Static | ZeroBOX

PE Compile Time

2020-07-11 19:10:58

PDB Path

C:\tipirupe_tazixalufo.pdb

PE Imphash

00e4a9909e1dd2f9b23ab751bea778c3

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x00022b80 0x00022c00 7.49061279143
.rdata 0x00024000 0x00005a6b 0x00005c00 4.44528028494
.data 0x0002a000 0x0000c3f4 0x00002600 2.73958059009
.rsrc 0x00037000 0x0006a518 0x0001c600 6.38042846253

Resources

Name Offset Size Language Sub-language File type
RT_CURSOR 0x00052388 0x000008a8 LANG_NEUTRAL SUBLANG_NEUTRAL dBase III DBT, version number 0, next free block index 40, 1st item "\251\317"
RT_CURSOR 0x00052388 0x000008a8 LANG_NEUTRAL SUBLANG_NEUTRAL dBase III DBT, version number 0, next free block index 40, 1st item "\251\317"
RT_CURSOR 0x00052388 0x000008a8 LANG_NEUTRAL SUBLANG_NEUTRAL dBase III DBT, version number 0, next free block index 40, 1st item "\251\317"
RT_ICON 0x00050e58 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00050e58 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00050e58 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00050e58 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00050e58 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00050e58 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00050e58 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00050e58 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00050e58 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00050e58 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00050e58 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00050e58 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00050e58 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00050e58 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00050e58 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00050e58 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00050e58 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00050e58 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00050e58 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00050e58 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00050e58 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00050e58 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00050e58 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00050e58 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00050e58 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00050e58 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00050e58 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00050e58 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00050e58 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00050e58 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00050e58 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_STRING 0x000530f8 0x0000041e LANG_ENGLISH SUBLANG_ENGLISH_TRINIDAD data
RT_STRING 0x000530f8 0x0000041e LANG_ENGLISH SUBLANG_ENGLISH_TRINIDAD data
RT_ACCELERATOR 0x00051380 0x00000018 LANG_ENGLISH SUBLANG_ENGLISH_TRINIDAD data
RT_ACCELERATOR 0x00051380 0x00000018 LANG_ENGLISH SUBLANG_ENGLISH_TRINIDAD data
RT_GROUP_CURSOR 0x00052c30 0x00000022 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_GROUP_CURSOR 0x00052c30 0x00000022 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_GROUP_ICON 0x00044260 0x00000068 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_GROUP_ICON 0x00044260 0x00000068 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_GROUP_ICON 0x00044260 0x00000068 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_GROUP_ICON 0x00044260 0x00000068 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_VERSION 0x00052c58 0x000001b4 LANG_NEUTRAL SUBLANG_NEUTRAL data

Imports

Library KERNEL32.dll:
0x424000 GlobalDeleteAtom
0x424004 GetLocaleInfoA
0x424008 HeapAlloc
0x42400c EndUpdateResourceW
0x424018 ReadConsoleA
0x42401c GetCommandLineA
0x424020 CreateActCtxW
0x424028 GlobalAlloc
0x42402c CopyFileW
0x424030 FreeConsole
0x424034 HeapCreate
0x424038 FindNextVolumeW
0x42403c GetFileAttributesW
0x424040 lstrlenW
0x424044 FlushFileBuffers
0x424048 DeactivateActCtx
0x42404c InterlockedExchange
0x424050 GetProcAddress
0x42405c ResetEvent
0x424060 WriteConsoleA
0x424064 RemoveDirectoryW
0x42406c GetTapeParameters
0x424074 GetModuleFileNameA
0x424078 SetConsoleTitleW
0x42407c GetModuleHandleA
0x424080 EraseTape
0x424084 VirtualProtect
0x42408c SetCalendarInfoA
0x424090 GetCurrentProcessId
0x424098 FindNextVolumeA
0x42409c lstrcpyW
0x4240a0 CreateFileA
0x4240a4 WideCharToMultiByte
0x4240b0 MultiByteToWideChar
0x4240b4 Sleep
0x4240c4 GetLastError
0x4240c8 HeapFree
0x4240cc TerminateProcess
0x4240d0 GetCurrentProcess
0x4240dc IsDebuggerPresent
0x4240e0 HeapReAlloc
0x4240e4 GetStartupInfoA
0x4240e8 GetCPInfo
0x4240ec RtlUnwind
0x4240f0 RaiseException
0x4240f4 LCMapStringW
0x4240f8 LCMapStringA
0x4240fc GetStringTypeW
0x424100 VirtualFree
0x424104 VirtualAlloc
0x424108 GetModuleHandleW
0x42410c TlsGetValue
0x424110 TlsAlloc
0x424114 TlsSetValue
0x424118 TlsFree
0x42411c SetLastError
0x424120 GetCurrentThreadId
0x424124 SetFilePointer
0x424128 CloseHandle
0x42412c ExitProcess
0x424130 WriteFile
0x424134 GetStdHandle
0x424144 SetHandleCount
0x424148 GetFileType
0x424150 GetTickCount
0x424158 GetStringTypeA
0x42415c HeapSize
0x424160 GetACP
0x424164 GetOEMCP
0x424168 IsValidCodePage
0x42416c GetUserDefaultLCID
0x424170 EnumSystemLocalesA
0x424174 IsValidLocale
0x42417c SetStdHandle
0x424180 GetConsoleCP
0x424184 GetConsoleMode
0x424188 LoadLibraryA
0x42418c GetLocaleInfoW
0x424190 GetConsoleOutputCP
0x424194 WriteConsoleW

Exports

Ordinal Address Name
1 0x401763 @GetFirstVice@8
!This program cannot be run in DOS mode.
`.rdata
@.data
FFYY;t$
FFYY;t$
t,h@kB
uJVVVVV
G09_(u
SVWj>3
0WWWWW
0WWWWW
QQSVWd
uQhPBB
^SSSSS
^SSSSS
0SSSSS
GWhpLB
t"SS9]
0SSSSS
t$htLB
tNIt?It0It
u&h`SB
>=Yt1j
j@j ^V
FVhpLB
HtHu4j
s[S;7|G;w
YYh TB
tR99u2
C PjPV
C$PjQV
C*PjTV
C+PjUV
C,PjVV
C-PjWV
C.PjRV
C/PjSV
0A@@Ju
0SSSSS
PPPPPPPP
0SSSSS
tNhL]B
t=hH]B
Vj@hpZB
u%hP]B
PPPPPPPP
t+WWVPV
URPQQh
u,VVWV
t VV9u
;t$,v-
UQPXY]Y[
_VVVVV
^WWWWW
0SSSSS
_VVVVV
<+t(<-t$:
+t HHt
<=DM#r
<=DM#r
0<=DM#r
<=DM#r
{[kyYikO
;Pmn!r/
kB@wZA]
zGY2H<
wv)9S]O
z*Gv\8"h
!jX18
CMQ%c4
;U'LUw
AQAD]k
BEG?i6
A&B]2[
{rd#B&
FAu1M"Z
.G[[@Z
^Wf~sy
\-7:Dt(w
(Q{Y8P
0I_+3v
Tf0&F1Q
%~$!lB
e{L{O^
>1k!\0O
RSw{$'
n+BEBa
aVi+_$
16O7`x
gp{a,\`|V
*<=~O%T<,
yC`gE);
DSLD)::
RiX`=6
%6'MGa
ExSWLl:w
}cWt{K
#Le3(`H
1EHvd}
PdKE~gG#
,g |E2\O
"0)+[v
o[6tJO
2c#)(F
N@{dSf
J}6OEL
R7Rj7=
fQ=4SL
yg|RYkB
C>W!h3p
K+bD'EF,
E=B\EH
w4\Mt@
^_k8G$
83`Ts
m-+15R
.Df/{I
E$uO]W
)0R!;Z@
a=!m'Ik
*l0 Dg
R~`)T9
xaV*!.
P7E63#
]`HVxSO
RK6F@S
ae#\ $
n]5t%Lt/n8
ow)-^K
d/FjLS
/qJ5:@Zw
'/)d_5?
_UU|BG@
Pw?f,T
urijN[
;,HRUg
5rHJNV
9Izk_H
hqu{<$
(>ncR.s
!3XJ:|jFR>
"n{N!d
|<N!E>F
[!].OfE
xcS-,\"&
MozOP
wU.97]
IW 8]S
x3Xw&j
55.y^P
n\S-KY4
bRZCF
0s0k`Cq
f#s\7
=c~Xnnqd
.Ec/&3
f)}15Z
sPN/Dk
#4sl(p
5(d":P
&Sm*=&
I!RA&]
F8Rs?k
bpZj#[j
bad allocation
string too long
invalid string position
Unknown exception
LC_TIME
LC_NUMERIC
LC_MONETARY
LC_CTYPE
LC_COLLATE
LC_ALL
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
EncodePointer
DecodePointer
FlsFree
FlsSetValue
FlsGetValue
FlsAlloc
CorExitProcess
runtime error
TLOSS error
SING error
DOMAIN error
An application has made an attempt to load the C runtime library incorrectly.
Please contact the application's support team for more information.
- Attempt to use MSIL code from this assembly during native code initialization
This indicates a bug in your application. It is most likely the result of calling an MSIL-compiled (/clr) function from a native constructor or from DllMain.
- not enough space for locale information
- Attempt to initialize the CRT more than once.
This indicates a bug in your application.
- CRT not initialized
- unable to initialize heap
- not enough space for lowio initialization
- not enough space for stdio initialization
- pure virtual function call
- not enough space for _onexit/atexit table
- unable to open console device
- unexpected heap error
- unexpected multithread lock error
- not enough space for thread data
This application has requested the Runtime to terminate it in an unusual way.
Please contact the application's support team for more information.
- not enough space for environment
- not enough space for arguments
- floating point support not loaded
Microsoft Visual C++ Runtime Library
<program name unknown>
Runtime Error!
Program:
bad exception
HH:mm:ss
dddd, MMMM dd, yyyy
MM/dd/yy
December
November
October
September
August
February
January
Saturday
Friday
Thursday
Wednesday
Tuesday
Monday
Sunday
united-states
united-kingdom
trinidad & tobago
south-korea
south-africa
south korea
south africa
slovak
puerto-rico
pr-china
pr china
new-zealand
hong-kong
holland
great britain
england
britain
america
swedish-finland
spanish-venezuela
spanish-uruguay
spanish-puerto rico
spanish-peru
spanish-paraguay
spanish-panama
spanish-nicaragua
spanish-modern
spanish-mexican
spanish-honduras
spanish-guatemala
spanish-el salvador
spanish-ecuador
spanish-dominican republic
spanish-costa rica
spanish-colombia
spanish-chile
spanish-bolivia
spanish-argentina
portuguese-brazilian
norwegian-nynorsk
norwegian-bokmal
norwegian
italian-swiss
irish-english
german-swiss
german-luxembourg
german-lichtenstein
german-austrian
french-swiss
french-luxembourg
french-canadian
french-belgian
english-usa
english-us
english-uk
english-trinidad y tobago
english-south africa
english-nz
english-jamaica
english-ire
english-caribbean
english-can
english-belize
english-aus
english-american
dutch-belgian
chinese-traditional
chinese-singapore
chinese-simplified
chinese-hongkong
chinese
canadian
belgian
australian
american-english
american english
american
Norwegian-Nynorsk
_nextafter
_hypot
Complete Object Locator'
Class Hierarchy Descriptor'
Base Class Array'
Base Class Descriptor at (
Type Descriptor'
`local static thread guard'
`managed vector copy constructor iterator'
`vector vbase copy constructor iterator'
`vector copy constructor iterator'
`dynamic atexit destructor for '
`dynamic initializer for '
`eh vector vbase copy constructor iterator'
`eh vector copy constructor iterator'
`managed vector destructor iterator'
`managed vector constructor iterator'
`placement delete[] closure'
`placement delete closure'
`omni callsig'
delete[]
new[]
`local vftable constructor closure'
`local vftable'
`udt returning'
`copy constructor closure'
`eh vector vbase constructor iterator'
`eh vector destructor iterator'
`eh vector constructor iterator'
`virtual displacement map'
`vector vbase constructor iterator'
`vector destructor iterator'
`vector constructor iterator'
`scalar deleting destructor'
`default constructor closure'
`vector deleting destructor'
`vbase destructor'
`string'
`local static guard'
`typeof'
`vcall'
`vbtable'
`vftable'
operator
delete
__unaligned
__restrict
__ptr64
__clrcall
__fastcall
__thiscall
__stdcall
__pascal
__cdecl
__based(
GetProcessWindowStation
GetUserObjectInformationA
GetLastActivePopup
GetActiveWindow
MessageBoxA
USER32.DLL
SunMonTueWedThuFriSat
JanFebMarAprMayJunJulAugSepOctNovDec
GAIsProcessorFeaturePresent
KERNEL32
CONOUT$
1#QNAN
1#SNAN
bad allocation
cehiwah manamuxezexemuwetesaxuzaduzawor
darujuwihunuyun zabebedidez zizofokajitaxipogejipubowexo gifitutatopumiduc deguvofagebifut
VirtualProtect
kernel32.dll
LocalAlloc
Milike japo xulogelo
ios_base::badbit set
ios_base::failbit set
ios_base::eofbit set
bad cast
C:\tipirupe_tazixalufo.pdb
GlobalDeleteAtom
GetLocaleInfoA
HeapAlloc
EndUpdateResourceW
InterlockedIncrement
GetQueuedCompletionStatus
ReadConsoleA
GetCommandLineA
CreateActCtxW
GetEnvironmentStrings
GlobalAlloc
CopyFileW
FreeConsole
HeapCreate
FindNextVolumeW
GetFileAttributesW
lstrlenW
FlushFileBuffers
DeactivateActCtx
InterlockedExchange
GetProcAddress
BeginUpdateResourceW
EnterCriticalSection
ResetEvent
WriteConsoleA
RemoveDirectoryW
SetConsoleWindowInfo
GetTapeParameters
SetEnvironmentVariableA
GetModuleFileNameA
SetConsoleTitleW
GetModuleHandleA
EraseTape
VirtualProtect
GetFileAttributesExW
SetCalendarInfoA
GetCurrentProcessId
GetPrivateProfileSectionW
FindNextVolumeA
lstrcpyW
KERNEL32.dll
WideCharToMultiByte
InterlockedDecrement
InterlockedCompareExchange
MultiByteToWideChar
InitializeCriticalSection
DeleteCriticalSection
LeaveCriticalSection
GetLastError
HeapFree
TerminateProcess
GetCurrentProcess
UnhandledExceptionFilter
SetUnhandledExceptionFilter
IsDebuggerPresent
HeapReAlloc
GetStartupInfoA
GetCPInfo
RtlUnwind
RaiseException
LCMapStringW
LCMapStringA
GetStringTypeW
VirtualFree
VirtualAlloc
GetModuleHandleW
TlsGetValue
TlsAlloc
TlsSetValue
TlsFree
SetLastError
GetCurrentThreadId
SetFilePointer
CloseHandle
ExitProcess
WriteFile
GetStdHandle
FreeEnvironmentStringsA
FreeEnvironmentStringsW
GetEnvironmentStringsW
SetHandleCount
GetFileType
QueryPerformanceCounter
GetTickCount
GetSystemTimeAsFileTime
GetStringTypeA
HeapSize
GetACP
GetOEMCP
IsValidCodePage
GetUserDefaultLCID
EnumSystemLocalesA
IsValidLocale
InitializeCriticalSectionAndSpinCount
SetStdHandle
GetConsoleCP
GetConsoleMode
LoadLibraryA
GetLocaleInfoW
GetConsoleOutputCP
WriteConsoleW
CreateFileA
zusu.exe
@GetFirstVice@8
.?AV_Locimp@locale@std@@
.?AVlogic_error@std@@
.?AVlength_error@std@@
.?AVout_of_range@std@@
Copyright (c) 1992-2004 by P.J. Plauger, licensed by Dinkumware, Ltd. ALL RIGHTS RESERVED.
.?AVtype_info@@
.?AVbad_exception@std@@
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
.?AV?$ctype@_W@std@@
.?AUctype_base@std@@
.?AVfacet@locale@std@@
.?AV?$basic_stringstream@_WU?$char_traits@_W@std@@V?$allocator@_W@2@@std@@
.?AV?$basic_stringbuf@_WU?$char_traits@_W@std@@V?$allocator@_W@2@@std@@
.?AV?$basic_iostream@_WU?$char_traits@_W@std@@@std@@
.?AV?$basic_ostream@_WU?$char_traits@_W@std@@@std@@
.?AV?$basic_istream@_WU?$char_traits@_W@std@@@std@@
.?AV?$basic_streambuf@_WU?$char_traits@_W@std@@@std@@
.?AV?$basic_ios@_WU?$char_traits@_W@std@@@std@@
.?AV?$_Iosb@H@std@@
.?AVios_base@std@@
.?AVruntime_error@std@@
.?AVexception@std@@
.?AVfailure@ios_base@std@@
.?AVbad_cast@std@@
.?AVbad_alloc@std@@
5T!z[w
gTTs[T
2zwjdV
ttttttttttttttttttttttttttttttttttttW
vQttttttU
Z]+tttttto
tttttto,
tttttt
Stttttt
ttttttU
otttttt9
9ttttl
tttttt19o
wtttttttttttttttttttttttttttttttttt
B1r%X2_-
BBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBB
BBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBB
BBBBBBBBBBBBBBBBB
BBBBBBBBBgvp^
BBBBBBBBBBBBBB88(X{
8BBBBgv
;BBBBBBBBBBBBB
EBBBBBBBBBB
8BBBBBBBBB[
EBBBBBB
EBBBBBB
EBBBBBB
BBBBBBBi
BBBBBBB
wG|LL=LD
1TvBBBBBBB7
XBBBBBBBX
BBBBBBB
xDxxbxM
BBBBBBBBB
BBBBBBBBB
BBBBBBBBBB
XBBBBBBBBBBBBB
BBBBBBBBBBBBBB
BBBBBBBBBBBBBBB
BBBBBBBBBBBBBBB
;BBBBBBBBBBBBBBBBB
n|Mv_BBBBBBBBBBBBBBBBB
&8BBBBBBBBBBBBBBBB
;BBBBBBBBBBBBBBBBBB
%8BBBBBBBBBBBBBBBBBBB
8BBBBBBBBBBBBBBBBBBBBBBW]
8BBBBBBBBBBBBBBBBBBBBBB0
0*8BBBBBBBBBBBBBBBBBBBBBEN
v8BBBBBBBBBBBBBBBBBBBBBE
BBBBBBBBBBBBBBBBBBBBBE
EBBBBBBBBBBBBBBBBBBBBBE
BBBBBBBBBBBBBBBBBBBBBBc
EBBBBBBBBBBBBBBBBBBBBBBB
BBBBBBBBBBBBBBBBBBBBBBBBB
BBBBBBBBBBBBBBBBBBBBBBBBBBB
BBBBBBBBBBBBBBBBBBBBBBBBBBBBBB
*EBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBB
BBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBB
.................................................q
#....4
.....3
MX......[
.......5
C.......I
........
..........
........
xW_~@J^
'Gjw\?
,No~eH
KKKKrryv
<<VU$Zg
C1pppp
&pp&p~E
SSXXX(
www6666B
mmmmmmmmmmm
mmmmmmmmmmm
mmmmmmmmmmm
mmmmmmmmmmm
mmmmmmmmmmmNi
mmmmmmmmmmmo
ZmmmmmmmmmmmN
mmmmmmmmmmmV
mmmmmmmmmmm
mmmmmmmmmmm@
mmmmmmmmmmm
mmmmmmmmmmmN3
mmmmmmmmmmmV/*
mmmmmmmmmmmN/j
%mmmmmmmmmmmNuf
mmmmmmmmmmm
mmmmmmmmmmm
]CJJr
%mmmmmmmmmmm
%mmmmmmmmmmm
mmmmmmmmmmm
mmmmmmmmmmm
[7[777[F
mmmmmmmmmmmH(
mmmmmmmmmmmo
mmmmmmmmmmm
!\mmmmmmmmmmm
mmmmmmmmmmm
mmmmmmmmmmmmmmmmmm
mmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmm
#########
#########
########!
########
########!
########
########
########
########
########
########
########
########
6########~!
J########!
J########
########
c#########################################################################################################################################################
@zzzzzz
lzzzzz)m
VXzzzzz
:[3zzzzz
hzzzzzan
zzzzz1
szzzzz%
zzzzzz
9?,6nnw
NZJ8uxt
]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]
]]]]]]
OOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOO
]]]]]]
]]]]]]
0000000000000000000000000000
]]]]]]
]]]]]]
]]]]]]
]]]]]]
]]]]]]
]]]]]]
]]]]]]
]]]]]]
]]]]]]
]]]]]]
0000000
]]]]]]
00EP~Y
]]]]]]
00000000
0^PYVII
]]]]]]
000000
]]]]]]
0000000000B
]]]]]]
000000
]]]]]]
0000000@P
]]]]]]
0000000k
]]]]]]
000000
]]]]]]
000000
]]]]]]
000000
]]]]]]
000000
]]]]]]
000000
]]]]]]
]]]]]]
]]]]]]Kj
jK]]]]]]
]]]]]]
]]]]]]
]]]]]]
PW]]]]]]
NP]]]]]]
P]]]]]
PP]]]]
//////
P]]]]]]
P]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]P
P]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]P
P]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]PPP]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]P]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]
dddddddddddddd
dddddd
ddddddd
dddddd
dddddS
ffffffff
BBBBbbb
ffffffffffffffffffff
AAAAAA
AAAAAAA
AAAAAAAA
VVVVVV^^^
NP|%~~~~YYDD
"~~~~D
~~~~~~~~~~~~~~~~~~~~~Iz~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
uuuuuuuuuuuu
4Q\ym@j
,BL_L-^
iiiiii
iiiiii
iiiiiiiiiiii
iiiiiiiiii
iiiiii
iiiiiiiii
iiiiiiiiiiiii
iiiiiiii

((((( H
h(((( H
H
KERNEL32.DLL
mscoree.dll
dutudexiw
boxodexov rujavivokubecedubew lanokopipematonadofus pitoxabehobowerokinohogaxituk
gewudubudihewujawejurorivujetit
ruvalobibukuzefukeku
mumefere pavegurovi
miwipufurudugiciyumenuzujifuhuvutedizocuditejeyimitip
yojepajumoninoxugevotecokuyabapesuwayidamewakejivumatuturoguxowofukojurirotuyumiwim
kuhidukefub wijobijawimusago zalewijofuhuxukuyepanujonuz gohabiraposekenapogakafete calaluneyukuwaxetoyumafotamobi
Sekovufoyun romeru
kawoviwayome
Powu bekitahexozoman yoxefo
fijepojegabudoyepavototewodeleromazobiturejawumagatofa
/ P6pL
,/KPip
/-P?pR
/ P6pL
,/KPip
/-P?pR
VS_VERSION_INFO
StringFileInform
020224a6
InternalName
sajbmianozu.iya
Copyright
Copyrighz (C) 2021, fudkagat
ProductVersion
2.41.59.42
VarFileInfo
Translation
/Xuyahetumoral yukexuvuc buluku lawipi nofigasob
Puwimeneyimi
Wamejofic'Xayejosaropazo cuduzo yijufe xariwegoxi
Sor/Piyagog degud ranijupum ricaziledojasi pujesahocBikameviko sixuyacenafupi loko nebekunodufuge nipunahoreheh xigavopuh rek zolil zupo ragetifubodomiVMemoxalajewas gagokoci sejigubugazelo defepaya cagedazevawut fihew dijiraxi tuvuholewo
Fokecahalox
jWepezikowi geyolevaki mezekeri toh nabikakonupa rucijelilifoxu hicuyasasuvan mifawonupemex lata tabifovaji
Copu yakocapeSYixidi xuliyico bajapapakuri bubupumayep lizasafinaj jacip penifegocosid notefanura{Menefapozohunik gozopiritutu vevetaxezoz gudolake siludokudexon kafizedasex boxejagugax fatemukexihudep gugifeve sadeyezere
Rafo mogogiwolobufud Bozivu nani tazogocafirepa japil
YXakicemijiban dezaxisatoti culibavodu tosutaderozateb vit gedawayorese liw puxuriweyokaba
-Zapopu fawun nexemoluv sepuvijulayifuy hahiro
Antivirus Signature
Bkav W32.AIDetect.malware2
Lionic Clean
Elastic malicious (high confidence)
MicroWorld-eScan Clean
FireEye Generic.mg.cb1aa8895db7b559
CAT-QuickHeal Clean
ALYac Clean
Cylance Unsafe
Zillya Clean
Sangfor Trojan.Win32.Save.a
K7AntiVirus Clean
BitDefender Clean
K7GW Clean
Cybereason malicious.1985b4
BitDefenderTheta Gen:NN.ZexaF.34170.rq0@a855u2ci
Cyren W32/Kryptik.EWJ.gen!Eldorado
Symantec ML.Attribute.HighConfidence
ESET-NOD32 Clean
Baidu Clean
APEX Malicious
Paloalto Clean
ClamAV Clean
Kaspersky VHO:Trojan-PSW.Win32.Convagent.gen
Alibaba Clean
NANO-Antivirus Clean
ViRobot Clean
Tencent Clean
Ad-Aware Clean
TACHYON Clean
Sophos Clean
Comodo Clean
F-Secure Clean
DrWeb Clean
VIPRE Clean
TrendMicro Clean
McAfee-GW-Edition BehavesLike.Win32.MultiPlug.dh
CMC Clean
Emsisoft Clean
Ikarus Trojan-Banker.UrSnif
GData Clean
Jiangmin Clean
MaxSecure Clean
Avira Clean
Antiy-AVL Clean
Kingsoft Clean
Gridinsoft Clean
Arcabit Clean
SUPERAntiSpyware Clean
ZoneAlarm Clean
Microsoft Trojan:Win32/Sabsik.FL.B!ml
Cynet Malicious (score: 100)
AhnLab-V3 Clean
Acronis suspicious
McAfee Clean
MAX Clean
VBA32 Clean
Malwarebytes Clean
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Rising Trojan.Generic@ML.100 (RDML:Qe4FKt56BVGlR8JwXvmDAQ)
Yandex Clean
SentinelOne Static AI - Malicious PE
eGambit Unsafe.AI_Score_99%
Fortinet Clean
Webroot Clean
Avast Clean
CrowdStrike win/malicious_confidence_100% (W)
No IRMA results available.