Static | ZeroBOX

PE Compile Time

2020-02-18 03:18:40

PE Imphash

0b6968a3728849da0a75cdaf93956fc2

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x00044e7f 0x00045000 7.53690076375
.data 0x00046000 0x005d51b8 0x00001a00 2.90970478401
.xuzo 0x0061c000 0x00000001 0x00000200 0.0
.ziw 0x0061d000 0x00001179 0x00000400 0.0
.new 0x0061f000 0x000044f6 0x00004600 5.33033791855
.rsrc 0x00624000 0x00001688 0x00001800 5.72640572942
.reloc 0x00626000 0x000054f0 0x00005600 2.69518826126

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x006241f0 0x000010a8 LANG_UZBEK SUBLANG_UZBEK_CYRILLIC data
RT_STRING 0x00625580 0x00000106 LANG_UZBEK SUBLANG_UZBEK_CYRILLIC data
RT_STRING 0x00625580 0x00000106 LANG_UZBEK SUBLANG_UZBEK_CYRILLIC data
RT_ACCELERATOR 0x006252b0 0x00000018 LANG_UZBEK SUBLANG_UZBEK_CYRILLIC data
RT_GROUP_ICON 0x00625298 0x00000014 LANG_UZBEK SUBLANG_UZBEK_CYRILLIC data
RT_VERSION 0x006252d8 0x000001c0 LANG_NEUTRAL SUBLANG_NEUTRAL data
None 0x006252c8 0x0000000a LANG_UZBEK SUBLANG_UZBEK_CYRILLIC data

Imports

Library KERNEL32.dll:
0xa1f004 FindResourceA
0xa1f008 GetModuleHandleExA
0xa1f014 SetWaitableTimer
0xa1f018 GetCurrentProcess
0xa1f01c CancelWaitableTimer
0xa1f020 ConnectNamedPipe
0xa1f024 GetConsoleAliasesA
0xa1f02c FindResourceExA
0xa1f030 GlobalFindAtomA
0xa1f034 GetLocaleInfoW
0xa1f038 SizeofResource
0xa1f040 GetFileAttributesA
0xa1f044 GetExitCodeProcess
0xa1f04c TerminateProcess
0xa1f050 GetAtomNameW
0xa1f05c GlobalUnlock
0xa1f060 SetLastError
0xa1f064 OpenWaitableTimerA
0xa1f068 LocalAlloc
0xa1f070 SetConsoleOutputCP
0xa1f074 AddAtomA
0xa1f078 GetTapeParameters
0xa1f07c GlobalWire
0xa1f080 lstrcatW
0xa1f084 VirtualProtect
0xa1f088 GetFileTime
0xa1f08c LocalFree
0xa1f090 SetFileAttributesW
0xa1f098 CompareStringW
0xa1f09c GetStartupInfoW
0xa1f0a0 RaiseException
0xa1f0a4 RtlUnwind
0xa1f0b0 IsDebuggerPresent
0xa1f0b4 HeapAlloc
0xa1f0b8 GetLastError
0xa1f0bc HeapFree
0xa1f0c0 GetModuleHandleW
0xa1f0c4 Sleep
0xa1f0c8 GetProcAddress
0xa1f0cc ExitProcess
0xa1f0d0 WriteFile
0xa1f0d4 GetStdHandle
0xa1f0d8 GetModuleFileNameA
0xa1f0dc GetModuleFileNameW
0xa1f0e8 GetCommandLineW
0xa1f0ec SetHandleCount
0xa1f0f0 GetFileType
0xa1f0f4 GetStartupInfoA
0xa1f0fc TlsGetValue
0xa1f100 TlsAlloc
0xa1f104 TlsSetValue
0xa1f108 TlsFree
0xa1f110 GetCurrentThreadId
0xa1f118 GetCurrentThread
0xa1f11c HeapCreate
0xa1f120 HeapDestroy
0xa1f124 VirtualFree
0xa1f12c GetTickCount
0xa1f130 GetCurrentProcessId
0xa1f138 SetFilePointer
0xa1f13c WideCharToMultiByte
0xa1f140 GetConsoleCP
0xa1f144 GetConsoleMode
0xa1f150 GetCPInfo
0xa1f154 GetACP
0xa1f158 GetOEMCP
0xa1f15c IsValidCodePage
0xa1f160 FatalAppExitA
0xa1f164 VirtualAlloc
0xa1f168 HeapReAlloc
0xa1f16c HeapSize
0xa1f170 FreeLibrary
0xa1f174 InterlockedExchange
0xa1f178 LoadLibraryA
0xa1f180 SetStdHandle
0xa1f184 WriteConsoleA
0xa1f188 GetConsoleOutputCP
0xa1f18c WriteConsoleW
0xa1f190 MultiByteToWideChar
0xa1f194 LCMapStringA
0xa1f198 LCMapStringW
0xa1f19c GetStringTypeA
0xa1f1a0 GetStringTypeW
0xa1f1a4 GetTimeFormatA
0xa1f1a8 GetDateFormatA
0xa1f1ac GetUserDefaultLCID
0xa1f1b0 GetLocaleInfoA
0xa1f1b4 EnumSystemLocalesA
0xa1f1b8 IsValidLocale
0xa1f1bc CreateFileA
0xa1f1c0 CloseHandle
0xa1f1c4 FlushFileBuffers
0xa1f1cc CompareStringA
0xa1f1d0 GetModuleHandleA
Library USER32.dll:
0xa1f1d8 GetMonitorInfoA

Exports

Ordinal Address Name
1 0x43ef70 Coruso
2 0x43ef80 Gorgeous
!This program cannot be run in DOS mode.
`.data
@.rsrc
@.reloc
0WWWWW
0WWWWW
QQSVWd
HHtXHHt
>If90t
0SSSSS
>=Yt1j
QQSVWh
j@j ^V
Y;=xlD
HtHu4j
s[S;7|G;w
tR99u2
r=PfD
0A@@Ju
Fh=pfD
^SSSSS
j"^SSSSS
tM<it-<ot)<ut%<xt!<Xt
<dty<itu<otq<utm<xti<Xte
HIf98t
HHtYHHt
HHt*HHt
<0|<9
tK<_t<<$t8<<t4<>t0<-t,<a|
<z~$<A|
<0|O<9
tU<A|B<P
tY<@tO<Zt
t\<@tXj'
NtFNt#NuV
t.<@t5V
TtUHtKHtAHt
0t-HHt
AtIHt0Hu
URPQQh
_VVVVV
_VVVVV
0SSSSS
0SSSSS
0WWWWW
AAFFf;
;t$,v-
UQPXY]Y[
t"SS9]
C PjPV
C$PjQV
C*PjTV
C+PjUV
C,PjVV
C-PjWV
C.PjRV
C/PjSV
.;1s(N
HHt4HHt
Ht\Ht,
teHtFHt&Hu
ty<%tA
PPPPPPPP
PPPPPPPP
u,VVWV
t VV9u
t+WWVPV
^SSSSS
^SSSSS
>:u8FV
VVVVVQRSSj
^SSSSS
^SSSSS
0SSSSS
^SSSSS
^WWWWW
0SSSSS
8VVVVV
@o;ZZn
:e;P?H
^- LCO
+}}#k
qD0YBe
KI0#-'
oyK6a3
%fX*Jd{eV
`Jex@u
SDXz%x]
[fi1P+
i=D??L/
.d`DQ7
mD04z2
/G7n.MB
7<DkG+?
dR`QCP
m\;7U
9+%S7VIY
#if2[p
V*cTz*5
S<i?M`
myuIHk
Q.}z5:
*-%w13Q
k%wbW^J
2t^QZ/
7hE^6t
lT#GLu
$Y8I@-b
T]2ETR
nYU'b%
x;cG;.
}7)2y?o
q17J%0\
~s2P'?
SSz'H1jm
kE>KCx
NQSHFj
Y8JdJ[
xx`"j/
U;pU^B
c#{]C+5
7hRSDh5
pM>U]sKE
~o!urk
Y8v$m&
pOUY3bAS
,.}6$`N
?[2P=K
|_UgV
|"9g;&
#e|7TI0/
-+0Qk2,
SfKHnH|
5bNlcp
JIDOIb
og|mL-h
.?qNt)
q;=C%"
kJG1K2v
$GvByW
g-d}cp
Byye<Q
=$a:)(x
l|U83
Bc8oMqT
H3E_!<
SjQ!w
"*3*aI
{)O?6M
.rd|g&?
mUNy}o
zII]K}F$
'jRVxr0
0A@ISb
u~:\oO
PS*_.&
E;gMtu
&R~1M
}io?a{f
K',]/|
&[z?BF
W.0BjR
{uV}E8
Et(0Ac
8D%5,+
fh[l >
iKW'kT
ET%^\:^G
}I.t*g3X
Y_\oi7
XZXyX"x
9i_Mi]
ODq}6*
:@yuz3~
gU,nSo
IB*+;
95twv^
vtylgkd
@o8"C4
lmS.l4
Up\u9vr
.2=k>*
nq|]}M
U&"JK?
U<K's;
=K(.{`
P'.7hP
X,.]ma
ITEh$w
qN*k2l
-/R;}E
d<\[(t
-H]4BD
DS684Bu
h+7!Mx
2>bY /
t&l}kM
V*m>|L
gV=Tf)
_OAE?#!
R\8;-
'nfa?-
xm^lJ(P
s^c-z7F{
=b{4e{
|GVxs2
`g\? ft
9t4DAA.v
C3Kwm'
`A"*CP
2DMci@
=r?)=6
e}*h/#
f;31PU
(~zTeDu
z8E2"
0]~k~_f
r*L.R0
FME$YWg
4[Fk`Ft
(<~4p
+~yF)6
0$tBU6C:
-SSi!
>m%dE.
N?>Q&E
+fI*61Js=9
GuaOw!
{m5&rz
]+1kwG)
:4^RF?
7{<7;h\m
TY}yo
=(^E9@P
PqaaIoV
"n+JO}
CvCh5U
>`.FVjW3
AL*;U
+&BTQd
jL]UFS
\PEJmp
rB5WkH
Ko:J/(9w
>;=vO.U
~xmQIC
-.i87U1y5
l(KC=<
58L=\a
R59_G0
=lGQ@x
rCIe3^
|3I+=:
m&LaV!'
UUhe@Y@h
?2 c5!
OUHWYT
mfDTp7
8OAk%!
WK>~O8
d{chC/g
)*<8o}
>[&PW?
#XQjKD
=}Q\mz0m
{Fo(Hk
HlHr "
<tlABa
Oq(e+X
50&A~kp
:sk:b1C
YjxqI{6
dFi%mC
kP9Ue$
>1bA.5N
e_],zT
m:AwEu;l
9%TiL:
RKV-w~[DI
VwlX2P
FJ^3HsP(
UE9xN}u
(zZhzR4
H/lDL$^
:"X\ '
659#ub
,8j'(G}
5@.j[r
PW-qyE6}z}1
q:_DQ1
+?~/"
D:T{h"
`Ykrj+
zb5>29
_HbBz8v
emCC!>p
%?A@Tik
FRQf
l$dd3L{
l$pvb}
_VVVVV
^WWWWW
0SSSSS
_VVVVV
<+t(<-t$:
+t HHt
.?AVlogic_error@std@@
.?AVinvalid_argument@std@@
.?AVlength_error@std@@
.?AVout_of_range@std@@
.?AVbad_cast@std@@
.?AVbad_typeid@std@@
.?AV__non_rtti_object@std@@
.?AVtype_info@@
.?AVbad_exception@std@@
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
.?AVexception@std@@
.?AVbad_alloc@std@@
string too long
invalid string position
invalid string argument
Unknown exception
(null)
`h````
xpxxxx
CorExitProcess
runtime error
TLOSS error
SING error
DOMAIN error
An application has made an attempt to load the C runtime library incorrectly.
Please contact the application's support team for more information.
- Attempt to use MSIL code from this assembly during native code initialization
This indicates a bug in your application. It is most likely the result of calling an MSIL-compiled (/clr) function from a native constructor or from DllMain.
- not enough space for locale information
- Attempt to initialize the CRT more than once.
This indicates a bug in your application.
- CRT not initialized
- unable to initialize heap
- not enough space for lowio initialization
- not enough space for stdio initialization
- pure virtual function call
- not enough space for _onexit/atexit table
- unable to open console device
- unexpected heap error
- unexpected multithread lock error
- not enough space for thread data
This application has requested the Runtime to terminate it in an unusual way.
Please contact the application's support team for more information.
- not enough space for environment
- not enough space for arguments
- floating point support not loaded
Microsoft Visual C++ Runtime Library
<program name unknown>
Runtime Error!
Program:
EncodePointer
DecodePointer
FlsFree
FlsSetValue
FlsGetValue
FlsAlloc
bad exception
LC_TIME
LC_NUMERIC
LC_MONETARY
LC_CTYPE
LC_COLLATE
LC_ALL
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
`h`hhh
xppwpp
Complete Object Locator'
Class Hierarchy Descriptor'
Base Class Array'
Base Class Descriptor at (
Type Descriptor'
`local static thread guard'
`managed vector copy constructor iterator'
`vector vbase copy constructor iterator'
`vector copy constructor iterator'
`dynamic atexit destructor for '
`dynamic initializer for '
`eh vector vbase copy constructor iterator'
`eh vector copy constructor iterator'
`managed vector destructor iterator'
`managed vector constructor iterator'
`placement delete[] closure'
`placement delete closure'
`omni callsig'
delete[]
new[]
`local vftable constructor closure'
`local vftable'
`udt returning'
`copy constructor closure'
`eh vector vbase constructor iterator'
`eh vector destructor iterator'
`eh vector constructor iterator'
`virtual displacement map'
`vector vbase constructor iterator'
`vector destructor iterator'
`vector constructor iterator'
`scalar deleting destructor'
`default constructor closure'
`vector deleting destructor'
`vbase destructor'
`string'
`local static guard'
`typeof'
`vcall'
`vbtable'
`vftable'
operator
delete
__unaligned
__restrict
__ptr64
__clrcall
__fastcall
__thiscall
__stdcall
__pascal
__cdecl
__based(
{flat}
`non-type-template-parameter
unsigned
short
<ellipsis>
,<ellipsis>
throw(
`template-parameter
cli::pin_ptr<
cli::array<
`anonymous namespace'
generic-type-
template-parameter-
`unknown ecsu'
union
struct
class
coclass
cointerface
extern "C"
[thunk]:
public:
protected:
private:
virtual
static
`template static data member destructor helper'
`template static data member constructor helper'
`local static destructor helper'
`adjustor{
`vtordisp{
`vtordispex{
const
volatile
volatile
volatile
signed
double
UNKNOWN
__int128
wchar_t
__int64
__int16
__int32
__int8
__w64
SystemFunction036
ADVAPI32.DLL
GetProcessWindowStation
GetUserObjectInformationA
GetLastActivePopup
GetActiveWindow
MessageBoxA
USER32.DLL
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
HH:mm:ss
dddd, MMMM dd, yyyy
MM/dd/yy
December
November
October
September
August
February
January
Saturday
Friday
Thursday
Wednesday
Tuesday
Monday
Sunday
united-states
united-kingdom
trinidad & tobago
south-korea
south-africa
south korea
south africa
slovak
puerto-rico
pr-china
pr china
new-zealand
hong-kong
holland
great britain
england
britain
america
swedish-finland
spanish-venezuela
spanish-uruguay
spanish-puerto rico
spanish-peru
spanish-paraguay
spanish-panama
spanish-nicaragua
spanish-modern
spanish-mexican
spanish-honduras
spanish-guatemala
spanish-el salvador
spanish-ecuador
spanish-dominican republic
spanish-costa rica
spanish-colombia
spanish-chile
spanish-bolivia
spanish-argentina
portuguese-brazilian
norwegian-nynorsk
norwegian-bokmal
norwegian
italian-swiss
irish-english
german-swiss
german-luxembourg
german-lichtenstein
german-austrian
french-swiss
french-luxembourg
french-canadian
french-belgian
english-usa
english-us
english-uk
english-trinidad y tobago
english-south africa
english-nz
english-jamaica
english-ire
english-caribbean
english-can
english-belize
english-aus
english-american
dutch-belgian
chinese-traditional
chinese-singapore
chinese-simplified
chinese-hongkong
chinese
canadian
belgian
australian
american-english
american english
american
Norwegian-Nynorsk
CONIN$
CONOUT$
SunMonTueWedThuFriSat
JanFebMarAprMayJunJulAugSepOctNovDec
bad allocation
GAIsProcessorFeaturePresent
KERNEL32
1#QNAN
1#SNAN
RemoveVectoredExceptionHandler
FindResourceA
GetModuleHandleExA
WriteConsoleOutputCharacterA
SystemTimeToTzSpecificLocalTime
SetWaitableTimer
GetCurrentProcess
CancelWaitableTimer
ConnectNamedPipe
GetConsoleAliasesA
GetCompressedFileSizeW
FindResourceExA
GlobalFindAtomA
GetLocaleInfoW
SizeofResource
GetSystemTimeAdjustment
GetFileAttributesA
GetExitCodeProcess
SetTimeZoneInformation
TerminateProcess
GetAtomNameW
FileTimeToSystemTime
GetEnvironmentVariableA
GlobalUnlock
SetLastError
OpenWaitableTimerA
LocalAlloc
SetConsoleCtrlHandler
SetConsoleOutputCP
AddAtomA
GetTapeParameters
GlobalWire
lstrcatW
VirtualProtect
GetFileTime
LocalFree
SetFileAttributesW
KERNEL32.dll
GetMonitorInfoA
USER32.dll
GetStartupInfoW
RaiseException
RtlUnwind
UnhandledExceptionFilter
SetUnhandledExceptionFilter
IsDebuggerPresent
HeapAlloc
GetLastError
HeapFree
GetModuleHandleW
GetProcAddress
ExitProcess
WriteFile
GetStdHandle
GetModuleFileNameA
GetModuleFileNameW
FreeEnvironmentStringsW
GetEnvironmentStringsW
GetCommandLineW
SetHandleCount
GetFileType
GetStartupInfoA
DeleteCriticalSection
TlsGetValue
TlsAlloc
TlsSetValue
TlsFree
InterlockedIncrement
GetCurrentThreadId
InterlockedDecrement
GetCurrentThread
HeapCreate
HeapDestroy
VirtualFree
QueryPerformanceCounter
GetTickCount
GetCurrentProcessId
GetSystemTimeAsFileTime
SetFilePointer
WideCharToMultiByte
GetConsoleCP
GetConsoleMode
EnterCriticalSection
LeaveCriticalSection
GetCPInfo
GetACP
GetOEMCP
IsValidCodePage
FatalAppExitA
VirtualAlloc
HeapReAlloc
HeapSize
FreeLibrary
InterlockedExchange
LoadLibraryA
InitializeCriticalSectionAndSpinCount
SetStdHandle
WriteConsoleA
GetConsoleOutputCP
WriteConsoleW
MultiByteToWideChar
LCMapStringA
LCMapStringW
GetStringTypeA
GetStringTypeW
GetTimeFormatA
GetDateFormatA
GetUserDefaultLCID
GetLocaleInfoA
EnumSystemLocalesA
IsValidLocale
CreateFileA
CloseHandle
FlushFileBuffers
GetTimeZoneInformation
CompareStringA
CompareStringW
SetEnvironmentVariableA
GetModuleHandleA
robiy.exe
Coruso
Gorgeous
1F2^2l2
6%727_7z7
8"8(8.848:8@8F8L8R8X8K9b:
;,<9<L<{<
>.>?>I>f>
0-0:0b2v2
4(454P4m4
7B7H7P7]7q7
88%878?8J8
?r?x?~?
0#0(080=0C0I0_0f0
1-1S1q1x1|1
1V2a2|2
3 3$3(3,303z3
5*555R5
7E8M8b8m8R9
6167I7
9;:[:q:w:
:!;2;{;
4 4$4M4s4
5-64686<6@6D6H6L6P6
:8;Q;z;
='=.=P=
>'>/>B>M>R>b>l>s>~>
>;?H?r?w?
2!242U2~2
2=3C3\3b3*454t4
5'585C5V5
6D7K7`7
:/:Q:^:c:
;C;I;T;`;u;|;
<(<4<B<H<T<Z<g<q<x<
?$?*?6?<?L?R?g?u?}?
0 0&0+01060E0[0f0k0v0{0
0/141B1J1V1]1f1y1
1b2<3D3\3t3
4!4)414=4a4i4
63]3j3h5\6
;4<T<D=m=
4 4'464B4O4s4
5#5G5v5
7"8/898G8P8Z8
849i9|9
<7<@<F<O<T<c<
4$4w4}4
070@0L0
132A2P2W2b2
8%8O8]8c8
9):7:n:v:
=,=2=L=Q=`=i=v=
>1>8>>>L>S>X>a>n>t>
3!3-3;3A3G3L3U3o3u3
7#7V7|7
050E0Q1r1v1z1~1
2#2.292D2R2]2p2~2
545<5A5H5N5T5Y5_5e5n5t5~5
111=1h1w1
3#4J4O4V4]4d4q4z4
4!5C5I5U5\5
6*6\6e6
:Z:e:t:
;(;<;M;Z;
080=0Y0{0
3U3j3z3
3,494m4z4
6.6;6[6f6
6$7+747>7E7Q7W7f7
8?8I8d8j8
9)9N9g9q9
;7;L;n;u;
0"1:1Z1
152U2b2
758G8o8
9=:Q:W:
<P<a<x<
>R>l>r>
3F3c3{3
4S5i5|5
6 6*686b6p6
9>9E9J9T9^9h9r9
:::D:N:
;!;(;/;6;T;a;
;$<6<J<
>(>8>H>
1f2k2p2u2~2
2 3O3o3
5#5+5C5
5=6B6I6N6U6Z6
71898F8|8
;;);7;w;
= =&=S=Z=
)0C0L0{0
4M5i5w5
:/;A;N;Z;d;l;w;
?"?:?A?K?S?`?g?
9$9-9P9
:$:^:`<
W0i0s0}0
3H3X3j3~3
8?<?@?D?H?L?P?T?X?\?`?d?h?l?p?t?x?|?
6 6$6(6,60646L7
7"8(8y8
<'===H=
5h5n5s5
;";(;.;i;
< <:<Y<q<
="=,=\=
!0'0-090?0g0o0y0
1!1*131?1K1X1_1j1r1z1
2c2p2~2
8<9F9^9
W1f1$2A2J2V2`2l2w2
8Q8]8l8x8
<"<(<.<4<:<@<F<L<R<X<^<d<j<p<v<|<
=$=*=0=6=<=B=H=N=T=Z=`=f=l=r=x=~=
2!2*2/2B2c2m2v2
2R?_?i?
0#040?0Q0g0v0
1 1)161;1@1W1h1n1t1~1
272?2E2O2Y2s2~2
3F3P3Z3j3p3
3W4p4u4}4
==$=*=.=4=8=>=B=H=L=Q=W=[=a=e=k=o=u=y=
0o6G789A9m9s9|9
<i=_>g>
0=1C1S1
8s9C<Z<
)0s2{5
82:R<d<v<
=1=J=]={=
>(>C>b>m>q>v>
0$0H0h0
3$3,343<3D3L3T3\3d3l3
<(<8<\<h<l<p<t<x<
> >$>(>,>0>4>8><>@>D>H>L>P>T>X>\>`>d>h>l>p>t>x>|>
2(2,2024282<2@2D2H2L2P2T2X2\2`2
3d:h:l:p:
2 2$2(2,2024282<2@2D2H2L2P2T2X2\2`2d2h2l2p2t2x2|2
3 3$3(3,3034383<3@3D3H3L3P3T3X3\3`3d3h3l3
6 6(60686@6H6P6X6`6h6p6x6
7 7(70787@7H7P7X7`7h7p7x7
8 8(80888@8H8
9l:p:x:|:
;(;8;<;L;P;T;X;`;x;
<(<8<<<L<P<T<\<t<
= =0=4=8=@=X=h=l=|=
=$>4>`>h>
?$?,?4?<?@?D?L?`?h?p?x?|?
000P0p0
1,101P1\1x1
2$2(2D2H2X2|2
3 3$3,3@3\3`3|3
4 4@4`4l4
5(5H5h5
6(6H6T6p6
787X7x7
888X8x8
9,9@9T9`9h9
jjjjjj
D(null)
mscoree.dll
KERNEL32.DLL
((((( H
h(((( H
H
zuwejawupujavacakowororiwupese
vufasapeyodekuhikep
VS_VERSION_INFO
StringFileInfo
040904E4
FileVersions
7.0.2.54
ProductVersions
7.0.21.21
InternalNames
galimatimod
LegalCopyrights
Wsekde
VarFileInfo
Translation
MNusijodaduz zigahefu telapilewuseh kutu kebodutelabofog lacegeyeril wude life
Begoveyayekafif sicile
6Vobe mowefato cowozeramo xakaki wuki vogudilow noludac/Namuvuta niwonuwiyubo wuziyigokuy retolayiretal
Xihowivugeheje
Antivirus Signature
Bkav W32.AIDetect.malware1
Elastic malicious (high confidence)
MicroWorld-eScan Clean
FireEye Generic.mg.10a6ee4d2adc0ebf
CAT-QuickHeal Clean
ALYac Clean
Malwarebytes Clean
VIPRE Clean
AegisLab Clean
Sangfor Trojan.Win32.Save.a
K7AntiVirus Trojan ( 0056f9be1 )
BitDefender Clean
K7GW Trojan ( 0056f9be1 )
CrowdStrike win/malicious_confidence_100% (W)
BitDefenderTheta Gen:NN.ZexaF.34670.uCX@aa1Nr3fG
Cyren Clean
Symantec ML.Attribute.HighConfidence
ESET-NOD32 a variant of Win32/Kryptik.HKJX
Baidu Clean
APEX Malicious
Avast Clean
ClamAV Clean
Kaspersky UDS:Trojan.Multi.GenericML.xnet
Alibaba Clean
NANO-Antivirus Clean
ViRobot Clean
Rising Trojan.Generic@ML.80 (RDML:o083kWm92yXdRVsLEQlJKg)
Ad-Aware Clean
Emsisoft Trojan.Agent (A)
Comodo Clean
F-Secure Clean
DrWeb Clean
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition BehavesLike.Win32.Trojan.fc
CMC Clean
Sophos ML/PE-A
SentinelOne Static AI - Malicious PE
GData Clean
Jiangmin Clean
Webroot Clean
Avira Clean
MAX Clean
Antiy-AVL Clean
Kingsoft Clean
Gridinsoft Clean
Arcabit Clean
SUPERAntiSpyware Clean
ZoneAlarm Clean
Microsoft Trojan:Win32/Caynamer.A!ml
Cynet Malicious (score: 100)
AhnLab-V3 Clean
Acronis suspicious
McAfee Artemis!10A6EE4D2ADC
TACHYON Clean
VBA32 Clean
Cylance Unsafe
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Tencent Clean
Yandex Clean
Ikarus Clean
MaxSecure Clean
Fortinet W32/GenKryptik.FDZD!tr
Cybereason malicious.077e6b
Paloalto Clean
Qihoo-360 HEUR/QVM10.1.8D09.Malware.Gen
No IRMA results available.