Static | ZeroBOX

PE Compile Time

2020-11-05 17:44:17

PE Imphash

b0ad6bf31823e1fb2677105ef8ea4f6c

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x0007738a 0x00077400 7.92394837378
.data 0x00079000 0x00016178 0x00004c00 1.06087572053
.pecawab 0x00090000 0x0000007c 0x00000200 0.0
.tls 0x00091000 0x00001009 0x00001200 0.0
.new 0x00093000 0x00002d1e 0x00002e00 5.50642719013
.rsrc 0x00096000 0x0001b680 0x0001b800 5.79288415722
.reloc 0x000b2000 0x0000154e 0x00001600 5.39559992695

Resources

Name Offset Size Language Sub-language File type
POFOLAZIVUVUMIMUPIRIC 0x000b08d8 0x00000bf7 LANG_MONGOLIAN SUBLANG_DEFAULT ASCII text, with very long lines, with no line terminators
RT_ICON 0x000b03f8 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x000b03f8 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x000b03f8 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x000b03f8 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x000b03f8 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x000b03f8 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x000b03f8 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x000b03f8 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x000b03f8 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x000b03f8 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x000b03f8 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x000b03f8 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x000b03f8 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x000b03f8 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x000b03f8 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x000b03f8 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x000b03f8 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x000b03f8 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x000b03f8 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x000b03f8 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x000b03f8 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x000b03f8 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x000b03f8 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x000b03f8 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x000b03f8 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x000b03f8 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x000b03f8 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x000b03f8 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x000b03f8 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x000b03f8 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x000b03f8 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x000b03f8 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_GROUP_ICON 0x000b0860 0x00000076 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_GROUP_ICON 0x000b0860 0x00000076 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_GROUP_ICON 0x000b0860 0x00000076 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_GROUP_ICON 0x000b0860 0x00000076 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_GROUP_ICON 0x000b0860 0x00000076 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_VERSION 0x000b14d0 0x000001b0 LANG_MONGOLIAN SUBLANG_DEFAULT data

Imports

Library KERNEL32.dll:
0x493000 FindResourceA
0x493004 GetModuleHandleExA
0x49300c GetConsoleAliasA
0x493010 FlushViewOfFile
0x493014 GetModuleHandleW
0x493018 GetTickCount
0x49301c SetFileTime
0x493020 GlobalFindAtomA
0x493024 GetLocaleInfoW
0x49302c GetFileAttributesA
0x493030 HeapCreate
0x493034 GetFileAttributesW
0x49303c TerminateProcess
0x493040 ReadFile
0x493044 lstrcatA
0x493048 RaiseException
0x49304c GetConsoleOutputCP
0x493058 SetLastError
0x49305c GetProcAddress
0x493060 OpenWaitableTimerA
0x493064 GetAtomNameA
0x493068 GetProcessId
0x49306c OpenWaitableTimerW
0x493074 GetModuleHandleA
0x493078 LoadLibraryExA
0x49307c FindAtomW
0x493084 CompareStringW
0x493088 CompareStringA
0x49308c GetStartupInfoW
0x493090 GetCurrentProcess
0x49309c IsDebuggerPresent
0x4930a0 HeapAlloc
0x4930a4 Sleep
0x4930a8 ExitProcess
0x4930ac WriteFile
0x4930b0 GetStdHandle
0x4930b4 GetModuleFileNameA
0x4930b8 GetModuleFileNameW
0x4930c4 GetCommandLineW
0x4930c8 SetHandleCount
0x4930cc GetFileType
0x4930d0 GetStartupInfoA
0x4930d8 TlsGetValue
0x4930dc TlsAlloc
0x4930e0 TlsSetValue
0x4930e4 TlsFree
0x4930ec GetCurrentThreadId
0x4930f0 GetLastError
0x4930f8 GetCurrentThread
0x4930fc HeapDestroy
0x493100 VirtualFree
0x493104 HeapFree
0x49310c GetCurrentProcessId
0x493118 FatalAppExitA
0x493120 VirtualAlloc
0x493124 HeapReAlloc
0x49312c FreeLibrary
0x493130 InterlockedExchange
0x493134 LoadLibraryA
0x49313c GetCPInfo
0x493140 GetACP
0x493144 GetOEMCP
0x493148 IsValidCodePage
0x49314c RtlUnwind
0x493150 HeapSize
0x493154 GetLocaleInfoA
0x493158 WideCharToMultiByte
0x49315c GetTimeFormatA
0x493160 GetDateFormatA
0x493164 GetUserDefaultLCID
0x493168 EnumSystemLocalesA
0x49316c IsValidLocale
0x493170 GetStringTypeA
0x493174 MultiByteToWideChar
0x493178 GetStringTypeW
0x49317c LCMapStringA
0x493180 LCMapStringW
Library USER32.dll:
0x493190 GetDesktopWindow

!This program cannot be run in DOS mode.
`.data
.pecawab|
@.rsrc
@.reloc
jXh@OI
>=Yt1j
QQSVWh
j@j ^V
t$h\8I
_VVVVV
_VVVVV
0SSSSS
0SSSSS
0SSSSS
0WWWWW
AAFFf;
uQht:I
0A@@Ju
URPQQhxs@
u,VVWV
t VV9u
C PjPV
C$PjQV
C*PjTV
C+PjUV
C,PjVV
C-PjWV
C.PjRV
C/PjSV
.;1s(N
HHt4HHt
Ht\Ht,
teHtFHt&Hu
ty<%tA
PPPPPPPP
FVhXLI
PPPPPPPP
GWhXLI
t"SS9]
;t$,v-
UQPXY]Y[
^SSSSS
^SSSSS
>:u8FV
VVVVVQRSSj
^SSSSS
^SSSSS
0SSSSS
t+WWVPV
^SSSSS
^WWWWW
0SSSSS
8VVVVV
e4A![
H-I)'AS1|
oylvUwp^O2p$
!oY[>U|$C
d_3KOr$I
nu>~x~
8^*;_
yG ,:Hvat
6=z^9oym
Z(S#uV
;7S.w2
Q$Mj+B
?xhj[k
&K`Y&T
%u pu>@i
-Jp&d~T
nDZP^T
/5&kRS`,
H}IcylD
Pap#e!
o!9'$IV
Lq""<L
2n8YbJ
km8u/V
UOybCyi
bf=9.F
fukyWGF
C|q-6/
>Pa_I|
47Yd[j
h*-o,i
&w dl$
Wu?Bt?
tUt=aM!
lxR&^0-
[lcu}We
s=-$}f
jy!zfl
G-{*FD
b!o{GR
w.mHhpw
R-Vlrm
0:)6Y]
Yh9,dm
`/|(Wh
iynJzh
CDf)iJ
V,kN({H
f]/Mm$
c2okpAx
i5'N"l
mXnucq
.Xv^gc
YB!7&
XxEUrK
${I<nA
??<qx9
(.V;Q1?
?q"l1[
I8s:R1VQ
q"_))C
=DNtT
o)aG)6mm?
?*`t!
7Ym9aq
?Fk\{YF
9cLF'#
G']\q9E1+|
h \ulv
)vIDFH
eod#4K
Eg|!m>
Pl[Q:3*
d,xOh`
'u\k=L
sLJ8is
jZyNF
\Pz!yp~^^S
)*%@+*
H1w|Ye #
;r7dhY
q.A#\3
WqF4=[<
~TZj`r
zJ"Zsb
FL&wa1
6(JRhS
A[Md,Nv
sw&JQ<
[jY$sV
%QIrS*
gXJ>4gx
q\gG)-r
+2Mo@O:OU
4@UEIO
I.Ka%L.~
R)RznK
4CiP_IFN
c>@Q?J
sra|+o'
W8jU$qJ
;&lu!
PsJSR#=
wUr}M
"Y}J22:
;M!~l>
&/AXx92
|+{Vp+
^KtYJg
2>zSi=
hMQU~
H9nuxRn]o
P0a&i#xZ
#Zb{~Q
4O'@5&>
1,V~k@/
.e:ui[C
QlP#{Ja
M_u7YLM\
_>9;\
`3H]EV
.39${V
HshTF4
Zumb`|
1E0g{h4=-
pANuv<C
WKagX\
;{64$>L
>=+ln0
9/+\7c
qpjCE0a
.tG&EP
3AOP%,
Pg.Tz]_mo
{/GbS^
%*j
CVi<'+2
@?|-'J
3!/teJ
eX;jN8
4>&^f.bZ
l}(0h-
`WQ4G;
>F"X$Of
1@BL/L$
JAL"m1
JF8ir<
kD;#i3
n(%,ko
//vA/9W
A `OC>B
!#a362
VmO#Dhx
64Hu^=
g'D>='
fMAR!'
Z}qkri
Pc"i2P.]
5L0>/s
-T70H&Y
ok4Gdn
'3y"/k
-no]s^>
=rt&-&
OIO}`v
Z46!DG
bN|&w"}
3$GoBCzv
N2+>B
!JKili
( gi#/
_GwI*M
HqFzbX
!Z3K}x
3]^s_d(
oiHz!d
_3E:tCI
!/wV+<
0JMVma
u 8:C%
m:ZpmE
~Ar,El
tAIw~"
F:LKfD
=2Dp^
-1*Mk=>
0tj.<%^d#i
@[6.X0
AIBrDY
zfcGsoG
un\1PO
YQ5q4Y
c[xyGo
NiVC,/#
Y0?t1C
nY&lqs
..:tF&O
w7kPSw
[yH'4F*+
1`pI[D
2_HM3i
9ym6o7
zD#4?c<uI
Ym3zu;
~= Q/e(
ub1@YH
{`zm4i
~+$Rcg2
'cbo;50
iR!7l{
b"kSkw4
}c^1#]Q
b)O"}Bfy
B*?!V$
'N=q&~
R*`\Cl
.f%,S"
H=?Hlq
Sx{c;}r?
p)B]X=
r@/h1R
aB^_=UsL
ac lNy
*ayc]l
VP)-z;o.D
/]th|8Q%
yzB~w!
e"r4{+
3kby}V
``:TTS
SnJ43(
gw]"d
Er2,_W
]pd/~jp
IL_UuC
H%jKbE
f[#DdH
tGPQ{F
'xCsk+d
_rfV(H
'"&cdXLu
&5_b-3}"
#XNoI,C
5SaD00
o`K\%3
$Z-&;I
{a'hXm
ex^r=B
@=eUfEZ
t*qfe,b+U
/t-0Mv^
FZC5X'9
3D*)CT
l_X&0G61
N_T]42
=O3@|g
o_V;}W
VJpX\*
DM!E>of
j6$9Ik0
v3&c!(K
Z|/9RR
pul'J6
ezn4o;
1.[):7
6za~`ET
eR8~fqFy
47/!L8
yDAcDAAZ
jlOhe,
V]tt wO
*]h|E[7
@B Nr2
WXx/2g29p
wVD4#g
o:bou#
,hM%R2
[L]7dA?
rwc/kC
/J1eY=
Rs@RO|iI
gmN2B~
I%Qp_[
+aO#L4
u,NHVE!
jr9aKx
("+NQ/`
p1"+NT%2
0L/Y+ic
IImbcP
&kLLMd
.M7Fgc
iOPECdW
-`]$$*
plUz}h
+|y'`9
)KaB#2
6_&!b~
<*0fi3
]W&FGB
wB2^6l$
j;/.>)
q@HR3g}?
c'j"A(
GUlt8y
i k%dsEo
E*;X~F
1 G[q
1>V')g
qZX~b
7/l>B.
a*P#@U
x}%637
Qef*-x
V/@We?%
u)JP+[
^`K4*
X<8C`_
G }Phe
U=^Is6
g2)NB|
_+6M}^
KB OW`
`3,L:{1
5xS"os`
!]IZaw
[JT?5QNz
m j,f8UT
|.DrB8
Sd2P
?'EBgqan
Ef@.I]/sc
fR5|5m
H`v^6R
:M&mbr
{y; E_Hd
|6h++R
Fww/DW
fU(=wr=
SP}Jq/
GzvZTD
^N*(/-
3@;NNA
| x8.k
K[HjzF7s^m7
Z?lVKHS
q.eCq1
qjtUUR|
6(DN=CB
%Y;z[^
o]8kl9ZB
103*MA
8dH1%p
:`!\AWON0
q Fz&&
*$?CR,
x3`v00
;|*Ka(
%7CUi
Y[}B#Q2_
0mth'
~'mG.G:
r\7:0_
oL=wl!
H):`{s
g40MRcV
F"N!Ezc[
IHJdUOEs
mBAWQY
K~7O&w
/q,.BT
^&>[41
_025x9
T(aMa^
1iyBaX
+`v\gd
l`,k79
?0Qi^<
c\nuv`
42s[ h
s`Vtuj
y6AQ=<
#|od|T
zKOp[o
yOq=P
]2~SY
;G)lU00
8 Hq6xK
c:TLn#P
G'i7Fg
d:Uubs
_uanF(
^cc)c4
&_fq~:
}+l"{1n~I
f #*,tvw
'&-Q,D240
mc7j,
*OCu<m(
P6B9>a
0S9';X<
k{P[\1
5Cy[~Lc1
"oj/6a
'@CUxp
1YLDqS
M2?RC/
,:!M/k
W/8WF e_
pJyz<F
$;6qhZ
|.D Ig8
8ujd5+
^RKaT\
|"_o1
>Xb5%u
-8D)?N
gC'oDE@-b
_r\1_g
@3=)JR
@&+|v:
ixw`Ah
*XMgew
E^Ij<m
+ZGhA]d
JOp9yu
=pbjwb'
)%7A(R
H4Tm*j
_..<h^
X_E'p-
\Q;Sn{
g6GL)98
x!d#n^f
B z?)e
c#9Fc"$
<E+"sn
c}t!~
^'A)r
NFyzm/6
q$G~9h|w
A[Y: m
}0)ciR=Z
QE@Zb=#W
h/:3(vM9&e
sd!o45
'!CN2M
(gDs_'
>.nj]fja
w"{~cg
71LPI&M^[
yfO=HY
[QR'M~
U=n0J4
o4uRrgq
-DXrSK
LisT3z*f
O=hwCWUZ[[
a9C|;S
{VYK!V
1oAx>]
o_`n&$
lA}?~;F
7<=o4oT
eB").k
r_URqN
"3l|Js
7dkE^&u
Cau`cX
dnrIbq
,u3R.S
e4>JCS
$c&yaN
^&~(<;OB
\XWjf|
}rbPM.
`mK*mo
QHFb~UFf
7d;YDI
o>:B1N
jNpNEVD
)2ebUrP
/'m~=Z,]
mS%E;#
'$Y5na
X_jH6M
OP^DP%
X&o=h-+
GPNx3v
gp#qJ3
sY%JQg
;y,$QP
N$[$ijz
_\4Ff`G
?b]jBS
io_hU.
E_b;Uo`
x#>hhS
Oi|x(w
F(H$#lE
Mk2ou~
D-v9xW
Dm.0r~
lAs'V;
HZU6cU1z
8OKswdn
lJ)[ZK
8~ama)
N1Q".^o
(9$#aC~
gsGP0RE
^-gyWW%
S!cxV[iG
irF'&S~
oa@cH-
Zq+$3
pkhzM>
\rLrk<>
.](RD!
UoKF{(
YksF~r
wEl7m
U#2M:G
JAdjQj
q~6Q="
A>+jr`
Kr}zk=
K:JkH
rER?de
SxrjY"@
_*}mNo
[I>rdRd
tfct5K
D{bW"h$
MsAo"J
0cc'3_
-'I[}P
|$riS[
^DB+w<
_h78=h
Mb+_/RT
u66D+R
CEA`*+
w*M>q<
mwibhH
aRDNpK)
,|;ie(9{$
<qI".4
B$E)9^Bb0
iy)DL$
oJ9@g>
|%]\wASN
Z4,vTk
sPA9:cx
a>~<&!
AoDR33
LD=lg"
/)[z;
$N[ow*?
~IN4t:
MO%%'n
uj~#@[
n`Ee{n
SfEWgK
?tH`T_P
,_?(5S
iC}h~C
b\670#
Gq/fC'
iID*Z)
+CS4I:U*yw
*'Gg]X
=<oPbQY
V\M;fw
BpA>P'
=gGIZ"
yFLPK(
CN4bS'i
wHf?k%
F,y@|qn
q){5XM
WRWQj'
*1A_j<
_b}Rum
2uin)AW
.oD:V2F&*p
!dK- e
vkU^nZg
d{%4=`7l~U%
ayi/3RP
Lj;-}
)JaeQ^s
|csxpV
B2+[1|u]
=76Tz(
T[)]/D
2=#zM'
-kes<V6Qck
]MG%Uq
T3jgRD>
0gU5n=e
%mjYf|G
"8mT:Qi
D--B=q
o"c"G+
vW>55p'J
oO\Ben
)BN?1`
-t$ 4c.
Vl1Ld^a[4
7YwCD
W==%Jl
:@8;z(
Nzm`r(5
ov&y9
Lj_$oiv
_muX(%
#Vt-:sM
BiBBeD
v[Io"r
Uu`}DdL
#oJg*9
md/E,7
dOoaQ7
p\XYY2w
:s7Kq-#^
Kq[##6
;%7HxiQ3
^/&?yK
dtz:#\
n:LTIN pX
@y=L`1!T\tJ
1}?~Gr
Tt3@YP
+)tL;-`
|tG=B)
MD-Q0c
I('+v|
c{{n+B
lUW=K3
'S);aP?7
~]`Oo
)QjP*$J)
Nrv{2k
eFKisw
-q\(g*
P*NU-z9
Br|v@}
P&a@-M
}zD;z2
?(/k7e
d-7a8b
6fYeSo
}V[}t!
Z"SjI$
%qB)BF
~#}QMe
/Qq(M"}
D}.*Wy
Uk7A^O
d'Au>)
xD8<nJES
lx2Xd>
G,=)KU
~-^0a
HL .'-
0?+y3K
(xXQjz
0.<XW:
?@qWOY@>
@vM7bv
tm"auz
n6VZBm
EU8R=qle
olc0'#
@.a"W;
*`w}^8m
$e;*_bb[
-X\_`1
ti7>Q^g`i?d
d]q+M
;^$ijO[
u5gF.
v&)(;Hu
$1rvn2
wCZ?n)
H.|K0|
$ h`LI
_VVVVV
^WWWWW
tNIt?It0It
0SSSSS
_VVVVV
<+t(<-t$:
+t HHt
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
CorExitProcess
runtime error
TLOSS error
SING error
DOMAIN error
An application has made an attempt to load the C runtime library incorrectly.
Please contact the application's support team for more information.
- Attempt to use MSIL code from this assembly during native code initialization
This indicates a bug in your application. It is most likely the result of calling an MSIL-compiled (/clr) function from a native constructor or from DllMain.
- not enough space for locale information
- Attempt to initialize the CRT more than once.
This indicates a bug in your application.
- CRT not initialized
- unable to initialize heap
- not enough space for lowio initialization
- not enough space for stdio initialization
- pure virtual function call
- not enough space for _onexit/atexit table
- unable to open console device
- unexpected heap error
- unexpected multithread lock error
- not enough space for thread data
This application has requested the Runtime to terminate it in an unusual way.
Please contact the application's support team for more information.
- not enough space for environment
- not enough space for arguments
- floating point support not loaded
Microsoft Visual C++ Runtime Library
<program name unknown>
Runtime Error!
Program:
EncodePointer
DecodePointer
FlsFree
FlsSetValue
FlsGetValue
FlsAlloc
SystemFunction036
ADVAPI32.DLL
GetProcessWindowStation
GetUserObjectInformationA
GetLastActivePopup
GetActiveWindow
MessageBoxA
USER32.DLL
LC_TIME
LC_NUMERIC
LC_MONETARY
LC_CTYPE
LC_COLLATE
LC_ALL
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
HH:mm:ss
dddd, MMMM dd, yyyy
MM/dd/yy
December
November
October
September
August
February
January
Saturday
Friday
Thursday
Wednesday
Tuesday
Monday
Sunday
united-states
united-kingdom
trinidad & tobago
south-korea
south-africa
south korea
south africa
slovak
puerto-rico
pr-china
pr china
new-zealand
hong-kong
holland
great britain
england
britain
america
swedish-finland
spanish-venezuela
spanish-uruguay
spanish-puerto rico
spanish-peru
spanish-paraguay
spanish-panama
spanish-nicaragua
spanish-modern
spanish-mexican
spanish-honduras
spanish-guatemala
spanish-el salvador
spanish-ecuador
spanish-dominican republic
spanish-costa rica
spanish-colombia
spanish-chile
spanish-bolivia
spanish-argentina
portuguese-brazilian
norwegian-nynorsk
norwegian-bokmal
norwegian
italian-swiss
irish-english
german-swiss
german-luxembourg
german-lichtenstein
german-austrian
french-swiss
french-luxembourg
french-canadian
french-belgian
english-usa
english-us
english-uk
english-trinidad y tobago
english-south africa
english-nz
english-jamaica
english-ire
english-caribbean
english-can
english-belize
english-aus
english-american
dutch-belgian
chinese-traditional
chinese-singapore
chinese-simplified
chinese-hongkong
chinese
canadian
belgian
australian
american-english
american english
american
Norwegian-Nynorsk
SunMonTueWedThuFriSat
JanFebMarAprMayJunJulAugSepOctNovDec
bad allocation
kernel32.dll
VirtualProtect
GlobalAlloc
GAIsProcessorFeaturePresent
KERNEL32
_nextafter
_hypot
1#QNAN
1#SNAN
FindResourceA
GetModuleHandleExA
SystemTimeToTzSpecificLocalTime
GetConsoleAliasA
FlushViewOfFile
GetModuleHandleW
GetTickCount
SetFileTime
GlobalFindAtomA
GetLocaleInfoW
GetSystemTimeAdjustment
GetFileAttributesA
HeapCreate
GetFileAttributesW
SetTimeZoneInformation
TerminateProcess
ReadFile
lstrcatA
RaiseException
GetConsoleOutputCP
FreeLibraryAndExitThread
ChangeTimerQueueTimer
SetLastError
GetProcAddress
OpenWaitableTimerA
GetAtomNameA
GetProcessId
OpenWaitableTimerW
SetConsoleCursorInfo
GetModuleHandleA
LoadLibraryExA
FindAtomW
LocalFileTimeToFileTime
KERNEL32.dll
GetDesktopWindow
USER32.dll
GetStartupInfoW
GetCurrentProcess
UnhandledExceptionFilter
SetUnhandledExceptionFilter
IsDebuggerPresent
HeapAlloc
ExitProcess
WriteFile
GetStdHandle
GetModuleFileNameA
GetModuleFileNameW
FreeEnvironmentStringsW
GetEnvironmentStringsW
GetCommandLineW
SetHandleCount
GetFileType
GetStartupInfoA
DeleteCriticalSection
TlsGetValue
TlsAlloc
TlsSetValue
TlsFree
InterlockedIncrement
GetCurrentThreadId
GetLastError
InterlockedDecrement
GetCurrentThread
HeapDestroy
VirtualFree
HeapFree
QueryPerformanceCounter
GetCurrentProcessId
GetSystemTimeAsFileTime
LeaveCriticalSection
FatalAppExitA
EnterCriticalSection
VirtualAlloc
HeapReAlloc
SetConsoleCtrlHandler
FreeLibrary
InterlockedExchange
LoadLibraryA
InitializeCriticalSectionAndSpinCount
GetCPInfo
GetACP
GetOEMCP
IsValidCodePage
RtlUnwind
HeapSize
GetLocaleInfoA
WideCharToMultiByte
GetTimeFormatA
GetDateFormatA
GetUserDefaultLCID
EnumSystemLocalesA
IsValidLocale
GetStringTypeA
MultiByteToWideChar
GetStringTypeW
LCMapStringA
LCMapStringW
GetTimeZoneInformation
CompareStringA
CompareStringW
SetEnvironmentVariableA
-ANOOOONA-
#<OQSSSQQQQQQQPN8
%MPPQPQPPPPPPPOPOOOOC#
@NPOPOOOOOOONONNNNNNMMC@
"BLNLLNLNMLMKKMAMMAMCACAAB@"
$AKAKAKAAAAAAAAAAA@A@@@@@@???$
"?AAA@A8@AAA@A@@@@@@@@??4?4??4?
49?499?@@@8@A@A@A8A@@@@@@?444444
.44344@@<A<AA<A<A<A<A<A<A8@@43443.
33344<<A==A<=<=<A<A<A=<A<A=<A93343
+3339<A>=====A=A====A==========9323+
2324=>>>>=>>>>>>>>>>>>>>>>>=>>=K;222
222=E>F>>F>F>F>>F>>F>>>F>>>F>>>>>222
11:FFFFFFFFFFFFFFFFFFFFFFFFFFFFFF:11
1,>DDDDGFDGFDGDGFDGDGDGFDGDGDGDDF>+1
,+GGGGGGGGDGGGGGGGGGGGDGGGGGGGGGGG1,
,2GHDIGIDIIIGIGHHHDIDIGIGIGIGGIIDI3,
)/IJIIIIIIIIIIIIIJIIIIIIIIIIIIIIIH/)
*JJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJR*
)FRJRRJRRJRRJRRJRRRRJRRJRRJRRRRRD*
0RTRTRTRTRTRTRTRTRTRTRTRTRTRTRR0
DTTTTTTTTTTTTTTTTTTTTTTTTTTTTD
&RUTUTUTTTUTUTTTUTTUTTUTTUTUR'
'TUUUUUUUUUUUUUUUUUUUUUUUUT'
!JVVVVVVVVVVVVVVVVVVVVVVJ!
7UWWWWWWWWWWWWWWWWWWU7
6TXXXXXXXXXXXXXXT7
5HTYYYYYYTH5
+>OOOOA+
(=OPPPPPOPON<%
AONNONNNMMMMMEEC
$<MAEAEAFAFCCCDDDD3$
#;DDDDDDD9CD<DDD3;;;;#
/;;39<C<CC<CCC<CC9;;;/
&4;3@C@C@@@C@@<C@@A<;44&
003@@=@=@@=@@AA@@@AA@320
12==H==H==H=H==H=H====20
1:HHHHHHHHHHHHHHHHHHJH:1
.<JJJJJJJJJJJJJJJJJJJJ@.
.=KKKKKKKKKKKKKKKKKKKKB)
?LLLLLLLLLLLLLLLLLLLL?
-QQQQQQQQQQQQQQQQQQQQ-
GRRRRRRRRRRRRRRRRRRG
JSSSSSSSSSSSSSSSSJ
6STTTTTTTTTTTTR6
"ITVVVVVVVVUI"
'578875'
45566663
3444433232-+
++++++++&&&***
""*&+&+&&+&&&*""
!%('('(('((-''%!
"))))))))))()))%
(.././././.../.(
0000000000000000
1111111111111111
.77777777777777.
88889999998888
:<<;;;;;<;<:
$<======<$
xxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
<<<<<O^
mmmII0I00k.
cAzzCCUU
ttttttttt
OVVVVVVVVVVVVVV
DDDDDDDDD
NNNWEEEEEE7NN
%%%%777WW77%%%
`4QQQQQQQQQQQQQQQQQQQ
PPPPPPP
xxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
--------------/
,,nnnn\a
uuodffddY
oodybbbbU
^^^^^^
99999&99999999
LVV"vI
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAA`
C`AAAAAAAA
AAAAAAAA`
AAAAAAAA
`AAAAAAAA9
`AAAAAAAA9
`AAAAAAAAX
9AAAAAAAA
H@@@@@@@@@q
f`AAAAAAAAX5ss;;}}}};;ss
9AAAAAAAA
!!!!!!!!kk
9AAAAAAAA
LLLLL
AAAAAAAAA
AAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAA
AAAAAA
AAAAAAAAAA
AAAAAA
AAAAAAAAAA
hAAAAAA
AAAAAAAAAAA
RAAAAAAAAAAAA
AAAAAAAAAAAAAh,tt
AAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
**********************vT
******Oe
******
******
******
******
******
******
*******IH**************i-****'
********<
********0wH**H
********'
'**********
)*******************
hhe@N[w
jqsFghh
fff@ffg
fehCdee
hfgAfgg
ox{Hhmh
tzvIhji
hrpFgih
vwsJili
dff1fih
feepfeh
mvw|hol
ionUekl
oolxmlh
edeSeff
":========:"
:=:2.%%%%%"+27=:
''''%%%"%%"%%2=:
'+%''%%%%%%%2="
+%'+%'%%%%%%#%+:2
"+'+%'''%%%%%%#"%:2
++'+'+'''%%%%%#%%:2
%+++'+'''''%%%%%"%;"
++++'++'+''%%%%%%+=
.+++++'+'+'''%%%%%3:
.+++++++'+'''''%%'=
....+++++'++'+''''3:
..++++'++'+'''+=
"=3722(
+.+.++'+'+''':"
::337272."
.+.++.++'++'3:
=8772727222"
..+.++++'++/=
=773737272332
//.+.+++.+'+=
=77777373733
///...+++.+=
=77777737377
/////...+++=
=:8777777737
///////...+=
=:8:77777773"
22///////..=
=::8:88777777
/2/2//////=
=;::::8877777
+/2////3=
:=:::::::88778
%/2/27:
"=:;:::8::8:888
=;;;;:::::888888"
:==:;;;::8::::8:87777.
==;=:;;;;:::8:8888777"
:==;=;;;;:;::::8:8877(
===;=;=:;;:;:::88:787
"====;=;=;;;:;:::::88(
2=====;=;;;;;:;:8:::4
2=======;=;;;;;;::::&
0=====;===;=;;;;:::2
"======;==;=;;;;:::& 8&
:=======;=;=;;;;:22;
:========;=====:
":========:"
'++'
$$$$!$!!
&$$$$!!!!
)$&$$$!!!!
$&$$$$$!!$0
$&&$$$$!,
---,+)
&&&&$$$)
'20---,,)
$)&&&$$$'
+-2-0---
)&&&&&$+
+220000-
))))&&&,
'222000-,
$))&()&'
2222202-
62222220+
6644222220,
$6626242220000'
2662624222220-
6666462622220'
266626262222-
666666262422"
26666666262-"%
'6666666464
'++'
!*
$'
****'
!$!!
!,***'
$$$!$
!..***
$$$$!
....*-
0....-!
000....,!
0000.....*
.00000....%
0000000..-
.0000000.!
00000000
)))(((
))))((
dddPddd
ddd@ddd
ddd@ddd
ddd0ddd
dddPddd
dddPddd
ddd0ddd
ddd@ddd
ddd@ddd
dddPddd
ddd`ddd ddd ddd`ddd
ddd`ddd
ddd ddd
ddd ddd
ddd`ddd
ddd`ddd ddd ddd`ddd
dddPddd
ddd@ddd
ddd@ddd
ddd0ddd
dddPddd
dddPddd
ddd0ddd
ddd@ddd
ddd@ddd
dddPddd
RRR@RRR
RRR@bbb
RRR@kkk
RRR@RRR
"""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""
7""""""""""""""""""""""""""""""""""""""""""""""
""""""""""""""""""""""""""""""""""""""""""""""
"""""""""""""""""""""""""""""""""""""""""""""
""""""""""""""""""""""""""""""""""""""""""""
"""""""""""""""""""""""""""""""""""""""""""
""""""""""""""""""""""""""""""""""""""""""
"""""""""""""""""""""""""""""""""""""""""
7"""""""""""""""""""""""z
""""""""""""""""""""""
""""""""""""""""""""""
___WWW
"""""""""""""""""""""
""""""""""""""""""""
z"""""""""""""""""""
""""""""""""""""""
7"""""""""""""""""
7""""""""""""""""
""""""""""""""""
"""""""""""""""
""""""""""""""
"""""""""""""
lllggg/gLLk
""""""""""""
lllsgggg/LLLL
""""""""""""
lllsgggggLLLL
"""""""""""""
sllggggLLLLL
""""""""""""""
llllggg//LLLL
"""""""""""""""
llgggggLLLLvv
""""""""""""""""
?llsggggLLL
7""""""""""""""""
?sggg//LLLL
7"""""""""""""""""
?gg/LLL
""""""""""""""""""
z"""""""""""""""""""
""""""""""""""""""""
"""""""""""""""""""""
""""""""""""""""""""""z
"""""""""""""""""""""""""""""""""""""""
7""""""""""""""""""""""""""""""""""""""""
"""""""""""""""""""""""""""""""""""""""""
""""""""""""""""""""""""""""""""""""""""""
"""""""""""""""""""""""""""""""""""""""""""
""""""""""""""""""""""""""""""""""""""""""""
"""""""""""""""""""""""""""""""""""""""""""""
""""""""""""""""""""""""""""""""""""""""""""""
7"""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""
}3333333333
UuL..Q
)nnn))P+
UUUUUUuU"
}3333333333
oooooooooooooooooooooooooooooooooooooooooooooooooooooooooIoooooooooooooooooooooooI
ooooooooooooooooooooooI
<oooooooooooooIIIIIIIII
ooooooooooooI
oooooooooooI
IooooooooooI
dd>"""
,IoooooooooI7
ZfzooooooooI
oooooooIO
uuY7mIooooooIO0""
)mIooooooIO
oooooooIO
sfzoooooooo
Z,IoooooooooIOOOOOOOOO
IooooooooooI
oooooooooooIIIIIIII
<ooooooooooooooooooooI
oooooooooooooooooooooI
ooooooooooooooooooooooIoooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooo
NNhhNnd
Hutizu wanabi fehufepoyeni. Hapi xayibelizu nerazijiwomusus. Nozejoyujavosi tesasiki. Yepefukusifave hayojumawe jatubuwo yofofuga debujoz. Fabugayiposeva lon hicahozupiwoya yabexesitoroj. Coxukakuhiliwod yixufumufuy. Xuriwiza jugefofacakec vocobom joyalejugeveko monerucinirafax. Yifiruhenenasug. Rosojivelezoyac vokigucu lodedetuz tugepirof. Lomiva vedekagucoh hozemefuz vav. Cavi defisizatun kasuvoy. Rivopoyerugonoh xipixoyob poy. Donocavufogab yofe tojahico taxiterex dobi. Zusu lubomecimidu kaluhujegorenu. Paxitisa lobupemayawi. Tobocopecayema begakirexowu viwadilezuw. Wujanekisa miyovurif vexemedebazoc. Gubafo. Poyijerajez. Yiwecu nunus pimorukewe bocetabof suru. Yavudat jitupunolufad joyu. Homezivodason cuhaf. Mimihaba. Xiforecemihuhuz wucaguwilapuyod senize tubokimufa zib. Hibotay pebuyiwav duvo sus sebuwonahahuci. Gukuwipin guvilikunepidet bakefage. Suvawoguzeyucuz yob xuh. Jefurecekena himacagi kehatuyed. Dure. Hibimabu zeduk voh wusavi xepuzopiligecu. Pivevapit buzavotim pesayanohuhusus baya buv. Puv do
&0,02080>0D0J0P0V0\0b0h0n0t0z0
0F1p1w1}1
2B3H3N3T3Z3`3g3n3u3|3
4/464I4e4
5!6'636
747:7C7J7l7
7-8C8K8^8i8n8~8
;>;G;N;W;
<!<9<K<a<t<
?R?]?g?x?
20262h2
3'4-4Q4o4
5%5:5A5U5\5
6!6-6<6B6W6h6t6
9T9d9j9v9|9
:#:*:/:7:@:L:Q:V:\:`:f:k:q:v:
;;;;o;t;
>%>H>U>a>i>q>}>
1$121E1X1|1
212A2V2l2
2<3G3V3
4$4*4<4A4
7#7(717N7T7_7d7l7r7|7
<#<:<@<E<T<]<j<u<
0P0V0}0
1a143?3G3\3
7&818H8
9#9+9C9K9c9k9
93:8:}:
;!<(<9<q<y<
=%>8>G>P>e>
??.?4?B?K?Z?_?i?w?
M2T2Z2
314:4F4
6!6(6,6064686<6@6D6
7,73787<7@7a7
7*8084888<8
:R;i;z;
;;<G<P<Y<e<q<}<
0060S0X0
=3>;>P>[>
232O2X2^2g2l2{2
6?6X6_6g6l6p6t6
7N7T7X7\7`7
8!8K8}8
9C:P:e:w:
2%22292
3!4'4D4J4j4
5(6.6R6u6
5{7C8U8_8i8
9C;W;m;~;
0!0p0y0
2M2\2(8
8"8&8*8.82868
:>>>B>F>J>N>R>V>Z>^>b>f>j>n>r>v>z>~>
2$2/2_2
849l9r9x9~9
9D:M:S:X:p:
;';/;>;E;R;r;|;
>D>M>q>w>}>
>1?9?E?R?Y?a?i?q?z?
2N7?:\:
5C5V5/868k8~8
<:<C<O<Y<e<p<
2J2V2e2q2
6"6(6.646:6@6F6L6R6X6^6d6j6p6v6|6
7$7*70767<7B7H7N7T7Z7`7f7
!=&=1=7=<=C=I=Q=X=
>2>?>I>Z>x>
?I?O?U?d?l?{?
0*040>0N0T0d0l0
1)252h2n2t2
3%3?3E3K3S3
4'5A5J5R5
1$1C1T1Z1
3(3C3J3S3\3e3n3w3
4!464;4R4
?+?A?I?
6<6U6b6p6
387<7@7D7H7L7P7T7X7\7`7d7q7=8
909?9k9
2$2,242<2
3X4h4x4
: :$:(:,:0:4:8:<:@:D:H:L:P:T:X:\:`:d:h:l:p:t:x:|:
8$8,848<8D8L8T8\8d8l8t8|8
9 9(90989@9H9P9X9`9h9p9x9
: :(:0:8:@:H:P:X:`:h:p:x:
; ;(;0;8;@;H;P;X;`;h;p;x;
?T?X?`?d?
000L0P0l0p0
1,101P1p1
282T2X2x2
383X3x3
mscoree.dll
KERNEL32.DLL
((((( H
h(((( H
H
kernel32.dll
POFOLAZIVUVUMIMUPIRIC
/ P6pL
,/KPip
/-P?pR
/ P6pL
,/KPip
/-P?pR
/ P6pL
,/KPip
/-P?pR
/ P6pL
,/KPip
/-P?pR
VS_VERSION_INFO
StringFileInfo
040904E4
FileVers
7.0.2.54
ProductVers
7.0.21.21
InternalNames
galimatimat
LegalCopyrighd
Jdfgl sfd
VarFileInfo
Translations
Antivirus Signature
Bkav W32.AIDetect.malware1
Elastic malicious (high confidence)
MicroWorld-eScan Trojan.GenericKD.46245600
CMC Clean
CAT-QuickHeal Clean
McAfee Packed-GBF!870B1EBD3A6F
Cylance Unsafe
Zillya Clean
AegisLab Trojan.Multi.Generic.4!c
Sangfor Trojan.Win32.Save.a
CrowdStrike win/malicious_confidence_100% (W)
BitDefender Trojan.GenericKD.46245600
K7GW Riskware ( 0040eff71 )
K7AntiVirus Riskware ( 0040eff71 )
Baidu Clean
Cyren Clean
Symantec ML.Attribute.HighConfidence
ESET-NOD32 a variant of Win32/Kryptik.HKSB
APEX Malicious
Avast Win32:PWSX-gen [Trj]
ClamAV Clean
Kaspersky HEUR:Trojan.Win32.Chapak.gen
Alibaba Clean
NANO-Antivirus Clean
ViRobot Clean
Rising Trojan.Kryptik!8.8 (CLOUD)
Ad-Aware Trojan.GenericKD.46245600
TACHYON Clean
Sophos Mal/Generic-S
Comodo Clean
F-Secure Clean
DrWeb Clean
VIPRE Clean
TrendMicro Clean
McAfee-GW-Edition BehavesLike.Win32.Lockbit.jc
FireEye Generic.mg.870b1ebd3a6f7418
Emsisoft Clean
SentinelOne Static AI - Malicious PE
GData Win32.Trojan-Stealer.PSWSteal.SNH2OW
Jiangmin Clean
eGambit Unsafe.AI_Score_99%
Avira Clean
Antiy-AVL Clean
Kingsoft Clean
Gridinsoft Clean
Arcabit Trojan.Generic.D2C1A6E0
SUPERAntiSpyware Clean
ZoneAlarm HEUR:Trojan.Win32.Chapak.gen
Microsoft Trojan:Win32/Azorult.FW!MTB
Cynet Malicious (score: 100)
AhnLab-V3 Trojan/Win.Glupteba.R418996
Acronis suspicious
BitDefenderTheta Gen:NN.ZexaF.34688.NCW@a4mnbIpO
ALYac Clean
MAX Clean
VBA32 Clean
Malwarebytes Trojan.MalPack.GS
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Tencent Clean
Yandex Clean
Ikarus Win32.Outbreak
MaxSecure Clean
Fortinet W32/Kryptik.HKRT!tr
Webroot W32.Malware.Gen
AVG Win32:PWSX-gen [Trj]
Cybereason malicious.8ab194
Paloalto generic.ml
Qihoo-360 Clean
No IRMA results available.