Static | ZeroBOX

PE Compile Time

2022-11-17 21:19:29

PDB Path

C:\kizud26 safujawesolecu\bufud vegu_dib\48\fayos\cidavu.pdb

PE Imphash

0af0ab32fec6d387d477684bace95bf2

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x00021818 0x00021a00 7.654701317
.data 0x00023000 0x0017c41c 0x00001800 1.89473051207
.rsrc 0x001a0000 0x000198c8 0x00019a00 4.13022468562
.reloc 0x001ba000 0x00002964 0x00002a00 2.40065142723

Resources

Name Offset Size Language Sub-language File type
RT_CURSOR 0x001b9048 0x000000b0 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_CURSOR 0x001b9048 0x000000b0 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_CURSOR 0x001b9048 0x000000b0 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_CURSOR 0x001b9048 0x000000b0 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_CURSOR 0x001b9048 0x000000b0 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_CURSOR 0x001b9048 0x000000b0 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_CURSOR 0x001b9048 0x000000b0 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_CURSOR 0x001b9048 0x000000b0 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x001b5068 0x00000468 LANG_PORTUGUESE SUBLANG_PORTUGUESE_BRAZILIAN GLS_BINARY_LSB_FIRST
RT_ICON 0x001b5068 0x00000468 LANG_PORTUGUESE SUBLANG_PORTUGUESE_BRAZILIAN GLS_BINARY_LSB_FIRST
RT_ICON 0x001b5068 0x00000468 LANG_PORTUGUESE SUBLANG_PORTUGUESE_BRAZILIAN GLS_BINARY_LSB_FIRST
RT_ICON 0x001b5068 0x00000468 LANG_PORTUGUESE SUBLANG_PORTUGUESE_BRAZILIAN GLS_BINARY_LSB_FIRST
RT_ICON 0x001b5068 0x00000468 LANG_PORTUGUESE SUBLANG_PORTUGUESE_BRAZILIAN GLS_BINARY_LSB_FIRST
RT_ICON 0x001b5068 0x00000468 LANG_PORTUGUESE SUBLANG_PORTUGUESE_BRAZILIAN GLS_BINARY_LSB_FIRST
RT_ICON 0x001b5068 0x00000468 LANG_PORTUGUESE SUBLANG_PORTUGUESE_BRAZILIAN GLS_BINARY_LSB_FIRST
RT_ICON 0x001b5068 0x00000468 LANG_PORTUGUESE SUBLANG_PORTUGUESE_BRAZILIAN GLS_BINARY_LSB_FIRST
RT_ICON 0x001b5068 0x00000468 LANG_PORTUGUESE SUBLANG_PORTUGUESE_BRAZILIAN GLS_BINARY_LSB_FIRST
RT_ICON 0x001b5068 0x00000468 LANG_PORTUGUESE SUBLANG_PORTUGUESE_BRAZILIAN GLS_BINARY_LSB_FIRST
RT_ICON 0x001b5068 0x00000468 LANG_PORTUGUESE SUBLANG_PORTUGUESE_BRAZILIAN GLS_BINARY_LSB_FIRST
RT_ICON 0x001b5068 0x00000468 LANG_PORTUGUESE SUBLANG_PORTUGUESE_BRAZILIAN GLS_BINARY_LSB_FIRST
RT_ICON 0x001b5068 0x00000468 LANG_PORTUGUESE SUBLANG_PORTUGUESE_BRAZILIAN GLS_BINARY_LSB_FIRST
RT_ICON 0x001b5068 0x00000468 LANG_PORTUGUESE SUBLANG_PORTUGUESE_BRAZILIAN GLS_BINARY_LSB_FIRST
RT_ICON 0x001b5068 0x00000468 LANG_PORTUGUESE SUBLANG_PORTUGUESE_BRAZILIAN GLS_BINARY_LSB_FIRST
RT_ICON 0x001b5068 0x00000468 LANG_PORTUGUESE SUBLANG_PORTUGUESE_BRAZILIAN GLS_BINARY_LSB_FIRST
RT_ICON 0x001b5068 0x00000468 LANG_PORTUGUESE SUBLANG_PORTUGUESE_BRAZILIAN GLS_BINARY_LSB_FIRST
RT_ICON 0x001b5068 0x00000468 LANG_PORTUGUESE SUBLANG_PORTUGUESE_BRAZILIAN GLS_BINARY_LSB_FIRST
RT_ICON 0x001b5068 0x00000468 LANG_PORTUGUESE SUBLANG_PORTUGUESE_BRAZILIAN GLS_BINARY_LSB_FIRST
RT_ICON 0x001b5068 0x00000468 LANG_PORTUGUESE SUBLANG_PORTUGUESE_BRAZILIAN GLS_BINARY_LSB_FIRST
RT_ICON 0x001b5068 0x00000468 LANG_PORTUGUESE SUBLANG_PORTUGUESE_BRAZILIAN GLS_BINARY_LSB_FIRST
RT_ICON 0x001b5068 0x00000468 LANG_PORTUGUESE SUBLANG_PORTUGUESE_BRAZILIAN GLS_BINARY_LSB_FIRST
RT_ICON 0x001b5068 0x00000468 LANG_PORTUGUESE SUBLANG_PORTUGUESE_BRAZILIAN GLS_BINARY_LSB_FIRST
RT_STRING 0x001b9760 0x00000166 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_STRING 0x001b9760 0x00000166 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_GROUP_CURSOR 0x001b90f8 0x00000022 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_GROUP_CURSOR 0x001b90f8 0x00000022 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_GROUP_CURSOR 0x001b90f8 0x00000022 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_GROUP_ICON 0x001b54d0 0x00000076 LANG_PORTUGUESE SUBLANG_PORTUGUESE_BRAZILIAN data
RT_GROUP_ICON 0x001b54d0 0x00000076 LANG_PORTUGUESE SUBLANG_PORTUGUESE_BRAZILIAN data
RT_GROUP_ICON 0x001b54d0 0x00000076 LANG_PORTUGUESE SUBLANG_PORTUGUESE_BRAZILIAN data
RT_GROUP_ICON 0x001b54d0 0x00000076 LANG_PORTUGUESE SUBLANG_PORTUGUESE_BRAZILIAN data
RT_VERSION 0x001b9120 0x00000208 LANG_NEUTRAL SUBLANG_NEUTRAL data

Imports

Library KERNEL32.dll:
0x401000 GetComputerNameA
0x401004 CreateMutexW
0x401008 FindResourceA
0x40100c EnumCalendarInfoA
0x401010 lstrlenA
0x401018 EnumDateFormatsExW
0x40101c AddConsoleAliasW
0x401020 SetTapeParameters
0x401024 GetModuleHandleW
0x401028 GetTickCount
0x40102c GetConsoleAliasesA
0x401034 GlobalAlloc
0x401038 LoadLibraryW
0x40103c ReadConsoleInputA
0x401040 CopyFileW
0x401044 ReadFile
0x401048 GetVolumePathNameA
0x40104c DisconnectNamedPipe
0x401050 GetProfileIntA
0x401058 GetLastError
0x40105c SetLastError
0x401060 GetProcAddress
0x401068 IsValidCodePage
0x401070 LoadLibraryA
0x401074 OpenMutexA
0x401078 CreateHardLinkW
0x40107c lstrcmpiW
0x401080 SetLocaleInfoW
0x401084 CreateMutexA
0x40108c _lopen
0x401090 GetVersionExA
0x401098 AddConsoleAliasA
0x40109c lstrcpyA
0x4010a0 CreateFileA
0x4010a4 CloseHandle
0x4010a8 WriteConsoleW
0x4010ac GetConsoleOutputCP
0x4010b0 WriteConsoleA
0x4010b4 SetStdHandle
0x4010b8 FlushFileBuffers
0x4010c4 Sleep
0x4010e0 HeapFree
0x4010e4 MultiByteToWideChar
0x4010e8 ExitProcess
0x4010ec GetStartupInfoW
0x4010f0 RtlUnwind
0x4010f4 RaiseException
0x4010f8 WriteFile
0x4010fc GetStdHandle
0x401100 GetModuleFileNameA
0x401104 HeapAlloc
0x401108 HeapCreate
0x40110c VirtualFree
0x401110 VirtualAlloc
0x401114 HeapReAlloc
0x401118 SetHandleCount
0x40111c GetFileType
0x401120 GetStartupInfoA
0x401124 TerminateProcess
0x401128 GetCurrentProcess
0x40112c IsDebuggerPresent
0x401130 TlsGetValue
0x401134 TlsAlloc
0x401138 TlsSetValue
0x40113c TlsFree
0x401140 GetCurrentThreadId
0x401144 HeapSize
0x401148 GetCPInfo
0x40114c GetACP
0x401150 GetOEMCP
0x401158 GetModuleFileNameW
0x401164 GetCommandLineW
0x40116c GetCurrentProcessId
0x401174 GetLocaleInfoA
0x401178 GetStringTypeA
0x40117c GetStringTypeW
0x401180 SetFilePointer
0x401184 WideCharToMultiByte
0x401188 GetConsoleCP
0x40118c GetConsoleMode
0x401190 LCMapStringA
0x401194 LCMapStringW
Library USER32.dll:
0x40119c EnumDesktopWindows
0x4011a0 CharToOemBuffA
0x4011a4 GetMenuBarInfo
0x4011a8 CharLowerBuffW
0x4011ac CharUpperBuffA
0x4011b0 LoadMenuW
0x4011b4 CharUpperW
0x4011b8 LoadBitmapW
0x4011bc DdeQueryStringA
0x4011c0 SetClipboardViewer

!This program cannot be run in DOS mode.
`.data
@.reloc
bad allocation
Unknown exception
CorExitProcess
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
runtime error
TLOSS error
SING error
DOMAIN error
An application has made an attempt to load the C runtime library incorrectly.
Please contact the application's support team for more information.
- Attempt to use MSIL code from this assembly during native code initialization
This indicates a bug in your application. It is most likely the result of calling an MSIL-compiled (/clr) function from a native constructor or from DllMain.
- not enough space for locale information
- Attempt to initialize the CRT more than once.
This indicates a bug in your application.
- CRT not initialized
- unable to initialize heap
- not enough space for lowio initialization
- not enough space for stdio initialization
- pure virtual function call
- not enough space for _onexit/atexit table
- unable to open console device
- unexpected heap error
- unexpected multithread lock error
- not enough space for thread data
This application has requested the Runtime to terminate it in an unusual way.
Please contact the application's support team for more information.
- not enough space for environment
- not enough space for arguments
- floating point support not loaded
Microsoft Visual C++ Runtime Library
<program name unknown>
Runtime Error!
Program:
EncodePointer
DecodePointer
FlsFree
FlsSetValue
FlsGetValue
FlsAlloc
(null)
`h````
xpxxxx
bad exception
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
HH:mm:ss
dddd, MMMM dd, yyyy
MM/dd/yy
December
November
October
September
August
February
January
Saturday
Friday
Thursday
Wednesday
Tuesday
Monday
Sunday
GetProcessWindowStation
GetUserObjectInformationA
GetLastActivePopup
GetActiveWindow
MessageBoxA
USER32.DLL
`h`hhh
xppwpp
Complete Object Locator'
Class Hierarchy Descriptor'
Base Class Array'
Base Class Descriptor at (
Type Descriptor'
`local static thread guard'
`managed vector copy constructor iterator'
`vector vbase copy constructor iterator'
`vector copy constructor iterator'
`dynamic atexit destructor for '
`dynamic initializer for '
`eh vector vbase copy constructor iterator'
`eh vector copy constructor iterator'
`managed vector destructor iterator'
`managed vector constructor iterator'
`placement delete[] closure'
`placement delete closure'
`omni callsig'
delete[]
new[]
`local vftable constructor closure'
`local vftable'
`udt returning'
`copy constructor closure'
`eh vector vbase constructor iterator'
`eh vector destructor iterator'
`eh vector constructor iterator'
`virtual displacement map'
`vector vbase constructor iterator'
`vector destructor iterator'
`vector constructor iterator'
`scalar deleting destructor'
`default constructor closure'
`vector deleting destructor'
`vbase destructor'
`string'
`local static guard'
`typeof'
`vcall'
`vbtable'
`vftable'
operator
delete
__unaligned
__restrict
__ptr64
__clrcall
__fastcall
__thiscall
__stdcall
__pascal
__cdecl
__based(
SunMonTueWedThuFriSat
JanFebMarAprMayJunJulAugSepOctNovDec
CONOUT$
bad allocation
xucebugafukuwuvekesacubupopijege
%s %f %c
VirtualProtect
nosagonexefohutu hopavedul suvedofosayatujuketujav
kesitakopumo
C:\kizud26 safujawesolecu\bufud vegu_dib\48\fayos\cidavu.pdb
D$(1D$
L$ _^]
QQSVWd
to=H>B
0SSSSS
r=x6B
j@j ^V
0A@@Ju
>=Yt1j
QQSVWh
HtHu4j
s[S;7|G;w
tR99u2
v$;5l>B
0SSSSS
PPPPPPPP
0SSSSS
PPPPPPPP
URPQQh,
uL9=8SB
t"SS9]
0WWWWW
AAFFf;
;t$,v-
UQPXY]Y[
t+WWVPV
";lI?Y<\
z,F&UX
QHmy2X
+Sw(\QJ
f\w`Ep
u-=p=T
cw(Q9 p
\uo>piq
+!u%uqBZ
d7W|;]3
QiJ!v&G)\-
~+P:Eh
PoX(1{g
c9JyIT
:S=NezuD
Kd)[V!*
sd>JRi
5lVnLC
MJ{%{n
ZzweH.Q
cl(/Mc
9yT4Bog"G
<-P3*d
^\NF`
V#%S*f
#=AOov+
.yIKt&
\)J+(+
sDeAkG
z[ETS_
Y)OA(If:
9l|fa=g
N5l,y\
-_vD!m
VOxDw-
TD7pgE
u[DW:]
ZF2<L.%X
cDbvoY
z_]pi`
V>[&[XK
J%^[M@
vTK BQF
'l1KG^.-%
sA?h=v
Heo&K +
M&tWu/B
jY|}-Y=*
NoUe>q~
9|pav_?
~(/V65E
aFK.^X
b /on`
,xxU.X
0J|Bl?
gY\teI
c6[AlX
N6[gv[
)4Fi{v
!3@r]G
_(9Wu'4
=d:}}
{PqP6$
]eO< ]
I42c`
&FZ`4^
.</-8>
W%jB"f
md_|jX
7tHk:"'
%Ru?aF
hZ8Wpz
~}N](P
G[>6@u
S0E3.K
s(Uy8jVu
5A8=e/%
A32Kiy
/!Q#2+b
gmFXCq
Y.A7Bh
joUl"m
I=Z:j4fK
kK|^;n
3\_Ng_
l51aM.
k2\08cJ
] 2f&,
2*UTYd
|Vk]1[
K.F}:yglP{
$kM!H'
PB-E<[
\u66lL
nJl6*d
7[,#Z
,$:I[c
H2Anz4
#&)GD2
M5~C7m!
G5>sJcV
I_]4Kivg
/K>cjp
;Ac4yO`
yaPiynR
IdV+m!
0)J|3B
XMpQN"
~*jq`X
VdLb1v
AQ?< U
,!5=Cd
H%w8Oh
O {Oq/
H7/jkkT
9F83$S3
&O%H`y
JE'AY7
qRa7<=
L?Msxf
Su6ySJD
<J5_\I
MF$g$F
K>ZnQH
6lrDP,
/oL^4H
Rl#%#(Q==
`A,Gb;a
|&@V-o
V4cOCV
Y`^iez;9+68
7)}3Ib
^5\.!-
e,8c_
Aca|'|/
(;:'i
6O'aS
XVSp
p/!+D[
'&~UjU
#Z1#!Y
Y?I5de
LKs>y3
[7|qRu
U6Rzjta
f,uD<
w[K^'F
HgVozhz
JyHTlV
IgJNUJ`
2xCzJB
Or?I2%
)XEcTNr
#!#mLAU
=c(W {
GetComputerNameA
CreateMutexW
FindResourceA
EnumCalendarInfoA
lstrlenA
GetConsoleAliasesLengthW
EnumDateFormatsExW
AddConsoleAliasW
SetTapeParameters
GetModuleHandleW
GetTickCount
GetConsoleAliasesA
GetWindowsDirectoryA
GlobalAlloc
LoadLibraryW
ReadConsoleInputA
CopyFileW
ReadFile
GetVolumePathNameA
DisconnectNamedPipe
GetProfileIntA
SetCurrentDirectoryA
GetLastError
SetLastError
GetProcAddress
BeginUpdateResourceW
IsValidCodePage
EnumSystemCodePagesW
LoadLibraryA
OpenMutexA
CreateHardLinkW
lstrcmpiW
SetLocaleInfoW
CreateMutexA
SetProcessShutdownParameters
_lopen
GetVersionExA
FileTimeToLocalFileTime
AddConsoleAliasA
lstrcpyA
KERNEL32.dll
SetClipboardViewer
DdeQueryStringA
LoadBitmapW
CharUpperW
LoadMenuW
CharUpperBuffA
CharLowerBuffW
GetMenuBarInfo
CharToOemBuffA
EnumDesktopWindows
USER32.dll
InterlockedIncrement
InterlockedDecrement
InitializeCriticalSection
DeleteCriticalSection
EnterCriticalSection
LeaveCriticalSection
UnhandledExceptionFilter
SetUnhandledExceptionFilter
HeapFree
MultiByteToWideChar
ExitProcess
GetStartupInfoW
RtlUnwind
RaiseException
WriteFile
GetStdHandle
GetModuleFileNameA
HeapAlloc
HeapCreate
VirtualFree
VirtualAlloc
HeapReAlloc
SetHandleCount
GetFileType
GetStartupInfoA
TerminateProcess
GetCurrentProcess
IsDebuggerPresent
TlsGetValue
TlsAlloc
TlsSetValue
TlsFree
GetCurrentThreadId
HeapSize
GetCPInfo
GetACP
GetOEMCP
InitializeCriticalSectionAndSpinCount
GetModuleFileNameW
FreeEnvironmentStringsW
GetEnvironmentStringsW
GetCommandLineW
QueryPerformanceCounter
GetCurrentProcessId
GetSystemTimeAsFileTime
GetLocaleInfoA
GetStringTypeA
GetStringTypeW
SetFilePointer
WideCharToMultiByte
GetConsoleCP
GetConsoleMode
LCMapStringA
LCMapStringW
FlushFileBuffers
SetStdHandle
WriteConsoleA
GetConsoleOutputCP
WriteConsoleW
CloseHandle
CreateFileA
Copyright (c) 1992-2004 by P.J. Plauger, licensed by Dinkumware, Ltd. ALL RIGHTS RESERVED.
.?AVtype_info@@
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
.?AVbad_exception@std@@
.?AVexception@std@@
TTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTT
#TTTTTTTTTTTTTTTTTTTTTTTTTC
TTTTTTTTTTTTTTTTTTTTTTTT
TTTTTTTTTTTTTTTTTTTTT'x
TTTTTTTTTTTTTTTTTTT
TTTTTTTTTTTTTTTTTTT
TTTTTTTTTTTTTTTTTT
TTTTTTTTTTTTTTTTTTTK
TTTTTTTTTTTTTTTTTTT
TTTTTTTTTTTTTTTTTTTTTD
TTTTTTTTTTTTTTTTTTTTTTTTTTTT
TTTTTTTTTTTTTTTTTTTTTTTTTTTT
TTTTTTTTTTTTTTTTTTTTTTTTTTTT<3
TTTTTTTT}
TTTTTTTTTTTTTTTTTT
TTTTTTT@
{TTTTTTTTTTTTTTTTTT
sTTTTTT
TTTTTTTTTTTTTTTTTT
%YWTTTTTTTTTTTTTTTTTT+Oof
;TTTTTTTTTTTTTTTTTT
TTTTTTTTTTTTTTTTTTT
TTTTTTTTTTTTTTTTTTTR(iQg
TTTTTTTTTTTTTTTTTTTTPcJN[
ZTTTTTTTTTTTTTTTTTTTTTA
\TTTTTTTTTTTTTTTTTTTTTT
TTTTTTTTTTTTTTTTTTTTTTTTT
TTTTTTTTTTTTTTTTTTTTTTTTTT
TTTTTTTTTTTTTTTTTTTTTTTTTTTTTm&TTTTTTTTTTTTTTTT
|}~~|~{
~}z{}~|
{}}}~~
{~z}{{~
|{~~z|
z}~~z}
||}|{~~{
z{{z||
~}|~|{
|z|~~}
{}{~}z
~z|}{}||
~|{|~{
|~}{zy
MMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMM
MMMMMMMMMMMMMMMMMMMMQ
V;MMMMMMMMMMMMMMMMMMw
MMMMMMMMMMMMMMMM.l
MMMMMMMMMMMMMMMu3
0^MMMMMMMMMMMMMM
K5MMMMMMMMMMMMMMM
MMMMMMMMMMMMMMM5%
wMMMMMMMMMMM-{
LMMMMMMMMMM{n
8MMMMMMMMMM
MMMMMMMMMMMM
MMMMMMMMMMMM{F
gMMMMMMMMMMMMM{
MMMMMMMMMMMM
MMM{}a
MMMMMMMMMMMM
&MMMMM
{MMMMMMMMMMMMMMMMMM{
JDMMMMMMMMMMMMMMMMMM-{
MMMMMMMMMMMMMMMMMM{
MMMMMMMMMMMMMMMMMM
ZMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMM
Df}-0"g"
t.<.^s
4~X/^OwF*^
/O4<Ez
kkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkk
YkkknzL
kkkkku$
Ckkkkkk;
kkkkkkk
kkkkkkk
kkkkkkkk
kkkkkkkkkk
w`kkkkkkkk
:::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::
]))))nnyV
jMjk$t
:::::::::::::::::
::::::::::::::::
8$>:::::::::::::::
:::::::::::::::
:::::::::::::::
:::::::::::::::
:::::::::::::::
:::::::::::::::(
:::::::::::::::wk
:::::::::::::::w
:::::::::::::::(
>:::::::::::::::(y
>:::::::::::::::t
>:::::::::::::::(T
>:::::::::::::::t
>:::::::::::::::tj3
>:::::::::::::::tyA&v
::::::::::::::::t
::::::::::::::::
::::::::::::::::hj
::::::::::::::::hy
8f__M_M
::::::::::::::::hT
::::::::::::::::h
^::::::::::::::::$y
::::::::::::::::h6
::::::::::::::::$f
::::::::::::::::$
4::::::::::::::::
::::::::::::::::$y
#p::::::::::::::::
::::::::::::::::^6L
::::::::::::::::^y
+Er<X|
::::::::::::::::
4::::::::::::::::4n52Hr7
::::::::::::::::
::::::::::::::::pV
::::::::::::::::
VsssJJ
V4::::::::::::::::^
:::::::::::::::::^
:::::::::::::::::
*m{***
::::::::::::::::::>>^M
p'(::::::::::::::::::::>>>
(:::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::
wwwwwwwwwww
Ywwwwwwwwwww
wwwwwwwwwww
wwwwwwwwwww
wwwwwwwwwwwxS
wwwwwwwwwww
jwwwwwwwwwwwx
wwwwwwwwwww
wwwwwwwwwww
gwwwwwwwwwww{
gwwwwwwwwwww
wwwwwwwwwwwx3
wwwwwwwwwww
wwwwwwwwwwwx
iwwwwwwwwwwwx}
wwwwwwwwwww
H_H_q_H__
wwwwwwwwwww
iwwwwwwwwwww
iwwwwwwwwwww
wwwwwwwwwww
wwwwwwwwwww
wwwwwwwwwwwd
wwwwwwwwwww
wwwwwwwwwwwPQ
wwwwwwwwwww
wwwwwwwwwww
wwwwwwwwwwwwwwwwww++++
wwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwww
/LLm
/
9
WT

WT>


{






W

Y

Jxxxxxx
Fxxxxx^
#8#-xxxxx
|xxxxx<
?xxxxxL
eIxxxxxf[C
xxxxx$
_xxxxxp
P\*xxxxx
xxxxxD
+Yxxxxx}
7bxxxxx
xxxxxx
~~~~~~
iiiiiiii
iiiiiiii
iiiiii
iiiiii
iiiiiiiii
iiiiiiiiii
iiiiiiii
iiiiiii
iiiiiiiii

2T2X2\2t2x2l:p:t:x:
0:4:8:<:@:D:H:L:P:T:X:\:`:d:h:l:p:t:x:|:
; ;$;(;,;0;4;8;<;@;D;H;L;P;T;X;\;`;d;h;l;p;t;x;|;
D0H0P0T0X0\0
1 10141D1H1L1T1l1p1
3(3<3_3v3
4$595Q5b5
6"6/6W6b6h6n6
7"7*747@7J7R7l7r7
828S8X8v8
9*:2:::D:S:`:f:p:
;";8;C;f;*<7<O<c<
="=K=]=
=F>M>o>v>
273@3m3
34'4:4E4J4Z4d4k4v4
435@5j5o5z5
5N6[6h6
1\2e2k2
3:3R3]3
4,4Q4d4|4
7$7N7\7b7
;8;=;L;U;b;m;
<$<*<8<?<D<M<Z<`<z<
1Z3e3m3
5[5m5s5
6*686M6W6}6
9 :P:b:
<*<1<I<
?E?K?V?b?w?~?
00,060=0U0d0k0x0
1F1L1h1
1 2C2M2
3 3&3.353:3B3K3W3\3a3g3k3q3v3|3
4$4*4F4y4
5(5A5y5
8%929<9J9S9]9
;T<`<s<
=(=O=x=
>?>X>_>g>l>p>t>
?N?T?X?\?`?
0!0K0}0
8j8p8x8
9`9k9u9
<#<0<<<D<L<X<|<
= =$=M=s=
>-?4?8?<?@?D?H?L?P?
= =&=-=4=;=B=I=P=W=_=g=o={=
0$060H0Z0
2%2,262>2K2R2
66$6<6B6Q6W6f6l6z6
7)7h7o7u7
99F9S9X9f9A:d:o:
4<5i5}5
9=:W:i:v:
2.2g2t2S3b3S4
4#5Z5d5
6$7/7]7k7z7
:U:_:w:
808P8p8
989X9t9x9
:(:H:d:h:
; ;D;P;X;
<$<(<H<h<t<
=0=P=p=x=
1$1,141<1D1L1T1\1d1l1t1
= =$=(=,=0=4=P=T=
> >$>(>,>0>@>H>L>P>T>X>\>`>d>h>l>x>0?4?
mscoree.dll
KERNEL32.DLL
(null)
((((( H
h(((( H
H
dahoyagedajamuhorero jeharitocuyegusurun jatoxameto rulujanasayogela jukocakete
gokuhipitevifoyiti moyapihaxuje diwukajavuhemeze kecosejokujosuyahacag
Vukohonobirotez
kernel32.dll
Nihehiremedumiy pezi bisanepexig piritotigihoj
kernel32.dll
Barebojegewak
tupatazajigozunosivuzatisozizituxewasekejayolacubevecosebujodeyopiludebozetufixedekamibenimuhebof
rosejuw
yodosutuzetanepapubu murerekezosazel xehuxogicaheriduxixolor
msimg32.dll
/ P6pL
,/KPip
/-P?pR
/ P6pL
,/KPip
/-P?pR
/ P6pL
,/KPip
/-P?pR
/ P6pL
,/KPip
/-P?pR
/ P6pL
,/KPip
/-P?pR
/ P6pL
,/KPip
/-P?pR
VS_VERSION_INFO
StringFileInfo
043831F2
InternalName
Holyday
FileDescription
Underweather
ProductsVersion
32.64.57.64
ProductName
GoldenSeg
ProductionVersion
90.26.1.43
VarFileInfo
Translation
OJefa vibolawam fezeretini xayuxibozos tuwocaxagiki fexohudameju hihutovusav weg$Yafeweratasodac decirelese tob magab
Kehacetifos tuzis&Sifokal sasay curukeyit jipuridamajelaLCey cetova deyel socalovojozo dehanovux koyurumohe jofev pebanef yixariduhix
Xehibijepu make8Nuhirikolekol sagudahale subim hafumesotig fetirebaxejom.Rizaze zoxuwi wejoxu sub nogalamepise wiwaremaGDehezemefufaxar vudohameruxaju xajovelusazeb tirafuy mucuz xosameramuzi
Fovagure
Xomoxeyesaj tet
BJutarejoyoyuc pogawujisucavov sudazupulu tosulekawojure jopazukaga
Cetohini
Hob muj
%Jifazu fufike wonigexoj tuhe poke cef
WZobosaxu momidoj gipis magoh mizomedafuda yewiwaxenebusa ruh fufohicoyowupa xajepol vod
Vakakif
Xaf pim mewad duw
Antivirus Signature
Bkav W32.AIDetectMalware
Lionic Trojan.Win32.Stealer.12!c
Elastic malicious (high confidence)
DrWeb Clean
MicroWorld-eScan Trojan.GenericKD.68190840
ClamAV Win.Packer.pkr_ce1a-9980177-0
FireEye Generic.mg.edc5c89d57bb8411
CAT-QuickHeal Clean
ALYac Clean
Cylance unsafe
VIPRE Clean
Sangfor Trojan.Win32.Save.a
K7AntiVirus Trojan ( 005a8b8b1 )
BitDefender Trojan.GenericKD.68190840
K7GW Trojan ( 005a8b8b1 )
Cybereason malicious.1a1f2a
BitDefenderTheta Clean
VirIT Clean
Cyren Clean
Symantec ML.Attribute.HighConfidence
tehtris Clean
ESET-NOD32 Win32/Smokeloader.F
APEX Malicious
Paloalto Clean
Cynet Malicious (score: 100)
Kaspersky Trojan-Spy.Win32.Stealer.eqlr
Alibaba Clean
NANO-Antivirus Clean
ViRobot Clean
Rising Trojan.Kryptik!1.B663 (CLASSIC)
Sophos Mal/Generic-S
F-Secure Trojan.TR/Kryptik.aclok
Baidu Clean
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition BehavesLike.Win32.Lockbit.dh
Trapmine suspicious.low.ml.score
CMC Clean
Emsisoft Trojan.GenericKD.68190840 (B)
SentinelOne Static AI - Malicious PE
GData Win32.Trojan-Downloader.SmokeLoader.NB26Q9
Jiangmin Clean
Webroot Clean
Avira TR/Kryptik.aclok
MAX malware (ai score=85)
Antiy-AVL Trojan/Win32.GenKryptik
Gridinsoft Ransom.Win32.Sabsik.ca
Xcitium Clean
Arcabit Trojan.Generic.D4108278
SUPERAntiSpyware Clean
ZoneAlarm Trojan-Spy.Win32.Stealer.eqlr
Microsoft Trojan:Win32/Azorult.FW!MTB
Google Detected
AhnLab-V3 Clean
Acronis suspicious
McAfee Artemis!EDC5C89D57BB
TACHYON Clean
DeepInstinct MALICIOUS
VBA32 Clean
Malwarebytes Trojan.MalPack.GS
Panda Trj/Chgt.AD
Zoner Clean
TrendMicro-HouseCall Clean
Tencent Trojan.Win32.Obfuscated.gen
Yandex Clean
Ikarus Trojan.Win32.SmokeLoader
MaxSecure Clean
Fortinet W32/GenKryptik.ERHN!tr
AVG Win32:CrypterX-gen [Trj]
Avast Win32:CrypterX-gen [Trj]
CrowdStrike win/malicious_confidence_100% (W)
No IRMA results available.