Static | ZeroBOX

PE Compile Time

2025-04-06 00:19:34

PE Imphash

8beb5ca1ff83475ee16fa1a921765aab

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x00028215 0x00028400 6.95986880129
.rdata 0x0002a000 0x0000a4d4 0x0000a600 4.98423726587
.data 0x00035000 0x00002198 0x00000c00 2.23958000378
.pdata 0x00038000 0x00001398 0x00001400 5.40721361737
.BSS 0x0003a000 0x0000093d 0x00000a00 6.6926423081
.gxfg 0x0003b000 0x000013d0 0x00001400 5.09495714681
.retplne 0x0003d000 0x0000008c 0x00000200 1.05058324797
_RDATA 0x0003e000 0x000001f4 0x00000200 4.19044730988
.reloc 0x0003f000 0x00000688 0x00000800 4.98009807556
.cSs 0x00040000 0x000b6800 0x000b6800 7.999760085

Imports

Library KERNEL32.dll:
0x140032ad8 CloseHandle
0x140032ae0 CreateFileA
0x140032ae8 CreateFileW
0x140032af0 DeleteCriticalSection
0x140032af8 EncodePointer
0x140032b00 EnterCriticalSection
0x140032b08 ExitProcess
0x140032b10 FindClose
0x140032b18 FindFirstFileExW
0x140032b20 FindNextFileW
0x140032b28 FlsAlloc
0x140032b30 FlsFree
0x140032b38 FlsGetValue
0x140032b40 FlsSetValue
0x140032b48 FlushFileBuffers
0x140032b50 FreeEnvironmentStringsW
0x140032b58 FreeLibrary
0x140032b60 GetACP
0x140032b68 GetCPInfo
0x140032b70 GetCommandLineA
0x140032b78 GetCommandLineW
0x140032b80 GetConsoleMode
0x140032b88 GetConsoleOutputCP
0x140032b90 GetCurrentProcess
0x140032b98 GetCurrentProcessId
0x140032ba0 GetCurrentThreadId
0x140032ba8 GetEnvironmentStringsW
0x140032bb0 GetFileSize
0x140032bb8 GetFileSizeEx
0x140032bc0 GetFileType
0x140032bc8 GetLastError
0x140032bd0 GetModuleFileNameA
0x140032bd8 GetModuleFileNameW
0x140032be0 GetModuleHandleExW
0x140032be8 GetModuleHandleW
0x140032bf0 GetOEMCP
0x140032bf8 GetProcAddress
0x140032c00 GetProcessHeap
0x140032c08 GetStartupInfoW
0x140032c10 GetStdHandle
0x140032c18 GetStringTypeW
0x140032c20 GetSystemTimeAsFileTime
0x140032c28 HeapAlloc
0x140032c30 HeapFree
0x140032c38 HeapReAlloc
0x140032c40 HeapSize
0x140032c50 InitializeSListHead
0x140032c58 IsDebuggerPresent
0x140032c68 IsValidCodePage
0x140032c70 LCMapStringW
0x140032c78 LeaveCriticalSection
0x140032c80 LoadLibraryExW
0x140032c88 MultiByteToWideChar
0x140032c90 QueryPerformanceCounter
0x140032c98 RaiseException
0x140032ca0 ReadFile
0x140032ca8 RtlCaptureContext
0x140032cb0 RtlLookupFunctionEntry
0x140032cb8 RtlPcToFileHeader
0x140032cc0 RtlUnwindEx
0x140032cc8 RtlVirtualUnwind
0x140032cd0 SetFilePointerEx
0x140032cd8 SetLastError
0x140032ce0 SetStdHandle
0x140032cf0 TerminateProcess
0x140032cf8 TlsAlloc
0x140032d00 TlsFree
0x140032d08 TlsGetValue
0x140032d10 TlsSetValue
0x140032d18 UnhandledExceptionFilter
0x140032d20 WideCharToMultiByte
0x140032d28 WriteConsoleW
0x140032d30 WriteFile

!This program cannot be run in DOS mode.$
`.rdata
@.data
.pdata
`.gxfg
@.retplne
_RDATA
@.reloc
AWAVAUATVWUSH
qt5V'_
]{zxE1
HcD$\H
|PI4D!
HcD$@H
x[]_^A\A]A^A_
AWAVAUATVWUSH
[]_^A\A]A^A_
AWAVAUATVWUSH
8[]_^A\A]A^A_
AWAVAUATVWUSH
Hct$hL
D$XHcL$X
D$h;D$,
D$XHcL$X
[]_^A\A]A^A_
AWAVAUATVWUSH
x[]_^A\A]A^A_
AWAVAUATVWUSH
`Kg$H)
8$!)c(H
ASv*~X
[]_^A\A]A^A_
AWAVAUATVWUSH
H[]_^A\A]A^A_
AWAVAUATVWUSH
[HDXH)
H+D$0L)
H[]_^A\A]A^A_
AWAVVWUSH
X[]_^A^A_
UAWAVAUATVWSH
[_^A\A]A^A_]
AWAVAUATVWUSH
X[]_^A\A]A^A_
AWAVAUATVWUSH
X[]_^A\A]A^A_
AWAVAUATVWUSH
u9G+=t9G+~
8[]_^A\A]A^A_
UAWAVAUATVWSH
m:cK`H
[_^A\A]A^A_]
AWAVATVWUSH
@[]_^A\A^A_
AWAVAUATVWUSH
H+T$8H)
H[]_^A\A]A^A_
AWAVATVWUSH
@[]_^A\A^A_
UVWSPH
AWAVAUATVWUSH
8[]_^A\A]A^A_
AWAVAUATVWUSH
H[]_^A\A]A^A_
AWAVAUATVWUSH
8[]_^A\A]A^A_
cXt/=y
u/HcH<H
WATAUAVAWH
A_A^A]A\_
VWATAVAWH
A_A^A\_^
WATAUAVAWH
A_A^A]A\_
H;xXu5
WAVAWH
A_A^_
kL@8o(u
D$@H;F
<htl<jt\<lt4<tt$<wt
UWATAVAWH
A_A^A\_]
x UAVAWH
S(HcS0
S(HcS0
S(HcS0
WATAUAVAWH
0A_A^A]A\_
u3HcH<H
UVWAVAWH
0A_A^_^]
WAVAWH
A_A^_
WAVAWH
A_A^_
WAVAWH
fA9,@u
fA9,vu
0A_A^_
p0R^G'
p*W4H
p*W4H
D$0@8{
LcA<E3
SVWATAUAVAWH
0A_A^A]A\_^[
@SVWATAUAVAWH
L!|$(L!
D$0HcH
pA_A^A]A\_^[
B(I9A(u
t$ WATAUAVAWH
A_A^A]A\_
AUAVAWH
u4I9}(
;I9}(tiH
0A_A^A]
@USVWATAUAVAWH
A_A^A]A\_^[]
UVWATAUAVAWH
`A_A^A]A\_^]
UVWATAUAVAWH
A_A^A]A\_^]
WATAUAVAWH
A_A^A]A\_
fD9t$b
l$ VWATAVAWH
L$&8\$&t,8Y
A_A^A\_^
t$ WATAUAVAWH
D!|$xA
A_A^A]A\_
L$ VWAVH
{ AUAVAWH
0A_A^A]
t$xt*3
x ATAVAWH
A_A^A\
t$ WATAUAVAWH
gfffffffH
A_A^A]A\_
WAVAWH
A_A^_
L$ VWAVH
fD94H}aD
@UATAUAVAWH
e0A_A^A]A\]
UVWATAUAVAWH
H;\$8u
H;\$8u
fE9$Iu
A_A^A]A\_^]
WATAUAVAWH
0A_A^A]A\_
H9>u+A
WATAUAVAWH
A_A^A]A\_
vyfffff
vyfffff
WAVAWH
A_A^_
@UATAUAVAWH
A_A^A]A\]
@USVWATAUAVAWH
H!D$ H
xA_A^A]A\_^[]
VATAUAVAWH
0A_A^A]A\^
UVWATAUAVAWH
fB9<I}1L
A_A^A]A\_^]
VWATAVAW
A_A^A\_^
@USVWATAVAWH
A_A^A\_^[]
SUVWATAVAWH
A_A^A\_^][
WATAUAVAWH
0A_A^A]A\_
D$0H9D$8
ATAUAVH
L$ fff
L$ |+L;
A^A]A\
fffffff
fffffff
VATAUAVAWH
0A_A^A]A\^
ffffff
fffffff
@SUVWATAVAWH
@A_A^A\_^][
ATAVAWH
A_A^A\
USVWAVH
A^_^[]
fffffff
fffffff
fffffff
ffffff
vKfffff
$#)":>
$.?">"+9c
?, (:"?&
;yc}c~}~|t
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
[aOni*{
~ $s%r
@b;zO]
v2!L.2
UUUUUU
UUUUUU
=imb;D
/>58d%
VM>cQ6
>jtm}S
)>6{1n
+f)>0'
;H9>&X
*StO9>T
n03>Pu
K~Je#>!
bp(=>?g
BC?>6t9^
K&>.yC
.xJ>Hf
y\PD>!
|b=})>
c [1>H'
uzKs@>
3>N;kU
kE>fvw
V6E>`"(5
?UUUUUU
?7zQ6$
Unknown exception
bad array new length
string too long
Sunday
Monday
Friday
August
__eabi
new[]
1#SNAN
1#QNAN
(null)
dddd, MMMM dd, yyyy
MM/dd/yy
February
January
Thursday
Tuesday
Wednesday
Saturday
InitializeCriticalSectionEx
LCMapStringEx
operator co_await
__restrict
CorExitProcess
HH:mm:ss
operator
October
November
September
December
bad exception
bad allocation
__fastcall
__thiscall
__vectorcall
__clrcall
__stdcall
__cdecl
__pascal
FlsSetValue
FlsGetValue
delete
FlsFree
AppPolicyGetProcessTerminationMethod
__unaligned
FlsAlloc
delete[]
LocaleNameToLCID
operator<=>
__ptr64
__swift_3
__swift_2
__swift_1
nan(snan)
nan(ind)
NAN(SNAN)
NAN(IND)
restrict(
__based(
Base Class Descriptor at (
Base Class Array'
Class Hierarchy Descriptor'
Type Descriptor'
`vector deleting destructor'
`scalar deleting destructor'
`vbase destructor'
`vector copy constructor iterator'
`eh vector copy constructor iterator'
`managed vector copy constructor iterator'
`vector vbase copy constructor iterator'
`eh vector vbase copy constructor iterator'
`vector constructor iterator'
`eh vector constructor iterator'
`managed vector constructor iterator'
`vector vbase constructor iterator'
`eh vector vbase constructor iterator'
`vector destructor iterator'
`eh vector destructor iterator'
`managed vector destructor iterator'
Complete Object Locator'
`virtual displacement map'
`vcall'
`string'
`udt returning'
`omni callsig'
`typeof'
`copy constructor closure'
`default constructor closure'
`local vftable constructor closure'
`placement delete closure'
`placement delete[] closure'
`vftable'
`local vftable'
`vbtable'
`anonymous namespace'
`local static thread guard'
`local static guard'
`dynamic atexit destructor for '
`dynamic initializer for '
operator ""
CloseHandle
CreateFileA
CreateFileW
DeleteCriticalSection
EncodePointer
EnterCriticalSection
ExitProcess
FindClose
FindFirstFileExW
FindNextFileW
FlsAlloc
FlsFree
FlsGetValue
FlsSetValue
FlushFileBuffers
FreeEnvironmentStringsW
FreeLibrary
GetACP
GetCPInfo
GetCommandLineA
GetCommandLineW
GetConsoleMode
GetConsoleOutputCP
GetCurrentProcess
GetCurrentProcessId
GetCurrentThreadId
GetEnvironmentStringsW
GetFileSize
GetFileSizeEx
GetFileType
GetLastError
GetModuleFileNameA
GetModuleFileNameW
GetModuleHandleExW
GetModuleHandleW
GetOEMCP
GetProcAddress
GetProcessHeap
GetStartupInfoW
GetStdHandle
GetStringTypeW
GetSystemTimeAsFileTime
HeapAlloc
HeapFree
HeapReAlloc
HeapSize
InitializeCriticalSectionAndSpinCount
InitializeSListHead
IsDebuggerPresent
IsProcessorFeaturePresent
IsValidCodePage
LCMapStringW
LeaveCriticalSection
LoadLibraryExW
MultiByteToWideChar
QueryPerformanceCounter
RaiseException
ReadFile
RtlCaptureContext
RtlLookupFunctionEntry
RtlPcToFileHeader
RtlUnwindEx
RtlVirtualUnwind
SetFilePointerEx
SetLastError
SetStdHandle
SetUnhandledExceptionFilter
TerminateProcess
TlsAlloc
TlsFree
TlsGetValue
TlsSetValue
UnhandledExceptionFilter
WideCharToMultiByte
WriteConsoleW
WriteFile
KERNEL32.dll
.?AVbad_array_new_length@std@@
.?AVbad_alloc@std@@
.?AVexception@std@@
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
.?AVlogic_error@std@@
.?AVlength_error@std@@
.?AVbad_exception@std@@
.?AVtype_info@@
AWAVAUATVWUSH
8[]_^A\A]A^A_
p0R^G'
p0R^G'
p0R^G'
p*W4H
p*W4H
p0R^G'
pB]P67
p0R^G'
p0R^G'
p0VXNh
p0R^G'
p@\xV.
p0R^G'
p0R^G'
p0R^G'
p0R^G'
p0R^G'
RetpolineV1
RetpolineV1
RetpolineV1
RetpolineV1
H/5wj&H
5{<5[H
H{CIl4
4O>Es2
HVkdM6K6
yiEVg
A23a!
14YC^n
0%eWa'
1eZ}8"
8Qn<%
1Ru-rx
p+AC,o
I,$3>j@@
N,&?M5
H_*?\G
mV:NA&2
JZ5@6a
2Jas0O
A;u:MZ
EzXY<n
hn2J\6x
hUg${u
:r`]u*
}8V<)
(i|-2n'M
>HW`C_
]G-G+
kRwgC|
,)I <
#<;M.3
ndr{~A
O\,tV4
_Gb91^
S0$S)*U5
U-B-4K
<=p} o
LrISF>:
#0q^J+
LIp 8l~
B6!+0*
jz]&5YV
@qezy)7P
.{WdjuU
p9Av!p
q>LM[e
BOmV#Yc3
+U!5%X
S<pA\g
2NBq>n
)bj'c'
`QoGB&
7X<t#|
M2v+!
Yr_k%@
s5w"3gR
ow\Q+t
G3\_n9
Vu{9lwj
\GB]up
nlE*jZ
T6uu0w
v:H'#h*8
n9Y!YUY
?k3vU
!_H0p1
_t?RF.C+?
>+1j!2
*mQiRV
v+mrkK
t%%IWE
.:"7VN
=$^V`9
:f:>j{'$
3m4/cu!
?+]LlL
N(.D2~
j.(xsm
h&1J?G
y^[IQ9;
#6wEq$
7^2FI
S>fiXI
^>5$+Jf
xeR6}~4X
UQ88f
h-|:?|
Bb UF>:
6 H{_8
c-lT]J
y,PK\6
0:;Yv:
.I|QGJ
/I;:P4
K)+-6C|
ffT]![
lHpa3:
<o.OCL
OpDE`y=Z
>tn5=,
;>t0a#
iNVsY~
j}UI#(
HZul1k
uf-f!J
~k"b}g
sM)onT7
ZTMO;m
P/P<I7
L%X+om
p}K#
Hj-1H0
{Fqq|N
5z4uKa
f9""21Qg
@UJ79X
j[QRe^
6H`[4gb$
n?{k5ZT
5Ag/~?
kO1V^P
[{fNm^
R3-\>4TA
Z1gJ`j
kl03?I
v:3U|Sa
f[e~m|@
G;CEJ&#s
N0 @wx
X|+7Cr[
Ro(pDM]
.J1y;U
Qw7(0<J
dq%}1z,
%Z;|*n|
zPJ/d`
UqArk'
,ihEx#
U^6d!TT
Y\/IXu<
5)+"qs
kExQ%$X
)nxozW
h%gR&U
ZL3:]s
/F;s~
"8Xkpy2
RKLE.c
bA.x4Ay
~|^i(
Jno>(]
2Urr1o
"}UzxN
&R^%$Q
sl=~V
|ieT!9
.42|,jSS
eH+-?pl
kVk]2F
yk#04<
0?h4Z\
XsUup
pggs)
-wzjGT
5*oxamDY
`(sXH;
MK<F1RQ
rnpu{c&
csH-_
'>^E-e
;DanhJ
3DC;&9
rA12?\,
jD"+8y
S1It"
;U#9n!
$YL6B{
r#W$j
5(7'k-
YCO)Co
b<K}yE
S#b2VI
{p<"n-
f"Wd_x
-C$=si
lHp?HKC
`qC8r
x)L!>]~
?1WEY3
,k%aPR
+91nIL
x';W<1
W6HQ9-`D
i:WI%q
\<7orBB#
+l$AiB
u%0*$j
[h<F!~L
1MSv>Ht]
<@a'$@
i|js$r
XW#'\,
|OL JS
B18?6.N
T9W0K/
^+knpM
i=a476-m
Hxfsx"h
ALa{(n
IrrId}
Vz/r[\
m4Mbdr
sg=P7C
b3*9(4YR
a`FiBX
<Oeo6rp
zmfQF>
?YEcmX
^`pQc
G kUu$
5}CTy85
6u6BM_
lhPz<7_`
R[ ^Qa@
eOKJ\
Evi03 '
PWK{J6I
bS}N0_&|
ZCrEh-bi
Fd0L#bo
hl<uo<
z?-/Y'8
ZZy;Ul
+3f4HK)
[i\Eh
cbMQc@
qIkP'!
.kE@V|
u?v))7
y+#!Agl
Eh~q#(7
9g;`tY
;Xava`
l21K)+D
$}*p1{
]=q3gP
55m,7.
87dsVY
;bsv!0
nVq@"R
S4hnL'
wL{C;_i
KjP|W^:
`"x";_
N}ZDL5
6X=3FZ
&+1:[-[
pij G?
C4Y1*C
p.g3p_
4F(qiw0?
_hFN4h
:;aC&>p
H.7$I%
,#bF.,R
.|8q>J
*fc]r~
,Ok!k3
7<3>16
o?uN$Z
vGBEaY
qWtBg%
.dQ|/
iDPU)O
\9uOqa
kE | e
Oeyp/L
HN^9m@
!^`s|Th
(FQyM[
@-btUP&
wT7`G:q
{Q 8Ft
TbLJG|
s+ b]
j=,s[%3
Uz&]Sg
ZHDp*2l
&hIBOzL
xRCm5K
RwPZ"7W
,SALd!
kkyJ\%zf
b#KtW0e7
B\/hql=
Er>o0c)
:Dr/.o
5gfmj$
VnlShu
Q,xaPJN
MqGJ{g{a
7bAf5
G7P}AL)[
9g788i
}_`_<;
3rQ]({
u&9c<;
5L%e?S
>yp/R$<
F]Gt1o\
3Y,:Jr
GM$v:7
S3?9ug
sb4p@pln
:-Q>~:
X1g6iWaI
C=O(O!
?]2bQ}m
S+]e\Bt
c-xsV6pe:
f'[|OX`
HSX*:G
wxg -e
ePj%iV
j=D_x>e
PjWK8X^
<#th_j
0DJDLd41L
w;eWu[
IS1<GI@
!v=v`nJ~
0?C&o
PViXs#
8f{?\!(
;24Y:WuUy
B[a5vd
4O]Y4!
uh ^hf
$x,Ji<
7@Vk*'
h^ft@2
Vk7cm*
p+P{NX
o79?;M
o|Tr/F
(X|J[o
)yQXfE
L@;`=gN
/sN~be
B;yBUV':
/|~_E3
C-2S<I
~qQ#ICpw
9Vd3jt
j`=}r@
{EwPv~
GF[f-2O
=Q"DKP> X
_){V0,
'S>2*-n
h%aEsU
UT)zd~M
Pin-zL`p@
-$EIjM$
pmZw*7
%s1s"/
KtBfvRf
$%9vY:6
~nR>Bu
^Ei)+f"nz7H
IDUebr
b]bRI
:]e(du
Srdpw,
Gn]8jq
71G$j~D
6T-1=Y
zdS|kKU
6F&&Oj
yV0vIk
vmzAPJ
9o't6"8%
3-p!];
}|~> #
-}.X:ci
l1&%X&
FZG<(%
"Iu$Jd
jgWUQk
W:A{Xgt
~8g,!?0
e_gR|0
']i7$f
0sYA,j
~Oa:)i
#N!Ou<$ZDW
VdgnP1
&qt".}
fwRh?
twZaea
p!0$y@!8
:zz^Tm
(^sZ9|
sSfe^2
BVn:r
(b3msT
dw>66@3
RFK!!fb
\>_fp[
~;Vu6*
r<"CG-e
FoCAs'*|
\/f>n"\H?
?a3vWK/
u<zdD4
@vo(63
vOf{;C
TIb^(5
3-f?{
DL>v^u|
<2v<s0
"%wY)F
#G|[tT
EC|iq
47VhxvIp
rWz=X3y
f?W,U[
Rj!af%
d9e/IRVD
>Ss`U6
AM;}kN
il@e<En
S^/]w3
$\1p1<
D};`&C
F5_]c-
GHfa[]v
Fg|v5*
q"G1-5
+Ic%t[
l/roKs_
?/$CE[
_9fQyF
C8hHNsk
=a.Lxde
JgHeHg5
;u6f4P
-\Nph_
R$'ju=y?.
^coQg/q)F[v
QL3mf|
'Ek;|=7
bV!:NO
TTv_j5
-A3mIh8
^kT0{Qd
|JE*HF
fUfL$p
qM1eOqi~U
|K%;xI4
sUfo"~
a8"5a&
BM+G=@#
h1d&yg
Vza; q/
!F6088|
$KY]Q}
4J)MgE
9-826Z
j<*1tC
(>D+mX
#[!I?oB
r0O6e_
^%|ng~
d]OB}'
|-vw8'\
Yq[tF>S3U
g(N!E
6ujiz]
n\KZ5Iy
wnq(NX
Uhm,/K
B?ngF!
^~io`7yfz
C@ew~
hkFwqU
lX5dhp
,J5^,^
]$<IKW
)u(vV
r&\Of$
_yPP%B
Z<E;jP
Gf0{fY
,|aI_T
Z"%DCx`E
Kd*>HEY
f`'l<0w
4^oX~f
F5(1KA
-bzK:D
S[+[Um%
jlHBX k
xRj6vd
L\?k7,
P&387
!xa0D1
P[|Df6
l82~1i
FSKvt2
?{D9(Q[OL]
}hDA|j
{q%HWS)`
.J/^.?
s}j<>0<~i
aYuK1
4P;vjY
$8'8bc:
vOSjq@
Oql+*B\
T|bZLaJ
jwP|]D
R{mauK
26%AJL-J
i=*;)V
oTe++Y
|>(jn`
"W,&:%p
9K%rS
C6 ,Ik
J\Z{3t
O8$dp
D5L"=_
}}[QP*
\S*Eo"^
;,o3ViE_
rP{Y-=
2 3\2a
IYGCkP{
38%A;3J
:Zu8a5z
4E`yX]v
;9U=YS
hG">)y
goy+1/
y*vez:
c\JNJbz
5IT5#h^K
@"/F1cBX
*Y^&gZ-
xqPIPq
>&~b]}
`Asd{UK
cqETb&
xc9}@K
To.&;As
#9vmxDQ
~TF)uK
&No2D8
@p$aQ,S
k BH]eE
hyINu,
ndc#.r
y,8ES?
(0:]j1T)
V+4Y5V
3hJ>%F
Wp,m +#
P6U*uG
!hb 7I
;%Yi_K
Su&Ue|
Q\.g@y
7EN3XtX
G:|*,!
iS@R.^cR
/_0cZ'U
Sw0S5R3
FWN9$Y%
ckYBfV
OO91L&
!$l]B#
iuk^?
ok'7h'
aKJ!1
19,qKD
hk;YJb
6I { I.R
U@6+-Q.
>we=@#(
=Pbg2c
jm}\$B>
N|^%Xs
O 5oB-
8I;om=l`
4zrPQqA
qRX!g9w.
`ZCW% y
?d:Z<d^
8;becg
leJ<&6K
LM$xH|2~
"CPCne
`#1JOI
JK\'ZV
`_N%h|
V7f3e
pR*j*W
;b1/_Ml
.S=S]U
=YPIra
e[F/~B
I1!7#)
*fnI=wW
[=~5UB
;~{)F/M
@1Oo;rE
y%m@8/
h)}JQ:
k<[)zR
Q*yI=S
~kbOHE
ah!&_b&NC
}g>*'
Z$@}[@;(
<.'I[Qx
kYOoL,
UjN+J:
"gS>*9
il'}ej
{h#xN"#=Y
j4($pF
{_|p]v
&2+)TU
YWTxNp_
=LA}HIE(H
'])*)m
+Fq"cU
g@3\sb>
<+O~'6N
d.NH;}
8dUB C
ms*ju
nWEr`#
Iw8iq
0emc8AA
h'7Yde
]Sj%bm
"Mm9a;qi
jaz,F,aN
r=cdhj
O1^:^f
BR2kW[4q
hx2,,Q
;!>W2>o_
}O=zl'
;NR;mR
oqewSV
.:0Iis
/4vHX%
UC9Unv
R)x1.K
iP^sjQ
z{OFoU2
<cEy87rk
_&IPnM
q5AGV3
xKZ\3
bV7}"R
FWrBMJ
j|wj/R
{t'<r}@
2,V>Glo
",m~rQEw
bbtfl
=i]AS{;*z
\&5 `^
%GlOS.t
n(Zc0MH
[}24oI
ER5oBQ
CP6$F?
oWq"j4
@O>k<@
qZMByA
UH@"SG
q})f=k
CSNX1"'
/LntZK
p CiwUs
TQnEqEt
/\kNF~7
f{",t5
o;8oYI
j`1gB$B
IBf8Y$
c,Kc-(.
]T}~G7
sb(O%}
~+%5m%w
/cU-h:
tW|,^N,
(gT[Cm
xU1+Lu
^G{y"[
'apUCt
/rIN%@:
6Wf2To^xW
sADwg[
!zQo~1
VJ)`7'
udz]/Q
j'oZw~
3y`fB|
f{lu:h
f73TPB?
x&c[dsY
F("hFo
{sK8vW
4czZ"M
bAZr1/(2
O6j~|;
G[<S>*
2{*MH
%d4z9Q
l3XJt4
@vxBNz
3"_9>W
e]s]d]
MGz&#^X|n
.9VnOf
]gq1#@4
tU"t!I<k!
&J>:KI
[p{W:It
$Bw{l&
fV,*cY
\6fnX*
q]b mV
>p4P?"
_n)<;F
;!sk["
Pt470
<|X8CG
x3V-K*
5.\xObV
4kQS2@
yQCwKX
@IaPR:4
0@f3
@rPS/
?'2Z_a
$e$r|3p
N (A"0
m)A2F
oo<4'R
Ec>*QVt
Axb-PS
0}V'?M
FqL-<4
NPRGp'
?"TW=gO
23YU9q7
GnO_asL
Sws^hY
>/xF??ht
fDDn!`:
(kc#k
{8Y]JN
KM 1ps
)$/?8M+_
P!q)+o
anD+'X
6VLz8b
0"~BH[X
#nj`x D
mV;ssA
cjEw<d,]
1.*'##u
0~.ym\
tuSr_5
$G/BTCa@
.x!EM[
#qqTjO
bQIb_1M
VNUjn(
H RG w
8YKs#F
"?[tpm%
7f?]8-
a9~Jbz
G0kl'W
`1U33_
n/4(^;
>^/Za7
46(]i$
+oG;A,
hd!2mM
Kg Vhr"
.Gl=$<
';u'vg*O
?D2FtJ
HKK|I?*
_-7I]K
I@~?*z
@,8j*cR:
Q\wZv)NT
'Eed=S
9f9Kp1G*p5
[>%3z(
-Jqthz
1VKjE3,
HjIE}
2'G_(
58hUkXOgfW
H0&wdu
Xj%&"D
5#ta)j
m>bV+X
ZdWVyP
0xyoW%9Ua
IqF=s8|
7l3IJd
9e(Wj%t
F:#Q~(
MF<^zU
kwH!QS(S|
g|(8si
)?le"Py
Q}E6V5
h|@mvC"l
`;t{5Z
hDpKliQ
'xPo=}
,{U^tH
vcyR4#
0IheE!
lfXh4pD
;f\o 2[
,R5b.Gt4
[m0^Gf#l
uiBG0N
:~&:Pz,
KoJ4){
2{L4sBF
drf7ScP
#&KrJx =
ehUb\N=
?Y'-{*
#J\Y~f
"i{>T%
qURU77
,OytCc
=<N* j
I5/1b1X
;AZF~
':*3ZxK^
W.C?aSB
$;kV8vg
qm][vR&
N5`X^i
"~ rc
]I^J35
{F6fa
fzxm=c ;
aI,Fo0
gA]sWH
__:<Kj
{4Ry""T
Wb1Ej<]
#P`W9GXX}
":vt4K
LKwgd}
Pb^X|V
<N,XFp-
gwMc`|
hmee=f
4d)@7*FP
L/4*d'
,%Y317#-
z@}c1o
+vcplSc
e?(Ff:
@+Xm C
?g`f)D
sl:_R5
Yv8}~L
cX`=5k
S~{\+o,p
p1\hfvHt^N
{JT`&y
H1f.;mG
#t#Q^g
U7f08o'
LhXHB/
c,UHs$
DE-6F
L9xG-[>
<CPXq
0n<1,W
bD^h$v
{*E[|^
!/QQu%vv(
vC@W6A
?3j("D>
\8o'A
PYfZiyH
<739N=
RoQc~KjA
*R9Iuq
0q|,l!fS
<?Et=?
Q#5s,5
s=6B2`
L'C/Wa
9EsHhe;d\
Ukk^8)(
*c/tn"K2y
R^a}4?
7}IF@Hx
`e@bM
/zeqox
5Jc{N#
Y;<2mN
C\.FQXW
x8p-IF'
0/fHO{
[eUhAI
UO'\OF/
Dn5^=)
j?v>P0
J4![Ds
A'KG*n
k}z+Cf
PT5gG.r~
_2ny9y
0VM=UP
xfY"<w
1@j/#Dy
pL2B|Q
5})t`p
`K6;"[]
5#OVNO
glSv`.
"az{O?B(
K`+/h.
s72Xk"j
L&%O")
@Tqe7U1
O^72p('
s4=$S*
"6`~o-
v23cMM
&H3-og
u71.H#
4zB>jy
9M%{?Uh8
d~7+G^O
A}8j7tJ
[m[;!HE^
4FCG=Vj
D)'aI?D
#q xTM
|WxG[p
:DK}f7
S9C*,&4E
rP32j;)
r[oysm
%*Yy,pg(4^C
KKrmaL
VXaz9]
qK3A^m%~t
B3-WhE
H;i]M<
] t&iN
!)VI>,U
fT)NPm
NCbkcE!+
nS]m=s%
5~#W4+sc
(cy@W`
AbX?rH
7,u|PF
zRrr2|
dl.\*=
|js">*JM
fcB2\Y
;7ecUV
wY0`c
,#S6,uOUz}
Hq<pzG
_h i,0
a}$JyN
p~#T{y
A8lG^A
Te^a@^.
Ud*^*!>e
qWKt:r
OE7Hu'?s
@*:mt6
gU/KQV
g5FtHn5O
=$8<y=>
z9Ka rq
xOwz5]
beVNu39~+
~Em._U
_+i'p\
PmP?iD
KFd$L6
ee|B:&3
KUBt=O
L)=6pt
l[OUP|8
+aq8wM
!8oRDG
T'`&O>
IcEvx+!5r
uA/.*d
bk{,S
i52<&e[Y
^cgv~=
v<ts;7
cMs^5U
z?Mk9/
ZE_^7u
h3tZMyd
)Wg8n2
_>,po/^
Y&RUk=Jb:Er
I6o"bC{
z,v Rc
QoSUq!g
&0)"w>nX
@s1tJ&
M@pOvIMf
Jk,wh%
;?<a-Jg
^2RBm>bw
SN`$oV
:+|'3~"tI
Lunp[#
7BC+-b
pX#5;Cnqm[
zaT%8k
WE G0{
;}qO2R
Zf,@RJ
j&U2EN
]EoY6|
/+.!Gm*z~
A1 SI8^M
n"DSl[
lhjp]Ym
`OBFNz$
|y6Y{%
$#:Anz
7^UQE#%
".iS8
y^e V(
{k<'6mo#
8uU'0\
sh*G+Kx
^-t"@6
L&@/!J
4#{t#IA=
gsInZGJ
yl\S%,
2_Jg4.+r
W=ZS%!
BTI-IC
=gK.m
1^ov'[>
]LseRZ
[SPu^R'
TE}v(.Y
<_Yhg$3w+
or<=sK
C*]8 <
Vc6Mx
!?3frt
x4sW2R
4\]84V
:TUwID
+MYss`%7
{Vh#hS@
u a]'<(
eK_2Pk
A&;:z.
I[v.ab+2
>Rt4B`
s+@V~ivfzZ
R:Zz+PY
gcknf0
M)gYh@
gQG0eO
=_kk^b
*nxO@I
yJM6<z
2Ksa6wm
6L6ork
[< X]/
MX6epEVG
6u8^%-
%,Nj:^
PJY^W!
`RCTbDV
csz+O;
BcKhZwK
Q\/hKY
UI\."G
xG_+1e
&ZH8ec
[f.l>F
)E>Pf5
YK_ 0z
!WcnUla
B%z*+m
GY3b%!z
C>brS)
bezY8Y
2wfV-[h
@L5iY}
R,.Ml/
ta/F-b}7
0@]Mxu
HP`\%o
@}MP|`
[&asud
;<CmlJ
H+fnjk
axH{s.
uI<yBmY0Ini
LM3i"&
Xe@r6~
dC6%h\
9HU/k
Z(F,\.9
(t.bVq
d}>_-Ew
U9D|_4
,):7+(
cEng1N
&il'v#o
`?HjUU8F
/zT9B:
H:cztu
kRtmWy
P;i! j_
va=s+3
O QH`Q
ArB7=Kd
2d!wu!
V_v"]t
>[2bcTM
C=$*fA
Lg&3'-[
KR4z?4vY
h.QOq-'U
oI4TX]|=KW
KF36s,
.M0Q^}
-@K}(<
tzkembv
we02G^*
z!<)W?
yeMp['3)
[nh7i]X
_ -g"R
R0CICV
| 5|BajS<
FzT%#c#@
+z"&f>
JEp!$Aa
NkpMn8c
s[x_E(
aK;Ve64Q!G
[8EUjr}
HTB,nK
*$;u6=
fETjIN
j::"ZP
$.!r[GC
|Yk^a!`
Zy%uF4
/lwK[I
cQh}ZRD
$p1Jlre*^Q
m=M+GQ
$FZEFnW
qz?tR'
*EuWa@
O`tx'
|>|yUw
H.r('n
L#qmr`
3i3c8}<6
j"75F1
3h<Xu&
3GWLDz
6$cG<U
5QvPc
:mLJw>"
c&EW#(
(ndN<]
hF0I<d$w
7 z{@{
z~a%yr
[|/cx[
-n<LX8F
>U&Irp
F:/uk?
zg`;V6|
F<QJE#
8x^1e"
:qp5'-
5?dK9( '
}AoP>,
/DHIH
>1;&^M
4Ae{wI
RzHlj`
mT^bN
eotvV/
V>A)Pu
$\VI7]
,1{&!#
]cN*k[
<1e.s-
{cl"DM_hW
B8?-w=
B9{>br
)>L(wW
zd2KMf/b
LNnPmv
qPF(-1
15!>Z\
a"Bxu2
lp*|cY
-aw}%r
ofS,-3
{sQ!,B
:8~,wt!>0
#pbMcQ
!xok^eh
#6n2;t
I'wFb7;
A>_JNA:
{E%^=d
r9_lxr
!SJ6H/]
g]rVY5Ib
Q\K@&%
m7`=0p6
y`^554Z
[/Q_i_@
@Rr)"2
qbc$tF
eATs!
r:o?+$
fm?n^y
>(boob>
92sa%@K
HniViA
C`k3^P
4*q|z
M0qCkR!#
6o~Zmd
rTn%61_{T8j
ka\xR.
vF:Tg|
bz G]Z
XM~fW_
Y5"F%b
*e5HRC
rTae2?4
&f7hc=
:{$+)_
OtLBaG19
x5s*ed
XrDZK<
H-jC)4
'&~*J:
YQHB["
}9c"Qpx
a)fKI,
pVRtlH4
Il^vV
`U) _u!
Q?H'"Wp"
6,Ad{|-oV
8rGm%_G
@VaRe
"Hs?MA
"Y)^2T-<
((((( H
dKERNEL32.DLL
dddd, MMMM dd, yyyy
MM/dd/yy
syr-sy
February
January
Thursday
Tuesday
Wednesday
Saturday
Sunday
Monday
Friday
div-mv
August
zh-cht
HH:mm:ss
zh-chs
October
November
September
December
smj-no
sma-no
quz-bo
uz-uz-latn
az-az-latn
sr-sp-latn
bs-ba-latn
sr-ba-latn
uz-UZ-Latn
az-AZ-Latn
sr-SP-Latn
bs-BA-Latn
sr-BA-Latn
kok-in
uz-uz-cyrl
az-az-cyrl
sr-sp-cyrl
sr-ba-cyrl
uz-UZ-Cyrl
az-AZ-Cyrl
sr-SP-Cyrl
sr-BA-Cyrl
mscoree.dll
sms-fi
smn-fi
kernelbase
smj-se
sma-se
quz-pe
quz-ec
syr-SY
div-MV
zh-CHT
zh-CHS
smj-NO
sma-NO
quz-BO
kok-IN
sms-FI
smn-FI
smj-SE
sma-SE
quz-PE
quz-EC
api-ms-win-core-file-l1-2-4
user32
kernel32
advapi32
api-ms-win-core-file-l1-2-2
api-ms-win-core-sysinfo-l1-2-1
api-ms-win-core-fibers-l1-1-1
api-ms-win-core-synch-l1-2-0
api-ms-win-core-xstate-l2-1-0
api-ms-win-core-winrt-l1-1-0
api-ms-win-core-string-l1-1-0
ext-ms-
api-ms-
(null)
CONOUT$
api-ms-win-core-processthreads-l1-1-2
api-ms-win-appmodel-runtime-l1-1-2
api-ms-win-core-localization-l1-2-1
api-ms-win-core-datetime-l1-1-1
api-ms-win-core-localization-obsolete-l1-2-0
ext-ms-win-ntuser-dialogbox-l1-1-0
api-ms-win-rtcore-ntuser-window-l1-1-0
api-ms-win-security-systemfunctions-l1-1-0
ext-ms-win-ntuser-windowstation-l1-1-0
Antivirus Signature
Bkav W64.AIDetectMalware
Lionic Trojan.Win32.Lumma.1u!c
Elastic malicious (high confidence)
MicroWorld-eScan Clean
CMC Clean
CAT-QuickHeal Clean
Skyhigh BehavesLike.Win64.Trickbot.dc
ALYac Clean
Cylance Unsafe
Zillya Clean
Sangfor Trojan.Win32.Save.a
CrowdStrike win/malicious_confidence_100% (W)
Alibaba Clean
K7GW Clean
K7AntiVirus Clean
huorong Clean
Baidu Clean
VirIT Clean
Paloalto Clean
Symantec ML.Attribute.HighConfidence
tehtris Clean
ESET-NOD32 a variant of Win64/Kryptik.EZV
APEX Malicious
Avast Win64:CrypterX-gen [Trj]
Cynet Malicious (score: 100)
Kaspersky UDS:DangerousObject.Multi.Generic
BitDefender Clean
NANO-Antivirus Clean
ViRobot Clean
Tencent Clean
Sophos Mal/Generic-S
F-Secure Clean
DrWeb Clean
VIPRE Clean
TrendMicro Clean
Trapmine Clean
CTX exe.trojan.kryptik
Emsisoft Clean
Ikarus Clean
FireEye Generic.mg.f258ba9ca646b974
Jiangmin Clean
Webroot Win.Malware.Gen
Varist W64/ABTrojan.UQBE-1824
Avira Clean
Fortinet W64/Kryptik.EZV!tr
Antiy-AVL Trojan[PSW]/Win32.Stealer
Kingsoft malware.kb.a.990
Gridinsoft Ransom.Win64.TrickBot.sa
Xcitium Clean
Arcabit Clean
SUPERAntiSpyware Clean
ZoneAlarm Clean
Microsoft Trojan:Win32/Wacatac.B!ml
Google Detected
AhnLab-V3 Trojan/Win.Kryptik.C5748808
Acronis Clean
McAfee Artemis!F258BA9CA646
TACHYON Clean
VBA32 Clean
Malwarebytes Crypt.Trojan.MSIL.DDS
Panda Trj/Chgt.AD
Zoner Clean
TrendMicro-HouseCall Trojan.Win32.VSX.PE04C9V
Rising Backdoor.DcRat!8.129D9 (TFE:1:OfHhlSV0GZG)
Yandex Clean
SentinelOne Static AI - Suspicious PE
MaxSecure Trojan.Malware.300983.susgen
GData Clean
AVG Win64:CrypterX-gen [Trj]
DeepInstinct MALICIOUS
alibabacloud Trojan[stealer]:Win/Wacapew.C9nj
No IRMA results available.