Static | ZeroBOX

PE Compile Time

2024-10-15 00:49:14

PE Imphash

54b907ef88e1152a442e4781bba49bdc

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x0000e217 0x0000e400 6.36050915734
.rdata 0x00010000 0x00006887 0x00006a00 4.52389797718
.data 0x00017000 0x00028eb0 0x00026800 5.61504332829
.pdata 0x00040000 0x00000db0 0x00000e00 4.82340894915
.reloc 0x00041000 0x00000da0 0x00000e00 2.26565864393

Imports

Library SHLWAPI.dll:
0x1800103c0 PathFindFileNameW
0x1800103c8 PathFileExistsA
0x1800103d0 PathFindFileNameA
Library USER32.dll:
0x1800103e0 wsprintfA
Library SHELL32.dll:
0x1800103b0 SHGetFolderPathA
Library ntdll.dll:
Library WININET.dll:
0x1800103f0 InternetOpenW
0x1800103f8 HttpQueryInfoA
0x180010400 InternetCloseHandle
0x180010408 InternetReadFile
0x180010410 InternetOpenUrlW
Library ADVAPI32.dll:
0x180010000 LookupPrivilegeValueA
0x180010008 OpenProcessToken
0x180010010 AdjustTokenPrivileges
Library KERNEL32.dll:
0x180010020 GetConsoleMode
0x180010028 GetConsoleCP
0x180010030 FlushFileBuffers
0x180010038 GetStringTypeW
0x180010040 LCMapStringEx
0x180010048 SetStdHandle
0x180010050 LoadLibraryW
0x180010058 OutputDebugStringW
0x180010060 LoadLibraryExW
0x180010068 SetFilePointerEx
0x180010070 WriteConsoleW
0x180010078 Thread32First
0x180010080 GetCurrentProcess
0x180010088 Process32First
0x180010090 WaitForSingleObject
0x180010098 CreateRemoteThread
0x1800100a0 OpenProcess
0x1800100a8 VirtualFreeEx
0x1800100b0 GetProcAddress
0x1800100b8 VirtualAllocEx
0x1800100c0 Process32Next
0x1800100c8 GetModuleHandleA
0x1800100d0 CreateToolhelp32Snapshot
0x1800100d8 CloseHandle
0x1800100e0 WriteProcessMemory
0x1800100e8 VirtualProtectEx
0x1800100f0 VirtualProtect
0x1800100f8 GetTempFileNameW
0x180010100 CreateFileA
0x180010108 lstrlenA
0x180010110 CreateProcessW
0x180010118 HeapAlloc
0x180010120 CompareFileTime
0x180010128 GetProcessHeap
0x180010130 WriteFile
0x180010138 GetProcessTimes
0x180010140 WideCharToMultiByte
0x180010148 Sleep
0x180010150 TerminateProcess
0x180010158 CreateFileW
0x180010160 lstrcatA
0x180010168 GetTempPathW
0x180010170 GetLastError
0x180010178 lstrcmpiA
0x180010180 Process32FirstW
0x180010188 IsWow64Process
0x180010190 Process32NextW
0x180010198 CreateMutexA
0x1800101a0 DeleteFileW
0x1800101a8 CreateThread
0x1800101b0 lstrcpyA
0x1800101b8 GetThreadContext
0x1800101c0 GetFileSize
0x1800101c8 SetThreadContext
0x1800101d0 GetNativeSystemInfo
0x1800101d8 CreateProcessA
0x1800101e0 ReadFile
0x1800101e8 MultiByteToWideChar
0x1800101f0 ResumeThread
0x1800101f8 HeapReAlloc
0x180010200 HeapFree
0x180010208 GetModuleHandleW
0x180010210 HeapCreate
0x180010218 Thread32Next
0x180010220 FlushInstructionCache
0x180010228 OpenThread
0x180010230 GetCurrentThreadId
0x180010238 GetCurrentProcessId
0x180010240 SuspendThread
0x180010248 VirtualQuery
0x180010250 VirtualFree
0x180010258 VirtualAlloc
0x180010260 GetSystemInfo
0x180010268 EncodePointer
0x180010270 DecodePointer
0x180010278 GetCommandLineA
0x180010280 RtlPcToFileHeader
0x180010288 RaiseException
0x180010290 RtlLookupFunctionEntry
0x180010298 RtlUnwindEx
0x1800102a0 ExitProcess
0x1800102a8 GetModuleHandleExW
0x1800102b0 HeapSize
0x1800102b8 GetStdHandle
0x1800102c0 GetModuleFileNameW
0x1800102d0 IsDebuggerPresent
0x1800102d8 IsValidCodePage
0x1800102e0 GetACP
0x1800102e8 GetOEMCP
0x1800102f0 GetCPInfo
0x1800102f8 SetLastError
0x180010300 GetFileType
0x180010310 DeleteCriticalSection
0x180010318 InitOnceExecuteOnce
0x180010320 GetStartupInfoW
0x180010328 GetModuleFileNameA
0x180010330 QueryPerformanceCounter
0x180010338 GetSystemTimeAsFileTime
0x180010340 GetTickCount64
0x180010348 GetEnvironmentStringsW
0x180010350 FreeEnvironmentStringsW
0x180010358 RtlCaptureContext
0x180010360 RtlVirtualUnwind
0x180010368 UnhandledExceptionFilter
0x180010378 FlsAlloc
0x180010380 FlsGetValue
0x180010388 FlsSetValue
0x180010390 FlsFree
0x180010398 EnterCriticalSection
0x1800103a0 LeaveCriticalSection

Exports

Ordinal Address Name
1 0x18000d298 ?ReflectiveLoader@@YA_KXZ
!This program cannot be run in DOS mode.
`.rdata
@.data
.pdata
@.reloc
@VWAVH
fD94zu
WAVAWH
A_A^_
SVWAVAWH
0A_A^_^[
x UATAUAVAWH
9D$,uy
9D$(tmL
A_A^A]A\]
@09\$@t
x UATAUAVAWH
A_A^A]A\]
` UAVAWH
UVWATAUAVAWE3
L+L$@E
\$XA_A^A]A\_^]
fffffff
ATAVAWH
A_A^A\
A:8uiI
t"A88t
VWATAVAWH
A_A^A\_^
x ATAVAWH
A_A^A\
x UAVAWH
Genuua
ineIuY
nteluQ3
WATAUAVAWH
@A_A^A]A\_
WATAUAVAWH
A_A^A]A\_
t$ WAVAWH
l$ VWATAVAWH
T$&@8t$&t9@8r
A81t@@8r
A_A^A\_^
` AUAVAWH
t$HHc0I
\$0D9=
A_A^A]
Hct$@H
sYHcL$HH
x ATAVAWH
A_A^A\
H3E H3E
VWATAVAWH
A_A^A\_^
UVWATAUAVAWH
A_A^A]A\_^]
D8eoupH
UVWATAUAVAWH
pA_A^A]A\_^]
WATAUAVAWH
A_A^A]A\_
AUAVAWH
0A_A^A]
@SVWATAUAVAWH
L!|$@L!
D$HHcH
A_A^A]A\_^[
SVWATAUAVAWH
0A_A^A]A\_^[
WATAVH
@A^A\_
LcA<E3
VWATAVAWH
0A_A^A\_^
@SUVWATAVAWH
PA_A^A\_^][
@UATAUAVAWH
!t$(H!t$ I
A_A^A]A\]
@UATAUAVAWH
A_A^A]A\]
AUAVAWH
0A_A^A]
VWATAVAWH
A_A^A\_^
\$ UVWATAUAVAWH
!|$HHc
|$HD9l$X
HcD$LH;
HcD$LH;
H!|$ L
A_A^A]A\_^]
D82u&H
D8t$Ht
xe;=t4
UVWATAUAVAWH
A_A^A]A\_^]
<9A|*H
WAVAWH
HcA<H
H WATAUAVAWH
A_A^A]A\_
@USVWATAUAVAWH
t)IcD$<A
L+W0D9
XA_A^A]A\_^[]
UVWATAUAVAWH
D9t$`t/H
A_A^A]A\_^]
UAVAWH
SUVWATAVAWH
0A_A^A\_^][
f9\$ u
UATAUAVAWH
D$`Ic_<3
A_A^A]A\]
H(H9J(u
permission denied
file exists
no such device
filename too long
device or resource busy
io error
directory not empty
invalid argument
no space on device
no such file or directory
function not supported
no lock available
not enough memory
resource unavailable try again
cross device link
operation canceled
too many files open
permission_denied
address_in_use
address_not_available
address_family_not_supported
connection_already_in_progress
bad_file_descriptor
connection_aborted
connection_refused
connection_reset
destination_address_required
bad_address
host_unreachable
operation_in_progress
interrupted
invalid_argument
already_connected
too_many_files_open
message_size
filename_too_long
network_down
network_reset
network_unreachable
no_buffer_space
no_protocol_option
not_connected
not_a_socket
operation_not_supported
protocol_not_supported
wrong_protocol_type
timed_out
operation_would_block
address family not supported
address in use
address not available
already connected
argument list too long
argument out of domain
bad address
bad file descriptor
bad message
broken pipe
connection aborted
connection already in progress
connection refused
connection reset
destination address required
executable format error
file too large
host unreachable
identifier removed
illegal byte sequence
inappropriate io control operation
invalid seek
is a directory
message size
network down
network reset
network unreachable
no buffer space
no child process
no link
no message available
no message
no protocol option
no stream resources
no such device or address
no such process
not a directory
not a socket
not a stream
not connected
not supported
operation in progress
operation not permitted
operation not supported
operation would block
owner dead
protocol error
protocol not supported
read only file system
resource deadlock would occur
result out of range
state not recoverable
stream timeout
text file busy
timed out
too many files open in system
too many links
too many symbolic link levels
value too large
wrong protocol type
bad allocation
Unknown exception
CorExitProcess
Sunday
Monday
Tuesday
Wednesday
Thursday
Friday
Saturday
January
February
August
September
October
November
December
MM/dd/yy
dddd, MMMM dd, yyyy
HH:mm:ss
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
GetCurrentPackageId
bad exception
MessageBoxW
GetActiveWindow
GetLastActivePopup
GetUserObjectInformationW
GetProcessWindowStation
__based(
__cdecl
__pascal
__stdcall
__thiscall
__fastcall
__clrcall
__eabi
__ptr64
__restrict
__unaligned
restrict(
delete
operator
`vftable'
`vbtable'
`vcall'
`typeof'
`local static guard'
`string'
`vbase destructor'
`vector deleting destructor'
`default constructor closure'
`scalar deleting destructor'
`vector constructor iterator'
`vector destructor iterator'
`vector vbase constructor iterator'
`virtual displacement map'
`eh vector constructor iterator'
`eh vector destructor iterator'
`eh vector vbase constructor iterator'
`copy constructor closure'
`udt returning'
`local vftable'
`local vftable constructor closure'
new[]
delete[]
`omni callsig'
`placement delete closure'
`placement delete[] closure'
`managed vector constructor iterator'
`managed vector destructor iterator'
`eh vector copy constructor iterator'
`eh vector vbase copy constructor iterator'
`dynamic initializer for '
`dynamic atexit destructor for '
`vector copy constructor iterator'
`vector vbase copy constructor iterator'
`managed vector copy constructor iterator'
`local static thread guard'
Type Descriptor'
Base Class Descriptor at (
Base Class Array'
Class Hierarchy Descriptor'
Complete Object Locator'
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
generic
unknown error
iostream
iostream stream error
system
LoadLibraryA
kernel32.dll
SeDebugPrivilege
ReflectiveLoader
firefox.exe
chrome.exe
trusteer
chrome.exe
opera.exe
msedge.exe
brave.exe
browser.exe
AvastBrowser.exe
AVGBrowser.exe
--disable-http2 --use-spdy=off --disable-quic
firefox.exe
taskmgr.exe
Diamotrixed
\\.\pipe\%s
CreateProcessInternalW
CreateProcessInternalW
rbNSpGEsyb
string too long
invalid string position
vector<T> too long
PathFindFileNameW
PathFileExistsA
PathFindFileNameA
SHLWAPI.dll
wsprintfA
USER32.dll
SHGetFolderPathA
SHELL32.dll
NtQueryInformationProcess
ntdll.dll
InternetOpenW
HttpQueryInfoA
InternetOpenUrlW
InternetReadFile
InternetCloseHandle
WININET.dll
OpenProcessToken
LookupPrivilegeValueA
AdjustTokenPrivileges
ADVAPI32.dll
GetCurrentProcess
Process32First
WaitForSingleObject
CreateRemoteThread
OpenProcess
VirtualFreeEx
GetProcAddress
VirtualAllocEx
Process32Next
GetModuleHandleA
CreateToolhelp32Snapshot
CloseHandle
WriteProcessMemory
VirtualProtectEx
VirtualProtect
GetTempFileNameW
CreateFileA
lstrlenA
CreateProcessW
HeapAlloc
CompareFileTime
GetProcessHeap
WriteFile
GetProcessTimes
WideCharToMultiByte
TerminateProcess
CreateFileW
lstrcatA
GetTempPathW
GetLastError
lstrcmpiA
Process32FirstW
IsWow64Process
Process32NextW
CreateMutexA
DeleteFileW
CreateThread
lstrcpyA
GetThreadContext
GetFileSize
SetThreadContext
GetNativeSystemInfo
CreateProcessA
ReadFile
MultiByteToWideChar
ResumeThread
HeapReAlloc
HeapFree
GetModuleHandleW
Thread32First
HeapCreate
Thread32Next
FlushInstructionCache
OpenThread
GetCurrentThreadId
GetCurrentProcessId
SuspendThread
VirtualQuery
VirtualFree
VirtualAlloc
GetSystemInfo
EncodePointer
DecodePointer
GetCommandLineA
RtlPcToFileHeader
RaiseException
RtlLookupFunctionEntry
RtlUnwindEx
ExitProcess
GetModuleHandleExW
HeapSize
GetStdHandle
GetModuleFileNameW
IsProcessorFeaturePresent
IsDebuggerPresent
IsValidCodePage
GetACP
GetOEMCP
GetCPInfo
SetLastError
GetFileType
InitializeCriticalSectionAndSpinCount
DeleteCriticalSection
InitOnceExecuteOnce
GetStartupInfoW
GetModuleFileNameA
QueryPerformanceCounter
GetSystemTimeAsFileTime
GetTickCount64
GetEnvironmentStringsW
FreeEnvironmentStringsW
RtlCaptureContext
RtlVirtualUnwind
UnhandledExceptionFilter
SetUnhandledExceptionFilter
FlsAlloc
FlsGetValue
FlsSetValue
FlsFree
EnterCriticalSection
LeaveCriticalSection
LoadLibraryExW
OutputDebugStringW
LoadLibraryW
LCMapStringEx
GetStringTypeW
FlushFileBuffers
GetConsoleCP
GetConsoleMode
SetStdHandle
SetFilePointerEx
WriteConsoleW
KERNEL32.dll
Loader.bin
?ReflectiveLoader@@YA_KXZ
.?AVbad_alloc@std@@
.?AVexception@std@@
.?AVlogic_error@std@@
.?AVlength_error@std@@
.?AVout_of_range@std@@
.?AVtype_info@@
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
.?AVbad_exception@std@@
.?AV_Iostream_error_category@std@@
.?AV_System_error_category@std@@
.?AVerror_category@std@@
.?AV_Generic_error_category@std@@
!This program cannot be run in DOS mode.
*XRich
`.rdata
@.data
@.reloc
CE SPW
L$$_^3
QQSVWd
Genuu_
ineIuV
nteluM3
uPVWhQ^@
~pjCXf
j@j _W
QQSVWh
j"_f9y
HtHu4j
URPQQh0
;t$,v-
UQPXY]Y[
PP9E u
x$;5$-A
x&;5$-A
~';_t|%3
xy;5$-A
permission denied
file exists
no such device
filename too long
device or resource busy
io error
directory not empty
invalid argument
no space on device
no such file or directory
function not supported
no lock available
not enough memory
resource unavailable try again
cross device link
operation canceled
too many files open
permission_denied
address_in_use
address_not_available
address_family_not_supported
connection_already_in_progress
bad_file_descriptor
connection_aborted
connection_refused
connection_reset
destination_address_required
bad_address
host_unreachable
operation_in_progress
interrupted
invalid_argument
already_connected
too_many_files_open
message_size
filename_too_long
network_down
network_reset
network_unreachable
no_buffer_space
no_protocol_option
not_connected
not_a_socket
operation_not_supported
protocol_not_supported
wrong_protocol_type
timed_out
operation_would_block
address family not supported
address in use
address not available
already connected
argument list too long
argument out of domain
bad address
bad file descriptor
bad message
broken pipe
connection aborted
connection already in progress
connection refused
connection reset
destination address required
executable format error
file too large
host unreachable
identifier removed
illegal byte sequence
inappropriate io control operation
invalid seek
is a directory
message size
network down
network reset
network unreachable
no buffer space
no child process
no link
no message available
no message
no protocol option
no stream resources
no such device or address
no such process
not a directory
not a socket
not a stream
not connected
not supported
operation in progress
operation not permitted
operation not supported
operation would block
owner dead
protocol error
protocol not supported
read only file system
resource deadlock would occur
result out of range
state not recoverable
stream timeout
text file busy
timed out
too many files open in system
too many links
too many symbolic link levels
value too large
wrong protocol type
bad allocation
Unknown exception
CorExitProcess
GetCurrentPackageId
bad exception
MessageBoxW
GetActiveWindow
GetLastActivePopup
GetUserObjectInformationW
GetProcessWindowStation
__based(
__cdecl
__pascal
__stdcall
__thiscall
__fastcall
__clrcall
__eabi
__ptr64
__restrict
__unaligned
restrict(
delete
operator
`vftable'
`vbtable'
`vcall'
`typeof'
`local static guard'
`string'
`vbase destructor'
`vector deleting destructor'
`default constructor closure'
`scalar deleting destructor'
`vector constructor iterator'
`vector destructor iterator'
`vector vbase constructor iterator'
`virtual displacement map'
`eh vector constructor iterator'
`eh vector destructor iterator'
`eh vector vbase constructor iterator'
`copy constructor closure'
`udt returning'
`local vftable'
`local vftable constructor closure'
new[]
delete[]
`omni callsig'
`placement delete closure'
`placement delete[] closure'
`managed vector constructor iterator'
`managed vector destructor iterator'
`eh vector copy constructor iterator'
`eh vector vbase copy constructor iterator'
`dynamic initializer for '
`dynamic atexit destructor for '
`vector copy constructor iterator'
`vector vbase copy constructor iterator'
`managed vector copy constructor iterator'
`local static thread guard'
Type Descriptor'
Base Class Descriptor at (
Base Class Array'
Class Hierarchy Descriptor'
Complete Object Locator'
Sunday
Monday
Tuesday
Wednesday
Thursday
Friday
Saturday
January
February
August
September
October
November
December
MM/dd/yy
dddd, MMMM dd, yyyy
HH:mm:ss
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
generic
unknown error
iostream
iostream stream error
system
SeDebugPrivilege
chrome.exe
string too long
invalid string position
vector<T> too long
ReflectiveLoader
InternetOpenW
HttpQueryInfoA
InternetOpenUrlW
InternetReadFile
InternetCloseHandle
WININET.dll
OpenProcessToken
LookupPrivilegeValueA
AdjustTokenPrivileges
ADVAPI32.dll
HeapAlloc
GetCurrentProcess
Process32First
WaitForSingleObject
GetProcessHeap
OpenProcess
Process32Next
CreateToolhelp32Snapshot
CloseHandle
CreateRemoteThread
VirtualProtectEx
VirtualAllocEx
WriteProcessMemory
EncodePointer
DecodePointer
GetCommandLineW
RaiseException
RtlUnwind
IsDebuggerPresent
IsProcessorFeaturePresent
GetLastError
InterlockedDecrement
ExitProcess
GetModuleHandleExW
GetProcAddress
MultiByteToWideChar
HeapSize
GetStdHandle
WriteFile
GetModuleFileNameW
HeapFree
SetLastError
InterlockedIncrement
GetCurrentThreadId
GetFileType
InitializeCriticalSectionAndSpinCount
DeleteCriticalSection
InitOnceExecuteOnce
GetStartupInfoW
QueryPerformanceCounter
GetSystemTimeAsFileTime
GetTickCount64
GetEnvironmentStringsW
FreeEnvironmentStringsW
UnhandledExceptionFilter
SetUnhandledExceptionFilter
FlsAlloc
FlsGetValue
FlsSetValue
FlsFree
TerminateProcess
GetModuleHandleW
EnterCriticalSection
LeaveCriticalSection
LoadLibraryExW
IsValidCodePage
GetACP
GetOEMCP
GetCPInfo
HeapReAlloc
OutputDebugStringW
LoadLibraryW
WideCharToMultiByte
LCMapStringEx
GetStringTypeW
FlushFileBuffers
GetConsoleCP
GetConsoleMode
SetStdHandle
SetFilePointerEx
WriteConsoleW
CreateFileW
KERNEL32.dll
.?AVbad_alloc@std@@
.?AVexception@std@@
.?AVlogic_error@std@@
.?AVlength_error@std@@
.?AVout_of_range@std@@
.?AVtype_info@@
.?AVbad_exception@std@@
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
.?AV_Iostream_error_category@std@@
.?AV_System_error_category@std@@
.?AVerror_category@std@@
.?AV_Generic_error_category@std@@
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0"><trustInfo xmlns="urn:schemas-microsoft-com:asm.v3"><security><requestedPrivileges><requestedExecutionLevel level="asInvoker" uiAccess="false"></requestedExecutionLevel></requestedPrivileges></security></trustInfo><application xmlns="urn:schemas-microsoft-com:asm.v3"><windowsSettings><dpiAware xmlns="http://schemas.microsoft.com/SMI/2005/WindowsSettings">true</dpiAware></windowsSettings></application></assembly>
1,282W2d2t2
2 3+323?3Z3
354<4I4[4t4}4
7J92:O<Y<s=}=
0`1`2M3
8I9c9y9
:7:R:m:
;1;<;_;j;v;
>7>U>\>`>d>h>l>p>t>x>
>:?E?`?g?l?p?t?
0^0d0h0l0p0
2K2R2Z2
3F6g6r6x6
;!<(<,<0<4<8<<<@<D<
3<3^3t3
374A4H4[4
5$5.5>5N5^5g5w5
627:7M7X7]7o7z7
7Y8p8}8
9#9(94999X9
:8:>:~:
=K=c=m=
>&?<?B?T?
0!0&0}0
7 7,71777K7Y7e7}7
9=:I:O:U:[:
=(=3=Q=m=u=z=
=!>)>4>9>T>Y>x>
?/?8???H?O?f?|?
O0Z0`0
[0x0~0
1?1N1U1
5/666K6U6
7-9?9y9
9M:]:s:
;+;2;Y;
>X>^>j>
2'2-232;2A2G2O2U2[2c2l2s2{2
8#828<8b8
1'191K1]1o1
1C6d6k6
797Y7n7x7
8@9S9c9
0>1H1N1b1n1
333U3\3
8)8/848<8B8b8
8#9B9b9q9
T1X1\1h1l1p1t1x1
2$2,242<2D2L2T2\2d2l2t2|2
3$3,343<3D3L3T3\3d3l3t3|3
4$4,444<4D4L4T4\4d4l4t4|4
5$5,545<5D5L5T5\5d5l5t5|5
6$6,646<6D6L6T6\6d6
? ?$?(?,?0?4?8?<?@?D?H?L?P?T?X?\?`?d?h?l?p?
$0,040<0D0L0T0\0d0l0t0|0
0\;`;d;h;|;
;8<<<@<D<H<L<P<T<X<\<`<d<h<l<p<t<x<|<
= =$=(=,=0=4=8=<=@=D=H=L=P=T=X=\=`=d=h=l=p=t=x=|=
l0p0x0
1 1(1@1P1T1d1h1l1p1x1
2(282<2L2P2`2d2h2p2
3 30343D3H3L3T3l3|3
4 444<4P4X4l4t4|4
5 5@5`5
60686<6X6`6d6|6
7 7(70747<7P7p7
808<8X8x8
9$9,9p9
: :0:<:\:d:l:x:
080X0x0
489<9@9D9H9L9P9T9X9\9`9d9h9l9p9t9x9|9
: :$:(:,:0:4:8:<:@:D:H:L:P:T:X:\:`:d:h:l:p:t:x:|:
;$;0;4;8;<;`;h;
> >$>(>,>8><>@>D>H>L>P>T>\>`>p>
?,?0?4?
!This program cannot be run in DOS mode.
*XRich
`.rdata
@.data
@.reloc
CE SPW
L$$_^3
QQSVWd
Genuu_
ineIuV
nteluM3
uPVWhQ^@
~pjCXf
j@j _W
QQSVWh
j"_f9y
HtHu4j
URPQQh0
;t$,v-
UQPXY]Y[
PP9E u
x$;5$-A
x&;5$-A
~';_t|%3
xy;5$-A
permission denied
file exists
no such device
filename too long
device or resource busy
io error
directory not empty
invalid argument
no space on device
no such file or directory
function not supported
no lock available
not enough memory
resource unavailable try again
cross device link
operation canceled
too many files open
permission_denied
address_in_use
address_not_available
address_family_not_supported
connection_already_in_progress
bad_file_descriptor
connection_aborted
connection_refused
connection_reset
destination_address_required
bad_address
host_unreachable
operation_in_progress
interrupted
invalid_argument
already_connected
too_many_files_open
message_size
filename_too_long
network_down
network_reset
network_unreachable
no_buffer_space
no_protocol_option
not_connected
not_a_socket
operation_not_supported
protocol_not_supported
wrong_protocol_type
timed_out
operation_would_block
address family not supported
address in use
address not available
already connected
argument list too long
argument out of domain
bad address
bad file descriptor
bad message
broken pipe
connection aborted
connection already in progress
connection refused
connection reset
destination address required
executable format error
file too large
host unreachable
identifier removed
illegal byte sequence
inappropriate io control operation
invalid seek
is a directory
message size
network down
network reset
network unreachable
no buffer space
no child process
no link
no message available
no message
no protocol option
no stream resources
no such device or address
no such process
not a directory
not a socket
not a stream
not connected
not supported
operation in progress
operation not permitted
operation not supported
operation would block
owner dead
protocol error
protocol not supported
read only file system
resource deadlock would occur
result out of range
state not recoverable
stream timeout
text file busy
timed out
too many files open in system
too many links
too many symbolic link levels
value too large
wrong protocol type
bad allocation
Unknown exception
CorExitProcess
GetCurrentPackageId
bad exception
MessageBoxW
GetActiveWindow
GetLastActivePopup
GetUserObjectInformationW
GetProcessWindowStation
__based(
__cdecl
__pascal
__stdcall
__thiscall
__fastcall
__clrcall
__eabi
__ptr64
__restrict
__unaligned
restrict(
delete
operator
`vftable'
`vbtable'
`vcall'
`typeof'
`local static guard'
`string'
`vbase destructor'
`vector deleting destructor'
`default constructor closure'
`scalar deleting destructor'
`vector constructor iterator'
`vector destructor iterator'
`vector vbase constructor iterator'
`virtual displacement map'
`eh vector constructor iterator'
`eh vector destructor iterator'
`eh vector vbase constructor iterator'
`copy constructor closure'
`udt returning'
`local vftable'
`local vftable constructor closure'
new[]
delete[]
`omni callsig'
`placement delete closure'
`placement delete[] closure'
`managed vector constructor iterator'
`managed vector destructor iterator'
`eh vector copy constructor iterator'
`eh vector vbase copy constructor iterator'
`dynamic initializer for '
`dynamic atexit destructor for '
`vector copy constructor iterator'
`vector vbase copy constructor iterator'
`managed vector copy constructor iterator'
`local static thread guard'
Type Descriptor'
Base Class Descriptor at (
Base Class Array'
Class Hierarchy Descriptor'
Complete Object Locator'
Sunday
Monday
Tuesday
Wednesday
Thursday
Friday
Saturday
January
February
August
September
October
November
December
MM/dd/yy
dddd, MMMM dd, yyyy
HH:mm:ss
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
generic
unknown error
iostream
iostream stream error
system
SeDebugPrivilege
firefox.exe
string too long
invalid string position
vector<T> too long
ReflectiveLoader
InternetOpenW
HttpQueryInfoA
InternetOpenUrlW
InternetReadFile
InternetCloseHandle
WININET.dll
OpenProcessToken
LookupPrivilegeValueA
AdjustTokenPrivileges
ADVAPI32.dll
HeapAlloc
GetCurrentProcess
Process32First
WaitForSingleObject
GetProcessHeap
OpenProcess
Process32Next
CreateToolhelp32Snapshot
CloseHandle
CreateRemoteThread
VirtualProtectEx
VirtualAllocEx
WriteProcessMemory
EncodePointer
DecodePointer
GetCommandLineW
RaiseException
RtlUnwind
IsDebuggerPresent
IsProcessorFeaturePresent
GetLastError
InterlockedDecrement
ExitProcess
GetModuleHandleExW
GetProcAddress
MultiByteToWideChar
HeapSize
GetStdHandle
WriteFile
GetModuleFileNameW
HeapFree
SetLastError
InterlockedIncrement
GetCurrentThreadId
GetFileType
InitializeCriticalSectionAndSpinCount
DeleteCriticalSection
InitOnceExecuteOnce
GetStartupInfoW
QueryPerformanceCounter
GetSystemTimeAsFileTime
GetTickCount64
GetEnvironmentStringsW
FreeEnvironmentStringsW
UnhandledExceptionFilter
SetUnhandledExceptionFilter
FlsAlloc
FlsGetValue
FlsSetValue
FlsFree
TerminateProcess
GetModuleHandleW
EnterCriticalSection
LeaveCriticalSection
LoadLibraryExW
IsValidCodePage
GetACP
GetOEMCP
GetCPInfo
HeapReAlloc
OutputDebugStringW
LoadLibraryW
WideCharToMultiByte
LCMapStringEx
GetStringTypeW
FlushFileBuffers
GetConsoleCP
GetConsoleMode
SetStdHandle
SetFilePointerEx
WriteConsoleW
CreateFileW
KERNEL32.dll
.?AVbad_alloc@std@@
.?AVexception@std@@
.?AVlogic_error@std@@
.?AVlength_error@std@@
.?AVout_of_range@std@@
.?AVtype_info@@
.?AVbad_exception@std@@
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
.?AV_Iostream_error_category@std@@
.?AV_System_error_category@std@@
.?AVerror_category@std@@
.?AV_Generic_error_category@std@@
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0"><trustInfo xmlns="urn:schemas-microsoft-com:asm.v3"><security><requestedPrivileges><requestedExecutionLevel level="asInvoker" uiAccess="false"></requestedExecutionLevel></requestedPrivileges></security></trustInfo><application xmlns="urn:schemas-microsoft-com:asm.v3"><windowsSettings><dpiAware xmlns="http://schemas.microsoft.com/SMI/2005/WindowsSettings">true</dpiAware></windowsSettings></application></assembly>
1,282W2d2t2
2 3+323?3Z3
354<4I4[4t4}4
7J92:O<Y<s=}=
0`1`2M3
8I9c9y9
:7:R:m:
;1;<;_;j;v;
>7>U>\>`>d>h>l>p>t>x>
>:?E?`?g?l?p?t?
0^0d0h0l0p0
2K2R2Z2
3F6g6r6x6
;!<(<,<0<4<8<<<@<D<
3<3^3t3
374A4H4[4
5$5.5>5N5^5g5w5
627:7M7X7]7o7z7
7Y8p8}8
9#9(94999X9
:8:>:~:
=K=c=m=
>&?<?B?T?
0!0&0}0
7 7,71777K7Y7e7}7
9=:I:O:U:[:
=(=3=Q=m=u=z=
=!>)>4>9>T>Y>x>
?/?8???H?O?f?|?
O0Z0`0
[0x0~0
1?1N1U1
5/666K6U6
7-9?9y9
9M:]:s:
;+;2;Y;
>X>^>j>
2'2-232;2A2G2O2U2[2c2l2s2{2
8#828<8b8
1'191K1]1o1
1C6d6k6
797Y7n7x7
8@9S9c9
0>1H1N1b1n1
333U3\3
8)8/848<8B8b8
8#9B9b9q9
T1X1\1h1l1p1t1x1
2$2,242<2D2L2T2\2d2l2t2|2
3$3,343<3D3L3T3\3d3l3t3|3
4$4,444<4D4L4T4\4d4l4t4|4
5$5,545<5D5L5T5\5d5l5t5|5
6$6,646<6D6L6T6\6d6
? ?$?(?,?0?4?8?<?@?D?H?L?P?T?X?\?`?d?h?l?p?
$0,040<0D0L0T0\0d0l0t0|0
0\;`;d;h;|;
;8<<<@<D<H<L<P<T<X<\<`<d<h<l<p<t<x<|<
= =$=(=,=0=4=8=<=@=D=H=L=P=T=X=\=`=d=h=l=p=t=x=|=
l0p0x0
1 1(1@1P1T1d1h1l1p1x1
2(282<2L2P2`2d2h2p2
3 30343D3H3L3T3l3|3
4 444<4P4X4l4t4|4
5 5@5`5
60686<6X6`6d6|6
7 7(70747<7P7p7
808<8X8x8
9$9,9p9
: :0:<:\:d:l:x:
080X0x0
489<9@9D9H9L9P9T9X9\9`9d9h9l9p9t9x9|9
: :$:(:,:0:4:8:<:@:D:H:L:P:T:X:\:`:d:h:l:p:t:x:|:
;$;0;4;8;<;`;h;
> >$>(>,>8><>@>D>H>L>P>T>\>`>p>
?,?0?4?
d[[[[[
[[[[[[[[[[[[js
[RRRR[[[[w|w
vv[[[[[[[[[[[
@@@@AI@@@@LB@@@@@@@@ODS@@@DWC\@`@@@@@@@@@@@@@@dfnk@@jF@@DF@@[D@@
mscoree.dll
- floating point support not loaded
- not enough space for arguments
- not enough space for environment
- abort() has been called
- not enough space for thread data
- unexpected multithread lock error
- unexpected heap error
- unable to open console device
- not enough space for _onexit/atexit table
- pure virtual function call
- not enough space for stdio initialization
- not enough space for lowio initialization
- unable to initialize heap
- CRT not initialized
- Attempt to initialize the CRT more than once.
This indicates a bug in your application.
- not enough space for locale information
- Attempt to use MSIL code from this assembly during native code initialization
This indicates a bug in your application. It is most likely the result of calling an MSIL-compiled (/clr) function from a native constructor or from DllMain.
- inconsistent onexit begin-end variables
DOMAIN error
SING error
TLOSS error
runtime error
Runtime Error!
Program:
<program name unknown>
Microsoft Visual C++ Runtime Library
Sunday
Monday
Tuesday
Wednesday
Thursday
Friday
Saturday
January
February
August
September
October
November
December
MM/dd/yy
dddd, MMMM dd, yyyy
HH:mm:ss
kernel32.dll
USER32.DLL
((((( H
h(((( H
H
CONOUT$
Mozilla/5.0
http://176.111.174.140/api/bot.bin
http://176.111.174.140/api/bot.bin
explorer.exe
http://176.111.174.140/api/bot64.bin
http://176.111.174.140/api/bot64.bin
Kernel32.dll
KernelBase.dll
Diamotrix
Diamotrix
Amscoree.dll
@R6002
- floating point support not loaded
- not enough space for arguments
- not enough space for environment
- abort() has been called
- not enough space for thread data
- unexpected multithread lock error
- unexpected heap error
- unable to open console device
- not enough space for _onexit/atexit table
- pure virtual function call
- not enough space for stdio initialization
- not enough space for lowio initialization
- unable to initialize heap
- CRT not initialized
- Attempt to initialize the CRT more than once.
This indicates a bug in your application.
- not enough space for locale information
- Attempt to use MSIL code from this assembly during native code initialization
This indicates a bug in your application. It is most likely the result of calling an MSIL-compiled (/clr) function from a native constructor or from DllMain.
- inconsistent onexit begin-end variables
DOMAIN error
SING error
TLOSS error
runtime error
Runtime Error!
Program:
<program name unknown>
Microsoft Visual C++ Runtime Library
dkernel32.dll
@ja-JP
USER32.DLL
Sunday
Monday
Tuesday
Wednesday
Thursday
Friday
Saturday
January
February
August
September
October
November
December
MM/dd/yy
dddd, MMMM dd, yyyy
HH:mm:ss
((((( H
h(((( H
H
CONOUT$
NIKMOK
Amscoree.dll
@R6002
- floating point support not loaded
- not enough space for arguments
- not enough space for environment
- abort() has been called
- not enough space for thread data
- unexpected multithread lock error
- unexpected heap error
- unable to open console device
- not enough space for _onexit/atexit table
- pure virtual function call
- not enough space for stdio initialization
- not enough space for lowio initialization
- unable to initialize heap
- CRT not initialized
- Attempt to initialize the CRT more than once.
This indicates a bug in your application.
- not enough space for locale information
- Attempt to use MSIL code from this assembly during native code initialization
This indicates a bug in your application. It is most likely the result of calling an MSIL-compiled (/clr) function from a native constructor or from DllMain.
- inconsistent onexit begin-end variables
DOMAIN error
SING error
TLOSS error
runtime error
Runtime Error!
Program:
<program name unknown>
Microsoft Visual C++ Runtime Library
dkernel32.dll
@ja-JP
USER32.DLL
Sunday
Monday
Tuesday
Wednesday
Thursday
Friday
Saturday
January
February
August
September
October
November
December
MM/dd/yy
dddd, MMMM dd, yyyy
HH:mm:ss
((((( H
h(((( H
H
CONOUT$
NIKMOK
Antivirus Signature
Bkav W64.AIDetectMalware
Lionic Trojan.Win32.Redcap.4!c
Elastic malicious (high confidence)
ClamAV Clean
CMC Clean
CAT-QuickHeal Clean
Skyhigh BehavesLike.Win64.PUP.dm
ALYac Gen:Variant.Lazy.604083
Cylance Unsafe
Zillya Clean
Sangfor Trojan.Win32.Lazy.Vnmd
CrowdStrike win/malicious_confidence_90% (D)
Alibaba TrojanDownloader:Win32/Redcap.e6cc7e01
K7GW Riskware ( 00584baa1 )
K7AntiVirus Riskware ( 00584baa1 )
huorong Clean
Baidu Clean
VirIT Clean
Paloalto generic.ml
Symantec ML.Attribute.HighConfidence
tehtris Clean
ESET-NOD32 Clean
APEX Malicious
Avast Win32:MalwareX-gen [Trj]
Cynet Malicious (score: 100)
Kaspersky HEUR:Trojan.Win32.Generic
BitDefender Gen:Variant.Lazy.604083
NANO-Antivirus Clean
ViRobot Clean
MicroWorld-eScan Gen:Variant.Lazy.604083
Tencent Win64.Trojan-Downloader.Agent.Tsmw
Sophos Harmony Loader (PUA)
F-Secure Trojan.TR/Redcap.otcpx
DrWeb Clean
VIPRE Gen:Variant.Lazy.604083
TrendMicro Clean
McAfeeD ti!E7548FF8C5DA
Trapmine malicious.high.ml.score
CTX dll.trojan.generic
Emsisoft Gen:Variant.Lazy.604083 (B)
Ikarus Clean
FireEye Generic.mg.079caee72a8dac67
Jiangmin Trojan.Generic.htciv
Webroot Clean
Varist W64/ABApplication.FAXW-8619
Avira TR/Redcap.otcpx
Fortinet W32/PossibleThreat
Antiy-AVL Trojan/Win32.Agent
Kingsoft malware.kb.a.1000
Gridinsoft Trojan.Win64.Agent.sa
Xcitium Clean
Arcabit Trojan.Lazy.D937B3
SUPERAntiSpyware Clean
ZoneAlarm HEUR:Trojan-Downloader.Win64.Agent.c
Microsoft Trojan:Win32/Wacatac.B!ml
Google Clean
AhnLab-V3 Trojan/Win.Inject.R672501
Acronis Clean
McAfee Artemis!079CAEE72A8D
TACHYON Clean
VBA32 Clean
Malwarebytes Malware.AI.798652179
Panda Trj/GdSda.A
Zoner Clean
TrendMicro-HouseCall Clean
Rising Trojan.Generic!8.C3 (TFE:5:QWGKLDjTyfV)
Yandex Clean
SentinelOne Static AI - Malicious PE
MaxSecure Clean
GData Gen:Variant.Lazy.604083
AVG Win32:MalwareX-gen [Trj]
DeepInstinct MALICIOUS
alibabacloud Trojan[downloader]:Win/Wacapew.C9nj
No IRMA results available.