Static | ZeroBOX

PE Compile Time

2023-11-07 15:31:02

PE Imphash

0e02f2783b58059fb828111a17212082

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x000a6b37 0x000a6c00 7.73361503233
.rdata 0x000a8000 0x00002234 0x00002400 5.43698029316
.data 0x000ab000 0x00012328 0x00001e00 1.38388667254
.rsrc 0x000be000 0x0000b0a0 0x0000b200 4.13374116168

Resources

Name Offset Size Language Sub-language File type
RT_CURSOR 0x000c6558 0x000025a8 LANG_NEUTRAL SUBLANG_NEUTRAL dBase III DBT, version number 0, next free block index 40
RT_CURSOR 0x000c6558 0x000025a8 LANG_NEUTRAL SUBLANG_NEUTRAL dBase III DBT, version number 0, next free block index 40
RT_CURSOR 0x000c6558 0x000025a8 LANG_NEUTRAL SUBLANG_NEUTRAL dBase III DBT, version number 0, next free block index 40
RT_CURSOR 0x000c6558 0x000025a8 LANG_NEUTRAL SUBLANG_NEUTRAL dBase III DBT, version number 0, next free block index 40
RT_CURSOR 0x000c6558 0x000025a8 LANG_NEUTRAL SUBLANG_NEUTRAL dBase III DBT, version number 0, next free block index 40
RT_ICON 0x000c3710 0x00000468 LANG_TURKISH SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x000c3710 0x00000468 LANG_TURKISH SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x000c3710 0x00000468 LANG_TURKISH SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x000c3710 0x00000468 LANG_TURKISH SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x000c3710 0x00000468 LANG_TURKISH SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x000c3710 0x00000468 LANG_TURKISH SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x000c3710 0x00000468 LANG_TURKISH SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_STRING 0x000c9010 0x00000090 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_STRING 0x000c9010 0x00000090 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_STRING 0x000c9010 0x00000090 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_GROUP_CURSOR 0x000c8b00 0x00000022 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_GROUP_CURSOR 0x000c8b00 0x00000022 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_GROUP_CURSOR 0x000c8b00 0x00000022 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_GROUP_ICON 0x000c3b78 0x00000068 LANG_TURKISH SUBLANG_DEFAULT data
RT_VERSION 0x000c8b28 0x000001dc LANG_NEUTRAL SUBLANG_NEUTRAL data

Imports

Library KERNEL32.dll:
0x4a8000 GetFullPathNameA
0x4a8004 UnregisterWait
0x4a8008 GlobalDeleteAtom
0x4a8018 GetComputerNameW
0x4a801c GetModuleHandleW
0x4a8020 GetTickCount
0x4a8024 GetCommandLineA
0x4a8028 GetSystemTimes
0x4a802c Sleep
0x4a8030 FormatMessageW
0x4a8038 HeapCreate
0x4a803c WriteConsoleW
0x4a8040 GetAtomNameW
0x4a8048 VirtualUnlock
0x4a804c GetShortPathNameA
0x4a8050 InterlockedExchange
0x4a8054 GetProcAddress
0x4a805c LoadLibraryA
0x4a8060 OpenWaitableTimerW
0x4a8064 LocalAlloc
0x4a8068 OpenJobObjectW
0x4a806c SetCommMask
0x4a8070 FoldStringW
0x4a8078 EnumDateFormatsA
0x4a8080 lstrcatW
0x4a8088 SetCalendarInfoA
0x4a808c SetFileShortNameA
0x4a8090 DebugBreak
0x4a8094 CloseHandle
0x4a8098 GetLastError
0x4a809c HeapFree
0x4a80a0 GetStartupInfoW
0x4a80a4 TerminateProcess
0x4a80a8 GetCurrentProcess
0x4a80b4 IsDebuggerPresent
0x4a80b8 VirtualFree
0x4a80c8 HeapAlloc
0x4a80cc VirtualAlloc
0x4a80d0 HeapReAlloc
0x4a80d4 ReadFile
0x4a80d8 ExitProcess
0x4a80dc WriteFile
0x4a80e0 GetStdHandle
0x4a80e4 GetModuleFileNameA
0x4a80e8 GetModuleFileNameW
0x4a80f0 GetCommandLineW
0x4a80f4 SetHandleCount
0x4a80f8 GetFileType
0x4a80fc GetStartupInfoA
0x4a8100 TlsGetValue
0x4a8104 TlsAlloc
0x4a8108 TlsSetValue
0x4a810c TlsFree
0x4a8114 SetLastError
0x4a8118 GetCurrentThreadId
0x4a8124 GetCurrentProcessId
0x4a812c SetFilePointer
0x4a8130 WideCharToMultiByte
0x4a8134 GetConsoleCP
0x4a8138 GetConsoleMode
0x4a813c GetCPInfo
0x4a8140 GetACP
0x4a8144 GetOEMCP
0x4a8148 IsValidCodePage
0x4a8150 RtlUnwind
0x4a8154 MultiByteToWideChar
0x4a8158 SetStdHandle
0x4a815c WriteConsoleA
0x4a8160 GetConsoleOutputCP
0x4a8164 LCMapStringA
0x4a8168 LCMapStringW
0x4a816c GetStringTypeA
0x4a8170 GetStringTypeW
0x4a8174 GetLocaleInfoA
0x4a8178 FlushFileBuffers
0x4a817c HeapSize
0x4a8180 CreateFileA
Library USER32.dll:
0x4a8188 CopyRect
0x4a818c SetActiveWindow

!This program cannot be run in DOS mode.
vRichK
`.rdata
@.data
HHtXHHt
>If90t
>=Yt1j
QQSVWh
j@j ^V
0A@@Ju
^SSSSS
j"^SSSSS
URPQQhhn@
0SSSSS
0SSSSS
0SSSSS
0WWWWW
AAFFf;
t"SS9]
PPPPPPPP
PPPPPPPP
;t$,v-
UQPXY]Y[
t+WWVPV
&Zj,_K
Vl'l`"
pOgR.?
>c0;qJ
D+=qzk
,Gyi>
FRVzl'
l#Vwvn
fClKv'8t
-}Hc+'
^8Fkp3
c(nL
+,eQ\y
I]1eUt
{pA^]sp
L<*}<f?U
-9cXvL
q.8^LB
R<=zXr
s~irnC
$ydoR8
6Xb?kS
=sQT=H$R
_ryWC&
=iaP\{
)eC|}
!2!c8)
L~cl_r
L!Bx!P
~vxpM"
_2W8oP(
mKf\`(
X^WKQv
ezW'"
~--*pW}
r;'-Ud
;Om<(8
P4d(Gz
t+)XP0:
NL[):[
\B|8${
]7|[ a
=Kxr;<O
+>*=*"h
7!w{14/
@"3c=.i
)-wlkut
xrSx
#^7F(GW
9<Zf1
k~]=eg
])}~SM
=O4O
(Q#%WK
sB*uyI
pwH3Mg
1Ots9#
n`[5k?
5c%}Y]@
j/I;Rh
B, 9\Q
/r&tZf7^\c
7n.e!D\
c:FP_R
96MP|A
);w'G:
/s?y.g
U,#jxDw
"&3o>&
<va]"2
ND8nmR
`=Cj7-
f.wr5b'
B}?EDa
B/5PB_{
4vO/VDbPi
uUNyU5
|B6Q>/
@YHT`=
ufNEuM
&eQdeT]
r>Zf0A
zmyj/N
QoE/)Q_
~= /s7
KEX-k}
Kn;e6hoY
xb~aHHV
6G'>8\
Qkl;%f
eKG]6q
jc`=@!E
\Z.U^^
h!Kax`
"P#K[ h
9y8#Y5/
3upJI^
>8,P*Y
O-!Wl*
%G@Kv{P
c;S` M
M7oXOi
?.5-x">
}U5#!e
hQujIP
rY<xzy:
&z<cO:
f;/d1i
P*R+Lv
$2C`+R
c<#d)W
P5ip{'<
5O`*:1
;VVkcK
\[b"Io
C]6C[P
H1VQxd
Sg|}/\TJ
~%"wU
I[bt?U
w##]-d9
gd(i1e
xK;3J,R
]e4!yQ
F_@Q$I
&0/N`k
Z&gf00
);:wjf
(=g'wG
wc|r?h
GIU=k
,-(D4+
l144),4
!q$Y1Wi
K_Th."
/-|r{:
iqze~|
;yqM.:
HtK3`{
^`]W.6
-1cjF6[
1:i|/
7.rVX,
l0Dpd3
Hb_k1T
7xC\Jk
l0!&v
jS4OvI]I_
9AqWJm
3[T+eQ
h)tc83g
R6iOeM
xKypphp
F(Du-9u
[^uDt*o*
Z$Dy_#
QYwXNrZ&
@11QIf
]ls Oy;
kd7&L=
$"VR&Z
/hxh0{+f)|
sv~`|td
HI7J-n
RW5c#B
T.%(6l
thV@}0
YN=N]q9-
lHAj4EAc1
7#vu>p),
@>~YOeL
j=+6sv
Uj*2OB
gx=B"Y
LJKTwV
X-fU*q__t[
*CHuQB
~JORVT
0{Y!o&4IG
!r2tk0
W48K]kAj
b$q! }
f'YygG
}{B]ngX
g/<.CP%#
LHHHb!ie1
bF'mhh}
tT+y'-
,F928C
W:Cth/
J!vm{1
4jB;VN
U{R_%#
$"K"_]X
lAGKyAu
?OY`Sz
=vu+EL
.`8FpX
y+p$N[s
mZ\&yG
z-Hd"jd/G
8$@4 >s5
y}cB0a/T
x!NfU(b
42C=s:
5(b]'P&i57q
.k-j!9
{baY-]
3/1lN9
BM3Iv_N#
34^ _GV
vT-T~8;m
n}|{o-
m$:_k^
a;P)8iH9
u.^%yO
Fk]`DW
>qq*^I*S
W?>cM%
iEC)_q
CLVLVf_
bPK>{(
\}x5mK(7
m t2Ygr
K?J{M%/+j
|LNP\)
6sw]O(
7~mTVd
e?rE#o
[Sdt;t
{Pp6p (9_
O8D19*
li+ ~2m
:W1:S2
`IJ?".
Y.4ax
vI.#{^U
VcQ:3;
]x=3r}
E8G[Gp
[|?M' 2
%j\KU$
A.1}I96
[6I!<K(
E0}U{[
OQ7A`C
CFW6;;
GZ\N)7
0s7cf$
~kGN
[>KQ5TOi
(%u2R5"
rbE<q[
+L[xa3
uCWKa@J
,(OBC[
Lj?Ey{
YeWycG
w7_!!?
eP[I!!
({%,00
^)C/OT
)M$MhAy
+zh>CY
VX/;NK
)ntvd'Zh
V?zDWm2
7wT/#J
Gyd1-l0
mzjlM`
(X?<h;
fb1D5\
S:^qB[
$w6,To
2qy N7!
a_s)]9'
z=_i`1:
SFq\f<
P ]+a@
Zf8+b*b
w*$6X)
Tp0~q|
g~#pV%
Kt>s~s
?1N3Gh1_K
]RrqFW
V9QPF,_=
T-94!>kw\
?tM&Gl
V[Z['
a"-l$#
X{hhS:
mo:vG;]p`
}o}77X<
0se=BX
@M^{f
&A| ~
,)_Mbs
@;i~I|ib
VmJ,[C
Y>c`_m
+}0hoj92
p`P[KA
8T ^!q8
Xoqj"x(
xi_sr
LVG~^9
pF4!GW
Bxi;8"9n
BRnHfBp
MR>vQH
M$ENNw
#4GZ5ivCy
-\~OR}
`)v07U
oIEn[o7
#\EiB:7+$
p#S _E2
|O!c[m
lVlCu
O=8R]s
B7xP*w
j2 %RO
4\Q8JL
ao%y6[
4h^oj)
z9f$p6g
C:"^b.2H
uaXB/W
7>rvYEW
RtnUEs
Vfd4G_&
fv^e4&
i5M~(Ii
VR$[hyL]
(Z)T'1
"\R4v
H!>aip
R>e@5p
5:&?
1fTuIf
}M)w5/H
+\1sDq
y:F\<X
oey\]J
QUKi]Q
VB_`f7
aBj5~+
Hxj#]L
8.Csas
F.5Juk
SD %.l
x'-X{WW
Cx{[$&
hWH0USN
vz]N0*
b2kCOK&
ml==?n
)&#b1*
1$:e-|
]LaWYOw
"JvlO
7K4[Cm
RW'i2M
gurJD0
c+GjYwgk
N\-tY6!
B~]Fi-
{.L`68:_
7}w~ZU
1B~5d^
gD:6:(
K8LEMY
dwXyp;
IsY\wV?
Jxxt~*
69 H'6
CzZ@F)
&`nAL&
p'i0;wn
x*1cd[
^8TD&#
y%XyTS/
-8]f\q
X{ozPJ
8N+j6/
-j#koH
!j6;^2
Lz%kV%\c
R*o.4J
xLA'.9x
X6=6-
ug;$Hf<
6*N|Hk
\V)>])
bMA4Llmr%
x?&ZT4T
363yi!
e9]V#{
1?\A?B
xkdn4N
a;nDR\`
0Y!u05*E'~qB
L(jgAB?#
A\Z%5v
1zl/cv
j&eg7zw
PfB1H(
V4e3Bt
(xVJd6r
hm@I/A
D[L}on
0ZEP8o:
7cwo_iY
2La$uj
tfZ!!d
bAu(2A^
O4E&OG
nmHOh
g9:6L8
t`5+z+
EIV?0)&
gXiqTZt
?&,V(T
xvO,mp
ujS`sH
g2#o<c7Y&/\.
*r,=W?
d2m'v`
-D!;:6
We}$+j
sZ (A
+(>2'h6
#>G},z
xEf1Z|
=(q>q
'<8JlG!Y]:
#Zv3x&+
@u'i$Q}/%
aGi"6Tp
3by{J&
*M[=]]
.`R5+V
wa7GMlJ
P*ADlYU
;n<M}v.
$cnz3K
AsFwZ.
B_UPSP
P!-#Z0
Spr^KV%
KY(?o*[?
fjbL;VLD
[FOo5{
D]K,hg
{+/R 2
0X^HtGG
>A/2:F
`0IXey
xxa7gNi
s9bkrJ
}OSU!S
I:9MI%r
7q~`2kwb
!qzLoQ
qNFqE $#
pdl#il
cv=*/m
sMHIKh
K^Rnpf
!UQ@"_
|(s-J@
1"fehX
E\Z=Um
P!*ywE
>Z"#F]
MKbe\c
>_sQ"d
1]B4;fU
ZP`,.?G
A0P%a"
U9Hf}U
"`>`bB
de$wCF
pyS~qO[
{l@_[?%
,8T}3.
aM@"Bg}dyZZ
^>. L#?!t
/d*~HC
xDd(kx
"$n\5D
)#Oyd]
-<C%KfB
-o%K''
I_"*@n
lvQ1ZfO
iAd+W#
H;wIPx
x25BA/
s[j|@q
#W8`tkM\1)
@4HE?P^
=B$>:R
`GDTD3
}|a"edn
/g(f(L
9.MHG]!
Rg@K*V
j,~{]p
7IGIwA
"%ikf@
"7v.W"eeM
w^3`Oe
@#aq9C
d:3a$F
s h4'
cK[%"f
IK;5|@
w2nV{'-W
a~@4}#&
yMP|"|*
XDHokj
=R+7Hy
FIk3AB=t(,
>i'f)>
Z6Ycz
EHVOvw
QI]-~
s[ow,d1
7M!B{t
K7f5|*
Q&$u}L
2Ni2GMv
RwF=#+
UdZ[ZJ`
~*]6{o
&_Q/^E
^o\zz|
eIIupv?
<epzlZ
c<q&V"
`&N(2lM
dbc4DH
kU*Pm$
P}!-WK'
?Kf~B]
"e4lgQ
O3sJsX
;DuvzZ
TK1]:<
_\E@SE
eB~>4K
m#U<2i
m1^,[!6A
b_?''h
8WT[do
a_6=GT
p)Cgn]
R^#xDp
<)peKtL0
)X^,%AY
8%WRxH=
<xNE3F^\d
wNv$>"
jaG66l`
#>> 9Q
eu Z5L
+RP@L6Bx
q8k!^`l
x8rw:>(
}+jMVF<
LMf5'mL
Zk+L93d
U#`Ul}
U^3-0{
!'eil*
+x$AeBo
y8<[f
V|xE@f
^EH7xy
>coib3
oOagvE[K
~FM:N0#]
U7X,$7k
~q}rCs
',XS;+
nF&cqm{z$
4_;4mK&
K25VWOn
37eXZiK
(YwLO6
jpzKa5`
,=Z+dbf#
KwPLJf
y.9Ljn
HiQmrg0
Ev,>3-
c:6My=
\|b#34
vw_+_]*
Oajlxo
v5Q5~K&H.S
8X]]M5EN
;r@+YQP
L:.7pGUi,5V
x AE&TIo
7GQC2^B
=Mzf!!
dR<blsP{
4t6Ve6
@n;tum
1?1i^M
ql_x}q
]q$G^h
4FO~l|
y}:JOI
%92z5?%
+L|9-g
t~BFC%KM
*vW{#`
>axNam
>qsfk
&I< b3G[
)Z!@T:
=Q%*zC
un`j>r
anp-,Q
wZWnup}g
=~iwg924
L?mEN^
i,OJ*`
@:{po;
X& LJ{
K$x<0l"
=a/9"M.|\
,/r$2#"h
Z//f71z
sH$vE k
6{kQkr
w7~3:\
/;Ei9
r] pqka
7<u#Vy)
_PQ!#C
\g dMX
?aUDv'5
^E=5n{
Si9r/
j%~2>g
8a.92vi<
C(:69;@
xpr}Ea
oR/sFG
4F5C}!
*w09lE
eN)Sba
~>Vze<y?
521Y4q
{Y=i:r#
EkQP^$
l)~1<.
OF]ETF
&P"k.,(#n
W*,4-W
2+\x#PJ
[8e$("env
hI wEf2Db
=yN)iz
%:]qg9
0u~$jZ
-+cV-
"C5H%
J'I:pY!
s~9.v&T
{JnNSm
9\4KS-
MIYp2S
<DxoQZL
aAwfM_mB
[6!nV.X.
AzW#Ig9
U&uXaZ
!sbH&eS
dO(98N
.fZl_m^|UQ
LbWE7E
`lYOcP
/COs3#
E(lk3C
;l~h8L
h%q4ol
dRrcH!
H~R0]8
<heJyy
Je'&L>G}
1B&$?}%
J~f$$4
C<4`y,
xfwr(1
W3*,ocJ
waAp-n
ksnydr|\
nR8,L%
@{}Nf]
y|g/pB
GJeU$m
Ist,K8
$Ft#2#~
(/R4ol
7Jtc3y9
3E,hnyjf
Zi#$7=
<E3KpB2
XdI(;d
%5gf@c
2#YJLD
Z!@eA[
Ld)(Ul
XsR_b=
NA&]&LF
r+'8o
}wuk`1P
1;spE#+P4
T~xs K
SBr~MH?q
S<u;aw
X"u 
*|RPGY
A2d0{-T(
Elv_Q=l
m3bJ9I
[{3a-u
ay0W=;E
AR9Fu#
H6P~NO
]j H,
aI}^+I6
5(c$6UeO
2~XAzp
Y@K&&f
p<Dt93qIn
iD5j&pKl
2GZ]M}o
txz)R%
YwSSc.}m
osmB66
c:'gdT
qKKcwcpy
0sCC a
3&Mfq)
#@r*4^
?r"{3h#
<dnaNkJ|/
L}J~,r
*DI1jcE
x{~Ed9
MO*3MND_
sc2G.:>OB2
%_$<v;w
0Q>ccnh
A,X.>F
"kaDt
[.WL4~U
]y^x;p5
C:xIZK{
v)I=,*
"@8KA~~
W wX_u
qm6J^A
BPExnC
>7UY*FS}
nv_Q[YE)
X*-0Sggo
zY;{]<
'uBJ9c
kKmQhI
c%fGBY
Y8("@l
}M)G|'
~&~dz3+YK
|~SQ#aUl
GEW&&.
LX3Cz^
FxNK=?
3nv*Ji
o5SL4G
fA4Z|Q
;?OD'Q
bc+V;D
-n:*(T
LwKx=O0
Cg-WH;
O=D9jL
8@K4E}H
4FuXh;n
_V\oPT
Gxx~I/x
\!KWi
09"4c`;
rloSRj
\i#6Sk!
l>;[TZ>[0
CF|H_y
T;FU19{
q6"CT|y
|B(p|
Y!b:<h
Cag:7b
*;;I_w
T3'Ps5
F~Z:}
X7UoQFx
7#[,^l
u<T!?i
8xi4~A
-^EsGhgu
6X^sHX
{{>csw
ICb*"-
0NCHNHK
!)R@?)
W"mN"*
1SjvI\<,Q
o9?edF
Mh"zt?\?
HvSE5\~
`w09IYU
-Ki!?
io]dKH
TRVMBLaw9
b*j_6/
_"8#zD
T/Y-<8
K$i>(=
^+(l>~@
&%*KCv
Lp1&6
3SG 6hG*
gN==}?
YgS-~9W
SpGl`8
" p8qKu
D-VAwxJ
tel3)
[kC&!'
`0l +2
z|XlSm
v=X>s6E
>4n:/n
.>_0)m
#V3zm
H"\Y+\
"jHO"tu%
#)}:W!9$
HRr1b|cT
z)[e6ufGP
#He|aD
HT6R#5S|S9
X?jA1
1rF6]A
M6*Sfy
}96MyA M
>A r4
:m%?uJ
kO;<"s
B3}xsGI}5
['mb7h
=P<HTKT
.7QcMqf
FGx-*A
W(AMA:H
uUZxfX<^@
"<+\-6
_3\Q%J
MdlKsx
m)5[^~
u3FkGOs
w`0[k`
H,6@Ol
Ya'CM:
q`u-]S
!'=F le;`
s(l7!(
~Ibna
(]d*,_5aW
ai7[*'
6CNnOu5
9&5-?~
oqhsLE
9mN0(&2
/*#ouz
tg$@Go
B:bJj|
:~liU
UsED!f
'B;y'E
n)?jL
RX"g ,?-
)!is!Q4
0'?Qcw
Bs]gwr
CB&+wV
ieGIk%
qUym&
yw3>U7)+
f0iK"[H
$5^x!J
vLg{@
}ZXqM?
*w?Vmh
9`J&$\
J:ZSZ]B:f3g
#rQ^o8
{4{j2'^
`G0dQRM
BqfAX:b
KC- lFI
Kq&4'?1
n3N)<b
n!Zq?w\
q^4w#3
}:}gn2UK
A!=qy=
j\3xh-
^H5;~
ue~`;n
TkC;M95
AF~]]B*#
:uES){
!i{r(Q
>5TH/T
BbU iM8L<!
P/zAS7
~YS2:"E
=[?-)M
ff:!7uBc"
Ty)Jol`
f@I5K"s
1f I.E,
BnVgLs`D)
m@VKfG
an7z?l
x@V}I!
eecbr5"
?;m] 5f
}X+-d"
'Hk82,
4Lc0Tu1
!uTB|[t
c3G]8@K
k|vuo1
KI>{2|l
bL(_(U
%r\N{evz
]{[)QJ
SC&74y
3yi_'S&@Nb<
E:#0#'?
-sz+SPz
79)(n
MU:l "
#kkkep
#N2XX'G
lY;O0l
dq;^P5^
Y1_=mI
t%-J*1
1}2+z<[1
2eIp^f
2VnQi+
,O\6Lm
(`v+Lq
Ewghy@XX
*]JE5+(
SR7yC{&M
*zIb5c
W}\pKF,
w K&[5/G
(nJ"\!
ck~#HC@
[6,\9p`
EB9j=^
F<wyBM2
!k; ^5
yG<wi|
snwy*Y
'8v'n9
Rv-~?:
6m9?"F
g:3ggY
)gO~rV
4-P19+
1Ff$J[aF
L0r@{c{
br>\'-
m9Sn)P
;icVUX
N^*qH]CZ
;Yblf<
,w"I+e
X)zMa!o
9QdRq(
N9{}nP
nm},u>
rl19_o
|{#a"e
HC^p][
dj@m^z
!Ni:=0{
tZF3%SF
i"1=#\
7@u1:O,?ot
ACXfdk
/Gn\D6
QR)&`k
;16dzh[
\.{A/b
(uYxQ"
Qj[GhD
]V=T7q2#
Lqu=I[]
jkXjrf
*u~VVV
(null)
`h````
xpxxxx
CorExitProcess
runtime error
TLOSS error
SING error
DOMAIN error
An application has made an attempt to load the C runtime library incorrectly.
Please contact the application's support team for more information.
- Attempt to use MSIL code from this assembly during native code initialization
This indicates a bug in your application. It is most likely the result of calling an MSIL-compiled (/clr) function from a native constructor or from DllMain.
- not enough space for locale information
- Attempt to initialize the CRT more than once.
This indicates a bug in your application.
- CRT not initialized
- unable to initialize heap
- not enough space for lowio initialization
- not enough space for stdio initialization
- pure virtual function call
- not enough space for _onexit/atexit table
- unable to open console device
- unexpected heap error
- unexpected multithread lock error
- not enough space for thread data
This application has requested the Runtime to terminate it in an unusual way.
Please contact the application's support team for more information.
- not enough space for environment
- not enough space for arguments
- floating point support not loaded
Microsoft Visual C++ Runtime Library
<program name unknown>
Runtime Error!
Program:
EncodePointer
DecodePointer
FlsFree
FlsSetValue
FlsGetValue
FlsAlloc
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
`h`hhh
xppwpp
GetProcessWindowStation
GetUserObjectInformationA
GetLastActivePopup
GetActiveWindow
MessageBoxA
USER32.DLL
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
HH:mm:ss
dddd, MMMM dd, yyyy
MM/dd/yy
December
November
October
September
August
February
January
Saturday
Friday
Thursday
Wednesday
Tuesday
Monday
Sunday
CONOUT$
SunMonTueWedThuFriSat
JanFebMarAprMayJunJulAugSepOctNovDec
bad allocation
vobarigawekowoxilinifur
ximawazudikahefafopoporifozib kadamuzayecep hizujajugejusawaharidam wunoguzazapeguvecazageganuzi
emuritowuwep
msimg32.dll
GetFullPathNameA
UnregisterWait
GlobalDeleteAtom
TryEnterCriticalSection
DebugActiveProcessStop
GetLogicalDriveStringsW
GetComputerNameW
GetModuleHandleW
GetTickCount
GetCommandLineA
GetSystemTimes
FormatMessageW
DeleteVolumeMountPointW
HeapCreate
WriteConsoleW
GetAtomNameW
GetTimeZoneInformation
VirtualUnlock
GetShortPathNameA
InterlockedExchange
GetProcAddress
GetNumaHighestNodeNumber
LoadLibraryA
OpenWaitableTimerW
LocalAlloc
OpenJobObjectW
SetCommMask
FoldStringW
GetDefaultCommConfigA
EnumDateFormatsA
CreateWaitableTimerW
lstrcatW
FreeEnvironmentStringsW
SetCalendarInfoA
SetFileShortNameA
DebugBreak
KERNEL32.dll
CopyRect
SetActiveWindow
USER32.dll
GetLastError
HeapFree
GetStartupInfoW
TerminateProcess
GetCurrentProcess
UnhandledExceptionFilter
SetUnhandledExceptionFilter
IsDebuggerPresent
VirtualFree
DeleteCriticalSection
LeaveCriticalSection
EnterCriticalSection
HeapAlloc
VirtualAlloc
HeapReAlloc
ReadFile
ExitProcess
WriteFile
GetStdHandle
GetModuleFileNameA
GetModuleFileNameW
GetEnvironmentStringsW
GetCommandLineW
SetHandleCount
GetFileType
GetStartupInfoA
TlsGetValue
TlsAlloc
TlsSetValue
TlsFree
InterlockedIncrement
SetLastError
GetCurrentThreadId
InterlockedDecrement
QueryPerformanceCounter
GetCurrentProcessId
GetSystemTimeAsFileTime
SetFilePointer
WideCharToMultiByte
GetConsoleCP
GetConsoleMode
GetCPInfo
GetACP
GetOEMCP
IsValidCodePage
InitializeCriticalSectionAndSpinCount
RtlUnwind
MultiByteToWideChar
SetStdHandle
WriteConsoleA
GetConsoleOutputCP
LCMapStringA
LCMapStringW
GetStringTypeA
GetStringTypeW
GetLocaleInfoA
FlushFileBuffers
HeapSize
CreateFileA
CloseHandle
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
lR!3CEG
ooooooooooooooooooooooooooooo\uuuT
oooooooc
ccccWc
ooooooockcc
cWO\T
ooooooo
OYooooooo
oooooooc
oooooooO
\cTccc
oooooooo
oooooooo
oooooooo
Ockc#c
YGccoooooooo\Oc
OWTcoooooooo
uoooooooooWcc
oooooooooooooooooooo
ooooooooooooooooooooT
ooooooG
oooooooooo
oooooo
cToooooooooou
cKoooooo
ccoooooooooooccvoooo
oooooooooooY#c
ooooooooooooo
kc#Ohuc
ooooooooooooo
hYoooooooooooooooooooooooooooooooooooooooooooooooooooooo
|z}}{|
~z|{{{
|~}|}|
}|{}~~
|}{~}|}{
}}}}}}
~|}}~|
}{zz{|
{{z||{{
z~z~|~z
z}}|{|
{~||}}
G?}uDDd
{{}|{{}
{~}}~~
~z~{}~~
|{z~|||{
}|z~|}
}}}~~z|~
{~{z~~
~~~|~~
~~{|~~
}~z|~|z
{}}{~z~
J(null)
mscoree.dll
KERNEL32.DLL
((((( H
h(((( H
H
VS_VERSION_INFO
StringFileInfo
040501E2
FileVersions
5.21.24.16
ProductVercion
71.7.10.59
InternalName
LegalCopyrights
CompanyNames
Success
VarFileInfo
Translation
UDaha kahafaxe xojipubax niju pahoboh pofegoj canenidabe pobaxamesiw juwaku favuratexuBJetabejijoxixu cusatofetoca pudabuvu xasoda lusanorara weyige roku
Mebohog tedexiKYuzedofov faxucige pugevokis wofecolosavi vojoril zutukukegel yafulesigawis/Zerona racijecib xifosisatadefax fabakakaficume
1Bowab puribu rukesusey rareyopace sed zudoteg jox
Cokasacol hujihelar
3Bekuxowive recejonelasu mokil yorojogogicixo titore
Antivirus Signature
Bkav W32.AIDetectMalware
Lionic Trojan.Win32.Stop.13!c
tehtris Clean
ClamAV Win.Packed.Smokeloader-10033583-0
CMC Clean
CAT-QuickHeal Ransom.Stop.P5
Skyhigh BehavesLike.Win32.Lockbit.bc
ALYac Trojan.Ransom.Stop
Cylance Unsafe
Zillya Clean
Sangfor Trojan.Win32.Save.a
K7AntiVirus Trojan ( 005b8d0d1 )
Alibaba Trojan:Win32/Redirector.542b5e93
K7GW Trojan ( 005b8d0d1 )
Cybereason Clean
huorong Trojan/Agent.bkv
Baidu Clean
VirIT Clean
Paloalto generic.ml
Symantec ML.Attribute.HighConfidence
Elastic malicious (high confidence)
ESET-NOD32 a variant of Win32/Kryptik.HXQM
APEX Malicious
Avast Win32:PWSX-gen [Trj]
Cynet Malicious (score: 100)
Kaspersky HEUR:Trojan-Ransom.Win32.Stop.gen
BitDefender Trojan.GenericKD.73785192
NANO-Antivirus Trojan.Win32.InstaBot.kqpqfm
ViRobot Trojan.Win.Z.Smokeloader_10033583_0.746496
MicroWorld-eScan Trojan.GenericKD.73785192
Tencent Malware.Win32.Gencirc.10c02b5f
TACHYON Clean
Sophos Mal/Generic-S
F-Secure Trojan.TR/AD.InstaBot.oftur
DrWeb Trojan.Siggen29.13882
VIPRE Trojan.GenericKD.73785192
TrendMicro Trojan.Win32.PRIVATELOADER.YXEHDZ
McAfeeD Real Protect-LS!D7528CD33B73
Trapmine malicious.high.ml.score
FireEye Generic.mg.d7528cd33b73718b
Emsisoft Trojan.GenericKD.73785192 (B)
Ikarus Trojan.Win32.Crypt
GData Trojan.GenericKD.73785192
Jiangmin Clean
Webroot Clean
Varist W32/Kryptik.MNU.gen!Eldorado
Avira TR/AD.InstaBot.oftur
Antiy-AVL Trojan/Win32.Sabsik
Kingsoft malware.kb.a.1000
Gridinsoft Ransom.Win32.Sabsik.sa
Xcitium Clean
Arcabit Clean
SUPERAntiSpyware Clean
ZoneAlarm HEUR:Trojan-Ransom.Win32.Stop.gen
Microsoft Trojan:HTML/Redirector.PAN!MTB
Google Detected
AhnLab-V3 Trojan/Win.Generic.R658943
Acronis Clean
McAfee Artemis!D7528CD33B73
MAX malware (ai score=87)
VBA32 BScope.Backdoor.Mokes
Malwarebytes Trojan.MalPack.GS
Panda Trj/Chgt.AD
Zoner Clean
TrendMicro-HouseCall Trojan.Win32.PRIVATELOADER.YXEHDZ
Rising Backdoor.Mokes!8.619 (TFE:5:zRLPcqYcSgN)
Yandex Clean
SentinelOne Static AI - Malicious PE
MaxSecure Trojan.Malware.300983.susgen
Fortinet W32/Kryptik.HXQM!tr
BitDefenderTheta Gen:NN.ZexaF.36810.Tq0@aiuO96kG
AVG Win32:PWSX-gen [Trj]
DeepInstinct MALICIOUS
CrowdStrike win/malicious_confidence_100% (W)
alibabacloud Trojan:Win/GenKryptik.HM!H
No IRMA results available.