Static | ZeroBOX

PE Compile Time

2022-10-02 09:33:43

PDB Path

C:\zicukohe54\gukok.pdb

PE Imphash

10c92732e2f9b87d0a930bebb28e6cad

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x0003f8f4 0x0003fa00 7.88663955407
.data 0x00041000 0x013a8420 0x0000b400 0.32639769011
.rsrc 0x013ea000 0x00017880 0x00017a00 4.308294736
.reloc 0x01402000 0x0000927c 0x00009400 0.825105569649

Resources

Name Offset Size Language Sub-language File type
RT_CURSOR 0x01401040 0x000000b0 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_CURSOR 0x01401040 0x000000b0 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_CURSOR 0x01401040 0x000000b0 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_CURSOR 0x01401040 0x000000b0 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_CURSOR 0x01401040 0x000000b0 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_CURSOR 0x01401040 0x000000b0 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_CURSOR 0x01401040 0x000000b0 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_CURSOR 0x01401040 0x000000b0 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_CURSOR 0x01401040 0x000000b0 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_CURSOR 0x01401040 0x000000b0 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x013fcbd8 0x00000468 LANG_TELUGU SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x013fcbd8 0x00000468 LANG_TELUGU SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x013fcbd8 0x00000468 LANG_TELUGU SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x013fcbd8 0x00000468 LANG_TELUGU SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x013fcbd8 0x00000468 LANG_TELUGU SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x013fcbd8 0x00000468 LANG_TELUGU SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x013fcbd8 0x00000468 LANG_TELUGU SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x013fcbd8 0x00000468 LANG_TELUGU SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x013fcbd8 0x00000468 LANG_TELUGU SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x013fcbd8 0x00000468 LANG_TELUGU SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x013fcbd8 0x00000468 LANG_TELUGU SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x013fcbd8 0x00000468 LANG_TELUGU SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x013fcbd8 0x00000468 LANG_TELUGU SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x013fcbd8 0x00000468 LANG_TELUGU SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x013fcbd8 0x00000468 LANG_TELUGU SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x013fcbd8 0x00000468 LANG_TELUGU SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x013fcbd8 0x00000468 LANG_TELUGU SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x013fcbd8 0x00000468 LANG_TELUGU SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x013fcbd8 0x00000468 LANG_TELUGU SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x013fcbd8 0x00000468 LANG_TELUGU SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x013fcbd8 0x00000468 LANG_TELUGU SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x013fcbd8 0x00000468 LANG_TELUGU SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_STRING 0x01401728 0x00000156 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_STRING 0x01401728 0x00000156 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_GROUP_CURSOR 0x014010f0 0x00000022 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_GROUP_CURSOR 0x014010f0 0x00000022 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_GROUP_CURSOR 0x014010f0 0x00000022 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_GROUP_CURSOR 0x014010f0 0x00000022 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_GROUP_ICON 0x013fd040 0x00000076 LANG_TELUGU SUBLANG_DEFAULT data
RT_GROUP_ICON 0x013fd040 0x00000076 LANG_TELUGU SUBLANG_DEFAULT data
RT_GROUP_ICON 0x013fd040 0x00000076 LANG_TELUGU SUBLANG_DEFAULT data
RT_VERSION 0x01401118 0x00000204 LANG_NEUTRAL SUBLANG_NEUTRAL data

Imports

Library KERNEL32.dll:
0x401008 CreateMutexW
0x40100c EnumDateFormatsExW
0x401010 VirtualQuery
0x401014 SetEndOfFile
0x401018 ClearCommError
0x40101c EnumCalendarInfoW
0x401024 OpenSemaphoreA
0x401028 SetCommBreak
0x40102c LockFile
0x401030 GetModuleHandleW
0x401034 GetTickCount
0x401038 GetConsoleAliasesA
0x40103c EscapeCommFunction
0x401040 ReadConsoleW
0x401044 FormatMessageA
0x401048 TlsSetValue
0x40104c GetVolumePathNameW
0x401050 FindResourceExA
0x401054 ReadConsoleInputA
0x40105c FindNextVolumeW
0x401064 GetACP
0x401068 GetDateFormatW
0x40106c ReplaceFileA
0x401070 GetStringTypeExA
0x401074 InterlockedExchange
0x401078 GetProfileIntA
0x401080 OpenMutexW
0x401088 SetLastError
0x40108c GetProcAddress
0x401094 CopyFileA
0x401098 LoadLibraryA
0x40109c WriteConsoleA
0x4010a8 GetCurrentProcessId
0x4010ac CreateFileA
0x4010b0 SetStdHandle
0x4010b4 WriteConsoleW
0x4010b8 GetConsoleOutputCP
0x4010bc CloseHandle
0x4010c0 SetFilePointer
0x4010c4 FlushFileBuffers
0x4010c8 ReleaseSemaphore
0x4010d4 Sleep
0x4010e8 MultiByteToWideChar
0x4010ec ExitProcess
0x4010f0 GetCommandLineA
0x4010f4 GetStartupInfoA
0x401100 GetLastError
0x401104 HeapFree
0x401108 RtlUnwind
0x40110c RaiseException
0x401110 HeapAlloc
0x401114 GetCPInfo
0x401118 GetOEMCP
0x40111c IsValidCodePage
0x401120 TlsGetValue
0x401124 TlsAlloc
0x401128 TlsFree
0x40112c GetCurrentThreadId
0x401130 TerminateProcess
0x401134 GetCurrentProcess
0x401138 IsDebuggerPresent
0x40113c WriteFile
0x401140 GetStdHandle
0x401144 GetModuleFileNameA
0x401158 WideCharToMultiByte
0x401160 SetHandleCount
0x401164 GetFileType
0x401168 HeapCreate
0x40116c VirtualFree
0x401178 HeapSize
0x40117c VirtualAlloc
0x401180 HeapReAlloc
0x401184 GetLocaleInfoA
0x401188 GetStringTypeA
0x40118c GetStringTypeW
0x401190 LCMapStringA
0x401194 LCMapStringW
0x401198 GetConsoleCP
0x40119c GetConsoleMode
Library USER32.dll:
0x4011a4 CharToOemBuffA
0x4011a8 LoadMenuA
0x4011ac CharUpperBuffA
0x4011b0 LoadMenuW
0x4011b4 GetSysColorBrush
0x4011b8 DdeQueryStringA
0x4011bc SetCaretPos
0x4011c0 GetClipboardOwner
Library ADVAPI32.dll:
0x401000 InitializeAcl

!This program cannot be run in DOS mode.
`.data
@.reloc
bad allocation
Unknown exception
CorExitProcess
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
EncodePointer
DecodePointer
FlsFree
FlsSetValue
FlsGetValue
FlsAlloc
(null)
`h````
xpxxxx
runtime error
TLOSS error
SING error
DOMAIN error
An application has made an attempt to load the C runtime library incorrectly.
Please contact the application's support team for more information.
- Attempt to use MSIL code from this assembly during native code initialization
This indicates a bug in your application. It is most likely the result of calling an MSIL-compiled (/clr) function from a native constructor or from DllMain.
- not enough space for locale information
- Attempt to initialize the CRT more than once.
This indicates a bug in your application.
- CRT not initialized
- unable to initialize heap
- not enough space for lowio initialization
- not enough space for stdio initialization
- pure virtual function call
- not enough space for _onexit/atexit table
- unable to open console device
- unexpected heap error
- unexpected multithread lock error
- not enough space for thread data
This application has requested the Runtime to terminate it in an unusual way.
Please contact the application's support team for more information.
- not enough space for environment
- not enough space for arguments
- floating point support not loaded
Microsoft Visual C++ Runtime Library
<program name unknown>
Runtime Error!
Program:
bad exception
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
HH:mm:ss
dddd, MMMM dd, yyyy
MM/dd/yy
December
November
October
September
August
February
January
Saturday
Friday
Thursday
Wednesday
Tuesday
Monday
Sunday
`h`hhh
xppwpp
Complete Object Locator'
Class Hierarchy Descriptor'
Base Class Array'
Base Class Descriptor at (
Type Descriptor'
`local static thread guard'
`managed vector copy constructor iterator'
`vector vbase copy constructor iterator'
`vector copy constructor iterator'
`dynamic atexit destructor for '
`dynamic initializer for '
`eh vector vbase copy constructor iterator'
`eh vector copy constructor iterator'
`managed vector destructor iterator'
`managed vector constructor iterator'
`placement delete[] closure'
`placement delete closure'
`omni callsig'
delete[]
new[]
`local vftable constructor closure'
`local vftable'
`udt returning'
`copy constructor closure'
`eh vector vbase constructor iterator'
`eh vector destructor iterator'
`eh vector constructor iterator'
`virtual displacement map'
`vector vbase constructor iterator'
`vector destructor iterator'
`vector constructor iterator'
`scalar deleting destructor'
`default constructor closure'
`vector deleting destructor'
`vbase destructor'
`string'
`local static guard'
`typeof'
`vcall'
`vbtable'
`vftable'
operator
delete
__unaligned
__restrict
__ptr64
__clrcall
__fastcall
__thiscall
__stdcall
__pascal
__cdecl
__based(
GetProcessWindowStation
GetUserObjectInformationA
GetLastActivePopup
GetActiveWindow
MessageBoxA
USER32.DLL
SunMonTueWedThuFriSat
JanFebMarAprMayJunJulAugSepOctNovDec
CONOUT$
bad allocation
tixawuracuzekohodumehuzohasazepinivujufidimavarekukavufehupasikavufehiwitozaxeyax
temuzozolexawabujopekufowivituvihuwicufubeyudikagesorivucubum
hoxizimagilagiwawimijumiduwi
zudedizih
ucerurecoboxonebo
koleweginabu
kernel32.dll
bad exception
GlobalAlloc
funuremutakuseroxobehiwe
fixanicowajim
zetidiwazixajoremoy
yuyeyupuyobomuxagijijayejexa
msimg32.dll
mefinukeresirofobolatudenijoromafopetaxo
gilabej
C:\zicukohe54\gukok.pdb
D$$1D$
L$\Qh<-@
D$$1D$
D$$PQQf
|*SSQVj
QQSVWd
0SSSSS
0A@@Ju
>=Yt1j
j@j ^V
HtHu4j
s[S;7|G;w
tR99u2
0SSSSS
PPPPPPPP
0SSSSS
PPPPPPPP
t"SS9]
URPQQh
;t$,v-
UQPXY]Y[
t+WWVPV
|@u/23
?lo2cX
PMG~d`
kbvbzV
i=g,Wn4
mt@@vH,
~>g"_MO=
cd8\Q(
W|0teV
&vH0x~
B7So `
ncRz;k
Ve_!^g)
_eD*C4
GlZb{R
3~x6>L
ywROJl
.`Mz{"a
/'TS$s
V"P2M2
wZD?'L`
"w`<=>
_X]!e
+Brg'-
hfvZ}jV#
,/;Yh]
Mp<aap
=^?1sSHY)
Q{?E@<
L%b08|f
x2UH}z'
*TRk=N
Z@<('C
&}Z[=
=;N_UAJNB\
3&dZX/
5uK>+}
`z*|f2
3,5[t?
Q|:U5ZlP
\-NOR`N;
9O+1t@P
Ocg~Dg
{:^^8vA
@FdSbB
b9q)mSz
fx"Gh.)F
,>nZiO
*SJx'
Pm-4&!
c4N#h`X
X2Mr?[J
P)%9d<
%(t%`~J
\:ATcX
i05"e
=dt[r^&
g;{v#y(
.ud:jko
>jY|~X"Y
\l$,@s
1Tr%;Ve
!6adY\
GQ D3*
0<s$@*
p\6x^)
\W#QMd'G
)yet;Y
O)]Q+l
n&oc9iv$
fy*d=
>yv4Xk
\MU`BFS
Ru8ATx*^
B,+3|k
>E-d%@
r4kPU=z
m4#q`m
T#mH<]+
:*t)?D
+),i3!
Te& 2y
[9W;PQ
eE}/$#
q,7w?wP
b1D'K1
E(Lttx
5;LbG:Bh
'YVDZ^o7j
o@Vh?8
";inj2/
k\2@ZiH
VI5_OS
ei43jy:
g;hm$B
Rg.vOM
gTF\FO
RCpd>D
|uo/.qf
HBIm(7
_hB^"|
PZY%h:
5qW5j;T
owVdqs
hrc\Pz
0"#gK6d
](6Qzuiq(
4/4`]-
`N8Kke
%yD]S!
Z#6wg@G
n W $t&'
66l0$k
|Ub~IgDb
IpHd8bp
`;eh#bg
]'79_(~C
`;}+?D
8^ld^[
qNRTH[
kU/p^Ow
fCPO)8R_z\
9eAHb:
}|x!Mf
iCjj'H
^o[ey#
8\0EQiCG
q;,?M<
-,W,
\jn:mv
c\6/5gFO7
K6]!R`
z@I#`KslvC
z<~-QisLy
SG`a]8
P$|Da=W
7el!
w%H`_R
POI*`9
2N_Y>Z3
DLAiHvO[K
vBVSTmI
HUwK7h
wY.cC|
YJqUZ"1+
o.4pSs
010?'3_
EWQ_hX
g3"8j;|y
PTjZlR
;.TaZ
6S>vl3R=b
 ?e_6
"H;OHKv
1Aa3=by
EH~Q/@N
0-7Ka@D
7HPNpdG
9nzD"
qYrJMtQ
`z$PHV
^LL33o
hdNFN"
3:@LNG
,UJ=2@
6k+6Jc0,g
rE%<pEz
]VC#>o/
!W%G&Q|
fFw7N6u
K^_dtvH
A xtw<
Q;SWS@0
YEtrr^*
HUay1Bn
BV2nT>
{#\syL{k
>J*O'o
k3y"8lM
xEX 1zgi
vn":GLgY
Ke%cw]
v 3uL
$20JN;y
ok}J}O
K|c:Vo
b2Y'nFV0E
lvRt%sZ&
([NnEiM
1{~:q9
Mvs-S4
*FvCLMQ
q#LA+K
w:t+~\
)m8aA/
{*a*.t
N@%Z|c
!u;Auu
v+!Z9<75
rt,iGk
7',C|!
ob>>F<
\7j/kb
=5yqbl
(C_-WA7
;^qo1e
">K9c1
{RuwwSu
Gn3B#s*1
Z)qs));
3|J7M->$SX`
4!kfA|*$T
$oo1Z'C
'?^X``
MMTjyA
*@I0a0
]}Ic;O
iBy0o9'6
',"475
Wz.sO_
@b@&sM
!m{AT[x
tlh!@v
vu8!AU
W0P_XMB
@ M@C&j
4el7UT
h4`}i1
ik/e`3s
']DsB31K
md"=(.?9
&Xtm!vy
&K} U_Cm
ucRyr[
K0:=>X
uVvqwz
q1(.QT2
ss>/8|
Ulm UH
ABAkLm
&JsB1Z
>Z5wpOv
"D"rrcr
Rk}TsJ
2\ o*K
Yk!w.E
WH$Vo}
ki.Wgu&
loN^]S
dJ)JPl
qw1#m?
Y:iyo&+
PO^'f_
ciUcZW
2UM/i=7<
6Abx\b.
uS5`ao
6P|,S
gsE!|
VgyZm
cYme1N
&YMoI\.
|-s{)v
V<l?H$
A7;:%!,o
=X`yW@
RpRI_Q
@m%`Ygn
r?2\ipc
t/qDi fm
n,EDYq,>
zP4E6b
F^{G#PQ
T2H?6b
tcg'E^
SiqUdC
);JKn&
6N(2x
ZGK2TS
@hG^-9I.
b6hD3
gKa6_p
wn3jg<
$Z[(=a
Hl?A`@
n3vzi0
TQ:ab7
Z>w.4w
p iGyp0E
>W5(47
X3DJOm
p>:?;e
&'kB'0mI
ZTq9IA
oxui v
_Df.LS
rVT/.v
ni}2xo
h883P\kx
e5,96q
%')VaW
9)7P3i
^&-AIm
X?#rXq
&L!T2Y
Hm9nm
=~bX896
-77Fi{
Wzy0_O
F49Qz]
erEm~5kiN
:u9%:d
r!*%sC
97WW D
Jk&;(9
JLfNX1
%OSSGZ
u8zx.Q#L[
.5(>f@
8/j="D
4Q@n(U
hmL{h^
RA>J7J,
X!V&pd3
cC"l<o
dezviwye[k
>X~81,u
jkT,.W
N0`_J#
dS:e:Y
)}=x\z1Xf
S#U<^Nz
w@4!_q
fro%}S
AXn"Tc*-
? ('#N
{>tNZIh
7R[Gics.s
<S8E5'Xz
(5[\MW
W# gSW
\P@z\O4T
=zy{IC
%4>Jc@+Y
GetDateFormatW
CreateMutexW
EnumDateFormatsExW
VirtualQuery
SetEndOfFile
ClearCommError
EnumCalendarInfoW
GetLogicalDriveStringsW
OpenSemaphoreA
SetCommBreak
LockFile
GetModuleHandleW
GetTickCount
GetConsoleAliasesA
EscapeCommFunction
ReadConsoleW
FormatMessageA
TlsSetValue
GetVolumePathNameW
FindResourceExA
ReadConsoleInputA
GetSystemWindowsDirectoryA
FindNextVolumeW
GetCompressedFileSizeA
GetACP
ReleaseSemaphore
ReplaceFileA
GetStringTypeExA
InterlockedExchange
GetProfileIntA
SetCurrentDirectoryA
OpenMutexW
GetCurrentDirectoryW
SetLastError
GetProcAddress
BeginUpdateResourceW
CopyFileA
LoadLibraryA
WriteConsoleA
BeginUpdateResourceA
GetWindowsDirectoryW
GetCurrentProcessId
KERNEL32.dll
GetClipboardOwner
SetCaretPos
DdeQueryStringA
GetSysColorBrush
LoadMenuW
CharUpperBuffA
LoadMenuA
CharToOemBuffA
USER32.dll
InitializeAcl
ADVAPI32.dll
InterlockedIncrement
InterlockedDecrement
InitializeCriticalSection
DeleteCriticalSection
EnterCriticalSection
LeaveCriticalSection
MultiByteToWideChar
ExitProcess
GetCommandLineA
GetStartupInfoA
UnhandledExceptionFilter
SetUnhandledExceptionFilter
GetLastError
HeapFree
RtlUnwind
RaiseException
HeapAlloc
GetCPInfo
GetOEMCP
IsValidCodePage
TlsGetValue
TlsAlloc
TlsFree
GetCurrentThreadId
TerminateProcess
GetCurrentProcess
IsDebuggerPresent
WriteFile
GetStdHandle
GetModuleFileNameA
InitializeCriticalSectionAndSpinCount
FreeEnvironmentStringsA
GetEnvironmentStrings
FreeEnvironmentStringsW
WideCharToMultiByte
GetEnvironmentStringsW
SetHandleCount
GetFileType
HeapCreate
VirtualFree
QueryPerformanceCounter
GetSystemTimeAsFileTime
HeapSize
VirtualAlloc
HeapReAlloc
GetLocaleInfoA
GetStringTypeA
GetStringTypeW
LCMapStringA
LCMapStringW
GetConsoleCP
GetConsoleMode
FlushFileBuffers
SetFilePointer
CloseHandle
GetConsoleOutputCP
WriteConsoleW
SetStdHandle
CreateFileA
Copyright (c) 1992-2004 by P.J. Plauger, licensed by Dinkumware, Ltd. ALL RIGHTS RESERVED.
.?AVtype_info@@
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
.?AVbad_exception@std@@
.?AVexception@std@@
BPpG%h
tk=,G@
kkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkM
Rkkkkkkkkkkk
fffffffffffffffffffffffffffffffff
Rkkkkkkkkkf
0&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&
kkkkkkkff?
zzzzzzzzzzzzzzzzz
kkkkkf
GGGGGGGGGGGG
kkkkkM?0&f
GGGGGGGGGGG
+GGGGGGGGGG
gHGGGGGGGGGG
GGGGGGGGG
GGGGGGGG
+GGGGGG)
GGG)GG
bbbb!gQ
&&&&&&&'g
ggggggggg
|gggggggg
![[[[[[[[
GrGrrrrrrrrGG1g
GrrrGrGrrrrr
ZGGGrGGGGGGrrGrGrGr
Mkkkkk
F#GGGGGGGrGGGGGGGGG
________3_
F#sGGGGGGGGGGGGGGGG
??fkkkkkk
F#GGGsGGGGGGGGGGGGAg{
+sGsGsG
kkkkkkkkk
sGGGGGGGGGGGGGG
kkkkkkkkk
GsGGGsGGGGGGGGrUg^
Scccccccc
kkkkkkkkk
GGGGGGGGGGGGGG
kkkkkkkkkk
GGsGGsGGGGGGG+-g
I"{g\kkkkkkkkkkkkkkkkkkkkkk
gkkkkkkkkkkkkkkkkkkkkkkk
qqqqqqN
gkkkkkkkkkkkkkkkkkkkkkkkkkR
gg4kkkkkkkkkkkkkkkkkkkkkkkkkkk?
kkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkk
----------------------
==========
=======h
=======h
u======h
PPmmmm
=====hY-
------zz
===========
========
r#-----
--------
GZZZZZ
nn~SS@''''''''
nS@@E'
iiiii~
aaaaaaa3
niibiiib@
naiibib
ZZZZZZZZZZZ
/ZZZZZZZZZZZZG
:ZZZZZZZZZZZZZZZZZZZZZ
ZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZ
VVVFFFFFF
ggxRmm
Kg6Rmm`3F
mm?$3G
>mmmm_vvvv
kmmmmmmmmm
mmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmm
}||||~
~zz|zz
{~~{|}
y}{yz{
z{}{{}z||
z|~~}{
y|{{}|
~~~}{z}}
|~~|}|
}{zz~||
~||z{~
e<zL<Qzzzz
3Y`$E`
$t`DOm
J J JpJpp
____k{%{{S%b
aaaaaaa
NNNNNNNNNNN
NNNNNNNNNNN
NNNNNNNNNNN
NNNNNNNNNNN(#x
-NNNNNNNNNNNoR
NNNNNNNNNNNla
YNNNNNNNNNNNoa
pNNNNNNNNNNNSa
TpNNNNNNNNNNN
_NNNNNNNNNNN
_NNNNNNNNNNN
NNNNNNNNNNNo
T+NNNNNNNNNNNS
!NNNNNNNNNNNo
xNNNNNNNNNNNoh
T!NNNNNNNNNNNz&eV
+NNNNNNNNNNNAP
xNNNNNNNNNNN
xNNNNNNNNNNN2
S+NNNNNNNNNNN9k
99MMjy
l+NNNNNNNNNNNs
+NNNNNNNNNNN
NNNNNNNNNNNl
'+NNNNNNNNNNN
"NNNNNNNNNNN
NNNNNNNNNNN1
NNNNNNNNNNNNNNNNNN
UNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNN
iiiiiiii
iiiiiiii
iiiiii
iiiiii
iiiiiiiii
iiiiiiiiii
iiiiiiii
iiiiiii
iiiiiiiii

2T2X2\2t2x2h:l:p:t:
: :$:(:,:0:4:8:<:@:D:H:L:P:T:X:\:`:d:h:l:p:t:x:|:
; ;$;(;,;0;4;<?@?H?L?P?T?
0$0(080<0@0H0`0p0t0|0
2#2S2s2}2
353A3L3R3
4$424c4i4v4
5 5'5-545;5B5I5O5V5\5c5h5|5
6#646Y6b6h6m6s6y6
7!777?7R7X7^7d7r7
82888>8h8
9)9/9R9]9g9n9s9{9
:2:O:e:u:
;/<7<L<W<
<,=R=Z=
=(>C>I>R>Y>{>
??&?1?:?P?[?u?
%0*050:0X0
1#1H1\1n1u1{1
6W7o7t7
4"4,4?4c4
7*7C7_7h7n7w7|7
81888L8S8z8
9"9.9<9B9N9T9a9k9r9
:K:Q:{:
<.<3<;<A<H<N<U<[<c<j<o<w<
=&=,=9=Y=_={=
>">2>9>H>T>a>
?,?5?Y?
1b1<2D2\2t2
4C4a4h4l4p4t4x4|4
4F5Q5l5s5x5|5
6 6j6p6t6x6|6
9"9B9G9/:f:~:
;3;X;};
<><L<R<u<|<
0l1q1v1{1
2Y2^2e2j2q2v2
8!8,8C8O8\8c8
8.9G9U9i9
:!:a:k:
<#<+<7<[<c<
< =)=5=N=
>O>h>o>w>|>
?^?d?h?l?p?
4,474=4C4H4Q4n4t4
5%5+5<5
5=9I9|9
9"9)90979?9G9O9[9d9i9o9y9
>+>2>b>
)0;0H0T0^0f0q0
4.4:4a4n4s4
=+=1=@=F=U=[=i=r=
>W>^>d>
,020V0y0
1E2_2h2
3G3T334B435
0070`0
0d1r1z1
2)3d3t3
5$5*5/555<5N5@6
9#9/999C9M9p9
:8:X:x:
;$;(;D;H;d;h;
<,<0<@<d<p<x<
=(=H=h=t=
>0>P>X>l>
0t0x0|0
8 8$8(8,80888<8H8P8
;$;,;4;<;D;L;T;\;d;l;t;|;
<P=`=d=h=l=p=t=x=|=
> >(>,>0>4>8><>@>D>H>L>X>
mscoree.dll
KERNEL32.DLL
(null)
((((( H
h(((( H
H
dohitolafiviwopadalufujabolezetitujomoxa
hevelocahevepago
saweses
kernel32.dll
kicidaladuxudewenusekamexokegasonupofuzuxijadupob
seluluwigocobimoxinasutusifawek
@jjjjj
/ P6pL
,/KPip
/-P?pR
/ P6pL
,/KPip
/-P?pR
/ P6pL
,/KPip
/-P?pR
/ P6pL
,/KPip
/-P?pR
/ P6pL
,/KPip
/-P?pR
/ P6pL
,/KPip
/-P?pR
VS_VERSION_INFO
StringFileInfo
043831F1
InternalName
Carina
FileDescription
CastroPlan
ProductsVersion
1.0.2.1
ProductName
GoldenEaring
ProductionVersion
60.1.81.50
VarFileInfo
Translation
+Fabuf rarozituh yejar nese boteyehusoci nit
HawubaMFupodizari buwesubaxil sabahogi sofia limarodewoma loxa xape tasubo hobulizoh7Zac vagutasidaduy tujujeri catuwovedutobu vohiyipenirus
ZusikDemuk gunal ruwovazadu wapowuye
Zukixo8Gop yoj zogubovaxifa xefuhe cegifodiwel daxapugu pulerel
Leva bagetujukexana kasahoGFuhowudige zid yidejino livive xetesovenuvule royekayixejizul tivakedef<Kofi gujej videnelikaje yadegumu riyosol gufasoney xonojoziz
=Mameg cuhu rinavezokuxere komavajerususo vipa hose buye rutek
)Bebojolilohoz xokogokimoyic cam sopatekuy9Hiyatinekigan xini yeyisodowi covebu bada vopeleraco tuce
9Yezasoferuwapo lapi ketuhikodaz lidi nawesococ fegu nonix
Antivirus Signature
Bkav W32.AIDetectMalware
Lionic Trojan.Win32.Stealerc.4!c
tehtris Generic.Malware
MicroWorld-eScan Gen:Variant.Zusy.474722
FireEye Generic.mg.2bc310d6ebdae84c
CAT-QuickHeal Clean
McAfee Artemis!2BC310D6EBDA
Cylance unsafe
VIPRE Gen:Variant.Zusy.474722
Sangfor Trojan.Win32.Save.a
K7AntiVirus Trojan ( 0056f9be1 )
BitDefender Gen:Variant.Zusy.474722
K7GW Trojan ( 0056f9be1 )
Cybereason malicious.c168aa
Baidu Clean
VirIT Clean
Cyren Clean
Symantec ML.Attribute.HighConfidence
Elastic malicious (high confidence)
ESET-NOD32 a variant of Win32/Kryptik.HTYF
APEX Malicious
Paloalto Clean
ClamAV Win.Packer.pkr_ce1a-9980177-0
Kaspersky HEUR:Trojan-PSW.Win32.Stealerc.gen
Alibaba Malware:Win32/km_24af8.None
NANO-Antivirus Clean
ViRobot Clean
Rising Trojan.Kryptik!1.B663 (CLASSIC)
Sophos Mal/Generic-S
F-Secure Heuristic.HEUR/AGEN.1312674
DrWeb Clean
Zillya Clean
TrendMicro Trojan.Win32.GCLEANER.YXDF3Z
McAfee-GW-Edition BehavesLike.Win32.Lockbit.gh
Trapmine malicious.moderate.ml.score
CMC Clean
Emsisoft Gen:Variant.Zusy.474722 (B)
SentinelOne Static AI - Malicious PE
GData Gen:Variant.Zusy.474722
Jiangmin Clean
Webroot Clean
Google Detected
Avira HEUR/AGEN.1312674
MAX malware (ai score=89)
Antiy-AVL Clean
Gridinsoft Ransom.Win32.STOP.dg!n
Xcitium Clean
Arcabit Trojan.Zusy.D73E62
SUPERAntiSpyware Clean
ZoneAlarm HEUR:Trojan-PSW.Win32.Stealerc.gen
Microsoft Trojan:Win32/Vidar.RDH!MTB
Cynet Malicious (score: 100)
AhnLab-V3 Trojan/Win.Vidar.R589224
Acronis suspicious
BitDefenderTheta Clean
ALYac Gen:Variant.Zusy.474722
TACHYON Clean
DeepInstinct MALICIOUS
VBA32 Trojan.Buzus
Malwarebytes Trojan.MalPack.GS
Panda Trj/Chgt.AD
Zoner Clean
TrendMicro-HouseCall Trojan.Win32.GCLEANER.YXDF3Z
Tencent Clean
Yandex Clean
Ikarus Trojan-Spy.MSIL.Agent
MaxSecure Trojan.Malware.300983.susgen
Fortinet W32/GenKryptik.GLHP!tr
AVG Win32:CrypterX-gen [Trj]
Avast Win32:CrypterX-gen [Trj]
CrowdStrike win/malicious_confidence_100% (W)
No IRMA results available.