Static | ZeroBOX

PE Compile Time

2022-11-05 03:44:04

PDB Path

C:\xen vuputu\po.pdb

PE Imphash

4aa773f91d20506f2979a40c36a81664

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x0005544c 0x00055600 7.92606521951
.data 0x00057000 0x00040ac0 0x00001800 1.72539938571
.rsrc 0x00098000 0x0000cd18 0x0000ce00 4.73679170096
.reloc 0x000a5000 0x00001c52 0x00001e00 3.10396680958

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x000a3f30 0x00000468 LANG_PORTUGUESE SUBLANG_PORTUGUESE_BRAZILIAN GLS_BINARY_LSB_FIRST
RT_ICON 0x000a3f30 0x00000468 LANG_PORTUGUESE SUBLANG_PORTUGUESE_BRAZILIAN GLS_BINARY_LSB_FIRST
RT_ICON 0x000a3f30 0x00000468 LANG_PORTUGUESE SUBLANG_PORTUGUESE_BRAZILIAN GLS_BINARY_LSB_FIRST
RT_ICON 0x000a3f30 0x00000468 LANG_PORTUGUESE SUBLANG_PORTUGUESE_BRAZILIAN GLS_BINARY_LSB_FIRST
RT_ICON 0x000a3f30 0x00000468 LANG_PORTUGUESE SUBLANG_PORTUGUESE_BRAZILIAN GLS_BINARY_LSB_FIRST
RT_ICON 0x000a3f30 0x00000468 LANG_PORTUGUESE SUBLANG_PORTUGUESE_BRAZILIAN GLS_BINARY_LSB_FIRST
RT_ICON 0x000a3f30 0x00000468 LANG_PORTUGUESE SUBLANG_PORTUGUESE_BRAZILIAN GLS_BINARY_LSB_FIRST
RT_ICON 0x000a3f30 0x00000468 LANG_PORTUGUESE SUBLANG_PORTUGUESE_BRAZILIAN GLS_BINARY_LSB_FIRST
RT_ICON 0x000a3f30 0x00000468 LANG_PORTUGUESE SUBLANG_PORTUGUESE_BRAZILIAN GLS_BINARY_LSB_FIRST
RT_ICON 0x000a3f30 0x00000468 LANG_PORTUGUESE SUBLANG_PORTUGUESE_BRAZILIAN GLS_BINARY_LSB_FIRST
RT_ICON 0x000a3f30 0x00000468 LANG_PORTUGUESE SUBLANG_PORTUGUESE_BRAZILIAN GLS_BINARY_LSB_FIRST
RT_ICON 0x000a3f30 0x00000468 LANG_PORTUGUESE SUBLANG_PORTUGUESE_BRAZILIAN GLS_BINARY_LSB_FIRST
RT_ICON 0x000a3f30 0x00000468 LANG_PORTUGUESE SUBLANG_PORTUGUESE_BRAZILIAN GLS_BINARY_LSB_FIRST
RT_ICON 0x000a3f30 0x00000468 LANG_PORTUGUESE SUBLANG_PORTUGUESE_BRAZILIAN GLS_BINARY_LSB_FIRST
RT_STRING 0x000a4c08 0x0000010c LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_STRING 0x000a4c08 0x0000010c LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_GROUP_ICON 0x000a4398 0x00000068 LANG_PORTUGUESE SUBLANG_PORTUGUESE_BRAZILIAN data
RT_GROUP_ICON 0x000a4398 0x00000068 LANG_PORTUGUESE SUBLANG_PORTUGUESE_BRAZILIAN data
RT_VERSION 0x000a4400 0x00000210 LANG_NEUTRAL SUBLANG_NEUTRAL data

Imports

Library KERNEL32.dll:
0x401008 CreateMutexW
0x40100c GetProfileIntW
0x401014 EnumCalendarInfoW
0x401020 UnlockFile
0x401024 GetTickCount
0x401028 GetConsoleAliasesA
0x40102c GetNumberFormatA
0x401034 ClearCommBreak
0x401038 GetDateFormatA
0x40103c GetVolumePathNameW
0x401040 FindResourceExA
0x401044 GlobalAlloc
0x401048 LoadLibraryW
0x40104c ReadConsoleInputA
0x401050 GetStringTypeExW
0x401058 FindNextVolumeW
0x40105c MulDiv
0x401060 GetDevicePowerState
0x401064 ReplaceFileA
0x401068 GetComputerNameA
0x40106c FindFirstFileA
0x401070 OpenMutexW
0x401074 GetLongPathNameW
0x401078 SetLastError
0x40107c lstrcmpiA
0x401080 GetProcAddress
0x401088 EnumDateFormatsExA
0x40108c IsValidCodePage
0x401090 CopyFileA
0x401094 LoadLibraryA
0x401098 CreateFileMappingA
0x40109c CreateHardLinkW
0x4010a4 HeapWalk
0x4010a8 GetModuleHandleA
0x4010ac SetLocaleInfoW
0x4010b4 CloseHandle
0x4010b8 CreateFileA
0x4010bc FlushFileBuffers
0x4010c0 WriteConsoleW
0x4010c8 GetConsoleOutputCP
0x4010cc WriteConsoleA
0x4010d8 MultiByteToWideChar
0x4010dc GetStartupInfoW
0x4010e0 GetModuleHandleW
0x4010e4 Sleep
0x4010e8 ExitProcess
0x4010ec GetLastError
0x4010f0 WriteFile
0x4010f4 GetStdHandle
0x4010f8 GetModuleFileNameA
0x4010fc TerminateProcess
0x401100 GetCurrentProcess
0x401104 IsDebuggerPresent
0x401108 HeapAlloc
0x40110c HeapFree
0x401118 TlsGetValue
0x40111c TlsAlloc
0x401120 TlsSetValue
0x401124 TlsFree
0x40112c GetCurrentThreadId
0x401134 HeapSize
0x401138 GetCPInfo
0x40113c GetACP
0x401140 GetOEMCP
0x401144 GetModuleFileNameW
0x401150 GetCommandLineW
0x401154 SetHandleCount
0x401158 GetFileType
0x40115c GetStartupInfoA
0x401164 HeapCreate
0x401168 VirtualFree
0x401170 GetCurrentProcessId
0x40117c SetFilePointer
0x401180 WideCharToMultiByte
0x401184 GetConsoleCP
0x401188 GetConsoleMode
0x40118c VirtualAlloc
0x401190 HeapReAlloc
0x401194 RtlUnwind
0x401198 LCMapStringA
0x40119c LCMapStringW
0x4011a0 GetStringTypeA
0x4011a4 GetStringTypeW
0x4011a8 GetLocaleInfoA
0x4011ac SetStdHandle
0x4011b0 RaiseException
Library USER32.dll:
0x4011b8 GetClipboardOwner
0x4011bc CharToOemBuffA
0x4011c0 CharUpperBuffW
0x4011c8 GetMenuBarInfo
0x4011cc LoadMenuA
0x4011d0 DdeQueryStringA
Library GDI32.dll:
0x401000 GetCharABCWidthsI
Library WINHTTP.dll:
0x4011d8 WinHttpQueryHeaders

!This program cannot be run in DOS mode.
`.data
@.reloc
bad allocation
Unknown exception
CorExitProcess
runtime error
TLOSS error
SING error
DOMAIN error
An application has made an attempt to load the C runtime library incorrectly.
Please contact the application's support team for more information.
- Attempt to use MSIL code from this assembly during native code initialization
This indicates a bug in your application. It is most likely the result of calling an MSIL-compiled (/clr) function from a native constructor or from DllMain.
- not enough space for locale information
- Attempt to initialize the CRT more than once.
This indicates a bug in your application.
- CRT not initialized
- unable to initialize heap
- not enough space for lowio initialization
- not enough space for stdio initialization
- pure virtual function call
- not enough space for _onexit/atexit table
- unable to open console device
- unexpected heap error
- unexpected multithread lock error
- not enough space for thread data
This application has requested the Runtime to terminate it in an unusual way.
Please contact the application's support team for more information.
- not enough space for environment
- not enough space for arguments
- floating point support not loaded
Microsoft Visual C++ Runtime Library
<program name unknown>
Runtime Error!
Program:
(null)
`h````
xpxxxx
EncodePointer
DecodePointer
FlsFree
FlsSetValue
FlsGetValue
FlsAlloc
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
GetProcessWindowStation
GetUserObjectInformationA
GetLastActivePopup
GetActiveWindow
MessageBoxA
USER32.DLL
`h`hhh
xppwpp
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
HH:mm:ss
dddd, MMMM dd, yyyy
MM/dd/yy
December
November
October
September
August
February
January
Saturday
Friday
Thursday
Wednesday
Tuesday
Monday
Sunday
Complete Object Locator'
Class Hierarchy Descriptor'
Base Class Array'
Base Class Descriptor at (
Type Descriptor'
`local static thread guard'
`managed vector copy constructor iterator'
`vector vbase copy constructor iterator'
`vector copy constructor iterator'
`dynamic atexit destructor for '
`dynamic initializer for '
`eh vector vbase copy constructor iterator'
`eh vector copy constructor iterator'
`managed vector destructor iterator'
`managed vector constructor iterator'
`placement delete[] closure'
`placement delete closure'
`omni callsig'
delete[]
new[]
`local vftable constructor closure'
`local vftable'
`udt returning'
`copy constructor closure'
`eh vector vbase constructor iterator'
`eh vector destructor iterator'
`eh vector constructor iterator'
`virtual displacement map'
`vector vbase constructor iterator'
`vector destructor iterator'
`vector constructor iterator'
`scalar deleting destructor'
`default constructor closure'
`vector deleting destructor'
`vbase destructor'
`string'
`local static guard'
`typeof'
`vcall'
`vbtable'
`vftable'
operator
delete
__unaligned
__restrict
__ptr64
__clrcall
__fastcall
__thiscall
__stdcall
__pascal
__cdecl
__based(
SunMonTueWedThuFriSat
JanFebMarAprMayJunJulAugSepOctNovDec
CONOUT$
bad allocation
rovogosekuruvozejitadunapa paruxayibovunamorohidoper
Gaz moboduboramenofifidijatuk
%s %f %c
kernel32.dll
Kiduhixodom wurof pon
Radifizibo
Cujudowarawu yal misibeko vuhelikosofanuj
yelusup hogay kegeyupahojuwojafinamap wihoweyayuceceze cizetiyegiwixutero
waxiyarosuguyogohijowunaciyoru hocuvamisaguzohu kelixabayobaxucobosi
lahejozanobames notebizosewepoxogafejudiya nilelukejuwuban mejivoginopuhuxuxoyebudaciyahu siv
pufacaduf
msimg32.dll
fajuvurewarecivaxusebezemagoxaja ziwayowu
kezotayuf zokaxebovunijifagutijor
bad exception
C:\xen vuputu\po.pdb
D$ 1D$
D$ 1D$
/SUVWu~
D$$PQQf
0SSSSS
Y;= {E
0A@@Ju
>=Yt1j
QQSVWh
j@j ^V
0SSSSS
0SSSSS
URPQQh
t"SS9]
PPPPPPPP
PPPPPPPP
0WWWWW
AAFFf;
;t$,v-
UQPXY]Y[
t+WWVPV
B96'Af0
y:m`%8@
' 99/v?0
' 99/v?0
clJfLX
z8sgpn
O$#1'/B
Y9kITb
95?=[y U
Z#Wk5aI6CR
A!Sr"|f
<mVNyA
DY:WgY"
;$W67l
AQTo@(4
Y}LDHY
~ZEy9,
=HUMhk,
oFCfWt
Y}8ehz
ZxPhVh1
dHC;Vg
(N\ZC@
tUBoVg
y1JK*T
9IDQpp
CjHJF|{
]FvCI4-"
9jgr)E
@{VCvjt P
IFtXu[
RVJgZ>V
3H.[$4j
&.#Z|D'Hp
:`g%(m
%u`RGV^K
U%|+6Y
W$PH*Y6
kHIg=w
d{W@7m
]>AR3,p
TQ'~>b
E}q}}%N
3,.S*%&
H$<RU|
AedA\qo
&$7Xt,
x'En11_
L40]+5|
{WWt;eP=nt
ejWN7w
W|xxN
hi6AoAC
}_45m~
A#Uj00_
REXcb8
fa35a0
u~TVyV
0XH-`|
A%an9x
Rq-[4Z
xN[E
,[`4\.s
^Omd&$
%hxHC*
CNlLV)
L*kPy&y
5@]8oAJ
7,AQ7G
@PY<]4W
]%CgO>
@1|JmB;g+
4(7B)@
XwnZjU
h9=^9J$93
3wVc&]
2@.DQ:m(
L#2cD<
LcR(>$
+bH(_&
${3x-8+)|
]+6sG0
v/uHt9S
u{pcVp
r>>wgh
mL4e~
^:++ PU
@K m,n1;&
@]R $nVhI
8**[1k
@x%>j
YWJ-S#0
fjf.O"p
itoj%q
D#SK~j
5FE)&:Dw
M>?96q
<|4W0&t9
Y6h yR
=M&.CNW^
=dI]\^
g}R:ki
=g]k'0
-pK-d9
I Rx4pT
A,YcZh
}4|r{:
p+`}`z[L
*h)I;dQ
Cb=Q7I
f;In.&W/
KZ~1gLt
P\G..
jt=0mf
j~k=z=yX
%I:J%#
N=Az@
=kBpCR
6r1_fFN%@+
cMZknd
(O&hTZX\
.J58$+
k%g$84
fWtHCe
=VTM:J
LIAD/(
2.?;-;
Um;X2
|qcw*:
5m])?H
"}fX8.
%}"D[Vo
=J#D4zSA
raFJn&zigN
'99j!-
tdKJtcQ
!L}s*_
1Zb)F2
uA:y/}
.:ghdA
DU~s)oS
uB-HwZ
T^a[BQ
IKaJk7
,%exi3
+8T>!"
~AB|V!Q
Xl_`+I
Wu/o,>
0{N\=.
88QD"V
M'jg5uo
(j>u27
GFvKjPm
KS:|raE
s70m
@"k`P{
YoK}"1
URp6v@
FO##9AD
EYyFF'
-;L93x4
wAi"MXLf
s7TS-r
%4yjJ
DBU,9&y
^x#$#g
Q$r1JcQ
%] zmy
H5tbDF
PN{"8
[T\#7Ju
2vVTm l
&XmCy%
Lq=|#]
$WKoIk
dO [
0<G=e\
%^7IdS
aB6KGD
_3caGL
[wIvy
-^womi
*7E&{}8
UobvVUl
C?Y/oa
8/+IX]
W&{e@:i
WYOBgA
3hz(#3
9{J)eH
L(w"6Cd
fw~rV9
OfAWR%8
7?p]&[)
=Dp=#[g
tl_\Iw@
BLntdK`<tZ$
4\c"y.
_XaJe8t
XlM7oNN
Te[Ai?
%yo[/eZ
7O)2~uk1
3@_\}~
{OKq'S
.JBa P
n)d}k
`7\_+>5'
M|T;yx;
!]V&ksl|
!2\;O!
Rh_t-QHq
#NN|Ijx
?oo|JV
1e5\`
Z%"KP?j
{A'L'd
Oe:?;N
YRIeBo
.;/a0D
H0,ze_}
0gOK,4
~6tGhh
5~!|K@
=_yVun
6X{y{q
^F%j"_
W.|r%\
zGCv|v?
K6Rh0v{z
u#KZUA
$qG |8
=33IF*#
&OuJbR
C`Z/MM
BBo4^UZ
(_x="T
53h:*b
=@A1[y@
]^#k?O
B@X 32
{dR<D&
BFG47P*Ti
V1NQ,9
<Jc:6Q
oDu:Y|
j.IZXI
&*R26K
f"Dd Y
s$gx68
#cmD"{
a`MRhH,
kx/m9?(
dDf`vNm
5o&7ds
d(o=O#
\eTkP
k(J,~U
` <[Sb
c8Nb-8{
;v'?Ox
QiL[$0
u33i)DS
-,3y/[;
=hxF5\<
\RT)YR
3~H;I-*[
h")F48
32Jh`?
p!o276
V0p~p1
JJ(R6b
;0}9e
CA(bULc
=w-Nuj
R^MVe#
-"BKyb
f+_Lxw
MM^u9'
gXi}
ZA^mhPl
Ji,73
.qf'g
f5N&Om
_Pn0Id
+t1S?
(%J]_9v
KX63pS)l
f6/M)t
<G4[82
DB<1=/
CemP"%
$kj'u+
0P0q )d8
`k+~A5
vX=1;
"sTPMC
wR3.k
h>W}e8`
g@1yw)
T<'<%r
$}3Fql
Sd>80T
;KAs|<
F:(iMO
]3?K"2%
mM%D.H
MvOnSz
3}?Qs_M
MV[Pqp
@J"R@d
)$]'U-;
p}5|@4:
~1{vga
VlrD;Cr0
#vOXrJ
VpBuyR
=ME%A,Z_
rcOYi$=
07@})t4
=[F('O">
#!v#.0)
SSk0WY
qs81{G
@_uWL-~*
eC?Esng|]L
i [A&8t
n\jd0tj
DSdCN~\
%?@sJ
|<h3E
[>)&`C
Adc qMCsw
2D Ze5
akG@u6
IoTZKRW
5I"w04s
}>F&Jy
TR}_2_L
W|jI}:
(wHjc2
^^d2C_
E:'OM0
K0A@N8
+GaLWe
SA:"Ni
[z+iYa
AhumR_
+$sS']
C(0|qx
"i|f-\#
O-&(\}3
NACS?e
"/He<]
.D1T`
B{Zb9*
O5/C6An
ND_2mA
41sB"{
=vh.LvQ#
$,;jAd
/)^]r|
w!=X9tr
|YQ#:;
6SssE{
5hC!{$
VCv^pG
"hfuKo"j
Z'KS!#R07
h>2K;/
}^es1c
3V2iHD
Yh!X={W
-EYUjoT
AfVZ<
g@hUeH
6cu|L
6$u9Vo
7A<'o`
97)sG
TFCf7D
z/;7Q4
4mN.j*
zwz"].#
2U1KnyT
G0z'6f
)yy7G>
P)$g@7
k)|+jL\
_a2w-6
!}VSMB
@Bf;9!
Sxf[0
HF2cv+
Vmwlp9
^Sp1@G
=y\C+'
H@TgZ'9'N
dC|O*l,
;ISv+~
oTVvc/
UGiU*9
`\*keP>
eSD\,M'
o":\v}
kZ3S)pK
a{,cUEK
+!dJHm
F;V@_Qk
%XJ`hA
u$70hj
WkydXqM
Wy`c#6
/yO5p]Z!(3
g*WZH1
^!"g.X
>}"mhL<
ukBFLU%,
b0k~I21
.ezW@#
4;2okf
iF~bdD
=LxE-q
A+%8+k
k9\I6BP
Uz/Pp|
wYG3q5
wS(5^4
{W1.ry
devW]rs
<~y~?K
|ZF>P/k
^Hq#Oh
s<-_d@5
s1Jj+
'_\&W
\vxPa`
EoX}=
I'qaWh
z,T5"XHk
99ZK|Y
v`|hB"k]
qg'?kEs
U3}12D
W &w0/
`/P,E8
fro6~!
^&0J/%l5
5OSI`
Wh}#`#
?~2g];9
tJ/"9,
BZ1qh]
j]8g9M
oBflZ4"n
'IAN-}
'?`!0R)
Lvt5b
B{'_ZUj
!Ht-8+
l@0g]6)
?i_!?'kX
F:\8=%r'W
Ya<IIXO
hdf #j&
%:)HiV
PM7>fIq4
`s(uL5[
$VFnY1#
3cu2r"el
Wo?Q*%
[zXVMu
0oC1gXg
K5P91rH
@/;.D{d[
0Y1b9R
7yURHi
'[{/l}
^'1aiH
M=!dngS
jcKf#$
X|n5$q
4hSQ^]*\
&x-JyC
~(i~32
)I9tDa
k%M$qhD07
Y!k]M;7QP+
G5gtP,
tS4|Z!
S-]fGM\
Ky&%ua
Gwk5bb
&i|2e3
eQx@>^
:K*,=U
N02'Bs@
5eTCN=
VhPZJW
rJh*.2x
{npx3&
cSFU_-
0^+;7'2>
$~+f;
0ZY[0>)
SxW(Us
>VDnGUF
x^GyJ3
55l{Yp
G1B7=
BjHGEEG'
?rA\*2
"~wmv<
6)dqz]
;N{6<Y
IU/!u:
AC1yD`
$g*$*k
v&v1{@
G+LnG)
0WsVdO
w{@7%lZ
Fum).nV
7p"_3$
7S>G}d
{3MdU<
D$HASx
a4 tA>
hhL(e1
RtI#HMhq
]`j'cx
a}_>Sw@
nA5I7X
dm;oIa~x
7aagS7`Pn6
Q-:A,]D
E)0965Yo
N[J&5
MjT=of
/}($?h
m~s`z,
sDMY]bb)
cEcI\
QQSVWd
HtHu4j
s[S;7|G;w
tR99u2
GetComputerNameA
CreateMutexW
GetProfileIntW
DeleteVolumeMountPointA
EnumCalendarInfoW
GetLogicalDriveStringsW
GetSystemWindowsDirectoryW
UnlockFile
GetTickCount
GetConsoleAliasesA
GetNumberFormatA
GetCompressedFileSizeW
ClearCommBreak
GetDateFormatA
GetVolumePathNameW
FindResourceExA
GlobalAlloc
LoadLibraryW
ReadConsoleInputA
GetStringTypeExW
EnumSystemCodePagesA
FindNextVolumeW
MulDiv
GetDevicePowerState
ReplaceFileA
SetCurrentDirectoryA
FindFirstFileA
OpenMutexW
GetLongPathNameW
SetLastError
lstrcmpiA
GetProcAddress
BeginUpdateResourceW
EnumDateFormatsExA
IsValidCodePage
CopyFileA
LoadLibraryA
CreateFileMappingA
CreateHardLinkW
SetProcessWorkingSetSize
HeapWalk
GetModuleHandleA
SetLocaleInfoW
GetWindowsDirectoryW
KERNEL32.dll
GetClipboardOwner
DdeQueryStringA
LoadMenuA
GetMenuBarInfo
DdeCreateStringHandleA
CharUpperBuffW
CharToOemBuffA
USER32.dll
GetCharABCWidthsI
GDI32.dll
WinHttpQueryHeaders
WINHTTP.dll
UnhandledExceptionFilter
SetUnhandledExceptionFilter
MultiByteToWideChar
GetStartupInfoW
GetModuleHandleW
ExitProcess
GetLastError
WriteFile
GetStdHandle
GetModuleFileNameA
TerminateProcess
GetCurrentProcess
IsDebuggerPresent
HeapAlloc
HeapFree
EnterCriticalSection
LeaveCriticalSection
TlsGetValue
TlsAlloc
TlsSetValue
TlsFree
InterlockedIncrement
GetCurrentThreadId
InterlockedDecrement
HeapSize
GetCPInfo
GetACP
GetOEMCP
GetModuleFileNameW
FreeEnvironmentStringsW
GetEnvironmentStringsW
GetCommandLineW
SetHandleCount
GetFileType
GetStartupInfoA
DeleteCriticalSection
HeapCreate
VirtualFree
QueryPerformanceCounter
GetCurrentProcessId
GetSystemTimeAsFileTime
InitializeCriticalSectionAndSpinCount
SetFilePointer
WideCharToMultiByte
GetConsoleCP
GetConsoleMode
VirtualAlloc
HeapReAlloc
RtlUnwind
LCMapStringA
LCMapStringW
GetStringTypeA
GetStringTypeW
GetLocaleInfoA
SetStdHandle
WriteConsoleA
GetConsoleOutputCP
WriteConsoleW
FlushFileBuffers
CreateFileA
CloseHandle
RaiseException
.?AVexception@std@@
.?AVtype_info@@
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
.?AVbad_exception@std@@
DRTTRS_U[gaaacbnnn
+)%411%
76,9/$//8(0/
-,*1B@730/)3A?A4
k0'(2'@
l%(30%A
E=,(/A
4189EEIC(4(8HHNH@(03'JX]VN
7040,;(0(6440(30'()%00(2'
)8650666022)0(('6%'0-
kokbkkhiigcg__\[_UXZU]SSQSQYQN>
ksswqyqyy
0/789:9
(+luj@*
'!KtuK
/|wmH"
g|o?&!
.?64;33%$1)"
ZAW\\b`akjdh[
VfeYSUSTROPNMD
>;8;-J$
6GG!="
2KQ"<E=9$L4
("*&*,).449300
fi[bXbZB@
IJLVKOXWQ]
%*&/5+,4-.
F0#@82E
HD'<=)G$
!CAB>?9;67:"
o[rSMN
jjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjI
jjjjjjjjjjjjjjjj%^r
ejjjjjjjjjjjjjjjj
jjjjjjjjjjjjjjjj%
/jjjjjjjjjjjjjjjj
44g46gg44
jjjjjjjjjjjjjjjj
jjjjjjjjjjjjjjjjle
jjjjjjjjjjjjjjjj
jjjjjjjjjjjjjjjj/
jjjjjjjjjjjjjjjjJ
jjjjjjjjjjjjjjjjJ
dss88}
jjjjjjjjjjjjjjjj
N88`=(
Jjjjjjjjjjjjjjjjj
Jjjjjjjjjjjjjjjjj/
jjjjjjjjjjjjjjjj
jjjjjjjjjjjjjjjj
jjjjjjjjjjjjjjjjGv
jjjjjjjjjjjjjjjj0/
jjjjjjjjjjjjjjjj
jjjjjjjjjjjjjjjj
^jjjjjjjjjjjjjjjjvv>2
IjjjjjjjjjjjjjjjG
jjjjjjjjjjjjjjj
7JIjjjjjjjjjjjjjjj-
jjjjjjjjjjjjjjj
Ijjjjjjjjjjjjjjj
Ijjjjjjjjjjjjjjj
-IjjjjjjjjjjjjjjjG
IjjjjjjjjjjjjjjjG
Ijjjjjjjjjjjjjjj
yv^I^I
Ijjjjjjjjjjjjju
^GjjjjjjjjjjjjI
Gjjjjjjjjjjjj
jjjjjjjjjjjjlE
jjjjjjjjjjjjJ
=hnlujjjjjjjjjjjj
Xujjjjjjjjjjjj
eujjjjjjjjjjjj
jjjjjjjjjjjj
[Gjjjjjjjjjjjj-^
vjjjjjjjjjjjjjI
..uuuuu
.G....
jjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjj
SSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSS.
SSSSSSSSSSSSSSP
4SSSSSSSSSSSSSS4'KY
SSSSSSSSSSSSS
SSSSSSSSSSSSS
DGYooG
lSSSSSSSSSSSSS
nwSSSSSSSSSSSSSS
SSSSSSSSSSSSSSw
SSSSSSSSSSSSS
SSSSSSSSSSSSSwne^L$
SSSSSSSSSSSSS.nIfC
SSSSSSSSSSSSS
SSSSSSSSSSSSS.
SSSSSSSSSSSSS
.SSSSSSSSSSSSS
SSSSSSSSSSSSS.~T
.SSSSSSSSSSSSS.
-.SSSSSSSSSSSSSBn@
[.SSSSSSSSSSSSS
hSSSSSSSSSSSSSS
SSSSSSSSSSS
.SSSSSSSSSS
@KKhB.SSSSSSSSSS4
.SSSSSSSSSS
.SSSSSSSSSS
nNNYoLSSSSSSSSSSS
SSSSSSSSSS4...PPPP
SSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSS
2\2`2d2
: :$:(:,:0:4:8:<:@:D:H:L:P:T:X:\:`:d:h:l:p:t:x:|:
; ;$;(;,;0;4;8;<;@;D;H;L;P;T;X;\;`;d;h;l;p;t;x;|;
2(2,242L2\2`2p2t2|2
4454I4h4
5.565F5U5[5
6"6(6.646B6h6t6
7#7)7/767=7C7J7P7W7]7d7k7r7y7
9!9'9-9P9a9g9m9s9
9$:]:h:|:
;#;-;4;9;A;H;N;c;t;z;
1!1C1h1|1
303K3Q3Z3a3
4'4.494B4X4c4}4
5-525=5B5`5
7,858;8
9"9-9Q9Z9a9j9
9!:4:L:^:
<5<X<k<
?_?e?v?
0/0A0O0d0n0
12191V1
343:3E3Q3f3m3
4'4-494H4N4W4c4q4w4
6A7H7c7h7p7v7}7
8 8+808;8@8M8[8a8n8
8/989D9}9
<+=6=@=Y=c=v=
00:0B0J0a0z0
55'5,50545]5
7=7D7H7L7P7T7X7\7`7
:D;J;c;i;
?#?8?s?
0+1[1m1
2G2L2Z2i2
383F3L3o3v3
5&656D6M6b6
9$93989B9P9
92;9;?;o;u;{;
< <%<5<:<@<F<\<c<
>7>'?P?
4"5O576@6`6e6?7D7
: :&:+:4:Q:W:b:g:o:u:
; ?,?_?
1 2,2S2`2e2s2N3q3|3
7'7m7s7
:':4:@:J:R:]:
> >'>1>9>F>M>}>
2&282J2
8'8.848J8e8
99'9,90949]9
;=;D;H;L;P;T;X;\;`;
0K1Q1V1\1c1u1
2G3_3d3
576D6W67E8>9
484T4X4t4x4
5 5@5L5h5t5
606L6P6l6p6
787X7x7
7 8(8,8D8H8X8|8
9 9$9,9@9H9\9
0(040<0D0L0T0\0d0l0t0|0
; ;(;,;
= =$=(=,=0=4=8=<=@=D=H=L=P=T=X=\=`=d=h=l=p=t=x=|=
mscoree.dll
(null)
KERNEL32.DLL
((((( H
h(((( H
H
didiwot gatiwisenoxewu giruxolaxiyipagopejonovoyix vupuzikewodepuxowamomufepevasuxe homoraze
kiwukabiful lamaxidegexuwulo tuzugivizeragi vuripujuwokesurehujusej
wobutolexayoduwa
dcanozizoxavajahavumugox
rilusegufewaferacawenuzel nijohucoveferifobi
Jasozidi vupexenapep
kernel32.dll
lbuzomaxahugobokirepuc
Dohah xopalecisibivox vevuyavafite cepavasuyube kikekogolalo
@jjjjj
@jjjjj
VS_VERSION_INFO
StringFileInfo
043831F1
InternalName
Invoiced
FileDescription
ColdWater
ProductsVersion
23.38.77.44
ProductName
GoldenEaring
ProductionVersion
78.29.87.100
VarFileInfo
Translation
5Wetipipiwico foyi bomatumipa yojacowo havururelobenuy=Mowehijekayere kavitekarewu yidapetikuwanit konumiyeda royuvunDuxep jihicege lehowomiyocim hosigu xibajunabojom bexepuhesahiw nufajuviselu wopafof yobomixuj leziruwifuboyak
Zepinozi yidah kocokanapuvasupIGapufugapecosi luhupavoliwe hekokagegesuno wuwolotegujahac zemub sapalimi*Gizowi hev huruvumemokiwo hojumusalo cotafWNolonipije hinagin yokapabu huyukeyitazus totedurapizi duv pikudijosa yaniyafak sapewep8Piyoyitu vifip yomey begureluv lisetihivof kisacociludeyKLuhemuvixabibe nudapi jovolejan vifulebe vumeyinicuredu set yagew boyetayin2Som likugu dabodojox nuyusoweya pahihucuwi tobowif0Witococakahudos nacasunivanej nanecelubumeru gip
?Tafatemep tiwaja vahumawokilava tenugoc vohatuyu rese wujavumol
Litulo vafibuzazeh lanorec
Sucisozohaz golehici hic
DTox wezovaduse nupajerafemur wohomotuziboluv jiwezadiximuxa rikapiwu
Antivirus Signature
Bkav W32.AIDetectMalware
Lionic Clean
tehtris Clean
DrWeb Clean
MicroWorld-eScan Clean
ClamAV Win.Packer.pkr_ce1a-9980177-0
FireEye Generic.mg.fab65e608359e725
CAT-QuickHeal Ransom.Stop.P5
ALYac Clean
Malwarebytes MachineLearning/Anomalous.94%
Zillya Clean
Sangfor Trojan.Win32.Save.a
K7AntiVirus Trojan ( 005690671 )
BitDefender Clean
K7GW Trojan ( 005690671 )
CrowdStrike win/malicious_confidence_100% (D)
BitDefenderTheta Clean
VirIT Clean
Cyren Clean
Symantec ML.Attribute.HighConfidence
Elastic malicious (high confidence)
ESET-NOD32 Clean
APEX Malicious
Paloalto Clean
Cynet Malicious (score: 100)
Kaspersky VHO:Backdoor.Win32.Tofsee.gen
Alibaba Clean
NANO-Antivirus Clean
ViRobot Clean
Tencent Clean
Emsisoft Clean
F-Secure Clean
Baidu Clean
VIPRE Clean
TrendMicro Clean
McAfee-GW-Edition BehavesLike.Win32.Worm.gc
Trapmine malicious.moderate.ml.score
CMC Clean
Sophos ML/PE-A
SentinelOne Static AI - Malicious PE
GData Clean
Jiangmin Clean
Webroot Clean
Avira Clean
MAX Clean
Antiy-AVL Clean
Gridinsoft Ransom.Win32.STOP.dg!n
Xcitium Clean
Arcabit Clean
SUPERAntiSpyware Clean
ZoneAlarm VHO:Backdoor.Win32.Tofsee.gen
Microsoft Trojan:Win32/Sabsik.FL.B!ml
Google Detected
AhnLab-V3 Clean
Acronis suspicious
McAfee Clean
TACHYON Clean
DeepInstinct MALICIOUS
VBA32 Clean
Cylance unsafe
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Rising Trojan.Kryptik!1.B663 (CLASSIC)
Yandex Clean
Ikarus Trojan-Spy.Agent
MaxSecure Trojan.Malware.300983.susgen
Fortinet W32/GenKryptik.ERHN!tr
AVG Win32:RansomX-gen [Ransom]
Cybereason malicious.449167
Avast Win32:RansomX-gen [Ransom]
No IRMA results available.