Static | ZeroBOX

PE Compile Time

2020-07-27 16:52:33

PE Imphash

794d44b735ee50031372522aab4383b2

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x00027979 0x00027a00 6.69421419545
.rdata 0x00029000 0x0000e610 0x0000e800 7.48626579995
.data 0x00038000 0x0001d68c 0x0000a200 0.67773721078
.yon 0x00056000 0x00000241 0x00000400 0.0
.rsrc 0x00057000 0x00009bc0 0x00009c00 5.50355132357

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x0005d788 0x00000468 LANG_SINDHI SUBLANG_SYS_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x0005d788 0x00000468 LANG_SINDHI SUBLANG_SYS_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x0005d788 0x00000468 LANG_SINDHI SUBLANG_SYS_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x0005d788 0x00000468 LANG_SINDHI SUBLANG_SYS_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x0005d788 0x00000468 LANG_SINDHI SUBLANG_SYS_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x0005d788 0x00000468 LANG_SINDHI SUBLANG_SYS_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x0005d788 0x00000468 LANG_SINDHI SUBLANG_SYS_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x0005d788 0x00000468 LANG_SINDHI SUBLANG_SYS_DEFAULT GLS_BINARY_LSB_FIRST
RT_STRING 0x00060530 0x0000068a LANG_SINDHI SUBLANG_SYS_DEFAULT data
RT_STRING 0x00060530 0x0000068a LANG_SINDHI SUBLANG_SYS_DEFAULT data
RT_STRING 0x00060530 0x0000068a LANG_SINDHI SUBLANG_SYS_DEFAULT data
RT_STRING 0x00060530 0x0000068a LANG_SINDHI SUBLANG_SYS_DEFAULT data
RT_STRING 0x00060530 0x0000068a LANG_SINDHI SUBLANG_SYS_DEFAULT data
RT_STRING 0x00060530 0x0000068a LANG_SINDHI SUBLANG_SYS_DEFAULT data
RT_STRING 0x00060530 0x0000068a LANG_SINDHI SUBLANG_SYS_DEFAULT data
RT_STRING 0x00060530 0x0000068a LANG_SINDHI SUBLANG_SYS_DEFAULT data
RT_STRING 0x00060530 0x0000068a LANG_SINDHI SUBLANG_SYS_DEFAULT data
RT_STRING 0x00060530 0x0000068a LANG_SINDHI SUBLANG_SYS_DEFAULT data
RT_GROUP_ICON 0x0005dbf0 0x00000076 LANG_SINDHI SUBLANG_SYS_DEFAULT data
RT_VERSION 0x0005dc68 0x000001b0 LANG_SINDHI SUBLANG_SYS_DEFAULT data

Imports

Library KERNEL32.dll:
0x4029018 FreeLibrary
0x4029024 InterlockedIncrement
0x4029028 SetMailslotInfo
0x4029030 InitializeSListHead
0x4029034 CancelWaitableTimer
0x4029038 GetTimeFormatA
0x402903c LockFile
0x4029040 ConnectNamedPipe
0x4029044 GetTickCount
0x402904c WriteFile
0x4029054 GetSystemPowerStatus
0x402905c HeapDestroy
0x4029060 GetFileAttributesA
0x4029064 GetConsoleAliasW
0x4029068 GetAtomNameW
0x402906c IsDBCSLeadByte
0x4029070 GetModuleFileNameW
0x4029074 SetLocalTime
0x4029078 CreateJobObjectA
0x402907c LCMapStringA
0x4029080 GetConsoleOutputCP
0x4029084 CreateDirectoryA
0x4029088 GetCurrentDirectoryW
0x402908c GetProcAddress
0x4029090 GetProcessHeaps
0x4029094 HeapUnlock
0x4029098 SetFileAttributesA
0x402909c LoadLibraryA
0x40290a0 LocalAlloc
0x40290a8 VirtualLock
0x40290ac FindAtomA
0x40290b0 GetTapeParameters
0x40290b4 GetModuleHandleA
0x40290b8 EraseTape
0x40290c8 CompareStringW
0x40290cc CompareStringA
0x40290d0 WriteConsoleW
0x40290d4 EnumDateFormatsExW
0x40290dc SetFilePointer
0x40290e0 HeapCompact
0x40290e4 GlobalUnlock
0x40290e8 ExitProcess
0x40290ec TerminateProcess
0x40290f0 GetCurrentProcess
0x40290f8 IsDebuggerPresent
0x40290fc GetCommandLineA
0x4029100 GetStartupInfoA
0x4029104 RaiseException
0x4029108 RtlUnwind
0x402910c HeapAlloc
0x4029110 GetLastError
0x4029114 HeapFree
0x4029118 GetModuleHandleW
0x402911c TlsGetValue
0x4029120 TlsAlloc
0x4029124 TlsSetValue
0x4029128 TlsFree
0x402912c SetLastError
0x4029130 GetCurrentThreadId
0x4029134 InterlockedDecrement
0x4029138 GetCurrentThread
0x402913c EnterCriticalSection
0x4029140 LeaveCriticalSection
0x4029144 Sleep
0x4029148 GetStdHandle
0x402914c GetModuleFileNameA
0x4029154 GetEnvironmentStrings
0x4029158 WideCharToMultiByte
0x4029160 SetHandleCount
0x4029164 GetFileType
0x4029168 DeleteCriticalSection
0x402916c HeapCreate
0x4029170 VirtualFree
0x4029178 GetCurrentProcessId
0x4029180 FatalAppExitA
0x4029184 VirtualAlloc
0x4029188 HeapReAlloc
0x402918c GetCPInfo
0x4029190 GetACP
0x4029194 GetOEMCP
0x4029198 IsValidCodePage
0x402919c CloseHandle
0x40291a0 CreateFileA
0x40291a8 HeapSize
0x40291ac SetConsoleCtrlHandler
0x40291b0 InterlockedExchange
0x40291b4 GetDateFormatA
0x40291b8 GetUserDefaultLCID
0x40291bc GetLocaleInfoA
0x40291c0 EnumSystemLocalesA
0x40291c4 IsValidLocale
0x40291c8 GetStringTypeA
0x40291cc MultiByteToWideChar
0x40291d0 GetStringTypeW
0x40291d4 LCMapStringW
0x40291d8 GetConsoleCP
0x40291dc GetConsoleMode
0x40291e0 FlushFileBuffers
0x40291e4 SetStdHandle
0x40291e8 SetEndOfFile
0x40291ec GetProcessHeap
0x40291f0 ReadFile
0x40291f4 GetLocaleInfoW
0x40291fc WriteConsoleA
Library USER32.dll:
0x4029208 GetDesktopWindow
Library ADVAPI32.dll:
0x4029000 BackupEventLogA
0x4029004 AbortSystemShutdownA
0x4029008 AddAccessDeniedAce
0x402900c EqualPrefixSid
0x4029010 GetLengthSid

Exports

Ordinal Address Name
1 0x4027ea0 Albus
2 0x4027eb0 Coffe
3 0x4027ed0 Super
4 0x4027ec0 SuspendYourMind
!This program cannot be run in DOS mode.
`.rdata
@.data
D$$QRP
tgSUVW
0WWWWW
_VVVVV
0WWWWW
QQSVWd
0SSSSS
uL9=T(
HHtXHHt
>If90t
<at9<rt,<wt
URPQQh
tNIt?It0It
>=Yt1j
j@j ^V
HtHu4j
s[S;7|G;w
tR99u2
0A@@Ju
^SSSSS
j"^SSSSS
HHtYHHt
tM<it-<ot)<ut%<xt!<Xt
<dty<itu<otq<utm<xti<Xte
HIf98t
tGHt.Ht&
^SSSSS
8VVVVV
;t$,v-
UQPXY]Y[
HHt*HHt
<0|<9
tK<_t<<$t8<<t4<>t0<-t,<a|
<z~$<A|
<0|O<9
tU<A|B<P
tY<@tO<Zt
t\<@tXj'
NtFNt#NuV
t.<@t5V
TtUHtKHtAHt
0t-HHt
AtIHt0Hu
_VVVVV
_VVVVV
0SSSSS
0SSSSS
C PjPV
C$PjQV
C*PjTV
C+PjUV
C,PjVV
C-PjWV
C.PjRV
C/PjSV
.;1s(N
HHt4HHt
Ht\Ht,
teHtFHt&Hu
ty<%tA
PPPPPPPP
PPPPPPPP
t"SS9]
0WWWWW
_VVVVV
^WWWWW
u,VVWV
t VV9u
^SSSSS
^SSSSS
>:u8FV
VVVVVQRSSj
^SSSSS
^SSSSS
0SSSSS
t+WWVPV
0SSSSS
_VVVVV
^SSSSS
^WWWWW
0SSSSS
8VVVVV
<+t(<-t$:
+t HHt
string too long
invalid string position
invalid string argument
Unknown exception
EncodePointer
DecodePointer
FlsFree
FlsSetValue
FlsGetValue
FlsAlloc
(null)
`h````
xpxxxx
UTF-16LE
UNICODE
CorExitProcess
runtime error
TLOSS error
SING error
DOMAIN error
An application has made an attempt to load the C runtime library incorrectly.
Please contact the application's support team for more information.
- Attempt to use MSIL code from this assembly during native code initialization
This indicates a bug in your application. It is most likely the result of calling an MSIL-compiled (/clr) function from a native constructor or from DllMain.
- not enough space for locale information
- Attempt to initialize the CRT more than once.
This indicates a bug in your application.
- CRT not initialized
- unable to initialize heap
- not enough space for lowio initialization
- not enough space for stdio initialization
- pure virtual function call
- not enough space for _onexit/atexit table
- unable to open console device
- unexpected heap error
- unexpected multithread lock error
- not enough space for thread data
This application has requested the Runtime to terminate it in an unusual way.
Please contact the application's support team for more information.
- not enough space for environment
- not enough space for arguments
- floating point support not loaded
Microsoft Visual C++ Runtime Library
<program name unknown>
Runtime Error!
Program:
bad exception
LC_TIME
LC_NUMERIC
LC_MONETARY
LC_CTYPE
LC_COLLATE
LC_ALL
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
`h`hhh
xppwpp
_nextafter
_hypot
Complete Object Locator'
Class Hierarchy Descriptor'
Base Class Array'
Base Class Descriptor at (
Type Descriptor'
`local static thread guard'
`managed vector copy constructor iterator'
`vector vbase copy constructor iterator'
`vector copy constructor iterator'
`dynamic atexit destructor for '
`dynamic initializer for '
`eh vector vbase copy constructor iterator'
`eh vector copy constructor iterator'
`managed vector destructor iterator'
`managed vector constructor iterator'
`placement delete[] closure'
`placement delete closure'
`omni callsig'
delete[]
new[]
`local vftable constructor closure'
`local vftable'
`udt returning'
`copy constructor closure'
`eh vector vbase constructor iterator'
`eh vector destructor iterator'
`eh vector constructor iterator'
`virtual displacement map'
`vector vbase constructor iterator'
`vector destructor iterator'
`vector constructor iterator'
`scalar deleting destructor'
`default constructor closure'
`vector deleting destructor'
`vbase destructor'
`string'
`local static guard'
`typeof'
`vcall'
`vbtable'
`vftable'
operator
delete
__unaligned
__restrict
__ptr64
__clrcall
__fastcall
__thiscall
__stdcall
__pascal
__cdecl
__based(
{flat}
`non-type-template-parameter
unsigned
short
<ellipsis>
,<ellipsis>
throw(
`template-parameter
cli::pin_ptr<
cli::array<
`anonymous namespace'
generic-type-
template-parameter-
`unknown ecsu'
union
struct
class
coclass
cointerface
extern "C"
[thunk]:
public:
protected:
private:
virtual
static
`template static data member destructor helper'
`template static data member constructor helper'
`local static destructor helper'
`adjustor{
`vtordisp{
`vtordispex{
const
volatile
volatile
volatile
signed
double
UNKNOWN
__int128
wchar_t
__int64
__int16
__int32
__int8
__w64
SystemFunction036
ADVAPI32.DLL
GetProcessWindowStation
GetUserObjectInformationA
GetLastActivePopup
GetActiveWindow
MessageBoxA
USER32.DLL
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
HH:mm:ss
dddd, MMMM dd, yyyy
MM/dd/yy
December
November
October
September
August
February
January
Saturday
Friday
Thursday
Wednesday
Tuesday
Monday
Sunday
united-states
united-kingdom
trinidad & tobago
south-korea
south-africa
south korea
south africa
slovak
puerto-rico
pr-china
pr china
new-zealand
hong-kong
holland
great britain
england
britain
america
swedish-finland
spanish-venezuela
spanish-uruguay
spanish-puerto rico
spanish-peru
spanish-paraguay
spanish-panama
spanish-nicaragua
spanish-modern
spanish-mexican
spanish-honduras
spanish-guatemala
spanish-el salvador
spanish-ecuador
spanish-dominican republic
spanish-costa rica
spanish-colombia
spanish-chile
spanish-bolivia
spanish-argentina
portuguese-brazilian
norwegian-nynorsk
norwegian-bokmal
norwegian
italian-swiss
irish-english
german-swiss
german-luxembourg
german-lichtenstein
german-austrian
french-swiss
french-luxembourg
french-canadian
french-belgian
english-usa
english-us
english-uk
english-trinidad y tobago
english-south africa
english-nz
english-jamaica
english-ire
english-caribbean
english-can
english-belize
english-aus
english-american
dutch-belgian
chinese-traditional
chinese-singapore
chinese-simplified
chinese-hongkong
chinese
canadian
belgian
australian
american-english
american english
american
Norwegian-Nynorsk
GAIsProcessorFeaturePresent
KERNEL32
SunMonTueWedThuFriSat
JanFebMarAprMayJunJulAugSepOctNovDec
CONIN$
CONOUT$
1#QNAN
1#SNAN
bad allocation
"4nQ;
c4F}!!]
W*C=ep
-1Ao;A-V
Lkj{Wh[
RXSg7Q
U^Zb&M}
#M.&D_
/1E~bE
)2>x]E
VqOz3b
,6Qed\q+
vA+d$
n5_>Q^
X4[u)o
B#rblAP
8H4.xB
J>N{Ec
Du,Kz\
Y|#[L)
5-9H*HN
%c-ddTZ
m4V/gt
u9Kk$L
\P_$!M
p}WCa2
?4]?_\
tnP&J'
* F.u;D
AZF@TD
]h#kDY
}H_('vr
Ku raP
$*G".w
9m[s@3
kwU}rC
fzo(&J
::Z]q7
7KL~EI
`l3%XE
?Nq_N#
y*TJ'T
|/mgz"
qc:mKf~
A_-me
Fu4Q1j
FisB{v
JmMmjW0x
S@{LW7
yU zjs
y.8@:BWU
m,J(`;Y
0@..v$
i'A11dY
A"ifL!n
RD*~8/
Z+a2>
%*6Q9g\}|
4d},+u
E_fywO!
rA:P6/
c>au4g
kBhZu^+
lA8FmS
QaDGt
vo~6|"_
cvRB7947
.GG%{WLX
vhl%aN7
EX,(]6
VirtualProtect
gesepinemu vedosowanohopupaxak
%s %f %c
vector<T> too long
ExitProcess
HeapCompact
SetFilePointer
WriteConsoleOutputCharacterW
EnumDateFormatsExW
SetLocalTime
FreeLibrary
SystemTimeToTzSpecificLocalTime
SetUnhandledExceptionFilter
InterlockedIncrement
SetMailslotInfo
ScrollConsoleScreenBufferW
InitializeSListHead
CancelWaitableTimer
GetTimeFormatA
LockFile
ConnectNamedPipe
GetTickCount
FindNextVolumeMountPointA
WriteFile
TzSpecificLocalTimeToSystemTime
GetSystemPowerStatus
GetSystemTimeAdjustment
HeapDestroy
GetFileAttributesA
GetConsoleAliasW
GetAtomNameW
IsDBCSLeadByte
GetModuleFileNameW
GlobalUnlock
CreateJobObjectA
LCMapStringA
GetConsoleOutputCP
CreateDirectoryA
GetCurrentDirectoryW
GetProcAddress
GetProcessHeaps
HeapUnlock
SetFileAttributesA
LoadLibraryA
LocalAlloc
AddVectoredExceptionHandler
VirtualLock
FindAtomA
GetTapeParameters
GetModuleHandleA
EraseTape
FreeEnvironmentStringsW
SetProcessShutdownParameters
LocalFileTimeToFileTime
KERNEL32.dll
GetDesktopWindow
GetProcessWindowStation
USER32.dll
EqualPrefixSid
AddAccessDeniedAce
AbortSystemShutdownA
BackupEventLogA
GetLengthSid
ADVAPI32.dll
TerminateProcess
GetCurrentProcess
UnhandledExceptionFilter
IsDebuggerPresent
GetCommandLineA
GetStartupInfoA
RaiseException
RtlUnwind
HeapAlloc
GetLastError
HeapFree
GetModuleHandleW
TlsGetValue
TlsAlloc
TlsSetValue
TlsFree
SetLastError
GetCurrentThreadId
InterlockedDecrement
GetCurrentThread
EnterCriticalSection
LeaveCriticalSection
GetStdHandle
GetModuleFileNameA
FreeEnvironmentStringsA
GetEnvironmentStrings
WideCharToMultiByte
GetEnvironmentStringsW
SetHandleCount
GetFileType
DeleteCriticalSection
HeapCreate
VirtualFree
QueryPerformanceCounter
GetCurrentProcessId
GetSystemTimeAsFileTime
FatalAppExitA
VirtualAlloc
HeapReAlloc
GetCPInfo
GetACP
GetOEMCP
IsValidCodePage
CloseHandle
CreateFileA
InitializeCriticalSectionAndSpinCount
HeapSize
SetConsoleCtrlHandler
InterlockedExchange
GetDateFormatA
GetUserDefaultLCID
GetLocaleInfoA
EnumSystemLocalesA
IsValidLocale
GetStringTypeA
MultiByteToWideChar
GetStringTypeW
LCMapStringW
GetConsoleCP
GetConsoleMode
FlushFileBuffers
SetStdHandle
SetEndOfFile
GetProcessHeap
ReadFile
GetLocaleInfoW
GetTimeZoneInformation
WriteConsoleA
WriteConsoleW
CompareStringA
CompareStringW
SetEnvironmentVariableA
ruwotarol.exe
SuspendYourMind
.?AVinvalid_argument@std@@
.?AVout_of_range@std@@
.?AVbad_cast@std@@
.?AVbad_typeid@std@@
.?AV__non_rtti_object@std@@
.?AVtype_info@@
.?AVbad_exception@std@@
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
.?AVexception@std@@
.?AVlogic_error@std@@
.?AVlength_error@std@@
.?AVbad_alloc@std@@
vvvvvvvvvvvvvvvvvvf
vvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvv
vvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvv
Uvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvv
vvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvv
vvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvv
Vvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvv
vvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvv
Uvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvv
$vvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvv
vvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvv
vvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvfV
fvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvV
vvvvvvvvvvvvvvvvvvvvvvvvvvV
Vvvvvvvvvvvvvvvvvvvvvvvf
fvvvvvvvvvvvvvvvvvvv
vvvvvvvvvvvvvvvvv
vvvvvvvvvvvvvvv
vvvvvvvvvvvvvf
fvvvvvvvvvvvv
vvvvvvvvvvv
vvvvvvvvvv
vvvvvvvvv
vvvvvvvvv
vvvvvvvvU
vvvvvvvv
vvvvvvvv
vvvvvvvv
////////
///////////
///////////
vvvvvvvv
vvvvvvvvf
fvvvvvvvvv
vvvvvvvvvvV
Vvvvvvvvvvvv
vvvvvvvvvvvv
FFFFFFFFFFFFFFFFFFFFFFFFFFFF
vvvvvvvvvvvvvUY
gFgFgFFFgFgFFFgFFgFFgFFgFg
YUvvvvvvvvvvvvvvv
FggggggggggggggggggggggggF
vvvvvvvvvvvvvvvvvUY
YUvvvvvvvvvvvvvvvvvvvV
Vvvvvvvvvvvvvvvvvvvvvvf
fvvvvvvvvvvvvvvvvvvvvvvvv
vvvvvvvvvvvvvvvvvvvvvvvvvvvvfV
Vfvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvv$
$vvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvv
FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFxFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFE
FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFE6FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFE
FFFFFFFFFFFFFFFFFFFFFFFFFFFFFE
FFFFFFFFFFFFFFFFFFFFFFFFFFFFFE
<xFFFFFFFFFFFFFFFFFFFFFFFFFFFF|
FFFFFFFFFFFFFFFFFFFFFFFFFp
16xRFFFFFFFFFFFFFFFFFFFFFxcS
FFFFFFFFFFFFFFFF
FFFFFFFFFFFFF6_
_6FFFFFFFFFFFx
xFFFFFFFFFx:-
u----:xFFFFFFFFc?--u
FFFFFFFV
VFFFFFF
FFFFFFcJ
rrhrrhrrhrhrrhrhrrrr
FFFFFFkJ
hhhhhhhhhhhhhhhhhh
FFFFFF
FFFFFF
FFFFFF
88888888888888888888
FFFFFFF
]````````````````````]
FFFFFFFF
*@@@@@@@@@@@@@@@@@@*
FFFFFFFFF
................
FFFFFFFFFFF
FFFFFFFFFFFFF
FFFFFFFFFFFFFFFF
FFFFFFFFFFFFFFFFFFFFFG
6xGFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF
CCCPPP
cccccccccccccccc
UUUUUU
4mmmmmmmmmk
TTTKKTKTTK
KKKKKKKKKK
8pppppppp`
jjjjjj
KERNEL32.DLL
(null)
mscoree.dll
((((( H
h(((( H
H
vonowerexijipeyekocubudopoki
VS_VERSION_INFO
StringFileInfo
040904E4
FileVers
7.0.4.54
ProductVersa
7.0.25.21
InternalName
falimatimad
LegalCopyrighd
Jdfglsdffh
VarFileInfo
Translations
(Menex nihufejuhahaxil wuhun vigozodijigi7Zilaxexekit xum felusota beyujaje keheladak fowevom gaxWTolagu gekifirura kupinebumosur putazabacohiye jenalokofayiv nerexu vijicay wacuxokehut*Hex monigotipa buteda mamehad bayedenirolo
?Loruyoraponabeg mutedujizemad cuyawigiveja ripovi wofazewivaduy
Zome kusobul
Jat gucid horimozelenufaf
Sujo loxLLakugakukoje luguco nibe kegiyuzeja lodurubego wal buzojun burumu xojogapibi
Kuhiduhicoso
?Lelatocuvecoc dilaxada japapacohim neke tuyedahazefuyud luhexaj6Duziludo tup jadu xerorogicip nadoyarili fewuxurojewedMHuguje mofotezivopolun xahanixeja nonidizovip yaculixef cigonewoluyev vupepof^Sega wivogilifuwoc befole kazihiwuc xicazetafi yapevimajimeg wozo holeroxez xewuguyujinage zuc
Zajeju tixocelisalesu!Mahapo xazojafiloz jiwozazezimejo'Cuv xelezewadojeb nurehibu xiyavohuyeje
]Wemituhaxire havoraxop hefenozamu yixola wukurapega demolafuze wekuxetuv vuliviwamowile jagef0Taxifepuza ruhajezolazo rebovamabo juwulafahewan7Tixezezazogi selumana wivujopapuxis cidinuset bak lizeb5Ponuv dobehurezonej seve dapob kew zumifixekuxi xumap8Fahoyaxejo nosusunirar niguxacagos losurezebiwajod jorof
Yuley faza jagi liyadi
JevivaleforowIVelanugopemonib yejutip topi hogowe rarelubihijaj fuzuduje nitocehahepoxi
Man xex cer mijukavufeta
LBetucodivar fad nufuhecehoneha gab tobotazid sodac rul bufiyawut lekijadepec:Nil yukilevonuxuha vir fulo goxeco mebovopego cojeh tokeba*Tufejosi latotekuvugik pomiziy fecesagopup
ZehoninefuramalAJorif daru gezoy lixokadenofavi honekakijed janawawahuco gafitireJBaja pusifewejeb pukodiyizom hotozisosufay movohajidito deroxaf far sekaze:Rutivipinupocop suxoz dinifowuked tipemofuv tuzupofobobece*Jok gako gihesesileze dopag fopoyexokuruvu
Bufiyo zebuOLasi woyor hupun halazubahofo sevufuj vaku juyuhujelifuri mat yitoz supuzubeboh&Kili biyo dic mavesutazikape giresikuc"Vibafimak joyicavel simuhelutowufubTiwajane voculisecedacaf rikedeviw nedebapo yowi yukumuhodugipud zelofafuv rodilalubaro hajuficebeMapabubop gogowu narodukuzacuraaKigodavoduy rezobik zidonuzoya rocaza bedidupitu sudopukonoye pidorolujago lojutigoc febihala hanGSuxad biwasefoz xilizis wawusohoyo susanalujuko zurilobi wefiyug zevetu
Dazupuzanudef meladazi\Cusaw gahonaxonayor luloyagabu pop yerusejay hapesokerubu zesuh vepeyut lado muvevewenofiyoc
Judejakifa kigijege lureveaPipuhi tusirudifuhux jederofexoliw denovad dupetupezi nax canexucezu bub difolalageb suyinururenu
%Tacexozemiyusij juxoyoyos jiwicefojulIHebecawadoxa poneze xesevine zibusipak dusiz pegonixacuho woyidofamapebilTZodatoyiyacep zafumusukurewi temusom pafo dikosabole petunidofu kibenugeje sakaruduh>Yuhoxer biyacar jewa coyor sesegam vexayecihavo sibaxafodixoko_Xopifokipec xeremohosudom cerijop muwiseyamey tawuhotecavuv dexamiy nukikezuyerapa mamegucaveyeGPiletorelunezez sim vesarucigib wovizeyafuveduw pasadogam koyudakolagov6Neke wosagitijevobo gufinin sakudibujoy yebufuzoya kud_Xeyatag zohinabiguwijox talozalesogola birolinujimu sofox fewavamugihitu posafakamozuwe sacovikRLujuxa puxavepaci luc seluxahaxa hicurimigacefo mexu dolitokeca xetu wocuvohecelelLCabumako joh wowozoweromaku yopawajoseyoha gozitelimu zafipiluvo tabehalerog$Hevomiyoloze xavohijeragara hezenapuWLigosawobefih wovuxifamulaf felocitipuluj juw xakenope lijibum nitehidutomemu jolemeteg
Fovozofazapugu)Yixacu saroga yivo wusijifinu gixemotenuz
Zopeheci nol wubipanur vatesADiwidadepuzixem rariwu hucufevavefum wehesijusawal yejeda dewatex>Kujudafodapo kexutifobowos xiluvegad wij losefiriloc puyuverot(Bibilami hudugejahetozu ned jehi tejidis6Zajuw poyusehakuc cef teduv novusadazowusur bigaribulaRKisazibe hiyibehah yohuperuwele yas behibebiravoj pene fuhugiw dovuxakibiw zijazolRYafararuticido noko zomicajej voyuwuzasadekub gofewuhedizuf yew becalu cisebofocuh!Vas xopurut punoxi supadu fiwopav"Javosimit lefoxara hedaxi yurixabuNCakazemuvo duk cogijixoleb xaled nuj xasih yegetohifemezib gumo dayoguwerejeru
SaroninedSGogukiri mikopivozop riluf tayog racexiricahexe fup sokokobopo ruxaselituku dupiyagVDataxecabovos woxegelatesa zadi pujijoyusayu hacorilugaweg soboziyalo xegama lugonozagGZifocomojekug xupav pigezedazowobo zipocanew ras gepad weyese tebokojul\Gukeyecabagoreh fumizupolecove mufoziyal gav vut julubonutuzoya naze duk huvohabipuye lexepe
QWamem mutumog wenaze tayifetebuz yorelij ripif lezivemizan cuhalexiwuy talojipoya_Vayiloxuvivamel zepovitarotax suceyuwoduto cecupogoh xeb wotebajuci xoviyefiv nigi xorakusobawi
Bahidegirezoxig pigayugilek2Rumavihufix sepadanim hedogabumogazat goyulaxakipeOJoz pixajaj nozifovuxuviful sazuyinitapuy kugaranef poditivafeb dikeronuweroganMKega picigetafamasav livego wucuvufaj padukiwuxilame covogoyagoto yobehovadev)Navih vodehuyiha fuwaberusif javok sareceFVeriki nemukacibup sayin damozinukihos zacafukijanoj bakecitez zeyurix
Basakekenajifa vozavocebojoran<Vafagecexot hayezocolugimot minorowube ruyuvero bacena bares
Livogidayalomok cipoboy
Juf xuxipuh bifit
Pazepu bovepikixuga
HoturogRLir litusan beculo duho zonalijeyomuhig lulah tipuyocubim fibirezijad buyafib fegiWWihoki gupaku duyajejivuzeka dowapufu mogayibofazuke yaceja mutifigisoxap wukopanesakusgYidutedomud vunecifuta yifiwasipen gogehafoveraz judiwetederihe riloxeguvip filivojoyoc bani paxi ticak
BefuyacBGevolicu mukuxogine gajovexiweje pepunayugozibor bidujakoza toyoxafNadarezo damavowekoya domoyewaguguli newupeho gopidesub dizodeneroxex feti gilodefuzimu cufuh jedudoza9Xisukehu sugodohe veviner sibisesape kari dax jiwey laligVJukiyivaj widiregefe muye masizixah goyobeyajus sukit pojav xoyukilexa yuwodubiped jiz6Jocuxu pejo cevekewatuwuf xeziguyuleb foloyod cogihunu Teyigijixiyan hub nipasesedi juslDotefewezasa sasepe palikecofixirav jawonuna tolimuyajojolux biberotohusuzu hun rivafamagehaw nofubisosecose
Femaniwiway
Vojekejiguj
Calegewobo kecu
Antivirus Signature
Bkav W32.AIDetect.malware1
Elastic malicious (high confidence)
MicroWorld-eScan Trojan.GenericKDZ.76039
CMC Clean
CAT-QuickHeal Clean
McAfee RDN/Generic.grp
Cylance Unsafe
Zillya Clean
AegisLab Trojan.Win32.Stop.j!c
Sangfor Trojan.Win32.Save.a
CrowdStrike win/malicious_confidence_90% (W)
BitDefender Trojan.GenericKDZ.76039
K7GW Trojan ( 0057e6951 )
K7AntiVirus Trojan ( 0057e6951 )
Baidu Clean
Cyren W32/Trojan.TFMQ-8690
Symantec ML.Attribute.HighConfidence
ESET-NOD32 a variant of Win32/Kryptik.HLLP
APEX Malicious
Paloalto generic.ml
ClamAV Clean
Kaspersky HEUR:Trojan-Ransom.Win32.Stop.gen
Alibaba Trojan:Win32/Starter.ali2000005
NANO-Antivirus Clean
ViRobot Clean
Tencent Clean
Ad-Aware Trojan.GenericKDZ.76039
Sophos Mal/Generic-S
Comodo Clean
F-Secure Clean
DrWeb Trojan.Siggen14.2132
VIPRE Clean
TrendMicro Clean
McAfee-GW-Edition BehavesLike.Win32.Generic.dh
FireEye Generic.mg.75fc5d6c951b284b
Emsisoft Trojan-Spy.Agent (A)
SentinelOne Static AI - Suspicious PE
Jiangmin Clean
MaxSecure Trojan.Malware.300983.susgen
Avira TR/AD.Cutwail.munvt
MAX malware (ai score=86)
Antiy-AVL Clean
Kingsoft Win32.Hack.Undef.(kcloud)
Gridinsoft Trojan.Win32.Kryptik.vb
Arcabit Trojan.Generic.D12907
SUPERAntiSpyware Clean
ZoneAlarm Clean
GData Trojan.GenericKDZ.76039
Cynet Malicious (score: 100)
AhnLab-V3 Trojan/Win.MalPE.R426946
Acronis Clean
BitDefenderTheta Gen:NN.ZexaF.34758.su0@a0OQJqiG
ALYac Clean
TACHYON Clean
VBA32 Clean
Malwarebytes Trojan.MalPack.GS
Panda Trj/GdSda.A
Zoner Clean
TrendMicro-HouseCall Clean
Rising Trojan.Kryptik!1.D782 (CLASSIC)
Yandex Clean
Ikarus Trojan.Win32.Crypt
eGambit Clean
Fortinet Malicious_Behavior.SB
Webroot W32.Trojan.Gen
AVG Win32:PWSX-gen [Trj]
Cybereason Clean
Avast Win32:PWSX-gen [Trj]
Qihoo-360 Clean
No IRMA results available.