Static | ZeroBOX

PE Compile Time

2022-02-08 03:06:02

PDB Path

C:\lilepunivelol.pdb

PE Imphash

4aa773f91d20506f2979a40c36a81664

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x00036cbc 0x00036e00 7.85228782641
.data 0x00038000 0x00040ac0 0x00001800 1.72965797788
.rsrc 0x00079000 0x0000cd18 0x0000ce00 4.45434181979
.reloc 0x00086000 0x00001b1c 0x00001c00 3.28510176089

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x00084f30 0x00000468 LANG_PORTUGUESE SUBLANG_PORTUGUESE_BRAZILIAN GLS_BINARY_LSB_FIRST
RT_ICON 0x00084f30 0x00000468 LANG_PORTUGUESE SUBLANG_PORTUGUESE_BRAZILIAN GLS_BINARY_LSB_FIRST
RT_ICON 0x00084f30 0x00000468 LANG_PORTUGUESE SUBLANG_PORTUGUESE_BRAZILIAN GLS_BINARY_LSB_FIRST
RT_ICON 0x00084f30 0x00000468 LANG_PORTUGUESE SUBLANG_PORTUGUESE_BRAZILIAN GLS_BINARY_LSB_FIRST
RT_ICON 0x00084f30 0x00000468 LANG_PORTUGUESE SUBLANG_PORTUGUESE_BRAZILIAN GLS_BINARY_LSB_FIRST
RT_ICON 0x00084f30 0x00000468 LANG_PORTUGUESE SUBLANG_PORTUGUESE_BRAZILIAN GLS_BINARY_LSB_FIRST
RT_ICON 0x00084f30 0x00000468 LANG_PORTUGUESE SUBLANG_PORTUGUESE_BRAZILIAN GLS_BINARY_LSB_FIRST
RT_ICON 0x00084f30 0x00000468 LANG_PORTUGUESE SUBLANG_PORTUGUESE_BRAZILIAN GLS_BINARY_LSB_FIRST
RT_ICON 0x00084f30 0x00000468 LANG_PORTUGUESE SUBLANG_PORTUGUESE_BRAZILIAN GLS_BINARY_LSB_FIRST
RT_ICON 0x00084f30 0x00000468 LANG_PORTUGUESE SUBLANG_PORTUGUESE_BRAZILIAN GLS_BINARY_LSB_FIRST
RT_ICON 0x00084f30 0x00000468 LANG_PORTUGUESE SUBLANG_PORTUGUESE_BRAZILIAN GLS_BINARY_LSB_FIRST
RT_ICON 0x00084f30 0x00000468 LANG_PORTUGUESE SUBLANG_PORTUGUESE_BRAZILIAN GLS_BINARY_LSB_FIRST
RT_ICON 0x00084f30 0x00000468 LANG_PORTUGUESE SUBLANG_PORTUGUESE_BRAZILIAN GLS_BINARY_LSB_FIRST
RT_ICON 0x00084f30 0x00000468 LANG_PORTUGUESE SUBLANG_PORTUGUESE_BRAZILIAN GLS_BINARY_LSB_FIRST
RT_STRING 0x00085c08 0x0000010c LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_STRING 0x00085c08 0x0000010c LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_GROUP_ICON 0x00085398 0x00000068 LANG_PORTUGUESE SUBLANG_PORTUGUESE_BRAZILIAN data
RT_GROUP_ICON 0x00085398 0x00000068 LANG_PORTUGUESE SUBLANG_PORTUGUESE_BRAZILIAN data
RT_VERSION 0x00085400 0x00000210 LANG_NEUTRAL SUBLANG_NEUTRAL data

Imports

Library KERNEL32.dll:
0x401008 CreateMutexW
0x40100c GetProfileIntW
0x401014 EnumCalendarInfoW
0x401020 UnlockFile
0x401024 GetTickCount
0x401028 GetConsoleAliasesA
0x40102c GetNumberFormatA
0x401034 ClearCommBreak
0x401038 GetDateFormatA
0x40103c GetVolumePathNameW
0x401040 FindResourceExA
0x401044 GlobalAlloc
0x401048 LoadLibraryW
0x40104c ReadConsoleInputA
0x401050 GetStringTypeExW
0x401058 FindNextVolumeW
0x40105c MulDiv
0x401060 GetDevicePowerState
0x401064 ReplaceFileA
0x401068 GetComputerNameA
0x40106c FindFirstFileA
0x401070 OpenMutexW
0x401074 GetLongPathNameW
0x401078 SetLastError
0x40107c lstrcmpiA
0x401080 GetProcAddress
0x401088 EnumDateFormatsExA
0x40108c IsValidCodePage
0x401090 CopyFileA
0x401094 LoadLibraryA
0x401098 CreateFileMappingA
0x40109c CreateHardLinkW
0x4010a4 HeapWalk
0x4010a8 GetModuleHandleA
0x4010ac SetLocaleInfoW
0x4010b4 CloseHandle
0x4010b8 CreateFileA
0x4010bc FlushFileBuffers
0x4010c0 WriteConsoleW
0x4010c8 GetConsoleOutputCP
0x4010cc WriteConsoleA
0x4010d8 MultiByteToWideChar
0x4010dc GetStartupInfoW
0x4010e0 GetModuleHandleW
0x4010e4 Sleep
0x4010e8 ExitProcess
0x4010ec GetLastError
0x4010f0 WriteFile
0x4010f4 GetStdHandle
0x4010f8 GetModuleFileNameA
0x4010fc TerminateProcess
0x401100 GetCurrentProcess
0x401104 IsDebuggerPresent
0x401108 HeapAlloc
0x40110c HeapFree
0x401118 TlsGetValue
0x40111c TlsAlloc
0x401120 TlsSetValue
0x401124 TlsFree
0x40112c GetCurrentThreadId
0x401134 HeapSize
0x401138 GetCPInfo
0x40113c GetACP
0x401140 GetOEMCP
0x401144 GetModuleFileNameW
0x401150 GetCommandLineW
0x401154 SetHandleCount
0x401158 GetFileType
0x40115c GetStartupInfoA
0x401164 HeapCreate
0x401168 VirtualFree
0x401170 GetCurrentProcessId
0x40117c SetFilePointer
0x401180 WideCharToMultiByte
0x401184 GetConsoleCP
0x401188 GetConsoleMode
0x40118c VirtualAlloc
0x401190 HeapReAlloc
0x401194 RtlUnwind
0x401198 LCMapStringA
0x40119c LCMapStringW
0x4011a0 GetStringTypeA
0x4011a4 GetStringTypeW
0x4011a8 GetLocaleInfoA
0x4011ac SetStdHandle
0x4011b0 RaiseException
Library USER32.dll:
0x4011b8 GetClipboardOwner
0x4011bc CharToOemBuffA
0x4011c0 CharUpperBuffW
0x4011c8 GetMenuBarInfo
0x4011cc LoadMenuA
0x4011d0 DdeQueryStringA
Library GDI32.dll:
0x401000 GetCharABCWidthsI
Library WINHTTP.dll:
0x4011d8 WinHttpQueryHeaders

!This program cannot be run in DOS mode.
`.data
@.reloc
bad allocation
Unknown exception
CorExitProcess
runtime error
TLOSS error
SING error
DOMAIN error
An application has made an attempt to load the C runtime library incorrectly.
Please contact the application's support team for more information.
- Attempt to use MSIL code from this assembly during native code initialization
This indicates a bug in your application. It is most likely the result of calling an MSIL-compiled (/clr) function from a native constructor or from DllMain.
- not enough space for locale information
- Attempt to initialize the CRT more than once.
This indicates a bug in your application.
- CRT not initialized
- unable to initialize heap
- not enough space for lowio initialization
- not enough space for stdio initialization
- pure virtual function call
- not enough space for _onexit/atexit table
- unable to open console device
- unexpected heap error
- unexpected multithread lock error
- not enough space for thread data
This application has requested the Runtime to terminate it in an unusual way.
Please contact the application's support team for more information.
- not enough space for environment
- not enough space for arguments
- floating point support not loaded
Microsoft Visual C++ Runtime Library
<program name unknown>
Runtime Error!
Program:
(null)
`h````
xpxxxx
EncodePointer
DecodePointer
FlsFree
FlsSetValue
FlsGetValue
FlsAlloc
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
GetProcessWindowStation
GetUserObjectInformationA
GetLastActivePopup
GetActiveWindow
MessageBoxA
USER32.DLL
`h`hhh
xppwpp
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
HH:mm:ss
dddd, MMMM dd, yyyy
MM/dd/yy
December
November
October
September
August
February
January
Saturday
Friday
Thursday
Wednesday
Tuesday
Monday
Sunday
Complete Object Locator'
Class Hierarchy Descriptor'
Base Class Array'
Base Class Descriptor at (
Type Descriptor'
`local static thread guard'
`managed vector copy constructor iterator'
`vector vbase copy constructor iterator'
`vector copy constructor iterator'
`dynamic atexit destructor for '
`dynamic initializer for '
`eh vector vbase copy constructor iterator'
`eh vector copy constructor iterator'
`managed vector destructor iterator'
`managed vector constructor iterator'
`placement delete[] closure'
`placement delete closure'
`omni callsig'
delete[]
new[]
`local vftable constructor closure'
`local vftable'
`udt returning'
`copy constructor closure'
`eh vector vbase constructor iterator'
`eh vector destructor iterator'
`eh vector constructor iterator'
`virtual displacement map'
`vector vbase constructor iterator'
`vector destructor iterator'
`vector constructor iterator'
`scalar deleting destructor'
`default constructor closure'
`vector deleting destructor'
`vbase destructor'
`string'
`local static guard'
`typeof'
`vcall'
`vbtable'
`vftable'
operator
delete
__unaligned
__restrict
__ptr64
__clrcall
__fastcall
__thiscall
__stdcall
__pascal
__cdecl
__based(
SunMonTueWedThuFriSat
JanFebMarAprMayJunJulAugSepOctNovDec
CONOUT$
bad allocation
rovogosekuruvozejitadunapa paruxayibovunamorohidoper
Gaz moboduboramenofifidijatuk
%s %f %c
kernel32.dll
Kiduhixodom wurof pon
Radifizibo
Cujudowarawu yal misibeko vuhelikosofanuj
yelusup hogay kegeyupahojuwojafinamap wihoweyayuceceze cizetiyegiwixutero
waxiyarosuguyogohijowunaciyoru hocuvamisaguzohu kelixabayobaxucobosi
lahejozanobames notebizosewepoxogafejudiya nilelukejuwuban mejivoginopuhuxuxoyebudaciyahu siv
pufacaduf
msimg32.dll
fajuvurewarecivaxusebezemagoxaja ziwayowu
kezotayuf zokaxebovunijifagutijor
bad exception
RSDS$H
C:\lilepunivelol.pdb
D$ 1D$
D$ 1D$
/SUVWu~
D$$PQQf
j h8mC
0SSSSS
0A@@Ju
>=Yt1j
QQSVWh
jThhnC
j@j ^V
0SSSSS
0SSSSS
URPQQh
t"SS9]
PPPPPPPP
PPPPPPPP
0WWWWW
AAFFf;
;t$,v-
UQPXY]Y[
t+WWVPV
?U*G5/
=no"1&_
*~1Z?
A.WrS(
&&RDj[
"w8Osc
(!xYn`
[36,iwx
NxAj-{>
9XLS#v<
OG[Fn\1
AU^&dM(a
8I}}yO
8j]Q@~k
tm7}wpKSC
D~&`KveY
BG}bwi
=f;:7kx
S,30hZ
ZU8D02
.BTJ7kN
AX|_oS3
Q}@LtR
7L3:;z
'kb-aO
g1G9IWl
7^y_*+b
h7!L5
LpZfl}
~5_cr~
cxVS\{
d=6"li
Y<_nG|1
.Dt}|O
fanX50
;9\7m!vpA~`$x
*'T`?}
+\kXEx
=bbmOU
<E'TjZ"
x;|r~i
Ah@]QPH
`ZFnu y
|J.AAF
v O5Wq
"pY6LC
eEcTi%
eZ{!%m!
$qoY{)
D1%cAJ
!hUul6
XD'rX6
%~|W49ca
&.]#45
I4SMkC
)NB>pWk
Z6 = t
51N$Yp6<n
D_7+~Lt
c*R@|r
Rvh"8GX
(vS$a0
([u*NO
~j%URo
h~1p0%[G
;mBK}EK
*&htC
{q4}*1
_;!;LW
8(Y,D_
tIX]$
VVV.2pAU
v*RU8s
\&}HZ
(gsQ+H7z
\lgwn)O
JcR-Y2
/@ga48s
!kBNSo1
w8gI.r
5pTQM>
wWF;`f
vD@1PlX
FK]xq%
9*3w8Lv
t*MKY$
>h3+^OSPQ
G9*OD w
~_0.O[
ZQ{)Hw/
-<>s/-`
>Oz\nR
^>+0gL
HovnnS
C&U"!L
6s]*{(ruQ
c]satY
sD[ ti
i/Ku@K
ECzPyX
!c1{E9'O
;IwAjA
6ayEZU
<}PC'D{
XH0+W`X
hKOs+g
|8hcx$!
wG8/Lr
|Mab%7
@@PJgw
A;4~Xk
'~%{w<{
H=A>0@
&]Wl|/
P.rbT_
M%1n!.o
.\#pn`
>LJp)>
(gwW#n
$!mvsL,
\8D}gJ
xYwsWQ
P)6:r&0S7
6,Mib'=
pMhyy%
;on;fQR
P;.({=1}
;6 -H-
}{,7UV
Adi[j-
bxvoF:
"N=ih=?
/YUN$?
vhT_o_:*
zQ@:IJ
I}!XH.
^q}46=
ZG`]{E
 -t,:
6d9J:<V
eX~<A/
ggAerH
9XM&M0?
j\VE}C
-iwX]f9
I@t5C0I
56uZDy
a$UdEl(
:mkCXqP
s3)Zil
JmV=KQ
xc2#Pd/
UP$Cak
b6nY^7_W
_Ux{\_]
b\|[v|&
NpNpp7
1?rl=+
T5sD9'{
i\opD*
)'[_!S
~H0!e8
N|0C:x
&fD*!3
`zD?e}
@e-dy)K!
{gx'f(`py
nVY<+C
+CKy}V
e66'4[a
1>1Q?*]'
2oT~lJ
FYID#h1
H7*\*.
a!I$64
4%eY{K3
L4^D 0{M
.*86|~$
(z?;f8
{vKVZ
>YAn0}
Vu/Fgtfl
rj(t1}
5G=r1<j:{
U)rV^6
yLiBUr
#ad~K|
pB65c}<p`3nG
_g*MH0a~
?%BKwm
4<tZ,T
Oc7a4{
phjU)4
8f^(i~#
mk=;s<s
TU.w\i
t*TLQA
G@Q"}K?
XOd/!M
ge/L_|
N5>#fN
nOlr&;
iBB <u1
o|K70i
S_+^&[
9;t)M]
X0VuY5Tg
]xxl)=
:>xabyc
MI'SB&
vLo4"L
4>M~Yb`f
6'q~!a
xENtvP
5}r:X@
XP{jv,
,x_sy8
M>pRlq
=:>%'#
67EwmQ
@lVx{m
QtrX|I
Q5(b%xP
hH0DzBH
Y52&p1o
N @Q[6
ATauMw
> rzJj
@J@O>8M
2lrJM$r(
>-8XP-
$)%zS%
HD-0Z-
Rv;es0aHj
Ss5Uvd
IZ_$Mq
6{wdT~
(Z^iFI
l/f-nA
=De6:n
GcnM82
7_/AA4v
.gZ{a1
5nFtJ.
t>JlE
ZKs}(S8
hPp@E7
H4\lN4S
.&Tt27
v-Ap:,
OnIp)X,
;eJ|K\-
D]n>'4
v|L^VP
:[IRoc
xS-q"F
>pVbD05
'u~`l/
5G1zE4
1a9n>:
A{%z)$
T6r8O!;O
BTQQP4
>y)M9T
FB&dag^
G&pn)S
3L{8pehr
=f.SpF
vHyfSo
[8_>_EuU
\Aa^#{
\AH~@k
3?ny%L
i+79%:,
cFa;f
s,`Z`zv
cY-p-m
^|)#TpQ;
->R&Og'
l(J2R[+z3
#bAsfk
Gy c2Z
C|~J9,
u>7Fj{
2_3}t)
0jy;RE[
YnJ<!F
cGw(g
AR=g{C
qP1Up5+0
a$9{d,
W)Vy+G
*Xa9zwkA
LE\:2B.
'=9=K4
'V<_n
&D&}sp
OaF%;S
4SmyjX
e1'Oyp
s2#hbRuW
$s4I<:LRZ
#j!D{|
m0na26mf
zf$L+2
[t\fm8
EX>!"FT
"n*{R1[
2|w76x9
bghk9l
8D&7[8
!k*RGx
~#j;{[
*/OSI-oX
:4p6"3
:>"m2E
=Q%i{k"d3
QQSVWd
HtHu4j
s[S;7|G;w
tR99u2
GetComputerNameA
CreateMutexW
GetProfileIntW
DeleteVolumeMountPointA
EnumCalendarInfoW
GetLogicalDriveStringsW
GetSystemWindowsDirectoryW
UnlockFile
GetTickCount
GetConsoleAliasesA
GetNumberFormatA
GetCompressedFileSizeW
ClearCommBreak
GetDateFormatA
GetVolumePathNameW
FindResourceExA
GlobalAlloc
LoadLibraryW
ReadConsoleInputA
GetStringTypeExW
EnumSystemCodePagesA
FindNextVolumeW
MulDiv
GetDevicePowerState
ReplaceFileA
SetCurrentDirectoryA
FindFirstFileA
OpenMutexW
GetLongPathNameW
SetLastError
lstrcmpiA
GetProcAddress
BeginUpdateResourceW
EnumDateFormatsExA
IsValidCodePage
CopyFileA
LoadLibraryA
CreateFileMappingA
CreateHardLinkW
SetProcessWorkingSetSize
HeapWalk
GetModuleHandleA
SetLocaleInfoW
GetWindowsDirectoryW
KERNEL32.dll
GetClipboardOwner
DdeQueryStringA
LoadMenuA
GetMenuBarInfo
DdeCreateStringHandleA
CharUpperBuffW
CharToOemBuffA
USER32.dll
GetCharABCWidthsI
GDI32.dll
WinHttpQueryHeaders
WINHTTP.dll
UnhandledExceptionFilter
SetUnhandledExceptionFilter
MultiByteToWideChar
GetStartupInfoW
GetModuleHandleW
ExitProcess
GetLastError
WriteFile
GetStdHandle
GetModuleFileNameA
TerminateProcess
GetCurrentProcess
IsDebuggerPresent
HeapAlloc
HeapFree
EnterCriticalSection
LeaveCriticalSection
TlsGetValue
TlsAlloc
TlsSetValue
TlsFree
InterlockedIncrement
GetCurrentThreadId
InterlockedDecrement
HeapSize
GetCPInfo
GetACP
GetOEMCP
GetModuleFileNameW
FreeEnvironmentStringsW
GetEnvironmentStringsW
GetCommandLineW
SetHandleCount
GetFileType
GetStartupInfoA
DeleteCriticalSection
HeapCreate
VirtualFree
QueryPerformanceCounter
GetCurrentProcessId
GetSystemTimeAsFileTime
InitializeCriticalSectionAndSpinCount
SetFilePointer
WideCharToMultiByte
GetConsoleCP
GetConsoleMode
VirtualAlloc
HeapReAlloc
RtlUnwind
LCMapStringA
LCMapStringW
GetStringTypeA
GetStringTypeW
GetLocaleInfoA
SetStdHandle
WriteConsoleA
GetConsoleOutputCP
WriteConsoleW
FlushFileBuffers
CreateFileA
CloseHandle
RaiseException
.?AVexception@std@@
.?AVtype_info@@
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
.?AVbad_exception@std@@
HHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHH$
HHHHHHHHHHH
HHHHHHHHH
HHHHHHH
[[[jjj
HHHHH$
BBB@P
{{{vP~d<
rrrrrsPPPPPPPPP
yPPPPPPPP
////////
UUUUUUUUUUUUU
9$HHHHH
HHHHHH
HHHHHHHHH
HHHHHHHHH
$5HHHHHHHHH
5HHHHHHHHHH
HHHHHHHHHHHHHHHHHHHHHH
HHHHHHHHHHHHHHHHHHHHHHH
PHHHHHHHHHHHHHHHHHHHHHHHHH
fPP:HHHHHHHHHHHHHHHHHHHHHHHHHHH
HHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHH
(********************(o
TTTT 6E
>e
[[[[[[[[[[[k05Z
[ [[ [ [[%
3-
[ [ [
[M
[ [ [
jjjjj~
xxQxQx
QxQxQxxxdM|C
bbbbbbs
6}Ljjjjjjjjjjj
DDDDDDD
jjjjjjjjjjjj
jjjjjjjjjjjjjjjjjjjjj
jjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjj
9999999999YYYYy=
bbZmYY
YYYYYYYYY
YYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYY
{}{{~|
z}~z~{
{|}|z}
z|{~{|}z
~z~|y{{
}{}z}z
~||~z{
}|}}|{z
{z~{~~
z{{}~}
z{}}~y
|}~z}y
z}z|z{
z|}~~}|
|~|{}}{
}{}|}~{|
|{|z}}{{
~}|~{y
||~}}|
jjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjI
jjjjjjjjjjjjjjjj%^r
ejjjjjjjjjjjjjjjj
jjjjjjjjjjjjjjjj%
/jjjjjjjjjjjjjjjj
44g46gg44
jjjjjjjjjjjjjjjj
jjjjjjjjjjjjjjjjle
jjjjjjjjjjjjjjjj
jjjjjjjjjjjjjjjj/
jjjjjjjjjjjjjjjjJ
jjjjjjjjjjjjjjjjJ
dss88}
jjjjjjjjjjjjjjjj
N88`=(
Jjjjjjjjjjjjjjjjj
Jjjjjjjjjjjjjjjjj/
jjjjjjjjjjjjjjjj
jjjjjjjjjjjjjjjj
jjjjjjjjjjjjjjjjGv
jjjjjjjjjjjjjjjj0/
jjjjjjjjjjjjjjjj
jjjjjjjjjjjjjjjj
^jjjjjjjjjjjjjjjjvv>2
IjjjjjjjjjjjjjjjG
jjjjjjjjjjjjjjj
7JIjjjjjjjjjjjjjjj-
jjjjjjjjjjjjjjj
Ijjjjjjjjjjjjjjj
Ijjjjjjjjjjjjjjj
-IjjjjjjjjjjjjjjjG
IjjjjjjjjjjjjjjjG
Ijjjjjjjjjjjjjjj
yv^I^I
Ijjjjjjjjjjjjju
^GjjjjjjjjjjjjI
Gjjjjjjjjjjjj
jjjjjjjjjjjjlE
jjjjjjjjjjjjJ
=hnlujjjjjjjjjjjj
Xujjjjjjjjjjjj
eujjjjjjjjjjjj
jjjjjjjjjjjj
[Gjjjjjjjjjjjj-^
vjjjjjjjjjjjjjI
..uuuuu
.G....
jjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjj
SSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSS.
SSSSSSSSSSSSSSP
4SSSSSSSSSSSSSS4'KY
SSSSSSSSSSSSS
SSSSSSSSSSSSS
DGYooG
lSSSSSSSSSSSSS
nwSSSSSSSSSSSSSS
SSSSSSSSSSSSSSw
SSSSSSSSSSSSS
SSSSSSSSSSSSSwne^L$
SSSSSSSSSSSSS.nIfC
SSSSSSSSSSSSS
SSSSSSSSSSSSS.
SSSSSSSSSSSSS
.SSSSSSSSSSSSS
SSSSSSSSSSSSS.~T
.SSSSSSSSSSSSS.
-.SSSSSSSSSSSSSBn@
[.SSSSSSSSSSSSS
hSSSSSSSSSSSSSS
SSSSSSSSSSS
.SSSSSSSSSS
@KKhB.SSSSSSSSSS4
.SSSSSSSSSS
.SSSSSSSSSS
nNNYoLSSSSSSSSSSS
SSSSSSSSSS4...PPPP
SSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSS
2\2`2d2
: :$:(:,:0:4:8:<:@:D:H:L:P:T:X:\:`:d:h:l:p:t:x:|:
; ;$;(;,;0;4;8;<;@;D;H;L;P;T;X;\;`;d;h;l;p;t;x;|;
2$2(202H2X2\2l2p2x2
4454I4k4
5-555E5T5Z5
6"6(6.646B6h6t6
7#7)7/767=7C7J7P7W7]7d7k7r7y7
9!9'9-9P9a9g9m9s9
9$:]:h:|:
;#;-;4;9;A;H;N;c;t;z;
1!1C1h1|1
303K3Q3Z3a3
4'4.494B4X4c4}4
5-525=5B5`5
7,858;8
9"9-9Q9Z9a9j9
9!:4:L:^:
<5<X<k<
?_?e?v?
0/0A0O0d0n0
12191V1
343:3E3Q3f3m3
4'4-494H4N4W4c4q4w4
6A7H7c7h7p7v7}7
8 8+808;8@8M8[8a8n8
8/989D9}9
<+=6=@=Y=c=v=
00:0B0J0a0z0
55'5,50545]5
7=7D7H7L7P7T7X7\7`7
:D;J;c;i;
?#?8?s?
0+1[1m1
2G2L2Z2i2
383F3L3o3v3
5&656D6M6b6
9$93989B9P9
92;9;?;o;u;{;
< <%<5<:<@<F<\<c<
>7>'?P?
4"5O576@6`6e6?7D7
: :&:+:4:Q:W:b:g:o:u:
; ?,?_?
1 2,2S2`2e2s2N3q3|3
7'7m7s7
:':4:@:J:R:]:
> >'>1>9>F>M>}>
2&282J2
8'8.848J8e8
99'9,90949]9
;=;D;H;L;P;T;X;\;`;
0K1Q1V1\1c1u1
5"8I8V8T:
=0=P=p=
> >@>`>|>
? ?@?`?
0(0H0P0\0
10181<1T1X1t1x1
0(040<0D0L0T0\0d0l0t0|0
; ;(;,;
= =$=(=,=0=4=8=<=@=D=H=L=P=T=X=\=`=d=h=l=p=t=x=|=
mscoree.dll
(null)
KERNEL32.DLL
((((( H
h(((( H
H
didiwot gatiwisenoxewu giruxolaxiyipagopejonovoyix vupuzikewodepuxowamomufepevasuxe homoraze
kiwukabiful lamaxidegexuwulo tuzugivizeragi vuripujuwokesurehujusej
wobutolexayoduwa
dcanozizoxavajahavumugox
rilusegufewaferacawenuzel nijohucoveferifobi
Jasozidi vupexenapep
kernel32.dll
lbuzomaxahugobokirepuc
Dohah xopalecisibivox vevuyavafite cepavasuyube kikekogolalo
@jjjjj
@jjjjj
VS_VERSION_INFO
StringFileInfo
043831F1
InternalName
Invoiced
FileDescription
ColdWater
ProductsVersion
23.38.77.44
ProductName
GoldenEaring
ProductionVersion
78.29.87.100
VarFileInfo
Translation
5Wetipipiwico foyi bomatumipa yojacowo havururelobenuy=Mowehijekayere kavitekarewu yidapetikuwanit konumiyeda royuvunDuxep jihicege lehowomiyocim hosigu xibajunabojom bexepuhesahiw nufajuviselu wopafof yobomixuj leziruwifuboyak
Zepinozi yidah kocokanapuvasupIGapufugapecosi luhupavoliwe hekokagegesuno wuwolotegujahac zemub sapalimi*Gizowi hev huruvumemokiwo hojumusalo cotafWNolonipije hinagin yokapabu huyukeyitazus totedurapizi duv pikudijosa yaniyafak sapewep8Piyoyitu vifip yomey begureluv lisetihivof kisacociludeyKLuhemuvixabibe nudapi jovolejan vifulebe vumeyinicuredu set yagew boyetayin2Som likugu dabodojox nuyusoweya pahihucuwi tobowif0Witococakahudos nacasunivanej nanecelubumeru gip
?Tafatemep tiwaja vahumawokilava tenugoc vohatuyu rese wujavumol
Litulo vafibuzazeh lanorec
Sucisozohaz golehici hic
DTox wezovaduse nupajerafemur wohomotuziboluv jiwezadiximuxa rikapiwu
Antivirus Signature
Bkav W32.AIDetectMalware
Lionic Clean
tehtris Clean
DrWeb Clean
MicroWorld-eScan Clean
FireEye Generic.mg.d3ea7d6746f35904
CAT-QuickHeal Ransom.Stop.P5
McAfee Artemis!D3EA7D6746F3
Malwarebytes Clean
Zillya Clean
Sangfor Trojan.Win32.Save.a
K7AntiVirus Trojan ( 005690671 )
BitDefender Clean
K7GW Trojan ( 005690671 )
Cybereason malicious.a27867
Arcabit Clean
BitDefenderTheta Clean
VirIT Clean
Cyren Clean
Symantec ML.Attribute.HighConfidence
Elastic malicious (high confidence)
ESET-NOD32 Clean
APEX Malicious
Paloalto Clean
ClamAV Win.Packer.pkr_ce1a-9980177-0
Kaspersky UDS:DangerousObject.Multi.Generic
Alibaba Clean
NANO-Antivirus Clean
SUPERAntiSpyware Clean
Rising Trojan.Kryptik!1.B663 (CLASSIC)
TACHYON Clean
Sophos Mal/Generic-S
F-Secure Clean
Baidu Clean
VIPRE Clean
TrendMicro Clean
McAfee-GW-Edition BehavesLike.Win32.Worm.dc
Trapmine malicious.moderate.ml.score
CMC Clean
Emsisoft Clean
SentinelOne Static AI - Suspicious PE
Jiangmin Clean
Webroot Clean
Google Detected
Avira Clean
Antiy-AVL Clean
Gridinsoft Ransom.Win32.STOP.dg!n
Xcitium Clean
Microsoft Trojan:MSIL/RedLineStealer.H!MTB
ViRobot Clean
ZoneAlarm UDS:DangerousObject.Multi.Generic
GData Clean
Cynet Malicious (score: 100)
AhnLab-V3 Clean
Acronis suspicious
VBA32 Clean
ALYac Clean
MAX Clean
DeepInstinct MALICIOUS
Cylance unsafe
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Tencent Clean
Yandex Clean
Ikarus Trojan-Spy.Agent
MaxSecure Clean
Fortinet W32/GenKryptik.ERHN!tr
AVG Win32:RansomX-gen [Ransom]
Avast Win32:RansomX-gen [Ransom]
CrowdStrike win/malicious_confidence_100% (W)
No IRMA results available.