Static | ZeroBOX

PE Compile Time

2022-02-11 05:22:04

PE Imphash

cb0d32ad83907c8b5d9a97a27bcf3623

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x0001b69c 0x0001b800 6.52787612792
.data 0x0001d000 0x00290f88 0x00015e00 7.30552733125
.wugosa 0x002ae000 0x000016a8 0x00001800 0.0
.rsrc 0x002b0000 0x00016e22 0x00017000 5.17767557004

Resources

Name Offset Size Language Sub-language File type
AFX_DIALOG_LAYOUT 0x002b0b20 0x00000002 LANG_NEUTRAL SUBLANG_NEUTRAL data
AFX_DIALOG_LAYOUT 0x002b0b20 0x00000002 LANG_NEUTRAL SUBLANG_NEUTRAL data
AFX_DIALOG_LAYOUT 0x002b0b20 0x00000002 LANG_NEUTRAL SUBLANG_NEUTRAL data
AFX_DIALOG_LAYOUT 0x002b0b20 0x00000002 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_CURSOR 0x002b30b4 0x000008a8 LANG_NEUTRAL SUBLANG_NEUTRAL dBase III DBT, version number 0, next free block index 40, 1st item "\251\317"
RT_CURSOR 0x002b30b4 0x000008a8 LANG_NEUTRAL SUBLANG_NEUTRAL dBase III DBT, version number 0, next free block index 40, 1st item "\251\317"
RT_CURSOR 0x002b30b4 0x000008a8 LANG_NEUTRAL SUBLANG_NEUTRAL dBase III DBT, version number 0, next free block index 40, 1st item "\251\317"
RT_CURSOR 0x002b30b4 0x000008a8 LANG_NEUTRAL SUBLANG_NEUTRAL dBase III DBT, version number 0, next free block index 40, 1st item "\251\317"
RT_CURSOR 0x002b30b4 0x000008a8 LANG_NEUTRAL SUBLANG_NEUTRAL dBase III DBT, version number 0, next free block index 40, 1st item "\251\317"
RT_CURSOR 0x002b30b4 0x000008a8 LANG_NEUTRAL SUBLANG_NEUTRAL dBase III DBT, version number 0, next free block index 40, 1st item "\251\317"
RT_CURSOR 0x002b30b4 0x000008a8 LANG_NEUTRAL SUBLANG_NEUTRAL dBase III DBT, version number 0, next free block index 40, 1st item "\251\317"
RT_ICON 0x002c5924 0x00000468 LANG_TAMIL SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x002c5924 0x00000468 LANG_TAMIL SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x002c5924 0x00000468 LANG_TAMIL SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x002c5924 0x00000468 LANG_TAMIL SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x002c5924 0x00000468 LANG_TAMIL SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x002c5924 0x00000468 LANG_TAMIL SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x002c5924 0x00000468 LANG_TAMIL SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x002c5924 0x00000468 LANG_TAMIL SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x002c5924 0x00000468 LANG_TAMIL SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x002c5924 0x00000468 LANG_TAMIL SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x002c5924 0x00000468 LANG_TAMIL SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x002c5924 0x00000468 LANG_TAMIL SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x002c5924 0x00000468 LANG_TAMIL SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x002c5924 0x00000468 LANG_TAMIL SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x002c5924 0x00000468 LANG_TAMIL SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x002c5924 0x00000468 LANG_TAMIL SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x002c5924 0x00000468 LANG_TAMIL SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x002c5924 0x00000468 LANG_TAMIL SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x002c5924 0x00000468 LANG_TAMIL SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x002c5924 0x00000468 LANG_TAMIL SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x002c5924 0x00000468 LANG_TAMIL SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x002c5924 0x00000468 LANG_TAMIL SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x002c5924 0x00000468 LANG_TAMIL SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x002c5924 0x00000468 LANG_TAMIL SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x002c5924 0x00000468 LANG_TAMIL SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x002c5924 0x00000468 LANG_TAMIL SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_STRING 0x002c6850 0x0000005e LANG_TAMIL SUBLANG_DEFAULT data
RT_STRING 0x002c6850 0x0000005e LANG_TAMIL SUBLANG_DEFAULT data
RT_STRING 0x002c6850 0x0000005e LANG_TAMIL SUBLANG_DEFAULT data
RT_ACCELERATOR 0x002c68b0 0x000000a8 LANG_TAMIL SUBLANG_DEFAULT data
RT_GROUP_CURSOR 0x002c699c 0x00000030 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_GROUP_CURSOR 0x002c699c 0x00000030 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_GROUP_CURSOR 0x002c699c 0x00000030 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_GROUP_ICON 0x002c6ae0 0x00000076 LANG_TAMIL SUBLANG_DEFAULT data
RT_GROUP_ICON 0x002c6ae0 0x00000076 LANG_TAMIL SUBLANG_DEFAULT data
RT_GROUP_ICON 0x002c6ae0 0x00000076 LANG_TAMIL SUBLANG_DEFAULT data
RT_GROUP_ICON 0x002c6ae0 0x00000076 LANG_TAMIL SUBLANG_DEFAULT data
RT_VERSION 0x002c6b58 0x00000214 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_MANIFEST 0x002c6d6c 0x00000092 LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with CRLF line terminators
None 0x002c6e18 0x0000000a LANG_TAMIL SUBLANG_DEFAULT data
None 0x002c6e18 0x0000000a LANG_TAMIL SUBLANG_DEFAULT data
None 0x002c6e18 0x0000000a LANG_TAMIL SUBLANG_DEFAULT data

Imports

Library KERNEL32.dll:
0x401000 GetDriveTypeW
0x401010 EnumCalendarInfoW
0x401018 SetComputerNameW
0x40101c CallNamedPipeW
0x401020 SetTapeParameters
0x401028 GetTickCount
0x40102c ReadConsoleW
0x401030 SetCommState
0x401038 SetHandleCount
0x401044 AddRefActCtx
0x401048 LoadLibraryW
0x40104c IsProcessInJob
0x401050 GetCalendarInfoW
0x401054 FreeConsole
0x40105c GetFileAttributesW
0x401060 CreateFileW
0x401064 GetOverlappedResult
0x401068 CompareStringW
0x40106c GetVolumePathNameA
0x401070 GetStringTypeExA
0x401074 EnumSystemLocalesA
0x401078 GetProfileIntA
0x40107c ReleaseActCtx
0x401084 GetProcAddress
0x401088 VerLanguageNameA
0x401090 SearchPathA
0x401094 GetTempFileNameA
0x401098 LoadLibraryA
0x40109c WriteConsoleA
0x4010a0 LocalAlloc
0x4010ac RemoveDirectoryW
0x4010b4 AddAtomA
0x4010b8 GlobalWire
0x4010bc GetModuleFileNameA
0x4010c0 EnumDateFormatsA
0x4010c4 GetModuleHandleA
0x4010c8 SetLocaleInfoW
0x4010cc lstrcatW
0x4010d4 FindNextFileW
0x4010d8 GetConsoleTitleW
0x4010dc EnumDateFormatsW
0x4010e0 SetCalendarInfoA
0x4010e8 SetFileShortNameA
0x4010f0 DeleteFileW
0x4010f4 DebugBreak
0x4010f8 GetProfileSectionW
0x4010fc EnumSystemLocalesW
0x401100 AreFileApisANSI
0x401108 EncodePointer
0x40110c DecodePointer
0x401110 Sleep
0x401124 GetLastError
0x401128 MoveFileA
0x40112c HeapFree
0x401130 HeapAlloc
0x401134 GetModuleHandleW
0x401138 ExitProcess
0x40113c GetCommandLineA
0x401140 HeapSetInformation
0x401144 GetStartupInfoW
0x401148 RaiseException
0x40114c RtlUnwind
0x401150 WideCharToMultiByte
0x401154 LCMapStringW
0x401158 MultiByteToWideChar
0x40115c GetCPInfo
0x401164 HeapCreate
0x401168 WriteFile
0x40116c GetStdHandle
0x401170 GetModuleFileNameW
0x401174 HeapSize
0x401180 IsDebuggerPresent
0x401184 TerminateProcess
0x401188 GetCurrentProcess
0x40118c TlsAlloc
0x401190 TlsGetValue
0x401194 TlsSetValue
0x401198 TlsFree
0x40119c SetLastError
0x4011a0 GetCurrentThreadId
0x4011a4 CloseHandle
0x4011ac GetLocaleInfoW
0x4011b4 GetFileType
0x4011bc GetCurrentProcessId
0x4011c4 GetACP
0x4011c8 GetOEMCP
0x4011cc IsValidCodePage
0x4011d0 GetUserDefaultLCID
0x4011d4 GetLocaleInfoA
0x4011d8 IsValidLocale
0x4011dc GetStringTypeW
0x4011e0 HeapReAlloc
0x4011e4 SetStdHandle
0x4011e8 GetConsoleCP
0x4011ec GetConsoleMode
0x4011f0 FlushFileBuffers
0x4011f4 SetFilePointer
0x4011f8 WriteConsoleW
0x4011fc DeleteFileA

!This program cannot be run in DOS mode.
Rich4Q6
`.data
.wugosa
generic
iostream
system
string too long
invalid string position
iostream stream error
Unknown exception
CorExitProcess
bad allocation
Visual C++ CRT: Not enough memory to complete call to strerror.
LC_TIME
LC_NUMERIC
LC_MONETARY
LC_CTYPE
LC_COLLATE
LC_ALL
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
(null)
`h````
xpxxxx
FlsFree
FlsSetValue
FlsGetValue
FlsAlloc
bad exception
Illegal byte sequence
Directory not empty
Function not implemented
No locks available
Filename too long
Resource deadlock avoided
Result too large
Domain error
Broken pipe
Too many links
Read-only file system
Invalid seek
No space left on device
File too large
Inappropriate I/O control operation
Too many open files
Too many open files in system
Invalid argument
Is a directory
Not a directory
No such device
Improper link
File exists
Resource device
Unknown error
Bad address
Permission denied
Not enough space
Resource temporarily unavailable
No child processes
Bad file descriptor
Exec format error
Arg list too long
No such device or address
Input/output error
Interrupted function call
No such process
No such file or directory
Operation not permitted
No error
HH:mm:ss
dddd, MMMM dd, yyyy
MM/dd/yy
December
November
October
September
August
February
January
Saturday
Friday
Thursday
Wednesday
Tuesday
Monday
Sunday
united-states
united-kingdom
trinidad & tobago
south-korea
south-africa
south korea
south africa
slovak
puerto-rico
pr-china
pr china
new-zealand
hong-kong
holland
great britain
england
britain
america
swedish-finland
spanish-venezuela
spanish-uruguay
spanish-puerto rico
spanish-peru
spanish-paraguay
spanish-panama
spanish-nicaragua
spanish-modern
spanish-mexican
spanish-honduras
spanish-guatemala
spanish-el salvador
spanish-ecuador
spanish-dominican republic
spanish-costa rica
spanish-colombia
spanish-chile
spanish-bolivia
spanish-argentina
portuguese-brazilian
norwegian-nynorsk
norwegian-bokmal
norwegian
italian-swiss
irish-english
german-swiss
german-luxembourg
german-lichtenstein
german-austrian
french-swiss
french-luxembourg
french-canadian
french-belgian
english-usa
english-us
english-uk
english-trinidad y tobago
english-south africa
english-nz
english-jamaica
english-ire
english-caribbean
english-can
english-belize
english-aus
english-american
dutch-belgian
chinese-traditional
chinese-singapore
chinese-simplified
chinese-hongkong
chinese
canadian
belgian
australian
american-english
american english
american
Norwegian-Nynorsk
_nextafter
_hypot
GetProcessWindowStation
GetUserObjectInformationW
GetLastActivePopup
GetActiveWindow
MessageBoxW
`h`hhh
xppwpp
Complete Object Locator'
Class Hierarchy Descriptor'
Base Class Array'
Base Class Descriptor at (
Type Descriptor'
`local static thread guard'
`managed vector copy constructor iterator'
`vector vbase copy constructor iterator'
`vector copy constructor iterator'
`dynamic atexit destructor for '
`dynamic initializer for '
`eh vector vbase copy constructor iterator'
`eh vector copy constructor iterator'
`managed vector destructor iterator'
`managed vector constructor iterator'
`placement delete[] closure'
`placement delete closure'
`omni callsig'
delete[]
new[]
`local vftable constructor closure'
`local vftable'
`udt returning'
`copy constructor closure'
`eh vector vbase constructor iterator'
`eh vector destructor iterator'
`eh vector constructor iterator'
`virtual displacement map'
`vector vbase constructor iterator'
`vector destructor iterator'
`vector constructor iterator'
`scalar deleting destructor'
`default constructor closure'
`vector deleting destructor'
`vbase destructor'
`string'
`local static guard'
`typeof'
`vcall'
`vbtable'
`vftable'
operator
delete
__unaligned
__restrict
__ptr64
__eabi
__clrcall
__fastcall
__thiscall
__stdcall
__pascal
__cdecl
__based(
1#QNAN
1#SNAN
bad locale name
ios_base::badbit set
ios_base::failbit set
ios_base::eofbit set
likofelevove matuziyoyocisaxuvabufuged vuzevanocinunofuvol laxixopozoro
zewoyazagibowucunufawe xejubitomiliri yepabufug
pakucofuxuputidodoco duyizocobebutecepunuc
%s %d %f
xamerujahomolayawo
tiwuwezebavelepabo
guyubetisekalojacufuhifa sozipupaxireduwiyiziyufo catonebitihu pomecuzeruxosehobufefisawo kalegapilifetuhevicurad
fozadawewelacis
bigavusuzi
Vica vozikak
vezutowiceforizoyiyazuda
pojew fobiputuxopoleyem vimuwixexupegetolok puroro yemofiroyexiwu
rowugokikeniwalojucidewofebawej
yayanuzusunazanelosoyapur
bad cast
?uZEeu
?uZEeu
?UUUUUU
?UUUUUU
D$$^][
QQSVWd
.t|PVj@
t"SS9] u
tWItHIt9It
uh\(@
^SSSSS
t h *@
HHtXHHt
?If90t
j@j ^V
t=MOC
HtHu4j
t*=RCC
;7|G;p
tR99u2
F Pj*S
F$Pj+Sj
F(Pj,S
F,Pj-S
F0Pj.S
F4Pj/S
F8PjDS
F<PjES
F@PjFS
FDPjGS
FHPjHS
FLPjIS
FPPjJS
FTPjKS
FXPjLS
F\PjMS
F`PjNS
FdPjOS
FhPj8S
FlPj9S
FpPj:S
FtPj;S
FxPj<S
F|Pj=S
C PjPV
C$PjQV
C*PjTV
C+PjUV
C,PjVV
C-PjWV
C.PjRV
C/PjSV
CHPjPV
CLPjQV
PPPPPPPP
PPPPPPPP
URPQQh@KA
t VV9u
;t$,v-
UQPXY]Y[
<+t"<-t
+t HHt
u-htA@
QShP;C
D$$)D$
f-00f=
tRHtCHt4Ht%HtFHHt
GetDriveTypeW
GetConsoleAliasExesLengthA
InterlockedIncrement
SystemTimeToFileTime
EnumCalendarInfoW
SetDefaultCommConfigW
SetComputerNameW
CallNamedPipeW
SetTapeParameters
MoveFileWithProgressA
GetTickCount
ReadConsoleW
SetCommState
TzSpecificLocalTimeToSystemTime
SetHandleCount
AllocateUserPhysicalPages
GetPrivateProfileIntA
AddRefActCtx
LoadLibraryW
IsProcessInJob
GetCalendarInfoW
FreeConsole
InterlockedPopEntrySList
GetFileAttributesW
CreateFileW
GetOverlappedResult
CompareStringW
GetVolumePathNameA
GetStringTypeExA
EnumSystemLocalesA
GetProfileIntA
ReleaseActCtx
GetCurrentDirectoryW
GetProcAddress
VerLanguageNameA
SetFirmwareEnvironmentVariableW
SearchPathA
GetTempFileNameA
LoadLibraryA
WriteConsoleA
LocalAlloc
BuildCommDCBAndTimeoutsW
FindFirstVolumeMountPointW
RemoveDirectoryW
BeginUpdateResourceA
AddAtomA
GlobalWire
GetModuleFileNameA
EnumDateFormatsA
GetModuleHandleA
SetLocaleInfoW
lstrcatW
FreeEnvironmentStringsW
FindNextFileW
GetConsoleTitleW
EnumDateFormatsW
SetCalendarInfoA
SetThreadAffinityMask
SetFileShortNameA
GetVolumeNameForVolumeMountPointW
DeleteFileW
DebugBreak
GetProfileSectionW
EnumSystemLocalesW
AreFileApisANSI
KERNEL32.dll
InterlockedDecrement
EncodePointer
DecodePointer
InitializeCriticalSection
DeleteCriticalSection
EnterCriticalSection
LeaveCriticalSection
GetLastError
MoveFileA
HeapFree
HeapAlloc
GetModuleHandleW
ExitProcess
GetCommandLineA
HeapSetInformation
GetStartupInfoW
RaiseException
RtlUnwind
WideCharToMultiByte
LCMapStringW
MultiByteToWideChar
GetCPInfo
IsProcessorFeaturePresent
HeapCreate
WriteFile
GetStdHandle
GetModuleFileNameW
HeapSize
UnhandledExceptionFilter
SetUnhandledExceptionFilter
IsDebuggerPresent
TerminateProcess
GetCurrentProcess
TlsAlloc
TlsGetValue
TlsSetValue
TlsFree
SetLastError
GetCurrentThreadId
CloseHandle
InitializeCriticalSectionAndSpinCount
GetLocaleInfoW
GetEnvironmentStringsW
GetFileType
QueryPerformanceCounter
GetCurrentProcessId
GetSystemTimeAsFileTime
GetACP
GetOEMCP
IsValidCodePage
GetUserDefaultLCID
GetLocaleInfoA
IsValidLocale
GetStringTypeW
HeapReAlloc
SetStdHandle
GetConsoleCP
GetConsoleMode
FlushFileBuffers
SetFilePointer
WriteConsoleW
DeleteFileA
.?AVerror_category@std@@
.?AV_Generic_error_category@std@@
.?AV_Iostream_error_category@std@@
.?AV_System_error_category@std@@
.?AV_Locimp@locale@std@@
.?AVlogic_error@std@@
.?AVlength_error@std@@
.?AVout_of_range@std@@
Copyright (c) 1992-2004 by P.J. Plauger, licensed by Dinkumware, Ltd. ALL RIGHTS RESERVED.
.?AVtype_info@@
.?AVbad_exception@std@@
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
.?AV?$ctype@D@std@@
.?AUctype_base@std@@
.?AVfacet@locale@std@@
.?AV?$basic_stringstream@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@
.?AV?$basic_stringbuf@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@
.?AV?$basic_iostream@DU?$char_traits@D@std@@@std@@
.?AV?$basic_ostream@DU?$char_traits@D@std@@@std@@
.?AV?$basic_istream@DU?$char_traits@D@std@@@std@@
.?AV?$basic_streambuf@DU?$char_traits@D@std@@@std@@
.?AV?$basic_ios@DU?$char_traits@D@std@@@std@@
.?AV?$_Iosb@H@std@@
.?AVios_base@std@@
.?AVruntime_error@std@@
.?AVexception@std@@
.?AVfailure@ios_base@std@@
.?AVsystem_error@std@@
zp$R$dab
cQ_9y#
dylkC-
XI<\4Y>
sr:WT'.
w"wcjk
"=29(c
px)tJW
^CVmJ`O
-%gFRt
>{"J\Cn+
@M"iJ/Oq[
SG-1 _P
egU;Eh
m`)`<gg
@E$dc
z~*z47
BNAPgJ
Q.K!m{s
W~)BNfQ
z]AYCf
2>{p'_
r {/Jv
%vrJH4r*
&mB#n1
3<T|f;
qi?<t3
>de6(R
L_rggH
dKcO7eC
xVjW]YRd
f7@[iy
6@GtO~
/"b}%T`
i'$ )g
;9S=&#
):2{nY
oHMr]2
cUvdqf
xWa.#
$5VkW\
9*9hu`
6kU(2w
vk/#"7
$4.M}Av
F \CME
@\VIz7
MhoJ]D
PN<"`}
-wLILrmVo
1q$({K
NV=uA7D
N5R^Rc
7_"B/&
(7yR7$
)}=V*?A\H>7
I'n$fl
b}8trh
3Vw[`X
PGYsu5
+{UR%pc
Up0S&p7
ia2l#9
}Awu=!J
-\Hy-H
e ;qEV
*3wHB@(
>X~;B(
^En6D7
Ksq(]Ge`
}V#+UVT
e{.rQW
3tw9@'
yN%_D8M
li%K.kl
|FQ"V}
!~rTj.8
S$3v\L
qE#bV5
#d?!@P
bL' ]sY
?y.#urtt^
ev.w,_=
'FUj$^~U
{f'.9c
om(<x[O.*
wuJ5|WV,
K?WY"DK^`
f"}<ne
>@)OPpm
V?*2_SO3
cV}HLh
TOx4zN\]
hmnT+]
m_w],&
n*27I2
Dc%.@xf
h,a3'P
7PeGk}2
hx99(_
t:EtFZV
iiMgGw]:
E{QN_X
v us\#%
/C*FFH
ZrYN`/=
{m=^GT
d:#_15
>Qd`7;
57gv@H
4i(E5,
G?2R:Q
|*Qlm<
|G" }F
8*_%+#
S524A;
"5ktO2
Iw}dLJ
k(oBy1
xBy:A-
Z5a{3z,
~LLQ|
=/D*P
@VOS)yN
s98Z/#B:o
ed'vC3
S;FKP%
BSVRwg
2%{"GPn
|=3g;h
.?AVbad_cast@std@@
.?AVbad_alloc@std@@
QQQQQQQQQ
bbbbbbb
llllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllljjj
lllllllllj
jllllllll
jlllllllj
jllllllj
jlllllj
zlllll
jlllllj
zlllllj
zlllllj
zlllllj
jjjjjjzzz
TTTTTTTT
zlllllj
gggggggggggggg
jlllll
zlllllj
B`Tg8KKKu
g8ddKKKuKuu
zlllllj
ddddKKKuKuK
dddKKKud
\zlllllj
jlllllj
\jlllllj
\jlllll
jlllllj
lllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllll
```````````````````````````````````````````````````````````````````````````````8ZZZZZZZZZZ
88```````+8
``````8
88Pttttt
`````8
?````+
?````~
++Pt````
ZZ~PPP
8++Pt````~
uuZZZ8Z888888888Pt````
t````~
___________G
````+hP
ot````Z~+
;eeeeeee
~~+`````````````````````````
AAAAAAAA
||||||||||
""""""""
nGGIgHeeeeeffffffj
=<>>BB
F*<#<=
F@@%=*
F$)@==>
F?&@$<>
F 2$
3,""'1&&!*%;)<=
%@?!B
1"5)()$
1('$<##$$G
V/,,,.
\VM-..2+ 2
ZUU^60
ZUT^UT6
YYWTSP9U7:065&6'@_
SNSRTW7O6W^88F9GAi
YONNMKRPOTO:7F6VAh
RMOLRR6OP6TA]AF_
MJK//K///6656h
KJ/2Q/M-445a
\[\a[[[\ZZXaV^VXUo
tvt|u~|t
u+H,FFGH
s)C+)(@
#$A+'(A@
%858+BA@
s3"3$*&$H?
"7*5('B'
*!#$@&'@O
$#!%#8M
{XV./337$!A+>
xX\[S/"--$#B*L
wUUV[[>29V45#M
qRXTVW:VWZVLE^
w2XYYVWV9Z>=L\
r.RS11W<<::E>^
QQS96017
.10/^
vuku{vvxtssvvsy{vxqvq
z[YTZVV^VZ^
zJFFHH3,3>N
wIFEEECBM0O
*@A//.-M
llbdihcijo
jig{ybuhvtz]r\
_`cZ^`xmp
L':8!4;
XMNWOPU
aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa
zzzzzzzzzzzzzzzzzzzzzzzzzz
aaaaaaaaaaaaaaa
aaaaaaaaaaaaa
Vzaaaaaaaaaaaa
zaaaaaaaaaaa
TTTTTTTTTTTT
zaaaaaaaaaa
TTTTTTTT
V7IIII
zaaaaaaaaa
IIIZIVT
,zaaaaaaaa
V7VIZIh
zaaaaaaa
ZIIZIZh
zaaaaaaazZ
VIZZZI
zaaaaaaaz,
IIVZVZ
,zaaaaaaaz,
VIVZZZ
zaaaaaaa
VIVZZVh
zaaaaaaaz
ZIVZVZ
zaaaaaaaz
VIVVVV
zaaaaaaaz
zzzZVVVV
zaaaaaaaz
zaaaaaaaz
zaaaaaaaz
zaaaaaaaz
zaaaaaaaz
KKKKKKKKKKKKKKKKKKKKKKK
zaaaaaaaz(
zaaaaaaaz
zaaaaaaaz
AAAAAA
zaaaaaaaz
zaaaaaaaz
aaaaaaaz
zaaaaaaaz
zaaaaaaaz
HHHHHH
aaaaaaaz
HHHHHH
zaaaaaaaz
HHHHHH
zaaaaaaaz
HHHHHH
aaaaaaaz
zaaaaaaaz
zaaaaaaaz
aaaaaaaz
zaaaaaaaz
zaaaaaaaz
zaaaaaaa
aaaaaaaa
aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa
dddddddddddddddd
Dtta,ddd,d,,d,,d,d,llly
ttttttt
aaaaaallly
222222222222222222222222222222222222222222222222222222E
TETEE2222222E
222222E
22222E
2222E:
2222T*N
*;;;;;;
TNNN"NN"NN"
2222T*33
2222T*
>>>>>>>><><<<g
2222T*
k2222T;
2222T*N
[[[''K
2222T*N
2222T*N
2222T;
2222T*
2222T;
TE22222222222222222222222222222222222222222222222222
BBBBBBBBBBBBBBBBBBBB
rrrrrrrr
'''''''''
\dttty
[[[\dd
IrBBBr
orrBBBBBBBBBBBBBBBBB
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
</assembly>
mscoree.dll
((((( H
h(((( H
H
wruntime error
TLOSS error
SING error
DOMAIN error
- Attempt to use MSIL code from this assembly during native code initialization
This indicates a bug in your application. It is most likely the result of calling an MSIL-compiled (/clr) function from a native constructor or from DllMain.
- not enough space for locale information
- Attempt to initialize the CRT more than once.
This indicates a bug in your application.
- CRT not initialized
- unable to initialize heap
- not enough space for lowio initialization
- not enough space for stdio initialization
- pure virtual function call
- not enough space for _onexit/atexit table
- unable to open console device
- unexpected heap error
- unexpected multithread lock error
- not enough space for thread data
- abort() has been called
- not enough space for environment
- not enough space for arguments
- floating point support not loaded
@Microsoft Visual C++ Runtime Library
<program name unknown>
Runtime Error!
Program:
(null)
KERNEL32.DLL
HH:mm:ss
dddd, MMMM dd, yyyy
MM/dd/yy
December
November
October
September
August
February
January
Saturday
Friday
Thursday
Wednesday
Tuesday
Monday
Sunday
WUSER32.DLL
CONOUT$
fibahiveyelaludadojix
vuruvavikoce
tudonunovekikurefutax husojekesitavezurebitagirerexufu
fikuza sicuh tizuwebonuwa xudawomoyowaxibepalal
Sezuk pixehotererev cicifiwalime suzixuligi
wevotezohivi mujinogemekodedadasivesaxiha zaxebicijaxotehufavowu heyulinuvusab
pupoduwojatecihukipezaxe
yareyavuj nateracigozesobukupu buwupasokozepewogofocojal
xukec cehobodayoxorofafez rozujapemonuviyunimokibujo
Xexolimog hamikojigodi xidetutu kigehucocemiv
tuvahuyanepatoterakemojociwuwi
gogohemibacivucujaxac
fijaholudalubozavadez
gapajegutehafenotimifewigagom
suwezafijixokilefewayucekulihev van wiyurigamufulusuxekujexuni diyojag wovinuse
nopuzuzihifikipurakeda
rezowuxajuse
@jjjjjj
jjjjjj
AFX_DIALOG_LAYOUTK
/ P6pL
,/KPip
/-P?pR
CaraziwikunovogSBunubosal fisuwusocic tahegisoxuw bahexayuh nec polusuf tovi mukitodagucu daninotep`Giviwoyamit sonezatiped tapexoror habogoxepoto neriwiyuyafaxa gahutaduwe xevumo sijogusi cubijaw
ZakidefurarugafUTahocefecapuv godu yohasikolaki legakaz xezedifu tez nodiraxu cehajixo xasibifobijilaJXuzi poriseg pipidahi fidelamirayite foyahocepige fakabulob gunopaxivoname
Koyifonu rupodafokomulu yoloma6Motuhotuhok tonenutew zakowanumewogi bajoruxoz xisecil&Poma pedoguji ciwi havifixadebuyip tiv Venamuyo juvovit devisokunasodepdMize kezabikafa tanowici xaf kobijunax huyuxeyiciwed huhajexokinone jeyik rahovaxehuxayuf wefocefoje4Zozim lodu kup mov yasumucopekuyuj lojo bovatuci wimKWutuzayepexu libidija powodot bupagegaz poxidogukuresom zimub vine jiwimumoZWitopifoz kezubesolodig boforur pocibuzuwipem buteforubik vovucife fopezibidep lilup yuduz#Jahefopuyenodag dakuxe lozogizuyuda
oSuniza sebusagaj nihabekogavibe wumewolas gahohimez geperonohimo geliniluruta roculevuj lowejav vanakafekazecob'Wafawubipawedu tejariwesudena diwigokiw6Samef dese hezohurav het yupumized depub zopumafuluwejNTaselemurevi doniy cutovuvivukit wurur tosiwezowa wez tomisazini fefadagehevax
Poziyuyuxixava4Yovuwubacuco mozibadaraw zonerodamijo winuretemaxusi.Yapuyomoge jivuteru hapi wulowe jex yixucosemu
YasacurGVaya tizucivon humunixanulezuh jogumukedicak midohek foraduzoziwu meteg
Boy kafajon liyavolixu mabojuxo
VS_VERSION_INFO
StringFileInfo
049805B1
InternalName
Backstage.exe
LegalCopyrights
Night bizon inc.
LegalTrademarks2
odjfngisdf
ProductName
CrazyTooth
ProductVersion
14.1.64.9
VarFileInfo
Translation
Antivirus Signature
Bkav W32.AIDetectMalware
Lionic Clean
tehtris Clean
ClamAV Win.Packed.Babar-10001332-0
FireEye Generic.mg.c5e15dbab0811bd4
CAT-QuickHeal Ransom.Stop.P5
ALYac Trojan.GenericKDZ.99285
Cylance unsafe
Zillya Clean
Sangfor Trojan.Win32.Save.a
K7AntiVirus Riskware ( 0040eff71 )
BitDefender Trojan.GenericKDZ.99285
K7GW Riskware ( 0040eff71 )
Cybereason malicious.5da835
BitDefenderTheta Clean
VirIT Clean
Cyren W32/Kryptik.JTQ.gen!Eldorado
Symantec ML.Attribute.HighConfidence
Elastic malicious (high confidence)
ESET-NOD32 a variant of Win32/Kryptik.HTMP
APEX Malicious
Paloalto generic.ml
Cynet Malicious (score: 100)
Kaspersky HEUR:Backdoor.Win32.Tofsee.gen
Alibaba Backdoor:Win32/Tofsee.fbbb0b37
NANO-Antivirus Trojan.Win32.Tofsee.jvytmc
ViRobot Clean
MicroWorld-eScan Trojan.GenericKDZ.99285
Rising Trojan.Generic@AI.100 (RDML:qWHNRV8RkbTzTfblgpn4nQ)
Sophos Troj/Krypt-WE
Baidu Clean
F-Secure Trojan.TR/AD.GenSHCode.bbygd
DrWeb Clean
VIPRE Trojan.GenericKDZ.99285
TrendMicro TrojanSpy.Win32.RACCOONSTEALER.YXDENZ
McAfee-GW-Edition BehavesLike.Win32.Lockbit.dh
Trapmine malicious.high.ml.score
CMC Clean
Emsisoft Trojan.GenericKDZ.99285 (B)
Ikarus Trojan.Win32.Krypt
GData Win32.Trojan.PSE.1SBCOOE
Jiangmin Clean
Webroot Clean
Avira TR/AD.GenSHCode.bbygd
MAX malware (ai score=86)
Antiy-AVL Trojan[Spy]/Win32.Windigo
Gridinsoft Spy.Win32.Raccoon.bot
Xcitium Clean
Arcabit Trojan.Generic.D183D5
SUPERAntiSpyware Clean
ZoneAlarm HEUR:Backdoor.Win32.Tofsee.gen
Microsoft Trojan:Win32/SmokeLoader.CX!MTB
Google Detected
AhnLab-V3 Trojan/Win.Generic.R568035
Acronis suspicious
McAfee Lockbit-FSWW!C5E15DBAB081
TACHYON Clean
DeepInstinct MALICIOUS
VBA32 TrojanSpy.Stealer
Malwarebytes Trojan.MalPack.GS
Panda Trj/GdSda.A
Zoner Clean
TrendMicro-HouseCall TROJ_GEN.R002C0DED23
Tencent Win32.Backdoor.Tofsee.Ljgl
Yandex Clean
SentinelOne Static AI - Suspicious PE
MaxSecure Trojan.Malware.300983.susgen
Fortinet W32/Kryptik.GJPP!tr
AVG Win32:BotX-gen [Trj]
Avast Win32:BotX-gen [Trj]
CrowdStrike win/malicious_confidence_100% (W)
No IRMA results available.