Static | ZeroBOX

PE Compile Time

2024-07-24 00:10:45

PE Imphash

42eb2b50acad70f9618962bfa70c7f34

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x0001ea87 0x0001ec00 6.57754240373
.rdata 0x00020000 0x0000a6ac 0x0000a800 4.62588544039
.data 0x0002b000 0x00031804 0x00030800 7.97675954773
.bsS 0x0005d000 0x000004ac 0x00000600 5.11129176259
.reloc 0x0005e000 0x00001f94 0x00002000 6.5277943557

Imports

Library USER32.dll:
0x42016c OffsetRect
Library KERNEL32.dll:
0x420000 GetCPInfo
0x420004 CreateFileW
0x420008 WaitForSingleObject
0x42000c CreateThread
0x420010 VirtualAllocEx
0x420014 FreeConsole
0x420018 RaiseException
0x420020 InitOnceComplete
0x420024 CloseHandle
0x420028 GetCurrentThreadId
0x420040 GetLastError
0x420050 CloseThreadpoolWork
0x420054 GetModuleHandleExW
0x420070 EncodePointer
0x420074 DecodePointer
0x420078 MultiByteToWideChar
0x42007c WideCharToMultiByte
0x420080 LCMapStringEx
0x420088 GetModuleHandleW
0x42008c GetProcAddress
0x420090 GetStringTypeW
0x420094 WriteConsoleW
0x420098 IsDebuggerPresent
0x4200a4 GetStartupInfoW
0x4200a8 GetCurrentProcess
0x4200ac TerminateProcess
0x4200b0 GetCurrentProcessId
0x4200b4 InitializeSListHead
0x4200b8 HeapSize
0x4200bc RtlUnwind
0x4200c0 SetLastError
0x4200c8 TlsAlloc
0x4200cc TlsGetValue
0x4200d0 TlsSetValue
0x4200d4 TlsFree
0x4200d8 FreeLibrary
0x4200dc LoadLibraryExW
0x4200e0 ExitProcess
0x4200e4 GetModuleFileNameW
0x4200e8 GetStdHandle
0x4200ec WriteFile
0x4200f0 GetCommandLineA
0x4200f4 GetCommandLineW
0x4200f8 HeapFree
0x4200fc HeapAlloc
0x420100 CompareStringW
0x420104 LCMapStringW
0x420108 GetLocaleInfoW
0x42010c IsValidLocale
0x420110 GetUserDefaultLCID
0x420114 EnumSystemLocalesW
0x420118 GetFileType
0x42011c GetFileSizeEx
0x420120 SetFilePointerEx
0x420124 FlushFileBuffers
0x420128 GetConsoleOutputCP
0x42012c GetConsoleMode
0x420130 ReadFile
0x420134 ReadConsoleW
0x420138 HeapReAlloc
0x42013c FindClose
0x420140 FindFirstFileExW
0x420144 FindNextFileW
0x420148 IsValidCodePage
0x42014c GetACP
0x420150 GetOEMCP
0x420160 GetProcessHeap
0x420164 SetStdHandle

!This program cannot be run in DOS mode.
`.rdata
@.data
.reloc
4VWQPS
D$DSV3
~,9~$t
YYW9^d|
L$8_^][3
I`hZB@
74s,l4th4
,e4",shH
FYY;t$
FYY;t$
PPPhZR@
u9F(t
tG9uCj
PPPPPWS
QQSVWd
URPQQhp
UQPXY]Y[
PVVVVV
PVVVVV
ARPRQh
jYjf
PPPPPPPP
uSSSSj
SWt@jU
_tqPVj@
_PVVVVV
j"_SVVVV
PVVVVV
^PSSSSS
j"^WSSSS
WVVVVV
PVSRSQV
PPPPPVW
PP9E u!PPSVP
PVVVVV
PWWWWW
D8(Ht'
D8(Ht5F
L:-^_[
f9:t!V
QQSVj8j@
NX9^`t1
;V\uYW
u2Vj@h
9C`u99C\t4
u29K\t-
PPPPPPPP
Unknown exception
bad array new length
string too long
generic
iostream
iostream stream error
bad cast
bad locale name
ios_base::badbit set
ios_base::failbit set
ios_base::eofbit set
Fail to schedule the chore!
This function cannot be called on a default constructed task
broken promise
future already retrieved
promise already satisfied
no state
future
Own head
JAHNsiu
0000000006:1@0000000005:@
vector too long
?bad allocation
bad function call
bad exception
device or resource busy
invalid argument
no such process
not enough memory
operation not permitted
resource deadlock would occur
resource unavailable try again
success
address family not supported
address in use
address not available
already connected
argument list too long
argument out of domain
bad address
bad file descriptor
bad message
broken pipe
connection aborted
connection already in progress
connection refused
connection reset
cross device link
destination address required
directory not empty
executable format error
file exists
file too large
filename too long
function not supported
host unreachable
identifier removed
illegal byte sequence
inappropriate io control operation
interrupted
invalid seek
io error
is a directory
message size
network down
network reset
network unreachable
no buffer space
no child process
no link
no lock available
no message available
no message
no protocol option
no space on device
no stream resources
no such device or address
no such device
no such file or directory
not a directory
not a socket
not a stream
not connected
not supported
operation canceled
operation in progress
operation not supported
operation would block
owner dead
permission denied
protocol error
protocol not supported
read only file system
result out of range
state not recoverable
stream timeout
text file busy
timed out
too many files open in system
too many files open
too many links
too many symbolic link levels
value too large
wrong protocol type
unknown error
GetCurrentPackageId
GetSystemTimePreciseAsFileTime
GetTempPath2W
0123456789abcdefghijklmnopqrstuvwxyz
0123456789abcdefghijklmnopqrstuvwxyz
__based(
__cdecl
__pascal
__stdcall
__thiscall
__fastcall
__vectorcall
__clrcall
__eabi
__swift_1
__swift_2
__swift_3
__ptr64
__restrict
__unaligned
restrict(
delete
operator
`vftable'
`vbtable'
`vcall'
`typeof'
`local static guard'
`string'
`vbase destructor'
`vector deleting destructor'
`default constructor closure'
`scalar deleting destructor'
`vector constructor iterator'
`vector destructor iterator'
`vector vbase constructor iterator'
`virtual displacement map'
`eh vector constructor iterator'
`eh vector destructor iterator'
`eh vector vbase constructor iterator'
`copy constructor closure'
`udt returning'
`local vftable'
`local vftable constructor closure'
new[]
delete[]
`omni callsig'
`placement delete closure'
`placement delete[] closure'
`managed vector constructor iterator'
`managed vector destructor iterator'
`eh vector copy constructor iterator'
`eh vector vbase copy constructor iterator'
`dynamic initializer for '
`dynamic atexit destructor for '
`vector copy constructor iterator'
`vector vbase copy constructor iterator'
`managed vector copy constructor iterator'
`local static thread guard'
operator ""
operator co_await
operator<=>
Type Descriptor'
Base Class Descriptor at (
Base Class Array'
Class Hierarchy Descriptor'
Complete Object Locator'
`anonymous namespace'
FlsAlloc
FlsFree
FlsGetValue
FlsSetValue
InitializeCriticalSectionEx
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
CorExitProcess
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
Sunday
Monday
Tuesday
Wednesday
Thursday
Friday
Saturday
January
February
August
September
October
November
December
MM/dd/yy
dddd, MMMM dd, yyyy
HH:mm:ss
AreFileApisANSI
CompareStringEx
EnumSystemLocalesEx
GetDateFormatEx
GetLocaleInfoEx
GetTimeFormatEx
GetUserDefaultLocaleName
IsValidLocaleName
LCMapStringEx
LCIDToLocaleName
LocaleNameToLCID
AppPolicyGetProcessTerminationMethod
_hypot
_nextafter
?5Wg4p
%S#[k=
"B <1=
.text$di
.text$mn
.text$x
.text$yd
.idata$5
.00cfg
.CRT$XCA
.CRT$XCAA
.CRT$XCC
.CRT$XCL
.CRT$XCU
.CRT$XCZ
.CRT$XIA
.CRT$XIAA
.CRT$XIAC
.CRT$XIC
.CRT$XIZ
.CRT$XLA
.CRT$XLZ
.CRT$XPA
.CRT$XPX
.CRT$XPXA
.CRT$XPZ
.CRT$XTA
.CRT$XTZ
.rdata
.rdata$T
.rdata$r
.rdata$sxdata
.rdata$voltmd
.rdata$zzzdbg
.rtc$IAA
.rtc$IZZ
.rtc$TAA
.rtc$TZZ
.tls$ZZZ
.xdata$x
.idata$2
.idata$3
.idata$4
.idata$6
.data$r
.data$rs
OffsetRect
USER32.dll
WaitForSingleObject
CreateThread
VirtualAllocEx
FreeConsole
RaiseException
InitOnceBeginInitialize
InitOnceComplete
CloseHandle
GetCurrentThreadId
ReleaseSRWLockExclusive
AcquireSRWLockExclusive
TryAcquireSRWLockExclusive
WakeAllConditionVariable
SleepConditionVariableSRW
GetLastError
FreeLibraryWhenCallbackReturns
CreateThreadpoolWork
SubmitThreadpoolWork
CloseThreadpoolWork
GetModuleHandleExW
IsProcessorFeaturePresent
EnterCriticalSection
LeaveCriticalSection
InitializeCriticalSectionEx
DeleteCriticalSection
QueryPerformanceCounter
EncodePointer
DecodePointer
MultiByteToWideChar
WideCharToMultiByte
LCMapStringEx
GetSystemTimeAsFileTime
GetModuleHandleW
GetProcAddress
GetStringTypeW
GetCPInfo
IsDebuggerPresent
UnhandledExceptionFilter
SetUnhandledExceptionFilter
GetStartupInfoW
GetCurrentProcess
TerminateProcess
GetCurrentProcessId
InitializeSListHead
KERNEL32.dll
RtlUnwind
SetLastError
InitializeCriticalSectionAndSpinCount
TlsAlloc
TlsGetValue
TlsSetValue
TlsFree
FreeLibrary
LoadLibraryExW
ExitProcess
GetModuleFileNameW
GetStdHandle
WriteFile
GetCommandLineA
GetCommandLineW
HeapFree
HeapAlloc
CompareStringW
LCMapStringW
GetLocaleInfoW
IsValidLocale
GetUserDefaultLCID
EnumSystemLocalesW
GetFileType
GetFileSizeEx
SetFilePointerEx
FlushFileBuffers
GetConsoleOutputCP
GetConsoleMode
ReadFile
ReadConsoleW
HeapReAlloc
FindClose
FindFirstFileExW
FindNextFileW
IsValidCodePage
GetACP
GetOEMCP
GetEnvironmentStringsW
FreeEnvironmentStringsW
SetEnvironmentVariableW
GetProcessHeap
SetStdHandle
HeapSize
CreateFileW
WriteConsoleW
+\|;oP
cS _@o
/V_lmzFO
__212^CH
kaWj2~
0d1ClMiD
c:&%gM
J}8eMC~
#o~h}c
{a,kio
.*otTRO
kDMWDRJ
/o;#m"
jd#,3tt
i!c7~!'
F425xd*?
iyC[|T
7}Uv7o
R*l+5$
d~n<HVD
U#UdJlM
6`q!RR^
TuQ"u:c
S8R,dK
6Bk${
M4?q``
-$m+6S
&Vw3l9B
I7LrF]
=eYpBt
R)aw\Q
_M8>/S
kc!?#~
8 ;V$L
'Yv1lF
_Ux%"-2o
$A7otio
g>ea,r
L5&Ot&
ExP0~w
%ENd@<
vcPk=[IL
UP<RN/NV
&y]Oe@
boTKm
s:P;X>w
57Ek\tn
:T?r(^
d~o(y?U
V)[HVU
+7(vfn7
Umqj8P
O;SZk}mt
#/NW:-s^:
~stI5n
uke<p6L>3
`J<"TJP
WY'xZk
Z&-f+a
=`;^F4
snlV?W
xmJ5l8r
$@a@fb
HU|7d'
LQM+0l
\ "8]FU
tpuF!L
!]Z*Er
5`Adr-
iL#g,S
0:t@kw
_6GP`
KC[uf,
]e`h^Q
|uZ%yo
dm)7h>}
~3>OC)_1
Jx{l(wA
tZ~?M4
.S}wu$L
"R\TD8J
_Q'@I7L8
)}"\9.
8v\Jo'
3%+,27
m[JaXr{
b~AlR%
;s1pf[
T&DvZxI"
o*V2S=
A9T=`<l
|J,R;5P
{_VSe
(;Vw'X3
Yor;T
!}*0W.4
bb7RP/
~b4,)n
VWJV!^
up_XmR
Re_:}~
2S7]/J
"[kZw2{
y?M4Mm)@
Pk`8Ms
xZi!*S
AQ5Dj$
+dp<N
f}g;1KYh
B^5'T2=
!M[7bR
d[-%kHh
,utY.n
UdJQO'*
3FQ&VA
Ob2GEQ5
h,DQUHtN
H>i'X
*VAA)=
9A`R0[=
kFS/FZ
zlAOMw
i)3\9F
/0N]Bwa
d+?<V
:R_nf!
yP*4iP@o
2IpzIc
4/vIGu
+maGo]
tYLmk%7
X7#Vn]+
&n_Z1(T
0_?^`}8
s%A%b9
,Ux#|"
M;eZn*
}(b7?Gf
g;$]lz
uh&4lY
KIj)hhi
=+wE-qH/
!( 1fY
ybUW=n$
?h<Tc[
I90e-+
8k^:`y
41Y<@ts^5
ewV)?'
P2jWgu
yzkN/t?6
SZI?";j
gHc*Yf
z&KhwL
sW#"%d'
I$OZ\{2
@{h7:t\
w]z8~K
C`+]lx
0mvhnC<
6P*M>e
-jiKx}
3= /z^m~
nI(YO6
%g$8/f
:G?/9@}z
nI//:P
'pE,?.-6N
@BtPoT%
:"VJ1L
sP"Ni}p
J# xOs
}&55RuB
7>\A1o
|QY[BD
0{_zin
)<yg!P
`m=;O!
'%=:G;o
bq3AtF
OTpfs4
'tNy@d
T;d2Cl
(u12dsU
mr>M>_/1
p(<)!6&.
.O^%dB
2&v,K``9
,Er-<vP
,<?l6?G?
H315HN
l@!R[EaH
(WOsATz]
i.v t]
;f7W]2(
Gtx[_Q
!<u"H0
A]D18C
d*2X3bC
[ubQS^
](mPlo
>[{&<h-
JlA%Cuk
Y1`'*k
z2y?g8
}wsDsc$
O H~h=0
`XM}jh
f4\.|L}!
2Qkg*g
H_))lU
A{5>:1
}@NHtv8o
WAlta)
*JVm`d
pe'`U9
~Ky,_} 9
4>>?j,K[
S"phIa
YjOo&I
.=&;L-
OU~ge9O/l
^&$2JU
t^7E:7
0FZw&CA
J]rM"(:
ku#cqut
Pth^1aN-
p_3>BI
Ec\!#r
=]cKflg
q}j/&sM
4PlYhB"
MKG`+
b~krC@
KCd ?6
pkEF3PS
v[>J8MbWw
~xC:JG
HWR5?W
[o@2pni
qh? d~m
PVbwpU~
L]LX%7
[>Fwbv
#gC2Fz
d>&J%Aq3
9/7Ty>
lgDFY6LI%
hxLj%Z
>NhY`;
KJ.Pu?d
td8NpbC
@*'V^2
/@6T;K)
[0Zj&:
.uDgEt
S8kM( r
DIXJgL
Ka1)4p
'V ao~
8M2`6n
.ZF!kc
%TTT(Rl
.h:Y?5 ZG
fyx!1{
{i,m-}
x!7DVYr
cq-'qO
O[%{SJ
qpZUx '
%yH1,33
Girz:I
Mj>3bz
:?I^NG
J3X*t4
yo/`n^
15cSX|I9Z
|:Dlgg
lc,uCR
rbEd)"sw
lTjm}5E
D'z_sz
nIe@\4
jnP^>'G@
Z&thmC
)O`M74U&p
TLG&E*p
\0/kcUM
ZO!(8/}
[gs2u.
SJ^'[L
q_=NXz1
qF4E5e
BEIb=)IC
0)\pY)
Q[pnZ/%
R(t-hz
9>Lqp},q
_^I(Pla
]sUJM"
wvzW[$
Xv*b'l
$g,rk^
&%vSI%k
U%a%&y;C
:b9mNN
TYL%EDa:$A@
{y##_m
gf82_j
P,%Yym
I@Im>?
'oY-/8
&L1,Gc
g^(.fD
a\&:wA
?qBqCL
~j%)ciW.
'[;:$}5
9 `oY^
tV~^|[
epwBmA
Q?40@x\
B,@?@<
82TJ4`
L31Px8
? Rcj7K^W
uO5,!zM
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
.?AVexception@std@@
.?AVbad_array_new_length@std@@
.?AVbad_alloc@std@@
.?AVruntime_error@std@@
.?AVsystem_error@std@@
.?AV_System_error@std@@
.?AVbad_cast@std@@
.?AVfailure@ios_base@std@@
.?AVtask_canceled@Concurrency@@
.?AVinvalid_operation@Concurrency@@
.?AV_Interruption_exception@details@Concurrency@@
.?AVfuture_error@std@@
.?AVlogic_error@std@@
.?AV<lambda_0456396a71e3abd88ede77bdd2823d8e>@@
.?AV<lambda_eb87dfd73f857f44e1a351ea42ce2b34>@@
.?AV<lambda_cf64729cb90f65090849ddab3f3d5e68>@@
.?AV<lambda_5e5ab22ea98f4361dbf159481d01f54d>@@
.?AV?$_Fake_no_copy_callable_adapter@A6AXXZ@std@@
.?AV<lambda_dc3a808d3cb651230a54fc79f9ff1e4d>@@
.?AVlength_error@std@@
.?AVbad_function_call@std@@
.?AVbad_exception@std@@
.?AVerror_category@std@@
.?AV_Generic_error_category@std@@
.?AV_Iostream_error_category2@std@@
.?AV_Ref_count_base@std@@
.?AV_Facet_base@std@@
.?AVfacet@locale@std@@
.?AU_Crt_new_delete@std@@
.?AUctype_base@std@@
.?AV?$ctype@D@std@@
.?AV_RefCounter@details@Concurrency@@
.?AV_CancellationTokenRegistration@details@Concurrency@@
.?AU_TaskProcHandle@details@Concurrency@@
.?AV?$_Func_base@X$$V@std@@
.?AU_Task_impl_base@details@Concurrency@@
.?AV?$_CancellationTokenCallback@V<lambda_3b8ab8d2629adf61a42ee3fe177a046b>@@@details@Concurrency@@
.?AV?$_Func_base@E$$V@std@@
.?AU?$_Task_impl@E@details@Concurrency@@
.?AV_Future_error_category2@std@@
.?AV?$_Associated_state@H@std@@
.?AV?$_Ref_count_obj2@U_ExceptionHolder@details@Concurrency@@@std@@
.?AV?$_Ref_count_obj2@U?$_Task_impl@E@details@Concurrency@@@std@@
.?AV?$_Func_impl_no_alloc@V<lambda_5e5ab22ea98f4361dbf159481d01f54d>@@X$$V@std@@
.?AV?$_Func_impl_no_alloc@V<lambda_cf64729cb90f65090849ddab3f3d5e68>@@X$$V@std@@
.?AV?$_Func_impl_no_alloc@V<lambda_eb87dfd73f857f44e1a351ea42ce2b34>@@E$$V@std@@
.?AV?$_Func_impl_no_alloc@V<lambda_0456396a71e3abd88ede77bdd2823d8e>@@X$$V@std@@
.?AV?$_Deferred_async_state@X@std@@
.?AV?$_Packaged_state@$$A6AXXZ@std@@
.?AV?$_Task_async_state@X@std@@
.?AV?$_Func_impl_no_alloc@V?$_Fake_no_copy_callable_adapter@A6AXXZ@std@@X$$V@std@@
.?AU?$_InitialTaskHandle@XV<lambda_dc3a808d3cb651230a54fc79f9ff1e4d>@@U_TypeSelectorNoAsync@details@Concurrency@@@?$task@E@Concurrency@@
.?AU?$_PPLTaskHandle@EU?$_InitialTaskHandle@XV<lambda_dc3a808d3cb651230a54fc79f9ff1e4d>@@U_TypeSelectorNoAsync@details@Concurrency@@@?$task@E@Concurrency@@U_TaskProcHandle@details@3@@details@Concurrency@@
.?AV?$_Func_impl_no_alloc@V<lambda_dc3a808d3cb651230a54fc79f9ff1e4d>@@X$$V@std@@
.?AV_ExceptionPtr_normal@?A0x6e02efe5@@
.?AV?$_ExceptionPtr_static@Vbad_alloc@std@@@?A0x6e02efe5@@
.?AV?$_ExceptionPtr_static@Vbad_exception@std@@@?A0x6e02efe5@@
.?AV_Locimp@locale@std@@
.?AVios_base@std@@
.?AV?$_Iosb@H@std@@
.?AV?$basic_ios@DU?$char_traits@D@std@@@std@@
.?AV?$basic_streambuf@DU?$char_traits@D@std@@@std@@
.?AV?$basic_ostream@DU?$char_traits@D@std@@@std@@
.?AV?$basic_filebuf@DU?$char_traits@D@std@@@std@@
.?AVcodecvt_base@std@@
.?AV?$codecvt@DDU_Mbstatet@@@std@@
.?AVtype_info@@
xP|H&{
~~|H&{
0#0*070;0G0M0[0p0z0
1#13181B1X1l1p1z1
222Q2P3Z3
315[8#9
9=;{;,>D>J>n?s?
4$5=5W5
7+717>7y7
8#8/8E8]8u8
8H9d9u9
;;$<a<
9@:J:O:n:
;(;<;^;
;4<B<]<|<
>(?E?o?
0<0B0H0S0[0d0
4"424M4Z4f4~4
4+5K5k5z5
6'6J6j6w6
7H7U7r7
1'2@2s2
3&434@4U4a4h4
606:6A6T6
7j7r7x7
;1;[;o;u;
<"<*<9<e<l<
?C?O?f?
40A0Z0
1!1Y1}1
2 3&3z3
5P6D9q9W:
>2?G?U?c?
0 0A0Q0W0^0e0
5?5e5t5
7 7&737:7_7g7t7
==4===l=u=~=
0%00070J0X0^0d0j0p0v0}0
1#1,1P1^1d1j1p1v1|1
2&252>2K2a2
3 333G3L3_3
66$6(6,606
;#;(;/<@<
7 7$7(7,7074787<7@7D7H7L7P7T7X7\7`7d7h7l7p7t7x7|7
:-:A:]:h:v:|:
:=;L;,<Y>
5H60858_8{8
;';,;1;L;Y;b;g;l;
< <A<Q<i<
030:0n0y0~;
<"<)</<J<Q<z<
=6=K=a=n=|=
3Q5S8!9m:
464;4G4L4`4
4I5P5b5k5
6&676W6
7 7)777
:?:F:v;
<0<><Q<\<g<
0!0+0/070C0]0
1%1,141L1Z1b1z1
1%21262<2A2I2O2W2
8X=^=p={=
<W=2>9>f>m>
?:?a?v?
0,0?0Y0h0
121C1]1c1n1
6*646[6e6
77&7+7i7q7
8-82878G8L8Q8a8f8k8{8
909C9d9q9
;8;B;R;W;\;w;
<,<A<e<w<
>">9>K>W>
?#?9?F?K?Y?
4J6\6D719
6#768~8
='=]=z=
343Y3)4a5
:4:_:r:}:
: ;a;p;
>#>8?L?
060J0j0t0
0A1o1k2w2
;(;7;A;N;X;h;
4:6@6N6]6"7)737W7
9):8:F:c:k:
:&;-;};
<!<3<E<W<i<{<
;'<H<.=
: ;|;)<
7H8N8S8Z8j8x8
0@1j1r1
8%858F8
9+9>9]9
:2:T:x:
?f?k?}?
4$4A4^4{4
6.6P6m6
829O9l9
: :*:6:B:L:V:`:j:t:~:
2$2(2,2D2H2L2P2T2X2
3 3$34383<3@3X3\3`3d3h3l3p3t3x3|3
4 4$4(4l4p4t4x4|4
5 5$5(5,505t5x5|5
6 6$6(6,6064686<6@6D6H6L6P6T6X6\6`6d6h6l6p6t6x6|6
7 7$7(7,7074787<7@7D7H7L7P7T7X7\7`7d7h7l7p7
;$;,;4;<;D;L;T;\;d;l;t;|;
<$<,<4<<<D<L<T<\<d<l<t<|<
=$=,=4=<=D=L=
3 3$3(3,3034383<3@3D3H3L3P3T3X3\3`3d3h3l3p3t3x3|3
6 6(60686@6H6P6X6`6h6p6x6
7 7(70787@7H7P7X7`7h7p7x7
8 8(80888@8H8P8X8`8h8p8x8
9 9(90989@9H9P9X9`9h9p9
; ;$;,;0;4;8;<;@;D;H;T;\;d;h;l;p;t;
< <$<(<,<0<4<8<<<
= =$=(=,=0=4=8=<=@=D=H=L=P=T=X=\=`=d=h=l=p=t=x=|=
> >$>(>,>0>4>8><>@>D>H>
8$8,848<8D8L8T8\8d8l8t8|8
: :,:8:D:P:\:h:t:
;(;4;@;L;X;d;p;|;
<$<0<<<H<T<`<l<x<
=$=0=<=H=T=`=l=x=
8$8,848<8D8L8T8\8d8l8t8|8
9$9,949<9D9L9T9\9d9l9t9|9
:$:,:4:<:D:L:T:\:d:l:t:|:
;$;,;4;<;D;L;T;\;d;l;t;|;
<$<,<4<<<D<L<T<\<d<l<t<|<
=$=,=4=<=D=L=T=\=d=l=t=|=
>$>,>4><>D>L>T>\>d>l>t>|>
9 9(90989@9H9P9X9`9h9p9x9
: :(:0:8:@:H:P:X:`:h:p:x:
; ;(;0;8;@;H;P;X;`;h;p;x;
< <(<0<8<@<H<P<X<`<h<p<x<
= =(=0=8=@=H=P=X=`=h=p=x=
> >(>0>8>@>H>P>X>`>h>p>x>
? ?(?0?8?@?H?P?X?`?h?p?x?
$3(303
4$4(484<4D4\4l4p4
5 5$5,5D5T5X5h5l5p5x5
6$6(686<6@6D6H6P6h6x6|6
7$7(7,747L7\7`7h7
8 80848<8T8d8h8l8p8t8|8
9 9$9,9D9T9X9h9l9p9x9
:$:4:8:H:L:T:l:|:
; ;8;H;L;T;l;|;
<,<0<4<<<T<d<h<x<|<
=4=D=H=X=\=`=h=
>(>,><>@>D>L>d>t>x>
?$?(?,?0?8?P?`?d?t?x?|?
0 04080H0L0\0`0d0l0
1 10141D1H1L1T1l1|1
2(2,20282P2`2d2t2x2|2
3 3(3@3P3T3d3h3l3p3x3
4,4<4@4P4T4X4\4`4h4
5 5054585<5@5D5L5d5t5x5
<$<,<4<D<T<x<
=(=4=<=\=
>0><>D>d>
?8?D?L?
0,040H0P0d0l0t0|0
1 1(1<1D1L1T1X1`1h1p1t1|1
2 2$2,2@2H2P2X2\2d2x2
4(4<4D4\4l4
5 5(505<5\5d5l5p5x5
6<6H6h6t6
7 7,7\7`7|7
8(848<8d8h8
9(9H9h9
:(:H:d:h:
;8;X;x;
<8<X<x<
=8=T=X=x=
(>0>8>H>
181H1X1h1x1
9$:@:`:
=$=H=h=
>(>H>l>
kernel32.dll
Bapi-ms-win-core-fibers-l1-1-1
api-ms-win-core-synch-l1-2-0
kernel32
api-ms-
((((( H
((((( H
(
mscoree.dll
ALC_ALL
LC_COLLATE
LC_CTYPE
LC_MONETARY
LC_NUMERIC
LC_TIME
Sunday
Monday
Tuesday
Wednesday
Thursday
Friday
Saturday
January
February
August
September
October
November
December
MM/dd/yy
dddd, MMMM dd, yyyy
HH:mm:ss
Bapi-ms-win-core-datetime-l1-1-1
api-ms-win-core-file-l1-2-2
api-ms-win-core-localization-l1-2-1
api-ms-win-core-localization-obsolete-l1-2-0
api-ms-win-core-processthreads-l1-1-2
api-ms-win-core-string-l1-1-0
api-ms-win-core-sysinfo-l1-2-1
api-ms-win-core-winrt-l1-1-0
api-ms-win-core-xstate-l2-1-0
api-ms-win-rtcore-ntuser-window-l1-1-0
api-ms-win-security-systemfunctions-l1-1-0
ext-ms-win-ntuser-dialogbox-l1-1-0
ext-ms-win-ntuser-windowstation-l1-1-0
advapi32
api-ms-win-appmodel-runtime-l1-1-2
user32
api-ms-win-core-fibers-l1-1-0
ext-ms-
Bja-JP
american
american english
american-english
australian
belgian
canadian
chinese
chinese-hongkong
chinese-simplified
chinese-singapore
chinese-traditional
dutch-belgian
english-american
english-aus
english-belize
english-can
english-caribbean
english-ire
english-jamaica
english-nz
english-south africa
english-trinidad y tobago
english-uk
english-us
english-usa
french-belgian
french-canadian
french-luxembourg
french-swiss
german-austrian
german-lichtenstein
german-luxembourg
german-swiss
irish-english
italian-swiss
norwegian
norwegian-bokmal
norwegian-nynorsk
portuguese-brazilian
spanish-argentina
spanish-bolivia
spanish-chile
spanish-colombia
spanish-costa rica
spanish-dominican republic
spanish-ecuador
spanish-el salvador
spanish-guatemala
spanish-honduras
spanish-mexican
spanish-modern
spanish-nicaragua
spanish-panama
spanish-paraguay
spanish-peru
spanish-puerto rico
spanish-uruguay
spanish-venezuela
swedish-finland
america
britain
england
great britain
holland
hong-kong
new-zealand
pr china
pr-china
puerto-rico
slovak
south africa
south korea
south-africa
south-korea
trinidad & tobago
united-kingdom
united-states
zh-CHS
az-AZ-Latn
uz-UZ-Latn
kok-IN
syr-SY
div-MV
quz-BO
sr-SP-Latn
az-AZ-Cyrl
uz-UZ-Cyrl
quz-EC
sr-SP-Cyrl
quz-PE
smj-NO
bs-BA-Latn
smj-SE
sr-BA-Latn
sma-NO
sr-BA-Cyrl
sma-SE
sms-FI
smn-FI
zh-CHT
az-az-cyrl
az-az-latn
bs-ba-latn
div-mv
kok-in
quz-bo
quz-ec
quz-pe
sma-no
sma-se
smj-no
smj-se
smn-fi
sms-fi
sr-ba-cyrl
sr-ba-latn
sr-sp-cyrl
sr-sp-latn
syr-sy
uz-uz-cyrl
uz-uz-latn
zh-chs
zh-cht
CONOUT$
Antivirus Signature
Bkav W32.AIDetectMalware
Lionic Clean
tehtris Clean
ClamAV Win.Keylogger.Lazy-10031941-0
CMC Clean
CAT-QuickHeal Clean
Skyhigh BehavesLike.Win32.Generic.fc
ALYac Clean
Cylance Unsafe
Zillya Clean
Sangfor Worm.Win32.Save.a
K7AntiVirus Clean
Alibaba Clean
K7GW Clean
Cybereason Clean
Baidu Clean
VirIT Clean
Paloalto Clean
Symantec ML.Attribute.HighConfidence
Elastic malicious (high confidence)
ESET-NOD32 a variant of Win32/Kryptik.HXIV
APEX Malicious
Avast Win32:Evo-gen [Trj]
Cynet Malicious (score: 100)
Kaspersky HEUR:Trojan.Win32.Stelpak.gen
BitDefender Clean
NANO-Antivirus Clean
ViRobot Clean
MicroWorld-eScan Clean
Tencent Clean
TACHYON Clean
Sophos ML/PE-A
F-Secure Clean
DrWeb Clean
VIPRE Clean
TrendMicro Clean
McAfeeD ti!525A892469B4
Trapmine malicious.high.ml.score
FireEye Generic.mg.1b1c6f48b7c91a48
Emsisoft Clean
SentinelOne Static AI - Malicious PE
GData Win32.Trojan.Kryptik.BZQ20A
Jiangmin Clean
Webroot Clean
Varist Clean
Avira Clean
Antiy-AVL Trojan[PSW]/MSIL.Convagent
Kingsoft malware.kb.a.914
Gridinsoft Clean
Xcitium Clean
Arcabit Clean
SUPERAntiSpyware Clean
ZoneAlarm HEUR:Trojan.Win32.Stelpak.gen
Microsoft Trojan:Win32/Stealerc.GAB!MSR
Google Detected
AhnLab-V3 Clean
Acronis Clean
McAfee Clean
MAX Clean
VBA32 BScope.TrojanPSW.Vidar
Malwarebytes Clean
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Rising Trojan.Stealerc!8.1840A (TFE:1:rCSQJn51qSS)
Yandex Clean
Ikarus Trojan-Spy.LummaStealer
MaxSecure Trojan.Malware.300983.susgen
Fortinet W32/Kryptik.HXIV!tr
BitDefenderTheta Gen:NN.ZexaF.36810.xuW@aKL@Lc
AVG Win32:Evo-gen [Trj]
DeepInstinct Clean
CrowdStrike win/malicious_confidence_100% (W)
alibabacloud Clean
No IRMA results available.