Static | ZeroBOX

PE Compile Time

2025-04-28 00:08:39

PE Imphash

130d5621ef2323889c6e1ed2746329fe

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x000dd176 0x000dd200 7.03768721998
.rdata 0x000df000 0x0000f324 0x0000f400 4.92349433817
.data 0x000ef000 0x00003b68 0x00001400 2.74545662139
.pdata 0x000f3000 0x00002820 0x00002a00 5.59727324097
.B5 0x000f6000 0x00004f53 0x00005000 6.92566333574
.gxfg 0x000fb000 0x00001e80 0x00002000 5.01179364434
.retplne 0x000fd000 0x0000008c 0x00000200 1.05058324797
.tls 0x000fe000 0x00000009 0x00000200 0.0203931352361
_RDATA 0x000ff000 0x000001f4 0x00000200 4.18117481474
.reloc 0x00100000 0x000009bc 0x00000a00 5.40195865363
.jss 0x00101000 0x00022600 0x00022600 7.99877320311
.rsrc 0x00124000 0x00000428 0x00000600 2.5199208337

Resources

Name Offset Size Language Sub-language File type
RT_VERSION 0x00124058 0x000003d0 LANG_ENGLISH SUBLANG_ENGLISH_US data

Imports

Library KERNEL32.dll:
0x1400eb5d8 AcquireSRWLockExclusive
0x1400eb5e0 CloseHandle
0x1400eb5e8 CreateFileA
0x1400eb5f0 CreateFileW
0x1400eb5f8 CreateThread
0x1400eb600 DecodePointer
0x1400eb608 DeleteCriticalSection
0x1400eb610 EncodePointer
0x1400eb618 EnterCriticalSection
0x1400eb620 EnumSystemLocalesW
0x1400eb628 ExitProcess
0x1400eb630 FindClose
0x1400eb638 FindFirstFileExW
0x1400eb640 FindNextFileW
0x1400eb648 FlsAlloc
0x1400eb650 FlsFree
0x1400eb658 FlsGetValue
0x1400eb660 FlsSetValue
0x1400eb668 FlushFileBuffers
0x1400eb670 FreeEnvironmentStringsW
0x1400eb678 FreeLibrary
0x1400eb680 GetACP
0x1400eb688 GetCPInfo
0x1400eb690 GetCommandLineA
0x1400eb698 GetCommandLineW
0x1400eb6a0 GetConsoleMode
0x1400eb6a8 GetConsoleOutputCP
0x1400eb6b0 GetCurrentProcess
0x1400eb6b8 GetCurrentProcessId
0x1400eb6c0 GetCurrentThreadId
0x1400eb6c8 GetEnvironmentStringsW
0x1400eb6d0 GetFileSize
0x1400eb6d8 GetFileSizeEx
0x1400eb6e0 GetFileType
0x1400eb6e8 GetLastError
0x1400eb6f0 GetLocaleInfoW
0x1400eb6f8 GetModuleFileNameW
0x1400eb700 GetModuleHandleA
0x1400eb708 GetModuleHandleExW
0x1400eb710 GetModuleHandleW
0x1400eb718 GetOEMCP
0x1400eb720 GetProcAddress
0x1400eb728 GetProcessHeap
0x1400eb730 GetStartupInfoW
0x1400eb738 GetStdHandle
0x1400eb740 GetStringTypeW
0x1400eb748 GetSystemTimeAsFileTime
0x1400eb750 GetUserDefaultLCID
0x1400eb758 HeapAlloc
0x1400eb760 HeapFree
0x1400eb768 HeapReAlloc
0x1400eb770 HeapSize
0x1400eb788 InitializeSListHead
0x1400eb790 IsDebuggerPresent
0x1400eb7a0 IsValidCodePage
0x1400eb7a8 IsValidLocale
0x1400eb7b0 LCMapStringEx
0x1400eb7b8 LCMapStringW
0x1400eb7c0 LeaveCriticalSection
0x1400eb7c8 LoadLibraryExW
0x1400eb7d0 MultiByteToWideChar
0x1400eb7d8 QueryPerformanceCounter
0x1400eb7e8 RaiseException
0x1400eb7f0 ReadConsoleW
0x1400eb7f8 ReadFile
0x1400eb800 ReleaseSRWLockExclusive
0x1400eb808 RtlCaptureContext
0x1400eb810 RtlLookupFunctionEntry
0x1400eb818 RtlPcToFileHeader
0x1400eb820 RtlUnwind
0x1400eb828 RtlUnwindEx
0x1400eb830 RtlVirtualUnwind
0x1400eb838 SetFilePointerEx
0x1400eb840 SetLastError
0x1400eb848 SetStdHandle
0x1400eb858 Sleep
0x1400eb868 TerminateProcess
0x1400eb870 TlsAlloc
0x1400eb878 TlsFree
0x1400eb880 TlsGetValue
0x1400eb888 TlsSetValue
0x1400eb890 UnhandledExceptionFilter
0x1400eb898 WaitForSingleObject
0x1400eb8a0 WakeAllConditionVariable
0x1400eb8a8 WideCharToMultiByte
0x1400eb8b0 WriteConsoleW
0x1400eb8b8 WriteFile

!This program cannot be run in DOS mode.$
`.rdata
@.data
.pdata
`.gxfg
@.retplne
_RDATA
@.reloc
AWAVAUATVWUSH
Dg~ A!
W%L 3(
%!a_~A
%!a_~A
HcD$LH
HcD$tH
[]_^A\A]A^A_
UAWAVAUATVWSH
IcD$<H
e([_^A\A]A^A_]
AWAVAUATVWUSH
=S?XDu
8[]_^A\A]A^A_
AWAVAUATVWUSH
8[]_^A\A]A^A_
UAWAVAUATVWSH
[_^A\A]A^A_]
UAWAVAUATVWSH
[_^A\A]A^A_]
AWAVAUATVWUSH
='GIzu
='GIzu
='GIzu
='GIzu
='GIzu
='GIzu
='GIzu
='GIzu
='GIzu
='GIzu
='GIzu
='GIzu
='GIzu
='GIzu
='GIzu
='GIzu
='GIzu
='GIzu
='GIzu
='GIzu
='GIzu
='GIzu
='GIzu
='GIzu
='GIzu
='GIzu
='GIzu
='GIzu
='GIzu
='GIzu
='GIzu
='GIzu
='GIzu
='GIzu
r6)1s(
"IGPLGN
"IGPLGN
"IGPLGN
Q05@!&D%@!
2"=~_=
2"=~_=
2"=~_=
D't!=j
D't!=j
D't!=j
^Hq"~X
^Hq"~X
[]_^A\A]A^A_
UAWAVAUATVWSH
[_^A\A]A^A_]
UAWAVAUATVWSH
[_^A\A]A^A_]
AVVWUSH
0[]_^A^
AWAVAUATVWUSH
%%?BUA
H[]_^A\A]A^A_
UAWAVAUATVWSH
C^t?=/K
C^t>=/K
C^t?=/K
~eqNnse
[_^A\A]A^A_]
AWAVAUATVWUSH
.Z~6=,
dk~_=-
8[]_^A\A]A^A_
AWAVAUATVWUSH
8[]_^A\A]A^A_
UAWAVAUATVWSH
[_^A\A]A^A_]
AWAVAUATVWUSH
~yi#*H
p)^_H)
H+D$0H
H[]_^A\A]A^A_
AWAVAUATVWUSH
H[]_^A\A]A^A_
AWAVAUATVWUSH
8[]_^A\A]A^A_
AWAVAUATVWUSH
8[]_^A\A]A^A_
AWAVAUATVWUSH
H[]_^A\A]A^A_
AWAVAUATVWUSH
|$P=^4
h[]_^A\A]A^A_
AWAVAUATVWUSH
LYRt3=
D$PH;D$0
aNr&aH
C^t)=/K
l|iPd'
[]_^A\A]A^A_
UAWAVAUATVWSH
=/fnVu
[_^A\A]A^A_]
5mCUP!
`>(s=8M#
=`>(su
UAWAVAUATVWSH
wBt!=/fnV
[_^A\A]A^A_]
AWAVAUATVWUSH
H[]_^A\A]A^A_
AWAVAUATVWUSH
8$KHxLH
X[]_^A\A]A^A_
AWAVAUATVWUSH
H[]_^A\A]A^A_
AWAVAUATVWUSH
8[]_^A\A]A^A_
AWAVAUATVWUSH
H[]_^A\A]A^A_
AWAVAUATVWUSH
8[]_^A\A]A^A_
AWAVAUATVWUSH
8[]_^A\A]A^A_
AWAVAUATVWUSH
H[]_^A\A]A^A_
UAWAVAUATVWSH
[_^A\A]A^A_]
UAWAVAUATVWSH
[_^A\A]A^A_]
UAWAVAUATVWSH
~.=">[
:i%E=9i%E
E=9i%E~
=:i%Eu
E=9i%E~
=:i%Eu
:i%Ef.
:i%Ef.
E=9i%E~
=:i%Eu
[_^A\A]A^A_]
AWAVAUATVWUSH
gDDA}I
H+L$(H)
H+L$ H
[]_^A\A]A^A_
AWAVAUATVWUSH
8[]_^A\A]A^A_
AWAVAUATVWUSH
8[]_^A\A]A^A_
AWAVAUATVWUSH
4etx=?
HkD$(dI
HkD$(dI
8[]_^A\A]A^A_
UAWAVAUATVWSH
[_^A\A]A^A_]
UAWAVAUATVWSH
[_^A\A]A^A_]
AWAVAUATVWUSH
8[]_^A\A]A^A_
AWAVAUATVWUSH
D$(=H
D$(=H
X[]_^A\A]A^A_
AWAVAUATVWUSH
8[]_^A\A]A^A_
AWAVAUATVWUSH
=:i%Eu
E=9i%E
:i%Ef.
=:i%Eu
E=9i%E
x[]_^A\A]A^A_
AWAVAUATVWUSH
8[]_^A\A]A^A_
AWAVAUATVWUSH
X[]_^A\A]A^A_
UAWAVAUATVWSH
[_^A\A]A^A_]
AWAVAUATVWUSH
8[]_^A\A]A^A_
AVVWSH
8[_^A^
AWAVAUATVWUSH
H[]_^A\A]A^A_
UAWAVAUATVWSH
SAt5f.
5r{4q!
[_^A\A]A^A_]
AWAVAUATVWUSH
8[]_^A\A]A^A_
UAWAVAUATVWSH
?q)m=3>
[_^A\A]A^A_]
AWAVAUATVWUSH
D$@L9`
h[]_^A\A]A^A_
AWAVAUATVWUSH
K86~I=E
[]_^A\A]A^A_
UAWAVAUATVWSPH
AWAVAUATVWUSH
8[]_^A\A]A^A_
AWAVAUATVWUSH
*~)=S4
X[]_^A\A]A^A_
AWAVATVWUSH
tX=IF]
@[]_^A\A^A_
AWAVAUATVWUSH
8[]_^A\A]A^A_
AVVWUSH
@[]_^A^
AWAVVWUSH
H[]_^A^A_
AWAVVWUSH
[]_^A^A_
AWAVAUATVWUSH
[]_^A\A]A^A_
AWAVAUATVWUSH
[]_^A\A]A^A_
AWAVATVWUSH
[]_^A\A^A_
AWAVATVWUSH
[]_^A\A^A_
AWAVATVWUSH
[]_^A\A^A_
AWAVATVWUSH
[]_^A\A^A_
UAWAVAUATVWSH
[_^A\A]A^A_]
AWAVAUATVWUSH
D$l=Wd
>==/;F
L$x=Wd
=S?XDu
S?XDf.
=S?XDu
t2;l=Wd
L$4=Wd
L$H=Wd
L$p=Wd
L$`=Wd
[]_^A\A]A^A_
UAWAVAUATVWSH
[_^A\A]A^A_]
AWAVVWUSH
8[]_^A^A_
AWAVAUATVWUSH
[]_^A\A]A^A_
AWAVAUATVWUSH
=<kPGu
x[]_^A\A]A^A_
AWAVAUATVWUSH
`s p_H
[]_^A\A]A^A_
AWAVAUATVWUSH
H[]_^A\A]A^A_
AWAVAUATVWUSH
[]_^A\A]A^A_
AWAVAUATVWUSH
[]_^A\A]A^A_
AWAVAUATVWUSH
8[]_^A\A]A^A_
UAWAVAUATVWSH
5Md'L!
[_^A\A]A^A_]
AWAVAUATVWUSH
YDJ~I=>
H[]_^A\A]A^A_
UAWAVAUATVWSH
[_^A\A]A^A_]
AWAVAUATVWUSH
8[]_^A\A]A^A_
UAWAVAUATVWSH
[_^A\A]A^A_]
AVVWUSH
0[]_^A^
AWAVVWUSH
8[]_^A^A_
AWAVAUATVWUSH
8[]_^A\A]A^A_
AVVWUSH
0[]_^A^
AWAVAUATVWUSH
X[]_^A\A]A^A_
AWAVAUATVWUSH
8[]_^A\A]A^A_
AWAVAUATVWUSH
X[]_^A\A]A^A_
AWAVAUATVWUSH
|$p=^4
|$p=^4
[]_^A\A]A^A_
AWAVAUATVWUSH
C^t)=/K
@5"q4:
C^t+=/K
H+t$PH)
[]_^A\A]A^A_
AWAVAUATVWUSH
[]_^A\A]A^A_
AWAVAUATVWUSH
[]_^A\A]A^A_
AWAVATVWUSH
0[]_^A\A^A_
AWAVAUATVWUSH
8[]_^A\A]A^A_
AWAVAUATVWUSH
8[]_^A\A]A^A_
AWAVAUATVWUSH
h[]_^A\A]A^A_
AVVWUSH
0[]_^A^
UAWAVAUATVWSH
e8[_^A\A]A^A_]
UAWAVAUATVWSH
~I=TP+
[_^A\A]A^A_]
UAWAVAUATVWSH
[_^A\A]A^A_]
&nWtJ=
AWAVAUATVWUSH
H[]_^A\A]A^A_
AWAVAUATVWUSH
[]_^A\A]A^A_
AWAVAUATVWUSH
tMKF=Z
D$8H;D$(
X[]_^A\A]A^A_
AWAVAUATVWUSH
[]_^A\A]A^A_
AWAVAUATVWUSH
b:Q4+I
5M"j!!
5pr)?!
[]_^A\A]A^A_
AWAVAUATVWUSH
D$P=^4
h[]_^A\A]A^A_
AWAVAUATVWUSH
H+T$@H)
|$`=^4
x[]_^A\A]A^A_
UAWAVAUATVWSH
ZnAMbBI
[_^A\A]A^A_]
AWAVAUATVWUSH
x[]_^A\A]A^A_
AWAVAUATVWUSH
D$_<LA
0"!53E
[]_^A\A]A^A_
AWAVAUATVWUSH
C^t>=/K
C^t?=/K
C^t>=/K
C^t?=/K
C^t?=/K
H[]_^A\A]A^A_
p_~.=(
AWAVAUATVWUSH
H[]_^A\A]A^A_
AWAVAUATVWUSH
X5t.=6
X5t.=6
8[]_^A\A]A^A_
AWAVVWUSH
([]_^A^A_
AWAVAUATVWUSH
8[]_^A\A]A^A_
AWAVAUATVWUSH
x[]_^A\A]A^A_
UAWAVAUATVWSH
[_^A\A]A^A_]
AWAVATVWUSH
=L4IOu
L4IO=O
0[]_^A\A^A_
AWAVAUATVWUSH
H[]_^A\A]A^A_
AWAVAUATVWUSH
8[]_^A\A]A^A_
AWAVAUATVWUSH
8[]_^A\A]A^A_
AWAVAUATVWUSH
8[]_^A\A]A^A_
AWAVAUATVWUSH
8[]_^A\A]A^A_
AWAVAUATVWUSH
D$(;D$,
8[]_^A\A]A^A_
7t=jM
AWAVAUATVWUSH
8[]_^A\A]A^A_
AWAVAUATVWUSH
D$(=(cU
8[]_^A\A]A^A_
AWAVAUATVWUSH
8[]_^A\A]A^A_
AWAVAUATVWUSH
D$0=Uy
D$,=Uy
D$H;D$(A
X[]_^A\A]A^A_
AWAVAUATVWUSH
8[]_^A\A]A^A_
AWAVAUATVWUSH
~_=J\G
= z}9~I=!z}9tl
=$\'[t
L$(H9H
H[]_^A\A]A^A_
AWAVAUATVWUSH
D;l$<A
H[]_^A\A]A^A_
AWAVAUATVWUSH
8[]_^A\A]A^A_
UAWAVAUATVWSH
[_^A\A]A^A_]
AWAVAUATVWUSH
H[]_^A\A]A^A_
UAWAVAUATVWSH
d6,lD!
[_^A\A]A^A_]
UAWAVAUATVWSH
S?XDf.
=S?XDu
=S?XDu
[_^A\A]A^A_]
AWAVAUATVWUSH
<=7$n3
H[]_^A\A]A^A_
AWAVAUATVWUSH
8[]_^A\A]A^A_
AWAVAUATVWUSH
C^t;=/K
H[]_^A\A]A^A_
UAWAVAUATVWSH
[_^A\A]A^A_]
UAWAVAUATVWSH
49=sL.%
&=tL.%
K=sL.%
[_^A\A]A^A_]
AWAVAUATVWUSH
8[]_^A\A]A^A_
AWAVAUATVWUSH
C^t>=/K
H+D$HH)
x[]_^A\A]A^A_
AWAVAUATVWUSH
8[]_^A\A]A^A_
AWAVAUATVWUSH
H[]_^A\A]A^A_
AWAVAUATVWUSH
mn;~9=i
H[]_^A\A]A^A_
UAWAVAUATVWSH
=/3C#u
[_^A\A]A^A_]
WATAUAVAWH
A_A^A]A\_
x ATAVAWH
A_A^A\
x ATAVAWH
A_A^A\
t$ UWAVH
taL9Chu
t$ WAVAWH
A_A^_
L90u H
@SUVWAVH
A^_^][
tpH91uk
x ATAVAWH
A_A^A\
l$ VWAVH
u/HcH<H
@UAVAWH
WATAUAVAWH
A_A^A]A\_
D8L$0u`A
VWATAVAWH
A_A^A\_^
WATAUAVAWH
A_A^A]A\_
H;xXu5
s WATAUAVAWH
D$h9t$P
A_A^A]A\_
WAVAWH
A_A^_
kL@8o(u
D$@H;F
<htl<jt\<lt4<tt$<wt
UWATAVAWH
A_A^A\_]
x UAVAWH
@USVWATAVAWH
A_A^A\_^[]
S(HcS0
S(HcS0
S(HcS0
kL@8o(u
D$@H;F
<htl<jt\<lt4<tt$<wt
|$ UATAUAVAWH
A_A^A]A\]
WATAUAVAWH
0A_A^A]A\_
S(HcS0
S(HcS0
S(HcS0
u3HcH<H
@USVWATAUAVAWH
A_A^A]A\_^[]
9Cu,fD9y
fB9<{u
fD9,pu
t$`fD9+t$I
L$ SUVWH
WAVAWH
fE98t'
0A_A^_
\$ UVWATAUAVAWH
f9t$bu
A_A^A]A\_^]
H9L$Ht?H
WATAUAVAWH
0A_A^A]A\_
\$ UVWATAUAVAWH
fD9,Au
A_A^A]A\_^]
|$ AVH
UVWATAUAVAWH
fE9,Fu
A_A^A]A\_^]
UVWAVAWH
0A_A^_^]
WAVAWH
A_A^_
WAVAWH
A_A^_
WAVAWH
fA9,@u
fA9,vu
0A_A^_
p0R^G'
p*W4H
p*W4H
D$0@8{
L$ VWAVH
L$ UVWATAUAVAWH
0A_A^A]A\_^]
T$ D){
t$ WATAUAVAWH
0A_A^A]A\_
D$(H!L$ E3
;D$hsL
t$ UWAUAVAWH
A_A^A]_]
SUVWATAVAWH
A_A^A\_^][
LcA<E3
UVWATAUAVAWH
A_A^A]A\_^]
D$ I;R
D$ I9P
SVWATAUAVAWH
0A_A^A]A\_^[
@SVWATAUAVAWH
L!|$(L!
D$0HcH
pA_A^A]A\_^[
SVWATAUAVAWH
A_A^A]A\_^[
SVWATAUAWH
L!d$(L!d$@D
D$HL9gXt
A_A]A\_^[
B(I9A(u
t$ WATAUAVAWH
A_A^A]A\_
WAVAWH
A_A^_
AUAVAWH
u4I9}(
;I9}(tiH
0A_A^A]
AUAVAWH
u4I9}(
;I9}(tiH
0A_A^A]
WAVAWH
@USVWATAUAVAWH
A_A^A]A\_^[]
@USVWATAUAVAWH
d$dD;d$l
A_A^A]A\_^[]
UVWATAUAVAWH
`A_A^A]A\_^]
UVWATAUAVAWH
A_A^A]A\_^]
UVWATAUAVAWH
`A_A^A]A\_^]
@USVWATAUAVAWH
A_A^A]A\_^[]
WAVAWH
@A_A^_
WATAUAVAWH
A_A^A]A\_
@SUVWATAVAWH
A_A^A\_^][
@UAVAWH
e0A_A^]
@UATAUAVAWH
e0A_A^A]A\]
@UATAUAVAWH
A_A^A]A\]
fD9t$b
l$ VWATAVAWH
L$&8\$&t,8Y
A_A^A\_^
t$ WATAUAVAWH
D!|$xA
A_A^A]A\_
{ AUAVAWH
0A_A^A]
t$xt*3
x ATAVAWH
A_A^A\
t$ WATAUAVAWH
gfffffffH
A_A^A]A\_
WAVAWH
A_A^_
L$ VWAVH
fD94H}aD
UATAUAVAWH
A_A^A]A\]
WATAUAVAWH
A_A^A]A\_
UATAUAVAWH
A_A^A]A\]
x ATAVAWH
fD9 tMH
fG9$Ou
0A_A^A\
x ATAVAWH
A_A^A\
fB9<@u
fB9,Nu
fB9,Nu
fB9,Nu
fA9,Au
fB9<Bu
fB94Ou
fB9<Hu
t}f91txH
@USVWATAVAWH
tyfD9 tsH
tQfD9 tK
fD9$Hu
@A_A^A\_^[]
WAVAWH
A_A^_
fB9<Hu
fB9<@u
fD94Au
fD94iu
fB9<Bu
tSf91tNH
t^;\$0tQ
UVWATAUAVAWH
H;\$8u
H;\$8u
fE9$Iu
A_A^A]A\_^]
WATAUAVAWH
0A_A^A]A\_
H9>u+A
VATAUAVAWH
0A_A^A]A\^
UVWATAUAVAW
A_A^A]A\_^]
UVWATAUAVAWH
A_A^A]A\_^]
@USVWATAUAVAWH
H!D$ H
xA_A^A]A\_^[]
VATAUAVAWH
0A_A^A]A\^
UVWATAUAVAWH
fB9<I}1L
A_A^A]A\_^]
VWATAVAW
A_A^A\_^
D$0H9D$8
AUAVAWH
A_A^A]
UVWATAUAVAWH
@8t$HtzL
`A_A^A]A\_^]
l$ VWATAVAWH
0A_A^A\_^
\$ UVWATAUAVAWH
s2fE9)I
fE9)fA
D$pfA;
0fD9l$pu
fD9l$pt
0A_A^A]A\_^]
u1!D$0H
UVWATAUAVAWH
PA_A^A]A\_^]
E80t"A
fD94Q}
WATAVH
0A^A\_
@USVWATAUAVAWH
xA_A^A]A\_^[]
WATAVH
0A^A\_
WATAUAVAWH
A_A^A]A\_
UVWATAUAVAWH
rsf;\$d
r_f;\$l
rKf;\$t
r7f;\$|
f;\$4r
f;\$<r
rvf;\$d
rbf;\$l
rNf;\$t
r:f;\$|
A_A^A]A\_^]
vyfffff
vyfffff
T$`fA;
WAVAWH
A_A^_
@USVWATAVAWH
A_A^A\_^[]
WATAUAVAWH
0A_A^A]A\_
WAVAWH
D8|$`t
A_A^_
x ATAVAWH
@A_A^A\
ATAUAVH
L$ fff
L$ |+L;
A^A]A\
UVWATAUAVAWH
@A_A^A]A\_^]
fffffff
fffffff
ffffff
fffffff
@SUVWATAVAWH
@A_A^A\_^][
ATAVAWH
A_A^A\
USVWAVH
A^_^[]
fffffff
fffffff
fffffff
ffffff
vKfffff
iostream stream error
0123456789abcdefghijklmnopqrstuvwxyz
0123456789abcdefghijklmnopqrstuvwxyz
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
[aOni*{
~ $s%r
@b;zO]
v2!L.2
UUUUUU
UUUUUU
=imb;D
/>58d%
VM>cQ6
>jtm}S
)>6{1n
+f)>0'
;H9>&X
*StO9>T
n03>Pu
K~Je#>!
bp(=>?g
BC?>6t9^
K&>.yC
.xJ>Hf
y\PD>!
|b=})>
c [1>H'
uzKs@>
3>N;kU
kE>fvw
V6E>`"(5
?UUUUUU
?7zQ6$
bad cast
ios_base::failbit set
ios_base::eofbit set
ios_base::badbit set
Unknown exception
invalid string position
iostream
bad array new length
string too long
bad locale name
Sunday
Monday
Friday
August
_hypot
__eabi
new[]
1#SNAN
1#QNAN
(null)
dddd, MMMM dd, yyyy
MM/dd/yy
directory not empty
text file busy
device or resource busy
no such file or directory
not a directory
is a directory
not enough memory
February
January
Thursday
Tuesday
Wednesday
Saturday
GetDateFormatEx
GetTimeFormatEx
EnumSystemLocalesEx
GetLocaleInfoEx
InitializeCriticalSectionEx
LCMapStringEx
CompareStringEx
stream timeout
timed out
invalid argument
operator co_await
connection reset
network reset
ios_base::failbit set
ios_base::eofbit set
ios_base::badbit set
not a socket
__restrict
file exists
connection already in progress
operation in progress
no such device or address
bad address
no such process
no child process
CorExitProcess
success
HH:mm:ss
too many symbolic link levels
too many links
no stream resources
resource deadlock would occur
bad file descriptor
operator
executable format error
io error
unknown error
protocol error
_nextafter
October
November
September
December
network down
no protocol option
bad exception
inappropriate io control operation
bad allocation
argument out of domain
resource unavailable try again
too many files open
too many files open in system
read only file system
not a stream
__fastcall
__thiscall
__vectorcall
__clrcall
__stdcall
__cdecl
__pascal
no link
cross device link
invalid seek
operation would block
argument list too long
filename too long
message size
FlsSetValue
FlsGetValue
delete
address in use
wrong protocol type
broken pipe
GetSystemTimePreciseAsFileTime
GetUserDefaultLocaleName
LCIDToLocaleName
IsValidLocaleName
state not recoverable
address not available
no lock available
no message available
host unreachable
network unreachable
value too large
file too large
result out of range
no message
bad message
FlsFree
illegal byte sequence
no space on device
no such device
no buffer space
AppPolicyGetProcessTerminationMethod
identifier removed
operation not permitted
address family not supported
function not supported
operation not supported
protocol not supported
not supported
connection aborted
interrupted
already connected
not connected
connection refused
destination address required
__unaligned
operation canceled
permission denied
owner dead
FlsAlloc
delete[]
GetTempPath2W
AreFileApisANSI
LocaleNameToLCID
operator<=>
__ptr64
__swift_3
__swift_2
__swift_1
nan(snan)
nan(ind)
NAN(SNAN)
NAN(IND)
restrict(
__based(
Base Class Descriptor at (
Base Class Array'
Class Hierarchy Descriptor'
Type Descriptor'
`vector deleting destructor'
`scalar deleting destructor'
`vbase destructor'
`vector copy constructor iterator'
`eh vector copy constructor iterator'
`managed vector copy constructor iterator'
`vector vbase copy constructor iterator'
`eh vector vbase copy constructor iterator'
`vector constructor iterator'
`eh vector constructor iterator'
`managed vector constructor iterator'
`vector vbase constructor iterator'
`eh vector vbase constructor iterator'
`vector destructor iterator'
`eh vector destructor iterator'
`managed vector destructor iterator'
Complete Object Locator'
`virtual displacement map'
`vcall'
`string'
`udt returning'
`omni callsig'
`typeof'
`copy constructor closure'
`default constructor closure'
`local vftable constructor closure'
`placement delete closure'
`placement delete[] closure'
`vftable'
`local vftable'
`vbtable'
`anonymous namespace'
`local static thread guard'
`local static guard'
`dynamic atexit destructor for '
`dynamic initializer for '
operator ""
AcquireSRWLockExclusive
CloseHandle
CreateFileA
CreateFileW
CreateThread
DecodePointer
DeleteCriticalSection
EncodePointer
EnterCriticalSection
EnumSystemLocalesW
ExitProcess
FindClose
FindFirstFileExW
FindNextFileW
FlsAlloc
FlsFree
FlsGetValue
FlsSetValue
FlushFileBuffers
FreeEnvironmentStringsW
FreeLibrary
GetACP
GetCPInfo
GetCommandLineA
GetCommandLineW
GetConsoleMode
GetConsoleOutputCP
GetCurrentProcess
GetCurrentProcessId
GetCurrentThreadId
GetEnvironmentStringsW
GetFileSize
GetFileSizeEx
GetFileType
GetLastError
GetLocaleInfoW
GetModuleFileNameW
GetModuleHandleA
GetModuleHandleExW
GetModuleHandleW
GetOEMCP
GetProcAddress
GetProcessHeap
GetStartupInfoW
GetStdHandle
GetStringTypeW
GetSystemTimeAsFileTime
GetUserDefaultLCID
HeapAlloc
HeapFree
HeapReAlloc
HeapSize
InitializeCriticalSectionAndSpinCount
InitializeCriticalSectionEx
InitializeSListHead
IsDebuggerPresent
IsProcessorFeaturePresent
IsValidCodePage
IsValidLocale
LCMapStringEx
LCMapStringW
LeaveCriticalSection
LoadLibraryExW
MultiByteToWideChar
QueryPerformanceCounter
QueryPerformanceFrequency
RaiseException
ReadConsoleW
ReadFile
ReleaseSRWLockExclusive
RtlCaptureContext
RtlLookupFunctionEntry
RtlPcToFileHeader
RtlUnwind
RtlUnwindEx
RtlVirtualUnwind
SetFilePointerEx
SetLastError
SetStdHandle
SetUnhandledExceptionFilter
SleepConditionVariableSRW
TerminateProcess
TlsAlloc
TlsFree
TlsGetValue
TlsSetValue
UnhandledExceptionFilter
WaitForSingleObject
WakeAllConditionVariable
WideCharToMultiByte
WriteConsoleW
WriteFile
KERNEL32.dll
.?AVbad_array_new_length@std@@
.?AVbad_alloc@std@@
.?AVexception@std@@
.?AV?$num_put@DV?$ostreambuf_iterator@DU?$char_traits@D@std@@@std@@@std@@
.?AVfacet@locale@std@@
.?AV_Facet_base@std@@
.?AU_Crt_new_delete@std@@
.?AV?$ctype@D@std@@
.?AUctype_base@std@@
.?AV?$numpunct@D@std@@
.?AVbad_cast@std@@
.?AVfailure@ios_base@std@@
.?AVsystem_error@std@@
.?AV_System_error@std@@
.?AVruntime_error@std@@
.?AV_Iostream_error_category2@std@@
.?AVerror_category@std@@
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
.?AVlogic_error@std@@
.?AVlength_error@std@@
.?AVout_of_range@std@@
.?AVbad_exception@std@@
.?AVtype_info@@
.?AV_Locimp@locale@std@@
.?AVios_base@std@@
.?AV?$_Iosb@H@std@@
.?AV?$basic_ios@DU?$char_traits@D@std@@@std@@
.?AV?$basic_streambuf@DU?$char_traits@D@std@@@std@@
.?AV?$basic_ostream@DU?$char_traits@D@std@@@std@@
.?AV?$basic_filebuf@DU?$char_traits@D@std@@@std@@
.?AVcodecvt_base@std@@
.?AV?$codecvt@DDU_Mbstatet@@@std@@
UAWAVAUATVWSH
[_^A\A]A^A_]
AWAVAUATVWUSH
UZt7=jC
8[]_^A\A]A^A_
AWAVAUATVWUSH
H[]_^A\A]A^A_
AWAVAUATVWUSH
UZt==jC
H[]_^A\A]A^A_
AWAVAUATVWUSH
UZt7=jC
8[]_^A\A]A^A_
p0R^G'
pR[|*
p0R^G'
pSQ~W'
p0R^G'
p0R^G'
p*W4H
p*W4H
p0R^G'
p0R^G'
pQZ0Z?!
p0VXNh
p@\xV.
pB]P67
p0R^G'
p0R^G'
p0R^G'
p0R^G'
p1XPw>
p0R^G'
p;S>D.X
p0R^G'
p0R^G'
p0R^G'
RetpolineV1
RetpolineV1
RetpolineV1
RetpolineV1
'x)hnW
%bIY7c
v?0N=;
*cQRY1
/Sb_~N
.1tZ]s.m
Rw:F_}
s]Czmo
A0XyJ9Z/
0!^e}6
3KJk/`
\6 =g-
(k34HYk
FI~=nl
W,R:P`5
8t9TN4
e(Q~%h
C@p8#y
267F~j
clO,a)
Z^X(O.M
+~"A<^
m[&{1w
5l;X3v
Hcv${>r
y?B3I^1
?%L|]GG
(_F?**P
b!mcTX
|`|qB4
A[bqU0[
ki^A>w
"oD*f*
rgwo+g}
BaAZahtc2L
6u8nbX{
%uV?o'$
0389$4
]u\Yos
XM]r!1
B6{lQ,|
Ge,t;n
kLY7!$
Aag4^}-
"&J/;x
~KyXsJ
[FZPd*
SO=%N`;
e?e)(3
^Lv>}P
JUWpwB<
?$Y0a_
`$/+}_
&Ys[)A&
@c!TaQ
[?BKC_
1Qn-2S
c]E xk
>,d$X{M
g:mZ$>Y
M[_)U<L
q2S/=-
"iUx),
8pMZ\
uURn+0
<h_$b~
2'j+t`*E
Sb<v&@
Z;<UJ1
gu|dJi
WuU|+|[t
~&h>TCn
dn]C:"4
G7;W^_
@eNuY>
x:n{nO
&Ei;wV
<Gf73~1
<1JtIb4
!`%AE
zCbfc0
C**45]
@s<;[q
swvLVj
e7C//|
7^07^O
Ea9]x6
>FK`L
Y<B>q'
T3h]]@
)`\!7Q
W6{1D-Z7xb
Dp}IhU
jZ;:4\M
+''sGJ
vheARV>
qF_@T-
<]`:I3@
/R?h?#
'"G+iH,
QbD)^+
&-=rRR^
{.n\3=l
o*#|p/
YhV4 /z
dd@>`l`
nQw|`s
/*6*wW'
mJf),<x
kQ!Z0E
ri{e.WsO
tfK6p
j`j2{KB
ag'Nrn8d
;>t"V@J
B,K^gS
<RFpkw5^
,W<S"q
J{v;lD
rXMT6)
4fR{IG
c!3jI"
1w?m-3P*
LACo|E
uWBN0>
l{MWiT
YbrPW7
NupTm&
<dtvA~
n|io!\AA{
I'p`yv5C
j6:y`A
^ ME)
)P1-Av
G%#5:[
Y'*0Y]
9iV?=y
,US)h'
#0'bk@
2..$rsN
j%P]n=
q&As[_
8"Y25b
*;LJx
.&mji.:!f
O2!ab>
p{&]Ev8
U3>fBf
Xa3Slzz
6):Y0/
n61#@-
=2VI&gb^
d;v m.
ugy.7$\*Rza
^e/uAF
}os]Mz
UEX30j
M`|*+`
+z@]{A
pkY,#Td
,n|2gY
b9i`Wh,
j;PN_
*xACLW
5@Fsxaf
].~XyU
lrO*V
x_|zC&)
[^HhgD
y;r(wh
%e{> d9g
+~G! F
DT^9a0
,5V}5T
V4sQn8
u'A,K>
6 h6"p
?+,jy%W%.
*"+?SZ
Nmmg~GXI
yb1Gvl0
Vk(6J\
pgM{Y(EU
f0.5i$w:
a?E6NU
:.p7B4
{\cEzG
[b|Z=0R
VdxeBF%
/:bjl
XDuoj
_N`9/D
V)4CN~
__"\L5z
6U"#3<
>U69 {W
;n%E^
YfOM\c
2PVcV_
M@3kvn
Od?(i
vfpU>\m
2Eg@I\|
*ZhR=;
$ pH%O:a
"LGqgd
*0|[{W
k3M<d>r3
^Jc&1
2:hCeZc
\6X~G6
GkK(PB
a\|=`1
wa V__
@SQOx/
bpllLg
~Wu=mx
h~%BAu
YO*\N-
u@uGM8
f%h$he
%VeBRR
qr~gg]
$PW6v3x-
{?g7r2
lbPWfA
80lC}y'
ck:%8mj5
xO$te&
"I|<H`
MRx2ij
Qyo4]te!
jWl{so
VA-WMn
*d8^1c
R95xfH
yBHqlz
v/E`c)
[2mjSW[
pG@dL2
B:3`N!
%5u@x}
&{_QV
)j4pQ!2Z
Qv/'{U
'mjewN
8uxm''>
^jD*1V114
_& 4f\x
o_TC6
#6H[0{U
J ,VA~
:CPJ<7
(k> ~<
<7eB]@
x+]Y}
>t >ad
">v#kX
XX5z;}
tr# (4vh
Jk3~t!Y
((((( H
((((( H
(
KERNEL32.DLL
english-nz
dddd, MMMM dd, yyyy
MM/dd/yy
syr-sy
February
January
spanish-uruguay
spanish-paraguay
Thursday
Tuesday
Wednesday
Saturday
Sunday
Monday
Friday
div-mv
spanish-peru
August
zh-cht
english-aus
english-us
german-swiss
italian-swiss
french-swiss
HH:mm:ss
zh-chs
united-states
spanish-honduras
spanish-el salvador
spanish-ecuador
October
November
September
December
smj-no
sma-no
english-trinidad y tobago
trinidad & tobago
puerto-rico
spanish-puerto rico
quz-bo
uz-uz-latn
az-az-latn
sr-sp-latn
bs-ba-latn
sr-ba-latn
uz-UZ-Latn
az-AZ-Latn
sr-SP-Latn
bs-BA-Latn
sr-BA-Latn
spanish-modern
german-lichtenstein
great britain
britain
kok-in
german-austrian
portuguese-brazilian
australian
dutch-belgian
french-belgian
belgian
norwegian
french-canadian
canadian
english-caribbean
spanish-mexican
english-american
english-can
united-kingdom
uz-uz-cyrl
az-az-cyrl
sr-sp-cyrl
sr-ba-cyrl
uz-UZ-Cyrl
az-AZ-Cyrl
sr-SP-Cyrl
sr-BA-Cyrl
mscoree.dll
kernel32.dll
chinese-traditional
norwegian-bokmal
english-uk
norwegian-nynorsk
slovak
sms-fi
smn-fi
american-english
irish-english
american english
german-luxembourg
french-luxembourg
chinese-hongkong
hong-kong
english-belize
chinese
kernelbase
smj-se
sma-se
chinese-singapore
english-ire
quz-pe
spanish-chile
swedish-finland
holland
england
new-zealand
chinese-simplified
spanish-dominican republic
quz-ec
spanish-nicaragua
english-usa
spanish-argentina
pr-china
pr china
spanish-panama
spanish-venezuela
spanish-guatemala
spanish-bolivia
spanish-colombia
south-korea
south korea
south-africa
english-south africa
america
spanish-costa rica
english-jamaica
syr-SY
LC_MONETARY
div-MV
zh-CHT
zh-CHS
smj-NO
sma-NO
quz-BO
kok-IN
LC_ALL
sms-FI
smn-FI
LC_COLLATE
smj-SE
sma-SE
LC_CTYPE
quz-PE
LC_TIME
LC_NUMERIC
quz-EC
api-ms-win-core-file-l1-2-4
user32
kernel32
advapi32
api-ms-win-core-file-l1-2-2
api-ms-win-core-sysinfo-l1-2-1
api-ms-win-core-fibers-l1-1-1
api-ms-win-core-synch-l1-2-0
api-ms-win-core-xstate-l2-1-0
api-ms-win-core-winrt-l1-1-0
api-ms-win-core-string-l1-1-0
ext-ms-
api-ms-
(null)
CONOUT$
api-ms-win-core-processthreads-l1-1-2
api-ms-win-appmodel-runtime-l1-1-2
api-ms-win-core-localization-l1-2-1
api-ms-win-core-datetime-l1-1-1
api-ms-win-core-localization-obsolete-l1-2-0
ext-ms-win-ntuser-dialogbox-l1-1-0
api-ms-win-rtcore-ntuser-window-l1-1-0
api-ms-win-security-systemfunctions-l1-1-0
ext-ms-win-ntuser-windowstation-l1-1-0
VS_VERSION_INFO
StringFileInfo
040904B0
CompanyName
Microsoft Corporation
FileDescription
Microsoft Windows Media Player Setup Utility
FileVersion
12.0.19041.1 (WinBuild.160101.0800)
InternalName
unregmp2.exe
LegalCopyright
Microsoft Corporation. All rights reserved.
OriginalFilename
unregmp2.exe
ProductName
Microsoft
Windows
Operating System
ProductVersion
12.0.19041.1
VarFileInfo
Translation
Antivirus Signature
Bkav Clean
Lionic Clean
Elastic malicious (high confidence)
ClamAV Clean
CMC Clean
CAT-QuickHeal Clean
Skyhigh BehavesLike.Win64.VirusWinExpiro.tc
McAfee Artemis!9048722B3619
Cylance Unsafe
Zillya Clean
Sangfor Trojan.Win32.Save.a
CrowdStrike win/malicious_confidence_100% (W)
Alibaba Trojan:Win64/Kryptik.d1d44004
K7GW Clean
K7AntiVirus Clean
huorong HEUR:Trojan/Agent.dc
Baidu Clean
VirIT Clean
Paloalto generic.ml
Symantec ML.Attribute.HighConfidence
tehtris Clean
ESET-NOD32 a variant of Win64/Kryptik.FAZ
APEX Malicious
Avast MalwareX-gen [Pws]
Cynet Clean
Kaspersky UDS:Trojan-PSW.Win32.Vidar.dsc
BitDefender Gen:Variant.Lazy.676115
NANO-Antivirus Clean
ViRobot Clean
MicroWorld-eScan Gen:Variant.Lazy.676115
Tencent Clean
Sophos Mal/Generic-S
F-Secure Trojan.TR/Kryptik.djiea
DrWeb Clean
VIPRE Gen:Variant.Lazy.676115
TrendMicro Clean
McAfeeD ti!DC411841C3A1
Trapmine Clean
CTX exe.trojan.lumma
Emsisoft Gen:Variant.Lazy.676115 (B)
Ikarus Trojan.Win64.Crypt
GData Gen:Variant.Lazy.676115
Jiangmin Clean
Webroot Win.Infostealer.Lumma
Varist Clean
Avira TR/Kryptik.djiea
Antiy-AVL Trojan[PSW]/Win32.Lumma
Kingsoft malware.kb.a.969
Gridinsoft Trojan.Win64.Kryptik.sa
Xcitium Clean
Arcabit Trojan.Lazy.DA5113
SUPERAntiSpyware Clean
ZoneAlarm Clean
Microsoft Trojan:Win32/Wacatac.B!ml
Google Detected
AhnLab-V3 Trojan/Win.Generic.R701596
Acronis Clean
VBA32 Clean
TACHYON Clean
Malwarebytes Malware.AI.3163381849
Panda Clean
Zoner Clean
TrendMicro-HouseCall Trojan.Win32.VSX.PE04C9Z
Rising Stealer.Lumma!8.177F6 (TFE:5:4XSOvUQ4zMB)
Yandex Clean
SentinelOne Clean
MaxSecure Clean
Fortinet W64/GenKryptik.NQ!tr
AVG MalwareX-gen [Pws]
DeepInstinct MALICIOUS
alibabacloud Trojan[stealer]:Win/Wacatac.B9nj
No IRMA results available.