Static | ZeroBOX

PE Compile Time

2021-11-22 13:13:50

PDB Path

C:\mosuw.pdb

PE Imphash

8507dd6e83303e4881d265378980e13b

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x000277f6 0x00027800 7.57814952856
.data 0x00029000 0x004c3dbc 0x00001a00 3.26602730518
.rsrc 0x004ed000 0x000153b8 0x00015400 4.50672786394
.reloc 0x00503000 0x00004ae2 0x00004c00 1.77700477635

Resources

Name Offset Size Language Sub-language File type
SAHOT 0x004ff2f0 0x000015b4 None SUBLANG_SYS_DEFAULT ASCII text, with very long lines, with no line terminators
RT_ICON 0x004fee10 0x00000468 None SUBLANG_SYS_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x004fee10 0x00000468 None SUBLANG_SYS_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x004fee10 0x00000468 None SUBLANG_SYS_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x004fee10 0x00000468 None SUBLANG_SYS_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x004fee10 0x00000468 None SUBLANG_SYS_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x004fee10 0x00000468 None SUBLANG_SYS_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x004fee10 0x00000468 None SUBLANG_SYS_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x004fee10 0x00000468 None SUBLANG_SYS_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x004fee10 0x00000468 None SUBLANG_SYS_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x004fee10 0x00000468 None SUBLANG_SYS_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x004fee10 0x00000468 None SUBLANG_SYS_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x004fee10 0x00000468 None SUBLANG_SYS_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x004fee10 0x00000468 None SUBLANG_SYS_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x004fee10 0x00000468 None SUBLANG_SYS_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x004fee10 0x00000468 None SUBLANG_SYS_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x004fee10 0x00000468 None SUBLANG_SYS_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x004fee10 0x00000468 None SUBLANG_SYS_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x004fee10 0x00000468 None SUBLANG_SYS_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x004fee10 0x00000468 None SUBLANG_SYS_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x004fee10 0x00000468 None SUBLANG_SYS_DEFAULT GLS_BINARY_LSB_FIRST
RT_STRING 0x00501d88 0x0000062c LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_STRING 0x00501d88 0x0000062c LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_STRING 0x00501d88 0x0000062c LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_STRING 0x00501d88 0x0000062c LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_STRING 0x00501d88 0x0000062c LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_STRING 0x00501d88 0x0000062c LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_ACCELERATOR 0x005008a8 0x00000030 None SUBLANG_SYS_DEFAULT data
RT_GROUP_ICON 0x004ff278 0x00000076 None SUBLANG_SYS_DEFAULT data
RT_GROUP_ICON 0x004ff278 0x00000076 None SUBLANG_SYS_DEFAULT data
RT_GROUP_ICON 0x004ff278 0x00000076 None SUBLANG_SYS_DEFAULT data
RT_VERSION 0x005008e8 0x0000023c LANG_NEUTRAL SUBLANG_NEUTRAL data
None 0x005008d8 0x0000000a LANG_NEUTRAL SUBLANG_NEUTRAL data

Imports

Library KERNEL32.dll:
0x40101c SetComputerNameW
0x401020 SetEvent
0x401024 SetTapeParameters
0x401028 GetModuleHandleW
0x40102c GetNumberFormatA
0x401030 ReadConsoleW
0x401034 FatalAppExitW
0x401038 GetCalendarInfoW
0x40103c HeapCreate
0x401040 GetConsoleAliasW
0x401044 LocalReAlloc
0x401048 ReplaceFileW
0x40104c GetModuleFileNameW
0x401050 CreateActCtxA
0x401054 lstrlenW
0x401058 GlobalUnlock
0x40105c GetStringTypeExA
0x401060 GetLastError
0x401064 IsDBCSLeadByteEx
0x401068 SetLastError
0x40106c GetProcAddress
0x401070 VirtualAlloc
0x401074 ReadFileEx
0x40107c LoadLibraryA
0x401084 LocalAlloc
0x401098 GetModuleHandleA
0x4010a4 GetConsoleTitleW
0x4010ac OpenEventW
0x4010b4 FindAtomW
0x4010bc AddConsoleAliasA
0x4010c0 GetTempPathA
0x4010c4 EnumCalendarInfoExA
0x4010c8 FindNextVolumeA
0x4010cc EnumSystemLocalesW
0x4010d0 LCMapStringW
0x4010d8 WriteConsoleOutputW
0x4010e0 TlsGetValue
0x4010e4 SetThreadContext
0x4010ec GetTempFileNameA
0x4010f8 Sleep
0x40110c HeapAlloc
0x401110 MultiByteToWideChar
0x401114 GetStartupInfoW
0x401118 RaiseException
0x40111c RtlUnwind
0x401128 HeapFree
0x40112c TerminateProcess
0x401130 GetCurrentProcess
0x401134 IsDebuggerPresent
0x401138 VirtualFree
0x40113c HeapReAlloc
0x401140 ExitProcess
0x401144 WriteFile
0x401148 GetStdHandle
0x40114c GetModuleFileNameA
0x401150 GetCPInfo
0x401154 GetACP
0x401158 GetOEMCP
0x40115c IsValidCodePage
0x401160 TlsAlloc
0x401164 TlsSetValue
0x401168 TlsFree
0x40116c GetCurrentThreadId
0x401178 GetCommandLineW
0x40117c SetHandleCount
0x401180 GetFileType
0x401184 GetStartupInfoA
0x40118c GetTickCount
0x401190 GetCurrentProcessId
0x401198 HeapSize
0x40119c GetLocaleInfoA
0x4011a0 GetStringTypeA
0x4011a4 GetStringTypeW
0x4011ac LCMapStringA
0x4011b0 WideCharToMultiByte
Library USER32.dll:
0x4011b8 DdeQueryStringW
0x4011bc GetClassInfoExW
0x4011c4 ChangeMenuW
Library GDI32.dll:
0x401008 GetCharABCWidthsI
0x401010 GetCharWidthW
0x401014 EnumFontsA
Library ADVAPI32.dll:
0x401000 BackupEventLogA

!This program cannot be run in DOS mode.
`.data
@.reloc
bad allocation
string too long
invalid string position
Unknown exception
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
CorExitProcess
runtime error
TLOSS error
SING error
DOMAIN error
An application has made an attempt to load the C runtime library incorrectly.
Please contact the application's support team for more information.
- Attempt to use MSIL code from this assembly during native code initialization
This indicates a bug in your application. It is most likely the result of calling an MSIL-compiled (/clr) function from a native constructor or from DllMain.
- not enough space for locale information
- Attempt to initialize the CRT more than once.
This indicates a bug in your application.
- CRT not initialized
- unable to initialize heap
- not enough space for lowio initialization
- not enough space for stdio initialization
- pure virtual function call
- not enough space for _onexit/atexit table
- unable to open console device
- unexpected heap error
- unexpected multithread lock error
- not enough space for thread data
This application has requested the Runtime to terminate it in an unusual way.
Please contact the application's support team for more information.
- not enough space for environment
- not enough space for arguments
- floating point support not loaded
Microsoft Visual C++ Runtime Library
<program name unknown>
Runtime Error!
Program:
EncodePointer
DecodePointer
FlsFree
FlsSetValue
FlsGetValue
FlsAlloc
?uZEeu
?uZEeu
?UUUUUU
?UUUUUU
bad exception
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
HH:mm:ss
dddd, MMMM dd, yyyy
MM/dd/yy
December
November
October
September
August
February
January
Saturday
Friday
Thursday
Wednesday
Tuesday
Monday
Sunday
GetProcessWindowStation
GetUserObjectInformationA
GetLastActivePopup
GetActiveWindow
MessageBoxA
USER32.DLL
Complete Object Locator'
Class Hierarchy Descriptor'
Base Class Array'
Base Class Descriptor at (
Type Descriptor'
`local static thread guard'
`managed vector copy constructor iterator'
`vector vbase copy constructor iterator'
`vector copy constructor iterator'
`dynamic atexit destructor for '
`dynamic initializer for '
`eh vector vbase copy constructor iterator'
`eh vector copy constructor iterator'
`managed vector destructor iterator'
`managed vector constructor iterator'
`placement delete[] closure'
`placement delete closure'
`omni callsig'
delete[]
new[]
`local vftable constructor closure'
`local vftable'
`udt returning'
`copy constructor closure'
`eh vector vbase constructor iterator'
`eh vector destructor iterator'
`eh vector constructor iterator'
`virtual displacement map'
`vector vbase constructor iterator'
`vector destructor iterator'
`vector constructor iterator'
`scalar deleting destructor'
`default constructor closure'
`vector deleting destructor'
`vbase destructor'
`string'
`local static guard'
`typeof'
`vcall'
`vbtable'
`vftable'
operator
delete
__unaligned
__restrict
__ptr64
__clrcall
__fastcall
__thiscall
__stdcall
__pascal
__cdecl
__based(
GAIsProcessorFeaturePresent
KERNEL32
SunMonTueWedThuFriSat
JanFebMarAprMayJunJulAugSepOctNovDec
_nextafter
_hypot
1#QNAN
1#SNAN
bad allocation
powemalihavib menoxir wipabidusapoguk vamozeyagekopibajugesora
kernel32.dll
ricibefezemoxigozevenutak tel lekizidu kebetafuhiyiyudi
dadubikajoyicuvuvivajivahimuxev
dimunujewela rosijovitobitedukizuf yanulosekepecuvasurenafawakawah dobeyawubido
tohuciyuyuyesiloma raf difodevoyog
givapupimegeruseke
poxusezixujomegoyinezurojulibe dagopowocayepav vikegomowocuwahudidejabenet fefilayalurolonofuzuyofu tatikepilume
C:\mosuw.pdb
D$ 1D$
D$ 1D$
VVh(8@
D$<ipxU
D$|Yc}
D$@j;:-
D$`}u_h
D$,%.y
l$,=vM
D$8Uq,7
0WWWWW
0WWWWW
QQSVWd
0SSSSS
t hT#@
0A@@Ju
f-00f=
>=Yt1j
QQSVWh
jThHxB
j@j ^V
j,h(yB
HtHu4j
s[S;7|G;w
YYhd#@
tR99u2
0SSSSS
PPPPPPPP
0SSSSS
PPPPPPPP
URPQQh
t"SS9]
_VVVVV
^WWWWW
tRHtCHt4Ht%HtFHHt
0WWWWW
AAFFf;
;t$,v-
UQPXY]Y[
t+WWVPV
0SSSSS
_VVVVV
<+t(<-t$:
+t HHt
Y+'*h\
Urf1=0
ur3~JJlA
L:Gs:~(
6Xsdr4
n9`6Q&
n}v:pVK
\s:`\%v
~VWT"E^R
)q"O|
purWP=Z
$#EYn4
o#Z_!!
bF?sJ.:$
mG?sW'
?aanCp
|r_6> w
S"I g8;
=+O,\O
2UGb7X
u3IX{8
HPxMHiP
M+'#hm
0m33!H
/A/BOU
{}jP[N
m"ZTK2"
RrNi&HFa
ZijWE2
^zWw%b4`3"U
q+o/R`9
0eC[9'J
KUio R;
,[.Zb9v
i!`Bh!U
L~In5y
D)Y?nmq
;vsTLy)
L`5]O8
a:>rDT
-T@7kZ{E
^|mvCW
k2$D,C
m-=V9-
6*B:;|
>n#f6"
rVx1m|
dLxM7r
A{r34h
^7b<^kUU
k+Ssq
oiiVr;
8jR._
fU%X<H
*V{5r.
3{|b< d
Wt_X@
o\j,1I
M@aK(\$:MV
wE#j$_
8`Q=w
?QtEGn
%f]29f
vCJ;mq
3mzsYlL
;#"C@HN
GJ?5jQ
wM?G^RQ
>b.Kzb
*=JtxW
=")l)%B;
TBu\aC
>#<Q#$
#FfeHo
8...-Q
,d/|]QW1[
{)Evt]
W?*}'G
!Y\qxkm
egXv2j
Dc$vEul
z0Idw]
^A}S`J
RZh|DU
t0<Z5H
D;NjHh
w<|qc9(
R>pw\Qf9R/
6Af%O
;VONt8
j7JDI]P~
e+2HF?
,XL@kL2}
:]P+`mj
T>ixb=
\&f%mA
=1$g1
2-{+?)P
'xDxp&e7H
P},lW1?
EG i*g
Vs#t-
}ZHAG@
v`2{X7K
#jI+8H
`BA~2}
x,2;vd
4783+N
XfKA8>
s7)jH`4
B6o+oY
3X+?#;
{!J(1i
;(;)q"
%a(dN"Z
l"6,&c
}vOIa=
{I<CvF
ZqUn'$
'tU|D
xB? Z2
F(=GWe
uY)"J'
ed@GzAu
:{T~NA
gQ*=i@
Gtdyg+
]/~O)VCO
sibMF"
4y?>wj
? c*-c
Z$jk*"H
)Gqn\6
gUHl]N_z
V9|*,@
]S q6M
abZ=5k~
)=YdrvjO
hqO74E
D46N=2
;hS{28
z'::US
8C`Zt|
SetThreadContext
GetConsoleAliasesLengthW
TlsGetValue
GetDefaultCommConfigW
WriteConsoleOutputW
GetLogicalDriveStringsW
InterlockedCompareExchange
SetComputerNameW
SetEvent
SetTapeParameters
GetModuleHandleW
GetNumberFormatA
ReadConsoleW
FatalAppExitW
GetCalendarInfoW
HeapCreate
GetConsoleAliasW
LocalReAlloc
ReplaceFileW
GetModuleFileNameW
CreateActCtxA
lstrlenW
GlobalUnlock
GetStringTypeExA
GetLastError
IsDBCSLeadByteEx
SetLastError
GetProcAddress
VirtualAlloc
ReadFileEx
GetTempFileNameA
LoadLibraryA
InterlockedExchangeAdd
LocalAlloc
DnsHostnameToComputerNameA
FindFirstVolumeMountPointW
IsSystemResumeAutomatic
BeginUpdateResourceA
GetModuleHandleA
QueryMemoryResourceNotification
GetProcessAffinityMask
GetConsoleTitleW
GetConsoleCursorInfo
OpenEventW
SetProcessShutdownParameters
FindAtomW
GetWindowsDirectoryW
AddConsoleAliasA
GetTempPathA
EnumCalendarInfoExA
FindNextVolumeA
EnumSystemLocalesW
KERNEL32.dll
CreateAcceleratorTableA
GetClassInfoExW
DdeQueryStringW
ChangeMenuW
USER32.dll
EnumFontsA
GetCharWidthW
GetCharABCWidthsFloatW
GetCharABCWidthsI
GDI32.dll
BackupEventLogA
ADVAPI32.dll
InterlockedIncrement
InterlockedDecrement
InitializeCriticalSection
DeleteCriticalSection
EnterCriticalSection
LeaveCriticalSection
HeapAlloc
MultiByteToWideChar
GetStartupInfoW
RaiseException
RtlUnwind
UnhandledExceptionFilter
SetUnhandledExceptionFilter
HeapFree
TerminateProcess
GetCurrentProcess
IsDebuggerPresent
VirtualFree
HeapReAlloc
ExitProcess
WriteFile
GetStdHandle
GetModuleFileNameA
GetCPInfo
GetACP
GetOEMCP
IsValidCodePage
TlsAlloc
TlsSetValue
TlsFree
GetCurrentThreadId
FreeEnvironmentStringsW
GetEnvironmentStringsW
GetCommandLineW
SetHandleCount
GetFileType
GetStartupInfoA
QueryPerformanceCounter
GetTickCount
GetCurrentProcessId
GetSystemTimeAsFileTime
HeapSize
GetLocaleInfoA
GetStringTypeA
GetStringTypeW
InitializeCriticalSectionAndSpinCount
LCMapStringA
WideCharToMultiByte
LCMapStringW
.?AVout_of_range@std@@
.?AVfacet@locale@std@@
.?AV_Locimp@locale@std@@
Copyright (c) 1992-2004 by P.J. Plauger, licensed by Dinkumware, Ltd. ALL RIGHTS RESERVED.
.?AVtype_info@@
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
.?AVbad_exception@std@@
.?AV?$basic_stringbuf@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@
.?AV?$basic_streambuf@DU?$char_traits@D@std@@@std@@
.?AVexception@std@@
.?AVlogic_error@std@@
.?AVlength_error@std@@
.?AVbad_alloc@std@@
gggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggg
gggggggggggggggggggggggggggggggggggggg
gggggggggggggggggggggggggggggggggggg9
ggggggggggggggggggggggggggggggggg9z
5@ggggggggggggggggggggggggggggggg
gggggggggggggggggggggggggggggg
[gggggggggggggggggggggggggggggd
[ggggggggggggggggggggggggggggg
[ggggggggggggggggggggggggggggg
gggggggggggggggggggggggggggggg
gggggggggggggggggggggggggggggg
ggggggggggggggggggggggggggggggg
ggggggggggggggggggggggggggggggggg[
ggggggggggggggggggggggggggggggggggggggggg
ggggggggggggggggggggggggggggggggggggggggg
ggggggggggggggggggggggggggggggggggggggggg
ggggggggggggggggggggggggggggggggggggggggg
pgggggggggg
gggggggggggggggggggggggggggg
ggggggggggG
gggggggggggggggggggggggggggg
ggggggggg
gggggggggggggggggggggggggggg
ggggggg@
gggggggggggggggggggggggggggg
gggggggggggggggggggggggggggg
gggggggggggggggggggggggggggg
gggggggggggggggggggggggggggg
ggggggggggggggggggggggggggggg
gggggggggggggggggggggggggggggcg
gggggggggggggggggggggggggggggg
gggggggggggggggggggggggggggggg
pggggggggggggggggggggggggggggggg
pgggggggggggggggggggggggggggggggggpgJ
cgggggggggggggggggggggggggggggggggggggg
ggggggggggggggggggggggggggggggggggggggggp
[gggggggggggggggggggggggggggggggggggggggg
[gggggggggggggggggggggggggggggggggggggggggg
[gggggggggggggggggggggggggggggggggggggggggggg
[gggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggg
UyNhOj
|zz~{}~}
|~{||}{~
zz~~z|
{{}|}|
||{}~z
{{~}~~
|z~~}{
|}|{|{}
~}|||{z
~~z~~}}
||~{|}
}}|{||{
}}{z||
{~~|~~
~|~{|~
|z}z}{|
z|z{z|
~~{{z{|
~}z|{z
||}}y}
{}|z~~{
W^hWYN
x0cwc)
HufVYCp
v-Gf"zB
aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa
aaaaaa
aaaaaaa/
qaaaaaaac
aaaaaaaa4
aaaaaaaaaaA<
aaaaaaaa
x,HH(H(N
{i#i{#VVtttVttt~~~~K
;S;;;;;7777777[7/7y[y[y
`&}A}=h
{qJ<<
Sapefo sijomohabi botasivoy wiwuwomi gotumupiz. Hufihiniyonuc wuzidejed yazuresije. Yewewuxu wibifulep manomaxusizic gurusodepibim vuba. Duxi. Lum peberekexohis joveyozocukurid gobu lazevov. Neze nuva mopu. Kibisotipeg suhosamuga nesofemetusirec giz lolesehiben. Kinafeb limecizinaja leheyusumu. Vezorotikox zuruxelurese naku bec. Fihinomew gitovudahojara wexoc. Nosahexohebuzek minocisiw jigepuberohojo. Rafodimufopew. Hatuned. Vamu dipudal viyufamazoho. Ruwopaw hoxijobutoyi lowesu xevuk fed. Piwuxuwawocucum. Ket nizolaraha tacej. Puyihorabice. Sujagucixidug mudazagu zuromu sibuxopasat relarexides. Layasuzeg jevojiwiwajeh. Patojenaj zipoma. Kinivawav wariponopireg. Denawu xaliyumopalob poluxubepim. Yumahuwazijoy cozey mica tizubamexek. Nocefejo pomida xefahuxuki wulukulinafutid. Ronigejep denupanucowuw dusupuhed zupago jovaporanijolav. Lelikepeyitu muhutorus lezo. Sigo limeso hafetizudov. Meherilil kawocizedukara. Buhofodulon gox. Dawovasu cediduyifije codo duxahobizulet. Fon busev wet ciyidapafowem. Dunat. Pidu
1P2T2X2\2`2d2h2l2p2t2x2|2
2T3X3\3`3t3x3
3 3$3(3,3034383<3@3D3H3L3P3T3X3\3`3d3h3l3p3t3x3|3
4 4$4(4,4044484<4t=x=|=
=,>0>8><>@>D>
? ?(?@?P?T?d?h?l?t?
040D0H0X0\0`0d0l0
1,101@1D1L1d1t1x1
555u5{5
5 6&6+636
9.9F9a9g9u9
:!:*:/:D:J:S:Y:_:f:m:s:z:
;!;<;D;K;S;[;h;o;
<.<D<L<R<X<a<n<w<
=3=I=O=s=y=
2!2'2-2B2a2
9@:d:j:p:v:
2/5<5S5q5
:$:*:4:C:b:
;;<;\;
<#<)<8<A<
=H=R=f=
>%>8>?>J>P>[>`>
N0T0t0
4$4Q4\4n4
5%595K5R5X5j5r5}5
697R7{7
=E>R>a>s>
3!3(3,3034383<3@3D3
4,43484<4@4a4
4*5054585<5
8888L8R8[8n8
8'9G9U9Z9
<%<0<6<<<A<J<g<m<x<}<
61B1u1
4\5d5|5
6&6:6C6p6
6"7*7=7H7M7]7g7n7y7
768C8m8r8}8
8Q9^9{9
;*;Q;^;
000j0w0
1!1E1|1
4%4A4J4P4Y4^4m4
5.555\5b5m5y5
6$60666C6M6T6l6{6
6-737]7c7
778Z8d8
9#9*90979=9E9L9Q9Y9b9n9s9x9~9
:;:A:]:
<1<8<<<@<D<H<L<P<T<
=!=<=C=H=L=P=q=
=:>@>D>H>L>
0.040I0n0
0:1P1`1
2,3L3Q3W3[3a3e3k3o3u3y3~3
5-555E5V5
7M8X8b8s8~8
=<=A=b=g=
>4>=>I>
>4?w?}?
629Y9f9d;X<
<H=N=T=Z=`=f=m=t={=
>>5><>K>P>U>Z>j>
>8?=?D?I?P?U?
2@2R2d2v2
2S4]4u4|4
:%;G;V;r;
<s=D?M?y?
1#2)252
484>4J4
5=637;7
>U?[?k?
7!7%7)7-7175797=7J7%8=8L8x8
4,4I4i4
5$5.585C5G5L5\5h5
6(6H6P6\6|6
707P7p7
8$8@8\8`8
9@9H9L9d9h9
: :<:@:\:`:|:
; ;4;<;@;D;L;T;\;p;x;|;
< <,<L<X<x<
00040T0x0
4$4,444<4D4L4T4\4d4l4
:(:8:\:h:l:p:t:x:
:0;4;`;d;h;l;p;t;x;|;
< <(<,<0<4<8<<<@<D<H<L<X<p<t<x<|<
<@=D=d=l=t=|=
>$>,>4><>D>
mscoree.dll
KERNEL32.DLL
((((( H
h(((( H
H
podekelah xadujozite
tefesuwenurosanuguzakalilorih yax xisolanicapuleyaromocabewasodir mewexayuki
Sax bucikidobebetapelohiwevojejusuze pofek sihesafiyatisutuwumibuhaguv gilanabuwimixahu
kucaparujodupasemeci kadakacohepinigenoki
cofihor hanodatujodakiwabufiyupivace dabacixigoyubefiw
sukinibizekafukocibikakozetumala binocolusijilegulihehevi powonudaravobuhuy howazacehuxupove
cemohuhalunuh fewosepuwujawit hosugemexarosahetiturela widigucojohiwejisuvix vodahoxixunad
vvomizibavobibuvisaw
siwekesifivicive kudojidafafidegivelajefitibemi
oJaj zuxobiyugusodik musunocawituja fiyuvegusapu
tihevecolevat mukofukete yobozufiwavupalod jukelubur hukarawupizepefetanifep
tovukaneza zicobaletiy
jiyamixetafefopuyujijobo zaxamakafiwepagusigini gubaselesopadadipepoju
VS_VERSION_INFO
StringFileInfo
043831F6
LegalCopyright
Copyright (C) 2023, parking
OriginalFilename
nsadgiuubsdeg.exe
ProductsVersion
36.47.26.15
ProductName
SolarOmir
ProductionVersion
1.24.57.52
VarFileInfo
Translation
LLigigijobunalox wimezux hukasatev hobiz kovesek domahowipawap cupipamexupiru.Soy wufefanixona ganacud wijuye citufal nuruma
Wapomebosanapoc roj kud6Mujukolaram boxocumonebuca novalayaba lotexonakac kikicDeceli henaholo vilivo lokowamelofaro mizapoxiyivika fulumelid cebifop xusitiveguhey yisuyugojexodoUTozucipozadi herolu givi tite pamu lulikegoj mari hudiniyopixalo xewewuvafez ficutexiGutopete facavigip xowazezulobaOKetaruwezumabin gaxi gicexoxis moxiwavitaf xitumiriyu fibe fawevez rul puhasiho
Dok tudafiw
Kopazivu
Vafococuwina puyakevidiz
Nolucuto tiw liz
PikaTSemasunevod caso yinohoretukuley woworepefi duyipaj jawopog paf bekukef haluwobujeguhPosa tedalof gupawesut sirisaxuhik volocobajehecaz lakubof mitadakadoposo motehatihe wewuzuxowatepob cev
Febedike hej rut jamexiz
Nofud wacehaximubo zedag,Ratovil palipowamumi vagabevifawazoy yeralewjBakaxicirowijo timuk lomojavaxoxax vuzufoyezizuta lejayewibagivu wegunekufej fawesale mecicuviti ferokecix
Riface*Rubus kenokeboyowix kucemunagomib zenacude9Meminunegoxot xebasepajine tuwopekefopa xerox pejakivujig$Newehonuv gahotif zitak hoyigedumidi
Xobogepox zacijose2Savukokil yisasolagu zisakevik jubefumozutuyu hura^Wezo yajobejo vuweg tudolemam bivajucude barifelexetim koduromuni yuzezulipoter sadaloyisoveco
Runibobemu haxuwehewuje%Pipopaxozohoso gehaget lumivozimizagi
Zut dijewehabavov
&Kih jiwenepi mukekunayege wod nibaxutudLoroluzemuhopax pasalo reditihow venopugapatone leni wixelidajugu guporaxihebayo gatexayacupar tejor
bVupicabode rofuzojew yecajihi fuletarazuzeg zesigi mida nujexafozax xoluvopimo gubohegumaso dolevo
BXocipixexepoke lodagokiwude xehinihirijah yipijag nic wavaziyivifa
Jegulurutecebo docil
Diyulosamaj xer
Yavutecuga cefa lepos
Ruzapawumod bovi
PBipogiri lozuyumawehoc jokugenebilog xudikicisuzin siv gigozob copaceb zilerutay
ASicemeye napaxelehuror wagisogecujefoz cetazowufelex vijepinigosa
7Gofalega bibuzi ruyayapu turuxibir ginanukedus kodumuhu
Hizopegafam humuvema
Bidogakino rojenowupic
OJotibiniz vuriyisoxenases pixen timusugim gacepusedubes cupojuvep zavalarucikisbMojeravubuc kilejiwafebad zuroval lagudagutiruxi gozogedayu yib xuv sirulucog zitosucigevo mizijisIMubifinehobowun pujolic pezujenu muvodiwenitin bun zuvubopewuh pem camoco
Yezeduvoxavago kizuhoturodam
Rar/Walofuzulab wilifeb nob pusogeres rojizufelales
VRupaxorisokimel nelehagile hajihawudeyima wajuhus bifugomufok gebab zeloz pasopayuhule1Lavetigaxu cakekigoj rujonakey xumekobokaj fewero\Rabadayiw guha cigudahijo gonuwecol raguyavocol bazeyi sugikuhotipamo fudehe ladupilayexaraz
Xohixabo kuzahametiQTafekigo muxisu gubulajoged zuna sabohicu kayohipalo yaxicacorimatec relogusuzoji
Wezoxuv!Ruhaf bijomo wabumewekir tufaheseMCuyufifofocatir caneram wazapovenaf huyom cusecukip buvadaduvow mewudikecekiwEVik kutujir ficosohorabiho pefozamases jicajo konoxi vuzideteja yayox>Sajofu nifutuv luhiyibo juziyuzeticufe hehu xolowupijucesu zivHLefiyi yudafomohoy yinenun zejipetago joyuvew zewojuyije bolivoyo gowuli!Fes tijibij mekehuvo widopuruxone
Kigevetume kadelubin govej,Solidirit duj tepe fojesuhepozoj tun mepuxey
Tezagup wibala docimujic
Antivirus Signature
Bkav W32.AIDetectMalware
Lionic Clean
Elastic malicious (high confidence)
DrWeb Trojan.Packed2.45287
MicroWorld-eScan Trojan.GenericKD.67075917
ClamAV Win.Packer.pkr_ce1a-9980177-0
FireEye Generic.mg.df8ab976221bbbd5
CAT-QuickHeal Ransom.Stop.P5
ALYac Clean
Malwarebytes Trojan.MalPack.GS
VIPRE Clean
Sangfor Trojan.Win32.Save.a
K7AntiVirus Trojan ( 00516fdf1 )
BitDefender Trojan.GenericKD.67075917
K7GW Trojan ( 00516fdf1 )
Cybereason malicious.aec62f
BitDefenderTheta Clean
VirIT Clean
Cyren W32/Kryptik.JUT.gen!Eldorado
Symantec ML.Attribute.HighConfidence
tehtris Clean
ESET-NOD32 a variant of Win32/Kryptik.HTNS
APEX Malicious
Paloalto generic.ml
Cynet Malicious (score: 100)
Kaspersky UDS:Backdoor.Win32.Androm.gen
Alibaba Clean
NANO-Antivirus Clean
ViRobot Clean
Rising Trojan.Generic@AI.100 (RDML:fbQCwgyhMcHatGE7WE1/rg)
Sophos Troj/Krypt-VZ
F-Secure Clean
Baidu Clean
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition BehavesLike.Win32.Worm.dh
Trapmine malicious.moderate.ml.score
CMC Clean
Emsisoft Trojan.GenericKD.67075917 (B)
Ikarus Trojan.Win32.Crypt
GData Trojan.GenericKD.67075917
Jiangmin Clean
Webroot W32.Trojan.Gen
Avira Clean
MAX malware (ai score=85)
Antiy-AVL Clean
Gridinsoft Ransom.Win32.LokiBot.bot
Xcitium Clean
Arcabit Clean
SUPERAntiSpyware Clean
ZoneAlarm HEUR:Backdoor.Win32.Androm.gen
Microsoft Ransom:Win32/Aicat.A!ml
Google Detected
AhnLab-V3 Clean
Acronis suspicious
McAfee Artemis!DF8AB976221B
TACHYON Clean
DeepInstinct MALICIOUS
VBA32 BScope.Backdoor.Mokes
Cylance unsafe
Panda Trj/Chgt.AD
Zoner Clean
TrendMicro-HouseCall TROJ_GEN.R002H07EG23
Tencent Clean
Yandex Clean
SentinelOne Static AI - Suspicious PE
MaxSecure Clean
Fortinet W32/GenKryptik.GJWM!tr
AVG Win32:DropperX-gen [Drp]
Avast Win32:DropperX-gen [Drp]
CrowdStrike win/malicious_confidence_100% (W)
No IRMA results available.