Static | ZeroBOX

PE Compile Time

2020-07-08 01:16:26

PDB Path

C:\wokiyemonak\fufociru\honehujehixuv\v.pdb

PE Imphash

9f6e89a1c9887d95e8374b4cda8a71c7

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x00079bcb 0x00079c00 7.93853506988
.data 0x0007b000 0x00fd46a0 0x00005200 1.19155532055
.rsrc 0x01050000 0x0001e5f8 0x0001e600 6.53958630388

Resources

Name Offset Size Language Sub-language File type
YASUTAXACOJIFIWIGIJUPEGU 0x0106d420 0x000008bd LANG_SERBIAN SUBLANG_DEFAULT ASCII text, with very long lines, with no line terminators
RT_CURSOR 0x0106dfa0 0x000000b0 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_CURSOR 0x0106dfa0 0x000000b0 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_CURSOR 0x0106dfa0 0x000000b0 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x0106cf40 0x00000468 LANG_SERBIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x0106cf40 0x00000468 LANG_SERBIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x0106cf40 0x00000468 LANG_SERBIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x0106cf40 0x00000468 LANG_SERBIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x0106cf40 0x00000468 LANG_SERBIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x0106cf40 0x00000468 LANG_SERBIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x0106cf40 0x00000468 LANG_SERBIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x0106cf40 0x00000468 LANG_SERBIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x0106cf40 0x00000468 LANG_SERBIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x0106cf40 0x00000468 LANG_SERBIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x0106cf40 0x00000468 LANG_SERBIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x0106cf40 0x00000468 LANG_SERBIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x0106cf40 0x00000468 LANG_SERBIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x0106cf40 0x00000468 LANG_SERBIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x0106cf40 0x00000468 LANG_SERBIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x0106cf40 0x00000468 LANG_SERBIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x0106cf40 0x00000468 LANG_SERBIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x0106cf40 0x00000468 LANG_SERBIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x0106cf40 0x00000468 LANG_SERBIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x0106cf40 0x00000468 LANG_SERBIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x0106cf40 0x00000468 LANG_SERBIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x0106cf40 0x00000468 LANG_SERBIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x0106cf40 0x00000468 LANG_SERBIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x0106cf40 0x00000468 LANG_SERBIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x0106cf40 0x00000468 LANG_SERBIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x0106cf40 0x00000468 LANG_SERBIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x0106cf40 0x00000468 LANG_SERBIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x0106cf40 0x00000468 LANG_SERBIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x0106cf40 0x00000468 LANG_SERBIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x0106cf40 0x00000468 LANG_SERBIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x0106cf40 0x00000468 LANG_SERBIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x0106cf40 0x00000468 LANG_SERBIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x0106cf40 0x00000468 LANG_SERBIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x0106cf40 0x00000468 LANG_SERBIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_STRING 0x0106e560 0x00000094 LANG_SERBIAN SUBLANG_DEFAULT data
RT_STRING 0x0106e560 0x00000094 LANG_SERBIAN SUBLANG_DEFAULT data
RT_ACCELERATOR 0x0106dd18 0x00000010 LANG_SERBIAN SUBLANG_DEFAULT data
RT_ACCELERATOR 0x0106dd18 0x00000010 LANG_SERBIAN SUBLANG_DEFAULT data
RT_GROUP_CURSOR 0x0106e050 0x00000022 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_GROUP_CURSOR 0x0106e050 0x00000022 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_GROUP_ICON 0x01060348 0x00000068 LANG_SERBIAN SUBLANG_DEFAULT data
RT_GROUP_ICON 0x01060348 0x00000068 LANG_SERBIAN SUBLANG_DEFAULT data
RT_GROUP_ICON 0x01060348 0x00000068 LANG_SERBIAN SUBLANG_DEFAULT data
RT_GROUP_ICON 0x01060348 0x00000068 LANG_SERBIAN SUBLANG_DEFAULT data
RT_GROUP_ICON 0x01060348 0x00000068 LANG_SERBIAN SUBLANG_DEFAULT data
RT_VERSION 0x0106e078 0x000001b4 LANG_NEUTRAL SUBLANG_NEUTRAL data

Imports

Library KERNEL32.dll:
0x401004 CreateActCtxW
0x401008 ReadConsoleInputA
0x401018 VerifyVersionInfoA
0x40101c CreateFileW
0x401028 EnumDateFormatsExA
0x40102c GetCurrentProcessId
0x401030 LoadLibraryA
0x401034 IsDebuggerPresent
0x401038 SetConsoleCP
0x40103c FindFirstVolumeA
0x401040 WriteFile
0x401044 BuildCommDCBW
0x401048 VerLanguageNameA
0x40104c SetFileApisToANSI
0x401050 WriteProcessMemory
0x401054 SetEvent
0x401058 GetExitCodeThread
0x40105c EndUpdateResourceW
0x401060 GetCPInfo
0x401064 GetLastError
0x401068 UpdateResourceA
0x40106c SetConsoleTitleW
0x401070 SetFilePointer
0x401074 LoadLibraryExA
0x401078 CopyFileW
0x401080 ReadConsoleA
0x401084 ActivateActCtx
0x401088 AddRefActCtx
0x40108c HeapLock
0x401094 ReadConsoleOutputA
0x401098 GetProcessHeaps
0x4010a0 GetUserDefaultLCID
0x4010a8 HeapAlloc
0x4010ac UnmapViewOfFile
0x4010b0 GetAtomNameA
0x4010b4 HeapSize
0x4010b8 GetGeoInfoW
0x4010bc GetCurrentProcess
0x4010c0 VirtualProtect
0x4010c4 GetProcAddress
0x4010c8 GetModuleHandleA
0x4010cc CreateThread
0x4010d0 GetVersionExW
0x4010d8 WaitForSingleObject
0x4010e0 VerifyVersionInfoW
0x4010ec GetComputerNameW
0x4010f0 CommConfigDialogW
0x4010f4 GetConsoleAliasA
0x4010f8 GetConsoleWindow
0x401100 GetDiskFreeSpaceA
0x401104 CloseHandle
0x401110 Sleep
0x401120 RaiseException
0x401124 RtlUnwind
0x401128 HeapReAlloc
0x40112c GetCommandLineA
0x401130 GetStartupInfoA
0x40113c HeapFree
0x401140 TerminateProcess
0x401144 GetModuleHandleW
0x401148 TlsGetValue
0x40114c TlsAlloc
0x401150 TlsSetValue
0x401154 TlsFree
0x401158 SetLastError
0x40115c GetCurrentThreadId
0x401160 HeapCreate
0x401164 VirtualFree
0x401168 VirtualAlloc
0x40116c SetHandleCount
0x401170 GetStdHandle
0x401174 GetFileType
0x401178 ExitProcess
0x40117c GetModuleFileNameA
0x40118c WideCharToMultiByte
0x401198 GetTickCount
0x40119c GetACP
0x4011a0 GetOEMCP
0x4011a4 IsValidCodePage
0x4011a8 GetLocaleInfoA
0x4011ac GetStringTypeA
0x4011b0 MultiByteToWideChar
0x4011b4 GetStringTypeW
0x4011b8 GetConsoleCP
0x4011bc GetConsoleMode
0x4011c4 SetStdHandle
0x4011c8 LCMapStringA
0x4011cc LCMapStringW
0x4011d0 WriteConsoleA
0x4011d4 GetConsoleOutputCP
0x4011d8 WriteConsoleW
0x4011dc FlushFileBuffers
0x4011e0 CreateFileA
Library USER32.dll:
0x4011e8 GetAltTabInfoA

Exports

Ordinal Address Name
1 0x46a01d @GetSecondsVice@0
2 0x46a020 @GetViceVersa@12
!This program cannot be run in DOS mode.
`.data
bad allocation
zukucesufofebuherozinigel
hohehalifacomuzigakemazonotacidi wimumofobuponetesu yakafif codizokubuguwe
nagodusoxacohusunasuranogub
vaxohuhigicixaxofopuy
xojemuvogukudizacamoyo
kernel32.dll
LocalAlloc
VirtualProtect
wegocefusoboyok
capejonuluwizibubufunem tipitutuvunewinumajozi
Zoh xacaxawotenoxojucupoz
bad allocation
string too long
invalid string position
Unknown exception
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
GAIsProcessorFeaturePresent
KERNEL32
bad exception
EncodePointer
DecodePointer
FlsFree
FlsSetValue
FlsGetValue
FlsAlloc
(null)
`h````
xpxxxx
CorExitProcess
runtime error
TLOSS error
SING error
DOMAIN error
An application has made an attempt to load the C runtime library incorrectly.
Please contact the application's support team for more information.
- Attempt to use MSIL code from this assembly during native code initialization
This indicates a bug in your application. It is most likely the result of calling an MSIL-compiled (/clr) function from a native constructor or from DllMain.
- not enough space for locale information
- Attempt to initialize the CRT more than once.
This indicates a bug in your application.
- CRT not initialized
- unable to initialize heap
- not enough space for lowio initialization
- not enough space for stdio initialization
- pure virtual function call
- not enough space for _onexit/atexit table
- unable to open console device
- unexpected heap error
- unexpected multithread lock error
- not enough space for thread data
This application has requested the Runtime to terminate it in an unusual way.
Please contact the application's support team for more information.
- not enough space for environment
- not enough space for arguments
- floating point support not loaded
Microsoft Visual C++ Runtime Library
<program name unknown>
Runtime Error!
Program:
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
HH:mm:ss
dddd, MMMM dd, yyyy
MM/dd/yy
December
November
October
September
August
February
January
Saturday
Friday
Thursday
Wednesday
Tuesday
Monday
Sunday
Complete Object Locator'
Class Hierarchy Descriptor'
Base Class Array'
Base Class Descriptor at (
Type Descriptor'
`local static thread guard'
`managed vector copy constructor iterator'
`vector vbase copy constructor iterator'
`vector copy constructor iterator'
`dynamic atexit destructor for '
`dynamic initializer for '
`eh vector vbase copy constructor iterator'
`eh vector copy constructor iterator'
`managed vector destructor iterator'
`managed vector constructor iterator'
`placement delete[] closure'
`placement delete closure'
`omni callsig'
delete[]
new[]
`local vftable constructor closure'
`local vftable'
`udt returning'
`copy constructor closure'
`eh vector vbase constructor iterator'
`eh vector destructor iterator'
`eh vector constructor iterator'
`virtual displacement map'
`vector vbase constructor iterator'
`vector destructor iterator'
`vector constructor iterator'
`scalar deleting destructor'
`default constructor closure'
`vector deleting destructor'
`vbase destructor'
`string'
`local static guard'
`typeof'
`vcall'
`vbtable'
`vftable'
operator
delete
__unaligned
__restrict
__ptr64
__clrcall
__fastcall
__thiscall
__stdcall
__pascal
__cdecl
__based(
`h`hhh
xppwpp
GetProcessWindowStation
GetUserObjectInformationA
GetLastActivePopup
GetActiveWindow
MessageBoxA
USER32.DLL
SunMonTueWedThuFriSat
JanFebMarAprMayJunJulAugSepOctNovDec
_nextafter
_hypot
1#QNAN
1#SNAN
CONOUT$
C:\wokiyemonak\fufociru\honehujehixuv\v.pdb
WARM[y+
B}WXlzB
Mm-P6D
EdiQ3#
?!]yn3
{E!"a*:
f!:,T^
v\aPM0
p]^xc)
LgsQ_C
;`Qe<F|<
$d W`H*\
#?77u6"%z
\-e/bd
J66v-[
wTrz+
%sJi*
(605q;
Y{`!y3yJ
78.Vf
A0Iw+\O
ijF0Kf
m)A?V*
O)r#`<n
8@Vx@\Yb8v
:LT&"'
:9\=F2
*eq9 mJ
5[UMW7@1
d^%N$i
+)9F*z
7KHMD" d;
St5zoM,
),8`&&
\&UbuQ:w
u?RVB[
>ly}UY
vw,E:%
je-1@u`=
{,)zB(
7Vr|*(
n"YC&2
UlTXq;XV9
:e\42Y
uxz?GQum9T
[=}X:`
JRFK3m
gK2.]c
"|1Zkz
iK$wWK
#|8loL
_q!7uI
2YfF8_o
.#UR@{
bR[We,
26ZHJv4!
3omz)nT
ma3i>
q0[R&
e_6~Om
\IR^N,
52LQHi
tLPxI
CI4sK}
X7x};8B.
-edbg
/:EvCf
;&UvZx
S*wd|hZ7;!
q6Tt1t
AlUAd>
gNtlW4
um"y2X
EB/P@%
AWz ,w
oO4v>1(
P/}x0zQu
B{~"j^
-p:3+Z$E
b,3U~w]
7MW5R8]KX
zqj>ai
")GF=8
V?jO4X>b
_O# a3
l~sbA>
2<[d!,
WVtai
EMi[IE
3_2"Ec
5O|=2|
I\;<R:,
5'to>g4NP
JCsA8U
0JVtqk0
[1Mswb
QNb}o?5
@zLqp)
T6zZrp
~ew9#@|
e#C^x7
w2YSK(Be
>q\^rr
h!^^Kk
EC[:2U
$?Z=@K
:u1NL_#M
}}rXXU
49xN21
YwI'=H__
'Xr`kW
:"-=9X
:RWsTQs6
^dV =t
K4byU?
tx'2^9+
++WjXW
JS!3Wl'
]/tv;fM
QKro+(
FN6:+.
&lCYXt
$[M3+t
.=;R3t
6{?gD9QJ3#
O+yC1m
>!kykS
\E!#sd
F4{B@/
q5Pi&_
*BWe>+
pG7Qu:a
s`^y|iS
vR:wqm
iux*T}
.jcHu
#XE6Hc
%~+qBO
z.S=3u>m(EQ
FA\MOp
F.2oe1"km
`^)Hjo1'
+#X?j\
9&)KVe
?x/.^6
J[[}j-
2)KY=X
eAX_Sr
bb L,9
b8aHQ
MB7.MYv
F@,6\y
A3{5)CO
-kL?==2b
+@0:9u
y6h-j$
"}}O3xZ
D$+2S.
p:dL1p
+l7l]-
C0Go:,
Ce@ydv
tBB+6f
yd6;7f
Qe:3{
%$D;?{Eb5
{-AYzZ
w%\0O0
.QR{5D
XLek|e
s^.ZSPI
;A=aJ+
@*P'f\
7s#1GW
drNJ,if
_7EO}Ix
.)}8-j<
wCX4 [
_YMy!
YP l.c
G)L}p3(
oXX}PG
'yyKI8
fSAX?
lqF`+<BE^_
&],\dj
an^7p!
.Bv%Dh
CgZ[}#M
&uwW|K1s
kkzAeB*
!HvAW'Ez
UO%fji
d{Cz`@V
}kV#@E
+*0rb'
_SVtfb
D{%UP!G+
cjfpe
..|N/UO
KxX2!Za
`r}<Sj
ndz;:n
W_3("D
YlbP`(
*~+>o:d
8'DFK>U
Cyijj^
98k4oqPi|
5Q(^XBi~
kZiI#:
!YKM8#
3>'J`l
HF}104c
}W/ta
+y"<`g
P9K?U<
0qGj%,
W^ !{
=$x:OE
PRG;5+UM
`}&$<7
cgkpGcAcI
2- mL_
n3tq|;i"
xHyT+v:Z
.EL$T#6
SHPM57
k#qEnFJ
Fd`!X{;4
M7qy-u
8H>M{4
|1cjR
) *(0D+
NkLm SZT]3M
+[>ECi}`q
3U}>Df
4{!g 6j=
3l2;Yn.
p/w"U$=
*DF(s.
Q[a{*csPl
SSDi$@
sphsQB
kcP.7v
qm(is66
=:=Kxb
q2P\<rU
T T7.Y|
_cN}e)
5B18J%Q
[6Y&UI(
R}^IJb>V
{E'%Zf
OXj,AA5@
G.r,zK
nDRm{#
!NF`h\
tTJzS
.x`|t|t
tj`OD%7
9r!Vqw
fGkCE;n
mt_kXbQ'
v5LnuI
P"#4qrd
U~%^;?
>gt'bv~w+}:
(5x6mI'5
S-`lN{
BXV_BA6
yo+bLF
q8w$7^*
8E5Q.8
THO+m1
>utP^|
U7m6gv
lSp|Q
[xYk,E ~
GUfgJa
l,dX_D
RU,-rO
'B=-Pq
/?G?S]"n
jp8t$5
}"UnKuc
W-a7{D
jVa$]4
eP=TuX
2tvr!l
LwFlO]
8JX/}*,
ZNOj*u
QA<=30NGs
cj57n;/C
Y;cM[A
`K+k-I
z3*Ac&
p!4IXf)
v!6ZW!
@"<k7/
^<S]f2
A$s!OF
EEE}4
-E~'g]*
GlHxja01
):R `~$G$
(ren*G
T\gR(#
Mq&%_Q
'+mV7t
_Go7H@
XF)R6-#
k bPls
]yUO.f"}>
J0pa$S
!AffpQ
EJW!Cc
kAoVj#
h9&\`y
z1b9Vafu
~_lk~l
~;*{3KN
0,kN-D^
"^17pL
.n_uWh5!]
RnTmQ-
7;`4T!UH\
op[;UN\&D3>
>*.oyI'
S[M]m4
r]Pba7
S X)JR
M*7S!G
*G[rAS
x;?ruX
($TEfz
3_04SZ#m
:G$**m
s]c U8
z0f"]7
{=`9vC3R
fcA9ZhK
*b%Uw.
.#`H<l&
e$%,c+o_c
V~iF"A
&5bJ\:_D
nk]xKE5
L$vT#;
sTfU?z"
9\%_T%
yL@K+Z/
Y=E@:\
yUV.H[
F-&Tkw
t^?r7\
:o^S>E
Gvb/A+
E47ua0
Y740}t
rzZDm
SegvT
k6Io-[7Jk
(<o1[y7^,[
_EgcMo2
PyCV;L
my$GQS3
\H<a;q
U=TGsf
@j~Z%1
tI~wY\
-4KZ4>
w!6F2z
S\}$R:
Kf/mwG
ipz"u@
$F:YT$(
AU:\$Z
<X[Hpq?
DizGTZi9}
s!1ZM"
m="|0M
DwC\zy
*6.KFh
r@]bx+
4m,cHe
U$aLJ8r
R,%*YG
LEm[{3<
v|q9=PU
Jph z
l.L6Tk
a]drx8.j*y
H3"jJW4
p8E+j^P
8kVM9*
)t;Ca,
zy]jjB
[Y4>DCC
_0Hf>b
0u)-IG
l9;G)<
QD3#9*
L$o-%vY
_B#?pr)
lK`w`[
X{)e?J
7+H=@t
WYZ_xQ
U 3oJl
td\+*{z
\&ut$VD9
iqy1 i{
-ZIVVl
e1iD:Y
D{3#~3`
vgZ k{h
*v[<]!
6vDYTID
9h/2_j
-'%4z k0
_{`@_R
8wbkA^
6$j@9/aw
y'nT;R
J|n;]#(
0JK8A9k
U<%xC\p
Dh3h1.
K]xtq&{s
^$n>]l
JTLds?
] s`y%
k'I)1xP
-&T6h#!J
",^CoA
CLCpU!
EPoUl@'
U?\VU[F
;N<}v#
&i6;~
2P;P{e
jZLcaG
>amVjc
T$PQ{Q
=lZ3M/p
UV!`N!8
|t3vLHU
\y<VvH
$kB8mS
)v(<7]
'V-G1J1
npiuGS
T~6A5
Gw^VYM
g&otaw
aB[K1o
8}:u#K
_A4npa
z$SZYX
>g*#8r
G_'Q_]
'IYk.s$
jY.(f_
|2UsD;c.#V
.Mte62
w^BN..P+
jam|LWt
c,&@[:
M"2YVC
0vP'EK
#3vTdA
>bnpy%U
P$|y14
Z/W$'I
D0cBSe
k~t+ME
r>v-:r
CyrJB'5
6tO8f$
8[t'&C
-p)_ol
>^Th74
-9C;,9
5% YTw
_z$h>=
HkUhEx
uI7qh
%$P#CT
lzfm3M
3<>x@+
*E%)G6B
E~z[DX
q)B\;K
CKmK`8R
(Ux:&a
`9'z.BuRm
*Rm.Ivc?
3Sn4B+
)cU3Xc+w5
'^lEAZ>
N!._%'
dE%F)#"
<Sm>WG
xFVZJF
N3C DM5
k$Z+J,
@hAKtY
w(@JJ0<
|a"Mjs
.p[Cun
.,gmp.
:C+F}Q.
.]uZBN
:jyaFm
0eFk2'|t
,$[H)D
Q&HFD{
cFw7Da(
|PAt!Q
tgmS//
o3\e{'{>
@;e*y0
%N<(F
7VB.h80
rlkK^V
rb=ppi
yNh2]H
Y^ Icp"
F3EvlT+
Dpq/v_
^9~d8t44!Vk
(RG(O
eaEJvr+
X'GRu/
q(]sF5
wFc0Dl
m$}*?-
&0g@Q=
W+B Dt
m5v44q/
C^.T_/
5vmJ{G
5DaxN.[
cQ,O!QGB
t'zs /w
YFkdqH
)0{i@!!
:zI/O1+
MJH?B
Q\d53qW
k\&{~z{I
_b/4481
<6q;PYS
g[3|g0
PX$+V~
,]dA[7
{-7>ge
ZW<6{P
F{dV!
tl}|aV
kS4ZXox
`^~mu~*
Vjl8(`h
Pcr4z0
l"OgZJ
hY_z,x
g.E}JF
t[Y')]
Uy38Ww
{#bXLo
15>5wbhF
:Npsk$
-NBWkR
nv/6n]T
EFy~}G
sj^?5G
B64u?M7x
=JDs^_
7f590|(d
g0`V&t
/y^vBz8U
@$HhdU_
IECHK(
1wOEHM
#.|['/gN
Z9y[%h|
seNDG)
ut.%rD
V&/}\K
['1q0[A
jl)fi<
{KTcD
!3>6d#.@j
2q D(pEN
H{-<&h
hbY"'o
]zcm;w\
AB&sMS
4RkIY d
O-G\{rZq
-Z\D!
N-@1%w
07Jok+h
G>9@GQ+
={1:)]{
8^_yno5r
AL;6;f
-[6RN1
Qm@dhJa
Pmkhdvx
,Z6B1}
M|L#nY
^^tD} +m
s![r/E
*/dRy\
7)j`e_=Np
*@+"r5
o {8N$
k<~p_A
c]8;t)
}2>p'|
Na0jQZ{
OX?HtO
ln/-/e1:
p5?7L
"vw/F>q:
FxV%v:
Hebf@R~AHHe
gv'mfO
Z)<W]L
jE)Sy<
<[<Qdx#oG
*Bpld\q
{7k:9o
?I#C/4
?lNp79Bw
J 'x+@
g^v3-T
alCDTW6za
}PvVqw
O`(K|
{/B5tH
=C9:EL
"l !1y
[-Xo?p
T<y~p3
C`M(<j
|v:rW-
-O,Hmy
t{x-DV
;);tLs
)]!r|h
!|l#D<
b,ZL(T$9
w,-d`zG
d1%P2!
!(mx#
f8[HG*~
|cX9 /
Osbwi\V
tw6"rr,
%z|Ier
0ehNU{n
cFtNMp#j
$[qdvw
#-!%h'
=k;|zp
JL12$X
aD)2OY\V'a
_(XQi?
yb{Uxu<{
@x41W/
,4q<*d
cjD`l
;&SBK
*_N-(w9
;m=I\z
wG DL_2
Y`F[N^
9dk30?
6!C;h-
YH_JT4
w* +2f
U'T}z$
^]<"'
l7Sf0x/e
I3^uC
{tu4$H
SMm#j~
>r^p=_Yp
ss8Lm?
e!f^2qO
,n*EZd
n*S,0t<%
RQ[ICG
r9Vi^1
;rMHvmZWfz
RK.#mJ
/n(f%`
|(y:<G
{GPw(!
t;_ek
2x?^,`
1}Yb |
,.Qa/T=
.#E'~fB
;K\n{
,R@WW)w
?0-~}2
5Ka*qmE
%6j3Dd
}F}VtR[
oYf GF
KZ=Z"*z
CqE^i\KIo
=pk(3
lV|[X(E
*__Tw@
*s4q*~)
CTV`bM}
\V2/^a
g_wCpdJ
_V@>N&
GN?sMLa
yL((P&
[V=5G|
Cr]QsFf
)#>67f
}\Tbw6
n6]i<P
kIrURv
IRd53:
d,VQT2o
X[e&|3
6H;>A62
{Wz!s8
VVVVVVh
E@bcs%
"ujVVV
^u(VVV
PSSSSS
0WWWWW
0WWWWW
QQSVWd
0SSSSS
_VVVVV
^WWWWW
HtHu4j
s[S;7|G;w
tR99u2
HHtXHHt
>If90t
j@j ^V
>=Yt1j
0A@@Ju
0SSSSS
PPPPPPPP
0SSSSS
PPPPPPPP
URPQQh
tRHtCHt4Ht%HtFHHt
0SSSSS
_VVVVV
;t$,v-
UQPXY]Y[
^SSSSS
j"^SSSSS
t"SS9]
t+WWVPV
<+t(<-t$:
+t HHt
EnterCriticalSection
CreateActCtxW
ReadConsoleInputA
InterlockedPopEntrySList
SetConsoleDisplayMode
CreateConsoleScreenBuffer
VerifyVersionInfoA
CreateFileW
WritePrivateProfileSectionW
GetPrivateProfileSectionW
EnumDateFormatsExA
GetCurrentProcessId
LoadLibraryA
IsDebuggerPresent
SetConsoleCP
FindFirstVolumeA
WriteFile
BuildCommDCBW
VerLanguageNameA
SetFileApisToANSI
WriteProcessMemory
SetEvent
GetExitCodeThread
EndUpdateResourceW
GetCPInfo
GetLastError
UpdateResourceA
SetConsoleTitleW
SetFilePointer
LoadLibraryExA
CopyFileW
GetConsoleAliasesLengthW
ReadConsoleA
ActivateActCtx
AddRefActCtx
HeapLock
DnsHostnameToComputerNameA
ReadConsoleOutputA
GetProcessHeaps
GetSystemWindowsDirectoryA
GetUserDefaultLCID
BuildCommDCBAndTimeoutsW
HeapAlloc
UnmapViewOfFile
GetAtomNameA
HeapSize
GetGeoInfoW
GetCurrentProcess
VirtualProtect
GetProcAddress
GetModuleHandleA
CreateThread
GetVersionExW
GetProcessAffinityMask
WaitForSingleObject
SetConsoleCursorInfo
VerifyVersionInfoW
WriteConsoleOutputCharacterW
GetFileAttributesExA
GetComputerNameW
CommConfigDialogW
GetConsoleAliasA
GetConsoleWindow
GetSystemTimeAsFileTime
GetDiskFreeSpaceA
KERNEL32.dll
GetAltTabInfoA
RealChildWindowFromPoint
USER32.dll
InterlockedIncrement
InterlockedDecrement
InitializeCriticalSection
DeleteCriticalSection
LeaveCriticalSection
RaiseException
RtlUnwind
HeapReAlloc
GetCommandLineA
GetStartupInfoA
UnhandledExceptionFilter
SetUnhandledExceptionFilter
HeapFree
TerminateProcess
GetModuleHandleW
TlsGetValue
TlsAlloc
TlsSetValue
TlsFree
SetLastError
GetCurrentThreadId
HeapCreate
VirtualFree
VirtualAlloc
SetHandleCount
GetStdHandle
GetFileType
ExitProcess
GetModuleFileNameA
FreeEnvironmentStringsA
GetEnvironmentStrings
FreeEnvironmentStringsW
WideCharToMultiByte
GetEnvironmentStringsW
QueryPerformanceCounter
GetTickCount
GetACP
GetOEMCP
IsValidCodePage
GetLocaleInfoA
GetStringTypeA
MultiByteToWideChar
GetStringTypeW
GetConsoleCP
GetConsoleMode
InitializeCriticalSectionAndSpinCount
SetStdHandle
LCMapStringA
LCMapStringW
WriteConsoleA
GetConsoleOutputCP
WriteConsoleW
FlushFileBuffers
CreateFileA
CloseHandle
tiyadez.exe
@GetSecondsVice@0
@GetViceVersa@12
.?AVbad_alloc@std@@
.?AVexception@std@@
.?AVlogic_error@std@@
.?AVlength_error@std@@
.?AVout_of_range@std@@
Copyright (c) 1992-2004 by P.J. Plauger, licensed by Dinkumware, Ltd. ALL RIGHTS RESERVED.
.?AVtype_info@@
.?AVbad_exception@std@@
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
|ycC:6
`ox=4T
0ID~pA5
1LSnH++
LLg5+7}O
!H:f|ip
VQvrA;
$WeuA01
!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!
!!!!!!!!!!!!!!!!!!!!
!!!!!!!!!!!!!!!!!!4
!!!!!!!!!!!!!!!!Q
}!!!!!!!!!!!!!!!y
U!!!!!!!!!!!!!!
)(!!!!!!!!!!!!!!!&
!!!!!!!!!!!!!!!
`!!!!!!!!!!!M
7!!!!!!!!!!
*p!!!!!!!!!!O%C
!!!!!!!!!!!!
x!!!!!!!!!!!!
!!!!!!!!!!!!!
\!!!!!!!!!!!!
!!!!!!!!!!!!O
!!!!!!!!!!!!!!!!!!]
!!!!!!!!!!!!!!!!!!
!!!!!!!!!!!!!!!!!!
!!!!!!!!!!!!!!!!!!
!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!
yyyyyyyyyyyyyyyyyyyyyyyyyyy
yyyyyyyyyyyyw
yyyyyyyyyyyx8
yyyyyyyyyy
yyyyyyyyy
&Z(xGyyyyyy
yyyyyyy
yyyyyyy
yyyyyyyy
zyyyyyyyy
!{yyyyyyyyyyyy
u_yyyyyyyyyyy
yyyyyyyyyyyy
yyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyy
SVaQi@@ @
AA^P`U
Ji3Bh-
U^)sv8
f;Ae&/J
Hr~0 l
+Pa< q
@V{:0~
3\tT!{
Qsz!.DlK
*6c:!t
Am|8!x
E9bxo+Z}t<e
?GVVVs
1EqmTTTm
??T?T?**?
ssEsE?NE
11VTNs
sqqqqqqqqqqqqqqqqqqqqqNs
1Emqqqqqqqqqqqqqqqqq*NEs
11111sssssssEsEsEEsEEs
11s11ssssssssEsEEEEs
DD!!!!!!!
H!!!!>>>>>!>!!DD
66>>>>!!D
dCdCCCC
dddddddddddddd
LLLLLLLLLLLLLLLLL
L666666666666666666L
P77777
nSSSSn
||MME7
''''''
LLLLLLLLLLLLLLLLLL
,,,,,,,,,&
BBBBBBBBBB
BBBBBBBBBB
'''''''''
'ooooooooo'
1111111o'
11o'
'o1111111o'
'ooooooooo'
'''''''''
zu|czz|
wsrsqvs
{~|v|~y
zsz`zxt
3F5#Zd\{~~
dddddd
dddddddddddddde
ddddddddde
dddddddde
ddddddde
dddddde
dddddde
ddddde
wwwwwwwwwww2
_!!11VVV
EETTm?
_!!!11VVs
!!11VVV
!!!11VVV
!!!111VsV
___vvvvvv
IIIIIIIIIIIIIIIIIIIIIIIIII
ffffffffffffff
f9f999999999
f9f9f9f9999999
ff9f9999999999999
ff9f9f9f999999
fff9f9f99f99999999
ff9ff9f
f99999999
ffff9f9/L
999999
ffffff
fff9f9f|
g99999
fffffff
299999
ffffff
g99999f9I
ffffft
29999ffI
g9999fI
fffff}
299ffI
XXXXXXXXXXXX
111111111w-O
11111111111
3?\R$O
Xuhey sezezag husegux hihorujo fetoxupaxanizi. Tokopipifuk gibojobupubiga xibimenuwuc. Tumize yet. Hiyazipi mibuwiv bibetepepatezey gafif. Feguwen cib yazabixuhezufo vapeyuju dilotitifinipe. Malanixe daroke defivokibewago tuyimumocuf depotifewaruk. Sidanejal. Ruzasu. Selaroco batazeyunudo. Koc cizujivuvew fidavijisav. Nabuzume dohoxo woginohiyom. Howelofe nilixovuboxat hakiwuziw jim tavibayic. Wuh. Yaya zalozaxudapibon gegeta. Joxelezasivujit huhekolotecic. Pekisaxodikozu penusukigas witexewenebonow. Yizorela cetejiti sojas vuwujukakovec betu. Lunalurowocor befehogoyoxuy xisejopifoxudiv. Joni. Mum. Hawakabeloyawob vecofokujevuh fewahul gayepireno ziwijifagucez. Cucalutakoverih jinu nesowaxusub zuforenoba tanixa. Suvuko xaf disehoje cesizetadalaba reneguhexu. Dativol wivim. Waratojofetuxi kunowov zufofeda cecogami boduwife. Pafif rixu. Lavesacoticay suxoji pagiceremekawar. Kevu nolelofaci nuwukirec gokoxif. Tes wego. Liju gediceh wizurorumu. Yeko rijitozewowu pur. Fakasufizaju maxumoco hiwuviy wogepilehi sejow
gavesuhemapusidil
hilufihojibos
zicurecakuyihujegaduzasotaboh
guyubekavaluwayohafosomenegonum
mefokidusalaxewegecasu
hitijepisixiduzetuj
xutigowuroya nuhoxigelecalu cedunokufoxizi
KERNEL32.DLL
(null)
mscoree.dll
((((( H
h(((( H
H
YASUTAXACOJIFIWIGIJUPEGU
VS_VERSION_INFO
StringFileInform
081564b6
InternalName
kogzmuafoke.exu
Copyright
Copyrighz (C) 2020, vodkaguds
ProductVersion
97.78.38.10
VarFileInfo
Translation
4Xucalomelucobog kiholicodepu soxegov nuvefafonon jutJRisukosubirakow fipud huday bumos sokabatobanite mujeka vudafocital guvevijDesidacadacocen nagesixehunu haxa guzuhodo fapacu nimugipurat howihoyedidobo hapikujipotoya rocux sicigahe
Hojufih wuz coyur codo gene*Yoz jeyimaboxax tokaluk mosovu madeterorux[Fif ginariti xekizuko hefuk sowaruhi fiduzanoco yihe johukezujolew sayinumihayiy nogakoseye
Joc7Deguvugekelem wovi sipotaraze runaguted vejulaserefiyam
Antivirus Signature
Bkav W32.AIDetect.malware2
Lionic Clean
Elastic malicious (high confidence)
MicroWorld-eScan Clean
FireEye Generic.mg.0fe287305bd628a1
CAT-QuickHeal Clean
Qihoo-360 Win32/Trojan.Generic.HwoCAp8C
McAfee Trojan-FTUB!0FE287305BD6
Cylance Unsafe
VIPRE Clean
K7AntiVirus Trojan ( 00576f791 )
BitDefender Clean
K7GW Trojan ( 00576f791 )
Cybereason Clean
Arcabit Clean
BitDefenderTheta Clean
Cyren Clean
Symantec ML.Attribute.HighConfidence
ESET-NOD32 Clean
Baidu Clean
APEX Malicious
Paloalto Clean
ClamAV Clean
Kaspersky UDS:DangerousObject.Multi.Generic
Alibaba Clean
NANO-Antivirus Clean
ViRobot Clean
Tencent Clean
Ad-Aware Clean
TACHYON Clean
Emsisoft Clean
Comodo Clean
F-Secure Clean
DrWeb Clean
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition BehavesLike.Win32.Generic.jc
CMC Clean
Sophos ML/PE-A
Ikarus Trojan-Spy.MSIL.Agent
Jiangmin Clean
Webroot W32.Trojan.Gen
Avira Clean
Antiy-AVL Clean
Kingsoft Clean
Gridinsoft Trojan.Win32.Packed.vl!heur
Microsoft Trojan:Win32/Hynamer.A!ml
SUPERAntiSpyware Clean
ZoneAlarm UDS:DangerousObject.Multi.Generic
GData Clean
Cynet Malicious (score: 100)
AhnLab-V3 Clean
Acronis Clean
VBA32 BScope.Trojan.Caynamer
ALYac Clean
MAX Clean
Malwarebytes MachineLearning/Anomalous.95%
Panda Trj/Genetic.gen
Zoner Clean
TrendMicro-HouseCall Clean
Rising Trojan.Kryptik!1.D82C (CLASSIC)
Yandex Clean
SentinelOne Static AI - Malicious PE
eGambit Clean
Fortinet W32/GenKryptik.ERHN!tr
AVG FileRepMetagen [Malware]
Avast FileRepMetagen [Malware]
CrowdStrike win/malicious_confidence_100% (D)
MaxSecure Trojan.Malware.300983.susgen
No IRMA results available.