Static | ZeroBOX

PE Compile Time

2020-10-25 05:24:43

PDB Path

C:\vahelevu\zesucohi.pdb

PE Imphash

7780eb9cc098185992365509d7637fd7

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x00059b8f 0x00059c00 7.95833397376
.data 0x0005b000 0x027469a0 0x00004800 0.629394402428
.rsrc 0x027a2000 0x0001fd70 0x0001fe00 6.39688093473

Resources

Name Offset Size Language Sub-language File type
RT_CURSOR 0x027c0400 0x000008a8 LANG_NEUTRAL SUBLANG_NEUTRAL dBase III DBT, version number 0, next free block index 40, 1st item "\251\317"
RT_CURSOR 0x027c0400 0x000008a8 LANG_NEUTRAL SUBLANG_NEUTRAL dBase III DBT, version number 0, next free block index 40, 1st item "\251\317"
RT_CURSOR 0x027c0400 0x000008a8 LANG_NEUTRAL SUBLANG_NEUTRAL dBase III DBT, version number 0, next free block index 40, 1st item "\251\317"
RT_ICON 0x027beef0 0x00000468 LANG_SERBIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x027beef0 0x00000468 LANG_SERBIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x027beef0 0x00000468 LANG_SERBIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x027beef0 0x00000468 LANG_SERBIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x027beef0 0x00000468 LANG_SERBIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x027beef0 0x00000468 LANG_SERBIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x027beef0 0x00000468 LANG_SERBIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x027beef0 0x00000468 LANG_SERBIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x027beef0 0x00000468 LANG_SERBIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x027beef0 0x00000468 LANG_SERBIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x027beef0 0x00000468 LANG_SERBIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x027beef0 0x00000468 LANG_SERBIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x027beef0 0x00000468 LANG_SERBIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x027beef0 0x00000468 LANG_SERBIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x027beef0 0x00000468 LANG_SERBIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x027beef0 0x00000468 LANG_SERBIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x027beef0 0x00000468 LANG_SERBIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x027beef0 0x00000468 LANG_SERBIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x027beef0 0x00000468 LANG_SERBIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x027beef0 0x00000468 LANG_SERBIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x027beef0 0x00000468 LANG_SERBIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x027beef0 0x00000468 LANG_SERBIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x027beef0 0x00000468 LANG_SERBIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x027beef0 0x00000468 LANG_SERBIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x027beef0 0x00000468 LANG_SERBIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x027beef0 0x00000468 LANG_SERBIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x027beef0 0x00000468 LANG_SERBIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x027beef0 0x00000468 LANG_SERBIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x027beef0 0x00000468 LANG_SERBIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x027beef0 0x00000468 LANG_SERBIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x027beef0 0x00000468 LANG_SERBIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x027beef0 0x00000468 LANG_SERBIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x027beef0 0x00000468 LANG_SERBIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x027beef0 0x00000468 LANG_SERBIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_STRING 0x027c18c0 0x000004aa LANG_SERBIAN SUBLANG_DEFAULT data
RT_STRING 0x027c18c0 0x000004aa LANG_SERBIAN SUBLANG_DEFAULT data
RT_STRING 0x027c18c0 0x000004aa LANG_SERBIAN SUBLANG_DEFAULT data
RT_ACCELERATOR 0x027bf400 0x00000010 LANG_SERBIAN SUBLANG_DEFAULT data
RT_ACCELERATOR 0x027bf400 0x00000010 LANG_SERBIAN SUBLANG_DEFAULT data
RT_GROUP_CURSOR 0x027c0ca8 0x00000022 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_GROUP_CURSOR 0x027c0ca8 0x00000022 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_GROUP_ICON 0x027b22f8 0x00000068 LANG_SERBIAN SUBLANG_DEFAULT data
RT_GROUP_ICON 0x027b22f8 0x00000068 LANG_SERBIAN SUBLANG_DEFAULT data
RT_GROUP_ICON 0x027b22f8 0x00000068 LANG_SERBIAN SUBLANG_DEFAULT data
RT_GROUP_ICON 0x027b22f8 0x00000068 LANG_SERBIAN SUBLANG_DEFAULT data
RT_GROUP_ICON 0x027b22f8 0x00000068 LANG_SERBIAN SUBLANG_DEFAULT data
RT_VERSION 0x027c0cd0 0x000001f0 LANG_NEUTRAL SUBLANG_NEUTRAL MS Windows COFF PowerPC object file

Imports

Library KERNEL32.dll:
0x401014 GetLongPathNameW
0x40101c AddRefActCtx
0x401020 GetCPInfoExW
0x401024 WriteConsoleInputA
0x401028 ReadConsoleInputW
0x40102c GetConsoleAliasW
0x401030 SetCommTimeouts
0x401034 SetConsoleCP
0x401038 VerifyVersionInfoA
0x40103c WaitNamedPipeA
0x401040 CreateMutexA
0x401044 WriteConsoleA
0x401048 GetLastError
0x40104c CreateFileA
0x401058 EnumDateFormatsExA
0x40105c SetStdHandle
0x401060 LoadLibraryW
0x401064 RequestDeviceWakeup
0x401068 FindFirstVolumeA
0x40106c ReadFile
0x401070 BuildCommDCBA
0x401074 VerLanguageNameA
0x401078 SetFileApisToANSI
0x40107c WriteProcessMemory
0x401080 ResetEvent
0x401084 Sleep
0x401088 EndUpdateResourceW
0x40108c GetCPInfo
0x401094 SetConsoleTitleA
0x401098 SetFilePointer
0x4010a0 EraseTape
0x4010a4 AttachConsole
0x4010ac ZombifyActCtx
0x4010b0 ReadConsoleOutputW
0x4010b8 GetStringTypeW
0x4010c0 HeapAlloc
0x4010c4 HeapLock
0x4010c8 GetAtomNameW
0x4010cc GlobalSize
0x4010d0 HeapValidate
0x4010d4 GetGeoInfoA
0x4010d8 GetCurrentProcess
0x4010dc GetProcAddress
0x4010e0 GetModuleHandleA
0x4010e4 CreateThread
0x4010e8 GetVersionExA
0x4010ec GetACP
0x4010f4 WaitForSingleObject
0x401100 LocalAlloc
0x401104 GetMailslotInfo
0x401110 GetComputerNameW
0x401114 CommConfigDialogA
0x401118 GetConsoleWindow
0x401120 GetDiskFreeSpaceW
0x401128 EnumDateFormatsA
0x40112c CopyFileA
0x401130 InitializeSListHead
0x40113c GetStartupInfoW
0x401148 HeapFree
0x40114c VirtualFree
0x401150 VirtualAlloc
0x401154 HeapReAlloc
0x401158 HeapCreate
0x40115c GetModuleHandleW
0x401160 ExitProcess
0x401164 WriteFile
0x401168 GetStdHandle
0x40116c GetModuleFileNameA
0x401170 TerminateProcess
0x401174 IsDebuggerPresent
0x401178 SetHandleCount
0x40117c GetFileType
0x401180 GetStartupInfoA
0x401184 GetModuleFileNameW
0x401190 GetCommandLineW
0x401194 TlsGetValue
0x401198 TlsAlloc
0x40119c TlsSetValue
0x4011a0 TlsFree
0x4011a8 SetLastError
0x4011ac GetCurrentThreadId
0x4011b8 GetTickCount
0x4011bc GetCurrentProcessId
0x4011c8 RtlUnwind
0x4011cc LoadLibraryA
0x4011d0 WideCharToMultiByte
0x4011d4 GetConsoleCP
0x4011d8 GetConsoleMode
0x4011dc FlushFileBuffers
0x4011e0 GetOEMCP
0x4011e4 IsValidCodePage
0x4011e8 HeapSize
0x4011ec GetLocaleInfoA
0x4011f0 GetConsoleOutputCP
0x4011f4 WriteConsoleW
0x4011f8 MultiByteToWideChar
0x4011fc GetStringTypeA
0x401200 LCMapStringA
0x401204 LCMapStringW
0x401208 CloseHandle
Library USER32.dll:
0x401210 GetAltTabInfoW
Library GDI32.dll:
0x40100c GetCharWidth32A
Library ADVAPI32.dll:
0x401004 BackupEventLogA

Exports

Ordinal Address Name
1 0x451260 @GetSecondVice@0
!This program cannot be run in DOS mode.
`.data
bad allocation
lihitomozecavizudovinegefi danutir xuyatedekoxijokayewewopom
Kapopoyelico budixozabos sivegawebusuce
verosiwagasedavijozegulozakegakutafojajocoxelufayifelif
Civaciguz yuvoxipugewod vaxen
Kocezafinoparog
kernel32.dll
LocalAlloc
VirtualProtect
porinufudifohe
CorExitProcess
runtime error
TLOSS error
SING error
DOMAIN error
An application has made an attempt to load the C runtime library incorrectly.
Please contact the application's support team for more information.
- Attempt to use MSIL code from this assembly during native code initialization
This indicates a bug in your application. It is most likely the result of calling an MSIL-compiled (/clr) function from a native constructor or from DllMain.
- not enough space for locale information
- Attempt to initialize the CRT more than once.
This indicates a bug in your application.
- CRT not initialized
- unable to initialize heap
- not enough space for lowio initialization
- not enough space for stdio initialization
- pure virtual function call
- not enough space for _onexit/atexit table
- unable to open console device
- unexpected heap error
- unexpected multithread lock error
- not enough space for thread data
This application has requested the Runtime to terminate it in an unusual way.
Please contact the application's support team for more information.
- not enough space for environment
- not enough space for arguments
- floating point support not loaded
Microsoft Visual C++ Runtime Library
<program name unknown>
Runtime Error!
Program:
EncodePointer
DecodePointer
FlsFree
FlsSetValue
FlsGetValue
FlsAlloc
GetProcessWindowStation
GetUserObjectInformationA
GetLastActivePopup
GetActiveWindow
MessageBoxA
USER32.DLL
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
HH:mm:ss
dddd, MMMM dd, yyyy
MM/dd/yy
December
November
October
September
August
February
January
Saturday
Friday
Thursday
Wednesday
Tuesday
Monday
Sunday
CONOUT$
SunMonTueWedThuFriSat
JanFebMarAprMayJunJulAugSepOctNovDec
C:\vahelevu\zesucohi.pdb
&}?~.wk
@nJb~zE
wA4?km
Jf 9"
T:XaG3
`*n9pv
iJTeJx
wsK>W$
M'=k6v
mem8#zkp
|&5GI4
bfnBdt
ra|Cv]pu
QC0X`:
eKD|+m
M>hbQ+O
ir??EhR
(@\qWx
=N#f+T8
sfA4&\
bNZo.6~
~y$v~G
.l@N)V.4S
p=Hzf5
NnudG4I
I*)UGw
Oq2iO8
h~@)O
XxG!f"-
Byj3Pu
="8b^
Sj;=I}VqF
/!]m))
PX>7ash
C]^'"?B
}X|E=jOg
zx!cq*
GtVt3a
f.UZb+
uerh`,
:@>ef6b
8HEwg~
fo&n/n
~*my;u
XDB=~6
.n({md
4<xwK{BQ
HXR$[t*
0n:o`m
4#k$A2
U\!_v^
X-x86
CGu5pN
2S82{ 2~+<
MiAIUx
-"-q\P
J9V+m0Z
DLrvQ\?
';[AMz
Vf6G+=
gW/L.[
:Q1%:~
$1NxHMa
A2u72l
}IDwYU
_I[U|WFM
<Cr5-[]Q
|Mg'UC
p%t)h9
Xf *07v
bi>32z
~KVRgCU
Rbhu`'
a 0yb}QO
Q'vWOA0
m'IaMx>I5
_{TcZA
6d6j"^
^/2" (W
7Ps`fp
A{a~~M+g
DS7,J{
*eU~uT7zD
Gk`,Hu'
^[xINv{
jrhHE,
o<CHt@!
ldHvA/xm
{.<BTuJ
Xn?*`j
=1!-=TbVA
~"W~oZ
$J2=QV>
YpbbM2
Af=@~m
^foepLd
Ug|_LoQg
+ 6DW-
&mUxv"
;MEa)h
>p;L'3
,l0$o
`2T2YD
js/g):
q;v{U&8
5=x8K=
o'j#+]JzS
?:Q QMDE(
}1Zb@w
;@|Q<
FDiOq(ptF
e[dAIw
xRvc1
!l/gc-
r YDH_
+rb=[g
O <a{Y
=,T|Y.
:IIRv{
^|1hJI
W)s mGjo
L|qaKi
E75,zY
3xph&}
:*S%;%
CHa^acF=@
D[a".-
c>D{ZG
QAm5F&
%X]bIs.l
J!jE`=
Yf~oBc
j=4W|8
yMw\Svp
2VIkY
4YjESXk
~o?)#*m
GjkI%kK
EcWAHf
<.Tz;e
18?b2-a
KdE mK
*ww8>Z
wJ!yq=E
y)okN[
}b0.5H
Szb%L?
"6#NrG
bhM@>0
f0YBWwHl
K-Ql,
F\eJ?0
C;+O;gT
V\y7;^
sz56|V
PWEF1}
WB@C{=
2-irH\
53G /Em
eR},TG|b49R
X<p%J
y'J]2S
#G6?Uq
kT7b21
z-*drg
XqSvf=
64QYJ|Dr$
bJkiLb
m:6*]+
rh;w_f
g7zAA<
MJhIy{
Y.ZTW$
0ds%*K}
%2kF&I
rQ"hcf
L"C/m~|
QRsewab
m\VFXn
chuR`V[Vl
|Gwp){kVX
lb{va
A*/fS9
>N@L2{f
]|M0
%I(Pv8
$mr97y
w+?B-rq
A0K*$6
j$E'ds}>>
j]`k~O
Zj93;x
$XQCi
]!wU:N
m0~BIxcq
<?;|X0
<?q;(?m
.%TB6a
xm!7~/
ZLw`ne
O96y,:#
}}PW0.0}
0T71wGi
{p$&|Q
cVXe ,
B&5UFe
<\4Lf:
Y3gf*1
mFGsj}
M{bQE"
k_n(!'
zj5xq}
E3S<SN
9VxF-n
qIj5M73q
x!V-tA
Z[[5[@
U0x%T5
9J%DUG
0\3c&5
Muw-WE
[v;:}4
IRaP(/
:~%iGbT
_uNG].4)
ba!;.t
V;KNm{
D))t<'
_Zymh]
ZZ(?9
IGL}?*V4
aE#M&^
~@F8^C
E"8%xi
Aq|RWn
dJj!E_H
]#}Q3E
hWchB!
oZ6L@L5
D$,||2
S4|8A
%u+##Q
'<,D'b8
nST9yz
dDJc-
k-d;ma
RIl( `
KVoB`:5"
|ia\[u
Kc/7uR
7u5$&b
!wU8Q+
.F#Fx,*O
(gI>J)g
;T)v0A
?bbuM1S
u*^{:q
fo~U^l
uvmI?H
8u!z35
AN5 iS?
=h-Q/$
UbeTqv
zro_o"
Q\VD|wX
Xct,cie
d0d{mO
In\N"L
;l/\)%3
LT;Eck
ksE,!p
?)R4:B
L[0QvB
]qW4H.
dkU[eU
=cz1=E'
#w2fd]
^= ZOz
LENK?~y< 1
!X~FJ%wk
px<!B?
a!lG19
!9q[0dcV>
aUHEO_#
Ga#CbW
1%PS7GgVT4
b@'fL!
Vd.%Qb2l
N$4L<w
ykInX
uQx%=F
qy4)%/
""7'YHDi
Spoa9GL
*Y#FU:
d)+RBR
MKoSRW
&na#y\
e<RrJ`
*)`R>lf
b,=ukn
frC_0z
x$Fo0e
6{+]LX
NVd=Vnz
D@Kv9[ Z
KUY@mA
i_U~Gm
#9S*?n
Di<&HikoPw
xXXCN&
Uw@6]#<
Zp@\3_
=!k:k=
HmZ9}AIr
B>6N7:
)Z5z 4
&&-%-/
Ox4Z LU
Zo3H;lW
Yz0"@3&
0"%5eFa
>,`#bu?
]u/oG)
y_"NHd
13ZVzh
<m4oEJ[
(Hu:"(a
zFdFup
(z'1Qg
@K->L~e
bgkyFZ
cO:gyh
C-X2K5
?X1v2B
zJw4@L
=9$m!_M
LS;bpL
Ys$M'V
r?Ru=)
H+^j&H
*nM9pQ<2`
UQ[+>"
d{7-ET]
aB?O5J
(acHlm
D$t=$?Sa
RCvJ/{
xUNgM/,
yR`wQ!]z}
v]CnQv-
?u];;3
nEKZH/
S2JvW2
uEk?h3
D3QD;T
xJeQ,3MI
?hA$JI
3,W/@$
)}[\Uu
7]aJo/
nkw%w`
t-Dwgi
G8{CrN)H
mg%'tc
Bf6hzoi
AJ5DqP
02eYz@F1
\higMq
a{krR
!$x\/sGs=<
1lOEDxD
'5m,}".
mhTZoE
6vwtBZ
cf6;-uQ
);\%r=
${tIr]Iw
39@pL?u
u#r#-bu
kCxFX0#M
e`=|a]
"FAC,L
0ZvAb>NH^
w5"17 D
69@@2IR
B!IZB)>/
](mK/AE]3
:juif(
O1\~D[
w34[;b
NABD3M
&d=p p
1ngQ~m
eeJ@|<nf
(Z96%n
2BYSyE
+^M6=e
WI2gBy
'Js,SM
-N\qPU
F?$Ega
?d]8g~
T@L4pH
"}2qEz
&[({1a
^=xw_Vl
L%Qf>.
Bf6I_j
PV dVW
qc?`S{
XDE!h)`
C;O('
_h4R&)D
?[NUQ1
X#e~%8Y
l;,L(q=
$5U$P,g
n0B&bE!2H
Sdf56G
W/E~@9A
t@^vtA
eZ$f[f
La9Dnp
5n(ve
W)A$'5
c<BQ3/
T,(thY
/nGo5wIV
mV+[:s
J_-,zMk
xudjQj?
Fa<@1's
Wct&vr
MizzX3OQ
j}F;VbG
T&Xv#'
CBo5n
l2[Lt2
}=h<\z
~7mlzM
wzHS`swwB
u|ns1"
~x0yjQ
^OaKv,
"]4:M\
i5K}/iYp
'C8<aG
I${YAT=
0[4%cm
MP9+X[
K1RI;FMI
y}m\~b
MZbOYg7
8Tgih8
;P!wT>
j/^ Pq
u)-St#
is*9>1
VeI;l
Cn!w^Y
,t'e'\
`}OE/^
H#,5M}W{
t*>c0{
_VA|x"
tLw v+
gj'h5^`
kN1Ia:
kKj+j>#
I:QB2L
GXY#>'
kP3}8a
vt+bvY
Lh(>@@
&{bnW1
sV! dt
wM7[AA
`@6@+,@
F@IBBN
-] I5
3mCqV~o
$iPih)
er(j{b
41@yi6VG
Gn\sBJ
R S9#!moB
paF|_l
w.]'v]M
Q:|_g:h
FDxB L-
>H,(W9
^XzWXQ/
`er`L]
$SleKGu
sY,Z0}f
ceaup+a{
]|7RhvE
6Zl[>]
"?7?yr
*:ayN<
'xv/B1,d%
/=8/zC"
LK0lA(
ovBM-W
W?[-8Dn
yC:<HMPsb
T)&eca
fS,UT;
N\BMwK7
yQPGXHgY
nU}Da
3y{#rA>
@3N-cJ\3
,uDFQi
aD%t}-
VL6zV'
Rfg#.W
SuYQ.
RQk:^m
m8CK9&
yCY/F@i
LA2l""
Cw\dIo
?$}v~
LDpTWLs
g>j*kF
aZk3Fp%
Ja2=tc
,_wf(D
N$e[P0G
]_'I%C
39Rg)]
a/3s43U{
!5/>Q+
r?2 {}&
WBPO
R<w4r'r
cT1Z8=
Vm[Wm[s
x$ZT=H
/?v3"
ce'_|G
@1.A+zb'
sS)yP$
I3AoOh
ZH65,2
en @30
A3Isdo
EU8-%XET
(80JXW
_]&-C[
k`H]?Q
+o%O/e
g?Vk/R
,}%:s@
*!">]%{
>un@s
6Wz($z)Wn
8Gf.YV
mYs};#
8T;Eh
(qp**I
ZK^)Qn
K3(^<i@
B ,-K=T
H^~|0
GuPWP
8BT.}<
C;@G7a
R$Dhy5
VVVVVV
VVVVVVh
ETbcs%
^u/VVV
PSSSSS
j@j ^V
>=Yt1j
QQSVWh
URPQQh
0SSSSS
0SSSSS
0SSSSS
0WWWWW
AAFFf;
0A@@Ju
;t$,v-
UQPXY]Y[
PPPPPPPP
PPPPPPPP
t"SS9]
t+WWVPV
InitializeSListHead
EnumDateFormatsA
LeaveCriticalSection
EraseTape
GetLongPathNameW
GetUserDefaultLangID
AddRefActCtx
GetCPInfoExW
WriteConsoleInputA
ReadConsoleInputW
GetConsoleAliasW
SetCommTimeouts
SetConsoleCP
VerifyVersionInfoA
WaitNamedPipeA
CreateMutexA
WriteConsoleA
GetLastError
CreateFileA
WritePrivateProfileSectionW
GetPrivateProfileSectionA
EnumDateFormatsExA
SetStdHandle
LoadLibraryW
RequestDeviceWakeup
FindFirstVolumeA
ReadFile
BuildCommDCBA
VerLanguageNameA
SetFileApisToANSI
WriteProcessMemory
ResetEvent
EndUpdateResourceW
GetCPInfo
SetConsoleCtrlHandler
SetConsoleTitleA
SetFilePointer
GetCurrentConsoleFont
CopyFileA
AttachConsole
GetConsoleAliasesLengthW
ZombifyActCtx
ReadConsoleOutputW
GetSystemWindowsDirectoryA
GetStringTypeW
BuildCommDCBAndTimeoutsA
HeapAlloc
HeapLock
GetAtomNameW
GlobalSize
HeapValidate
GetGeoInfoA
GetCurrentProcess
GetProcAddress
GetModuleHandleA
CreateThread
GetVersionExA
GetACP
WaitForMultipleObjects
WaitForSingleObject
GetSystemPowerStatus
WriteConsoleOutputCharacterA
LocalAlloc
GetMailslotInfo
SetEnvironmentVariableW
GetFileAttributesExA
GetComputerNameW
CommConfigDialogA
GetConsoleWindow
PostQueuedCompletionStatus
GetDiskFreeSpaceW
KERNEL32.dll
GetAltTabInfoW
USER32.dll
GetCharWidth32A
GDI32.dll
AdjustTokenPrivileges
BackupEventLogA
ADVAPI32.dll
UnhandledExceptionFilter
SetUnhandledExceptionFilter
GetStartupInfoW
DeleteCriticalSection
EnterCriticalSection
HeapFree
VirtualFree
VirtualAlloc
HeapReAlloc
HeapCreate
GetModuleHandleW
ExitProcess
WriteFile
GetStdHandle
GetModuleFileNameA
TerminateProcess
IsDebuggerPresent
SetHandleCount
GetFileType
GetStartupInfoA
GetModuleFileNameW
FreeEnvironmentStringsW
GetEnvironmentStringsW
GetCommandLineW
TlsGetValue
TlsAlloc
TlsSetValue
TlsFree
InterlockedIncrement
SetLastError
GetCurrentThreadId
InterlockedDecrement
QueryPerformanceCounter
GetTickCount
GetCurrentProcessId
GetSystemTimeAsFileTime
InitializeCriticalSectionAndSpinCount
RtlUnwind
LoadLibraryA
WideCharToMultiByte
GetConsoleCP
GetConsoleMode
FlushFileBuffers
GetOEMCP
IsValidCodePage
HeapSize
GetLocaleInfoA
GetConsoleOutputCP
WriteConsoleW
MultiByteToWideChar
GetStringTypeA
LCMapStringA
LCMapStringW
CloseHandle
cecadev.exe
@GetSecondVice@0
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
TIQ[QQ
OCOCGOe
|]]]\]
qqmmxmgm8L
/FAzm;5
/IQjE((
AYY~~lw
IHf2*3zM
D9`yio
SMtp?8
#Tds=/1
TW~~:5
MMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMM
MMMMMMMMMMMMMMMMMMMM
MMMMMMMMMMMMMMMMMMZ
Y`MMMMMMMMMMMMMMMM
9sVPMMMMMMMMMMMMMMM
MMMMMMMMMMMMMMSv
jMMMMMMMMMMMMMMM
`MMMMMMMMMMMMMMM
RMMMMMMMMMMM
MMMMMMMMMMD
MMMMMMMMMM
MMMMMMMMMMMMC
rMMMMMMMMMMMM
MMMMMMMMMMMMM
EMMMMMMMMMMMM
MMMMMMMMMMMM
MMMMMD
QMMMMMMMMMMMMMMMMMM
n]MMMMMMMMMMMMMMMMMM{
MMMMMMMMMMMMMMMMMM
7MMMMMMMMMMMMMMMMMM
76MMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMM
6CO`OG
x8#4)8O66`8
)4OQ`ee
<6QQQD_
c9@b#+I
"<m~d'r
=jr+${
'1_8q
>kz7v
A4_vm'W{r7e
]]]]]]]]]]]]]]]]]]]]]]]
.::::.
|pqqcc
>>>pq:
cE|||||||||||||||||||||zE
|||||||||||||||||.z
EEEEEEE
EEEEEEEE
XXjjjjjj
FFFFFFF
v@@@@@@@@@@@@@@v
nnnnnnnnnnnnnnnn
>>>>>q>qqqqqqq
>>>>p>q>qqqqq
>>>>>>
]]]]]]]]]]]]]]]]]]]]]]]
^^^^^^^^^^^^^
^^^^^^^^^^^^^^^^
^^^^^^^^^^^^^^^^
^^^^^^^^^^^^^^
;;;;;#;;#;;;;
2rrrr2
FFFFFF22
pFFFp
#####;;
{{{{{{
$$$$$$$$$$$$
l$$l$$l
q888888888
((((((((
ytz_wxx
tqoooup
wrx^vtq
[\Wt{~
/B2!X`Zz}~{
""""""""""""""""""""""""""""""""""""""
"uuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuu"
"uuuuu
########@#@@@@@@
######@###@@@@@@@@@@@@@@
###########@##@
@@@@@@@@@
######@##@
@@@@@@@@
#########@##@
@@@@@@@
#######@#
@@@@@@
##########@#
@@@@@@
########
:X~R##########
######
#######
#######
#g#####
"uuuuu
g######
gg#####
"uuuuu
#g#####
"uuuuuu
gg######u"
"uuuuuuu
#g#####
"uuuuuuuuuu
gg####u"
"uuuuuuuuuuu
gg###u"
"uuuuuuuuu
gg#gu"
"uuuuuuuuuuuuuu
"uuuuuuuuuuuu
ttttYYY??????
PPPPPPPPPPPPPPPPPPPPPPPPPPY
*********
*******
*************
******
********
********
******
4/}*****
/j*****
%4/}*****
/j****
4/}****
gggggg
>>>MM>
Jgggg>
JJJggg
JJJJJg
JJJJJg
JJJJJJ
JJJJJJJ
JJJJJJJJ
444444
cccccccccccccc}
************
*999999999999*
*ccccc
*ccccccc
1=YO"L
iiiiii
iiiiii
iiiiiiiiiiii
iiiiiiiiii
iiiiii
iiiiiiiii
iiiiiiiiiiiii
iiiiiiii

Gepiragaxowohoz falenuvesexoloj domibezol
penowipazisalaleyiligebo pokuyowewofemoxo fefoyakelabepecodi
fTegah
fusufaf
mscoree.dll
KERNEL32.DLL
((((( H
h(((( H
H
/ P6pL
,/KPip
/-P?pR
/ P6pL
,/KPip
/-P?pR
VS_VERSION_INFO
StringFileInform
081564b6
FileVersion
41.29.120.69
InternalName
voygmuaroke.exe
Copyright
Copyrighz (C) 2020, wodkaguds
ProductVersion
14.35.97.13
VarFileInfo
Translation
DPufepu menefe becedecocu bamayegibovur fecatekojurire nudajubikuwotu
Jawenu pit
Votohoyidi raxiyaxog
Futuce porifucocixeyPJabidisuwaw ditepanojejufir peviyolusakuxu bagoxonicov mezinokuli hakibelebicazoUFirupevocepo sericola yerakap fugayome cepaluvokigegu mif muredobalebif cehafularabad
Pigofiyoridux
\Zezepiyuwiyo vahebibe lesoromexagosa gidazahiro voweyodaxige panace mudibav tikerap sinigami Jepofuwam jal novelevugagu ledabEFoji dugetajoxoyubu nivuguyuhusos vewoworom zig vozet ruvabatugurovep
-Xopepadef televagoji laferuja gemava cij teza"Guzocizidanipi camitew yidalenixewTXijorewubevaw juroza hunusufajagugur ruzepeyifero wofo pulisowuduzuyol xecekoy wesim
Favu gulujeyicicuyug pib&Nirid yud vasugeculotog sokipebi coxim%Wocacu nadivesojuka gok kitu layuvipi^Cane yosetedehohohim xorebulura kexat lumamiduvekonu cifofemagu minaca xacuzah vuriwadehinokumOJica sokusurenewezut gecalusonuyewa daketujekuw mufe nel vomi wusirif noxixorocAMiker rexikusoce kezazibewugiy cisukaveci domixuxu tuyizelahunayiHDemab muduvubo morewuwaroxu rajifajol yilelucapu saruligevabuceg piyatof?Rojesurigupuh yitaf calas befihote kisux toxoyoke ciy key mehemyPejivosekig legulewomowad hipakapokifec geriboyasayezi yojunasawil tavebenotepej remo kacilixedicacop xetuna vaxowuwewesa
UFewosuhiji fidofek vigepavigafuwo wosaridixom vuvezus wehij payavib neravuyapoz yidoz
Wogefo sejarimi
Rarofip
Detavaneta
XDukoruxolarak siv xirecakecik sipoxawepacuze gaxaxebayaro loz gozukikopewuju zoyoduhosig*Zonosodugexa subukinija tukoj goluvovagigi
Sasodavocuhucoj ganabekalo)Pejawayux jovayo lomuresoyeluk suhufiyoko
Rucomavahixelu petobevezu4Wopejimudoz jiyehegavido wusoj dotadoradox kajuxiwatOVufogakozon dabunebofoxariy foxomeculivajo zabizal tohu mipuhu nanobuyugefi zecoSuvefaxezi tojizesabogulup wujojeten nozafowad zufamehetuxuxi gopuzidusihujo tenifasem gixiwazir kumucezazavama
Antivirus Signature
Bkav Clean
Lionic Clean
Elastic malicious (high confidence)
MicroWorld-eScan Clean
FireEye Generic.mg.7033117dc3ecbb31
CAT-QuickHeal Clean
McAfee Clean
Cylance Unsafe
VIPRE Clean
Sangfor Trojan.Win32.Save.a
K7AntiVirus Trojan ( 005690671 )
BitDefender Clean
K7GW Trojan ( 005690671 )
Cybereason malicious.98b1c3
BitDefenderTheta Clean
Cyren W32/Kryptik.EMQ.gen!Eldorado
Symantec ML.Attribute.HighConfidence
ESET-NOD32 Clean
Baidu Clean
APEX Malicious
Paloalto Clean
ClamAV Clean
Kaspersky VHO:Trojan-PSW.Win32.Convagent.gen
Alibaba Clean
NANO-Antivirus Clean
ViRobot Clean
Tencent Clean
Ad-Aware Clean
TACHYON Clean
Sophos ML/PE-A
Comodo Clean
F-Secure Clean
DrWeb Clean
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition BehavesLike.Win32.Lockbit.hc
CMC Clean
Emsisoft Trojan.Crypt (A)
Ikarus Trojan-Spy.MSIL.Agent
GData Clean
Jiangmin Clean
MaxSecure Trojan.Malware.300983.susgen
Avira Clean
Antiy-AVL Clean
Kingsoft Clean
Gridinsoft Trojan.Win32.Packed.lu!heur
Arcabit Clean
SUPERAntiSpyware Clean
ZoneAlarm Clean
Microsoft Trojan:Win32/Azorult.RW!MTB
Cynet Malicious (score: 100)
AhnLab-V3 Clean
Acronis suspicious
VBA32 BScope.Trojan.Sabsik.FL
ALYac Clean
MAX Clean
Malwarebytes Trojan.MalPack.GS
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Rising Trojan.Generic@ML.90 (RDML:Y2IPve0j4p/oJQteOU/aPw)
Yandex Clean
SentinelOne Static AI - Malicious PE
eGambit Unsafe.AI_Score_72%
Fortinet W32/GenKryptik.ERHN!tr
Webroot Clean
AVG Win32:PWSX-gen [Trj]
Avast Win32:PWSX-gen [Trj]
CrowdStrike win/malicious_confidence_100% (D)
Qihoo-360 Clean
No IRMA results available.