Static | ZeroBOX

PE Compile Time

2025-03-01 05:33:40

PE Imphash

7f830c1be2775636f0aaf6ee74829bf2

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x0000c706 0x00000000 0.0
.rdata 0x0000e000 0x00005d00 0x00000000 0.0
.data 0x00014000 0x0052f1b8 0x00000000 0.0
.pdata 0x00544000 0x000001bc 0x00000000 0.0
.00cfg 0x00545000 0x00000010 0x00000000 0.0
.tls 0x00546000 0x00000010 0x00000000 0.0
.\'3 0x00547000 0x006c758b 0x00000000 0.0
.Qfk 0x00c0f000 0x00000868 0x00000a00 2.21434162457
.wYM 0x00c10000 0x00fd4e90 0x00fd5000 7.91885798508
.reloc 0x01be5000 0x00000100 0x00000200 2.48382742289

Imports

Library msvcrt.dll:
0x140c0f000 __C_specific_handler
0x140c0f008 __getmainargs
0x140c0f010 __initenv
0x140c0f018 __iob_func
0x140c0f020 __set_app_type
0x140c0f028 __setusermatherr
0x140c0f030 _amsg_exit
0x140c0f038 _cexit
0x140c0f040 _commode
0x140c0f048 _fmode
0x140c0f050 _initterm
0x140c0f058 _onexit
0x140c0f060 _time64
0x140c0f068 _wcsicmp
0x140c0f070 _wcsnicmp
0x140c0f078 abort
0x140c0f080 calloc
0x140c0f088 exit
0x140c0f090 fprintf
0x140c0f098 free
0x140c0f0a0 fwrite
0x140c0f0a8 malloc
0x140c0f0b0 memcpy
0x140c0f0b8 memset
0x140c0f0c0 rand
0x140c0f0c8 signal
0x140c0f0d0 srand
0x140c0f0d8 strcat
0x140c0f0e0 strcpy
0x140c0f0e8 strlen
0x140c0f0f0 strncmp
0x140c0f0f8 strstr
0x140c0f100 vfprintf
0x140c0f108 wcscat
0x140c0f110 wcscpy
0x140c0f118 wcslen
0x140c0f120 wcsncmp
0x140c0f128 wcsstr
Library KERNEL32.dll:
0x140c0f138 DeleteCriticalSection
0x140c0f140 EnterCriticalSection
0x140c0f148 GetLastError
0x140c0f158 LeaveCriticalSection
0x140c0f168 Sleep
0x140c0f170 TlsGetValue
0x140c0f178 VirtualProtect
0x140c0f180 VirtualQuery
Library KERNEL32.dll:
0x140c0f190 GetSystemTimeAsFileTime
0x140c0f198 CreateEventA
0x140c0f1a0 GetModuleHandleA
0x140c0f1a8 TerminateProcess
0x140c0f1b0 GetCurrentProcess
0x140c0f1b8 CreateToolhelp32Snapshot
0x140c0f1c0 Thread32First
0x140c0f1c8 GetCurrentProcessId
0x140c0f1d0 GetCurrentThreadId
0x140c0f1d8 OpenThread
0x140c0f1e0 Thread32Next
0x140c0f1e8 CloseHandle
0x140c0f1f0 SuspendThread
0x140c0f1f8 ResumeThread
0x140c0f200 WriteProcessMemory
0x140c0f208 GetSystemInfo
0x140c0f210 VirtualAlloc
0x140c0f218 VirtualProtect
0x140c0f220 VirtualFree
0x140c0f228 GetProcessAffinityMask
0x140c0f230 SetProcessAffinityMask
0x140c0f238 GetCurrentThread
0x140c0f240 SetThreadAffinityMask
0x140c0f248 Sleep
0x140c0f250 LoadLibraryA
0x140c0f258 FreeLibrary
0x140c0f260 GetTickCount
0x140c0f268 SystemTimeToFileTime
0x140c0f270 FileTimeToSystemTime
0x140c0f278 GlobalFree
0x140c0f280 HeapAlloc
0x140c0f288 HeapFree
0x140c0f290 GetProcAddress
0x140c0f298 ExitProcess
0x140c0f2a0 EnterCriticalSection
0x140c0f2a8 LeaveCriticalSection
0x140c0f2b8 DeleteCriticalSection
0x140c0f2c0 MultiByteToWideChar
0x140c0f2c8 GetModuleHandleW
0x140c0f2d0 LoadResource
0x140c0f2d8 FindResourceExW
0x140c0f2e0 FindResourceExA
0x140c0f2e8 WideCharToMultiByte
0x140c0f2f0 GetThreadLocale
0x140c0f2f8 GetUserDefaultLCID
0x140c0f300 GetSystemDefaultLCID
0x140c0f308 EnumResourceNamesA
0x140c0f310 EnumResourceNamesW
0x140c0f318 EnumResourceLanguagesA
0x140c0f320 EnumResourceLanguagesW
0x140c0f328 EnumResourceTypesA
0x140c0f330 EnumResourceTypesW
0x140c0f338 CreateFileW
0x140c0f340 LoadLibraryW
0x140c0f348 GetLastError
0x140c0f350 FlushFileBuffers
0x140c0f358 FlsSetValue
0x140c0f360 GetCommandLineA
0x140c0f368 GetCPInfo
0x140c0f370 GetACP
0x140c0f378 GetOEMCP
0x140c0f380 IsValidCodePage
0x140c0f388 EncodePointer
0x140c0f390 DecodePointer
0x140c0f398 FlsGetValue
0x140c0f3a0 FlsFree
0x140c0f3a8 SetLastError
0x140c0f3b0 FlsAlloc
0x140c0f3b8 UnhandledExceptionFilter
0x140c0f3c8 IsDebuggerPresent
0x140c0f3d0 RtlVirtualUnwind
0x140c0f3d8 RtlLookupFunctionEntry
0x140c0f3e0 RtlCaptureContext
0x140c0f3e8 RaiseException
0x140c0f3f0 RtlPcToFileHeader
0x140c0f3f8 RtlUnwindEx
0x140c0f400 LCMapStringA
0x140c0f408 LCMapStringW
0x140c0f410 SetHandleCount
0x140c0f418 GetStdHandle
0x140c0f420 GetFileType
0x140c0f428 GetStartupInfoA
0x140c0f430 GetModuleFileNameA
0x140c0f438 FreeEnvironmentStringsA
0x140c0f440 GetEnvironmentStrings
0x140c0f448 FreeEnvironmentStringsW
0x140c0f450 GetEnvironmentStringsW
0x140c0f458 HeapSetInformation
0x140c0f460 HeapCreate
0x140c0f468 HeapDestroy
0x140c0f470 QueryPerformanceCounter
0x140c0f478 GetStringTypeA
0x140c0f480 GetStringTypeW
0x140c0f488 GetLocaleInfoA
0x140c0f490 HeapSize
0x140c0f498 WriteFile
0x140c0f4a0 SetFilePointer
0x140c0f4a8 GetConsoleCP
0x140c0f4b0 GetConsoleMode
0x140c0f4b8 HeapReAlloc
0x140c0f4c8 SetStdHandle
0x140c0f4d0 WriteConsoleA
0x140c0f4d8 GetConsoleOutputCP
0x140c0f4e0 WriteConsoleW
0x140c0f4e8 CreateFileA

!This program cannot be run in DOS mode.$
`.rdata
@.data
.pdata
@.00cfg
h.reloc
6vw>^p
E-;hm0
HeapAlloc
7u{?N]2
X woF(
b;#0]lqb<LN}
iY$zGk
wg\Mqv
9RY,]"Z%C2
Vd\RJF
SkhwQi
5TY{E;M
/"83
KTSJy6
(*Zhuf
N[~f~v
W=f4Q>
UfC$8Lx
T0rnU
5*n1rl\
0r~Y^8
.]0rN
V0rZY
CO'>8L<o
8L<_^8L<
u)}{W.b
>6vIZ3
5t=^a6
^miqM6
WZl>]3b1
Ro>sTZ
.j,~1r
@I:*)6
8I:*)=<
a`[+<M
_6Va}@!E
a}@)x8
W,Da29
wgfV2Zu
xG`jL3
(9RyK`3yi9;`3y
].VV3^
Y_gmy[
Qe}@mA
wcslen
^*wop]
oi.%}q&3
RtlPcToFileHeader
Pk*Ae#5
I nysY(
4=4fS1
dB{8|}
9cVhb=
k4.*sE:
*8zI>H
!.K4O\
8 .K<z,
LC!.K8
L+=@%F
Bh{UBLw
1{K<tf
}5SC-K7J
M0eMy}
"9[,l4
%tI`HraE
Ne0vQ
Z'z*onR
.?n5v&-
veVw&-
iVw&-HZ
Hr5x;s
|T`T"$
X~l/l.
":ZRo9
Qmj.{&
E0:umF
Qi[tp#]
(u=9I(+
SetLastError
>zX#H%
E48_jT
n\a|Z~
LV{N0/Ns
}w9N<{
5i/P(+
,bT4'2u
feU*2Q
V:&su30
XO'?D.cu
2jP!^~
0s<=f$H
b`>_vM
0+3Myf
,1!cai
.Rl<V,
&5"E2!R
6H(1k&
^[+>)g
_>8g'OG
8g''_v8g'G
bpt+XwK
[[$tr6
6Za5i"
+x_,=7
*y?1)
0^}ED*
J!f.`X
%HTz\DeT
jln&"/3w
z@>\2_
x :!^X
eC?FtA
\1,>Y/
wf}!?<
Q8ya`4
\gU{9!
7tf:<'Yw|Ll
N{{87.
7cv*ZBk
/WNBY&Y
Nb/o'
,|fARh
_aSzG%
o9pi #
W {g5H[
oxjQ5~x
t-;B+5~
m*n`!W
K<"'>=
2lp#_c
eFS[n>3
r*HDia
jCZSvz
-X8wM&
T|u?Wm1+Y
signal
MultiByteToWideChar
o}dM>t
d|u=T{
}y@No&6
uCm=|#0
Q-(BdHT
I918Y;
S\4s36{rL]go
Bc*6e!
QpYCc*6E
FCc*6~
1.Cur)
AVKFkC
o(xp~bvK^/G/
*6c7Di~<
G$HLNu
xT7VJ6
+8 -:i<P
0G6-nR{
oo`@~q
:<fSW5
K?M4?+
U~-4l$u%
GetSystemTimeAsFileTime
Cxw?[n
4b\z,t
1]2eyBI
0&sm,N
|37Q H)
["g%kP*2
?(c&[i
'2F^BY
CzF<B%
{7wK]sF#
}sf3-M
!Y,M'l
QjuuY
,bQQFs#
RC>OB<
EnumResourceLanguagesA
:\%#y
7-$op6
|zmZg6
?52O]{
SetFilePointer
CreateFileA
UOKH4
)F428<
bhv~%Pi
kuJ8uA
p<338,0R
bZYsrt
gRCkOr
,#I-XWP
wE]"pWN
uNgt;
xLE_Y
.0pBNf
n~;%L?7
Ht?~]l
76L&_>
8i3.6%G
&[S.j7<
f&7%dl
d8$5_D
:py@oM)N
$;#v:x
9"x#o
L8~2KL
--lCKF
liwdRss
9(neFF
{{f/&I%
A:vqfE"
Hk~5e7
Lu|HJ*D
Xy}(&fl
jNQF2Yn
><'_nK
FlsSetValue
}.>w#U
Uc=c;Q"ptw
y.8"'U
<ew;_%
*pM'q[
m-s^H
<DMys
:<Iw
+nKS90
CreateFileW
]mZZ<2Qd
5$ ?Yv
jHVNncb
.jP^_?
Och1_*8
R@u$O
#B=`V!"
]=P=BJ
GetSystemDefaultLCID
t|\e%8*Kr
gu:@Ya}
u/{0U]
bjlRz|
SS~;p7=
l2y/t$
we0:73
OpenThread
|TNvdk'y
GetModuleFileNameA
J~i*n
Pb7;kl
P&=ENF
$*A/CT
@MF8E*
nZM'X_:Yp
>nC{}'
i2-Nl
EN++7#&
Q_Hbw
M<|n'"
0k-+NB
5:qw?Z
?en\?E
]na@Je
-iU3w]5AU3w
*ed"_gg
3)ox1*
0_Iw^h
@l)F T
ED~NH
ZV`69+>_
\Asill
W,~O=U&:N
wcscpy
|eMgb
|6ZO[f}
v3m2qU
:$SR:Pc\l
\*G~0eKp
,N!|Ac
7@?F2d
Kd.v~A
"[r/v~
t.v~AX
WpZZmPoW
_n)xoi^
o=73hJ
%jh4tc
yk|{(b
./v`^S
}JJ'vs
QZ9q/?
^*kviQ8;
nnQ^[]/Tw
I*nTv_
+mS5|15l|
!7JQ$R
^GElqK
/op"8z
?EPw-kg
Uvq+7xV
^M(\$w
&'+i l
{'_Mm-
=u4)>~
Iuntv=
yaSc/'
tjAx&,
-[7ukeqy=Zo
$)|(DC3);(/4
F\D?mI
gq!*"'Z
n?*ORcL
Sn*OF{
^"+OJ0K
EgGj+~I
>\=]W;
,t#62&
i+|Jv#
7Ep[\`
PS+)#x
,Pcp,A
Xu)p?m
D.g/(WiWyPX|
Y: #A,
VxM@&<
.Jz#=6t
~|#{E%
J&p#,r
0#W]\S
%Q X=G
VCE2zi7D
mpQ=^A
J'j`(
p`vl:y>
M4PM/U
Q+QjxcAi
GetLastError
7zCiE?
/%K(ziH
T[l`Eg
^njeBt
*^}[X+
%!Xo7
sTSFW`
iW1PI*
|vG}NWh
+>[u,
wR kQ"
d2hxu=9
_?%dh_
rXpCBu
&2>*oU{
j=_V*a
n%SJGmCIn
x/1Ljg
lRknO/K
BT|'Gr
2qg|)!
z9{woj.
nHeak(
D=nHei
5R[>e7
.>}5lx0"
v5FH* 1
Ix\!0-
*ImBl<rnP
@p>(Bu
m1F~}S
__getmainargs
HdbDDPv
kCZ7oT
!Jt'qc<7rol
R+BF>}0
Cn>\lP
kC2?aT
tXnWn]
B FJ 4
E5'[jw
*;D.\
[P{G_/
3$Teh
.=JE\
lLMa1ZJ =
y)<^+a
y)<\#"'
y)<ry}
SuspendThread
g4`E U
[1`"Ft
803^n+jv
C\q%2b
U_!bi8
C/x15Q
.x15Qt
'.OU/~
:}\0dc
k!*2HN
48AvOI
s6aI>-+
q`*8>$
\yF c1
,'$&R`
=&/,2k3J
nAM<|DG
mD;!]*
7QO/eX8
GetStdHandle
2:PWMK
e:*GGo
BAd:*G
0:f~;Ij
j;>G+V
p=j)}x&C
U_n=KX
0<\ac[G
)}6^V
>5.(UZ
<u % J
j`':R
ExitProcess
LHaRGO?
=RFuHB
Xs2PWc
jysD!$
$3}=##
xAUV1QV
&!0"nv
=\YMzM
?f@Vcc
P"Z>Lk^?{
]i/hrP
08dEU7
!kIC.00
y\XN:N
{M*F5u
m/k/'l
4'4DBH
%\=d%3
BWY)Ip
)FBExp!FBE
xjG5qm
Vy79A3
b|k9r)
c|K9l29
b|+9~#
We/Y\yw
n(@*f#
0)I<F!R
n{RAS@
>s$7\B
;*jI_.
7Hk<f34
xh}{O*
memcpy
NIAHb
+iFqUsj
(GqUw}8
0\c)k^
<5.@-4oV
7Bi3%p.
Bvu+]b\
Pl{XAH
{t)[HB
| 61o/
!,%$v$
[vI/OV
SetProcessAffinityMask
EncodePointer
FindResourceExW
=:*wJ+
M'c7|xuD
R8*"pS
VZPnt3
q,^+>3
}Zf0Bi
sm+zQs
rEZ\^J9p
dD*hnx
^nBu3a'
/g/2Xi
hGW/8&
l'%^0q
X :d^n
-%]{/A
D*`Zf7
8A?zI{0x
Or}I3+s
(iAD>^
of&n27
^?2 !f
C*Ua&v
bzC@P%
2N~V!,
n"81(;+_G
L5b$ZH
) @"VRL7F
pa +(b
oD"ArS
c"n43m*R
A}vdFq
7(wu}A"
~`1e:.
`(:7\A
NNHL/Vc
4}T?Jk]
)q}t%0
9>z{0
}N}*:~$
,}}wBK,
-no+,_
oG;d*5
9 0?
k>M ChT
GH"9@\
yt?m*'
MP{$N<
[w!"L3
hR7}Z3
U/YKdD
_'d1c{h
>$B%2v
Xu/VN+
3)Z.}k
RtlLookupFunctionEntry
="l45V,<
$m0LK|
A.&Fw+
n87}Tan87,
Ji; 1
}5IpMP
+Dv9\s
?PgAZf
(Ve!Q%4
PNdW[a?L
D}6}Gp
;5FvZm
,);Epu
u4cn/|
]E)RNRZ
,J#ph`
aw,J#7
")|GB+
]+ZM|,;
(}zdOTFq
mAt%cU
|N\wV\
2E?>j*
iRxHi$
FE'cM}
jmLWWkjmL
K0(8qX
$TO,RrJ
Rr5xx,
A9q\q/
ee'!AoB
>i.7_V.)
^95=4@m
nTUm&P
{4PjC$
y+u'8'
pmbK&w
iu\: !
bO1T%X
fJp(G8
j_3wJg
jNZ%F>
(hp+X[
HeapSize
3FZp6$
b)N!%-9
DH#]k9W
0fBn.a,
Ih*~M^
vGBAd_
M[C[bTdu
sL2*!-
=r[w{-
'pu0`u
#xH3^$
p;3,f/
I/a%jw
cnc4d7t6:
p#I/k4
=kO2Do(JH
rkRI$A
MlI~0Q
hQxv%R/
\d24A6:-
-BN%Sy3`
hqgF-U
tY/.g-l
:kMAl8]Z!krE:
bucOGY
B_Zkqy
kv<u{-
fwrite
^&,UfD8
8E2!3#
gkMHMX
X:Do2CB
A0]Wqa
BtaiL
RPutdC
B5BGx%
<y3cx@a
gow4[I
vMaH.iT^
6;*'e+1j>_3Q
0el?pm
_%-]m<}
sbt4I`
JBR"-`
nh~`|m
Jf]B\0u
\0u.Fz\0u
oN)~2f
G Gg$y
94>N\B>
GetCurrentProcessId
!1m`$8 ,
{YHpM\
j5bm[#
WriteConsoleW
Pn`OR=
FindResourceExA
e3|I*rp
$[-5ms
c:HASH
7o.7 JN
glLi2%
strlen
KZcHFj
&DA-[5n
;+,Ae9
'%:+,A
K[H+[q
9u-vkw~Wsr
*cbnYx
!Jo6UP
F9)khx
TWKQ}*RA
Z{_+]{
j3sQ8H
ru:@Q&
LKNce/j
c[el=W
"Vxz@2
*SnW2l
42a\="
)=-V](
IsValidCodePage
n.0E~,
)L1c,K
@1PH#h
Atlp`\
7gY<vM*
1-:_3 :
7UZz97j
?*{'ga6
J9Z(d$
&??f^Wr'??~
pUQ[pb
l:bh}izW
@!mxq8
eW05#.
m%'+ \qP
#p]'Rp
rzeP%S-@&
^>\.hCJ
/UZ)GYu
GetStartupInfoA
_amsg_exit
1Nwe-V
yOwe-S
_commode
nQ3e2T
wrYzm
FnY^(08P
(C]!/>
8\Z\gb
Xf!a
0t"lt<m
ogl(3B
@C[5d&
X>g9I~BD
J.uV{L6X]x{
x<x1p=
q>C#vI
xl>[(?
\rWh:o
ca.u_.FPQN!
r&pD0~
'1%hMRU
K38_~/
%2mw+yj
K/4+Tu
_SK@~cP
c~OW~Y
8mxyE]D
fe"Uh!R"
$q/I9~
+Od?y G
5R*$ftg5z
W#*IOB
yZY%Xn
PTb%QV
e>zbtw
iz07Lm
4,u 8;1
Ak$a4A+
_wcsnicmp
x88(BH
K_?|[
?9Kqm9
&DG|g1
`9@+V]
L1Qtp_
J8yB76
Z4ipYRI
I'5u#\
Zy$7|}
R?dd{g
tu0I5
8X;pouL
-]cJ50
~!]pq4~!]
TY>SLI
WCYR9:
w ,X^Qv$
H^Qv4d
q|`EoA
X,CZV'
v^=jSxq
N`cKJP
;"|p2C
@7-ICp
I<l],X6,
$m,X6\
?bNj3M
E>AqI-
O'>61=
gug^J,
T-n0bg_
9peR+Y
,A~58|@
Qa<hLsr
s/"-cMY
@Yf%bi|G4
kD!.9Pl
|pLM-y
klsTNLegb
D[JMbl
sKMbh
uA1 Y?P
xQpu-e1tW
Pe6c#3^
y9J<aNH
s:8vAf
T=5o(
%G6ame)
v*j6^.
e&^YvM(
,f4O5m
Cc9ej4ja
C'+=A-x;e
y4>Jws
d3xv[YW
O\ct*L
+a  E
[+>B$3,0
g]~@P20
`k}\X>
__setusermatherr
;>^!/6j
hh;em_
kUE]3*Er
,8qvsLd7
'N>_zy
h(NtD5
Zx8otU4
MCOtB{
$P+sZ4
&gZD-x
C,6toak@
2#)ba
]^}WD!
SetThreadAffinityMask
InitializeCriticalSection
gCzw X
j(3W'3
;fx,uz1x,iM
VzpDJB
(Jxeo9(
a PQJb
U1kWFs
KoofF+
P+G=,F
wB_r~
jb@,_U.
Evu4IU
%R3z\T
;&*$lh
~t.&pkIJ
aCOr;:
KuC3{Khd
xxN-UX)
FlsAlloc
sWFQqi
DHY=$.
Msf5cn
z'._\z!
<ddGh
AUu\:9
hHI"aC
bb717t
~?&(o)
vgrQ_?
)XmrhT
^VR;$80
R\z;$8>
"F+_-W
!^@-ei'nH:
a&j;j:~6
yvk@.m
,yi9>0
o,?+!V
\}6Tvp
)(JpBi
efs-0[
CZZ4In
b$a3'w
Sa'_W+
F^,B-\+
J4N/b)
WriteConsoleA
heKL9&
@)nM.F
N99u u
6/RE:|
DMjC|7N/
v8/<#[a
QueryPerformanceCounter
yUzNIx
C|:|A9
R[:|JC
/| i[W
0g58t1
Auy9lM
4BGof
bDi C6
=5 _gJ
a&M%rtff
2O!)7
s><MFv!
B{<JS?
?6ArQ"&
,BOIqXv
e(JC*
*v~w5C
HWo@0IE
@H@~n#
jCau8oC
k,O-a^t
Q>'VMh
l2BFe&
mIw3t6p%
0PFviE
N.,W"9
QMu32
H:yHcL
VirtualFree
" iPoq,
ILE1QZ
a~P}6%
%(@,C0
hmw$(o
SU!i=;l
[Wu@8l[Wup
HeapReAlloc
(KlTiG
w[78S7
YYfbhtl
7^5g)M^gUH
FH`z7Pp
BrF)]QR
-URLs
^aI%^i
B{ci$
{*bWwk
fPl:^x
MZ)|.Vg
C18ltaO
*_YW`I`
2ymT_K
u*._lk
/|T;yt`E
F-:lR
CZv).O%
8|m\Lf
GAK<_P
|RUNoF
8n4Z6]
PL$>7
BUYj=E#
+\K+8C
V"}r]4
UR8^.
L-F>it
R;Zz&:
MGS)+
\WR;l'
g(0X2n
VzNxNE'w5
SIuC=PO"s0
s-6Gn4
__C_specific_handler
'| h$~
0ef]ey
mx^z*P
Rr)lRG
nL/)lrF
1hh?o#k0'
I%k%U@
R;"PxVv4
tqc*B2
W' 26
A_=06U
E=?c)E$S
lblE&+
AFCDoP
1k$K19/!
PQw>g#
Cro_*2
!sSCa{
JgZ&N4
0Vd{C%u
g !s>_
_MbI)o
xJwsgM<
U8105H
,b?mDp
HeapFree
3FoxJZ
MB6DKVM
XTB~"`
=a9)>U 0
d3>'gu
C<)s
).y>ns
yyt2j"
Sy$7rB
pJB_j'
q:qDa9
o|x+q,
2PleCv
\/aDQm'r
`0Ie8C
1z&&GO3
p{&&gg
FreeEnvironmentStringsW
xI^pfC
q<jUB)
=xJR!A
FlsGetValue
v6/YzxTP
6=c3>`
d1vpdt
:$s~Rx
R]UIK(
)i(GqM
opAP]
0.U$;z^
v)1.U$
y&fyN:
\~{klS
)|7\0Qna
`RZe//
TqB$\
0)d1[S
$*s'*m
<ItQ"_B
Q=P#h*
woI/;u
!(5k$s
z29)#>
#Q18Hb~F
w,Pvs
<_PkM
([u},9
k](mUH
a.B9$W]
'zX1Pj@
8"cJU-
YTQb3)>
:>rtAV
gAXcqPV
et25CW
pYmz>!
^B*oaJ7
N`)a=]yKB?
pP_+);
({BGWQ
<xd@AB
#E`^D,4
#Yp+H>
8+fawW
N&~^`5,!
AH~^`%
2=8~^`
?jHNIj
_]+JL_y
"4}iqkf
ldC'Q/
-i:Tf!
SjSE|h6
Q76bf!
wi^IC;oi^I
n?c}eU
/o*oUN
8}TLT+
f8k:5Q
G;uw3<
;bqlMB
>+i>}~.U.K@
t`0lF.@
1\W2jm
zupW$[
e;VmV\s,N
7`PMbml
''WSzw''W
.:%P&~
SetHandleCount
a[vF*U8
6nvkZr
Y3}.cC
6p[4}@
1 K #2P
\HH7i\
\%X;G
\G.),a
X'Jhga
xj^4G
}IBx0U
dg>u)gZ
h%nXAm~[rU
8g$l=a
[ i}lU
ses)E`S
8w(b+[
o"0Qt
r&3hw2
;"@@M{
+O99h@
x*}fN/
~/fh/q
Wx8>fbd
[Ndi}V
-#@Iul
xYKYzxc
- .S9
~N)~p;
37SJ{#Fs
?B,d2m
FEc`2h
U>$mT$4
0^oBcG
_oB#*A
S<_oB#
Q_oB#`
4_oBc+
F;!`H=|7
cmJuYMg,
} 3(1H
A:(XkI2
;[jp75ny
-RE~v>c
M8U!hwc
<8x]$U
Ky>g:lK
GetCommandLineA
uQVEDK
t)5up)
@(-4Q6
Gr6w2{`
(7J-Q|G
)w3G(SGhu:
P.;4I+s
y1G9.k
\C:mRF
!fq?d0
-N_L5X
txo%/,
~;"A<Q
?<3Dgm
@3pnIc
Zc0dxM
%YQ:I*
SAremo
Bn~8v
rzt:V~
t~|x#|
N>AO=%
jfRo+j
o:?P'W
LuY'J
OJ)Ghd
$#~EscV
GetTickCount
O'lNpP
US%C,m%
H2WwU/
O6kb,[
}DwqZ
bQ*?lu
0r5d#I
r`9gRJ$K
:]@a$y*
y2;FK)
sIsm;4aKh
C AL!i
kK^%\2
.,R/k
MVO&'PR)
R&tZK.
'65`:*
?ig_M<0P|
m#N,46
i8oo{c,?
BR?!M0
4Zfz<!
V'8Ewr
i.I5yu
a^U+5B
5)F(p/z
$Q<s&V
z%Zm:ebP
@XIsE3N
aeJ6Ati/X$
DT=avz
,u.)1VQ
QKS6E_K
^RO%"P
CC7($K
!i-(o_
{'A:f68
%IEQWx
2>cvnf
cw%.Xo
J0Qlu+5
s!8>AFb
y;A0CDt
C;"#/8
D5KhYQ[
x|?n<L
+Rwt9U1Mc
}d0rXr<
NeX;d6
nB&WUw
2Dak|.G
G+=xTH
:>;^O\
<{6}Z-
&\t?yU6z
fPoM7RX
+`dkI@
?1r?hK
ei`c#
~hE`iG
W<p,--
x]Dto_9
"2B8,
''4)s.
3U~<'jc
Y#do^A.I9
btC|4Q
vh36"]
p%5x>o
*xjF9K
B{QOE
i$$]Q>
2;JaE
'W}7,l
sWQ\3k/N
?/Q6G*
>.[MPL
Xr_%,V[
@!:aan
Cc!iB+
>\6*b#
",Z7G()
xTuBwWhV
D81%#a
olcc9"
EGPj,Y
{86eM^gi]!g
}rg|[4
0X^wtP
2,"Y,k$a
L-rb3.
[8ivAN
Cjwc>9o7
M|mwzb
nWD8_
ca`x,5=
0Lx2{,nZ
udaw{j
Q"vE46
Xa[C-W W
!g.Wo{
$Fr1~r
l"-]^E
Npbchu
|D?a+L
+rse`r|
;8S/c3
F{?K>V
{oe;Dx
ZstyV>I
6;bUVt#1
GOV^Xq
&.M)r!f
+CshB%
>xu7qg)
%Sy[g<
-#H*cK
&C%bEg
Gat*c(:#
C~<;n"
0f%H],F`
]]=p3K
},:xh"
mn$_mE
02py]&
[QF-{v
otTE'0V
)Uu2>Dq
DdbML
=1RjB-
myO*KM
wN!I}Q
MuCe3a(
%gU=]o
SU'&k~
5sK%cW
r-xQw]
Ni.2{n3
Ffe~CA
In=l`8
?|D;p<
o!k%+j
z_7|LC
&<\w,G
fQ+rfN
>Hy1}F
|q,c*_KmQ
Qt ~Pwt
Q.>*PK
7)`KF(
c&`xR*M
H2[+?Y
!Ht;\=
LUA]kG
/^bs`AY%R
VN71NI
g6}]d1
B(aC7*
>([fW,G
R=[gQ&
>o7Nz3R
.YYYzQ
c%Ig7.
#k_.xk
@5%C6\
*NzkA^K;t
</O78r
R~<x+}
gmr2;p
ZF9_%^o@2
B,!5pO*
YsXm74
;c3@O f
W2tsD|
H'({XZv-
y!$(I2
W_hW3o
At+Ix:
.$1z:<
Q-e5g!
C'e>fw
?Bp4qW
MJ@kN~Lf
VW2p*=
vk>K!U:
Jx<1:YHY|
,`:O*x
u1F" !
_."W0-
sC:!k}
okx(>2
z_T;5%;
;tjyaS
(-{:Awu
39`ymt
dT#";D
>!?h4V}
48HO%R
JU\H^2
$o&+p+
<FtfB^
JqP+^9_
PU[h78o9a
<j3OH{[:
P7L%CiY
C]"HwQN@
!_|.*/D:
6^P+80F
gX_d/r
J$7}RQ
{>fjv
!09=:Twp(
r}"z<q\
]>{A%)r
s,6XoN
UOeKxh
:a'-H
].!rbD,s,
u>\Tr<0~*T
>e!+";
SUwvW
amMGKR
pq~Lh'
Aimg;^
,cE/WW
jDNm&wO
K5+`g|
w<*oZ 5
Gdov_p
i8 RW+
7qz66p?l
`U4>>Q
xwlVpj
#q^7-]
BgwTp$
BH_Wrf
vIPijb
'L&BM1
U**MiG
[(aZ{qh
~q~M)
K}QA0[
[w(WqDu3
$!g@V&
Z{xI!;B
>CsJ}q
5y`+W|
kSX%>33
"}b='m
A4.\V:|V
y%)kg6S
F(%Zp;
e{a]AO
%N?MCw
$Z*#&u
,?*ZO]An*
\\A^lfNC
MKkK4H
|R{ion,H
_jB8ed
*sob4t4
O)XPNacK
fQK+N5
TRm\o(
D''#]k
9/IN4@
N#kt:E[
5LouWeW
}Fw!Mw).
_mGWzCv
()W?b.~31,`{P
*'hOO*64
-`!o9
RO( S"
5 N)Ak
A$}u3R
dRau^{
y?;I4
0\y}st
*GmF<;qV
QwE~8,_d!_
eW`V/z
st5(lJQ
s&3%>-KJ
yGa$}#t
>:X^pfO
gEEw-M9
(NF}GT
*n';_f
c)a1Qh
/y}r+oF
g"RRu_
M>to93$
t9#+~an
AUx1v3
?y`7#B
j6dz|]
nK2D#N
[:%5uVl
(TxKVN#
::T;Hd
391zO^
oImaYI
!?}$2`?
CeK"b
guZE9:
@7<[pBE#
us=Wp{
~v(yO`
PBg9L/
-6-V\
=t@\>{
eo4S'+
Q8V z
Wa?Q#^O
Cz $Dw^
N*H4FKn:
C2%z>WT4%
;Hoj:'i
G&\q*u
)pG|ZN>
&HDX\z
uu-`Nm
w(X/1i
*yBEwK
)|yF^E
ByO|B
3,'*@^
>iXf<t.K
@5^KmS
s+Q=iJC
&}~%a9
nn4*6;
:<K`C0#
JCpkB1o
:}a}M8S
:N{57D
in@Etm
<YyW&!B|y!e
j(J+1=EO
>MV7k<S
[RekL6#
'0&.=Qz9
&/D'{w
4r;O]H
@WH[TL
VFYr*`
a$C/[)
nd/e$i
lgcJs!!
et@gP
@/rw&Q
_M5GuK#
E/o4uE1
B9zhcQd
5iIIq?
CrL$Dwe
]&a,s}
Mt aJi
/q=N@(
ED>~{F
Z_%?)g
!')WZB
OlFcga
y/8p9`
ej~y{Vx?
|/z'G2?
1#:0[Wj
,Q^_s_`
5Eiep4JZ
"[h;*(
@mc6SX
lmtl_k)rTGs
nJ?@YHn
u{+GqV)g
I2M|X3
_C<Pt
HTe/]3Gfo
D; `%\m
8i?PTg
O"%;i@3
=^+Y&
R'c|vA8
O':=YP
Jod7|0
nsJ\S>
!E7+&5
Kmhw--,
W01_{
6am?3^Z
h H4bN
k(f'm>
%{s"t82
D5|#H!*lG
79|zb ~*
F(w[MZ
\ahDbs
;NQis_c
s~S5x&
U(-c\l
a8If"0]
F= F9.
'DhPt=
jft]K"j
5RW7.&
vOG@k9(
(IRxZ;f9
#(Nix
69<ip1#Vc
3G.#Bc3
LKv8\v
QCH#RL
"-ZN8&
@XM`/W
%i0Y~Q
@(qYF#
w-BcW(
N~rU,9
4l7d9/
'qc>+7m
\{0W$;
#,X4+=N
`4l,!-N
K-:._d
?=O]Zi
C,w)f*|
C~2B6{
bGhK2x
i(fM$
[h`WP
geVLC;5Z
qwk1.9
CO*B#R
8Al9T8
H1B>, a-Gq]
?^bU#n
GM5[V}
P,=VoD9O
>nwI4.
X,_i(zm
(}.tyR
0igdTv
I*rW!(
S.*BGV
$>#BFP
w#(k<u
@\.,Jb
4?.pHJ
qQC6:E
;EgpYN
i9Mio@2
_gal<
<!I\t'
\5!:xK
}*PF)H
\( tod5
FFQo_*
Ypntq@LF
]#w1`ks*
P8%5H
pWX@mn
x}[{[3
x5Vj*9
!I(,n
Eb_2h9
"?V#K>
TpW(e?
=4[@g)
&NTR0Z
|lkacH
[F0psQ
/$9 ]QJ
\T-EMV
RF4kc
PrRybU
3ab4mCJ46
i2T>\Rt86uV
{bUoC"
Og;??z
~=|<"G*
?n6)bgf
*(3\2.
x>Q:aa
IFg%"H
IGf)CW
H*tADL
'$ 4Yr
ojGA6jK
iw8Wd/
fSinQP
Yb'ps!
FliXWS
X;e%z@
nRT#a<
UvG*.W
A{Fwh3J
;U3tTE=
/|~Sy
td_D=q
rw9W+<
OL%_V
k\PJr7
obi'q0_
|Ar!o9
E[FLmX
oAV<!
Z8&vK
->qWId6
c]xj*
"*&sxw
Hd]h,M
ON(@_#
x6/Yyd
+qDvl$
{zcGEY
#>>x\Eok
dAIAB
Jpagz[
Z4Q]5B
+NVgr7kW
]OIG7d
bFTtvp
y-DzC{3
.aYpiPK=
`78lvy
tG|N;/jc
6!eNdD
.a\+>4
t"+%Z'
rG?"'m
WMhgK|
Li-Ar5
?e|&*;@
W*g 3+H
"71plX
)m], &
^>!H2~.
AXV!q@9~PCF
u5p{TdS
$UcLI7:
X<xFkG8}
@@87^`
?3;|#DBb
(RH&/S
6d7d7x
efB1 &
O,Q*=Z
qqJ'r
fu#.gT2%
>0EX7/
yFy`{D
9nE5RP
ku++7q
1Z7[.P
$Ei:%DCO}
x9,SuNP=?
K4xs6)
x]rJT3
EXWW)Q
F'Lv+D){
P17%"1
t7_:#M
e+a\dH
w5g*Z6
}|Yj.9}
>C488#
xhLq?O
Vh^Np
GcE$s<
QywvH^O
'#u+LZBh0
_;;gFl
>#?N&f
Mw@EN^
^E4zRtE31.
b&;}"]
|dHmC/
r)m$1\
y%~J&%
oLHP8'
j$Ct!.
:fBGkb
q3$XW*|
+t<JO+
ZZUDyx
h~"^d$
vRg!}+5
!"@R B
bP#N,>
d]n75\S
B;% /aN
?bfI['
@$J)SF
050GaL
OzE4CS
"%=8`-
G<NDQ4
]#5=?.
FP)R8<S
Sm?f5U
QL[8"o
r/$#,en
z^f5&_P
i94a-}W
NIU6c
$VU9/+N.6
3",Yo-
,T>JWxpvp
q$N:*b
$=qx:=
<!m@*hPM
[hJMZ}[
>Lth^jrXLl
EE:2#QE
.vgcKJ
B0L/=2
vW5x5{
O&oQ{H:
:FZR7j
=gQNQf
^`.+6X
Te@W6U=
M=aVi;
NNK3uq
e4m)@l
E@Csb\H+n/{
GY6-IN/
tG6*?E
j$NxXrs
X%f5!T9
^?V+(5W
dJH*{dE
j5w(.}
g#L.xV
ttc7]yP
kVJl#:o
3V:QJ,g3C=
MT7/WPPK
DOq_ =
bEWbkKBJ
$K662c
+nxTWLE
D-<bix
ixB:S_E
QR9dc}@l
Bsbp*a
R8JEMW
=\y/Dm
{9o\P
%u@AOe
BF"bmUL
svhCai
_($zGu
yvFB|@}%>(x
LL{9>3
>$b#%1
'l}|9?
q;&b~`:
xciE#kl
r?%N'lu
gZ10"K
5$;i#j
'<d`Md%
N?V}kp
lkEV["c
9%Vs`6En
(;skwyv
XZ+e%T
|d-D'k
} AZ_[
te;L,WR
SZ3q&>p9Q
X@CQpU
$2It2C
8jB d;
x?=;0_j0
uXUy<?
P([.?t
4]2Gw_Bp^
_?J}Sg
'.2(GOu
77T{%)V
wYOm~2Z=a
(xIIHL@
jtr4Y0
6b).?Ywt
?)k|"
2]w~:K
xB$DM"
k)o3yH
W?yGo'e>Y
>IFGnIQ]\
zbI" m4
\vb!E^
)*[5&q
vSd5`8
{n2c$X
y6ngXk
N@-G2#i
t[q_lh9C
`T!&df\k
caWVAj
`u\D+&
:mBsw.
Iv}t69
3gZs2^
e:ayN;^@
V#L$ x)
!n^~2P
xGRX,uq
:0>K5O?Y
ONHe{X!
MDkST,
BajAJx/
T[D:1/
_#9!W^
dR)a5a]
GX:Iiv
ZqaN^_
)&(!kQ)
Z+!Aj6Gr
{9+}^l
QDO; 7
yhvT.p
QD</7
MIW`hnu
ruB0pRmr
\wCikJ
J {8k%Ol
"MWPTi
):a@B1
LeD>ZN
/r]Kn]m
0.C`G^
8sd$Rvtb
X^Lmk(
h`H6 H
%:E"@0L
A/V@S~
3d3)XueAU0k
;,%89]y
e}1)iK
&5U$sq +Ef
Bb}Fy{,q1-
ZR3smV
e|)i{{
AAbi|9
iq*S7'CC6
sE(js{G
K<XODK
I6~,YC<|
1>J[Cxa
X2$U{d
2Tgb||yY
qI651ewx
Z}9.oF*
?rz)4~w0
)/non~
S78Ij%Y
7i1m-O
7Y,Yj=bW"O
;&vRx:
( s5Jj
XV&(GA
Fz-qf)O
os.?GL
2xo;Wn
uT-,B1
w\M"P&
,$`cr{
zfrRRr
o1P-1[o"
>o1QX/
#"0RAN
N=?HZtX
}[$}'n
25k&"`
SIV3s*&
H?~nZR
(BL1B)4
vmB+g-YF6
]6Bd|f
2V:Wjs?Y/
m&s,I<
ERb\~O(
cm|Eak
KR[bq6
)CM=;A
#|AfQG
(E~Kyz
&{'`qb
#5%?]J1~
+8X>zR
&bDWtR
6EQ]{@W
cVzx6^
?T4M7E
|:AVWaQ?
e<+m4'3M
D0K_df
AB|I9>6
F"}_t+
Rxtoi3
O^-aZG
LTLs(O/
GJNbV%
,ak`ttW
kWjG~0
%$Uur
[yMmi#
Dr/,=
l66S=L
(Jg\?D
ya:hr/A~
yhd';%W
JgiXK*J
F*!"Nn
5I4X8R
>~hefg
UHO{J
6o4 lO
o+\>:>x
s_D(2v_
(iecmX&
tKlO6
0F8^=V
(iEX8@[
ca:5|[
e^\`)S
&$LU}n
'J?$Iit
J",1N'
be5>{:
VBo%@W
yqY#KF
JdHN)1xk
`HzBT-'*C
FX'<<1
7aG9zm
GE|;eL
|9NJ's@
`*01(#
Gv{9[
C&2*Wc
}213;4
,|4 J\
vDt[58k
z1Qt09:
K{d }Np7F
Zjh!_g
^Pw?o
g2w4]Jyq/WjrM
hL,S13tV;:
5{xAcb
z @=,h
`X@^xo
`Ni+f#
Gs0l)a
:8Ez~@
%30>%l
;_vM&j
PxXJh
h:!o8>
GTSgu)
"@@? 8
S" -(D@
Nw:Wsd
xF+XK^
|@?@zI
K&{(Zg
TG4C'(
![0R&0
Jow[k/>5
)m\r'!"
6"p]KLv
NHGI?1^
<J}#Vw
-&7V|T
10 TCr
Ga[Esu
)uBQsh
T#<>T&
@+/XJ/
D}H;};
D7'/R^<o
c"A:eo
#Wh/V=
Et1QWiA
]CJo,]]
{ctOC"9
>>Wn("pb@5
Vn$8>!SG
*#96Sv?BL
xd<V0.
rr$W/z"g
M'I?^C
$d}rGPK
?mtbQ:\5
~WIF*v:
s#E`v>
:B59^s6[
N?Llr}
"5p0RZb
+HXx c
v=U/Jr
qWDMa`
/&qVLJ
J<o?}'
h3Pm|\Qrb~
2]ojNa
=l)q%&bdK
Nu-n$)
0N^<.a
Cw(u1t)
=d!5gZ@B
`LeDIK
;M9|cp
'DIDiBv_
~#HeQOU`
4<[7gs
4<27cW
,ef"3`
W>|r,v-s
NYo:&0#z
^sDu7.
i!VZt>
{0 %@6<
f5&c4p
^jd<eW
z,0qo`?l1
2/[*]t
E%xMYK
k7&w22
{lHHWg
zbp7dp
`L0kis1
FvI'*
Antivirus Signature
Bkav W64.AIDetectMalware
Lionic Trojan.Win32.VMProtect.4!c
Elastic malicious (high confidence)
ClamAV Clean
CMC Clean
CAT-QuickHeal Trojan.Agent
Skyhigh BehavesLike.Win64.Kryptik.wc
ALYac Clean
Cylance Unsafe
Zillya Clean
Sangfor Clean
CrowdStrike win/malicious_confidence_90% (W)
Alibaba Clean
K7GW Trojan ( 005aea641 )
K7AntiVirus Trojan ( 005aea641 )
huorong Clean
Baidu Clean
VirIT Clean
Paloalto generic.ml
Symantec ML.Attribute.HighConfidence
tehtris Clean
ESET-NOD32 a variant of Win64/Packed.VMProtect.QF
APEX Malicious
Avast Win64:MalwareX-gen [Trj]
Cynet Malicious (score: 100)
Kaspersky Trojan.Win32.Agent.xbwwas
BitDefender Trojan.GenericKD.75955174
NANO-Antivirus Clean
ViRobot Clean
MicroWorld-eScan Trojan.GenericKD.75955174
Tencent Win32.Trojan.Agent.Ljgl
Sophos Mal/Generic-S
F-Secure Heuristic.HEUR/AGEN.1374859
DrWeb Trojan.BankBot.663
VIPRE Clean
TrendMicro Clean
McAfeeD Real Protect-LS!DCDE423F70CE
Trapmine Clean
CTX exe.trojan.vmprotect
Emsisoft Trojan.GenericKD.75955174 (B)
Ikarus PUA.VMProtect
FireEye Trojan.GenericKD.75955174
Jiangmin Clean
Webroot Clean
Varist W64/ABTrojan.EONJ-2893
Avira HEUR/AGEN.1374859
Fortinet Riskware/Application
Antiy-AVL Trojan[Packed]/Win64.VMProtect
Kingsoft Win32.Trojan.Agent.xbwwas
Gridinsoft Trojan.Heur!.02212023
Xcitium Clean
Arcabit Trojan.Generic.D486FBE6
SUPERAntiSpyware Clean
Microsoft Trojan:Win64/Reflo!rfn
Google Detected
AhnLab-V3 Trojan/Win.MalwareX-gen.R693121
Acronis Clean
McAfee Artemis!DCDE423F70CE
TACHYON Clean
VBA32 Clean
Malwarebytes Malware.AI.2291236743
Panda Trj/Chgt.AD
Zoner Clean
TrendMicro-HouseCall Clean
Rising Trojan.Kryptik@AI.88 (RDML:LaJg31nfqkILRMDXdmGX1Q)
Yandex Clean
SentinelOne Static AI - Suspicious PE
MaxSecure Trojan.Malware.300983.susgen
GData Win32.Backdoor.Rozena.D7VA60
AVG Win64:MalwareX-gen [Trj]
DeepInstinct MALICIOUS
alibabacloud Trojan:Win/Packed.VMProtect.AW
No IRMA results available.