Static | ZeroBOX

PE Compile Time

2021-01-13 04:22:48

PE Imphash

3a8897c84eb41f36b4bbabcc617408b8

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x0006e000 0x00010000 7.92703740481
.sedata 0x0006f000 0x000c1000 0x000c1000 7.81940266336
.idata 0x00130000 0x00001000 0x00001000 0.697017299932
.rsrc 0x00131000 0x00017000 0x00017000 4.01563924105
.sedata 0x00148000 0x00001000 0x00001000 7.98145004983

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x00147858 0x00000468 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED GLS_BINARY_LSB_FIRST
RT_ICON 0x00147858 0x00000468 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED GLS_BINARY_LSB_FIRST
RT_ICON 0x00147858 0x00000468 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED GLS_BINARY_LSB_FIRST
RT_ICON 0x00147858 0x00000468 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED GLS_BINARY_LSB_FIRST
RT_ICON 0x00147858 0x00000468 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED GLS_BINARY_LSB_FIRST
RT_ICON 0x00147858 0x00000468 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED GLS_BINARY_LSB_FIRST
RT_ICON 0x00147858 0x00000468 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED GLS_BINARY_LSB_FIRST
RT_ICON 0x00147858 0x00000468 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED GLS_BINARY_LSB_FIRST
RT_ICON 0x00147858 0x00000468 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED GLS_BINARY_LSB_FIRST
RT_ICON 0x00147858 0x00000468 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED GLS_BINARY_LSB_FIRST
RT_GROUP_ICON 0x00147d78 0x00000014 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_GROUP_ICON 0x00147d78 0x00000014 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_GROUP_ICON 0x00147d78 0x00000014 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data

Imports

Library KERNEL32.dll:
0x530165 GetProcAddress
Library MSVCRT.dll:
0x530171 strncpy
Library IPHLPAPI.DLL:
0x53017d GetInterfaceInfo
Library PSAPI.DLL:
0x530189 GetMappedFileNameW
Library USER32.dll:
0x530195 GetWindow
Library ADVAPI32.dll:
0x5301a1 RegDeleteKeyA
Library SHELL32.dll:
0x5301ad SHGetFolderPathW

!This program cannot be run in DOS mode.
.sedata
.idata
.sedata
jAQh>L
0$]?=t'j
iA+oB||=
W#\2rL
sBAD3@m
D0L@yZ
5pZnRr
LKlA6_Cn
QX"rQ=
}z2~de
=t`|&22
Pc_3no
r,B|po
j62nUJKK
Uc!p$1
[&-E^no$Z 5x!Ba
LcVR]Z
2e:AA[bMf%
tB]Vav
czH5|k2
A&A\<gRQ`
uz\4tu|
1^!)*KvKY
Oh5##a
qrp{}%
KDGzG`
$v44#r
vL0Lym
o|%x5!
t+c5#Ch
}lS]yy{
s&GR}6
tSPJr;
?ZW:6d
$rmXq8Ay
`Q!y;Ag
D*W`#C
r&(M9{;
w%\c$V
"Z|G/7a
`[JG-}h
/KRSNW
MXs|o
h/~0$a
g0QaFY
kqcuiZ
90=C8?2
D}1l 0N
dtY?E}K
r!Yv^+e
zP}{qj{mx
,6;_W/
[Ally\
_^j&*c
3bNh2Q
u*4{E-8
?iD:b9
\$4tZf
vgdKt_&E/
,;f(V7
#V^&+U
wW^S|ye8
}+,GtbGX
]{TAMy
x:/O.v
vR.\Qp
?>Z"Cq
(N55)I
c,Bp/Q
~-`6KS
^ZHB!9
&M8=*X
3|N2:d
AU2A@H/
{Ra(\]:h
C3ngS|
F#<X1G
6i716"~:u%
`5wr1~]
{}[~r)
NU'8ZK
IGt{e>NB1f
h0`"7}3
cU1{o2
GQd8j9
>kl!D5
%tF_3aL)
Q,6EuT
Y27P'r!
'a})8C
p@7gK8
y:\$A=
,>!Hn1
I1xFDO
Z?HcV-
&0'V~;
JeG2ib
{y[QE@
b4M0Pkg&YNt
$ahLSq
In3?h6?HgHr
''\?.G
7`fC~)Ml
r-TT$T
xC3L 4K\*y
/OX7.
"dgdVR
nG1qq=
AQcw6Q
TT&^4Y7
TG5CM^
|+5d+^8<d
CM&k=
ausotI
q8!TEb
m+NR#
!6w,MK
%MRA.i
fCt<u$
KO,W:u
l`#ZPy
|2A.v6
;L$,wv)L$,
~*>6S\
Z):A.R
{G!SA.d
)rm|O1
gM>ZNn
j03*Ef
C.?EWe
(K}MS6
A.6<.LzU
A.8pcd
n-\?=y
=RZx.P
;Vj:'uvZ]nR
>PP->&
!.:h"]
I_oKr]
*&:\.9
wR59),>py
".:3)H
e}24'N
&Q/6!`
"]$SVW
-t.N[N.g+
]dp7p4
VHxjy)
@2:,\R
:avU"]
103*P\y
BeN:s7
8BB|da
lrm|ON
E[N2kQ
d$ rms
kF[N1jP
dND}cw]
GetModuleHandleA
GetProcessHeap
HeapCreate
ntdll.dll
RtlAllocateHeap
LoadLibraryExA
CreateFileW
GetFileSize
ReadFile
CloseHandle
VirtualProtect
GetTickCount
GetProcAddress
RtlFreeHeap
InitializeCriticalSection
EnterCriticalSection
LeaveCriticalSection
DbgBreakPoint
DbgUserBreakPoint
DbgUiRemoteBreakin
kernel32.dll
NtQueryInformationThread
NtSetInformationThread
user32.dll
advapi32.dll
hid.dll
iphlpapi.dll
VirtualAlloc
VirtualFree
SetThreadAffinityMask
GetCurrentThread
ExitProcess
GetSystemDefaultLangID
GetSystemTime
SystemTimeToFileTime
WriteFile
GlobalAlloc
GlobalLock
GlobalUnlock
GetCurrentThreadId
GetExitCodeThread
OpenThread
TerminateThread
SuspendThread
MultiByteToWideChar
WideCharToMultiByte
IsWow64Process
GetStartupInfoW
TlsAlloc
TlsGetValue
TlsSetValue
TlsFree
CheckRemoteDebuggerPresent
CreateThread
ResumeThread
GetThreadContext
SetThreadContext
mscoree.dll
mscorwks.dll
mscorsvr.dll
KernelBase.dll
mscoreei.dll
clr.dll
diasymreader.dll
SECheckProtection
SEGetAppStatus
SESetAppStatus
SEGetLicenseUserInfoW
SEGetLicenseTrialInfo
SEGetNumExecUsed
SEGetNumExecLeft
SESetNumExecUsed
SEGetExecTimeUsed
SEGetExecTimeLeft
SESetExecTime
SEGetTotalExecTimeUsed
SEGetTotalExecTimeLeft
SESetTotalExecTime
SEGetNumDaysUsed
SEGetNumDaysLeft
SECheckHardwareID
SECheckExpDate
SECheckExecTime
SECheckTotalExecTime
SECheckCountryID
SEGetHardwareIDW
SECheckLicenseFileW
SEGetLicenseHash
SENotifyLicenseBanned
SEResetTrial
SEGetProtectionDate
SEAddMemoryGuard
SEDelMemoryGuard
CreateFileMappingW
MapViewOfFile
MapViewOfFileEx
UnmapViewOfFile
LoadLibraryExW
LoadLibraryA
=j&&LZ66lA??~
}{))R>
f""D~**T
V22dN::t
o%%Jr..\$
&&Lj66lZ??~A
99rKJJ
==zGdd
""Df**T~
;22dV::tN
$$Hl\\
C77nYmm
%%Jo..\r
>!KK
55j_WW
&Lj&6lZ6?~A?
~=zG=d
"Df"*T~*
2dV2:tN:
x%Jo%.\r.
t>!K
a5j_5W
ggV}++
Lj&&lZ66~A??
bS11*?
Xt,,4.
RRvM;;
MMfU33
PPxD<<%
Bc!! 0
~~zG==
Df""T~**;
dV22tN::
xxJo%%\r..8$
tt>!
pp|B>>q
aaj_55
UUPx((
cccc||||wwww{{{{
kkkkoooo
gggg++++
YYYYGGGG
&&&&6666????
nnnnZZZZ
RRRR;;;;
[[[[jjjj
9999JJJJLLLLXXXX
CCCCMMMM3333
PPPP<<<<
~~~~====dddd]]]]
ssss````
""""****
2222::::
$$$$\\\\
7777mmmm
llllVVVV
eeeezzzz
xxxx%%%%....
ttttKKKK
pppp>>>>
ffffHHHH
aaaa5555WWWW
UUUU((((
BBBBhhhhAAAA
='9-6d
_jbF~T
11#?*0
,4$8_@
t\lHBW
QPeA~S
>4$8,@
p\lHtW
+HpXhE
T[$:.6
00006666
CCCCDDDD
TTTT{{{{
####====
ffff((((
vvvv[[[[
IIIImmmm
%%%%rrrr
]]]]eeee
llllppppHHHHPPPP
FFFFWWWW
kkkk::::
AAAAOOOOgggg
tttt""""
nnnnGGGG
VVVV>>>>KKKK
yyyy
YYYY''''
____````QQQQ
;;;;MMMM
ccccUUUU!!!!
6bad allocation
_except_handler3
MSVCRT.dll
GetInterfaceInfo
IPHLPAPI.DLL
??3@YAXPAX@Z
strncpy
wcsrchr
??2@YAPAXI@Z
strncat
_wcsicmp
_wcsnicmp
__dllonexit
_onexit
_initterm
malloc
_adjust_fdiv
GetMappedFileNameW
PSAPI.DLL
DeviceIoControl
DeleteCriticalSection
GetModuleFileNameW
CreateFileMappingW
MapViewOfFile
UnmapViewOfFile
GetModuleHandleExA
LoadLibraryExW
MapViewOfFileEx
GetLogicalDriveStringsW
QueryDosDeviceW
KERNEL32.dll
wsprintfW
OpenClipboard
EmptyClipboard
SetClipboardData
CloseClipboard
MessageBoxW
FindWindowA
GetDesktopWindow
GetClassNameA
GetWindow
USER32.dll
RegOpenKeyExA
RegQueryValueExA
RegCloseKey
RegCreateKeyExA
RegSetValueExA
RegDeleteKeyA
ADVAPI32.dll
SHGetFolderPathW
SHELL32.dll
103*{wzu
103*Ef
?03*Ef
103*Ef
<R`#BR
=R*8>RZ
$?RDl>R?.=R6
]DRFu;R
zDR_.CR
?Rk+=Rl
=R\>AR
c=RFW?Rw
AR,EBRp
?Rc8=R
=R>t=R
?R^2CR
]>R}4ER)e@R-&=R
;RK>CR
?Rd#BR
;RDe?R
_=RF(AR
?RkZ=RkO=R
AR[p?R
?R(CAR
<RI~?RE
>Rl2AR-
?RxZARFk?R
<RNK=R
@RHI>R_
)=R?jER
strncpy
malloc
_onexit
wcsrchr
MSVCRT.dll
MSVCRT.dll
_except_handler3
IPHLPAPI.DLL
GetInterfaceInfo
??2@YAPAXI@Z
??3@YAXPAX@Z
MSVCRT.dll
MSVCRT.dll
MSVCRT.dll
MSVCRT.dll
__dllonexit
MSVCRT.dll
_adjust_fdiv
MSVCRT.dll
MSVCRT.dll
_initterm
MSVCRT.dll
strncat
MSVCRT.dll
??2@YAPAXI@Z
MSVCRT.dll
MSVCRT.dll
_wcsicmp
MSVCRT.dll
_wcsnicmp
MSVCRT.dll
MSVCRT.dll
_initterm
__dllonexit
MSVCRT.dll
MSVCRT.dll
PSAPI.DLL
GetMappedFileNameW
PSAPI.DLL
GetMappedFileNameW
GetLogicalDriveStringsW
03*EtV
KERNEL32.dll
KERNEL32.dll
QueryDosDeviceW
_wcsnicmp
MSVCRT.dll
KERNEL32.dll
GetModuleFileNameW
GetWindow
KERNEL32.dll
UnmapViewOfFile
USER32.dll
USER32.dll
GetClassNameA
MSVCRT.dll
USER32.dll
OpenClipboard
USER32.dll
EmptyClipboard
USER32.dll
SetClipboardData
USER32.dll
CloseClipboard
KERNEL32.dll
MapViewOfFileEx
MapViewOfFile
KERNEL32.dll
<$f^f^
CreateFileMappingW
KERNEL32.dll
strncat
USER32.dll
wsprintfW
wcsrchr
USER32.dll
MessageBoxW
KERNEL32.dll
DeleteCriticalSection
KERNEL32.dll
GetModuleHandleExA
MSVCRT.dll
strncpy
MSVCRT.dll
wsprintfW
LoadLibraryExW
KERNEL32.dll
_wcsicmp
RegDeleteKeyA
ADVAPI32.dll
ADVAPI32.dll
RegCreateKeyExA
ADVAPI32.dll
ADVAPI32.dll
RegCloseKey
RegSetValueExA
RegQueryValueExA
ADVAPI32.dll
rm|X-X
RegOpenKeyExA
ADVAPI32.dll
KERNEL32.dll
/X-6DN
DeviceIoControl
MSVCRT.dll
USER32.dll
USER32.dll
MessageBoxW
SHGetFolderPathW
SHELL32.dll
MSVCRT.dll
USER32.dll
GetDesktopWindow
FindWindowA
USER32.dll
USER32.dll
FindWindowA
USER32.dll
FindWindowA
USER32.dll
FindWindowA
f_`fW
R&:H)H
xfA.w7
1S+=.
I+:m*E
}fYfX
B{*@4G
6A34$n
c)3~1L2
@z`!m?
1N$:eeSE
~1STI{
+PJ{^-
)PZ>}z
f"03Pg
,PDqaL
R-H,P\[
/,P>*G
sm/PzDq,
jNcL<B
lpgO},P@P
b y2/PAC
zd/PN
-Pyh\e/3
vG0-PJ#
:^(P-Ph
fKyAx?
ic.2CA"
D6HD*2!
PEi*2g
+2C~-x,
$2"td`
U!G^*2
ht_|:
m|8]>-2c
W*2%S6TV
&24]0Yb
%2L'~x[
r*2L02
yx<W+2
'2e@,K8-
F*2nO]
]j.2_+
q9$(2c
Ik*2Jt
;Y"C(2/
JkWLT
Dv8N9T
i#<`6GV
D/K?8[
_xUn[:
b8otMZ
@@i)jg
DQL.{:6
+"I8h;
QQN%cv
5 7SO<
'49xY>
rG3ro`
rm|OfA
`9'FBp0
RCx-x0
rCv7h:!
19nMl6
)KCco4
Nz;R:s
af(NllX
DX),y`]
G7GbV2
2@\8C^
,$PfZf
Xqn^fY
;AqZpX
JAxOyM'
Om|YfA
2p*8^N
t$ fJ`
4$fWZIp
OfzUG
03*ED
[L_N/hiK
5rm|Oh
h}ovaO
103*E?
0rm|O&
EpsjIW
t$ fQ`
qpsjzeS
;6ZN(a
$fHv*R
yFZN<u!
G4I%L`
+aG6Ft
E+zD$X
) %&=Z
'D)Tpa`Q`
'|=^X7
's&El(
"6e/ML
6cSHeq
8FQxyY
&nHAF}
wrBFd7g
|^GL=F
(r<F+x
K`~%;FH
o7AFUr
:F6V~;7
f)\5s7F"
]F N!n
j @F1Sf
;_V!n=Fqqn
TuY:5m0
>FQN%cW
x%9^k=FN6B
6@WqBF
?F#A#!
AFcErL
WaW`W,Z
@`cxy*
m5*D`
#op<BE
v]|zVZpW
"|61[N
P[N6op`
#Nl@+YI
jP:%XOP
l\^DLY
:`wx:)w
]hA}N}
i-K>(R
ov4YLy
y-DEKk
MAIeJ
YIvTU9\
q:5qN
F4sz"I
)AkFJ9
fItOf5
eB[N0i-
psR!)c
)+bql
KmGwiy
fJymxk
t5u3)H
M+>MW$~r
KGe5"~
iK9{$~
XA)~#NQ
7'~{n7o
wi@$~%G
mqw~>m
$~~]lx6
($~MV`
'~D)Tp-s?F
~f*`.
yc{0)~JQ
mL[NB{?
rm|O_Vt
&b.=ms
?Jzl{;4
~M =iQj
@@w*JC
Hq*px>
4&_`(=
9nw%T
L(ab_y!
~BLBwjd}
>n2/Z=
^=x)\?
^E3`s{3'
K,`&.L4
Pp*HZN
vS~a$=
7[oJC.
rks65$
03*E!|
34w{5+
'bDK6"
s)NcwE
lhvq5
R9ZW37M4
#co$eG
s&ElQq
-B9Z^n
hfK{$z,
$fKfSf[f
P{^2K~
:[N=v:
q1`C~{
pt60))
>R5H)U
6tI7u{IW
-\+Z/@
XW>)8=
;E?tJT
uCM_xn
gq1sWdy
Qs+(S6
^2/Z=K
/pp{'Jz
C-:=03*E
3C@E&R
Vo)8[N
>-:!&Q
d$ fIf
(q-p+t
!103*`
qpf 7[N,e
s3guAf
?Oii@
qps_Rt
k%1^NU
fApCqA
4i#J^N
rm|OYA
@Q(FqT
pL^N?x$!1
/m-n./d
103*Ed
R=._p
{Rp*>?
Q+1;%x
\x@oRppn
dKt/6!`
R49x9
fZxM..^n2m
5^N*cd
|8gJz[
=.3kz%W
O^NB{'
I'G@c0cEM
EFhd/M
T;I8h ~
I0CG#'=$
G1:l6CF
'd0z(}
R5>tyU
&>v-F\O
oRVFI[
HR~/_a
Ok:Veb*
cM2=/7
!x"iY_
?$Wq-e
/wI*(I
*a<mYX4n
GMr"@X
n-\?=y
n"aFJ^
@k]BC
`WqZC,
d*44d&
ma^{.]-
d49q 4
y1x/CMM!%U
/6!`Vd
_ZbgM.
U49|=.
{srE8:
xP_NAz>
=)JUT
QN%c~Ue
2!|uB
WQZmkC
@v0-cg
{R1j8Vova
)4dfq!
99<%l|Dk
oP^N#\
(Ib}<.f"o2dZ
%Wb}|.
8sC0~i
,W[KNp
g,Sh5h
I03*EF!
kf Jc."
Q(&b(E
&1aSv6c
fJ^NAz>
/6!z!*
03*E~Ga
!_ywpp2f|
<W]g9*lv6xVz$
2XQe36
5e`mS6
>^0[Ji
TH3}A1
8Rt>Rh
ovaV{Q
0:803*Ef
KA31$]
.*^7os
+bp37Q
fy32^NB{
c0:G*E
M^N?x$
rSDG^N%^
=6J]%~
kjHn3Hw"
Xb"dBd
ri#A^N
?.RXJh
4EM)e<
,/}7*i<c
u+*Re<&Z
Q})%d<
UQg<@Jy
\-e<:%
k<aIgl|zz
]2Yk<C
k<aIgl
8yXi(Wg<HIW>
Nz/i<4
c<B-tW&"
;(c<Qvg;eQ
Qdk<yV
oF@d<&
y>je<:
0)=]e<.
fJDLf<
I^N=vw
1:g103
'(K^N5n
{?103*
O)OnoF
5;-K)v=a
>hnZ/?
Ip?q'psj
)Hh*=D
Q>.,2hd+B
S>.GMO
tg|zK>.
FZny"x^
6_N1j.
\=&#|y~`
L_N&_#
*jhDH^E
>4nyf6
Rl3>iL
$gm;'%
|66TX"
uM}6iL)
K_N7pqaE,
{_103f.
>.ag![
l&I_Ne
X \,:A
SD*J-z
]@D8J|
5cmmJN
;HPfQf
d$ j@j
D$&<fW
103*X?}
d$ h8KH
rzW[u3zw'
X99W[%
/PN8dnx
,?Fn*A.
Ge/6!`
E(, 2d}
]BjN*c
7`RVtW
,;BFz4$
zKF]^%
HNT"A.
+]q%X[`.l
O?`"D>
=Stk6;
5$WlnMu
WwZ@Tp
s2i5A.
JA.ag![
O{aGZm
9zKusOSiP
=Hswgj
)ubx;-
Ba_13#
MHjN4m
KjN+d(
-@=QJK
J{/:wEO
T59(,B)
I.DJ4p/
4qpsj.
}zlSNkuS
I.E9&MF
.;VeCI
1h^,0?
DH@U
\;hk0Q
L4mNal
/6!`jIR
y0SeXr
!~o)Ze
Y~@Se2
Ye#Nl@
P_xXej
MZ2wTe
Re7\!/2
JWenU"
ArW)0*&
Pe*{&6r
OUe)Tf?
Ue_Zbg
[s[t,BSe
Pefe+t
nyXh^DC
hSEK@.|
{BkNAz]@
#P`S
2-<hk7C
TkN'`<
IoW/hilm
6CjnEV
CBimDa
YI]p`k
eR59),^g
.7:IzU
wSc;e~
t48VZ$
m(I;~a
+Bt.FkN
4_B@|y
epQmVa
qpsj&3
(U^ci~
Rt5S~a>}
3zSueB
ova|eq
_gD6aD!!
03*EeQ
4hnxdx
qpsjH#Y
!1hec?CY@
Nj%p|z.
Zx|,t}
)zs6?5
N2!|uo
DEYJjM
UI>BlG$
`2C.^d
W%\|OV
!103*]
)XfzGA
nyXg!2jN
/39}r7
6?,1D}
$8qljFJ`G
XBjN=v
GjN5nQ\a
N5:!`
\$-6O^
Tps.1*
4'w<ZI.#7|l|
LjN5n2
/6!6JZ[?
pnJNdK
Xa~3x\n
b;jN'`
JC.Z^c
2-<m5RC.
{8z6f6
G,='qZ6
jNjNC|_'
PjN4mP
geAE[B
7K<"B%r
ovaLY/
103X!%
VDu@2b
C.@F8Vu
x=YKJO
`6jN1j
"i?-:%
103;PX
QOp$Hl
; Nr@K
4AD=23
h"SjNM
PjN:sT
KGwXzz
rm|Ore
M>jN.g
<?jNB{
Fh,>1?
K~a>><
s3r4:~
nyXo8o
J^.qrVY&X<@u
103*Eh
qr:+@Yh
4+{@^Y
CNa 2=
)5hEI1?
.4>(_x
4;t <G
rm|zC0
MkN>w#.
OkN>w;8
2S^gl7_
{bLRB.
i1M/:M
kN8lP>
H+/"4fo
^/:j\k
PZFrP4
^5:Kpsj
AyL>Yf
0imtVe_n
103*Ef
/6!`fJ
;JkN1jM
R*B.=A
/^A?{k^
9]a1}H/K
NHrFwx
jJB.6<
3>GL'G
O[/^Au1
B.-3Qs
_jN>w;
*Y<:vaY-\?
cm-oMZ
_CA@,H
_b%p}:[
103*Ef
E}RVlS
+jEP@lX
6t"%??
J7o$D*
\=rm|O
WPvO2N
Ga8Zwtg
D/A0#K
$\2=.p
9rji|3
S+=."(
nApS'+)
=|h%/g
U8<,/As|
fW_~]G
)pMfC/
OnN@y%
m'3nNy
2#.Zn.
c2aD!!
T\04h;
$NgEZ1
u]-c$]
jhDH^E
eFnN5n2
03*E^9
AR=.:r
0i-QnN
zUZ=A14Fx
LB{?SZ
<`H.@v*E
X;?/2Dv
"[mnN
I8No#.7<C
(k%erWY
r>rIpnJNdK
?EOYfLV
fq+9nN
fS-]Or
1;iXqpsj
<nN:s
f*c'7~
5$Wi2]
AligCG]D
L:sp!M
/6!l{N
%8QAVya*l
!LIG#'=$
`CG7:L~
|$]C@R3
103hWWA
{CCsbg
%ThCV%
kF{e=
311/L_
F9=+<.
2<.eko
nv8@^.
x[!;2<.
*Mh4Q2?
!`s-YoN
:Hh3W2?
KJ<._eW
;MWa1j
L>w;Kk
HoN-f*
4'`$!z*
YA!%zS
BN+<.x
t<XA"{CH
y\`PSe
5$W)M+<.
dw<.DJ~m.
9cuu1F
SR<.dj
?h'z2?
7cw[Bh
&U86rXU
dtkfQR)
g{V$bl3
VHoN#\Bn
8X;<"5Q
Fr,+tg
o.J+103*
ukV!:K
:1:#c3
Zzkd]?
ir)7^ n
t/6!`r
[t4>sy
oN%^"DO
.9ik&m|
(zdI,RM
<@i((K
;`[nvl
s-HoNR
Q48,>py
2oN8qW=
<.(`oR
GoNB{a
6B`qA_
Ovp|PT(
IUssGY
WwX yZ
4$|8}6
'`F8nN
03*ET/
LJ&*@'
!QGu1=
CnN/hN/.Y<Z
Q_4VFzS
KSqcc7P
+3QCCa
R?.U=6
])>][7;Q8
yM|_3Q
7m9mX-
HF"&<#
(_,8d;
+1fv~r
B-tWSc
n%W?u=
;G(l$c
B$~aV"
3Qr+bmo
Kms7?z
n7sk X
U7kL/"
~UQoRj
rP!#%V
j`X t9zz
FqYXehTr
E**-Wye
@{=}md
od%^Tg
KO(lIR
OtsA'(d
F214ki
"0kkt,
Hc&OA_
`-FB/^(
X5-5l/H
:}y8!}
Vi~th
JSZ[E
3T(cZs
@l9@o|
*Y\mf3=
"pXHIf
Tf]fZf
GetACP
<KERNEL32.dll
RtlUnwind
GetVersion
:GetProcAddress
GetModuleHandleA
RaiseException
HeapFree
PGetOEMCP
ExitProcess
WriteFile
SetHandleCount
;GetStdHandle
7GetFileType
HeapAlloc
HeapDestroy
>GetStartupInfoA
HeapCreate
$GetCPInfo
VirtualFree
GetVersionExA
VirtualAlloc
GetCommandLineA
=TerminateProcess
HeapReAlloc
)IsBadWritePtr
MSVCRT.dll
3GetCurrentProcess
IsBadReadPtr
IsBadCodePtr
7PSAPI.DLL
GetModuleFileNameA
LoadLibraryA
@LCMapStringA
(LCMapStringW
GetStringTypeA
GetStringTypeW
IPHLPAPI.DLL
_USER32.dll
WideCharToMultiByte
ADVAPI32.dll
SHELL32.dll
MultiByteToWideChar
GetEnvironmentStrings
]UnhandledExceptionFilter
FreeEnvironmentStringsW
GetEnvironmentStringsW
3*FreeEnvironmentStringsA
GetEnvironmentVariableA
SetUnhandledExceptionFilter
Safengine Shielden v2.3.9.0
/6!`X-
KERNEL32.dll
MSVCRT.dll
IPHLPAPI.DLL
PSAPI.DLL
USER32.dll
ADVAPI32.dll
SHELL32.dll
GetProcAddress
strncpy
GetInterfaceInfo
GetMappedFileNameW
GetWindow
RegDeleteKeyA
SHGetFolderPathW
997www
rB:8.8;q
>9..8=C
T-?DDDDD6Me
T,3<7%
(3410!\k
yPRWxtXYYZht
RPJHPz}
"zzz~}
ssVVnYvvxer
SVsy}}}}}}}}vr
Gctzzz}}}}}}}}}zWq
Vzzzz}~
~}}}}zt"
Vtty{X%
Twzztt
;'00*/
qXXoxypY;n
`^[79T:N]`w
e5k}}~}t4_
-Q1ABGCRzr
@FHKKJJD/
Mbfd\Z
{msZ1 !
ZURs) !
JIB{) !
RIJ{) !
kac{)$!
ZQR1)$!
{us9JEB
{y{{)$)
{}{R1,)
{us)JEB
sqs)JIJ
kiksBEB
{y{)Z]Z
ZYZR101
RURskmk
smk){y{
Z]ZZc]Z
RQJscec
sqs1kmks941
kmkBcec
JIJ1{y{s)(!{c]Z
cYZ)RIJ
REB)1$)
{qs!1$)
{y{Z)$)
REJR9()
ZQR9B89
k]kZ1 !
RIJ1) !
ZYZJ)$!
{qsR1()
cUR!B89
RQJc941
JEBs989
RQJcBEB
B89)941c101
9<9Z941)
J<Bs1()
ZMR1cYZ))
JEJBJEJ
ZQR)901
RIJ!901
ZUR{B,)
k]Z)J<9
cUR1J<9
981c10)
RIJ{RIJ
JABk)()
REJ11$!
ZQR!J81
ZMJRR<9
REB)B41
Antivirus Signature
Bkav W32.AIDetectMalware
Lionic Trojan.Win32.Generic.lIx9
Elastic malicious (high confidence)
ClamAV Clean
CMC Clean
CAT-QuickHeal Clean
Skyhigh BehavesLike.Win32.Generic.dc
ALYac Trojan.GenericKD.74107475
Cylance Unsafe
Zillya Clean
Sangfor Trojan.Win32.Noobyprotect.Vrg7
CrowdStrike win/malicious_confidence_100% (D)
Alibaba Packed:Win32/NoobyProtect.31f427f0
K7GW Trojan ( 00481e081 )
K7AntiVirus Trojan ( 005239691 )
huorong Clean
Baidu Clean
VirIT Clean
Paloalto generic.ml
Symantec ML.Attribute.HighConfidence
tehtris Clean
ESET-NOD32 a variant of Win32/Packed.NoobyProtect.M suspicious
APEX Malicious
Avast Win32:RATX-gen [Trj]
Cynet Malicious (score: 100)
Kaspersky HEUR:Trojan.Win32.Generic
BitDefender Trojan.GenericKD.74107475
NANO-Antivirus Clean
ViRobot Trojan.Win.Z.Noobyprotect.962560
MicroWorld-eScan Trojan.GenericKD.74107475
Tencent Malware.Win32.Gencirc.1419b90b
Sophos Mal/Generic-S
F-Secure Heuristic.HEUR/AGEN.1348656
DrWeb Clean
VIPRE Trojan.GenericKD.74107475
TrendMicro Clean
McAfeeD Real Protect-LS!B36366F4A279
Trapmine malicious.moderate.ml.score
CTX exe.trojan.noobyprotect
Emsisoft Trojan.GenericKD.74107475 (B)
Ikarus PUA.NoobyProtect
FireEye Generic.mg.b36366f4a27987d6
Jiangmin Clean
Webroot Clean
Varist W32/Trojan.DZQ.gen!Eldorado
Avira HEUR/AGEN.1348656
Fortinet W32/NoobyProtect.SSSE!tr
Antiy-AVL GrayWare/Win32.SafeGuard.a
Kingsoft malware.kb.a.1000
Gridinsoft Trojan.Heur!.030100A1
Xcitium MalCrypt.Indus!@1qrzi1
Arcabit Trojan.Generic.D46ACA53
SUPERAntiSpyware Clean
ZoneAlarm HEUR:Trojan.Win32.Generic
Microsoft Backdoor:Win32/Zegost.DU
Google Detected
AhnLab-V3 Trojan/Win32.Agent.R102129
Acronis Clean
McAfee GenericRXAA-FA!B36366F4A279
TACHYON Clean
VBA32 Clean
Malwarebytes Generic.Malware.AI.DDS
Panda Trj/CI.A
Zoner Clean
TrendMicro-HouseCall TROJ_GEN.R002H07IB24
Rising Trojan.Kryptik@AI.83 (RDML:+YhEykvzG+XHISG/rAh6kg)
Yandex Trojan.GenAsa!V9qRHIEA934
SentinelOne Static AI - Malicious PE
MaxSecure Trojan.Malware.300983.susgen
GData Win32.Packed.NoobyProtect.B
AVG Win32:RATX-gen [Trj]
DeepInstinct MALICIOUS
alibabacloud Trojan:Win/Wacatac.B9nj
No IRMA results available.