PE Compile Time

2018-11-15 16:43:36

PE Imphash

271d0f1638ce5b8074966ad4d7246277

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
UPX0 0x00001000 0x00048000 0x00048000 6.9651306486
UPX1 0x00049000 0x00039000 0x00038200 1.61636800011
.rsrc 0x00082000 0x00007000 0x00006c00 6.75721673474
.imports 0x00089000 0x00001000 0x00000800 4.06851768974

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x00088658 0x00000468 LANG_SERBIAN SUBLANG_NEUTRAL Device independent bitmap graphic, 16 x 32 x 32, image size 1024
RT_ICON 0x00088658 0x00000468 LANG_SERBIAN SUBLANG_NEUTRAL Device independent bitmap graphic, 16 x 32 x 32, image size 1024
RT_ICON 0x00088658 0x00000468 LANG_SERBIAN SUBLANG_NEUTRAL Device independent bitmap graphic, 16 x 32 x 32, image size 1024
RT_ICON 0x00088658 0x00000468 LANG_SERBIAN SUBLANG_NEUTRAL Device independent bitmap graphic, 16 x 32 x 32, image size 1024
RT_ICON 0x00088658 0x00000468 LANG_SERBIAN SUBLANG_NEUTRAL Device independent bitmap graphic, 16 x 32 x 32, image size 1024
RT_ICON 0x00088658 0x00000468 LANG_SERBIAN SUBLANG_NEUTRAL Device independent bitmap graphic, 16 x 32 x 32, image size 1024
RT_ICON 0x00088658 0x00000468 LANG_SERBIAN SUBLANG_NEUTRAL Device independent bitmap graphic, 16 x 32 x 32, image size 1024
RT_ICON 0x00088658 0x00000468 LANG_SERBIAN SUBLANG_NEUTRAL Device independent bitmap graphic, 16 x 32 x 32, image size 1024
RT_STRING 0x0007c758 0x000002e6 LANG_SERBIAN SUBLANG_NEUTRAL data
RT_STRING 0x0007c758 0x000002e6 LANG_SERBIAN SUBLANG_NEUTRAL data
RT_STRING 0x0007c758 0x000002e6 LANG_SERBIAN SUBLANG_NEUTRAL data
RT_ACCELERATOR 0x0007bb18 0x00000010 LANG_SERBIAN SUBLANG_NEUTRAL data
RT_GROUP_ICON 0x00088ac4 0x00000076 LANG_SERBIAN SUBLANG_NEUTRAL data

Imports

Library KERNEL32.DLL:
0x428000 GetProcAddress
0x428004 LocalAlloc
0x428008 VirtualProtect
0x42800c GetLongPathNameA
0x428018 GetTickCount
0x42801c lstrcmpiA
0x428020 lstrcpyW
0x428024 GetModuleHandleW
0x428030 MoveFileA
0x428034 VerifyVersionInfoA
0x42803c EncodePointer
0x428040 DecodePointer
0x428044 GetLastError
0x428048 ExitProcess
0x42804c GetModuleHandleExW
0x428050 AreFileApisANSI
0x428054 MultiByteToWideChar
0x428058 WideCharToMultiByte
0x42805c RaiseException
0x428060 RtlUnwind
0x428064 GetCommandLineA
0x428068 HeapAlloc
0x42806c HeapFree
0x428070 HeapSize
0x428074 IsDebuggerPresent
0x428084 FatalAppExitA
0x428090 SetLastError
0x428098 CreateEventW
0x42809c Sleep
0x4280a0 GetCurrentProcess
0x4280a4 TerminateProcess
0x4280a8 TlsAlloc
0x4280ac TlsGetValue
0x4280b0 TlsSetValue
0x4280b4 TlsFree
0x4280b8 GetStartupInfoW
0x4280bc CreateSemaphoreW
0x4280c0 GetStdHandle
0x4280c4 WriteFile
0x4280c8 GetModuleFileNameW
0x4280d0 FreeLibrary
0x4280d4 LoadLibraryExW
0x4280d8 IsValidCodePage
0x4280dc GetACP
0x4280e0 GetOEMCP
0x4280e4 GetCPInfo
0x4280e8 GetFileType
0x4280ec GetCurrentThread
0x4280f0 GetCurrentThreadId
0x4280f4 GetProcessHeap
0x4280f8 GetModuleFileNameA
0x428100 GetCurrentProcessId
0x428110 GetDateFormatW
0x428114 GetTimeFormatW
0x428118 CompareStringW
0x42811c LCMapStringW
0x428120 GetLocaleInfoW
0x428124 IsValidLocale
0x428128 GetUserDefaultLCID
0x42812c EnumSystemLocalesW
0x428130 HeapReAlloc
0x428134 OutputDebugStringW
0x428138 GetStringTypeW
0x42813c FlushFileBuffers
0x428140 GetConsoleCP
0x428144 GetConsoleMode
0x428148 ReadFile
0x42814c ReadConsoleW
0x428150 SetStdHandle
0x428154 SetFilePointerEx
0x428158 WriteConsoleW
0x42815c CloseHandle
0x428160 CreateFileW

!This program cannot be run in DOS mode.
.imports
Wu;SSSSSSSS
SSSSSSSS
QQSVWd
<itx<o
<itx<o
jdh(&E
j@j _W
Y;=<XE
~pjCXf
HtHu4j
,SVWj0X
Wj0XPV
t WW9}
jA[jZZ+
URPQQhp
tf=8YE
PP9E u
~';_t|%3
Ht+Ht$Ht
HtHHt
;t$,v-
UQPXY]Y[
tK<_t<<$t8<<t4<>t0<-t,<a|
<z~$<A|
0t-HHt
<0|L<9
tE<A|2<P
t9<_u5
t.<_u*
Tt^HtTHtJHt
<A|,<P
AtOHt5Hu
OtFOt#OuV
KKt*KKt
<0| <9
jdh )E
jdh@)E
PWWWWV
PSSSSV
<0|m<9
G Pj*S
G$Pj+S
G(Pj,S
G,Pj-S
G0Pj.S
G4Pj/S
G8PjDS
G<PjES
G@PjFS
GDPjGS
GHPjHS
GLPjIS
GPPjJS
GTPjKS
GXPjLS
G\PjMS
G`PjNS
GdPjOS
GhPj8S
GlPj9S
GpPj:S
GtPj;S
GxPj<S
G|Pj=S
tyPVj@W
_tcPVj@
u#j,Xf;
>Cu/f9F
vlh<XE
+tHHt
+t"HHt
HAO8t
Yu2Vj@h
SVWjA_jZ+
uBjAYjZ+
SVjA[jZ^+
jAZjZ^
uHjAXf;
uWjAXf;
WPPPPj
PVVVVQ
PVVVVQ
+tIIt
-t*j0X;
+t"HHt
jilidimizicanorukepu nabufoxipaxo
behepojugayurepobunusofeyawepe zejose
%s %f %c
banemi
lonexidozitesetizupuyevi yicozakayijeto mififofacoruralexugo lobihazekakigini venecotacewami bebetipogirosoweharekiri saxekobege copupizotodizepa %f
pehojoxegatekucacolobajeci
goredegiwuwoheluga
duyumavohevifafajesibicepuxidu maxebocugazimehuxadixi citulosizinivuxolifiri vin
"0'7"*!
4,;="
435(3%
5.-2+#/*,
9,' 0
.+/!)!1?9
2=9':3
(.#8$2
*!.3-):
"?2>3!
")<%-&
%"*(-<+!
(2*!(3
6;>1=7#$0 *
--<,4,4;
"??-,<)
?1;* *
...0/+;
;5+7)
/-?<&:"!
>93%;'
#"(82*4=
91<*:??"
!.8"2
'5#,.4
.38>)&
!%#9?$24*
$>:&7:
9:.%76:'
3;*$35,
$?145#7&<+
"+8-</
="6!::
+!1"/84
14%'%<4
6#.8>2
#7/0:5
8.3(6
,=.8&8,
)2#888*
8,;)2+#'&/
4.*$*>0
#<&67<#1
/8%**11
*>+:)85
2<06-=
&1:3* '
$$7,$7
3#>23>
?%63?% $
*1?287
&(,9%70
8.=74
$.7*)"
2:<?7&
2( 0?.
#4;$6.7))"
($"2//-
-:(!3:(/
;/&1!.<"$(2
""+$,3
8&1%*+
%3">
&/*)/>
$4.""2
?&7+%417
+7$*'0>8
#9<<8'
01!%;%/:/
3"7>/
43#3/;
#<-8%
%3;.5)72
72 94=
#27(,
$?#(2*
:+05%6>
24< '7
74-%'%)
?8&+;72#4=
7'.)=):
?!120
(?6*"
9'*(42">
- $&>=
<6?13!6&'79
8%-85:
*./-2;5%4<)
!/:8+230
8&->0
914)9"
)1)4!
3/(/+)3+
17=5>.4)
&.);;
;96!7+
9%!1#.!
+!'-$,2
6';'.(
:%75$.5
"67%22:5
9;)-'>>-4
4?-<6%-+
578;<$4<?
--,!?4
($$;='2
2*041-
#$:9)
;787)*&
<,;>8:+'
+$8&*!.
(-47'+<8.
3(=#+3(
62?"26!/
!;(" ;
#,6'(=
7*/7:(
%3(<*3->
!.4/4?
#5#1,+
,"6)9
;.4#,/
-!9(">:
.#&39$
9+9<17
3&$"8=
6$!10%&
43%,7.
'8>4;$
&/#>6
?0?#7%
59/!&"
9=%+>5
)$4?44/5
%16(8-
.14- <
!+#-7#/1':9#8
7$.(<4!
?3*)/ ?
2)2"(2
!,6'=$
#(956;3'$
8?2?*2
,?6.;
;=939$
4$--.(!'4
& 137*1=-
20>*43
)5*/>!
?$$6$%$
0:559"
%;!<;#*
>&5"-1
>64("8.
/5!/&&
;8<2=>68
$?%2:1(
#)>))0
"5&25)0
.25161
%(7*%&
%8&3(+80>3
' 0+"5
+*55'0
3.!(+
#?>20
(21159-
)>$&;'
,#3?'!<
*,2/(,7-:
>!30'&
*6-&>;
!3*".)
3<):0>*
$'<:%=
'7=,7&,
!*/;4!'5
7/2#25
07?.+,=
!*7/2>"
-6?'?/-?1
2#8%.6"+
79*1<!<
:-</#
$/,=.79
.660-5
?! 9;+
'414>55*%)09%
*,)5=-$
$)6<41
442%*3
)!*4*4
)!'! 8
:%8$0'
<<2$7
+'*:.9#
'7?!%);&
&;#/1<'
4%#/))
838>4/-
"7+-%0
=7""6#8
. />"
82$)!9=/ .
.<&3/ 8
*=)!8/;
;<=&%1
("*(."
'>6.?%
/4"=:
&:7 16'
*,$$*1
5#)6;;
2$ <:0.
+&8907!!7=
1*6$&(
=-740(&3
.9(1".8(
$*!% " '=
>%(;424
;*()0
!#*=.033)*
=!:'*"+
.7<&;+;5
%*5?"::1;
#-+7-!+
/),0);
*80.:;87=<
=%9?=&2
(9050&
*:-%%
0')#98
;0>"*
#',628
$!6%)-'
/$9"?.8
<2#6&:
9(&*"'
6?<.%"<)
&->>$:
#1,$(7
)1->);0"8
6,#:8/#!
4#<';'
/ =.1#
(-:??6
-*,#3
2&<,&)!
7$73"'
;-('/-
4'(6*+&00<
*+%&93!
"9.4++- $ 7)6
5.8%9;
,0-?<7</
! &<#3
+70$?<
$7"5+
$,&?=>
+/3(>=
599 /.
"1673"
#8+&!%
,2-+'9
,',;(1
=8'3%
8 /;=
9: 6$&:>*8?
1=( <'
55!+>3
$3$85#9<
%7:&1'
8#3#=+5,';
?(4"/'7
$"8!)
1)"#-%
'/43<$%
'/.%!8834
>8&,!='
'!;&:92
! >/87<
3.')1
&$8"057:
1<4*7'
+(8.)'
/%9=(:/
7#(:
>9*4".4
%75==(
=&23+!$5:05
*($9'2<0
-4:3>9
,6?<(3
>3' 9>
;-2!$$
(83-3$$
'/8<;="
864*5;
/4;%.;<,9&><
),!67:
7*:=(1
7 +8126
-',+2-&
+. (8
'14+2)'+
.$)?/**)
73(559
'$.<8&
436?%0!
:#!5#*77
:*!>&*
<)<#!&
.,!;?
7>68.#+(
,5<"$";
85*=6
& >&<*
,+46!&#)6
5*?3#(=3
043%>,9
(((<'>,!1
9/>.6<
=*'0>>:
7&1$%?
68+&.3
#%(=2&
2>7/
";#9-
>% )">" )&/
5604*%
1=8?$4
-/6 + ?
=/>42:
2 =%*3
29 .1
:;7$%:
$=7,%<
*7*4;&
8( !)27
$:.*/8
'(3+"&
7$5>/>.9>?6
>7=(*2
0&-38:;
<111021/
;-;?$)"=&
6/3)!
">/?*.,
'!1369=8;3*.
156%8
2;01)-
>.%+=9
<9,121
8. )(7
7469.1<
#8/438!-
=%=7#
5?&(-&
4:=;,
+),8!
.2%$-
&?+3;(
312-%+'
# ,)67
7 52%5
4%'!5#:
%=<"#7
>?60#.
968$5;
:1)0"!<
#+06(!
&&3 !??>;6
+7(6/#
!*)./+
&;8!88
=#!$&076
($0?1:,.&
>60'07.
$2#-%2
891!>:
1#0.*3
(??027;'2*
6%=<32! 7)>
< ;7'+
+$)?2<#
5/%5=>.%9
,; -:*
&<1 <%3<
6789;6;<
;=)+0*">+?
&.65.:!2
?.: (9
$=/
8/"%2(
6;"3 7
>'" #'
3=(,!2'
+"#-74
7>2; >
#(2)/:+.
!&'6"+
*?92<)2-
+/2%*;$;4
:.46,?
3&%052*
.436(2<>?2
"9*=5+*+5<
'),0.2
=:+==/8#
=8),0"
?;%/;(
?( >=<
9= '**
7/=(!
6*6>)
!#'*?6>$
?)"040
3+7,<'
!',.9,8
;#"$.'
:0#7)!
5.8&81
#(()=8+
+"5;83
86.=&84
12*/66)
+3,=)4:*
0+.$98
'-*35
*,!; &
&;=!0/%
,86%6 .
= '5>-"5
10"4+2
:1'*;2
36=:5"
&865.4
?",!,'
/-%9-
78>&!96
1 7>;'
++3'&9
'5)7!8
)<"%&,$
8?,>*=&(;(
!75.>&
861>3)*:
<?9,:+6
!43=$)3="
?8,?5%4
&?:.>?5,%%,
3'34%7
>/&$*=7
 ( "78
3*8%)$
(5>+>66:
"+553"
5-$8=4
)=84*$6
;!298"+3>9
'.<("4
02=60?.2
0(5()?
+0" (*
%1175%
<<#52>
'#*+4.')
(&(7#5.93%
+'?1",
86524"
?;&$'+"=
++"#1>2
'-</"4
9"7+ 68
!).?)?='
6<5:2/6
94%>;'2
2$"()>
))?%?
/##$6=,
581$5#
5.2=:'>
'+&)'"0
*++=$
1,38.&
8=2.< %
<!97&&&(#
8)./!>
;)7/*33&6<%
53).,1
"2.=5
$9-$-5
'=<((*:!2/
#17!!8
*6<2(3
03+-#9
#/91($5;
,;2*;?
9%7*-,.
>0> :+0*&
.?*3+2
81 %.5
3-4!8
6'-//<=
))'79"
$3)=&
*'':=&
:<?;'
05974-
)40!:4
:+8/#&2
<'42)?<
&?6%56
)#8)?:
0:9)4.
;9.( *
".+4(5
>66'0,
-.=0,/
&?:3$
<09!6.>#)
357<<-
<3/-*
'>&;4!
*'8>.;24
;<*,;$
3/*-54=
7$5%"<
+(8<-4
">5+09
3.6<,5
13;&-0=
+8$;.+
6)5!%(
+#6$#7
0"): )
; '&&)-9
%;?9!)(
1#4&4*9
9?03"$
&?&=) %6"
8+=-/;%><
<32<2575
$(,)9=
308& <=
>#% )%
1)*6;:($
# 03>7
0=?1&?1-
*9" 4+-*3
/=8)1>=)
,08%'3
>4& )
+,60$?&
+,2+3<
?0%%14
!5!&55.=
"/7&3:;
*3,'%$#
5:3%
#$9
<&6<3'+8
>!$> >>?9
>>%37
1=$%:/2
">00.0
37384 1*
<0-<#;
+22%#.'
?1?&!9(+/7
5**78=&
439&-$
',,) ,?+$
'2<<=
<4:!!(:!7-2
+95%2-#
05+">?
38)#--
9$=*>("4!,7"
'-=>>9'
7>-5,#
0/9! !56
",&"<*
#=9=&
$77/%&.
*1((96!
'<)7(*;:
$7"/7?
$:0)4*
'>.%;
+"9)+
4&>($+-
5'*:=75)' :
48%#?3
45&3#6/<7
&9)2:=
4)1*=8:2;
/=8" )?
51) 6*
>!:4-.,"<
'%3:-/
#3!.)7*
":&328
?99)*
=")>')
$<8%5%
#5-=4
9320#":
+ "<" =
22(:)"=9
%/)?:;
=9-+66+
-'-3:;
;1=-9$
;=:;( 8
"00=4!-
6'"%/4-
"4(,0'%5:
)$# 3
*$#*9(
0$8*>:=
?-7754.?=
9#(.($
:34"4:
-8.2%;#47
;2>1!2+=
9?('.=
=7.=.3;
,6>=1??;8
(.3<"(:
670).:!
3, )1?3
:6)&-6
:"%?#9
6; 5??#
5/81+)
<0'?:<7
2;+-+9
4;*) ;
6+;' 5!
==5%/-
(#1*=*
&$?!1<'
9$>&'>2+
#&/!;?9
#28"')2-
0"'"">
00:(6;
4?'7#*'
1*1<?60
58>/*+'
'=&8 5
'7,8#*2
='24/201
8'=2!
-22"6+(
**07/
=:/68?
4$=: 2*$
9*$+5-
=3120769#>
1.)>9-
#,*?4
24.""
2&02)=!
!$;*3.
.1$3":4
:#''98:
. *0-(+
=:>;%;
":9$31
&02?>
$3!-)!
3,,<56
,* =*<'
0";,7"(&840
0&"8!0
#?<> ;
8')??4
)**22/.
-';$*.#
$:$< 3
4'8-19
("/0=:.
./,40%:
43,:%)"
69*$82
)')109)
*8.02:+
"=%7(3
*78<%!
+?5(-'
/=#+19+$
81(0.57
<>/8+82
-(?('!
>"5%,</<
;.&1:> 0,
!07'9'
5#+#0:
4" ,7?
7&/=6<)
1:71(1
-!8"'2
&#/71;
>2/'"/
#.%"1-
6&0;=7
#/1=??.
7%44#.,
->5;3#
*#&67-+
%:1= 
#%-$*"
'.!;<
>#99,9:&
+)?4(.1
949=!5
%4582%&
)+13,&
='=460-
6;=.#(/
65*;6:
,/#'#!'5
9,%2$4
"'52?9
0#66+:1%
4-)2#.
3>95!;/4"
/$-9 ?
&(090+=
<-4&<%
0,>?)1 )
!+?(&;
=14+8-8
5514420?
!4*$5
!+0:;;
-8&$7?
?)+?"
6/&73<
1"((=* 7'
?'&'%$
!71(!;#
$11<(;
<,2?)?,"
3#&>=
((*6 7
##/5('
(88?&'&%
71! ;#2#
7(1(/#,74
#/'>3=%,7.$35
9>,8--
6(?*>
?)+?"
:5'4?%$
2+9+(2
1-"52+
2%',1-
&<9-.*
:'5;,=
%:$7:"=.
=-75.9
>"3%3.
9?%*041
3&6::(
=+;,6?
9 0:()4
=:&: #
8,15!/ 4.
$%;0?
<-$=5/
<:85*4
63.*6&
21./ 
7++3+'
8&09:);
#*,,*;.=
62,--47>&
!96 95
&!88#3
;<%/(<0
7%%"/=>?&.4/96$
7<?4-(
47=-'
(9)%9-
$1=/,2
">;4*"$/,
3)'%18
/+;!7(*2
8(2;5
;-25?9?7
0(,(=="03::
$6-=-.7
$</70'
913' 5
(***7/
(<"86"1
63<157
%(&&8(7
'+!#/
+04+>*4
&%&" 3
2? -2
8+(.")+
<*4&5/6)
(=224##-
(#1*#*
-0 5;1
;2:,2(
*0+%4
(=.68+
61.(;(
$72.'(
#<7'<7
-28675,
',/;=1
5<!<2&
+'/886
10"&0!
:.+&17
&59=3?
':39!+/&9
4(<5:/
=%<:<+6/
#.+??6$
1#,75)
!7".#(.-
$1<9&-6
2"5 *(=.
<-88!61
5/!,+
+#>$0'
708/!:)/-
7)&:,>.,%
%#" -6:
'3!7;&
4),!0'
<(';?+#7":/
/3 <
$ "8#:&;$7
(=:.74
%>+;8+
"8>$$?3
43.(&8/449#2",
$!3/(!#
844!!"*
$:43&'$)
.%07#<
;1.?><
8'2?!#')
5"#5
<.';&.2,#8
9*51=9
34-%,3
.7 ::,
%#=7&$
-"<%30#?
="!+&-'$
52$3 0
.2>3/!$4
?/84"6$
.,762?
'#:8" <
6"+:$8
>!&!7>,
?<6"#9
)?%#3(7
3/"?)0
2##$++,
$"6#">
+77+/%"
"%/6 %'$?
>8,0#68
(2;#""
:$#?++
+,8%#.3;*,0
$9)+ 0.
&**2!+
.#=>!
>+/*50
=.. 71
2/=%*2<
+8?>6"
5:8>;9
0''98&
60#6-)=
'#9#1=
5-.:.;
<-##3
2<4.05
$7/6#;38
+.,4;4 ..
3"<743
(/92;(<5
)>( '4
/'( !/0
:(#7$(
%!$>0%
=<$/2<&
69'9;>*
:,")7 14
; 0!7
"'8/25
5'-?<(=8(
0) !>&'
6<8$:?
%9#83
).23>052.
+!+<,!
36!4&1+>
&?6, 
5:;?"4
1:1))<
0$:)92
/!6(!
!#!$'52
7="7
!324.(*
11&74+
"'4+:1
')5 >:/"
,- /"(7
9/$3<
+6<$%:*2
432&)0;
5 1 016<4"
"2??!4"
+#?&,$
/+?4/&
61<9(
96"'.5
8*<;;%>4
561,.,+7
!%8(7*
%80=01!
:%.0;..2
*<9%:.3>33
4+*+>8
231= :8?'2
'!<)-!
77*:9:
14>96=
>9<&9*
#%.*,*
'<<=+?"-<
%+4'#$?"/(
'&#*2
41="?<6
;/:
# /8#+8;
549$0"
#(8-/
'"! 59>
.8%%?
;<-$ 2;
37',%/
/7-/<"
95="1*
8$; &51
+3;34
3:6,,2&
'+7 //7
($($9/+
6%203
6,$(!<
3/0$')
,6$(27&
--8;2,;
4$'6:5!
!&&*-*
!*46=7)
>#7.1/;
468+2)
:4>0!<
6=002+/,
!((6<
*/#'15
95''';
>1338%(
>$:?*6
4'0;#(
"7+/'++;
8%?72#
&(')5<3 1
$',-:"
7#';?(
7:/)+1!6
05=9(
( 95+9'>
1"&(.&
469>3.9)3
3+,3(#
5/$"(-
+("'*(
30/%0:5
*"59")
'+2;.$0
(3/ !+0?;4
'1='=4
(,6#!7(>)6
-*(0=
;.08?#8&"+ 3<3%
)!8*5:
</483<
6.> 16?
)<82$
-9738:/
;04*4'3
0&2"4.
8)0 >-
":>0*)7
% ?+:02
*?+&!:$
' (>3
6=--4.
';.!/&&1
9&:$4/=,
0:87<6$?$
>..!>4
,7%#$'
03#7+01
3+>6;
"56'2)
<+ 8&>.
; 58!7'.=*
.( 6:>6-
<07/-4
.&4*8$.
8>3;+
<"(<&
/78#==
%)=!8
;,&$!5=
275:?2
4,!&5"
&&#/*7
3:.*/:*%
2:.6).
60"-"3
/ 948))
1*3/6$;=2
#!?-<11(,?
4!..*?=-
2,%=246'
?%; -
1#<84<21,
7.7'0
>+>232.
9&0%=>
5(.<".
94!%-?
'9$9+6
+56+%2
-(5 0'
/%';9:
,",!*
4>29(
)4$8):
')7"0%
;(6>%:
(62.%+29<05
1: =;7
/!%+;<
><0 9
/1#'+
93$?):.
"8 4+7
*.&"9?"%?1+#
'$%:75:
!39#/ ..>
;*:#'(1767"$
3*"+39!
6!+?2,9
#+!*$%;
)8*,-;6
4,?8-$
>*&-(?
97"-+
#'248)
)>/!""
<*6,(
>-,<%7
7#&- +
'?!##0
?95- ,
,4*8"$608
0.=>+'
%3'*90,243+7
.$;,(3($
36?-3
7.7=(
,)9+)
;=#$1"
0&.;(-
="%!5
"+$=05:
>>))'.
6239'9
1 $=.6
/23"+,
40%4)1/
5)19'3%,
&-&8)3
21' 76/=!
$9('#1
)7.;!
"$+2!=
6:"!)4
+=""?<8
1/&52$7.9
10&'(:
"?/ 8!<1
4%(?917:
(!.=/57-
*="((6
'7+,.!
3430>&
9/!/(-
>.8'*&,!
+;,9' 4'<
2>*!;/,
&;(<5:
(.=2#..
.+0<604
(.*!=?
*": 6;+
)9<!*-
0$=!>61
(6"=2
#<1/7<+
< )0;
&91%'
#=)6):
5=?5<>
4#.<"0
#5)?="/
"(6<',=
9-!#=51
&+4,>*=
#!*+0
+>9-*.,>8
1%<8',
$"')9"
!<(4"6
"$#8 9
-1$;36'
+'75/,
-?#""(
#=41-0=&0"
<,10&"
!&:(!#'
'39,*0*
5;=(.2
)0-.)
'?;96
)&97+2:
7$$/2,41""
#++1*)(;)/;-
2;3+2
59;=''
$..$%)
>*<921-:
24 &8#
+34(6/
11=!'
+(3(%-:
$>>6:$1(3:
';: +#
"&?41*
=+(4-24/< 4'8!
+0/?
04 .<9
4**621+40% 6
"";","=
/5',,3
)?'2"?=%.
7#$;$&
???$,3
="<%;-
&5'>0,#'
:.*)-7
)#30(9
+%&?,%
(=3-1';
<$4#%:
;!$8-,
'+#&112,
<+*(1":
(+5+94;(8
'!**/
!)-,
> 5,,
96#/-/2.
?.(89
8$/(8<?
% %3")9
=%1 7)?!2-
?:+.-%
"0*!151
984#<
) !0"0;
.;?:)-6
=71/9)%(
.;;8'
"+$,-405-
<??9;=
!> ?#''7
= 8'?<,
2<>:"
?25+3>;
$:'.9?$
"*,#>"60
/,'>#$
5""99,
;,9 -/?-
4;#0#0
989#+&'/=4
22"253
+*6 23
.8;$% >
%7%/5?7,++,;
:!6.;#
106,4?(1
,.7!<!
9!,'3$<
"->6,$
48' :!%
;#%+<?61!
98=.92"=46.
4.!?=
%,%/,8
2#.659
,5:1--
'!!4<%
:*-'=%<
4!)"0
2=<?(?"0
:"$#.-2
;:%0'09
9$,'*"1
/-+4>&7"3 5"5"
"8<?6)
% 10!.
-"%;/,9
;82).;
4,#";
;33:-8
)623)#
7*"')%
! 55>;-*-.4
.!(419;
0&/3>0
.!(-;
.-?(!7
!>6;.%
4 41617$
($!.>)
3" ")3
61'=>&
,<325
(+**!
9!?+#7.5
68)0!)/:-*:
%7269-
&5090/2
(?!7.?
=!"?2>=5
8*80='
73: %7!
< $* ,*(5
generic
unknown error
iostream
iostream stream error
system
string too long
invalid string position
xdigit
bad allocation
bad function call
regex_error(error_collate): The expression contained an invalid collating element name.
regex_error(error_ctype): The expression contained an invalid character class name.
regex_error(error_escape): The expression contained an invalid escaped character, or a trailing escape.
regex_error(error_backref): The expression contained an invalid back reference.
regex_error(error_brack): The expression contained mismatched [ and ].
regex_error(error_paren): The expression contained mismatched ( and ).
regex_error(error_brace): The expression contained mismatched { and }.
regex_error(error_badbrace): The expression contained an invalid range in a { expression }.
regex_error(error_range): The expression contained an invalid character range, such as [b-a] in most encodings.
regex_error(error_space): There was insufficient memory to convert the expression into a finite state machine.
regex_error(error_badrepeat): One of *?+{ was not preceded by a valid regular expression.
regex_error(error_complexity): The complexity of an attempted match against a regular expression exceeded a pre-set level.
regex_error(error_stack): There was insufficient memory to determine whether the regular expression could match the specified character sequence.
regex_error(error_parse)
regex_error(error_syntax)
regex_error
permission denied
file exists
no such device
filename too long
device or resource busy
io error
directory not empty
invalid argument
no space on device
no such file or directory
function not supported
no lock available
not enough memory
resource unavailable try again
cross device link
operation canceled
too many files open
permission_denied
address_in_use
address_not_available
address_family_not_supported
connection_already_in_progress
bad_file_descriptor
connection_aborted
connection_refused
connection_reset
destination_address_required
bad_address
host_unreachable
operation_in_progress
interrupted
invalid_argument
already_connected
too_many_files_open
message_size
filename_too_long
network_down
network_reset
network_unreachable
no_buffer_space
no_protocol_option
not_connected
not_a_socket
operation_not_supported
protocol_not_supported
wrong_protocol_type
timed_out
operation_would_block
address family not supported
address in use
address not available
already connected
argument list too long
argument out of domain
bad address
bad file descriptor
bad message
broken pipe
connection aborted
connection already in progress
connection refused
connection reset
destination address required
executable format error
file too large
host unreachable
identifier removed
illegal byte sequence
inappropriate io control operation
invalid seek
is a directory
message size
network down
network reset
network unreachable
no buffer space
no child process
no link
no message available
no message
no protocol option
no stream resources
no such device or address
no such process
not a directory
not a socket
not a stream
not connected
not supported
operation in progress
operation not permitted
operation not supported
operation would block
owner dead
protocol error
protocol not supported
read only file system
resource deadlock would occur
result out of range
state not recoverable
stream timeout
text file busy
timed out
too many files open in system
too many links
too many symbolic link levels
value too large
wrong protocol type
CorExitProcess
Unknown exception
FlsAlloc
FlsFree
FlsGetValue
FlsSetValue
InitializeCriticalSectionEx
CreateEventExW
CreateSemaphoreExW
SetThreadStackGuarantee
CreateThreadpoolTimer
SetThreadpoolTimer
WaitForThreadpoolTimerCallbacks
CloseThreadpoolTimer
CreateThreadpoolWait
SetThreadpoolWait
CloseThreadpoolWait
FlushProcessWriteBuffers
FreeLibraryWhenCallbackReturns
GetCurrentProcessorNumber
GetLogicalProcessorInformation
CreateSymbolicLinkW
SetDefaultDllDirectories
EnumSystemLocalesEx
CompareStringEx
GetDateFormatEx
GetLocaleInfoEx
GetTimeFormatEx
GetUserDefaultLocaleName
IsValidLocaleName
LCMapStringEx
GetCurrentPackageId
GetTickCount64
GetFileInformationByHandleExW
SetFileInformationByHandleW
SystemFunction036
_hypot
_nextafter
bad exception
MessageBoxW
GetActiveWindow
GetLastActivePopup
GetUserObjectInformationW
GetProcessWindowStation
Sunday
Monday
Tuesday
Wednesday
Thursday
Friday
Saturday
January
February
August
September
October
November
December
MM/dd/yy
dddd, MMMM dd, yyyy
HH:mm:ss
__based(
__cdecl
__pascal
__stdcall
__thiscall
__fastcall
__vectorcall
__clrcall
__eabi
__ptr64
__restrict
__unaligned
restrict(
delete
operator
`vftable'
`vbtable'
`vcall'
`typeof'
`local static guard'
`string'
`vbase destructor'
`vector deleting destructor'
`default constructor closure'
`scalar deleting destructor'
`vector constructor iterator'
`vector destructor iterator'
`vector vbase constructor iterator'
`virtual displacement map'
`eh vector constructor iterator'
`eh vector destructor iterator'
`eh vector vbase constructor iterator'
`copy constructor closure'
`udt returning'
`local vftable'
`local vftable constructor closure'
new[]
delete[]
`omni callsig'
`placement delete closure'
`placement delete[] closure'
`managed vector constructor iterator'
`managed vector destructor iterator'
`eh vector copy constructor iterator'
`eh vector vbase copy constructor iterator'
`dynamic initializer for '
`dynamic atexit destructor for '
`vector copy constructor iterator'
`vector vbase copy constructor iterator'
`managed vector copy constructor iterator'
`local static thread guard'
Type Descriptor'
Base Class Descriptor at (
Base Class Array'
Class Hierarchy Descriptor'
Complete Object Locator'
template-parameter-
generic-type-
`anonymous namespace'
`non-type-template-parameter
`template-parameter
`vtordispex{
`vtordisp{
`adjustor{
`local static destructor helper'
`template static data member constructor helper'
`template static data member destructor helper'
static
virtual
private:
protected:
public:
[thunk]:
extern "C"
short
unsigned
volatile
std::nullptr_t
<ellipsis>
,<ellipsis>
throw(
double
__int8
__int16
__int32
__int64
__int128
<unknown>
wchar_t
__w64
UNKNOWN
signed
volatile
`unknown ecsu'
union
struct
class
coclass
cointerface
volatile
const
cli::array<
cli::pin_ptr<
{flat}
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
1#SNAN
1#QNAN
RSDS>z
C:\febiputapucu cu.pdb
r\runtime\crypt\tmp_1329744317\bin\soxa.pdb
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
.?AVerror_category@std@@
.?AV_Generic_error_category@std@@
.?AV_Iostream_error_category@std@@
.?AV_System_error_category@std@@
.?AVbad_alloc@std@@
.?AVexception@std@@
.?AVinvalid_argument@std@@
.?AVlogic_error@std@@
.?AVlength_error@std@@
.?AVout_of_range@std@@
.?AVoverflow_error@std@@
.?AVruntime_error@std@@
.?AVbad_function_call@std@@
.?AVregex_error@std@@
.?AVtype_info@@
.?AVbad_cast@std@@
.?AVbad_typeid@std@@
.?AV__non_rtti_object@std@@
.?AVbad_exception@std@@
.?AVDNameNode@@
.?AVcharNode@@
.?AVpcharNode@@
.?AVpDNameNode@@
.?AVDNameStatusNode@@
.?AVpairNode@@
GetProcAddress
LocalAlloc
VirtualProtect
GetLongPathNameA
GetFileInformationByHandle
IsProcessorFeaturePresent
GetTickCount
lstrcmpiA
lstrcpyW
GetModuleHandleW
ExpandEnvironmentStringsW
WritePrivateProfileStructW
MoveFileA
VerifyVersionInfoA
FillConsoleOutputCharacterA
EncodePointer
DecodePointer
GetLastError
ExitProcess
GetModuleHandleExW
AreFileApisANSI
MultiByteToWideChar
WideCharToMultiByte
RaiseException
RtlUnwind
GetCommandLineA
HeapAlloc
HeapFree
HeapSize
IsDebuggerPresent
EnterCriticalSection
LeaveCriticalSection
DeleteCriticalSection
FatalAppExitA
UnhandledExceptionFilter
SetUnhandledExceptionFilter
SetLastError
InitializeCriticalSectionAndSpinCount
CreateEventW
GetCurrentProcess
TerminateProcess
TlsAlloc
TlsGetValue
TlsSetValue
TlsFree
GetStartupInfoW
CreateSemaphoreW
GetStdHandle
WriteFile
GetModuleFileNameW
SetConsoleCtrlHandler
FreeLibrary
LoadLibraryExW
IsValidCodePage
GetACP
GetOEMCP
GetCPInfo
GetFileType
GetCurrentThread
GetCurrentThreadId
GetProcessHeap
GetModuleFileNameA
QueryPerformanceCounter
GetCurrentProcessId
GetSystemTimeAsFileTime
GetEnvironmentStringsW
FreeEnvironmentStringsW
GetDateFormatW
GetTimeFormatW
CompareStringW
LCMapStringW
GetLocaleInfoW
IsValidLocale
GetUserDefaultLCID
EnumSystemLocalesW
HeapReAlloc
OutputDebugStringW
GetStringTypeW
FlushFileBuffers
GetConsoleCP
GetConsoleMode
ReadFile
ReadConsoleW
SetStdHandle
SetFilePointerEx
WriteConsoleW
CloseHandle
CreateFileW
`.rdata
@.data
@.reloc
cOn;bx
u?0yW\scfFm?
W<ngPatha
*cmpiA
f$8uf6
Pg&4lC
HBOutp
SI2>b^
tlUnwi
dLp05k
Q-#I's
xl;aqA
CID&ih
XPTPSW
B~BB A
~o77jBBRjP=p
\(079>
F(ggFD.ggD\
c3mX@\
\gg(gDDDED
wv!!w/n
7777a77
XXG\X|
~91\Ju
{Lq**P
w|wKB2
6?.t"5d
KERNEL32.DLL
ExitProcess
GetProcAddress
LoadLibraryA
VirtualProtect
KERNEL32.DLL
GetProcAddress
LocalAlloc
VirtualProtect
GetLongPathNameA
GetFileInformationByHandle
IsProcessorFeaturePresent
GetTickCount
lstrcmpiA
lstrcpyW
GetModuleHandleW
ExpandEnvironmentStringsW
WritePrivateProfileStructW
MoveFileA
VerifyVersionInfoA
FillConsoleOutputCharacterA
EncodePointer
DecodePointer
GetLastError
ExitProcess
GetModuleHandleExW
AreFileApisANSI
MultiByteToWideChar
WideCharToMultiByte
RaiseException
RtlUnwind
GetCommandLineA
HeapAlloc
HeapFree
HeapSize
IsDebuggerPresent
EnterCriticalSection
LeaveCriticalSection
DeleteCriticalSection
FatalAppExitA
UnhandledExceptionFilter
SetUnhandledExceptionFilter
SetLastError
InitializeCriticalSectionAndSpinCount
CreateEventW
GetCurrentProcess
TerminateProcess
TlsAlloc
TlsGetValue
TlsSetValue
TlsFree
GetStartupInfoW
CreateSemaphoreW
GetStdHandle
WriteFile
GetModuleFileNameW
SetConsoleCtrlHandler
FreeLibrary
LoadLibraryExW
IsValidCodePage
GetACP
GetOEMCP
GetCPInfo
GetFileType
GetCurrentThread
GetCurrentThreadId
GetProcessHeap
GetModuleFileNameA
QueryPerformanceCounter
GetCurrentProcessId
GetSystemTimeAsFileTime
GetEnvironmentStringsW
FreeEnvironmentStringsW
GetDateFormatW
GetTimeFormatW
CompareStringW
LCMapStringW
GetLocaleInfoW
IsValidLocale
GetUserDefaultLCID
EnumSystemLocalesW
HeapReAlloc
OutputDebugStringW
GetStringTypeW
FlushFileBuffers
GetConsoleCP
GetConsoleMode
ReadFile
ReadConsoleW
SetStdHandle
SetFilePointerEx
WriteConsoleW
CloseHandle
CreateFileW
pmedumehoromaremidotoyofejuzewo hemonucalemixifije ladibudoxu
yabamebofetuyasuhafewife hogeturuhozuyodomoruvaruwi yixuti rorazevalobimizifike
sofejejidewawisazovumubodemevipu lodeyememugugawaka kenuba
nilufexepatijojahopala sawagukiveva jogagehoxuligiharedo copururivuxasilutacuzo lecuzusojelopo
cokefutezobili
nojuwacadigelaboga zelunavedimasehiloyekemi napiwewekulurodifilupugefehareli botomayete
copeyipajekevuladoweruhufica
sogifomikuboragisacimuya lavunutelinogavilonomidutarice duviyeconunixilanahulu jeki
zitoworadotofibiwuxoji juniwace ba kihiporiwi
kotutudubime dafizonefurenawocidiromu sopuponikitakivi nevimahuxivicobokawasili rivorovedabafoxatomepexegasotazo
zelekoso rosonobififarodaxudorigawu bi kuzicudajalefadeyu gepuxigovalajegexe
titoruwefugobuwicayalijata fawusiduho
jigucekucodolovirekirarisibifi
fawupemenenu
kernel32.dll
kernel32.dll
kubojasulekohibixozaxiti kab pewibu pobubavofigi pinope
yezi fowutikuyiwugefalofinaji
socuhopaxatajesijavelatisiru zijokibocukiwi vohivaganadeyixetutowasovozo yipubigokumugohedilijonuci
jebolarakasuwikesuru yunuxatuboda
xdigit
emscoree.dll
@kernel32.dll
DR6002
- floating point support not loaded
- not enough space for arguments
- not enough space for environment
- abort() has been called
- not enough space for thread data
- unexpected multithread lock error
- unexpected heap error
- unable to open console device
- not enough space for _onexit/atexit table
- pure virtual function call
- not enough space for stdio initialization
- not enough space for lowio initialization
- unable to initialize heap
- CRT not initialized
- Attempt to initialize the CRT more than once.
This indicates a bug in your application.
- not enough space for locale information
- Attempt to use MSIL code from this assembly during native code initialization
This indicates a bug in your application. It is most likely the result of calling an MSIL-compiled (/clr) function from a native constructor or from DllMain.
- inconsistent onexit begin-end variables
DOMAIN error
SING error
TLOSS error
runtime error
Runtime Error!
Program:
<program name unknown>
Microsoft Visual C++ Runtime Library
ADVAPI32.DLL
Dja-JP
zh-CHS
az-AZ-Latn
uz-UZ-Latn
kok-IN
syr-SY
div-MV
quz-BO
sr-SP-Latn
az-AZ-Cyrl
uz-UZ-Cyrl
quz-EC
sr-SP-Cyrl
quz-PE
smj-NO
bs-BA-Latn
smj-SE
sr-BA-Latn
sma-NO
sr-BA-Cyrl
sma-SE
sms-FI
smn-FI
zh-CHT
az-az-cyrl
az-az-latn
bs-ba-latn
div-mv
kok-in
quz-bo
quz-ec
quz-pe
sma-no
sma-se
smj-no
smj-se
smn-fi
sms-fi
sr-ba-cyrl
sr-ba-latn
sr-sp-cyrl
sr-sp-latn
syr-sy
uz-uz-cyrl
uz-uz-latn
zh-chs
zh-cht
USER32.DLL
Sunday
Monday
Tuesday
Wednesday
Thursday
Friday
Saturday
January
February
August
September
October
November
December
MM/dd/yy
dddd, MMMM dd, yyyy
HH:mm:ss
((((( H
((((( H
ALC_ALL
LC_COLLATE
LC_CTYPE
LC_MONETARY
LC_NUMERIC
LC_TIME
american
american english
american-english
australian
Antivirus Signature
Bkav W32.AIDetectMalware
Lionic Trojan.Win32.Sodinokibi.3!c
Elastic malicious (high confidence)
ClamAV Win.Malware.Score-6995873-0
CMC Clean
CAT-QuickHeal Trojan.Ghanarava.16766203547a47d3
Skyhigh BehavesLike.Win32.Generic.hm
ALYac Trojan.Ransom.Sodinokibi
Cylance Unsafe
Zillya Trojan.DelShad.Win32.88
Sangfor Trojan.Win32.Save.a
CrowdStrike win/malicious_confidence_100% (W)
Alibaba Trojan:Win32/Kryptik.07326550
K7GW Trojan ( 005502101 )
K7AntiVirus Trojan ( 005502101 )
huorong Clean
Baidu Clean
VirIT Trojan.Win32.Encoder.BQDT
Paloalto generic.ml
Symantec ML.Attribute.HighConfidence
tehtris Generic.Malware
ESET-NOD32 a variant of Win32/Kryptik.GTZN
APEX Malicious
Avast Win32:Malware-gen
Cynet Malicious (score: 100)
Kaspersky Exploit.Win32.Nekto.sr
BitDefender Trojan.Ransom.Sodinokibi.A
NANO-Antivirus Trojan.Win32.GenKryptik.fridtc
ViRobot Trojan.Win32.S.Ransom.555520
MicroWorld-eScan Trojan.Ransom.Sodinokibi.A
Tencent Malware.Win32.Gencirc.10bdbcaf
Sophos Mal/GandCrab-G
F-Secure Trojan.TR/Crypt.XPACK.Gen
DrWeb Trojan.Encoder.28489
VIPRE Trojan.Ransom.Sodinokibi.A
TrendMicro Clean
McAfeeD Real Protect-LS!61C19E7CE627
Trapmine malicious.high.ml.score
CTX exe.trojan.generic
Emsisoft Trojan.Ransom.Sodinokibi.A (B)
Ikarus Trojan.Crypter
FireEye Generic.mg.61c19e7ce627da9b
Jiangmin Trojan.Chapak.elc
Webroot W32.Ransom.Sodinokibi
Varist W32/ABTrojan.WIND-0221
Avira TR/Crypt.XPACK.Gen
Fortinet W32/GenKryptik.DLJK!tr
Antiy-AVL Virus/Win32.Expiro.imp
Kingsoft malware.kb.a.1000
Gridinsoft Malware.Win32.Gen.bot!se30272
Xcitium Packed.Win32.MUPX.Gen@24tbus
Arcabit Trojan.Ransom.Sodinokibi.A
SUPERAntiSpyware Trojan.Agent/Gen-Dropper
Microsoft Trojan:Win32/Kryptik.DR!MTB
Google Detected
AhnLab-V3 Trojan/Win32.Kryptik.C3339079
Acronis Clean
McAfee Sodinokibi!61C19E7CE627
TACHYON Clean
VBA32 Malware-Cryptor.2LA.gen
Malwarebytes Generic.Malware.AI.DDS
Panda Trj/GdSda.A
Zoner Clean
TrendMicro-HouseCall Clean
Rising Ransom.Sodinokibi!1.CA18 (CLASSIC)
Yandex Trojan.GenAsa!EiuI0U44kfI
SentinelOne Static AI - Malicious PE
MaxSecure Trojan.Malware.74430890.susgen
GData Trojan.Ransom.Sodinokibi.A
AVG Win32:Malware-gen
DeepInstinct MALICIOUS
alibabacloud Exploit:Win/Nekto.sr
IRMA Signature
ESET Security (Windows) a variant of Win32/Kryptik.GTZN trojan
Avast Core Security (Linux) Win32:Trojan-gen
C4S ClamAV (Linux) Win.Malware.Score-6995873-0
F-Secure Antivirus (Linux) Trojan.TR/Crypt.XPACK.Gen [Aquarius]
Windows Defender (Windows) Trojan:Win32/Kryptik.DR!MTB
McAfee CLI scanner (Linux) Sodinokibi
Forticlient (Linux) W32/GenKryptik.DQHN!tr
Bitdefender Antivirus (Linux) Trojan.Ransom.Sodinokibi.A
G Data Antivirus (Windows) Virus: Trojan.Ransom.Sodinokibi.A (Engine A)
Sophos Anti-Virus (Linux) Mal/GandCrab-G
DrWeb Antivirus (Linux) Trojan.Encoder.28489
Trend Micro SProtect (Linux) Clean
ClamAV (Linux) Win.Malware.Score-6995873-0
eScan Antivirus (Linux) Trojan.Ransom.Sodinokibi.A(DB)
Emsisoft Commandline Scanner (Windows) Trojan.Ransom.Sodinokibi.A (B)
Cuckoo

We're processing your submission... This could take a few seconds.