Static | ZeroBOX

PE Compile Time

2021-02-18 07:38:31

PDB Path

C:\vacuj93 wimamexac.pdb

PE Imphash

804abf6bfd1eb86d699699dd471c7b89

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x0006d5e0 0x0006d600 7.96135097468
.rdata 0x0006f000 0x00003b5a 0x00003c00 3.87980580694
.data 0x00073000 0x00008fc0 0x00001800 2.80534972517
.rsrc 0x0007c000 0x0001b8a0 0x0001ba00 6.37188498746

Resources

Name Offset Size Language Sub-language File type
RT_CURSOR 0x00096388 0x00000130 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_ICON 0x00095e58 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00095e58 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00095e58 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00095e58 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00095e58 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00095e58 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00095e58 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00095e58 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00095e58 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00095e58 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00095e58 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00095e58 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00095e58 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00095e58 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00095e58 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00095e58 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00095e58 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00095e58 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00095e58 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00095e58 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00095e58 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00095e58 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00095e58 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00095e58 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00095e58 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00095e58 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00095e58 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00095e58 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00095e58 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00095e58 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00095e58 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_STRING 0x000973f8 0x000004a6 None SUBLANG_DEFAULT data
RT_STRING 0x000973f8 0x000004a6 None SUBLANG_DEFAULT data
RT_STRING 0x000973f8 0x000004a6 None SUBLANG_DEFAULT data
RT_STRING 0x000973f8 0x000004a6 None SUBLANG_DEFAULT data
RT_STRING 0x000973f8 0x000004a6 None SUBLANG_DEFAULT data
RT_ACCELERATOR 0x00096378 0x00000010 None SUBLANG_DEFAULT data
RT_ACCELERATOR 0x00096378 0x00000010 None SUBLANG_DEFAULT data
RT_GROUP_CURSOR 0x000964b8 0x00000014 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_GROUP_ICON 0x00089260 0x00000068 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_GROUP_ICON 0x00089260 0x00000068 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_GROUP_ICON 0x00089260 0x00000068 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_GROUP_ICON 0x00089260 0x00000068 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_VERSION 0x000964d0 0x000001b4 LANG_NEUTRAL SUBLANG_NEUTRAL data

Imports

Library KERNEL32.dll:
0x46f00c GetTickCount
0x46f010 GetConsoleAliasesA
0x46f018 ReadConsoleW
0x46f01c WriteFileGather
0x46f020 SetHandleCount
0x46f024 GlobalAlloc
0x46f02c Sleep
0x46f038 SetConsoleCP
0x46f040 FindNextVolumeW
0x46f048 GetAtomNameW
0x46f04c GetCPInfoExW
0x46f050 SetLastError
0x46f054 GetProcAddress
0x46f058 VirtualAlloc
0x46f060 EnumDateFormatsExA
0x46f068 LoadLibraryA
0x46f06c WriteConsoleA
0x46f074 CreateHardLinkW
0x46f080 IsDebuggerPresent
0x46f084 RequestDeviceWakeup
0x46f08c DuplicateHandle
0x46f090 DeleteAtom
0x46f094 lstrcpyW
0x46f09c LCMapStringA
0x46f0a0 HeapAlloc
0x46f0a4 GetModuleHandleW
0x46f0a8 ExitProcess
0x46f0ac DecodePointer
0x46f0b0 GetCommandLineW
0x46f0b4 HeapSetInformation
0x46f0b8 GetStartupInfoW
0x46f0c4 GetStdHandle
0x46f0c8 GetFileType
0x46f0d4 EncodePointer
0x46f0d8 TerminateProcess
0x46f0dc GetCurrentProcess
0x46f0e0 WriteFile
0x46f0e4 GetModuleFileNameW
0x46f0e8 HeapCreate
0x46f0f0 GetLastError
0x46f0f4 SetFilePointer
0x46f0f8 HeapFree
0x46f0fc CloseHandle
0x46f100 LoadLibraryW
0x46f104 TlsAlloc
0x46f108 TlsGetValue
0x46f10c TlsSetValue
0x46f110 TlsFree
0x46f118 GetCurrentThreadId
0x46f128 GetCurrentProcessId
0x46f12c WideCharToMultiByte
0x46f130 GetConsoleCP
0x46f134 GetConsoleMode
0x46f138 RtlUnwind
0x46f13c GetCPInfo
0x46f140 GetACP
0x46f144 GetOEMCP
0x46f148 IsValidCodePage
0x46f14c RaiseException
0x46f150 SetStdHandle
0x46f154 FlushFileBuffers
0x46f158 HeapSize
0x46f15c HeapReAlloc
0x46f160 WriteConsoleW
0x46f164 MultiByteToWideChar
0x46f168 LCMapStringW
0x46f16c GetStringTypeW
0x46f170 CreateFileW
Library USER32.dll:
0x46f178 GetClipCursor
Library ADVAPI32.dll:

!This program cannot be run in DOS mode.
`.rdata
@.data
SSSSSS
VVVVVVV
^uOVh(
r=h2G
j@j ^V
^SSSSS
HHtXHHt
?If90t
tWItHIt9It
QQSVWh
URPQQh`
;t$,v-
UQPXY]Y[
t"SS9] u
PPPPPPPP
PPPPPPPP
<+t"<-t
+t HHt
{Yh7xI8
*Im}kh
YBm(2/
W!L@5~
Wd;c0P*
7auh3d
$Tu@Lb
C]'?K
.M?|NX
QHR#hJ
8.#h&3wln
~x1M^
_itg9;
<Q b3
O|foeE
$0&;Uz
(j'Na$`
%H}ufc
3.ovcl
:!FZ\p\
7W,!lE
l]5cOx1y^
A1J@Oo
#I}fU
bso1&0
4$[=V,
t\'Jz!]A
Rn_&FJv
]<6-JM
lC5:y%
f=-=$0R
I+Z9XEP
{oU^Ii1
XV@vP{
g-9GE
@F/*hs)1i
g:t=Kq
OV&"p>@V_
m^I[l!
r^wM;K{
H. _"i
KUrsP"
(|q/Cn#
kWb}ff
]Bv4^f
,KglNcZ
2P]P|1
4eM9$
>Up-Js
) s)oD
x$)g]62Vi/
,RQnTs
QnpqA*
7e Fh&^
2)>~l.
NY{utI
q8/!cwA
2Njw:h)
Zi^J_;
iU<'Yp
m0kNnl
\?86RaQ
i\QaIF
#}s]*.H
wnzK6F
>'oKsJ
{e^MK!0
^Aw)'r'
CUOoi#
kgyt\2
Ps_9T]V
<T.:Py
m?$W(ha
<o*&>&
i)-QG#
XWrTvm
yy,zLtoi
&92@gW
12sIJvU
DRa=Hx
?I|[Zu
I30+r4
}+0rVu
*_,aPy
AhbNY#@#+
v.*sC
Xf0E:8a
y%Nf`k
fwB3]5
@Qk2N
kv#l1bZh
;Of`"\
b\z(".
Zfy]7,
1NcIr]@
*J]@ I
6oH+aM
}7)a23
73\:Kb
55$x2H
E86C?$
lY[K_"
N#2kr
a5&|$R
rBWs]H
a0RVGM
;P5s]RG
#~X#Fa
%C-/5(
E"H`eZ
UNz..Tb@
HKHm5OH
1{Ld-
\0)r`O
PC~qI&
YUm"H*)
~UGW.h
|G"]*Y\j#
3X.nPg
\zw_vkM
[ :}9h
$-Z~v#
~toTNfw
YOQr )
-%CrS_%/
T`9W%I
;ZqUm{
O6Gi*N
>.Y7$;
-CYi.ZA%
?c3CW3TM
IbBw21
:B@tJ
&}}w}\
I>C?*X
lh.N,~
uAqTvy
9HbXy
3>ZG<>
QPIjK>
D\*?P~
VdGpR,
/ei-S9
M9%K|S
B:>6\A
;g)//&
0bNzc<W
F.P[l'Ba
sewU_P[
f@.0yK
LW)#&-
nvIixZ8
,JV1x{?
;m>3t ;,
n]ngGn
8h+Y,c|
i5p!g]}|
Land6{
5~J4RW
CiQGO
+|uZ+T
]QgdH?
ex<D3t
*GKe_j
:b!Gx
)UFWJ0
\N4V2XE
3_/#9(
W^z`m+
K1-T/q
Z5<d[m
F.hxa$
iw;vw/W
Njp;;hz
-{[L"J
;ACb"\
c6\Q}m<
c5H36
6l7y\q
Z16dvAMy
j&u2b%
E^4#djr
^oG'7,
7\r1,z+
KSs$VL
`D*l^<z
vCRALM
zDXw_sH
`!tDiH
a!f+=z
#jq!fg
V+of/wZy
a+V/v>
+| HaR&
DVlHsB
J8U)%}
!bAFXWZ
$AU:L)
(cWdWJ0
u=5VZXi
pm1@&>`
\^?X!p^y
\QDy~W
oR!*){
XHnsj
!.SB#gD
tu!l5Uq
%L<42t:
#@z5.-
3mEBo0
/*.ey#
>'E9ZWOV>
<~N_`<5
=)h;3da
YnF*-s
vPxO%D
d8ZUmN
-HQ{|_
q;JeV>
_GU:LLD.6
)_3b`;
_DqE|h!
on`Ub&
na],\"
nf.nb,
]'Y.C.Dq
/?&eg*
zd(|N,
IL_ewae
xB]p_Et
z}w2mO
!8FCtUb
%:cP8jF<w
;jGlUvT
ENN-co
l"P/Yy
%s5gD!g
6z/t@q
^{9$W;SB
!|=^nv[
p}ayqc
_H F|)
TSkn8nK
`#zDI=
c`\tD2
A{1d'fK
[6+&TG
b>FQ5JR
D$$3=5
`Fz:A3Rowh@
y7YKX
#XF-('
i3|5?
fP0aAJ
_9'c/gT
XRB{_H
HA4q-/
qw|):V
pvQOoTj
9'^^2c
xD0L"L}
&E;d}A
Q5-9eQ
2#U`g!
[$njIiyvw
1g+"0T3
4YHbPVb
7A$.&g
P!l#hO
i>otCJ
amH_cA
[I)3.:
>O@ERv
@ 0*9c-
~W("qdK
33|k{t
w-2X2+
!.qYEs
a1a*<V
w(&?m|>
V-5hdt
&_H}PE
70HU|s
kQaa+
s>S4@c
{48Yek
'nPsQ(
Lvt^tF
9ejQ[n
HH<*Ma
G"/wZt
^mK5qJ
7-J~.R
p~vu=#
3'#|DqN
G1yNbCk
v*5I5Jn
9)8K6G
5Z/e'U;
kYbsT;
@$"+wxf
J2Fx|V
JC/$JZ
XSLp8<W
xG7~w^
mS!eM
}/;fpQ
8N=for
|)dA]a
Kq[Z:g
!*3]9>
JNI)Dj4`
)h6*6l>
M{&e,4
~W{awV]
arM|%a$K#
74LrW-
|8SJUs
Us5-h_
"PhUhg
n&(PV^F
]_A_!Q
z=Sp-p(
w<'zZSB
:R&+S
Rl4M^A
>1fd:3
9O|PHZ
-d=?0b
&gIH3I
5>n<>;|e
OIHl?1
Ug}U'9-
:{n}44-
dTjulZ&
ATH*)3'x/
6E)arW
?|E"3a
;ema%X9Q
4#laj*sk
kd"Hv?
hTx;(jh
OEl,g`
GYBaR!
9*/UrS
$|,TI+
^e^PGY
\C5=v6
6V0|"H
Qp!t##
,{?#d@
BGbjv:
:0_uww
kpV2$4
lquVL9*
`(!'r2
@Cz1vT
}!%'s7MF'
GCpp)XaL
N5rxPj:
mDu8UdxFN
TH({?U
'cQ{`U<
MF!K);/R
j%%j*Z
#3Fa&E|
PSXqSE%O0m
nok}j>
<e2-H6
,m9)Wi
4-Er5
ci()~!
06>P_s
>K\6)lF
bmKM)u~|
0HCbo/
0_Ig0$,
Uj`&sMU
1BfI*ghK
[+`/1*
,+}C;B
$MJ=]k)mc
{%mas'Dkzs
rv_s"_
X1D(V(J
c8=qf$
aNGZso
23kdVn
QRmBZU
KoAf;%
QP^qV0
@|@ou^
X_O6,L*
lPJZ%4
D{^Je
E"f"Zn
>Iz<'/
rGk)kj!
\rp{Is
IS?' z
s-&d#kc
d*;Q-"
o,ykqU
cZ:IW%SU
fl@~,VVt
GM4(QI
Om/)[c
sMZ1}GJ
<7lAG=W
domI-^
w5(2V@L%
c/z;//F
6;Ko(8
MkSg\R
#jV RnT"l
=&0(vUJ
Ho=t-\z
s7]xRP
Ly5H.w{
<uLuni
[?peEr
Sih9\#
J::_gb
F-9TN1
r(Ub`
F~wvsQ
I`T;%<
Cy7Ve>
phim@*
LqHC>E
eF5{!
;n(,"4$
D&]=RQ
ST1?Zq
@z(C#M
E!j}Z#z
Mti[,q7'x
mJ*N*;
dB|0,`
7y\-Z{
Avwc8}
@1dRzr
VISL~|
O4:m0A
^>XHgf
t)>Y&+J
wu%a]5d
:v(A1Z
T%2Agf
IWm9y|`?$ k
'2G6w:
"ICm"$v
'FlX([
7:ZN~<
?M ~/
&@mPa&+W
L97.@u
KD3T}X\x
$=aQr4
Ar}aB#B
8yFObV&
Q>iI96ge
X9edb2
vGkQ<A$Y
bEI7#%
WWvmo^
,A03yUVX&
*$K`kq
w7^eIw
>1E$Pk^L4
G0"2u
QdhT].
+`@{^f
k J?>
h/<ee+h
l39e1`
rWAxhp
/qyj`O
OYc{tL&
m*p|,5
O&L0b'p@
Y,;>[2
{41sq$
!>avtk
$l9Pf|
|QA#^3X
AOQYJ^
qzLttU
$qcH(f
"?um~Vq
}}*D^G
s'(q$
K+_4p"
E|mlB>
@#GO"[Dz
X>AwE3
a s-!mg
HQ)cT'.{g
M1|SSj
P&}8U
=Fz"Cm
@i^fj6
-[rQawmx
8!5} O
9O"f'-m|2
P4j5{x
j#xu<N
Ot2_"0
+:;M1$K@$
K!I|e2F
3:Bp-QR
oT}\z6\
yj]fGTKr
.zO]);
Vch)J(
fF<EN\
(U_2rq
PNAMo8;
[:N-.}
$QTWe2
]_k ht
ettJqX
UJ<Fw@
(obd~}
cGqHz)l
d{*=&J
k1dnJNP
wcuH?#/
Lf'*\Q
n[<"Gl=
$ab"6n
N%.qfpz
!c0[7.f
=qsd@F
q%M8nB
$ *gw.
-..jQP
SMjmn65
%V\X/?
w2nFp#
JhtVRe&
qj-@2 /
(|K Y9}
5YyEve
brd<\bb:P
#PYCQ&
a:zpG^!
*K7#|HG"
HzR35}
G?cHY"
m]$^6B'{
-h]x!WU
V3hmwX
t7gvQq
k_9[b<
fo^GR!4
Q`PI:Y
#Bt t<fz;
d5ylsw
P <Dt/m
,&{#O7IZ
j9A<8o.
;7"Kn@UO
n` d6R}
I}a:5S
"3mcc7
]9~n7i
^o0R#R
kf3EY;g
$gx(-k
E4;}O.
m#<{f&
|n|$L|
lD#ZQ!
s5'bB5
msb~y2
Dl>{0+{
#Z%m7yU4
{s;hYu
$WFk0)c
rI,7+U
L4[ki(
,r_ptK
A>Nsl11
n\uc#T
yls$G.JF
n8?me28B7<h
pM8;;p
.+@>!Y
ER}JV7
.>~MLl
jpLWjhw
RTbc{o;
.9mHd37
:`MmCZ
17FK R
RNtC7]b$
tIFT";h
_cI8/
S2$8w5
CY%<SJ
i1M'~>6@
ve `hY
kM\}I[Q
l);Rv)d
zO7[cs
[(Qg/5
JY<wi?
@DHW=1
8?u~7O[8Ke
{6m39$s
78rN*C
co>L(L
ssgYI{s
0rYZ2Q
;G*`m[
R/99Pb2
SiXKh4/
_u1}Ye(
Gq$OZT`
]gWbU5a&m^
INvDvB
8[J0k(
8O:MN"+
0dq!e$
.151qp
C^wnR/
bt0cWl
zE?9Br
,def=x
uz-F7O
=rq]o~>"
X7II:W&
BY9TY8g
/bNo'(
^j+=Br
qDITq,
>M=>6v
q1sI1%,
K^|(m+
1d.'U3
@of*.
;nEgek|8
7Y7+;/
~Nj\C
9"PzYP
&s}:g8
e.O$g
vqVxt?
f+'|3:97
}Q4=@
'U<bu%
#fZu#
D7+@Q$
BZ/0s;
9!QM8H
H_@G<O
*F:$o.DU
?0N<(\y
t&#"3[M
5lxu?]
OP+Z{
|Q*gO
tdC:*tN
.[|ae:
.nAl&.
72YZU%
N*InGwQ
1Lu~~q]u+MbkV
0z@ yFWB
d]u|ok
v3EgA
f~frao!NQ
`20k!|
|aeGjuuR
tZ4o>zH
>lDpFD
v(o[,m
{s9o.=
yj%iCS
Kh-W)r;I
{K-r[F_
jC)Jdd0
aOjNiZ
Gpcx3C
ER94cgDS/
{8RtaO\
j deQ6{
814^|<
=3ys1)
<)J3.&[
*Z=zG
!Yua3*
0m=.QV
V)B!6*{
CorExitProcess
(null)
`h````
xpxxxx
FlsFree
FlsSetValue
FlsGetValue
FlsAlloc
GetProcessWindowStation
GetUserObjectInformationW
GetLastActivePopup
GetActiveWindow
MessageBoxW
HH:mm:ss
dddd, MMMM dd, yyyy
MM/dd/yy
December
November
October
September
August
February
January
Saturday
Friday
Thursday
Wednesday
Tuesday
Monday
Sunday
`h`hhh
xppwpp
_nextafter
_hypot
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
1#QNAN
1#SNAN
Lazexohex xewiset gepes
Zohiboluvitepem
Damilasosasalep
VirtualProtect
kernel32.dll
LocalAlloc
wunobakiwofibiwinatohudogusimatumucaruyewisume
RSDSy!2h
C:\vacuj93 wimamexac.pdb
SetCriticalSectionSpinCount
GetEnvironmentStringsW
GetTickCount
GetConsoleAliasesA
GetSystemTimeAsFileTime
ReadConsoleW
WriteFileGather
SetHandleCount
GlobalAlloc
InitializeCriticalSectionAndSpinCount
GetProcessHandleCount
GetSystemWindowsDirectoryA
SetConsoleCP
DeleteVolumeMountPointW
FindNextVolumeW
SetConsoleCursorPosition
GetAtomNameW
LCMapStringA
GetCPInfoExW
SetLastError
GetProcAddress
VirtualAlloc
BeginUpdateResourceW
EnumDateFormatsExA
GetFirmwareEnvironmentVariableW
LoadLibraryA
WriteConsoleA
UnhandledExceptionFilter
CreateHardLinkW
GetDefaultCommConfigA
SetConsoleCursorInfo
IsDebuggerPresent
RequestDeviceWakeup
QueryPerformanceFrequency
DuplicateHandle
DeleteAtom
lstrcpyW
KERNEL32.dll
GetClipCursor
USER32.dll
AdjustTokenPrivileges
ADVAPI32.dll
HeapAlloc
GetModuleHandleW
ExitProcess
DecodePointer
GetCommandLineW
HeapSetInformation
GetStartupInfoW
EnterCriticalSection
LeaveCriticalSection
GetStdHandle
GetFileType
DeleteCriticalSection
SetUnhandledExceptionFilter
EncodePointer
TerminateProcess
GetCurrentProcess
WriteFile
GetModuleFileNameW
HeapCreate
IsProcessorFeaturePresent
GetLastError
SetFilePointer
HeapFree
CloseHandle
LoadLibraryW
TlsAlloc
TlsGetValue
TlsSetValue
TlsFree
InterlockedIncrement
GetCurrentThreadId
InterlockedDecrement
FreeEnvironmentStringsW
QueryPerformanceCounter
GetCurrentProcessId
WideCharToMultiByte
GetConsoleCP
GetConsoleMode
RtlUnwind
GetCPInfo
GetACP
GetOEMCP
IsValidCodePage
RaiseException
SetStdHandle
FlushFileBuffers
HeapSize
HeapReAlloc
WriteConsoleW
MultiByteToWideChar
LCMapStringW
GetStringTypeW
CreateFileW
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
99#####
9%99995
+++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++J
++++++++++++++
++++++++++++++
+++++++++++++o
%+++++++++++++C%
+++++++++++++
++++++++++++++}
++++++++++++++
+++++++++++++
+++++++++++++
+++++++++++++
B+++++++++++++
+++++++++++++
+++++++++++++
J+++++++++++++
+++++++++++++
J+++++++++++++
J+++++++++++++m
+++++++++++++=s
+++++++++++++e$K
+++++++++++o
P++++++++++e
J++++++++++
}J++++++++++
J++++++++++
++++++++++
^o++++++++++~JJJ
+++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
56$$vm
HBx,V>g5
2votK{~}
nnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnn
Rnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnz
nnnnnnnnnnnnnnnnn
nnnnnnnnn
nnnnnnnnnnnnnn
2(0gqonnnnnnnnnnnnn
nnnnnnnnnn
nnnnnnnnnE
nnnnnn
<>jlTT
nnnnnn
X?j#&d
nnnnnn
nnnnnnn
nnnnnnn
"s)b)__[
nnnnnnn'9h
2nnnnnnn2r
nnnnnnn
Bnnnnnnnnn
#[nnnnnnnnn
nnnnnnnnnn
b2nnnnnnnnnnnnn
nnnnnnnnnnnnnn[
nnnnnnnnnnnnnnn
nnnnnnnnnnnnnnn
BonnnnnnnnnnnnnnnnnB
gnnnnnnnnnnnnnnnnn
nnnnnnnnnnnnnnnn
2*9&"_
AxQ[onnnnnnnnnnnnnnnnnn
}#00T?
nnnnnnnnnnnnnnnnnnn[)r[q<hu
nnnnnnnnnnnnnnnnnnnnnn]
nnnnnnnnnnnnnnnnnnnnnn
nnnnnnnnnnnnnnnnnnnnn
nnnnnnnnnnnnnnnnnnnnn
nnnnnnnnnnnnnnnnnnnnn
nnnnnnnnnnnnnnnnnnnnn
nnnnnnnnnnnnnnnnnnnnnn
nnnnnnnnnnnnnnnnnnnnnnn
nnnnnnnnnnnnnnnnnnnnnnnnn
nnnnnnnnnnnnnnnnnnnnnnnnnnn
nnnnnnnnnnnnnnnnnnnnnnnnnnnnnn
nnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnn
nnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnn
[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[/[[[[[[[[[[[[[[[[[[[
[[[[[[[<
</[[[[[[[[[[[
[[[[[[[[[<
<[[[[[[[[
=Yk`HDBB
[[[[[[[/
[[[[[[[
[[[[[[[<GmS
[[[[[[[
[[[[[[[[U
[[[[[[[[[
<[[[[[[[[[[
.Cyo+o3S
[[[[[[[[[[[[j
[[[[[[[[[[[[[[
[[[[[[[[[[[[[[
.[[[[[[[[[[[[[[
[[[[[[[[[[[[[[[[Ad
`[[[[[[[[[[[[[[[[[lr4
.[[[[[[[[[[[[[[[[[^y3a
[[[[[[[[[[[[[[[[[
[[[[[[[[[[[[[[[[[
0[[[[[[[[[[[[[[[[[[[
[[[[[[[[[[[[[[[[[[[[[
[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[
,Mo|bF
Fb~~xK
\q~~~K
-e~~7N
\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\D
\\\\\\\\\\\\\\\\\
Os\\\\\\\\\\\\\\\\
\\\\\\\\\\\\\\\
s\\\\\\\\\\\\\\\
ts\\\\\\\\\\\\\\\
s\\\\\\\\\\\\\\\
-s\\\\\\\\\\\\\\\
s\\\\\\\\\\\\\\\
Qs\\\\\\\\\\\\\\\
s\\\\\\\\\\\\\\\
Hs\\\\\\\\\\\\\\\
\\\\\\\\\\\\\\\
\\\\\\\\\\\\\\\
\\\\\\\\\\\\\\\
\\\\\\\\\\\\\\\
\\\\\\\\\\\\\\\
\\\\\\\\\\\\\\\
6\\\\\\\\\\\\\\\\
\\\\\\\\\\\\\\\\
\\\\\\\\\\\\\\\\
\\\\\\\\\\\\\\\\
\\\\\\\\\\\\\\\\
\\\\\\\\\\\\\\\\
^\\\\\\\\\\\\\\\\
\\\\\\\\\\\\\\\\
\\\\\\\\\\\\\\\\
\\\\\\\\\\\\\\\\
\\\\\\\\\\\\\\\\e|
\\\\\\\\\\\\\\\\
UQ\\\\\\\\\\\\\\\\O
Ue\\\\\\\\\\\\\\\\^
\\\\\\\\\\\\\\\\^
\\\\\\\\\\\\\\\\
\\\\\\\\\\\\\\\\
\\\\\\\\\\\\\\\\e?
y}yRyJ
-\\\\\\\\\\\\\\\\Q
\\\\\\\\\\\\\\\\e
\\\\\\\\\\\\\\\\^
\\\\\\\\\\\\\\\\\^
\\\\\\\\\\\\\\\\\
\\\\\\\\\\\\\\\\\\
\\\\\\\\\\\\\\\\\\\\
s sssss
\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\
jW%<@Q
OOy*OO
@^@^^^@R
?E5?tv}
SdS=}~
______-
_____-
{{{{{{{{{{{
G00000000000000000000000000
LLLLLLLLLLLLLL
LLLLLL`
LLLLLLL2
LLLLLL
H--------
--------------------
%%%%%%%%%%%%%%%%%%
YYYYYYYYYY%
YYYYYY
%qqqqq
%qqqqq
%qqqqqqY8
%qqqqqqqY8
%qqqqqqqqH
gggggggggK
ggggggggggg?K
3HShT7e~
mscoree.dll
runtime error
TLOSS error
SING error
DOMAIN error
- Attempt to use MSIL code from this assembly during native code initialization
This indicates a bug in your application. It is most likely the result of calling an MSIL-compiled (/clr) function from a native constructor or from DllMain.
- not enough space for locale information
- Attempt to initialize the CRT more than once.
This indicates a bug in your application.
- CRT not initialized
- unable to initialize heap
- not enough space for lowio initialization
- not enough space for stdio initialization
- pure virtual function call
- not enough space for _onexit/atexit table
- unable to open console device
- unexpected heap error
- unexpected multithread lock error
- not enough space for thread data
- abort() has been called
- not enough space for environment
- not enough space for arguments
- floating point support not loaded
FMicrosoft Visual C++ Runtime Library
<program name unknown>
Runtime Error!
Program:
(null)
wKERNEL32.DLL
WUSER32.DLL
HH:mm:ss
dddd, MMMM dd, yyyy
MM/dd/yy
December
November
October
September
August
February
January
Saturday
Friday
Thursday
Wednesday
Tuesday
Monday
Sunday
((((( H
h(((( H
H
CONOUT$
fekovimofojituzuwivuwubajiyofori
pCizizikin
gupokiw
cuhumeweliwolutuho
Laraxejofivi yiluvojut
Bofezosefotif melolu sovusutocey mimuv
Bececafiv kijumolibis mim vak
luzuwitomoyeyufepisotasedaruvexuhed
GxGpGhG`GXGPGHG@G8G0G(G G
VS_VERSION_INFO
StringFileInform
090124C0
InternalName
bomgpiaruci.iwa
Copyright
Copyrighz (C) 2021, fudkagat
ProductVersion
15.54.17.21
VarFileInfo
Translation
)Judisigidu rizuxuxoci yanor cuk yijanilug
.Lojo tifebihihopo mifibazotunewo gebedibofajolbFevu boxuloxapijah melum fizumisivifuzo vamawir peracacocubete dedahijaluyob femuxetegawoge ficeyi@Zipelokaj hac toru lon gehe yebopizecekin moka gum simo fuxegope2Dap tatikafadehibu fiduvigovido lozepe konazoreriw<Vosukuxixit tahacevada yitumogij pebuwoxipubac wifimaputazec
Rege ripoma8Hasuxecem feyidez bahoxuzukahoso fidediwubazisi vunifefa;Dopozafabayi feraturifa xuhiw depuvi dalubo molinig pixeniw+Hadigaxonabifon hiziyogadil cewaneca mazavo
ANaziwokefek rijoyurogebetuc zekitosipudo cimoxirosur vewodat cidifNibufe deviwifawinop meduzuw vigob gosi likuwunirimiyuj waliwo lepexobetoj tiwasoxewosabi viduledehewutRufebipugine redukakazonexo lazubolunimizin neliberuwipayu suki yolelu mananeragi jerepizajo ligupifujiv fayurorisus
Mafuge
Xihenetimen
Sib tuve yepebow.Gaxoz tacucefebu zezonaponapocu figojexijunora
<Wawozitaful vihowodo xuvegepoxo jule hepu kesevoxaw tugepiruJRoyixihir rukeboga cenilibivirepe hegoneko puxesuk zuxahehiri hahaz vacoce;Horenude foh yirika kizeferavibira vuzuzimoke jifejituhokoy2Somefupekiz fucokuluwa disatete neparug nojekucapeKCejude fufuju kihe jonasihayiba fegafo panaledabuleno bivivoj toxagalovubuc$Pemilorugugeha rekusemene piha zijux_Lilujidili coc tafog panogoy kisudepimev nugefewof fehebitemeger hikinagajox pemelokinuf ronabe#Yeyodup yihojejizuxahud vufumubutat/Zehogocotimehuw revim bawijifa jibobin kifurese>Vuf woregewaxofibe capopiwupubex xovokidecule ved fumu vifibowSRucahe mone xixeyiy lohalehix bihiwepa kinuy kasaxobanupugop yacutafi fawigas nugecTGewiro fezewuxasoxi xexifojituk zahojesucad fenejoyodojo xayi puti kiciweconir lovid
-Goxapayevekehad fewomexedecugo goluyapucepadu
BodafevicamasiKFal kudulezeza pepalitorulu titedeniguzoda mibotanukuyuku rarera haheniwafeTPimonuveke xuva zovom sumipuwipi zicumibayomod ligiw jihifagusivabo citozapo wafibik
3Fucizedusimoma zex pisizasamena tagowowetapu mecawe:Dohawugox lavihitur hubusojifuzi vumebuwazicuvey pebaxitis
SurelobihayoZZecuyave vahepacuyufi siviyegi jajedapire fixitiw cabemumetinod bukofozoca xitide nihowiye
KPeze yukedosija jutoy nafiyejom zeyifanodo riketaj kibohoj poji xodenusamijKLozevuz feninakoko ravabofagimegas zekowoxupe coh yuvugixicivebe coje codup
Antivirus Signature
Bkav Clean
Lionic Clean
Elastic malicious (high confidence)
MicroWorld-eScan Clean
FireEye Generic.mg.ae43eeced75fa3cb
CAT-QuickHeal Clean
ALYac Clean
Cylance Unsafe
VIPRE Clean
Sangfor Trojan.Win32.Save.a
CrowdStrike win/malicious_confidence_100% (D)
BitDefender Clean
K7GW Hacktool ( 700007861 )
K7AntiVirus Clean
Baidu Clean
Cyren W32/Kryptik.FOQ.gen!Eldorado
Symantec Packed.Generic.528
ESET-NOD32 Clean
APEX Malicious
Paloalto Clean
ClamAV Win.Packed.Fragtor-9908420-0
Kaspersky VHO:Trojan.Win32.Convagent.gen
Alibaba Clean
NANO-Antivirus Clean
ViRobot Clean
Rising Trojan.Generic@ML.96 (RDML:4HAF/l3I3q+20zUQ8qK3Zg)
Ad-Aware Clean
Sophos ML/PE-A
Comodo Clean
F-Secure Clean
DrWeb Clean
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition BehavesLike.Win32.Emotet.hc
CMC Clean
Emsisoft Clean
SentinelOne Static AI - Malicious PE
GData Clean
Jiangmin Clean
Webroot Clean
Avira Clean
MAX Clean
Antiy-AVL Clean
Kingsoft Clean
Gridinsoft Clean
Arcabit Clean
SUPERAntiSpyware Clean
Microsoft Trojan:Win32/Sabsik.FL.B!ml
Cynet Malicious (score: 100)
AhnLab-V3 Clean
Acronis suspicious
McAfee Lockbit-FSWW!AE43EECED75F
TACHYON Clean
VBA32 Malware-Cryptor.2LA.gen
Malwarebytes Trojan.MalPack.GS
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Tencent Clean
Yandex Clean
Ikarus Trojan-Ransom.StopCrypt
eGambit Unsafe.AI_Score_99%
Fortinet W32/Kryptik.FOQ!tr
BitDefenderTheta Gen:NN.ZexaF.34266.Jq0@a8Cv3ChO
Cybereason malicious.d6e32b
Avast Clean
MaxSecure Trojan.Malware.300983.susgen
No IRMA results available.