Static | ZeroBOX

PE Compile Time

2023-03-10 23:47:51

PE Imphash

120ba7bb85687acfe32c4ec5264bcb00

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x0000decc 0x0000e000 6.65200265742
.rdata 0x0000f000 0x0004760e 0x00047800 7.18705268049
.data 0x00057000 0x0177c17c 0x00004000 1.19804775351
.tls 0x017d4000 0x000009cd 0x00000a00 0.00498607082918
.rsrc 0x017d5000 0x0001f4b8 0x0001f600 4.96553574563

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x017f27c8 0x00000468 LANG_TURKISH SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x017f27c8 0x00000468 LANG_TURKISH SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x017f27c8 0x00000468 LANG_TURKISH SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x017f27c8 0x00000468 LANG_TURKISH SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x017f27c8 0x00000468 LANG_TURKISH SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x017f27c8 0x00000468 LANG_TURKISH SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x017f27c8 0x00000468 LANG_TURKISH SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x017f27c8 0x00000468 LANG_TURKISH SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x017f27c8 0x00000468 LANG_TURKISH SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x017f27c8 0x00000468 LANG_TURKISH SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x017f27c8 0x00000468 LANG_TURKISH SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x017f27c8 0x00000468 LANG_TURKISH SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x017f27c8 0x00000468 LANG_TURKISH SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x017f27c8 0x00000468 LANG_TURKISH SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x017f27c8 0x00000468 LANG_TURKISH SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x017f27c8 0x00000468 LANG_TURKISH SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x017f27c8 0x00000468 LANG_TURKISH SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x017f27c8 0x00000468 LANG_TURKISH SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x017f27c8 0x00000468 LANG_TURKISH SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x017f27c8 0x00000468 LANG_TURKISH SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x017f27c8 0x00000468 LANG_TURKISH SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x017f27c8 0x00000468 LANG_TURKISH SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x017f27c8 0x00000468 LANG_TURKISH SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x017f27c8 0x00000468 LANG_TURKISH SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x017f27c8 0x00000468 LANG_TURKISH SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x017f27c8 0x00000468 LANG_TURKISH SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x017f27c8 0x00000468 LANG_TURKISH SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x017f27c8 0x00000468 LANG_TURKISH SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x017f27c8 0x00000468 LANG_TURKISH SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x017f27c8 0x00000468 LANG_TURKISH SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x017f27c8 0x00000468 LANG_TURKISH SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x017f27c8 0x00000468 LANG_TURKISH SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x017f27c8 0x00000468 LANG_TURKISH SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x017f27c8 0x00000468 LANG_TURKISH SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x017f27c8 0x00000468 LANG_TURKISH SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x017f27c8 0x00000468 LANG_TURKISH SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x017f27c8 0x00000468 LANG_TURKISH SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x017f27c8 0x00000468 LANG_TURKISH SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_STRING 0x017f4408 0x000000b0 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_STRING 0x017f4408 0x000000b0 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_STRING 0x017f4408 0x000000b0 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_STRING 0x017f4408 0x000000b0 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_STRING 0x017f4408 0x000000b0 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_STRING 0x017f4408 0x000000b0 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_STRING 0x017f4408 0x000000b0 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_GROUP_ICON 0x017ec408 0x00000068 LANG_TURKISH SUBLANG_DEFAULT data
RT_GROUP_ICON 0x017ec408 0x00000068 LANG_TURKISH SUBLANG_DEFAULT data
RT_GROUP_ICON 0x017ec408 0x00000068 LANG_TURKISH SUBLANG_DEFAULT data
RT_GROUP_ICON 0x017ec408 0x00000068 LANG_TURKISH SUBLANG_DEFAULT data
RT_GROUP_ICON 0x017ec408 0x00000068 LANG_TURKISH SUBLANG_DEFAULT data
RT_VERSION 0x017f2ca8 0x000001e4 LANG_NEUTRAL SUBLANG_NEUTRAL data

Imports

Library KERNEL32.dll:
0x40f00c GetTimeFormatA
0x40f014 GetModuleHandleW
0x40f018 EnumTimeFormatsA
0x40f01c FormatMessageW
0x40f020 GetConsoleAliasW
0x40f024 GetFileAttributesW
0x40f028 GetModuleFileNameW
0x40f02c CompareStringW
0x40f030 GetStringTypeExA
0x40f034 GetConsoleOutputCP
0x40f038 GetConsoleAliasesW
0x40f03c WriteConsoleOutputW
0x40f040 GetProcAddress
0x40f04c LoadLibraryA
0x40f050 HeapWalk
0x40f058 EnumDateFormatsA
0x40f05c SetConsoleTitleW
0x40f060 BuildCommDCBA
0x40f068 GetShortPathNameW
0x40f06c DeleteAtom
0x40f074 SetLastError
0x40f078 GetComputerNameA
0x40f07c MultiByteToWideChar
0x40f080 HeapAlloc
0x40f084 Sleep
0x40f088 ExitProcess
0x40f08c GetStartupInfoW
0x40f090 TerminateProcess
0x40f094 GetCurrentProcess
0x40f0a0 IsDebuggerPresent
0x40f0a4 GetCPInfo
0x40f0ac GetACP
0x40f0b0 GetOEMCP
0x40f0b4 IsValidCodePage
0x40f0b8 TlsGetValue
0x40f0bc TlsAlloc
0x40f0c0 TlsSetValue
0x40f0c4 TlsFree
0x40f0c8 GetCurrentThreadId
0x40f0cc GetLastError
0x40f0d8 HeapFree
0x40f0dc VirtualFree
0x40f0e0 VirtualAlloc
0x40f0e4 HeapReAlloc
0x40f0e8 HeapCreate
0x40f0ec WriteFile
0x40f0f0 GetStdHandle
0x40f0f4 GetModuleFileNameA
0x40f104 GetCommandLineW
0x40f108 SetHandleCount
0x40f10c GetFileType
0x40f110 GetStartupInfoA
0x40f118 GetTickCount
0x40f11c GetCurrentProcessId
0x40f124 SetFilePointer
0x40f128 WideCharToMultiByte
0x40f12c GetConsoleCP
0x40f130 GetConsoleMode
0x40f134 LCMapStringA
0x40f138 LCMapStringW
0x40f13c GetStringTypeA
0x40f140 GetStringTypeW
0x40f144 GetLocaleInfoA
0x40f148 RtlUnwind
0x40f14c HeapSize
0x40f150 SetStdHandle
0x40f154 WriteConsoleA
0x40f158 WriteConsoleW
0x40f15c FlushFileBuffers
0x40f160 ReadFile
0x40f164 CreateFileA
0x40f168 CloseHandle
0x40f16c GetModuleHandleA
Library ADVAPI32.dll:
0x40f000 DuplicateToken
Library WINHTTP.dll:
0x40f174 WinHttpReadData

!This program cannot be run in DOS mode.
`.rdata
@.data
uBhse@
HHtXHHt
>If90t
0A@@Ju
to=X}E
teh?7@
^F<-uB
<xtX<XtT
j h8[E
>=Yt1j
QQSVWh
jThx[E
j@j ^V
^SSSSS
j"^SSSSS
t"SS9]
v$;5|}E
0SSSSS
PPPPPPPP
0SSSSS
0SSSSS
PPPPPPPP
URPQQh
0WWWWW
AAFFf;
t+WWVPV
;t$,v-
UQPXY]Y[
jkXjef
/Yu.S3
_VVVVV
^WWWWW
0SSSSS
_VVVVV
<+t(<-t$:
+t HHt
CorExitProcess
(null)
`h````
xpxxxx
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
EncodePointer
DecodePointer
FlsFree
FlsSetValue
FlsGetValue
FlsAlloc
runtime error
TLOSS error
SING error
DOMAIN error
An application has made an attempt to load the C runtime library incorrectly.
Please contact the application's support team for more information.
- Attempt to use MSIL code from this assembly during native code initialization
This indicates a bug in your application. It is most likely the result of calling an MSIL-compiled (/clr) function from a native constructor or from DllMain.
- not enough space for locale information
- Attempt to initialize the CRT more than once.
This indicates a bug in your application.
- CRT not initialized
- unable to initialize heap
- not enough space for lowio initialization
- not enough space for stdio initialization
- pure virtual function call
- not enough space for _onexit/atexit table
- unable to open console device
- unexpected heap error
- unexpected multithread lock error
- not enough space for thread data
This application has requested the Runtime to terminate it in an unusual way.
Please contact the application's support team for more information.
- not enough space for environment
- not enough space for arguments
- floating point support not loaded
Microsoft Visual C++ Runtime Library
<program name unknown>
Runtime Error!
Program:
`h`hhh
xppwpp
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
HH:mm:ss
dddd, MMMM dd, yyyy
MM/dd/yy
December
November
October
September
August
February
January
Saturday
Friday
Thursday
Wednesday
Tuesday
Monday
Sunday
GetProcessWindowStation
GetUserObjectInformationA
GetLastActivePopup
GetActiveWindow
MessageBoxA
USER32.DLL
SunMonTueWedThuFriSat
JanFebMarAprMayJunJulAugSepOctNovDec
CONOUT$
bad allocation
n'-[B>-p
Gl*&rd
f&)%7qK[ryY
diCUm}
}OirE_
aMp8&R7>
6.GH&j
^v%x)ey
Az;VH2
pA<_a_
d>k"`/
J4j]x!
RZkr]
{gl=&Q
56]K.
S,\['r
0O|4}}M
I|lU)V
/H/h2*
Mxzix?_
|z.I-up@1
Fl)Fjd
0[imF1
i@X"yG8[1>zA
A[;Rz^6H|
[xVk!S
gS$oCW
xinbNb
f$s$/`%7
1%?-)?
/^rH>OA
P{v!Q7
BC!,i}
:]:I7
Y)f.f+
cJe83
)eU+?
2@_ub$
ar9P0V
?triu`
J Ok`G
g5<JB@TQ
;/$zGzj
tW=!:76
_&BCTN
P5]Y~$
FfpglC
3qo6B5}0
yaoi6;#AW
qQDNt;
^L3WcoW
f;"2oP
)n3iISc<H^Y
ZO$,RB
4h/[?
_~r<Bl
O0BM%,
9DT-,`
l)1>KL
X!GBv<
X6;'DHMs
u|',rUR
>XVVHq
la"FYQ
#$qe#(
L)n0M]
?~||_<
yPIOs71
Bmo^B+9
-Hd`D(
@Xq6gQL
g/&n{?
g)ygF^%O
Tt1^W;
FI~7?#
*|3<9R
1S*yaW6mK
U|(NZD2
F`se3u
9zWq;
jRF3.;u
$FGN (
+$BX}.
T@`j'E^V
i?nHtSxD
[b@Z"7
/V'!w-
>&\>B
8'cB(u<
V$hW#T
im[yI@
:Fn.o
ll[V9>
'AZ78.
Mb@yrpK
~+\QW%5
XC}iaT&
`m~y 6l
@w!1u/
lPSt[Hx:
!AuVd3
AzP{]lE
O7J-}b
}wu5mkz
,[\EOj
'Ia!,c
pXD[H_s
@1Fxf4
@=INZUr
5u2bE2
naCF{0
W:Ob#d
73T9bAFZI
3k8V#z
I@M3js
0zMink
Ns"~oi)
=i9w?L
bai99`
&y0]{}
IXl=N1
|dUOa3
(gCQ=,
OxB+<|
(RUGjU
M&Lgc'
hc .DM
&tUcN
B|9`QV'
)XK-FH
rY#RTJL
5# \9\LS
u0|W7;!
[>H}q}
8Ku-:7T
ai;E}T
\>r(i4S
:|Rt9N
wD:4v$,
P"cON)
0#$^jP=
3._mI2
m0hcR6
V2Oc:V
\B$83=ZR
(#zA%{
|T27 
J[3'va<V
/PlezEE
zv(q)F>
*EANYJS
oQaX/r
pCtHm
C?xoICp
])*d3
F>LmS;
v4W[ufK%
Mru~Y
[~Y-F!
CwOUCh
-Xi\;.e
UvQRn:
`DbD(z
(__~yp
1<zj-j
[,J=S{
M&V]yd
CU?F<:
pV@Bh2
C=l>wZ$
Von/CF0
}:+a@O
s\9D0~Cl
!vhB-yr
4X'}3[
0Nj9G2J
j.e(t=
{( d3
gP"X+1[
;pqPv`*
Um9_fo<9
.30AocR
z!Nf[U
PzQzb
Z'u?**
x}GS{N.A
;=Et@oU
`(Ij'u
1D!.)d
PKYS%e
?~ppu(~
\?2-,%
g%<<tk
J[2gRe
~}(9]aZnL
j7f|8/E5Lm
p)@%0x
SOi&51
6zv9je0
0EyWu+2C
3jP8N7
2EN!&I
v5)@VrY
.PkTJ/
%rX6_c8
!"mc%|@
`lRl-i
!3j.bE
jLSSy]
F\t'|@
owEkG(Q
x{HFjWG
{ELgw0
D%]{;XP
iQ8IU
6tU[ZQp
Fkx#@xd
>TwY'%
5_U|y9
/{=>.R
`_|:M3
-+e37NgZT
d*u>`a
vbER)9
*ka1OEG
mUKa}'An2
BXp']8
3[JSF2
f-H*0-o
<g8nEN
|lk!wU
u2Ff\i
0gPXgZ
]4,/E6
Pj!i |
;``zoL
_3J1;-
<YHPqR
W2U?*(
.ZY]Px
N=?PyX
isf'bU!c
lE6CyS
#0327dV\
M:IkoS
@b$.xW<E-S
'(rd3O
;[J5s$
}o7Z-+
paAr_r
nm%!K@
RuB}gP
j8^Q6f
]!Y?n#J
yGxcZm
v46*`]
O^l6Kt
}j.oAHc
ULVT>I
-;\,"?
<!Q'+}(
rJz),Ia
)bjTa`
uX+`C;
QR}-/V
W8Q7*oU
W~YDj5
1P;?(}9QA"
NNbSB$%
{hGD!t
=XH@$m
s&UcjfY
^<m2.3<
@"As35
h"^?)L
{g4J'3Lu
Ja&MoKX _
W9Oq?
`!3yri
yy/`gl
v>\C/g
k3)-dk
ftlTXsS
G2jTxO-0
KkrCl!
DG)9Yz
7:y(*S^
%.ou>*
""=:!?3
gI/A}j
)CeE3P
Q`2Jf3Q
?Y@L:b
<0;ZnC
&]W&}.
>.snzQ'
TN!?Z<
e,}kqj
(8HwM+
h@,p"{M;
@BJ)3s?
BoiLC4
[_r%w}
w+9@CM
vOU8J+
`4W^RO
K+G|[f|
]?eH"ke`
)-S&6y
@5=9Ix
B`4A]@
>5ViB=
fW:K"~
=]hlbOP
=5(}kdI
~}J*i[
2_P)}
y(gC}S
K=x>Cr
p',_T1
OZF[wB
\5JY`8
u8ns+>^
V; n1S
vG{>7n
A@|o%/
=s'X7,
&qCS?t{
E~2EJ5
38[~,4
EQcq>Q
({m1ED
>{rL!gU
Cj91+x+Ul
P P@#cd
p]["n3
UY9R\(|
zjPLGG]
e|fVY-g-
cTH>a>cy
f-iZ~}
<3s1SK
!3|;xq
qCSv>x
MF<ZG"
_,(Ru&
_han:i
Zzk_AV
X}[eD*
"PY;AL
pScXT&
N6X*?f:Vs,
=TKZFr]
B-lsde6
8#,AxfYC"
0z[&zd
ksSsT=
,FD1(r8
lgzm'WRn_
g#W a3
5waO2i
oRv[:}
@l2]fX
,Eb*~6O
d|pM(`u
084u[P&e
mF>l;!
tRX~1<XOSd
w\P|$^
]d"g&#w
,SVmx#
3}`XzA.
J_</Nb_
B;v97R%T
&/t)]i
Bx-']/
a[fEzs
n%l{(J
^:xW :"
GlobalAlloc
Dolakuf taxusihajinug heyad tajey mezajipuseb
Rotefuwuzizof tajiyu
msimg32.dll
GAIsProcessorFeaturePresent
KERNEL32
1#QNAN
1#SNAN
GetComputerNameA
WriteConsoleOutputW
InterlockedDecrement
GetTimeFormatA
FreeEnvironmentStringsA
GetModuleHandleW
EnumTimeFormatsA
FormatMessageW
GetConsoleAliasW
GetFileAttributesW
GetModuleFileNameW
CompareStringW
GetStringTypeExA
GetConsoleOutputCP
GetConsoleAliasesW
SetLastError
GetProcAddress
FindVolumeMountPointClose
CreateMemoryResourceNotification
LoadLibraryA
HeapWalk
ConvertDefaultLocale
EnumDateFormatsA
SetConsoleTitleW
BuildCommDCBA
DeleteCriticalSection
GetShortPathNameW
DeleteAtom
LocalFileTimeToFileTime
KERNEL32.dll
DuplicateToken
ADVAPI32.dll
WinHttpReadData
WINHTTP.dll
MultiByteToWideChar
HeapAlloc
ExitProcess
GetStartupInfoW
TerminateProcess
GetCurrentProcess
UnhandledExceptionFilter
SetUnhandledExceptionFilter
IsDebuggerPresent
GetCPInfo
InterlockedIncrement
GetACP
GetOEMCP
IsValidCodePage
TlsGetValue
TlsAlloc
TlsSetValue
TlsFree
GetCurrentThreadId
GetLastError
LeaveCriticalSection
EnterCriticalSection
HeapFree
VirtualFree
VirtualAlloc
HeapReAlloc
HeapCreate
WriteFile
GetStdHandle
GetModuleFileNameA
InitializeCriticalSectionAndSpinCount
FreeEnvironmentStringsW
GetEnvironmentStringsW
GetCommandLineW
SetHandleCount
GetFileType
GetStartupInfoA
QueryPerformanceCounter
GetTickCount
GetCurrentProcessId
GetSystemTimeAsFileTime
SetFilePointer
WideCharToMultiByte
GetConsoleCP
GetConsoleMode
LCMapStringA
LCMapStringW
GetStringTypeA
GetStringTypeW
GetLocaleInfoA
RtlUnwind
HeapSize
SetStdHandle
WriteConsoleA
WriteConsoleW
FlushFileBuffers
ReadFile
CreateFileA
CloseHandle
GetModuleHandleA
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
?,n_{>O
&o"o"""""
u6<<<u
e$$$$e
YYYp\qq??p??
xz88zSzzS=`
fCCCN 
>!..2A
2].b.//
A/!P!W
+%++++++
+"%%++E+
MMM]M:F
Y0*a*aa
ociEnE
ofAuu`
oAfVA`QQ
*******************************************************************
\auw.***
***jWRh
)i***c|
***gbH
gieAc_f@]giAife@fehAddjB\nbEgif
ebc~nsp
FUJVE9H+CJJ+;GM*AA?+otz
114P~|
||||||||||||||||||J
||||||||||||||||||||||||||||||||||||||||||||||R
|||||||||||||||||||||||||||||||||||||||||||||R
|||||||||||||||||||||||||||||||||||||||||||||R
||||||||||||||||||||||||||||||||||||||||||||R
||||||||||||||||||||||||||||||||||||||||||||R
|||||||||||||||||||||||||||||||||||||||||||R
|||||||||||||||||||||||||||||||||||||||||||R
||||||||||||||||||||||||||||||||||||||||||R
^|||||||||||||||||||||||||||||||||||||||||R
|||||||||||||||||||||||||||||||||||||||||
||||||||||||||||||||||||||||||||||||J
J||||||||||||||||||||||||||||||
||||||||||||||||||||||||||
W333WWWWWWWO
||||||||||||||||||||||J
OOWOWOOOOOOO
J|||||||||||||||||||
|||||||||||||||||
n}n}}.:&
|||||||||||||||
}}}}}}}}}}}:}::::::
|||||||||||||J
:}}}:}::::::::
J||||||||||||
:}:}:}
}::::::
gggggg
|||||||||||R
R||||||||||
|||||||||
}+zzzzz}z}zzzz}zzzzzzzzzz{
|||||||||R!7
7gz++++z+++++++++++++++++z++z
777!R||||||||
777zT+
+++++777
||||||||
||||||||
||||||||
||||||||RP,7
,PR||||||||J
J|||||||||
||||||||||
|||||||||||
||||||||||||R
R|||||||||||||
|||||||||||||||
222222222222222222222222
|||||||||||||||||
|||||||||||||||||||
|||||||||||||||||||||J
J||||||||||||||||||||||||
||||||||||||||||||||||||||||J
J||||||||||||||||||||||||||||||||||^R
R^||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
OOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOO
OOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOc
OOOOOOOOOOOOOOOOOOOOOOOOOOOOOOc
OOOOOOOOOOOOOOOOOOOOOOOOOOOOOOc
pOOOOOOOOOOOOOOOOOOOOOOOOOOOOOc
OOOOOOOOOOOOOOOOOOOOOOOOOOOOOc
OOOOOOOOOOOOOOOOOOOOOOOOOOOO
8OOOOOOOOOOOOOOOOOOOOOOOOO
OOOOOOOOOOOOOOOOOOOOO
pOOOOOOOOOOOOOOOO
OOOOOOOOOOOOO
RRRRRYY
OOOOOOOOOOO
RQYQYQ
OOOOOOOOO
OOOOOOOO
OOOOOOOg
gOOOOOO
OOOOOO
OOOOOO
UUUUUUUUUUUUUUUUUU
OOOOOO
OOOOOO
jjjjjjjjjjjjjjjjjjjj
OOOOOO7:
:7OOOOOOOm&
&mOOOOOOOOl
GGGGGGGGGGGGGGGGGG
lOOOOOOOOO
OOOOOOOOOOOp
BBBBBBBBBBBBG%
pOOOOOOOOOOOOO
OOOOOOOOOOOOOOOO
OOOOOOOOOOOOOOOOOOOOO'
'OOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOO
iJiJiiJii
HHHHHHHHHHHHHHHH
##############
@@@@@@
{~}|z{|}
~~{{{~~
~|{}|{
y|~}}}y~|
}y{|}{
{{zzz}
}}y{~|
}||{}}|
{z{}|||
}~}~}|
{}|~|z
~}~|||
~}{~z{|}}
z{|}{z~|
||~|{~z
|{|{||
=bCWbEiPOf[]iUedM=W4558(+&&
+\UC]KUfU`WfXSUSSdXLP_i]fdhfd
(bEa]EfIE]EXPiOQEbISLhcfPSUfi
/]bSfKKKT]Ea]EKWf]SXEKc[bEPUP
+KDELUCEKLfEKUfRagSfLRDPgPBD\
+XfbWEaESURaSWbPX_IfLbEQfPSEE
4IQXP]aPCPPKaPIWSPa]cEP]XhLSK
MIUXOS]UK[E]ESKcEbK[XS[G\KfES
7KX[hKQ]SQY]SQN[PPSfXPP`SEEET
=cOP]KfEc]UO]^ScEUBKXSLTSi[ab
AS]S_hXfESEKSPLSSgP[LPXbiWXfU
>f[]]EfHKbLfb]JESWWWaM]TfR[fb
FSSHEEKbRS]XgEKKTTBSSKPPcPbiX
SbXG]cfS]S]\]\P]XEL]Qc]XIcf[a
OSI]XXK[CSXcUf]P]XEKPXSb]gb^U
EXVU]EES]UcCfWSK]ffaSf]PRPKbf
fIK]EgTWaEPbEQ[ILSLXfPPfKSUEb
bciUfQKTK]NXKdDXCXaf^IfK]fTbG
fX]bbEEN]KKKISKKXhbbPSTfESSSP
fcXhff]Kb_]hSEESGXS]]SaEbIKKX
5S]UI]WEP]fSSSE[cKS]ff]]gUbSf
&8cXWWX89M>f[UbKfgWfZ_ETfgT
]hei[
iTBEX+
abIX]h
PiSXfX
"EPbXXi
&cfELiL9
$&MLLWiS
g]SbfX]f==35.hSPXXPcb
MfGKWc]BfEXBP[XbiaLh
fP]QdSXXbZK]COQESSU
hKd^hdfc]XXTZf]S]
KcaLh]SQPPKSF4
&HRXPKgEKF&
-*5-215-!*/
/.!5--2
52 88!
2!"4'2-5!,85)
2+5-42!2
"%82.)
3(.%+(566
3+1131*1$($3(+1$
5.$.+2
$/$. + +3,(
35"321$!
"3.331+
1!$!.+7
&+5.!++.%$
!3&1/1-&$(,33
7/.3-(.$!*.3
0.). 0.
!1.05+2
#&1/!021
JC:-a`jeI1
D9<>g6O^4
7U*T0G,]M
LSbk\Q8F[
+cd=VB@P.
HYf2X35RE
{~~~}~
}}~|{~
~}|~}|
bqstwz
uuuuuuuuuuuuue
mqttwm
goostu
moqttw
bmmost
hmoqsm
ssososooooooooo
>99999999999999999
9999999999999999999
99999999999999999999>
}999999999999999999999
9999999999999999999999
99999999999999999999999
99999999999999999999999
999999999999999999999999
~999999999999999999999999
9999999999999999999999999
A>>>999999999999999999999
~~~~}AA>>>9999999999999999
~~~~~A}>A>999999999999
~~~~}}}>>>>999999
~~~~~}}>}>>99
*0********)())(((((&(&&
DFMMFI

F\YUSFQ
DR`[WUKD
DRa]XUKD
JH]`YTFQ
DGONFI
WSWSSSSSN
NWWSWSSSSS

//////////.8
5/........///8
v/.........../.
5............./
:/..............
.............../
k.../............
k::5..../........
vuookok::5........
yyuuvookmkk:65...
$$$%%$%%""%"""
66666622BC5
?2?>2jjggg\Z
2262222
aaaaaaaaa]
dMJJJJJJJSkn
EV%m
b!l
RMe
Xc
UH!!`
WJH''##!!_
YTOOMKKHH'%##!^
BBBUBBBUBBBUBBBUBBBUBBBUBBBUBBBUMMMjddd
BBB'ppp
MMMOeee
!!!,!!!U!!!U!!!U!!!U!!!U!!!U!!!U!!!U!!!U!!!U!!!U!!!U!!!U!!!U777
222Csss
777Uggg
ww```A
-----]USS
yyy---
yy----
yyyy---
yy-----
SSSSSSSSSSSSSSSSSS
SSSSSSSSSSSSSSSSSS
SSSSSSSSSSSSSSSSSS8:
vvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvv
vvvvvvvvvvvvvvvvvvvvvvvvvvvvvvv
vvvvvvvvvvvvvvvvvvvvvvvvvvvvvv
vvvvvvvvvvvvvvvvvvvvvvvvvvvvv
vvvvvvvvvvvvvvvvv
j>ovvvvvvvvvvvvvvvv
vvvvvvvvvvvvvvv
vvvvvvvvvvvvvv
]jjj]]_
vvvvvvvvvvvvv
vvvvvvvvvvvv
f2^^^NN
Kvvvvvvvvvvv
^^NNNN
vvvvvvvvvv
vvvvvvvvv
vvvvvvvv
Pvvvvvvvv
\Kvvvvvvvvv
Kvvvvvvvvvv
Kvvvvvvvvvvv
vvvvvvvvvvvv
vvvvvvvvvvvvv
vvvvvvvvvvvvvv
vvvvvvvvvvvvvvv
vvvvvvvvvvvvvvvvvvvvvvvvvvv
ovvvvvvvvvvvvvvvvvvvvvvvvvvvv
vvvvvvvvvvvvvvvvvvvvvvvvvvvvv
vvvvvvvvvvvvvvvvvvvvvvvvvvvvvv
vvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvv
~~~~~~
mscoree.dll
E(null)
KERNEL32.DLL
((((( H
h(((( H
H
talezogexohosezutepejihifimipo
Cusineza yocivodaku
kernel32.dll
hejiyet
VS_VERSION_INFO
StringFileInform
040501E4
FileVersions
81.97.88.26
ProductVersion
96.62.3.66
InternalName
Change
LegalCopyrights
Revenge
CompanyNames
VarFileInfo
Translation
UDutuzudakihajit vucim boxuyasegosa vaworiho hofugojuvebahiv hayozitawoxute sah humolo
_Cavavu zuwegede vuzenu wogebosuponejo xahe senovuvus bivahicice jiyotuxuciyawi pupeyuj larexake
LVaxesuxovakihoc wumecesuxehagog xuwolikanelaviw welociwagitesok yopajibezubiYLakolihaji wezuzobunerug yemejexomefey yuxepawecagoc gesinukijayu joxoficibima nofizekeyu
Pageforixamuh pevux yohihinayiniZufa cotelinef toxilen dotezuju)Teherunubeda yohe goluyavuyecaye nukihidaNBomefexaveyaka fasicak vepebacurog yakiwaguheto femelocuke rokokovome vipihaho
Duxidopuzonite sato zovanelada
Div maxozipowi kamovavilapujo4Mosonovoriwa nosulagimico bahep tofezoxopa fomepihozBTexeyuvisa tikisoyey joginizahosi nohohopifusobu xere hewovayomeso
Hisufa fileb dapOHayebaf gene bajoponevubuy gapebulokubeso vinuyiz vos sisaru hacohiwagatuxi naw
NJukiwijix loremoy zahusuruja gowu xufinosezonojem taxotep pilop nayeyicezukadaBJukixutaz ceginewafar ripetuni hiculudogileb gupogipuy mopakihanew
EYayodaxiyulogal tafalagazutesur henerivezik cihinafeviyuwu segakazoli#Yup juhefojute hediwayuluxe zah feg@Wisawape secojecoromigu xilocogis wace femefedoyox cofabepakihel1Vavazazamuxu zimacik hizehahi kewusaroli kipu kin?Tociw gipicid busufoz futitubogixuse kog dijadiza vudiviwesozebOPoci memuvukucokixu voz xecunetudarodo zagesimihuhozeg jutobuberito mofehocadokTNomuxawimoku xobufiladu ficuge tefo jufuliborofufe dosugavab jefule sef miw wejawaji>Gekuyoyalu cay walafasapadumik fepov zizufavaf lawumawojeketetrLevoxecovi mehavabi gatikuwiwuwakop kiyayezesaxitin benaxutu zijoxiveyel sod ledepuxicojun zukijafonay niditunikusmNirekinotib sisafujenohi nijofacehomita josureruvezo yuveduzixag fenogen fatidexi zimeyijunibava nejide pucim5Wekayadewayebik vajupesucibehiz licajihatomeg luciteg&Gumoyulefa civelokenufe doronanocizuno-Bifesunafotu vuzole vehen lawijab xuladalitux0Cosixibopupe detataxuj ceyoz tuzahekituroyap danTVocewaseriruj gewiki loyedoyatic nucuxogamojez gebumuhipacuti xinim teduhobapiw kasi
Lajaburaweru susujevedatayef
Kodakomumeres zawemupivixa
HFax mafenud sux jikekek pigacohajejo luyi wehuc tog puvupubefapej motofuITalonugaxi defadut boxasaxo xehososuxaxo wac jidatute gonuge ser fudogasa
XBapasifebijobuy pinuhuvumufu sugesok gebugizum woxixujimayu tohovapikofukik tulinejohebu_Tigurigibaj simofafihehoju rakakavica mepixov kipoy zuxocudeyul pudi rarosuvapixu pay sagihorek9Hajucaxeva nuk tifidizujalef yizococu cukozoca cenuyerigiMCewicutamefew jupisusaso wevegu mibowajoze kucegoseb fexicobidopomit gisuvixi(Vakonojucuwoy werobararotivi nisetut jak
FRiyi zot nucebixi bodirunax wogamukowisawa sadewec soxudanuno gepapuboJMugiruhitunum monezijesosebu lilanagofi gemuco wixugogakomom vupaposalopad
Wuwohibovodoj
;Fayedeyeyu bizalehedap yonudakutesuzo hibox sihadiwolopenet
Antivirus Signature
Bkav W32.AIDetectMalware
Lionic Virus.Generic.AI.1!c
tehtris Generic.Malware
ClamAV Win.Packed.Fareit-10030127-0
CMC Clean
CAT-QuickHeal Clean
Skyhigh BehavesLike.Win32.Lockbit.gh
ALYac Clean
Cylance Unsafe
Zillya Clean
Sangfor Trojan.Win32.Save.a
K7AntiVirus Clean
Alibaba Clean
K7GW Clean
Cybereason Clean
Baidu Clean
VirIT Clean
Paloalto Clean
Symantec Packed.Generic.525
Elastic malicious (high confidence)
ESET-NOD32 Clean
APEX Malicious
Avast Clean
Cynet Malicious (score: 100)
Kaspersky VHO:Trojan-PSW.Win32.Racealer.gen
BitDefender Clean
NANO-Antivirus Clean
ViRobot Clean
MicroWorld-eScan Clean
Tencent Clean
TACHYON Clean
Sophos ML/PE-A
F-Secure Clean
DrWeb Clean
VIPRE Clean
TrendMicro Clean
McAfeeD Real Protect-LS!FD75736F30D5
Trapmine malicious.high.ml.score
FireEye Generic.mg.fd75736f30d58471
Emsisoft Clean
SentinelOne Static AI - Suspicious PE
GData Clean
Jiangmin Clean
Webroot Clean
Varist Clean
Avira Clean
Antiy-AVL Clean
Kingsoft malware.kb.a.999
Gridinsoft Clean
Xcitium Clean
Arcabit Clean
SUPERAntiSpyware Clean
ZoneAlarm VHO:Trojan-PSW.Win32.Racealer.gen
Microsoft Trojan:Win32/Caynamer.A!ml
Google Detected
AhnLab-V3 Clean
Acronis Clean
McAfee Clean
MAX Clean
VBA32 Malware-Cryptor.2LA.gen
Malwarebytes MachineLearning/Anomalous.94%
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Rising Trojan.Generic@AI.100 (RDML:82phhBIqWtj+HigyVd74PA)
Yandex Clean
Ikarus Clean
MaxSecure Trojan.Malware.300983.susgen
Fortinet W32/Kryptik.HBBY!tr
BitDefenderTheta Gen:NN.ZexaF.36806.Eu0@aK2rsFmG
AVG Clean
DeepInstinct MALICIOUS
CrowdStrike win/malicious_confidence_100% (D)
alibabacloud Clean
No IRMA results available.