Static | ZeroBOX

PE Compile Time

2020-12-21 02:39:15

PDB Path

C:\zocatubewu\ficigeruja yopogexotuyuta\nutax.pdb

PE Imphash

52c37101f2973085af5ed972e3b0d2d3

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x0009c250 0x0009c400 7.98253650459
.data 0x0009e000 0x0046bc64 0x00004800 0.621858864349
.rsrc 0x0050a000 0x00015ed8 0x00016000 5.7702727528

Resources

Name Offset Size Language Sub-language File type
RT_CURSOR 0x0051d6d8 0x000008a8 LANG_NEUTRAL SUBLANG_NEUTRAL dBase III DBT, version number 0, next free block index 40, 1st item "\251\317"
RT_CURSOR 0x0051d6d8 0x000008a8 LANG_NEUTRAL SUBLANG_NEUTRAL dBase III DBT, version number 0, next free block index 40, 1st item "\251\317"
RT_CURSOR 0x0051d6d8 0x000008a8 LANG_NEUTRAL SUBLANG_NEUTRAL dBase III DBT, version number 0, next free block index 40, 1st item "\251\317"
RT_CURSOR 0x0051d6d8 0x000008a8 LANG_NEUTRAL SUBLANG_NEUTRAL dBase III DBT, version number 0, next free block index 40, 1st item "\251\317"
RT_ICON 0x00519c20 0x00000468 LANG_SERBIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x00519c20 0x00000468 LANG_SERBIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x00519c20 0x00000468 LANG_SERBIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x00519c20 0x00000468 LANG_SERBIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x00519c20 0x00000468 LANG_SERBIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x00519c20 0x00000468 LANG_SERBIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x00519c20 0x00000468 LANG_SERBIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x00519c20 0x00000468 LANG_SERBIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x00519c20 0x00000468 LANG_SERBIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x00519c20 0x00000468 LANG_SERBIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x00519c20 0x00000468 LANG_SERBIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x00519c20 0x00000468 LANG_SERBIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x00519c20 0x00000468 LANG_SERBIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x00519c20 0x00000468 LANG_SERBIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x00519c20 0x00000468 LANG_SERBIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x00519c20 0x00000468 LANG_SERBIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x00519c20 0x00000468 LANG_SERBIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x00519c20 0x00000468 LANG_SERBIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_STRING 0x0051fc38 0x0000029e LANG_SERBIAN SUBLANG_DEFAULT data
RT_STRING 0x0051fc38 0x0000029e LANG_SERBIAN SUBLANG_DEFAULT data
RT_STRING 0x0051fc38 0x0000029e LANG_SERBIAN SUBLANG_DEFAULT data
RT_STRING 0x0051fc38 0x0000029e LANG_SERBIAN SUBLANG_DEFAULT data
RT_STRING 0x0051fc38 0x0000029e LANG_SERBIAN SUBLANG_DEFAULT data
RT_STRING 0x0051fc38 0x0000029e LANG_SERBIAN SUBLANG_DEFAULT data
RT_STRING 0x0051fc38 0x0000029e LANG_SERBIAN SUBLANG_DEFAULT data
RT_ACCELERATOR 0x0051a120 0x00000010 LANG_SERBIAN SUBLANG_DEFAULT data
RT_ACCELERATOR 0x0051a120 0x00000010 LANG_SERBIAN SUBLANG_DEFAULT data
RT_GROUP_CURSOR 0x0051df80 0x00000022 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_GROUP_CURSOR 0x0051df80 0x00000022 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_GROUP_ICON 0x0051a088 0x00000068 LANG_SERBIAN SUBLANG_DEFAULT data
RT_GROUP_ICON 0x0051a088 0x00000068 LANG_SERBIAN SUBLANG_DEFAULT data
RT_GROUP_ICON 0x0051a088 0x00000068 LANG_SERBIAN SUBLANG_DEFAULT data
RT_VERSION 0x0051dfa8 0x000001ec LANG_NEUTRAL SUBLANG_NEUTRAL data

Imports

Library KERNEL32.dll:
0x401004 EnumDateFormatsW
0x401010 CreateTapePartition
0x401014 GetLongPathNameW
0x40101c AddRefActCtx
0x401020 GetCPInfoExA
0x401024 WriteConsoleInputW
0x401028 ReadConsoleInputW
0x40102c GetTapeParameters
0x401030 WaitCommEvent
0x401038 GetConsoleCP
0x40103c VerifyVersionInfoA
0x401040 WaitNamedPipeW
0x401044 CreateMutexA
0x401048 WriteConsoleW
0x40104c GetLastError
0x401050 CreateFileA
0x401054 DeleteFileW
0x401060 EnumDateFormatsExW
0x401064 SetStdHandle
0x401068 LoadLibraryW
0x40106c IsDebuggerPresent
0x401070 FindFirstVolumeW
0x401074 WriteFile
0x401078 BuildCommDCBW
0x401080 VerLanguageNameW
0x401084 AreFileApisANSI
0x401088 WriteProcessMemory
0x401090 PeekConsoleInputA
0x401094 SetEvent
0x401098 IsBadReadPtr
0x40109c Sleep
0x4010a0 WaitForSingleObject
0x4010a4 LoadResource
0x4010a8 GetCPInfo
0x4010ac FreeConsole
0x4010b4 SetConsoleTitleW
0x4010c0 AttachConsole
0x4010c8 ReadConsoleA
0x4010cc ReadConsoleOutputW
0x4010d4 GetStringTypeW
0x4010dc HeapUnlock
0x4010e0 HeapLock
0x4010e4 GetAtomNameW
0x4010e8 HeapReAlloc
0x4010ec HeapCompact
0x4010f0 GetGeoInfoW
0x4010f4 GetCurrentProcess
0x4010f8 GetProcAddress
0x4010fc GetModuleHandleA
0x401100 CreateThread
0x401104 GetVersionExW
0x401108 GetOEMCP
0x401110 VerifyVersionInfoW
0x401118 LocalAlloc
0x40111c SetMailslotInfo
0x401120 GetCPInfoExW
0x401128 SetCalendarInfoA
0x40112c GetComputerNameW
0x401130 GetConsoleWindow
0x401138 SetFileApisToOEM
0x40113c GetStringTypeA
0x401140 HeapSize
0x401144 GetDiskFreeSpaceA
0x401148 GetModuleHandleW
0x40114c ExitProcess
0x401158 GetCommandLineA
0x40115c GetStartupInfoA
0x401160 HeapAlloc
0x401164 TlsGetValue
0x401168 TlsAlloc
0x40116c TlsSetValue
0x401170 TlsFree
0x401178 SetLastError
0x40117c GetCurrentThreadId
0x401184 GetStdHandle
0x401188 GetModuleFileNameA
0x401194 TerminateProcess
0x401198 LoadLibraryA
0x4011a0 SetFilePointer
0x4011a4 SetHandleCount
0x4011a8 GetFileType
0x4011b8 WideCharToMultiByte
0x4011c0 HeapCreate
0x4011c4 VirtualFree
0x4011c8 HeapFree
0x4011d0 GetTickCount
0x4011d4 GetCurrentProcessId
0x4011dc VirtualAlloc
0x4011e0 GetACP
0x4011e4 IsValidCodePage
0x4011e8 RtlUnwind
0x4011ec GetLocaleInfoA
0x4011f0 GetConsoleMode
0x4011f4 FlushFileBuffers
0x4011f8 MultiByteToWideChar
0x4011fc LCMapStringA
0x401200 LCMapStringW
0x401204 WriteConsoleA
0x401208 GetConsoleOutputCP
0x40120c CloseHandle

Exports

Ordinal Address Name
1 0x493800 @GetSecondVice@0
!This program cannot be run in DOS mode.
`.data
bad allocation
penowipazisalaleyiligebo fetovekisaduvuf pokuyowewofemoxo fefoyakelabepecodi
kernel32.dll
LocalAlloc
VirtualProtect
Yav fug
Jab fupucu
%s %f %c
CorExitProcess
EncodePointer
DecodePointer
FlsFree
FlsSetValue
FlsGetValue
FlsAlloc
runtime error
TLOSS error
SING error
DOMAIN error
An application has made an attempt to load the C runtime library incorrectly.
Please contact the application's support team for more information.
- Attempt to use MSIL code from this assembly during native code initialization
This indicates a bug in your application. It is most likely the result of calling an MSIL-compiled (/clr) function from a native constructor or from DllMain.
- not enough space for locale information
- Attempt to initialize the CRT more than once.
This indicates a bug in your application.
- CRT not initialized
- unable to initialize heap
- not enough space for lowio initialization
- not enough space for stdio initialization
- pure virtual function call
- not enough space for _onexit/atexit table
- unable to open console device
- unexpected heap error
- unexpected multithread lock error
- not enough space for thread data
This application has requested the Runtime to terminate it in an unusual way.
Please contact the application's support team for more information.
- not enough space for environment
- not enough space for arguments
- floating point support not loaded
Microsoft Visual C++ Runtime Library
<program name unknown>
Runtime Error!
Program:
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
GetProcessWindowStation
GetUserObjectInformationA
GetLastActivePopup
GetActiveWindow
MessageBoxA
USER32.DLL
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
HH:mm:ss
dddd, MMMM dd, yyyy
MM/dd/yy
December
November
October
September
August
February
January
Saturday
Friday
Thursday
Wednesday
Tuesday
Monday
Sunday
SunMonTueWedThuFriSat
JanFebMarAprMayJunJulAugSepOctNovDec
CONOUT$
C:\zocatubewu\ficigeruja yopogexotuyuta\nutax.pdb
g|1HZ|
&h,l7s
anz(,<
+0n?`@
OhGs9*
L~,9:</i
FV"T;[
kOHfT7
wx!d#2
yEGSJEJ
z8y5rJ
q>/da7
':kb#Zz2Z7
@pO\!U
)>uO l
]K4X5.J
`Q<'!>M
NK6{r
Ns*GHl
_o940y
r?cm0=
OWY..-
'OWpX$N
mwcel(
sT|A'R!
{C`Imgn
#DhLmL
[nCiD,>
1z.~`%~~/f3
|~W<3Foo
H$yv2B
NM33YJ
7%Db]q
@in;pTn
;'iG!?W
7.ze!#
K@4'y#Fg^w
oOIV/n
v&WuYW
a\m2Tr
MdzpUS
+W)v^mc
_):b7=/)
+CS}i}
$`=hbE
p*6Zuna
Msgv]G
>8tQ<P0
jI/)h[L
CzuN0L#
UwxXRqF
'dQ6g^
%B~l86
CN#\-D
.`qC'
/8!Z:p
xXeJC$-
=z "e`[Q
zm}w3h
DuFiz@
yM7ofk
2!|B9^<I
%xSav[c
lOF|AA\7,
<B,a}g
l_QVrhV
4g9`%
aH14whY
y]\8pYW
*uVuw[
"+0~Xv.'\
B{aB"
Ma-m%q
*[" U8
'RkZ3>
;wIph#
H1~0bw
&='^x1
N<XOVK
s}rUWt
4CJ$y[
8n@l1e(
ZN2p"l?
3zZdZ
Dj?RxB
R8%1F-hD
Y-@GdBA
K]/&Hd
$REW_u
PAc{$7
J|;<bBm
k0$NoQ
8(y*1Up
0gfb?L
UD@~[VJ
=@H^eU
DdQUw8:o
.gLnn
>x6nGaE
S1y{}>
vjM.r3
ltBpS|}
\xH^*O=X
P6/:!"
R[WCCh
4]c"3,
]iB[7A
R$~-k"
.Hxob~
N]pE3,"$
)XfpSD
B<,TV_
gZAAfH
BZQ<f^
pA=w^I
CK\XM$
WPz-m~
6H8n9*
\o}FFx
SQl,@BUrT
9@^N>x
a\FLNL
h8Q9"p
r_HSs%
ilhELwrg<+
[T2#$`
]If#3;
D|8/p:`
3Q^FM
~0zP&w76D`
Hac6(,
w|8@#2
^,r/SV
!|sa[c
2rk)7B
C=kpLd
F$mJ4!y
84@3t!
wZIr,u'
l*x`V>
VfPY0{
HAeOC
HBmR_>^q
7KO'%o
nh}?[,
;9Z !"
dJyE3|
[XS@uJ
^q-=rr
|jZ1orB3
=h}qG$2
M+Xf\0H
..JGoR
VXEzl#,
@5uF)|
Sn6v]l
xX/hFJ
|l*-,A
!+r<8H
VIb1u]
ZYC#>k
XH#Zj2
)h>exi
?k3?L
:\E%T
cv]J/>
Vo$f,H4
.`lSi2
fKw*(`
I"HQh^
f<X)RA
>Jsq#!/
Aw?{xl?
oY-,m
2}MITN
rkC^p&i=h@K
/zKhC{t[
;aK8nE
u:ax&o
p,J78
hjWRB
Z2t1jg
!6S{oh
}MBkP
K{%`);
yu~XxW)
<o3:W5
e]|h!:4
q4rMc^
)7K$je
3ijf9*
mpka?A:
KzF.NNU
p&"4"y0
'*.fb
W,3qWl
0Z*k=.
/suBdp
6V/8r;
-K#"%$
|4|49p
Hg5~z}
fA9)2&;
ovwGZ .
T}1w([
HsaOji
,/1saF
}"b>P$F
#0.7PO
$)9Lm\
F$Cmf
)9'Ag
XVo+P]
?SVh^\
Rh(Hng
p6cz'*
n?Gw#xx9
JlN\}M
,HhY_
&>{&-=
iH[?Br)i
% y<o>
SsM7?.
aP2X-#
b9x=A#?
'0{eWsu
DjW3R}
PkJ/J?
:02\K'
CgpO,~]
_0#U)]3
t(2=Hx
c*qj?9
Wk^}q\
T37EJ\
?-~EZy
JcXe>{
U<l;jG
'[5<ra
=E0"U^
vd0~%5
q\uK~
j4}ar0
ztGo2{
Q:bc((
q|;"ZI
(UtV@
1N3INon
>rX|-
;Of$-k
J#pnPS
63&22.
4U[3G)M
\/T"@R*
"4RR~<
^6E:+1)
8^j`RD
S= 6Z|y
Ji}H&1
G$#C,4
"iiyG
\@LP\^
m!RAY!)
/dJHE(b
g;(9YG1TE
Py,;`@
w'7-m<
B4^rA(
dB*EOk/
+%Slc<
s"C6 /n-
|Z[ X#
+'^SsCR2
'F\ms97
KSviKf
4J;bpj h
Gg0No$o
L].Y8q9'Q
:&|?vm
,7FPxZ
bDIAec
~-;";S*
!4IN2w
)}]o\44
2yDmhY
*zD#9/%
D%N*t)
$.<oqH
BH6vdJ
?n<B{g
!qzw*+
S!l,Tu
|af":58
d5JtQB
74E^`W
2_p i4
UcTbvf
:TLGBNb\<
%!Xyn
8Yy6$sz
:L=gN-6
b2vl'
~W[$@4`
[tq5Cj
mMT\ed
sA/CI|
rM>96z
pKhv%X@
pZp\U`
S3w|Y?:K
6@.N@,
C6V~~
Kv='^[W
gye]`]jb
J.ao%+
I7A8XY
=s=4bUt,f
j\C7q&
+b\}0xv|
K\Vz3o
(H]|a1
a-MxOq~
~}AR3x7
cD\*SliFI
MGgpAv
:pWC]7
/JC=}V
FpTI]C
}rV$:?
CXU'hflo
n0O9i-9s#
P_JlZj
o8vkM)
!4xhAj
my}KF@
v>QraU
)`!^1a
2}'|-D
Yl53k*
R[%zwe
@_^Ruv
q`"d&Z
)W?xRP
?3~#{N
?~yZ)(
TR=wz2
Z|W%wHbW]$P
lzvtM!
#*.rV'
:9Xn7
\/2Yn
nEQ}tOQZ
V`j%UYb
dXu21l
Xq5[IEfG
GeA15m
lDj^6*
.zpQC;7
j qp$p
ju'*S$
#=0+@I
L[l=G<)
7Y%0~i
_-1_'#
^B6n\S
SL^P@#KMH
^[fBYy^Yt.
ZIoj(rD
`@T4EJ99g
/]Mf!$
k&"Vmb
+M23*r
mTUVnvS
XyUZbR
_Z~oKo4
[F@da%
$Z%r%<
o\*Ofk
QwOjF6
Xyolak
\v6m=h
O1?~OYUlw
].(X+0n
Ej"o.jpUK
C9tEau_{
Cb"EkX
S=4c:p
7pd!BP&!^
'>aUNI
H"IUout
Lpv% l
4B)]tU
baf;G"
/gt;kg
Yjg|Z-
'$<Vly
;gM$'J
u[VH.0
mT9RAp
/m<G8Xq
zNP~1*
Y5.D|w
.;0yup
s+z%L+
fAnWx
w)bFr"
+\BJF^^
4y+qfb~
X@/%k[6$en1
ZT8(y
q Ab]E
9>?w=d
iUqz85w\S0oO1E
;kkVC$rD
E/TWIP
nr:2>~:k
p~&vIu
`3"\&Y
_Fa;fCiENR
`gEbSGI
JpAD0'z
A9B.5a
UeGF:m*c
Lyz5c_!
mj5w;N_
FTlVG
{{)%%h
KZoHa:
FxfT=M
kecS>@
T(@`"9N
6#DQbT
0xPv^;
gVMI^>
@lY:s^
XClX"t|
s]HB6.-
3cs{`ut]
icE47
Wf5c6T
S32a*
9>7Z.Dnhd
qau<wr
ww|/._
AH!.^H
#-}x%_d
rusw{3
AE^VRgd
'}>)]K/
["8| wC
{jvoQ"
<(G5RZ
L+O'DO
d`91f
6f~:KQ
m2;%!&6n
[.yDrD
cglZ(P
u/E=^U
(bn"jEIl
)7)_[j
WZAPtc
e"3f&rksrx*
!)YPpA== j
(YETOPw
duPG5d
LmY43
V_r'e6
sI(V&]X
#EqXa 3
$C1@up
R/J($"d
I6<:I
ScFH2l
D{}q9V
[U=k?,
6v{}.@
MluVh_
H~GY}m
bUmM)r
}'LL3Y
)T"Q,+
)#9wJu
w|%W2E
[CeM.%A
Ob'm(
L8(IQ|
df/'SXZ
M!K1rV
jt4N=y
B!]+r9/
EQi0 uk
QNt(4pE<
4N".HU
$*`ER-
Yc'U+U
eV+[_m
}$Y ,uFv
\>~D'T\
0<6p<4
2@Y*{;_,
45xP<:N
$cQUWS
=YQ{!y
MOc-\1|'
+B*o"+
88PoKwr
e7AMq>
2v<x|3
/ CqO&\
RjqLqIB
Ng%^:J
CjuZ:&
7|36)I
6{2lD1aJ$
cGcXP2
!3snJ,
nqSqge
4qXebx
5vyfsH
{&'$#Z
i'V.)X);
\t-Ec<
YPaL~F
AWyrq?
8UrS)H/Y
v3zYX@#
RJU&P.
\G\STL
{Sg)9[/
We5m$(U4
j!GM,9
68fb^V
~g<C?K
GkqpYN
pgW\a
-R[0A.P
vSyt<Q
45}_Db
a_n8?^z1g
k{y=?\Q
}:,qA/<\u
dU7<I)
FBTev{`e
pfUHJ]R
P+One3m
!BZ"~so
^4<()R'
r%F3#R|
)#`p.'\D
1=VBA-
|9B.RX
$sR^S=l
,,2Of|1
XN'rP.cg
J#2J.3
AT*HSp
U6R%`u
Fm2Ge3d
>4na##@
Ryo,0e=
02DuJn
"Suq^/
B_PPP`FK
`v00_2
H)5/Kv
yX\ |
F(MLZ\
0"WPp
/j'9Bt
`B0kKocK`
9tm/'y
<p{VQl[
Wr5clk5B
~\T@Il
1*o'Z
?0`cAF
HKCN?+
HWM:)z
[MtRnH3
Z.BH&<3
GzbMj&
CsG XJ&
0FN+"j&AQv_
VXBc*=
B3fX}D
+..521R
2bvA`
?}|+J;:o
jrste!A
Xz8h#_
6u0s_F
yNtGPXT@~
ef'o,B
4e"XTR
>y[U;?
x?4QT>C
jYDf@Z=
&YykS]
)4eD,W
Mye*3&.
+)-yA,
/Xj}>3
:aqAf
=6"n 4
5{jc=Z
aX4::Z
&o'LC2
Q E/m8/k
2<%xDe
JlPqBok c
U[O%RD
v]yPmtQ
KMt5L"
g`~q2K4
S{{AJW
w`C'Tt
ac^Im[
*o;4``
X.4}g-M-7
_y+'~ej
}.8Wg.
IBm30*
zLXH'I
q|qsrk
KawjU:=%Y
sgTpFZ
< N:ge
0,0&!R9
/JP6g$J-
#S*iS
5`>j8XHH
TH)5U3
o[,Lh
%X7tm)j
4F9{JG
{sr Z7
\;dqqH'X5r
%9`n07 O
%a#my|
\*wwd.
>DvcK0d
0R991&!
t4I*<p
{k'N8rb
gvXCba
2 @$Cl
]W>`]r\6y
5:/,Fq
I/!Bqo|
9{|m4_D
{Gih$`
i^UD3h
4S3h`rSuG
/ZD[[
E' #"\A
Wo*_(sx
4rl<Oa
7Oj=$.2
4+fip|
K`%~!+
v_fsZh$%
JI-A]/
$3\bcPu
@& i2y
3A\O2*:
WrseT}
.+i@*`,
-qXrOcl
a|m*u!
uU`$ |D/D
j7N3Y3
oIIC@)b
(rkT6&x
g/2SnD|
@{lYZ`
tj_\1)
~'I+2'
H1-2orn
n\d.M42
"dyHQ>q
]ij)3l
"k>d)G
(qFg}<
+QhvU'
wh6@J+
X*uq\U
KtL<(y
p*EYb`
C-aF*k?
LG&7K/
fh9~{V
3*xTce
A8UU|f.2
-5`NI
ToCH[r]!
f.`wZI9
!,p?8v
/^0jpa
yzkLy=
al[v{~y
SNo{5>
),rceT7
[E8fxS
]D$R(#P
fN^DLm
eyR32i
uH_>xr
ywq.{o
0ZKk U
?-hj{iZ
G7(3"#Cq
_*o=8&c
m(Ip&J
Iy!I%jb9
OSkP,E
MDD=TIoO
jpb+;4
SAxru$'Q
S}Y_]Cgg~-
xSzXe
:OxQ y.
bEIO'<
U?9^WQ
V:I+[u
brgU<]
o$>p3Ar
1:`kKS
IGK$P*
J'josIAeD=xf
P?7j#iU
{F|[dG-s
b^ER,c
UK%gni@7
*Pu{9=
#+."zs
*]j?-HA
bfXdT{
twf)_
#(+ Rs
NOp0-;
S*&kDXb
3/[e#?
>*!\21|
CbE@U^'KU
&M,::C
UUuv2!
vHs76+
8?eTFb
0c7.$H5
vD[u1I~;j
Z8\3C
Rceopw
L/~JE5
eM*ZGG
%#E<5
KeLN5f
!7R(D"j
Pd{Tii>G
2)'A?C
IH{gKI
bC9}u'
'$3UQwv
x)}wa,5
]?T2z-cx&
'X.7~~
8|}{TZOH
"Q@D
A*7]>W
]3PB8c;
&]F# p
ztTzQE`
qEy,'5
r{sqE}
VBwII#
"%eQTC
!Sc!LTz
nexDDe[D
3Y`:bL
Dk&AFM
a3ugo$C
[0Z9|f
K#8+-_w
SWpO=T
*DcG_O
cA,l]w
,!3}VBQ
}M1md5
MFI<>"
oY@D~Z|P
l_Q;GX
PUf;U"
"XK~^[&
&)c4`
oRG*5B
ognn(UY
AKV`ET
PMTdOK
_1qcn}w
xM+#P^)4
xF<5,R
yf55nI1
r7& eKA
YPyC`-
QRgs'E
_MTP#K9*
=x00\s
rZtQ>UW
,1-w(1M?e
{==|bbB
~g_1p
i^+\Y_
zsY`\JR
(LN 8
"+|"oW*
0_l3${
'"O;9L)
D@p{~=
enqDQ8
iyJkM%FQs{m
MaYL;f
B5pTrl
*s.#M
SAgpZ6
fjlI.d
]KCX$%
q)+A-{'0
t5]]Wc
FyfQUj
xtvPkF
L#IF78
\-5;a
&Mu-o0hdc
2J0b3t
x^cu{,
X5/ZTdG
r!"CIC;
tcV~l
(in`\Y
0aY%w0v
=Cep]`O
]j(ab@6'
VI9.]m
P!e-B/
*/1:C?
aAt<DA
YY$Y^M\
v8ML<;
p_(6$A
+?OjGjH
TE=ufs
~X-x>^B
zt]$)~_.
{-*<GE
rH<sI'#
VV7W>rp6"
%ObU*D
dHrAx?
Br_"vz
h.B|7vIj
p>PM+i
r{;*/K
XOScPO
9fxa^}
ovmc9i
?9Y&rI
WgQu}ga
h9mwz:
CXcL'%
^Vme{e
p2:|Dq
uG#nXB
"%_\l'
AA,)*#
>.<i<IG
*j<vkY
'O#BCh
/~Uf}OI
8B^SPg
t~#&:J3
E_1I0i
hmEBna5O
{jGp4E2
^5'$CI
M&-B90
An>U%O%d
(>Altr0_
WXFh#fZdG;
V23ilMJ
eA7OJKI
cdQ3vQl
l+i"X?r(
_0/i)>Z
dTTw M
2T$Ro
Ak!"(%
+I!7nR
So+>hAx
/3^qji
cd1~x\
nJ.Q)O
ZU*dsZ
3Ct.#|
b%/UV:
Ow}{(B
\^su9p
o0a JK?_
AA}<);
9'>R}YY
Cau5=6
"QP5ZD
|Ko{2v
kn2(!#
0HbWPSq
+auWv/
3,ni{,+x1
2|t@LT
JK;AoC
#^UObP
C*$f0Q)
Y-&ELMgk{
[0(yC}
GNw 8O=
gT*oh9S
RE>4&)
\O%GZo
fc2sx&
v}HB<~
+a@3{l
=e!'}}
^;,Qp
3s$Fo&@
|Bmxi[bRr
,*.=P$
=.s+eZl1{
W#(|&k
w$NbS\Z#y
Cxs.Y2F
AHY}3+`
gnf3V}
y/.,}3z8
S@C8Nh
#<?[Cy
}oLE9ck
`X:VO3b
#dZz@N
$g\+(K
lB\Wg?;
fc5Bdy
^"*' Kn
#*fV[)
k`J&)1
%w2dk!
=<{JRR$
U>?,#i
d.oET3
3r<M'8
49+8Z(
ZO/,9q
#6>/-*q
Q?(=sw
j[<)rx
SB1&a|
(Rp$H_
<eR$7b
p!G=G5t
Sf8jd!
\)43y"zA
f_FcY2
=2+B1l9
;jYd;@L
:X [=(
Dj-]-y
a vxLR(7f8
'L\emU
'5Vl3
(,sj/=
MxG=PF
G.Ez=75
n& p(!
6 Ec>O
FxVyav 1I4%
q'Z+O-
;02/b
i_/'HW
/80q>awD
$]BUfws4
GEx#:{
$rV#DM
4I1CV4
?S]^&l
16|<{P
V|2Y8S
xVfg$f
^+-L^I^!#
#<%HQh
FvS/
Brn/CL
2gO>'
X{Bkr&
.}y?6|
}];[_w&
C1/7&[
M6jkM|
^-*9]E
|:N=-E
r$Lyy%
JM5+N*
<$!\j
Kb7tw3[_
ORZik~2
982&!!c
{}9CBe
=qP!<L
dTsv1jTF
(WIO:7jL
~#'7i7_
-i'/EO
/awWQX?
/mPN.5
IhR+uS^
U0s|pTg
0"u'a^x
9J~B!WO
+ H>((O
r59&GhQ{N
$)|E_j
tJ@eca5
H^TaR:>
xJ #EL5
d?hdc_
t@JN*BI
u.zGL.(I
p;T\aW
NOwLUR
^^&!CT
5Bcg/:
k&i`@R
3O-S]R
=v\?=)
zXLUTiz
O.:09O
]Mf!Le
V_.:'X
$IY"WU*
#92&q.
D7!Y"Z{
mPb_>(O{C
:;}bq,3<"
fxuWTG
@,WbB2
h,hU7T
\SUd*$!1|
=Flp|{~2&
VVVVVVV
E@XjdB
E\bcs%
PSSSSS
uBh+]I
j@j ^V
>=Yt1j
0A@@Ju
0SSSSS
0SSSSS
0SSSSS
URPQQh
PPPPPPPP
PPPPPPPP
t"SS9]
;t$,v-
UQPXY]Y[
t+WWVPV
InterlockedPopEntrySList
EnumDateFormatsW
LeaveCriticalSection
GetConsoleAliasesLengthA
CreateTapePartition
GetLongPathNameW
GetUserDefaultLangID
AddRefActCtx
GetCPInfoExA
WriteConsoleInputW
ReadConsoleInputW
GetTapeParameters
WaitCommEvent
GetNumaNodeProcessorMask
GetConsoleCP
VerifyVersionInfoA
WaitNamedPipeW
CreateMutexA
WriteConsoleW
GetLastError
CreateFileA
DeleteFileW
WritePrivateProfileSectionA
GetPrivateProfileSectionW
EnumDateFormatsExW
SetStdHandle
LoadLibraryW
IsDebuggerPresent
FindFirstVolumeW
WriteFile
BuildCommDCBW
FindActCtxSectionStringW
VerLanguageNameW
AreFileApisANSI
WriteProcessMemory
RequestWakeupLatency
PeekConsoleInputA
SetEvent
IsBadReadPtr
WaitForSingleObject
LoadResource
GetCPInfo
FreeConsole
SetConsoleCtrlHandler
SetConsoleTitleW
GetCurrentConsoleFont
SetConsoleTextAttribute
AttachConsole
GetConsoleAliasesLengthW
ReadConsoleA
ReadConsoleOutputW
GetSystemWindowsDirectoryW
GetStringTypeW
BuildCommDCBAndTimeoutsW
HeapUnlock
HeapLock
GetAtomNameW
HeapReAlloc
HeapCompact
GetGeoInfoW
GetCurrentProcess
GetProcAddress
GetModuleHandleA
CreateThread
GetVersionExW
GetOEMCP
WaitForMultipleObjects
VerifyVersionInfoW
WriteConsoleOutputCharacterA
LocalAlloc
SetMailslotInfo
GetCPInfoExW
SetEnvironmentVariableW
SetCalendarInfoA
GetComputerNameW
GetConsoleWindow
PostQueuedCompletionStatus
SetFileApisToOEM
GetStringTypeA
HeapSize
GetDiskFreeSpaceA
KERNEL32.dll
GetModuleHandleW
ExitProcess
UnhandledExceptionFilter
SetUnhandledExceptionFilter
GetCommandLineA
GetStartupInfoA
HeapAlloc
TlsGetValue
TlsAlloc
TlsSetValue
TlsFree
InterlockedIncrement
SetLastError
GetCurrentThreadId
InterlockedDecrement
GetStdHandle
GetModuleFileNameA
DeleteCriticalSection
EnterCriticalSection
TerminateProcess
LoadLibraryA
InitializeCriticalSectionAndSpinCount
SetFilePointer
SetHandleCount
GetFileType
FreeEnvironmentStringsA
GetEnvironmentStrings
FreeEnvironmentStringsW
WideCharToMultiByte
GetEnvironmentStringsW
HeapCreate
VirtualFree
HeapFree
QueryPerformanceCounter
GetTickCount
GetCurrentProcessId
GetSystemTimeAsFileTime
VirtualAlloc
GetACP
IsValidCodePage
RtlUnwind
GetLocaleInfoA
GetConsoleMode
FlushFileBuffers
MultiByteToWideChar
LCMapStringA
LCMapStringW
WriteConsoleA
GetConsoleOutputCP
CloseHandle
xifacawu.exe
@GetSecondVice@0
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
TIQ[QQ
OCOCGOe
|]]]\]
qqmmxmgm8L
/FAzm;5
/IQjE((
AYY~~lw
IHf2*3zM
D9`yio
SMtp?8
#Tds=/1
TW~~:5
6CO`OG
x8#4)8O66`8
)4OQ`ee
<6QQQD_
c9@b#+I
"<m~d'r
=jr+${
'1_8q
>kz7v
A4_vm'W{r7e
iiiiii
iiiiii
iiiiiiiiiiii
iiiiiiiiii
iiiiii
iiiiiiiii
iiiiiiiiiiiii
iiiiiiii

lihitomozecavizudovinegefi danutimir xuyatedekoxijokayewewopom
fohipuxejizokow
luyokacedagus riviwatef mifayoxehumenamakevehekulavi
Pedocij tib kicajubate letapewak tufezixavis
Patejeyiwedifa
mscoree.dll
KERNEL32.DLL
((((( H
h(((( H
H
/ P6pL
,/KPip
/-P?pR
/ P6pL
,/KPip
/-P?pR
VS_VERSION_INFO
StringFileInform
081504b6
FileVersion
12.3.67.16
InternalName
voygmuaroge.exe
Copyright
Copyrighz (C) 2020, wodkaguds
ProductVersion
66.8.14.85
VarFileInfo
Translation
DPufepu menefe becedecocu bamayegibovur fecatekojurire nudajubikuwotu
Jawenu pit
Votohoyidi raxiyaxog
Futuce porifucocixeyPJabidisuwaw ditepanojejufir peviyolusakuxu bagoxonicov mezinokuli hakibelebicazoUFirupevocepo sericola yerakap fugayome cepaluvokigegu mif muredobalebif cehafularabad
Pigofiyoridux
\Zezepiyuwiyo vahebibe lesoromexagosa gidazahiro voweyodaxige panace mudibav tikerap sinigami Jepofuwam jal novelevugagu ledabEFoji dugetajoxoyubu nivuguyuhusos vewoworom zig vozet ruvabatugurovepMMaxijosici vuzagesayosi dizopemonus hokejila penivupowefami digetajoluda waci
"Guzocizidanipi camitew yidalenixewTXijorewubevaw juroza hunusufajagugur ruzepeyifero wofo pulisowuduzuyol xecekoy wesim
Favu gulujeyicicuyug pib&Nirid yud vasugeculotog sokipebi coxim%Wocacu nadivesojuka gok kitu layuvipi^Cane yosetedehohohim xorebulura kexat lumamiduvekonu cifofemagu minaca xacuzah vuriwadehinokumOJica sokusurenewezut gecalusonuyewa daketujekuw mufe nel vomi wusirif noxixorocAMiker rexikusoce kezazibewugiy cisukaveci domixuxu tuyizelahunayiHDemab muduvubo morewuwaroxu rajifajol yilelucapu saruligevabuceg piyatof?Rojesurigupuh yitaf calas befihote kisux toxoyoke ciy key mehemyPejivosekig legulewomowad hipakapokifec geriboyasayezi yojunasawil tavebenotepej remo kacilixedicacop xetuna vaxowuwewesa
UFewosuhiji fidofek vigepavigafuwo wosaridixom vuvezus wehij payavib neravuyapoz yidoz
Wogefo sejarimi
Rarofip
Detavaneta
Yimikekowapiyev-Rinovoyefice vurolajo yamotohikemax yizopevifEDozuderadixokun wadejuvodafig guvitifejoyunam xoseyerasec gamopi guhaXDukoruxolarak siv xirecakecik sipoxawepacuze gaxaxebayaro loz gozukikopewuju zoyoduhosig*Zonosodugexa subukinija tukoj goluvovagigi
Sasodavocuhucoj ganabekalo)Pejawayux jovayo lomuresoyeluk suhufiyoko
Rucomavahixelu petobevezu4Wopejimudoz jiyehegavido wusoj dotadoradox kajuxiwatOVufogakozon dabunebofoxariy foxomeculivajo zabizal tohu mipuhu nanobuyugefi zecoSuvefaxezi tojizesabogulup wujojeten nozafowad zufamehetuxuxi gopuzidusihujo tenifasem gixiwazir kumucezazavama
QXadoyika voleluxahujah yace kekifazowocac wahayaro hizoba huguzunux rarofajupiwin
Jarawud xopiMececuv jumu jowe hapavucatoyis
HikinokJexicenokape pumudemeliluli bekeRujohuj lutob liwohenivor verunukix codejokezat wekoravucehexe biporegoji didefelemudes yepewe bokuyafRejapetaxij vicaguhe duzoyumucuxa yiza gavavuliworuze niragofejavoho tezurozu hezavevej wenelenit fimi=Tuxu juxupir medi bimude domujut saxovefin jawironolufe ducis
YamaWTekaxi baxav higata babojah vukodo bobahagafonexiv lowimecoze gov wobehoxo yizilejunacu!Gubuzakuziz poyodiyetanatu fefuweUKihavifedowab sigicesoya raloduremomobe jacuhupe toreha homajafuh mefoleda fivokireja
JKoxunuvuyoyec cajevayitemexa rezehonavetid diyobo tinonu sibefaju nakunukiJZoresohodu zehubiwikihoka puzolo dezufepuyu fivudilekesir xameti dagotikor
NodexijefAWipawakavavuji hivaf zacohidefaduvoy poc sevekobi lobuwojo mileja
OJutecepikorolaj sewul nibuh caromuwekafex kipewec bazibopo jepi sawogixohisofew
Wiveyemosaj bemetubuno
DilekisCXesav tolericuzusi dalexagi fesicebolebox tage kagusap peha dikuposCMetilovusujodoy sofazugemit caciyecabi yiz xuwaho bumejayi burihulikVakilel jaruhupejecofap deveburipis zijogukopumed yobizexicimu xidacilifanew tisuroriv nexena joxojivuvesif6Guwigan vokupayolozis canubodiva fekiracud ravezobujuz
Mofacad
/Lubusacix bexarepume xofuyoxipirase ciyakoxivut
\Xiyi purayigu cotenubomamexur vizahiyewobuc vodosotazayey rax nilexumuxu fey golozileruheyof&Pujufaw wise ledayunedowasol xolopeguwQNutilonegogacef febokoropinaj ciruzoxoj fugusamadosa fuhuvo ricozatebo riroxolara
Xap tefefunu rekil yefiwizijuOFogocokaxu dumowecabo tegutorilef xazomajidubuyic gar gubixayofawa genanepevomi
Antivirus Signature
Bkav Clean
Lionic Clean
Elastic malicious (high confidence)
MicroWorld-eScan Clean
FireEye Generic.mg.e6bf9a1d8f14d2e1
CAT-QuickHeal Clean
Qihoo-360 HEUR/QVM10.1.AB77.Malware.Gen
ALYac Clean
Cylance Unsafe
VIPRE Clean
Sangfor Trojan.Win32.Save.a
K7AntiVirus Trojan ( 005690671 )
BitDefender Clean
K7GW Trojan ( 005690671 )
Cybereason malicious.ff0761
BitDefenderTheta Clean
Cyren W32/Kryptik.EMQ.gen!Eldorado
Symantec ML.Attribute.HighConfidence
ESET-NOD32 Clean
Baidu Clean
APEX Malicious
Paloalto Clean
ClamAV Clean
Kaspersky Clean
Alibaba Clean
NANO-Antivirus Clean
ViRobot Clean
Tencent Clean
Ad-Aware Clean
TACHYON Clean
Sophos ML/PE-A
Comodo Clean
F-Secure Clean
DrWeb Clean
Zillya Clean
TrendMicro Clean
CMC Clean
Emsisoft Trojan.Crypt (A)
SentinelOne Static AI - Malicious PE
GData Clean
Jiangmin Clean
Webroot Clean
Avira Clean
Antiy-AVL Clean
Kingsoft Clean
Gridinsoft Trojan.Win32.Packed.lu!heur
Arcabit Clean
SUPERAntiSpyware Clean
ZoneAlarm Clean
Microsoft Ransom:Win32/StopCrypt.MYK!MTB
Cynet Malicious (score: 100)
AhnLab-V3 Clean
Acronis suspicious
McAfee Clean
MAX Clean
VBA32 Clean
Malwarebytes MachineLearning/Anomalous.95%
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Rising Clean
Yandex Clean
Ikarus Clean
eGambit Unsafe.AI_Score_93%
Fortinet W32/GenKryptik.ERHN!tr
AVG FileRepMalware
Avast FileRepMalware
CrowdStrike win/malicious_confidence_100% (D)
MaxSecure Trojan.Malware.300983.susgen
No IRMA results available.