Static | ZeroBOX

PE Compile Time

2023-09-14 23:16:43

PE Imphash

eb596fc515d9f07ea83f140a5c4c78cc

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x00016398 0x00016400 6.4502969889
.rdata 0x00018000 0x0000b0d6 0x0000b200 5.05803145414
.data 0x00024000 0x00001ef4 0x00000e00 2.23118606765
.pdata 0x00026000 0x000015fc 0x00001600 5.08046058385
.gfids 0x00028000 0x000000cc 0x00000200 1.56418565396
.tls 0x00029000 0x00000009 0x00000200 0.0203931352361
.rsrc 0x0002a000 0x00337658 0x00337800 7.95876761946
.reloc 0x00362000 0x0000066c 0x00000800 4.91824612934

Resources

Name Offset Size Language Sub-language File type
DB 0x0004e700 0x00312dd7 LANG_KOREAN SUBLANG_KOREAN data
DLL 0x0002a100 0x00024600 LANG_KOREAN SUBLANG_KOREAN PE32+ executable (DLL) (GUI) x86-64, for MS Windows
RT_MANIFEST 0x003614d8 0x0000017d LANG_ENGLISH SUBLANG_ENGLISH_US XML 1.0 document text

Imports

Library KERNEL32.dll:
0x180018020 ReadFile
0x180018028 CloseHandle
0x180018030 SetFilePointer
0x180018038 WriteFile
0x180018040 RaiseException
0x180018048 GetLastError
0x180018058 DeleteCriticalSection
0x180018060 GetProcAddress
0x180018068 LoadLibraryW
0x180018070 HeapDestroy
0x180018078 HeapAlloc
0x180018080 HeapFree
0x180018088 HeapReAlloc
0x180018090 CreateFileW
0x180018098 GetProcessHeap
0x1800180a0 GetTempPathA
0x1800180a8 GetModuleHandleW
0x1800180b0 SizeofResource
0x1800180b8 FreeResource
0x1800180c0 LockResource
0x1800180c8 LoadResource
0x1800180d0 FindResourceW
0x1800180d8 ReadConsoleW
0x1800180e0 SetEndOfFile
0x1800180e8 GetModuleFileNameW
0x1800180f0 MultiByteToWideChar
0x1800180f8 HeapSize
0x180018100 FlushFileBuffers
0x180018108 WriteConsoleW
0x180018110 SetFilePointerEx
0x180018118 SetStdHandle
0x180018120 GetStringTypeW
0x180018128 EnterCriticalSection
0x180018130 LeaveCriticalSection
0x180018138 SetEvent
0x180018140 ResetEvent
0x180018148 WaitForSingleObjectEx
0x180018150 CreateEventW
0x180018158 RtlCaptureContext
0x180018160 RtlLookupFunctionEntry
0x180018168 RtlVirtualUnwind
0x180018170 UnhandledExceptionFilter
0x180018180 GetCurrentProcess
0x180018188 TerminateProcess
0x180018198 IsDebuggerPresent
0x1800181a0 GetStartupInfoW
0x1800181a8 QueryPerformanceCounter
0x1800181b0 GetCurrentProcessId
0x1800181b8 GetCurrentThreadId
0x1800181c0 GetSystemTimeAsFileTime
0x1800181c8 InitializeSListHead
0x1800181d0 OutputDebugStringW
0x1800181d8 RtlPcToFileHeader
0x1800181e0 EncodePointer
0x1800181e8 RtlUnwindEx
0x1800181f8 TlsAlloc
0x180018200 TlsGetValue
0x180018208 TlsSetValue
0x180018210 TlsFree
0x180018218 FreeLibrary
0x180018220 LoadLibraryExW
0x180018228 InterlockedFlushSList
0x180018230 ExitProcess
0x180018238 GetModuleHandleExW
0x180018240 WideCharToMultiByte
0x180018248 GetACP
0x180018250 GetStdHandle
0x180018258 GetFileType
0x180018260 GetConsoleCP
0x180018268 GetConsoleMode
0x180018270 LCMapStringW
0x180018278 IsValidCodePage
0x180018280 GetOEMCP
0x180018288 GetCPInfo
0x180018290 GetEnvironmentStringsW
0x180018298 FreeEnvironmentStringsW
0x1800182a0 GetCommandLineA
0x1800182a8 GetCommandLineW
0x1800182b0 SetLastError
Library USER32.dll:
0x1800182c0 wsprintfA
0x1800182c8 wsprintfW
Library ADVAPI32.dll:
0x180018000 SystemFunction036
0x180018008 RegSetValueExW
0x180018010 RegOpenKeyExW
Library ole32.dll:
0x1800182d8 CoUninitialize
0x1800182e0 CoInitializeEx
0x1800182e8 CoGetObject

Exports

Ordinal Address Name
1 0x1800021a0 in
2 0x180002150 out
!This program cannot be run in DOS mode.
`.rdata
@.data
.pdata
@.gfids
@.reloc
x ATAVAWH
@A_A^A\
H9A0ugH
UVWAVAWH
A_A^_^]
|$ AVH
L$ SVWH
|$ AVH
H3E H3E
VWATAVAWH
A_A^A\_^
B(I9A(
UATAUAVAWH
L9`8tA
A_A^A]A\]
UVWATAUAVAWH
pA_A^A]A\_^]
WATAUAVAWH
A_A^A]A\_
AUAVAWH
I9}(t9H
0A_A^A]
@SVWATAUAVAWH
L!|$(L!
D$0HcH
pA_A^A]A\_^[
SVWATAUAVAWH
0A_A^A]A\_^[
WATAUAVAWH
r 9_ t
ri9V vdH
A_A^A]A\_
WATAUAVAWH
A_A^A]A\_
WATAUAVAWH
A_A^A]A\_
ffffff
VWATAVAWH
A_A^A\_^
x ATAVAWH
A_A^A\
H;xXu9
UVWAVAWH
A_A^_^]
t$ UWATAVAWH
D8d$pt
A_A^A\_]
D$@H;G
D$0H;G
S,, <Zw
CA< t(<#t
S,, <Zw
CA< t(<#t
<htr<jtb<lt6<tt&<wt
!,X< w
t$ WAVAWH
s4+sP+
0A_A^_
t$ WATAUAVAWH
s4+sP+
A_A^A]A\_
x ATAVAWH
A_A^A\
WATAUAVAWH
A_A^A]A\_
t$ UWATAVAWH
D8d$Ht
D8d$Ht
A_A^A\_]
WATAUAVAWH
A_A^A]A\_
u3HcH<H
WAVAWH
A86taH
0A_A^_
L$ WATAUAVAWH
@A_A^A]A\_
x ATAVAWH
A_A^A\
|$ UATAUAVAWH
A_A^A]A\]
t$ WATAUAVAWH
'D8l$@
t)D8l$@t
WD8l$@t
D8l$@t
A_A^A]A\_
D82u&H
D8t$Ht
x ATAVAWH
gfffffffH
D8d$ht
A_A^A\
WATAUAVAWH
A_A^A]A\_
fD9t$b
UVWATAUAVAWH
A_A^A]A\_^]
VWATAVAW
A_A^A\_^
WATAUAVAWH
A_A^A]A\_
\$ UVWATAUAVAWH
H!D$ E
`A_A^A]A\_^]
WAVAWH
@A_A^_
WATAUAVAWH
A_A^A]A\_
l$ VWATAVAWH
L$&@8t$&t0@8q
A81t@@8r
A_A^A\_^
fD94Fu
SVWATAUAWH
HA_A]A\_^[
@UATAUAVAWH
H!T$0D
uf!T$(H!T$
A_A^A]A\]
@USVWATAUAVAWH
D8l$ht
A_A^A]A\_^[]
@UATAUAVAWH
e0A_A^A]A\]
ATAVAWH
0A_A^A\
s WAVAWH
0A_A^_
UATAUAVAWH
A_A^A]A\]
WATAUAVAWH
A_A^A]A\_
ffffff
fffffff
WAVAWH
0A_A^_
WAVAWH
A_A^_
@SUVWATAUAVAWH
D88Hte
8A_A^A]A\_^][
SUVWATAUAVAWH
D88Ht!
D98Ht;H
8A_A^A]A\_^][
UVWATAUAVAWH
D(8Ht}
`A_A^A]A\_^]
|$ ATAVAWH
\$@@8=
A_A^A\
USVWAVH
A^_^[]
LcA<E3
InitializeConditionVariable
SleepConditionVariableCS
WakeAllConditionVariable
Unknown exception
bad allocation
bad array new length
bad exception
EventRegister
EventSetInformation
EventUnregister
EventWriteTransfer
FlsAlloc
FlsFree
FlsGetValue
FlsSetValue
InitializeCriticalSectionEx
Main Invoked.
Main Returned.
`vftable'
`vbtable'
`vcall'
`typeof'
`local static guard'
`string'
`vbase destructor'
`vector deleting destructor'
`default constructor closure'
`scalar deleting destructor'
`vector constructor iterator'
`vector destructor iterator'
`vector vbase constructor iterator'
`virtual displacement map'
`eh vector constructor iterator'
`eh vector destructor iterator'
`eh vector vbase constructor iterator'
`copy constructor closure'
`udt returning'
`local vftable'
`local vftable constructor closure'
new[]
delete[]
`omni callsig'
`placement delete closure'
`placement delete[] closure'
`managed vector constructor iterator'
`managed vector destructor iterator'
`eh vector copy constructor iterator'
`eh vector vbase copy constructor iterator'
`dynamic initializer for '
`dynamic atexit destructor for '
`vector copy constructor iterator'
`vector vbase copy constructor iterator'
`managed vector copy constructor iterator'
`local static thread guard'
operator ""
Type Descriptor'
Base Class Descriptor at (
Base Class Array'
Class Hierarchy Descriptor'
Complete Object Locator'
__based(
__cdecl
__pascal
__stdcall
__thiscall
__fastcall
__vectorcall
__clrcall
__eabi
__ptr64
__restrict
__unaligned
restrict(
delete
operator
`h````
xpxxxx
`h`hhh
xwpwpp
(null)
CorExitProcess
NAN(SNAN)
nan(snan)
NAN(IND)
nan(ind)
Sunday
Monday
Tuesday
Wednesday
Thursday
Friday
Saturday
January
February
August
September
October
November
December
MM/dd/yy
dddd, MMMM dd, yyyy
HH:mm:ss
UTF-16LEUNICODE
AreFileApisANSI
GetCurrentPackageId
LCMapStringEx
LocaleNameToLCID
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
[aOni*{
~ $s%r
@b;zO]
v2!L.2
1#QNAN
1#SNAN
UUUUUU
UUUUUU
=imb;D
/>58d%
VM>cQ6
>jtm}S
)>6{1n
+f)>0'
;H9>&X
*StO9>T
n03>Pu
K~Je#>!
bp(=>?g
BC?>6t9^
K&>.yC
.xJ>Hf
y\PD>!
|b=})>
c [1>H'
uzKs@>
3>N;kU
kE>fvw
V6E>`"(5
?UUUUUU
?7zQ6$
%s%04X.bat
C:\ProgramData\Microsoft\Windows
_|Zsrfu[nj|TkXjhynts
_|HwjfyjXjhynts
_|Rfu[nj|TkXjhynts
_|Hqtxj
_|TujsUwthjxx
_|TujsYmwjfi
_|WjxzrjYmwjfi
_|TujsUwthjxxYtpjs
_|Vzjw~NsktwrfyntsYtpjs
_|LjyHtsyj}yYmwjfi
_|XjyHtsyj}yYmwjfi
_|Fqqthfyj[nwyzfqRjrtw~
_|Wjfi[nwyzfqRjrtw~
_|\wnyj[nwyzfqRjrtw~
_|Uwtyjhy[nwyzfqRjrtw~
_|Kwjj[nwyzfqRjrtw~
WyqFhvznwjUjgQthp
WyqWjqjfxjUjgQthp
WyqSyXyfyzxYtItxJwwtw
WyqSyXyfyzxYtItxJwwtwStYjg
WyqNsnyZsnhtijXywnsl
WyqHwjfyjZxjwYmwjfi
WyqLjy[jwxnts
QiwJszrjwfyjQtfijiRtizqjx
HwjfyjUwthjxxNsyjwsfq\
[nwyzfqFqqthJ}
[nwyzfqUwtyjhyJ}
powershell Add-MpPreference -Exc"
InvokeMainViaCRT
"Main Invoked."
FileName
ExitMainViaCRT
"Main Returned."
FileName
Microsoft.CRTProvider
.text$di
.text$mn
.text$mn$00
.text$x
.text$yd
.idata$5
.00cfg
.CRT$XCA
.CRT$XCL
.CRT$XCZ
.CRT$XIA
.CRT$XIC
.CRT$XIZ
.CRT$XLA
.CRT$XLZ
.CRT$XPA
.CRT$XPX
.CRT$XPXA
.CRT$XPZ
.CRT$XTA
.CRT$XTZ
.rdata
.rdata$T
.rdata$r
.rdata$zETW0
.rdata$zETW1
.rdata$zETW2
.rdata$zETW9
.rdata$zzzdbg
.rtc$IAA
.rtc$IZZ
.rtc$TAA
.rtc$TZZ
.xdata
.xdata$x
.edata
.idata$2
.idata$3
.idata$4
.idata$6
.data$r
.pdata
.gfids$x
.gfids$y
.tls$ZZZ
.rsrc$01
.rsrc$02
Install_AtAdmin.dll
SetLastError
MultiByteToWideChar
GetModuleFileNameW
CreateFileW
ReadFile
CloseHandle
SetFilePointer
WriteFile
RaiseException
GetLastError
InitializeCriticalSectionEx
DeleteCriticalSection
GetProcAddress
LoadLibraryW
HeapDestroy
HeapAlloc
HeapFree
HeapReAlloc
HeapSize
GetProcessHeap
GetTempPathA
GetModuleHandleW
SizeofResource
FreeResource
LockResource
LoadResource
FindResourceW
KERNEL32.dll
wsprintfA
wsprintfW
USER32.dll
RegOpenKeyExW
RegSetValueExW
ADVAPI32.dll
CoGetObject
CoInitializeEx
CoUninitialize
ole32.dll
EnterCriticalSection
LeaveCriticalSection
SetEvent
ResetEvent
WaitForSingleObjectEx
CreateEventW
RtlCaptureContext
RtlLookupFunctionEntry
RtlVirtualUnwind
UnhandledExceptionFilter
SetUnhandledExceptionFilter
GetCurrentProcess
TerminateProcess
IsProcessorFeaturePresent
IsDebuggerPresent
GetStartupInfoW
QueryPerformanceCounter
GetCurrentProcessId
GetCurrentThreadId
GetSystemTimeAsFileTime
InitializeSListHead
OutputDebugStringW
RtlPcToFileHeader
EncodePointer
RtlUnwindEx
InitializeCriticalSectionAndSpinCount
TlsAlloc
TlsGetValue
TlsSetValue
TlsFree
FreeLibrary
LoadLibraryExW
InterlockedFlushSList
ExitProcess
GetModuleHandleExW
WideCharToMultiByte
GetACP
GetStdHandle
GetFileType
GetConsoleCP
GetConsoleMode
LCMapStringW
IsValidCodePage
GetOEMCP
GetCPInfo
GetEnvironmentStringsW
FreeEnvironmentStringsW
GetCommandLineA
GetCommandLineW
GetStringTypeW
SetStdHandle
SetFilePointerEx
WriteConsoleW
FlushFileBuffers
SetEndOfFile
ReadConsoleW
SystemFunction036
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
.?AVtype_info@@
.?AVbad_alloc@std@@
.?AVexception@std@@
.?AVbad_array_new_length@std@@
.?AVbad_exception@std@@
.?AVCAtlStringMgr@ATL@@
.?AUIAtlStringMgr@ATL@@
.?AUIAtlMemMgr@ATL@@
.?AVCWin32Heap@ATL@@
.?AVCAtlException@ATL@@
!This program cannot be run in DOS mode.
UqRich{
`.rdata
@.data
.pdata
@.gfids
@.reloc
x ATAVAWH
@A_A^A\
t$ WATAUAVAWH
A_A^A]A\_
@SVWATAUAVAW
A_A^A]A\_^[
H9A0uT
\$ UVWATAUAVAWH
`A_A^A]A\_^]
|$ 1t3
WAVAWH
@A_A^_
fD9<ru
H SUVWAVAWH
8A_A^_^][
H SVWH
|$ AVH
H3E H3E
VWATAVAWH
A_A^A\_^
B(I9A(
UATAUAVAWH
L9`8tA
A_A^A]A\]
UVWATAUAVAWH
pA_A^A]A\_^]
WATAUAVAWH
A_A^A]A\_
AUAVAWH
I9}(t9H
0A_A^A]
@SVWATAUAVAWH
L!|$(L!
D$0HcH
pA_A^A]A\_^[
SVWATAUAVAWH
0A_A^A]A\_^[
WATAUAVAWH
r 9_ t
ri9V vdH
A_A^A]A\_
WATAUAVAWH
A_A^A]A\_
WATAUAVAWH
A_A^A]A\_
ffffff
VWATAVAWH
A_A^A\_^
x ATAVAWH
A_A^A\
H;xXu9
t$ UWATAVAWH
D8d$pt
A_A^A\_]
D$0H;G
t$ WATAUAVAWH
s4+sP+
A_A^A]A\_
WATAUAVAWH
A_A^A]A\_
t$ UWATAVAWH
D8d$Ht
D8d$Ht
A_A^A\_]
L$ UVWATAUAVAWH
0A_A^A]A\_^]
u3HcH<H
WAVAWH
A86taH
0A_A^_
L$ WATAUAVAWH
@A_A^A]A\_
x ATAVAWH
A_A^A\
t$ WATAUAVAWH
'D8l$@
t)D8l$@t
WD8l$@t
D8l$@t
A_A^A]A\_
D82u&H
D8t$Ht
x ATAVAWH
gfffffffH
D8d$ht
A_A^A\
WATAUAVAWH
A_A^A]A\_
fD9t$b
WATAUAVAWH
A_A^A]A\_
WAVAWH
0A_A^_
@SUVWATAUAVAWH
D88Hte
8A_A^A]A\_^][
SUVWATAUAVAWH
D88Ht!
D98Ht;H
8A_A^A]A\_^][
VATAUAVAWH
A_A^A]A\^
UVWATAUAVAWH
D(8Ht}
`A_A^A]A\_^]
WAVAWH
@A_A^_
l$ VWATAVAWH
L$&@8t$&t0@8q
A81t@@8r
A_A^A\_^
fD94Fu
SVWATAUAWH
HA_A]A\_^[
@UATAUAVAWH
H!T$0D
uf!T$(H!T$
A_A^A]A\]
@USVWATAUAVAWH
D8l$ht
A_A^A]A\_^[]
@UATAUAVAWH
e0A_A^A]A\]
ATAVAWH
0A_A^A\
s WAVAWH
0A_A^_
UATAUAVAWH
A_A^A]A\]
UVWATAUAVAWH
A_A^A]A\_^]
VWATAVAW
A_A^A\_^
WATAUAVAWH
A_A^A]A\_
\$ UVWATAUAVAWH
H!D$ E
`A_A^A]A\_^]
ffffff
fffffff
WAVAWH
A_A^_
|$ ATAVAWH
\$@@8=
A_A^A\
USVWAVH
A^_^[]
LcA<E3
InitializeConditionVariable
SleepConditionVariableCS
WakeAllConditionVariable
Unknown exception
bad exception
EventRegister
EventSetInformation
EventUnregister
EventWriteTransfer
FlsAlloc
FlsFree
FlsGetValue
FlsSetValue
InitializeCriticalSectionEx
Main Invoked.
Main Returned.
`vftable'
`vbtable'
`vcall'
`typeof'
`local static guard'
`string'
`vbase destructor'
`vector deleting destructor'
`default constructor closure'
`scalar deleting destructor'
`vector constructor iterator'
`vector destructor iterator'
`vector vbase constructor iterator'
`virtual displacement map'
`eh vector constructor iterator'
`eh vector destructor iterator'
`eh vector vbase constructor iterator'
`copy constructor closure'
`udt returning'
`local vftable'
`local vftable constructor closure'
new[]
delete[]
`omni callsig'
`placement delete closure'
`placement delete[] closure'
`managed vector constructor iterator'
`managed vector destructor iterator'
`eh vector copy constructor iterator'
`eh vector vbase copy constructor iterator'
`dynamic initializer for '
`dynamic atexit destructor for '
`vector copy constructor iterator'
`vector vbase copy constructor iterator'
`managed vector copy constructor iterator'
`local static thread guard'
operator ""
Type Descriptor'
Base Class Descriptor at (
Base Class Array'
Class Hierarchy Descriptor'
Complete Object Locator'
__based(
__cdecl
__pascal
__stdcall
__thiscall
__fastcall
__vectorcall
__clrcall
__eabi
__ptr64
__restrict
__unaligned
restrict(
delete
operator
`h````
xpxxxx
`h`hhh
xwpwpp
(null)
CorExitProcess
NAN(SNAN)
nan(snan)
NAN(IND)
nan(ind)
Sunday
Monday
Tuesday
Wednesday
Thursday
Friday
Saturday
January
February
August
September
October
November
December
MM/dd/yy
dddd, MMMM dd, yyyy
HH:mm:ss
AreFileApisANSI
GetCurrentPackageId
GetSystemTimePreciseAsFileTime
LCMapStringEx
LocaleNameToLCID
UTF-16LEUNICODE
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
[aOni*{
~ $s%r
@b;zO]
v2!L.2
1#QNAN
1#SNAN
UUUUUU
UUUUUU
=imb;D
/>58d%
VM>cQ6
>jtm}S
)>6{1n
+f)>0'
;H9>&X
*StO9>T
n03>Pu
K~Je#>!
bp(=>?g
BC?>6t9^
K&>.yC
.xJ>Hf
y\PD>!
|b=})>
c [1>H'
uzKs@>
3>N;kU
kE>fvw
V6E>`"(5
?UUUUUU
?7zQ6$
LFreeLibrary
ExitThread
_|Zsrfu[nj|TkXjhynts
_|HwjfyjXjhynts
_|Rfu[nj|TkXjhynts
_|Hqtxj
_|TujsUwthjxx
_|TujsYmwjfi
_|WjxzrjYmwjfi
_|TujsUwthjxxYtpjs
_|Vzjw~NsktwrfyntsYtpjs
_|LjyHtsyj}yYmwjfi
_|XjyHtsyj}yYmwjfi
_|Fqqthfyj[nwyzfqRjrtw~
_|Wjfi[nwyzfqRjrtw~
_|\wnyj[nwyzfqRjrtw~
_|Uwtyjhy[nwyzfqRjrtw~
_|Kwjj[nwyzfqRjrtw~
WyqFhvznwjUjgQthp
WyqWjqjfxjUjgQthp
WyqSyXyfyzxYtItxJwwtw
WyqSyXyfyzxYtItxJwwtwStYjg
WyqNsnyZsnhtijXywnsl
WyqHwjfyjZxjwYmwjfi
WyqLjy[jwxnts
QiwJszrjwfyjQtfijiRtizqjx
HwjfyjUwthjxxNsyjwsfq\
[nwyzfqFqqthJ}
[nwyzfqUwtyjhyJ}
c:\programdata\microsoft\windows\t1.t
windows\system32
winlogon.exe
logonui
taskhost
svchost.exe
InvokeMainViaCRT
"Main Invoked."
FileName
ExitMainViaCRT
"Main Returned."
FileName
Microsoft.CRTProvider
.text$di
.text$mn
.text$mn$00
.text$x
.text$yd
.idata$5
.00cfg
.CRT$XCA
.CRT$XCL
.CRT$XCZ
.CRT$XIA
.CRT$XIC
.CRT$XIZ
.CRT$XLA
.CRT$XLZ
.CRT$XPA
.CRT$XPX
.CRT$XPXA
.CRT$XPZ
.CRT$XTA
.CRT$XTZ
.rdata
.rdata$T
.rdata$r
.rdata$zETW0
.rdata$zETW1
.rdata$zETW2
.rdata$zETW9
.rdata$zzzdbg
.rtc$IAA
.rtc$IZZ
.rtc$TAA
.rtc$TZZ
.xdata
.xdata$x
.edata
.idata$2
.idata$3
.idata$4
.idata$6
.data$r
.pdata
.gfids$x
.gfids$y
.tls$ZZZ
.rsrc$01
.rsrc$02
msort_x64.dll
SetLastError
MultiByteToWideChar
ReadFile
WriteFile
GetModuleFileNameW
SetFilePointer
CreateFileW
CloseHandle
GetFileSize
VirtualAlloc
GetProcAddress
GetModuleHandleW
CreateThread
DeleteFileW
TerminateProcess
GetLastError
WideCharToMultiByte
RaiseException
InitializeCriticalSectionEx
DeleteCriticalSection
HeapDestroy
HeapAlloc
HeapFree
HeapReAlloc
HeapSize
GetProcessHeap
CreateMutexW
GetModuleFileNameA
KERNEL32.dll
RegOpenKeyExW
RegCreateKeyExW
RegQueryValueExW
RegSetValueExW
RegGetValueW
ADVAPI32.dll
SHGetSpecialFolderPathW
SHELL32.dll
CoGetObject
CoInitializeEx
CoUninitialize
ole32.dll
PathFileExistsW
StrStrIW
StrStrIA
SHLWAPI.dll
EnterCriticalSection
LeaveCriticalSection
SetEvent
ResetEvent
WaitForSingleObjectEx
CreateEventW
RtlCaptureContext
RtlLookupFunctionEntry
RtlVirtualUnwind
UnhandledExceptionFilter
SetUnhandledExceptionFilter
GetCurrentProcess
IsProcessorFeaturePresent
IsDebuggerPresent
GetStartupInfoW
QueryPerformanceCounter
GetCurrentProcessId
GetCurrentThreadId
GetSystemTimeAsFileTime
InitializeSListHead
OutputDebugStringW
RtlPcToFileHeader
EncodePointer
RtlUnwindEx
InitializeCriticalSectionAndSpinCount
TlsAlloc
TlsGetValue
TlsSetValue
TlsFree
FreeLibrary
LoadLibraryExW
InterlockedFlushSList
ExitProcess
GetModuleHandleExW
GetACP
GetStdHandle
GetFileType
LCMapStringW
GetFileAttributesExW
GetConsoleMode
ReadConsoleW
IsValidCodePage
GetOEMCP
GetCPInfo
GetEnvironmentStringsW
FreeEnvironmentStringsW
GetCommandLineA
GetCommandLineW
GetStringTypeW
SetStdHandle
SetFilePointerEx
FlushFileBuffers
GetConsoleCP
SetEndOfFile
WriteConsoleW
SystemFunction036
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
.?AVtype_info@@
.?AVbad_exception@std@@
.?AVexception@std@@
.?AVCAtlStringMgr@ATL@@
.?AUIAtlStringMgr@ATL@@
.?AUIAtlMemMgr@ATL@@
.?AVCWin32Heap@ATL@@
.?AVCAtlException@ATL@@
<?xml version='1.0' encoding='UTF-8' standalone='yes'?>
<assembly xmlns='urn:schemas-microsoft-com:asm.v1' manifestVersion='1.0'>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v3">
<security>
<requestedPrivileges>
<requestedExecutionLevel level='asInvoker' uiAccess='false' />
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
j6UUUUUUUU
WUUUUUUUUUUUUUUUUUUUUUU
rHQu!I6\
-hX5hX]ix
vOJR.>Eg)
}jpBf\{[]VC
@@{G7I*V5
&Dvl'I_
h1'SCL
pWHC`;U|
D+6E@{jh
qUa_o-`
]=%q)GW
fTO*rK
kza|/q
$a"U1q
[T-5L9
_d;R5}
rPX5~PR
aPR]vP
GX5~PR
PR=fPBPUoPR
+ NBPU
T5<NR]V
[TuBI5
5NUUm\
b^MjR[
X$l[]V
8I54(I
^~R,EQ|
f=asB
9asBS
oI5&I>
ir\YCf
5_o&99
;Ey.CM!
[=@=@mU
!}yQA
!3m+.5
)~~jh0Oh/
'yI}W
SSggggg
SSggggS
SSgggg{
%kCUl)
EnQx6H
1o?mFJ
T8!}zc
iIDRn!
?K==z{
RnI4|v
5L=jg l
"n3S2L;<
tYHGFFa
Dv{HBR
A\ )7R
5$g}u8
HpwWH2
6T2L;<
tynO?x
Dg}5C/I)
$B=wpI
3B{Yuk
s3O"l;Z
| @{j(
bH~j(a>-
CXO+-I
/5d$l{
~HdW@/9#
Io8aH
n,$!Ua
+~ox\/H
#TalK*
iX=f+y
{Tqo%}
TuiKz2U
OztV]f+
_s{Ws[I
K~jh0O>9HQ
zTqo%=9
>_qo%}
~{V]f+
>_qo%=
r]'QuZo
@SUf[I
V]v+IUn+I
iX=f+9
n+IUn+I
jn+IUn+I
iX=f+9V
4TU/qz
j|)g/J
M[B?x\
qEqaUwoXEz
iX=f+9
,=J9f/J9
PU{Tqo%}
{Rqo%)7
>_qo%}
Jv3jKR
?fzYai
jLS_}nK
r[IO*v[I
iX=f+y
l%G\.+l7
iX=f+9
>^~xai
d;Up$TalK
-!SC!I9
b+I9~/
w{Wco%
axJ9|/
SUf[I_
9EM9P/J9
~;U]v+
iX=f+9>n
SCq[B{
i7J$aOP
n+I9N/J
qI$/oS`
~+I}~W
iX=f+9
W#m%}u
vj(nKh/
vj(nKh/
^TuE$a
$?Ruzo
l7</Ii
RnE/J9
3 _a@$
rYzQuu
hg032v]
vc4<^`[
%i7P"I9
B^r|=FX5
*v+9;kW
hohw!/
hjhw!/9
-7N/Jg
^~2IQTz
m@yIHR.
hWl^r25
z nWl^
bA$1SOvQy
i0_5F$
yI~Wix
*vjhE~jh0Oh/
6Uu[IF
^TeF$o
/v0?Up
EUfD2~
Zn%@>WL/
<)#_,
IL n:C
5i7Q^RqA$
Oz3O ^
a!IF>#
q~8h^5
-p2R L
'gUq"yu
ReF$C;|o
=MQTF;
Wp$) Zo
',8asBMo
KvY%Cz
O;Z{IH
*\S\w#
`EB'@{
n%|Pzk
'SC!I9
Qp1T;jR3
r[I";v[
lW|+I'
Qp1T;jR3
eTws[I
a"gtvs[I"Stvs[I"{tvs[I"
0.mws[
mS}W@S
z'_muv
{iWs"I
U/qz?U
'9\}W@S
L=O5n(1
M=OUs"
V+\O$!
pzWUWz
}5PdH?
/ai7o()`
CB{9Up
f2N59
3B{Yuk
%NrUuM
vY%CF^
EG..*l
ERr|na
*9FV"lW
'9^:$,
;<v=3aS
h0?Up1
NAHdj($
/EiC{7Q
&$2E'0H
Rg9qy`
77v"J_o
rM"Zh$
ODSCq[
ODSCq[
ODSCq[
EDC;*N
'Io1wT
VJ9("Bo
]L~jh0
rCDtB'
@)7DD't
qpRn}""t
!SC!y{
Y1dj($_J
+Rn}"J
@y ,Hgj
AHdj($_J
\}"BSC
\}"BSC
N=ACW?
_o%CaJ9
bJR.BD
*X0Ix6
T5c$Ua
KB?xl4ka
B{9Up[
Y>O{Ih/
p3 "~M
G1}hW
O(ls!JR
5L=wK"J
G1}hW
u0%LrR}
AlInl"
Kv-VR
8":^ZE
DIv-V
0#n[]V
LD)w*"
{,"J}n D
}Q"J}UL
0"J}uJ
>BDo?5
F'|t2}
#"RuaJR
/|B ?}
3%;\2$|/q
0fwKu{R
pz/W/W
Ma:#g}
MB?x<Uma
z\imaG
IZM_hhh
mXL~jh0Oh/
R.K^4R
Rn(/z;4v
+/J)w0/
@Rn4/J9
-I;FhI
E)wX^T
E)7n^4
E)7n^4
>,/J)wX^4U
a{tvVu
#%=m,u
R.K^4R
O}nn+:
RnyQH
"[QAlC
IS.(/:
^op{a(nK
"[QAlC
6;4E.=
.8U0@R
.8U0@R
h[0$}.
br_&/:
='/J9Z
2U0@NP
[ nW[C`
\cyQ_u
DQ}nz+
lE}nz+
lE}nz+
rMQ}nz+
lE}nz+
E}nz+:
%|6ij|
QH)W;/
't2PA:
sVyQF>
4dd+/z
"8ifI
{6/:c~("'{
2voE|~
VtVT EQ)w
Czs/nEij
nn6[QB
+v+jsg
VD{Yuk
NoSUM_[u
U1[%1Snm+
{mE9|^D
7>/J)w
Rnn+J9
vumC>?
O-lI~($
3B{Yuk
vtZ%oo)
dj($}U
oEgU&mC~
)7~+:r>
)7~+:v?^X
euHCB{
x+J_Fu
_SCq)7
_SCq)7
_SCq)7
}oE=@~M
vAd/:?
d+J)Gg+
}1)Gg+J
lE)W|+
mE)W|+:K
y>_v+J=
_SCq)7
*af rvR
ZS~[p0
oE=@~M
?#2PF{
j4KF{j
+8 !Ua
-$U&+$
[H*:+$
5L=7C[QB
G1}hW
0SnF[Q
Ck>_qu
_Q_}|-
g*+I UQpIH
eT>hj|
$|6i7/
!P>nBLR
3nt"Jg
^YM9t"
Av&I9r"
'y'UMo5E
LeH-o-o-o-o-o-o-o-o-o
qODUapI{
v"zAvb
xB ?}
%qZS~
$|ZRuP
q)Wx("
.ZCD?x
#$$7p(
E$7A(B
>7A(zT
GHHE?B
U]FHv[h
P~(n;5
d[]4 i
$oLD{94
AQU0 yc
)waPDvY
E)75(jX
`PTEMI
$qS[Pz
5:%A}n
I>RcT`
3(B}nqP
mU4BRqOI
Mu^[q|D%
fSkT(5
WYU/V/V
Q/V/V/V/V/V
UC5TC5TC5T
=SGR U{g
5(Jmn\
!D"|25
|> NTa
]AhIHR
Z3D'9 Ct
1Sn:NT
%~=>&?
KzrFh/
957lC7
#$)W StVe
TM4%Iopn
`LQ=P>=
V?rk[m
2E)w9S
&GHv,H
)W1E;V
)I")w9S
[Q5u&I9
[Q5u&I
[Q5u&I9,
[Q5u&I
I>RGR M
chOrBv
8Dl*O/
1E!Y<S
%)w:ST
#dQ7lC7
G)W ST
0E=jW?
%N[,u$
MIBR=8
|59BR]
fONPe@r
MIBR=8
?&MUOI
@|x[u7
[Q5u&I9n
r\oEo{
x3EU~O
3%IUfS
)W StR
|U4BRqOIR
wfq"z
Y0E|6)
[Q5u&!)
>(})u6
n>(})Jg
hj(]xj
bzTo(]xj
'Ig=z0
Pk"SC!I
O;Z[%
)~~jh0O
hjpBLR
za~jh0
$UQ#$!
\$=PR.
RKuH-U
*^]U=@]U
+=c~8K'
\%e+)[I
l%e+)[I
l%e+)[I
Ib~h%S
IUUMjR
olB ?}
*LCz.'|
wU5MUl=
@BHoa
SUoOREOI
{$i5}^
'IW}\/
HzR1<B
$]R5u&!
x a|,St
5L=7[LQB
~ a4Ct
R.#CT]8
U/qzAj
z3&Vr<5.
z3&Vr<5.
!:#g)w
2DU8\
$CTq1\2
)w0CTA
$]2PF;
:Cd36^R
VU=91|
JR]<*
2.IBR]
$a?UpqP=Q1
!uj&j
j9\B*f
q2D|ZR
"Rq.I6oW
r]2D;.GH
G1}hW
5L=w.C
3D=jo"xIE
r-3D;.GH
P1@{j(
3D=jW3
$)G;CT
e3Dg)7R
vyLI\_
'hG0%'h
6U4LIx
6?cJNv
_H9V3D
]ORe`J*
i0_e`J ~
aJ&l3
VUe2m?
i7/SR1
*LCzHg
:0S2Ue
*0CR=L
LU\dHH
A`p7n=
Gz'/"D
jx0I8!s
5DgyBv
8m?VWE
h*nBLR
h*nBLR
h*nBLR
nYOB?x
I ^mT}
SJ9Z2D
RORqYO
*LCzV&
hX}ZORMp
I*X0I`
)|4H>_~H
L0IUL0
LBO>O
cv_Fu3XO
$Uk=IE
0(I`pB
G1}hW
G1}hW
olB pr
L8"n[]V
Y0I8!t
0(I nB
fx=IHR_
ZdJ*0SR
#Ut2$y
~^%Ct\
~^%Ctd;sa
~^%Ct|
~^%Ct|
!:^v&a
>g>FT}
/Q{7/S
c8CB?x
^qb%h[
*CT=aJR
OZlR~[G
*LCzV'
7JRaiH
7JRaiH?
7JRaiHO
lpZ%aO
1AdK/,b
eoM/>1
G1}hW
_S'UT0
nUU<^f0
mpKPl7
N85xdxL
n^hI\_]
nq+0X=w
>gST}
;6\%X5C
ruA-RG
R1P1PqQ
&a~`{
usU$a~8
O3nX5C
7Jr</J
G[oX5C
yDLQ5C
RGR Ut
pSu)VRm
3VBri
>__.z~
kBKR5C
{~7uAr|
{7uAr4[
{~7uAr<
)z~7uAr
{7uArd
].z~7uAr|
+PCz&9
;^A%X5C
B%X5C
3Z$X5C
3wLQ5C
)l\I~{
1N&X~7F
7vI`8pV
b%@kUl
$p9pyu8
7Jr\i|
;BD'X5C
]~$X5C
>g>FT}
G:&X5C
G:&X5C
u1&X5C
y_|Q5C
[U5#Cf0
I6?cJN
~tO?x<`
J*jT25
G1}hW
G1}hW
Ztd;sa
-:>g&a
>O<FT}
c%;Vc%
0Hv+i
P~jh0O
aO{9Up
"&9[HS
3 nW[C O{9~
dj($)w
*:[Hy~
&9[H=?
}@'SCL
1Up$ _
`O{9U0
UD{94~
~@dj($
v"t 0<
d!%~?~
9POzB'
3pc@X-
y\~jhp;5
j5!`;5
P+"SC!A
&i5}c4F
c4Fc4F
h/Cr):
A[:CCa
Ay:CCa
M _0pB
454|v*z(
jM,:#:
za~jh0
Egh(lg
;\}W M
za~jh0
OS|2U0$g
@,:CCa;
@SC,:CCa;
T4z{;_
@C,:#:
Oa~jh0
Egh(Dg
S,:CC!
,:CC!z@p
Egh(Dm
OS|2U0$g
SC,:CC
C,:CCaF;
<$@{($|
@,:CCa;
C,:C!j?
v=H'oo
v=H'oo
Egh(DS
{,:CC!
3l!Ig,:
{C,:CC!j
C,:CC!j?
S?5Dp
n_IL>j
wO}W`x
Jg|2U0$g
pz/W/W
OS|2U0$g
l3PF{j
{C,:CC
@SC,:CCa;
C,:CCa;
{C,:CC!j
,:CC!j
3l!Ig,:
{C,:CC!j
C,:CC!j?
SC,:CCa
C,:CCa
Jg|2U0$g
OS|2U0$g
=`(@2PF{o
N2PF{j
{C,:CC
Egh(@2PF
@,:CCaF;
C,:CCaF;
KC,:CCaF;
<$@~($|
@SC,:CCa;
C,:CCa;
,:CC!j
v=H'oo
v=H'oo
ABm 0U
L`pDg60
v=H'oo
v=H'oo
C!z@p
wq I~jh0_o
3l!Ig,:
Bg,:CC!:#8
BS,:CC!
B{,:CC!
C,:CCa
C,:CC!j
SC,:CCa
C,:CCa
KO!9[@
OS|2U0$g
'{C,:CC
=ukF{j
KC,:CC
SC,:CC
N2PF{j
@{C,:CCaF;
Egh(DS
@SC,:CCa;
C,:CCa;
C,:C!j?
{C,:C!j
v=H'oo
G@`Dg6
v=H'oo
3l!Ig,:
O!I{,:
c.0<E6
Egh(Dg
S,:CC!
,:CC!z@p
C,:CCa
Bg,:CC!:#8
BS,:CC!
B{,:CC!
C,:CCa
3l!Ig,:
Egh(Dm
Egh(L=
Egh(L}
PH.,`8
PH.,`8
l3PF{j
SC,:CC
KC,:CC
g,:CC!:#8
{,:CC!
zC,:CCa;
C,:CCa;
yHNP{o
Egh(Dm
v=H'oo
v=H'oo
v=H'oo
oqC,:@
~%1w3}%
45RU7F
b9FB?x
[/W/Waj
&I;zhIH
O;zhIH
@;Z~KR
b[E)=zt
KzZ[ U
_H=:;k
EZEUcc$
qZEq)W
VQjscl
D"|R]8$
X5O{954
rK{9454
8Itkl[
M;6c$g#
KN*\~K
oI`U`U
O;6c$g#
rj!L;6c$g#}
L;6c$g#
%q'@k5
#S55Fr
#I;6c$g#
M;6c$iW
paj<42
/`L &p
H~UPc$qU
c3Fr6R
c3Fr6R
c$}u>F
$?Upp*.
ac$C|5
f}~"cG
3Dv3#
@OakH'|
c$@`o(
FLakH'|
+c$a?U
9_~)Jgw
LUcc$|
gl3N*v
KNNNv
Ca~jh0
O5CR61g
9ZZE;:
fAooc
dxtgDg60
{,W1`;
'@`(pB
3h=5[/0
ab;`(0
>Ac;`(
ab;`(0
P]Vnc;`(
@yrFh/3HF~W
Bra!st6
mAHdj($o
mg 2Dg0
yk}Z/$_
P`80|*:0
<?<z=H|
]OUMg=
9`(0/py
$L}\[
PlA vh(0.0.
8}h(0.0.
ch(0.0.
DQoC@k
3Hdj($o
Hd;Ru>F
MBO>7ND
m6z0?U0.?
QEsHRe
5L=7= J
~j$n0 J
IS,:Ca
!c6@ta
m\]G[
+6c$g#
Un=p[
KB6?~I
N[nuFm
J;6c$g#
)7/ :#
~%a";v_
Sn^@Dv
`_I\~o
K;6c$g#
" .7/
$@\n^@
.7/
~UPc$/
6?~I>7
~%a";v_
A nj<42
L9n@tF
L9n@Dv?
C*WH`w
$L9n@Dv
^Ovq_IL>
,:@~h(
K,:@~h(
&9[h=~
C*WH`w
42U'1%|
c$}u>F
@1%@;@
+6c$g#
K;6c$g#
1%@~3nLI
H^l#Sn
N[nuFm
}%!fOvq_IL>
vc}%a"
f1%|5
ubJ2PF{GkLIF;e
cJR{GkL
+6c$g#
$A*WH`7
&9[h=^
D1%@>0
D1%@\= n7
+6c$g#
vY}%S?
)7c@Dv
D@;7c@
-I;6c$iW
o{Cq'SC
)lCCaz@p
'os@{w
%@+@r+
$aOv3\.!
a@Dv,.
+6c$g#
^zP|*:
#Sn> ";..
c$}u>F
L;6c$g#
c3Fr6R
+6c$g#1
?yp~2u
^zP|*:
)w1 B/H
;Z~KRz
}0t2T<
h?XXy[o(
c$}u>F
EQl;;H~S
Yqf?U<
+6c$g#1
c3Fr6R\
b3Fr6R
#I;6c$g#
c3Fr6R
#I;6c$g#
U%$OvYV
7N~WpU
v1~%a"
w1~%qd
b3Fr6R
WPc$q}
c3Fr6R
#I;6c$g#
DvYUB
+anOv3ZUr
$?|hp;5
_Xy{a(
WPc$q}
c3Fr6R
L;6c$g#
L;6c$g#
+6c$g#1
L;6c$g#
^zP|*:
W5:F2XE
K;6c$g#1O*
c$}u>F
]1|IOv?
/2U<?U|
oq;Z~KRz
c3Fr6R
WPc$q}
c3Fr6R
c$}u>F
pz1P{"
N[rk\[
7IzP|w
0wo$[
0wo$[
\4\Dv{$ds
c$}u>F
+6c$g#
+6c$g#1
'SC!y;Y
]f$$Ov
]f$$Ov
]f$$Ov
b>HH:+
]1$$M
]1$$M
.";v$d
ff$|`/
$@>@oO
WPc$q}
c3Fr6R
c3Fr6R\
WPc$q}
c3Fr6R
7 $|~
N[nuFm
za~jh0
,:az;a
C@~h(
O!I{,:S
$@+@r
-I;6c$iW
Eg,:Ca:#8
Pgh(Lo
)@v3}%
BHRu>F
H;6c$!
@~WAHv
p $@{3
M/I=wvp
#~O?x\=3a
@O?x\=3a
ozIO?x
Sn pQ_
UdH?<}n
?}~,\T
zW?%C25
N.<})u
P+"SC!A
ho(]8o
jMdj($
P+"SC!A
a"g;&HB
Pk"SC!I
a"g;0HB
Pk"SC!I
jEdj($h
.:[8K9
d0UA I
IRn2 :
NE/!go
jRWUWUWUWU
uU5TWUCuU5
h*nBLR
Hvt[%|
Box6.n
D'@{W[
HtrvB{
#!SC!I
GB{IvX
I>RcT`
BK .l!.mw
wt[%)W
dW6HvA
7d#D|5
r3!z;
*I=w<#D
]H9t&:
pz'P7D
Pg~k7ik
D)wv&J9
!J9lg
Box6.;
tI9lg"
@pR.r&J
5BD{Y=
D|6)7.z
K~MU8o
WeEeEeEeE
zk}{T=
@8"08"
0P~M?}
~#)7.z{
!?Kz{T
t!SC!I
.C/I)w}&
=zc~Ho
Lt:[O{
L]H9lg
qgz&Jg
|/qz'oUMo
wy&JoS
$)7.z
.)7.z
}&J9vg
Antivirus Signature
Bkav W64.AIDetectMalware
Lionic Clean
tehtris Clean
ClamAV Clean
CMC Clean
CAT-QuickHeal Clean
Skyhigh Clean
ALYac Trojan.GenericKD.73272252
Cylance Unsafe
Zillya Clean
Sangfor Clean
K7AntiVirus Clean
Alibaba Clean
K7GW Trojan ( 005b7a591 )
Cybereason Clean
huorong Clean
Baidu Clean
VirIT Clean
Paloalto Clean
Symantec Clean
Elastic malicious (high confidence)
ESET-NOD32 a variant of Win64/Agent.EBC
APEX Malicious
Avast Win64:MalwareX-gen [Trj]
Cynet Malicious (score: 100)
Kaspersky Trojan.MSIL.Quasar.crf
BitDefender Trojan.GenericKD.73272252
NANO-Antivirus Clean
ViRobot Clean
MicroWorld-eScan Trojan.GenericKD.73272252
Tencent Malware.Win32.Gencirc.1411c606
TACHYON Clean
Sophos Clean
F-Secure Trojan.TR/Agent.pmtbl
DrWeb Clean
VIPRE Trojan.GenericKD.73272252
TrendMicro TROJ_GEN.R014C0XGQ24
McAfeeD Clean
Trapmine suspicious.low.ml.score
FireEye Generic.mg.81e9262f4a1fb09c
Emsisoft Trojan.GenericKD.73272252 (B)
Ikarus Trojan.Win64.Agent
GData Trojan.GenericKD.73272252
Jiangmin Clean
Webroot Clean
Varist W64/ABTrojan.OSWN-2006
Avira TR/Agent.pmtbl
Antiy-AVL Trojan/Win64.Agent
Kingsoft Clean
Gridinsoft Clean
Xcitium Clean
Arcabit Trojan.Generic.D45E0BBC
SUPERAntiSpyware Clean
ZoneAlarm Trojan.MSIL.Quasar.crf
Microsoft Program:Win32/Wacapew.C!ml
Google Detected
AhnLab-V3 Clean
Acronis Clean
McAfee Artemis!81E9262F4A1F
MAX malware (ai score=82)
VBA32 Clean
Malwarebytes Clean
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Rising Trojan.Agent!8.B1E (CLOUD)
Yandex Clean
SentinelOne Clean
MaxSecure Trojan.Malware.8426628.susgen
Fortinet W64/Agent.EBC!tr
BitDefenderTheta Clean
AVG Win64:MalwareX-gen [Trj]
DeepInstinct MALICIOUS
CrowdStrike win/malicious_confidence_90% (W)
alibabacloud Clean
No IRMA results available.