Static | ZeroBOX

PE Compile Time

2024-10-08 19:56:51

PE Imphash

12b2bc20d7737a83639913d36501fd39

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x00059000 0x00024800 7.99865333895
.sedata 0x0005a000 0x0015a000 0x00159600 7.56754632236
.idata 0x001b4000 0x00001000 0x00000400 2.86063498811
.rsrc 0x001b5000 0x00012000 0x00011c00 6.31404310907
.sedata 0x001c7000 0x00001000 0x00001000 7.98422499187

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x001c5fd8 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x001c5fd8 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x001c5fd8 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x001c5fd8 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x001c5fd8 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x001c5fd8 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x001c5fd8 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x001c5fd8 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x001c5fd8 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x001c5fd8 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x001c5fd8 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x001c5fd8 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x001c5fd8 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_GROUP_ICON 0x001c6440 0x000000bc LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_MANIFEST 0x001c64fc 0x0000050d LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, ASCII text

Imports

Library USER32.dll:
0x1401b41b6 CreateWindowExW
Library COMCTL32.dll:
0x1401b41ce None
Library KERNEL32.dll:
0x1401b41e6 GetACP
Library ADVAPI32.dll:
0x1401b41fe OpenProcessToken
Library GDI32.dll:
0x1401b4216 SelectObject
Library IPHLPAPI.DLL:
0x1401b422e GetInterfaceInfo
Library msvcrt.dll:
0x1401b4246 _wcsnicmp
Library PSAPI.DLL:
0x1401b425e GetMappedFileNameW
Library SHELL32.dll:
0x1401b4276 SHGetFolderPathW

!This program cannot be run in DOS mode.
RichZpc
.sedata
.idata
.sedata
Htxy/E\
!%<c1%
f.b&l!|
r%/,OZ#
t-L^|I
O?-xd9
:("h^&]vyK
ZwjwXW&
Z0Ld+Z
)HshLb
:.h|t*
e3<!A<o
$Wp6m5
i\M'3D
e}.kTpR
'/e6N}I
3VZ"p|UX?
G3A50,
JjH;y-
KRa'h`
TpQeKp2
bA[<%'
%s6:K2
bYw[G\x
-.qwp8yO
PB9 9s
gU n8*_
\B$ph}
\#:DeZ
q :}"!
Laz5^)"
.t&pX&.
 d{]Y
Cj:mED
KbR-B+VG
E*K)Q*
sA8NT^R
jGwxXBPC
?6`1yR
3jP*rO
XQJ>*
$q8s98
JkiZ4
E3m=zV0
SF6'cU
//bZJu3
4JJ Qz
isjvE%
xTxUrR
9+X9JF
s7:d}^
x^c{7Zl
w1&e~@
?,FT^%
0%[ey2p
i*3KQg2t
>b3TpQ
M1aNIh
1T/0^Gz
l2<0LN]
}<{f#X^U
3Y\%'R
Y,DR,`#
]KO[HPo
Zvi)2;
Y+;aM@
Q4_Z#^
rJX%%X
rkB8Zv
^-Kgq
L<`.i|
+)@W.-`
bU/m.~|4y2sJ|
YRTHX5
=%rXM)
u&r[AP
)+EC)H.
<rZ@'L
TdI\K,W
Z4 !%N
"IJMWR
RXa_~D
-Cnhkvw
%=;l5k
ONU.p3h"
)~cRu,
H?<>He
Puf@!(
E[Ebx`
;?>#G<M68
m5[X|2
l7\f+Q?N[*
#T!P[0
/_fE/K
Or\=,O1
s_ojy
6<F$p"
T%_Ofr
iqVol6
8=z{| Z
GwRCLdn
oU\|c9
:}R[[z
yFGcN
;=]Lh@
:&p9Mi
K>oUM/t
9=/Zwx
GqNoi{@n
JrXF|m
9)+}^aR=Q
=NRm1^x
A1|xCNJ
]Y@{`H; =
95zxQ5
]yQY;+
bUZa]|G\
m}- ks
uKa;sm
a0/QDH
+;SO2b
!h^s.CM+
%QT%V^
{N?;L?* ;C
FLb5/r
8778#i
"Cw8S1q
~`b1jg
%i$tfv
6lzRq4
iA(__:
9Ha67E
qy6d}A
_=_cFC
>vwQ[
'p>#t6
g^C%S4:
z;b}~
){h$wJ
M(P>^K
~tgd/Y
"$FElMz
,yI,n_)
@3*i0u
aau`0f
NLTG>h
q/Q,Zu
o3/ZH
wr--JE
e?o0kK
}lRH[M
GDq_{8
/RFZ.v
9.:Xef
@&8o<d
]9LnmxW
RF$e^*
ry1`{#R
R~;"RS
nVdW7$
\sSs+ >
Wr3KU9
4CqL(Z
os<x7v
HfLi|i*x
.X('[d>
p%cw.y?
M?eigb
,cww|F
;|VMP[
5)}sR8
eoq`Y$8
+Yt&yHG
4V]QN6
,lp7{q
.GB$:X
PU2Z<<
<X]J$l
UeKDD+
PTMT1(
Mh?";+
T+rZx?r
'g4#g^
|i48.
r\'x%2
xl)Qz
b?Yohw
<p_]XE#1Ti
yarCm
0\}zh^
55@n}\
!@b7mW
nz@OEI
?SIan =?
P'z<$D
x.}ecm$
7)7-Eb
S 1)(J
w?S%:L
2oW_}^/
GP/@p'E&
0y4hfW7{$c<
&\"2W
/GM:#@
$3j5VT
~>{"AOC
\jt'REbc
HewLw}F
*@-B3_
+R!C+v
}.,Eoc
nM".K
@p~9FZ
d9(q>.o
$\8#~xu
vsZ|eD
6"r9zQ
-->7yng
9+v.3T
:.[|:(Cs
v2j6T<
<wD8UE
egI0G]
Nl/t_W
5;]z_*
Z]0Q8~
2>hK`V
Z?+AO$
x[LXP
-{F-5f
GIAxA,
w_$d~{
j8(@5W
u(h>v
_q^Q2I
ioCsYM
z)lu/
IIyl=o
z^{jI6
{r3<GE
1}.7
ZCG)cw(
lMXX#z
FJ5c5k
9.WC}IZu
;CO_7o=
* !\5b
Z!xE>z
bCD$ti
M?iLa]
1m{2mC2NC
lBp|o3
1[/pyj
X.BL9j]
5L-ENQ>vx
:LOs7f
f}#<EsO
Du-\TkT+TH
*EZ"m3x2
5{o26N)h
&JP&MU
yB=l*2}
hTjx96
zo4rZ
Kpq|!"L9
MDUXY%P
AT(GZRSB
103*Ef
wRKb#CJ
qYk{a^
QN8,C.
HcL <H
VWATAUAVH
A^A]A\_^
WATAUAVAWH
A_A^A]A\_
VWATAUAVH
A^A]A\_^
^o!N)eF
WATAUAVAWH
A_A^A]A\_
|5(W-nQ
kL3OXTuV
nyXATfA
Zrm|OfA
(EA*Yd
V[ ?uz
mo6h=,
srt[]dv
mtro^1
UVWATAUAVAWH
D$86Qk
A_A^A]A\_^]
D$gifA
~/zh<-
g:{vgr
{zv'=b
103*%h
A]A\_^][
*rct&S.j
dV#n`-
XW.0=L
UtuTsr
VWATAUAVH
A^A]A\_^
UgL[~63B
103*E-
UkPFK,
GgxhM
e,*!3`
103^73
A^A]A\_^
GetModuleHandleA
GetProcessHeap
ntdll.dll
RtlAllocateHeap
LoadLibraryExA
CreateFileW
GetFileSize
ReadFile
CloseHandle
VirtualProtect
GetTickCount
GetProcAddress
RtlFreeHeap
InitializeCriticalSection
EnterCriticalSection
LeaveCriticalSection
DbgBreakPoint
DbgUserBreakPoint
DbgUiRemoteBreakin
kernel32.dll
NtQueryInformationThread
NtSetInformationThread
user32.dll
advapi32.dll
hid.dll
iphlpapi.dll
VirtualAlloc
VirtualFree
SetThreadAffinityMask
GetCurrentThread
ExitProcess
GetSystemDefaultLangID
GetSystemTime
SystemTimeToFileTime
WriteFile
GlobalAlloc
GlobalLock
GlobalUnlock
GetCurrentThreadId
GetExitCodeThread
OpenThread
TerminateThread
SuspendThread
MultiByteToWideChar
WideCharToMultiByte
GetStartupInfoW
TlsAlloc
TlsGetValue
TlsSetValue
TlsFree
CheckRemoteDebuggerPresent
CreateThread
ResumeThread
GetThreadContext
SetThreadContext
mscoree.dll
mscorwks.dll
mscorsvr.dll
KernelBase.dll
mscoreei.dll
clr.dll
diasymreader.dll
SECheckProtection
SEGetAppStatus
SESetAppStatus
SEGetLicenseUserInfoW
SEGetLicenseTrialInfo
SEGetNumExecUsed
SEGetNumExecLeft
SESetNumExecUsed
SEGetExecTimeUsed
SEGetExecTimeLeft
SESetExecTime
SEGetTotalExecTimeUsed
SEGetTotalExecTimeLeft
SESetTotalExecTime
SEGetNumDaysUsed
SEGetNumDaysLeft
SECheckHardwareID
SECheckExpDate
SECheckExecTime
SECheckTotalExecTime
SECheckCountryID
SEGetHardwareIDW
SECheckLicenseFileW
SEGetLicenseHash
SENotifyLicenseBanned
SEResetTrial
SEGetProtectionDate
SEAddMemoryGuard
SEDelMemoryGuard
CreateFileMappingW
MapViewOfFile
MapViewOfFileEx
UnmapViewOfFile
LoadLibraryExW
=j&&LZ66lA??~
}{))R>
f""D~**T
V22dN::t
o%%Jr..\$
&&Lj66lZ??~A
99rKJJ
==zGdd
""Df**T~
;22dV::tN
$$Hl\\
C77nYmm
%%Jo..\r
>!KK
55j_WW
&Lj&6lZ6?~A?
~=zG=d
"Df"*T~*
2dV2:tN:
x%Jo%.\r.
t>!K
a5j_5W
ggV}++
Lj&&lZ66~A??
bS11*?
Xt,,4.
RRvM;;
MMfU33
PPxD<<%
Bc!! 0
~~zG==
Df""T~**;
dV22tN::
xxJo%%\r..8$
tt>!
pp|B>>q
aaj_55
UUPx((
cccc||||wwww{{{{
kkkkoooo
gggg++++
YYYYGGGG
&&&&6666????
nnnnZZZZ
RRRR;;;;
[[[[jjjj
9999JJJJLLLLXXXX
CCCCMMMM3333
PPPP<<<<
~~~~====dddd]]]]
ssss````
""""****
2222::::
$$$$\\\\
7777mmmm
llllVVVV
eeeezzzz
xxxx%%%%....
ttttKKKK
pppp>>>>
ffffHHHH
aaaa5555WWWW
UUUU((((
BBBBhhhhAAAA
='9-6d
_jbF~T
11#?*0
,4$8_@
t\lHBW
QPeA~S
>4$8,@
p\lHtW
+HpXhE
T[$:.6
00006666
CCCCDDDD
TTTT{{{{
####====
ffff((((
vvvv[[[[
IIIImmmm
%%%%rrrr
]]]]eeee
llllppppHHHHPPPP
FFFFWWWW
kkkk::::
AAAAOOOOgggg
tttt""""
nnnnGGGG
VVVV>>>>KKKK
yyyy
YYYY''''
____````QQQQ
;;;;MMMM
ccccUUUU!!!!
GetInterfaceInfo
IPHLPAPI.DLL
??3@YAXPEAX@Z
strncpy
wcsrchr
??2@YAPEAX_K@Z
strncat
_wcsicmp
_wcsnicmp
msvcrt.dll
__C_specific_handler
_unlock
__dllonexit
_onexit
malloc
_initterm
_amsg_exit
GetMappedFileNameW
PSAPI.DLL
SEProtectStartUltra
SEProtectEnd
SEProtectStartMutation
SEUnProtectStart
SEUnProtectEnd
SESDKDummy64.dll
DeviceIoControl
DeleteCriticalSection
GetModuleFileNameW
CreateFileMappingW
MapViewOfFile
UnmapViewOfFile
GetModuleHandleExA
LoadLibraryExW
MapViewOfFileEx
GetLogicalDriveStringsW
QueryDosDeviceW
KERNEL32.dll
wsprintfW
OpenClipboard
EmptyClipboard
SetClipboardData
CloseClipboard
MessageBoxW
FindWindowA
GetDesktopWindow
GetClassNameA
GetWindow
USER32.dll
RegOpenKeyExA
RegQueryValueExA
RegCloseKey
RegCreateKeyExA
RegSetValueExA
RegDeleteKeyA
ADVAPI32.dll
SHGetFolderPathW
SHELL32.dll
memset
memcpy
t$(AWH
<$WAQH
4$APfD
l$(AUL
l$(AUL
T$(ASD
4$w>fD
t$HAUfD
bqpsjfD
strncpy
_onexit
wcsrchr
malloc
IPHLPAPI.DLL
GetInterfaceInfo
A^A]A\A[AZAY
AX_^][Z
msvcrt.dll
??3@YAXPEAX@Z
A_A^A]A\A[
&QAZAYAX_^]
msvcrt.dll
A_A^A]A\A[
AZAYAX_^]
msvcrt.dll
iA_A^A]A\A[
AZAYAX_^]
msvcrt.dll
AX_^][Z
A^A]A\A[AZAY
L$8TWL
msvcrt.dll
AZAYAX_^]
A_A^A]A\A[
strncat
KERNEL32.dll
A_A^A]A\A[
AZAYAX_^]
|$ ATf
msvcrt.dll
A_A^A]A\A[
{*E[ZYX
AZAYAX_^]
_wcsicmp
??2@YAPEAX_K@Z
A\A[AZAYAX_
A_A^A]
^][ZYX
103*EH
msvcrt.dll
A\A[AZAYAX_
A_A^A]
8^][ZYX
msvcrt.dll
A^A]A\A[AZAY
msvcrt.dll
OjAX_^][Z
msvcrt.dll
A_A^A]A\A[
AZAYAX_^]
msvcrt.dll
_wcsnicmp
-103*EH
_unlock
_^][ZY
A]A\A[AZAYAX
msvcrt.dll
__C_specific_handler
A_A^A]A\A[
AZAYAX_^]
_initterm
msvcrt.dll
AZAYAX_^]
2-A_A^A]A\A[
msvcrt.dll
A_A^A]A\A[
AZAYAX_^]
__dllonexit
msvcrt.dll
l$pAWD
AX_^][Z
A^A]A\A[AZAY
msvcrt.dll
AZAYAX_^]
A_A^A]A\A[
d$(ASH
msvcrt.dll
cA^A]A\A[AZAY
_amsg_exit
AX_^][Z
PSAPI.DLL
GetMappedFileNameW
A^A]A\A[AZAY
AX_^][Z
D$XARH
KERNEL32.dll
GetLogicalDriveStringsW
A^A]A\A[AZAY
AX_^][Z
KERNEL32.dll
QueryDosDeviceW
A^A]A\A[AZAY
AX_^][Z
d$pAWH
KERNEL32.dll
GetModuleFileNameW
A^A]A\A[AZAY
/6AX_^][Z
103*EL
UnmapViewOfFile
KERNEL32.dll
wAZAYAX_^]
A_A^A]A\A[
USER32.dll
A_A^A]A\A[
AZAYAX_^]
GetClassNameA
USER32.dll
AZAYAX_^]
A_A^A]A\A[
GetWindow
\$8APfD
USER32.dll
/AX_^][Z
A^A]A\A[AZAY
OpenClipboard
USER32.dll
A_A^A]A\A[
AZAYAX_^]
EmptyClipboard
USER32.dll
SetClipboardData
OA_A^A]A\A[
AZAYAX_^]
USER32.dll
A^A]A\A[AZAY
AX_^][Z
CloseClipboard
$ AZfD
MapViewOfFileEx
A_A^A]
*E^][ZYX
-<A\A[AZAYAX_
KERNEL32.dll
l$PARD
KERNEL32.dll
pA_A^A]A\A[
MapViewOfFile
AZAYAX_^]
KERNEL32.dll
wsprintfW
CreateFileMappingW
FA\A[AZAYAX_
^][ZYX
A_A^A]
USER32.dll
A_A^A]A\A[
w^[ZYX
AZAYAX_^]
USER32.dll
MessageBoxW
A_A^A]
GA\A[AZAYAX_
o^][ZYX
KERNEL32.dll
DeleteCriticalSection
A_A^A]A\A[
AZAYAX_^]
t$(AQf
ADVAPI32.dll
A_A^A]A\A[
+AZAYAX_^]
RegOpenKeyExA
ADVAPI32.dll
A^A]A\A[AZAY
AX_^][Z
RegQueryValueExA
d$hATH
ADVAPI32.dll
RegCloseKey
A_A^A]
^][ZYX
A\A[AZAYAX_
\$@ASD
ADVAPI32.dll
RegDeleteKeyA
AZAYAX_^]
A_A^A]A\A[
ADVAPI32.dll
RegCreateKeyExA
A_A^A]A\A[
AZAYAX_^]
D$HRAR
ADVAPI32.dll
RegSetValueExA
A_A^A]A\A[
AZAYAX_^]
KERNEL32.dll
GetModuleHandleExA
AX_^][Z
,uA^A]A\A[AZAY
KERNEL32.dll
LoadLibraryExW
A\A[AZAYAX_
A_A^A]
^][ZYX
T$0QfD
t$xAVL
KERNEL32.dll
DeviceIoControl
AZAYAX_^]
A_A^A]A\A[
$$ATfA
SHELL32.dll
memset
SHGetFolderPathW
memcpy
(AZAYAX_^]
A_A^A]A\A[
USER32.dll
GetDesktopWindow
A_A^A]A\A[
bAZAYAX_^]
USER32.dll
FindWindowA
A^A]A\A[AZAY
AX_^][Z
msvcrt.dll
AX_^][Z
2mA^A]A\A[AZAY
A_A^A]A\A[
AZAYAX_^]
msvcrt.dll
t$(API
103*Ef
J/6!`D
<$RARA
P@2?fE
4$AUfA
]"C_A]H
103*Ef
X/6!`H
S103*E
%?'E,H
103*EH
//6!`L
Drm|OA
@()kfA
D <ATH
103*|L
%o~z)I
L/6!`fE
\R+k,l
tc"49H
103*EE
103*EI
+G,/fA
+G,/fA
103*EfD
4qpsjH
v5aU$(
rm|OfD
t$ APA
3psjfA
103*EI
q8p fD
103*EH
\%fAPL
qpsjfD
/6!`fA
La8_K4
A\A[AZAYAX_
A_A^A]
!`^][ZYX
(103*EfA
/6!PfA
103*fA
)H4EXt
A_A^A]
A\A[AZAYAX_
,$ATfD
A]A\A[AZAYAX
_^][ZY
I03*EfA
a8g?0o
z=ZJfD
I103*fA
A[AZAYAX_^
A_A^A]A\
AYAX_^][
A_A^A]A\A[AZ
(F["D!
tbG&-Oz"
A]A\A[AZAYAX
_^][ZY
Dm|OeH
.9LcD!<fA
103*EH
HcD!<L
LcD <L
HcL <H
| ATH
|$hfA!
<%0kY)H
qpAUAVf
#ZAWfA
d$ )D%
103*Ef
frm|OfA
<"/AWf
103*EA
Ke^@Hq
ykOxk9D
yjt&/
y?q0>8
y*CXud
hayzlxT
h-fsNb
ZTbyty
j@/^u,
g#dI*{#
@`cp?.
@gp.C&
%JN+3fA
/Uc|7A
ls0}XA
nupM/V
uN#vDE
N+j~8;
103*EA
T7qqHH
*oT2$b
1+Z#-r
u<+5xM
ni?rUn
103*@*
K)j"8=
KU<2c.
KR4C;+
"19)g1
Ky6s'7
@@lx7ry
KMJHnfE
}9lR~7
;kR23}iL
(If{kR9
M$sR:|B Y{
jRSr~
e)h@=kR'"
qpWsRS1
Yb*kR{
qR#k*;vJ
^S 1anR
{,rR+'
,KAjRy
lRD9R6
i0p<zA
i;ICF}
i|R \Q
9pJXfD3
jQq@ATD
{Pth]'
{K?|!)2
'?&?K+
|('|fH
c-gb97
b"RL@/
FSxC{X
XxkY/4N
SxDu\H
,RxNU
UQx[gY
V[Yx+'
wrOx_t=0
fnl1_x
,syOxO
&XxIGT
Xx\0Y;
TxguM]
ZjQx3*
P,J<a4
"19/FF
_~Ix(A
U<2c{rH
*-h@-h
yrm|OfD
P~c9tf
Yt&T/h
LW0qmL
> AUfA
bn[f&9
1:Ug4<K
5t*Y9DD
t5pNCB
%,>=?z"
jYCo|Z
ovZs|{
p|lw_S
DK_\W`
625To|
] 4{|_=
h"p|PI.
00Z#,t||
kzz|{,
9z&`+t|r
m|j<6
p|"KGW8
SQIJEt|T
c\@E ?
,%K-dvH
sE4/RH
\?Z7tjP
zx#R?
L03*EH
MJHnC]
@103*f
+qpsjH
^][ZYX
tgA\A[AZAYAX_
A_A^A]
thj'Og
#FEz$
bC@h/
&YifS:
F^fT;'
dfP'+UK
dqr}^f
~_fnah
mB^fY6n;
vg^p`f
&q)_f%1
%pgfZ>
}_fV.~
a^`5Q_
]uf'_f
>Q^fd^
O5U2hfj
td^fn!
_fOoO!
"@^f/6
LOjt\K^fg
?~Q:t$
|X%By
s[Idj~
QZ~Mi{
yoL*d2!
O:*iu#
FMjh&p
jsTl@uQ|\
QH|j9>v
~Sin|jm
^}jR!^
JD1\"|
V-8Z}jf[r
jN1 l@Y~P
j_j0``
zj(8k'
*{}j**
yjkqrT
M,'}jP1
o{@'yj
ja(S#\
c)t|j!
yW1}jm{
v_VB$_
[Y.(5Q
@{Ok^QR
]<g{T
[m. H
2vaz)<
9dS6l0
&_eS0D
hSI0l"
eS1PCN{
m&b/~IpSs
"^]FoS
:#KPjS
hhSCkN
aS/lnG
bSN+j~
6E`PdS
`>kS#^r
Qz(ghS:
=opveSFn
ElhSflN
{eS)gY
=dS'=GG
cS|(p\
S,jp<e(#
`bo~3B13
7yA8<)
C@J2QC8b,
w(F0E~
C#lIRm
CUl5wr
@"{)np
`A\A[AZAYAX_
A_A^A]
^][ZYX
cB~C4#S
;?`!d9
;4"?=p
rm|OBs7#
^MLN57>`
Tx~ZlHi
@`cbdc
\?Z%2z*
?q0>:(U6
1i@|x+m
9, ~}m
90A/"di
/tw&9H^
AZAYAX_^]
qA_A^A]A\A[
Dczs^G
lk{d#:fO
qf_D-jK
&:-[yo(
&:of5t
ul'IYI
&gD gH
&sV};9N
DCS*f]
U/zoZ{
<^eC^d3
_rnS/5
k2Hy,P2
_V;fMN
oL'6"P
|j]d\7W
|'=GGi_
x[qJ@UqJ U
ova^{wx
|-C: K
0/IU9,
,~Yli#
0G.vrc
0ba \:
x<}=}=
YqVp[u
103*E.
,v9cX=_
B(7c#D
@`cwx!
*|>c_g
[|/\5c
Zd?cC.6?
xM8c-(
&k+;cU
^v4BcS:
k8c`H-p
H [g&"{
?cS1<>
#@S9cr
b>?crS/<"
9c{[42<
)49c@D/
G:"q(;c|
_P`wGP@c
*7c#3<+]
7c=hkLl(J
t5c^n)
jj;cTW
"}4R9c6
&9cGPZ#*
D/Cc_=
5$W2Yi
zI0Z#
f/0[=#
g%bwBg#
|6%=8}#
j(q+Cc
2)Ge4F
.9A_A^A]
4'\mu#
^][ZYX
w^A\A[AZAYAX_
/6!`fA
X(s}WN
"E2,$D
HY `K]L@
tvutfD
AZAYAX_^]
A_A^A]A\A[
103*EH
"<,69I
]w%v#A
103*EU
D"?AVH
L 8UfD
eovaL+
cHcD#<H
#Ppi %3
3*E>%$
rm|OfA
/x##3}
#GI"+BMD
b45%#S
GLSq3o
]9Z;4!##o
5#J<*
5$W}4D
:|B _j2
_w;9_4
cg@XRl
eaaT}B
W?SZoB
'ppa<Sq
'0>q[=S
1`=>SJ7
s>SS<)~
WWCDSN
PeX"@S
!EV'>S9
v]SsDShG
I;?SV:
y24HS*Wi
Y'GDS<
Vb>ST2
9I>S!J,~
z==Sy[h
4FS~|U
<S{zrnSXPn
<!B3JHSrx
A-]FS8)
u=STV
>S2G[[S
ESc=Sl
w'&?SKZ
NIV=Sx
%DSp|
}h/e\<S
*E+hG~
iS\\};w
rS/<ac
s[(8
G@+\OP+
Kt+:H_@
vIB,if
AZAYAX_^]
cA_A^A]A\A[
\$(AT@
gERI[h'
\jI6]
oJ{vJ
4G7$ ]
r1]!(B
1Q"Z+
0lmirn;4P
Y-4"!Y
v0uli&
103*Eh
"6vEL<Y-
)(%4w/
6LawTJ
v!jMFa
>hOZhy
z}~a?h
]>o!&W
/IU9\9
bLvx0:
+'pUf}:
yv:Pi9
hClINU=
5>GJsB
mUI6(U
1x`A3o_
{3u ?6
<D2auD&
8)yS]-
f/UOQz
}RHNoP
h)%nd!]
|{2l2
O9tn[78
wX7m:
w^:af2.
W>0i(?
jFr %'
103*EZ
{<v9(t
z_5$PF
DK]bA|$
8#ovF_
rH]yR.G
rm|d`f
pU,cLO
v%}LSQ
T;]fMU
9@e>)I
'No"Ap9t
103*EH
brm|Ow
>UNi:5
]%tv#2
xw34nP
QL]0qTup
>o+ V7s8~
5~aZuFA
-6Zw*v3
y~,1mn
5$Wnp
qnw;J(
K}2! "
D$4vT2
103>}(
aHn|5Kju3
3IjuDn
h,suww/A
\qu{H~
Dokju p
m2`lu+7*
Igqu5V
AjuO$b
^v?nu6#
U*luG6}5
kuMy7y
iu"%pl~,&
nuno<#e:
`ua`su
_lu,9sra3
gu/lnGh
bGh@Wt
NsuN1 lD(
5zku|P
X<3CCju
~;[HluI
`J$\ku
xT%?r$)S
\lA:oP
5$WD2$!I
X(smG-3
lH)e>g
4p)EV2+
%h7>Np
103*EM~
}e2B)XO
zg&(qvx
/6!`9^
)HA2,!L
W]br'nO
coWbOoO!a
F)qXbf{!
+mKd]b
]b,HjP'
(XZ=KYb
n]b}nW
UblN`i
]]b>Ct
0Wbw_g
-`bKfyPS7
[bj%JhS
VbVbj8
SbYw7eF
7Z]UeXb_
<P>WbD
>AGbMz
t3EDzU
T0qgT0
9PLQWE
Wfd[]d
}LZwZl
PNMK*(
-\@GH
+hA8vV
F4Oh~MTBo
)"BQ\Le
q@$gI@D3'bD
($Uq:67
|'Vuc=|(
103*5V
1"Jl]g
?`sW4T
@e,X,33-;
HVMKJ(
L3OXN+'@
;Qf|qG|X
{M!=,4
jf)fA
N)DQxb
hV];J(
A;np`W
zsT3Bp
jVaDV'
~_@'Cd
zwXWSD
M(2a 0
D$YsAPH
D$[nfA
D$RwPf
5$Wr6!`
$cGsd>S\
xdonB-hP@
kRnwmRN
k3"Do'
I[Z\Cu
@ODCn&
d66sv%
,9sr)B2
.*N7|i
xC5"}oL
rm|u3=6
A?>,q O
Kb2, V
,rm|O&
k:9[8'
<>y1|D9H
D{;, ?
&f/}2R;9
TjW-BXM)B
LhDvfy
bNyhN\
,0c%pB
l%'SfA
rm|O]"SN
\2G]R(]3
9"B{2'Z
{RP1f]
@6mlp]
SU0H~r
rm|OD|
/6<jT5
2w 5\x
|o.]nq
v{ZAsBD
lQPiHP
FHOa R
w?.P{3~h
I%.$A74p
:pUQ:pM
GTc2Dw/,;*L
ejAx{2
P|@O7X
~uIPT#
yUNdY5N*kafG6L
CDzoKDZ?
103*E9x.
k4*0yo\8a
~LCG6*
!C@ODC
Ih7n'j
RUdp%H
}Lj#nu
Yk2w/j\
.9)^UW
`nE#20
;4t-)J
8.3oxn
vSqA7
fjneX
A2dn4
y"ki|
nngK(
D`Fp|no
8:qP-
X{TVo;
O9eO:w;!
mgD g
ggF"m
"Xo`z
>?E$m
`1@Pc{
kSUsgHkd
~5,oD)
d~tJY
Rs`cnW
H~SiV,A]6
Zv?;\=
T3i6RC_h^
*oFE}n
xgLKBl
cJf;d}
CLHY/,b
j, u~D
=Z/6!`
rdcgd#
4'N?ld
p(cG7zlMM
cDK'pfs
DaF%^m
XALPa{
P&;WPf
j{6EdM0qD#z
`aW3_l
u03*EA
aS0k"
30?.P{3
-#(dmc
6]~1je
103*E*
_U">O+
h?{,B_U
P|PU^T
Fx'I B
ym~Y;p
=3jim:
!}`k#~
3o`!xY
103*Ec
-Oz"!#
Dw1U9%
zMD9R6
(:&3!}M^
3Fu3ByM
fyMX=g
uXdZ|M
+Bps zM^0o<
GhnU|M
_^\%\KzM
.deI"!
|>zMZ|
}M/^*hH>!
|hcJ0>
)ha2ey
1m|OhC
s*(e${y8
cyn8wT
O;fU;I
Q`OQ8Z
F*)h]$
xGU,*Y
nPGK:.
`o{XY\
adeHiD
]}fdhm
v51b~7
{o'bd!x
2O:&Sd
=Qj@uM
31{/M@
OklbU
WFbsIF|
UWdsBT
#qpsjH+
GZa}"(
>4AW<8
ul@GK*
=}FO^Rgy
).oNEG
M?"4gy
>E!jfW
W2AQfA
?oPTuC@
+ y1lN
cbGh^#
DqG$ Y
#,(YoD
%3"NB=
&So+&$
#'$wi:
tU0a,5@
G|irf[dJ"
X7v9ps
{l>m~
X.SIVrS
~bswX!
e#Pycb
n%!Rh5K
4!o$\%#
{Q6,iJ
/Vt, b
ovaf{q
mrq(T8
5$WS7$
LhELdy
L#brYA
d'V,U!fi
h=Xr0"k
t`[B(6*
>o60k7
"rUW.~]
>+y.N7
PB?rTe<
yh_M.
,?oG5}|u=
!77<x
O(>D-cX4}s
{q6r{q6r+Gh
/xTm7~
U:zC{d
NU+@\-
zXGUDh
/5f"ob9
jiwfzU
z;;"QXt!
(x[+l5
kH>{\+
pb_."#
wvSR}%x0
J@wVZ7
iE.jsi
hD%[xt
[t=$hy
@R1cR~R
qps[?]8
%{4'V"
%}lck_Vn
-f3 q9
bovaKd
x{"^%)
Lb7StUD`
BNj:N{
of\!]Vr#?
hduKH)
/a0R)Kv
%QEh*
?\$_<~Gx
{GfrVkQ
"0(uS|G
(3dU/?
rR;|{G
tr@}GH
{G_(EQ
.:|G8'#
{G#3<+
GBk!8(&
8~Gv@%
n]~`Z|G
T}G)j"CK
pQPF{Q
qHj!C@Q
_5^q(+B>
'6[2A]F-
0wX#,7
103*EwK
]3@V;7
k)|E}6
/6d+<@
`\Mi2(
F;03*E
@2m`<~
#V !2}E
XZG6;:
qpsj-n
103*E<X
w4qq!6
#?@<U1
yUFb+'
sj>c>0
E^I+{$
|irf5a_
*ha^cy
k_PWKp
}N')zg
103*E:
%pzi`jm
4}0}V;
4SQX\9|n?
Z.}:X&
8{B%tG~:
103*Eh
U%v9h>gF
uK0,uq
~pm@Vd
r3bh>Fcy
V+9Cs^%
eQ|K1?
/`cD/@
nmeh->
mF)j]^
bAr$)V
tVGpOW~
/6!h(H
32IB].
`i=BKI
103*Ekas
yP10&[7`
* U1Z;
I(/A "
(103*E
rm|A^D
_4S!&P
103*8A]N
JXO]VS
kx!P'V
P+Y2cfl.
51Bs3
G, cG
j`kf<~
@uL[w#
O^V@-U
jmqb'Vx{
!glj8d
V-U-/{
?nYNr|
qn6st>V
.>r|6"
(`itzF
dQzen=
/Bv"v1
>*t)WT
_l1z}-
XAR?Sce
jx%'j
[:a@S;
9q0j?f
"0el$
cVa}(!
=0>u(p
~E9+9''h!
t~C&.K
QpAp$
\nB<8F
zeW%5#
r9s&Pp
}6uT=E
7Nfa'?E
wkQ` ^
a7<=rA|
WBq?DL?U
~qko:;
Zp:@m8
-qx#sb
Xy>T6h
>%P+J2a
8^prL<
=xq{7?
J')KG^
><[r`eZ
cw<GbA,
kjeig7
I1aIxn*
E'*]Uo
L<v{U51k
u$?>Pl
?CB>`L
]2a6}OO2R&
PQG29SG=
*PyY)Q
%kv"]q&G
b$S(AP#
Blm3`V
%'^DO<
&Z.Ef=
5L[fwWK_
/qzVudp
jiK0t
~TAT=Y[{
[5#>*:
0>/k&z
khb#&(
:K-LFF-s
"3:x'_
9w`*:2
m-Z[ezA
#2:iWE
-0yhZ2
wz3yV%%
!e^C4i][
t&+k(g
$g*u#*
7}%SdE>
scQ~8X
'32G&+
~.AI2.c
bd+vbv+V5O
{>G2gb"g
@.k3\P
U`DwG2
&O9^&
I_u<,R
iCDBng*
$dt8sS
ktNiM5
:{3r${
%O,hjOIsn
G>&i7;Mf
8F^i><
jP8dHeNk-
64J6x;
`UU<Ye
i^p}6v)
Wq3V;2
V7@3"T
BoXs>3Q>
g=0'!b:,
oadwlK
i=ORG#
-*ZGJuZ;
"3%MI)
94(t=.X-
"~q%^@
6rH<-?
eSp>*'j.
Sn2OA$
nAGWw#
ATTdN)
0y%G'sc
%AoUo8
G:E0&/
PCqH=Zy+
p6T{j$
*Gmzy{
>k8dxe
>Rq` \
$N-AG>Y
^FgnMQ
Sk!8JT
7yOU;';oj{
s;RvHd;
KYBDWRz
x=)FK
[)C3Pq
eZv4#%_!
7#Qa1w
k%OfDWAv
7LmV\$O
Xd9PkH
[SyoJ@
`-XgJK
u}icm{
h3(Q)`!
.^+12#=
B+EBQ}z
"'tjh^
Ee?Jm[
%SJjfs
|VKqLFe
GaaYZz
o0N4f,
WhJs::
[{1JCT`:
uM)WWs
Cjkxkz
^k;x2H~
RT'S`l
?4:)V^
`m!\U#
[n'jNa
:8WzZ?S
pd&!{>
A*v8SE
Bw2fwI
f{nBq
zs(Z_c
)R&2~PS
PA`t z
`x\yC|
pR$[=l
f}A(]jq
/4ex[<A
<4H.15
(G0p'kd
+l Pne7;s
A*0,&h
aS(rf!
|(b<`B
beuU<,
3T%*uU!
cbpLFv@
X!/"gc
oO1(pt
4W}~6U3
RO|Xp>
@nihIJ%
doNW#\7e
$Us;S0
m |U=\D
U qS :{
|n_:|
+G\FA#
4Itlb"yRF
3|/T}9
K~]~mwv
EZ0{%q
8Jtp2_
w$e!&i
.text$mn
.text$mn$00
.text$mn$21
.text$x
.idata$5
.00cfg
.CRT$XCA
.CRT$XCAA
.CRT$XCZ
.CRT$XIA
.CRT$XIAA
.CRT$XIAC
.CRT$XIC
.CRT$XIZ
.CRT$XPA
.CRT$XPX
.CRT$XPXA
.CRT$XPZ
.CRT$XTA
.CRT$XTZ
.gfids
.rdata
.rdata$00
.rdata$r
.rdata$voltmd
.rdata$zzzdbg
.rtc$IAA
.rtc$IZZ
.rtc$TAA
.rtc$TZZ
.xdata
.xdata$x
.idata$2
.idata$3
.idata$4
.idata$6
.data$r
.data$rs
.pdata
A_A^A]A\A[
AZAYAX_^]
USER32.dll
ShowWindow
GetDC
)GetACP
DestroyWindow
FlsFree
MulDiv
CreateWindowExW
PeekMessageW
NTlsFree
GetMessageW
RegisterClassW
eDefWindowProcW
0DispatchMessageW
ReleaseDC
6DrawTextW
TranslateMessage
EndDialog
MoveWindow
PostMessageW
MessageBoxW
eMessageBoxA
DestroyIcon
SetWindowLongPtrW
GetOEMCP
GetClientRect
HeapSize
GetCPInfo
FindClose
GetWindowLongPtrW
LocalFree
TlsAlloc
SendMessageW
ReadFile
InvalidateRect
COMCTL32.dll
KERNEL32.dll
WriteFile
LCMapStringW
!GetLastError
DeleteFileW
HeapFree
kGetDialogBaseUnits
HeapAlloc
CloseHandle
FlsAlloc
IsValidCodePage
GetStringTypeW
FreeLibrary
FlushFileBuffers
GDI32.dll
CGetTempPathW
+CompareStringW
CreateFileW
GetModuleHandleW
FormatMessageW
FindNextFileW
PSAPI.DLL
GetDriveTypeW
GetModuleFileNameW
FlsSetValue
t$3AUf
LoadLibraryExW
SetDllDirectoryW
6msvcrt.dll
SystemParametersInfoW
MsgWaitForMultipleObjects
~ShutdownBlockReasonCreate
DialogBoxIndirectParamW
CreateSymbolicLinkW
GetCurrentDirectoryW
HeapReAlloc
SetEnvironmentVariableW
GetCommandLineW
FindFirstFileW
GetEnvironmentStringsW
RemoveDirectoryW
ExpandEnvironmentStringsW
GetEnvironmentVariableW
QueryPerformanceCounter
WriteConsoleW
GetProcAddress
GetCurrentProcess
WaitForSingleObject
CreateProcessW
QueryPerformanceFrequency
GetExitCodeProcess
x[TerminateProcess
GetStartupInfoW
GetFileAttributesExW
FindFirstFileExW
K32GetModuleFileNameExW
MultiByteToWideChar
K32EnumProcessModules
WideCharToMultiByte
}GetFinalPathNameByHandleW
GetProcessHeap
SSetConsoleCtrlHandler
FreeEnvironmentStringsW
RtlCaptureContext
CreateDirectoryW
/SetEndOfFile
RtlVirtualUnwind
RtlLookupFunctionEntry
UnhandledExceptionFilter
RtlUnwindEx
5$WGetTimeZoneInformation
IsProcessorFeaturePresent
GetCurrentProcessId
SetUnhandledExceptionFilter
GetCurrentThreadId
IsDebuggerPresent
SetLastError
InitializeSListHead
EncodePointer
GetFileType
TlsSetValue
RtlPcToFileHeader
RaiseException
YTlsGetValue
GetCommandLineA
PeekNamedPipe
InitializeCriticalSectionAndSpinCount
FileTimeToSystemTime
GetFileInformationByHandle
GetFullPathNameW
VSystemTimeToTzSpecificLocalTime
ExitProcess
GetStdHandle
GetConsoleMode
GetModuleHandleExW
SetStdHandle
SetFilePointerEx
FlsGetValue
ReadConsoleW
GetConsoleOutputCP
DeleteCriticalSection
ADVAPI32.dll
GetFileSizeEx
SelectObject
GetTokenInformation
;OpenProcessToken
CreateFontIndirectW
DeleteObject
oConvertSidToStringSidW
SHELL32.dll
IPHLPAPI.DLL
ConvertStringSecurityDescriptorToSecurityDescriptorW
LeaveCriticalSection
X03*ED
qpsEnterCriticalSection
Crm|Of
GetSystemTimeAsFileTime
^][ZYX
A\A[AZAYAX_
A_A^A]
Safengine Shielden v2.4.0.0
1U)AYy
D$(WfD
d$=ARH
4$APAVH
DUSER32.dll
COMCTL32.dll
KERNEL32.dll
ADVAPI32.dll
GDI32.dll
IPHLPAPI.DLL
msvcrt.dll
PSAPI.DLL
SHELL32.dll
CreateWindowExW
GetACP
OpenProcessToken
Antivirus Signature
Bkav W64.AIDetectMalware
Lionic Clean
Elastic malicious (high confidence)
ClamAV Clean
CMC Clean
CAT-QuickHeal Clean
Skyhigh Clean
ALYac Trojan.GenericKD.74316972
Cylance Unsafe
Zillya Clean
Sangfor Suspicious.Win32.Save.a
CrowdStrike win/malicious_confidence_70% (D)
Alibaba Clean
K7GW Trojan ( 005bb86e1 )
K7AntiVirus Trojan ( 005bb86e1 )
huorong Clean
Baidu Clean
VirIT Clean
Paloalto Clean
Symantec Trojan.Gen.MBT
tehtris Clean
ESET-NOD32 a variant of Win32/GenCBL.FGX
APEX Malicious
Avast Win64:DangerousSig [Trj]
Cynet Malicious (score: 100)
Kaspersky UDS:Rootkit.Win64.Agent.gen
BitDefender Trojan.GenericKD.74316972
NANO-Antivirus Clean
ViRobot Clean
MicroWorld-eScan Trojan.GenericKD.74316972
Tencent Clean
Sophos Mal/BadCert-Gen
F-Secure Trojan.RKIT/Agent.ecpsx
DrWeb Trojan.Rootkit.22113
VIPRE Trojan.GenericKD.74316972
TrendMicro Clean
McAfeeD Clean
Trapmine malicious.moderate.ml.score
CTX exe.trojan.generic
Emsisoft Trojan.GenericKD.74316972 (B)
Ikarus Trojan.Win64.Krypt
FireEye Generic.mg.110a014684ddaaf2
Jiangmin Clean
Webroot Clean
Varist W64/Noobyprotect.B.gen!Eldorado
Avira RKIT/Agent.ecpsx
Fortinet W32/GenCBL.FGX!tr
Antiy-AVL GrayWare/Win32.SafeGuard.a
Kingsoft Clean
Gridinsoft Trojan.Heur!.010100A3
Xcitium Clean
Arcabit Trojan.Generic.D46DFCAC
SUPERAntiSpyware Clean
ZoneAlarm UDS:Rootkit.Win64.Agent.gen
Microsoft PUA:Win32/Kuping
Google Detected
AhnLab-V3 Clean
Acronis Clean
McAfee Clean
TACHYON Clean
VBA32 Clean
Malwarebytes Generic.Malware.AI.DDS
Panda Clean
Zoner Clean
TrendMicro-HouseCall TROJ_GEN.R014H0CJF24
Rising Trojan.MalCert!1.BCF8 (CLASSIC)
Yandex Clean
SentinelOne Clean
MaxSecure Virus.W32.packed.Noobyprotect.B
GData Win64.Trojan.Agent.D0CNKZ
AVG Win64:DangerousSig [Trj]
DeepInstinct MALICIOUS
alibabacloud Clean
No IRMA results available.