Static | ZeroBOX

PE Compile Time

2022-02-20 12:59:42

PDB Path

C:\hecopihomo_weme\wul\rabanot-takobugegovec\gocaxewi-kivaticu.pdb

PE Imphash

3b596a432a380031d33a0111e2fc4aa5

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x0003ffbe 0x00040000 7.88016574817
.data 0x00041000 0x0017c41c 0x00001800 1.89033905353
.rsrc 0x001be000 0x000099a8 0x00009a00 5.37850443038
.reloc 0x001c8000 0x000029ec 0x00002a00 2.39174991592

Resources

Name Offset Size Language Sub-language File type
RT_CURSOR 0x001c71b8 0x000000b0 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_CURSOR 0x001c71b8 0x000000b0 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_CURSOR 0x001c71b8 0x000000b0 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_CURSOR 0x001c71b8 0x000000b0 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_CURSOR 0x001c71b8 0x000000b0 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_CURSOR 0x001c71b8 0x000000b0 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_CURSOR 0x001c71b8 0x000000b0 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_CURSOR 0x001c71b8 0x000000b0 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x001c3200 0x00000468 LANG_PORTUGUESE SUBLANG_PORTUGUESE_BRAZILIAN GLS_BINARY_LSB_FIRST
RT_ICON 0x001c3200 0x00000468 LANG_PORTUGUESE SUBLANG_PORTUGUESE_BRAZILIAN GLS_BINARY_LSB_FIRST
RT_ICON 0x001c3200 0x00000468 LANG_PORTUGUESE SUBLANG_PORTUGUESE_BRAZILIAN GLS_BINARY_LSB_FIRST
RT_ICON 0x001c3200 0x00000468 LANG_PORTUGUESE SUBLANG_PORTUGUESE_BRAZILIAN GLS_BINARY_LSB_FIRST
RT_ICON 0x001c3200 0x00000468 LANG_PORTUGUESE SUBLANG_PORTUGUESE_BRAZILIAN GLS_BINARY_LSB_FIRST
RT_STRING 0x001c78d0 0x000000d8 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_STRING 0x001c78d0 0x000000d8 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_GROUP_CURSOR 0x001c7268 0x00000022 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_GROUP_CURSOR 0x001c7268 0x00000022 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_GROUP_CURSOR 0x001c7268 0x00000022 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_GROUP_ICON 0x001c3668 0x0000004c LANG_PORTUGUESE SUBLANG_PORTUGUESE_BRAZILIAN data
RT_VERSION 0x001c7290 0x00000204 LANG_NEUTRAL SUBLANG_NEUTRAL data

Imports

Library KERNEL32.dll:
0x401000 GetComputerNameA
0x401004 CreateMutexW
0x401008 FindResourceA
0x40100c SetLocaleInfoA
0x401010 EnumCalendarInfoA
0x401014 lstrlenA
0x40101c EnumDateFormatsExW
0x401020 AddConsoleAliasW
0x401024 SetTapeParameters
0x401028 GetModuleHandleW
0x40102c GetTickCount
0x401034 GlobalAlloc
0x401038 LoadLibraryW
0x40103c ReadConsoleInputA
0x401040 CopyFileW
0x401048 ReadFile
0x40104c GetVolumePathNameA
0x401050 DisconnectNamedPipe
0x401054 GetConsoleAliasesW
0x401058 GetProfileIntA
0x401060 GetLastError
0x401064 SetLastError
0x401068 GetProcAddress
0x40106c IsValidCodePage
0x401070 LoadLibraryA
0x401074 OpenMutexA
0x401078 CreateHardLinkW
0x401080 lstrcmpiW
0x401084 CreateMutexA
0x401088 VirtualProtect
0x401090 _lopen
0x401094 GetVersionExA
0x40109c AddConsoleAliasA
0x4010a0 lstrcpyA
0x4010a4 CreateFileA
0x4010a8 CloseHandle
0x4010ac WriteConsoleW
0x4010b0 GetConsoleOutputCP
0x4010b4 WriteConsoleA
0x4010b8 SetStdHandle
0x4010bc FlushFileBuffers
0x4010c8 Sleep
0x4010e4 HeapFree
0x4010e8 MultiByteToWideChar
0x4010ec ExitProcess
0x4010f0 GetStartupInfoW
0x4010f4 RtlUnwind
0x4010f8 RaiseException
0x4010fc WriteFile
0x401100 GetStdHandle
0x401104 GetModuleFileNameA
0x401108 HeapAlloc
0x40110c HeapCreate
0x401110 VirtualFree
0x401114 VirtualAlloc
0x401118 HeapReAlloc
0x40111c SetHandleCount
0x401120 GetFileType
0x401124 GetStartupInfoA
0x401128 TerminateProcess
0x40112c GetCurrentProcess
0x401130 IsDebuggerPresent
0x401134 TlsGetValue
0x401138 TlsAlloc
0x40113c TlsSetValue
0x401140 TlsFree
0x401144 GetCurrentThreadId
0x401148 HeapSize
0x40114c GetCPInfo
0x401150 GetACP
0x401154 GetOEMCP
0x40115c GetModuleFileNameW
0x401168 GetCommandLineW
0x401170 GetCurrentProcessId
0x401178 GetLocaleInfoA
0x40117c GetStringTypeA
0x401180 GetStringTypeW
0x401184 SetFilePointer
0x401188 WideCharToMultiByte
0x40118c GetConsoleCP
0x401190 GetConsoleMode
0x401194 LCMapStringA
0x401198 LCMapStringW
Library USER32.dll:
0x4011a0 EnumDesktopWindows
0x4011a4 CharToOemBuffA
0x4011a8 GetMenuBarInfo
0x4011ac CharLowerBuffW
0x4011b0 CharUpperBuffA
0x4011b4 LoadMenuW
0x4011b8 CharUpperW
0x4011bc LoadBitmapW
0x4011c0 DdeQueryStringA
0x4011c4 SetClipboardViewer

!This program cannot be run in DOS mode.
`.data
@.reloc
bad allocation
Unknown exception
CorExitProcess
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
runtime error
TLOSS error
SING error
DOMAIN error
An application has made an attempt to load the C runtime library incorrectly.
Please contact the application's support team for more information.
- Attempt to use MSIL code from this assembly during native code initialization
This indicates a bug in your application. It is most likely the result of calling an MSIL-compiled (/clr) function from a native constructor or from DllMain.
- not enough space for locale information
- Attempt to initialize the CRT more than once.
This indicates a bug in your application.
- CRT not initialized
- unable to initialize heap
- not enough space for lowio initialization
- not enough space for stdio initialization
- pure virtual function call
- not enough space for _onexit/atexit table
- unable to open console device
- unexpected heap error
- unexpected multithread lock error
- not enough space for thread data
This application has requested the Runtime to terminate it in an unusual way.
Please contact the application's support team for more information.
- not enough space for environment
- not enough space for arguments
- floating point support not loaded
Microsoft Visual C++ Runtime Library
<program name unknown>
Runtime Error!
Program:
EncodePointer
DecodePointer
FlsFree
FlsSetValue
FlsGetValue
FlsAlloc
(null)
`h````
xpxxxx
bad exception
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
HH:mm:ss
dddd, MMMM dd, yyyy
MM/dd/yy
December
November
October
September
August
February
January
Saturday
Friday
Thursday
Wednesday
Tuesday
Monday
Sunday
GetProcessWindowStation
GetUserObjectInformationA
GetLastActivePopup
GetActiveWindow
MessageBoxA
USER32.DLL
`h`hhh
xppwpp
Complete Object Locator'
Class Hierarchy Descriptor'
Base Class Array'
Base Class Descriptor at (
Type Descriptor'
`local static thread guard'
`managed vector copy constructor iterator'
`vector vbase copy constructor iterator'
`vector copy constructor iterator'
`dynamic atexit destructor for '
`dynamic initializer for '
`eh vector vbase copy constructor iterator'
`eh vector copy constructor iterator'
`managed vector destructor iterator'
`managed vector constructor iterator'
`placement delete[] closure'
`placement delete closure'
`omni callsig'
delete[]
new[]
`local vftable constructor closure'
`local vftable'
`udt returning'
`copy constructor closure'
`eh vector vbase constructor iterator'
`eh vector destructor iterator'
`eh vector constructor iterator'
`virtual displacement map'
`vector vbase constructor iterator'
`vector destructor iterator'
`vector constructor iterator'
`scalar deleting destructor'
`default constructor closure'
`vector deleting destructor'
`vbase destructor'
`string'
`local static guard'
`typeof'
`vcall'
`vbtable'
`vftable'
operator
delete
__unaligned
__restrict
__ptr64
__clrcall
__fastcall
__thiscall
__stdcall
__pascal
__cdecl
__based(
SunMonTueWedThuFriSat
JanFebMarAprMayJunJulAugSepOctNovDec
CONOUT$
bad allocation
xucebugafukuwuvekesacubupopijege
tulabehifubidizemet civesujijijahosut
wixuzabayuc pemudazewemuyizamawijecad janamerapiribesigomosacusezeve
%s %f %c
nosagonexefohutu hopavedul suvedofosayatujuketujav
kesitakopumo
C:\hecopihomo_weme\wul\rabanot-takobugegovec\gocaxewi-kivaticu.pdb
D$(1D$
L$ _^]
QQSVWd
0SSSSS
j@j ^V
tehsq@
0A@@Ju
>=Yt1j
QQSVWh
HtHu4j
s[S;7|G;w
tR99u2
0SSSSS
PPPPPPPP
0SSSSS
PPPPPPPP
URPQQh
uL9=83D
t"SS9]
0WWWWW
AAFFf;
;t$,v-
UQPXY]Y[
t+WWVPV
bP1+U@
L;SZ_fE
Kf},k_
meO0H
.?h q1
X"n=FW,
CGJi8r
Ek_(KtAi
tg,Gc
)3DA[3G
rG$"I0
;m5x%c
`[4C~T
xAftA9
?"kO,f
$u=2&G#4
#V)wq]A
\A~1%%
H.\H.|
hYG.lQw
pa]&z.m
,@Qs(GV
jfvg'G
/UNA'!
`2Vb3^_
W[ >Lf0K
}S&_OP
,X2TD]
k!wZb8X
b).R3EY
f!)&Qt
z<My$A
8G)jrU
H*2N!)
KX1NhjJ
bmWQ*gNG
t[B.PW :>R
b+f4br
J%qycr
:o6;xc
}lAKW:
j'z(RL
f&q6$H
SQQ0l?3)N
)SCk)V'
(,'hh4`.
g!+6oU+
$2wD7F
C@bx>E
POnmoM
UaZvL>
Ibf3HB
X,a2Lk
?uf:J"
'bgS4
>|{!o
d2?3m}
L-[:i%
.Nwe69
+"U&.z
vna"je
AzE5?"
Xa3|]5
alAVw-
IJM2V6
!L0xSA#
XFb#SO!i
a:I,37
ch2_~"
X5zW*_
`ulzq+]X
R^)8Im
~dOQp20
U^$J>a
:N(TY}4&
gO>t(v
g56<C9]g
G ytXJz=
L)@aF}
,&>JUE
?ebpOA
@sR.0p[
b!5$ K`
i+J<jh
U ?Y$~
p^:JM(
:rRFB+&x
NNOV}
!4,0+z
(B(avfm
58exwv
Qo::Kz4
`}a*!w
AHAp-Jj/
vQuhW+`S3
N-r`,X
|3h52My
Cy^m!@V]\
|fQY$H
aGp#D?|
@iLh$S
H>thxq
6rw0Ex
|`m*JddHHs
1mE6y|(
+)GNKH
(~}S1gV
>"Xz'
9lO#&'g
NeW{#GW
HSY6KO
nOn|;7
-zw3~'
fu4GS7
wP-?!@n
'PkT;{{
>Py(Z{L
80)/srb'
{NhrFO
s|d*q@
6aF7dL
$N[Qwe
g.kGDp
KJC0cX:s
v'v@wcH
+E#gY)o
k%Z+L?
Z.s\K=m
Fp!(.->
0w*OLD
>F2q9>
e"Q|aE
?37! 
4Pnmo
(d5,EsWp
e&'ff!V
T\bD8
<ij'[F
F(R:8B
k>~4YG
<Mp3XQ
dC}\Dz\
-Gk["a
S82`.m
u&[P[G
b&y\;@
gt8cB&h
!l4_]Q)^
J[[Mv:
^xa\]
qtJ~~W
GcK[?J=
.S#Q<D
Q*X{u3
Mf/#_w
3f)j<^Y`
(,%cY$
{"ELlX0
N9ITY"
#iWgS9
Q}D=*w
%T=;0M
(QbT:{
v'k3ciccw
8M_8XD
yv~4aLy
C~&_b,
\b8Cj]
L#ql^p
l(S:.7;oj
"gGhk@
9d=|pQs$
`w!:Cp[R
~l>]rhr
r:9/F6
.W%(kKT?q
^*_:+_
1=IU,u
-|_|=v
5?aU?D
[cReuA
n*3[.N
X}=vMo
?)5P`Xc
Or]@uU
4SzAF9
DpbRBZMXUd
J.KNc$
q%wn!L
CAJpFm
)LZ#G}
cAHYlzR
#+c4z
[.'zfl^
-XBzDb.
dilXq&
;+30`T
r%o;SL
~vomBKYy
S/3jH"
)0oa{]Z
9vWX>G
NOoUzoq
SWITQ
WRC98#
kh0H<9
''^r/>
nIf7!91
?05,@l
J\VLbj5:
,.pDLD
wwbZgv
GPET0u
,qI9?%;
'bKI{Wk2
p_!t8Q
yT0-lVNZ
2aPZdh
Se.-6H[
?8xDI16
~o~#WH
Xp_yHZch
D/sh!A
qc2A.ZD
;G3PNA
CNrMsO
!T`]FOb
\qF9pt
XQ\mpN
[T"!-bA
Q@rcm)~
n#9IgP
1va?:/
.cP{|
ia0=Z.
y)S^ r
'9dHBZ
WF~f.D
-dLU=!
HKU6/.l-S
\ct(u.
Z'Y6Ey
L^#GS>t
@")M]8
\xMwc~
|BDImLf
OB8:+C
'X8\V
6 EX6t
X9I\p&<
e&&?0EnN
cCuKt3_
]\W#sz%
x|'\b=
Q&1_",@
56$QH.J
JKB#,JV|
^(d#4m
Un,JNT
9N8L\v
7E-6r"
<bm& ]
$*1+p3
#<bV,~
/LiU7/5-JH
=0mDD_~
t!N^-s*#C
|1nfm[
(_>H]f-d
,"6~E,[
l>J15#
N0EcOm
N@g>x%
H'X4!>
;|W*_C
eKhU\!<
^]o"T!E$g
q7[NT7
efPM2^kwrhA
Fl$6W*
F][>8Pb
W7izl_
P#kr'J
HqvB&|zKV
9=Gf S
7(O#lO
xyeig>
i5tZ0]
WdzN7m
K:0haEj
_mTa2XI7]
A3Of|&
%pkbd?
c6vMm1@@
ao4?Wz
P.{s)?_
G;)_C~
>obkK_;
629OM<
rq;tWS
ur>E&Gl
l302*
mbLm9
H0D5Z1?
:E}IR*
9,s Ec
rta04R
6uv"$iG[
|,^pS*<
>g]89j
~jD)ave3t
tkI*[`
;a"2Z&
;PVM-r
4r-$&`
WnQ"?L
zE(A QeMK
<Ymvex-C
Xq9G^9
UmX%em
$~!ye
B=[ok7
l/1O~Q
S1E*Qw
}*a%Au
'3G.G}
@7dbgY!{
uN;tqt=[
JaVr m
=2_~J[
,XEl|\#
SDGl{`fI;
@%jX(h
M0 >G^
Ur^y4Y
zE4=xrf
@[uGa|m
Vb?kU%
7ba,ks
X7c5wf
vPY}:cU
7*^flB
(OE ';
P\*]xW=
il3769
B:6\okM
yXCT'dMH
g0!%J6
53N}&KODc
.IuO)
0Ib<BJA
*5Xem;7d
f(+1q(M
q6rLq/
J+q yJ-
V&S<i\~Pp0z
HWaYq0
).Fh1{
,4)ru`M
@1~N2';
Q.Y1P\O
QsB2hg
>~)Dj/
xQJZys
`1gKX8
Ds;hHS
q|YXN<eK{V>Y
VPqv:Q)
CVjp*
sHB:[P(t
I>8{+\
IOurH[
,Mi^}s
`HQ8zkeYBj~Q
GetComputerNameA
CreateMutexW
FindResourceA
SetLocaleInfoA
EnumCalendarInfoA
lstrlenA
GetConsoleAliasesLengthW
EnumDateFormatsExW
AddConsoleAliasW
SetTapeParameters
GetModuleHandleW
GetTickCount
GetWindowsDirectoryA
GlobalAlloc
LoadLibraryW
ReadConsoleInputA
CopyFileW
EnumSystemCodePagesA
ReadFile
GetVolumePathNameA
DisconnectNamedPipe
GetConsoleAliasesW
GetProfileIntA
SetCurrentDirectoryA
GetLastError
SetLastError
GetProcAddress
IsValidCodePage
LoadLibraryA
OpenMutexA
CreateHardLinkW
BeginUpdateResourceA
lstrcmpiW
CreateMutexA
VirtualProtect
SetProcessShutdownParameters
_lopen
GetVersionExA
FileTimeToLocalFileTime
AddConsoleAliasA
lstrcpyA
KERNEL32.dll
SetClipboardViewer
DdeQueryStringA
LoadBitmapW
CharUpperW
LoadMenuW
CharUpperBuffA
CharLowerBuffW
GetMenuBarInfo
CharToOemBuffA
EnumDesktopWindows
USER32.dll
InterlockedIncrement
InterlockedDecrement
InitializeCriticalSection
DeleteCriticalSection
EnterCriticalSection
LeaveCriticalSection
UnhandledExceptionFilter
SetUnhandledExceptionFilter
HeapFree
MultiByteToWideChar
ExitProcess
GetStartupInfoW
RtlUnwind
RaiseException
WriteFile
GetStdHandle
GetModuleFileNameA
HeapAlloc
HeapCreate
VirtualFree
VirtualAlloc
HeapReAlloc
SetHandleCount
GetFileType
GetStartupInfoA
TerminateProcess
GetCurrentProcess
IsDebuggerPresent
TlsGetValue
TlsAlloc
TlsSetValue
TlsFree
GetCurrentThreadId
HeapSize
GetCPInfo
GetACP
GetOEMCP
InitializeCriticalSectionAndSpinCount
GetModuleFileNameW
FreeEnvironmentStringsW
GetEnvironmentStringsW
GetCommandLineW
QueryPerformanceCounter
GetCurrentProcessId
GetSystemTimeAsFileTime
GetLocaleInfoA
GetStringTypeA
GetStringTypeW
SetFilePointer
WideCharToMultiByte
GetConsoleCP
GetConsoleMode
LCMapStringA
LCMapStringW
FlushFileBuffers
SetStdHandle
WriteConsoleA
GetConsoleOutputCP
WriteConsoleW
CloseHandle
CreateFileA
Copyright (c) 1992-2004 by P.J. Plauger, licensed by Dinkumware, Ltd. ALL RIGHTS RESERVED.
.?AVtype_info@@
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
.?AVbad_exception@std@@
.?AVexception@std@@
nMNMHKNLILJJJI
PDABDAHE
&$EDCAA
f&DH@#A&C
f6DC''
f&#+ @!@IA
f!C&&
\ ("3"%&A&BC#
^!"%.4%
[!* 52&
> C>AA$"
c)%% 4@5G
"#4! ! (#"
% 5(&%
7))133
5'&"$&&@@
c+)..,
32+%&
"%!252534$$M
%"3 $K
).53 !" %&&c
l\;UY.,-+
a__`ac9[74*+."
dSS\Z[V[]Z[U7<9cGMGf
eW`VSY]M8G<U[MM<G]9l
ZVQUUSV<0V99<66[<n
YVSTSSYYV]V9Z66D<;MO
bQRTWT0TT//0;Z077;8d
QR1Q/.0/82%e
Q*.*-2+48f
,Q,.41
ot}ltsusuqsr}
f#?FFFF
j&B?(???
d<'%$&
c! %? %@<
'>&>?@CC
_'&"#&!=
2)43' B
1++') )'@>
3. <"8>'G
zVR-*+2
{WX62+/&"
xRYYYV;45&5'CN
xSVTW6ZZ\7ENG^
wSSSZT:Y6766M]
RRUTV6:E]
QQS.,,04X
/Q-..*Z
iiiiiiii
iiiiiiii
iiiiii
iiiiii
iiiiiiiii
iiiiiiiiii
iiiiiiii
iiiiiii
iiiiiiiii

2T2X2\2t2x2l:p:t:x:
0:4:8:<:@:D:H:L:P:T:X:\:`:d:h:l:p:t:x:|:
; ;$;(;,;0;4;8;<;@;D;H;L;P;T;X;\;`;d;h;l;p;t;x;|;
$0(0004080<0
1$1(1,141L1P1h1x1|1`2g2
3?3V3h3v3
3Q4W4k4r4y4
5'62686>6\6q6w6}6
7"7<7B7u7
8#8(8F8R8^8d8
8`9f9l9r9|9
:#:0:6:@:O:n:
F0N0c0n0
3=3X3^3g3n3
4*444;4F4O4e4p4
5:5?5J5O5m5
6+686]6q6
1,252;2
3"3-3Q3Z3a3j3
3!444L4^4
5.6J6m6
7,727U7\7u7
;%;2;=;O;b;m;s;y;~;
<*<0<J<[<a<r<
1W1*353=3Q3n3
4+5=5C5]5l5y5
9$9d9n9
?&?2?G?N?b?i?
0%040;0H0k0
181P1v1
3'3,31373;3A3F3L3Q3`3v3
4I4R4^4
9#9-9a9l9v9
;$<0<C<U<p<x<
<=H=Y=
>(>/>7><>@>D>m>
?$?(?,?0?
0M0T0X0\0`0d0h0l0p0
6<7K7Z7c7x7
7:8@8H8S8
809;9E9V9a9
:S;Z;o;
<(<L<T<
=C=a=h=l=p=t=x=|=
=F>Q>l>s>x>|>
? ?j?p?t?x?|?
= ='=/=7=?=K=T=Y=_=i=r=}=
6!6'666<6J6S6b6g6q6
687?7E7
9#9(969
:4:?:b:
:5;B;[;y;
83999]9
:':9:F:R:\:d:o:
011K1T1
172D2#323#4
516B6}6
6-7;7J7X7`7m7
9%:/:G:p:
?,?6?@?L?X?b?n?z?
0 0@0\0`0h0l0
1(141P1\1x1
24282T2X2x2
3 3$3<3@3\3`3h3p3x3|3
4 4@4`4
5$585X5d5
1$1,141<1D1L1T1\1d1l1t1
= =$=(=,=0=4=P=T=
> >$>(>,>0>@>H>L>P>T>X>\>`>d>h>l>x>0?4?
mscoree.dll
KERNEL32.DLL
(null)
((((( H
h(((( H
H
dahoyagedajamuhorero jeharitocuyegusurun jatoxameto rulujanasayogela jukocakete
gokuhipitevifoyiti moyapihaxuje diwukajavuhemeze kecosejokujosuyahacag
kernel32.dll
kernel32.dll
Barebojegewak
tupatazajigozunosivuzatisozizituxewasekejayolacubevecosebujodeyopiludebozetufixedekamibenimuhebof
rosejuw
yodosutuzetanepapubu murerekezosazel xehuxogicaheriduxixolor
msimg32.dll
/ P6pL
,/KPip
/-P?pR
/ P6pL
,/KPip
/-P?pR
/ P6pL
,/KPip
/-P?pR
/ P6pL
,/KPip
/-P?pR
/ P6pL
,/KPip
/-P?pR
/ P6pL
,/KPip
/-P?pR
VS_VERSION_INFO
StringFileInfo
043831F2
InternalName
FileDescription
Underweather
ProductsVersion
59.46.64.93
ProductName
GoldenSeg
ProductionVersion
74.58.95.46
VarFileInfo
Translation
OJefa vibolawam fezeretini xayuxibozos tuwocaxagiki fexohudameju hihutovusav weg$Yafeweratasodac decirelese tob magab
Kehacetifos tuzis&Sifokal sasay curukeyit jipuridamajelaLCey cetova deyel socalovojozo dehanovux koyurumohe jofev pebanef yixariduhix
Xehibijepu make8Nuhirikolekol sagudahale subim hafumesotig fetirebaxejom.Rizaze zoxuwi wejoxu sub nogalamepise wiwaremaGDehezemefufaxar vudohameruxaju xajovelusazeb tirafuy mucuz xosameramuzi
Fovagure
Xomoxeyesaj tet
BJutarejoyoyuc pogawujisucavov sudazupulu tosulekawojure jopazukaga
Cetohini
Hob muj
%Jifazu fufike wonigexoj tuhe poke cef
Vakakif
Xaf pim mewad duw
Kayihurazexom
Antivirus Signature
Bkav W32.AIDetectMalware
Lionic Trojan.Win32.Stealer.12!c
Elastic malicious (high confidence)
MicroWorld-eScan Gen:Variant.Zusy.477145
ClamAV Win.Packer.pkr_ce1a-9980177-0
FireEye Generic.mg.eabf49a55264bcc1
CAT-QuickHeal Ransom.Stop.P5
McAfee Artemis!EABF49A55264
Malwarebytes Trojan.MalPack.GS
Zillya Clean
Sangfor Trojan.Win32.Save.a
K7AntiVirus Trojan ( 005690671 )
BitDefender Gen:Variant.Zusy.477145
K7GW Trojan ( 005690671 )
Cybereason malicious.7f27f2
Baidu Clean
VirIT Clean
Cyren Clean
Symantec ML.Attribute.HighConfidence
tehtris Clean
ESET-NOD32 a variant of Win32/GenKryptik.GLVV
APEX Malicious
Paloalto Clean
Cynet Malicious (score: 100)
Kaspersky HEUR:Trojan-Spy.Win32.Stealer.gen
Alibaba TrojanSpy:Win32/Stealer.471c9abd
NANO-Antivirus Clean
ViRobot Trojan.Win.Z.Jaik.319488
Rising Trojan.Kryptik!1.B663 (CLASSIC)
Emsisoft Gen:Variant.Zusy.477145 (B)
F-Secure Trojan.TR/Kryptik.qtjmj
DrWeb Clean
VIPRE Gen:Variant.Zusy.477145
TrendMicro TROJ_GEN.R002C0WGG23
McAfee-GW-Edition BehavesLike.Win32.Lockbit.fc
Trapmine Clean
CMC Clean
Sophos Mal/Generic-S
SentinelOne Static AI - Malicious PE
GData Gen:Variant.Zusy.477145
Jiangmin Clean
Webroot Clean
Avira TR/Kryptik.qtjmj
MAX malware (ai score=84)
Antiy-AVL Clean
Gridinsoft Malware.Win32.RedLine.bot
Xcitium Clean
Arcabit Trojan.Zusy.D747D9
SUPERAntiSpyware Clean
ZoneAlarm HEUR:Trojan-Spy.Win32.Stealer.gen
Microsoft Trojan:Win32/Wacatac.B!ml
Google Detected
AhnLab-V3 Trojan/Win.Generic.C5455428
Acronis suspicious
VBA32 Clean
ALYac Gen:Variant.Jaik.155650
TACHYON Clean
DeepInstinct MALICIOUS
Cylance unsafe
Panda Trj/Genetic.gen
Zoner Clean
TrendMicro-HouseCall TROJ_GEN.R002C0WGG23
Tencent Trojan.Win32.Obfuscated.gen
Yandex Clean
Ikarus Trojan.Win32.Krypt
MaxSecure Trojan.Malware.300983.susgen
Fortinet W32/GenKryptik.ERHN!tr
BitDefenderTheta Clean
AVG Win32:CrypterX-gen [Trj]
Avast Win32:CrypterX-gen [Trj]
CrowdStrike win/malicious_confidence_100% (W)
No IRMA results available.