Static | ZeroBOX

PE Compile Time

2024-11-28 18:09:19

PE Imphash

bb056fb7e1da8cae84145e3bec77d9d4

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x0009aa4a 0x0009ac00 6.64789198134
.rdata 0x0009c000 0x0000902c 0x00009200 5.00067786803
.data 0x000a6000 0x000045ec 0x00002200 5.34160419249
.00cfg 0x000ab000 0x00000008 0x00000200 0.0611628522412
.tls 0x000ac000 0x00000009 0x00000200 0.0203931352361
.reloc 0x000ad000 0x00004eac 0x00005000 6.70085806698
.bss 0x000b2000 0x0004a800 0x0004a800 7.99941404054

Imports

Library KERNEL32.dll:
0x4a3d84 CloseHandle
0x4a3d88 CloseThreadpoolWork
0x4a3d8c CompareStringW
0x4a3d90 CreateEventW
0x4a3d94 CreateFileW
0x4a3d9c DecodePointer
0x4a3da4 EncodePointer
0x4a3dac ExitProcess
0x4a3db0 FindClose
0x4a3db4 FindFirstFileExW
0x4a3db8 FindNextFileW
0x4a3dbc FlushFileBuffers
0x4a3dc4 FreeLibrary
0x4a3dcc GetACP
0x4a3dd0 GetCPInfo
0x4a3dd4 GetCommandLineA
0x4a3dd8 GetCommandLineW
0x4a3ddc GetConsoleMode
0x4a3de0 GetConsoleOutputCP
0x4a3de4 GetCurrentProcess
0x4a3de8 GetCurrentProcessId
0x4a3dec GetCurrentThreadId
0x4a3df4 GetFileSize
0x4a3df8 GetFileSizeEx
0x4a3dfc GetFileType
0x4a3e00 GetLastError
0x4a3e04 GetModuleFileNameA
0x4a3e08 GetModuleFileNameW
0x4a3e0c GetModuleHandleA
0x4a3e10 GetModuleHandleExW
0x4a3e14 GetModuleHandleW
0x4a3e18 GetOEMCP
0x4a3e1c GetProcAddress
0x4a3e20 GetProcessHeap
0x4a3e24 GetStartupInfoW
0x4a3e28 GetStdHandle
0x4a3e2c GetStringTypeW
0x4a3e34 HeapAlloc
0x4a3e38 HeapFree
0x4a3e3c HeapReAlloc
0x4a3e40 HeapSize
0x4a3e48 InitOnceComplete
0x4a3e58 InitializeSListHead
0x4a3e5c InitializeSRWLock
0x4a3e60 IsDebuggerPresent
0x4a3e68 IsValidCodePage
0x4a3e6c LCMapStringW
0x4a3e74 LoadLibraryExW
0x4a3e78 MultiByteToWideChar
0x4a3e80 RaiseException
0x4a3e84 ReadFile
0x4a3e8c ResetEvent
0x4a3e90 RtlUnwind
0x4a3e98 SetEvent
0x4a3e9c SetFilePointerEx
0x4a3ea0 SetLastError
0x4a3ea4 SetStdHandle
0x4a3eb8 TerminateProcess
0x4a3ebc TlsAlloc
0x4a3ec0 TlsFree
0x4a3ec4 TlsGetValue
0x4a3ec8 TlsSetValue
0x4a3ed4 VirtualAlloc
0x4a3ed8 VirtualFree
0x4a3ee8 WideCharToMultiByte
0x4a3eec WriteConsoleW
0x4a3ef0 WriteFile
Library USER32.dll:
0x4a3ef8 BeginPaint
0x4a3efc CreateWindowExW
0x4a3f00 DefWindowProcW
0x4a3f04 DispatchMessageW
0x4a3f08 EndPaint
0x4a3f0c GetMessageW
0x4a3f10 PostQuitMessage
0x4a3f14 RegisterClassW
0x4a3f18 ShowWindow
0x4a3f1c TranslateMessage
0x4a3f20 UpdateWindow
Library GDI32.dll:
0x4a3f28 TextOutW

!This program cannot be run in DOS mode.$
`.rdata
@.data
.00cfg
.reloc
F(-f 4
F(-\Yn
F(-^z
F(-^KJ
F(-#;(
F(-Q4!
F(-i~g$
F(-(g7?
F(-uo6a
F@uo6a
F$-w},
QQSVWd
<ItC<Lt3<Tt#<h
A<lt'<tt
8^8tb9^4~]
YYh|;J
URPQQh
M$j"^QRRRRR
M,j"^QRRRRR
Vj0XPW
j"[VWWWW
uSSSSj
f9:t!V
QQSVj8j@
UQPXY]Y[
PPPPPWV
PP9E uPPSWP
PVVVVV
^PQQQQQ
E ^PQQQQ
CY<u
PPPPPPPP
PVVVVV
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
[aOni*{
~ $s%r
@b;zO]
v2!L.2
?5Wg4p
%S#[k=
"B <1=
success
Unknown exception
This function cannot be called on a default constructed task
bad array new length
vector too long
string too long
no state
broken promise
future
future already retrieved
Memory successs released
promise already satisfied
generic
Fail to schedule the chore!
dddd, MMMM dd, yyyy
MM/dd/yy
directory not empty
text file busy
device or resource busy
no such file or directory
not a directory
is a directory
not enough memory
February
January
Thursday
Tuesday
Wednesday
Saturday
Sunday
Monday
Friday
GetLocaleInfoEx
InitializeCriticalSectionEx
LCMapStringEx
CompareStringEx
GetFileInformationByHandleEx
stream timeout
timed out
August
_hypot
invalid argument
operator co_await
SetThreadpoolWait
CreateThreadpoolWait
CloseThreadpoolWait
connection reset
network reset
not a socket
__restrict
file exists
connection already in progress
operation in progress
no such device or address
bad address
no such process
no child process
CorExitProcess
HH:mm:ss
FlushProcessWriteBuffers
FreeLibraryWhenCallbackReturns
too many symbolic link levels
too many links
WaitForThreadpoolTimerCallbacks
no stream resources
resource deadlock would occur
bad file descriptor
operator
executable format error
io error
unknown error
protocol error
_nextafter
SetThreadpoolTimer
CreateThreadpoolTimer
CloseThreadpoolTimer
October
GetCurrentProcessorNumber
November
September
December
network down
no protocol option
bad exception
inappropriate io control operation
bad allocation
argument out of domain
resource unavailable try again
too many files open
too many files open in system
read only file system
not a stream
__fastcall
__thiscall
__vectorcall
__clrcall
__stdcall
bad function call
__cdecl
__pascal
SubmitThreadpoolWork
CreateThreadpoolWork
CloseThreadpoolWork
no link
cross device link
invalid seek
operation would block
InitializeSRWLock
__eabi
argument list too long
filename too long
message size
ReleaseSRWLockExclusive
TryAcquireSRWLockExclusive
AcquireSRWLockExclusive
FlsSetValue
FlsGetValue
delete
address in use
wrong protocol type
broken pipe
GetSystemTimePreciseAsFileTime
SetFileInformationByHandle
state not recoverable
address not available
no lock available
no message available
WakeAllConditionVariable
InitializeConditionVariable
WakeConditionVariable
host unreachable
network unreachable
value too large
file too large
result out of range
no message
bad message
FlsFree
illegal byte sequence
InitOnceExecuteOnce
no space on device
no such device
no buffer space
AppPolicyGetProcessTerminationMethod
identifier removed
operation not permitted
address family not supported
function not supported
operation not supported
protocol not supported
not supported
connection aborted
interrupted
already connected
not connected
connection refused
destination address required
__unaligned
operation canceled
permission denied
owner dead
GetCurrentPackageId
FlsAlloc
new[]
delete[]
CreateEventExW
CreateSemaphoreExW
CreateSymbolicLinkW
CreateSemaphoreW
SleepConditionVariableSRW
SleepConditionVariableCS
1#SNAN
1#QNAN
AreFileApisANSI
LocaleNameToLCID
operator<=>
GetTickCount64
__ptr64
__swift_3
__swift_2
__swift_1
nan(snan)
(null)
nan(ind)
NAN(SNAN)
NAN(IND)
restrict(
__based(
Base Class Descriptor at (
Base Class Array'
Class Hierarchy Descriptor'
Type Descriptor'
`vector deleting destructor'
`scalar deleting destructor'
`vbase destructor'
`vector copy constructor iterator'
`eh vector copy constructor iterator'
`managed vector copy constructor iterator'
`vector vbase copy constructor iterator'
`eh vector vbase copy constructor iterator'
`vector constructor iterator'
`eh vector constructor iterator'
`managed vector constructor iterator'
`vector vbase constructor iterator'
`eh vector vbase constructor iterator'
`vector destructor iterator'
`eh vector destructor iterator'
`managed vector destructor iterator'
Complete Object Locator'
`virtual displacement map'
`vcall'
`string'
`udt returning'
`omni callsig'
`typeof'
`copy constructor closure'
`default constructor closure'
`local vftable constructor closure'
`placement delete closure'
`placement delete[] closure'
`vftable'
`local vftable'
`vbtable'
`anonymous namespace'
`local static thread guard'
`local static guard'
`dynamic atexit destructor for '
`dynamic initializer for '
operator ""
AcquireSRWLockExclusive
CloseHandle
CloseThreadpoolWork
CompareStringW
CreateEventW
CreateFileW
CreateThreadpoolWork
DecodePointer
DeleteCriticalSection
EncodePointer
EnterCriticalSection
ExitProcess
FindClose
FindFirstFileExW
FindNextFileW
FlushFileBuffers
FreeEnvironmentStringsW
FreeLibrary
FreeLibraryWhenCallbackReturns
GetACP
GetCPInfo
GetCommandLineA
GetCommandLineW
GetConsoleMode
GetConsoleOutputCP
GetCurrentProcess
GetCurrentProcessId
GetCurrentThreadId
GetEnvironmentStringsW
GetFileSize
GetFileSizeEx
GetFileType
GetLastError
GetModuleFileNameA
GetModuleFileNameW
GetModuleHandleA
GetModuleHandleExW
GetModuleHandleW
GetOEMCP
GetProcAddress
GetProcessHeap
GetStartupInfoW
GetStdHandle
GetStringTypeW
GetSystemTimeAsFileTime
HeapAlloc
HeapFree
HeapReAlloc
HeapSize
InitOnceBeginInitialize
InitOnceComplete
InitializeConditionVariable
InitializeCriticalSectionAndSpinCount
InitializeCriticalSectionEx
InitializeSListHead
InitializeSRWLock
IsDebuggerPresent
IsProcessorFeaturePresent
IsValidCodePage
LCMapStringW
LeaveCriticalSection
LoadLibraryExW
MultiByteToWideChar
QueryPerformanceCounter
RaiseException
ReadFile
ReleaseSRWLockExclusive
ResetEvent
RtlUnwind
SetEnvironmentVariableW
SetEvent
SetFilePointerEx
SetLastError
SetStdHandle
SetUnhandledExceptionFilter
SleepConditionVariableCS
SleepConditionVariableSRW
SubmitThreadpoolWork
TerminateProcess
TlsAlloc
TlsFree
TlsGetValue
TlsSetValue
TryEnterCriticalSection
UnhandledExceptionFilter
VirtualAlloc
VirtualFree
WaitForSingleObjectEx
WakeAllConditionVariable
WakeConditionVariable
WideCharToMultiByte
WriteConsoleW
WriteFile
BeginPaint
CreateWindowExW
DefWindowProcW
DispatchMessageW
EndPaint
GetMessageW
PostQuitMessage
RegisterClassW
ShowWindow
TranslateMessage
UpdateWindow
TextOutW
KERNEL32.dll
USER32.dll
GDI32.dll
iThVLJ
.?AVbad_array_new_length@std@@
.?AVbad_alloc@std@@
.?AVexception@std@@
.?AV?$_Deferred_async_state@_N@std@@
.?AV?$_Packaged_state@$$A6A_NXZ@std@@
.?AV?$_Associated_state@_N@std@@
.?AV?$_Func_impl_no_alloc@V?$_Fake_no_copy_callable_adapter@A6A_NPAD@ZAAY0BAE@D@std@@_N$$V@std@@
.?AV?$_Func_base@_N$$V@std@@
.?AV?$_Fake_no_copy_callable_adapter@A6A_NPAD@ZAAY0BAE@D@std@@
.?AV_Future_error_category2@std@@
.?AVerror_category@std@@
.?AVsystem_error@std@@
.?AV_System_error@std@@
.?AVruntime_error@std@@
.?AV_Generic_error_category@std@@
.?AV?$_Task_async_state@_N@std@@
.?AV?$_Ref_count_obj2@U?$_Task_impl@E@details@Concurrency@@@std@@
.?AV_Ref_count_base@std@@
.?AU?$_Task_impl@E@details@Concurrency@@
.?AU_Task_impl_base@details@Concurrency@@
.?AV_DefaultPPLTaskScheduler@details@Concurrency@@
.?AUscheduler_interface@Concurrency@@
.?AV?$_Func_impl_no_alloc@V<lambda_1>@?0??_CancelAndRunContinuations@?$_Task_impl@E@details@Concurrency@@UAE_N_N00ABV?$shared_ptr@U_ExceptionHolder@details@Concurrency@@@std@@@Z@X$$V@std@@
.?AV?$_Func_base@X$$V@std@@
.?AV?$_Func_impl_no_alloc@V<lambda_1>@?0??_ScheduleContinuationTask@_Task_impl_base@details@Concurrency@@QAEXPAU_ContinuationTaskHandleBase@45@@Z@X$$V@std@@
.?AV?$_Func_impl_no_alloc@V<lambda_1>@?0???R1?0??_ScheduleContinuationTask@_Task_impl_base@details@Concurrency@@QAEXPAU_ContinuationTaskHandleBase@45@@Z@QBE?A?<auto>@@XZ@X$$V@std@@
.?AV<lambda_1>@?0???R0?0??_ScheduleContinuationTask@_Task_impl_base@details@Concurrency@@QAEXPAU_ContinuationTaskHandleBase@34@@Z@QBE?A?<auto>@@XZ@
.?AV<lambda_1>@?0??_ScheduleContinuationTask@_Task_impl_base@details@Concurrency@@QAEXPAU_ContinuationTaskHandleBase@34@@Z@
.?AV<lambda_1>@?0??_CancelAndRunContinuations@?$_Task_impl@E@details@Concurrency@@UAE_N_N00ABV?$shared_ptr@U_ExceptionHolder@details@Concurrency@@@std@@@Z@
.?AV?$_CancellationTokenCallback@V<lambda_1>@?0??_RegisterCancellation@_Task_impl_base@details@Concurrency@@QAEXV?$weak_ptr@U_Task_impl_base@details@Concurrency@@@std@@@Z@@details@Concurrency@@
.?AV_CancellationTokenRegistration@details@Concurrency@@
.?AV_RefCounter@details@Concurrency@@
.?AU?$_InitialTaskHandle@XV<lambda_1>@?0???$?0V?$_Fake_no_copy_callable_adapter@A6A_NPAD@ZAAY0BAE@D@std@@@?$_Task_async_state@_N@std@@QAE@$$QAV?$_Fake_no_copy_callable_adapter@A6A_NPAD@ZAAY0BAE@D@3@@Z@U_TypeSelectorNoAsync@details@Concurrency@@@?$task@E@Concurrency@@
.?AU?$_PPLTaskHandle@EU?$_InitialTaskHandle@XV<lambda_1>@?0???$?0V?$_Fake_no_copy_callable_adapter@A6A_NPAD@ZAAY0BAE@D@std@@@?$_Task_async_state@_N@std@@QAE@$$QAV?$_Fake_no_copy_callable_adapter@A6A_NPAD@ZAAY0BAE@D@3@@Z@U_TypeSelectorNoAsync@details@Concurrency@@@?$task@E@Concurrency@@U_TaskProcHandle@details@3@@details@Concurrency@@
.?AU_TaskProcHandle@details@Concurrency@@
.?AV?$_Func_impl_no_alloc@V<lambda_1>@?0??_MakeVoidToUnitFunc@details@Concurrency@@YA?AV?$function@$$A6AEXZ@std@@ABV?$function@$$A6AXXZ@6@@Z@E$$V@std@@
.?AV?$_Func_base@E$$V@std@@
.?AV<lambda_1>@?0??_MakeVoidToUnitFunc@details@Concurrency@@YA?AV?$function@$$A6AEXZ@std@@ABV?$function@$$A6AXXZ@5@@Z@
.?AV?$_Func_impl_no_alloc@V<lambda_1>@?0???$?0V?$_Fake_no_copy_callable_adapter@A6A_NPAD@ZAAY0BAE@D@std@@@?$_Task_async_state@_N@std@@QAE@$$QAV?$_Fake_no_copy_callable_adapter@A6A_NPAD@ZAAY0BAE@D@3@@Z@X$$V@std@@
.?AV<lambda_1>@?0???$?0V?$_Fake_no_copy_callable_adapter@A6A_NPAD@ZAAY0BAE@D@std@@@?$_Task_async_state@_N@std@@QAE@$$QAV?$_Fake_no_copy_callable_adapter@A6A_NPAD@ZAAY0BAE@D@2@@Z@
.?AVinvalid_operation@Concurrency@@
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
.?AVfuture_error@std@@
.?AVlogic_error@std@@
.?AVlength_error@std@@
.?AVbad_function_call@std@@
.?AVbad_exception@std@@
.?AVtype_info@@
.?AVstl_condition_variable_interface@details@Concurrency@@
.?AVstl_condition_variable_vista@details@Concurrency@@
.?AVstl_condition_variable_win7@details@Concurrency@@
.?AVstl_critical_section_interface@details@Concurrency@@
.?AVstl_critical_section_vista@details@Concurrency@@
.?AVstl_critical_section_win7@details@Concurrency@@
0"0W4]4
:1D1J1<2B2
3d4o4u459;9
1$2*2q2w2
8Z9e9k99>?>
2n3t3H4N4
9-:3:p:v:Q>\>b>
0f1k1q1
=C>N>T>
<Q=W=k>q>
1x2~2t3
3h4n4^5d5
9[:i:o:r;x;
<i=0>U>
?)?c?i?
2G3U3[3
4$6*6J7P7%8+8,929=:C:
;b<p<v<f=l=Q>W>
041W1>3I3O3
5e8k8:9@9
:):1:7:
=>>\>n>
5"7(7-888>8
839m9x9~9';-;
; <&<y<
<!='=z>
2J3T3Z3P4V4
536>6D6X7^7
6!6w6}6
8#8j8p8
;J<T<Z<D=J=
03191 2+212
4A5L5R51676
;M<X<^<
0A1L1R1L3R3
7w8}809;9A9
=E>K>&?1?7?
Y0_0$1/151
4H5N5e6k6
?.?9???
>0D0.191?1*202
5"5(6.6 7+717
93:>:D:6<<<
=!=p=v=
5Z6d6j6\7b7
= =i=o=
^0i0o0
7j8p8B9V9\9
8c9i9-:8:>:
=!>4>:>
>C?N?T?
0N1Y1_1
<d=o=u=
3.494?41575
7N9Y9_9Q:W:
=!>,>2>
5a6l6r6
4N5Y5_5'6-6
=.>9>?>
1*202y2
9S:^:d:b<h<
1N2Y2_2
748:8-989>9!:':
;j<t<z<}=
=:>D>J>Q?W?
4J5P5N6Y6_6f7l7
>!>n>t>
0]1h1n1Y2_2
3!3&4,4
:M;X;^;A<G<
3`4k4q4-535
8>9I9O9\:b:
102;2A2
5J6T6Z6Z7`7
8)8/8&9,9
8J9T9Z9;:A:
3A4L4R4
4:5D5J5
7j8t8z8p9v9
:):/:^;d;P<[<a<
>1?7?t?z?
N0Y0_0c1i1]2h2n2
8^9i9o9
4*545:5
7=8H8N8
;<-<=<C<
<+=1=o=
2 2^2d2s3~3
7)7/77:=:=;C;
<<=C=I=
>1?7?|?
1`2k2q2K3Q3
9X:^::;D;J;<<B<
=->8>>>
1N2T2=3H3N3E4K4
;O<Y<_<
<H=p={=
=[>f>l>
0.191?1#2.242
5:6D6J6
8.9<9K9Q9
=c>r>x>
:f:q:y:
=0H0N0
5A5G5U6[6
7m8s8?9E9
.090?0
8.999?9
<>=I=O=A>G>
3<4B4w5}5
>h>n>Z?d?j?
7/858$9/959
<\<b<"=(=~>
.090?0U1[1
8$849:9::D:J:J;P;
=k>q>0?;?A?
7M8X8^8V9\9
;s<y<U=`=f=
263A3G3
4P5[5a56%6
7=8H8N8
:A;L;R;
>J?T?Z?
7-838$9*9
Q0\0b0F1L1
0d1o1u1v2|2
3)4/4-535
9$:*:{:
>>s?~?
0P1[1a1
4j5t5z5
6@7K7Q70868
=k>q>$?/?5?
=*>4>:>J?P?
5^7i7o72888
<">->3>
0j1t1z153;3
4,525o5u5*646:6
:0;;;A;S<Y<
1@2K2Q2
5:6D6J6
7c8i8 9+919Z:`:@;K;Q;;<A<
2P4[4a4F5L5
9j:t:z:t;z;A<L<R<9=?=
0f1q1w1
1!1)2\2b2
3^3i3o3
1/252r2x2
;M<X<^<?=E=
>Z?d?j?
l0r0*141:1'2-2
6j6t6z6
0&0o0u0
9::D:J:
8$8r8x8
9!:':z:
=j>t>z>r?x?
$0/050F1L112<2B2Q3W334>4D4
8^9i9o9f:l:P;[;a;F<L<
=I>T>\>
3>5I5O5
809;9A9&:,:
:5<;<:=D=J=D>J>
]0h0n0
:J;T;Z;)</<
2 3&3|3
;m<x<~<K=Q=
0Z1d1j1
2J3T3Z3
5`6f6J7T7Z7D8J8
1^2i2o2e3k3
>">p?v?
^0i0o071=1
6=7C7$8/858#;);
;*<4<:<4=?=E=
J0T0Z0M1S1
2(3a3l3r3
;.<9<?<
5R6b6r6x6
6C7Q7a7g7
7-838{8
9;:j:t:z:U;[; <+<1<D=J=
:;%;i;
<l<r<R=i=
30>0D0Z1`1
<`=k=q=Y>_>
1Z2d2j2`3f3
4"4c5i5A6L6R697?7
0 1&1o1u1
3N4Y4_476=6
:P;[;a;A<G<
P0[0a0r1x1N2Y2_2{3
3]4h4n4a5g5
<N=Y=_=e>
?^?i?o?
4m5x5~5i6o6
:B;H;.<9<?<
99r9x9
>=?H?N?
3^4i4o4
5c6n6t6
*040:091?1
2Z3d3j3[4a4
9N:Y:_:\<b<
2^3i3o3N4~4
5N5Y5_5z6
6 7+717
*040:0
3o4u4 5+515
7 8+818
5)5/556;6
.090?0
6>7I7O7l8r8
:#;);~;
;f<l<@=K=Q=D?J?
5.696?6
8N8Y8_8T9Z9.:9:?:X;^;@<K<Q<<=B=
0.191?1
6@7K7Q7s8y8`9k9q9Y:_:0;;;A;&<,<
>0?;?A?
6j7t7z7
8:9D9J9
3o4u4!585>5
9m:x:~:s;y;*<4<:<
>j?t?z?
4`5k5q5
6^7i7o7^8d8
6*747:7
9^:i:o:^;d;
9*:0:y:
<P=[=a=r>x>0?;?A?
0D0J0
0 1+111H4N4
5>5I5O5Z6`6
>>>I>O>3?9?
2M3X3^374a4g4
4-585>5
#0.0402181
2`3k3q3
7$8*8t8z8
::;D;J;
1g2m2p3{3
4N5Y5_5
3p4v4.595?546:6'72787"9[9a9
;Z<n=y=
=n>t> ?+?1?
1;2A2.393?3
<A=p={=
?P?[?a?
1-232{2
2J3T3Z3"5(5
9/:^:i:o:
;><I<O<
1.292?2\3b3
>'?-?|?
0_1e1j2t2z2]3c3
4Z5d5j5J6P6
6^7i7o7t8z8`9k9q9d:j:
;);/;=<C<
1j2t2z2I3O3
7J8T8Z8
9R:X:;%;y;
H0S0Y0
1`2k2q2
3Z4d4j475=5
00T1Z1`2k2q2F3x3~3
4S4^4d4?5E5
:.;9;?;#<)<
Z0d0j0k1q1
8^9i9o9
<`=k=q=m>
4.595?5
7]8h8n8Z9`9
<>=I=O='?-?
1T1Z1^2i2o273=3
:Z;d;j;j<p<
3N4Y4_4N5T5
7>8I8O8>9D9
<:=D=J=
<!<C=I=
0Z1d1j1b2h2.393?3.444
8Y8_8-989>9(:.:
=:>D>J>
1Z2d2j2B3H3
5@7K7Q7+868<8
;P<[<a<
J0T0Z0.141
>T>Z>n?t?
354;4@5K5Q5|6
6P7[7a7I8O8
<q=w=C>N>T>A?G?
3$3w3}3
8#9)9|9
<$<*<~>
8)8/8!9'9
;I<S<a<k<y<
=(=F=a=h=
>>&>1>7>>>H>Q>Y>c>i>o>u>
?3?E?^?s?z?
060I0|0
2(2C2V2j2x2
3@3N3m3u3
4>4W4r4
445A5N5_5
6"6D6_6p6}6
:::M:X:e:l:
;.<\<z<
==9=Y=|=
?5?R?m?{?
0&060F0O0a0j0u0|0
1V2`2i2
3#3_3i3r3{3
4-4A4^4
5Q5Y5i5{5
5O7U7\7c7h7n7t7y7
8#8)8/848:8@8E8K8Q8V8\8b8g8m8s8x8~8
9"9(9.93999?9D9J9P9U9[9a9f9l9r9w9}9
:':6:@:V:d:r:
=2>;>U>d>m>z>
?.?3?F?
N0)2:2v2
7G7O7a7n7
7$878U8c8
:H:O:T:X:\:`:
>7?L?W?_?j?p?{?
0 000D0X0_0y0
161C1Q1_1j1s1y1
5'6.6K6O6S6W6[6
/050I0X0f0t0
1%121A1
2(2@2E2Q2V2j2
2)3F3O3j3
4:4S4X4a4C5R5[5i5
66(8n8
91:<:{:
:W;e;r;
0J0c0m0y0
151C1J1P1k1r1
3(3U3p3{3
5%53595T5|5
8'868A8F8K8i8x8
9?9\9a9f9
:*:K:X:m:v:
;;$;4;9;>;O;V;`;i;s;
<)<<<V<j<
=+=Y=h=z=
2!333c3
4"4&4,40464:4D4W4
7 7*7:7
:U:\:c:j:|:
< =>=C=H=M=}=
1E2_2d2
3*303424k4
5%5F5M5d5z5
5;6A6a6
8:9D9g9q9
9Q<q<T=
9919C9U9v9
8,8D8w8
5+6A6|6
82898A8J8
;(;-;2;M;W;c;h;m;
<$<:<b<v<
1N1c1m1#2I2
565H5R5l5{5
91:W:~:
1(2/262Y2
7;7F7V7
7D8J8b8
0=1W1d1
2W3l3u3~3
<&=?/?O?U?a?
0!0)01090W0_0
8,8=8E8U8f8
8!909<9K9^9}9
:':R:t:
::+:7:A:
4080<0L0P0`0d0h0l0
1,1014181<1L1P1`1d1h1l1p1t1x1
2 282H2L2`2d2h2l2p2t2x2
3 3$3(303H3P3h3x3|3
4(4,4@4D4H4L4P4T4X4l4p4
5(505H5X5\5`5d5p5
6,606@6D6H6L6`6x6
7$7(7,7<7@7P7T7X7`7x7
8(808H8X8\8p8t8x8|8
9 9$9(9,9094989L9P9`9d9h9p9
: :0:4:8:<:P:h:p:
;,;0;4;8;<;L;P;`;d;h;l;
<,<0<4<8<<<L<P<`<d<h<l<p<t<x<
= =$=(=<=@=P=T=X=`=x=|=
1$1,141<1D1L1T1\1d1l1t1|1
2$2,242<2D2L2T2\2d2l2t2|2
3 3$3(3,3034383<3@3D3H3L3P3T3X3\3`3d3h3l3p3t3x3|3
4h5p5x5
8 8(80888@8H8P8X8`8h8p8x8
9 9(90989@9H9P9X9`9h9p9x9
: :(:0:8:@:H:P:X:`:h:p:x:
; ;$;(;,;0;4;8;<;@;D;H;L;P;T;X;\;`;d;h;l;p;t;
< <$<(<,<0<4<8<<<@<D<H<L<P<T<X<\<`<d<h<l<p<t<x<
= =$=(=,=0=
5$5,545<5D5L5T5\5d5l5t5|5
6$6,646<6D6L6T6\6d6l6t6|6
7$7,747<7D7L7T7\7d7l7t7|7
8$8,848<8D8L8T8\8d8l8t8|8
9$9,949<9D9L9T9\9d9l9t9|9
:$:,:4:<:D:L:T:\:d:l:t:|:
;$;,;4;<;D;L;T;\;d;l;t;|;
<$<,<4<8<@<H<P<X<`<h<p<x<
= =(=0=8=@=H=P=X=`=h=p=x=
> >(>0>8>@>H>P>X>`>h>p>x>
? ?(?0?8?@?H?P?X?`?h?p?x?
0 0(00080@0H0P0X0`0h0p0x0
1 1(10181@1H1P1X1`1h1p1x1
2 2(20282@2H2P2X2`2h2p2x2
3 3(30383@3H3P3
8$8,848<8D8L8T8\8d8l8t8|8
9$94989H9L9P9X9p9
: :0:4:8:<:D:\:l:p:
;(;8;<;L;P;T;\;t;
< <(<@<
; ;$;(;,;8;<;@;D;H;L;P;T;h;l;p;
T7h7t7
8(84888<8@8H8P8X8\8d8l8t8
9 9(9,90989L9T9h9p9|9
: :(:0:4:<:P:X:`:h:l:t:
; ;@;H;T;
;0<P<X<`<l<
=(=4=<=d=h=
>(>H>h>
?(?H?h?
8 808`8
=P> ?p?
< <0<@<X<d<h<l<
,*z?4{N
R_q|?\Lh
*Pww3
`&V[ze
lA9$&7
}'am.S
Z<$m3}
^o*3HN|_
0f@'?44
}9!_AD
*H.x/@
1ou>:Y
h@y[,Y
^/|tUt
gH1qb*
r1R`X0
j'7qtr
wxmdo+
J-aTV0=
}[9oI
K6://T
])kj(z
K.g|1@a@
5OHm9f
la[N>=9
{Ip}"-"
V;C,?R
}#R~'s
;yh65,J
85jzHP
|SSaR6
Y`?gkY
|v{v=1z
QHU@Xu
({eY8>
iWeahl
^@3%sG
]YK@Gn
7r&c@,
l/=VpO
n@PnhhF
a{kvr(
d IR,FhoA~
wb:-s2
`+zfN3
sr2eHw
"+7SWY
3xZU_cy
6wpMq}
7k Pu.N
6I'`E$
^fN{5"
PI,--3
=:Y}q
Ez"}&j
D]p<Vl
UlOjf`
S[*@l"
RGR8E5T
]f0s{m
Y!Wy@]
h$KoxjxW
]0gX6*
n]-w7?
%GvV0S-
asaAc{~
i%.]g|(<
P%'L C
a^26.y
*P""3[
g=iq1^
e3.gUa
Mk5RcJE(
_<gDnfNij*/\I
2{jia?
m!s}:T
4.vRcc^p
]]NGR/
+M.G!h$(10
&PZ:Bk0
,\wvIB&7P3
jS"]NjZJ
f!U>7^
no7.~w
tj>3k7
^nlyhG
HQ}pfMl
GO_ky7%
Gk/0Ci
/|}Dl$.R
6>R$;1
)5[v$W]
4uqg]^=\O6
J6r|:+%z
n,'oMz
0meWww}
#U6Vd^
hWc7XKL*js
e2{GgrA
(0WlXe2
Q~1eN_
|]Idq(
|yF=*e
`ft8Trl
5DTCTB
-e &3o
J6"hR^
eo6O|He
rUAuwo
BY_(fE
oOn}#\PXeA
RhkwH_i
1\$c`s
rJ%75b
[U\0?@
gEO*RTz
89VgzD
UmtJ9f
+-G rp6
u<,Wv/
xZ]6yu
bu'ndN
,*IHzxu
D=FqzUA
B,Imtm
!#KLb@
[XJWuX
yO~y./
uI0LUH;
f> -IR
z1=lQ}
c[B%|s
_?n6#@
3s.0~{
2_VOxv
H?P"vP*
>le-r\
6mIqw1;
q--XCj
d|A}2~:
{c#kNc5
:;n5M=
bNZwGr
z'\/Y}
M`RJ=^
+s)U6~)
m.8/^Y
U!tKj-T
bStE$f
lH" mR(-!
kR54mTX
iQ"nwXDc
H/:RtI
Wo#@1(
c.@iB@q~|m
=!9tG^S
:lz1y&
X)l2FlEe
n|kb 7
n`\%9Z
9a/jYO
y*SH*ua
(YQv*
\kf"?4
c7LiWAv
PF/_:G
woM25O
1f]\!y\
m\S4|CY
z!1{u
%nwJF+=0
VY8OR.<
s fg$s
q1E9(8
SZwt EKEJ
n>:]ju
zW2.Hk+
3~^`=]
4rO ~n
orI\F)
3]\$q_.
[D5FIV
8w/}O*c
Z_Kr3k~
J&3SNmHa!
AVxq&-t
zF]!1
_"r~$D
:a%j-5P
K},DsD
O[0GRD[
6r#`)^591
z7LU+u
I0UvEQNKp!
N#Pa(T
Z$XXO04"&w
mXWU?./>f
jqoCwJ
Ynr&?[
A.n7(h
Ze%sh
u{pOTN
*(pLcF
@giF@]
(VImL}a
*D8}r@!*7b
9)2Bi!F
.8=@zdk
et!LM5
`rPf';
la(gP0
1Dr)tIk
5*n+)z
9<A \%G
,`#u{Y!
mGpXvKp
w 7xRvMc
!eM46!
"}X .]R
\cuOc/
6XwC;z
>MT884(smi*
~DF-<*2
jVovJ*5
.i5;lN
<QS.+y
/P}!6"
@rZqB_
ZC?fMY_E*F
:;c}${
NjG$fR7
pck*<r
~v)MXT
Bf&6&6
!xt_f5{
KHK1aF#
8@o~7B
:'r'\~
7'?F7y
;"%_}w
@>H_|q%[k
v8xzE'
Kt^TTkf9>R
fj{d9
U"Ou-xj
f3yBdm
oiwf11
LX=s{L
3gf<,~
'{SD'S
l2*7WHk!
P7&2n/
98A+:u}T{
|m`"#B
zx;`[<
.P.)e4
:`S9DW
xmi\SX
w?Q8w+7
b>FOWA
Ytgoh*q
,Fl=z
FAhJ;?
Vz"1Zuo
YhiY@x:R+
=?Wh*
tp&:=_
%%2<QX
S7cl|@
J[+}+:
5N< DDn
jBR49)"
R\Y>MwFX
kU~QW6
=/H#6~
Xk7NH$
qkY[Iyuc~
<9h"Y5
R+?F.e
gBw/=pY
3~0p98
ln+E-3
WTq0x~X
Z9/"iE
>yoMD/5
o)7gZY
{&(=k@
H w?z\6
A8j1#_$
~ jT~!
a'@sLv
EU|7hR6
PJv&z|
*ekKG!/9
QAW4^/
&*3UT
b26qhC
.A^-ny
zou?}
`FY4?o3m
s\yFn
x)zCrD
d$Mb#X
(Eq1cD
Dz##1o
H)mMoh
+X^FRyc
BWc^4
Mj0qtQaT
A.&;Py
,jYTFK
L<r9v9
7BkgV+
}3(4EPBaz
D\dM31^<
de\_si
<oX5$8VC
RRQAP J
COd"|q
Js=Tdr
?No(Up
8aCvja
0TK=ql
K*5TUa4
I[d*i"u
1zF}'l
2VRz<6s
b!q]1?
X4XSU^-
f#KA?_Rw
`7)?&0
/b^2w&
?/`{iO
lA7[;+E9
%sAP}y
r0t'Vb
;\>S\O
w5_m}^
^zJP=
EPWGf-X
0yX+Ku*
-Nhr+n
WY&`vA7
q6/NE)
IC8wJzZ
mVjb}Jr
r,i`S1
Hdd 69
1KWhQz
y)VVh7
$GW\j1E
(^o4/jD:
\ =<Xo0
M~'!%na
p0Q~?
QH>#6s
Bur6oE|
n>WT&C
(\Jhf+
FIE[m3
Ug^-z,
sJ ?-
<&`dc
3uc:Cy4Fz
;cgt"\
[s|kUc
]\5>K~
=-G$cs
},qmg8
ii:A/i<
[#c]pk
d2U=8O6
Zowbg&Z
Hb<Wkm
SJ%70Qx
aKAPl17
gGYBMV
&z%m#V
|oxPke{+
A&tO&N
Af7Uts
\;T#2=
lX:U]y
aX/4)6
dgvt"";
BNLYBH
+F^c;T
O-ye-C
V_i8z\
47w7qJ
tquY^=^
P#g)`u
%h^XUe
-pNq<T
Nb^]_I
0Uk`h=
c@iU$$
QMXP7r6$e6F
|L*FZ\
w[eh]|F
d}O([C
GN|[42
P2riZE;
ovTOE:
CJ""67R
=9Y9\\GU
N-2Tk>WF9E
G/S)a6
&9t%ly
g8q'}p
,:bkx#
cDCoOH
]rJG7;
fhq}_P
k@+X>Qs
6{`Jv|
$Amp3L
ay*c"v4
bPYgpz!
"1l'A>
%ncLQ>$4
Q(*N_2?
*oSmSfoW
XP2d?/
f+d!U=
iKgoV2
a<)&YTl
7|ti"[
7tjM4cy
qRrN}d
r<vzR
U^8FaQ6
t'kzc_rf
T~ZYg{8
_mE*B;<
&_8Y75
*NVG8%
fx=e^
ni$81}
1]6IBD
nlWO4M
pPr>(a
uw'!^?
"Ps7T/
n>`lXi%
llgiQ*
w+2DFW
'S<'MV
N3O!b
wA8Y*o
i9B(_R
1,d[1]MX
^* dcM
_sVE#A
kd!X$
#w:X,:
BB7-V.a&m
^LK%([
zuW5`YW
4;c[56D
(Su`V-
,<Kj9E
an=jf!
pruxs0
:aXEyeKn
F>D%]1
T#E,=s<
J36Rp9ERT
t;>Cex
2h!V}6
Tn3wY/
oN{%Jw
Ia_ab
z^u3OG
'F+:"'b
=GS`>eR&
'TsFa=\
($Z/CC
|p*6sX
P-O[%O<{iIx
HoQpyP=
L<.:om
l*kSA3
=%c<b1
LGYae%
(W]B*7*
S9n#q
~Ip5>4
Jbe"Gf
aiT_O4
C_zn
*f(z*]
D7axF;:
WiUGC5k
MjeH[F^
,4AAe
J,*MSJ
AsYj6G
/]Eh#?F
A>g_Xii
j0Kq|4A
n|hH'J
#0k{rk
8>A91F
_2JL_e
x4%B6ZB
_ci|ODDE
D4WD7Z
RRkpL\L-
q%<Spf
8{@`vu7Q
+p|A,P
3)dF2M
A^@g$p\
m\r~AK
3B.>9M
H)$K`w
D+rb R
8HMi/(
\M5L(Nt
uN67{X
H/Yx
Wd6llw-o
5Rs8,29
0>9>=0
D7,iXYP2x
e~Y.U(
Lmd^@}
]K3Y<Q
vX"b{V
Jj*A%8
Sample Window Class
((((( H
Window
Hello!
dddd, MMMM dd, yyyy
MM/dd/yy
syr-sy
February
January
Thursday
Tuesday
Wednesday
Saturday
Sunday
Monday
Friday
div-mv
August
zh-cht
HH:mm:ss
zh-chs
October
November
September
December
smj-no
sma-no
quz-bo
uz-uz-latn
az-az-latn
sr-sp-latn
bs-ba-latn
sr-ba-latn
uz-UZ-Latn
az-AZ-Latn
sr-SP-Latn
bs-BA-Latn
sr-BA-Latn
kok-in
uz-uz-cyrl
az-az-cyrl
sr-sp-cyrl
sr-ba-cyrl
uz-UZ-Cyrl
az-AZ-Cyrl
sr-SP-Cyrl
sr-BA-Cyrl
mscoree.dll
kernel32.dll
sms-fi
smn-fi
kernelbase
smj-se
sma-se
quz-pe
quz-ec
syr-SY
div-MV
zh-CHT
zh-CHS
smj-NO
sma-NO
quz-BO
kok-IN
sms-FI
smn-FI
smj-SE
sma-SE
quz-PE
quz-EC
api-ms-win-core-file-l1-2-4
user32
kernel32
advapi32
api-ms-win-core-file-l1-2-2
api-ms-win-core-sysinfo-l1-2-1
api-ms-win-core-fibers-l1-1-1
api-ms-win-core-synch-l1-2-0
api-ms-win-core-xstate-l2-1-0
api-ms-win-core-winrt-l1-1-0
api-ms-win-core-fibers-l1-1-0
api-ms-win-core-string-l1-1-0
ext-ms-
api-ms-
(null)
CONOUT$
api-ms-win-core-synch-l1-2-0.dll
api-ms-win-core-processthreads-l1-1-2
api-ms-win-appmodel-runtime-l1-1-2
api-ms-win-core-localization-l1-2-1
api-ms-win-core-datetime-l1-1-1
api-ms-win-core-localization-obsolete-l1-2-0
ext-ms-win-ntuser-dialogbox-l1-1-0
api-ms-win-rtcore-ntuser-window-l1-1-0
api-ms-win-security-systemfunctions-l1-1-0
ext-ms-win-ntuser-windowstation-l1-1-0
Antivirus Signature
Bkav W32.AIDetectMalware
Lionic Clean
Elastic malicious (high confidence)
ClamAV Clean
CMC Clean
CAT-QuickHeal Clean
Skyhigh Clean
ALYac Clean
Cylance Unsafe
Zillya Clean
Sangfor Trojan.Win32.Save.a
CrowdStrike win/malicious_confidence_100% (W)
Alibaba Clean
K7GW Clean
K7AntiVirus Clean
huorong Clean
Baidu Clean
VirIT Clean
Paloalto Clean
Symantec ML.Attribute.HighConfidence
tehtris Clean
ESET-NOD32 a variant of Win32/GenKryptik.HDSK
APEX Malicious
Avast FileRepMalware [Trj]
Cynet Malicious (score: 100)
Kaspersky VHO:Trojan-PSW.Win32.Stealerc.gen
BitDefender Clean
NANO-Antivirus Clean
ViRobot Clean
MicroWorld-eScan Clean
Tencent Win32.Trojan.Genkryptik.Yylw
Sophos ML/PE-A
F-Secure Clean
DrWeb Clean
VIPRE Clean
TrendMicro Clean
McAfeeD ti!C4A5FDD60676
Trapmine malicious.high.ml.score
CTX Clean
Emsisoft Clean
Ikarus Clean
FireEye Generic.mg.a55d149ef6d095d1
Jiangmin Clean
Webroot Clean
Varist Clean
Avira Clean
Fortinet Clean
Antiy-AVL GrayWare/Win32.Kryptik.gpyt
Kingsoft malware.kb.a.924
Gridinsoft Clean
Xcitium Clean
Arcabit Clean
SUPERAntiSpyware Clean
Microsoft Trojan:Win32/Wacatac.B!ml
Google Clean
AhnLab-V3 Clean
Acronis Clean
McAfee Clean
TACHYON Clean
VBA32 BScope.TrojanSpy.Stealer
Malwarebytes Clean
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Rising Clean
Yandex Clean
SentinelOne Static AI - Malicious PE
MaxSecure Trojan.Malware.300983.susgen
GData Clean
AVG FileRepMalware [Trj]
DeepInstinct MALICIOUS
alibabacloud Clean
No IRMA results available.