Static | ZeroBOX

PE Compile Time

2024-07-24 07:28:08

PE Imphash

42eb2b50acad70f9618962bfa70c7f34

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x0001ea87 0x0001ec00 6.59416179907
.rdata 0x00020000 0x0000a6ac 0x0000a800 4.62791732188
.data 0x0002b000 0x00080404 0x0007f400 7.9953044812
.bsS 0x000ac000 0x000004ac 0x00000600 5.11129176259
.reloc 0x000ad000 0x00001f94 0x00002000 6.52590022842

Imports

Library USER32.dll:
0x42016c OffsetRect
Library KERNEL32.dll:
0x420000 GetCPInfo
0x420004 CreateFileW
0x420008 WaitForSingleObject
0x42000c CreateThread
0x420010 VirtualAllocEx
0x420014 FreeConsole
0x420018 RaiseException
0x420020 InitOnceComplete
0x420024 CloseHandle
0x420028 GetCurrentThreadId
0x420040 GetLastError
0x420050 CloseThreadpoolWork
0x420054 GetModuleHandleExW
0x420070 EncodePointer
0x420074 DecodePointer
0x420078 MultiByteToWideChar
0x42007c WideCharToMultiByte
0x420080 LCMapStringEx
0x420088 GetModuleHandleW
0x42008c GetProcAddress
0x420090 GetStringTypeW
0x420094 WriteConsoleW
0x420098 IsDebuggerPresent
0x4200a4 GetStartupInfoW
0x4200a8 GetCurrentProcess
0x4200ac TerminateProcess
0x4200b0 GetCurrentProcessId
0x4200b4 InitializeSListHead
0x4200b8 HeapSize
0x4200bc RtlUnwind
0x4200c0 SetLastError
0x4200c8 TlsAlloc
0x4200cc TlsGetValue
0x4200d0 TlsSetValue
0x4200d4 TlsFree
0x4200d8 FreeLibrary
0x4200dc LoadLibraryExW
0x4200e0 ExitProcess
0x4200e4 GetModuleFileNameW
0x4200e8 GetStdHandle
0x4200ec WriteFile
0x4200f0 GetCommandLineA
0x4200f4 GetCommandLineW
0x4200f8 HeapFree
0x4200fc HeapAlloc
0x420100 CompareStringW
0x420104 LCMapStringW
0x420108 GetLocaleInfoW
0x42010c IsValidLocale
0x420110 GetUserDefaultLCID
0x420114 EnumSystemLocalesW
0x420118 GetFileType
0x42011c GetFileSizeEx
0x420120 SetFilePointerEx
0x420124 FlushFileBuffers
0x420128 GetConsoleOutputCP
0x42012c GetConsoleMode
0x420130 ReadFile
0x420134 ReadConsoleW
0x420138 HeapReAlloc
0x42013c FindClose
0x420140 FindFirstFileExW
0x420144 FindNextFileW
0x420148 IsValidCodePage
0x42014c GetACP
0x420150 GetOEMCP
0x420160 GetProcessHeap
0x420164 SetStdHandle

!This program cannot be run in DOS mode.
`.rdata
@.data
.reloc
4VWQPS
D$DSV3
~,9~$t
YYW9^d|
L$8_^][3
I`hZB@
74s,l4th4
,e4",shH
FYY;t$
FYY;t$
PPPhZR@
u9F(t
tG9uCj
PPPPPWS
QQSVWd
URPQQhp
UQPXY]Y[
PVVVVV
PVVVVV
ARPRQh
jYjf
PPPPPPPP
uSSSSj
SWt@jU
_tqPVj@
_PVVVVV
j"_SVVVV
PVVVVV
^PSSSSS
j"^WSSSS
WVVVVV
PVSRSQV
PPPPPVW
PP9E u!PPSVP
PVVVVV
PWWWWW
D8(Ht'
D8(Ht5F
L:-^_[
f9:t!V
QQSVj8j@
NX9^`t1
;V\uYW
u2Vj@h
9C`u99C\t4
u29K\t-
PPPPPPPP
Unknown exception
bad array new length
string too long
generic
iostream
iostream stream error
bad cast
bad locale name
ios_base::badbit set
ios_base::failbit set
ios_base::eofbit set
Fail to schedule the chore!
This function cannot be called on a default constructed task
broken promise
future already retrieved
promise already satisfied
no state
future
Own head
JAHNsiu
0000000006:1@0000000005:@
vector too long
?bad allocation
bad function call
bad exception
device or resource busy
invalid argument
no such process
not enough memory
operation not permitted
resource deadlock would occur
resource unavailable try again
success
address family not supported
address in use
address not available
already connected
argument list too long
argument out of domain
bad address
bad file descriptor
bad message
broken pipe
connection aborted
connection already in progress
connection refused
connection reset
cross device link
destination address required
directory not empty
executable format error
file exists
file too large
filename too long
function not supported
host unreachable
identifier removed
illegal byte sequence
inappropriate io control operation
interrupted
invalid seek
io error
is a directory
message size
network down
network reset
network unreachable
no buffer space
no child process
no link
no lock available
no message available
no message
no protocol option
no space on device
no stream resources
no such device or address
no such device
no such file or directory
not a directory
not a socket
not a stream
not connected
not supported
operation canceled
operation in progress
operation not supported
operation would block
owner dead
permission denied
protocol error
protocol not supported
read only file system
result out of range
state not recoverable
stream timeout
text file busy
timed out
too many files open in system
too many files open
too many links
too many symbolic link levels
value too large
wrong protocol type
unknown error
GetCurrentPackageId
GetSystemTimePreciseAsFileTime
GetTempPath2W
0123456789abcdefghijklmnopqrstuvwxyz
0123456789abcdefghijklmnopqrstuvwxyz
__based(
__cdecl
__pascal
__stdcall
__thiscall
__fastcall
__vectorcall
__clrcall
__eabi
__swift_1
__swift_2
__swift_3
__ptr64
__restrict
__unaligned
restrict(
delete
operator
`vftable'
`vbtable'
`vcall'
`typeof'
`local static guard'
`string'
`vbase destructor'
`vector deleting destructor'
`default constructor closure'
`scalar deleting destructor'
`vector constructor iterator'
`vector destructor iterator'
`vector vbase constructor iterator'
`virtual displacement map'
`eh vector constructor iterator'
`eh vector destructor iterator'
`eh vector vbase constructor iterator'
`copy constructor closure'
`udt returning'
`local vftable'
`local vftable constructor closure'
new[]
delete[]
`omni callsig'
`placement delete closure'
`placement delete[] closure'
`managed vector constructor iterator'
`managed vector destructor iterator'
`eh vector copy constructor iterator'
`eh vector vbase copy constructor iterator'
`dynamic initializer for '
`dynamic atexit destructor for '
`vector copy constructor iterator'
`vector vbase copy constructor iterator'
`managed vector copy constructor iterator'
`local static thread guard'
operator ""
operator co_await
operator<=>
Type Descriptor'
Base Class Descriptor at (
Base Class Array'
Class Hierarchy Descriptor'
Complete Object Locator'
`anonymous namespace'
FlsAlloc
FlsFree
FlsGetValue
FlsSetValue
InitializeCriticalSectionEx
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
CorExitProcess
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
Sunday
Monday
Tuesday
Wednesday
Thursday
Friday
Saturday
January
February
August
September
October
November
December
MM/dd/yy
dddd, MMMM dd, yyyy
HH:mm:ss
AreFileApisANSI
CompareStringEx
EnumSystemLocalesEx
GetDateFormatEx
GetLocaleInfoEx
GetTimeFormatEx
GetUserDefaultLocaleName
IsValidLocaleName
LCMapStringEx
LCIDToLocaleName
LocaleNameToLCID
AppPolicyGetProcessTerminationMethod
_hypot
_nextafter
?5Wg4p
%S#[k=
"B <1=
.text$di
.text$mn
.text$x
.text$yd
.idata$5
.00cfg
.CRT$XCA
.CRT$XCAA
.CRT$XCC
.CRT$XCL
.CRT$XCU
.CRT$XCZ
.CRT$XIA
.CRT$XIAA
.CRT$XIAC
.CRT$XIC
.CRT$XIZ
.CRT$XLA
.CRT$XLZ
.CRT$XPA
.CRT$XPX
.CRT$XPXA
.CRT$XPZ
.CRT$XTA
.CRT$XTZ
.rdata
.rdata$T
.rdata$r
.rdata$sxdata
.rdata$voltmd
.rdata$zzzdbg
.rtc$IAA
.rtc$IZZ
.rtc$TAA
.rtc$TZZ
.tls$ZZZ
.xdata$x
.idata$2
.idata$3
.idata$4
.idata$6
.data$r
.data$rs
OffsetRect
USER32.dll
WaitForSingleObject
CreateThread
VirtualAllocEx
FreeConsole
RaiseException
InitOnceBeginInitialize
InitOnceComplete
CloseHandle
GetCurrentThreadId
ReleaseSRWLockExclusive
AcquireSRWLockExclusive
TryAcquireSRWLockExclusive
WakeAllConditionVariable
SleepConditionVariableSRW
GetLastError
FreeLibraryWhenCallbackReturns
CreateThreadpoolWork
SubmitThreadpoolWork
CloseThreadpoolWork
GetModuleHandleExW
IsProcessorFeaturePresent
EnterCriticalSection
LeaveCriticalSection
InitializeCriticalSectionEx
DeleteCriticalSection
QueryPerformanceCounter
EncodePointer
DecodePointer
MultiByteToWideChar
WideCharToMultiByte
LCMapStringEx
GetSystemTimeAsFileTime
GetModuleHandleW
GetProcAddress
GetStringTypeW
GetCPInfo
IsDebuggerPresent
UnhandledExceptionFilter
SetUnhandledExceptionFilter
GetStartupInfoW
GetCurrentProcess
TerminateProcess
GetCurrentProcessId
InitializeSListHead
KERNEL32.dll
RtlUnwind
SetLastError
InitializeCriticalSectionAndSpinCount
TlsAlloc
TlsGetValue
TlsSetValue
TlsFree
FreeLibrary
LoadLibraryExW
ExitProcess
GetModuleFileNameW
GetStdHandle
WriteFile
GetCommandLineA
GetCommandLineW
HeapFree
HeapAlloc
CompareStringW
LCMapStringW
GetLocaleInfoW
IsValidLocale
GetUserDefaultLCID
EnumSystemLocalesW
GetFileType
GetFileSizeEx
SetFilePointerEx
FlushFileBuffers
GetConsoleOutputCP
GetConsoleMode
ReadFile
ReadConsoleW
HeapReAlloc
FindClose
FindFirstFileExW
FindNextFileW
IsValidCodePage
GetACP
GetOEMCP
GetEnvironmentStringsW
FreeEnvironmentStringsW
SetEnvironmentVariableW
GetProcessHeap
SetStdHandle
HeapSize
CreateFileW
WriteConsoleW
j*]U?6
GL#M$N
#jh<&4F
G:%^%+
FeFPs|
3\g,LX^
FE8R,J
x+p5>TeA
>mK}Y+
71Kz"U
3{t81&
`6tb8k
4L]F!!
N.8-IG
=I+K I
m#JlM
f@g;xMU<
zI@zn'[
f50v?6
%ev0SM
,Yy#z#
$Q,\^`)Dz
z;\k^u
Po';TCG
OCKTF-
O|R^Vcx+)
,x3?$QmE
Dmkw\oC!
aKAg[A
Qnt{p?(
uC(N2#
(7{vR6x
eLLJO)
v%Qtmt'&uW
,,Tq$F*
ok=gxm]E
:rf.)%
!OI^v@
6`v|B;
u,/G2
;7itE"z
(,^V1<5
d[u[2"
/'ll|i
1}\8zuFGcGU
i/z3bg
>k~hyH
_/tnqP
'8*@<0*E
KBdg+;
uw&f[r]
)IR%GnY
1i"U,cbTLmV+t
>|DhHCPI
&h2!3Q
l1f=Mt
iF-i/(
:PmaQDMl
&#lRu
^=)55y
t.zCivg
nhcs-E
n]>%'\
t& b?o
UU($][
]ex[Ob)
4,e#J
;0N9Mwk
u(@\zH
WU{% f
C]oa"4
4@1[eV~y
nS)G7-
Ew/\.r/
T,L%Nw
Soh5Y[
Q|DUdEMR
o_"AhQx
nFHZ8g
jz$R,4
w\gO43e
B,nIE+
,Ws0@.
3x"Yh%
}iRi7L
|V]Md
FzOE*?
x,U7sd|N
JQ^%:d
iSlbw=G
Qye9E-X
i#pMmr
E)gD5G
\D@RxB
%~3W-6
A:;2w)A
Er@!aEf
t|)d2>0
ev2B;j
h,SAoHfOZ9
hS(X;!
#q9yrt#
6+]V61Z8$
}!%pPB
:RN?jn,r@
{BS.a=hDM
u\(CZJ
zmw!ad
l"=aHI2!
y/dcUv
O6!fI\P$E(
%rZR[H
Tz;-Y8
.N>Vcw
r#M <
c[Qy2Xd
|)]8%(
cA+5z1E
,U|/x%
G3[At8
6G,^*Zd
GXM6l3
MfEt<29
([ggM7t
s~oHS3a
BUw\<
dU#j9'
GR9#.c
]zQ0l`
|o9&[y
I6S1e^
aZjsq\
;U]qD}
8v#OFQD
02*$1<
|d!26Pa
u<$TU#;9Y
CYKIav
rtS("{
5oxdAU
PGL8q!
yjPO}W
'2VCWW
uF7Eq.
:}FatX^
x746y-k
07oTB'
vtFRsl
z}jX<
QFqZ1x
'!!eYO
gE^1itn8
hyGme
qG4'lJ
~pb/g3
M_{vJ^w
VqmOzX
(Y6JU&
8x-cTh$
s M=]7
Dr~nt"G
fs5CL
wM101K2
M?G|(5
eu<c7Z
/R[b]'
46:xv-
!.m0B{
HlC~VV
bPHyH_
Hi%A)Ix
BEyC
fy$L+t
c\3@Ho
Vt&B<&!
QH:dg"#
&G?x!J
XjZ-A-
Q7)R7W
eIQ/ZXbx
o;n!o*
2XG5|7
((190y
r@Onzm
aOQ:wMG
w+jXb1
ZuLFy9
!K]lZW
>?C cl
RD'p).
v:f"zj
l31.|p
DUh!5~
^ZF5Y?b
~Y%@_)
j+:=h[
W3-I7vKPM
w;1G}9
8Iog||U
&)Rea^5
O~,k&d
NMa@@A
#qjSQx
Mc\,m:
uAk.It
Vma'41pg
A%FvLh9
!sbpN&
nDey^0
H1;6$CQS
PWZ9Bm
w5gJzw
9C;`'
ey]=%ud
] B{@bx
]Ws1(W
h+]_*h
vRf8Qg9
Ya}6T!c
DL]P0G+
BQe9<E
sz^M}c
JRRKJ.
a|,6\<
F=DjW,
_^}|^s
.kl\)K
#p`4s:`
{LC~;b>
5C<iT-V
F#/8jm
k2"~Vn
Ri0JT,
\,\.=y
[|~?s)7
=IulzR
*KZm5+
OR1(-g
lG^9~a("
$6o=I/
BtFWf/{)(
;?C+Me
s4G&\j
79Yac(
T#GJZdW
lBorjw<
1l7JKD
c4TA*(
K2w@<L(
C]SSR
7>ySsc
@4-hzX
TZ>fUH
vu0{qva
[$Saj:
z7j'>[{H
^=J@fH
@YT{[:R
"{*o+}
bGnn:}
k^Qa(|
%qu(\T@l
d]q 0,
:1GP1^
CrY]6(
Cl+hd%
4[jXYE
]Dv707
Bf iYP
a4M+b0
M*'"j=b-
#zM8;=
}2p-=TN
&>);t|yW
Z4jHfh
dO-r;C
x/>9GC
[M:7R_
P{R%+de
>fH^/G
miKmuw
\ep:<U
_w/'6A#
{o^Fp
]fbc(_
e<^B\\
O}/0I9
~W?`2\
srn'u0
o|_-1-
O@|&@R4i
pVPS(H
|G;HjK^
l>So4H
a:RR,In
P/L>m+
D~c%uDF
uJsfjuf
R"_.v2"
rjEW5H
9wg!mv
vgSk+r%
L'{<AM
q<$^k~
v;UN|M
*R,/-B
w)L1yd
G=u4A6
D<)#>w
EW=eD7
?1I;1I
bO4?5R
u6>?Mv^j
zE)JPa
h^4(rq
Q?C3!Q
@MF<TY
&)J[x`
K4IBDf.
TMklMe
60pQVQg
G}kNQ]
.'mFqct
JioYbw
&R|{MT
>f e!@
&DO6;%
Y$Kj%)
g?2Wdu_
~M9M4v?
3RX+X=s
j)zG ]
=v$N<p
?>:u:E8
ln"#'P
!m7)c*,
_;K!PXA
}p!(Z$
K+B{xb
v@V"km
D4>r2)
uUn&B!
yK@8Yq
g^Pt0{
a)^0@`
1JrV-%*
59LSu_Z
|w!gG[
$#q(/b
@ZqZ;c
%" Jz-
\m(v*=
ct4ue=
mZ*lkY
Y=(:n^
J_s;<63
Iow?+g
eel@a8
|s0T7XJ7!
^>j#Eq
OAITNQI
[wd2;Z
pMz[z6*G
x2F6!Y
LZ=X*~
+>Bc*dkl
[vy@EjQ}
R`~ICs
D8M~DB
&h|`;M
g ~g\3
4>MfO|i
9^\:!P}V
$#Mkt"y
.H/Lqd
]=c&.*
W=xfMmzZL
2i,%JVs
@]e2_9-VG
|vRxb&
[BpGe*
:yS1AfW
r"1TvFQ
xqvYB4
D%EbaUU4
#J<]M+
c%]#7>
{LJI`T
wc2An=
K9Kw}*
S]xb&a$
<H6HX;
d aC=&
$KC=$
iP~n5O
9{< r7
y;N08
Ev9(AT
5OR6=mq=o
wTkCSb
QAbBAz
D0y<1L*t
U]Y9v3
"g&fUX
$l"pjb
~&EoTY
j 8AWG8
BN^o4;
N|VG[s
p@S#`e
WQUZ.W
M,G:t6
Y+`8T3
X<gI#%!
J(@ZGLE
0gMPF(G{
4pD(q0_
7GqP^Xw
`#&+Ip
;cb/?Vai
DijxlLMt.
4NM;^dU
g/h1"-B
Y8^~3.
mb9;yH
mg?{WjFP
?I>EAK
G2B`\=
NO${|_
R#FFh<
7|guEsQ
wyWlcz
jM~%a/xm
o[bD.~
SH~zl\M71W
+^DKaj
`%U9<z
yu/1wU
?i.zED
0tQlLq6
/@yalw
E.P_69
[{d>=&(
95w`^}
37qM&_
/gpa.p
Ks`%pvh
%+hhQ|J
}BO7{9
L3_,Y
0XJ4NM(*t|
L+k09<>
HuO@rj@
0FB0##"
h;?*#k#
)TWh.i>
~7gyp.:{
*&W$g|
@WZN|RK{
>s"j"
U,64dr1;
~I]KW<S
3kA>\5
"mc_iVR
*p^O'=5u
E685s}
e3j,6
oI?kk;E
F7bE[
<ox6BmP@
^yp{=r
c4jfK@
28wY~^
4r5Ku4k
%oaqv&
2HB0@$
4?_v[%
.&Qwqa
.xW!@xY
>Dzj=|
yVX&fHV6
&+jlW)r
lP&u?I
%8JbEH
h9 B`(
@)Q{4gl
y+B9Ou
WldfrF&+
=\2kM]
bO.M,:T"
!B/eBo
<ArV9%N
JI 5nq
7^{wXeUa
0/%!S&
al]Z6|
l\an@.C-Ak
0[i o|p
!5Ib8t
S,k48(3yE
$Qe~>$
NvgOY9o
3YZ/2"
HQQwoE
Tc/*I=L]
yMK=ibe
A l5!H0O
YY+q
j`l|l)
eZ w\B
\z2V}`
>`9mia(2'F
YO$HRC
.AQ3&^
2%n0OA
$cDP#Ow
$;_E7@
[r=[3<
:nh+~|
j#I^P)*o
l8b:ra
lj\vCjr
)bUu09
|M@3@MID
)kw{rC
q=p9d$
je[XGT
;J^,Qu
g+%w:/
1HFClD
`RI.qb/
hG$SZ"
gR8fKy
3bp1{,zM
7i`ELg
EBW.~x
+_A|yJ
NY%7ZlG
}x-@oL
h0A xCD
O W%?z
_%*~2p
p&!EnU
$JY;;m
/qRD3-
}j'Tq.
a1QO&S
5r[vs=
2%EQhf
'eZxR
_2Cop%fr
tE* '(
-OYOz?
^nf}A9
[z>y9sWv/
j>W9#Y
ydCtx'
((u*j}
9l?'?~+`
Q6/Xs2
5o6*$V
T%!uK;
.10;{S
I5thEX
t,eUV?
r/t[ZR
:not_[~~
/?3ejs3
E7!(CA
"K9U*v;
~An|nqn
>zv%=:h
YlpYyd
v~5vS(Xd
{5U{sx~
$bA@;c
$825g%l]
JIn\pn
0C)bFY
VGN^V}
z!nryH
}J7wHO
=*3\J*
q7PlqF
OosXQe
u20KV
}LYqRd
jV"REA
/'I7tx
LO*U<j
Gq{!yz
u@_kn0
PY6bi&k6
u$=kPI|
wDijH/
86$^j7P
Yf}.D
jbv/e
WG{lkY/mJz
#W:q_-
/'zr+qp
AXf'jC~\
i[d2x@
`o_n_&
ji%YYGDqK
5jz)crq
^LR5^X
_+G4OB
=R,dH%
41JO{}+w
.|Z2"n
& =KMM+m
<{vB;J
Gs&&/q
i,j/8.
}Q*`TX
2<a&Q!
"m"[_aF
q;ce&/
Xm|M4e
T,aEQ(
r3w|]<V
{,]1o|
D$>]*w
tb6/ =6i
MIhU([
CgAE1Goy
ZC|Rxh
oo>A{a(
UJx[Li
:kZu)=j
;nWjiv
DtHFJ7;O(
.{2a#,
R2)M/ZZc
U'a56}
0gkI\Z
-gM!|"
urgf:#q
W WG9]6
&Nlu`e
PmCFE_
=XM4a]
]%|ZWC
M]mo$t
|eQ@2@g
20"PZ*
.u?*9M~
nM8>~D
i<W/u9
xYL%&9
R<NW(O
+<Z\q]
{*\$V`|
Sve;-`N9:
qm>wa`
SB :$U;
'Y =4F
^jxldIi
<n#9 }
=8SF]GPW
Eagyjj
/py$DH
a"-zm:V
/N2gVD
VVz`Xs
x(k^Q8
3sTe4dv
,4NF[7
h<MRRw
(XWR>|g^
xkT%#b
*ATzar
*tm;tj
98Zh+9
9!Sa?8&
Z:l'[*
\5=#hk
I/06PY
;$rkW&@
[=TJF9
*Q|f_F
t`-[6L(
R~4>oX
isL^k!
I>)/cif4`
YnwEZ5F"
2.VK>Hr>
6`kcRXE
.%%~V!
MB|#?
?J[/.u
#x:>[=
PCsnHDe
LV:ao~
1RAD01
B{`%K//
Q_du'U
bym:3id
E\?A<n{
FmjLsX
u3I$r$w
[Fnl-y
Tm^cd6
5v8~KFx
25JZW-%c3
0v^r='
JwUM63
/6ba3K
*M3SLP
tJD/xa
9}yLYL[
'K+o_.B
bKN:%n(
nU%])~
z<,HRuHK
\fKOK|
s7=<iV
a Z=#-
1@;Mef~
PJH[^7
\Ij=p9
t(E\b^
$Z&=*a
z_'^m|k
N`caw!by
(/{TEh
t$IY|5
^a'.2 4
(ZrL7e
#5L;b1
t#Mog
b#{gHm7
@fKc'-
*$z|k{
1uZHK}=
-%0pr8
\m\n(L
~XBPGc
(b/?R*=
lx`/VW
r7@^s9
v&t[$M
c9iF).
x(5}/l
pkj3P>
h7rpW4S
%uBW(Xp
%vaj2##s~
\Kt|09*8
Q!q=$(g
SJAGaj&
2|~[W
<{!IvEm%j
&2$yOk
V])n;`
(\/txL
e4?!?5
%l5Hoz
,Lc|O
Hp}N:X
.BWH(M
f5&X'a
n+!+/UG
Qb0`uU
r42Wq]B
nD$GiM
}~8L2F
"2N`TJ:
_T+dg5
9n65@
abZ~VO7
;j2Rp
K-%o4dj
X)!g6x]/
C6vGvC
In2_N#3N
M/`+ST
C9=V!
R S%AI
3YHtAc<
x.)z#n
9bgAMd
"F_V]
KtcLw_
9?#=\?
/=~.gS
g~GvnR
Wh@g[:Z$
-kWiTp
T}}[1P
pO)!:V{
M%*$hN
u]*nPQ
HYoZar
L1H_v#
etH{uv
~CWo8+
sz]goA
sB./}w
wgo8z=
zLACL%0
"O0hq)!
trfe|q
*W^_X5
8mD%>j
tv7N$,
Cf2~uw
{Z5b_n
+Y*ap-
o4n1KB
lX0o/dF
CU6GXs
(5JCK&
?=myg=F
<YZYy|
"izO:%
T,=Kva
G`CGIE
u#al-1k
&w-D3QY
`K3}jK
p%OhsyO
!(*85+f
=4QhbO^
$t*PC#a
[H|ED~q
mx<x"8
f >y}.
`%QW`u
.B6PURl^q
xIfAYjJc
'|{Z.D
5LnA +3
5P'p;ja
:C:".6
x~uzv9
Ivkf4B
1qU)Kdj
a&{dxwS
*V"WS!
#Q#uwT
<lS5dY
kEN5ixT
D?J\kx
UITlF|
*FypxP
#$ANG+
'}5y]M
9e/o)v
ZQ+<~y
hCC@oH
!Pe6D#A
+MJ'ld$
H0?~XE
zyIG%%
`Tt$a|
{3Y!3A
<5A/##
{~e5q[9
!w)^@Lk
,>w;{y
gNP><+u
X^F}ype
BRnLSX
9(Zl5EB
!if;76
xzSzG:
z k_jx
S~.dRQ
}ibW,~
)|c)*w
se]L!3
Y<eG~u
6t\,<dV
3A"t.2
Jlu<-_
Fvqg|b
d]IZ_d
boB)$u7I$
vdjQ_8
Xad1Z;
ZXzKVH
Nf"wWe
mJ,<Z9B
YmPx=h
|qRH$_R
X)<-_[|
wN)RgDV&
$(Sn{H
!,1ctU
/kuc;J3
az<p:E
nH4I03
'{f_s(
yP0>p&f
PNxEsn
@H2S^?
F ,oSQVb
hiGy>K@
,59!1%\o
6M(<VUO
F+){dW
&v|aYm
_rdRbd
E9%^Fi
)h:YQq
\#$vM~
IfTy]CD"
6<IMeo
>wKq6`
UlmmbF
~fZk<E
Z/rEQp/'
t;<pJ
)@y;Ga
ci&2An
NA\$a
$rf*R_y
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
.?AVexception@std@@
.?AVbad_array_new_length@std@@
.?AVbad_alloc@std@@
.?AVruntime_error@std@@
.?AVsystem_error@std@@
.?AV_System_error@std@@
.?AVbad_cast@std@@
.?AVfailure@ios_base@std@@
.?AVtask_canceled@Concurrency@@
.?AVinvalid_operation@Concurrency@@
.?AV_Interruption_exception@details@Concurrency@@
.?AVfuture_error@std@@
.?AVlogic_error@std@@
.?AV<lambda_0456396a71e3abd88ede77bdd2823d8e>@@
.?AV<lambda_eb87dfd73f857f44e1a351ea42ce2b34>@@
.?AV<lambda_cf64729cb90f65090849ddab3f3d5e68>@@
.?AV<lambda_5e5ab22ea98f4361dbf159481d01f54d>@@
.?AV?$_Fake_no_copy_callable_adapter@A6AXXZ@std@@
.?AV<lambda_dc3a808d3cb651230a54fc79f9ff1e4d>@@
.?AVlength_error@std@@
.?AVbad_function_call@std@@
.?AVbad_exception@std@@
.?AVerror_category@std@@
.?AV_Generic_error_category@std@@
.?AV_Iostream_error_category2@std@@
.?AV_Ref_count_base@std@@
.?AV_Facet_base@std@@
.?AVfacet@locale@std@@
.?AU_Crt_new_delete@std@@
.?AUctype_base@std@@
.?AV?$ctype@D@std@@
.?AV_RefCounter@details@Concurrency@@
.?AV_CancellationTokenRegistration@details@Concurrency@@
.?AU_TaskProcHandle@details@Concurrency@@
.?AV?$_Func_base@X$$V@std@@
.?AU_Task_impl_base@details@Concurrency@@
.?AV?$_CancellationTokenCallback@V<lambda_3b8ab8d2629adf61a42ee3fe177a046b>@@@details@Concurrency@@
.?AV?$_Func_base@E$$V@std@@
.?AU?$_Task_impl@E@details@Concurrency@@
.?AV_Future_error_category2@std@@
.?AV?$_Associated_state@H@std@@
.?AV?$_Ref_count_obj2@U_ExceptionHolder@details@Concurrency@@@std@@
.?AV?$_Ref_count_obj2@U?$_Task_impl@E@details@Concurrency@@@std@@
.?AV?$_Func_impl_no_alloc@V<lambda_5e5ab22ea98f4361dbf159481d01f54d>@@X$$V@std@@
.?AV?$_Func_impl_no_alloc@V<lambda_cf64729cb90f65090849ddab3f3d5e68>@@X$$V@std@@
.?AV?$_Func_impl_no_alloc@V<lambda_eb87dfd73f857f44e1a351ea42ce2b34>@@E$$V@std@@
.?AV?$_Func_impl_no_alloc@V<lambda_0456396a71e3abd88ede77bdd2823d8e>@@X$$V@std@@
.?AV?$_Deferred_async_state@X@std@@
.?AV?$_Packaged_state@$$A6AXXZ@std@@
.?AV?$_Task_async_state@X@std@@
.?AV?$_Func_impl_no_alloc@V?$_Fake_no_copy_callable_adapter@A6AXXZ@std@@X$$V@std@@
.?AU?$_InitialTaskHandle@XV<lambda_dc3a808d3cb651230a54fc79f9ff1e4d>@@U_TypeSelectorNoAsync@details@Concurrency@@@?$task@E@Concurrency@@
.?AU?$_PPLTaskHandle@EU?$_InitialTaskHandle@XV<lambda_dc3a808d3cb651230a54fc79f9ff1e4d>@@U_TypeSelectorNoAsync@details@Concurrency@@@?$task@E@Concurrency@@U_TaskProcHandle@details@3@@details@Concurrency@@
.?AV?$_Func_impl_no_alloc@V<lambda_dc3a808d3cb651230a54fc79f9ff1e4d>@@X$$V@std@@
.?AV_ExceptionPtr_normal@?A0x6e02efe5@@
.?AV?$_ExceptionPtr_static@Vbad_alloc@std@@@?A0x6e02efe5@@
.?AV?$_ExceptionPtr_static@Vbad_exception@std@@@?A0x6e02efe5@@
.?AV_Locimp@locale@std@@
.?AVios_base@std@@
.?AV?$_Iosb@H@std@@
.?AV?$basic_ios@DU?$char_traits@D@std@@@std@@
.?AV?$basic_streambuf@DU?$char_traits@D@std@@@std@@
.?AV?$basic_ostream@DU?$char_traits@D@std@@@std@@
.?AV?$basic_filebuf@DU?$char_traits@D@std@@@std@@
.?AVcodecvt_base@std@@
.?AV?$codecvt@DDU_Mbstatet@@@std@@
.?AVtype_info@@
xP|H&{
~~|H&{
0#0*070;0G0M0[0p0z0
1#13181B1X1l1p1z1
222Q2P3Z3
315[8#9
9=;{;,>D>J>n?s?
4$5=5W5
7+717>7y7
8#8/8E8]8u8
8H9d9u9
;;$<a<
9@:J:O:n:
;(;<;^;
;4<B<]<|<
>(?E?o?
0<0B0H0S0[0d0
4"424M4Z4f4~4
4+5K5k5z5
6'6J6j6w6
7H7U7r7
1'2@2s2
3&434@4U4a4h4
606:6A6T6
7j7r7x7
;1;[;o;u;
<"<*<9<e<l<
?C?O?f?
40A0Z0
1!1Y1}1
2 3&3z3
5P6D9q9W:
>2?G?U?c?
0 0A0Q0W0^0e0
5?5e5t5
7 7&737:7_7g7t7
==4===l=u=~=
0%00070J0X0^0d0j0p0v0}0
1#1,1P1^1d1j1p1v1|1
2&252>2K2a2
3 333G3L3_3
66$6(6,606
;#;(;/<@<
7 7$7(7,7074787<7@7D7H7L7P7T7X7\7`7d7h7l7p7t7x7|7
:-:A:]:h:v:|:
:=;L;,<Y>
5H60858_8{8
;';,;1;L;Y;b;g;l;
< <A<Q<i<
030:0n0y0~;
<"<)</<J<Q<z<
=6=K=a=n=|=
3Q5S8!9m:
464;4G4L4`4
4I5P5b5k5
6&676W6
7 7)777
:?:F:v;
<0<><Q<\<g<
0!0+0/070C0]0
1%1,141L1Z1b1z1
1%21262<2A2I2O2W2
8X=^=p={=
<W=2>9>f>m>
?:?a?v?
0,0?0Y0h0
121C1]1c1n1
6*646[6e6
77&7+7i7q7
8-82878G8L8Q8a8f8k8{8
909C9d9q9
;8;B;R;W;\;w;
<,<A<e<w<
>">9>K>W>
?#?9?F?K?Y?
4J6\6D719
6#768~8
='=]=z=
343Y3)4a5
:4:_:r:}:
: ;a;p;
>#>8?L?
060J0j0t0
0A1o1k2w2
;(;7;A;N;X;h;
4:6@6N6]6"7)737W7
9):8:F:c:k:
:&;-;};
<!<3<E<W<i<{<
;'<H<.=
: ;|;)<
7H8N8S8Z8j8x8
0@1j1r1
8%858F8
9+9>9]9
:2:T:x:
?f?k?}?
4$4A4^4{4
6.6P6m6
829O9l9
: :*:6:B:L:V:`:j:t:~:
2$2(2,2D2H2L2P2T2X2
3 3$34383<3@3X3\3`3d3h3l3p3t3x3|3
4 4$4(4l4p4t4x4|4
5 5$5(5,505t5x5|5
6 6$6(6,6064686<6@6D6H6L6P6T6X6\6`6d6h6l6p6t6x6|6
7 7$7(7,7074787<7@7D7H7L7P7T7X7\7`7d7h7l7p7
;$;,;4;<;D;L;T;\;d;l;t;|;
<$<,<4<<<D<L<T<\<d<l<t<|<
=$=,=4=<=D=L=
3 3$3(3,3034383<3@3D3H3L3P3T3X3\3`3d3h3l3p3t3x3|3
6 6(60686@6H6P6X6`6h6p6x6
7 7(70787@7H7P7X7`7h7p7x7
8 8(80888@8H8P8X8`8h8p8x8
9 9(90989@9H9P9X9`9h9p9
; ;$;,;0;4;8;<;@;D;H;T;\;d;h;l;p;t;
< <$<(<,<0<4<8<<<
= =$=(=,=0=4=8=<=@=D=H=L=P=T=X=\=`=d=h=l=p=t=x=|=
> >$>(>,>0>4>8><>@>D>H>
8$8,848<8D8L8T8\8d8l8t8|8
: :,:8:D:P:\:h:t:
;(;4;@;L;X;d;p;|;
<$<0<<<H<T<`<l<x<
=$=0=<=H=T=`=l=x=
8$8,848<8D8L8T8\8d8l8t8|8
9$9,949<9D9L9T9\9d9l9t9|9
:$:,:4:<:D:L:T:\:d:l:t:|:
;$;,;4;<;D;L;T;\;d;l;t;|;
<$<,<4<<<D<L<T<\<d<l<t<|<
=$=,=4=<=D=L=T=\=d=l=t=|=
>$>,>4><>D>L>T>\>d>l>t>|>
9 9(90989@9H9P9X9`9h9p9x9
: :(:0:8:@:H:P:X:`:h:p:x:
; ;(;0;8;@;H;P;X;`;h;p;x;
< <(<0<8<@<H<P<X<`<h<p<x<
= =(=0=8=@=H=P=X=`=h=p=x=
> >(>0>8>@>H>P>X>`>h>p>x>
? ?(?0?8?@?H?P?X?`?h?p?x?
$3(303
4$4(484<4D4\4l4p4
5 5$5,5D5T5X5h5l5p5x5
6$6(686<6@6D6H6P6h6x6|6
7$7(7,747L7\7`7h7
8 80848<8T8d8h8l8p8t8|8
9 9$9,9D9T9X9h9l9p9x9
:$:4:8:H:L:T:l:|:
; ;8;H;L;T;l;|;
<,<0<4<<<T<d<h<x<|<
=4=D=H=X=\=`=h=
>(>,><>@>D>L>d>t>x>
?$?(?,?0?8?P?`?d?t?x?|?
0 04080H0L0\0`0d0l0
1 10141D1H1L1T1l1|1
2(2,20282P2`2d2t2x2|2
3 3(3@3P3T3d3h3l3p3x3
4,4<4@4P4T4X4\4`4h4
5 5054585<5@5D5L5d5t5x5
<$<,<4<D<T<x<
=(=4=<=\=
>0><>D>d>
?8?D?L?
0,040H0P0d0l0t0|0
1 1(1<1D1L1T1X1`1h1p1t1|1
2 2$2,2@2H2P2X2\2d2x2
4(4<4D4\4l4
5 5(505<5\5d5l5p5x5
6<6H6h6t6
7 7,7\7`7|7
8(848<8d8h8
9(9H9h9
:(:H:d:h:
;8;X;x;
<8<X<x<
=8=T=X=x=
0:8:@:P:
=8=H=X=h=x=
5$6@6`6
9$9H9h9
:(:H:l:
kernel32.dll
Bapi-ms-win-core-fibers-l1-1-1
api-ms-win-core-synch-l1-2-0
kernel32
api-ms-
((((( H
((((( H
(
mscoree.dll
ALC_ALL
LC_COLLATE
LC_CTYPE
LC_MONETARY
LC_NUMERIC
LC_TIME
Sunday
Monday
Tuesday
Wednesday
Thursday
Friday
Saturday
January
February
August
September
October
November
December
MM/dd/yy
dddd, MMMM dd, yyyy
HH:mm:ss
Bapi-ms-win-core-datetime-l1-1-1
api-ms-win-core-file-l1-2-2
api-ms-win-core-localization-l1-2-1
api-ms-win-core-localization-obsolete-l1-2-0
api-ms-win-core-processthreads-l1-1-2
api-ms-win-core-string-l1-1-0
api-ms-win-core-sysinfo-l1-2-1
api-ms-win-core-winrt-l1-1-0
api-ms-win-core-xstate-l2-1-0
api-ms-win-rtcore-ntuser-window-l1-1-0
api-ms-win-security-systemfunctions-l1-1-0
ext-ms-win-ntuser-dialogbox-l1-1-0
ext-ms-win-ntuser-windowstation-l1-1-0
advapi32
api-ms-win-appmodel-runtime-l1-1-2
user32
api-ms-win-core-fibers-l1-1-0
ext-ms-
Bja-JP
american
american english
american-english
australian
belgian
canadian
chinese
chinese-hongkong
chinese-simplified
chinese-singapore
chinese-traditional
dutch-belgian
english-american
english-aus
english-belize
english-can
english-caribbean
english-ire
english-jamaica
english-nz
english-south africa
english-trinidad y tobago
english-uk
english-us
english-usa
french-belgian
french-canadian
french-luxembourg
french-swiss
german-austrian
german-lichtenstein
german-luxembourg
german-swiss
irish-english
italian-swiss
norwegian
norwegian-bokmal
norwegian-nynorsk
portuguese-brazilian
spanish-argentina
spanish-bolivia
spanish-chile
spanish-colombia
spanish-costa rica
spanish-dominican republic
spanish-ecuador
spanish-el salvador
spanish-guatemala
spanish-honduras
spanish-mexican
spanish-modern
spanish-nicaragua
spanish-panama
spanish-paraguay
spanish-peru
spanish-puerto rico
spanish-uruguay
spanish-venezuela
swedish-finland
america
britain
england
great britain
holland
hong-kong
new-zealand
pr china
pr-china
puerto-rico
slovak
south africa
south korea
south-africa
south-korea
trinidad & tobago
united-kingdom
united-states
zh-CHS
az-AZ-Latn
uz-UZ-Latn
kok-IN
syr-SY
div-MV
quz-BO
sr-SP-Latn
az-AZ-Cyrl
uz-UZ-Cyrl
quz-EC
sr-SP-Cyrl
quz-PE
smj-NO
bs-BA-Latn
smj-SE
sr-BA-Latn
sma-NO
sr-BA-Cyrl
sma-SE
sms-FI
smn-FI
zh-CHT
az-az-cyrl
az-az-latn
bs-ba-latn
div-mv
kok-in
quz-bo
quz-ec
quz-pe
sma-no
sma-se
smj-no
smj-se
smn-fi
sms-fi
sr-ba-cyrl
sr-ba-latn
sr-sp-cyrl
sr-sp-latn
syr-sy
uz-uz-cyrl
uz-uz-latn
zh-chs
zh-cht
CONOUT$
Antivirus Signature
Bkav W32.AIDetectMalware
Lionic Clean
tehtris Clean
ClamAV Win.Keylogger.Lazy-10031941-0
CMC Clean
CAT-QuickHeal Clean
Skyhigh BehavesLike.Win32.Generic.jc
ALYac Gen:Variant.Fragtor.589903
Cylance Unsafe
Zillya Clean
Sangfor Trojan.Win32.Save.a
K7AntiVirus Clean
Alibaba Clean
K7GW Clean
Cybereason malicious.06c622
Baidu Clean
VirIT Clean
Paloalto Clean
Symantec ML.Attribute.HighConfidence
Elastic malicious (high confidence)
ESET-NOD32 a variant of Win32/Kryptik.HXIV
APEX Malicious
Avast Win32:Evo-gen [Trj]
Cynet Malicious (score: 100)
Kaspersky HEUR:Trojan.Win32.Stelpak.gen
BitDefender Gen:Variant.Fragtor.589903
NANO-Antivirus Clean
ViRobot Clean
MicroWorld-eScan Gen:Variant.Fragtor.589903
Tencent Clean
TACHYON Clean
Sophos Generic ML PUA (PUA)
F-Secure Clean
DrWeb Clean
VIPRE Gen:Variant.Fragtor.589903
TrendMicro Clean
McAfeeD ti!48F0E9CCA359
Trapmine malicious.high.ml.score
FireEye Generic.mg.b42e6e906c622c07
Emsisoft Gen:Variant.Fragtor.589903 (B)
SentinelOne Static AI - Malicious PE
GData Gen:Variant.Fragtor.589903
Jiangmin Clean
Webroot Clean
Varist Clean
Avira Clean
Antiy-AVL Clean
Kingsoft malware.kb.a.974
Gridinsoft Clean
Xcitium Clean
Arcabit Trojan.Fragtor.D9004F
SUPERAntiSpyware Clean
ZoneAlarm VHO:Trojan-PSW.MSIL.Convagent.gen
Microsoft Trojan:Win32/Wacatac.B!ml
Google Detected
AhnLab-V3 Clean
Acronis Clean
McAfee Clean
MAX malware (ai score=83)
VBA32 BScope.TrojanPSW.Vidar
Malwarebytes Clean
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Rising Trojan.Stealerc!8.1840A (TFE:1:rCSQJn51qSS)
Yandex Clean
Ikarus Trojan-Spy.LummaStealer
MaxSecure Trojan.Malware.300983.susgen
Fortinet Clean
BitDefenderTheta Gen:NN.ZexaF.36810.QuW@aa6vITn
AVG Win32:Evo-gen [Trj]
DeepInstinct Clean
CrowdStrike win/malicious_confidence_70% (D)
alibabacloud Clean
No IRMA results available.