Static | ZeroBOX

PE Compile Time

2022-10-04 05:18:24

PDB Path

C:\hib\pefelunuvejas\zay.pdb

PE Imphash

37146ea85ae0b616e18a34bdbcaf2cf8

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x00021036 0x00021200 7.67699448644
.data 0x00023000 0x013a843c 0x0000b400 0.327709378053
.rsrc 0x013cc000 0x00015300 0x00015400 4.36088208843
.reloc 0x013e2000 0x00009624 0x00009800 0.798910244283

Resources

Name Offset Size Language Sub-language File type
RT_CURSOR 0x013e0628 0x00000568 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_CURSOR 0x013e0628 0x00000568 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_CURSOR 0x013e0628 0x00000568 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x013de9f8 0x00000468 LANG_PORTUGUESE SUBLANG_PORTUGUESE_BRAZILIAN GLS_BINARY_LSB_FIRST
RT_ICON 0x013de9f8 0x00000468 LANG_PORTUGUESE SUBLANG_PORTUGUESE_BRAZILIAN GLS_BINARY_LSB_FIRST
RT_ICON 0x013de9f8 0x00000468 LANG_PORTUGUESE SUBLANG_PORTUGUESE_BRAZILIAN GLS_BINARY_LSB_FIRST
RT_ICON 0x013de9f8 0x00000468 LANG_PORTUGUESE SUBLANG_PORTUGUESE_BRAZILIAN GLS_BINARY_LSB_FIRST
RT_ICON 0x013de9f8 0x00000468 LANG_PORTUGUESE SUBLANG_PORTUGUESE_BRAZILIAN GLS_BINARY_LSB_FIRST
RT_ICON 0x013de9f8 0x00000468 LANG_PORTUGUESE SUBLANG_PORTUGUESE_BRAZILIAN GLS_BINARY_LSB_FIRST
RT_ICON 0x013de9f8 0x00000468 LANG_PORTUGUESE SUBLANG_PORTUGUESE_BRAZILIAN GLS_BINARY_LSB_FIRST
RT_ICON 0x013de9f8 0x00000468 LANG_PORTUGUESE SUBLANG_PORTUGUESE_BRAZILIAN GLS_BINARY_LSB_FIRST
RT_ICON 0x013de9f8 0x00000468 LANG_PORTUGUESE SUBLANG_PORTUGUESE_BRAZILIAN GLS_BINARY_LSB_FIRST
RT_ICON 0x013de9f8 0x00000468 LANG_PORTUGUESE SUBLANG_PORTUGUESE_BRAZILIAN GLS_BINARY_LSB_FIRST
RT_ICON 0x013de9f8 0x00000468 LANG_PORTUGUESE SUBLANG_PORTUGUESE_BRAZILIAN GLS_BINARY_LSB_FIRST
RT_ICON 0x013de9f8 0x00000468 LANG_PORTUGUESE SUBLANG_PORTUGUESE_BRAZILIAN GLS_BINARY_LSB_FIRST
RT_ICON 0x013de9f8 0x00000468 LANG_PORTUGUESE SUBLANG_PORTUGUESE_BRAZILIAN GLS_BINARY_LSB_FIRST
RT_ICON 0x013de9f8 0x00000468 LANG_PORTUGUESE SUBLANG_PORTUGUESE_BRAZILIAN GLS_BINARY_LSB_FIRST
RT_ICON 0x013de9f8 0x00000468 LANG_PORTUGUESE SUBLANG_PORTUGUESE_BRAZILIAN GLS_BINARY_LSB_FIRST
RT_ICON 0x013de9f8 0x00000468 LANG_PORTUGUESE SUBLANG_PORTUGUESE_BRAZILIAN GLS_BINARY_LSB_FIRST
RT_ICON 0x013de9f8 0x00000468 LANG_PORTUGUESE SUBLANG_PORTUGUESE_BRAZILIAN GLS_BINARY_LSB_FIRST
RT_ICON 0x013de9f8 0x00000468 LANG_PORTUGUESE SUBLANG_PORTUGUESE_BRAZILIAN GLS_BINARY_LSB_FIRST
RT_ICON 0x013de9f8 0x00000468 LANG_PORTUGUESE SUBLANG_PORTUGUESE_BRAZILIAN GLS_BINARY_LSB_FIRST
RT_ICON 0x013de9f8 0x00000468 LANG_PORTUGUESE SUBLANG_PORTUGUESE_BRAZILIAN GLS_BINARY_LSB_FIRST
RT_ICON 0x013de9f8 0x00000468 LANG_PORTUGUESE SUBLANG_PORTUGUESE_BRAZILIAN GLS_BINARY_LSB_FIRST
RT_ICON 0x013de9f8 0x00000468 LANG_PORTUGUESE SUBLANG_PORTUGUESE_BRAZILIAN GLS_BINARY_LSB_FIRST
RT_STRING 0x013e1178 0x00000186 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_STRING 0x013e1178 0x00000186 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_GROUP_CURSOR 0x013e0b90 0x00000030 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_GROUP_ICON 0x013dee60 0x00000076 LANG_PORTUGUESE SUBLANG_PORTUGUESE_BRAZILIAN data
RT_GROUP_ICON 0x013dee60 0x00000076 LANG_PORTUGUESE SUBLANG_PORTUGUESE_BRAZILIAN data
RT_GROUP_ICON 0x013dee60 0x00000076 LANG_PORTUGUESE SUBLANG_PORTUGUESE_BRAZILIAN data
RT_VERSION 0x013e0bc0 0x0000020c LANG_NEUTRAL SUBLANG_NEUTRAL data

Imports

Library KERNEL32.dll:
0x401010 SetLocaleInfoA
0x401014 EnumCalendarInfoA
0x401018 VirtualQuery
0x40101c GetProfileIntW
0x401020 FindResourceExW
0x401028 ReadConsoleA
0x40102c UnlockFile
0x401030 SetCommBreak
0x401034 GetModuleHandleW
0x401038 GetTickCount
0x40103c FormatMessageA
0x401044 ClearCommBreak
0x401048 GetDateFormatA
0x40104c TlsSetValue
0x401050 GlobalAlloc
0x401054 CopyFileW
0x40105c GetStringTypeExW
0x401060 FindNextVolumeW
0x401064 ReplaceFileW
0x401068 GetVolumePathNameA
0x40106c GetDevicePowerState
0x401070 ReleaseSemaphore
0x40107c OpenMutexW
0x401084 SetLastError
0x401088 GetProcAddress
0x40108c GetLongPathNameA
0x401094 EnumDateFormatsExA
0x40109c LoadLibraryA
0x4010a0 CreateHardLinkW
0x4010ac ReadConsoleInputW
0x4010b4 CloseHandle
0x4010b8 CreateFileA
0x4010bc FlushFileBuffers
0x4010c0 WriteConsoleW
0x4010c4 GetConsoleOutputCP
0x4010c8 WriteConsoleA
0x4010cc SetupComm
0x4010d0 CreateMutexW
0x4010d4 GetConsoleAliasesW
0x4010d8 SetStdHandle
0x4010e4 Sleep
0x401100 GetLastError
0x401104 HeapFree
0x401108 MultiByteToWideChar
0x40110c ExitProcess
0x401110 GetCommandLineA
0x401114 GetStartupInfoA
0x401118 RtlUnwind
0x40111c RaiseException
0x401120 WriteFile
0x401124 GetStdHandle
0x401128 GetModuleFileNameA
0x40112c TerminateProcess
0x401130 GetCurrentProcess
0x401134 IsDebuggerPresent
0x401138 HeapAlloc
0x40113c HeapCreate
0x401140 VirtualFree
0x401144 VirtualAlloc
0x401148 HeapReAlloc
0x40114c GetCPInfo
0x401150 GetACP
0x401154 GetOEMCP
0x401158 IsValidCodePage
0x40115c TlsGetValue
0x401160 TlsAlloc
0x401164 TlsFree
0x401168 GetCurrentThreadId
0x40117c WideCharToMultiByte
0x401184 SetHandleCount
0x401188 GetFileType
0x401190 GetCurrentProcessId
0x401198 HeapSize
0x40119c GetLocaleInfoA
0x4011a0 GetStringTypeA
0x4011a4 GetStringTypeW
0x4011a8 SetFilePointer
0x4011ac GetConsoleCP
0x4011b0 GetConsoleMode
0x4011b4 LCMapStringA
0x4011b8 LCMapStringW
Library USER32.dll:
0x4011c0 SetCaretPos
0x4011c4 CharToOemBuffA
0x4011cc GetMenuBarInfo
0x4011d0 LoadMenuA
0x4011d4 CharUpperBuffA
0x4011d8 DdeQueryStringA
Library GDI32.dll:
0x401008 GetCharABCWidthsI
Library ADVAPI32.dll:
0x401000 InitializeAcl
Library WINHTTP.dll:
0x4011e0 WinHttpReadData

!This program cannot be run in DOS mode.
RRichKR
`.data
@.reloc
bad allocation
Unknown exception
CorExitProcess
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
runtime error
TLOSS error
SING error
DOMAIN error
An application has made an attempt to load the C runtime library incorrectly.
Please contact the application's support team for more information.
- Attempt to use MSIL code from this assembly during native code initialization
This indicates a bug in your application. It is most likely the result of calling an MSIL-compiled (/clr) function from a native constructor or from DllMain.
- not enough space for locale information
- Attempt to initialize the CRT more than once.
This indicates a bug in your application.
- CRT not initialized
- unable to initialize heap
- not enough space for lowio initialization
- not enough space for stdio initialization
- pure virtual function call
- not enough space for _onexit/atexit table
- unable to open console device
- unexpected heap error
- unexpected multithread lock error
- not enough space for thread data
This application has requested the Runtime to terminate it in an unusual way.
Please contact the application's support team for more information.
- not enough space for environment
- not enough space for arguments
- floating point support not loaded
Microsoft Visual C++ Runtime Library
<program name unknown>
Runtime Error!
Program:
(null)
`h````
xpxxxx
EncodePointer
DecodePointer
FlsFree
FlsSetValue
FlsGetValue
FlsAlloc
bad exception
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
HH:mm:ss
dddd, MMMM dd, yyyy
MM/dd/yy
December
November
October
September
August
February
January
Saturday
Friday
Thursday
Wednesday
Tuesday
Monday
Sunday
GetProcessWindowStation
GetUserObjectInformationA
GetLastActivePopup
GetActiveWindow
MessageBoxA
USER32.DLL
`h`hhh
xppwpp
Complete Object Locator'
Class Hierarchy Descriptor'
Base Class Array'
Base Class Descriptor at (
Type Descriptor'
`local static thread guard'
`managed vector copy constructor iterator'
`vector vbase copy constructor iterator'
`vector copy constructor iterator'
`dynamic atexit destructor for '
`dynamic initializer for '
`eh vector vbase copy constructor iterator'
`eh vector copy constructor iterator'
`managed vector destructor iterator'
`managed vector constructor iterator'
`placement delete[] closure'
`placement delete closure'
`omni callsig'
delete[]
new[]
`local vftable constructor closure'
`local vftable'
`udt returning'
`copy constructor closure'
`eh vector vbase constructor iterator'
`eh vector destructor iterator'
`eh vector constructor iterator'
`virtual displacement map'
`vector vbase constructor iterator'
`vector destructor iterator'
`vector constructor iterator'
`scalar deleting destructor'
`default constructor closure'
`vector deleting destructor'
`vbase destructor'
`string'
`local static guard'
`typeof'
`vcall'
`vbtable'
`vftable'
operator
delete
__unaligned
__restrict
__ptr64
__clrcall
__fastcall
__thiscall
__stdcall
__pascal
__cdecl
__based(
SunMonTueWedThuFriSat
JanFebMarAprMayJunJulAugSepOctNovDec
CONOUT$
bad allocation
dihegegifayadekevisisebes
popanuhegelemi
cajibe
dubuyozatukopegorelevikorucubefu
kernel32.dll
bad exception
%s %f %c
msimg32.dll
C:\hib\pefelunuvejas\zay.pdb
D$ 1D$
D$`PSS
D$ 1D$
T$$RPPf
QQSVWd
to=(>B
0SSSSS
0A@@Ju
>=Yt1j
j@j ^V
HtHu4j
s[S;7|G;w
tR99u2
v$;5L>B
0SSSSS
PPPPPPPP
0SSSSS
PPPPPPPP
URPQQh
t"SS9]
;t$,v-
UQPXY]Y[
t+WWVPV
b7`F",
B'lx>j
GM{%2^
J_9bdqk7*
vj>mRM
_zWYa5
e85Jfy
L~gC2O
5T?Ah*m
\PGA:
u00vEq#
X"|}lR
=%:0=${
aD^&gL
K0t)w"1
2*,0iT7
m`-69Wg
E/g<3#
7V5x[FCu
\K37|Si"
z3]CGi
(NKhZm
X\[=vi
\LW'$/
t#L/ u9O
NT~q-hX
eB"@|xF
H<%~4U
=&j0u5
-I'_)6
ip>OI$v
a1Xc0#
i>}2<w+
~:Dh_v
?%f+2TiS
u5":lE
%'=s.B:
pXrt*|
8b4FMU
0LW}{y
7sRB|#lp
hyOVsk
xE6]T9$
MS)e52*
X.9jsz
z3NKkR
q}beIU
\Nh0GK
cy(<XS*f7
X>`:5^$!04/
B0Tda%
=^^^+1H
5n]/w*
}byQ||
Kpz`w1
kS;:-+
n]8|aM
r^F 6u
+"p]Ui!
bi6mR]
u_YU3G
PKG:rO
2;VnZa
g-.]{^
*4([]c
YGR_.v
JVCNNWg,
|!yQ;=>
4T_H;z
+fOKoi
3+NA-;
(!o#Dq
M/O/1j
-BT}pzn
3CUMu6
ej:q3[Y
k3ud2\?)YK
f= J!7|E
]>QoRR
((b^KL
-wOCN#
j"("%K\
.lc.,8
x&|(Q|
q)B?^g
<;a{}q
;WB@gQ
f5H=Iu
1~~+&X
N5bb~T
Vp7lb+
:k3W=k:
#3:qa1
>wi=dF
NO>e.b>
u(x@h:1
_<#3PU
v5<jVl
3Nf:`-tC4
G08Tv5\U0
fM_ZsM
\67p*3
lR,>AE
.ED,.#
,rF/MO
cVH-J}:>
5^P! n
Z+BG(y
t j^|K
fe64(R
htJ^}u
)D>;{{x
((L'UTQ
ODSjAp
2l8{:v
r~;z)"
jzy#eMF
LAsD)u
9=zy5u
*Y;yUd
,;Y|!U
ip&%a=
lVE4go
<+=Y!G
[?xU{r:G
O|}Gx&
W~FZ6"
rM+aC6l
$zvEcv
d=g1c*
E=i#Y!<+
Suiwg;
SetupComm
CreateMutexW
SetLocaleInfoA
EnumCalendarInfoA
VirtualQuery
GetProfileIntW
FindResourceExW
DeleteVolumeMountPointA
ReadConsoleA
UnlockFile
SetCommBreak
GetModuleHandleW
GetTickCount
FormatMessageA
GetCompressedFileSizeW
ClearCommBreak
GetDateFormatA
TlsSetValue
GlobalAlloc
CopyFileW
GetSystemWindowsDirectoryA
GetStringTypeExW
FindNextVolumeW
ReplaceFileW
GetVolumePathNameA
GetDevicePowerState
ReleaseSemaphore
GetConsoleAliasesW
SetCurrentDirectoryA
GetLogicalDriveStringsA
OpenMutexW
GetCurrentDirectoryW
SetLastError
GetProcAddress
GetLongPathNameA
BeginUpdateResourceW
EnumDateFormatsExA
CreateMemoryResourceNotification
LoadLibraryA
CreateHardLinkW
BeginUpdateResourceA
SetProcessWorkingSetSize
ReadConsoleInputW
GetWindowsDirectoryW
KERNEL32.dll
SetCaretPos
DdeQueryStringA
CharUpperBuffA
LoadMenuA
GetMenuBarInfo
DdeCreateStringHandleA
CharToOemBuffA
USER32.dll
GetCharABCWidthsI
GDI32.dll
InitializeAcl
ADVAPI32.dll
WinHttpReadData
WINHTTP.dll
InterlockedIncrement
InterlockedDecrement
InitializeCriticalSection
DeleteCriticalSection
EnterCriticalSection
LeaveCriticalSection
UnhandledExceptionFilter
SetUnhandledExceptionFilter
GetLastError
HeapFree
MultiByteToWideChar
ExitProcess
GetCommandLineA
GetStartupInfoA
RtlUnwind
RaiseException
WriteFile
GetStdHandle
GetModuleFileNameA
TerminateProcess
GetCurrentProcess
IsDebuggerPresent
HeapAlloc
HeapCreate
VirtualFree
VirtualAlloc
HeapReAlloc
GetCPInfo
GetACP
GetOEMCP
IsValidCodePage
TlsGetValue
TlsAlloc
TlsFree
GetCurrentThreadId
InitializeCriticalSectionAndSpinCount
FreeEnvironmentStringsA
GetEnvironmentStrings
FreeEnvironmentStringsW
WideCharToMultiByte
GetEnvironmentStringsW
SetHandleCount
GetFileType
QueryPerformanceCounter
GetCurrentProcessId
GetSystemTimeAsFileTime
HeapSize
GetLocaleInfoA
GetStringTypeA
GetStringTypeW
SetFilePointer
GetConsoleCP
GetConsoleMode
LCMapStringA
LCMapStringW
SetStdHandle
WriteConsoleA
GetConsoleOutputCP
WriteConsoleW
FlushFileBuffers
CreateFileA
CloseHandle
Copyright (c) 1992-2004 by P.J. Plauger, licensed by Dinkumware, Ltd. ALL RIGHTS RESERVED.
.?AVtype_info@@
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
.?AVbad_exception@std@@
.?AVexception@std@@
rrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrr
rrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrr
rrrrrrrrrrrrrrrrr
rrrrrrrrr
rrrrrrrrrrrrrr
rrrrrrrrrrrrr
rrrrrrrrrr
rrrrrrrrrK
rrrrrr
rrrrrr_
rrrrrr]
Crrrrrrr
rrrrrrr_>
rrrrrrr
rrrrrrr
}rrrrrrri
rrrrrrrrr
rrrrrrrrr
hT0T#Hu
irrrrrrrrrr
rrrrrrrrrrrrr}
IXYrrrrrrrrrrrrrr
jrrrrrrrrrrrrrrr
rrrrrrrrrrrrrrr
rrrrrrrrrrrrrrrrr
rrrrrrrrrrrrrrrrr
rrrrrrrrrrrrrrrr
rrrrrrrrrrrrrrrrrr
rrrrrrrrrrrrrrrrrrr
rrrrrrrrrrrrrrrrrrrrrr>e9
rrrrrrrrrrrrrrrrrrrrrr
rrrrrrrrrrrrrrrrrrrrr
rrrrrrrrrrrrrrrrrrrrr
rrrrrrrrrrrrrrrrrrrrr
rrrrrrrrrrrrrrrrrrrrr
}rrrrrrrrrrrrrrrrrrrrrr
rrrrrrrrrrrrrrrrrrrrrrr
}rrrrrrrrrrrrrrrrrrrrrrrrr
}rrrrrrrrrrrrrrrrrrrrrrrrrrr
rrrrrrrrrrrrrrrrrrrrrrrrrrrrrrt
rrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrt
X=irrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrr
&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&4
&&&&&&
=&&&&&&&p
M&&&&&&&
f&&&&&&&&
&&&&&&&&&&
b&&&&&&&&
uuututtttttttttttttttt
Bu||||
g8/f)]o8z
rrrrrx
'>rrrr
8qferrrrr
rrrrrr
rrrrrr
rrrrrr
8g~~6;
Bmmmmm
888888888
88888888
_A_A_AA
881-188
@@@@xBBB
@@@@BB
nb>5@@xxB
$$$$$$$$$$$$$$$
`````V
WWWWWWWW
$``A"$
)L$``$
)L$``$
)L$``$
)L$``$
$``$)$q
$``$)$q
Tw$$$$$w
$$$$$A```$
$$$$$`````$
```````````A
````````````
`````````````````````2```````````````````````````````````````````````````````````````````````````````````````
}}*~~~~~~~~~~}}}}
hhhllllll
t??w<<jjjt
}}Bdltt?
}}}}}}}}}D
a}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}
{{~}}~
{{|}||
{~|y{{{|~
~}~}~}
}|}{}|
~|~|}z~z
~~}}}~
~|~~}{
~}|||~
|||{}{
~{|z}{
~}y~|z~
z~|y}~}|
~|}}}}
~}~z{}
}{z{z~||}
{~}}}~~
~||}~{
{~}z~~
{{{z~~y
z~|~|{
}yzz}}
||{}}z|
{}zy|{~y
}~{|~}
~{zz{}
zz.{cc
Nr,z,{,
Z4ZS2SN
QQ---QQQ--Q-
QJQ~wi80
X$Xf$U$$
33U8^30
BBBBBBB9B
B@9@9@
HHHHHHHHHHH9D
HHHHHHHHHHH6
kHHHHHHHHHHH.
HHHHHHHHHHHhe
HHHHHHHHHHH
uHHHHHHHHHHH
3fHHHHHHHHHHH
HHHHHHHHHHH
HHHHHHHHHHH
HHHHHHHHHHH
HHHHHHHHHHH9
HHHHHHHHHHH
h%u6hT
zHHHHHHHHHHH
<FgHHHHHHHHHHH
HHHHHHHHHHH
gHHHHHHHHHHH
WQzHHHHHHHHHHH
HHHHHHHHHHH
HHHHHHHHHHH<
zHHHHHHHHHHH
zHHHHHHHHHHH
zHHHHHHHHHHH
HHHHHHHHHHH
NzHHHHHHHHHHH~
HHHHHHHHHHH
HHHHHHHHHHH;
HHHHHHHHHHHHHHHHHHMMMM@@@
HHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHH
>B6666661
T66666
66666#]
)I66666%
A66666
5l66666\
66666x
666666
~~~~~~~


2(2,2t2x2|2
H:L:P:T:X:\:`:d:h:l:p:t:x:|:
; ;$;(;,;0;4;8;<;@;D;H;L;P;T;X;\;`;d;h;l;p;t;x;|;
;l=p=x=|=
> >$>,>D>T>X>h>l>p>x>
060<0B0u0
161=1F1M1Y1g1m1z1
1Q2W2o2v2}2
2$313:3?3T3Z3c3i3o3v3}3
484V4r4
5!5f5q5w5}5
6(6:6J6R6l6r6x6
7<7B7b7m7w7
8*808:8I8h8
:(:::N:
;6<><S<^<
=C>L>y>
>+?3?F?Q?V?f?p?w?
?0L0v0{0
0Z1g1t1
1B2G2Q2
<"<3<o<
<#=(=-=2=B=q=
>!>(>->
00G0l0
2/262N2z2
4"5)5B5V5\5e5x5
516Q6_6d6
9/9:9@9F9K9T9q9w9
:(:.:?:
3+4E4T4a4m4}4
555h5w5
8M8Z8d8r8{8
<$<-<3<<<A<P<w<
=?=E=P=\=q=x=
>&>0>7>O>^>e>r>
?@?F?b?z?
1 1(1/141<1E1Q1V1[1a1e1k1p1v1{1
3(3/373<3@3D3m3
4$4(4,404
5M5T5X5\5`5d5h5l5p5
5W8^8r8
1$1:1E1\1h1u1|1
2G2`2n2
223:3z3
5 5D5L5o5x5
7?7X7_7g7l7p7t7
8N8T8X8\8`8
9!9K9}9
7 7&7-747;7B7I7P7W7_7g7o7{7
:$:6:H:Z:
<%<,<6<><K<R<
00$0<0B0Q0W0f0l0z0
1)1h1o1u1
2G3g3W4
='=,=:=
>8>C>f>
/0A0N0Z0d0l0w0
91:K:T:
:7;D;#<2<
= >+>Y>g>v>
2A2K2c2
"?1?;?E?Q?]?g?s?
0 0<0@0H0L0h0
1(1H1h1t1
282X2`2d2|2
3 3<3@3H3P3X3\3d3x3
4 4@4`4
1$1,141<1D1L1T1\1d1l1t1
:(<8<H<X<h<
<P=`=d=h=l=p=t=x=|=
> >(>,>0>4>8><>@>D>H>L>X>
mscoree.dll
(null)
KERNEL32.DLL
((((( H
h(((( H
H
pahelufozapobavicijuvotavuko
kernel32.dll
lselihuwaham
@jjjjj
jjjjjj
/ P6pL
,/KPip
/-P?pR
/ P6pL
,/KPip
/-P?pR
/ P6pL
,/KPip
/-P?pR
VS_VERSION_INFO
StringFileInfo
043831F1
InternalName
Polonez
FileDescription
GastroPlan
ProductsVersion
36.48.65.92
ProductName
GoldenEaring
ProductionVersion
60.1.81.50
VarFileInfo
Translation
Cotarax
Puzihehoreposil hozecubalomala=Ceriluxeva luvubobiyeto salediguzihic zojaniso wicotolax gazu-Zayukupexehojo cuzayowovavutu kijolitadiwedez
Xibivefeyo
RuhuficHoyohajitulexu teged wanaravogu xolazuc gosohuzejil racatihuwozodiv hivodidujorijib sacitixemaduguzAVutimuk bebibako nowelasujagub sabobahubetolus potolimomada cezug<Rowox devesoxof bofimem sebe kobocobeke baxopujeya rul xepam
Vutefu sorobozeh"Yesulefixew kidicehive lajuhekawuy
Paro misohekexepob
0Tutifesexurilib talekoneso pixufuyawukoy hicudamVFixocoruvetuw diru gayepikuh tixuvujuwajelu zowo wojilire nivahuvoji zibi hunihobecige
-Togiwucigup ciwoxenix girihece wapi munifizub
Antivirus Signature
Bkav W32.AIDetectMalware
Lionic Clean
tehtris Generic.Malware
DrWeb Clean
Cynet Malicious (score: 100)
CMC Clean
CAT-QuickHeal Clean
ALYac Clean
Cylance unsafe
Zillya Clean
Sangfor Trojan.Win32.Save.a
K7AntiVirus Trojan ( 005690671 )
BitDefender Clean
K7GW Trojan ( 005690671 )
Cybereason malicious.383c9f
BitDefenderTheta Clean
VirIT Clean
Cyren W32/Kryptik.KCL.gen!Eldorado
Symantec ML.Attribute.HighConfidence
Elastic malicious (high confidence)
ESET-NOD32 Clean
APEX Malicious
Paloalto Clean
ClamAV Win.Packer.pkr_ce1a-9980177-0
Kaspersky UDS:DangerousObject.Multi.Generic
Alibaba Clean
NANO-Antivirus Clean
SUPERAntiSpyware Clean
MicroWorld-eScan Clean
Rising Trojan.Kryptik!1.B663 (CLASSIC)
Ad-Aware Clean
Sophos ML/PE-A
F-Secure Clean
Baidu Clean
VIPRE Clean
TrendMicro Clean
McAfee-GW-Edition BehavesLike.Win32.Lockbit.fm
Trapmine malicious.high.ml.score
FireEye Generic.mg.6b59056d039c885c
Emsisoft Clean
SentinelOne Static AI - Suspicious PE
Jiangmin Clean
Webroot Clean
Avira Clean
MAX Clean
Antiy-AVL Clean
Microsoft Trojan:Win32/Sabsik.FL.B!ml
Gridinsoft Ransom.Win32.STOP.dg!n
Xcitium Clean
Arcabit Clean
ViRobot Clean
GData Clean
Google Detected
AhnLab-V3 Clean
Acronis suspicious
McAfee Artemis!6B59056D039C
TACHYON Clean
DeepInstinct MALICIOUS
VBA32 Trojan.Buzus
Malwarebytes Clean
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Tencent Trojan.Win32.Obfuscated.gen
Yandex Clean
Ikarus Trojan.Win32.Crypt
MaxSecure Trojan.Malware.300983.susgen
Fortinet W32/GenKryptik.ERHN!tr
AVG Win32:PWSX-gen [Trj]
Avast Win32:PWSX-gen [Trj]
CrowdStrike win/malicious_confidence_100% (W)
No IRMA results available.