Static | ZeroBOX

PE Compile Time

2020-11-09 14:43:36

PDB Path

C:\cufelu\de.pdb

PE Imphash

c27ba2db4defa26c8fc20960b3e14f80

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x00071d01 0x00071e00 7.97144163136
.rdata 0x00073000 0x000046de 0x00004800 4.42479542084
.data 0x00078000 0x02838a80 0x00004000 0.810008958327
.rsrc 0x028b1000 0x00010350 0x00010400 6.15053212842

Resources

Name Offset Size Language Sub-language File type
RT_CURSOR 0x028c0e48 0x000000b0 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_CURSOR 0x028c0e48 0x000000b0 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x028c07d8 0x00000468 LANG_SERBIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x028c07d8 0x00000468 LANG_SERBIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x028c07d8 0x00000468 LANG_SERBIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x028c07d8 0x00000468 LANG_SERBIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x028c07d8 0x00000468 LANG_SERBIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x028c07d8 0x00000468 LANG_SERBIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x028c07d8 0x00000468 LANG_SERBIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x028c07d8 0x00000468 LANG_SERBIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x028c07d8 0x00000468 LANG_SERBIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x028c07d8 0x00000468 LANG_SERBIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x028c07d8 0x00000468 LANG_SERBIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x028c07d8 0x00000468 LANG_SERBIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x028c07d8 0x00000468 LANG_SERBIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x028c07d8 0x00000468 LANG_SERBIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x028c07d8 0x00000468 LANG_SERBIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x028c07d8 0x00000468 LANG_SERBIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x028c07d8 0x00000468 LANG_SERBIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x028c07d8 0x00000468 LANG_SERBIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_STRING 0x028c1200 0x0000014a LANG_SERBIAN SUBLANG_DEFAULT data
RT_STRING 0x028c1200 0x0000014a LANG_SERBIAN SUBLANG_DEFAULT data
RT_ACCELERATOR 0x028c0cf0 0x00000028 LANG_SERBIAN SUBLANG_DEFAULT data
RT_ACCELERATOR 0x028c0cf0 0x00000028 LANG_SERBIAN SUBLANG_DEFAULT data
RT_GROUP_CURSOR 0x028c0ef8 0x00000022 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_GROUP_ICON 0x028b6da0 0x0000005a LANG_SERBIAN SUBLANG_DEFAULT data
RT_GROUP_ICON 0x028b6da0 0x0000005a LANG_SERBIAN SUBLANG_DEFAULT data
RT_GROUP_ICON 0x028b6da0 0x0000005a LANG_SERBIAN SUBLANG_DEFAULT data
RT_VERSION 0x028c0f20 0x000001b4 LANG_NEUTRAL SUBLANG_NEUTRAL data

Imports

Library KERNEL32.dll:
0x473004 GlobalDeleteAtom
0x473008 WriteConsoleInputW
0x47300c lstrlenA
0x473014 EnumDateFormatsExW
0x473020 UpdateResourceA
0x473024 EndUpdateResourceW
0x473028 GetCurrentProcess
0x47302c GetUserDefaultLCID
0x473034 GetComputerNameW
0x473038 SetEvent
0x473040 ReadConsoleW
0x473044 SetFileTime
0x473048 WriteFile
0x47304c CreateActCtxW
0x473054 ActivateActCtx
0x473058 GetConsoleCP
0x47305c GlobalFindAtomA
0x473060 LoadLibraryW
0x473064 TerminateThread
0x473068 ReadConsoleInputA
0x47306c CopyFileW
0x473074 ReadConsoleOutputW
0x473078 GetVersionExW
0x473084 GetConsoleAliasW
0x473088 VerifyVersionInfoA
0x47308c CreateFileW
0x473090 CreateActCtxA
0x473094 SetConsoleTitleA
0x473098 GetConsoleOutputCP
0x47309c InterlockedExchange
0x4730a0 GetLongPathNameW
0x4730a4 SetLastError
0x4730a8 GetProcAddress
0x4730b4 LoadLibraryA
0x4730b8 WriteConsoleA
0x4730bc DeleteTimerQueue
0x4730c0 CreateTapePartition
0x4730c4 GetProfileStringA
0x4730cc GetModuleHandleA
0x4730d0 BuildCommDCBA
0x4730d4 VirtualProtect
0x4730dc GetCPInfoExA
0x4730e0 FindFirstVolumeA
0x4730e8 GetSystemTime
0x4730ec AreFileApisANSI
0x4730f0 CreateThread
0x4730f4 CreateFileA
0x473100 GetLastError
0x473104 HeapReAlloc
0x473108 HeapAlloc
0x47310c GetCommandLineA
0x473110 GetStartupInfoA
0x473114 RaiseException
0x473118 RtlUnwind
0x47311c GetModuleHandleW
0x473120 Sleep
0x473124 ExitProcess
0x473128 GetStdHandle
0x47312c GetModuleFileNameA
0x473130 TerminateProcess
0x473134 IsDebuggerPresent
0x473138 HeapFree
0x473144 HeapCreate
0x473148 VirtualFree
0x47314c VirtualAlloc
0x47315c WideCharToMultiByte
0x473164 SetHandleCount
0x473168 GetFileType
0x47316c TlsGetValue
0x473170 TlsAlloc
0x473174 TlsSetValue
0x473178 TlsFree
0x473180 GetCurrentThreadId
0x47318c GetTickCount
0x473190 GetCurrentProcessId
0x47319c GetCPInfo
0x4731a0 GetACP
0x4731a4 GetOEMCP
0x4731a8 IsValidCodePage
0x4731ac HeapSize
0x4731b0 GetLocaleInfoA
0x4731b4 GetConsoleMode
0x4731b8 FlushFileBuffers
0x4731bc LCMapStringA
0x4731c0 MultiByteToWideChar
0x4731c4 LCMapStringW
0x4731c8 GetStringTypeA
0x4731cc GetStringTypeW
0x4731d0 SetFilePointer
0x4731d4 CloseHandle
0x4731d8 WriteConsoleW
0x4731dc SetStdHandle
Library USER32.dll:
0x4731e4 GetAltTabInfoA

!This program cannot be run in DOS mode.
`.rdata
@.data
VVVVVVh
SVWhLPG
PVVVVV
0WWWWW
0WWWWW
jXhPeG
QQSVWd
0SSSSS
HHtXHHt
>If90t
t hT:G
>=Yt1j
jThxfG
j@j ^V
F\=p9G
HtHu4j
s[S;7|G;w
YYhd:G
tR99u2
0SSSSS
0SSSSS
0A@@Ju
^SSSSS
j"^SSSSS
URPQQh(
;t$,v-
UQPXY]Y[
t"SS9]
PPPPPPPP
PPPPPPPP
t+WWVPV
c:S'|q
BFNWsw
K=/^ /d
A7;NM@
,V'spl%
5TmLJaY
E,.3Rm
seP=3)
OOcf2n
wj.N9@
d#?_jb
-c#:t
BsznBo
DafERQ
C"hy%a
.^h7(>
Tg~bv6
~Nu9d.K
yG3t=[
;}kM7K
9:>8QU
lW(S"z
"=E?ppz
)Jm:P#
cDtP!P
T:XgZ_9T
V&>VxP
37[e|P$`eR
s~8Gq5~};
m3v|sG
EDZH;2
<( H
<O_BRED>J
)Qzkul
>B`+0W{
_}Nc!
{3pQPU
9#pHs$/
xWn'J1e
J<N][j
Jn\EA:
L@++ YF
?TKGQk
!hbod (_
Cqo|%S
[[K6AS
Gi9tv
)ZZG'u:
uu/(_ti
ob(_s*5
'O2H{v
FX+>f
ET}[>q
1pN08U<
2qSh?w
pN<j*c
(u_DE
/zYhr14@F
Ng}P[Ay
^NpF`g
L+&cFAd
y#q^=7
#6P0/3
?Ns9RF1
Z,H?_A
pTl\zs
z^#8/S
,#<{f{
YmIgIPJfEIb)
Ry|2e
uEU9LPg
\A_i.%
l24*%hO
H&oQR"v
XDS#Z}
&t&&r>
6f!j6( c
Muf7h/[bN
Me3&.f
3^.2_T
>rN,N
8)suYu
QNJUE}E5
rE1$z|
AGziTE
p(a/I@a
LPqo?
%n:bvJ
"[Oapc
jDgr# -
-RGxq,
._nO9
;]<J!|
G8yX`C
9e0uvL
Ok@5i5rb(
3<p$/6
~|gBw!&
[%3vUkv
wPN\i7
Ly{nR^qD
%ix_E3
sqqVy-}l;F
C9u>m'
/90YED0{u
xi]6VSY
}6a;,c
*Z2=XM
o^~[Jb
P};&&"i
k\J(0X.U1
jjP2d%b
,ZD4;6(
ZR[MyzS
{MNXj12
*4L=Ct
,:xC#>z
dW]0O
[M]]e<
z"1Ev2<
-N4&h?D?
54OI'N
m2YEHZ
MHDCGj=
4p>bN=
7reqE{
PGF.E$+
}Ays/X
}o%e?a
jgbHH9\
?zBWwPE
RV=ul
&# 5mE
jD+8[:
Y[wV0,
VcG4Nf
XCaz%s
^WK:-&<
=fDaf'[
x!>Sr&
5,gr,A
Q_s=?n
N/YY.-
bCCpe?-
8t:57u
U6Rdn~`TCNm
e.6v@~U
4s>jP'
2*}_sW
#%8F=A
`66EYj
k2?7gs,
{a_EQpi+
'AOi0q
HtF+9Y3H
3DAmCZ
>xMwl4a
WnlIUF
CK|{0
hfftd84
u"!"eV
m2ASJ`
dYl.OuQ
=DQ=gA
Gh,KL%`
udK7l[
6VW>K1
tBB+&x
86c)A{
t4t.A7
c8X\34~
O}L.,:+
zx Fo^
f\~f#AF
yWE7E%ZTQ
rZ_}$e
&m1hP/
HOS|q_hw
?lE?z4
s2]VMn_
\cw2.x
5RA:a
CJy;B~
SVS0J
dQ3#'k
Ts@A7'
{q,:!'9o
'0JFMnD
S{[F};
*Ki_^b
RI=O`}
]o$:&D
*EH>Zjk
g4e?qJ
&TC5o^+
c]1!wjd
Vo8`K k
)O.j.3
R&gON3
\96_ILh~>
!r%<R
vYH8+D!
iJ[yqU
%g&+u!
+D#8-B
5L>)T2
>1`@c7.
gM]j^'
+~*D1!
e-A*R!
3Kn#FDl
]t"(=:
9u@O>Sb@
G6v[UR
jyYSp!
}#*x\p
&?4(tF
K:|ruM
cPtT$`
j@A-B4
4X1VQ-R.r
vk15l(
~7P&B
S2GAw}
3q!)v/d
p.+c7QR
-29!Q|
G)E^.;
:TNX!R
{Gt` 5
'*@$&>
X_z==`
+AJ9;,G
n4*UwhI
XG(uy_
Njsxf'!LV
k,iD`f
Xez=6*f
Q'6`i:
9;V8(X
gD@"Ug
kf&zT
+Z<u|K
p'){N1
FHRp8)o
MSQ#p-q
DZ,f/oR
@WBDFM
\2yTLZ
-8nT4^
"@xY.%
[4T$V.
4`gX2[9
<S(w8e7
MEdt,~=
khFy8Y
h=D>;;%
,WLLyH
%864tX
u:~=89
els(U;
u2_K7E
G~-;N]2C
UOoH]6
k.o*`k
;,)Sw
c4'pRG,%s
3Jqeb?
HuqdP}
''q{@b
cYCUdHsR
vzgs@Z
9t/J'},lc
`*lFw0?b
69F 9d
xV_<i}z
eYxElu
GpRt!^"_\
2_L6Gx
lD}.p!
}->Qk9
9l>A"7:
.435W9
a,^I~n
f>-MM
Uig,*f
Q`U(A\-7
}b{+"K
#ApPNYDii
o/~=#7
1fT]WW
uVORHD
zz9:fx
*7bUe
'V,Uq%
}mgYQF
QlTS6c
^2}8T7
Tr6L<}
Z_RtH[
_{S38r
#./1z)
(ej;XV.A9
2ngA"Of
rZe{#
r@:g V
mo|/"i
S N3]_
^L~<?D
\u5>G!B
}.3ho<
gy~V[g
z%3^9&9%o
B3 Q7T
_|3}{A
m>{V'!
'(i\!2T
\[T:EK
~"7,C]
,[&xH
ik`zQ%
jq_qp6G
5aajY+
a.CMOn
M,H:O/'
=xyeO,
/aN|u-
_X(5^Y`
}Ngh$"
8T`Im'
y]^fXX!@
:%*R6x
p+&z2j
T}L/!W<m
6W2k@c?
sr}2nd-y(
E7b{b:
1M{||8
'[}thX
o7oYD8
`3KU/^
kN(9*
M/z)$9
j!rR<TU
GdG#?\0
KzQ~9&
XCbtiv
"O(gL_
sd&+8\1X
ZKIlBc
10| l0
C]F${#r
Acm{IM
sOJtRV\
%y3FP,z
_I-A|/M
S\:zB]
5hkM]wH
"h75q'Gh
76Q7^>
zhoI!0
T9(e##
z4#AY
o(>Az+
z=K-7p
3Jf%Kff
ZcD [P
E=HyJ?{s
TQMFu-
y<lQ\F
(wj_MKt
&Krz}n
_8+n[
6y-sQ@
WWE9[Xm
370%S<_N(
Pfq:@/yv
EB>D7/`v
<oSBeZK'
S[_jNb
Wn/!#1
Hhzl~r
|}3i6&
mZY}`!
0]KPIe
51Bs i
ru?x_.g
0:R&sn>
!WI&l?F
/@Ae}8/!]'
0tk97L
].w"a8
Jk;vJxZ
t"D?sJ
k]r):u
ZI|C7
-[mF&x
Uwnb=0
aOl+dni
g/VNf6
%a4\I2zB
3cEdXG
c*.d-
TWdnH3
w.4/-/
?%xXp$U
RR^eMtTZ
Wqg,yi
%Pg*g\x
::fB@0
0WM@f{0K
:e^j+L
x{g5&|#
"I5[Kx
l1TKV2
/Dr4*C
%y-Rtb|
%gDD3.
cAE|Od
+w7!O6J
.}mHFS
^i%+qr
U*S9$<
v9i7~H
a'T|Q]
DM"e<6
Vwm'C[U
e$R.k+
MV2QKu
<D~5(d
1lx `;
\BNR'l
-ea|*>
Q:_@ao
I5g^P
~O*z5v
](o[9t
].P?.vXWEm
|,m)hd
]&-{)"
Krbz:`Z
[w,;7^
dbUtH9U%
0S=DUh
P)zw+6
l4?1O}
"P$]M]
p1o0pje
b"i7{g
k!(f4#'
GWeJ#wT
]),Kxs
nv?$H,
fzpZQ3
np ~\w
W3&yz
YSoxU.
"@sp?P
nP6t&#
5G%e 6
^T)VCT
:0,6=QT
Xd:`C*
dI=Q=,
^7]v)
"7MHx8
tR].X8+
c6>?}/
;qq`hz
w!p ?R
sXfo=}yuZ2
sdMkAQ
$[^t'o
!{amTx
-<|;Q>
:_Z<.
9M>^Jd
A048r9
`j9sxr5
E2S[:[
xb4Eb!
&sm:jfV
oA&UeN
MEF>*nY
TY"M9o
!K#KJV
Br?dWd
j0(8sM
*j):k*
m5._sw
#367HK
_'}O1dpP
d'3Z~Kj
xA,|2+
5({lKB
xQFaDa
AQ,#P=n
O~l696
1rj$wM<
Hs3?pv
A3Y@8.
`oX<I|
;Q'Xm|
D^\px0t
r&GybV
IrZ=]e
#@^q~o
V?icl\
\"]Kh
=OROd9
Pb/fA-
AZc3qI
LT2C*FX
@s9LEp
~0OtN(R/
L$-17J
TyJ.VcL}
c^oGX/
qb-(/e
S6{9_.
qB7A Z!
F{2Wu0vX
7<a:1f
1Vl*>'
N1<Gfp
.Wv)_vON
A0&mD.
\^=Q"AL
wA8?).
0^&L`#r
~P"MTnJ
U\ NcZ'
Ugy`(^+
BVvKAv
x6U_ (
~*&fog
%nY&!Z
Nc<|\3
vq#I-lc9
L54bc{!
(=&6^z
+c4N0K
0]5><i
XjH"-[
0Dkvsn
zpSN1K:
rJ!NwV
jA/n8_Hj
pBM<yzF8
&x3%qr
A0`y o
pel{|'
CAC)_`
eEQ$[
:_c>G`
^J-R$.IP
[NQVp.{
c+!\u(
ogqC,Wb
Slr|Kb
d!X?BW
iUbG(f$
s5bi7J>
dgChNn
9WSY(FG
zp>|.W
2{H*r
E!g!!5
A8;_$X
r"jsz8
`KGd(vl
wU-[lg
~i]kpD
'Ed@YS
F*w>:0
uBW6!)E
~gC-<I
$K'f!)
<.7,*P
.Ujw)u8*
7]qY?l
Kd<^"<
63SL'l
'kO,(A
]j<-:\0
.'ByHa
_Xbk|v
IED)FzT
eY-=Sa
Yk`+\`
,wDz#a
zh9c@]
m'>39-
,atqM7
&SfTy|
TV&0K
5'(W,C
_{3X~_1
yO$!Z\S"
5$]z&{Z
*X(_xXb
j\e<+n
e,p6'W
g)naJU
{/W4:Z
pD$o4}j
Fb0iHC
/mZl.D
U81i4"
N8N{nNZ
VrYJ=7
]j:Rf9
f"yC4zaH
3X`@2#3V/MD
#oiqBm
fj!\M;}pI0
{ZTADU
z6jw9/7
-ZO`,&
5h%gfz
e+w[ 8IP#a
G:4Kt|
YaGhoNcwMDjn?
/1mbcy
;C#B)y2
HH9GOE
qq?YNZj
2I`Q9'|
a_h1J1
nu 5OU
}c\8u]
]UPevS
</28"?
J4vPm#
w'k-HD
wa!X"i4
mOY>~S
`Immn7
KZ0dE
PR\X=f
C&!D=&
B w\ l
$,/tm+M
0nu}EL7
8gV'9sF
;Ac-aQ
jr^/@s
DFx~|~
[@+gq{%
RVJ1ws,
:U<;.e[c
s&BFez<
1 o(M6
a\Olco
,Srh'JV
)#%[17
"!~Q[i
){TB,*
hn{P&\A]'C
b`AZ|>
/|CE]j
lEVMN|
eMkIy8
y&N7x%
_Mo^HD
{%Q!!eY
[xAPi%
+Nt@Rdr
*9LTvn
<y<-@G
$YAKp
[L,r@b
}KO![%
^?P" l
ch3v i3J.
]KVqnLd_&
$u\',
r<;fBr
4ubRC@:t{v
n5Q^fF
[GTW;'
V}<.9Y
14tC:HI#
Jsyn6}
:RMSjJh;
n\rNvG
Mz!@"h
{w1C!~
aXkmN
$L\qAE
)j1O=m@
b[a2x<m
jW-0i \
kT?)2rg
Pdq>Rw
8$8|:a=
KRy/Lf
BJ6ZA$
[?~cnoU
+&Y0$
'<'vId
k8n/rC-
k>EWWP
%>07G%
DW4Lsi
FM>fW!
U|LQ]\
D;|zcn
QoCaur
E*=BoC
zF#aJH
}&-"Ir1h<e$
+f-A}(
,E]C;
s5rN{<
`5PcWuO:m
NMHY|`
ImB^;GU
waL{6p
CFK*2#
(BkPn$
y>+#<|eB
Xu{_y1
?hP@on
FM>7bC
4Z}Xc%R
k{\-\1\B
$\fp$l
E*jzN0
RC:P u
PZW\n$
]3)C*~
VrV1>v8
l"eo0e1
IHqX@w
4+QtV4
I*\H0k
MOE,Eb
Ve^jC_
tc^1yQ
+Gs*{e
n$qV/zL)l
B68@%ULG
{ZM#}`
r#*+zz
Y,a)4l
bad allocation
string too long
invalid string position
Unknown exception
CorExitProcess
runtime error
TLOSS error
SING error
DOMAIN error
An application has made an attempt to load the C runtime library incorrectly.
Please contact the application's support team for more information.
- Attempt to use MSIL code from this assembly during native code initialization
This indicates a bug in your application. It is most likely the result of calling an MSIL-compiled (/clr) function from a native constructor or from DllMain.
- not enough space for locale information
- Attempt to initialize the CRT more than once.
This indicates a bug in your application.
- CRT not initialized
- unable to initialize heap
- not enough space for lowio initialization
- not enough space for stdio initialization
- pure virtual function call
- not enough space for _onexit/atexit table
- unable to open console device
- unexpected heap error
- unexpected multithread lock error
- not enough space for thread data
This application has requested the Runtime to terminate it in an unusual way.
Please contact the application's support team for more information.
- not enough space for environment
- not enough space for arguments
- floating point support not loaded
Microsoft Visual C++ Runtime Library
<program name unknown>
Runtime Error!
Program:
(null)
`h````
xpxxxx
EncodePointer
DecodePointer
FlsFree
FlsSetValue
FlsGetValue
FlsAlloc
bad exception
GetProcessWindowStation
GetUserObjectInformationA
GetLastActivePopup
GetActiveWindow
MessageBoxA
USER32.DLL
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
`h`hhh
xppwpp
Complete Object Locator'
Class Hierarchy Descriptor'
Base Class Array'
Base Class Descriptor at (
Type Descriptor'
`local static thread guard'
`managed vector copy constructor iterator'
`vector vbase copy constructor iterator'
`vector copy constructor iterator'
`dynamic atexit destructor for '
`dynamic initializer for '
`eh vector vbase copy constructor iterator'
`eh vector copy constructor iterator'
`managed vector destructor iterator'
`managed vector constructor iterator'
`placement delete[] closure'
`placement delete closure'
`omni callsig'
delete[]
new[]
`local vftable constructor closure'
`local vftable'
`udt returning'
`copy constructor closure'
`eh vector vbase constructor iterator'
`eh vector destructor iterator'
`eh vector constructor iterator'
`virtual displacement map'
`vector vbase constructor iterator'
`vector destructor iterator'
`vector constructor iterator'
`scalar deleting destructor'
`default constructor closure'
`vector deleting destructor'
`vbase destructor'
`string'
`local static guard'
`typeof'
`vcall'
`vbtable'
`vftable'
operator
delete
__unaligned
__restrict
__ptr64
__clrcall
__fastcall
__thiscall
__stdcall
__pascal
__cdecl
__based(
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
HH:mm:ss
dddd, MMMM dd, yyyy
MM/dd/yy
December
November
October
September
August
February
January
Saturday
Friday
Thursday
Wednesday
Tuesday
Monday
Sunday
SunMonTueWedThuFriSat
JanFebMarAprMayJunJulAugSepOctNovDec
CONOUT$
bad allocation
wijiwifalipimetibuligijabudidozo fed rolujalajuliv fomij docoxewicudavobinidegamu
hizejikekacuwawidobikopaganinetayizufuluyijoyegixoyobohamepoxedujohuyokuyusu
Tipit gedo fizayed mizetawovadu yewaxacolitena
Bikoruma fej mebebohudor vem rawuso
Belifocavo buvapetaxan xafuki yov rivifasid
hapawikitozibozipusi dagetegopuwikafox
Yokanohufupo kuluhonin lugudabicevu liyonirit
Sipiwaxe
kernel32.dll
LocalAlloc
Loridaruy lafaj biveyiwa pupeyobo xarefez
%s %f %c
xewusejixadehayemugaceyanexirohoyayihiperahutusojekavuvo
C:\cufelu\de.pdb
SetProcessAffinityMask
GlobalDeleteAtom
WriteConsoleInputW
lstrlenA
GetConsoleAliasesLengthW
EnumDateFormatsExW
WriteConsoleOutputCharacterA
BuildCommDCBAndTimeoutsA
UpdateResourceA
EndUpdateResourceW
GetCurrentProcess
GetUserDefaultLCID
SetConsoleScreenBufferSize
GetComputerNameW
SetEvent
GetSystemDefaultLCID
ReadConsoleW
SetFileTime
WriteFile
CreateActCtxW
InitializeCriticalSection
ActivateActCtx
GetConsoleCP
GlobalFindAtomA
LoadLibraryW
TerminateThread
ReadConsoleInputA
CopyFileW
GetSystemWindowsDirectoryA
ReadConsoleOutputW
GetVersionExW
InterlockedPopEntrySList
DnsHostnameToComputerNameW
GetConsoleAliasW
VerifyVersionInfoA
CreateFileW
CreateActCtxA
SetConsoleTitleA
GetConsoleOutputCP
InterlockedExchange
GetLongPathNameW
SetLastError
GetProcAddress
GetConsoleDisplayMode
EnterCriticalSection
LoadLibraryA
WriteConsoleA
DeleteTimerQueue
CreateTapePartition
GetProfileStringA
WaitForMultipleObjects
GetModuleHandleA
BuildCommDCBA
VirtualProtect
GetFileAttributesExW
GetCPInfoExA
FindFirstVolumeA
GetPrivateProfileSectionW
GetSystemTime
AreFileApisANSI
CreateThread
KERNEL32.dll
GetAltTabInfoA
RealChildWindowFromPoint
USER32.dll
UnhandledExceptionFilter
SetUnhandledExceptionFilter
GetLastError
HeapReAlloc
HeapAlloc
GetCommandLineA
GetStartupInfoA
RaiseException
RtlUnwind
GetModuleHandleW
ExitProcess
GetStdHandle
GetModuleFileNameA
TerminateProcess
IsDebuggerPresent
HeapFree
LeaveCriticalSection
DeleteCriticalSection
HeapCreate
VirtualFree
VirtualAlloc
FreeEnvironmentStringsA
GetEnvironmentStrings
FreeEnvironmentStringsW
WideCharToMultiByte
GetEnvironmentStringsW
SetHandleCount
GetFileType
TlsGetValue
TlsAlloc
TlsSetValue
TlsFree
InterlockedIncrement
GetCurrentThreadId
InterlockedDecrement
QueryPerformanceCounter
GetTickCount
GetCurrentProcessId
GetSystemTimeAsFileTime
InitializeCriticalSectionAndSpinCount
GetCPInfo
GetACP
GetOEMCP
IsValidCodePage
HeapSize
GetLocaleInfoA
GetConsoleMode
FlushFileBuffers
LCMapStringA
MultiByteToWideChar
LCMapStringW
GetStringTypeA
GetStringTypeW
SetFilePointer
CloseHandle
WriteConsoleW
SetStdHandle
CreateFileA
.?AVlogic_error@std@@
.?AVlength_error@std@@
.?AVout_of_range@std@@
.?AVtype_info@@
.?AVbad_exception@std@@
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
.?AVexception@std@@
.?AVbad_alloc@std@@
IJA<<=
xqrX:#
=^Xu[J
vnhHI8ACP]Z\shv]8!
xhmF?OQlgwppkmuZ
ukrD@Zmihn_iemyM
kimY[nlmhlmzqwW*
vZjjvumr|
}_bUK#
`gtmhmn~`
wgthgn]S7,&'
xgvlgP7
pB$A>egjlh2
,]m=9nk
%xruU~
yz{vdVD@.
&\ftwPK
8<za",
01|r#1
3NL}wC;
5PWpI/-
IMk7-=
RZyvA<
rrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrr
rrrrrrrrrrrrrrrrrrrr
rrrrrrrrrrrrrrrrrr
rrrrrrrrrrrrrrrrd&kzP
rrrrrrrrrrrrrrr
^rrrrrrrrrrrrrr
rrrrrrrrrrrrrrr
rrrrrrrrrrrrrrr
|rrrrrrrrrrr
rrrrrrrrrru
rrrrrrrrrr
rrrrrrrrrrrrn
Orrrrrrrrrrrr
K4rrrrrrrrrrrrr
rrrrrrrrrrrr
rrrrrrrrrrrr
grrrrru
frrrrrrrrrrrrrrrrrr
Wrrrrrrrrrrrrrrrrrry{H\
rrrrrrrrrrrrrrrrrr
0rrrrrrrrrrrrrrrrrr
rrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrr
}}}}}}}}}}}}}}}}}}}}}}}}}}}
}}}}}}}}}}}}
}}}}}}}}}}}
n}}}}}}}}}}
}}}}}}}}}
)}}}}}}
/}}}}}}}
`~P!<}}}}}}}
K}}}}}}}}
}}}}}}}}
}}}}}}}}}}}}
}}}}}}}}}}}
&dq}}}}}}}}}}}}
}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}
~Vc&}_p'
_|,}hxI
{n~zo{
[[[[jeeeeeeeeeeeeeeeeeeeeeeej[[[[[[[[[[[[[[[[[[[[[
[[[[[[[[[[[[[[[[[[[e
e[[[[[[[[[[[[[[[[[[j
j[[[[[[[[[[[[[[[[[e
e[[[[[[[[[[[[[[[[[e
e[[[[[[[[[[[[[[[[[e
e[[[[[[[[[[[[[[[[[e
e[[[[[[[[[[[[[[[[[e
99yRRj?
e[[[[[[[[[[[[[[[[[e
e[[[[[[[[[[[[[[[[[e
e[[[[[[[[[[[[[[[[[e
e[[[[[[[[[[[[[[[[[e
e[[[[[[[[[[[[[[[[[e
y9 RRR
e[[[[[[[[[[[[[[[[[e
9yRRRj
e[[[[[[[[[[[[[[[[[e
e[[[[[[[[[[[[[[[[[e
e[[[[[[[[[[[[[[[[[e
e[[[[[[[[[[[[[[[[[e
e[[[[[[[[[[[[[[[[[e
e[[[[[[[[[[[[[[[[[e
e[[[[[[[[[[[[[[[[[e
e[[[[[[[[[[[[[[[[[e
TTTTTTT
e[[[[[[[[[[[[[[[[[e
TTTTTTTT
e[[[[[[[[[[[[[[[[[e
""Y"Y"YYPPPPPP
e[[[[[[[[[[[[[[[[[e
e[[[[[[[[[[[[[[[[[e
y")#VVwwrrlllrrrwVV
e[[[[[[[[[[[[[[[[[e
lll>ll
e[[[[[[[[[[[[[[[[[e
l
e[[[[[[[[[[[[[[[[[e
e[[[[[[[[[[[[[[[[[e
yJf>
e[[[[[[[[[[[[[[[[[e
e[[[[[[[[[[[[[[[[[e
e[[[[[[[[[[[[[[[[[e
<55555555555555<
e[[[[[[[[[[[[[[[[[e
e[[[[[[[[[[[[[[[[[e
e[[[[[[[[[[[[[[[[[e
e[[[[[[[[[[[[[[[[[e
y99yyyyy
e[[[[[[[[[[[[[[[[[j
y99yyyyRy
j[[[[[[[[[[[[[[[[[[e
yy9yyyyyy
e[[[[[[[[[[[[[[[[[[[
[[[[[[[[[[[[[[[[[[[[[jeeeeeeeeeeeeeeeeeeeeeeej[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[
&55555555555555555
5ZZZZZZZZZZZZZZZZZZ5
&tZo4qqqqqqqqqqqqqZZZ4
qZZZZqZZZoqZ
qZZZZqZZZoqZZZoq
qZZZZqZZZZqZZZZq
qqqqqqqqqqqqqqqq
5ZoqZttZqZ
oZqZZZ
5ZoqZZZZqZttZqZZZ
5ZoqZZZZqZZZZqZZZZqoZ5
5ZoqqqqqqqqqqqqqqqqoZ5
5ZoqZZZZqZZZZqZZZ
qZZZZqZZZZqZZZoqoZ5
qZZZZqZZZZqZZZZq
qqqqqqqqqqqqqq
oooooo
P,NllllN,P
111111NN
1LLLL1L1
&ZZZZttt'''
555555555555555555
\\\\\\\\\\\
F\\\\\\\\\F
\\\\\\\\
X\\\\\\\\
X\\\\\\\\
X\\\\\\\\
X\\\\\\\\
X\\\\\\\\
X\\\\\\\\
X\\\\\\\\
X\\\\\\\\
X\\\\\\\\
ZNNNNNNNNN
X\\\\\\\\
X\\\\\\\\
X\\\\\\\\
X\\\\\\\\
X\\\\\\\\
X\\\\\\\\
X\\\\\\\\
\\\\\\\\\
\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\
I.........IIIIII.
.IIIII.
.IIIII.
.IIIII.
.IIIII.
.IIIII.
.IIIII.
.IIIII.
.IIIII.
.IIIII.
.IIIII.
.IIIII.
.IIIII.
.IIIII.
.IIIIII.........IIIIII
{x~f}|
yurtrwv
|s~d|xv
6F7$\g_{
mscoree.dll
(null)
KERNEL32.DLL
((((( H
h(((( H
H
xobudazureri jabep dugod gunuyojigoyicowucomeyacebupef
xokihuwotoweye
puhasirukafijoviyozoda yap
Vadajofeb rokima siced
miwipufurudugiciyumenuzujifuhuvutedizocuditejeyimitip
bazuletohadepuyeviji
yojepajumoninoxugevotecokuyabapesuwayidamewakejivumatuturoguxowofukojurirotuyumiwim
hubupebibigupoxisecuna
VS_VERSION_INFO
StringFileInform
081564b6
InternalName
kogzmuadeke.exi
Copyright
Copyrighz (C) 2020, vodkagats
ProductVersion
99.9.26.51
VarFileInfo
Translation
AMejayururud duv muvusocu jovagovuji tototari tezudicukuwami direnADeselopas lavegit kacoj pidure rekipoziyine nur rudezijuk pukulev
hJifon yiwiwoviramojoz guyoneray hobafolo cahelarepipojuv zesusexosok kagewan suwimo huku jacusizodahirag
-Tibotizotumepa jotezagojoxiwiw xucotifupuzeco
Antivirus Signature
Bkav W32.AIDetect.malware1
Lionic Trojan.Multi.Generic.4!c
Elastic malicious (high confidence)
MicroWorld-eScan Clean
CMC Clean
CAT-QuickHeal Clean
Qihoo-360 Win32/Heur.Generic.HwoCFhsA
McAfee Artemis!B9D0201D96BF
Cylance Unsafe
Zillya Clean
Sangfor Trojan.Win32.Save.a
CrowdStrike win/malicious_confidence_100% (W)
BitDefender Clean
K7GW Trojan ( 005690671 )
K7AntiVirus Trojan ( 005690671 )
Baidu Clean
Cyren Clean
Symantec Packed.Generic.525
ESET-NOD32 a variant of Win32/Kryptik.HLZM
APEX Malicious
Paloalto generic.ml
ClamAV Clean
Kaspersky UDS:DangerousObject.Multi.Generic
Alibaba Trojan:Win32/Kryptik.c2c6268e
NANO-Antivirus Clean
ViRobot Clean
Rising Trojan.Kryptik!1.D82C (CLASSIC)
Ad-Aware Clean
TACHYON Clean
Emsisoft Trojan.Crypt (A)
Comodo Clean
F-Secure Clean
DrWeb Clean
VIPRE Clean
TrendMicro Clean
McAfee-GW-Edition BehavesLike.Win32.Emotet.hc
FireEye Generic.mg.b9d0201d96bf236e
Sophos Mal/Generic-S
SentinelOne Static AI - Malicious PE
Jiangmin Clean
Webroot Clean
Avira Clean
Antiy-AVL Clean
Kingsoft Clean
Microsoft Trojan:Win32/Caynamer.A!ml
Gridinsoft Clean
Arcabit Clean
SUPERAntiSpyware Clean
ZoneAlarm Clean
GData Win32.Trojan-Spy.CryptBot.QZAZ86
Cynet Malicious (score: 100)
AhnLab-V3 Clean
Acronis suspicious
ALYac Clean
MAX Clean
VBA32 Clean
Malwarebytes Trojan.MalPack.GS
Panda Trj/Genetic.gen
Zoner Clean
TrendMicro-HouseCall Clean
Tencent Clean
Yandex Clean
Ikarus Trojan-Banker.UrSnif
eGambit Clean
Fortinet W32/Kryptik.HLZM!tr
BitDefenderTheta Gen:NN.ZexaF.34058.Iq0@amPg5FfG
AVG Win32:MalwareX-gen [Trj]
Cybereason Clean
Avast Win32:MalwareX-gen [Trj]
MaxSecure Trojan.Malware.300983.susgen
No IRMA results available.