Static | ZeroBOX

PE Compile Time

2022-09-11 17:40:37

PE Imphash

730ccfd85ae71d78dc0190fcc22c95c1

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x0000e2aa 0x0000e400 5.79613919413
.data 0x00010000 0x001034e4 0x00085e00 7.99253662409
.doy 0x00114000 0x00000400 0x00000400 0.0
.rsrc 0x00115000 0x0001026f 0x00010400 5.01199092876

Resources

Name Offset Size Language Sub-language File type
AFX_DIALOG_LAYOUT 0x00115754 0x00000002 LANG_NEUTRAL SUBLANG_NEUTRAL data
AFX_DIALOG_LAYOUT 0x00115754 0x00000002 LANG_NEUTRAL SUBLANG_NEUTRAL data
AFX_DIALOG_LAYOUT 0x00115754 0x00000002 LANG_NEUTRAL SUBLANG_NEUTRAL data
BURUHIPEFENERAFUFAFIHUDIMISO 0x00115758 0x00000d96 LANG_SAAMI SUBLANG_DEFAULT ASCII text, with very long lines, with no line terminators
DIYU 0x001164f0 0x00000016 LANG_SAAMI SUBLANG_DEFAULT ASCII text, with no line terminators
TUTEHETAYIGAHEWEDURIPIHAKUHEWOC 0x00116508 0x00000ee8 LANG_SAAMI SUBLANG_DEFAULT ASCII text, with very long lines, with no line terminators
YESISEBEFAMIK 0x001173f0 0x000004a3 LANG_SAAMI SUBLANG_DEFAULT ASCII text, with very long lines, with no line terminators
RT_ICON 0x00122b8c 0x00000468 LANG_SAAMI SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x00122b8c 0x00000468 LANG_SAAMI SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x00122b8c 0x00000468 LANG_SAAMI SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x00122b8c 0x00000468 LANG_SAAMI SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x00122b8c 0x00000468 LANG_SAAMI SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x00122b8c 0x00000468 LANG_SAAMI SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x00122b8c 0x00000468 LANG_SAAMI SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x00122b8c 0x00000468 LANG_SAAMI SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x00122b8c 0x00000468 LANG_SAAMI SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x00122b8c 0x00000468 LANG_SAAMI SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x00122b8c 0x00000468 LANG_SAAMI SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x00122b8c 0x00000468 LANG_SAAMI SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_STRING 0x001241f8 0x000006ca LANG_SAAMI SUBLANG_DEFAULT data
RT_STRING 0x001241f8 0x000006ca LANG_SAAMI SUBLANG_DEFAULT data
RT_STRING 0x001241f8 0x000006ca LANG_SAAMI SUBLANG_DEFAULT data
RT_STRING 0x001241f8 0x000006ca LANG_SAAMI SUBLANG_DEFAULT data
RT_ACCELERATOR 0x001248c4 0x000000a8 LANG_SAAMI SUBLANG_DEFAULT data
RT_GROUP_ICON 0x001249c0 0x00000068 LANG_SAAMI SUBLANG_DEFAULT data
RT_GROUP_ICON 0x001249c0 0x00000068 LANG_SAAMI SUBLANG_DEFAULT data
RT_GROUP_ICON 0x001249c0 0x00000068 LANG_SAAMI SUBLANG_DEFAULT data
RT_VERSION 0x00124a28 0x0000025c LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_MANIFEST 0x00124c84 0x000005eb LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with CRLF line terminators

Imports

Library KERNEL32.dll:
0x40100c ReleaseSemaphore
0x401010 ReadConsoleInputA
0x401014 VerifyVersionInfoA
0x401018 GetCPInfoExW
0x40101c CreateEventA
0x401020 GetSystemDirectoryW
0x401024 GetProcAddress
0x401028 GetModuleHandleA
0x40102c LocalAlloc
0x401034 OpenWaitableTimerW
0x401038 DeleteFileA
0x40103c EnumResourceTypesW
0x401040 GetLongPathNameW
0x401044 GetModuleHandleW
0x401048 SetThreadLocale
0x401050 FindNextFileA
0x401054 LocalFlags
0x401058 GetComputerNameExW
0x40105c GetConsoleAliasA
0x401064 GetLastError
0x401068 GetConsoleMode
0x40106c AddAtomA
0x401074 SetCalendarInfoA
0x40107c GetComputerNameW
0x401080 EnumTimeFormatsA
0x401084 AddAtomW
0x401088 SetSystemTime
0x40108c _llseek
0x401090 GetShortPathNameA
0x401094 EnumCalendarInfoA
0x401098 EnumCalendarInfoExA
0x40109c FindNextFileW
0x4010a0 CreateActCtxW
0x4010a8 CloseHandle
0x4010ac ReadFile
0x4010b0 WriteConsoleW
0x4010b4 HeapSize
0x4010bc LoadLibraryW
0x4010c0 HeapReAlloc
0x4010c4 WideCharToMultiByte
0x4010c8 HeapAlloc
0x4010cc MoveFileA
0x4010d0 GetCommandLineW
0x4010d4 HeapSetInformation
0x4010d8 GetStartupInfoW
0x4010dc GetCPInfo
0x4010e8 GetACP
0x4010ec GetOEMCP
0x4010f0 IsValidCodePage
0x4010f4 EncodePointer
0x4010f8 TlsAlloc
0x4010fc TlsGetValue
0x401100 TlsSetValue
0x401104 DecodePointer
0x401108 TlsFree
0x40110c SetLastError
0x401110 GetCurrentThreadId
0x40111c IsDebuggerPresent
0x401120 TerminateProcess
0x401124 GetCurrentProcess
0x401128 ExitProcess
0x40112c WriteFile
0x401130 GetStdHandle
0x401134 GetModuleFileNameW
0x401138 HeapCreate
0x401144 SetFilePointer
0x401148 SetHandleCount
0x401150 GetFileType
0x401164 GetTickCount
0x401168 GetCurrentProcessId
0x401170 LCMapStringW
0x401174 MultiByteToWideChar
0x401178 GetStringTypeW
0x40117c HeapFree
0x401180 Sleep
0x401188 SetStdHandle
0x40118c GetConsoleCP
0x401190 FlushFileBuffers
0x401194 RtlUnwind
0x401198 CreateFileW
Library USER32.dll:
0x4011a8 LoadMenuW
0x4011ac GetMenuInfo
0x4011b0 GetListBoxInfo
Library GDI32.dll:
0x401000 GetCharWidth32A
Library SHELL32.dll:
0x4011a0 FindExecutableA
Library WINHTTP.dll:
0x4011b8 WinHttpReadData

!This program cannot be run in DOS mode.
`.data
hatunezimoge
%s %d %f
HH:mm:ss
dddd, MMMM dd, yyyy
MM/dd/yy
December
November
October
September
August
February
January
Saturday
Friday
Thursday
Wednesday
Tuesday
Monday
Sunday
FlsFree
FlsSetValue
FlsGetValue
FlsAlloc
CorExitProcess
(null)
`h````
xpxxxx
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
GetProcessWindowStation
GetUserObjectInformationW
GetLastActivePopup
GetActiveWindow
MessageBoxW
`h`hhh
xppwpp
D$ )D$
D$xfkp
Y;=@VI
^SSSSS
r=0ZI
j@j ^V
HHtXHHt
?If90t
QQSVWh
t"SS9] u
vL;5$\I
u}h\*@
URPQQh
PPPPPPPP
PPPPPPPP
;t$,v-
UQPXY]Y[
LoadLibraryW
GetWindowsDirectoryA
FindFirstVolumeMountPointW
ReleaseSemaphore
ReadConsoleInputA
VerifyVersionInfoA
GetCPInfoExW
CreateEventA
GetSystemDirectoryW
GetProcAddress
GetModuleHandleA
LocalAlloc
DeleteTimerQueueTimer
OpenWaitableTimerW
DeleteFileA
EnumResourceTypesW
GetLongPathNameW
GetModuleHandleW
SetThreadLocale
InterlockedCompareExchange
FindNextFileA
LocalFlags
GetComputerNameExW
GetConsoleAliasA
WriteProfileSectionW
GetLastError
GetConsoleMode
AddAtomA
AssignProcessToJobObject
SetCalendarInfoA
QueryInformationJobObject
GetComputerNameW
EnumTimeFormatsA
AddAtomW
SetSystemTime
_llseek
GetShortPathNameA
EnumCalendarInfoA
EnumCalendarInfoExA
FindNextFileW
CreateActCtxW
GetConsoleCursorInfo
KERNEL32.dll
LoadMenuW
GetListBoxInfo
GetMenuInfo
USER32.dll
GetCharWidth32A
GDI32.dll
FindExecutableA
SHELL32.dll
WinHttpReadData
WINHTTP.dll
WideCharToMultiByte
HeapAlloc
MoveFileA
GetCommandLineW
HeapSetInformation
GetStartupInfoW
GetCPInfo
InterlockedIncrement
InterlockedDecrement
GetACP
GetOEMCP
IsValidCodePage
EncodePointer
TlsAlloc
TlsGetValue
TlsSetValue
DecodePointer
TlsFree
SetLastError
GetCurrentThreadId
UnhandledExceptionFilter
SetUnhandledExceptionFilter
IsDebuggerPresent
TerminateProcess
GetCurrentProcess
ExitProcess
WriteFile
GetStdHandle
GetModuleFileNameW
HeapCreate
EnterCriticalSection
LeaveCriticalSection
SetFilePointer
SetHandleCount
InitializeCriticalSectionAndSpinCount
GetFileType
DeleteCriticalSection
FreeEnvironmentStringsW
GetEnvironmentStringsW
QueryPerformanceCounter
GetTickCount
GetCurrentProcessId
GetSystemTimeAsFileTime
LCMapStringW
MultiByteToWideChar
GetStringTypeW
HeapFree
IsProcessorFeaturePresent
SetStdHandle
GetConsoleCP
FlushFileBuffers
RtlUnwind
HeapReAlloc
HeapSize
WriteConsoleW
ReadFile
CloseHandle
CreateFileW
)e~MOFk'
k`1uv6
U-Qc/C
E vT0p
(ed30m
`SdDXf
Ax%NDWd^
hk_:R`
9_tGuZ=
'w--dbE
EpqelRd
AWn,ikr
[LGh7N
Si^dfU
4p|gI2\
4'{P4~
Z/L?9^
"'^Y]Y'
Dup)Uz
1,Ei_6
L=gN?g
lv(O(Q
T+w5`_
+GP]A
8B/n/'
c/hW?
fLYdhv
#@R'@"
2EkuA'
Sk7ZHo
P9,J$U
.5jOy0
nml)*Y
iA]eqe
.Ksj@f
w6]{Br
PLY;KG
P-&,)fZ@f
"yw:S9
_WkUI4
]"V8D~
!%bM@,F
FocH50
x$+v,X
]iD==;(
2Tx0*7
G-*8?v4
#kpt]
\[=2CP
0k[H#[Cl
?pv}k"
4XGB;
*K8!pa
GR=2F8v
T>7V_B
fhAyyw
:J?(j=)(?B
v7fiq5
rR,IH4*c
1<BFX@
jjmH&+
;~Bg3el
z<C0,,2sl
Ar&)CKH
1;O0=.
l+i8$6
,K]pcmr
x+RV3O
IAHN{i
g(0spV5&
gN__<@
e!aV_O
@1u{TU'
-vI9T
&0Qc|J
akmH+][
UQAnUd
<Na1{
T,mg7
J~M*H,z*cRA
zL:o/,?qs
7#`"`f
c-Uh@n
Xv2"Qnz
*F|5Ny
M,N6Y4
*/-8=9O
'N-BIz
sHr;IR
I+U:-{
SUb+>b
XNAh?P
iiKooX
=@gQs*2^r
z1P>CX
BnrVe4
rf/C"p
K~_Tvd
1M7o_|
](% =?
GM?zFtN
c}g*DfE;
QqL}7~
Txlv,}
pe5R|)>
J&\w=w
`'S)%&
`3:z!a4
Y02ZNpw
#.gVBq
#b!G!##
w<vBnW/
Co"&0h
r"PIhE`
n)%H@<
g:<>:l
~{y}nglvt
vakHXMs
{e"z"
yw+z</>
rFXwMe
IFp]_b
nZ`x^x
mB-/0zB\Z(
*o6Bn"
*OwO%0
6nBS;0
Csear
OE2ShV
=+bsZ5
_l@Qkz
soLh}C
Whk"+J|af
{7k..:5j
kd+c&0{'G
C[Cmnr
/^ m8Zj
3kXq#M8s
fiqZ:O
1@SvIi
xDNG@G#
5AqApZ,
a9]jz-D8_
8K`56U
m.!aY>
,.^~gei/
hXd$\(
?o~[ Q
,{s+tz
m8bC(A
0e*YG
Ot8p77
3<;fGW
630L*AX;I
xHkM7B
D1W4)r{
>>AhY\
)91no!A.
h`s'_)
XSp<^u
0HF Rd
\u=mj^
>nYBH3
#&,*__
9xw$D_
k%~fSN
gy"UB+7
lq\q@U=
/l>oJ<A@:
}>75!Ey{
mkBO!J6
-ivOOC
Sq#$2/
AW;4`?&
{sq #e
07a^57^
>%yl6&q
R(f5Evn'*
C[Ruq.
%z4z@y
3<:j+P
tM/K;#U
c>9KIEi
.y6Z,D
{].=d)
+X|(Id
.!2zjS$
Zq}5iX
_^1$&)@
9dOBa<
Q"(_@+Dw
K't@84
D[e;'G
&)H}va
>^"a-_(
$8GZ.B
ma_^x1R
d?j-'c
ll. 3^P
P}BK?rz
wT/)FA
~-k'mX
UbPqd
GWJKB:v
Tpyg3I
>t{TT_
kbz@hC
[-k-&
F7$=+jr
3-j!oq3
g-lELo
1n{1+.G
!y'W}M
no Rb/
z{G,`s
*A%{nN
^z>R{~=
C/;K(8#
0}-~SS@W
?<qJF`[z
oDzRaM
J&fYv_9"
==u=`m
*Q:7HP
eY84XD
:?fz/Au
@NHH#P
[|(tKg
\<7.bw\
S/5!1b
i0s=Y'
eW^]R1
DY:Z:`
!UB#;$#
|.<DY7~
E {4{\
d*cgU3
7yX@#[
aJ~}]`3
cfDeL%
LwI,{YL_
1]W&2+-
GoavR^\
+`[opX
#H#UtO
m/hA;~
|Dx[)u
!T^es:e
I{-ci%
7Xby G
VR7+h#
7pJ|@D
"J=0!
I.mhVW
@'%+P>
UWwBSlE
ajnfL[
0k345w
<@DW^*
(%2;4R
Xt3Eo"v
e%xc[E
5/48eb
xle|k-m
4C9%!d
d_WVP7
7@Xy1;^;
}doVa'
kCOTy6t
<VUfm
hKls(*-8
!1LmW/
dL7P8_S
xw<>oM
18`&.
)&hwev
E9?w_t=
3SA<V@
@[FcK,
;\7m"Q
fi;%oMb
[Q(.S7
V$&Del
3/,~Lh(
@ZG.K5
EJkm>0
Ay7xH_GdL)|
Wlrqg@Dn
2<V3FN
Lu|5[S.c
?.!0D
B"oJLLe
*gAJ'iD,
-:"Y<}fYI
Kb8Xc'o
DvvT(IA
.z@/AW
R>{FGF
gf%Wg-6h
]:1" !
]Nt,%Jq
2h{~x;
lgPabS{6
h(}xT&
'ri%Qys
@[|Znm
[YQb88i|
7ig[.g1
OC!RG(
q}{ise
hL:ct"
p$ZC-:"
qGpUJZ
#^*RR2
9~do`>;
-4gEQN
pek/@N
B^A7%-
H`a7$1
KYb[~n)6
h-fp*@f
1NQi"!W
KCHw_>
M1HG/a~
mq#|UY
S[,nA5j
kg6MkF
WHJ5w@>
C3prtf
KBeq7M X
Htp95
KiHc_g
Q@A%Zo"[bf
y#\AjM
B,I~=\
L<KwlO{
?Z`|o'
rgF<n
_/18zV
`lNcAn
B$\Vq?
S;lSi,
-R+l#S
>:g_-A
+Zc57[
!~A0bn*
q?}Q`64
KU(f"%
HNy8Cs
w@w_Ec
o$?qRj
@?]`YDh
Z`6W{
WAIi:0
0$r%8M
3pZ~0=/
e=mj"-
v-vJ6"
b,r|`[
&W/J~$
W(T<-G
KSZd8z&
R~y\7'
W_&xV<
Ls<\T"
.A!dJM
)0.OM"
yj/kE^[
DeiA3,
y ]'ptt
B06)9x
4uH}m
mhDq"i
a>G2:L$
hChWW"
H;&e&L
S!e(~D
OsA;UzM{
g!?-33
A+c9IE
H$BR:t
VW)J,
b7%F^G>
bT8;%B"
U?u#L(
)tuFn|{k
X2[RX_
(6Hhh`
67[X9+
>n7iC"
VtZi`N
?(XU9k
,!WO+e
E4M&CR/
:Q=$'s
Y,lLs
$aYoe+M
w4?3t_N
iBb>5i
_j\[1`6
0BZ|',
_ Q:LW
ppy:a*
nLxK@t
2BEH-?
-KL+M@QQ
J+txf/ox<
{hUi}[
xEg2O`
~$OS"X2
}s%u#?
^Ai>WH
_Gk4wl
P*E$r7
&ku)h*@W
i6a,Z\
Bg{5;=
`5_s3%
`RX6M
A>hj%(
T0?IU
#)7,\8
1%C=M;
vt:ZrI
yl5eC2K8<
D&dNc@
iHUeDJ
fhS[B!
`8R58`4
un?RvP
12SFrg
v<#:\$I
2faqYu
/Oy*6\
9ya@y,
l}2YI.
#,Z~BL
Yp1ji8,
P@Mzw3
q,PtCt
\]?Ec;
cB$0Z>Dw
#dguHs
\=as,
@nKmgpX
(3Z(yN
*PPQh_
abC@_>>$
zIqLv?8
C&l[XS
LuP6 "M
!`x%@@
L<[)(xH
~MKy@k
q(g2e3+
}%|J{'
GrM,>nPW
ssU>A g
V)/;Hd
_8:;w8NM
CKZ+tl
2.?a'n
A\=Q5:
]?),KqB
_gMHTt0
-5%PT<
McPF=po;
)>OhoR3
E/,H|~
$\wIcg
&+k]g'f
M`zP|E
P~9//Z8
>{k<2i
I5hoKy
nu #NG
f08an[
FDRx
|5b=9k
4Ke?Ze'2
q"32q6
0$h[5Z8
t,*t3B
a.#-D^&G
Kl`F5~b
6V,mDz
]~D)%m
W}+J|W=+|
~mU{ZF
b00mU[
MSSy/wl
]Pl 1(
+jU(Ju.
j|8@p\0
DO`*I
gP=HD!v$
zOU_be
&Z3G\lQO
eJV-Zql
/--0tJ
g["YU
Xg0|Zp
!tgXGfv
IEySBV
KX87>y
?|zV>S
75"io]
55"-t6L
By]6X\
S$qlM[
7UzU+o)
ak#D0/
Sx q}jX
P|gH%b
]A33qNg
D0u9qV
%]9K9i
,SgKsW
B;I8]o7
EVqX"%
WsJ>8%
sjTL&
j[J(!^F
e{@zTm
:,"S3:
tAv%!i
*_{n!O
ns^sHN
Ujq%pWH
W}@=M
8XwYv%]
P8Hsl]
3iNdw>
S1y~>},
>_6h4K
sNN-p8Yz!
uRb25a
{`}kIN
<r9td;
v)1>4TC
394W]}
K6nA=Z
Vr=fvS
7>sC>S
OH0LZN
$mI'!/Q
nY?Abp
PZKS&2
qeb6 M
LP>6 $
YF8W9q
5[Vca~
s^^V?=
J[8* i
Fo+(8s
=]*)71
zMU@Pq
5qAo]1
nRh6gXp&o<
fIB#YzJ
txCzln
ngwh?[
}.?HG
!mgi4b
ffU8&C
o_KZXE7A
j]J<9D
:j@9_{hS
>ciKXk_=
yM,OPWh0$
z=pFpX
` NgqS
eUwy,L}d
qWg]qY
'aBfG6u
NeMSm!
XtzBOD
+hl@#T
f%#prD
~5nMC6
EK1qvhj
d1eNgr
#W4|uX,
^fpM{Q
%+<M}"0y
>>+I|^d
A)`}ra
!#dfP,
Dkx]7_i
iJ]'%t
Zq=w5c
RA7JZ{ux
O/tl3T
Ic|/{F
\=<iVP
a,>UWf
&|t~\o
B6Vm+=
;Hxvjf
dSmm@
Sc LL n
"P_tQ"s[
f||E$y
)E9#-1
\)jh3,
ZN ^X}z
(1c#-l
;GSOF`rb
>8arxO
Mh|)l2
G2Z5AN1
2 6K<h
L),R:7
wmHw}81H"
'}&d&6
d"n/5e
e]geF
K(w?%*
O=>Y<-2
cq{paJ
_]?4<G
[w/J|d(L
TDsoJ^
'bJPBz~
N$N'j06<4
\F*Ji,
XFBHmg[@
3C~GcYb
'S=&IU
n/b[EB
Pz{sOVn
TnCP^hMq3q
HTRZ[C
Vq`IJ-y
Lrjb0G
()}_|2Mx
BQRO,m{)\
#N0sGE!
#)&gP,[
|1hrQ).
a`"yX-:g
<a(zrf
N=U&fY(h
nfCHE:
<~iXAP
k8\fO9
CO;~A&
AL40Mn
u9G!(T
BMMdXx}
?uL(>~
Pua|bIW
+CnzJ`f
PVZ1yCW)&
9XdM*Z
0\z?<
[gLV|9
6[3EkaF
(5:\b0
ZSM,\+$
p]&4I3n&
xI*O$[
+|KCD<RD^.
M :yOL
TySf8r
bnXu:.
s!)$LT
:[/O/I
eXlnUv)
SbALi2X9
A8T{S5
V8+37a
@^XK<lsj
080WGk
'Sml:"9
k,Sq"OgU'y\
;IG383
'ZInZ4
$= k
qZ`mT5
0S0z%[
)38EKU2B
ARlZdKQ
#/8O:l
dA#-m;
[lB&Za
3t;$4f
(|t(6t
Ph6)mEI
Zb0tY^3
\^R0=}
*B[+8;
D1{AzX(
@s~N!!
lxk"_A
tvTVgQ
P{<`Q@G
~JSp;R
T\i)",
&rydh]
2$12aWf
=Uzx]A
q.RRr:
_0t.&B
S!{@G[|
VUL*a&S
`tfZ22
{,_#/c
\5/Hj.
YU%RM%
w+^;^4}3M
eAC,_U
*!^nyS
V*V*#@
@|\kOG
MpMEDrfH
})kFDJ
Of~<PI
W"Igfm
#KaQXE}
EdapNu
Cm|\tv
0Gix]b
KN#/un
p'|\DR
-<sGhS
b.@Q>N
fYxlj^
"EbnHPyl
0z3'fZ
@II0UZ
E[VwVna
abs4bGJr
82D|o-
L)S7dwF
Ef.>W4
NoP[abf
nY7|uy
}BJi-]Xj
Ld>DVR'
x!+:ba
S3FQCkg
2c3X\u)
GS"!scR
^4'euT
/DRoD-nx
xEaO}S
`]9gb*
uLJ-$I
>Q=NSt
VT\OJ:g
HFv Y
v~g]'#
3Vz-e}%s
LD;h{K
'2}FR SHG
Q+Uq/
p#8rWck
H82PgE
rr;A^e
Q8{J1P
LPM[|_$vt
[d8N T
Sxxs-ld
s\Vd,s
u> AY>
a)IKNH7b
24MY$R
;^c0IC
qmq^L
Bb)7UW
TB7h\SJxG9V.
d#6$@;
Hp^cu<A@
*bZq/b
PNt qIb
iU%jW$
:hbq)(
N}o'ERx^[
ckVO0X
6:j6V%P
HBdW*
IOG/n(
R9@'R)
_y{yFkYF
_}w^)0
sQMEJj
cT]Pax
K.niOj
-U'1:[
s)CBU,
&_d9.v
WS_#ivk
iOP#jln
?Fk& U
i7G_a:F
^oW=X#'6
b,y{`k
S_T|9P|
3']fQ(i_
N:Jjg7
n0v; e
dVyp=@
3WF#lo
:k_.e
Rwcfy
h [_J<f
Ab?u]Q&
+OvqyqK
mhBP5<U
WVV)`K
#OaEmS
k(_H~<%
RUd>a+
KR:a_g
!oli]4
p#+*1o
N6|"`Y
z~=mH>I
KJBQm'2}s
<uinBi
FF.*fx
!|l7;3
SZUNhZ
=iZ{~N
.z?^d!
T+^>e3
}#!f`\
QA;g!=
(|j-")E
Ysq}=V
UJoBDNw
Wh0qv9
2{B~l:
d60e]r
{kT q3
rI'| A
$nu0"'
X9|,8
8/0C}p
2^Sv|
}N3lQ7
(!7Y}
)hMaWQ
slAP)|
{8Uc/m
"9day+
93n!V>
RH^ivL
6y\+CS
}.>"jd6
_$3#^!
`QT6iXT
{mv$hP
fLoIVo
'6H[>P~
eq[8EiA
{1q"6H2
wK(N"oz
RWV%/^6:
H>9v^?}
w~\Ji`-
qH5)Qh
WGZ|Om
~5n5}O
NVQ;}*
dU\9hn
7t\3Gj
q_@]4Zu
=1x69X
kFUdhmEvu%\
+rzef$
=D\ov*5
z:|A{e
V#XW(
^^dWoJ
F;U?rw
xd_O~Z
t%l8=|r
X<#Pi2
Z?HV^)
NVcdS-c
~G{4.I
QuCafVn
)S-HAz
**Rx
N=yr=&
I\F+83
e~owQF1
p54pn'
>S|yu"
&~^r$^
%0\.?$f
3Z?@a`y
u/V9YJ
zfxbSi!
\amY.<
_i|zFX
]`U;z;
qq`,aJH!
bq_t+'Mb
2)gVf5
mtKO\1
@}ql(Lb
BH$cq#32!|s.
kIjx:]I
2%o]e=)
%n*-)P
I=gu`H
^GAWcK,
qVl(8l
1mkw{(Y
)5i=](
Rz+"[
`a,cQz
M;|hC*
@fU^hw-SL
.|_&7G
Xbs0l\
mG48G3
^#zsG9
qHcv~T*?F
el$WbU
$W[gun
b}rCxeR@
g&L|9/
x|a%]E?$
}dY*y,
mGT'j4o
h-7L(d
Yi^6D6
T&28ni
CdAios5
W0S!AH
T,R ,-
EX@.&u
)hw[e*
eJm"J#
CLw[C7o
dP=:q1
IN-#vE
Z[[*p^o
3#:f(>Xt
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
Nukosotefec. Tovazaz. Wat. Gaduvaco borihinaxotoh catocesoroju nidilujomanas nitezupu. Yefecelabewat resofaheno dobebov kilegibonuhoma. Vujevewawemifug. Jatenav roceyuzayur kamup hewupivezo puh. Tosegeme pebigejalif fareyodijeg. Zav yesiwudokam cajevamocahoxed jifehetipeh. Letege jocak gepoxagege. Zoresamuwazi. Diyeniwulowuh bip bugoba xorufunupolegab. Rupitetiho zexufoloyezodeh zaco. Hetavufuzu waped cuj xah. Bay. Yowumowekeyami suxemu voyaverocupidud. Madofamon newoja. Geyijupefovo pexocit welacuhexuh tedufelipehipo poceruliza. Kuwaz. Deriziyire tecibadicexuxab nivofufozusi rewopi watijecufuvu. Pudijusewekuvig dosavumakezami. Decupixojufoc. Vaci naxisisohuf sexegakufotoka. Vasidi puyihok pulotonoh tasogogidi veyubonu. Tuti copika fuvegumebi deyu wuwaz. Radocirava. Xipejuhice bewuwek. Fuvijoxe xifilamo juz. Liwenepet fitokow. Yupitelixarir fovukababotitu mavi catudimolakuz. Surehasakivodiw ciharuticasox gunozevagil napeluri. Milewanasucabi xubogi coji mobuha jadafupoxeba. Fuho zawapa pivaxuzoxayo. Juyejebolo
Nuvecuwinoxex dofinine
Cewugodoyo yekik. Hokeherejo hojuniy siten hovemajabokab. Povixeb kodigodetulates suroc baben vomoloj. Xonef rahim ridedomibaxev. Lixizo. Vikoyibom xejecunod zadulobal bego. Zon melenovek. Rojucar pabebosopegemud gekeket. Vizasuma nemimekadu kejalutivaye. Yehimulu tuborivubisog sadu wugiromuley tojoyizej. Hiseha nikuyaduti sohowapes. Foxijikekaso. Nerupazuxoso yuvubu. Divewiyasoy hoxewakad punu. Riditafozasu safenoxep togaxayovuyuf cace. Wegehocohec kimap. Mehuyix defoxayomogiso. Nemigabofeha. Zanar timitu jugicuhona dego. Yecajikep xotihahu yawilukekoc. Kuh. Ranag piji riy lanixop midafotobef. Jiwesasubohoj. Tanexac rituvisido webafuhosikuy. Jezid rawej. Yute pidore bivo pigizic bawu. Kiwodub. Cuwo wegicemo gipuvev xotefowoyagi fotavoyakobutox. Hafepafek. Foluho. Luheg. Novemim car gopo zah pedamitocosu. Cewejacuvusagi. Soho zocafopo yobugapuy jexo. Kih lesu rotuyeb. Zaruyosaruc. Modayofuz cazi. Zadogip. Hugezozopa nabobodu lemizubecol. Ravan. Suhewaw gezemeveweraf pubajohedogibog yuwadakisejolow. Godopo cuj
RRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRR
nnnnnnnnnnKnKKK>RRRRRRRRRR
KRRRRRRRRRR
KRRRRRRRRRR
xxxxxxxxxxxxxx7
KRRRRRRRRRR
%xxxxxxxxxxxxx7
nRRRRRRRRRR
xxxxxxxxxxxxxx
RRRRRRRRRR
%xxxxxxxxxxxxx7
RRRRRRRRRR
xxxxxxxxxxxxxx
RRRRRRRRRR
xxxxxxxxxxxxxx
RRRRRRRRRR
%%xxxxxxxxxxx
RRRRRRRRRR
%%%xxxxxxx
RRRRRRRRRR
RRRRRRRRRR
RRRRRRRRRR
RRRRRRRRRR
RRRRRRRRRR
RRRRRRRRRR
RRRRRRRRRR
RRRRRRRRRR
RRRRRRRRRR
====================
RRRRRRRRRR
====================
RRRRRRRRRR
RRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRR
;}]Dt:!v}
D|#]bO9}
}s}]s }
sbs#O"5
s,XHkwv
F}kg"y
~y}|||{
z{{{|}
|}~|}~~
~}|~}~~
||~~z~
~z}}|}}~z|{
~~|||}
}}|z{~|
~}{~{}
}~}}z{
}}{~}}
|~|~~}
~~y~~{
|~~}||
}~|y~z
|||~{{{
|{|~y||
~~|{~{
~~~}~}
}}~}||}
~|}{}|
|~}}~~
z|{~}|
}||~|}{
|~~z}{z
~~}~|~{||
}}}~||
~}|{||}{
~{|~~|
Lrrrrrrrrrrr
>>>>>>>>
>x>x>x>xx>x>x>x>x
xxxxxx
xxxxxxxx
px<<<<<<<<<<<<<<<<<<<<<xp
vvvvvvvvvvvvv
vEvEvEvEEvEvEEvE<p.
EEEEEEEEEEEEEE
WWWWWWWWW
^^^^^^^
.v55^5^
IvO###v
C)AACI
qHHHHHHH'H
vHeeeeeeeeO
Hzzzzzzzz
O44444QQQT
lTTT}TT}T}T}f
l}RRRRRRRRRRRRz
<<<<<<<<<<<<<<<<<<<a
<<<<<<<<+
^<<<<<<<<
<<<<<<<<
A<<<<<<<<
I<<<<<<<6
:5<<<<<6
<<<<<<I
<<<<<<<<<<<`
' <<<<<<<<<<<<
<<<<<<<<<<<<<<
<<<<<<<<<<<<<<
<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<assemblyIdentity version="5.1.0.0" processorArchitecture="x86" name="wextract" type="win32"></assemblyIdentity>
<description>IExpress extraction tool</description>
<dependency>
<dependentAssembly>
<assemblyIdentity type="win32" name="Microsoft.Windows.Common-Controls" version="6.0.0.0" processorArchitecture="x86" publicKeyToken="6595b64144ccf1df" language="*"></assemblyIdentity>
</dependentAssembly>
</dependency>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v3">
<security>
<requestedPrivileges>
<requestedExecutionLevel level="asInvoker" uiAccess="false"></requestedExecutionLevel>
</requestedPrivileges>
</security>
</trustInfo>
<compatibility xmlns="urn:schemas-microsoft-com:compatibility.v1">
<application>
<supportedOS Id="{e2011457-1546-43c5-a5fe-008deee3d3f0}"></supportedOS>
<supportedOS Id="{35138b9a-5d96-4fbd-8e2d-a2440225f93a}"></supportedOS>
<supportedOS Id="{4a2f28e3-53b9-4441-ba9c-d69d4a4a6e38}"></supportedOS>
<supportedOS Id="{1f676c76-80e1-4239-95bb-83d0f6d0da78}"></supportedOS>
<supportedOS Id="{8e0f7a12-bfb3-4fe8-b9a5-48fd50a15a9a}"></supportedOS>
</application>
</compatibility>
</assembly>
yadiher
kefuxabebavat
zeyifavucojabog
HH:mm:ss
dddd, MMMM dd, yyyy
MM/dd/yy
December
November
October
September
August
February
January
Saturday
Friday
Thursday
Wednesday
Tuesday
Monday
Sunday
nKERNEL32.DLL
mscoree.dll
runtime error
TLOSS error
SING error
DOMAIN error
- Attempt to use MSIL code from this assembly during native code initialization
This indicates a bug in your application. It is most likely the result of calling an MSIL-compiled (/clr) function from a native constructor or from DllMain.
- not enough space for locale information
- Attempt to initialize the CRT more than once.
This indicates a bug in your application.
- CRT not initialized
- unable to initialize heap
- not enough space for lowio initialization
- not enough space for stdio initialization
- pure virtual function call
- not enough space for _onexit/atexit table
- unable to open console device
- unexpected heap error
- unexpected multithread lock error
- not enough space for thread data
- abort() has been called
- not enough space for environment
- not enough space for arguments
- floating point support not loaded
@Microsoft Visual C++ Runtime Library
<program name unknown>
Runtime Error!
Program:
(null)
((((( H
h(((( H
H
WUSER32.DLL
QCONOUT$
AFX_DIALOG_LAYOUT
BURUHIPEFENERAFUFAFIHUDIMISO
DIYUTUTEHETAYIGAHEWEDURIPIHAKUHEWOC
YESISEBEFAMIK#
2Puvubo mizitagucu molake tez wuhuc kafawabusesolas
Pevidifecotote rojay=Lesisojov mojefabadis vawilelurore terucorifanamal wicosokufi[Tefele miviv fekocolin veco vukolisutopu gofovererebar sedobudicaz xijayinu vuzihajohebavawaPolab yububofimo bigogopogunokaw zasinesof kiduxufacisucuy buviyajojih bitemomer xahef rimocuwiri
Zidoyafexi(Fixa helatuya fogukutunuyu rudopug nogos-Bufuxu woxoki yage resaf kelobuc faweyodukomoASesukap maj pacinocuwib tapisuv xoloduwiju devupujihaya xam yodamGig paguke vadagupiy kohapibelatDetebafovusaz giyecakenicuzo boko famofiyof donafutit woku zuwicoxefakax xeyezadofiha pixacificejotuc vaxovohoxulebi
Nisajutasaci fiyajedipocodeWCaloxoyitajeto nah repuzuvivuwaw bodacumeduwa xomulicoliku jenoluvexudiban fodeva wuzagGDupahu ruresaposifixa bofisun taxog neze nahuna fun keyakara sidohihujuKVutavevizukeseh wugopibabuze jubusihi gayawuyubon cekoyu cubejatedida sadik'Bocu pawofuguha tiyadobot nasije megowi
Xaravuwo folebeyezi
Wawugiko buxuPHisikutulesece lomoheces daked bana hapuyewowamop mugunubiru dogobiw vemoximejox
Yazalagu bolerelebele
CucubinexuzilaraNubasipapu yafuhaxuviyisey zeniho vasabibu havimemabomap rujekega bexi levanupiyewidey guvirosuli/Ciligoli mec kixor cuwakazi yapogezoxurulo zaheKBepudogop birox rubocam busegow hir donetez gof gedux mofuluhihawi yozidopi1Sihiyiyotiyuzu ridu yehucawasogovo haziwerof furi/Hicomamin yuru fajifu pekagibulexo divebawomoge
Yubulilumu zufib yohajeyawiiGefimolixejokaz cohecuyobuwomox sosumisaxico nuravuvaput camexenewuz tipasecewa wutafapepahaf jayaka gici*Yax tove zagokafevicux yevajihomufeg tabup%Mejum nuzodo dakigigugacaho fumogehalNCivu pasa fev padikixajijivin decagumefutez yayowonakujoy kiha murid zetifumetONumozuhucawil zep pekitus jepehonapagicir segahunaxufiy yalezunejus rubitevonec!Zecex vacumacinotegu damipunawowa,Koc sohu vewubageba wawikogizulo deyimar pep
Miviz xoy yiye`Picotohes vemusonah kujo fewoho jezihir livatomoligow gadilelerazena cedirafopaviw xakahabuguzigYJexojugeruhuwi newugewefukeje hisa baxuyojet tejimimatimoh vobo zusapayiwatumuk kefedikul
LKikuta seguxibuhililac xicaworobebapam wuhecuni wigote fuyucilu vikubucumeza
Rawotusulaji rixemixavosutfMafacuwe logomo pawibowupezico jikuw yozegofufo hiteyipigolu guhonoxez betuweteko yubicirabo sapefibam
Xosibude zeb vupobecujgYomixagilaz tadijuwijumim silugunoremuhuc jijacipa xeyotadihuto tumasaloyi sivefe jozacez zetavafah map0Vakofayukojon linolax fejazoyaluwihet teluyebogiEMacuxenalala saboyohemil fuxoce zizo tepoyobih lohehavasepi fohagazob'Tigizef pipegi pisevexen yecujaxa vuxojFNayukewakiwe gidewacoko duvap lagexarafaxe hinoba yagaxafi yefureyumonRVogahis tekufac dunanehoweh yusutasuvake fewe nodivotabu rufoduhamey cecekewanehod
HahelakakocPZajerema dujamoguhe dutubemiw cub nosuvo hehawubezomux gez ruj suro yoroyahorifoCBitafogusot yebexunodumi disepuzoci xoyihuwucuremij xulujetajuvaror
Titikabuy bew nop%Sevigunafepewe zugufi dajuvotazuducewUXitacicivumalor fefut nuhesonovodugem duyotucohe wifuguxupogu jumegudu rowuzijatojozaeMumaber lugabizixejetaj wunesuvex royohu puwiwej lur najobovafeteded jimowesilixez wavadu hahozucusuz,Voyalazeca pexad suzamelubelab belewonupuvob
VS_VERSION_INFO
StringFileInfo
046805E6
CompanyName
Furious
FileDescription
WholeSheet
FileVersion
99.21.74.80
InternalName
FloriousCourse.exe
LegalTrademarks1
Coordinator inc.
OriginalFilename
roulette.exe
VarFileInfo
Translation
Antivirus Signature
Bkav Clean
Lionic Clean
Elastic malicious (high confidence)
MicroWorld-eScan Trojan.GenericKD.65878993
ClamAV Clean
FireEye Generic.mg.488720af6f69c898
CAT-QuickHeal Backdoor.MSIL
ALYac Gen:Variant.Zusy.452500
Malwarebytes Trojan.MalPack.GS
VIPRE Gen:Variant.Zusy.452500
Sangfor Trojan.Win32.Save.a
K7AntiVirus Trojan ( 0059fbe91 )
BitDefender Trojan.GenericKD.65878993
K7GW Trojan ( 0059fbe91 )
CrowdStrike win/malicious_confidence_100% (W)
Baidu Win32.Trojan.Kryptik.jm
VirIT Clean
Cyren W32/Convagent.BR.gen!Eldorado
Symantec Trojan Horse
tehtris Generic.Malware
ESET-NOD32 a variant of Win32/Kryptik.HSZY
APEX Malicious
Paloalto generic.ml
Cynet Malicious (score: 100)
Kaspersky HEUR:Trojan-Spy.Win32.Stealer.gen
Alibaba TrojanSpy:Win32/Stealer.45076846
NANO-Antivirus Clean
ViRobot Trojan.Win.Z.Zusy.675328
Rising Trojan.Kryptik!1.E370 (CLASSIC)
Emsisoft Trojan.GenericKD.65878993 (B)
F-Secure Clean
DrWeb Trojan.Siggen20.1541
Zillya Clean
TrendMicro Trojan.Win32.PRIVATELOADER.YXDCJZ
McAfee-GW-Edition BehavesLike.Win32.Generic.jc
Trapmine malicious.high.ml.score
CMC Clean
Sophos Troj/Krypt-VE
SentinelOne Static AI - Malicious PE
GData Trojan.GenericKD.65878993
Jiangmin Clean
Webroot W32.Trojan.Gen
Avira TR/Dropper.Gen2
MAX malware (ai score=88)
Antiy-AVL Trojan[Backdoor]/MSIL.Convagent
Gridinsoft Trojan.Win32.Gen.bot
Xcitium Clean
Arcabit Trojan.Zusy.D6E794
SUPERAntiSpyware Clean
ZoneAlarm Clean
Microsoft Trojan:Win32/Casdet!rfn
Google Detected
AhnLab-V3 Trojan/Win.Generic.R561584
Acronis suspicious
McAfee GenericRXVO-MJ!488720AF6F69
TACHYON Clean
VBA32 BScope.Trojan.Khalesi
Cylance unsafe
Panda Clean
Zoner Clean
TrendMicro-HouseCall Trojan.Win32.PRIVATELOADER.YXDCJZ
Tencent Win32.Trojan-Spy.Stealer.Szfl
Yandex Clean
Ikarus Trojan-Banker.UrSnif
MaxSecure Trojan.Malware.300983.susgen
Fortinet PossibleThreat.PALLASNET.H
BitDefenderTheta Clean
AVG Win32:TrojanX-gen [Trj]
Avast Win32:TrojanX-gen [Trj]
No IRMA results available.