Static | ZeroBOX

PE Compile Time

2020-05-15 21:58:12

PDB Path

C:\siyatucuzaz\sexij.pdb

PE Imphash

9e3ac2424cecff905bdab3e7336b91cb

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x00078ee0 0x00079000 7.96451543995
.rdata 0x0007a000 0x00004b32 0x00004c00 4.44703198917
.data 0x0007f000 0x00009004 0x00001800 2.9073699702
.rsrc 0x00089000 0x0004b1cd 0x00016200 6.27326567561

Resources

Name Offset Size Language Sub-language File type
RT_CURSOR 0x0008b230 0x000000b0 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_CURSOR 0x0008b230 0x000000b0 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_CURSOR 0x0008b230 0x000000b0 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_CURSOR 0x0008b230 0x000000b0 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_CURSOR 0x0008b230 0x000000b0 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x0009d000 0x00000468 LANG_LATVIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x0009d000 0x00000468 LANG_LATVIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x0009d000 0x00000468 LANG_LATVIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x0009d000 0x00000468 LANG_LATVIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x0009d000 0x00000468 LANG_LATVIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x0009d000 0x00000468 LANG_LATVIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x0009d000 0x00000468 LANG_LATVIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x0009d000 0x00000468 LANG_LATVIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x0009d000 0x00000468 LANG_LATVIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x0009d000 0x00000468 LANG_LATVIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x0009d000 0x00000468 LANG_LATVIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x0009d000 0x00000468 LANG_LATVIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x0009d000 0x00000468 LANG_LATVIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x0009d000 0x00000468 LANG_LATVIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x0009d000 0x00000468 LANG_LATVIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x0009d000 0x00000468 LANG_LATVIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x0009d000 0x00000468 LANG_LATVIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x0009d000 0x00000468 LANG_LATVIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x0009d000 0x00000468 LANG_LATVIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x0009d000 0x00000468 LANG_LATVIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x0009d000 0x00000468 LANG_LATVIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_STRING 0x0009e3d4 0x000004a6 LANG_MANIPURI SUBLANG_DEFAULT data
RT_STRING 0x0009e3d4 0x000004a6 LANG_MANIPURI SUBLANG_DEFAULT data
RT_STRING 0x0009e3d4 0x000004a6 LANG_MANIPURI SUBLANG_DEFAULT data
RT_STRING 0x0009e3d4 0x000004a6 LANG_MANIPURI SUBLANG_DEFAULT data
RT_STRING 0x0009e3d4 0x000004a6 LANG_MANIPURI SUBLANG_DEFAULT data
RT_ACCELERATOR 0x0009e8c4 0x00000010 LANG_MANIPURI SUBLANG_DEFAULT data
RT_ACCELERATOR 0x0009e8c4 0x00000010 LANG_MANIPURI SUBLANG_DEFAULT data
RT_GROUP_CURSOR 0x0009e90c 0x00000022 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_GROUP_CURSOR 0x0009e90c 0x00000022 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_GROUP_CURSOR 0x0009e90c 0x00000022 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_GROUP_ICON 0x0009ea20 0x0000004c LANG_LATVIAN SUBLANG_DEFAULT data
RT_GROUP_ICON 0x0009ea20 0x0000004c LANG_LATVIAN SUBLANG_DEFAULT data
RT_GROUP_ICON 0x0009ea20 0x0000004c LANG_LATVIAN SUBLANG_DEFAULT data
RT_VERSION 0x0009ea6c 0x000001b4 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_MANIFEST 0x0009ec20 0x000005ad LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with very long lines, with CRLF line terminators

Imports

Library KERNEL32.dll:
0x47a008 SetThreadContext
0x47a014 HeapAlloc
0x47a018 UpdateResourceA
0x47a01c HeapFree
0x47a024 BackupSeek
0x47a028 GetTickCount
0x47a02c GlobalAlloc
0x47a030 LoadLibraryW
0x47a034 SizeofResource
0x47a038 GetTapePosition
0x47a040 WriteConsoleW
0x47a044 GetAtomNameW
0x47a048 LCMapStringA
0x47a04c GetLastError
0x47a050 GetProcAddress
0x47a054 VirtualAlloc
0x47a05c LoadLibraryA
0x47a060 WriteConsoleA
0x47a068 GetModuleFileNameA
0x47a070 AddConsoleAliasA
0x47a074 FindNextVolumeA
0x47a078 lstrcpyA
0x47a080 CreateFileW
0x47a084 GetStringTypeW
0x47a088 GetModuleHandleW
0x47a08c ExitProcess
0x47a090 DecodePointer
0x47a094 GetCommandLineA
0x47a098 HeapSetInformation
0x47a09c GetStartupInfoW
0x47a0a8 IsDebuggerPresent
0x47a0ac EncodePointer
0x47a0b0 TerminateProcess
0x47a0b4 GetCurrentProcess
0x47a0bc WriteFile
0x47a0c0 GetStdHandle
0x47a0c4 GetModuleFileNameW
0x47a0c8 HeapCreate
0x47a0d8 RtlUnwind
0x47a0dc SetHandleCount
0x47a0e0 GetFileType
0x47a0e8 SetFilePointer
0x47a0ec CloseHandle
0x47a0f0 TlsAlloc
0x47a0f4 TlsGetValue
0x47a0f8 TlsSetValue
0x47a0fc TlsFree
0x47a104 SetLastError
0x47a108 GetCurrentThreadId
0x47a114 WideCharToMultiByte
0x47a11c GetCurrentProcessId
0x47a124 RaiseException
0x47a128 Sleep
0x47a12c CreateFileA
0x47a130 GetCPInfo
0x47a134 GetACP
0x47a138 GetOEMCP
0x47a13c IsValidCodePage
0x47a140 GetConsoleCP
0x47a144 GetConsoleMode
0x47a148 SetStdHandle
0x47a14c FlushFileBuffers
0x47a150 HeapSize
0x47a154 HeapReAlloc
0x47a158 SetEndOfFile
0x47a15c GetProcessHeap
0x47a160 MultiByteToWideChar
0x47a164 ReadFile
0x47a168 LCMapStringW
Library USER32.dll:
0x47a170 GetCursorPos
Library ADVAPI32.dll:

!This program cannot be run in DOS mode.
`.rdata
@.data
f-00f=
^SSSSS
<at,<rt"<wt
URPQQh
HHtXHHt
?If90t
j@j ^V
tRHtCHt4Ht%HtFHHt
tCHt(Ht
;t$,v-
UQPXY]Y[
t"SS9] u
<+t"<-t
+t HHt
PPPPPPPP
PPPPPPPP
<Y%t'8
J=xX8$
9LERivv
NRCf!J
Bw!DUL
H~>V,
`J~G(ZT
:f8*WO
aM8d0<
5w5&rq Hi3p6
n`GuyGg
@\e;\
MYb"yIu
\%+|-T5
O)%3Px
cEQiWf9
S2yjIeN
R4,i8`
a@;_@/
:%</|q5
ar&_Z<
gWi!'>.
o4XI,1
?$\P4+QL2
ZCUCMz7xD
UB^:Z~
) ?/o`
>3-%(?
dOd.DM$
$NAu`3
)L0Wl
^OQB03
[LW}wC
TA-t9?
(sKs0
[V_$L"0M
B(1$nGPw
b{SnF-
#YwOo+
5R|jPXc
V^eSj@
gZ_< Px
SVUOvn
'tna{<
hbV1W\z
?r+4:!
b@/i/'y]
i9T,Mf0
W&59`}c
MI@[X.
#a^4O@ 3
U'hTt5
6ijr0J
]w|u|E<
3kRxYH
aN"JMZ
2\H$0AU
;})(2AH.
Lq~Q$a
lY0n+|
9%]FYfb
`}rh5E
ZNug 5
MCd%1#.
+;e;K@
e7-,o0
zi _"B
`pz'U#u^}
epi$Xu
u9un!%
#8ka]
Nf,b%ZH{N
D.6YRI
epOJ[O
!b:NcV
M}=fNBa
O/.fTS
`x *aG%
!O*aq*.+
f=S;*n
4%gZ9$
CVTOU~
<1|Tyj
yIdsn%_
2)3{&s
uf(8Szz4
;J8~9^
Z3"NLM
n`Uf_
3<p@k;Z
8xSZlf&
RsrcBYy
@Ke.Vp
$'SXc^Q
PGP*O} ^
H8J8M8
.3etr0w
<SH)2xP~
uSt5(fhhum
NF@9k)eL
?I^18)CF
2?O1`x
&Yu8x>
61QICV+
^//PfL
N>1YN
M_ *thP
hm^(F*wY1^
"hD+^
I2tenB
MJA6@c
f&;l['g5
(SoJcQ%
@]A[,|
-A$4N"$J
_)"YGuy
|'Iq<_
0EydNb
tSGF"Fe
NrJ1U;
'k1PHw/
u F5&1
s"odcA
|eL%t%G g
Yuc)[B:
!D_Z1D
XqMB?N
i}O&3G
{&ux)e
2i#'Jl
gC13Hd
NcSYC@Y9
"sl-wxg,
G"^q7o
9T&v-z
~awkGW
0U3ydc
rdxuwS
6hcI%M
C--Fly
mMoKHn
$w(]}C:hX
GhmE&Gz
kkU_6_,C~l
.DF"T
(qK?k#
!.ldNxH3:a
BzOqxSAx
[g6pQp
)3?$37D
p+ ]td
#VRT&2
X3U5CK^
j<b`lb
9+uCGy
If'#RW
S~3~=u
|@e 2)q
cbI6Yh3
Wv%i6N
gL3VFM
Rn3}QA
wLX{ X
Y!Rbm.8e
iq'!>(
8IY6{x
_J>{_C
?,QP7
-Nle"z
DCA^_[N
&YKif|
pDn;`_
H"C^Dl
Un(UUD|
N>}'UA
WU9ovS
5+b )c
XH9lf,
$|iH{7
tL7;On
RzR}lL
I*+vm.d
_sm.;p,.2
rPdLGS
}qnIZuS
xBqx1).]3
LLNu)@
at5$qb
sADMLV
DQ&0,/Bs
-bIX.+*
|.`KA$)f
-PxRyL0~
=Pp5Iw
TC,&X'
%U2-`j
&X#H2k
$yRUu,
w\mXk}
6~SNF^,s
|fZSw
Mq/SW+
#e@(P]
/6aMF5S
)pU`MHVB
yc$(&*
}oci/R5Q]
>1YHSP
b_!1[f?$2}5/
^y4|Ay
))e:{1
<./51m
9Wc@9F
Xa;w=7m<V
"~oV*`-Y
+XBQf>
SaG:Zp^
mBTJ3H$
bFHoCMZ
hX[q:)
a'44!'
2!/`=8
Fjz0SF
f0&+#,}
eCyWAz
UE*Ep)
>7=jx3
1fG>Oi
mluGw%tJ
3i:1sE
BGN7@^
!x[$*F+
m<_^F(^t,
^-]@&m=
,@BR>Y
Ij%{sQwD
M}^SDR[
wC8P)dO!
k}PTRi
Vig'jc
?ClmMZ(/
9Jo>$c
#NNFvQ
RsK:NiQ
ABqi]wMvF
D~Yn03y
LDj==w
U5ZZ*6`
iM?QFJ
sfK_Yj
$Xja`1
F{-O"L0
3s}"\x
Gjg'^-
S2/c!
UzW?Z?`}
\@/T.
vAjm]4r
7='TQv
+`@N!:N
Oo.Se/
F[<iSq
)<YDZ(MC
J1@*yx~
6v<0[s
4\hp-yOO
9j=Sve
H #!P
DlY#+]
;pe/wA
b{pqj!
y=L'w9e
(O'xxz
~J!'xF]
1/A<ZM
y=T;,%
n]i~/&
_[4l~P
;lPz
?;(\[
D{C`DW2j
{K;s[&
WL[*fN
c|(ezH^|y
<M*x +
tevnEV9
3\hi$H,
,B^@{
)(+P
oM.wao
#=*qCx
(Qq'2e
!dy2+d
x5+B$q
vm-g7;
v{G:ajO
WQ:BF8
e925e.n
t&Wfjj
:+ztYr
,77Rs
;}K+~!H
x|[f,9Q
Q/@C!%
:a|2QH
2r<&;X
+8e'{hK
46{[F0
GXoFv
E_AMB/X
%~m'r1d
iZ9Qm\4
<W8mWG+7|
Ex_3j5(6
VU=)RiJ
f,KP6H
^,zn8x
n!<q4G
=xZ"FX
oQ%?w7
sE*@+z
D\iVoe
dZ{x'F_S
3~u^|w
|-alZH
@bm.w6
Dp\iN!Kf
?y4>r^to
$r:PLc
MaU|J7
c'W8KU
q~Y.gxAg
?yfn']
EsJC8Vz
+hCYvx
pgkMO;
^<>|z@_PPzp
GsOljP
UC,(z!
5HwG%'F
-uA,Bn4|
$m,,v
:m+e'[
Hvq\gme
t^$zQ4
C,\eyH
bh{<OCX
K7:H^r]
<5fCVV
v5A&>v
a;Jw(g
K7e+4
P)!D${[O
$1M~ep
Onam$]
g;1;|:C
#Cksu)
*g%}>1Q$?&
iMl.eIc
P ^7_Y
Us>$/Y
KoK'<s>x
rkj*4-),
icH1S X
kwG3`&d
hZR4iF
?*DZ'
cNHjg'
:;-qscF[
!^{OoQ!
t B-Wdb
jnCHEx
Cx~W]b
A%}7TxoyE
uw2SO)
3/|?FP
t|{.%=
8gdKwZ
OU&th-
3"2'hJ
Ls;~8n
z$pT|gJ
euwnP/
?h~P3B
IU-e=/
whegJH
qI0@s}_W
H(kH7;
9~FS=+Q
Qj!5@L
.pD^u@1m
a5x*-=
z|xcp1
HmWi1M=k
N7Rj?2b9).
KG@%`L
9,D`g-;p
3|arI5
m3.Yv
kX0~#u
.\}F7'
70@pF*
mPFpYx7
AO3)-F
D I _4
lo1.o2
SpF|}i
3j_%:|1
T';=$c
f-Xv_5
)tGii5&
{dg)>\V
EFo!Vc
i)RTNO
SdE_#u
4E_7Wc
ch, !()
Xk9zV@B
.\A,6d|
8?_`R8^
#lGLAgp1kmFz9
+RPPoO
{l<35'
<P]a-X
Am@gfi
+Nc~cq
6)Hy(
\H'q<~
!(z<Qk
OhFjF$"
hz5A\&
fk;E61
eBuhMo
=e>x'#
p!`Yyxf)v
7k,2KS
Iqv>0N
I*$@_e
Ta8!:YyF
,rwh>W
)\>`k6:B
:MT;$;y
NJ[q3j
0xTQj'
x2+y\p/
Iw1RBK
LO_?hZ#26
F6 1:u
r$<@EO.^
<'gJ~pu$
qllra{
zhUSJf
|!RrL;
1L]VKd
~kMG~4
'*!7L;(*
,vv8\D
LINpe+
7#{(3n0
SA5x}QQ
~\Ph75
Bh&XPum
6#l9T{
nY"5["
P^a4i*
"w\nEE
Ybhu(
5jpuf%
,]+2GFTU
_:9&<%_
;<4!b:
%U5iJ|
GuRYelG2
gfT9-p
P0Q7C>"!
t{lH]4*
e0r!b
F5vAd,u
O;yhLv
dg+AH.
\,,HL}
C}3#9"
F.NWc^
[%|RmC
D8b)T=
*"z.sw
@0>g[Uq
t~h ;M
G]$v5d
hD?.W5TQ
/L@A`*;
Nz:Bv^'
7#i-49
\ukPG"F+
O^dRZz
F~].I 5
%r,4\H
rUsgPf
=O0.L{
+.]Asz
j%`O?T 0L
G<&Dw
YBa{f5
d<kwM;B
GO`-OK1
<~?6[@5
7'Tsc%Lu
$4kuCy
J<!`P!
E^;8Ih
4Ln1V-
T.CW7'
AYBP:l*
~$2H;q3
Q?#8&E
/Xak nW
Ssh)S-
vp0QH<
SvS&%M
\BA%&s
@>5cp\
10cdv@%#
e6?BTc
^"2+m%
3f]E.b
&QZH;`
/6y|G|[
3iO2 e6M P
:xQ<>Z
sSlntjf1cU
F`"JaA
$cOo06
#nOLH'LA
_.quY(a
h#u/%5uD<
J]Njv%
fWT[ 1
~uZ#tyFM'
2l0A`b'
y:i_VA:+]J>
=Aa|R_<
#9Y;P|
J$8sB,cW_9u
"vB('+W
PNA;Aa
[(aN3g
Q=50}^
RGv;"I
b@fS;L
:IT8<D
Knymfl
+~$:/2
am84m\
cAzKq"
^/a[G[!3
f)v`sbA [A
Er@%/0
g1#]/,
ha?sl^w
)$~4|0
|=s dY
B9$VS~
DB1P?q
vR{ZrM
VjzDJM
# YUb65
d"/F<E7
sfZG^#Q
9B@y<6z
Qgc3Cs
@zksF:
4B9[B3
#; 'Nj
wW*Sg19
k${T;F
6.)twH
QfIPqj]r
`)[3-b
hLNT3O
Eyf>*6m
Tu-1!
1Sx.SW
>qvgZ&
o#jIdN?
$ W;:}
QI~n]
)'kK#
>jf<8`N:
DZ6C\-
*$(qvKz
bC[ z[
]LK]?LT
y^9%l.wy
G,d>d<
uL[sN=
a~Z$f@
9\mG,e'
,}:4QZ
|`dj|s
\*MmeN
vM*uav
3mqokq
zKl*HOUT
H]mf#d
fz^k\li
rsf&<J?Z
G%iL2c
|4Fh1Q
N-|7JP
jFsAiU
<#E!qL
&Ub:am
"b|jMgi
;XMTt8
4!J{J"
|QQ{jV
0bQv1`E
zKW/9n
gS^BLlZ,C
f4Kht|
6,-1{&
{j^sA-^
%gotrct
kf6eB&,
/ b*I]`WU
iMr+?q
6x~KRe
B'C"=:n4+}
3g}&kO
<#n*3Q
{&5,j
]']-_:
?''2f}5
:g:7Z-
L6{^m
a]|CPM
Q7(vQ
fG-Y`.
5?6u.*
>l"4oT
?R@Cjy
b#>)S8
dr3]MM}
Flev_>
3+ybYvT0
=Rjjy1
DhJq&O
w._LV4
oi>$(MKMLS
4]^)H8
N>1bZc
jdP BP&
ek5;_,
|lS$z(
8% 2{0
DCy_vX
HhZ/Ec
"wS,En
qKlg6>=
&wU rd
v;uGp!<
`lRNY)
K-Y3i*3
jmY*i
|:|uCR_
bg)~hs
+3:9J
bilnme"A
yL!X9%
B=%b\nR
+q4*0R
S10,=[S
iaS+N":
RhWW!;
:CwQc_
:$6T?u
qvO?AM
^n1RH2Y
$"_/y$
k6cwR-i9O
CiQ|(c
G&Ui>y
r4O@3~l
-*7r,,
i_W6m^G
PJT429
0Q0.1f
4$lbwTRO
I}nQ`(
_.u7th"~V
A)7H:M
ZS$I*P
o]Uu@N
V]Lsus
nLhw.
n\>q2]
7~Zg:&
&ZcwW$
V%qg*,
a.>Fo2
4+CbJR6
bqa5rH%
j9lUo{`
2<KeVjE
y$kF4p
p_e-)w
H/r*{R5
>/dv(i
R=_H9JS
Y"!kJ>z@fJL
g'p[H4\
HIRC8]z%2C]`
N?@{LX
|$y92
8SB'~KY
?`QOI9
i]IBgT
-$rRZf
bIS6iO
.{Gmz+
xb=;3V
U4G,~zhh
.x*0/q&p7i
JULStI
mKt6q%"
CN;Dzy
q>QCnQ
\HY>)j
t"z-`F"2
{Jv"?dJ
@_o`1M
2mF|& f6i
}GV k_
J71 ,Xd
DvF!QYL
',uZXHX
Fq<qK8-
ECUR e(
X(IPkG
FP-^hb)%x\
!a6:B<
.+y-a#
3'$kw<
yNMENn
6FjPzS
VYV&kw
d:\!S61
;(sW62
DiDTXD
`K@_8su
0 2'k#
o-+TC`G_
Z/k`%c
zF1#X-P
{{v+wv
f"^m
]s2|d-
g:7DAdmapK
8?|y(D
%+Xlo2
avA ~m
+r2ePl
cg2j-uQgY|
JR<MGy
bQ90M?
{W%SK
8j=6%te
wv)C'>M]
DIEfT]
U!H=Ae
k$Gtm
CorExitProcess
?uZEeu
?uZEeu
?UUUUUU
?UUUUUU
UTF-16LE
UNICODE
(null)
`h````
xpxxxx
FlsFree
FlsSetValue
FlsGetValue
FlsAlloc
GetProcessWindowStation
GetUserObjectInformationW
GetLastActivePopup
GetActiveWindow
MessageBoxW
HH:mm:ss
dddd, MMMM dd, yyyy
MM/dd/yy
December
November
October
September
August
February
January
Saturday
Friday
Thursday
Wednesday
Tuesday
Monday
Sunday
`h`hhh
xppwpp
_nextafter
_hypot
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
Complete Object Locator'
Class Hierarchy Descriptor'
Base Class Array'
Base Class Descriptor at (
Type Descriptor'
`local static thread guard'
`managed vector copy constructor iterator'
`vector vbase copy constructor iterator'
`vector copy constructor iterator'
`dynamic atexit destructor for '
`dynamic initializer for '
`eh vector vbase copy constructor iterator'
`eh vector copy constructor iterator'
`managed vector destructor iterator'
`managed vector constructor iterator'
`placement delete[] closure'
`placement delete closure'
`omni callsig'
delete[]
new[]
`local vftable constructor closure'
`local vftable'
`udt returning'
`copy constructor closure'
`eh vector vbase constructor iterator'
`eh vector destructor iterator'
`eh vector constructor iterator'
`virtual displacement map'
`vector vbase constructor iterator'
`vector destructor iterator'
`vector constructor iterator'
`scalar deleting destructor'
`default constructor closure'
`vector deleting destructor'
`vbase destructor'
`string'
`local static guard'
`typeof'
`vcall'
`vbtable'
`vftable'
operator
delete
__unaligned
__restrict
__ptr64
__eabi
__clrcall
__fastcall
__thiscall
__stdcall
__pascal
__cdecl
__based(
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
1#QNAN
1#SNAN
Sezinusujafa narumos wohitehehoga
nacanogulofameguyakuridipijidarugozene
gavumoribifokevesibotunujiviyosiwemajiki
Cizizikisani
VirtualProtect
kernel32.dll
LocalAlloc
lamagukogehaxehugohetohucuxitegafabukulojanosawizenop
C:\siyatucuzaz\sexij.pdb
SetProcessAffinityMask
SetThreadContext
WriteConsoleOutputCharacterW
GetDefaultCommConfigW
HeapAlloc
UpdateResourceA
HeapFree
GetEnvironmentStringsW
BackupSeek
GetTickCount
GlobalAlloc
LoadLibraryW
SizeofResource
GetTapePosition
SetConsoleCursorPosition
WriteConsoleW
GetAtomNameW
LCMapStringA
GetLastError
GetProcAddress
VirtualAlloc
GetFirmwareEnvironmentVariableW
LoadLibraryA
WriteConsoleA
BeginUpdateResourceA
GetModuleFileNameA
SetConsoleCursorInfo
AddConsoleAliasA
FindNextVolumeA
lstrcpyA
KERNEL32.dll
GetCursorPos
USER32.dll
NotifyChangeEventLog
ADVAPI32.dll
GetModuleHandleW
ExitProcess
DecodePointer
GetCommandLineA
HeapSetInformation
GetStartupInfoW
UnhandledExceptionFilter
SetUnhandledExceptionFilter
IsDebuggerPresent
EncodePointer
TerminateProcess
GetCurrentProcess
IsProcessorFeaturePresent
WriteFile
GetStdHandle
GetModuleFileNameW
HeapCreate
EnterCriticalSection
LeaveCriticalSection
InitializeCriticalSectionAndSpinCount
RtlUnwind
SetHandleCount
GetFileType
DeleteCriticalSection
SetFilePointer
CloseHandle
TlsAlloc
TlsGetValue
TlsSetValue
TlsFree
InterlockedIncrement
SetLastError
GetCurrentThreadId
InterlockedDecrement
FreeEnvironmentStringsW
WideCharToMultiByte
QueryPerformanceCounter
GetCurrentProcessId
GetSystemTimeAsFileTime
RaiseException
CreateFileA
GetCPInfo
GetACP
GetOEMCP
IsValidCodePage
GetConsoleCP
GetConsoleMode
SetStdHandle
FlushFileBuffers
HeapSize
HeapReAlloc
SetEndOfFile
GetProcessHeap
MultiByteToWideChar
ReadFile
LCMapStringW
GetStringTypeW
CreateFileW
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
iiiiii
iiiiii
iiiiiiiiiiii
iiiiiiiiii
iiiiii
iiiiiiiii
iiiiiiiiiiiii
iiiiiiii

CeKqioL
Ijh~~AI
LA~~c_
Bnx~bHE
U^~~IJ~
\_~~mk
\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\D
\\\\\\\\\\\\\\\\\
Os\\\\\\\\\\\\\\\\
\\\\\\\\\\\\\\\
s\\\\\\\\\\\\\\\
ts\\\\\\\\\\\\\\\
s\\\\\\\\\\\\\\\
-s\\\\\\\\\\\\\\\
s\\\\\\\\\\\\\\\
Qs\\\\\\\\\\\\\\\
s\\\\\\\\\\\\\\\
Hs\\\\\\\\\\\\\\\
\\\\\\\\\\\\\\\
\\\\\\\\\\\\\\\
\\\\\\\\\\\\\\\
\\\\\\\\\\\\\\\
\\\\\\\\\\\\\\\
\\\\\\\\\\\\\\\
6\\\\\\\\\\\\\\\\
\\\\\\\\\\\\\\\\
\\\\\\\\\\\\\\\\
\\\\\\\\\\\\\\\\
\\\\\\\\\\\\\\\\
\\\\\\\\\\\\\\\\
^\\\\\\\\\\\\\\\\
\\\\\\\\\\\\\\\\
\\\\\\\\\\\\\\\\
\\\\\\\\\\\\\\\\
\\\\\\\\\\\\\\\\e|
\\\\\\\\\\\\\\\\
UQ\\\\\\\\\\\\\\\\O
Ue\\\\\\\\\\\\\\\\^
\\\\\\\\\\\\\\\\^
\\\\\\\\\\\\\\\\
\\\\\\\\\\\\\\\\
\\\\\\\\\\\\\\\\e?
y}yRyJ
-\\\\\\\\\\\\\\\\Q
\\\\\\\\\\\\\\\\e
\\\\\\\\\\\\\\\\^
\\\\\\\\\\\\\\\\\^
\\\\\\\\\\\\\\\\\
\\\\\\\\\\\\\\\\\\
\\\\\\\\\\\\\\\\\\\\
s sssss
\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\
jW%<@Q
OOy*OO
@^@^^^@R
?E5?tv}
SdS=}~
kkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkk
&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&
oooooooo
oooooo
ooooooooooo
oooooo
ooooooooo
ooooooo
oooooooooo
oooooooo
oooooooooo
oooooo
%ooooooo
?:%ooooooo
c:%||ooo
c:%o|ooooo
c:%|oooooo
c:%||ooooo
c:%o|ooooo
&&&&&&
c:%||oooooo&
&&&&&&&
c:%o|ooooo
&&&&&&&&&&
c:%||oooo&
&&&&&&&&&&&
c:%||ooo&
&&&&&&&&&
c:%||o|&
&&&&&&&&&&&&&&
c:%||o&
&&&&&&&&&&&&
rrrrrrrrr$
iZZZZZ
iiiiiii
iZZZZZ
iZZZZZ
iZZZZZZZZ
iZZZZZZZ
77`7`777
`````7
CCCCCC
CCCCCCC
CCCCCCCC:
iiX##
333333333333333333333
333333333333333333333333333333333333333333333333333333333333333333333333333333333333333333333333333
GG++++++++++++GGG+111111111111+GG+lll
+GG+lll
+GG+llll
+GG+jllllN
+GG+jjjlla
+GG+jjjjl
+GG+jjjjjl
+GG+jjjjjjj
a+GGVVVVVVVVVa
eJaGGV
GGVVVVVVVVVVVaGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGG
8q|{9y
6Qe}nJl
6DSiP2fz
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0" xmlns:v3="urn:schemas-microsoft-com:asm.v3"><assemblyIdentity version="1.1.00.00" name="AutoHotkey" type="win32"></assemblyIdentity><dependency><dependentAssembly><assemblyIdentity type="win32" name="Microsoft.Windows.Common-Controls" version="6.0.0.0" processorArchitecture="*" publicKeyToken="6595b64144ccf1df" language="*"></assemblyIdentity></dependentAssembly></dependency><compatibility xmlns="urn:schemas-microsoft-com:compatibility.v1"><application><supportedOS Id="{8e0f7a12-bfb3-4fe8-b9a5-48fd50a15a9a}"></supportedOS><supportedOS Id="{1f676c76-80e1-4239-95bb-83d0f6d0da78}"></supportedOS><supportedOS Id="{e2011457-1546-43c5-a5fe-008deee3d3f0}"></supportedOS><supportedOS Id="{35138b9a-5d96-4fbd-8e2d-a2440225f93a}"></supportedOS><supportedOS Id="{4a2f28e3-53b9-4441-ba9c-d69d4a4a6e38}"></supportedOS></application></compatibility><v3:application><v3:windowsSettings xmlns="http://schemas.microsoft.com/SMI/2005/WindowsSettings" xmlns:ws2="
mscoree.dll
runtime error
TLOSS error
SING error
DOMAIN error
- Attempt to use MSIL code from this assembly during native code initialization
This indicates a bug in your application. It is most likely the result of calling an MSIL-compiled (/clr) function from a native constructor or from DllMain.
- not enough space for locale information
- Attempt to initialize the CRT more than once.
This indicates a bug in your application.
- CRT not initialized
- unable to initialize heap
- not enough space for lowio initialization
- not enough space for stdio initialization
- pure virtual function call
- not enough space for _onexit/atexit table
- unable to open console device
- unexpected heap error
- unexpected multithread lock error
- not enough space for thread data
- abort() has been called
- not enough space for environment
- not enough space for arguments
- floating point support not loaded
GMicrosoft Visual C++ Runtime Library
<program name unknown>
Runtime Error!
Program:
E(null)
KERNEL32.DLL
WUSER32.DLL
HH:mm:ss
dddd, MMMM dd, yyyy
MM/dd/yy
December
November
October
September
August
February
January
Saturday
Friday
Thursday
Wednesday
Tuesday
Monday
Sunday
((((( H
h(((( H
H
CONOUT$
fekovimofojituzuwivuwubajiyofori
kupokopopecehicuvevujukamuno
fusanegebafehoxesiberanumehexopovuf
/ P6pL
,/KPip
/-P?pR
/ P6pL
,/KPip
/-P?pR
gGovuginavoleji wumejes putepop jetujozuwawoxug levopexirexed wuboguvecey ziyiyo giyolugob nomotib yagis)Judisigidu rizuxuxoci yanor cuk yijanilug
bFevu boxuloxapijah melum fizumisivifuzo vamawir peracacocubete dedahijaluyob femuxetegawoge ficeyi@Zipelokaj hac toru lon gehe yebopizecekin moka gum simo fuxegope2Dap tatikafadehibu fiduvigovido lozepe konazoreriw<Vosukuxixit tahacevada yitumogij pebuwoxipubac wifimaputazec
<Hewanurekig pecegeced hipufizowomoces zejahixevi yadatacusex
Rege ripoma8Hasuxecem feyidez bahoxuzukahoso fidediwubazisi vunifefa;Dopozafabayi feraturifa xuhiw depuvi dalubo molinig pixeniw+Hadigaxonabifon hiziyogadil cewaneca mazavo
1Yonufuwu zatuso fixeyajeraref miyuyix rosadi fehiANaziwokefek rijoyurogebetuc zekitosipudo cimoxirosur vewodat cidifNibufe deviwifawinop meduzuw vigob gosi likuwunirimiyuj waliwo lepexobetoj tiwasoxewosabi viduledehewutRufebipugine redukakazonexo lazubolunimizin neliberuwipayu suki yolelu mananeragi jerepizajo ligupifujiv fayurorisus
DHixibe kuxen jugediwuzaxexif jelijapux bik goramep fewakow focipiyuf
Mafuge
Xihenetimen
Sib tuve yepebow.Gaxoz tacucefebu zezonaponapocu figojexijunora
Vobazuhabimon hes codec<Wawozitaful vihowodo xuvegepoxo jule hepu kesevoxaw tugepiruJRoyixihir rukeboga cenilibivirepe hegoneko puxesuk zuxahehiri hahaz vacoce;Horenude foh yirika kizeferavibira vuzuzimoke jifejituhokoy2Somefupekiz fucokuluwa disatete neparug nojekucapeKCejude fufuju kihe jonasihayiba fegafo panaledabuleno bivivoj toxagalovubuc$Pemilorugugeha rekusemene piha zijux_Lilujidili coc tafog panogoy kisudepimev nugefewof fehebitemeger hikinagajox pemelokinuf ronabe#Yeyodup yihojejizuxahud vufumubutat/Zehogocotimehuw revim bawijifa jibobin kifurese>Vuf woregewaxofibe capopiwupubex xovokidecule ved fumu vifibowSRucahe mone xixeyiy lohalehix bihiwepa kinuy kasaxobanupugop yacutafi fawigas nugecTGewiro fezewuxasoxi xexifojituk zahojesucad fenejoyodojo xayi puti kiciweconir lovid
-Goxapayevekehad fewomexedecugo goluyapucepadu
BodafevicamasiKFal kudulezeza pepalitorulu titedeniguzoda mibotanukuyuku rarera haheniwafeTPimonuveke xuva zovom sumipuwipi zicumibayomod ligiw jihifagusivabo citozapo wafibikKRexiyosununuti rihoxorowopal vemerey fawunujokog foco xacovuku luhohefaneru3Fucizedusimoma zex pisizasamena tagowowetapu mecawe:Dohawugox lavihitur hubusojifuzi vumebuwazicuvey pebaxitis
SurelobihayoZZecuyave vahepacuyufi siviyegi jajedapire fixitiw cabemumetinod bukofozoca xitide nihowiye
KLozevuz feninakoko ravabofagimegas zekowoxupe coh yuvugixicivebe coje codup
VS_VERSION_INFO
StringFileInform
090101a0
InternalName
bomgpiaruci.iwa
Copyright
Copyrighz (C) 2021, fudkagat
ProductVersion
15.54.12.11
VarFileInfo
Translation
Antivirus Signature
Bkav W32.AIDetect.malware2
Lionic Clean
Elastic malicious (high confidence)
DrWeb Clean
MicroWorld-eScan Clean
FireEye Generic.mg.ebff6c5c942d1800
CAT-QuickHeal Clean
McAfee GenericRXQC-OC!EBFF6C5C942D
Malwarebytes Clean
VIPRE Clean
Sangfor Trojan.Win32.Save.a
K7AntiVirus Clean
BitDefender Clean
K7GW Hacktool ( 700007861 )
CrowdStrike win/malicious_confidence_80% (D)
BitDefenderTheta Clean
Cyren W32/Kryptik.FOQ.gen!Eldorado
Symantec Packed.Generic.528
ESET-NOD32 Clean
APEX Malicious
Paloalto Clean
ClamAV Clean
Kaspersky UDS:Trojan-Spy.Win32.Stealer.gen
Alibaba Clean
NANO-Antivirus Clean
ViRobot Clean
Rising Trojan.Generic@ML.100 (RDML:WZT8r/7gJ6Uegug9RBIIqg)
Ad-Aware Clean
Sophos ML/PE-A
Comodo Clean
F-Secure Clean
Baidu Clean
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition BehavesLike.Win32.Lockbit.hc
CMC Clean
Emsisoft Clean
Ikarus Trojan.Win32.Crypt
GData Clean
Jiangmin Clean
Webroot Clean
Avira Clean
MAX Clean
Antiy-AVL Clean
Kingsoft Clean
Gridinsoft Clean
Arcabit Clean
SUPERAntiSpyware Clean
ZoneAlarm Clean
Microsoft Trojan:Win32/DllCheck.A!MSR
Cynet Malicious (score: 100)
AhnLab-V3 Trojan/Win32.Injector.C456594
Acronis suspicious
ALYac Clean
TACHYON Clean
VBA32 Malware-Cryptor.2LA.gen
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Tencent Clean
Yandex Clean
SentinelOne Static AI - Malicious PE
eGambit Clean
Fortinet Clean
AVG FileRepMetagen [Malware]
Cybereason malicious.51cf3d
Avast FileRepMetagen [Malware]
MaxSecure Trojan.Malware.300983.susgen
No IRMA results available.