Static | ZeroBOX

PE Compile Time

2022-09-20 03:18:57

PDB Path

C:\zocaka_wobihos\zaliwufanamin-xosusemof\81\duner.pdb

PE Imphash

990ed3e722a6c734f32b219aae1f4a33

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x00021aa8 0x00021c00 7.66086449718
.data 0x00023000 0x0014b6dc 0x00001800 1.89753609045
.rsrc 0x0016f000 0x000283f8 0x00028400 4.1233946715
.reloc 0x00198000 0x00002818 0x00002a00 2.40702179162

Resources

Name Offset Size Language Sub-language File type
RT_CURSOR 0x001965f8 0x00000568 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_CURSOR 0x001965f8 0x00000568 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_CURSOR 0x001965f8 0x00000568 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_CURSOR 0x001965f8 0x00000568 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_CURSOR 0x001965f8 0x00000568 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_CURSOR 0x001965f8 0x00000568 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_CURSOR 0x001965f8 0x00000568 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_CURSOR 0x001965f8 0x00000568 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_CURSOR 0x001965f8 0x00000568 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_CURSOR 0x001965f8 0x00000568 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_CURSOR 0x001965f8 0x00000568 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x00190df0 0x00000468 LANG_PORTUGUESE SUBLANG_PORTUGUESE_BRAZILIAN GLS_BINARY_LSB_FIRST
RT_ICON 0x00190df0 0x00000468 LANG_PORTUGUESE SUBLANG_PORTUGUESE_BRAZILIAN GLS_BINARY_LSB_FIRST
RT_ICON 0x00190df0 0x00000468 LANG_PORTUGUESE SUBLANG_PORTUGUESE_BRAZILIAN GLS_BINARY_LSB_FIRST
RT_ICON 0x00190df0 0x00000468 LANG_PORTUGUESE SUBLANG_PORTUGUESE_BRAZILIAN GLS_BINARY_LSB_FIRST
RT_ICON 0x00190df0 0x00000468 LANG_PORTUGUESE SUBLANG_PORTUGUESE_BRAZILIAN GLS_BINARY_LSB_FIRST
RT_ICON 0x00190df0 0x00000468 LANG_PORTUGUESE SUBLANG_PORTUGUESE_BRAZILIAN GLS_BINARY_LSB_FIRST
RT_ICON 0x00190df0 0x00000468 LANG_PORTUGUESE SUBLANG_PORTUGUESE_BRAZILIAN GLS_BINARY_LSB_FIRST
RT_ICON 0x00190df0 0x00000468 LANG_PORTUGUESE SUBLANG_PORTUGUESE_BRAZILIAN GLS_BINARY_LSB_FIRST
RT_ICON 0x00190df0 0x00000468 LANG_PORTUGUESE SUBLANG_PORTUGUESE_BRAZILIAN GLS_BINARY_LSB_FIRST
RT_ICON 0x00190df0 0x00000468 LANG_PORTUGUESE SUBLANG_PORTUGUESE_BRAZILIAN GLS_BINARY_LSB_FIRST
RT_ICON 0x00190df0 0x00000468 LANG_PORTUGUESE SUBLANG_PORTUGUESE_BRAZILIAN GLS_BINARY_LSB_FIRST
RT_ICON 0x00190df0 0x00000468 LANG_PORTUGUESE SUBLANG_PORTUGUESE_BRAZILIAN GLS_BINARY_LSB_FIRST
RT_ICON 0x00190df0 0x00000468 LANG_PORTUGUESE SUBLANG_PORTUGUESE_BRAZILIAN GLS_BINARY_LSB_FIRST
RT_ICON 0x00190df0 0x00000468 LANG_PORTUGUESE SUBLANG_PORTUGUESE_BRAZILIAN GLS_BINARY_LSB_FIRST
RT_ICON 0x00190df0 0x00000468 LANG_PORTUGUESE SUBLANG_PORTUGUESE_BRAZILIAN GLS_BINARY_LSB_FIRST
RT_ICON 0x00190df0 0x00000468 LANG_PORTUGUESE SUBLANG_PORTUGUESE_BRAZILIAN GLS_BINARY_LSB_FIRST
RT_ICON 0x00190df0 0x00000468 LANG_PORTUGUESE SUBLANG_PORTUGUESE_BRAZILIAN GLS_BINARY_LSB_FIRST
RT_ICON 0x00190df0 0x00000468 LANG_PORTUGUESE SUBLANG_PORTUGUESE_BRAZILIAN GLS_BINARY_LSB_FIRST
RT_ICON 0x00190df0 0x00000468 LANG_PORTUGUESE SUBLANG_PORTUGUESE_BRAZILIAN GLS_BINARY_LSB_FIRST
RT_ICON 0x00190df0 0x00000468 LANG_PORTUGUESE SUBLANG_PORTUGUESE_BRAZILIAN GLS_BINARY_LSB_FIRST
RT_ICON 0x00190df0 0x00000468 LANG_PORTUGUESE SUBLANG_PORTUGUESE_BRAZILIAN GLS_BINARY_LSB_FIRST
RT_ICON 0x00190df0 0x00000468 LANG_PORTUGUESE SUBLANG_PORTUGUESE_BRAZILIAN GLS_BINARY_LSB_FIRST
RT_ICON 0x00190df0 0x00000468 LANG_PORTUGUESE SUBLANG_PORTUGUESE_BRAZILIAN GLS_BINARY_LSB_FIRST
RT_ICON 0x00190df0 0x00000468 LANG_PORTUGUESE SUBLANG_PORTUGUESE_BRAZILIAN GLS_BINARY_LSB_FIRST
RT_ICON 0x00190df0 0x00000468 LANG_PORTUGUESE SUBLANG_PORTUGUESE_BRAZILIAN GLS_BINARY_LSB_FIRST
RT_ICON 0x00190df0 0x00000468 LANG_PORTUGUESE SUBLANG_PORTUGUESE_BRAZILIAN GLS_BINARY_LSB_FIRST
RT_ICON 0x00190df0 0x00000468 LANG_PORTUGUESE SUBLANG_PORTUGUESE_BRAZILIAN GLS_BINARY_LSB_FIRST
RT_ICON 0x00190df0 0x00000468 LANG_PORTUGUESE SUBLANG_PORTUGUESE_BRAZILIAN GLS_BINARY_LSB_FIRST
RT_ICON 0x00190df0 0x00000468 LANG_PORTUGUESE SUBLANG_PORTUGUESE_BRAZILIAN GLS_BINARY_LSB_FIRST
RT_ICON 0x00190df0 0x00000468 LANG_PORTUGUESE SUBLANG_PORTUGUESE_BRAZILIAN GLS_BINARY_LSB_FIRST
RT_ICON 0x00190df0 0x00000468 LANG_PORTUGUESE SUBLANG_PORTUGUESE_BRAZILIAN GLS_BINARY_LSB_FIRST
RT_ICON 0x00190df0 0x00000468 LANG_PORTUGUESE SUBLANG_PORTUGUESE_BRAZILIAN GLS_BINARY_LSB_FIRST
RT_ICON 0x00190df0 0x00000468 LANG_PORTUGUESE SUBLANG_PORTUGUESE_BRAZILIAN GLS_BINARY_LSB_FIRST
RT_ICON 0x00190df0 0x00000468 LANG_PORTUGUESE SUBLANG_PORTUGUESE_BRAZILIAN GLS_BINARY_LSB_FIRST
RT_ICON 0x00190df0 0x00000468 LANG_PORTUGUESE SUBLANG_PORTUGUESE_BRAZILIAN GLS_BINARY_LSB_FIRST
RT_ICON 0x00190df0 0x00000468 LANG_PORTUGUESE SUBLANG_PORTUGUESE_BRAZILIAN GLS_BINARY_LSB_FIRST
RT_ICON 0x00190df0 0x00000468 LANG_PORTUGUESE SUBLANG_PORTUGUESE_BRAZILIAN GLS_BINARY_LSB_FIRST
RT_ICON 0x00190df0 0x00000468 LANG_PORTUGUESE SUBLANG_PORTUGUESE_BRAZILIAN GLS_BINARY_LSB_FIRST
RT_STRING 0x00197258 0x000001a0 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_STRING 0x00197258 0x000001a0 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_GROUP_CURSOR 0x00196b60 0x00000030 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_GROUP_CURSOR 0x00196b60 0x00000030 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_GROUP_CURSOR 0x00196b60 0x00000030 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_GROUP_CURSOR 0x00196b60 0x00000030 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_GROUP_ICON 0x0018aa30 0x00000068 LANG_PORTUGUESE SUBLANG_PORTUGUESE_BRAZILIAN data
RT_GROUP_ICON 0x0018aa30 0x00000068 LANG_PORTUGUESE SUBLANG_PORTUGUESE_BRAZILIAN data
RT_GROUP_ICON 0x0018aa30 0x00000068 LANG_PORTUGUESE SUBLANG_PORTUGUESE_BRAZILIAN data
RT_GROUP_ICON 0x0018aa30 0x00000068 LANG_PORTUGUESE SUBLANG_PORTUGUESE_BRAZILIAN data
RT_GROUP_ICON 0x0018aa30 0x00000068 LANG_PORTUGUESE SUBLANG_PORTUGUESE_BRAZILIAN data
RT_GROUP_ICON 0x0018aa30 0x00000068 LANG_PORTUGUESE SUBLANG_PORTUGUESE_BRAZILIAN data
RT_VERSION 0x00196b90 0x00000238 LANG_NEUTRAL SUBLANG_NEUTRAL data

Imports

Library KERNEL32.dll:
0x401000 CreateMutexW
0x401004 FindResourceA
0x401008 SetLocaleInfoA
0x40100c EnumCalendarInfoA
0x401014 EnumDateFormatsExW
0x401018 GetProfileIntW
0x40101c FindResourceW
0x401024 GetComputerNameW
0x401028 GetModuleHandleW
0x40102c GetTickCount
0x401030 GetConsoleAliasesA
0x401034 LoadLibraryW
0x401038 CopyFileW
0x40103c GetVersionExW
0x401040 ReadFile
0x401048 GetVolumePathNameA
0x40104c lstrlenW
0x401050 SetThreadPriority
0x401054 DisconnectNamedPipe
0x40105c GetLastError
0x401060 SetLastError
0x401064 GetProcAddress
0x401068 VirtualAlloc
0x40106c IsValidCodePage
0x401074 LoadLibraryA
0x401078 OpenMutexA
0x40107c lstrcmpiW
0x401084 _lopen
0x401088 SetFileShortNameA
0x40108c GetVersionExA
0x401090 ReadConsoleInputW
0x40109c GlobalAddAtomW
0x4010a0 AddConsoleAliasA
0x4010a4 CreateFileA
0x4010a8 CloseHandle
0x4010ac WriteConsoleW
0x4010b0 GetConsoleOutputCP
0x4010b4 WriteConsoleA
0x4010b8 SetStdHandle
0x4010bc FlushFileBuffers
0x4010c8 Sleep
0x4010e4 HeapFree
0x4010e8 MultiByteToWideChar
0x4010ec ExitProcess
0x4010f0 GetStartupInfoW
0x4010f4 RtlUnwind
0x4010f8 RaiseException
0x4010fc WriteFile
0x401100 GetStdHandle
0x401104 GetModuleFileNameA
0x401108 HeapAlloc
0x40110c HeapCreate
0x401110 VirtualFree
0x401114 HeapReAlloc
0x401118 SetHandleCount
0x40111c GetFileType
0x401120 GetStartupInfoA
0x401124 TerminateProcess
0x401128 GetCurrentProcess
0x40112c IsDebuggerPresent
0x401130 TlsGetValue
0x401134 TlsAlloc
0x401138 TlsSetValue
0x40113c TlsFree
0x401140 GetCurrentThreadId
0x401144 HeapSize
0x401148 GetCPInfo
0x40114c GetACP
0x401150 GetOEMCP
0x401158 GetModuleFileNameW
0x401164 GetCommandLineW
0x40116c GetCurrentProcessId
0x401174 GetLocaleInfoA
0x401178 GetStringTypeA
0x40117c GetStringTypeW
0x401180 SetFilePointer
0x401184 WideCharToMultiByte
0x401188 GetConsoleCP
0x40118c GetConsoleMode
0x401190 LCMapStringA
0x401194 LCMapStringW
Library USER32.dll:
0x40119c EnumDesktopWindows
0x4011a0 CharToOemBuffA
0x4011a4 CharUpperBuffW
0x4011a8 GetMenuBarInfo
0x4011ac LoadBitmapA
0x4011b0 CharLowerBuffW
0x4011b4 UnhookWinEvent
0x4011b8 DdeQueryStringW
0x4011bc CharUpperBuffA
0x4011c0 SetClipboardViewer

!This program cannot be run in DOS mode.
`.data
@.reloc
bad allocation
Unknown exception
CorExitProcess
bad exception
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
runtime error
TLOSS error
SING error
DOMAIN error
An application has made an attempt to load the C runtime library incorrectly.
Please contact the application's support team for more information.
- Attempt to use MSIL code from this assembly during native code initialization
This indicates a bug in your application. It is most likely the result of calling an MSIL-compiled (/clr) function from a native constructor or from DllMain.
- not enough space for locale information
- Attempt to initialize the CRT more than once.
This indicates a bug in your application.
- CRT not initialized
- unable to initialize heap
- not enough space for lowio initialization
- not enough space for stdio initialization
- pure virtual function call
- not enough space for _onexit/atexit table
- unable to open console device
- unexpected heap error
- unexpected multithread lock error
- not enough space for thread data
This application has requested the Runtime to terminate it in an unusual way.
Please contact the application's support team for more information.
- not enough space for environment
- not enough space for arguments
- floating point support not loaded
Microsoft Visual C++ Runtime Library
<program name unknown>
Runtime Error!
Program:
EncodePointer
DecodePointer
FlsFree
FlsSetValue
FlsGetValue
FlsAlloc
(null)
`h````
xpxxxx
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
HH:mm:ss
dddd, MMMM dd, yyyy
MM/dd/yy
December
November
October
September
August
February
January
Saturday
Friday
Thursday
Wednesday
Tuesday
Monday
Sunday
GetProcessWindowStation
GetUserObjectInformationA
GetLastActivePopup
GetActiveWindow
MessageBoxA
USER32.DLL
`h`hhh
xppwpp
Complete Object Locator'
Class Hierarchy Descriptor'
Base Class Array'
Base Class Descriptor at (
Type Descriptor'
`local static thread guard'
`managed vector copy constructor iterator'
`vector vbase copy constructor iterator'
`vector copy constructor iterator'
`dynamic atexit destructor for '
`dynamic initializer for '
`eh vector vbase copy constructor iterator'
`eh vector copy constructor iterator'
`managed vector destructor iterator'
`managed vector constructor iterator'
`placement delete[] closure'
`placement delete closure'
`omni callsig'
delete[]
new[]
`local vftable constructor closure'
`local vftable'
`udt returning'
`copy constructor closure'
`eh vector vbase constructor iterator'
`eh vector destructor iterator'
`eh vector constructor iterator'
`virtual displacement map'
`vector vbase constructor iterator'
`vector destructor iterator'
`vector constructor iterator'
`scalar deleting destructor'
`default constructor closure'
`vector deleting destructor'
`vbase destructor'
`string'
`local static guard'
`typeof'
`vcall'
`vbtable'
`vftable'
operator
delete
__unaligned
__restrict
__ptr64
__clrcall
__fastcall
__thiscall
__stdcall
__pascal
__cdecl
__based(
SunMonTueWedThuFriSat
JanFebMarAprMayJunJulAugSepOctNovDec
CONOUT$
bad allocation
zuburixazolegimoca
Jamumo
sasikunodaw
%s %f %c
VirtualProtect
Zotilubomope gelonob pamugoxoyisop
gikihicexunesabecatak gowafezotatayojevijudofobepixi fuvesajahizocehedibiselogesavak
bibigeye
C:\zocaka_wobihos\zaliwufanamin-xosusemof\81\duner.pdb
D$(1D$
L$ _^]
/SUVWuN3
HtHu4j
s[S;7|G;w
tR99u2
QQSVWd
to=H>B
0SSSSS
j@j ^V
Y;= =B
tehC~@
0A@@Ju
>=Yt1j
QQSVWh
v$;5l>B
0SSSSS
PPPPPPPP
0SSSSS
PPPPPPPP
URPQQh\
uL9=8SB
t"SS9]
0WWWWW
AAFFf;
;t$,v-
UQPXY]Y[
t+WWVPV
Yz1~g#
o8bFd3
v<GGvH
Z#lNXa
}A"*5
4|B>o!l
bT;t=nyk
=a13?
zF$48B
(PnWP+
i=.k4@
~H%S./Q
"gCp5
?k,|F+'
4%@?t&f]?
bvbOE:
:MK4PV
htbhno
J!Zg`
z"Q=*DXd
<rb""Z>
agZt={e
wRfMN]S
w6G[B:
Y`j:[[
Z.HX#F`
*U);Omi
n52k\N
ps\9J_
=9<GlY
0v,#Vi
Qpp4*|3
Qc?hC1Y
r#=L,K8
\Zev9k'~
^th\(
*m2:I\
qQ0}LUJ
G@nReo
\+P1>v
8>u#LjO
H(3g&c
<6H(NA
ew0C0x
TMH}!b
co;+W<
J|al_D
dRq2\aX-
4(u,1
3/q"z2RT
ST%e|:
I=m^7=J>
Ep6z+D
k=~7?g
2;ob'w_
NF;lcQ
[hx,Iyt^#
ynn*ZS
u;d0.$
7ddlj!
D`C#5Y6
cUs?}L
I_H>D$
YDJ6/;%yb:H
4):ssM
T9X`s.8_2
YV/T4|
V.No |4.
=sodfw
7D/pG$
lM(6n5
Pr$+~_.
Aky6(uM
#XubBl
j%_2|8
^(Pjy*
gmhne&
r)9J6t
&4t`eB
9AHT<$K?
bOrsiG
rI2K*aJ
"n+wij
)YX@Rj]
y2H,*Rz
2~R;G)
%JK0xu
Z<|h~t
dr'q/K#
Cv,=Tao
b8g06H
HHa`f1U!
>UR,(c
gSVNSz
>z]G|0(
;QBtLE
wK*lFz
OoM%O0K)
@(Tbx%
csi9C*-v
;GZOGO
R^_gf4
:W? rG-
*l%P^h]
lJ(Fae
j;80c)
4;\F`P
Ly'0;V
{iy_Z
0oK$YNAy
6Edtfop
cTx#qH
1N[+Zq
=RLU6!*
t}9wxO
$_.rds
:rbgH@
|rE/k>A
[^Lia92
7 '4L0
fHA.o&C
|h2'wa
R -'*8
~Cr%}?bx
ivN/M
ed|p,!
Ft%IfnQ
Scc22@
cz_h!et
k<n%[>@
\s,hr=
YrM~ku
9?)Z-P =
JT*LA
(Al3q3!
qavaJ;
5[y@Lo
Fibn`I
sKK+:
JoBd_%
^;3F/H`]
In=.rZ
2$lY9W
_]3nv$
Lg7"|w
Z_=yeU
Vu~;4<
UTcB(_
/<~8Wr&
s(l!z+
v'[j./
o't*lH
Y0.OMH
CreateMutexW
FindResourceA
SetLocaleInfoA
EnumCalendarInfoA
GetConsoleAliasesLengthW
EnumDateFormatsExW
GetProfileIntW
FindResourceW
ScrollConsoleScreenBufferW
GetComputerNameW
GetModuleHandleW
GetTickCount
GetConsoleAliasesA
LoadLibraryW
CopyFileW
GetVersionExW
ReadFile
GetCompressedFileSizeA
GetVolumePathNameA
lstrlenW
SetThreadPriority
DisconnectNamedPipe
SetCurrentDirectoryA
GetLastError
SetLastError
GetProcAddress
VirtualAlloc
IsValidCodePage
EnumSystemCodePagesW
LoadLibraryA
OpenMutexA
lstrcmpiW
SetProcessShutdownParameters
_lopen
SetFileShortNameA
GetVersionExA
ReadConsoleInputW
GetWindowsDirectoryW
FileTimeToLocalFileTime
GlobalAddAtomW
AddConsoleAliasA
KERNEL32.dll
SetClipboardViewer
CharUpperBuffA
DdeQueryStringW
UnhookWinEvent
CharLowerBuffW
LoadBitmapA
GetMenuBarInfo
CharUpperBuffW
CharToOemBuffA
EnumDesktopWindows
USER32.dll
InterlockedIncrement
InterlockedDecrement
InitializeCriticalSection
DeleteCriticalSection
EnterCriticalSection
LeaveCriticalSection
UnhandledExceptionFilter
SetUnhandledExceptionFilter
HeapFree
MultiByteToWideChar
ExitProcess
GetStartupInfoW
RtlUnwind
RaiseException
WriteFile
GetStdHandle
GetModuleFileNameA
HeapAlloc
HeapCreate
VirtualFree
HeapReAlloc
SetHandleCount
GetFileType
GetStartupInfoA
TerminateProcess
GetCurrentProcess
IsDebuggerPresent
TlsGetValue
TlsAlloc
TlsSetValue
TlsFree
GetCurrentThreadId
HeapSize
GetCPInfo
GetACP
GetOEMCP
InitializeCriticalSectionAndSpinCount
GetModuleFileNameW
FreeEnvironmentStringsW
GetEnvironmentStringsW
GetCommandLineW
QueryPerformanceCounter
GetCurrentProcessId
GetSystemTimeAsFileTime
GetLocaleInfoA
GetStringTypeA
GetStringTypeW
SetFilePointer
WideCharToMultiByte
GetConsoleCP
GetConsoleMode
LCMapStringA
LCMapStringW
FlushFileBuffers
SetStdHandle
WriteConsoleA
GetConsoleOutputCP
WriteConsoleW
CloseHandle
CreateFileA
Copyright (c) 1992-2004 by P.J. Plauger, licensed by Dinkumware, Ltd. ALL RIGHTS RESERVED.
.?AVtype_info@@
.?AVbad_exception@std@@
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
.?AVexception@std@@
VVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVV6ee
XVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVV+
VVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVv
2/VVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVv
VVVVVVVVVVVVVVVVVVVVVVVVVVVVVVV
VVVVVVVVVVVVVVVVVVVVVVVVVVVVVVD
VVVVVVVVVVVVVVVVVVVVVVVVVVVVV@A
VVVVVVVVVVVVVVVVVVVVVVVVVVVVV
VVVVVVVVVVVVVVVVVVVVVVVVVVVVV
?VVVVVVVVVVVVVVVVVVVVVVVVVVVVVV
VVVVVVVVVVVVVVVVVVVVVVVVVVVVVV
VVVVVVVVVVVVVVVVVVVVVVVVVVVVVVV/
VVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVV
VVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVV%
VVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVV1
VVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVV
VVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVV
VVVVVVVVVV6
/VVVVVVVVVVVVVVVVVVVVVVVVVVVV
VVVVVVVVVV
VVVVVVVVVVVVVVVVVVVVVVVVVVVV
bVVVVVVVVV
VVVVVVVVVVVVVVVVVVVVVVVVVVVV
bVVVVVVV
VVVVVVVVVVVVVVVVVVVVVVVVVVVVD
VVVVVVVVVVVVVVVVVVVVVVVVVVVVD
VVVVVVVVVVVVVVVVVVVVVVVVVVVV
uXVVVVVVVVVVVVVVVVVVVVVVVVVVVVDn>"j
gTVVVVVVVVVVVVVVVVVVVVVVVVVVVVVDn
+VVVVVVVVVVVVVVVVVVVVVVVVVVVVV
dj"djY
VVVVVVVVVVVVVVVVVVVVVVVVVVVVVVbV
VVVVVVVVVVVVVVVVVVVVVVVVVVVVVVTq
VVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVb`L
VVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVV
VVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVTV
VVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVV
VVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVT0
VVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVV1]
VVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVV1
VVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVV
KKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKK
mKKKKKKKKKKKKKKKKKKKKKKKKK
8VKKKKKKKKKKKKKKKKKKKKKKKK
KKKKKKKKKKKKKKKKKKKKK
KKKKKKKKKKKKKKKKKKK
KKKKKKKKKKKKKKKKKKKzg
KKKKKKKKKKKKKKKKKK
_:KKKKKKKKKKKKKKKKKKK
KKKKKKKKKKKKKKKKKKK
KKKKKKKKKKKKKKKKKKKKK
KKKKKKKKKKKKKKKKKKKKKKKKKKKKM^
AKKKKKKKKKKKKKKKKKKKKKKKKKKKKlN
KKKKKKKKKKKKKKKKKKKKKKKKKKKK
KKKKKKKK[
KKKKKKKKKKKKKKKKKK=3
wKKKKKKKO
<KKKKKKKKKKKKKKKKKK
KKKKKK
KKKKKKKKKKKKKKKKKK
KKKKKKKKKKKKKKKKKK*
nKKKKKKKKKKKKKKKKKK
KKKKKKKKKKKKKKKKKKKb
KKKKKKKKKKKKKKKKKKK
RKKKKKKKKKKKKKKKKKKKK
#KKKKKKKKKKKKKKKKKKKKKQ
KKKKKKKKKKKKKKKKKKKKKK
xLKKKKKKKKKKKKKKKKKKKKKKKKK
\KKKKKKKKKKKKKKKKKKKKKKKKKK
KKKKKKKKKKKKKKKKKKKKKKKKKKKKK
(KKKKKKKKKKKKKKKK
y{~|z|
~}~~~zy{
||yz~}
~|}z{|
|||}z~
|~||}{}
y~{~}~
|~}}z|
||}~~~
{~}|y}
z|{z}|{{}
~{|~|||
zz}~z|
|}||||~
||}{z{~
|y~~}|~{|}
}|z|~|
~}~}~~
y{|~~}
}~}z}z
}~|z{z~~
}}z~|z
~{}{z{
~~~||~
|||}~y}
...............................................................................................................................................................................................................................................................................................................................................................................$
.........................................
.................w
H.........
..............
.............
..........
.........
......
k=R<'2f
......
......
.......
.......
.......
.......
.......-
.........
R"c6h%
"=.........$/
-..........$
.............
..............=R
r...............
aEH...............$7#T
.................
.................H
................
................../
...................=
......................
......................
.....................
.....................
w.....................
.....................
......................_
.......................
.........................H
...........................
H..............................{
..................................{CfR=+
-..........................................................................................................................
qqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqq
qqqqqqqqqqqqqqqqqqqT
qqqqqqq
qqqqqqqqqqq
4Nqq-R
qqqqqqqqq
qqqqqqqq-+x
iqqqqqqq
qqqqqqqp;
qqqqqqq
!!k+vy
qqqqqqqW|
qqqqqqqqX_lHv
qqqqqqqqq
qqqqqqqqqq
qqqqqqqqqqqq4
qqqqqqqqqqqqqqi
qqqqqqqqqqqqqq
qqqqqqqqqqqqqq
iqqqqqqqqqqqqqqqq%
RqqqqqqqqqqqqqqqqqZ
qqqqqqqqqqqqqqqqq.
3qqqqqqqqqqqqqqqqq
P-qqqqqqqqqqqqqqqqq
qqqqqqqqqqqqqqqqqqq
-qqqqqqqqqqqqqqqqqqqqq
-qqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqq
jj4.4jV4
Z\<9_uL
/d6XX6
MchO~M
~{NOMN~~**
H N~N{&
IAAAA$
U@@vym
R<Ry<i<<
U|vUUm
@mG33i
yx#6<
9&h_^{9
?vpp))p
::::::{
:::::a0
:::::E
^:::::y
:::::I
J:::::>d
:::::(
m:::::
:::::/1
:::::P
:::::LD
Y::::::
cccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccc]
)ccccccccccccccccK
cccccccccccccccc
ccccccccccccccccPKZZZ
Pcccccccccccccccc
EeTe-{
[[T-ZZ
cccccccccccccccc
cccccccccccccccc
cccccccccccccccc
cccccccccccccccc
ccccccccccccccccr
ccccccccccccccccr
cccccccccccccccc
rcccccccccccccccc
rcccccccccccccccc
cccccccccccccccc
cccccccccccccccc
cccccccccccccccc?
cccccccccccccccc
cccccccccccccccc
Mcccccccccccccccc
cccccccccccccccc
]ccccccccccccccc?
ccccccccccccccc
yr]ccccccccccccccc
ccccccccccccccc
]ccccccccccccccc
]ccccccccccccccc
]ccccccccccccccc?
]ccccccccccccccc?
]ccccccccccccccc
]ccccccccccccc
?cccccccccccc]
?cccccccccccc
Fcccccccccccc
Fccccccccccccr{Z
cccccccccccc
cccccccccccc
e"ee-T
cccccccccccc
cccccccccccc
?cccccccccccc
ccccccccccccc]
R?RRRR
cccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccc
RRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRe
eRRRRRR
RRRRRR
RRRRRR
RRRRRR
RRRRRR
RRRRRR
RRRRRR
RRRRRR
RRRRRR
RRRRRR
RRRRRR
RRRRRR
RRRRRR
RRRRRR
RRRRRR
RRRRRR
RRRRRR
RRRRRR
RRRRRR
RRRRRR
RRRRRR
RRRRRR
RRRRRR
RRRRRR
RRRRRR
RRRRRR
RRRRRR
RRRRRRP
~~~~~~~~~T
PRRRRRR
RRRRRR
RRRRRR
RRRRRR
RRRRRR
RRRRRR
RRRRRR
RRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRR
RRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRR
RRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRR
RRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRR
RRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRR
iiiiiiiii
iiiiiii
iiiiiiiiiiiii
iiiiii
iiiiiiii
iiiiiiii
iiiiii
riiiii
riiiii
hhhhhhYhYYYYYYYYYY
hhhYYYY
hhhYYYYYY
hhhhYYYY
OYY-Y-----
hhhO
hhh
hE
h
Y
Y
kkkkvv
vvvvvlQ
|/kkkkkkkkkkkkkkkkkkkkk
kkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkk
222qqqqq
222q2qq
2222qqqqqq
.Bqqqq
11122B
11112.
111112.
1111111
iiiiiiii
iiiiiiii
iiiiii
iiiiii
iiiiiiiii
iiiiiiiiii
iiiiiiii
iiiiiii
iiiiiiiii



2T2X2\2t2x2
0:4:8:<:@:D:H:L:P:T:X:\:`:d:h:l:p:t:x:|:
; ;$;(;,;0;4;8;<;@;D;H;L;P;T;X;\;`;d;h;l;p;t;x;|;
101@1D1 2'2Q2W2
3(363A3K3c3u3
4/454;4A4O4
6=6H6N6T6r6
7 7*727L7R7X7
8)848R8f8l8
8i9o9u9{9
:$:3:@:F:P:_:~:
>!>C>J>
J0R0g0r0
3A3\3b3k3r3
4.484?4J4S4i4t4
5>5C5N5S5q5"6/6<6a6u6
=&>+>p>u>|>
!0*010:0z0
1=2C2c2
4%4,4E4Y4_4h4{4
445T5b5g5
8828=8C8I8N8W8t8z8
9+919B9
2-2<2I2U2e2l2{2
3P3_3h3
4(5<5]5c5
546>6f6
8J;Q;j;p;{;
<2<9<Q<]<c<o<~<
=;=P=v=
>%?-?w?~?
0!000F0Q0V0a0f0q0v0
1"1.1e1n1z1
516<6F6_6i6|6
9%9@9H9P9g9
=$=(=,=0=4=8=<=@=
=J?j?o?
L0Q0r0w0
0X1]1o1
273=3V3\3
4*434H4x4
7#8*8?8z8
9:8:?:G:L:P:T:}:
:.;4;8;<;@;
<+<]<d<h<l<p<t<x<|<
<1=7===C=I=O=V=]=d=k=r=y=
0)0;0M0_0q0
032=2U2\2f2n2{2
6+696?6O6T6l6r6
67<7Y7
8"9C9O9v9
>8>(?Q?
0Y1s1|1
2W2d2C3R3C4
77M7[7j7x7
:E:O:g:
: :,:8:B:N:Z:d:n:x:
; ;<;@;H;L;h;p;t;
<,<0<L<P<X<`<h<l<t<
=$=(=H=T=p=|=
>4>8>T>X>t>x>
? ?@?`?
1$1,141<1D1L1T1\1d1l1t1|1
= =(=,=0=@=D=H=L=P=T=X=\=`=d=
> >$>(>,>0>@>H>L>P>T>X>\>`>d>h>l>x>0?4?
mscoree.dll
KERNEL32.DLL
(null)
((((( H
h(((( H
H
bugisubopocasose miwejemokupixu dilumutixalayitojecoruj behifomahixonezibubateyufiv dizadofi
zunapokonuzukagidofogeruzexar fobawipifujunuyodomuvafolodepive pazefacojupivuw pinenayacedehovuduzuzigodivowa
wkernel32.dll
kernel32.dll
nacamuzoyahapafupuyaveh
Kofefayuw
Hetuhapaborepuv medisapow sojipujayoni jalivoxowelevat timekizi
msimg32.dll
Yutawi
/ P6pL
,/KPip
/-P?pR
/ P6pL
,/KPip
/-P?pR
/ P6pL
,/KPip
/-P?pR
/ P6pL
,/KPip
/-P?pR
/ P6pL
,/KPip
/-P?pR
/ P6pL
,/KPip
/-P?pR
/ P6pL
,/KPip
/-P?pR
/ P6pL
,/KPip
/-P?pR
/ P6pL
,/KPip
/-P?pR
VS_VERSION_INFO
StringFileInfo
043831F2
FileDescription
Underweather
LegalCopyright
Copyright (C) 2023, historic
ProductsVersion
32.64.57.64
ProductName
GoldenSeg
ProductionVersion
50.16.75.31
VarFileInfo
Translation
Kelu raludajiyefekTinekeyunowaji konufatis zukubepe finabap ditanoyepuw nehifeyorodu zijuroditala socavewe yonuno vugowosazav
Wori gavupurunoki7Rikolemo wida jeb zasixuhizoy bebukocu wafac luvayosico$Solovakofanire cehuyikolebobuw putaj
Hexefeve xixito yesakepaxiru
Nodi sevuniki cibaboceceboy:Lihukefome kifote xogapiyugepirek rapipiwamehaf mafugecedoWJudezap jetajed kaponuzinalugi cixasomadipaxit hesefozub meje zofesujodozude butal mito.Sapumicinekabex bimexeretojifo hikika noju dacPHanofuwa foz zebusaroje yakiwugagisi mome birohano layatuhulosugiy mabilacomizil
Rixicuz
TSaguyumicuwagey fejoyuzusenedi xagu namanipapi rizija nuwuy cetirucodig zejobocuroni
Muwasitu
@Wemasuyomoz meviru zeripita pitulijet xewera lesif pawevimatihiz
Gazamuvolijupad renayoparozeru
Jojani
Antivirus Signature
Bkav W32.AIDetectMalware
Lionic Trojan.Win32.Convagent.4!c
Elastic malicious (high confidence)
MicroWorld-eScan Clean
ClamAV Win.Packer.pkr_ce1a-9980177-0
FireEye Generic.mg.3e95261aa1315079
CAT-QuickHeal Clean
ALYac Clean
Malwarebytes Generic.Malware/Suspicious
Zillya Clean
K7AntiVirus Clean
BitDefender Clean
K7GW Clean
Cybereason malicious.c3caaf
Baidu Clean
VirIT Clean
Symantec ML.Attribute.HighConfidence
tehtris Clean
ESET-NOD32 a variant of Win32/GenKryptik.GLWS
APEX Malicious
Paloalto Clean
Cynet Malicious (score: 100)
Kaspersky UDS:DangerousObject.Multi.Generic
Alibaba Clean
NANO-Antivirus Clean
ViRobot Clean
Rising Trojan.Kryptik!1.B663 (CLASSIC)
Emsisoft Clean
F-Secure Clean
DrWeb Clean
VIPRE Clean
TrendMicro Clean
Trapmine suspicious.low.ml.score
CMC Clean
Sophos ML/PE-A
Ikarus Clean
GData Win32.Trojan-Stealer.LokiBot.989QR8
Jiangmin Clean
Webroot W32.Trojan.Gen
Avira Clean
MAX Clean
Antiy-AVL Clean
Gridinsoft Ransom.Win32.STOP.dg!n
Xcitium Clean
Arcabit Clean
SUPERAntiSpyware Clean
ZoneAlarm UDS:DangerousObject.Multi.Generic
Microsoft Trojan:Win32/Sabsik.FL.B!ml
Google Detected
AhnLab-V3 Clean
Acronis suspicious
McAfee Artemis!3E95261AA131
TACHYON Clean
DeepInstinct MALICIOUS
Cylance unsafe
Panda Trj/Chgt.AD
Zoner Clean
TrendMicro-HouseCall Clean
Tencent Clean
SentinelOne Static AI - Malicious PE
MaxSecure Clean
Fortinet W32/GenKryptik.ERHN!tr
BitDefenderTheta Clean
AVG Win32:TrojanX-gen [Trj]
Avast Win32:TrojanX-gen [Trj]
CrowdStrike win/malicious_confidence_100% (W)
No IRMA results available.