Static | ZeroBOX

PE Compile Time

2020-06-27 09:23:36

PDB Path

C:\zibefayato.pdb

PE Imphash

4d4fdfb7fcb2254a31ad850df30aced5

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x0005aff0 0x0005b000 7.96111647187
.data 0x0005c000 0x027469a4 0x00004800 0.629509250835
.rsrc 0x027a3000 0x00012988 0x00012a00 6.32453850141

Resources

Name Offset Size Language Sub-language File type
RT_CURSOR 0x027b4030 0x000008a8 LANG_NEUTRAL SUBLANG_NEUTRAL dBase III DBT, version number 0, next free block index 40, 1st item "\251\317"
RT_CURSOR 0x027b4030 0x000008a8 LANG_NEUTRAL SUBLANG_NEUTRAL dBase III DBT, version number 0, next free block index 40, 1st item "\251\317"
RT_CURSOR 0x027b4030 0x000008a8 LANG_NEUTRAL SUBLANG_NEUTRAL dBase III DBT, version number 0, next free block index 40, 1st item "\251\317"
RT_ICON 0x027b2b30 0x00000468 LANG_SERBIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x027b2b30 0x00000468 LANG_SERBIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x027b2b30 0x00000468 LANG_SERBIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x027b2b30 0x00000468 LANG_SERBIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x027b2b30 0x00000468 LANG_SERBIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x027b2b30 0x00000468 LANG_SERBIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x027b2b30 0x00000468 LANG_SERBIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x027b2b30 0x00000468 LANG_SERBIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x027b2b30 0x00000468 LANG_SERBIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x027b2b30 0x00000468 LANG_SERBIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x027b2b30 0x00000468 LANG_SERBIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x027b2b30 0x00000468 LANG_SERBIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x027b2b30 0x00000468 LANG_SERBIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x027b2b30 0x00000468 LANG_SERBIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x027b2b30 0x00000468 LANG_SERBIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x027b2b30 0x00000468 LANG_SERBIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x027b2b30 0x00000468 LANG_SERBIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x027b2b30 0x00000468 LANG_SERBIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_STRING 0x027b54d8 0x000004aa LANG_SERBIAN SUBLANG_DEFAULT data
RT_STRING 0x027b54d8 0x000004aa LANG_SERBIAN SUBLANG_DEFAULT data
RT_STRING 0x027b54d8 0x000004aa LANG_SERBIAN SUBLANG_DEFAULT data
RT_ACCELERATOR 0x027b3030 0x00000010 LANG_SERBIAN SUBLANG_DEFAULT data
RT_ACCELERATOR 0x027b3030 0x00000010 LANG_SERBIAN SUBLANG_DEFAULT data
RT_GROUP_CURSOR 0x027b48d8 0x00000022 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_GROUP_CURSOR 0x027b48d8 0x00000022 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_GROUP_ICON 0x027b2f98 0x00000068 LANG_SERBIAN SUBLANG_DEFAULT data
RT_GROUP_ICON 0x027b2f98 0x00000068 LANG_SERBIAN SUBLANG_DEFAULT data
RT_GROUP_ICON 0x027b2f98 0x00000068 LANG_SERBIAN SUBLANG_DEFAULT data
RT_VERSION 0x027b4900 0x000001f0 LANG_NEUTRAL SUBLANG_NEUTRAL MS Windows COFF PowerPC object file

Imports

Library KERNEL32.dll:
0x401018 AddRefActCtx
0x40101c GetCPInfoExW
0x401020 WriteConsoleInputA
0x401024 ReadConsoleInputW
0x401028 GetConsoleAliasW
0x40102c SetCommTimeouts
0x401038 SetConsoleCP
0x40103c VerifyVersionInfoA
0x401040 WaitNamedPipeA
0x401044 CreateMutexA
0x401048 WriteConsoleA
0x40104c SetLastError
0x401050 CreateFileA
0x40105c EnumDateFormatsExA
0x401060 SetStdHandle
0x401064 LoadLibraryW
0x401068 RequestDeviceWakeup
0x40106c FindFirstVolumeA
0x401070 ReadFile
0x401074 BuildCommDCBA
0x401078 VerLanguageNameA
0x40107c SetFileApisToANSI
0x401080 WriteProcessMemory
0x401084 ResetEvent
0x401088 Sleep
0x40108c EndUpdateResourceW
0x401090 GetCPInfo
0x401094 GetLastError
0x40109c SetConsoleTitleA
0x4010a0 SetFilePointer
0x4010a4 GetLongPathNameW
0x4010a8 CopyFileA
0x4010ac AttachConsole
0x4010b4 ZombifyActCtx
0x4010b8 ReadConsoleOutputW
0x4010c0 GetStringTypeW
0x4010c8 HeapAlloc
0x4010cc HeapLock
0x4010d0 GetAtomNameW
0x4010d4 GlobalSize
0x4010d8 HeapValidate
0x4010dc GetGeoInfoA
0x4010e0 GetCurrentProcess
0x4010e4 GetProcAddress
0x4010e8 GetModuleHandleA
0x4010ec CreateThread
0x4010f0 GetVersionExA
0x4010f4 GetACP
0x4010fc WaitForSingleObject
0x401108 LocalAlloc
0x40110c GetMailslotInfo
0x401118 GetComputerNameW
0x40111c CommConfigDialogA
0x401120 GetConsoleWindow
0x401128 GetDiskFreeSpaceW
0x401130 EnumDateFormatsA
0x401138 InitializeSListHead
0x401144 GetStartupInfoW
0x401148 SetHandleCount
0x40114c GetStdHandle
0x401150 GetFileType
0x401154 GetStartupInfoA
0x40115c TerminateProcess
0x401160 IsDebuggerPresent
0x401168 HeapFree
0x40116c VirtualFree
0x401170 VirtualAlloc
0x401174 HeapReAlloc
0x401178 HeapCreate
0x40117c GetModuleHandleW
0x401180 ExitProcess
0x401184 WriteFile
0x401188 GetModuleFileNameA
0x40118c GetModuleFileNameW
0x401198 GetCommandLineW
0x40119c TlsGetValue
0x4011a0 TlsAlloc
0x4011a4 TlsSetValue
0x4011a8 TlsFree
0x4011b0 GetCurrentThreadId
0x4011bc GetTickCount
0x4011c0 GetCurrentProcessId
0x4011cc RtlUnwind
0x4011d0 LoadLibraryA
0x4011d4 WideCharToMultiByte
0x4011d8 GetConsoleCP
0x4011dc GetConsoleMode
0x4011e0 FlushFileBuffers
0x4011e4 GetOEMCP
0x4011e8 IsValidCodePage
0x4011ec HeapSize
0x4011f0 GetLocaleInfoA
0x4011f4 GetConsoleOutputCP
0x4011f8 WriteConsoleW
0x4011fc MultiByteToWideChar
0x401200 GetStringTypeA
0x401204 LCMapStringA
0x401208 LCMapStringW
0x40120c CloseHandle
Library USER32.dll:
0x401214 GetAltTabInfoW
Library GDI32.dll:
0x40100c GetCharWidth32A
Library ADVAPI32.dll:
0x401004 BackupEventLogA

Exports

Ordinal Address Name
1 0x4526a8 @GetSecondVice@0
!This program cannot be run in DOS mode.
`.data
bad allocation
lihitomozecavizudovinegefi danutir xuyatedekoxijokayewewopom
Kapopoyelico budixozabos sivegawebusuce
verosiwagasedavijozegulozakegakutafojajocoxelufayifelif
Civaciguz yuvoxipugewod vaxen
Kocezafinoparog
kernel32.dll
LocalAlloc
VirtualProtect
porinufudifohe
CorExitProcess
runtime error
TLOSS error
SING error
DOMAIN error
An application has made an attempt to load the C runtime library incorrectly.
Please contact the application's support team for more information.
- Attempt to use MSIL code from this assembly during native code initialization
This indicates a bug in your application. It is most likely the result of calling an MSIL-compiled (/clr) function from a native constructor or from DllMain.
- not enough space for locale information
- Attempt to initialize the CRT more than once.
This indicates a bug in your application.
- CRT not initialized
- unable to initialize heap
- not enough space for lowio initialization
- not enough space for stdio initialization
- pure virtual function call
- not enough space for _onexit/atexit table
- unable to open console device
- unexpected heap error
- unexpected multithread lock error
- not enough space for thread data
This application has requested the Runtime to terminate it in an unusual way.
Please contact the application's support team for more information.
- not enough space for environment
- not enough space for arguments
- floating point support not loaded
Microsoft Visual C++ Runtime Library
<program name unknown>
Runtime Error!
Program:
EncodePointer
DecodePointer
FlsFree
FlsSetValue
FlsGetValue
FlsAlloc
GetProcessWindowStation
GetUserObjectInformationA
GetLastActivePopup
GetActiveWindow
MessageBoxA
USER32.DLL
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
HH:mm:ss
dddd, MMMM dd, yyyy
MM/dd/yy
December
November
October
September
August
February
January
Saturday
Friday
Thursday
Wednesday
Tuesday
Monday
Sunday
CONOUT$
SunMonTueWedThuFriSat
JanFebMarAprMayJunJulAugSepOctNovDec
C:\zibefayato.pdb
%g0G]s
`/J]$[q]
S';s,F!
#C_&2Av
bKas CP
"'61eZ9|
nuenGGK)-
hx>K6P
5WhQF
wEsZ'W_
I#BE_'
?u((eZ
}3~81Oq
!rZNZ`
?Ng$Gm
s#by:DjAMb
f(_'| yT
UY8>SD::+
!$X`l3]
)8aX{p
2]v#;s
K_xo"U
9$5gXr<kq
L<zi,k
EC{du|
hwr0AR
CQXk)R2
'a`Zj[?
iA;C|
r/@$j3
\Ll}Z1
3CCWq86
E,lpw^B0
Zk}n_O
rQ>?fe_;
iz2dm.
2U|+J3
~>T,)&
e\#+FU
cF`Z'RA
d.IIl(T
xoi8T?
"f'v+C
(Jfap(C
L{tYIH
1;%r'y
?9r!DP
A05o+b
%)"}moYC
`G/Iw~
..y -`I
*-^[eY>*
{z.k\^
)1\,Skk
zyOz'j
>bb#{*
0tr?@^
(9>In"
8T'I]X,
S%/O(A
%'.-gj
b?%P@#B
/jP`WT
U4YJs{
<ALBxN
q/kPYde
WY"gr6
]K6]w~
$Cqu5vx
7kj~Mc;#
%L>]:bD
fHp^JtdQ
ds]K0q5
`G(nH
z"F=RB:
#HKLdL
^U$5]b
oAM`d]a\
5R-rU!
jRB?r 6
{x:Z6S
T8q.I,v
{m%${~
bt~PM2
5YwIU UR
J^X'4!
aiGL8&
["@mIv
(dB]h.
<X\,fgR
xB}>6:
5-0Sfc
qb\$zi0
sN?<uE
(WdV`h
Mqnww,:&
L$@]a6
XUo1BG
;OUZaK
,S:5Cy
<G@D
0:13/J>Ng4z
>i/v-24
)HJjI0P
bYd/pr
2dC|n2Q:
0pwL&U:
}_TY5(
x!^=6.
-VxsX=f
>+=Usv
@,'YnVY
\1_T~!
[ ?^Va
:(3k)N
Ups'U-
k*{2fI"
<G&=Y"
N*@WS]
e9r$>v<
S_or^v
+sij}1
UHX)#?p
*@=GFaQ
,X;ygO
Pk>=Sw
'K'_}vqoT
#vO(Fg
8xd4~OC
zhY.a<
(\!Z!O
"*gZ5$
)=Fmd0
Jg&N&3
7PjXe^
MkCub-jq
%l3*>O
MYajnY
W9x_r2G+
7\.t,cD
TPz{.
Y51@ENvK
\NGIE3
xL`Goto
"'>Jj8
HF&kpB
[Np2K%
s}-x9E
r.TQ?|x
4L0xT`,
%/Xqo
pa&fe)
avkP2h
Z>4AH
`Opr//;
m5oZjQ=
d>pbFI (
ChIA23
Bq2SPU
Q_RPMP
nY/?N
3+O'P~
]":h5j
5|fy<8<D
E\Y(Ni
J}2b,u
rvx$<k
#6Z>]%
~[22co
j~9&Ej
n_:vTlV
Ue?89
,r7 C^
@FZ:9c:E
,7S%^t
K(9dA*
.1k>FK
AT9=Hb
K}K|i$
8zc=*KB>W
`F8LsP
qO-xrz
@6w"5+
^U$Qodz
ux?2&;
Y]^VD>
QSZ2.![
@:kw#t
y;+>St
lU?&N4l
kL~ZG0
{L$9{Q
qehCf
Vj29tNo
rgy4Sv
fj9ms4
cvr3Q"
nVM:R#
I, R'G"
C88)W&
kJlK#Nn
=aMIt!
< zFq(
x]-WQ
.h}y{K
TxkX@^c
aW4-nY|1
A;[KORu
W|YIF^
4[R\neD
!qa/z m
1{"D^1
_esE;"F
mN's|.
/.2+FP
u,&O"_
]>/OG5l
8I>QrKor
z55 "3
5)nUzU?
[6gHdu
dw34_eN
K#i.IR
gSX(DR>
~]:IaAZ,
?Gtn`7<g
d/]uR,n
_f*z4S
3#a?L\
9N-PN"y|`
[q"[0m
%>fI]np]1
9a9izQ;x8
.~%^Ig
nP5\/y
m{Z|K#A
vJD30K
_~l~0v
6y}"xs
p+]qq8E
2qr$$nC
Q)T$FO2
_eR/GV
1np`:aa
D*07A:
gArj`
^M6Fb[iqJ
X>4h=b
@m,%G6
eQfIK-
l& q6T
;_ lUO
eD"ji
~x[~If
'z0`30ZD9
&xP~!k
Vh#g~'
++35qC
$ElwcP
S}|~gae
(7Jj&38
GNsS4T
RgZEa<
x"J/Ta
0\G%)&8
cc9SCI
;d76ZF
zNJ0Ye
X,OiO?
FUa<3i
}QTiE
zrw^*/
k{w5zX
dK2<o/+
F@EQ2)L
0d~}gyc
''%(Cb>
=7,/pF3
!\IYjWZ
i"(|H-q
gJkApJ
HW|,_0
P>sW)g
^1+i!b5
g`Z+PWH
Xe!3&?!L
B)8JGP'C
f$UC(U
:u=ms1
+W$0r"
b%)D+
F7Eq$}
N|7;{
Y=M`Edd
~mb_/e
SWJ(87
tR"e/p
8\a+m3
$T;nCNI
t%!<F(
=K{BWe
{Q@a7a
_JQ;)=
SD@T}v<T
~\,WB-
7FW-nG
YgbVg:
g*E^nR
&QjBPB
Y^<E.B
.(w'cIf$
-Deqkzk
t<e4gr
w;+gA;
ry4ZpRI
qL?%f
Ib3Q]N
t/hTrRP
KD]-Y~S@
kj-'OJ&
^y(|uh
rb"a&r
-6{Te[
kARMcN&%NYH!
vxeG:1
uWp{SQ-
*H8k"h
CGGfqUH
+^>yw
TcG>4%.
PcB g~
Xa\= OdU
'qd{mEE|L
(Z+jsN
lpCbMX
~&1Du
\uWaEf(
O5dn!q
bNi<f"
(twCA+
?+m)v6
YN:0/@
vK$# W7
t6Mva0
alwe2T
%4(;]?
pR`<_)
\hTS/e
RI<7r?
?5rFzC
WD'L"J
|EAx|
JtHN$_
-2glC9$BO
N35uHv
TxH.:p
pbf;>O
Z>4T;hO
:te-@W:
vxh X"
9Ih~(Y9l
;O8uSu
?Jrp1^b
1\d?zh(
.%ih4@
n'(<"=E+
ECV$,iMWN7&
u=;{6YR
~2gJzf
Mo9%6;
$}xKMSg_F
LvU?O{
`CbED>
CP<\91+
[2q}]L
VF|abW'
wH773';&4
fRyZ"]
g@5D2,q
= #zZx
%3vC5@'.
bydO9h
_i5G?Q
du0cB{
H{W2^E
S9UF\{
UEAl%M
bwDY2g
UT!vWi
1d8=ot
4>Y~tR6
G+Ri9s
DhN7 E
~`<L&Y
Ze62;[
#vXg.<$ve
. :r;M
^k4-]:3
c1O-K0
sY0$dGu
*!|5B-G
4H>TUO_]
i*^YMR
pE,NaN4I
_-AnJq
GQwvUl
46,:pA
1\}N x
kJw@e9
DPf"37
_;zZ-2
xJ4\s/
+!DVGqz
Ya,IT
ln\$K;;
bq2-)Z
v^l0F0
+}Sx',-
SZaVY@)
RH DJD
v)pfw{3
"P>g^
w*L>JXj
*:O0mG
B~DFG9p`!
qx%d4V*&
%#OVj
*]EBvE
b-|T <
}7Zv1j)
IO6(O
+P!._V
k}ILKw
<ZM6*N
[xW_1w
:\S{ci
E]=nHg
i.8JuV/
*gi/<P
111ZB
;^j5[^
F(8C4P
K|_hV^C~
K,#Uh-
h}3>5
3JR-gm
6lsdqx
g.b}?nzR
)2p9z2d<k
:[8K&*]!
ax^(ON
s{lfHa
b0rY'M
L>3Q"a
lgY7k}-
53Mdez
f2)k0k
:i!.qf
}CB"FR
Mk{Rb(
rr9h<\
buDh{=\
S/{T1&
QVM-G'
<i>&<
BOQMktZ0
4Yk#(9%D
k|q91q(>9
8K#G{Fw
~U(%0=
f*1nBmx
qHc>j9N
zW;#(t
_`HNX:
#`tQKR65
h_sxr[
v3TZg*;
Dj<l,)~
RZKz'\
RhkP)[J
Wb!L$jK
v'zj.$
#of-Mbh
Pb7tfG1N
!_'ibX)>Iw
{IegyS+n
eiJs2
x'L>4[J
b<Z}D%
{[:X)N
;k[<Xt
KV,fW<
(3x+l
ysv_hX
zUX7(t
Aw#eYG
H=!~,knVe
TJPwK^!
~n{|:D
Y9FxT+8~
c\_<c
Y|A$*
B]`.fq
'|@UY2~j
>rpx]u
c9"pep3D
zNY.YV
Vn"WZN
'Ya$0Y
";]7`a
".,9J
/GXht
9UW /wK
H*QZb.
jUPH9RVn0%3
45^h\_
NjE*9;cL3
q#2GvT
5,Xssz
lS(xF)X
5 s;g%
_n>/ |
}0n,LL
kvdt*A
{6AYVBz3r
"I7(k4
6&%Yal
a@c{"G?
)qM"p@
uF4W(wu:tr\I#CI
1r qz\9
:e*C88
0#xbs)
cq{E-/
$t4+t]
8eC!P^S
<0P>7r
"H|>J\
ZORZCgjq,
$w"FGF
hB#f:DO
:h!j7y*
[6tcvV
<+1eF
AH<NYkF?
.>lW9x
XIu0n0
Z!.VE{
;++3ntf
44T+QMf
$8WmI
%[R#F4
5Sadi.
7l]+sc
EL5N./
uWp1cT
VVVVVV
VVVVVVh
ETbcs%
^u/VVV
PSSSSS
j@j ^V
>=Yt1j
QQSVWh
URPQQh
0SSSSS
0SSSSS
0SSSSS
0WWWWW
AAFFf;
0A@@Ju
;t$,v-
UQPXY]Y[
PPPPPPPP
PPPPPPPP
t"SS9]
t+WWVPV
InitializeSListHead
EnumDateFormatsA
LeaveCriticalSection
GetLongPathNameW
GetUserDefaultLangID
AddRefActCtx
GetCPInfoExW
WriteConsoleInputA
ReadConsoleInputW
GetConsoleAliasW
SetCommTimeouts
GetConsoleDisplayMode
CreateConsoleScreenBuffer
SetConsoleCP
VerifyVersionInfoA
WaitNamedPipeA
CreateMutexA
WriteConsoleA
SetLastError
CreateFileA
WritePrivateProfileSectionW
GetPrivateProfileSectionA
EnumDateFormatsExA
SetStdHandle
LoadLibraryW
RequestDeviceWakeup
FindFirstVolumeA
ReadFile
BuildCommDCBA
VerLanguageNameA
SetFileApisToANSI
WriteProcessMemory
ResetEvent
EndUpdateResourceW
GetCPInfo
GetLastError
SetConsoleCtrlHandler
SetConsoleTitleA
SetFilePointer
GetCurrentConsoleFont
CopyFileA
AttachConsole
GetConsoleAliasesLengthW
ZombifyActCtx
ReadConsoleOutputW
GetSystemWindowsDirectoryA
GetStringTypeW
BuildCommDCBAndTimeoutsA
HeapAlloc
HeapLock
GetAtomNameW
GlobalSize
HeapValidate
GetGeoInfoA
GetCurrentProcess
GetProcAddress
GetModuleHandleA
CreateThread
GetVersionExA
GetACP
WaitForMultipleObjects
WaitForSingleObject
GetSystemPowerStatus
WriteConsoleOutputCharacterW
LocalAlloc
GetMailslotInfo
SetEnvironmentVariableW
GetFileAttributesExA
GetComputerNameW
CommConfigDialogA
GetConsoleWindow
PostQueuedCompletionStatus
GetDiskFreeSpaceW
KERNEL32.dll
GetAltTabInfoW
USER32.dll
GetCharWidth32A
GDI32.dll
AdjustTokenPrivileges
BackupEventLogA
ADVAPI32.dll
UnhandledExceptionFilter
SetUnhandledExceptionFilter
GetStartupInfoW
SetHandleCount
GetStdHandle
GetFileType
GetStartupInfoA
DeleteCriticalSection
TerminateProcess
IsDebuggerPresent
EnterCriticalSection
HeapFree
VirtualFree
VirtualAlloc
HeapReAlloc
HeapCreate
GetModuleHandleW
ExitProcess
WriteFile
GetModuleFileNameA
GetModuleFileNameW
FreeEnvironmentStringsW
GetEnvironmentStringsW
GetCommandLineW
TlsGetValue
TlsAlloc
TlsSetValue
TlsFree
InterlockedIncrement
GetCurrentThreadId
InterlockedDecrement
QueryPerformanceCounter
GetTickCount
GetCurrentProcessId
GetSystemTimeAsFileTime
InitializeCriticalSectionAndSpinCount
RtlUnwind
LoadLibraryA
WideCharToMultiByte
GetConsoleCP
GetConsoleMode
FlushFileBuffers
GetOEMCP
IsValidCodePage
HeapSize
GetLocaleInfoA
GetConsoleOutputCP
WriteConsoleW
MultiByteToWideChar
GetStringTypeA
LCMapStringA
LCMapStringW
CloseHandle
sutixeje.exe
@GetSecondVice@0
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
TIQ[QQ
OCOCGOe
|]]]\]
qqmmxmgm8L
/FAzm;5
/IQjE((
AYY~~lw
IHf2*3zM
D9`yio
SMtp?8
#Tds=/1
TW~~:5
GGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGG
GGGGGGGGGGGGGGGGGGGGW%4
GGGGGGGGGGGGGGGGGGI
]GGGGGGGGGGGGGGGG|K`@V
GGGGGGGGGGGGGGG
GGGGGGGGGGGGGG<
GGGGGGGGGGGGGGG
]GGGGGGGGGGGGGGGt
GGGGGGGGGGG
'YGGGGGGGGGG
!GGGGGGGGGGc
GGGGGGGGGGGG
GGGGGGGGGGGG
GGGGGGGGGGGGG
pGGGGGGGGGGGG8i
{GGGGGGGGGGGGcNGGGGG
GGGGGGGGGGGGGGGGGG
GGGGGGGGGGGGGGGGGG
{GGGGGGGGGGGGGGGGGG
GGGGGGGGGGGGGGGGGG{
uGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGG
bbbbbbbbbbbbbbbbbbbbbbbbbbb6^
bbbbbbbbbbbb
bbbbbbbbbbb
#bbbbbbbbbb:
'bbbbbbbbb
bbbbbb
bbbbbbbT
Bbbbbbbb
bbbbbbbbT
bbbbbbbb
PbbbbbbbbbbbbL
p\bbbbbbbbbbb
bbbbbbbbbbbbT
Dbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbb
#|gv@}
6CO`OG
x8#4)8O66`8
)4OQ`ee
<6QQQD_
c9@b#+I
"<m~d'r
=jr+${
'1_8q
>kz7v
A4_vm'W{r7e
iiiiii
iiiiii
iiiiiiiiiiii
iiiiiiiiii
iiiiii
iiiiiiiii
iiiiiiiiiiiii
iiiiiiii

Gepiragaxowohoz falenuvesexoloj domibezol
penowipazisalaleyiligebo pokuyowewofemoxo fefoyakelabepecodi
fTegah
fusufaf
mscoree.dll
KERNEL32.DLL
((((( H
h(((( H
H
/ P6pL
,/KPip
/-P?pR
/ P6pL
,/KPip
/-P?pR
VS_VERSION_INFO
StringFileInform
081564b6
FileVersion
41.29.120.69
InternalName
voygmuaroke.exe
Copyright
Copyrighz (C) 2020, wodkaguds
ProductVersion
14.35.97.13
VarFileInfo
Translation
DPufepu menefe becedecocu bamayegibovur fecatekojurire nudajubikuwotu
Jawenu pit
Votohoyidi raxiyaxog
Futuce porifucocixeyPJabidisuwaw ditepanojejufir peviyolusakuxu bagoxonicov mezinokuli hakibelebicazoUFirupevocepo sericola yerakap fugayome cepaluvokigegu mif muredobalebif cehafularabad
\Zezepiyuwiyo vahebibe lesoromexagosa gidazahiro voweyodaxige panace mudibav tikerap sinigami Jepofuwam jal novelevugagu ledabEFoji dugetajoxoyubu nivuguyuhusos vewoworom zig vozet ruvabatugurovep
-Xopepadef televagoji laferuja gemava cij teza"Guzocizidanipi camitew yidalenixewTXijorewubevaw juroza hunusufajagugur ruzepeyifero wofo pulisowuduzuyol xecekoy wesim
Favu gulujeyicicuyug pib&Nirid yud vasugeculotog sokipebi coxim%Wocacu nadivesojuka gok kitu layuvipi^Cane yosetedehohohim xorebulura kexat lumamiduvekonu cifofemagu minaca xacuzah vuriwadehinokumOJica sokusurenewezut gecalusonuyewa daketujekuw mufe nel vomi wusirif noxixorocAMiker rexikusoce kezazibewugiy cisukaveci domixuxu tuyizelahunayiHDemab muduvubo morewuwaroxu rajifajol yilelucapu saruligevabuceg piyatof?Rojesurigupuh yitaf calas befihote kisux toxoyoke ciy key mehemyPejivosekig legulewomowad hipakapokifec geriboyasayezi yojunasawil tavebenotepej remo kacilixedicacop xetuna vaxowuwewesa
UFewosuhiji fidofek vigepavigafuwo wosaridixom vuvezus wehij payavib neravuyapoz yidoz
Wogefo sejarimi
Rarofip
Detavaneta
XDukoruxolarak siv xirecakecik sipoxawepacuze gaxaxebayaro loz gozukikopewuju zoyoduhosig*Zonosodugexa subukinija tukoj goluvovagigi
Sasodavocuhucoj ganabekalo)Pejawayux jovayo lomuresoyeluk suhufiyoko
Rucomavahixelu petobevezu4Wopejimudoz jiyehegavido wusoj dotadoradox kajuxiwatOVufogakozon dabunebofoxariy foxomeculivajo zabizal tohu mipuhu nanobuyugefi zecoSuvefaxezi tojizesabogulup wujojeten nozafowad zufamehetuxuxi gopuzidusihujo tenifasem gixiwazir kumucezazavama
Antivirus Signature
Bkav W32.AIDetect.malware2
Lionic Clean
Elastic malicious (high confidence)
DrWeb Clean
Cynet Malicious (score: 100)
CMC Clean
CAT-QuickHeal Clean
McAfee Trojan-FTUB!47F0522A0CFD
Cylance Unsafe
Zillya Clean
Sangfor Trojan.Win32.Save.a
K7AntiVirus Trojan ( 005690671 )
Alibaba Clean
K7GW Trojan ( 005690671 )
CrowdStrike win/malicious_confidence_90% (W)
BitDefenderTheta Clean
Cyren W32/Kryptik.EMQ.gen!Eldorado
Symantec ML.Attribute.HighConfidence
ESET-NOD32 Clean
Zoner Clean
TrendMicro-HouseCall Clean
Paloalto Clean
ClamAV Clean
Kaspersky UDS:Exploit.Win32.Shellcode.gen
BitDefender Clean
NANO-Antivirus Clean
ViRobot Clean
MicroWorld-eScan Clean
Rising Trojan.Generic@ML.90 (RDML:jxrCgX8ZYPN8ZeNFkmimuw)
Ad-Aware Clean
Sophos ML/PE-A + Troj/Krypt-K
Comodo Clean
F-Secure Clean
Baidu Clean
VIPRE Clean
TrendMicro Clean
McAfee-GW-Edition BehavesLike.Win32.Lockbit.gc
FireEye Generic.mg.47f0522a0cfd75f0
Emsisoft Trojan.Crypt (A)
Ikarus Trojan-Spy.MSIL.Agent
Jiangmin Clean
Webroot Clean
Avira Clean
MAX Clean
Antiy-AVL Clean
Kingsoft Clean
Microsoft Trojan:Win32/Azorult!ml
Gridinsoft Trojan.Win32.Packed.lu!heur
Arcabit Clean
SUPERAntiSpyware Clean
ZoneAlarm UDS:DangerousObject.Multi.Generic
GData Clean
AhnLab-V3 Clean
Acronis suspicious
VBA32 BScope.Trojan.Sabsik.FL
ALYac Clean
TACHYON Clean
Malwarebytes MachineLearning/Anomalous.95%
Panda Clean
APEX Malicious
Tencent Clean
Yandex Clean
SentinelOne Static AI - Malicious PE
MaxSecure Trojan.Malware.300983.susgen
Fortinet W32/GenKryptik.ERHN!tr
AVG FileRepMalware
Cybereason malicious.c477c8
Avast FileRepMalware
Qihoo-360 HEUR/QVM10.1.BEAF.Malware.Gen
No IRMA results available.