Static | ZeroBOX

PE Compile Time

2025-03-22 00:24:47

PE Imphash

d743740f06aa0a325bb5c948f63319ce

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x000bbe30 0x000bc000 5.95452285203
.rdata 0x000bd000 0x00009954 0x00009a00 4.81365631961
.data 0x000c7000 0x00001ff0 0x00000c00 2.45124487394
.pdata 0x000c9000 0x000013ec 0x00001400 5.56035892468
.gxfg 0x000cb000 0x00001120 0x00001200 4.90393141539
.retplne 0x000cd000 0x0000008c 0x00000200 1.05058324797
_RDATA 0x000ce000 0x000001f4 0x00000200 4.16913312541
.reloc 0x000cf000 0x00000668 0x00000800 4.92891981294
.idata 0x000d0000 0x00057800 0x00057800 7.9994662489

Imports

Library KERNEL32.dll:
0x1400c4f18 CloseHandle
0x1400c4f20 CompareStringW
0x1400c4f28 CreateFileA
0x1400c4f30 CreateFileW
0x1400c4f38 DeleteCriticalSection
0x1400c4f40 EncodePointer
0x1400c4f48 EnterCriticalSection
0x1400c4f50 ExitProcess
0x1400c4f58 FindClose
0x1400c4f60 FindFirstFileExW
0x1400c4f68 FindNextFileW
0x1400c4f70 FlsAlloc
0x1400c4f78 FlsFree
0x1400c4f80 FlsGetValue
0x1400c4f88 FlsSetValue
0x1400c4f90 FlushFileBuffers
0x1400c4f98 FreeEnvironmentStringsW
0x1400c4fa0 FreeLibrary
0x1400c4fa8 GetACP
0x1400c4fb0 GetCPInfo
0x1400c4fb8 GetCommandLineA
0x1400c4fc0 GetCommandLineW
0x1400c4fc8 GetConsoleMode
0x1400c4fd0 GetConsoleOutputCP
0x1400c4fd8 GetCurrentProcess
0x1400c4fe0 GetCurrentProcessId
0x1400c4fe8 GetCurrentThreadId
0x1400c4ff0 GetEnvironmentStringsW
0x1400c4ff8 GetFileSize
0x1400c5000 GetFileType
0x1400c5008 GetLastError
0x1400c5010 GetModuleFileNameW
0x1400c5018 GetModuleHandleExW
0x1400c5020 GetModuleHandleW
0x1400c5028 GetOEMCP
0x1400c5030 GetProcAddress
0x1400c5038 GetProcessHeap
0x1400c5040 GetStartupInfoW
0x1400c5048 GetStdHandle
0x1400c5050 GetStringTypeW
0x1400c5058 GetSystemTimeAsFileTime
0x1400c5060 HeapAlloc
0x1400c5068 HeapFree
0x1400c5070 HeapReAlloc
0x1400c5078 HeapSize
0x1400c5088 InitializeSListHead
0x1400c5090 IsDebuggerPresent
0x1400c50a0 IsValidCodePage
0x1400c50a8 LCMapStringW
0x1400c50b0 LeaveCriticalSection
0x1400c50b8 LoadLibraryExW
0x1400c50c0 MultiByteToWideChar
0x1400c50c8 QueryPerformanceCounter
0x1400c50d0 RaiseException
0x1400c50d8 ReadFile
0x1400c50e0 RtlCaptureContext
0x1400c50e8 RtlLookupFunctionEntry
0x1400c50f0 RtlPcToFileHeader
0x1400c50f8 RtlUnwindEx
0x1400c5100 RtlVirtualUnwind
0x1400c5108 SetEnvironmentVariableW
0x1400c5110 SetFilePointerEx
0x1400c5118 SetLastError
0x1400c5120 SetStdHandle
0x1400c5130 TerminateProcess
0x1400c5138 TlsAlloc
0x1400c5140 TlsFree
0x1400c5148 TlsGetValue
0x1400c5150 TlsSetValue
0x1400c5158 UnhandledExceptionFilter
0x1400c5160 WideCharToMultiByte
0x1400c5168 WriteConsoleW
0x1400c5170 WriteFile

!This program cannot be run in DOS mode.$
`.rdata
@.data
.pdata
@.gxfg
@.retplne
_RDATA
@.reloc
B.idata
AWAVAUATVWUSH
D$d-X${
D$d-}6
D$d-/{e
D$d-[J
D$d-O}a1
D$d-`f
CO-7w
T$|iT$|
L$|iL$|
L$liL$l
@"b#A!
@"b#A!
?ol|A!
?ol|A!
[]_^A\A]A^A_
UAWAVAUATVWSH
[_^A\A]A^A_]
UAWAVAUATVWSH
3Hcv<H
[_^A\A]A^A_]
rskgD)
3Hcv<H
UAVVWSH
[_^A^]
UAVVWSH
[_^A^]
UAWAVAUATVWSH
0=YqA)
[_^A\A]A^A_]
UAWAVAUATVWSH
[_^A\A]A^A_]
AWAVAUATVWUSH
[]_^A\A]A^A_
UAWAVAUATVWSH
q@-@Rz=
[_^A\A]A^A_]
AWAVAUATVWUSH
H[]_^A\A]A^A_
K8eyD)
UAWAVAUATVWSH
[_^A\A]A^A_]
UAWAVAUATVWSH
[_^A\A]A^A_]
UAWAVAUATVWSH
-v$/yA
[_^A\A]A^A_]
AWAVVWUSH
8[]_^A^A_
AWAVAUATVWUSH
D$ -6b*
D$ -6,H#
D$$6,H#
X[]_^A\A]A^A_
D$$6b*
UAWAVAUATVWSH
6yVdE)
[_^A\A]A^A_]
UAWAVAUATVWSH
[_^A\A]A^A_]
UAWAVAUATVWSH
[_^A\A]A^A_]
UAWAVAUATVWSH
[_^A\A]A^A_]
UAWAVAUATVWSH
\u1zA)
[_^A\A]A^A_]
UAWAVAUATVWSH
e([_^A\A]A^A_]
-ey:j-
UAWAVAUATVWSH
[_^A\A]A^A_]
AWAVAUATVWUSH
D$@-G@
D$@-YG
D$@-s8Si
[]_^A\A]A^A_
UAWAVAUATVWSH
-g:#@A
[_^A\A]A^A_]
UAWAVAUATVWSH
[_^A\A]A^A_]
UAWAVAUATVWSH
[_^A\A]A^A_]
UAWAVAUATVWSH
EL-h`E
EL-a6i
EL-x-|0
EL-}QKa
[_^A\A]A^A_]
UAWAVAUATVWSH
e([_^A\A]A^A_]
UAWAVAUATVWSH
e8[_^A\A]A^A_]
UAWAVAUATVWSH
[_^A\A]A^A_]
UAWAVAUATVWSH
[_^A\A]A^A_]
UAWAVAUATVWSH
[_^A\A]A^A_]
AWAVAUATVWUSH
D$<-="
D$<-R(-J
D$<-u /h
D$Lu /hH
D$Lu /hH
[]_^A\A]A^A_
AWAVAUATVWUSH
D$4-X{Rd
x[]_^A\A]A^A_
AWAVAUATVWUSH
D$D-Ys
X[]_^A\A]A^A_
UAWAVAUATVWSH
OVZrL!
+CZXL!
[_^A\A]A^A_]
^_{],*
mA @M)
AWAVAUATVWUSH
D$D-cS
D$D-c6
D$D-p~
D$D-G>sb
D$D-2x"t
x[]_^A\A]A^A_
UAWAVAUATVWSH
>P{v\M
{f*LHM!
[_^A\A]A^A_]
UAWAVAUATVWSH
-0.[=-
UAWAVAUATVWSH
e([_^A\A]A^A_]
UAWAVAUATVWSH
[_^A\A]A^A_]
D$4X68=
D$0-X68=
AWAVAUATVWUSH
D$4-M4
D$4-zk!X
D$4-r/
h[]_^A\A]A^A_
D$0-&mrr
AWAVAUATVWUSH
x[]_^A\A]A^A_
UAWAVAUATVWSH
[_^A\A]A^A_]
u/HcH<H
WATAUAVAWH
A_A^A]A\_
VWATAVAWH
A_A^A\_^
WATAUAVAWH
A_A^A]A\_
H;xXu5
u3HcH<H
UVWAVAWH
0A_A^_^]
WATAUAVAWH
A_A^A]A\_
WAVAWH
A_A^_
WAVAWH
A_A^_
p0R^G'
p*W4H
p*W4H
D$0@8{
LcA<E3
SVWATAUAVAWH
0A_A^A]A\_^[
@SVWATAUAVAWH
L!|$(L!
D$0HcH
pA_A^A]A\_^[
B(I9A(u
t$ WATAUAVAWH
A_A^A]A\_
AUAVAWH
u4I9}(
;I9}(tiH
0A_A^A]
@USVWATAUAVAWH
A_A^A]A\_^[]
UVWATAUAVAWH
`A_A^A]A\_^]
UVWATAUAVAWH
A_A^A]A\_^]
p0R^G'
WATAUAVAWH
A_A^A]A\_
fD9t$b
l$ VWATAVAWH
L$&8\$&t,8Y
A_A^A\_^
t$ WATAUAVAWH
D!|$xA
A_A^A]A\_
L$ VWAVH
@UATAUAVAWH
e0A_A^A]A\]
UVWATAUAVAWH
PA_A^A]A\_^]
u$D8r(t
D81uUL9r
uED8r(t
vAD8s(t
u$D8r(t
fD91uTL9r
uED8r(t
v@D8s(t
WATAUAVAWH
0A_A^A]A\_
H9>u+A
@USVWATAUAVH
D8t$ht
D8t$ht
A^A]A\_^[]
f9)u4H9j
u%@8j(t
UVWATAUAVAWH
xWI96tRI
0A_A^A]A\_^]
WATAUAVAWH
A_A^A]A\_
vyfffff
vyfffff
WAVAWH
A_A^_
@UATAUAVAWH
A_A^A]A\]
@USVWATAUAVAWH
H!D$ H
xA_A^A]A\_^[]
VATAUAVAWH
0A_A^A]A\^
UVWATAUAVAWH
fB9<I}1L
A_A^A]A\_^]
VWATAVAW
A_A^A\_^
ATAUAVH
L$ fff
L$ |+L;
A^A]A\
x UAVAWH
fD94H}aD
fffffff
fffffff
WATAUAVAWH
0A_A^A]A\_
@USVWATAUAVAWH
eHA_A^A]A\_^[]
@SUVWATAVAWH
@A_A^A\_^][
ffffff
fffffff
USVWAVH
A^_^[]
fffffff
fffffff
fffffff
ffffff
vKfffff
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
UUUUUU
UUUUUU
=imb;D
/>58d%
VM>cQ6
>jtm}S
)>6{1n
+f)>0'
;H9>&X
*StO9>T
n03>Pu
K~Je#>!
bp(=>?g
BC?>6t9^
K&>.yC
.xJ>Hf
y\PD>!
|b=})>
c [1>H'
uzKs@>
3>N;kU
kE>fvw
V6E>`"(5
?UUUUUU
?7zQ6$
Unknown exception
bad array new length
string too long
C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe
.idata
Sunday
Monday
Friday
August
__eabi
new[]
dddd, MMMM dd, yyyy
MM/dd/yy
February
January
Thursday
Tuesday
Wednesday
Saturday
InitializeCriticalSectionEx
LCMapStringEx
CompareStringEx
operator co_await
__restrict
CorExitProcess
HH:mm:ss
operator
October
November
September
December
bad exception
bad allocation
__fastcall
__thiscall
__vectorcall
__clrcall
__stdcall
__cdecl
__pascal
FlsSetValue
FlsGetValue
delete
FlsFree
AppPolicyGetProcessTerminationMethod
__unaligned
FlsAlloc
delete[]
AreFileApisANSI
LocaleNameToLCID
operator<=>
__ptr64
__swift_3
__swift_2
__swift_1
restrict(
__based(
Base Class Descriptor at (
Base Class Array'
Class Hierarchy Descriptor'
Type Descriptor'
`vector deleting destructor'
`scalar deleting destructor'
`vbase destructor'
`vector copy constructor iterator'
`eh vector copy constructor iterator'
`managed vector copy constructor iterator'
`vector vbase copy constructor iterator'
`eh vector vbase copy constructor iterator'
`vector constructor iterator'
`eh vector constructor iterator'
`managed vector constructor iterator'
`vector vbase constructor iterator'
`eh vector vbase constructor iterator'
`vector destructor iterator'
`eh vector destructor iterator'
`managed vector destructor iterator'
Complete Object Locator'
`virtual displacement map'
`vcall'
`string'
`udt returning'
`omni callsig'
`typeof'
`copy constructor closure'
`default constructor closure'
`local vftable constructor closure'
`placement delete closure'
`placement delete[] closure'
`vftable'
`local vftable'
`vbtable'
`anonymous namespace'
`local static thread guard'
`local static guard'
`dynamic atexit destructor for '
`dynamic initializer for '
operator ""
CloseHandle
CompareStringW
CreateFileA
CreateFileW
DeleteCriticalSection
EncodePointer
EnterCriticalSection
ExitProcess
FindClose
FindFirstFileExW
FindNextFileW
FlsAlloc
FlsFree
FlsGetValue
FlsSetValue
FlushFileBuffers
FreeEnvironmentStringsW
FreeLibrary
GetACP
GetCPInfo
GetCommandLineA
GetCommandLineW
GetConsoleMode
GetConsoleOutputCP
GetCurrentProcess
GetCurrentProcessId
GetCurrentThreadId
GetEnvironmentStringsW
GetFileSize
GetFileType
GetLastError
GetModuleFileNameW
GetModuleHandleExW
GetModuleHandleW
GetOEMCP
GetProcAddress
GetProcessHeap
GetStartupInfoW
GetStdHandle
GetStringTypeW
GetSystemTimeAsFileTime
HeapAlloc
HeapFree
HeapReAlloc
HeapSize
InitializeCriticalSectionAndSpinCount
InitializeSListHead
IsDebuggerPresent
IsProcessorFeaturePresent
IsValidCodePage
LCMapStringW
LeaveCriticalSection
LoadLibraryExW
MultiByteToWideChar
QueryPerformanceCounter
RaiseException
ReadFile
RtlCaptureContext
RtlLookupFunctionEntry
RtlPcToFileHeader
RtlUnwindEx
RtlVirtualUnwind
SetEnvironmentVariableW
SetFilePointerEx
SetLastError
SetStdHandle
SetUnhandledExceptionFilter
TerminateProcess
TlsAlloc
TlsFree
TlsGetValue
TlsSetValue
UnhandledExceptionFilter
WideCharToMultiByte
WriteConsoleW
WriteFile
KERNEL32.dll
.?AVbad_array_new_length@std@@
.?AVbad_alloc@std@@
.?AVexception@std@@
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
.?AVlogic_error@std@@
.?AVlength_error@std@@
.?AVbad_exception@std@@
.?AVtype_info@@
p0R^G'
p0R^G'
p0R^G'
p*W4H
p*W4H
p0R^G'
p0R^G'
pB]P67
p0R^G'
p0R^G'
p@\xV.
p0R^G'
p0R^G'
p0R^G'
p0R^G'
p0R^G'
RetpolineV1
RetpolineV1
RetpolineV1
RetpolineV1
S3bO8=#
&vYk3;
&{+Jg)
M<OR`^
RK>y?=
cNcj0;_;|
p17s$f}"
{oZLi5
l]Vh;<
|_E%;(p
qIc]Q2
GjOFoE_
o0{rv"
|e9l(Y
jw;XB9:
&q0!Wi
:`sz'R
#\f|c
$y7:'B
+UQ%=b)
JI:Ph0
tW(7XC|;81
j;Gn) U
>{Z`>q
w0&I!>7
#fK;7I[
+"`2uO
@>3hZ3
Q`:U4R\
|9NkUy
%roKv
KDzy_"
c&]Zu~
/ZKAlx/G
BsU)y]$
-VZTK_
3$*j6>
u^F@4~
+5F<,.
aoZ!B7p
T}sO\d
h;%u^f
DGxnJW
Kn@U<J
bj=^X{/=
9)D(}n
6,6$]l
4-sb[:D
zoyjnC
3>g!Rf
t~A92<c
w!TUyB
A_*H4c
G,Qce_z
~ =URv
Ma@(30S
n$c`xr~
~Wm"r[
sJq;U5
dm?7<
d^cp?&
3TSe5;
r}lj&7
zm0m5.S
WsV"R}v
|=75B|
y,W<VAI
0pPB$3
SHVV9[E
v&ao@i
5QG)qB
fc;YT
Z 5+D`
v|9fuSA
kW2@LTY
R@kXXwW
~H?J:"I
'E6}f-m
>W+0Mo
eupZ,q
C)$^F)
PvwuI,0
d*nGQP
$OTAQpa
XBUz1
wC2CMM
rsaA|hU
9DqQf{n
~hppr2
!4d>%a;
?r~fy
oJEtTM
k>y.,.
9-oMsk!
YHh-"8
5[:iBov
YjB[du
xK(TT~
{W y9a
!vCYC?
s/T z9
[C=#In
Z0xb.g
DYDB'7E
vE_Dfz
8,:\aN
1QoJ>[
/hR{SC
K\)tg[
yS(j'i78
IMe1SD7
,,_p~.
a1PqS1F;
*pJR6>I
pWf4:7
5[dL"*
)w5S7N
w5cX#u
ExNq<;A
s$LZh:
[[Ya!Y3
oSz)&mZ
DagtGB
:l-3US
K(,j%P
'I_bv$
?l[<Ip
O14bGvz
29YKK<a
l08V-I
%w3W%z
"^^0d%
2zz0|z
"eB/{)
c!X1)So
NH.ZHzFLj
KG6lTx
O"5oZn
AoLnEt
K>$GF4
>D *,zM
>(`2w8
mb;hQd
K3U[vK
U~.]qM>A
WSWxnBd$/t
wl 6O
{W*{{B
z\PbB{
9nG*GMh
s@VGwjW
[x^,?M'ay
^spI%~
F21e7pABl
4me}7j
;<:Qx$
%f(HxT
%N\=9U
Q6W`\3=
^sbEbv
o]Sd[U
>wEid7K
RJg|m84
*?pLY~
5T*abe
gkK%Z;#
x9-)D{p
nv2z&=
}Z5lk#
&PP\,A
U"s Ps}kr
zr"~Q~
2+oT^7
%^Es,n
Uz<s(8
q%OXQZ
]!.qPTF
/)&fPVU
A\$>FN
zLwGRk
_q2@:Pw
G26dB`
R/!YB!
L!*}Gm
v&'8Ua
r%evRQf*P
F"nPF2I
"hdk`|Tu3|
RF&wwG
]4&~MI
!8f;Vc
JSB:M5
.Yz(KUc
Q=#0-1
(up"s
r/L%tM
z"3PdcO
p#X]HEZJoB
(yvX"
JznxYF
g8`O/[2
^y^(*TE
'0~EDC
zKIPd~@
\"l4UU
86~?TW
8Qg`/@
6W+dhDy
}o:uN'
&9P6Bt
^L\j (
dVj e0
h(BA<]
z ~eeuWE
;Q>92
`LI\5D`y6
,S:sVQ
9:!01
u`5HASo
KNrf}S
/g|^RQ
=G,C^CEH$
O,12`G
sCikh9
loAIEkS
/)o3-t
g^]HGx
u|;|G`
tSs`ZZ
GNFq}?>4
Dg>35>tv
"mDZ7^9
~G"`d*V
#NSr06
Z6-G'oz
0{*tBhg
G.aU|Z
a;D@FN
JKj#8Z
PjFxd9
8iX_\6
4(NH8(z
\1[qaZ
j9(1w*2B
NY*J6[
{ kCzs
Xc_5o-
^A'f50
%X<{;P
!3C\}\
871.en=
wfVf'z
b7|E@7@H
9xK}7z#
;\O=M?c
ECw1A,
/1*Zjx
DYS50
[?@;HJ
`/*qpN
q*Bf_#
$H3An@
f3(<21
)XflS/
_x}<=K
X)-'n?[
QB5tz$
oK`,;e
u[KMm*
^2D2j{
A)+e6%j
vb+D{o
spfk64
80Ec~!FRe
D#{P9V
+/v%tr
nuNtYX'
vd]A4A
R\+x3H0
WIdV_s
h{6)w8
F u'O$
t}{1m*
Q*dGpF0Q#
a}(hr6W
'7/{Rt>-
modA~&
"-l}%f
?SsDAvc
"+Fl_xQ
!9p/%]
1<&*wf
P*_Z<x
mL>IEc
c4v*i9
drBK&/
=j./n]
:qKQ]c8
.H@9<9
-]t r:
CI2BoD
}|sT#$$k
Q]j|W)
4N$> z!
Ak<Hy!e
)z5K95
\h]lgc
zW)0'#:(
Ne`Fbe
Wr)zTQ
(SSXq
$#semE
fxVem7
'&B;:y*
dA3c.b
(|''e{@
:_Gb{t
pbW9)_
;9~?m]
1rKdYQ
gpK2==
cR)y(`+z
}#Hal?
+1:d=W
rEL"FP
k': lIF`r/
hi\Qy9
!tGRDo
$<]{5m^
D4fwhqaz
4Nt{/Y
w{t4H!
S]0{>pD
9n{d^t
NapdRX
k*q{b8})
}wBn@U
+<ApdfY
!~,d~Z*f
SzzrVu)
^J2Tfx
yEDL&nw
r5'PPK
1O.l'Cpk
qIfRpZ04p
Nw6P4l
LHw6H/
*gyv]}
6*PXP\
?}v9$f
cmP6AsC^sw
'[HD`&
ctd%jo
EA\JPW;
$>G32pD
4OT9YxN
"vu[IM
o'Hx8#
7~Lev7N
}dlS}-
pMC,;C.
}uR<lH
"3gq$>
/V}h?MD
0C+d,;
sQEBl~
(t=lH$
f`Bmt!
HZ$*/!i
0V{^A!
9a9O!x
^\>E;6
DeR CzI<x
$2Kgj0
>jp_c_
X9yV88]
L]Q^s!
-saAm#
+|P:/O
n=b%<[
f2~gUw
j8|56UHx
<R=mXt
4mKv!v(n
wnskr5
TJaj3H`
JZZV~1h
.h?CE55
{xh3"8
05^xz-
W"J_EZ0m
;-`r,V
if_J"#D
qz"4 VU
~Vq<Vvc
#`;v3m
/x,8KT
d8c:Vt
9_Nd2DA
-uQRU|>
%]=<>3
D`R:GE
>|]PgE
mz!q7D
fklJ+^
Xud^"r
E,o8pZj
J)" $T
UJ!gX8A
OO-9%+
v}`DO+r
myTd&
`)SQD4
{cGP\K
fI^I_n
iC.OlT=
4BO8d_
qv>5!LD
|H%=*87
Q}M'S>
#g7G.[
G{Ri[1
~NOS|=d
XCiv'R/
3O0,9e
G\ihgK
ms[En}r
2ia#u
Fiv|pM
+}Bq-`
E|X}>\[d
ivRXn0
P%z5t7n=
bN1*^H
-iIui""M
m%>dZ3y
upX5!S
-f-6*D|
%I_.@6!
e.;.My
; VLbS>
W$hS2h
BRYbGk
Ai_d3P
:YTF}2
#,7FO6
jSZR*e;H1E
K1WjC|
FQKs*m@cI
U-Ry%7
>(l`<|n
iA&Tl7.q
e&O\`<
4Z^IY~
<!)PX0p
Chs)nb
!RHeV=X
+4:fS/@u
2Qha^7v
10;'g
{:MsF)
CVJ9n?
;Z&e<R
dS%js
4,4D:H
Q;3P)7
pqj\FE
(]uOXr
'"#@CN
rEpyj!\G
Pg$iW}A(
^ `_tI5c
6w]gcB
KDo;eB
b0NCzY
Qm@ERA
ZOW|m:
z;|!9>
o}!,\)
A-+!Aj
LB:_=
0rXc~U
~s';9F
MT$eNZ
g|g~H#1
;Fl^_)
>:NS;`2
thi[R
^X>j?fx+0
Pf0qRT
y!t$}>
bY"zujS9
_`S U>
S;ee;d
/*)?L^|$!zG
N3DhhF
:bzyq
A8sc^
z(njFK
xmu2i0E
=Z0z*<~,
tEl#3t
La)e~!
xUj7,c
u+BCSaV
U\cRg,
k)?'q?($
EmT'L*
9PI}8:
:[PHuf
4K1Wqb
kj>0:&
<-|tTN(
h=;Nm=
oo{!dj
\`ioO^;
WCYH:j\
cc*[1o
ExhcZeMn`
Ha1=f3O
g=aoI>
Ru}gj)
?RSoSJc%
tE7E=^
e4j35t
[k2Xh,1
8Q4A&w6
^%S1ix
&>t0OH
~AF2Z
@n}+uW
+qx&AA
9E5Tu!F
<#cTn.xL
CVsgB;-
y* Cg?
5%/Wx{&
~#$ufBd
xHx?*;
VSq_{V
%$5}",*uX+i
Np@q5{~
~8{S0p!
>!+wRG"
Jp[H&Z
'fjbb0,|D
E)e_6G
G{NH9
W$ZPGA
O) -iAe
zYUt-6
#Lejba
,Cn]5y
1+Fk!
g5j\1`
bm4H_o^
S%xT%9r
P}yYCHS
-T]Sw:
dC{G-
KpvK??*l
[HihI{
!EFxpy
w2\?2CN
J K<q`
lm*)V\
ZfG1[e
0}9+`t}
L@\!6((2
\UR3?b
|Y(ZG,
K0]&G=
o0F60j|
O>big2
%hjF@^
W4;(Wu
rSItA&
TO{&Fa
A88'FuP
U=H?09o
76Dft-%
9zLAYW
Xv6=Rb
kla-G#I6nX
6*'Vea%
S"H_(Sq
G8;VKi
=T\U*Y&v
A]W[y6
\%1vr10j
'ed!K?
DigiCert Inc1
www.digicert.com1!0
DigiCert Trusted Root G40
210429000000Z
360428235959Z0i1
DigiCert, Inc.1A0?
8DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA10
[K]taM?
SA|X=G
http://ocsp.digicert.com0A
5http://cacerts.digicert.com/DigiCertTrustedRootG4.crt0C
2http://crl3.digicert.com/DigiCertTrustedRootG4.crl0
jj@0HK4
DigiCert, Inc.1A0?
8DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA10
230113000000Z
260116235959Z0
California1
Santa Clara1
NVIDIA Corporation1
NVIDIA Corporation0
Aoi0Ka
Mhttp://crl3.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crl0S
Mhttp://crl4.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crl0>
http://www.digicert.com/CPS0
http://ocsp.digicert.com0\
Phttp://cacerts.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crt0
DigiCert, Inc.1A0?
8DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1
joS&;J
20231102033749Z0
Ontario1
Ottawa1
Entrust, Inc.1+0)
"Entrust Timestamp Authority - TSA1
Entrust.net1@0>
7www.entrust.net/CPS_2048 incorp. by ref. (limits liab.)1%0#
(c) 1999 Entrust.net Limited1301
*Entrust.net Certification Authority (2048)0
991224175051Z
290724141512Z0
Entrust.net1@0>
7www.entrust.net/CPS_2048 incorp. by ref. (limits liab.)1%0#
(c) 1999 Entrust.net Limited1301
*Entrust.net Certification Authority (2048)0
Entrust.net1@0>
7www.entrust.net/CPS_2048 incorp. by ref. (limits liab.)1%0#
(c) 1999 Entrust.net Limited1301
*Entrust.net Certification Authority (2048)0
150722190254Z
290622193254Z0
Entrust, Inc.1(0&
See www.entrust.net/legal-terms1907
0(c) 2015 Entrust, Inc. - for authorized use only1&0$
Entrust Timestamping CA - TS10
T=A^C_(F
http://www.entrust.net/rpa03
http://ocsp.entrust.net02
!http://crl.entrust.net/2048ca.crl0
Entrust, Inc.1(0&
See www.entrust.net/legal-terms1907
0(c) 2015 Entrust, Inc. - for authorized use only1&0$
Entrust Timestamping CA - TS10
221004172103Z
290101000000Z0u1
Ontario1
Ottawa1
Entrust, Inc.1+0)
"Entrust Timestamp Authority - TSA10
_Xg>gX
http://ocsp.entrust.net03
'http://aia.entrust.net/ts1-chain256.cer01
http://crl.entrust.net/ts1ca.crl0
https://www.entrust.net/rpa0
Entrust, Inc.1(0&
See www.entrust.net/legal-terms1907
0(c) 2015 Entrust, Inc. - for authorized use only1&0$
Entrust Timestamping CA - TS1
231102033749Z0)
Entrust, Inc.1(0&
See www.entrust.net/legal-terms1907
0(c) 2015 Entrust, Inc. - for authorized use only1&0$
Entrust Timestamping CA - TS1
((((( H
aKERNEL32.DLL
dddd, MMMM dd, yyyy
MM/dd/yy
syr-sy
February
January
Thursday
Tuesday
Wednesday
Saturday
Sunday
Monday
Friday
div-mv
August
zh-cht
HH:mm:ss
zh-chs
October
November
September
December
smj-no
sma-no
quz-bo
uz-uz-latn
az-az-latn
sr-sp-latn
bs-ba-latn
sr-ba-latn
uz-UZ-Latn
az-AZ-Latn
sr-SP-Latn
bs-BA-Latn
sr-BA-Latn
kok-in
uz-uz-cyrl
az-az-cyrl
sr-sp-cyrl
sr-ba-cyrl
uz-UZ-Cyrl
az-AZ-Cyrl
sr-SP-Cyrl
sr-BA-Cyrl
mscoree.dll
sms-fi
smn-fi
kernelbase
smj-se
sma-se
quz-pe
quz-ec
syr-SY
div-MV
zh-CHT
zh-CHS
smj-NO
sma-NO
quz-BO
kok-IN
sms-FI
smn-FI
smj-SE
sma-SE
quz-PE
quz-EC
api-ms-win-core-file-l1-2-4
user32
kernel32
advapi32
api-ms-win-core-file-l1-2-2
api-ms-win-core-sysinfo-l1-2-1
api-ms-win-core-fibers-l1-1-1
api-ms-win-core-synch-l1-2-0
api-ms-win-core-xstate-l2-1-0
api-ms-win-core-winrt-l1-1-0
api-ms-win-core-string-l1-1-0
ext-ms-
api-ms-
CONOUT$
api-ms-win-core-processthreads-l1-1-2
api-ms-win-appmodel-runtime-l1-1-2
api-ms-win-core-localization-l1-2-1
api-ms-win-core-datetime-l1-1-1
api-ms-win-core-localization-obsolete-l1-2-0
ext-ms-win-ntuser-dialogbox-l1-1-0
api-ms-win-rtcore-ntuser-window-l1-1-0
api-ms-win-security-systemfunctions-l1-1-0
ext-ms-win-ntuser-windowstation-l1-1-0
Antivirus Signature
Bkav W64.AIDetectMalware
Lionic Trojan.Win32.InjectorNetT.4!c
Elastic malicious (high confidence)
ClamAV Clean
CMC Clean
CAT-QuickHeal Trojan.Ghanarava.1742894699f3bc3b
Skyhigh BehavesLike.Win64.Trojan.th
ALYac Gen:Variant.Midie.162967
Cylance Unsafe
Zillya Clean
Sangfor Trojan.Win32.Kryptik.Vp5p
CrowdStrike win/malicious_confidence_100% (W)
Alibaba Trojan:Win64/GenKryptik.4470e0b6
K7GW Trojan ( 005c39d71 )
K7AntiVirus Trojan ( 005c39d71 )
huorong Clean
Baidu Clean
VirIT Trojan.Win64.Genus.HWR
Paloalto generic.ml
Symantec Trojan Horse
tehtris Clean
ESET-NOD32 a variant of Win64/Injector.WR
APEX Malicious
Avast Win64:CrypterX-gen [Trj]
Cynet Malicious (score: 100)
Kaspersky Trojan.Win32.InjectorNetT.mb
BitDefender Gen:Variant.Midie.162967
NANO-Antivirus Clean
ViRobot Clean
MicroWorld-eScan Gen:Variant.Midie.162967
Tencent Malware.Win32.Gencirc.10c351d5
Sophos Mal/Generic-S
F-Secure Trojan.TR/Crypt.Agent.gpyoa
DrWeb Clean
VIPRE Gen:Variant.Midie.162967
TrendMicro Clean
McAfeeD ti!41B06A71F35F
Trapmine Clean
CTX exe.trojan.crypt
Emsisoft Gen:Variant.Midie.162967 (B)
Ikarus Trojan.Crypt.Agent
FireEye Generic.mg.e3f8c373ee1990ee
Jiangmin Clean
Webroot Win.Trojan.Gen
Varist W64/ABTrojan.GKHD-0448
Avira TR/Crypt.Agent.gpyoa
Fortinet W64/GenKryptik.HHHH!tr
Antiy-AVL Trojan/Win64.GenKryptik
Kingsoft Clean
Gridinsoft Ransom.Win64.Wacatac.oa!s1
Xcitium Clean
Arcabit Trojan.Midie.D27C97
SUPERAntiSpyware Clean
ZoneAlarm Clean
Microsoft Clean
Google Detected
AhnLab-V3 Trojan/Win.Zusy.R696935
Acronis Clean
McAfee Artemis!E3F8C373EE19
TACHYON Clean
VBA32 TrojanPSW.Lumma
Malwarebytes Crypt.Trojan.MSIL.DDS
Panda Trj/Chgt.AD
Zoner Clean
TrendMicro-HouseCall Trojan.Win32.VSX.PE04C9V
Rising Trojan.Kryptik!8.8 (CLOUD)
Yandex Clean
SentinelOne Clean
MaxSecure Trojan.Malware.218555844.susgen
GData Gen:Variant.Midie.162967
AVG Win64:CrypterX-gen [Trj]
DeepInstinct MALICIOUS
alibabacloud Trojan:Win/InjectorNetT.mh
No IRMA results available.