Static | ZeroBOX

PE Compile Time

2024-09-17 02:08:27

PE Imphash

142e7fec3bbae1af3a6f0d1369c091e9

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x00023498 0x00023600 6.43000715112
.data 0x00025000 0x00000370 0x00000400 4.08951354977
.rdata 0x00026000 0x00007200 0x00007200 5.92809770465
.pdata 0x0002e000 0x00001c8c 0x00001e00 5.12534012667
.xdata 0x00030000 0x00001a98 0x00001c00 4.16087118244
.bss 0x00032000 0x00015340 0x00000000 0.0
.idata 0x00048000 0x00000b24 0x00000c00 4.17138746332
.CRT 0x00049000 0x00000060 0x00000200 0.312493774595
.tls 0x0004a000 0x00000010 0x00000200 0.0
.rsrc 0x0004b000 0x00000228 0x00000400 3.40841560204
.reloc 0x0004c000 0x00000144 0x00000200 3.72999288327

Resources

Name Offset Size Language Sub-language File type
RT_MANIFEST 0x0004b058 0x000001ca LANG_ENGLISH SUBLANG_ENGLISH_US XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators

Imports

Library KERNEL32.dll:
0x1400482c0 CloseHandle
0x1400482c8 CreateToolhelp32Snapshot
0x1400482d0 DeleteCriticalSection
0x1400482d8 EnterCriticalSection
0x1400482e0 FlushInstructionCache
0x1400482e8 GetCurrentProcess
0x1400482f0 GetCurrentProcessId
0x1400482f8 GetCurrentThreadId
0x140048300 GetLastError
0x140048308 GetModuleHandleW
0x140048310 GetProcAddress
0x140048318 GetSystemInfo
0x140048320 GetThreadContext
0x140048328 HeapAlloc
0x140048330 HeapCreate
0x140048338 HeapDestroy
0x140048340 HeapFree
0x140048348 HeapReAlloc
0x140048358 IsDBCSLeadByteEx
0x140048360 LeaveCriticalSection
0x140048368 LoadLibraryA
0x140048370 MultiByteToWideChar
0x140048378 OpenThread
0x140048380 ResumeThread
0x140048388 SetThreadContext
0x140048398 Sleep
0x1400483a0 SuspendThread
0x1400483a8 Thread32First
0x1400483b0 Thread32Next
0x1400483b8 TlsGetValue
0x1400483c0 VirtualAlloc
0x1400483c8 VirtualFree
0x1400483d0 VirtualProtect
0x1400483d8 VirtualQuery
0x1400483e0 WideCharToMultiByte
Library msvcrt.dll:
0x1400483f0 __C_specific_handler
0x1400483f8 ___lc_codepage_func
0x140048400 ___mb_cur_max_func
0x140048408 __getmainargs
0x140048410 __initenv
0x140048418 __iob_func
0x140048420 __set_app_type
0x140048428 __setusermatherr
0x140048430 _amsg_exit
0x140048438 _cexit
0x140048440 _commode
0x140048448 _errno
0x140048450 _fileno
0x140048458 _fmode
0x140048460 _initterm
0x140048468 _lock
0x140048470 _onexit
0x140048478 _setjmp
0x140048480 _setmode
0x140048488 _unlock
0x140048490 abort
0x140048498 calloc
0x1400484a0 exit
0x1400484a8 fflush
0x1400484b0 fprintf
0x1400484b8 fputc
0x1400484c0 free
0x1400484c8 fwrite
0x1400484d0 localeconv
0x1400484d8 longjmp
0x1400484e0 malloc
0x1400484e8 memchr
0x1400484f0 memcmp
0x1400484f8 memcpy
0x140048500 memset
0x140048508 signal
0x140048510 strerror
0x140048518 strlen
0x140048520 strncmp
0x140048528 vfprintf
0x140048530 wcslen

!This program cannot be run in DOS mode.
`.data
.rdata
@.pdata
@.xdata
.idata
@.reloc
ATUWVSH
[^_]A\
[^_]A\
AUATUWVSH
[^_]A\A]
ATUWVSH
@[^_]A\
AUATUWVSH
H[^_]A\A]
ATUWVSH
`[^_]A\
AVAUATUWVSH
[^_]A\A]A^
AWAVAUATUWVSH
[^_]A\A]A^A_
AWAVAUATUWVSH
[^_]A\A]A^A_
AVAUATUWVSH
@[^_]A\A]A^
AVAUATUWVSH
[^_]A\A]A^
ATUWVSH
[^_]A\
@ L9B u
B0H)r(H9r(}NH
AUATUWVSH
([^_]A\A]
I9@ }E
SH;A ~MH
B H;A }
ATUWVSH
[^_]A\
H;B0s:L
AWAVAUATUWVSH
H[^_]A\A]A^A_
AUATUWVSH
([^_]A\A]I
([^_]A\A]
([^_]A\A]
ATUWVSH
[^_]A\
[^_]A\
[^_]A\
AUATUWVSH
([^_]A\A]
([^_]A\A]
([^_]A\A]
AWAVAUATUWVSH
8[^_]A\A]A^A_
AUATUWVSH
([^_]A\A]
AUATUWVSH
([^_]A\A]
ATUWVSH
Error: uH
nhandledH
eption: H
dled excH
[^_]A\
AVAUATUWVSH
[^_]A\A]A^
x2H;X s,I
AUATUWVSH
H[^_]A\A]
H[^_]A\A]
H[^_]A\A]
AUATUWVSH
8[^_]A\A]
8[^_]A\A]
8[^_]A\A]
AVAUATUWVSH
[^_]A\A]A^
[^_]A\A]A^
AUATUWVSH
([^_]A\A]
AWAVAUATUWVSH
I9~ H
I;} H
([^_]A\A]A^A_
AWAVAUATUWVSH
([^_]A\A]A^A_
AWAVAUATUWVSH
([^_]A\A]A^A_
AWAVAUATUWVSH
H[^_]A\A]A^A_
AWAVAUATUWVSH
[^_]A\A]A^A_
AWAVAUATUWVSH
[^_]A\A]A^A_
AUATUWVSH
([^_]A\A]
AUATUWVSH
([^_]A\A]
AVAUATUWVSH
[^_]A\A]A^
AUATUWVSH
invalid H
integer:H
H[^_]A\A]
AUATUWVSH
([^_]A\A]
AVAUATUWVSH
[^_]A\A]A^
AWAVAUATUWVSH
8[^_]A\A]A^A_
AUATUWVSH
([^_]A\A]
AWAVAUATUWVSH
8[^_]A\A]A^A_
AWAVAUATUWVSH
([^_]A\A]A^A_
ATUWVSH
[^_]A\
AUATUWVSH
[^_]A\A]
[^_]A\A]
AWAVAUATUWVSH
<<"wbH
xH;3}sH
<<"w=H
H;3}*H
H;;}EH
8[^_]A\A]A^A_
AWAVAUATUWVSH
8[^_]A\A]A^A_
ATUWVSH
`[^_]A\
`[^_]A\
AWAVAUATUWVSH
([^_]A\A]A^A_
AVAUATUWVSH
[^_]A\A]A^
AWAVAUATUWVSH
D$0QZ^&H
D$0D")
[^_]A\A]A^A_
AVAUATUWVSH
[^_]A\A]A^
AWAVAUATUWVSH
([^_]A\A]A^A_
tH;;}
AUATWVSH
[^_A\A]]
U H9P0~&H
H H9Y0
ATWVSH
[^_A\]
AVAUATUWVSH
;MZtwH
IcD$TH9
[^_]A\A]A^
ATWVSH
H;0uUH9
[^_A\]
AUATUWVSH
([^_]A\A]
AWAVAUATUWVSH
X[^_]A\A]A^A_
@0H+B0H
AWAVAUATUWVSH
x[^_]A\A]A^A_
AWAVAUATUWVSH
D$PM#a0H
x[^_]A\A]A^A_
L$PL9\$Xu.
AWAVAUATUWVSH
d$@tkL
X[^_]A\A]A^A_
t%H;+} H
ATUWVSH
[^_]A\
[^_]A\
AWAVAUATUWVSH
([^_]A\A]A^A_
([^_]A\A]A^A_
AWAVAUATUWVSH
([^_]A\A]A^A_
AVAUATUWVSH
[^_]A\A]A^
AWAVAUATUWVSH
H[^_]A\A]A^A_
AWAVAUATUWVSH
8[^_]A\A]A^A_
AUATUWVSH
([^_]A\A]
AUATUWVSH
([^_]A\A]
AWAVAUATUWVSH
8[^_]A\A]A^A_
AWAVAUATUWVSH
([^_]A\A]A^A_
AWAVAUATUWVSH
H[^_]A\A]A^A_
AVAUATUWVSH
P[^_]A\A]A^
AWAVAUATUWVSH
[^_]A\A]A^A_
ATUWVSH
[^_]A\
AWAVAUATUWVSH
H[^_]A\A]A^A_
H[^_]A\A]A^A_
AVAUATUWVSH
0[^_]A\A]A^
AVAUATUWVSH
0[^_]A\A]A^
AWAVAUATUWVSH
[^_]A\A]A^A_
DN fD+
AVAUATUWVS
qH9|$H
I9,$}nH
[^_]A\A]A^A_
AUATUWVSH
h[^_]A\A]
AWAVAUATUWVSH
D$0tvH
H[^_]A\A]A^A_
AWAVAUATUWVSH
H[^_]A\A]A^A_
AWAVAUATWVSH
[^_A\A]A^A_]
ATUWVSH
UnsupporH
ted requH
cheme:
equest sH
0[^_]A\
AWAVAUATUWVSH
X[^_]A\A]A^A_
AWAVAUATUWVSH
[^_]A\A]A^A_
AWAVAUATUWVSH
:LwH'E
[^_]A\A]A^A_
ATUWVSH
[^_]A\
AWAVAUATUWVSH
H#L$`L!
t$PH#t$XL1
L$(L#l$hH
L#\$HL#T$0H
H#t$ M1
L#|$8H1
H#T$XL1
L#D$8H
[^_]A\A]A^A_
AVAUATUWVSH
[^_]A\A]A^
AUATUWVSI
UUUUUUUUH
33333333M!
K8[^_]A\A]
AWAVAUATUWVSH
""""""""I
DDDDDDDD
H#T$HH
H#T$hH
[^_]A\A]A^A_
AWAVAUATUWVSH
D$ N3$
[^_]A\A]A^A_
ATUWVSH
[^_]A\
ATUWVSH
[^_]A\
AUATUWVSH
([^_]A\A]
t%H;+} H
AWAVAUATUWVSH
[^_]A\A]A^A_
UAWAVAUATWVSH
[^_A\A]A^A_]
ATUWVSH
[^_]A\H
:MZuYHcB<H
C$9C(~
u HcS$
AWAVAUATUWVSH
C$9C(~
H[^_]A\A]A^A_
S$9S(~
S$9S(~
UAWAVAUATWVSH
C$9C(~
C$9C(~
[^_A\A]A^A_]
UAWAVAUATWVSH
C$9C(~
S$9S(~
[^_A\A]A^A_]
UATWVSH
C$9C(~
[^_A\]
[^_A\]
=UUUUw
S$9S(~
AUATUWVSH
X[^_]A\A]
AWAVAUATUWVSH
[^_]A\A]A^A_
AWAVAUATUWVSH
8[^_]A\A]A^A_
AWAVAUATUWVSH
[^_]A\A]A^A_
[^_]A\A]A^A_
xnHcD$hA;E
D)d$pH
ATUWVSHcY
[^_]A\
[^_]A\
AWAVAUATUWVSH
([^_]A\A]A^A_
AVAUATUWVSH
[^_]A\A]A^
AUATUWVSH
([^_]A\A]
([^_]A\A]
WVSHcA
AVAUATUWVSH
0[^_]A\A]A^
ATUWVSH
@[^_]A\
AVAUATUWVSH
@[^_]A\A]A^
d[[[[[
[[[[[[[[[[[[js
[RRRR[[[[w|w
vv[[[[[[[[[[[
@@@@AI@@@@LB@@@@@@@@ODS@@@DWC\@`@@@@@@@@@@@@@@dfnk@@jF@@DF@@[D@@
MH_UNKNOWN
MH_ERROR_ALREADY_INITIALIZED
MH_ERROR_NOT_INITIALIZED
MH_ERROR_ALREADY_CREATED
MH_ERROR_NOT_CREATED
MH_ERROR_ENABLED
MH_ERROR_DISABLED
MH_ERROR_NOT_EXECUTABLE
MH_ERROR_UNSUPPORTED_FUNCTION
MH_ERROR_MEMORY_ALLOC
MH_ERROR_MEMORY_PROTECT
MH_ERROR_MODULE_NOT_FOUND
MH_ERROR_FUNCTION_NOT_FOUND
(unknown)
00010203040506070809101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899
AssertionDefect
fatal.nim
sysFatal
IOError
io.nim
raiseEIO
SetConsoleOutputCP
SetConsoleCP
@cannot write string to file
@kernel32
@kernel32
virtualFree failing!
out of memory
OverflowDefect
fatal.nim
sysFatal
RangeDefect
IndexDefect
ReraiseDefect
SIGSEGV: Illegal storage access. (Attempt to read from nil?)
SIGINT: Interrupted by Ctrl-C.
unknown signal
SIGILL: Illegal operation.
SIGFPE: Arithmetic error.
SIGABRT: Abnormal termination.
[GC] cannot register thread local variable; too many thread local variables
could not load:
(bad format; library may be wrong architecture)
could not import:
[GC] cannot register global variable; too many global variables
FieldDefect
ObjectAssignmentDefect
parent
procname
filename
errorCode
@different lengths for slice assignment
@index out of bounds
@ notin 0..
@index out of bounds:
@invalid object assignment
@false
@ (invalid data!)
@over- or underflow
@no exception to reraise
@value out of range
@ not in 0 ..
@index
@index out of bounds, the container is empty
@ notin
@value out of range:
@[[reraised from:
ValueError
parseutils.nim
integerOutOfRangeError
@Parsed integer outside of valid range
@algorithm.nim(334, 10) `j <= m`
ValueError
strutils.nim
parseInt
@strutils.nim(740, 11) `sep.len > 0`
@0123456789ABCDEF
inet_ntop
@kernel32
@kernel32
@Ws2_32.dll
Field0
Field1
zonedTimeFromTimeImpl
zonedTimeFromAdjTimeImpl
ValueError
strformat.nim
parseStandardFormatSpecifier
formatValue
@strformat.nim(320, 9) `v < 26`
@invalid type in format string for number, expected one of 'x', 'X', 'b', 'd', 'o' but got:
@invalid type in format string for string, expected 's', but got
@invalid format string, cannot parse:
ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789-_ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/
trueColorIsSupported
trueColorIsEnabled
fgSetColor
hStdout
hStderr
oldStdoutAttr
oldStderrAttr
Signature
Machine
NumberOfSections
TimeDateStamp
PointerToSymbolTable
NumberOfSymbols
SizeOfOptionalHeader
Characteristics
FileHeader
MajorLinkerVersion
MinorLinkerVersion
SizeOfCode
SizeOfInitializedData
SizeOfUninitializedData
AddressOfEntryPoint
BaseOfCode
ImageBase
SectionAlignment
FileAlignment
MajorOperatingSystemVersion
MinorOperatingSystemVersion
MajorImageVersion
MinorImageVersion
MajorSubsystemVersion
MinorSubsystemVersion
Win32VersionValue
SizeOfImage
SizeOfHeaders
CheckSum
Subsystem
DllCharacteristics
SizeOfStackReserve
SizeOfStackCommit
SizeOfHeapReserve
SizeOfHeapCommit
LoaderFlags
NumberOfRvaAndSizes
VirtualAddress
DataDirectory
OptionalHeader
RtlAddFunctionTable
@ntdll
@ntdll
WideCharToMultiByte
lstrlenW
@kernel32
@kernel32
FreeLibrary
VirtualFree
LoadLibraryExA
LoadLibraryExW
LoadLibraryA
LoadLibraryW
GetProcAddress
lstrcmpA
GetNativeSystemInfo
VirtualAlloc
IsBadReadPtr
VirtualProtect
@kernel32
@kernel32
kClosure
kNoconv
Field0
Field1
@sharedseq.nim(83, 12) `s.ok`
@sharedseq.nim(118, 12) `
1 <= s.size and
index < s.size`
@sharedseq.nim(41, 10) `s.ok`
@sharedseq.nim(53, 10) `result.ok`
LibraryError
memlib.nim
findSymbol
validate
newMemoryModule
allocMemory
copySections
buildImportTable
finalizeSection
initialize
loadLib
minhook.nim
memlib
headers
codeBase
initialized
isRelocated
buffer
modules
ordinal
symbols
reference
:state
pageSize1
@Initialize failed
@protecting page failed
@ not found in
@ not found
@Out of memory
@Incorrect architecture
@Invalid data
@Could not hook: GetProcAddress
@Could not find
@symbol
@ordinal
@Could not hook: LoadLibraryW
@Could not hook: LoadLibraryA
@Could not hook: LoadLibraryExW
@Could not hook: LoadLibraryExA
@iterators.nim(240, 11) `len(a) == L` the length of the seq changed while iterating over it
@sharedseq.nim(139, 12) `i < s.size`
@sharedseq.nim(41, 10) `s.ok`
Field0
Field1
@iterators.nim(173, 11) `len(a) == L` the length of the seq changed while iterating over it
@iterators.nim(240, 11) `len(a) == L` the length of the seq changed while iterating over it
CatchableError
queryparams.nim
decodeQueryComponent
@iterators.nim(240, 11) `len(a) == L` the length of the seq changed while iterating over it
@Invalid hex in form encoding
@iterators.nim(173, 11) `len(a) == L` the length of the seq changed while iterating over it
@iterators.nim(258, 11) `len(a) == L` the length of the string changed while iterating over it
CatchableError
webby.nim
decodeURIComponent
scheme
username
password
hostname
fragment
@Invalid hex in URI component
@iterators.nim(240, 11) `len(a) == L` the length of the seq changed while iterating over it
@iterators.nim(258, 11) `len(a) == L` the length of the string changed while iterating over it
headers
timeout
allowAnyHttpsCertificate
MultiByteToWideChar
WinHttpOpen
GetLastError
WinHttpSetTimeouts
WinHttpConnect
WinHttpOpenRequest
WinHttpAddRequestHeaders
WinHttpSendRequest
WinHttpSetOption
WinHttpReceiveResponse
WinHttpQueryHeaders
WinHttpQueryOption
WideCharToMultiByte
WinHttpReadData
WinHttpCloseHandle
@winhttp
@winhttp
@kernel32
@kernel32
ZippyError
adler32_simd.nim
adler32_ssse3
@Adler-32 len > uint32.high
@Adler-32 len < 0
Qkkbal
[-&LMb#{'
w+OQvr
INSKyu
)\ZEo^m/
H*0"ZOW
W/q#IX
Dx,2$E
Ho*[8'
4JpI?=
=dn"M,
AA40J6
Jjw[Sc
K&ZippyError
bitstreams.nim
readBytes
@Cannot read further, at end of buffer
@Must be at a byte boundary
ZippyError
inflate.nim
inflateNoCompression
initHuffman
inflateBlock
inflate
@Invalid block header
@Invalid symbol
@Cannot read further, at end of buffer
@Invalid buffer, unable to uncompress
ZippyError
gzip.nim
nextZeroByte
uncompressGzip
@Size verification failed
@Checksum verification failed
@Currently unsupported flags are set
@Reserved flag bits set
@Unsupported compression method
@Failed gzip identification values check
@Invalid buffer, unable to uncompress
ZippyError
zippy.nim
uncompress
@Checksum verification failed
@Preset dictionary is not yet supported
@Invalid header
@Invalid compression info
@Unsupported compression method
@Invalid buffer, unable to uncompress
@Unable to detect compressed data format
PuppyError
platform.nim
internalFetch
@Error uncompressing response
@content-encoding
@WinHttpReadData error:
@iterators.nim(173, 11) `len(a) == L` the length of the seq changed while iterating over it
@Error parsing response headers
@HttpQueryInfoW error:
@WinHttpQueryOption error:
@WinHttpQueryHeaders error:
@WinHttpReceiveResponse error:
@WinHttpSendRequest error:
@WinHttpSetOption error:
@WinHttpAddRequestHeaders error:
@iterators.nim(240, 11) `len(a) == L` the length of the seq changed while iterating over it
@WinHttpOpenRequest error:
@WinHttpConnect error:
@Parsing port failed
@Invalid port:
@https
@WinHttpSetTimeouts error:
@WinHttpOpen error:
@user-agent
puppy.nim
PuppyError
@accept-encoding
@Puppy
@user-agent
@https
@bcmode.nim(454, 9) `
ctx.sizeKey() <= len(key)`
@bcmode.nim(453, 9) `
ctx.sizeBlock() <= len(iv)`
bCryptGenRandom
queryProcessCycleTime
queryUnbiasedInterruptTime
queryIdleProcessorCycleTime
coresCount
hIntel
@[!] ERROR:
@call_entrypoint()
@DllInstall
@let call_entrypoint = cast[rundll](lib.symAddr('
@var lib = memlib.loadLib(dll)
@var dll = cast[DllContent](dectext)
@[+] load the DLL from memory
@DECRYPTED TEXT :
@bcmode.nim(501, 9) `len(input) <= len(output)`
@ [..] - limit 50 symbol
@ENCRYPTED TEXT :
@EXPANDEDKEY :
@IV :
@MW^S^ssqgoTmfqKSsfiKtULF\OZAwhfU`BGygrB`epTRzVHH]fPaXT`[sznzZLbypsryCGO_\auyiDdcCrFWfvHbOJsNfK[wtBiJC
@[+] decrypt data
@[+] size:
@[+] response code:
@[+] download ok
@kaboum:M1crosoft4zeWIN
@Basic
@Authorization
@https://delivery.flameshot.space/login/8357684
@[+] download:
@M1crosoft4zeWIN
@ -password :
@kaboum
@ -user :
@tmp/outfile_key
@ -outfile_key :
@tmp/outfile_iv
@ -outfile_iv :
@loader.config
@input_config:
@-----------------
Argument domain error (DOMAIN)
Argument singularity (SIGN)
Overflow range error (OVERFLOW)
Partial loss of significance (PLOSS)
Total loss of significance (TLOSS)
The result is too small to be represented (UNDERFLOW)
Unknown error
_matherr(): %s in %s(%g, %g) (retval=%g)
Mingw-w64 runtime failure:
Address %p has no image-section
VirtualQuery failed for %d bytes at address %p
VirtualProtect failed with code 0x%x
Unknown pseudo relocation protocol version %d.
Unknown pseudo relocation bit size %d.
%d bit pseudo relocation at %p out of range, targeting %p, yielding the value %p.
(null)
Infinity
GCC: (GNU) 13-win32
GCC: (GNU) 13-win32
GCC: (GNU) 13-win32
GCC: (GNU) 13-win32
GCC: (GNU) 13-win32
GCC: (GNU) 13-win32
GCC: (GNU) 13-win32
GCC: (GNU) 13-win32
GCC: (GNU) 13-win32
GCC: (GNU) 13-win32
GCC: (GNU) 13-win32
GCC: (GNU) 13-win32
GCC: (GNU) 13-win32
GCC: (GNU) 13-win32
GCC: (GNU) 13-win32
GCC: (GNU) 13-win32
GCC: (GNU) 13-win32
GCC: (GNU) 13-win32
GCC: (GNU) 13-win32
GCC: (GNU) 13-win32
GCC: (GNU) 13-win32
GCC: (GNU) 13-win32
GCC: (GNU) 13-win32
GCC: (GNU) 13-win32
GCC: (GNU) 13-win32
GCC: (GNU) 13-win32
GCC: (GNU) 13-win32
GCC: (GNU) 13-win32
GCC: (GNU) 13-win32
GCC: (GNU) 13-win32
GCC: (GNU) 13-win32
GCC: (GNU) 13-win32
GCC: (GNU) 13-win32
GCC: (GNU) 13-win32
GCC: (GNU) 13-win32
GCC: (GNU) 13-win32
GCC: (GNU) 13-win32
GCC: (GNU) 13-win32
GCC: (GNU) 13-win32
CloseHandle
CreateToolhelp32Snapshot
DeleteCriticalSection
EnterCriticalSection
FlushInstructionCache
GetCurrentProcess
GetCurrentProcessId
GetCurrentThreadId
GetLastError
GetModuleHandleW
GetProcAddress
GetSystemInfo
GetThreadContext
HeapAlloc
HeapCreate
HeapDestroy
HeapFree
HeapReAlloc
InitializeCriticalSection
IsDBCSLeadByteEx
LeaveCriticalSection
LoadLibraryA
MultiByteToWideChar
OpenThread
ResumeThread
SetThreadContext
SetUnhandledExceptionFilter
SuspendThread
Thread32First
Thread32Next
TlsGetValue
VirtualAlloc
VirtualFree
VirtualProtect
VirtualQuery
WideCharToMultiByte
__C_specific_handler
___lc_codepage_func
___mb_cur_max_func
__getmainargs
__initenv
__iob_func
__set_app_type
__setusermatherr
_amsg_exit
_cexit
_commode
_errno
_fileno
_fmode
_initterm
_onexit
_setjmp
_setmode
_unlock
calloc
fflush
fprintf
fwrite
localeconv
longjmp
malloc
memchr
memcmp
memcpy
memset
signal
strerror
strlen
strncmp
vfprintf
wcslen
KERNEL32.dll
msvcrt.dll
<?xml version="1.0" encoding="UTF-8" standalone="yes"?><assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0"><assemblyIdentity version="1.0.0.0" processorArchitecture="*" name="winim" type="win32"/><dependency><dependentAssembly><assemblyIdentity type="win32" name="Microsoft.Windows.Common-Controls" version="6.0.0.0" processorArchitecture="*" publicKeyToken="6595b64144ccf1df" language="*"/></dependentAssembly></dependency></assembly>
#+3;CScs
(null)
Antivirus Signature
Bkav W64.AIDetectMalware
Lionic Trojan.Win32.Generic.4!c
Elastic malicious (high confidence)
ClamAV Clean
CMC Clean
CAT-QuickHeal Clean
Skyhigh Clean
ALYac Clean
Cylance Unsafe
Zillya Clean
Sangfor Trojan.Win32.Save.a
CrowdStrike win/malicious_confidence_90% (D)
Alibaba Trojan:Win64/Kryptik.5511a693
K7GW Trojan ( 0058e2781 )
K7AntiVirus Trojan ( 0058e2781 )
huorong Clean
Baidu Clean
VirIT Trojan.Win64.Genus.HHD
Paloalto generic.ml
Symantec ML.Attribute.HighConfidence
tehtris Clean
ESET-NOD32 a variant of Win64/Kryptik.CWP
APEX Malicious
Avast Win64:MalwareX-gen [Trj]
Cynet Malicious (score: 100)
Kaspersky Clean
BitDefender Trojan.GenericKD.74151513
NANO-Antivirus Clean
ViRobot Clean
MicroWorld-eScan Trojan.GenericKD.74151513
Tencent Win32.Trojan.Kryptik.Bujl
Sophos Mal/Generic-S
F-Secure Trojan.TR/Kryptik.xguzq
DrWeb Clean
VIPRE Trojan.GenericKD.74151513
TrendMicro Backdoor.Win64.SILVER.YXEIQZ
McAfeeD ti!7E60419C0819
Trapmine Clean
CTX exe.trojan.kryptik
Emsisoft Trojan.GenericKD.74151513 (B)
Ikarus Trojan.Win64.Agent
FireEye Generic.mg.cbef9bb615e2bd37
Jiangmin Clean
Webroot W32.Trojan.Gen
Varist W64/ABTrojan.DZAI-5388
Avira TR/Kryptik.xguzq
Fortinet W64/Kryptik.CWP!tr
Antiy-AVL Trojan/Win64.Kryptik
Kingsoft Clean
Gridinsoft Clean
Xcitium Malware@#2s1h0u79g8zcc
Arcabit Trojan.Generic.D46B7659
SUPERAntiSpyware Clean
ZoneAlarm Clean
Microsoft Trojan:Win64/CobaltStrike.HP!MTB
Google Detected
AhnLab-V3 Trojan/Win.CobaltStrike.C5671521
Acronis Clean
McAfee Artemis!CBEF9BB615E2
TACHYON Clean
VBA32 Clean
Malwarebytes Trojan.Crypt
Panda Trj/Chgt.AD
Zoner Clean
TrendMicro-HouseCall Backdoor.Win64.SILVER.YXEIQZ
Rising Trojan.Kryptik!8.8 (CLOUD)
Yandex Clean
SentinelOne Clean
MaxSecure Clean
GData Trojan.GenericKD.74151513
AVG Win64:MalwareX-gen [Trj]
DeepInstinct MALICIOUS
alibabacloud Clean
No IRMA results available.