Static | ZeroBOX

PE Compile Time

2019-10-17 22:15:02

PE Imphash

e124209f91a98dbd65697c49d4798cec

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x000b299a 0x000b2a00 7.91995001612
.data 0x000b4000 0x005d4a48 0x00001a00 2.60317611167
.kefo 0x00689000 0x00000001 0x00000200 0.0
.zokohef 0x0068a000 0x00001179 0x00000400 0.0
.new 0x0068c000 0x0000327d 0x00003400 5.44270431781
.rsrc 0x00690000 0x000023f0 0x00002400 5.37689689789
.reloc 0x00693000 0x00005260 0x00005400 2.09782065754

Resources

Name Offset Size Language Sub-language File type
RT_CURSOR 0x00691408 0x00000134 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_ICON 0x00690310 0x000010a8 LANG_BELARUSIAN SUBLANG_DEFAULT data
RT_STRING 0x00691fb0 0x0000043a LANG_BELARUSIAN SUBLANG_DEFAULT data
RT_STRING 0x00691fb0 0x0000043a LANG_BELARUSIAN SUBLANG_DEFAULT data
RT_STRING 0x00691fb0 0x0000043a LANG_BELARUSIAN SUBLANG_DEFAULT data
RT_STRING 0x00691fb0 0x0000043a LANG_BELARUSIAN SUBLANG_DEFAULT data
RT_ACCELERATOR 0x006913d0 0x00000018 LANG_BELARUSIAN SUBLANG_DEFAULT data
RT_GROUP_CURSOR 0x00691540 0x00000014 LANG_NEUTRAL SUBLANG_NEUTRAL Lotus unknown worksheet or configuration, revision 0x1
RT_GROUP_ICON 0x006913b8 0x00000014 LANG_BELARUSIAN SUBLANG_DEFAULT data
RT_VERSION 0x00691558 0x000001c0 LANG_NEUTRAL SUBLANG_NEUTRAL data
None 0x006913f8 0x0000000a LANG_BELARUSIAN SUBLANG_DEFAULT data
None 0x006913f8 0x0000000a LANG_BELARUSIAN SUBLANG_DEFAULT data

Imports

Library KERNEL32.dll:
0xa8c00c LoadResource
0xa8c014 HeapAlloc
0xa8c018 SetWaitableTimer
0xa8c01c HeapFree
0xa8c020 GetModuleHandleExW
0xa8c024 GlobalLock
0xa8c028 LockFile
0xa8c02c ConnectNamedPipe
0xa8c030 GetConsoleAliasesA
0xa8c034 FindResourceExA
0xa8c038 GlobalAlloc
0xa8c03c GetLocaleInfoW
0xa8c048 GetFileAttributesA
0xa8c04c GetExitCodeProcess
0xa8c054 EnumDateFormatsExW
0xa8c05c VirtualUnlock
0xa8c060 LCMapStringA
0xa8c064 GetAtomNameA
0xa8c068 OpenWaitableTimerW
0xa8c06c AddAtomA
0xa8c070 GetTapeParameters
0xa8c074 GlobalFindAtomW
0xa8c07c GlobalUnWire
0xa8c080 VirtualProtect
0xa8c084 GetFileTime
0xa8c088 GetCurrentProcessId
0xa8c08c EnumCalendarInfoExA
0xa8c090 LocalFree
0xa8c09c CompareStringW
0xa8c0a8 GetStartupInfoW
0xa8c0ac TerminateProcess
0xa8c0b0 GetCurrentProcess
0xa8c0bc IsDebuggerPresent
0xa8c0c8 RtlUnwind
0xa8c0cc GetModuleHandleW
0xa8c0d0 Sleep
0xa8c0d4 GetProcAddress
0xa8c0d8 ExitProcess
0xa8c0dc WriteFile
0xa8c0e0 GetStdHandle
0xa8c0e4 GetModuleFileNameA
0xa8c0e8 GetModuleFileNameW
0xa8c0f4 GetCommandLineW
0xa8c0f8 SetHandleCount
0xa8c0fc GetFileType
0xa8c100 GetStartupInfoA
0xa8c108 TlsGetValue
0xa8c10c TlsAlloc
0xa8c110 TlsSetValue
0xa8c114 TlsFree
0xa8c11c SetLastError
0xa8c120 GetCurrentThreadId
0xa8c124 GetLastError
0xa8c12c GetCurrentThread
0xa8c130 HeapCreate
0xa8c134 HeapDestroy
0xa8c138 VirtualFree
0xa8c140 GetTickCount
0xa8c148 SetFilePointer
0xa8c14c WideCharToMultiByte
0xa8c150 GetConsoleCP
0xa8c154 GetConsoleMode
0xa8c158 GetCPInfo
0xa8c15c GetACP
0xa8c160 GetOEMCP
0xa8c164 IsValidCodePage
0xa8c168 FatalAppExitA
0xa8c16c VirtualAlloc
0xa8c170 HeapReAlloc
0xa8c174 MultiByteToWideChar
0xa8c178 CloseHandle
0xa8c17c CreateFileA
0xa8c188 FreeLibrary
0xa8c18c InterlockedExchange
0xa8c190 LoadLibraryA
0xa8c194 SetStdHandle
0xa8c198 WriteConsoleA
0xa8c19c GetConsoleOutputCP
0xa8c1a0 WriteConsoleW
0xa8c1a4 LCMapStringW
0xa8c1a8 GetStringTypeA
0xa8c1ac GetStringTypeW
0xa8c1b0 GetTimeFormatA
0xa8c1b4 GetDateFormatA
0xa8c1b8 GetUserDefaultLCID
0xa8c1bc GetLocaleInfoA
0xa8c1c0 EnumSystemLocalesA
0xa8c1c4 IsValidLocale
0xa8c1c8 FlushFileBuffers
0xa8c1cc ReadFile
0xa8c1d0 SetEndOfFile
0xa8c1d4 GetProcessHeap
0xa8c1d8 HeapSize
0xa8c1dc CompareStringA
0xa8c1e0 GetModuleHandleA
Library USER32.dll:
Library ADVAPI32.dll:
0xa8c000 EqualSid

Exports

Ordinal Address Name
1 0x4acbd0 Gorgeous
2 0x4acbc0 Robinson
3 0x4acbb0 SeeYou
!This program cannot be run in DOS mode.
`.data
.zokohefy
@.rsrc
@.reloc
_VVVVV
HHtXHHt
>If90t
^F<-uB
<xtX<XtT
jF<-uH
<xtV<XtR
<at9<rt,<wt
URPQQhpc@
uBhnr@
>=Yt1j
QQSVWh
j@j ^V
Y;=0KK
0A@@Ju
Fh=(EK
to=xMK
^SSSSS
j"^SSSSS
tM<it-<ot)<ut%<xt!<Xt
<dty<itu<otq<utm<xti<Xte
HIf98t
HHtYHHt
tGHt.Ht&
^SSSSS
8VVVVV
;t$,v-
UQPXY]Y[
_VVVVV
_VVVVV
0SSSSS
0SSSSS
0SSSSS
0WWWWW
AAFFf;
t"SS9]
C PjPV
C$PjQV
C*PjTV
C+PjUV
C,PjVV
C-PjWV
C.PjRV
C/PjSV
.;1s(N
HHt4HHt
Ht\Ht,
teHtFHt&Hu
ty<%tA
PPPPPPPP
PPPPPPPP
0WWWWW
u,VVWV
t VV9u
t+WWVPV
^SSSSS
^SSSSS
>:u8FV
Pf95,dK
VVVVVQRSSj
^SSSSS
^SSSSS
0SSSSS
^SSSSS
^WWWWW
0SSSSS
8VVVVV
`W/EI<
7Ge[E;
b</0ARr
wxsER,
?>z]A5
lh)nT{
-`>Hm.
lu[dPYvHj
&z?>:B
|U?'"x
Ac%3j:
q,nH"Z
_|LZ4]y
V*[=S|
O;9L3d
X;h)2F{.
o!d{<e_J
vG=[-5H;
/Z%OC|l
i|M?NO
~6Q%="
Ucv6$&
5%z,mj
cLk$P[\
"$LW,
Yfvtw(
83S:fh
MSN_qx
tN&z}8g*p
Rqse>o5mZd
\=fKEL
!7lMWc
;Ky(IY-
S_U,(b
hRDc.=
<:HYCf)
]pD%6M
P>PI8fv
"u&Z:fh
YPm-E]
bxase
s=JO91
I/]U"
B/if|HnW=
GfURF>
rY-7F8
gO"wzG
!t?GD[
S&nUBwrf
M#jxG(
t.W~ `3Rj
=Y`l10
yYEb7m
9SX2i}W
4S%|kTg
B(]hwrE
SsA)s5 (;
97x^V.
{N812\
Hx<<(p
C\2v=b0
DNNT]n)
OeUT>a
nBzeH~
de-W_O
Zc,HYuT
9Y%u@&
c]+aC\
0yVYN,
W;qo=i
dQatzcl
uAhO+9s
GLhQ(\#
wUl8.K
;nioWs
y's#tb
BwG|IS
!@pfC\
P%Fs 
*I)Xkt
[!yS:U
.[@Yi.
COM.eZK
ab}=BC
JGs 2L
1usE<P
>fj B&
;BVhpWI
qWjK%
XlIS,h
1tA~I|.%q
H%[6`/
G1V@*i
A/q,s=j
]\jj:&
r^gq0~z
lwN2ZB9{
j2\dRh0i
_Vl!@I
;GNhM?
Gz}uy7X
`LJsCC5
Y{,xn,J
vQa\y&H
Q*Yqb}dG
|k*J\:vn
*r-3Y6
b?v}x$
=6"S%b
;%6,EE
W9@qyY
$~.N0w
i8J15=
j@q{cA
,t+Sc
pu<<,@
vB^l7%
Ziw"iB
/&rsKzm
v\Z`6\%
{V#Q`28
Y.h`'+4
"Nd8k
+sk=Y;
>wdsgs8Q
5pB4,{
u,%|Ei
:0:*qm
O6V(-j
cO !&oK
Jy2q*He
y*fT}m
mZ{<^<{y9`
Y>ZKFy
|*+0vn"C
ZK^{>$
bZ.YQW*{
g0nWQP
e0f0#1c
yCf/HH
_Ho;2qv
6Uc+~#
cjJUin
x96Aw/
nR`oc
Kq\Ih.eY
-uBEX Z2y
QL$<'7'!n
WRe2WY
0>&>oi
0;8 TmYYR
t5?xls
"ovc9b
Z4w/xTGN
f%Pjx;
914A5@
%8FFQ_W
fRXg!n
lHme/l
7-P.|z
_p6P&Y
ae^Gs*
KW~BI)
],$h f
\=r9{2
w+;+g9
kiG"'"#
)Oq-A3
l?SfF^56
py|jK]
?nl\r'
$1j8}}
9PdUiM
SC9aFy
V6"/4;
:M*v8vz
/gT2:a
c ?Ibz
^3:BlFS
ZqxCR
mRHh5;
(RIkdla
N(<eA&n
2r<|No
7FcU]-S4>7~
y@tfBP
V\vk<5)
>:PmY^
m~n_Vxy
=ja-2(
o RD9)
gh,eH6
~!vWFa
\:7k&d(
Ac0k=D
Xq0gw5
c?H'I8^<M
NAR_-G&$=w4<
N4Z1;F1
;E~3?1
U!}&6AD
*V7OCL
i]N%N%
*vFS@m
(\"zOXD>CE
^-oi-M
[qpIv5*
uU9P*9n
Wk!-"c
+-yo}v
<;1&\y
r7(]x!v
3E:e)d;j
atc>F\
-ziAg(`."
LTmXa-
yF(T2|
iEBrg]?!
15$~(i
d(hqr$
N+@[4;X
PIA6}T
fC<}l<
%wUbeQAs
oEU`Y3
|{>hRT+}
V-+3ez
|"&)EG
5s#f
pqeCOr
#Zk4Oh
D;Y%9w
u!i.um
Jmx[\
2jLpc
`<5X3S
3b:@Ph
\{QJaj
hO#_wh
1kMBwJ
}$}Myw
DI$=0D
^D4Mu:
1(\j4.E
BMV3P.
.?yvEc
YE?~c0ki}xBqv
$#0ATb
'OWul6
gGeztS
$B)/]QY
Ykha#U
NYWoI%
OM^2~+d_E
OE3z&F
%E&rhso
H/4{]$
w>=mO/
f#LeNl
pGP]Euy
=[n/s
CZ$6m'
{jD;p4
zey]St%ZH"
[nNQtz
2^c9!8
'_TN~}
aR(>k:
%/4I2l
h6C\RYoH
FZ~9*N
H|k4lZ{Z
!F!uu2k*}
MZ8>\K
bB&9"T
8?!SV5%5M
5362lsa
8g|#0t`g
#0_:Ow
u]9g@n
ZT$qfW:
yn08+b
y^6hvlx
:0$+ozgoDH
C#01`H
@Rw'uy
!z*Ri/
(w`E\l
4$ \+\4`
pLe\Bh+u1
i&RnAU@
5:!k,r
XI\KIH,r
X5SA3U3[
1%qef/]h
z6.?6v
4c"R1G
;hi,Br| 0
l_bVH;
1+Z<#[m
*m.!,
&AAAwkv
;4fq3}
o"<0T!
A.:y`B
CpLE_2
M|Kow\
58&NED$
g0yl'j
QDjifC9
5+tlG;,
#.3,1|E
U?kIn@
wIW&kSq
q,qO?S
~nx78!
s0a1nSGQ
|26Sz$
IYy's
"@x-B;
dY*wZ]
<7p#=5
FMkTu{
w}Uf,]
4{4DhH
(dGk@\
=XZn34
\@#AIYI7
(@Oi4l&
5Q\|Ro
S+zn)C
sO6C-Ns
p"{dmi6
`Yf$tsN
ojAH"9
?`PWx_
;BY\2rl
h55%Ec
spp1n,
aLN5n?
RlDL6?
qNXJ<9j
:Tbo$[
&As63D
Tk<`{+
QDnuW\
5o(t\RkA~
*-c#\2
Vzf7!
XD#Fo!}P
vR|6Xf
u?ov9P?
+F>r7.
_o)C|~
lC.B-_
S] <+=
<=qB(
V N}fo
k*R0F@
!H)Dtl
x<ex?{
;M\KrM
9gvg)I
J~~W!O
V[e3q J
i'er:n7
f qd{%U
NAEh<&
1Mo^i\
GRHQ2
cAUvAx
>7Y}p^J4
[Heq]w
WFWsNZ
)*\-/b.
0#:`=b
HdkMF'
}fIsX
l:dv`?]
EoiH9Z
*E=EWtr
;xw7"M
AULA$)
Dh)59B
Q==el*
`Z^K2(8-
^y!R:}"#
*+,oFF
rr!V41
?g9:']
}-{N6
Wobs\`
3JX^/Ugt2
_7gJ(s
_8[vqe
T$_>-;.
62;RWhN
qR.^Zk
*fDnD6<
5a<*dR|
zK^^#P
U!`[AA
q6@]@Db
h,>s5BRB.{
aIB]M|
*v60FP
B_di?*
?`g*nHV
)BZ?1_
x<toPe
K^j5/'
1f%'\A
:S#m93
:[YxJ,
,Oht x
vp^N}eZF
SeiVdf
o"oI#j
fRBO$K
/rU;c/
#$k36U`
RBdjdW
$7}3kr
u:0J='E
dzy,WE
Xwl<qH
._9bkq
#'/^tf
!7 oK4
wS'uZT
Gn}JMK
sHO<10
?/|5m3I&
vbO-;i
[.K&uy
I'`KYK
r\T%rS
_}zbo4
d+~#xQ
IFnVw'
W]k/)Ku
r?{0+#
el7%^xI
C`G_<O
Y3I%2L9
H _n)]
@cVl1>.s
R2!1Ur+J
q4\x'43#[
4lmkRp6
o@LA+g
1zAz=K
@cs?Jk4
xVYjW"
+klQ3[
7Eta|o
SO^0wV
huXTt5+a
W%z@R"
#Qz46w.
EY<,OF<@
KcS"5S
@.Q7 f
xIA#P$
B|0ux|
<JUOLL0
nP^*H]
%D>Q=s
!q.i?m
I{n.hQ
:E^Wgi
"~/jyduX
r(lVcI
{h7sS,
4bWfg3;
B\+Uf3kWV|}
'_W$c2
[B,~F*$
M]0M}<
5nWWEqr9
1h;2sI
y9|Esn
a.{ZtF
\Cr<@BZQ
DO-g'+(!
Sf5i`Ay&
mzs4p|D
7,(Q-(
22&K0dJX
w/1#3Q
T>0ou[
|@d:~
fC>,z<
|b[Nl/YJ
6AUOG|{r
^g,1}]
$$`nzv'-y
>[E4TW9
_2Mo.8
4dK5P|
Q<-3VU
e&.-F@2
s'B0]3T
cVcq,=
I4p6gc
?9E&SLJ
l(Q`]^]N
W(V&bJ
5=Xv_lb
%]<}2T}j
;;is<AR
id%_(C
K7-1cj
~t@nf_
gE$Q$\*#
S"XhFV
@tngND<8
j1p^4
}$9]i#
_V-+4o
:h3>b1
]u5@H3(
3MWAJg^9|~
\Z@Jlac
bN{f/~
!mEy&GL\L
s'T@O!
1gsI$[
@$4}!(i
*<Ys@i
+Iy|!$,$@i
B*@t;;
K/:3?N
?eT3&;
>@'%WE
xF-!-6
-/Bjt@
S+f)0
odDgD[\
4Gt%50c
OzRrrN
]x\-T6{
%@L9$}
szV.#P
}{Y$;|C{
`-kd%*
SLS4 [4?
*vFZ&4z
QIvB9!
f}Z(5"
65UrC2
3h-\T
DS?E'g&
"=<^8j
S]</~l
Xsw|2m
n45Lv\%
LA+#P&
tI8:WZl
:VjW/g
/mMarXK
hovp)Kc6=F
GdKM}6
.Z{#.)V+
+v8[>z`
h*?am!
t-A&LL
S)hc&Z
*Gc>{$`
qa8W1uBA
#f%")kyC^Q9y
$K9]Fe
tV=dnZ
3BW}@s
G&b[n&
wgvn1R
'0mHi\""Y
9--O(BYG
!+%4u*
dL*sbO=&<
JoZ=l:a,
V;o<;;
kTkKh0
z:2A:>`
~/;<!{
j^anX8
_oYFo1i
k-H.%ri
7Vq^^F
oQyCC'
KjcSH$U
{OF~Fd
`{i;FQ
+]^ps<
m_Y:cQ
-_q't1
l1T8/n
>lw3>cE
:={XpU
U\s`&
duj,Jr
<5$c*'7
tc:sIz
UT)s\`Z
N%SIr{
Xtu),
0,iD<~ U
(}kN8b
6.9VID
DB]VV]j
`1=5-]:
fY6ai[
pwH;R~9_
~p()pw
+Cx{ Y
m:T-EF:A\<
V}clTu0Az
p<8sE2
<Q]Xr=
~TCa<\
ti-\nc
d+~Ko&
&T":oD
>sI6W6
KEG |%
/<dKigQ
F(LqdO
LT\j9X
z`U.Lt
5I={50N
A%bb/d
`L93.]7?
NiHk{
OPuB2.`
4@$#m
bH* B0Y
gz*KS>I1
JoHfcuw
8?)`b'
O`#hc{_m
"yV_8=
0Gd$B(A
g1M<MB
w5P"[2-g
]:FLzA
K^xR\J
-9S]4Q
)uv~4#
|CvRPl
r5o}g,
W'v;l
QV9hd0H
!/8,#@
oh70[S
@rh>.8
qi-lt?
)Q lnW`
zBB|Hd
C fw7r
#:5IS|
)oFe%`$v
AIC!Cq
?ibI02"
278L+@
a_M"@s=
Pi.PT}
t,-v[3{lwL
j,UD@8
5V@*96
UuKvjVm
Q!q4#BK
Zy=[+Q?"
BT9IN
4xRL,t
g0li#t
)VB@z9
l9xk
"'G}s[
Um0h27R`
[Mqg^@kX
#JSZKB
GCD3 ^
6'A%9-/
aMoyGIEf~
)k;2uQ4O
?rp!Pg_
:!U|B)
V1[B+\
J/:MJP
,pxh+l
O;%K:l
_GNvJC
&'RvK~
^Vy&C&
P{^|m
3O27:p
AE+sGJ@$
6%jM:`
48d{S>m
L[*TCR
hC=$Aj
}:5h~y
m<}r;R
B}n6Mf
mGt{1%
\heCH0
_tXD-X
uw0Hg.)
%OHi{'E
S6L_A(
'oi-T?
[q'1ze
W4S"(T
VLf@?rl(V
w)wyZ{B
R?Bv%*
wMedV?
;"8?S!
|6MNCoS
U)K`3D
olmK01
;r n->
Q`~Nc|
K{My`z:
rgA{lr
%(E1px
|#:%gp
ZVtB \
kMpFzf
3lG*a(
s>Sd!r
b(8.)U
ft?Zcc
<0ef]S
Gb'.>g
+"&TY0
,9L2<@
#'M}9&)D{
9ZK|+s)
n{/[t"
:n&aSf~C
{QsElI
3"w>a',o
9-T7z{
]rc|_@
XaD^5g
/l009.
?]`y@"`
taf\.*^0
|9e^\;
BS ye3
[Eo|iy
+*2BPr
Fg9\)c
b#?K\C
Wr5cv
tbu|=qDLka
%9NSG7<Id<(
oa.kf
f"`&#V
dxE%AV
*9'GkPr
E:f~d=
NE|dYT
p'b]iU
zz(j9L
&D0EgA_
H^=C@&tf
*nq;Gq
+po<F3
0u'o#h
?i<gas
o7XSJ
v#<$@
NKya.Q]
mlcIca8_
m4Or!=1,
Q$DjB&
lNLwg$
p5,(J>
&x^SE+*,
_(8YIA6-
DH8~Q.
wW'?Nc
`H}X?~-
6&;vs;q(wo
^z[:"^
hq=+CZ
y^1L'>e}T
t XJ($
c,c<-l[@|_
e}hJ+Q7
oSy+-i
1H19|/~
`\bs: @
eOBDSD
GTWY.;
U&4Y=G
@w2JL)
*40[)`
#hF^eF
u3(eX9e
C|dRE!!
M2^U1K
H3*X/v
6JK7Bj
1]("!H
HC<,1~
Oca~do
Z`ly$h
MYNf%Hk
9SQ7xk
{Q[L-w*
E6[+[|
,59fdU
]7mqZR
Pun!E)|
rMWUGg7&2^
A:>_ [O
LOH|UM
DJOs~Y
LLN,+6
9cG$L<8
hB6`tzp
!*0~T2}
J(6~\C
.K6J%XG
u3C'=V#
ACj;1!
G)\,5W/
,mZD2J
QfAT,V(
.~rL*X
QFaZ-;
u$G6t3
oDIyN5
dz>MhM
XV}_/V
G*F:wv
ohXqtk
YG#A"S
L;w].m=
^X\T~!
yA`[#lez
(NoP tla
aT51*l
kv*;>d
&9# >M
^7QStul
Z"KW6r
h-;_4a
?8d`@2
+ioj~Z8@k
ZHRPXW
(6fNQ>
t0:wB
6TUI<,[
\N/2~c
se ^^#
}{%`_R[pbw
z8#u$k+
xgHf}F
vb$d5I
HWva{9
`XZF~~s
Yf",gYL
#O *uVM
SyAies
2TNi1Z
%U.qyHG
7$-p(^`2
HOkTFRm
ofc/D.
OF3CjI
,/$jGL
L~l.V(4
<Vb<{_
|mO(pzG6~
T%Z$"l,Z
JX@hu>`
PX"BA6O
}7]&#d$\
^+y"&R
$g=XWZ
W@Lp<f
y]%ZM`
4w#!1G
*6s1XWU7
Ozt;8wb
O}R9`b
/He%x%g
+R^.i
+`>6Fw
ZaD6<k
+N{*d1
=3h55[
O1:]]uL
b_lAF
J}L~B?2
eLrsY~
vLpr|e
#oj./N
,6CUr\
CDGu?@
*'efri
?;;b/&
"HY?WJ
kwb/Kx
Z|hf"8N
7OLmSHD
Z|x'qqn
v(}W4X
oO_)>X
^BUo~u
9dO@,<%FP
-(^L#h
jO-AWK
u|}Zk'
,?fCWX
<JBzVym
2A??#=
v8IiptTB
S|F{Xb
ryF(~3
!W6N{Q'
;Pi"eK
~LcPxG
&D3*&"
~|! v/
E3[Op1
EfqaFh
2gd]?%
8c5c=[
|_a9tTP
Z{ti;9
kqa4\2
)\pZ9$lL
'.&nwf
wv_&_N\
M$*r]GY
+@9T`U
;6>&sf
d{!{b:
I].'pS
PHkx.h
Fb>]X'
UPu%p|
~$qT-)Al
=|M1cI
j>b8pU
pe4 ~,M
>?Y-T[30M5
?doLi]`V
:yl#UFypS
*uVq##M2
#lb=jw{
=?H`!0 v
pR2t4
bY6\O,
$CGnE`
===S%Zp
-'lKLd
2psDF#
X8qQql
Een;XLZ
Xg\eB{u8
5:3rcI
w6[-we
:8R,|n
J<{nw(@
HdW{4<
_IfKvLd
ec:KC7
|F_"8u1+5
X59eUM
PUjm#
!k+u?ym
lq<_Il
BM.W='
o0"U'E
.:3FNbm
Uv=>HJ
To"|7R
0d$s"\kaeE
'.Y$b]q
U%=.C*?2
>n)YCg
:m;?^&
;O`znn(
W3s,8~
_WbB _
MExdG4gN
Y90^Lu
_b[}{GL
*OF/z(
v2huC\;
?)~>'T
4qe~#p
=3CS>wHx
Azgn%c
%veXH?Q
4({xZ>
`")Z/(Wy
(2!YrH
<775is
nxBe9w
X:[L -;
WWWWWW
L$ QWW
WWWWWW
l$hd3L{
l$tvb}
_^][u.j
_VVVVV
^WWWWW
0SSSSS
_VVVVV
<+t(<-t$:
+t HHt
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
(null)
`h````
xpxxxx
UTF-16LE
UNICODE
CorExitProcess
runtime error
TLOSS error
SING error
DOMAIN error
An application has made an attempt to load the C runtime library incorrectly.
Please contact the application's support team for more information.
- Attempt to use MSIL code from this assembly during native code initialization
This indicates a bug in your application. It is most likely the result of calling an MSIL-compiled (/clr) function from a native constructor or from DllMain.
- not enough space for locale information
- Attempt to initialize the CRT more than once.
This indicates a bug in your application.
- CRT not initialized
- unable to initialize heap
- not enough space for lowio initialization
- not enough space for stdio initialization
- pure virtual function call
- not enough space for _onexit/atexit table
- unable to open console device
- unexpected heap error
- unexpected multithread lock error
- not enough space for thread data
This application has requested the Runtime to terminate it in an unusual way.
Please contact the application's support team for more information.
- not enough space for environment
- not enough space for arguments
- floating point support not loaded
Microsoft Visual C++ Runtime Library
<program name unknown>
Runtime Error!
Program:
EncodePointer
DecodePointer
FlsFree
FlsSetValue
FlsGetValue
FlsAlloc
LC_TIME
LC_NUMERIC
LC_MONETARY
LC_CTYPE
LC_COLLATE
LC_ALL
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
`h`hhh
xppwpp
SystemFunction036
ADVAPI32.DLL
GetProcessWindowStation
GetUserObjectInformationA
GetLastActivePopup
GetActiveWindow
MessageBoxA
USER32.DLL
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
HH:mm:ss
dddd, MMMM dd, yyyy
MM/dd/yy
December
November
October
September
August
February
January
Saturday
Friday
Thursday
Wednesday
Tuesday
Monday
Sunday
united-states
united-kingdom
trinidad & tobago
south-korea
south-africa
south korea
south africa
slovak
puerto-rico
pr-china
pr china
new-zealand
hong-kong
holland
great britain
england
britain
america
swedish-finland
spanish-venezuela
spanish-uruguay
spanish-puerto rico
spanish-peru
spanish-paraguay
spanish-panama
spanish-nicaragua
spanish-modern
spanish-mexican
spanish-honduras
spanish-guatemala
spanish-el salvador
spanish-ecuador
spanish-dominican republic
spanish-costa rica
spanish-colombia
spanish-chile
spanish-bolivia
spanish-argentina
portuguese-brazilian
norwegian-nynorsk
norwegian-bokmal
norwegian
italian-swiss
irish-english
german-swiss
german-luxembourg
german-lichtenstein
german-austrian
french-swiss
french-luxembourg
french-canadian
french-belgian
english-usa
english-us
english-uk
english-trinidad y tobago
english-south africa
english-nz
english-jamaica
english-ire
english-caribbean
english-can
english-belize
english-aus
english-american
dutch-belgian
chinese-traditional
chinese-singapore
chinese-simplified
chinese-hongkong
chinese
canadian
belgian
australian
american-english
american english
american
Norwegian-Nynorsk
CONIN$
CONOUT$
SunMonTueWedThuFriSat
JanFebMarAprMayJunJulAugSepOctNovDec
bad allocation
%s %f %c
0 %s %d %f
GAIsProcessorFeaturePresent
KERNEL32
1#QNAN
1#SNAN
RemoveVectoredExceptionHandler
EnumDateFormatsExW
WriteConsoleOutputCharacterA
LoadResource
SystemTimeToTzSpecificLocalTime
HeapAlloc
SetWaitableTimer
HeapFree
GetModuleHandleExW
GlobalLock
LockFile
ConnectNamedPipe
GetConsoleAliasesA
FindResourceExA
GlobalAlloc
GetLocaleInfoW
GetSystemTimeAdjustment
InterlockedPopEntrySList
GetFileAttributesA
GetExitCodeProcess
GetCompressedFileSizeA
GetTimeZoneInformation
GetEnvironmentVariableA
VirtualUnlock
LCMapStringA
GetAtomNameA
OpenWaitableTimerW
AddAtomA
GetTapeParameters
GlobalFindAtomW
SetConsoleCursorInfo
GlobalUnWire
VirtualProtect
GetFileTime
GetCurrentProcessId
EnumCalendarInfoExA
LocalFree
LocalFileTimeToFileTime
KERNEL32.dll
GetProcessDefaultLayout
USER32.dll
EqualSid
ADVAPI32.dll
GetStartupInfoW
TerminateProcess
GetCurrentProcess
UnhandledExceptionFilter
SetUnhandledExceptionFilter
IsDebuggerPresent
EnterCriticalSection
LeaveCriticalSection
RtlUnwind
GetModuleHandleW
GetProcAddress
ExitProcess
WriteFile
GetStdHandle
GetModuleFileNameA
GetModuleFileNameW
FreeEnvironmentStringsW
GetEnvironmentStringsW
GetCommandLineW
SetHandleCount
GetFileType
GetStartupInfoA
DeleteCriticalSection
TlsGetValue
TlsAlloc
TlsSetValue
TlsFree
InterlockedIncrement
SetLastError
GetCurrentThreadId
GetLastError
InterlockedDecrement
GetCurrentThread
HeapCreate
HeapDestroy
VirtualFree
QueryPerformanceCounter
GetTickCount
GetSystemTimeAsFileTime
SetFilePointer
WideCharToMultiByte
GetConsoleCP
GetConsoleMode
GetCPInfo
GetACP
GetOEMCP
IsValidCodePage
FatalAppExitA
VirtualAlloc
HeapReAlloc
MultiByteToWideChar
CloseHandle
CreateFileA
InitializeCriticalSectionAndSpinCount
SetConsoleCtrlHandler
FreeLibrary
InterlockedExchange
LoadLibraryA
SetStdHandle
WriteConsoleA
GetConsoleOutputCP
WriteConsoleW
LCMapStringW
GetStringTypeA
GetStringTypeW
GetTimeFormatA
GetDateFormatA
GetUserDefaultLCID
GetLocaleInfoA
EnumSystemLocalesA
IsValidLocale
FlushFileBuffers
ReadFile
SetEndOfFile
GetProcessHeap
HeapSize
CompareStringA
CompareStringW
SetEnvironmentVariableA
GetModuleHandleA
saherikeb.exe
Gorgeous
Robinson
SeeYou
0 0&0,02080>0D0J0P0V0\0b0h0n0t0z0
8d9j9p9v9|9
:*:/:5:;:Q:X:b;i;
>q>C?l?
1]1c1}1
2(2=2G2m2
66E6'=
+929g9z9S<Z<
=@>]>z>
2H2P2o2
6,666=6H6Q6g6r6
7<7A7L7Q7o7 8-8n8
9E9J9r9
:":C:l:
:+;1;J;P;
=&=1=D=
>2?9?N?
2?2L2Q2r2w2
31373B3N3c3j3~3
4"40464B4H4U4_4f4~4
4?5E5o5u5
5I6l6v6
7$7*7:7@7U7c7k7q7z7
88$838I8T8Y8d8i8t8y8
9"90989D9K9T9g9q9}9
:5:=:H:
=5=%>N>
7N7[7e7s7|7
;.;G;c;l;r;{;
3&4?4P4
4q5r6#7
=>)>5>>>
??:?_?k?
0B0K0W0
9T:l:Y;
4B4l4j8
8J;N;R;V;Z;^;b;f;v;
7"7&7*7.72767A7H7R7|7
9959Q9c9
:&:?:E:J:Y:`:f:n:t:
=&=1=C=V=a=g=m=r={=
>$>>>O>U>f>
33%313L3
0$0(0,0004080<0@0
91:K:T:v:
;O<T<Y<^<g<
=+>^>h>n>{>
&0+02070>0C0
2"2/2e2
4!4&4>4D4S4Y4h4n4|4
7#8^8n8
:-;5;s;
='=<=C=I=_=z=
?#?-?5?@?p?
3)303`3
: ;>;P;b;
1X3 424<4F4q4y4
5#777M7^7{7
:":&:*:.:2:6:::>:B:F:J:N:R:V:Z:^:b:f:j:n:r:v:z:~:
;<5<;<e<k<
3 3$3M3s3
4-54585<5@5D5H5L5P5
3K4X4x4
:%:.:f:
;#;-;4;O;W;d;k;%<D<
0T1]1c1h1
2%2*272?2N2U2b2
5A6I6U6b6i6q6y6
<p>v>|>
?$?*?0?6?<?B?H?N?T?Z?`?f?l?r?x?~?
0 0&0,02080>0D0J0
!>&>1>:>?>R>s>}>
;*<?<I<q<x<
=(===U=_=f=v=}=
>">(>.>8>?>F>
??)?>?D?b?m?v?
A0V0g0
_8e8p8v8
9"9'9-91979;9A9E9K9O9]9c9}9(<
5=5C5L5S5
899/:7:
8*8u;y;};
;z<U=m=|=
6"848F8q8
4$4,444<4D4L4T4\4d4l4t4|4
; ;$;(;,;0;8;<;@;D;H;L;P;T;X;\;`;d;
= =$=(=,=0=4=8=<=@=D=H=L=P=T=X=\=`=p=x=|=
2 2$282<2
: :$:(:,:0:4:
: :(:0:8:@:H:P:X:`:h:p:x:
; ;(;0;8;@;H;P;X;`;h;p;x;
< <(<0<8<@<H<P<X<`<h<p<x<
?8?X?t?x?
0 0@0L0h0t0
101<1X1d1
2$2@2\2`2
3 3@3`3
4(4H4h4
5(5H5h5
6(6H6h6
K(null)
mscoree.dll
KERNEL32.DLL
((((( H
h(((( H
H
VS_VERSION_INFO
StringFileInfo
040904E4
FileVersions
7.0.2.54
ProductVersions
7.0.21.21
InternalNames
galimatimod
LegalCopyrights
Wsekda
VarFileInfo
Translation
%Wegiyocey puxoyoyoripuho rivapiyiwure5Japiko gudewuharad nelititogoxig guvohelovizefiv sofa+Yedefukexadadaj nop jifosod hojesi nuriguri
Pojere xehovobi
bZusoruleku kozami fibonuxajo lizecofixoma mobikahim vekeyiwazuripo suhixu ruxanita hiyus widukodovRLegenihocan cemiwek zin wacotolojakoga ricame zejeve tixe lajicugoseka wunetujipiy(Focacebuzi xipiyeravifaje jaxivulawuvuri
JocutuwehumaMCujaguhejo pometovo kosaxefole hehuragaf puyorixiyuxulux yuhol zatebawolovisi
Nobe runeru2Vuterahapedinij wiw lopisexecufev suroguv rubileme
Wid7Mucabecobe vubinexoj betiwabino madokiwa cecavaxoxohajegKopaseh mewuput payili gudiyey zugutuc yajipekewakak teniyaji bomiriwedocehit fipasaheratanas yohuvipib
Varuxepisunepi jevucepavu
gVabive topofubivu rayo suxoneyehoyenam digonupoyuja bopahatuxafopac jozujizuzag buniwatiyu zexexesoveba
Pureyape|Yucenoxukag tekogu jinajumorob mibowazifudabec jicegewasexuz tulironiguvicit lamohavow bubihocixozewi fafiyudumek vujofufojelMexipunagedip fadekopenu xinoxuhuwaraz pubazigurime degeyiyowutih povokoj yiligijode gipilamig doresojucezuf
UVukubumip zuviwureb gemevo wulejuwi bejipar sinezega gimor zotovuyax joru mudixafotab%Mefewun taxusam dof nul gad yagom dob
Ripubefahabu cajatagituruxi?Diyahos talaloputu vohuzoraraw jificiyawuhom zilexujun yakedaju>Vura pewoja dole dolurerom wijiwiradifofa joreweri yucujobecugPPom ricowovekebep herav tilutagay wupudan kigelili rasekavutan boraga zakave xay
Huhamos=Zumisitaza rifum pafiyihesokox xujic ravadu mani xawajemeyuweVateb liyucaxuba racef xatigiwe
!Nehoyoguho gotofazavuzin gemu yig'Payepelatuyelim cufino poroj gexe xegaw
Antivirus Signature
Bkav W32.AIDetect.malware1
Elastic malicious (high confidence)
ClamAV Clean
CMC Clean
CAT-QuickHeal Clean
Qihoo-360 HEUR/QVM10.1.7A9B.Malware.Gen
McAfee Packed-GBF!7D828DF10C7F
Cylance Unsafe
Zillya Clean
AegisLab Trojan.Win32.Mokes.m!c
Sangfor Trojan.Win32.Save.a
K7AntiVirus Clean
BitDefender Clean
K7GW Clean
Cybereason Clean
Baidu Clean
Cyren Clean
ESET-NOD32 a variant of Win32/GenKryptik.FDVZ
APEX Malicious
Paloalto generic.ml
Cynet Malicious (score: 100)
Kaspersky UDS:Trojan-Ransom.Win32.Stop.gen
Alibaba Clean
NANO-Antivirus Clean
SUPERAntiSpyware Clean
MicroWorld-eScan Clean
Rising Trojan.Kryptik!1.D4B0 (CLOUD)
Ad-Aware Clean
Emsisoft Clean
Comodo Clean
F-Secure Clean
DrWeb Clean
VIPRE Clean
TrendMicro Clean
McAfee-GW-Edition BehavesLike.Win32.Generic.bc
FireEye Generic.mg.7d828df10c7f01c5
Sophos ML/PE-A
SentinelOne Static AI - Malicious PE
Jiangmin Clean
Webroot W32.Malware.Gen
Avira Clean
Antiy-AVL Clean
Kingsoft Clean
Microsoft Trojan:Win32/Ranumbot.RF!MTB
Gridinsoft Clean
Arcabit Clean
ViRobot Clean
ZoneAlarm Clean
GData Clean
TACHYON Clean
AhnLab-V3 Clean
Acronis suspicious
VBA32 BScope.Trojan.Wacatac
ALYac Clean
MAX Clean
Malwarebytes Trojan.MalPack.GS
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Tencent Win32.Trojan.Raas.Auto
Yandex Clean
Ikarus Trojan.Crypt
eGambit Clean
Fortinet W32/Kryptik.HKIW!tr
BitDefenderTheta Gen:NN.ZexaF.34670.VCW@am!0Lwic
AVG Win32:DropperX-gen [Drp]
Avast Win32:DropperX-gen [Drp]
CrowdStrike win/malicious_confidence_90% (W)
MaxSecure Trojan.Malware.300983.susgen
No IRMA results available.