Static | ZeroBOX

PE Compile Time

2019-04-21 09:59:22

PE Imphash

fd3dbd431c841e102676ceab0d209962

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x00036e1e 0x00037000 6.63469930275
.rdata 0x00038000 0x0000898d 0x00008a00 5.64621791049
.data 0x00041000 0x00005bd8 0x00003600 3.53786607561
.reloc 0x00047000 0x00002fd6 0x00003000 4.97047686082

Imports

Library WS2_32.dll:
0x1003832c WSADuplicateSocketA
0x10038330 closesocket
0x10038334 accept
0x10038338 select
0x1003833c __WSAFDIsSet
0x10038340 recv
0x10038344 send
0x10038348 WSAGetLastError
0x1003834c setsockopt
0x10038350 WSAStartup
0x10038354 WSASocketA
0x10038358 socket
0x1003835c inet_addr
0x10038360 htons
0x10038364 bind
0x10038368 listen
Library KERNEL32.dll:
0x10038080 TlsGetValue
0x10038084 Sleep
0x10038088 GetSystemTime
0x1003808c SetThreadPriority
0x10038090 TlsSetValue
0x10038094 GetCurrentThreadId
0x10038098 DuplicateHandle
0x1003809c GetCurrentThread
0x100380a0 GetCurrentProcess
0x100380a4 TlsAlloc
0x100380a8 ResumeThread
0x100380ac UnmapViewOfFile
0x100380b0 DeleteFileA
0x100380b4 CreateDirectoryA
0x100380b8 WriteFile
0x100380bc SetFileTime
0x100380c0 CreateFileA
0x100380c4 FindClose
0x100380c8 FindNextFileA
0x100380cc FindFirstFileA
0x100380d0 SetErrorMode
0x100380d8 GetComputerNameA
0x100380dc GetVersionExA
0x100380e0 GlobalUnlock
0x100380e4 GlobalLock
0x100380e8 GlobalAlloc
0x100380ec GlobalDeleteAtom
0x100380f0 GlobalAddAtomA
0x100380f4 SystemTimeToFileTime
0x100380f8 SetEvent
0x10038100 LCMapStringW
0x10038104 LCMapStringA
0x10038108 IsValidCodePage
0x1003810c GetOEMCP
0x10038110 GetACP
0x10038114 GetCPInfo
0x10038118 CloseHandle
0x1003811c MultiByteToWideChar
0x10038120 FlushFileBuffers
0x10038124 GetConsoleMode
0x10038128 GetConsoleCP
0x1003812c WideCharToMultiByte
0x10038130 GetModuleHandleA
0x10038134 HeapSize
0x10038138 HeapReAlloc
0x1003813c VirtualAlloc
0x10038140 VirtualFree
0x10038144 HeapDestroy
0x10038148 HeapCreate
0x1003814c GetStartupInfoA
0x10038150 GetFileType
0x10038154 SetHandleCount
0x1003815c GetModuleFileNameA
0x10038160 GetStdHandle
0x10038164 InterlockedDecrement
0x10038168 SetLastError
0x1003816c InterlockedIncrement
0x10038170 TlsFree
0x10038174 GetCommandLineA
0x10038178 IsDebuggerPresent
0x10038184 TerminateProcess
0x10038188 CreateThread
0x1003818c RaiseException
0x10038190 HeapAlloc
0x10038194 HeapFree
0x10038198 GetEnvironmentStrings
0x1003819c ExitProcess
0x100381a0 GetModuleHandleW
0x100381a8 RtlUnwind
0x100381b0 GetEnvironmentStringsW
0x100381b8 GetTickCount
0x100381bc CreateSemaphoreA
0x100381c0 ReleaseSemaphore
0x100381c4 GetLastError
0x100381c8 LeaveCriticalSection
0x100381cc EnterCriticalSection
0x100381d0 DeleteCriticalSection
0x100381d8 GetCurrentProcessId
0x100381dc CreateEventA
0x100381e0 ExitThread
0x100381e4 WaitForSingleObject
0x100381e8 LoadLibraryA
0x100381ec GetProcAddress
0x100381f0 FreeLibrary
0x100381f4 GetLocaleInfoA
0x100381f8 SetFilePointer
0x100381fc WriteConsoleA
0x10038200 GetConsoleOutputCP
0x10038204 WriteConsoleW
0x10038208 SetStdHandle
0x1003820c CompareStringA
0x10038210 CompareStringW
0x10038218 GetStringTypeA
0x1003821c GetStringTypeW
0x10038220 ReadFile
Library USER32.dll:
0x1003822c MessageBeep
0x10038230 ExitWindowsEx
0x10038234 VkKeyScanA
0x10038238 GetAsyncKeyState
0x1003823c MapVirtualKeyA
0x10038240 RegisterWindowMessageA
0x10038244 PeekMessageA
0x10038248 WaitMessage
0x1003824c DispatchMessageA
0x10038250 EqualRect
0x10038254 GetForegroundWindow
0x10038258 WindowFromPoint
0x1003825c RegisterClassExA
0x10038260 CreateWindowExA
0x10038264 SetWindowLongA
0x10038268 SetClipboardViewer
0x1003826c GetClipboardOwner
0x10038270 GetClipboardData
0x10038274 DefWindowProcA
0x10038278 PostQuitMessage
0x1003827c GetWindowLongA
0x10038280 GetPropA
0x10038284 IsWindowVisible
0x10038288 SetPropA
0x1003828c RemovePropA
0x10038290 ChangeClipboardChain
0x10038294 DestroyWindow
0x10038298 SendMessageA
0x1003829c KillTimer
0x100382a0 SetTimer
0x100382a4 OpenClipboard
0x100382a8 EmptyClipboard
0x100382ac SetClipboardData
0x100382b0 CloseClipboard
0x100382b4 DrawIconEx
0x100382b8 LoadCursorA
0x100382bc ChangeDisplaySettingsA
0x100382c0 OpenDesktopA
0x100382c4 EnumDesktopWindows
0x100382c8 SystemParametersInfoA
0x100382cc FindWindowA
0x100382d0 GetClassNameA
0x100382d4 PostMessageA
0x100382d8 GetCursorPos
0x100382dc GetSystemMetrics
0x100382e0 GetDesktopWindow
0x100382e4 GetWindowRect
0x100382e8 mouse_event
0x100382ec IsRectEmpty
0x100382f0 IntersectRect
0x100382f4 GetKeyboardState
0x100382f8 keybd_event
0x100382fc EnumDisplaySettingsA
0x10038300 GetThreadDesktop
0x10038304 SetThreadDesktop
0x10038308 CloseDesktop
0x1003830c GetDC
0x10038310 ReleaseDC
0x10038314 SetRect
0x10038318 GetIconInfo
0x1003831c OpenInputDesktop
0x10038324 EnumWindows
Library GDI32.dll:
0x10038020 DeleteDC
0x10038028 DeleteObject
0x1003802c GetObjectA
0x10038030 GetBitmapBits
0x10038034 CreateDIBSection
0x10038038 ExtEscape
0x1003803c GdiFlush
0x10038040 GetStockObject
0x10038044 CombineRgn
0x10038048 CreateRectRgn
0x1003804c CreateRectRgnIndirect
0x10038050 GetRegionData
0x10038054 CreateDCA
0x10038058 GetDIBits
0x1003805c CreateCompatibleBitmap
0x10038060 GetDeviceCaps
0x10038064 CreateCompatibleDC
0x10038068 RealizePalette
0x1003806c SelectPalette
0x10038070 BitBlt
0x10038074 SelectObject
0x10038078 CreatePalette
Library ADVAPI32.dll:
0x10038000 RevertToSelf
0x10038008 RegDeleteValueA
0x1003800c RegSetValueExA
0x10038010 RegCreateKeyA
0x10038014 RegCloseKey
0x10038018 GetUserNameA

Exports

Ordinal Address Name
1 0x10001010 ?ReflectiveLoader@@YGKPAX@Z
!This program cannot be run in DOS mode.
`.rdata
@.data
.reloc
t!< u\
RSWPVQ
FD9^l}T
F,u6j8h
V<;V$t
t59~<~V
9~<~"3
V<_^[]
)_0uQ;
G4;G<}C
G4;G<uV
GD_^[]
GH_^[]
F<)^h)^d
Ndf+Nh
Nl;FxwT
Vp;VxsT
Fd+Fh=
tX9H tS9H$tN
O(9O$u
@PAQBR
t78^\t
Hd9^ t
h V)GR
9FTt89
Q\f+QT
A`f+AXf
V`+VXP+U
QQSVWd
PPPPPPPP
0WWWWW
0WWWWW
HtHu4j
s[S;7|G;w
tR99u2
HHtXHHt
>If90t
j@j ^V
_VVVVV
^WWWWW
^F<-uB
<xtX<XtT
0SSSSS
0A@@Ju
t"SS9]
>=Yt1j
;t$,v-
UQPXY]Y[
URPQQh
0SSSSS
0SSSSS
^SSSSS
j"^SSSSS
0SSSSS
_VVVVV
PPPPPPPP
t+WWVPV
<+t(<-t$:
+t HHt
bad allocation
UnlockWindowStation
user32.dll
127.0.0.1
%s: unusual colour = %d
getBgColour
getBgColour: bpp %d?
Hextile
ZlibHex
BKbhTb~XBK!;
%&'()*456789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz
&'()*56789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz
BKbhTb~XBK!;
Application transferred too many scanlines
Invalid SOS parameters for sequential JPEG
Corrupt JPEG data: found marker 0x%02x instead of RST%d
Premature end of JPEG file
Warning: unknown JFIF revision number %d.%02d
Corrupt JPEG data: bad Huffman code
Corrupt JPEG data: premature end of data segment
Corrupt JPEG data: %u extraneous bytes before marker 0x%02x
Inconsistent progression sequence for component %d coefficient %d
Unknown Adobe color transform code %d
Obtained XMS handle %u
Freed XMS handle %u
Unrecognized component IDs %d %d %d, assuming YCbCr
JFIF extension marker: RGB thumbnail image, length %u
JFIF extension marker: palette thumbnail image, length %u
JFIF extension marker: JPEG-compressed thumbnail image, length %u
Opened temporary file %s
Closed temporary file %s
Ss=%d, Se=%d, Ah=%d, Al=%d
Component %d: dc=%d ac=%d
Start Of Scan: %d components
Start of Image
Component %d: %dhx%dv q=%d
Start Of Frame 0x%02x: width=%u, height=%u, components=%d
Smoothing not supported with nonstandard sampling ratios
At marker 0x%02x, recovery action %d
Selected %d colors for quantization
Quantizing to %d colors
Quantizing to %d = %d*%d*%d colors
%4u %4u %4u %4u %4u %4u %4u %4u
Unexpected marker 0x%02x
Miscellaneous marker 0x%02x, length %u
with %d x %d thumbnail image
JFIF extension marker: type 0x%02x, length %u
Warning: thumbnail image size does not match data length %u
JFIF APP0 marker: version %d.%02d, density %dx%d %d
%3d %3d %3d %3d %3d %3d %3d %3d
End Of Image
Obtained EMS handle %u
Freed EMS handle %u
Define Restart Interval %u
Define Quantization Table %d precision %d
Define Huffman Table 0x%02x
Define Arithmetic Table 0x%02x: 0x%02x
Unknown APP14 marker (not Adobe), length %u
Unknown APP0 marker (not JFIF), length %u
Adobe APP14 marker: version %d, flags 0x%04x 0x%04x, transform %d
Caution: quantization tables are too coarse for baseline JPEG
6b 27-Mar-1998
Copyright (C) 1998, Thomas G. Lane
Write to XMS failed
Read from XMS failed
Image too wide for this implementation
Virtual array controller messed up
Unsupported marker type 0x%02x
Application transferred too few scanlines
Write failed on temporary file --- out of disk space?
Seek failed on temporary file
Read failed on temporary file
Failed to create temporary file %s
Invalid JPEG file structure: SOS before SOF
Invalid JPEG file structure: two SOI markers
Unsupported JPEG process: SOF type 0x%02x
Invalid JPEG file structure: missing SOS marker
Invalid JPEG file structure: two SOF markers
Cannot quantize to more than %d colors
Cannot quantize to fewer than %d colors
Cannot quantize more than %d color components
Insufficient memory (case %d)
Not a JPEG file: starts with 0x%02x 0x%02x
Quantization table 0x%02x was not defined
JPEG datastream contains no image
Huffman table 0x%02x was not defined
Backing store not supported
Requested feature was omitted at compile time
Not implemented yet
Invalid color quantization mode change
Scan script does not transmit all data
Cannot transcode due to multiple use of quantization table %d
Premature end of input file
Empty input file
Maximum supported image dimension is %u pixels
Missing Huffman code table entry
Huffman code size table overflow
Fractional sampling not implemented yet
Output file write error --- out of disk space?
Input file read error
Didn't expect more than one scan
Write to EMS failed
Read from EMS failed
Empty JPEG image (DNL not supported)
Bogus DQT index %d
Bogus DHT index %d
Bogus DAC value 0x%x
Bogus DAC index %d
Unsupported color conversion request
Too many color components: %d, max %d
CCIR601 sampling not implemented yet
Suspension not allowed here
Buffer passed to JPEG library is too small
Bogus virtual array access
JPEG parameter struct mismatch: library thinks size is %u, caller expects %u
Improper call to JPEG library in state %d
Invalid scan script at entry %d
Bogus sampling factors
Invalid progressive parameters at scan script entry %d
Invalid progressive parameters Ss=%d Se=%d Ah=%d Al=%d
Unsupported JPEG data precision %d
Invalid memory pool code %d
Sampling factors too large for interleaved scan
Wrong JPEG library version: library is %d, caller expects %d
Bogus marker length
Bogus JPEG colorspace
Bogus input colorspace
Bogus Huffman table definition
IDCT output block size %d not supported
DCT coefficient out of range
Invalid component ID %d in SOS
Bogus buffer control mode
MAX_ALLOC_CHUNK is wrong, please fix
ALIGN_TYPE is wrong, please fix
Sorry, there are legal restrictions on arithmetic coding
Bogus message code %d
JPEGMEM
Qkkbal
- deflate 1.1.4 Copyright 1995-2002 Jean-loup Gailly
need dictionary
inflate 1.1.4 Copyright 1995-2002 Mark Adler
incompatible version
buffer error
insufficient memory
data error
stream error
file error
stream end
winsta.dll
WinStationConnectW
kernel32.dll
WTSGetActiveConsoleSessionId
ProcessIdToSessionId
LockWorkStation
DEVICE0
SYSTEM\CurrentControlSet\Hardware Profiles\Current\System\CurrentControlSet\Services
DISPLAY
Order.BltCopyBits.Enabled
Cap.DfbBackingMode
Pointer.Enabled
Screen.ForcedBpp
User32.DLL
EnumDisplayDevicesA
ChangeDisplaySettingsExA
Attach.ToDesktop
RFB %03d.%03d
VNCAUTH_
Authentication failed
NEWFBSIZ
LASTRECT
POINTPOS
RCHCURSR
X11CURSR
JPEGQLVL
COMPRLVL
TIGHT___
ZLIBHEX_
ZLIB____
HEXTILE_
CORRE___
RRE_____
COPYRECT
FTC_UPFL
FTC_DNCN
FTC_UPDT
FTC_UPRQ
FTC_DNRQ
FTC_LSRQ
FTS_DNFL
FTS_UPCN
FTS_DNDT
FTS_LSDT
[unknown]
Error writing file data
Server does not support data compression on upload
Could not create file
Path length exceeds MAX_PATH value
Cannot open file, perhaps it is absent or is a directory
Path length exceeds 255 bytes
Cannot impersonate logged on user
<unknown>
VNCHooks.CopyRect.WindowPos
WinVNC desktop sink
WindowsScreenSaverClass
Screen-saver
WinVNC
ConsoleWindowClass
WinVNC.Update.DrawRect
WinVNC.Update.CopyRect
WinVNC.Update.Mouse
WinVNC.Local.Keyboard
WinVNC.Local.Mouse
WinVNC_Win32_Instance_Mutex
invalid map/set<T> iterator
map/set<T> too long
list<T> too long
localhost
GetMonitorInfoA
MonitorFromPoint
SAS window class
SAS window
Winlogon
Default
<unavailable>
string too long
invalid string position
CorExitProcess
Unknown exception
bad exception
EncodePointer
DecodePointer
FlsFree
FlsSetValue
FlsGetValue
FlsAlloc
runtime error
TLOSS error
SING error
DOMAIN error
An application has made an attempt to load the C runtime library incorrectly.
Please contact the application's support team for more information.
- Attempt to use MSIL code from this assembly during native code initialization
This indicates a bug in your application. It is most likely the result of calling an MSIL-compiled (/clr) function from a native constructor or from DllMain.
- not enough space for locale information
- Attempt to initialize the CRT more than once.
This indicates a bug in your application.
- CRT not initialized
- unable to initialize heap
- not enough space for lowio initialization
- not enough space for stdio initialization
- pure virtual function call
- not enough space for _onexit/atexit table
- unable to open console device
- unexpected heap error
- unexpected multithread lock error
- not enough space for thread data
This application has requested the Runtime to terminate it in an unusual way.
Please contact the application's support team for more information.
- not enough space for environment
- not enough space for arguments
- floating point support not loaded
Microsoft Visual C++ Runtime Library
<program name unknown>
Runtime Error!
Program:
(null)
`h````
xpxxxx
GAIsProcessorFeaturePresent
KERNEL32
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
Complete Object Locator'
Class Hierarchy Descriptor'
Base Class Array'
Base Class Descriptor at (
Type Descriptor'
`local static thread guard'
`managed vector copy constructor iterator'
`vector vbase copy constructor iterator'
`vector copy constructor iterator'
`dynamic atexit destructor for '
`dynamic initializer for '
`eh vector vbase copy constructor iterator'
`eh vector copy constructor iterator'
`managed vector destructor iterator'
`managed vector constructor iterator'
`placement delete[] closure'
`placement delete closure'
`omni callsig'
delete[]
new[]
`local vftable constructor closure'
`local vftable'
`udt returning'
`copy constructor closure'
`eh vector vbase constructor iterator'
`eh vector destructor iterator'
`eh vector constructor iterator'
`virtual displacement map'
`vector vbase constructor iterator'
`vector destructor iterator'
`vector constructor iterator'
`scalar deleting destructor'
`default constructor closure'
`vector deleting destructor'
`vbase destructor'
`string'
`local static guard'
`typeof'
`vcall'
`vbtable'
`vftable'
operator
delete
__unaligned
__restrict
__ptr64
__clrcall
__fastcall
__thiscall
__stdcall
__pascal
__cdecl
__based(
GetProcessWindowStation
GetUserObjectInformationA
GetLastActivePopup
GetActiveWindow
MessageBoxA
USER32.DLL
`h`hhh
xppwpp
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
HH:mm:ss
dddd, MMMM dd, yyyy
MM/dd/yy
December
November
October
September
August
February
January
Saturday
Friday
Thursday
Wednesday
Tuesday
Monday
Sunday
1#QNAN
1#SNAN
CONOUT$
SunMonTueWedThuFriSat
JanFebMarAprMayJunJulAugSepOctNovDec
WSADuplicateSocketA
WSASocketA
WS2_32.dll
FreeLibrary
GetProcAddress
LoadLibraryA
WaitForSingleObject
ExitThread
CreateEventA
GetCurrentProcessId
InitializeCriticalSection
DeleteCriticalSection
EnterCriticalSection
LeaveCriticalSection
GetLastError
ReleaseSemaphore
CreateSemaphoreA
CloseHandle
TlsGetValue
GetSystemTime
SetThreadPriority
TlsSetValue
GetCurrentThreadId
DuplicateHandle
GetCurrentThread
GetCurrentProcess
TlsAlloc
ResumeThread
UnmapViewOfFile
DeleteFileA
CreateDirectoryA
WriteFile
SetFileTime
CreateFileA
FindClose
FindNextFileA
FindFirstFileA
SetErrorMode
GetLogicalDriveStringsA
GetComputerNameA
GetVersionExA
GlobalUnlock
GlobalLock
GlobalAlloc
GlobalDeleteAtom
GlobalAddAtomA
SystemTimeToFileTime
SetEvent
KERNEL32.dll
GetProcessWindowStation
OpenInputDesktop
GetIconInfo
SetRect
ReleaseDC
CloseDesktop
SetThreadDesktop
GetThreadDesktop
EnumDisplaySettingsA
keybd_event
GetKeyboardState
IntersectRect
IsRectEmpty
mouse_event
GetWindowRect
GetDesktopWindow
GetSystemMetrics
GetCursorPos
PostMessageA
GetClassNameA
FindWindowA
SystemParametersInfoA
EnumDesktopWindows
OpenDesktopA
ChangeDisplaySettingsA
LoadCursorA
DrawIconEx
CloseClipboard
SetClipboardData
EmptyClipboard
OpenClipboard
SetTimer
KillTimer
SendMessageA
DestroyWindow
ChangeClipboardChain
RemovePropA
SetPropA
IsWindowVisible
GetPropA
GetWindowLongA
EnumWindows
PostQuitMessage
DefWindowProcA
GetClipboardData
GetClipboardOwner
SetClipboardViewer
SetWindowLongA
CreateWindowExA
RegisterClassExA
WindowFromPoint
GetForegroundWindow
EqualRect
DispatchMessageA
WaitMessage
PeekMessageA
RegisterWindowMessageA
MapVirtualKeyA
GetAsyncKeyState
VkKeyScanA
ExitWindowsEx
MessageBeep
GetUserObjectInformationA
USER32.dll
GetBitmapBits
GetObjectA
DeleteObject
GetSystemPaletteEntries
DeleteDC
ExtEscape
CreateDCA
GetDIBits
CreateCompatibleBitmap
GetDeviceCaps
CreateCompatibleDC
RealizePalette
SelectPalette
CreatePalette
SelectObject
CreateDIBSection
BitBlt
GdiFlush
GetStockObject
CombineRgn
CreateRectRgn
CreateRectRgnIndirect
GetRegionData
GDI32.dll
RegCloseKey
RegCreateKeyA
RegSetValueExA
RegDeleteValueA
ImpersonateLoggedOnUser
RevertToSelf
GetUserNameA
ADVAPI32.dll
RtlUnwind
GetSystemTimeAsFileTime
GetModuleHandleW
ExitProcess
HeapFree
HeapAlloc
RaiseException
CreateThread
TerminateProcess
UnhandledExceptionFilter
SetUnhandledExceptionFilter
IsDebuggerPresent
GetCommandLineA
TlsFree
InterlockedIncrement
SetLastError
InterlockedDecrement
GetStdHandle
GetModuleFileNameA
InitializeCriticalSectionAndSpinCount
SetHandleCount
GetFileType
GetStartupInfoA
HeapCreate
HeapDestroy
VirtualFree
VirtualAlloc
HeapReAlloc
HeapSize
GetModuleHandleA
WideCharToMultiByte
GetConsoleCP
GetConsoleMode
FlushFileBuffers
MultiByteToWideChar
ReadFile
GetCPInfo
GetACP
GetOEMCP
IsValidCodePage
LCMapStringA
LCMapStringW
FreeEnvironmentStringsA
GetEnvironmentStrings
FreeEnvironmentStringsW
GetEnvironmentStringsW
QueryPerformanceCounter
GetTickCount
GetLocaleInfoA
SetFilePointer
WriteConsoleA
GetConsoleOutputCP
WriteConsoleW
SetStdHandle
CompareStringA
CompareStringW
SetEnvironmentVariableA
GetStringTypeA
GetStringTypeW
winvnc.x86.dll
?ReflectiveLoader@@YGKPAX@Z
VNC AAAABBBBCCCC
.?AVvncEncodeCoRRE@@
.?AVvncEncoder@@
.?AVvncEncodeHexT@@
.?AVvncEncodeRRE@@
.?AVvncEncodeTight@@
.?AVvncEncodeZlib@@
.?AVvncEncodeZlibHex@@
.?AVomni_thread_fatal@@
.?AVomni_thread@@
.?AVomni_thread_invalid@@
.?AV_internal_omni_thread_dummy@@
;3+#>6.&
'2, /+0&7!4-)1#
.?AVFileTransferItemInfo@@
Mirage Driver
DemoForge Mirage Driver
dfmirage
.?AVbad_alloc@std@@
.?AVexception@std@@
.?AVvncClient@@
.?AVvncClientThread@@
.?AVvncDesktopThread@@
.?AVlogic_error@std@@
.?AVlength_error@std@@
.?AVout_of_range@std@@
.?AVvncCorbaConnect@@
.?AVvncServer@@
.?AVvncSockConnect@@
.?AVvncSockConnectThread@@
.?AVVSocket@@
.?AVtype_info@@
.?AVbad_exception@std@@
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
4'414K4V4
5!6L6s6
>K?k?x?
9>9E9`9e9
=#=)=2=8=?=E=K=Q=W=\=r=v=|=
3/3\3x4
<9<C<L<Q<d<
=$=-=E=M=f=k=
=9>F>Q>V>
1 1)1T1i1
2%2:2E2M2S2v2
373A3L3T3c3i3t3
!0E0i0
7A8L8P8T8X8\8`8d8h8l8p8
9D9Z9x9
:):1:G:O:~:
4e8E9D<
6>>E>L>S>Z>a>h>
9T:8<A<N<W<~<
;<+<J<
>&>H>4???S?
96@6G6N6U6\6c6j6q6x6
5$63689@9a9k9x9
8$838=8P8_8n8x8
<(<6<I<W<j<
>,>5>C>L>Z>c>q>z>
>9?K?j?v?
8$8W8v8{8
: :;:@:
<=<Z<m<r<
>2>?>r>y>
2`3t5x5|5
2&2/272@2
4.494E4P4\4h4s4
9%9.979Q9
9):8:a;
;4<J<R<Y<
091]1c1i1t1
1v1\2e2
3(3.3?3z3
808U8l8
=(=1=9=
;';0;K;y;
<"<(<=<
=*=F=O=
1_2f2x2
3$5A5G5
9:1:V:Q;_;h>}>
0#0\0j0
2B2M2l2
383C3[3
1>1h1s1
7L8~8z9
=1=c=n=
=T=b=V?
0v1f2v3
1%111:1
9f:;6;>;D;R;Z;a;k;q;
=<=B=M=T=_=o=
>+>7>=>D>N>X>s>
748F8P8m8~8
9G:_:d:
0"0<0H0P0`0u0
1S2Z2|2
3 3-393I3P3_3k3x3
444C4L4p4
4?5E5V5l5~5
7 7$7M7s7
8-94989<9@9D9H9L9P9
:9:H:P:`:y:
: ;(;8;
<2=7===A=G=K=Q=U=[=_=d=j=n=t=x=~=
?A?L?o?
?"?&?*?.?2?6?:?>?B?F?J?N?R?V?Z?^?b?f?j?n?r?v?z?
2$2(2,2024282<2@2
7 7f7l7
7>8k8]9
;+<$=m=
77F7L7W7c7x7
8+878E8K8W8]8j8t8{8
;';-;9;?;O;U;j;x;
<"<(<-<<<R<]<b<m<r<}<
.050/1
263N3Y3}3
4(4M4`4x4
5"5E5L5e5y5
<.=7===
757Z7=99;=;A;E;I;M;Q;U;\;p;
; <(<h<r<
=G>P>\>
>3?<?H?a?
0'0/0;0B0K0^0h0t0}0
3#323;3H3S3e3x3
4%4*434@4F4`4q4w4
8(9m9@;K;S;
50f0|0
7Y8f8>9H9
1(1b1o1y1
595B5H5Q5V5e5
8919>9J9T9\9g9
0 1&1<1G1^1j1w1~1
2I2b2v2
3!3'3-343;3B3I3P3W3^3f3n3v3
4'424U4
5)6C6L6
7)758q8
0/0c0i0u0
5O7\7u7
9<9F9O9Z9o9v9|9
9$9F9X9j9|9
8_9/<F<
;1=7=<=B=I=[=
Y1f1t1
142W2i2
3!494a4y4
6,6L6t6
7)7I7t7
8)8I8q8
829I9a9
;!;1;A;K;a;f;k;u;
<!<1<7<<<Q<W<\<q<w<|<
=!=+=A=Q=a=q=
t3x3|3
4d4h4l4p4t4x4|4
5,5054585<5@5D5H5L5P5X5\5`5d5h5l5p5t5x5|5
8$8(8,8084888<8@8D8H8L8P8T8X8d8h8l8p8t8x8|8
`1d1h1l1p1t1x1|1
2 2$2(2,2024282<2@2D2H2L2P2T2X2\2`2d2h2l2p2t2x2|2
3 3$3(3,3034383<3@3D3H3L3(:4:@:L:X:d:p:|:
7T9X9\9
; ;$;(;,;0;4;8;<;@;D;H;L;P;T;@=D=H=L=P=T=,>0>4>8><>@>D>H>L>
? ?$?(?,?0?4?8?<?@?D?H?L?P?T?X?\?`?d?h?l?p?t?x?|?
0 0$0(0,0004080<0@0D0H0L0P0T0X0\0`0d0h0l0p0t0x0|0
1H1L1P1T1X1\1`1d1h1
2$2(2,202(:,:
0 0$0(0,0004080<0@0D0H0L0P0T0X0\0`0d0h0l0p0t0x0|0
1 1$1(1,1014181<1@1D1
< <$<(<0<H<L<d<t<x<
=(=8=<=L=P=T=\=t=
> >0>4><>T>d>h>x>|>
?4?8?P?`?d?x?|?
0 0$0(000H0X0\0l0p0t0|0
141D1H1X1\1d1|1
2 2024282@2X2h2l2|2
3 3$3(303H3L4T4`4
5$5@5L5l5t5
6(6H6P6X6`6h6p6x6
7,787X7`7l7
808<8\8d8l8t8|8
9$909X9l9x9
:0:<:\:d:p:
;$;8;D;L;l;t;|;
<$<D<L<T<X<\<d<x<
=(=0=8=D=h=
>$>D>P>p>|>
?(?H?P?X?`?h?p?x?
080@0H0P0\0|0
1$1D1P1
2(2H2T2p2
3 3P3X3\3t3x3
4$4<4@4\4`4|4
5 5<5@5`5
6 6@6`6
0$0(0H0d0h0
101L1p1
3(3,3034383<3@3D3H3L3P<t<x<|<
<$=(=,=H=d=|=
1(1,101P1t1x1
6$6,646<6D6L6T6\6d6l6t6|6
?(?8?H?l?x?|?
0 0$0(0,0004080<0@0D0H0L0P0T0X0\0`0d0h0x0
mscoree.dll
KERNEL32.DLL
(null)
((((( H
h(((( H
H
Antivirus Signature
Bkav W32.AIDetectMalware
Lionic Trojan.Win32.Gimmiv.4!c
Elastic Windows.Trojan.CobaltStrike
ClamAV Clean
CMC Clean
CAT-QuickHeal Clean
Skyhigh Clean
ALYac Misc.HackTool.Meterpreter
Cylance Unsafe
Zillya Tool.Inject.Win32.8428
Sangfor Riskware.Win32.Gimmiv.V1rc
CrowdStrike win/grayware_confidence_100% (W)
Alibaba HackTool:Win32/Inject.7b4c9efc
K7GW Riskware ( 0040eff71 )
K7AntiVirus Riskware ( 0040eff71 )
huorong HackTool/VNCDll.c
Baidu Clean
VirIT Clean
Paloalto generic.ml
Symantec Trojan Horse
tehtris Clean
ESET-NOD32 Win32/Gimmiv.AH
APEX Clean
Avast Win32:Malware-gen
Cynet Malicious (score: 99)
Kaspersky HEUR:Trojan.Win32.Generic
BitDefender Gen:Variant.Babar.39204
NANO-Antivirus Trojan.Win32.Inject.iupebg
ViRobot Clean
MicroWorld-eScan Gen:Variant.Babar.39204
Tencent Malware.Win32.Gencirc.10bf742c
Sophos Mal/Generic-S
F-Secure Trojan.TR/Gimmiv.dhghl
DrWeb Tool.Inject.80
VIPRE Gen:Variant.Babar.39204
TrendMicro PUA.Win32.WINVNC.A
McAfeeD ti!C50183EED715
Trapmine Clean
CTX dll.trojan.inject
Emsisoft Gen:Variant.Babar.39204 (B)
Ikarus Trojan.Win32.Gimmiv
FireEye Gen:Variant.Babar.39204
Jiangmin HackTool.Inject.bgl
Webroot W32.Trojan.Gen
Varist W32/ABRisk.XKMB-8668
Avira TR/Gimmiv.dhghl
Fortinet Riskware/Inject.HEUR
Antiy-AVL HackTool/Win32.Inject
Kingsoft Win32.Trojan.Generic.a
Gridinsoft Trojan.Win32.Downloader.ns
Xcitium Malware@#208igf02pd1mq
Arcabit Trojan.Babar.D9924
SUPERAntiSpyware Clean
ZoneAlarm HEUR:Trojan.Win32.Generic
Microsoft Trojan:Win32/Malgent
Google Detected
AhnLab-V3 Trojan/Win.Inject.C5469602
Acronis Clean
McAfee GenericRXAA-AA!719A93419DD5
TACHYON Clean
VBA32 Clean
Malwarebytes Malware.AI.3542577369
Panda Trj/CI.A
Zoner Clean
TrendMicro-HouseCall PUA.Win32.WINVNC.A
Rising HackTool.Inject!8.36B (TFE:5:zv9jVe2jqCF)
Yandex Clean
SentinelOne Static AI - Malicious PE
MaxSecure Trojan.Malware.10455307.susgen
GData Gen:Variant.Babar.39204
AVG Win32:Malware-gen
DeepInstinct MALICIOUS
alibabacloud Clean
No IRMA results available.