Static | ZeroBOX

PE Compile Time

2020-03-18 06:51:41

PE Imphash

1c198acdc88e6433341d82c12cfad0a9

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x0004938f 0x00049400 7.50402962764
.data 0x0004b000 0x0395e23c 0x00001c00 2.87272623346
.wuxer 0x039aa000 0x00000001 0x00000200 0.0
.cowubag 0x039ab000 0x00001179 0x00000400 0.0
.new 0x039ad000 0x000046b7 0x00004800 5.47627759715
.rsrc 0x039b2000 0x00001730 0x00001800 5.78260365503
.reloc 0x039b4000 0x00009204 0x00009400 1.76648805184

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x039b2220 0x000010a8 None SUBLANG_DEFAULT data
RT_STRING 0x039b35c0 0x0000016e None SUBLANG_DEFAULT data
RT_STRING 0x039b35c0 0x0000016e None SUBLANG_DEFAULT data
RT_ACCELERATOR 0x039b32e0 0x00000018 None SUBLANG_DEFAULT data
RT_GROUP_ICON 0x039b32c8 0x00000014 None SUBLANG_DEFAULT data
RT_VERSION 0x039b3318 0x000001c0 LANG_NEUTRAL SUBLANG_NEUTRAL data
None 0x039b3308 0x0000000a None SUBLANG_DEFAULT data
None 0x039b3308 0x0000000a None SUBLANG_DEFAULT data

Imports

Library KERNEL32.dll:
0x3dad000 ExitProcess
0x3dad008 FindResourceA
0x3dad014 HeapAlloc
0x3dad018 SetWaitableTimer
0x3dad01c HeapFree
0x3dad020 GetModuleHandleExW
0x3dad024 LockFile
0x3dad028 SetTapeParameters
0x3dad030 FindResourceExA
0x3dad034 GlobalAlloc
0x3dad038 GetLocaleInfoW
0x3dad03c SizeofResource
0x3dad044 GetFileAttributesA
0x3dad048 GetExitCodeProcess
0x3dad04c GetAtomNameW
0x3dad058 GlobalUnlock
0x3dad05c DisconnectNamedPipe
0x3dad060 VirtualUnlock
0x3dad064 GetConsoleAliasesW
0x3dad068 SetLastError
0x3dad06c OpenWaitableTimerW
0x3dad070 SetConsoleCtrlHandler
0x3dad074 SetConsoleOutputCP
0x3dad078 AddAtomA
0x3dad07c GlobalFindAtomW
0x3dad080 GlobalUnWire
0x3dad084 lstrcatW
0x3dad088 VirtualProtect
0x3dad08c GetFileTime
0x3dad090 GetCurrentProcessId
0x3dad094 LocalFree
0x3dad098 SetFileAttributesW
0x3dad0a4 CompareStringW
0x3dad0a8 GetStartupInfoW
0x3dad0ac RaiseException
0x3dad0b0 RtlUnwind
0x3dad0b4 TerminateProcess
0x3dad0b8 GetCurrentProcess
0x3dad0c4 IsDebuggerPresent
0x3dad0c8 GetLastError
0x3dad0cc DeleteCriticalSection
0x3dad0d0 LeaveCriticalSection
0x3dad0d4 FatalAppExitA
0x3dad0d8 EnterCriticalSection
0x3dad0dc VirtualFree
0x3dad0e0 VirtualAlloc
0x3dad0e4 HeapReAlloc
0x3dad0e8 HeapCreate
0x3dad0ec HeapDestroy
0x3dad0f0 GetModuleHandleW
0x3dad0f4 Sleep
0x3dad0f8 GetProcAddress
0x3dad0fc WriteFile
0x3dad100 GetStdHandle
0x3dad104 GetModuleFileNameA
0x3dad108 GetModuleFileNameW
0x3dad114 GetCommandLineW
0x3dad118 SetHandleCount
0x3dad11c GetFileType
0x3dad120 GetStartupInfoA
0x3dad124 TlsGetValue
0x3dad128 TlsAlloc
0x3dad12c TlsSetValue
0x3dad130 TlsFree
0x3dad134 InterlockedIncrement
0x3dad138 GetCurrentThreadId
0x3dad13c InterlockedDecrement
0x3dad140 GetCurrentThread
0x3dad148 GetTickCount
0x3dad150 SetFilePointer
0x3dad154 WideCharToMultiByte
0x3dad158 GetConsoleCP
0x3dad15c GetConsoleMode
0x3dad160 GetCPInfo
0x3dad164 GetACP
0x3dad168 GetOEMCP
0x3dad16c IsValidCodePage
0x3dad174 FreeLibrary
0x3dad178 InterlockedExchange
0x3dad17c LoadLibraryA
0x3dad180 MultiByteToWideChar
0x3dad184 CloseHandle
0x3dad188 CreateFileA
0x3dad18c HeapSize
0x3dad190 SetStdHandle
0x3dad194 WriteConsoleA
0x3dad198 GetConsoleOutputCP
0x3dad19c WriteConsoleW
0x3dad1a0 LCMapStringA
0x3dad1a4 LCMapStringW
0x3dad1a8 GetStringTypeA
0x3dad1ac GetStringTypeW
0x3dad1b0 GetTimeFormatA
0x3dad1b4 GetDateFormatA
0x3dad1b8 GetUserDefaultLCID
0x3dad1bc GetLocaleInfoA
0x3dad1c0 EnumSystemLocalesA
0x3dad1c4 IsValidLocale
0x3dad1c8 FlushFileBuffers
0x3dad1cc ReadFile
0x3dad1d0 SetEndOfFile
0x3dad1d4 GetProcessHeap
0x3dad1d8 CompareStringA
0x3dad1dc GetModuleHandleA
Library USER32.dll:
0x3dad1e4 GetMonitorInfoA

Exports

Ordinal Address Name
1 0x4434d0 Cruso
2 0x4434e0 Gorgeous
3 0x4434c0 SeeYou
!This program cannot be run in DOS mode.
`.data
.wuxer
.cowubagy
@.rsrc
@.reloc
0WWWWW
_VVVVV
0WWWWW
QQSVWd
HHtXHHt
>If90t
0SSSSS
^F<-uB
<xtX<XtT
jF<-uH
<xtV<XtR
<at9<rt,<wt
URPQQhX
>=Yt1j
QQSVWh
j@j ^V
HtHu4j
s[S;7|G;w
tR99u2
0A@@Ju
^SSSSS
j"^SSSSS
tM<it-<ot)<ut%<xt!<Xt
<dty<itu<otq<utm<xti<Xte
HIf98t
HHtYHHt
_VVVVV
_VVVVV
0SSSSS
0SSSSS
tGHt.Ht&
^SSSSS
8VVVVV
;t$,v-
UQPXY]Y[
HHt*HHt
<0|<9
tK<_t<<$t8<<t4<>t0<-t,<a|
<z~$<A|
<0|O<9
tU<A|B<P
tY<@tO<Zt
t\<@tXj'
NtFNt#NuV
t.<@t5V
TtUHtKHtAHt
0t-HHt
AtIHt0Hu
0WWWWW
AAFFf;
t"SS9]
C PjPV
C$PjQV
C*PjTV
C+PjUV
C,PjVV
C-PjWV
C.PjRV
C/PjSV
.;1s(N
HHt4HHt
Ht\Ht,
teHtFHt&Hu
ty<%tA
PPPPPPPP
PPPPPPPP
u,VVWV
t VV9u
0WWWWW
t+WWVPV
^SSSSS
^SSSSS
>:u8FV
VVVVVQRSSj
^SSSSS
^SSSSS
0SSSSS
^SSSSS
^WWWWW
0SSSSS
8VVVVV
;Cg20v
v)cJQ/'+
LVyCN?
3/J"QF
l]s#FC
9&8f$|#:
70a!Q%
cpf6[F~c
k+Jy6bD
+6ZeP)
`bI9oW$
H;{N`d
J#XIjL
>fm@{\
IXtgJI
1vL{s\
1BBqTp.8
+$0,O_!r
Rz!6)@}
/*/xPH.
(DkqJ&-[9
u;wi2A]
_BVx/1
fCnYdg
/uKjeP
\S>_;
b<3P#AH
+rtZB5
sD{L#u
(I)nCy
c$3A%N
=YT`3T
o.$cB9s
m~bt|M
rL7eYP
$GLTYA/D@
[DU`mqkE
$tfk>'B<=H0
}%WNUx
'FbWpv-R~ybbB
V4 sz6
a@f<Zm
in+i(Q7
;Ia5kc
i9l]Rkr
yJ+lT&No@#;Rv
TM>Wpus
f_xcN
OD_]LxG
%k+enTe
Z*KoA\
=P'fK'
fj,?s
Sdm]d8( p
U?Le#1
qMbx>_
+Eg4yb
.4n`09
-[N]$9
f;>YLL
+l/5C4MfqJ4
R2K_bRd
x,a_!p[
UA~/qG:
?G@bhb
-x1g5g
l`"T<4
;bK-:.
lEVH(0P:
Sij/@?
r>[e$"o
]O\+|e
/0f&N)
5j%+4K
k$Au3a
e=L('U
LX@[=5
zs'osx
HX,X`_
cPsDJM
'O0sT
uXw>j?
\g$az-
a/_xf#
l$%e!rF
Vh6|;W
BRIcC;
d^*w!Ci%
$SR>se0
@X[g}%
HS4jO1
a>-FQW
p=*r)I'%
41*:u4
Z"AV)"
0lP#>E
pcO8 [T+i
4DEHjTj
#)-=Qz
1ZY{^]
V>l*8?
Y?"W/4
vN~d&/
s$ATi.<
wjpG5t
<iIcFFX
oH?`|\X
B*utBL
z=AWn:
*8J>)A5
p*6 lx
MyA_Tp
q*s}Fr
=,2Wy%
zrj^)Wd
<n~ +Z<
Cx*,*?
I%z{En
ivF|"g
|}s7-Lk
EU8S;W
`V>`s+nN
<5V@AF
z}9!)V6P
JZFHqI%
i0W@$$I
KAmQ0(@6K
8;dkXQ&%
n!6]t>
yoqT7[*h
<paE2&'
1m5Sc
9XI^B#g
sHy/pp
s)~4#}J
I}meIw
),3]1R
3,q4u*,
C4n$CI
u{'C0Dn
DU[UlWU
6UoA0f
S^f7?
w-9cR1
}ojy/qD
Q2!K)6z
Pb0k/h|
0cKa;!z
Y'4>M=
W+C208pe
Ws[*~t
7JQ/*^&'
7/eoC-p
XzMZOJ
e|KBTs
.*#.]8-
;^$4QP
efqyTQ
M]C$ySn
VR /G@
Db7+F%
A$0r(\!
iF6}if
/\G0#V
8BVW&[y
Xs',+X
z LdA1V
0I$i(1
v(/(S0
DPvaxH
`LMYzq
YA=zBu
Q_'I%W$k
sw![$kW
P*FB]i
aC:Z*i
_=z0]+W
3V[KL]
\E5D?V
<UGC3
HdQ|vpg
E*P68?
i]Q]wk
s M{;$*.
oB<)'f
J2&^Mg
G kIss
G9''~!
%#ym.K
`6;nV.
}AfiF
|^;e:Mh
YhjL@d
vQ2- RW/
o]v;%b
m_N6m
L`T)jXB$
7"SXcB9
?Vzz `
n\~$(u
H14/4>
]-gM</M
a6Bz1OZ*{Q
IC<m~b
#=U@0;
)$Qf^U
M_whNa
L>>}&C
yl`i}Y
i-.Koy\..
.3?fIn
-u [)
FG"_#C
y:<sn%
)knAG5@
|2d"cV
`zj)gZ
$k}rrv
L(X3@}.
\bss h
)H~pMn
*!<y1_
R'mu-YT
TF[LA-=)D
gvW69_
qgmg8$u}
a1L1_\
,<($nBd
;b5'Q#D
bTLA*x
uH{9?k
bOJFp_
y3T@wV
b?tQX%
+,.xclf
_qQx,+
66gz;M
|?d&%biA
UUUUUU
UUUUUU
l$dd3L{
l$pvb}
_VVVVV
^WWWWW
0SSSSS
_VVVVV
<+t(<-t$:
+t HHt
.?AVlogic_error@std@@
.?AVinvalid_argument@std@@
.?AVlength_error@std@@
.?AVout_of_range@std@@
.?AVbad_cast@std@@
.?AVbad_typeid@std@@
.?AV__non_rtti_object@std@@
.?AVtype_info@@
.?AVbad_exception@std@@
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
.?AVexception@std@@
.?AVbad_alloc@std@@
string too long
invalid string position
invalid string argument
Unknown exception
(null)
`h````
xpxxxx
CorExitProcess
runtime error
TLOSS error
SING error
DOMAIN error
An application has made an attempt to load the C runtime library incorrectly.
Please contact the application's support team for more information.
- Attempt to use MSIL code from this assembly during native code initialization
This indicates a bug in your application. It is most likely the result of calling an MSIL-compiled (/clr) function from a native constructor or from DllMain.
- not enough space for locale information
- Attempt to initialize the CRT more than once.
This indicates a bug in your application.
- CRT not initialized
- unable to initialize heap
- not enough space for lowio initialization
- not enough space for stdio initialization
- pure virtual function call
- not enough space for _onexit/atexit table
- unable to open console device
- unexpected heap error
- unexpected multithread lock error
- not enough space for thread data
This application has requested the Runtime to terminate it in an unusual way.
Please contact the application's support team for more information.
- not enough space for environment
- not enough space for arguments
- floating point support not loaded
Microsoft Visual C++ Runtime Library
<program name unknown>
Runtime Error!
Program:
UTF-16LE
UNICODE
EncodePointer
DecodePointer
FlsFree
FlsSetValue
FlsGetValue
FlsAlloc
bad exception
LC_TIME
LC_NUMERIC
LC_MONETARY
LC_CTYPE
LC_COLLATE
LC_ALL
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
`h`hhh
xppwpp
SystemFunction036
ADVAPI32.DLL
GetProcessWindowStation
GetUserObjectInformationA
GetLastActivePopup
GetActiveWindow
MessageBoxA
USER32.DLL
Complete Object Locator'
Class Hierarchy Descriptor'
Base Class Array'
Base Class Descriptor at (
Type Descriptor'
`local static thread guard'
`managed vector copy constructor iterator'
`vector vbase copy constructor iterator'
`vector copy constructor iterator'
`dynamic atexit destructor for '
`dynamic initializer for '
`eh vector vbase copy constructor iterator'
`eh vector copy constructor iterator'
`managed vector destructor iterator'
`managed vector constructor iterator'
`placement delete[] closure'
`placement delete closure'
`omni callsig'
delete[]
new[]
`local vftable constructor closure'
`local vftable'
`udt returning'
`copy constructor closure'
`eh vector vbase constructor iterator'
`eh vector destructor iterator'
`eh vector constructor iterator'
`virtual displacement map'
`vector vbase constructor iterator'
`vector destructor iterator'
`vector constructor iterator'
`scalar deleting destructor'
`default constructor closure'
`vector deleting destructor'
`vbase destructor'
`string'
`local static guard'
`typeof'
`vcall'
`vbtable'
`vftable'
operator
delete
__unaligned
__restrict
__ptr64
__clrcall
__fastcall
__thiscall
__stdcall
__pascal
__cdecl
__based(
{flat}
`non-type-template-parameter
unsigned
short
<ellipsis>
,<ellipsis>
throw(
`template-parameter
cli::pin_ptr<
cli::array<
`anonymous namespace'
generic-type-
template-parameter-
`unknown ecsu'
union
struct
class
coclass
cointerface
extern "C"
[thunk]:
public:
protected:
private:
virtual
static
`template static data member destructor helper'
`template static data member constructor helper'
`local static destructor helper'
`adjustor{
`vtordisp{
`vtordispex{
const
volatile
volatile
volatile
signed
double
UNKNOWN
__int128
wchar_t
__int64
__int16
__int32
__int8
__w64
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
HH:mm:ss
dddd, MMMM dd, yyyy
MM/dd/yy
December
November
October
September
August
February
January
Saturday
Friday
Thursday
Wednesday
Tuesday
Monday
Sunday
united-states
united-kingdom
trinidad & tobago
south-korea
south-africa
south korea
south africa
slovak
puerto-rico
pr-china
pr china
new-zealand
hong-kong
holland
great britain
england
britain
america
swedish-finland
spanish-venezuela
spanish-uruguay
spanish-puerto rico
spanish-peru
spanish-paraguay
spanish-panama
spanish-nicaragua
spanish-modern
spanish-mexican
spanish-honduras
spanish-guatemala
spanish-el salvador
spanish-ecuador
spanish-dominican republic
spanish-costa rica
spanish-colombia
spanish-chile
spanish-bolivia
spanish-argentina
portuguese-brazilian
norwegian-nynorsk
norwegian-bokmal
norwegian
italian-swiss
irish-english
german-swiss
german-luxembourg
german-lichtenstein
german-austrian
french-swiss
french-luxembourg
french-canadian
french-belgian
english-usa
english-us
english-uk
english-trinidad y tobago
english-south africa
english-nz
english-jamaica
english-ire
english-caribbean
english-can
english-belize
english-aus
english-american
dutch-belgian
chinese-traditional
chinese-singapore
chinese-simplified
chinese-hongkong
chinese
canadian
belgian
australian
american-english
american english
american
Norwegian-Nynorsk
CONIN$
CONOUT$
SunMonTueWedThuFriSat
JanFebMarAprMayJunJulAugSepOctNovDec
bad allocation
0 %s %d %f
GAIsProcessorFeaturePresent
KERNEL32
1#QNAN
1#SNAN
ExitProcess
RemoveVectoredExceptionHandler
FindResourceA
WriteConsoleOutputCharacterA
SystemTimeToTzSpecificLocalTime
HeapAlloc
SetWaitableTimer
HeapFree
GetModuleHandleExW
LockFile
SetTapeParameters
GetCompressedFileSizeW
FindResourceExA
GlobalAlloc
GetLocaleInfoW
SizeofResource
SetSystemTimeAdjustment
GetFileAttributesA
GetExitCodeProcess
GetAtomNameW
GetTimeZoneInformation
GetEnvironmentVariableA
GlobalUnlock
DisconnectNamedPipe
VirtualUnlock
GetConsoleAliasesW
SetLastError
OpenWaitableTimerW
SetConsoleCtrlHandler
SetConsoleOutputCP
AddAtomA
GlobalFindAtomW
GlobalUnWire
lstrcatW
VirtualProtect
GetFileTime
GetCurrentProcessId
LocalFree
SetFileAttributesW
LocalFileTimeToFileTime
KERNEL32.dll
GetMonitorInfoA
USER32.dll
GetStartupInfoW
RaiseException
RtlUnwind
TerminateProcess
GetCurrentProcess
UnhandledExceptionFilter
SetUnhandledExceptionFilter
IsDebuggerPresent
GetLastError
DeleteCriticalSection
LeaveCriticalSection
FatalAppExitA
EnterCriticalSection
VirtualFree
VirtualAlloc
HeapReAlloc
HeapCreate
HeapDestroy
GetModuleHandleW
GetProcAddress
WriteFile
GetStdHandle
GetModuleFileNameA
GetModuleFileNameW
FreeEnvironmentStringsW
GetEnvironmentStringsW
GetCommandLineW
SetHandleCount
GetFileType
GetStartupInfoA
TlsGetValue
TlsAlloc
TlsSetValue
TlsFree
InterlockedIncrement
GetCurrentThreadId
InterlockedDecrement
GetCurrentThread
QueryPerformanceCounter
GetTickCount
GetSystemTimeAsFileTime
SetFilePointer
WideCharToMultiByte
GetConsoleCP
GetConsoleMode
GetCPInfo
GetACP
GetOEMCP
IsValidCodePage
InitializeCriticalSectionAndSpinCount
FreeLibrary
InterlockedExchange
LoadLibraryA
MultiByteToWideChar
CloseHandle
CreateFileA
HeapSize
SetStdHandle
WriteConsoleA
GetConsoleOutputCP
WriteConsoleW
LCMapStringA
LCMapStringW
GetStringTypeA
GetStringTypeW
GetTimeFormatA
GetDateFormatA
GetUserDefaultLCID
GetLocaleInfoA
EnumSystemLocalesA
IsValidLocale
FlushFileBuffers
ReadFile
SetEndOfFile
GetProcessHeap
CompareStringA
CompareStringW
SetEnvironmentVariableA
GetModuleHandleA
dakosu.exe
Gorgeous
SeeYou
8$8*80868<8B8H8N8T8Z8`8f8l8_9{:
<E<R<e<
< >*>G>X>b>
0)0F0S0{2
4$4A4^4{4
66%6E6|6
;!;.;B;W;
=>w>O?g?l?
2B3H3N3T3Z3`3g3n3u3|3
4/464j4
4#5A5H5L5P5T5X5\5`5d5
5&616L6S6X6\6`6
7J7P7T7X7\7
;t;F<o<
?\?c?m?
0)0<0`0
1)181q1
2#2f4t4z4
50565A5F5N5T5^5e5y5
:":':6:?:L:W:i:u:
=2>8>_>k>
1!1)1=1Z1
2K3w3|3
4!4N4i4o4x4
4&5b5x5
66'676L6
7,8D8O8s8|8
9C9V9n9
:8:J:l:r:
;);7;L;V;|;
0&0[0n0G3N3
71797X7h7z7
::':,:0:4:]:
<=<D<H<L<P<T<X<\<`<
111Z1_1v1
4`6l6r6w6}6
7>7W7^7r7
7"8*8j8t8
:':,:S:k:q:|:
;;3;:;R;c;i;t;~;
<3<B<I<V<y<
<$=*=F=^=
=!>+>c>k>
? ?&?/?6?Q?V?^?d?k?q?x?~?
0)0.0;0I0O0\0|0
1<1D1`1m1
1H2n3K6}6
080E0C273
949$:M:
3M3Z3d3r3{3
7-7F7b7k7q7z7
"0;0L0
0m1n23
:%:1:::
;;+;b;k;w;
<0<^=l={=
5S6k6X7
0A0k0i4
4I7M7Q7U7Y7]7a7e7u7
3!3%3)3-31353B3K3`3
3H4M4_4}4
595?5U5[5
77%727A7k7
8i9r9x9
==%=3=<=K=P=Z=h=
=J?Q?W?
4$4I4`4
*0T0d0p1
2&242B2M2X2c2q2|2
425W5_5d5k5q5w5|5
151P1\1
3B4i4n4u4|4
5@5b5h5t5{5
6.6I6{6
6#727R7\7
9(:6:=:y:
;";,;G;[;l;y;
0.050W0\0x0
0&141c1}1
5!6=6M6Z6z6
7C7J7S7]7d7p7v7
8)8/858^8h8
9 989H9m9
:5;V;k;
;!<&<<<a<
0A1Y1y1
9$9-9y9
:\:p:v:
<(<7<o<
6,696?6I6W6
8#8J8t8
9'9]9d9i9s9}9
:$:8:Y:c:m:
:#;@;G;N;U;s;
;C<U<i<
>:>G>W>g>
122B2]2}2
737N7[7
4A5S5e5
6Q7c7u7
#9j9r9C;Y;
6)7<7k7z7F=
= =$=(=,=0=4=8=<=@=D=H=L=P=T=
X3\3`3d3h3l3p3t3x3|3
66C6f6
9(9D9`9|9
9::L:U:^:l:
3+4Z4\5c5
8J9W9w9
=$>:>E>_>e>j>~>
2<2B2H2N2
3#3(3@3Z3y3
4"4B4L4|4"6/6
7A7G7M7Y7_7
8"8)81898A8J8S8_8k8x8
9%:{;t>
;;;l;|;?<E<Q<`<
0060<0B0H0N0T0Z0`0f0l0r0x0~0
1 1&1,12181>1D1J1P1V1\1b1h1n1t1z1
Q7V7a7j7o7
4(525A5H5\5a5g5m5
6!60676>6D6W6]6l6r6~6
617m7r7|7
8.888Q8W8b8z8
2/242:2>2D2H2N2R2X2\2a2g2k2q2u2{2
;W<H>Q>}>
e0&1N1X1
25=+>3>
1y2o3w3*4
5M6S6c6
2A2Z2m2
383S3r3}3
0$0H0h0
4$4,444<4D4L4T4\4d4l4t4x4
=(=8=H=X=|=
> >$>(>,>0>4>8><>@>D>H>L>P>T>X>\>`>d>h>l>p>t>x>|>
2 2024282<2@2D2H2L2P2T2X2\2`2d2h2
; ;$;(;,;0;4;
`2d2h2l2p2t2x2|2
3 3$3(3,3034383<3@3D3H3L3P3T3X3\3`3d3h3l3p3t3x3|3
6 6(60686@6H6P6X6`6h6p6x6
7 7(70787@7H7P7X7`7h7p7x7
8 8(80888@8H8P8X8`8h8
; ;$;4;8;<;@;H;`;p;t;
<$<(<8<<<@<H<`<p<t<
= =$=,=D=T=X=h=l=p=x=
?$?8?@?H?P?T?X?`?t?|?
(0H0h0
101P1p1
282D2`2h2l2
3<3H3P3
4 4<4@4\4`4
5 5,5H5T5p5|5
6(6H6h6
707P7p7
888X8x8
989X9x9
: :4:<:P:X:\:d:l:
D(null)
mscoree.dll
KERNEL32.DLL
((((( H
h(((( H
H
zuwejawupujavacakowororiwupese
vufasapeyodekuhikep
VS_VERSION_INFO
StringFileInfo
040904E4
FileVersions
7.0.2.54
ProductVersions
7.0.21.21
InternalNames
galimatimod
LegalCopyrights
Wsekda
VarFileInfo
Translation
MNusijodaduz zigahefu telapilewuseh kutu kebodutelabofog lacegeyeril wude life
Begoveyayekafif sicile
6Vobe mowefato cowozeramo xakaki wuki vogudilow noludac/Namuvuta niwonuwiyubo wuziyigokuy retolayiretalBKedufo jidukacorebopu jevisifunisajam kajapowave cel xakomi hivuni
Antivirus Signature
Bkav W32.AIDetect.malware1
Elastic malicious (high confidence)
MicroWorld-eScan Gen:Variant.Graftor.939918
CMC Clean
CAT-QuickHeal Clean
McAfee RDN/Generic PWS.y
Cylance Unsafe
VIPRE Trojan.Win32.Generic!BT
Sangfor Trojan.Win32.Save.a
K7AntiVirus Trojan ( 0057aa691 )
BitDefender Gen:Variant.Graftor.939918
K7GW Trojan ( 0057aa691 )
CrowdStrike win/malicious_confidence_100% (W)
Baidu Clean
Cyren W32/Kryptik.DVD.gen!Eldorado
Symantec ML.Attribute.HighConfidence
ESET-NOD32 a variant of Win32/Kryptik.HKJX
APEX Malicious
Paloalto generic.ml
ClamAV Clean
Kaspersky HEUR:Backdoor.Win32.Mokes.gen
Alibaba Trojan:Win32/Kryptik.5ae7c00a
NANO-Antivirus Clean
ViRobot Clean
SUPERAntiSpyware Clean
Tencent Win32.Trojan.Inject.Auto
Ad-Aware Gen:Variant.Graftor.939918
Emsisoft Trojan.Agent (A)
Comodo Clean
F-Secure Clean
DrWeb Trojan.Siggen13.6179
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition BehavesLike.Win32.Generic.fc
FireEye Generic.mg.6cf0200d66b943e0
Sophos Mal/Generic-S
SentinelOne Static AI - Malicious PE
GData Gen:Variant.Graftor.939918
Jiangmin Clean
MaxSecure Clean
Avira Clean
MAX malware (ai score=99)
Antiy-AVL Clean
Kingsoft Win32.Troj.Undef.(kcloud)
Gridinsoft Trojan.Win32.Kryptik.oa
Arcabit Trojan.Graftor.DE578E
AegisLab Trojan.Win32.Noon.l!c
ZoneAlarm HEUR:Backdoor.Win32.Mokes.gen
Microsoft Trojan:Win32/Glupteba!ml
Cynet Malicious (score: 100)
AhnLab-V3 Trojan/Win.MalPE.R415606
Acronis suspicious
BitDefenderTheta Gen:NN.ZexaF.34670.wCX@amS1cOpG
ALYac Gen:Variant.Graftor.939918
TACHYON Clean
VBA32 Clean
Malwarebytes Trojan.MalPack.GS
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Rising Trojan.Kryptik!1.D4B0 (CLOUD)
Yandex Clean
Ikarus Backdoor.Win32.Kredoor
eGambit Clean
Fortinet W32/Kryptik.HKJI!tr
Webroot Clean
AVG Win32:Trojan-gen
Cybereason malicious.85074c
Avast Win32:Trojan-gen
Qihoo-360 Win32/Trojan.Generic.HwoCi3sA
No IRMA results available.