Static | ZeroBOX

PE Compile Time

2019-09-13 20:54:28

PDB Path

C:\jakifayovinavoha-megudabesetolixug-zijare52-bidabufu4.pdbsol.pdb

PE Imphash

01992796d8a3fe630703874f98e2677e

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x000a9214 0x000a9400 7.95404308343
.rdata 0x000ab000 0x0000689d 0x00006a00 5.69269200493
.data 0x000b2000 0x02773028 0x00002200 3.37696239393
.jarop 0x02826000 0x00001200 0x00000400 0.0
.dasavol 0x02828000 0x0000004a 0x00000200 0.0
.rsrc 0x02829000 0x00005a08 0x00005c00 4.62808143116

Resources

Name Offset Size Language Sub-language File type
VOWAGOTAX 0x0282b160 0x000005c6 None SUBLANG_DEFAULT ASCII text, with very long lines, with no line terminators
YOSIBALIBINIBUREWEHO 0x0282ad88 0x000003d8 None SUBLANG_DEFAULT ASCII text, with very long lines, with no line terminators
RT_CURSOR 0x0282d968 0x000008a8 None SUBLANG_DEFAULT dBase III DBT, version number 0, next free block index 40, 1st item "\251\317"
RT_CURSOR 0x0282d968 0x000008a8 None SUBLANG_DEFAULT dBase III DBT, version number 0, next free block index 40, 1st item "\251\317"
RT_CURSOR 0x0282d968 0x000008a8 None SUBLANG_DEFAULT dBase III DBT, version number 0, next free block index 40, 1st item "\251\317"
RT_CURSOR 0x0282d968 0x000008a8 None SUBLANG_DEFAULT dBase III DBT, version number 0, next free block index 40, 1st item "\251\317"
RT_CURSOR 0x0282d968 0x000008a8 None SUBLANG_DEFAULT dBase III DBT, version number 0, next free block index 40, 1st item "\251\317"
RT_ICON 0x02829cb8 0x000010a8 None SUBLANG_DEFAULT dBase III DBT, version number 0, next free block index 40
RT_ICON 0x02829cb8 0x000010a8 None SUBLANG_DEFAULT dBase III DBT, version number 0, next free block index 40
RT_STRING 0x0282e650 0x000003b8 None SUBLANG_DEFAULT data
RT_STRING 0x0282e650 0x000003b8 None SUBLANG_DEFAULT data
RT_STRING 0x0282e650 0x000003b8 None SUBLANG_DEFAULT data
RT_ACCELERATOR 0x0282b728 0x000000a0 None SUBLANG_DEFAULT data
RT_GROUP_CURSOR 0x0282e210 0x00000022 None SUBLANG_DEFAULT data
RT_GROUP_CURSOR 0x0282e210 0x00000022 None SUBLANG_DEFAULT data
RT_GROUP_ICON 0x0282ad60 0x00000022 None SUBLANG_DEFAULT data

Imports

Library KERNEL32.dll:
0x4ab008 CreateMutexW
0x4ab00c lstrlenA
0x4ab010 _llseek
0x4ab014 SetEndOfFile
0x4ab01c WriteTapemark
0x4ab020 CreateJobObjectW
0x4ab028 WaitForSingleObject
0x4ab02c SetComputerNameW
0x4ab030 CallNamedPipeW
0x4ab034 WriteFile
0x4ab038 SetCommState
0x4ab040 GetDriveTypeA
0x4ab044 ActivateActCtx
0x4ab048 GlobalAlloc
0x4ab04c LoadLibraryW
0x4ab050 Sleep
0x4ab054 CopyFileW
0x4ab060 GetConsoleWindow
0x4ab070 TerminateProcess
0x4ab074 IsDBCSLeadByte
0x4ab078 GetBinaryTypeW
0x4ab07c GetOverlappedResult
0x4ab080 CompareStringW
0x4ab084 GetACP
0x4ab088 lstrlenW
0x4ab08c RaiseException
0x4ab090 DeactivateActCtx
0x4ab094 GetProcAddress
0x4ab098 GetTapeStatus
0x4ab0a0 LoadLibraryA
0x4ab0b0 SetConsoleOutputCP
0x4ab0bc AddAtomA
0x4ab0c0 GetTapeParameters
0x4ab0c8 EnumDateFormatsA
0x4ab0cc GetThreadPriority
0x4ab0d4 GetCommTimeouts
0x4ab0dc _lopen
0x4ab0e0 GetVersionExA
0x4ab0e4 LocalSize
0x4ab0e8 CopyFileExA
0x4ab0ec AreFileApisANSI
0x4ab0f0 lstrcpyA
0x4ab0f4 CloseHandle
0x4ab0f8 CreateFileA
0x4ab0fc WideCharToMultiByte
0x4ab10c InterlockedExchange
0x4ab110 MultiByteToWideChar
0x4ab120 GetLastError
0x4ab124 MoveFileA
0x4ab128 HeapFree
0x4ab12c HeapAlloc
0x4ab130 GetCurrentProcess
0x4ab13c IsDebuggerPresent
0x4ab140 GetModuleHandleW
0x4ab144 ExitProcess
0x4ab148 GetCommandLineA
0x4ab14c GetStartupInfoA
0x4ab150 GetCPInfo
0x4ab154 RtlUnwind
0x4ab158 LCMapStringW
0x4ab15c LCMapStringA
0x4ab160 GetStringTypeW
0x4ab164 HeapCreate
0x4ab168 VirtualFree
0x4ab16c VirtualAlloc
0x4ab170 HeapReAlloc
0x4ab174 GetStdHandle
0x4ab178 GetModuleFileNameA
0x4ab17c TlsGetValue
0x4ab180 TlsAlloc
0x4ab184 TlsSetValue
0x4ab188 TlsFree
0x4ab18c SetLastError
0x4ab190 GetCurrentThreadId
0x4ab194 GetOEMCP
0x4ab198 IsValidCodePage
0x4ab19c SetHandleCount
0x4ab1a0 GetFileType
0x4ab1bc GetTickCount
0x4ab1c0 GetCurrentProcessId
0x4ab1c8 GetStringTypeA
0x4ab1cc HeapSize
0x4ab1d0 GetUserDefaultLCID
0x4ab1d4 GetLocaleInfoA
0x4ab1d8 EnumSystemLocalesA
0x4ab1dc IsValidLocale
0x4ab1e0 SetFilePointer
0x4ab1e4 GetConsoleCP
0x4ab1e8 GetConsoleMode
0x4ab1ec GetModuleHandleA
0x4ab1f0 GetLocaleInfoW
0x4ab1f4 SetStdHandle
0x4ab1f8 WriteConsoleA
0x4ab1fc GetConsoleOutputCP
0x4ab200 WriteConsoleW
0x4ab204 FlushFileBuffers
Library WINHTTP.dll:
0x4ab20c WinHttpCloseHandle

Exports

Ordinal Address Name
1 0x4a8070 _futurama@4
2 0x4a8060 _hiduk@8
3 0x4a8040 _hockey@4
4 0x4a8050 _husaberg@4
5 0x4a8030 _hyppo@4
6 0x4a8080 _lifan@8
!This program cannot be run in DOS mode.
KRichQ
`.rdata
@.data
.jarop
.dasavolJ
^\9nTr
^@9n8r
C0)0)t$0
C4)0)t$,
9q<v9A<s
F09^(u
SVWj>3
0WWWWW
0WWWWW
QQSVWd
^SSSSS
^SSSSS
0SSSSS
t"SS9]
0SSSSS
tNIt?It0It
0A@@Ju
<+t(<-t$:
+t HHt
j@j ^V
>=Yt1j
HtHu4j
s[S;7|G;w
tR99u2
C PjPV
C$PjQV
C*PjTV
C+PjUV
C,PjVV
C-PjWV
C.PjRV
C/PjSV
0SSSSS
PPPPPPPP
0SSSSS
PPPPPPPP
t+WWVPV
tRHtCHt4Ht%HtFHHt
URPQQhX
_VVVVV
^WWWWW
u,VVWV
t VV9u
;t$,v-
UQPXY]Y[
0SSSSS
_VVVVV
e0s{B,|
r9dI?h
e0s{B,|
@Ye0s{B,|
H%[E=T
7`h0$o
B;/?N*7
q2Q?d5
[Tzkh%i
$qVd7!
(#fTLQ
c:*wt+
B}NP.#
SDF>rH
4J3+{c
\Vi#X0
Mp4MKC
VO"Npq
]}Wo0@
G!d!2W
$^(@m{>
p)Z'/8g
$f8z#)
?*#?zy
_{fC` n
9**jp?
EEUDv&wDk
>H.|[
Q$nGlB
w`N;$b
BeX9L8
K&}0fF:
aNbN${_[~
=BeA:<9ByX]
K\}t(p`
2t"Lwz
bGZ}e3
:aGXp]
Xx%b+k
U+w9bR
>'GLIiD
?Wuh3aI:
91i{>F
;EQD{]
H2`g,
|tE _3
y{Oq"*
u`L`,gkW
}yJ"gh
s':]fh
_*GRG~L
H^yZ]O
UXgAx%
5iCYz:Mqp
tmvf+`
;:y+p_
mSUzoIP
Bm388:
)B?j?~I
{?pQp@
RBDh]mM
tz-! !
C>nXwTA
v+YV~T
7ujNMjV
6O&A8i
M=`mYs7|C$
OA`9+q*
jJB3{+
q)eeFG
ipp;Tv
(oMDB^
{Dh`mJo
YX?>c
\TwUBo(
*5@za<*
%9Ci{0;
h*630d
Uq}YY
ie]B\F
dGS-4w
yH`'6\>
|O)t8m
?)<W}C
fH[5F?4
c8xr6x
0c%7;8
AH!B7L
#z7;z7,
u<}TazHs
4`e}Im9j
c,AqW;p+
1s#Emx
ss.&D @
T h<v~8t
&[\s2v
RbiI;~0
vC|`Tw
c_P!1D
8|S.8?ZjO)
sj[PHo
lZTg/@.
n.5.@g
GdTrqNa
~m{]:fk
SJP~N>
od>u^~
5]C<l]8
#Szxt^
i+`OJ0
Lm>J5{
y=C6FA
3f{(e}E
B,jO^)
~{ZZ~[Ytj
L08X6/
agccC7
PF#e&J
c^a#~a
X]nU]]
DB@3\c
S-Q9$@^\
sKq^iY
0Hwa]d
py#rw38
b~I}(Q;!
'!"OHT
>@C;*ir
=[e8ji}
iMxYzU
?{xSCev
M6i2U)
tHMbc@
#,sfM
eJ}b3$*
CaeL5J
A-EhL*
XM/i-*xR(}
cU)S`"
[+1/+$
7W~sdAC
egV[O-O
Mm~_pa
m0ee.u
dQ`'RC
{]_~BV
WQ_HN4
?mzfD/
mR)"aV
=HKIKG
7hs{Bu
Vq@*?m{
,(vBnY
Oa'{eB
U0khmf
YlgATc
b/=vmd_N
'^lT^b:
8-Q,-R_
jxAprk
,Uu{Go
f[<{sye
0rVxj0j
4`-3bU
KWRS2H
]-AasU?s
9u3(RJ
gk9QS\
YoA%um
y_pFaQ=F
86\c7-
G.L2D{
V-oL17
A7:\>O
y.<<Gvi
qVE:HW
.B0jz3M
'^xg-d
b%bA0R
]t:dYe6q
gIiwb+:t|
W$Ho>w
"4"9TJ
>pD%7P
27`YM;FwCK[7
L^BP3d
*JZ+8j
4UNqbs
xZ'sZ4
f TV?r
@*k5UJ
"ZrHUB8v
]=zPa#|XL
p5:j|_
en1-mT
/$*vA{^
=BSJ*6
c,18jNdC
_bI<$I
y1W&[G!7
KD&?jr
fh]8DFX
A&$J~XF[6"
![Ykag
_o[BP}
r>&yo\
bwipf5
3U?fJ'
3=@Aai
gu[t=r
sI"qzim
X|@JU
G~7+1
zwhQ\cf
{Ax-(0#
;OaS\-
b]9}bU
>9JO\9
(Y<N]D
bv};LTC
gqQuo)
v>?<e{
h60,PF
g@pW:7
[#O\sC
=0nN,<2
&<t>)+
n5N&^6
p00.N>]
Z'UV P
("~D`A
|sp37?
S?+9c_
L06rq>
!!FWwy
eaNG"]o
|K>~i2
MgoFn'w
pT8kW%
zqUD|-
w!M_F@
cGDZX6gw
}dK{HT
.}C9yW'
|O:zmi
=7WmG%b=
eUiW,F
!Z3&`1c
Z1H)*9
EW,ZZ_q
+~#1Cd
8?[=N^
qW$b`@G
=,*#~7
0/[SMP
uh,CcF&
JWe*1%yT+
;hpt`s
TP';w@
A}\+co
L0GE`X
*1#(D#
]POd<Z
$SV17.
-b:_h+u
c0qC%l
nV-l-U~
Sdm<H#
!`PzZa
WAk4GW
f{"w[xT
%lOo@?
&/=S()
bo6<+
O}"}H9
J=s#a_
-=;r1`
M(y\hCI}
aCC0Wg
\EN.[I
8In:%i
Azn?_=
Y$G#K*
\VMd":
2Qm}GK/w
-rr*"[
xkgt0m
g"xwEL
;TB&Gn
>QK|>i
4{lRZw
&~{S{FC0
6C_k$oJ
1ZG>0%H
#&QaLif
^P5=hb
i;ZVhj
J&T7J_
Fe0mhx
s|XW6H
dyK_#g
,%/f>[
%{=R|Rz
-N%0_P
_7_5r/%
kn79`W
Q-xGA/
2oQ\I
*lI)wb
Dvg cN
pwJvO6
n(su+n
cf7azBu
;\`([G
cB1_}u
VSb`5m
5<V@qO
8 jzoL
S[_oKUF6
H*ZCdIQj
98h0BI
} 9<6I
X8ALDU
0Y:,%qj[
tj-?Sm
+X7/6~
55Py\!P
299#=LC
4%tV8|
?9{`Vxb
JhKV&:O
b><&v)
vhOlXYH
:nYEKy
PI!55h0dYO
BGKJT
0crb%wm
|!k$LR
VC>(9x
W{YuJl
lgM]9!}
K%Z1*8
fJl<k;
nn'Pet
[88I9L
2qEq:y
XYZ/4&
Pe}>&]
%2[v`!
$w=M!tk
aiC@Il
"frBn`
s,EoM3
<i <dfSt
w0m7nS
e.%o:p
L^Em3v
b;&8t?
gbQ@>I(
D^I/&l
y'rJ&"
x@vqe/
`|ZJ0G'
Pjul`p
W;m}P*
v9*<m;
_IN3.E'
!?ABWP
2&=+ca%
To~/"1
./[[3x
NVQ$/l
7]^5S$&
>j^I;U
uP0Spn
qbLYlx
<_:Ne'
3UL]ew
vjI!17
1otn"?,
N"n;/9
?2PV[N
O5C$]K
F)V9=w
1d`4A}
KwZOEN
]=,ck2u
]Of3`Bb
a*q%v$
+`jZ0Q
Z8XptSb
e<Og#=58[K
\_U_+e
VK-:RA
coX RS[
1N|G{8
k!BtL9@
3 }qI@|
de{}Ul
^"]C;d
ue\B|\
4Q?wD @
08`a]g
W6{ID1t
otBLrS?
as-,c6
M^6_PS
uUB"5FX
=3(R.0
;W}f!pm
fK`nBn
QM:3']0
|S,QQ2
W`ptIK
%@e:V
@6-dtV
8KgCAn
?e6zX#
b@K[`s.;
"mt6e00
5G"SL}-}
^Qv<%4w
ZI6G[h
]U^_w_
.2 X2LU
P}Lh(,f
Q ?!PF
| &v{t
rGyT.q:
;P;]4l
"1M~+J
qy"_+W
Or8-oo
=7uzO-
DjFL4
8_Q=FQ
dz I.k3X
"e"m&y
_cI)3Q
.jsd7=
N<MNUKDu.
V78,#6
>HU7hK
A)hf&pg
]kE0m<
JPZ&iL
>#Y/l
&tKHXw
+vNhRp[1
J28n"@;
9v`\^8
nT,iJO~
T/nM&^&
>v_snK]
vlyX!+s
Qq-r8z
K\)cz1
fyn*52
(F[-z0h
<YD[7w^
T\PBW
/gi{km
IiPcA)/
MkIg$<5U
[{ek./:`
~pLmNUW
P5%Y1#
G\2QV6
kX#2#~
($2R[x
F-qy*;XkBRS
1G`|D,
BDDvym
TX1hOb{N
J~rQA]
Aj9NUR
%HB+Uz
_TN}%uT
FeI#cL
?M!yL
^Bde@k
5fNf]"
<tr}K[q
CMn^~_
IylXth
ye=]+E
'u[:Yf
-yy9Snc
]_-FS1
?{rSw*u2{K<V
b(v>E@
8+Ib@%
pl'$*T
6ZSy()X
}fU5ic
D\)m"D!G
+iumLT
it=9xr5
vkurBB
Xae""
Po^GCc
:9!uhT
YBfVTA
QEm/>P0'
? DA}Yqx6
@4WW5+x
=sA~rF
_@_U2A
Gz)W6K
s%Umd^
+ey6l!gK
IxKVl&$a
,Dys{
S;|<>P
J}f].YU4
yVTm<p
jh[5:MC
;i1?9\
p\e!uG
6O`'ZGm
IMnje1
W^\uS{v
G4UNWv
_3^pis
hHF`#>
OF\d:5a
V_9Db{
[9R{o>
bJ9NUV
ELbKW}/
AA_C^M
f*bo!9
f@(A'M
P(nPRb4
XfGhR
d\o*ueg
Yywq_t
B;Yu5/*
nY\GZh$
%Y1WdmE
?5@/K9
8jW*Eb
O\7BrhIM@
{O?o/~
%b>7AAp,
;k+[]k
i]ZTdV
"))L8:t
5DYprhH*
3}zQ)w
By9!Hp
Yewt1)
0wm@ BE
W81>a9n)ue
PrE"5Kn
3.t68
:o[Hh#[S
NYc||N
[*~>|2
OTO2@F
1SHM+#
=lT%\`:'{qy
0T3_j9
64_q<l
a(,P(g
QMU-ZE
pg =>Wu
~?tDzU
:#DcC\
c-_q-m
M%U_&K
b\tMjD
9{G>FA
DfLv^I@2
rH3-11
_WIVzw?
sJo9Q7
aYy:{@
?I]6D:
/)<~e
w ^7vB
xo!my@`
Rct'+J
Im{\&A
0&uMp0L
7NiSeEf
3\PA>q1h
V0LaXf
11Ef.+-~lkY
iSqyHj
-$XF37
0QB%|>
%|Zvq[s
w>?3lC
T{^Z!?
\=2rIG
rrqw#UY<q:X
t@>Uu}
n-(9?]
4eO)w C
GNF~;L
#lbX1{
oS*\*>
k1!7KrFG
(,Y'G;Nr
yckR{`#
yKMJF4Z
U\y{7I?
#XZL4~)
igoo"k
Qz%{da
;$1T]Y
&]<\r,]
g`]AD;
%$~~$h@
h-<qPX
Si|fqd!
~25M V
Xvr3g>
H&"sv+#,
4u]pn>
zvB*&x@
vQd+,Al
<v7I-Q
(#m2Z_
Bg6yR^
N26AU5
20)2i%
?2}B':f
cZ Uco
]S=(p
1;#@2n
urv-wj
~Gjua
+J<sg~
^7-<^;'
,9Tw14
wZ_LY?
60yJ/oD
$m?Zs!
RpDb*HS
MDW$\s
:nZ+|'v
=$hTaKBO
dc}K_A
4\_yfa<
bQ4iu#
^MK&%b
\;3L&Q
3>/s\|=r
Ix'R^4
w^W#C?
=B4bE1l,
b:4yL/
+`Oo!7
0Ya|<A
:Nr'~Mc
/!_1t-
$oiC.%
cIpy2+
qnp9TI
t[P=K
Z=?tY'
LVE%I
pBpVrQ
=o,c0D
@[P:6c
2i)jwm9r
v!7G]u
7Yv f@|
nlBg(3
e,ri[k4
hNNgs8F
MR9?u
$@Q`~Z
,dxucn
54PW*_
Z-ZGKJ
c#9e}/
nG3OH
$.{q,<
'j&(|n
bR{/3_
;S:RWk
V9wrJR
ztq#S1
W]TSnh
dm^*5F
.CUNO"
>8xl?J
Ypl.!~
f-)6M0+
@ec0qx
+=F"n:
_83f/G
:yqpo,
Q\WmT%
/h.=g`
0\fZ%QZ
z6\3+g
nd~0'o)L=
vKm,W~P
yYZa-@a
EI{w8_M
n(9,1R.
'C)OMz
/JS=/p
|*{kc`!l
,?yKho,
/`RY}
>J~Zp@o
2SK'>":
Dqg;L
o"s,wv
_;+XNLV
Q5=2w4\
#e\Rh?
igdeF[v
V! Ff~+!
pFp1@W
~gRVF!v%A
g&B!]a
\t;W7N:X
>k{%t^
9p8V2y
xZCuoK
c.>M"=
5zuu0]
Lum"3#
]"Sb{
Tw!!N/CV
wr]L%L
,lF`^)
e)X^xz
jJml8D
\o|s)0U
$vo1.\
jQX4^Y
+@3E_
e*jxrV
OPmoT_
q-m7a9
`|DH_L
Io?m=Z
M{H}+ke
$D2G/Zi
hb[W'I
%k|rS\
,(X+>'
{$]*?t
S }VjokW@
y/c99T
I4iA_d
_!_Cla"%
;1ksVj|$
@6+wrlc
U.LkKR
t?=i\w
c^`?w{
joAJhH
M3)b$u
o[u.tX
22(/m!q
5wL|ak
a&rn2>V4o
>aFw't
V6C}Hu@-_
FuQqoL
.53&yG
3o,>lKB~X
KuH2cC
Nn2k5d
.n s3bR
Q95'^9;
1R;[0[n
((}Ri$
kyWzX/*
['L123
r5CgN~_
<Ksz.W&
I]^Kb
\&Hn,c
_,!:IN
"!t\UQL
m\^XVK
Jk1+JF
2|O?HJ
QWqNmZ
rQ'3pG
]{ 'F
KZ%Y|D
5t~U8v
+Up"dmL7
t{RQyg
'fBI^H
*Jq0y
*:0FWn
(>YuzP
"NwY mQ
.^T:+Y
z`spVQ
vT@Oa"
c0&c\
u9DOtE
@WlM7
q#L\x;
`9AGVT
7tgBX=
[XIudtZ}
x,:J@H
wtyh?j
_\BBr0
JPBA8
qVlkiT
X !V08P
j2/nSZ
52+WBBd
N*-QvAv
G&MqB7
8\~7A8.#i
<8pA~zY?U
O&\acr
AB;u`(u
Lu7rEa,a
'xKuVFH
?F0"l%
seP9t$ig
ki=+2b
9jI!>W
Y=Gx3t
&7,2L/~
0RdiiIj
ym=s%-
aJGYKr
UAtjCj2K
XRbajz
>5Yu}
9z3,7ix
p6c!q,
Sh=:6~
I^bk=B
'bj<.
T/4kgbp
RA0 O<
9dlXz\
>~6[>A
(n(&#1
VtJF-D
+_gz`U
fCrU,1
Y)FdjZ
g7RBN}m
YRIIABk
6l)EF>
7jEwyf
O743?h
5Tb,kW
Z@.t"S
s&r_ z
#C);PU
ZhsU6!
srM*6lmV
FmN*(NU
"NGMsQ
U(%KV$&
q6~51
'.I?>G
]3Sz9C"
:<9}0I
I l8!s
X}q#V,
A~($C!!
=n#<6n
UB0,@9
+?(in
>:@dn4
:*X Jl'
+5Gjw[
;8l'Pn
|>jhzBf
W+kZt
#IT82Z
o'c)enc
<hFm|,
Of3Yh?-
S*JlGm
Y7F@IC
<COVT^YB`
(zE;m/e
:l271b]
w#(K 38
h%lr=R
D_\E_r<
9}8XLg
.<M+Nw
O+8c5p
`Uzy\1
#6"$YL
aA32lZ
n1jr?-T
A5DDg
"8cyVB[
m]?S`5
6%.M|r,
,2-fy?,
uG%p5E,
`gh25I
_hVp20
XKUECd
X4*|s.
ALahOV
^uNJJ"
Y.Ov6L
Wu\jIX
kL=w*l
CrX%Hho
3XO&yX?;
LTaTQ{
;\mY~ v
8+L'FS
Df#3[LR5
\e`e c
}r"[FK
AwwFoh
56kO-H
OPIi22B
0_'mhO
fXxFU{k
>8oQ,?5(8&\
=zoMqwj
jceQ*-
`ln"t<
vhFAkzZ
o75N=^
;W;;w<
PzHYuy
!O.77bs
:G_Y' p
op`.)x
R@h7LP
/Y+('>
4j={fe;U
+lOVggY
UC)fb1
SmsN(e
o'#3n\
$rOK$S
@.K;2
zYK?Zbwp
Jc8g_8X
g_q$IV
p\gbC&p
@y~p0<N
Q'G:M$
F,xp~d
pb4s:!
EGe"agp
-p]`W<I
#F*k!rRw
P#QT^
8;\Z}-
y2T93IT
=7WbQ#
hOfne\CF
+usOlG
i=tjIQ
9at(>N
\OfVwQ
!,z`Qh
CJp.hIZ
3k"L55?
.L7@6#
6G*x:>
F?ag}WY
TfjG9d
&/F]>W?
{r3n]hE'CR
yj^}O
z}g(u
O3oFv%.
)..PYY
c|EQ'i
s10s{=9_
Y+Z;MhPO
&{mLd9~
80XPou<
AXS2M|
^u\/4%7
,!,NUW
?|dtc(
t~(3ij
h7./%j3
9~7h[902
e<}kcU
V`Ewr>
eh9+/O-Z
V#:|F}T
k(31{R
|FW-o*
V{~#/I
";trh"
Dz3}QD
.F28$
1PR&P6
f9J7q<
/BD+^Y
%\Zn4`
er;,oVk
haqUB
rvLD"[~
b^bvm
~,k `&1H
*/(A(
v2^*c
09Dd^#
E5L@6b
pMA3ne
;n.`0{
7,?9P,PzO
C+Mrbt
~0pr0%
z+IWz0
k!yl08
~^h^CgZz6
;%*K^-
f#z@c
.^*W3|"
]88!ti-
z{]QFe'!
LDp"O\
L7D5`A
qc'a9G
HDjjYA
x(yk]sj
/espAjg
XwW]wd
6n>9*+o'0
>ML32M
-7T] "_
egj-3=
x^7)2\
l!Bt*0
;FX(G6
8e8`L'/
!8'e2+
uFWWWW
D$pP3@C
l$8 B05
l$TX[kC
bad allocation
string too long
invalid string position
Unknown exception
CorExitProcess
LC_TIME
LC_NUMERIC
LC_MONETARY
LC_CTYPE
LC_COLLATE
LC_ALL
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
(null)
`h````
xpxxxx
runtime error
TLOSS error
SING error
DOMAIN error
An application has made an attempt to load the C runtime library incorrectly.
Please contact the application's support team for more information.
- Attempt to use MSIL code from this assembly during native code initialization
This indicates a bug in your application. It is most likely the result of calling an MSIL-compiled (/clr) function from a native constructor or from DllMain.
- not enough space for locale information
- Attempt to initialize the CRT more than once.
This indicates a bug in your application.
- CRT not initialized
- unable to initialize heap
- not enough space for lowio initialization
- not enough space for stdio initialization
- pure virtual function call
- not enough space for _onexit/atexit table
- unable to open console device
- unexpected heap error
- unexpected multithread lock error
- not enough space for thread data
This application has requested the Runtime to terminate it in an unusual way.
Please contact the application's support team for more information.
- not enough space for environment
- not enough space for arguments
- floating point support not loaded
Microsoft Visual C++ Runtime Library
<program name unknown>
Runtime Error!
Program:
EncodePointer
DecodePointer
FlsFree
FlsSetValue
FlsGetValue
FlsAlloc
RUUUUU
<8bunz8
l,kg<i
<@En[vP
bad exception
HH:mm:ss
dddd, MMMM dd, yyyy
MM/dd/yy
December
November
October
September
August
February
January
Saturday
Friday
Thursday
Wednesday
Tuesday
Monday
Sunday
united-states
united-kingdom
trinidad & tobago
south-korea
south-africa
south korea
south africa
slovak
puerto-rico
pr-china
pr china
new-zealand
hong-kong
holland
great britain
england
britain
america
swedish-finland
spanish-venezuela
spanish-uruguay
spanish-puerto rico
spanish-peru
spanish-paraguay
spanish-panama
spanish-nicaragua
spanish-modern
spanish-mexican
spanish-honduras
spanish-guatemala
spanish-el salvador
spanish-ecuador
spanish-dominican republic
spanish-costa rica
spanish-colombia
spanish-chile
spanish-bolivia
spanish-argentina
portuguese-brazilian
norwegian-nynorsk
norwegian-bokmal
norwegian
italian-swiss
irish-english
german-swiss
german-luxembourg
german-lichtenstein
german-austrian
french-swiss
french-luxembourg
french-canadian
french-belgian
english-usa
english-us
english-uk
english-trinidad y tobago
english-south africa
english-nz
english-jamaica
english-ire
english-caribbean
english-can
english-belize
english-aus
english-american
dutch-belgian
chinese-traditional
chinese-singapore
chinese-simplified
chinese-hongkong
chinese
canadian
belgian
australian
american-english
american english
american
Norwegian-Nynorsk
`h`hhh
xppwpp
GetProcessWindowStation
GetUserObjectInformationA
GetLastActivePopup
GetActiveWindow
MessageBoxA
USER32.DLL
_nextafter
_hypot
i^^?(>
Y:/(A6>
<e+000
GAIsProcessorFeaturePresent
KERNEL32
? Complete Object Locator'
Class Hierarchy Descriptor'
Base Class Array'
Base Class Descriptor at (
Type Descriptor'
`local static thread guard'
`managed vector copy constructor iterator'
`vector vbase copy constructor iterator'
`vector copy constructor iterator'
`dynamic atexit destructor for '
`dynamic initializer for '
`eh vector vbase copy constructor iterator'
`eh vector copy constructor iterator'
`managed vector destructor iterator'
`managed vector constructor iterator'
`placement delete[] closure'
`placement delete closure'
`omni callsig'
delete[]
new[]
`local vftable constructor closure'
`local vftable'
`udt returning'
`copy constructor closure'
`eh vector vbase constructor iterator'
`eh vector destructor iterator'
`eh vector constructor iterator'
`virtual displacement map'
`vector vbase constructor iterator'
`vector destructor iterator'
`vector constructor iterator'
`scalar deleting destructor'
`default constructor closure'
`vector deleting destructor'
`vbase destructor'
`string'
`local static guard'
`typeof'
`vcall'
`vbtable'
`vftable'
operator
delete
__unaligned
__restrict
__ptr64
__clrcall
__fastcall
__thiscall
__stdcall
__pascal
__cdecl
__based(
SunMonTueWedThuFriSat
JanFebMarAprMayJunJulAugSepOctNovDec
CONOUT$
1#QNAN
1#SNAN
bad allocation
VirtualBritect
zizobeladaguzewolacowaduyeruma
ios_base::badbit set
ios_base::failbit set
ios_base::eofbit set
bad cast
C:\jakifayovinavoha-megudabesetolixug-zijare52-bidabufu4.pdb
sol.pdb
DosDateTimeToFileTime
SetDefaultCommConfigA
CreateMutexW
lstrlenA
_llseek
SetEndOfFile
BuildCommDCBAndTimeoutsA
WriteTapemark
CreateJobObjectW
GetNamedPipeHandleStateA
WaitForSingleObject
SetComputerNameW
CallNamedPipeW
WriteFile
SetCommState
SetProcessPriorityBoost
GetDriveTypeA
ActivateActCtx
GlobalAlloc
LoadLibraryW
CopyFileW
GetPrivateProfileStructW
GetSystemPowerStatus
GetConsoleWindow
GetSystemTimeAdjustment
DeleteVolumeMountPointW
LeaveCriticalSection
TerminateProcess
IsDBCSLeadByte
GetBinaryTypeW
GetOverlappedResult
CompareStringW
GetACP
lstrlenW
RaiseException
DeactivateActCtx
GetProcAddress
GetTapeStatus
BeginUpdateResourceW
LoadLibraryA
BuildCommDCBAndTimeoutsW
IsSystemResumeAutomatic
SetConsoleDisplayMode
SetConsoleOutputCP
SetCurrentDirectoryW
PostQueuedCompletionStatus
AddAtomA
GetTapeParameters
SetEnvironmentVariableA
EnumDateFormatsA
GetThreadPriority
CreateIoCompletionPort
GetCommTimeouts
GetCurrentDirectoryA
_lopen
GetVersionExA
LocalSize
CopyFileExA
AreFileApisANSI
lstrcpyA
KERNEL32.dll
WinHttpCloseHandle
WINHTTP.dll
WideCharToMultiByte
InterlockedIncrement
InterlockedDecrement
InterlockedCompareExchange
InterlockedExchange
MultiByteToWideChar
InitializeCriticalSection
DeleteCriticalSection
EnterCriticalSection
GetLastError
MoveFileA
HeapFree
HeapAlloc
GetCurrentProcess
UnhandledExceptionFilter
SetUnhandledExceptionFilter
IsDebuggerPresent
GetModuleHandleW
ExitProcess
GetCommandLineA
GetStartupInfoA
GetCPInfo
RtlUnwind
LCMapStringW
LCMapStringA
GetStringTypeW
HeapCreate
VirtualFree
VirtualAlloc
HeapReAlloc
GetStdHandle
GetModuleFileNameA
TlsGetValue
TlsAlloc
TlsSetValue
TlsFree
SetLastError
GetCurrentThreadId
GetOEMCP
IsValidCodePage
SetHandleCount
GetFileType
InitializeCriticalSectionAndSpinCount
FreeEnvironmentStringsA
GetEnvironmentStrings
FreeEnvironmentStringsW
GetEnvironmentStringsW
QueryPerformanceCounter
GetTickCount
GetCurrentProcessId
GetSystemTimeAsFileTime
GetStringTypeA
HeapSize
GetUserDefaultLCID
GetLocaleInfoA
EnumSystemLocalesA
IsValidLocale
SetFilePointer
GetConsoleCP
GetConsoleMode
GetModuleHandleA
GetLocaleInfoW
SetStdHandle
WriteConsoleA
GetConsoleOutputCP
WriteConsoleW
FlushFileBuffers
CreateFileA
CloseHandle
budosol.exe
_futurama@4
_hiduk@8
_hockey@4
_husaberg@4
_hyppo@4
_lifan@8
.?AV_Locimp@locale@std@@
.?AVout_of_range@std@@
Copyright (c) 1992-2004 by P.J. Plauger, licensed by Dinkumware, Ltd. ALL RIGHTS RESERVED.
.?AVtype_info@@
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
.?AVbad_exception@std@@
.?AV?$ctype@_W@std@@
.?AUctype_base@std@@
.?AVfacet@locale@std@@
.?AV?$basic_stringstream@_WU?$char_traits@_W@std@@V?$allocator@_W@2@@std@@
.?AV?$basic_stringbuf@_WU?$char_traits@_W@std@@V?$allocator@_W@2@@std@@
.?AV?$basic_iostream@_WU?$char_traits@_W@std@@@std@@
.?AV?$basic_ostream@_WU?$char_traits@_W@std@@@std@@
.?AV?$basic_istream@_WU?$char_traits@_W@std@@@std@@
.?AV?$basic_streambuf@_WU?$char_traits@_W@std@@@std@@
.?AV?$basic_ios@_WU?$char_traits@_W@std@@@std@@
.?AV?$_Iosb@H@std@@
.?AVios_base@std@@
.?AVruntime_error@std@@
.?AVexception@std@@
.?AVlogic_error@std@@
.?AVfailure@ios_base@std@@
.?AVlength_error@std@@
.?AVbad_cast@std@@
.?AVbad_alloc@std@@
99999zzzzzzzzzz.z...
kkee22hhh55wII
IIIIIIIIIIIIIIIIIIII
IIIIIIIIIIIIIIIIIIII
Vefozenoxe. Bevekatedok dajozimin yewiluxomox hozaje. Jazorufeseye. Riwivam. Ficemuhezepim. Rosukofobos mifug pupetaxaku punipoviyumo dirafejow. Suf yadanuxare doyeku zocucawahog yadacage. Beyoneyufiw. Kujupiwobifo puh curulelabodixed cozay feyiyofij. Yerudujasat heyewajafax zehexofexixeje vetakepavukol fugominu. Towiweno yaxuhotinigabo cejenahayadan. Fitokimozeyapu hosagujovuyide hikayejo kuvigi. Fubas varigeralay. Tafisam. Takelaz datiwetal hecebaxubu wotoliriwah. Xusijab sorul wixoce. Kameb gunonacovu regibekil. Naka kihasonoyeyono tehaxijobumumux digenacafovuti. Dop bokaloduzubi xihumexesahi jam. Japunu duy macijirubip. Vetokeduz batevuve cunal biwajururo loyokexenar. Rusesukopap sepakiko bahili. Jitareyidiyelug pazezevujuwi jenoke jazesah lulagaxawit. Kinorise gagawonunulebol xuti cezu. Mazoyoxote nigami. Wemaji sehazorenoz. Pawugu hugigosanete dexa pujoh. Pomonume joxuwemob. Bateniholex famixumiwozok dotahugukove vebozilixavo fadorujumasan. Kunurimuvahuwi kum sixuHejezatiyi sucatuxovocu. Cahivigof mofic
iiiiii
iiiiii
iiiiiiiiiiii
iiiiiiiiii
iiiiii
iiiiiiiii
iiiiiiiiiiiii
iiiiiiii

Jjjjjjjj
Jjjjjj
Jjjjjjj
jjjjjj
mscoree.dll
((((( H
h(((( H
H
(null)
KERNEL32.DLL
kernel32.dll
K`K,K
YOSIBALIBINIBUREWEHO
VOWAGOTAX
/ P6pL
,/KPip
/-P?pR
/ P6pL
,/KPip
/-P?pR
GKatejo zohonajojawas vesimu hoxu nujecafulag huc xiguyakoluy vuboxugile
Terirepeyur hokud hif wuzor
Hihidec mubagosARijagimitun sufiv xeyuwaz bohezihozezuba wiyomebat mutokibozabaxufGulemamic focey hofibusixaka dusofasarecutax rax nixoxeyod ganigawexohif nenonujayimajax hobif vawumad
Bac remiyi tibihiMZadulozidu xafur hekebesaboyora talav woxocaxetajuraw haneseyey juduvumipilox
aDeviziyekovulol kuhipaxovuca jifebelawub focazevejawu pavoyoxecaziwav rus gopuvosumuw budofucudek
Lax gakubedexebom vulERixeruv yiwidolahici benezip bopeviraroz rehazohij doyomasaxazo ciyenMXaya jinehal pefex daxawuxaneco mufesafereh jidumikoho vula rurujefihaz ketifVHuz yekepom pacibucel reh zoyi yokocofur hesedum mikiruhipo wihazajuvun vufilawutizefeFCevapulaneye vus kamakeb secapatew bularisadig vozuxopem wopelez ruras\Pukovifa vesutip wisimerilizaso daluteweke pohinupofowap zazerejivecav few wuduhuh zunaf zayBKurepap bivotigucifurel recuxocodukap fizeyolomoze litamemedixupap
Antivirus Signature
Bkav W32.AIDetect.malware1
Elastic malicious (high confidence)
DrWeb Trojan.DownLoader37.16176
MicroWorld-eScan Trojan.GenericKD.45850055
FireEye Generic.mg.12e66476395f8c1d
CAT-QuickHeal Clean
Qihoo-360 Win32/Trojan.Generic.HwoCuqcA
ALYac Trojan.Ransom.Stop
Cylance Unsafe
VIPRE Trojan.Win32.Generic!BT
Sangfor Trojan.Win32.Save.a
K7AntiVirus Trojan ( 00576f791 )
BitDefender Trojan.GenericKD.45850055
K7GW Trojan ( 00576f791 )
CrowdStrike win/malicious_confidence_100% (W)
BitDefenderTheta Gen:NN.ZexaF.34608.UyW@ay6YAIaG
Cyren W32/Trojan.PFJH-4046
Symantec ML.Attribute.HighConfidence
TotalDefense Clean
Zoner Clean
TrendMicro-HouseCall Ransom.Win32.STOP.THCOHBA
Avast Win32:PWSX-gen [Trj]
ClamAV Win.Packed.Midie-9839746-0
Kaspersky HEUR:Trojan-Downloader.Win32.Upatre.gen
Alibaba TrojanDownloader:Win32/Kryptik.bcf50b35
NANO-Antivirus Trojan.Win32.GenKryptik.inxnjh
ViRobot Trojan.Win32.S.Agent.755200.AE
AegisLab Clean
Rising Trojan.Kryptik!1.D250 (CLASSIC)
Ad-Aware Trojan.GenericKD.45850055
Sophos Mal/Generic-S
Comodo Malware@#uji6a7x6z8sk
F-Secure Trojan.TR/Crypt.ZPACK.gyvjy
Baidu Clean
Zillya Clean
TrendMicro Ransom.Win32.STOP.THCOHBA
McAfee-GW-Edition BehavesLike.Win32.MultiPlug.bc
CMC Clean
Emsisoft Trojan.GenericKD.45850055 (B)
SentinelOne Static AI - Malicious PE
GData Trojan.GenericKD.45850055
Webroot W32.Trojan.Glupteba
Avira TR/Crypt.ZPACK.gyvjy
MAX malware (ai score=100)
Antiy-AVL Clean
Kingsoft Win32.Troj.Generic_a.a.(kcloud)
Gridinsoft Trojan.Win32.Packed.oa
Arcabit Trojan.Generic.D2BB9DC7
SUPERAntiSpyware Clean
AhnLab-V3 Trojan/Win32.ClipBanker.R370568
ZoneAlarm HEUR:Trojan-Downloader.Win32.Upatre.gen
Microsoft Trojan:Win32/Azorult.RM!MTB
Cynet Malicious (score: 100)
ESET-NOD32 a variant of Win32/Kryptik.HJUV
Acronis Clean
McAfee Packed-GDK!12E66476395F
TACHYON Clean
VBA32 BScope.Trojan.Glupteba
Malwarebytes Glupteba.Backdoor.Bruteforce.DDS
Panda Trj/Genetic.gen
APEX Malicious
Tencent Win32.Trojan-downloader.Upatre.Dzak
Yandex Clean
Ikarus Trojan-Banker.UrSnif
eGambit Clean
Fortinet W32/Upatre.HJUV!tr.ransom
AVG Win32:PWSX-gen [Trj]
Cybereason malicious.6395f8
Paloalto generic.ml
MaxSecure Clean
No IRMA results available.