Static | ZeroBOX

PE Compile Time

2019-10-17 05:17:53

PE Imphash

5c9f82cdabd8e2926163412888fe3f28

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x0003fb83 0x0003fc00 7.45038782827
.data 0x00041000 0x0395cf68 0x00001800 2.190971799
.xutok 0x0399e000 0x00000001 0x00000200 0.0
.nemuk 0x0399f000 0x00000179 0x00000200 0.0
.tls 0x039a0000 0x00000009 0x00000200 0.0203931352361
.new 0x039a1000 0x00004840 0x00004a00 5.38207462669
.rsrc 0x039a6000 0x000023f0 0x00002400 5.050311187
.reloc 0x039a9000 0x000092f4 0x00009400 1.74333132928

Resources

Name Offset Size Language Sub-language File type
RT_CURSOR 0x039a7408 0x00000134 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_ICON 0x039a6310 0x000010a8 LANG_BELARUSIAN SUBLANG_DEFAULT dBase IV DBT of @.DBF, block length 4096, next free block index 40, next free block 4291692042, next used block 4291823369
RT_STRING 0x039a7fb0 0x0000043a LANG_BELARUSIAN SUBLANG_DEFAULT data
RT_STRING 0x039a7fb0 0x0000043a LANG_BELARUSIAN SUBLANG_DEFAULT data
RT_STRING 0x039a7fb0 0x0000043a LANG_BELARUSIAN SUBLANG_DEFAULT data
RT_STRING 0x039a7fb0 0x0000043a LANG_BELARUSIAN SUBLANG_DEFAULT data
RT_ACCELERATOR 0x039a73d0 0x00000018 LANG_BELARUSIAN SUBLANG_DEFAULT data
RT_GROUP_CURSOR 0x039a7540 0x00000014 LANG_NEUTRAL SUBLANG_NEUTRAL Lotus unknown worksheet or configuration, revision 0x1
RT_GROUP_ICON 0x039a73b8 0x00000014 LANG_BELARUSIAN SUBLANG_DEFAULT data
RT_VERSION 0x039a7558 0x000001c0 LANG_NEUTRAL SUBLANG_NEUTRAL data
None 0x039a73f8 0x0000000a LANG_BELARUSIAN SUBLANG_DEFAULT data
None 0x039a73f8 0x0000000a LANG_BELARUSIAN SUBLANG_DEFAULT data

Imports

Library KERNEL32.dll:
0x3da1000 HeapReAlloc
0x3da1008 EnumDateFormatsExW
0x3da100c FindResourceExW
0x3da1014 LoadResource
0x3da1018 SetWaitableTimer
0x3da101c GetCurrentProcess
0x3da1020 HeapFree
0x3da1024 GetModuleHandleExW
0x3da1028 GlobalLock
0x3da102c CancelWaitableTimer
0x3da1030 LockFile
0x3da1034 SetTapeParameters
0x3da1038 GetModuleHandleW
0x3da103c GetConsoleAliasesA
0x3da1044 GetLocaleInfoW
0x3da1050 GetFileAttributesA
0x3da1060 DisconnectNamedPipe
0x3da1064 VirtualUnlock
0x3da1068 GetProcAddress
0x3da106c GetAtomNameA
0x3da1070 LocalAlloc
0x3da1074 AddAtomA
0x3da1078 GlobalFindAtomW
0x3da107c GlobalUnWire
0x3da1080 lstrcatW
0x3da1084 FatalExit
0x3da1088 GetFileTime
0x3da108c GetConsoleCursorInfo
0x3da1090 EnumCalendarInfoExA
0x3da1094 LocalFree
0x3da1098 LCMapStringW
0x3da109c CompareStringW
0x3da10a0 CompareStringA
0x3da10a4 TerminateProcess
0x3da10b0 IsDebuggerPresent
0x3da10b4 GetStartupInfoW
0x3da10b8 RaiseException
0x3da10bc RtlUnwind
0x3da10c0 HeapAlloc
0x3da10c4 GetLastError
0x3da10c8 EnterCriticalSection
0x3da10cc LeaveCriticalSection
0x3da10d0 TlsGetValue
0x3da10d4 TlsAlloc
0x3da10d8 TlsSetValue
0x3da10dc TlsFree
0x3da10e0 InterlockedIncrement
0x3da10e4 SetLastError
0x3da10e8 GetCurrentThreadId
0x3da10ec InterlockedDecrement
0x3da10f0 GetCurrentThread
0x3da10f4 Sleep
0x3da10f8 ExitProcess
0x3da10fc WriteFile
0x3da1100 GetStdHandle
0x3da1104 GetModuleFileNameA
0x3da1108 GetModuleFileNameW
0x3da1114 GetCommandLineW
0x3da1118 SetHandleCount
0x3da111c GetFileType
0x3da1120 GetStartupInfoA
0x3da1124 DeleteCriticalSection
0x3da1128 HeapCreate
0x3da112c HeapDestroy
0x3da1130 VirtualFree
0x3da1138 GetTickCount
0x3da113c GetCurrentProcessId
0x3da1144 SetFilePointer
0x3da1148 WideCharToMultiByte
0x3da114c GetConsoleCP
0x3da1150 GetConsoleMode
0x3da1154 GetCPInfo
0x3da1158 GetACP
0x3da115c GetOEMCP
0x3da1160 IsValidCodePage
0x3da1164 FatalAppExitA
0x3da1168 VirtualAlloc
0x3da116c MultiByteToWideChar
0x3da1170 CloseHandle
0x3da1174 CreateFileA
0x3da117c HeapSize
0x3da1180 SetConsoleCtrlHandler
0x3da1184 FreeLibrary
0x3da1188 InterlockedExchange
0x3da118c LoadLibraryA
0x3da1190 SetStdHandle
0x3da1194 WriteConsoleA
0x3da1198 GetConsoleOutputCP
0x3da119c WriteConsoleW
0x3da11a0 LCMapStringA
0x3da11a4 GetStringTypeA
0x3da11a8 GetStringTypeW
0x3da11ac GetTimeFormatA
0x3da11b0 GetDateFormatA
0x3da11b4 GetUserDefaultLCID
0x3da11b8 GetLocaleInfoA
0x3da11bc EnumSystemLocalesA
0x3da11c0 IsValidLocale
0x3da11c4 FlushFileBuffers
0x3da11c8 ReadFile
0x3da11cc SetEndOfFile
0x3da11d0 GetProcessHeap
Library USER32.dll:

Exports

Ordinal Address Name
1 0x43ea50 Lolipops
2 0x43ea30 NoMoreLies
3 0x43ea40 Robinson
!This program cannot be run in DOS mode.
`.data
.xutok
.nemuk
@.rsrc
@.reloc
D$$QRP
tgSUVW
0WWWWW
_VVVVV
0WWWWW
QQSVWd
HHtXHHt
>If90t
0SSSSS
uL9=$2D
^F<-uB
<xtX<XtT
jF<-uH
<xtV<XtR
<at9<rt,<wt
URPQQh|
>=Yt1j
QQSVWh
j@j ^V
HtHu4j
s[S;7|G;w
tR99u2
0A@@Ju
^SSSSS
j"^SSSSS
tM<it-<ot)<ut%<xt!<Xt
<dty<itu<otq<utm<xti<Xte
HIf98t
HHtYHHt
tGHt.Ht&
^SSSSS
8VVVVV
;t$,v-
UQPXY]Y[
HHt*HHt
<0|<9
tK<_t<<$t8<<t4<>t0<-t,<a|
<z~$<A|
<0|O<9
tU<A|B<P
tY<@tO<Zt
t\<@tXj'
Du h4$
NtFNt#NuV
j@hP2D
t.<@t5V
TtUHtKHtAHt
0t-HHt
dj@hP2D
AtIHt0Hu
_VVVVV
_VVVVV
0SSSSS
0SSSSS
0WWWWW
AAFFf;
t"SS9]
C PjPV
C$PjQV
C*PjTV
C+PjUV
C,PjVV
C-PjWV
C.PjRV
C/PjSV
.;1s(N
HHt4HHt
Ht\Ht,
teHtFHt&Hu
ty<%tA
PPPPPPPP
PPPPPPPP
0WWWWW
u,VVWV
t VV9u
t+WWVPV
^SSSSS
^SSSSS
>:u8FV
Pf9543D
VVVVVQRSSj
^SSSSS
^SSSSS
0SSSSS
^SSSSS
^WWWWW
0SSSSS
8VVVVV
bR%ExiD
=Gw[YZBml)
[r=$y}
LmgmG`
[+qBZ(
oZ7}
z=<0Xkq
a]r74T
G.,]3!X
5ycXPXZ
3Jlv8T6
ISjiZZI<
WJJP/x
W5ZWr=
R+>\pp
|uA*e
k*| ny2
H68#M?
jY<@W~
l3/G9'F
V/=Ug0
QU3U#C]
_IIkjwdA
prrsXQF
B-.LxH
@YkLDd%
yD"Kq#
4.w%_.L
ctBNN.p
+A$I^z
7FE}(G!
t`*UGP53
[,*%RhR
DP6+<r
8%d#h$
e`A0HS!
WFtp6d
M0H\Wd
BKDkqj*9
5[tp9W
ex%u\h
hK7[r5
@<4WQM
}.Xy==
5h`<VJP
S7fK`U
}0I=-@y
u1Hk"
Qb+1OV/k
{`3\IA
O=VWR{
^/jG[4
"9$]wA'
L#D's)
:_eOG-
{^maDS
7~b-oxhA
=>b_-qIw^
iO^G^G
$;X`Ql
MRWpOA
jzBaA)
z%)-.u
B|8&`j
Y^[LQ1
4_VF=j3$
bp1LVs
HnO`d\y
\FHWyz
*nOwUR;=t
^[Lb0m
!/)z\A
GL+r72
1Pp l}g
{C%*1L
R/ 72j
tKjitw1
_E<i8_
!h`L'Y
!6&>3h
0jhJ*1zk
3okB9xH
,Mj]<<#
[bgqL,
C97G)r
I[$-&j
bf&Nf1
4$Gavv
ZC_EGLV
hcOAh`
Le3=&C
.Z*+:p
b^4>@E
7kt!;8~y
7kh4_0&
E<}SL\
NE|\n
e5dmve
vKBx8w
u97%Dx
4}]7F
NF86(`
ip6{%>79
{YMQ*<
@b]#\h
8Y[$@I
{vtK*@
viQQ|T^b
YmFVt>
W7UIOk
AAQFt'
3ymdCM~
_U"[%i
HvuAVr
kC1g2U
.'qq,b;
Z9#0GA
27>,)S
^71fXI
e~xKA`CcJ
/8mePR
F\OI@Q
y(SN[o7
dO7NB,
XI-%Xl
*k_d.Z
wT_7({
D|z"KDxqPr
g#7eigI
B\hGfiqS
|e2hxVF
|&1-E~W
l/<g\lc@
C%>j<
H|Z40r
Cwh+A_
eQ0LSg
bMtOhk
K\auq+;
EKybBe
{TcI?,
B/"[oy
wCDj3^
Hw]E\e
X1ua_Ph[
PDsJP[
2{P)\t*s
iY%L{LYa
i^>Dy5S
c!:eQp
ce?hR!
@^n;]_[
bw+mpa5
n,7]Sy
|Sac0g
8BO>u-
c\Q4@/7
+E&~Kri,N
jafTy[
Ye@g>F/
IE:Xa3
w6u;731
_#1%,gd
1A'*-T!
+-,@U7
GA>Nc
^+izdE
Hk#FDT
~KL|TAR
cmk/~'
~O![y5
Nf84PD
0\N&$.
~F{+H&
D$(;D$,v
SSSSSS
l$hd3L{
l$tvb}
_^][u.j
.?AVinvalid_argument@std@@
.?AVout_of_range@std@@
.?AVbad_cast@std@@
.?AVbad_typeid@std@@
.?AV__non_rtti_object@std@@
.?AVtype_info@@
.?AVbad_exception@std@@
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
.?AVexception@std@@
.?AVlogic_error@std@@
.?AVlength_error@std@@
.?AVbad_alloc@std@@
string too long
invalid string position
invalid string argument
Unknown exception
(null)
`h````
xpxxxx
EncodePointer
DecodePointer
FlsFree
FlsSetValue
FlsGetValue
FlsAlloc
UTF-16LE
UNICODE
CorExitProcess
runtime error
TLOSS error
SING error
DOMAIN error
An application has made an attempt to load the C runtime library incorrectly.
Please contact the application's support team for more information.
- Attempt to use MSIL code from this assembly during native code initialization
This indicates a bug in your application. It is most likely the result of calling an MSIL-compiled (/clr) function from a native constructor or from DllMain.
- not enough space for locale information
- Attempt to initialize the CRT more than once.
This indicates a bug in your application.
- CRT not initialized
- unable to initialize heap
- not enough space for lowio initialization
- not enough space for stdio initialization
- pure virtual function call
- not enough space for _onexit/atexit table
- unable to open console device
- unexpected heap error
- unexpected multithread lock error
- not enough space for thread data
This application has requested the Runtime to terminate it in an unusual way.
Please contact the application's support team for more information.
- not enough space for environment
- not enough space for arguments
- floating point support not loaded
Microsoft Visual C++ Runtime Library
<program name unknown>
Runtime Error!
Program:
bad exception
LC_TIME
LC_NUMERIC
LC_MONETARY
LC_CTYPE
LC_COLLATE
LC_ALL
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
`h`hhh
xppwpp
Complete Object Locator'
Class Hierarchy Descriptor'
Base Class Array'
Base Class Descriptor at (
Type Descriptor'
`local static thread guard'
`managed vector copy constructor iterator'
`vector vbase copy constructor iterator'
`vector copy constructor iterator'
`dynamic atexit destructor for '
`dynamic initializer for '
`eh vector vbase copy constructor iterator'
`eh vector copy constructor iterator'
`managed vector destructor iterator'
`managed vector constructor iterator'
`placement delete[] closure'
`placement delete closure'
`omni callsig'
delete[]
new[]
`local vftable constructor closure'
`local vftable'
`udt returning'
`copy constructor closure'
`eh vector vbase constructor iterator'
`eh vector destructor iterator'
`eh vector constructor iterator'
`virtual displacement map'
`vector vbase constructor iterator'
`vector destructor iterator'
`vector constructor iterator'
`scalar deleting destructor'
`default constructor closure'
`vector deleting destructor'
`vbase destructor'
`string'
`local static guard'
`typeof'
`vcall'
`vbtable'
`vftable'
operator
delete
__unaligned
__restrict
__ptr64
__clrcall
__fastcall
__thiscall
__stdcall
__pascal
__cdecl
__based(
{flat}
`non-type-template-parameter
unsigned
short
<ellipsis>
,<ellipsis>
throw(
`template-parameter
cli::pin_ptr<
cli::array<
`anonymous namespace'
generic-type-
template-parameter-
`unknown ecsu'
union
struct
class
coclass
cointerface
extern "C"
[thunk]:
public:
protected:
private:
virtual
static
`template static data member destructor helper'
`template static data member constructor helper'
`local static destructor helper'
`adjustor{
`vtordisp{
`vtordispex{
const
volatile
volatile
volatile
signed
double
UNKNOWN
__int128
wchar_t
__int64
__int16
__int32
__int8
__w64
SystemFunction036
ADVAPI32.DLL
GetProcessWindowStation
GetUserObjectInformationA
GetLastActivePopup
GetActiveWindow
MessageBoxA
USER32.DLL
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
HH:mm:ss
dddd, MMMM dd, yyyy
MM/dd/yy
December
November
October
September
August
February
January
Saturday
Friday
Thursday
Wednesday
Tuesday
Monday
Sunday
united-states
united-kingdom
trinidad & tobago
south-korea
south-africa
south korea
south africa
slovak
puerto-rico
pr-china
pr china
new-zealand
hong-kong
holland
great britain
england
britain
america
swedish-finland
spanish-venezuela
spanish-uruguay
spanish-puerto rico
spanish-peru
spanish-paraguay
spanish-panama
spanish-nicaragua
spanish-modern
spanish-mexican
spanish-honduras
spanish-guatemala
spanish-el salvador
spanish-ecuador
spanish-dominican republic
spanish-costa rica
spanish-colombia
spanish-chile
spanish-bolivia
spanish-argentina
portuguese-brazilian
norwegian-nynorsk
norwegian-bokmal
norwegian
italian-swiss
irish-english
german-swiss
german-luxembourg
german-lichtenstein
german-austrian
french-swiss
french-luxembourg
french-canadian
french-belgian
english-usa
english-us
english-uk
english-trinidad y tobago
english-south africa
english-nz
english-jamaica
english-ire
english-caribbean
english-can
english-belize
english-aus
english-american
dutch-belgian
chinese-traditional
chinese-singapore
chinese-simplified
chinese-hongkong
chinese
canadian
belgian
australian
american-english
american english
american
Norwegian-Nynorsk
CONIN$
CONOUT$
SunMonTueWedThuFriSat
JanFebMarAprMayJunJulAugSepOctNovDec
bad allocation
VirtualProtect
0 %s %d %f
vector<T> too long
HeapReAlloc
RemoveVectoredExceptionHandler
EnumDateFormatsExW
FindResourceExW
WriteConsoleOutputCharacterA
LoadResource
SetWaitableTimer
GetCurrentProcess
HeapFree
GetModuleHandleExW
GlobalLock
CancelWaitableTimer
LockFile
SetTapeParameters
GetModuleHandleW
GetConsoleAliasesA
TzSpecificLocalTimeToSystemTime
GetLocaleInfoW
GetSystemTimeAdjustment
InterlockedPopEntrySList
GetFileAttributesA
GetCompressedFileSizeA
GetTimeZoneInformation
GetEnvironmentVariableA
DisconnectNamedPipe
VirtualUnlock
GetProcAddress
GetAtomNameA
LocalAlloc
AddAtomA
GlobalFindAtomW
GlobalUnWire
lstrcatW
FatalExit
GetFileTime
GetConsoleCursorInfo
EnumCalendarInfoExA
LocalFree
LCMapStringW
KERNEL32.dll
GetProcessDefaultLayout
USER32.dll
TerminateProcess
UnhandledExceptionFilter
SetUnhandledExceptionFilter
IsDebuggerPresent
GetStartupInfoW
RaiseException
RtlUnwind
HeapAlloc
GetLastError
EnterCriticalSection
LeaveCriticalSection
TlsGetValue
TlsAlloc
TlsSetValue
TlsFree
InterlockedIncrement
SetLastError
GetCurrentThreadId
InterlockedDecrement
GetCurrentThread
ExitProcess
WriteFile
GetStdHandle
GetModuleFileNameA
GetModuleFileNameW
FreeEnvironmentStringsW
GetEnvironmentStringsW
GetCommandLineW
SetHandleCount
GetFileType
GetStartupInfoA
DeleteCriticalSection
HeapCreate
HeapDestroy
VirtualFree
QueryPerformanceCounter
GetTickCount
GetCurrentProcessId
GetSystemTimeAsFileTime
SetFilePointer
WideCharToMultiByte
GetConsoleCP
GetConsoleMode
GetCPInfo
GetACP
GetOEMCP
IsValidCodePage
FatalAppExitA
VirtualAlloc
MultiByteToWideChar
CloseHandle
CreateFileA
InitializeCriticalSectionAndSpinCount
HeapSize
SetConsoleCtrlHandler
FreeLibrary
InterlockedExchange
LoadLibraryA
SetStdHandle
WriteConsoleA
GetConsoleOutputCP
WriteConsoleW
LCMapStringA
GetStringTypeA
GetStringTypeW
GetTimeFormatA
GetDateFormatA
GetUserDefaultLCID
GetLocaleInfoA
EnumSystemLocalesA
IsValidLocale
FlushFileBuffers
ReadFile
SetEndOfFile
GetProcessHeap
CompareStringA
CompareStringW
SetEnvironmentVariableA
poxemofi.exe
Lolipops
NoMoreLies
Robinson
4x519v<
U0b061N1\1
1$1*10161<1B1H1N1T1Z1`1f1l1r1x1~1
252?2\2m2w2
7!7>7K7
9`:j:w:
>.>C>m>t>z>
1g1?2W2\2
52686>6D6J6P6W6^6e6l6s6z6
77&7Z7
81888<8@8D8H8L8P8T8
9!9<9C9H9L9P9q9
9::@:D:H:L:
<N=V=k=v=
: :$:(:,:0:1;N;j;
0 0@0w0
02181I1_1
3&383F3[3e3
3)414N4
6!7?7e7G>
?(?4?I?P?d?k?
0(0.0;0E0L0d0s0z0
0%1+1U1[1w1
1/2R2\2
3 3&3;3I3Q3W3`3g3
4/4:4?4J4O4Z4_4l4z4
8'8T8\8{8
:#;A;H;L;P;T;X;\;`;d;
;&<1<L<S<X<\<`<
=J=P=T=X=\=
=<>Y>^>E?J?d?
s0c1n1
2*2/2F2
2\3b3w3
5#5.575M5X5r5~5
5"6'62676U6
848Y8~8
:$;a;p;
>K>d>k>
>/?7?w?
14191q1v1
202=2I2Q2Y2e2
9\:|:l;
;|=\>%?V?l?
5/595L5p5
8!838N8V8^8u8
8&979C9I9f9+:U:
<&<7<s<
="=.=:=F=Q=Y=
3g4J6z6
9{:;3;c;m;y;
<!<8<><^<g<s<
=J=S=_=x=
6J7b7O8
181b1`5
5@8D8H8L8P8T8X8\8l8
4 4$4(4,474>4H4r4
6A9O9U9o9t9
:!:):/:9:@:T:[:a:o:v:{:
?'?2?D?P?^?d?j?o?x?
3:3F3y3
6:6F6m6z6
8B889=9O9m9
5!5@5t5
:(:6:D:V:d:r:
??%?.?5?<?E?M?S?Y?
6B7X7c7
93:]:h:0;B;H;w;
<+=/=3=7=;=?=C=G=Q=~=
>->@>l>
0J1#2f2t2{2
3G3O3X3`3j3
354?4H4
5"5B5`5
7(787V7
8.8Y8l8s8
929d9r9
P0[0g0m0s0
161<1P1Y1^1v1
1,2;2[2
4_4d4z4
4!5:5b6
77J7`7
>c>F?_?
1 1:1K1b1k1
2,363N3V3
4?4f4u4
9<:A:j:
>)>5>H>U>j>w>}>
0G0O0U0[0a0
0"1O1e1
2L2b2v2
8!8*8E8K8a8g8
9!:+:1:>:M:w:
=(>~>Y?
0+010?0H0W0\0f0t0
0V2]2c2
2C3N3q354B4W4i4
8Q9m9{9
0X1i1q1F7
8P8d9o9x9
:':9:K:]:o:
081@1^1f1
:2B2Q2
3%3;3L3i3
8 9f9o9
6 6$6(6,6064686<6@6D6H6L6P6T6X6\6`6d6h6l6p6t6x6|6
9J9P9\9
5A5C6J6
91:>:^:x:
:f;K<Q<
?!?,?J?q?
1.14191?1F1X1t1
6)6A6h6y6~6
:7:?:I:V:^:d:j:
;(;/;:;B;J;S;\;j;x;
;3<@<N<[<n<{<
2X3`3q3
5o6h8w859R9[9g9q9}9
??.?b?n?}?
3 3&3,32383>3D3J3P3V3\3b3h3n3t3z3
4"4(4.444:4@4F4L4R4X4^4d4j4p4v4|4
=,=1=<=
::':g:~:
;;4;<;A;P;[;m;
<<2<8<K<Q<`<f<r<
?(?-?4?;?D?O?X?u?{?
0a0v0
9:9U9r9
;f;q;u;z;
0(0H0L0h0
0P2T2X2`2
5$5,545<5D5L5T5\5d5l5t5|5
<,<8<<<@<D<H<P<T<X<\<`<d<h<l<p<t<x<|<
> >$>(>,>0>4>8><>@>D>H>L>P>T>X>\>`>d>h>l>p>
147P7p7
2(2,2024282<2@2D2H2L2P2T2X2\2`2
; ;$;(;,;0;4;
2 2$2(2,2024282<2@2D2H2L2P2T2X2\2`2d2h2l2p2t2x2|2
3 3$3(3,3034383<3@3D3H3L3P3T3X3\3`3d3h3l3p3t3x3|3
6 6(60686@6H6P6X6`6h6p6x6
7 7(70787@7H7P7X7`7h7p7x7
8 8(80888@8H8P8X8`8h8p8
:,:0:@:D:H:L:T:l:|:
;,;0;@;D;H;P;h;x;|;
<$<(<,<4<L<\<`<p<t<x<|<
=4=D=H=P=h=
>$>D>H>L>T>h>
?0?P?\?x?
0 0@0`0|0
1$1(1D1H1X1|1
2 2$2,2@2\2`2|2
3 3@3`3l3
4(4H4T4p4
505P5p5
686X6x6
787X7x7
888X8x8
9$9T9d9x9
:D:\:p:|:
;(;8;X;l;x;
< <4<@<H<`<l<
jjjjjj
D(null)
KERNEL32.DLL
mscoree.dll
((((( H
h(((( H
H
kernel32.dll
VS_VERSION_INFO
StringFileInfo
040904E4
FileVersions
7.0.2.54
ProductVersions
7.0.21.45
InternalNames
galimatimod
LegalCopyrights
Wsekda
VarFileInfo
Translation
%Wegiyocey puxoyoyoripuho rivapiyiwure5Japiko gudewuharad nelititogoxig guvohelovizefiv sofa+Yedefukexadadaj nop jifosod hojesi nuriguri
Pojere xehovobi
bZusoruleku kozami fibonuxajo lizecofixoma mobikahim vekeyiwazuripo suhixu ruxanita hiyus widukodovRLegenihocan cemiwek zin wacotolojakoga ricame zejeve tixe lajicugoseka wunetujipiy(Focacebuzi xipiyeravifaje jaxivulawuvuri
JocutuwehumaMCujaguhejo pometovo kosaxefole hehuragaf puyorixiyuxulux yuhol zatebawolovisi
Nobe runeru2Vuterahapedinij wiw lopisexecufev suroguv rubileme
Wid7Mucabecobe vubinexoj betiwabino madokiwa cecavaxoxohajegKopaseh mewuput payili gudiyey zugutuc yajipekewakak teniyaji bomiriwedocehit fipasaheratanas yohuvipib
Varuxepisunepi jevucepavu
gVabive topofubivu rayo suxoneyehoyenam digonupoyuja bopahatuxafopac jozujizuzag buniwatiyu zexexesoveba
Pureyape|Yucenoxukag tekogu jinajumorob mibowazifudabec jicegewasexuz tulironiguvicit lamohavow bubihocixozewi fafiyudumek vujofufojelMexipunagedip fadekopenu xinoxuhuwaraz pubazigurime degeyiyowutih povokoj yiligijode gipilamig doresojucezuf
UVukubumip zuviwureb gemevo wulejuwi bejipar sinezega gimor zotovuyax joru mudixafotab%Mefewun taxusam dof nul gad yagom dob
Ripubefahabu cajatagituruxi?Diyahos talaloputu vohuzoraraw jificiyawuhom zilexujun yakedaju>Vura pewoja dole dolurerom wijiwiradifofa joreweri yucujobecugPPom ricowovekebep herav tilutagay wupudan kigelili rasekavutan boraga zakave xay
Huhamos=Zumisitaza rifum pafiyihesokox xujic ravadu mani xawajemeyuweVateb liyucaxuba racef xatigiwe
!Nehoyoguho gotofazavuzin gemu yig'Payepelatuyelim cufino poroj gexe xegaw
Antivirus Signature
Bkav W32.AIDetect.malware1
DrWeb Trojan.DownLoader38.29904
MicroWorld-eScan Trojan.GenericKDZ.74062
FireEye Generic.mg.000e43fe0944da48
CAT-QuickHeal Clean
McAfee Trojan-FTKE!000E43FE0944
Cylance Unsafe
Zillya Clean
SUPERAntiSpyware Trojan.Agent/Gen-Kryptik
Sangfor Trojan.Win32.Save.a
CrowdStrike win/malicious_confidence_100% (W)
Alibaba Trojan:Win32/Ranumbot.8a29e18c
K7GW Trojan ( 0057a8a71 )
K7AntiVirus Trojan ( 00516fdf1 )
Arcabit Clean
BitDefenderTheta Gen:NN.ZexaF.34670.uGW@ayYF!8ac
Cyren Clean
Symantec Clean
ESET-NOD32 a variant of Win32/Kryptik.HKIW
APEX Malicious
Avast Win32:Malware-gen
ClamAV Clean
Kaspersky HEUR:Trojan.Win32.Bsymem.gen
BitDefender Trojan.GenericKDZ.74062
NANO-Antivirus Clean
Paloalto generic.ml
AegisLab Clean
Tencent Clean
Ad-Aware Trojan.GenericKDZ.74062
TACHYON Clean
Emsisoft Trojan.Agent (A)
Comodo Clean
F-Secure Clean
Baidu Clean
VIPRE Trojan.Win32.Generic!BT
TrendMicro Clean
McAfee-GW-Edition BehavesLike.Win32.Generic.fh
CMC Clean
Sophos Mal/Generic-S
Ikarus Win32.Outbreak
Jiangmin Backdoor.Mokes.dxo
eGambit Clean
Avira TR/Crypt.Agent.qtkbj
Antiy-AVL Clean
Kingsoft Win32.Troj.Undef.(kcloud)
Gridinsoft Trojan.Win32.Kryptik.oa
Microsoft Clean
ViRobot Clean
ZoneAlarm Clean
GData Trojan.GenericKDZ.74062
Cynet Malicious (score: 100)
AhnLab-V3 Trojan/Win.MalPE.R415606
Acronis Clean
ALYac Trojan.GenericKDZ.74062
MAX malware (ai score=100)
VBA32 BScope.Trojan.Wacatac
Malwarebytes Trojan.MalPack.GS
Zoner Clean
TrendMicro-HouseCall Clean
Rising Trojan.Kryptik!1.D4B0 (CLOUD)
Yandex Clean
SentinelOne Static AI - Malicious PE
MaxSecure Clean
Fortinet W32/GenKryptik.FDVZ!tr
Webroot Clean
AVG Win32:Malware-gen
Cybereason Clean
Panda Trj/GdSda.A
Qihoo-360 Win32/Trojan.Bsymem.HwoChz8A
No IRMA results available.