Static | ZeroBOX

PE Compile Time

2022-08-03 01:00:47

PE Imphash

7826118a518ad3bb6f3d483135c427db

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x0001d682 0x0001d800 6.50254235275
.data 0x0001f000 0x00296590 0x0001b400 6.3784833223
.sixe 0x002b6000 0x00000005 0x00000200 0.0
.rsrc 0x002b7000 0x000195b8 0x00019600 3.89436075899

Resources

Name Offset Size Language Sub-language File type
RT_CURSOR 0x002ce0e8 0x000010a8 LANG_NEUTRAL SUBLANG_NEUTRAL dBase III DBT, version number 0, next free block index 40
RT_CURSOR 0x002ce0e8 0x000010a8 LANG_NEUTRAL SUBLANG_NEUTRAL dBase III DBT, version number 0, next free block index 40
RT_CURSOR 0x002ce0e8 0x000010a8 LANG_NEUTRAL SUBLANG_NEUTRAL dBase III DBT, version number 0, next free block index 40
RT_CURSOR 0x002ce0e8 0x000010a8 LANG_NEUTRAL SUBLANG_NEUTRAL dBase III DBT, version number 0, next free block index 40
RT_ICON 0x002cd810 0x00000468 LANG_TAMIL SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x002cd810 0x00000468 LANG_TAMIL SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x002cd810 0x00000468 LANG_TAMIL SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x002cd810 0x00000468 LANG_TAMIL SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x002cd810 0x00000468 LANG_TAMIL SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x002cd810 0x00000468 LANG_TAMIL SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x002cd810 0x00000468 LANG_TAMIL SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x002cd810 0x00000468 LANG_TAMIL SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x002cd810 0x00000468 LANG_TAMIL SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x002cd810 0x00000468 LANG_TAMIL SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x002cd810 0x00000468 LANG_TAMIL SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x002cd810 0x00000468 LANG_TAMIL SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x002cd810 0x00000468 LANG_TAMIL SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x002cd810 0x00000468 LANG_TAMIL SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x002cd810 0x00000468 LANG_TAMIL SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x002cd810 0x00000468 LANG_TAMIL SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x002cd810 0x00000468 LANG_TAMIL SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x002cd810 0x00000468 LANG_TAMIL SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x002cd810 0x00000468 LANG_TAMIL SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x002cd810 0x00000468 LANG_TAMIL SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x002cd810 0x00000468 LANG_TAMIL SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x002cd810 0x00000468 LANG_TAMIL SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x002cd810 0x00000468 LANG_TAMIL SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x002cd810 0x00000468 LANG_TAMIL SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x002cd810 0x00000468 LANG_TAMIL SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x002cd810 0x00000468 LANG_TAMIL SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x002cd810 0x00000468 LANG_TAMIL SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x002cd810 0x00000468 LANG_TAMIL SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x002cd810 0x00000468 LANG_TAMIL SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_STRING 0x002cfea0 0x00000714 LANG_TAMIL SUBLANG_DEFAULT data
RT_STRING 0x002cfea0 0x00000714 LANG_TAMIL SUBLANG_DEFAULT data
RT_STRING 0x002cfea0 0x00000714 LANG_TAMIL SUBLANG_DEFAULT data
RT_STRING 0x002cfea0 0x00000714 LANG_TAMIL SUBLANG_DEFAULT data
RT_ACCELERATOR 0x002cdcf0 0x00000090 LANG_TAMIL SUBLANG_DEFAULT data
RT_GROUP_CURSOR 0x002cf190 0x00000030 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_GROUP_CURSOR 0x002cf190 0x00000030 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_GROUP_ICON 0x002cdc78 0x00000076 LANG_TAMIL SUBLANG_DEFAULT data
RT_GROUP_ICON 0x002cdc78 0x00000076 LANG_TAMIL SUBLANG_DEFAULT data
RT_GROUP_ICON 0x002cdc78 0x00000076 LANG_TAMIL SUBLANG_DEFAULT data
RT_GROUP_ICON 0x002cdc78 0x00000076 LANG_TAMIL SUBLANG_DEFAULT data
RT_VERSION 0x002cf1c0 0x0000020c LANG_NEUTRAL SUBLANG_NEUTRAL data

Imports

Library KERNEL32.dll:
0x401008 SearchPathW
0x401010 AllocConsole
0x401018 LoadResource
0x401024 WaitNamedPipeA
0x401028 OpenSemaphoreA
0x401034 EnumCalendarInfoExW
0x401038 EnumTimeFormatsA
0x401040 GetDriveTypeA
0x401044 GetVolumePathNameW
0x401048 GlobalAlloc
0x401054 GetCalendarInfoA
0x401058 GetFileAttributesW
0x40105c SetSystemPowerState
0x401060 lstrcatA
0x401064 EnumSystemLocalesA
0x401068 GlobalUnfix
0x40106c GetProfileIntA
0x401070 GlobalFix
0x401074 GetLastError
0x40107c GetProcAddress
0x401080 SetComputerNameA
0x401084 ResetEvent
0x401088 LoadLibraryA
0x40108c WriteConsoleA
0x401090 GetProcessId
0x401098 OpenWaitableTimerW
0x40109c SetFileApisToANSI
0x4010a0 QueryDosDeviceW
0x4010a4 AddAtomA
0x4010ac SetSystemTime
0x4010b0 GetModuleFileNameA
0x4010b4 FindNextFileA
0x4010c0 GetModuleHandleA
0x4010c4 CreateMailslotA
0x4010c8 EnumDateFormatsW
0x4010cc CompareStringA
0x4010d0 GetShortPathNameW
0x4010d4 SetCalendarInfoA
0x4010d8 TerminateJobObject
0x4010e0 DeleteFiber
0x4010e8 WideCharToMultiByte
0x4010ec InterlockedExchange
0x4010f0 MultiByteToWideChar
0x4010f4 EncodePointer
0x4010f8 DecodePointer
0x4010fc Sleep
0x401110 HeapFree
0x401114 HeapAlloc
0x401118 HeapReAlloc
0x40111c GetCommandLineA
0x401120 HeapSetInformation
0x401124 GetStartupInfoW
0x401128 GetCPInfo
0x40112c RaiseException
0x401130 RtlUnwind
0x401134 LCMapStringW
0x401138 GetACP
0x40113c GetOEMCP
0x401140 IsValidCodePage
0x401144 TlsAlloc
0x401148 TlsGetValue
0x40114c TlsSetValue
0x401150 TlsFree
0x401154 GetModuleHandleW
0x401158 SetLastError
0x40115c GetCurrentThreadId
0x401168 IsDebuggerPresent
0x40116c TerminateProcess
0x401170 GetCurrentProcess
0x401178 HeapCreate
0x40117c SetHandleCount
0x401180 GetStdHandle
0x401188 GetFileType
0x40118c ExitProcess
0x401190 WriteFile
0x401194 GetModuleFileNameW
0x401198 SetFilePointer
0x40119c CloseHandle
0x4011ac GetTickCount
0x4011b0 GetCurrentProcessId
0x4011b8 GetStringTypeW
0x4011bc GetLocaleInfoW
0x4011c0 HeapSize
0x4011c4 GetUserDefaultLCID
0x4011c8 GetLocaleInfoA
0x4011cc IsValidLocale
0x4011d0 GetConsoleCP
0x4011d4 GetConsoleMode
0x4011d8 LoadLibraryW
0x4011dc SetStdHandle
0x4011e0 FlushFileBuffers
0x4011e4 WriteConsoleW
0x4011e8 CreateFileW
0x4011ec DeleteFileA
Library GDI32.dll:
0x401000 GetCharABCWidthsW

!This program cannot be run in DOS mode.
`.data
generic
iostream
system
iostream stream error
Unknown exception
bad allocation
Visual C++ CRT: Not enough memory to complete call to strerror.
LC_TIME
LC_NUMERIC
LC_MONETARY
LC_CTYPE
LC_COLLATE
LC_ALL
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
bad exception
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
HH:mm:ss
dddd, MMMM dd, yyyy
MM/dd/yy
December
November
October
September
August
February
January
Saturday
Friday
Thursday
Wednesday
Tuesday
Monday
Sunday
FlsFree
FlsSetValue
FlsGetValue
FlsAlloc
(null)
`h````
xpxxxx
CorExitProcess
Illegal byte sequence
Directory not empty
Function not implemented
No locks available
Filename too long
Resource deadlock avoided
Result too large
Domain error
Broken pipe
Too many links
Read-only file system
Invalid seek
No space left on device
File too large
Inappropriate I/O control operation
Too many open files
Too many open files in system
Invalid argument
Is a directory
Not a directory
No such device
Improper link
File exists
Resource device
Unknown error
Bad address
Permission denied
Not enough space
Resource temporarily unavailable
No child processes
Bad file descriptor
Exec format error
Arg list too long
No such device or address
Input/output error
Interrupted function call
No such process
No such file or directory
Operation not permitted
No error
united-states
united-kingdom
trinidad & tobago
south-korea
south-africa
south korea
south africa
slovak
puerto-rico
pr-china
pr china
new-zealand
hong-kong
holland
great britain
england
britain
america
swedish-finland
spanish-venezuela
spanish-uruguay
spanish-puerto rico
spanish-peru
spanish-paraguay
spanish-panama
spanish-nicaragua
spanish-modern
spanish-mexican
spanish-honduras
spanish-guatemala
spanish-el salvador
spanish-ecuador
spanish-dominican republic
spanish-costa rica
spanish-colombia
spanish-chile
spanish-bolivia
spanish-argentina
portuguese-brazilian
norwegian-nynorsk
norwegian-bokmal
norwegian
italian-swiss
irish-english
german-swiss
german-luxembourg
german-lichtenstein
german-austrian
french-swiss
french-luxembourg
french-canadian
french-belgian
english-usa
english-us
english-uk
english-trinidad y tobago
english-south africa
english-nz
english-jamaica
english-ire
english-caribbean
english-can
english-belize
english-aus
english-american
dutch-belgian
chinese-traditional
chinese-singapore
chinese-simplified
chinese-hongkong
chinese
canadian
belgian
australian
american-english
american english
american
Norwegian-Nynorsk
`h`hhh
xppwpp
GetProcessWindowStation
GetUserObjectInformationW
GetLastActivePopup
GetActiveWindow
MessageBoxW
Complete Object Locator'
Class Hierarchy Descriptor'
Base Class Array'
Base Class Descriptor at (
Type Descriptor'
`local static thread guard'
`managed vector copy constructor iterator'
`vector vbase copy constructor iterator'
`vector copy constructor iterator'
`dynamic atexit destructor for '
`dynamic initializer for '
`eh vector vbase copy constructor iterator'
`eh vector copy constructor iterator'
`managed vector destructor iterator'
`managed vector constructor iterator'
`placement delete[] closure'
`placement delete closure'
`omni callsig'
delete[]
new[]
`local vftable constructor closure'
`local vftable'
`udt returning'
`copy constructor closure'
`eh vector vbase constructor iterator'
`eh vector destructor iterator'
`eh vector constructor iterator'
`virtual displacement map'
`vector vbase constructor iterator'
`vector destructor iterator'
`vector constructor iterator'
`scalar deleting destructor'
`default constructor closure'
`vector deleting destructor'
`vbase destructor'
`string'
`local static guard'
`typeof'
`vcall'
`vbtable'
`vftable'
operator
delete
__unaligned
__restrict
__ptr64
__eabi
__clrcall
__fastcall
__thiscall
__stdcall
__pascal
__cdecl
__based(
bad locale name
ios_base::badbit set
ios_base::failbit set
ios_base::eofbit set
zujuhixedu
guhitazi
xipapigujawasuvataj
yejurigamowocobifirugukumarahiz
dunuzamimusax
refekiyitovuhuvabehibuzok
ridapohaxezehofecuputecarukoririheborutoyo
%s %d %f
zalavegolenos
sigur zaxozufa xupemeyuzusuxayiwutoyihefoso
gezuhahonivugeno
vacebasoserawocilevisatuco
pecakamufizapiyavagix
folavovizapohabowemi
tanomuxihijiporifulera
invalid string position
vector<T> too long
string too long
bad cast
1#QNAN
1#SNAN
T$0UVRP
9t$Pr9
D$ 9t$4s
L$ j@Q
L$ j@Q
T$$j@R
T$$j@R
T$hjlR
D$hPQRV
T$hjlR
D$hPQRV
DVPQRh
\$L9D$D
9t$Dr
D$09t$`r
<+t'<-t#<0u
T$hWQR
L$0VPQ
tv9urVj
t}9uyj
PPPPPPPP
QQSVWd
.t|PVj@
t=MOC
HtHu4j
t*=RCC
;7|G;p
tR99u2
t"SS9] u
HHtXHHt
?If90t
j@j ^V
uh4+@
^SSSSS
F Pj*S
F$Pj+Sj
F(Pj,S
F,Pj-S
F0Pj.S
F4Pj/S
F8PjDS
F<PjES
F@PjFS
FDPjGS
FHPjHS
FLPjIS
FPPjJS
FTPjKS
FXPjLS
F\PjMS
F`PjNS
FdPjOS
FhPj8S
FlPj9S
FpPj:S
FtPj;S
FxPj<S
F|Pj=S
C PjPV
C$PjQV
C*PjTV
C+PjUV
C,PjVV
C-PjWV
C.PjRV
C/PjSV
CHPjPV
CLPjQV
tKhX7@
t:hT7@
u h\7@
PPPPPPPP
HHtYHHt
URPQQh`tA
u}h08@
t VV9u
;t$,v-
UQPXY]Y[
D$PTC@
<+t"<-t
+t HHt
GetVolumeNameForVolumeMountPointA
GlobalFix
SearchPathW
FindFirstChangeNotificationW
AllocConsole
GetConsoleAliasExesLengthA
LoadResource
InterlockedIncrement
InterlockedDecrement
WaitNamedPipeA
OpenSemaphoreA
FreeEnvironmentStringsA
MoveFileWithProgressA
EnumCalendarInfoExW
EnumTimeFormatsA
SetProcessPriorityBoost
GetDriveTypeA
GetVolumePathNameW
GlobalAlloc
GetPrivateProfileIntA
GetVolumeInformationA
GetCalendarInfoA
GetFileAttributesW
SetSystemPowerState
lstrcatA
EnumSystemLocalesA
GlobalUnfix
GetProfileIntA
DeleteFiber
GetLastError
GetCurrentDirectoryW
GetProcAddress
SetComputerNameA
ResetEvent
LoadLibraryA
WriteConsoleA
GetProcessId
InterlockedExchangeAdd
OpenWaitableTimerW
SetFileApisToANSI
QueryDosDeviceW
AddAtomA
GetPrivateProfileStructA
SetSystemTime
GetModuleFileNameA
FindNextFileA
FindFirstVolumeMountPointA
CreateIoCompletionPort
GetModuleHandleA
CreateMailslotA
EnumDateFormatsW
CompareStringA
GetShortPathNameW
SetCalendarInfoA
TerminateJobObject
LocalFileTimeToFileTime
KERNEL32.dll
GetCharABCWidthsW
GDI32.dll
WideCharToMultiByte
InterlockedExchange
MultiByteToWideChar
EncodePointer
DecodePointer
InitializeCriticalSection
DeleteCriticalSection
EnterCriticalSection
LeaveCriticalSection
HeapFree
HeapAlloc
HeapReAlloc
GetCommandLineA
HeapSetInformation
GetStartupInfoW
GetCPInfo
RaiseException
RtlUnwind
LCMapStringW
GetACP
GetOEMCP
IsValidCodePage
TlsAlloc
TlsGetValue
TlsSetValue
TlsFree
GetModuleHandleW
SetLastError
GetCurrentThreadId
UnhandledExceptionFilter
SetUnhandledExceptionFilter
IsDebuggerPresent
TerminateProcess
GetCurrentProcess
IsProcessorFeaturePresent
HeapCreate
SetHandleCount
GetStdHandle
InitializeCriticalSectionAndSpinCount
GetFileType
ExitProcess
WriteFile
GetModuleFileNameW
SetFilePointer
CloseHandle
FreeEnvironmentStringsW
GetEnvironmentStringsW
QueryPerformanceCounter
GetTickCount
GetCurrentProcessId
GetSystemTimeAsFileTime
GetStringTypeW
GetLocaleInfoW
HeapSize
GetUserDefaultLCID
GetLocaleInfoA
IsValidLocale
GetConsoleCP
GetConsoleMode
LoadLibraryW
SetStdHandle
FlushFileBuffers
WriteConsoleW
CreateFileW
DeleteFileA
.?AVerror_category@std@@
.?AV_Generic_error_category@std@@
.?AV_Iostream_error_category@std@@
.?AV_System_error_category@std@@
.?AV_Locimp@locale@std@@
.?AVlogic_error@std@@
.?AVlength_error@std@@
.?AVout_of_range@std@@
Copyright (c) 1992-2004 by P.J. Plauger, licensed by Dinkumware, Ltd. ALL RIGHTS RESERVED.
.?AVtype_info@@
.?AVbad_exception@std@@
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
.?AV?$numpunct@D@std@@
.?AV?$num_put@DV?$ostreambuf_iterator@DU?$char_traits@D@std@@@std@@@std@@
.?AV?$ctype@D@std@@
.?AUctype_base@std@@
.?AVfacet@locale@std@@
.?AV?$basic_stringstream@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@
.?AV?$basic_stringbuf@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@
.?AV?$basic_iostream@DU?$char_traits@D@std@@@std@@
.?AV?$basic_ostream@DU?$char_traits@D@std@@@std@@
.?AV?$basic_istream@DU?$char_traits@D@std@@@std@@
.?AV?$basic_streambuf@DU?$char_traits@D@std@@@std@@
.?AV?$basic_ios@DU?$char_traits@D@std@@@std@@
.?AV?$_Iosb@H@std@@
.?AVios_base@std@@
.?AVruntime_error@std@@
.?AVexception@std@@
.?AVfailure@ios_base@std@@
.?AVsystem_error@std@@
"8v# 5>a
m,>JnD
Q=Xp4
ze[\S$K
AX0aHm
RT*QNa
P'bs#>vaBl<
\|:kMQ
sO*^RY
` _p(5
?9Rco{o
bJI_Tu,
q;9_>h
DBXb:Vc
[=/(M'
}\uhr|#
C #&|#Wz;
=;r:R1
@#kEel
\$J{'C
Tl04}&
)?cle1
gUo =P
Dyhs]V
Avm,X=
+4Ce3@
yewbQm
X;0*k7
`F"2Y0
`t4KY#
%Z)-Y3
ynjVT~XB
%Zy;/A
Wv.*#
BiM=Uw
C}671Y
wX?:<X
c~iHw
0'BU[q
td[zm$
\F,/bI
X}X6=9e
&-8xzR
&%+oAQ
<u$:BU$
:"$iqU%o
nXi=2^
MJ!SL]%
pIL.!r
<ZaRo&
wi;1?i
H/NFyD
78gLO`6
LXO~<)
sBu9k8
EGw2I)
;slj.L
/nRe<~
.JMl(>
tJF&j;xFX
0u3xn.
-29s,<#
84{d5C"
'n0U5h
E'CSaA
%oRKuE
yhRn{/
N$.DgK
fF4G|P
c:raG
kSP(L\
\uxngX
d<}gHc
QZjqYX
N+k!0k]
\+Ue+y-
CgbP%z
G:3Vqr
xspv6i
UE4;f
-eSX1O
zyvC"-F
qT34zG
bW'=_`
(N=XE]
'%yL;>M
NI6B9"
NN\4:l
>{2 .&
n3<w2zjc
Z.HtE#
"+i]DAM7'
bUQRKwf
[@J=\S
<0cF_"
!x:Yq`
f7fi];
8F#cS+
P=%g&)
(sNb/J
,x8haKb
#Blt.U.
IRao-
s^]\11
k#m_#p)
__4U9h
Cu]! *
bKWp,o
F~<oNWd
QG-TV@
h'`E~m|
X:=FtX
%<+6C`
8}=]fezj]
mkV+Su
uBPEo/
eA/]Je
n+9"1M
)1BxI:
"PQq+"
!G.Dt>
WDYI!D.;R
cfK(JK
2?[Hee
"L6w1
D`;_$!
>a'")Z
a:9K)#b7
.%e(2f
>a VL,
"04yD]
&Rw@62N{
"kU#9
xBYUV\
_"h`M4
J;"]\R
H'AGi'i
#c s(%SU
6P-(bK
v}OMg`Vc
.?AVbad_cast@std@@
.?AVbad_alloc@std@@
GGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGG
GGGGGGGGG
GGGGGGGG
GGGGGGG
GGGGGG
fffffff
pppppppp
**************]p
p*0YYY
{{0000
{{0000
GGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGG
===============================================================================%
%%=======`%qt|ssssssI
======%|
=====%|s%s
|t||||
====`ts
ststts
I\%%s`
IIIIIs
====;s
Iqqqqqq
====;I99
%%%%%%%%%\
====;I
***********
|====;I\
|====`6\
|====;q
|====;I
|====;q
;;`=========================
NNNNNNN
NNNNNNNNN
iiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiii6iiiiiiiiiiiiiiiiiiiiii6tiiiiiiiiiiiiiiiiiiiiii
iiiiiiiiiiiiiiiiiiiii
iiiiiiiiiiiiiiiiiiiii6
6iiiiiiiiiiiiiiiiiiiii
6iiiiiiiiiiiiiiiiiiii
iiiiiiiiiiiiiiiiiiii
iiiiiiiiiiiiiiiiii
tiiiiiiiiiiiiiiiiiii
iiiiiiiiiiiiiiiii
tiiiiiiiiiiiiiiiiii
6iiiiiiiiiiiiiiii
iiiiiiiiiiiiiiiii
iiiiiiiiiiiiiit
6iiiiiiiiiiiiiiii
iiiiiiiiiiiiii
iiiiiiiiiiiiii
iiiiiiiiiiiii6
tiiiiiiiiiiii
iiiiiiiiiiii
iiiiiiiiii
iiiiiiiiiii6k
iiiiii
iiiiiiiiiii
6iiiiiiiiiit
tiiiiiiiii
iiiiiiiii
6iiiiiiiii
iiiiiiiiii6
6iiiiiiiiiiii
iiiiiiiiiiiiiiit
tiiiiiiiiiiiiiiiiiii
66iiiiiiiiiiiiiiiiiiiiiiii
iiiiiiiiiiiiiiiiiiiiiiiiiiiiiiii
iiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiii
iiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiii
iiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiii
iiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiii
iiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiii
6iiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiii
iiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiii
iiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiii
6iiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiii
iiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiii6tiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiii
}|||z}
{z{~~~
|~z~|{~
{zz~~~
z}{{|}
|{~|||
~~~{|z
99999999
l49\\\\\\\\\\\\\
\\\\\94l
+++++++++++++\$l
l$\++_+_+_+_+_+
,,,,,,,,,
VVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVV
VVVVVVVVVVV
VVVVVVVVVVV+
VVVVVVV)
VVVVVVVVVVV)
VVVVVVVVVVV
VVVVVVVVVVVV
+VVVVVVVVVVVV
VVVVVVVVVVVV
eeeeeeee
VVVVVVVVVVVVVd
iiiiiiii
VVVVVVVVVVVd
66666lll
VVVVVVVVVd
VVVVVVVd
ggggggggggggi]
VVVVVd
VVVVVVV
55554d
DVVVVVVVVVVVVVVV
gdVVVVVVVVVVVVVVVVVVog
VVVVVVVVVVVVVVVVVVVV`
gdVVVVVVVVVVVVVVVVVVVV#
`VVVVVVVVVVVVVVVVVVVVVV
dVVVVVVVVVVVVVVVVVVVVVV
VVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVV
UU3UUU
GGGGGG
============================================================================================================================================================================================================
Z_===============_
_=============_
============_
===========_
_pppppppppppp
==========_
pppppppp
=========_
---~-;p
========_
=======_
~--~-~|
=======
;-~~~-
=======
--;~;~
=======
;-;~~~
=======ZI
PPPP~~
;-;~~;|
=======
~-;~;~
=======
;-;;;;
=======
=======
___________;_;_;;;;
=======
P_________;_;;;
=======
P_____;_____
=======
=======
YYYYYYYYYYYYYYYYYYYYYYY
=======
=======
=======
=======
FFFFFFFF
=======
$MMMMM
Z=======
=======
=======
Z=======
=======
=======
a$$$$$
Z=======
$
=======
$$$$$$$
=======
$$$$$$$$
Z=======
$$$$$$$
=======
=======
=======_
Y999dddddddddd
_========_
Z_====================================================================================================================================================================================================
aaaaaaaaaaaaaaaa
mmmmmmPPP
ZZZdddddZ
d88BBBB
########*#***F4
333333333
{{{{{{{{
9_88::{
((((( H
h(((( H
H
HH:mm:ss
dddd, MMMM dd, yyyy
MM/dd/yy
December
November
October
September
August
February
January
Saturday
Friday
Thursday
Wednesday
Tuesday
Monday
Sunday
nKERNEL32.DLL
(null)
mscoree.dll
runtime error
TLOSS error
SING error
DOMAIN error
- Attempt to use MSIL code from this assembly during native code initialization
This indicates a bug in your application. It is most likely the result of calling an MSIL-compiled (/clr) function from a native constructor or from DllMain.
- not enough space for locale information
- Attempt to initialize the CRT more than once.
This indicates a bug in your application.
- CRT not initialized
- unable to initialize heap
- not enough space for lowio initialization
- not enough space for stdio initialization
- pure virtual function call
- not enough space for _onexit/atexit table
- unable to open console device
- unexpected heap error
- unexpected multithread lock error
- not enough space for thread data
- abort() has been called
- not enough space for environment
- not enough space for arguments
- floating point support not loaded
@Microsoft Visual C++ Runtime Library
<program name unknown>
Runtime Error!
Program:
WUSER32.DLL
@CONOUT$
zxuyiguwobajaposicajoyefic
norawipugusicafidokocusesameyuguticacahififapazilirotafedociyitovewiyabufofejotozagerehawitevilalatexinadunisoxekebebut
rorazos
Vimu sedibiku lojifota gepocedaz
jjjjjj
VS_VERSION_INFO
StringFileInfo
029805B1
CompanyName
Factorial
LegalCopyrights
Challenger fazan inc.
LegalTrademarks2
objfngizdf
ProductName
ProductVersion
70.2.43.14
VarFileInfo
Translation
iTax satonahifitezim fareye yixadoyayox pubapadah hofudeyunim gihorupad fahefivex zarodevimupapiw xusaseruRCebuluyobogu zomezaxicu cokapu momivo pisopudu zek cejenixocowubox tufo cik yecifuuGiniyerazen yopemigixilovof tubufadofigahej tocawe noyihaxasivuf dupicezofuf dahodubebote zarudisipusoyu wimizifa kij
Limayavegeg pewajalecohagu
Nahapabikax"Rowenajisebevi vewuviwi nibawiwebo-Mexaba sutidayiba gukoyixun sademutafay cerel
BinafuhifGocec sugotuhuput dabibepisit nohudesuxo wagowage xutoxosiligenot gegatey koyirufaf mifarazefudazo cagURelixi buwerujupimirow pine higufecore vabuligasonu jilegisix repedevokisi lononarisi
MCeci xalab kemoy rihupovixifax cipeh rim wobeyo famiduxasubi yil fupimuzosixa
Jotesokofef+Topoduha cevix vovewigatecub rofiguboyenari<Rakawirazusex tifelebope biyuzokecidufe luvogu gobabuzudakezkTaxopozudi jovohapay wajeposezec sapesefis fedafuhofavofa repupotefuwoxi nalojucediyim vicu jinexun ziwifim
Vuzocoroce batezexLXutifetejovan levo yewuxuhogabihim lilalekosam bopur gulalubuvamevu xat loyiETewecehehari tadusazotupe cepiyezewuxev fec lufolasesi pir nefotudidu
Sefanesofuniy
qWohuyaxohoc silidado tijobunolohe gonatihacef pudazisudajinon zugizix jofilufujeyano bubabu salakipijogiz zijiyom
7Tinuwihizeki basukicesavedos lokahoruwi dapecujinilelap
5Hutodinenepole cekiwuziwu dadevuvohara maxokeweja fep
Zihacino bixemikijozerFBevoya pukopigiso vizoximodihuy kivogec rusupuxotavivet rozalorugifimekNomicutixesa mabulaxo gedicuyoco nuwaga rekojapozasaro carelaca dakuxeyogil dowus lamiyewoga jiyevevoyewizeIWaxucapegagi wemokezet yelodawurudubu gakazemazunoxa pehelokevalin juyepo%Kijasukivizul wusayucof xirajejezulet@Yunofujoy firiluxasudolat gowul tamuhexiku muxidokahi xasohacepobJugowagawomi xalol jupadog tecoperabol yelaz wojusox codowuzoco riwenur buxajuvihip kanowedonilivo
4Semakiviwemimo zufi meh sime kahoxofapucab medijapam
Yipesopinasow xorud difop
Putiheyinetefom tavotobixek/Yuvumowicik jazuribosoditef davehiwepuzodav hag
`Hocubojaco sag xolavifufuz tekatisuwa yuwicum vizuwe xefagugulesijek buruzajacusa nobewimarilusaMMawusot bozulaban hiseyigic selah vunabehahifa cicirimitef nisenomuxibelu yabuReminuremicot geretegedaxu hunabakib roka roveyanimexa wicexajasowafol tuxusofo yojopuhonicaj yadeceh silovunivecuxuy
Antivirus Signature
Bkav W32.AIDetectMalware
Lionic Trojan.Win32.Convagent.4!c
Elastic malicious (high confidence)
MicroWorld-eScan Gen:Variant.Zusy.470560
FireEye Generic.mg.72b9eecc26102e19
CAT-QuickHeal Clean
ALYac Clean
Malwarebytes Clean
VIPRE Clean
Sangfor Virus.Win32.Save.a
K7AntiVirus Clean
BitDefender Gen:Variant.Zusy.470560
K7GW Clean
Cybereason Clean
Baidu Clean
VirIT Clean
Cyren Clean
Symantec ML.Attribute.HighConfidence
tehtris Clean
ESET-NOD32 Clean
APEX Malicious
Paloalto Clean
ClamAV Clean
Kaspersky HEUR:Trojan-Downloader.Win32.Convagent.gen
Alibaba Clean
NANO-Antivirus Clean
ViRobot Clean
Rising Trojan.Generic@AI.100 (RDML:vZ4kiaqwQIQcnlyPprSExQ)
TACHYON Clean
Sophos Troj/Krypt-XU
F-Secure Clean
DrWeb Clean
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition BehavesLike.Win32.Generic.fh
Trapmine malicious.high.ml.score
CMC Clean
Emsisoft Gen:Variant.Zusy.470560 (B)
Ikarus Trojan.Win32
GData Gen:Variant.Zusy.470560
Jiangmin Clean
Webroot Clean
Avira Clean
Antiy-AVL Clean
Gridinsoft Ransom.Win32.STOP.dg!n
Xcitium Clean
Arcabit Clean
SUPERAntiSpyware Clean
ZoneAlarm HEUR:Trojan-Downloader.Win32.Convagent.gen
Microsoft Trojan:Win32/CryptInject.FB!MTB
Cynet Malicious (score: 100)
AhnLab-V3 Clean
Acronis Clean
McAfee Artemis!72B9EECC2610
MAX malware (ai score=86)
DeepInstinct MALICIOUS
VBA32 Clean
Cylance unsafe
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Tencent Win32.Trojan-Downloader.Convagent.Xmhl
Yandex Clean
SentinelOne Static AI - Suspicious PE
MaxSecure Clean
Fortinet W32/Kryptik.HTQQ!tr
BitDefenderTheta Clean
AVG Win32:RansomX-gen [Ransom]
Avast Win32:RansomX-gen [Ransom]
CrowdStrike win/malicious_confidence_100% (W)
No IRMA results available.