Static | ZeroBOX

PE Compile Time

2023-02-09 07:10:28

PE Imphash

4328f7206db519cd4e82283211d98e83

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
0x00002000 0x00012000 0x0000873e 7.95733098148
.rsrc 0x00014000 0x00002c70 0x00002e00 7.47100938738
.reloc 0x00018000 0x0000000c 0x00000200 0.101910425663
.imports 0x0001a000 0x00002000 0x00000200 1.14864242974
.themida 0x0001c000 0x00672000 0x00672000 5.85382116839

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x00014130 0x00001d72 LANG_NEUTRAL SUBLANG_NEUTRAL PNG image data, 128 x 128, 8-bit/color RGBA, non-interlaced
RT_GROUP_ICON 0x00015ea4 0x00000014 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_VERSION 0x00015eb8 0x00000334 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_MANIFEST 0x000161ec 0x00000a83 LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with CRLF line terminators

Imports

Library kernel32.dll:
0x41a078 GetModuleHandleA
Library mscoree.dll:
0x41a080 _CorExeMain

!This program cannot be run in DOS mode.
`.rsrc
@.reloc
B.imports
.themida
QEBj|M
Zwcpe.Yq4
AZ7BD?
/p]JWBTsTpX
{C]+g`qy
thWui{
!Ql7%
jybMn8
_OKxE_
gLqUD1
7]bUd&
7~a$%v.
(inCXBQ
3%IUkiS
H,K~H\
?Hq"Vf$3
8q/~M~
)<E;Uc
|\DW#c
Fc?xX`Q1i
*(9kGyB
vSy9Ee5
6[Ab/J
~w.ZzT
zk*{)eF
DX~jmU
#n'/yp
=~aCsX
|HC@DW
I:)aI;"
%m,.Gg
[w+wB
A.o#GI
"+^]V{L
SeKu|~
tsTmZN
F?!@rvH
9.#V>A/A
,eKH^2
L;Z|}s'?
.OuD!J
uYmYsW
[6C#Dxb`
+tW|<,
Mhv4fb
\`7fk5]H
nLlV0e
|L(yPm
XS%p>R2I
eFnzf/
{M?Z:r
[`$,G^T
*cT,}y
Q[^=S#
]nKx:=
SC;W4t
35ZQEI
F-v6F3r
0tH:R/
n<Pv}}c~_}{u
2K"wnKh
uDcGjn
Z>;UiN
G6lU/z
ct&34}
F;h$0mXs
J40W|$
d2*Ghh
KaW6kB
|N<w86L
={96_3Y
q\e2rU
?nZw;O
/0IYg=
dK p]w
i;1w}K
{|d]q+J
XBOZOp
wP_MzG
vt^'Ird
EV(}kU
\;+t"ScB
H?=F_(
C.hQC>
lhZATb
a0a9a'
`@NW|@
R,w'nm
~|GMcb
.U1wt0
y|%kn7
<?xml version="1.0" encoding="utf-8"?>
<assembly manifestVersion="1.0" xmlns="urn:schemas-microsoft-com:asm.v1">
<assemblyIdentity version="1.0.7.0" name="MyApplication.app"/>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v2">
<security>
<requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3">
<requestedExecutionLevel level="asInvoker" uiAccess="false" />
</requestedPrivileges>
</security>
</trustInfo>
<compatibility xmlns="urn:schemas-microsoft-com:compatibility.v1">
<application>
<!-- A list of the Windows versions that this application has been tested on
and is designed to work with. Uncomment the appropriate elements
and Windows will automatically select the most compatible environment. -->
<!-- Windows Vista -->
<!--<supportedOS Id="{e2011457-1546-43c5-a5fe-008deee3d3f0}" />-->
<!-- Windows 7 -->
<!--<supportedOS Id="{35138b9a-5d96-4fbd-8e2d-a2440225f93a}" />-->
<!-- Windows 8 -->
<!--<supportedOS Id="{4a2f28e3-53b9-4441-ba9c-d69d4a4a6e38}" />-->
<!-- Windows 8.1 -->
<!--<supportedOS Id="{1f676c76-80e1-4239-95bb-83d0f6d0da78}" />-->
<!-- Windows 10 -->
<!--<supportedOS Id="{8e0f7a12-bfb3-4fe8-b9a5-48fd50a15a9a}" />-->
</application>
</compatibility>
<!-- Indicates that the application is DPI-aware and will not be automatically scaled by Windows at higher
DPIs. Windows Presentation Foundation (WPF) applications are automatically DPI-aware and do not need
to opt in. Windows Forms applications targeting .NET Framework 4.6 that opt into this setting, should
also set the 'EnableWindowsFormsHighDpiAutoResizing' setting to 'true' in their app.config. -->
<application xmlns="urn:schemas-microsoft-com:asm.v3">
<windowsSettings>
<dpiAware xmlns="http://schemas.microsoft.com/SMI/2005/WindowsSettings">true</dpiAware>
<dpiAwareness xmlns="http://schemas.microsoft.com/SMI/2016/WindowsSettings">PerMonitorV2, PerMonitor</dpiAwareness>
<longPathAware xmlns="http://schemas.microsoft.com/SMI/2016/WindowsSettings">true</longPathAware>
</windowsSettings>
</application>
<!-- Enable themes for Windows common controls and dialogs (Windows XP and later) -->
<!--
<dependency>
<dependentAssembly>
<assemblyIdentity
type="win32"
name="Microsoft.Windows.Common-Controls"
version="6.0.0.0"
processorArchitecture="*"
publicKeyToken="6595b64144ccf1df"
language="*"
/>
</dependentAssembly>
</dependency>
</assembly>
PPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDING
kernel32.dll
GetModuleHandleA
mscoree.dll
_CorExeMain
_^][ZYX
z:Zb5-
_^][ZYX
!This program cannot be run in DOS mode.
`.rdata
@.data
@.rsrc
@.reloc
RSDSiV@
Z:\Oreans Projects\SecureEngine\src\plugins_manager\internal_plugins\embedded dlls\TlsHelperXBundler\Release\XBundlerTlsHelper.pdb
.text$mn
.idata$5
.rdata
.rdata$T
.rdata$zzzdbg
.idata$2
.idata$3
.idata$4
.idata$6
.tls$ZZZ
.CRT$XLA
.CRT$XLZ
.rsrc$01
.rsrc$02
KERNEL32.dll
<?xml version='1.0' encoding='UTF-8' standalone='yes'?>
<assembly xmlns='urn:schemas-microsoft-com:asm.v1' manifestVersion='1.0'>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v3">
<security>
<requestedPrivileges>
<requestedExecutionLevel level='asInvoker' uiAccess='false' />
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
0$0(0,000
_^][ZYX
_^][ZYX
!bc>(Kw
T>vBir
;}\\21
&r54f^
_^][ZYX
_^][ZYX
_^][ZYX
_^][ZYX
_^][ZYX
5DB)~1
4$XRTZ
1y$]H%
/BqCN4
!2+HX
_^][ZYX
-xr{x5
_^][ZYX
_^][ZYX
_^][ZYX
/BXC'K
_^][ZYX
_^][ZYX
{j(_cd
XSWhRt
pAr=Fu
0JLe5l
ikO`,n
_^][ZYX
_^][ZYX
_^][ZYX
_^][ZYX
5i\H|!
=>'b5@
_^][ZYX
_^][ZYX
_^][ZYX
_^][ZYX
_^][ZYX
_^][ZYX
yX%|(Z]l7
_^][ZYX
uP;PC"n
_^][ZYX
_^][ZYX
_^][ZYX
hPiTCk
_^][ZYX
_^][ZYX
_^][ZYX
_^][ZYX
_^][ZYX
85<dnD
_^][ZYX
_^][ZYX
3,$1,$3,$\
_^][ZYX
_^][ZYX
?a[KB(
_^][ZYX
_^][ZYX
$VWhLP
_^][ZYX
_^][ZYX
?Wc/~S
_^][ZYX
_^][ZYX
_^][ZYX
_^][ZYX
_^][ZYX
sHvG3^(
_^][ZYX
_^][ZYX
_^][ZYX
_^][ZYX
_^][ZYX
_^][ZYX
1F|L[N
/BHpx+
_^][ZYX
_^][ZYX
NARR_\
jBI}x/
_^][ZYX
,Z+dHk
_^][ZYX
_^][ZYX
_^][ZYX
_^][ZYX
_^][ZYX
_^][ZYX
_^][ZYX
_^][ZYX
_^][ZYX
PQRSUVW
2_^][ZYX
_^][ZYX
_^][ZYX
f\,$wh
_^][ZYX
!2AL<3>
1+'UQ98
$s1B*U
_^][ZYX
_^][ZYX
_^][ZYX
_^][ZYX
5H6LN%
3,$1,$3,$\
[3<$1<$3<$
_^][ZYX
3<$1<$3<$\1
4$Y^RTZ
gDQY?}
1m=:B^
(5&&[K
_^][ZYX
_^][ZYX
\]]zj
$\VRhR
3<$1<$3<$\R
3,$1,$3,$\-
4$[ST[W
4$[WT_
34$14$34$
W\XO<([y
/bugcheckfull
/showinstance
PQRSUVW
_^][ZYX
*)G<[[
$h`/(j
4$XRTZ
34$14$34$\
f#?Q+h^
D2igT;
/bugcheck
_^][ZYX
_^][ZYX
$\QTYR
3,$1,$3,$
34$14$34$\U
^3,$1,$3,$\h(
)4$^Qh
4$\ST[
,$\QRhb
4$[VT^
3,$1,$3,$\
;m%7RO}V
-80n^[-
4$[VT^
34$14$34$\h
`/-wSS
[3<$1<$3<$\
3<$1<$3<$\
A"w|5
e/b[ndK
_^][ZYX
_^][ZYX
_^][ZYX
_^][ZYX
_^][ZYX
v`_ko/
.8P[Z-
_^][ZYX
/B0=(#
_^][ZYX
M^\6R0Er
_^][ZYX
0asS5
3,$1,$3,$\
6pw{1#
3<$1<$3<$
4$[VT^
+>=3cm
vtAY3
dEV!>w
~DP1zqZ
2%YDn#R_#
_^][ZYX
_^][ZYX
4$XVT^
_^][ZYX
/B+r\!
,$PhZX
<$Uh"J
$PTXVh
(>?Yhy
]34$14$34$\
X34$14$34$\
w-$2_^
_^][ZYX
3,$1,$3,$
RVhQse
4$[ST[
.?BHJ!
34$14$34$\Uh
m,&l/J*
zhP6G'
DXBH_FNT
PROC_OUT = %d, Process = %x
_^][ZYX
_^][ZYX
HrKB;x
3S-d>e
34$14$34$\
4$XUT]
4$XUT]
PQRSUVW
}]_^][ZYX
gh~;$w
WinLicenseInstance
hRvjg;
&4c$?m/
4$XWT_
WinLicenseVersion
ProcIN
gPXprotExit
kv$1\T
ah.<rN
|[V/!9
3,$1,$3,$\
CheckOUT
[{xpw[
OF;RBheT
PROC_OUT = %d
CHECK_IN = %d
~AfaUXE
_^][ZYX
_^][ZYX
WLSoftwareVersion
mBr/d
_^][ZYX
/Bk`(y
/BLiZ:
.zPkoZ
3<$1<$3<$\
6">uK;
_^][ZYX
>9~-U{
_^][ZYX
4$Ph|,
$hGDRh
^h4Y0M
4$YVT^
<$UhZ
[34$14$34$
X34$14$34$
w9Z_Vh
_^][ZYX
Np;/deactivate
_^][ZYX
&i0CN!
_^][ZYX
_^][ZYX
+BSm7m~
_^][ZYX
/dumpstatus
ExitOUT
$dp|O_
Z%)TTM
_^][ZYX
4$XWT_
$hODgY
3,$1,$3,$\
_^][ZYX
_^][ZYX
$hyX[ZXPZ
tCE|;w
_o*rY3
zT9}RY
4$YVT^
4$Xh}_XV
4$[WT_P
y-8keu
,$hml!s
4$YRTZ
3<$1<$3<$\
34$14$34$\
<$VT^R
DDDDDDDD
vH6L=+
4$XWT_
3<$1<$3<$\
_^][ZYX
K}$hci
<$h&)Y!_
34$14$34$\
3,$1,$3,$
3,$1,$3,$\
4$[WT_
3<$1<$3<$\VT^
34$14$34$\
]^3<$1<$3<$\
4$ZWT_
4$[QTY
3,$1,$3,$\
3,$1,$3,$
3<$1<$3<$\W
3,$1,$3,$
s-&-?-/
{~UVh8
LirDHe
_^][ZYX
_^][ZYX
34$14$34$\
34$14$34$\VS
Z34$14$34$\hb
3,$1,$3,$\
4$YUT]
3,$1,$3,$\h
4$[WT_
3,$1,$3,$
PROC_IN = %d, Process = %x
_^][ZYX
3,$1,$3,$\
34$14$34$\S
^3<$1<$3<$\
34$14$34$\
3<$1<$3<$\h=
4$[h3q
$hV}Hg
4$[WT_R
4$YVT^
v ?^UH
_^][ZYX
4$ST[V
4$\VQVh
3,$1,$3,$\W
4$YUT]Q
69'Ah!
_^][ZYX
4$YRTZ
4$ZWT_
4$XQTY
4$[RTZ
34$14$34$\
-{V_]R
3,$1,$3,$
3,$1,$3,$\
3,$1,$3,$
yRShd%ut[
4$YhrJdP
4$YVT^Q
$:VhG_
3<$1<$3<$
34$14$34$
$hnRL[
~sUhXOww]
4$XUT]
3,$1,$3,$\Rh$
4$[PTX
E_oZ34$14$34$\
4$XWT_
3<$1<$3<$\
3,$1,$3,$
,$he ?.
<$\WVR
w@@5kR
?<V+Pe
$Rh#0A
3<$1<$3<$\
4$[ST[
4++:99
_^][ZYX
TX<APH\|5
HHOOK_IN = %d
7ZT*[D$f
ExitOk
M\30&eM
_^][ZYX
l/nosplash
_^][ZYX
/forcerun
ua-VhJq
4$[WT_
_^][ZYX
sh/showcode
<u3>99
6_ZnD1
_^][ZYX
YNKLe7
3,$1,$3,$
4$Xh l
7a2-}!
_^][ZYX
_^][ZYX
gnX$ht
Ha0<^
_^][ZYX
_^][ZYX
&.6>defg
v iBExpInfo
CheckIN
/logstatus
/bugcheck2
_^][ZYX
6!fZw5
5rhI!)
]34$14$34$\
_^][ZYX
/getwlstatus
_^][ZYX
_^][ZYX
34$14$34$
J1zbz(
_^][ZYX
To(57P`p
Software\WinLicense
Software\WinLicense
[&S'<f
Exception Information
PROC_IN = %d
SplashClassName
*%p9-!
4$[ST[
^tj_]p
96O[6
_^][ZYX
[mExitIN
6{)tX)
WLProjectName
_^][ZYX
3<$1<$3<$
)t;@O1
_^][ZYX
TP_IN = %d
*gIqj)81
CHECK_OUT = %d
WLSoftwareName
/skipactivexreg
.WRmM%(
E%)o9`
_^][ZYX
53es+)
_^][ZYX
4$WT_P
(U!g6f
diUa$
&wWryL
WLProtectionDateTime
34$14$34$\
3,$1,$3,$
$$UVh7
+g?Q*U
WinLicenseDriverVersion
_^][ZYX
K1[9,k
_^][ZYX
4$ZVT^
Telegram Desktop
34$14$34$\
Tue Aug 27 02:37:26 2024
$PTXSh
$h:F++
4$XVT^
4$YST[W
QPhtQ.OX
$\VVhj
[hEo/q
Qu>6-9
8h*|VT
4$[ST[
34$14$34$\
Qkkbal
TProcOUT
afej+/
Please, contact the software developers with the following codes. Thank you. (version %d.%d.%d)
(press CTRL+C on this window to copy to clipboard)
CheckIN = %d
CheckOUT = %d
ProcIN = %d
ProcOUT = %d
ExitIN = %d
ExitOUT = %d
TPin = %d
HWIn = %d
IntV = %x, %x, %x, %x
7= MR0#p
m$kea9
4$[UT]
4$[RTZV
\/showcode2
^}m.1#
^3,$1,$3,$\
4$[QTY
4$ZST[
$h*-~!
3<$1<$3<$\
34$14$34$\
w2m`c&
v7/checkprotection
3,$1,$3,$
34$14$34$\
34$14$34$\S
4$ZPTX
/S^J82
3<$1<$3<$\Sh
$\YRWhV
4$hM_2
34$14$34$
}?o_]U
4$XST[
34$14$34$\
3,$1,$3,$\
34$14$34$\
4$YUT]
4$YUT]
$$QWhn
$UShvY
3,$1,$3,$\Q
4$YPTX
,$hh^G
3,$1,$3,$\
4$\RhLy5T
4$UUhv
4$YVT^
34$14$34$
3<$1<$3<$\
4$YQTY
WP]XRh
3,$1,$3,$\
p{OYh'
;b?ZBB
$QWh0A
hw?Zh0A
4$YST[
_34$14$34$\h
4$[ST[
4$XRTZ
3<$1<$3<$
$\PPha>
3,$1,$3,$\S
4$XWT_
Software\WLkt
Vo)+RmG
3,$1,$3,$\V
4$^RTZ
[3,$1,$3,$\
OQzBg,
5fKQ!g
*M'~&v
$h<!80
X>0DDb
4$[RTZ
4$[ST[
3<$1<$3<$
3,$1,$3,$\
4$XQTY
sEX6ho
4$XWT_
4$[WT_
4$YPTXU
4$ZRTZ
VQWcE_
3,$1,$3,$\
L.-xEe
X34$14$34$\
EthoMQ
3<$1<$3<$
4$[PTXV
4$_RTZ
<$\VT^
$h@nl:
4$XUT]
_3,$1,$3,$\
34$14$34$
4$\h)-
4$Whgk4
_3,$1,$3,$\
75-li$
3,$1,$3,$\
3<$1<$3<$\
4$XQTY
34$14$34$\
[&?BBv
3<$1<$3<$\Q
uBRo&r
3<$1<$3<$\
^3<$1<$3<$\
$[PVh\
<$Vh%T
$h4(UM
34$14$34$\
3<$1<$3<$\
4$XWT_R
3,$1,$3,$
jC3:2|^
4$[RTZ
Ph'7{MX
,$hK&)
1<$3<$\
X34$14$34$\
X3,$1,$3,$\Q
3,$1,$3,$\U
3<$1<$3<$\
4$XRTZ
[3<$1<$3<$\
4$XPTX
3,$1,$3,$\
2x+-+-#$
3<$1<$3<$
4$[VT^
d,}}X_
Y3,$1,$3,$\
3,$1,$3,$\
Z3,$1,$3,$\
34$14$34$\
<$QhO!- Y
$hCHwJ
XYhU7P/
3,$1,$3,$\Q
SWhb.(b_
3,$1,$3,$
,$hp1
<$\RSh
3<$1<$3<$
4$^VT^
3,$1,$3,$\
$VT^Ph
<$\Qhy
4$XWT_
4$[QTYU
$SPWhh[
4$[ST[
_3,$1,$3,$
4$YWT_
_3,$1,$3,$\
3<$1<$3<$\S
<$\RPR
4$YhtTY$
3<$1<$3<$
4$[RTZ
[3,$1,$3,$\
3,$1,$3,$\
]3<$1<$3<$\PS
}r!<\B
&c|v "
X^N1T5,eu
o(W&98
34$14$34$
4$[PTX
4$XVT^
34$14$34$\
<$Ph-+
4$\hB{
4$XST[
34$14$34$\W
$\ShM_6
3,$1,$3,$\
4$XPTX
Z3<$1<$3<$\RSh{
$RSh0A
3<$1<$3<$
tP5@=$
tP2it!|
tP%@.$rE
tP%@.$rE
mOvP}r
d1$B@6
t^=UvR
t^=UvR
vP;gsX=
}@.$rE
#uOxPs
vP;gxX=
eH-X<q
vP;gwVyY
vP;gxVyY
tX>qm
tP%@.$
uOvP}gu
tP%@.$
uOvP}q
tP%@.$
$Bi\ |
$BiD |
p1$BF5
p1$Bq1
vP;id'|
vP;ip'|
eOvP}gt
\1$Bq1
3!{H7R
mgt$h}
BV|$hi
x^4U[P{Hyc
9P3|C#
yOkXF
H:Viqm
}HDP:c
u|PDH%
_^BV&X
}HK^BU
'_Pf@9
"yOUXD
]|PLB2%B
0wH{Rz
#uOxPs
]|PLF2
}HK^4U
5H7,-J
}HK^4U
0wH{Rz
0wH{Rz
0wH{Rz
?EB!}
U#$BH
*UL2$B
*Up1$B
BV|3d<u
3|UTXU
Uc+$BH%R
$|VV^KV
1$BH;3L
BV|$h%
={5k|{53i
U"0$Bz
#BVy3%u
wHdU{Z
eH}^4U
uP^/[^P
^=[bP
^4U ^KU
}UH^KUD$
1$Bz5P
P|^KUX
tQ{IzQ
x&N&1$
Q{Iz,:
}V#ZDAu
t(rlz(rl
t,<A2$BV
(r\y(r\
1$BVO,<
5yH{Rz@
t(rlz(rl
:bUdP<
|P-HC3
#TP1$BH
}H4PX~5
U4K$Bgt
%eOMk|
BH?PO@
P;Dz^=Uy
UH3$B@9
+BV|^KU}P3
N=:4;b
=~5PBv
}@=$T?u
-H%3d]t
PX~5PBv
=~5PBv
1PX~5PBv
BV,3BWt
x1$Bc~
t1$Bwt
1_&VZV
\1$BP~
l1$BPW
t0kcmV
l<TuXU
gr?$%B
Gr?@%B
r54VyNv
^=UfP5N
%uVLh||
%wVLh||
}cm*r?
}cm*r?
cm*r?f
cm*r?~
wcm+r?
cm*r?&
wcm+r?
}cm*r?
wcm+r?"%B
wcm+r?N%B
cm+r?:%B
wcm+r?
_=Uh3<et
UX^KU~P
VvS{H7P.{
PX~5PBv
PX~5PBv
PX~5PBv
X00~@B$
1$Tu1$B
2^BVUP{@
0^=USP
~xk|~6
t^4U~P|J
HwR{H;X
}{5PBs
A1$B@5Y
O{PFH&2<
6Q>Uvk|I
BUvh|H
}H'PEH
PX~5PBv
Ru~5PBv
%OvP5@5
23$BF<
10YHFR
|0$BFG
_xa0$BJ
|0$B@G
*$BH?R
1Py?*~1
*$BH/P
1$}gt0
U;#$Bz
1/$B@G
+$BH?R
*$BHC^&
+$BHyYJ&A-B
^BUhXDP
|0$BH:
-$BVxQ?
a0$B@G
|0$B@9
2$BH7R
1$rFa'B
1$}gt0
`0$Bi@
*$BH?R
*$BVvP'J
0/$Bi@
,+$BF5
1$r45XGP
1$r44XGP
1$}U}V
1$n6Q-B
1$BV03
/$BJvV
PX~5^KV
8^4U[P
4^=VwXF
JfLP5H
Pv@qP}VyX<
}E50pN
x@=$VO
m@=$V~
UY2$B@-
={5P3{
1_=U'$
40ggt$
Ur)$BF5
3~UgXU
O1$B@-
<0~@=$
u{5XGe
u{5PBs
}1_&UzX=
6SzP<H>P%
#yUwXE
>gv0Ig|0M
?U|Ptq
3|U_XU
1$:Fe&B
t^=UgP
}cm+r?[
}cm+r?
}cm+r?
}cm+r?
<0~@=$
}cm+r?[
}cm+r?
}cm+r?
}cm+r?
<0~@=$
Uv,#HS[
t&Ts+$BH2
=H-P%H
RsH:P.|
.3$B@7
.3$B@5
0s|V|X2
PX~5PBv
}z5PBv
,^=U}P5
1PX~5PBv
HH>^4UyP
1PX~5PBv
i33u)t
mH%^KU
}VvP#N
/BV03d
mH;PJ
u,P2H7
yH$0vG
u^=V#Q{E5
tU_^/UU^BUuSz
u^BUwQ{Iz
/$B@pC
}H%^KVwX2
^=VwX2
LG{_=V
U{1$Bz
}H;3`b1$?
HuPeFN
U P}HuPuH
pxP|HuR
P}He^KV|X5
},PvH|R|N
Uy#$Bs
$Bz5z]
^=UK0p
^=UK0p
HuPX~5PBv
m~5PBv
U$2$Bz
t^=Vzc
2$B@B$:
|^=UuX
mH=^4U
1$Tm1$BH2
U^1$BN
PX~5PBv
uH}ZDA
U)*$BH
}H%^KU
/$Bgt3
U|1$BF5
U`E$B@=$
;^yP; 5
#CUx^=Vy
={5PBs
($B@X
m~5PBv
}z5PBv
M[vPMte$
0Pu@,$
"CUmQn
s0{g'0
^=U~Py
k|{5PBv
2P7H'X\
P?gTX]
P;Dz^=Uy
Utq$BH
U(s$BH
/$BH%X9
U^0$BH%X9
1PX~5PBv
MUdP*HLPwN
^KVwX2
mH-XC
1_4U[[D
PDHj0v
$BgtR{
qH{P}H
mH{P}H
/PX~5PBv
1$;F1%B
UT/$Bz
$BH-X6
TS1$BAp
$BH-Pp
mUd^KU
}@=$T-u
@H7PX~5PBv
m~5$he
^=UzP"
$Bz5PBv
1PX~5PBv
1$BV|b
%i[mXC
u@=$T/t
%vUwXC
1PX~5z
;PvPMN
t^4Uu+B
mU{PlFG
U-F$Bz
U|^KUTZC18
UqE$Bz
t^4Uu+B
N$BH-Pp
$Bz5P;
$Bz5PBv
U[1$Bz
s|UXPz
tP<~5PBv
U!2$BN
PX~5PBv
2$BJyf-
m~5PBv
Uj@$B@U
PX~5PBv
UK3$B@9
2$BHSR
}^=UOP
0|UwXW
PX~53P
|]vPMH
%]SW3D
t35=2$
$B@=$Vr
-r65^=V
s|U|3[
3!{H:X]
U&$Bz
UF2$Bz
q@-$rE
Uv-$Bz
PX~5PBv
UPy$BH
$Bz53+
]D^4Vy
$B@=$T(t
H4,-)t
3}UbXU
t0f*2$r
P}HeP+
$Bz5PBv
1PX~5PBv
mPaP;HKX]
$BgsPM
1$BOv,$H4
4)ry3)ry:)ry9
a1$B8+^
X@ S|3b
PX~5PBv
4PX~5PBv
xPQB!S}
Uv:$Bz
,PX~5PBv
=~5PBp
U{1$Bz
UX-$BH
+|Uw^BVs
3|UVXU
}J{0mH{
3|U{XU
}~53\82$:
1$BV|3
}Vx^=Ux
=~5PBv
U]1$Bz
Uo1$B@9
#PMH6,
uHyVIJt
tQ{IzQ
x&N&1$
Q{Iz,:
}V#ZDAu
t(rlz(rl
t,<A2$BV
(r\y(r\
1$BVO,<
5yH{Rz@
t(rlz(rl
:bUdP<
U\K%BH
A2f[2$T
,5\`0x
A.t,vs
9!`^gy
y!QIHw<wr
}Eu_}Eu_}Eu_}Eu_}Eu_}
tZ|BtZ|BtZ|Bt
tY|?tY|?tY|?t
t_}Eu_}Eu_}Eu_}Eu_}Eu
}BuZ}BuZ}BuZ}
}?uY}?uY}?uY}
}`:,G r
3,$1,$3,$\
4$[huFZ'
3,$1,$3,$
3<$1<$3<$\
$Zh;tn`
ttE2^%
3,$1,$3,$
4$XUT]
4$XQTY
34$14$34$\
3<$1<$3<$\
34$14$34$\
34$14$34$\
$UT]Qh
YH-D;m>
[34$14$34$\
4$XST[
3<$1<$3<$\
3<$1<$3<$
4$XPTX
4$[UT]
4$XQTYR
VC03"z
[34$14$34$\
4$XQTY
4$[VT^
+kiXkU
4$XQTY
3,$1,$3,$\
3<$1<$3<$\h
,$\UT]
34$14$34$
lo~2-lEJ
f[fQfh
4$\h]>
3<$1<$3<$\hu
$\hrw!
3<$1<$3<$\
<$\SShw.
$\hX$Y0
4$[QTY
34$14$34$
4$\hEF\?
4$ZVT^
$\h$kc^
3,$1,$3,$\U
4$\VT^
$ZhK-$h
4$XRTZ
<$Whtf
3<$1<$3<$\
3<$1<$3<$\
4$[RTZP
X34$14$34$\h
$h*Jmz
4$XST[
3,$1,$3,$\
Y3<$1<$3<$\
4$ZWT_
4$QTYP
$\UPhI
4$XUT]
,$\PTX
$\h"~!4
4$XPTX
,$\hG>
3<$1<$3<$\
3,$1,$3,$\
,$\QTY
4$[UT]
34$14$34$\R
3,$1,$3,$\
3,$1,$3,$
34$14$34$\
X3<$1<$3<$\
_34$14$34$\h
3<$1<$3<$\
3<$1<$3<$\
34$14$34$\
4$XST[
3,$1,$3,$\P
$[ho:Pi
4$XST[
4$XPTX
4$ZPTX
3<$1<$3<$\S
s5%9~.H
34$14$34$\
3,$1,$3,$\
4$[PTX
4$[WT_
$h5~:1
3,$1,$3,$\
$\hZs}l
4$^ST[
3<$1<$3<$\
. 9lf
zOich:7
4$XPTX
4$[QTY
lX34$14$34$\
4$[QTYW
4$ZQTY
4$ZWT_
4$XWT_
W.yCj
]?6|I+
3<$1<$3<$
4$\h9:8)
3,$1,$3,$\h
34$14$34$\W
34$14$34$\hZ
4$\QQho
34$14$
Z3<$1<$3<$\
4$\h~6=}
4$\WT_S
34$14$34$\h
$\h)DY5
4$ZST[
34$14$34$\
4$^ST[
4$XUT]
3<$1<$3<$\S
4$XWT_
3<$1<$3<$\VT^
^3<$1<$3<$\P
,$\PTX
Sp-qn
3<$1<$3<$
y\jZIF
,$\WT_
3<$1<$3<$\
;P8Kp0
,$\WT_S
<$\hBPc
34$14$34$\
34$14$34$\VT^
4$[UT]
34$14$34$\
4$[QTYR
$Xht]h|
3<$1<$3<$\
$XhowW
2! 1Ew
3,$1,$3,$\S
3<$1<$3<$\Q
R7-/[gC/
3,$1,$3,$\Q
3<$1<$3<$\W
3<$1<$3<$\
[3,$1,$3,$\R
$ZST[Q
~i9$QTY
4$XQTY
34$14$34$\h
4$XQTY
3<$1<$3<$\
3,$1,$3,$\S
3<$1<$3<$
34$14$34$\
34$14$34$\SQh
34$14$34$\PW
{XBRN'CO
VVPifuq
,$\hNsr}
4$XUT]
34$14$34$\
3<$1<$3<$
4$ZVT^
$ZhXhq]
`Xs}N#,
4$_hGU
4$XUT]
4$XWT_
+6 ,gh7
$\hXg4w
34$14$34$\
4$XST[
3,$1,$3,$\
^3<$1<$3<$\
4$XVT^
Z34$14$34$
~;w.Bv
4$]PTXU
34$14$34$\
3<$1<$3<$\
s@t:z_S
3,$1,$3,$\U
"S/DE|
3,$1,$3,$
4$]QTY
4$[QTY
4$XPTX
3<$1<$3<$\
4$[UT]
4$XQTY
4$ZVT^
3,$1,$3,$
4$ZRTZ
4$XVT^
3<$1<$3<$\
4$ZUT]
3<$1<$3<$\
4$XRTZ
jJ{/*q
DwtSM#
3,$1,$3,$\
$hi2qG
<$\h:4A4
4$[QTY
<$PTXQ
$XhJa<t
3<$1<$3<$
3,$1,$3,$\
4$\RTZ
4$ZUT]
_34$14$34$\
Z3<$1<$3<$\
3,$1,$3,$
$hg5!
4$XWT_
4$XUT]
,$\hy$6<
3<$1<$3<$
34$14$34$\U
34$14$34$\
4$XST[
<$\ST[
,$h|)&&
3,$1,$3,$
4$XWT_
4$[UT]
4$XUT]
4$XWT_
3<$1<$3<$\h
,$\h#"
nw,=d4
4$XWT_
lxO_z5
t\52jG
r#)]b~[
+^oe/.
3,$1,$3,$\
]3<$1<$3<$\
oM:Rr,
zKmbLP
$Rhk,@
$hc_%J[
[3,$1,$3,$\
7,%?dF
>OTH&qe
4$[RTZP
4$[h:G
3,$1,$3,$\
3,$1,$3,$\
4$ZQTY
4$ZUT]
$h)I e
3<$1<$3<$\
3<$1<$3<$\S
$\h\j0
3<$1<$3<$\
_34$14$34$\
4$[WT_
4$XVT^
34$14$34$\
4$XVT^
4$UhW{=
3<$1<$3<$\
^3<$1<$3<$\
4$XST[
)7F|0G
3,$1,$3,$
4$[ST[
4$[RTZ
4$[RTZ
PhWs/+
34$14$34$\
$\VT^P
<$h/W=
4$[UT]
34$14$34$\
3,$1,$3,$\V
4$XPTX
3<$1<$3<$\
$QhTPxJY
,$\QTY
k/VByT
3<$1<$3<$
4$[UT]
^3,$1,$3,$\
3,$1,$3,$
E7a6_f
34$14$34$\
4$XQTY
4$XVT^
4$[UT]
34$14$34$
4$XVT^
,$\hI`
_34$14$34$\
4$XVT^
KTvY.X
3<$1<$3<$\
34$14$34$\
3<$1<$3<$\
4$ZQTY
3,$1,$3,$
4$[QTY
34$14$34$\
3,$1,$3,$\V
K,en=@~
<$\hD4`,
/63k:Q
$\UT]R
3,$1,$3,$\
5&,&q-Z
<$Uhkq<
[(jf^
3<$1<$3<$
n_!ayS
Z3<$1<$3<$\
e.v%9 z
$\UT]V
Z3,$1,$3,$\
4$[RTZ
<$\QTYP
3,$1,$3,$\
4$\VT^
3<$1<$3<$\
<$\WT_
*v*w[B
W+s1j(]
,$\Rhr
6'-fcz
3,$1,$3,$\U
34$14$34$\
4$XQTY
z\Ja7.
34$14$34$\
4$[QTYP
3<$1<$3<$\
4$ZQTY
4$XQTY
3,$1,$3,$\S
3<$1<$3<$\
<$WT_S
3,$1,$3,$\
4$[ST[
34$14$34$\
O(y93z
4$XWT_
d{Wac
qty`w`
X[Z~t9
,$\UT]
4$XRTZ
$[hQ"4
34$14$34$\
4$[QTY
3,$1,$3,$\
4$[ST[
$\h4J,
4$ZRTZ
4$[PTX
4$XPTXR
31f[XIf
4$[VT^
34$14$34$\
y=w4'+
`&~h/
"[,8\5
-\J UQ}
3,$1,$3,$\R
3,$1,$3,$\
3<$1<$3<$\
<$Vh'o=
4$\ST[
PRShw2
$\QVh7
3<$1<$3<$\S
3,$1,$3,$\S
$\hRNq$
$hE7./
4$[VT^
[34$14$34$\
4$XUT]
4$[PTX
1<lEm?
q2FPcV
3<$1<$3<$
Duo9G&SH
J{Ocy9
ZW;btZ
34$14$34$
g=6s83
?xpn6\&
X3,$1,$3,$
$h"jbl
3<$1<$3<$
3,$1,$3,$\
4$XPTX
[34$14$34$\
34$14$34$
4$XVT^
Y#,hZ?n
4$Sh3 <
34$14$34$\
4$\RWQ
3<$1<$3<$\
]3<$1<$3<$\
$fhITfXf1
X3<$1<$3<$\
34$14$34$\
3,$1,$3,$\
34$14$34$\hhr
,$\hy+`}
3<$1<$3<$\
4$\UT]
34$14$34$\
34$14$34$\
,$\UT]
4$[WT_
4$ZUT]
4$[QTY
4$XRTZ
4$[ST[
4$[h[j
3,$1,$3,$\
3,$1,$3,$\
3<$1<$3<$\V
X3,$1,$3,$\h
<$WhPj
4$XRTZ
4$[hsW
Z3,$1,$3,$
$Xh6,|y
Uh|DQ"
$\hRuXX
3,$1,$3,$\
$$h?eXJ
,$\VPh
4$[WT_
Z3,$1,$3,$\
X34$14$34$\
,$\hAt
4$ZQTY
3<$1<$3<$
3,$1,$3,$\QR
^3,$1,$3,$\
4$[ST[
4$ZWT_
3<$1<$3<$\
4$XRTZ
4$ZWT_
4$XST[
$\hu#?J
4$ZST[
$h#vnL
34$14$34$\h
4$YQTY
"dcOb
4$\hs%
4$XQTY
34$14$34$
3,$1,$3,$
4$[UT]
3,$1,$3,$\S
$XUT]Q
4$[RTZ
34$14$34$
4$XQTY
34$14$34$\
4$XQTY
[34$14$34$\
[3,$1,$3,$\
3,$1,$3,$\
34$14$34$\
4$XPTX
3,$1,$3,$\
4$[UT]
3,$1,$3,$\
4$[PTX
3<$1<$3<$\
4$[RTZ
3<$1<$3<$\
3,$1,$3,$\Q
4$XST[
,$\ST[
4$[VT^
34$14$34$
3<$1<$3<$\S
3<$1<$3<$\h
4$XVT^
3,$1,$3,$\
$XhR"Vf
<$\h;N
3<$1<$3<$
<$\QUP
4$\hgM
I"(?w#
34$14$34$\
34$14$34$\W
34$14$34$\
3<$1<$3<$
$Xh}* :
4$ZST[
4$XWT_
4$XUT]
3<$1<$3<$\S
,$\QTY
3<$1<$3<$
34$14$34$\
<$\Uh2
34$14$34$
Z34$14$34$\Q
$\hDDen
4$\h"W
<$\ST[
$$SSh-
$\h8zef
4$XWT_
4$XQTY
$\VT^P
1<$3<$\
4$[RTZ
-,[9v)
<$\WT_R
4$XST[
4$[QTY
34$14$34$\
J&u^98
4$XhKR
3,$1,$3,$
[3,$1,$3,$\
4$ZUT]
4$[QTY
4$[ST[
34$14$34$\Q
3<$1<$3<$\
{|4]4d
34$14$34$\
4$ZUT]
4$ZUT]
,$\hkp
4$\hq~e%
B:j"f6
$\VT^U
34$14$34$\
4$XQTY
34$14$34$\U
34$14$34$
<$\ST[
3<$1<$3<$\R
3<$1<$3<$\S
$$h&q9j
<$\VT^P
3,$1,$3,$\
4$[RTZ
3,$1,$3,$\
$[h$YRD
3<$1<$3<$\
3,$1,$3,$
_34$14$34$\
]3<$1<$3<$\
3,$1,$3,$\
3,$1,$3,$
4$ZST[
4$Xhjj
$$RWh2
4$[ST[
$\hn,M'
3,$1,$3,$\
,$\UT]
$h/aj?
4$\QTY
QWh@RD<_
<$\PTXU
{m%NL[
4$[VT^
4$XST[
3<$1<$3<$\
4$\RhH
4$[QTY
Z34$14$34$\
34$14$34$\
4$[ST[
$$QPh+
34$14$34$\W
,$\ST[
,$\WT_
3<$1<$3<$\
4$XQTY
3,$1,$3,$\Q
<$\ST[
g&4nc~
RQhg|K
3<$1<$3<$\
4$_UT]
3,$1,$3,$\P
3,$1,$3,$
34$14$34$\
34$14$34$\
34$14$34$\
4$XST[
4$\huN
4$[ST[
34$14$34$\
4$[PTX
4$XST[
34$14$34$\
4$XST[
*doCb
4$XVT^
4$Xhy[D
34$14$34$
4$Xhnk
c7#a$
34$14$34$\
4$[QTY
3<$1<$3<$\
4$XUT]
[34$14$34$\
4$[RTZ
3,$1,$3,$\
4$XhL3
34$14$34$\
<$\hP2
3,$1,$3,$\
{.4I'
3<$1<$3<$\
3<$1<$3<$
3,$1,$3,$\
3<$1<$3<$\R
4$_WT_
4$XST[
4$XRTZ
4$[QTY
4$XVT^
]3<$1<$3<$\S
4$XST[
3,$1,$3,$\S
$\RWhwH
34$14$34$\R
4$XRTZ
3<$1<$3<$\S
4$]QTYS
34$14$34$\h
%t7Ct6
4$[RTZ
4$\QTY
34$14$34$\S
4$ZQTY
34$14$34$\W
4$XST[
3,$1,$3,$\
4$XPTX
34$14$34$
34$14$34$\
3<$1<$3<$\
3<$1<$3<$\
3<$1<$3<$
34$14$34$\S
4$[VT^
4$ZPTX
34$14$34$\
3<$1<$3<$\
4$ZPTX
,$QhmW
34$14$34$\
34$14$34$\
$[RTZQ
4$XPTX
3,$1,$3,$\R
A=WpE
34$14$34$\SQ
4$_PTX
4$\QTY
Ph%1t}XH
$Ph4Zl7X
3,$1,$3,$\
4$ZVT^
3,$1,$3,$\
,$\UT]
3<$1<$3<$\
3<$1<$3<$\
3,$1,$3,$\
4$ZST[
34$14$34$\
4$XST[
XUh22*B
34$14$34$
3,$1,$3,$\
$$hG[0
3,$1,$3,$\
4$ZWT_
$\VPh!
4$[ST[
3<$1<$3<$\
$\hDSR{
4$XRTZ
4$_PTX
4$XWT_
4$XVT^
4$XWT_V
4$ZVT^
4$\hwGY,
$h+S@v
3,$1,$3,$\
3<$1<$3<$\
4$\QTY
4$XST[
34$14$34$\W
$\h=y,
4$XST[
3<$1<$3<$\S
<$\h8Q
34$14$34$
Zh?odH
$h-&v{
3,$1,$3,$\
4$ZWT_
$hq{bA
4$\VT^
34$14$34$\
4$[VT^
3,$1,$3,$
$\hUG/>
4$XRTZ
3,$1,$3,$\
3<$1<$3<$\
RWhqoD
,$\ST[
3,$1,$3,$
4$\h\2
Z34$14$34$
34$14$34$\
4$[QTY
+A4Zee
4$XRTZ
,$\hQ*
34$14$34$\
4$Zh)$
4$\WT_
[3<$1<$3<$\
$hM)7
3<$1<$3<$
$\ha6Ij
4$ZWT_
,$\RhZ
[6,iHF^
$\hOG;
3,$1,$3,$\V
Z3,$1,$3,$\
4$hJ@Oe^
4$XRTZ
S7m#*a]z<
4$XST[
4$XQTY
4$ZPTX
<$\ST[P
4$]VT^
<$\ST[
4$XRTZ
4$XRTZ
,$\ST[
<$\WT_
3<$1<$3<$\Q
3,$1,$3,$\
,$\PTX
3,$1,$3,$\
4$XRTZ
$\hmTIc
$PTXSh
<$PTXV
34$14$34$\hI
$\htu~
34$14$34$\U
,$\WT_
34$14$34$\
3,$1,$3,$\
3,$1,$3,$\
4$[UT]
3,$1,$3,$\
4$XUT]
3<$1<$3<$\
3,$1,$3,$\
$h~QaqX
Antivirus Signature
Bkav W32.AIDetectMalware
Lionic Trojan.Win32.DInvoke.4!c
Elastic malicious (high confidence)
ClamAV Clean
CMC Clean
CAT-QuickHeal Clean
ALYac Trojan.GenericKD.73978811
Cylance Unsafe
Zillya Clean
Sangfor Suspicious.Win32.Save.a
CrowdStrike win/malicious_confidence_70% (D)
Alibaba Trojan:MSIL/DInvoke.12e8605e
K7GW Trojan ( 005ba1be1 )
K7AntiVirus Trojan ( 005ba1be1 )
huorong Clean
Baidu Clean
VirIT Trojan.Win32.Genus.WKI
Paloalto generic.ml
Symantec Trojan Horse
tehtris Generic.Malware
ESET-NOD32 a variant of Win32/GenKryptik.HBGQ
APEX Malicious
Avast Win32:CrypterX-gen [Trj]
Cynet Clean
Kaspersky Trojan.MSIL.DInvoke.bpw
BitDefender Trojan.GenericKD.73978811
NANO-Antivirus Virus.Win32.Gen.ccmw
ViRobot Trojan.Win.Z.Wacapew.6807040
MicroWorld-eScan Trojan.GenericKD.73978811
Tencent Malware.Win32.Gencirc.14189437
Sophos Mal/Generic-S
F-Secure Trojan.TR/Redcap.lwvnv
DrWeb BackDoor.AsyncRATNET.1
VIPRE Trojan.GenericKD.73978811
TrendMicro Backdoor.Win32.ASYNCRAT.YXEH5Z
McAfeeD Real Protect-LS!19574D1C471C
Trapmine malicious.high.ml.score
CTX exe.trojan.msil
Emsisoft Trojan.GenericKD.73978811 (B)
Ikarus Trojan.Win32.Themida
FireEye Generic.mg.19574d1c471ceaa9
Jiangmin Trojan.MSIL.apfpq
Webroot Clean
Varist W32/ABTrojan.SCPV-3960
Avira TR/Redcap.lwvnv
Fortinet PossibleThreat.PALLAS.H
Antiy-AVL Trojan/MSIL.DInvoke
Kingsoft Win32.HeurC.KVMH008.a
Gridinsoft Trojan.Win32.AsyncRAT.tr
Xcitium Clean
Arcabit Trojan.Generic.D468D3BB
SUPERAntiSpyware Clean
ZoneAlarm Trojan.MSIL.DInvoke.bpw
Microsoft Trojan:MSIL/AgentTesla.LQL!MTB
Google Detected
AhnLab-V3 Trojan/Win.MSILZilla.R522143
Acronis Clean
McAfee Artemis!19574D1C471C
TACHYON Clean
VBA32 BScope.TrojanPSW.MSIL.Reline
Malwarebytes Generic.Malware.AI.DDS
Panda Clean
Zoner Probably Heur.ExeHeaderL
TrendMicro-HouseCall Backdoor.Win32.ASYNCRAT.YXEH5Z
Rising Trojan.DInvoke!8.16EDB (CLOUD)
Yandex Clean
SentinelOne Static AI - Malicious PE
MaxSecure Trojan.Malware.277780955.susgen
GData Trojan.GenericKD.73978811
AVG Win32:CrypterX-gen [Trj]
DeepInstinct MALICIOUS
alibabacloud Trojan:Win/DInvoke.bjx
No IRMA results available.