Static | ZeroBOX

PE Compile Time

2022-11-18 22:52:45

PDB Path

C:\rumad nawavumu\xidukoxivic30\mev82\ludogaw.pdb

PE Imphash

510dd539bc8b58414f44caf85838ae97

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x000473c4 0x00047400 7.9004745305
.data 0x00049000 0x0014b6dc 0x00001800 1.89879535067
.rsrc 0x00195000 0x000283f8 0x00028400 4.09072278621
.reloc 0x001be000 0x00002992 0x00002a00 2.40606391152

Resources

Name Offset Size Language Sub-language File type
RT_CURSOR 0x001bc5f8 0x00000568 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_CURSOR 0x001bc5f8 0x00000568 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_CURSOR 0x001bc5f8 0x00000568 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_CURSOR 0x001bc5f8 0x00000568 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_CURSOR 0x001bc5f8 0x00000568 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_CURSOR 0x001bc5f8 0x00000568 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_CURSOR 0x001bc5f8 0x00000568 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_CURSOR 0x001bc5f8 0x00000568 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_CURSOR 0x001bc5f8 0x00000568 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_CURSOR 0x001bc5f8 0x00000568 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_CURSOR 0x001bc5f8 0x00000568 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x001b6df0 0x00000468 LANG_PORTUGUESE SUBLANG_PORTUGUESE_BRAZILIAN GLS_BINARY_LSB_FIRST
RT_ICON 0x001b6df0 0x00000468 LANG_PORTUGUESE SUBLANG_PORTUGUESE_BRAZILIAN GLS_BINARY_LSB_FIRST
RT_ICON 0x001b6df0 0x00000468 LANG_PORTUGUESE SUBLANG_PORTUGUESE_BRAZILIAN GLS_BINARY_LSB_FIRST
RT_ICON 0x001b6df0 0x00000468 LANG_PORTUGUESE SUBLANG_PORTUGUESE_BRAZILIAN GLS_BINARY_LSB_FIRST
RT_ICON 0x001b6df0 0x00000468 LANG_PORTUGUESE SUBLANG_PORTUGUESE_BRAZILIAN GLS_BINARY_LSB_FIRST
RT_ICON 0x001b6df0 0x00000468 LANG_PORTUGUESE SUBLANG_PORTUGUESE_BRAZILIAN GLS_BINARY_LSB_FIRST
RT_ICON 0x001b6df0 0x00000468 LANG_PORTUGUESE SUBLANG_PORTUGUESE_BRAZILIAN GLS_BINARY_LSB_FIRST
RT_ICON 0x001b6df0 0x00000468 LANG_PORTUGUESE SUBLANG_PORTUGUESE_BRAZILIAN GLS_BINARY_LSB_FIRST
RT_ICON 0x001b6df0 0x00000468 LANG_PORTUGUESE SUBLANG_PORTUGUESE_BRAZILIAN GLS_BINARY_LSB_FIRST
RT_ICON 0x001b6df0 0x00000468 LANG_PORTUGUESE SUBLANG_PORTUGUESE_BRAZILIAN GLS_BINARY_LSB_FIRST
RT_ICON 0x001b6df0 0x00000468 LANG_PORTUGUESE SUBLANG_PORTUGUESE_BRAZILIAN GLS_BINARY_LSB_FIRST
RT_ICON 0x001b6df0 0x00000468 LANG_PORTUGUESE SUBLANG_PORTUGUESE_BRAZILIAN GLS_BINARY_LSB_FIRST
RT_ICON 0x001b6df0 0x00000468 LANG_PORTUGUESE SUBLANG_PORTUGUESE_BRAZILIAN GLS_BINARY_LSB_FIRST
RT_ICON 0x001b6df0 0x00000468 LANG_PORTUGUESE SUBLANG_PORTUGUESE_BRAZILIAN GLS_BINARY_LSB_FIRST
RT_ICON 0x001b6df0 0x00000468 LANG_PORTUGUESE SUBLANG_PORTUGUESE_BRAZILIAN GLS_BINARY_LSB_FIRST
RT_ICON 0x001b6df0 0x00000468 LANG_PORTUGUESE SUBLANG_PORTUGUESE_BRAZILIAN GLS_BINARY_LSB_FIRST
RT_ICON 0x001b6df0 0x00000468 LANG_PORTUGUESE SUBLANG_PORTUGUESE_BRAZILIAN GLS_BINARY_LSB_FIRST
RT_ICON 0x001b6df0 0x00000468 LANG_PORTUGUESE SUBLANG_PORTUGUESE_BRAZILIAN GLS_BINARY_LSB_FIRST
RT_ICON 0x001b6df0 0x00000468 LANG_PORTUGUESE SUBLANG_PORTUGUESE_BRAZILIAN GLS_BINARY_LSB_FIRST
RT_ICON 0x001b6df0 0x00000468 LANG_PORTUGUESE SUBLANG_PORTUGUESE_BRAZILIAN GLS_BINARY_LSB_FIRST
RT_ICON 0x001b6df0 0x00000468 LANG_PORTUGUESE SUBLANG_PORTUGUESE_BRAZILIAN GLS_BINARY_LSB_FIRST
RT_ICON 0x001b6df0 0x00000468 LANG_PORTUGUESE SUBLANG_PORTUGUESE_BRAZILIAN GLS_BINARY_LSB_FIRST
RT_ICON 0x001b6df0 0x00000468 LANG_PORTUGUESE SUBLANG_PORTUGUESE_BRAZILIAN GLS_BINARY_LSB_FIRST
RT_ICON 0x001b6df0 0x00000468 LANG_PORTUGUESE SUBLANG_PORTUGUESE_BRAZILIAN GLS_BINARY_LSB_FIRST
RT_ICON 0x001b6df0 0x00000468 LANG_PORTUGUESE SUBLANG_PORTUGUESE_BRAZILIAN GLS_BINARY_LSB_FIRST
RT_ICON 0x001b6df0 0x00000468 LANG_PORTUGUESE SUBLANG_PORTUGUESE_BRAZILIAN GLS_BINARY_LSB_FIRST
RT_ICON 0x001b6df0 0x00000468 LANG_PORTUGUESE SUBLANG_PORTUGUESE_BRAZILIAN GLS_BINARY_LSB_FIRST
RT_ICON 0x001b6df0 0x00000468 LANG_PORTUGUESE SUBLANG_PORTUGUESE_BRAZILIAN GLS_BINARY_LSB_FIRST
RT_ICON 0x001b6df0 0x00000468 LANG_PORTUGUESE SUBLANG_PORTUGUESE_BRAZILIAN GLS_BINARY_LSB_FIRST
RT_ICON 0x001b6df0 0x00000468 LANG_PORTUGUESE SUBLANG_PORTUGUESE_BRAZILIAN GLS_BINARY_LSB_FIRST
RT_ICON 0x001b6df0 0x00000468 LANG_PORTUGUESE SUBLANG_PORTUGUESE_BRAZILIAN GLS_BINARY_LSB_FIRST
RT_ICON 0x001b6df0 0x00000468 LANG_PORTUGUESE SUBLANG_PORTUGUESE_BRAZILIAN GLS_BINARY_LSB_FIRST
RT_ICON 0x001b6df0 0x00000468 LANG_PORTUGUESE SUBLANG_PORTUGUESE_BRAZILIAN GLS_BINARY_LSB_FIRST
RT_ICON 0x001b6df0 0x00000468 LANG_PORTUGUESE SUBLANG_PORTUGUESE_BRAZILIAN GLS_BINARY_LSB_FIRST
RT_ICON 0x001b6df0 0x00000468 LANG_PORTUGUESE SUBLANG_PORTUGUESE_BRAZILIAN GLS_BINARY_LSB_FIRST
RT_ICON 0x001b6df0 0x00000468 LANG_PORTUGUESE SUBLANG_PORTUGUESE_BRAZILIAN GLS_BINARY_LSB_FIRST
RT_ICON 0x001b6df0 0x00000468 LANG_PORTUGUESE SUBLANG_PORTUGUESE_BRAZILIAN GLS_BINARY_LSB_FIRST
RT_ICON 0x001b6df0 0x00000468 LANG_PORTUGUESE SUBLANG_PORTUGUESE_BRAZILIAN GLS_BINARY_LSB_FIRST
RT_STRING 0x001bd170 0x00000284 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_STRING 0x001bd170 0x00000284 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_GROUP_CURSOR 0x001bcb60 0x00000030 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_GROUP_CURSOR 0x001bcb60 0x00000030 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_GROUP_CURSOR 0x001bcb60 0x00000030 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_GROUP_CURSOR 0x001bcb60 0x00000030 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_GROUP_ICON 0x001b0a30 0x00000068 LANG_PORTUGUESE SUBLANG_PORTUGUESE_BRAZILIAN data
RT_GROUP_ICON 0x001b0a30 0x00000068 LANG_PORTUGUESE SUBLANG_PORTUGUESE_BRAZILIAN data
RT_GROUP_ICON 0x001b0a30 0x00000068 LANG_PORTUGUESE SUBLANG_PORTUGUESE_BRAZILIAN data
RT_GROUP_ICON 0x001b0a30 0x00000068 LANG_PORTUGUESE SUBLANG_PORTUGUESE_BRAZILIAN data
RT_GROUP_ICON 0x001b0a30 0x00000068 LANG_PORTUGUESE SUBLANG_PORTUGUESE_BRAZILIAN data
RT_GROUP_ICON 0x001b0a30 0x00000068 LANG_PORTUGUESE SUBLANG_PORTUGUESE_BRAZILIAN data
RT_VERSION 0x001bcb90 0x0000020c LANG_NEUTRAL SUBLANG_NEUTRAL data

Imports

Library KERNEL32.dll:
0x401000 SetupComm
0x401004 CreateMutexW
0x401008 FindResourceA
0x40100c SetLocaleInfoA
0x401010 EnumCalendarInfoA
0x401018 EnumDateFormatsExW
0x40101c GetProfileIntW
0x401020 FindResourceW
0x401028 GetComputerNameW
0x40102c GetModuleHandleW
0x401030 GetTickCount
0x401034 GetConsoleAliasesA
0x401038 GlobalAlloc
0x40103c LoadLibraryW
0x401040 CopyFileW
0x401044 GetVersionExW
0x401048 ReadFile
0x401050 GetVolumePathNameA
0x401054 lstrlenW
0x401058 SetThreadPriority
0x40105c DisconnectNamedPipe
0x401064 GetLastError
0x401068 SetLastError
0x40106c GetProcAddress
0x401070 IsValidCodePage
0x401078 LoadLibraryA
0x40107c OpenMutexA
0x401080 lstrcmpiW
0x401088 _lopen
0x40108c SetFileShortNameA
0x401090 GetVersionExA
0x401094 ReadConsoleInputW
0x4010a0 AddConsoleAliasA
0x4010a4 CreateFileA
0x4010a8 CloseHandle
0x4010ac WriteConsoleW
0x4010b0 GetConsoleOutputCP
0x4010b4 WriteConsoleA
0x4010b8 SetStdHandle
0x4010bc FlushFileBuffers
0x4010c8 Sleep
0x4010e4 HeapFree
0x4010e8 MultiByteToWideChar
0x4010ec ExitProcess
0x4010f0 GetStartupInfoW
0x4010f4 RtlUnwind
0x4010f8 RaiseException
0x4010fc WriteFile
0x401100 GetStdHandle
0x401104 GetModuleFileNameA
0x401108 HeapAlloc
0x40110c HeapCreate
0x401110 VirtualFree
0x401114 VirtualAlloc
0x401118 HeapReAlloc
0x40111c SetHandleCount
0x401120 GetFileType
0x401124 GetStartupInfoA
0x401128 TerminateProcess
0x40112c GetCurrentProcess
0x401130 IsDebuggerPresent
0x401134 TlsGetValue
0x401138 TlsAlloc
0x40113c TlsSetValue
0x401140 TlsFree
0x401144 GetCurrentThreadId
0x401148 HeapSize
0x40114c GetCPInfo
0x401150 GetACP
0x401154 GetOEMCP
0x40115c GetModuleFileNameW
0x401168 GetCommandLineW
0x401170 GetCurrentProcessId
0x401178 GetLocaleInfoA
0x40117c GetStringTypeA
0x401180 GetStringTypeW
0x401184 SetFilePointer
0x401188 WideCharToMultiByte
0x40118c GetConsoleCP
0x401190 GetConsoleMode
0x401194 LCMapStringA
0x401198 LCMapStringW
Library USER32.dll:
0x4011a0 EnumDesktopWindows
0x4011a4 CharToOemBuffA
0x4011a8 CharUpperBuffW
0x4011ac GetMenuBarInfo
0x4011b0 CharLowerBuffW
0x4011b4 UnhookWinEvent
0x4011b8 DdeQueryStringW
0x4011bc CharUpperBuffA
0x4011c0 LoadBitmapW
0x4011c4 SetClipboardViewer

!This program cannot be run in DOS mode.
`.data
@.reloc
bad allocation
Unknown exception
CorExitProcess
bad exception
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
runtime error
TLOSS error
SING error
DOMAIN error
An application has made an attempt to load the C runtime library incorrectly.
Please contact the application's support team for more information.
- Attempt to use MSIL code from this assembly during native code initialization
This indicates a bug in your application. It is most likely the result of calling an MSIL-compiled (/clr) function from a native constructor or from DllMain.
- not enough space for locale information
- Attempt to initialize the CRT more than once.
This indicates a bug in your application.
- CRT not initialized
- unable to initialize heap
- not enough space for lowio initialization
- not enough space for stdio initialization
- pure virtual function call
- not enough space for _onexit/atexit table
- unable to open console device
- unexpected heap error
- unexpected multithread lock error
- not enough space for thread data
This application has requested the Runtime to terminate it in an unusual way.
Please contact the application's support team for more information.
- not enough space for environment
- not enough space for arguments
- floating point support not loaded
Microsoft Visual C++ Runtime Library
<program name unknown>
Runtime Error!
Program:
EncodePointer
DecodePointer
FlsFree
FlsSetValue
FlsGetValue
FlsAlloc
(null)
`h````
xpxxxx
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
HH:mm:ss
dddd, MMMM dd, yyyy
MM/dd/yy
December
November
October
September
August
February
January
Saturday
Friday
Thursday
Wednesday
Tuesday
Monday
Sunday
GetProcessWindowStation
GetUserObjectInformationA
GetLastActivePopup
GetActiveWindow
MessageBoxA
USER32.DLL
`h`hhh
xppwpp
Complete Object Locator'
Class Hierarchy Descriptor'
Base Class Array'
Base Class Descriptor at (
Type Descriptor'
`local static thread guard'
`managed vector copy constructor iterator'
`vector vbase copy constructor iterator'
`vector copy constructor iterator'
`dynamic atexit destructor for '
`dynamic initializer for '
`eh vector vbase copy constructor iterator'
`eh vector copy constructor iterator'
`managed vector destructor iterator'
`managed vector constructor iterator'
`placement delete[] closure'
`placement delete closure'
`omni callsig'
delete[]
new[]
`local vftable constructor closure'
`local vftable'
`udt returning'
`copy constructor closure'
`eh vector vbase constructor iterator'
`eh vector destructor iterator'
`eh vector constructor iterator'
`virtual displacement map'
`vector vbase constructor iterator'
`vector destructor iterator'
`vector constructor iterator'
`scalar deleting destructor'
`default constructor closure'
`vector deleting destructor'
`vbase destructor'
`string'
`local static guard'
`typeof'
`vcall'
`vbtable'
`vftable'
operator
delete
__unaligned
__restrict
__ptr64
__clrcall
__fastcall
__thiscall
__stdcall
__pascal
__cdecl
__based(
SunMonTueWedThuFriSat
JanFebMarAprMayJunJulAugSepOctNovDec
CONOUT$
bad allocation
zuburixazolegimoca
Jamumo
sasikunodaw
%s %f %c
VirtualProtect
gikihicexunesabecatak gowafezotatayojevijudofobepixi fuvesajahizocehedibiselogesavak
bibigeye
C:\rumad nawavumu\xidukoxivic30\mev82\ludogaw.pdb
D$(1D$
L$ _^]
/SUVWuN3
L$ Qj@RP
jXh8tD
HtHu4j
s[S;7|G;w
tR99u2
QQSVWd
0SSSSS
jTh vD
j@j ^V
0A@@Ju
>=Yt1j
QQSVWh
0SSSSS
PPPPPPPP
0SSSSS
PPPPPPPP
URPQQh
t"SS9]
0WWWWW
AAFFf;
;t$,v-
UQPXY]Y[
t+WWVPV
U;l$jE
JF =:|;/
hBN&t"
hBN&t"
MNO 4/
T|?&Wsz
o)cC`fw
jKV=m[,
iY[M#J]
PT=<@_
9P`G)5)g
5+RVEe=k
~rQYH^
<v%a2[
<4bI"n
v8{6L%
9#k:6}8
}o$^,X
3HVVlq
T[.,Ur
&t'CLi
Kq{E#V
JIRy2F
PGhbEz|p
,)R" yc
MM=2's
1Q_OR:{
dyrIDH+
Aq:@@sz
EVD_[!
lq6||]Qs)
T/y-Kf+y
%*rciy
k+,i,`H<u
^BWbNbF
YR: 5CVB{
WUE}v1
SswSj[
A`E}i$
atBX8B
UZBr;3,jz
=#~2m=
@vd\3
r+bl:`@
wU]E1FKO
&<zJO~
F"{XLG
Eu8;(zv8
s;gi5I
=eJoqK
"dS-pK
Jf Vww
LE_8*m
$5Ku[1
G#L?GB
9u&^d^
|UbRk'7
A*/:cw
W1+pe6
`3_"k&
Cm:0FU
un&s[v
T{kr2$
|9}MimM
CE.7t+
1X/BbB
D1dMVN
S#[4Py
=Dn_jf."
DyB0G#]
bi<m,T
mZ+6C[
hmB/p.
e^IMjm;Xp
~&;|;8}
FXP54]a
w1*onp
;||E]z
Y84T~d0v
[~;Uw!~
QX<MUV
%FfN%<wj
a~GN"ui#c
{HsxBfu!
,N;2bS
QxeQ~6
u7M:OM
)'iDS?~S
G,eQ4e
wW9Y**K
j3r9wX
]8aRb:
@0XM'Cs
6\+w^3
9i)^av
0p B2o
cI=-kv9
|#eZ*kN
*YRA$g
D*RGx0
!oGXh4
ONct9E
lt='L:
u/isGP
VE|x^V
(D#XwN2l
gofO1T
~>xy,?
X(+znV
3qB)Cwh
3ZM{<G
;f6OAi3
}/Z~zy
Yp&6W?
a7fd)e
tnr)oB
$o+"X1
BPMFKS
yMFJ[=
tmQ:/_
=nCT28
Y.y^T]
XVj"fT)a
{R7,/ub
7]guR|H
> W'=(j
V,6Zv_}
'tS3+&
C9Q*5_
7,Z@g}
&`1]{M
mRUKK:
JsAgiB*r
N3x=z"
'b+PmX2
$b0L^+
^RaTjfz
^5FSlMLy
RnC,g5
kY#dyb"
xzw\65
?1u~bt
hyUrn\~&h
]wzW\j
ESUdy+&
JgIDUC
0z-TB1I
e7JBPB
c~FCgH
e{]|z5XK
?k5g>6
V= ,{
YrZ9TY
)(bMdm
kqF=Se
=]N5>t'
ipgZh7
):m[Hb
6<&V.'
u|q~$A
$Q{Xhj
O"(g?,
1Q~Qa[=Qa
I6wmsv
_M\gvB
5K8JRI
R,EJ^&%m7Cz
]IB-:i
hO0NAd
J#g|{kt
l.;~2ro
uv1\We
9(k%RYUs4
G#Yh?+
gM R=f
^ZJV+`
MN!,QF
osD?5h
FhMcHs
JJGYLp
$Rt9,4
8$)Z`y
hwi$<e
~|ql$/<cHPv
bOLn5X
edIg<t}
j5n}NBJ
*Z5DNK
T#4vB;
D6 &uL4
G\g7Pq
8H$S;;8
1blL)w
y}s_)!
MXKZaf
Q@l!i-
HAji#&KW
^V~<D1
U@puY:
rwVQ$C'
cH"y'
"A^b-Z
fw`F4'
63g~^$
L9"Irlw
Tj6D}E
2TF(lgq
#Vuy`@J
Jnt3G>9
ogHIhP
)i2;~*
ZdAHDg
"_"1*
-qD_UJ
'B~99H
,%L}O_
5Iz@Ho
:%t:i'
MCA9:1.
DNx=`A}
QdvE1n
Wz\B87
!O.%~/5"3.
Fxb|9F
~R==I]
'p2!eL
6zD/Qr
V@EuCh
iEy8'")ol-w
{i{tr\}
%Ur&~`
Ci@p]t
eD]"2~
)9`vH,
f"%BC}
s%jchem
9;jjwS+g
K4*ZaJo
kZa|w<;
@x,oZ@
ue0[+'
p"X0>7
U@BT\Q
l*g/6r-g
QA,iK0{
v(_rX)
,vq&,K#
vxsSrE
f2EgP1
>)E<;iv
r]*HPL
9',50s:
@yHP^X
Z(EAr%;#
?;`=Z3
KD^=<#
f{brU'd
Vn O@p
-uz[Uq
<zB1|,
v"!>Z.
dL\wo'
5CxNqx
3xvEN*_
^b7GMp
WU^exq
KNC h[z
TVYh !
Z!c&g>
3Y5#;lrl
s(`PVr|
8}#JI~
4iDj?A
3EOI '
z?Y0h {
*AbaA
vocTl^B
U)Zl=0e
P)v(/}8
gHd3Qv
b#%XV)
0TJP]$0
NB/2dt
eE)^pz
Ln "wli"
F)M}$;
P ^+nNz
GqE{xp)
ua;SLF
|'<5My)
5@T:hi
9=>{{le
cYL]cH
`_[h;|
+|w.4B
p!yU9[
V[-xw$
7Xau.3
WJ(4"/
5W9(Oq
V?Z/9K
HqYi:?
83m2%M
*G6Tns
hM(A C
jMB8Ya
IYIF$[
_v(=2]K
b5K{M6
N.K7JUj
a>{p ;
lw%]}z
.&L>k$J
/U"cz+{
-v"xj0
_JG:T|L
u/X-a(k6
M]K$i$$
|=Gm &^V
ButJ9Y
+}xbZ<
'N5 Wi
\{=82}
:")k{=P
<")^Pp
/hw:1":
aA-fua
;&RxK&
t@;G/Jq
rtJ52a
g>amw3G
5P<pA'
cMg{n*
((`6T+G
j#]jUA
G(#J6
y.SDXP
:pFtBk
<ekCM$,
}FR-oF
1!Lcod
XH_y@s
4cT5+e
!Ko3LWd)
4Swg#
oe]R7dby
n_NXO.
`|!j)@
nyqgY8
Z<7g.H
^j5;4`
t'Qmmo
+&HxzR
|:V3Ut
CBb)SC})
/=G2ju8
rWu>>d^z
Q)J{sO2/
nbXL'U
%&ftXM
1?cl^f
S,s#^{
Y!@bzn
v[?Ayf
V(wnQCo
>r.F%Q
$uH"$n
CldUoxjjU
{<r|0"WA<y
P@3pq\
C}y^e6
G._1+b^
/s^Rfj
=fJh}4
84h=BP
1Wm3E9D
eKA}9e
UUtRNW
Z2-|+"{F
dk,RT
.Pzx"`
+R s;wu
TqhFX;
%]+Ba
Q,L*56|GxQ
90LbE0
q08(d<
_m0q?#y+Ed@H~D
\':eO[y
w?y<-M
uyzOoY
<_( P";
_0J^L
)lFtvx
}m&E[0c.
s(_;Lm
r3!1<)
]A(4:GO
E&(m|6
,4{(P
l'W<XRJ (
~ulE62
wR"'D&
:Z@mpr
UqS.fE
9cp+3<
REUjaV
p--nN$
;?`K$>
dyX7A\
yuv1-HZ
~ECOq@y
]LdJ~pk4
W}![Q
G/Npmol
A.Sq7H
bVJQ,a[
<6uAh|
Jcf_bM
Ak3]]U
Z(Ou--KZ_
Rd1A-@
zv WZ|
x4FH]]
CA[mTq]L
;$iCT^
l$^;Sy
j:nq"*
+l,b{$
b20pf@
u0^i($-~
k6nDE2
L:C2V}]
_ps7W-
2X>^%PV
&q7Vo,
&nE?wx
Na%gvG
z,N=/R<K
\G*/]
oC"_m)
q&{Es~
221!JE
?KH;h3
jg[|pq
Y4Jm5']G
FvD-)}^
/O,CPm
mrm=&m
!j#o'p
l=hA\y
hmB@O//v
=m,>aX
iS`-oO%
}!<V6J
%NMO8]
{s#*WG
SetupComm
CreateMutexW
FindResourceA
SetLocaleInfoA
EnumCalendarInfoA
GetConsoleAliasesLengthW
EnumDateFormatsExW
GetProfileIntW
FindResourceW
ScrollConsoleScreenBufferW
GetComputerNameW
GetModuleHandleW
GetTickCount
GetConsoleAliasesA
GlobalAlloc
LoadLibraryW
CopyFileW
GetVersionExW
ReadFile
GetCompressedFileSizeA
GetVolumePathNameA
lstrlenW
SetThreadPriority
DisconnectNamedPipe
SetCurrentDirectoryA
GetLastError
SetLastError
GetProcAddress
IsValidCodePage
EnumSystemCodePagesW
LoadLibraryA
OpenMutexA
lstrcmpiW
SetProcessShutdownParameters
_lopen
SetFileShortNameA
GetVersionExA
ReadConsoleInputW
GetWindowsDirectoryW
FileTimeToLocalFileTime
AddConsoleAliasA
KERNEL32.dll
SetClipboardViewer
LoadBitmapW
CharUpperBuffA
DdeQueryStringW
UnhookWinEvent
CharLowerBuffW
GetMenuBarInfo
CharUpperBuffW
CharToOemBuffA
EnumDesktopWindows
USER32.dll
InterlockedIncrement
InterlockedDecrement
InitializeCriticalSection
DeleteCriticalSection
EnterCriticalSection
LeaveCriticalSection
UnhandledExceptionFilter
SetUnhandledExceptionFilter
HeapFree
MultiByteToWideChar
ExitProcess
GetStartupInfoW
RtlUnwind
RaiseException
WriteFile
GetStdHandle
GetModuleFileNameA
HeapAlloc
HeapCreate
VirtualFree
VirtualAlloc
HeapReAlloc
SetHandleCount
GetFileType
GetStartupInfoA
TerminateProcess
GetCurrentProcess
IsDebuggerPresent
TlsGetValue
TlsAlloc
TlsSetValue
TlsFree
GetCurrentThreadId
HeapSize
GetCPInfo
GetACP
GetOEMCP
InitializeCriticalSectionAndSpinCount
GetModuleFileNameW
FreeEnvironmentStringsW
GetEnvironmentStringsW
GetCommandLineW
QueryPerformanceCounter
GetCurrentProcessId
GetSystemTimeAsFileTime
GetLocaleInfoA
GetStringTypeA
GetStringTypeW
SetFilePointer
WideCharToMultiByte
GetConsoleCP
GetConsoleMode
LCMapStringA
LCMapStringW
FlushFileBuffers
SetStdHandle
WriteConsoleA
GetConsoleOutputCP
WriteConsoleW
CloseHandle
CreateFileA
Copyright (c) 1992-2004 by P.J. Plauger, licensed by Dinkumware, Ltd. ALL RIGHTS RESERVED.
.?AVtype_info@@
.?AVbad_exception@std@@
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
.?AVexception@std@@
}1m$$rr
!YF8!'
QQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQ
8QQQQQQQQQQQQQQQQQQQQQQQQQ
QQQQQQQQQQQQQQQQQQQQQQQQ4
E9T&QQQQQQQQQQQQQQQQQQQQQO
QQQQQQQQQQQQQQQQQQQf
QQQQQQQQQQQQQQQQQQQ
QQQQQQQQQQQQQQQQQQ
-QQQQQQQQQQQQQQQQQQQ
QQQQQQQQQQQQQQQQQQQts.
xQQQQQQQQQQQQQQQQQQQQQak
QQQQQQQQQQQQQQQQQQQQQQQQQQQQ
zQQQQQQQQQQQQQQQQQQQQQQQQQQQQ
QQQQQQQQQQQQQQQQQQQQQQQQQQQQ
QQQQQQQQWPQQQQQQQQQQQQQQQQQQ@*j
QQQQQQQ
bQQQQQQQQQQQQQQQQQQ
QQQQQQ
QQQQQQQQQQQQQQQQQQ
QQQQQQQQQQQQQQQQQQ
QQQQQQQQQQQQQQQQQQ
QQQQQQQQQQQQQQQQQQQB
QQQQQQQQQQQQQQQQQQQ >M
eqQQQQQQQQQQQQQQQQQQQQ
DQQQQQQQQQQQQQQQQQQQQQ
IQQQQQQQQQQQQQQQQQQQQQQ7
QQQQQQQQQQQQQQQQQQQQQQQQQ
1QQQQQQQQQQQQQQQQQQQQQQQQQQ!
QQQQQQQQQQQQQQQQQQQQQQQQQQQQQ
QQQQQQQQQQQQQQQQ
{|~|z~
|~~~|}
}{~||}{
{|{}~~|
|z~z{y{
~|z~y}}
zz~}z{|
~y|~|~|
{|z{~}y
z|}}|~
|~|}z}||
}~~~}|{
|~|}{{
{z|z{{
{}}z{y
z|}~{{}
{z||}|
~}~~}{{
zz~z|}}~|
}|{~|~
{|}~}}
||}{{~{
~~~~~~~~
;FHH}}
ZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZ
ZZZZZZZZZZZZZZZZZZZ
qZZZZZZZ!
ZZZZZZZZZZZ
ZZZZZZZZZ!
[P`IPD/
3!ZZZZZZZZ
ZZZZZZZ
ZZZZZZZ
ZZZZZZZ!
ZZZZZZZo
ZZZZZZZZp3
Q7]b],
ZZZZZZZZZ
!ZZZZZZZZZZq
ZZZZZZZZZZZZ<
ZZZZZZZZZZZZZZ
ZZZZZZZZZZZZZZv
ZZZZZZZZZZZZZZ
ZZZZZZZZZZZZZZZZ
ZZZZZZZZZZZZZZZZZ
ZZZZZZZZZZZZZZZZZE
ZZZZZZZZZZZZZZZZZ
ZZZZZZZZZZZZZZZZZL>
ZZZZZZZZZZZZZZZZZZZL
ZZZZZZZZZZZZZZZZZZZZZ
ZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZ
%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%Y3Cy
%%%8)NFP
%%%%%%
%%%%%%%
%%%%%%%
%%%%%%%%T
%%%%%%%%%%#
%%%%%%%%
~~~~~~
~~~~~~
:::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::+
:::::::::::::::::
::::::::::::::::
:::::::::::::::
:::::::::::::::
:::::::::::::::
:::::::::::::::
:::::::::::::::
:::::::::::::::
:::::::::::::::
:::::::::::::::
:::::::::::::::
:::::::::::::::
:::::::::::::::RX
:::::::::::::::
:::::::::::::::R
:::::::::::::::R
:::::::::::::::R
::::::::::::::::R
::::::::::::::::!|
mg::::::::::::::::
J::::::::::::::::
::::::::::::::::
::::::::::::::::
P::::::::::::::::
J::::::::::::::::
::::::::::::::::
a::::::::::::::::
k::::::::::::::::I|
::::::::::::::::
VCCVCVUVUU222
jncs::::::::::::::::
cI::::::::::::::::P6b
J::::::::::::::::P
J::::::::::::::::J
]k::::::::::::::::k
J::::::::::::::::I
::::::::::::::::s
::::::::::::::::I
iiii-YAYY
k::::::::::::::::Pgv8n
:::::::::::::::::P3
:::::::::::::::::
g::::::::::::::::::
::::::::::::::::::::
:::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::
>QQF4m
FcwP0u
tAG00a
t=\e0>
"Uw%y?m
VVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVD
+aVVVVVVVVVVVVVVVVb
VVVVVVVVVVVVVVVVP
VVVVVVVVVVVVVVVV<b
{<VVVVVVVVVVVVVVVV
VVVVVVVVVVVVVVVV
VVVVVVVVVVVVVVVV
VVVVVVVVVVVVVVVV@
~^^KA[
VVVVVVVVVVVVVVVV{<
VVVVVVVVVVVVVVVV
VVVVVVVVVVVVVVVV
VVVVVVVVVVVVVVVV
VVVVVVVVVVVVVVVV
VVVVVVVVVVVVVVVV{P%%~
VVVVVVVVVVVVVVVVP
VVVVVVVVVVVVVVVV
VVVVVVVVVVVVVVVVu
VVVVVVVVVVVVVVVV
VVVVVVVVVVVVVVVVPP\
VVVVVVVVVVVVVVVVP
VVVVVVVVVVVVVVVV
XPDVVVVVVVVVVVVVVVu
VVVVVVVVVVVVVVV
DVVVVVVVVVVVVVVV P
VVVVVVVVVVVVVVV
DVVVVVVVVVVVVVVV
PDVVVVVVVVVVVVVVV
DVVVVVVVVVVVVVVVu
PDVVVVVVVVVVVVVVVuP
&PDVVVVVVVVVVVVVVV
DVVVVVVVVVVVVV
uVVVVVVVVVVVVD
PuVVVVVVVVVVVVPp'
.VVVVVVVVVVVV
.VVVVVVVVVVVV
VVVVVVVVVVVV
VVVVVVVVVVVV
VVVVVVVVVVVV
)VVVVVVVVVVVVg
uVVVVVVVVVVVV
VVVVVVVVVVVVVD@+
VVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVV
IX\IID\f
ppppll
OT%%XM4
@HHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHH@
jjyy;;
jjyyy;;
jjjyyy;;;
rrrrrr
++++++++++++++++++
+IIIIII^^^
HH,,,,,
--------------
UUUUUUUUUUUU
UffffffffffffU
U=====
U=======
iiiiiiii
iiiiiiii
iiiiii
iiiiii
iiiiiiiii
iiiiiiiiii
iiiiiiii
iiiiiii
iiiiiiiii



2T2X2\2t2x2
0:4:8:<:@:D:H:L:P:T:X:\:`:d:h:l:p:t:x:|:
; ;$;(;,;0;4;8;<;@;D;H;L;P;T;X;\;`;d;h;l;p;t;x;|;
0(0,040L0\0`0p0t0x0
2(222H2\2
2313=3
4 4d4y4
5&5,5:5@5E5Q5W5]5c5p5
6B6J6Q6W6_6d6j6t6
797D7X7^7d7j7
8,868;8@8H8T8
:&:6:F:V:a:g:r:w:
0*111R1Y1!2{2
3c3k3~3
4"474w4
0%12103
=l>u>{>
?J?b?m?
0<0a0t0
3#3*343^3l3r3
7(7.7H7M7\7e7r7}7
8-848:8H8O8T8]8j8p8
=j?u?}?
2(2:2H2]2g2
2+354<4
506`6r6
88:8A8Y8
;';.;U;[;f;r;
<)</<<<F<M<e<t<{<
<&=,=V=\=x=
=0>S>]>
?#?)?0?6?>?E?J?R?[?g?l?q?w?{?
040:0V0
0#1,181Q1
1-2?2#3`3w3
455B5L5Z5c5m5
9$9)989_9
:O:h:o:w:|:
;^;d;h;l;p;
838@8L8T8\8h8
:1:8:<:@:D:H:L:P:T:
;!;<;C;H;L;P;q;
;:<@<D<H<L<
="=(=2=;=F=R=W=g=l=r=x=
=A?S?e?
6#62676A6O6
7Q7]7i8
7)7o7u7
:":,:4:?:o:
4 505K5k5
7%7.797N7U7[7q7
;";4; <
3&303<3H3R3^3j3t3~3
404L4P4X4\4x4
5 5$5<5@5\5`5h5p5x5|5
64686X6d6
7$7(7D7H7d7h7
808P8p8
9(9H9T9
1$1,141<1D1L1T1\1d1l1t1|1
= =(=,=0=@=D=H=L=P=T=X=\=`=d=
> >$>(>,>0>@>H>L>P>T>X>\>`>d>h>l>x>0?4?
mscoree.dll
KERNEL32.DLL
(null)
((((( H
h(((( H
H
bugisubopocasose miwejemokupixu dilumutixalayitojecoruj behifomahixonezibubateyufiv dizadofi
zunapokonuzukagidofogeruzexar fobawipifujunuyodomuvafolodepive pazefacojupivuw pinenayacedehovuduzuzigodivowa
wkernel32.dll
kernel32.dll
nuhivobejimabemupuhedesono
nacamuzoyahapafupuyaveh
Kofefayuw
msimg32.dll
Yutawi
/ P6pL
,/KPip
/-P?pR
/ P6pL
,/KPip
/-P?pR
/ P6pL
,/KPip
/-P?pR
/ P6pL
,/KPip
/-P?pR
/ P6pL
,/KPip
/-P?pR
/ P6pL
,/KPip
/-P?pR
/ P6pL
,/KPip
/-P?pR
/ P6pL
,/KPip
/-P?pR
/ P6pL
,/KPip
/-P?pR
VS_VERSION_INFO
StringFileInfo
043831F2
InternalName
JapanTech
FileDescription
Underweather
ProductsVersion
32.64.57.64
ProductName
GoldenSeg
ProductionVersion
50.16.75.31
VarFileInfo
Translation
8Cog yijolifajenebeg zoxesa waw walizaf watazugid mekufal'Jiwucuyev cofoxuw tojasuritoy dexodotay=Xiyihunifaci tijipoluvavatuf lon kokux dabumojutuviva runutog
Rafisive biwawaw cudi jugupayo
Burawid bunajuwuhu lohum\Noh dey faponivomomuw zaxopalunuki hixihenut feyecesesavi viku say kamumasufofik xuhaxitudex
Jewuwilufez mulovuduj
Tag tisofaxexa+Jovob papezegamur jubobohaj yujijeniramofev
Mohorivut zaha
IHay xerofivixomuwir muzofonud zunuyexomihus foxuy pagig wavevajo bawo mez
WPuwifajurecebog wivaluvewiwev seyaximazu wawazufoh ximarisobudimo zalozujod civixufipit
HNov jiba nihehoku ruzosorogefog lesuxijaweseyex havaxotukari dupicizureg
Nasewucof
@Vey yenozab lipoveku bogoy mij yoguxul beruzu wotavuda lesik buhJJuja xaragiwupexa yamod yidupubap wegofopehota niwexaxihew wogave zefa cul
Antivirus Signature
Bkav W32.AIDetectMalware
Lionic Trojan.Win32.Stealerc.4!c
Elastic malicious (high confidence)
DrWeb Clean
MicroWorld-eScan Trojan.GenericKD.68212617
FireEye Generic.mg.a8dcd1088cd20043
CAT-QuickHeal Ransom.Stop.P5
McAfee Artemis!A8DCD1088CD2
Cylance unsafe
VIPRE Trojan.GenericKD.68212617
Sangfor Trojan.Win32.Save.a
K7AntiVirus Trojan ( 005690671 )
BitDefender Trojan.GenericKD.68212617
K7GW Trojan ( 005a8afb1 )
Cybereason malicious.f4f68e
Arcabit Trojan.Generic.D410D789
BitDefenderTheta Clean
VirIT Clean
Cyren W32/Kryptik.KEN.gen!Eldorado
Symantec ML.Attribute.HighConfidence
tehtris Clean
ESET-NOD32 a variant of Win32/Kryptik.HUBQ
APEX Malicious
Paloalto Clean
Cynet Malicious (score: 100)
Kaspersky HEUR:Trojan-Spy.Win32.Stealer.gen
Alibaba Clean
NANO-Antivirus Clean
ViRobot Clean
Rising Trojan.Kryptik!1.B663 (CLASSIC)
Sophos Mal/Generic-S
F-Secure Clean
Baidu Clean
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition BehavesLike.Win32.Lockbit.gh
Trapmine Clean
CMC Clean
Emsisoft Trojan.GenericKD.68212617 (B)
Ikarus Clean
Jiangmin Clean
Webroot W32.Trojan.Gen
Avira Clean
MAX malware (ai score=85)
Antiy-AVL Trojan/Win32.Wacatac
Gridinsoft Ransom.Win32.STOP.dg!n
Xcitium Clean
Microsoft Trojan:Win32/SmokeLoader.DS!MTB
SUPERAntiSpyware Clean
ZoneAlarm HEUR:Trojan-Spy.Win32.Stealer.gen
GData MSIL.Trojan-Stealer.NetStealer.D2TOZD
Google Detected
AhnLab-V3 Trojan/Win.Generic.R592088
Acronis suspicious
VBA32 BScope.Trojan.Fabookie
ALYac Clean
TACHYON Clean
DeepInstinct MALICIOUS
Malwarebytes Trojan.MalPack.GS
Panda Trj/Chgt.AD
Zoner Clean
TrendMicro-HouseCall TROJ_GEN.R002H07GG23
Tencent Trojan.Win32.Obfuscated.gen
Yandex Clean
SentinelOne Static AI - Malicious PE
MaxSecure Trojan.Malware.300983.susgen
Fortinet W32/GenKryptik.ERHN!tr
AVG Win32:BotX-gen [Trj]
Avast Win32:BotX-gen [Trj]
CrowdStrike win/malicious_confidence_100% (W)
No IRMA results available.