Static | ZeroBOX

PE Compile Time

2022-04-25 06:48:59

PE Imphash

a589c292925e83b27bb92739ab013116

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x000a50aa 0x000a5200 7.45051133964
.data 0x000a7000 0x0038a824 0x00003c00 1.32820378069
.lorih 0x00432000 0x00000400 0x00000400 0.0
.kub 0x00433000 0x000005dc 0x00000600 0.0
.rsrc 0x00434000 0x00006048 0x00006200 3.93397403997

Resources

Name Offset Size Language Sub-language File type
RT_CURSOR 0x00438768 0x000008a8 LANG_NEUTRAL SUBLANG_NEUTRAL dBase III DBT, version number 0, next free block index 40, 1st item "\251\317"
RT_CURSOR 0x00438768 0x000008a8 LANG_NEUTRAL SUBLANG_NEUTRAL dBase III DBT, version number 0, next free block index 40, 1st item "\251\317"
RT_CURSOR 0x00438768 0x000008a8 LANG_NEUTRAL SUBLANG_NEUTRAL dBase III DBT, version number 0, next free block index 40, 1st item "\251\317"
RT_CURSOR 0x00438768 0x000008a8 LANG_NEUTRAL SUBLANG_NEUTRAL dBase III DBT, version number 0, next free block index 40, 1st item "\251\317"
RT_CURSOR 0x00438768 0x000008a8 LANG_NEUTRAL SUBLANG_NEUTRAL dBase III DBT, version number 0, next free block index 40, 1st item "\251\317"
RT_ICON 0x00436978 0x00000988 LANG_SINDHI SUBLANG_SYS_DEFAULT dBase III DBT, version number 0, next free block index 40
RT_ICON 0x00436978 0x00000988 LANG_SINDHI SUBLANG_SYS_DEFAULT dBase III DBT, version number 0, next free block index 40
RT_STRING 0x00439ec8 0x00000180 LANG_SINDHI SUBLANG_SYS_DEFAULT data
RT_STRING 0x00439ec8 0x00000180 LANG_SINDHI SUBLANG_SYS_DEFAULT data
RT_STRING 0x00439ec8 0x00000180 LANG_SINDHI SUBLANG_SYS_DEFAULT data
RT_STRING 0x00439ec8 0x00000180 LANG_SINDHI SUBLANG_SYS_DEFAULT data
RT_STRING 0x00439ec8 0x00000180 LANG_SINDHI SUBLANG_SYS_DEFAULT data
RT_GROUP_CURSOR 0x00438738 0x00000030 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_GROUP_CURSOR 0x00438738 0x00000030 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_GROUP_CURSOR 0x00438738 0x00000030 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_GROUP_ICON 0x00437300 0x00000022 LANG_SINDHI SUBLANG_SYS_DEFAULT data
RT_VERSION 0x00439028 0x00000204 LANG_NEUTRAL SUBLANG_NEUTRAL data

Imports

Library KERNEL32.dll:
0x401010 WriteConsoleInputW
0x401018 CommConfigDialogA
0x40101c FindResourceExW
0x401028 WaitNamedPipeA
0x401034 GetModuleHandleExW
0x401038 WriteConsoleInputA
0x40103c SetComputerNameW
0x401040 OpenSemaphoreA
0x401048 SetTapeParameters
0x401050 ReadConsoleW
0x40105c EnumTimeFormatsA
0x401060 EnumTimeFormatsW
0x401064 GetCommandLineA
0x401068 GetDriveTypeA
0x40106c GetVolumePathNameW
0x401074 LoadLibraryW
0x401078 GetConsoleMode
0x40107c FatalAppExitW
0x401080 ReadConsoleInputA
0x401084 CreateEventA
0x401088 SetConsoleCP
0x401090 GetFileAttributesA
0x401094 SetSystemPowerState
0x401098 ReadFile
0x40109c FindVolumeClose
0x4010a0 GetACP
0x4010a4 GetStartupInfoW
0x4010a8 RaiseException
0x4010ac GetShortPathNameA
0x4010b4 FindFirstFileA
0x4010b8 GetLastError
0x4010bc SetLastError
0x4010c0 PeekConsoleInputW
0x4010c4 SetVolumeLabelW
0x4010c8 HeapUnlock
0x4010cc MoveFileW
0x4010d0 CopyFileA
0x4010d8 VerLanguageNameW
0x4010dc GetTempFileNameA
0x4010e0 FindClose
0x4010e4 GetAtomNameA
0x4010e8 LoadLibraryA
0x4010ec LocalAlloc
0x4010f0 CreateHardLinkW
0x4010f4 AddAtomW
0x4010f8 RemoveDirectoryW
0x4010fc SetCommMask
0x401100 FoldStringW
0x401104 FoldStringA
0x40110c GetModuleHandleA
0x401110 FindNextFileW
0x401114 GetConsoleTitleW
0x401118 VirtualProtect
0x401120 GetShortPathNameW
0x401128 DeleteFileA
0x40112c WriteConsoleW
0x401130 SetFilePointer
0x401134 FlushFileBuffers
0x40113c GetComputerNameA
0x401144 ExitProcess
0x401148 GetConsoleCP
0x40114c SetStdHandle
0x401150 MoveFileA
0x401154 HeapAlloc
0x401158 GetProcAddress
0x40115c GetModuleHandleW
0x401160 DecodePointer
0x401164 WideCharToMultiByte
0x401168 HeapReAlloc
0x40116c GetCommandLineW
0x401170 HeapSetInformation
0x401178 WriteFile
0x40117c GetStdHandle
0x401180 GetModuleFileNameW
0x401184 HeapCreate
0x401188 EncodePointer
0x40119c IsDebuggerPresent
0x4011a0 TerminateProcess
0x4011a4 GetCurrentProcess
0x4011b0 TlsAlloc
0x4011b4 TlsGetValue
0x4011b8 TlsSetValue
0x4011bc TlsFree
0x4011c4 GetCurrentThreadId
0x4011cc HeapFree
0x4011d0 GetCPInfo
0x4011d4 GetOEMCP
0x4011d8 IsValidCodePage
0x4011dc CloseHandle
0x4011e4 SetHandleCount
0x4011e8 GetFileType
0x4011f0 GetTickCount
0x4011f4 GetCurrentProcessId
0x4011fc Sleep
0x401200 RtlUnwind
0x401204 MultiByteToWideChar
0x401208 HeapSize
0x40120c LCMapStringW
0x401210 GetStringTypeW
0x401214 CreateFileW
Library USER32.dll:
0x401224 CharUpperBuffA
0x401228 CharUpperW
Library GDI32.dll:
0x401008 GetTextFaceA
Library ADVAPI32.dll:
Library SHELL32.dll:
0x40121c DragAcceptFiles
Library WINHTTP.dll:
0x401230 WinHttpWriteData

!This program cannot be run in DOS mode.
`.data
.lorih
CorExitProcess
FlsFree
FlsSetValue
FlsGetValue
FlsAlloc
(null)
`h````
xpxxxx
?ZEM-'^
?{yK+;
?765@Z
?e')lW
UUUUUU
333333
?333333
?UUUUUU
?$rxxx
HH:mm:ss
dddd, MMMM dd, yyyy
MM/dd/yy
December
November
October
September
August
February
January
Saturday
Friday
Thursday
Wednesday
Tuesday
Monday
Sunday
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
GetProcessWindowStation
GetUserObjectInformationW
GetLastActivePopup
GetActiveWindow
MessageBoxW
`h`hhh
xppwpp
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
_nextafter
_hypot
1#QNAN
1#SNAN
cisicofiyotufifuhafexuvisoyugomubovulatesenayacarajeheyugifavapomocumovuv
lunoraruxanapolewimewogicujijul
0.1 %f
veluguhikukilud
uTVWhh{@
^SSSSS
j h QJ
to=P}J
tWItHIt9It
QQSVWh
j@j ^V
URPQQh@
tRHtCHt4Ht%HtFHHt
t"SS9] u
PPPPPPPP
PPPPPPPP
;t$,v-
UQPXY]Y[
<+t"<-t
+t HHt
WoN5gN
wczRe#
}dWB?
zb!{)N
t"v53vM
CjOD';
/&?r+N
-2J(3?
9c,CGM,9
@#DIk:u
5W.sPH]o<'
jIC6wE
$ec$~mx~z
T^x8&5
FDW"\
RNSdaz
Z:A=OC
eyW7^p
=fp0_Hv
ans{7c
+0G+.D
l[o|23
R<^JA?
GBollfY
{pR+zI
DQWE(wdH
QAsqn3
5Qddi
WH.R.
v0[Mzv
9CoQS.
|^9shz=
*W7UL3
)K^V@-
~';D?8
|aS-0[
br?+Es
G4HVxsM:H
Y?x`D]<
'F2,w:
dbB(j
kVo((Zd
W !Tg$S
a=YztI
FD"<9y u
63^p/,
a@kq4\
11c2grF*
!?p3|C
EKz|lu
0rB%|_[n
Xvc|vLy
)q,vuf
7!>0T|
?c+IfI
Ue;'@G
mKOzUo
Wy|xO!
/e Qbi
Y%?&L:R
0A\.-)
,.?Xc
tm[w".>
McPh^@
lF%bO!
C?RT&a
/T]#PP,
XGz=K4
$u6+$
;},^l\
jw%o,S
$?6r}UP.
v1D"*N7s
tV8,}sc
8kFy`$^_
sspkqi
S~8r2p
|_,>pi
O:IQ]/ly
m8|5!!>
"*s7R8
F#[rnz
#y^/f>
+$[Qcw
xV-_o
'yyHx{/w
MVy.tl
;+I xd
b-=@#|e
/j1n3]
}Yrjg-
Vcu7:R
&uG=5(5
^>@~*[
+xq1g#<$
<s8!EzAB
C6~K?PV'2H
?ZAg j
zq?neG
v-vF)P
SH/9Y2c
sJ{QsmHP
;lt4]
<E1~z"
}kvMm
a\R"~&
)v.zG$
_.Ud>?)
rUYl(v[
ngJvda
toevi@
snH[!{
$nz/TEh
YhDACr
i;Gy|9
)\W-kb
0}b.]a
lr^#ZK
; Kn7W
BK$o>ub
@oO?].
4~QN:`i!
;"_m.6>
0W.)(Te
Ur? /u
'-)SE^
tc-'wd^
i]SD5| 9
V(xKi.h*
)J7'hs
ejStmU
<_d|sS
v]<^Ei
/8<jw3K.
."75K&
NZ.[he
95}qE3
*m:]JW]
RT"]at
?G^7V
y8d&+V
_=P|;~
Z%5~~?
]|G$Hn
Kf09n7
7-lC^yc
zT:)Q^
UYQU1KC)8
D4~+r/
As}p}D
q"{by9.
w$avzjv
byNl8b*
UUj@V
^Cn"?u
j1Fd2u
,EB!LY
=NHHJR
w;6*uz#
Pj"bei
(bomYO7
yG3>X#
9KZR@L:
H0[@sh
^qN0H(V
6`C3.6B
QV"R35
K<$0o9
#}F"]y
\^QV0w
H:2.pe
)*QE=%b
dWkScW
F%/]_D
v5@p}O
jeb=o%
e,u|KG
Um1(O<u
p55^S}
I10x4_
h&0%cF
ja6HhPgt
5C;D 7
-k3 =UC
>2N#+QRU
yhZ/v-p
ZSSW=
bPEGb0
DaCjIql
`L<9:Iq
<CuH!!
R+=@BQd
A ,QAY
x>0~sK
1@f8Z~K
1:`diYC
EiF|a(
nXqV>
uq5sZV
\a-sil)I{
0YF#mM{'
S~v!3n
dPIu~
RP+p{,
l[Nd%%
oTZ)s)
7xB)+k
@MpIMvI
?H$c9$
E7scw_
,JG!V A
LmdUpi%d
_fbYX=0*
_j:uzA#a
xE>Gl@:_
`"j>Z.
CN:ill
%Fym^'.
$NI8Y_
Bj<yV:l
3Px\_o`
c[C;2r
NF0*L?
\$7z[e
h]i1c"
)%}x\3!?6
tf}4}NH
v4hMZq
/a[:l!
}meZ59n
:"&'X\"
`2ZH5}
0M32Z$fA
Wbv~Tl
CMg~fo
6cv|[&
oNCV:9,)
qJ">0DE
BL+wj"%x
1h?HB*r3
q,Q'L5
]s[?8n
5.qlp`
m>"wW7#
Co+yRD_p
@IP:_cY
{Eak&
6+A\0O?
\WuDlI.
Osjl?z`
yC`v{c|
+|IkB
]2<~3os
,x+?,aLn
|bvwm
] \*7C/`b
u&/!O/W^
GD7itC
9nA8_C
/;d>39
U;f]lJ
p$tT=@I
Y<GEkP7s
JX&J{.:
XIrupt
i;B9Y5
3$<zez
l@XPrc
.5c2fo
SvE9|<
EG"7wQHd
>ZG/Ekm%
bt*VxW
J?E;jnq
~zA>@^
=^[Z*t
!;<l'\
Hf"@Wy
Y#L7iv
vt\xTd
Ur|u?Lc
Dw.!4fx
8W0gax:C
y@kI7C
Towf.5
y8hng<
N+J1Ly
Va-NZM
t#o:?h
V[qr9\_
Ov=jqq#
Np.=:HP
+]J5dc
E]a{/)
%lC#e]q
/<Wl#<
O$m5t.Zau
,ZYFD=(e
639$+4!
yuMGUF
hj')S&
R_]Dqb
$2~>:(
SBV&9
teQ"J!
$_@J]M
g&L&PQMa
67,`<6
Gxg'ufn
atUYyQ
uj_$h=4v
V^Beg%
"vwNNM
ck/(AT
4U}k/o
,%d^3B
_Z\uz=
I.P{VB9wx
"e?X?A
)\8C 3&.\
NEW.!G_s~Ln
mH@@"~
k^];^z2q
m"x}`R/Ix
tb/"<F
g#F2n$$
.r-FHh:+v
dCg_Y"
DSGoa.
E89o q[
+A*AMN
d#z.X)
Y'&U-/h
}pho$<p
5(Ns9$
G)CJ!-<
b1#}8~QZ
W-&#B\
^^,q'Zd4j
8H0JH2
wb%~pE
JGvTpB+*sf
O]I<R5H
*s<qhu
bY*K_j
lYGanX
aZY0UW
#kKn5s
#B5LM|
d-J;^7
F~FXg
i :2Wu
Yy]M3c
1tFUd<Jf
}dU{"y7
H` EE^
`Fb+!q
gagTk8gWffTK
~*qL?^AR
9@%HH$
Y.${#k&
rXEn{:V
p{ca0(
JF?,! +
>r&o 's-
@a*R%
o)Z_%-"Q
Q;{Y4p
LjwD#t
Z^M_?nI
E?*uQ=uf
\G*jlk
N)r~e/
~l*>NN5
dOj:(E
't[>nw
@2+0yf;8
b1as}%
)]u8 r
AA>@f>
Ab@{bgV\
q9HDcu
~K\3d
pzz"w&
qn+@4$
R:i_~G
[y :'w
0$`>%&
EJk|biC"
JaUj.8)
OpOk69
RZ@i:?j
JpV;{B
>"4"#0
IiigZ
}|F(Lk
2u1xrI
&tb`ky
<}_P3d
vR?SP
'7L P9
}.%8\"
-Ukz?a
i}`K.p
!|("MA
c^H:i~
%F!qAR;
5k#[n)~
w}3p*|
"@<A]
I+#)d*
ik?S8M
=55SmBE
hJ"?v8dG*a
9GqZg(
@5|]>f
#['A,H
~HdseIR
TJLdpR
z7EyyYs5
\bCJ+tfB
3z\TO|<
T,Mts5
d#6Y4.
ob<%L9
0s>GWu
S_I@^uu
+-(4lMK
3zmHb
@}!*M@
.8j3jmm
OLMqYV~
8-si3P
[%[1x
+9I'`
;V(6_G
5@v[n;$
FgVVCL
<~-Z=^
1Nh7qy
j6{hXJ
7@v['{![
\0^mDz
<72WA,y
\DYbOt
4_+{ux
zeOB.I
8'[Xrx&
uAq`Y%
#QZUN
5R`zd3
pwJEd,
N\q*V I
CEUUb+
"sE+-y
zgUQAI{
/=6$$?g
\oHEMq
Hk3o`s;
7QHtea
pw**j8
+wrS;
LTS}s)ncg\s
Mp;")`^
FB{b5ON
0lGco8#7lR
AarxJG*dz|)r
Se*ZKO
s/.f4Pu
mE"=W[
RU=EBG
JQV=zwG*Io
#6noz1
W.}/>R
'~0$i`
7,x:hN=z
fr| i@V
&Z\KUyD
)BP&hN
`w.T}J
}&c)98
23"#\NkZ!
c'q UaE
u?"e'Z
nSu*f%
VFXpBi0
jLJ1l?H
W8<_5a\~
Sa2}1K
p 9ksP
D<:vfL5
u/+nK0k0
XA<Q{5
e$GQ!L
mezW2C
Pv[K_x
OYe&GK
gKOp@L
~KXO8|
f1Aain
;OI~8b
n6Rw{9
d??c5Zy
ogP&~"
E3_y5e@
';A d$
J4wK^A;
G0BS7;
l)i]#u
eTF;6Y}S
vrkKWx:#O
CXUKbWV
tpux'
m:Ec#'>
$o0#gu
9mQ~D^A
s~i-8p
fpsYpJ
`M)~qG
A1QH:e
RsL3-'
>H~`%!|_
)Uxo8y
+pV7m*
B>u*}N
ywv$GsO+\V
n$pmat
3?x$!'
Sg:S0K
:x?L6K
j[*t>LL
yve<ql
OZ%8Xbf
or[;'U
T9rx"9+
U^<_aY]
,_f2E&
Jguz=E{0
B(19'5
XfXH)A
=onDu
Ek[Gy:
^-M}(]
x70~Az
` cho9D
N8jH(1
+K2UB[
3,Kf_kuE
rppRQ|
wQ~g6,
F9,$a;u
2/}.y,
P<OP)V
ppO@~wF
7 ce'B
`~,"V0
Byw{'o
;dqA@?K
Q*<'l|>|
%,}/AM
)S4S_9
Yx*Qq1
UVp.2}
3T"ObL
ib).8<d
54:Q+'
O4-4ye%j
3iaKbVP
e#+xh~~
P,@lF_
3l7XruY
HAEkz^H
a.z#zzR
=.v$,d
bTivw3
Fvt<MSn&[5
Rw$%/eJ
=aYEAx
U`Cp X
&K?T>y
a5Dw*'
~GS~RP'
JCx4kG\Y5
k3P>'M
-{?D)7
|)"k(;
:X67Aj
f.a^J+T
!>SdX3
}xpDp>
WLM<A^
\t">+>
lB[3:~
_5x=_=wE\
_.zRWY
EV'.ic
yy\]Dau
W],7vRv
tO4:>@
LD8$m'
ZV#^mRh
`[UebE
WaO`lV
5(2Ur?B
N2[*(4rp
9X6^-{
..~W^3[
>`>klKi
VUl/i}
m~!307
>?b'.
la7W)y_d
C:_Y5a
{j@+`4
n?cQ1l
O5Quh7Z_
1ncRd9'!Cb
`HnUj+
0iB|uhI+
p`}{1#CHw
t(tw'.
x,iyAbt
ks<0&G
'8/sEO-
N*m. V
)zc/RS
_O/:-q3
h~,Y,Z
B%IcA\
^4;^<
Q~rvG
wna5R*
,oA#`W
Ne^*'hw
*T/#or
nYI(HS
U$odRdr
jH>2WS
02aP6
<oB) a
wu5b|F1Z
Z_VSB5
GL+dGSh=
}@U5h3
<J1eHW
2IW#3(X[
+-SMx&\
VvW0|Q
ZFo<iv
Wg8q<
:^>B6"tl1AY
LsJv5D
U#':PB
00K"yB
zg^oz]=[
i`M vl
5!Tn.s
(N8;R\3
Ji5J~ENW
O4C^vk8
b?KC"&
N?]/H_*z
p`P,xH^?
L)W[bx[
T`z$3Q
u_>F)s;
wG@6L
d1R<QG
ydaFwkV
A5IxI9
T,\v+YE
+W\RV\
(V#j|e
~H5dZ<
$1|qKH
t-N.TGl2-8
:#(LAt'
iiEz!4
z<"ssh
xtV0Dd
$7b9so_
i\VI||
}+\4#+Uy
lo%B#?qZ
fW>W0K
g4f&1
)^<>DV
ie>~.=
G~egwVL
hoVlQa
nQE_M<fB
JCSJC
v1B7a\3
~yf!QR
wT.66^
!P.m^:/
71Yg>s;
> fJy'
c#[o2Y
fqO+Xkp
_i{ja_
aXJG"C
{ID@v4
F3yb.
,@}A(B
<]tNP^
}v+6;w
(8nQ{c
+dKWa`
Wn'>}
cg-K\^
C^yQ.G
( %War
x+qm-~
X`-BM&!
F=H2lJ427O
~dd$b>
\yR#US
3q^kG~
IGf<gz
Pn#"A`
XtMyb=D-
}0l2ht
Fn3kx`
expOrM
ms%Zt
z6pH:i
, a,6:
`s0m!
r^l$;=
PZLtSW
94{8w^
lF+M+w
Zozk'6
@&Bb-$
)j4>*ju[>m?
0"E(X=
|\>.bMA
;=:LE,E
nG4z=l
FaaUJed
uD$yWJ^
/P8Lt:r
`:D$QLv
`F":~U
Sb$k?E
Eo5[x-q
4Tr{|[n
3u]?fdCl
Q~IjMl
4jquQQh
87~Po#
Q&-SI^
unxC$f
B,tMUU
_z`:H]
fn|P`F
DmqgRy-
$n5 .U
2Qp l/
}pVY~|S
d*z:_c_
\ ;5.>W`
@x+U~~
9#UXA-7
SK(*82
Ht6Qa!
k"}|m_
36TH;y
Um>Gk$s
rq*mCj
~FDh~K36
-Ui{9wi
dL+ij7
1?`C/~fa
\'%ngN<
wG'vMq'
6fUSp
4)|GMdU
jLQ]{o
D;IJNnE
[SSluc
@&|X)\E
:*l~&O
&cpts&2e
Q{v%v1
`EpDS"8^
PFtEVA
W2t0Ky
)_%Bd,H
t>oK$<
UepPrb
'y#Tz-8"
uD&6v
1/n^?V
=7I0:
jq.}1?
)(6-$Z
<"-rX9]
MPN>*^_x
/_rR)_N
.&oud(OE
.qY)PO
rn.*)y
u}HR*\
ywirW_
%}}(5/
v8irJk
*~VGDk
dAQ=Q2
A:$oU<
9!*'90
\n4dJb
j18hs/
]DlmlDK5
z"}^Y?
mnb'x]
'BIrx,
S8dC5p
b]t(qV
NpJuYQ
pnxG@+{
m.t':_
Q+z[,
b+(xE.
7g,rRL
v?M'cZ
PkxTHF
D<F-LP#
9(qfxdO
`lDo$K
m4SI2F0`
UF-loh@
fO4)_E
83gqu!
P&FDPT
r^f8 c
6l5uZ2
t[-kH3
!3V6^
cx27$Y;y
<DwD>Q
> >o!P
k>,$YZ
e2#Cxc
eEM9f|
^r[UXR
ng!p;{
>BDCi
l=a1'Ht
GwtGE{b
Da.{.H
yHS{Hd
n2Z#Ar4
K;(vF-
E4!v8
E<0er:#
as!XNy+
T;mu)It
+$.%'
ldj5nJ
I+-F9"9
k5M:G<[
,mr._*
~[*9+r
E/lW(R
..V>%x
:W<'ylRr
]"R5:a
3}RQW<a
4B}InB
'<vpyPf
Z?p18t
KQB_(j
52GNeE
d![&r8$
]yV%x<
rx%DL`|
Z9N](
hw.@Ib
YE?#+c
=*iuj~
XXc=4u
^W-}}_
es1Up2
;/4dN?Z
LI6mvH
r~5n +VA
WYoK'w
1#3zA;
T7/\
b8vf.u
? dg2
X0Fk/Y^
sFORoX|6
N}cEj'
S%vxZ=M
`f.o}!
?:*uHeD
]d2Lu+
KIb(vl
UR]3%
i3x;Lg
]=k[I!
-`@)~}
C}-/P
gaFiFk
ve6LsA
?C~YU.
dy7JQB
f)41'>
87.K=;
/N)=*l
G9-"^WO0S
uhBp)0ziI<s
I<gU h
:q!MGDz
T~GiW7
S09sYi:p
5PI~AR
'M|&QY
'SJ;/I
jJUy~`
6qw;<\
S\#qj.
@.-W#dC
p2T$P
t*]<fO-
1(:41G
hicav,
6L06K<Ye
=axBdX
(koIM/
_V8ki4
cC82qB'w
'q,8L'
po[Gi1(AF
MZR[+I
n\h8Zp
Mjbme|
{GCdHB
@Jl16s
1{Ci(y
oPO<`=
}%3._.
|any%AX
>5l&:\
8ox86/
~SJ+tBA
u7 oh?
D$()D$
D$0)D$
T$ RPP
D$(Ph`G@
ExitProcess
GetVolumeNameForVolumeMountPointA
GetComputerNameA
FindVolumeClose
WriteConsoleInputW
GetConsoleAliasesLengthW
CommConfigDialogA
FindResourceExW
BuildCommDCBAndTimeoutsA
MapUserPhysicalPages
WaitNamedPipeA
SetDefaultCommConfigW
GetEnvironmentStringsW
GetModuleHandleExW
WriteConsoleInputA
SetComputerNameW
OpenSemaphoreA
GetSystemDefaultLCID
SetTapeParameters
ConvertFiberToThread
ReadConsoleW
GetWindowsDirectoryA
GetConsoleAliasExesW
EnumTimeFormatsA
EnumTimeFormatsW
GetCommandLineA
GetDriveTypeA
GetVolumePathNameW
GetEnvironmentStrings
LoadLibraryW
GetConsoleMode
FatalAppExitW
ReadConsoleInputA
CreateEventA
SetConsoleCP
DeleteVolumeMountPointW
GetFileAttributesA
SetSystemPowerState
ReadFile
GetCompressedFileSizeA
GetACP
GetStartupInfoW
RaiseException
GetShortPathNameA
GetNamedPipeHandleStateW
FindFirstFileA
GetLastError
SetLastError
PeekConsoleInputW
SetVolumeLabelW
HeapUnlock
MoveFileW
CopyFileA
EnumSystemCodePagesW
VerLanguageNameW
GetTempFileNameA
FindClose
GetAtomNameA
LoadLibraryA
LocalAlloc
CreateHardLinkW
AddAtomW
RemoveDirectoryW
SetCommMask
FoldStringW
FoldStringA
GetPrivateProfileSectionNamesA
GetModuleHandleA
FindNextFileW
GetConsoleTitleW
VirtualProtect
QueryPerformanceFrequency
GetShortPathNameW
ReadConsoleOutputCharacterW
DeleteFileA
KERNEL32.dll
CharUpperW
CharUpperBuffA
USER32.dll
GetTextFaceA
GDI32.dll
AbortSystemShutdownA
ADVAPI32.dll
DragAcceptFiles
SHELL32.dll
WinHttpWriteData
WINHTTP.dll
MoveFileA
HeapAlloc
GetProcAddress
GetModuleHandleW
DecodePointer
WideCharToMultiByte
HeapReAlloc
GetCommandLineW
HeapSetInformation
IsProcessorFeaturePresent
WriteFile
GetStdHandle
GetModuleFileNameW
HeapCreate
EncodePointer
EnterCriticalSection
LeaveCriticalSection
UnhandledExceptionFilter
SetUnhandledExceptionFilter
IsDebuggerPresent
TerminateProcess
GetCurrentProcess
InitializeCriticalSectionAndSpinCount
DeleteCriticalSection
TlsAlloc
TlsGetValue
TlsSetValue
TlsFree
InterlockedIncrement
GetCurrentThreadId
InterlockedDecrement
HeapFree
GetCPInfo
GetOEMCP
IsValidCodePage
CloseHandle
FreeEnvironmentStringsW
SetHandleCount
GetFileType
QueryPerformanceCounter
GetTickCount
GetCurrentProcessId
GetSystemTimeAsFileTime
RtlUnwind
MultiByteToWideChar
HeapSize
LCMapStringW
GetStringTypeW
SetStdHandle
GetConsoleCP
FlushFileBuffers
SetFilePointer
WriteConsoleW
CreateFileW
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
|{z}~|
~~{~||
|~{}~|~~
|~|z{{
}{{|{~y~
~{|y||
}z{~}|
zzzzz~
~}}~~~
|~}~~{z
}{|{|}
z~~~}{|
}~||~~
~~{}~~}z
z~~|z{
~|{~{||
~}zy~|
z{{}|~~
||~|~}}
mscoree.dll
runtime error
TLOSS error
SING error
DOMAIN error
- Attempt to use MSIL code from this assembly during native code initialization
This indicates a bug in your application. It is most likely the result of calling an MSIL-compiled (/clr) function from a native constructor or from DllMain.
- not enough space for locale information
- Attempt to initialize the CRT more than once.
This indicates a bug in your application.
- CRT not initialized
- unable to initialize heap
- not enough space for lowio initialization
- not enough space for stdio initialization
- pure virtual function call
- not enough space for _onexit/atexit table
- unable to open console device
- unexpected heap error
- unexpected multithread lock error
- not enough space for thread data
- abort() has been called
- not enough space for environment
- not enough space for arguments
- floating point support not loaded
@Microsoft Visual C++ Runtime Library
<program name unknown>
Runtime Error!
Program:
KERNEL32.DLL
(null)
HH:mm:ss
dddd, MMMM dd, yyyy
MM/dd/yy
December
November
October
September
August
February
January
Saturday
Friday
Thursday
Wednesday
Tuesday
Monday
Sunday
WUSER32.DLL
((((( H
h(((( H
H
CONOUT$
gahipapizeyavegejofitefolafe
cmovuwefivinije
tisutiforuniwarikozelabunabunage
bonusexunixarabilucujozuxatu
dfumicecikosef
sayitup
zazubulusamimipu
gudarevenolijaninuhidelifi
girahapayaregifojaporozoheg
kuciravidabisifokomuwefejuyoroxi
fawababoyisulowuzepih
@jjjjj
@jjjjj
/ P6pL
,/KPip
/-P?pR
VS_VERSION_INFO
StringFileInfo
037485B3
InternalName
ElasticAttrebas.exe
LegalTrademark1
DoesGet
OriginalFilename
Huklusa.exe
ProductName
Jadgazfu
ProductVersion
1.0.2.1
VarFileInfo
Translation
5Tazasubeti xetebisudo caxokotodife lopaboh jadeb dohi
TCajuxu ladoxasutarajol vabidonuciheba fulokupejivo fawezey womedasimixe sini pofihil
Huyoba sawovotemil hefok
Tupomod jisugKPev segafi nokokexefojihol zizaba womufe masawisisoh babo vunixevonak rihaf#Gotixah mixek dififis vugajoxawixozoYisofebu suhemiluhedafaj pokicay datozudurodefi hayahuduf yocofunurunaxi wilesilapi nokiyekez yavemedizoji gafe
Sogexa bemejuziwuye
LicujupeputiGWusivapo wovalugigafi boba koto kuzi yoyorahuxopi hugiya rivizosuginoliRWanifi yigewegufin huwefiyivixutes zecegolimu gayeramuyoyehep jota cevo ripaleniwu
Teyetunozirace rutepowec
]Vevobedirucup ruzicamek zuxenec kejive varojagabi hurugowahosukiy vojimolosu sohuc vepemujelaWZufiyuwefu pagivumuhumid ceruharucabi hokiwigilorucat bis vapodexocihuye cuxojize vocep`Jofudotizehuxe wiruvenefe hej fiwubonab ligarujokecaho xovi nixagu dirimejamej yoz zutujarihuzad
#Ruvatuku pogaw weceduba zupitujoviw
Macipuyu;Zilajozihiluyuz rizorubudawicav gucixakav misemir rogunocuh`Nadutitafoj wiruhule nenobobaxa bedado yoripobig columatimavad cilavulicume gure daj numitewoziySXolitenelejodi wacadu cib zetanebizi koperi yeziribelegubip bifecayeyaguk nikuhumom
DPeyarad jopirefuxahax pidohiyojoder red yova dariyecanimepe nuwomori"Nizanoculevaf cec celejamiz punamu1Loduk cut zixomomah sazagep jepa tefi hajovulomuy7Xewopinulesik vocoyaf rotivi teno nonavapafabi javukojafYoranahehan gononezonafinoh mawasodudarej juzosowucajo wucusorivahex ficajudakikete fufukopuduciye menKPecace taheguzitarew xufa zito berak gowadixasuna dosutujinukoc yuyaxovabof
Basaw mazucubabim
FTotavizunu gilepupiha sajaxagufufa rapesih meja hoje kuhe supugemesabi(Tun gama wesix fepiliwolac hazuy xadelug1Tom facuvi wonameket bayibocu lubobigefug jonutus
Antivirus Signature
Bkav W32.AIDetectMalware
Lionic Clean
tehtris Clean
MicroWorld-eScan Gen:Heur.Mint.Zard.24
FireEye Generic.mg.49c3a1783950fa16
CAT-QuickHeal Ransom.Stop.P5
Skyhigh BehavesLike.Win32.Lockbit.bc
ALYac Gen:Heur.Mint.Zard.24
Malwarebytes Trojan.MalPack.GS
Zillya Clean
Sangfor Trojan.Win32.Save.a
CrowdStrike win/malicious_confidence_100% (D)
BitDefender Gen:Heur.Mint.Zard.24
K7GW Hacktool ( 700007861 )
K7AntiVirus Clean
Baidu Clean
VirIT Clean
Symantec ML.Attribute.HighConfidence
Elastic malicious (high confidence)
ESET-NOD32 Clean
APEX Malicious
Paloalto Clean
Cynet Malicious (score: 100)
Kaspersky VHO:Trojan.Win32.Agent.gen
Alibaba Clean
NANO-Antivirus Clean
ViRobot Clean
Rising Trojan.Generic@AI.100 (RDML:9EvI9u/Ycpseau4n/zkXWg)
TACHYON Clean
Sophos ML/PE-A
F-Secure Clean
DrWeb Clean
VIPRE Gen:Heur.Mint.Zard.24
TrendMicro Clean
Trapmine malicious.high.ml.score
CMC Clean
Emsisoft Gen:Heur.Mint.Zard.24 (B)
Ikarus Trojan.Win32.Crypt
GData Win32.Trojan.PSE.1UONF
Jiangmin Clean
Webroot Clean
Varist Clean
Avira Clean
Antiy-AVL Clean
Kingsoft Clean
Gridinsoft Trojan.Heur!.02014021
Xcitium Clean
Arcabit Trojan.Mint.Zard.24
SUPERAntiSpyware Clean
ZoneAlarm VHO:Trojan.Win32.Agent.gen
Microsoft Trojan:Win32/Sabsik.FL.B!ml
Google Detected
AhnLab-V3 Clean
Acronis Clean
McAfee Clean
MAX malware (ai score=89)
DeepInstinct MALICIOUS
VBA32 Clean
Cylance unsafe
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Tencent Trojan.Win32.Obfuscated.gen
Yandex Clean
SentinelOne Static AI - Malicious PE
MaxSecure Ransomeware.GandCrypt.Gen
Fortinet Clean
BitDefenderTheta Clean
AVG Clean
Cybereason malicious.a06c92
Avast Clean
No IRMA results available.