Static | ZeroBOX

PE Compile Time

2020-03-28 22:11:14

PDB Path

C:\dinexowehol42\hub_37\tarat95-lopifaba jako.pdb

PE Imphash

010b99662693ba25ba201961c31754d2

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x00086a3f 0x00086c00 7.97848805628
.data 0x00088000 0x027469a0 0x00004800 0.627905038167
.rsrc 0x027cf000 0x0001fd70 0x0001fe00 6.39355880654

Resources

Name Offset Size Language Sub-language File type
RT_CURSOR 0x027ed400 0x000008a8 LANG_NEUTRAL SUBLANG_NEUTRAL dBase III DBT, version number 0, next free block index 40, 1st item "\251\317"
RT_CURSOR 0x027ed400 0x000008a8 LANG_NEUTRAL SUBLANG_NEUTRAL dBase III DBT, version number 0, next free block index 40, 1st item "\251\317"
RT_CURSOR 0x027ed400 0x000008a8 LANG_NEUTRAL SUBLANG_NEUTRAL dBase III DBT, version number 0, next free block index 40, 1st item "\251\317"
RT_ICON 0x027ebef0 0x00000468 LANG_SERBIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x027ebef0 0x00000468 LANG_SERBIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x027ebef0 0x00000468 LANG_SERBIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x027ebef0 0x00000468 LANG_SERBIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x027ebef0 0x00000468 LANG_SERBIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x027ebef0 0x00000468 LANG_SERBIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x027ebef0 0x00000468 LANG_SERBIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x027ebef0 0x00000468 LANG_SERBIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x027ebef0 0x00000468 LANG_SERBIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x027ebef0 0x00000468 LANG_SERBIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x027ebef0 0x00000468 LANG_SERBIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x027ebef0 0x00000468 LANG_SERBIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x027ebef0 0x00000468 LANG_SERBIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x027ebef0 0x00000468 LANG_SERBIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x027ebef0 0x00000468 LANG_SERBIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x027ebef0 0x00000468 LANG_SERBIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x027ebef0 0x00000468 LANG_SERBIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x027ebef0 0x00000468 LANG_SERBIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x027ebef0 0x00000468 LANG_SERBIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x027ebef0 0x00000468 LANG_SERBIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x027ebef0 0x00000468 LANG_SERBIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x027ebef0 0x00000468 LANG_SERBIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x027ebef0 0x00000468 LANG_SERBIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x027ebef0 0x00000468 LANG_SERBIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x027ebef0 0x00000468 LANG_SERBIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x027ebef0 0x00000468 LANG_SERBIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x027ebef0 0x00000468 LANG_SERBIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x027ebef0 0x00000468 LANG_SERBIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x027ebef0 0x00000468 LANG_SERBIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x027ebef0 0x00000468 LANG_SERBIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x027ebef0 0x00000468 LANG_SERBIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x027ebef0 0x00000468 LANG_SERBIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x027ebef0 0x00000468 LANG_SERBIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x027ebef0 0x00000468 LANG_SERBIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_STRING 0x027ee8c0 0x000004aa LANG_SERBIAN SUBLANG_DEFAULT data
RT_STRING 0x027ee8c0 0x000004aa LANG_SERBIAN SUBLANG_DEFAULT data
RT_STRING 0x027ee8c0 0x000004aa LANG_SERBIAN SUBLANG_DEFAULT data
RT_ACCELERATOR 0x027ec400 0x00000010 LANG_SERBIAN SUBLANG_DEFAULT data
RT_ACCELERATOR 0x027ec400 0x00000010 LANG_SERBIAN SUBLANG_DEFAULT data
RT_GROUP_CURSOR 0x027edca8 0x00000022 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_GROUP_CURSOR 0x027edca8 0x00000022 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_GROUP_ICON 0x027df2f8 0x00000068 LANG_SERBIAN SUBLANG_DEFAULT data
RT_GROUP_ICON 0x027df2f8 0x00000068 LANG_SERBIAN SUBLANG_DEFAULT data
RT_GROUP_ICON 0x027df2f8 0x00000068 LANG_SERBIAN SUBLANG_DEFAULT data
RT_GROUP_ICON 0x027df2f8 0x00000068 LANG_SERBIAN SUBLANG_DEFAULT data
RT_GROUP_ICON 0x027df2f8 0x00000068 LANG_SERBIAN SUBLANG_DEFAULT data
RT_VERSION 0x027edcd0 0x000001f0 LANG_NEUTRAL SUBLANG_NEUTRAL MS Windows COFF PowerPC object file

Imports

Library KERNEL32.dll:
0x401014 GetLongPathNameA
0x40101c AddRefActCtx
0x401020 GetCPInfoExW
0x401024 WriteConsoleInputA
0x401028 ReadConsoleInputW
0x40102c GetConsoleAliasW
0x401030 SetCommTimeouts
0x401034 SetConsoleCP
0x401038 VerifyVersionInfoA
0x40103c WaitNamedPipeA
0x401040 CreateMutexA
0x401044 WriteConsoleW
0x401048 GetLastError
0x40104c CreateFileA
0x401058 EnumDateFormatsExA
0x40105c SetStdHandle
0x401060 LoadLibraryA
0x401064 RequestDeviceWakeup
0x401068 FindFirstVolumeA
0x40106c ReadFile
0x401070 BuildCommDCBA
0x401074 VerLanguageNameW
0x401078 SetFileApisToANSI
0x40107c WriteProcessMemory
0x401084 ResetEvent
0x401088 Sleep
0x40108c EndUpdateResourceW
0x401090 GetCPInfo
0x401098 SetConsoleTitleA
0x4010a0 EraseTape
0x4010a8 AttachConsole
0x4010b0 ZombifyActCtx
0x4010b4 ReadConsoleOutputW
0x4010bc GetStringTypeW
0x4010c4 HeapAlloc
0x4010c8 HeapLock
0x4010cc GetAtomNameW
0x4010d0 HeapReAlloc
0x4010d4 HeapValidate
0x4010d8 GetGeoInfoA
0x4010dc GetCurrentProcess
0x4010e0 GetProcAddress
0x4010e4 GetModuleHandleA
0x4010e8 CreateThread
0x4010ec GetVersionExA
0x4010f0 GetACP
0x4010f8 WaitForSingleObject
0x401104 LocalAlloc
0x401108 GetMailslotInfo
0x401114 GetComputerNameW
0x401118 CommConfigDialogA
0x40111c GetConsoleWindow
0x401124 GetDiskFreeSpaceW
0x40112c EnumDateFormatsA
0x401134 InitializeSListHead
0x401140 GetStartupInfoW
0x40114c HeapFree
0x401150 VirtualFree
0x401154 VirtualAlloc
0x401158 HeapCreate
0x40115c GetModuleHandleW
0x401160 ExitProcess
0x401164 WriteFile
0x401168 GetStdHandle
0x40116c GetModuleFileNameA
0x401170 SetFilePointer
0x401174 TerminateProcess
0x401178 IsDebuggerPresent
0x40117c SetHandleCount
0x401180 GetFileType
0x401184 GetStartupInfoA
0x401188 GetModuleFileNameW
0x401194 GetCommandLineW
0x401198 TlsGetValue
0x40119c TlsAlloc
0x4011a0 TlsSetValue
0x4011a4 TlsFree
0x4011ac SetLastError
0x4011b0 GetCurrentThreadId
0x4011bc GetTickCount
0x4011c0 GetCurrentProcessId
0x4011cc RtlUnwind
0x4011d0 WideCharToMultiByte
0x4011d4 GetConsoleCP
0x4011d8 GetConsoleMode
0x4011dc FlushFileBuffers
0x4011e0 GetOEMCP
0x4011e4 IsValidCodePage
0x4011e8 HeapSize
0x4011ec GetLocaleInfoA
0x4011f0 WriteConsoleA
0x4011f4 GetConsoleOutputCP
0x4011f8 MultiByteToWideChar
0x4011fc GetStringTypeA
0x401200 LCMapStringA
0x401204 LCMapStringW
0x401208 CloseHandle
Library USER32.dll:
0x401210 GetAltTabInfoW
Library GDI32.dll:
0x40100c GetCharWidth32A
Library ADVAPI32.dll:
0x401004 BackupEventLogA

Exports

Ordinal Address Name
1 0x47e0f0 @GetSecondVice@0
!This program cannot be run in DOS mode.
`.data
bad allocation
lihitomozecavizudovinegefi danutir xuyatedekoxijokayewewopom
goyorigamejudil
Kapopoyelico budixozabos sivegawebusuce
verosiwagasedavijozegulozakegakutafojajocoxelufayifelif
jamoyuburayiwafibodobikiguhibepibarivahuguya
kernel32.dll
LocalAlloc
VirtualProtect
porinufudifohe
CorExitProcess
runtime error
TLOSS error
SING error
DOMAIN error
An application has made an attempt to load the C runtime library incorrectly.
Please contact the application's support team for more information.
- Attempt to use MSIL code from this assembly during native code initialization
This indicates a bug in your application. It is most likely the result of calling an MSIL-compiled (/clr) function from a native constructor or from DllMain.
- not enough space for locale information
- Attempt to initialize the CRT more than once.
This indicates a bug in your application.
- CRT not initialized
- unable to initialize heap
- not enough space for lowio initialization
- not enough space for stdio initialization
- pure virtual function call
- not enough space for _onexit/atexit table
- unable to open console device
- unexpected heap error
- unexpected multithread lock error
- not enough space for thread data
This application has requested the Runtime to terminate it in an unusual way.
Please contact the application's support team for more information.
- not enough space for environment
- not enough space for arguments
- floating point support not loaded
Microsoft Visual C++ Runtime Library
<program name unknown>
Runtime Error!
Program:
EncodePointer
DecodePointer
FlsFree
FlsSetValue
FlsGetValue
FlsAlloc
GetProcessWindowStation
GetUserObjectInformationA
GetLastActivePopup
GetActiveWindow
MessageBoxA
USER32.DLL
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
HH:mm:ss
dddd, MMMM dd, yyyy
MM/dd/yy
December
November
October
September
August
February
January
Saturday
Friday
Thursday
Wednesday
Tuesday
Monday
Sunday
CONOUT$
SunMonTueWedThuFriSat
JanFebMarAprMayJunJulAugSepOctNovDec
C:\dinexowehol42\hub_37\tarat95-lopifaba jako.pdb
Ra`PdL7!9W\
J-Hg8R
Gj^`*|G
}.54HW
R's[lM
'U~[J
Xs43}7-
'_'/]z
+"JkgG
='$8=HO
{Dh6Zn
zD0?z)
2t:3+<
_,p&ryL
X~1d~[
}^BPPd
~f&t2R
54Qc(m.
y?ENUm
2a6sYg
5/(*6[
`$L1oF
g|$z=3b
WPMTi'
0gcJCj
kl67fi
d$$QII`!
.#fJo7
4<SXM
U>?:6
<l2cZd
1`2Pt}
xqt"gl>
aoSJK7
'BU=\Ccv
VX-Jnhb
}h?a.n
0Q4*D
<;(Q?K6
x1FxXr
FdwImK
0$M@zM
(]Kdx/
%e&f2!
DJ-M!u
WD,<41
GS(0s2
JFgH'<
RepIdL
/1w=^[5)
_tu^]N
thYne
z9nVxx
2R;e56
Eo,_zqo
X{w!5s
usJ|(ot-
vA/::c
^S^NQb
Fxr2(~N
bb)%h'ap
#DZ:qq|
m]R&+_
.a}%i1
?9Yw)q
n`I]oR
}jBp^8
#bmHzd
w>\Oj`P
?z`].zh
_ReO9l
s{+zLF
(,bH+=
e15+*%s^
"W.ghr
&ZahB};
SW'?XE0
#(}HPtw
~semuc
w{I#IH
: ^SY
ukAw.-
}"3`!h
>B20f_
"Y g'C
x_#a-I
e"/y<V
9O|Ug4
g*qO!qI
Hu0~Bq
TW9.R
K'A)-4
_Y55ML9
Nr%wHz
Bd#^VJ
UT75RL
._w<+)`
fu!5FO~
E<O#b-
=7lu`P
=A"Kpav
~pPgG"
B(h*ht$
k>K^Nh
?y1y88
\s+]H?
a<+$Z8
.Dj/VX
2yg 8:
)'Zb]Q
fNNd^P
L.~)i-
]Y1/2U_P
<)};b]
pZY0"-q
o(hp@(E]
]:?n?w
~.:.GjM
8#Y9HI
tA{2v4u
,*zLn`
EMHeA<
x%EHsK
<DXpL*
rnw6V@
WIe+
%Qrp\H
J<s{$-&
N/zv 4
?>p.!<
e12#[YCz
_ ]Gd
&){BEoE
y2KLJ_
T%~<W
-XR>f?
,`UB2x
8hUjRvfX
aCf8]
K{r5U<
OTJw`Rh
)eD_^j
(~U(R;Z
kObqLT
_pwfc_I
9"1K}
#z-O=T$Lc
,^=j:6|
&}Ouoi
:T)rC0K
STe'oBr
(y fe}6
8:by}v8
A.GsKHk
XMRG{;
`.e{MV
&;l%7}
$1;8qQkL
-_.YZ_?8u
<iGaS
d{h[ddqy.
!JI[(
y MIx
AlSN7w
>.#W#b
!45?g#
iRw1Mq
z>'T6<r/
\ @C|&
c8]!aX
[[6`S?
tV@e?J
@z/](e
{[_^q%
&HKq,M
0Gr 6h
|''@0?
m+.##G
Zo(lmp
!hk5z=
QC*{)
Ma)YGd
=ccDMc
7L#VO%
bMzs6*
nFq3Cp
<Ip1WN
Fzi3|5B
5Dv7cEd
*ZuCNB1X}n
U\u5]I
QHlX88
C)PQt!
:bnJ;:
v^m2?_M
u\4W@L
GslQJP
^cMUGw/eu
)|)'9L
o3NM{J
`WnH7g^
<)-hM>S9
4X/pesiq
J+he:;[A
eEm.{d
gce`'=
+)^p0
n!+Tr]
.g`O1y
MW|$Xk
lUIM==
Kk_f$l
|y.\?<Wkf
6oI1M;u
}3cY3fY
u72c.yO
|B=jORF
sY5uLKqe8i
8yLt\r
1Pe$24
ioV9*h
!VDefs
.qDQBB
kjDG#y
vs.gn
Nks$]X
~`]<dMq
ynZ!r::
-`Tm}6W
|p'wxtAz]
;kPZI*"
BA"J%7
Aq-l<X
`4i{-(
RScK^z@
\vIS<|5
;ToJfT
jE78vO
J4B>RkP
**:=v*EN
?b*T*ZT5
BF=IT<
YFW@iLF
&w2{se
)uRy>!+
=m&I |t
pIf3tX
sYHJ2'
vn`;#S
F6wmF,
g8EwPz
X\!4D*
w0j)$x
1)yW^XY
PTr;XH)
capHkC
bE=#|C0R\g
1Rd3x
87#M}{!
Q?'=)W)k
B-qhyd,w
5/?1S~
iiK^/b
,X%'}M
/ |KK9
;YYY*~
(t76jPP
D/kq.p
o~4w'W
q>#Zf)
,,OE)H
*al%PC
~P]hDn
R_X.6l
YTLC<.
\?ov^}{M*
C&K4 f9N(H
{VW{[_(
U`bv`Jk;
cKezO9
aU2$Fw
S@4ZoT
onTc$$]
vWuQ,:
m,D)yR%<
Vpm4|`{
E> ]]Q
84.{!:
;A7B)xn.
9;yd2"
uq.).u
a7@]aA
*Q^aALC
aH4j_m
LDElrS
,pX#$
m?y&9D
{E|Bu^
rfWp`J
foKpp$
w<nlR0
DP$<:
9p\oO-
/.*Cb_
uWoR>uY">
wSs`mM#
MIn_L]
YxkU!w?
T2c|E/x
zO:'gc;
!t~~p
5ryH?s
>b12Y
}4'xZ^
t^D5)jf
;BzBf>]
kXiHR"8
F'2,+_
ZFa5rJ
0ln{kI4m0
j=!}q[
hQ@U_jF1i
V4y!6Z
v {!?ROAV
N#3klW
T!U'NI
}"weSN
)h}Hj8>4
MR!|f
n9MgD~
@VU0?H
c/~G[
Rl&>?]
jLmC[fCx
?o(T#V
a^ZZx=x\
0$da;e
~:o"p1Q
Fj~oFn
1DbJyn
[tW~E50
Y>n&$%
6_WvQB7
b-Ok+
HDAH+
6Y^9u:
_|DiO\
Gw4AZ
G@R6a
=9x8Oa
V[!YIe
^JNE5H
n[{]cz
}6w TPl
%VjghSr&0
RF(>3<yC
?*h}\2
R<rjRp
Y1c'}3
B y3u]
I^NvH
JcgW=j%
fr{c=
|;q]aQ
`4@.8q
X^1x{$
e5tz5j>
7*)$)~
6~|h3s%\T
xvf=z&
X]"Z Z
1)hZQ!K
"-*6VY
hOB@%Pa
f*41-re
|Ecr6:>'tlsJ
,k:f2w
FYl{)]bQ
K`mf(R
eEY5B
lUU&Ifn
bY[) '
XslcpoE
a=U1Ql
])-+#d
*F95{*
x?qP[=
m2`p2C
U*)*BB
nzEFPK
Cn-kg
!5EN&v
J>ugO"
'$Ft<n
LBElPrI
&gD'DG
BvSQ!j
Cx hkx
8G1[4}
0@0)`^
0k,bY)/
$)d=v=
_OpVA.
*!C<\b(
X`Us#Da
`;=\R(L
i'13-}
R/;ZDn3
9}~k~m8C
P%OF_5Y
r*PpDG
:Nb_aa
g]z^fx
|!NE{D
wbVKE0f
<.B"1Y
"H/cX"
D+%Vp{^
e;^Gu2
7AJXM=h
]@/6J
*egV(\/H
}y)uMPo
o@nF5n
ri(WSg
"_&uH?
S{V.^^{U
Lo6'v{
1u+qAF
WUSUT,+
\+GU'v
~2%|{{
fyeJ+qo
Irg\ O
DT-iiW
xnpo<QTz&-
y)p_S#
=VH!$+
7:$C`<
6@Sf)O
#lF5Wn9
uF[4}
T&t,5{1
Y]O1Ud&M<
"mrw!h
DEJv{13
~$5=`i
iEgq_<4
f|F'v!
Voz'SCc
Cg|yom8
&3iU<.
i$952s
c+g.Uvg`I
4,!2pT
1aHSDU
%0G_ZLx
YY?kO|tJOF
j)8\cE
HRpW:[
d5|^vG
I;kO6bJ
+}mk/8
ul?va7
bG0Go(
Wawkp^9
xct$7-,x
;my=9-
dmx<-]h
S9 N}M
^-w`p1
}/`gR[5:
vd4gk|
@t$H.u6R
P)~#33?
fCB4XS
Hi^*)t
R`R8sr^|
iyX\]*
U4]N<p8
Khho?*
H VQjb
hr7 A5
YweY{
}3cu#.
=vhB9l?0
DLqB7
LSMn_N
)8jeT1nq
a8r]bzG,h
pon&D"
bi+|Nq\
BCqK=O
UM;hf{X
Qj[<3"
u8#yfWZ(:
]!4Z):
N7ba75
J4[>Y
/DMu#F
?}KNVi
ps:~Mh
kD+p4Hx
a[\}>e
Hc9r2Nw
.'e?TC
TH5#Sq
L}XRU$=h{
-,/f@xL
wjTE-S:i
2\Te k
%@ vj[
@G'on7Mm
AQBFP
vB2iA"
<]y~*D
9rk@]<0
@1q2>
d3P8gX!
lhD]Wh
;+tLD$v
oTN7er
f.DbGU
lR@o2^
FSfzR[
*G^oTw
h\'&xb
M|D+B,
#pc}>nAmM
/\D~WPmcg
7 dEUnk
aW[Wd$k
Q 7LPy
^\#6>\
]0rlZ_
/B2xDw
b~So?|
U|XXuz
QKM|w~
kg1xr%3<
c4QHo
`!,6GJ
6'FNwz
{0"`e4
SczTJp
i,b}(O
tegk_)
l) ;Sh
CB2TwK
]Q'JKd
#0IKX
<UEdiu
2W~d4On
O]jL7(
?\_mm+
kGWD@;4
Vdb&@Fk
k'>T?gc+l%wR
8{i}rX
zW`=1<L
58LW|@i
n'P[<D
XS:pbo
>$XTkC7p015
gO3r\&
ZMVSNz
=f:~445
2\9d(t
9D3]ciG
ZxDm95#
(q[9dF=
`]AK@&
FvLQFJw
ygK_{}@,
=UZ@ B)-Rr
No<OKA
(YZU1r
DEft/ka
^k`|s
YIjgb3
~|O_b@
j:#:Kq
}vU,+W1
==o,EmUrj
+N^mWUz
yG^;ekA
dNp}kS@c
Xi}u:T4
=\JYP|
cICcO%s
D1q0?[
FDT54zf-
#n0mWl
f:"*PC
[?<pc5
E$ per
JH -Aq
T">L8C
z>IM#C
Ai$^_
<qBBy
-\ _>[y
q$@UDF
xah3 i
!E~pi
9.f<N.
#?QQhD
B>Qb*E
@qc7^r+a*
8'/\{dHWY;
hvvo):
5|)od~
:$e$EA
pDSW}%
~UVec6
}XBTHPT_=}
"h7LV<
@Yd3!mD
t;yshy
'+qa+6
opj$_in
4s`!X8Dax
B\.&34
we<X=D
7wfDQ5
1CC!
,uyo2xuS
?V,mfU[
[[g&O)/4
8GZIrX
r,Y}Df
[T>d\+
Rx).{
.gUJhd
S^~4X
uIiVO-v
hI:PMD
d3;e\/
gJ?HW[r
0z'wOJD&j
Z.IX/3
qZ;^_t
|q(PS\
hoH^8P&
,}m~r?l
k*Wt@v
Bl moj
Y&b{eFH
OlNPY|
S^sCVQ
bMtP{k"
'<$dx~y
9?MCH/
K0IJFkQ
6g[&Yt
~HC<Ye
K0l[zI
Yw;uu,&
~fINf>u
pOiGkP+?
H3)%-V
'T}"oG
p.6uw
]5W`(;
FHh%~n:=,
yD+N_E:
ZmM] i
SYi9'k
:Xv*i=
q_Dh*2]/~
g,a2CH<
JK:rkn
f\!ES+
QCViAK
QQC!YIKP
@y{f"_
d>!IwV
G?:d[b
J60,x}
y\;voZ7}
YZJ^l3
jgU8uZ
ZQT]kJ
IIc=JNW
:ufXrm
2XnCqF
S!o`AC,y
?cIS+y
H4O]X_
QEBX{uB
%v>{?I
]}^| L
mkzUey*
,]VH> 0K
+uEl.{
|TP0]"
1^[)H@
1_5a+@
w[$6wZ
7,cw6gn8
3:R3Mcw
M?}9KI
ioQVI.u
FLM`]P
UxP3W
S.Z8V<~p
G*bS1A
uLt@T
Am)vhl
j7DR7sc
\kQ04C
`^9JVp
)wQ}KP
!RUZivV
N{wpo\`
{5f{V/q
?'*4<l{
0&:+FCTE
BreY'H6*
hNs*iM+
99W|^7
<^}'{O
{@^+UR
|@{pZ
p!c=q-;
^}1z,ds$
y @gw0
>0(byT
C?C"yt
y26FDwQ
,a5tBP
iWgiDL
kn%+11
aw4"G>
C|60L
vJoWq
D;>f+j.
#PL*?4;
kt%gVQ
]nvtNmc
38kV7a
Ci"<xe
=W: +\2
1PyESw
dy=PJa
w#5\-=K
JbER2V
Ygu>/3m
wT;%C-Z
I3SW\=
U&E{m.Y
@}<x.4
9EqmZY
wAyXk^Eh
$a;Ioo
9^ylo./
Y.^kGQ
1KQyio
EdmguG[
)|+=:%
Q'i+)
,.u,p6,
1[(e^X4
3ZPSf.-5
` y55
Yx:-K&
'ty!Ey3?}
O8T]zH)
.hl8o
n.}%<1
K[j%2M
H*L@==`k
t[LwGb
()ZbZ4
sJY3R2
G663{?
e%@!j1
-3Q4z_
Yt`.q
\L:~~F
g!=5eu
GN]F&Z+
fPjzbD/
Mk@)Vh=
"L2e_"L
=+Xymo
i*)7+6e
zy?MA
>-DS98"
M!WkD R
iD+=9d
flmP7'}S&
Tqs=@6
;A4oNX]r
nWm`zj
PmeD>HG
cwVMu}58t
lc~u:7!
-|_k,l
5,N}fX
<wwTbU
^%[gAX
iAsW)f
3.#7jpi
[9++>(
"8\qN4M4j
anl;( c5
p>BmV9
S[y;D+B
><[_.V
PXEfVY+
>zNr l
;B`.`X
iXM=xu
{{j:Fe
pAyW'1
gT.!N @-k
z:D&7
x04MQQ
[%$TEf
5;R"S
JWM$;9
$k5&hN(S
%v(j2=
|udkONh
,zr'FV
ZdPoOE
-<i0?5<
I2!X"K
A)A|i5 ~
NY%vFQ
RMmDyh
c1Z@_3
e00wWO
!}P*Mw
IPTiK^hX
&dRzZW;
%H>kft
>C@FPW<
9w.NW,
hkQj5
~g&Qm@Qgs
U" 1$AaF!
X84V\i
r,x}y7G
Xu0!aY
9K\4f~
kl%jB*
G3a~Eh
5?sDB}
j<7yl1
/zh6Nb
sxTI3<N
Yeuw%~
fDH#)I
G.cus
78e0*m
C5kkzs
2Z ~"0
VVVVVV
VVVVVVh\
ETbcs%
D$$PVV
^u2VVV
PSSSSS
j hpjH
j@j ^V
>=Yt1j
QQSVWh
teh9!H
URPQQhh*H
0SSSSS
0SSSSS
0SSSSS
0WWWWW
AAFFf;
0A@@Ju
;t$,v-
UQPXY]Y[
PPPPPPPP
FVh<%@
PPPPPPPP
GWh<%@
t"SS9]
t+WWVPV
InitializeSListHead
EnumDateFormatsA
LeaveCriticalSection
EraseTape
GetLongPathNameA
GetUserDefaultLangID
AddRefActCtx
GetCPInfoExW
WriteConsoleInputA
ReadConsoleInputW
GetConsoleAliasW
SetCommTimeouts
SetConsoleCP
VerifyVersionInfoA
WaitNamedPipeA
CreateMutexA
WriteConsoleW
GetLastError
CreateFileA
WritePrivateProfileSectionW
GetPrivateProfileSectionA
EnumDateFormatsExA
SetStdHandle
LoadLibraryA
RequestDeviceWakeup
FindFirstVolumeA
ReadFile
BuildCommDCBA
VerLanguageNameW
SetFileApisToANSI
WriteProcessMemory
RequestWakeupLatency
ResetEvent
EndUpdateResourceW
GetCPInfo
SetConsoleCtrlHandler
SetConsoleTitleA
GenerateConsoleCtrlEvent
GetCurrentConsoleFont
SetConsoleTextAttribute
AttachConsole
GetConsoleAliasesLengthW
ZombifyActCtx
ReadConsoleOutputW
GetSystemWindowsDirectoryA
GetStringTypeW
BuildCommDCBAndTimeoutsA
HeapAlloc
HeapLock
GetAtomNameW
HeapReAlloc
HeapValidate
GetGeoInfoA
GetCurrentProcess
GetProcAddress
GetModuleHandleA
CreateThread
GetVersionExA
GetACP
WaitForMultipleObjects
WaitForSingleObject
GetSystemPowerStatus
WriteConsoleOutputCharacterA
LocalAlloc
GetMailslotInfo
SetEnvironmentVariableW
GetFileAttributesExA
GetComputerNameW
CommConfigDialogA
GetConsoleWindow
PostQueuedCompletionStatus
GetDiskFreeSpaceW
KERNEL32.dll
GetAltTabInfoW
USER32.dll
GetCharWidth32A
GDI32.dll
AdjustTokenPrivileges
BackupEventLogA
ADVAPI32.dll
UnhandledExceptionFilter
SetUnhandledExceptionFilter
GetStartupInfoW
DeleteCriticalSection
EnterCriticalSection
HeapFree
VirtualFree
VirtualAlloc
HeapCreate
GetModuleHandleW
ExitProcess
WriteFile
GetStdHandle
GetModuleFileNameA
SetFilePointer
TerminateProcess
IsDebuggerPresent
SetHandleCount
GetFileType
GetStartupInfoA
GetModuleFileNameW
FreeEnvironmentStringsW
GetEnvironmentStringsW
GetCommandLineW
TlsGetValue
TlsAlloc
TlsSetValue
TlsFree
InterlockedIncrement
SetLastError
GetCurrentThreadId
InterlockedDecrement
QueryPerformanceCounter
GetTickCount
GetCurrentProcessId
GetSystemTimeAsFileTime
InitializeCriticalSectionAndSpinCount
RtlUnwind
WideCharToMultiByte
GetConsoleCP
GetConsoleMode
FlushFileBuffers
GetOEMCP
IsValidCodePage
HeapSize
GetLocaleInfoA
WriteConsoleA
GetConsoleOutputCP
MultiByteToWideChar
GetStringTypeA
LCMapStringA
LCMapStringW
CloseHandle
busekil.exe
@GetSecondVice@0
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
TIQ[QQ
OCOCGOe
|]]]\]
qqmmxmgm8L
/FAzm;5
/IQjE((
AYY~~lw
IHf2*3zM
D9`yio
SMtp?8
#Tds=/1
TW~~:5
XV}Tf~Qx
~,}wv|~zx
6CO`OG
x8#4)8O66`8
)4OQ`ee
<6QQQD_
c9@b#+I
"<m~d'r
=jr+${
'1_8q
>kz7v
A4_vm'W{r7e
]]]]]]]]]]]]]]]]]]]]]]]
.::::.
|pqqcc
>>>pq:
cE|||||||||||||||||||||zE
|||||||||||||||||.z
EEEEEEE
EEEEEEEE
XXjjjjjj
FFFFFFF
v@@@@@@@@@@@@@@v
nnnnnnnnnnnnnnnn
>>>>>q>qqqqqqq
>>>>p>q>qqqqq
>>>>>>
]]]]]]]]]]]]]]]]]]]]]]]
^^^^^^^^^^^^^
^^^^^^^^^^^^^^^^
^^^^^^^^^^^^^^^^
^^^^^^^^^^^^^^
;;;;;#;;#;;;;
2rrrr2
FFFFFF22
pFFFp
#####;;
{{{{{{
$$$$$$$$$$$$
l$$l$$l
q888888888
((((((((
ytz_wxx
tqoooup
wrx^vtq
[\Wt{~
/B2!X`Zz}~{
""""""""""""""""""""""""""""""""""""""
"uuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuu"
"uuuuu
########@#@@@@@@
######@###@@@@@@@@@@@@@@
###########@##@
@@@@@@@@@
######@##@
@@@@@@@@
#########@##@
@@@@@@@
#######@#
@@@@@@
##########@#
@@@@@@
########
:X~R##########
######
#######
#######
#g#####
"uuuuu
g######
gg#####
"uuuuu
#g#####
"uuuuuu
gg######u"
"uuuuuuu
#g#####
"uuuuuuuuuu
gg####u"
"uuuuuuuuuuu
gg###u"
"uuuuuuuuu
gg#gu"
"uuuuuuuuuuuuuu
"uuuuuuuuuuuu
ttttYYY??????
PPPPPPPPPPPPPPPPPPPPPPPPPPY
*********
*******
*************
******
********
********
******
4/}*****
/j*****
%4/}*****
/j****
4/}****
gggggg
>>>MM>
Jgggg>
JJJggg
JJJJJg
JJJJJg
JJJJJJ
JJJJJJJ
JJJJJJJJ
444444
cccccccccccccc}
************
*999999999999*
*ccccc
*ccccccc
1=YO"L
iiiiii
iiiiii
iiiiiiiiiiii
iiiiiiiiii
iiiiii
iiiiiiiii
iiiiiiiiiiiii
iiiiiiii

lpenowipazisalaleyiligebo pokuyowewofemoxo fefoyakelabepecodi
fusufaf
mscoree.dll
KERNEL32.DLL
((((( H
h(((( H
H
/ P6pL
,/KPip
/-P?pR
/ P6pL
,/KPip
/-P?pR
VS_VERSION_INFO
StringFileInform
081564b6
FileVersion
41.29.120.69
InternalName
voygmuaroke.exe
Copyright
Copyrighz (C) 2020, wodkaguds
ProductVersion
14.35.97.13
VarFileInfo
Translation
DPufepu menefe becedecocu bamayegibovur fecatekojurire nudajubikuwotu
Jawenu pit
Votohoyidi raxiyaxog
Futuce porifucocixeyPJabidisuwaw ditepanojejufir peviyolusakuxu bagoxonicov mezinokuli hakibelebicazoUFirupevocepo sericola yerakap fugayome cepaluvokigegu mif muredobalebif cehafularabad
Pigofiyoridux
\Zezepiyuwiyo vahebibe lesoromexagosa gidazahiro voweyodaxige panace mudibav tikerap sinigami Jepofuwam jal novelevugagu ledabEFoji dugetajoxoyubu nivuguyuhusos vewoworom zig vozet ruvabatugurovep
-Xopepadef televagoji laferuja gemava cij teza"Guzocizidanipi camitew yidalenixewTXijorewubevaw juroza hunusufajagugur ruzepeyifero wofo pulisowuduzuyol xecekoy wesim
Favu gulujeyicicuyug pib&Nirid yud vasugeculotog sokipebi coxim%Wocacu nadivesojuka gok kitu layuvipi^Cane yosetedehohohim xorebulura kexat lumamiduvekonu cifofemagu minaca xacuzah vuriwadehinokumOJica sokusurenewezut gecalusonuyewa daketujekuw mufe nel vomi wusirif noxixorocAMiker rexikusoce kezazibewugiy cisukaveci domixuxu tuyizelahunayiHDemab muduvubo morewuwaroxu rajifajol yilelucapu saruligevabuceg piyatof?Rojesurigupuh yitaf calas befihote kisux toxoyoke ciy key mehemyPejivosekig legulewomowad hipakapokifec geriboyasayezi yojunasawil tavebenotepej remo kacilixedicacop xetuna vaxowuwewesa
UFewosuhiji fidofek vigepavigafuwo wosaridixom vuvezus wehij payavib neravuyapoz yidoz
Wogefo sejarimi
Rarofip
Detavaneta
XDukoruxolarak siv xirecakecik sipoxawepacuze gaxaxebayaro loz gozukikopewuju zoyoduhosig*Zonosodugexa subukinija tukoj goluvovagigi
Sasodavocuhucoj ganabekalo)Pejawayux jovayo lomuresoyeluk suhufiyoko
Rucomavahixelu petobevezu4Wopejimudoz jiyehegavido wusoj dotadoradox kajuxiwatOVufogakozon dabunebofoxariy foxomeculivajo zabizal tohu mipuhu nanobuyugefi zecoSuvefaxezi tojizesabogulup wujojeten nozafowad zufamehetuxuxi gopuzidusihujo tenifasem gixiwazir kumucezazavama
Antivirus Signature
Bkav W32.AIDetect.malware1
Lionic Clean
Elastic malicious (high confidence)
MicroWorld-eScan Clean
FireEye Generic.mg.7671047a15b52a9c
CAT-QuickHeal Clean
McAfee Clean
Cylance Unsafe
VIPRE Clean
Sangfor Trojan.Win32.Save.a
K7AntiVirus Trojan ( 005690671 )
BitDefender Clean
K7GW Trojan ( 005690671 )
Cybereason malicious.9302aa
Baidu Clean
Cyren W32/Kryptik.EMQ.gen!Eldorado
Symantec ML.Attribute.HighConfidence
ESET-NOD32 Clean
APEX Malicious
Paloalto generic.ml
ClamAV Clean
Kaspersky VHO:Trojan-Ransom.Win32.Convagent.gen
Alibaba Clean
NANO-Antivirus Clean
ViRobot Clean
Rising Trojan.Generic@ML.90 (RDML:TXzCgWpRGBo64aSvOqOalg)
Ad-Aware Clean
TACHYON Clean
Emsisoft Trojan.Crypt (A)
Comodo Clean
F-Secure Clean
DrWeb Clean
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition BehavesLike.Win32.MultiPlug.jc
CMC Clean
Sophos ML/PE-A
Ikarus Trojan-Banker.UrSnif
GData Clean
Jiangmin Clean
Webroot Clean
Avira Clean
Antiy-AVL Clean
Kingsoft Clean
Gridinsoft Trojan.Win32.Packed.lu!heur
Arcabit Clean
SUPERAntiSpyware Clean
ZoneAlarm Clean
Microsoft Trojan:Win32/Azorult!ml
Cynet Malicious (score: 100)
AhnLab-V3 Clean
Acronis suspicious
BitDefenderTheta Clean
ALYac Clean
MAX Clean
VBA32 BScope.Trojan.Sabsik.FL
Malwarebytes Trojan.MalPack.GS
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Tencent Clean
Yandex Clean
SentinelOne Static AI - Malicious PE
eGambit Unsafe.AI_Score_82%
Fortinet W32/GenKryptik.ERHN!tr
Qihoo-360 HEUR/QVM10.1.BD47.Malware.Gen
Avast Clean
CrowdStrike win/malicious_confidence_100% (D)
MaxSecure Trojan.Malware.300983.susgen
No IRMA results available.