Static | ZeroBOX

PE Compile Time

2022-11-01 07:13:49

PE Imphash

7826118a518ad3bb6f3d483135c427db

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x0001d682 0x0001d800 6.4993496432
.data 0x0001f000 0x002cce10 0x00051c00 7.62837000636
.yogiv 0x002ec000 0x00000005 0x00000200 0.0
.rsrc 0x002ed000 0x000195b8 0x00019600 3.90095101365

Resources

Name Offset Size Language Sub-language File type
RT_CURSOR 0x003040e8 0x000010a8 LANG_NEUTRAL SUBLANG_NEUTRAL dBase III DBT, version number 0, next free block index 40
RT_CURSOR 0x003040e8 0x000010a8 LANG_NEUTRAL SUBLANG_NEUTRAL dBase III DBT, version number 0, next free block index 40
RT_CURSOR 0x003040e8 0x000010a8 LANG_NEUTRAL SUBLANG_NEUTRAL dBase III DBT, version number 0, next free block index 40
RT_CURSOR 0x003040e8 0x000010a8 LANG_NEUTRAL SUBLANG_NEUTRAL dBase III DBT, version number 0, next free block index 40
RT_ICON 0x00303810 0x00000468 LANG_TAMIL SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x00303810 0x00000468 LANG_TAMIL SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x00303810 0x00000468 LANG_TAMIL SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x00303810 0x00000468 LANG_TAMIL SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x00303810 0x00000468 LANG_TAMIL SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x00303810 0x00000468 LANG_TAMIL SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x00303810 0x00000468 LANG_TAMIL SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x00303810 0x00000468 LANG_TAMIL SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x00303810 0x00000468 LANG_TAMIL SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x00303810 0x00000468 LANG_TAMIL SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x00303810 0x00000468 LANG_TAMIL SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x00303810 0x00000468 LANG_TAMIL SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x00303810 0x00000468 LANG_TAMIL SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x00303810 0x00000468 LANG_TAMIL SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x00303810 0x00000468 LANG_TAMIL SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x00303810 0x00000468 LANG_TAMIL SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x00303810 0x00000468 LANG_TAMIL SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x00303810 0x00000468 LANG_TAMIL SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x00303810 0x00000468 LANG_TAMIL SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x00303810 0x00000468 LANG_TAMIL SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x00303810 0x00000468 LANG_TAMIL SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x00303810 0x00000468 LANG_TAMIL SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x00303810 0x00000468 LANG_TAMIL SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x00303810 0x00000468 LANG_TAMIL SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x00303810 0x00000468 LANG_TAMIL SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x00303810 0x00000468 LANG_TAMIL SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x00303810 0x00000468 LANG_TAMIL SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x00303810 0x00000468 LANG_TAMIL SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x00303810 0x00000468 LANG_TAMIL SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_STRING 0x00305ea0 0x00000714 LANG_TAMIL SUBLANG_DEFAULT data
RT_STRING 0x00305ea0 0x00000714 LANG_TAMIL SUBLANG_DEFAULT data
RT_STRING 0x00305ea0 0x00000714 LANG_TAMIL SUBLANG_DEFAULT data
RT_STRING 0x00305ea0 0x00000714 LANG_TAMIL SUBLANG_DEFAULT data
RT_ACCELERATOR 0x00303cf0 0x00000090 LANG_TAMIL SUBLANG_DEFAULT data
RT_GROUP_CURSOR 0x00305190 0x00000030 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_GROUP_CURSOR 0x00305190 0x00000030 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_GROUP_ICON 0x00303c78 0x00000076 LANG_TAMIL SUBLANG_DEFAULT data
RT_GROUP_ICON 0x00303c78 0x00000076 LANG_TAMIL SUBLANG_DEFAULT data
RT_GROUP_ICON 0x00303c78 0x00000076 LANG_TAMIL SUBLANG_DEFAULT data
RT_GROUP_ICON 0x00303c78 0x00000076 LANG_TAMIL SUBLANG_DEFAULT data
RT_VERSION 0x003051c0 0x0000020c LANG_NEUTRAL SUBLANG_NEUTRAL data

Imports

Library KERNEL32.dll:
0x401008 SearchPathW
0x401010 AllocConsole
0x401018 LoadResource
0x401024 WaitNamedPipeA
0x401028 OpenSemaphoreA
0x401034 EnumCalendarInfoExW
0x401038 EnumTimeFormatsA
0x401040 GetDriveTypeA
0x401044 GetVolumePathNameW
0x401048 GlobalAlloc
0x401054 GetCalendarInfoA
0x401058 GetFileAttributesW
0x40105c SetSystemPowerState
0x401060 lstrcatA
0x401064 EnumSystemLocalesA
0x401068 GlobalUnfix
0x40106c GetProfileIntA
0x401070 GlobalFix
0x401074 GetLastError
0x40107c GetProcAddress
0x401080 SetComputerNameA
0x401084 ResetEvent
0x401088 LoadLibraryA
0x40108c WriteConsoleA
0x401090 GetProcessId
0x401098 OpenWaitableTimerW
0x40109c SetFileApisToANSI
0x4010a0 QueryDosDeviceW
0x4010a4 AddAtomA
0x4010ac SetSystemTime
0x4010b0 GetModuleFileNameA
0x4010b4 FindNextFileA
0x4010c0 GetModuleHandleA
0x4010c4 CreateMailslotA
0x4010c8 EnumDateFormatsW
0x4010cc CompareStringA
0x4010d0 GetShortPathNameW
0x4010d4 SetCalendarInfoA
0x4010d8 TerminateJobObject
0x4010e0 DeleteFiber
0x4010e8 WideCharToMultiByte
0x4010ec InterlockedExchange
0x4010f0 MultiByteToWideChar
0x4010f4 EncodePointer
0x4010f8 DecodePointer
0x4010fc Sleep
0x401110 HeapFree
0x401114 HeapAlloc
0x401118 HeapReAlloc
0x40111c GetCommandLineA
0x401120 HeapSetInformation
0x401124 GetStartupInfoW
0x401128 GetCPInfo
0x40112c RaiseException
0x401130 RtlUnwind
0x401134 LCMapStringW
0x401138 GetACP
0x40113c GetOEMCP
0x401140 IsValidCodePage
0x401144 TlsAlloc
0x401148 TlsGetValue
0x40114c TlsSetValue
0x401150 TlsFree
0x401154 GetModuleHandleW
0x401158 SetLastError
0x40115c GetCurrentThreadId
0x401168 IsDebuggerPresent
0x40116c TerminateProcess
0x401170 GetCurrentProcess
0x401178 HeapCreate
0x40117c SetHandleCount
0x401180 GetStdHandle
0x401188 GetFileType
0x40118c ExitProcess
0x401190 WriteFile
0x401194 GetModuleFileNameW
0x401198 SetFilePointer
0x40119c CloseHandle
0x4011ac GetTickCount
0x4011b0 GetCurrentProcessId
0x4011b8 GetStringTypeW
0x4011bc GetLocaleInfoW
0x4011c0 HeapSize
0x4011c4 GetUserDefaultLCID
0x4011c8 GetLocaleInfoA
0x4011cc IsValidLocale
0x4011d0 GetConsoleCP
0x4011d4 GetConsoleMode
0x4011d8 LoadLibraryW
0x4011dc SetStdHandle
0x4011e0 FlushFileBuffers
0x4011e4 WriteConsoleW
0x4011e8 CreateFileW
0x4011ec DeleteFileA
Library GDI32.dll:
0x401000 GetCharABCWidthsW

!This program cannot be run in DOS mode.
`.data
.yogiv
generic
iostream
system
iostream stream error
Unknown exception
bad allocation
Visual C++ CRT: Not enough memory to complete call to strerror.
LC_TIME
LC_NUMERIC
LC_MONETARY
LC_CTYPE
LC_COLLATE
LC_ALL
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
bad exception
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
HH:mm:ss
dddd, MMMM dd, yyyy
MM/dd/yy
December
November
October
September
August
February
January
Saturday
Friday
Thursday
Wednesday
Tuesday
Monday
Sunday
FlsFree
FlsSetValue
FlsGetValue
FlsAlloc
(null)
`h````
xpxxxx
CorExitProcess
Illegal byte sequence
Directory not empty
Function not implemented
No locks available
Filename too long
Resource deadlock avoided
Result too large
Domain error
Broken pipe
Too many links
Read-only file system
Invalid seek
No space left on device
File too large
Inappropriate I/O control operation
Too many open files
Too many open files in system
Invalid argument
Is a directory
Not a directory
No such device
Improper link
File exists
Resource device
Unknown error
Bad address
Permission denied
Not enough space
Resource temporarily unavailable
No child processes
Bad file descriptor
Exec format error
Arg list too long
No such device or address
Input/output error
Interrupted function call
No such process
No such file or directory
Operation not permitted
No error
united-states
united-kingdom
trinidad & tobago
south-korea
south-africa
south korea
south africa
slovak
puerto-rico
pr-china
pr china
new-zealand
hong-kong
holland
great britain
england
britain
america
swedish-finland
spanish-venezuela
spanish-uruguay
spanish-puerto rico
spanish-peru
spanish-paraguay
spanish-panama
spanish-nicaragua
spanish-modern
spanish-mexican
spanish-honduras
spanish-guatemala
spanish-el salvador
spanish-ecuador
spanish-dominican republic
spanish-costa rica
spanish-colombia
spanish-chile
spanish-bolivia
spanish-argentina
portuguese-brazilian
norwegian-nynorsk
norwegian-bokmal
norwegian
italian-swiss
irish-english
german-swiss
german-luxembourg
german-lichtenstein
german-austrian
french-swiss
french-luxembourg
french-canadian
french-belgian
english-usa
english-us
english-uk
english-trinidad y tobago
english-south africa
english-nz
english-jamaica
english-ire
english-caribbean
english-can
english-belize
english-aus
english-american
dutch-belgian
chinese-traditional
chinese-singapore
chinese-simplified
chinese-hongkong
chinese
canadian
belgian
australian
american-english
american english
american
Norwegian-Nynorsk
`h`hhh
xppwpp
GetProcessWindowStation
GetUserObjectInformationW
GetLastActivePopup
GetActiveWindow
MessageBoxW
Complete Object Locator'
Class Hierarchy Descriptor'
Base Class Array'
Base Class Descriptor at (
Type Descriptor'
`local static thread guard'
`managed vector copy constructor iterator'
`vector vbase copy constructor iterator'
`vector copy constructor iterator'
`dynamic atexit destructor for '
`dynamic initializer for '
`eh vector vbase copy constructor iterator'
`eh vector copy constructor iterator'
`managed vector destructor iterator'
`managed vector constructor iterator'
`placement delete[] closure'
`placement delete closure'
`omni callsig'
delete[]
new[]
`local vftable constructor closure'
`local vftable'
`udt returning'
`copy constructor closure'
`eh vector vbase constructor iterator'
`eh vector destructor iterator'
`eh vector constructor iterator'
`virtual displacement map'
`vector vbase constructor iterator'
`vector destructor iterator'
`vector constructor iterator'
`scalar deleting destructor'
`default constructor closure'
`vector deleting destructor'
`vbase destructor'
`string'
`local static guard'
`typeof'
`vcall'
`vbtable'
`vftable'
operator
delete
__unaligned
__restrict
__ptr64
__eabi
__clrcall
__fastcall
__thiscall
__stdcall
__pascal
__cdecl
__based(
bad locale name
ios_base::badbit set
ios_base::failbit set
ios_base::eofbit set
zujuhixedu
guhitazi
xipapigujawasuvataj
yejurigamowocobifirugukumarahiz
dunuzamimusax
refekiyitovuhuvabehibuzok
ridapohaxezehofecuputecarukoririheborutoyo
%s %d %f
zalavegolenos
sigur zaxozufa xupemeyuzusuxayiwutoyihefoso
gezuhahonivugeno
vacebasoserawocilevisatuco
pecakamufizapiyavagix
folavovizapohabowemi
tanomuxihijiporifulera
invalid string position
vector<T> too long
string too long
bad cast
1#QNAN
1#SNAN
T$0UVRP
9t$Pr9
D$ 9t$4s
L$ j@Q
L$ j@Q
T$$j@R
T$$j@R
T$hjlR
D$hPQRV
T$hjlR
D$hPQRV
DVPQRh
\$L9D$D
9t$Dr
D$09t$`r
<+t'<-t#<0u
T$hWQR
L$0VPQ
tv9urVj
t}9uyj
PPPPPPPP
QQSVWd
.t|PVj@
t=MOC
HtHu4j
t*=RCC
;7|G;p
tR99u2
t"SS9] u
HHtXHHt
?If90t
j@j ^V
uh4+@
^SSSSS
F Pj*S
F$Pj+Sj
F(Pj,S
F,Pj-S
F0Pj.S
F4Pj/S
F8PjDS
F<PjES
F@PjFS
FDPjGS
FHPjHS
FLPjIS
FPPjJS
FTPjKS
FXPjLS
F\PjMS
F`PjNS
FdPjOS
FhPj8S
FlPj9S
FpPj:S
FtPj;S
FxPj<S
F|Pj=S
C PjPV
C$PjQV
C*PjTV
C+PjUV
C,PjVV
C-PjWV
C.PjRV
C/PjSV
CHPjPV
CLPjQV
tKhX7@
t:hT7@
u h\7@
PPPPPPPP
HHtYHHt
URPQQh`tA
u}h08@
t VV9u
;t$,v-
UQPXY]Y[
D$PTC@
<+t"<-t
+t HHt
GetVolumeNameForVolumeMountPointA
GlobalFix
SearchPathW
FindFirstChangeNotificationW
AllocConsole
GetConsoleAliasExesLengthA
LoadResource
InterlockedIncrement
InterlockedDecrement
WaitNamedPipeA
OpenSemaphoreA
FreeEnvironmentStringsA
MoveFileWithProgressA
EnumCalendarInfoExW
EnumTimeFormatsA
SetProcessPriorityBoost
GetDriveTypeA
GetVolumePathNameW
GlobalAlloc
GetPrivateProfileIntA
GetVolumeInformationA
GetCalendarInfoA
GetFileAttributesW
SetSystemPowerState
lstrcatA
EnumSystemLocalesA
GlobalUnfix
GetProfileIntA
DeleteFiber
GetLastError
GetCurrentDirectoryW
GetProcAddress
SetComputerNameA
ResetEvent
LoadLibraryA
WriteConsoleA
GetProcessId
InterlockedExchangeAdd
OpenWaitableTimerW
SetFileApisToANSI
QueryDosDeviceW
AddAtomA
GetPrivateProfileStructA
SetSystemTime
GetModuleFileNameA
FindNextFileA
FindFirstVolumeMountPointA
CreateIoCompletionPort
GetModuleHandleA
CreateMailslotA
EnumDateFormatsW
CompareStringA
GetShortPathNameW
SetCalendarInfoA
TerminateJobObject
LocalFileTimeToFileTime
KERNEL32.dll
GetCharABCWidthsW
GDI32.dll
WideCharToMultiByte
InterlockedExchange
MultiByteToWideChar
EncodePointer
DecodePointer
InitializeCriticalSection
DeleteCriticalSection
EnterCriticalSection
LeaveCriticalSection
HeapFree
HeapAlloc
HeapReAlloc
GetCommandLineA
HeapSetInformation
GetStartupInfoW
GetCPInfo
RaiseException
RtlUnwind
LCMapStringW
GetACP
GetOEMCP
IsValidCodePage
TlsAlloc
TlsGetValue
TlsSetValue
TlsFree
GetModuleHandleW
SetLastError
GetCurrentThreadId
UnhandledExceptionFilter
SetUnhandledExceptionFilter
IsDebuggerPresent
TerminateProcess
GetCurrentProcess
IsProcessorFeaturePresent
HeapCreate
SetHandleCount
GetStdHandle
InitializeCriticalSectionAndSpinCount
GetFileType
ExitProcess
WriteFile
GetModuleFileNameW
SetFilePointer
CloseHandle
FreeEnvironmentStringsW
GetEnvironmentStringsW
QueryPerformanceCounter
GetTickCount
GetCurrentProcessId
GetSystemTimeAsFileTime
GetStringTypeW
GetLocaleInfoW
HeapSize
GetUserDefaultLCID
GetLocaleInfoA
IsValidLocale
GetConsoleCP
GetConsoleMode
LoadLibraryW
SetStdHandle
FlushFileBuffers
WriteConsoleW
CreateFileW
DeleteFileA
.?AVerror_category@std@@
.?AV_Generic_error_category@std@@
.?AV_Iostream_error_category@std@@
.?AV_System_error_category@std@@
.?AV_Locimp@locale@std@@
.?AVlogic_error@std@@
.?AVlength_error@std@@
.?AVout_of_range@std@@
Copyright (c) 1992-2004 by P.J. Plauger, licensed by Dinkumware, Ltd. ALL RIGHTS RESERVED.
.?AVtype_info@@
.?AVbad_exception@std@@
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
.?AV?$numpunct@D@std@@
.?AV?$num_put@DV?$ostreambuf_iterator@DU?$char_traits@D@std@@@std@@@std@@
.?AV?$ctype@D@std@@
.?AUctype_base@std@@
.?AVfacet@locale@std@@
.?AV?$basic_stringstream@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@
.?AV?$basic_stringbuf@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@
.?AV?$basic_iostream@DU?$char_traits@D@std@@@std@@
.?AV?$basic_ostream@DU?$char_traits@D@std@@@std@@
.?AV?$basic_istream@DU?$char_traits@D@std@@@std@@
.?AV?$basic_streambuf@DU?$char_traits@D@std@@@std@@
.?AV?$basic_ios@DU?$char_traits@D@std@@@std@@
.?AV?$_Iosb@H@std@@
.?AVios_base@std@@
.?AVruntime_error@std@@
.?AVexception@std@@
.?AVfailure@ios_base@std@@
.?AVsystem_error@std@@
{pPNFn2G
\4Fp!_=
DVa'X%
[*l&<}
#!y>%Hy
K{]6AF
?h*\uB[
};,|9D
)2LEiQ
R#IB=|
\cxql+
S]olcPt
1)^K\E
o1$w)7
u]:d3_!L
tO#wVa
r)siI#
+y%op'8
)T9su8
[<~pC9@h6@j
mh>F"ox
:J`P.I
^N9GUS
4cjTdP
x|Y]TNR
0VA.\w
\W-8=
&_k_S:
IL;{''p
^_B)h<
:b<oD}
Wb`rD8B
m:tRVU
!8Y`]s
g<E-zb
uVs3L.
+`@(M2
3^]Ta8
`NEa4x
L"'>Z
YH E"an
Ip/dA&3
/IUh)M
M%9fo\:
UO+i.?4
)|f|I;
oMoUPd
t1v D4
i5U+(1
xrdb_oj
ff5RR2~
pKyxDN
CF4zg!<8
\z&bh"_
e>Y`g
CF=xF+/
ZvZ<Ol
`ci!Jg>
Z< ^<j
$lr$S`5
vkT2"
M`es(dw-
U0;ywak
n?%&&/
u\3|B-
C=>:|x
NOhJoI
%C6q>JQ2|
A]yA_D
PSvSBn
,GWW7y
D7gED*
&s{pM}~:i
Rt.25R
\ki^sc`
X: ZHY
v?DxrCO
|oiz"l
OjOyP8
d[J/s
+|nHQ}
a,h{dK
$4xsdP/
#u#.oO
<H r-6tQ
ZvZO9x
q+j'0C
)z)}Sl3
utog9L2
,/pDy]o
[k3kZwF
*$(q\:
Z8jVA)nO
^p%#%
NhWWk$Z
~["U2w
wkFNI@
Y7m.f8]
!~>DH_
nW<Di
]%>'|
<+A\~7"
KyS!Md
3T6?EGw
=]55k!A[
rx/0:@wx
dY3kzi
0b}%RZ
SliU|qO
rMa&6`
] 8&lc
m5{jh
kQD\>l
g;dQlML
hn 3g.
Dl{PY+#k
8Ew0~`
(2g$7Q
t/qE/!.
lG/^ }
K3SnGT
g&L:Q[
:B!+l?
0i2"tV~GTb
jmVGlF
JKh #
.+.=P~Cza<
&h8}gpYL
v[9:_|
kJT[4e
5{Mb}t
1_v+OX
+0'.@{P
H)e&Iq=
9R,/#
Tzxov+
5{"tX#
cJo%Gi
IF?%O]
gm*Z9{7G
6wOFho
f^r8B1
_O`y;)
N2h;u]f
AXumx$
mu)IqK!_
O^ )`t
Aj*vzj
[J$H/w
YRdD6(
]n7Umd
U@nV%3j?
$h0Rzc5a<
.phjE&|B
i:@`O
zK2?r%g
iw^dF +
M}|GNo
qW^l^Z
)3lvHC
qnHSQ*=
,7c-27[}
?S_/zQ
l<&hjR)
OSlJA[
_8Qdj_
jB=Gi
T6[Rwlz
]tb`!M
x`GD,[
qL?^j#/n
a%77ztV
R2SjG`
~AEk/RE
Zx`&mza
`g2jTyUPT
~lQb+7
Uv,In~
3ticNg
k@gUC\
_m1R\$
5q{Ytam`;
z1HOhe
O'/?.@
Nl4ZM}~-
l{wu!C
h}N&k1
'qj{2g
w'=m-BX
TF_5_n9
SqG\(XI
(VHRs~x~
/'/7~R
vJTtNa4
2M7-#d
YB;tuA
8=S=*!
"8B/m*
1V!~|$
:(t5aJ
z5hXO(N
J]:X]g
Maf(-g
yIOHe`
?:@.Hm6{m
z[~#(PE+
}3g=ya
g++z\$R
@h]gY=
/6z'v
$cHTkF
k($][:
:a#C'c
'daTrP
;+@fYi
J^\ P-
xxcd*1
0gMKqK
iUsJaV
scS-7C
kg-/*k
mv:.]Q
|/~f{\4
Kx]KN/
eKg!emO
%9+Xc#
>[,\rW
IPh&>9
{=s_De
}-Qp~b
-{9sd$
Q>2?Nm
SZPH0[xe
G&dxAD
lvKPm2
i"6PnO
nK+%*U7h"&
RIFsY3
K$Hm Y
"&?oQ{'&1
kE+#y'|
r7hTx^7
k'F<9S
5hc/jY
]z@eCJ
( 6(8[
YHkx#\
dLVaJ=)bf
kL+RqX
pk$<.0w
$k)]hg
-?>s*F
,Wy88r"
8G.A1w
JPQ?J'
j%@|vr+
tb{)0
(eOxVw
5&3XoOa
+BYmXiPO
~]YrTf
Q9&ZeIN
e(E^am
{{;]J#
-,[N>K
3aHP`%
c?>;Cr
u]X1Tcz
tA5([.
XZ<RNw
Nxp(B4
$D-t>{V
/)[VYDo
k<hE[,
m(!'@3%X
?D_JHf
}yLn@-
AN{f/,
%M?ql|
)aMlA~B
(p/=;:?4
:eZYnC,&
+ipob
7`:9J%
yK$0r/
dE<Zq}D
>9oMZ4
6V;>B}C
:h4|JS
_9o";
~oN&s,
E2iNZd
IY*a-|
>o)}by
(AWotWj
AYz-?8
0Vi]N<Bd
_I{NNh
(E0C1-
u;'CO7
3v,Z)_
o'T*~Nu$
Q`D<,>y
?kz@@#
Je%c&'A
@s2R~/
oLGCf/
DT$'WZ6
VE15sS\
fvk`0tH^Y
9X6*u'.
0,,4:ul
vqk>ar
iM\_7q
/ugPgZ0u
@)@jJ%
8oY!gR
oM\~
[:*lg
5vA.h&
|B+]{iq
7zYb'l
h82f!U
|pxvBc
UocpFt
M'Q=>T
vK!Pw-
c]~N&l
{d5zC'
/vyJM9
2w{Pf8
4nN9(s
XP2L0Ir
+wsd,+
6!Q/u4-wI{
~rfP=&
dV>6nVL|O
Ve3m5bn
K?*45Z
)RC]MF
%2t!E
Vs:j_W
@55@\_
*l]8j5
>Ub-ER
F6(Gf]
(sj}Hk=x
w-skC$
vOl05es
^^%U[E
q$U?YxX
'juNOW%_Z
ts\G'S
yGe"?o
ky6;46
4X5^1mg4
8jeZeT2>`
B?lxSD
D0mN9c
Iv$z27
Jv50lO
R0FpQ_
d`2}p38
/0|/{m
HW3PR4
Gdu)@Y
rRx/8=xVJ
z5Jat5u
N4uf"N!
]]@u8
>|@jNZ
/KC#(}
@XS+}snV.
bLAW}5
t(\CkgM
TY["me
YE:o==87
eKfVSV
l#M5]#mD
d41V-rC
>`#eZp\d
`m4V^GK
K?-tXQ
N4R*t\CF
C<cj~&
Kg)u/P
[k1K?d
TW:"VSP3
a=jp2x
Zd);`f
v"-q.n:
=[8e`G
#I24h{
OPl6Lq
wW'H8%
hc~Tg#
xzH>Q?/{9;(z
/b|}K
u*))7
;2pI)d
*M<I4V
PY23c#
+hIxcm
(ZC<=xf
6-U^a[
_mPr^H,7q
F3ie"k
?@3rPp
%EMF1G
Oo!Tm:$g
~VmWoH
V%Xvj]
vl)%4~.
$+_<v~
B[5kYz
Q]3?[k
P!t\~%
%1D=@B
VBoy5P5o
STl_4w
NuZ`gE
H1c[;%E!
>wJ>&cM
"+FYd*
+3"<:F5A
}TTR&
%FDl@0#F
t,IMED
{+eX;%
p9h+ .
t<ulk~l
l5pzW2
zih2,Sfcpq=
b!QVDP
w~SpCC
~]&^rTr
!H12F?
SHK?(>
oX,_G[
FUwrxu
#(/%uK
VKbUEse/
lgYvcU
^,$`&d
$U)~ltu%
JlBJ\+
"3>!DP:
vs+L?b
'Pq#:v
<sIA,~
wG1x%0
P{7 *RW
mI-&l3
R0E+-|
*4_W0
,wl6_fs
Qe-*oU
j5psr'{Q
&xAiw
N1W70h
BR e4l
QkCsin
c|z"k
`X=4'v7
ZR^,Nd
`yE_Ej
*_Vf/N
^7AAC3
N@:*Yv
do{F!D[
tx36F-
gu{Vo:;T
.T-Z#YX
y^gfy#
KLt@,et!2YS
1L<1Df
E _#T'
\]E'.%
Rb#:?YX
&FJtW\0<
j:{9l-
0@SnLM~|
qI\w^c
HWd9D*t
{6$'s"
S}!kAiS
cSWcrt
{kd]-U
9JJCi!n5
>}i_hu
&Z)s?A
3:Kq'$
i%mqAD
q'EFlo
l)1tZ/
[^RL{j
nl2CNO
#[kXw-
tpLQ%lrJ
*cd.6@l
\5Y]Fk
_YNdoP
ohFT.5
"'#hc,
*oN:usK
x>tRgm
XIM<sy
.?AVbad_cast@std@@
.?AVbad_alloc@std@@
GGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGG
GGGGGGGGG
GGGGGGGG
GGGGGGG
GGGGGG
fffffff
pppppppp
**************]p
p*0YYY
{{0000
{{0000
GGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGG
===============================================================================%
%%=======`%qt|ssssssI
======%|
=====%|s%s
|t||||
====`ts
ststts
I\%%s`
IIIIIs
====;s
Iqqqqqq
====;I99
%%%%%%%%%\
====;I
***********
|====;I\
|====`6\
|====;q
|====;I
|====;q
;;`=========================
NNNNNNN
NNNNNNNNN
><<<<<
w<<<wQ
KKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKK
KKKKKKKKKKKKKKKKKKKKKKKKKKKKKKK
KKKKKKKKKKKKKKKOyKKKKKKKKKKKKKK
4KKKKKKKKKKKKKK
KKKKKKKKKKKKK
L"KKKKKKKKKKKKK
BKKKKKKKKKKK
+KKKKKKKKKKKK
uKKKKKKKKKK
KKKKKKKKKKK
KKKKKKKKK
KKKKKKKKK3
KKKKKKKKK
4;KKKKKK3
KKKKKKKs
KKKKKKK+;Iq2
4KKKKKKK
jKKKKKKN
KKKKKKKK
KKKKKKKKKKe
nKKKKKKKKKKKKKKKk
KKKKKKKKKKKKKKKKKKKK
KKKKKKKKKKKKKKKKKKKKKKKB
KKKKKKKKKKKKKKKKKKKKKKKKB.
(4xKKKKKKKKKKKKKKKKKKKKKKKKKBo.
KKKKKKKKKKKKKKKKKKKKKKKKKKKB
KKKKKKKKKKKKKKKKKKKKKKKKKKKKs"]KKKKKKKKKKKKKKKKKKKKKKKKKKKKK
KKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKK
ggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggg
gggggg
ggggggg
1gggggg
mggggkx
gggg1zW
5gggg5
5gggggggg
gggggggggg
mggggggggggg
ggggggggggggg
5gggggggggggggggggggggg
z~{}{~
{~{|}}
||}|}{
}~|}|z
~{z{|{
}~|z||
z~{z}}
}}{{|~}
}~}}{|
99999999
l49\\\\\\\\\\\\\
\\\\\94l
+++++++++++++\$l
l$\++_+_+_+_+_+
,,,,,,,,,
VVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVV
VVVVVVVVVVV
VVVVVVVVVVV+
VVVVVVV)
VVVVVVVVVVV)
VVVVVVVVVVV
VVVVVVVVVVVV
+VVVVVVVVVVVV
VVVVVVVVVVVV
eeeeeeee
VVVVVVVVVVVVVd
iiiiiiii
VVVVVVVVVVVd
66666lll
VVVVVVVVVd
VVVVVVVd
ggggggggggggi]
VVVVVd
VVVVVVV
55554d
DVVVVVVVVVVVVVVV
gdVVVVVVVVVVVVVVVVVVog
VVVVVVVVVVVVVVVVVVVV`
gdVVVVVVVVVVVVVVVVVVVV#
`VVVVVVVVVVVVVVVVVVVVVV
dVVVVVVVVVVVVVVVVVVVVVV
VVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVV
UU3UUU
GGGGGG
============================================================================================================================================================================================================
Z_===============_
_=============_
============_
===========_
_pppppppppppp
==========_
pppppppp
=========_
---~-;p
========_
=======_
~--~-~|
=======
;-~~~-
=======
--;~;~
=======
;-;~~~
=======ZI
PPPP~~
;-;~~;|
=======
~-;~;~
=======
;-;;;;
=======
=======
___________;_;_;;;;
=======
P_________;_;;;
=======
P_____;_____
=======
=======
YYYYYYYYYYYYYYYYYYYYYYY
=======
=======
=======
=======
FFFFFFFF
=======
$MMMMM
Z=======
=======
=======
Z=======
=======
=======
a$$$$$
Z=======
$
=======
$$$$$$$
=======
$$$$$$$$
Z=======
$$$$$$$
=======
=======
=======_
Y999dddddddddd
_========_
Z_====================================================================================================================================================================================================
aaaaaaaaaaaaaaaa
mmmmmmPPP
ZZZdddddZ
d88BBBB
########*#***F4
333333333
{{{{{{{{
9_88::{
((((( H
h(((( H
H
HH:mm:ss
dddd, MMMM dd, yyyy
MM/dd/yy
December
November
October
September
August
February
January
Saturday
Friday
Thursday
Wednesday
Tuesday
Monday
Sunday
nKERNEL32.DLL
(null)
mscoree.dll
runtime error
TLOSS error
SING error
DOMAIN error
- Attempt to use MSIL code from this assembly during native code initialization
This indicates a bug in your application. It is most likely the result of calling an MSIL-compiled (/clr) function from a native constructor or from DllMain.
- not enough space for locale information
- Attempt to initialize the CRT more than once.
This indicates a bug in your application.
- CRT not initialized
- unable to initialize heap
- not enough space for lowio initialization
- not enough space for stdio initialization
- pure virtual function call
- not enough space for _onexit/atexit table
- unable to open console device
- unexpected heap error
- unexpected multithread lock error
- not enough space for thread data
- abort() has been called
- not enough space for environment
- not enough space for arguments
- floating point support not loaded
@Microsoft Visual C++ Runtime Library
<program name unknown>
Runtime Error!
Program:
WUSER32.DLL
@CONOUT$
zxuyiguwobajaposicajoyefic
norawipugusicafidokocusesameyuguticacahififapazilirotafedociyitovewiyabufofejotozagerehawitevilalatexinadunisoxekebebut
rorazos
Vimu sedibiku lojifota gepocedaz
jjjjjj
VS_VERSION_INFO
StringFileInfo
029805B1
CompanyName
Factorial
LegalCopyrights
Challenger fazan inc.
LegalTrademarks2
objfngizdf
ProductName
ProductVersion
70.2.43.14
VarFileInfo
Translation
iTax satonahifitezim fareye yixadoyayox pubapadah hofudeyunim gihorupad fahefivex zarodevimupapiw xusaseruRCebuluyobogu zomezaxicu cokapu momivo pisopudu zek cejenixocowubox tufo cik yecifuuGiniyerazen yopemigixilovof tubufadofigahej tocawe noyihaxasivuf dupicezofuf dahodubebote zarudisipusoyu wimizifa kij
Limayavegeg pewajalecohagu
Nahapabikax"Rowenajisebevi vewuviwi nibawiwebo-Mexaba sutidayiba gukoyixun sademutafay cerel
BinafuhifGocec sugotuhuput dabibepisit nohudesuxo wagowage xutoxosiligenot gegatey koyirufaf mifarazefudazo cagURelixi buwerujupimirow pine higufecore vabuligasonu jilegisix repedevokisi lononarisi
MCeci xalab kemoy rihupovixifax cipeh rim wobeyo famiduxasubi yil fupimuzosixa
Jotesokofef+Topoduha cevix vovewigatecub rofiguboyenari<Rakawirazusex tifelebope biyuzokecidufe luvogu gobabuzudakezkTaxopozudi jovohapay wajeposezec sapesefis fedafuhofavofa repupotefuwoxi nalojucediyim vicu jinexun ziwifim
Vuzocoroce batezexLXutifetejovan levo yewuxuhogabihim lilalekosam bopur gulalubuvamevu xat loyiETewecehehari tadusazotupe cepiyezewuxev fec lufolasesi pir nefotudidu
Sefanesofuniy
qWohuyaxohoc silidado tijobunolohe gonatihacef pudazisudajinon zugizix jofilufujeyano bubabu salakipijogiz zijiyom
7Tinuwihizeki basukicesavedos lokahoruwi dapecujinilelap
5Hutodinenepole cekiwuziwu dadevuvohara maxokeweja fep
Zihacino bixemikijozerFBevoya pukopigiso vizoximodihuy kivogec rusupuxotavivet rozalorugifimekNomicutixesa mabulaxo gedicuyoco nuwaga rekojapozasaro carelaca dakuxeyogil dowus lamiyewoga jiyevevoyewizeIWaxucapegagi wemokezet yelodawurudubu gakazemazunoxa pehelokevalin juyepo%Kijasukivizul wusayucof xirajejezulet@Yunofujoy firiluxasudolat gowul tamuhexiku muxidokahi xasohacepobJugowagawomi xalol jupadog tecoperabol yelaz wojusox codowuzoco riwenur buxajuvihip kanowedonilivo
4Semakiviwemimo zufi meh sime kahoxofapucab medijapam
Yipesopinasow xorud difop
Putiheyinetefom tavotobixek/Yuvumowicik jazuribosoditef davehiwepuzodav hag
`Hocubojaco sag xolavifufuz tekatisuwa yuwicum vizuwe xefagugulesijek buruzajacusa nobewimarilusaMMawusot bozulaban hiseyigic selah vunabehahifa cicirimitef nisenomuxibelu yabuReminuremicot geretegedaxu hunabakib roka roveyanimexa wicexajasowafol tuxusofo yojopuhonicaj yadeceh silovunivecuxuy
Antivirus Signature
Bkav W32.AIDetectMalware
Lionic Clean
Elastic malicious (high confidence)
MicroWorld-eScan Gen:Variant.Zusy.470560
CMC Clean
CAT-QuickHeal Clean
McAfee Clean
Malwarebytes Clean
VIPRE Clean
Sangfor Trojan.Win32.Save.a
K7AntiVirus Clean
BitDefender Clean
K7GW Clean
Cybereason malicious.de987e
BitDefenderTheta Clean
VirIT Clean
Cyren Clean
Symantec ML.Attribute.HighConfidence
tehtris Clean
ESET-NOD32 Clean
APEX Malicious
Paloalto Clean
ClamAV Clean
Kaspersky HEUR:Trojan-Downloader.Win32.Convagent.gen
Alibaba Clean
NANO-Antivirus Clean
ViRobot Clean
Rising Trojan.Generic@AI.100 (RDML:j3YByWTIDQWFblfWfOjpXQ)
TACHYON Clean
Sophos Troj/Krypt-XU
Baidu Clean
F-Secure Clean
DrWeb Clean
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition BehavesLike.Win32.Lockbit.hc
Trapmine malicious.high.ml.score
FireEye Generic.mg.6752f0f596295d62
Emsisoft Clean
Ikarus Trojan.Win32
GData Clean
Jiangmin Clean
Webroot Clean
Google Detected
Avira Clean
Antiy-AVL Clean
Gridinsoft Ransom.Win32.STOP.dg!n
Xcitium Clean
Arcabit Clean
SUPERAntiSpyware Clean
ZoneAlarm HEUR:Trojan-Downloader.Win32.Convagent.gen
Microsoft Trojan:Win32/Sabsik.FL.B!ml
Cynet Malicious (score: 100)
AhnLab-V3 Clean
Acronis Clean
VBA32 Clean
ALYac Clean
MAX malware (ai score=88)
DeepInstinct MALICIOUS
Cylance unsafe
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Tencent Clean
Yandex Clean
SentinelOne Static AI - Suspicious PE
MaxSecure Trojan.Malware.300983.susgen
Fortinet Clean
AVG RansomX-gen [Ransom]
Avast RansomX-gen [Ransom]
CrowdStrike win/malicious_confidence_100% (W)
No IRMA results available.