Static | ZeroBOX

PE Compile Time

2020-06-30 00:32:51

PDB Path

C:\yigefefubimafi.pdber\runtime\crypt\tmp_41295613\bin\vixivobo.pdb°D‘D$‘D4‘D°“D

PE Imphash

7992f385465c3a91784159b680857f5e

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x00044636 0x00044800 7.53314480032
.rdata 0x00046000 0x00004cc2 0x00004e00 5.4599427565
.data 0x0004b000 0x003f3cdc 0x00001a00 3.4025757446
.buxuda 0x0043f000 0x00001001 0x00000400 0.0
.rsrc 0x00441000 0x00019508 0x00019600 5.43723380014

Resources

Name Offset Size Language Sub-language File type
CUZOPECADUDONAGUJOVENEKOCUZEVO 0x00455338 0x000006c5 LANG_SAAMI SUBLANG_ARABIC_MOROCCO ASCII text, with very long lines, with no line terminators
DAKALAMOXITILAWOZEXUGELE 0x00456c80 0x000003d8 LANG_SAAMI SUBLANG_ARABIC_MOROCCO ASCII text, with very long lines, with no line terminators
FUCUTI 0x00455a00 0x0000127b LANG_SAAMI SUBLANG_ARABIC_MOROCCO ASCII text, with very long lines, with no line terminators
WIPUJAXECUMAWEYENANIWOFOPOPA 0x00457058 0x000005c6 LANG_SAAMI SUBLANG_ARABIC_MOROCCO ASCII text, with very long lines, with no line terminators
RT_CURSOR 0x00459888 0x000008a8 LANG_SAAMI SUBLANG_ARABIC_MOROCCO dBase III DBT, version number 0, next free block index 40, 1st item "\251\317"
RT_CURSOR 0x00459888 0x000008a8 LANG_SAAMI SUBLANG_ARABIC_MOROCCO dBase III DBT, version number 0, next free block index 40, 1st item "\251\317"
RT_CURSOR 0x00459888 0x000008a8 LANG_SAAMI SUBLANG_ARABIC_MOROCCO dBase III DBT, version number 0, next free block index 40, 1st item "\251\317"
RT_CURSOR 0x00459888 0x000008a8 LANG_SAAMI SUBLANG_ARABIC_MOROCCO dBase III DBT, version number 0, next free block index 40, 1st item "\251\317"
RT_CURSOR 0x00459888 0x000008a8 LANG_SAAMI SUBLANG_ARABIC_MOROCCO dBase III DBT, version number 0, next free block index 40, 1st item "\251\317"
RT_ICON 0x00454e58 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00454e58 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00454e58 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00454e58 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00454e58 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00454e58 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00454e58 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00454e58 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00454e58 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00454e58 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00454e58 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00454e58 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00454e58 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00454e58 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00454e58 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00454e58 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00454e58 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00454e58 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00454e58 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00454e58 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00454e58 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00454e58 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00454e58 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00454e58 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_STRING 0x0045a2a0 0x00000266 LANG_SAAMI SUBLANG_ARABIC_MOROCCO data
RT_ACCELERATOR 0x00457620 0x00000078 LANG_SAAMI SUBLANG_ARABIC_MOROCCO data
RT_GROUP_CURSOR 0x0045a130 0x00000022 LANG_SAAMI SUBLANG_ARABIC_MOROCCO data
RT_GROUP_CURSOR 0x0045a130 0x00000022 LANG_SAAMI SUBLANG_ARABIC_MOROCCO data
RT_GROUP_ICON 0x004552c0 0x00000076 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_GROUP_ICON 0x004552c0 0x00000076 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_GROUP_ICON 0x004552c0 0x00000076 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_VERSION 0x0045a158 0x00000144 LANG_SAAMI SUBLANG_ARABIC_MOROCCO data
None 0x004576d8 0x0000000a LANG_SAAMI SUBLANG_ARABIC_MOROCCO data
None 0x004576d8 0x0000000a LANG_SAAMI SUBLANG_ARABIC_MOROCCO data
None 0x004576d8 0x0000000a LANG_SAAMI SUBLANG_ARABIC_MOROCCO data
None 0x004576d8 0x0000000a LANG_SAAMI SUBLANG_ARABIC_MOROCCO data
None 0x004576d8 0x0000000a LANG_SAAMI SUBLANG_ARABIC_MOROCCO data

Imports

Library KERNEL32.dll:
0x446004 SetThreadContext
0x446008 lstrlenA
0x44600c TlsGetValue
0x446010 SetLocalTime
0x446014 FreeLibrary
0x446018 CallNamedPipeA
0x446020 SetWaitableTimer
0x446028 LoadLibraryExW
0x446030 GlobalSize
0x446034 GetProfileSectionA
0x446038 WriteConsoleInputA
0x44603c GetComputerNameW
0x446044 CreateNamedPipeW
0x446048 WriteFile
0x44604c GetCommandLineA
0x446050 GlobalAlloc
0x446058 GetConsoleMode
0x44605c TerminateThread
0x446060 Sleep
0x446074 GetFileAttributesA
0x446078 Beep
0x446080 GetBinaryTypeA
0x446084 lstrcatA
0x446088 DisconnectNamedPipe
0x44608c InterlockedExchange
0x446090 GetStdHandle
0x446094 OpenMutexW
0x44609c GetLastError
0x4460a4 HeapSize
0x4460a8 MoveFileW
0x4460ac GetLocalTime
0x4460b0 LoadLibraryA
0x4460b4 LocalAlloc
0x4460bc AddAtomA
0x4460c0 SetCommMask
0x4460c4 GetOEMCP
0x4460cc DebugBreakProcess
0x4460d0 CreateMutexA
0x4460d4 VirtualProtect
0x4460d8 GetSystemTime
0x4460e0 CompareStringW
0x4460e4 DeleteFileA
0x4460e8 TerminateProcess
0x4460ec GetCurrentProcess
0x4460f4 IsDebuggerPresent
0x4460f8 HeapReAlloc
0x4460fc HeapAlloc
0x446100 GetStartupInfoW
0x446104 RaiseException
0x446108 RtlUnwind
0x44610c HeapFree
0x446110 GetModuleHandleW
0x446114 GetProcAddress
0x446118 TlsAlloc
0x44611c TlsSetValue
0x446120 TlsFree
0x446128 SetLastError
0x44612c GetCurrentThreadId
0x446134 GetCurrentThread
0x446140 FatalAppExitA
0x446148 HeapCreate
0x44614c HeapDestroy
0x446150 VirtualFree
0x446154 VirtualAlloc
0x446158 ExitProcess
0x44615c GetModuleFileNameA
0x446160 GetModuleFileNameW
0x44616c GetCommandLineW
0x446170 SetHandleCount
0x446174 GetFileType
0x446178 GetStartupInfoA
0x446180 GetTickCount
0x446184 GetCurrentProcessId
0x44618c GetCPInfo
0x446190 GetACP
0x446194 IsValidCodePage
0x4461a0 GetTimeFormatA
0x4461a4 GetDateFormatA
0x4461a8 GetUserDefaultLCID
0x4461ac GetLocaleInfoA
0x4461b0 EnumSystemLocalesA
0x4461b4 IsValidLocale
0x4461b8 GetStringTypeA
0x4461bc MultiByteToWideChar
0x4461c0 GetStringTypeW
0x4461c4 LCMapStringA
0x4461c8 WideCharToMultiByte
0x4461cc LCMapStringW
0x4461d0 GetLocaleInfoW
0x4461d8 CompareStringA
0x4461dc GetModuleHandleA
Library USER32.dll:
0x4461e4 GetWindowInfo

!This program cannot be run in DOS mode.
`.rdata
@.data
.buxuda
0WWWWW
0WWWWW
QQSVWd
0SSSSS
t$hXcD
t h,jD
u&hxiD
>=Yt1j
QQSVWh
j@j ^V
HtHu4j
s[S;7|G;w
YYh<jD
tR99u2
uQhtkD
0A@@Ju
URPQQh
HHt*HHt
<0|<9
tK<_t<<$t8<<t4<>t0<-t,<a|
<z~$<A|
<0|O<9
tU<A|B<P
tY<@tO<Zt
tQh|pD
t\<@tXj'
YPWhTpD
Du h|sD
NtFNt#NuV
t.<@t5V
TtUHtKHtAHt
HuShDtD
0t-HHt
u+h`uD
u8h\uD
AtIHt0Hu
_VVVVV
_VVVVV
0SSSSS
0SSSSS
0WWWWW
AAFFf;
;t$,v-
UQPXY]Y[
C PjPV
C$PjQV
C*PjTV
C+PjUV
C,PjVV
C-PjWV
C.PjRV
C/PjSV
.;1s(N
HHt4HHt
Ht\Ht,
teHtFHt&Hu
ty<%tA
PPPPPPPP
PPPPPPPP
t"SS9]
u,VVWV
t VV9u
^SSSSS
^SSSSS
>:u8FV
VVVVVQRSSj
^SSSSS
^SSSSS
0SSSSS
t+WWVPV
^SSSSS
^WWWWW
0SSSSS
8VVVVV
"Gwbw
01HJZN^z
>!QF5u
z`mk=d
>!QF5u
*k9a{uo+M
IDm+{kF
Q{6~VAl
R|aWZ>\
3t()'L
fK}#c97q
9Q}2cE
\+KxS?Nv
DhY)'.x_
]E"DeX
,vtQ,L
6&VD4y
gn-xHr
#r@@lt
4"g+;Z
nWil/(
CXB<GsH%
9. hbh7?:
mZ*v{
RPU7h4A
#B:U-@!
(RE}hd
2AF2FC
ZK$x<$L
0-P7s{
p?HN@:
!o\7/
>a(Emu[9$x
OZY}rXf
5L~e %
)=5E*G
:J&@f4`e{
f)6SK2
ZU~\Cg
,sc}lq/[|
:+OWMjWE
[JXwv
3oGeh[
IX-jFd
749M=n\N
Z0:+djh
g&QmE~
| c^?a
&1 ' ^
RvRLme
]my7-Vn
{-Q5!<(f
_Qn+3R
z8yFFa
?ACa}6D!C5
A^*{!t
f@2+|RA
"QqDpW
x|DR+d
D1K!!J
b f\;CX
E3=Rw8
(wOQ((
LoHkS.r^
,)[m-%y
{E5uhG
WP-ZH<
:jqebD
=2~kM'Y
q4MM*6
OLbo4L
o*B>1|
o<>xg]
G}M\9Z
,(=D^_
U+ZP)8
{xEaUQ
<+'rR8z
j%.q_5
JjEQp`9
C#!az5
T}wXz9
"Y$.zk
54E9ZV
.+OeE7
9 VX~r
VTk-77
s(-f!|
(YcBSf
g+$5wL
K=#/yxkyj
K%>=re
0if"A
;VgS:T
[eW?-@K
jM^i5{mT:
n8`/Un
i|JL9]
!ZJk\V
~/C'MC
x<13Ku
;,?7CW
M&HKiQ?
[PpJo^J
Roc_-Q
7qrk{0}C
CL@,q3<{
k.{h`2
r\KP{c,
b3Of}S
jifQ$t
1!#=3lo
|Iy\md
w@zg5K
lweKg/
?).%JL^6l
] XF+V
IwWi)d
tQ38H
S8-'mw
V6%Rj5D;Z
QE`EYA
d)? jr~.
Ls6|-p
gj.R,?O
;[*#N%
M/7OpC
H;Xjc/
)JNf!l
`iw#)^
MuUgq'
uURw$*Q8
~Zv>gEVzdur
LsO&dV
e}(Pdh
?,Bf6+:9
[Uk^{B
D9@+xe
ioyQ;
*uJ'~f
F+@qcY
ek(&9Q
vwNY3&*S
}"4w5;
P@FJj
+-;frw
=Fx>lf
8|6dFd
yQ0$~~o
q(ovevW~d
L8;P1i
x!a8=[
ZPs|F
eIpB_,
]b'MxS
)+kWI@
q,)h};
SPvS-j
tw\?z0
Y$S(A~
5p|-16
^Yb\$5
6cf/|E(
bN<UgF
/p2_u-E)9
BE%WpQz
h-B8+@,
f0->b=
[,$ZnW
SF[v*Bja8"
7)+8:X#
'}<]u,
Xn>tkqb
CRO#z<
[Xd Cz
5QQ[UT
a6+%,H
3(XcT?
#v]50"t
V`P>C
iF4-QB
E8-=2P
,T8_Akv
.A/JghO
)LW>d`
*Z/9eXe
bLJ6L*:Z
) GqYn1
9O17JqtRf4
){?>[_
_9{qr!
Xa&Z<i
A}P=em:
:[fX!i
uc>].C
Rv80)ub*#Fi
nTZiCo
hGMrkJ
?NjgF
4y{6@y
{k)9{^p
k+{00^
=jkQo+>^7r
~lr9y^H
/{/3"9
:[v'BD
"o|pH#
?rHA)I9
a:=cY!
5Sy_}&?
si!|r2
lNspv
q=6&M@o;
}[WXh'j
"C<hw&"
_tS;H,
[EDfmu
dzN .ISwF
4LdHmR.
NUEpLO
{e8SuK
3T58W1Q
S{^idV
/dmVIU,
4k[5JN
bkb5)b
kY>RUcc
*<[CH6
aK!]jf=
H&G+a*
%O&sFy
_VVVVV
^WWWWW
0SSSSS
_VVVVV
tNIt?It0It
tRHtCHt4Ht%HtFHHt
<+t(<-t$:
+t HHt
bad allocation
string too long
invalid string position
invalid string argument
Unknown exception
EncodePointer
DecodePointer
FlsFree
FlsSetValue
FlsGetValue
FlsAlloc
CorExitProcess
runtime error
TLOSS error
SING error
DOMAIN error
An application has made an attempt to load the C runtime library incorrectly.
Please contact the application's support team for more information.
- Attempt to use MSIL code from this assembly during native code initialization
This indicates a bug in your application. It is most likely the result of calling an MSIL-compiled (/clr) function from a native constructor or from DllMain.
- not enough space for locale information
- Attempt to initialize the CRT more than once.
This indicates a bug in your application.
- CRT not initialized
- unable to initialize heap
- not enough space for lowio initialization
- not enough space for stdio initialization
- pure virtual function call
- not enough space for _onexit/atexit table
- unable to open console device
- unexpected heap error
- unexpected multithread lock error
- not enough space for thread data
This application has requested the Runtime to terminate it in an unusual way.
Please contact the application's support team for more information.
- not enough space for environment
- not enough space for arguments
- floating point support not loaded
Microsoft Visual C++ Runtime Library
<program name unknown>
Runtime Error!
Program:
bad exception
LC_TIME
LC_NUMERIC
LC_MONETARY
LC_CTYPE
LC_COLLATE
LC_ALL
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
Complete Object Locator'
Class Hierarchy Descriptor'
Base Class Array'
Base Class Descriptor at (
Type Descriptor'
`local static thread guard'
`managed vector copy constructor iterator'
`vector vbase copy constructor iterator'
`vector copy constructor iterator'
`dynamic atexit destructor for '
`dynamic initializer for '
`eh vector vbase copy constructor iterator'
`eh vector copy constructor iterator'
`managed vector destructor iterator'
`managed vector constructor iterator'
`placement delete[] closure'
`placement delete closure'
`omni callsig'
delete[]
new[]
`local vftable constructor closure'
`local vftable'
`udt returning'
`copy constructor closure'
`eh vector vbase constructor iterator'
`eh vector destructor iterator'
`eh vector constructor iterator'
`virtual displacement map'
`vector vbase constructor iterator'
`vector destructor iterator'
`vector constructor iterator'
`scalar deleting destructor'
`default constructor closure'
`vector deleting destructor'
`vbase destructor'
`string'
`local static guard'
`typeof'
`vcall'
`vbtable'
`vftable'
operator
delete
__unaligned
__restrict
__ptr64
__clrcall
__fastcall
__thiscall
__stdcall
__pascal
__cdecl
__based(
{flat}
`non-type-template-parameter
unsigned
short
<ellipsis>
,<ellipsis>
throw(
`template-parameter
cli::pin_ptr<
cli::array<
`anonymous namespace'
generic-type-
template-parameter-
`unknown ecsu'
union
struct
class
coclass
cointerface
extern "C"
[thunk]:
public:
protected:
private:
virtual
static
`template static data member destructor helper'
`template static data member constructor helper'
`local static destructor helper'
`adjustor{
`vtordisp{
`vtordispex{
const
volatile
volatile
volatile
signed
double
UNKNOWN
__int128
wchar_t
__int64
__int16
__int32
__int8
__w64
SystemFunction036
ADVAPI32.DLL
GetProcessWindowStation
GetUserObjectInformationA
GetLastActivePopup
GetActiveWindow
MessageBoxA
USER32.DLL
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
HH:mm:ss
dddd, MMMM dd, yyyy
MM/dd/yy
December
November
October
September
August
February
January
Saturday
Friday
Thursday
Wednesday
Tuesday
Monday
Sunday
united-states
united-kingdom
trinidad & tobago
south-korea
south-africa
south korea
south africa
slovak
puerto-rico
pr-china
pr china
new-zealand
hong-kong
holland
great britain
england
britain
america
swedish-finland
spanish-venezuela
spanish-uruguay
spanish-puerto rico
spanish-peru
spanish-paraguay
spanish-panama
spanish-nicaragua
spanish-modern
spanish-mexican
spanish-honduras
spanish-guatemala
spanish-el salvador
spanish-ecuador
spanish-dominican republic
spanish-costa rica
spanish-colombia
spanish-chile
spanish-bolivia
spanish-argentina
portuguese-brazilian
norwegian-nynorsk
norwegian-bokmal
norwegian
italian-swiss
irish-english
german-swiss
german-luxembourg
german-lichtenstein
german-austrian
french-swiss
french-luxembourg
french-canadian
french-belgian
english-usa
english-us
english-uk
english-trinidad y tobago
english-south africa
english-nz
english-jamaica
english-ire
english-caribbean
english-can
english-belize
english-aus
english-american
dutch-belgian
chinese-traditional
chinese-singapore
chinese-simplified
chinese-hongkong
chinese
canadian
belgian
australian
american-english
american english
american
Norwegian-Nynorsk
SunMonTueWedThuFriSat
JanFebMarAprMayJunJulAugSepOctNovDec
bad allocation
kernel32.dll
easProtect
vector<T> too long
GAIsProcessorFeaturePresent
KERNEL32
<8bunz8
l,kg<i
<@En[vP
?1#QNAN
1#SNAN
_nextafter
_hypot
C:\yigefefubimafi.pdb
er\runtime\crypt\tmp_41295613\bin\vixivobo.pdb
FileTimeToDosDateTime
SetThreadContext
lstrlenA
TlsGetValue
SetLocalTime
FreeLibrary
CallNamedPipeA
SystemTimeToTzSpecificLocalTime
SetWaitableTimer
SetUnhandledExceptionFilter
LoadLibraryExW
GetNumberOfConsoleMouseButtons
GlobalSize
GetProfileSectionA
WriteConsoleInputA
GetComputerNameW
GetProcessPriorityBoost
CreateNamedPipeW
WriteFile
GetCommandLineA
GlobalAlloc
GetVolumeInformationA
GetConsoleMode
TerminateThread
GetSystemPowerStatus
SetVolumeMountPointA
GetSystemTimeAdjustment
DeleteVolumeMountPointW
GetFileAttributesA
SetTimeZoneInformation
GetBinaryTypeA
lstrcatA
DisconnectNamedPipe
InterlockedExchange
GetStdHandle
OpenMutexW
GetHandleInformation
GetLastError
GetCurrentDirectoryW
HeapSize
MoveFileW
GetLocalTime
LoadLibraryA
LocalAlloc
BuildCommDCBAndTimeoutsW
AddAtomA
SetCommMask
GetOEMCP
CreateIoCompletionPort
DebugBreakProcess
CreateMutexA
VirtualProtect
GetSystemTime
KERNEL32.dll
GetWindowInfo
USER32.dll
DeleteFileA
TerminateProcess
GetCurrentProcess
UnhandledExceptionFilter
IsDebuggerPresent
HeapReAlloc
HeapAlloc
GetStartupInfoW
RaiseException
RtlUnwind
HeapFree
GetModuleHandleW
GetProcAddress
TlsAlloc
TlsSetValue
TlsFree
InterlockedIncrement
SetLastError
GetCurrentThreadId
InterlockedDecrement
GetCurrentThread
DeleteCriticalSection
LeaveCriticalSection
FatalAppExitA
EnterCriticalSection
HeapCreate
HeapDestroy
VirtualFree
VirtualAlloc
ExitProcess
GetModuleFileNameA
GetModuleFileNameW
FreeEnvironmentStringsW
GetEnvironmentStringsW
GetCommandLineW
SetHandleCount
GetFileType
GetStartupInfoA
QueryPerformanceCounter
GetTickCount
GetCurrentProcessId
GetSystemTimeAsFileTime
GetCPInfo
GetACP
IsValidCodePage
InitializeCriticalSectionAndSpinCount
SetConsoleCtrlHandler
GetTimeFormatA
GetDateFormatA
GetUserDefaultLCID
GetLocaleInfoA
EnumSystemLocalesA
IsValidLocale
GetStringTypeA
MultiByteToWideChar
GetStringTypeW
LCMapStringA
WideCharToMultiByte
LCMapStringW
GetLocaleInfoW
GetTimeZoneInformation
CompareStringA
CompareStringW
SetEnvironmentVariableA
GetModuleHandleA
.?AVinvalid_argument@std@@
.?AVout_of_range@std@@
.?AVbad_cast@std@@
.?AVbad_typeid@std@@
.?AV__non_rtti_object@std@@
.?AVtype_info@@
.?AVbad_exception@std@@
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
.?AVexception@std@@
.?AVlogic_error@std@@
.?AVlength_error@std@@
.?AVbad_alloc@std@@
(((((g
pppppppppppNNNNNNNN
========N
\\\\\\\\\\\\\\\\\\\\\
Eq_J"7
D7"J_qE
444444444
.........................................................................................................................................................................
.............
Fp..............F
Q8.........WX
[...............F
F\......
n...............
...............
Je................
`................[
................Q
.................QYyyyyyyyyyyy
x.................F
................
^lF..............
6666666666
X............P1
oX..........
X........P1
33333333333333
zX......
3^oX....
x7F........pP
.................
Q........................X
........................X
>>>Ij..........................Q
..........................
Q............................xIKT............................XkQ..............................
..............................
..............
!!!!!!!!'
DDDDDDDD~
ccc]i2N
]]]-]]-]-]-
99~999
6Z+&Nj!
:^,Is~
tt=XL-0
EEEE;;
x;;;;;;
f;;;;;;;
vZ&ub
222222222222222222222
CJ666666666666666666666J
]]]]]]J
222222222222
J62&CCj
62jJJC
62jJJj
F222222222
62jJJC=
J>]>2J
J62jJJC=
C=]]]]]]]
JC=>>]]]]]]]]]]>6
>>>>>>>>>>>]>6J
666666666>6666J
666666666666666666666
666666666666666666666J
JJJJF>=
==t==tt=
=6]==;
EEEEEEEEEEEEEEEEEEEEEEE
l66666666666666666666666l
44444444
44446l
Zuuuu
ZZuuuu
ZZuuuuu
Zuuuu
ZZu
l6Bnnn
`````````````^
llllll`
``````
l`````````
`````````````
uuu&`<
N[q
P33333333P3
UUUUUUUUU
``amsvs
b`bqxzz
565Jvzw
NNN@uvu
OMOCxwz
Dawayixedutug. Walanugugul badaxakewiniro. Cazuji fomofad zokevifulukiyet monuxeyogesoged hopuzirizabacuw. Tiresalevukig nezoxe cedaxapeyel. Capas berolape parorixezigoka nuxepi tafi. Cosaxikor kakehosaxucikil. Fuhuya kevunaxekuj jogenusecetifi. Mumogipubasemu sap bebu. Subagak. Gihen lumud. Piwerikoxec jinasanovijotuj galuvacoxefuce hepatenepolahos xohayim. Kukodapul. Xazazupaxac gohixup wobanud hatugu. Tubayefoc hedipixiyoco zehi. Naselupanu zunifanup xijopolifafad dije. Periya xaca. Wadicogapeze cemug. Dobiwalepugani hax kiyehuvada. Dosibej nag jojofida zucaxodi pepari. Wuzu refewohebuz fetatiso gumo. Zobanu. Fisubujo budupaj nihuyuh daribiyu cexatupisovik. Bagupobiyu ner ricoduludifawa mibidayeh. Jud ficidoxudoyul yozajaxicasami. Hojiwemiviy cax mokuwofom. Cefilosono. Zowip febonimayowe jagovipenu pubirikozucosog. Rowibosukuz xukocuxohupifur lepuredako zesah hido. Heguj digu watujifofitaruh munesavakavesu fugu. Nutamepexujepuc jivojoheh lafewamodesok rinofumog. Ragilin yenusudi pabocohuxak vucolijisoboj.
Zegivucobe zebubuxufu vinaxuki. Jur weh dajukazim tizofigijolawov. Watonulojol layecey pilizonivat. Zusocipop xesidoha jeza. Medifoxunuwik wozarucupud nonewuzixoko. Dekajak gizidajup puxe. Revopidojo giyagojo siha. Himem hidapiferuwolir fanifahixu vitowaz. Deliw. Bidepu jifuh. Mokugore pecimajuhe renelebuxikorey. Wezuxarud. Tij. Jogejoy lisevazig kiv. Bowobuhepolime husul dup wageketuyoroya. Vojunis nuzejac turevetetijiyu. Lecoxi fotineharege norupebogixex. Xowururidatom yayupisubuyapuh. Zadukiyunok mulipuhu. Vesuzoda bocotag. Nufenipu xadomacucedal panipizozokolil topifupanex. Necufezebejado ciw xezurogeva kalucu. Sefejonusaxu pukiteyo hojenovakisoyon. Mahapuhab perefocukisemuh tejepo. Nipe tabigodadi tiwadufinami. Tozev. Vevulejotejono logufe. Zonumabuveh sitecuham jesagihewe. Ginonax lutoxohugodu vil tomejib rorunihufijuxug. Dopehefadoxavo. Muk yege. Zesayokadej kapiloxofijewis fog. Zuwabifopen. Purav vafihubibaba. Cemesowogugoza teso likojefayuyu lolitezola wozopan. Behuyuvih. Pijofesi nigogaraguzelug tuj
Muyabesiho dilamob mesuvu rawopiyanadayu rub. Refamakasacuh huhidupewopoy lajadudimed rir. Xamic pijucijemo repekagojuki. Wigocojawuca wogeged wahac juhitepisuce. Xidatuyi xukiwi separutosum lufofodi gof. Tawo hekamohokunonoh cikehez woyowohacegok. Dayemabudukif rov cuxa. Kiki xek. Mefanubiwayedak rur. Matineberimanez moceboyob civu lopehezenagav nehahil. Muzoyemed doye dojenawoved gasebu cudam. Mavezoho. Fomehukuyegepu tetiloce mekarugi. Tisepetetonefi. Fisawizixuzap kejisogudataju. Sasoxovomax hacudejawatutaz. Vekecasev nihixocuzexi sesegalek pulirepepifu. Teteguvucer gimitup supani. Riyadikayegi roz. Tisubo tomopakupepic. Sijeropub yeninorenewuto put papi. Xulocociz yok zehogera cuveyitawed numekozef. Wil jisuyofurawiwus gerelurav. Cuwafowu zacazehonu jiyim. Yewexaruhizixuh suwoketad cepacivo. Xonavevax jigaxi piwalivuginey yus bifuzujezovovux. Durogipumo yubebubobepesu xulid pujevarakopabo guxuneturiv. Dodoxanidofeb. Risezulepo kuxazuca vojigafopevog pasoboveli daz.Hibova. Tuxoxasutotico sipu notikop pogu
iiiiii
iiiiii
iiiiiiiiiiii
iiiiiiiiii
iiiiii
iiiiiiiii
iiiiiiiiiiiii
iiiiiiii

Djjjjjjj
Djjjjj
Djjjjjj
jjjjjjjj
jjjjjjjj
KERNEL32.DLL
mscoree.dll
((((( H
h(((( H
H
yufoxejoxu
CUZOPECADUDONAGUJOVENEKOCUZEVO
FUCUTI
DAKALAMOXITILAWOZEXUGELE
WIPUJAXECUMAWEYENANIWOFOPOPA
/ P6pL
,/KPip
/-P?pR
/ P6pL
,/KPip
/-P?pR
VS_VERSION_INFO
StringFileInfo
041904E6
FileVerus
1.0.52.18
ProductVersys
1.8.37.29
VarFileInfo
Translations
KLijubamumuh yuwun zakawuriv rud moxa jagobefis zojajugezuwaf duna gupofumozBPacobos cixipicegulupox gimezatitesug jexalolaner lubejaluki lokok
FekuwijomahotufgMibehumar xitotixiti hopamawubidav nebutozeriko pexife wegorapu mafoyeducekas kulizajakof nazeyulikalel
Nivugiyejafax
Demosovem femedazim
Antivirus Signature
Bkav W32.AIDetect.malware1
Elastic malicious (high confidence)
DrWeb Clean
MicroWorld-eScan Trojan.GenericKD.46190656
FireEye Generic.mg.cd4a716b2886b9d6
CAT-QuickHeal Clean
ALYac Trojan.GenericKDZ.74697
Cylance Unsafe
Zillya Clean
AegisLab Trojan.Win32.Noon.l!c
Sangfor Trojan.Win32.Save.a
K7AntiVirus Trojan ( 0057b7ae1 )
BitDefender Trojan.GenericKD.46190656
K7GW Trojan ( 0057b7ae1 )
Cybereason malicious.55f5f0
BitDefenderTheta Gen:NN.ZexaF.34684.zuX@aC7f9gkO
Cyren W32/Kryptik.DYI.gen!Eldorado
Symantec ML.Attribute.HighConfidence
ESET-NOD32 a variant of Win32/Kryptik.HKOR
APEX Malicious
Avast Win32:CrypterX-gen [Trj]
ClamAV Clean
Kaspersky HEUR:Trojan-Spy.Win32.Noon.gen
Alibaba Trojan:Win32/Ranumbot.1c2034cc
NANO-Antivirus Clean
ViRobot Clean
Tencent Win32.Trojan.Inject.Auto
Ad-Aware Trojan.GenericKDZ.74697
TACHYON Clean
Sophos Mal/Generic-R + Mal/GandCrypt-A
Comodo TrojWare.Win32.Agent.mrwhy@0
F-Secure Clean
Baidu Clean
VIPRE Trojan.Win32.Generic!BT
TrendMicro Clean
McAfee-GW-Edition BehavesLike.Win32.Lockbit.gc
CMC Clean
Emsisoft Trojan.GenericKDZ.74697 (B)
Ikarus Trojan.Win32.Crypt
GData Win32.Trojan.PSE.1L1P37C
Jiangmin Clean
eGambit Clean
Avira TR/Crypt.Agent.hrogz
Antiy-AVL Clean
Kingsoft Win32.Troj.Undef.(kcloud)
Gridinsoft Trojan.Win32.Kryptik.ns
Arcabit Clean
SUPERAntiSpyware Clean
ZoneAlarm Clean
Microsoft Trojan:Win32/Glupteba.PR!MTB
Cynet Malicious (score: 100)
AhnLab-V3 CoinMiner/Win.Glupteba.R417847
Acronis suspicious
McAfee RDN/Generic.grp
MAX malware (ai score=100)
VBA32 Clean
Malwarebytes Trojan.MalPack.GS
Panda Trj/GdSda.A
Zoner Clean
TrendMicro-HouseCall TROJ_GEN.R002C0RDQ21
Rising Malware.Obscure/Heur!1.9E03 (CLOUD)
Yandex Clean
SentinelOne Static AI - Malicious PE
MaxSecure Clean
Fortinet W32/Kryptik.HKPA!tr
Webroot W32.Trojan.Gen
AVG Win32:CrypterX-gen [Trj]
Paloalto generic.ml
CrowdStrike win/malicious_confidence_100% (W)
Qihoo-360 Clean
No IRMA results available.