Static | ZeroBOX

PE Compile Time

2020-10-18 03:33:50

PDB Path

C:\nicof\fonorucesiza.pdb

PE Imphash

40b1f970cd866a04c66be8c7bed9fe15

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x000913ab 0x00091400 7.96358235019
.data 0x00093000 0x0056ec50 0x00004e00 1.09614077271
.rsrc 0x00602000 0x00018ed8 0x00019000 6.39356668384
.reloc 0x0061b000 0x00004e4e 0x00005000 1.4397283268

Resources

Name Offset Size Language Sub-language File type
RT_CURSOR 0x00618bb0 0x000000b0 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_CURSOR 0x00618bb0 0x000000b0 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x00618568 0x00000468 LANG_SERBIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x00618568 0x00000468 LANG_SERBIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x00618568 0x00000468 LANG_SERBIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x00618568 0x00000468 LANG_SERBIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x00618568 0x00000468 LANG_SERBIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x00618568 0x00000468 LANG_SERBIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x00618568 0x00000468 LANG_SERBIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x00618568 0x00000468 LANG_SERBIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x00618568 0x00000468 LANG_SERBIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x00618568 0x00000468 LANG_SERBIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x00618568 0x00000468 LANG_SERBIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x00618568 0x00000468 LANG_SERBIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x00618568 0x00000468 LANG_SERBIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x00618568 0x00000468 LANG_SERBIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x00618568 0x00000468 LANG_SERBIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x00618568 0x00000468 LANG_SERBIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x00618568 0x00000468 LANG_SERBIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x00618568 0x00000468 LANG_SERBIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x00618568 0x00000468 LANG_SERBIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x00618568 0x00000468 LANG_SERBIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x00618568 0x00000468 LANG_SERBIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x00618568 0x00000468 LANG_SERBIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x00618568 0x00000468 LANG_SERBIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x00618568 0x00000468 LANG_SERBIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x00618568 0x00000468 LANG_SERBIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x00618568 0x00000468 LANG_SERBIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_STRING 0x0061ae28 0x000000ae LANG_SERBIAN SUBLANG_DEFAULT data
RT_STRING 0x0061ae28 0x000000ae LANG_SERBIAN SUBLANG_DEFAULT data
RT_STRING 0x0061ae28 0x000000ae LANG_SERBIAN SUBLANG_DEFAULT data
RT_STRING 0x0061ae28 0x000000ae LANG_SERBIAN SUBLANG_DEFAULT data
RT_STRING 0x0061ae28 0x000000ae LANG_SERBIAN SUBLANG_DEFAULT data
RT_STRING 0x0061ae28 0x000000ae LANG_SERBIAN SUBLANG_DEFAULT data
RT_STRING 0x0061ae28 0x000000ae LANG_SERBIAN SUBLANG_DEFAULT data
RT_ACCELERATOR 0x00618a70 0x00000010 LANG_SERBIAN SUBLANG_DEFAULT data
RT_ACCELERATOR 0x00618a70 0x00000010 LANG_SERBIAN SUBLANG_DEFAULT data
RT_GROUP_CURSOR 0x00618c60 0x00000022 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_GROUP_ICON 0x006089c8 0x00000068 LANG_SERBIAN SUBLANG_DEFAULT data
RT_GROUP_ICON 0x006089c8 0x00000068 LANG_SERBIAN SUBLANG_DEFAULT data
RT_GROUP_ICON 0x006089c8 0x00000068 LANG_SERBIAN SUBLANG_DEFAULT data
RT_GROUP_ICON 0x006089c8 0x00000068 LANG_SERBIAN SUBLANG_DEFAULT data
RT_VERSION 0x00618c88 0x000001e4 LANG_NEUTRAL SUBLANG_NEUTRAL data

Imports

Library KERNEL32.dll:
0x401010 GetCPInfoExA
0x401014 WriteConsoleInputA
0x401018 ReadConsoleInputA
0x40101c GetTapeParameters
0x401020 SetTapePosition
0x401024 WriteTapemark
0x401028 GetConsoleAliasesW
0x40102c WriteConsoleW
0x401030 SetLastError
0x401034 BuildCommDCBW
0x40103c RequestDeviceWakeup
0x401040 LoadLibraryA
0x401044 FlushFileBuffers
0x401048 GetLongPathNameA
0x40104c PulseEvent
0x401050 SleepEx
0x401054 WaitForSingleObject
0x40105c FreeConsole
0x401064 SetConsoleTitleA
0x401068 ReleaseActCtx
0x401070 AttachConsole
0x401074 ReadConsoleW
0x401078 GetProcessHeap
0x40107c AllocConsole
0x401084 GetGeoInfoW
0x401088 GetCurrentProcess
0x40108c GetProcAddress
0x401090 GetModuleHandleW
0x401094 CreateThread
0x401098 GetProcessHeaps
0x40109c GetOEMCP
0x4010a4 SetSystemPowerState
0x4010a8 FindAtomW
0x4010ac SetFileApisToOEM
0x4010b0 OpenWaitableTimerW
0x4010b4 HeapValidate
0x4010b8 WideCharToMultiByte
0x4010c0 GetUserDefaultLCID
0x4010cc GetCommandLineA
0x4010d0 GetStartupInfoA
0x4010d4 GetModuleHandleA
0x4010d8 HeapAlloc
0x4010e4 TerminateProcess
0x4010f0 IsDebuggerPresent
0x4010f4 TlsGetValue
0x4010f8 TlsAlloc
0x4010fc TlsSetValue
0x401100 TlsFree
0x401108 GetCurrentThreadId
0x40110c GetLastError
0x401114 ReadFile
0x401118 SetHandleCount
0x40111c GetStdHandle
0x401120 GetFileType
0x401128 SetFilePointer
0x40112c Sleep
0x401130 ExitProcess
0x401134 WriteFile
0x401138 GetModuleFileNameA
0x40114c HeapCreate
0x401150 VirtualFree
0x401154 HeapFree
0x40115c GetTickCount
0x401160 GetCurrentProcessId
0x401168 GetCPInfo
0x40116c GetACP
0x401170 IsValidCodePage
0x401174 VirtualAlloc
0x401178 HeapReAlloc
0x40117c RtlUnwind
0x401180 MultiByteToWideChar
0x401184 SetStdHandle
0x401188 RaiseException
0x40118c LCMapStringA
0x401190 LCMapStringW
0x401194 GetStringTypeA
0x401198 GetStringTypeW
0x40119c GetLocaleInfoA
0x4011a0 GetConsoleCP
0x4011a4 GetConsoleMode
0x4011a8 HeapSize
0x4011ac CloseHandle
0x4011b0 WriteConsoleA
0x4011b4 GetConsoleOutputCP
0x4011b8 CreateFileA
Library USER32.dll:
0x4011c0 GetAltTabInfoW
Library GDI32.dll:
0x401008 GetCharWidth32A
Library ADVAPI32.dll:

Exports

Ordinal Address Name
1 0x48c625 @GetVice@0
!This program cannot be run in DOS mode.
`.data
@.reloc
bad allocation
Boruka hipeturuhog
rinakimuhuzafoluj
sisezarijetehotawuyofifegupunowegowuciduwubosuziwirafugurufojofebapuvaju
LocalAlloc
VirtualProtect
%s %f %c
runexobozez
?ZEM-'^
?{yK+;
?765@Z
?e')lW
UUUUUU
?333333
?333333
?UUUUUU
?$rxxx
GAIsProcessorFeaturePresent
KERNEL32
(null)
`h````
xpxxxx
EncodePointer
DecodePointer
FlsFree
FlsSetValue
FlsGetValue
FlsAlloc
CorExitProcess
runtime error
TLOSS error
SING error
DOMAIN error
An application has made an attempt to load the C runtime library incorrectly.
Please contact the application's support team for more information.
- Attempt to use MSIL code from this assembly during native code initialization
This indicates a bug in your application. It is most likely the result of calling an MSIL-compiled (/clr) function from a native constructor or from DllMain.
- not enough space for locale information
- Attempt to initialize the CRT more than once.
This indicates a bug in your application.
- CRT not initialized
- unable to initialize heap
- not enough space for lowio initialization
- not enough space for stdio initialization
- pure virtual function call
- not enough space for _onexit/atexit table
- unable to open console device
- unexpected heap error
- unexpected multithread lock error
- not enough space for thread data
This application has requested the Runtime to terminate it in an unusual way.
Please contact the application's support team for more information.
- not enough space for environment
- not enough space for arguments
- floating point support not loaded
Microsoft Visual C++ Runtime Library
<program name unknown>
Runtime Error!
Program:
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
`h`hhh
xppwpp
GetProcessWindowStation
GetUserObjectInformationA
GetLastActivePopup
GetActiveWindow
MessageBoxA
USER32.DLL
_nextafter
_hypot
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
HH:mm:ss
dddd, MMMM dd, yyyy
MM/dd/yy
December
November
October
September
August
February
January
Saturday
Friday
Thursday
Wednesday
Tuesday
Monday
Sunday
1#QNAN
1#SNAN
SunMonTueWedThuFriSat
JanFebMarAprMayJunJulAugSepOctNovDec
CONOUT$
C:\nicof\fonorucesiza.pdb
c2I7*OyL
B@d>g:
)8oo>
MNWZjz0l
$Ip^7/
m=e?m1
r}nEa=
oW?<s^J
8"XDzW"
|Y($:*
AUp'JuE
Q}`]VI
oH}I[n
pe/oP\
"0u!A5
*u4s@8v
a}{E0_\KB
3NHx9&
08t$;"
VmLXB`
;dn(f5@
xZ$-*z
j;U*G6
"H3Fni
=9}=&T
r7E(rs3
a]xT]4
j;]W7i
gL*$`B
Chr,t!0
kY@l14
Hzb0|y
4bFoy&
k 3M.5
+,b d\
6:?j\j
7ly|mT
mhdQsj
LzQS0M
g{"Lb
}&U,2][
uA$b7]
&hCl5 T
I`&7oY
S^t"a^
tt5@)c
Ac`OG%
h(+GQ9O?_
kA-]ZK
/bu1!K
$;>99$|\
\YO9%S
9V=WGaZ5
mbM&&d
Y['mdy
TM2FFe
E~{TsP
'G`}0w0
@ZzEj
W~;sM5
WGzo](
i'63@[
Vg<$@A
Z3Ca61N[%n
x[lQ?.L mHz
YI<)C^!?
Lt)e'r
%$92CL
3j8t$6
-{UC%C
DC+=gW
h{lA7)
;OxCJr
`~@toM
E6K4qL
t(h}Pc
Yf+15!b?Hm+9
{+L`p_&
%03$oi1%
bkAn?B3
q+I#V \?.
,@#ei.
,m*]P ''c
xd9~e'$
G:Kb`B
V2@w'
n9_lg*
1:5D.b4cv
E[m/@T
Rhg2<E
maB|jB
/1O|$$
1-;%b:
4v]Zlg
wy*WF`
[505_yj
Ojhw8Z
b T+oX
j)cqIh
GXA4WQ{&
1Y)(Rc>
AGt}NM
*(l#`B
I<eu{Y
O&+]EU
1"O|"q
mw~iTX
@f+V,<
j[q?77M?/
fxP^Pep;c
|Nvl7#
".@-"e~x
1BU4.U
Do1K6a=
|2ZtsB
32S,,h
pLZZl7
]QGFI;
,% ]%o
9(x{EdY
"I.+XV
AvR.;uZ"
Ft>}~Z=
r5"h0x
P&w`0!c
):ilk+[
KRyL-(
_60N#C
#'85zg
M;>%AZ
LF]*K3L
5L=\ljK
a[|}=c
N]!bp{u)
6:!\Iu
Q5Xy6
mj.|xl
.r>#{|s
w2H15f
Ah+N$>
a_=7-_
{0qttZ
E[#Lg)ZLk
Bdur\
h~a7fV
B%B.: 4
Vo0([.
wr4E9v!O.=
^"qq3]
|,>7zX
M6Js4Nnd
Gq-E%[
_M+A{4Vqj
XJf5f%
C)O[pR
NV`%Rv
=4e="'
"LOs39
RfHGEp
,?f'3>M
hF-6#V
qXle<n
IPDJlk
x),RK!
';ViYk
NQnDPO!i
.#TKSe
0#&\J4
6*Q`s0
Y-<Qb)
hc\DI[A|-
_hZm~F
[MPPom
hS}a{$2j
]R07q#
gc31)[
6y@'yn
[]V*p@
r`Vl'_
qv:@wo(
.,bLb$
T/LOt?
!4YLi|
hA~6I4+
87:5^xueH
#hw;NR
.FsBh5!
}6!I9~wT
`%%x$2N
x}ER^v
5vqm N
S|>Y5
iY$k)SC7
M{JC,UE
)C%AfM
f0-|C^
2;S.lx
z}^40u3
Jwdg6@x
t5xf[y
uT>pE}
Ae/dNOELd@xl
N^pb^r
;@=_ts
49sxJM
xV|n';%
>B?bK8
U BuQr
GMR7L]
H+ 4f/3
[,Ja>;z?-fDu
AgL_d@/
5<NPxa~
|e&kTTH
!/ri$_\
$NU""F=
@g2g<}dV
v}wnU*f
|#@!C:7
pTIKZ{
'^*KlxOFq
`IBz*Q
$"A|q\
k {O=P?
O9Y(8o
cr[3_Y,
_h;*8H
*JeTkf
]v/v98
2u]\p`O
jEinMBX
WxNJ}y
v*[s}
|o"D$7)
ir=?m7
Cj$_[D7]
9C;Ka}
"Yr}7t
qCD{.4D
[40(P|
|a`h%g_>WX70E
mvv&8]
iu>`qF
g45EZU
|.d8^
A'(U4JE
"k&8|8
I-srx\
qJ^Zbh
i5"P{Z
~3]%F1
EagF1*
h.@}-kW
nNA].9
X@Jz`6
{p.! F|x
!p/QDie
O-.%)s
h{}<<(x
vr_gEX
6}m)7w
BjTt<}\
(JZ)%#t
TSW6B]
\7gn,~$
nq?[(|@S
5' Uy!
dW`Vyn(
~I3f2B"
T]g?sW
(-_Dn9e
PJ"I!n|+
sY,wHz
Iq )@-
cY\Jp.N
_#9MIB
ZSO2=8
iB$:h
)\)etT
K<G+gpVV|
v5eQ<kq
&{J@r]0
:/Oech
Rp:gu?
UNG`.)G
8}uQq%
_>8p9BA
Z!qs29
:`m><b
h5fv$x5
Z!=_2c|
[j2Zff]
S0{o\V0
0/szI8
^L]IYK:
a`W3p
(If4\ou
OD'83i#
2sQ+YszN
UD*$e{{
0*2D'U
v]_4b}T
9.lqp2.
$A4SE}
ndme#TeM
tQ8.;u
8r o{F^
c]kV0b
&&~'HD
?fGpxd
Oja9k#
|wzG_E
y@5@!k
H8o.qq
56gS8p
N{508`
4 b_@dxZ
@|<mT$F'==
"T!D)Z
ch5ZS{
, S+Sh
}i+r!|Xg
RGV!DBT
(GGEWal
**\5\A
-U><#o(
S5 ,GY
4,uy[;
|7Vg?8
1n{qeY6
F7I.k=
vlr'A*
s5Wdbp2X6
T!cEzA
~|(>0^;q_
3M=P,j~
?UCF/8Y
`LKa)
@"D\e
/"Up'|
~DK` *
)5o*%,
I;6`3n
#HT'jt<
`TGbLHm
cDw/gP
UsI~./
P2Rs@.%
~xA6t
z$H'jU
.kWtuD
Y+Y!0zl
#/V.U)^
ypIN^zzTi,
H~9aAI
rAf2?*(
)WSh(Sej
:dOql!.L
BUWa<qQZ
:?{Zqb
Y'!v o
Ibj@>y
%I"'HC
`gEZqFg
|4p Va
*wBX%b
g5upop
=pV/3Ga
CjrUj.
MaV6Pp
u<;4@F
)9yTkME^
<REl)4
@>uyZoy
)$Dtr<ieV
~Yn="6
msS[\<d
R?5t6h
|BDR~>T
6Ugxq)
Xdx=l
O1/lT
0~ZWFa
W-nQ?SVs
f7gWA3
B"[evw
yp`V 7
q+s1^5
T^wMeXU
eLu}46
~"L%k8e
>=;4gB
Z^o/{2{;
$qY9*1
OxcpPg
%*_M1z/
5@JW"
,!f]Wk
.57I]~
(d$Gnb
`0<K`=
Jsnf&
]3R$z
liQ"fz0.
K@:C,+
'uA/po
!2%.\v
}c'G.C~U
2D'ma~f
-s=2oD-
metP[*
&vKPgL
9Gvo}C
#\'Q%J
?]z ({
zGbwSb
mz0j0,
.i8?]?
3GN9vH
kZ}W> S
FOo)[x
+^ljT1^
WD.@AG
x|$i#R1
,P*m$C
!n&K-k
iO)rE[_
(p;_*%
k,A3{4m
*#l65[
zfWM=,
28Vt#P
}Bk}L"hot[]
Hf[GrW$
R?}o4G6
:D1h`?
^$k fh
9Y`jYy
R,b'aU
Z|PZ?
WlS$9u;
nXk,OaE!ag
}7Erpi
55B<r'
HSL0u;a
T=MUaZfE[
Z'0/8>DI
)65(T;
a,O&G[
i.yjPcB
:%3O\o
=?R<vR
]6V|lY
$l=3gS
1Vj.D)@:
fj>R^E
;<oH#`[
^-%BkF/
OF&Vp?
_Qpp~+
w40sJS
S<VB5ZHn
OW '/m
ZE#@Ad
KU&:!<
S4qa=0
6"5[#<
aQa"*r
y(h)ML@
(4k[Fe
V%dp~.,F
fpbf2Q%r
S}-(3HDT
,elqDiv
1UC/Et
b5evx\Z
6q|N.,f
q5^|0,z
`2:H@S
Et^h|]
">6Xy4
z$r'[r
{w,v5i
F~u7"\
8)M_:8
XAO6L'R
n>1]E%
qLe>Z_
K}.K{9
--o"42
u0ftQp
G5+3qE
pdb$"VnG
pkkGqv
ScjU6[A,
Soo[Gd?
9O[HB6
4ae5yN
*w ((,t
W+K~7L
xcc/OG!5
}.\dJ0i
,83EVc
*@kVrk
y,L8s!g
M#}0oC
zi5##5Y
aj"hjv
,X^Tum
,h6s5t
PRwz0G
ljzw{C
v2Q~G*
*b#9T_
`!#*"+
jVM0E/
a5gn)$um
TLy7}$
?~""<N
iXx|_=h
/y5pI~U
YGD~6
mV'c~Q*
uw_f/Xz
DL(}Kd
^2PS}d
g(::Q/a
|Qy?eh
fa6IW>c
kVEC$oE'
WZ>XIx
\%~[t*
f>-'^
|HX[ng+
27( 3,
Xh_&`'zt
/nu9B0
>%O\[.Z3z_
]p:ZR-
4bT%Tm<
g>2RY8N
-~=E(U.P
XVa!pa
jb_dt8k
&79MD<}Y
ZQ^8wo
41+$Nz
*]}RCk
5<&nJ}
\neAVlsL
9JPo-uVM
?_4X +
j6d{Bg
90tgk/GYx
fY[NGl
O%9>)?k
gpq>CNL
Sv-3'&
ksF=@x
"RTA:j=
b|!&3H[
#]/GH 7[
9/P>#\
q6OW~ja
{TrEv@
w5~v}?
2Fl}GX
2zTP[M
+~g+|R
`gGv}1
M{*=%P
z %^(f
jJzpT6
+zu&-d
0b~21Z
ioSI ^
K[k!E7
z9Adoj
Jz-k nG
<TR$vp
|o,<5t
R@9yPv
~+uXiS
>!k`@</k
'UV\ E,r
p!bDUE
bjwN."JWD%
B%l$'F
[i4P;69
<]M{_A:
Yaaev{n
.iSiJw
!4W6W|
>`u9{5
r\ddk6
*RMt_>
:W4.5<
'<r\5k
?$gP9E
4S\eo5
91)T?1
ibr=B}=
oZ]g<)
RNI?!x
m3+>|>
-$v,<8P
Z!5,GB
zKE66;z6:P
Mb'1S;
}CP/M.R4
@GQ7((:
rXV2AN
w"*l&a3
\$lrW{`
){TQ!r
uWOi+c
D_:\4Op
4=v71mqj
$.|%I@
Kky^GU
W$^3w?
bk.ABn1
qra0Q5N
cPihp_
ca~%H@
vsp3uL
WDyY7]SRC#81v
U.:X\&S
gkLlC6
iq>J6_rKt
3o_vQ
4UCix^
Y)|=-m
m\ _?}IV
F9snH\{
880X3ps
wj\Ox
CI@!P
,~*vcu
bh<*a(
/qM.Vp
@6EPKP
K\>$>$
m*C+{U
t$.W:x$
NAx5e5
$QX.>:4
lT_.bt
a]n0V`s
)tpi}w
#z Cb=
%!W$=z
Sh>J);r
W7Y_l1
f9B/'G
'Yv6QwZ
Y}m%jI
I:,s&H
.j:D
Fe@zdx
F+&x-8
:d|H"[
uZF:}p
S,qp1"
a.Ti+I
v]fv;2
fe.ST};
paDc(_
E6E{qN
Lll3'mp
uIaPE][
+mPw\Q
86S,]2
&a)&<?
5x,05ep>X
~+\,')
DVr1dNQe^R
823"#,B
-z@$3Z
VjO HTt
{L.Tqz
,k3i;9
+RATH/
P<IqUf
=WJgV/
B4$5]<K
WRyP5'j
$a~>m
-^rZ #
H!}BUZ
}0;WI/
S@]F}l
gw~>6>_5>
VLI*6c
o00SAT1
6oN7wY
~T[@Q|e>
$^B13r
D\sy`l
:ppKcM
!dxam
F~^";'"QrS:D
YZ2eJ?
,-lu@n
6b{r\S
}_-NWRk
~%_~{$
P#x%K/9P#
m3>Hrrir
;TkM;M
?AjvK{
$#hagz
AMynKG
='qrU4T
A(r(I4
9,VPY4@
FXdhaJ
R!JC#(*
^k9c21k
Aj'[]z
[XVtt.,
,yTtb@Y
X_[Q:R
.uRDgnW
pIx7UWv
5AK.#l3P
A8)9z5
~5`[O$0
HYR|A5
S2*=<I
1.mO\:
NMFuMI
<]hMC|u|
pd.KBz
S0Fx7m
U9o-WZu
Q:~=oU
<JJQE{
_OLOs
|u,:xf
1n]9,6
u2'yMj1
b0QG71`
1w+nhs
fGsm(:
Gs"X/t
?3,3?E
t&TeYt
lBq@4So
vrCSYPI
JB:joC
JV)Sxv"$
pb%p[*
jkTETxe!da
_cRGTv
X/ R]7:Q
(<QRIi
~,-k%6d
!R%d~5
:^c']W
=|XkzK
qr9+5;L
t*k\<i
.GI-Z{
U@v\}d!
$wA<ij
@W_MkC
h:>uAV
$>IGPn
nn}TFsn
~@bf3M1<
<}1&g?
I&Gg$q
A@!)[Wu
2v:e4(*
CQCIcW
~%PHzA3B
U8nRD+
n?_M6r
=xoS/5y($
J+8et/
m]ce|
Qw~C}fc
}5SfMr*
X][U&`B
o}*!Y}
4u P`C7;g
0|II`
4$RbLp
[.MYhZ
Fy3)1!
1.`xabX&#
{qN-kB
j'Ib6ak
cHMDW`i"1D
meXnRJ
$20'@@
!WLqe(
{Z-<DX
'" Xc9;/V
p7~=rW
g$PQg-
%[,sw
[UwcSDK
"+>\V'[19
uob!6Y
"x~zV
Ei1U<*:~26+
0IW";w{{+
GuPcq"
_d#'X#*]
FVPaLVL
"H3p|w
/&G!Eu
B!))2x
?0\Y%Ke}
&+rko Ko
b,$lJc
"dks>.
uMHVg&
jF}w<j[)
j:6[<
SGA|#O
q+=L["G
UTyI3%
v837WY
oJw86p
I=zUhX
s_?%kly
~o'9i_
TV_0's
}.>>!+iw=
.0>rzE
j"rw\,1
m@OrR&
<:cO)Y
5hzq9
(>J+K`r
OXLP9r
(*rRhxG
9gZ5n^
"}kY^uj
Bg^1@B
DCFb+R
ENy9pU
|`y!~{
B0,)*"
KL1jIP
Dxm([-
~+mb V
C,)T/9g^
^{.Ql*
W4}{n]@
"Zf$IZ
W$S0r8
3{.E"x
b]5vaj
hP1tQxo
o,C3{X
vpK)I;
[$Pnxf
~^^_O.
Rt{J6I~QW[
[J2V(U
RsHRT<
9J/"=<&7
e|_U6l
a)5(otG
j ;;A@!Vh
x~VIE$
J&#Sn&
P)%HWYW
H*&j2t
Z=}z.z
ul?Qzj
`Uu'RI5
d:PTMF
W+4&Kfu
\%r+1i/d
:( TUd
(p>:
T?kl3_x|HR
JdMdU1J
_qAwW\
T4h@,r
&6P4rh
44..RWA
NQD0"N
c7f6}lxW
*!,@~R
u$VVVV
E<XjdB
EPbcs%
uyVVVV
VVVVVV
SUVWuD3
SSSSSSSS
PSSSSS
_VVVVV
^WWWWW
HHtXHHt
>If90t
F\=X2@
tehtoH
j@j ^V
u&h 2@
>=Yt1j
tNIt?It0It
tRHtCHt4Ht%HtFHHt
0A@@Ju
0SSSSS
0SSSSS
_VVVVV
^SSSSS
j"^SSSSS
URPQQh
0SSSSS
0SSSSS
GWh\5@
t"SS9]
FVh\5@
v$;5,hI
PPPPPPPP
PPPPPPPP
<+t(<-t$:
+t HHt
;t$,v-
UQPXY]Y[
t+WWVPV
GetConsoleAliasesLengthA
ProcessIdToSessionId
GetUserDefaultLCID
ReleaseActCtx
GetCPInfoExA
WriteConsoleInputA
ReadConsoleInputA
GetTapeParameters
SetTapePosition
WriteTapemark
GetConsoleAliasesW
WriteConsoleW
SetLastError
BuildCommDCBW
InitializeCriticalSectionAndSpinCount
RequestDeviceWakeup
LoadLibraryA
FlushFileBuffers
GetLongPathNameA
PulseEvent
SleepEx
WaitForSingleObject
WaitForMultipleObjects
FreeConsole
SetConsoleCtrlHandler
SetConsoleTitleA
GenerateConsoleCtrlEvent
SetConsoleWindowInfo
AttachConsole
ReadConsoleW
GetProcessHeap
AllocConsole
BuildCommDCBAndTimeoutsW
GetGeoInfoW
GetCurrentProcess
GetProcAddress
GetModuleHandleW
CreateThread
GetProcessHeaps
GetOEMCP
WaitForMultipleObjectsEx
SetSystemPowerState
FindAtomW
SetFileApisToOEM
OpenWaitableTimerW
HeapValidate
WideCharToMultiByte
KERNEL32.dll
GetAltTabInfoW
USER32.dll
GetCharWidth32A
GDI32.dll
AreAnyAccessesGranted
ADVAPI32.dll
GetCommandLineA
GetStartupInfoA
GetModuleHandleA
HeapAlloc
EnterCriticalSection
LeaveCriticalSection
TerminateProcess
UnhandledExceptionFilter
SetUnhandledExceptionFilter
IsDebuggerPresent
TlsGetValue
TlsAlloc
TlsSetValue
TlsFree
InterlockedIncrement
GetCurrentThreadId
GetLastError
InterlockedDecrement
ReadFile
SetHandleCount
GetStdHandle
GetFileType
DeleteCriticalSection
SetFilePointer
ExitProcess
WriteFile
GetModuleFileNameA
FreeEnvironmentStringsA
GetEnvironmentStrings
FreeEnvironmentStringsW
GetEnvironmentStringsW
HeapCreate
VirtualFree
HeapFree
QueryPerformanceCounter
GetTickCount
GetCurrentProcessId
GetSystemTimeAsFileTime
GetCPInfo
GetACP
IsValidCodePage
VirtualAlloc
HeapReAlloc
RtlUnwind
MultiByteToWideChar
SetStdHandle
RaiseException
LCMapStringA
LCMapStringW
GetStringTypeA
GetStringTypeW
GetLocaleInfoA
GetConsoleCP
GetConsoleMode
HeapSize
CloseHandle
WriteConsoleA
GetConsoleOutputCP
CreateFileA
cobavoyut.exe
@GetVice@0
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
vvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvv
vvvvvvvvvvvvvvvvvvvvvvvvvB
bvvvvvvvvvvvvvvvvvvvvvvv
vvvvvvvvvvvvvvvvvvvv
$ hvvvvvvvvvvvvvvvvvvv2
IHvvvvvvvvvvvvvvvvvv
vvvvvvvvvvvvvvvvvv
_Fvvvvvvvvvvvvvvvvvvv
~8evvvvvvvvvvvvvvvvvvv
lvvvvvvvvvvvvvvvvvvvvv;
vvvvvvvvvvvvvvvvvvvvvvvvvvvv
vvvvvvvvvvvvvvvvvvvvvvvvvvvv
uSFvvvvvvvvvvvvvvvvvvvvvvvvvvvv
vvvvvvvvv
vvvvvvvvvvvvvvvvvvg
`Ovvvvvvvv,vvvvvvvvvvvvvvvvvv
vvvvvvv
vvvvvvvvvvvvvvvvvv
vvvvvvvvvvvvvvvvvv
%vvvvvvvvvvvvvvvvvvA
vvvvvvvvvvvvvvvvvv
L<W]vvvvvvvvvvvvvvvvvvv
vvvvvvvvvvvvvvvvvvv
R0U1vvvvvvvvvvvvvvvvvvvv
vvvvvvvvvvvvvvvvvvvvv
Qr!/{Mvvvvvvvvvvvvvvvvvvvvvvvvvj
vvvvvvvvvvvvvvvvvvvvvvvvvv
vvvvvvvvvvvvvvvvvvvvvvvvvvvs
vvvvvvvvvvvvvvvvvvvvvvvvvvvv-vvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvv
/D@yk95
-IQhE&&
HGd1*1xL
D8`xhn
QLso>8
!Sbs;-0
vvvvvvvvvvvvvvvvvvvvvvvvvvv
kevvvvvvvvvvvv
vvvvvvvvvvv
vvvvvvvvvv
vvvvvvvvv
vvvvvv,
vvvvvvv
EvvvvvvvOj
(vvvvvvvv
vvvvvvvv-vv
vvvvvvvvvvvv
vvvvvvvvvvv,
%vvvvvvvvvvvv
nvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvv
ut~Qx|
|G"9[]3
XFwB
CT{*:h@
7"{[q=
'u#~Lo
`9<c"%C
7hr$)~
:U{H)~
Aix6#w
<.`rk"Z|q;_
.www.&
MMMMMMM
MMMMMMMM
FFFFFFFFFFFFFFFFFFF
vvnnnnnnnnnnnnnnnnnvvvvvvvvvvvvvn
nvvvvvvvvvvv
-------------
vvvvvvvvvvn
nvvvvvvvvvvn
nvvvvvvvvvvn
nvvvvvvvvvvn
e----------------e
nvvvvvvvvvvn
nvvvvvvvvvvn
nvvvvvvvvvvn
nvvvvvvvvvvn
----------------
nvvvvvvvvvvn
nvvvvvvvvvvn
nvvvvvvvvvvn
nvvvvvvvvvvn
e--------------
nvvvvvvvvvvn
eeee{{{
nvvvvvvvvvvn
nvvvvvvvvvvn
nvvvvvvvvvvn
nvvvvvvvvvvn
nvvvvvvvvvvn
nvvvvvvvvvvn
nvvvvvvvvvvn
G%%%%%%%GGGG
nvvvvvvvvvvn
nvvvvvvvvvvn
E,,,,,
nvvvvvvvvvv
vvvvvvvvvvvn{
nvvvvvvvvvvvvvnnnnnnnnnnnnnnnnnnvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvv
SSSSSSSSSSS
FFFFFFFFF4
g''''g
SSSSSSSSSSSSSS
IIIIIIIII
xsy]vvv
rqmnmso
x~xquyu
wpw]trq
/@1X_Zz{}z
>D?H?P?T?X?\?
?;?C?K?R?
0)0<0K0Q0Y0b0
6P7h7t7
7=8G8S8Z8e8l8s8|8
9*949?9J9i9o9t9
:":):D:I:W:
<)<;<H<M<S<W<]<a<g<k<q<u<z<
1$1u1z1
3=3E3h3
3%414Q4a4m4v4
676f7n7v7
9[:\;l;};
:(:6:K:U:{:
8!8%8)868H8
9$919L9S9k9
='=3=H=O=c=j=
>&>5><>I>l>
?9?Q?w?
1(1-12181<1B1G1M1R1a1w1
7K8X8x8
:1:L:R:[:b:
;(;/;:;C;Y;d;~;
<.<3<><C<a<
==<=s=
1O3`3h3n3s3y3
4#4/4<4C4z4
5'565;5\5a5
636;6G6
637;7H7
898E8Q8]8
9"9.979@9
>">;>E>X>|>
1$1,1C1\1x1
939Q9X9\9`9d9h9l9p9t9
96:A:\:c:h:l:p:
;Z;`;d;h;l;8>
1=1D1]1q1w1
1L2l2|2
5'5,5;5D5Q5\5n5
6'6.636<6I6O6i6z6
:1;v;I=T=\=
=">+>7>P>b>
?2???D?R?
-0P0[0~0
021_1u2|2
4G5e5q5}6H7M7_7}7
8%8T8b8
9S:`:y:
<2<]<m<
0&040t0
2383?3G3L3P3T3}3
3.44484<4@4
5+5]5d5h5l5p5t5x5|5
\0f0~0
4<4N4`4r4
;X<N=V=
,020B0
3%3.33393C3L3W3c3h3x3}3
849:9Z9
=k=>?>/?X?
6%7?7H7
9?:E:R;o;
1&1D1N1W1b1w1~1
2`3f3k3q3x3
5,50585<5X5x5
6(6D6H6h6
7(747L7P7p7
808P8p8
=$=,=4=<=D=L=T=\=d=l=t=|=
4<6D6L6T6\6d6l6t6|6
7<7@7H7L7P7T7X7\7`7d7h7l7p7t7x7|7
8 8$8(8,888P9T9
kernel32.dll
(null)
KERNEL32.DLL
mscoree.dll
((((( H
h(((( H
H
VS_VERSION_INFO
StringFileInform
082504b6
FileVersion
1.7.38.44
InternalName
voygcuadage.exe
Copyright
Copyrighz (C) 2020, wodkagudy
ProductVersions
1.16.44
VarFileInfo
Translation
'Mivamivusotaj kukidi sasur tuhozi hemor\Hamofehexebawal fogibubivaru yuropec sareresar yivayazecahulu fimurihulakure cimeyunawizewisHLecabifele zecemofosenesam kebofidozalal fuveyadurepu wogejibetiz cebodu^Mayewuzucumaw zabofaza rufegadobafiyuy filupodujavomit bop deyiw fujazeluzaf tur nuwuwovuvixuvCBudanebimudubag cadoxekedital savogoy piyirogokirom karazis laniyos
Daporesen cic.Nek hozuheritihos kenelatokupuj jurubenidajiza
0Nukipixujabed jova mucater deyon denu jeyacidebo=Rosehozixenemac zikudizufu juxivodasede sogipamoco sijeneluhaBPipubey mofijodiday gemagogeh dupocadasesolul dasaniw pofanop viyeFBixugevilizi zonununigetu xosopu wuyukutada zowicaro furecep pesoloyub
Kenegodiza sikimec covituwutaPPuloperehodop xew pazefom lurefazuyod gesoru gadumolop facelimame lihobiboc tibe#Lovul vefewaripuyuw yofozivo lufugiBLako hifilogay potabukex hosozoteyu socahaxer febeyal pewoxacudapo=Kofitixasurumek sotuyovitevewaf wafom bohi hayacetoj yotanaha
Muxewejakoni/Himekapusacec xumayojub baj curi gofirakokiboluYGafayecixuvux now gulamakavidicu ziyuyedin zunixoregomofa zit laxekiz titejecazojaz zepobkMex polake vebul cogonijuz cihopebupepag gafewuralibodu cusirubozekati neyakibizepusub gulekolozux lacigate?Vopacuxuyur wibimodu kizenajecikapuy yekem bafaho jocusevujulavZDudegehejojab dazoponow yekumotuci fayerajuwigifi yewuxobi fakicup tiwehuravudo bezelozegu4Pecikec wijunoyol vilosaki zemajucenetile nasulunubojSicovogapetopo dupesejofijeju vufazahekov getedaw bayoce yisefacahosipi juvepuderoya tan yuzekihile sutozu2Vucisid jinejifoniviwut mon gedidozikuwoyi cihefik
Ciguxiwononici mezewi zitoro?Remapamuluyulad cajufa kuyarixin livozugenuc yisihu wecejegewuh
Pucewuhon repisotujoduxoyNJiyipixohorag deceh zoxebej nek fogi nayikux dufa sebumili mugizefilaret wegipJNugakidegamew navisoxud mamazoxe nipehaga jahuy seh cidoxevimi walulugufux*Yifon havenobawo fogabicuzal tofeloyececum
Wobetesido suvesebuxomelot
Xagurorim zedojokit hikomulaHFal digan covorujiyexabih zetod bahohibinabok xupefamebubu ficexunidayid/Loye warojeguzuco pifayudolagefuy katecu ruxeka"Zosinudosohuf tijoruha faxevofogojLPeh kezufareper yinenoroh jej bigoceyezekuki xihawul wop sumon nimoyefuteterTNecid tic fenamu bipoc pupitelawa cipubibigerevu jusofubuk wafomihaveg mob hejucibos>Dir hadinuzuhep porayevote muzegumenorihan coyufomoxo doxa rus
Hoxazawiwod fupucu
Beduyofimux xogozehuyawJNenayebinikove vuhanuzi gariluru jimagig rocesesun jim tedaj mupituhi vuvu+Gejipo puzikaha zuga mesohoyo xafexome goma
Moba futumibe(Tanudipa wupavabifinax xemamaweladen marUPofunoc temamojavopu kajenulecola harilupulaz xuyiliso xucutuhabebe yujoyer dayakorum
Gerifihebasazi gunihewinujHerudo nezetamar buvagogaxuca siroropuvuka visopuhibezem fagunilugidabo hekisiyofi hivijiko duyekuromukaniSGevo muhixihaxiyul loyeyuzuy nino duzacicip kupuzopog mey hibudagipuboy mipi lusuka[Yedifetafag reki lopucupiho rupo debeh putegabowuy pevuhevisowire jobironiv tutopazafemefaw
Pewuhomumiru gobakehoheg&Silekabecop gicov mupeyo yisapukezocazmWedidujo yow puxilin zewufo lazutahipof gixutezope yanazubowesoce rumafojuyagapoy ruwosomemicanuf cozosobotes
Bajuhozaximepo nitisi
Hilegehihedo mekanisozu2Likarivasiga wejehumubere huhugoma vijutezumav fav
Bimecefef hefayuguxogesIVeguwakan rojiyutirabila tuxij dexa jehoposabem tijoxexuj vixaxasiju gowe8Rigoniropigox kujakiyasu huba mihogeman devehahizeze fov+Yekabuhujadawe xulo miduribijiz yumab tuput:Fiparavahi digopeziluvanes zeho sas xozaxu docefamuxesizon
:Rorehil pixuhawubatejo vifupekogibi dusoje terurawiribiyoy[Kehinujiho pefigotokogalu jeyiwisafomi celuwomeyezezog pegaya todabekucigaj tobixure nawema;Vewezacuj lorumozila yabo yugigot bocetisezibatin var gemig[Wulitocedala puyinimipotama nozi jeyavo kafigapur nilela dobe jecohoveyekugix zegafa seheki
Ceh kijakadiniradow fafodarix2Zuvemabo dodap cuhuro bahudorebihoke gahodayikukew
Rerewarih`Zenodetuwopaha zecupikizeyoley yanevobi pogicavomefosaw zowivapijerav gozirenuwadif vewiziwalefi4Bozazadas huf pimigeseb hiwicut pavoxun favoreyu gok
Budefup
8Hofozopuyawa xodolivabic faleki huvidobeyawo kigepirolef
Johiwivojunexar
Antivirus Signature
Bkav W32.AIDetect.malware2
Lionic Trojan.Win32.Convagent.4!c
Elastic malicious (high confidence)
DrWeb Clean
MicroWorld-eScan Clean
FireEye Generic.mg.58fa567894c7dc28
CAT-QuickHeal Clean
ALYac Clean
Cylance Unsafe
VIPRE Clean
Sangfor Trojan.Win32.Save.a
K7AntiVirus Trojan ( 0056f9be1 )
BitDefender Clean
K7GW Trojan ( 0056f9be1 )
Cybereason Clean
BitDefenderTheta Clean
Cyren Clean
Symantec Packed.Generic.525
ESET-NOD32 Clean
Zoner Clean
TrendMicro-HouseCall TROJ_GEN.R002H07GE21
Paloalto generic.ml
Cynet Malicious (score: 100)
Kaspersky UDS:DangerousObject.Multi.Generic
Alibaba Ransom:Win32/GandCrab.052955a3
NANO-Antivirus Clean
ViRobot Clean
Tencent Clean
Ad-Aware Clean
Sophos Mal/Generic-S
Comodo Clean
F-Secure Clean
Baidu Clean
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition BehavesLike.Win32.Virut.bc
CMC Clean
Emsisoft Clean
Ikarus Clean
GData Clean
Jiangmin Clean
Webroot Clean
Avira Clean
Antiy-AVL Clean
Kingsoft Clean
Gridinsoft Trojan.Win32.Packed.lu!heur
Arcabit Clean
SUPERAntiSpyware Clean
ZoneAlarm UDS:DangerousObject.Multi.Generic
Microsoft Trojan:Win32/Azorult!ml
TACHYON Clean
AhnLab-V3 Clean
Acronis suspicious
McAfee RDN/GenericM
MAX Clean
VBA32 Clean
Malwarebytes Trojan.MalPack.GS
Panda Clean
APEX Malicious
Rising Trojan.Generic@ML.98 (RDML:AxYisjh7qfPFX14eWjXHeA)
Yandex Clean
SentinelOne Static AI - Suspicious PE
MaxSecure Trojan.Malware.300983.susgen
Fortinet W32/GenKryptik.ERHN!tr
AVG Win32:RansomX-gen [Ransom]
Avast Win32:RansomX-gen [Ransom]
CrowdStrike win/malicious_confidence_90% (W)
Qihoo-360 Win32/Trojan.Generic.HwoClpsA
No IRMA results available.