Static | ZeroBOX

PE Compile Time

2025-04-06 23:52:47

PE Imphash

d7df155ab6f6974888ad50c6d9e3480f

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x0003a6ea 0x0003a800 6.98847111589
.rdata 0x0003c000 0x0000c0bc 0x0000c200 4.95064808963
.data 0x00049000 0x00002718 0x00000e00 2.30928178386
.pdata 0x0004c000 0x0000177c 0x00001800 5.45789795896
.BSS 0x0004e000 0x00000396 0x00000400 6.26771171898
.gxfg 0x0004f000 0x00001470 0x00001600 4.85086787783
.retplne 0x00051000 0x0000008c 0x00000200 1.05058324797
_RDATA 0x00052000 0x000001f4 0x00000200 4.21715429019
.reloc 0x00053000 0x0000076c 0x00000800 5.30135933327
.cSs 0x00054000 0x0005cc00 0x0005cc00 7.99950135193

Imports

Library KERNEL32.dll:
0x140045f48 AcquireSRWLockExclusive
0x140045f50 CloseHandle
0x140045f58 CreateFileA
0x140045f60 CreateFileW
0x140045f68 CreateThread
0x140045f70 DeleteCriticalSection
0x140045f78 EncodePointer
0x140045f80 EnterCriticalSection
0x140045f88 ExitProcess
0x140045f90 ExitThread
0x140045f98 FindClose
0x140045fa0 FindFirstFileExW
0x140045fa8 FindNextFileW
0x140045fb0 FlsAlloc
0x140045fb8 FlsFree
0x140045fc0 FlsGetValue
0x140045fc8 FlsSetValue
0x140045fd0 FlushFileBuffers
0x140045fd8 FreeEnvironmentStringsW
0x140045fe0 FreeLibrary
0x140045fe8 FreeLibraryAndExitThread
0x140045ff0 GetACP
0x140045ff8 GetCPInfo
0x140046000 GetCommandLineA
0x140046008 GetCommandLineW
0x140046010 GetConsoleMode
0x140046018 GetConsoleOutputCP
0x140046020 GetCurrentProcess
0x140046028 GetCurrentProcessId
0x140046030 GetCurrentThreadId
0x140046038 GetEnvironmentStringsW
0x140046040 GetExitCodeThread
0x140046048 GetFileSize
0x140046050 GetFileSizeEx
0x140046058 GetFileType
0x140046060 GetLastError
0x140046068 GetModuleFileNameA
0x140046070 GetModuleFileNameW
0x140046078 GetModuleHandleExW
0x140046080 GetModuleHandleW
0x140046088 GetOEMCP
0x140046090 GetProcAddress
0x140046098 GetProcessHeap
0x1400460a0 GetStartupInfoW
0x1400460a8 GetStdHandle
0x1400460b0 GetStringTypeW
0x1400460b8 GetSystemTimeAsFileTime
0x1400460c0 HeapAlloc
0x1400460c8 HeapFree
0x1400460d0 HeapReAlloc
0x1400460d8 HeapSize
0x1400460e8 InitializeSListHead
0x1400460f0 IsDebuggerPresent
0x140046100 IsValidCodePage
0x140046108 LCMapStringW
0x140046110 LeaveCriticalSection
0x140046118 LoadLibraryExW
0x140046120 MultiByteToWideChar
0x140046128 QueryPerformanceCounter
0x140046130 RaiseException
0x140046138 ReadFile
0x140046140 ReleaseSRWLockExclusive
0x140046148 RtlCaptureContext
0x140046150 RtlLookupFunctionEntry
0x140046158 RtlPcToFileHeader
0x140046160 RtlUnwindEx
0x140046168 RtlVirtualUnwind
0x140046170 SetFilePointerEx
0x140046178 SetLastError
0x140046180 SetStdHandle
0x140046190 TerminateProcess
0x140046198 TlsAlloc
0x1400461a0 TlsFree
0x1400461a8 TlsGetValue
0x1400461b0 TlsSetValue
0x1400461c0 UnhandledExceptionFilter
0x1400461c8 WaitForSingleObjectEx
0x1400461d0 WakeAllConditionVariable
0x1400461d8 WideCharToMultiByte
0x1400461e0 WriteConsoleW
0x1400461e8 WriteFile

!This program cannot be run in DOS mode.$
`.rdata
@.data
.pdata
`.gxfg
@.retplne
_RDATA
@.reloc
AWAVAUATVWUSH
HcD$\H
[DiT$X
HcD$<H
%KzdSA
h[]_^A\A]A^A_
AWAVAUATVWUSH
X[]_^A\A]A^A_
AWAVAUATVWUSH
=*H=qu
[]_^A\A]A^A_
AWAVAUATVWUSH
8[]_^A\A]A^A_
AWAVAUATVWUSH
HcD$lH
D$x;D$8
HcD$lH
D$`HcD$`H
D$hHcL$h
tv=ZJ
Hcl$xH
[]_^A\A]A^A_
AWAVAUATVWUSH
H[]_^A\A]A^A_
AWAVAUATVWUSH
%?w[x1
[]_^A\A]A^A_
UAWAVAUATVWSH
G#"&!H
<QsVmI)
;z+`^uH
0IH$%2K
ixOSV^
AF~i=jBOT
[_^A\A]A^A_]
UAWAVAUATVWSH
[_^A\A]A^A_]
AWAVAUATVWUSH
H[]_^A\A]A^A_
AWAVAUATVWUSH
=2`8.~i=r
=3`8.t
8[]_^A\A]A^A_
AVVWUSH
b@t,=xgK^
0[]_^A^
AWAVAUATVWUSH
8[]_^A\A]A^A_
AWAVAUATVWUSH
8[]_^A\A]A^A_
AWAVAUATVWUSH
H+D$0H
H[]_^A\A]A^A_
UAWAVAUATVWSH
[_^A\A]A^A_]
AWAVAUATVWUSH
BAtG=1Z
=Mg.Iu
=Mg.Iu
x[]_^A\A]A^A_
AWAVAUATVWUSH
BA~)=*
BAth=1Z
X[]_^A\A]A^A_
AWAVAUATVWUSH
QDOt+=
H[]_^A\A]A^A_
AWAVAUATVWUSH
X[]_^A\A]A^A_
AWAVAUATVWUSH
H[]_^A\A]A^A_
AWAVAUATVWUSH
H+D$(H
H[]_^A\A]A^A_
AWAVATVWUSH
P[]_^A\A^A_
AWAVAUATVWUSH
$}Rt9=
H[]_^A\A]A^A_
UAWAVAUATVWSH
[_^A\A]A^A_]
UAWAVAUATVWSH
X[_^A\A]A^A_]
UAWAVAUATVWSH
[_^A\A]A^A_]
UAWAVAUATVWSH
UAWAVAUATVWSH
UAWAVAUATVWSH
AWAVAUATVWUSH
X[]_^A\A]A^A_
AWAVAUATVWUSH
X[]_^A\A]A^A_
AWAVAUATVWUSH
H[]_^A\A]A^A_
AWAVAUATVWUSH
8[]_^A\A]A^A_
WATAUAVAWH
A_A^A]A\_
sH9.tgH
9D$(}LH
sH9.t&H
u/HcH<H
WATAUAVAWH
A_A^A]A\_
D8L$0u`A
VWATAVAWH
A_A^A\_^
WATAUAVAWH
A_A^A]A\_
H;xXu5
WAVAWH
A_A^_
kL@8o(u
D$@H;F
<htl<jt\<lt4<tt$<wt
UWATAVAWH
A_A^A\_]
x UAVAWH
S(HcS0
S(HcS0
S(HcS0
WATAUAVAWH
0A_A^A]A\_
u3HcH<H
UVWAVAWH
0A_A^_^]
WAVAWH
A_A^_
WAVAWH
A_A^_
WAVAWH
fA9,@u
fA9,vu
0A_A^_
p0R^G'
p*W4H
p*W4H
D$0@8{
LcA<E3
UVWATAUAVAWH
A_A^A]A\_^]
D$ I;R
D$ I9P
SVWATAUAVAWH
0A_A^A]A\_^[
@SVWATAUAVAWH
L!|$(L!
D$0HcH
pA_A^A]A\_^[
SVWATAUAVAWH
A_A^A]A\_^[
SVWATAUAWH
L!d$(L!d$@D
D$HL9gXt
A_A]A\_^[
B(I9A(u
t$ WATAUAVAWH
A_A^A]A\_
WAVAWH
A_A^_
AUAVAWH
u4I9}(
;I9}(tiH
0A_A^A]
AUAVAWH
u4I9}(
;I9}(tiH
0A_A^A]
WAVAWH
@USVWATAUAVAWH
A_A^A]A\_^[]
@USVWATAUAVAWH
d$dD;d$l
A_A^A]A\_^[]
UVWATAUAVAWH
`A_A^A]A\_^]
UVWATAUAVAWH
A_A^A]A\_^]
UVWATAUAVAWH
`A_A^A]A\_^]
@USVWATAUAVAWH
A_A^A]A\_^[]
WATAUAVAWH
A_A^A]A\_
fD9t$b
l$ VWATAVAWH
L$&8\$&t,8Y
A_A^A\_^
t$ WATAUAVAWH
D!|$xA
A_A^A]A\_
L$ VWAVH
{ AUAVAWH
0A_A^A]
t$xt*3
x ATAVAWH
A_A^A\
t$ WATAUAVAWH
gfffffffH
A_A^A]A\_
WAVAWH
A_A^_
L$ VWAVH
fD94H}aD
u+!D$0
@UATAUAVAWH
e0A_A^A]A\]
UVWATAUAVAWH
H;\$8u
H;\$8u
fE9$Iu
A_A^A]A\_^]
WATAUAVAWH
0A_A^A]A\_
H9>u+A
D$0H9D$8
WATAUAVAWH
A_A^A]A\_
vyfffff
vyfffff
WAVAWH
A_A^_
@UATAUAVAWH
A_A^A]A\]
@USVWATAUAVAWH
H!D$ H
xA_A^A]A\_^[]
VATAUAVAWH
0A_A^A]A\^
UVWATAUAVAWH
fB9<I}1L
A_A^A]A\_^]
VWATAVAW
A_A^A\_^
@USVWATAVAWH
A_A^A\_^[]
SUVWATAVAWH
A_A^A\_^][
WATAUAVAWH
0A_A^A]A\_
ATAUAVH
L$ fff
L$ |+L;
A^A]A\
VATAUAVAWH
0A_A^A]A\^
fffffff
fffffff
ffffff
fffffff
@SUVWATAVAWH
@A_A^A\_^][
ATAVAWH
A_A^A\
USVWAVH
A^_^[]
fffffff
fffffff
fffffff
ffffff
vKfffff
fmST^UMIfwSYHUIU\N
nf|H[W_MUHQfL
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
[aOni*{
~ $s%r
@b;zO]
v2!L.2
UUUUUU
UUUUUU
=imb;D
/>58d%
VM>cQ6
>jtm}S
)>6{1n
+f)>0'
;H9>&X
*StO9>T
n03>Pu
K~Je#>!
bp(=>?g
BC?>6t9^
K&>.yC
.xJ>Hf
y\PD>!
|b=})>
c [1>H'
uzKs@>
3>N;kU
kE>fvw
V6E>`"(5
?UUUUUU
?7zQ6$
Unknown exception
bad array new length
string too long
Sunday
Monday
Friday
August
__eabi
new[]
1#SNAN
1#QNAN
(null)
dddd, MMMM dd, yyyy
MM/dd/yy
directory not empty
text file busy
device or resource busy
no such file or directory
not a directory
is a directory
not enough memory
February
January
Thursday
Tuesday
Wednesday
Saturday
InitializeCriticalSectionEx
LCMapStringEx
stream timeout
timed out
invalid argument
operator co_await
connection reset
network reset
not a socket
__restrict
file exists
connection already in progress
operation in progress
no such device or address
bad address
no such process
no child process
CorExitProcess
success
HH:mm:ss
too many symbolic link levels
too many links
no stream resources
resource deadlock would occur
bad file descriptor
operator
executable format error
io error
unknown error
protocol error
October
November
September
December
network down
no protocol option
bad exception
inappropriate io control operation
bad allocation
argument out of domain
resource unavailable try again
too many files open
too many files open in system
read only file system
not a stream
__fastcall
__thiscall
__vectorcall
__clrcall
__stdcall
__cdecl
__pascal
no link
cross device link
invalid seek
operation would block
bad array new length
argument list too long
filename too long
message size
RoUninitialize
RoInitialize
FlsSetValue
FlsGetValue
delete
address in use
wrong protocol type
AppPolicyGetThreadInitializationType
broken pipe
GetSystemTimePreciseAsFileTime
state not recoverable
address not available
no lock available
no message available
host unreachable
network unreachable
value too large
file too large
result out of range
no message
bad message
FlsFree
illegal byte sequence
no space on device
no such device
no buffer space
AppPolicyGetProcessTerminationMethod
identifier removed
operation not permitted
address family not supported
function not supported
operation not supported
protocol not supported
not supported
connection aborted
interrupted
already connected
not connected
connection refused
destination address required
__unaligned
operation canceled
permission denied
owner dead
FlsAlloc
generic
delete[]
GetTempPath2W
LocaleNameToLCID
operator<=>
__ptr64
__swift_3
__swift_2
__swift_1
nan(snan)
nan(ind)
NAN(SNAN)
NAN(IND)
restrict(
__based(
Base Class Descriptor at (
Base Class Array'
Class Hierarchy Descriptor'
Type Descriptor'
`vector deleting destructor'
`scalar deleting destructor'
`vbase destructor'
`vector copy constructor iterator'
`eh vector copy constructor iterator'
`managed vector copy constructor iterator'
`vector vbase copy constructor iterator'
`eh vector vbase copy constructor iterator'
`vector constructor iterator'
`eh vector constructor iterator'
`managed vector constructor iterator'
`vector vbase constructor iterator'
`eh vector vbase constructor iterator'
`vector destructor iterator'
`eh vector destructor iterator'
`managed vector destructor iterator'
Complete Object Locator'
`virtual displacement map'
`vcall'
`string'
`udt returning'
`omni callsig'
`typeof'
`copy constructor closure'
`default constructor closure'
`local vftable constructor closure'
`placement delete closure'
`placement delete[] closure'
`vftable'
`local vftable'
`vbtable'
`anonymous namespace'
`local static thread guard'
`local static guard'
`dynamic atexit destructor for '
`dynamic initializer for '
operator ""
AcquireSRWLockExclusive
CloseHandle
CreateFileA
CreateFileW
CreateThread
DeleteCriticalSection
EncodePointer
EnterCriticalSection
ExitProcess
ExitThread
FindClose
FindFirstFileExW
FindNextFileW
FlsAlloc
FlsFree
FlsGetValue
FlsSetValue
FlushFileBuffers
FreeEnvironmentStringsW
FreeLibrary
FreeLibraryAndExitThread
GetACP
GetCPInfo
GetCommandLineA
GetCommandLineW
GetConsoleMode
GetConsoleOutputCP
GetCurrentProcess
GetCurrentProcessId
GetCurrentThreadId
GetEnvironmentStringsW
GetExitCodeThread
GetFileSize
GetFileSizeEx
GetFileType
GetLastError
GetModuleFileNameA
GetModuleFileNameW
GetModuleHandleExW
GetModuleHandleW
GetOEMCP
GetProcAddress
GetProcessHeap
GetStartupInfoW
GetStdHandle
GetStringTypeW
GetSystemTimeAsFileTime
HeapAlloc
HeapFree
HeapReAlloc
HeapSize
InitializeCriticalSectionAndSpinCount
InitializeSListHead
IsDebuggerPresent
IsProcessorFeaturePresent
IsValidCodePage
LCMapStringW
LeaveCriticalSection
LoadLibraryExW
MultiByteToWideChar
QueryPerformanceCounter
RaiseException
ReadFile
ReleaseSRWLockExclusive
RtlCaptureContext
RtlLookupFunctionEntry
RtlPcToFileHeader
RtlUnwindEx
RtlVirtualUnwind
SetFilePointerEx
SetLastError
SetStdHandle
SetUnhandledExceptionFilter
TerminateProcess
TlsAlloc
TlsFree
TlsGetValue
TlsSetValue
TryAcquireSRWLockExclusive
UnhandledExceptionFilter
WaitForSingleObjectEx
WakeAllConditionVariable
WideCharToMultiByte
WriteConsoleW
WriteFile
KERNEL32.dll
.?AVbad_array_new_length@std@@
.?AVbad_alloc@std@@
.?AVexception@std@@
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
.?AVruntime_error@std@@
.?AVsystem_error@std@@
.?AV_System_error@std@@
.?AVlogic_error@std@@
.?AVlength_error@std@@
.?AVbad_exception@std@@
.?AVtype_info@@
.?AVerror_category@std@@
.?AV_Generic_error_category@std@@
p0R^G'
p0R^G'
p0R^G'
p*W4H
p*W4H
p0R^G'
pB]P67
p0R^G'
p0R^G'
p0VXNh
p0R^G'
p@\xV.
p0R^G'
p0R^G'
p0R^G'
p0R^G'
p0R^G'
RetpolineV1
RetpolineV1
RetpolineV1
RetpolineV1
7H9-N
:N@TGt
^5;4ON
[+~F-]_
0%K3_uC
C:d#pYA
B ehqz
ten:V6
f"/_@JH
^(*,uD
2/3~VI=
dnq[+G
B*Os5`J
hMQb8
w[e}x]$
>/&7,+
+:`({Ip[
FTSGjlo
?u_j}'
r*0;C
\W*Q:R
X< ;5;
dzZ&!
;E`M?1ap T
g4zZzH
)1#Yxk:`
B'SE=l!Sq
b{H<]`
4gS)jF
AI:3
s!9PS7
b cZ",
U6o]Y9
M/5\wD
!sm%~a
xJ!K*4j
L2PgbF
nKwE)\+JM
"wmpN,
5-$Q,\
k+].()
\v}5JK
r)e2V
0k?y6[
intlTa
!}SsNV
}O+JeN
z:bATd
@0,5}]
xASX"/
wcCXP@U,
(A4oQ<
9\#Dc>
0f?.v7
}sv<1L
4lviur
Zfr{rp
!83P;v
.$w*Sz!
r~b_pM
|Qo,:~
wXa7a=
@%Q>Uv
R]:CwL
O}\9UmYw7
@U/b`x
LyX{E`
sPR**V
Qyv*EC
]K;J$I
$d2W[m
E"?Z?R
MK@_<}l
~W,eBY
q%FkU
VXW?nC
vsw~`k
O~3qtE
ys.on!
l':R8f
.,%}i]K
3E3HXZ
Ya'NS
5J~;x%
1+}=*BN
g1W8fqY"
hGG;!p
nCh~Yn
z.'}`4
NSlSMuR
KrW6wG
J,G.,UO
)HR/GWp`
5*"7.v3
xcI0K0
;hkY9O
))?-t.
ZAm:/Gn
F.zpY6J
AP>ikh
1dtHx-
f1O;X[@
6}vU X
9;b!=n4
67+".V
J@jl?+
*"d%L`
Oh%VD_
T/G,,P
c%G<n|
VG&#\0
kkv6nd4
HCq\wQ
;rFSp/7
AnFeWG
hfMtYH)
'*WphK
S;0')'F
iM6LFH
D;!j#T
tKU8\
"x&n(V
`Epu[O
B3g/]pE
io1VGB
YShUOG
ZC'eq%-yT
rV{I^C
{|DAQmL^m
{d-H0
jgpAF3
kakKjr
9)8Y{
vYzf(\
j*l=l<
<H3xA{C
+iXQ$Z{
w\fk}c
Sg,)N/?
l4fQ!R
'#'R91
^ag8lQ
8tGR$}>
Jf0id-
g_ 88P
v'ms8'
!UOYH*
'$.opLz
Q{a}MzIj
\WP5
a&S;5)H
X4ARa8
QqnXI\
&-R>9_ZK
fl2G;_
1r.|5B
Sv+l~d
l(.V$Kx
p*B0uc
W!RCYN
*T/:XLFp
n!lL`:
19.Z#<
KY34v.
$Swy4
q<\Kbf
I;Q#VDZe
i>43)%%u
Q"FZ.5D
vmY0ss
G<-aIi
:trxV|
qPHcw(
l4vzp]T;
]=d#\#m
lbV#r
'j}v;{
a\+hT!
\d~:#d
yLi4B=
:BNM5e
/fe87H#y.
n+Z|{ADP
T-{K$W
]M}a'
9yC@d]
LL<?iw,
$J@vX6edL+
%Cu D
t+~9|2
v:=K*R
E-JLy"
o1oGV=d
+Ch"LX2nC
d9:/yF
^[@{G1i7
QJ@QuE
;6|u~H
h8nc@YG
aGZ_x(
B&GcsJ
QXC:nQ
7LNj3C
H}*jo@'[pgw
zq9o2>
*@qM@T
}K&0[T<
}=:MQ!
~?gd[~
=l!z&GH
F6d&$+
<'U>XZs
jki%;Pl'
N2ND4p
\Vv&l
l2.jr#C/
9!'/9J
W-?zU
@g$2c|)C
>[8~G.
M"vhi{
!8--<W
fx5{oz
[OpEf:
e:#=$-
Xu=N)[
6l1k&?
bqu]i/B
pHax^R
^y=LH):
lK(]5P
H$I6y|
/\<c[g
~@2a+GH
uxZ%n(
1 I@Ncv
`&T#3i
xSbU,Ox
uw(_.
;4|1L=
u"PqS/;
bU{-_Y
~|a.2QTpY
]O'|u0
w-]',a
ig2)/b
] ]X'<T
d">2:f
p;`4d=
4JRZ(D(
<,uX0/
%-%sn}
H"$sTJ
~]>"7L1j
Y&W4s0
7Zr;9w
<rb8a
86Z\,-
.OQow8
@+"@tI
9V\kRt
0=:K#w(
Wwfo
&D !Gv
QF4g|]
:xx>/+
*RlYK?Z
O.}2)&
>:r++J
q_eCUl
o17n?!
'c3dLMt"-
*/!=
<!4<0E
$<I"%'
4w,)%/-
bHer"Q
~=Bzatv
Cd\^^%
nljs!,
.~PEx4
NgN\)(:
:'j0sa
S.q&P@
xgFEB'
n#I/|
O7w+=1z
Ty%G^5
<w{iq|
"aW\#N
]^l;q
M4:)\{A
yPa3qaS
k3- 2dlF
Gp&iW0K
=5n1K!
|"I9>"
3`9?0z
6#h!::,a
n=-WnT
]_'vzW
8@8Q5O
E+.JXZd
g'WG+T\si
&z0n+s
h[W)yY"
8ZhBx_
oR$PEd
H`tcGOs
6QE,~ N
nbCzC9
7fS=6#
XleRT0
u}/./0D
S2:fHnn
G7~OZb
fKx;$Z
VtD6Q6o
=hlP0.6
5Yxqhv
|q\p.i7O
H>v;Hj
Q\I*JK
<'$Q v
nV<C^~
M1.Lz|t^
&\ 63.
=t<X3[
oZq?qt
e0Oq):
C2d+l$
|}0$]8xG
OC.{&v%
y5b?Wk
wnw<{dq
fSo3'I{U
c(`[01
/gu`^G
NX/C$7
9D\fQC"
TQ6SU6
dF3HZC
Q0m1I
L+eJ$*
rlQ}%J
@z*'{b
tgnq{Uk5
>YbA}0
GnOw5U
!esdZ'
13V,C/
}>,J}|E
~L4EHm
Qa1~5
C3&?7W
wil}6h
dG!o m
]R!QU=
a3g,0m
`0-agf
U;!xY/K9_
K;O*tN
sh.oKR
>~h>xE
}VU\-vTVT
k4iW,N
Ek>Qy)$b
X!dCL|
Op9~1Ka.
+(`T3Z
l BA5Wj
~={vWI
cy^p}P
9uAS0L4
$EQ<`_
}#Z9+%
m!/7?#
% _zsg
d9`ihB
dbnJn.
%+S|mM
hcDV`?
J1haug
]Om=~d
/1DJ3+
{5LgW!8
%njskJ
+5,5ah
GDoR|
y(J;.w):F.n
!MQQ&5
tmF8mf
XXzE{40ER
r_Fi}I
dNWegU
&r*7DE
Gib$[Z
)6K#!6N;
M}Q(>z^G
7,bNV/Qc
q~h?dz
nVs>Tz
>ZD5l~
usqnpi
0|ka.R
P3AaaC
O^ue)P
ijGMqBS_!2
z{kEHQ
@z%a}[
g4_}BF
dHU^M5v
n-0*LrvBk
~P@Wi:P
=_9|2(
p<bI1F
e<jDKVA
Xn3KJU
{>bFE'q%
2)7kSHz
u[Mp]<kz
b%*}qa
CO]#ye5
I?"A*&
d*oA$G
*7*>Cj
,>%9J=
@(p]}:6
OY7McIuv
b^NXoQ0/
G(:xx|
Sz3dig
@lj`j%
Oi3]hX
w!p^#=
wtK2{B
WCtO3=
> (|?=S\
g8r*h*,D
sA?tt=
(a|;0'
h<Z0At
MB1O%vWo
|lz,i5
1`E].i
7jbIRf
tYwcJz
+HtF4A
tlKML:
eM+>#%
-z!jp
>Gnn#Bq
;)k|p]
dCY>IG
.:[yp,m
bw_ij0dM
cw0pg.
L_A9H0
\ljIm|
;uBP#}
fE^PRyC
C/J-b5
<|'?n)
j^HhqF-
#i V.'
D$QlL,/
B_9"|Y
wKV07
h~M[Vo
Az\e$e
L>9W;-J
BFb+S#8
a&7tZmp
$(?I-X
d);,Y%^
Cs{XfY
wOmD"e
!xh#u+
<0e!Z3L
pr'I="6
qh22os
B-zhBZ*
n?va(8
?fmmL|?
o?\$dB
^?~lB0!
C|Mw[|
PEp,Pn
~0Cv!1
X8DgLb
*D~gdeS
%DWOG!
|pm.'N
9;~iob~
.P &M
n2{V)8#E
LTZ>D:l
z"y g?
AZ/}|E7
O_='Lgm+
,FaR+}
@"()x}3
Gdv`g&]k
l#B0zJ
Z`om'I
/Yrt*
>q"r1?
Xl"*\h>
"_<s_!b
jaZ<LZ&
h'g#Ql
oQJkvJ
R/6)Q.
RTzlEz
P$cp<q
=)},/T
`cj0\0
{=w"&O
}{'b,i
zj][}cg
k.,sA4<
zkS^En
GM[\c
x&FQDp
57Mn)[-6
meJO&=
J+OzZo
+{^bxr7[
x5|sBw
AqeJUJe4
uo}uKkD
8DA#{9,1
^'u=4?
-/K:}a
$Xq2UV"
Ru~bA2u
Ng.%um
a{gDFRC
J&fb%R
|uZt]7
D(SHfP
{m~}e{
0v+K2P
5&#br)
kt$eI42I
sX>?iz
c}n0)d
6sYQa*
|#hmni
,n$x@$V
qr6A&I
RG4wqh
>hvF5na
$*5pv0
pb{[:G
vDD[v\
J]/?e!
5P3"SR
>)1U^NY#
3%67d$p1
||}O~O
|UOe$t
wR7</u
I|vpF=]c=
N-;wV(
qmA37N
h~*8=P
KdZ)NPpY
*c!Rw$
2uN~^C
5<1V5_
y*PY{u
\(X9kmq^
0+ZJ3:
x*TOjK
<K>|"+|&7j#U
+57J0
a=%K(v
6F(!pUu
cDmV(V
Oq<`Gj/
Y'XjQ>
t,?UEs!x
Cew_OA<
O*_o;L %j9
fJp{Yet,
|)Sw)&FY
$tc#~_u
MA$qgj
6d6)/~
ku<chf
Nf.2,2R^aRE
a_Nxp&Ag
}61$BY
ozZ11e
Lf$R9!U
%;-_IN
8xa$fd~
}Ne<$,F)
AmfT_fs
%2w%cS
RZdy2z
h],kavN>m
#xW^?0
#>@6w;%
)#O6`+|
Z\^Ys,
L->^D++
WVYVd.
x6 co1
5KTbRC
_x-Tc"x
Kt/Bak
2kd]^h$
>,Bd*f
WWHn]0Q
WF./ci[D
*bv9HO
mP":UB
>v};fs
1)ln9fn
iyR\Q,P
;F5c8Vc
t_h`eLY
UW43sm
p)8d'>
]D>GUl
]e(}MLi>
NduG 5
fLPAXU
Sl z^>
QYcq_9
gGy];A
&J9JHw
tHj.oeq^
6rWjgk
X/AJ)7{5I
bkT(q*
G;2yD[
<g@lEs
&oy2HFc$
>(qj42
mQX_9l
U_t?Oa
dqN9Op
q:$B`
H$4O'r
R[k[^n`p
]!!iFb
*E1CK<Y
1!c@1>
A%k~%sQ
fW}QTfTjD
)LO(t*
\FH*G)]=I
|6"MTX
CE9GfE/
IQh^(4
tu8QWV
((((( H
dKERNEL32.DLL
dddd, MMMM dd, yyyy
MM/dd/yy
syr-sy
February
January
Thursday
Tuesday
Wednesday
Saturday
Sunday
Monday
Friday
div-mv
August
zh-cht
HH:mm:ss
zh-chs
October
November
September
December
smj-no
sma-no
quz-bo
uz-uz-latn
az-az-latn
sr-sp-latn
bs-ba-latn
sr-ba-latn
uz-UZ-Latn
az-AZ-Latn
sr-SP-Latn
bs-BA-Latn
sr-BA-Latn
kok-in
uz-uz-cyrl
az-az-cyrl
sr-sp-cyrl
sr-ba-cyrl
uz-UZ-Cyrl
az-AZ-Cyrl
sr-SP-Cyrl
sr-BA-Cyrl
mscoree.dll
kernel32.dll
sms-fi
smn-fi
kernelbase
smj-se
sma-se
quz-pe
quz-ec
syr-SY
div-MV
zh-CHT
zh-CHS
smj-NO
sma-NO
quz-BO
kok-IN
sms-FI
smn-FI
smj-SE
sma-SE
quz-PE
quz-EC
api-ms-win-core-file-l1-2-4
user32
kernel32
advapi32
api-ms-win-core-file-l1-2-2
api-ms-win-core-sysinfo-l1-2-1
api-ms-win-core-fibers-l1-1-1
api-ms-win-core-synch-l1-2-0
api-ms-win-core-xstate-l2-1-0
api-ms-win-core-winrt-l1-1-0
api-ms-win-core-string-l1-1-0
ext-ms-
api-ms-
(null)
CONOUT$
api-ms-win-core-processthreads-l1-1-2
api-ms-win-appmodel-runtime-l1-1-2
api-ms-win-core-localization-l1-2-1
api-ms-win-core-datetime-l1-1-1
api-ms-win-core-localization-obsolete-l1-2-0
ext-ms-win-ntuser-dialogbox-l1-1-0
api-ms-win-rtcore-ntuser-window-l1-1-0
api-ms-win-security-systemfunctions-l1-1-0
ext-ms-win-ntuser-windowstation-l1-1-0
Antivirus Signature
Bkav W64.AIDetectMalware
Lionic Trojan.Win32.Lumma.1u!c
Elastic malicious (high confidence)
MicroWorld-eScan Gen:Variant.Lazy.674883
CMC Clean
CAT-QuickHeal Trojan.Ghanarava.1744046911a18c46
Skyhigh BehavesLike.Win64.Trickbot.jc
ALYac Gen:Variant.Lazy.674883
Cylance Unsafe
Zillya Clean
Sangfor Trojan.Win64.Kryptik.Vbv7
CrowdStrike win/malicious_confidence_100% (W)
Alibaba Trojan:Win64/Kryptik.f373edea
K7GW Clean
K7AntiVirus Clean
huorong Clean
Baidu Clean
VirIT Clean
Paloalto generic.ml
Symantec ML.Attribute.HighConfidence
tehtris Clean
ESET-NOD32 a variant of Win64/Kryptik.EZV
APEX Malicious
Avast Win64:CrypterX-gen [Trj]
Cynet Malicious (score: 100)
Kaspersky UDS:DangerousObject.Multi.Generic
BitDefender Gen:Variant.Lazy.674883
NANO-Antivirus Clean
ViRobot Clean
Tencent Clean
Sophos Mal/Generic-S
F-Secure Clean
DrWeb Clean
VIPRE Gen:Variant.Lazy.674883
TrendMicro Clean
McAfeeD ti!9D2ADAD9A2CE
Trapmine Clean
CTX exe.trojan.kryptik
Emsisoft Gen:Variant.Lazy.674883 (B)
Ikarus Clean
FireEye Generic.mg.c6a119bfd5690fd9
Jiangmin Clean
Webroot W32.Trojan.Gen
Varist W64/ABTrojan.JARF-5539
Avira TR/Kryptik.bucdx
Fortinet W64/Kryptik.EZV!tr
Antiy-AVL Trojan/Win64.Kryptik
Kingsoft malware.kb.a.996
Gridinsoft Ransom.Win64.TrickBot.sa
Xcitium Clean
Arcabit Trojan.Lazy.DA4C43
SUPERAntiSpyware Clean
ZoneAlarm Clean
Microsoft Trojan:Win64/LummaC.AN!MTB
Google Detected
AhnLab-V3 Trojan/Win.Kryptik.R699262
Acronis Clean
McAfee Artemis!C6A119BFD569
TACHYON Clean
VBA32 Clean
Malwarebytes Crypt.Trojan.MSIL.DDS
Panda Trj/GdSda.A
Zoner Clean
TrendMicro-HouseCall Trojan.Win32.VSX.PE04C9V
Rising Trojan.ShellCodeLoader!1.12B08 (CLASSIC)
Yandex Clean
SentinelOne Static AI - Suspicious PE
GData Gen:Variant.Lazy.674883
AVG Win64:CrypterX-gen [Trj]
DeepInstinct MALICIOUS
alibabacloud Trojan[stealer]:Win/LummaC.AT8PHU
No IRMA results available.