Static | ZeroBOX

PE Compile Time

2024-10-24 00:00:48

PE Imphash

03f8fdb61d1ee75e4c09d1f972e966b4

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x00126b50 0x00000000 0.0
.rdata 0x00128000 0x0004b6ee 0x00000000 0.0
.data 0x00174000 0x0077c740 0x00000000 0.0
.pdata 0x008f1000 0x0000ce34 0x00000000 0.0
.vmp0 0x008fe000 0x003838f5 0x00000000 0.0
.vmp1 0x00c82000 0x00c043d4 0x00c04400 7.97628021399
.reloc 0x01887000 0x000000e0 0x00000200 2.33056119697
.rsrc 0x01888000 0x000001e0 0x00000200 4.77099667394

Resources

Name Offset Size Language Sub-language File type
RT_MANIFEST 0x01888058 0x00000188 LANG_ENGLISH SUBLANG_ENGLISH_US XML 1.0 document text

Imports

Library bcrypt.dll:
0x140db4000 BCryptFinishHash
Library d3dx11_43.dll:
Library d3d11.dll:
Library D3DCOMPILER_43.dll:
0x140db4030 D3DCompile
Library KERNEL32.dll:
0x140db4040 GetProcAddress
Library USER32.dll:
0x140db4050 ScreenToClient
Library ADVAPI32.dll:
0x140db4060 OpenProcessToken
Library SHELL32.dll:
0x140db4070 ShellExecuteA
Library MSVCP140.dll:
Library dwmapi.dll:
Library WINHTTP.dll:
0x140db40a0 WinHttpOpen
Library CRYPT32.dll:
0x140db40b0 CertFreeCertificateChain
Library IMM32.dll:
0x140db40c0 ImmGetContext
Library Normaliz.dll:
0x140db40d0 IdnToAscii
Library WLDAP32.dll:
0x140db40e0 None
Library WS2_32.dll:
0x140db40f0 listen
Library RPCRT4.dll:
0x140db4100 UuidToStringA
Library PSAPI.DLL:
0x140db4110 GetModuleInformation
Library USERENV.dll:
0x140db4120 UnloadUserProfile
Library VCRUNTIME140_1.dll:
0x140db4130 __CxxFrameHandler4
Library VCRUNTIME140.dll:
0x140db4140 __current_exception
Library api-ms-win-crt-runtime-l1-1-0.dll:
0x140db4150 exit
Library api-ms-win-crt-stdio-l1-1-0.dll:
0x140db4160 fclose
Library api-ms-win-crt-heap-l1-1-0.dll:
0x140db4170 _set_new_mode
Library api-ms-win-crt-math-l1-1-0.dll:
0x140db4180 atanf
Library api-ms-win-crt-string-l1-1-0.dll:
0x140db4190 isupper
Library api-ms-win-crt-time-l1-1-0.dll:
0x140db41a0 _localtime64_s
Library api-ms-win-crt-convert-l1-1-0.dll:
0x140db41b0 strtod
Library api-ms-win-crt-utility-l1-1-0.dll:
0x140db41c0 rand
Library api-ms-win-crt-filesystem-l1-1-0.dll:
0x140db41d0 _fstat64
Library api-ms-win-crt-locale-l1-1-0.dll:
0x140db41e0 _configthreadlocale
Library WTSAPI32.dll:
0x140db41f0 WTSSendMessageW
Library KERNEL32.dll:
0x140db4200 GetSystemTimeAsFileTime
Library USER32.dll:
Library KERNEL32.dll:
0x140db4220 LocalAlloc
0x140db4228 LocalFree
0x140db4230 GetModuleFileNameW
0x140db4238 GetProcessAffinityMask
0x140db4240 SetProcessAffinityMask
0x140db4248 SetThreadAffinityMask
0x140db4250 Sleep
0x140db4258 ExitProcess
0x140db4260 FreeLibrary
0x140db4268 LoadLibraryA
0x140db4270 GetModuleHandleA
0x140db4278 GetProcAddress
Library USER32.dll:
0x140db4288 GetProcessWindowStation

!This program cannot be run in DOS mode.
`.rdata
@.data
.pdata
@.vmp0
h.vmp1
h.reloc
@.rsrc
790zsQ
KXo<R#>
lpImI6IW
N4!cQQ!nH
8nc1X'
;F)A]|-
{BX}4Z
rxMXA+>
L2OoQtT
KD$|o/
:*G:_6*>
NUQoi<
azG(!,
2I*}yl
Uq*BIr~L
g`.gJ%j
.^ZU
L>*9P^
z/Y<0q
,.rimC&
,a/u.|j
-Lxb./
FreeLibrary
(P?w6,@|
Za+J9{
2vX\58
FeN$-%
fIn|R*
W|40Hu@
jOG{\
@X HR3
")}A1Z
F~cn8FzC
{z,vK{
VCjYA-
fP?R;jPV
~Npk!&f
gZW?g0
x&+i(t|q
T4+K+k
csA$jB
sx]|R*>.
CiS2W|Q
+{UR;
0JhL`$
0k'Q<q
kH9zN9
ExitProcess
"?Sl}!
@wpS7~
PB7sVA
<8Xj!,
)G~Dy5
;NRTzz
/$q')QW
hwVb/2+
^0aL)9,
eZZj!_
5-y=@Lo
8l^:t[
'2m71V.
}I9GFU
dD[.shD*x
(NGh{ (.
xS(PeC
0D^|m.
WinHttpOpen
\m,4 ?
=$!4X,
*}bl4M
b+wLnb
L7L5b4
/^,O#r^pa
-g[?8e
ny&)ck$+
j((qyn
n=&Ce1
\UeI9@
$C=/%:.p@Er
<k`$)
snW v9
Xc]v]|
D3DX11CreateShaderResourceViewFromMemory
d3d11.dll
bcJ@Z9
RIKp~b
t>!*!6
fXjwME
Y}A@E~
&doZT*
|BZJxS
rQKe 8~i&
xh->b"
mI>!L5I
DJGgh{Z
A0C#3!
S-iwpP
4E"{{;}cR
B]nZ\
K$g6+NK
,K76l(
1&KD#1
l2["'U
>B/I7N>Y
@3UH}
1'`t5W
)z}RWR7S
`xnb2%D
BzY}kS
Q4G4d_L
(+|d%Q
lwRrZ6+
]8[_iIk[3
{9O;J{u
{/ieJ{
h7h,3il
z<_q<Y
[I(<<,
TN >}V
}&OQ>V
=,}TMk
~,FWjaq
krK{5/N
WZU-C
{};#N{
RGZ_Un
ZY.=bd.j
q%8~8'.
_&G/B
/?tvk_t
[o`+)g
F#eIF4={U
+**t C
K3))wB
j5*PUL
r9CBzQ
~03<1S
&X&%N;
't}&C
,:Z;RUY
?-I)b[
D}B6x[
T]H|Bv
{j\iJ{
g?b?J}I
b0Yx\>
Hf@?U?
Et<>v3
ZW|xL_
%}#JT9!R
\E_%bTc
dP|Uq{JOr
U}MC,j
Gf O;|
ml*B8
{|JYM{
.iS{u${
yai%_<
d3dx11_43.dll
?M~;|M
E`S&"?
_UbxR&eTGck
fuSxhP
Yd;ha>
:$xGf\q
H,piy@.R
KKEi_B
GetSystemTimeAsFileTime
>&A*&[
-5t,MN3\"M@
DwmExtendFrameIntoClientArea
?K5Y`0
HD@Dxu
TW_te_
LL;~2]
Fl*SB4J
a'sFSw
{#Z-?aL0
[hNuV9
>ko-y`
9|!h @
7}<f~&!
Tp\CEoPFS
MrdwE|)a
zQYeW`
1mNvhY
ar89Oh]C>
bN/xbG
46eV[x
p;@~GF$
<8(>^;
k1D825
1RfJvUW
mkr*|))#
FLHxi$
_ fwpl
/n}i5y
}2bSM
*Og0_98gD
`owY:R
iy84ey-
VHpsGx
l3Y{RT
\5!(=3
"V)9J/
=52w8C
6<4}FW
"OFSY]
mYFO_|
i776m&W
GetModuleFileNameW
)'@K}6
[>Y23t
D-Rek[
gm{|Q/k
{)LR%d
DfcZm{
0T'M%sVQ
WINHTTP.dll
|UO6%<
/pc6NfJ
sq^Xq7
@kA,ea
{R$D=yro
kKk=Q42
Yye3M2
@JKD$Cu
?h8@Y
T8\*W^
Yu*MUH)
_set_new_mode
#+/|X#"
y}w^p1xUQj6
mf8P>
GetProcessAffinityMask
K=v! [
[]Oh9oCx9
A~J{o
^7@wa&
=#\uzgu
*:F%rh
h%oH>cP
]6|}:|
IdnToAscii
{,bwCzN
z1{Nw29
w4J2{}
fkQ~"~
0@%how
L]Ts4q
}f)`yV
jm!ftM
;zfK:g
c9+Uu&
L$(e8IK
0E~ogw
Awp62D4
^O-6jXa
pM4e#l
ozuy?&
4=9&tV
#J5Rs;
P=oyQ[
Sa3S,v;w
8.P6B7
+_+d`$
HZAET
KIMM32.dll
=bmwtM
I t.K
9C"1wK)
U7x4K,]+
fJ}yq/{
D~2Ce*
vD9LQX
[G/%(
p@*~qA
->zC9=k
Z{2~Tp`2
$fp2'q
e2wUjz2=
P[+`ik
eF(Q&%
Cm5oQZ
p6]q0_
c@gb9,
_T9l@ F
vxQ&Q|
OTT5.~`
jXEfo+
N[!1uJ
ep2A5u{Km
5q2mCh2
ALA`R}N
HhKJ,SQ
_{o1Df
pd\(@Z
MV8j$}
rCy+OA
mmC?acE$
mbraO
o; As
4#}![}
*X%,D'
|7)B/v
`g5nDw+7
tZ:v*w\@1
&+oz l
QCn3j.J
O[c86S
.//Ey/
^Zoo+I
,OBl8V
:'5Mp<
Oyp~ #
),!Lur
5 wuQO
Z: pc(
Gr\>Lo(
{(d JpN
Q/`\TVr
`IpxR+IG
76&f.B
g/=6\0U7
S%.yQ9a
>8rY0*
##p.QS
oeM@1
iq`z($
sz=H[&
Z(;frSd
2Wv?]h
[8Nx3*"-c
|$`svf
]c-rRI,8
GR:df^
|?"B5
.~q{3I
.}R}PS
N`J.SO
=b9[n#
f|%6BiB
[w5o7
;K\q:u
q)K=F*5-+ze
=6iW9l
iMG%QG
a;u9j;
9AYn&m
b"7:o%%
/TCS,L
M2s5Y}
F:~Mfw
,Yn\h?
'7B?(X
sv;5aQ
s$=-,]HHd!
\='S`(
m^J?m5
")`1\A
{7#Vxc.
"LA/$"
*({'4
O)]6&+
~e=J2ui$
eP_wunC-
8`e]$'
Y;u/1e
9u)O'B
^'Qb%'<
^CO1.Y
~z#Pio7)@j}
}a>hZ[
#kV{T}
Mfy1e'
I@5ZFc
fSQarb.
LjVd2}
J`JveN[ 8
1gx-bO
IL*D'a
j'v`-)
kn]om
"VoJ\M
)^oUpu
'fT]+
]<ow!YD
p6ki)Pbu1
/JVBG'
yR69tu
bjLi9v}
1VdBNK
"s[,r3
(WF).;r]
tC:Wur
LN7&+-B
Qz'LeO
itdSdt
an:-FI,
C4WIxl
l>DEY-<
agt:$)
7"N&pH)F
H&&)@t
$z.T4|
S]1Z U
3AfVs?
:v~dDHB
d/%E]
o!4Pg
"nm4 &
}P%v\1
3#fNGD{
A,`%U4
SUP6ps
IN$.][r
@RXp{~
a]qlu`/@
o_]fg%'
/}9/[bn
)WqO'=z
a[a]xQ
SdZ:2l
Wphff:x
j'=QYh[e
li%ngN
@k7&Do
p@*'%bH^
wyfY.b
<t_PX+
7oHU[B"jt+
.Tu##T
^Zh!)'r
&K]}84
};R}J@
pGipO
8(T66W7
(0xxq^
OcxP[|
XS6),n
'%+WE7U
EZ.TbB
XlJ0r_
USw0#)
e{! rj
H^7Sf'
HL@H+[
gkGps><
/wy\w]
+S #.)B]d
\#mfKkI5
"gQ>8_
"O``aZ
16ZbR]
3P&;by
mdG2J]
!"nr3m
/l4gsc
AhO-=U=0
Y3D.Q^p
:>:9gm
"hiB6J
QZ6lbhG
?/o$>+d
dB0nPM\
8;d)2Z
hy6|!Z
\Y)Y:1
`x\AWIw0
wL%11k
+3$<tZ
95M3NI
~_0%@e
_Xu9]H
vJ:MYg;
hxg"!9
tcKU>l
2`=fA_b
Aj"QgZ'
?(%)w]
U] c.sB
3VdUM|
e&|KYR
ZUcN|+w)
$NmX&
t>{D}E
;a[!!x
oSW,,*
M6]r_J
fpl^SS
@!seK`
)WZ4s9
2.$r%L
H_9{l}
@q 9"F
'tvUekcP
R}-{]e
~1mab`'
<Wn~<
+0'y19\'
-'N>~]7
&,>qW#
>auAEQ
m=MWxu
__current_exception
?SU=~!
masro_
-,;`./~9`'
|JdXQr
UE3zJ+^
C.45"h
8F@Ia|r
YG4/tcG=
ADVAPI32.dll
ZdqhQm3dc
+!Qx>8,
w>?YSJ
AD<ceA
ef|9_XIS
*ub4J+
5:yX8;
ks,w[|
gT|q6Z{S
ep5K[1f
*hS)V#
y!J>GV
75V`K)
w,V;^G
Zo!3tR
:\S.WF
VWaoC8
!P<9XRv
O6VwWN
#6!qQ0
([ra=B8e
{IOJ{
z3MG.G+
{b$^N{
p|qL;Y
b,jV<.{
pVE[Oa
mt/+b
m-$9S05
S[.@8o
8i(Q/.
z(P?T
hfSSg,`I
nJX&n"
4soxx\9
o3"b!?
!ae{(K
\Bi`\%
r#3tYu
c*;3h>|
T<~Gwz
!B4i/=
Q/#sKynb2
)%@wK(hZ
X/>r6{
N#&N.yj
lzIP8,
"Hyj?W
Pfen$&
kl!F4p
!jc!=|P#
2VCRUNTIME140_1.dll
{]rl\y
@GgKwK
w])nx$
F]@[xK
2&l{7#
}K4F}Z
%IvS1x
,0xU!K
"H$sy!
!KB?B
e&Mr}q
.wo3e%
}hq/c*#
xs<l12
pjnuwF
"K+x*A
IFVtM)6F
lKX>p|
7j%wF}oV3M!
(+k-#T4
|XA!gE
v?^G R
-K;VRv
FI3%$/
5Bv&7L
'ti4qp
=)nMM_
o$%w K
c'z%a
(]93^o
s3d\5>
[YR22<
wJM/-
UnloadUserProfile
t 7!l9
r!krfcwk
3kA/R0k'
2"g?%v
'oyr>;
pfsYo]
c(NP(*
3!,z`q
/|&M.H
BZ S3&
D7GU+taj6
B}iu:3
E!j42o
W9q3#T
A./rVA'
E|/cfpB
.W9Skg?
GetProcessWindowStation
\&TT"$
i>QI`iS
P>y-#E
Ho?R/[
*%{txA
qq4(ow
`!7+Gx
yym`yp7
ro>B{lF
@]mH)B
*oF.ze
K44aT:
^ux>`~ZP
kBPn0n
W!|V!\l
1p(XCs
Ot6tvV
ptwz6}
`)P]>z
hDX<It>
^d;">i3
4*z41e
Abh3K"
"s-6:c1f
#-8ibt
vR^gZh
erigBr
t]5ZMq|
M7*rki
N7RZ(O
6~h_[=
QPr,E"
dFgJ`~0npI]
bhHb6I
~FZ{&,
6YqQt?
$|\Q^^!f
|K?*(G9
pTP}^L%
}g2MDJ
:tL$f{nW
$`'hcY^
RgV:89
Q(4< Fk
xtjh::
B=,)t+
G_w*;t
PqRCC`s
SUmeVy
QOX):eT
oc@5,Si
7u4z#m
kqH|tC
N8-F;Z
?mXmtD
izOYf
.(P.H'
pYX[K#
K+~U"Q
]zb~h*dx
?hIm@<
M$LUgP_z'
]YWF^J
`bdou
6Nj3m~
X67eW|
+n[qxr
s$fEDrL
na4<V
"D7:w2
n/u(5{?
{%"x
4|4vx)
~U:m@S
2k;=q7
Y{=+gJ
!#QHD
C+(~l>
jLanMq
L"spxg
3"zyrzu
'.{QQ6vp
(lgc=]6
mB'=tb*
EnN5Yt)
-ljQJ&
8&u[`NG
CDXWmN
xXApXre
sx<IET
G-LpSfY
^7=($\
XG8?6=
3Sk5en}
#EO`^?Y
Do7L^2U
d17W!CA
yk`[l2z
K-]%|R
_J6-`eH
RPytX.G
D4'1qY
j1EGU>
c\Z`C+(_<R
*YwUJY
H}tB0I
};.o" 2
i\zhy&o_
.z{D#
>P}\RYi
x2K_t1
?|JiB/
{Lo+y"
kGAb_tPpp
no,2[h[F
2{~u5<PF
x!*FX\
d$9KD!
%!Oy6A
=0e{2x
8h,-*#
0n+cB`J
`.K2#'8
(H`XLL
)Crbj;
gn3z,/E
/u-s"c2
\["WxdB|
MEB].
pExR3vj
%){Z+k
e w)u{
cl7NV$
k7Fm;]
o*{4c0
Ii`|pipO
hH}i'+5m_|
yA'SiH/.
$GCAR"
=Fg6KZ"
bb+4h8Z\
o}&KJlOM
X4'GW
c]C(AqM
,zcZza
.yi%Z8
D[=EKs
Pnp#`y{
Cg;d7U
Ohul(M
Du $uq
@d4^bly.
=T,$XL
GC{waG
J+#/Q-
6w?`rq
:$[^W=$
]AVqag}
-sw|]=
3pp{3V
LXnsr?/
aE"i@
V<Lu<x
F(n(A4.h4
xtya!(
UuidToStringA
E0.79qjM]
7$Qj(|
Ef?}2(
ZI_R<\0
U-@2V8M
{:_dKq
-W 1#/&
('*e>.
ymIm%{
i[8r7b
g=Kdx&
c87_Cy}
oyv3|_{
j{=(Z<T
aeh9mF
kG~irImK
DIWWZ-
SI@A@s
P@K}`P
VCRUNTIME140.dll
L:I*lqH
!WeFq0f
gY%l.:
$5<.<x
GW((e9
1O=s']
n0LsP(
:re`0QC
H"9Cw
4"u~B'l
=V1K.n
V12]!5
MOWhYd;
>7NME4
Lvkr&vY
KQ]41e+Qa7
dmXgwE|:
-A]hn/
V0]5:G]
&`54Sg
Y-oVt
jg!,W<
BPeIHBs
"jU&+T
l6rEx6
_fstat64
K?HSx(
j`.Zld
@JMtwPi
OP_<%P
rI8twP
WTSSendMessageW
jI;7^
7q5^}S
4vD9M!EmU!
[K]dFC
|FJNty
r"n#b<
7[VbA9
+L1Wp}l
~W11=E5
dgP0=E5
um^pBac
KERNEL32.dll
Ozi0de
LOyUW
]_`<VWo
(dMa{M
{Kf4YFGO
S;PP{k
cNJ}0?=
~:34 8
q|\YVz
Mzm}Ut
G9UnZ(
x~N*'+
Fd*-,q3'N
e%MReo
:I\_Zn
~WS4!QEj
!{, e-y/lp
*pN,_KiE
"nciL4
Fa7xODo
S$mr"(
hyu0Js[
Q~3?'@"
 5ThZ
k8&@TD
0x1LwY
NT88BJ\Q
LocalFree
7SHS<h
SJ$Oh@
oapS)q5
%1w.{&
Q$|n2.u
'`vp_<
F9s8SjwA
y0C, !0
15yQd*
$Q)OF6
omNVYm
P_7j<0w
\Y^Zn*
-N9CS9
KCHjeRv
JUKCHj
Tlj%rS
:DGb-6k
]/j]hA
uEON_t
YR3j@i
,[voXx
\2$.~Cqw
-Xlt3/!vt:
..YN;
^#W+!h/`
Eo&ZhP
GetModuleInformation
CaoFEfa
6qFu%;
yQ?:"G
Pc4 1Bc4
rhu(YDdB
MSVCP140.dll
5(L$nN
Yaf2{`
|_`w]{*2U:
AbDBIT
P|73Qj
{$$^O0vj
Rd,G+X
j1QB|x
( z`'"
"!q*d!
'Ls- W
e4.Oy]nNH}]
B4qqOBO0fCm
HK7V 6
*)@89[
4gQq!,
\TfW$_
li`>54i
,dc.UZ
fx7j_?>4
A;r%+*
J[}(r7rug
$R.)@5
&1uQ,/B0
xN@4$V
,(\7<K
"e!@wv@
?f1$B<b
;.N4AHp
qi]E+-
kMN5R7
F}hJo$
-kbRI"s
Pq"h-Cj
+}=EdG
T/.t-!
rg6s+Hb
B5\4?P
FRSSkM
T<D2U9
-kbrZ
f'BR^n{:
[:hYxv
y#BQ6q13$
yphqXbZ
c]=3J(O
nWUy2*q
|+uxKZ
oQGh2 h
'\CD?/
V9T"e5
r>!\J/
<c},b(
{5B!]s
V/~%u|
}M<TDs
p|6C7I
AcgeO"#:
/tC\#0"
]f36;t
n:~?2/:
@NPQTK
~e1oa)
qHUF'!
,tb=Gwn
R1y46W*o
xWYcvP
yZ{T(iZ
0#gS=G
V(B:BMr'E6
\M)N3y
Ly~Y}}
DP?T8N
^t,%fJ
umf#[+
63]%AA;
q:+XcMU
miKeGEmk
poC^>/N(
Q=<,[[.
/N'IM~Q"
-`lSjV
h'"?9@
a(&4&,
]%[~e>_
]>U6F:
pv.=DIB&
<]T#2A
'Pc;\>u
`\,fT"
u+xB2U$Vr\
K=gvv8:]
~!>,vN5O
i-Y:6 Y6!#
vAf6Q`62Jw
60-(k/
FKxB.f3bH
*SK6)e
='Fi,e
2&#tt&
BY8JiU6
V-6QRY/
D7(Y4%St
&~rLwqaF
h-(E@%
,@Pzvk c
\Ri'Jl
/lFkTF
=#'OW{
$SmdOwW
/1LW9(
ggIll)
E]Xr$XI
rj(fp,
my.kC4
*:\}4|
(lL x<
oz;def
4iOpB-S8Y=
|zobnu
?@{%lX
-GgJBv
>9e>^a
Ww#6@%m+
5 BME
"+3[M=
Rw3+@n
|W#Xm1n
cMs|q,
9}Q-{D
3jt%?~md
'%[(#M
+~.2|w3
U-S 5V
Ys_!tx
t{L!i,]
:%V<_{
t[ICAc
m|5\
YqxNH!
k,8dMg
8+Ke't
oiDq6oS
~@r%r}o:
O!G>fJ
>;b[$'
)LkLY.
g;F|5r
.endHAAi
'R('"z
"QL">Yn
n?h6|
T5_`vs
l} {Pb
:4IdoI
9SDFxmH'B+
JMXd@st?
2147%9
.e(HZq/
96w|0,
/v0t`vAc
oPYYfI|S
\nHv'X
/'{D7h
idr38&-
zJOd7^
IxhI>A)
K6B/A\
C#hw#J
V_;w9%
eV?R\hkx
R89|x]
~:Ck%`
'jJIOV
Jn3PCQ
}w!UA2%
x22:IU
]tAx6`
m[G$Vl
(lCY@h$,
NHccq<
_t]SEg?
Y~9LA%5
$TJ?->
4T<(C_
.V05gJt
s,.H=
L#Xsew/^
lI*,rI
nH*nOc
qq[KIY
y}sYPuH
,YR@/W
2>#;-=
i _P!>
*d9:OEm
4b|>'^
@NWEhH
?ZcXi|
AqI,C\`
K=|iit
}i6Q!R
k<*mi
:f$qF*hb[K
N>pMV7
M,Um]{
~>0q%9
C4>;E"
&/I[Gm3
rPO%j#q
<~+%.u
'?b=)~
?2~":+V
7+9<DvG
*^AX>{@
5V!h&z
["H\u-
QsP?p.
/|#')"i
V.s"!/
)- RnS
{bAIi9
$0z}67
eeX/&Yt
x[TLZ=
3p&JwN
tr`916'7
[6d,W~q
hpnN_5
>-dy:=
s 6H_|z
c01u6hK"
8p(]OT<
8;L8Hv
qkRL1?
ZrdYQ
Tao8D
q?Rj9A
,pP4N+
KscHS
&*Mz\\
aV(c#At
dqPi'VjF
%Awjk7M
JGo?tt
L""`X,
fj*=gcz
/gz$T
C{yjHO
@Zs7K
(a7^<D
*qbjUt
<yU42N
an*ez$(
)&bM^o
b1Z&GX
.{G29*
^}R2Q`7
P!&/;N
J*fN0L
O,@{u&U
6(WG@>V,
~J^4j'.
;RkdXH/
4w Qtx
$$zZuF
yGjHW)
lF."}c
J;A)@b
PBy$JW>
*1JZjYt
q<EWK5
'q2&3|
<*A%W|u
BCq,#E
k+7f`k
Z.]LuqIg
Js*N54
D18ZR.J8
+.9r`1
Km"JHC
s_4RrK
1Tr{>{
gJm5"|
_$t1Z_V2
R[xVlN([L
Dv~xL%
0D2f+
3hSV?(
}JYO;f
|c5hcC
y.)Q;(gcHp
){twz
J$j'A'
VRGz]:
B-_xJ%
L@^3\!
)hRpf}B
c},[v:
Obll+9@
6.09r^
YVA{!J
Y<I_!_!
;g!D7;5P
)O&@m
3N5>UYFML
xDQdev
zkP#JV4
C*p@9S
-B#sn;3
uO7oI1
hm8zMc{
x$/|k$
tLZ>q;
L8FICa,
Z=}H<H
]j> iy0
g5Bf62
q3(5_&
bc|=[C7kaR
u- MRy
Z92wqF
~ypj0v
0Y$O\b
H5>pH5!v
Lj#H>iV
[`cK+G
3yT6rNB
7c*YNb)O1tNY
bX400?
S$IK{k
xR&3j"4
H.b!#jU
{79Vr[
PU1Ksy3
~BPm]5
pkb/B
J-R[t6Wh
I'msc
(l,>Yjyg
=%9}Ob
_8,CK[\
|Fx\zx
K_mg7}
^Fwfm
LweHyQ
X6|Da"
I-\Qc!:Q;
Am68jU
d^zG*E:&
en3cbI
i@,v>~p
R[o}+
s,Ph=:H[jF
}%Ve71
#NT|r-{8\:
H"-ck&F
p?=wNR
K`[^?F
|U8}T$
JNN5<
xIdr'[}
DZpzN\B
k'f]2 v_
BhP`BF
(;qlnK
!=KLVHzl_
3MjqE\
K;lglu[
L`aufe:]>
c:1vj&
,,%(S$C4
zRR }W
Y:O0e ZtJ
#u_U,]V
}#'sS5
GbK[-Z
~i+*[9
f;=|`WT
SCu"?
"]ai#Mm
0!5Ln+tW
w:9-\^~jd`
g-L+Mw
g6IVL%
6U`^]F
;4SEUu
{_Siec
"{*SzT
`+vW,A
%LD yZ
rG2)`B B
j8l>Zf
]O[Y!>+
M^1uPW
p/+_9/
r3$`n[.
{&BiQ
T%T%34
7/rq"$
%Yhl\d
j\[_:bj
Kdtn04
S4~2V}
DF3EY
:n>N3}2
Kjp(t"j
14m5V,YuR
OIEd>J
7IS<+2-
HM9{#M
Auk 7Wk
(4{.?HD
5f'xq^
&+gss?
Z,Y6Da
<[w\\`>pQ
Sr@iUS
+:J<Z<
QxA@Ld
)dbP0."A
2AsjV/
0J}WpgQ
G=dn8H>
z(]0`d
<s<D<XL
tk X6g
x$:YsR
4"KCA^
O#6r>-f
0MLv:?
B(pKxv.
q sDU{A
>;5e[jR
-bjcx+
1(q^+0
5pVuQd%
9,Pl4R#
%Sil|$
*tp^geeyO
h>j(*1
u#ClK7
9#<5G;@K
9'S3?K/7eO
y(tLY2
c8FpsS7
{*qK;L
Tgxy{AH
&WGo}=
<$IV+N"
FR:6BQ
HU:m:p
Sq:D2_AtM
'X@tEbO
<'Zo./
2Zh%2#"
fW>Etz
\\8}<)
8A#PpGG
-LS2(A
?:;mST^
{AzVT*
WE?0%jM-B
~b| &Xd0
Ri4POw
\>EURW
A0%2dG
dhN4#CJ
H5ow;B
v(E:ac
pB hDm5K
N1P'iL
]T,@A^
V9d@tV
^SF"+$
W<p7K^
d{cy,W
[wLs`9
k;,QEWB
VA ^`K
u&*&7.
;rjZ[i
:UQbSL
j1j;cS
oZ90*zGSo5IsM
HJ?PI@
#`'Bu!
?p%%c S
z7oNgp6
|4xT<zZ
!?gZtS
KfI`8qe
_nx$GB
6KcN~F
?6+\G
)LkBKu
hp:JmId
*wE|iv];d
t8{k4K
WgU@;3
ZW|.P
HW.kl'
<`/NuQ"
"/7ur=i
aCR=e`
#/"gr@
rGex;{
xc#HB+
OQ>L5!|
_vm* rx
jm):I^
NeqFR1{I
-*oprFq
e+ *co
'ShPZ
2G:lCm
RlsE--j
$_[OR/
>?NW>B
EF%i/D
JaLpwJ
FF}Sn"
=,cVQ"
9}6;3.p#
G/U?Bi
oQS\pT
loRl=3
Q:Ch$*Z
J>LwNX
q~rWGa
iC.cJi
<x,k
Ddi]\BCO
]`M$t=%
-bM-g8
fbCNYP
e]xpF
cWW(;H
ZTV-C+
\k@:}C=
5)L@icD
,V|a>vBk
SS<f6g
{G^IXF
E+Jx2%
7H8kLMj
S^4l&I
b`)6'C
;H|)mMQ<}
zYLH#%
_N4J)\
Gw2\;y0
riUN&j
xf#EoW
^tw$R
TdPzdV
wJ[2GZ
LqoL:f
M[{4Yt7
S$Y{oTJ&V
T`aqYQ
l74/sM\
n=8Ktd@
EX\=="
6'}!dol
ix65\ae
7v<%YL
/&V};T
|I:y6v
l)zY(Vm
NUw._vz
F9:NRQ
3xv86{
/<H*UR
*lDDF5
A6TZ F
TJ+vV&
FRg!'|
yl0g5'\Q
WOm)|t
yC"-[_
@^?YP@
{i~;U`G
0ol_h{N
9Xl^h"E
MX>-2P
@)mmh`Q
Q5t/,{#M]
Uc)B^$
|FW/EK
I/r^c2
l,uq/d
asalHW
~tmCB4
#/FyyT
qcd{xz"k~@
m#\6bm/
T@Z/TW
fl5koU
qO@.s6H3
v=V`I>&
+f\Ce
noB^RN
Q/I_9q
$wfD`0O
XueLW(H
R.Vk))Y>
b89S|[1
kBW]f:~
e^}>C`g
#I6X{t&
bSU(sk
PIm(@J
5.0'1
N%lm/
^k7Bz!c
~5q&>lp
ATD3_H
`4;CrHw\
cAQ<#8
c#HHz2[6
M[Z]ON
!3T2&o
Ypk_0zq
r[)9?iv{
/'/7Mt
iBMGvS
D3;diL
3*x$.X
XyYxj
>GQfs<nN
@H3sc0
W^wV~}2
|Ft*k90?
V-&M l
W4Q6 &
:"JPl:
Zg2R6vp
Y-8.]&Q9X
5f_!jX=X
{B.nI6
FDY}?`
@O{Mmj9
m5.X[L
MRRDr#-L
[33U<+
7Y/60l
f"63",
k#7-r%
*[RRlcIl
TT$j^f
'W6`1S
Ap 81I
p4|]J7
/=L,&eJ
,;,4Tj
Gz$.2'
N"mrTw
si[Bx4
L5PT%-n
Qs-#uN
dOkdj
.^#?9H
?*W50\
h *!Z4%bMzX
t0*^Iu,A3
dHkICsu
7B>,O$
7{_i5
X)x\}1
M1S&[W
(/nT`H+
c:=L^CyT
Cl*Gy,r
kapyoy-l
b>;]@t
,D![{Tm
U0jgw
G;zra8
tW'uy39
Ce{Z_2'
aMU9P^
!kHG;;YDg1
X3KmHG4
tOcY+V
rU]-mH
"so1~E-
.SE`DLg
!`iC~Gv
3}? .V
<~.k l
^@rgKF
=CW(&f`=7
c[Xn!Z-Y
yV5:="
OL:N=e
_PMhB<
<H44hL
BqOL{9Ae;
S5nV6]
}w6kgtf
.yH#6kK
N#D*"M
2x(/{]
W3BI D
TWNy5]
@ay#xFJ<)
8}xS;?
qA5!dE
cTA{4sqH
Y}!mfW/.]a
A,g)oi
DcFDLO
TdC8[1>Ij
.>%Y$x((U
`d#ZYb7
d@RezN
ss[[Q/
Ed@/4m
\aC[Pce
/k0v"R]
XlP]jp
;bBEe^
NP%`Vo}
6wN]Ah
|<D_87
Zp;[+V
+1#1Ko
@0+?!]
Z~x)lr
Z:n*F0
(nbAhp
e)c\oY
: !4k;
Yh+4bIQ
),m(-;J
Nu3A7A
dZE) r
b!y-x@
FJ?1`-
&@LyBx
,t,c5G
CR`/N!6
eL1#w*
33]n!^F?\
,~%2~k
o',VBp"
,oHdpP
EdY#Ir
R,}-vN4
\Y|PoM
*W:8+9
wo@yF*H[
EFIw1r=]Bah
3v1>VA
Rus$=q
;CN_O2v
PuZl5
vu|3>u
0$4\rM
ujc@p\
4p">S,
!Sz\q|
Fbv'l
+D^s.r
agz'/)_
%HMgX%x
M4MzPC
SJqf~
7n6:Fm
NM$le>
Q+1klm
z& Zh`
l\`(Y1A
!l29:`
Q -x+U
-pHMhK
aC0olUy
rS<B1m(_
YH2$L|s
a+jI8N
8@{1O&+
6qU`5E
uEuiW?
.RxJ#r
Ghi~Il
*CY)&T
,3.yFy6
I.*_&X
oymViu
71oJ"
a_i.J(
KXAgk
ghN^}V^l
$49WNX
'q|ej
JrGO6
ykuUY[
IQQ9hg
7{ i)%
o:S(G_
3\"k];
.,N.G0
As.'
n9`F)G
kpQvnF
G{=7*O
HNKr~s.
?:x2Dnb
O@pv+Qa
R%B%#+i
0o87Vj
t?G|Rl#x
3Hg@-Y
fK46&g
_&RA4|
d{cP_f
9b#u[h
`R'0/%
wC!$~
U8-Gb5%
A{S&p9
HE$mj36
j(6$I&P
`_:$ot
EA&UFmvl
BJ0(!b
{5-2O6
dT13&e
j <w&vT
EAiV%=&q
Ol$f{k
of.$Ly
n.MR:Y
@$]s$"
rlp,p_
5my~7R
7BrG/ @v
/>~B?Y`
y)(6MN/8u
3)y*R%%'(\~
r=*XqH
Op=`b)
.YR8VZvq
8O iM
.@n(T}
.$V-Q^
d8(Qc&z
Pn}>=I
Pe:gcx
*8*co_
/l91h
5F$R_[b
DnbIU(
q&-nV$
L^9*
?4=1|d
*Byb$uE
a'hCNm
s]LA8j
Y^rre t
;KnjMF
>LvdBL
ZI5`6W2
RBHnrXhB
Bb*4o*
whH1WF
v_>w 1
$#_2`n^
SX)@%K9
Z_|KDu
QWPMXt
S-bejQ
}aI43nvE
dpZLk0
F8m'=/
4X4M`%
9Iy2e3
sD?!TuM
i)}P|Y
R}16{|;$
zF']A83
`y&(OF
Yx'kG'
[Z$y>X
C%#qqgPn,?
[<IP~/
SC8pa>o
iJ*|tp
?0~wtGZzX
6l515s$
J$ozsd
a#}wyg
]o[#Ub
vLzd1m/
~bDC]n
I?&B`Q
|p-kW> ^(
[Rc4[j
b!aSZH^
{R!m0D
Y6Yo<?
xNP+GP
+@JVWw
Yg>[<cN
,&x?H^Wha
LnX@PS
BylW=jTc
vYD{I
e,PmSS<@
8/`h^#
,maO7\=
0i<}g#J
dmH hS
Id!RBuN
U9]]9[
zMTO!K
vfy0vV
bqK\bI
G2p>=9
Pm-^-]
8EoT\;
*`j|8Q}
(}4=tx
Fa0._h
z,[yD5
;CUc4Z
|ynZW-[
_^b&=!\
J{E=+(
>G"ig~dP
iLi7<l_jG
w9_(ja
Bl3mNqS
Vd#VDr
5Ath`k9
#y$VZv
;N*HON<
$Zy\wa
Vm)9#M
2v(Oo-4
Xc1W2v)
EF(]GckC
Z$3kfn
k;C5,W
/]+^(vG%z
=k!kbL
\sww9^N,
;5y1fj
A]N Xo
yC[yS0.
241y72
dZlS[<
b.U!Tp
K1uCof
&h:{xd
~wem>E
6YrN5Ha
&~vZx>
6R&D@a
2paW)SD
J$|2)xDo
u{*w.
\ALrM1B
bE0ad@
WLDAP32.dll
`F3Xe\
n-o<:^
TL !2J
*iM>~e&
A7g&!/90
$VK$DG
_4Bz8(f
9dmqBW
>r_nhp+
uJUbr5
:34U3XLb
|4u!7i`bf
Rfn-M
I<.(?R
qi1:\~
qLqv)y
Mqv)'%6
| D^`+\
::D^`+G
X)WZPKb
;JZmj0
mFZErX
dc0pFcc
7:oc*O
VAsB]7
*b*(]uU
`Mwhx"
DxVEcp
(3)J>j
[i/=[(2
3Q^H!&QWaJ
zp_Lw=
XuT_D8Y<
E8b%)2
6z\fPw
D3DCompile
`,^N`!c`
J*:;T?
!?BaY
-i.J;/@
i,\vc@,7
ZVA ,q/
pz_:#9
"I%Z$]&
j|:*B<
lkj0v*H
AezvUgq}
-lwmu[
&`-/>S
Ld)dF{3X
bkR^_4
4x>k.lqW
`DWi0B
^uG4M&
zAE`ctzQE
4{BSvfL
bCqTCW=
api-ms-win-crt-utility-l1-1-0.dll
H;lp/iB
4q}0vbxj
\O?0O_
j&`,G<
^P4'aB
yRD~D2,
1wbGe\.\
@}(Iw3
D3D11CreateDeviceAndSwapChain
t0{_G
a]1nZB
l^y\[TDi
E$K$qR
Gl20|p
75o+-;
x3Nt|b
gI$i>4
?PbatJ
G1;({K
:L]tuU
3j_8e"
ql_yab
(&]>\4
k.kr{p
41?VG=
9u;k!oT
|\GTDE
k*$ZNW
F:?(x|>O
||Q`:(X
tDIt!x
de0^cf
|+8xw$
-_%FJY
Uofc 6
*'j z
"Ls?dO'
Wgj2=FYXp
5yC=xV
Sz8VE
90/V0xW
jB\G&^C
?rINlD
YpIOY!>
!L>\Ba
-{t:~Z
BwF76]
2]LD5Y
A3}D$V}
/]V@%
SHELL32.dll
BCryptFinishHash
j=<W5rM
r5eaI/
W"0HV[
"T4Mo!
s;?"WX%
/*(&qcAD
OpenProcessToken
"7kUo!
&$i^/A
Q~l[0H
ShellExecuteA
{r4-^{.
iWzIXT
jt2B<{
Fs\)@Js-
@s0}|Lsy+
%I(32X
g3sOmN!
b^pxnd
`kx0=D
EKn_\K
hORI?D
2)>aD!NBfyH
ihi|Hnh
GF_IDa|
uyiBv9^J
H@m(W0-
\+LI6YDn
g4]63E+
i6n0W}
6E\9pq
I"U{o2
cDc7A40
[B!/n]W
Y^*W`=
pX7dwv
*,`iPQL
?#=$Hq=
PHiFT.
(^6:(f,
isupper
|x}YjF:GH
reXN[j
)&~1IQ
1Ez5^/
9on.k0
$An&_3
*=k:3E
t2cc?aw
kd>vV_
hd~I4x
nhEdM})N
UDB0ENnQ
7pen"t
Antivirus Signature
Bkav W64.AIDetectMalware
Lionic Trojan.Win32.Generic.4!c
Elastic malicious (high confidence)
ClamAV Clean
CMC Clean
CAT-QuickHeal Clean
Skyhigh BehavesLike.Win64.Generic.rc
ALYac Trojan.GenericKD.74390332
Cylance Unsafe
Zillya Clean
Sangfor Trojan.Win32.Save.a
CrowdStrike win/malicious_confidence_90% (D)
Alibaba Packed:Win64/VMProtect.6072c786
K7GW Trojan ( 0058cdc71 )
K7AntiVirus Trojan ( 0058cdc71 )
huorong Clean
Baidu Clean
VirIT Clean
Paloalto generic.ml
Symantec ML.Attribute.HighConfidence
tehtris Generic.Malware
ESET-NOD32 a variant of Win64/Packed.VMProtect.L suspicious
APEX Malicious
Avast Win64:MalwareX-gen [Trj]
Cynet Malicious (score: 100)
Kaspersky UDS:DangerousObject.Multi.Generic
BitDefender Trojan.GenericKD.74390332
NANO-Antivirus Clean
ViRobot Clean
MicroWorld-eScan Trojan.GenericKD.74390332
Tencent Clean
Sophos Mal/VMProtBad-A
F-Secure Heuristic.HEUR/AGEN.1315472
DrWeb Clean
VIPRE Trojan.GenericKD.74390332
TrendMicro Clean
McAfeeD Real Protect-LS!D4C7B1C538C2
Trapmine Clean
CTX exe.trojan.agen
Emsisoft Trojan.GenericKD.74390332 (B)
Ikarus PUA.VMProtect
FireEye Generic.mg.d4c7b1c538c273dc
Jiangmin Clean
Webroot Clean
Varist Clean
Avira HEUR/AGEN.1315472
Fortinet Riskware/Application
Antiy-AVL GrayWare/Win32.Wacapew
Kingsoft Win32.Troj.Unknown.a
Gridinsoft Trojan.Win64.Packed.sa
Xcitium Clean
Arcabit Trojan.Generic.D46F1B3C
SUPERAntiSpyware Clean
ZoneAlarm UDS:DangerousObject.Multi.Generic
Microsoft Program:Win32/Wacapew.C!ml
Google Detected
AhnLab-V3 Trojan/Win.Agent.R673869
Acronis Clean
McAfee Clean
TACHYON Clean
VBA32 Clean
Malwarebytes Malware.AI.1481366914
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Rising Clean
Yandex Clean
SentinelOne Static AI - Malicious PE
MaxSecure Clean
GData Win64.Application.Agent.4C2MD7
AVG Win64:MalwareX-gen [Trj]
DeepInstinct MALICIOUS
alibabacloud VirTool:Win/Packed.VMProtect.L
No IRMA results available.