Static | ZeroBOX

PE Compile Time

2022-07-24 09:43:19

PDB Path

C:\coki 48\tuzipekuhuriva-guwubohiroy_wa.pdb

PE Imphash

305c32ee7516131cef129ed3db842454

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x0006baf6 0x0006bc00 7.95819208487
.data 0x0006d000 0x00175ffc 0x00001c00 2.45971963387
.rsrc 0x001e3000 0x00013c88 0x00013e00 4.34033947841
.reloc 0x001f7000 0x0000290c 0x00002a00 2.34287063929

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x001f5988 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x001f5988 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x001f5988 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x001f5988 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x001f5988 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x001f5988 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x001f5988 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x001f5988 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x001f5988 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x001f5988 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x001f5988 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x001f5988 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x001f5988 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x001f5988 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x001f5988 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x001f5988 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x001f5988 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x001f5988 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x001f5988 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x001f5988 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x001f5988 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x001f5988 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_STRING 0x001f68e0 0x000003a2 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_STRING 0x001f68e0 0x000003a2 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_STRING 0x001f68e0 0x000003a2 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_ACCELERATOR 0x001f5e68 0x00000048 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_GROUP_ICON 0x001ef5c8 0x00000068 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_GROUP_ICON 0x001ef5c8 0x00000068 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_GROUP_ICON 0x001ef5c8 0x00000068 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_VERSION 0x001f5eb0 0x0000025c LANG_ENGLISH SUBLANG_ENGLISH_US data

Imports

Library KERNEL32.dll:
0x401014 GetCommState
0x401018 GetCurrentProcess
0x401020 GetModuleHandleExW
0x401024 AddConsoleAliasW
0x40102c CreateHardLinkA
0x401030 GetTickCount
0x401040 GetPriorityClass
0x401044 GetVolumePathNameW
0x401048 LoadLibraryW
0x40104c SizeofResource
0x401054 GetNamedPipeInfo
0x401058 SetComputerNameExW
0x40105c MultiByteToWideChar
0x401060 InterlockedExchange
0x401068 GetLastError
0x40106c SetLastError
0x401070 GetProcAddress
0x401074 VirtualAlloc
0x401078 PeekConsoleInputW
0x401084 RemoveDirectoryA
0x40108c LoadLibraryA
0x401090 LocalAlloc
0x401098 GetNumberFormatW
0x40109c AddAtomW
0x4010a0 RemoveDirectoryW
0x4010a8 FoldStringA
0x4010ac GetOEMCP
0x4010b0 FindNextFileA
0x4010bc SetCalendarInfoA
0x4010c0 _lopen
0x4010c4 GlobalAddAtomW
0x4010c8 SetFileAttributesW
0x4010cc CloseHandle
0x4010d0 CreateFileA
0x4010d4 PeekNamedPipe
0x4010d8 WriteConsoleInputW
0x4010dc BackupWrite
0x4010e4 SetStdHandle
0x4010f0 HeapFree
0x4010f4 GetModuleHandleW
0x4010f8 Sleep
0x4010fc ExitProcess
0x401100 GetCommandLineA
0x401104 GetStartupInfoA
0x401108 WriteFile
0x40110c GetStdHandle
0x401110 GetModuleFileNameA
0x401114 GetCPInfo
0x401120 GetACP
0x401124 IsValidCodePage
0x401128 TlsGetValue
0x40112c TlsAlloc
0x401130 TlsSetValue
0x401134 TlsFree
0x401138 GetCurrentThreadId
0x40113c TerminateProcess
0x401140 IsDebuggerPresent
0x401144 HeapAlloc
0x401148 HeapCreate
0x40114c VirtualFree
0x40115c HeapReAlloc
0x401160 WideCharToMultiByte
0x401164 GetConsoleCP
0x401168 GetConsoleMode
0x40116c FlushFileBuffers
0x401170 HeapSize
0x401184 SetHandleCount
0x401188 GetFileType
0x401190 GetCurrentProcessId
0x401198 LCMapStringA
0x40119c LCMapStringW
0x4011a0 GetStringTypeA
0x4011a4 GetStringTypeW
0x4011a8 GetLocaleInfoA
0x4011ac RtlUnwind
0x4011b0 WriteConsoleA
0x4011b4 GetConsoleOutputCP
0x4011b8 WriteConsoleW
0x4011bc SetFilePointer
Library USER32.dll:
0x4011cc CharToOemBuffA
0x4011d0 LoadMenuA
Library GDI32.dll:
Library ADVAPI32.dll:
0x401000 RegOpenKeyA
Library SHELL32.dll:

!This program cannot be run in DOS mode.
`.data
@.reloc
bad allocation
Unknown exception
CorExitProcess
runtime error
TLOSS error
SING error
DOMAIN error
An application has made an attempt to load the C runtime library incorrectly.
Please contact the application's support team for more information.
- Attempt to use MSIL code from this assembly during native code initialization
This indicates a bug in your application. It is most likely the result of calling an MSIL-compiled (/clr) function from a native constructor or from DllMain.
- not enough space for locale information
- Attempt to initialize the CRT more than once.
This indicates a bug in your application.
- CRT not initialized
- unable to initialize heap
- not enough space for lowio initialization
- not enough space for stdio initialization
- pure virtual function call
- not enough space for _onexit/atexit table
- unable to open console device
- unexpected heap error
- unexpected multithread lock error
- not enough space for thread data
This application has requested the Runtime to terminate it in an unusual way.
Please contact the application's support team for more information.
- not enough space for environment
- not enough space for arguments
- floating point support not loaded
Microsoft Visual C++ Runtime Library
<program name unknown>
Runtime Error!
Program:
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
EncodePointer
DecodePointer
FlsFree
FlsSetValue
FlsGetValue
FlsAlloc
GetProcessWindowStation
GetUserObjectInformationA
GetLastActivePopup
GetActiveWindow
MessageBoxA
USER32.DLL
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
HH:mm:ss
dddd, MMMM dd, yyyy
MM/dd/yy
December
November
October
September
August
February
January
Saturday
Friday
Thursday
Wednesday
Tuesday
Monday
Sunday
Complete Object Locator'
Class Hierarchy Descriptor'
Base Class Array'
Base Class Descriptor at (
Type Descriptor'
`local static thread guard'
`managed vector copy constructor iterator'
`vector vbase copy constructor iterator'
`vector copy constructor iterator'
`dynamic atexit destructor for '
`dynamic initializer for '
`eh vector vbase copy constructor iterator'
`eh vector copy constructor iterator'
`managed vector destructor iterator'
`managed vector constructor iterator'
`placement delete[] closure'
`placement delete closure'
`omni callsig'
delete[]
new[]
`local vftable constructor closure'
`local vftable'
`udt returning'
`copy constructor closure'
`eh vector vbase constructor iterator'
`eh vector destructor iterator'
`eh vector constructor iterator'
`virtual displacement map'
`vector vbase constructor iterator'
`vector destructor iterator'
`vector constructor iterator'
`scalar deleting destructor'
`default constructor closure'
`vector deleting destructor'
`vbase destructor'
`string'
`local static guard'
`typeof'
`vcall'
`vbtable'
`vftable'
operator
delete
__unaligned
__restrict
__ptr64
__clrcall
__fastcall
__thiscall
__stdcall
__pascal
__cdecl
__based(
SunMonTueWedThuFriSat
JanFebMarAprMayJunJulAugSepOctNovDec
CONOUT$
bad allocation
Buvuwadi rogivoz yoyedutezuxuk
rujehulayafaligubovotodeho
Tidevefofogoxa cozivuduy xavexixegukure
Notoreta bejopebodeluk loxirohirubeve nebawicameh
Tilucuk vejotesevidag munarijaraxe
Lobexoxac
bad exception
Lemigig
Pexelubarev
Zupowu naletuyalejozon
msimg32.dll
C:\coki 48\tuzipekuhuriva-guwubohiroy_wa.pdb
VVVVVV
0A@@Ju
tehhT@
<+t(<-t$:
+t HHt
0SSSSS
t h(-@
>=Yt1j
j@j ^V
0SSSSS
0SSSSS
t"SS9]
PPPPPPPP
PPPPPPPP
URPQQhx
t+WWVPV
;t$,v-
UQPXY]Y[
92vhTn
>y<E{y
IBV~BI
.Lr=.+3
2^VeY_
B2Z0H/
gTFvHA-
JFrkBO)
v8aCmA
8bUZ.8!
^Cw;M:
i_)kPF
i+[pJJ9
|/a:VU
4S#*O<
Po<J7u?n
RG6[C8V
DMwn+V
5O=OP}
@fP3x8
tzgK@x!
p/FbO)M
SmO`.V
r9n2T6
Jwp2\m
GAm+T
b8 "c^
"8PYy[J
M6%)'c
V6KPhB
1n`*-&
)lK.2b
)wg4mR
7z&8&zMQ)
v~ d,+
b+M`Au
@rkx5p
ps6]{Y
xI@J.4_?
)B6D)Y
Zir@-u"
$LA#^+[H
'vvYxh
~+9CNH>
P#`vhH
rBpk(t2
\8}K,S
SL`LAi
_0oCUT
fI$.box
/Jn++t
jp9\!`'
ks40=([A^
P!h^H#;
w"o;](
&^!&:E
nt\`Ve
5|r:poP
~8&Lg
IA?6BX
M><I\3
zKkHwv
TTMIq#Q
7O'h9p
2+c\eD
"5T~nS
yB(u_n
}FKX7o
9uz588
pzj*[{
x&5akV
7gAN>Jq
@Huh,j
Xig}0y
rwKAa&}
&eR@nM
LV+~ry
kmg*DX
Q:H0#V
f9!v=~
#+~Ywa
RW~.RV
#.Z.#
XN?5yh
*P'W.A
DvZ`3J
L|A!+yv
0kGHfDL
]xk<;u
+&Y>SEY
KP_hfu
<0SFlS
j#pUW6)\
|h;z:/
G/=0oF]
)pVr'>[0
6!+GGi5
'K~(,Q
Z[N(CO
>Q7$d/~
7u64E3dSw
*Gr-EH
9OvZb:q
s$pA"D
o59q"/
Onk-lb
M?ua{-T
iD>K4.
Ym4#S8
]`y]!-C D>)?
O.K6DDe5
El8s}T7
\^YbUm
G:0tX#]
RC>\yG
PkSe#*
__%3C(
XPE`z<$
V5VQ?(
4dHk1Q
K|Bx=eQB
]N;~|I4vd
Ruik)%
%2uO7+
q+IA5:66
s\=):{~
w9{?jy
BR`FD9
hb!!5RqLU
O~pX<w
o7_b6&
+H^S!J
O/`V"4l
mU`f|+
"9SRl9
tS-E,:
uuv1q2
/L/x$K
T[|Q;2p
FHLS"=B
k>T x K
l*^{I"z
S$NZT
\'"DG%k
z)4P9hu
F#$g/;/
507=nHh
cO(Po]
(=U:>+$+d5K$
%,\Zq|
7yI'c5[A
fA\vA-~
A#Q<$s
~T$"&-
WT=J+,
.t43]d
uafPpJ
./7nz((
WLDfXihw
'qm$Q}
<2$>N(o
Jw?^$
+$nWiX/
TfX}dc
Uhps]h?x
Gl'ABlOW
[}7Gnm
6Ia$?r
U3CC|Yh
8lvZ-L}!
Y>WQu:
fJCzzwJ]
!8JS#f
K3\x`dN-
l2f6@%
Ut66z<H
a+y+&0
^p|,9`
hsv$GW
Mq(\e&
}.=ZKN
4nmAb^
`#EF;"q
F"5IC&?K
ySv:"L
! /{zv
PHK}qx
3p.05rR?
+C>"6@
B]@x49
g@#q)@}
]3WvKz
6zzfki#
qp?s-pU
R~jZ~#
^%n W
F;0.B
w_#ZU/x4*
kQa-K,w
vXhIXO
57/Gr@a
wDI6|jV
r)FR4,
//'dcj[t
0>Af)j
!xId:J
+G8aIy
eyqtoe
Y6)YNi
QR-2xn
fTHnOc
k_gW[x
#j=|B
l:zNW@
PmLpvA
xF'Y3O
'~WT\
5ufI*q
NdWG'2
?>`>UX
5cs R`
79Lz~V
L#YM1(
fvoV|{
P;YgMVI\
3)ofhw
<>24y%
{sm&'z
v*I[jG
m)1J0q
_<(8rp
~U(bzW
w1H{KH
5uu~<L
>a*JZx
oT7t{~
47e.]+
bu^CyH
Y1_,^p_
wbc:~x
Xvd{G
v1@@B=
%-K*cc
RuI{9@x
wej{L
Jzb~;O
^y(g&\=\
=|pu]e
iq$%OXq
33M%kH/
2M`<b!P8b
<PQz[Hc
gHIn$q
Oob<(W
e,~0nC
0%/H3j
OL4c2m
?C)4H/
&&iYRi
'F)>*X
KY>k-iA7
{/,ZrJx
lKaTx/
}#rBW
:k%cD<
hV_S(U
wR$K/o
e|w_.^9
7bM5^(
F77~~#
1y.o?8q
C^"\0O5
bO%S3B
ur^N@e
EOl&>2
bOYf:q
6_)yBAY;
Y;5r'W
.";el\
7N'yZZ
<88b>B
x=Wlcs
|Vl_,|
v"Zc+lf
tNYi{"
xK@FxDR
NIk_n"
|s,~?Aa
SMJF;~J{
!VP(8^!
!oPd%)
1{6{sD
~mYw.
3w9^Zg
mQLnm.b
H17IK{*n"|
%H]jj*
Y|R#
B%dV.c
H'&sQIV
xWKTJR
T2qM[
4tiY n
%=cb8~
bALD:<)=
hz\WXB
%)mMw,a
Ab5~0{
2I/.iDXl
*CLFH*
ZjF'}?U|
Jn`3Q~-
cg3XSD
q_)bbL
'r|Q'~g@
44FG[]uL
n,~'Wk}Yt
#/@.pfN
-^aDn2
9y_((U
%MWmqm
xve#YV
SwpL<G(
}N6[pb\
i3[k%6
4Mu.z]
$m+'+d4
b$(Ae w
1Dh%4K
}KP~r>
4P.s=
1T"+:P
<@H'uf
LNr%zw
vN2@d'
:xpj|e7
xqTz=n
H3C`]gp
,.#|v4
'(,tj?6q
ECz;]^
N=I|^_:EB
iF6hiqWOD
8EUnF|
R*J#J98
x,t@a0
.QEF/H/
s!(Wja'E
PhX7^r
C/}6L0
_QPonj
X'bSB6
">o[#)'
?vK/ G
AVicK#
kc*;|29
k<I"oF
n^6Bz9
{3K_=b
8xk_@Q
A60 IHi]
rz"9Rr7
g>pxBI
w"#VdX.
r`uuH7?
h!a9Ai
+<K)6{f
--ldCohz
mKUhMOO
kBRIM<D
mP+I.P|
WI2:lb
#%1[+W
ZnZvy|
SavBT|
V~$KOE
>vD-~6e
o>$&I$In
o96Yf$r
;lhWe\"*
ZfZL9yoC
3DG=~W
SfEiIE
B?.O^2
%t;1nAOk
SV{Dhr
rjL`69
H+l'XE#<
6S)k<z}C
-BL6>_;
'1<HY-
;wIy#T|@??
'|l<:n
ft*(wR
\-iBv=F
cP;d-T_ P
37xF9V
D&ZvKS
gF*,x:
8yv$KBL
4`GV_$
I9%I.EF
A5~W)ii
|qolA
`OwI+&
V}VpOgQ
27^MI/e
F]DJos
kH5V:5
Vs=m|kfmR
>hQ)/~;
niV5}`
A5U_.Ao
N$(7%~
>XYrC{
7T#(h(
wIjTz;
/p;i n
%6/`.}
xd,fvR
N4x0[pJ
/8U?g}0
`1B{UJ[
)[BtqOi
$$_o/Ug1
z,Rsp2Z
hOJFFP
F~:iN'
aXA]KP$~
PS5y'Re
BQ5af'o
pr{ g
?n'!l>r
z&;~><6
/48P-8
Tk4}+2
#|I'7QpOH
w:s!Jcs
!*w]o'
]}^x!,!
l}l3;
*wv0;<
pvbu3lE2
OD7xl5
v%:2p1
j6G3k3
s*#m)r
QYksuA
=~0mwA
O-"y?<
1`',R0&
{@Z'M1
9X?+A(
[H%Lhr
v7L?Yl{
v"]dSt
D<DCC*
ML\h {
(O`MNFY
"7:3n;
^$bEEj]u
,OU1T0
\oVQ02o
'fzS`
HIeetp
'mfws*
_4;iL
yn{Dnp
e#DL7Q
$2Fu$.
xe%(,`
S8,ZgK
_~DKL4
Kjvr5,
$ja!{=
E#9JF'-y
CSXzBu
Urm\b=j
ot]1M`
QI3G[7
/O6Zd1
$VlyPA
(q=y*
<@)19i
Z9&1j8
OkW`IL-CJ-E`@f
Cz=k#)%
ZVZc:i
46Y82v
]M*tf?
_haUP_
FZ>K9H
jRAX%L
;vhWEk
l~3fou
U-HzSiiK
H}8E (
R0)l^4
~1AzCw3
)ekhh=5
Q9m1ji#
VN'L~
tzWn3f
oe7}nf
#;gNc[
u9:7;@
9u`oM0
Wpp;:Nr
2W?QTyao
QI.]i2
d.Ci5F
:a-y3.
+d3mfi;j2c
Xm8-[*
h}8`c
pEkWz(
_KL3 V
J12-YL
0M!y@{+
Ymi6ZYN/
u&L)4l
Xb'o=U
PMMa>W
S;&`K`
7F7wO
t"a-ZuE
rK/e&,+M_
!^*zf!
*J9*=t'
z3|iF/o
,)M&N`L
eT=}~kt/Q
zno?Us
kA")j$
w2"g4u
^aGGgqd|)
q/}IZ 8 qk
\e3@_N
-mDG9R.
.C+.u7prFM
PQr8wg
UN\'-g
S@yu@;
U6"]ih
1I"gr9
F_6t5T
<]cE3y
k(f`AI
OB7WohI
0:Kh<z
@YQK0,
1uYOn/9
%gvCNb
VB]v2]Z]p
EI>MI
[*<C@^
;9!{G8
i#B5^~$g
3d`7Gu
+\dV-#
F.g w"
=" 0&(
`.?S-@Nv
lLyH-r
~|D$k8
R"sL%_;*
xS>kvzr
wU|kPjrFU
yg^=0Aq}
;7lMy+
R/V_43
coO$exc
}k_ur.
UNOV r2
ABVzb'
d&1qVw7
C#PrpA
kA^v{>
?j8toQ-s
i%b4/:1j-?-
Y@n/c
H~-iwzK
*izrXaR
Qt"f`J
}5m4A*
%:),N@
,,s {uJ
\7Fb9.o>rH
nlNm>c
3]*1u3k
0((v7sB
{zw:},
x5[&"3
vE+~t6El
3[W3#;:
j[OUz9$
Y6N!MV
qij1?|U
pV&1/*
p/=%1VkG
HO2sLd
[5w9(_
#WWjn]6_
6'0Brw
[`>7T$
jjw(F`
Gy8;e.
`h@OTh
6k$dd/Q{f
mB1[Y>
a;'~)3
pL2MZm
<@BlNc
xB^wa$
CSKc.P
w(5V=ULtQ
TAhOup
0H?>OK-
dzFDY]
iA3eBN
O}U\CZ
C#7N%qA
k>F/khR2
|f20uq
n}qjQf
[OTmZk
'7nBm`
/*xS{$
}|kf\!
>jglgF
&h#ER^
tZO*@_
M-@v 9W"
x}>C@X
kfr/B/
CIm'Nl{>
%5X8?Y
|aZ=aO
+D6l$5
Q;+:U}
~4g\abJ
~]F.1-
.w"Lne
[g& K}~>
>[\k;C
MVLp5Q
omZt`^2
*O$s|]
t@*`zK
{5EM|Q
\"8.GkR.
zOb:K
{-m%<6
5$e(_<
J4)on+
[NS1.z
M4<e2O#;
W0rQBZ
>h5dl
641g CQK
7ZSkr/mC~
#h"SOv}*
{9W>h_
r`oN|1
8T*~0m
M@ `^R
3[E}D,
0Fs;D4}
Xd/&`E
nMj%15
CeD*Z~
k-1Ce:Vj
fm,[i[
_4n]L]
(b:{$?
7g`?QN
U8`o$e
61^nj@
SetDefaultCommConfigA
WriteConsoleInputW
PeekNamedPipe
WriteConsoleOutputCharacterA
GetCommState
GetCurrentProcess
GetSystemWindowsDirectoryW
GetModuleHandleExW
AddConsoleAliasW
SetVolumeMountPointW
CreateHardLinkA
GetTickCount
GetConsoleAliasesLengthA
GetWindowsDirectoryA
GetConsoleAliasExesW
GetPriorityClass
GetVolumePathNameW
LoadLibraryW
SizeofResource
GetConsoleAliasExesLengthW
GetNamedPipeInfo
SetComputerNameExW
MultiByteToWideChar
InterlockedExchange
FillConsoleOutputCharacterW
GetLastError
SetLastError
GetProcAddress
VirtualAlloc
PeekConsoleInputW
BeginUpdateResourceW
BackupWrite
RemoveDirectoryA
EnumSystemCodePagesW
LoadLibraryA
LocalAlloc
SetConsoleCtrlHandler
GetNumberFormatW
AddAtomW
RemoveDirectoryW
BeginUpdateResourceA
FoldStringA
GetOEMCP
FindNextFileA
FindFirstChangeNotificationA
FreeEnvironmentStringsW
SetCalendarInfoA
_lopen
GlobalAddAtomW
SetFileAttributesW
KERNEL32.dll
ChangeDisplaySettingsA
LoadMenuA
CharToOemBuffA
GetWindowTextLengthW
USER32.dll
GetCharABCWidthsFloatA
GetBitmapDimensionEx
GDI32.dll
RegOpenKeyA
ADVAPI32.dll
ExtractAssociatedIconW
SHELL32.dll
UnhandledExceptionFilter
SetUnhandledExceptionFilter
HeapFree
GetModuleHandleW
ExitProcess
GetCommandLineA
GetStartupInfoA
WriteFile
GetStdHandle
GetModuleFileNameA
GetCPInfo
InterlockedIncrement
InterlockedDecrement
GetACP
IsValidCodePage
TlsGetValue
TlsAlloc
TlsSetValue
TlsFree
GetCurrentThreadId
TerminateProcess
IsDebuggerPresent
HeapAlloc
HeapCreate
VirtualFree
DeleteCriticalSection
LeaveCriticalSection
EnterCriticalSection
HeapReAlloc
WideCharToMultiByte
GetConsoleCP
GetConsoleMode
FlushFileBuffers
HeapSize
InitializeCriticalSectionAndSpinCount
FreeEnvironmentStringsA
GetEnvironmentStrings
GetEnvironmentStringsW
SetHandleCount
GetFileType
QueryPerformanceCounter
GetCurrentProcessId
GetSystemTimeAsFileTime
LCMapStringA
LCMapStringW
GetStringTypeA
GetStringTypeW
GetLocaleInfoA
RtlUnwind
WriteConsoleA
GetConsoleOutputCP
WriteConsoleW
SetFilePointer
SetStdHandle
CreateFileA
CloseHandle
.?AVtype_info@@
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
.?AVbad_exception@std@@
VFjx7~
.?AVexception@std@@
ccccccccccccccccccccccccccccccccccccccccccccccccccccccc
oooooooooooooooooooooooooooooooooopcccccccccccojZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZ
opcccccccccZo
SSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSS
occcccccZZioSS
HHHHH%H%%%
"SSZocccccZoooooSI
SZoccccc
"SZocccccoZS
"SZocccccoZ
oSIQQQR
SZocccccoZ
oSq%QQQQ
"SZocccccoZ
oSIRRRQQQ
SZocccccoZ
oSqRRRR%QQ
h"SZocccccoZ
HRRQQQQ
"SZocccccoZ
RRRRRQQQ
h"DZocccccoZ
oDqHHHHHRRR%`
occcccoZ
occcccoZ
HHHHm&
occcccoZ
occcccoZ
occcccoZI
SSSSSSS
occcccoZI
occccco
o8q>!
occccco
occccco
ooooooooooooooooo
occccco
occccco
occccco
RRQQQQ
occccco
<RRRRQQQ
ccccco
(]]]]]]]]z]
ccccco
oiiZcccccco
occccccccco
H%R%R%H
occccccccco
;ccccccccco
toooooooooo;cccccccccco
cccccccccccccccccccccco
ccccccccccccccccccccccco->6>6>6>>>>>>
cccccccccccccccccccccccccponrrrrrrrrrr
ccccccccccccccccccccccccccciooooooooooo
ccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccc
OOOOOOOOOOO
5wEEEE_
UwFEFEEL
FFE@G
xxxxxxxxxxx
33333,
[[[[[[[[[[[[[[[
NEEEEEEEEEEEEEEN
[o;;;L
[??[8[
[??[8[
I;M[??[
-[[[[[-
[??[;
!ea[[[[[
????[;
[[[[[?????[
kkkkkk%
{???????????
????????????
?????????????????????
???????????????????????????????????????????????????????????????????????????????????????
---^^^^^^
nnYYY9
fxxxxx}
|}~~|}{|
|~~}~}y
~|z{}|
{{{{~~
~|z|||
}{y{}|~}
}~~}z|{y
}{|z~~
~|{{~~
||||||
~}||~{{
yz{|z{}
~{{||{{~~
|}|}|}
{~}zz|
y~z~}|
~|}~}~
~{}|z}
}~~}~|~|
}y~|z}~
|z~{z|
|{~~~z|~}
||z|z~
{~|}~|}
z~}{~|
|~{}z||
~||~|{
|}||{}z
|}z|}|}
"`HIH`
p`XHH#%E
`] p`"%
cQ#` `]
d%d?%?
qSq|5q5555
XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX
XXXXXX
XXXXXX
XXXXXX
XXXXXX
e)XXXXXX]N
4aSjXXXXXX
XXXXXX
9XXXXX9
LXXXX)
BxXXXXXX}
XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX
;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;
;;;;;(;(;((((((((((((((((((((((((((((;
;(((((
;(((((((
;(((((
;;((((((((
;;((((((
;;;((((((((((
;;;;;((((((
;;;;(;(((((((
;;;;;(;(((((((
;;;;;;(;((((((j@
;;;;;;;(;((((((j@
;;;;;;;;;;((((((j@
;;;;;;;;;;;((((((j@
;;;;;;;;;(;;((((((j@
;;;;;;;;;;;;;;(((((j@
;;;;;;;;;;;;((;(;(((j@
888|""
r~~:::
18||""
~~~:::
88||""
pppppppppppppppppppppppppppppppppp
QQQQQQQQQQQQQQQQQQQQQQQQQ
MMMMMMMMMMMMMM
*******M
MMMMMM?
MMMMMMM
MMMMMM
MMMMMB
MMMMMx
N4pppp0
~pppp0
N<OO^`YUrppp
ppppppppppppppppppppppppppp
ppppppppppppppppppppppppppppprrpppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppp
TTTTTT
TTT)ZZ<
XeeWaI
XeeWaI
111111111111
1@@@@@@@@@@@@1
144444
14444444OF
GGGGGGGGG<F
GGGGGGGGGGG
2\2`2d2|2
(9,9094989<9@9D9H9L9P9T9X9\9`9d9h9l9p9t9x9|9
: :$:(:,:0:4:8:<:@:D:H:L:P:T:X:\:`:d:h:l:p:t:x:|:
= =$=(=l=p=x=|=
> >$>,>D>T>X>h>l>p>x>
?b?t?y?
00,070D0U0i0
1:1N1T1l1r1
2?2K2Q2V2\2b2i2p2w2~2
3(30373?3G3N3Y3k3
4 4)464@4G4L4R4]4d4m4}4
5#5+515G5V5\5
6&6.636M6X6{6?7L7
8+9C9l9~9
= >)>V>q>w>
?#?.?3?C?M?T?_?h?~?
0)0S0X0c0h0
071D1Q1v1
12$2.2}2 3
3&4+4p4u4|4
5!6*616:6z6
7.7R7r7
:!:+:_:j:t:
<"=.=A=S=n=v=~=
>F>W>z>??i?
2'2<2C2W2^2v2
3)303=3`3u3
4-4E4k4
6!6&6,60666;6A6F6U6k6v6{6
;*<A<q<
034383<3@3D3H3L3P3T3X3\3i3{3M4W4d4
8$888>8G8Z8~8
939A9F9
<"<(<-<6<S<Y<d<i<q<w<
"1.1a1
4r4L5T5l5
738S8C9l9
-0G0V0c0o0
171j1y1
4$4O4X4d4
:#:S:t:
2;2H2T2\2d2p2
535Q5X5\5`5d5h5l5p5t5
566A6\6c6h6l6p6
7Z7`7d7h7l7
8!8'868<8J8S8b8g8q8
8a:h:n:
;;%;/;8;C;O;T;d;i;o;u;
071D3V3h3
9$9(9,9094989<9@9
;D;R;Z;g;
=$>1>J>
0K0Y0b0
4F4L4X4
< <@<\<`<
=(=H=T=p=|=
>8>X>t>x>
?8?X?x?
0$0(040<0D0L0T0\0d0l0t0|0
9X<`<d<h<l<p<t<x<|<
= =$=(=,=0=4=8=<=@=D=H=L=P=T=X=\=`=d=h=l=p=t=x=|=
mscoree.dll
KERNEL32.DLL
((((( H
h(((( H
H
japahigocefemajawuberacopas
fosavul
Pijavosepatupam kenib tiduvatabida viranokowis
kernel32.dll
kernel32.dll
Koxejex
VS_VERSION_INFO
StringFileInfo
042230F2
FileDescription
LegalCopyright
Copyright (C) 2022, Fofigraf
OriginalFilename
glits.exe
ProductsVersion
1.78.4.93
ProductName
Cascade
ProductionVersion
11.95.6.19
VarFileInfo
Translation
Fegafofuv7Cow tucajofemeze wirimuduteg tavukutesedey gutid yitehoFebumac fiziji bimiruke jitayos Fewile hoduxiwim nexo cotes calo
Pawadetug
Varohoyesar duvi pefezuvuvabe*Xip mofijanilecezo fufuxin basi gidotorayo(Zigawi hibeziw pununawik lode cocukuluje
]Xigahaguwonowon zimefahif nacaxos vuyibisukoc jek sanireguga girecivawahug gomixi huxey camot
Jufupupezunile gaxekemutuxevMPadipibetucah noh xomogukesikaduw fotehayolohit wovigatibobole kagew doxozetieZujuduruxo dufexoyevaniluf puhayesanedabo fewomapuxuh lowopuyuhiso dibukax wevapujetuwubom yuvixixepa/Fuvamuremejaj xigu goyihogadofow defukahu bafatnRerofezovu rux yexosabofafas zukomiwitovejop lelizusodurifuz paharuramoje zabibojunuyena nakuz wifunizayinoreh
FivikiiTamubegesuxiyoz ditatibeka yapuhogiluva pulo kapenuyanay tupuyohi wugug cabaxebatemecuy lowifoc bomuraluh{Nonigucuw cadozeheci seruwedezacihih vojuwucu tolavinawalafot leye puwelumoxegogi rawarogebeyigo nahuyiseyuj gipufoxuvadari
Pecekewocovuj
Dih loyudolewiwul
_Porojihusifutuk hir tuyesusuyevu huhiniyo niwakicayuyev jofeb giyazutakipolec gawili wibol xedu
Ricogerocegix zesufimimeyixetATufas nif citolez refonarigolohe dof gijufoko gahoyexe gos koboca[Vapakayem zamejinuku com pisohiciso satiri biloy decuco vebomewexixap hohabe pocivojocikucoNXuc cutucuridepicaz fipidu wahocahorobuw vesocinodani dero lamuvaroxeneka suboCKefapakuta ner wiyepaxez wowilakisutecit nuketun konocajebi huzebif
Taj dan yivowiro gujokel
Antivirus Signature
Bkav W32.AIDetectMalware
Lionic Clean
Elastic malicious (high confidence)
MicroWorld-eScan Clean
FireEye Generic.mg.7d09d9b412845150
CAT-QuickHeal Ransom.Stop.P5
Skyhigh BehavesLike.Win32.Generic.hc
ALYac Clean
Malwarebytes Clean
Zillya Clean
Sangfor Trojan.Win32.Save.a
K7AntiVirus Trojan ( 005690671 )
BitDefender Clean
K7GW Trojan ( 005690671 )
CrowdStrike win/malicious_confidence_100% (D)
BitDefenderTheta Clean
VirIT Clean
Symantec ML.Attribute.HighConfidence
tehtris Clean
ESET-NOD32 Clean
APEX Malicious
Paloalto Clean
ClamAV Win.Packer.pkr_ce1a-9980177-0
Kaspersky VHO:Trojan-Ransom.Win32.Stop.gen
Alibaba Clean
NANO-Antivirus Clean
ViRobot Clean
Rising Trojan.SmokeLoader!1.EB63 (CLASSIC)
Sophos Troj/Krypt-VK
Baidu Clean
F-Secure Clean
DrWeb Clean
VIPRE Clean
TrendMicro Clean
Trapmine malicious.moderate.ml.score
CMC Clean
Emsisoft Clean
SentinelOne Static AI - Malicious PE
MAX Clean
GData Clean
Jiangmin Clean
Webroot Clean
Google Detected
Avira Clean
Varist Clean
Antiy-AVL Clean
Kingsoft malware.kb.a.1000
Gridinsoft Clean
Xcitium Clean
Arcabit Clean
SUPERAntiSpyware Clean
ZoneAlarm VHO:Trojan-Ransom.Win32.Stop.gen
Microsoft Trojan:Win32/Sabsik.FL.B!ml
Cynet Malicious (score: 100)
AhnLab-V3 Clean
Acronis suspicious
McAfee Clean
TACHYON Clean
DeepInstinct MALICIOUS
VBA32 Malware-Cryptor.Grygoryi.3
Cylance unsafe
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Tencent Trojan.Win32.Obfuscated.gen
Yandex Clean
Ikarus Trojan.Win32.Crypt
MaxSecure Trojan.Malware.300983.susgen
Fortinet W32/GenKryptik.ERHN!tr
AVG Clean
Cybereason malicious.a01e21
Avast Clean
No IRMA results available.