Static | ZeroBOX

PE Compile Time

2024-11-02 01:54:27

PE Imphash

407b29a1346b818a12b66f58555063ce

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x0004f0da 0x0004f200 6.52049402813
.rdata 0x00051000 0x00014840 0x00014a00 5.32826499325
.data 0x00066000 0x00006ddc 0x00002c00 3.30876973057
.rsrc 0x0006d000 0x000001e0 0x00000200 4.71767883295
.reloc 0x0006e000 0x000045b4 0x00004600 6.6248038445

Resources

Name Offset Size Language Sub-language File type
RT_MANIFEST 0x0006d060 0x0000017d LANG_ENGLISH SUBLANG_ENGLISH_US XML 1.0 document text

Imports

Library KERNEL32.dll:
0x451060 GetFileAttributesA
0x451064 Process32NextW
0x451068 CreateFileA
0x45106c Process32FirstW
0x451070 CloseHandle
0x451074 GetSystemInfo
0x451078 CreateThread
0x45107c GetThreadContext
0x451080 GetProcAddress
0x451084 GetLastError
0x451088 RemoveDirectoryA
0x45108c ReadProcessMemory
0x451090 CreateProcessA
0x451094 CreateDirectoryA
0x451098 SetThreadContext
0x45109c SetEndOfFile
0x4510a0 HeapSize
0x4510a4 GetProcessHeap
0x4510b0 GetTempPathA
0x4510b4 Sleep
0x4510bc OpenProcess
0x4510c4 GetModuleHandleA
0x4510c8 ResumeThread
0x4510cc GetComputerNameExW
0x4510d0 GetVersionExW
0x4510d4 WaitForSingleObject
0x4510d8 CreateMutexA
0x4510dc FindClose
0x4510e0 PeekNamedPipe
0x4510e4 CreatePipe
0x4510e8 FindNextFileA
0x4510ec VirtualAlloc
0x4510f4 WriteFile
0x4510f8 VirtualFree
0x4510fc FindFirstFileA
0x451104 WriteProcessMemory
0x451108 GetModuleFileNameA
0x45110c VirtualAllocEx
0x451110 ReadFile
0x45111c GetOEMCP
0x451120 GetACP
0x451124 IsValidCodePage
0x451128 FindNextFileW
0x45112c FindFirstFileExW
0x451134 HeapReAlloc
0x451138 ReadConsoleW
0x45113c SetStdHandle
0x451140 GetFullPathNameW
0x451148 DeleteFileW
0x45114c EnumSystemLocalesW
0x451150 GetUserDefaultLCID
0x451154 IsValidLocale
0x451158 GetLocaleInfoW
0x45115c LCMapStringW
0x451160 CompareStringW
0x451164 HeapAlloc
0x451168 HeapFree
0x45116c GetConsoleMode
0x451170 GetConsoleOutputCP
0x451174 FlushFileBuffers
0x451178 SetFilePointerEx
0x45117c GetFileSizeEx
0x451180 GetCommandLineW
0x451184 GetCommandLineA
0x451188 GetStdHandle
0x45118c GetModuleFileNameW
0x451198 GetFileType
0x4511a0 GetDriveTypeW
0x4511a4 CreateFileW
0x4511a8 RaiseException
0x4511ac GetCurrentThreadId
0x4511c0 CloseThreadpoolWork
0x4511c4 GetModuleHandleExW
0x4511dc InitOnceComplete
0x4511e4 InitializeSRWLock
0x451210 GetModuleHandleW
0x451214 EncodePointer
0x451218 DecodePointer
0x45121c MultiByteToWideChar
0x451220 WideCharToMultiByte
0x451224 LCMapStringEx
0x451228 GetStringTypeW
0x45122c GetCPInfo
0x451234 SetEvent
0x451238 ResetEvent
0x45123c CreateEventW
0x451248 GetCurrentProcess
0x45124c TerminateProcess
0x451250 IsDebuggerPresent
0x451254 GetStartupInfoW
0x451258 GetCurrentProcessId
0x45125c InitializeSListHead
0x451260 RtlUnwind
0x451264 SetLastError
0x451268 TlsAlloc
0x45126c TlsGetValue
0x451270 TlsSetValue
0x451274 TlsFree
0x451278 FreeLibrary
0x45127c LoadLibraryExW
0x451280 ExitProcess
0x451284 WriteConsoleW
Library USER32.dll:
0x45129c GetSystemMetrics
0x4512a0 ReleaseDC
0x4512a4 GetDC
Library GDI32.dll:
0x45104c SelectObject
0x451050 CreateCompatibleDC
0x451054 DeleteObject
0x451058 BitBlt
Library ADVAPI32.dll:
0x451000 RevertToSelf
0x451004 RegCloseKey
0x451008 RegQueryInfoKeyW
0x45100c RegGetValueA
0x451010 RegQueryValueExA
0x451018 GetSidSubAuthority
0x45101c GetUserNameA
0x451024 LookupAccountNameA
0x45102c RegSetValueExA
0x451030 OpenProcessToken
0x451034 RegOpenKeyExA
0x451038 RegEnumValueA
0x45103c DuplicateTokenEx
Library SHELL32.dll:
0x45128c SHGetFolderPathA
0x451290 ShellExecuteA
0x451294 SHFileOperationA
Library ole32.dll:
0x45132c CoUninitialize
0x451330 CoCreateInstance
0x451334 CoInitialize
Library WININET.dll:
0x4512ac HttpOpenRequestA
0x4512b0 InternetWriteFile
0x4512b4 InternetOpenUrlA
0x4512b8 InternetOpenW
0x4512bc HttpEndRequestW
0x4512c4 HttpSendRequestExA
0x4512c8 InternetOpenA
0x4512cc InternetCloseHandle
0x4512d0 HttpSendRequestA
0x4512d4 InternetConnectA
0x4512d8 InternetReadFile
Library gdiplus.dll:
0x45130c GdiplusStartup
0x451310 GdipSaveImageToFile
0x451318 GdiplusShutdown
0x451324 GdipDisposeImage
Library WS2_32.dll:
0x4512e0 closesocket
0x4512e4 inet_pton
0x4512e8 getaddrinfo
0x4512ec WSAStartup
0x4512f0 send
0x4512f4 socket
0x4512f8 connect
0x4512fc recv
0x451300 htons
0x451304 freeaddrinfo

!This program cannot be run in DOS mode.
`.rdata
@.data
@.reloc
CM @PRj
VVVVhP
CE PRQQ
CE PRQQ
CE PRQQ
CE PRQQ
CE PRQQ
urj@j"
PPPPPWS
tFh$&E
QQSVWd
URPQQh@
UQPXY]Y[
F4_^[]
<ItC<Lt3<Tt#<h
A<lt'<tt
SVWj03
WWWSHSh
WPWWWS
tGh08E
t3h<8E
t"hH8E
:u"f9z
ARPRQh
PPPPPPPP
SWt@jU
_tqPVj@
u&h<NE
j$h(@F
3=$aF
<at.<rt!<wt
<=upG8
[ShTNE
[Sh\NE
[ShdNE
u,PQRS
Wj0XPV
SPjdVQ
QQSVj8j@
D8(Ht'
PPPPPWS
PP9E u:PPVWP
u kE$<
j-Xf9E
zSSSSj
f9:t!V
tl=@bF
NX9^`t1
;V\uYW
tjh`kE
u2Vj@h
9C`u99C\t4
u29K\t-
CY<u
PPPPPPPP
bad exception
bad allocation
bad function call
device or resource busy
invalid argument
no such process
not enough memory
operation not permitted
resource deadlock would occur
resource unavailable try again
address family not supported
address in use
address not available
already connected
argument list too long
argument out of domain
bad address
bad file descriptor
bad message
broken pipe
connection aborted
connection already in progress
connection refused
connection reset
cross device link
destination address required
directory not empty
executable format error
file exists
file too large
filename too long
function not supported
host unreachable
identifier removed
illegal byte sequence
inappropriate io control operation
interrupted
invalid seek
io error
is a directory
message size
network down
network reset
network unreachable
no buffer space
no child process
no link
no lock available
no message available
no message
no protocol option
no space on device
no stream resources
no such device or address
no such device
no such file or directory
not a directory
not a socket
not a stream
not connected
not supported
operation canceled
operation in progress
operation not supported
operation would block
owner dead
permission denied
protocol error
protocol not supported
read only file system
result out of range
state not recoverable
stream timeout
text file busy
timed out
too many files open in system
too many files open
too many links
too many symbolic link levels
value too large
wrong protocol type
unknown error
FlsAlloc
FlsFree
FlsGetValue
FlsSetValue
InitializeCriticalSectionEx
InitOnceExecuteOnce
CreateEventExW
CreateSemaphoreW
CreateSemaphoreExW
CreateThreadpoolTimer
SetThreadpoolTimer
WaitForThreadpoolTimerCallbacks
CloseThreadpoolTimer
CreateThreadpoolWait
SetThreadpoolWait
CloseThreadpoolWait
FlushProcessWriteBuffers
FreeLibraryWhenCallbackReturns
GetCurrentProcessorNumber
CreateSymbolicLinkW
GetCurrentPackageId
GetTickCount64
GetFileInformationByHandleEx
SetFileInformationByHandle
GetSystemTimePreciseAsFileTime
InitializeConditionVariable
WakeConditionVariable
WakeAllConditionVariable
SleepConditionVariableCS
InitializeSRWLock
AcquireSRWLockExclusive
TryAcquireSRWLockExclusive
ReleaseSRWLockExclusive
SleepConditionVariableSRW
CreateThreadpoolWork
SubmitThreadpoolWork
CloseThreadpoolWork
CompareStringEx
GetLocaleInfoEx
LCMapStringEx
0123456789abcdefghijklmnopqrstuvwxyz
0123456789abcdefghijklmnopqrstuvwxyz
__based(
__cdecl
__pascal
__stdcall
__thiscall
__fastcall
__vectorcall
__clrcall
__eabi
__swift_1
__swift_2
__ptr64
__restrict
__unaligned
restrict(
delete
operator
`vftable'
`vbtable'
`vcall'
`typeof'
`local static guard'
`string'
`vbase destructor'
`vector deleting destructor'
`default constructor closure'
`scalar deleting destructor'
`vector constructor iterator'
`vector destructor iterator'
`vector vbase constructor iterator'
`virtual displacement map'
`eh vector constructor iterator'
`eh vector destructor iterator'
`eh vector vbase constructor iterator'
`copy constructor closure'
`udt returning'
`local vftable'
`local vftable constructor closure'
new[]
delete[]
`omni callsig'
`placement delete closure'
`placement delete[] closure'
`managed vector constructor iterator'
`managed vector destructor iterator'
`eh vector copy constructor iterator'
`eh vector vbase copy constructor iterator'
`dynamic initializer for '
`dynamic atexit destructor for '
`vector copy constructor iterator'
`vector vbase copy constructor iterator'
`managed vector copy constructor iterator'
`local static thread guard'
operator ""
operator co_await
operator<=>
Type Descriptor'
Base Class Descriptor at (
Base Class Array'
Class Hierarchy Descriptor'
Complete Object Locator'
`anonymous namespace'
CorExitProcess
(null)
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
[aOni*{
~ $s%r
@b;zO]
v2!L.2
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
UTF-16LEUNICODE
Sunday
Monday
Tuesday
Wednesday
Thursday
Friday
Saturday
January
February
August
September
October
November
December
MM/dd/yy
dddd, MMMM dd, yyyy
HH:mm:ss
AreFileApisANSI
EnumSystemLocalesEx
GetDateFormatEx
GetTimeFormatEx
GetUserDefaultLocaleName
IsValidLocaleName
LCIDToLocaleName
LocaleNameToLCID
AppPolicyGetProcessTerminationMethod
NAN(SNAN)
nan(snan)
NAN(IND)
nan(ind)
_hypot
_nextafter
1#QNAN
1#SNAN
]vQ<)8
|)P!?Ua0
Eb2]A=
u?^p?o4
y1~?|"
?x+s7
?5Od%
?|I7Z#
>,'1D=
?g)([|X>=
~U`?K
:h"?bC
@H#?43
Ax#?uN}*
r7Yr7=
F0$?3=1
H`$?h|
&?~YK|
sU0&?W
<8bunz8
?#%X.y
F||<##
<@En[vP
?5Wg4p
%S#[k=
"B <1=
Unknown exception
bad array new length
string too long
generic
iostream
Fail to schedule the chore!
This function cannot be called on a default constructed task
broken promise
future already retrieved
promise already satisfied
no state
future
invalid stoi argument
stoi argument out of range
bad locale name
ios_base::badbit set
ios_base::failbit set
ios_base::eofbit set
d122f964d1224a00cff1eef50e53e286
07c6bc37dc50874878dcb010336ed906
1b6eb2
78ac18116a6aa0b8e6b8858603044624
PJ8SQhDqQIVoFTBjOE3=
OQIcgR9kYxLm4WU 12lkgKmq
QIVnSy==
XoRcgFPm
MISjiO==
OIMjiO==
P E9RBbYPcMdHA==
UT9RiVQmOcMVSQ==
XQ0x0D9uXaM4MWa9erdpf64UMJ8hfdOqgTE4V1QrfcMl7FOaesSff6 7JrPmXT2e2G==
XQ0x0D9uXaM4MWa9erdpf64UMJ8hfdOqgTE4V1QrfcMl7FOaesSff6 7G1bofx6t2NA40VIef9sK4GKhdHGwf6CeO1Dr
XTI9hlMUfq==
1SSbNA4wLvAEKEaHKHdpP7Ja
XQ0x0D9uXaM4MWa9erdpf64UMJ8hfdOqgTE4V1QrfcMl7FOaesSff6 7JrPm
fdMl4EslPpz8
XxAm41EaeND=
XQ0x0D9uXaM4MWa9erdpf64UMJ8hfdOqgTE4V1QrfcMl7FOaesSff6 7G1bofx6t2NA4Z0ceewn8KmYh1L0ogA==
MLMKWTEJXa0xLUmuLV==
0uwnhy==
Xu0K0y==
1TAc4A0dewoZR2meeH afKC2
1TAc4A0dewn=
1SoghA0dewn=
WMwgge==
dxIRhBjoOm==
dxIRhFHZOoZ=
OTwSfUQT
ORsjiU9iedDm
MdMlfVL2
fS9cgErsP9Wb5Gl=
dSMpgkQlPpzlSGmh
USMRYkATdNQcN3aofL0jW0 g1A==
XxAm41EaeKI97Gu2
TLQsZZL XS0d7H37erZ=
TNQghkz=
VSwqhEQrfSkWBEm70l==
ULEw0y==
Xwwl4Ez XSMa7XyefMp=
Uw0aiE4rLv5cRg==
PpPn0E4T1MoKSWCQerqQiU==
TccR4EQf2MWbSXx=
Wc0piE4n
XS0nfE4s
TS0kg0Mo
YSclWEQf2MWbSXx=
PtvpRxLUQ 4VHQ==
TS0liEQngsSL8XqaQnGjh0CU01v geNq2c0pgQWd1NI9Hyq8d80k3KKs4XUlPJXo
OIRkQQVm
GGgug00T2MWREUGee8Glg6qU003mS yheTAkQUMagwvYBGU7d1ZZMqWb3KyaSpyhdMocgkAm2JR
L7RBV04ngwMl7CQJg2GbSmGb2LvkeNKcgwcmgg4o1TIc7CQofMOb205HrkUC
GGfkQQVmOIR=
OIREHe==
STEahhVq
Ocgn4u==
TS0liEQngsSL8XqaQnG8gLGm00H hxiqe90VQV9WgoSd53yiN20ofK0oN63c3NN=
XRcK0CQG0uES6nyadsWtf6 U2q3kYTSV0uEmglMreSo4J2YieM0Q31OIN0Vd1vKqeNsSiEQrWcwkSQ==
TS0khFQT2NAFRWQa
1MAa4EQf2S9g4mihd1 lgLKs27LTheaZhNfnRRDsQtLTGz6UN0c=
ONMlfUIo2wLk
XRcK0CQG0uES6nyadsWtf6 U2q3kYTSV0uEmglMreSo4OWUefL0aZqqeO035UR6JYvAGYDsPVKIwM1l=
XRcK0CQG0uEm5nGnd7CJ31VqBHz5YTStgcca4VI6Tcwq4WCtc2SmfKKZMJTh3xSq
Yccb4U4CUq==
0trnRBv=
UwMd3VQlgvEc7HGedripPpmMO1HnfySVdM0l
UwMd3VQlgvEc7HGedripPpqMO1HnfySVdM0l
XQ0x0D9uXaM4MWa9erdpf64UMJ8hfdOqgTD8YjM6TTMp6mKjfK4bgrSj16Y=
XxAm4FQcguW95WJ=
P roTO==
P rpRe==
P roSe==
P rpSO==
TTMphkQnguAS4Wm
fdMl4EslPpzlSX7a
LdI9h0okdMojBCYbKHdffWFc
L9rdOgwTdMSc53KPKIJ7Nm3aOKPkMr==
M9P8WVcigsz=
L9rdOgwr2MV8
LsPdNy==
Xw0U4VEsdwMj5CUagLZ=
OMMV4UIUgwcm5nqkdLq iWGsO0VnhxSudM5l4UL OKQg5GJ6Kl==
fS9SiEMogSV8EXB6N2V7QE==
fTH0hu==
fcwl4E4m
VSMW3k4afcH8MGuUd80Q1JGsO0rn2NN=
PtrnRBvTPJb=
PtrnRBvTP z=
PtrnRBvTP D=
PtrnRBvTPSP=
ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/
abcdefghijklmnopqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVWXYZ0123456789
System
NtUnmapViewOfSection
ntdll.dll
0x00000000
fDenyTSConnections
SYSTEM\CurrentControlSet\Control\Terminal Server
netsh advfirewall firewall set rule group="Remote Desktop" new enable=Yes
sc config termservice start= auto
net start termservice
" /add /y
net user "
" /add
net localgroup "Administrators" "
'" SET PasswordExpires=FALSE
WMIC USERACCOUNT WHERE "Name = '
'" SET Passwordchangeable=FALSE
' -DestinationPath '
powershell -Command Expand-Archive -Path '
vnc.exe
invalid string position
list too long
vector too long
iostream stream error
0123456789ABCDEF
.text$di
.text$mn
.text$x
.text$yd
.idata$5
.00cfg
.CRT$XCA
.CRT$XCAA
.CRT$XCC
.CRT$XCL
.CRT$XCU
.CRT$XCZ
.CRT$XIA
.CRT$XIAA
.CRT$XIAC
.CRT$XIC
.CRT$XIZ
.CRT$XLA
.CRT$XLZ
.CRT$XPA
.CRT$XPX
.CRT$XPXA
.CRT$XPZ
.CRT$XTA
.CRT$XTZ
.rdata
.rdata$T
.rdata$r
.rdata$sxdata
.rdata$voltmd
.rdata$zzzdbg
.rtc$IAA
.rtc$IZZ
.rtc$TAA
.rtc$TZZ
.tls$ZZZ
.xdata$x
.idata$2
.idata$3
.idata$4
.idata$6
.data$r
.data$rs
.rsrc$01
.rsrc$02
ReadFile
GetModuleFileNameA
WriteProcessMemory
SetHandleInformation
FindFirstFileA
VirtualFree
WriteFile
Wow64DisableWow64FsRedirection
VirtualAlloc
FindNextFileA
CreatePipe
PeekNamedPipe
FindClose
CreateMutexA
WaitForSingleObject
GetVersionExW
GetComputerNameExW
ResumeThread
GetModuleHandleA
OpenProcess
SetCurrentDirectoryA
CreateToolhelp32Snapshot
GetTempPathA
Wow64RevertWow64FsRedirection
GetLastError
GetFileAttributesA
Process32NextW
CreateFileA
Process32FirstW
CloseHandle
GetSystemInfo
CreateThread
GetThreadContext
GetProcAddress
VirtualAllocEx
RemoveDirectoryA
ReadProcessMemory
CreateProcessA
CreateDirectoryA
SetThreadContext
KERNEL32.dll
ReleaseDC
GetSystemMetrics
USER32.dll
DeleteObject
CreateCompatibleDC
SelectObject
CreateCompatibleBitmap
BitBlt
GDI32.dll
GetSidIdentifierAuthority
DuplicateTokenEx
RegEnumValueA
RegOpenKeyExA
OpenProcessToken
RegSetValueExA
ImpersonateLoggedOnUser
LookupAccountNameA
CreateProcessWithTokenW
GetUserNameA
GetSidSubAuthority
GetSidSubAuthorityCount
RegQueryValueExA
RegGetValueA
RegQueryInfoKeyW
RegCloseKey
RevertToSelf
ADVAPI32.dll
ShellExecuteA
SHGetFolderPathA
SHFileOperationA
SHELL32.dll
CoInitialize
CoUninitialize
CoCreateInstance
ole32.dll
HttpOpenRequestA
InternetWriteFile
InternetOpenUrlA
InternetOpenW
HttpEndRequestW
HttpAddRequestHeadersA
HttpSendRequestExA
InternetOpenA
InternetCloseHandle
HttpSendRequestA
InternetConnectA
InternetReadFile
WININET.dll
GdipSaveImageToFile
GdipGetImageEncodersSize
GdipDisposeImage
GdipCreateBitmapFromHBITMAP
GdipGetImageEncoders
GdiplusShutdown
GdiplusStartup
gdiplus.dll
freeaddrinfo
getaddrinfo
inet_pton
WS2_32.dll
RaiseException
GetCurrentThreadId
IsProcessorFeaturePresent
FreeLibraryWhenCallbackReturns
CreateThreadpoolWork
SubmitThreadpoolWork
CloseThreadpoolWork
GetModuleHandleExW
InitializeConditionVariable
WakeConditionVariable
WakeAllConditionVariable
SleepConditionVariableCS
SleepConditionVariableSRW
InitOnceComplete
InitOnceBeginInitialize
InitializeSRWLock
ReleaseSRWLockExclusive
AcquireSRWLockExclusive
EnterCriticalSection
LeaveCriticalSection
InitializeCriticalSectionEx
TryEnterCriticalSection
DeleteCriticalSection
WaitForSingleObjectEx
QueryPerformanceCounter
GetSystemTimeAsFileTime
GetModuleHandleW
EncodePointer
DecodePointer
MultiByteToWideChar
WideCharToMultiByte
LCMapStringEx
GetStringTypeW
GetCPInfo
InitializeCriticalSectionAndSpinCount
SetEvent
ResetEvent
CreateEventW
UnhandledExceptionFilter
SetUnhandledExceptionFilter
GetCurrentProcess
TerminateProcess
IsDebuggerPresent
GetStartupInfoW
GetCurrentProcessId
InitializeSListHead
RtlUnwind
SetLastError
TlsAlloc
TlsGetValue
TlsSetValue
TlsFree
FreeLibrary
LoadLibraryExW
ExitProcess
CreateFileW
GetDriveTypeW
GetFileInformationByHandle
GetFileType
SystemTimeToTzSpecificLocalTime
FileTimeToSystemTime
GetModuleFileNameW
GetStdHandle
GetCommandLineA
GetCommandLineW
GetFileSizeEx
SetFilePointerEx
FlushFileBuffers
GetConsoleOutputCP
GetConsoleMode
HeapFree
HeapAlloc
CompareStringW
LCMapStringW
GetLocaleInfoW
IsValidLocale
GetUserDefaultLCID
EnumSystemLocalesW
DeleteFileW
GetCurrentDirectoryW
GetFullPathNameW
SetStdHandle
ReadConsoleW
HeapReAlloc
GetTimeZoneInformation
FindFirstFileExW
FindNextFileW
IsValidCodePage
GetACP
GetOEMCP
GetEnvironmentStringsW
FreeEnvironmentStringsW
SetEnvironmentVariableW
GetProcessHeap
HeapSize
SetEndOfFile
WriteConsoleW
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
.?AVbad_exception@std@@
.?AVfuture_error@std@@
.?AVlogic_error@std@@
.?AVinvalid_argument@std@@
.?AVlength_error@std@@
.?AVout_of_range@std@@
.?AVbad_function_call@std@@
.?AVfailure@ios_base@std@@
.?AVruntime_error@std@@
.?AVbad_alloc@std@@
.?AVsystem_error@std@@
.?AVtask_canceled@Concurrency@@
.?AV<lambda_0456396a71e3abd88ede77bdd2823d8e>@@
.?AV<lambda_5e5ab22ea98f4361dbf159481d01f54d>@@
.?AV<lambda_9de88c4009318ef1202283857f94e673>@@
.?AV<lambda_cf64729cb90f65090849ddab3f3d5e68>@@
.?AV_Interruption_exception@details@Concurrency@@
.?AV_System_error@std@@
.?AVinvalid_operation@Concurrency@@
.?AV?$_Fake_no_copy_callable_adapter@A6GXPAUConnexionDetails@@@ZAAPAU1@@std@@
.?AVexception@std@@
.?AV<lambda_eb87dfd73f857f44e1a351ea42ce2b34>@@
.?AVbad_array_new_length@std@@
.?AV_ExceptionPtr_normal@?A0xb4bb966e@@
.?AV?$_ExceptionPtr_static@Vbad_alloc@std@@@?A0xb4bb966e@@
.?AV?$_ExceptionPtr_static@Vbad_exception@std@@@?A0xb4bb966e@@
.?AVstl_condition_variable_interface@details@Concurrency@@
.?AVstl_condition_variable_vista@details@Concurrency@@
.?AVstl_condition_variable_win7@details@Concurrency@@
.?AV_Locimp@locale@std@@
.?AVstl_critical_section_interface@details@Concurrency@@
.?AVstl_critical_section_vista@details@Concurrency@@
.?AVstl_critical_section_win7@details@Concurrency@@
.?AVtype_info@@
.?AV?$basic_stringstream@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@
.?AV?$basic_filebuf@DU?$char_traits@D@std@@@std@@
.?AV?$_Func_impl_no_alloc@V<lambda_5e5ab22ea98f4361dbf159481d01f54d>@@X$$V@std@@
.?AV?$codecvt@DDU_Mbstatet@@@std@@
.?AV_Future_error_category2@std@@
.?AV?$_Ref_count_obj2@U_ExceptionHolder@details@Concurrency@@@std@@
.?AV?$_Func_impl_no_alloc@V<lambda_cf64729cb90f65090849ddab3f3d5e68>@@X$$V@std@@
.?AU?$_InitialTaskHandle@XV<lambda_9de88c4009318ef1202283857f94e673>@@U_TypeSelectorNoAsync@details@Concurrency@@@?$task@E@Concurrency@@
.?AV?$_Func_impl_no_alloc@V<lambda_0456396a71e3abd88ede77bdd2823d8e>@@X$$V@std@@
.?AV?$_Func_impl_no_alloc@V<lambda_9de88c4009318ef1202283857f94e673>@@X$$V@std@@
.?AV?$basic_stringbuf@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@
.?AVios_base@std@@
.?AVerror_category@std@@
.?AV?$_Associated_state@H@std@@
.?AV?$ctype@D@std@@
.?AV?$basic_iostream@DU?$char_traits@D@std@@@std@@
.?AV?$_CancellationTokenCallback@V<lambda_3b8ab8d2629adf61a42ee3fe177a046b>@@@details@Concurrency@@
.?AVcodecvt_base@std@@
.?AV_Facet_base@std@@
.?AV?$_Func_impl_no_alloc@V<lambda_eb87dfd73f857f44e1a351ea42ce2b34>@@E$$V@std@@
.?AV_Generic_error_category@std@@
.?AV?$_Func_impl_no_alloc@V?$_Fake_no_copy_callable_adapter@A6GXPAUConnexionDetails@@@ZAAPAU1@@std@@X$$V@std@@
.?AU_Crt_new_delete@std@@
.?AV?$_Iosb@H@std@@
.?AV_Iostream_error_category2@std@@
.?AV?$basic_ofstream@DU?$char_traits@D@std@@@std@@
.?AV_DefaultPPLTaskScheduler@details@Concurrency@@
.?AV?$basic_streambuf@DU?$char_traits@D@std@@@std@@
.?AU?$_Task_impl@E@details@Concurrency@@
.?AUctype_base@std@@
.?AV?$_Func_base@X$$V@std@@
.?AV?$basic_istream@DU?$char_traits@D@std@@@std@@
.?AV?$basic_ios@DU?$char_traits@D@std@@@std@@
.?AV?$_Task_async_state@X@std@@
.?AVfacet@locale@std@@
.?AU?$_PPLTaskHandle@EU?$_InitialTaskHandle@XV<lambda_9de88c4009318ef1202283857f94e673>@@U_TypeSelectorNoAsync@details@Concurrency@@@?$task@E@Concurrency@@U_TaskProcHandle@details@3@@details@Concurrency@@
.?AV_RefCounter@details@Concurrency@@
.?AV_Ref_count_base@std@@
.?AV?$_Ref_count_obj2@U?$_Task_impl@E@details@Concurrency@@@std@@
.?AV?$basic_ostream@DU?$char_traits@D@std@@@std@@
.?AV?$_Func_base@E$$V@std@@
.?AU_TaskProcHandle@details@Concurrency@@
.?AUscheduler_interface@Concurrency@@
.?AV?$_Packaged_state@$$A6AXXZ@std@@
.?AV_CancellationTokenRegistration@details@Concurrency@@
.?AU_Task_impl_base@details@Concurrency@@
<?xml version='1.0' encoding='UTF-8' standalone='yes'?>
<assembly xmlns='urn:schemas-microsoft-com:asm.v1' manifestVersion='1.0'>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v3">
<security>
<requestedPrivileges>
<requestedExecutionLevel level='asInvoker' uiAccess='false' />
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
0#0(020C0H0R0c0h0r0
1#1(121C1H1R1c1h1r1
2#2(222C2H2R2c2h2r2
3#3(323C3H3R3c3h3r3
4#4(424C4H4R4c4h4r4
5#5(525C5H5R5c5h5r5
6#6(626C6H6R6c6h6r6
7#7(727C7H7R7c7h7r7
8#8(828C8H8R8c8h8r8
9#9(929C9H9R9c9h9r9
:#:(:2:C:H:R:c:h:r:
;#;(;2;C;H;R;c;h;r;
<#<(<2<C<H<R<c<h<r<
=#=(=2=C=H=R=c=h=r=
>#>(>2>C>H>R>c>h>r>
?#?(?2?C?H?R?c?h?r?
0#0(020C0H0R0c0h0r0
1"111C1M1c1m1
2 2'24282D2J2X2k2w2
<'<6<J<`<
< =I=V=v=
>!>)>3>D>J>N>T>`>
3V4e4&5:5
769F9`9f:x:
;V<6=H=
0F1U1G2_2d2k2r2y2
2`3d3h3l3v3
8F9P9U9q9
;3;`;i;z;
<<'<4<9<
=!=f=x=
>6><>C>
2e3r3x3
3W4b4o4
<@<g<r<z<
<<=C=]=6>E>.?6?W?^?
1"1+1Q1g1n1w1
2"2&383
5>6a6j6F7\7
3,3@3\3
4$4<4C4
6#767R7
:&:I:l:
I0X0}0
1+1A1K1Y1^1d1k1
1/2K2U2c2
566C6_6
7;7T7Z7
:':8:F:N:T:^:h:r:|:
637T7r7
8+9L9_9
;&<5<'>
5,666V7h7
&050{0V2h2
797}7d8s8
<!<e<L=[=
1M142C2
9&;8;u;
>->V>e>
89V<f<o<u<
!0(0W0n0
4I5V5_5e5s5
7)767?7_7p7z7
1243_3
5D6M6S6w6
6,6I6u6
212g2q2
5&5D5M5e5
646J6w6
7%7@7H7t7{7
8 959a9q9v9
9:-:@:L:S:f:r:}:
;;;E;R;\;n;
0"0=0X0s0
1,2N2T2\2
3!3-343y3
3X4n4z4
6&:8:`:
>%>/>7>
??6?H?
6$7Q7\7p7
5(5,50545F5X5
4 464H4
0K1Z1r1
6$6(6,606F6X6{6
8W8)9c9
223"5?5s6Z8w8
=_=d>i>w>}>
0'0-060
6 6:6y6
:!;G;d;
5 5$5(5,5054585<5@5D5H5L5P5T5X5\5`5d5h5l5v5
:.:M:q:
6$6<6o6
0171Y1r1
1&242S2m2
3*3f3s3
363H3a4
:H;O;a;v;
<%<T<Z<m<t<z<
3,7\7V8d8
0?1L1c1m1v1
282E2w2
8%9+929I9V9
95:D:!;>;
<.<F<T<e<w<
=2=F=L=d=n=|=
?!?1?8?D?^?}?
00>0t0
2&2A2N2Z2u2
343N3n3
414I4\4q4
415B5I5Q5g5
7-7H7S7
8*9>9J9
:#:/:I:h:s:~:
<-<M<q<|<
11%1*10161;1A1G1L1R1X1]1c1i1n1t1z1
2$2)2/252:2?2F2K2Q2W2\2b2h2m2s2y2~2
3#3(3.34393?3E3J3P3V3[3a3g3l3r3x3}3
4 4,494N4V4\4j4r4
7$7/767;7D7R7W7g7l7}7
88,878@8H8R8X8^8d8p8~8
9 9'9.959<9C9J9R9Z9b9n9w9|9
::&:-:4:;:B:I:P:X:`:h:s:x:~:
<3<:<@<R<\<
=8>c>x>}>
3N4W4_4
5#5,5N5U5h5q5
6>6G6T6Z6
7)8A8F8
(0/04080<0@0
4!4%4)4-4145494=4A4E4I4M4Q4U4Y4]4a4e4i4m4q4u4
7!7=7H7V7\7m7~7
5/5K5k5y5
7,7=7I7X7p7
8!8*8/848O8Y8e8j8o8
::.:C:M:`:g:s:
;><D<X<
<K=P=W=}=
;%;y;g<q<~<
<J=m=t=
3]4a4e4i4m4q4u4y4P9W9|9
2g2$4w4
6$858F8W8+:9:
;%;3;C;X;o;
;M<a<j<
>&?Y?l?
4!4'4B4I4i4
<#<P<W<
4!4,424=4C4Q4o4
5-5F5}5
!2'292D2
=F>s>|>
&0D0O0
0!1&1+10191
:(;=;O;\;u;
<.<5<V<
050S0q0
303:3S3
; <=<\<5=
$0a0k0
2@2H2\2h2m2r2
3#3(383=3B3R3W3\3l3q3v3
4-4Y4b4
6%6*6/6J6Y6d6i6n6
787J7`7e7j7
8#959A9V9`9x:
:\;9<@<
8I9[9a9
; <*<`<
>8?G?U?r?z?
0X0_0h0
112E2|2
5/5E5R5W5e5
7M7o788j9
1a2~203
636Z6$7.7X7k8A:
1>14Y5t5
< >&>A>F>s>{>
?'?0?;?C?a?m?
3D3h3q3|3
2$2.282<2B2F2L2R2X2^2d2
2 3(343A3H3Q3Z3j3{3
425;5y5
6)6.646
9*9<9}9
= >.>:>K>Y>d>,?
$030p0~0
7/7A7S7e7w7
5#6\6s6
859T96:j<
9 :H:z:
8G<M=U=
7S7b7~<,=
?I?X?d?s?
40=0F0O0z0
22>2D2
5%5.5T5E6
6I9Q9Y9a9i9
7,8T8t8
2,3z3r4
7$7A7c7
9#9b9l9
:":,:W:a:k:
;!;+;B;L;w;
<7<A<K<b<l<
="=,=W=a=k=
>!>+>B>L>w>
?7?A?K?b?l?
0"0,0W0a0k0
1!1+1B1L1w1
272A2K2b2l2
3"3,3W3a3k3
4!4+4B4L4w4
575A5K5b5l5
6"6,6W6a6k6
7!7+7B7L7w7
878A8K8b8l8
9"9,9W9a9k9
:!:+:B:L:w:
;7;A;K;b;l;
<"<,<W<a<k<
=!=+=B=L=w=
>7>A>K>b>l>
?"?,?W?a?k?
0!0+0B0L0w0
171A1K1b1l1
2"2,2W2a2k2
3!3+3B3L3w3
474A4K4b4l4
5"5,5W5a5k5
6!6+6B6L6w6
777A7K7b7l7
8"8,8W8a8k8
9!9+9B9L9w9
:7:A:K:b:l:
;";,;W;a;k;
<!<+<B<L<w<
=7=A=K=b=l=
>">,>W>a>k>
?!?+?B?L?w?
070A0K0b0l0
1"1,1W1a1k1
2!2+2B2L2w2
373A3K3b3l3
4"4,4W4a4k4
5!5+5B5L5w5
676A6K6b6l6
7"7,7W7a7k7
8!8+8B8L8w8
979A9K9b9l9
:":,:W:a:k:
;!;+;B;L;w;
<7<A<K<b<l<
="=-=\=f=p=
>">,>6>B>m>s>}>
?/?9?C?a?q?
0"0,0W0a0k0}0
<3D3H3L3P3T3X3\3`3d3h3l3p3t3x3|3
4 4$4(4,4044484<4@4D4H4L4P4T4X4\4`4d4h4l4p4t4x4|4
5 5$5(5,5054585<5@5D5H5L5P5T5X5\5`5d5h5l5p5t5x5|5
6 6$6(6,60646H6L6P6d6h6l6p6t6x6|6
7 7$7(7,7074787<7@7D7H7L7P7T7h7l7p7t7x7|7
7H8L8P8T8X8\8`8d8h8l8p8t8x8|8
8l;t;|;
<$<,<4<<<D<L<T<\<d<l<t<|<
=$=,=4=<=D=L=T=\=d=l=t=|=
d3h3l3p3t3x3|3
3074787<7@7D7H7L7P7T7X7\7`7d7h7l7p7t7x7|7
: :(:0:8:@:H:P:X:`:h:p:x:
; ;(;0;8;@;H;P;X;`;h;p;x;
< <(<0<8<@<H<P<X<`<h<p<x<
3$3(3
`<h<p<t<x<|<
<`=h=l=p=t=x=|=
=p>t>x>|>
?$?(?,?0?4?8?<?@?D?H?L?P?T?X?\?`?d?h?l?p?t?x?|?
034383<3@3D3H3L3P3T3X3\3`3d3h3l3p3t3x3|3X9\9`9d9h9l9p9t9x9|9
:$:,:4:<:D:L:T:\:d:l:t:|:
>$>0><>H>T>`>l>x>
? ?,?8?D?P?\?h?t?
0(040@0L0X0d0p0|0
1(141@1L1X1d1p1|1
<$<,<4<<<D<L<T<\<d<l<t<|<
=$=,=4=<=D=L=T=\=d=l=t=|=
>$>,>4><>D>L>T>\>d>l>t>|>
?$?,?4?<?D?L?T?\?d?l?t?|?
0$0,040<0D0L0T0\0d0l0t0|0
1$1,141<1D1L1T1\1d1l1t1|1
2$2,242<2D2L2T2\2d2l2t2|2
= =(=0=8=@=H=P=X=`=h=p=x=
> >(>0>8>@>H>P>X>`>h>p>x>
? ?(?0?8?@?H?P?X?`?h?p?x?
0 0(00080@0H0P0X0`0h0p0x0
1 1(10181@1H1P1X1`1h1p1x1
2 2(20282@2H2P2X2`2h2p2x2
3 3(30383@3H3P3X3`3h3p3x3
H>L>P>T>X>\>`>d>h>l>p>t>x>|>
? ?$?(?,?0?4?8?<?@?D?H?L?P?
0 0$0(0,0004080<0@0D0H0L0P0T0X0\0`0d0h0l0p0t0
1014181<1T1X1\1`1d1h1l1p1t1x1|1
14282@2
3 30343D3H3L3T3l3|3
4 484H4L4\4`4d4l4
5,505@5D5H5L5T5l5|5
6,6064686@6X6h6l6|6
707@7D7T7X7\7d7|7
8 808@8P8T8d8h8l8
909@9D9T9X9h9x9|9
: :0:4:D:H:`:d:h:l:
;0;4;8;<;D;H;L;P;T;\;t;
< <$<(<,<0<4<<<T<d<h<x<|<
= =4=8=P=T=X=l=p=t=x=
>(>,>0>H>X>\>p>
? ?8?<?T?d?t?x?|?
00040L0P0T0h0l0
1 1$1<1L1P1T1\1t1
2 2$2<2L2\2l2p2
3 3$3(3,3034383<3@3T3X3p3t3x3
4,40444L4\4l4p4
5(585H5L5P5T5\5t5
6064686@6H6`6p6
707@7P7T7\7`7d7x7|7
8 8$8,8D8H8`8p8
?<?D?P?p?
040T0`0
1$1,141D1P1p1x1
2<2D2P2X2|2
3,343<3D3L3T3\3h3
4$4,484X4d4
5 5(50585@5H5X5|5
6,646<6D6P6p6|6
7 7@7H7P7X7`7l7
8,848<8D8L8T8`8
989D9d9l9t9
:<:D:P:p:x:
;(;H;P;`;
<$<,<4<<<H<l<t<|<
=8=@=L=l=t=
> >(>4>T>\>d>t>|>
? ?(?8?\?d?l?t?|?
0$0,040<0H0h0p0|0
1$1,141<1D1L1T1\1d1l1t1|1
2 2D2L2T2\2d2l2t2|2
3<3D3L3T3\3d3l3t3|3
4,444<4D4L4T4\4d4l4x4
545<5D5L5T5\5d5l5t5|5
6$6,646<6D6L6T6\6d6l6t6|6
7$7,747<7D7L7T7\7d7p7
8 8(80888@8P8t8|8
9$9,949<9D9L9T9\9d9l9t9|9
:$:,:4:<:D:L:T:\:d:l:t:|:
;$;,;4;<;D;L;T;\;d;l;x;
<$<,<4<<<D<L<T<\<d<l<t<|<
=$=,=4=<=D=L=T=\=d=l=t=|=
>$>,>4><>H>l>t>|>
?$?,?4?<?D?L?T?\?d?l?t?|?
0<0D0L0T0\0d0l0t0|0
1<1D1L1T1\1d1l1t1|1
2$2,242<2D2L2T2\2d2p2
3$3,343<3D3L3T3\3d3l3t3|3
444<4D4L4T4\4d4l4t4|4
5$5,545<5D5L5T5\5d5l5t5|5
6$6,646<6D6L6T6\6d6l6t6
7$7,747<7D7L7T7\7d7l7t7|7
8$8,848<8D8L8T8\8d8l8t8|8
9$9,949<9D9L9T9\9d9l9t9|9
:$:,:4:<:D:L:T:\:d:l:t:|:
;$;,;4;<;D;L;T;`;
< <D<L<T<\<d<l<t<|<
=$=,=4=<=D=L=T=\=d=l=t=|=
>$>,>4><>D>L>T>\>d>l>t>|>
? ?,?L?X?x?
0 040D0P0p0|0
1 1@1L1l1x1
2,242<2H2P2
30383P3X3l3|3
4 4(404<4\4h4
5(5H5P5X5`5l5
60686@6H6P6`6p6
747@7`7l7
8<8L8X8`8
9 9@9H9P9\9|9
:8:D:d:l:t:x:|:
;,;4;<;D;H;L;T;h;p;x;
<4<8<T<X<x<
= =<=@=\=`=
> >@>`>|>
? ?@?`?
0 0@0`0
1 1@1`1
2 2@2`2h2t2
3(3H3h3
4$4(404D4L4P4T4X4`4t4|4
0\0`0h0
082<2@2D2H2L2P2T2X2\2`2d2p2t2x2|2
2 303@3P3`3x3
3@6D6H6L6
Bkernel32.dll
api-ms-win-core-synch-l1-2-0.dll
Eapi-ms-win-core-fibers-l1-1-1
api-ms-win-core-synch-l1-2-0
kernel32
api-ms-
mscoree.dll
(null)
((((( H
((((( H
(
DLC_ALL
LC_COLLATE
LC_CTYPE
LC_MONETARY
LC_NUMERIC
LC_TIME
Sunday
Monday
Tuesday
Wednesday
Thursday
Friday
Saturday
January
February
August
September
October
November
December
MM/dd/yy
dddd, MMMM dd, yyyy
HH:mm:ss
Eapi-ms-win-core-datetime-l1-1-1
api-ms-win-core-file-l1-2-2
api-ms-win-core-localization-l1-2-1
api-ms-win-core-localization-obsolete-l1-2-0
api-ms-win-core-processthreads-l1-1-2
api-ms-win-core-string-l1-1-0
api-ms-win-core-sysinfo-l1-2-1
api-ms-win-core-winrt-l1-1-0
api-ms-win-core-xstate-l2-1-0
api-ms-win-rtcore-ntuser-window-l1-1-0
api-ms-win-security-systemfunctions-l1-1-0
ext-ms-win-ntuser-dialogbox-l1-1-0
ext-ms-win-ntuser-windowstation-l1-1-0
advapi32
api-ms-win-appmodel-runtime-l1-1-2
user32
ext-ms-
Eja-JP
american
american english
american-english
australian
belgian
canadian
chinese
chinese-hongkong
chinese-simplified
chinese-singapore
chinese-traditional
dutch-belgian
english-american
english-aus
english-belize
english-can
english-caribbean
english-ire
english-jamaica
english-nz
english-south africa
english-trinidad y tobago
english-uk
english-us
english-usa
french-belgian
french-canadian
french-luxembourg
french-swiss
german-austrian
german-lichtenstein
german-luxembourg
german-swiss
irish-english
italian-swiss
norwegian
norwegian-bokmal
norwegian-nynorsk
portuguese-brazilian
spanish-argentina
spanish-bolivia
spanish-chile
spanish-colombia
spanish-costa rica
spanish-dominican republic
spanish-ecuador
spanish-el salvador
spanish-guatemala
spanish-honduras
spanish-mexican
spanish-modern
spanish-nicaragua
spanish-panama
spanish-paraguay
spanish-peru
spanish-puerto rico
spanish-uruguay
spanish-venezuela
swedish-finland
america
britain
england
great britain
holland
hong-kong
new-zealand
pr china
pr-china
puerto-rico
slovak
south africa
south korea
south-africa
south-korea
trinidad & tobago
united-kingdom
united-states
zh-CHS
az-AZ-Latn
uz-UZ-Latn
kok-IN
syr-SY
div-MV
quz-BO
sr-SP-Latn
az-AZ-Cyrl
uz-UZ-Cyrl
quz-EC
sr-SP-Cyrl
quz-PE
smj-NO
bs-BA-Latn
smj-SE
sr-BA-Latn
sma-NO
sr-BA-Cyrl
sma-SE
sms-FI
smn-FI
zh-CHT
az-az-cyrl
az-az-latn
bs-ba-latn
div-mv
kok-in
quz-bo
quz-ec
quz-pe
sma-no
sma-se
smj-no
smj-se
smn-fi
sms-fi
sr-ba-cyrl
sr-ba-latn
sr-sp-cyrl
sr-sp-latn
syr-sy
uz-uz-cyrl
uz-uz-latn
zh-chs
zh-cht
CONOUT$
image/jpeg
Antivirus Signature
Bkav W32.AIDetectMalware
Lionic Trojan.Win32.Amadey.a!c
Elastic malicious (high confidence)
MicroWorld-eScan Trojan.GenericKD.74672006
CTX exe.trojan.amadey
CAT-QuickHeal Trojandownloader.Deyma
ALYac Gen:Variant.Doina.48774
Cylance Unsafe
Zillya Downloader.Amadey.Win32.481
CrowdStrike win/malicious_confidence_100% (D)
BitDefender Trojan.GenericKD.74672006
K7GW Trojan-Downloader ( 005790d31 )
K7AntiVirus Trojan-Downloader ( 005790d31 )
huorong Clean
VirIT Trojan.Win32.Genus.WWP
Symantec ML.Attribute.HighConfidence
tehtris Clean
ESET-NOD32 a variant of Win32/TrojanDownloader.Amadey.A
APEX Malicious
Paloalto generic.ml
Cynet Malicious (score: 100)
Kaspersky UDS:DangerousObject.Multi.Generic
Alibaba TrojanDownloader:Win32/Deyma.16768b2e
NANO-Antivirus Trojan.Win32.AVI.ktfoir
ViRobot Clean
Tencent Malware.Win32.Gencirc.11caf0b6
Sophos Troj/Amadey-O
F-Secure Clean
DrWeb Trojan.MulDrop28.36200
VIPRE Trojan.GenericKD.74672006
TrendMicro Clean
McAfeeD Real Protect-LS!C07E06E76DE5
Trapmine malicious.moderate.ml.score
CMC Clean
Emsisoft Trojan.GenericKD.74672006 (B)
Ikarus Trojan.Spy.Stealer
FireEye Generic.mg.c07e06e76de584bc
Jiangmin Clean
Webroot Clean
Varist W32/Agent.DJJ.gen!Eldorado
Avira DR/AVI.Agent.zxrkv
Antiy-AVL Trojan[Downloader]/Win32.Deyma
Kingsoft Win32.Trojan-Downloader.Deyma.gen
Gridinsoft Trojan.Win32.Amadey.tr
Xcitium Malware@#1yo3drjdyrl54
Arcabit Trojan.Generic.D4736786
SUPERAntiSpyware Clean
ZoneAlarm HEUR:Trojan-Downloader.Win32.Deyma.gen
Microsoft Trojan:Win32/Multiverze
Google Detected
AhnLab-V3 Dropper/Win.Generic.C5689800
Acronis Clean
VBA32 BScope.TrojanDownloader.Deyma
TACHYON Clean
Malwarebytes Trojan.MalPack
Panda Trj/Chgt.AD
Zoner Clean
TrendMicro-HouseCall Clean
Rising Downloader.Amadey!8.125AC (TFE:5:NOjn92KW7VV)
Yandex Trojan.DL.Amadey!l2iDsWs+1R8
SentinelOne Static AI - Malicious PE
Fortinet W32/Amadey.A!tr.dldr
DeepInstinct MALICIOUS
alibabacloud Clean
No IRMA results available.