Static | ZeroBOX

PE Compile Time

2025-03-28 01:17:44

PE Imphash

8beb5ca1ff83475ee16fa1a921765aab

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x00048365 0x00048400 6.39528897167
.rdata 0x0004a000 0x0000a57c 0x0000a600 5.01727861994
.data 0x00055000 0x00002138 0x00000c00 2.25041566706
.pdata 0x00058000 0x0000156c 0x00001600 5.46394458578
.gxfg 0x0005a000 0x000013d0 0x00001400 5.09495714681
.retplne 0x0005c000 0x0000008c 0x00000200 1.05058324797
_RDATA 0x0005d000 0x000001f4 0x00000200 4.2301823387
.reloc 0x0005e000 0x00000688 0x00000800 4.98269098603
.cSs 0x0005f000 0x00058800 0x00058800 7.99953532367

Imports

Library KERNEL32.dll:
0x140052ad8 CloseHandle
0x140052ae0 CreateFileA
0x140052ae8 CreateFileW
0x140052af0 DeleteCriticalSection
0x140052af8 EncodePointer
0x140052b00 EnterCriticalSection
0x140052b08 ExitProcess
0x140052b10 FindClose
0x140052b18 FindFirstFileExW
0x140052b20 FindNextFileW
0x140052b28 FlsAlloc
0x140052b30 FlsFree
0x140052b38 FlsGetValue
0x140052b40 FlsSetValue
0x140052b48 FlushFileBuffers
0x140052b50 FreeEnvironmentStringsW
0x140052b58 FreeLibrary
0x140052b60 GetACP
0x140052b68 GetCPInfo
0x140052b70 GetCommandLineA
0x140052b78 GetCommandLineW
0x140052b80 GetConsoleMode
0x140052b88 GetConsoleOutputCP
0x140052b90 GetCurrentProcess
0x140052b98 GetCurrentProcessId
0x140052ba0 GetCurrentThreadId
0x140052ba8 GetEnvironmentStringsW
0x140052bb0 GetFileSize
0x140052bb8 GetFileSizeEx
0x140052bc0 GetFileType
0x140052bc8 GetLastError
0x140052bd0 GetModuleFileNameA
0x140052bd8 GetModuleFileNameW
0x140052be0 GetModuleHandleExW
0x140052be8 GetModuleHandleW
0x140052bf0 GetOEMCP
0x140052bf8 GetProcAddress
0x140052c00 GetProcessHeap
0x140052c08 GetStartupInfoW
0x140052c10 GetStdHandle
0x140052c18 GetStringTypeW
0x140052c20 GetSystemTimeAsFileTime
0x140052c28 HeapAlloc
0x140052c30 HeapFree
0x140052c38 HeapReAlloc
0x140052c40 HeapSize
0x140052c50 InitializeSListHead
0x140052c58 IsDebuggerPresent
0x140052c68 IsValidCodePage
0x140052c70 LCMapStringW
0x140052c78 LeaveCriticalSection
0x140052c80 LoadLibraryExW
0x140052c88 MultiByteToWideChar
0x140052c90 QueryPerformanceCounter
0x140052c98 RaiseException
0x140052ca0 ReadFile
0x140052ca8 RtlCaptureContext
0x140052cb0 RtlLookupFunctionEntry
0x140052cb8 RtlPcToFileHeader
0x140052cc0 RtlUnwindEx
0x140052cc8 RtlVirtualUnwind
0x140052cd0 SetFilePointerEx
0x140052cd8 SetLastError
0x140052ce0 SetStdHandle
0x140052cf0 TerminateProcess
0x140052cf8 TlsAlloc
0x140052d00 TlsFree
0x140052d08 TlsGetValue
0x140052d10 TlsSetValue
0x140052d18 UnhandledExceptionFilter
0x140052d20 WideCharToMultiByte
0x140052d28 WriteConsoleW
0x140052d30 WriteFile

!This program cannot be run in DOS mode.$
`.rdata
@.data
.pdata
@.gxfg
@.retplne
_RDATA
@.reloc
UAWAVAUATVWSH
g{a7A!
g{a7A!
>kJbA!
X[B&D!
X[B&D!
6_/YE!
6_/YD!
6_/YD!
6jBsD!
uFMPA!
uFMPA!
[_^A\A]A^A_]
i/$FE!
i/$FE!
i/$FD!
UAWAVAUATVWSH
,[-*F$
[_^A\A]A^A_]
D$T;D$d
H+T$hI
UAWAVAUATVWSH
[_^A\A]A^A_]
AWAVAUATVWUSH
D$0K!A
D$,-K!A
D$,-Bt
D$\HcL$\
HcL$\D
D$0K!A
L$<HcT$\D
lHcT$\D
T$<Lc\$<H
Lc\$\L
D$8;D$L
T$<LcL$\F
T$<LcL$<L
LcL$\M
HcL$\D
T$4HcL$4
L$@LcL$8F
[]_^A\A]A^A_
T$<LcD$\F
T$<LcD$<L
LcD$\M
HcL$\D
T$4HcL$4
L$@LcD$8F
AWAVAUATVWUSH
D$\-RD
D$\-:0
D$\-~
D$\-*}
D$\-]L9o
[]_^A\A]A^A_
AWAVAUATVWUSH
<X hA%
[]_^A\A]A^A_
UAWAVAUATVWSH
e([_^A\A]A^A_]
AWAVAUATVWUSH
H[]_^A\A]A^A_
UAWAVAUATVWSH
[_^A\A]A^A_]
AWAVAUATVWUSH
`9SNSM
D$0-nK
D$0-5=
D$0-"T
x[]_^A\A]A^A_
D$0-K%
UAWAVAUATVWSH
[_^A\A]A^A_]
D$0-n["
D$@-+rB
L<k:L)
UAWAVAUATVWSH
[_^A\A]A^A_]
AWAVAUATVWUSH
D$4-a5
x[]_^A\A]A^A_
AWAVAUATVWUSH
x[]_^A\A]A^A_
UAWAVAUATVWSH
[_^A\A]A^A_]
AWAVAUATVWUSH
[]_^A\A]A^A_
D$0-T,
AWAVAUATVWSH
D$0-"}fb
gfB`'rL
~bwbM!
p[_^A\A]A^A_
UAWAVAUATVWSH
[_^A\A]A^A_]
AWAVAUATVWUSH
D$4-=F
D$4-}4
D$4-Xy
D$4-;~
x[]_^A\A]A^A_
AWAVAUATVWUSH
D$<*
D$8-*
D$8-n7
D$8-gpC
D$8-iF
D$8-ry
\%U-RF
x[]_^A\A]A^A_
D$4Q92/
D$0-8?
D$0-Q92/
UAWAVAUATVWSH
x)z?E)
-x)z?-
[_^A\A]A^A_]
u/HcH<H
WATAUAVAWH
A_A^A]A\_
VWATAVAWH
A_A^A\_^
WATAUAVAWH
A_A^A]A\_
H;xXu5
WAVAWH
A_A^_
kL@8o(u
D$@H;F
<htl<jt\<lt4<tt$<wt
UWATAVAWH
A_A^A\_]
x UAVAWH
S(HcS0
S(HcS0
S(HcS0
WATAUAVAWH
0A_A^A]A\_
u3HcH<H
UVWAVAWH
0A_A^_^]
WAVAWH
A_A^_
WAVAWH
A_A^_
WAVAWH
fA9,@u
fA9,vu
0A_A^_
p0R^G'
p*W4H
p*W4H
D$0@8{
LcA<E3
SVWATAUAVAWH
0A_A^A]A\_^[
@SVWATAUAVAWH
L!|$(L!
D$0HcH
pA_A^A]A\_^[
B(I9A(u
t$ WATAUAVAWH
A_A^A]A\_
AUAVAWH
u4I9}(
;I9}(tiH
0A_A^A]
@USVWATAUAVAWH
A_A^A]A\_^[]
UVWATAUAVAWH
`A_A^A]A\_^]
UVWATAUAVAWH
A_A^A]A\_^]
WATAUAVAWH
A_A^A]A\_
fD9t$b
l$ VWATAVAWH
L$&8\$&t,8Y
A_A^A\_^
t$ WATAUAVAWH
D!|$xA
A_A^A]A\_
L$ VWAVH
{ AUAVAWH
0A_A^A]
t$xt*3
x ATAVAWH
A_A^A\
t$ WATAUAVAWH
gfffffffH
A_A^A]A\_
WAVAWH
A_A^_
L$ VWAVH
fD94H}aD
@UATAUAVAWH
e0A_A^A]A\]
UVWATAUAVAWH
H;\$8u
H;\$8u
fE9$Iu
A_A^A]A\_^]
WATAUAVAWH
0A_A^A]A\_
H9>u+A
WATAUAVAWH
A_A^A]A\_
vyfffff
vyfffff
WAVAWH
A_A^_
@UATAUAVAWH
A_A^A]A\]
@USVWATAUAVAWH
H!D$ H
xA_A^A]A\_^[]
VATAUAVAWH
0A_A^A]A\^
UVWATAUAVAWH
fB9<I}1L
A_A^A]A\_^]
VWATAVAW
A_A^A\_^
@USVWATAVAWH
A_A^A\_^[]
SUVWATAVAWH
A_A^A\_^][
WATAUAVAWH
0A_A^A]A\_
D$0H9D$8
ATAUAVH
L$ fff
L$ |+L;
A^A]A\
fffffff
fffffff
VATAUAVAWH
0A_A^A]A\^
ffffff
fffffff
@SUVWATAVAWH
@A_A^A\_^][
ATAVAWH
A_A^A\
USVWAVH
A^_^[]
fffffff
fffffff
fffffff
ffffff
vKfffff
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
[aOni*{
~ $s%r
@b;zO]
v2!L.2
UUUUUU
UUUUUU
=imb;D
/>58d%
VM>cQ6
>jtm}S
)>6{1n
+f)>0'
;H9>&X
*StO9>T
n03>Pu
K~Je#>!
bp(=>?g
BC?>6t9^
K&>.yC
.xJ>Hf
y\PD>!
|b=})>
c [1>H'
uzKs@>
3>N;kU
kE>fvw
V6E>`"(5
?UUUUUU
?7zQ6$
Unknown exception
bad array new length
string too long
C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe
Sunday
Monday
Friday
August
__eabi
new[]
1#SNAN
1#QNAN
(null)
dddd, MMMM dd, yyyy
MM/dd/yy
February
January
Thursday
Tuesday
Wednesday
Saturday
InitializeCriticalSectionEx
LCMapStringEx
operator co_await
__restrict
CorExitProcess
HH:mm:ss
operator
October
November
September
December
bad exception
bad allocation
__fastcall
__thiscall
__vectorcall
__clrcall
__stdcall
__cdecl
__pascal
FlsSetValue
FlsGetValue
delete
FlsFree
AppPolicyGetProcessTerminationMethod
__unaligned
FlsAlloc
delete[]
LocaleNameToLCID
operator<=>
__ptr64
__swift_3
__swift_2
__swift_1
nan(snan)
nan(ind)
NAN(SNAN)
NAN(IND)
restrict(
__based(
Base Class Descriptor at (
Base Class Array'
Class Hierarchy Descriptor'
Type Descriptor'
`vector deleting destructor'
`scalar deleting destructor'
`vbase destructor'
`vector copy constructor iterator'
`eh vector copy constructor iterator'
`managed vector copy constructor iterator'
`vector vbase copy constructor iterator'
`eh vector vbase copy constructor iterator'
`vector constructor iterator'
`eh vector constructor iterator'
`managed vector constructor iterator'
`vector vbase constructor iterator'
`eh vector vbase constructor iterator'
`vector destructor iterator'
`eh vector destructor iterator'
`managed vector destructor iterator'
Complete Object Locator'
`virtual displacement map'
`vcall'
`string'
`udt returning'
`omni callsig'
`typeof'
`copy constructor closure'
`default constructor closure'
`local vftable constructor closure'
`placement delete closure'
`placement delete[] closure'
`vftable'
`local vftable'
`vbtable'
`anonymous namespace'
`local static thread guard'
`local static guard'
`dynamic atexit destructor for '
`dynamic initializer for '
operator ""
CloseHandle
CreateFileA
CreateFileW
DeleteCriticalSection
EncodePointer
EnterCriticalSection
ExitProcess
FindClose
FindFirstFileExW
FindNextFileW
FlsAlloc
FlsFree
FlsGetValue
FlsSetValue
FlushFileBuffers
FreeEnvironmentStringsW
FreeLibrary
GetACP
GetCPInfo
GetCommandLineA
GetCommandLineW
GetConsoleMode
GetConsoleOutputCP
GetCurrentProcess
GetCurrentProcessId
GetCurrentThreadId
GetEnvironmentStringsW
GetFileSize
GetFileSizeEx
GetFileType
GetLastError
GetModuleFileNameA
GetModuleFileNameW
GetModuleHandleExW
GetModuleHandleW
GetOEMCP
GetProcAddress
GetProcessHeap
GetStartupInfoW
GetStdHandle
GetStringTypeW
GetSystemTimeAsFileTime
HeapAlloc
HeapFree
HeapReAlloc
HeapSize
InitializeCriticalSectionAndSpinCount
InitializeSListHead
IsDebuggerPresent
IsProcessorFeaturePresent
IsValidCodePage
LCMapStringW
LeaveCriticalSection
LoadLibraryExW
MultiByteToWideChar
QueryPerformanceCounter
RaiseException
ReadFile
RtlCaptureContext
RtlLookupFunctionEntry
RtlPcToFileHeader
RtlUnwindEx
RtlVirtualUnwind
SetFilePointerEx
SetLastError
SetStdHandle
SetUnhandledExceptionFilter
TerminateProcess
TlsAlloc
TlsFree
TlsGetValue
TlsSetValue
UnhandledExceptionFilter
WideCharToMultiByte
WriteConsoleW
WriteFile
KERNEL32.dll
.?AVbad_array_new_length@std@@
.?AVbad_alloc@std@@
.?AVexception@std@@
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
.?AVlogic_error@std@@
.?AVlength_error@std@@
.?AVbad_exception@std@@
.?AVtype_info@@
p0R^G'
p0R^G'
p0R^G'
p*W4H
p*W4H
p0R^G'
pB]P67
p0R^G'
p0R^G'
p0VXNh
p0R^G'
p@\xV.
p0R^G'
p0R^G'
p0R^G'
p0R^G'
p0R^G'
RetpolineV1
RetpolineV1
RetpolineV1
RetpolineV1
*qth Yc
0nwY5ncUS
.HX1p,4
\;~^jj
sb"v70
AZ{jbo
bzdFJv
FqVj*~_HI
7>r=m&
o{6H72k
/>KXi_
o-ya59
.'ty}-
tI1sAjth
"x@X 6
>1Q?c"8(#n
">$j(&
^BSTVn
lAwe:Z
;6Ap@A
\\OW_8y
z!63]ZhLV
\hcdj9
O<vSmX?8Q
?a6gNV
&M,Lo-
p?=AcVA
*APW_p
%$OK)Y
.>;{AR
vKZs39
+Smz(T
+/E1\3'
6\;*'^
V@CT?L
@WcEp=
#;SW(&
>w| [3bq
|xC!@F
5<830n
:8pL(a
fa?/~mj
s,G\"M
/5`1>z
4v.Kjix
\^f+R.
wc%\++
xeo~4
StD"Qu
,4cEpE
!+?5tCO
3sI-Q.
[ g^(E
nUF/BL
w#/|KC
NY^L_dy
TqFdj
,jdN<e[B
<OPvL(
^DW9ID2
=`eOB~_
mZZcP]
.!M)'7
nwLBd On
[D,sRru
oi&>FZ_
8@OA?p
v#91lf
1*Qen
Br0@+"
:C1GRz
.l>Q<<
tzo@^t
W[IXxHLuT
<*Ko}a
J|exK`m
|oZ%'i9
(HSZ{my
O_2Yq?
x>IpR$
z=T?XA
V";GGx
O}7h!uN
ZgS<rh
a!\%{;
rWPd;4
}%lRPY
OVlq2e
hTGCb[
*X2<6P
Dck\Pc+Yg
$X\lh<
FR+,-S
NW5]Y
MnN@%.
0Nr4S$
[bONm"
7l-p\[K
GIEVGe
<kmr!|
RkV0O!
l<_C3b
)f^[I"nX9
c~EEt6
M~@Y$v%
5%~BWe
)w?<Xd
6Vz#'Htb
[E[WD(
Jti$%@f
:KKE~\
:*e0@H
328#LUs
PYH3#3
1q>!sbU
GN<3G+
~jGa2"
]]za_{
x]M`52
)g9MA-g ;R?
|P<Z{QKhi
x;qifV
UTt[~?
ZxVhek
,#(T e
Y*"cs`
D+7RaCr
]peUF.
gWDYzB
@e-SLo
;(P"Nc{
cB*^&y ^
$oqClW
i!$UYd
roJR>#>
+Yp9i3
p`MD~tU
0K94?D|
25NWiB
`z#.o7
%0m2y0
Wx)H{A
K53P3
khBwAZ
{1000ZA}J
Hs%[}j
#O&Y,m
<Rt"g}
_tF,9a
*lFdPH
dqde>
S`m@vLk
!K0@Ve
Cn-t<'(`
hXABawX
=]@2)R
k+kmN-
[\WRqq
4jlag6
qR")ZO
O)18w^g
$4@@Y'
H>.G7O
os\=A`
bxJ33&H
@}IN{Z
bJ}]69
A5UsS2
JN=5dN$c
Ooy.}A
{#d?Qa
Bm4aNYg>
MX3V*KX
w=ZK9a
(?nvDyT
Z>aA+b
e3{oWWz
YiYeu7
RM)U<=
\Pf28r
qkaV6M
B;nnYuK
iy]%t&*
xfD8qv
TQ..(U
C%C^POk
{x0r'-
?2m\nSWH
^d"S U
usm994
]LYEfR
@"lY:S
)-6v&U^
OzmP \
^*X1,?b>/3^
wy4?/^
QN/ I;7n
5vQIiz
p~6%-e
S HifC
faJdoxh
H)7^t~
6[~nl{%
m[$C{$i
Jn2z/I
?mt#?`
rU3*}Q$
#RSE7h<0
a2QDk-
A,(Wt._H
D=TDHj
99Vm4\
V(z0L*
ByicGac
dLG5+0:
(s`k*0=
!1=1VT
'DOD!G
x0WFk<
kczqWC
0F>R!=@
KiX`7
OMn~E!-#
wg?+eSf
U|uZb
3Je8+m
<VDxsPb
j4Q.oW
{y:48k
Mz&%wZ
z@uHFC
#[QN}i
~^Wd\P
GL~*7+"
C9:2F~$
"kOo)5.
i!4wY?
x*-:II
|c:0B]W
qH8Q\J4u
Vfvad2
kzt;Qa
[#PP&I
kubGH"
\dEB$l|1m]
[b\oDk
[R,?|y
n&qm5
}U_P'mcYK`K
Ndj?K
j'dZ i
J0vje{
o;P:1B
7Av[9
}$K]H!|%
7w1Un>
q*XFB
%&Z'HT
d)Lv4|t)
!35<vW
DqZa:'
fBKQ^;,
!X:[xf
_nUrDq
kbUL"~%
tCL%+o
F{lP/c
kB}(,r^
P,= 30R
e(Rh}3
)1Y 'g.
YGWyG^
=t9t1
0-:H]*(j
KI_Z6<<
{Ir:~;
13YNt5
Pk%.bZ
P|(X.n
uE "?KA
zAb%1rc
N#`Yiw
8T5ENb
5O5ZWI
1re~,E
Sh@i/w
nhiOgx
4"9FbF
A](wBo
7old'6
=+*? A
q'$0 %
W VM`k
rEv93Db
c*Xnl}X
M{28eD/
r`M`+yX
[e'rg3
ADt<rF
r-%z(+
b7l:Vl
\M82|E
k@)0vB
AaHz)("
eK_jZ7b
{fTPE@
>x\R.
q1<?]-kX
s#%w7&
:HU.Uh
@;LV/;.
yco93L
uaF#?0
M)nPd*
%2<^Y?ZwO
YW~G(S
<_1h9"
^NKlJj
1hFOY,
f?e]tJ#
pO0g/A
tA.F)
'7Md1F
#;Br@[
30GZQY
[r:B%+
C%v`n-
g5#s\)
!s>f!io
UR5]]
B\8?G-
fI~h<I.
9dmIF.
nd)A@y
9%y,q`
M_<[Kn
JUm0@o
[0V+n s
Uz7;3
}0V;?~
P@yHbS
UqIM+)0o
2AF"&9
A@LFd^
aJD98g
6r[_?vR
yN@NNn
_q\ic
he]DS*N9
=Z-67g
$@*9:z
k_-c)<`7
YTc))KC?'
! 18\Qq
PeiB=$
))_A&(
`a<j.[
<-{g3_CA
GF{s*L
;-;2u]R
{v<I"<
(3^\k#
$f;x~W]
,?5));
?qQ~kB
XOwOL2
w-H8W.
gZQ5wm
P%SUD:Jg_n
{qai2/
u=q6MDmm8`
a0[hl|k
\bhN]r
(rcwXG
KNTh@8(
u#dc/lT
Gz`sAN
`?G+P<s
t`GzR>i
S8nTkR
5~rin\
j[D9_Y
+I!W4hJ.
$]oijk
T3Qx)h
^#]x~4
OpW-SL
)1ixHFP\
ze`W%.
(Czb0?7HJ]zG
{nfW_A
nCl)<A
$|Cb@^
g3o5I9
'04aLfz@
J#[^Fv
hF"?_,
BOq33=
tzH;e~
0;1YlV
o5[B6t7
`:a]_
*1B;|V
v3Z=f{
/L()pf
nif.~M
7{{O(|N
pMYV\u
2D tHl|j
$$Z["W
m+]/-C
XwFW*e
YU>2u@
HX.?/h
rcn-cO
2kb*F=
`3I)9w
Q]nET#OpoL
*v&+w+
`\Isb`
"4#Y:<
j{).YR
HVsKvM
R:w8C
'\<e;<
`53{&o
5{ecWXl
*Cg$2[`
f0>t=P
YEF7A-
C9|{[zhW
n-H-M5
LnnSUF
eE.u9;
|No<{2
Lilp[x
`Xy\M&
<lV>l9Rc
tH$%:B*
YBM".
$=}3|(.*S
X_*Qvn
yz[i8j,3
Z1*/pHAnK
L(4R\W
QcBAq6G
.L.![^)
TG_@wG
BkftjyZVP
^3 ]qXn
fQZau-l
J]Cn#s
+gN2j~
rEH2$50`
u 2! c
\Xa"q-
oI8]*px
;Ah4;J
?tDR*A
o*al0!
<S:vfv
LCJ_b-#
BBud-&cF
;kM 8%k
=(ETsq
(;h,JO
3]!;We
S4/M(W
Hr}:)A(
:um1#c
RKk7-IEWe@
x`g|gG
Ux<(o;
o^Zl$xr,
ZS~m%@I
]d|%D='
4?ouYwX
x=[Kf
2v7k3RH
'vG L.
#R6z"H.
0.^cpn{
+;aT~b^
go=U3(S
uzpfm:
.ss>QRL
u4};6HC}
=L(*SJ
Hpe6Y\
E4`To'
kg x51
].5u%8
a|62.vW
EDwLF3
c(X{0~
I7mC]a
6OKF;_Q
~](LE9
5jRD@PrT
v)yC/[s
q1)/R
jSm`5
OGJ3+W
9Q%k^c
!t~4l:d
{;z4cW
km.< b
;'Bq4t
-f&+#U
-$;0uR
lu zNQ}
KqbmqS
\ou#B~w
nC|M~(
b]Je-r
)zRavq
8<^9z2
|+,AGU
~G}t8Ss
O1;'|G
y^ZPMC
Kf;E\aTcg
7ASm_UM@
f&"MZo
JChM1fi
=D" 5wv
-n>['V
hr5#'ib
he9e!q
Tf6In
z#fn>_
lvz;xW
"WaD2
vs<];P
8H9DcU
CqSzUc
ywy*N%
r$5jQZZ
<uc4J\
W_(sv$T
n-3% }
iCV[fI&Tz
I=1#**~D~
t:.^#J
%'hNA=
8i6T5QgN00c
K2N;ZG
0v~sg"
fM*tf$
\J&y*l#
(`Zq-
p1qU3?0
ng8|'2
9+dL+
SkQIyg`
*_Rmc"AHP,
;'/e^N-+(
g\A %;!
$zM|u%
@)KXrJ
WYIP?70
5Uyq#n @
HjhsL}P
~Ne=i.
lxt_:k
5~B8y0
(jOkn
-vHTjA10V
)ww)#e2
~e(6dB[
%7+be9
SnzP_#a
EfB.SK
<?U._}L
1;EEdr
Re/Ai%
<^)TR]K
NCQCd+<%%
T1Pa+?
EY"Vz-Fmr
7ASW>0
;2Q~`3
<<7|\9
|oHZMn
PJpB};
4:/#<5
XJ1*8D
SSOd{A
EIV)#|&W
Q.0FOG
{Xnvf*
**hQl
6yOA~3
0rz.>vxs
Ve$.}+0p+
K_h(wS]
z-Ch@+?
RZ![dZ
lRN2}$J
}%~IH~
'rFkY'
W$!i[t
ba8Ceu
j+'ICZ8/
H1Q`Mp
TW!]aa
[GnBnf-
oX/<N>|
?j[&T-
l,W-|XM[@r
'kOow]\
3s1}C!2 MR%
xQ/PN}
8DUN\|
v,t>+b'
4m0gUX
x7*#h
Vg"{^A
+g5[r3;F!
Url?x~
A+*cMa
?WN`NX
jFHB54
ei,b+"
p/Du/+($
6zq-j%y
E5/K`e4
LDP$M?97
d_!%C2
^Wj6V
Q=e4`c7
BcQ+D
Q)B$kw
s<pbO0+g
i85}`s
kjEbCe
XG:d%mr
iVP=m,
'6-5Md-]
DigiCert Inc1
www.digicert.com1!0
DigiCert Trusted Root G40
210429000000Z
360428235959Z0i1
DigiCert, Inc.1A0?
8DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA10
[K]taM?
SA|X=G
http://ocsp.digicert.com0A
5http://cacerts.digicert.com/DigiCertTrustedRootG4.crt0C
2http://crl3.digicert.com/DigiCertTrustedRootG4.crl0
jj@0HK4
DigiCert, Inc.1A0?
8DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA10
230113000000Z
260116235959Z0
California1
Santa Clara1
NVIDIA Corporation1
NVIDIA Corporation0
Aoi0Ka
Mhttp://crl3.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crl0S
Mhttp://crl4.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crl0>
http://www.digicert.com/CPS0
http://ocsp.digicert.com0\
Phttp://cacerts.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crt0
DigiCert, Inc.1A0?
8DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1
joS&;J
20231102033749Z0
Ontario1
Ottawa1
Entrust, Inc.1+0)
"Entrust Timestamp Authority - TSA1
Entrust.net1@0>
7www.entrust.net/CPS_2048 incorp. by ref. (limits liab.)1%0#
(c) 1999 Entrust.net Limited1301
*Entrust.net Certification Authority (2048)0
991224175051Z
290724141512Z0
Entrust.net1@0>
7www.entrust.net/CPS_2048 incorp. by ref. (limits liab.)1%0#
(c) 1999 Entrust.net Limited1301
*Entrust.net Certification Authority (2048)0
Entrust.net1@0>
7www.entrust.net/CPS_2048 incorp. by ref. (limits liab.)1%0#
(c) 1999 Entrust.net Limited1301
*Entrust.net Certification Authority (2048)0
150722190254Z
290622193254Z0
Entrust, Inc.1(0&
See www.entrust.net/legal-terms1907
0(c) 2015 Entrust, Inc. - for authorized use only1&0$
Entrust Timestamping CA - TS10
T=A^C_(F
http://www.entrust.net/rpa03
http://ocsp.entrust.net02
!http://crl.entrust.net/2048ca.crl0
Entrust, Inc.1(0&
See www.entrust.net/legal-terms1907
0(c) 2015 Entrust, Inc. - for authorized use only1&0$
Entrust Timestamping CA - TS10
221004172103Z
290101000000Z0u1
Ontario1
Ottawa1
Entrust, Inc.1+0)
"Entrust Timestamp Authority - TSA10
_Xg>gX
http://ocsp.entrust.net03
'http://aia.entrust.net/ts1-chain256.cer01
http://crl.entrust.net/ts1ca.crl0
https://www.entrust.net/rpa0
Entrust, Inc.1(0&
See www.entrust.net/legal-terms1907
0(c) 2015 Entrust, Inc. - for authorized use only1&0$
Entrust Timestamping CA - TS1
231102033749Z0)
Entrust, Inc.1(0&
See www.entrust.net/legal-terms1907
0(c) 2015 Entrust, Inc. - for authorized use only1&0$
Entrust Timestamping CA - TS1
((((( H
KERNEL32.DLL
dddd, MMMM dd, yyyy
MM/dd/yy
syr-sy
February
January
Thursday
Tuesday
Wednesday
Saturday
Sunday
Monday
Friday
div-mv
August
zh-cht
HH:mm:ss
zh-chs
October
November
September
December
smj-no
sma-no
quz-bo
uz-uz-latn
az-az-latn
sr-sp-latn
bs-ba-latn
sr-ba-latn
uz-UZ-Latn
az-AZ-Latn
sr-SP-Latn
bs-BA-Latn
sr-BA-Latn
kok-in
uz-uz-cyrl
az-az-cyrl
sr-sp-cyrl
sr-ba-cyrl
uz-UZ-Cyrl
az-AZ-Cyrl
sr-SP-Cyrl
sr-BA-Cyrl
mscoree.dll
sms-fi
smn-fi
kernelbase
smj-se
sma-se
quz-pe
quz-ec
syr-SY
div-MV
zh-CHT
zh-CHS
smj-NO
sma-NO
quz-BO
kok-IN
sms-FI
smn-FI
smj-SE
sma-SE
quz-PE
quz-EC
api-ms-win-core-file-l1-2-4
user32
kernel32
advapi32
api-ms-win-core-file-l1-2-2
api-ms-win-core-sysinfo-l1-2-1
api-ms-win-core-fibers-l1-1-1
api-ms-win-core-synch-l1-2-0
api-ms-win-core-xstate-l2-1-0
api-ms-win-core-winrt-l1-1-0
api-ms-win-core-string-l1-1-0
ext-ms-
api-ms-
(null)
CONOUT$
api-ms-win-core-processthreads-l1-1-2
api-ms-win-appmodel-runtime-l1-1-2
api-ms-win-core-localization-l1-2-1
api-ms-win-core-datetime-l1-1-1
api-ms-win-core-localization-obsolete-l1-2-0
ext-ms-win-ntuser-dialogbox-l1-1-0
api-ms-win-rtcore-ntuser-window-l1-1-0
api-ms-win-security-systemfunctions-l1-1-0
ext-ms-win-ntuser-windowstation-l1-1-0
Antivirus Signature
Bkav W64.AIDetectMalware
Lionic Trojan.Win32.Caynamer.4!c
Elastic malicious (high confidence)
ClamAV Clean
CMC Clean
CAT-QuickHeal Trojan.Ghanarava.17431783132da8ca
Skyhigh BehavesLike.Win64.Trickbot.bc
ALYac Clean
Cylance Unsafe
Zillya Clean
Sangfor Trojan.Win32.Kryptik.Vi93
CrowdStrike win/malicious_confidence_100% (W)
Alibaba Trojan:Win64/GenKryptik.60caa68f
K7GW Trojan ( 005c49bc1 )
K7AntiVirus Trojan ( 005c49bc1 )
huorong Clean
Baidu Clean
VirIT Clean
Paloalto generic.ml
Symantec ML.Attribute.HighConfidence
tehtris Clean
ESET-NOD32 a variant of Win64/GenKryptik.HHRD
APEX Malicious
Avast Win64:Evo-gen [Trj]
Cynet Malicious (score: 100)
Kaspersky Trojan.Win32.InjectorNetT.ol
BitDefender Trojan.GenericKDZ.110563
NANO-Antivirus Clean
ViRobot Clean
MicroWorld-eScan Trojan.GenericKDZ.110563
Tencent Win32.Trojan.FalseSign.Simw
Sophos Mal/Generic-S
F-Secure Trojan.TR/Crypt.Agent.frxdy
DrWeb Clean
VIPRE Trojan.GenericKDZ.110563
TrendMicro Clean
McAfeeD ti!D20816D1E73F
Trapmine Clean
CTX exe.trojan.generic
Emsisoft Trojan.GenericKDZ.110563 (B)
Ikarus Trojan.Win64.Krypt
FireEye Generic.mg.19cc136b64066f97
Jiangmin Clean
Webroot Win.Malware.Gen
Varist W64/Agent.NGAW
Avira TR/Crypt.Agent.frxdy
Fortinet W64/GenKryptik.HHRD!tr
Antiy-AVL Trojan/Win32.Caynamer
Kingsoft Clean
Gridinsoft Ransom.Win64.Wacatac.sa
Xcitium Clean
Arcabit Trojan.Generic.D1AFE3
SUPERAntiSpyware Clean
ZoneAlarm Clean
Microsoft Trojan:Win32/Caynamer.A!ml
Google Detected
AhnLab-V3 Trojan/Win.Caynamer.C5746250
Acronis Clean
McAfee Artemis!19CC136B6406
TACHYON Clean
VBA32 Clean
Panda Trj/Chgt.AD
Zoner Clean
TrendMicro-HouseCall Trojan.Win32.VSX.PE04C9V
Rising Trojan.Kryptik!8.8 (CLOUD)
Yandex Clean
SentinelOne Static AI - Suspicious PE
MaxSecure Trojan.Malware.300983.susgen
GData Win32.Trojan-Stealer.LummaStealer.O96P9Z
AVG Win64:Evo-gen [Trj]
DeepInstinct MALICIOUS
alibabacloud Trojan:Win/Wacatac.B9nj
No IRMA results available.