Static | ZeroBOX

PE Compile Time

2024-07-30 04:25:37

PE Imphash

203d63d5d9a088e2d84cef737227986b

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x00007f66 0x00008000 6.14995580811
.rdata 0x00009000 0x00002230 0x00002400 4.6398875295
.data 0x0000c000 0x004f13b8 0x004f0000 6.48617749969
.pdata 0x004fe000 0x00000180 0x00000200 3.05237006283
.00cfg 0x004ff000 0x00000010 0x00000200 0.151271325305
.tls 0x00500000 0x00000010 0x00000200 0.0
.rsrc 0x00501000 0x00000348 0x00000400 2.79480904539
.reloc 0x00502000 0x00000078 0x00000200 1.43377001429

Resources

Name Offset Size Language Sub-language File type
RT_VERSION 0x00501060 0x000002e4 LANG_ENGLISH SUBLANG_ENGLISH_US data

Imports

Library msvcrt.dll:
0x14000ac48 __C_specific_handler
0x14000ac50 __getmainargs
0x14000ac58 __initenv
0x14000ac60 __iob_func
0x14000ac68 __set_app_type
0x14000ac70 __setusermatherr
0x14000ac78 _amsg_exit
0x14000ac80 _cexit
0x14000ac88 _commode
0x14000ac90 _fmode
0x14000ac98 _initterm
0x14000aca0 _onexit
0x14000aca8 _wcsicmp
0x14000acb0 _wcsnicmp
0x14000acb8 abort
0x14000acc0 calloc
0x14000acc8 exit
0x14000acd0 fprintf
0x14000acd8 free
0x14000ace0 fwrite
0x14000ace8 malloc
0x14000acf0 memcpy
0x14000acf8 memset
0x14000ad00 signal
0x14000ad08 strlen
0x14000ad10 strncmp
0x14000ad18 vfprintf
0x14000ad20 wcscat
0x14000ad28 wcscpy
0x14000ad30 wcslen
0x14000ad38 wcsncmp
0x14000ad40 wcsstr
Library KERNEL32.dll:
0x14000ad50 DeleteCriticalSection
0x14000ad58 EnterCriticalSection
0x14000ad60 GetLastError
0x14000ad70 LeaveCriticalSection
0x14000ad80 Sleep
0x14000ad88 TlsGetValue
0x14000ad90 VirtualProtect
0x14000ad98 VirtualQuery

!This program cannot be run in DOS mode.$
`.rdata
@.data
.pdata
@.00cfg
@.reloc
uKHcQ<
AWAVVWSH
[_^A^A_
t.ffff.
fffff.
UAWAVAUATVWSH
ffffff.
[_^A\A]A^A_]
ffffff.
AWAVATVWSH
X[_^A\A^A_
fffff.
fffff.
AVVWSH
([_^A^
AVVWSH
([_^A^
uVHcH<
uZHcP<
u!HcQ<
uVHcP<
upLcB<B
ffffff.
AWAVAUATVWUSH
[]_^A\A]A^A_
AVVWUS
[]_^A^
AVVWUSH
0fffff.
@[]_^A^
AWAVAUATVWUSH
ffff.
[]_^A\A]A^A_
AWAVAUATVWUSH
#ffffff.
[]_^A\A]A^A_
UAWAVAUATVWS
[_^A\A]A^A_]
AWAVAUATVWUSH
8[]_^A\A]A^A_
AWAVAUATVWUSH
8[]_^A\A]A^A_
Argument domain error (DOMAIN)
Argument singularity (SIGN)
Overflow range error (OVERFLOW)
Partial loss of significance (PLOSS)
Total loss of significance (TLOSS)
The result is too small to be represented (UNDERFLOW)
Unknown error
_matherr(): %s in %s(%g, %g) (retval=%g)
Unknown pseudo relocation protocol version %d.
Unknown pseudo relocation bit size %d.
%d bit pseudo relocation at %p out of range, targeting %p, yielding the value %p.
Address %p has no image-section
VirtualQuery failed for %d bytes at address %p
VirtualProtect failed with code 0x%x
Mingw-w64 runtime failure:
__C_specific_handler
__getmainargs
__initenv
__iob_func
__set_app_type
__setusermatherr
_amsg_exit
_cexit
_commode
_fmode
_initterm
_onexit
_wcsicmp
_wcsnicmp
calloc
fprintf
fwrite
malloc
memcpy
memset
signal
strlen
strncmp
vfprintf
wcscat
wcscpy
wcslen
wcsncmp
wcsstr
DeleteCriticalSection
EnterCriticalSection
GetLastError
InitializeCriticalSection
LeaveCriticalSection
SetUnhandledExceptionFilter
TlsGetValue
VirtualProtect
VirtualQuery
msvcrt.dll
KERNEL32.dll
6C^GF^J
>0+/.'1<!*?
2W0G#4-
;'_)V
&A^%/?:!:=[R
5$;#*2W3<
B'?8_
-$)V"S
(E-<_'"V
5 8-%T
6:&\D\E
#)-DB8
[7 =^J
-+SSF ^9.
):M!U ,=
.TJ_O]3$3K
'5E:Q'I
V^B+4
SGKM9&6
2W0G<)(
A-+SSG
.4X/*>4R
\%E';
J<;4 -
F:;(
83<+9
!)-D@5&^6-
H%'+[=8(G
:;9:O1
Z_4V8FX
TF)68F6A&
* ,0GO%;
^3=[R#
^,W4K
3>A?^R
/^%$6!
?I'1/#(
*K7=[
V<45!Y
U/>)(
61<4"8
Z,"-E'
S*7DX
63$1^5
+R7>"-
-%[!'3=2
@^A'1-
9_;#UW 4
+'U@#5E
.VFB\Z)7<
REF!
(U86/*!4
W8<^!YE[
21V+B&6&
@_ G[.
-;W8C9<
EE^WL.
5N_ZV
2:"^]?
+-M]38"2^R
WV:6C
1V+BZ6R6O
TF%68\<_4[Z
<+'9YR
F:(*V?
X&_,V;
'$$884
)*J=\#[-$*W
5(8)!
#\/#O=B
_:W+@WB">?C
_O8,/+@
BTEV#5(
Y3$=(+_
+:REO08
'&\D3$?-
]7SX-+%%
BZZ<8=)_($
Z&EGX7
#SV!<U
\5525-
R3MB(HP
A'))?8(
39<4)V
L0?G;.
:9=25=
1W4@A:%
^^C;!-
K2W0G
YR;O)0
3:K#W0G
6@$B<
8=T #
83<+&):
/;R40/
%)"B(!
1X[R(+_=
A;'7:0
-/;^+-3
*E?\10+
-$)QJJ
]_(UV*
:#HT>!P
8$^1O/ZX
@^LW9?
8(M"(#3
? WX%
":2R"X[R)<?H
BZR<>!1
::#4/(9? #!
:$<>4O
_;.&^!SW
-+S#$0>*%&P
<1"+S?
8=^L](
/X8%_+
@9^!Y59Z
A&>3&)44;<UZ
*;WH-91
"<X#-
@^ 78K
^A&Z'X
%9)?*&
F";*P<J
+/!"?*
=!W]5;;
1V+B\Z9?
>&&@9^!Y5=[
&G/'$$
T3>"H3<
!W]5;;
*[9_+,=
BZV<9-)C($S
_5=%--
$K$_=:V
8GT"ZI'
$M;Z9I
(=YC;8
4_.ZK"
#?H4""
\ZWG9$
2#(B-=
J(;5@S:-
(=Y<8W
(=Y<8W
U1>6-,
&[*8E[_
B ?6+KN(
1V+B0[61EL
(*)*J$
%++*^.6
9=K!U#$
@T<><1V(
-+RMD=4
-!I7K5
\/783<=
I )-D6%X\
9T6T 0
B$0/*9WR
@_948J
4 &XB1>"-$
32W0GFC-
_5$93$*$
-9U6.Z
8F<.;
71'Z);)!
#8-(+UB:>
H#6R;
(1O)^8
[R),TH
I"!*3(
\Z9,+@
,-$*^Y
.E-9-D
(^(+BC9*
:"Y")$
?;PD>P?
2W3[C$:
*1<GCU
8>)D-
1R7F/)9
[E&I!Z2
FBO?V/84?
^>J(;\
<;&CRA0;%'
]^YU46
YE>?;V5&
'EA9)*?
$96_*'$;5
<#'W!;
/07\A25
?E^$#
#VIX)%
,3[C$T
6REMW8#!,_5
+>-$)V
_6-DB
-+S>+
3"_?^9
=(F*#%
;\=8&+
NV\<*H
:ZRM I$C
"#41V(
:ZRM ^D+&
/?+2W0@%$9Q7
Z'/83?
^-I1K
*X%6-[
E:96\?.'(
0_LW9?
..F(2\
0^"/?K
U3(0'I
X'Q*#\
$6-D;
5G[B$M
?*X)<X[
5C05$Z>-
P;342$
T; =C(5Y
CR=E/5E
9 H9\.
''FF:8*U?
U#M1#(
^/P83<=
&-D6%K>
V]'6(_
+:RF/2
"W0G4_
0"6C"3.
=.=W0G@9WT9?
(2^?1Q
B-+S>+L
/9^7XX+*<
28,0G.1
CW%<5!Y
=U7B-+R
O(I)1GG
%'H+I"='3(
E?L83>
K?W0G.
[U03*0 2
A^C/%=
/65 "55
67D U2Z
&-IE)1
1Q$M5^3
6-CC_
9^7X7+*
#4:)2R4GG_37
^ _>X[R
1V(MX84(
+9ID1$
XI*=A7'3
.WC=5!Y
.VN1V(
SA= 6/
WFF-+QU
B3%_)VKI!H!9-D-
"3B%'/>-[R
)V"S1#
)V"S.B>
#E!6V\
2K0?\?
;(_1"\
,,";>;9
9'4)V7/+=
-<>M';R
"8+_XU',
,"_>;9
?(0!T#V
'4)V7/+=
"8+_XU',
R/#'09$-
R96 *@
?(0!T#V
9'4)V7/+=
-<;M';R
"8+_XU',
1O($/(Z
0#$ 3!
5C05$/9=
V"%B'-
++E1$Z
(6G5)P
V2W0@%!
(6R5?I
9-%)#!
7-$)Q*
-+QTD),[
!Y8%Y3
X$$8>,4<
78.4)V=S.'.D-
V]FYBW*
.=W0G4
,!=;#+9
-5=C45BZ X
=_R<W$0 $-
#?H4"%
2W:G"!
\VWK=4
A["J0'
$I=7(G
;S'B:)(
-4)V?S1*%A(D;B
2W]5A/Z
G^.I.*
0@B?00
:TDE'))7
^!YE,Z
TBE-+R
Y@?>55
+:#&!,(+?>*
/ =!=!
:Z!W%+,
^ .9-[R
8^:RG 5
?/R1V(
ZU>\5
(7C/K_
?_:"&!
#<GC#X<[1$
/T_Y-
-$)V"S1
#!P)2_!
Z =AA>
!]<0$9
KI,I6C!
Q&<[M'*8
8$AG0+
'5:628
EM,H6C
-/+^B-,I
V]'6(_
63;%EY
CG!2!Y-'!1
@E[.+YJ^H
\7#>0<
;2W0G>
2<GU$
0G@9W)<J
;$)V7/+=5
GB.?8_
V\I_6'4]V8
GK_%!&
#&JW\8#=
-+QTD,
UC:5!Y1
,%YC9_
R?<=;(
T8:5!Y1
/%YG9_
BZRP+@
%$'&;V\
J]8&5=
J<./3\
<56<8V<G
]I,I6C"
=[R(+]C9<E
[UV ;Z
83<=!=!1
)<^I"=
"+?J1A
1V+!8;
A;H0<?
(TD BF>
6C"3;%E8
%'H+I%-!3(
!>!=X)
%'H/I%
+:^G,049<=
2K0?A8%
V]'6(_
9^7X4P,,
."<0G@
C=)@$W
?542>=
,<,2W3&.
%'H+I%
-+S>+L
R+,*0;$-
9=4)VK3
:^!YGX
GK7E!)
ZW4T8^YU
<#2W!>
[UV,#F
_+X4-W
-+S>> 1$
C?9X)_
0M5^3<>0
3\^6">-
8_,'?
EGAXL8,
<!Q=&
AS!-5D
\%/&*"
8 -D-
9=K!U ,
(U$<Z)
"WV1V(M"
5Z[U$O
'8#&+9
]ZXN!:$
F-< 4=
.?_G[4W83>7>
_'6-D
6.\4#7X
2<3[B<:P+/
7A_EU8CZ1
2W0@A"
(=Y<<4
+ 1V(
(D6-C#^%?
#-+SSF/^16C
:K]%=[
8+? GK8O
;(_),X
?__:6!
67D T
<12W0@
E,583?
6V.^
[R;O+8
S .-$(
#6,_-
%'H/I'
%<\<=H
C=)@?,
0M5^.S%K
RG;-+R
E=ZU3(0=I
6-CCY0#
($6-C#^%?#=
J8I%10G
M;Z9I 7
I_IPT0G
[R;T\B&/
($6,G
:ZRM ^)?&
#?H4""
\ZW4=
$6-D-<
:ZRM ID?&
M;Z9I 5
:ZRM M9?&
<;2W0@%$
M;Z9I 4
J8IX14G
!X[R;T\B./4
0 ;).
.-$)Q*
#?H4"'==
\ZW<=$
M;Z9I 7
+ ;#OC
J7/C<5
=+(7-_%
-+_3#
&PST5F
!O992%SG
-#9=Y=
'C$*>=
[A_4!%1
X[R(+_
O!?]Q6
[GZA0,W
/-3:'!H>7
.<7_?L
!>B$(Y
KP"'*
.&(568
/<,*-
0) (+T! ,W
(7)68F>%&
5FXU*
(<^4!<,
# '6-^
9F<0;;
18=#63
(WE@Z+< !
1"8+-)
/;;)\?
^G"R#^5
DR2;_!
2W68X4.
2W3,2_.
V))&<66-*
6*+1; W'6/
108#)$ 2
V+ 6,=:<VV#
7L";:I5
/&#!<8-
S%0*V1)0S>2?&06
3/3.(#?G!%
&?99?=<V%
6ZZ1#&
".';;17
/) 5;$2-
0&>/G"
-&G,4-&?:*
502X"9+<4+
'/>5?!*<<97.;
$'6$<$,(+20
-$)VM-
) 2!<+
.:"1)74$@
1;V3"%
0)5B<5
7*0""4?F'$+
0#=""19_?=
1;-^5 :
6/".;?3.
.203:R5) *5?,!91
/3&??$
+;%-"05)
:&4(#=&5
F=6=&00*7:;#
=1\"(6;V3'U
5-?$N2
7 4=&63*
V+,&(8-
2%1(#1#!]"$
? 6>W%&>^
5=/C,5(7/)
,*% ,4
*":^;>
>>0?'5;+
%1?2(<',1
&.#)<">7
#$05$<+;/) &
2W3,@4.
G.C_) N)
>-.-V4
V?<6
R9#<@
RD057S
8RJV9^
E-/ZV9
-/%V;J
-D>519
F-*-V8J
)D%51Z
!D'%2S
3-/ZV7J
2-$ZV%?
!D%%1.
8R6V>7
V ?%6^D$51+
8R6#?$
8R3#??
0-&ZV%J
VD/%0(
$R V<0
1D%51
2W6 @$-
!B4)V
2W0:@_-
2W6<@_-
2W1<@$-
&;4?C 1-[R
O%7+64
>.)-D-
6/18++$
>*(Z=2W0G
)(8Z 1V(
7*3^D-
*6#,?;9
%%83$+##
-.[45^$$B-D-
'.8Z*&B<
,18^+#%
1<>33X
,.0?25-
3"0680?
#<@)+#
'3'>2%3
%5])*9V0*
&'+/=/
]8+;^)
'48:57)^
83<F+8Z6/
1)-D-
2\5(;"
[%-_?8
6)H-^1
=_I2<0
2741V(
61;-813=76
:=#+%?*)
SJ37Z>2
>(O1V(#X+9
%C$)V4K
2W3 A4-
7 -2W1
C4)V8IS
B<A6/\]F
6C^GF^J
>0+/.'1<!*?
/6'>(2
)7^(7+
_;/4\F!-T/<6:.8^3!
?\"U5FT@
6'>(/Q
Y5-=9 _+;4\F
$%&O5"Y
-$)V<J
D9(57+.S
SB.'>H&
=$)>"F[
Q]6,":
[\+T(9
E2\K49D>
HR6)36
)K'7\/"T9
/+(.@1
""(%+Z
H8+FY&
,/H626
#O59\#?<>
7##5,;54
B96.9#Y+
0AE'(Q
5H/5:@/]
?(E 5!8:
'TX=9.
/:T3$9#H
)C2,B"J
*3!09R)C#
C/8 ?L
X2Y;.#>
5A:$VJ
X6UB:.E
Y#>0.
]GW?%%\$$:
!%<Y->
4*A]<6
TB-(CF+
"13X7#H&N
0=3\91%9
%" 8B0 E
*Q2?69>
_%VU""
6<. D(7
%E*)(+ H3
122D]5!
*;RC,>
_RV(/,
&<5(+0
E&2']('G(>
0MB+-VJ
(#&&<;&H
<0E1G6
J^_'4%
O4612E
?Z+(9-[
+%?>?=
+$_6Z!
9.$4Z.
_+R%1,
%%:T!=
0%W*71.:GMA
%EY&[?
#P1D;"95!
^%!"7#
O(Z_,?
;9,7+;
<C.!C$Z3QW'
?]*_]1M
LN#.@(
>^B%H-%1^
)8"1(_E/
/FO'G(
B/G_K"'
&1>&16+
5I($2?
!A75/V
:96\?.*P60
\22\+?6#2
CG=)S0H
H6=0,#;
1E?)_>(
TM 0"
Y@*)I
?46<YO
E8=!^9 ^
'0/<),T03$%
SN'TF'K=
]A 4;,
WHC"(?!
=)6/*(Y
O=K*,Y['
" ."1_
/+?T<
-), *_
):J)<P2'_
6(9(EV
Y%0Q0;9"3<
R+W^(;
[S8, ?T4
10FF$/
$]=V1,)
Z6:'-"J
C" L<
!H;4==#&'
!>\/F_
P9*.A.5>
!++,,$]8
<XRJ9A
U:_A<>
]*!W*DX
!"-PK,
22"> [8
W)2'6;
3[$;4(
RG9W4=7/?
10!.^K
Z#?$O1V$[:+
F &$:"
$.&_"=?%5ZPG
1![*G 8#<A
A%(75BY
* !'AC#:(5K+$"E
C"#<#.-6$
B$4!.DJ<I
<\X"$$ T
OYZ5+;
1/T!_GS
62<+13
](>^07(
L%7>ME$
A0A"E)[EFA?
WH/>>F&(
2P(J,B60T(
)0;2#4%<X
,DEAC&0
(;<Y#
)6[C^:
*!?0S'*#-<2
@$R24*,'
W'4,:=9
0:8%5;>
E;60:5=X
".$7!@43U7
%3A5 9>$
C%378 E:;-8R
_#(P""
Z7=?W
$AJ'E+
4D?Y\V30+[
W'.7'=Q8
2KA4$#
G#+V'6!
_.[(5,9
G^['Y4
9U0D&_U.
%0!5+I<
I6>4.&
:$59A-
8;;VKDE4' *>#$Z
,C5!MG=4
52[9/$;
1'7;C>
7+IY0\
$ U*@!
D-;/7/XS
!.4.KE
_4T+Z&
)8 !YS)
#2B=#?
)&\H9<Y/&
4?^(G.9
;%>?>-5"
2:-)2$"
FX(1S8?(
2E$8_L < $
D*)C&J30%8(5
[!)<*!>3\
82;'8/
"ZDZC=[
4)<$3
5T$&F9
B0 -T'>$)^R(
PJ7,%8:
*#6+W<=
$!&R0K&<(;
?!+3O$A!%
69E8;
8!^S"%
50?488%.!&
6C$W /
6$/"4"
('T%'H'
:\SWDW
=.$_5)
<._I>F$D !1RY+(X7
K;D-=-
>GM59.
23S#"\6
+G:?9.1
@BY$,G"
7M<5$^D.
,?,#=>
,!! >%
. Q!!"- I."J%.-
RP&(0"
K!G]GQ*
6&%5B!
1$ )6R>
0$WS(R
&59:F9%
5T$<X04297G
;;5T$,
"?T,&=
R >9'1V+S
/-<./-
67Z"97
?<74[-
9;UE2YU
"6BW72*E$
N-RQYO
<!=8#,J
3/0) 8
TUH]4<H_-
=$BYH"6 T69
=0@<C
6#%6/*.<7?
/]>:>%:0
:S_[&-1
9;+X-
9"-(/?
!,$.UE%#
3#!2]0
[#"!VF
".;5*5.
VDC=#]B
>$!==V
2Y<'"-P
$J;?'
'=566
5@!9U8
:"]>./
!C6O[N#
3C9(7
7L%=:(#)U
4M>#+!0
!5?L!.
>;3:.$4
5=L=+6<
/D*95C
+8WR_#90@
%('>TV
WY+>'<
W3;->/
))9)1Y
^)<#;[
$8X;68U;+'09
)?+84A
$3DC-$
4L7O_:_:&'6
WJ\O9>
K+7.<_
76C)\6*W
2$8C<K
+?V5&#54?
F#A&2\5
Z+VN'^0 =%;/
:\4R2<&A
6C+'7?(
%SW:=S
J $"=
)V;:<
0_$R).
DF;!RC
#D%9)P<
&AX!62
H_<><
&E:&.;>/C-
0T(VCI/
[$31-#
\?T!"*
O]SS!K6;
O\22:_
5)5<>.!5
37S,V+3$
]X[&*0
:;[A]4!
( GC^+
C_5!(?Y?
7[^/0
=]-;C9T*
<%$%ZR
G .I??!Z0)
>D6JA3
G/!3JT*.A5
O'2;5E:
;<4I;T
'09G>?
<#3G>+
2$53#/
9.*&U^
4S9:BJS
3&^3/
#,$#+M
FZ[Q@
(,Q0QU
2,H;>6
4XUUG!
J/61&89
?XZ SK7D
$"0T1"
7!T964
-]@=89)
X) X4.>
%"+$20
/". 0:3
_9"; ,
39:W= .
.9A]-#S
@E_0=4;4^
="-V1"$
A(4M(-(
0(A2;4
VH&# $
@-P@E"+
?5C1EN
0D;429%
;B$&%
/J:E!+
J']H4K81
<^Z.QZ
YZG/4%
-G V'M^>
O#6>)4
5$&5*$!
U=.)&!6
*/V
R=("V"
EAJY<1#+
B!39Q
\(-E2[$^"0*7-'.>
_/7:&Y
8<5<'%,
$R5D+,
T6)5;"
%LHB\*+
8Z=,R")
35='2$
7#5/^-
!.+#90'Z=O
@3>+=1
"@>_LQ
'PX /"
AF-_=,
4';R_#*
"+?<=$T%)?
%>) G
?.WH/WA
:9"*6#-
<=-'$
6X'*&8>
O9'%"A/PS;?
(2V%5F#D8E
[=R.0<
1**+'D
C><?0;
>#;9M'
??#SK0
HR!@Y<
N/D!G3
=5G(^
EG7\88!@
;O 0@T[
*1^EE>) U
59:8#V,
V+H4L+
Z_D5'3
4N\"3&
1.F]6+
3T/\2;
&-;Q\:Z()
^_Y=U!"?
2F[AT.
?X>.$F]B
V$Z'J*#
0'KF#
PY7Q#U
)AX>!])
$/6'*?
7B<W!:>A
5T!!4U$6_0
/G?!K'Y
6,:+!-ENSF8
&C$=AD
P<C('% '5
1=K19%
69&92Y
8'=^=%
3>RD;Z
:GD_"V72
"[7084)%%
'.1D3=*
2.4G,=
;5-4]
:>E0"&
"K1@.8RPB
.@= '#;
+;>9F9
..1B0)
!&*<_^"_@2
C>LAH.<9
=:%"8/
8-<*$6?
_30F9E
.#U4WT
KG?].2#:3
2<7(M[
:O!%_46V
Y6"="3E
T&VD=>X
U4?<W/\K=
9B'@&> 7
;M((&;
S&LJS<!,]5]Q@
@\U!Y(Z$0
D_#-#6
U7F2'=
ZA)Y/20X
V%1<!
:_#A%R,V
>#UR!
N71#S5;
>4&%!>
@- S^-7
%VU"R5
"4.I9< 5
H/,:-E
>$;<$1WS/V*
V:UE
"5W+7/T:G^B
E&/6\;:N
6[.^7&38
"V#!^J
X#9AK2T
.B>QE>=
;SG?)P
FE4>$;
]?^Q6.<$5T@KR<-=1A
:6-ES)
"&)40<
=8!Z 0@Z
S2=55;?;C&&&?_Q
>175G(5
= *&<T<0:6$(6M
G(15F)
33']T
6L$)>9G\,?6
<()4#T
>:80>
'B[!(X
7?9#@L#
'!Y&^E
V!7J0D.%?<
#+31=#,
6BCAC,R0J?
G"7X76
Z(*X,*
0&*+W(
1.KF58)VJ
<KX:_Z
(PYO8D
02 $0CY
V=!;)S
XRY>!
..:4S10#_
=]0;AD
9?"87%
]E"(8*Y
^!0%((8?$
C8) 13:
=2AS\+/U.
F3;5?#8
U:/4<S5
KR9" U$<
&"+==!
Y7< *B
>A/W:
F5LW1;K$@;9
E#)LY
LU0_I9
>1'++A73W
.*SJ,/
G?,B+#
/B&?8L
D5O -Q
!=!X<U
3]3D::
/)/#8P
9.$3CIQ
G+<6'+[U%*
667L$,
&!!)%5
68HS9;W;4
)=*K5G).
<!>,)8
S9<,+"]Z'=
!2!=4'
;S[T9V
$H7654-B3
!CX+;A
7>"GF@
50128B
,!&4?S,
E80 X
%9625(+$9!
:77=9#<
\)-5?
V!901IY9%
[H*/=5#8
[BUD99
8?7-+;
54;(4_S%C<C
Y?%7$@/<<L\
5M>)Z3
@9(?2B
"">-"F
V):Z,*
>3 999
2$H*&J$C/7T:M
W8/$%]=
:"#/NC5 "
D<8&#$
I6'"=X
V8!%>#*5)
#UY!F>5
("A9!J
\.5]\G=?
O1-3?+U%
]<!G)]
]S6#@.
T>5*?>O0
)>7X4%
#0P@16#Z-1M
?+I:<3H=;?@G
DC1 1<V$
]SW"#>1=
8:B!Z42
\0 [9*5
')QRE=_2)
Z!! WX
'S063
^-)387
6I;?U3
;5AU%N
T7#=]
./5/*/
DF;-3;
,A*I$&.5
'A+3S@?
V'W*+
&96CI7
_?5V?0
&#3\'Y
!";?%X=>
:@OCU(C
OG 6Y-
C,=A^"
!/EM0\&+
=A6^^Q
<86Z!C:'
';6-KE!S
:UJ9F&
:C4LS<3
@^Q48\-]
5!T8;
8R1!4F
/2:<$L;<
1T@L36
?+$-(5
;=^-Y,
Y3%*"2
["I35\X:&
>64B><C
Y5S%3
$&7=9%
(:0[<:
%A2)+I
/;! 0\7
-"4/#4
@T<!4)BN'
1/.# BXM
>WP00
ZQW# O:
XD)4+/
=V67T,&8H8:
\)B#*?[
7<?I:2
))4C34$ B
B.#ZQ?90
*7/;T5
(3</2S"I/'4A!
E94P9X:%8)
# "V(1
$&>(AA
43;-(E
7N:1&[
4*8<?"
*1,-92)$1"#ZZ
=+;=^'6/Q[
9&<LEZ=3
8+\#1=8(
7S $F)3F
7/D#90
4(9%$:E -
<9/'E,<H(@
;=)(Y;
>185Y'#
64Q'+K
9 6\5<-
+?6*),9
S4S8<6
J>* $-X54(?JM$U=
9<6/ -9%Z^-=
'/0=<@&$I4
/:,$\
M"T#>6
L5(1*;S(%*
%;;RE?B8
>=/9U$;-8-P
;#!:$\F#E$6R01T
OYC]0
U+3KOS
6 E#4
?(4:7.
V+8DU:
+* J<H5$. B
"=[:
W(>1J
-U6P&;<H%63
3^!'J-
G+#9?1Y2U7T
2!="!)
W6M'(HP>?%?
(/1574#'7
4(?'*E
3S<>]4V5]
-AI=RCB
#*/!$#U
! U C
8P?]+
1RG=;?!*<I4<9
@;&W!:-7C
T()]+4<)
9(,+7(8
GK65$
/3$9AS
#]U"[#
1>CQ[>*
VF+"=[5
8E?-8R.
+E;U 0+!W4UZT
<,C?<4IG4
E>'*0+#
;C?V*
I;F?4!*B5
9>#K_Z
@3%9'=N
&4^8 J^
K(X)U3'4
0@6:7C
Y-P 7'
7P2*!:
7Y7W%78
-G:_5<3'#P
&>D]7=7
U?(\63:
"HU"-#
[4-518=
=X%(<?4=-[
38](%9I?
35M*5--0C1
2(362.
V)*7!<?*=)
%)-[_
8G<9&A
1J79-V4#
KE&# U
X1'=.!_?
&4'@?Z(
8A4J"
8+YG'
""<0?G.1
&84Z1)
S6_Z//
0TG*_B
[R6<(&
+$&ZT#
("<96/1
L_*\(+!>
C5F,&*J
4$^_@
!6LED)A;9X
E '*684BB
H[/<'<
DZH=B'!6R(.-&
69@XC&< (
0"#)-'
^ZU?3]#
B-4W-U
K)7+B$
(<X$.5W%A
2]2:;<
7> V(Z$
V(=H"2C#%@
[//?>2E
]=3[:!0
-A<P)&)P*#
@:4?'@V
"!>]8/4?
#6]@&U4'
*<</
0<C B[AZ
:<$<V2
0*U3+J2C"%=>
9:5=",
)@\J"+\X+T
1:>2#83X
*[ #&X
:?1!=3
2?OU$YC=
S%G3]-+293?^
4.0)N;
Q$B8OA
3##>(7
[S5VF
XEY?S+!)E
C7*C<!
7B[.\9*D90
,!39$HQ'KT
=^+"V
?#.7(7
55\<#/R
O]YU)
45VD:5%
;,<+7<
.#V.8Z
<X%YV^T(
4?=''Z
$FO\.,9*D
,U04842$5
[75#$6&=
7228&\
%&=4*OY
@^WWF
!5$)9/
_<TU),
;Z-&Q.
(!?,?0W
.$\X0,>>
"E5:
*A,F[E
),LW>'C
,"GM6#X)
\+*#/Z
YH8I N<KC.A+
('7 @9
F"==-)VF'
+6.<]"]+M8
&M%6>%Y
X)2,<-
>[=8P<
1,2:6#9*R
O5+_U(
VR(?+5
+*'5.!
82+?"V
C):\!-
G8U9%FM
?,$-F#
.K/.!&
1+R8(E*:DT'-Y
0%Z+6"
= ZV7"
8$1G$
FF6 Z#9I
_>G<*:9
6B5&"1
*Z1-!0
6*E$L%
OULUE=
)RJ8S
R=4(!
74*=;,I\
'(+)<\
3E_]VX"
4*HX,H
>N"6*JS3
0AV9O"E-
4-5V7G? VVC
FA5\:W#
+!)C0$
V!G"NA
%.5)4
[?^>^3$<
A2B6',
T>+=W4
7%3+!D0;C
T)&!67;
6S#L(35
AWU"<"
?X4",+<%
;4*2S$
G2:J*O9%
%6K?=0)
4_[6#H:#]
#Q1?^Y 2#-KF4
A"'4[/
^>"]3#
-$:S*:%
:)6<^8&71
"0O.;>O
3F<) @&4
5Z&A"-
35N=52
$,4U)4=3
7B3O9R
9L?<%1<
A^>^2/
U49F$&0
9Q#5'B
68:%");3Z
('/Z+%
56/V[!
B !Y-,5
2,&A9\V
B?_6;
BI!?8!
2)5M-6U
>6P\I%B
:,-@+5W9
7:]'2J
, B4$11
M;4"1@0'%G
@8+ E8
=RV45Y1(5PO!
8!5FY>%%
\C9%!Z=
Y%N; T
*42"\KE
;W.JHV4;7
$R406<608R
'<:\<+
## 1!#7
(?]<(C
G#.WMF->9
U2T?86%
2(&R'</_#
/_!$\+#\=
),MF>M
T*K49A
3-4<8&
%3F05;#C-_!
^ /"6#
9-Y*+6>
6^3>8D
$$'(Q4
#_N>"Y
A-$);
%2Z3&\
% 5S!9
#VB:&+A
Y/S8/#4A@6^E-Y
%( 2J#
&O?;21X)
<+K%4$0
7C&I=0XKF6.!4
':/$T"?I
G+36$#,2
+^<[&&
%U1GN:
I9P78B
?"RT&\$!
:9Y0,]
?GWK_\$(
V;6">X\ZR
; '\:A+
$;6(2
4G GY&Y_Q
>:*VAE
^2%0NR_
[@Z!X_
L</XV0
*H+?#>.9
F/0[&>,%
'<<&R/UG
/'U">+0+.>
A./K!&
X3^5%!X_
'1$?+6,J
A*C><+55
%'5AA"$,54%BC+-
*2:<F#22
N2(E4)
%2; ]2$,
@<'@B%5H
;'7/1V
UZH=UE
$_(2)@
59,"3,
#1AK"
#TC/9)S;+;2&
?_:_4%83\0
((/1"V46
;&1E
EA T1T
9< ]6 &
"5(R
_-.(0SB
^ _8$5$%#Z^
.#8T=/E
^A"W24'
I_#F0&U
%B$<(Z[
00Q1.;&HT
1_>"M$N:>@B U
P6;/5
=?U+VJ
1;FX:*
DM\^+^&
)#_7
(<97*-\ ?
AE('?Y )";C
=U=?4/
#8=\D.#'!2
9,A)&>>&%8[
R<,B[?[
7#(D.+
E:U"0"]G
C-RW?I
G.A':@
?/4*'^
U!3D4
]Y#/(-?^?6M:
$C%)DL5
7+"5D.&
5"2YOP7#
="?^(
=3'"^"8
Z<*PS=
U4 BTHC,%)6X;
=..S1!
=#;',C&
&68<._, G
7/?QVF
:$7G$0=
59^)UO
#">&\_
A4?3=851
#V9!J)
V<L%E[
X52,36*
6>!F3X[
'7*=B'
0='LX
A$(<3
%]B>U4.
.R45&PC-!#"1A##&OB
> C;)6.'+<%
"/)<:C16'
&?5?EN
M8901:<G$C
<A@2?P
I-J<79\1G
/4Q0P<HC
6&\*%2
H'H5=2G
G>?!!/V:2$
*!"[62R1B
'0_2["
<?,5;"
I?A],A
$<,%B)
=N01(&V):,?#
&_\-6-/4
#259)6$'6
$4<(>7
*E.71;O
D?U?'AWA
'61A/43
8#\>9&#485
;8J_(
]I&Q46
I6*RE)#2!
82&R4).
\$^<W!+K
Q&G#"$
#VT26I
!<6Y"?8O
$()S!7,*#
)%;9[-
8>C6!
<:/!:"
A:? 7(0
?A$>;4
% T.)%/
K;$)E$#
GA9_95
!# )_9%W+2
$'T4;#
_/2^&C)<A
Y(93++
-;>24;+
1[7%4Q/
6G; -*]
)4V;"
*_6&@
<QSE!PH
E?YU4% U
((9($/
;)5>&I
1'))@&3H
;'9)IF,
/TDEA-
%0&L>4"
1.%SE=
*$\0-#
Y,6AF9
XU%UA3
18F$$L,VF
[(:2JG
&7_4-!>&
.?YPP$=
@9:.&F
7IR8.$#
8;#6N7 .
XC-.'0
L?S#E?U
\$*/,?
:GU $5!
?<XX&:#,
;H,)82
5.[0C+1C
6+78%C
$P61_'
!;/S2)X7U
<.24I$+
2:@%%)
I0-D;"\
#5==1*
8?5[5@
(B-6+1)
8(-'0
!./_M)&!0>
G2[<(+-4#/O:(8
!HT*UC6
>#G6;<
*2A0/0
;3?(!QH
Y$X?#:=V$
>?4A++.
?"XF.\*
Z8%<^7
GBE%F0
:.?>"O
=?$"4
@B>1-6?
\CC@=UQ;A
(%5=F<X+
W5/<99*
C'TU>+(
""49K>
O<-_=)
'?X_,8
BZ4YJ(1[@6'
-]83+,
^D+T9&
)\<=:_!U6T4
T*$+7,'C6
I?9Z;$P
1FEXC"(
\2_2U>
*%'835%C,!
"=R#/!
%:Q*<Y;)
V$!"7#9E
6!%+"#
62F=S1
&8C>*X?90
$Y)HF_E
+U2A5.
+)1?<?
!QQ(4]J_
/UK+R!
G""(4:9
(-X\48
(+ &-/
"U1M!+
#)>?>#6
I/<>5!;-00I
=91#T
R>X?H3O/
<8-;YL
IA8$LAA+B)
].RPP;B
9$?10'"UA I
(C9+:_&
HV<N*4+
UI<:[K(
#(*>$G')/
8C!\HV
2&(?<\Y6=Y_4
M!V0F&%
@2>:'
9:\ 8E&
%5'59_
\7) !,E66
:;70)3(
/* UQ^2
P(0.F6:
,#.^5(A
55W8 -_<
)??,&3V
<@UR%E.
7!=39
>!8/74 ?!
)?Z'5DA#
!(7%;(6,%O
"3A8W1.
*2W/1
58LFC
L^6H$&
99D!!B\RC&-
(J!,>:
$>0,1G));E*%R
&?.X<)F
2_*+\ 5"
H/))1//
87"*ZH5
49)T/P]B
?*7EH
;*?"X
_&?1% >
^C[0]:#J
W<W63T^^
'R"/.]^.-
6CV[!5
&3([6(3Y
#7?(*<
-$2]6*%B6P*0
>>1*)W4:
:)58>&#V76
P#!-[8%!
*[WT85Z
8+&A/72
<>5YT4@8
7V</*#
?S7:C3!E
"2QXB]=
)!)Y-#
5E=+&%
[.<6#+*
)/ -=H
86"8)_
Z0R/6;\4@
9H8]>>5
/+&]B7
N*#L&X
EG^>,/SU?'9_
#):&R17
??9^F6
/O=;@$$"+
C5*&>A0,B*%P9
6* +=<774
6A+<>&
^%3=&9
GM%2VG
>="8"-
<B?-C-_0KU76A0*!
0' Z*6.
+,<9G4-
>-2?=#1G
#+5?!
<=#VDE
U!P09U
!"W"-3
$^FOSA)"^H?
"7!;WJ'
)KB2=C$
F.P58(
O<1K.<
&""KZ@
!(,A^5^?
*'?'.+97^:
/W2756;
5GWU>J
=@@/",
IY*$7.C
'>6+/\+8 (
<Y$R,T
F_SW&;
%B_A.Z
U7K74
<%OZ28
4&C##63U&
91 5)<59
C%-_[,
97;>)46
5#<#1)D.#
>D[XYD
)1]!!.![%X
5>\^9!A(
D\#;'1 1
<I"";H
!#]0@+(5*UH(?
<?9&L'
&#X4+WCEE
H,7\<
O2'%%
#'(;G\
,<A%&W7;,_
["#4=#5+
%'%>+6
4428.W
BA%"T4
$4^4SQ #7
DMF8"0*I
= 454M
F\_!R#
:V<"&%QI8I
-$/TP>6&
PK0D&]'
%"$_;_)
4<L 9%":=- 40P*
%G93)#;
(/T&?D_L[
5C4[)82
A'BR*?(4-/_
Y7RA!=V&
- *L2KE
(:?/#3.='
-3//\H(;E
59MC^R
67P0.
8=7E?5,YT;!O( ^
6>8K2'(
E $?)&"
V806=_
>]+W !:
Z1(CA)S
3&FH(G
$;4,8!
'!_7\,
4\,74_6G
*R$68UUG
Y1\WU
"&?B5 =.
-)-/9HI
R&/8?<
@-44T1
WQY?-HE #
; )#@T+\
VT8W.I
G<?,@[
?.!=<7
!C*'*A)
8V54,!
&8#";2(8*
J%B(?!1
;!)S(,G
[$)+-6?
6=6$;X
::)3A=\
_%$Z>"
2)]L!2
5J2 >7+)
V09K# T^,
5SRC#
3 -U'T(
>\)0"O
/39^G/
5_3.4^
+%460:
^25C+*":
%47+'<
K;&.&*G
GE&L(/+
VH12B,B:
/.O)EUH8
$RZ;\2V*ZKG
['P?4
Y<<!&+('%*
*.4=!B[)-6
#5,B52
1?=_-W
*_@J =
A#U9C$-
8?0>-E,
'$+T>.Z3
W(Y($@8
8%@E4&V!
C9BY?-
N4+6>M,V\/
,E(:<"!
(G4U:/
!+X[%-
"&U,^R
$3+&E
TXWYC(
UH688(
I*K'CC4
_!*1<8>N(
*EV.<
CUW;$#CB@;9"<(#?5(
//]6=/>%>$
Y<;<,1'1
9*D#5E_9
6!"9F9>
299R8" 5
"XA,&=
0$F#Y,_
B>R>X
A;S$].^
%([LV('4-;
%>=+3=
;GG"9O
#?789(^! %I>
+T %6)"
9M*<# 5;
*9Q4K_
15 ]"[
#ER$]JW
#/3+KW/;3
HS3K7()
"$45!8R
D-78?+%7
-RPCJ2
K2#=! F
.$' )V?*4P%8=
"4-.!026
_(6!=85
],#20>
)XCS39]D
5X QP \05=$
,7:E=I
Antivirus Signature
Bkav W64.AIDetectMalware
Lionic Trojan.Win32.Reflo.4!c
tehtris Clean
ClamAV Win.Trojan.Genkryptik-10016533-0
CMC Clean
CAT-QuickHeal Trojan.CoinMiner.S32378657
Skyhigh BehavesLike.Win64.Trojan.rh
ALYac Clean
Cylance Unsafe
Zillya Trojan.Kryptik.Win64.48466
Sangfor Suspicious.Win32.Save.a
K7AntiVirus Trojan ( 005af85d1 )
Alibaba Trojan:Win64/Coinminer.32f5356c
K7GW Trojan ( 005af85d1 )
Cybereason malicious.90814a
Baidu Clean
VirIT Clean
Paloalto generic.ml
Symantec Trojan.Coinminer!g3
Elastic Windows.Generic.Threat
ESET-NOD32 a variant of Win64/Kryptik.EDF
APEX Malicious
Avast Win64:Evo-gen [Trj]
Cynet Malicious (score: 100)
Kaspersky HEUR:Trojan.Win64.Reflo.pef
BitDefender Gen:Heur.Mint.Zard.25
NANO-Antivirus Trojan.Win64.Kryptik.kqizrx
ViRobot Clean
MicroWorld-eScan Gen:Heur.Mint.Zard.25
Tencent Trojan.Win64.Kryptik.16001249
TACHYON Clean
Sophos Troj/Krypt-ADL
F-Secure Heuristic.HEUR/AGEN.1371433
DrWeb Trojan.Siggen29.10332
VIPRE Gen:Heur.Mint.Zard.25
TrendMicro TROJ_GEN.R002C0DGU24
McAfeeD ti!4F63CD101E4B
Trapmine suspicious.low.ml.score
FireEye Gen:Heur.Mint.Zard.25
Emsisoft Gen:Heur.Mint.Zard.25 (B)
huorong Trojan/W64.CoinMiner.cf
GData Gen:Heur.Mint.Zard.25
Jiangmin Clean
Webroot W32.Coinminer.Gen
Varist W64/Kryptik.LEG.gen!Eldorado
Avira HEUR/AGEN.1371433
Antiy-AVL Trojan/Win64.GenKryptik
Kingsoft Win64.Trojan.Reflo.pef
Gridinsoft Trojan.Win64.CoinMiner.sa
Xcitium Clean
Arcabit Trojan.Mint.Zard.25
SUPERAntiSpyware Clean
ZoneAlarm HEUR:Trojan.Win64.Reflo.pef
Microsoft Trojan:Win64/Coinminer.RB!MTB
Google Detected
AhnLab-V3 Dropper/Win.DropperX-gen.R622355
Acronis Clean
McAfee Trojan-FWHP!0838E4E90814
MAX malware (ai score=85)
VBA32 OScope.Trojan.Win64.Miner
Malwarebytes Trojan.Crypt
Panda Trj/GdSda.A
Zoner Clean
TrendMicro-HouseCall TROJ_GEN.R002C0DGU24
Rising Dropper.Injector!8.DC (TFE:5:qANomcoTHvR)
Yandex Clean
Ikarus Trojan.Win64.Krypt
MaxSecure Clean
Fortinet W64/GenKryptik.GQCB!tr
BitDefenderTheta Clean
AVG Win64:Evo-gen [Trj]
DeepInstinct MALICIOUS
CrowdStrike win/malicious_confidence_60% (W)
alibabacloud Miner:Win/Reflo.pyj
No IRMA results available.