PE Compile Time

2024-09-22 20:40:44

PE Imphash

2eabe9054cad5152567f0699947a2c5b

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
\x00 0x00001000 0x00068000 0x0002de00 7.98264785246
.rsrc 0x00069000 0x000005d4 0x00000600 5.41712517937
.idata 0x0006a000 0x00001000 0x00000200 1.04281456314
hvpntabg 0x0006b000 0x002a5000 0x002a4c00 6.38815978019
otujhggi 0x00310000 0x00001000 0x00000600 5.23995965538
.taggant 0x00311000 0x00003000 0x00002200 0.778140285306

Resources

Name Offset Size Language Sub-language File type
RT_MANIFEST 0x00069454 0x0000017d LANG_ENGLISH SUBLANG_ENGLISH_US XML 1.0 document, ASCII text, with CRLF line terminators
RT_MANIFEST 0x00069454 0x0000017d LANG_ENGLISH SUBLANG_ENGLISH_US XML 1.0 document, ASCII text, with CRLF line terminators

Imports

Library kernel32.dll:
0x46a035 lstrcpy

!This program cannot be run in DOS mode.
.idata
hvpntabg
otujhggi
.taggant
}Q}jdd#
KpS&=bd
q$p.v^
m]#slO
X-rnNkzj
`F+sfs
-hV#c/m
pz}$)`{Mu
J!7_gZ
zSn`c=_n#H
hmMLvbTAw
xpT`DtY
tv8;Kv\
dDy=PSB
W`RT&U
~(nq5+:T
F2D#M
mE+ffC$qV
cO\2[{
85N5br$
=,nle2J
o"}+`c
pg/i&gTH
;%guYq
N]}m)a
eqx?((
<D9"gK
c6wZWg
bHXsXy
r[r~Y<
cwB8o`
^&RZk"
a-p0ai
cC,bj<
s,6S2;
VA;aeF
x@7x4^\
N`e;AN
,.8p[i]
bgpq]e
s'aI/DI
7w0/,N
XU\g9Y
Y5@rGo
{{vD`T
lK6x~4DK
F)2_e3'
payTmk
u3X=I]@L%
uf/1,.H
j-y97Z
l x{[c
%B|4b8$
q4rj(3R
0S#hgfb
Rq>Jkj
;yc[sc
\F"TLY
*gRp;8
fyG(|0
Y4KhCE
J:<fl{
pi$#GC
ri,%aBzi
cb|:0i
d- @R6f
W8RHi!
=:1Dv,= Y
6-'L%v>
0#c7>i
NvRcA0j$
\R{~Hq
U.tO3x
xN<'>I7r
ergps8
sgn}RH
h0.Xh4-
,sRnffF
~CJtp@
#'hx#k
js[vdx!lz=3
kch<0A
cRA.j@
OV]dfU
ek%s(1
4CIjT*.
gwlY>$
[f(9iH
PAX)r@
QA7<HF
Rx":tKxelyz
8pc" b
g,!>RHM
nal{x3
YpFeUJ
8pc<j.
MiA-R2i
:@(gr%
lkoNvg
eCfvXi
P>WlV
+[kD{1
: .%f
..Ezxr
@J^d}9:
Err3pKkH
rt{JDV
DE`3"W
,k])1p
j`x@aa
$Zz>O;
u5~IMup
%.r/et
v?jDrf-
5.WP0X.
!P[pXh
/:/j<R
DaZ~oM
&5M|/P
mpOo:0i]
V<jPkH,jg
CkXZ{V!
wIFD0X
3PlTy1by
]JyH05
B>8N9[6
L$2V]x
d,!iT$W
|u)>~B
D8+VmRLp,X
S&g>|
he()ba\FS
vVfChiw
'l3De^~
lR~nYl
Ah&=e,
*N!d#d"
3imWc!e
IN*@*'
_eke*Z
}m0_!#;
@-b|lF
Cl4#@lB
^Lz^T_
3-AKM7?
~]\ +9
U}4P:ao
)p.9eZR
t"rKQbGhZ
qW7U>zcN_G
Puu&b&
l9*zz%
[p8SSbe
bX&^2C
3.`5A7
I2BLk@
<N|zOQg
K_hc7QFe
T,"ff,k
wrxMd8
NP#*8(
:fo,p*
k>i[mt
h,QcZZh
tYf%z!
bqZ\nv
5v$p+e
E=nJ"
X187Ht
2DfR432B
2ro,yF
;R!u2l@
l>%mj?Xe
n&B0Y$
iKtOo`
#v#*FT
S:p2QD
)s6(iz
'|~,^o
KH|!f'Z
1XE<rEg
eq)|WMG
]H.dYZ
>Vf*Yl
s(Jshk=k
%v>nY
#!nhx]
JpU$04
hL,<"QA
aZN.f^
PpTy^#<
0yCtjZo
>B{*O3
3@i4M
//jlf
%bz,NR
"MGt#
aKHI'?
A|78K0=
(#C%t2I
{<p{z
ZiM<bX
RyuDsv
wK)G:}
6(&Tp3
|DM{t
'D0"K&
IvR" {7n
;uC?GB
_Etnc2
W6i<"\
$d5d!j3K
oAwA&S
`Jc0fuU
U~ph'2
Hr3{|l{-DT
<tE/!$
AGQZfx
)cZ~|K
bfm6trpdm{*4
MpyD74
KnU?nB
lM5fz"
AA4,p>
i?qRU5DZ
+{t]Hu
OA.E@\
\m yp9
j[cx!88l
V#H,2M
Ef>Bbh~
++ebIMu
}4?+Yh
@<Wh O
5zT!yI
2ASg'a
V7qf=YXK
^RX%XJx
py%K)Tx
h!y>x#
Glo!nY
'|,CU[|#
|XmN|_
=:p1>)8
3nTY{"
{t,)EH
R?yA'0~
i#*E~hL
p)AH1F8o
6b/0i_
41:`t@
@jNXlna%Z~
VQ$Pe,
lVsaxs
Stm^s!
}Y@V0c
ycogfd
.Ov\Arb;
z?[{pa
yuhP(K
j$o?w5
kLVE.bHzpY;
":tWHG
"M=c9N
]g5P}u
g~v<]_G
&,(YCj#
)-Z[zP
)IhgXm
.OVMbf
Vef~N
^s2mtZUb
W:3+F7W
"paHj=B
@r/*{&[N
alhv@xwZFp
b"Yu8Yj?
jl6hgo|\
[8s @
{Su*ahDCho|
dlH',o
Bt|yYwx
rd^yX3
p`k;")
?'kr8m}
AAhnzQZYS
OKRlfE
%m&ZC-
Pt:z'R
@6)["0
e>,@z+w
nA|srGh
x#Qb#
41'r2\@
|Ky=@hA%
1B`{D{
Cae Pjb
}JQ mH
TB[3P-
Z \`Li
cOYc",}
c%[m`T6z
w jN`hr
k]0xXf2
"C{Y;bu+et
mc3adC
V5X!H
zi%6W#
^=e%l5j
DbZ@Dwz
m*F8[As
Xc&J99
O2rf7d
?XPlQi
vC4$xH
x"Alr:
pHX9rM
%r*t|L
u$s$Atr3
Y~#[xdS
{$y9A~r4
x7J$<r@MC
$q@Avr_
jIxvag
\}\]F7$m
"*uhlv
/)H|;u
0zHD%V
gMyvVW
k2lEnW;
<?xml version="1.0" encoding="UTF-8"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" xmlns:asmv3="urn:schemas-microsoft-com:asm.v3" manifestVersion="1.0">
<assemblyIdentity version="6.3.2.0" processorArchitecture="x86" name="AnyDesk.AnyDesk.AnyDesk" type="win32" />
<description>AnyDesk screen sharing and remote control software.</description>
<dependency>
<dependentAssembly>
<assemblyIdentity type="win32" name="Microsoft.Windows.Common-Controls" version="6.0.0.0" processorArchitecture="x86" publicKeyToken="6595b64144ccf1df" language="*" />
</dependentAssembly>
</dependency>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v2">
<security>
<requestedPrivileges>
<requestedExecutionLevel level="asInvoker" />
</requestedPrivileges>
</security>
</trustInfo>
<asmv3:application>
<asmv3:windowsSettings xmlns="http://schemas.microsoft.com/SMI/2005/WindowsSettings">
<dpiAware>true/PM</dpiAware>
</asmv3:windowsSettings>
</asmv3:application>
</assembly>
<?xml version='1.0' encoding='UTF-8' standalone='yes'?>
<assembly xmlns='urn:schemas-microsoft-com:asm.v1' manifestVersion='1.0'>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v3">
<security>
<requestedPrivileges>
<requestedExecutionLevel level='asInvoker' uiAccess='false' />
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
PADPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPAD
lstrcpy
CreateThread
kernel32.dll
KERNEL32.dll
)21_:5
Themida
K&?L8z
4=%2=%
R=h{R,6
CSpp>
)[ppcs
nCrcs;
[dQEN@
++prcs
'=h8!&
r#+~d}1
IG6["o
)8DN'x
.go6T_`
ho6["o
Io6]"o
hw6["oU
hG6["o
dG60go6e
.io6["o
d?60ew6c
IG6]"o
1go64a
fw6*%o6d
fo6TpD
!]$]QC
Iw6]"o
hG6]"o
IG6]"o
3Mo60a
Iw6]"o
&io6]"o
Io6]"o
\2Sxz^
*5#+~Z_
n5/f#7
L%;%c2i
~}@Nx@
@/@NQ+
3<$1<$3<$
Gi|s)\$
1<$3<$1<$
Z3,$1,$3,$
Yh5'ca
_^][ZYX
$SQhF7
^Gz)D$
^GzX]Y
_^][ZYX
et7UZ]
ARQh#&
3,$1,$3,$\
_34$14$34$
_^][ZYX
_^][ZYX
$Y3<$1<$3<$
_^][ZYX
$ #~{_
4$^PTX
O.Z^1t$
4$_PTX
w5/+"G
3<$1<$3<$\
34$14$34$\P
]Ph|2
PQRSUVW
:_^][ZYX
34$14$34$\
$\3,$1,$3,$\
QhMRR]
3<$1<$3<$
wQSPh%
_^][ZYX
_^][ZYX
_^][ZYX
_^][ZYX
$hfP -
W"f5su
4$[WT_SU
.5ZKhc
_^][ZYX
4$YQTYW
$[XKCW
+LW{_1
XSh?o$)
_^][ZYX
.$n;|f
_^][ZYX
7r$oa)
ZXVhAa
$SVh~Q
34$14$34$\
4$RTZWQ
_^][ZYX
+{_1l$
_^][ZYX
_^][ZYX
_^][ZYX
_^][ZYX
!WFL/)
#JZr@f
3<$1<$3<$\1
_RWZ_V
,$Ph$|
_^][ZYX
_^][ZYX
^z1,$3,$1,$
4$Uh2y
O?u|Z3
2]_R%)
4$[QTYR
_^][ZYX
_^][ZYX
~`>{]PS
4$[UT]
$UT]WUS
XW^_RVS
_^][ZYX
_^][ZYX
_^][ZYX
_^][ZYX
_^][ZYX
3,$1,$3,$\h
,$#W[u
4$_PTX
_^][ZYX
4$ZPTX
_^][ZYX
_^][ZYX
_^][ZYX
34$14$34$\Q^
PVX^F1
'D!;B)
3,$1,$3,$\
4$PTXQ
4$[QTY
4$[QTY
2ll<.f
4$UT]Wh}
%P({~-L
3<$1<$3<$
6)'9-)
_^][ZYX
W5I.Zx
_^][ZYX
1W_`aZXS
$UQhWw
3,$1,$3,$
gh:%PG
4$ZPTX
,$\%uc
4$P^XV
-7 _V]
4$ZRTZU
3,$1,$3,$\
,$\3,$1,$3,$
$\Uh`^qp
nh~_2
3<$1<$3<$
4$A5}{
1ZX`aZXZXVPRPR
34$14$34$\
4$[VT^
,$PTXS
4$h!Eof
4$^UT]
4$YST[P
ZY@@%8
4$YQTYVP
$1<$3<$1<$O
3<$1<$3<$\
,$Z])T$
4$QTYWh{
'YuXME
4$hDL,
^Z-gUiK
S-rPb^V
4$S^V_
X3,$1,$3,$\P
3,$1,$3,$
$\`RPR
1ZXZ``aPR
1ZX`aaa
4$YUT]
b2QPhZW
$$WVhu
$7.woSQ
,$\H@W
Mo5)|$
Z34$14$34$
4$XRTZV
$$RVh$
$\->Jo
1ZXW`a
_a```a
Z1,$3,$1,$
1,$3,$1,$
$$\'nCP
$hA~RRT
$\H%v'
4$]PTX
o[UShS@3/[K
,$\h!ZQW
4$PTXS
$YRQZYWR_
4$]^1l$
<$RTZQ
$!SoyS
4$[RTZ
34$14$34$
1ZXZXW`a_
1ZXS[XPRV^
1ZXZXZXh
RQhMIyOYS
eZ3,$1,$3,$
<$\3<$1<$3<$
3,$1,$3,$\
34$14$34$\WT
3<$1<$3<$
s0*^-r
{hGd)Z
4$YRTZ
,$Q`?mZQS
M_PRSV
3<$1<$3<$\)
WPh5tuYXH
Z]34$14$34$
$h]vu+
[3<$1<$3<$
$$Phdl+f
$\PRQPR
3,$1,$3,$
%*~1l$
4$^VT^Q
>PRTZUQ
$$+R~
4$^VT^
4$ZST[
4+o3h=
nv^SRhr
X34$14$34$
?8?=)L$
^3<$1<$3<$
34$14$34$\Q
oWURh:5
`FnMSP
$XhvmFJ
4$[RTZ
1ZX_VP
34$14$34$
GZ3,$1,$3,$\
$RTZSRhU|
34$14$34$
Z3<$1<$3<$
3,$1,$3,$\U
__3,$1,$3,$\
3<$1<$3<$
34$14$34$
Z3<$1<$3<$\
1<$3<$1<$
lNw^AA
34$14$34$\3
34$14$34$
^-NAg~
eDUSER32.dll
ADVAPI32.dll
NTDLL.dll
1,$3,$\
4$XWT_R
WPh1bV
3,$1,$3,$
e.iHo.iyST=
V1-A4b
8CmB7'
mRHoo>
1ZXaZXSPRPR
1PXZX[
1`aQYZX
Z34$14$34$\
`a`aXV`
1QPXYPRQY
RZZXZXSPR
1V^ZX`PR
4$[RTZP
``RZRZa
4$gF`gW
[3,$1,$3,$\
1ZXPR`a`a
1`aZX``aRZaa
1ZXQYaa
34$14$34$
34$14$34$
^3<$1<$3<$\
PRPRQY`a
1`S[`a
a8umZX
CSFwCk]
_WT_VS
4$XRTZ
4$[VT^
34$14$34$\
$ZQhJ1
3<$1<$3<$
5G4q]W
or8Jk9
CSwkw*
o98Vm9
ohs:=!
o~8}o9
?i8Km9
trp,~<
,Rj=!6
/T'^4ot
/T'^49
o98It9
quKm3tX
IN0B[wk
p3?ku;
a:pu;b
F2i8~o9
a=su;H
67iw02
VM3{i}
4N)ot'
o98:n9
o983i9
@!;CHT
22I^O^
&iI)42I
"/CHT"
ch"PDHT
D8E$`>
EH,yDHT
Eyr}DHTy
{"RCHT
n",DHTyMh
J!yDHT
DHCzDH
8(I5DM@
4>)~XHT
E$`>U$
U$`>E$
DHT}XHT
]$`8E$
d"yDHT
EH!=NHT
EHT@,=T
2["{BHT
c<O7q"iDHT
{DHFzjI
vq}DHTy
Ez"TCHT
J!yDHT@,
r"yDHT
E|"KCHTD
W"mDHT
Q"rDHTy
DH,yDHT
3P>AHT
M.\j?ER`
c.yl?E
.Zg?E1j?E
a?DM*D.
j?EJ*DE
e?EPrc
e?ERjc
e?ERjc
e?ERzc
h?E(er
e?EPzc.
";7dw<
kiJ*DE
z.'g?E
f?EJ'DE
^?DQzc.
e?EXjc
e?ER))$
:.t]?D
c.6`?DS
e?ETjc
WDEOIE
:.+`?DW
3W2c3f%&3W
\)f&&3W
3W9%3W
4W)(WM
+3W(W
Sf%9DW
l?rqx.!8W
.3{ e?
c*)!PW
>B3W{8W
53W1h8W
3E3W{tt
[b+#u`
H7<iHWb1XWa
3W+`W;
23W#(W
+3W1j8W
A3W'h80u
)3W8W
m1t(3W
^,3W)`W0
3.s(3W
<83Wk(W
63f&]QW
H3W1h8W
`+8W;+`W
<3W)(W
Xc0W.
3W1k8W
39! Yc
&3WPW
)3W)(W
3W1e5$RI
3W1i8W
3W'f85
c1fl9{"
3W)8W4q
.H76)PWV
D!`W.!
y73W1i8W
I3W'h8
v;3WHW
i+3W)XW
3.s(3W
a,3W{8WN
k4!8W?
o;3W)PW3
$*3W+XW
63f%P`W
S=3W'h8
I&3Wp0
nm0u(3W
FNr#^O
35p(3W
:+@W;)g
53W)PW
3W (WV<
S=3W9.3W
63f%'4W
XW/)h8W
3W'(Wd1PWV
<27)PWV
63f%C3W
1?3W1r_`
!@W?d>
38)h8W
)(W0k(WT'
C3W#(W;!XW
7!(WV<%
3W+XW;!`W1t
3W((Wc
3W1f8W
)*3W1PW
3Wn3*N2Mo
3W(h8W
a-C!@WV
.H76'(Wd
83W)(W
zuk'4W
6k5!XW
3WsU<*3
H78'(WVhPW_{@W
39)s|x
s4[!6\(es4[!
3W (WV<%
')(W%"
3=!8W2
3W(PWtY-
H7=iPWd
j,3W1f8W
3W(f8W
3WhHW_1PW
?.3W+(W
3=iHWaqPWd
63f%13W
P2o+JN2ec{
+3W1jQ
3W 0W90W
3W+@W;@W
3WhPW^qHWeqPWa{@W
`'h80!XW
s<3W)jl
3W+(W;)
3l.H76{@W
`)0W?O
XW9'h8
iPW^1HW
Jj3Wt(3W
f33W1h8W
H76#(W
)3WHW
3W+0W;
H7<!(WV
3W(h8W
h8)i8W
3W+@W;
x%3W'h8d
{vv?|v
63W1h8W
zs3W9r
5hIAiHWd{8W
1<$3<$
,$|F\f
3<$1<$3<$
Z34$14$34$\
4$[QTY
,$U'wo
Exception Information
Please, contact the software developers with the following codes. Thank you.
(press CTRL+C on this window to copy to clipboard)
CheckIN = %d
CheckOUT = %d
ProcIN = %d
ProcOUT = %d
ExitIN = %d
ExitOUT = %d
TPin = %d
HWIn = %d
IntV = %x, %x, %x, %x
$$L=]w
4$YVT^
14$34$14$
UhSDw}]
Z3<$1<$
_[3,$1,$3,$
3<$1<$3<$\
,$qVAVQ
0qNPQh
4$YVT^
4$Uh7p.b
34$14$34$
5<9Y !
.P.:bJ/3!)
~4jH0-m
4jV<ve
bO48qPz-c
kP7-!|
bK9*dH0
7:JPB@
&+SWG"
H6:sYz-
:bJ/3bJ
<I74jH0
,lR6:rY
qY>;sWz[
+fQ4+zV
3jX>;rY
-,rY.,!)82!)
4iV6 i
G91Yq8
iI48kW
gV7vz_
*dH48bJ
ZXQ`PR
a``aPR
W_aVV^^
`aZXZX
3,$1,$3,$
4$hxWQB
,$QhpO^_
4$H@Pe
1<$3<$1<$W
]hg=5+
UgVe+
09l`Hf}
CBooDB
$TB3KX
CB_RTB
)rAq,B
BU-^Ba
SByxWp
.?M|ars.b
QpFW^B
Z@f 0`
0ZyHxA
5l+1,
>T8tT'
a@fRocb
/;3XAA
3,$1,$3,$\
PR`a`a
1W_ZXPRRZ
$$UT]S
1,$3,$\
4IFSMGR VKD VMM VWIN32 VXDLDR
-Ps[iH
3,$1,$
4$[VT^
$$]7}>
3An internal exception occurred (Address: 0x%x)
Please, contact yoursite@yoursite.com. Thank you!
+&G&<``
1ZXXZXP`
sF}P$)
$^PR``a`aaZ
VP`aX^P
M">~AA
1ZXZXP`Q`aYW
1ZXZXa
ZXZXP`
XPPRPRPR
1`aZXZX
```aaR
1`aZX`
LhY[q"Y1
-`OKo%
4$YST[W
--|}oe
&:fq!Q
&:hG!:
&:pBQ
&:hH!:
&:hB!:
p]l95("
[fo!Qpa
Z!'`hE
&:6kc_
}1pBs
&:hE!:
p/?#{ji
z~d{jj
Ed5UMP{)f
zVd5UM
}dY]M6
yqwkr2nFe
c)p-}Mq
yqwir8
y^.dq+
"CiMV
yvl7yY
+yg{x]
#/M=IyE
aqk86I
qEv"fs
qSCZaqR
yFl+yY
z~d#eM,f
zVd5UMQ
zVd5UM
v.T{fq
yqQK]q
rNd#]M)
rvd#]MY
zVd5]MP
yqPJ]q
RKQd-"
}dY]Mr
MdY]M_
zVd{,j
+7UMP{
yq}iq
'lhJk#
b %7T&
yqPJyq
5At(Cx
Q,,!\4ze
EE]&s:
k.u`<8{
"QMDyQ
7o1lD@
.u`<8{
].u`<8{`<>
a.u`<8{
c_'umCN
Pclkiq
U4{-z8
-4Wa7?D
"t/d9Q
"Qbg'u
i/u^2~
"Qag?u
k#Jvw#
jQ$B[Qcl
k#|2@A
j/[|!^
#`bk#Y
QK^N_ct
kQS!+Q
[#u'0#
Q!)uQC
RGUcm'u
7u[g?u
.u`<8{
8{`<>2
}I=s+{8
#=C-BdXZ
ZXPPR`S[
1R`aZZX
PPRQPR
1ZXQYaZX
PXa`S[PR
|ZXP`PRPX
1`aZXa
PPRPR`a
>apZXZX
_PPR``aPR
V^aPP`
1`aZXZX
Q@9V<a
J(!7V^a^P``
R`W_S[aZP`PRPR
1`W_S[aZX
XP``S[W_a`
PRPRRZ
1ZXZXP
aP`aXaP`P
hJ[>e.;
`aaYPPR
1PXZXZX
PPRQPR
1S`a[ZX
1ZX`aaXPPR``a
RP`aXZPP`PR
1ZX`aaX
AV7PAa
PSPR`a
PPRQPR
XPSP`aX[
4$ZRTZU
Yh""Rj
_Z[1|$
4$XRTZ
3,$1,$3,$
aV`aPR
2C`aa[PS`PX
ZXPPRPRZX
QQQYYYPRPR`a
1ZXZXZ
1ZX`aa
`RZRZaXj
PRRQYZ
`aaZXP
PRPRS[
1ZXXZXX
1ZXYPR
ZXaPPRPRS[
1ZXaXPPRV^ZX
1`aZXZX
PSPRQY
1ZXaZX
LXxW_aX
1ZXZXaP``QY`aaR`aZa
1ZXaZP
;VPR`a
1ZXZX^
`R`a_[
VPXaZX
`aa^P`
gK28';
1ZXW_a_P
1ZX_ZP
P`PRPX
:aZXPQRQYZY
X``aPR
1ZXaaP``
P`PRPR
'ZXPR`a
1ZXZXa
98R\aa
1`aZXPQ
1ZXV^a
1``aPXaZX
PPRWPR
SP``QY`aaPR
1QYZXa
[P`PR`a
PRWQY_
1ZX`aa
PSQ`aY[
1ZX_P`
1ZXRZaa
``RZPR
`aaZXP
PPRPR`a
XP```aV^aSPX[a
1ZXW_a_
1QYZXPR
1`aZXaXj
_g'A:}
PRPW_X
`aaaPW
&PVP`aX^
1ZXYYP`
aPPRPR`a
1ZXZXZX
1ZX[ZX
1ZX`aaP``PR
1ZX`aaSS[[a
1V^ZXX
1ZX`aaXPV`PR
PVV`a^^
P`R`aZ
P`R`aZPR
1`aZXa
PRWQY_
1ZXPXaZXPPR``aS[a
1ZXaZX
1ZXZXZ
1RZZXZXX
SkkHDB
wP`V`a^PRRZ
1`aZXa
Df~PPR`
1`aZXZX
sSS[[a
1QRZYZXPQ
XPPRPR
XPPR`QYPR
5I3|ZX
PPS`a[X
`aP`PR`a
ZXPRPR
1QYZXa
1`aZXZXP
1ZX_P`PR`a
1ZXZX``aPR
1ZX_aP
1E6=<a
8&Xl72
ZX^PQ`QY
PVS`a[^
ZXaP``V^`aa
PRQ`aY
1ZX[``a
1ZXaZXP`PR
PWPRPR
1PXZX_
aZXP`Q
1ZXZXa
1``a`aaZX
EQ`aa[P`PRS[
*3Q&SPR
ZXPPRPRPX
1S`a[ZX
QYP`PRRZ
[ZXPPR
1`aZX^P
:u&xYP
1ZXV^aZX
PPPRW_
1ZXZXX
[hPLwWQ
1`aZXYP`
pyCz<hf
1ZXZXPRQY
i|ZXaP
1ZX`aa
JUctPR
|1PP`PXRZaX
Ye4`Y
H)ZXPVPR
ZXPR`a
1ZXZXaP
PRPRRZ
1``aPR
1ZXaZX
a^PPRPR`a
acOJ-|
1S[ZXPR
_^\!<a
1PXZX[P
PPRQPR
,$\VT^
,$e<?=X
&uHHjuHHj
Y!-Z].
`/,J!gG
1^Y/mh
->Z'5h
rU ]'Eh]
,-2%g_
%5h`%}h
!mh['*Z
dI{x&1
dI{x&1
\0)/\"
K3X2)Z
\"12X"
e\"13X"
xj13X"
k)E)C\"
j_)\"
\"11X"
)TRIYN
NpgX8C'
HCgGz?
eF?>XG
z)n*Hoz3D
/FdlGJ
,;jF+>
#xv?zQ&
wc_^_#DC
ah_^#>
}n!1cl\
ZG@i`Y"
zU_^bY
}>%rE>
0$H*MU
+{v~/s52
|}:*"G72
*It#*av
*It#*a
*It#*av
*It#*a
sVXQU
8?/08{
"88Pj0Y
]Riby#
W]eZV9
Q!eHW9
M8Qtpp
M8XobV
;h&X85
Fkh=*(
gb|&2bri
gb6J7b;oxb
b>1t~1
b>x`+m/
b>nZ9
4)-Kc&
I6F4/I#U
sOiB}i
:3x\nO
P;YXBBz
Xt#NXt
4r"frdw
^Xt#NXt
y N>Xt
X_Jr|p
nx_+r|p
X7r|p#
r|p!fX
nx_5s|p
r|p!vX,8
vX_|r|p
r|%N>Xt
q+r.u+rJK
z|UJzA
l+rTpc(|"
:|_}j|Vw
Upr2p
pr2pr@s"
z|-}R|
+|W&z|
+|>.z|
\|'W{|WX
nx#NvX
nx# nXJ4
._1r|p
r|wwE:
r|pI~XM
r|-N~X_
r|pI~X-
X_zr|p#
X_Rs|pQ
coXxcWXq#
Dc"/TS
r|,86xp
r|_+s|p
`oXq#nX-
X,8x|p
n(*8n{p
NI~X_6s|p
r|p!vX_Is|p
r|p#VX@
[C(8l|p
<NT#=I
pKz[-H
<N6;=No
|=I?Mab
HkMab6
:n~Sab
"n~hdg
2n~)dg
:n~Fab
GabX#=F,c
IZNab6c
Izag7
GabqlzW
~J~/ab
HabT#=
Hab~(ab
=I7"ag
Hyag7
2nQ7dA
`IjMab
2n~Jab
Habk`QU
HaF~Mab
*nkDk[9
I|"agWs
HaE~pag
5[>|R/
Gh"}0>
aNG)b/Gab
G)bNG)b
a\!a@
alXa9.
UaG*aJ
^?-QUU
`|8D=y
GYb.GD
UaMa
a.GYb.Ge
aNG)bNG
aNG)bNG
ItR?(}z5
b.GYb.G
`:Z"7I
a/Gab<Nab
`9[VbPi
a.GYbNGQ
b.GYbNG)b
b.GYb*G
:n6#=N
r,$:
b?0$:
J3|2Be7
t*$b?EY
w/$b?
!9dqw
z?`yw$
$b?FL)
w0$z?4
Kd@F;
\*GiwR
E&6Z.#
C]$>6U
b?-":^
ro?`yw
b?*<d#
+#Fqw$
A8^iwe:
+#4^a<
ow Fiw
+#-d=!
bX-MLG4
sl5<b"
#?{_*i
`&e%$z?-b)
rg?)$.
*+$)|C
+$+$:
<$3N4
>gWTs6
3f<<Af
tk^ydk
lfy1kfytk\
#fHv3f
eu_#f5
#f~x#fHpk
y-k^yuA
]ydk94>k
udk0f+k
vtk^yFk^y"
}knnnk
?~k.AW
qHk^y)k
kfytk\=73f
udk^y)k
ydk^y)k
kfytka
Lnaydk
+k^y)k
kfytk\
lfysqfytka6
kfytk\]$
sfKc3fA
AfoMTA>
B3fIT&C
eS+#f.
x!OvxaO
YFAwFP
kfpD:JQ
r#u~U
xOZq7W
y!O^xaO
mFBOZo7W
J&}H;N
vxOZqG
YFAwFP
kfy<AwFP
x!OvxaO
y!O^xaO
WFAwFP
HOZo7W
/M\9lD
nfyZofy
Hw`GCb,
kfyYofy
X?gkD#
FrOZxaOgR
eIm3fA
yhT=&+k
kTg>k^Q
u.kfy-kfytk\
y)k^y)k
#fu1v3>
y-k[Q~k
sfwe3fA
sfIF#fA
#fGbAf
y)k^y)k
aCQF6i
eEm3fA
mk^y)k
lfy=kfytka
kf}kfQ
/#f`fKM
sfK[2xQ
u.kfy=kfytkaR
kfG{kfQ
#fAHsfL
eAMAfA
ydk^y)k
y-k}qnk
u.kfy=kfytkaQ
sfO<Af~
3f8zsf
e[#AfA
e#(o6!
sf$|3fA
u.kfy=kfytka
sfRFAf
Ftd3f*
lfytka/`
kfytka
ydkz|)k^y)k
lfyEqfytka
y-k^yFk
#f5}Af
k^y.kfy
kfytka
yO1>k|
~kfy<AwFP
x!OvxaO
kfx!O^xaO
4$XVT^
3<$1<$3<$\
3<$1<$3<$\
1ZX^``aV^`a`aaa
1,$3,$1,$M
DOPRPR
1ZX`aZX
$hqi$
4$[PTX
Y_PPRPR
1PRQYPR
ZXPRPR
1ZXZXZX
$$G7>r
34$14$34$
4$_UT]h
$QSQhD
4$XUh\
+N_)L$
MabPZF
x(C=V8
NB[vZH
34$14$34$\
1`QYW_
aZXPRPR`aPR
QYZXZX
_3,$1,$3,$\
$h^Sf*
1ZX^PR``aPR
ZhgGAD
4$[RTZ
1ZXZX``aW_`aPR
1ZX_aP`PR
1ZXPX`aaX
$<WT_Q
3<$1<$3<$
4$[ST[
4$[RTZ
~H}hAbD
3<$1<$3<$\
1`aZXP`aPR
1ZXXPRW_PR
I|31T$
3,$1,$3,$\
WPRZX_
4$It5Q
~PXZX[
``aW_S[a
3<$1<$3<$
X3,$1,$3,$
$$QSPQ
<$\hX-
14$34$
NJ{jzs
]7j=F.
4$[RTZ
>Nm{!t$
4$[Uhx
1ZXaZ`
ZX`V^`a
18w)t$
PRV^`a
$$^{.z
~Q`a`aYa
a[``PR
4$[RTZV
PRPR`a`a
1ZXPRZV^XZX
1ZXZXPR
1ZXZXa
1ZX`PR
aPR`PR
1ZXS[a
PXRZZX
34$14$34$\
a`aa`W_
#QYPXRZaa
_!-qPR
B}{G-w
qTuqy)
-8?_;Z
_}1L$
,$F~%?
34$14$
34$14$34$\3
4$_hPk
ikk/i*
Ph*PMj
h4C"Qk
hh 3Ij h
ia6%oQ
3-hkh*
\m"7Qk
3.h16/oQ8
'oQk'k5
L3V4k}
7kvV%6=
5Hl#5V
5:?]p
aI6/7Q
s&eVh*C
Q16t z
i16QoQ
oy7SAm
s6fVh*CDn5
ia6Q?Q
s^cVh*C
i96QoQ
aI6/oQ
ia6%oQ
,7Q.6hhk
h<SDA5
YE"yV]
khIh*
Qh*(Dr
h5!nru
hfRDn5
\j"7Qk
h5ZG}
PDj"@VB
/r+"mc\ID
"'oQZx~
)7Qknh*
^ha6Q?Q
ia3#k=
B>q4kGt
Q#5n]A
5jq#5gD
h3F7#55
ia6%oQ
>/oQnw
16ioQC
i16/oQ
i96/?Q
16-w1k
aA6/oQ'
I6ioQd`
jo4c,r!?q
=16G#+
Sh*h6k5
i6'7Qk
[q$Ge5
9or3et
Fn>//Q
h4zDk5
0.D~v+Vrs
7AYQ8n
'MEsDt
S8&W53{
``aPXPR
4$0wyyV
$0so'U
$}T{+P
1PXZXZX`S
1ZXW_^a
$$YN1{
RZQYZX
3,$1,$3,$\
4$[VT^
$$QPh/m
VCT'mb>k&1QY
$WSVha
1,$3,$\V
4$XST[
$$3<$1<$
1,$3,$
$$VSRV
34$14$34$
.F;xWQf
:[y_Qf
xl=B^[="
xxVC|m=
5Zzo5Zw
xh=tRl=b
gLjh=y
=O@[="
FnPbb0hj
yl=oAE"
:7FUu\[
"=3)aV
M\d3mw
lZ2OB|
`./nEZ
lZHkEZ#
jEQS=^
xl=[sQ=
wj5<mj?
:[(Po*
Vm(n`=Z
d2nc=Z
^>~tQb~
SokHIe0
PokHIekHSokHIe*
^>~tQb~
:ZLf;H9
:ZxWQf~
:ZPwQf
D#<CcA
PAtx&eAx
:ZP!e2
fj6i`X
!pr-;)M
?#4#s6f
"E:\'w:
C:\#E'
=@<}#=
8l(qv
De2qvy
b+0vl,2=)
tAvFqa4
0v5i4v
0<:j,r4v
4vch4v
Aw=sx7?u(
dAs>#>
dAs>>
%%Su@OiS~d
dAs>%>`
dAs>$>
dA|>^As
sZC|8]
dAs@%>s
NC,pM;s
>W]LC
dAs>#>
=W8D=w
dAs>!>
nVC,AK
dAs@>s
dAs@H>s
dAs@#>s
cAs@H>s
KdAsI`As
yVC,9
|rnuPmz
/WC,AGK%
!VC,;`
dAs>H>
%WF204
dAs> >
AS 436
bCk9s<d
Xzp$YI
r<d9s(d
dR=)d9s
r<d9s(d
A)dXcv
s(d9sJN
{Fk+`pLk
r<d9s(d
d>g<d.=
dEKczZ
d9sOW\
>V:s(d
#P<d9sg
*Q$j3[}
r<d:>$
d9sAH-
dAsXaAs
]Ks??`
:fnO h{
34$14$34$\
3<$1<$3<$\
1ZX``PXV^PR
4$XPTX
VPX^SPR
PR`aV^
1`aZX``a`aPR
1ZXaS`
$hzooW
Q``a`a
1ZXaY`
`a`aPRW_
1`aZXa
4$XVT^
a`W_RZa
$s'x{R
`aZXPRPXQY
;HH@-
`aPRQYS[
PRPR`a
1PR`aPR
1`aZX`
nZ.";!uD
4$XUT]
XP`aXY
?X5N.|
4$XWT_
^OMj9]]S
Jkq1l$
ru/./2c
ELi3K@r
^WV;${
KVJ_[VE#
VFev7"
6\X6V1
4;N9WV7
-3''YC
5VVqYs
VF1,,<
'6VE(9
V{.WV;
VfqCH;
5Ve]LV
VVIOLV
C~pVTG
5V&suc*"
gCjruL
V!E6V7
VFLWVr
1/[V!;
fa^6VG
8NZWVF
-WVxvk
KV>[V
5VkFLV
VVBQM|
'g^[V1/6V;
k<>b[V
]Q[Vi9
*6Vd(LV
_i~6V[
5Vr>6V
K|\'kLVG
VD96V~
VVi5uV
;kZWV7
ZV(PWV
N[qWg.
4$XUT]
4$[RTZ
1`aZXa
4$[UT]
3,$1,$3,$\
0vy_GU
S[XPPR
34$14$34$\
8SRQYW_Z
34$14$34$
PRSPXV^[
1ZX`aaZX`V
^`W_PR
3<$1<$3<$\
S[PR`a
1ZXRZa
ZXPRPR
1`a`aZX
4$XUT]
3I%DZXP
``aQY`aa
PRS[PR
ZXaPRPRPR
1ZXRZZX
34$14$34$\
-#ig~%
3<$1<$3<$
$$hJF02
,$!Ok?
o-bH~z
PRVW_`a^PRPR
1ZXPXa`PR
3<$1<$3<$
4$[ST[
<$\SUV
`WV^_``a
1ZXZXa`P
.6v%>y
MXWPX_
$hWl2B
1ZX_a`PRPX
`aZX`RZV^aa
PRRW_PR
3<$1<$3<$\
PRPRPR
1`aZXQ`aS[Y
1ZXW_[
$UT]QW
`aPRPR
3<$1<$3<$\
1`a`aZX
34$14$34$\U
PINo|S
$TZh"9
Mta}
3<$1<$3<$\
4:081l$
4$"NzuR
3<$1<$3<$
1ZX`a[PR
S[RV^Za
1RS[ZZX``PX`a
1ZXQYZXa
4$XRTZ
3,$1,$3,$\
ZXQRZYZX
1ZXa``aV^QYPR
3,$1,$3,$
4$XQTY
4$XWT_
S`a`a[ZXWQPR
1ZXYPR
1S[S[ZX_
4$XWT_
1`aZXYPR
Z`QY`a
4$f3W~V
1ZXW_a
RZS[V`a
$TcfsV
3<$1<$3<$\
4$XUT]
34$14$34$
3<$\VU
Z]3<$1<$
34$14$34$
%X{/)|$
%X{/_X
3<$1<$3<$
$h^*)v
!i8=b2^
W2lk:.^
WrT(+\
2dnbZ_
j,iurq
%]pzO5
FOssymNs
{]g0F(s
oFO(sFO
|FO(sOKNs
O(sRw_
O(sFOp
yOpFONs
zO(szO
(7<J]k
OsszOss
os\@p
ONszOss
OssFOp
QNszO
0#pFONs
Oss@?^
PDN98Aq
OspJps
ONszO(s
oFOss/z%
M5&8ss2
*zOssZ
WqL(szO?
$>EONS
NG~zO!
yONszOa
O1qzO_
ELc>@6
zOssP5Ns
mkuYA/
!a%c[B
O(sFO-
Oa3zO(sh
sPI|OszO
O(sFOp
=P,LW:#
55FOp
O(szOss
?XU(sFO
O(sFOp
O(sFO1q
O(sFOp
OssFO(s
oFO(sFO
ozO(sFOps
oFOsszO
ONscPR
ozOssFO
pzOssJ
oFOssnO
2qH4!C
(N>IOf
~6zJHz
O(szO1q
),2[,N
O(szOps
ONsFO(A
#zOpt
Oss6(j3
Qksu~"
O(szO(szO
Op8{Os
O(sN(Osi
jApFO(s
oFO(sFO?q
ONszO>
(sFO(szOpsFOss
tsz_p
|pzOp
zFONsFO
w#LssFO
ozO(sFOss
oFO)]v
pRCps\
OpzOssFO(s
ozOssFO
omu$|*3
1ZXaPPR
1ZX`aXa
1RZZXP
3<$1<$3<$\
1`aZX`PR
]34$14$34$\
4$XST[
```aPXa`
1ZXZXaS
PRP`aXPR`aPR
Q_PRQY`a
1ZXZXZX
`S[V^PXa
QZXRPR
1ZXZX`
3,$1,$3,$\
_3,$1,$3,$\
4$[VT^
34$14$34$\
``aPXS[a
```aPX`aaPQYXSPR
1ZX`a[aS`PR
4$XUT]
3,$1,$3,$\
PRV^PR
ZXPRPX
1ZXW_ZX
1ZX^^PR
1SQY[VRZ`a^ZX
1ZX[`PR
1ZXRZa[
1ZX[XSVS[^[
;Y34$14$34$
34$14$
Antivirus Signature
Bkav W32.AIDetectMalware
Lionic Trojan.Win32.Amadey.4!c
Elastic malicious (high confidence)
ClamAV Clean
CMC Clean
CAT-QuickHeal Trojan.Ghanarava.1735400731268de2
Skyhigh BehavesLike.Win32.Themida.vh
ALYac Gen:Variant.Mikey.172612
Cylance Unsafe
Zillya Trojan.Themida.Win32.125360
Sangfor Suspicious.Win32.Save.ins
CrowdStrike win/malicious_confidence_100% (W)
Alibaba TrojanDownloader:Win32/Amadey.1c967e75
K7GW Trojan ( 00587f0f1 )
K7AntiVirus Trojan ( 00587f0f1 )
huorong Clean
Baidu Clean
VirIT Trojan.Win32.Genus.XLD
Paloalto generic.ml
Symantec Trojan.Gen.MBT
tehtris Generic.Malware
ESET-NOD32 a variant of Win32/Packed.Themida.HZB
APEX Malicious
Avast Win32:MalwareX-gen [Drp]
Cynet Malicious (score: 99)
Kaspersky UDS:DangerousObject.Multi.Generic
BitDefender Gen:Variant.Mikey.172612
NANO-Antivirus Trojan.Win32.TPM.kubzrr
ViRobot Trojan.Win.Z.Zusy.2976256.A
MicroWorld-eScan Gen:Variant.Mikey.172612
Tencent Malware.Win32.Gencirc.1425c328
Sophos Mal/Amadey-D
F-Secure Trojan.TR/Crypt.TPM.Gen
DrWeb Trojan.MulDrop28.52943
VIPRE Gen:Variant.Mikey.172612
TrendMicro Clean
McAfeeD Real Protect-LS!1C41E3FBE310
Trapmine malicious.high.ml.score
CTX exe.trojan.amadey
Emsisoft Gen:Variant.Mikey.172612 (B)
Ikarus Trojan.Win32.Amadey
GData Gen:Variant.Mikey.172612
Jiangmin Clean
Webroot Clean
Varist W32/Agent.JDU.gen!Eldorado
Avira TR/Crypt.TPM.Gen
Antiy-AVL Trojan/Win32.Amadey
Kingsoft Win32.HeurC.KVMH008.a
Gridinsoft Trojan.Heur!.030120A1
Xcitium Malware@#3brrslva9pd10
Arcabit Trojan.Mikey.D2A244
SUPERAntiSpyware Clean
ZoneAlarm Mal/Amadey-D
Microsoft Trojan:Win32/Amadey.BAN!MTB
Google Detected
AhnLab-V3 Trojan/Win.Generic.R687037
Acronis Clean
VBA32 TScope.Malware-Cryptor.SB
TACHYON Clean
Malwarebytes Trojan.MalPack.Themida.Generic
Panda Trj/Chgt.AD
Zoner Probably Heur.ExeHeaderL
TrendMicro-HouseCall Trojan.Win32.VSX.PE04C9j
Rising Trojan.Agent!1.1074D (CLASSIC)
Yandex Clean
TrellixENS Artemis!1C41E3FBE310
SentinelOne Static AI - Malicious PE
MaxSecure Trojan.Malware.7175239.susgen
Fortinet W32/PossibleThreat
AVG Win32:MalwareX-gen [Drp]
DeepInstinct MALICIOUS
alibabacloud Trojan[downloader]:Win/Amadey.BMS2XJC
IRMA Signature
Trend Micro SProtect (Linux) Clean
Avast Core Security (Linux) Win32:MalwareX-gen [Drp]
C4S ClamAV (Linux) Clean
Trellix (Linux) Clean
Sophos Anti-Virus (Linux) Mal/Amadey-D
Bitdefender Antivirus (Linux) Gen:Variant.Mikey.172612
G Data Antivirus (Windows) Virus: Gen:Variant.Mikey.172612 (Engine A)
WithSecure (Linux) Trojan.TR/Crypt.TPM.Gen
ESET Security (Windows) a variant of Win32/Packed.Themida.HZB trojan
DrWeb Antivirus (Linux) Trojan.MulDrop28.52943
ClamAV (Linux) Clean
eScan Antivirus (Linux) Gen:Variant.Mikey.172612(DB)
Kaspersky Standard (Windows) HEUR:Trojan-Downloader.Win32.Generic
Emsisoft Commandline Scanner (Windows) Gen:Variant.Mikey.172612 (B)
Cuckoo

We're processing your submission... This could take a few seconds.