Static | ZeroBOX

PE Compile Time

2025-01-22 03:46:28

PDB Path

G:\目录\2025工作站\主控工程\主控修复上线包\shellcode\注入自身进程\Release\注入自身进程.pdb

PE Imphash

c67ef5a5a21b6fceb58b3ff6fde243b5

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x0004a8c6 0x0004aa00 6.62798710484
.rdata 0x0004c000 0x00009600 0x00009600 5.07375700356
.data 0x00056000 0x00001cb0 0x00000a00 2.62474965551
.rsrc 0x00058000 0x000b4754 0x000b4800 7.06178337202
.reloc 0x0010d000 0x00002410 0x00002600 6.53808725549

Resources

Name Offset Size Language Sub-language File type
RT_CURSOR 0x00058388 0x00000134 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_BITMAP 0x000584bc 0x00000328 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x0009ec4c 0x000010a8 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_ICON 0x0009ec4c 0x000010a8 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_ICON 0x0009ec4c 0x000010a8 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_ICON 0x0009ec4c 0x000010a8 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_ICON 0x0009ec4c 0x000010a8 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_ICON 0x0009ec4c 0x000010a8 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_STRING 0x0009fcf4 0x000000d8 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_RCDATA 0x0009fdcc 0x00000080 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_GROUP_CURSOR 0x0009fe4c 0x00000014 LANG_NEUTRAL SUBLANG_NEUTRAL Lotus unknown worksheet or configuration, revision 0x1
RT_GROUP_ICON 0x0009fe60 0x00000014 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_MANIFEST 0x0009fe74 0x0000017d LANG_ENGLISH SUBLANG_ENGLISH_US XML 1.0 document text
None 0x0009fff4 0x0006c760 LANG_NEUTRAL SUBLANG_NEUTRAL Dyalog APL version 142.86

Imports

Library KERNEL32.dll:
0x44c018 CreateThread
0x44c01c GetVersionExA
0x44c020 VirtualAlloc
0x44c024 GetModuleFileNameA
0x44c028 ExitProcess
0x44c02c Process32FirstW
0x44c030 Process32NextW
0x44c034 WriteConsoleW
0x44c038 CreateFileW
0x44c03c ReadConsoleW
0x44c040 GetCurrentProcess
0x44c044 CloseHandle
0x44c048 ReadFile
0x44c04c GetFileSize
0x44c054 CreateFileA
0x44c058 SetFilePointerEx
0x44c05c GetFileSizeEx
0x44c060 GetConsoleMode
0x44c06c TerminateProcess
0x44c078 GetCurrentProcessId
0x44c07c GetCurrentThreadId
0x44c084 InitializeSListHead
0x44c088 IsDebuggerPresent
0x44c08c GetStartupInfoW
0x44c090 GetModuleHandleW
0x44c09c RaiseException
0x44c0a0 RtlUnwind
0x44c0a4 GetLastError
0x44c0a8 SetLastError
0x44c0bc TlsAlloc
0x44c0c0 TlsGetValue
0x44c0c4 TlsSetValue
0x44c0c8 TlsFree
0x44c0cc FreeLibrary
0x44c0d0 GetProcAddress
0x44c0d4 LoadLibraryExW
0x44c0d8 EncodePointer
0x44c0dc GetStdHandle
0x44c0e0 WriteFile
0x44c0e4 GetModuleFileNameW
0x44c0e8 GetModuleHandleExW
0x44c0ec GetCommandLineA
0x44c0f0 GetCommandLineW
0x44c0f4 HeapFree
0x44c0f8 HeapAlloc
0x44c0fc GetCurrentThread
0x44c100 GetDateFormatW
0x44c104 GetTimeFormatW
0x44c108 CompareStringW
0x44c10c LCMapStringW
0x44c110 GetLocaleInfoW
0x44c114 IsValidLocale
0x44c118 GetUserDefaultLCID
0x44c11c EnumSystemLocalesW
0x44c120 MultiByteToWideChar
0x44c128 OutputDebugStringW
0x44c12c FindClose
0x44c130 FindFirstFileExW
0x44c134 FindNextFileW
0x44c138 IsValidCodePage
0x44c13c GetACP
0x44c140 GetOEMCP
0x44c144 GetCPInfo
0x44c148 WideCharToMultiByte
0x44c158 SetStdHandle
0x44c15c GetFileType
0x44c160 GetStringTypeW
0x44c164 GetProcessHeap
0x44c16c HeapSize
0x44c170 HeapReAlloc
0x44c174 FlushFileBuffers
0x44c178 GetConsoleOutputCP
0x44c17c DecodePointer
Library USER32.dll:
0x44c190 MessageBoxA
Library ADVAPI32.dll:
0x44c000 RegQueryValueExA
0x44c004 RegOpenKeyExA
0x44c008 RegCloseKey
0x44c00c InitializeAcl
0x44c010 SetSecurityInfo
Library SHELL32.dll:
0x44c184 ShellExecuteExA
0x44c188 None

!This program cannot be run in DOS mode.
`.rdata
@.data
@.reloc
u"h(mE
URPQQh0:@
V<0|M<9
<0|$<9
UQPXY]Y[
QQSVWd
j<h(CE
j"^f92
j"_f9z
SWt@jU
_tqPVj@
VSSSSS
VPPPPP
VPPPPP
j0Z9~4t
j0Z9~4t
j0Z9~4t
j0Z9~4t
j0Z9~4t
j0Z9~4t
j0Z9~4t
j0Z9~4t
j0Z9~4t
j0Z9~4t
j0Z9~4t
j0Z9~4t
t#9^$}
t#9^$}
uj*Xf;
<j*Xf;
uj*Xf;
<j*Xf;
uj*Xf;
<j*Xf;
t#9^$}
uj*Xf;
<j*Xf;
<ItC<Lt3<Tt#<h
A<lt'<tt
<ItC<Lt3<Tt#<h
A<lt'<tt
<ItC<Lt3<Tt#<h
A<lt'<tt
<ItC<Lt3<Tt#<h
A<lt'<tt
<ItC<Lt3<Tt#<h
A<lt'<tt
<ItC<Lt3<Tt#<h
A<lt'<tt
Tt)jhZf;
JjlZf;
Tt)jhZf;
JjlZf;
Tt)jhZf;
JjlZf;
Tt)jhZf;
JjlZf;
Tt)jhZf;
JjlZf;
Tt)jhZf;
JjlZf;
F +F4+
8^8tb9^4~]
F +F4+
8^8tb9^4~]
F +F4+
8^8tb9^4~]
V +V4+
tb9^4~]
V +V4+
tb9^4~]
V +V4+
tb9^4~]
V.jx_f;
~ +~4+
V.jx_f;
~ +~4+
V.jx_f;
~ +~4+
V.jx_f;
~ +~4+
V.jx_f;
~ +~4+
V.jx_f;
~ +~4+
F.jgYf;
jg[BjG_
F.jgYf;
F.jgYf;
F.jgYf;
jg[BjG_
F.jgYf;
F.jgYf;
PRRRRR
PRRRRR
PRRRRR
ul<0|[<9
ul<0|[<9
x!j$Xf9
x!j$Xf9
_PVVVVV
j"_SVVVV
PVVVVV
^PSSSSS
j"^WSSSS
WVVVVV
PVSRSQV
t^j*Yf
uSSSSj
f9:t!V
QQSVj8j@
xi;5 |E
xg;5 |E
ARPRQh
jYjf
NX9^`t1
;V\uYW
u2Vj@hh
9C`u99C\t4
u29K\t-
35<|E
j,h@JE
F95`mE
M,j"^QRRRRR
Vj0XPW
r!SSPVQ
dr#SSjdVQ
M$j"^QRRRRR
j"[VWWWW
u#VhX|E
PVVVVV
PVVVVV
PVVVVV
PSSSSS
PPPPPPPP
PPPPPVW
PP9E u!PPSVP
xE;5 |E
^PQQQQQ
E ^PQQQQ
7;1u"3
CY<u
uTh0)E
D8(Ht'
D8(Ht5F
L:-^_[
xK;5 |E
tNSVWP
C:\ProgramData\Microsoft\Program\ziliao.jpg
Microsoft
SOFTWARE\Microsoft\Windows\CurrentVersion\Run
C:\ProgramData\Microsoft\EdgeUpdate\Log\chuangkou.log
Unknown exception
bad allocation
bad array new length
__based(
__cdecl
__pascal
__stdcall
__thiscall
__fastcall
__vectorcall
__clrcall
__eabi
__swift_1
__swift_2
__swift_3
__ptr64
__restrict
__unaligned
restrict(
delete
operator
`vftable'
`vbtable'
`vcall'
`typeof'
`local static guard'
`string'
`vbase destructor'
`vector deleting destructor'
`default constructor closure'
`scalar deleting destructor'
`vector constructor iterator'
`vector destructor iterator'
`vector vbase constructor iterator'
`virtual displacement map'
`eh vector constructor iterator'
`eh vector destructor iterator'
`eh vector vbase constructor iterator'
`copy constructor closure'
`udt returning'
`local vftable'
`local vftable constructor closure'
new[]
delete[]
`omni callsig'
`placement delete closure'
`placement delete[] closure'
`managed vector constructor iterator'
`managed vector destructor iterator'
`eh vector copy constructor iterator'
`eh vector vbase copy constructor iterator'
`dynamic initializer for '
`dynamic atexit destructor for '
`vector copy constructor iterator'
`vector vbase copy constructor iterator'
`managed vector copy constructor iterator'
`local static thread guard'
operator ""
operator co_await
operator<=>
Type Descriptor'
Base Class Descriptor at (
Base Class Array'
Class Hierarchy Descriptor'
Complete Object Locator'
`anonymous namespace'
template-parameter-
`template-parameter-
generic-type-
`generic-type-
`non-type-template-parameter
`template-type-parameter-
`generic-class-parameter-
`generic-method-parameter-
nullptr
lambda
`template-parameter
`vtordispex{
`vtordisp{
`adjustor{
`local static destructor helper'
`template static data member constructor helper'
`template static data member destructor helper'
static
virtual
private:
protected:
public:
[thunk]:
extern "C"
short
unsigned
volatile
volatile
std::nullptr_t
std::nullptr_t
<ellipsis>
,<ellipsis>
noexcept
double
__int8
__int16
__int32
__int64
__int128
<unknown>
char8_t
char16_t
char32_t
wchar_t
decltype(auto)
__w64
UNKNOWN
signed
volatile
`unknown ecsu'
union
struct
class
coclass
cointerface
const
cli::array<
cli::pin_ptr<
{flat}
FlsAlloc
FlsFree
FlsGetValue
FlsSetValue
InitializeCriticalSectionEx
bad exception
CorExitProcess
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
(null)
AreFileApisANSI
CompareStringEx
EnumSystemLocalesEx
GetActiveWindow
GetDateFormatEx
GetEnabledXStateFeatures
GetLastActivePopup
GetLocaleInfoEx
GetProcessWindowStation
GetSystemTimePreciseAsFileTime
GetTimeFormatEx
GetUserDefaultLocaleName
GetUserObjectInformationW
GetXStateFeaturesMask
IsValidLocaleName
LCMapStringEx
LCIDToLocaleName
LocaleNameToLCID
LocateXStateFeature
MessageBoxA
MessageBoxW
RoInitialize
RoUninitialize
AppPolicyGetProcessTerminationMethod
AppPolicyGetThreadInitializationType
AppPolicyGetShowDeveloperDiagnostic
AppPolicyGetWindowingModel
SetThreadStackGuarantee
SystemFunction036
Sunday
Monday
Tuesday
Wednesday
Thursday
Friday
Saturday
January
February
August
September
October
November
December
MM/dd/yy
dddd, MMMM dd, yyyy
HH:mm:ss
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
NAN(SNAN)
nan(snan)
NAN(IND)
nan(ind)
[aOni*{
~ $s%r
@b;zO]
v2!L.2
1#QNAN
1#SNAN
?5Wg4p
%S#[k=
"B <1=
_hypot
_nextafter
RSDSl(
\shellcode\
\Release\
.text$mn
.text$x
.idata$5
.00cfg
.CRT$XCA
.CRT$XCAA
.CRT$XCZ
.CRT$XIA
.CRT$XIAA
.CRT$XIAC
.CRT$XIC
.CRT$XIZ
.CRT$XPA
.CRT$XPX
.CRT$XPXA
.CRT$XPZ
.CRT$XTA
.CRT$XTZ
.rdata
.rdata$CastGuardVftablesA
.rdata$CastGuardVftablesC
.rdata$r
.rdata$sxdata
.rdata$voltmd
.rdata$zzzdbg
.rtc$IAA
.rtc$IZZ
.rtc$TAA
.rtc$TZZ
.xdata$x
.idata$2
.idata$3
.idata$4
.idata$6
.data$r
.data$rs
.rsrc$01
.rsrc$02
CreateFileA
GetFileSize
ReadFile
CloseHandle
GetCurrentProcess
ExitProcess
CreateThread
GetVersionExA
VirtualAlloc
GetModuleFileNameA
CreateToolhelp32Snapshot
Process32FirstW
Process32NextW
KERNEL32.dll
MessageBoxA
USER32.dll
InitializeAcl
RegCloseKey
RegOpenKeyExA
RegQueryValueExA
SetSecurityInfo
ADVAPI32.dll
ShellExecuteExA
SHELL32.dll
UnhandledExceptionFilter
SetUnhandledExceptionFilter
TerminateProcess
IsProcessorFeaturePresent
QueryPerformanceCounter
GetCurrentProcessId
GetCurrentThreadId
GetSystemTimeAsFileTime
InitializeSListHead
IsDebuggerPresent
GetStartupInfoW
GetModuleHandleW
InterlockedPushEntrySList
InterlockedFlushSList
RaiseException
RtlUnwind
GetLastError
SetLastError
EnterCriticalSection
LeaveCriticalSection
DeleteCriticalSection
InitializeCriticalSectionAndSpinCount
TlsAlloc
TlsGetValue
TlsSetValue
TlsFree
FreeLibrary
GetProcAddress
LoadLibraryExW
EncodePointer
GetStdHandle
WriteFile
GetModuleFileNameW
GetModuleHandleExW
GetCommandLineA
GetCommandLineW
HeapFree
HeapAlloc
GetCurrentThread
GetDateFormatW
GetTimeFormatW
CompareStringW
LCMapStringW
GetLocaleInfoW
IsValidLocale
GetUserDefaultLCID
EnumSystemLocalesW
MultiByteToWideChar
GetFileAttributesExW
OutputDebugStringW
FindClose
FindFirstFileExW
FindNextFileW
IsValidCodePage
GetACP
GetOEMCP
GetCPInfo
WideCharToMultiByte
GetEnvironmentStringsW
FreeEnvironmentStringsW
SetEnvironmentVariableW
SetStdHandle
GetFileType
GetStringTypeW
GetProcessHeap
SetConsoleCtrlHandler
HeapSize
HeapReAlloc
FlushFileBuffers
GetConsoleOutputCP
GetConsoleMode
GetFileSizeEx
SetFilePointerEx
ReadConsoleW
CreateFileW
WriteConsoleW
DecodePointer
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
.?AVbad_alloc@std@@
.?AVexception@std@@
.?AVbad_array_new_length@std@@
.?AVbad_exception@std@@
.?AVtype_info@@
.?AVDNameNode@@
.?AVcharNode@@
.?AVpcharNode@@
.?AVpDNameNode@@
.?AVDNameStatusNode@@
.?AVpairNode@@
~~~S
_kzpm
&ct*!lt
*iwkt
%R[51kq
nV5+jD
<?xml version='1.0' encoding='UTF-8' standalone='yes'?>
<assembly xmlns='urn:schemas-microsoft-com:asm.v1' manifestVersion='1.0'>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v3">
<security>
<requestedPrivileges>
<requestedExecutionLevel level='asInvoker' uiAccess='false' />
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
kPJf1o
U ]PqO
=*v{o#
C$g&"o
aoU&v+8w
Co8}{%m#+
yhY3+"
cg<#q"a
N)%1Qh|y
ocb9C|
iS1^)LV
C7,@Ke
IWFb-"
Io;6+Ve7F
.]{sYJL
UlOkP,
+sO^gy
9xN2?0Y8
h$=_Ny
)2B'v=
Cu73h-r
JvS^gR!
~[8'q_q
e:?)[6
6Fp-a%
C-5rtq
4qdhNR
#<: +<V
Q=i,xH
Nq?(R7
d hWqZx2
!EWs=<
4`M\wFX=
F^ru{G
\w'#aS
r4MV|lX
xOV+&1
RSfYFc
8_LqAY
]45f__
i-wC&g
FuR.;IN=
7p%E^i
v@E+.4
3IKP*-
K10NAy
v*hpXL$
F,X =
Vww8Gg
Sc}GWsEI
Xo-ztd@
H]iYzK,
M\E/Sl_
?v3K]I
aNli3b
s*{?R
Pi5'%9
e#FHE5
r!*wg+
- 4H@R
Os\fX
FxRAjw
4,mL}v
E#(G.l
|cDOw6<
Rqbcg6
r_$OAr
U%gQW\
rb"7`\
z-c.Zp
P/=G#%3
[B1Mso
6!qAoi.
2_6KR=
0?Q=Qu
Bl5<3C
FA=4M.]
}zvTC|
r7+.@!
.hiPc4
,Bx=:"
.n-&DT
E4Ow{{
+hZ]K
W(o-((
;z^_gG$
af><gy
AHI6hTsH
ZSaJ)oO
UsjcusM
IHv.fh
9"Id0P]
%<n0vQ
V?Ip;(_
BXb-%G
\}8^YL
L&p}a'
&Fk?nQ
"(f~db
/2Ii(@
gdJNI(bd
61Zt'tz
u:k7E)
C/Nj?-1
q$D1*9-
QvXIZ
}G89)}
hc)h[W
$sLG"[aVZ\
M}Nz_
X7=$}8;
5F 9P6
|Dg*3L
CxybofU
0}>#Aoj
M@{0&
P)|U;'l
UNJCu8
Xrh}'\K
J&d0[L
3p~*q5T(e
#h`WI+
<tOth]
xN BGWcB
hT^5+@
hV!K{n
K`@Owd)
lpxl^D
wd%4V3D
M60q\B*
S_!l\?B@
l\jo[s
D00AR.
\)^AcwL+
\$b!+V
S<(FkM:
j[*Rf
c$D:_uc@
31>[2]
mk0Hds"
%DD"o]
x#R1~;
%\{;]r
=&-2P^e
ZgP^x[rV
Q;'OUx
scYRQ/
CGiw-W
u[c+y*M
"dj3de
7k-[C9
Q.e>N]S
`VW6Ya
xJW^!w
Wl2gL&MR
v#;QJsp"
'A3\{S
ILrgy
:MHlHz
caEm+~
i/-X7K
U?0}|1
v`JEnq|
I#tI-0
0#uoK%
"z\z'Z
2$''p{
Fy_1.L
N4?m#.
\@F']:
0HW<>.
|;p4;z
ze=h>Yi
rR`;/g
:4LUK*
2}"D!s[8l
q`)]%@
-)nN:~
FfLt;2
t,@JtO
-FyVKD(
|caXu8
gg,&Tg0
<hIOkt*\(X
-O'[Kc*
GQ8F*C
/"5JOd
"lZhZG/:C
cS@159
m(HThJ
}LD\^"z
ay(OM6
.M)`q.?P
z7l2Hx
0uo6bjjk
"BKRsx
'gVQ3T6Mj
aOpy#o
?eY|o3
eQpme#G
DCjZ+$3L
ShPhr~
s{,&og
)fs+AQ
<ul4bubj
Z%K(x.
nZrD;i
cSE'IW
NCf7lX
D\Decd
U1u/i
w3q*HJ
8=szrt
',qi-H
2/I*sFSl~
PYS+Op
Q/(DO]
<uL0?(
4^G5:L
4q;T/L
yZf<PBI
Pl2I]x
n6ta&G
8#"V0e
&Gvzxq!
*&4s+R
+P/"QD_
-KJR5;
P7\7wj
x8lR0D
Ae=Y<C
}T?KPJ
KP~4'w-
Y%,f^`+
S$2?;]
<C|u$^
?_.NOI
&4&#(E
KZ#>?u
vZ|ZOBry
JVOz5i`
D~_+GE
);z]r&"
hL8id+F
vk_t(si
8&P ?W
&F-Y4\
!(~z<0
"YBk*Z
ZzYxz>
{_Qxby
GcW!em
nMv WL
?N@I+.
9*{b)X9
P348T^
BNK-pUI
R{dd&6Q
5R]qFu
"u5pKeC
q7y0uvj
_S_(aVjL
:.jP/($
UWXL=,{
tZKY<r
~"{_lp|K
B`?H>]Y
?"Ea4:
{.VtR$
_w@:e
fuq'E?
n*^@,f
sg4~NF
zQ)K/o$Ry
;{YMHN
NQ\s>#
`")Kh
Us i8'
(Qh$\%A
|rS9PF_
Ym(xef_2
"[Vn.\W
]^wWDl~Mh6
C#LS='
^3T`*pQe_<
fya11;&
db<zBy
s9f.
3t*:kOtn
2_Q>sB
` 6YBY
un 5q7
xGE.eI*
O<FcScM
u)?Bi7
"2ui2(
KH&/UE
KN#6Sn
=dDe>C
g7u%Al
fs^MwDP
Fr/O.{
8R-eMsq+
O%]TPBo
NrP:$O
(uXcscf
z)aH)-S
tL@gSwZ
h91_R/
+?&lBE
Vo!P%$
7t}<q$
n{MG"I
)|6J~<
0{R9T$5<b
6o3aWIkOE-B=
sy//!2
ahgUp
y6F&-:
N,DZoJ
7'tXiC
7p/@u;`
TI4}c1
=(acIN
|"+{>l
v=h /H
%kBx/q
,1AG:)
6aiI@+q
{|FD' D
i'm-@x
JSSd1 (w
bkCJ)
c,H9[&
8k%7JU[e7
d2XT(q
.xz^(D
hO3dqvI-^^
Zhm-Z:
fH:Ypm
U'vgOVO
6U$XLh
I0v_ke
N++C.KV'
7XtJ+&=)
L gnq`
YT#'a)C
@V?eOS
CCu%^?r^
+O;^\r
8'\gO
Bmq^;z
!UW"g^<j
E9;Pyu9
k.odxD
lwHY_Y,
]G`~Q8
71T`wd
hVD1}h
r$tIaB
5ZI}~K
(@'5a^
2}@p^_
0$!P+"[
v6{mV-
Kl'[QU
z=A&ze
RT1^dm
8eB2#gM
>=*c\0
%D_bp[!
5;uqUC
Oz~eyW'
+dSg61
KK7uxb
&<dl9og
NnU)Dm
x\6K?JQ
#bz~-X
cZk1@R
4522A/D
hd[:d
mhUjyjh
>:5QvN
~(F[mGl
w;eTe)HQX
1JF:DxI
8%idcW)
mFv,Y;in4z
yFM:B
J7!soX
t]u*m-
U?.i?[M
(rBG%s
Avz%p
t=~:-
&K$;o7
i( Ek;&N
(V"/=D
Qg{H*
hL=Zx'Q
u%4$`h<
xC<&R+}
ZP"WUs
x+O mR
o=llS^
RrEA;P
,o)@NUC
4] 8B
F*L"L]}
)u[{sgz
qxKrsf
Sw1nkf
5)U @
osC9Bn
0;)@"6
D{R"vXn
[5Ky"M
HV&gA[
Z?\>uv
6W32(Ze<
4Wt]3*%
uf8"?26
Ggp@4o
2l;3T-i
Kr3^j"
PPUQt^
z6m\YE
7J3kb4w
k?rY(i
3I8fc9
bQ@wYU
nl2xK3
LV)d#5{/
mfey>2'
-5_]lU
bn;^Ls
1*Jnv&
fG|dUl.d
(*XnE"7Y
CZ!|.{d
OA?1^M
/4~{Fg
XFg;H]*
1{7CSp
JIpBh,
|n@4~v
_q*>,Q
/"X%+
Us'E"PY/
8{S1E|Qo
Q*2av
k9ya>`MK
LUC`(pg
:o|gg:~J
`+JKU75
Uw]uVhp
SVlyN5
HVAECJ
>-j8Ci
m "rhv2
T_bpJS2
kJ~lao.j
6T`?f?#
V(]Ve'
R~K$L^
EpmEdi
YX]y\Z,
*9"0c@
.jhF*I
<'HsAI
\<|>`4kf
I"^!M/
;z^ZE)
9e5%sl
By)!lhK
k\91~f
^K_aI]\
s/V"1O
ba2Z9yW
'X8kjZ
T{3;Yc
P_Rd0t}
RVpRI)<
g|1|&qy
::{Ow4
`r+"e%
SXag4b
fV/NO[?
$Qo&T
Z3y}1VD7
TYF=5f
#RP!U@o
p5{\_R;
&1.N'i
5hxcwT
D13rd9
p`7If+#
?#}D@%
[>ffdNY
6i=Z>B
nveT`^
c+2D7m
vW~h9V
,4N#NC8+
q(_5S@
oLrmz-
^v })[
3Yp7pKL
N/M^Q
33{f&V
2^U!_"
Pd2D,|
.Iq{<m
%6^8'r
{Ot+8*
kU }`>
lFab3k
%n<WaDK
@Uk3z#Q
3/Es%~
#Gl8Ve
#`Jk,}0/
]kTwtj
A[86$J'
AnJ|Ga
/$n]oO
d {=!(b
B;'tBh
%P<l%!
D')k\5
_]V"B,
4'Aa}8
zvvYun
j3x-$%
iEY$^y
iTS)ZW
m^ZJ9Y
]|5l<'
$7ufC
3i,*_'
W7lO(A
`^|z[+.
LJ@b-J
(^Y>Ks
u(_5FC
K>D/.I
oq.*EE
{2G4z<,
e!.?|u
"[5Mw_uv
I@j(R}
4J!z06,8]
%juK8Q
aq,Ve
Bd; 1kn
ZlBC$.
|EScP
W#4r_Qwt
\h"*:l
ypLiNSpn
qubVUR
:8=(C8
eZib5xK[
E,Sw6b3
z8T0WD
_o,s!H
OP&4iL
:b5/;f
8+r6WA
P\'S=z}/
"&6SXRj
-Ll+{4
DCCs?s
l J4\8\
K+r6$Pp
6&\x,H
Xzft'K*
b1,_12
O"(H)j
tYEWV-
<14=>&
SrZ5>%
;YVuD7
yIUn\#
UMRVrHlo
8[X{>I
z Su'5
'&/n6#
^"!P0s7
O_!$LWPMF
X3Ul]3G@
Vv:wG
v'0h2{
(6c*9[
C:ezUf
bhRG'i)
B<!k2gT
y|SiNVU
N_.EXf
xmn\>y
V0Avka
@(hzv@
_jl\Gv%
tLdR66
51$y!
!Fkf>m,
v%R]#V
Xni-<n.
H]Hzcd
r:3<o-b
qxk$.h
f3Klhp
Jyl`BH
JJH?P
[abz(
W-S05\O]h
YI{,p-
\p:IO:
s&O),(
-`l"i<l
V:S'@5^
2jBMl,
"[;lg}
* .>kR
z`&(ck
*Op$v;
[l7[S\d
{sPcuc_
`ii#6M<
%H1n_S
TW?^]a
EIjC6
,Yy;.K
|V&%Ej<4a
0ce+@D-?l
(@LkTG
sKK_@\
SYLT.;
E:~SYS
[9+a]T
,tSj?R
C(SbsJ
kX7IX=
MXJp1E 7/
.hW`>\
)GMh]0
eT$s(z
JaQS6/
p^75!q
jqFyg>>
vv-<ozG
@8!{@"
CSk2F7
vBZKG~@b
prK~lb
pm|y}?D
!qP:|xI
[o`g%%
gCqc3SU
*mj]69}
SDKf|O
PR7qgL
uZ88WZW>|-
y.;?^j
Kg}$&>E
a0]!LA
(ttWoD
nTm`4\
&UG9%H
g5~q!/
a<>SpQ
=EM;6@
(S'n!#W
sVau?0
9z8t%x
eC[i!b
{,%16=
Tsr.hN;V
YIT>X"
.^y!GB
pZKyj.
JQZ5ES
qVq<i$
$@`,^j
@C`(uD
`*C/Ir6
p!$xsU
>sv GK
k!Y<kf
<9L!Kx
!+A$M
,n~*uCnX
~anaj7
|Jv>=
VE;CTB
? I),S
=a5.PE
YI4 aF
$E;ce^
`G7B,$
3cE%SB
Af1x2:
t]gG:r
5G_mYX
"E0-;#
"u%'z#
1aZ,=k
su-d`4
AK /Az
\;'76>
Fk=@fo
/q,ldz
1vy74Y
hzn[z2#mH
]V*;0/K
|7(EG](
ntUQA*
^@1.k19
*'`$p#
DZ 2y;
&JAz~!
-./55?YQZ
z5_}iZ
MahT ]3@
Vw(fDw
cL+p'qy
<[>knE
o(3$Jt
*l%_pqJC
bW0VkR
)FIrRm!
Tu4b(dl
x@%4S%8e
jOj*i_
8\OvY|
KiGpke
UdqfN
wEmG^*
$@cS\
pU`C$`9
0Az@t"F'
C^p(H<;|
}F>KA9
/(xEfs
imHsn^
k.ZOv2
X|X9B9
M[qL+^3
pr12NAD
%hZM}3,
A,:QQ0
C9LY[.P
q9D}c:
7?6!bk
DQFbUC%
fNqk(h
Cmt?&wC
}onMe+
vb&AN|
Fri{uv
[t#6S]dU8
::=KO7I
J.8Ninl+P3,7h3Th
_aT@l_
qCg!?3
4-^k$E
}F\j<*
^g`Z#~
s2ZEl*
Qn,YS/Z{G4
&!=EO$1h
OataAA
rD95p;
171>1N1
2L3o3}3
5"565B5P5c5{5
656;6A6G6M6S6Y6_6e6k6q6w6}6
::&:-:4:;:B:J:R:Z:f:o:t:z:
;%;,;3;:;A;H;P;X;`;k;p;v;
<<'</<:<?<E<O<y<
? ?2?<?
0M0\0e0r0
0*101V1_1e1x1D2d2n2
3g3p3u3
3_4d4z4
550555K5_5l5q5
6#626F6X6`6}6
6797J7[7r7
808:8D8M8
9C9M9V9_9t9}9
<&=k=p=t=x=|=
132g2o2
6l7K9{9
;6;;;f;k;
<=<Z<o<
=8=C=Q=W=h=y=
>(>/>5>N>U>
0/0D0p0
1;1Q1l1
6 606g6q6~6
:#;@;M;X;_;y;
1G1e1n1y1
3N4*5m5q6
718h8v8
9%939B9S9a9l9z9
;/;L;{;
</<4<T<
0.0>0N0W0y0
2+3>3J3V3b3n3z3
8+9O9Z9m9t9
;"<R<j<
1&292w2
3>4N4j4
51585A5Q5a5y5
9*:6:M:W:z:
=S>e>{>
2B2M2n2|2
233A3L3
3R4X5c5
6#6=6K6V6x6~6
819_9u9
:.:Q:j:w:
;-;G;s;
=9=H=U=
=*>;>n>
5'6-6Z6`6
8 8,8=8v8
<8<H<l<
=>=K=m=
=*>5>K>d>
061I1a1e1i1m1q1u1y1}1
202:2`2
3+3Q3k3p3
4&5c5o5
6Q6\6m6
7.7A7i7}7
:#:K:R:\:
;8<]<e<k<q<w<
<L=W=b=g=l=
><?c?s?
0#0(0-0=0B0G0f0{0
171A1\1v1
22+2G2V2[2`2{2
3/393E3J3O3p3
0^1v1|1
:&;k;p;t;x;|;
2N4@6Y6
6%737=7Z7`7h7v7
7A8O8[8q8
9):.:v:
80>0D0J0
1#1*181>1L1R1\1u1~1
292@2D5
7C7Q7n7
7f8l8r8x8~8
9(9@9F9L9Z9`9n9
:1;O;\;k;
</=6=H=Z=
>!?_?l?
1K1P1V1[1f1l1r1x1~1
2 3e3~3
4-737;7G7~7
8H8S8]8l8t8|86:
1I1R1X1c1y1
2#2Y2t2
4+4A4T4`4s4
7L7b7r7
8!8,828=8C8Q8^8b8j8v8
5@5Z5}5
6/6G6i6
8G>M>S>Y>_>e>k>q>w>}>
;n<T>X>\>`>d>h>l>p>
4181<1@1D1H1L1P1
14484<4@4D4H4L4P4
7$9(9,9094989<9@9
0@2D2H2L2P2T2X2\2
==<=@=D=H=L=
.6L6u6=8C8I8O8U8[8a8g8m8s8y8
4 4+4p4v4
4D526<6I6z6
7,767B7
7C8I8K9]9E:
5X5%6?6j6y6
7)767[7b7
7<8C8k8
9(9;9U9i9
:*:X:g:y:
;";/;S;];
<7<><i<q<
=,=B=U=
>!>'>2>7><>L>Q>V>f>k>p>
?!?&?6?;?@?P?U?Z?j?o?t?
0 0%0*0:0?0D0T0Y0^0n0s0x0
1$1)1.1>1C1H1X1]1b1r1w1|1
2'2:2[2h2}2
3;3c3z3
4!4>4W4\4a4~4
45C5p5
6%6*6/6J6Y6d6i6n6
7K7`7p7u7z7
80858:8X8p8u8z8
:;:S:X:]:x:
<)<5<:<?<T<Y<^<v<
=!?Y?c?
1!1'1o3
8%8E8T8^8k8u8
<%<7<x<
=!='=k=
4=4[4n4
6B6P6X6i6w6~6B7]8l8
=0>6><>B>H>N>
/0_0s0
00112K2
303j3q3
4!4h4u4
7'898i8
?-???Q?c?u?
4%474I4
1R1q1:2A2H2R2[2|2
4'494?4H4N4
6#7,7D7p7
7]8e8w8|8
97:Q:V:
1!1D1Y1o1|1
2<62;f=
u0{0%101?1M1\1e1e2
1T2Z2g2
9.989[9|9
1#1_1|1
5{8?9u9|9
5+5V5i5t5
6%636y6
;4;L;q;
7.8g8/=
151;1u1{1
22-2c2=3
425<5W5
5q6y6r7w7
8 9J9R9o9
: ;W;t;
1.1M1x1
1"2D2h2
9&9<9D9C=l>
7C9M9|:
<!<'<-<3<9<?<E<K<Q<W<]<c<i<o<u<{<
=#=)=/=5=;=A=G=M=S=Y=_=e=k=q=w=}=
>+>?>E>+?^?
==#='=+=/=3=7=;=?=C=G=K=O=S=W=[=_=c=g=k=
33#3'3+3/33373;3?3C3G3K3O3S3b3
7-7J7g7
828O8l8
3 3$3(30383@3H3P3X3`3h3p3x3
4 4(40484@4H4P4X4`4h4p4x4
5 5(50585@5H5P5X5`5h5p5x5
6 6(60686@6H6P6X6`6h6p6x6
1 1$1(1,1014181<1@1D1H1L1P1T1X1\1`1d1h1l1p1t1x1|1
586@6D6H6L6P6T6X6\6`6d6h6l6p6t6x6|60787@7D7H7L7P7T7X7\7d7h7l7p7t7x7|7
`3d3h3l3p3t3x3|3
4 4$4(4,4044484<4@4D4H4L4P4T4X4\4`4d4h4l4p4t4x4|4
4 8$8(8,8
1(141@1L1X1d1p1|1
2$202<2H2T2`2l2x2
3 3,383D3P3\3h3x3
4 4,484D4P4\4h4t4
4@>D>H>L>P>T>X>\>`>d>h>l>p>t>x>|>
?$?,?4?<?D?L?T?\?d?l?t?|?
0$0,040<0D0L0T0\0d0l0t0|0
1$1,141<1D1L1T1\1d1l1t1|1
2$2,242<2D2L2T2\2d2l2t2|2
3$3,343<3D3L3T3\3d3l3t3|3
4$4,444<4D4L4T4\4d4l4t4|4
5$5,545<5D5L5T5\5d5l5t5|5
0 0(00080@0H0P0X0`0h0p0x0
1 1(10181@1H1P1X1`1h1p1x1
2 2(20282@2H2P2X2`2h2p2x2
3 3(30383@3H3P3X3`3h3p3x3
4 4(40484@4H4P4X4`4h4p4x4
5 5(50585@5H5P5X5`5h5p5x5
6 6(60686@6H6P6X6`6h6p6x6
5$5,545<5D5L5T5
9 9$9,9D9T9X9h9l9p9x9
:(:8:<:L:P:X:p:
;,;0;4;<;T;d;h;x;|;
2$282@2T2\2d2l2p2t2|2
3 3$3@3H3L3\3
484@4H4T4
6(6H6h6
74787X7x7
788X8x8
989X9x9
:8:X:x:
< <@<`<
$0@0`0
8 9@9X9p9
DigiCert Inc1
www.digicert.com1.0,
%DigiCert Assured ID Code Signing CA-10
191122000000Z
230204120000Z0w1
Beijing1*0(
!Beijing Qihu Technology Co., Ltd.1*0(
!Beijing Qihu Technology Co., Ltd.0
'xZ@?x
*http://crl3.digicert.com/assured-cs-g1.crl00
*http://crl4.digicert.com/assured-cs-g1.crl0L
https://www.digicert.com/CPS0
http://ocsp.digicert.com0L
@http://cacerts.digicert.com/DigiCertAssuredIDCodeSigningCA-1.crt0
DigiCert Inc1
www.digicert.com1$0"
DigiCert Assured ID Root CA0
220801000000Z
311109235959Z0b1
DigiCert Inc1
www.digicert.com1!0
DigiCert Trusted Root G40
]J<0"0i3
v=Y]Bv
http://ocsp.digicert.com0C
7http://cacerts.digicert.com/DigiCertAssuredIDRootCA.crt0E
4http://crl3.digicert.com/DigiCertAssuredIDRootCA.crl0
~qj#k"
DigiCert Inc1
www.digicert.com1$0"
DigiCert Assured ID Root CA0
110211120000Z
260210120000Z0o1
DigiCert Inc1
www.digicert.com1.0,
%DigiCert Assured ID Code Signing CA-10
.http://www.digicert.com/ssl-cps-repository.htm0
http://ocsp.digicert.com0C
7http://cacerts.digicert.com/DigiCertAssuredIDRootCA.crt0
4http://crl3.digicert.com/DigiCertAssuredIDRootCA.crl0:
4http://crl4.digicert.com/DigiCertAssuredIDRootCA.crl0
j-#O7;
(f*^[0
DigiCert Inc1
www.digicert.com1!0
DigiCert Trusted Root G40
220323000000Z
370322235959Z0c1
DigiCert, Inc.1;09
2DigiCert Trusted G4 RSA4096 SHA256 TimeStamping CA0
http://ocsp.digicert.com0A
5http://cacerts.digicert.com/DigiCertTrustedRootG4.crt0C
2http://crl3.digicert.com/DigiCertTrustedRootG4.crl0
DigiCert, Inc.1;09
2DigiCert Trusted G4 RSA4096 SHA256 TimeStamping CA0
220921000000Z
331121235959Z0F1
DigiCert1$0"
DigiCert Timestamp 2022 - 20
Ihttp://crl3.digicert.com/DigiCertTrustedG4RSA4096SHA256TimeStampingCA.crl0
http://ocsp.digicert.com0X
Lhttp://cacerts.digicert.com/DigiCertTrustedG4RSA4096SHA256TimeStampingCA.crt0
DigiCert Inc1
www.digicert.com1.0,
%DigiCert Assured ID Code Signing CA-1
http://www.360.cn 0
DJ*C~Oj
DigiCert, Inc.1;09
2DigiCert Trusted G4 RSA4096 SHA256 TimeStamping CA
221212063039Z0/
DigiCert Inc1
www.digicert.com1$0"
DigiCert Assured ID Root CA0
131022120000Z
281022120000Z0r1
DigiCert Inc1
www.digicert.com110/
(DigiCert SHA2 Assured ID Code Signing CA0
p1f3q>
http://ocsp.digicert.com0C
7http://cacerts.digicert.com/DigiCertAssuredIDRootCA.crt0
4http://crl4.digicert.com/DigiCertAssuredIDRootCA.crl0:
4http://crl3.digicert.com/DigiCertAssuredIDRootCA.crl0O
https://www.digicert.com/CPS0
DigiCert Inc1
www.digicert.com110/
(DigiCert SHA2 Assured ID Code Signing CA0
191122000000Z
230204120000Z0w1
Beijing1*0(
!Beijing Qihu Technology Co., Ltd.1*0(
!Beijing Qihu Technology Co., Ltd.0
'xZ@?x
/http://crl3.digicert.com/sha2-assured-cs-g1.crl05
/http://crl4.digicert.com/sha2-assured-cs-g1.crl0L
https://www.digicert.com/CPS0
http://ocsp.digicert.com0N
Bhttp://cacerts.digicert.com/DigiCertSHA2AssuredIDCodeSigningCA.crt0
Htf{#
&zK,u_
DigiCert Inc1
www.digicert.com110/
(DigiCert SHA2 Assured ID Code Signing CA
http://www.360.cn 0
20221212063040Z0
GlobalSign nv-sa1*0(
!Globalsign TSA for CodeSign1 - R6
GlobalSign nv-sa110/
(GlobalSign Timestamping CA - SHA384 - G40
220406074538Z
330508074538Z0T1
GlobalSign nv-sa1*0(
!Globalsign TSA for CodeSign1 - R60
>-re+0
&https://www.globalsign.com/repository/0
-http://ocsp.globalsign.com/ca/gstsacasha384g40C
7http://secure.globalsign.com/cacert/gstsacasha384g4.crt0
0http://crl.globalsign.com/ca/gstsacasha384g4.crl0
'v/i)~
.@]|Gt0
GlobalSign Root CA - R61
GlobalSign1
GlobalSign0
180620000000Z
341210000000Z0[1
GlobalSign nv-sa110/
(GlobalSign Timestamping CA - SHA384 - G40
a:c|9#ymt
"http://ocsp2.globalsign.com/rootr606
%http://crl.globalsign.com/root-r6.crl0G
&https://www.globalsign.com/repository/0
$KtZ}r
GlobalSign Root CA - R61
GlobalSign1
GlobalSign0
141210000000Z
341210000000Z0L1 0
GlobalSign Root CA - R61
GlobalSign1
GlobalSign0
PmBf/M
'YLv9[
GlobalSign nv-sa110/
(GlobalSign Timestamping CA - SHA384 - G4
GlobalSign nv-sa110/
(GlobalSign Timestamping CA - SHA384 - G4
fu8`#o
Dapi-ms-win-core-fibers-l1-1-1
api-ms-win-core-synch-l1-2-0
kernel32
api-ms-
Runtime Error!
Program:
<program name unknown>
Microsoft Visual C++ Runtime Library
mscoree.dll
CLC_ALL
LC_COLLATE
LC_CTYPE
LC_MONETARY
LC_NUMERIC
LC_TIME
(null)
Dapi-ms-win-core-datetime-l1-1-1
api-ms-win-core-file-l1-2-2
api-ms-win-core-localization-l1-2-1
api-ms-win-core-localization-obsolete-l1-2-0
api-ms-win-core-processthreads-l1-1-2
api-ms-win-core-string-l1-1-0
api-ms-win-core-sysinfo-l1-2-1
api-ms-win-core-winrt-l1-1-0
api-ms-win-core-xstate-l2-1-0
api-ms-win-rtcore-ntuser-window-l1-1-0
api-ms-win-security-systemfunctions-l1-1-0
ext-ms-win-ntuser-dialogbox-l1-1-0
ext-ms-win-ntuser-windowstation-l1-1-0
advapi32
api-ms-win-appmodel-runtime-l1-1-2
user32
api-ms-win-core-fibers-l1-1-0
ext-ms-
Sunday
Monday
Tuesday
Wednesday
Thursday
Friday
Saturday
January
February
August
September
October
November
December
MM/dd/yy
dddd, MMMM dd, yyyy
HH:mm:ss
Dja-JP
((((( H
((((( H
(
american
american english
american-english
australian
belgian
canadian
chinese
chinese-hongkong
chinese-simplified
chinese-singapore
chinese-traditional
dutch-belgian
english-american
english-aus
english-belize
english-can
english-caribbean
english-ire
english-jamaica
english-nz
english-south africa
english-trinidad y tobago
english-uk
english-us
english-usa
french-belgian
french-canadian
french-luxembourg
french-swiss
german-austrian
german-lichtenstein
german-luxembourg
german-swiss
irish-english
italian-swiss
norwegian
norwegian-bokmal
norwegian-nynorsk
portuguese-brazilian
spanish-argentina
spanish-bolivia
spanish-chile
spanish-colombia
spanish-costa rica
spanish-dominican republic
spanish-ecuador
spanish-el salvador
spanish-guatemala
spanish-honduras
spanish-mexican
spanish-modern
spanish-nicaragua
spanish-panama
spanish-paraguay
spanish-peru
spanish-puerto rico
spanish-uruguay
spanish-venezuela
swedish-finland
america
britain
england
great britain
holland
hong-kong
new-zealand
pr china
pr-china
puerto-rico
slovak
south africa
south korea
south-africa
south-korea
trinidad & tobago
united-kingdom
united-states
zh-CHS
az-AZ-Latn
uz-UZ-Latn
kok-IN
syr-SY
div-MV
quz-BO
sr-SP-Latn
az-AZ-Cyrl
uz-UZ-Cyrl
quz-EC
sr-SP-Cyrl
quz-PE
smj-NO
bs-BA-Latn
smj-SE
sr-BA-Latn
sma-NO
sr-BA-Cyrl
sma-SE
sms-FI
smn-FI
zh-CHT
az-az-cyrl
az-az-latn
bs-ba-latn
div-mv
kok-in
quz-bo
quz-ec
quz-pe
sma-no
sma-se
smj-no
smj-se
smn-fi
sms-fi
sr-ba-cyrl
sr-ba-latn
sr-sp-cyrl
sr-sp-latn
syr-sy
uz-uz-cyrl
uz-uz-latn
zh-chs
zh-cht
CONOUT$
RAny use of this Certificate constitutes acceptance of the DigiCert CP/CPS and the Relying Party Agreement which limit liability and are incorporated herein by reference
Antivirus Signature
Bkav Clean
Lionic Trojan.Win32.Babar.4!c
Elastic Windows.Trojan.TwistedTinsel
ClamAV Clean
CMC Clean
CAT-QuickHeal Trojan.Multi
Skyhigh Artemis!Trojan
ALYac Gen:Variant.Jaik.263476
Cylance Unsafe
Zillya Trojan.Agent.Win32.4128111
Sangfor Trojan.Win32.Agent.Axl9
CrowdStrike win/malicious_confidence_100% (W)
Alibaba Trojan:Win32/Generic.e13abae1
K7GW Trojan ( 005c00a71 )
K7AntiVirus Trojan ( 005c00a71 )
huorong Clean
Baidu Clean
VirIT Clean
Paloalto generic.ml
Symantec ML.Attribute.HighConfidence
tehtris Clean
ESET-NOD32 a variant of Win32/Agent.AHCE
APEX Clean
Avast Win32:Agent-BDDR [Drp]
Cynet Malicious (score: 99)
Kaspersky HEUR:Trojan.Win32.Agentb.gen
BitDefender Gen:Variant.Jaik.263476
NANO-Antivirus Trojan.Win32.Babar.kvlmgd
ViRobot Clean
MicroWorld-eScan Gen:Variant.Jaik.263476
Tencent Malware.Win32.Gencirc.10c0a4c2
Sophos Mal/Generic-S
F-Secure Trojan.TR/Agent.hzhsr
DrWeb Clean
VIPRE Gen:Variant.Jaik.263476
TrendMicro Clean
McAfeeD ti!6AEABC38E658
Trapmine Clean
CTX exe.trojan.generic
Emsisoft Gen:Variant.Jaik.263476 (B)
Ikarus Trojan.Win32.Agent
FireEye Generic.mg.723fa883af933361
Jiangmin Clean
Webroot Win.Trojan.Babar
Varist W32/ABTrojan.QBAU-1529
Avira TR/Agent.hzhsr
Fortinet W32/Agent.AHCE!tr
Antiy-AVL GrayWare/Win32.Wacapew
Kingsoft Win32.Trojan.Agentb.gen
Gridinsoft Ransom.Win32.Wacatac.sa
Xcitium Malware@#10umbeoyggg6o
Arcabit Trojan.Jaik.D40534
SUPERAntiSpyware Clean
Microsoft Trojan:Win32/Wacatac.B!ml
Google Detected
AhnLab-V3 Dropper/Win.Generic.R689899
Acronis Clean
McAfee Artemis!723FA883AF93
TACHYON Clean
VBA32 BScope.Trojan.Downloader
Malwarebytes Malware.AI.1163237881
Panda Trj/Agent.ASH
Zoner Clean
TrendMicro-HouseCall TROJ_GEN.R002H09AO25
Rising Trojan.Sabsik!8.128D4 (TFE:5:9u6a2PLrbiL)
Yandex Trojan.Agent!ut1/lfR1OZ8
SentinelOne Static AI - Suspicious PE
MaxSecure Trojan.Malware.324987160.susgen
GData Gen:Variant.Jaik.263476
AVG Win32:Agent-BDDR [Drp]
DeepInstinct MALICIOUS
alibabacloud Trojan:Win/Wacatac.B9nj
No IRMA results available.