Static | ZeroBOX

PE Compile Time

2020-04-14 06:06:00

PDB Path

C:\malamu\wuxesugukohi\nuyopukoj defexomop53-pu.pdb

PE Imphash

00a47d6be4445a02dce374ef34dd9b76

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x00059320 0x00059400 7.96921388709
.rdata 0x0005b000 0x000037f0 0x00003800 4.42739006342
.data 0x0005f000 0x02838a60 0x00004000 0.692967420368
.rsrc 0x02898000 0x00006178 0x00006200 6.33850789093

Resources

Name Offset Size Language Sub-language File type
RT_CURSOR 0x0289dcf0 0x000000b0 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_CURSOR 0x0289dcf0 0x000000b0 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x0289d698 0x00000468 LANG_SERBIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x0289d698 0x00000468 LANG_SERBIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x0289d698 0x00000468 LANG_SERBIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x0289d698 0x00000468 LANG_SERBIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x0289d698 0x00000468 LANG_SERBIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x0289d698 0x00000468 LANG_SERBIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_STRING 0x0289e028 0x0000014a LANG_SERBIAN SUBLANG_DEFAULT data
RT_STRING 0x0289e028 0x0000014a LANG_SERBIAN SUBLANG_DEFAULT data
RT_ACCELERATOR 0x0289db98 0x00000028 LANG_SERBIAN SUBLANG_DEFAULT data
RT_ACCELERATOR 0x0289db98 0x00000028 LANG_SERBIAN SUBLANG_DEFAULT data
RT_GROUP_CURSOR 0x0289dda0 0x00000022 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_GROUP_ICON 0x0289db00 0x0000005a LANG_SERBIAN SUBLANG_DEFAULT data
RT_VERSION 0x0289ddc8 0x000001b4 LANG_NEUTRAL SUBLANG_NEUTRAL data

Imports

Library KERNEL32.dll:
0x45b004 WriteConsoleInputW
0x45b008 lstrlenA
0x45b010 EnumDateFormatsExW
0x45b014 FindResourceExW
0x45b01c EndUpdateResourceW
0x45b020 GetUserDefaultLCID
0x45b028 GetComputerNameW
0x45b02c SetEvent
0x45b034 GetProcessHeap
0x45b038 ReadConsoleW
0x45b03c SetFileTime
0x45b040 WriteFile
0x45b044 CreateActCtxW
0x45b04c GetVolumePathNameW
0x45b050 ActivateActCtx
0x45b054 GetConsoleCP
0x45b058 GlobalFindAtomA
0x45b05c TerminateThread
0x45b060 ReadConsoleInputA
0x45b068 ReadConsoleOutputW
0x45b06c GetVersionExW
0x45b070 SetConsoleCP
0x45b07c GetConsoleAliasW
0x45b080 VerifyVersionInfoA
0x45b084 GetMailslotInfo
0x45b08c CreateActCtxA
0x45b090 SetConsoleTitleA
0x45b094 GetConsoleOutputCP
0x45b098 InterlockedExchange
0x45b09c GetLastError
0x45b0a0 GetLongPathNameW
0x45b0a4 SetLastError
0x45b0a8 GetProcAddress
0x45b0b4 LoadLibraryA
0x45b0b8 WriteConsoleA
0x45b0bc CreateTapePartition
0x45b0c0 GetProfileStringA
0x45b0cc GetModuleHandleA
0x45b0d0 UpdateResourceW
0x45b0d8 BuildCommDCBA
0x45b0dc VirtualProtect
0x45b0e4 GetCPInfoExA
0x45b0e8 SetCalendarInfoA
0x45b0ec FindFirstVolumeW
0x45b0f0 GetCurrentProcessId
0x45b0f8 GlobalReAlloc
0x45b0fc GetSystemTime
0x45b100 AreFileApisANSI
0x45b104 CreateThread
0x45b108 CreateFileA
0x45b114 HeapReAlloc
0x45b118 HeapAlloc
0x45b11c GetStartupInfoW
0x45b120 GetModuleHandleW
0x45b124 Sleep
0x45b128 ExitProcess
0x45b12c GetStdHandle
0x45b130 GetModuleFileNameA
0x45b138 TerminateProcess
0x45b13c GetCurrentProcess
0x45b140 IsDebuggerPresent
0x45b148 HeapCreate
0x45b14c VirtualFree
0x45b150 HeapFree
0x45b154 VirtualAlloc
0x45b158 GetModuleFileNameW
0x45b164 GetCommandLineW
0x45b168 SetHandleCount
0x45b16c GetFileType
0x45b170 GetStartupInfoA
0x45b174 TlsGetValue
0x45b178 TlsAlloc
0x45b17c TlsSetValue
0x45b180 TlsFree
0x45b188 GetCurrentThreadId
0x45b194 GetTickCount
0x45b1a0 GetCPInfo
0x45b1a4 GetACP
0x45b1a8 GetOEMCP
0x45b1ac IsValidCodePage
0x45b1b0 WideCharToMultiByte
0x45b1b4 RtlUnwind
0x45b1b8 HeapSize
0x45b1bc GetLocaleInfoA
0x45b1c0 GetConsoleMode
0x45b1c4 FlushFileBuffers
0x45b1c8 LCMapStringA
0x45b1cc MultiByteToWideChar
0x45b1d0 LCMapStringW
0x45b1d4 GetStringTypeA
0x45b1d8 GetStringTypeW
0x45b1dc SetFilePointer
0x45b1e0 CloseHandle
0x45b1e4 WriteConsoleW
0x45b1e8 SetStdHandle
Library USER32.dll:
0x45b1f0 GetAltTabInfoA

!This program cannot be run in DOS mode.
`.rdata
@.data
PVVVVV
HHtXHHt
>If90t
>=Yt1j
QQSVWh
j@j ^V
0SSSSS
0SSSSS
0SSSSS
0A@@Ju
^SSSSS
j"^SSSSS
URPQQhPy@
0WWWWW
AAFFf;
t"SS9]
PPPPPPPP
PPPPPPPP
;t$,v-
UQPXY]Y[
t+WWVPV
=Ql_}U|
/ekPc:gC
>z$u1:
gt4$L"
QF-Q^-D
=L!h>g
gS}7p|
L i8($H*
RZ<hYza :
$X-5uvu
*-~bIB.
hs\=8D5
5D*nk%
_hSc,#
0?P1(eL
b)xv7~
0i)^WKPC
GOf+v3x;9?
ATT[DC
7t;5HdX
P!!B7|
`{m':e
=iHG,7
7e@[=h5
N13n;h
.'[_N5
]WHTen
u;_<sR<
I\}k/w
1j}b7g
m+a{],
n\D)Z8&1
ZC1F4c
o$y:'+MG
(mCt,}
)x%OU|
I$'e"'Es.
GT@u#o;(a}<n
MEo3!#
offLEaf,
M2%T:Pl
o)?>e-u
(%8*y-
Q;CNhR1
0/4m/0I
\X"{5|
GlqCrA
Lz>;!sPU
)yQ"^G
kIdS3`>M{$w
qGWRp#
Q9~aE
iX8XP,z
d.&./s
ZW<8RY
(fF~!+`n8
fP{^8|
l{?:!v
DiFfs:
#K}(`R
ctaWQ4
kMB>[.
m6x[XJ
d@6T &
^)9NZo
aAQpptZ
uWlmrP
.%diH%
z"#pxL
~>2q.t
z(pD7O
@H_m:J3]
[p<~o{
pZ;AvK
e*],~7
YJH@}"
FG^sJ=
{h` Vb
M*|6d7?
Y~Yh]l
PO#ABmrpE
blIa\c
\g.ciB
ajPjLQ'
'LMD<Uj/&
NEK+ciL
'y-eu?
y0*w$%^
='vJ;G
o% F,,
.\oeCY
fq9kUGC
f9kJFD
Q2-nzu5
G>o\NA
;@.k:nF
YHM'xi(9
/Z^W-OO
/:>6Di;{2
S0Q[Gk
%%Mt&]
,j7I#R>
]e2< $a
4'|\d-"
ZUoOdg
\{s#J(
Pr1>p%
(rU0y[
cy S?j
~{8VUw
Y'pcx
3x]slF7x
&2v<[<
zL1QI(
pK#y36
Eug8WgA
~&.yEi
/vhN^@
xN7sb$
4MS;F.R!
D-d&>`yB
#xB)Dx
@OwbTt
v*8YB`
fE'svQqD
"-9`D[sa
Z+UHx)47|5sb
w.+sYb
]NOb/{<
G%4A9i6%
_oT{M4
l/6}'Q
1TJQJ7
C}":2EE
je}D6P`
)@tH.5
g3Y ^w
Q@c rF
nOmw|@
<'+#=.
A@2-5p
|G\f]KW
r]=W R
'd{:KS|
hyK`IR
zNW*rW3
rr_$Y"9H-
2(@5}
3xYoo)
n99AA}
B.)QF^P
w*~II,
&aqT+/W-
Ji1D?_SQ
[)'-az
epm.5f
%`xO|/C
F}u~Mpz
>f:;0u
kDNu[=
<qu`83J
,sz4fH
=^"l>`
wFs|vK
}0Bb#g#
6SB"E
9oPQl j
a,Vxb
a^mwc4
/E"@vH_
wi&eXW
$)6B,Q
ZJd18:
3k-Ry._4;
U3NAJQ
Shsq,_>
V0p*?oL
;zvMwB
-yXT2L
Y9E%Nm
C=)WR|
`v9/o5
1[[=kx
j$(e@.
$y=W'@
W9e|zg
?ALV[X
Y/Z3lT4*j
$9t%9n
pI&v\CT
hBJ61h}
<#GsFz
Gk+?0lN
L+gv*7
v@MAN%
X5*.p1&
k;[eu)rLO
%v,c&f;
;s"9@F
)Uf9if
>cb7Lmz
>D.\IJh
n?#2_G\
:~o>Oq
XSR8*Z
{;pR5>
}"2X,yl
Iu6#,
oEd#T*
OSs@72]!~Xq
z/wn;)
Wv{SbAw
B~A$L}
~GT%X2
@,M6*f
+2Tcgd"
zZrv%B
fi7v!j
@c%3[e
w*+2w/
J ;0LG#
Wvco&O
(m=+}2
$06u.b`w
3G:K1
YI24;?+
[BLc_]
Q\$4,=Z
$`+bOH
~UQ-GZR
iJ"NvD*
-e*,MV
VHzFMK
Sq,c@'
2T!e*;
^E_4A%
l6LTwii
+]Ni2X
\wXTW7:
tIP+'$
nPpt5!
`lV.*J
SCyF<IcP
=+(k+,
IH`wdS
DxbB/YvE
K~u\x]ci
RnAlV_
xS~@Qd
2ce%Og
&%7lK&I|A
!e==WF
^$:RM
dQ\RJ$
/{,VI]rO
4\q'7qW
("GiKL
}!6J]jA
E]#f"I
9V^&$)Es
j4kOHOI(
pdHc8.]"
boo=\D`}#
Gy=>7&
wg%QiZT
;MiM)d
l|[W:^.
PU9!t"
?I_rl|:,y
Z$|\Ft3
rX/Li3
f*YI_M
^Y7{dp
5 5QV&L
93@ImWB
3F<&:'
tI{u_WE
V[;TaP
wfk:wQ
?|9u?"d#}
YFD2L4
^&SOD7
#Ir-<3
%ZW0Y1'
q` h<#
)T}c[/k2
hrh#U
ZvB(&w8U
0(KI!I
U+^Am-
|6lyrb
^q"N\Hv
eg?:=9I~
J]"z+AMXHy:
3A#vW_Vf
T@h%T_
'f8M6rz
#~v1|*
C3n6DeD
aBo1{]Z)
Tw9v<w
P,Ss'
c7r,*Voe
i79}*u=%R
'u`/'eh
uQ~uUR"
Tt\P}>e-
1]5Vrz'
tDy{>F
dN+/tP5
:p.]+Ms
9rT~Dwd
-=z)9!
X]yY4|S:
KPN-1sH
xz|Fc;%
MY!v'l
@dbQ<M#
,N>`Yk
?<3a}+
'jt/ ;
Yf0/J;d6~
OcwP}.
oXf]3sP
?dvzg
_}9~(@^
zyusCp
peqLlpr
Hw/9YK23
,l$1_5L
7uYj3c
X!@*3z@
z5]S|w
14$E~T
I_G@zM
+=NS&@C
>~I/R
L67Ahi&
n.y@bh
qq^n%8
g_b;rzH
Yl6|y,
sUH[Ly
Y Zviz)
Yg/^Wyi
'&'Y>?
IRKiXq
"fq'e!
8e%}T4
\5,)Wju#
@bn/sn
.WQ$Ln
gZ 1w*
oP(%X0\x
r}@N@G
JQQSN2;
$tYTV[Gk
o|y-}%p
Wg;4fOW
s:m= q
l@qDI0
;#=/n'"
|DP0#H
i=,Dt|
Y2Bi7/
q{uon2
t}h2'ml
L1}@,g
\_V"$Y
&DfRQS
R"[03j
c52:n_
BX/66>n
Bs+DH4
4>@*8zmH]
{BTbNqH
I'(2H5
&/Cup'0
tflQ|$
\aOQ3!i
ACD2R^
WY"UfH
{,La'=e
L-ziY6h
7M@`<\jt
rltp/l
A}sALL
SPJ9)[
T3ngu#V
8Qfb:#
Vr@#M9
2S?D&N
LZ@a?"
|O\N&$)
t_\Opn
A)8\Z!
rfs=*2
9,f/jN
Petjkt
6$"9E0
`Cf^e-S
{\Rdq9`
xq;=kFjL(u@
[7 |SR
<_#<wl
O5EfT;
<(TG&V
gQwC51z
= *;Uh
k;E0wT
@>:@W>G
S\Sl2P!
,1Cp(f
r*!` iI
6O5M:K(
@_g{RQ
nklpBg\
wA/b5.
,'hL!N
aEJFm$
K3Cdi(
0Cg=#r
RvzHJD
U&m:(<
9^@Ym_gt
cA|Y;_
_4!2g!
2H?e_1
*,^Qu/S
J'$ascf@b
o@Pl_$
{ns/"w
ZBKB20
\l9RCU
A?K_hA
<)d}E`
J{ov~CD!:
8?P=G1
p1oypH
e{\Ws[2
F$S.=k
{7"&~N
TmZ'FI
AgBpv"
C$r|gv
%Yl%YT
)J@7NC
ke'Q'a
Qk?w[+
;V\/f3
d-'6<<
gc<7Y/{P
w;C&4?
S/o7t{
Q:3&XlK
/[[u*Rd
N},)Dz&
S]wD8#
J~Y%WBr
e&}dQ-
IiP(To
s`ni#c
Du.F9:
$/551W
i`S-Mm+
Hdc<Z|"
<z[f,,
4z!@owy
r4S)3^
?\d+\z
^BPaYIp$R
7($tB?`x
ake9a<
h[{Tl@
C{/KzKJ
urYGT"
S2{*?T
@Xhm{*
1Fl0V;
EzxM'F
Qy"zZ?
y{">#J!
4agoW
Mc(^vk
jdklg&
E/Ji1P
@>LLT|i
~8d4W5
~<3t&1
~iVF2#
sQPOW[$At
4p\zxR
"v;2HC
kxs}`|
]?'2BB
joW)TH
,ALf]B&O7
g$6$v-
I@LjkA
dtA[0J6T8
|Xcf)tu
,=JDja#Q
p:x\T2
iEK{ym
-~6 2gR
[!XLz&N-
&;@Ihc
7,TL>f
tyoVI|q
n=X\ I
FCkzX6da/X|
lIQb&LI
"z[c:)'
U.>Uzq
^J,&gbS
nF<1km
cK8+& s
>JMz|'k
q^k@$+A
'H'I~/D
PVj9_BP
AFN,w,
%}Mk0u
u*8Q'[
|}mvoT
`C_"L[\<K
z&k)l]
cAN!w7
SzCRY
b<D)'R
[~Z&a"
}+TFZ
L.%@4]
J?R;Y0
W6/@i7?#
`)[^B=
Q5D^SW
.w|u]4
-9yZM{B
b/'=lv]
X<Xbfo
,e'!li
,+c,R\a
hn^p~0*
U'g'Aa
g&%c2FP
CorExitProcess
runtime error
TLOSS error
SING error
DOMAIN error
An application has made an attempt to load the C runtime library incorrectly.
Please contact the application's support team for more information.
- Attempt to use MSIL code from this assembly during native code initialization
This indicates a bug in your application. It is most likely the result of calling an MSIL-compiled (/clr) function from a native constructor or from DllMain.
- not enough space for locale information
- Attempt to initialize the CRT more than once.
This indicates a bug in your application.
- CRT not initialized
- unable to initialize heap
- not enough space for lowio initialization
- not enough space for stdio initialization
- pure virtual function call
- not enough space for _onexit/atexit table
- unable to open console device
- unexpected heap error
- unexpected multithread lock error
- not enough space for thread data
This application has requested the Runtime to terminate it in an unusual way.
Please contact the application's support team for more information.
- not enough space for environment
- not enough space for arguments
- floating point support not loaded
Microsoft Visual C++ Runtime Library
<program name unknown>
Runtime Error!
Program:
(null)
`h````
xpxxxx
EncodePointer
DecodePointer
FlsFree
FlsSetValue
FlsGetValue
FlsAlloc
GetProcessWindowStation
GetUserObjectInformationA
GetLastActivePopup
GetActiveWindow
MessageBoxA
USER32.DLL
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
`h`hhh
xppwpp
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
HH:mm:ss
dddd, MMMM dd, yyyy
MM/dd/yy
December
November
October
September
August
February
January
Saturday
Friday
Thursday
Wednesday
Tuesday
Monday
Sunday
SunMonTueWedThuFriSat
JanFebMarAprMayJunJulAugSepOctNovDec
CONOUT$
bad allocation
wijiwifalipimetibuligijabudidozo fed rolujalajuliv fomij docoxewicudavobinidegamu
Tipit gedo fizayed mizetawovadu yewaxacolitena
Bikoruma fej mebebohudor vem rawuso
Belifocavo buvapetaxan xafuki yov rivifasid
hapawikitozibozipusi dagetegopuwikafox
bazuletodadepuyeviji
kernel32.dll
LocalAlloc
%s %f %c
xewusejixadehayemugaceyanexirohoyayihiperahutusojekavuvo
RSDSLR
C:\malamu\wuxesugukohi\nuyopukoj defexomop53-pu.pdb
SetProcessAffinityMask
WriteConsoleInputW
lstrlenA
GetConsoleAliasesLengthW
EnumDateFormatsExW
FindResourceExW
WriteConsoleOutputCharacterA
EndUpdateResourceW
GetUserDefaultLCID
SetConsoleScreenBufferSize
GetComputerNameW
SetEvent
GetSystemDefaultLCID
GetProcessHeap
ReadConsoleW
SetFileTime
WriteFile
CreateActCtxW
InitializeCriticalSection
GetVolumePathNameW
ActivateActCtx
GetConsoleCP
GlobalFindAtomA
TerminateThread
ReadConsoleInputA
GetSystemWindowsDirectoryA
ReadConsoleOutputW
GetVersionExW
SetConsoleCP
InterlockedPopEntrySList
DnsHostnameToComputerNameW
GetConsoleAliasW
VerifyVersionInfoA
GetMailslotInfo
GetTimeZoneInformation
CreateActCtxA
SetConsoleTitleA
GetConsoleOutputCP
InterlockedExchange
GetLastError
GetLongPathNameW
SetLastError
GetProcAddress
GetConsoleDisplayMode
EnterCriticalSection
LoadLibraryA
WriteConsoleA
CreateTapePartition
GetProfileStringA
WaitForMultipleObjects
SetEnvironmentVariableA
GetModuleHandleA
UpdateResourceW
CancelTimerQueueTimer
BuildCommDCBA
VirtualProtect
GetFileAttributesExW
GetCPInfoExA
SetCalendarInfoA
FindFirstVolumeW
GetCurrentProcessId
GetPrivateProfileSectionW
GlobalReAlloc
GetSystemTime
AreFileApisANSI
CreateThread
KERNEL32.dll
GetAltTabInfoA
RealChildWindowFromPoint
USER32.dll
UnhandledExceptionFilter
SetUnhandledExceptionFilter
HeapReAlloc
HeapAlloc
GetStartupInfoW
GetModuleHandleW
ExitProcess
GetStdHandle
GetModuleFileNameA
LeaveCriticalSection
TerminateProcess
GetCurrentProcess
IsDebuggerPresent
DeleteCriticalSection
HeapCreate
VirtualFree
HeapFree
VirtualAlloc
GetModuleFileNameW
FreeEnvironmentStringsW
GetEnvironmentStringsW
GetCommandLineW
SetHandleCount
GetFileType
GetStartupInfoA
TlsGetValue
TlsAlloc
TlsSetValue
TlsFree
InterlockedIncrement
GetCurrentThreadId
InterlockedDecrement
QueryPerformanceCounter
GetTickCount
GetSystemTimeAsFileTime
InitializeCriticalSectionAndSpinCount
GetCPInfo
GetACP
GetOEMCP
IsValidCodePage
WideCharToMultiByte
RtlUnwind
HeapSize
GetLocaleInfoA
GetConsoleMode
FlushFileBuffers
LCMapStringA
MultiByteToWideChar
LCMapStringW
GetStringTypeA
GetStringTypeW
SetFilePointer
CloseHandle
WriteConsoleW
SetStdHandle
CreateFileA
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{F
_{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{`
d{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{
{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{
{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{Og47
{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{
{{{{{{{{{{{{{{{{{{{{{{{{{{{{{E
{{{{{{{{{{{{{{{{{{{{{{{{{{{{{
{{{{{{{{{{{{{{{{{{{{{{{{{{{{{
{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{
{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{
d{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{
d{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{
{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{
{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{<!
{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{
{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{Yg
>{{{{{{{{{{F
{{{{{{{{{{{{{{{{{{{{{{{{{{{{
a{{{{{{{{{{q
d{{{{{{{{{{{{{{{{{{{{{{{{{{{{
{{{{{{{{{d
d{{{{{{{{{{{{{{{{{{{{{{{{{{{{
{{{{{{{
d{{{{{{{{{{{{{{{{{{{{{{{{{{{{
d{{{{{{{{{{{{{{{{{{{{{{{{{{{{
{{{{{{{{{{{{{{{{{{{{{{{{{{{{
k=_{{{{{{{{{{{{{{{{{{{{{{{{{{{{
{{{{{{{{{{{{{{{{{{{{{{{{{{{{{
`{{{{{{{{{{{{{{{{{{{{{{{{{{{{{\
y{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{
rv{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{
>{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{
>{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{>
\{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{
{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{>
{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{
{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{<
{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{<
{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{
,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,
,,,,,,,,,,,
5,,,,,,,,,,
=,,,,,,,,,
,,,,,,,,,,{l
,,,,,,,,,,,,,
,,,,,,,,,,,,,
,,,,,,,,,,,,,Wo
,,,,,,,,,i
,,,,,,,,,7n
$2,,,,,,,,,
,,,,,,,,,
'>,,,,,
52yu%,
4NZ{n$'~
;7zd$
3RI~wE=
2MSqI,*
GRn3*;~Q
VZ~;).
P_|qA;~
mscoree.dll
(null)
KERNEL32.DLL
((((( H
h(((( H
H
xobudazureri jabep dugod gunuyojigoyicowucomeyacebupef
puhasirukafijoviyozoda yap
Vadajofeb rokima siced
Yokanohufupo kuluhonin lugudabicewu liyonirit
Sipiwaxa
hubupebibigupoxisecuna
VS_VERSION_INFO
StringFileInform
081564b6
InternalName
kogzmuadeke.exi
Copyright
Copyrighz (C) 2020, vodkagata
ProductVersion
99.9.26.59
VarFileInfo
Translation
ADeselopas lavegit kacoj pidure rekipoziyine nur rudezijuk pukulev
hJifon yiwiwoviramojoz guyoneray hobafolo cahelarepipojuv zesusexosok kagewan suwimo huku jacusizodahirag
-Tibotizotumepa jotezagojoxiwiw xucotifupuzeco
Antivirus Signature
Bkav W32.AIDetect.malware1
Lionic Trojan.Multi.Generic.4!c
Elastic malicious (high confidence)
MicroWorld-eScan Trojan.GenericKDZ.76859
FireEye Generic.mg.54f514d1a984a45b
CAT-QuickHeal Clean
ALYac Trojan.GenericKDZ.76859
Cylance Unsafe
VIPRE Clean
Sangfor Trojan.Win32.Save.a
K7AntiVirus Trojan ( 005690671 )
BitDefender Trojan.GenericKDZ.76859
K7GW Trojan ( 005690671 )
Cybereason Clean
Baidu Clean
Cyren W32/Kryptik.EUY.gen!Eldorado
Symantec Packed.Generic.525
ESET-NOD32 a variant of Win32/Kryptik.HLZR
APEX Malicious
Paloalto generic.ml
ClamAV Win.Dropper.Raccoon-9884213-0
Kaspersky HEUR:Trojan.Win32.Zenpak.gen
Alibaba Trojan:Win32/Kryptik.a250542e
NANO-Antivirus Clean
ViRobot Clean
Rising Trojan.Kryptik!1.B40D (CLASSIC)
Ad-Aware Trojan.GenericKDZ.76859
Emsisoft Trojan.GenericKDZ.76859 (B)
Comodo Malware@#1yc52m71ajueh
F-Secure Trojan.TR/Crypt.Agent.ekluc
DrWeb Trojan.DownLoader41.5021
Zillya Clean
TrendMicro Mal_HPGen-50
McAfee-GW-Edition BehavesLike.Win32.Emotet.gc
MaxSecure Trojan.Malware.300983.susgen
CMC Clean
Sophos Mal/Generic-S
SentinelOne Static AI - Malicious PE
GData Win32.Trojan.BSE.FC0O54
Jiangmin Clean
Webroot Clean
Avira TR/Crypt.Agent.ekluc
MAX malware (ai score=88)
Antiy-AVL Clean
Kingsoft Win32.Troj.Undef.(kcloud)
Gridinsoft Clean
Arcabit Trojan.Generic.D12C3B
SUPERAntiSpyware Clean
ZoneAlarm HEUR:Trojan.Win32.Zenpak.gen
Microsoft Ransom:Win32/StopCrypt.MQK!MTB
Cynet Malicious (score: 100)
AhnLab-V3 Trojan/Win.Hpgen.R436162
Acronis suspicious
McAfee RDN/Generic.grp
TACHYON Clean
VBA32 Trojan.Zenpak
Malwarebytes Trojan.MalPack.GS
Panda Trj/GdSda.A
Zoner Clean
TrendMicro-HouseCall Clean
Tencent Clean
Yandex Trojan.Zenpak!CS8UKE284FA
Ikarus Trojan.Win32.Glupteba
eGambit Unsafe.AI_Score_85%
Fortinet W32/Kryptik.HLZT!tr
BitDefenderTheta Gen:NN.ZexaF.34058.zq0@aGC@uqpG
AVG Win32:MalwareX-gen [Trj]
Avast Win32:MalwareX-gen [Trj]
CrowdStrike win/malicious_confidence_90% (W)
Qihoo-360 Win32/Heur.Generic.HwoCueAA
No IRMA results available.