Static | ZeroBOX

PE Compile Time

2020-08-15 23:06:49

PDB Path

C:\bejewap69\zec\16\xegezizopoyaw\ludugezat29.pdb

PE Imphash

a07e2478ced6ea4bff168cbb215d0722

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x0001c000 0x0001c000 6.31293509976
.rdata 0x0001d000 0x0000871c 0x00008800 4.77970528128
.data 0x00026000 0x0272c99c 0x00023e00 7.91611716035
.rsrc 0x02753000 0x00005ae0 0x00005c00 5.21591758496
.reloc 0x02759000 0x0001359c 0x00013600 0.901603005846

Resources

Name Offset Size Language Sub-language File type
RT_CURSOR 0x02756c40 0x000010a8 None SUBLANG_DEFAULT dBase III DBT, version number 0, next free block index 40
RT_CURSOR 0x02756c40 0x000010a8 None SUBLANG_DEFAULT dBase III DBT, version number 0, next free block index 40
RT_CURSOR 0x02756c40 0x000010a8 None SUBLANG_DEFAULT dBase III DBT, version number 0, next free block index 40
RT_CURSOR 0x02756c40 0x000010a8 None SUBLANG_DEFAULT dBase III DBT, version number 0, next free block index 40
RT_ICON 0x02756308 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x02756308 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x02756308 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x02756308 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x02756308 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x02756308 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_STRING 0x027585a8 0x00000532 None SUBLANG_DEFAULT data
RT_STRING 0x027585a8 0x00000532 None SUBLANG_DEFAULT data
RT_STRING 0x027585a8 0x00000532 None SUBLANG_DEFAULT data
RT_ACCELERATOR 0x027567d0 0x00000070 None SUBLANG_DEFAULT data
RT_ACCELERATOR 0x027567d0 0x00000070 None SUBLANG_DEFAULT data
RT_GROUP_CURSOR 0x02757ce8 0x00000030 None SUBLANG_DEFAULT data
RT_GROUP_CURSOR 0x02757ce8 0x00000030 None SUBLANG_DEFAULT data
RT_GROUP_ICON 0x02756770 0x0000005a LANG_ENGLISH SUBLANG_ENGLISH_US data

Imports

Library KERNEL32.dll:
0x41d008 CopyFileExW
0x41d00c SetLocalTime
0x41d010 GetCPInfo
0x41d018 HeapAlloc
0x41d020 ReadConsoleA
0x41d02c CreateDirectoryW
0x41d034 GetModuleHandleW
0x41d038 GetTickCount
0x41d03c GetCurrentThread
0x41d044 SetCommState
0x41d048 GetCommandLineA
0x41d050 TlsSetValue
0x41d054 ActivateActCtx
0x41d058 GlobalAlloc
0x41d060 LoadLibraryW
0x41d068 TerminateProcess
0x41d070 lstrlenW
0x41d074 SetThreadPriority
0x41d07c LCMapStringA
0x41d084 InterlockedExchange
0x41d08c GetStartupInfoA
0x41d090 GetStdHandle
0x41d094 GetCPInfoExW
0x41d098 GetLastError
0x41d09c GetThreadLocale
0x41d0a4 GetProcAddress
0x41d0ac Process32FirstW
0x41d0b4 FindAtomA
0x41d0bc FindNextFileA
0x41d0c0 WriteProfileStringA
0x41d0c4 GetThreadPriority
0x41d0d0 HeapSetInformation
0x41d0d4 EnumResourceNamesA
0x41d0d8 GetStringTypeW
0x41d0dc WriteProfileStringW
0x41d0e0 CompareStringA
0x41d0e4 GetCPInfoExA
0x41d0e8 GetVersionExA
0x41d0ec GetProfileSectionW
0x41d0f0 CopyFileExA
0x41d0f4 FlushFileBuffers
0x41d0f8 CloseHandle
0x41d0fc MultiByteToWideChar
0x41d100 HeapValidate
0x41d104 IsBadReadPtr
0x41d108 RaiseException
0x41d118 GetModuleFileNameW
0x41d11c GetACP
0x41d120 GetOEMCP
0x41d124 IsValidCodePage
0x41d128 TlsGetValue
0x41d12c TlsAlloc
0x41d130 GetCurrentThreadId
0x41d134 TlsFree
0x41d138 SetLastError
0x41d144 GetCurrentProcessId
0x41d14c Sleep
0x41d150 ExitProcess
0x41d154 GetModuleFileNameA
0x41d160 WideCharToMultiByte
0x41d168 SetHandleCount
0x41d16c GetFileType
0x41d170 HeapDestroy
0x41d174 HeapCreate
0x41d178 HeapFree
0x41d17c VirtualFree
0x41d180 WriteFile
0x41d184 GetCurrentProcess
0x41d18c IsDebuggerPresent
0x41d190 HeapSize
0x41d194 HeapReAlloc
0x41d198 VirtualAlloc
0x41d19c RtlUnwind
0x41d1a4 DebugBreak
0x41d1a8 OutputDebugStringA
0x41d1ac WriteConsoleW
0x41d1b0 OutputDebugStringW
0x41d1b4 LCMapStringW
0x41d1b8 GetStringTypeA
0x41d1bc GetLocaleInfoA
0x41d1c0 LoadLibraryA
0x41d1c4 SetFilePointer
0x41d1c8 GetConsoleCP
0x41d1cc GetConsoleMode
0x41d1d0 SetStdHandle
0x41d1d4 WriteConsoleA
0x41d1d8 GetConsoleOutputCP
0x41d1dc CreateFileA
Library USER32.dll:
0x41d1e4 GetMessageTime
Library WINHTTP.dll:
0x41d1ec WinHttpOpen

!This program cannot be run in DOS mode.
`.rdata
@.data
@.reloc
URPQQh
PPPPPPPP
PPPPPPPP
j9hx!B
j9hx!B
y!hH"B
u!hH'B
u!hH'B
u!hP(B
jfh@*B
jfh@*B
jgh@*B
jgh@*B
jih@*B
jih@*B
jjh@*B
jjh@*B
u!hX)B
u!h`+B
u!hP&B
u!hH'B
jfh@*B
jfh@*B
jgh@*B
jgh@*B
jih@*B
jih@*B
jjh@*B
jjh@*B
u!hX)B
;t$,v-
UQPXY]Y[
jDhp/B
jDhp/B
jEhp/B
jEhp/B
jPhp/B
jphp/B
jphp/B
jxhp/B
jxhp/B
j:hd0B
jJhH2B
jJhH2B
j]hH2B
j]hH2B
j{hH2B
j{hH2B
u!h`$B
u!h83B
u!h<$B
u!h83B
u!hT.B
y!hH"B
j/h89B
j/h89B
jZh89B
jZh89B
j0hH;B
bad allocation
Unknown exception
f:\dd\vctools\crt_bld\self_x86\crt\src\onexit.c
Client
Ignore
Normal
Error: memory allocation: bad memory block type.
Invalid allocation size: %Iu bytes.
Client hook allocation failure.
Client hook allocation failure at file %hs line %d.
Error: possible heap corruption at or near 0x%p
The Block at 0x%p was allocated by aligned routines, use _aligned_realloc()
Error: memory allocation: bad memory block type.
Memory allocated at %hs(%d).
Invalid allocation size: %Iu bytes.
Memory allocated at %hs(%d).
Client hook re-allocation failure.
Client hook re-allocation failure at file %hs line %d.
HEAP CORRUPTION DETECTED: after %hs block (#%d) at 0x%p.
CRT detected that the application wrote to memory after end of heap buffer.
HEAP CORRUPTION DETECTED: after %hs block (#%d) at 0x%p.
CRT detected that the application wrote to memory after end of heap buffer.
Memory allocated at %hs(%d).
HEAP CORRUPTION DETECTED: before %hs block (#%d) at 0x%p.
CRT detected that the application wrote to memory before start of heap buffer.
HEAP CORRUPTION DETECTED: before %hs block (#%d) at 0x%p.
CRT detected that the application wrote to memory before start of heap buffer.
Memory allocated at %hs(%d).
Client hook free failure.
The Block at 0x%p was allocated by aligned routines, use _aligned_free()
%hs located at 0x%p is %Iu bytes long.
%hs located at 0x%p is %Iu bytes long.
Memory allocated at %hs(%d).
HEAP CORRUPTION DETECTED: on top of Free block at 0x%p.
CRT detected that the application wrote to a heap buffer that was freed.
HEAP CORRUPTION DETECTED: on top of Free block at 0x%p.
CRT detected that the application wrote to a heap buffer that was freed.
Memory allocated at %hs(%d).
DAMAGED
_heapchk fails with unknown return value!
_heapchk fails with _HEAPBADPTR.
_heapchk fails with _HEAPBADEND.
_heapchk fails with _HEAPBADNODE.
_heapchk fails with _HEAPBADBEGIN.
Bad memory block found at 0x%p.
Bad memory block found at 0x%p.
Memory allocated at %hs(%d).
Object dump complete.
crt block at 0x%p, subtype %x, %Iu bytes long.
normal block at 0x%p, %Iu bytes long.
client block at 0x%p, subtype %x, %Iu bytes long.
{%ld}
%hs(%d) :
#File Error#(%d) :
Dumping objects ->
Data: <%s> %s
Detected memory leaks!
f:\dd\vctools\crt_bld\self_x86\crt\src\mlock.c
f:\dd\vctools\crt_bld\self_x86\crt\src\mbctype.c
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
EncodePointer
DecodePointer
f:\dd\vctools\crt_bld\self_x86\crt\src\tidtable.c
FlsFree
FlsSetValue
FlsGetValue
FlsAlloc
CorExitProcess
f:\dd\vctools\crt_bld\self_x86\crt\src\stdenvp.c
f:\dd\vctools\crt_bld\self_x86\crt\src\stdargv.c
f:\dd\vctools\crt_bld\self_x86\crt\src\a_env.c
f:\dd\vctools\crt_bld\self_x86\crt\src\ioinit.c
runtime error
TLOSS error
SING error
DOMAIN error
An application has made an attempt to load the C runtime library without using a manifest.
This is an unsupported way to load Visual C++ DLLs. You need to modify your application to build with a manifest.
For more information, see the "Visual C++ Libraries as Shared Side-by-Side Assemblies" topic in the product documentation.
- Attempt to use MSIL code from this assembly during native code initialization
This indicates a bug in your application. It is most likely the result of calling an MSIL-compiled (/clr) function from a native constructor or from DllMain.
- not enough space for locale information
- Attempt to initialize the CRT more than once.
This indicates a bug in your application.
- CRT not initialized
- unable to initialize heap
- not enough space for lowio initialization
- not enough space for stdio initialization
- pure virtual function call
- not enough space for _onexit/atexit table
- unable to open console device
- unexpected heap error
- unexpected multithread lock error
- not enough space for thread data
This application has requested the Runtime to terminate it in an unusual way.
Please contact the application's support team for more information.
- not enough space for environment
- not enough space for arguments
- floating point support not loaded
Microsoft Visual C++ Runtime Library
<program name unknown>
Runtime Error!
Program:
Assertion Failed
Warning
Microsoft Visual C++ Debug Library
_CrtDbgReport: String too long or IO Error
Debug %s!
Program: %s%s%s%s%s%s%s%s%s%s%s%s
(Press Retry to debug the application)
Module:
File:
Line:
Expression:
For information on how your program can cause an assertion
failure, see the Visual C++ documentation on asserts.
HeapQueryInformation
%s(%d) : %s
Assertion failed!
Assertion failed:
, Line
<file unknown>
Second Chance Assertion Failed: File
_CrtDbgReport: String too long or Invalid characters in String
GetProcessWindowStation
GetUserObjectInformationW
GetLastActivePopup
GetActiveWindow
MessageBoxW
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
HH:mm:ss
dddd, MMMM dd, yyyy
MM/dd/yy
December
November
October
September
August
February
January
Saturday
Friday
Thursday
Wednesday
Tuesday
Monday
Sunday
Complete Object Locator'
Class Hierarchy Descriptor'
Base Class Array'
Base Class Descriptor at (
Type Descriptor'
`local static thread guard'
`managed vector copy constructor iterator'
`vector vbase copy constructor iterator'
`vector copy constructor iterator'
`dynamic atexit destructor for '
`dynamic initializer for '
`eh vector vbase copy constructor iterator'
`eh vector copy constructor iterator'
`managed vector destructor iterator'
`managed vector constructor iterator'
`placement delete[] closure'
`placement delete closure'
`omni callsig'
delete[]
new[]
`local vftable constructor closure'
`local vftable'
`udt returning'
`copy constructor closure'
`eh vector vbase constructor iterator'
`eh vector destructor iterator'
`eh vector constructor iterator'
`virtual displacement map'
`vector vbase constructor iterator'
`vector destructor iterator'
`vector constructor iterator'
`scalar deleting destructor'
`default constructor closure'
`vector deleting destructor'
`vbase destructor'
`string'
`local static guard'
`typeof'
`vcall'
`vbtable'
`vftable'
operator
delete
__unaligned
__restrict
__ptr64
__clrcall
__fastcall
__thiscall
__stdcall
__pascal
__cdecl
__based(
GetUserObjectInformationA
MessageBoxA
USER32.DLL
(null)
`h````
xpxxxx
f:\dd\vctools\crt_bld\self_x86\crt\src\output.c
bad exception
f:\dd\vctools\crt_bld\self_x86\crt\src\convrtcp.c
SunMonTueWedThuFriSat
JanFebMarAprMayJunJulAugSepOctNovDec
f:\dd\vctools\crt_bld\self_x86\crt\src\_getbuf.c
f:\dd\vctools\crt_bld\self_x86\crt\src\_file.c
`h`hhh
xppwpp
Unknown Runtime Check Error
Stack memory around _alloca was corrupted
A local variable was used before it was initialized
Stack memory was corrupted
A cast to a smaller data type has caused a loss of data. If this was intentional, you should mask the source of the cast with the appropriate bitmask. For example:
char c = (i & 0xFF);
Changing the code in this way will not affect the quality of the resulting optimized code.
The value of ESP was not properly saved across a function call. This is usually a result of calling a function declared with one calling convention with a function pointer declared with a different calling convention.
Stack around the variable '
' was corrupted.
The variable '
' is being used without being initialized.
CONOUT$
MSPDB80.DLL
Stack around _alloca corrupted
Local variable used before initialization
Stack memory corruption
Cast to smaller type causing loss of data
Stack pointer corruption
bad allocation
xupegeke
fifukixodovimisixivugojikisoyi
ziyoturicemiyati
xevufaxifonuzaju
guhopopowapocomuloyagecuvifu
tuwonihec
cahevuvalasuzuyewamuseti
bosexaxivinuyutayo
vuwunidaza
zexikobifixivawihe duzovonezulu racojesagabulamokucitebahora
gipikebuyodeneserehafokibimilete tidufimofuzegadedalodixelaheniy bisubuwosixunujezame
joxigemozitazolabaxomugufanebudi zuwubesasozetoyogucubeboyaxejeju mafalazinajusepolubuvex hixagemipafiyagabevuxafemuha netufozazag
wenisovabupelibehaj
dunopirefatepebup
joxepibapogedi
lobiluzubayezuruzurowipi
kajahuduhidopujotati
pehevaseyowihiyar
huwayamifomuvajusij
nagirazubotugupu
C:\bejewap69\zec\16\xegezizopoyaw\ludugezat29.pdb
DosDateTimeToFileTime
FindFirstChangeNotificationW
CopyFileExW
SetLocalTime
GetCPInfo
GetConsoleAliasExesLengthA
HeapAlloc
InterlockedIncrement
ReadConsoleA
InterlockedDecrement
GetSystemWindowsDirectoryW
CreateDirectoryW
FreeEnvironmentStringsA
GetModuleHandleW
GetTickCount
GetCurrentThread
GetPrivateProfileStringW
SetCommState
GetCommandLineA
SetProcessPriorityBoost
TlsSetValue
ActivateActCtx
GlobalAlloc
GetVolumeInformationA
LoadLibraryW
IsProcessorFeaturePresent
TerminateProcess
GetCompressedFileSizeA
lstrlenW
SetThreadPriority
GetNamedPipeHandleStateW
LCMapStringA
GetPrivateProfileIntW
InterlockedExchange
SetCurrentDirectoryA
GetStartupInfoA
GetStdHandle
GetCPInfoExW
GetLastError
GetThreadLocale
ReadConsoleOutputCharacterA
GetProcAddress
DisableThreadLibraryCalls
Process32FirstW
WritePrivateProfileStringA
FindAtomA
SetEnvironmentVariableA
FindNextFileA
WriteProfileStringA
GetThreadPriority
CreateIoCompletionPort
QueryMemoryResourceNotification
HeapSetInformation
EnumResourceNamesA
GetStringTypeW
WriteProfileStringW
CompareStringA
GetCPInfoExA
GetVersionExA
GetProfileSectionW
CopyFileExA
KERNEL32.dll
GetMessageTime
USER32.dll
WinHttpOpen
WINHTTP.dll
MultiByteToWideChar
HeapValidate
IsBadReadPtr
RaiseException
DeleteCriticalSection
EnterCriticalSection
LeaveCriticalSection
GetModuleFileNameW
GetACP
GetOEMCP
IsValidCodePage
TlsGetValue
TlsAlloc
GetCurrentThreadId
TlsFree
SetLastError
SetUnhandledExceptionFilter
QueryPerformanceCounter
GetCurrentProcessId
GetSystemTimeAsFileTime
ExitProcess
GetModuleFileNameA
GetEnvironmentStrings
FreeEnvironmentStringsW
WideCharToMultiByte
GetEnvironmentStringsW
SetHandleCount
GetFileType
HeapDestroy
HeapCreate
HeapFree
VirtualFree
WriteFile
GetCurrentProcess
UnhandledExceptionFilter
IsDebuggerPresent
HeapSize
HeapReAlloc
VirtualAlloc
RtlUnwind
InitializeCriticalSectionAndSpinCount
DebugBreak
OutputDebugStringA
WriteConsoleW
OutputDebugStringW
LCMapStringW
GetStringTypeA
GetLocaleInfoA
LoadLibraryA
SetFilePointer
GetConsoleCP
GetConsoleMode
SetStdHandle
WriteConsoleA
GetConsoleOutputCP
CreateFileA
CloseHandle
FlushFileBuffers
.?AVtype_info@@
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
.?AVbad_exception@std@@
.?AVexception@std@@
7Co4!]
dvR?6f
(m&[{t
!aC37Rrb
EU_J_Ec9
<,@|l{
!,X}7b,
@5=oyz
Dm #U|j
zXUro?
}pJD50
h*g;0hYV
~Q6#{i
-><'^*
;P#hu-
m\Fu"Dk
NwmUrF
{JQv\v
"<liEx^
GbaC!{~
Tz#ffL
*YG8Er
KB--#k
Fs:!N*
(mnGgF
jG:?`Q
|vMI:+
?57)yk
<)|K3%
oH8fQc
KSn}"@-
wL>mPw
_j\_~J
*#3luNj
x,*iqw"
HC5tyO#Qz
;Fx)-Sb=g
Cu+-u^
5R~r 1DZ
k8vi[
lgo7sdY{4
([gs/0Q
v|Vox;
CwTWbp
?PS<p3(
'=!{4o
h%J]][
/]%FSht
1])('j
@r1@IL0(
S*RXPDI
$5gdy!>
Dg:k96-
jDD8t1.N
IyXuW]
*l~_`h
?dl!(c?
KV3DU^
k\[u`0
e3.u1v~
A|1RFTKi
=_J;+i
n|}dQ;
)V$6W*7
R>78^Q
+RD%m.;
a53[EVD
D$$'DY
gF>+i;
g?x7x;+
6h@J m
ApN}l8.
*uuq_w
hsUhll
I/?:V[
hOFpek
Ia].OcW
r4vm4o
NdY)S|"6
Cik_[!y
=-\h'Rrpu
?j3Xsk
|SFCd
Z^'p(r
]rV<(F:
-y8<-<D
B09KZh
pox[wA
:I8Ld
$$^%#?
z2~4f}
L>^&68
F\3tXT*
0r{AKtv
f(FF})
PP;NW]9
]t <r
[6PdoO'
`#eA8A
^)M[Cs
?_WKdj
pSpJcx
gXNPcz
J7sEMXi
~jB*V*
I}qnmD
(;+_7u
O1ca3+
,0v '=
B2WB#OP
h51Lp(
UY22UcV<-
Qx;=pA
@Z~}QC{
+egOf<
ZAbi,8c
), %cw0
!eRXG}
k!F\L^
97F,$p
Pr{,d!4V
l GrU[
^[37ss
NbFOdI
.2b$LF
$6Z"{:uL
L<HP-4
cuNOmo
OT~o'g
`N#/i)S
Vk~Wfr
!5,EP3
"09fWc
|)jD8u
a*Q4vKd
e+qKWFPl
WB}V^:
fnFn[
9BZQ
*Zi>y8
["(\C"
1eE,/5m
S&@H"K
L7|PjgKEJ.
`XCkOu
%Jl\7M>`
#!8,&h}o
mn8@@8
LC!oZ-J
}ITB"B
1MDao%
HhqKnX
o"IhrG
e-C&q6d
Q!cD^YH
oajiB7X+
i(C~7iPG
Z_,@jS
vnaxo-<
qD(MWG
$2t(se
X^Npkm
WiQu[#
lz/fU'
&]Hj(t
Cve_[V
Bs.F9!W
x2lg Fz
<l;VR+fm
rC)<t?-X
cR<`]V
O.xF7Q
}qdS/"&
%54LgW4
c>?xK$JFf
GxH_@a%d
{R?"1
Ec~|yJ
GgG%$]W
L;f4is
Zz?&:J
M#?WZX
8U$5cw(L
`jff/{:
k\'Eu`"W
~UJJn$
?fRq)-
=[~.X'
bLnW4e
);}<~*
*J^bn=
@jqk|H
+R-S~fL
kIOF%,
)k;"*Lo
1M/:w
R4i|yA
4X$0J^6
X{XM$zT=
MQ9#_=
6wU.zn+
2Osd#}Wsc
z v9a.'
+[mjx8KNrG
=+U\(@*%mm
;PAsb)
9&saB[
],l\3R7
@W3YSO
4?V&cg
YcH+>9
J%|`!C
l'vQ`=
5Y4Yzv
dv"B^#V
#p&Z](T
*vsC+;
[Y]NTA
,4u ?(
2.e&i!
j1DmK7
&0.y,"
'xAjAGx
UkMy9'Z
P]G"$<
fG$6rj
cY1;dMK,
sRs8,{]
r 128n
:L^nkA
+0A$6L$
pm$cGo
f]GS>qv
G+AEk^
tw+:Pi;
i:ZDya
yg+cFF
GhKlfZ
h%>S=~
o)[0sA"G
g'jAA1
dt3J'"
\]ix+_
D9$e9
PAj#wXt04
<)zy/07
Ot0t(K
'-REgM
,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,$$$$$$$$$$$$$$$$
,,,,,,,,,$$
[[[[[[[[[[[[[>
[$,,,,,,,,P
[$,,,,,,,$
.[$,,,,,,$.[
P[O>JJ
[P>>>O[$,,,,,$
[$>J>O[
,,,,,P[
JO[$,,,,,$[O
[[[[[[
,,,,,$[O
[[[[[[[[[P>JJO[
,,,,,$[
[[[[[[[[[[[[[PJJJ^[$,,,,,P[O
P$$$P$PP$PP$P$PJJJ.[
,,,,,$[O
JJJ.[$,,,,,$[O
,,,,,$[^8
yX{{{{{{{{{{{{{{
[$,,,,,$[^8I{+
,,,,,$[^8
[$,,,,,$[.
,,,,,$[.
,,,,,$[.BI{
,,,,,$[
,,,,,$[
[$,,,,,$[
))))]]]
P,,,,,$[
))))]]]]+{I
$,,,,,$[
)))+{I
$,,,,,$[
$,,,,,$P$$
IIIIIIIIIIIIIIII
,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,
``````````````````````````````````````````````````````
```````
bbbbbb0
``````
"yyyyy
YT````
y00000b
/UT````
//"y````
"""U""U""U
//"y````
"y````
)|||PPPa
||PPP
)|||PP
)]]]||||a
))]]]a
``````````````````````````````````````````````````
AAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAA
gra^|y
182=2O2
6:7?7I7
;S;H<M<_<
=/=I=f=k=
?"?d?m?
0"0O0T0Y0
0(1-1?12(212A2M2c2o2x2~2
7"7@7J7V7q7w7
7H8P8Y8i8u8
9!9-929b9n9
;<;B;{;
<<E<O<[<v<
=(=-=?=e=q=
0!0>0C0`0e0
1&1/1q1
3+474d4i4n4{4
6>6C6H6n6
7(8-8?8k8p8
8*9:9e9
:9;+<\<a<f<
<B=R=W=
??I?N?S?
010:0d0i0n0
2'2k2t2
34393>3
7=8F8p8u8z8
=#=0===U=}=
?2?9?K?R?
00050:0?0
0+171V1p1|1
262R2^2n2z2
3F3K3P3U3|3-4
8&818I8R8_8
151W4j4
8+8_8w8
;;4;8;P;U;b;
<7=G=N=]=r=y=
>'>0>4>:>@>F>L>Q>V>\>a>g>p>w>~>
?(?K?R?~?
0030H0]0g0u0
2X2]2o2N3
8#80858C8K8c8
979m9|9
:':,:3:=:A:K:Z:^:d:k:
!040q0
2:2I2^2c2h2
7*8:8[8
8!9B9d9
:):/:C:
;-;I;^;c;k;
>$>+>>>T>[>n>
0/0C0N0g0p0
0?1D1I1P1}1
4?4c4j4t4
7"727>7Y7i7u7
7@8F8t8y8~8
: ;';H;M;_;
=3=q=y=
0%0T0k0
1:1K1x1
1^2e2t2
3a3h3r3
4)424;489E9N9h9s9z9
::%:.:4:?:I:X:a:j:{:
;A;M;z;
0'070>0e0
080?0G0L0P0T0}0
0.14181<1@1
2+2]2d2h2l2p2t2x2|2
;);.;4;A;F;L;
<J<V<b<g<l<
<#=(=-=2=
>=>B>G>
1!1?1D1I1
3/353P3]3b3h3u3z3
32474<4A4t4
55$5M5R5W5\5
5-62676<6g6l6q6
7.777i7
839:9I9i9n9s9
9*:1:;:M:W:w:|:
:);2;;;C;X;];o;
=,>0>4>8><>@>
? ?5???`?e?o?}?
22C2L2v2{2
2!3*3T3Y3^3
5=5B5G5
6)788=8O8h8
= >J>y>"?.?
0 0*060A0K0T0
6%6D6c6
7"7'7f7n7
8D8I8N8
:D:L:Q;Z;
<<I<N<S<
<!=*=T=Y=^=
>/>8>b>g>l>
?(?-???
1(212[2`2e2
3"3,3:3?3I3]3c3k3u3
4A4L4m4
7?7X7_7g7l7p7t7
8N8T8X8\8`8
9!9K9}9
>>>C>H>b?n?
0 0%0N0
1"1`1g1
4!4r4~4
6'636?6D6V6[6a6g6
6(9-9?98:=:O:
50555:5s5{5
5:6C6m6r6w6A7M7z7
768?8i8n8s8
<$=0=]=b=g=
>">O>T>Y>
0:1C1m1r1w1
1!2J2S2}2
353^3g3
6"7.7[7`7e7
8.9:9g9l9q9
;&;P;U;Z;
<<^<g<
?'?0?Y?w?
0 1Q1d1
1,2=2j203:3
4S4X4]4
6!7D7M7
9$:):.:T:
<5=i=s=
041>1h1
3=4F4\4e4r4
5>5G5q5v5{5
6+616:6H6R6`6f6
7=7N7h7q7{7
<!=&=+=
1@2G2U3\3
>'?,?1?
0 0$0(0,0004080<0@0D0H0<2
2-393i3n3s3
:%;*;/;
2$3(3,3034383<3@3D3H3L3P3T3X3p3t3x3|3
;1;U;a;
;'<J<V<
==$=G=h=m=
=4>?>w>
? ?;?B?K?b?i?
0X0]0o0
2(363I3c3
6e7k7p7
8%8O8T8Y8
959:9?9
96:Y:b:
;J;g;q;
=H=M=R=
=0>G>}>
@0[0b0i0p0w0~0
?"?)?0?7?>?E?L?T?\?c?l?s?|?
0*000<0I0O0V0\0d0l0t0{0
3K4U4l4y4M6i6
9"9)9\9l9q9w9
::':7:A:P:U:Z:`:n:t:
=!=&=,=[=j=r=z=
>+>;>j>u>{>
2$2(2,2p2t2x2
(7,707
`<d<h<
0 0$0(0,0004080<0@0D0H0L0P0T0X0\0`0d0h0l0p0t0x0|0
1 1$1(1,1014181<1@1D1H1L1P1T1
<2@2H2L2P2T2
3(3,3<3@3D3L3d3h3
484X4x4
585@5L5l5x5
686X6x6
7(7H7h7
888T8X8t8x8
989@9D9`9h9l9
;(;H;P;d;
:$:0:4:`:d:h:l:p:t:x:|:
; ;(;,;0;4;8;<;@;D;H;L;X;p;t;x;|;
jjjjjjj
jjjjjjjj
jjjjjj
f:\dd\vctools\crt_bld\self_x86\crt\src\dbgdel.cpp
_BLOCK_TYPE_IS_VALID(pHead->nBlockUse)
f:\dd\vctools\crt_bld\self_x86\crt\src\_mbslen.c
_loc_update.GetLocaleT()->locinfo->mb_cur_max == 1 || _loc_update.GetLocaleT()->locinfo->mb_cur_max == 2
f:\dd\vctools\crt_bld\self_x86\crt\src\dbgheap.c
_CrtCheckMemory()
_calloc_dbg_impl
(_HEAP_MAXREQ / nNum) >= nSize
_pFirstBlock == pOldBlock
_pLastBlock == pOldBlock
fRealloc || (!fRealloc && pNewBlock == pOldBlock)
pOldBlock->nLine == IGNORE_LINE && pOldBlock->lRequest == IGNORE_REQ
_CrtIsValidHeapPointer(pUserData)
pUserData != NULL
_pFirstBlock == pHead
_pLastBlock == pHead
pHead->nBlockUse == nBlockUse
pHead->nLine == IGNORE_LINE && pHead->lRequest == IGNORE_REQ
_msize_dbg
_CrtSetDbgFlag
(fNewBits==_CRTDBG_REPORT_FLAG) || ((fNewBits & 0x0ffff & ~(_CRTDBG_ALLOC_MEM_DF | _CRTDBG_DELAY_FREE_MEM_DF | _CRTDBG_CHECK_ALWAYS_DF | _CRTDBG_CHECK_CRT_DF | _CRTDBG_LEAK_CHECK_DF) ) == 0)
_CrtMemCheckpoint
state != NULL
(*_errno())
_printMemBlockData
(L"Buffer is too small" && 0)
Buffer is too small
(((_Src))) != NULL
strcpy_s
f:\dd\vctools\crt_bld\self_x86\crt\src\tcscpy_s.inl
((_Dst)) != NULL && ((_SizeInBytes)) > 0
ibase == 0 || (2 <= ibase && ibase <= 36)
strtoxl
f:\dd\vctools\crt_bld\self_x86\crt\src\strtol.c
nptr != NULL
strtoxq
f:\dd\vctools\crt_bld\self_x86\crt\src\strtoq.c
Assertion Failed
Warning
f:\dd\vctools\crt_bld\self_x86\crt\src\dbgrpt.c
Microsoft Visual C++ Debug Library
_CrtDbgReport: String too long or IO Error
wcscpy_s(szOutMessage, 4096, L"_CrtDbgReport: String too long or IO Error")
Debug %s!
Program: %s%s%s%s%s%s%s%s%s%s%s%s
(Press Retry to debug the application)
Module:
File:
Line:
Expression:
For information on how your program can cause an assertion
failure, see the Visual C++ documentation on asserts.
memcpy_s(szShortProgName, sizeof(TCHAR) * (260 - (szShortProgName - szExeName)), dotdotdot, sizeof(TCHAR) * 3)
<program name unknown>
wcscpy_s(szExeName, 260, L"<program name unknown>")
__crtMessageWindowW
f:\dd\vctools\crt_bld\self_x86\crt\src\setlocal.c
((ptloci->lc_category[category].wlocale != NULL) && (ptloci->lc_category[category].wrefcount != NULL)) || ((ptloci->lc_category[category].wlocale == NULL) && (ptloci->lc_category[category].wrefcount == NULL))
KERNEL32.DLL
f:\dd\vctools\crt_bld\self_x86\crt\prebuild\eh\typname.cpp
pNode->next != NULL
mscoree.dll
strcpy_s(*env, cchars, p)
_setenvp
f:\dd\vctools\crt_bld\self_x86\crt\src\stdenvp.c
strcat_s(outmsg, (sizeof(outmsg) / sizeof(outmsg[0])), rterrs[tblindx].rterrtxt)
strcat_s(outmsg, (sizeof(outmsg) / sizeof(outmsg[0])), "\n\n")
strncpy_s(pch, progname_size - (pch - progname), "...", 3)
strcpy_s(progname, progname_size, "<program name unknown>")
strcpy_s(outmsg, (sizeof(outmsg) / sizeof(outmsg[0])), "Runtime Error!\n\nProgram: ")
_NMSG_WRITE
f:\dd\vctools\crt_bld\self_x86\crt\src\crt0msg.c
strcpy_s(szOutMessage, 4096, "_CrtDbgReport: String too long or IO Error")
strcpy_s(szExeName, 260, "<program name unknown>")
__crtMessageWindowA
_expand_base
f:\dd\vctools\crt_bld\self_x86\crt\src\expand.c
pBlock != NULL
kernel32.dll
(format != NULL)
f:\dd\vctools\crt_bld\self_x86\crt\src\isctype.c
(unsigned)(c + 1) <= 256
f:\dd\vctools\crt_bld\self_x86\crt\src\dbgrptt.c
_CrtDbgReport: String too long or Invalid characters in String
wcscpy_s(szOutMessage2, 4096, L"_CrtDbgReport: String too long or Invalid characters in String")
e = mbstowcs_s(&ret, szOutMessage2, 4096, szOutMessage, ((size_t)-1))
strcpy_s(szOutMessage, 4096, szLineMessage)
strcat_s(szLineMessage, 4096, "\n")
strcat_s(szLineMessage, 4096, "\r")
strcat_s(szLineMessage, 4096, szUserMessage)
strcpy_s(szLineMessage, 4096, szFormat ? "Assertion failed: " : "Assertion failed!")
strcpy_s(szUserMessage, 4096, "_CrtDbgReport: String too long or IO Error")
_itoa_s(nLine, szLineMessage, 4096, 10)
_VCrtDbgReportA
wcstombs_s(&ret, szaOutMessage, 4096, szOutMessage, ((size_t)-1))
strcpy_s(szOutMessage2, 4096, "_CrtDbgReport: String too long or Invalid characters in String")
wcstombs_s(((void *)0), szOutMessage2, 4096, szOutMessage, ((size_t)-1))
wcscpy_s(szOutMessage, 4096, szLineMessage)
%s(%d) : %s
wcscat_s(szLineMessage, 4096, L"\n")
wcscat_s(szLineMessage, 4096, L"\r")
wcscat_s(szLineMessage, 4096, szUserMessage)
wcscpy_s(szLineMessage, 4096, szFormat ? L"Assertion failed: " : L"Assertion failed!")
Assertion failed!
Assertion failed:
wcscpy_s(szUserMessage, 4096, L"_CrtDbgReport: String too long or IO Error")
, Line
<file unknown>
Second Chance Assertion Failed: File
_itow_s(nLine, szLineMessage, 4096, 10)
_VCrtDbgReportW
f:\dd\vctools\crt_bld\self_x86\crt\src\winsig.c
("Invalid signal or error", 0)
WUSER32.DLL
sizeInBytes >= count
src != NULL
memcpy_s
f:\dd\vctools\crt_bld\self_x86\crt\src\memcpy_s.c
dst != NULL
wcscpy_s
((_Dst)) != NULL && ((_SizeInWords)) > 0
f:\dd\vctools\crt_bld\self_x86\crt\src\malloc.h
("Corrupted pointer passed to _freea", 0)
((((( H
h(((( H
H
nstrncpy_s
f:\dd\vctools\crt_bld\self_x86\crt\src\tcsncpy_s.inl
(L"String is not null terminated" && 0)
String is not null terminated
strcat_s
f:\dd\vctools\crt_bld\self_x86\crt\src\tcscat_s.inl
A_set_error_mode
f:\dd\vctools\crt_bld\self_x86\crt\src\errmode.c
("Invalid error_mode", 0)
("inconsistent IOB fields", stream->_ptr - stream->_base >= 0)
f:\dd\vctools\crt_bld\self_x86\crt\src\_flsbuf.c
str != NULL
(null)
("'n' format specifier disabled", 0)
(ch != _T('\0'))
( (_Stream->_flag & _IOSTRG) || ( fn = _fileno(_Stream), ( (_textmode_safe(fn) == __IOINFO_TM_ANSI) && !_tm_unicode_safe(fn))))
f:\dd\vctools\crt_bld\self_x86\crt\src\output.c
(stream != NULL)
f:\dd\vctools\crt_bld\self_x86\crt\src\vsprintf.c
(count == 0) || (string != NULL)
_vsnprintf_helper
("Buffer too small", 0)
string != NULL && sizeInBytes > 0
_vsprintf_s_l
format != NULL
_vsnprintf_s_l
@_mbstowcs_l_helper
f:\dd\vctools\crt_bld\self_x86\crt\src\mbstowcs.c
s != NULL
retsize <= sizeInWords
bufferSize <= INT_MAX
_mbstowcs_s_l
(pwcs == NULL && sizeInWords == 0) || (pwcs != NULL && sizeInWords > 0)
length < sizeInTChars
2 <= radix && radix <= 36
sizeInTChars > (size_t)(is_neg ? 2 : 1)
sizeInTChars > 0
xtoa_s
f:\dd\vctools\crt_bld\self_x86\crt\src\xtoa.c
buf != NULL
_wcstombs_l_helper
f:\dd\vctools\crt_bld\self_x86\crt\src\wcstombs.c
pwcs != NULL
sizeInBytes > retsize
_wcstombs_s_l
(dst != NULL && sizeInBytes > 0) || (dst == NULL && sizeInBytes == 0)
wcscat_s
_vswprintf_helper
f:\dd\vctools\crt_bld\self_x86\crt\src\vswprint.c
string != NULL && sizeInWords > 0
_vsnwprintf_s_l
xtow_s
("Invalid file descriptor. File possibly closed by a different thread",0)
(_osfile(fh) & FOPEN)
_lseeki64
f:\dd\vctools\crt_bld\self_x86\crt\src\lseeki64.c
(fh >= 0 && (unsigned)fh < (unsigned)_nhandle)
_write
f:\dd\vctools\crt_bld\self_x86\crt\src\write.c
isleadbyte(_dbcsBuffer(fh))
((cnt & 1) == 0)
_write_nolock
(buf != NULL)
f:\dd\vctools\crt_bld\self_x86\crt\src\_getbuf.c
_isatty
f:\dd\vctools\crt_bld\self_x86\crt\src\isatty.c
_fileno
f:\dd\vctools\crt_bld\self_x86\crt\src\fileno.c
sizeInBytes > 0
_wctomb_s_l
f:\dd\vctools\crt_bld\self_x86\crt\src\wctomb.c
sizeInBytes <= INT_MAX
((state == ST_NORMAL) || (state == ST_TYPE))
("Incorrect format specifier", 0)
_output_s_l
_woutput_s_l
f:\dd\vctools\crt_bld\self_x86\crt\src\mbtowc.c
(str != NULL)
_get_osfhandle
f:\dd\vctools\crt_bld\self_x86\crt\src\osfinfo.c
Bfclose
f:\dd\vctools\crt_bld\self_x86\crt\src\fclose.c
_fclose_nolock
(_osfile(filedes) & FOPEN)
_commit
f:\dd\vctools\crt_bld\self_x86\crt\src\commit.c
(filedes >= 0 && (unsigned)filedes < (unsigned)_nhandle)
_close
f:\dd\vctools\crt_bld\self_x86\crt\src\close.c
f:\dd\vctools\crt_bld\self_x86\crt\src\_freebuf.c
stream != NULL
siyomozezovafahineyesugulehif
ginerevamowinihilukihojipay
nuxuhisufufutewusiyakuzigewimi vogoce puropufejukew
gavitihisil
kernel32.dll
cewawosunu sagemosucaboyabemuba warocejufimol pidurekasokivazu fozecafogofuzowuroseboregasu
zanizuduvoveyenabocacupimo laguvideyuyuxisu fazabomiyukelepuwabuvi
ponafewonoboliketeridigutome borobelukopecapozaka
liciyowomidebogonizimujupazuza
jenomexatajurokulixorohigozogake
kexupofenafuvetur
zasozevuritiguvixowewewexeno
&Wobumagivexo cuvabus kiko vopotayayivi8Hoduhexixekajay koxijiz mexecuwuxusivo petided pipavomil5Xadas zap koyuce rivutap vacahetiromo polikizehizevibiGihahezirasusa seyapomeyuyojan xuri didujavetukat vewuvipiwoxehel nayavayisojo sifemigotipe loxicukovofab[Wecodo dugomaperog xojiciwexadu loxayicac nak vawakakir zagigutujufelu koxigod kehecoxikuxe
&Sayiwahevujife yusuvegivi kotenefokeri*Sed nakoyam kufusupore lofivozoy wexifedul/Xodabide yorevuzikofani zopitununek lidiyorehew
Bob kijagakuhZDeyanija novogosiwikob mupofoholuvuhe hola rahozehomuyotet deletediduwab dosoxe laxohebahiSFoku yecedimog gujijila xoro kowugoferowuboz colele logukefok wotufabecumetey rowuvOWepejaneyase xok bolocibit susohuzejif tarocobuxa kimini gel kov zibekajaripeyi
YegihlBoverulabu yunaronusira cejolowihusil junesilav kihures xulocuv dakodaz zubugoz feboxufazaba pukatejolezuram
Pujetido koway
JJiwivuxuma cusamahuditat lelacawubanuro tuzanajigibacuf faluy wofuniwenosa
Ducikedi lavavumugkMaxuxirevo pojobutofoyuxel yahifab wubajak pazovenofuhu nipikap toleye masusenalaru sogepixih dofocamezapoz
dMefe zurazitayejoteg fekimoxulewir voh tezalonu nosoyara fajalanog xisuw lupebetukuf yeyekakonafazod
Nuhib lifew jebofipu
Yasivemocekuji samotonalajapam
RetuxebiEJuwepofinoja muloseboyuwajek webenot dejaz lecojuduroful fuc labixule
Sugomi dorujuwecupexi xetepok>Rexa jadifigegoxupan virulu ratameziwicohum sazap viyixomuzeboVXife nasubafowetov gugi lujexucaceraxeg midevi golavuy nir neh lukuzepivu sexowoxaluvohPihewatoci zucaj gizimusocapic cefejukim jiyibovifivi biyotahiw covadesusepelex navotabuyepene bokamapabWejiyebiluya watihe yocosoranul
Conimugow daf
Jadotijusek:Supimafen pige tohijevafo lusofoficaxa jovexezaholufo rano
Nufomuhoyijaxo tagobisohozib
Antivirus Signature
Bkav W32.AIDetect.malware1
Lionic Clean
Elastic malicious (high confidence)
MicroWorld-eScan Clean
CMC Clean
CAT-QuickHeal Ransom.Stop.Z5
ALYac Clean
Cylance Unsafe
VIPRE Clean
Sangfor Trojan.Win32.Save.a
K7AntiVirus Clean
BitDefender Clean
K7GW Clean
Cybereason malicious.56dc79
BitDefenderTheta Gen:NN.ZexaF.34142.yuW@a4xwVtfO
Cyren Clean
Symantec Packed.Generic.620
ESET-NOD32 Clean
Baidu Clean
APEX Malicious
Paloalto generic.ml
ClamAV Clean
Kaspersky UDS:DangerousObject.Multi.Generic
Alibaba Clean
NANO-Antivirus Clean
ViRobot Clean
Tencent Clean
Ad-Aware Clean
TACHYON Clean
Emsisoft Clean
Comodo Clean
F-Secure Clean
DrWeb Clean
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition BehavesLike.Win32.Dropper.fh
FireEye Generic.mg.e74e8f9adb0df482
Sophos ML/PE-A
SentinelOne Static AI - Malicious PE
Jiangmin Clean
MaxSecure Trojan.Malware.300983.susgen
Avira Clean
Antiy-AVL Clean
Kingsoft Win32.PSWTroj.Undef.(kcloud)
Microsoft Trojan:Win32/Sabsik.TE.B!ml
Gridinsoft Clean
Arcabit Clean
SUPERAntiSpyware Clean
ZoneAlarm Clean
GData Clean
Cynet Malicious (score: 100)
AhnLab-V3 Clean
Acronis suspicious
McAfee Packed-GDT!E74E8F9ADB0D
MAX Clean
VBA32 BScope.Trojan.AET.281105
Malwarebytes Clean
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Rising Trojan.Kryptik!1.D975 (CLASSIC)
Yandex Clean
Ikarus Trojan.Win32.Azorult
eGambit Unsafe.AI_Score_97%
Fortinet Clean
Webroot Clean
AVG FileRepMalware
Avast FileRepMalware
CrowdStrike win/malicious_confidence_100% (D)
No IRMA results available.