Static | ZeroBOX

PE Compile Time

2020-06-11 20:29:15

PE Imphash

9c90aa63bb435d1aab6db36d5bf4ee01

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x0004ac63 0x0004ae00 7.49490680745
.data 0x0004c000 0x0395d288 0x00001c00 2.87668906286
.fipuh 0x039aa000 0x00000001 0x00000200 0.0
.wuta 0x039ab000 0x00001179 0x00000400 0.0
.new 0x039ad000 0x00004907 0x00004a00 5.46102494387
.rsrc 0x039b2000 0x00002ca0 0x00002e00 4.99275807652
.reloc 0x039b5000 0x00009918 0x00009a00 1.75028734675

Resources

Name Offset Size Language Sub-language File type
RT_CURSOR 0x039b3498 0x00000134 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_ICON 0x039b23a0 0x000010a8 LANG_ENGLISH SUBLANG_SPANISH_EL_SALVADOR data
RT_STRING 0x039b4b30 0x0000016e LANG_ENGLISH SUBLANG_SPANISH_EL_SALVADOR data
RT_STRING 0x039b4b30 0x0000016e LANG_ENGLISH SUBLANG_SPANISH_EL_SALVADOR data
RT_STRING 0x039b4b30 0x0000016e LANG_ENGLISH SUBLANG_SPANISH_EL_SALVADOR data
RT_STRING 0x039b4b30 0x0000016e LANG_ENGLISH SUBLANG_SPANISH_EL_SALVADOR data
RT_STRING 0x039b4b30 0x0000016e LANG_ENGLISH SUBLANG_SPANISH_EL_SALVADOR data
RT_STRING 0x039b4b30 0x0000016e LANG_ENGLISH SUBLANG_SPANISH_EL_SALVADOR data
RT_STRING 0x039b4b30 0x0000016e LANG_ENGLISH SUBLANG_SPANISH_EL_SALVADOR data
RT_ACCELERATOR 0x039b3460 0x00000018 LANG_ENGLISH SUBLANG_SPANISH_EL_SALVADOR data
RT_GROUP_CURSOR 0x039b35d0 0x00000014 LANG_NEUTRAL SUBLANG_NEUTRAL Lotus unknown worksheet or configuration, revision 0x1
RT_GROUP_ICON 0x039b3448 0x00000014 LANG_ENGLISH SUBLANG_SPANISH_EL_SALVADOR data
RT_VERSION 0x039b35e8 0x000001d0 LANG_NEUTRAL SUBLANG_NEUTRAL data
None 0x039b3488 0x0000000a LANG_ENGLISH SUBLANG_SPANISH_EL_SALVADOR data
None 0x039b3488 0x0000000a LANG_ENGLISH SUBLANG_SPANISH_EL_SALVADOR data

Imports

Library KERNEL32.dll:
0x3dad000 HeapReAlloc
0x3dad008 EnumDateFormatsExW
0x3dad00c FindResourceExW
0x3dad014 LoadResource
0x3dad018 SetWaitableTimer
0x3dad01c GetCurrentProcess
0x3dad020 HeapFree
0x3dad024 GetModuleHandleExW
0x3dad028 GlobalLock
0x3dad02c CancelWaitableTimer
0x3dad030 LockFile
0x3dad034 SetTapeParameters
0x3dad038 GetModuleHandleW
0x3dad03c EnumCalendarInfoExW
0x3dad044 GetLocaleInfoW
0x3dad050 GetFileAttributesA
0x3dad060 DisconnectNamedPipe
0x3dad064 VirtualUnlock
0x3dad068 GetConsoleAliasesW
0x3dad06c GetProcAddress
0x3dad070 GetAtomNameA
0x3dad074 LocalAlloc
0x3dad078 AddAtomA
0x3dad07c GlobalFindAtomW
0x3dad080 GlobalUnWire
0x3dad084 lstrcatW
0x3dad088 FatalExit
0x3dad08c GetFileTime
0x3dad090 GetConsoleCursorInfo
0x3dad094 LocalFree
0x3dad098 LCMapStringW
0x3dad0a0 CompareStringW
0x3dad0a4 TerminateProcess
0x3dad0b0 IsDebuggerPresent
0x3dad0b4 GetStartupInfoW
0x3dad0b8 RaiseException
0x3dad0bc RtlUnwind
0x3dad0c0 HeapAlloc
0x3dad0c4 GetLastError
0x3dad0c8 EnterCriticalSection
0x3dad0cc LeaveCriticalSection
0x3dad0d0 TlsGetValue
0x3dad0d4 TlsAlloc
0x3dad0d8 TlsSetValue
0x3dad0dc TlsFree
0x3dad0e0 InterlockedIncrement
0x3dad0e4 SetLastError
0x3dad0e8 GetCurrentThreadId
0x3dad0ec InterlockedDecrement
0x3dad0f0 GetCurrentThread
0x3dad0f4 Sleep
0x3dad0f8 ExitProcess
0x3dad0fc WriteFile
0x3dad100 GetStdHandle
0x3dad104 GetModuleFileNameA
0x3dad108 GetModuleFileNameW
0x3dad114 GetCommandLineW
0x3dad118 SetHandleCount
0x3dad11c GetFileType
0x3dad120 GetStartupInfoA
0x3dad124 DeleteCriticalSection
0x3dad128 HeapCreate
0x3dad12c HeapDestroy
0x3dad130 VirtualFree
0x3dad138 GetTickCount
0x3dad13c GetCurrentProcessId
0x3dad144 SetFilePointer
0x3dad148 WideCharToMultiByte
0x3dad14c GetConsoleCP
0x3dad150 GetConsoleMode
0x3dad154 GetCPInfo
0x3dad158 GetACP
0x3dad15c GetOEMCP
0x3dad160 IsValidCodePage
0x3dad164 FatalAppExitA
0x3dad168 VirtualAlloc
0x3dad16c MultiByteToWideChar
0x3dad170 CloseHandle
0x3dad174 CreateFileA
0x3dad17c HeapSize
0x3dad180 SetConsoleCtrlHandler
0x3dad184 FreeLibrary
0x3dad188 InterlockedExchange
0x3dad18c LoadLibraryA
0x3dad190 SetStdHandle
0x3dad194 WriteConsoleA
0x3dad198 GetConsoleOutputCP
0x3dad19c WriteConsoleW
0x3dad1a0 LCMapStringA
0x3dad1a4 GetStringTypeA
0x3dad1a8 GetStringTypeW
0x3dad1ac GetTimeFormatA
0x3dad1b0 GetDateFormatA
0x3dad1b4 GetUserDefaultLCID
0x3dad1b8 GetLocaleInfoA
0x3dad1bc EnumSystemLocalesA
0x3dad1c0 IsValidLocale
0x3dad1c4 FlushFileBuffers
0x3dad1c8 ReadFile
0x3dad1cc SetEndOfFile
0x3dad1d0 GetProcessHeap
0x3dad1d4 CompareStringA
0x3dad1d8 GetModuleHandleA
Library USER32.dll:

Exports

Ordinal Address Name
1 0x4449c0 Lolipops
2 0x4449a0 NoMore
3 0x4449b0 Robin
!This program cannot be run in DOS mode.
`.data
.fipuh
@.rsrc
@.reloc
D$$QRP
tgSUVW
0WWWWW
_VVVVV
0WWWWW
QQSVWd
HHtXHHt
>If90t
0SSSSS
^F<-uB
<xtX<XtT
jF<-uH
<xtV<XtR
<at9<rt,<wt
URPQQh
>=Yt1j
QQSVWh
j@j ^V
HtHu4j
s[S;7|G;w
tR99u2
0A@@Ju
^SSSSS
j"^SSSSS
tM<it-<ot)<ut%<xt!<Xt
<dty<itu<otq<utm<xti<Xte
HIf98t
HHtYHHt
tGHt.Ht&
^SSSSS
8VVVVV
;t$,v-
UQPXY]Y[
HHt*HHt
<0|<9
tK<_t<<$t8<<t4<>t0<-t,<a|
<z~$<A|
<0|O<9
tU<A|B<P
tY<@tO<Zt
t\<@tXj'
NtFNt#NuV
t.<@t5V
TtUHtKHtAHt
0t-HHt
AtIHt0Hu
_VVVVV
_VVVVV
0SSSSS
0SSSSS
0WWWWW
AAFFf;
t"SS9]
C PjPV
C$PjQV
C*PjTV
C+PjUV
C,PjVV
C-PjWV
C.PjRV
C/PjSV
.;1s(N
HHt4HHt
Ht\Ht,
teHtFHt&Hu
ty<%tA
PPPPPPPP
PPPPPPPP
0WWWWW
u,VVWV
t VV9u
t+WWVPV
^SSSSS
^SSSSS
>:u8FV
VVVVVQRSSj
^SSSSS
^SSSSS
0SSSSS
^SSSSS
^WWWWW
0SSSSS
8VVVVV
%6jC`6
:5vc4Hm\Z
j>IMuw
z3ZRTw3
;=r0_$W
Yxz$2n
:y~dBL
9O) ?@
T8E<A~]
aL#]#
4Y)\`P
s&gq s
r}+uFrG
Yupb-$2
FW|u/;]
L-G$=
:!5x'g
.n`be+
_0[06&
ePOw}
'8@ +KX
|Rb\Lt~
gmaw&4
Gr@ys
@Ww[_!-
\5T]s|i7p
7tV_fM
XAvTwH`
ppx-$'
?#1TT&~Y
x.K\C#
{=JZL76
.zT7uz
&/7weqj
9H.>)i
>U?BOQ
u2jH$t
kA9_8>
&mZ-FZ
J"oFcJ]
Q/ufk'
S5]}@
%7jJ+6IH}
IteZ2qk
=}7P:tY
znqQ^=
vMW '+
~,)IZZD
3+A"Og
dQ5OM@e
"-yys1
/HRo/
R3BNDYM
a!j1jy
E_2/&:
{';WQh
M";E9J
3dzPFV
2>%(l>G]W
0b2V]0
\A$''Y~
[<3X/g
I&/\+X
%T+I:n
`rMo<*
646G/r
EjO{[X
W^B-$P
}a-aoKpB
OsOP(d
N'?&iCk
v5t_#M
Ex?lH?
b,t;-cG$8
S'&=Z$
)j8$I`
B+iWk8
x)9E4<
S!WQ=NP
-G#Nb?
Q$M!Z{
,NH7N"x5
!6Y{G[L
N'42Q4
B/6/~KD
:~]8aD
-\[z$lcBr
||(&C8
"h~\,S
,DF5_P
G;anl.
IN9m(A
d74_3.)xC?
@_,e1a_
2i:%<3e
Y{:uxl
mJvcJ!
KfT%jm
%wgLlaYK
H(XiaLjgq
BNtUg5g
U%Z"s`
=D;I]Tl-
q(7nyt
J/Kyo%
IPeq&Q
|2su@oD
y^T<m7
7F\IJX}
-2,"rX
XgM,jS<1
z0At;
5d>dUt%<
n/P$JU
7JgZ\m
KIp2!OI
6[aC&&
(Q5dg/,&
wI._eJ
?)B{i)NT
fqM$c*0e
JsH?Ss
Y( gw0
9!]N a
V#0!@<
Z;?rPg`5
@pXC=l
cEYb"F
J/-j)
}JGH|w?
<|vDox
7=nLfC
&Ddrka
%e#wtV
Bof0W5
qPf*,q4
?/!$_.
BV/mQy
k.e_d5
(/nd|d
dAQ5Nr
LRw:CO
`K6=\]
$Sa0$@j
0gXi/OD
}%XN%+
plVl]a
-Dw6wS
A/qY$N
JugwZ@
XSpI-M
Gjnhax
Tqimvg
<k<%O*a`&
}{RM{<
1)ojfb
ybNkTBK?
vJ=c7wQ
sWW%*6
P\r.g{d
/vAMEzt
|OlS97
j@y.\r
nD#!xb
>=wr_8
k!V!l~n
%cR5D3
+l]I{y24
>>[)bx
N,N c!
|S(w`\
:k:*4a
VX]`[7
c%IY$7
th<t^6
?BPomt
Pn%K>/
"v4=8aH2
)}&k6R~
",~-3X
/`>$U!
!8MTgd
sI/8\VN
`<G~@&j
'NH)<7
Z'F%bk
'iaO!N
TNH$P*oK
8}4>D8#:
/ncSz[
*LK8cV
d3Ool"-.j*]x
ksq"E#b'
QXEFU)t$O
!DX`?*
]/E6mt
=qw3T>
O,HCsE
7]t;
(nPv%w
~[EJZK
/Y!,8$#+
~nt}}+.
Zm5n8^
A?2;% s
[m&f_yC
&=[2^H!o7
78vuui
P;.eIPj>
Q,/"')8
N~+SzO
x}#{h#
[EQ-t68
qB{v_UJ
u=7"(>
By{A'8g
|[+O>j
I)z6c,
-|T[r
rBfr=0<2Q
L$HQSS
D$X;D$\v
SSSSSS
D$HPQQQ
l$hd3L{
l$tvb}
_^][u.j
_VVVVV
^WWWWW
0SSSSS
_VVVVV
<+t(<-t$:
+t HHt
.?AVinvalid_argument@std@@
.?AVout_of_range@std@@
.?AVbad_cast@std@@
.?AVbad_typeid@std@@
.?AV__non_rtti_object@std@@
.?AVtype_info@@
.?AVbad_exception@std@@
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
.?AVexception@std@@
.?AVlogic_error@std@@
.?AVlength_error@std@@
.?AVbad_alloc@std@@
string too long
invalid string position
invalid string argument
Unknown exception
(null)
`h````
xpxxxx
EncodePointer
DecodePointer
FlsFree
FlsSetValue
FlsGetValue
FlsAlloc
UTF-16LE
UNICODE
CorExitProcess
runtime error
TLOSS error
SING error
DOMAIN error
An application has made an attempt to load the C runtime library incorrectly.
Please contact the application's support team for more information.
- Attempt to use MSIL code from this assembly during native code initialization
This indicates a bug in your application. It is most likely the result of calling an MSIL-compiled (/clr) function from a native constructor or from DllMain.
- not enough space for locale information
- Attempt to initialize the CRT more than once.
This indicates a bug in your application.
- CRT not initialized
- unable to initialize heap
- not enough space for lowio initialization
- not enough space for stdio initialization
- pure virtual function call
- not enough space for _onexit/atexit table
- unable to open console device
- unexpected heap error
- unexpected multithread lock error
- not enough space for thread data
This application has requested the Runtime to terminate it in an unusual way.
Please contact the application's support team for more information.
- not enough space for environment
- not enough space for arguments
- floating point support not loaded
Microsoft Visual C++ Runtime Library
<program name unknown>
Runtime Error!
Program:
bad exception
LC_TIME
LC_NUMERIC
LC_MONETARY
LC_CTYPE
LC_COLLATE
LC_ALL
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
`h`hhh
xppwpp
Complete Object Locator'
Class Hierarchy Descriptor'
Base Class Array'
Base Class Descriptor at (
Type Descriptor'
`local static thread guard'
`managed vector copy constructor iterator'
`vector vbase copy constructor iterator'
`vector copy constructor iterator'
`dynamic atexit destructor for '
`dynamic initializer for '
`eh vector vbase copy constructor iterator'
`eh vector copy constructor iterator'
`managed vector destructor iterator'
`managed vector constructor iterator'
`placement delete[] closure'
`placement delete closure'
`omni callsig'
delete[]
new[]
`local vftable constructor closure'
`local vftable'
`udt returning'
`copy constructor closure'
`eh vector vbase constructor iterator'
`eh vector destructor iterator'
`eh vector constructor iterator'
`virtual displacement map'
`vector vbase constructor iterator'
`vector destructor iterator'
`vector constructor iterator'
`scalar deleting destructor'
`default constructor closure'
`vector deleting destructor'
`vbase destructor'
`string'
`local static guard'
`typeof'
`vcall'
`vbtable'
`vftable'
operator
delete
__unaligned
__restrict
__ptr64
__clrcall
__fastcall
__thiscall
__stdcall
__pascal
__cdecl
__based(
{flat}
`non-type-template-parameter
unsigned
short
<ellipsis>
,<ellipsis>
throw(
`template-parameter
cli::pin_ptr<
cli::array<
`anonymous namespace'
generic-type-
template-parameter-
`unknown ecsu'
union
struct
class
coclass
cointerface
extern "C"
[thunk]:
public:
protected:
private:
virtual
static
`template static data member destructor helper'
`template static data member constructor helper'
`local static destructor helper'
`adjustor{
`vtordisp{
`vtordispex{
const
volatile
volatile
volatile
signed
double
UNKNOWN
__int128
wchar_t
__int64
__int16
__int32
__int8
__w64
SystemFunction036
ADVAPI32.DLL
GetProcessWindowStation
GetUserObjectInformationA
GetLastActivePopup
GetActiveWindow
MessageBoxA
USER32.DLL
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
HH:mm:ss
dddd, MMMM dd, yyyy
MM/dd/yy
December
November
October
September
August
February
January
Saturday
Friday
Thursday
Wednesday
Tuesday
Monday
Sunday
united-states
united-kingdom
trinidad & tobago
south-korea
south-africa
south korea
south africa
slovak
puerto-rico
pr-china
pr china
new-zealand
hong-kong
holland
great britain
england
britain
america
swedish-finland
spanish-venezuela
spanish-uruguay
spanish-puerto rico
spanish-peru
spanish-paraguay
spanish-panama
spanish-nicaragua
spanish-modern
spanish-mexican
spanish-honduras
spanish-guatemala
spanish-el salvador
spanish-ecuador
spanish-dominican republic
spanish-costa rica
spanish-colombia
spanish-chile
spanish-bolivia
spanish-argentina
portuguese-brazilian
norwegian-nynorsk
norwegian-bokmal
norwegian
italian-swiss
irish-english
german-swiss
german-luxembourg
german-lichtenstein
german-austrian
french-swiss
french-luxembourg
french-canadian
french-belgian
english-usa
english-us
english-uk
english-trinidad y tobago
english-south africa
english-nz
english-jamaica
english-ire
english-caribbean
english-can
english-belize
english-aus
english-american
dutch-belgian
chinese-traditional
chinese-singapore
chinese-simplified
chinese-hongkong
chinese
canadian
belgian
australian
american-english
american english
american
Norwegian-Nynorsk
CONIN$
CONOUT$
SunMonTueWedThuFriSat
JanFebMarAprMayJunJulAugSepOctNovDec
bad allocation
VirtualProtect
%s %f %c
0 %s %d %f
vector<T> too long
GAIsProcessorFeaturePresent
KERNEL32
1#QNAN
1#SNAN
HeapReAlloc
RemoveVectoredExceptionHandler
EnumDateFormatsExW
FindResourceExW
WriteConsoleOutputCharacterA
LoadResource
SetWaitableTimer
GetCurrentProcess
HeapFree
GetModuleHandleExW
GlobalLock
CancelWaitableTimer
LockFile
SetTapeParameters
GetModuleHandleW
EnumCalendarInfoExW
TzSpecificLocalTimeToSystemTime
GetLocaleInfoW
GetSystemTimeAdjustment
InterlockedPopEntrySList
GetFileAttributesA
GetCompressedFileSizeA
GetTimeZoneInformation
GetEnvironmentVariableA
DisconnectNamedPipe
VirtualUnlock
GetConsoleAliasesW
GetProcAddress
GetAtomNameA
LocalAlloc
AddAtomA
GlobalFindAtomW
GlobalUnWire
lstrcatW
FatalExit
GetFileTime
GetConsoleCursorInfo
LocalFree
LCMapStringW
KERNEL32.dll
GetProcessDefaultLayout
USER32.dll
TerminateProcess
UnhandledExceptionFilter
SetUnhandledExceptionFilter
IsDebuggerPresent
GetStartupInfoW
RaiseException
RtlUnwind
HeapAlloc
GetLastError
EnterCriticalSection
LeaveCriticalSection
TlsGetValue
TlsAlloc
TlsSetValue
TlsFree
InterlockedIncrement
SetLastError
GetCurrentThreadId
InterlockedDecrement
GetCurrentThread
ExitProcess
WriteFile
GetStdHandle
GetModuleFileNameA
GetModuleFileNameW
FreeEnvironmentStringsW
GetEnvironmentStringsW
GetCommandLineW
SetHandleCount
GetFileType
GetStartupInfoA
DeleteCriticalSection
HeapCreate
HeapDestroy
VirtualFree
QueryPerformanceCounter
GetTickCount
GetCurrentProcessId
GetSystemTimeAsFileTime
SetFilePointer
WideCharToMultiByte
GetConsoleCP
GetConsoleMode
GetCPInfo
GetACP
GetOEMCP
IsValidCodePage
FatalAppExitA
VirtualAlloc
MultiByteToWideChar
CloseHandle
CreateFileA
InitializeCriticalSectionAndSpinCount
HeapSize
SetConsoleCtrlHandler
FreeLibrary
InterlockedExchange
LoadLibraryA
SetStdHandle
WriteConsoleA
GetConsoleOutputCP
WriteConsoleW
LCMapStringA
GetStringTypeA
GetStringTypeW
GetTimeFormatA
GetDateFormatA
GetUserDefaultLCID
GetLocaleInfoA
EnumSystemLocalesA
IsValidLocale
FlushFileBuffers
ReadFile
SetEndOfFile
GetProcessHeap
CompareStringA
CompareStringW
SetEnvironmentVariableA
GetModuleHandleA
xahahe.exe
Lolipops
NoMore
303C4Q4
0"060o0|0
:5;B;o;
1"1(1.141:1@1F1L1R1X1^1d1j1p1v1|1
2%2E2O2l2}2
3&3N5b5
717N7[7
;=;k<y<
<*=s>*?<?I?y?
0)0=0O0V0\0n0v0
8#8)838<8G8S8X8h8m8s8y8
99'9,90949]9
;=;D;H;L;P;T;X;\;`;
<.<Q<d<4>;>
131~4n5
6'7L7/9+;/;3;7;;;?;C;G;H<e<
11171W1
1I2O2`2v2
2-333?3
4=4O4]4r4|4
5@5I5f5
%0k;r;
070=0H0T0i0p0
1(161<1H1N1[1e1l1
2E2K2u2{2
2O3r3|3
4*404@4F4[4i4q4w4
55%5*595O5Z5_5j5o5z5
;)<5<A=
>->S>q>x>|>
>V?a?|?
0 0$0(0,000z0
515Z5_5v5
8"8-828B8L8S8^8g8}8
9(9R9W9b9g9
96:C:`:
:7;<;d;
=#=<=B=
0$1+1@1{1
233c3u3
414>4C4d4i4
5$5+595\5i5u5}5
718<8F8_8i8|8
:2;>;Q;c;~;
<-<V<g<s<y<
>??V?g?
(040=0F0R0^0j0v0
4 4=4B4
> ?E?Q?h?n?
(010=0z0
2"3 7s7
:';E;k;
4)6-6165696=6A6E6P6W6a6
8,8e8s8
9Z;h;n;
<$<*<5<:<B<H<R<Y<m<t<z<
1*131@1K1]1i1w1}1
4&5,5S5_5
828S8_8
9!:[:X;];o;
:6;V;8>Z>
556O6X6
7)7A7`7
<<,<:<H<V<d<v<
0$0+0G0(1.1?1E1N1U1\1e1m1s1y1
<T=f=l=
?O?S?W?[?_?c?g?k?u?
0%0,050:0Q0d0
5&515k5s5|5
6!6Y6c6l667A7F7f7
88.8N8 9=9L9\9z9
:6:R:}:
:!;/;?;V;
=@>`>w>
1$141G1v1
2$3/3@3Z3`3t3}3
6'6.656
8<9C9n9
2'3/3D3^3o3
4P5Z5r5z5
;!<`<e<
'0,0M0Y0l0y0
0<2k2s2y2
33F3s3
3'4/4p4
546B6P6
7#878p8
:6:;:@:E:N:i:o:
<E<O<U<b<q<
2%2+2:2@2O2U2c2l2{2
5Y6f6{6
6'777R7r7
<(<C<P<
:M:a;l;u;
;3<E<W<i<{<
>%?6?~?
2#3+3h3p3
%0;0j4r4
4A5U5k5|5
::n:w:
2 2$2(2,20242
88<8@8D8H8L8P8T8X8\8`8d8h8l8p8t8x8|8
:#;F;z;
=!=*=3=A=
575f5h6o6
?0?F?Q?o?
041:1?1S1Y1^1d1k1}1
6*6I6a6
:):/:W:_:i:v:~:
;#;/;;;H;O;Z;b;j;s;|;
<S<`<n<{<
8U9r9{9
=)>Z>j>-?3???N?
3"3(3.343:3@3F3L3R3X3^3d3j3p3v3|3
4$4*40464<4B4H4N4T4Z4`4f4l4r4x4~4
<"<2<7<=<B<H<M<T<Z<d<m<
N9Y9r9
:/:9:a:h:~:
;4;M;T;d;n;u;
<[<l<r<x<
<E=J=T=u=X>`>f>l>q>
??(???E?Z?_?e?k?
0-020:0A0u0
9#91979A9U9Z9`9d9j9n9t9x9~9
2w3h5q5
7F8n8x8
U4K5S5
7)8/8?8
)6k9Y<
959a9z9
:5:R:z:
;F<Q<U<Z<
0(0H0L0h0
0P2T2X2`2
5$5,545<5D5L5T5\5d5l5t5|5
<,<8<<<@<D<H<P<T<X<\<`<d<h<l<p<t<x<|<
> >$>(>,>0>4>8><>@>D>H>L>P>T>X>\>`>d>h>l>p>
147P7p7
2024282<2@2D2H2L2P2T2X2\2`2d2h2
; ;$;(;,;0;4;
2 2$2(2,2024282<2@2D2H2L2P2T2X2\2`2d2h2l2p2t2x2|2
3 3$3(3,3034383<3@3D3H3L3P3T3X3\3`3d3h3l3p3t3x3|3
6 6(60686@6H6P6X6`6h6p6x6
7 7(70787@7H7P7X7`7h7p7x7
8 8(80888@8H8P8X8`8h8p8
;(;,;0;4;<;T;d;h;x;|;
<$<(<,<0<8<P<`<d<t<x<
=4=D=H=X=\=`=h=
>l>t>|>
?(?H?h?
080D0`0
1 1@1\1`1
2$2(282\2h2p2
3 3<3@3\3`3|3
4 4@4L4h4t4
505L5P5p5
606P6p6
787X7x7
888X8x8
9 949<9P9X9l9t9x9|9
:,:8:@:X:d:
;$;d;t;
< <8<D<t<
=,=4=<=H=|=
jjjjjj
D(null)
KERNEL32.DLL
mscoree.dll
((((( H
h(((( H
H
kernel32.dll
VS_VERSION_INFO
StringFileInfo
040904E4
FileVersions
7.0.2.54
ProductVersions
7.0.21.45
InternalName
calimatimodunads.exe
LegalCopyrights
Vsekda
VarFileInfo
Translation
%Wegiyocey puxoyoyoripuho rivapiyiwure5Japiko gudewuharad nelititogoxig guvohelovizefiv sofa+Yedefukexadadaj nop jifosod hojesi nuriguri
Pojere xehovobi
bZusoruleku kozami fibonuxajo lizecofixoma mobikahim vekeyiwazuripo suhixu ruxanita hiyus widukodovRLegenihocan cemiwek zin wacotolojakoga ricame zejeve tixe lajicugoseka wunetujipiy(Focacebuzi xipiyeravifaje jaxivulawuvuri
JocutuwehumaMCujaguhejo pometovo kosaxefole hehuragaf puyorixiyuxulux yuhol zatebawolovisi
Nobe runeru2Vuterahapedinij wiw lopisexecufev suroguv rubileme
Wid7Mucabecobe vubinexoj betiwabino madokiwa cecavaxoxohajegKopaseh mewuput payili gudiyey zugutuc yajipekewakak teniyaji bomiriwedocehit fipasaheratanas yohuvipib
Varuxepisunepi jevucepavu
Yuc jigozekuso marituxo
RevumaJDoxo roviniremifab vanosahode lobidaf yoyenexefune yocifake rewedaduduwinegVabive topofubivu rayo suxoneyehoyenam digonupoyuja bopahatuxafopac jozujizuzag buniwatiyu zexexesoveba
Pureyape|Yucenoxukag tekogu jinajumorob mibowazifudabec jicegewasexuz tulironiguvicit lamohavow bubihocixozewi fafiyudumek vujofufojelMexipunagedip fadekopenu xinoxuhuwaraz pubazigurime degeyiyowutih povokoj yiligijode gipilamig doresojucezufUVukubumip zuviwureb gemevo wulejuwi bejipar sinezega gimor zotovuyax joru mudixafotab%Mefewun taxusam dof nul gad yagom dob
Ripubefahabu cajatagituruxi?Diyahos talaloputu vohuzoraraw jificiyawuhom zilexujun yakedaju>Vura pewoja dole dolurerom wijiwiradifofa joreweri yucujobecugPPom ricowovekebep herav tilutagay wupudan kigelili rasekavutan boraga zakave xay
Huhamos=Zumisitaza rifum pafiyihesokox xujic ravadu mani xawajemeyuweVateb liyucaxuba racef xatigiwe
!Nehoyoguho gotofazavuzin gemu yig'Payepelatuyelim cufino poroj gexe xegaw
Faluwom yoxicomihuRBelenipiyo numanami dev kobevizewiwug tabucaliroxow vub salaluxemusekej bojiwinesi
Jamibubifajaj jivacotategupet
Pomo kij bavijelebuvunag betoz;Mox kufe murukil nevil magiduxason yumireton lor bawutireviJFapesegab yakihucuv lume hoyidewixinehez cobomohedagici voyex verof fuduju
Cimiyup
Xumidolupar tixaye yorisudam3Jivejemufos duromorib micaketekale kazemajegef dehi
Kewuyuz pibe meb bezavaze hezi&Jafisil geye beyojoyedav jerako cihufu
Vuligero
Vuk himimuwir cotane ciyexaki
ZaxenujMiti tuzuciliyo wubuyeku rufe mevemofaxoduboz fun tawufogocubi yuzamemaduciyix jowuyayonuh hepegicipajuraw
Subigumawuxaceb reh
MNusijodaduz zigahefu telapilewuseh kutu kebodutelabofog lacegeyeril wude life
Begoveyayekafif sicile
6Vobe mowefato cowozeramo xakaki wuki vogudilow noludac/Namuvuta niwonuwiyubo wuziyigokuy retolayiretalBKedufo jidukacorebopu jevisifunisajam kajapowave cel xakomi hivuni
Antivirus Signature
Bkav W32.AIDetect.malware1
Elastic malicious (high confidence)
MicroWorld-eScan Trojan.GenericKD.36657875
FireEye Generic.mg.29e8627d7b80c21f
CAT-QuickHeal Clean
McAfee RDN/Generic.grp
Cylance Unsafe
VIPRE Trojan.Win32.Generic!BT
Sangfor Trojan.Win32.Save.a
K7AntiVirus Trojan ( 0057a5e41 )
BitDefender Trojan.GenericKD.36657875
K7GW Trojan ( 0057a5e41 )
Cybereason malicious.0a3108
Arcabit Trojan.Generic.D22F5AD3
BitDefenderTheta Gen:NN.ZexaF.34670.xC1@aWfbpggG
Cyren W32/Kryptik.DTT.gen!Eldorado
Symantec ML.Attribute.HighConfidence
ESET-NOD32 a variant of Win32/Kryptik.HKIW
Baidu Clean
APEX Malicious
Avast Win32:DropperX-gen [Drp]
ClamAV Win.Packed.Generickdz-9851112-0
Kaspersky HEUR:Trojan-Spy.Win32.Noon.gen
Alibaba TrojanSpy:Win32/Glupteba.555d2606
NANO-Antivirus Clean
ViRobot Clean
AegisLab Trojan.Win32.Noon.l!c
Tencent Win32.Trojan.Inject.Auto
Ad-Aware Trojan.GenericKD.36657875
Sophos Mal/Generic-S
Comodo Malware@#q38m3zrllukf
F-Secure Clean
DrWeb Trojan.Siggen13.3998
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition BehavesLike.Win32.Trojan.fh
CMC Clean
Emsisoft Trojan.Agent (A)
Jiangmin Backdoor.Mokes.dxo
MaxSecure Clean
Avira Clean
MAX malware (ai score=100)
Antiy-AVL Clean
Kingsoft Win32.Troj.Undef.(kcloud)
Gridinsoft Trojan.Win32.Kryptik.oa
Microsoft Trojan:Win32/Glupteba.VAM!MTB
SUPERAntiSpyware Clean
ZoneAlarm Clean
GData Trojan.GenericKD.36657875
Cynet Malicious (score: 100)
AhnLab-V3 Trojan/Win.MalPE.R415312
Acronis suspicious
VBA32 BScope.Trojan.Wacatac
TACHYON Clean
Malwarebytes Trojan.MalPack.GS
Panda Trj/GdSda.A
Zoner Clean
TrendMicro-HouseCall Clean
Rising Trojan.Kryptik!1.D4B0 (CLOUD)
Yandex Clean
SentinelOne Static AI - Malicious PE
eGambit Clean
Fortinet W32/GenKryptik.FDVZ!tr
Webroot W32.Trojan.Dropper
AVG Win32:DropperX-gen [Drp]
Paloalto generic.ml
CrowdStrike win/malicious_confidence_100% (W)
Qihoo-360 Win32/Trojan.Generic.HwoCcnIA
No IRMA results available.