Static | ZeroBOX

PE Compile Time

2024-03-31 08:53:28

PE Imphash

f12d8b251be05e4edfe87a7ba231b1f4

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
UPX0 0x00001000 0x00096000 0x00000000 0.0
UPX1 0x00097000 0x00063000 0x00062800 7.93291200855
.rsrc 0x000fa000 0x0000e000 0x0000da00 4.76166975915

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x00106b84 0x00000468 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED GLS_BINARY_LSB_FIRST
RT_ICON 0x00106b84 0x00000468 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED GLS_BINARY_LSB_FIRST
RT_ICON 0x00106b84 0x00000468 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED GLS_BINARY_LSB_FIRST
RT_ICON 0x00106b84 0x00000468 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED GLS_BINARY_LSB_FIRST
RT_ICON 0x00106b84 0x00000468 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED GLS_BINARY_LSB_FIRST
RT_ICON 0x00106b84 0x00000468 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED GLS_BINARY_LSB_FIRST
RT_ICON 0x00106b84 0x00000468 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED GLS_BINARY_LSB_FIRST
RT_ICON 0x00106b84 0x00000468 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED GLS_BINARY_LSB_FIRST
RT_GROUP_ICON 0x00106ff0 0x00000076 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_VERSION 0x0010706c 0x00000350 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_MANIFEST 0x001073c0 0x000002d2 LANG_ENGLISH SUBLANG_ENGLISH_US XML 1.0 document, UTF-8 Unicode (with BOM) text, with very long lines, with CRLF line terminators

Imports

Library ADVAPI32.dll:
0x140107770 CryptEncrypt
Library COMCTL32.dll:
0x140107780 ImageList_Create
Library CRYPT32.dll:
0x140107790 CertOpenStore
Library GDI32.dll:
0x1401077a0 DeleteDC
Library gdiplus.dll:
0x1401077b0 GdipFree
Library KERNEL32.DLL:
0x1401077c0 LoadLibraryA
0x1401077c8 ExitProcess
0x1401077d0 GetProcAddress
0x1401077d8 VirtualProtect
Library ole32.dll:
0x1401077e8 CoUninitialize
Library USER32.dll:
0x1401077f8 GetDC
Library WLDAP32.dll:
0x140107808 None
Library WS2_32.dll:
0x140107818 WSAGetLastError

!This program cannot be run in DOS mode.
.RichS
:Tnrl$
t& E+z
HGEG;W"
+u_/$X
eX~m+v
O8@9_%
8[Hj@7
USVWATAVAW
A_A^A\_^[]
2]4m^rs
fD9,Gu
]'FXk
whS$W$
#1<@.222@HP),
$HP(J{
K}~^PM
h7PP88
K161<|
'|_zT<
8qM@k>
UPY"Su,
I/K2!Hgu
@@M322HPX``
*6(1{v/
X/BWxY
PA ,-H=pP
#"SSC8
XsXmX<
!+FXBX.X
$'JU6U*U.y
:9sHLy
*9rbD9D#D
14a4a9
+#Cx$
!'~?r?B?
j6~6r6
v j : y
xq`5ha
}$3>cH9J
jD8)teH
LU)F$$
,/.f?Z
0(aK@p
^8>E8,
+`|xdOW@%
uE9h(uap2L
p nIS-ap
``1JXt
9@HpBf
HpKI9p
t`y>Zl
2#CyEa)
laHc"<
*[O!T`Uh
)8QH@\
{w/K%O
h`Y(Mi
spA@H>J<
,taca"!_
cJ\]k,
i&i@'H
98nB(}g
$##hx@#
C{ED{?
'5 oyMQ
9`2A,
C@Nbye
HMVk_P
9`WD9C[
(008u
lTY66RP
ZnP@6h
tEJ0M/d
s04^n>
S8H,5L
0JXApx3
Iy3y$'y9-y.y
^xqi%@
.u+`5R>e>N
& }8K(
@~H?I(
_!@5vcFu
l96N~+
vC]lipT
f98u$K
(p$_\?\
C@!}f@^
yb$-9r
[X$_`$'
R"_=I}
l"=M:i
C&yz<<<
}9HL3 A
P,: o?
<miN(~|
_*^pb6K
Z%kh?+
9{ |X;
PqD}su
[aRW:0
$V5NMG8
ER9tXzX
]iC^oH
M!PL^]G
;Q(u0.
QEQ4[Z-I
ft"tp4
)),(I_
A"0r7I
K~XDXU
"6N%lR
y&9CFv<
=7n?y8
=; P L
T}=Ee}8N0
-:x0B[)
IE8EHe
,N`>D
LI_pZJ
V<{ZsCP
LpqrsY
]M\/A_
E;h;Q~
$ZRsh~
1 /cEG
u&zUP};
;^GhM
LxIZv:@
D"+ya4
dlhbz#g
)ac]Pq
M9WPt(
?H9txu
^h ZhC
[_.c5@"P
sw(4/&
+/?"q,`_
bDX@{P~({
4M@KHC@K4M
4HC@KH
l+?~\x
LMxO"z
4N$N@8"Pu
Dp)`C(<
S@`mjh
T#I@Ih8
B!=XG0H
Qfrdvy6:/
B.dyvq
ydh'v"
xKgTD/
v^J.,o]
D@8*u?P
4)>\Kp
J+Vs0%;
 S!"~
m#$a%&'
(S)*S+
/012394S5
:;<'S=>?@ABCDEF
GH7ISJKL
&K'()y*+
,H/K0
3456]k's
K;+<=X
LwKuY|O
LOPU#l-'
Tyoy"X
cu(H0AN
F_FVY;4
w{*a{vt
%h[U"k
`eQyCp?p
jIcla{0
Nh`^EXA
"H=Rv.H
oj9YPkDzM
!&z=X
5?t.*B(?
WOJx*G
S,NGe,[t
cp'BHK
g<2`(bK
>/j4u6A8
~ztQ16
H?inr&
k8$cKM
Hy4`u
^ TC4<
YQ:@@c9I
At$Nu>'wq<
7E8-3,
39`0t&D
`/u@cg
St*7bm
C9JEo-X
!gZq"!jb
t/7&Ev
{EL7A#
9B(~=jB i
NiVt>X
Y/P{J^
@8CPP*
Xu7 %
y&}u_dIX
22!zHX
h|Vp]{lu"sT
4.2%^
Tu WvP:
<.< mf C
P)8MK*
YYZZJ\B\
@7=XW
]"]Z_f
p9B\*O\
0t2[(hN.
w?0"pijP"
Udp"vP
+ju|DN
@s_hpl
f~x4@arj
H@`-Hp%
L\6?y4
wB%u&T
V42-le|
YJ;T09p
@1@PXRy*
%/5aU;
n"-30|\
4nsF^-
L0~tBr
s>GUMxjZ
ts y
Z#M5JK8
2H(Oh0
$t#hA&
zaX_YX-H
>%%ZHY
,a@A-
AZ:gP_
]bB9jK
Bj:a@5
T@@0D;
%QCJOi
S# #M"
yt&7b+
`G0paI
'[HP:3
xPTy U
`XKF*#
E0v4$
|!q\Mpp
pW"_^/{
A[!'^@
|~pe$4
.P:b.u
OruYlVX
i,=RY^8
Ep*,x\A
`{V?%F=
9P72`{Da
\2RO8HpF.
8ayBpB
u5AMbb%
:zJAdN
\tPxZM
W%?MjT
5H!=3'T
)>EG^8
t_8g!
`Db@}J>
[1nFKR1lZ
jR&lT
7w(i5H#3
sJN90R8
V&Yybh<
zd{ }K
X<\w"=5
tSl4x<
pO-,uq
7Y,DO(
Dtrum8Z\
A*PP`c
fK9`p8
?5:Di`
m,D)(L
;6sH<S
%u EBL
0^|tDB
w&m#)R
8EX|z.A
hSxPx/O
(('@V6
ml#3>k
J{4&8Z7
F]t}A+
)$l"Cp
[C@"c^
g@Xi#E8
B5<.>=l
NChCPv
Fm$n]Q
,D&LDKe6
_epCs>6
sAX0Y(O
0A@Et
`DI-R\
QPz1)QK
->>Noac
'iEUgt}
\8e9bv
CFapUS
G>TjP?
/2P |M
(|B~{l
&'NPw5
,80++gO#
,E(/N)
Bbq^%j
aCMqwH
y{?L9Bl
GUTF;E
6t&i$LE
a6fCKnu0
=q/SNS\
=!t&k4
Xal(
)}Za ,}Y.=L
4yH2IcD
:+2*t
SA@Zrp
lAtjdu,A
p:\Y;
8%?*UX
(N+T]$
6\ 5hs
S8Xq_Dw
98!ppK\
jU!~CI
sIwQ69
+A+m)N
Hc/H0R!
~xijH^
(hj'kc
unknowno=
#7`zFv
!"XC-T!)
u5yo_qf
w3`f3$9
f@c!\L
6@^3pP
/HDj`
.aMw$&
!CpHI&
uA`V0{A
http/1.1
I} S S
a3m%H6
`(2ZyU
m;+.bI;
,cx0R
*84Gv^
c(d3P^
&[~7:Aq
7}SL@$
:H@SQu
zRPd"e
S4_)R%
<z@ia"
|aL`c<YHL
(wX0B$
"mF(j()
r&6PREAu
bp/>%B
K!t@Zu
"mo_egXE<
06xU1M
T.61,
;/t'[
D3l:?5
tfxPSu
A@K%AHb
|\-4XX
F/Sri>
OGINDIS
STARTT
v7AUTH
I"/W&y$
<{tBkJ(
VGiAPe
ID%8M
(&'`\e
\VqHAkI/
;|)t#=
u;crRb
`7V|-|
y\D*EJD@>WyZ
s\F#w12
6"bV19
/8J]L_
<V1e=EjA(
b`33?+Y
TQrnaeB
`}\"4
$<-uqA
Bx{S#ts
(i881p
MTPUTF8
44L|#YN|
mHiC9p
Nw!^WY
OR#CEZ
_XB)i"k
pwswrU=
X.y$\/n
;t3|h?
G>Eb3*
FGrIJu
TurYcmX
HqfwlgKV
]6'Z?&[u,Wfc
Tp+42u
%p,1*8
mIPE_h
8'0+7F
~Gd] k]
@!P}f8e
.5PJ8C
Vr'J8Oir
K0[u)bU
A84E<I{
ND2ItK
;emp,Q
)hy$ &
9,I3u9
Y.>|p.
8XWindows
,.!p@[
!8D<36
t;E] B
!1Y&Gp
QxtklE
d!8d43.
}cDHA
E<tfLE
gs?^~
e|{#4N
jA0BA0
H27Fp
LQ_>(O{H
Xty$ML
6zS9YK
#'oxU
CBI[L$y
=SnA0O
]KQWcR
E 'il%
<.u]9>
"%9{8v5c
H*[LQO
:uI/tTa
G&.u+a
xj #tL]
"HxNuG&
JYQ{8]-
itNK#h
t0 +n(
3b</!k
Hmu\d
S\Ry.HpTP
Ho%OGy
12M|y*
Ku,_Wd
B8``a30H
-U#a %
s`pm+S
\2+7 9t
Rr''''
'3?KW<
,=h#$~()]%
3hhBN M
]R/AlC
6$.w?i
%)w5a>1'$A+
<%,8X9(
;Y9yH{
i(*T0^
J!|htb
zoYY8J
N< .!m
sx})u`
wp7LcG
G0XLw`F*
?w%-leG
r.|!">
f_w;YL,f
%V7^Py'
+C&->$m
8-Oi<.@t4H
mNp[Q]
U<xk!z,
A%\ZB:/t\
<EaqaJ
qTWvF'.
-KRo"n
;5<SN4A
><i!o"-@.
nXjX#@
Yy9(;LB<Bx
t +ck
jlL@p5
C*)[mr
\=O?L?_m
XhNp+MwP
$<TE
d'q0^|1
&Pl|^_=]
nMZ|]%4
}r3n3x1
2*9 G/`\[
={@=y!=
oIx&P`*
`TR&ZJ
"<XF\F
s7;ab5
2u<qMf:.d
+GCVZ4
*Eo_0 Z
a81@AD4
z`P.\{
v,(&l!
L9hh]*@YhB
`,\`80
NX!+L9e
R B!Yq;6t
w~PC"mW
D83L&8w
hN(eaQ'
eTa5`!)
U![yoy&
p1L0PPf
Q:Xuo Q
4K.olC
u5K_1o
1m}X|/0
8t.ug!
JpX$q\#
uEtfP@
RG$qK-c
Genut\3
>mhuP(K
x@taE|X
/};XXs
yxXu5P
|wnhp
:HvK$Gf;
@"s$sR=
H060Mi
Y@a`.r
!dddvL
&_&_kpkp'_!_
a0.J@MP`pC
}I@OP`p
$.pI`1P
(P@0 J)
Pp3?r_
|u%I71c
u7EJ^u
WR!al>*
jI+)mf
;gti^td2
J+N9_>
%|=%,v
gH@:PB
P"b*i<
D}<{r2
M4aD;Kc\O(
rh$ Qv_D
vZoR=`
mHLd(&g
wPd`'Ho
c(u!db
99~C c
7>5`.>
D]D((c
eZ|@BW
/hj1%Wt
7*W4H
r\`rs'd9
R9h_lpR9
(7_&p%
1y10:k
FV0U0.
x61bYK
1&utJ\
Bfjd8E|
%'#JB
@j) <9
^*'H4H
h0a;Eb
J%/=gH
M9s 0t
mwV5`l
jdL4h=
c4S'&S
fAJxUd
!e$^#A
T(Bo1%
y'lpR9
o3.PTX
|'l-2'5
*P0R+qE
LMrU2!IL GrAMI
nu,*f\0'
O<C:fv
:<htl<jt\<lt4<tF<wt
A=_AN_
~674u.
:Zr*VN
[q!!E'[
F@w!,I<%w
0%nkxP
(XlgIc
K\LpPXqT
daDx"P
dEPD8f
}vLc{?
F=XP\'
%<UO)x
/04+B8|
"q,7Y%(
KtbCVS2r2
99v%A
<@>;@u
Xt9Z-W_96
w_W$X|a
^Z9KcJ
Q2c:u0
JzcCB@
>u:D(9yt
[O2BnR
2QR:a@A@P
Et:+$m
&^T.+02q
46(4lW9
X. wz:
hPI6Kr]t
VYdxB,
pSRkE`
jX'_g@^
'.5cP
sd3z69$
#hV,"'
y$D8r(
F1uUL9r
sKB6!SH
X?<u*s
4Ib:(-
"PDN!J
Y`x*JZ
i>C"JQX_y
pt (0: C
8:i}@<
m8*Oa@<
dhR{[E
R8Oi&~lP
PE%Lc/
q!'05|
WhW;D:
B9<I}1
%H+Rl8
T@Bdd.
`d)$[K&.
<eMOKz&.
0_4J+u
#VXv\u
5|3#lf]
qxS@29r
GsU-L
9<M3Ni
*tcszCIs
A^T08(
$;h%K_)
p08Qut
{r"jm5
p tq:x
|>;]}y}
AqJq8J
Ej@e`tY0
j8@?00A0n
n~7#m5
i)DZAM
L*@k7`
mGRmm3
WIe=dh
`VeG/u
9 t#Io5
":uq&
!Gm<lXA
oE$(+n
f_ZUH.
i\B?.;
HN&i|o
EtP~/{K
fb8ZZ#
BAQkHo
4xWI96tR
ImJP``@'
sp`xVi
HJh1y
;$@,q U
fE$,=p
oL:4YE
Fh<o7FR
?MT3>)2
X{~v8
IK2v[:
$wF:y*
ICdA,3
K}NLxR{Q#w
rI.X%b
WVc%!
T-C/-;
M~T"bM
H{H}UnB`Mu
I(|l{C@M=
x>u-=
;Vs^q$QtL
.UE9TG
)q/|b(
u#sZ!#Z
-mCXb%
i6BHUJv
mDomYF
a*:Roi
%h2XB/Ye
^`xX%@
"0aDRM
y/8E:#
pt#Jt*D2
8LQO LcA|
E2LNJC
;Z^&fL
u,?zE
___Et!
-J[??@H
_a)v!
b?4\@a
_?bX1
];B?2?[[
H?hX!/
y_?[B^
(KS[M_
|_```$
q`%SX
]KBL}U
K+x N*
@Bg938
(m999>Rd
d"<Tfm{2
xl9999bP<,
n''''bR<
N9999@*
&NNNN2>P`ONNNn
o/(oD
rrrr`t
hJ;999>(
oF:\vcpkg
ldtrees\curl\src\e5cd7b45
748466.clean\lib>asy
socket cb:
%d REMOVED_
dOUINOUPD
[{ADDK
call e_
multi_Y_ac
on(u)A
toptbALL
SpTLOA:S
oH-Cookie:
FGHIJKLMNOPQRST
efghijklmn
uvwxyz
?image/!.jpg
-d{!.sv +xml
~&htm]/
pd?Rhi
quod-p
Can't ad
a subp|t
; bound
D6posiO
sfer-Encodi
form-@Lo
.oResolv
_lDNS cxeQ
9_"4$0
!%4095[^;
%zu +b|v
,>RUEALSE
Pc9AddKC
Lw}! E
WARNING:
d\bufT
via.URLOPT
.)_MAX
PUBLIC KEY)
ha256/
3(E?;a
2{r;((#
Too;/(W
0suppXt
-Se &if
VghcMe.
P@WAIT
ROXYUs
CxAMO;
RFC 6874
)[fPA
SO_KEEu
Ape&
Q.Uo/o
TCP_NOD
eeB@$
wRhlpapi.d
[^"]"5u_2s
CMEM[+(
n[kStc,
RECV-O
yNFj%
yW un[
~1.2.11
$@?vTR@
?ONNECTF=
\BpZdOOG
dp@d:%W9D
-s8a%B
J8"sXO
8B2% h
^lQhq-{L
~ ! S/s
e/Unm3La
v?o0fWo
U`@1#@
. AsH-
>x$G0417Y
O{Z\%3
.3^!h*
C1DX$}i@['.Q
GSS-API
xxti75p$
2`?_1!
\`dhGMU
}pWA/<A
C/hCDGM/
wFE/EE
\U V<m
2W@Thufri
atN.Jo
ebv6pr
f`g&/ul
1.3a$A
LG_MDr!
ACRSAFIGNDZ
_112A_X
H$Fl#
?AGREEDB
NYOHUR
_CYLIN
K,_SL3
<ENPCT1
CPRF?nh
LLE_OWF
GroNZb
thmJtcyw0
Acqu<!+0
=c<dB'a
piXdA!
_ERROR[
_R)0F
~}1_\if
RA)=-_
DILIT8
XAMIN:
pismse
a~Tbol[
IBODY
o[. aOK [X
m0POP3
RCPT TO:
&f=?&h
421 -!Gf
'w?. D
7 ^PBSZAC
M<OS/4
I^NAMEF
>OUNC
)SRB`]
aPc)_d
6LOOKUP,
jvT?.
(8NNNNHXhxNNNN
$''''(,48''''<@DH''''LPT\
'''dhpBt
&GO A)(
;TI& M
HTSFFPNNf/VVL
_T^ASCII
3270jGI4
df>1':
UE!)&(
d8,; Height3
,1`[^@
w8ascii
_hr,iq
)a{q4ap
[%*45[
:.](O!6m1
-*oqL>(
Zji[N~
s8`hzc
K)Dh]o
d?,HE#(K
x)/u0J
ITHM_MIS/]?,
UFF^TOO
|ST+/P
VLD/UNKhWN/co
G:SAGE/-03
5?xCs/Fj
POdCY/
T;ZmtB
&>C?)h
V1/U Ic
I|S4U"
=uhP>?TG4
/QOP(G\
@Uj?Na/
[usuY/
#(e.g.
'rcm_0X
`%?<l-
B_#KKm
D\j/nQ
q(s)uoN*&0
72.5.29.17/
/.o_ob
sk:9x(4
$(NNNN@PhxNNNN
''''0H`x''''
rrrr (08rrrr@P\`rrrrlp|
 0HrrrrXp
0H''''`h
H_2pnb163v
i_FK/6n
k;;/2,
rO5eUCH5
8tOh1S
TF :9r
v*u%uisU
NNqg/n_
DG_%!
tMoI TK
kZrRe&Zu4
_ #9!'
!``MK^ftvm
wift_1
r!3ptr64
~^V|X|
udtmM`EH
wO+xL=?
F%jT?/
H|VSqEx
NNCPgR/S
k#d8L2
~ $s%r
@b;zO]
m5'/_{ta
=_nt7Nxn
s>d"b.e
Uc&db
0P9999h
pulqXM?p
W$_ap#r
$0''''@HXd&'''hp
(@Prrrrhpx
0@''''Xh
M/dd/y
05HH:mm:;
*9dB( J
?@m[\*
]^_`?{|}~
fnl24X%
7V/r7w
?tApisANSI
LCMap;d
`{8ToFID
(C0D9!'
8F@GHIBN
r`NhON
rBN0!@"P
H7X89!'
9!@JPK
rBN`LpN
ws?dn
pp_*r{o
.fokjo
XcEhK
Lu*U
TO?Ktc
FhoIm8
u?^Zyp
]lr?pH
6onC/E
[/NE/L
"/HOhBf
boW?C_
k!? cvb
8!'@}P
?(OrBN
hYO'vb
Zhdb
wbkb &
dym?.d
`[pb_
5~l?c!
x:i!
#Ib?3]
VM>cQ6
>jtm}S
BC.6t9^
kE?M>`~
hrr;9x
//crc<
#j<+e?
[-&LMb#{'
w+OQvr
ZEo^m/
H*0"DW
IiGM>nw
ewh/?y
\nNJd
995-i'
Gn'Bt`
y31329
|'8nO}`
8056167_
{N^NDL
6?M"5/
o3a.o*O+
8O?POI
x<P:N:
L v*Mo
wDO%J1
G?Mwr^r"
^0/J_tT
X'?iZ'
SR>/p
i)9999
BNN.}=
c?#WM{'
rrr!k+
i*F!1A
.B&B0X.B.B
"V)z}<
}@ AF|
y*6@MZ
P'CvX0
voltmd
0>4v$O
>|r@01
#>d!9$/y
v@i i0
FWl'E'
b N"$$8&
4d66@<8>
\,^8`bbNd$f
h8jblNn$p
r8tbvNx
UY]aeM
4Mimquy}7M
:(<J>8@
ge(V.t}
W72xm7`
rH7$ ?)
rbt\v$x
Q0C$C&
<p>N@$B8D8Fb
HNJ$L*N8PbRN
X8Zb\N^$`*b8dbfNh$j*
v x>z0|
\FZ8>\<
<@td~9(
."<$.&
(.*.xz0N
.:.<.>
l4Slg
$W@~nF
<7mn00
C<OS6\
-X{ko
T4R:]X
o*]bm
f=n<'V
^]VoeIW
.+<hD1N
BG51jZ
idWbvnv
oWbms
$K(-8
4;b]C,
w70/.*
74<S9Z
M@h'e_
Rdg`?&
6V^W6^
g"|#
)m[?oS
eVJh>a"
$|Gfrv
/=tMt{
0WKJH31eC
v%S8>w
@P`xSL
k;_@*@b%
m@nvnn
`vk t'
DO?'^w
lFZY@Zv
<O0oPp
t0uYu#
xGyyw{.o{f;
zHeapI
U4Nex>
u+iBoE
OME8fM
JkAdPi
"A:d'R
y!Zsh#
%nR,oS
OIkSZ
`@xrsQ+E
eR$O;<
(]_^[H
keu|hdp
Z"6|fs
9e)~G
G,X):
HJ"Hge
}T4PbA
v ~CGU
]IV.KuIv7b
J42f};
QyMH"3U
yWfuR(
E&}}y'
VY0k]c {#w
pxx swy
pxx twy
pxx twy
rxx`swy
rxx`swy
sv{_twy
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0"><assemblyIdentity name="XP style" processorArchitecture="amd64" version="1.0.0.0" type="win32"></assemblyIdentity><dependency><dependentAssembly><assemblyIdentity type="win32" name="Microsoft.Windows.Common-Controls" version="6.0.0.0" processorArchitecture="amd64" publicKeyToken="6595b64144ccf1df" language="*"></assemblyIdentity></dependentAssembly></dependency><trustInfo xmlns="urn:schemas-microsoft-com:asm.v3"><security><requestedPrivileges><requestedExecutionLevel level="asInvoker" uiAccess="false"></requestedExecutionLevel></requestedPrivileges></security></trustInfo></assembly>
ADVAPI32.dll
COMCTL32.dll
CRYPT32.dll
GDI32.dll
gdiplus.dll
KERNEL32.DLL
ole32.dll
USER32.dll
WLDAP32.dll
WS2_32.dll
CryptEncrypt
ImageList_Create
CertOpenStore
DeleteDC
GdipFree
ExitProcess
GetProcAddress
LoadLibraryA
VirtualProtect
CoUninitialize
VS_VERSION_INFO
StringFileInfo
080404B0
CompanyName
Microsoft Corporation
FileDescription
CTF Loader
FileVersion
10.0.19042.4
InternalName
ctfmom
LegalCopyright
(C) Microsoft Corporation. All rights reserved.
OriginalFilename
ctfmom.exe
ProductName
Microsoft(R) Windows(R) Operating System
ProductVersion
10.0.19042.4
VarFileInfo
Translation
Antivirus Signature
Bkav W64.AIDetectMalware
Lionic Trojan.Win32.Reconyc.4!c
tehtris Clean
ClamAV Clean
CMC Clean
CAT-QuickHeal Clean
Skyhigh Clean
ALYac Trojan.GenericKD.72181802
Cylance Unsafe
Zillya Trojan.Fsysna.Win32.66696
Sangfor Trojan.Win32.Reconyc.Vq9f
K7AntiVirus Clean
Alibaba Clean
K7GW Clean
Cybereason malicious.cf0731
Baidu Clean
VirIT Clean
Symantec ML.Attribute.HighConfidence
Elastic malicious (moderate confidence)
ESET-NOD32 a variant of Generik.FWHPHXK
APEX Malicious
Avast Win64:DropperX-gen [Drp]
Cynet Malicious (score: 99)
Kaspersky Trojan.Win32.Reconyc.pofo
BitDefender Trojan.GenericKD.72181802
NANO-Antivirus Clean
ViRobot Clean
MicroWorld-eScan Trojan.GenericKD.72181802
Tencent Malware.Win32.Gencirc.1409c951
Sophos Mal/Generic-S
F-Secure Trojan.TR/Reconyc.thiwi
DrWeb Trojan.Siggen28.118
VIPRE Trojan.GenericKD.72181802
TrendMicro TROJ_GEN.R002C0XD524
McAfeeD ti!847E71DBCD39
Trapmine malicious.moderate.ml.score
FireEye Generic.mg.d161e13cf0731d0b
Emsisoft Trojan.GenericKD.72181802 (B)
Paloalto generic.ml
GData Trojan.GenericKD.72181802
Jiangmin Clean
Webroot Clean
Varist Clean
Avira TR/Reconyc.thiwi
MAX malware (ai score=82)
Antiy-AVL Trojan/Win32.Reconyc
Kingsoft malware.kb.b.789
Gridinsoft Clean
Xcitium Clean
Arcabit Trojan.Generic.D44D682A
SUPERAntiSpyware Clean
ZoneAlarm Trojan.Win32.Reconyc.pofo
Microsoft Trojan:Win32/Casdet!rfn
Google Detected
AhnLab-V3 Downloader/Win.Powershell.C5655683
Acronis Clean
McAfee Clean
TACHYON Clean
VBA32 Clean
Panda Trj/Chgt.AD
Zoner Clean
TrendMicro-HouseCall TROJ_GEN.R002C0XD524
Rising Trojan.Reconyc!8.153 (CLOUD)
Yandex Trojan.Reconyc!3MDrTkzBlgA
Ikarus Trojan.SuspectCRC
MaxSecure Clean
Fortinet W32/PossibleThreat
BitDefenderTheta Clean
AVG Win64:DropperX-gen [Drp]
DeepInstinct MALICIOUS
CrowdStrike win/malicious_confidence_90% (W)
alibabacloud Trojan:Win/Reconyc.pofo
No IRMA results available.