Static | ZeroBOX

PE Compile Time

2022-11-23 01:58:00

PDB Path

C:\cegahayahoxi\jemakejutic26 cez14\pewi.pdb

PE Imphash

27e0e821b6cccff944541ab6ad842917

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x0003825a 0x00038400 7.79754816127
.data 0x0003a000 0x01fd0024 0x00001a00 2.12065604571
.rsrc 0x0200b000 0x00019308 0x00019400 4.03890921288
.reloc 0x02025000 0x00009060 0x00009200 0.96932054457

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x02022fc0 0x00000468 LANG_PORTUGUESE SUBLANG_PORTUGUESE_BRAZILIAN GLS_BINARY_LSB_FIRST
RT_ICON 0x02022fc0 0x00000468 LANG_PORTUGUESE SUBLANG_PORTUGUESE_BRAZILIAN GLS_BINARY_LSB_FIRST
RT_ICON 0x02022fc0 0x00000468 LANG_PORTUGUESE SUBLANG_PORTUGUESE_BRAZILIAN GLS_BINARY_LSB_FIRST
RT_ICON 0x02022fc0 0x00000468 LANG_PORTUGUESE SUBLANG_PORTUGUESE_BRAZILIAN GLS_BINARY_LSB_FIRST
RT_ICON 0x02022fc0 0x00000468 LANG_PORTUGUESE SUBLANG_PORTUGUESE_BRAZILIAN GLS_BINARY_LSB_FIRST
RT_ICON 0x02022fc0 0x00000468 LANG_PORTUGUESE SUBLANG_PORTUGUESE_BRAZILIAN GLS_BINARY_LSB_FIRST
RT_ICON 0x02022fc0 0x00000468 LANG_PORTUGUESE SUBLANG_PORTUGUESE_BRAZILIAN GLS_BINARY_LSB_FIRST
RT_ICON 0x02022fc0 0x00000468 LANG_PORTUGUESE SUBLANG_PORTUGUESE_BRAZILIAN GLS_BINARY_LSB_FIRST
RT_ICON 0x02022fc0 0x00000468 LANG_PORTUGUESE SUBLANG_PORTUGUESE_BRAZILIAN GLS_BINARY_LSB_FIRST
RT_ICON 0x02022fc0 0x00000468 LANG_PORTUGUESE SUBLANG_PORTUGUESE_BRAZILIAN GLS_BINARY_LSB_FIRST
RT_ICON 0x02022fc0 0x00000468 LANG_PORTUGUESE SUBLANG_PORTUGUESE_BRAZILIAN GLS_BINARY_LSB_FIRST
RT_ICON 0x02022fc0 0x00000468 LANG_PORTUGUESE SUBLANG_PORTUGUESE_BRAZILIAN GLS_BINARY_LSB_FIRST
RT_ICON 0x02022fc0 0x00000468 LANG_PORTUGUESE SUBLANG_PORTUGUESE_BRAZILIAN GLS_BINARY_LSB_FIRST
RT_ICON 0x02022fc0 0x00000468 LANG_PORTUGUESE SUBLANG_PORTUGUESE_BRAZILIAN GLS_BINARY_LSB_FIRST
RT_ICON 0x02022fc0 0x00000468 LANG_PORTUGUESE SUBLANG_PORTUGUESE_BRAZILIAN GLS_BINARY_LSB_FIRST
RT_ICON 0x02022fc0 0x00000468 LANG_PORTUGUESE SUBLANG_PORTUGUESE_BRAZILIAN GLS_BINARY_LSB_FIRST
RT_ICON 0x02022fc0 0x00000468 LANG_PORTUGUESE SUBLANG_PORTUGUESE_BRAZILIAN GLS_BINARY_LSB_FIRST
RT_ICON 0x02022fc0 0x00000468 LANG_PORTUGUESE SUBLANG_PORTUGUESE_BRAZILIAN GLS_BINARY_LSB_FIRST
RT_ICON 0x02022fc0 0x00000468 LANG_PORTUGUESE SUBLANG_PORTUGUESE_BRAZILIAN GLS_BINARY_LSB_FIRST
RT_ICON 0x02022fc0 0x00000468 LANG_PORTUGUESE SUBLANG_PORTUGUESE_BRAZILIAN GLS_BINARY_LSB_FIRST
RT_ICON 0x02022fc0 0x00000468 LANG_PORTUGUESE SUBLANG_PORTUGUESE_BRAZILIAN GLS_BINARY_LSB_FIRST
RT_ICON 0x02022fc0 0x00000468 LANG_PORTUGUESE SUBLANG_PORTUGUESE_BRAZILIAN GLS_BINARY_LSB_FIRST
RT_ICON 0x02022fc0 0x00000468 LANG_PORTUGUESE SUBLANG_PORTUGUESE_BRAZILIAN GLS_BINARY_LSB_FIRST
RT_ICON 0x02022fc0 0x00000468 LANG_PORTUGUESE SUBLANG_PORTUGUESE_BRAZILIAN GLS_BINARY_LSB_FIRST
RT_ICON 0x02022fc0 0x00000468 LANG_PORTUGUESE SUBLANG_PORTUGUESE_BRAZILIAN GLS_BINARY_LSB_FIRST
RT_ICON 0x02022fc0 0x00000468 LANG_PORTUGUESE SUBLANG_PORTUGUESE_BRAZILIAN GLS_BINARY_LSB_FIRST
RT_ICON 0x02022fc0 0x00000468 LANG_PORTUGUESE SUBLANG_PORTUGUESE_BRAZILIAN GLS_BINARY_LSB_FIRST
RT_STRING 0x02023eb8 0x0000044c LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_STRING 0x02023eb8 0x0000044c LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_STRING 0x02023eb8 0x0000044c LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_GROUP_ICON 0x0201cc00 0x00000068 LANG_PORTUGUESE SUBLANG_PORTUGUESE_BRAZILIAN data
RT_GROUP_ICON 0x0201cc00 0x00000068 LANG_PORTUGUESE SUBLANG_PORTUGUESE_BRAZILIAN data
RT_GROUP_ICON 0x0201cc00 0x00000068 LANG_PORTUGUESE SUBLANG_PORTUGUESE_BRAZILIAN data
RT_GROUP_ICON 0x0201cc00 0x00000068 LANG_PORTUGUESE SUBLANG_PORTUGUESE_BRAZILIAN data
RT_VERSION 0x020234b0 0x00000234 LANG_NEUTRAL SUBLANG_NEUTRAL data
None 0x020234a0 0x0000000a LANG_NEUTRAL SUBLANG_NEUTRAL data

Imports

Library KERNEL32.dll:
0x401000 CreateMutexW
0x401004 SetLocaleInfoA
0x401008 EnumCalendarInfoA
0x40100c lstrlenA
0x401010 EnumDateFormatsExW
0x401014 GetProfileIntW
0x401018 FindResourceW
0x40101c GlobalAddAtomA
0x401020 _lwrite
0x401024 GetComputerNameW
0x401028 GetTickCount
0x40102c GetConsoleAliasesA
0x401038 GetDateFormatA
0x40103c WriteFile
0x401040 GlobalAlloc
0x401044 SetFileShortNameW
0x401048 FatalAppExitW
0x40104c ReadConsoleInputA
0x401050 FreeConsole
0x401058 FindNextVolumeW
0x40105c DisconnectNamedPipe
0x401060 GetConsoleAliasesW
0x401064 SetLastError
0x401068 lstrcmpiA
0x40106c GetProcAddress
0x401070 VirtualAlloc
0x401074 LoadLibraryA
0x401078 OpenMutexA
0x401080 _lopen
0x401084 AddConsoleAliasA
0x40108c CreateFileA
0x401090 CloseHandle
0x40109c Sleep
0x4010b0 MultiByteToWideChar
0x4010b4 GetLastError
0x4010b8 HeapFree
0x4010c4 GetStartupInfoW
0x4010c8 RtlUnwind
0x4010cc RaiseException
0x4010d0 GetCPInfo
0x4010d4 GetACP
0x4010d8 GetOEMCP
0x4010dc IsValidCodePage
0x4010e0 GetModuleHandleW
0x4010e4 TlsGetValue
0x4010e8 TlsAlloc
0x4010ec TlsSetValue
0x4010f0 TlsFree
0x4010f4 GetCurrentThreadId
0x4010f8 TerminateProcess
0x4010fc GetCurrentProcess
0x401100 IsDebuggerPresent
0x401104 HeapAlloc
0x401108 HeapCreate
0x40110c VirtualFree
0x401110 HeapReAlloc
0x401114 SetHandleCount
0x401118 GetStdHandle
0x40111c GetFileType
0x401120 GetStartupInfoA
0x401124 ExitProcess
0x401128 GetModuleFileNameA
0x40112c GetModuleFileNameW
0x401138 GetCommandLineW
0x401140 GetCurrentProcessId
0x401148 HeapSize
0x40114c GetLocaleInfoA
0x401150 GetStringTypeA
0x401154 GetStringTypeW
0x401158 LCMapStringA
0x40115c WideCharToMultiByte
0x401160 LCMapStringW
0x401168 SetFilePointer
0x40116c GetConsoleCP
0x401170 GetConsoleMode
0x401174 FlushFileBuffers
0x401178 SetStdHandle
0x40117c WriteConsoleA
0x401180 GetConsoleOutputCP
0x401184 WriteConsoleW
Library USER32.dll:
0x40118c DdeQueryStringW
0x401190 CharUpperBuffA
0x401194 LoadMenuW
0x401198 CharLowerBuffW

!This program cannot be run in DOS mode.
`.data
@.reloc
bad allocation
string too long
invalid string position
Unknown exception
bad exception
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
EncodePointer
DecodePointer
FlsFree
FlsSetValue
FlsGetValue
FlsAlloc
(null)
`h````
xpxxxx
CorExitProcess
runtime error
TLOSS error
SING error
DOMAIN error
An application has made an attempt to load the C runtime library incorrectly.
Please contact the application's support team for more information.
- Attempt to use MSIL code from this assembly during native code initialization
This indicates a bug in your application. It is most likely the result of calling an MSIL-compiled (/clr) function from a native constructor or from DllMain.
- not enough space for locale information
- Attempt to initialize the CRT more than once.
This indicates a bug in your application.
- CRT not initialized
- unable to initialize heap
- not enough space for lowio initialization
- not enough space for stdio initialization
- pure virtual function call
- not enough space for _onexit/atexit table
- unable to open console device
- unexpected heap error
- unexpected multithread lock error
- not enough space for thread data
This application has requested the Runtime to terminate it in an unusual way.
Please contact the application's support team for more information.
- not enough space for environment
- not enough space for arguments
- floating point support not loaded
Microsoft Visual C++ Runtime Library
<program name unknown>
Runtime Error!
Program:
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
HH:mm:ss
dddd, MMMM dd, yyyy
MM/dd/yy
December
November
October
September
August
February
January
Saturday
Friday
Thursday
Wednesday
Tuesday
Monday
Sunday
`h`hhh
xppwpp
GetProcessWindowStation
GetUserObjectInformationA
GetLastActivePopup
GetActiveWindow
MessageBoxA
USER32.DLL
Complete Object Locator'
Class Hierarchy Descriptor'
Base Class Array'
Base Class Descriptor at (
Type Descriptor'
`local static thread guard'
`managed vector copy constructor iterator'
`vector vbase copy constructor iterator'
`vector copy constructor iterator'
`dynamic atexit destructor for '
`dynamic initializer for '
`eh vector vbase copy constructor iterator'
`eh vector copy constructor iterator'
`managed vector destructor iterator'
`managed vector constructor iterator'
`placement delete[] closure'
`placement delete closure'
`omni callsig'
delete[]
new[]
`local vftable constructor closure'
`local vftable'
`udt returning'
`copy constructor closure'
`eh vector vbase constructor iterator'
`eh vector destructor iterator'
`eh vector constructor iterator'
`virtual displacement map'
`vector vbase constructor iterator'
`vector destructor iterator'
`vector constructor iterator'
`scalar deleting destructor'
`default constructor closure'
`vector deleting destructor'
`vbase destructor'
`string'
`local static guard'
`typeof'
`vcall'
`vbtable'
`vftable'
operator
delete
__unaligned
__restrict
__ptr64
__clrcall
__fastcall
__thiscall
__stdcall
__pascal
__cdecl
__based(
SunMonTueWedThuFriSat
JanFebMarAprMayJunJulAugSepOctNovDec
CONOUT$
bad allocation
huwocicupenixey
%s %f %c
kernel32.dll
VirtualProtect
zacelekadeciyuwugajeduka hupomijihu dimufoximecopoxihemoxulehena
cicegu wonuw vofuparemobuyinihoguxukomejoxo topiwijawop lojururezadodenaguxopi
yucawecikobevazu rujuweniduwedoguyotejet sazimofizuvavavalovisecokifilos begeyixenexewodukolikedefo
cudohagirepotucitacebuxofafakasemurekomafeyirizi
Nuf xewucohasa hudofiwowimicu
bixevoyuluwusikugujokinove gulufatezikoyixobitiwijigiwigo fixam zitobojulebarejujeyehahonotisuvo hikohucot
msimg32.dll
fukoyawurinixi
C:\cegahayahoxi\jemakejutic26 cez14\pewi.pdb
D$01D$
D$480@
D$ PQQf
wSSWVj
0WWWWW
HtHu4j
s[S;7|G;w
tR99u2
0WWWWW
QQSVWd
0A@@Ju
0SSSSS
j@j ^V
HHtXHHt
>If90t
>=Yt1j
QQSVWh
0SSSSS
PPPPPPPP
0SSSSS
PPPPPPPP
t"SS9]
URPQQh
^SSSSS
j"^SSSSS
0WWWWW
AAFFf;
;t$,v-
UQPXY]Y[
t+WWVPV
&&&s5
]% 4L|
]% 4)&
f]hFUMb
ag -^+
>n-IUM
?5x8CUO:
]EMJ{6
AQ$,1x
.nrNF67*<
7"w FPZ
]OU+zH
@49qH'
D;CZa _?K
kbR\o8
,,]8B(
7V:"<
IG0H)8dF;
~Y9EHK
M<mr")?nBeo
JIY"TDI"
Wp96h{
xn#?$/
G`<'5T
yM3/%+
pK#Vsw
Ny-FF
Uf_aU`
:P[pgZ
o>{GbB
|HUX$
/Kb2Nvi
8M}[O1,
N%f55K
C:B]Mf
wcO08Z
S"XVR'
nor|bj
<mcM,V
Ykhd+*
$+B$a1
8W[JCM{
}P8U]K
^I]zm+
+J'[I/D
YW)@r3r
Nz]C8s
A2qj%J`
<}%F|x
!ma7bRw
S{W$Yf
MZ%-cN
TZv^oC
I<odFRj
5U,3Aut
[]~PDO
`Ba1`
_"-`hrb
dd\CS^)
"Mf3#
zA.Jj`
6J%?^t
h+S&g!
71dGWZ
^s/d#L
Gm]eQ!
4o3b/.
!:Nt'|y
E4:DM2
4d+`:_
mq0RZU99S_
h2OBgr
7QjSb)qo
'iG`-2jE
\.7$$"
"e)m_i
#J@{,g
vzI4]yY
9,v="HP
Znrg3F
jJq?y{
$|rv2%
jjv~v}
.>O+"1
kW|`l
&$UOV|N
o2^M|-U
L _x0t6]
-.H1wS[
'z^AH`{
bDDp=$vh&
3FjGpFya
I|jk%*
opS&dw{ZN
L?!;!b
T|e;8j
1vsS2J
^pN<mE
q"g*]
aR{8%7%3
t;4<P"
(Yqu:W
AM@x;<,L
]YG&Wd
,RsTH#t
KX3%R}
g,rm|V
eR;xo#
f]tpQe
jQG"3!|
IQO9)J
&|g=F8'2
JSQV>\
'Y<dV(;
u)*IN=2m
>~T)]y
j60{\5
xMT*!;`
1,|~9
gw>@9UqgS
;(isb&
=Ewx|}
=_6&K~
=\2WS
CPIm?
{rI7H/
z'>rB{D
d}HuM140
wXNvQ3
YS>):W-L
|>fpC_d
9g&U7^
}dm_Wy
~5{PZY
Qlq@p
xyzg-\9&
?W{'bS@B
Ftu9@X
:@[7V/B
r/1"?y~N
|:iq1k
e` ^,S
Dgju4~
*k.(`A
XUZA/c8
<VrE\O
EaUDR;r
?R^Hk'
CKl4!#,o:p
:(Rvz}
6'0S^T
Bt2044
D gGFf
Gom;31
RV]cZuF
k0lY_O
I e{sM
BQs=E'
:|\(1/
vQ'l_6
PS>{"!
30kFv;>T1wo
Yls7/(
50h(S i!
e/@tih
PPaEfZ
e::.+N
{4h=e_
**k 9&
OmYE7?
%ALQ}
v4t._+
j>${L=R
KDB ,%
uc^+5Q
; k\sy|
r$2?~9
p@_[{a
|qx|A;
Fsrxl;I
C9RZ$'m
#pr_D&v,
z\3[^:
s!|WWz
b|S }~
G*z53w
*;w]urPE[
_M1!^O
X{?:WK
6#$UNsb
>Azik|
FdH_j.Lws
i[<[Gz
D^VxQG
V7Wv"R
`6IwB>
BfH57 X
LAyzCU
1N9G33
9=VWNZuZ
.;hA2=
}*'>Ben
Ct,w|??
4=:"qC
I~5 ww
Bz| Z~t"
:XkVuo
Q+m`:L
\A_24o
BO!iQ8Or
KK[92)m
`^+mH/D
3:z?w.CU
0(@/[t
"0#K-d
u[zA%I
&\x!j1}
S*,`H!
qx;nqV
wqxd9TR
~{K[8R
x$+Cpn
u"O'SV
)OG~><
~"HMiM@~
_o ."
MQA(/6M>
YQ=!jewC
u: {q}
m#g='_#I
L@d\`r
u~-@tJ
%\CyK
+"wLSK2
D_{:1n
:ft6WP
*JPW33
t]|JDV
L%Y.?q
*y.3s]q
WBO]>e4
no`)rq9
.9-Iqu#
`BFj*
CRDNP,
K~Vra6`c&
'|p"4[
I9~r[
V)*_3MR
mOhO:9
+tYa8sm
@fO=n'
jtV_af
&P3e(C
jc1'~;
^![Twc
2@A!V^
QHTG{q
Z)<gyDOl
(OX[S3,
}<BPR^
@7p.b6
7~[KS<
j#D.3S
'!N9C.
*ufXlmV:t"
baYd0q
l"x~]h
xNf:~U
*V1(!t
2olT*Dd
Fx%E'
X,XU>2
,&)IRc
}]B\Q~
dT+toT
@u4p<5
\#r6Y%
Sp:4*
OM%^^Z)m
0D_N'
yvv+6:D
%?vP`u
mv8Dq"3Fa1>
ypN{`I0
9e#yjs
:Km<?C
9r; Yi;
Rqn+98
fUI(BE
i=FZ}K
g;CVC9&
:A6Clf/
QH/C0;
Ja,@s+$
[\F*l]
CreateMutexW
SetLocaleInfoA
EnumCalendarInfoA
lstrlenA
EnumDateFormatsExW
GetProfileIntW
FindResourceW
GlobalAddAtomA
_lwrite
GetComputerNameW
GetTickCount
GetConsoleAliasesA
GetConsoleAliasesLengthA
GetWindowsDirectoryA
GetDateFormatA
WriteFile
GlobalAlloc
SetFileShortNameW
FatalAppExitW
ReadConsoleInputA
FreeConsole
EnumSystemCodePagesA
FindNextVolumeW
DisconnectNamedPipe
GetConsoleAliasesW
SetLastError
lstrcmpiA
GetProcAddress
VirtualAlloc
LoadLibraryA
OpenMutexA
ScrollConsoleScreenBufferA
_lopen
AddConsoleAliasA
LocalFileTimeToFileTime
KERNEL32.dll
LoadMenuW
CharUpperBuffA
DdeQueryStringW
CharLowerBuffW
USER32.dll
InterlockedIncrement
InterlockedDecrement
InitializeCriticalSection
DeleteCriticalSection
EnterCriticalSection
LeaveCriticalSection
MultiByteToWideChar
GetLastError
HeapFree
UnhandledExceptionFilter
SetUnhandledExceptionFilter
GetStartupInfoW
RtlUnwind
RaiseException
GetCPInfo
GetACP
GetOEMCP
IsValidCodePage
GetModuleHandleW
TlsGetValue
TlsAlloc
TlsSetValue
TlsFree
GetCurrentThreadId
TerminateProcess
GetCurrentProcess
IsDebuggerPresent
HeapAlloc
HeapCreate
VirtualFree
HeapReAlloc
SetHandleCount
GetStdHandle
GetFileType
GetStartupInfoA
ExitProcess
GetModuleFileNameA
GetModuleFileNameW
FreeEnvironmentStringsW
GetEnvironmentStringsW
GetCommandLineW
QueryPerformanceCounter
GetCurrentProcessId
GetSystemTimeAsFileTime
HeapSize
GetLocaleInfoA
GetStringTypeA
GetStringTypeW
LCMapStringA
WideCharToMultiByte
LCMapStringW
InitializeCriticalSectionAndSpinCount
SetFilePointer
GetConsoleCP
GetConsoleMode
FlushFileBuffers
SetStdHandle
WriteConsoleA
GetConsoleOutputCP
WriteConsoleW
CloseHandle
CreateFileA
.?AVfacet@locale@std@@
.?AV_Locimp@locale@std@@
Copyright (c) 1992-2004 by P.J. Plauger, licensed by Dinkumware, Ltd. ALL RIGHTS RESERVED.
.?AVlogic_error@std@@
.?AVlength_error@std@@
.?AVout_of_range@std@@
.?AVtype_info@@
.?AVbad_exception@std@@
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
.?AV?$basic_stringbuf@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@
.?AV?$basic_streambuf@DU?$char_traits@D@std@@@std@@
.?AVexception@std@@
.?AVbad_alloc@std@@
tk4[T>s
}{~|~~{}
~~~|{|
{{z||~
~~}|}}
|zz{{~
~{|}z{
}}{}}~
{|||||
|}}~}~
{~~}|{z
}~}{}|{
z||||||
{{|~{}
|{}}}{
~{|{{y~
{{z{}}|
~{~}z~
|~{}{|
}}}{}z
~|~|}~}
|{y}~}|
~|}{|{}
n5 ^Ti
QYvTwD
^~:~LL
B?.AUj!
PT;;7?
?:;::>s
/////pp
UUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUxwx
xwwcEUUUUUUUUUUUUUU
UUUUUUUUUUUUUU
#je"eyy
DUUUUUUUUUUUUUw
UUUUUUUUUUUUU
ouUUUUUUUUUUUUU
\>UUUUUUUUUUUUUU
UUUUUUUUUUUUUU>
UUUUUUUUUUUUU
UUUUUUUUUUUUU>\
UUUUUUUUUUUUUx\
UUUUUUUUUUUUUE
UUUUUUUUUUUUUx
UUUUUUUUUUUUU
^ixUUUUUUUUUUUUU
UUUUUUUUUUUUUxKa
xUUUUUUUUUUUUUxj
xUUUUUUUUUUUUU
xUUUUUUUUUUUUU
UUUUUUUUUUUUUU
_UUUUUUUUUUUwE
DxUUUUUUUUUU
eKBjV<
xUUUUUUUUUU
xUUUUUUUUUU_o
ZxUUUUUUUUUU_
UUUUUUUUUUU'
UwUUUUUUUUUU
UUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUU
~~~~~~
222222m
22222m
?dddddddddsZZZZZZZZZZZ_
QQQQQQ
[>YYYY
[>YYY>[
JJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJ
JJJJJJJJJJJJJJJJJJJJJJJJJJJ5
5JJJJJJJJJJJJJJJJJJJJJJJJJJJJJ
JJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJ
||||||||||||||||||
aaaaaaaaaa|
aaaa4a4a444
aaaaaa44
aaaa4aa
yyyyyyyyyyyyyyYl
~~~~~~
1024282<2@2D2H2T2X2\2`2d2h2l2p2t2
; ;$;(;,;0;4;8;<;@;D;H;L;P;T;X;\;`;d;h;l;p;t;x;|;
0 0$0(0,0004080<0@0D0H0L0P0T0X0\0`0d0h0l0
0<1@1P1T1\1t1
2 2024282<2D2\2l2p2
3,30343<3T3d3h3x3|3
444D4H4P4h4
4#6+636
797C7Y7m7
9 9d9q9z9
:1:j:s:y:~:
;<;B;H;N;b;p;w;
<I<T<\<a<m<s<
<T=Z=`=f=q=w=}=
<:>a>j>
>D?Q?[?`?
1'111N1_1i1
2(2]2e2z2
5Z5`5q5
:);/;7;D;X;m;
7$818/:f<=7=<=
4"636m6z6
:(:D:M:S:\:a:p:
;1;8;_;e;p;|;
<!<'<3<9<F<P<W<o<~<
<0=6=`=f=
=:>]>g>
? ?&?-?3?:?@?H?O?T?\?e?q?v?{?
0>0D0`0
22K2g2
4a4f4t4
5'5-565I5m5
6"60656x8
9%9B9H9S9X9`9f9p9w9
1b1<2D2\2t2
3%353<3K3W3d3
3 4/484\4
6-636e6
7'8B8H8Q8X8z8
9%90999O9Z9t9
9$:):4:9:W:
>A>J>Q>Z>
?$?<?N?r?
0 0$0M0s0
1-24282<2@2D2H2L2P2
7)848>8O8Z8
9L:S:h:
;8;E;Q;Y;a;m;
<V<_<k<
='=s=~=
?3?Q?X?\?`?d?h?l?p?t?
60A0\0c0h0l0p0
1Z1`1d1h1l1
2 2(242=2B2H2R2[2f2r2w2
9(949>9F9Q9
>X?]?o?
010=0d0q0v0
2#2)272@2O2T2^2l2
2%3,323L5
:c;r;c<
=3=j=t=
>4???m?{?
0O182u2
>?:?\?
0,080`0p0
1$1D1L1X1x1
2 2(20282D2d2h2l2t2
303L3P3X3\3x3
484@4D4\4`4|4
585D5`5l5
6(6H6d6h6
707P7l7p7
80888L8T8h8p8t8|8
1 1(1,1D1L1P1p1
7 707@7d7p7t7x7|7
=$=,=4=<=D=L=T=\=d=l=t=|=
> >$>(>,>0>4>8><>@>D>H>L>P>T>X>\>`>d>h>l>p>t>x>|>
KERNEL32.DLL
(null)
mscoree.dll
((((( H
h(((( H
H
fecatihemakupi newadejuvahuyice roterebanatogulususaxe jazayinimerorirowa mukobiseyizepo
videbukuvezecexezokey yavijufa jonemonoguvi cuboce
vugegu
yculenagoletomedefabofatevihomo
kernel32.dll
VS_VERSION_INFO
StringFileInfo
043831F2
FileDescription
Underweather
LegalCopyright
Copyright (C) 2023, historic
ProductsVersion
32.64.57.24
ProductName
Fruits
ProductionVersion
35.19.17.96
VarFileInfo
Translation
&Macewudamujupaj rafifi kuxiwozu pegozi9Nanolik dav sopayajiwog curuhew lac ticakuyetig dukufofosBXixosa guwedige xik wonidajir fuvogalitap wetabatajo kabesupakisum`Dakitoresivun zuluvelojodofab wamijilowocef vaxalocuxegikaj sazoboho wem riyo vawase sim korifadDMojedosesa mobejotazit xahivus hukivepohoner sojewiwe jivukiluco sogaFerulafowilijic xizubifimac nibudofehatovo zita cutekapiga befeburibiy ziconusiboxa vibuyirayayew8Sucenizasuwar vorajowehipenas zufohebadahe goteyenumisip@Hoyozoyos nud vakeju xokib telezona voharajesom yotaho casohoyaf;Suzime zofoxuxizuxitev lijiputakezeb vexesisufusi nusowohes
Zepaxibifofak laduwa"Jozup cosozuco xosidopife kubivicu
(Neli wahey puraxavedowicic xubig yehitez
Cazaxabebivajo
+Wehuvo yonuxexa lasiz razurer bepizizulabivWHacutafiben solipedihiwoce hisihe suheberovu pipijero nogijuc sipejibugarupa rixajacozu
6Zutimacarojigub wiwu nogefep mikojewi yuhupin vevumoveGHaxava jafosul tutefomijo zepedez baduki wemuzaf gedusonojujetek lahoyo
^Napikojejasu leli woya cofofuromimu lixikonozeha jilayaxajevif gayonarep lodek terovoj pebelammSatihifaje goy gubuwozidegepid cesutigimepu fir jugezepajetote jizatusa hahifejukukavap dokotatahutup wesoyiwJLeyu golobopuyomij jecoyapobopu jehefizuv xer volohugerukazu duhibuyowawol
Pogumogovavicus5Doyi fek mumada detavexugaga yeh narusevafihas voyoraUDabonexunen latup wateseviyizew yaxuh yovulinezepuxe recikozul lonufimati ped haxupox]Copeyipakicurec kulosifewof xudasuziwaraye hihigayo votujewefetuwof gaz furotedozi kavenehoha
Luxox tijap
Antivirus Signature
Bkav W32.AIDetectMalware
Lionic Clean
tehtris Generic.Malware
DrWeb Clean
MicroWorld-eScan Clean
CMC Clean
CAT-QuickHeal Ransom.Stop.P5
McAfee Artemis!45C1BB2DD4F6
Malwarebytes MachineLearning/Anomalous.94%
VIPRE Clean
Sangfor Ransom.Win32.Save.a
K7AntiVirus Trojan ( 0056d16b1 )
Alibaba Clean
K7GW Trojan ( 0056d16b1 )
Cybereason malicious.e652e8
BitDefenderTheta Clean
VirIT Clean
Cyren W32/Kryptik.KEN.gen!Eldorado
Elastic malicious (high confidence)
ESET-NOD32 Clean
APEX Malicious
Paloalto Clean
ClamAV Win.Packer.pkr_ce1a-9980177-0
Kaspersky UDS:DangerousObject.Multi.Generic
BitDefender Clean
NANO-Antivirus Clean
SUPERAntiSpyware Clean
Tencent Clean
TACHYON Clean
Sophos ML/PE-A
F-Secure Clean
Baidu Clean
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition BehavesLike.Win32.Lockbit.fh
Trapmine suspicious.low.ml.score
FireEye Generic.mg.45c1bb2dd4f6dfab
Emsisoft Clean
SentinelOne Static AI - Malicious PE
Jiangmin Clean
Webroot Clean
Avira Clean
Antiy-AVL Clean
Microsoft Trojan:Win32/Sabsik.FL.B!ml
Gridinsoft Ransom.Win32.STOP.dg!n
Xcitium Clean
Arcabit Clean
ViRobot Clean
ZoneAlarm UDS:DangerousObject.Multi.Generic
GData Clean
Cynet Malicious (score: 100)
AhnLab-V3 Clean
Acronis suspicious
VBA32 BScope.Trojan.GenKryptik
ALYac Clean
MAX Clean
DeepInstinct MALICIOUS
Cylance unsafe
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Rising Trojan.Kryptik!1.B663 (CLASSIC)
Yandex Clean
Ikarus Trojan-Spy.MSIL.Agent
MaxSecure Trojan.Malware.300983.susgen
Fortinet W32/GenKryptik.ERHN!tr
AVG TrojanX-gen [Trj]
Avast TrojanX-gen [Trj]
CrowdStrike win/malicious_confidence_100% (D)
No IRMA results available.