Static | ZeroBOX

PE Compile Time

2020-07-11 23:05:09

PDB Path

C:\rucubinam\subegoh-77_hejazuye.pdb

PE Imphash

6809132c99c8b7d8b68eb68186d7f67f

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x00030b14 0x00030c00 7.77422329415
.data 0x00032000 0x028378b8 0x00003e00 0.813526838472
.rsrc 0x0286a000 0x00013bc0 0x00013c00 6.41936601436

Resources

Name Offset Size Language Sub-language File type
PUHAJIBA 0x0287a778 0x00000685 LANG_SERBIAN SUBLANG_DEFAULT ASCII text, with very long lines, with no line terminators
VOXOMOSIHUTOJOPOTE 0x0287ae00 0x00000636 LANG_SERBIAN SUBLANG_DEFAULT ASCII text, with very long lines, with no line terminators
ZEFUTOPUREDUPIYEZ 0x0287b438 0x000021af LANG_SERBIAN SUBLANG_DEFAULT ASCII text, with very long lines, with no line terminators
RT_CURSOR 0x0287d648 0x00000130 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_ICON 0x0287a298 0x00000468 LANG_SERBIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x0287a298 0x00000468 LANG_SERBIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x0287a298 0x00000468 LANG_SERBIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x0287a298 0x00000468 LANG_SERBIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x0287a298 0x00000468 LANG_SERBIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x0287a298 0x00000468 LANG_SERBIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x0287a298 0x00000468 LANG_SERBIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x0287a298 0x00000468 LANG_SERBIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x0287a298 0x00000468 LANG_SERBIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x0287a298 0x00000468 LANG_SERBIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x0287a298 0x00000468 LANG_SERBIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x0287a298 0x00000468 LANG_SERBIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x0287a298 0x00000468 LANG_SERBIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x0287a298 0x00000468 LANG_SERBIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x0287a298 0x00000468 LANG_SERBIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x0287a298 0x00000468 LANG_SERBIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x0287a298 0x00000468 LANG_SERBIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x0287a298 0x00000468 LANG_SERBIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x0287a298 0x00000468 LANG_SERBIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_STRING 0x0287da70 0x0000014a LANG_SERBIAN SUBLANG_DEFAULT data
RT_STRING 0x0287da70 0x0000014a LANG_SERBIAN SUBLANG_DEFAULT data
RT_ACCELERATOR 0x0287d620 0x00000028 LANG_SERBIAN SUBLANG_DEFAULT data
RT_ACCELERATOR 0x0287d620 0x00000028 LANG_SERBIAN SUBLANG_DEFAULT data
RT_GROUP_CURSOR 0x0287d778 0x00000014 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_GROUP_ICON 0x02870858 0x00000068 LANG_SERBIAN SUBLANG_DEFAULT data
RT_GROUP_ICON 0x02870858 0x00000068 LANG_SERBIAN SUBLANG_DEFAULT data
RT_GROUP_ICON 0x02870858 0x00000068 LANG_SERBIAN SUBLANG_DEFAULT data
RT_VERSION 0x0287d790 0x000001b4 LANG_NEUTRAL SUBLANG_NEUTRAL data

Imports

Library KERNEL32.dll:
0x401000 GetComputerNameA
0x401008 CreateFileA
0x40100c GlobalDeleteAtom
0x401014 lstrlenA
0x40101c EnumDateFormatsExW
0x401024 UpdateResourceA
0x401028 EndUpdateResourceW
0x40102c ReadConsoleA
0x401030 GetCurrentProcess
0x401034 GetUserDefaultLCID
0x401038 WaitForSingleObject
0x40103c WriteConsoleInputA
0x401040 SetEvent
0x401048 GetModuleHandleW
0x40104c SetFileTime
0x401050 ReadConsoleOutputA
0x401054 WriteFile
0x401058 CreateActCtxW
0x401060 ActivateActCtx
0x401064 GetConsoleCP
0x401068 GlobalFindAtomA
0x40106c LoadLibraryW
0x401070 TerminateThread
0x401074 ReadConsoleInputA
0x401078 CopyFileW
0x401080 GetVersionExW
0x40108c GetConsoleAliasW
0x401094 VerifyVersionInfoA
0x401098 CreateActCtxA
0x40109c SetConsoleTitleA
0x4010a0 GetConsoleOutputCP
0x4010a4 SetLastError
0x4010a8 GetProcAddress
0x4010ac VerLanguageNameA
0x4010b0 HeapUnlock
0x4010bc GetDiskFreeSpaceW
0x4010c0 LoadLibraryA
0x4010c4 WriteConsoleA
0x4010cc DeleteTimerQueue
0x4010d0 CreateTapePartition
0x4010d4 GetProfileStringA
0x4010d8 BuildCommDCBA
0x4010dc VirtualProtect
0x4010e4 GetCPInfoExA
0x4010e8 FindFirstVolumeA
0x4010f0 GetSystemTime
0x4010f4 AreFileApisANSI
0x4010f8 CreateThread
0x401104 GetLastError
0x401108 HeapReAlloc
0x40110c HeapAlloc
0x401110 GetStartupInfoW
0x401114 RaiseException
0x401118 RtlUnwind
0x40111c Sleep
0x401120 ExitProcess
0x401124 GetStdHandle
0x401128 GetModuleFileNameA
0x40112c TerminateProcess
0x401130 IsDebuggerPresent
0x401134 HeapFree
0x401140 HeapCreate
0x401144 VirtualFree
0x401148 VirtualAlloc
0x40114c GetModuleFileNameW
0x401158 GetCommandLineW
0x40115c SetHandleCount
0x401160 GetFileType
0x401164 GetStartupInfoA
0x401168 TlsGetValue
0x40116c TlsAlloc
0x401170 TlsSetValue
0x401174 TlsFree
0x40117c GetCurrentThreadId
0x401188 GetTickCount
0x40118c GetCurrentProcessId
0x401198 HeapSize
0x40119c GetCPInfo
0x4011a0 GetACP
0x4011a4 GetOEMCP
0x4011a8 IsValidCodePage
0x4011ac GetLocaleInfoA
0x4011b0 WideCharToMultiByte
0x4011b4 GetStringTypeA
0x4011b8 MultiByteToWideChar
0x4011bc GetStringTypeW
0x4011c0 LCMapStringA
0x4011c4 LCMapStringW
Library USER32.dll:
0x4011cc GetAltTabInfoA

!This program cannot be run in DOS mode.
`.data
bad allocation
string too long
invalid string position
Unknown exception
CorExitProcess
runtime error
TLOSS error
SING error
DOMAIN error
An application has made an attempt to load the C runtime library incorrectly.
Please contact the application's support team for more information.
- Attempt to use MSIL code from this assembly during native code initialization
This indicates a bug in your application. It is most likely the result of calling an MSIL-compiled (/clr) function from a native constructor or from DllMain.
- not enough space for locale information
- Attempt to initialize the CRT more than once.
This indicates a bug in your application.
- CRT not initialized
- unable to initialize heap
- not enough space for lowio initialization
- not enough space for stdio initialization
- pure virtual function call
- not enough space for _onexit/atexit table
- unable to open console device
- unexpected heap error
- unexpected multithread lock error
- not enough space for thread data
This application has requested the Runtime to terminate it in an unusual way.
Please contact the application's support team for more information.
- not enough space for environment
- not enough space for arguments
- floating point support not loaded
Microsoft Visual C++ Runtime Library
<program name unknown>
Runtime Error!
Program:
EncodePointer
DecodePointer
FlsFree
FlsSetValue
FlsGetValue
FlsAlloc
bad exception
GetProcessWindowStation
GetUserObjectInformationA
GetLastActivePopup
GetActiveWindow
MessageBoxA
USER32.DLL
Complete Object Locator'
Class Hierarchy Descriptor'
Base Class Array'
Base Class Descriptor at (
Type Descriptor'
`local static thread guard'
`managed vector copy constructor iterator'
`vector vbase copy constructor iterator'
`vector copy constructor iterator'
`dynamic atexit destructor for '
`dynamic initializer for '
`eh vector vbase copy constructor iterator'
`eh vector copy constructor iterator'
`managed vector destructor iterator'
`managed vector constructor iterator'
`placement delete[] closure'
`placement delete closure'
`omni callsig'
delete[]
new[]
`local vftable constructor closure'
`local vftable'
`udt returning'
`copy constructor closure'
`eh vector vbase constructor iterator'
`eh vector destructor iterator'
`eh vector constructor iterator'
`virtual displacement map'
`vector vbase constructor iterator'
`vector destructor iterator'
`vector constructor iterator'
`scalar deleting destructor'
`default constructor closure'
`vector deleting destructor'
`vbase destructor'
`string'
`local static guard'
`typeof'
`vcall'
`vbtable'
`vftable'
operator
delete
__unaligned
__restrict
__ptr64
__clrcall
__fastcall
__thiscall
__stdcall
__pascal
__cdecl
__based(
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
HH:mm:ss
dddd, MMMM dd, yyyy
MM/dd/yy
December
November
October
September
August
February
January
Saturday
Friday
Thursday
Wednesday
Tuesday
Monday
Sunday
SunMonTueWedThuFriSat
JanFebMarAprMayJunJulAugSepOctNovDec
bad allocation
wijiwifalipimetibuligijabudidozo fed rolujalajuliv fomij docoxewicudavobinidegamu
hizejikekacuwawidobikopaganinetayizufuluyijoyegixoyobohamepoxedujohuyokuyusu
lagadozumuvexe
Tipit gedo fizayed mizetawovadu yewaxacolitena
Bikoruma fej mebebohudor vem rawuso
Belifocavo buvapetaxan xafuki yov rivifasid
hapawikitozibozipusi dagetegopuwikafox
Yokanohufupo kuluhonin lugudabicevu liyonirit
Sipiwaxe
LocalAlloc
Loridaruy lafaj biveyiwa pupeyobo xarefez
C:\rucubinam\subegoh-77_hejazuye.pdb
VVVVVVh
D$PPVV
PVh`/@
PVVVVV
0WWWWW
0WWWWW
QQSVWd
0SSSSS
>=Yt1j
QQSVWh
j@j ^V
HtHu4j
s[S;7|G;w
tR99u2
0SSSSS
0SSSSS
URPQQh
0WWWWW
AAFFf;
0A@@Ju
;t$,v-
UQPXY]Y[
PPPPPPPP
PPPPPPPP
t"SS9]
t+WWVPV
&vVVDP
t 01^k
P>C~.`1
Y:&r*}
n"P]OYol
%Hu]ig
lkfoM3./
b~b6pV
oA"&D%
"U,Qvc
{;sz[aVQ
ftJ(o_
q-mVo+
(2ge{q
Kb+6))q
Dk+R/X
.?fEO9
`k`G^L
%<nq]m
gWf(>OI
AxaMR<
RRS@A`
_`md(?
ta#\Z~
B2JOK<
aL=+m%
IFe0}"+$
gK'SNW
xS(DBO
A3;cB&
1O&dCOz
WBMwV{
+nMSv<6
|Xs|8im
C"Jm6^
Q)bc5V
S t6I|
!]d_J,F
Qc>m+(
r$K"V!Y
6g|`*btk'd
^@30/v
bZ<n4Wh
yzWk*-8
f&1j>h@
h_*>G|e
9TkN?I
bp\74P*
)9aRi<
q[ S8"?G
vW~VVg,
~NqbS"P
Hf+azD
C2DV9<
9['mO|
@)D$?-
)X$,bp4#
_U&Y>S
T:p2t;
}rq8iK}
l!o+Pq
8z|uht
+V,h:>
R!4oqE
)H2FP<
1I:*)?
axl)L^P
e,J\tM
$!<(>B#
D"n0~6X
qCDT71
H1\x=?
*~H{yz
F*>GcF:
w/6eUm
pV0\o9
-,%?>S
hX`B8BL%
VG'CNy
w=Lksn+
XZ Q+b
L\TP5xL7V(T
,/ajWmd
7y@[VgS}
S{&kXY[;
SwtOZ:
a"Sb,h
~M"uWo
SivpyF5
_J+=%Y
k@cqL1d
1GYnNa
:Bpbi(
Y[s=|"
_8K<
RpSOkPM
Iw/3c>
=X9mx`
3_4OA|^
[x]~t~
E@}>]"
iJ.`~
v/7}p/I6
xAwhRx
:I[?1r
O2~S46
\U:U)=S(Y7
94>wOx
WhJKaZ
4)J?eX
BcNLCnO
d8%Pz(6
`)FhY0
6_kyq]
&(e&12
]}9 ]!
EE@3^G6
sk)'b%G
G&/$gsZ
?3Hdh%
XDQy.4
%>)?M9
'Z~8_b<T}
2O"gtR
`Q`LXf
y$gJ@J
-PdwoL[rB
popakk*@|
~63bq,
&W0uhA
$e%BU
#;Wn?/
Zp+Cz.K
ZVGx+P
M9'L2Z
iO?VUS
uG/b6A!
Y]KM9a
#Pdd=.P
qf@MpE
\9Q-_-
.l@|5+`A
n.u)O4
qdzHt7
oOb;qz
^l::a>
NbQvz6
&7T_@^
E)45rUO5Tc
/FtvX%{
oE+7%c
(#B?$/{
>NaRw(
SkIwa\~n
0i&+01
jns%PIt
I!MiS6<
3XG.yZ
c`#VK>H.
o~bOCWDy
rxwWNo
uJ'~KH
JfLR2X8g
/<0zmW
$(n"7/
"j2p /@
8yRd,/
,INpBN
KwXV9a
@v4*irB
JD=sTJ
P*$~m\
1Xg! V
qz>Mt
}G1:8Y2N
Fe(4EZ2
)p6i;n
jRk{p~
0}<b"{
yDA-i?w
30;0S<O
NQ\pRS
lW@=>1
W1DhE:P
"zDCUm
xbwpUA
)2-_kw
kn<)hf
~eg=,b
Nme)NYh
/lp]21
ab9C*hLyXLYm
BQ[^VE
^+!Yb}
H2oDPV
;6Dft\o
ehVsJs
oE}RK
{bdDD%
<;7hA^T
Qtbey/
pBt$.
wr"CZ
tP|oT#
Q|XuDL
e%}B6X
SEf/1Xq
m.SWf$|
}}z\-t/
R^ gOE<
*N|!Pt&+
8M&J,Vp
/6[GRpA
jprm/#
Q'k29+&
YxO%2n
h*AXw^
j@8=[v
n@_-w_z
7HfIOi
5!LJ'#h
fAodwrH
62}r4D!
?[l0(
>QPu>F
qe4C[\
b5 K5bS
Ii(}ei
pj5e
~LdLlj
VQiz8t
g%[>3:
WT$^(
YPNYy#y[
@zfYLxE
D2h>cZ
-na}YZ
T~XJuG
j;XlBBgL
!8hrQ-
o<2y^Ox
Ib.^c
%S-#7OH
B7\OQa
F&>^Nq
@xMN9G
2Vl|Q7
[IBpwV
2CMk@dgm
.w#aZd
DqS3^C
r]MJQ!
Pl dL*
Y iPdg
M8]w;
NS'qzWG
JpJ86;
GetComputerNameA
SetProcessAffinityMask
CreateFileA
GlobalDeleteAtom
WriteConsoleOutputCharacterW
lstrlenA
GetConsoleAliasesLengthW
EnumDateFormatsExW
BuildCommDCBAndTimeoutsA
UpdateResourceA
EndUpdateResourceW
ReadConsoleA
GetCurrentProcess
GetUserDefaultLCID
WaitForSingleObject
WriteConsoleInputA
SetEvent
GetSystemDefaultLCID
GetModuleHandleW
SetFileTime
ReadConsoleOutputA
WriteFile
CreateActCtxW
InitializeCriticalSection
ActivateActCtx
GetConsoleCP
GlobalFindAtomA
LoadLibraryW
TerminateThread
ReadConsoleInputA
CopyFileW
GetSystemWindowsDirectoryA
GetVersionExW
InterlockedPopEntrySList
DnsHostnameToComputerNameW
GetConsoleAliasW
SetConsoleCursorPosition
VerifyVersionInfoA
CreateActCtxA
SetConsoleTitleA
GetConsoleOutputCP
SetLastError
GetProcAddress
VerLanguageNameA
HeapUnlock
GetConsoleDisplayMode
EnterCriticalSection
GetDiskFreeSpaceW
LoadLibraryA
WriteConsoleA
InterlockedExchangeAdd
DeleteTimerQueue
CreateTapePartition
GetProfileStringA
BuildCommDCBA
VirtualProtect
GetFileAttributesExW
GetCPInfoExA
FindFirstVolumeA
GetPrivateProfileSectionW
GetSystemTime
AreFileApisANSI
CreateThread
KERNEL32.dll
GetAltTabInfoA
RealChildWindowFromPoint
USER32.dll
UnhandledExceptionFilter
SetUnhandledExceptionFilter
GetLastError
HeapReAlloc
HeapAlloc
GetStartupInfoW
RaiseException
RtlUnwind
ExitProcess
GetStdHandle
GetModuleFileNameA
TerminateProcess
IsDebuggerPresent
HeapFree
DeleteCriticalSection
LeaveCriticalSection
HeapCreate
VirtualFree
VirtualAlloc
GetModuleFileNameW
FreeEnvironmentStringsW
GetEnvironmentStringsW
GetCommandLineW
SetHandleCount
GetFileType
GetStartupInfoA
TlsGetValue
TlsAlloc
TlsSetValue
TlsFree
InterlockedIncrement
GetCurrentThreadId
InterlockedDecrement
QueryPerformanceCounter
GetTickCount
GetCurrentProcessId
GetSystemTimeAsFileTime
InitializeCriticalSectionAndSpinCount
HeapSize
GetCPInfo
GetACP
GetOEMCP
IsValidCodePage
GetLocaleInfoA
WideCharToMultiByte
GetStringTypeA
MultiByteToWideChar
GetStringTypeW
LCMapStringA
LCMapStringW
.?AVlogic_error@std@@
.?AVlength_error@std@@
.?AVout_of_range@std@@
.?AVtype_info@@
.?AVbad_exception@std@@
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
.?AVexception@std@@
.?AVbad_alloc@std@@
IJA<<=
xqrX:#
=^Xu[J
vnhHI8ACP]Z\shv]8!
xhmF?OQlgwppkmuZ
ukrD@Zmihn_iemyM
kimY[nlmhlmzqwW*
vZjjvumr|
}_bUK#
`gtmhmn~`
wgthgn]S7,&'
xgvlgP7
pB$A>egjlh2
,]m=9nk
%xruU~
yz{vdVD@.
&\ftwPK
8<za",
01|r#1
3NL}wC;
5PWpI/-
IMk7-=
RZyvA<
(^huB/1
vvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvv'_
vvvvvvvvvvvvvvvvvvvvM
6evvvvvvvvvvvvvvvvvv
vvvvvvvvvvvvvvvvwo
vvvvvvvvvvvvvvv
@vvvvvvvvvvvvvv
vvvvvvvvvvvvvvv
vvvvvvvvvvvvvvv
vvvvvvvvvvv
vvvvvvvvvv
vvvvvvvvvv
I]vvvvvvvvvvvvL
vvvvvvvvvvvv
%vvvvvvvvvvvvv
jvvvvvvvvvvvv
vvvvvvvvvvvv
svvvvv
vvvvvvvvvvvvvvvvvv
vvvvvvvvvvvvvvvvvv
vvvvvvvvvvvvvvvvvv
vvvvvvvvvvvvvvvvvv
vvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvv
@@@@@@@@@@@@@@@@@@@@@@@@@@@
U?@@@@@@@@@@@@
MXx@@@@@@@@@@@
O@@@@@@@@@@
y@@@@@@@@@
@@@@@@
@@@@@@@
@@@@@@@
@@@@@@@@
@@@@@@@@
@@@@@@@@@@@@b
@@@@@@@@@@@
WE#@@@@@@@@@@@@
@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@
Vb+}Zk(~]u ~c}(
[[[[jeeeeeeeeeeeeeeeeeeeeeeej[[[[[[[[[[[[[[[[[[[[[
[[[[[[[[[[[[[[[[[[[e
e[[[[[[[[[[[[[[[[[[j
j[[[[[[[[[[[[[[[[[e
e[[[[[[[[[[[[[[[[[e
e[[[[[[[[[[[[[[[[[e
e[[[[[[[[[[[[[[[[[e
e[[[[[[[[[[[[[[[[[e
99yRRj?
e[[[[[[[[[[[[[[[[[e
e[[[[[[[[[[[[[[[[[e
e[[[[[[[[[[[[[[[[[e
e[[[[[[[[[[[[[[[[[e
e[[[[[[[[[[[[[[[[[e
y9 RRR
e[[[[[[[[[[[[[[[[[e
9yRRRj
e[[[[[[[[[[[[[[[[[e
e[[[[[[[[[[[[[[[[[e
e[[[[[[[[[[[[[[[[[e
e[[[[[[[[[[[[[[[[[e
e[[[[[[[[[[[[[[[[[e
e[[[[[[[[[[[[[[[[[e
e[[[[[[[[[[[[[[[[[e
e[[[[[[[[[[[[[[[[[e
TTTTTTT
e[[[[[[[[[[[[[[[[[e
TTTTTTTT
e[[[[[[[[[[[[[[[[[e
""Y"Y"YYPPPPPP
e[[[[[[[[[[[[[[[[[e
e[[[[[[[[[[[[[[[[[e
y")#VVwwrrlllrrrwVV
e[[[[[[[[[[[[[[[[[e
lll>ll
e[[[[[[[[[[[[[[[[[e
l
e[[[[[[[[[[[[[[[[[e
e[[[[[[[[[[[[[[[[[e
yJf>
e[[[[[[[[[[[[[[[[[e
e[[[[[[[[[[[[[[[[[e
e[[[[[[[[[[[[[[[[[e
<55555555555555<
e[[[[[[[[[[[[[[[[[e
e[[[[[[[[[[[[[[[[[e
e[[[[[[[[[[[[[[[[[e
e[[[[[[[[[[[[[[[[[e
y99yyyyy
e[[[[[[[[[[[[[[[[[j
y99yyyyRy
j[[[[[[[[[[[[[[[[[[e
yy9yyyyyy
e[[[[[[[[[[[[[[[[[[[
[[[[[[[[[[[[[[[[[[[[[jeeeeeeeeeeeeeeeeeeeeeeej[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[
&55555555555555555
5ZZZZZZZZZZZZZZZZZZ5
&tZo4qqqqqqqqqqqqqZZZ4
qZZZZqZZZoqZ
qZZZZqZZZoqZZZoq
qZZZZqZZZZqZZZZq
qqqqqqqqqqqqqqqq
5ZoqZttZqZ
oZqZZZ
5ZoqZZZZqZttZqZZZ
5ZoqZZZZqZZZZqZZZZqoZ5
5ZoqqqqqqqqqqqqqqqqoZ5
5ZoqZZZZqZZZZqZZZ
qZZZZqZZZZqZZZoqoZ5
qZZZZqZZZZqZZZZq
qqqqqqqqqqqqqq
oooooo
P,NllllN,P
111111NN
1LLLL1L1
&ZZZZttt'''
555555555555555555
\\\\\\\\\\\
F\\\\\\\\\F
\\\\\\\\
X\\\\\\\\
X\\\\\\\\
X\\\\\\\\
X\\\\\\\\
X\\\\\\\\
X\\\\\\\\
X\\\\\\\\
X\\\\\\\\
X\\\\\\\\
ZNNNNNNNNN
X\\\\\\\\
X\\\\\\\\
X\\\\\\\\
X\\\\\\\\
X\\\\\\\\
X\\\\\\\\
X\\\\\\\\
\\\\\\\\\
\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\
I.........IIIIII.
.IIIII.
.IIIII.
.IIIII.
.IIIII.
.IIIII.
.IIIII.
.IIIII.
.IIIII.
.IIIII.
.IIIII.
.IIIII.
.IIIII.
.IIIII.
.IIIIII.........IIIIII
{x~f}|
yurtrwv
|s~d|xv
6F7$\g_{
Vudoni yefesixosi vohiyeyasicok. Tepez yoxekocamebino. Yotusacawazi. Yokivitotuv pozudafipod kekefufojajup yaciperecijukew seyovovozuhukit. Fahir wuzexomuguvun. Cudejula. Fomilezuxaroz. Rufemimazuzob pocureliya gelegapu faba. Kovi nil jinebokozikojey. Nuxaginode vopabanag zenu muveri papecoruyi. Geduxi nefolocalew xajikufo davutibosoyohey horivexabihifaz. Manuwonojinefez rakas xav kob hofupof. Lerewiji fasasakimewezac jejomaci. Ledikujorewe zavulacajima. Vokapokohatu parubepolovi kuy cemayiva rucijedavo. Vud. Pajixop maguma biboyijaso. Cajacocugabaxa defiducikorode negavihebelal tek jufobuxecokuhig. Cigujuzakec. Yeve. Jeratifikatopi wubilicumaselu. Juhubonopiyafu. Robagarubiy fadageyafu jivuce jadomalifud. Soho kobobizanuw. Fine solaf besulugoro gutiyomeporada likohonutewayo. Sano begozas. Ducuyiredanevad vegagazi. Zuvowavayafe. Goxom defu dujexe zuwanawuguw. Jux kiwodek wobosi reri. Rideyetex. Zigopidaj guyubife. Nafawat naxamiliyifamu rijipifenitonuw jir gutediweyokojop. Kotogob nobasane xid. Fefihuzakiney
Mayuye xocakis pomawekeresereh. Lefilinipoxawol vafepuk dicafuban. Hujapopumoy. Masatafuri. Didalorigu. Zikugerivifaw hociyudupem. Zikowim koxak nejaseyek. Sehorepas cacanimagofibu nabijeditu. Lomo gasu hirusume panufogi. Nuzelireto rekixacabigu. Budumolupofat xiso ligeyoj kosuvijogemobe. Biwejicufak runubifesezuw poxakapoyiteyac bame zajobihekevuheh. Rojecelo kalizumaz fozozoxulutazo. Nadikacejawov mih feruricedikexef jejositude kidogejekosume. Woxovarekav pogexo. Jibopeninibesa rot gev. Gixiremukur gused rida robupacejahoy. Medujavuw jadilitufetoca coxotarujute jayemaxale tisoxufaxuh. Gido rawupepaj. Kolopegalakaru hay hepox. Bij xucepovubazadam lad doba vam. Yineworoyakew tocivexixesor natovurovuwozi nibihox. Duha. Zajapihamu cegabufolapis pelivibizo fapugatetawecog. Desizaz zefoh wuxetizegijaz. Nogudikayevali. Cimeficaxusedep fefewelit. Pomonividilomu vahebuy zekexime webiro wule. Bidenakaxeruwod newokurugaxuzed zinuhay. Tenekawasoyagu. Hofigezoriyirip soviy vafok. Kusafujiyoto vocusiniyevo. Defupumave. W
Peja. Tefexemosolotad. Purudocifihisob jijupa calacosug zenesojubavul. Ducijovol xuzucode mimelebozo. Zagakamedadosi dutawegafotaj boheyo tixajef. Wavo. Cikinibinulaz. Botaxa cuvika feyokenezarora jela wojemeceleker. Cipazobur saz repaya gayagof hoyete. Nomumape felabaya gihom meromezo. Ripuli dozicecazi yezuhecenatux. Gof foga giwomupobodimaj geju. Sotax kopuxah mik. Babuneha zurivasodekohi. Kekuyusa picaw hopakesibuxe kivovofucibezu fitilimoregon. Tukepoyesinig cij vepovekedif. Yide sones moyurotiju. Jisi fugixa. Pozidatebo juketiruvozete cajegovulasa. Figogerofexoho facowaxonoxogu. Huyeyona leyatasil kidogihi wofosejefivi. Motifon xujinonivufoj cepanove. Suku hagak tokifozecavov pedinemewajil. Haxipayix mav josugebapi. Babix hawi woxemagase. Lixa ginotadukufuy. Navamezihikasov cemod zexagigeyi. Dub nufazirorop xuvopucezeramo. Voseked zigonepa jasigayukacod jutakoxokovo fewajet. Hehayiro xivarelufufeg kovanibojid. Rivod dedibimesogula werametacupu tajelakacula cegokegigexes. Rosukujapu hodisonuli reriyevitu
mscoree.dll
KERNEL32.DLL
((((( H
h(((( H
H
xobudazureri jabep dugod gunuyojigoyicowucomeyacebupef
puhasirukafijoviyozoda yap
miwipufurudugiciyumenuzujifuhuvutedizocuditejeyimitip
bazuletohadepuyeviji
yojepajumoninoxugevotecokuyabapesuwayidamewakejivumatuturoguxowofukojurirotuyumiwim
kernel32.dll
pilahukinofuka
hubupebibigupoxisecuna
fayehihapoyivucihi subevojupicu busosepuya bimekut zesuj
PUHAJIBA
VOXOMOSIHUTOJOPOTE
ZEFUTOPUREDUPIYEZ
VS_VERSION_INFO
StringFileInform
081564b6
InternalName
kogzmuadeke.exi
Copyright
Copyrighz (C) 2020, vodkagats
ProductVersion
91.78.38.18
VarFileInfo
Translation
AMejayururud duv muvusocu jovagovuji tototari tezudicukuwami direnADeselopas lavegit kacoj pidure rekipoziyine nur rudezijuk pukulev
hJifon yiwiwoviramojoz guyoneray hobafolo cahelarepipojuv zesusexosok kagewan suwimo huku jacusizodahirag
-Tibotizotumepa jotezagojoxiwiw xucotifupuzeco
Antivirus Signature
Bkav W32.AIDetect.malware1
Lionic Trojan.Win32.Noon.l!c
Elastic malicious (high confidence)
MicroWorld-eScan Trojan.GenericKDZ.76838
CMC Clean
CAT-QuickHeal Clean
ALYac Gen:Variant.Zusy.396701
Cylance Unsafe
Zillya Clean
Sangfor Trojan.Win32.Save.a
K7AntiVirus Trojan ( 0056f9be1 )
BitDefender Trojan.GenericKDZ.76838
K7GW Trojan ( 0056f9be1 )
Cybereason malicious.54aa68
BitDefenderTheta Clean
Cyren W32/Banker.HC.gen!Eldorado
Symantec Packed.Generic.525
ESET-NOD32 a variant of Win32/Kryptik.HLZM
Baidu Clean
APEX Malicious
Paloalto generic.ml
ClamAV Win.Dropper.Ursnif-9884016-0
Kaspersky UDS:Trojan-Spy.Win32.Noon
Alibaba Trojan:Win32/GandCrab.e8437012
NANO-Antivirus Clean
ViRobot Clean
Rising Trojan.Kryptik!1.D82C (CLASSIC)
Ad-Aware Trojan.GenericKDZ.76838
Emsisoft Gen:Variant.Zusy.396701 (B)
Comodo Clean
F-Secure Clean
DrWeb Clean
VIPRE Clean
TrendMicro TROJ_FRS.VSNW05H21
McAfee-GW-Edition BehavesLike.Win32.Generic.dc
FireEye Generic.mg.5da37b461ae4c329
Sophos Mal/Generic-S
SentinelOne Static AI - Malicious PE
Jiangmin Clean
MaxSecure Clean
Avira Clean
MAX malware (ai score=86)
Antiy-AVL Clean
Kingsoft Clean
Microsoft Trojan:Win32/Azorult!ml
Gridinsoft Clean
Arcabit Clean
SUPERAntiSpyware Clean
ZoneAlarm Clean
GData Gen:Variant.Zusy.396701
Cynet Malicious (score: 100)
AhnLab-V3 Trojan/Win.Agent.C4582242
Acronis suspicious
McAfee RDN/Generic.grp
TACHYON Clean
VBA32 Clean
Malwarebytes Trojan.MalPack.GS
Panda Trj/GdSda.A
Zoner Clean
TrendMicro-HouseCall TROJ_FRS.VSNW05H21
Tencent Win32.Trojan.Inject.Auto
Yandex Clean
Ikarus Trojan-Banker.UrSnif
eGambit Clean
Fortinet W32/UrSnif.C6C8!tr
Webroot Clean
AVG Win32:MalwareX-gen [Trj]
Avast Win32:MalwareX-gen [Trj]
CrowdStrike win/malicious_confidence_100% (W)
Qihoo-360 Win32/Heur.Generic.HwoCueAA
No IRMA results available.