Static | ZeroBOX

PE Compile Time

2024-04-10 10:42:00

PE Imphash

503675ed4e0eeb5c3949bdcfdd2a8fd0

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x0000e384 0x0000e400 6.68144464088
.rdata 0x00010000 0x00004ff6 0x00005000 4.75363964037
.data 0x00015000 0x00096520 0x00094600 7.96822338113
.rsrc 0x000ac000 0x00000338 0x00000400 3.84120456799
.reloc 0x000ad000 0x00000fa0 0x00001000 6.5571808075

Resources

Name Offset Size Language Sub-language File type
RT_VERSION 0x000ac0a0 0x00000114 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_MANIFEST 0x000ac1b8 0x0000017d LANG_ENGLISH SUBLANG_ENGLISH_US XML 1.0 document text

Imports

Library KERNEL32.dll:
0x10010038 GetModuleHandleW
0x1001003c WriteFile
0x10010040 GetWindowsDirectoryW
0x10010044 DeleteFileW
0x1001004c VirtualProtect
0x10010050 GetLastError
0x10010054 GetTickCount64
0x10010058 CreateThread
0x1001005c GetCurrentProcessId
0x10010060 CloseHandle
0x10010064 GetModuleHandleA
0x10010068 DeviceIoControl
0x1001006c GetProcAddress
0x10010070 MultiByteToWideChar
0x10010074 CreateFileW
0x10010078 Sleep
0x1001007c WriteConsoleW
0x10010080 SetStdHandle
0x10010084 GetStringTypeW
0x10010088 LCMapStringW
0x1001008c HeapSize
0x10010090 HeapReAlloc
0x10010094 RtlUnwind
0x10010098 SetFilePointerEx
0x1001009c GetProcessHeap
0x100100a0 GetTickCount
0x100100a4 GetConsoleMode
0x100100a8 GetConsoleCP
0x100100ac OutputDebugStringW
0x100100b0 GetCPInfo
0x100100b4 GetOEMCP
0x100100b8 HeapFree
0x100100bc HeapAlloc
0x100100c0 IsDebuggerPresent
0x100100c8 GetCommandLineA
0x100100cc GetCurrentThreadId
0x100100d0 EncodePointer
0x100100d4 DecodePointer
0x100100d8 ExitProcess
0x100100dc GetModuleHandleExW
0x100100e0 WideCharToMultiByte
0x100100e4 GetStdHandle
0x100100e8 GetModuleFileNameW
0x100100f4 SetLastError
0x100100fc GetCurrentProcess
0x10010100 TerminateProcess
0x10010104 TlsAlloc
0x10010108 TlsGetValue
0x1001010c TlsSetValue
0x10010110 TlsFree
0x10010114 GetStartupInfoW
0x10010118 GetFileType
0x1001011c DeleteCriticalSection
0x10010120 GetModuleFileNameA
0x1001012c GetEnvironmentStringsW
0x10010134 EnterCriticalSection
0x10010138 LeaveCriticalSection
0x1001013c LoadLibraryExW
0x10010140 IsValidCodePage
0x10010144 GetACP
0x10010148 FlushFileBuffers
Library ADVAPI32.dll:
0x10010000 QueryServiceStatusEx
0x10010004 OpenSCManagerW
0x10010008 OpenServiceW
0x1001000c StartServiceW
0x10010010 ChangeServiceConfigW
0x10010014 CreateServiceW
0x10010018 QueryServiceConfigW
0x1001001c CloseServiceHandle
Library SHELL32.dll:
0x10010150 SHGetFolderPathA
Library fwpuclnt.dll:
0x10010174 FwpmFilterEnum0
0x10010178 FwpmEngineOpen0
0x10010180 FwpmEngineClose0
0x10010184 FwpmFreeMemory0
0x10010188 FwpmFilterDeleteById0
0x1001018c FwpmCalloutEnum0
Library CRYPT32.dll:
0x10010024 CertOpenStore
Library WS2_32.dll:
0x10010158 gethostbyname
0x1001015c WSACleanup
0x10010160 WSAStartup
0x10010164 gethostname
Library IPHLPAPI.DLL:
0x10010030 GetAdaptersInfo

!This program cannot be run in DOS mode.
`.rdata
@.data
@.reloc
D$(j@P
D$$PhX%"
F j Pj
RQh\&"
RQhX&"
Ot;=ge
Wj7h8?
D$HSVW
D$$j,j
D$ Pj$
L$L_^[3
QSVWh?
htHjlZ;
HHtXHHt
nt'joZ;
YYjgXf9
>0t<NAj0X
~pjCXf
j@j _W
~';_t|%3
URPQQh
jA[jZZ+
PP9E u
;t$,v-
UQPXY]Y[
PWWWWV
PSSSSV
+tHHt
+t"HHt
HAO8t
,SVWj0X
Wj0XPV
CorExitProcess
(null)
`h````
xpxxxx
FlsAlloc
FlsFree
FlsGetValue
FlsSetValue
InitializeCriticalSectionEx
CreateEventExW
CreateSemaphoreExW
SetThreadStackGuarantee
CreateThreadpoolTimer
SetThreadpoolTimer
WaitForThreadpoolTimerCallbacks
CloseThreadpoolTimer
CreateThreadpoolWait
SetThreadpoolWait
CloseThreadpoolWait
FlushProcessWriteBuffers
FreeLibraryWhenCallbackReturns
GetCurrentProcessorNumber
GetLogicalProcessorInformation
CreateSymbolicLinkW
SetDefaultDllDirectories
EnumSystemLocalesEx
CompareStringEx
GetDateFormatEx
GetLocaleInfoEx
GetTimeFormatEx
GetUserDefaultLocaleName
IsValidLocaleName
LCMapStringEx
GetCurrentPackageId
GetTickCount64
GetFileInformationByHandleExW
SetFileInformationByHandleW
MessageBoxW
GetActiveWindow
GetLastActivePopup
GetUserObjectInformationW
GetProcessWindowStation
Sunday
Monday
Tuesday
Wednesday
Thursday
Friday
Saturday
January
February
August
September
October
November
December
MM/dd/yy
dddd, MMMM dd, yyyy
HH:mm:ss
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
`h`hhh
xppwpp
1#SNAN
1#QNAN
CsrGetProcessId
ntdll.dll
UserRegisterWowHandlers
user32.dll
RtlAdjustPrivilege
RtlWriteRegistryValue
HeapAlloc
HeapFree
GetTickCount
GetProcessHeap
CreateFileW
MultiByteToWideChar
GetProcAddress
DeviceIoControl
GetModuleHandleA
CloseHandle
GetCurrentProcessId
CreateThread
GetModuleHandleW
WriteFile
GetWindowsDirectoryW
DeleteFileW
DisableThreadLibraryCalls
VirtualProtect
GetLastError
GetTickCount64
KERNEL32.dll
CloseServiceHandle
OpenSCManagerW
OpenServiceW
StartServiceW
ChangeServiceConfigW
QueryServiceStatusEx
QueryServiceConfigW
CreateServiceW
ADVAPI32.dll
SHGetFolderPathA
SHELL32.dll
FwpmFilterDeleteById0
FwpmFreeMemory0
FwpmEngineClose0
FwpmFilterDestroyEnumHandle0
FwpmEngineOpen0
FwpmFilterEnum0
FwpmFilterCreateEnumHandle0
FwpmCalloutCreateEnumHandle0
FwpmCalloutDestroyEnumHandle0
FwpmCalloutEnum0
fwpuclnt.dll
CertAddEncodedCertificateToStore
CertOpenStore
CRYPT32.dll
WS2_32.dll
GetAdaptersInfo
IPHLPAPI.DLL
IsDebuggerPresent
IsProcessorFeaturePresent
GetCommandLineA
GetCurrentThreadId
EncodePointer
DecodePointer
ExitProcess
GetModuleHandleExW
WideCharToMultiByte
GetStdHandle
GetModuleFileNameW
UnhandledExceptionFilter
SetUnhandledExceptionFilter
SetLastError
InitializeCriticalSectionAndSpinCount
GetCurrentProcess
TerminateProcess
TlsAlloc
TlsGetValue
TlsSetValue
TlsFree
GetStartupInfoW
GetFileType
DeleteCriticalSection
GetModuleFileNameA
QueryPerformanceCounter
GetSystemTimeAsFileTime
GetEnvironmentStringsW
FreeEnvironmentStringsW
EnterCriticalSection
LeaveCriticalSection
LoadLibraryExW
IsValidCodePage
GetACP
GetOEMCP
GetCPInfo
OutputDebugStringW
GetConsoleCP
GetConsoleMode
SetFilePointerEx
RtlUnwind
HeapReAlloc
HeapSize
LCMapStringW
GetStringTypeW
SetStdHandle
WriteConsoleW
FlushFileBuffers
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
SO-'+M
5*+61-^
aUbU:8
,KONP!GFIUCO
(KY\^W
FF7E\K
7;! "
H:1D3D
g^PU~UQRQUUU
jfklolnqt
tpuvyvw{~
gcvnjmpc,cvc
gcvnjmpc,cvc
afpmkc,cvc
afpmkc,cvc
qmemscvnjmpcp,cvc
qmemscvnjmpcp,c
dgpcdmv,cvc
dgpcdmv,cvc
14.qc,cvc
14.qc,cvc
mncp_,cvc
mncp_,cvc
jgc`_m,cvc
jgc`_m,cvc
rfcumpjb,cvc
rfcumpjb,cvc
plqllh1h{h
plqllh1h{h
5678h{soruhu1h{h
5678h{soruhu1h{
693fkurph1h{h
693fkurph1h{h
msedge.exe
msedge.exe
edlgxeurzvhu1h{h
edlgxeurzvhu1h{
pd{wkrq1h{h
pd{wkrq1h{h
7:hn{akg0gzg
7:hn{akg0gzg
SSDtqyugt0gzg
SSDtqyugt0gzg
Uqiqw"Gzrnqtgt0gzg
Uqiqw"Gzrnqtgt0
dckfwrnc{gtdtqyugt0gzg
dckfwrnc{gtdtqy
vyejtqog0gzg
vyejtqog0gzg
kgzrnqgt0gzg
kgzrnqgt0gzg
fqve*ata
fqve*ata
b]oaea*ata
b]oaea*ata
Ejpanjap
Atlhknan*ata
Ejpanjap
Atlhkn
q_^nksoan*ata
q_^nksoan*ata
nqeuejc*ata
nqeuejc*ata
3_dnkia*ata
3_dnkia*ata
japo_]la*ata
japo_]la*ata
o]b]ne*ata
o]b]ne*ata
/1,_dnkia*ata
/1,_dnkia*ata
P]k>nksoan*ata
P]k>nksoan*ata
a`hctaqnvrdq^oqnwx-dwd
a`hctaqnvrdq^oq
'+*<i_P
"UW9)9I
-8n}/^
y:)WWWfG
8)WWtG
/L8S6k
{*WW9`
7I \QU_
U9)W'L
>48)WW
r<T9)W
U9)WH|
>/"]Jm
xS9)W=
Q-9?'X
/2T9)Wzr
LV9)WN
j8)WW,
;)WW?Fx
h1']9)W
M:.}.U
%WW9t-y
YsgY9)W
kYXW9)
=9WW9~a
l}4e)?
`V9)W,
7AH8WW
M(b|0.
iL?.W
(;@]UW9)umZ
?<^9)]m
U(WW9D
ELuHWpP
qaUW9)
i:)WWWqD
;)WWt>
^h!uWa
!m(8+}Z
S9)W:I
t8>Mo:
WS:rV|
Sl&!F]
8#?h"/
;)WW:*W
pOgQf4Q
> nHn>AT]
V9)W^K
.6MW9?,:
oV9)WP
B>9)yS
.ZKW9?
N^+S9)W7f
K4M6dv
V:|]r)
WTW9)6
p8)WWh
0;)WWC
+WW9kO
;:5Bba
U9)WAw
8)WWBIW
UW9).#{IZ
;)WWw0
VVW9)W
/N~W9_
}@RM.6b
o8)WWl
V/;)WW
3/+i9?
GKT9)W
^8:)WWO0bg'nz
p4C!*WW9&
%z^M=
jk8)WWZ
:!s:)WW
I]U9)W
I\.wi.
t+WW9/
gUW9)W3
V9)WK|
V9)W&H
*vBVW9)
B([U ?%@
q1GgOKW
]7emM`oE
~w^Tc#HY
HCE{/5
4jILSWnk
!cV/Uf}
Mc)$S*
}3;JU*
Z+XkAy
aSm&Rc#A
vNbAA1
]Vhxy0
5QiUo{
Ny4:MO6
;u;!{#b
QD9bv7f
6q)fC/
I3!9}b
S_,bgEy
Sm!RYB
K$kxMVy
Sd/n[-vuY
!E8^~o
*MTX&S
[o0[O5
Ua+lekI
vw./oK
l;(koi]
=E[IkZ
^+0O_)
-OK8)IOS
v"kNw`
$?=Mw6
b[bdP/
O2ixpLa!
|FunlfK
)sMRsr
AN%d{_
gN$yfG
}EE<:
K(_wYA
[E%L_$ay
yd=MzF
wB !e.
/7DXCM
L}+^vt
@(kTz
7)XS6$
5L-g5H
S&%5hN
m"r}0(3C
5]j#K&6
<O?Sv'/sH
GZ% ?
)xh`~*
cJ&(HE
71DH`$
~Z4a{
mWIf@;
@+cby-5%
.b`tj7r
7zM2ac
LA.Jq&
/:&FAfv
L(Cz^\\ax
P&ek[S
#[c6Ev6
~"9-X&
U$%+9]
;!Tg&!
`Ht8h}q4T
`*B`Av
vF;pvT
VdbEP:
)^H[)3
GLHk{F
\S&Wv6
kUT-y8f
*oAed.
*pO-W_S
~,km?m
lpCI!r
z "9EF
UFq>?e
}%|Mz'
!50NSb]
bYS)OEi
}3">sG
-K_/V=\)
Mm\upt
m;YO$0
^,K`HK
vV5h_!Z
Ud8i6,^")
5_QNHi<
A8&+x]
3fMrp1
CE}+#aP
q|!vR{
{ghQEVrJeDrd@H4^
^ rC(F
/ev|EW
2D1MYo
Fv-v0/
z6/lGT
yx+F+0^5!p"
(=1F;Z
K__8M[]#AQ[$C
]F#hU)
lMn2_>Of
U)CS[S
:J"'n#,
_HESaz
ZN,Z*k
OvFVA@
IM*VpA\
KY9!d~
d&sQTT
i-w[ &
K$+AQx
+dP+$`Q%
]<~U^s
IN$xy@
T3(,R^L4
M9R49k--
ZP504z
sqX"=kB
H>=j{S!>
zh{'c"-(
f$-96?
W,jx]j0
y [!Z=
(;&fU%f$N=
F&o14]i
,E_].PD6^C0))
OFlEfi
z%iEe|
cm$hFG
T0&vfbZ
HcX%AcG
L%3cax
xu;;`T
EvNd9o
hzEJ9G
3NF% M
1 1aF30=P
]Q3~<r
Ta d1:
Q--h'H
.+cVo+
;3~Wtc
8Z%)$X
dG%LMR
5[N^jd
.)U!e1
9F|"#Q
'K1|3B
7'rpt1p
+v@MD
l[ $Wk
w\~S7J
+\|+[&
Y[.S,_
&>DQD{c
FF9y&z
S{d74?
&q}#_-
keb^{K
=X)aWo
8_W.{!8q
+9q2Cg6FR
/ZA7|k
DA=*:+q
L>Dyg`
/o1acJ
8i1Yt%
%mD:E~
m-@/\Q
%Pc>X^f+
hcL{B`
YvB<+!
+sz!jv
B4Kq5y
x!}c,m
YU/Kt
RaBrf:
DP=|00
?#y\hm
;ChKCx<
$O]q7l(
Q?c5&/
9bej]oCA
A0~Ax;
OUbqqp /*U
/N[Ih
TAQbH1
WhavXc
;D}4#k4
Ze]3hX^
8a-wEM
f?+xY:
,kOCA0
tnft{o
MhM'Jy
c!~sMc
)Qlp #
\|%?s+
A00KXF
I9N*8Y
:Kh.]X
b<?4#
f];;'^f
X)d5e~
m"Dg;G]
M[pl*e
3e<)f5z
fj=Dcd
d-'$DG
:FX%+i
+u\y%S
)46_@[
.(,'_t
3;2s8)%
Dv27Bf
Jfpv$V-
P=2Rz"
rB=q-4K
<J8J,)
N^I^:O`6X
)[j!C%
oEyc;z
?$cwXw
Rl_Lmu
6(nT&e6
!s1"|F
^^1)FD
+QCtGI)
+dA=Dg
6=z!ov
,Af.r+|
3#3b )
a` AiQk
c&F+o)
1^[`OQ
j<B={K4*
O7SCQ4
[hJ;m@
A ]Kliu
^6R7l>
l|xD`d
/6n!CQ"
dc!2MB
(JAlMZG
i+#Om7
P<b:mL[
Tdo8+R
^yuh6P
7VD5?Mvo
XYUKi3
6&`/S)
)PCr[`
8.uA{m/
j>)Ou&
K{/l=p
[A`#mC
g%"Ex`!I
q".m2~
)Q`ewr
YL>tZo
eH9[sp
BDx2cg
-$(|~5
=C%,d1
\o0c.{
T]e{h//4;
6*Guiz
15sV 86y"%j
'Ka#}o%
ZcIhs#s0ww
4Kna'^
m[ohu$
4qy+PG
$5LDz3
QTO[0S
^gmR`}#
=RRYc}z
#y#KI&
;4Eyk.
]UCic%
SBxx8%0n
nWA [= SX
},B7-c
j^]O6%
(sJ?B+
IS-|gpx
WQ;pmA
%LU![
X8\%c;
t8go3Q
iQ?Y~Ib
l-]/oMH
%f!6Sy
.,O]#x3
-r}!~0!
;1`GsKy
}mX_e&G
iGdA?u6-Z
JaBv=4
S,x6qAR>
b)DB*H
D:D7;&
;hUPa,i
^dGD&<
aM[fRS
EzsM+V
SL7\OKQi^~
?!enVP
m@N[@Vva4@
#S"j*/J\~
jj.)xw
p?|-"g
sUOM&/|
6AHhBS
y%=FBi
|@zME7}LC
*q!ab2gF\
C![Xh9
?4+!rd-{
CJCYc-SVx.
+ghscs-
=nTx|Y
Q-k]1d
WM|?xO
oQS<{=r
0yI6S}#K
ng.}tV
;%e-.h`[bk
CAS !4
4FXg2F
ks5SPF
p]~|p^JQc
e-QN>`|
hUOPKe@
[>#2k55
Q#cA+?
Zh?B 2,
HP<.pA
B#uWFh/
QDsP/S
Y-J1a.
f#mW1W
uQ7crH
PN1-xr.?
s{*ZZ8e
,0:n%3
5]1 i;
R}fNd$
yMK[Og
=3TuT+
1 ^ocs@n
iSPJ0&
W =uQ~
My+Y]p
|h[-u
+$ -sH
mBiwK
_6Ds[B
-a6-HgR
<!aXC^
_678iUN?.OMP:;&
a@P$3X
Tj&rdu
#0.+X3
`MTIDpd^K
kdK 4A
0KNOL5SDz
;^8SZ0
vHKE=Fv6`
fSA3j
C/ex. o
0{@R%%?}V
(b*1pQ
UN\F2A
]GVMKY
MlAh>=
PJG/H*W
[86- H
P TwA8$
K=d-t6
EIb)Cb
CjHKy2Sxj
n?tS_m
d7@dwZ/v
~t,/wB
gP}$>L
|8^Tv`
5Fop2^,
Z{#^\G
|OE)u?dKFKV
B|cXG{-
y+e&&u
yi_tF![6
dg]1gU
T$%Yc
/>"J;>n7K2
;Cl6'`
Nn\;o>
0C8ux
F4h$E/
ft?U!G:u
uw7##L
*jN+Gm
STkkMH
Y-*Q6#
5Dwk#6
d9`g3s6
K%b-7`
taE..]
e=A#Gd+z
B!>Xai
h]t8n]
A4{2gC
n61Oi)
;c!_2:
TnC5DE
z"BU)6
&LJHnX
U8E@y/
h1ANC
CNp8CQ
S+fs{
{^L `~
>/}=3A
RyL-oyx
VNxpgp3
Fi/k%
tt}7Zx
sJt{%!
-[ nt\
VWkg4-6
xk<yBW-(
*'ViQS
a7ePbuI
^XAT5D
c:B2:rN7o
Zu'a|Gy,
8}eu}O8
.P=oI|
IWASv)
EVN.|
[ek^S6
5ae^G2=
44Cl0~
e SPlx],kd
_..^Z{
o&(NB*$7
&*O-%R
(:BL{Z
$a-;.Lf
w;io6
wzom' Ga*7
Sd#"Q<Z
AULzhi
+VT;0i
1bma1m
8s=gf5O
qnE*@)
e@5""=.
xQ2PJr
@){N>|u
Yn.bQ
Pvh%~&
&vqS;\
^z0.6
Jc3wy1
]/w}_`o
UEn1ZZCw
iEU#fF-Y
ZVY{$F,984
b#1{u\yW
kb!wbZUT
%.A{hS1X\]
c%g?Eu
bJ->>T(
nM80zR
+jY46yc3
2YZAlQN
]LX[<I
A^X?.*
KL!#OD
^\MF$+
QOc#\-
h)QK7RS
o:c<+X
AU9pqn
)DnqvE
NN<!o
pSK6LA
LTrC4+
rh8Ex2
RK2SOE5d
&k$C+z
3!_#G
Nm#`!X
k9KJ";
E36Xsrj
=[>lUvG~}
PE4$iA
lATLyE
_"SM:#
5Md3gxOY
o:g>k+3
t"Nv:SAFlS/2q8
ia5;Q*
;K*Ou:
=$vye=
|nf6e,
G B6Fkl&
f(uk!0
|QC1qS
!ApFon
.w!#h/Ua
j-sW!Lu5
v#/mUnK
GX-&i~
u$o>-<Cc?
Ya&x6:
N#@nS!Hw
1hnu!Mc+
JSM=-u
DKK78v-
3_uC?gE
jgech>
9{`mq|
X1zXe,@
\iwG1
T*X97L
%YHA(:S~
-PrYS
Y}%PQM
QC8aJf
zo`[/CM
-av;)WW
wVW9)&
+WW9s]
d`1V9)W
n~,{bU
K`HuS$q
LgZ~y-<
BvdtMe
UW9);,
TW9q^(
h)UW9)
nT9)Ww}U~
:)WWti
>9w2);
8)WW^Y
/IHj%N1"
3/;)WW
UW9)ya%s
G/C63Ui
T9)WTRM6
$,;y|J]+
a3nU9)W
YbocT9)W
$X=M^J
^+WW9z).`
:)PQ/p
T9/QPE
AJ/WW.3
;)WWd{,
HVW9)*
)8oFY4
@2)WA
*Wz>VS
L /DWm
*y:)WWjj
(WW9*'
jC7^r]
uk:)WW^
6-t9L0
;)WW~_
_kQ3.(
/0PW9.Uix
fVW9)-I
H|T9)W
[8X--b&
SNV9)W!3
lE[9qp
RFW[@()=@
mxX"+'>
8)WWEx
sDW"L^
}7r(WW9
}]D.!?b6
@1(WW9
+WW9PJA
xT9)W.a
!N3/_lr
r_(WW9
(Wj#,d
{*WW9^!Od
'-k<Wq
VW9)4O
T]-8nmf
8)WWI(
pQ:)WW
U9)WbA?H
\9HcHb+
!lwARI
C}vu"D=
a48,f,
Gmp L&
AL*)WAJ
T%Bq78
CSUW9)
' Te]A
&VW9)t
s=tLU9l
:8cs*WW9f
sJ;)WW/
>\{Is@
t9)A$5
U9)W2U(.
hvs)&[
{U:)WW
m*WW9J
?!o9)(W
?ZH9)Z
Y=)Aa))W
?RuAB'
x=*WW9
T9)WE_
{ES9)W/]
aAR<SW/
T9 p]>?)
3T9)W}/F
6ak0TW9)
3VW9)|8
DQo3YU9)W
^lYbiT
BRb;)o
f`u7xM
*^2[g-c
N%}h&[q
( ('E}
JDCzt2'\
ff?wR
`57;@I
g5)8q4
;oMU'0S
vwcCe1'?&
gAVV5wZ
>e.g(n
D0h{;ex
|ukD>`
roo;xz
Iokpv0
{j-F3'M
yRL'A?
E65';n.
))T^'k
JDZ]pW'
7G<pjH?
,5.Y/Zd
IsBKh't
Ckz~Y'
[fC')
^=xbAaMj
Ar<'!s
dD@\l)
YyxC:J
Xz;RYI
d2zk\C
Ebv'?Z
tw'q>V)
,Q'hL{
9=_RMdE/~I
g.G3og
Y8.T\<
ZsU&J?
DE%&v?w
Kg@S#"E
=KU=ch/5
#=KU=n]
IC1=ME?~q
#MDU1'
UC~];I%
NMFjCq
^2 3 =
7]U7g8
"Z}OSY
<CLTOG-+
79}XG9
;C=}>-
?1bGa_]$?>
!o?5Jb
Nbb-?!
]~#CY'[;
_a}vq.
CYCeMF
pUlv1%
BQ_3DK
saoW':
T*[W`M5'<
D_e96.
/@S'lP
2.,]i]
PYOad>
O6nIzJ
,Z'#~G!
>S)6SAQ
/m]CC
[+[thO
__`Cg7#
On7CO[#
tW^) k^
GM7?S
y}]}S[
_e5"]+,[
!mM*Hi
SXcO0S-Tf
aI)O}KI4y1
M,iPafe
&8_]%"
g6%xsN5#e
S}3C:7
|7D%QL
5O.IP9Y
#ID]i297
z1p17*awU
Yt/{9"
m?U:3/
s0#Y,)}
8Q&;IH
UEC%h6
]^]Y;_
w9ZoO
Xc~>9es
E4Ywjx
.QEI}
I= %ss?
]sYa1'
4=g?}B5
Ec.:gYB*
$YS^BqZ(
SF;<LDII
wTY<+;
T*Jt"'
(:c'\|B0
X}N\j0
(a!~43
e{"'rNh
J"1;AJ
CwTDFP
8.YF ;SW
TA=N]p
8SZ!)ES
8N!/WL9
|yF-yYl
s#/^#=
{wmO!5$9hD1?
C5Ae`3'
fZviUP
#{1N/x
N[p;V
B~9i{{!
C-nBO[
KQ>;ma
4l]A1j
0,qk?iQ
Wk)dEv
6]@)1i$+!'Gk^
]YXB7s
W*[`hm^
^$%~^I_
7Lf)c
-JHOinx
<=,1-WZ!F-GNa
A[6Ym
_TFFOA9I
k=ay!`
w^C8#9#'
Im&=P-[
^TWbev
1>[-Ho
kur_u
p_EX\r
)osf6B
J8^S^se;
_)H Pfg
'!UG.q
9)WxF5
I/5$S9
V-W]3?
S_$*WW9
]@,!m527
>VW9)J
U9)W c
rz(VW9)>
m`FO'$
q2<=5A
lVW9).q
{[MJzJH7_
A^^?EH
ALK-W,
QQ>WKW
&QV9)W
(|sCDSv
Cl-U9)W
)9.BI#*
$(TW9)_
NppQ7b
l^L:)WW|
ABU-WAZ
8z :{/f
8S9R)S
w;_}TW9)
j o1k-
T<JpX`
UW9)pjCKiT9)WE
)K(]q2
B7;)WWy
\Vo5D.e
3lVW9)
]?Rz,,)
)W]>Sz(
AO~(WW9
U9)W5V
Unj],7UiW/=W
n$*WW9
F%@$s3
VW9)n.
LMtDo/vtu
S7V9)W
;)WW?(I
8)WW^#
:c*WW9
W9#xj>/(Z
EUUW9)
v731c
p+:)WW
<1-WW9
)xA:%WW>
rW9?][9)W
SW/?@W9?GL8)
L]U9)W
7VQ8 s\
dVW9)/
J^:}Y#
S9?B\8)A
D*WW9W
h/VGV9RVA.
H*WW9#
8)WWl5
|P4xAP
Ib2J{,
RWve`d
0g:)WW`"
)NDRVh
RDf8)A
h3.PP4xA8N
w8)WW-
7;)WWGz
v/cO>
;)WWQjs
)u%;,O
vn-lH9mH
(WQ> k
~9)^p/
DN:)WW
FwE"6s
p)#VW9)P
WxF(&]3
P//IV9
](4nPP
{;L+WW9r!A>
/RDV9?}
8k/-HV9
9^#3#P
Mr:)WWI
;x+WW9
UW9)%Z
cVW9)n
S9?9F9)
;db3#V
BK>nZW
VW9)h)u
'W:)WWLu
[j*WW9/
MV9RhAm
UW9)`z
Z!Di=K
'C;k/e
mUEu47
a}Ku{Aj
C:55#>ZO
EP#)AO
%QWdHq
_W4?B6
M9Y;V1u
\x$*hwC
_,~Hu4
Qv=)K
?fP5K+i
q_yGats
?^56-Y8:M
D5dZC9;^0
&s*7*\Q5
TH>DG(
-BEC/
ZMD.,{}R
xmiOLH
55G Ynr+
bx;IH.
M%7N.BO
k@2P=]
_>MmCP
-308?R
$5`?-
NeHHYm
\Kg22h
]U7k>O
M[[kU5}
$`ZSws
uF;V5!Ii<
#WQN0
V2MBVa
g$TA?F
6POqX9#
V8Z(k#!
&k3e1$5
^F@>.88
fp?p{o6
@oP|Uuj
%b.UV^%vU)
f~&bagr4
VEr=%`
r!@;j0
>_/*xv
-P#9mO
d!93 Ulw
A=w5a.h/W)k
aGDyOGP
i{%)/8
CaJ9Emn
\k(uHj
S'?1=@u
7]QU%h
cw*%a
hs!*2A
rC}e~d
PB+/Pe
V"a~"@
;:&F<w
\'yU8vk
^Oz[Ch
&Xt!2y
6#>D##
T7i*OG
MNxC/K
?}rKZ@
VO~yJ[Q
s.[(nE
A=RwU3
GMoX%1=_%
g^0uQ$
Q>{XXAm}
8/r;(-y
FN!@p4
)^rH{s$z
q{^TSI
/NY5q,
69 +MPJM
+MPL~XE
pf19os
giy^]Y(
VL[$bmA
]{uuKn
|!HFU/@
d@-)&8
2*02nB!
S>e\K^
4|U -q
1kpL7:
RLy[ak
/zlCRl7U
%7>;Ys86
A[*E (
cU8A-x
8`!H#"
6XEt!a
` rL}\
%XdC}c
~%?ZZ
W*~c;*8
VWp8zT
:H;MH=[@
z/Nzm3
NffxE*BF
"Hz75&
g1@cZF8
)8K^Px
MXBeVL
cunSC4
mOY&}_P
6[be.6
g@v5e;
i@j4eN`/
sxqozP
S7bgCZ
Lc+(fj
91cTs!&
X+RqT*
1>Ot#y
c+"AFY
?PiIp#fz:
LBVMQb
AKSC g
G9Y&[x
CrfjCgo
_Z7A]
+\:NGOD
Xg]v9f0C
Xt6S.*q
/YS=~
/3d# V
`~rnV)
cM{[/Y
??&8\2
_RDw[d
WO=$ARw
X|4w#o
oG,O!W
9r]K0\
& +|s&
cXx(g:
rk9=H%
de9*Zd
i1YLYU
w[g=+h
k\v\-8D{
"lUffa
BQAmM[
pn&5by
53]V1
ZZjLX4
l/RpRJ#
ZI`7/_g
s@V!;U
!N-ozn
,D^m$<
h}m53jS
Y|TJIN
8y#Ujp
E"{g[w
{Cn#*d
q06c+l
xciZjh
A<Ga^*
7*Hoh|?
[qk#+L
1$;;-UX
^83`aZ
A2*m2wI
}W|%>ca 7
Kh#E@{
yNa$G[l5
i;=B\
;q_kR6})
Yx&3?L
#BIQV^79
w;6\a`
YDv$D298
k!Sq=SN[[ZwfV
8ahZ*V@C
;A;kM
@7}Z?wN
k'QqIG
IJEdiO
9_2k&E
7_G\Qx
=fmL?UY
Y/G 2cX4
sv}B|-5
({_^?:
Gh?wk/ -
h))tQ%Z
}x4cQdC
xbc}>?
g4W$\g4~
6dUM^=
?$'Jn.
&'3U3y
@~izmI
@?&Y4I
'GkQ5
RyT'F^
H!u'Oon
]Ih3UEw'
x;S'pT
lKGyhkS
[8]0>'
5&Iw!8y
WSjX'@
e39of\-
Z3'`{%A
@I4+s;j
Kc8'l
r|$5K,
4_(S+>U
=/`R15lF
j^<34 hj
8Siphm
z3XI/(4
,~AXjx
.{:LCs
~?/hpUcQe
7$KbQ|j,KDA
_g]UtkSm
#\9]#`\
4 8Kp;z~e@ZI
@/K+l,
(%z%E`
^o6i_"
IfOkV5
DT]ohh
Dy]l,lXr
h|(uCqr
$j[v~VH
kp;sFe)K.
4tw[$\
b_=6-|_
D@<c)3i;
K`o|3b
Xk.sQe
u/"27K%2mf
VIse4J
=g.j28
Y;EWn}
wtNg`79
#H@kF0
}!)Mpa
l-vF'+
(!SE[(8R
Q<3M^A
=Q,Afk
6&GYOC~
+8T~*^
+rTf#C
+k1%|H
v] U=p~
G7L5vE$
tX%N]I
N[Ct_[
)ZXF+m
`W%R%Z
{=bw3?x
FWTf$X
\C6`xx
rSURKVA
z \\tD
yT76uX
fBA@PS
zrzsbtP
9(5}q[;
1E{CaP
hany7$
j=)ApPH
nORkx=MM(
nn>QYN
+20/,
/o?_/ij
W%;b08a@1
KMet^J
-%hB_%#
-upizZY
Zwqb\+
[X)4,;
OX<[\u
$ft(0H
xXy[80N"
P48q5E
8% Mc7
^nMkm
dnmF0B+
kLU0UW
0OR#sF
1^{^#
T&{1p@
No$LbF
1d"7tD
;A]aLG
/czqBk
7iy{R4
r/6QM2
b; tc0S+A+
GhzIXI
1zp,]aC3Z
ohvY-kZ
bA4PD%
(gk Mo
6)ZGBHQF
e|)ST
gf )t]
ej_,@l}
emBO[:
A&[!M+5ZM/
6:U~5-c
:?xIYe
FlR*U"x
8;@{&,
+x}.f?
%I&o}Sc;
^ ({alyb
4HX|%sL
qp<h#gK
>\e*Z.h#
N0F<Ex
\ =W;e
zTLRU+
d3$pg(Z
Sp@y$z
ioay;z4
Z.`Fa+
rU,H,2
bH`~I|!
~=3}}l$
\-5%GC
5*V'b>
-c]a.7
SR[}tB
q|F\Ij
7pZ!u_
z$2;u
>[+%>X
2KTU 1
'Y3xFT
D}`}fX
/,5]+8f
2Y,1g7
)P}PND
04`or1X
A }ZCo7`
O_.HE
b^d1{#R
cU5Mnl8
I.4{>[
!~;()|
;4>'cg
<Z9A!4p
=^L D@
1|(GIl@
uY0_1w
DpCd<1
kB-~8Q
Ka%&n4O
XTZAAk
@2k&@3
A1@fx:
TD_#^!
f7$Q99
tp*;k/&m#
&^8VkP
aTcli
HmgfS=+
,uQ~#
lGqh&D
K]>sQy
c|mF+~
H_[fmZ
P.8|~v.
!D#V4g
6CF_g+n`
vE4Haj
Gi*D7K
e3d#&0C
(yl=>
b~R?W7
^AY:4-
KpMns'EK
zCIKH/
3(FKgIo @
"X%!e%
)7&6:2
7%u% -L)+
r5-@X#
eEf-&Im
b#>e1?
Fb*WW9
#rPJjO3
^]QQ>?%
uwT9)W
%:)WWITF3fq
aIHh)>
D)3zF?
DS9)xA
;)WWN/P
_e}:)WW
MD#uVi(WW9S
U9)WGmR
;)WW7H;L
dZzy G
hACjSW/
`f;)WWC
e$:'9Z
TW/o[T9?aY=)A
{tPeA`
!v*WW9{
1+WW90
b=)Aj -W
;)WW=I
VW9)AI^
ws~gBK
(t&TW9)V1f_
?,6W\A
VW9)'S
X+WW9U
3!o?L
V9)WT[
t:stWi@
5+WW9br%
er.!?`
)<U9)Wc
n(WW9$Z
d:)WWO3
n/qLT9
P3.-W/
AS9?C:)
;)WWj8P)p*WW9V
T9?pG:)Ah
e0F9Cz
Mse:)WW
,h7)W-
>)'A)
M-Mm++M
#ujA+s
d9Msge
S]+h]uhMms+M
=OX#d~]
M]n6ay#:
MK+cMOi`-
~t5i]w
}zp=X#u
E]as(]a
@w&U#6H
E}#$})sCM
#)&A#:X
#(>?!h;
/MSjc
N!KfL
ir[!#?
%6?#Z4ys/
w=EZ#MOm#-1_O#
4wDiMhO
#?kU#z/
7MmlAEG
-jKCMZ
q7MgPuc
sH?MOm}
a%cMUGmem#!
MiH+MJ
uEI)$s
}omY]5
a7#w,qs
#O{?#:
q5a=#-
YY=q7i
@#^-qfY[#
('Z9`|
C`gW9!qh;
&_W.W0S9R^
iBh{5B
E<n*mdj
AVW9)$
;)WWuwh
j/,f_9
VW9)l5
{1zL%nX
TdT9)W
)mT%<z/
4{*WW9
,Au})WA
d8)WWh;.
$;)WWF
H#^0h~Cel
-](WW0
+WW9q.
}[QVW9)
?a>:)(l
SW/=o_9#
-\=)WA^fSW
#sVW9)#
?PA=EY
&6U"Cm
[@~2P=
/-?]CM;
-WJb9La
c[mn]C
[cR];@
8:=OEM
K.!Ma!O
C=V1M+]
8}BT|96
;'AxW9[
7a7 sam
OfGH)OQ
( $jt7
JycG"C
$_ehVD
>RH`Q%
AMZ-WA
E&c'J8)WWL#))B
-\ )WA
YoT9)Wy8
X?kn+Z
58)WW$
:),X?/
PP3#(S-
uMd/bh
QO&faB7
)hs77P
T0#|w7
u7=^V]
]m?#!I
y#jC}i
h1+g^6
uNF5xmf
`^.hOM
6\I-=
!h#$am
H_W>VZ
)W(<on
g1)AY!W
_W>/Q(
A7Q)W^
d{Yz$Y
;TW9)*
:N2T9)W
gW9SnA
a_9?s`9)
! p{&)`
6r8T9)W
??hi1)
hX%A+*WW
T9>$L9)A-
]^*[E0G
(WW9n#
FswLt[
~1)Wx3
+WW9u"gakTW9)
/;8)WW
?];)WW
Ak5)WRt
VU8)WW
;)WW75n
!oN+A3
?/xhB.
6*WW9r^
HTW9)h
TW/3 _9
c3TW9)
V9)Wvk
7!Qh
^\&TW9)
)5T9)W
F@cC_W/
E:V9)WCz
Fx<p# p
,3/DT'
hAf%WW
D~Ry~J
:)WW.O0
&A(e!W
Dw5/,Z
_~//(W9
8)WW@/
ns7`JS;RZ
-Xh)WA
xu^fAo
8)WWHO0b
!b 7i#j
U9)W#d
.pj {V
c]&U9)W
4?3(\Q
oFbnJqw
T]cd*oG
Uoghg|
N2*WW9
tTW9)w
-WAFlWW
QM.9)QQ
uvzTW9)W
._;)WWbu
r[+WW9ls
-%UWW?.,^
h(2Vi@
8)WWP?
O:)WW]
eWVW9)mj
ABi)W@@LWW/6
WvV9)W6=+
_6U9)WD
'l:)WW
r@)o6X
kCQm;[w4{ Mn
9)]P/LdW9
iRna)Dh
R!TW9)H
:)WW\9
Y%AL WW
V9)W?~
>|<9)A(;-W
$bp-~{
T9)WN<7Y
!:)WWB
SW.S%W9?
S9#P,8
+WW9wLG
*J;a}*
efD(WW9c
W9.PQ?
)dq+WW9
Em*0;Q0
{k`P[1
SW?Sq(
_9?v"9)W
UW9)=0-|{T9)W
TW?#]P
SW/!^W9/
9m9)A5
}>*WW9k
S7TW9)
A5)WW3
{HF4.n
A|+WWF)
WU{0VTY
NPQ/cUW9
?]V9)A
?~S9)4A
?.,JG-H
G8TW9)A+
?)W4/D
?DU9)A
.{?)W'
/[3)WA
//SW9.
xA&.WW
)F>)WW/8
U9))V)
?)Wz>]
Ai9)WAF
A=/WW/
4/8GW9
/u?)W)8
@Ak$WW/
7.,B^?
Q/QQW9_
G8VW9)(QH
?3T9)P
)F8)WW/
bAj&WW
Q8G9)A
)F9)WW>?
?]T9)A
/INW9?hF9)A
zP>RNh7
P0F+BP
`/yXW9
.A"9)WA
/8OW9#,[?
pAF1WWO
/aZW9?
/MZW9?
AF$WW>
!m0.!~i
k-?#]Q^/
/Q03.A0-)W]
?2X9)A
WFW9)W
<WJZ?:A9)
W9)AT )W'
!j/(BW9
*)WPE/
XW9?rH9)
CW9?%J9)
?*Y9)!
BkGW9.
&)Wz.?
C/1SW9
Z?KA9)
(/:WWO
#R;WWO
!}Af3WW
&AJ/)W
WFW9)W
?DR9)'
O9)A11)WA
.: WW8
?3R9)A`&)WAv
WW/a]W9?{
AM/)WW
G8WW9)
A`1)WA
IW9?Pt9)
@9)(B'
Aa;)WA#
Z?'K9)AJ
X/`LW9
AA(WWN
EjPF:9
WW/1_W9
WnF+8P0
W9)A(#)W
BTJW9?
I9)zx8
A]%)W4/ovW9
GW9JA`))W'
P/=IW9
A]<)W!
WW9?YR9)
?hX9)Aq)WA
!o/1IW9
_iAB%WW/
}W9?0|9)4A
/WW??lY9)A}2)W
GW9JAy')WA#:WW/
)F9)WW3
A^))WV
QAd!WW
H9)4Aw
A_%WW5rT
\Qt9)!
_9)A[4)Wz8
)F9)WW
tW9?{U9)A
?cp9)!
?)WAQ/WW
uW9/Aw
AO;WW/
/FzW9NQ
V9)Wx/ZtW9
K4gW9]
?;X9)A
)WAk;WW
ULXF=,
W9)A*.)W
u !w:2
Jo8xAA
FNc:tU&
<?xml version='1.0' encoding='UTF-8' standalone='yes'?>
<assembly xmlns='urn:schemas-microsoft-com:asm.v1' manifestVersion='1.0'>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v3">
<security>
<requestedPrivileges>
<requestedExecutionLevel level='asInvoker' uiAccess='false' />
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
3)454:4@4G4L4l4
6V6[6j6
8$8R8_:e:
=/=g=q=
='>1>Z>
1&2+2=2g2p2
3(3D3P3U3[3b3g3
4:4W4_4o4
2 2$2(2,2024282<2@2D2W2l2r2
646H6\6
;C;k;y;%=C=\=c=k=p=t=x=
>R>X>\>`>d>
1#3*3=3u3{3
4 404@4I4
7U7Z7d7
;-;7;D;N;e;
<-<<<D<M<V<x<
Antivirus Signature
Bkav W32.AIDetectMalware
Lionic Trojan.Win32.Generic.4!c
tehtris Generic.Malware
ClamAV Win.Malware.Wacatac-9789007-0
CMC Clean
CAT-QuickHeal Clean
Skyhigh BehavesLike.Win32.Generic.jc
ALYac Gen:Variant.Midie.90294
Cylance Unsafe
Zillya Trojan.Agent.Win32.3916223
Sangfor Trojan.Win32.Save.a
K7AntiVirus Trojan ( 003a9b741 )
Alibaba Trojan:Win32/MalwareX.5668a0a7
K7GW Trojan ( 003a9b741 )
Cybereason Clean
Baidu Clean
VirIT Clean
Paloalto generic.ml
Symantec ML.Attribute.HighConfidence
Elastic malicious (high confidence)
ESET-NOD32 a variant of Win32/Agent.UGD
APEX Malicious
Avast Win32:MalwareX-gen [Trj]
Cynet Malicious (score: 100)
Kaspersky UDS:DangerousObject.Multi.Generic
BitDefender Gen:Variant.Midie.90294
NANO-Antivirus Clean
ViRobot Clean
MicroWorld-eScan Gen:Variant.Midie.90294
Tencent Malware.Win32.Gencirc.14085da7
TACHYON Clean
Sophos Mal/Generic-S
F-Secure Heuristic.HEUR/AGEN.1361666
DrWeb Clean
VIPRE Gen:Variant.Midie.90294
TrendMicro TROJ_GEN.R002C0PDB24
McAfeeD Real Protect-LS!B96F469D875C
Trapmine malicious.high.ml.score
FireEye Generic.mg.b96f469d875c7fa8
Emsisoft Gen:Variant.Midie.90294 (B)
SentinelOne Static AI - Malicious PE
GData Gen:Variant.Midie.90294
Jiangmin Clean
Webroot Clean
Varist W32/Zusy.ON.gen!Eldorado
Avira HEUR/AGEN.1361666
Antiy-AVL Trojan/Win32.Wacatac
Kingsoft malware.kb.a.996
Gridinsoft Clean
Xcitium Clean
Arcabit Trojan.Midie.D160B6
SUPERAntiSpyware Clean
ZoneAlarm UDS:DangerousObject.Multi.Generic
Microsoft Trojan:Win32/Wacatac.B!ml
Google Detected
AhnLab-V3 Trojan/Win32.Wacatac.R353801
Acronis Clean
McAfee GenericRXQX-OZ!B96F469D875C
MAX malware (ai score=87)
VBA32 Clean
Panda Trj/Chgt.AD
Zoner Clean
TrendMicro-HouseCall TROJ_GEN.R002C0PDB24
Rising Trojan.Agent!1.D708 (CLASSIC)
Yandex Clean
Ikarus Trojan.Win32.Agent
MaxSecure Trojan.Malware.1728101.susgen
Fortinet W32/Agent.UGD!tr
BitDefenderTheta Gen:NN.ZedlaF.36810.Qu8@aq2H2Wfj
AVG Win32:MalwareX-gen [Trj]
DeepInstinct MALICIOUS
CrowdStrike win/malicious_confidence_100% (W)
alibabacloud Trojan:Win/Midie
No IRMA results available.