Static | ZeroBOX

PE Compile Time

2020-04-27 16:26:19

PDB Path

C:\vipak36_zahenusakehah\nenexod.pdb

PE Imphash

a84fa8c5c9d81b30cf439f0d2b7f422b

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x00056d74 0x00056e00 7.97302679858
.rdata 0x00058000 0x00004031 0x00004200 4.424144014
.data 0x0005d000 0x0288f258 0x00003a00 0.865440820496
.rsrc 0x028ed000 0x0000c810 0x0000ca00 6.62970541471

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x028f8980 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_ZIMBABWE GLS_BINARY_LSB_FIRST
RT_ICON 0x028f8980 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_ZIMBABWE GLS_BINARY_LSB_FIRST
RT_ICON 0x028f8980 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_ZIMBABWE GLS_BINARY_LSB_FIRST
RT_ICON 0x028f8980 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_ZIMBABWE GLS_BINARY_LSB_FIRST
RT_ICON 0x028f8980 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_ZIMBABWE GLS_BINARY_LSB_FIRST
RT_ICON 0x028f8980 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_ZIMBABWE GLS_BINARY_LSB_FIRST
RT_ICON 0x028f8980 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_ZIMBABWE GLS_BINARY_LSB_FIRST
RT_ICON 0x028f8980 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_ZIMBABWE GLS_BINARY_LSB_FIRST
RT_ICON 0x028f8980 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_ZIMBABWE GLS_BINARY_LSB_FIRST
RT_ICON 0x028f8980 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_ZIMBABWE GLS_BINARY_LSB_FIRST
RT_ICON 0x028f8980 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_ZIMBABWE GLS_BINARY_LSB_FIRST
RT_ICON 0x028f8980 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_ZIMBABWE GLS_BINARY_LSB_FIRST
RT_ICON 0x028f8980 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_ZIMBABWE GLS_BINARY_LSB_FIRST
RT_STRING 0x028f9390 0x0000047a LANG_ENGLISH SUBLANG_ENGLISH_ZIMBABWE data
RT_STRING 0x028f9390 0x0000047a LANG_ENGLISH SUBLANG_ENGLISH_ZIMBABWE data
RT_ACCELERATOR 0x028f8e90 0x00000030 LANG_ENGLISH SUBLANG_ENGLISH_ZIMBABWE data
RT_ACCELERATOR 0x028f8e90 0x00000030 LANG_ENGLISH SUBLANG_ENGLISH_ZIMBABWE data
RT_GROUP_ICON 0x028f8de8 0x00000068 LANG_ENGLISH SUBLANG_ENGLISH_ZIMBABWE data
RT_GROUP_ICON 0x028f8de8 0x00000068 LANG_ENGLISH SUBLANG_ENGLISH_ZIMBABWE data
RT_VERSION 0x028f8f00 0x000001b4 LANG_NEUTRAL SUBLANG_NEUTRAL data
None 0x028f8ef0 0x0000000a LANG_NEUTRAL SUBLANG_NEUTRAL data
None 0x028f8ef0 0x0000000a LANG_NEUTRAL SUBLANG_NEUTRAL data
None 0x028f8ef0 0x0000000a LANG_NEUTRAL SUBLANG_NEUTRAL data
None 0x028f8ef0 0x0000000a LANG_NEUTRAL SUBLANG_NEUTRAL data

Imports

Library KERNEL32.dll:
0x458008 WriteConsoleOutputW
0x45800c EndUpdateResourceW
0x458014 GetConsoleAliasA
0x45801c GetCurrentProcess
0x458028 WaitForSingleObject
0x458030 GetModuleHandleW
0x458034 EnumCalendarInfoExW
0x458038 SetThreadUILanguage
0x45803c GetConsoleTitleA
0x458044 GetConsoleCP
0x458048 GetSystemDirectoryW
0x45804c ReadConsoleInputA
0x458054 GetVersionExW
0x458058 lstrcpynW
0x458060 GetFileAttributesW
0x458068 WriteConsoleW
0x45806c IsBadWritePtr
0x458070 GetMailslotInfo
0x458074 GetModuleFileNameW
0x458078 CreateActCtxA
0x45807c lstrcatA
0x458080 lstrlenW
0x458084 FlushFileBuffers
0x458088 VerifyVersionInfoW
0x45808c InterlockedExchange
0x458098 SetLastError
0x45809c GetProcAddress
0x4580a0 PeekConsoleInputW
0x4580a4 EnumDateFormatsExA
0x4580ac LocalLock
0x4580b4 GlobalGetAtomNameA
0x4580b8 ResetEvent
0x4580bc GetLocalTime
0x4580c0 LocalAlloc
0x4580c8 SetConsoleOutputCP
0x4580cc SetFileApisToANSI
0x4580d4 GetOEMCP
0x4580d8 GetModuleHandleA
0x4580dc HeapSetInformation
0x4580e0 GetCPInfoExA
0x4580e4 FindFirstVolumeA
0x4580ec GetCurrentProcessId
0x4580f4 LCMapStringW
0x4580f8 LCMapStringA
0x458104 HeapAlloc
0x458108 Sleep
0x45810c ExitProcess
0x458110 GetCommandLineA
0x458114 GetStartupInfoA
0x458118 RaiseException
0x45811c RtlUnwind
0x458120 GetLastError
0x458124 WriteFile
0x458128 GetStdHandle
0x45812c GetModuleFileNameA
0x458130 TerminateProcess
0x458134 IsDebuggerPresent
0x458138 HeapFree
0x458144 VirtualFree
0x458148 VirtualAlloc
0x45814c HeapReAlloc
0x458150 HeapCreate
0x458154 TlsGetValue
0x458158 TlsAlloc
0x45815c TlsSetValue
0x458160 TlsFree
0x458164 GetCurrentThreadId
0x458168 LoadLibraryA
0x458178 WideCharToMultiByte
0x458180 SetHandleCount
0x458184 GetFileType
0x45818c GetTickCount
0x458194 GetCPInfo
0x458198 GetACP
0x45819c IsValidCodePage
0x4581a0 HeapSize
0x4581a4 GetLocaleInfoA
0x4581a8 GetStringTypeA
0x4581ac MultiByteToWideChar
0x4581b0 GetStringTypeW
Library USER32.dll:
0x4581b8 RealGetWindowClassA

Exports

Ordinal Address Name
1 0x401065 @SetFirstEverVice@8
!This program cannot be run in DOS mode.
`.rdata
@.data
"u|VVV
VVVVVV
0WWWWW
0WWWWW
QQSVWd
0SSSSS
>=Yt1j
j@j ^V
HtHu4j
s[S;7|G;w
tR99u2
0SSSSS
0SSSSS
URPQQhXs@
0A@@Ju
;t$,v-
UQPXY]Y[
PPPPPPPP
PPPPPPPP
t"SS9]
t+WWVPV
eyB1-,~
ou3F5m
1T8]~#y
\v!Y/kwg
TUF5X?U!
9#H@b0P<
kk"OQr
JUFA_Ep
8gm{jd9_
}YX(ZR
N{Ju~/j
q7G_#8{
T3:KQA`n(
m}xrFv|
NG1MnL
R+Ip}zQ
Vhz7?u
&YYv8-
|5L?Z>
~9?YqI
*)3{]dH
Q2S+JS
a=97<.mk
Lr.fN1
wu"79]~T
u/[9@5
w/m>Z|
1 `^ko
#nY]5
:&|vNV(G
,DQ}`u;j
"4rLu6
sMlV7"a
O5j)$);C_
?2HYZ*E[
}9vL@
Zh-z/tV
vW/PeF
Hb<Ua='&i
9z@ZMv}
;|0jzh
ZY'SKy8NW]
j)(Ce<
}SW^Ggz~
n=6rdb
A?D7S<
(zgFGn
eRGbYW
#$v>}da
MTs8m9
?# dmI
vX(_w8
L~D(pi
nB/O[r
~&e+^,
,c`Y,^.\8
W$Jisu*y(=T-
/_,(BU
FXD&<
c!\A`nMm-)
W{X+uw
wotA~qS
T&:~iy
oJzZv0
AS!h<b
bx@$D1MT
}a:lS)#
(~,DS66
+F{Ivs
z3k[6xw
>8P4gF
h0t1CU5
dReu7v
VxnJ`c
ANjnx)
R;YofV
OO~uJQ
:R3Mz[?
gl}PM,!
I(xg!R
~ge^vc
B.ps>%
qVs3VRULl
.iV#tL
v|`Cb#
yL/A[7
^~QNh,
x]MT1c
4@Pri3g
0k{BdubW
s^z}yn
O1,~^+h@
M&J|[k
u=Kna
<DNG\e
0F!j{IW
dN;l4p*
'B^jGX
x?V~XO
rT(mZ"
8R11}K
'.t|'/
\fDLY+
8L~3r7
E0,"(6
sAoqgS
&\U)\=
nVCB!`
?]bT)wB
{v{YI%I
DmV`/
$0#$#V
J&Z;d9m
3+(H:Q
4kOGy;
9KyWF-
XEf"3*b
OI^]p2J
@xx$w0GI
73}l.6Zk+
#[4\NU
8#sgjU`
Wg8Qe,
zc;w.G
HQg4^[
v[@hUv
~exG}W
6*u~9+
@WO?vU+3
N_^5$P
V.}.(\@
*q*R%(
+BPzjJ
gTu#@
[+;-qyU
5HT/H~
4|,)"Vb
*qU|y"
(.iJ#W
iJ>:HE
~(O\mV
U[R]+vU
s{ sGAP
I?}w{]
E<hc'N0y
\'ybZA
QGs;MTJ
OZ+9Y7
9:-9=N
\LqCB.a
19rR<fp
p&s&Wb
V~"yAC
N$XPfd
Q[E- V
,B}O$X
A6C{aY
v\/}l}E
a7TL"t2UK
8sm8)_
gAdFFc\
!++O:O_
xUo@H.
g8rr!-
4P3^1am
w*e~ov
q<,4-anH
wa%RDkH
!=JD1{
Cc|juJG
C2On2Ax
X%)cVN
:]|5[
K^K16BpL'
B#?'Ps
*|Lu#
F+>;3rk7
g0d-s:0D
mn4bk}qx
lW4H\v
+!T (8
oB9]fs
>3Ic]|
X)kW@2"Kg
8?I8Nw=
"zGe]~fDkZ
XTuc[k
<B>cXsr2
XXraQ^
SX^:W
L`pIO
0;CDki
][,Yyf
X;ju.~.
(D4W-U
/5hoV}
E=*N^=a
kER(lw
)tPDf2
QF^BgJ
onAx?%
q6T[%i
(T_ I~
3zUS{w'A
2U{!fG4
i.]aGc
nRJ~O
qq~O6l}V
AcleKq
w`@p`Y
E)FA+>>
obdaKSMi2
37w3lJ
bue`Az
JqZ$j#
3C)(FI5z
(qL*gG
x\*w6.FCLMy(`
X*L>zp]
%*xSD5L
)(;gZn]J
Yt!09/
:-XWn}
/|=#'TJ
"''en
Z2hJRb
iUmkk?
84)ML
i/4O|"N
a#={}^
+RnqS[
)atzcB
Q#x 1|X
XQ=P='
m#I/>>`
A^8R#)P
/ Fo KgE
xY%F)bq
OTlvn}
$qHON}
$@C=J}|!Q
;q6E"I
4,i5p"
1apb*X
SkR&2f
&Cd)P1
VZlv52
W7x'47O?-:
+?Q!_[
9CQ,K9N
v#KBO.
j)e1cn
yxc+[=
L)cy;%
X>`k*Um
\=>N!=
s3A`Ju
wa:BnZ
@D I84
_Rv!X
_].BS-o
$ T9f#A
#k5Ut_
-OhvmaZ6v\
[-yTMNe
;DH_E
YT@+vg
8z.!=o
X1{)f0@5
l0-7e?
R*M8edY`{
&:c=.
VIK5Y4
/b![r*V
Be4sVWg
pXijp%
XcP~02
Knz_+G
q>H4%V
FnusR_
G"PmsA
|pJ@Cr
|r>6L.
?7T-=4
p2<V\6
`!Lm2oKC
]8`[4:
MsuQAq_
;Fng5eW
H['6a#N
V9szHtZ
C-|x3K
Y*y*K)
hX\w$M
8g4$Sy
*Zmi1G\
Al8+ib
=!u 7N
dg(r}XA
+'|j#B
0XDx47
5:p-e=$
.\>Sz>
D:wPVD
Z>Im\
rviIci
hdn2+t
"8- 93`4
(3"S6Ac{/
_'~m@`
wthA#n?
(g _yL
yg.S?U
#$TtN{
N >Y6e\
ev\@=(_
c^Q6p_
lHAtx\
3[<}44
s#P=Pb
2e"zA>\'
u.?B)j
HGfP@P
zf;xCn
qjB9Zv
lFw {c
c;'R\(AeUy
)JR<2p
$~av j
4x 4:^
SM,vl3
_jkHn[#$
rqg6{sM
t:8sO=U
0H43#)~
$Z*_8_
IdC:vd
!Sv}|Q
CPC<_Z{
L@,sM
0yM4yY
~K`(TO//
~TSqB]r
'%SGKFV
BL/'D8
e[RH-p
@OXy1*
NV(B(+#
ie^B~>PRCKHJ
+ On[o
*UH605
\ &vo/B
-67\j"[
{Ui{%0
XxjBe6
Ls:D=WF
8FU2u-
(b[BW4K
i5b&VJ
$XwMx1N
N+$[TM$?8
3(*\JNo7<Ng
'4sQ6`
vxKC"3
00)q_-s
1^@njJ
^b+MVm
1=uyX
5C/vELg
@[._L=
k=K5F$(
'#+Wn
<+:-?=
;cWc^c
0p3=o/
+<7v7&
4:{v? `
Ms{`'Y
%l]7FO
qnI73lb
rq%{V
SzqkxBK\
BHe,{#
X}A`Fi
Y<!"Rg
mPS+cR}oy":
*#o/NU
=R5pH}
j.L(is
I 34QE
ZbKr1
Bj/3NcZ
La%BUX
WH3EB<a
$`Z~C"
|n*Z,=
W]8 fH
%-KWV>
3egF1?
vI>tUtX
2XuC6k
OljP((?[
Ht<JPNC
$qFM)J6@i
2PxfB2
ZqiLdx~T
_1--X6_x(`
cMxM$[8M
`WNgf`
jz4:~fA
bm!"UF xj9
$~a*;2
a4%d-X
]X?$4
G8n,GQ
Eqf7ny
]We9oG
+vf[$K
<DI2qK
9UwBYn
@R3)D~
LldJu
{ sVTK
EShiV{
<OJLki
u>|#%~
dLiMa,E
g1+HO=
<DQp`ti
z5BKY(52
e)~.VF
RB|,(D
in"(=q
oasN\1i/
=aN&{}
053dX@
&\jIFW[
=Zr\)\
O<'|5q3
K61C3G
fCK<n[
+>FgMh
g_xKVe
<&%hTJ
i:c"l{X
+gn64a
?f=2&YRi
nbh:`g
lS/rv|
lIT-8N}
:o)<a+sUT
:;N:>k
Qn)+3{
Hl6*\X
N(fjfA
D8%5`X
VRO.;kz
c?AAi9
&%%:Um{
8P3_H
K`E.
'$Kxh'
ei#}6(
oba_RG
t34WZ;
SWUy]#
(~OKMa
J[E#(|
#1Un>Ax
^m_P_+
mJq~@B
~G?YQn
~)Dud
275sYo
}RcC'Kr
pq{kD`
{O?HQ<
z4}g?2
{M0GF
k,QT5(I
2y&nfS
cwQmmJ
kgTfu*
IDr2 ^2
0.)Yo:w
Mx8?a%Q
~gmgM\V
^J)Go4
e4q+/9{
oLbJ9V
(Y%q]j
TP8|1I
e3@[O J
Ukd<@,u&
7jn]vU#
JrpLq,Q
\M8M$`
YdW>YH
gror[2
?]YV{l
b~e9lCA
1}2\)uO
Y>Xp\)
_xMsR\j
W4t>pD
*\8qiiT
WX4@"I@
kq\)sSB
mbh`JNEx
.49,5
C7,+&b
7-;Z.t
YtcajJdi
eTYD*o!|P~
!r0b4$}
)e$%uQDy
FN`Rf=
j1ko+'i]
+DGziy
x;$E13
7U'{OBvM
e^CXn6
OXXx6I5
,h"={tpS
K~<iaZ
sNpp_M
W4=n$+
q[%U&@
RDQk66
bEf3wje-
I^!fJf
AZ,rWAu
;:U*#T
p{r4Pl
wo+ES#e0Z
t`;$ v5
{a8,L
FS3ou@
ssEj[,
|%m;2u
bZP$Sv
@%Sg^dO|&
bad allocation
string too long
invalid string position
Unknown exception
CorExitProcess
runtime error
TLOSS error
SING error
DOMAIN error
An application has made an attempt to load the C runtime library incorrectly.
Please contact the application's support team for more information.
- Attempt to use MSIL code from this assembly during native code initialization
This indicates a bug in your application. It is most likely the result of calling an MSIL-compiled (/clr) function from a native constructor or from DllMain.
- not enough space for locale information
- Attempt to initialize the CRT more than once.
This indicates a bug in your application.
- CRT not initialized
- unable to initialize heap
- not enough space for lowio initialization
- not enough space for stdio initialization
- pure virtual function call
- not enough space for _onexit/atexit table
- unable to open console device
- unexpected heap error
- unexpected multithread lock error
- not enough space for thread data
This application has requested the Runtime to terminate it in an unusual way.
Please contact the application's support team for more information.
- not enough space for environment
- not enough space for arguments
- floating point support not loaded
Microsoft Visual C++ Runtime Library
<program name unknown>
Runtime Error!
Program:
EncodePointer
DecodePointer
FlsFree
FlsSetValue
FlsGetValue
FlsAlloc
bad exception
GetProcessWindowStation
GetUserObjectInformationA
GetLastActivePopup
GetActiveWindow
MessageBoxA
USER32.DLL
Complete Object Locator'
Class Hierarchy Descriptor'
Base Class Array'
Base Class Descriptor at (
Type Descriptor'
`local static thread guard'
`managed vector copy constructor iterator'
`vector vbase copy constructor iterator'
`vector copy constructor iterator'
`dynamic atexit destructor for '
`dynamic initializer for '
`eh vector vbase copy constructor iterator'
`eh vector copy constructor iterator'
`managed vector destructor iterator'
`managed vector constructor iterator'
`placement delete[] closure'
`placement delete closure'
`omni callsig'
delete[]
new[]
`local vftable constructor closure'
`local vftable'
`udt returning'
`copy constructor closure'
`eh vector vbase constructor iterator'
`eh vector destructor iterator'
`eh vector constructor iterator'
`virtual displacement map'
`vector vbase constructor iterator'
`vector destructor iterator'
`vector constructor iterator'
`scalar deleting destructor'
`default constructor closure'
`vector deleting destructor'
`vbase destructor'
`string'
`local static guard'
`typeof'
`vcall'
`vbtable'
`vftable'
operator
delete
__unaligned
__restrict
__ptr64
__clrcall
__fastcall
__thiscall
__stdcall
__pascal
__cdecl
__based(
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
HH:mm:ss
dddd, MMMM dd, yyyy
MM/dd/yy
December
November
October
September
August
February
January
Saturday
Friday
Thursday
Wednesday
Tuesday
Monday
Sunday
SunMonTueWedThuFriSat
JanFebMarAprMayJunJulAugSepOctNovDec
bad allocation
kabacekivopadezehibide cisedeyobusegetuvufijoxayuti zixoyivenidabihewaluzofamuniher
daxadediha
vuvuwikoviyihuhobive
kernel32.dll
LocalAlloc
VirtualProtect
zevopucujihocufidiwugucunociwe najidus pecahalogajeripezububed
RSDSZ2
C:\vipak36_zahenusakehah\nenexod.pdb
GetConsoleAliasesLengthW
WriteConsoleOutputCharacterA
WriteConsoleOutputW
EndUpdateResourceW
InterlockedIncrement
GetConsoleAliasA
InterlockedDecrement
GetCurrentProcess
GetSystemWindowsDirectoryW
SetEnvironmentVariableW
WaitForSingleObject
GetSystemDefaultLCID
GetModuleHandleW
EnumCalendarInfoExW
SetThreadUILanguage
GetConsoleTitleA
GetEnvironmentStrings
GetConsoleCP
GetSystemDirectoryW
ReadConsoleInputA
SetVolumeMountPointA
GetVersionExW
lstrcpynW
SetConsoleCursorPosition
GetFileAttributesW
SetTimeZoneInformation
WriteConsoleW
IsBadWritePtr
GetMailslotInfo
GetModuleFileNameW
CreateActCtxA
lstrcatA
lstrlenW
FlushFileBuffers
VerifyVersionInfoW
InterlockedExchange
FillConsoleOutputCharacterW
ChangeTimerQueueTimer
SetLastError
GetProcAddress
PeekConsoleInputW
EnumDateFormatsExA
CreateTimerQueueTimer
LocalLock
EnterCriticalSection
GlobalGetAtomNameA
ResetEvent
GetLocalTime
LocalAlloc
DnsHostnameToComputerNameA
SetConsoleOutputCP
SetFileApisToANSI
BeginUpdateResourceA
GetOEMCP
GetModuleHandleA
HeapSetInformation
GetCPInfoExA
FindFirstVolumeA
DeleteTimerQueueTimer
GetCurrentProcessId
GetConsoleProcessList
KERNEL32.dll
RealGetWindowClassA
USER32.dll
UnhandledExceptionFilter
SetUnhandledExceptionFilter
HeapAlloc
ExitProcess
GetCommandLineA
GetStartupInfoA
RaiseException
RtlUnwind
GetLastError
WriteFile
GetStdHandle
GetModuleFileNameA
TerminateProcess
IsDebuggerPresent
HeapFree
DeleteCriticalSection
LeaveCriticalSection
VirtualFree
VirtualAlloc
HeapReAlloc
HeapCreate
TlsGetValue
TlsAlloc
TlsSetValue
TlsFree
GetCurrentThreadId
LoadLibraryA
InitializeCriticalSectionAndSpinCount
FreeEnvironmentStringsA
FreeEnvironmentStringsW
WideCharToMultiByte
GetEnvironmentStringsW
SetHandleCount
GetFileType
QueryPerformanceCounter
GetTickCount
GetSystemTimeAsFileTime
GetCPInfo
GetACP
IsValidCodePage
HeapSize
GetLocaleInfoA
GetStringTypeA
MultiByteToWideChar
GetStringTypeW
LCMapStringA
LCMapStringW
tuluko.exe
@SetFirstEverVice@8
.?AVlogic_error@std@@
.?AVlength_error@std@@
.?AVout_of_range@std@@
.?AVtype_info@@
.?AVbad_exception@std@@
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
.?AVexception@std@@
.?AVbad_alloc@std@@
D4%}~4#
DRT~y+3
)CD|` ,
2WM~m*7
(AYzo4L{
|-Ez|7B
?T_}u,.}
77O~o*/|
?N|~KX
#9:{c,&
CSO}uGGz~6>
<VarG54~
&SWpC,H}T
.ZI|~/D
&_X}N*3
]b{wF=
c)@AK
5Uunj|
sOO.L!i
,Sq=!k
04p~{3
lHLl28R
6YlD)v
V}|)8MwQ
1Mc;"x
0=lC.}
{7f~~Dm
mscoree.dll
KERNEL32.DLL
((((( H
h(((( H
H
VS_VERSION_INFO
StringFileInform
020564c6
InternalName
sagzmeoloke.iwi
Copyright
Copyrighz (C) 2021, fudkageta
ProductVersion
7.59.22.123
VarFileInfo
Translation
jYakibozeluz pisejovokuhara vutibejeku xilelajo vubicoyozep nap didoxejati yucodar lacobowilu yoyakejugaletTVukuduvehutupi jegijigocox cimomerebewoxag lapuxi sisiwiho lenokuwi mapum dojutokega'Dis nupuriyohuzi latovayufeh hilaxecayeJFininawadic midenabuhucuje yix wodiwixus cax totilesuro laretagol jujopeji
Cijociy lamucom
Cajo zuwetipekeholu
Roxaxufeled
@Hudowav bekopikosa pora bavu wudu poluhuxa balelibetale zisovuciUNunaweseli waviyur hazec zoted xibujevu wuvufewireto nogoroguyopu bukohudejux pabahubZFobamogupuxahu sojo sixinuwixode cocinumemeriwo luwisuxota cetomosocibam tovade xucivinizaSWamilekuciyi suxupekomedox rad dejilaba desiginebi hemuco rivizozeja gali lulobukegDGexavadenos vonowo segega musojikecopahi niguruseregisas joba guvidaEVok fizisumelo fosomacokawoli kiziwihaxexawe gigejodimilafe rera yehubBiyilijogibe figalonevoliro pubi jawiwurafec bohaka fuvayeyopesov ruhasime lipuraxu sogurakulexuhu
Antivirus Signature
Bkav W32.AIDetect.malware2
Lionic Trojan.Win32.Zenpak.4!c
Elastic malicious (high confidence)
DrWeb Trojan.DownLoader41.20698
MicroWorld-eScan Gen:Variant.Fragtor.9685
FireEye Generic.mg.fc316a48dadfc20e
CAT-QuickHeal Clean
ALYac Gen:Variant.Fragtor.9685
Cylance Unsafe
Zillya Clean
Sangfor Trojan.Win32.Save.a
K7AntiVirus Trojan ( 0056f9be1 )
BitDefender Gen:Variant.Fragtor.9685
K7GW Trojan ( 0056f9be1 )
Cybereason Clean
BitDefenderTheta Gen:NN.ZexaF.34088.Aq0@a8@L!Iki
Cyren W32/Kryptik.EWJ.gen!Eldorado
Symantec ML.Attribute.HighConfidence
ESET-NOD32 a variant of Win32/GenKryptik.FJHS
Zoner Clean
TrendMicro-HouseCall Mal_HPGen-50
Paloalto Clean
ClamAV Win.Packed.Fragtor-9887412-0
Kaspersky HEUR:Trojan.Win32.Zenpak.gen
Alibaba Clean
NANO-Antivirus Clean
ViRobot Clean
Rising Trojan.Kryptik!1.D8AC (CLASSIC)
Ad-Aware Gen:Variant.Fragtor.9685
Sophos Mal/Generic-R + Troj/Krypt-W
Comodo Clean
F-Secure Clean
Baidu Clean
VIPRE Clean
TrendMicro Mal_HPGen-50
McAfee-GW-Edition BehavesLike.Win32.Generic.gc
SentinelOne Static AI - Malicious PE
CMC Clean
Emsisoft Trojan.Crypt (A)
Ikarus Trojan.Crypt
GData Gen:Variant.Fragtor.9685
Jiangmin Clean
eGambit Unsafe.AI_Score_89%
Avira Clean
Antiy-AVL Clean
Kingsoft Win32.Troj.Undef.(kcloud)
Gridinsoft Ransom.Win32.STOP.ko!se5276
Arcabit Trojan.Fragtor.D25D5
SUPERAntiSpyware Clean
ZoneAlarm HEUR:Trojan.Win32.Zenpak.gen
Microsoft Trojan:Win32/Azorult.RT!MTB
Cynet Malicious (score: 100)
AhnLab-V3 CoinMiner/Win.Glupteba.R438187
Acronis suspicious
McAfee Packed-GDT!FC316A48DADF
MAX malware (ai score=86)
VBA32 BScope.TrojanRansom.Blocker
Malwarebytes Trojan.MalPack.GS
Panda Trj/GdSda.A
APEX Malicious
Tencent Clean
Yandex Clean
TACHYON Clean
MaxSecure Trojan.Malware.300983.susgen
Fortinet W32/GenKryptik.FJHN!tr
Webroot Clean
AVG Win32:PWSX-gen [Trj]
Avast Win32:PWSX-gen [Trj]
CrowdStrike win/malicious_confidence_100% (W)
No IRMA results available.