Static | ZeroBOX

PE Compile Time

2025-03-24 00:01:50

PE Imphash

d743740f06aa0a325bb5c948f63319ce

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x000bee90 0x000bf000 5.92435984367
.rdata 0x000c0000 0x000098b4 0x00009a00 4.769739331
.data 0x000ca000 0x00001fa0 0x00000c00 2.22746157734
.pdata 0x000cc000 0x00001410 0x00001600 5.11224411653
.gxfg 0x000ce000 0x00001120 0x00001200 4.90393141539
.retplne 0x000d0000 0x0000008c 0x00000200 1.05058324797
_RDATA 0x000d1000 0x000001f4 0x00000200 4.22089573144
.reloc 0x000d2000 0x00000668 0x00000800 4.92037866893
.idata 0x000d3000 0x00056400 0x00056400 7.99949447487

Imports

Library KERNEL32.dll:
0x1400c7f18 CloseHandle
0x1400c7f20 CompareStringW
0x1400c7f28 CreateFileA
0x1400c7f30 CreateFileW
0x1400c7f38 DeleteCriticalSection
0x1400c7f40 EncodePointer
0x1400c7f48 EnterCriticalSection
0x1400c7f50 ExitProcess
0x1400c7f58 FindClose
0x1400c7f60 FindFirstFileExW
0x1400c7f68 FindNextFileW
0x1400c7f70 FlsAlloc
0x1400c7f78 FlsFree
0x1400c7f80 FlsGetValue
0x1400c7f88 FlsSetValue
0x1400c7f90 FlushFileBuffers
0x1400c7f98 FreeEnvironmentStringsW
0x1400c7fa0 FreeLibrary
0x1400c7fa8 GetACP
0x1400c7fb0 GetCPInfo
0x1400c7fb8 GetCommandLineA
0x1400c7fc0 GetCommandLineW
0x1400c7fc8 GetConsoleMode
0x1400c7fd0 GetConsoleOutputCP
0x1400c7fd8 GetCurrentProcess
0x1400c7fe0 GetCurrentProcessId
0x1400c7fe8 GetCurrentThreadId
0x1400c7ff0 GetEnvironmentStringsW
0x1400c7ff8 GetFileSize
0x1400c8000 GetFileType
0x1400c8008 GetLastError
0x1400c8010 GetModuleFileNameW
0x1400c8018 GetModuleHandleExW
0x1400c8020 GetModuleHandleW
0x1400c8028 GetOEMCP
0x1400c8030 GetProcAddress
0x1400c8038 GetProcessHeap
0x1400c8040 GetStartupInfoW
0x1400c8048 GetStdHandle
0x1400c8050 GetStringTypeW
0x1400c8058 GetSystemTimeAsFileTime
0x1400c8060 HeapAlloc
0x1400c8068 HeapFree
0x1400c8070 HeapReAlloc
0x1400c8078 HeapSize
0x1400c8088 InitializeSListHead
0x1400c8090 IsDebuggerPresent
0x1400c80a0 IsValidCodePage
0x1400c80a8 LCMapStringW
0x1400c80b0 LeaveCriticalSection
0x1400c80b8 LoadLibraryExW
0x1400c80c0 MultiByteToWideChar
0x1400c80c8 QueryPerformanceCounter
0x1400c80d0 RaiseException
0x1400c80d8 ReadFile
0x1400c80e0 RtlCaptureContext
0x1400c80e8 RtlLookupFunctionEntry
0x1400c80f0 RtlPcToFileHeader
0x1400c80f8 RtlUnwindEx
0x1400c8100 RtlVirtualUnwind
0x1400c8108 SetEnvironmentVariableW
0x1400c8110 SetFilePointerEx
0x1400c8118 SetLastError
0x1400c8120 SetStdHandle
0x1400c8130 TerminateProcess
0x1400c8138 TlsAlloc
0x1400c8140 TlsFree
0x1400c8148 TlsGetValue
0x1400c8150 TlsSetValue
0x1400c8158 UnhandledExceptionFilter
0x1400c8160 WideCharToMultiByte
0x1400c8168 WriteConsoleW
0x1400c8170 WriteFile

!This program cannot be run in DOS mode.$
`.rdata
@.data
.pdata
@.gxfg
@.retplne
_RDATA
@.reloc
B.idata
AWAVAUATVWUSH
D$,-8t<
D$,-6j
D$H;D$L
T$DiT$D
L$DiT$D
T$DiT$\
(fT)D!
t$4iL$4
T$\iD$\
5(t,U%
[]_^A\A]A^A_
#b2iA!
UAWAVAUATVWSH
[_^A\A]A^A_]
UAWAVAUATVWSH
[_^A\A]A^A_]
UAWAVAUATVWSH
3Hcv<H
[_^A\A]A^A_]
3Hcv<H
AWAVAUATVWUSH
D$8-%u
D$8-fN
D$hHcL$h
HcL$hD
L$DHcT$hD
HcT$hD
T$DLcT$DL
LcT$hM
R8rVE)
L$@;L$T
T$DLcL$hF
T$DLcL$DL
LcL$hM
HcL$hD
T$<HcL$<
L$HLcL$@F
U^\DA!
[]_^A\A]A^A_
L$DHcT$hD
GHcT$hD
T$DLc\$DH
Lc\$hL
AWAVAUATVWUSH
D$`-k;
D$`-P3?
D$`-Mn
D$`-LY
D$`-(_*b
D$`-I{ob
-&5{6A
[]_^A\A]A^A_
AWAVAUATVWUSH
m!S-HP
kcKPE)
[]_^A\A]A^A_
KZjeA)
AWAVAUATVWUSH
h[]_^A\A]A^A_
UAWAVAUATVWSH
[_^A\A]A^A_]
UAWAVAUATVWSH
[_^A\A]A^A_]
UAWAVAUATVWSH
->-KuA)
[_^A\A]A^A_]
~EK<E)
UAWAVAUATVWSH
A"HGE)
[_^A\A]A^A_]
UAWAVAUATVWSH
[_^A\A]A^A_]
UAWAVAUATVWSH
E$-R>;
E$-9S|
E$-3#G7
eh[_^A\A]A^A_]
E83#G7
UAWAVAUATVWSH
[_^A\A]A^A_]
UAWAVAUATVWSH
[_^A\A]A^A_]
UAWAVAUATVWSH
[_^A\A]A^A_]
UAWAVAUATVWSH
[_^A\A]A^A_]
UAWAVAUATVWSH
[_^A\A]A^A_]
UAWAVAUATVWSH
e.s~-t
[_^A\A]A^A_]
UAWAVAUATVWSH
[_^A\A]A^A_]
UAWAVAUATVWSH
[_^A\A]A^A_]
AWAVAUATVWUSH
h[]_^A\A]A^A_
AWAVAUATVWUSH
D$`-IR<S
5S9-U~
[]_^A\A]A^A_
UAWAVAUATVWSH
e([_^A\A]A^A_]
UAWAVAUATVWSH
[_^A\A]A^A_]
AWAVAUATVWUSH
x[]_^A\A]A^A_
AWAVAUATVWUSH
D$4-&R
[]_^A\A]A^A_
UAWAVAUATVWSH
[_^A\A]A^A_]
AWAVAUATVWUSH
D$,-h<
D$,-yB
[]_^A\A]A^A_
UAWAVAUATVWSH
7lBUE)
[_^A\A]A^A_]
AWAVAUATVWUSH
D$|-n$'
D$|-c"K
D$|-DU
D$|-TC
D$|-^.
r<Dle$
X47E)
[]_^A\A]A^A_
<G/BM)
kD_/$`L
UAWAVAUATVWSH
[_^A\A]A^A_]
UAWAVAUATVWSH
-aXn-~
x:--aXnD
[_^A\A]A^A_]
UAWAVAUATVWSH
[_^A\A]A^A_]
UAWAVAUATVWSH
#N-S.w
[_^A\A]A^A_]
UAWAVAUATVWSH
[_^A\A]A^A_]
UAWAVAUATVWSH
[_^A\A]A^A_]
AWAVAUATVWUSH
D$0-/8
D$0-Py
EZ7NA)
h[]_^A\A]A^A_
UAWAVAUATVWSH
[_^A\A]A^A_]
UAWAVAUATVWSH
-Xw&x-
[_^A\A]A^A_]
UAWAVAUATVWSH
[_^A\A]A^A_]
UAWAVAUATVWSH
[_^A\A]A^A_]
UAWAVAUATVWSH
[_^A\A]A^A_]
u/HcH<H
WATAUAVAWH
A_A^A]A\_
VWATAVAWH
A_A^A\_^
WATAUAVAWH
A_A^A]A\_
H;xXu5
u3HcH<H
UVWAVAWH
0A_A^_^]
WATAUAVAWH
A_A^A]A\_
WAVAWH
A_A^_
WAVAWH
A_A^_
p0R^G'
p*W4H
p*W4H
D$0@8{
LcA<E3
SVWATAUAVAWH
0A_A^A]A\_^[
@SVWATAUAVAWH
L!|$(L!
D$0HcH
pA_A^A]A\_^[
B(I9A(u
t$ WATAUAVAWH
A_A^A]A\_
AUAVAWH
u4I9}(
;I9}(tiH
0A_A^A]
@USVWATAUAVAWH
A_A^A]A\_^[]
UVWATAUAVAWH
`A_A^A]A\_^]
UVWATAUAVAWH
A_A^A]A\_^]
p0R^G'
WATAUAVAWH
A_A^A]A\_
fD9t$b
l$ VWATAVAWH
L$&8\$&t,8Y
A_A^A\_^
t$ WATAUAVAWH
D!|$xA
A_A^A]A\_
L$ VWAVH
@UATAUAVAWH
e0A_A^A]A\]
UVWATAUAVAWH
PA_A^A]A\_^]
u$D8r(t
D81uUL9r
uED8r(t
vAD8s(t
u$D8r(t
fD91uTL9r
uED8r(t
v@D8s(t
WATAUAVAWH
0A_A^A]A\_
H9>u+A
@USVWATAUAVH
D8t$ht
D8t$ht
A^A]A\_^[]
f9)u4H9j
u%@8j(t
UVWATAUAVAWH
xWI96tRI
0A_A^A]A\_^]
WATAUAVAWH
A_A^A]A\_
vyfffff
vyfffff
WAVAWH
A_A^_
@UATAUAVAWH
A_A^A]A\]
@USVWATAUAVAWH
H!D$ H
xA_A^A]A\_^[]
VATAUAVAWH
0A_A^A]A\^
UVWATAUAVAWH
fB9<I}1L
A_A^A]A\_^]
VWATAVAW
A_A^A\_^
ATAUAVH
L$ fff
L$ |+L;
A^A]A\
x UAVAWH
fD94H}aD
fffffff
fffffff
WATAUAVAWH
0A_A^A]A\_
@USVWATAUAVAWH
eHA_A^A]A\_^[]
@SUVWATAVAWH
@A_A^A\_^][
ffffff
fffffff
USVWAVH
A^_^[]
fffffff
fffffff
fffffff
ffffff
vKfffff
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
UUUUUU
UUUUUU
=imb;D
/>58d%
VM>cQ6
>jtm}S
)>6{1n
+f)>0'
;H9>&X
*StO9>T
n03>Pu
K~Je#>!
bp(=>?g
BC?>6t9^
K&>.yC
.xJ>Hf
y\PD>!
|b=})>
c [1>H'
uzKs@>
3>N;kU
kE>fvw
V6E>`"(5
?UUUUUU
?7zQ6$
Unknown exception
bad array new length
string too long
C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe
.idata
Sunday
Monday
Friday
August
__eabi
new[]
dddd, MMMM dd, yyyy
MM/dd/yy
February
January
Thursday
Tuesday
Wednesday
Saturday
InitializeCriticalSectionEx
LCMapStringEx
CompareStringEx
operator co_await
__restrict
CorExitProcess
HH:mm:ss
operator
October
November
September
December
bad exception
bad allocation
__fastcall
__thiscall
__vectorcall
__clrcall
__stdcall
__cdecl
__pascal
FlsSetValue
FlsGetValue
delete
FlsFree
AppPolicyGetProcessTerminationMethod
__unaligned
FlsAlloc
delete[]
AreFileApisANSI
LocaleNameToLCID
operator<=>
__ptr64
__swift_3
__swift_2
__swift_1
restrict(
__based(
Base Class Descriptor at (
Base Class Array'
Class Hierarchy Descriptor'
Type Descriptor'
`vector deleting destructor'
`scalar deleting destructor'
`vbase destructor'
`vector copy constructor iterator'
`eh vector copy constructor iterator'
`managed vector copy constructor iterator'
`vector vbase copy constructor iterator'
`eh vector vbase copy constructor iterator'
`vector constructor iterator'
`eh vector constructor iterator'
`managed vector constructor iterator'
`vector vbase constructor iterator'
`eh vector vbase constructor iterator'
`vector destructor iterator'
`eh vector destructor iterator'
`managed vector destructor iterator'
Complete Object Locator'
`virtual displacement map'
`vcall'
`string'
`udt returning'
`omni callsig'
`typeof'
`copy constructor closure'
`default constructor closure'
`local vftable constructor closure'
`placement delete closure'
`placement delete[] closure'
`vftable'
`local vftable'
`vbtable'
`anonymous namespace'
`local static thread guard'
`local static guard'
`dynamic atexit destructor for '
`dynamic initializer for '
operator ""
CloseHandle
CompareStringW
CreateFileA
CreateFileW
DeleteCriticalSection
EncodePointer
EnterCriticalSection
ExitProcess
FindClose
FindFirstFileExW
FindNextFileW
FlsAlloc
FlsFree
FlsGetValue
FlsSetValue
FlushFileBuffers
FreeEnvironmentStringsW
FreeLibrary
GetACP
GetCPInfo
GetCommandLineA
GetCommandLineW
GetConsoleMode
GetConsoleOutputCP
GetCurrentProcess
GetCurrentProcessId
GetCurrentThreadId
GetEnvironmentStringsW
GetFileSize
GetFileType
GetLastError
GetModuleFileNameW
GetModuleHandleExW
GetModuleHandleW
GetOEMCP
GetProcAddress
GetProcessHeap
GetStartupInfoW
GetStdHandle
GetStringTypeW
GetSystemTimeAsFileTime
HeapAlloc
HeapFree
HeapReAlloc
HeapSize
InitializeCriticalSectionAndSpinCount
InitializeSListHead
IsDebuggerPresent
IsProcessorFeaturePresent
IsValidCodePage
LCMapStringW
LeaveCriticalSection
LoadLibraryExW
MultiByteToWideChar
QueryPerformanceCounter
RaiseException
ReadFile
RtlCaptureContext
RtlLookupFunctionEntry
RtlPcToFileHeader
RtlUnwindEx
RtlVirtualUnwind
SetEnvironmentVariableW
SetFilePointerEx
SetLastError
SetStdHandle
SetUnhandledExceptionFilter
TerminateProcess
TlsAlloc
TlsFree
TlsGetValue
TlsSetValue
UnhandledExceptionFilter
WideCharToMultiByte
WriteConsoleW
WriteFile
KERNEL32.dll
.?AVbad_array_new_length@std@@
.?AVbad_alloc@std@@
.?AVexception@std@@
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
.?AVlogic_error@std@@
.?AVlength_error@std@@
.?AVbad_exception@std@@
.?AVtype_info@@
p0R^G'
p0R^G'
p0R^G'
p*W4H
p*W4H
p0R^G'
p0R^G'
pB]P67
p0R^G'
p0R^G'
p@\xV.
p0R^G'
p0R^G'
p0R^G'
p0R^G'
p0R^G'
RetpolineV1
RetpolineV1
RetpolineV1
RetpolineV1
S3bO8=#
&vYk3;
&{+Jg)~
M<OR`^
RK>y?=
cNcj0;_;|
A;N1n3f(
oQ3p4rH
hI$&}M
d;,}M\
z4UTQp\
$[Zr\j
FI@zcT
=gB:*]
)\waJ|&W
H};g(E
pk)o~=K
&n Q(
7l{df
QFtTOs
M[tj'l.
rwt}Z
]HDHt
O"gK(
`n)S6E
1g/X2Z
E01]=;
Nmkw=X'
:qdwZZ
]r[)z;E
4}#g^X
_o.2l
2l5@ 9
e:9!)}
z{S(z3z
;1[^~JJ,
|9NkUw
1$@-!3
O)9/c]
0H(4=.
IA5/Pxl
a?wItR
\gVLUYX
D/@&*0
KZ++``
YR$oP{F
<nCR`/
:zlh"N
uNAc+UD+JB
JJqoH#
v,Em!b
.d'Du
EF`U>_
f"d^l\wC&
"?HD {
(GI./
D{C.)(
9WOG59
r^7$.7
Wb"83:Z
b"%~^Q!
<1t<?r]
c-qIK1
HN(Orn
YR=dVw
CP3YxHy>1
$=r7}n
pnJr4y
RP5%Do!S+
N[ xt$[
W*":X5
M"YFk7|
:Nhp@%
BbXv4!
1MpSlH
OX'{~eXeE
U1GUa{l
<W/~PH;
s~?=6]
ZBV#$+2
$E:D/LhC
{@jy .
RD|m+F\5
LP&*cO
I-'b/Q
q;bnmm
\~P!{u
[rAM|
p|:EnM;k
~-kQP g
`Hc:EH
u95m$Ad
LWV[6Q
7=A[Ux
$9*o(c
`T?8ZeSI
H~Lw"t
Tk^To%i
v_O)<?k
n?OLNa
P|z?qT
;rSHQK
Fe)+BU
s7+|&]'
e{#w%Y
]hE}:'
!/+BDs
;:ygP0mwk
wGBUC$
B,"pR+
T\s D5
c47q;s
uwb/caXq
<1!=W\
eOKW$k
HQDM:R-+
4hU4Fc+
Q"GTTKK(
m> o0J`]N,
[3}&/:
nx]\,
,UdwAJ
xR{b,
O*KGY.
f)kZQ|
Nw%Yr.YT
6r.(u
$cwA8n$
4^#]R
DNh:t+D
sR~*C:L
@^B7z}
pNu}RCL+
XU:<[s
Z~YJH-
Q#m(Cc
:GM8wz$U
=lzT_~
rB?H't
kbl7=5
yYcMlI
as5qPv
&V-z.M
!J"OL,c
^3EMwB
"fJ@~N
9GFv:
Ubp57?
^WgkSRV%
33R}B
g\Qb }D?0
rdNzy=
!4[n]r`
jV1([%
@YQ#O}
QM`:V$Jz
JT"?dCH
:s'3JV
17x1.Q
r}Ko/h
ry7Mi.
*h%}7
r1['b-pqh
|ME7rs
v\NcgUi
#G'.%m
RI7t'l\
ZB\*I_
BJ/S}_7b
Po"LY$
"Cj**
3=^ZT(
b46yXl
3gGs(De
bnOtdL
?f.zDL
zsx9M.~9
*@i.Ib
iL{nnm
)=4P$b^
=Bv(QZ
(;8-5N
#SQ]:uN9
,4AGkG
z`}NjJ
NL66T"
S2x.cbVc
^MltkE
>;tf$y
=R9lSly
%9)Ea:
E= @W`}
}I/rT#
c]&+SG
e;.Vl?
#&Q'^3
4:mZs^
dCn)"~
Ct3?4r
$ 1;ZeA
wPP1It
'hil?l
sO1X/_
VKD"9{`
aEiHXH
SA:#jn
$Gvs1x
durpRd
6I=Jn2J0_
R:;-;N
9BRRe*r
C[% A[
BJ,a*_
f[jg46
u}.)C}
WI!<+@
0rf5:N
Oad{Re(
_/Y#'Q
41e2=NU;
o*;HSO
el6lK2
;Qh4]7&
6K2*',B-F
0dO6b,
8"OYq2
q~O7!B
L^s)uvoYU!
ZB&HVh
7u):GbAa{
;=9RKE
q6o#1j
JYpP$DW
vW~9Gm
&iIDTw9
$MurhG
_cJ(a$
&<7`OU
roa jB
sT3?mt
GW]C*z
BY%!W;
jr\rJ0
xe8xW5
ww;5 k
got=us
3>iTNr
{4Af%w
jmh/aPy
7A#>;B
)`EE^6
%q.m'6
}Vl^f-S
M"&)8L
6uDy/I1N
sB);rs
JEqStMV
53hchp
:`;pu]
s-!`m_
r|ML!w#J
>;M^4km
W+NaAwl
3C(]|ay$G+
=I!rfx
s9@e]=
m*s?o(XC
wkm,?O{
:5;Ozn
2>}S7Fv )
>V$lv8
i'{i}D
SQZ?!3LM?
So$WlDs~
[j?BHt<
|0g;tG
L2m|g$
#2]!u
XNqf;E
z,Mu_T
JpUKU`
YR.k>Q
HQpt_t
RtkVLb
['@9HJ
2~Q/o=
`j\=|j
\J^;Q4
N&Gy8:
YERiHK
b|iSW
~+D)XU
ns+35:
qL2.+r
@+%-Ib
e3>(}Jy#
s\2-;M
gpf+Y|
axZR6/
ZB"^.V}
s,x57
/|jW!L/
4DwKll
94%Xb
4=zSWK
JU-<7>
6+YJkP
H_T.-0
]=mKo|
~>Z{%o*
y! Hjo
MES 0dF
^Oy!Kb
aSV&oV
WA|n4[
-Yj@#e
M<Uzz;
GLb~*T
c 8Q46
=BS# E
*k{:n3
gO*Dex
7]njX/
@&6Y3v
@P"Z<8
}((klsZ
'&"0`X
$@"XS%
@Sk<NcPGy{
qTL\jG
=e"7T!tpp;
)~:NK5
(#+(7,
DkgjYF
8eP8F!
>U]"w64
a`6<0>
6_RLc0-
68kg/kx
h,9"M&6
\BzRk=
AQm?g1Xo}]
iZX!.|
bCx7+~
BS~/V#$_
!,%H+N
Xw(\M^
A{o^`n
Kv2A]!x
-uZK|uaD
uAEcYvk
U+(/SD
@UT]2
RZ"zj]
&H7wgfo
,(}~7@O0
( R.z:
8wA-m63
P^{/n=
]MK[2("
:i/G&}L
IC\_]4
\umCry
Dk~#-w
h_Dqh@
a|3(kT
9>-ya^J
._CVz2?
*:2N]j
MBktlI
nLD:_~
vy7ndWB
{PP-:@
>$OLj
(0bxa(
?*d(T>Givma
3j-g4E
BfHw s
0%=pV5
M%6pyZ
8R\- Y
4Bi#G]|ru&
1vE=WW'
j9,;Zv
pD;~m/
,6i\UiL$
+e}]Y%{
-a1@x?
k^DQCf
XO;MMT?
\ZWFsBN
$F&! %
dZkO>k1
E^"8w
_&KfI{
evjZ5R:
+0Nsb
gW([+R
IUATP6
`cc6PD
lcJ]K~6
`Gx<hE
0?(1avY-U
#o.x&`%'m
N[1'xDQ
SyVjTJ
yT51h:
]x.@&x
iA|TrA
wzy}W\UD]
m mrX"e0
VsY|oZ
x2z_f4;
d<%,gz1
Q>Zv*kiOV
62t@'y$<
Aw@PX1
sw3TfZ
p=RIjXS
6q-b(,~?
;"6 F[
`3l&a`
]/Is91p
/f0b\;
^_GjCQ
@}7J]6
w`mqhy
Q)<q(r
r&jW6T&
pwA*gq
]A!l>/
xcZy<v
+_%Sxk
vxE0:J
M:bKfz,,
p:g- 4
]u#>XL
kv"^{[
'r7D:bzh
n?ecOj
JO_,Oz
+jewig
YfsWHS
.]zb;n
`*^iE6
>1v6i]
LH%#:'
4nZ5?f
:.N88Tn5!
"#R|J<
N8~"p4m"
gwy>8
?$9/Q6Z
/msj}%
fLJ#J,
}QksOf
2D9V`ICl
^%v;cXQ
uRJdErYa
81NS)QaP
g!"l$#
<xRj-u
F4W.5Q
mX+>f2~'
K={:+{J
xE~f2f,
LkKzvI7
XKU@ ^
Y@??EE
#jES[$
k?T7.O
GU^>4{
)lmVCt
RNhITH]
]&Mgko
idk-DF
k<ejS{
jnaTO*
nv+%u'
^{Y|[E
z8H}.d8
izdo+y'm
6v%&[o
*5n(%
0<^avOO<:n$Z
Ss]kZV
^`Z.Q6
6TT> 2e
~&4NBh
6u?WS
+`6-YW
/r[KZ1
ulvelqn
w-^c\N=1
7Z|?b}%
f/w,dZ
&/2vcTY
9k,9iE
8vb,ze
`j3g?`
`9{w[w
Z-h&?=ud
s9{2>O
d,ON|X
F`@rnO
QXu!]{h5
[l8Y\n
k5&,3 NK"
r/q!(.3
=Z`m]r
U",(I$
+J:H#c
$`1i}c
A*WI:.C
Eu",s1
x3ehBSx
K)VS^8
Rd;+ma
:oj%m;=e=
"])ZD!{H
q3&-n7:J
6XM{]K.:
=-9Cv<
W3nrWs2v(
w`mGj2
&uR!&K
$i]}Y~u
q$vrlN
j:SSQX
Yj:r^j;
]RQfWp
0d.#]+
>#>P\
6<r.MYl]9
9s' N"Ka
)e4 0d?
\u[MnLP1bq'E
<[C=(cM
VB]szO
!A.M;E
ji9lHf
;)g3FE
1 =zB'L
k'Bv]4
VTudd/
Qg%arp
^-KVJ2g
>@s/yJ
QS:l8w
GxZmT*
RPUo7}\
aX2qKAC-
dsN2<:
NI'I_9
0+PDQ"
w2rctA
E9rvK"
IU0Q^j
zARtE=
^uHwf.
:bswg^'3
eZnBq$
fj]TFkRm4>Xp
dPv&\P
IJ.{9"h
hU//QbT
!jQhV3
o"g%[z2
7#5$TS
X:*(kL
*E[IGu%
$qIni;
ub'[G0
BuO`Av
z*yfd?
$Cs(,b@L
,fLA}9
$@b"\(Ao
DfyaRS
@K:|'P
<kb&l-|
`n'93
tbcwgF:d
P3`;);
FF[{Dv
Rcz<12
aK[;&1
jG.q*S
AIU/;64=
nmgL3n
v,#^O&dF
uNb'a}
|o-F9l+y0
SK!g/g-<
vFS>*]
k3i fs
'KS`+B
b@DR<&
A[3lmO"
vR0ih!
4/7Pm=
)9zr~%f
Xc3 Q
_b i-b
<YnLy-7H
nyi?@kC
uvPE[E
/zBiv2F
U?z$Gu
J",B7/i
/|}ELe
nkyBO9.|Z6
CzM>F&
\E{@GXd&
z6,6Y1
(Az Zt
%9BIlVe
^:0yT>
((((( H
aKERNEL32.DLL
dddd, MMMM dd, yyyy
MM/dd/yy
syr-sy
February
January
Thursday
Tuesday
Wednesday
Saturday
Sunday
Monday
Friday
div-mv
August
zh-cht
HH:mm:ss
zh-chs
October
November
September
December
smj-no
sma-no
quz-bo
uz-uz-latn
az-az-latn
sr-sp-latn
bs-ba-latn
sr-ba-latn
uz-UZ-Latn
az-AZ-Latn
sr-SP-Latn
bs-BA-Latn
sr-BA-Latn
kok-in
uz-uz-cyrl
az-az-cyrl
sr-sp-cyrl
sr-ba-cyrl
uz-UZ-Cyrl
az-AZ-Cyrl
sr-SP-Cyrl
sr-BA-Cyrl
mscoree.dll
sms-fi
smn-fi
kernelbase
smj-se
sma-se
quz-pe
quz-ec
syr-SY
div-MV
zh-CHT
zh-CHS
smj-NO
sma-NO
quz-BO
kok-IN
sms-FI
smn-FI
smj-SE
sma-SE
quz-PE
quz-EC
api-ms-win-core-file-l1-2-4
user32
kernel32
advapi32
api-ms-win-core-file-l1-2-2
api-ms-win-core-sysinfo-l1-2-1
api-ms-win-core-fibers-l1-1-1
api-ms-win-core-synch-l1-2-0
api-ms-win-core-xstate-l2-1-0
api-ms-win-core-winrt-l1-1-0
api-ms-win-core-string-l1-1-0
ext-ms-
api-ms-
CONOUT$
api-ms-win-core-processthreads-l1-1-2
api-ms-win-appmodel-runtime-l1-1-2
api-ms-win-core-localization-l1-2-1
api-ms-win-core-datetime-l1-1-1
api-ms-win-core-localization-obsolete-l1-2-0
ext-ms-win-ntuser-dialogbox-l1-1-0
api-ms-win-rtcore-ntuser-window-l1-1-0
api-ms-win-security-systemfunctions-l1-1-0
ext-ms-win-ntuser-windowstation-l1-1-0
Antivirus Signature
Bkav W64.AIDetectMalware
Lionic Clean
Elastic malicious (high confidence)
ClamAV Clean
CMC Clean
CAT-QuickHeal Clean
Skyhigh Clean
ALYac Gen:Variant.Lazy.670229
Cylance Unsafe
Zillya Trojan.Inject.Win32.352585
Sangfor Trojan.Win32.Save.a
CrowdStrike win/malicious_confidence_90% (D)
Alibaba Clean
K7GW Riskware ( 00584baa1 )
K7AntiVirus Riskware ( 00584baa1 )
huorong Trojan/Injector.cep
Baidu Clean
VirIT Trojan.Win64.Genus.HWW
Paloalto Clean
Symantec ML.Attribute.HighConfidence
tehtris Clean
ESET-NOD32 a variant of Win64/Injector.WR
APEX Malicious
Avast Win64:Evo-gen [Trj]
Cynet Malicious (score: 100)
Kaspersky VHO:Trojan-PSW.Win32.Convagent.gen
BitDefender Gen:Variant.Lazy.670229
NANO-Antivirus Clean
ViRobot Clean
MicroWorld-eScan Gen:Variant.Lazy.670229
Tencent OB:Trojan.Win64.Injector.16001769
Sophos Generic ML PUA (PUA)
F-Secure Clean
DrWeb Clean
VIPRE Gen:Variant.Lazy.670229
TrendMicro Clean
McAfeeD Clean
Trapmine Clean
CTX exe.unknown.lazy
Emsisoft Gen:Variant.Lazy.670229 (B)
Ikarus Trojan.SuspectCRC
GData Gen:Variant.Lazy.670229
Jiangmin Clean
Webroot Win.Malware.Gen
Varist Clean
Avira Clean
Antiy-AVL Trojan/Win64.GenKryptik
Kingsoft Clean
Gridinsoft Clean
Xcitium Clean
Arcabit Trojan.Lazy.DA3A15
SUPERAntiSpyware Clean
ZoneAlarm Clean
Microsoft Trojan:Win32/LummaStealer.Z!MTB
Google Detected
AhnLab-V3 Trojan/Win.Zusy.R696935
Acronis Clean
McAfee Clean
TACHYON Clean
VBA32 Clean
Malwarebytes Crypt.Trojan.MSIL.DDS
Panda Trj/GdSda.A
Zoner Clean
TrendMicro-HouseCall Trojan.Win32.VSX.PE04C9V
Rising Trojan.ShellCodeLoader!1.12B07 (CLASSIC)
Yandex Clean
SentinelOne Clean
MaxSecure Trojan.Malware.300983.susgen
Fortinet W64/Injector.WR!tr
AVG Win64:Evo-gen [Trj]
DeepInstinct MALICIOUS
alibabacloud Clean
No IRMA results available.