Static | ZeroBOX

PE Compile Time

1970-01-01 09:00:00

PE Imphash

c2d457ad8ac36fc9f18d45bffcd450c2

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x000c4f56 0x000c5000 6.32875661581
.rdata 0x000c6000 0x00174e48 0x00175000 6.27502013482
.data 0x0023b000 0x000a39a0 0x00019a00 3.88015742771
.pdata 0x002df000 0x00004f80 0x00005000 5.20205218826
.xdata 0x002e4000 0x000000b4 0x00000200 1.7871122628
.idata 0x002e5000 0x00000554 0x00000600 4.00646499814
.reloc 0x002e6000 0x00004550 0x00004600 5.42694141278
.symtab 0x002eb000 0x00000004 0x00000200 0.0203931352361

Imports

Library kernel32.dll:
0x63b2c0 WriteFile
0x63b2c8 WriteConsoleW
0x63b2d0 WerSetFlags
0x63b2d8 WerGetFlags
0x63b2e8 WaitForSingleObject
0x63b2f0 VirtualQuery
0x63b2f8 VirtualFree
0x63b300 VirtualAlloc
0x63b308 TlsAlloc
0x63b310 SwitchToThread
0x63b318 SuspendThread
0x63b320 SetWaitableTimer
0x63b330 SetEvent
0x63b338 SetErrorMode
0x63b348 RtlVirtualUnwind
0x63b358 ResumeThread
0x63b370 LoadLibraryW
0x63b378 LoadLibraryExW
0x63b380 SetThreadContext
0x63b388 GetThreadContext
0x63b390 GetSystemInfo
0x63b398 GetSystemDirectoryA
0x63b3a0 GetStdHandle
0x63b3b8 GetProcAddress
0x63b3c0 GetErrorMode
0x63b3d0 GetCurrentThreadId
0x63b3d8 GetConsoleMode
0x63b3e8 ExitProcess
0x63b3f0 DuplicateHandle
0x63b400 CreateThread
0x63b410 CreateFileA
0x63b418 CreateEventA
0x63b420 CloseHandle

!This program cannot be run in DOS mode.
`.rdata
@.data
.pdata
@.xdata
@.idata
.reloc
B.symtab
Go build ID: "Tq76I-505n-zBx2Dju4f/ww05aFsai1-ilS3QJ7Aj/arTPb_5HYTOnS-257crk/0zNFAQBgsQ0SihJ7Y87h"
l$ M9,$u
8cpu.u
P0H9S0
PPH9SP
PpH9Sp
UUUUUUUUH!
33333333H!
expafH
nd 3fH
2-byfH
te kfH
D$hH9P@w
\$hH9H@v)H
H9L$(r
debugCal
debugCal
debugCalH9
debugCalH9
l819um
debugCalH9
84t6H9
runtime.
runtime H
error: H
HPL9x(t
29t$0u
29t$0u
D9T$PtcI
/H9S u
2H9t$0u
H9t$0u
L9T$PteI
L9T$Pt
/H9S u
/H9S u
H9BpwA@
D$hH98
t$8H+V
P`f9P2tgH
\$0f9C2u
H9D$(t
^0H9X0tX
tA8Z t+H
\$0H9K
D$pH9H
D$0H9H
|$pH9\$
T$ H+:
UUUUUUUUH!
UUUUUUUUH
wwwwwwwwH!
wwwwwwwwH
J0f9J2vuH
f9s2u;H=
D$$u$L
L$0H+Y
runtime.H9
QxM9Qpu
L9L$Xt#H
runtime.H9
reflect.H9
I9N0tVH
T$ 9T$$
t%H9QPtH
rpH92w
tRI9N0tLH
|$0uMH
memprofi
lerau*f
9q0s&H9J
Q8H+Q(
H9D$XA
H9D$XA
H9D$8A
T$xH9T$0u
t$pH9t$Hu
P8H9P(s
z(H9z0
runtime.H9
gopau/f
|$x2u
runtime.H9
runtime.H
runtime.H
G0I9F0t=
runtime.H9
P8H9V8t
P2f9V2
H@H9N@uyH
H+H H+H(H+H0H
8noneuW1
8crasuD
8singu
8systu
l$0M9,$u
l$PM9,$u
X0H;CPt^H
l$ M9,$u
l$0M9,$u
l$PM9,$u
l$(M9,$u
l$ M9,$u
l$@M9,$u
S(H9P(u^H
P H9S u<H
P+8S+t
\$0H9S
Q H9S u/
Q(8S(u&
Q0H9S0u
I8H9K8
\$0H9S
\$0H9S
H H9K u
H08K0u
PXH9SX
SpH9Pp
P H9S unH
S0H9P0ud
P88S8u[H
l$ M9,$u
l$ M9,$u
D$`tMD
t$0H9F t
l$ M9,$u
l$ M9,$u
\$0H9S
\$0H9S
reflect.H9
Valuu,f
reflect.
ujH9x@vQH
uJH9x@
u$H9H@v
t$0H9F uIH
\$0H9S0u$H
Q8H9S8u
IHH9KH
l$(M9,$u
l$(M9,$u
l$(M9,$u
l$(M9,$u
l$0M9,$u
H H9K u(H
H(H9K(u
H8H9K8
@81t#@
\$0H9S
Q H9S u
I(H9K(
l$ M9,$u
l$ M9,$u
L$hu/H
L$huFH
t$0H9N
~(H9z(u.H
l$(M9,$u
P H9S u
t$0H9F t
H 9K u
H(H9K(u
l$ M9,$u
t$PHcX(
L$pHcY(
;fileu
;unixtz
unixgramL9#t/
unixpackL9#
;tcp4t
;tcp6t
;udp4t
;udp6u
;udp4t
;udp6ub
l$ M9,$u
l$(M9,$u
l$ M9,$u
l$ M9,$u
l$ M9,$u
|$`H9=
?fileumH
method:H
l$@M9,$u
l$@M9,$u
l$@M9,$u
l$@M9,$u
(BADINDEI
(MISSINGI
%!(BADWIL
%!(BADPRL
%!(EXTRAM
%!(NOVERM
t$0H9F
l$ M9,$u
l$ M9,$u
l$ M9,$u
l$ M9,$u
l$ M9,$u
l$ M9,$u
H9P@uYH
$D3T$4D3T$ D3T$
D3T$8D3T$$D3T$
D3T$<D3T$(D3T$
$D3T$,D3T$
D3T$0D3T$
D3T$4D3T$
D3T$8D3T$ A
D3T$<D3T$$A
T$ D3T$
$D3T$(A
T$$D3T$
D3T$,A
T$(D3T$
D3T$0A
T$,D3T$ D3T$
D3T$4A
T$0D3T$$D3T$
D3T$8A
T$4D3T$(D3T$
D3T$<A
T$8D3T$,D3T$
T$<D3T$0D3T$
$D3T$4D3T$ D3T$
D3T$8D3T$$D3T$
D3T$<D3T$(D3T$
$D3T$,D3T$
D3T$0D3T$
D3T$4D3T$
D3T$8D3T$ A
D3T$<D3T$$A
T$ D3T$
$D3T$(A
T$$D3T$
D3T$,A
T$(D3T$
D3T$0A
T$,D3T$ D3T$
D3T$4A
T$0D3T$$D3T$
D3T$8A
T$4D3T$(D3T$
D3T$<A
T$8D3T$,D3T$
T$<D3T$0D3T$
$D3T$4D3T$ D3T$
D3T$8D3T$$D3T$
D3T$<D3T$(D3T$
$D3T$,D3T$
D3T$0D3T$
D3T$4D3T$
D3T$8D3T$ A
D3T$<D3T$$A
T$ D3T$
$D3T$(A
T$$D3T$
D3T$,A
T$(D3T$
D3T$0A
T$,D3T$ D3T$
D3T$4A
T$0D3T$$D3T$
D3T$8A
T$4D3T$(D3T$
D3T$<A
T$8D3T$,D3T$
T$<D3T$0D3T$
$D3T$4D3T$ D3T$
D3T$8D3T$$D3T$
D3T$<D3T$(D3T$
$D3T$,D3T$
D3T$0D3T$
D3T$4D3T$
D3T$8D3T$ A
D3T$<D3T$$A
T$ D3T$
$D3T$(A
T$$D3T$
D3T$,A
T$(D3T$
D3T$0A
T$,D3T$ D3T$
D3T$4A
T$0D3T$$D3T$
D3T$8A
T$4D3T$(D3T$
D3T$<A
T$8D3T$,D3T$
T$<D3T$0D3T$
PXH9SXu
[bisect-H
match 0xH
[bisect-H
match 0xH
l$ M9,$u
H H9K
P H9S u
8leaku
kernel32H9
l$ M9,$u
l$ M9,$u
t$0H9N
~(H9z(u.H
P H9S u
l$ M9,$u
D$DRichH
l$ M9,$
S(H9P(u>H
ommitRegH
istryTraH
nsactionH
yWaitRecH
eivePortH
chedSignH
ingLevelH
tIntervaH
lProfileH
emaphoreH
dSectionH
NtFlushIH
nstallUIH
LanguageH
D$KueryH
InformatH
ionWorkeH
rFactoryH
NtYieldEH
xecutionH
D$&tSH
ecureConH
nectPortH
eryEventH
bugActivH
eProcessH
D$&tSH
inglePhaH
seRejectH
tWriteFiH
leGatherH
ryInformH
ationTraH
nsactionH
AssignPrH
ocessToJH
obObjectH
DebugFilH
terStateH
estAlertH
RenameTrH
ansactioH
nManagerH
tResetWrH
iteWatchH
tSetQuotH
aInformaH
tionFileH
CreateKeH
yedEventH
ushBuffeH
rsFileExH
ueryInfoH
rmationJH
obObjectH
FlushWriH
teBufferH
llocateUH
serPhysiH
calPagesH
tCreateDH
irectoryH
ObjectExH
tAcquireH
ProcessAH
ctivityRH
eferenceH
eplyPortH
ateCrossH
VmMutantH
yIntervaH
lProfileH
tSaveKeyH
mpersonaH
teAnonymH
ousTokenH
obObjectH
etSystemH
EnvironmH
entValueH
tAddAtomH
ryBootEnH
tryOrderH
tReadFilH
eScatterH
seMutantH
D$&tCH
reateDebH
ugObjectH
etEaFileH
RegistryH
eTemporaH
ryObjectH
ateUuidsH
eProfileH
stemTimeH
NtSaveMeH
rgedKeysH
NtSetBooH
tOptionsH
eateWnfSH
tateNameH
ddAtomExH
ateKeyTrH
ansactedH
itializeH
RegistryH
D$&tCH
reateLowH
BoxTokenH
yDirectoH
ryObjectH
D$&tOH
penKeyTrH
ansactedH
eryInforH
mationTrH
ansactioH
nManagerH
umerateTH
ransactiH
onObjectH
ntinueExH
ySectionH
D$&tDH
eleteDriH
verEntryH
WorkerFaH
ctoryWorH
kerReadyH
efaultUIH
LanguageH
eEnclaveH
ryObjectH
ocateUseH
rPhysicaH
lPagesExH
QueryOpeH
nSubKeysH
tPlugPlaH
yControlH
tSetDefaH
ultHardEH
rrorPortH
UuidSeedH
tAllocatH
eLocallyH
UniqueIdH
areSigniH
ngLevelsH
SetVolumH
eInformaH
tionFileH
nDirectoH
ryObjectH
NtOpenTrH
ansactioH
nManagerH
NtCallbaH
ckReturnH
rTokenExH
NtCancelH
IoFileExH
ayStringH
rtContaiH
nerImperH
sonationH
CreateSyH
mbolicLiH
nkObjectH
D$KueryH
SystemEnH
vironmenH
tValueExH
pagationH
CompleteH
llbackEnH
listmentH
PrivateNH
amespaceH
D$&tPH
ropagatiH
onFailedH
iteWatchH
nSectionH
D$&tEH
numerateH
ValueKeyH
NtReplyWH
aitReceiH
vePortExH
tImpersoH
nateClieH
ntOfPortH
ateNamedH
PipeFileH
leteAtomH
moveProcH
essDebugH
D$&tTH
ranslateH
FilePathH
yInformaH
tionAtomH
NtIsProcH
essInJobH
ReleaseSH
emaphoreH
FlushKeyH
rySecuriH
tyPolicyH
aveKeyExH
leteWnfSH
tateNameH
TerminatH
eEnclaveH
ryEaFileH
eateCrosH
sVmEventH
InformatH
ionTokenH
nResourcH
eManagerH
helpCachH
eControlH
lockFileH
ateTokenH
tMUIRegiH
stryInfoH
eryInforH
mationEnH
listmentH
eateMailH
slotFileH
ockVirtuH
alMemoryH
lseEventH
NtQueryDH
efaultUIH
LanguageH
mControlH
reateRegH
istryTraH
nsactionH
lEnclaveH
NtComparH
eObjectsH
NtAccessH
CheckByTH
ypeAndAuH
ditAlarmH
uestPortH
tQuerySyH
mbolicLiH
nkObjectH
earEventH
pleteConH
nectPortH
NtQueryIH
nformatiH
onByNameH
terTokenH
NtRaiseEH
xceptionH
ownWorkeH
rFactoryH
eateWaitH
ablePortH
itializeH
NlsFilesH
tEntriesH
D$&tAH
cceptConH
nectPortH
reTokensH
yDirectoH
ryFileExH
ptureVaSH
paceBulkH
dateWnfSH
tateDataH
tCreateEH
ventPairH
D$&tCH
ommitTraH
nsactionH
bleLastKH
nownGoodH
tCreateJH
obObjectH
D$&tAH
ccessCheH
ckByTypeH
eezeTranH
sactionsH
NtCommitH
CompleteH
alAndWaiH
tForSingH
leObjectH
ObjectAuH
ditAlarmH
tOpenTraH
nsactionH
NtOpenEnH
listmentH
D$&tSH
etSecuriH
tyObjectH
DevicePoH
werStateH
eTokenExH
QueryKeyH
tGetCompH
leteWnfSH
tateSubsH
criptionH
ushVirtuH
alMemoryH
erateBooH
tEntriesH
eryDefauH
ltLocaleH
gisterPrH
otocolAdH
dressInfH
ormationH
GetNlsSeH
ctionPtrH
NtShutdoH
wnSystemH
NtPrivilH
egeCheckH
D$&tAH
djustGroH
upsTokenH
D$&tQH
ueryLiceH
nseValueH
ateEventH
D$&tLH
ockVirtuH
alMemoryH
NtSetCacH
hedSigniH
ngLevel2H
tCancelSH
ynchronoH
usIoFileH
ecoverTrH
ansactioH
nManagerH
ventPairH
NtRecoveH
rResourcH
eManagerH
NtCreateH
PrivateNH
amespaceH
placeKeyH
ValueKeyH
tiatePowH
erActionH
FilterBoH
otOptionH
chedSignH
ingLevelH
NtEnumerH
ateDriveH
rEntriesH
NtRaiseHH
ardErrorH
NotifyChH
angeMultH
ipleKeysH
MultipleH
ValueKeyH
ReadFileH
NtQueryIH
nstallUIH
LanguageH
pactKeysH
AccessChH
eckByTypH
eResultLH
istAndAuL
ditAlarmL
loadKey2H
DebugFilH
terStateH
WriteReqH
uestDataH
ePermaneH
ntObjectH
tSetLowWH
aitHighEH
ventPairH
ContinueH
tReadReqH
uestDataH
stenPortH
eDirectoH
ryObjectH
leteWnfSH
tateDataH
NtGetNotH
ificatioH
nResourcH
eManagerH
penEventH
vilegedSH
erviceAuH
ditAlarmH
artitionH
D$&tRH
ecoverEnH
listmentH
AdjustToH
kenClaimH
sAndDeviH
ceGroupsH
NtDeleteH
ObjectAuH
ditAlarmH
D$&tSH
etBootEnH
tryOrderH
InstructH
ionCacheH
NtQueryAH
uxiliaryH
CounterFH
requencyH
D$KollfH
orwardTrH
ansactioH
nManagerH
nKeyTranH
sactedExH
NtFreezeH
RegistryH
D$&tIH
nitializH
eEnclaveH
nloadKeyH
SystemPoH
werStateH
adOnlyEnH
listmentH
FlushProH
cessWritH
eBuffersH
repareEnH
listmentH
eResourcH
eManagerH
eatePortH
yInformaH
tionFileH
plyWaitRH
eplyPortH
ockProduH
ctActivaH
tionKeysH
nectPortH
tManagePH
artitionH
rectGrapH
hicsCallH
yInformaH
tionPortH
D$&tQH
ueryWnfSH
tateDataH
pressKeyH
AccessChH
eckAndAuH
ditAlarmH
NtGetNexH
tProcessH
acePartiH
tionUnitH
tCreatePH
rofileExH
ystemInfH
ormationH
tSubscriH
beWnfStaH
teChangeH
NtOpenSyH
mbolicLiH
nkObjectH
ateReserH
veObjectH
setEventH
elIoFileH
DrawTextH
NtManageH
HotPatchH
tLockRegH
istryKeyH
PowerInfH
ormationH
SetDefauH
ltLocaleH
yWnfStatH
eNameInfH
ormationH
tCreatePH
artitionH
AccessChH
eckByTypH
eResultLH
istAndAuH
ditAlarmH
ByHandleH
rivilegeH
ObjectAuH
ditAlarmH
tSetLowEH
ventPairH
tOpenRegH
istryTraH
nsactionH
eryVolumH
eInformaH
tionFileH
bleLastKH
nownGoodH
leaseWorH
kerFactoH
ryWorkerH
QueryBooH
tOptionsH
D$DtdllH
ndows\syH
stem32\nH
tdll.dllH
eggcallH
eggcallH
l$HM9,$u
l$8M9,$u
d$(t6vSF
l$8M9,$u
D$Bcall
l$HM9,$
KeyKey
Unlock
Unwrap
ReadAt
pwrite
String
handle
status
offset
Family
Handle
Offset
HEvent
fmtSbx
sharpV
intbuf
Format`tI
Lookup
mustBe
CanInt
CanSet
IsZero
Method
SetCap
SetInt
SetLen
Slice3
NumOut
common
stkOff
append
Common
addArg
argLen
method
encode
strict
Strict
Decode
Encode`
closed
bisect
Uint64
Uint32
period`xH
*error
*uint8
*int16
*int32
*int64
*[]int
unsafe
opaque
nfiles
ptrbit
gcdata
etypes
rodata
gofunc
funcID
pcfile
signed
goexit
insert
remove
noscan
npages
nelems
divMul
inList
isFree
layout
refill
unpack
allocN
qcount
ticket
parent
tryGet
mcache
pcache
palloc
timers
cycles
lenPos
varint
thread
divmod
procid
vdsoSP
vdsoPC
noCopy
_panic
_defer
labels
counts
inHeap
ensure
scalar
parked
frames
retPop
abiMap
result`
shared
victim
delete
doSlow@
Getenv
decref
incref
rwlock
isFile
Accept
Fchdir
Fchmod
Fchown
Pwrite
Writev
errors
System
Relocs
closer`TK
Uint16
Align_
GCData
HasTag
Mcount
Xcount
Floats
Stride
NewGCM
Enable
Opaque@
Init64
Refill
Reseed@?@
recent
enable
cmpVal
topbits
*func()
Encrypt
TryLock
dirinfo
ReadDir
Readdir
WriteAt
WriteTo
readdir
wrapErr
writeTo
Timeout
Control
success
Release
syscall
ObjName
NewProc
Pointer
Machine
Exports
pending
consume
*fmt.pp
badVerb
doPrint
fmt0x64
fmtBool
reflect
PkgPath
buckets
CanAddr
CanUint
Complex
Convert
IsValid
MapKeys
SetBool
SetUint
SetZero
TryRecv
TrySend
pointer
ChanDir
gcSlice
nameOff
textOff
typeOff
GcSlice
HasName
MapType
addRcvr
*[]int8
regPtrs
*[8]int
amended
*[1]int
padChar
Replace
Namelen
Buffers
*string
runtime
*uint16
*uint32
*uint64
*[]uint
*[]bool
ptrSize
funcoff
filetab
covctrs
hasmain
typemap
srcFunc
npcdata
startPC
startSP
isEmpty
takeAll
objBase
pushAll
dequeue
enqueue
sortkey
waiters
nextSeq
inSweep
balance
dispose
putFast
pushcnt
discard
runnext
preempt
destroy
seqlock
entries
morebuf
gsignal
sigmask
blocked
isextra
alllink
lockedg
libcall
chacha8
lockedm
startpc
racectx
waiting
cgoCtxt
coroarg
tophash
growing
compute
ensured
gcStats
closing
makeArg
callers
popHead
popTail
private
getSlow
pinSlow
trySwap
InitBuf
InitMsg
RawRead
ReadMsg
prepare
Section
OEMinfo
Ordinal
Forward
*pe.Net
DosStub
Symbols
strconv
InCount
IsBlank
Methods
InSlice
unicode
Decrypt
outUsed
decrypt
Feature
setting
Package
Changed
verbose
literal
*[]uint8
overflow
*os.File
*os.file
ReadFrom
Truncate
readFrom
userTime
sockaddr
FindProc
Reserved
Internal
Sockaddr
*[8]bool
mustFind
mustLoad
FullName
CheckSum
ReadRune
*fmt.fmt
fmtFloat
truncate
fmtFlags
erroring
wrapErrs
doPrintf
fmtBytes
printArg
GoString
CanFloat
MapIndex
MapRange
NumField
SetBytes
SetFloat
assignTo
setRunes
typeSlow
uncommon
FuncType
Pointers
Uncommon
*[]int16
*[]int32
*[]int64
go.shape
checkSum
constSum
ReadByte
lastRead
contains
prevRune
nextwhen
fullName
*uintptr
*float32
*float64
*[]error
cuOffset
entryoff
baseaddr
bytedata
pcHeader
noptrbss
ecovctrs
funcName
textAddr
funcInfo
entryOff
FileLine
Function
tryMerge
subtract
lessThan
slotsPtr
sweepgen
needzero
elemsize
specials
heapBits
objIndex
flushGen
nextFree
scavenge
dataqsiz
elemtype
raceaddr
isSelect
waitlink
waittail
refStore
maySweep
putBatch
runqhead
runqtail
sudogbuf
statsSeq
waitTime
disabled
lastTime
varintAt
targetpc
waitsema
lockAddr
mstartfn
throwing
spinning
freeWait
ncgocall
waitlock
freelink
libcallg
dlogPerM
stktopsp
coroexit
tracking
writebuf
sigcode0
sigcode1
guintptr
released
inStacks
mSpanSys
otherSys
heapGoal
idleTime
cpuStats
heapScan
sysStats
cpuStats
concrete
asserted
dispatch
callingG
fileLine
dstSpill
lockSlow
pushHead
headTail
rwunlock
*poll.FD
InitBufs
lastbits
readbyte
IsStream
RawWrite
Shutdown
WSAIoctl
WriteMsg
eofError
readLock
pollable
waitRead
*pe.File
ReaderAt
Relocate
MetaData
Sections
PtrBytes
OutCount
OutSlice
register
*sys.nih
bitCount
generate
*[8]uint8
Temporary
*[4]uint8
*[1]uint8
*[14]int8
*[2]uint8
Interface
ImageBase
Subsystem
Signature
writeByte
writeRune
Precision
padString
reordered
panicking
argNumber
badArgNum
doPrintln
fmtString
Anonymous
CallSlice
NumMethod
SetString
bytesSlow
ArrayType
regAssign
retOffset
stackPtrs
inRegPtrs
framePool
*[]string
decodeMap
BlockSize
Available
ReadBytes
WriteByte
WriteRune
readSlice
math/rand
*chan int
*[]uint16
*[]uint32
*[]uint64
textStart
NotInHeap
pclntable
noptrdata
enoptrbss
typelinks
itablinks
pkghashes
inittasks
gcbssmask
startLine
isInlined
nfuncdata
StoreNoWB
rangefunc
lessEqual
recovered
nextDefer
nextFrame
schedtick
schedwhen
sizeclass
startAddr
freeindex
allocBits
spanclass
largeType
scanAlloc
reclaimed
deferpool
goidcache
numTimers
available
caughtsig
mallocing
profilehz
printlock
traceback
schedlink
lockedExt
lockedInt
nextwaitm
libcallpc
libcallsp
cheaprand
locksHeld
syscallsp
syscallpc
stackLock
waitsince
ancestors
noverflow
nevacuate
committed
largeFree
inObjects
stacksSys
mCacheSys
gcMiscSys
totalTime
stackScan
totalScan
heapStats
sleepStub
*[8]int32
assignArg
assignReg
localSize
ClearBufs
ConnectEx
Ftruncate
acceptOne
writeLock
waitWrite
Reserved2
InitialSP
InitialIP
*pe.Reloc
IsManaged
WriteFile
DosHeader
DosExists
PutUint16
PutUint32
PutUint64
*abi.Kind
*abi.Type
PtrToThis
*abi.Name
aesCipher
Specified
seenLossy
freqcache
bitCounts
bitLength
*[]func()
*[8]string
appendMode
checkValid
*[1]string
*struct {}
OffsetHigh
*[100]int8
SizeOfCode
BaseOfCode
*[8]uint64
*[50]uint8
UnreadRune
*fmt.State
clearflags
fmtBoolean
fmtInteger
fmtUnicode
widPresent
*[68]uint8
goodArgNum
catchPanic
fmtComplex
fmtPointer
missingArg
printValue
IsExported
CanComplex
CanConvert
Comparable
SetComplex
SetIterKey
SetPointer
UnsafeAddr
FieldAlign
Implements
IsVariadic
IfaceIndir
assignIntN
valueStart
stackBytes
outRegPtrs
StructType
*[64]uint8
DecodedLen
EncodedLen
*[5]uint32
*[8]uint32
ReadString
UnreadByte
*[4]uint16
*io.Writer
*io.Reader
*io.Closer
*[]uintptr
*complex64
*[]float32
*[]float64
pclnOffset
modulename
enoptrdata
pluginpath
gcdatamask
*runtime.g
*runtime.m
*runtime.p
insertBack
allocCache
gcmarkBits
pinnerBits
allocCount
countAlloc
nextSample
tinyoffset
tinyAllocs
stackcache
allocLarge
releaseAll
*[2]uint64
mSyscallID
tryGetFast
workbufhdr
checkempty
sysmontick
sudogcache
mspancache
timer0When
timersLock
recordLock
cyclesLost
stringData
threadLock
resumesema
goSigStack
preemptoff
isExtraInC
needextram
cgoCallers
preemptGen
waitreason
gcscandone
throwsplit
raceignore
parentGoid
selectDone
oldbuckets
difference
inWorkBufs
largeAlloc
numObjects
totalFreed
totalFrees
mSpanInUse
accumulate
gcIdleTime
atomicInfo
_interface
sysmonWake
sleepRatio
shouldStop
gomaxprocs
*chan bool
frameStore
*[4]uint64
unlockSlow
*[96]uint8
*sync.Pool
victimSize
swapLocked
*sync.Once
runtimeCtx
readuint16
RawControl
readUnlock
*pe.Export
BlockItems
*pe.Symbol
RichHeader
FileHeader
BaseOfData
*[8]uint16
*abi.TFlag
IsEmbedded
ReadVarint
crypto/aes
*hash.Hash
nonDefault
MarkerOnly
*[17]int32
*[0]func()
*[3]uintptr
*[6]uintptr
*[2]uintptr
*[5]uintptr
*os.dirInfo
SetDeadline
SyscallConn
WriteString
setDeadline
*func() int
*[256]uint8
SizeOfImage
LoaderFlags
*fmt.buffer
writeString
precPresent
wrappedErrs
unknownType
oldoverflow
panicNotMap
FieldByName
OverflowInt
SetMapIndex
capNonSlice
extendSlice
lenNonSlice
stackAssign
sync/atomic
*[9]uintptr
WithPadding
crypto/sha1
*[1]uintptr
*[607]int64
BufferCount
*io.discard
*complex128
pctabOffset
runtimehash
funcnametab
findfunctab
textsectmap
deferreturn
dstRegister
syscalltick
syscallwhen
speciallock
ensureSwept
pushAll
acquiretime
releasetime
bytesMarked
flushedWork
raceprocctx
pinnerCache
newSigstack
createstack
waitunlockf
isMutexWait
stackguard0
stackguard1
preemptStop
trackingSeq
setoverflow
newoverflow
noldbuckets
*[68]uint64
totalAllocs
mCacheInUse
buckHashSys
gcPauseTime
gcTotalTime
globalsScan
publishInfo
setEventErr
slotsOffset
errIntegral
errOverflow
*[10]uint16
*sync.Mutex
*sync.eface
poolDequeue
*sync.entry
GetFileType
readConsole
writeUnlock
prepareRead
VirtualSize
MZSignature
*pe.Section
*[]pe.Reloc
SizeOfBlock
MetaDataRVA
COFFSymbols
StringTable
FieldAlign_
DataChecked
*[15]uint64
ReturnIsPtr
*abi.FuncID
LatinOffset
*cipher.cfb
crypto/rand
*cpu.option
LoadAcquire
*[32]uint64
debug/dwarf
*dwarf.Attr
ShouldPrint
matchResult
resurrected
*func() bool
Readdirnames
*syscall.DLL
MustFindProc
InternalHigh
*[]struct {}
writePadding
CanInterface
FieldByIndex
MethodByName
OverflowUint
*func(int64)
SetIterValue
panicNotBool
AssignableTo
assignFloatN
*[]*abi.Type
makeFuncCtxt
*[16]uintptr
AppendDecode
AppendEncode
DecodeString
*sha1.digest
*rand.Source
*io.ReaderAt
RuntimeError
linktimehash
modulehashes
takeFromBack
deferBitsPtr
initHeapBits
dequeueSudoG
readyNextGen
statusTraced
heapScanWork
deferpoolbuf
goidcacheend
gcAssistTime
limiterEvent
timerRaceCtx
pageTraceBuf
*[32]uintptr
captureStack
recordUnlock
*runtime.mOS
highResTimer
isExtraInSig
mLockProfile
pcvalueCache
locksHeldLen
atomicstatus
paniconfault
inMarkAssist
runnableTime
sameSizeGrow
nextOverflow
gcCyclesDone
srcStackSize
dstStackSize
dstRegisters
*sync.noCopy
ReadMsgInet4
ReadMsgInet6
WriteToInet4
WriteToInet6
writeConsole
prepareWrite
waitCanceled
*atomic.Bool
*windows.DLL
MajorVersion
MinorVersion
StorageClass
OriginalName
MetaDataSize
ResourcesRVA
NetDirectory
AppendUint16
AppendUint32
AppendUint64
internal/abi
*abi.NameOff
*abi.TypeOff
*abi.Imethod
*abi.RegArgs
aesCipherAsm
XORKeyStream
internal/cpu
Undocumented
StoreRelease
ShouldEnable
*bisect.cond
*[][4]uint64
*flate.hcode
CodeByteShell
*func() error
*func() int64
*syscall.Proc
TimeDateStamp
FileAlignment
SizeOfHeaders
DataDirectory
*[8]struct {}
*func(string)
*func() int32
*fmt.fmtFlags
handleMethods
*fmt.Stringer
*reflect.Type
*reflect.Kind
*reflect.flag
InterfaceData
OverflowFloat
UnsafePointer
ConvertibleTo
InterfaceType
IsDirectIface
stepsForValue
decodeQuantum
MarshalBinary
crypto/sha256
*bytes.readOp
*bytes.Buffer
*bytes.Reader
*fs.PathError
*interface {}
*runtime.Func
filetabOffset
*runtime.itab
*[8]*abi.Type
takeFromFront
*runtime.coro
decPinCounter
getPinnerBits
incPinCounter
newPinnerBits
nextFreeIndex
pinnerBitSize
reportZombies
setPinnerBits
acquireStatus
*[253]uintptr
checknonempty
*[512]uintptr
deletedTimers
scannedStacks
*runtime.note
*[65504]uint8
varintReserve
cgoCallersUse
waitTraceSkip
signalPending
hasCgoOnStack
preemptShrink
parkingOnChan
nocgocallback
trackingStamp
gcAssistBytes
*runtime.hmap
*runtime.bmap
incrnoverflow
oldbucketmask
missingMethod
inputOverflow
IncNonDefault
*[]sync.eface
internal/poll
*poll.fdMutex
skipSyncNotif
ZeroReadIsEOF
GetsockoptInt
ReadFromInet4
ReadFromInet6
SetsockoptInt
WriteMsgInet4
WriteMsgInet6
*atomic.Int64
*windows.Proc
*pe.BlockItem
SectionNumber
*pe.DosHeader
OverlayNumber
SectionHeader
NetCLRVersion
*[]*pe.Symbol
ResourcesSize
VersionLength
VersionString
InsertionAddr
SizeOfRawData
*abi.FuncType
IntRegArgAddr
*abi.FuncFlag
crypto/cipher
*cipher.Block
*[]cpu.option
*atomic.Uint8
*[]dwarf.Attr
*bisect.dedup
*flate.byFreq
*intern.Value
*Public.AesCFB
*func() string
*syscall.Errno
VirtualAddress
OptionalHeader
*fmt.wrapError
truncateString
*fmt.Formatter
*reflect.Value
mustBeExported
*reflect.rtype
CompareAndSwap
*[]*sync.entry
EncodeToString
*sha256.digest
*go.shape.bool
*io.ReadSeeker
*runtime.Frame
funcnameOffset
*[]abi.TypeOff
*runtime._func
srcStackOffset
dstStackOffset
*runtime.stack
*runtime.gobuf
*runtime.mspan
*runtime.mutex
lockRankStruct
manualFreeList
typePointersOf
*runtime.gList
*runtime.sudog
*runtime.hchan
*runtime.waitq
*runtime.wbBuf
*runtime.timer
runSafePointFn
traceBufHeader
preemptExtLock
becomeSpinning
asyncSafePoint
createOverflow
tinyAllocCount
largeFreeCount
smallFreeCount
heapStatsDelta
totalAllocated
gcCyclesForced
scavengeBgTime
*[][]*abi.Type
tryLoadOrStore
*sync.readOnly
increfAndClose
*poll.pollDesc
*poll.fileKind
readbyteOffset
*atomic.noCopy
*atomic.Uint32
*atomic.Uint64
*pe.COFFSymbol
*pe.FileHeader
*[]*pe.Section
InsertionBytes
*[]abi.Imethod
*aes.aesCipher
*cipher.Stream
*[6]cpu.option
*godebug.value
nonDefaultOnce
*sys.NotInHeap
*godebugs.Info
*[8]dwarf.Attr
*bisect.Writer
*[]bisect.cond
compress/flate
*[]flate.hcode
*func() uintptr
SetReadDeadline
setReadDeadline
*func(int) bool
*syscall.Handle
*syscall.WSABuf
*Go2gabh.Export
NumberOfSymbols
Characteristics
*fmt.wrapErrors
*func() []error
*fmt.GoStringer
*reflect.Method
FieldByIndexErr
FieldByNameFunc
OverflowComplex
stringNonString
exportedMethods
ExportedMethods
*reflect.abiSeq
*map[string]int
*[8]*sync.entry
*func(int, int)
encoding/base64
ConstantTimeSum
UnmarshalBinary
AvailableBuffer
*rand.rngSource
*sort.Interface
*windows.WSAMsg
*chan struct {}
*unsafe.Pointer
*[]interface {}
*[8]abi.TypeOff
*runtime._defer
*runtime._panic
*runtime.sigset
*runtime.mcache
*runtime.gcBits
markBitsForBase
prepareForSweep
*runtime.pinner
setStatusTraced
statusWasTraced
*runtime.gcWork
*runtime.lfnode
inPtrScalarBits
largeAllocCount
smallAllocCount
gcDedicatedTime
Antivirus Signature
Bkav W64.AIDetectMalware
Lionic Trojan.Win32.ShellcodeRunner.4!c
Elastic malicious (high confidence)
ClamAV Clean
CMC Clean
CAT-QuickHeal Clean
Skyhigh Clean
ALYac Clean
Cylance Unsafe
Zillya Clean
Sangfor Trojan.Win32.Save.a
CrowdStrike win/malicious_confidence_90% (D)
Alibaba Clean
K7GW Clean
K7AntiVirus Clean
huorong Clean
Baidu Clean
VirIT Clean
Paloalto generic.ml
Symantec ML.Attribute.HighConfidence
tehtris Clean
ESET-NOD32 a variant of WinGo/ShellcodeRunner.UG
APEX Malicious
Avast FileRepMalware [Drp]
Cynet Malicious (score: 100)
Kaspersky Trojan.Win64.Shellcode.auz
BitDefender Trojan.Autoruns.GenericKD.150
NANO-Antivirus Clean
ViRobot Clean
MicroWorld-eScan Trojan.Autoruns.GenericKD.150
Tencent Win64.Trojan.Shellcode.Ekjl
Sophos Mal/Generic-S
F-Secure Dropper.DR/AVI.Agent.utbzo
DrWeb Clean
VIPRE Clean
TrendMicro Trojan.Win64.AMADEY.YXEJ3Z
McAfeeD ti!6DC5FCBD3D05
Trapmine Clean
CTX exe.trojan.shellcoderunner
Emsisoft Trojan.Autoruns.GenericKD.150 (B)
Ikarus Trojan.WinGo.Agent
FireEye Clean
Jiangmin Clean
Varist W64/ABTrojan.OPWA-8597
Avira DR/AVI.Agent.utbzo
Fortinet W32/ShellcodeRunner.UG!tr
Antiy-AVL Trojan/Win32.ShellcodeRunner
Kingsoft Win32.Troj.Unknown.a
Gridinsoft Clean
Xcitium Clean
Arcabit Clean
SUPERAntiSpyware Clean
ZoneAlarm UDS:DangerousObject.Multi.Generic
Microsoft Trojan:Win64/Androm
Google Detected
AhnLab-V3 Trojan/Win.Donut.C5688175
Acronis Clean
McAfee Artemis!F01ED03B7A78
TACHYON Clean
VBA32 Clean
Malwarebytes Malware.AI.3996307552
Panda Trj/Chgt.AD
Zoner Clean
TrendMicro-HouseCall Trojan.Win64.AMADEY.YXEJ3Z
Rising Clean
Yandex Clean
SentinelOne Static AI - Suspicious PE
MaxSecure Clean
GData Win32.Malware.Donut.1515V3
AVG FileRepMalware [Drp]
DeepInstinct MALICIOUS
alibabacloud Trojan:Multi/ShellcodeRunner.UU
No IRMA results available.