Static | ZeroBOX

PE Compile Time

2024-10-23 23:53:45

PE Imphash

03f8fdb61d1ee75e4c09d1f972e966b4

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x00128420 0x00000000 0.0
.rdata 0x0012a000 0x0004b9ae 0x00000000 0.0
.data 0x00176000 0x0077cb40 0x00000000 0.0
.pdata 0x008f3000 0x0000ced0 0x00000000 0.0
.vmp0 0x00900000 0x0038560d 0x00000000 0.0
.vmp1 0x00c86000 0x00c072c0 0x00c07400 7.97682380073
.reloc 0x0188e000 0x000000c8 0x00000200 2.19341914113
.rsrc 0x0188f000 0x000001e0 0x00000200 4.7763773136

Resources

Name Offset Size Language Sub-language File type
RT_MANIFEST 0x0188f058 0x00000188 LANG_ENGLISH SUBLANG_ENGLISH_US XML 1.0 document text

Imports

Library bcrypt.dll:
0x141728000 BCryptFinishHash
Library d3dx11_43.dll:
Library d3d11.dll:
Library D3DCOMPILER_43.dll:
0x141728030 D3DCompile
Library KERNEL32.dll:
0x141728040 GetProcAddress
Library USER32.dll:
0x141728050 ScreenToClient
Library ADVAPI32.dll:
0x141728060 OpenProcessToken
Library SHELL32.dll:
0x141728070 ShellExecuteA
Library MSVCP140.dll:
Library dwmapi.dll:
Library WINHTTP.dll:
0x1417280a0 WinHttpOpen
Library CRYPT32.dll:
0x1417280b0 CertFreeCertificateChain
Library IMM32.dll:
0x1417280c0 ImmGetContext
Library Normaliz.dll:
0x1417280d0 IdnToAscii
Library WLDAP32.dll:
0x1417280e0 None
Library WS2_32.dll:
0x1417280f0 listen
Library RPCRT4.dll:
0x141728100 UuidToStringA
Library PSAPI.DLL:
0x141728110 GetModuleInformation
Library USERENV.dll:
0x141728120 UnloadUserProfile
Library VCRUNTIME140_1.dll:
0x141728130 __CxxFrameHandler4
Library VCRUNTIME140.dll:
0x141728140 __current_exception
Library api-ms-win-crt-runtime-l1-1-0.dll:
0x141728150 exit
Library api-ms-win-crt-stdio-l1-1-0.dll:
0x141728160 fclose
Library api-ms-win-crt-heap-l1-1-0.dll:
0x141728170 _set_new_mode
Library api-ms-win-crt-math-l1-1-0.dll:
0x141728180 atanf
Library api-ms-win-crt-string-l1-1-0.dll:
0x141728190 isupper
Library api-ms-win-crt-time-l1-1-0.dll:
0x1417281a0 _localtime64_s
Library api-ms-win-crt-convert-l1-1-0.dll:
0x1417281b0 strtod
Library api-ms-win-crt-utility-l1-1-0.dll:
0x1417281c0 rand
Library api-ms-win-crt-filesystem-l1-1-0.dll:
0x1417281d0 _fstat64
Library api-ms-win-crt-locale-l1-1-0.dll:
0x1417281e0 _configthreadlocale
Library WTSAPI32.dll:
0x1417281f0 WTSSendMessageW
Library KERNEL32.dll:
0x141728200 GetSystemTimeAsFileTime
Library USER32.dll:
Library KERNEL32.dll:
0x141728220 LocalAlloc
0x141728228 LocalFree
0x141728230 GetModuleFileNameW
0x141728238 GetProcessAffinityMask
0x141728240 SetProcessAffinityMask
0x141728248 SetThreadAffinityMask
0x141728250 Sleep
0x141728258 ExitProcess
0x141728260 FreeLibrary
0x141728268 LoadLibraryA
0x141728270 GetModuleHandleA
0x141728278 GetProcAddress
Library USER32.dll:
0x141728288 GetProcessWindowStation

!This program cannot be run in DOS mode.
`.rdata
@.data
.pdata
@.vmp0
h.vmp1
h.reloc
@.rsrc
s>}POw
kt%QU#
tNRyE~n
OpenProcessToken
8n$VcHf
T<V'%l
'V9h4\]
($&6Nyj6-C
HP5E5
q!iwHvj
ik6ER\n*
O}xFiO
p&9BI]C
B]##IS
aA2]b5#
# PR\,
;&R/]-)
E;9ih7
e#t+QC
eM^:sr-
z#OQDE8
h*^h[#
I~x9BD
Ef}T5N
7&}10o
Q\(ImC
iis1FZL
`5J<Ie
?8J"|y
uXx+My
N+$]91Wo
7$'xx@9o
#')dp_Z
BiT!:=
QS1Q"0n|
R)6[)K
W~4y=h
m1eBD1
l8Oamt
+S)>>U
p^2X!vi
{&Ik~Xx
<%uE5Awi
,FiH.f]
9vgJf+
1duk^H
AI`%gf
3o-,O=
;>}Q)KUVS
gz(3C&
hN:Rxl
jb%$Bst
sV-rB^_;
xm9x7;~N
]dDh)q
!e$d&m
(j~PqEB
c%>W@Wl@
P4|,?A
]ZxDlK#D
4:pA+7
$,%JQ5_
jpJ/>/
i?aZewgf
;= _u8>
FP~$f1
$f-0[Lm
C6wLXX
,B(lhR=
7{4C$;q
3,s^p.
Pj#n.1
uO=|`Hn
Y#tyQE
mpcXcA
$M=q]p
qk~8a4
B;=j+:
n$*aSg
s%+<Se
5@x"(o
w3_q$'
P#"D@)
wbh8*0
nl&6K*
rH<z5@
etcm:C
nJ\EiT
I1).Dy
wF%XZm
_vzsy|-
10Rt%7
.@S{q
4Henz
jP\~i7
-9Bf)F
% -i\|I%
&"15p)p
J`)3@h*
smm?ly@1
UD:#O!<!3
><Tw*8x
9o+6C
CDv[3
Vt_#Y/:z
I22L:%ZXEp[
6$CRA0
j`P1hb
ONgAiM
:Y6Q`3
J"[g &Z
rO}fb.%
)v4al)
*L|2wQm
;1V/OT
S#QCO`
5D; N=
:Mk_V^
dsH#8=*
"M!z4 ){]
"p|pEJ
?)Kr;d
Hldq`e
]u9>>D
XjyA@=
9Y3_ d
]&E\]f
h"]m!3
-<e+*r
3BW'e3
K/"E<K@.
ocC-^[
WPGO|#bR
{HT(s[
I+"0Mm
3b*Q\g
UuR07V
G.Ks-dUn
W.tjds
T6J}W2F
)u>JXC
??0?$basic_ios@DU?$char_traits@D@std@@@std@@IEAA@XZ
75''F2
WTSSendMessageW
>g[n~y,
.cD6)*$
H3s8j"
)S5Cz
~,iWdd
kd<%W&
S~;)^(
S#(URN
5MEg+w
>8j2u2
owxJl@
JGt5PeHp
-/Uh<I
=Xt5jN]
~2x&`~
4~s|Ct
)/Qi7!l
/9F,wM
-'V";f
_+&4=~
y>yCq_
t2RJu~
M"ijznc8
_hL#)yj
+9N3@l
u$rZW-
IgF,y*
wKziZOhPo
un>\a2
Q\fU Q
wZNM0<f
8^SRZ2
{:mAf2
>A?*K[
U_%4/;
}sft,)
*2nC_sB
V!:p}:!
ff$!Ms|
oCfN&o
6$PjLZ$
($zPRD$
Z<{r.\
]:`/uXE
IQQZUJnQ
uU8|0(0
*%HO4 y
Y8.K)-{
!AqFDS
3R7;Dx]
e3+z'%/
`R6k?G
'w0f=p?B
;j]~!LT
gc+Z> v
]]+Y\J
3\Fp'z
X\9*&d
y'ncgU
5uK]#]m
]E"RoG
]lMN3c
GW'q$c`
LPU3BJ
+HUa#C
f<FW_i
pZ\wks9
,kj9xW
przTx(#
ShellExecuteA
#fI3~FX
M0B*uC
_set_new_mode
M.K5.9
fz9JqY:
n<(x=E
;@gGMi
Q)m[{9
E9-$W}#
p0r*kz&
HUCfyI
=i5cX?h[%
DYeS6>
/AOD'Nz
t\w0RJ4
ydA35H
/u9z gO
4"P66g
L1($T"
fJ Uy
-CR<4,
2g<DE&
]U!6=+P?\FV
Gs{5wF
4+t!Q<
&8>DvN
UnloadUserProfile
AF'rA2
m]'a47
R=-nmX
;kIIO
sgDBf0_
7g%VG-%
NSI0o{
2}U}7v%
9~wsO[
sZY>lqI
ux4V,3
eE5|zS
,j.=.U
t((-9I
s=_=P
Cag<KI
v\,)j[oI
b@I.m+3
yGoyI
/Nrp@PA
o*8# e-8
8II}KF9
umk|>
5~=]E*
Jk2tN=
f,Try&
oDr5ijj
V$7gKk
LocalFree
}MQI}n
knUK}uJ
VI}zw&
|Oo;QqO),
>;bJ}P:
-BH}x1
B+@it[
4);h1"
KaUZd
7w[aM(
^TUYU
RomYz
u:<9X!
drlqAl
D#o#x1
w$HMH;
@E84ES
-LQ$e8<
'1p/G#
:"UHO
aVmo(n
q$IF+Q(
c(sx .c
mdzhC6
XT@pHh
j$cnde$P
?J}`yMJ
Cc[}@%
HOR(M}
mU69lt
Hn\I6p
CGYmG3AY
6}OY4
K'8#>Kx
e?.;7O
2Yd~2-
-@9Lb4m
7mzr1<
DwmExtendFrameIntoClientArea
^+9Ozz
3:Xq/M
N@bf^'
mA14J)
j#MtG%#
ToJIfO]
"B7uuz'
$EGKc\Qm
Mmi#<z
:zI|r@
[zn]'xPx
-yh.6,+
)^Zs#M.
lQ2gxs
!|iwE=
",w90
%rAKi?
q*-g0FA
RY@4dn
?c3y ]r
o-EhfM
\o|BRPR`
v9'Y0W
G{t2Qj0Hg
4<lgm[<
x'Wwx.
%!>&C8
i&;["X
#F]_2G^
qFv+#9D
HNf{6x
q.w@#eO@
H%:{Wc
T4N;mj
P|zUC:F
qkTQL*
Do#32T
Q*78uz
z}!m@uH$
-kbg",6s
T@)@I?
)zkaf&
.=6 .p
2d:rj1
VP &J{
8v(`P*
mXpr"A@P`
sEu@Pg
3H6=Yz
A"cKKY
/4,,sN#
Blc9mx
kYgoX*
yd5mH
KIFgJT
_fstat64
pLj\n
*87G3Y
%6(m#:"
ev *Z@
VCRUNTIME140_1.dll
A}D4#N}wq
+{0!~c
NH'CB8
2/SS<B
OT4LD`;0
}7yq)3
)<Q3mE
FlAn?Q
kCR*$C
'#kff'
zm+sIeI
ImmGetContext
ofVR!}=
M]m Qx
}om|v6
~zK14a
iG`$z
Vjzf+2
=w?6N2B
nco$}Tg
m$(UUj$c
QTj$v*
q$UXPv$
HPeY@GP
q+5Fp9W_
%}$}H`g$(#
ghn\!}
.<!M_P0!
m.sx9m
. +,$\
(ii&B:
.MKIU63,
<%N9kb
yPnYv9k
3aIM"5
a$|Kcg
IdP7+o|c
j$vHE`
V=g65\
;]W:B1
{Qo`%pC
.te}ge
gKuWM:m
rnr2Wm6
m$<a|j$
D3D11CreateDeviceAndSwapChain
K:t\:r
QcL:Qj
vT,YG\
:+f]8n|
;wr0U{
GetProcAddress
"$p4f\
Q}k%^
H{=j{U
r\rPbW8
J_5b2Z3!
C|fX8'"
19Sus+
7-"af[U
Bq9$vK
xN+dIu
ox<vER
0u2!]]
{Haa48
}<,DGe
u'<xHB/
n+9MH}
enw+}
/ h[3P
s<-lIN
"u9dH/
&#eIzN
&x?:tN
jSc mQ
S}@JksN
4=f)'R
&z6N`Rx
umdi|i
/Muw?KMir
*Cx,>Tl
Kju]K#_
g~RKraf
fTzhF0
PiP7&e
yRsr*
9}'yh8
t\ #r]
8YM9*j
u4#|P[
dW3u-x
|N%:u
9F!pWFS4
4<<8TDk
4HhH{fF
UuidToStringA
M9I{jh]?1
NlpD`wD
\GuUfY
ft_.\n
kRY'cp8'
Jk}:P;`
VXF<)0Et
&,cfrt
Po!!hq.
6 nF4RQ
<5UKzCy
PkXU(n
(`,M?R
]0@IL*
nd}aBS
u31Pdfw
6.+_dx
6xziaT
l;Xx[|
_j_cUQA
ZU*!|YT
qj!I}dRSI
D/&9;~J
$ T&CO
Ba\_9S
x$98Hu%
E*e\>v
8aHxdN
!g&nAk0
9^y\_&f@
K:#$8KO
zr}1jX
Dd`AFKQ :
=Z^H<X
"g>FUuJf
$Wmve@
oyX&nz
~{FM~wVb
GetModuleFileNameW
j.`G'8$v
.-G.NA-Z
YUVROM
sOTcr0
UT~H2w
p+"42;
qOWZE
jECZ9
-u-TTx
:KQXG<
VO2*9{
r%_-d-
[v?6I~
/k$tq_c
z$.M/]\)
.Cp@r'
bi*9Ks
{NNttr
l~LNRx
lH|Dlf
'HM<X&Z-Q
c\mEC|4+
q;w5|
FD:VIu
Nk{|Dx
?\&eyI
4k;W/5
N'.+5o
q} %M&-
90%i,4'%A
Fa0PL6%
Jpa#DH
y1F4ET
\K^v*k)
)"ZGLSM~3
M]zu}k
jaY4^
;/j=,;
lTz8Qn[
U1u>oi
cv.N->9G
H.o[!g
h/?1$$X
G4#,(x`
/.1Q nHx
~1i}M*vW
/$&S5V
GDS=-
`^</JS
I7Pgx|
n?N]B9~
}M!&}0
q|/ u8
P`Y:U`
GQKe3D
mOT&S[]
!Qm^PJY!
3V^M%\uu
D3DCompile
;,p<'O
.+_:Nq
W[(<WQ
0I|t1a
h$35b$
&FZTP<
kf\N}R
B7BOH PN%
ph%+DR!
USERENV.dll
r>IgI)
&wAWuN
_.bN{m
~|Q-rK
j>')%%
wSk4<W
jQ2emj
s+e%+
%L\=v:Z
WDBu>i`
`*mG@Rh
OeuJn
R4zg.+
n'RaY]
"-!A:I
],j|x1,
GetUserObjectInformationW
Y:]}-\A
[1iOe8
3,zsBp
0:YJvJf
3Ag"3<
*V=\.*
W<x{~;
iSPJ3:
QonCj|
h%ulI#
ZS@FVy
G<wFh]
3}Ase]
kqp>EN
T2^_Wk
$V8{EN
8mW |+1
+TKt$I
(36GcKb
_wguR.ct
KBXkb|w
LoadLibraryA
__CxxFrameHandler4
tqaPKa
.KhudsJ#|
nA8z+kE
+-0d2:Y
&w:o_%
Ep'hip
}_11%T
(LZ`'u
6}q$M8
~7/zfs
dO$GScf
?wITF
%4{9&TmFK+
&LaodzYl
/O}.5s
w2#Op
]a\}.5s
Cpr68q
Q'b-kD
q5AtQEm
9hLrLlX
+>ZLs9~
e;?YN+f
x3'[;s
uO*9>YKP0
XAH /P
W1-vQQ
2JXnkG
4c]./<
6+"$c!J,
77l1D2~
<Q!&UD
-_Bzz,x
/<CuXYzu
(fXl|y&
/,`U*}
*,grIx
j/Kf3~
BXK)'t5
f@vOu=
:\u|6G
e$`]"b$
g!rfL|
%%i!p0:D
-m)5#+*
D7~e$g:
L]})H>]
tLMM}o
HkU ;"
7>WUZ"
.u"*)2
:g^uby
.\E2x_
er(^\]f
\5b<W
Ii_jn^P
cSHELL32.dll
;ZPKmAw
6suxP@
B`(40!Y
LW&R> {
vJek(;Q
3nTuL&j
<C0eQjR
++&zGSX&
^k$"tx
W{R9F
api-ms-win-crt-time-l1-1-0.dll
@a%rZ@!
"L>KRV
;|T;a'$
f$iNkc
J|$Vzcv$
j"pw$p
PY>01m
8qXmxY
Fsx[qC
@a$18q
vd$p|_n$
<HMOS0
USER32.dll
=<*r[]
;;V6n
26o{B|~
`1FX(97
xsc`9E"
api-ms-win-crt-math-l1-1-0.dll
-CvN+,v
_^o@'xJ
u"B8fT'%\
.D=_Y"
{1 *=C
09tL}&J5
,~sbDA
}odaXZK
)gjm@(
-NGJ9,
WLDAP32.dll
r;{"3C0
<UsU0F.N
krRLw;Lv
f}<p];2}
3XQ@{5f
VjTp{Z
LJ@!d
;(uEZP?
VbI1_|
B[^|$H
Qu(TL^s
CKa/Tst
ysTx5]
E=ZCD.&
p$F,YYA
Iv%,m@
,|/6=D
nG97'm
vHiQtT
Q{^tC.
=2i?HW
$s0Tk{o`oo
IN/=_t$
8 gXhp
^+S|DyG
>,R~1m
-QL&,
oE1g(c
'%n]_pM
kkv)XG
W-q$>N
Ej'Z0,
7t1w,g
[:J_@
b*C=a;
;.Of~X
Z9 j4K
vadYcYw
3~t)C~
$>tK=\
=*,o*\
~Iv{Y$
M6I}prr
=IdAY2
Ej$;v>e$
VnAHEP=
rVw].3
MBB!K/
U&w9to
cpNLRv
U*v&J(
V^7;G.N_
b^5H 2
DTJD;t
^W(K$2
api-ms-win-crt-stdio-l1-1-0.dll
Rs|*C?
h+hTT
%x^\!)
Gu v-B
cy 3@DS
1vR+}On
jlZ!-hl
LocalAlloc
ZP1 8?
CbZk|%
INuW[R
wECMQKh
Y9_.8ob
9_.8T-#
:#"^240
C\9A,y
YK*qm>U7
qrHRFtn
GetSystemTimeAsFileTime
uS H-U
j:>o|+Y
\Z@}pJ*
2^Pd,F
#~G@@q
t:h>ze
?Tj4XL9
j]J%s1d+
Q(r6@k(3*^L(l
$<|+5!
->/8:,{>
8Q}K:JQ
PO0OmD
=ae3;
^Hpg%G
-]O`"wD
CuqYb@
qB&;NY
9|"v8~
k-0U~_m
5yB4ie
iGLT'i
~'\2{u
%fJ[`%
ag4L X
./0Md85
Z9I~B+
u$x$*r$
t$cz.
V*Q2JY
`D#n."
';d\:G
lZ{3O%A
3$p}>H
.B :n
\*vYf
vo_VKdm
xv"Scp
PSAPI.DLL
7x9js(
z,C^(s
V;suzv
=hIKt{iI
quwoUe
]KJ^dp
Vwt]b5&
Hg]/0V
s!<\/(
0TFH1d
)v~QA+
aO<%ib`Y=+
QT:2![
I|y$:Sx
uu$}Q\
{$C8&r
X]@=t6\C=
JkYRE'w
C|4>",|
"4H91 ^
nce3s
QD:5P(
A)7!!fi
ibf;/HJ
@&~R'qTH
ywj!<g
zitS`4
4sgRx1
7siXQJ
]9<W>b
?;Q:~OvZqqO
6zIbru
nD{Y"i
1LT-rkg
yX@vzU
y%|%mR
]0vm$W;
ho$6F7r
>G-I)*
nA!8*1
uZs?Ot
[uNodQ
xehTe
pcA^XnLz
uSni}!
\J{T&C
^$tp]1
%&;ywh
m+N~WPZ|
?jf(`d
d3dx11_43.dll
ontUyl
F?!b.&+
D7E}5(
x';pUA(+
igD B
OG&s?/n
#q@U-Cz
?DZeo,
a#D$=Ni
a#D0q(
onrN#
B F`&2
pEzeVHfPq#
9yy`kV
4kBK"}
CDFl=`o
"oTdg$
Q\(_,H
JrYL^
Uiud"y
Za<l5\g!
8`p3;@U
6//%[x
xLnfi!d
-%0t+p`
68uy`>I
%u}m9L
Or5x_NY
QpL%zW
/Wr$2l&
i'+{.y
er@IeP>;
1{S;p+:
[D{w+G
d,s{gFR$
t$a]9s$z&
})id8rD^$
z'YYWR
<zZ563
=T;=<4*
itUUeq
PwX['2
mUMV81
Q+'uf5
fclose
OT|,yE
IWAGr:
e7QrK
GetModuleHandleA
lsLmY(
s$/b't$T
[NOM[I
@Qbc(%iC
Uo`n>n
yO\%is
xO\%c4
h$2?vg$
@`5A+e
t;=@?0Q
G:~$f+6t$
p$N$d|
l$q>{FA
'z"z$l
','z4u
~fl4q
api-ms-win-crt-locale-l1-1-0.dll
p>cS.X\
'%f86{5
'K$hBX6}
rvnHr&1W
m 974|e7
%K4<9Ao1
|Ti+A5x@-
NNzd8[
Mn1&mL
tk56$Z
W*KSd^HB
Wa5[!tv
KR!,-_e
2B+<8{,38R
n5c8 H
L1_Ch-
>RfwDG+edK
fa:5`*k
1%.w>*
H`.)R1ny
P`~mc)n?
JsK[qi
&#eC}G
CWc"mXe
fMua8#'q
cfHc%
e[})1OT}
qo)`\J
_-vPfiG
f[-DeC&
A9O|yt
_ue*P1l
K54ETI6r
z[y=n:
&7@_T.5p
y-YFu.
:7*pu$
31<2.o
)vqP>{C
anSKgD
=X$%_P(
5/<MfI
]>:ugq
j|Kq<u71
iMUK9z
GZlflx
E{]|*
GetProcAddress
au}X;L>A
z<>cBO
|ag'E<
JtP9Zx
sj;lp{
'/2G$]
R2$K6Vq
_j_JL2&
@sQp;?
deC3d2
_'FsiK
@=<YAsL
:8'JLi
")3<5h
"Ca-ely
'}^_SVx
fq8Z*;y
^HYvaxG
Bl$$y9c$7
-/+#g$
:jg<l
srr$XAv
3u9^yfI:
api-ms-win-crt-convert-l1-1-0.dll
0Ry$m
jPwn2+u
|j,CL:`
kZ!8WJr
WjU/3R
:-_]qw
\UgT-<^hG e
\iyCJ@
x:Y!eL
UcYzC(
Re}&dD
B*ixPo
KL,ox
_XcX0#
i`~A0fzo
,6ILNqS!
I,ZiE`7
PX!>"6
g*: e9N
Uu@d6]f
aA\k.\[
MZSh7Y
v^o"wHL
b*ZZM+dN
j.~wBXB
~En<)%
-}IdRP
1#RF2s
0>M]fZ
j5x4~R
FIIj!(c
f:7_Ke
:L`Gg.<@
K5"v'(
J*#2eH
mY}cuZ
|wu`':
U#/$&uUl
>Z-;~w
PP,N(n
SpKvxZz
ldpAkb<
U_ush6
3._Cgs)w1
i)/%$zz
$t')FW
O;xjsp
Ux+@Z<
D\u"=4~
enJ8Rt
UH" Gl
<U Q10
@#jm>4
gwdvKZb
V(lq#\U
>!v*lPx6
qtLC|Q
LpDu`|
v2D,IME)7
/Vql!se
LM0g{!
b{/[}f
{Y 5A8
\OT%vX
6t*tE^
c<-b18{
|[="U?
zx$Udh>
d+*u&~K
?@zN8|
y_J7#`q
hgk_ZP
K!# Dp
nAF(&$
TP~IEGE
hcz<{2
rSQcP0
?56=9cL
UWeq*WU
D3mVy#
QJ3_2s
R<=6;q
,qG.ZK
oH*{@xvI
{!q2Cm
$xLt@h
cjq0S
$G-|#'
9c'IF^
2m@vO<
zaC00^
%R`H/l
/xl"Sy
0"Q4Na
+6xobBu
Iy9JaK
rOf*XA
j.3RvY
dpg44+
spTLHW
&JdZN1
O;q@R<
PT)m^c
'51Pu~^1
yf~ea"
RNI3;p
'`mW!X
]\X&-F
(5N?L?7_
f;ci8n<
pYlFH2
yM2xPHr
b/^sMts
gb$q+2
xJ8AIf
B0l@S
YK/^VS
h6dT]]tg
-AzWU6
p~~v#3@
rH[!XQ{
1g7l2ci
D`|dP2
._+um[
QJ3~/3Y
yzWe& N
4.@In)<
tl0T,6+~Di9`Z*
~/AqiE
{'Y>s^
XP-HA!
xoPGyp
]}:%Eb
rQt:LLW
,i|V |
T_K=@E)
n<GL#f
g]q#`3q
Og@oJT
}WX9p1
.Bu}uC
"zY}@s
Ub"L%D
x6h^^&
L}2TM8
5t_s!(
Uw]ASx
@$nU`aN^q
U_a)[@
&Zg-^s-#!
z"`{?,
Y?gE40q
:IlssV
0=Rkpsi+
x@N%Kct
^J'1au@
??=.,E
&&TD]
`>r^v%V
$hUL@ds
hc97Sp
5lhE%s
k2=}}o
vPC3qS
w.O:>8
X<r^&>x
\)T~}Qc
)X?.s0w
HFv5d*
[cZctz
MV9fB,B
o`J$ 5fH
<"53sn
#$dX?V
.fkx2C
1C}KOK
P3*Zu"
N:{xlldt-y
gk+ W:
#BgmRy
i<WT|0B
Johg9=
0Ilv2O
eAE!&-k
\0dCq*
fd^\Lom
8(od"53
5rn~oY
ErKJ~Q<
P<C%bG
)XP_S?
<p=r'*
p!@! YJ
Mj~=YTP
qHh M&%
I)-%1O
;s4lun
RMa&Qf
D}qTtR/
`k[Msc
'e#"+x
|^ZY'L
Kqf[7"
@ZgFW/
>$uv.Y
eQX]{.
D0O!g
c/&qjG
G_2*Hh
'VsIY6|
nq1"Ho{
(:d^FR
NmGPlfNG}
i"0Dg$
f#IOdk2
|o5i-X
8La>=m
>ARNO8fz
5>4mjP
p0Kxz3
8-?5S_
L[fooh&{,
q$)uCv$
Rh,CNd
RPR#PN
r3A@~q3-
KWh&4|g
-k$c,f
*>w3}k
$("QSQ,
Bzkf"X
#BZgQ8|
SF-KuRn
{7)z;]\
g|IB:t|nxX"
T];Tx
Q@R~ga
]<)[5U
AxS(~C
Hl:t>5
9.Ijw
WPf;pZ
1K]^h1
|%Q~z.
\p8(q;1<_
_S2u$\
6!aN9c
qduA8l6
[U 8=,
1$\?3K_PK
p38$u}
XnAD`f\$|Q
awn$VZ
4sY3":
!N3=z/
,-?clg
IdnToAscii
*HfcM?V
OJt/jZ
'."lwE
.V'1zo
$Q^_7)
V;3zy?
I%!Y68J
*jIMM32.dll
I0=%up
K2}%w,P!
yf~}}
MA -w/
SetProcessAffinityMask
Y>f6F6r
y:F4n6
HX3vE,
5Y:@.&_U
E<4q1#
[mcy-b
6<8+915Z
-$zP5,
bn8r{G
Tg36y4HjV9
]pasUt
9e9`!F;
)fL:ne
/Gu,/4
1tzfC%
_(n,Sk
j@jHA(
*Um}~W
WreO=K
(qKMFngj`G"V
Mq/zI^
~1hN![
A?oh0'
*i?ax%
/`ny^r\
WX}=U}W}
r]=8~]
F;qFPq>
`id.8m
TEZUbzB
SeEhhZ{,
nDX:KZ
I&(wVF
KERNEL32.dll
=ZEEg9c
((MR}]39
q5!hCw
.?Ci x
]psA,LW
AV~Qee~D1
~Ozuux-
7HOL3J
hMd6A4
<=mk=H
p>%<x`
zLOKNE
yqD)A'a
hn!V-S
qC9k"5m
"#{.p)
<SKS1,
D/}k%Q
&cywQo
xDY*Q#
`&Gac,Y
c5+~kpw
bnKaoR3
kbRWQz
+i!byef
v[0WP:
10U[m&v
WyvAw;
rw<H>xbU
[%>3*1
% 4Gqbt
$Qt3[r-
HF[4K
yk!i^
E+gTZ!
A){dGR
$Z{Y>|
y,d*dwK
6Ne<K?
eFn|pE1~>`
#H1+9v
1=RlZ-
k/sp]@
SG<Y7
lTp}^OCp
{|K&%}
na\~.N
$]$UI.
sAvD69
a<KEy~
M__DTI
|n)lg7+
rkFJtbe+
+.M)~Wg
\7(wsQ&
X{ar*=
#(sx'*r
^U1BG\
@DX\v0
G=~6h'
(-FcT]3v
YGEHdZ
{oB~)i).
'|g*&J
CRx6MEDY
%ZR.\s
w~$Kg<;
23/ic
Uyqfly
)6YG\X
R"rz#w
@.j #
xA[OD/
[{|:6>
mYX9I!
<-:1l#
Lf/IF+
X^~SRCsv
.tq`J|
J)yB=A]
=e}B#m
1jsLF9
t%IQDC
> (MM4
h;erC|
k<Jf07
kqIw=wm
%-~3M4
O=&qT+z
}) c3-
C9Qg;F%h
Pu=jC
SIdilQ
"GV<Qaf
RSBzU!3
1R4={c
UxmbtW
JzJ`3jXo
(-ay0<;@`
(})QwSS,
3tBI&_
F9(OUJ
JW`dw`
g)].3j
e_Qk/{
dB9~D/
^[:kvA"
U{_{}(
3@/#3C6
#/K<gA
Zz$s]
YpV,BsD
l841$JQ^o
nOR?N\
L)cb*z
@F xGr
D^!,}1
\o.;U]
RYs`[X
ia/esE
53cahj
Iah}Uc
4{O/rq
LNhe%&A
a{V`-# %
(Kq{.ub
b%%OBz
IcVKj"%
_ H$;*
S#i'7|
Ag^bqH
+:DbK%Dk,
XW8{wm
Y9'*4TK
(cPvXP
U":krH
5Cr+~J
@e])k
OMBL>{|
MdB]iYxn
64W[^|
BAi j.MS
kIcJi#
!gn^]X
8AQ9Q
0"<z9@`D
oaHhq{
]DQ&jMB
(^S#t_
4MxJ~[S
Dv/l9n
N5txh]
I#]vr}w
vT$cw?
;%]F4Y[
q8h8nX
pk\ZQeE
D{=z*+|
zzU{HP
;\Km8'
V"H)~~5
us?h%#%|zACpt
(Z_,!*
)fBO"JbkJ
A@zr&r9
V^f32p
[uq2O_
|$m8{/
x|g>f@
_U;SXU
5\OyHS
uC(v7UU
huJDA
h`{Lyx*
fjmk]^
7`Hq)]
+XL8,;
){48L0
>F7-kV
a&;a|
=c\Oh#6
G[y@kJ
n?zLd(+]
AyW:`
xY\C=
U*Fwoa
,8T}2c>7
n]hMq`
*Tguc0
&Xq54(
vZ&;bq6
`jr^{0D7@>)
b*L~-=
6v^7Qn7*
Xhuxna}
Dg_d~J
K.>>ua
%2/K=F
_F)}^-@h%
Y+&ABX
@Opocb
bs~c"OT
OV*3:d
hKE1+K
YB~i7>5
dc %~L
?`?!Hx
9SmU n".%A
hr5 OvZN
|;&u&f
P<^]rY
HBK 22
I}jsK|
moMU78j
k9hR[4
H~HRm54
XqbB:$
6z*qE*
Z:ViA&
b,lzxl
z}m38|
,,M>4,.
6E;{*%
m~{B`a
<fPcQ/
b$"<7j
*tFQFU
<Op4.g
4bo8X`+
$!y1{yj
'Tzhs3
[Sv @Z1c
}IW1f!7
Gi}W0~r
4064.N
^k+y"Kh
mJ$=APU<g
{Iu xia
<,6mLC
N#Ao3Vh
x0M[.b
&"}?j
XU^cWOkD
lZHpMyQ>
.)Hx$v0
|(6sz[
iJenq=R
MRSjJ]
=73AY}S
rmD.QI
;a%9:N
Fds~$C
:.p<!Gd
r3h6z~{
B[vJdy
U$kJ08
V)*M\|
(E5Mhl
UD[C8%
1"\wt[
FUT\MO
'H7k5^
E~=~8jL9
$`Sad^@
'X{`4j[
=33Vvp"
%4|QEB
KF@R:[U
Zxd/|H
EJ#q8m#q
FZ,4^2
!uy,LG
V}08bF|
ZAd@-E
OHn(l<(
1wW+;0
.)p[.l
Ny0U~]
R0kHEK<(}
I:f,eyj*
3x;?R$
uP68\i
XO)Nxb
NnBYv!
K 2x1H
)ZJl4B
afo2&$
H(JJ&
P1QIH~
Rnq+vy
N'-}/;
`rLJ[D
AA>8)^w
NT_VB&
4@iEmhI
29@HVq
(Xbb38
BP.nID
.ETqb~
"{A~2;e
m|<4~&n
2|JMM9
|})(Hu&b[
`*S:6;x
G$IY/=7~
&3t8vF
[=L's.(
8f#q4%~FC
?51y=t8Q(
|F3yw$
OZ}g~%
X[k,&A
e&>_I&~
uLgM(A
$gQ61k
~q4+"-
9~UEDa
<w:SI0
e3vU);
em#P6^/
ne!%Yl
fB>bj@c
-BAG9H
;6N1Ah
HeFAIf
SS!DcM
xeStir
w{y+Rp
esvMC
ardTE
GSt5b(-
%t+"A2
r(H(Y\
.0"|h.
Rv,)QT
._/ttt
X&9K^9+Y
WFV|IT
l<R#^F.%
,Dy\f&
T;_QsCC
lZwy9
C[fh&|
^"(b~2
*X{p/1b
^?{MBd
!X0)QV
b\l9OmN
XZ'@xP
dhD.8a
"K1HCnl
A(;#S$
E&N.t@
|0?_Ki
l5HZ#J&*
#g!]!hW
w yJDfC1
/>>6M.
Su~P%~
rm_'lK
q\8pZQ
{od{Ri"
y`+#[{f
gwl;^nZc
HNGT2*
& j+"x
f*b2>Y
#q1L[t
qFx'~Lq
#<qw,u
hsS`A*kq
(P3O"H
30XUQ<
5m'X|bz
b) wtF
i$F5>8
|Ev!pTT
jFB=XJ
G+=`o(
Qx/"a\-
i]yoO
O;a7-&^
mGxIP6
$[ev)5a
x"\FEi
nv4Ohw%c_
bZ;V@1*
]7wk4#
"kfe":#Gb@
[5k`:c
st[_$K(x
7r)tFY
_8P:W$n
M@G7W;
XC0W?M
FpL}3'
R>{drU,
&cphAC
@fitxk
bO;~zd
LAAaWR
P"*2=v-
~OKM]a
do|!-P
*yOf=e4X
|.DKgz
5z3$+Q
r z@'g|
h`Z$wC
iBUhG
u[+D]h
*XB^Z6
)uh.9R
zc#1?n
C"%W7yz
4jIAcF
WY/bV3w
<X9e/E
)C"=w;
=)yG/h
|I &BI
=bf<?@;uP
^:EP}E
aLj8^e
,H'$51u
GmE4g.
6d]Z32
7: j`M
0iMc
4&Zudo
2O`47{
d:/F*`?
t2Zsl@\
+NpF4
<QvD7h
"[Nf|US6$
ZBYA;0
b`c/Iu
nOS)'#
Don9V/
ta[h#d;
pn)xgN
=9vpUI
lYq?bFj
!["b`!f
Q<kIA`2C
^6nbdz
lKU]A%
iSx%aTd
k=JQps
T%bISR
>1_aki3
yh3 /O
l(&8cG
gOFoG
8q(r&{
/#N],!
Qvjv(2
+|~61t[#7o
>9X)Pc
sQ\$4|
FFj{r@g
F@@7mOB
W-lYFQ
,\D]Lu
+(i6t0n(
Tfi|T}i
~{I=R
1c9+1J
4F(V7-
r[jsCZ{
SXv[f*#
blpU8c
fGs,Kb
o)AJ"%[
o )!(a
V+1E[t`
ue|,:[o
C5[AZK
B%w /Ik
S\=bxE
Tpok~'
D6asH9Wg
/+Y!}R
#*WU&7
;gQA7~
!Fs6k{
^KcLs0Xv
7gMjYD
ew=NIb=
8?p;JO|
QLALh{
RwJ^*d
63gtV|
MA.rd
0P`~tZ
T7y {;
D(hKY2
b?(tzL
T.tn|!
uYkjj
N}QrUB
xphmNN
e#: M
8F])W|
e!Irom
|[shnv
]b?-#z
q_PTkZ
?<&[.t\N`
1QX@OD]'
Y;eFlk
<p^;Gm
NJoD(!g
<# %r$
i"Y|&|
IB8<=X
lA,xfR
V*}m$*!
sX7dj2
Avk5g$
<7NUgFL]
BAAwP$_
(rTuaj
Wct?0}4
F"5yM|
a:S5!A
Lm<,\36
i.g[jet
YUF+wQ
0h_SW`
wbb ,o
TE>lfPo
i +@9n*P
Y npfxa
`y{v5R
'hIP!eJ
o>vl{&$
a0dH~h
7;-6D0H
C3%8q6
>}k,B[
_@py-:
0%@";@I
/=i@Gk
WCb!Ovmp
~l)luj
_lC5,\
qYlK!wUy
RcHFZ=
Eal 8p
;$$jq
Tx`_z@
%#)^P"
USEw<}3
tfV_is<:
v_MFs*9
tb|"\M[
V\YGDN
I isq8sC^Hjy%
y}`P0a
v!o\tqH
o8Gw-=y
zn3eAF
=]SUf:W
-U"JH-w/
s4":O/
B&m8Mi
t1"">Tq
]~s\0Mf
)MF-d`
N]Rz7<
a'2,"pY!kOZ
.D!)$xd
*Zbl `H
x,ZLY?
S,\~m9,U
,9[~M`)j=
p!v<MK]
I.a[bBa
70IV0
pd(/hb
BS/i}Z
,ID#)^
EjDm~X
?~JjcV
FXCspxN+
Rv42x$
WM1gw"
Vo4rq9
=9+BG,
kF`0_7
^lR+XL
=K<0\P
`] Q\aNJ
Q9mz-@
,S@Q|i
xBc<R(F
6;j~B
Y&^wn(]
-@Q/jf-
vg#Bm;
JR0/|$@(
4R_t'D
"}~-$
GQ1Sky
#24GKF
u\p_0p(
\rQl%`
yUdE1j
Dk%\(lv?9I
w[X$aDEH
i-D,K8
]0hgZN
7QMsxJ
_zc0S^
":$'|P
sn,Z<'
WS}>l5
Z+[7B
C@ZtBm&
*3dH4
IAY+wD
hH=3seg|f
OK03xm1
IJAuW
Rn\GX1
9xU;}5
RAW"%$
14W@1Yw
wEf;hb
HS~F
buTTPP
DsrHM-
cf~zY;
wGQnU*%
XwISSst)
/e%@.?t
^gy^b8
kt\]qt
:&bv^=
50$#y=
WlW'%Q
hX@5b5
fVpi~o#
?D!I$_+
k]mV.^i
)=Du;L]
.%Q7FSqj|y
|j{m9@f
v9q^Fj
'OI>`j
jz^z\`po-DN
3<G_G
f&ZV9D
ayP5[;
n1\ad,x
2B0#;0
@Nccgt
"E>n6y>
jYMfla
z^7'_`
35yjx`
=$h398q)
OR#pJ\
h%<J6
[gX.4Zu
a&gC"E
'bqo<BMU
D@8X)]
$@Tu@h
`O`3Z
n+xhA@
/^E8H6
r`T^"/
)[|R)Q
-=KH/\'
oVjD&<
>>3=Ti
Kop%)j1
#SR&C5!
z\\xb^
K!tIH72s
g5:b*>\,
jw*P9Z
$V~[3]=X
g9LE?8
'F!jZI
zodeHf
R'11u=O
k5hAhk
"@mP?~75M
y?^SMW
lk!@8$
D|6j:a
EBql}f
*.X;c]
4kF1J7~
?Stuv^W
#!BrdE<
;MyG<)|
}n2L894
#Qe+Y.
||_755
Zd1i)s
.I4Uq=
qoS@Gr
*(}Z|t
<&r:2x
@&hF(m
)Sr0?,
9) `3X
zGS<His
mI5dT>
.NV[gE
}>$37E
@(=_oKhR
7B*9`qu
4O);]
Yx%F_p)
@SDLs:
Antivirus Signature
Bkav W64.AIDetectMalware
Lionic Trojan.Win32.VMProtect.4!c
Elastic malicious (high confidence)
ClamAV Clean
CMC Clean
CAT-QuickHeal Clean
Skyhigh BehavesLike.Win64.Generic.rc
ALYac Trojan.GenericKD.74390709
Cylance Unsafe
Zillya Clean
Sangfor Trojan.Win32.Save.a
CrowdStrike win/malicious_confidence_70% (D)
Alibaba Packed:Win64/VMProtect.6072c786
K7GW Trojan ( 0058cdc71 )
K7AntiVirus Trojan ( 0058cdc71 )
huorong Clean
Baidu Clean
VirIT Clean
Paloalto generic.ml
Symantec ML.Attribute.HighConfidence
tehtris Clean
ESET-NOD32 a variant of Win64/Packed.VMProtect.L suspicious
APEX Malicious
Avast Win64:MalwareX-gen [Trj]
Cynet Malicious (score: 100)
Kaspersky UDS:DangerousObject.Multi.Generic
BitDefender Trojan.GenericKD.74390709
NANO-Antivirus Clean
ViRobot Clean
MicroWorld-eScan Trojan.GenericKD.74390709
Tencent Clean
Sophos Mal/VMProtBad-A
F-Secure Heuristic.HEUR/AGEN.1315472
DrWeb Clean
VIPRE Trojan.GenericKD.74390709
TrendMicro Clean
McAfeeD Real Protect-LS!A83176090561
Trapmine Clean
CTX exe.trojan.vmprotect
Emsisoft Trojan.GenericKD.74390709 (B)
Ikarus PUA.VMProtect
FireEye Generic.mg.a831760905618a8f
Jiangmin Clean
Webroot W32.Malware.Gen
Varist Clean
Avira HEUR/AGEN.1315472
Fortinet Riskware/Application
Antiy-AVL GrayWare/Win32.Puwaders
Kingsoft Win32.Troj.Unknown.a
Gridinsoft Trojan.Win64.Packed.sa
Xcitium Clean
Arcabit Trojan.Generic.D46F1CB5
SUPERAntiSpyware Clean
ZoneAlarm Clean
Microsoft Program:Win32/Wacapew.C!ml
Google Detected
AhnLab-V3 Trojan/Win.Agent.R673869
Acronis Clean
McAfee Artemis!A83176090561
TACHYON Clean
VBA32 Clean
Malwarebytes Malware.AI.2137149506
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Rising Clean
Yandex Clean
SentinelOne Static AI - Malicious PE
MaxSecure Clean
GData Win64.Trojan.Agent.RKPPQK
AVG Win64:MalwareX-gen [Trj]
DeepInstinct MALICIOUS
alibabacloud VirTool:Win/Packed.VMProtect.L
No IRMA results available.