Static | ZeroBOX

PE Compile Time

2021-03-02 22:06:36

PDB Path

C:\gogone.pdb

PE Imphash

2b117a88efd5ad3db577a4f98b26ff8a

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x0001a8a5 0x0001aa00 7.73096095707
.rdata 0x0001c000 0x00004644 0x00004800 3.99966178353
.data 0x00021000 0x02ac3cd0 0x00001400 2.19847185151
.nutem 0x02ae5000 0x00000272 0x00000400 0.0
.rsrc 0x02ae6000 0x00016d98 0x00016e00 6.37587346094

Resources

Name Offset Size Language Sub-language File type
AFX_DIALOG_LAYOUT 0x02afbac0 0x00000002 LANG_NEUTRAL SUBLANG_NEUTRAL data
AFX_DIALOG_LAYOUT 0x02afbac0 0x00000002 LANG_NEUTRAL SUBLANG_NEUTRAL data
AFX_DIALOG_LAYOUT 0x02afbac0 0x00000002 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_CURSOR 0x02afbbf8 0x000000b0 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_CURSOR 0x02afbbf8 0x000000b0 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x02afb5d0 0x00000468 LANG_DIVEHI SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x02afb5d0 0x00000468 LANG_DIVEHI SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x02afb5d0 0x00000468 LANG_DIVEHI SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x02afb5d0 0x00000468 LANG_DIVEHI SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x02afb5d0 0x00000468 LANG_DIVEHI SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x02afb5d0 0x00000468 LANG_DIVEHI SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x02afb5d0 0x00000468 LANG_DIVEHI SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x02afb5d0 0x00000468 LANG_DIVEHI SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x02afb5d0 0x00000468 LANG_DIVEHI SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x02afb5d0 0x00000468 LANG_DIVEHI SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x02afb5d0 0x00000468 LANG_DIVEHI SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x02afb5d0 0x00000468 LANG_DIVEHI SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x02afb5d0 0x00000468 LANG_DIVEHI SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x02afb5d0 0x00000468 LANG_DIVEHI SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x02afb5d0 0x00000468 LANG_DIVEHI SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x02afb5d0 0x00000468 LANG_DIVEHI SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x02afb5d0 0x00000468 LANG_DIVEHI SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x02afb5d0 0x00000468 LANG_DIVEHI SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x02afb5d0 0x00000468 LANG_DIVEHI SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x02afb5d0 0x00000468 LANG_DIVEHI SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x02afb5d0 0x00000468 LANG_DIVEHI SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x02afb5d0 0x00000468 LANG_DIVEHI SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x02afb5d0 0x00000468 LANG_DIVEHI SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x02afb5d0 0x00000468 LANG_DIVEHI SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_STRING 0x02afc758 0x0000063e LANG_BULGARIAN SUBLANG_DEFAULT data
RT_STRING 0x02afc758 0x0000063e LANG_BULGARIAN SUBLANG_DEFAULT data
RT_STRING 0x02afc758 0x0000063e LANG_BULGARIAN SUBLANG_DEFAULT data
RT_STRING 0x02afc758 0x0000063e LANG_BULGARIAN SUBLANG_DEFAULT data
RT_GROUP_CURSOR 0x02afbca8 0x00000022 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_GROUP_ICON 0x02afba38 0x00000068 LANG_DIVEHI SUBLANG_DEFAULT data
RT_GROUP_ICON 0x02afba38 0x00000068 LANG_DIVEHI SUBLANG_DEFAULT data
RT_GROUP_ICON 0x02afba38 0x00000068 LANG_DIVEHI SUBLANG_DEFAULT data
RT_GROUP_ICON 0x02afba38 0x00000068 LANG_DIVEHI SUBLANG_DEFAULT data
RT_VERSION 0x02afbcd0 0x000001b4 LANG_NEUTRAL SUBLANG_NEUTRAL data

Imports

Library KERNEL32.dll:
0x41c000 LoadLibraryExW
0x41c004 SetMailslotInfo
0x41c008 HeapFree
0x41c010 WaitForSingleObject
0x41c014 SetEvent
0x41c018 OpenSemaphoreA
0x41c01c GetTickCount
0x41c020 CreateActCtxW
0x41c024 Sleep
0x41c028 GetVersionExW
0x41c02c GetAtomNameW
0x41c030 GetModuleFileNameW
0x41c034 SetConsoleTitleA
0x41c038 GetCPInfoExW
0x41c03c GetProcAddress
0x41c040 VirtualAlloc
0x41c048 LoadLibraryA
0x41c04c WriteConsoleA
0x41c050 LocalAlloc
0x41c058 EraseTape
0x41c064 Module32Next
0x41c068 EndUpdateResourceA
0x41c06c DeleteAtom
0x41c074 FindNextVolumeA
0x41c078 lstrcpyW
0x41c07c LCMapStringW
0x41c080 EncodePointer
0x41c084 DecodePointer
0x41c088 GetCommandLineA
0x41c08c HeapSetInformation
0x41c090 GetStartupInfoW
0x41c094 RaiseException
0x41c0a0 IsDebuggerPresent
0x41c0a4 TerminateProcess
0x41c0a8 GetCurrentProcess
0x41c0ac HeapAlloc
0x41c0b0 GetLastError
0x41c0b8 TlsAlloc
0x41c0bc TlsGetValue
0x41c0c0 TlsSetValue
0x41c0c4 TlsFree
0x41c0cc GetModuleHandleW
0x41c0d0 SetLastError
0x41c0d4 GetCurrentThreadId
0x41c0dc ReadFile
0x41c0e8 SetFilePointer
0x41c0ec CloseHandle
0x41c0f0 ExitProcess
0x41c0f4 WriteFile
0x41c0f8 GetStdHandle
0x41c0fc GetModuleFileNameA
0x41c104 WideCharToMultiByte
0x41c108 SetHandleCount
0x41c110 GetFileType
0x41c118 HeapCreate
0x41c120 GetCurrentProcessId
0x41c128 GetConsoleCP
0x41c12c GetConsoleMode
0x41c130 GetCPInfo
0x41c134 GetACP
0x41c138 GetOEMCP
0x41c13c IsValidCodePage
0x41c140 MultiByteToWideChar
0x41c144 RtlUnwind
0x41c148 SetStdHandle
0x41c14c FlushFileBuffers
0x41c150 HeapSize
0x41c154 LoadLibraryW
0x41c158 WriteConsoleW
0x41c15c GetStringTypeW
0x41c160 HeapReAlloc
0x41c164 CreateFileW

!This program cannot be run in DOS mode.
`.rdata
@.data
.nutem
@.rsrc
D$0PVV
HHtXHHt
?If90t
^SSSSS
j@j ^V
URPQQhpz@
t"SS9] u
PPPPPPPP
PPPPPPPP
;t$,v-
UQPXY]Y[
"CX.2?
I;]5QV
I*Afl5
vuLjL.
g\}|Ha=srcB
WR<Xk6-
1ioS|a
]\$d[P
ui"L=@FK
^O5F-g
>C0aH0
pX9C6GV
|?T[z.0
"X5" &
/f5XS[
k|f{oX
l{v-$SfIg
uDndk!
^{YsAz
X)v|AA
zw,q@XW
u_:NjZ
keqX=c
<?W(>]p
* `lqV
H.=7wj;D
0,xBcN!M*
M4|<]7
<FD]K!
'-W-Fh
3/[>=_f;Lb`
I+jl5
[No*,3
N!F1)F
54kpjs8
sp2G6%
$b{:j.
r^;F/
J3 4$k
l<$$8<;
p[__%1]
}*D5ze
Ql?1\R
bRjHl^sN
^/HUaF
MBd.pb
B%(z`W
v^I08j
rYs]c>
G]yCK_
4w2pS~t
K2'!|3
B[{ZyB-
jGp~,x
=oN0h#z
kvfL&)0
?%M `J5
?K`@G9
prHa6Cp
Q;w7t
SQU3|-7
E[{x&-x
}PdJ JA
UL4[It
'b0T]*u
S&_3IV
<*!fUm$
ZgM]&`
!bmWE&
1KD18l~
JnD%mtd
EFR.+x?e&S
&eEa!c(
!J!|'D
WIhC);
)ybX8U
0ip2<$P
y/7ghF
+m:.21|
5+~V{,1
w1,|xZ
0j,`_L
lw+d~rd
E/}Y6C
ZpDM3.
FBe(x&
53R<{C
a Y)[U*
TY6+_#&fL]
+_p'yd
B,lfqsH
sDvHv%
Mch!1N
y&mZ4oI!
d-gM`y
Au]Cd:
J<6;~?0C
)4of"@
QQSVWd
t=MOC
HtHu4j
t*=RCC
;7|G;p
tR99u2
Unknown exception
bad allocation
(null)
`h````
xpxxxx
FlsFree
FlsSetValue
FlsGetValue
FlsAlloc
CorExitProcess
HH:mm:ss
dddd, MMMM dd, yyyy
MM/dd/yy
December
November
October
September
August
February
January
Saturday
Friday
Thursday
Wednesday
Tuesday
Monday
Sunday
`h`hhh
xppwpp
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
Complete Object Locator'
Class Hierarchy Descriptor'
Base Class Array'
Base Class Descriptor at (
Type Descriptor'
`local static thread guard'
`managed vector copy constructor iterator'
`vector vbase copy constructor iterator'
`vector copy constructor iterator'
`dynamic atexit destructor for '
`dynamic initializer for '
`eh vector vbase copy constructor iterator'
`eh vector copy constructor iterator'
`managed vector destructor iterator'
`managed vector constructor iterator'
`placement delete[] closure'
`placement delete closure'
`omni callsig'
delete[]
new[]
`local vftable constructor closure'
`local vftable'
`udt returning'
`copy constructor closure'
`eh vector vbase constructor iterator'
`eh vector destructor iterator'
`eh vector constructor iterator'
`virtual displacement map'
`vector vbase constructor iterator'
`vector destructor iterator'
`vector constructor iterator'
`scalar deleting destructor'
`default constructor closure'
`vector deleting destructor'
`vbase destructor'
`string'
`local static guard'
`typeof'
`vcall'
`vbtable'
`vftable'
operator
delete
__unaligned
__restrict
__ptr64
__eabi
__clrcall
__fastcall
__thiscall
__stdcall
__pascal
__cdecl
__based(
GetProcessWindowStation
GetUserObjectInformationW
GetLastActivePopup
GetActiveWindow
MessageBoxW
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
weyugapadofuzis
lixuhurejofakamamemoteku
gunuhoboyibaxuzagasawa
VirtualProtect
kernel32.dll
LocalAlloc
%s %f %c
fufunihu boxacigofekecaiedupozijawovubo wem
piyasubulifuxakayopoceyahov hucuceracasuyasonaheta bevogenexenecoposilubeyinego
invalid string position
string too long
bad exception
C:\gogone.pdb
LoadLibraryExW
SetMailslotInfo
HeapFree
GetEnvironmentStringsW
WaitForSingleObject
SetEvent
OpenSemaphoreA
GetTickCount
CreateActCtxW
GetVersionExW
GetAtomNameW
GetModuleFileNameW
SetConsoleTitleA
GetCPInfoExW
GetProcAddress
VirtualAlloc
BeginUpdateResourceW
LoadLibraryA
WriteConsoleA
LocalAlloc
SetEnvironmentVariableA
EraseTape
GetProcessAffinityMask
SetProcessShutdownParameters
Module32Next
EndUpdateResourceA
DeleteAtom
FindActCtxSectionStringW
FindNextVolumeA
lstrcpyW
LCMapStringW
KERNEL32.dll
EncodePointer
DecodePointer
GetCommandLineA
HeapSetInformation
GetStartupInfoW
RaiseException
UnhandledExceptionFilter
SetUnhandledExceptionFilter
IsDebuggerPresent
TerminateProcess
GetCurrentProcess
HeapAlloc
GetLastError
IsProcessorFeaturePresent
TlsAlloc
TlsGetValue
TlsSetValue
TlsFree
InterlockedIncrement
GetModuleHandleW
SetLastError
GetCurrentThreadId
InterlockedDecrement
ReadFile
EnterCriticalSection
LeaveCriticalSection
SetFilePointer
CloseHandle
ExitProcess
WriteFile
GetStdHandle
GetModuleFileNameA
FreeEnvironmentStringsW
WideCharToMultiByte
SetHandleCount
InitializeCriticalSectionAndSpinCount
GetFileType
DeleteCriticalSection
HeapCreate
QueryPerformanceCounter
GetCurrentProcessId
GetSystemTimeAsFileTime
GetConsoleCP
GetConsoleMode
GetCPInfo
GetACP
GetOEMCP
IsValidCodePage
MultiByteToWideChar
RtlUnwind
SetStdHandle
FlushFileBuffers
HeapSize
LoadLibraryW
WriteConsoleW
GetStringTypeW
HeapReAlloc
CreateFileW
.?AVlogic_error@std@@
.?AVlength_error@std@@
.?AVout_of_range@std@@
.?AVtype_info@@
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
.?AVexception@std@@
.?AVbad_alloc@std@@
.?AVbad_exception@std@@
mmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmY
mmmmmmmmmmmmmmmmv%
mmmmmmmmmmmmmmmm
mmmmmmmmmmmmmmmmov
DzpAqz
ommmmmmmmmmmmmmmm$o
mmmmmmmmmmmmmmmm$n
mmmmmmmmmmmmmmmm
mmmmmmmmmmmmmmmm
mmmmmmmmmmmmmmmm
mmmmmmmmmmmmmmmm
mmmmmmmmmmmmmmmm
$mmmmmmmmmmmmmmmm
mmmmmmmmmmmmmmmm
mmmmmmmmmmmmmmmm<
mmmmmmmmmmmmmmmm
$mmmmmmmmmmmmmmmm
mmmmmmmmmmmmmmmme
mmmmmmmmmmmmmmmm
mmmmmmmmmmmmmmmm
mmmmmmmmmmmmmmmm
%mmmmmmmmmmmmmmmm
Ymmmmmmmmmmmmmmme
$mmmmmmmmmmmmmmmS
Ymmmmmmmmmmmmmmm&
?mmmmmmmmmmmmmmmS
YmmmmmmmmmmmmmmmS
YmmmmmmmmmmmmmmmS
Z&Ymmmmmmmmmmmmmmm
Ymmmmmmmmmmmmmmm
Ymmmmmmmmmmmmmmm$R
88@8@l
@Ymmmmmmmmmmmmm!R%
mmmmmmmmmmmm
{K{bDzK
mmmmmmmmmmmm
_mmmmmmmmmmmm
_mmmmmmmmmmmm
!mmmmmmmmmmmm
A^=3==3
!mmmmmmmmmmmm
!mmmmmmmmmmmm
6mmmmmmmmmmmml+^
#emmmmmmmmmmmm&%
mmmmmmmmmmmmmY
!!!!!__
?mmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmm
hhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhI
hhhhhhhhhhhhhIV
hhhhhhhhhhhh
#=hhhhhhhhhh
hhhhhhhhhh
hhhhhhhhhhE
hhhhhhhhhhE
hhhhhhhhhh
hhhhhhhhhho
hhhhhhhhhhEC
hhhhhhhhhh
hhhhhhhhhh
hhhhhhhhhhE
hhhhhhhhhh
shhhhhhhhhh
NmJRB{A2"fI~RhhhhhhhhhhI
24*<4)*
hhhhhhhh
n4hhhhhhhh
NRhhhhhhhh
v*hhhhhhhhh
AIMIIM
hhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhh
V*vMX~
F=y)X9e3
/yyoG|
CeKqioL
Ijh~~AI
LA~~c_
Bnx~bHE
U^~~IJ~
\_~~mk
\\\\\\\\\\\\\\\\\\\\\\\\\\\
q0\\\\\\\\\\\\
,\\\\\\\\\\\z=
\\\\\\\\\\kw
\\\\\\\\\([
\\\\\\
\\\\\\\j_
7\\\\\\\
3\\\\\\\\j
\\\\\\\\
\\\\\\\\\\\\M
\\\\\\\\\\\8
\\\\\\\\\\\\j
\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\
5~~~~~~
nnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnn
Rnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnz
nnnnnnnnnnnnnnnnn
nnnnnnnnn
nnnnnnnnnnnnnn
2(0gqonnnnnnnnnnnnn
nnnnnnnnnn
nnnnnnnnnE
nnnnnn
<>jlTT
nnnnnn
X?j#&d
nnnnnn
nnnnnnn
nnnnnnn
"s)b)__[
nnnnnnn'9h
2nnnnnnn2r
nnnnnnn
Bnnnnnnnnn
#[nnnnnnnnn
nnnnnnnnnn
b2nnnnnnnnnnnnn
nnnnnnnnnnnnnn[
nnnnnnnnnnnnnnn
nnnnnnnnnnnnnnn
BonnnnnnnnnnnnnnnnnB
gnnnnnnnnnnnnnnnnn
nnnnnnnnnnnnnnnn
2*9&"_
AxQ[onnnnnnnnnnnnnnnnnn
}#00T?
nnnnnnnnnnnnnnnnnnn[)r[q<hu
nnnnnnnnnnnnnnnnnnnnnn]
nnnnnnnnnnnnnnnnnnnnnn
nnnnnnnnnnnnnnnnnnnnn
nnnnnnnnnnnnnnnnnnnnn
nnnnnnnnnnnnnnnnnnnnn
nnnnnnnnnnnnnnnnnnnnn
nnnnnnnnnnnnnnnnnnnnnn
nnnnnnnnnnnnnnnnnnnnnnn
nnnnnnnnnnnnnnnnnnnnnnnnn
nnnnnnnnnnnnnnnnnnnnnnnnnnn
nnnnnnnnnnnnnnnnnnnnnnnnnnnnnn
nnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnn
nnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnn
[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[/[[[[[[[[[[[[[[[[[[[
[[[[[[[<
</[[[[[[[[[[[
[[[[[[[[[<
<[[[[[[[[
=Yk`HDBB
[[[[[[[/
[[[[[[[
[[[[[[[<GmS
[[[[[[[
[[[[[[[[U
[[[[[[[[[
<[[[[[[[[[[
.Cyo+o3S
[[[[[[[[[[[[j
[[[[[[[[[[[[[[
[[[[[[[[[[[[[[
.[[[[[[[[[[[[[[
[[[[[[[[[[[[[[[[Ad
`[[[[[[[[[[[[[[[[[lr4
.[[[[[[[[[[[[[[[[[^y3a
[[[[[[[[[[[[[[[[[
[[[[[[[[[[[[[[[[[
0[[[[[[[[[[[[[[[[[[[
[[[[[[[[[[[[[[[[[[[[[
[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[
,Mo|bF
Fb~~xK
\q~~~K
-e~~7N
(null)
KERNEL32.DLL
mscoree.dll
runtime error
TLOSS error
SING error
DOMAIN error
- Attempt to use MSIL code from this assembly during native code initialization
This indicates a bug in your application. It is most likely the result of calling an MSIL-compiled (/clr) function from a native constructor or from DllMain.
- not enough space for locale information
- Attempt to initialize the CRT more than once.
This indicates a bug in your application.
- CRT not initialized
- unable to initialize heap
- not enough space for lowio initialization
- not enough space for stdio initialization
- pure virtual function call
- not enough space for _onexit/atexit table
- unable to open console device
- unexpected heap error
- unexpected multithread lock error
- not enough space for thread data
- abort() has been called
- not enough space for environment
- not enough space for arguments
- floating point support not loaded
AMicrosoft Visual C++ Runtime Library
<program name unknown>
Runtime Error!
Program:
HH:mm:ss
dddd, MMMM dd, yyyy
MM/dd/yy
December
November
October
September
August
February
January
Saturday
Friday
Thursday
Wednesday
Tuesday
Monday
Sunday
WUSER32.DLL
((((( H
h(((( H
H
BCONOUT$
fekovimofojituzuwivuwubajiyofori
gjowupivawixevov volubazojabocis xubixawowatiro
Sip ninafahomuruluguxuda gevizanifipiloxitagocayabu
xa togexoyebofe waxazeyonekicoyogixowolezitalay kisecovilirowaxizonuloce
vemetahupofutadiki
AFX_DIALOG_LAYOUT
VS_VERSION_INFO
StringFileInform
080805a0
InternalName
bomgpiaruci.iwa
Copyright
Copyrighz (C) 2021, fudkagat
ProductVersion
75.74.30.5
VarFileInfo
Translation
gGovuginavoleji wumejes putepop jetujozuwawoxug levopexirexed wuboguvecey ziyiyo giyolugob nomotib yagis)Judisigidu rizuxuxoci yanor cuk yijanilug\Socucudum varojavuhore paju fizayaki kavun sedol donakefi lecog tifebofizemodod xobahapozexe
.Lojo tifebihihopo mifibazotunewo gebedibofajolbFevu boxuloxapijah melum fizumisivifuzo vamawir peracacocubete dedahijaluyob femuxetegawoge ficeyi@Zipelokaj hac toru lon gehe yebopizecekin moka gum simo fuxegope2Dap tatikafadehibu fiduvigovido lozepe konazoreriw<Vosukuxixit tahacevada yitumogij pebuwoxipubac wifimaputazec
Rege ripoma8Hasuxecem feyidez bahoxuzukahoso fidediwubazisi vunifefa
*Vezuzoladec mehumusutonobaw vefadusococavu1Yonufuwu zatuso fixeyajeraref miyuyix rosadi fehiANaziwokefek rijoyurogebetuc zekitosipudo cimoxirosur vewodat cidifNibufe deviwifawinop meduzuw vigob gosi likuwunirimiyuj waliwo lepexobetoj tiwasoxewosabi viduledehewutRufebipugine redukakazonexo lazubolunimizin neliberuwipayu suki yolelu mananeragi jerepizajo ligupifujiv fayurorisus
Mafuge
Xihenetimen
Sib tuve yepebow.Gaxoz tacucefebu zezonaponapocu figojexijunora
Vobazuhabimon hes codec<Wawozitaful vihowodo xuvegepoxo jule hepu kesevoxaw tugepiruJRoyixihir rukeboga cenilibivirepe hegoneko puxesuk zuxahehiri hahaz vacoce;Horenude foh yirika kizeferavibira vuzuzimoke jifejituhokoy2Somefupekiz fucokuluwa disatete neparug nojekucapeKCejude fufuju kihe jonasihayiba fegafo panaledabuleno bivivoj toxagalovubuc$Pemilorugugeha rekusemene piha zijux_Lilujidili coc tafog panogoy kisudepimev nugefewof fehebitemeger hikinagajox pemelokinuf ronabe#Yeyodup yihojejizuxahud vufumubutat/Zehogocotimehuw revim bawijifa jibobin kifurese>Vuf woregewaxofibe capopiwupubex xovokidecule ved fumu vifibowSRucahe mone xixeyiy lohalehix bihiwepa kinuy kasaxobanupugop yacutafi fawigas nugecTGewiro fezewuxasoxi xexifojituk zahojesucad fenejoyodojo xayi puti kiciweconir lovid
Antivirus Signature
Bkav W32.AIDetect.malware1
Lionic Trojan.Win32.Zbot.m6l9
Elastic malicious (high confidence)
MicroWorld-eScan Gen:Variant.Fragtor.35416
FireEye Generic.mg.b09c4c58f6aa6f8e
CAT-QuickHeal Clean
McAfee RDN/Generic.grp
Cylance Clean
Zillya Clean
Sangfor Trojan.Win32.Save.a
K7AntiVirus Trojan ( 00581d621 )
BitDefender Gen:Variant.Fragtor.35416
K7GW Trojan ( 00581d621 )
CrowdStrike win/malicious_confidence_100% (W)
BitDefenderTheta Gen:NN.ZexaF.34236.nu0@am7p4faG
Cyren W32/Kryptik.FOQ.gen!Eldorado
Symantec Trojan.Gen.9
ESET-NOD32 a variant of Win32/Kryptik.HNCZ
Baidu Clean
APEX Malicious
Paloalto generic.ml
ClamAV Win.Trojan.Generic-9904991-0
Kaspersky HEUR:Exploit.Win32.Shellcode.gen
Alibaba Exploit:Win32/Shellcode.3bc7d16a
NANO-Antivirus Clean
ViRobot Clean
Rising Malware.Heuristic!ET#94% (RDMK:cmRtazrhDWMfcWM81Lm9Q5e17kTX)
Ad-Aware Gen:Variant.Fragtor.35416
Sophos Mal/Generic-R + Troj/Krypt-BO
Comodo Malware@#2y8809lkgmbx1
F-Secure Clean
DrWeb Clean
VIPRE Clean
TrendMicro Clean
McAfee-GW-Edition BehavesLike.Win32.Generic.dc
CMC Clean
Emsisoft Gen:Variant.Fragtor.35416 (B)
SentinelOne Static AI - Malicious PE
GData Gen:Variant.Fragtor.35416
Jiangmin Backdoor.Tofsee.fbs
Webroot W32.Trojan.Gen
Avira TR/Kryptik.mjgwx
MAX Clean
Antiy-AVL Clean
Kingsoft Win32.Troj.Generic_a.a.(kcloud)
Gridinsoft Malware.Win32.GenericMC.cc
Arcabit Clean
SUPERAntiSpyware Clean
ZoneAlarm Clean
Microsoft Trojan:Win32/Raccoon.BB!MTB
Cynet Malicious (score: 100)
AhnLab-V3 Malware/Win.Generic.C4737245
Acronis suspicious
VBA32 Malware-Cryptor.2LA.gen
ALYac Gen:Variant.Fragtor.35416
TACHYON Clean
Malwarebytes Trojan.MalPack.GS
Panda Trj/GdSda.A
Zoner Clean
TrendMicro-HouseCall TROJ_GEN.R002H07JS21
Tencent Clean
Yandex Clean
Ikarus Trojan.Win32.Crypt
eGambit Clean
Fortinet W32/GenKryptik.FMSH!tr
AVG Win32:MalwareX-gen [Trj]
Cybereason malicious.0b35d1
Avast Win32:MalwareX-gen [Trj]
MaxSecure Trojan.Malware.300983.susgen
No IRMA results available.