Static | ZeroBOX

PE Compile Time

2022-12-17 18:19:28

PDB Path

C:\fura.pdb

PE Imphash

0af0ab32fec6d387d477684bace95bf2

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x00032be8 0x00032c00 7.825997464
.data 0x00034000 0x0017c41c 0x00001800 1.89366446037
.rsrc 0x001b1000 0x000198c8 0x00019a00 4.55519406158
.reloc 0x001cb000 0x00002a0e 0x00002c00 2.30971205794

Resources

Name Offset Size Language Sub-language File type
RT_CURSOR 0x001ca048 0x000000b0 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_CURSOR 0x001ca048 0x000000b0 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_CURSOR 0x001ca048 0x000000b0 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_CURSOR 0x001ca048 0x000000b0 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_CURSOR 0x001ca048 0x000000b0 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_CURSOR 0x001ca048 0x000000b0 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_CURSOR 0x001ca048 0x000000b0 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_CURSOR 0x001ca048 0x000000b0 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x001c6068 0x00000468 LANG_PORTUGUESE SUBLANG_PORTUGUESE_BRAZILIAN GLS_BINARY_LSB_FIRST
RT_ICON 0x001c6068 0x00000468 LANG_PORTUGUESE SUBLANG_PORTUGUESE_BRAZILIAN GLS_BINARY_LSB_FIRST
RT_ICON 0x001c6068 0x00000468 LANG_PORTUGUESE SUBLANG_PORTUGUESE_BRAZILIAN GLS_BINARY_LSB_FIRST
RT_ICON 0x001c6068 0x00000468 LANG_PORTUGUESE SUBLANG_PORTUGUESE_BRAZILIAN GLS_BINARY_LSB_FIRST
RT_ICON 0x001c6068 0x00000468 LANG_PORTUGUESE SUBLANG_PORTUGUESE_BRAZILIAN GLS_BINARY_LSB_FIRST
RT_ICON 0x001c6068 0x00000468 LANG_PORTUGUESE SUBLANG_PORTUGUESE_BRAZILIAN GLS_BINARY_LSB_FIRST
RT_ICON 0x001c6068 0x00000468 LANG_PORTUGUESE SUBLANG_PORTUGUESE_BRAZILIAN GLS_BINARY_LSB_FIRST
RT_ICON 0x001c6068 0x00000468 LANG_PORTUGUESE SUBLANG_PORTUGUESE_BRAZILIAN GLS_BINARY_LSB_FIRST
RT_ICON 0x001c6068 0x00000468 LANG_PORTUGUESE SUBLANG_PORTUGUESE_BRAZILIAN GLS_BINARY_LSB_FIRST
RT_ICON 0x001c6068 0x00000468 LANG_PORTUGUESE SUBLANG_PORTUGUESE_BRAZILIAN GLS_BINARY_LSB_FIRST
RT_ICON 0x001c6068 0x00000468 LANG_PORTUGUESE SUBLANG_PORTUGUESE_BRAZILIAN GLS_BINARY_LSB_FIRST
RT_ICON 0x001c6068 0x00000468 LANG_PORTUGUESE SUBLANG_PORTUGUESE_BRAZILIAN GLS_BINARY_LSB_FIRST
RT_ICON 0x001c6068 0x00000468 LANG_PORTUGUESE SUBLANG_PORTUGUESE_BRAZILIAN GLS_BINARY_LSB_FIRST
RT_ICON 0x001c6068 0x00000468 LANG_PORTUGUESE SUBLANG_PORTUGUESE_BRAZILIAN GLS_BINARY_LSB_FIRST
RT_ICON 0x001c6068 0x00000468 LANG_PORTUGUESE SUBLANG_PORTUGUESE_BRAZILIAN GLS_BINARY_LSB_FIRST
RT_ICON 0x001c6068 0x00000468 LANG_PORTUGUESE SUBLANG_PORTUGUESE_BRAZILIAN GLS_BINARY_LSB_FIRST
RT_ICON 0x001c6068 0x00000468 LANG_PORTUGUESE SUBLANG_PORTUGUESE_BRAZILIAN GLS_BINARY_LSB_FIRST
RT_ICON 0x001c6068 0x00000468 LANG_PORTUGUESE SUBLANG_PORTUGUESE_BRAZILIAN GLS_BINARY_LSB_FIRST
RT_ICON 0x001c6068 0x00000468 LANG_PORTUGUESE SUBLANG_PORTUGUESE_BRAZILIAN GLS_BINARY_LSB_FIRST
RT_ICON 0x001c6068 0x00000468 LANG_PORTUGUESE SUBLANG_PORTUGUESE_BRAZILIAN GLS_BINARY_LSB_FIRST
RT_ICON 0x001c6068 0x00000468 LANG_PORTUGUESE SUBLANG_PORTUGUESE_BRAZILIAN GLS_BINARY_LSB_FIRST
RT_ICON 0x001c6068 0x00000468 LANG_PORTUGUESE SUBLANG_PORTUGUESE_BRAZILIAN GLS_BINARY_LSB_FIRST
RT_ICON 0x001c6068 0x00000468 LANG_PORTUGUESE SUBLANG_PORTUGUESE_BRAZILIAN GLS_BINARY_LSB_FIRST
RT_STRING 0x001ca760 0x00000166 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_STRING 0x001ca760 0x00000166 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_GROUP_CURSOR 0x001ca0f8 0x00000022 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_GROUP_CURSOR 0x001ca0f8 0x00000022 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_GROUP_CURSOR 0x001ca0f8 0x00000022 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_GROUP_ICON 0x001c64d0 0x00000076 LANG_PORTUGUESE SUBLANG_PORTUGUESE_BRAZILIAN data
RT_GROUP_ICON 0x001c64d0 0x00000076 LANG_PORTUGUESE SUBLANG_PORTUGUESE_BRAZILIAN data
RT_GROUP_ICON 0x001c64d0 0x00000076 LANG_PORTUGUESE SUBLANG_PORTUGUESE_BRAZILIAN data
RT_GROUP_ICON 0x001c64d0 0x00000076 LANG_PORTUGUESE SUBLANG_PORTUGUESE_BRAZILIAN data
RT_VERSION 0x001ca120 0x00000208 LANG_NEUTRAL SUBLANG_NEUTRAL data

Imports

Library KERNEL32.dll:
0x401000 GetComputerNameA
0x401004 CreateMutexW
0x401008 FindResourceA
0x40100c EnumCalendarInfoA
0x401010 lstrlenA
0x401018 EnumDateFormatsExW
0x40101c AddConsoleAliasW
0x401020 SetTapeParameters
0x401024 GetModuleHandleW
0x401028 GetTickCount
0x40102c GetConsoleAliasesA
0x401034 GlobalAlloc
0x401038 LoadLibraryW
0x40103c ReadConsoleInputA
0x401040 CopyFileW
0x401044 ReadFile
0x401048 GetVolumePathNameA
0x40104c DisconnectNamedPipe
0x401050 GetProfileIntA
0x401058 GetLastError
0x40105c SetLastError
0x401060 GetProcAddress
0x401068 IsValidCodePage
0x401070 LoadLibraryA
0x401074 OpenMutexA
0x401078 CreateHardLinkW
0x40107c lstrcmpiW
0x401080 SetLocaleInfoW
0x401084 CreateMutexA
0x40108c _lopen
0x401090 GetVersionExA
0x401098 AddConsoleAliasA
0x40109c lstrcpyA
0x4010a0 CreateFileA
0x4010a4 CloseHandle
0x4010a8 WriteConsoleW
0x4010ac GetConsoleOutputCP
0x4010b0 WriteConsoleA
0x4010b4 SetStdHandle
0x4010b8 FlushFileBuffers
0x4010c4 Sleep
0x4010e0 HeapFree
0x4010e4 MultiByteToWideChar
0x4010e8 ExitProcess
0x4010ec GetStartupInfoW
0x4010f0 RtlUnwind
0x4010f4 RaiseException
0x4010f8 WriteFile
0x4010fc GetStdHandle
0x401100 GetModuleFileNameA
0x401104 HeapAlloc
0x401108 HeapCreate
0x40110c VirtualFree
0x401110 VirtualAlloc
0x401114 HeapReAlloc
0x401118 SetHandleCount
0x40111c GetFileType
0x401120 GetStartupInfoA
0x401124 TerminateProcess
0x401128 GetCurrentProcess
0x40112c IsDebuggerPresent
0x401130 TlsGetValue
0x401134 TlsAlloc
0x401138 TlsSetValue
0x40113c TlsFree
0x401140 GetCurrentThreadId
0x401144 HeapSize
0x401148 GetCPInfo
0x40114c GetACP
0x401150 GetOEMCP
0x401158 GetModuleFileNameW
0x401164 GetCommandLineW
0x40116c GetCurrentProcessId
0x401174 GetLocaleInfoA
0x401178 GetStringTypeA
0x40117c GetStringTypeW
0x401180 SetFilePointer
0x401184 WideCharToMultiByte
0x401188 GetConsoleCP
0x40118c GetConsoleMode
0x401190 LCMapStringA
0x401194 LCMapStringW
Library USER32.dll:
0x40119c EnumDesktopWindows
0x4011a0 CharToOemBuffA
0x4011a4 GetMenuBarInfo
0x4011a8 CharLowerBuffW
0x4011ac CharUpperBuffA
0x4011b0 LoadMenuW
0x4011b4 CharUpperW
0x4011b8 LoadBitmapW
0x4011bc DdeQueryStringA
0x4011c0 SetClipboardViewer

!This program cannot be run in DOS mode.
`.data
@.reloc
bad allocation
Unknown exception
CorExitProcess
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
runtime error
TLOSS error
SING error
DOMAIN error
An application has made an attempt to load the C runtime library incorrectly.
Please contact the application's support team for more information.
- Attempt to use MSIL code from this assembly during native code initialization
This indicates a bug in your application. It is most likely the result of calling an MSIL-compiled (/clr) function from a native constructor or from DllMain.
- not enough space for locale information
- Attempt to initialize the CRT more than once.
This indicates a bug in your application.
- CRT not initialized
- unable to initialize heap
- not enough space for lowio initialization
- not enough space for stdio initialization
- pure virtual function call
- not enough space for _onexit/atexit table
- unable to open console device
- unexpected heap error
- unexpected multithread lock error
- not enough space for thread data
This application has requested the Runtime to terminate it in an unusual way.
Please contact the application's support team for more information.
- not enough space for environment
- not enough space for arguments
- floating point support not loaded
Microsoft Visual C++ Runtime Library
<program name unknown>
Runtime Error!
Program:
EncodePointer
DecodePointer
FlsFree
FlsSetValue
FlsGetValue
FlsAlloc
(null)
`h````
xpxxxx
bad exception
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
HH:mm:ss
dddd, MMMM dd, yyyy
MM/dd/yy
December
November
October
September
August
February
January
Saturday
Friday
Thursday
Wednesday
Tuesday
Monday
Sunday
GetProcessWindowStation
GetUserObjectInformationA
GetLastActivePopup
GetActiveWindow
MessageBoxA
USER32.DLL
`h`hhh
xppwpp
Complete Object Locator'
Class Hierarchy Descriptor'
Base Class Array'
Base Class Descriptor at (
Type Descriptor'
`local static thread guard'
`managed vector copy constructor iterator'
`vector vbase copy constructor iterator'
`vector copy constructor iterator'
`dynamic atexit destructor for '
`dynamic initializer for '
`eh vector vbase copy constructor iterator'
`eh vector copy constructor iterator'
`managed vector destructor iterator'
`managed vector constructor iterator'
`placement delete[] closure'
`placement delete closure'
`omni callsig'
delete[]
new[]
`local vftable constructor closure'
`local vftable'
`udt returning'
`copy constructor closure'
`eh vector vbase constructor iterator'
`eh vector destructor iterator'
`eh vector constructor iterator'
`virtual displacement map'
`vector vbase constructor iterator'
`vector destructor iterator'
`vector constructor iterator'
`scalar deleting destructor'
`default constructor closure'
`vector deleting destructor'
`vbase destructor'
`string'
`local static guard'
`typeof'
`vcall'
`vbtable'
`vftable'
operator
delete
__unaligned
__restrict
__ptr64
__clrcall
__fastcall
__thiscall
__stdcall
__pascal
__cdecl
__based(
SunMonTueWedThuFriSat
JanFebMarAprMayJunJulAugSepOctNovDec
CONOUT$
bad allocation
xucebugafukuwuvekesacubupopijege
%s %f %c
VirtualProtect
nosagonexefohutu hopavedul suvedofosayatujuketujav
kesitakopumo
C:\fura.pdb
D$(1D$
L$ _^]
QQSVWd
to=HNC
0SSSSS
r=xFC
jTh0-C
j@j ^V
0A@@Ju
>=Yt1j
QQSVWh
j,h@/C
HtHu4j
s[S;7|G;w
tR99u2
v$;5lNC
0SSSSS
PPPPPPPP
0SSSSS
PPPPPPPP
URPQQh,
uL9=8cC
t"SS9]
0WWWWW
AAFFf;
;t$,v-
UQPXY]Y[
t+WWVPV
7BE0B;
gDLzp
hfUKEbU
A+LmCm
}c-L:W
RP=z&c
G>]'\?
E):hFo
x&|4n6
kBRdVSkD
>,$?=4
Wk@+e(pzC
8o"4Vw
jkf8T$
"D*lqa
I(XczW
maR`yV
1#/6eV
mdy{ph
VI.5$J
w#Ij;>
,Z,'VJ
T*^w;,
M$iHvy
;Ghh.'
1>v=]z
m.+u!@
nM*or*
Zb+/P4f
`L6`O^g
)mLW+Z
vffN%[
5v0B^f
{f5S9C,
7' TlFy
.g9JkL7
%]kE,gP
?#Zt[ <
mKf=:>
77>H&sa
-!B'~4
x k{ 1
P7KESwK(i
QY8n'1
A{P6c;
eKe|IT(
/q&|QV\
6)wI#A
4g$kN2
N\/17VT
'LQ?NT
Ro])5/
j[.nO>
W3cLo$
/ ?t`B
"8';U\
1@oIu=g
kL=5rX
h(rQR9
swe,Dxh
*$CQdF
?JTg^s
&{SAUd
+rna$j
J8y{Kms
xw5v<o3_
aMVoK6y
/\I0X
M$$-}a
9x}^r8E
Ej\mci
4\)Cg`o
4H9"{R
Lk\?&p
*:`]"u;z
m4>,zn
%;H?PU
o@>a|u
'8O01#
reo4:S
Ai3b)C
'|X4~|
F-4/??
$\a,CfW
{#6iG6
s[(en,
C=My17
3_x3WP
S_z&b-
^+l_$
]-AZ>X
bI/G[_
SX+DEyz
Mh5uyuz
WBgN`A
ry,%bG
e'75]C
L$#(+]f*
?h-xXq86
+9oY~]
hiZ8z)
M?s,no
pkDS^>
->YIK_
=u7jJt
sQ:W]J
{Ai xh
$t|.ARo
5hLAXB
8XCRjpPA
V;6eUu
`%p-aCu
NU]4Q3K
#P;#W^
DWzPu.gM+
b_rrG
LR.aFs
mQ3Nf5
fb24L2
Q9\.'x
YP$PW58:
R3GgR{
\7$m7[-2
)(U8A>
06}-v-
Xje}+/
1>E6_l<
dG-5l'
ISPaGosW
<,2|hy
&3xvSK[U3
37*_IPXy
uM<&k2`
Q@+$-~j
TcC+hp
Um/D_P
2948s9
Ad3bqi
UkS'}iXf
0(,4<0
~0cfu$-h
I/LtZ
FtMC/u
g.c3nq
I1BX{(He
5=.5&7[
G=P+ /Q
_Ay7bPo;g
'7MBYx@
N%(Tt#*;xP|A
M>G{0
!Pq9yw;
Mr1y=R
Y|qw{O
9F;Yq{0zvi
Bz]{I'FH4
2(8pj~
*+CWq9"
*W|:82
ik 7r;|
nHyPNnR)W
:}qPoxOmby
mtCn:U
RB'1Yu|
s.n$Na
};G)h:<
LX9Mz>Zix
9!,:Dc
y0tGIuZ
;B8rzK2
eatM~z
S==\uCT
%w+y;~$_v
[vcg^/]U(W
;{&()N
SaC~mJ
l/mh9^
\dZOpE
j\kyjj
m'N[+"T
D4jXl-
[gcuhLx
87=>8s`
e!nb[=xk
h!A,NL
F'n=Mr
bRH(R'
2&J|VH
A'd!s5
+QXU@,3R 4
jAD^/
y:}13][
h";Jnu
SRjd#x
8;<01`
6"Q:m/v
;+@T/G
0Kk,)eL@
T^TaMz}G
4Q 2I<
%8De_n8=
]&|'J-
{E(n_L5
H_TwO]
'*,7e_
0e,?'4
.{XuZq
N~T]8g
85_c>V
S778w-
6!#b@1!
)K3}^
ck>s]}'
W*O(JKT
|sXC~9
)~Li+4>4#
O7KUT_I
c926l$
p I*Ax
CQ2$oqg
Ol<8U<
p~>$";
EGY~br0
7%6d#O
c6GsW)
ri;X^$
U*+2_F
|{K,a,
u<5>1
UQ5I6H
:d<gEo
`@E9fW
@\iLe^
s.-BF9
+X(X-%+
`Zk]d.
I2$J1q
x~UNQ4
`@?caY}6w
,QXv 2
iIi}H7
$vGk{^
<?J$WY!
7+qn_[#
ty95h0
l>TF&
GetComputerNameA
CreateMutexW
FindResourceA
EnumCalendarInfoA
lstrlenA
GetConsoleAliasesLengthW
EnumDateFormatsExW
AddConsoleAliasW
SetTapeParameters
GetModuleHandleW
GetTickCount
GetConsoleAliasesA
GetWindowsDirectoryA
GlobalAlloc
LoadLibraryW
ReadConsoleInputA
CopyFileW
ReadFile
GetVolumePathNameA
DisconnectNamedPipe
GetProfileIntA
SetCurrentDirectoryA
GetLastError
SetLastError
GetProcAddress
BeginUpdateResourceW
IsValidCodePage
EnumSystemCodePagesW
LoadLibraryA
OpenMutexA
CreateHardLinkW
lstrcmpiW
SetLocaleInfoW
CreateMutexA
SetProcessShutdownParameters
_lopen
GetVersionExA
FileTimeToLocalFileTime
AddConsoleAliasA
lstrcpyA
KERNEL32.dll
SetClipboardViewer
DdeQueryStringA
LoadBitmapW
CharUpperW
LoadMenuW
CharUpperBuffA
CharLowerBuffW
GetMenuBarInfo
CharToOemBuffA
EnumDesktopWindows
USER32.dll
InterlockedIncrement
InterlockedDecrement
InitializeCriticalSection
DeleteCriticalSection
EnterCriticalSection
LeaveCriticalSection
UnhandledExceptionFilter
SetUnhandledExceptionFilter
HeapFree
MultiByteToWideChar
ExitProcess
GetStartupInfoW
RtlUnwind
RaiseException
WriteFile
GetStdHandle
GetModuleFileNameA
HeapAlloc
HeapCreate
VirtualFree
VirtualAlloc
HeapReAlloc
SetHandleCount
GetFileType
GetStartupInfoA
TerminateProcess
GetCurrentProcess
IsDebuggerPresent
TlsGetValue
TlsAlloc
TlsSetValue
TlsFree
GetCurrentThreadId
HeapSize
GetCPInfo
GetACP
GetOEMCP
InitializeCriticalSectionAndSpinCount
GetModuleFileNameW
FreeEnvironmentStringsW
GetEnvironmentStringsW
GetCommandLineW
QueryPerformanceCounter
GetCurrentProcessId
GetSystemTimeAsFileTime
GetLocaleInfoA
GetStringTypeA
GetStringTypeW
SetFilePointer
WideCharToMultiByte
GetConsoleCP
GetConsoleMode
LCMapStringA
LCMapStringW
FlushFileBuffers
SetStdHandle
WriteConsoleA
GetConsoleOutputCP
WriteConsoleW
CloseHandle
CreateFileA
Copyright (c) 1992-2004 by P.J. Plauger, licensed by Dinkumware, Ltd. ALL RIGHTS RESERVED.
.?AVtype_info@@
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
.?AVbad_exception@std@@
.?AVexception@std@@
'%')%%
%*%%%%
55":8
;<<!#::(
+':6237304+
JSa_lj[d\YYX^[ZZgVVWZUQF)
%9GED<IFEE+
;@?#:6+
:EKIIJNNQUVYN+
Dirf`dbhhadeac_P+'
Wuqkssnwzs{}
&0@C=RQSY^X>7-.
+Q][T;
MMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMM
MMMMMMMMMMMMMMMMMMMMQ
V;MMMMMMMMMMMMMMMMMMw
MMMMMMMMMMMMMMMM.l
MMMMMMMMMMMMMMMu3
0^MMMMMMMMMMMMMM
K5MMMMMMMMMMMMMMM
MMMMMMMMMMMMMMM5%
wMMMMMMMMMMM-{
LMMMMMMMMMM{n
8MMMMMMMMMM
MMMMMMMMMMMM
MMMMMMMMMMMM{F
gMMMMMMMMMMMMM{
MMMMMMMMMMMM
MMM{}a
MMMMMMMMMMMM
&MMMMM
{MMMMMMMMMMMMMMMMMM{
JDMMMMMMMMMMMMMMMMMM-{
MMMMMMMMMMMMMMMMMM{
MMMMMMMMMMMMMMMMMM
ZMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMM
Df}-0"g"
t.<.^s
4~X/^OwF*^
/O4<Ez
kkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkk
YkkknzL
kkkkku$
Ckkkkkk;
kkkkkkk
kkkkkkk
kkkkkkkk
kkkkkkkkkk
w`kkkkkkkk
:::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::
]))))nnyV
jMjk$t
:::::::::::::::::
::::::::::::::::
8$>:::::::::::::::
:::::::::::::::
:::::::::::::::
:::::::::::::::
:::::::::::::::
:::::::::::::::(
:::::::::::::::wk
:::::::::::::::w
:::::::::::::::(
>:::::::::::::::(y
>:::::::::::::::t
>:::::::::::::::(T
>:::::::::::::::t
>:::::::::::::::tj3
>:::::::::::::::tyA&v
::::::::::::::::t
::::::::::::::::
::::::::::::::::hj
::::::::::::::::hy
8f__M_M
::::::::::::::::hT
::::::::::::::::h
^::::::::::::::::$y
::::::::::::::::h6
::::::::::::::::$f
::::::::::::::::$
4::::::::::::::::
::::::::::::::::$y
#p::::::::::::::::
::::::::::::::::^6L
::::::::::::::::^y
+Er<X|
::::::::::::::::
4::::::::::::::::4n52Hr7
::::::::::::::::
::::::::::::::::pV
::::::::::::::::
VsssJJ
V4::::::::::::::::^
:::::::::::::::::^
:::::::::::::::::
*m{***
::::::::::::::::::>>^M
p'(::::::::::::::::::::>>>
(:::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::
wwwwwwwwwww
Ywwwwwwwwwww
wwwwwwwwwww
wwwwwwwwwww
wwwwwwwwwwwxS
wwwwwwwwwww
jwwwwwwwwwwwx
wwwwwwwwwww
wwwwwwwwwww
gwwwwwwwwwww{
gwwwwwwwwwww
wwwwwwwwwwwx3
wwwwwwwwwww
wwwwwwwwwwwx
iwwwwwwwwwwwx}
wwwwwwwwwww
H_H_q_H__
wwwwwwwwwww
iwwwwwwwwwww
iwwwwwwwwwww
wwwwwwwwwww
wwwwwwwwwww
wwwwwwwwwwwd
wwwwwwwwwww
wwwwwwwwwwwPQ
wwwwwwwwwww
wwwwwwwwwww
wwwwwwwwwwwwwwwwww++++
wwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwww
/LLm
/
9
WT

WT>


{






W

Y

Jxxxxxx
Fxxxxx^
#8#-xxxxx
|xxxxx<
?xxxxxL
eIxxxxxf[C
xxxxx$
_xxxxxp
P\*xxxxx
xxxxxD
+Yxxxxx}
7bxxxxx
xxxxxx
~~~~~~
iiiiiiii
iiiiiiii
iiiiii
iiiiii
iiiiiiiii
iiiiiiiiii
iiiiiiii
iiiiiii
iiiiiiiii

2T2X2\2t2x2l:p:t:x:
0:4:8:<:@:D:H:L:P:T:X:\:`:d:h:l:p:t:x:|:
; ;$;(;,;0;4;8;<;@;D;H;L;P;T;X;\;`;d;h;l;p;t;x;|;
D0H0P0T0X0\0
1 10141D1H1L1T1l1p1
3(3<3_3v3
4$595Q5b5
6"6/6W6b6h6n6
7"7*747@7J7R7l7r7
828S8X8v8
9*:2:::D:S:`:f:p:
;";8;C;f;*<7<O<c<
="=K=]=
=F>M>o>v>
273@3m3
34'4:4E4J4Z4d4k4v4
435@5j5o5z5
5N6[6h6
1\2e2k2
3:3R3]3
4,4Q4d4|4
7$7N7\7b7
;8;=;L;U;b;m;
<$<*<8<?<D<M<Z<`<z<
1Z3e3m3
5[5m5s5
6*686M6W6}6
9 :P:b:
<*<1<I<
?E?K?V?b?w?~?
00,060=0U0d0k0x0
1F1L1h1
1 2C2M2
3 3&3.353:3B3K3W3\3a3g3k3q3v3|3
4$4*4F4y4
5(5A5y5
8%929<9J9S9]9
;T<`<s<
=(=O=x=
>?>X>_>g>l>p>t>
?N?T?X?\?`?
0!0K0}0
8j8p8x8
9`9k9u9
<#<0<<<D<L<X<|<
= =$=M=s=
>-?4?8?<?@?D?H?L?P?
= =&=-=4=;=B=I=P=W=_=g=o={=
0$060H0Z0
2%2,262>2K2R2
66$6<6B6Q6W6f6l6z6
7)7h7o7u7
99F9S9X9f9A:d:o:
4<5i5}5
9=:W:i:v:
2.2g2t2S3b3S4
4#5Z5d5
6$7/7]7k7z7
:U:_:w:
2;L;l;v;
< <@<`<
=(=D=H=h=t=
>4>8>T>X>t>x>
? ?(?X?`?d?|?
080D0`0
1 1@1H1\1d1x1
1$1,141<1D1L1T1\1d1l1t1
= =$=(=,=0=4=P=T=
> >$>(>,>0>@>H>L>P>T>X>\>`>d>h>l>x>0?4?
mscoree.dll
KERNEL32.DLL
(null)
((((( H
h(((( H
H
dahoyagedajamuhorero jeharitocuyegusurun jatoxameto rulujanasayogela jukocakete
gokuhipitevifoyiti moyapihaxuje diwukajavuhemeze kecosejokujosuyahacag
Vukohonobirotez
kernel32.dll
Nihehiremedumiy pezi bisanepexig piritotigihoj
kernel32.dll
Barebojegewak
tupatazajigozunosivuzatisozizituxewasekejayolacubevecosebujodeyopiludebozetufixedekamibenimuhebof
rosejuw
yodosutuzetanepapubu murerekezosazel xehuxogicaheriduxixolor
msimg32.dll
/ P6pL
,/KPip
/-P?pR
/ P6pL
,/KPip
/-P?pR
/ P6pL
,/KPip
/-P?pR
/ P6pL
,/KPip
/-P?pR
/ P6pL
,/KPip
/-P?pR
/ P6pL
,/KPip
/-P?pR
VS_VERSION_INFO
StringFileInfo
043831F2
InternalName
Holyday
FileDescription
Underweather
ProductsVersion
32.64.57.64
ProductName
GoldenSeg
ProductionVersion
90.26.1.43
VarFileInfo
Translation
OJefa vibolawam fezeretini xayuxibozos tuwocaxagiki fexohudameju hihutovusav weg$Yafeweratasodac decirelese tob magab
Kehacetifos tuzis&Sifokal sasay curukeyit jipuridamajelaLCey cetova deyel socalovojozo dehanovux koyurumohe jofev pebanef yixariduhix
Xehibijepu make8Nuhirikolekol sagudahale subim hafumesotig fetirebaxejom.Rizaze zoxuwi wejoxu sub nogalamepise wiwaremaGDehezemefufaxar vudohameruxaju xajovelusazeb tirafuy mucuz xosameramuzi
Fovagure
Xomoxeyesaj tet
BJutarejoyoyuc pogawujisucavov sudazupulu tosulekawojure jopazukaga
Cetohini
Hob muj
%Jifazu fufike wonigexoj tuhe poke cef
WZobosaxu momidoj gipis magoh mizomedafuda yewiwaxenebusa ruh fufohicoyowupa xajepol vod
Vakakif
Xaf pim mewad duw
Antivirus Signature
Bkav W32.AIDetectMalware
Lionic Trojan.Win32.GCleaner.4!c
tehtris Clean
DrWeb Clean
MicroWorld-eScan Trojan.GenericKD.68190777
FireEye Generic.mg.188332f8d2291317
CAT-QuickHeal Ransom.Stop.P5
ALYac Clean
Malwarebytes Trojan.MalPack.GS
VIPRE Trojan.GenericKD.68191130
Sangfor Ransom.Win32.Save.a
K7AntiVirus Clean
BitDefender Trojan.GenericKD.68190777
K7GW Clean
CrowdStrike win/malicious_confidence_100% (W)
BitDefenderTheta Clean
VirIT Clean
Cyren W32/ABRisk.UVCS-0702
Symantec ML.Attribute.HighConfidence
Elastic malicious (high confidence)
ESET-NOD32 a variant of Win32/GenKryptik.GLVX
APEX Malicious
Paloalto Clean
ClamAV Win.Packer.pkr_ce1a-9980177-0
Kaspersky HEUR:Trojan-Downloader.Win32.GCleaner.gen
Alibaba Clean
NANO-Antivirus Clean
ViRobot Clean
Rising Trojan.Kryptik!1.B663 (CLASSIC)
TACHYON Clean
Sophos Mal/Generic-S
F-Secure Trojan.TR/Kryptik.fecqb
Baidu Clean
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition BehavesLike.Win32.Lockbit.fh
Trapmine suspicious.low.ml.score
CMC Clean
Emsisoft Trojan.GenericKD.68190777 (B)
Ikarus Trojan.Win32.Krypt
GData Win32.Trojan.GleaMal.9TOCQN
Jiangmin Clean
Webroot Clean
Google Detected
Avira TR/Kryptik.fecqb
Antiy-AVL Trojan/Win32.GenKryptik
Gridinsoft Malware.Win32.Gen.bot
Xcitium Clean
Arcabit Trojan.Generic.D4108239
SUPERAntiSpyware Clean
ZoneAlarm HEUR:Trojan-Downloader.Win32.GCleaner.gen
Microsoft Ransom:Win32/LockbitCrypt.SV!MTB
Cynet Malicious (score: 100)
AhnLab-V3 Clean
Acronis suspicious
McAfee Artemis!188332F8D229
MAX malware (ai score=80)
DeepInstinct MALICIOUS
VBA32 Clean
Cylance unsafe
Panda Trj/Chgt.AD
Zoner Clean
TrendMicro-HouseCall TROJ_GEN.R002H0CGF23
Tencent Trojan.Win32.Obfuscated.gen
Yandex Clean
SentinelOne Static AI - Malicious PE
MaxSecure Clean
Fortinet W32/GenKryptik.ERHN!tr
AVG Win32:CrypterX-gen [Trj]
Cybereason malicious.876946
Avast Win32:CrypterX-gen [Trj]
No IRMA results available.