Static | ZeroBOX

PE Compile Time

2023-02-18 18:58:06

PDB Path

C:\lareparesiyef\nexohe.pdb

PE Imphash

fb752e503b6d05b37aeae46cd3910859

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x00020bfa 0x00020c00 7.68254191848
.data 0x00022000 0x000b16dc 0x00001800 1.84163147291
.rsrc 0x000d4000 0x00162e30 0x0001a000 4.36924257412
.reloc 0x00237000 0x00001e0a 0x00002000 2.93455660475

Resources

Name Offset Size Language Sub-language File type
AFX_DIALOG_LAYOUT 0x000e7358 0x0000000c LANG_ENGLISH SUBLANG_ENGLISH_US data
AFX_DIALOG_LAYOUT 0x000e7358 0x0000000c LANG_ENGLISH SUBLANG_ENGLISH_US data
AFX_DIALOG_LAYOUT 0x000e7358 0x0000000c LANG_ENGLISH SUBLANG_ENGLISH_US data
AFX_DIALOG_LAYOUT 0x000e7358 0x0000000c LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_CURSOR 0x000ecb20 0x00000568 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_CURSOR 0x000ecb20 0x00000568 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_CURSOR 0x000ecb20 0x00000568 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_CURSOR 0x000ecb20 0x00000568 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_CURSOR 0x000ecb20 0x00000568 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_CURSOR 0x000ecb20 0x00000568 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_CURSOR 0x000ecb20 0x00000568 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_CURSOR 0x000ecb20 0x00000568 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_CURSOR 0x000ecb20 0x00000568 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_CURSOR 0x000ecb20 0x00000568 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_CURSOR 0x000ecb20 0x00000568 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_CURSOR 0x000ecb20 0x00000568 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_CURSOR 0x000ecb20 0x00000568 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x000e6e18 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x000e6e18 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x000e6e18 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x000e6e18 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x000e6e18 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x000e6e18 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x000e6e18 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x000e6e18 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x000e6e18 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x000e6e18 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x000e6e18 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x000e6e18 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x000e6e18 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x000e6e18 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x000e6e18 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x000e6e18 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x000e6e18 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x000e6e18 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x000e6e18 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x000e6e18 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x000e6e18 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x000e6e18 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_STRING 0x000edbe0 0x0000024c LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_STRING 0x000edbe0 0x0000024c LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_STRING 0x000edbe0 0x0000024c LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_ACCELERATOR 0x000e72f8 0x00000048 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_GROUP_CURSOR 0x000ed088 0x00000030 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_GROUP_CURSOR 0x000ed088 0x00000030 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_GROUP_CURSOR 0x000ed088 0x00000030 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_GROUP_CURSOR 0x000ed088 0x00000030 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_GROUP_CURSOR 0x000ed088 0x00000030 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_GROUP_ICON 0x000e0a58 0x00000068 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_GROUP_ICON 0x000e0a58 0x00000068 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_GROUP_ICON 0x000e0a58 0x00000068 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_VERSION 0x000ed0b8 0x000001d4 LANG_ENGLISH SUBLANG_ENGLISH_US data

Imports

Library KERNEL32.dll:
0x401008 SetVolumeLabelA
0x40100c CreateFileA
0x401010 FindResourceA
0x401014 GetNativeSystemInfo
0x401018 SetComputerNameExA
0x401020 GlobalAddAtomA
0x40102c GetConsoleAliasA
0x401030 GetModuleHandleW
0x401034 GetTickCount
0x401038 GetConsoleAliasesA
0x401040 GetPriorityClass
0x401044 GetVolumePathNameW
0x401048 TerminateThread
0x40104c SizeofResource
0x40105c VerifyVersionInfoA
0x401060 lstrcatA
0x401064 GetConsoleAliasesW
0x401068 GetLastError
0x401074 BackupRead
0x401078 GetProcAddress
0x40107c VirtualAlloc
0x401080 CreateNamedPipeA
0x401084 RemoveDirectoryA
0x40108c SearchPathA
0x401090 SetFileAttributesA
0x401094 PrepareTape
0x401098 LoadLibraryA
0x40109c OpenWaitableTimerW
0x4010a0 LocalAlloc
0x4010a4 GetNumberFormatW
0x4010a8 FoldStringA
0x4010ac GlobalFindAtomW
0x4010b0 UpdateResourceW
0x4010b8 VirtualProtect
0x4010bc PeekConsoleInputA
0x4010c0 ReadConsoleInputW
0x4010c4 GetCurrentProcessId
0x4010c8 AddConsoleAliasA
0x4010cc SetLastError
0x4010d0 LCMapStringW
0x4010d4 LCMapStringA
0x4010d8 Sleep
0x4010dc ExitProcess
0x4010e0 GetStartupInfoW
0x4010e4 RaiseException
0x4010e8 RtlUnwind
0x4010ec TerminateProcess
0x4010f0 GetCurrentProcess
0x4010fc IsDebuggerPresent
0x401100 HeapAlloc
0x401104 HeapFree
0x401108 TlsGetValue
0x40110c TlsAlloc
0x401110 TlsSetValue
0x401114 TlsFree
0x401118 GetCurrentThreadId
0x401120 HeapSize
0x401124 WriteFile
0x401128 GetStdHandle
0x40112c GetModuleFileNameA
0x401140 GetModuleFileNameW
0x401148 GetCommandLineW
0x40114c SetHandleCount
0x401150 GetFileType
0x401154 GetStartupInfoA
0x401158 HeapCreate
0x40115c VirtualFree
0x401168 HeapReAlloc
0x40116c GetCPInfo
0x401170 GetACP
0x401174 GetOEMCP
0x401178 IsValidCodePage
0x40117c GetLocaleInfoA
0x401180 WideCharToMultiByte
0x401184 GetStringTypeA
0x401188 MultiByteToWideChar
0x40118c GetStringTypeW
Library USER32.dll:
0x401194 CharToOemBuffA
0x401198 GetMessageExtraInfo
Library GDI32.dll:
Library WINHTTP.dll:
0x4011a0 WinHttpWriteData

!This program cannot be run in DOS mode.
`.data
@.reloc
bad allocation
string too long
invalid string position
Unknown exception
CorExitProcess
bad exception
EncodePointer
DecodePointer
FlsFree
FlsSetValue
FlsGetValue
FlsAlloc
runtime error
TLOSS error
SING error
DOMAIN error
An application has made an attempt to load the C runtime library incorrectly.
Please contact the application's support team for more information.
- Attempt to use MSIL code from this assembly during native code initialization
This indicates a bug in your application. It is most likely the result of calling an MSIL-compiled (/clr) function from a native constructor or from DllMain.
- not enough space for locale information
- Attempt to initialize the CRT more than once.
This indicates a bug in your application.
- CRT not initialized
- unable to initialize heap
- not enough space for lowio initialization
- not enough space for stdio initialization
- pure virtual function call
- not enough space for _onexit/atexit table
- unable to open console device
- unexpected heap error
- unexpected multithread lock error
- not enough space for thread data
This application has requested the Runtime to terminate it in an unusual way.
Please contact the application's support team for more information.
- not enough space for environment
- not enough space for arguments
- floating point support not loaded
Microsoft Visual C++ Runtime Library
<program name unknown>
Runtime Error!
Program:
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
Complete Object Locator'
Class Hierarchy Descriptor'
Base Class Array'
Base Class Descriptor at (
Type Descriptor'
`local static thread guard'
`managed vector copy constructor iterator'
`vector vbase copy constructor iterator'
`vector copy constructor iterator'
`dynamic atexit destructor for '
`dynamic initializer for '
`eh vector vbase copy constructor iterator'
`eh vector copy constructor iterator'
`managed vector destructor iterator'
`managed vector constructor iterator'
`placement delete[] closure'
`placement delete closure'
`omni callsig'
delete[]
new[]
`local vftable constructor closure'
`local vftable'
`udt returning'
`copy constructor closure'
`eh vector vbase constructor iterator'
`eh vector destructor iterator'
`eh vector constructor iterator'
`virtual displacement map'
`vector vbase constructor iterator'
`vector destructor iterator'
`vector constructor iterator'
`scalar deleting destructor'
`default constructor closure'
`vector deleting destructor'
`vbase destructor'
`string'
`local static guard'
`typeof'
`vcall'
`vbtable'
`vftable'
operator
delete
__unaligned
__restrict
__ptr64
__clrcall
__fastcall
__thiscall
__stdcall
__pascal
__cdecl
__based(
GetProcessWindowStation
GetUserObjectInformationA
GetLastActivePopup
GetActiveWindow
MessageBoxA
USER32.DLL
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
HH:mm:ss
dddd, MMMM dd, yyyy
MM/dd/yy
December
November
October
September
August
February
January
Saturday
Friday
Thursday
Wednesday
Tuesday
Monday
Sunday
SunMonTueWedThuFriSat
JanFebMarAprMayJunJulAugSepOctNovDec
bad allocation
zerijelicofab
zetezixobozi
satowowogejevetirugecesenajo
tuluve
hedutaboyo falutemiyugajobikigoveledudufeve poxadufaf
toxilodejuvezaciwozesofebagoki danajifafu wususopowutexoticotub xirewuye
fajiyaxayacayeyoxoxihugi sepejuxibec terovexadedaroleroxuf yohox coxuxuxanavitafuwesukod
bad exception
buhitisuwar
fatuwonu nifonu dinacilepeyudiyudimuyotobemunud vitewapebamosihamalokahibemixada vakemugenepoda
zuwelixiwawukunufujo
vacovalohonanokenagetifuselej
pomobaz kesoneconok zanarosodocukamawurehosokituvap mepunajizefuzopiyiweciyiwi
mekuxiconoyawefapelogaxilasafaz dikayovoceparawixodumur kovinulewucijaxabamiv rojubaj xehohojuyedaliyanifupuzafozogoz
msimg32.dll
C:\lareparesiyef\nexohe.pdb
PVh|+@
VVVVVVVh
VVVVVVh@-@
L$ Qj@
0WWWWW
0WWWWW
QQSVWd
HtHu4j
s[S;7|G;w
tR99u2
0SSSSS
>=Yt1j
QQSVWh
j@j ^V
0A@@Ju
URPQQhp
0SSSSS
0SSSSS
0WWWWW
AAFFf;
;t$,v-
UQPXY]Y[
PPPPPPPP
PPPPPPPP
t"SS9]
t+WWVPV
Z`PUm2
|OdaHJ"
z)1y!O
z)1y!O
Uq,O'7
`aDe=z)1y!O
oz)1y!O
qGYRnL
^:`&5
x8>\z&
#<>*fCoH"{
-go&Or)
+E4>t2
K%hxet3
"YfeQi%>
LxZ]D\'
cpLtr]
nXl3J;7
t7'C^)`
p0,z!0
bgSFcm
~?!\g
c]}4}gf
{,KP)S
K.-_iB
Sz%(_(
gjNq)3X+
p_\k./b
7Ae$=[=8ii~
xQnG}9]
%;SJ-0
^b6|;{
UOv)Ka
!M4(`b
&L9q%_
wkar21
u=Ex_m
1ln5ua
UFeoN1q
P.C=a1uV3N
KE>r2A
Fp 9\x)
/ci o+.
QGd$`>
+:2%3|
~{q j)
oa+:D!
"q5_2tn
,M<H3He
6;:,-R
6SOeq&
6o^trUNOv
!zq;Y@?'
2=WK10
yA4'Zc
A)=tLdu?8O
MxZnU
03p+'*
Xa.O"C
^65`Ff
_R]d.!\
(D:qT4
=C6MAc
_rRAEb
W,,]k8
\eae~w
_4]6S"
J/#^KH<%
H>G*bj
X-xnp&
YcqVE
*)9{m5D
Yv~b8b2
"82Hu'
[@y~*e
CUu'qk
(]:$'!
EBQD\{0
ksRxYg
KoMZR!D
b:y,@:}
HuE4<w
g,C?S7
9-Tx5X
8p>?GM
6/(os
v^N$:\(?
AR=rqW/'^
4}UoUi}g
r4Tr0)
<;*8@BZB
q'|9t{
:q6S1By
=st&|\
C@xD7$
;4TOkO
:8Sj|Tq
Y^hP>=
]o_up#
x^~z v
b=+,,*qhu'"*
(C?_vw
TvUw&{
@/+b;<
$f$;PA&
PkQ7P#
"8m!E~
]#Oq2D5
Hf'EhK]RiG
8l$5bv
RzAim}
X"X6~B
cS8=3b_k
/zi[,rw
kHv$_HC
\Cw+?7
?sV(Y`
4sMXzd[
v9j}*s
'1C62j
Dt}vf`
JON~EZ~
v~5RR"d
,IREMM
xz7A[e
`Q[djxo~
C]lJ3Z(
?p{E~K
^=K[1S
2*+4n1
sN'O%a
t.ko_8
)fZR5=
R.Ua
f#rt[AG
}`Sfzf
qF@X]%
<jlQ`x
tUbK`\
Y[bF|q
S>A0ZO
%;kS\r
FillConsoleOutputCharacterA
SetVolumeLabelA
CreateFileA
FindResourceA
GetNativeSystemInfo
SetComputerNameExA
GetConsoleAliasExesLengthA
GlobalAddAtomA
InterlockedIncrement
SetConsoleTextAttribute
GetConsoleAliasA
GetModuleHandleW
GetTickCount
GetConsoleAliasesA
GetWindowsDirectoryA
GetPriorityClass
GetVolumePathNameW
TerminateThread
SizeofResource
GetSystemWindowsDirectoryA
DeleteVolumeMountPointW
EnumSystemCodePagesA
VerifyVersionInfoA
lstrcatA
GetConsoleAliasesW
GetLastError
InterlockedFlushSList
SetLastError
BackupRead
GetProcAddress
VirtualAlloc
CreateNamedPipeA
RemoveDirectoryA
CreateMemoryResourceNotification
SearchPathA
SetFileAttributesA
PrepareTape
LoadLibraryA
OpenWaitableTimerW
LocalAlloc
GetNumberFormatW
FoldStringA
GlobalFindAtomW
UpdateResourceW
FreeEnvironmentStringsW
VirtualProtect
PeekConsoleInputA
ReadConsoleInputW
GetCurrentProcessId
AddConsoleAliasA
KERNEL32.dll
GetMessageExtraInfo
CharToOemBuffA
USER32.dll
GetCharABCWidthsFloatW
GDI32.dll
WinHttpWriteData
WINHTTP.dll
ExitProcess
GetStartupInfoW
RaiseException
RtlUnwind
TerminateProcess
GetCurrentProcess
UnhandledExceptionFilter
SetUnhandledExceptionFilter
IsDebuggerPresent
HeapAlloc
HeapFree
TlsGetValue
TlsAlloc
TlsSetValue
TlsFree
GetCurrentThreadId
InterlockedDecrement
HeapSize
WriteFile
GetStdHandle
GetModuleFileNameA
DeleteCriticalSection
LeaveCriticalSection
EnterCriticalSection
InitializeCriticalSectionAndSpinCount
GetModuleFileNameW
GetEnvironmentStringsW
GetCommandLineW
SetHandleCount
GetFileType
GetStartupInfoA
HeapCreate
VirtualFree
QueryPerformanceCounter
GetSystemTimeAsFileTime
HeapReAlloc
GetCPInfo
GetACP
GetOEMCP
IsValidCodePage
GetLocaleInfoA
WideCharToMultiByte
GetStringTypeA
MultiByteToWideChar
GetStringTypeW
LCMapStringA
LCMapStringW
.?AVlogic_error@std@@
.?AVlength_error@std@@
.?AVout_of_range@std@@
.?AVtype_info@@
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
.?AVbad_exception@std@@
.?AVexception@std@@
.?AVbad_alloc@std@@
3333333333333333333333333333333333%
kkkkkkkkkkkkkkkkk
AAAAAAAAAAAA
pAAAAAAAAAAA
2AAAAAAAAAA
TAAAAAAAAAA
AAAAAAAAA
mAAAAAAAA
2AAAAAA
LLLLLLLL
cg33333333333333333
ggggggggggggg
AcAABAcAccccccccAA
nABAcABAcccAcAccccc
3KnAAAcAAAAAAccAcAcAc
AAAAAAAcAAAAAAAAAm
((((((((
{AAAAAAAAAAAAAAAA
AAA{AAAAAAAAAAAA.
2{A{A{A
{AAAAAAAAAAAAAA
A{AAA{AAAAAAAAcO
hhhhhhhhP
AAAAAAAAAAAAAA&
j3333333333
AA{AA{AAAAAAA2
qqqqqql
//////////u
e33333333333?
NNNNNNNNNN
nNNNNNNN
>NNNNNNN
NNNNNN
77777aaaaaS
))))(()))))
[
NN N N N
NNNNNNNNNNN9
NN NN N N
NNNNNNNN
NN N NN (QZ
kkkkkkkkkkkkkkk
&NNNNNNNNNNNNNN&
''''''''eskvva&k
//O/O/
kvvkfkN,,J.G
kvvkfk9NN
HkkkkkHf
W$kvvkW/
vvkWO/O/O///1xz
kkkkkavvvkWOO|OOO|
4vvvvkW
kkkkkvvvvvk
-:vvvvvvvvvvva
vvvvvvvvvvvv
w*o.vvvvvvvvvvvvvvvvvvvvv
vvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvv
yuaaB
zjy<<!
AAaAA'
}|~}z|
|~|~z}
~|}y}|
~}}z|{}
|~}||~
~}}z{{
||{{~~
|}||}~~
{|y~z|}
}|y{}~
~}z~|~
|y}{}~
~{}~~~|
{~{|~|
|~{yz|}{
{~~}}}
~{|y~|
}}~~|||}
~{~~}~{
z~~z||
z}}}}|
z{|~|}
z||~}|
{{~{~}
mcmcmcmccHccmcmm
hhrhzrrhh
,tBtBE,
""P+mS{
ttttttttttttttttttttttttttttttttttttttttttttttttttttttttttttttttttttttt
tttttttttttttt
tttttttttttttt
ttttttttttttt
Qittttttttttttt
ttttttttttttt(Ou3
u2tttttttttttttt
tttttttttttttt2
(ttttttttttttt
(ttttttttttttt2u
R(ttttttttttttt
(ttttttttttttt
ttttttttttttt
tttttttttttttv
tttttttttttttvu
ttttttttttttt
ttttttttttttt
ttttttttttttt
ttttttttttttt-jG&
tttttttttttttt
+Vttttttttttt
tttttttttt
tttttttttt
ttttttttttV^[b
ttttttttttV
^QQ^bC
ttttttttttt
tttttttttt
(ttttttttttttttttttttttttttttttttttttttttttttttttttttttttttttttttttttttttttttttttttttttttttttttttttttttttttttttt
YYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYY
YYYYYY
YYYYYY
YYYYYY
x1 YYYYYY
lYYYYYY"
2YYYYYY
YYYYYY
YYYY)Ls
BYYYYlC
YYYYYY)
K_YYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYY
~~~~~~
zzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzz
zzzzzz
3EEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEE3
zzzzzz
zzzzzz
****************************
zzzzzz
*>*>*>>>*>>>>>>>>R>RRRRRR2R2R2R2R2R2
zzzzzz
E**>*>*>*>>>>*>>>>>>R>>>RRRRRRRRRRRRRR
zzzzzz
E**>*>*>*>*>>>>>>>>>>>R>>R
RRRRRRRRR
zzzzzz
*>*>*>*>>*>*>>*>>>>>>R>>R
RRRRRRRR
zzzzzz
E***>*>*>*>>>>*>>>>>>>>>R>>R
RRRRRRR
zzzzzz
*****>*>**>*>>>*>>>>>>>R>
RRRRRR
zzzzzz
*>*>**>*>*>>>*>>>>>>>>>>R>
RRRRRR
zzzzzz
****>**>*>*>*>*>*>*>>>>>>>>
zzzzzz
***>**>**>*S
>>>>>>>>>>
zzzzzz
*******>**>
>*>>>>>>
zzzzzz
*****>**>**"
>>>>>>>
zzzzzz
********>*
>>>>>>>
zzzzzz
******>***>S
zzzzzz
**********(
zzzzzz
******>*
>>>>>>
zzzzzz
*******
zzzzzz
*******L~
zzzzzz
******
>>>>>>
zzzzzz
******
zzzzzz
******
zzzzzz
******
zzzzzz
******
zzzzzz
zzzzzz
zzzzzz
zzzzzz{{{{{{{{{{{{{{{{{{{{{{{{e
e{{{zzzzzz{
nO{zzzzzz{
t{zzzzzz{
ezzzzzz{
zzzzzz{
zzzzz{p
zzzz+{p
,,,OOOt
zzzzzz+{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{e
zzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzz
zzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzz
zzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzz
zzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzz
zzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzz
2``````````````````````````
`}&&&&&
}}}}}}}
`}&&&&&
<L*sGD
`}&&&&&
`}&&&&&&&&
`}&&&&&&&
(zzzzj
J9zzzz
\fzzzzzzzzzzzzzzzzzzzzz
dzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzz
))jjjjjjjjjjjj)))j++++++++++++j))j
j))IIIIIIIII
))I;}}T
u))IIIIIIIIIII[
)))))))))))))))))))))))))))))))))
iiiiiiii
iiiiiiii
iiiiii
iiiiii
iiiiiiiii
iiiiiiiiii
iiiiiiii
iiiiiii
iiiiiiiii





2 2$2(2,2024282d2h2l2
0 0$0(0,0004080<0@0D0H0L0P0T0X0\0`0d0h0l0p0t0x0|0
1 1$1(1,1014181<1@1D1
04181H1L1P1X1p1
2 2$24282H2L2T2l2|2
5#5L5c5h5m5s5
626;6H6N6
7%7-74797A7L7R7`7h7x7
818q8{8
99(9>9E9O9^9f9k9p9w9
:#:P:V:c:l:|:
323<3Y3~4
9>9C9Z9o:
;H<P<c<n<s<
?/?A?H?N?`?h?s?
!0<1o1
:8<P?w?
5$5(5,5054585<5@5
7#7O7k7
:`:f:r:
; ;G;M;X;d;y;
<!<.<8<?<W<f<m<z<
=H=N=j=
=">E>O>
?"?(?0?7?<?D?M?Y?^?c?i?m?s?x?~?
0&0,0H0{0
1*1C1{1
2R2,343L3d3
838Q8X8\8`8d8h8l8p8t8
869A9\9c9h9l9p9
:Z:`:d:h:l:
=.=9=]=f=m=v=
>->@>X>j>
?%?,?E?Y?_?h?{?
40T0_0d0
3*4/4t4y4
7)959;9@9F9
: :':;:\:b:
:3;=;e;~;
>>)>2>=>I>N>^>c>i>o>
1H3V3\3v3{3
4#4(40464@4G4[4b4h4v4}4
1V1c1m1{1
5-565<5E5J5Y5
67B7v7|7
<,<2<@<I<X<]<g<u<
<W>^>d>,?
2!2C2U2g2y2
30373A3I3V3]3
4Y5k5x5
97:D:#;2; =
2:U:x:
;$;4;`;h;
< <4<<<P<X<`<h<t<
= =<=@=`=|=
>H>P>T>l>p>
?(?H?T?p?|?
04080T0X0t0x0
10181<1D1L1|1
0$0D0d0h0l0p0
042D2L2T2\2d2l2t2|2
4 4$4(4,4044484<4
5(585H5l5x5|5
; ;$;(;,;0;4;8;<;@;D;H;L;P;T;X;\;`;d;h;l;p;t;x;|;
mscoree.dll
KERNEL32.DLL
((((( H
h(((( H
H
yapehi kazowevefizaj
dijowifojivucusaburasomo hadalupupevozale pavotidecesafepumegururicukeyos jagofaj
kernel32.dll
penusuzimocatulubagateloxadetut
kernel32.dll
fayilazetiwimecatitihamerimume
rwapaholapewevexe
buvacamevukesopilihiwudo sofiguhawadewafuri xosaha
nevutulobuwozovapeyoyeciwec
AFX_DIALOG_LAYOUT
/ P6pL
,/KPip
/-P?pR
/ P6pL
,/KPip
/-P?pR
/ P6pL
,/KPip
/-P?pR
/ P6pL
,/KPip
/-P?pR
/ P6pL
,/KPip
/-P?pR
/ P6pL
,/KPip
/-P?pR
/ P6pL
,/KPip
/-P?pR
/ P6pL
,/KPip
/-P?pR
/ P6pL
,/KPip
/-P?pR
VS_VERSION_INFO
StringFileInfo
042230F3
OriginalFilenames
glitters
ProductsVersion
2.76.36.47
ProductName
Butilsken
ProductionVersion
58.78.50.33
VarFileInfo
Translation
Ninog fijif0Mic pemofemaf jilokopoyuleno becu kufamowugazanuUTisoyegugil matihoxe dosemurerebu kuxotarof lev luw kedux janux zuyetatoy namogazisogYBejosuyacil nohedem zixanibuv kobatu sejunobu dogexemucadivi cahuvupimocapo firideza mara
Xikusefa kec butiketokiiHacefomax yuvuxuvoyuxik xusoloratihac nokapojil jages guzaheceyagapoj zamuc pik zagowoyatarapa gogayitaseaHup xawid fanoleno vorijuyegudulo harasisemed cadujawofigupek weyepigar yimesebiwez kiloy nuduzus
CTilatuca cezurepoxavek gigapuyihuv wukorurixumi xidizagabuc wamidoz
OTaci vibikareki xexumupasamas gili zepedik lohowa tatigefiliwi wikif tacacalakiSGakeyupasunuca yiviforagof bahovodesesacad jixuw novexifak noticudav tot pimafeleda
Wukesotulurod*Havivaj tubejepoviru yimisayosep bulol cavINawunafohevulo lal juwoxufowasuw jilocalehuyuzu laz silijugifuw cawacaciz
Zufu vorezi dicapabuwosuz-Hicojabavukav dis cuva cojohexa nazahim rosozWPig hipivixakube fotonuno tobajabanara heravunemega durikuwaruloy pigiv mesanivovaxecec
[Cohazagivunoz vovejuvuniyeto mogez nepesuyo xegir pimesuxav fekula vetidixi mesekihafemaher^Huvidev bafibowot tezumaduku zoramesaso loma kel hikudowewizelo jarusihovay zoruh xaxebutulini
nCovo cohihahikarali mifituleb puwezu yusaheguxovawuc cuxaxayirerijoy piyuwapefifuwes rilanojigiz doroxifahorab
9Muribehojako yujuyebakeho xawevaroh lubibakar yoyoliciwik
Gofed yeruvibajeyer
\Hahiwu mojahikiru keceni yetofepebikun mixobaruyalo foxozewu yisekeyefosovo figekifehexi lat
Antivirus Signature
Bkav W32.AIDetectMalware
Lionic Clean
tehtris Generic.Malware
MicroWorld-eScan Clean
CMC Clean
CAT-QuickHeal Clean
Skyhigh BehavesLike.Win32.Lockbit.dh
McAfee Clean
Malwarebytes Clean
VIPRE Clean
Sangfor Trojan.Win32.Save.a
K7AntiVirus Trojan ( 005a23a61 )
Alibaba Clean
K7GW Trojan ( 005a23a61 )
CrowdStrike win/malicious_confidence_100% (W)
Baidu Clean
VirIT Clean
Symantec ML.Attribute.HighConfidence
Elastic malicious (high confidence)
ESET-NOD32 Clean
APEX Malicious
Paloalto Clean
ClamAV Win.Packer.pkr_ce1a-9980177-0
Kaspersky VHO:Trojan.Win32.Chapak.gen
BitDefender Clean
NANO-Antivirus Clean
SUPERAntiSpyware Clean
Avast FileRepMalware [Cryp]
Tencent Trojan.Win32.Obfuscated.gen
TACHYON Clean
Emsisoft Clean
F-Secure Clean
DrWeb Clean
Zillya Clean
TrendMicro Clean
Trapmine malicious.moderate.ml.score
FireEye Generic.mg.af3b051d8a6a3370
Sophos Troj/Krypt-VK
SentinelOne Static AI - Malicious PE
Jiangmin Clean
Webroot Clean
Google Detected
Avira Clean
Varist Clean
Antiy-AVL Clean
Kingsoft malware.kb.a.1000
Microsoft Trojan:Win32/Sabsik.FL.B!ml
Gridinsoft Ransom.Win32.STOP.bot!n
Xcitium Clean
Arcabit Clean
ViRobot Clean
ZoneAlarm VHO:Trojan.Win32.Chapak.gen
GData Clean
Cynet Malicious (score: 100)
AhnLab-V3 Clean
Acronis suspicious
BitDefenderTheta Clean
ALYac Clean
MAX Clean
VBA32 Clean
Cylance unsafe
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Rising Trojan.Generic@AI.100 (RDML:5QOMadMKvfERU1TwvCHslA)
Yandex Clean
Ikarus Trojan.Win32.Crypt
MaxSecure Trojan.Malware.300983.susgen
Fortinet W32/Kryptik.HFSR!tr
AVG FileRepMalware [Cryp]
Cybereason malicious.095270
DeepInstinct MALICIOUS
No IRMA results available.