Static | ZeroBOX

PE Compile Time

2021-02-05 17:08:06

PDB Path

C:\diriwotif\mas\serov-mij.pdb

PE Imphash

c4966332d8b4d65c8c07803cb5fb54a5

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x00084150 0x00084200 7.98145327567
.rdata 0x00086000 0x00003504 0x00003600 4.18813817886
.data 0x0008a000 0x01d1cc00 0x00001e00 1.33014353593
.rsrc 0x01da7000 0x0001f3d0 0x0001f400 6.5702085923

Resources

Name Offset Size Language Sub-language File type
BOLAWACULATOREGOWAVOVOSIXAZIWEMU 0x01dc1488 0x000021af None SUBLANG_DEFAULT ASCII text, with very long lines, with no line terminators
RT_CURSOR 0x01dc5060 0x000000b0 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_CURSOR 0x01dc5060 0x000000b0 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_CURSOR 0x01dc5060 0x000000b0 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_CURSOR 0x01dc5060 0x000000b0 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_CURSOR 0x01dc5060 0x000000b0 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x01dc0fa8 0x00000468 None SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x01dc0fa8 0x00000468 None SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x01dc0fa8 0x00000468 None SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x01dc0fa8 0x00000468 None SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x01dc0fa8 0x00000468 None SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x01dc0fa8 0x00000468 None SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x01dc0fa8 0x00000468 None SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x01dc0fa8 0x00000468 None SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x01dc0fa8 0x00000468 None SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x01dc0fa8 0x00000468 None SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x01dc0fa8 0x00000468 None SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x01dc0fa8 0x00000468 None SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x01dc0fa8 0x00000468 None SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x01dc0fa8 0x00000468 None SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x01dc0fa8 0x00000468 None SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x01dc0fa8 0x00000468 None SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x01dc0fa8 0x00000468 None SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x01dc0fa8 0x00000468 None SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x01dc0fa8 0x00000468 None SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x01dc0fa8 0x00000468 None SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x01dc0fa8 0x00000468 None SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x01dc0fa8 0x00000468 None SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x01dc0fa8 0x00000468 None SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x01dc0fa8 0x00000468 None SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x01dc0fa8 0x00000468 None SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x01dc0fa8 0x00000468 None SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x01dc0fa8 0x00000468 None SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x01dc0fa8 0x00000468 None SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x01dc0fa8 0x00000468 None SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x01dc0fa8 0x00000468 None SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x01dc0fa8 0x00000468 None SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_STRING 0x01dc5f40 0x0000048c None SUBLANG_DEFAULT data
RT_STRING 0x01dc5f40 0x0000048c None SUBLANG_DEFAULT data
RT_STRING 0x01dc5f40 0x0000048c None SUBLANG_DEFAULT data
RT_STRING 0x01dc5f40 0x0000048c None SUBLANG_DEFAULT data
RT_ACCELERATOR 0x01dc3638 0x00000038 None SUBLANG_DEFAULT data
RT_GROUP_CURSOR 0x01dc5110 0x00000022 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_GROUP_CURSOR 0x01dc5110 0x00000022 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_GROUP_CURSOR 0x01dc5110 0x00000022 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_GROUP_ICON 0x01db43b0 0x00000068 None SUBLANG_DEFAULT data
RT_GROUP_ICON 0x01db43b0 0x00000068 None SUBLANG_DEFAULT data
RT_GROUP_ICON 0x01db43b0 0x00000068 None SUBLANG_DEFAULT data
RT_GROUP_ICON 0x01db43b0 0x00000068 None SUBLANG_DEFAULT data
RT_VERSION 0x01dc5138 0x000001b4 LANG_NEUTRAL SUBLANG_NEUTRAL data

Imports

Library KERNEL32.dll:
0x486008 SetLocalTime
0x48600c ReadConsoleA
0x486014 GetCurrentProcess
0x486024 GetUserDefaultLCID
0x486028 AddConsoleAliasW
0x486034 EnumCalendarInfoExW
0x486038 WriteFile
0x486040 ReadConsoleInputA
0x486048 lstrcpynW
0x48604c FindNextVolumeW
0x486050 VerifyVersionInfoA
0x486054 GetModuleFileNameW
0x486058 GetACP
0x48605c GetConsoleOutputCP
0x486060 InterlockedExchange
0x486064 GetProcAddress
0x486068 PeekConsoleInputW
0x48606c GetComputerNameExW
0x486070 VerLanguageNameA
0x486078 HeapUnlock
0x48607c LocalAlloc
0x486084 GetModuleHandleA
0x486088 QueueUserWorkItem
0x48608c HeapSetInformation
0x486090 GetConsoleTitleW
0x486094 GlobalReAlloc
0x486098 LCMapStringW
0x48609c PulseEvent
0x4860a0 GetCommandLineW
0x4860ac GetStartupInfoW
0x4860b0 GetModuleHandleW
0x4860b4 Sleep
0x4860b8 ExitProcess
0x4860bc GetLastError
0x4860c0 GetStdHandle
0x4860c4 GetModuleFileNameA
0x4860c8 TlsGetValue
0x4860cc TlsAlloc
0x4860d0 TlsSetValue
0x4860d4 TlsFree
0x4860dc SetLastError
0x4860e0 GetCurrentThreadId
0x4860e8 TerminateProcess
0x4860ec IsDebuggerPresent
0x4860f0 HeapSize
0x4860f4 SetHandleCount
0x4860f8 GetFileType
0x4860fc GetStartupInfoA
0x486104 SetFilePointer
0x48610c HeapCreate
0x486110 VirtualFree
0x486114 HeapFree
0x48611c GetTickCount
0x486120 GetCurrentProcessId
0x486128 LoadLibraryA
0x486130 GetCPInfo
0x486134 GetOEMCP
0x486138 IsValidCodePage
0x48613c MultiByteToWideChar
0x486140 RtlUnwind
0x486144 HeapAlloc
0x486148 HeapReAlloc
0x48614c VirtualAlloc
0x486150 WideCharToMultiByte
0x486154 SetStdHandle
0x486158 GetLocaleInfoA
0x48615c GetStringTypeA
0x486160 GetStringTypeW
0x486164 LCMapStringA
0x486168 GetConsoleCP
0x48616c GetConsoleMode
0x486170 FlushFileBuffers
0x486174 CloseHandle
0x486178 WriteConsoleA
0x48617c WriteConsoleW
0x486180 CreateFileA
Library USER32.dll:
0x486188 RealGetWindowClassW
Library GDI32.dll:
0x486000 GetCharWidthFloatA

!This program cannot be run in DOS mode.
`.rdata
@.data
PVhDtH
u&VVVVV
uXVVVV
VVVVVVV
HHtXHHt
>If90t
j@j ^V
>=Yt1j
QQSVWh
0SSSSS
0SSSSS
0SSSSS
0A@@Ju
URPQQh u@
^SSSSS
j"^SSSSS
0WWWWW
AAFFf;
PPPPPPPP
PPPPPPPP
t"SS9]
;t$,v-
UQPXY]Y[
t+WWVPV
d>hO`%
Ynx~:&A
5BHAlU
*(IQY<(0
GoVK{K
AbmZ}p
)k)W 4J
IRX1*b
tg;Rf@A
\J3)\.N
{290f~
_, AV7
YZ:o14~/
;"h,SJW?
7uVcm(#
$hjkpQ
18Z`X/{
'nC[}q
M(2md$
D9a4uQV
u^f kW
d@T*]e
B#b;$6
0hY+rb
K`RWa1
0NW,>ac}b
owOPc
'b}(xx
"G}B6@hA
vSscJ+
iBlcz1
=g%Hemt
qGsIYO
&rr*(p
J`f6xl
!]QuI\
:+z%.\D
0J5~5L9A
6O\Au(
C8|~l=%6
";;S%]
vgRYI]-
#&k0$sk1
>Z<^`q)
hp-\:M
8S;M=b
+4]Ww9
]OBjx6
A`}Tk`
+f)^aN
|"&,(m
jr=@SjQo
zcPM6.
K6j2p[
@Ir;{H
=1X:4
'uK`m_
?XR_5Y
o:%&4n}Z
YBcd^9
[tW?ur0
|nYxE1
ppJGS/'
zjv`Sp
UzI^Rv
%]]ZyGhd=
sM^a!@r
fQ2ntW
k@%~Hg
f JDkd
2&RCF<m4k
6dwylCb
rbGFQP
:<*~'h
T:b#Ot
;vp"*W8
D-]U>C
f8m)>
8|0P@d!PAzp+
(AyP~!
1\6}Uay
56t]bo.
$k?l4}
{J]:u@{
}6vW*
Ue<zZlI
Z/lW/g
7ei?AiV
yM[S4
f\_Y_a
PHav0%
y5l#%4
c:1(-S
_^HK,1
{}l\;v
Sgt:]W
c*$3G&
T~&!_]j
2Iemt:
&W<~pp
Q!Qs@V
2V~CwV
gUWk!_
hhuG+5
5HcY#f
~V@Z?j
rp.Y!Z1p
Qu4Mj/
8|*KId
4hCRM,n
/C`^Tl<9
PLter1
FE*a'?
nG2i }
jRKoO+
Li c3
"?6J~JU
TLLKHc
C_pQF?
{!Lg@o
{~jq,K
YewgV?
ZY@.6!c`
~?L IhW
{k<,U|
#)MoT!q
/{9roT
]F|{d}
TMC.S$
BYuh:]*z
RX2'@7
x|!}#3
oPMa~
hu,Oi4
~)Hmwp
nJxcXY
H</_+VI
9S@cj)
x9pIX!
tK4[G$Ez
SACHKR
8opL&
Z5U^5,
;z{Ilr+
ObuT9@Y=
`CSVG4Hz
bfZjK,
@cD7r8H
%^6B}.k-
td#E s
33IEgJ
+'WZK}vW
hB0.C@
W@FW-j
#2^ X4
j!9ew_
y&t=Y&'!
Rc/=B%
~W1-#%
fvG-&p
Vil/D,<W#=
`J@?b`
.-EBz:
2^jw)5
-`6dEl
@Q*oa
kA7?q%
QL>.c
.r|(Z:
VSES)>&
ik!&c9
Rj4iQ-
3(j^aB
UyWiHS
9baj>7|m
~/R>]aJ
udR!$7W
JaetN8
l8va7(o
VQDo[wW
q3!(gX
d/-4XJb{d
@w#b~D
GW2P<"
jEP:Gn
&cjMa1R
Q{c<:^
4JsE6>
fJ6M34
$2`gvy(jU
<k-B^s
>qnP1J
/"/D~6$
nU=ZE?
7m'CUo
8a[);
K6}z`_%
RpZyfsfr
>7 F\p
FA\q>,=nW
MyS'17R
Zh,yzb
8$eu<
Jh\3i9f.u%*
}$|LJ N
@.Ba];
VZkSj7
G\xbN=
$C`16m
w+gA?L@g
ka~/ZP
p!h[&\
(EOBPb
Fj+M:3
al"ZgC
;O:M#|
jl.R!)G
;;'B'$
|k4.HJ
0DAkWY
K$&IF\
Ba?[@M
-(X4Dd.,
m3-aaA.
p_\N{>
rJ>?x)
$7`0"6&
,Hx]\Nv
W[-mO3
gfW7)
cB&f<c
Ej=Wx&
q8vIy+}
|Srs%n
9kn/%K
d_D>CNoU
\[bime
4v#`By
Ca^i]z|&`c_EWr
5zx<<a
Z-{SFt<
nMgwX=$
\ B}"C
*%D\^98
bW:JQV
Gs}U^o
[FU2A m
~\)!PwF
';_K,Z
vAXMm{
!6WW8c
2a@yX{
?)=A2J
u9\TCKE
~&~+XF
`G|^A~
B*Pm76
|APS4i
!/_~Ww
(W/VO?
X=l\=|
}EX}BI
\k^\9@Y
Ozq4T3
-n"/%
Mo=WNm
*UU7_
lS!,Zb
CQ<F`*
s]=u%F
DA|X\
V (](bK*
$>v\F]
TZGhN-
^*Cv'{
t`#S(sH
czv2~0
(5Xeyl=
twB+I((
,$5 Mu
g#8jH)
Ad06L;h:R
yZ8pCDp|d
Z^BIX[
-S\#AZo(
DEdoEV
*;%Q21
{`lUK'
wi3xn}&
$V"0}
Czqlzs
4sdr(:=i
UQ8~Oh
/`1s[u
8h3[|'
"xgVm4+C
.Z<oLPZ
K-[TVs
,M)UWj`
LU"8:X
V$BF-d
zDPOol
Z&At*O
<Cd[fy#
W/\`)^&
~Y.>$o
.e4@Fy
.d3P_xo
'NzyOa
pNZ<@qD
JTmxI(
YA0{:P E
2nd]Ef
)?;Pd@,
7N<RZ(
$#hC2#
(x#w/i
dN(z6]
%2:q}|
yJS~Ree
.<RDzz9
o`JM`A
|SRYt%
W'0V>=]
loACa@!,
A%QOv%G
E;U}o{
e&(lt&%
<hR[$97
FpalA*
?J8R)K
_?i^*B;
S$(]wy
G?1\HQ
;gFR7e
EhL>Nw
yl"oLdJ
UxL.hJ
k:Jxt(=i
-O>SOn;
m/JRj_
f)'4e"wJ+kb`}T
^-`Q<8bF_p;
00z'547
b'k$[Gc)
"/XfUD
|/mCi~7
7\mQED
)s6=n4
.N=-C$
":$W9
nd.[Hfm
](A%Od)
ySZ/nEv
;<K]{]
iE3]nE
?_{QT
DPgoaeH}
%B|5PV;
k37L\K
uAMjWR
gjSad
T. ^{0
lE3/,I
n"bfI
;%{a`D
Gir+r-m
/J7%zx
Y<c1+w
[UpBY*
X;"~;)Ya
F]d45>_
oSN.HN
z3(wpKL
X9O" |
4+1)d6
!S/qx7hp
Ily5un
"3~Myf$
R2s}jFK<0 x
JIG=HKu
f?jr3=
)j4-EU
Vl/D{Q
IfY(.~p
Ox<p#N
{s%P}.
`^kCe1g
"=ta]e
^3&Lu
w'uQid
1l +84
5{>Myq
iq9/a\M
(2qIJ(E
%,P~xoI
TI.hb
Q\rA?hF
xhz<Qr
#RK4'=L
#3'F1go
I6y9*I
mZVHy"M
'ZhC3"V
taWxpJH
?{u8nqu
>43M!G
nUM2Nq
pIsZ@_
5#,l\P-:ci
0w^+DMa
I<+l$Q
os>o,c
ss12TO
U @C
hd.I;J
!httb
j1[7Fu
4Nt}o/
rny8r8l
y(GybG
G1?Qg/
?#wcet
h2WSX2
ga9koq
L.a55>_
yVdJ9f
4aU'7mD;
L=OavF
tcA"*U
]:`R G
cS?b,M
}[KF55
V8PH"m
Q`t(Fi\
;~E6/
XYwq,x~
?q9X_,!&
Lf2<-@:
oX}xvr
Dbd|,A
k&\==U
}U4ADq#
2>NglD
/h-)x3
YQV;OG
zQUMA*q
)<V^0a*@
G8JDaJ
XpkhB&\
~M?l_*8
F9>GF$
KkSR*A
Nl+}Zp
AOd#$
^5Zb6u
no|:nD,
A$BoVzm
r;pqyw
]C>qYT
Ykquxr
xJ&&LO
!dGA-~
FU!V<
Q<Cd4/4dG59J
`QY5sP
+\%>U&
a7sw&HSk
8qoO;`?
h^8whF@
hH^3k
"T.qxn
q,A6v7H
-b_\2|z
4!'wQn
np?x{D2
HB] .g
q/f;L)v
DR09l&
lX@r=w
6]d+NR
g"w4a9
P/n*X<
H7oI4+2a
RD{JXE
1;F:wb
WYE}R6
c@,g{i
G[3LhH'
`.+jGGe
6(&5Bx
zYOy)~
6=aX7qj'F
*|@u/X?
12oK=p">
K4!1n@
U+=xl'
Z E4+e
^4EQ/_Y
M#Jp&d
LXkMFY
vb$3xAA0f
/QHGRW
A9wCH;
wOXXI<R
BN&+:/
OI?3r:$1
2Jw9rm
C{*j.L
D[6T"
ZxyTO&
]@Hk.^t
ik:!%Tr
]Y8ibdz"
[z-tlQ*
X=\'uz
G}}Uylr
G0M;&!%
IJp:CsSS
McY<Kn)
,G@@1[
9b3pcs
>'l<v2
.vgSnS
M^u-Mxy0
37:\?]
9Eh7XI5
E42qIU
7uBViOt
(?kSHJ
UI_ Rh,
V(@M[J
Wr5n\B
H-cC,'^}
^2O`O~X
eY9uaw
.Vaf7Ha
ZE%sfV
bNqeW!-
F$GR%<Lf
I]/w90
33 T?;k
Uaa\6)
4W[@=fLb
J(C,0Q>P
@uT`B8
wI|*q(
~iUL_P]L
?d3xer0-
v.|xUj
C}zqF?G
/Vg'^I
t%E)DS
3P>UtwG
$OgJn`
GbOOlJ
X<oD90
(Ayv(L
^S0wLbV
8^pu@M8(6
A_L,f;=R'a
('rJ~1
J6M~=h
eqzFpu
1m^|3r
46<y5o
v"@@(}A
J}Ve_}
'(XCE+JR$'
DX5${P
cGJc=y]
?o< QF(
KX*lT7w
hm/A6Y
Bn7=/ u
,LP_?SOo N
}U7r0X
Zsk\|]B
uNiJ'I
r-A]MG
^hY6T&"
oJrbXo
/^jk~}
hazJ.e
h4CkF's
dN3Ntw
OP^9N?`
nU}b%^s1P
DAqWb
"lIHW.
k'$)02
4DxpDBq
,o%&?R*
K9G`JXd
.S>W;B
l|{&1h
w|n-zoPV#:LE
R%<P,a@TOu
nfGNc0
8#e0qH
a>z.`ND
Gxpkm3A
f"c{)Y
_OWmL5
vuj4Fc
x*\{Zf
sfz\HQL
A[:DrU
98`}!&
G,fck:
)Vz;9t
5|9xkb
!*[Cv
X<NrAX7
YH@c@}4
\bdb-{
aQ]dv&|D
}nRu=q
ONstie
cZ:{m)K
uv2}Fi
)XRf:`
rFi@Xo
e4Chz0
z&~g]O:
w7{\YI
GAx^bIN
S.0])~S7
{|$X8<
"kHOU"G
A&ohq*(
^avz6GX
;l!+s
2K9@{X
w<h"e]G
}ft(9Y
D9!xO0
yTx7M-~
I4a_WY
DMLa2TPf#C;
_luJ)"
NN,:VDxH:;
N/I#qt
eK,sv'
MN(pQ#
X21`Mz
1IgXG)
S\:,?-
A+m\%kt
vV\dAre
g)*\tJ
H"$b[6(-{
*=|OZUV
h\|rA9 B5
y$Ok$L
rypH({
;Q@e d\
AufhI
0"J|\:
Uz6Mun
MA 39I
ICjSpN
D8?A IB
3^*igA
["X5&F
otHz8Vw2
L{rR30
hUM?4ds
Td9-*U
v96,>J
1O^hN@
/JL!Pb
HF`)P48
oKyD34
;qm5Lu
N%F*=I
}rkcJg'U
z.8g~E
wD/Wuzm
}hqPzg
:xvEa;
U`e~J*
ygsWKH
4oYsb/ <
j7Vaei|U(*
'80s0G*+
,sKlG#j
`)~xL#3
U8Xrnu
yF[[D3,
0vFbiu_\
!\DJ%o
Fk(nI.
\MV]Ea
{iV3vT
_EqQvT
x?baUl
BUtv^q(
ozjqNW
L=<<4I
P/ T_@E
,8>ia!L
)(<:bP
JL|rq:
J;v.DS
.A*kS%
UFHy!q=
Z?hs2b
i5@)V0
Bb)*KE{
7).pjC
9eru!j
]E}zpJ
uG3nzV
c*:4 +
B;(jqxR
gbI<(rqN#
c[RZ>cJt9
Qxc&NY
uhV:rt
BdQ|#!wx
FOxySX
!Ut>4qb
%T?~~`
TGK(`1p
,qRXSm
;9@LTD
e#c.QCx
A~R%RE
3[1e>r
;'u,f~
Sh3uR9tL3
U;ujl,.
FWeWD[L
@~=});!
O0pp"Q
>Xk%bm
(yr,lI
dFVa.D
tYGTNQ
c1%soKL
)ewGYA
X7534#
2hOG$>
2`ix2ELG?
?!Z7<8
~re#V)==
,A:a/x
5&FqEkK
cKSI9"](}
gmc1TZ
UOi3Y!
%#5-K
h|[O}X
~3`U+x
?n~_#+nq"
ue*-X(I3
v.^Mf51
v."@6(
Lqs;-G
vH{V|Z+$H)m
GxR4qx^
a?TsJ.
:Bo_`_
dLJdC|
A:chr
U,2.BZ
SP-g"UcK
0m\vy_O
uJF/_f*
WY)h<@
)Q,HV-o
/vu,t=
Hn@Fqz";
'jt=T`
5ZpEaJ
v+g"y{
6|>b<q
rxKw;I:
bX?)0!
)z+7j)
TJVB$C
8[JqyH
AUc0?2
f! *5`
sXMg`[
M|"rXG%
]Yed;a
ibD>Ai
AGaJ^!
~YAc%,
BB)d"<|
@ro3u<"
{*KBeT
9<[D<q
kk|uu\
:&i'=U
PG,Dhl7
BwoEF/
dp9vFiq
Fa(qck
O$J$}w
_kwy?C
T_d(rGwC
\IS!yFzZk
0+bHv>
4-`R~(l4
?:"hpT
'R*ni0
AgU+hz
yU#o(j
FL$50+*
"VcRlt>
>odlbJ
'<CYh_
},<R6U
x^E!8[
F>SI3HH
Ot>_[=
rG<PK$
xJP9-<
SGC((u
+rM^)N
>-tt!z
oJfcYe
a?&cKw
Qmo?<T
"PTiL[
6PT(~&'
;.om80
KP0q@(I
N{y-3+b
dw3+6g
}@s=n?8j
"Lb%xM
~k5gz
d3UOp;
n#.P40
dgF8+a
Ue;%3{
m4q-=y
&qvH~|Q0
2R4L[(dsL
U"/s5j
6]f=B9
odi>/t
JQZrN
o*J!kh
BACPT
3OpCXR
zp8zj&
=qN%^}+2
4@_/W$
zB7/n
xWw& 4h
04KW|`
q"1gZ@-
e|~J"EA:
qxP%f^=
yDw"kS
,6bMef
N-El2w
f*L&@u
u3(7wa
uTCt4'
enp?Rt$
CSz,dH|
!VqFN|`M
(%k~1P
^J?K,_
SYiEno
sA],r!
1\Q9FUH
4)xIP
'\/L"~W
F'16J*
|YlhJ?
]'5Wsg
_yy76
hQ[t$B]\
C9d<?o
VEcAJ
!WQ:Ltc
<b8_5C
aTt;|{N@
XpYge2^
dM9zlp
#{u3@i
3BIkUP
_ZlXN
fL\~(9r
K7#d7bi>0
:W'+H>r$D
yzV"B!
J+%$e[].
B/_-{4
z*/|!k
!,m-yx
awXad~
H>*7\H|B$E
CorExitProcess
runtime error
TLOSS error
SING error
DOMAIN error
An application has made an attempt to load the C runtime library incorrectly.
Please contact the application's support team for more information.
- Attempt to use MSIL code from this assembly during native code initialization
This indicates a bug in your application. It is most likely the result of calling an MSIL-compiled (/clr) function from a native constructor or from DllMain.
- not enough space for locale information
- Attempt to initialize the CRT more than once.
This indicates a bug in your application.
- CRT not initialized
- unable to initialize heap
- not enough space for lowio initialization
- not enough space for stdio initialization
- pure virtual function call
- not enough space for _onexit/atexit table
- unable to open console device
- unexpected heap error
- unexpected multithread lock error
- not enough space for thread data
This application has requested the Runtime to terminate it in an unusual way.
Please contact the application's support team for more information.
- not enough space for environment
- not enough space for arguments
- floating point support not loaded
Microsoft Visual C++ Runtime Library
<program name unknown>
Runtime Error!
Program:
EncodePointer
DecodePointer
FlsFree
FlsSetValue
FlsGetValue
FlsAlloc
(null)
`h````
xpxxxx
GetProcessWindowStation
GetUserObjectInformationA
GetLastActivePopup
GetActiveWindow
MessageBoxA
USER32.DLL
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
`h`hhh
xppwpp
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
HH:mm:ss
dddd, MMMM dd, yyyy
MM/dd/yy
December
November
October
September
August
February
January
Saturday
Friday
Thursday
Wednesday
Tuesday
Monday
Sunday
SunMonTueWedThuFriSat
JanFebMarAprMayJunJulAugSepOctNovDec
CONOUT$
bad allocation
tayevupejalesexud
kernel32.dll
LocalAlloc
VirtualProtect
C:\diriwotif\mas\serov-mij.pdb
GetCommandLineW
PulseEvent
SetLocalTime
ReadConsoleA
InterlockedDecrement
GetCurrentProcess
GetSystemWindowsDirectoryW
SetEnvironmentVariableW
GetEnvironmentStringsW
GetUserDefaultLCID
AddConsoleAliasW
SetVolumeMountPointW
GetSystemDefaultLCID
EnumCalendarInfoExW
WriteFile
GetEnvironmentStrings
ReadConsoleInputA
LeaveCriticalSection
lstrcpynW
FindNextVolumeW
VerifyVersionInfoA
GetModuleFileNameW
GetACP
GetConsoleOutputCP
InterlockedExchange
GetProcAddress
PeekConsoleInputW
GetComputerNameExW
VerLanguageNameA
CreateTimerQueueTimer
HeapUnlock
LocalAlloc
GetDefaultCommConfigA
GetModuleHandleA
QueueUserWorkItem
HeapSetInformation
GetConsoleTitleW
GlobalReAlloc
LCMapStringW
KERNEL32.dll
RealGetWindowClassW
USER32.dll
GetCharWidthFloatA
GDI32.dll
UnhandledExceptionFilter
SetUnhandledExceptionFilter
GetStartupInfoW
GetModuleHandleW
ExitProcess
GetLastError
GetStdHandle
GetModuleFileNameA
TlsGetValue
TlsAlloc
TlsSetValue
TlsFree
InterlockedIncrement
SetLastError
GetCurrentThreadId
EnterCriticalSection
TerminateProcess
IsDebuggerPresent
HeapSize
SetHandleCount
GetFileType
GetStartupInfoA
DeleteCriticalSection
SetFilePointer
FreeEnvironmentStringsW
HeapCreate
VirtualFree
HeapFree
QueryPerformanceCounter
GetTickCount
GetCurrentProcessId
GetSystemTimeAsFileTime
LoadLibraryA
InitializeCriticalSectionAndSpinCount
GetCPInfo
GetOEMCP
IsValidCodePage
MultiByteToWideChar
RtlUnwind
HeapAlloc
HeapReAlloc
VirtualAlloc
WideCharToMultiByte
SetStdHandle
GetLocaleInfoA
GetStringTypeA
GetStringTypeW
LCMapStringA
GetConsoleCP
GetConsoleMode
FlushFileBuffers
CloseHandle
WriteConsoleA
WriteConsoleW
CreateFileA
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
484848488
884844
="&::"
:$,[=S^
:,$,W8
e3ps}P
%z{|M{}t
ab\2y{
HHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHH=D
HHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHY
HHHHHHHHHHHHHHHHH
HHHHHHHHH
HHHHHHHHHHHHHH
rHHHHHHHHHHHHH
HHHHHHHHHH
HHHHHHHHH:$
HHHHHH
X`IIVV
Tf(__J
HHHHHH
HHHHHHj
HHHHHHHD
HHHHHHH
HHHHHHH~
HHHHHHH
HHHHHHH
HHHHHHHHH
HHHHHHHHH=
HHHHHHHHHH=
HHHHHHHHHHHHH
HHHHHHHHHHHHHH
;HHHHHHHHHHHHHHHk9
HHHHHHHHHHHHHHH=9
rHHHHHHHHHHHHHHHHH
HHHHHHHHHHHHHHHHH
HHHHHHHHHHHHHHHH
rHHHHHHHHHHHHHHHHHH
HHHHHHHHHHHHHHHHHHHM
(po<<e
HHHHHHHHHHHHHHHHHHHHHH
HHHHHHHHHHHHHHHHHHHHHH{
HHHHHHHHHHHHHHHHHHHHH
HHHHHHHHHHHHHHHHHHHHH
>T(plU
HHHHHHHHHHHHHHHHHHHHH
HHHHHHHHHHHHHHHHHHHHH
HHHHHHHHHHHHHHHHHHHHHHB
HHHHHHHHHHHHHHHHHHHHHHH
HHHHHHHHHHHHHHHHHHHHHHHHH
HHHHHHHHHHHHHHHHHHHHHHHHHHHS
HHHHHHHHHHHHHHHHHHHHHHHHHHHHHH7k
HHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHH7^
HHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHH
2WyC(s
nJOr6;X
W~~A.y
;]pL.z
%]~~I9
Qh~I>
+>S}W!
5;Oi4;O
z((z(z
(zNz/g
c7....V
).!-dfm
DQ=,ioh
nnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnn
nnnnnn
nnnnnnn
nnnnnnnnnn
{=`u'tX
nnnnnnnnnnn
nnnnnnnnn
nnnnnnnnnnnnnn
{=`utX
nnnnnnnnnnnn
%%%%%%%%%%%
HHHHHHHHHHHHHHHHHHHHHHHH
##AA!yy33
##wA!!
#AAA!yy33
##wA!!yy33
#AA!!yy33
HHHHHHHHHHHHHHHHHHHHHHHHHHHHHH
..................................
GGGGGYGYGYYYYYYYYYYYYYYGG
GYYYYYY
GYYYYYYY
GGYYYYYY-|
GGGYYYYYk
GGGGGYYYY
GGGGGYYYYYt
GGGGGGGGYYY
GGGGGGGYGYYYt
44444444544444x
bb qq
@4....
bb qq
....44444444444444444444x
...........................
.............................
....................................................................................................
bbbbbb
bbbbbbb
bbbbbbbb&
``````OOO
i;====22@@
22222*rf
u*====@
u====@
?.urf|
=====================
z===================================================================================================
QQQQQQQQQQQQ
Z))))x
ZZZ))M
ZZZZZ)
ZZZZZZZ
)BMlb1^
4@T>"S
~}r(-V~
Wereci vemawero ciporogezicicav. Xenaf jiwam winu zitekilumehewig fawuc. Takosinav yizik. Buy. Sayopivegif vow. Fenom dubu hafak tusehin rofa. Naxogel nacohubulohi zunivoye gumehiwabecofo. Gileciyavoli. Dija kocixixoterodi zoyi. Gewa dojif fakuva seper wawacemagug. Denuw doxe lulicogenopo vodebahorumawif. Cot gakikajazif ferecuf. Dareg. Raninag cinireta. Lox yevomusayud. Dopejunalebu bezuvawepe tinivuvarifik mohowu. Gicutosaf jijabezawiyowuc zemivinizel. Xupun hewuwojojafogu dafesaxe kazifasotuco mihajuserunin. Jafay wud rodavujosixira. Juwusuw rugune. Yofiwoma fasiyo zicup. Xijisexavulu hiha xidepu how. Jatexu wevezizawipij wikiwi. Ravuxicefazuhe yason rosol jujovi zusitav. Murinarubitomom. Nexi gubul tefapu bezucokoh kav. Kuvihiboyopuri vetokenad hup werazagufuzi vegisu. Lizemejomumen guvufohek tatonota yibejezixehe. Kozutufalupomo gabayof zic. Koyinocuno fenoh botijekesenif suvewaz dugaxenehipi. Digim tevusocu. Jomevozut. Sanud nopi picucujicicavi. Mayoxizahozeweg. Moyukafavek. Daculaj juleduxiwavoh ruyupa
iiiiii
iiiiii
iiiiiiiiiiii
iiiiiiiiii
iiiiii
iiiiiiiii
iiiiiiiiiiiii
iiiiiiii

mscoree.dll
KERNEL32.DLL
(null)
((((( H
h(((( H
H
cakehidulizuxiyena
tolahusiki habojixosufuvovokuzemihivuraz
pameyiwozodakabam hiwahevofawocucoducaribezij yakumevebuvayukoley sabere kiyujomugapitamagegu
firejurusemowetiwinigazomuxoru kucezebonujiketakekudabuceyitigo yomotaxizavazuzisobarulufevejup
waluxokumepamipokof bucocedidawitozukihiyapoxadeyite wem
BOLAWACULATOREGOWAVOVOSIXAZIWEMU
/ P6pL
,/KPip
/-P?pR
/ P6pL
,/KPip
/-P?pR
VS_VERSION_INFO
StringFileInform
020164c6
InternalName
saxzmoimoku.apa
Copyright
Copyrighz (C) 2021, fudkagata
ProductVersion
7.12.29.13
VarFileInfo
Translation
2Teluyopabem wile cogeruroga gob weto bopado tuvoja5Nizav wasebuweguxu kaxaka polaxamuwo taxoyud riximunu,Duboyo lejo hujahig sohafote kudetuvog bajac
Coyuvodi kevovipuyuviwYFef jupabilav hak zefobebiregova boci sopapikibiyefo xowehujutiye sipuyof vizelazafaxuvac5Mawezusaxised sumazusi mihi pumezezeb pacubetuyonoyen
nXub hukiyutawoxine copidudidos soyatilixolehuy doco cesetigijobuduk juxiwudukuzos fihutabucizuhed pozakoliyofe*Widihaxotegafu hawu riwusizo tinisagayusag
Sis gabajuwoho novoyukiwapepabdCawo kipifucezi gapu vihovixeyalesej hasamadajoko hudixogi badeyudevaseya keto xatufaxuwenih xokahamVPihopofuwezume tadamapicolid luzikufujeyi wubowe takiridutuza famecihoyol hatelifobuza7Feti kuzemidejunari fovapexazij nibi moreb dixagaw zowu
Xanuludi wekiJLewehe makihexiyowud nulakuwet mitifudomuzuhan tafiju tohe rocufiduzuwovet9Tiwucike jirecuvacirin kug hocafifohigesoz mihecuhumimuyaiSudukahiv nixovihayekazup lim tosopupami lobap yoxiguwupumej cugakap mevivodugav nusanafixoy wikifahagevaRHivudal lazawubitoluxed pinujerutu kuyig busuxojedul gunezejiwigajo cudilamokixilu
Kejocus sijizojagejijun lezoxaUTah sewodanifovojiv nit kapahari wejanalaporafo rujawowucebaye yowuci govo wopovayuto
Sohusidipo pepikakowiwaODoveror tebawiroli xofihocu falew kofohikewuweco fogeyewog wiyotesexih feyegikeWSepefe mamebikalarifo cawejociyiyo xuxizugo kanevupul jadepado tavofic jecoyop vumidafo+Vabayasised taserururodukef riresijeruzameh9Cuhe sazo jabupafulaya bel yasolosolugize voyufiherovixeb8Vuradeleye gij menuti yehari fecaxagefucarir vay decocix
hDujulesiye dadaveyiyehit geciwigun biwudusowoku tosizadekuhar lovihic wijalu najexamamug siyarije kefevi
Fuhizofo vukemasokSBiladuy tahalalofogun gocuzidategeheg yacivit mafuyul bahotan witixi bodicovo ximucoYijeveyeliju dubibozag saragekeconucin zuxosuwamar lusex mejexebiyuh gaco soyavedilapuk pebusuhovila bimewaduki!Mecebagucu pamexilide pahosezogif
Bavopifivid foxehi zunulejil'Memikatelacaf wiyijuzovay zelanatojudub&Netuposiwoveyaf navasigef porebowubuce
Hiwal divimajehehoxot haxif
VivatPFocutilur neyetoyamenapis raruv kigileba sahepegubux jifules wexidukige leju rih
Antivirus Signature
Bkav Clean
Lionic Clean
Elastic malicious (high confidence)
MicroWorld-eScan Gen:Variant.Fragtor.15265
FireEye Generic.mg.4e120e201ef1e0c7
CAT-QuickHeal Clean
ALYac Clean
Cylance Unsafe
Zillya Clean
Sangfor Trojan.Win32.Save.a
K7AntiVirus Trojan ( 0056d16b1 )
BitDefender Gen:Variant.Fragtor.15265
K7GW Trojan ( 0056d16b1 )
Cybereason Clean
BitDefenderTheta Gen:NN.ZexaF.34126.Qq0@a4GlrAnG
Cyren W32/Kryptik.EWJ.gen!Eldorado
ESET-NOD32 a variant of Win32/Kryptik.HMII
Baidu Clean
APEX Malicious
Paloalto Clean
ClamAV Clean
Kaspersky UDS:DangerousObject.Multi.Generic
Alibaba Clean
NANO-Antivirus Clean
ViRobot Clean
Tencent Clean
Ad-Aware Gen:Variant.Fragtor.15265
TACHYON Clean
Sophos ML/PE-A
Comodo Clean
F-Secure Clean
DrWeb Clean
VIPRE Clean
TrendMicro Clean
McAfee-GW-Edition BehavesLike.Win32.Emotet.jc
CMC Clean
Emsisoft Gen:Variant.Fragtor.15265 (B)
SentinelOne Static AI - Malicious PE
GData Gen:Variant.Fragtor.15265
Jiangmin Clean
Webroot Clean
Avira Clean
Antiy-AVL Clean
Kingsoft Clean
Gridinsoft Clean
Arcabit Clean
SUPERAntiSpyware Clean
ZoneAlarm Clean
Microsoft Trojan:Win32/Azorult.RF!MTB
Cynet Malicious (score: 100)
AhnLab-V3 CoinMiner/Win.Glupteba.R440044
Acronis suspicious
McAfee RDN/Generic.grp
MAX malware (ai score=82)
VBA32 BScope.Backdoor.Mokes
Malwarebytes Trojan.MalPack
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Rising Trojan.Kryptik!1.D91D (CLASSIC)
Yandex Clean
Ikarus Clean
eGambit Unsafe.AI_Score_58%
Fortinet W32/Kryptik.HMIM!tr
AVG Win32:RansomX-gen [Ransom]
Avast Win32:RansomX-gen [Ransom]
CrowdStrike win/malicious_confidence_100% (W)
MaxSecure Trojan.Malware.300983.susgen
No IRMA results available.