Static | ZeroBOX

PE Compile Time

2022-09-07 14:14:49

PDB Path

C:\yuvucopupelus\zoyu19\corimik\hajezugo\loxamox.pdb

PE Imphash

63b403774c774916f9ed6282f41f8cf0

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x0002da26 0x0002dc00 7.44699835956
.data 0x0002f000 0x01fee3a4 0x00001c00 2.4628538841
.rsrc 0x0201e000 0x0000d950 0x0000da00 4.34767050246
.reloc 0x0202c000 0x0000abb4 0x0000ac00 1.15994927144

Resources

Name Offset Size Language Sub-language File type
RT_CURSOR 0x0202a930 0x00000568 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_CURSOR 0x0202a930 0x00000568 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_CURSOR 0x0202a930 0x00000568 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_CURSOR 0x0202a930 0x00000568 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_CURSOR 0x0202a930 0x00000568 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_CURSOR 0x0202a930 0x00000568 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x02027018 0x00000468 LANG_PORTUGUESE SUBLANG_PORTUGUESE_BRAZILIAN GLS_BINARY_LSB_FIRST
RT_ICON 0x02027018 0x00000468 LANG_PORTUGUESE SUBLANG_PORTUGUESE_BRAZILIAN GLS_BINARY_LSB_FIRST
RT_ICON 0x02027018 0x00000468 LANG_PORTUGUESE SUBLANG_PORTUGUESE_BRAZILIAN GLS_BINARY_LSB_FIRST
RT_ICON 0x02027018 0x00000468 LANG_PORTUGUESE SUBLANG_PORTUGUESE_BRAZILIAN GLS_BINARY_LSB_FIRST
RT_ICON 0x02027018 0x00000468 LANG_PORTUGUESE SUBLANG_PORTUGUESE_BRAZILIAN GLS_BINARY_LSB_FIRST
RT_ICON 0x02027018 0x00000468 LANG_PORTUGUESE SUBLANG_PORTUGUESE_BRAZILIAN GLS_BINARY_LSB_FIRST
RT_ICON 0x02027018 0x00000468 LANG_PORTUGUESE SUBLANG_PORTUGUESE_BRAZILIAN GLS_BINARY_LSB_FIRST
RT_ICON 0x02027018 0x00000468 LANG_PORTUGUESE SUBLANG_PORTUGUESE_BRAZILIAN GLS_BINARY_LSB_FIRST
RT_ICON 0x02027018 0x00000468 LANG_PORTUGUESE SUBLANG_PORTUGUESE_BRAZILIAN GLS_BINARY_LSB_FIRST
RT_ICON 0x02027018 0x00000468 LANG_PORTUGUESE SUBLANG_PORTUGUESE_BRAZILIAN GLS_BINARY_LSB_FIRST
RT_STRING 0x0202b680 0x000002ce LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_STRING 0x0202b680 0x000002ce LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_GROUP_CURSOR 0x0202ae98 0x00000030 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_GROUP_CURSOR 0x0202ae98 0x00000030 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_GROUP_ICON 0x02021618 0x00000030 LANG_PORTUGUESE SUBLANG_PORTUGUESE_BRAZILIAN data
RT_GROUP_ICON 0x02021618 0x00000030 LANG_PORTUGUESE SUBLANG_PORTUGUESE_BRAZILIAN data
RT_VERSION 0x0202aec8 0x00000240 LANG_NEUTRAL SUBLANG_NEUTRAL data
None 0x020274e8 0x0000000a LANG_NEUTRAL SUBLANG_NEUTRAL data

Imports

Library KERNEL32.dll:
0x401014 PeekNamedPipe
0x401018 TlsGetValue
0x40101c GetStringTypeA
0x401020 GetProfileIntW
0x401024 FindResourceW
0x40102c _lwrite
0x401038 ConnectNamedPipe
0x40103c GetTickCount
0x401040 GetConsoleAliasesA
0x401048 CreateActCtxW
0x40104c GetLocaleInfoW
0x401050 WriteConsoleOutputA
0x401054 TransactNamedPipe
0x401058 GetNamedPipeInfo
0x401060 GetLastError
0x401064 HeapReAlloc
0x401068 GetProcAddress
0x40106c AttachConsole
0x401070 VirtualAlloc
0x401078 SearchPathA
0x40107c SetFileApisToOEM
0x401080 LoadLibraryA
0x401084 OpenMutexA
0x401088 GetProcessId
0x40108c Module32FirstW
0x401090 EnumResourceTypesW
0x401094 GetCommTimeouts
0x401098 HeapSetInformation
0x40109c UpdateResourceW
0x4010a4 ReadConsoleInputW
0x4010ac ResetWriteWatch
0x4010b0 WriteConsoleW
0x4010b4 GetConsoleOutputCP
0x4010b8 WriteConsoleA
0x4010bc GetDateFormatW
0x4010c4 lstrcmpiA
0x4010c8 GetComputerNameA
0x4010cc Sleep
0x4010e0 HeapFree
0x4010e4 TerminateProcess
0x4010e8 GetCurrentProcess
0x4010f4 IsDebuggerPresent
0x4010f8 GetStartupInfoW
0x4010fc RtlUnwind
0x401100 RaiseException
0x401104 LCMapStringA
0x401108 WideCharToMultiByte
0x40110c MultiByteToWideChar
0x401110 LCMapStringW
0x401114 GetCPInfo
0x401118 HeapAlloc
0x40111c HeapCreate
0x401120 VirtualFree
0x401124 GetModuleHandleW
0x401128 TlsAlloc
0x40112c TlsSetValue
0x401130 TlsFree
0x401134 SetLastError
0x401138 GetCurrentThreadId
0x40113c HeapSize
0x401140 ExitProcess
0x401144 WriteFile
0x401148 GetStdHandle
0x40114c GetModuleFileNameA
0x401150 GetModuleFileNameW
0x40115c GetCommandLineW
0x401160 SetHandleCount
0x401164 GetFileType
0x401168 GetStartupInfoA
0x401170 GetCurrentProcessId
0x401178 GetACP
0x40117c GetOEMCP
0x401180 IsValidCodePage
0x401184 GetUserDefaultLCID
0x401188 GetLocaleInfoA
0x40118c EnumSystemLocalesA
0x401190 IsValidLocale
0x401194 GetStringTypeW
0x40119c CloseHandle
0x4011a0 CreateFileA
0x4011a4 GetConsoleCP
0x4011a8 GetConsoleMode
0x4011ac FlushFileBuffers
0x4011b0 SetFilePointer
0x4011b4 SetStdHandle
0x4011b8 SetEndOfFile
0x4011bc GetProcessHeap
0x4011c0 ReadFile
Library USER32.dll:
0x4011c8 CharUpperBuffA
0x4011cc LoadMenuW
0x4011d0 CharLowerBuffA
0x4011d4 CharToOemBuffA
Library GDI32.dll:
0x401008 StretchDIBits
Library ADVAPI32.dll:

!This program cannot be run in DOS mode.
`.data
@.reloc
bad allocation
string too long
invalid string position
Unknown exception
LC_TIME
LC_NUMERIC
LC_MONETARY
LC_CTYPE
LC_COLLATE
LC_ALL
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
bad exception
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
EncodePointer
DecodePointer
FlsFree
FlsSetValue
FlsGetValue
FlsAlloc
CorExitProcess
(null)
`h````
xpxxxx
UTF-16LE
UNICODE
runtime error
TLOSS error
SING error
DOMAIN error
An application has made an attempt to load the C runtime library incorrectly.
Please contact the application's support team for more information.
- Attempt to use MSIL code from this assembly during native code initialization
This indicates a bug in your application. It is most likely the result of calling an MSIL-compiled (/clr) function from a native constructor or from DllMain.
- not enough space for locale information
- Attempt to initialize the CRT more than once.
This indicates a bug in your application.
- CRT not initialized
- unable to initialize heap
- not enough space for lowio initialization
- not enough space for stdio initialization
- pure virtual function call
- not enough space for _onexit/atexit table
- unable to open console device
- unexpected heap error
- unexpected multithread lock error
- not enough space for thread data
This application has requested the Runtime to terminate it in an unusual way.
Please contact the application's support team for more information.
- not enough space for environment
- not enough space for arguments
- floating point support not loaded
Microsoft Visual C++ Runtime Library
<program name unknown>
Runtime Error!
Program:
HH:mm:ss
dddd, MMMM dd, yyyy
MM/dd/yy
December
November
October
September
August
February
January
Saturday
Friday
Thursday
Wednesday
Tuesday
Monday
Sunday
united-states
united-kingdom
trinidad & tobago
south-korea
south-africa
south korea
south africa
slovak
puerto-rico
pr-china
pr china
new-zealand
hong-kong
holland
great britain
england
britain
america
swedish-finland
spanish-venezuela
spanish-uruguay
spanish-puerto rico
spanish-peru
spanish-paraguay
spanish-panama
spanish-nicaragua
spanish-modern
spanish-mexican
spanish-honduras
spanish-guatemala
spanish-el salvador
spanish-ecuador
spanish-dominican republic
spanish-costa rica
spanish-colombia
spanish-chile
spanish-bolivia
spanish-argentina
portuguese-brazilian
norwegian-nynorsk
norwegian-bokmal
norwegian
italian-swiss
irish-english
german-swiss
german-luxembourg
german-lichtenstein
german-austrian
french-swiss
french-luxembourg
french-canadian
french-belgian
english-usa
english-us
english-uk
english-trinidad y tobago
english-south africa
english-nz
english-jamaica
english-ire
english-caribbean
english-can
english-belize
english-aus
english-american
dutch-belgian
chinese-traditional
chinese-singapore
chinese-simplified
chinese-hongkong
chinese
canadian
belgian
australian
american-english
american english
american
Norwegian-Nynorsk
`h`hhh
xppwpp
Complete Object Locator'
Class Hierarchy Descriptor'
Base Class Array'
Base Class Descriptor at (
Type Descriptor'
`local static thread guard'
`managed vector copy constructor iterator'
`vector vbase copy constructor iterator'
`vector copy constructor iterator'
`dynamic atexit destructor for '
`dynamic initializer for '
`eh vector vbase copy constructor iterator'
`eh vector copy constructor iterator'
`managed vector destructor iterator'
`managed vector constructor iterator'
`placement delete[] closure'
`placement delete closure'
`omni callsig'
delete[]
new[]
`local vftable constructor closure'
`local vftable'
`udt returning'
`copy constructor closure'
`eh vector vbase constructor iterator'
`eh vector destructor iterator'
`eh vector constructor iterator'
`virtual displacement map'
`vector vbase constructor iterator'
`vector destructor iterator'
`vector constructor iterator'
`scalar deleting destructor'
`default constructor closure'
`vector deleting destructor'
`vbase destructor'
`string'
`local static guard'
`typeof'
`vcall'
`vbtable'
`vftable'
operator
delete
__unaligned
__restrict
__ptr64
__clrcall
__fastcall
__thiscall
__stdcall
__pascal
__cdecl
__based(
GetProcessWindowStation
GetUserObjectInformationA
GetLastActivePopup
GetActiveWindow
MessageBoxA
USER32.DLL
SunMonTueWedThuFriSat
JanFebMarAprMayJunJulAugSepOctNovDec
CONOUT$
bad allocation
fivediwibu dayilay
ladutojavufu
%s %f %c
kernel32.dll
riyew modocekixogenuruliyeg xasacadizugufive giwujipe
jiroyes secupabomofuyowubocivanoyicay jiwozenamazapuhipexejaga
macezegefefanesonobasada tozikeruzogegela wuzasuvatozugac nutifanajuxuhodogaci
msimg32.dll
siwidafopodefowuv datojolofowa kobevozowoyizanomuce juxajidilejesa geseveso
numalihijuwufataramo volekaxoyufuyojotazuwogifojin lomopejesaka jelalej
hegoyuwoc ziselumujatebi fatiziwawiyulijazedulujimusav buc zuyinigedaburaro
ios_base::badbit set
ios_base::failbit set
ios_base::eofbit set
bad cast
C:\yuvucopupelus\zoyu19\corimik\hajezugo\loxamox.pdb
^\9nTr
^@9n8r
D$ VSUP
tth\9@
D$XT:@
D$,1D$
L$,QRRf
j8VhX8@
F09^(u
0WWWWW
0WWWWW
QQSVWd
HtHu4j
s[S;7|G;w
tR99u2
t"SS9]
0SSSSS
F\=`#@
HHtXHHt
>If90t
<at9<rt,<wt
URPQQh|
u&h(#@
>=Yt1j
QQSVWh
j@j ^V
C PjPV
C$PjQV
C*PjTV
C+PjUV
C,PjVV
C-PjWV
C.PjRV
C/PjSV
0A@@Ju
0SSSSS
PPPPPPPP
0SSSSS
PPPPPPPP
t+WWVPV
^SSSSS
j"^SSSSS
tGHt.Ht&
^SSSSS
8VVVVV
;t$,v-
UQPXY]Y[
0WWWWW
AAFFf;
^SSSSS
^SSSSS
u,VVWV
t VV9u
kQ5`iuL
8cl}oDs
0)=*Z$
uEOc'M
lA/VwillO`
MM>_Q$(|W
}\EBS)6B
lH!{&|
WH)5<}
PK[b[Le
2Ro)*
mwUz+*
Z,Ql=\7
nBsnae
Nynw}1.l4
\MktGA8K
+123<{
v$y,$d
iue1x>
zm9!~(
^$c0b
tcqt"Z
+xgFCx
aM[~62
Y9`.${
_?aj,.F
z[hmO
fHHC$;(pVv
'c`c]c
IJnD;
up)z}d1
p:3!8t
LMP|Y:
p#-l5;]:
m_t*2A
D%kE.R
[F{"nOw=
x2xah.
:<!nwy
oEzdd6
}W94!):
k03+O/
9zA8h%
#BFC 3d
=Nf(<)
NJq6Frr
p=6~4j
"vf`@0
9;bBqu\
-w.s7Q
c"d{8v
AJ%3T
7t}iYb
Ja#HIq24O
G)b[Vn
P7s\-
v\AWcx
-.4d 0+
-Tyi;sU
Zd(SZ
-qfZHH
vGGx!c
))Q73c}O
p&<gc&P
(`="9@
SVXu}md
$gBkBYE
m!0#0G
o/3To.
M0OEvh
^mATh7
!0l,{?
j/(&/N
xt%a{[)
7WKw-n
Ne%y~L{*
m6^r|j
ebJM6%
a~Cs8V{
ID%"v't
;r-S*q
.$s0P6
OssQjE
iz#,MOKf
Lom#?'0.
TW0>P'
^D@DhL
4d*"7XF
jPcno
W@OV5*5
?m ..n/E
-"[X[l
+cwn/A
PzVqw,<
PuQ*t}
z5H(UA;
)CJ7"mFB
4?dryst
m?|FbVbe
/]XUB^
$4:l
a:lXkAi
sGcu@h
+g :d1
NP[9%;
mWhe[4
LkFax7
0Ju:Vb/
P/H>]5
R?d#N9
u%iVQl
fC-ap
#xIRba
d^}&QI<
+ 7|Dr
Z=Eg!L
0Cg*cj]AB
|\cuLC
.w<Pf0
E#HSod
}5:r7;GF
F_]K]*j
-(-E(0Y)
uW"3k&L`!
&n9gp$
%g8yNh:
FF2"J}}
{3nI'
ae:9a?n
5lY`f-
n0I_E8
3xB>_T
jC*}>
(y;SMw^2
VI4aU.4?
].Jn9i
={7[lp=E
pC}[UB
!_xFpb
<i`x_$F
28Q0w9
sLF2,]Y
.E~q5f
l:t,0]P
>>P[I,u
A2N)3HEF<
F^@&O(p
,wyx#p
GetComputerNameA
GetDateFormatW
FillConsoleOutputCharacterA
HeapReAlloc
WritePrivateProfileStructA
PeekNamedPipe
TlsGetValue
GetStringTypeA
GetProfileIntW
FindResourceW
InterlockedIncrement
_lwrite
InterlockedDecrement
FindCloseChangeNotification
ConnectNamedPipe
GetTickCount
GetConsoleAliasesA
GetConsoleAliasesLengthA
CreateActCtxW
GetLocaleInfoW
WriteConsoleOutputA
TransactNamedPipe
GetNamedPipeInfo
GetCompressedFileSizeA
GetLastError
lstrcmpiA
GetProcAddress
AttachConsole
VirtualAlloc
CreateMemoryResourceNotification
SearchPathA
SetFileApisToOEM
LoadLibraryA
OpenMutexA
GetProcessId
Module32FirstW
EnumResourceTypesW
GetCommTimeouts
HeapSetInformation
UpdateResourceW
CancelTimerQueueTimer
ReadConsoleInputW
GetWindowsDirectoryW
ResetWriteWatch
KERNEL32.dll
CharLowerBuffA
LoadMenuW
CharUpperBuffA
CharToOemBuffA
USER32.dll
StretchDIBits
GDI32.dll
InitiateSystemShutdownA
ADVAPI32.dll
InitializeCriticalSection
DeleteCriticalSection
EnterCriticalSection
LeaveCriticalSection
HeapFree
TerminateProcess
GetCurrentProcess
UnhandledExceptionFilter
SetUnhandledExceptionFilter
IsDebuggerPresent
GetStartupInfoW
RtlUnwind
RaiseException
LCMapStringA
WideCharToMultiByte
MultiByteToWideChar
LCMapStringW
GetCPInfo
HeapAlloc
HeapCreate
VirtualFree
GetModuleHandleW
TlsAlloc
TlsSetValue
TlsFree
SetLastError
GetCurrentThreadId
HeapSize
ExitProcess
WriteFile
GetStdHandle
GetModuleFileNameA
GetModuleFileNameW
FreeEnvironmentStringsW
GetEnvironmentStringsW
GetCommandLineW
SetHandleCount
GetFileType
GetStartupInfoA
QueryPerformanceCounter
GetCurrentProcessId
GetSystemTimeAsFileTime
GetACP
GetOEMCP
IsValidCodePage
GetUserDefaultLCID
GetLocaleInfoA
EnumSystemLocalesA
IsValidLocale
GetStringTypeW
InitializeCriticalSectionAndSpinCount
CloseHandle
CreateFileA
GetConsoleCP
GetConsoleMode
FlushFileBuffers
SetFilePointer
SetStdHandle
SetEndOfFile
GetProcessHeap
ReadFile
WriteConsoleA
GetConsoleOutputCP
WriteConsoleW
.?AV_Locimp@locale@std@@
.?AVout_of_range@std@@
Copyright (c) 1992-2004 by P.J. Plauger, licensed by Dinkumware, Ltd. ALL RIGHTS RESERVED.
.?AVtype_info@@
.?AVbad_exception@std@@
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
.?AV?$ctype@D@std@@
.?AUctype_base@std@@
.?AVfacet@locale@std@@
.?AV?$basic_stringstream@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@
.?AV?$basic_stringbuf@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@
.?AV?$basic_iostream@DU?$char_traits@D@std@@@std@@
.?AV?$basic_ostream@DU?$char_traits@D@std@@@std@@
.?AV?$basic_istream@DU?$char_traits@D@std@@@std@@
.?AV?$basic_streambuf@DU?$char_traits@D@std@@@std@@
.?AV?$basic_ios@DU?$char_traits@D@std@@@std@@
.?AV?$_Iosb@H@std@@
.?AVios_base@std@@
.?AVruntime_error@std@@
.?AVexception@std@@
.?AVlogic_error@std@@
.?AVfailure@ios_base@std@@
.?AVlength_error@std@@
.?AVbad_cast@std@@
.?AVbad_alloc@std@@
kkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkk-
Rkkkkkkkkkkk
:::::::::::::::::::::::::::::::::
Rkkkkkkkkk:
*||||||||||||||||||||||||||||||||||
kkkkkkk::
DDDDDDDDDDDDDDDDDD
kkkkk:
kkkkk-
|qBBB~
|q~~~BBB
~~~~BB
~~BBBB
~~~~~BBB3,N
|||||||
,,,,,,,,,"
,,,,,,,,
,[[[[[
/////$
yyyyyyyyyyyyy
&&&&&&&&
|,SBBB
~~BBBB
~~~~BBB
-kkkkk
:kkkkkk
kkkkkkkkk
kkkkkkkkk
J-tkkkkkkkkk
tkkkkkkkkkk
kkkkkkkkkkkkkkkkkkkkkk
kkkkkkkkkkkkkkkkkkkkkkk
,kkkkkkkkkkkkkkkkkkkkkkkkkR
;,,\5\,,
kkkkkkkkkkkkkkkkkkkkkkkkkkk
kkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkk
zzzzzzz
3rrrrrrrrrrrrrrrrrrrr37
??????????
6e???????
???????
g??????
8aaa1U
xaa1a1
n44449944444
???????????u+]
TRWzzzzz
G????????
zzzzzz
zzzzzzz
zzzzzzzzzzzzzzz
*zzzzzzzzzzzzzzzz
vzzzzzzzzzzzzzzzzzzzzzzzzzzz
Bzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzz
TTTTTTTTTTTTTTT
TWT]OOnnA
4444444
TTTTTt
~~~{|~
{{~|~|{
|z~|~}|}}
|~}~{|z
||z}z}
y||{||~
{~zy~|}
}y~{|~
{z}|{z
{~~~z|
}z}}~z{
~~|{{~|
z{}}z}
~~}~||
||}{}|{
{{}y}|
y~}|~y
~~~}|}
~{~z{~
{~|~z||~
~yyzz~|
}{~~~~}
}z}z{z}
z|{}~~}
{~~~~~




2 2`2d2h2l2p2t2x2
3h3p3t3x3|3
3H4L4P4T4
: :(:0:8:@:H:P:X:`:h:p:x:
; ;(;0;8;@;H;P;X;`;h;p;x;
< <(<0<8<@<H<P<X<`<h<p<x<
3 3$3(3,3034383<3@3D3H3L3P3T3X3\3`3d3h3l3p3t3x3|3
4 4$4(4,4044484<4@4D4H4L4P4T4X4\4`4d4h4l4p4t4x4|4
: :$:(:,:0:4:8:<:P:T:X:\:`:d:h:l:p:t:x:|:
:`;d;t;x;|;
<$<(<,<4<L<\<`<p<t<|<
=0=@=D=T=X=\=`=h=
>$>(>,>4>L>\>`>p>t>x>|>
? ?$?(?,?0?4?<?T?d?h?x?|?
0$04080H0L0P0T0X0`0x0
1 10141D1H1P1h1x1|1
2 282<2T2d2h2x2|2
>$>_>y>
0#1E1O1e1y1
3D3Q3a3f3y3
304]4f4l4q4{4
5N5X5`5e5t5z5
6<6B6O6V6^6c6h6p6
7"7I7h7
778<8B8G8R8X8^8d8r8
;#<F<M<U<y<
=#=5=Z=h=v=
60@0Y0a0y0
141b1l1
1!2D2Y2a2k2z2
3 3@3J3g3x3
7K8c8{8
9Z9`9q9
:$;=;f;k;
0!050J0o0
:/;F;W;
=">(>E>J>
738@8S8
365>5S5^5
0!0(0,0004080<0@0D0
1,13181<1@1a1
1*2024282<2
393B3N3
4-4S4q4x4|4
4V5a5|5
6 6$6(6,606z6
7-838S8
99)9S9a9g9
=#===B=Q=Z=g=r=
>">)>/>=>D>I>R>_>e>
3_5j5r5
7&8,888
;!;-;=;D;S;_;l;
;(<7<@<d<
5M5s5[7
:,:2:=:I:^:e:y:
;$;<;K;R;_;
<-<3<O<g<
=*=4=l=t=
>!>)>2>>>C>H>N>R>X>]>c>h>w>
0-0H0N0W0^0
1$1+161?1U1`1z1
2*2/2:2?2]2
3#3P3\4
3'3T3\3{3
5B5b5g5A6N6
7%707T7]7d7m7
7$878O8a8
889>9W9]9
>?O?a?
0-0P0]0i0q0y0
11f1k1
1<2E2K2
3&3Q3\3
44'4/4;4D4I4O4Y4b4m4y4~4
; ;Y;m<x<
=0=B=T=f=x=
213<3F3_3i3|3
6%6@6H6P6g6
9,9=9Z9
>+?4?M?
W6[6_6c6g6k6o6s6w6{6
7'7.7^7
7l8:<:h:
=f=A>y>
282l2r2~2
41474x5
:j;Z=a=
6)6N6e6
<'<0<e<s<y<
5G6g6W7
='=?=h=
[1i1q1~1
2&2,21272>2P2@3
=(>K>n>
?!?<?Y?y?
2"2'242@2`2l2
3 3(303<3\3`3d3l3
4 4<4@4H4L4h4
5(505`5h5l5
6 6@6`6l6
7,707P7l7p7
8,808L8P8p8
989X9x9
: :(:0:8:L:T:X:\:d:l:t:
;0;8;@;H;P;\;
<4<@<`<l<
=<=H=h=p=x=
>$>,>4>@>l>
04080X0`0
3P6`6d6h6t6|6
8 8D8P8T8X8\8`8h8l8p8t8x8|8
9(9094989<9@9D9H9L9P9T9`9
1,1L1p1
383T3p3X:x:
((((( H
h(((( H
H
KERNEL32.DLL
mscoree.dll
(null)
roronivecekuwurepup
jisukupojawiyufacitid
hexosetafuli duhetofamu pavarupukepisukazidoped xanebobukejecinareyomaso
hirovorekecepozusekejoludux
kernel32.dll
kapawafejuh
vemonipilu
padugebopukubafiyavajabi
lwabizuxunecijuguyeka
peyosicako
jjjjjjjjjjjjj
jjjjjjj
jjjjjj
jjjjjj
/ P6pL
,/KPip
/-P?pR
/ P6pL
,/KPip
/-P?pR
/ P6pL
,/KPip
/-P?pR
/ P6pL
,/KPip
/-P?pR
/ P6pL
,/KPip
/-P?pR
/ P6pL
,/KPip
/-P?pR
VS_VERSION_INFO
StringFileInfo
042831F2
FileDescription
ElecticalStone
LegalCopyright
Copyright (C) 2023, histsrical
ProductsVersion
70.41.9.76
ProductName
Octoberfxst
ProductionVersion
89.66.9.2
VarFileInfo
Translation
SXonali pekohehuxu sabisicuhovinef darorofop mosofuvegaxoyu womaj jazokejobogux hiha
Hemaye venu fil moviceh muhera?Ponifiyakog bojononafuhebih haramorogevasu pesi zasagorijatubarhWiwovomefo nubewaleyug litakuriligawet mefohica wesazojojixodej lowetetow pipuwu kahamahetobajur febirecWCiyekulegepare tuwisepax luhofotenir xatugavihasasi tinuwohovetavon burerudu sokihudeso5Gez wihilahiwas rirayaciko vavoxifohuxi rukono sifoli@Xaxitokiruyuwo puguwabop puyohijum vuviriyujovofo deyezazalidaje,Warumute komuh zumewuhulaw vavidemogaxa cuku>Jaceluzewucik nehekesicirefax kaceye vudexawucewemu pafokolufo
Gasimiz zowelolubosom dur yem
Jadetupavaw
4Sesexinofomabox ragaduketej wovulosamavam lanu xanil
=Sijiginidisiw seveme zumotofodiyaxey covetoway xebogayicajuya^Hod fotimuhakuk hivicehugona jatihi hesofedikepivu wimuciwelugefuk kayayuzifo timasexoru momin
Ciz luwiyomosezisaz
'Zovecin cavog xarawi bayopo mid dicamix
Hil hojaxeju
FoceBZanopepu bovuzizixoyuxu maserub digaxapuwewira himivipeniwadiv zub0Yicabun xanacemipokule kozutobafac bitajugejetom
Antivirus Signature
Bkav W32.AIDetectMalware
Lionic Trojan.Win32.Convagent.4!c
Elastic malicious (high confidence)
ClamAV Win.Packer.pkr_ce1a-9980177-0
CMC Clean
CAT-QuickHeal Ransom.Stop.P5
McAfee Lockbit-FSWW!120CBB2CCA4D
Malwarebytes Trojan.MalPack.GS
VIPRE Gen:Heur.Mint.Zard.59
Sangfor Trojan.Win32.Save.a
CrowdStrike win/malicious_confidence_100% (W)
Alibaba Backdoor:Win32/Convagent.7aae114e
K7GW Trojan ( 0056f9be1 )
K7AntiVirus Trojan ( 0056f9be1 )
Baidu Clean
VirIT Clean
Cyren W32/Kryptik.KGV.gen!Eldorado
Symantec ML.Attribute.HighConfidence
tehtris Generic.Malware
ESET-NOD32 a variant of Win32/Kryptik.HUGD
APEX Malicious
Paloalto Clean
Cynet Malicious (score: 100)
Kaspersky HEUR:Backdoor.Win32.Convagent.gen
BitDefender Gen:Heur.Mint.Zard.59
NANO-Antivirus Clean
SUPERAntiSpyware Clean
MicroWorld-eScan Gen:Heur.Mint.Zard.59
Rising Trojan.Kryptik!1.B663 (CLASSIC)
Sophos Troj/Krypt-VK
F-Secure Trojan.TR/Crypt.Agent.qymiw
DrWeb Trojan.PWS.Stealer.37399
Zillya Clean
TrendMicro Trojan.Win32.AMADEY.YXDHCZ
McAfee-GW-Edition BehavesLike.Win32.Lockbit.dh
Trapmine Clean
FireEye Generic.mg.120cbb2cca4d4036
Emsisoft Gen:Heur.Mint.Zard.59 (B)
SentinelOne Static AI - Suspicious PE
Jiangmin Trojan.PSW.Stealerc.bf
Webroot W32.Malware.Gen
Avira TR/Crypt.Agent.qymiw
Antiy-AVL Trojan/Win32.Kryptik
Microsoft Trojan:Win32/Fabookie.RZ!MTB
Gridinsoft Trojan.Win32.SmokeLoader.bot
Xcitium Clean
Arcabit Trojan.Mint.Zard.59
ViRobot Clean
ZoneAlarm HEUR:Backdoor.Win32.Convagent.gen
GData Gen:Heur.Mint.Zard.59
TACHYON Clean
AhnLab-V3 Trojan/Win.RedLine.R595181
Acronis suspicious
BitDefenderTheta Clean
ALYac Gen:Heur.Mint.Zard.59
MAX malware (ai score=86)
DeepInstinct MALICIOUS
VBA32 BScope.TrojanRansom.Stealc
Cylance unsafe
Panda Trj/Genetic.gen
Zoner Clean
TrendMicro-HouseCall Trojan.Win32.AMADEY.YXDHCZ
Tencent Trojan.Win32.Obfuscated.gen
Yandex Clean
Ikarus Trojan-Spy.Agent
MaxSecure Trojan.Malware.300983.susgen
Fortinet W32/GenKryptik.ERHN!tr
AVG Win32:RansomX-gen [Ransom]
Cybereason Clean
Avast Win32:RansomX-gen [Ransom]
No IRMA results available.