0)
"Entrust Timestamp Authority - TSA10
_Xg>gX
http://ocsp.entrust.net03
'http://aia.entrust.net/ts1-chain256.cer01
http://crl.entrust.net/ts1ca.crl0
https://www.entrust.net/rpa0
Entrust, Inc.1(0&
See www.entrust.net/legal-terms1907
0(c) 2015 Entrust, Inc. - for authorized use only1&0$
Entrust Timestamping CA - TS1
231102033749Z0)
Entrust, Inc.1(0&
See www.entrust.net/legal-terms1907
0(c) 2015 Entrust, Inc. - for authorized use only1&0$
Entrust Timestamping CA - TS1
kernel32.dll
Bapi-ms-win-core-fibers-l1-1-1
api-ms-win-core-synch-l1-2-0
kernel32
api-ms-
(null)
((((( H
((((( H
(
mscoree.dll
ALC_ALL
LC_COLLATE
LC_CTYPE
LC_MONETARY
LC_NUMERIC
LC_TIME
Sunday
Monday
Tuesday
Wednesday
Thursday
Friday
Saturday
January
February
August
September
October
November
December
MM/dd/yy
dddd, MMMM dd, yyyy
HH:mm:ss
Bapi-ms-win-core-datetime-l1-1-1
api-ms-win-core-file-l1-2-2
api-ms-win-core-localization-l1-2-1
api-ms-win-core-localization-obsolete-l1-2-0
api-ms-win-core-processthreads-l1-1-2
api-ms-win-core-string-l1-1-0
api-ms-win-core-sysinfo-l1-2-1
api-ms-win-core-winrt-l1-1-0
api-ms-win-core-xstate-l2-1-0
api-ms-win-rtcore-ntuser-window-l1-1-0
api-ms-win-security-systemfunctions-l1-1-0
ext-ms-win-ntuser-dialogbox-l1-1-0
ext-ms-win-ntuser-windowstation-l1-1-0
advapi32
api-ms-win-appmodel-runtime-l1-1-2
user32
api-ms-win-core-fibers-l1-1-0
ext-ms-
Bja-JP
american
american english
american-english
australian
belgian
canadian
chinese
chinese-hongkong
chinese-simplified
chinese-singapore
chinese-traditional
dutch-belgian
english-american
english-aus
english-belize
english-can
english-caribbean
english-ire
english-jamaica
english-nz
english-south africa
english-trinidad y tobago
english-uk
english-us
english-usa
french-belgian
french-canadian
french-luxembourg
french-swiss
german-austrian
german-lichtenstein
german-luxembourg
german-swiss
irish-english
italian-swiss
norwegian
norwegian-bokmal
norwegian-nynorsk
portuguese-brazilian
spanish-argentina
spanish-bolivia
spanish-chile
spanish-colombia
spanish-costa rica
spanish-dominican republic
spanish-ecuador
spanish-el salvador
spanish-guatemala
spanish-honduras
spanish-mexican
spanish-modern
spanish-nicaragua
spanish-panama
spanish-paraguay
spanish-peru
spanish-puerto rico
spanish-uruguay
spanish-venezuela
swedish-finland
america
britain
england
great britain
holland
hong-kong
new-zealand
pr china
pr-china
puerto-rico
slovak
south africa
south korea
south-africa
south-korea
trinidad & tobago
united-kingdom
united-states
zh-CHS
az-AZ-Latn
uz-UZ-Latn
kok-IN
syr-SY
div-MV
quz-BO
sr-SP-Latn
az-AZ-Cyrl
uz-UZ-Cyrl
quz-EC
sr-SP-Cyrl
quz-PE
smj-NO
bs-BA-Latn
smj-SE
sr-BA-Latn
sma-NO
sr-BA-Cyrl
sma-SE
sms-FI
smn-FI
zh-CHT
az-az-cyrl
az-az-latn
bs-ba-latn
div-mv
kok-in
quz-bo
quz-ec
quz-pe
sma-no
sma-se
smj-no
smj-se
smn-fi
sms-fi
sr-ba-cyrl
sr-ba-latn
sr-sp-cyrl
sr-sp-latn
syr-sy
uz-uz-cyrl
uz-uz-latn
zh-chs
zh-cht
CONOUT$
Antivirus Signature
Bkav W32.AIDetectMalware
Lionic Trojan.Win32.Lazy.l!c
tehtris Clean
ClamAV Win.Keylogger.Lazy-10031941-0
CMC Clean
CAT-QuickHeal Clean
Skyhigh Artemis!Trojan
ALYac Clean
Cylance Unsafe
Zillya Clean
Sangfor Trojan.Win32.Save.a
K7AntiVirus Trojan ( 00515e9f1 )
Alibaba Clean
K7GW Trojan ( 00515e9f1 )
Cybereason Clean
Baidu Clean
VirIT Clean
Paloalto generic.ml
Symantec ML.Attribute.HighConfidence
Elastic malicious (high confidence)
ESET-NOD32 a variant of Win32/Kryptik.HXLV
APEX Malicious
Avast Win32:CrypterX-gen [Trj]
Cynet Malicious (score: 100)
Kaspersky HEUR:Trojan-Spy.Win32.Stealer.gen
BitDefender Gen:Variant.Lazy.567086
NANO-Antivirus Clean
ViRobot Clean
MicroWorld-eScan Gen:Variant.Lazy.567086
Tencent Trojan.Win32.Kryptik.16001224
TACHYON Clean
Sophos Mal/Generic-S
F-Secure Clean
DrWeb Clean
VIPRE Clean
TrendMicro Clean
McAfeeD Real Protect-LS!64AE8807B835
Trapmine malicious.high.ml.score
FireEye Generic.mg.64ae8807b8359c84
Emsisoft Gen:Variant.Lazy.567086 (B)
SentinelOne Static AI - Malicious PE
Jiangmin Clean
Webroot W32.Trojan.Gen
Varist W32/Kryptik.MJE.gen!Eldorado
Avira Clean
Antiy-AVL Clean
Kingsoft malware.kb.a.807
Gridinsoft Trojan.Heur!.00012031
Xcitium Clean
Arcabit Trojan.Lazy.D8A72E
SUPERAntiSpyware Clean
ZoneAlarm HEUR:Trojan-Spy.Win32.Stealer.gen
GData Gen:Variant.Lazy.567086
Google Detected
AhnLab-V3 Clean
Acronis Clean
McAfee Artemis!64AE8807B835
MAX malware (ai score=85)
VBA32 BScope.TrojanPSW.Vidar
Malwarebytes Clean
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Rising Stealer.Agent!8.C2 (TFE:5:s6y2KdE9tVH)
Yandex Clean
Ikarus Trojan-Spy.LummaStealer
MaxSecure Trojan.Malware.300983.susgen
Fortinet Clean
BitDefenderTheta Gen:NN.ZexaF.36808.GyY@amfWPZki
AVG Win32:CrypterX-gen [Trj]
DeepInstinct MALICIOUS
CrowdStrike win/malicious_confidence_90% (D)
alibabacloud Trojan:Win/Kryptik.HDAT
No IRMA results available.