Static | ZeroBOX

PE Compile Time

2024-10-19 09:14:38

PE Imphash

f86f1d8dc6f11a3ff46c688154b1d7e2

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x000b9970 0x00000000 0.0
.rdata 0x000bb000 0x00026554 0x00000000 0.0
.data 0x000e2000 0x0001d7a0 0x00000000 0.0
.pdata 0x00100000 0x0000780c 0x00000000 0.0
_RDATA 0x00108000 0x000001d0 0x00000000 0.0
.vmp0 0x00109000 0x00380a2f 0x00000000 0.0
.vmp1 0x0048a000 0x005c797c 0x005c7a00 7.91760514073
.reloc 0x00a52000 0x000000e4 0x00000200 2.17387200185
.rsrc 0x00a53000 0x000001e0 0x00000200 4.76569929136

Resources

Name Offset Size Language Sub-language File type
RT_MANIFEST 0x00a53058 0x00000188 LANG_ENGLISH SUBLANG_ENGLISH_US XML 1.0 document text

Imports

Library KERNEL32.dll:
0x1404b6000 WaitForSingleObjectEx
Library USER32.dll:
0x1404b6010 LoadCursorA
Library d3d9.dll:
0x1404b6030 Direct3DCreate9Ex
Library dwmapi.dll:
Library urlmon.dll:
0x1404b6050 URLDownloadToFileA
Library CRYPT32.dll:
Library IMM32.dll:
0x1404b6070 ImmReleaseContext
Library Normaliz.dll:
0x1404b6080 IdnToAscii
Library WLDAP32.dll:
0x1404b6090 None
Library WS2_32.dll:
0x1404b60a0 getsockname
Library RPCRT4.dll:
0x1404b60b0 RpcStringFreeA
Library PSAPI.DLL:
0x1404b60c0 GetModuleInformation
Library USERENV.dll:
0x1404b60d0 UnloadUserProfile
Library VCRUNTIME140_1.dll:
0x1404b60e0 __CxxFrameHandler4
Library VCRUNTIME140.dll:
0x1404b60f0 __C_specific_handler
Library api-ms-win-crt-runtime-l1-1-0.dll:
0x1404b6100 _configure_narrow_argv
Library api-ms-win-crt-stdio-l1-1-0.dll:
0x1404b6110 _lseeki64
Library api-ms-win-crt-heap-l1-1-0.dll:
0x1404b6120 realloc
Library api-ms-win-crt-time-l1-1-0.dll:
0x1404b6130 _gmtime64
Library api-ms-win-crt-utility-l1-1-0.dll:
0x1404b6140 qsort
Library api-ms-win-crt-filesystem-l1-1-0.dll:
0x1404b6150 _stat64
Library api-ms-win-crt-convert-l1-1-0.dll:
0x1404b6160 strtoul
Library api-ms-win-crt-string-l1-1-0.dll:
0x1404b6170 tolower
Library api-ms-win-crt-locale-l1-1-0.dll:
0x1404b6180 _configthreadlocale
Library api-ms-win-crt-math-l1-1-0.dll:
0x1404b6190 ceilf
Library ADVAPI32.dll:
0x1404b61a0 OpenProcessToken
Library SHELL32.dll:
0x1404b61b0 ShellExecuteA
Library WTSAPI32.dll:
0x1404b61c0 WTSSendMessageW
Library KERNEL32.dll:
0x1404b61d0 GetSystemTimeAsFileTime
Library USER32.dll:
Library KERNEL32.dll:
0x1404b61f0 LocalAlloc
0x1404b61f8 LocalFree
0x1404b6200 GetModuleFileNameW
0x1404b6208 GetProcessAffinityMask
0x1404b6210 SetProcessAffinityMask
0x1404b6218 SetThreadAffinityMask
0x1404b6220 Sleep
0x1404b6228 ExitProcess
0x1404b6230 FreeLibrary
0x1404b6238 LoadLibraryA
0x1404b6240 GetModuleHandleA
0x1404b6248 GetProcAddress
Library USER32.dll:
0x1404b6258 GetProcessWindowStation

!This program cannot be run in DOS mode.
`.rdata
@.data
.pdata
@_RDATA
@.vmp0
h.vmp1
h.reloc
@.rsrc
Z#^!8J
'9"Nz[T
i+liqj
Direct3DCreate9Ex
e$3HI0
k)7f4.
|4Uy=F
MSVCP140.dll
hr0%`:
FcobX.
E{HKgQ
=yZTsy$
=rRKlY
7Q+Wz
/.QDkb
nN=<*t
U,cD6/oi
u0fAdu
:!gT!0
z\u3C]
/`y!~/?"
'X?Om~
r}J*dJJ
x9'_kGt
m:z)wpC[
/w/^0<9
`\PyOw/f
!.uOR0k
)po7pe$
Ma+?p2
xzAhFL9
>qh~)}
spb3!^!
h i?&Z>
{|iw9M
XSKv}h
_configthreadlocale
q7(Ukq`
S_d~z_t
sS,]oV
=M)jB_
{qDmqs
uA]o'x^'
jc/sR|y
vOHL@BL
foqht9
9pI5.et
2Hk;R5
a#O "8h
y;I03"]>mq
K3,&[@^
mx}[))jK
UZgA=X
WaitForSingleObjectEx
Hqf2KC
UnloadUserProfile
5?}IQWo:
[rWyXh.
5yPzypE
a$R(c9Q
n()6b[
s Oc@f
wm(wxV`Frfd
Y)fmDg
yy@4o2b\u
*7]6d`
3B.kzjf
&t!*x<
/#U%pP
:N3t55
31xyl*
Myta]H
ZW4xi:
CXs 3K]&
=;7tFJ
k8geV{
/neIA(
By+Bl?*j
rmiqrz2
ccdn`#hk
dhgkx@N
HkihVy
-L Udh
[u#vRQ
orTY&+>
N!p~I%
czF#IK
FRH_>Il
T/uTK$
_2MaE`m
31+VKt
%n"Sr~
&iaj=y
,^\^K1
hizU7i
qqpWb_
r[1ni)
'm+IbIo,
yU0kG.
6#$EFz?tYa7y
RAc3lN
}q>k8"(
<x9MmF
>P_x'Bf
SM6 */
Z)'%O}
cyLM[e
'B9Twyk;I
HhV+y^
Um3?uk
t{p7'c
fGi[*N
]?w'R"
K6yB*t0
URLDownloadToFileA
l2U=Hi/}D
`PZxaD.)
rP#Tz'
>PsP#rV
QZ$ZuY
fP>4D^
3HJ,GO
}M,gi+_,
a#6Z:Q
ExitProcess
iir.[j
E=Ln#,9
.yQ$od(;`
BD6*ID
q#?QpR
vd%c~`
[-xEg2
kfJn&?
e~(GY(
i-)>V=
N*o =@
UmW8I[m
NixQm.i3Ym
_uML(Z
PfLccE
@:q\u~
'EU,pJ
xoGZv~
<Gp_ed
Y{8G=4"
0`.6IE
\~#hSv
Nlh6z5
T!Dii/
qml5f*
EJ-#H2
CNQK60
"<HxgKj
dYg"O&
*=wJpH
98Dzm
P4"9L8jf
O65c<]Xp
,YZ4-x*0l*
u\K7TV
`?z}^])
(AWrtj6
DKDlD8
VFHd]D
-B?;q`m
8pe\eF'?P
2CPm(2
GetUserObjectInformationW
0oG<'/
a]Damq1
uM1]=pM
?|tCXc
m?/f+.
}'\CjaJ^m
jY5nCQq-
.O>_~a=e/
",|ucd
v;>-/4b
TJ~lvW
qx?UR3
?)O|u|4O
okC9rhk
VbQKVr%E
6tQC16
!`t|We
Dclyi,
Ul@ xL
g~B<K,
Dch=V,
5%ZTek
Ft9DK)\7
Pe/<E^
B"u5qT
-,\NG<U
e!V+WgnD
GetProcessWindowStation
j0r]%m0:Y
lxpB_A
qOEMCC
%]g4RX>
~M.Mc\U
F!"w-b
W!YhNR@:>
'[6]N)m
^|cK9W
|U.,v`
:x"iX.
HC'(uwNd;
M[, |v
>ZhlDtE
S'z&6Vl"
(W)u<
g*W#0A
=M{|ks
aj6e-
ShellExecuteA
jDd6`$
,c+*'c
p{p[VRq
DHD"7LH
O]=Sk!
3&|t`1
D?3h8^
X>RUDN
Z449Io
VCRUNTIME140.dll
/t)8U0
^I!C_J
[bC1dB
,Y[V.G
^K'E5
4.\6\K
/]gUfMI
lanRR{Tr/a
Hu3{UJWgxZ
yc)VZg
i*De~`
9eX'-c
NuHG}`
XX)tb~"
yD|H5YyCD
}ggfEu
r-LPlp
bCgg-l
%rZvDd;rt
*p*Aa#
XB^$y]~
6^;\/6
g9S}$Hc@
'8mBc]G
"0*Yq%0
Dit^f?
~|k_]l
I/Z>`(j
x6T>Z
q<$1kp
fi ooD
Z.S5b`X`
=2D.n@x
CA`BqI
T,}|w_
vSf U3
p]_^j9!,$
(DLjoI
e0Uq9s
$(y9DY#
?WixU1uxTYn
@iFlSD
@uXb<Dw
&Z0mor
-\ p7m
gME5fO
^I-VC6
m=BjY.
~:#o([@
;QOn@?
9Ofre@^
8/.+=,!4x
'X|X`,
BQAA~|
y2Rqa
WTSSendMessageW
EK/kiY
p=^(iY
:t=(*rhJ
[t<C(7E$
h1Boq1wY
()P~;5E
jN,#WT
IQ?x2d
'7FJa"
N K^yL
7eLsW6z
L~RN}@
Q9tP4JJ
rd6pwr
qFkuiC
*o`$NVd
dwbnU
hphIB~
6O(d)6
y"lL)[
PZ)]|q
m|sI*~
qSro"q0
fmfr!X
Wq=HZ?
<YB'6c
0O7`E
(Q4F7'
5(<dPobv7U'W=
CC},BM
t$%c\&
xiSNo!6[
TF'!KI@g
T&0Bo)h
||CNxO
"*D[\~
MPQz2H
OZbvO6
Hh,eb9
7E.Pm3
Re^*;DL
1'+`x0
Ut"J{SA
Q*2)*n
::w*F%
h?CPr{
vRg:5z
<TAq"C
DWu:?gSl3
}W1 PL
eA8W[L=b
/Y|oMn
zL'*l$
P"OIrs
8w`;'w
g<$FLi$
_lseeki64
Vv0;xf
?6)M$N
Normaliz.dll
,B*5WS
P{n45EE
)16}#.W8
R;<+(j
-[GxcT
E1w7FoH
%|LlF<
hcs^8@\&_B
et^A46
>7[@:4a
EG#"Eh
Utn]K!
Q~C:EN
4sl/LA
10yFG!
%N5yN+
PhPVTX?q
/6&=n,b
{T]\#zt
k[]ng"
<",^6m
3R,8n2']6
)%v?h
Q}`S&6
?;SW`6
P=(t/
)xiO:
h,eJUG
:T4byDT
/q7 ]{
m9mMZ
7b3rAxo
2"UWeE
[*|yOU2
;4SVzi
`0-`=GlH
qQNU>6
Dd3&]>
h~)Ny3
sYx>h=
_stat64
C3aoVM
R+Vcl
"=Vo>to
*]xpB/
55lxv<
qjMihq%
[qZeilqy56
'Pb:b|
.k)TPC@H!
z=1DfB
~jq`H!
0i<YJ2J,
N2=#ZZr
+E5g}>
Vh}B|Q
~@{);[
I=iL&
e]iZA%X
muSXHb
$FtT:)L/TJ
4yr(mt
_(KU?G$
ZPX5Ue
api-ms-win-crt-string-l1-1-0.dll
U2rE]L(1p
i::RVF
[oDh+[
ic~[{Yb
uv>Qis
]1eIS
{Zhne@
Lb*q/
g'jvD_D
r-S)|>*
GetProcAddress
RpcStringFreeA
Jj<{S]c
!o9TBm5
:7p,uf
zauL.p
L&emeJm
USER32.dll
,r}hi1
xq<rn`
<tFvL
%Ut%tm
ut4c`$
5{3W.Dm-W`H
[*VhUM;\Qs
A 5"R3
pc{{}9
SXa+~GA
&"s><ecY:
Z6Mw1]Ogs
d<.|Oo5
piqHy9
$qA%.:
Ze#D*T
2b#]%A
ZXK!pg
!u']:)
FyZ5'i
h5" R&v
0ADtdEo?
&Ts0Me(
$`HU9@
:%4(+}
kvjgX}
oH+'\2lq
~&6G'N
KCzT~m
]~dW<^~
/`$6{[P
6}TEA`o@&
eiaGAL
;9s7=nz
B7`|ijc
pBU[G,>b/
dwmapi.dll
oq98-Q
kG1coD
h9b#Wz?~
=EX*WH8
uF6NXpFE
Hgn8#b
-&*Y'Z
^`JcmK
{?FSsT
_configure_narrow_argv
M7n9RM
{$F^*TL
&$RFZo+
GbR'RB
{RiyNn
,*wct{
>7mqFFh
api-ms-win-crt-heap-l1-1-0.dll
>5SwBl
uG";{G
4txXQz
IX:NHf
JZ9.tp'
E:-a,]
q&9Eiqa
(.[k0'
R& bT)&
8\6|QG
\.nCe#R
\0L8a#%
o@38%z
2)'9HA(
l Cj3I
iy!g#,
Y<TcR|
(i]!0hw
*,e"h-
~C)j4QX(
5xa+ E]zm|l
h`<%,n
_Ok@;c
n!j0L?
gx"*Hg
'ezPD!
Q`?h0"
YiM8AA;o
GTxvj%vH
i_dqH-
aYHhL]"
z{;#Kd
7o:e
6kN!\#
UTLfu7f
}d_?Q,
*Ga80rY
85]-n8
{H5szh
/*dy>eY
q48>=4
JB_[br
9eAm?z9x
]sJ0o8
#~Fp^~44
5I49~}#N~
as%.GC
b0d7*]
XWEX?(c
Gu+=+Uf(X
~CN#9l
_fT1nLR
dTY`"A',
[I2^lC9
YU>`=8
E}1C@@
{~z]A'/@1r$/P
2UQQB]=t
?t%wV,'
P++l/Y
P:aL. FY8
m\=H
k^8{Qk
|ZG2Jb
6QuU#Gy
MnZzBf(
b`z>(s
<!ZJQ1
N yG-Y
H&p4Jx
#M@[SdX:
3&93Xq?
9lpWVv*a
,V>T6
l=@t:
`l#uU8
Db'}k~
4!ISwA
&eEWZ?
fEI|o4I
'0Wzo,b
7odOX}
dfA\#H=
(la%-;
4T^6x_&sw
_R%,d8n
hxgw 4
]d01eg
4)w/1)8
e-Yx#I
?<tqCt
oawxH]
@_#;7>
=?yjTF
BG{Uo@
,r@|cT$
#aZ.)rh
+a671.
wW[.pf
?}FUk5
gId6iz
CmxKP X
QP.tZI
T`jE)'
{~)3S]?j
]:k{#$
J@5k}80
MF\L1i
.Th1SW
:ZV\L
j&w1DI
PUofE]
O;a8a=
j9qpaz
1p>%7'
}}^s6e
Lmp>.ft
66++wLGR
OM2O|O
KkST1I
^M6m'0
1M(_[$
AXLG`rcb&ID
$J6knj
CW|+<h
yVQd@~9
'&7]
fkylV
/z?$`g
W{hoGl,
27MX.L;W
E$xhbn
CsjJAiYE
1>t;fR6
J>1tZ
o`s\-hI
])xMz]_N1
f[?17U%:
G!z0O;qH~?
CC5Ao"
u.":.
kHnmZZ0i
x7!$+W
@6ben<
?nccQ
9r@t3(
zKx]Z"
~!*JhN
]d1a8W
G)@!j8
)N{/jY-
7%~+H"+
Tx"A$_
xI87q4
MGY5~+
M*#,~=
ZnV6PR=
<q] d\{J
s7xNlz@
H7XQ\D
Nq. $I$
#v+<.E
I5D'U2
m7d`&+
5.rEIa1
HBmTRw
x@j`JD>
5zG)[>
f56LMc
m$:n,\
ZZ9Vzda:
qvTz-I
LkcIy_
zUxPg/
,LNx8b_
'\P9C/jO9F":
/j6Sq9
|4Kh9m
m#slNYj{
2"x'_x
}v?CSA
D0^hTf
?b#BI}
AZmQuX
d`m:WZ
TJk("iT
m1%+,:
5JLUDaf
HXS"JCK
yc^!pH
A>i6>P
.R{=mP
jl]SZI
~mMf_b
tXi:8L
7>#xDc
%9nAjO
mZ:1nWR
At_6BF
{"x3G-
7HAc?q
PxpTRE[
}kXjqx
g*/o}$
>nQ[~kfDa
;d[?lf
$r(m%Y
jNA\I
'zgRA#
vUr])@V&z
'quXpI
[LE~-Z
ui&R`a
{Om^W#
w,ciB{~M
0kWa$5
EWHWED
Ft'&O_
1r}SB~
6rNN+W
#tjr1y
okwMS+
mI$`TBi
nrbV%)
`W!X])]
DoFpm5
4@C5cE
)g5bqL+
JKgZw&?c
K8QMkEp
{UQjY6
`Zb/^*
V$Z&F#2
v?s`&i
+5K<{^
n;HbngT
A_xW'#
s!Ww!>|y$
ZKtL'j
~QIeQ|j
>VL`:V'<
(A` fA
c|!UlS
6gS:y}
f"b3#|
|ozDW3
6y[w=H
c'e(`T
q`{zAq
u2r&j:{Shn$
&yQ<tq
>@5K"c
ruR8qo
\H0[f
{V2 kC
~XH3@Y0
hNW8gP
]eRiB\
U7oq]\/U
n+KhCA
`,yTx
r|PmxZ
on)-iH
c]}/KC4Tf
J6)y[gA
mi8/_m
7=bSMZE
%Od0lfj
B]D%TV
gGq+hZY
r!(R9#dq{x
pZRDpL
\y)pNO
{E:~t?9
|upb#
05v(RQ`
SC,AD-
FWk79g
>MeYy$
ff)fVW
hYk_x5
MR/_10y
ucS}j\EIh
yxufd5
[Eo0NZk
yqpe"N
L!:^dTg
ypZ4,
R~5r6Q
)i)P'V|=
B/RqVOx
SQ[4ess`
4DrhRIv
axK>fw
2A9"RQ
-B!W)%
;Ml4g^E
rDq^%|
6O1O(yd
E%RKX=}
%RmK]n-Mz
FN+"=l
2g&Q\~
prxIic
<W%%+v
jOG)~0
K\&1:VP
ys;bV?
uy/aV0,
-R&X%
MA~`tb
hbZ`EBW_
K*r$?oV
pU!%3~
;H570s
;vF0I
E*7$f]
"Ua\k\
yc)m#g
bmba#b
K^CO#"P
3BWf$
(4T-&r
woUvx
@p4H=*
@7jm8
[IwC#
i)AVA(
<@S)7*
|b5|z|
880=Jy
_X"W*o
0;?`'
7Q]N0c
y[~GGK
3iNkBig2J
}09pPX
:|yjX
_UxDT1
ttO@$)
:6O3F4Y
pY=[ebo
.YtQ1
wlGhX
Le&$mue
>['xSm:
{&b@.9
?>##r1i
']%\_<
&>aWKu
VcapPM#5
<Fi\<T
M+I<R\
_RUhLh
Ie+Ve>P
K;#ue_
"O}217
*D`X@we
EV~$a0
g^V\={
-VTWgF
gQ2<!;
(I9se2
o:(ZH{
9Mrii|
\XWk[z
a<zyc
m?G=Ev
|f0Fi<
i&IO Q
j{nB;<1
?WCv-7
A_DMkg#
Lps`zO
U,'/>M
A~gzO@
*^o&r8l_
&d[5g,
x%wfNPR
6<dh5B_
s'+Jj?
me7ved
7 nqI
Bw$VIj
-k>v2T
jC>$zT
;1Ny*r
z1abmb
*Fv'YP7
r6Ln8BY!Z
zhAXK4
.A\z3k\u@
zI[ii+<
s]/m[?
4S<'p%
P}pR r
Uc6~YI
SZY&(,
_hx|r2
dn|P-E
mv#R0@
HSLO7m
b1;O%d0
sYjZ.d
YSn@Px
\CHAG`
N8B`Qn
>x.wo>
1S(coc
oJfdszk
6L06,d
e9FZ1P
]K HD*
TB|Bv"
Ou 7Qa
^NQ8Ma=
/D;7B
{=dHn#H#C
(k<+jOd
Z?PU``
is=!"G;
dtC.E&,
y9T z(
s Pj:~
Ne&8~y
/)N4x:FK8D
)TOB>B
tNT1_
K>j!tg33
?#IC7G
d"*Q??
IFQMXO
tr>z%{
('!#|=
wYZ,'i
(/|k%U
T.i+FbL0i=
6O ^R&
3<x~|+
yR/MR_
y}z;t&V
)Ev %X-
CtH[,F
Q6)cwG
3j`!{kH
)54z(t
@Fxq9;>
nb+4~u
j8U%ZL
"+HvKmr
t]O%D-
Ot[r5U\
3M0O~#
& i7Lp1
L5%"o$
DuKbPJ[#
!0zN3A+
nojk~u!
A&c!d,
/VG?lum
WIGdgz
/d_Xj
Ha(WmC
{0.g<.b
*ycDyG
_7kZAgT
lXIRHg
C?,2@r
%t2m;<:
m#[^~N
7k*j/3
BSm m{
_u3UH2x
u8t2q<
;$i+Dk
z`XWe,
r0z [".
#LJq%S
na~^@E
e4@n*Q
!WGxmv
%C{uz,
u7jK>#
6pQ^~n
JQ=3.[
5<7Et*t
)l2ErYM`
oE{4etR~,v
/?H(~Qn
lm)ji=RK
ey;&F;
txOidG
|{16lnf
qM0/1vc
|XW;|'
rrIgi$
xZH%5r
q)>b'D
;+vs[UQiS
~Ixb)P
;}E>=S=
j`ZK,C
##inkM
GoQo%k1
}_W|)E
7LQ9{d
q|+e
IfF!ep0
hl`az;
WS<nc^I
LWp>\[
{5^$WBH
Q}6\o^
K&ofb#
J'ZQ9{
S%!9ja
9wY4-8
>_=H3(u
r0A|_?m
%|y:lfWy
t%}JL;\5
<y}{:s
g}7E{q
tC|mU:
l-H{3u
nk|y4X
T&fP*R
p:M?$P
IjW n
?M`R& >
xn!C3N
SA:(]@kj@*
TD#h1r`Y
P=jHi|
'tS=4=
X'C4J9
)lY{ 3
U+vSk>s
wH>ow
i)[W]x
mKC!W#
AgCb8~
Zv"1z|
VBoK@u
?S5LC
PrU(j)
E23y19
*'30OG
/W2j-y
Cml:j.
YyHJrX|q[hX
jFAA-(
e.8 ax
n2qLe{=
JQQcIK
}-FAJOh
IM0(2s#
I1L"66
N6+=2VE-
-7>Qrcj
}sU$#_G
TI%!%f*J2
VIkh.X
.UA/ROe
+@N&CA}D9
?`?#6=%
:IK`~q7
J."ct/
IR@sA7
= 0-'~
R&SK;-
~Z"r"ple
l+hM(,
be%F(WcN
s>1>{E9WFYl
u_[(%Gu
hQ;jLC
-s^v^o
k4CjOoA
KQ#;CY
+H4) G
)y,RC7#
O{eWpPil
eoNK3G
Z"oKq0
9=!R+t
E$*6y!
&E7QLn
-sO`~4
`o3+rk
@$%;+m
[*P)z
q2'v{h0
"E5';|n
:(/#$@
3`XUI?2
ek"2YM:
DMH90k
BK$d5~l
< 'Rh t\}>
IS[pc
G-mTH[5b@
]jQy($
1E.G\<
$6b)vZN
xVLgJ*
u7XCX2
o~>J)CS
7R5XePOn
<j>M$1H
l_ne4Q
fwfnm;IK\
(RtrC;
nD}$XeW
>~BsTsus
G.~lY8X
_QHF2-}
!ch1Y
g\)NiUo
$eCR45P
6z_8)6
($@RyOYi
/)$@R*o
)k}@5l#}>
*OhG*1
{bO%s9j
[lz[K#
UjLL$
K)]5em
/y\ z{'
api-ms-win-crt-convert-l1-1-0.dll
VR1O$#F
>|\>1WX
gBXWTSAPI32.dll
oIviK}
I:>tZh8x7
5Kvbnm
JFFB?$
ho+>Q+
f<h?Kh<
b<_,$j<V%
>S\}*jT
_gtRZg:U
'p"Z/{t
N.uG/
$#2.#!
2M_TczP
_gmtime64
zX)]-a%
LZZ#}T
cYffs5}
hz1/g;
ng,z5o
VjV<7n
4^1EBhl,
^)_C+%
JlX)Cvf
zd/{Ta
4F;txa*s;F;
eZlmY)7
)yDZR5
UNE:j5
Bim&5v
2phc^a
O(W[_!
vVc2W
^)1-iA
He#`n0
meLS\!h
:b{AEo
'2y1I|
s=)bdH
f=*R_F
j,BVcR
X%`1A=
?/Ew-*L
cw$:U?k{
_JA|r
U"6*E
$;#&Qj
x'rp6
YiIeLY
jd=(j4]cS
F|[%a9
_;THIq@
d?E7<)s
Je9$~.\
q^Co?M
(06}tH
;K%Ykww
*pcER?L
h@E4D#g!0
:D:5[{
Y.giDV
G)n!-0
H$cB=Si
!Mh4N>K
G-Id@M
"Mw@N#
=kp F~w
X0ZZ^3
#KCUOT|]
4NYkd;
.=<o4A
XlvWNk
6_VMI$}
k4!-k^$
{;jkp5
]G)~x"
k dF:2
/2B^SU
a["<qR
Us+uy3
;gf}P/
api-ms-win-crt-locale-l1-1-0.dll
rODcD1
,aM)Vm
~Zm89w
wjbo]T
w$q-v<L?
-t5Vmz
}9yP`
FU5g>9
#Sq:s0
}3D{B
>!*R,I
GhMWpT
"MJ"LQ
jk@)bkD
j@)bUr
De3"vF
qAUq,"
X<>+D
6E+ 4D
,Ubc)]
KX)*e'/
wG0S7i
;(9fd=K
|LNtV?<
iQnd=KG
WS}8$
PLD7Xe"h
xG<]"A
WP|ZDfjE
K3<4fjE
a8 "^=
E?YxaY?
api-ms-win-crt-time-l1-1-0.dll
OhX;De
z,Tw9f
?xk][S7
rJ3.N5O
vyg{%?B
mMxEun
a8Tj?S
!Y'J/4
;cZ'l
kPQUd?
D3qNX[%
=+/1MrD
hddiY
/b>-,]
ygK$*I
7@KhKA2
RP[!GvL
dTjGpD
_;,zl?
zP)"fA
|2!Y0f
,Z<qmi?[
rO[V7b
e{{t,1
S1En,z
wQ"<^;
YHm*TH6b"
Q%E7?@
:1J]qq
'y:!)A
\7'[]s$
W-F8F4
az^[`_
-'o(i+U
28OH\|S
Zoz)SN
U.z`;H
voyk|]
]-~0U{
tO*:Ch
Kry(\`{7
7<~O-y
ti?tSu
q^m2bM
a}QxE8
=906`GZ@
xu}uMA
0gR]w?;
.V*r9@
%,J+y
buD:r
((NDc:
,)>AS8k
Y,oem2
/2#;qF
cbE=F[
0bfZE%
S_3gzV
f'W'9S
SLJ&S
:)SY.=
dnlP*:2
o\6XJB
ovENf2
[:_;-!:
,k:;Cc
fE0_\U
US/b}!
VUti[(5
(A?`KG
c<fSS:?
a6=R'~Y
c@hY&A
DXY5G0
)Yo#'>!
NYK>fJ\
<NjLaZm
E4A/C5
3b]7cfd
>y:~P6J
2^sK^^+
yu97rH
u6mI_7
uP:ww't
[v.t'r
a+4aw%
J@%-k~
<7~'e,}
k>dzo[
6MX6k)a
api-ms-win-crt-runtime-l1-1-0.dll
=H8~iu,
ZGVm4qp
s5qqp}bm
/"4G"B4
\esc3l.{c+D<
sZo2hcu\A
tE\*4Qv
B0F\pT
1B1Vx'
~9RxR{L
Y:`1H@
#|O$LKA
,`\1:]@
}SSr?4
Fh@c7S
-E\9)t
b@AzbJ
)lkviA
vB/80Y
?QxqEgU
uy3|F
g<QOe4
q m5Yo
BGJ`:Y
>%u-E
x6u'/lV
6ky`fO
|L_i7g
O+]2J`
/vg*EW
ym0LJ`
\\}s}Y
5)(4ToW
gWW/:`
7O"5BK
X9z5]I
^6d%EW
!U!4kY^
hOxsEW
|}:>Fj]
<lR5HI
|D1qd(]
CertFreeCertificateChainEngine
fnX$"z
4g9'aqH
=Yw10&
ZeX~%%
`%lDp=
"jVI`t~0
KBlCMt
Fr_sAIq
cy&d@S
H9_.}'
b~tM~d
%"BLFX
76v|!i
c1tU 7nv
X&l4"1W
<o:z#!
e5)hZn
FiCs~2
h^ayM;
[{>b\{o[
*O*BPb
lJ2B;~
3gM&EOo
>o/nd5
4{*y'hV)
K}u/*b
X<{ z\2a?
Ui?EY5T
X$*0|0
,Vhiy\
V))C|
;nAJ^7
G+bM{1
0"5qBH1
%mC9Q)
/AP@%e
BW0IM
UNYZ@V
0F;Ws2
%Aqzg;.
nW=nhtS
CCUAUw
mmJ7$\
{WIS<4
&&wt_%Fuu
!EPey#
FS$s:2
k=F9?W
bNR; t
!xAR}P
N^>}3^
fDy$BD
=T B"7
nyM6yW
G6&>cv
U6N?n^
])*#d{
>cDQIYs
Q$f3Q\
>QQ,}h
R--+,E_4
CS`~=$
mRNMe|
86ClYE>k?
\qs&Q*>*
)Z|X&
o(PE
p19%@9
~(D.+?
?Mf'^aP
{u^'$p6
@'a$N6
awbe0%
Po&mn;
g3Mq<W
H2y4"S
i<-6eP
7CTE.L3
,AV:bI
lg[KwLH
{n~1PT
s!P:KF4
#@$Zg%
p7Egk-
#O@`oS
j-VP.O
y[K`E
dac0FMpE
M3xVj=u
O\wO-w
#Oh!D)
X5#BQj
prc[ta1
rX/?ByFh
{aPF=F
rY9:!(m{
QVu>&HrI<
ALW8B!
DP2a/;
Rm@D~!
\<OB`s
x?H)9d
;^K#Eq
9`6aF5yAYG
674E37
rQc[$U
G\)L8Hd
w8RkN7D
#?^'/%
e> q_GHj%
O33i.q
%q}yY&B
7PdMXYsH
rW:zW!$
jmKj(s
\@P3r
~Ul`2B
?Ng&n\;
OPc GiY
=&S&9b
icmWJB
_p[$t+
p1O~'"
* 7Ja\
>!pRR)
;GhBlY
'@nrY`
<`ifTdg
0dm=X
HwNosV
VCakO;
6%Xz{3
.*5G$!d
!vATci
R{oqR
.T{8cpi
lzw`0S
sM[M\h
C9qAE m
9Sk*.\
n1gz?z
)v_vT
xt+>Q^5P
[|}:2P43
.F)HU9
:~)CU9sN
|Q45ZgN
r9x{?<R
mM;42A:
0?%i7Q
cFZ5wfVQq
Fr|4#+
]`Wtw^`
H`23!I`M
r5E`lY
l:Qci1
1DiW3.
vX'${d
Qf6#;gG
/3s<vn
9I'9L?
jWS2_32.dll
KByY!O
06 p8V
-E}THG$+
qcm[*Z
v7Jb5=?J
MiUcN
&S!3qn
m0Fjum
Oz#?_7Xx(
:wt_|D
kjn3@I
zdJQ-
<733pE
\HxUP.
h`M)+cp
iGg*N_
[/@nIi
g7)q))
64Sw$6g
_M3TJ9
[$&Rc@OAa\
NhtDnRX
B;)t~CNXr
;a,s5R}
[k?NhE
KQioAL
_Af O%
!db}cvy
fv4>}
l*#*?g
Jy\nO*
CRYPT32.dll
zpq20<
P|UEkQ
M77At]
R'NSJ!
;.=tuQ
<@9/ d
V4=9cQ+
Uc7*<r
'&C1eRp
vMwA"AI
Ysf]V7#
vN+Q1E
.\42o>
eyCW,0
8w79B`
u1E[&Y
OxZc06
'=*M'P
NjQcEk
k*TqAD
H/-939
4!gGA$
IjS\Kd
4DOTazE
T 3'x]
yOzO7Cu
,g7-Gi
aRo y[m
LoadLibraryA
>JW,h"
\JDvkP
q.0_[L
GetProcessAffinityMask
(A'ls:
>QHAPLg[
,a3r1A
v;__@C}
)MpNne
wyGw/B
jp;WAZ2
LiPi4q
A:uFc1
;!u:FD
{UgYFWT
01NpbAK^r
',W1SX
T%,(FH
Xag8%
kluaN
C|]d?/]
iNCmKPz
(?yC9=p3
y!2m#xTC_{?
tolower
`"kIw0
Sj* <|
;.k^&!
Q2!<x
SU}%y)
zw1,]6
m8CR12
" T$N4
D%*=S3
H|AcCm
h09B' V
x+]!.1
P \Y=2
frT8b~3
D.d`!w
meMImG
:a]A2U
w|]!\7
(a;VmG
LocalAlloc
lq:7Vo
~tX$Ex
:Z)=m>
i@-sr*
Gvc}UmK9
e(h4&
<ux[]6<
p('rK
p;VQ1=
qL`by`
]x}Rh>
A3e?ch%^
)alNt/
4W:U_o
C^)M3g
6 R:bIN
6Nt=cD
5yP`&R
Yxhqq1
~^onV[
'NHD(
7:cB
HGH''7
|,UM'{b
8"7*Dj25M
s(B"5s
t?(]h~
*N<g2(&
Fv?mC}1
jP'+ND
AWN\64
!F*.=`H9
C+.&D
pZNym0kv
Lb]cK1
6709j[
0|EhGDW.
__C_specific_handler
-/UlxR
n\Z2Zn
M~aVFU
kjxkJ
JZcOqpa5
PI;|7/=
6'pD2_
>9|N5o
sn-)q
0$aI)w
m8Sl*XQ
xRl*Xd
*3*U7]
Y_;*_E(
Bo#o>O
hH!(;@
~%v`3D
EDG_ct?;
!~?"A'
B0BTG2
(H{r!$
n9']M}I
!GEN*~
q%^D~qZ~
td0qg
,92gWq
7TI:Q?TH#
.4hfh(-
]~hle`
?['r;k
Qr\Re=
-#G|8+1
z?d} 1
ybq$x[
d3/zx
j+@f;I
4F$h2f\
{sss|wt
M_f\:XSF
ImmReleaseContext
xt@V|g
~\s^b<
I+LH3qO
z-H]s.:
8!a=Wp
$."mV
[NH2Oe
H<,YJOWNygV
EhgD$}
Xb\TMwY
u1jJ3|
GXD/1KT
W-Gxv(
u(G607
W|tXCR
TyCV.W
H)3\akz
6#jZnN
l|tr6pTc
Am%_XUh
.H^% L
)liB/
UA4 Bh
IMM32.dll
&7{=<~)
UpG9Jv
v7Ez8;
SetProcessAffinityMask
Aja+\,
4Y3ut$
0kqN79
'b>nk}
q~B60O
mSr/d^
B|4;b
zN(+?;
|4c'^S
gsTP|Z
hd'/yL
d'/yr*
Sb4XXu
^rli:lD
jpUk:\
?]>Y3oC
JYb871Y
O]pZ.'-
3>]|k)
5>*|&B
r-B&'5
8H\:i{
>\]Vs[!
YmkNK
p'jRc,
E.b'uDbK
[m1>Hn;)
B<O,yI-
e4?-?v
}!iB^w
nE*A]W.
\im)+a8v
lsV nIA
*N*uq%
%5Y/lp
Gfp{hk5
wZNcI&
(~u`je
F1Z0"N
L)2*b ^
v9rI$Z!
Lw\mfuBh
yjoQOS
@MkT\CV
U1sdQ0
/WY)ID
,YPyl4tU
@lyF\p
R^P,M'1PfW
TF+LbD
A}AQ.dA
OE)ZiOq
ZY1=n%9
Cw^Pm;
rtdP$H
RTr.2rJ
UU9:Uu
-N?DS"
+6^(4dQX
6ym{
4p@Ft
$F\,iW
o],Tl
K,|U9J,KH
uBkUQ^;
n68$C%
uodC<e?
6Wiyh*
(fM3*P
8;*>xO
2\kAsf
+gPdz{
__CxxFrameHandler4
% )j*)
YYO!%B
WSZ\%HDR
,NUuVwa
A%A*COb
%\ XvP
Wc*'v?
S+*#}$
I[n=-w
v=VFR,
\}S<sQ
Ih^niO
>/cZ9'
%alMq_
:0nzCcoqzb+
<}\Fdx
SLd@@n
..YWWy
h9NCgaS
Vbk)IF
N<8 *N
O=a&N^k
H*3>M
IfJl]o
19s bl
Yd::"p
Nr3}P5
oT*0+`D?
rgk}Yj
|W7IjD)
y!d"Z=
19e>JN
UN|)k0
1Nh##>
;dHD(Sq
WQtF"I
}32r@G
mkC}$k
r1ptwZF
L4=>!v
_/QmQem
=|`?Y4
'Dz';P.f
<*OCmYy
4I\fCw
4%g9CY
@i:n|
@>9'`
9t5TNA
8Yl*c/
qK>D8n
$9'2ei
0B=zfi
/C#h%p
Jq9GI1q#G
vgq@r#
t$2/ihK
ETOaL#OA
|]=k8%
B4:cTw=>
&"Mv#"
SXP0Q5W
^e'm$|
ZjF)1A
"k/e!
l2qg[J
+CwsyD
|fR[/bi
(bV)'M
/km"MG
{~qH\_2s
yx]'Ui
lF|mYf
+wj%o]j
WB&OR;
jO|4]7
UB*(wDv
7IN\f$_
4V;H[!
f .K&$G
p/HMJi
F=~\(
`jv/#h
/l}5gWns
\0Bhde
hwLBN}
,JoQkRJ
zHW}iB
'|v<TY|
j3w@pY/E
}|:q.m
kt|0GA
TLSi#J
YQg.;O(
C dl!"
7ZTA|L
}~q~0B~#g
;I}=QlK
v-'*L
KUP<E6^p@
ug=jn
:E967>V<d
6W2v&6
}\dcXVOCK$
6X:D~6
(^i1*h"
GetSystemTimeAsFileTime
1paKCJ
/zEti'
4]rI Q4r$7D
?IdZ#N'e)K)
)IJz$_
1hIbX f
.N/lm!
W[a|\]
k\^-b;
+a\2I0
'6nK\}7
]yKOOT"Rz
Psk.z-
1K)J.n
FreeLibrary
9q(nF!c
npSd(n!J
wl+n5 Q
JgZT-A
33`e`:""PBI
X2\=[g
SEI57q
1E<09S
4O)]=s
O?(z.-f3
~]*SD/
|r<Jc/G
yOZCViF|
R`r[|n
qe~Y|q>
G\eG/5
/#hvT
\BCutGm
g\[r[}
QrO^v[
Sr@Bq5s
ee+KP`e
.s11U6
p3{mo9
4#[3 J
RxNUX0
OrH4f{
xY;;yY
&SEXf'&4Z
z8E,d.#
e^U"GY
uaIZA6*A}
vT2fh
@R.om&
$SQ\us
{&E[FF
*?]rx:=:
;6?M+U
+{5#_Eb
N ]@.,
_lC};d
.t9q.T
YV/~BM
;+JK;R
W7FvMw
;#P^nWg
k9|1 K8|
1_4|?"
cK>!f.l=u
mRv)o+'
v)o+_W
~`%qU
#UNNda{
L.;=7B
0x@sN!
qsX9@ij,
wsX9@L
md^5D]
?~88?1L<
Ti{B7_
#(N^#a
YrA~4l
)4E\0N
Q'H)@z
QFNk&~
AsPq"s
8WH\c`J
/nL}[H
+&QY8t
^ZM#KP
TDo1Tw
8uvY(K
6}X<?6
X<zRPCRT4.dll
AoxOqg
P%aYg+r
""a`R8X
51iU^^g
Rv=G->L
z$+fe6
?(v|/O
NWiUnIJ
uDbOV_|
u "0Av
S=X$$S
Xg(lA"
|mt$A.
IdnToAscii
_n1-R;
*"c1WF
e5Ze."
D]" vV
OeG.P9~
2!-uMn
:Aa5$$
*AbqwQ0
(K.h(i
--2h}
OC^~q~
5yY'D@/
%]eD$B
KSiqwup>
d{h>R^
HeS|~F
&t1<$H
2YwpYJ
=nf#,4
ByS9q@)'R@;
Antivirus Signature
Bkav W64.AIDetectMalware
Lionic Trojan.Win32.Generic.4!c
Elastic malicious (high confidence)
ClamAV Clean
CMC Clean
CAT-QuickHeal Clean
Skyhigh BehavesLike.Win64.Downloader.tc
ALYac Clean
Cylance Unsafe
Zillya Clean
Sangfor Suspicious.Win32.Save.a
CrowdStrike win/malicious_confidence_100% (D)
Alibaba Packed:Win64/VMProtect.346174cd
K7GW Clean
K7AntiVirus Clean
Baidu Clean
VirIT Clean
Paloalto generic.ml
Symantec ML.Attribute.HighConfidence
tehtris Generic.Malware
ESET-NOD32 a variant of Win64/Packed.VMProtect.IH
APEX Malicious
Avast Win64:MalwareX-gen [Trj]
Cynet Malicious (score: 100)
Kaspersky UDS:DangerousObject.Multi.Generic
BitDefender Trojan.GenericKD.74400349
NANO-Antivirus Clean
ViRobot Clean
MicroWorld-eScan Trojan.GenericKD.74400349
Tencent Clean
Sophos Mal/VMProtBad-A
F-Secure Heuristic.HEUR/AGEN.1315472
DrWeb Clean
VIPRE Trojan.GenericKD.74400349
TrendMicro Clean
McAfeeD Real Protect-LS!4C428E14CF5F
Trapmine Clean
CTX exe.trojan.agen
Emsisoft Trojan.GenericKD.74400349 (B)
huorong Clean
FireEye Generic.mg.4c428e14cf5fc2c5
Jiangmin Clean
Webroot W32.Malware.Gen
Varist Clean
Avira HEUR/AGEN.1315472
Fortinet W32/PossibleThreat
Antiy-AVL GrayWare/Win32.Wacapew
Kingsoft Win32.Troj.Unknown.a
Gridinsoft Trojan.Win64.Packed.sa
Xcitium Clean
Arcabit Trojan.Generic.D46F425D
SUPERAntiSpyware Clean
ZoneAlarm UDS:DangerousObject.Multi.Generic
Microsoft Program:Win32/Wacapew.C!ml
Google Detected
AhnLab-V3 Trojan/Win.Generic.C5687340
Acronis Clean
McAfee Artemis!4C428E14CF5F
TACHYON Clean
VBA32 Clean
Malwarebytes Malware.AI.3696726045
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Rising Clean
Yandex Clean
Ikarus Trojan.Win64.Vmprotect
MaxSecure Trojan.Malware.300983.susgen
GData Win32.Trojan-Downloader.Generic.20DK5L
AVG Win64:MalwareX-gen [Trj]
DeepInstinct MALICIOUS
alibabacloud VirTool:Win/Packed.VMProtect.IJ
No IRMA results available.