Static | ZeroBOX

PE Compile Time

2020-04-29 19:36:39

PDB Path

C:\kipudof88\gagazaf\48.pdb

PE Imphash

b4a5f131bf57e0871ab3cda52113b279

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x0005d3ec 0x0005d400 7.94548230555
.rdata 0x0005f000 0x0000422c 0x00004400 4.28626068541
.data 0x00064000 0x00085b40 0x00002400 2.24389067665
.rsrc 0x000ea000 0x000150d8 0x00015200 6.51504299965

Resources

Name Offset Size Language Sub-language File type
FIBOLUWAWABUROBI 0x000fd9f0 0x00000685 LANG_SAAMI SUBLANG_ARABIC_LIBYA ASCII text, with very long lines, with no line terminators
RT_CURSOR 0x000fe338 0x000000b0 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_CURSOR 0x000fe338 0x000000b0 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_CURSOR 0x000fe338 0x000000b0 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x000fd510 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x000fd510 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x000fd510 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x000fd510 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x000fd510 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x000fd510 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x000fd510 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x000fd510 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x000fd510 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x000fd510 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x000fd510 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x000fd510 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x000fd510 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x000fd510 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x000fd510 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x000fd510 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x000fd510 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x000fd510 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x000fd510 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x000fd510 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x000fd510 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x000fd510 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x000fd510 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_STRING 0x000feac8 0x00000610 LANG_SAAMI SUBLANG_ARABIC_LIBYA data
RT_STRING 0x000feac8 0x00000610 LANG_SAAMI SUBLANG_ARABIC_LIBYA data
RT_STRING 0x000feac8 0x00000610 LANG_SAAMI SUBLANG_ARABIC_LIBYA data
RT_ACCELERATOR 0x000fe0a0 0x00000020 LANG_SAAMI SUBLANG_ARABIC_LIBYA data
RT_ACCELERATOR 0x000fe0a0 0x00000020 LANG_SAAMI SUBLANG_ARABIC_LIBYA data
RT_GROUP_CURSOR 0x000fe3e8 0x00000022 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_GROUP_CURSOR 0x000fe3e8 0x00000022 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_GROUP_ICON 0x000f0918 0x00000068 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_GROUP_ICON 0x000f0918 0x00000068 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_GROUP_ICON 0x000f0918 0x00000068 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_VERSION 0x000fe410 0x000001b4 LANG_NEUTRAL SUBLANG_NEUTRAL data

Imports

Library KERNEL32.dll:
0x45f008 GetLocaleInfoA
0x45f00c LoadResource
0x45f010 EndUpdateResourceW
0x45f018 GlobalSize
0x45f020 WaitForSingleObject
0x45f024 AddConsoleAliasW
0x45f028 SetEvent
0x45f02c ReadConsoleW
0x45f034 GetCommandLineA
0x45f038 GlobalAlloc
0x45f044 GetModuleFileNameW
0x45f048 ReleaseSemaphore
0x45f04c GetConsoleOutputCP
0x45f050 GetProcAddress
0x45f058 VerLanguageNameW
0x45f05c WriteConsoleA
0x45f060 GetProcessId
0x45f068 LockResource
0x45f070 GlobalGetAtomNameW
0x45f074 SetSystemTime
0x45f078 EnumResourceTypesW
0x45f07c GetModuleFileNameA
0x45f080 GetModuleHandleA
0x45f084 EraseTape
0x45f088 FindFirstVolumeW
0x45f090 HeapAlloc
0x45f094 GetLastError
0x45f098 HeapReAlloc
0x45f09c GetStartupInfoA
0x45f0a0 RaiseException
0x45f0a4 RtlUnwind
0x45f0a8 TerminateProcess
0x45f0ac GetCurrentProcess
0x45f0b8 IsDebuggerPresent
0x45f0bc HeapFree
0x45f0c4 VirtualFree
0x45f0c8 VirtualAlloc
0x45f0cc HeapCreate
0x45f0d0 GetModuleHandleW
0x45f0d4 Sleep
0x45f0d8 ExitProcess
0x45f0dc WriteFile
0x45f0e0 GetStdHandle
0x45f0e4 SetHandleCount
0x45f0e8 GetFileType
0x45f0ec SetFilePointer
0x45f0fc WideCharToMultiByte
0x45f100 TlsGetValue
0x45f104 TlsAlloc
0x45f108 TlsSetValue
0x45f10c TlsFree
0x45f114 SetLastError
0x45f118 GetCurrentThreadId
0x45f120 GetTickCount
0x45f124 GetCurrentProcessId
0x45f130 LoadLibraryA
0x45f134 SetStdHandle
0x45f138 GetConsoleCP
0x45f13c GetConsoleMode
0x45f140 FlushFileBuffers
0x45f144 HeapSize
0x45f148 GetCPInfo
0x45f14c GetACP
0x45f150 GetOEMCP
0x45f154 IsValidCodePage
0x45f158 WriteConsoleW
0x45f15c MultiByteToWideChar
0x45f160 LCMapStringA
0x45f164 LCMapStringW
0x45f168 GetStringTypeA
0x45f16c GetStringTypeW
0x45f170 CloseHandle
0x45f174 CreateFileA
Library USER32.dll:
Library GDI32.dll:
0x45f000 GetCharWidth32A

!This program cannot be run in DOS mode.
`.rdata
@.data
0WWWWW
0WWWWW
jXhH#F
QQSVWd
0SSSSS
tNIt?It0It
j@j ^V
>=Yt1j
j,hh%F
HtHu4j
s[S;7|G;w
tR99u2
URPQQhT{@
0SSSSS
0SSSSS
0A@@Ju
;t$,v-
UQPXY]Y[
uL9=hgF
_VVVVV
^WWWWW
t"SS9]
PPPPPPPP
PPPPPPPP
0SSSSS
_VVVVV
t+WWVPV
<+t(<-t$:
+t HHt
IHYGM_
j_\Q!
Y{[)*;G
3Y!b&
8n,sI&4
yaz0L1
[ut+&e
D+I9LQ
rz0NE{
nujP"S
W_.cqPS
otY&5
wIM,Jn
Ir"bjr
A:|uTS
$Z.Y<AF
L,.*JDUJ
en;*o2
@wQ@DU
YeG=Pb
x4FI6P
S5dk0=[mB
G[odztd
8\O^#L
*)L>!jU
Ob79^
cm.+j+
[Ko/l
7j|i<k1'
QbNh'*c
{U`[KS
@]/.,5|o
$J(~U%
3s;GL O(M
fO3xw$
Z)j}ow
@LUbOg
Yq4Qd*
H>YA]YV
9&)f+
;oo[H$
c9j0]
s~[uTg@
t$+dn2
t+9eh
yzP VZ
yy+~N"
+C9<n5Z
/FV[bR
g}YkBpw
'CnY4V
jEaNxm
VBD?4Z
s|QLY3NO
vdzVH
]4g'%?
wAeB >(
yq[/N`
v?|;1fB
zE~`-i
D>r0f+qk
y(BQV+\7
Po'Lfx
t=E, sR
1>[JXp+]
>,gp?Y
*=aLk*W
(AGK'X
(b@50'a
1mh;vYR
aqMicz
+*aGI
7d-:g-
Q<GYzJ
6%7+"]
"2HA`2lag
mgQGZq
mcg{\
0cq#I~
M8zf-d`
GqSxwbe
>gQ!6
>EY`Tr&=0
|,x>-|a
{H1qmo
>sx*wIf
4cr7|,)C
pti+8'e
sb~~~m
a{6,mR
w2sfT^EV/
Q7i5P
c0\Hl1A
#D{cP6W
"5l }F
pJuo%e
zB)Zq+
8C?Xth
~GfGXD
$"#P&<
wdEO+{
&]/LsG6eA3I<y
vbRB^-
C]MIjG
GL{+7@
1`n!cl[
Ap\nJK
4^aHI_
_[fXL)
vb|s9?
+ylq=h
-oC/rh
&qH]=4
/ql3<+u:k&"
wI{X$T
[&(Tn;
B07{Nx
-m"I(Oa
.Rm<.4T(<
%{WZ"=~"
Ra{tk
Fp>qom
{~%_6O
?kjiS#
%f2(vPFh(
^1dUo}7
a@rb!f
K/Nv#t
>4L<ie
]YSm8H
Q@OEwN
gZB$rj1
p:3[6#C~
wT!]7rv
}tZ |
:qq|q;2
*8dm,;
Y@2<C|
FSl`*R
$)[nV|
*9`%U!
z^]{7:[+
ayK&=g
m'&vXK}B
6{RY\B
#"|U4B
\m*Z>g<
8|sV7o
zy(~.Q/h
CEa,b$
v=O*q
%+LT}K[
yX| n7&
:XRp[g
X'|Sn`
=b-krHB
n9UurPK]A
{c>SOp
''i#]?
%DW4L{"y
s)'c0fU
UA6S Drk
s)H b,
5$k~INL
j;:8r2^
H$g/W*
P !|=o
0"Hke&
bUG%9!
7d=y[m
RC<vDj
4j*m6R
NJ2U*f@
h1SI|z
<xno?Q
IO~`:^D
^+1{$M
w"ph~1=
Zf ~GB
?xqYxH
|~#$y9
=)1Z,$k
xH+l/L
Vig7H1 X
ir)fEO
Mn0{Ib
rV}Wr#
'Y2\|.
Lh^X/n
(c,u0=8F
T4 jp>{
LL?qj=
MI%_N]
`jnk~+*&I
ycgjPgO
M]+K'.
>>_MfV
z.u`W.
=<lSa&
}o+g$yO
h<Ez-+
oo/{2#2
=#~gn[I
6qtnkdp
a:Jm(m
ee<p}9=MD*
LqNj5E
l#4ms0i
i@6Aw<pLk1"S{
XAa*3FP
4f`~7O
Cz`pD#
8cP2^]
TW.\{16\
X'2y{t
a-?|~#
i2 ,hB
wA~6D5]
U_M0;-
|/r/w(k4
6]OvYZG'
n)'U"D'
YeV]jq
UFim*6}O^
`%35Y`:
QqdQ8e
H6j(zt
5jj*kVY
3aw,T{
qo_Ch`
FM^u-=:'J
uDC.me&
d$>z>.)fVOY
,d9i(Q0l
(a1}e1+
o*D)R'
VHt{a8i
:%1T'9J^
=uyX;|n
ndb)T1
M|dcYO
,WNY^+
|t\l8_\
>1GwT@k
Ygl!1R
TP:\W@
*NJW%Fx
hU4[1V
!"n4QI
9-P?D^H
f#$9%O
!-|BcO!
@Yx9*r
._U%UBw
[56{49
!a:rLg
(jK3\"
kw~tdl
LXD08I<
sTN_]e
bj_G8.Z
E34VgNz
.ERHQ
gaC!t`[
5@=;`[
X02#Ec
l6OZ4F
X[eJWV
Wy1&ap
Y_4(q7z@t
WzqB2X1
z295br
RlJzk5
1c*{x
W'C62}:V
iD1rBA
's6>Q^
?DJ`*ax
s}NIEC
oDP^"8
S;_nyG
t&Lw?J'
4ql|T]
Kou8nE
6=kn5v
>UUn6~P
@W*GIjF
0~l>qS
FvPJDas7Si{
{nW3=\
@Rl@>i{
Xw$n^
X7;Po{
$Ed\6t
LRC/,o&
JxLL:i
19!>\@
o51n{+
4%chWd
9|+ZA4
@s ~t<J
M4J~1#
Ii2,3{
z"'0.R
hCO)Ne~
5Vj7vo
d>RQwl^n
@lr+{4|
]][4)w
Fl35!J[/
.r&#h%
6Vs|LG-c
l,DK>Q
zsv(dz
)wE+5nVly
uL\ bt
*m<SK"
LeIY=^=x
UmRW3,&
h^|r`d{F
M]Ss7d
bQ,ve
Igsn]A
el$Fl a
eXh_)"
Ua13k(^
GI|<V
,;2XHr
kdUG+
H]d9Q4y)B
1?ZcT'
daW3%xc
n@{]Sn
v X,_Q
itl40M
1g~[C5
2;L:';
P.rvCbOU
j5Ayw)8z
:<.bFw0
oR)$wY4vn
R-@.DV
2C,4w
~V/NPbFR
3|F0PBG
;`faW=
4T8!mj
loMXh
! Z;R5S
WMVY >c
`jlhu}
ZHT~Q.
wsDF[Xy
:7-|Q|
vF"dzZ
m6WoGZw4
IZ 7;
F|~^?o>i^U
^Z)p3XU
G(cxn"5
Uit[?pU
FOIGN5
o^C;TEnfL
a>cWs>m
Nmd9QI2
S,,WR'
}[fIwG
Sy}tAzx
TAG<50D
x{OXwF^%=
oxlbsI
aFoQeo
hN7OP[
xJoX2
9b"+7%
ku.V*X
%Ip*7V
1 Z58A
y;86$_
^t5s>s
-5{K\=
i;TS!z
@Y5k9t
w<Nx8j
/pI70
dRI\}Oq
pY;nZ\BLN
)l'9a"
s=p4|O
I4$ExHP
azD|J[
C7:6h/Jb
n1j=(R~J
&S^TB!
RJ.M;
W;K#*_
-J&~#D-
]$,*m0
I$ . .
ve<949
7j~1%[
4+}y&&%&
s_x2,,
nQ j4S
?ayeRE
Q!7~~
BI:C;2
*s3|NS
)O+\t6
`7H"xI
hxEsR3p#
s-O9 2Z
z>V} R>v
!yUKlu
K_p`js
zw'4AV
/vZkQa
q;S,k\
QobGTJf
.n591U
B$R/KV`e
(m5dhj
u%}uVV
.[}(1[X*
1;Cd[}1
FQZ>oO
3NK~!(
t#_/l;
'`+a/
vg4s@Y
clXXv*w
l8O6DLe
%dXl82=
`6U~e*F ]
<RNoIJ
_RvMFm
7[aBI
Wb>`e
R?2v>hu
t:l(xL
-xtU>2
~rWa10
lNO`o
Y';|?e;
j8,l~W
!Qo<R!
~4nA\L
mlb_J-
&%dv"W
=6jC#K
'PZVTJD4K
]ts^I$d
IsVV0D
%51}ZR
KVs$P*
6`-{NX0
.=rpRP]
bO:21]
B?3R/.!n5Y
49}{Hm
q%rRgO
4B=9(W70
rTPeO2v
i|G96_
=|h_dy
34iDB-n
-n4$hqF
;bCgC{E
BVjX7*
^(%&R*
;`yhyp
[Kyr`%
yL%2tAx
r~P#z2%
" I{bc
dmJN(j
H~8KJ=
qF;CV~
`dfC?s
Lx?z[/
aENlKg
k3Eet6T
F84b;P
|yR-@]
*2X*`u'
aA1uEe
j3Q(ph
35V#bl
bEBhZa
IyF@Od
gZ6emo6F
b 3G)!
5L@EHi
8O.[7hb
,|ne,=
<@^18;6
Dn!brvGR
LO\]v0
->s ok3
Y=|s9-
}dEze6&
3LZ"vU
_4MR'R
&MUmN5
=ho{<e
rwQ(% c
'KI8Bg
^=n};!
SXm-%8
#j_8znA5#
x`j6w4d
hIZR")
/av4X2
-5[i*&
8&D_FS;
v2+S _&
-\@<]+v
TdBom]
PPE#`3^
y~>tI{p
%&SV[y
r{*4[p
IWRT"b
#'PHc+^t3
S+<!P7h
iPFOQ
M^7Uf{
L{_km&
bgx"eG
gY[fh[9
,OV*pJ
@aca/>,M1
~F}u.t
H>)XNx
<W4V'dlL
uj4\Fe
-,~qjd
6%02Jro
sZ#nr`
A,jTP/"
s6'lB>
JYc8.%
[EE:2,
('+:aw
GWQv$$mh
Tp{oNG
UF`Pg9
o>,7\6"
ke1U,4X
+FBTBRX
uij>ulp
V&bu|&
]teAs7
Lp`6dc[
vmxdTD
5E\nPx
#9iA;>
~/@0{S
JcK<4T
iiOnoSO
bad allocation
string too long
invalid string position
Unknown exception
CorExitProcess
runtime error
TLOSS error
SING error
DOMAIN error
An application has made an attempt to load the C runtime library incorrectly.
Please contact the application's support team for more information.
- Attempt to use MSIL code from this assembly during native code initialization
This indicates a bug in your application. It is most likely the result of calling an MSIL-compiled (/clr) function from a native constructor or from DllMain.
- not enough space for locale information
- Attempt to initialize the CRT more than once.
This indicates a bug in your application.
- CRT not initialized
- unable to initialize heap
- not enough space for lowio initialization
- not enough space for stdio initialization
- pure virtual function call
- not enough space for _onexit/atexit table
- unable to open console device
- unexpected heap error
- unexpected multithread lock error
- not enough space for thread data
This application has requested the Runtime to terminate it in an unusual way.
Please contact the application's support team for more information.
- not enough space for environment
- not enough space for arguments
- floating point support not loaded
Microsoft Visual C++ Runtime Library
<program name unknown>
Runtime Error!
Program:
EncodePointer
DecodePointer
FlsFree
FlsSetValue
FlsGetValue
FlsAlloc
bad exception
GetProcessWindowStation
GetUserObjectInformationA
GetLastActivePopup
GetActiveWindow
MessageBoxA
USER32.DLL
_nextafter
_hypot
Complete Object Locator'
Class Hierarchy Descriptor'
Base Class Array'
Base Class Descriptor at (
Type Descriptor'
`local static thread guard'
`managed vector copy constructor iterator'
`vector vbase copy constructor iterator'
`vector copy constructor iterator'
`dynamic atexit destructor for '
`dynamic initializer for '
`eh vector vbase copy constructor iterator'
`eh vector copy constructor iterator'
`managed vector destructor iterator'
`managed vector constructor iterator'
`placement delete[] closure'
`placement delete closure'
`omni callsig'
delete[]
new[]
`local vftable constructor closure'
`local vftable'
`udt returning'
`copy constructor closure'
`eh vector vbase constructor iterator'
`eh vector destructor iterator'
`eh vector constructor iterator'
`virtual displacement map'
`vector vbase constructor iterator'
`vector destructor iterator'
`vector constructor iterator'
`scalar deleting destructor'
`default constructor closure'
`vector deleting destructor'
`vbase destructor'
`string'
`local static guard'
`typeof'
`vcall'
`vbtable'
`vftable'
operator
delete
__unaligned
__restrict
__ptr64
__clrcall
__fastcall
__thiscall
__stdcall
__pascal
__cdecl
__based(
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
GAIsProcessorFeaturePresent
KERNEL32
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
HH:mm:ss
dddd, MMMM dd, yyyy
MM/dd/yy
December
November
October
September
August
February
January
Saturday
Friday
Thursday
Wednesday
Tuesday
Monday
Sunday
CONOUT$
SunMonTueWedThuFriSat
JanFebMarAprMayJunJulAugSepOctNovDec
1#QNAN
1#SNAN
bad allocation
kixucigehorosaxuyumugavek
gigezexolepapenaluvofiyiyosogovamovuvokopojuhutatunecezopokaduyu
duwoyisewekehalowazikazidamulacokiwesamehatazaku
kernel32.dll
LocalAlloc
VirtualProtect
RSDS{m
C:\kipudof88\gagazaf\48.pdb
GetSystemDefaultLangID
GetLocaleInfoA
LoadResource
EndUpdateResourceW
InterlockedDecrement
GlobalSize
GetEnvironmentStringsW
WaitForSingleObject
AddConsoleAliasW
SetEvent
ReadConsoleW
FindActCtxSectionStringA
GetCommandLineA
GlobalAlloc
GetSystemWindowsDirectoryA
LeaveCriticalSection
GetModuleFileNameW
ReleaseSemaphore
GetConsoleOutputCP
GetProcAddress
EnterCriticalSection
VerLanguageNameW
WriteConsoleA
GetProcessId
ProcessIdToSessionId
LockResource
BeginUpdateResourceA
GlobalGetAtomNameW
SetSystemTime
EnumResourceTypesW
GetModuleFileNameA
GetModuleHandleA
EraseTape
FindFirstVolumeW
KERNEL32.dll
RealChildWindowFromPoint
USER32.dll
GetCharWidth32A
GDI32.dll
HeapAlloc
GetLastError
HeapReAlloc
GetStartupInfoA
RaiseException
RtlUnwind
TerminateProcess
GetCurrentProcess
UnhandledExceptionFilter
SetUnhandledExceptionFilter
IsDebuggerPresent
HeapFree
DeleteCriticalSection
VirtualFree
VirtualAlloc
HeapCreate
GetModuleHandleW
ExitProcess
WriteFile
GetStdHandle
SetHandleCount
GetFileType
SetFilePointer
FreeEnvironmentStringsA
GetEnvironmentStrings
FreeEnvironmentStringsW
WideCharToMultiByte
TlsGetValue
TlsAlloc
TlsSetValue
TlsFree
InterlockedIncrement
SetLastError
GetCurrentThreadId
QueryPerformanceCounter
GetTickCount
GetCurrentProcessId
GetSystemTimeAsFileTime
InitializeCriticalSectionAndSpinCount
LoadLibraryA
SetStdHandle
GetConsoleCP
GetConsoleMode
FlushFileBuffers
HeapSize
GetCPInfo
GetACP
GetOEMCP
IsValidCodePage
WriteConsoleW
MultiByteToWideChar
LCMapStringA
LCMapStringW
GetStringTypeA
GetStringTypeW
CloseHandle
CreateFileA
.?AVlogic_error@std@@
.?AVlength_error@std@@
.?AVout_of_range@std@@
.?AVtype_info@@
.?AVbad_exception@std@@
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
.?AVexception@std@@
.?AVbad_alloc@std@@
GFZT-,
jY]Yb/
MMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMM+
CD5MMMMM
czMMMMMM
MMMMMMMf]
~MMMMMMMST
MMMMMMMM
_MMMMMMMMMM)
dMMMMMMMM
sNZz:B\
$EdtX8
=YqD.~
N

#

#
wYyy,i
A$#
#
#
#
i]E"Xa
#
#
=};;IQ
#







Cx

T

%-%oeoYy
Y&@R&:n
hx

T


jQ?
x

?
T
w\jTTZD
e42QQZ`4
T?

x?)
)Q


,,;',,@



NN11N_11)
Qu3un3H
UUUUUUUUU
UUUUUUUUU
UUUUUUUUR
UUUUUUUU
UUUUUUUUR
*UUUUUUUU
*UUUUUUUU
UUUUUUUU
UUUUUUUU
UUUUUUUU{
UUUUUUUU{
UUUUUUUU{
UUUUUUUU
UUUUUUUU8RT
s]UUUUUUUUR
T]UUUUUUUU
UUUUUUUUI
9UUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUU
.3+.ggo{z}
:gx-Z
GWD7lvo|
|{<{z~
llllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllll&
&llllll
EEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEE
llllll
llllll
llllll
********
llllll
******
llllll
***********
llllll
******
llllll
*********
llllll
*******
llllll
**********
llllll
********
llllll
zM**********
llllll
******
llllll
*******
llllll
*******
llllll
llllll
*X*****
llllll
X******
llllll
XX*****
llllll
*X*****
llllll
XX******
llllll
*X*****
llllll
XX****
llllll
llllll
llllll
llllll
llllll
???????????
llllll
llllll
llllll
llllll
llllll
llllll
PPPPPP>>>>eeee
g))))F
llllll
llllllllllllllllllllllllllllllllllllllll
llllllllllllllllllllllllllllllllllllllllll
llllllllllllllllllllllllllllllllllllllllllll
llllllllllllllllllllllllllllllllllllllllllllll
llllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllll
ffffffffffffff
f%f%%%%%%%%%
f%f%f%f%%%%%%%
ff%f%%%%%%%%%%%%%
ff%f%f%f%%%%%%
fff%f%f%%f%%%%%%%%
ff%ff%f
f%%%%%%%%
ffff%f%u,
%%%%%%
ffffff
fff%f%fzQ
fffffff
ffffff
%%%%%f%
%%%%ff
{{{{{{{{
{{{{{{{{{{{{{{{{{{{{
FFFFFFFFFFFFFFf
ttf&]f
{{;;;;;;;;;f&
Yf{{;Pvv
6dhhZ&
K{{;;;;;;;;;;;
f{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{
/LYqg7h
&;H\G'Y
Giluhipekiyac bobajutux. Dikahimehinapul. Velodumipoco. Cepubahutixok. Yiroj cihuciwocaxif vorib. Nosewusarepal hisimezec wuw namubilaxajokub xevowehat. Dedamacubumez rub vera zayutakecihi hurone. Xilocecalo liyezetula kuwocorayarid xesati vafefexa. Jisapecote xiko xeno. Veh. Citakecutanerag fipo. Wodo yuyigi zijinu jepuhusoyosesis vim. Gelazo xowugohizito. Bucaneyelowiseb hun. Vafesilo voxuzeriyosono gehasup. Gezosahuje maroroji pajoxemewafoj cufas nawar. Hisuxogu givimiwah. Xudirazoraw nexapawizusik sisi wemerehimawewik. Pojufi fugederu mija kuzolizumabu. Fidiloraloh numiborun guguje zuxax kapamemahuw. Corubuxufibit gazijigojajume zinihekekisasok nuf. Javimufayaki cayukid. Magudazegugen yeniloboxihebib zolod kitaweyixoha donexal. Betubemukacewo zuwuvegiger rososi. Vadal vizotocime. Davejafocapu lufasuk woc. Tafuyo xejosiconoruyi. Wabubesaxajolar josidokono vekej. Dorivivaf wupoxosetato cupidawujejar ludezemedujo pulaz. Rug dog hape tidoxiyekihake yerixikukikomiw. Jonokek nupitavimusi. Curiwon kesedofireh pe
mscoree.dll
KERNEL32.DLL
F|FxFtFpFlFhFdF`F\FXFTFPFLFHFDF@F<F8F,F F
((((( H
h(((( H
H
wujuyaxofiwegiyisebeze
FIBOLUWAWABUROBI
VS_VERSION_INFO
StringFileInform
020224a6
InternalName
sojbmoeminu.ihe
Copyright
Copyrighz (C) 2021, fudkagata
ProductVersion
8.19.590.38
VarFileInfo
Translation
UJoyuxumahare zagimas pez lugiya fapijoxamaber lumemax yumacabe kawajadapufu cuwutotil
Pahuwezehop xayeluhopuwovul
Gacewitiduvifek ratikamokesoli
Zefavoni situzixotezaji nawo
]Xoferakuxebub fosi vag waloc kosizabeceboge hoducixecak rimu cijinekubojabiz gaj cuwapihenizacWajoxemorusebo tonabozazek ludepe japevusajinelu subeketo leyu matojiloziwoho fofoziwedema kuxiyame9Heposotosofuka sategawe xuvobobuwog valesag pifexudifohup
Pukoyafinezo vegat bijuciw vobublFomegihumawonoc tizexekekude lamecakeloriya gemo kalipiyojecora siyafevozoluvi fonicuyukutoxes yuximaterisij-Xevi cujasahiyupurot pixinufu falevu lerotiri
[Nuxigih vimuwataretizi renafipa gugodamadabi vucitup mahivob nuzuwakodufibet helevugumacalebZuvic zatecel cunayoseve nilekuvucuj dunakam hiconavetukay kazisejayo tiseponiye jatedafaxu zuvozaDJuxuzuwogeg kinudacawumal guyuvig toxixiguce guwamuheruhoyok guruvop<Hohoxorekaje xipa tabilexojenu zenad heziporayunigi pakirobu5Juwetetudav rapey cisuzigicisux jafadija kucelimomido
Decut nakiraw daruxu
USurocexij fisufofizojufu rocu hagonisimeh guvekolawu cotedepu jivebenigikinot canukevTYituxaduraciyoz ceritet capoy bekafuk jek yobaxigematewu saxe gesixeniy jasumolubuwa1Lecifeyayum fogevesudazu besilibavicefa xukutudefQTujigupoh gogaru vubataloyil safoyax guy tuguxefipazeyeh vujilenexo vazemafi buweGWeyagur potufocalewaw manuvacigut maxug rohizujawuv susobezedatusa koye
Antivirus Signature
Bkav W32.AIDetect.malware2
Lionic Clean
Elastic malicious (high confidence)
ClamAV Clean
CMC Clean
CAT-QuickHeal Clean
ALYac Clean
Cylance Unsafe
Zillya Clean
Sangfor Trojan.Win32.Save.a
K7AntiVirus Clean
BitDefender Clean
K7GW Hacktool ( 700007861 )
CrowdStrike win/malicious_confidence_100% (D)
Baidu Clean
Cyren W32/Kryptik.EWJ.gen!Eldorado
Symantec ML.Attribute.HighConfidence
ESET-NOD32 Clean
APEX Malicious
Paloalto Clean
Cynet Malicious (score: 100)
Kaspersky UDS:Trojan.Win32.Zenpak.gen
Alibaba Clean
NANO-Antivirus Clean
SUPERAntiSpyware Clean
MicroWorld-eScan Clean
Rising Trojan.Kryptik!1.D977 (CLASSIC)
Ad-Aware Clean
Emsisoft Clean
Comodo Clean
F-Secure Clean
DrWeb Clean
VIPRE Clean
TrendMicro Clean
McAfee-GW-Edition BehavesLike.Win32.Generic.gc
FireEye Generic.mg.01b2e0187b466e21
Sophos ML/PE-A
Ikarus Clean
Jiangmin Clean
Webroot Clean
Avira Clean
Antiy-AVL Clean
Kingsoft Clean
Microsoft Trojan:Win32/Sabsik.FL.B!ml
Gridinsoft Clean
Arcabit Clean
ViRobot Clean
ZoneAlarm Clean
GData Clean
TACHYON Clean
AhnLab-V3 Clean
Acronis suspicious
McAfee Clean
MAX Clean
VBA32 Clean
Malwarebytes Trojan.MalPack.GS
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Tencent Clean
Yandex Clean
SentinelOne Static AI - Malicious PE
eGambit Unsafe.AI_Score_92%
Fortinet Clean
BitDefenderTheta Gen:NN.ZexaF.34170.Eq0@aWKr6KeO
Avast Clean
MaxSecure Trojan.Malware.300983.susgen
No IRMA results available.