Static | ZeroBOX

PE Compile Time

2024-10-09 21:37:21

PE Imphash

91d1583dab6f50e9cc35b0dbf587fb1f

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x00066292 0x00066400 6.57514263919
.rdata 0x00068000 0x0001913e 0x00019200 5.27525303878
.data 0x00082000 0x00007c34 0x00003800 3.86805454787
.rsrc 0x0008a000 0x000001e0 0x00000200 4.71767883295
.reloc 0x0008b000 0x00005ff0 0x00006000 6.62402004952

Resources

Name Offset Size Language Sub-language File type
RT_MANIFEST 0x0008a060 0x0000017d LANG_ENGLISH SUBLANG_ENGLISH_US XML 1.0 document text

Imports

Library KERNEL32.dll:
0x468060 GetFileAttributesA
0x468064 Process32NextW
0x468068 CreateFileA
0x46806c Process32FirstW
0x468070 CloseHandle
0x468074 GetSystemInfo
0x468078 CreateThread
0x46807c GetLocalTime
0x468080 GetThreadContext
0x468084 GetProcAddress
0x468088 GetLastError
0x46808c RemoveDirectoryA
0x468090 ReadProcessMemory
0x468094 CreateProcessA
0x468098 CreateDirectoryA
0x46809c SetThreadContext
0x4680a0 SetEndOfFile
0x4680a4 HeapSize
0x4680a8 GetProcessHeap
0x4680b8 GetTempPathA
0x4680bc Sleep
0x4680c4 OpenProcess
0x4680cc GetModuleHandleA
0x4680d0 ResumeThread
0x4680d4 GetComputerNameExW
0x4680d8 GetVersionExW
0x4680dc WaitForSingleObject
0x4680e0 CreateMutexA
0x4680e4 FindClose
0x4680e8 PeekNamedPipe
0x4680ec CreatePipe
0x4680f0 FindNextFileA
0x4680f4 VirtualAlloc
0x4680fc WriteFile
0x468100 VirtualFree
0x468104 FindFirstFileA
0x46810c WriteProcessMemory
0x468110 GetModuleFileNameA
0x468114 VirtualAllocEx
0x468118 ReadFile
0x468120 GetOEMCP
0x468124 GetACP
0x468128 IsValidCodePage
0x46812c FindNextFileW
0x468130 FindFirstFileExW
0x468138 HeapReAlloc
0x46813c ReadConsoleW
0x468140 SetStdHandle
0x468144 GetFullPathNameW
0x46814c DeleteFileW
0x468150 EnumSystemLocalesW
0x468154 GetUserDefaultLCID
0x468158 IsValidLocale
0x46815c HeapAlloc
0x468160 HeapFree
0x468164 GetConsoleMode
0x468168 GetConsoleCP
0x46816c FlushFileBuffers
0x468170 SetFilePointerEx
0x468174 GetFileSizeEx
0x468178 GetCommandLineW
0x46817c GetCommandLineA
0x468180 GetStdHandle
0x46818c GetFileType
0x468194 GetDriveTypeW
0x468198 CreateFileW
0x46819c ExitProcess
0x4681a0 RtlUnwind
0x4681a4 LoadLibraryW
0x4681a8 UnregisterWaitEx
0x4681ac QueryDepthSList
0x4681b4 RaiseException
0x4681b8 GetCurrentThreadId
0x4681c0 QueueUserWorkItem
0x4681c4 GetModuleHandleExW
0x4681c8 FormatMessageW
0x4681cc WideCharToMultiByte
0x4681e0 SetLastError
0x4681e8 CreateEventW
0x4681ec SwitchToThread
0x4681f0 TlsAlloc
0x4681f4 TlsGetValue
0x4681f8 TlsSetValue
0x4681fc TlsFree
0x468204 GetTickCount
0x468208 GetModuleHandleW
0x468214 EncodePointer
0x468218 DecodePointer
0x46821c MultiByteToWideChar
0x468220 CompareStringW
0x468224 LCMapStringW
0x468228 GetLocaleInfoW
0x46822c GetStringTypeW
0x468230 GetCPInfo
0x468234 SetEvent
0x468238 ResetEvent
0x468244 GetCurrentProcess
0x468248 TerminateProcess
0x46824c IsDebuggerPresent
0x468250 GetStartupInfoW
0x468254 GetCurrentProcessId
0x468258 InitializeSListHead
0x46825c CreateTimerQueue
0x468260 SignalObjectAndWait
0x468264 SetThreadPriority
0x468268 GetThreadPriority
0x46828c UnregisterWait
0x468290 GetCurrentThread
0x468294 GetThreadTimes
0x468298 FreeLibrary
0x4682a0 GetModuleFileNameW
0x4682a4 LoadLibraryExW
0x4682a8 VirtualProtect
0x4682ac DuplicateHandle
0x4682b0 ReleaseSemaphore
0x4682bc WriteConsoleW
Library USER32.dll:
0x4682d4 GetSystemMetrics
0x4682d8 ReleaseDC
0x4682dc GetDC
Library GDI32.dll:
0x46804c SelectObject
0x468050 CreateCompatibleDC
0x468054 DeleteObject
0x468058 BitBlt
Library ADVAPI32.dll:
0x468000 RevertToSelf
0x468004 RegCloseKey
0x468008 RegQueryInfoKeyW
0x46800c RegGetValueA
0x468010 RegQueryValueExA
0x468018 GetSidSubAuthority
0x46801c GetUserNameA
0x468024 LookupAccountNameA
0x46802c RegSetValueExA
0x468030 OpenProcessToken
0x468034 RegOpenKeyExA
0x468038 RegEnumValueA
0x46803c DuplicateTokenEx
Library SHELL32.dll:
0x4682c4 SHGetFolderPathA
0x4682c8 ShellExecuteA
0x4682cc SHFileOperationA
Library ole32.dll:
0x468364 CoUninitialize
0x468368 CoCreateInstance
0x46836c CoInitialize
Library WININET.dll:
0x4682e4 HttpOpenRequestA
0x4682e8 InternetWriteFile
0x4682ec InternetOpenUrlA
0x4682f0 InternetOpenW
0x4682f4 HttpEndRequestW
0x4682fc HttpSendRequestExA
0x468300 InternetOpenA
0x468304 InternetCloseHandle
0x468308 HttpSendRequestA
0x46830c InternetConnectA
0x468310 InternetReadFile
Library gdiplus.dll:
0x468344 GdiplusStartup
0x468348 GdipSaveImageToFile
0x468350 GdiplusShutdown
0x46835c GdipDisposeImage
Library WS2_32.dll:
0x468318 closesocket
0x46831c inet_pton
0x468320 getaddrinfo
0x468324 WSAStartup
0x468328 send
0x46832c socket
0x468330 connect
0x468334 recv
0x468338 htons
0x46833c freeaddrinfo

!This program cannot be run in DOS mode.
`.rdata
@.data
@.reloc
j h,]G
j\h(^G
jXh _G
j<h0cG
j4hXdG
j$hXeG
j@hhgG
u78Gdt
CM @PRj
uhh@oF
jIh@iG
VVVVh@hG
tdhT.H
uN9Fpt
u<9Fpt
urj@j"
u+h`<F
Wj4XPV
A(;A,v
O,9O(vV
+A Vj$
+AHVj(
FT9~Xt0
;{dv(2
@(;A(s
+A$tU3
G(9_Lu8
/SPPWh
FYY;w(|
FY;w(|
9V(~?j
V<;V8}
YYF;w,|
G@WVPR
Q;FD~Z
4Q;FD~Z
C8;sx|
tWVWj>
9V(~?j
V<;V8}
1QhXaC
tB;wPt
a;w0tV
:;w0tBj
);{0t3
FP;FL~
Q;FD~R
t]VWj>
}:;2|6
9pdt>V
Sk{$4kK(4
kG$4kW(4
BHkW($
Q;FD~R
t]VWj>
FY;w(|
9V(~?j
V<;V8}
O`j@SV
FY;w(|
Q;FD~R
FYY;w(|
9V(~>j
V<;V8}
9V(~Bj
V<;V8}
Q;FD~R
1QhXaC
F,H_[u
tO9xp~J
u28C`t
QQSVWd
URPQQh
;t$,v-
UQPXY]Y[
F4_^[]
<ItC<Lt3<Tt#<h
A<lt'<tt
SVWj03
WWWSHSh
WPWWWS
:u"f9z
ARPRQh
PPPPPPPP
SWt@jU
_tqPVj@
<at.<rt!<wt
<=upG8
Wj0XPV
SPjdVQ
QQSVj8j@
D8(Ht'
PPPPPWS
PP9E u:PPVWP
f95ThH
u kE$<
t4hoUE
zSSSSj
f9:t!V
NX9^`t1
;V\uYW
u2Vj@h
9C`u99C\t4
u29K\t-
PPPPPPPP
bad exception
bad allocation
system
unknown error
bad function call
device or resource busy
invalid argument
no such process
not enough memory
operation not permitted
resource deadlock would occur
resource unavailable try again
address family not supported
address in use
address not available
already connected
argument list too long
argument out of domain
bad address
bad file descriptor
bad message
broken pipe
connection aborted
connection already in progress
connection refused
connection reset
cross device link
destination address required
directory not empty
executable format error
file exists
file too large
filename too long
function not supported
host unreachable
identifier removed
illegal byte sequence
inappropriate io control operation
interrupted
invalid seek
io error
is a directory
message size
network down
network reset
network unreachable
no buffer space
no child process
no link
no lock available
no message available
no message
no protocol option
no space on device
no stream resources
no such device or address
no such device
no such file or directory
not a directory
not a socket
not a stream
not connected
not supported
operation canceled
operation in progress
operation not supported
operation would block
owner dead
permission denied
protocol error
protocol not supported
read only file system
result out of range
state not recoverable
stream timeout
text file busy
timed out
too many files open in system
too many files open
too many links
too many symbolic link levels
value too large
wrong protocol type
FlsAlloc
FlsFree
FlsGetValue
FlsSetValue
InitializeCriticalSectionEx
InitOnceExecuteOnce
CreateEventExW
CreateSemaphoreW
CreateSemaphoreExW
CreateThreadpoolTimer
SetThreadpoolTimer
WaitForThreadpoolTimerCallbacks
CloseThreadpoolTimer
CreateThreadpoolWait
SetThreadpoolWait
CloseThreadpoolWait
FlushProcessWriteBuffers
FreeLibraryWhenCallbackReturns
GetCurrentProcessorNumber
CreateSymbolicLinkW
GetCurrentPackageId
GetTickCount64
GetFileInformationByHandleEx
SetFileInformationByHandle
GetSystemTimePreciseAsFileTime
InitializeConditionVariable
WakeConditionVariable
WakeAllConditionVariable
SleepConditionVariableCS
InitializeSRWLock
AcquireSRWLockExclusive
TryAcquireSRWLockExclusive
ReleaseSRWLockExclusive
SleepConditionVariableSRW
CreateThreadpoolWork
SubmitThreadpoolWork
CloseThreadpoolWork
CompareStringEx
GetLocaleInfoEx
LCMapStringEx
0123456789abcdefghijklmnopqrstuvwxyz
0123456789abcdefghijklmnopqrstuvwxyz
pEvents
Lock already taken
SetThreadGroupAffinity
GetThreadGroupAffinity
GetCurrentProcessorNumberEx
GetLogicalProcessorInformationEx
pScheduler
version
eventObject
ppVirtualProcessorRoots
SchedulerKind
MaxConcurrency
MinConcurrency
TargetOversubscriptionFactor
LocalContextCacheSize
ContextStackSize
ContextPriority
SchedulingProtocol
DynamicProgressFeedback
WinRTInitialization
MaxPolicyElementKey
Mbp?333333
pContext
pExecutionResource
RoInitialize
RoUninitialize
RegisterTraceGuidsW
UnregisterTraceGuids
TraceEvent
GetTraceLoggerHandle
GetTraceEnableLevel
GetTraceEnableFlags
pThreadProxy
switchState
Access violation - no RTTI data!
Bad dynamic_cast!
__based(
__cdecl
__pascal
__stdcall
__thiscall
__fastcall
__vectorcall
__clrcall
__eabi
__swift_1
__swift_2
__ptr64
__restrict
__unaligned
restrict(
delete
operator
`vftable'
`vbtable'
`vcall'
`typeof'
`local static guard'
`string'
`vbase destructor'
`vector deleting destructor'
`default constructor closure'
`scalar deleting destructor'
`vector constructor iterator'
`vector destructor iterator'
`vector vbase constructor iterator'
`virtual displacement map'
`eh vector constructor iterator'
`eh vector destructor iterator'
`eh vector vbase constructor iterator'
`copy constructor closure'
`udt returning'
`local vftable'
`local vftable constructor closure'
new[]
delete[]
`omni callsig'
`placement delete closure'
`placement delete[] closure'
`managed vector constructor iterator'
`managed vector destructor iterator'
`eh vector copy constructor iterator'
`eh vector vbase copy constructor iterator'
`dynamic initializer for '
`dynamic atexit destructor for '
`vector copy constructor iterator'
`vector vbase copy constructor iterator'
`managed vector copy constructor iterator'
`local static thread guard'
operator ""
operator co_await
operator<=>
Type Descriptor'
Base Class Descriptor at (
Base Class Array'
Class Hierarchy Descriptor'
Complete Object Locator'
`anonymous namespace'
CorExitProcess
`h````
xpxxxx
(null)
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
[aOni*{
~ $s%r
@b;zO]
v2!L.2
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
UTF-16LEUNICODE
Sunday
Monday
Tuesday
Wednesday
Thursday
Friday
Saturday
January
February
August
September
October
November
December
MM/dd/yy
dddd, MMMM dd, yyyy
HH:mm:ss
AreFileApisANSI
EnumSystemLocalesEx
GetDateFormatEx
GetTimeFormatEx
GetUserDefaultLocaleName
IsValidLocaleName
LCIDToLocaleName
LocaleNameToLCID
AppPolicyGetProcessTerminationMethod
NAN(SNAN)
nan(snan)
NAN(IND)
nan(ind)
_hypot
_nextafter
1#QNAN
1#SNAN
]vQ<)8
|)P!?Ua0
Eb2]A=
u?^p?o4
y1~?|"
?x+s7
?5Od%
?|I7Z#
>,'1D=
?g)([|X>=
~U`?K
:h"?bC
@H#?43
Ax#?uN}*
r7Yr7=
F0$?3=1
H`$?h|
&?~YK|
sU0&?W
<8bunz8
?#%X.y
F||<##
<@En[vP
<8bunz8
l,kg<i
<@En[vP
?5Wg4p
%S#[k=
"B <1=
Unknown exception
bad array new length
generic
iostream
iostream stream error
Fail to schedule the chore!
This function cannot be called on a default constructed task
broken promise
future already retrieved
promise already satisfied
no state
future
invalid stoi argument
stoi argument out of range
bad locale name
ios_base::badbit set
ios_base::failbit set
ios_base::eofbit set
9de0451ffa8c2fdfc09ef4161fee0a87
0560249ade67ec7685a36e57ffd4df2f
61b84f
119166ab80fd58e21fa54aad0849e091
LCkjFNKEQjBBFX7CP9e=
J5hb4dC930el5DbudbPpjvVr1ME=
LV8lFq==
SB4a5BKy
HV5h7K==
JVZh7K==
LC39GNa SWN3EB==
P6lP7RLyQmS6QV==
S3cvOz4GZkSeK1ooeb7DgVPVNKht1mOrb6R2JXLDhmSw5K2qecLtgVV8KsZyI22fXT==
S3cvOz4GZkSeK1ooeb7DgVPVNKht1mOrb6R2JXLDhmSw5K2qecLtgVV8H2lA1G6uX0N2ORDqhiyV2LYxdrzKgVnfP2ND
S6V76hH6hA==
W55 BwZINFGPIJoXKr7DQWub
S3cvOz4GZkSeK1ooeb7DgVPVNKht1mOrb6R2JXLDhmSw5K2qecLtgVV8KsZy
aqZjSAnxRzFi
SKNkSXzmgXJ=
S3cvOz4GZkSeK1ooeb7DgVPVNKht1mOrb6R2JXLDhmSw5K2qecLtgVV8H2lA1G6uX0N2NW8qgGtiIrbx1vTChp==
HYZIKPzVZk6IJZAKLF==
VHJl6u==
SHcIOu==
W6NaSwVpgGu P7Auer3ogzn3
W6NaSwVpgGt=
W5Be6wVpgGt=
RZJe5a==
9KVP6xeAQw==
9KVP6BCaQy5=
J6JQ4QL5
J4Fh7Q4ugnJx
HqZj4RGd
a5la5AmERi2m3Lz=
95Zn5gLxRzFwQLAx
P5ZPMgv5fXWnL8oEfvTxXPVh2B==
SKNkSXzmgUOj5LIh
OY3qNVGlZ26o5MgmebS=
O03e6gu=
Q5Jo6ALDh2q7zJAm06==
PYRuOu==
SJJjSAulZ2Sl52Mufwi=
PJc97AZDNFanPl==
KC2lOAZ53WuVQ1Q6ebj4jJ==
OppPSALr4W2mQ2L=
Rpcn7AZz
S5cl4AZE
O5ci5WHA
T5pjKALr4W2mQ2L=
KGInFtG6Sj 6FV==
O5cj7ALziCYW62EqQ8zxiPnV12Fl2nNrXpcn5MRp3XOjFDEndSTy4zvt5Y4xASXp
JV4iEMQy
BTts5WV54W22CZUueSzzhVbV11cyDiyi 6NiEQHmiGB9zL8mdLScNfHc4LImDyyi9ZBa5gvy4TXk
Gj4zJWZziGSw5H4ZgMzpTbrc3MFw0WKdbJpk5cZA33On5H4EfwHp3PQIsl4O
BTsiEMQyQSX=
JV4Cva==
N6R96dQC
JptlSq==
O5cj7ALziCYW62EqQ8zlhArn11Rl3Gir lcTER48iyYo38MyNMTCgzLpO7coOWN=
S4pIOyLS2EK34sMqdcPHgVVV3rcwJ2SWVHRk5hHDg2ueH7byewT44QzJO15pMEKr 0FQ7ALDYmCvQV==
O5ci6BL54XGQP14q
WZN9SALr42er2rwxdL3zhAvt38V53na0c0slFNyESDR4EEj NK6=
J0Zj4QDA4GRv
S4pIOyLS2EK34sMqdcPHgVVV3rcwJ2SWVHRk5hHDg2ueM18ufvTo0fbfP1cgF06KTINEMzn1XUOHK6z=
S4pIOyLS2EKx3sUDdRvX4QGrCIJgJ2Subpp9SRDhVmCB21QJcMLAgzv0NK3tOGSr
Tpp SQZOWA==
VGElFxq=
PJZbRRLxiFKn5MUudbbDQe8NP2Rz1HSW9Zcj
PJZbRRLxiFKn5MUudbbDQebNP2Rz1HSW9Zcj
S3cvOz4GZkSeK1ooeb7DgVPVNKht1mOrb6Q6MfHhV3SA4rYzfuXphgDk278=
SKNkSBLoiE2j31X=
KmEmHK==
KmEnFa==
KmEmGa==
KmEnGK==
O6Zn6gLziEG321Ap
aqZjSAnxRzFwQ2kq
GqV76WjwfWuuzHbrKr7tgLqd
GlEbCcr5fWYn38Y5KsCkObObPLZwxA==
Hl26KR8uiCF=
GlEbCcrD4W1i
GF2bBu==
SJcSSRzEfGSu3H8qgvS=
JZZTSQD6iGix3sEAdvjnjLrtP15z3GSv9ZhjSQGlQUWr3LXlK6==
a5lQ7AHAi21iC2PlNMOkRt==
a6UY6q==
apJjSAZy
ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/
abcdefghijklmnopqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVWXYZ0123456789
Keyboard Layout\Preload
00000419
00000422
00000423
0000043f
System
NtUnmapViewOfSection
ntdll.dll
0x00000000
fDenyTSConnections
SYSTEM\CurrentControlSet\Control\Terminal Server
netsh advfirewall firewall set rule group="Remote Desktop" new enable=Yes
sc config termservice start= auto
net start termservice
" /add /y
net user "
" /add
net localgroup "Administrators" "
'" SET PasswordExpires=FALSE
WMIC USERACCOUNT WHERE "Name = '
'" SET Passwordchangeable=FALSE
' -DestinationPath '
powershell -Command Expand-Archive -Path '
vnc.exe
invalid string position
list too long
vector too long
string too long
0123456789ABCDEF
.text$di
.text$mn
.text$x
.text$yd
.idata$5
.00cfg
.CRT$XCA
.CRT$XCAA
.CRT$XCC
.CRT$XCL
.CRT$XCU
.CRT$XCZ
.CRT$XIA
.CRT$XIAA
.CRT$XIAC
.CRT$XIC
.CRT$XIZ
.CRT$XLA
.CRT$XLZ
.CRT$XPA
.CRT$XPB
.CRT$XPX
.CRT$XPXA
.CRT$XPZ
.CRT$XTA
.CRT$XTZ
.rdata
.rdata$T
.rdata$r
.rdata$sxdata
.rdata$zzzdbg
.rtc$IAA
.rtc$IZZ
.rtc$TAA
.rtc$TZZ
.tls$ZZZ
.xdata$x
.idata$2
.idata$3
.idata$4
.idata$6
.data$r
.rsrc$01
.rsrc$02
ReadFile
GetModuleFileNameA
WriteProcessMemory
SetHandleInformation
FindFirstFileA
VirtualFree
WriteFile
Wow64DisableWow64FsRedirection
VirtualAlloc
FindNextFileA
CreatePipe
PeekNamedPipe
FindClose
CreateMutexA
WaitForSingleObject
GetVersionExW
GetComputerNameExW
ResumeThread
GetModuleHandleA
OpenProcess
SetCurrentDirectoryA
CreateToolhelp32Snapshot
GetTempPathA
Wow64RevertWow64FsRedirection
GetLastError
GetFileAttributesA
Process32NextW
CreateFileA
Process32FirstW
CloseHandle
GetSystemInfo
CreateThread
GetLocalTime
GetThreadContext
GetProcAddress
VirtualAllocEx
RemoveDirectoryA
ReadProcessMemory
CreateProcessA
CreateDirectoryA
SetThreadContext
KERNEL32.dll
ReleaseDC
GetSystemMetrics
USER32.dll
DeleteObject
CreateCompatibleDC
SelectObject
CreateCompatibleBitmap
BitBlt
GDI32.dll
GetSidIdentifierAuthority
DuplicateTokenEx
RegEnumValueA
RegOpenKeyExA
OpenProcessToken
RegSetValueExA
ImpersonateLoggedOnUser
LookupAccountNameA
CreateProcessWithTokenW
GetUserNameA
GetSidSubAuthority
GetSidSubAuthorityCount
RegQueryValueExA
RegGetValueA
RegQueryInfoKeyW
RegCloseKey
RevertToSelf
ADVAPI32.dll
ShellExecuteA
SHGetFolderPathA
SHFileOperationA
SHELL32.dll
CoInitialize
CoUninitialize
CoCreateInstance
ole32.dll
HttpOpenRequestA
InternetWriteFile
InternetOpenUrlA
InternetOpenW
HttpEndRequestW
HttpAddRequestHeadersA
HttpSendRequestExA
InternetOpenA
InternetCloseHandle
HttpSendRequestA
InternetConnectA
InternetReadFile
WININET.dll
GdipSaveImageToFile
GdipGetImageEncodersSize
GdipDisposeImage
GdipCreateBitmapFromHBITMAP
GdipGetImageEncoders
GdiplusShutdown
GdiplusStartup
gdiplus.dll
freeaddrinfo
getaddrinfo
inet_pton
WS2_32.dll
RaiseException
GetCurrentThreadId
IsProcessorFeaturePresent
QueueUserWorkItem
GetModuleHandleExW
FormatMessageW
WideCharToMultiByte
EnterCriticalSection
LeaveCriticalSection
TryEnterCriticalSection
DeleteCriticalSection
SetLastError
InitializeCriticalSectionAndSpinCount
CreateEventW
SwitchToThread
TlsAlloc
TlsGetValue
TlsSetValue
TlsFree
GetSystemTimeAsFileTime
GetTickCount
GetModuleHandleW
WaitForSingleObjectEx
QueryPerformanceCounter
EncodePointer
DecodePointer
MultiByteToWideChar
CompareStringW
LCMapStringW
GetLocaleInfoW
GetStringTypeW
GetCPInfo
SetEvent
ResetEvent
UnhandledExceptionFilter
SetUnhandledExceptionFilter
GetCurrentProcess
TerminateProcess
IsDebuggerPresent
GetStartupInfoW
GetCurrentProcessId
InitializeSListHead
CreateTimerQueue
SignalObjectAndWait
SetThreadPriority
GetThreadPriority
GetLogicalProcessorInformation
CreateTimerQueueTimer
ChangeTimerQueueTimer
DeleteTimerQueueTimer
GetNumaHighestNodeNumber
GetProcessAffinityMask
SetThreadAffinityMask
RegisterWaitForSingleObject
UnregisterWait
GetCurrentThread
GetThreadTimes
FreeLibrary
FreeLibraryAndExitThread
GetModuleFileNameW
LoadLibraryExW
VirtualProtect
DuplicateHandle
ReleaseSemaphore
InterlockedPopEntrySList
InterlockedPushEntrySList
InterlockedFlushSList
QueryDepthSList
UnregisterWaitEx
LoadLibraryW
RtlUnwind
ExitProcess
CreateFileW
GetDriveTypeW
GetFileInformationByHandle
GetFileType
SystemTimeToTzSpecificLocalTime
FileTimeToSystemTime
GetStdHandle
GetCommandLineA
GetCommandLineW
GetFileSizeEx
SetFilePointerEx
FlushFileBuffers
GetConsoleCP
GetConsoleMode
HeapFree
HeapAlloc
IsValidLocale
GetUserDefaultLCID
EnumSystemLocalesW
DeleteFileW
GetCurrentDirectoryW
GetFullPathNameW
SetStdHandle
ReadConsoleW
HeapReAlloc
GetTimeZoneInformation
FindFirstFileExW
FindNextFileW
IsValidCodePage
GetACP
GetOEMCP
GetEnvironmentStringsW
FreeEnvironmentStringsW
SetEnvironmentVariableW
GetProcessHeap
HeapSize
SetEndOfFile
WriteConsoleW
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
.?AVbad_exception@std@@
.?AV_ExceptionPtr_normal@?A0x03848f66@@
.?AV?$_ExceptionPtr_static@Vbad_alloc@std@@@?A0x03848f66@@
.?AV?$_ExceptionPtr_static@Vbad_exception@std@@@?A0x03848f66@@
.?AVstl_condition_variable_interface@details@Concurrency@@
.?AVstl_condition_variable_vista@details@Concurrency@@
.?AVstl_condition_variable_win7@details@Concurrency@@
.?AVstl_condition_variable_concrt@details@Concurrency@@
.?AVfuture_error@std@@
.?AVlogic_error@std@@
.?AV_System_error_category@std@@
.?AVinvalid_argument@std@@
.?AVlength_error@std@@
.?AVout_of_range@std@@
.?AVbad_function_call@std@@
.?AV_Locimp@locale@std@@
.?AVstl_critical_section_interface@details@Concurrency@@
.?AVstl_critical_section_vista@details@Concurrency@@
.?AVstl_critical_section_win7@details@Concurrency@@
.?AVstl_critical_section_concrt@details@Concurrency@@
.?AVtype_info@@
.?AVWaitBlock@details@Concurrency@@
.?AVSingleWaitBlock@details@Concurrency@@
.?AVMultiWaitBlock@details@Concurrency@@
.?AVWaitAllBlock@details@Concurrency@@
.?AVWaitAnyBlock@details@Concurrency@@
.?AVTimedSingleWaitBlock@details@Concurrency@@
.?AV?$_MallocaArrayHolder@PAVContext@Concurrency@@@details@Concurrency@@
.?AVimproper_lock@Concurrency@@
.?AVscheduler_resource_allocation_error@Concurrency@@
.?AUITopologyExecutionResource@Concurrency@@
.?AUITopologyNode@Concurrency@@
.?AUTopologyObject@GlobalCore@details@Concurrency@@
.?AUTopologyObject@GlobalNode@details@Concurrency@@
.?AVunsupported_os@Concurrency@@
.?AVResourceManager@details@Concurrency@@
.?AUIResourceManager@Concurrency@@
.?AVScheduleGroupBase@details@Concurrency@@
.?AVScheduleGroup@Concurrency@@
.?AVCacheLocalScheduleGroup@details@Concurrency@@
.?AVFairScheduleGroup@details@Concurrency@@
.?AU_Chore@details@Concurrency@@
.?AVScheduler@Concurrency@@
.?AVRealizedChore@details@Concurrency@@
.?AVCacheLocalScheduleGroupSegment@details@Concurrency@@
.?AVScheduleGroupSegmentBase@details@Concurrency@@
.?AVFairScheduleGroupSegment@details@Concurrency@@
.?AVscheduler_worker_creation_error@Concurrency@@
.?AVimproper_scheduler_reference@Concurrency@@
.?AVimproper_scheduler_attach@Concurrency@@
.?AVSchedulerBase@details@Concurrency@@
.?AVcontext_unblock_unbalanced@Concurrency@@
.?AVcontext_self_unblock@Concurrency@@
.?AVmissing_wait@Concurrency@@
.?AVinvalid_scheduler_policy_key@Concurrency@@
.?AVinvalid_scheduler_policy_value@Concurrency@@
.?AVinvalid_scheduler_policy_thread_specification@Concurrency@@
.?AVnested_scheduler_missing_detach@Concurrency@@
.?AVinvalid_oversubscribe_operation@Concurrency@@
.?AVContext@Concurrency@@
.?AVContextBase@details@Concurrency@@
.?AVCancellationTokenRegistration_TaskProc@details@Concurrency@@
.?AV?$_MallocaArrayHolder@PAVevent@Concurrency@@@details@Concurrency@@
.?AVExecutionResource@details@Concurrency@@
.?AUIExecutionResource@Concurrency@@
.?AVSchedulerProxy@details@Concurrency@@
.?AUISchedulerProxy@Concurrency@@
.?AVFreeThreadProxy@details@Concurrency@@
.?AVThreadProxy@details@Concurrency@@
.?AUIThreadProxy@Concurrency@@
.?AUIThreadProxyFactory@details@Concurrency@@
.?AVFreeThreadProxyFactory@details@Concurrency@@
.?AV?$ThreadProxyFactory@VFreeThreadProxy@details@Concurrency@@@details@Concurrency@@
.?AVVirtualProcessor@details@Concurrency@@
.?AVInternalContextBase@details@Concurrency@@
.?AUIExecutionContext@Concurrency@@
.?AVExternalContextBase@details@Concurrency@@
.?AVThreadInternalContext@details@Concurrency@@
.?AVThreadScheduler@details@Concurrency@@
.?AUIScheduler@Concurrency@@
.?AVVirtualProcessorRoot@details@Concurrency@@
.?AUIVirtualProcessorRoot@Concurrency@@
.?AVFreeVirtualProcessorRoot@details@Concurrency@@
.?AVThreadVirtualProcessor@details@Concurrency@@
.?AV__non_rtti_object@std@@
.?AVbad_typeid@std@@
.?AV?$basic_stringstream@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@
.?AVfailure@ios_base@std@@
.?AV?$basic_filebuf@DU?$char_traits@D@std@@@std@@
.?AVruntime_error@std@@
.?AV?$_Func_impl_no_alloc@V<lambda_5e5ab22ea98f4361dbf159481d01f54d>@@X$$V@std@@
.?AV?$codecvt@DDU_Mbstatet@@@std@@
.?AVbad_alloc@std@@
.?AV?$_Ref_count_obj2@U_ExceptionHolder@details@Concurrency@@@std@@
.?AU?$_InitialTaskHandle@XV<lambda_9de88c4009318ef1202283857f94e673>@@U_TypeSelectorNoAsync@details@Concurrency@@@?$task@E@Concurrency@@
.?AV?$_Func_impl_no_alloc@V<lambda_0456396a71e3abd88ede77bdd2823d8e>@@X$$V@std@@
.?AV?$_Func_impl_no_alloc@V<lambda_9de88c4009318ef1202283857f94e673>@@X$$V@std@@
.?AV?$basic_stringbuf@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@
.?AVios_base@std@@
.?AVerror_category@std@@
.?AV?$_Associated_state@H@std@@
.?AV<lambda_7c33b2c4310ad8c6be497d7a2a561bb8>@@
.?AV?$ctype@D@std@@
.?AVsystem_error@std@@
.?AV?$basic_iostream@DU?$char_traits@D@std@@@std@@
.?AV?$_CancellationTokenCallback@V<lambda_3b8ab8d2629adf61a42ee3fe177a046b>@@@details@Concurrency@@
.?AVcodecvt_base@std@@
.?AV_Facet_base@std@@
.?AV?$_Func_impl_no_alloc@V<lambda_eb87dfd73f857f44e1a351ea42ce2b34>@@E$$V@std@@
.?AV_Generic_error_category@std@@
.?AV?$_Func_impl_no_alloc@V?$_Fake_no_copy_callable_adapter@A6GXPAUConnexionDetails@@@ZAAPAU1@@std@@X$$V@std@@
.?AVtask_canceled@Concurrency@@
.?AU_Crt_new_delete@std@@
.?AV?$_Iosb@H@std@@
.?AV?$basic_ofstream@DU?$char_traits@D@std@@@std@@
.?AV_DefaultPPLTaskScheduler@details@Concurrency@@
.?AV?$basic_streambuf@DU?$char_traits@D@std@@@std@@
.?AV<lambda_0456396a71e3abd88ede77bdd2823d8e>@@
.?AV<lambda_5e5ab22ea98f4361dbf159481d01f54d>@@
.?AV?$_Func_impl_no_alloc@V<lambda_7c33b2c4310ad8c6be497d7a2a561bb8>@@X$$V@std@@
.?AV_Iostream_error_category@std@@
.?AVbad_cast@std@@
.?AU?$_Task_impl@E@details@Concurrency@@
.?AUctype_base@std@@
.?AV?$_Func_base@X$$V@std@@
.?AV?$basic_istream@DU?$char_traits@D@std@@@std@@
.?AV?$basic_ios@DU?$char_traits@D@std@@@std@@
.?AV_Future_error_category@std@@
.?AV<lambda_9de88c4009318ef1202283857f94e673>@@
.?AV?$_Task_async_state@X@std@@
.?AVfacet@locale@std@@
.?AU?$_PPLTaskHandle@EU?$_InitialTaskHandle@XV<lambda_9de88c4009318ef1202283857f94e673>@@U_TypeSelectorNoAsync@details@Concurrency@@@?$task@E@Concurrency@@U_TaskProcHandle@details@3@@details@Concurrency@@
.?AV_RefCounter@details@Concurrency@@
.?AV_Ref_count_base@std@@
.?AV?$_Ref_count_obj2@U?$_Task_impl@E@details@Concurrency@@@std@@
.?AV_Interruption_exception@details@Concurrency@@
.?AV?$basic_ostream@DU?$char_traits@D@std@@@std@@
.?AV?$_Func_base@E$$V@std@@
.?AV_System_error@std@@
.?AU_TaskProcHandle@details@Concurrency@@
.?AUscheduler_interface@Concurrency@@
.?AV?$_Packaged_state@$$A6AXXZ@std@@
.?AVinvalid_operation@Concurrency@@
.?AV?$_Fake_no_copy_callable_adapter@A6GXPAUConnexionDetails@@@ZAAPAU1@@std@@
.?AVexception@std@@
.?AV<lambda_eb87dfd73f857f44e1a351ea42ce2b34>@@
.?AV_CancellationTokenRegistration@details@Concurrency@@
.?AVbad_array_new_length@std@@
.?AU_Task_impl_base@details@Concurrency@@
<?xml version='1.0' encoding='UTF-8' standalone='yes'?>
<assembly xmlns='urn:schemas-microsoft-com:asm.v1' manifestVersion='1.0'>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v3">
<security>
<requestedPrivileges>
<requestedExecutionLevel level='asInvoker' uiAccess='false' />
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
0#0(020C0H0R0c0h0r0
1#1(121C1H1R1c1h1r1
2#2(222C2H2R2c2h2r2
3#3(323C3H3R3c3h3r3
4#4(424C4H4R4c4h4r4
5#5(525C5H5R5c5h5r5
6#6(626C6H6R6c6h6r6
7#7(727C7H7R7c7h7r7
8#8(828C8H8R8c8h8r8
9#9(929C9H9R9c9h9r9
:#:(:2:C:H:R:c:h:r:
;#;(;2;C;H;R;c;h;r;
<#<(<2<C<H<R<c<h<r<
=#=(=2=C=H=R=c=h=r=
>#>(>2>C>H>R>c>h>r>
?#?(?2?C?H?R?c?h?r?
0!010A0S0X0b0s0x0
1)171A1O1[1e1q1{1
5/5H5o5
66O6h62777<7Y7
;1<6<;<P<
>,?[?h?
1~2034383<3F3T3
5V6c667E7
162E2,3
5)5O5T5[5b5i5t5x5|5
5<6@6D6H6V6b6
;8<B<G<c<
>D>M>^>g>l>s>
4M5b5h5s5
5E6R6X6c6
677B7O7e7
>N>`>i>o>
> ?G?R?Z?
2'2.2b2h2r2
3!474>4G4W4]4f4
4=5R5b5
5i6v6}6
8R8_8m8
=%=V?g?
3&3;3Q3[3i3n3t3{3
4?4[4e4s4
7F8S8o8
9;9T9Z9
<'<4<B<J<P<Z<d<k<u<
"0U0n0
061E1v1
6K6m6t697
929D9c9
4(4Y4c4
6(6\6f6
9(9\9f9
4X4V6h6
9::!;0;o;V<e<
0C0*191x1_2n2
6L637n7w7
8,8V8h8
9*9{96<H<
=f=u=&?8?
0(020<0O0|0
>/>R>m>
2D3I3w3
3E4i4v4
4G5&686]6T7
2J3S3Y3}3
>+?W?a?}?
2.2O2X2p2
2&3D3Z3
464E4`4h4
7?7M7`7l7s7
868>8[8e8r8|8
>&>A>\>
979O9l9
3:3,7;7E7P7T7X7\7f7x7
;_>i>x>|>
?1?I?f?
778D9a9
= =,=0=4=8=F=X=
9 :/:G:d:
?(?K?f?k?v?|?
1*2L2R2`2f2o2
7"8i8c9
3&787d7i7w7}7
:S:u:{:
90d0v0
0<1V1v3
8#;E;y<
N065E5n5
5s658!9'9D9U9\9
12N204\4
<V=s=@>U>r>
4)484<4@4D4H4L4P4T4X4\4`4d4h4l4p4t4x4|4
919H9R9X9
5$5<5o5
:i;f>x>&?8?Y?_?f?
2*2F2R2l2
2$2C2]2x2
:>:f:v:Y;
0&181Q1
2,3F3X3q4
0F0Q0Z0
2$268D8
;8;Y;f;t;|;
4&686d6+8z8
>&?5?Y?
4!4D4d4q4
9P9[9i9a:q:}:
:,;L;[;q;w;|;
=,>a>h>
?;?N?_?s?
0!0A0I0W0f0s0
22A2P2o2
5:5V5o5
60686H6r6
9,9A9`9{9
:.:N:n:}:
<#<8<E<N<S<f<
=%>K>Q>
252G2R2g2}2
3&393}3
7$7+72777=7C7H7N7T7Y7_7e7j7p7v7{7
8 8%8+81868<8B8G8M8S8X8^8d8i8n8u8z8
99$9*90959;9A9F9L9R9W9]9c9h9n9t9y9
:#:5:=:L:d:
;4;B;N;Z;h;z;
<*<M<g<x<
==4=F=T=f=w=
0#0*010=0
4$4+414;4J4R4^4o4v4
5 5+51585F5O5Z5a5
6,6<6L6U6
8D8S8j8p8v8|8
8I9V9~9
;(;-;:;t;
1d2m2u2
3"3+393B3d3k3~3
4$4:4t4}4
5 5%585
6)777u7
8)9S9v9
=3=Q=~=
4+4'6D6Q6t6
7*7Q7b7
9&:U:p:S;`;
=1>]>c>j>q>v>
030@0J0\0v0
1*1D1S1m1
2$2>2\2t2
3,3B3P3d3p3
334>4N4Z4h4v4
555N5S5f5
< <'<4<:<F<O<o<
==/=:=A=
0-0F0a0
0%1,1;1
787C7I7a7
<)</<=<C<_<f<N=X=^={=
> >&>:>D>N>[>g>
9;9A9q9;
?4?b?n?
3L4}4/5<5O5
6606>6D6i6
8^:k:x:
;(;A;P;r;
==*=8=L=
>4?W?z?
0)0/0@0T0
1 3M3y3
2%2:2c2p2{2
3A3b3{3
5@5O5]5
696H6V6
>#?)???F?
2-2>2S2j2
55@5R5
698E8w8
2M2a2f2
7=9%:X:
<)=?=L=i=p=u=~=
> >,><>J>U>o>
>*?5?D?e?}?
0#0=0r0
121;1H1]1
292V2g2
3Z3g3w3
4#4-4:4D4Q4[4
5$50565L5g5s5
6+6G6e6
7&7,73797J7U7s7
;`;H<b<
3,3^3d3
;=<X<s<
7.8u8t9
:&:J:x:
<={=W>
6:6J6W6{6
<F<d<|<]=
>6>Y>s>
>!?U?^?z?
0"1'141N1^1d1j1G2
8!9H9e9
?B?O?}?
0;0\0h0
1#1:1@1Y1
2!252H2
1&2k2p2t2x2|2
9K9P9T9X9\9
)2E2N2
3 303I3j3x3~3
4!424<4J4e4v4
:#=t=8?
2(2H2V2]2c2
4 4,484N4t4
5!5&5A5K5W5\5a5|5
6#6l6u6
8)8>8H8[8b8n8
99:?:S:
>M?g?l?
5L6:7D7Q7
8@8G8Y8
;);E<d<y<
5E5_5n5|5
6,696G6U6`6
4&6E6m6
Y0i2n3
67&7D8
9%9*94999D9O9\9j9w9
=9=N=Y=a=l=r=}=
>>'>?>M>U>m>
0;0@0F0K0S0Y0a0
6b;h;z;
8)949F9,=3=
?!?U?x?
3F3M3n3
4B4W4g4t4
5"5;5L5V5x5
0?0J0X0
131E1O1q1
1%2L2m2
6=7C7U7h7
:4:^:e:k:r:w:
;+;0;5;E;J;O;_;d;i;y;~;
<,<:<F<R<f<|<
='=7=K=P=U=r=
=$>[>`>e>
?"?@?O?t?
0 0A0Q0r0
4C6b;f>
0&0_0q0w0$1
363@3v3
6N6]6k6
6'7.7n7u7~7
7%828a8m8
<#<@<a<h<
5#606?6
<+<?<a<k<
>#?A?L?
0#0(0-0?0
4K6W899
R3Z4k4H6S6c6
7$767f8l8z8
9;9Q9g9p9{9
;%;=;E;t;
1!191A1b1
;C<N<Z<d<n<r<x<~<
=F=N=Z=g=n=w=
>!>*>:>
0*010>0R0W0]0
>+>v>}>
:-;?;Q;c;u;
2 2(20282
:';H;.<
<G=f=H>
2>3J3k3
585?5h5c6
7&767B778K8
<1D1{1
84<;<B<_<{<
6;6J6V6e6x6
6&7/787A7l7
:v;;<h<
575V5b5
7%7=7C7O7n7t7B8
9(939@9R9
97:L:U:^:
>!>)>1>9>W>_>
1!222C2m2
3=4L4j4
5-5K5_5e5
s0-1l1
;"<H<n<
>1>L>g>
2@2[2~2
7%7M7h7
8)8Q8|8
:';R;u;
<<L<c<
=7=A=K=b=l=
>">,>W>a>k>
?!?+?B?L?w?
070A0K0b0l0
1"1,1W1a1k1
2!2+2B2L2w2
373A3K3b3l3
4"4,4W4a4k4
5!5+5B5L5w5
676A6K6b6l6
7"7,7W7a7k7
8!8+8B8L8w8
979A9K9b9l9
:":,:W:a:k:
;!;+;B;L;w;
<7<A<K<b<l<
="=,=W=a=k=
>!>+>B>L>w>
?7?A?K?b?l?
0"0,0W0a0k0
1!1+1B1L1w1
272A2K2b2l2
3"3,3W3a3k3
4!4+4B4L4w4
575A5K5b5l5
6"6,6W6a6k6
7!7+7B7L7w7
878A8K8b8l8
9"9,9W9a9k9
:!:+:B:L:w:
;7;A;K;b;l;
<"<,<W<a<k<
=!=+=B=L=w=
>7>A>K>b>l>
?"?,?W?a?k?
0!0+0B0L0w0
171A1K1b1l1
2"2,2W2a2k2
3!3+3B3L3w3
474A4K4b4l4
5"5,5W5a5k5
6!6+6B6L6w6
777A7K7b7l7
8"8,8W8a8k8
9!9+9B9L9w9
:7:A:K:b:l:
;";,;W;a;k;
<!<+<B<L<w<
=7=A=K=b=l=
>">,>W>a>k>
?!?+?B?M?|?
#0-070B0L0X0`0
1"1,1W1a1k1
2%2M2W2a2k2u2
4 4$4(4,4044484<4@4D4H4L4P4T4X4\4`4d4h4l4p4t4x4|4
5 5$5(5,5054585<5@5D5H5L5P5T5X5\5`5d5h5l5p5t5x5|5
6 6$6(6,6P6T6X6\6`6d6x6|6
7 7$7(7,7074787<7@7D7H7L7P7T7X7\7`7d7h7l7p7t7x7|7
8(8,8084888<8@8
9 9$9(9,9094989<9
<$<,<4<<<D<L<T<\<d<l<t<|<
=$=,=4=<=D=L=T=\=d=l=t=|=
>$>,>4><>D>L>T>\>d>l>t>|>
4 4$4(4,4044484<4@4
8 8$8(8,8084888<8@8D8
9$9,949<9D9L9T9\9d9l9t9|9
:$:,:4:<:D:L:T:\:d:l:t:|:
;$;,;4;<;D;L;T;\;d;l;t;|;
<$<,<4<<<D<L<T<\<d<l<t<|<
=$=,=4=<=D=L=T=\=d=l=t=|=
>$>,>4><>D>L>T>\>d>l>t>|>
?$?,?4?<?D?L?T?\?d?l?t?|?
0 0(00080@0H0P0X0`0h0p0x0
1 1(10181@1H1P1X1`1h1p1x1
2 2(20282@2H2P2X2`2h2p2x2
3 3(30383@3H3P3X3`3h3p3x3
4 4(40484@4H4P4X4`4h4p4x4
5 5(50585@5H5P5X5`5h5p5x5
6 6(60686@6H6P6X6`6h6p6x6
7 7(70787
: :$:(:,:0:4:8:<:@:D:H:L:P:T:X:\:`:d:h:l:p:t:x:|:
:L;P;T;X;\;`;d;h;l;p;t;x;|;
< <$<(<,<0<4<8<<<@<D<H<L<P<T<X<\<`<d<h<l<p<t<x<|<
= =$=(=,=0=4=8=`=d=h=l=p=t=x=|=
> >$>(>,>0>4>8><>@>D>H>L>P>T>X>\>`>d>h>l>p>
0d0h0l0p0t0x0|0
1h2l2p2t2x2|2
4 4$4(4,4044484<4@4D4H4L4P4T4X4\4`4d4h4l4p4t4x4|4
5 5$5(5,5054585<5@5D5H5L5P5T5X5\5`5d5h5l5p5t5x5|5
6 6$6(6,6064686<6@6D6H6L6P6T6X6\6`6d6h6l6p6t6x6|6
7 7$7(7,7074787x7
8 8(80888@8H8P8X8`8h8p8x8
9 9(90989@9H9P9X9`9h9p9x9
: :(:0:8:@:H:P:X:`:h:p:x:
6 6$6(6,64686<6@6D6H6L6P6\6d6l6p6t6x6|6
7 7$7(7,7074787<7@7D7
8 8$8(8,8084888<8@8D8H8L8P8T8X8\8`8d8h8l8p8t8x8|8
9 9$9(9,9094989<9@9D9H9L9P9T9X9\9`9d9h9l9p9t9x9
3$3,343<3D3L3T3\3d3l3t3|3
7(747@7L7X7d7p7|7
8$808<8H8T8`8l8x8
9 9,989D9P9\9h9t9
: :,:8:D:P:\:h:t:
6$6,646<6D6L6T6\6d6l6t6|6
7$7,747<7D7L7T7\7d7l7t7|7
8$8,848<8D8L8T8\8d8l8t8|8
9$9,949<9D9L9T9\9d9l9t9|9
:$:,:4:<:D:L:T:\:d:l:t:|:
;$;,;4;<;D;L;T;\;d;l;t;|;
<$<,<4<<<D<L<T<\<d<l<t<|<
= =(=0=8=@=H=P=X=`=h=p=x=
> >(>0>8>@>H>P>X>`>h>p>x>
? ?(?0?8?@?H?P?X?`?h?p?x?
0 0(00080@0H0P0X0`0h0p0x0
1 1(10181@1H1P1X1`1h1p1x1
2 2(20282@2H2P2X2`2h2p2x2
3 3(30383@3H3P3X3`3h3p3x3
D;H;L;P;T;X;\;`;d;h;l;p;t;x;|;
< <$<(<,<0<H<L<P<T<X<\<`<d<h<l<
=(=,=0=4=8=<=@=D=H=L=P=T=X=\=`=d=h=l=p=t=x=|=
> >$>(>,>0>4>8><>@>D>H>L>P>T>X>\>`>d>h>l>p>
?\?`?d?h?
0,00040<0T0d0h0x0|0
1 10141D1H1L1T1l1|1
2(2,20242<2T2d2h2x2|2
3 3(3@3P3T3d3h3l3p3x3
404@4D4L4d4t4x4
5 5$5(505H5X5\5l5p5x5
6$64686H6L6P6X6p6
7 7$74787<7@7H7`7p7t7
8 8(8@8P8T8\8t8
9 9(9@9P9T9d9h9l9t9
: :$:,:D:H:`:p:t:
;4;D;H;\;`;p;t;|;
<,<0<4<<<T<X<p<
= =0=4=D=H=L=T=l=|=
>,>0>4><>T>d>h>x>|>
? ?8?H?L?\?`?d?l?
0,000@0D0H0P0h0x0|0
1 1$1(101H1X1\1l1p1t1x1
2,202H2X2\2p2t2
30343L3\3`3d3l3
44484P4`4d4h4|4
5$54585@5X5\5t5
6(686<6L6P6T6X6\6`6h6
7 787<7T7d7h7x7|7
8(8,8084888@8X8h8l8|8
9(9,90949<9T9d9t9
:$:(:,:0:4:8:@:X:h:l:|:
;,;0;@;P;T;d;h;x;|;
< <$<<<@<D<L<d<h<l<
=,=0=H=L=P=X=p=t=
>(>8><>T>X>p>
? ?4?8?<?T?X?\?p?t?x?
0 0$0(0004080<0D0X0\0l0|0
1 1$1,101D1H1L1P1T1h1l1p1t1x1|1
242D2T2X2p2
3 3$3,3D3H3`3d3h3p3
4 4$4,4D4H4L4P4T4X4\4`4d4h4|4
5 5$585<5@5X5h5x5|5
6(6,606H6L6d6t6x6|6
7 7$787H7L7d7t7x7|7
8(8,8D8H8`8d8x8|8
909@9D9H9`9p9t9
202<2\2d2p2
3,343<3D3t3
4(444T4\4d4l4x4
5 5(505<5D5d5t5
6$6,646<6L6T6d6t6
707<7\7d7l7x7
8,888X8`8h8t8
9,949<9D9L9T9\9d9l9t9|9
: :,:L:T:`:
;<;D;L;T;\;d;l;x;
<0<8<@<P<t<|<
=$=0=P=\=|=
> >(>4>T>\>d>p>
?4?<?D?L?T?\?d?l?t?|?
0$0,040<0D0L0T0`0
1$101T1\1d1l1t1|1
2$2,242@2`2h2p2|2
3$3,343<3D3L3T3`3
4 4,4L4T4`4
5$5,545<5D5L5T5\5d5l5t5
6$6,686X6`6l6
7$7,747<7D7L7T7\7d7p7
8(8H8T8t8|8
9$9,949<9D9L9T9\9d9l9x9
:$:,:4:@:d:l:t:|:
; ;D;L;T;\;d;l;t;|;
<$<,<4<<<D<L<T<\<d<l<t<|<
=$=,=4=<=H=l=t=|=
>$>,>4><>D>L>T>\>d>l>t>|>
?(?L?T?\?d?l?t?|?
0$0,040<0D0L0X0|0
1$1,141<1D1L1T1\1d1l1t1|1
2$2,242<2D2L2T2\2d2l2t2|2
3$3,343<3D3L3T3\3d3l3t3|3
4$4,444<4D4L4T4\4d4l4t4|4
5$5,545<5D5L5T5\5d5l5t5|5
6 6D6L6T6\6d6l6t6|6
7$7,747<7D7L7T7\7d7l7t7|7
8$8,848<8D8L8T8\8d8l8t8|8
9$9,949<9D9L9T9\9d9l9t9|9
:$:,:4:<:D:L:T:\:h:
;$;,;4;<;D;L;T;\;d;l;t;|;
<$<,<4<<<D<L<T<\<d<l<t<|<
=$=,=4=<=D=L=T=\=d=l=t=|=
>$>,>4><>D>L>T>\>d>l>t>|>
?$?,?4?<?H?l?t?|?
0,040<0D0L0T0\0d0l0t0|0
1$1,141<1D1L1T1\1d1l1t1|1
2$2,242<2D2L2T2\2d2l2t2|2
343@3`3l3
4,484X4d4
5 5@5L5l5x5
6$6,6`6p6|6
7 787@7X7`7t7
8$8L8T8h8
9$949@9`9l9
:$:0:8:P:X:p:
;$;,;4;<;H;h;t;
<<<H<h<t<
= =8=@=L=l=x=
>$>D>P>p>x>
?$?8?@?T?\?h?
0 040<0D0L0P0X0l0t0
1 1<1@1H1T1t1|1
2<2H2h2t2
383@3H3T3t3
4$4D4P4p4x4
585@5H5L5T5h5p5|5
6 6D6P6X6p6|6
787@7L7l7t7
8(80888@8D8L8`8h8x8
8 9,949<9H9h9t9
: :(:0:4:<:P:X:`:h:l:t:
; ;(;0;4;<;P;X;`;h;l;t;
<$<0<P<X<d<
=$=D=P=p=|=
>0>8>D>d>p>
?,?4?<?D?H?P?d?l?t?|?
080D0h0
1<1H1h1t1
282@2H2T2
3$3T3X3t3x3
4 4$444X4d4l4
585X5x5
686X6x6
787X7x7
888X8x8
989X9x9
: :@:`:
; ;<;@;H;P;X;`;h;l;p;x;
< <$<(<0<D<L<T<\<p<x<|<
;0<L<p<
> ?D?`?
Bkernel32.dll
zh-CHS
az-AZ-Latn
uz-UZ-Latn
kok-IN
syr-SY
div-MV
quz-BO
sr-SP-Latn
az-AZ-Cyrl
uz-UZ-Cyrl
quz-EC
sr-SP-Cyrl
quz-PE
smj-NO
bs-BA-Latn
smj-SE
sr-BA-Latn
sma-NO
sr-BA-Cyrl
sma-SE
sms-FI
smn-FI
zh-CHT
az-az-cyrl
az-az-latn
bs-ba-latn
div-mv
kok-in
quz-bo
quz-ec
quz-pe
sma-no
sma-se
smj-no
smj-se
smn-fi
sms-fi
sr-ba-cyrl
sr-ba-latn
sr-sp-cyrl
sr-sp-latn
syr-sy
uz-uz-cyrl
uz-uz-latn
zh-chs
zh-cht
api-ms-win-core-synch-l1-2-0.dll
combase.dll
advapi32.dll
Fapi-ms-win-core-fibers-l1-1-1
api-ms-win-core-synch-l1-2-0
kernel32
api-ms-
mscoree.dll
(null)
((((( H
((((( H
(
ELC_ALL
LC_COLLATE
LC_CTYPE
LC_MONETARY
LC_NUMERIC
LC_TIME
Sunday
Monday
Tuesday
Wednesday
Thursday
Friday
Saturday
January
February
August
September
October
November
December
MM/dd/yy
dddd, MMMM dd, yyyy
HH:mm:ss
Fapi-ms-win-core-datetime-l1-1-1
api-ms-win-core-file-l1-2-2
api-ms-win-core-localization-l1-2-1
api-ms-win-core-localization-obsolete-l1-2-0
api-ms-win-core-processthreads-l1-1-2
api-ms-win-core-string-l1-1-0
api-ms-win-core-sysinfo-l1-2-1
api-ms-win-core-winrt-l1-1-0
api-ms-win-core-xstate-l2-1-0
api-ms-win-rtcore-ntuser-window-l1-1-0
api-ms-win-security-systemfunctions-l1-1-0
ext-ms-win-ntuser-dialogbox-l1-1-0
ext-ms-win-ntuser-windowstation-l1-1-0
advapi32
api-ms-win-appmodel-runtime-l1-1-2
user32
ext-ms-
american
american english
american-english
australian
belgian
canadian
chinese
chinese-hongkong
chinese-simplified
chinese-singapore
chinese-traditional
dutch-belgian
english-american
english-aus
english-belize
english-can
english-caribbean
english-ire
english-jamaica
english-nz
english-south africa
english-trinidad y tobago
english-uk
english-us
english-usa
french-belgian
french-canadian
french-luxembourg
french-swiss
german-austrian
german-lichtenstein
german-luxembourg
german-swiss
irish-english
italian-swiss
norwegian
norwegian-bokmal
norwegian-nynorsk
portuguese-brazilian
spanish-argentina
spanish-bolivia
spanish-chile
spanish-colombia
spanish-costa rica
spanish-dominican republic
spanish-ecuador
spanish-el salvador
spanish-guatemala
spanish-honduras
spanish-mexican
spanish-modern
spanish-nicaragua
spanish-panama
spanish-paraguay
spanish-peru
spanish-puerto rico
spanish-uruguay
spanish-venezuela
swedish-finland
america
britain
england
great britain
holland
hong-kong
new-zealand
pr china
pr-china
puerto-rico
slovak
south africa
south korea
south-africa
south-korea
trinidad & tobago
united-kingdom
united-states
CONOUT$
image/jpeg
Antivirus Signature
Bkav W32.AIDetectMalware
Lionic Trojan.Win32.Amadey.a!c
Elastic malicious (high confidence)
ClamAV Win.Malware.Generic-10033391-0
CMC Clean
CAT-QuickHeal Trojandownloader.Deyma
Skyhigh BehavesLike.Win32.Generic.hh
ALYac Gen:Variant.Zusy.535541
Cylance Unsafe
Zillya Clean
Sangfor Downloader.Win32.Amadey.Vuku
CrowdStrike win/malicious_confidence_70% (D)
Alibaba TrojanDownloader:Win32/Amadey.dcc40490
K7GW Trojan-Downloader ( 005790d31 )
K7AntiVirus Trojan-Downloader ( 005790d31 )
huorong Clean
Baidu Win32.Trojan.Delf.in
VirIT Clean
Paloalto generic.ml
Symantec ML.Attribute.HighConfidence
tehtris Clean
ESET-NOD32 a variant of Win32/TrojanDownloader.Amadey.A
APEX Malicious
Avast Win32:MalwareX-gen [Trj]
Cynet Malicious (score: 100)
Kaspersky UDS:DangerousObject.Multi.Generic
BitDefender Gen:Variant.Zusy.535541
NANO-Antivirus Trojan.Win32.Redcap.ksraod
ViRobot Clean
MicroWorld-eScan Gen:Variant.Zusy.535541
Tencent Malware.Win32.Gencirc.141d3e5a
Sophos Mal/Generic-S
F-Secure Trojan.TR/Redcap.wksod
DrWeb Trojan.MulDrop28.29236
VIPRE Gen:Variant.Zusy.535541
McAfeeD Real Protect-LS!689FF816FC3D
Trapmine malicious.high.ml.score
CTX exe.trojan.amadey
Emsisoft Gen:Variant.Zusy.535541 (B)
Ikarus Trojan-Downloader.Win32.Amadey
FireEye Generic.mg.689ff816fc3db388
Jiangmin Clean
Webroot W32.Malware.Gen
Varist Clean
Avira TR/Redcap.wksod
Fortinet W32/Amadey.A!tr.dldr
Antiy-AVL Trojan[Downloader]/Win32.Deyma
Kingsoft malware.kb.a.948
Gridinsoft Trojan.Win32.Downloader.sa
Xcitium Clean
Arcabit Trojan.Zusy.D82BF5
SUPERAntiSpyware Clean
ZoneAlarm HEUR:Trojan-Downloader.Win32.Deyma.gen
Microsoft Trojan:Win32/Amadey.BKC!MTB
Google Detected
AhnLab-V3 Trojan/Win.Generic.R671687
Acronis Clean
VBA32 BScope.TrojanDownloader.Deyma
TACHYON Clean
Malwarebytes Malware.AI.1487355604
Panda Trj/GdSda.A
Zoner Clean
TrendMicro-HouseCall Clean
Rising Downloader.Amadey!8.125AC (CLOUD)
Yandex Trojan.DL.Amadey!uNEWiAa7AVM
SentinelOne Static AI - Malicious PE
MaxSecure Trojan.Malware.1728101.susgen
GData Gen:Variant.Zusy.535541
AVG Win32:MalwareX-gen [Trj]
DeepInstinct MALICIOUS
alibabacloud Trojan[downloader]:Win/Amadey.A
No IRMA results available.