Sample details: c77d1c0c0ecd0b2f81f2bcf89fb07279 --

Hashes
MD5: c77d1c0c0ecd0b2f81f2bcf89fb07279
SHA1: be7d13c25052903d150ed07e836e210e298b9995
SHA256: 1d4a3957a4f4d83f1edffcb0b596e04d98c82f801ae4b23208a34076203f42f6
SSDEEP: 6144:DZf0hyXr3xpfrWXUKvx4bObrygrJ+Rh3P4vGaL67sEN1UT8EJ8PZlTS/wWg6Ttwi:1ftTDfrWlqbO/y3f4e66vB88xU2X
Details
File Type: PE32
Yara Hits
YRP/contentis_base64 | YRP/domain | YRP/Microsoft_Visual_Cpp_v50v60_MFC | YRP/IsPE32 | YRP/IsWindowsGUI | YRP/IsBeyondImageSize | YRP/screenshot | YRP/win_registry | YRP/win_files_operation |
Source
http://shamanic-extracts.biz/cunrb78f
http://centralbaptistchurchnj.org/cunrb78f
http://lacosturera.es/cunrb78f
http://arkberg-design.fi/cunrb78f
http://basedow-bilder.de/cunrb78f
http://sambad.com.np/cunrb78f
http://lacosturera.es/cunrb78f
http://centralbaptistchurchnj.org/cunrb78f
http://sambad.com.np/cunrb78f
Strings
		!This program cannot be run in DOS mode.
`.data
.rdata
@.pdata
@.idata
tR99u2
Unknown inU
L$$_^]d
j#h 	@
PQh@2@
@_^[]U
t$fhhL@
SjDh(%@
t$2hHE@
t)h-XE
UPRjyh
VVhHE@
UThXD@
tO@@f9
tsh"`E
RSRh("@
Uj?SQh<
jjj[Ths
Rj(Vhu
RTj"h6
jqh0F@
#<$jgV
UVQRhq
t$ghH9@
@<HHj@
QX_^]PQ
PQjHht
Pj"hZTE
D$ _^WSh
t$oh R@
j6j7hLW@
SetupzlZh(
RThzm@
DialogPa
lAlloc
UPUj`hS
$jBShS
nized cont
G;~ uZ3
RSh$P@
VPRQj,
j.h@D@
jxSh(/@
RVhX%@
SjDj-jb
D$$PhzWE
PQUUUR
GetDlgItDmP
t%#<$h
j:h85@
$VVRh_
<$j#Sj h_
Sjvjwh
t$ehh;@
tZMudexA
t$@h@Y@
laceIcon
ImageList_Setj
jphk7?
jsj0Rj
P0huYE
t	ItvIu
jDPhp^E
_^[VhMYE
Tj^Pj?
jlj5Uj
WaitForSingleObject
t5<Xt'hAaE
jBjShe
D$ PjEh
jfh5QE
jPjIjNjoh$
jhh@TE
j6j7UhB
jrh7aE
j]h(]E
]UhW_E
j3hF>?
- unable t
- not eno To managP`
ifyChangeKe
nFilter
Domain IT
oundWindo
CSensorMa
ReuseDDElPar
SET_TRIP
lstrle
Init this 
ipc_alloc_DeferWind
tteryCap
ileBuffe
DlgCtrlID
Regisi
%s%s%p
ATUS		Ha
waveIn
anuary
tringW
data>  Ex
tNovDec
AIN_TYPE_
GetVer- not enoug
SELECTED
am for more in
PathFindExtensi
CMFCRibbonQ
  SSSSSSS
FctMrg.AddAc
cal static thKDD
erican
TIONS_TABLE
ch-canadian
edrawWindow
r Name: %s
GetVersiH
-------- --
CE(64)&L
bS11*?
oy DSP Tab
debugl
GetMenuIt
GetStringTy
: Name %s Z
BS DV FN 
BIN Dum
SetMenuI
pDiGetDevic
ntime to termi- unable to inPD
ng point not Candidates:
WordToOb
SetStdH31s %4s  %@
red par
nd in DV: na
iption:    %s
TlsGetValueor
GetTex
memory
EsifSvcWri6D
_j..kS
'qGk6T
x$h3'>
	!|PN:ae
eGs)$m
2.Sl/a
KPeN-Gi
R'PO-$'
k*j//,82
B%!8};8
^LBu$K
Eq[\(BM
ksO+6c<
Y4J,f+
Rw(%t*
)`L0+C
G/=^pj
g91fEg
Y]P?tv
>%EOg:
oJ*5}9C
=#&GD)'
adqA`#6@\
H}gpOM;n
^4Vstd
C+kv%a
(%/lI R
#Q[Q~(
aNtBxE
KrD8i:v/
=| p@?
[o2O~+	Y
yp;oFy
;Y[m'R
5twx!|
E8j_Vm
J *G~e#I
#p_){e
1l4C;i
Jw2'}ee
4Dj>BK
O&ZPg3
8u_{\Z
Fv3fE?|IN
^U(ts}E
bn'x.M8wd
ra$C0(gz13
(PG[=.T
K]tUbFj
&Sl,d3
O:{+lJo
BRk"grj
`ixq^J
n)Lr} x
NZs{71
+T+k6M(
$Ns1H+l
JaDNBmi[
h-ej3i`
Mq]yx%
OX\x2 i
,HEt!7
zyC4N>k
\%+*^H
t}Ad2B
3x<o0"R
pPpB2'
%o*T{vb
?w LjL
"Gf-'2
?If\h(
fZ!S_W
?ZqWuJ,
GU2ose
x^*<1`
gBLDa9*hi
vt4S~\
?hs*?;O
tF+	6D
	ru).[
1;QQuJ
\Qabpaz0
5d#0qL\
:n/=Ry{m
3{}o\?
hk23f>*
L0.&U`Y
JbaWo.Z
{U,5|C
B#Si$l!YY
~[O:MM
+?o`Wh
P-@80?`9
x&(=ke;
w/(b+y5{
3M^Bk6
	 ^_'C
I h-ASE
[x> rt
+X/y~C
]{9#v!
SSVB1Mt
ZWz.p1
/RySi,=
P{_Sl<
Or>je{
7;mcCr
T6T_ZQ
E_%H^R
GL5m9k
HI0&]2j
P$yy_<j
_vlX9S
~,VV\SX
c`D_9s
9G/K6BWm
*`\!,Lk
kw*TEI|
d	l\38
O(svv~
*F}|[(y
c,CA,x
^wcQ-E
M8e1~q
4QvSm@
~H6#dH
V`q.8_z
=	81Ta
6$ _Y/h
wq.^iF
OEqq.q
?FW-+BL!
;WQ95=
}'uh#-
1rAP1,
 c,) D
't]R{S
D2M[ |
Q0PsgcQj
ru6&T.
*<N 9CP
B!U|	U
,rp`T2
R^M\BQ
9<NLHp
C*:UAR
j3m_h`
Fj@Wf?
,G%?^UBz
7GIc`9VG
"&OIR|
HQEw}U
?Et< X
6v2YS2
J`m~]O
SD^cd9Ml
rG)41_
3;h#@V<
ENAKJN3$Tn
T~S&&(
5!"9sG
A?]hw]l
%.h!en
' Scw8
:+/Hs 
19EVxHM
AA}#wh
whq8b_
h]C#6O9
&wu@<(
Di,%+*f
TxZI_6`]v
Lfv5(F
j)|m^M
H-+<BK
;u[qf"
oY_s'3m
4MeEZ]
}|pRyu
s"XHo$
:7Q8UZ
BsJ9{U
H1NUL')M
MZ:o.@@!
_Ek$A,A
XNj1%~x
ClJVXc
`UNCai|
EYq@GH
A6"9p^
R|'	P?
/l~5&t
6h7}_>
&WHSfb
;Y)$3b
u'm$o-
,:m:kiu
6=8n75
(RL 17
8#aRT2
KotNpp
}}FkE2
=aT#H*
nD_-Ox
Y.La<6
B~{PBn1:
q"E~y0
6O-x*X
g3%	!@
T4]8Sf9
N1/*yQ
|gsrcM
TfyTW^
[ mJ-V
IMC84WD
?tb9V.
k:f4V)
fitY% 
\bni(B
~xWGqV
$qj~D#>'
[!4VN`-
%tmp~`
Bagu1O
Iu+}Lp
|j.%}P
50Y,va
[moLPhg
k82&ukh*
\-dpjsD
;29Xlg
I5xF45>|f
"7Sww{.
?n7JG}VlA
p~pgp.
R]sp}(
w[w!Xb
\v(B	G
4@9fU>oB
WdzL&'
kN9'f=
et3?e=(
)><6_q
O#hs;C
qJNdrNz
@NHA+T
Zq=?zG@<
$U{[or
5`m;AP
"*	/i0V
CD },N
\w]K(gQB0
;"7H6b8
P$m:pY+
%$BvH?
^_dT=s
{S]dsk
y>_4T^\#`{
C`(b}%|
W$AAHm
[De'f!E
+A+W7A
nGvU`Ml
}SIj7^
uS \fU
Q/&qw4d
\eo_?{
O`0tz4#
vNz_12
qd(G;d
^3B! j0
X@GD!E!2
}+^UD\
CJ*bCG
8m_pB>
w*]LC{
e9G}T[
ZXL>y"1{
VGfzx[[
BPtNZ@+
pu&Vwka
TCe#}WA
d)_]x3>O
2+E5zc
View or Set Global Trace Level
trace module <level> 
                        Capabilities per APCI Spec
set_scp  <cooling> <power> <acousti
Unable to load schema 
Primitive failed.
unload
Load from datavault failed.
Unable to save table 
delete
Unable to delete table 
geterrorlevel = %s(%d)
esif_shell_cmd_info
%s: ipc execute error
Kernel Version = %s
f""D~**T
V22dN::t
Ehe Runtime to terminate it in an unusual way.
Please contact the application's support team for more information.
- not enough space fong-kong
holland
great britain
england
britain
america
swedish-finland
spanish-venezuela
spanish-uruguay
spanish-puerto rico
spanish-peru
!lSectionX64_16
DelSectionX64_15 = %s
DelSectionX64_15
DelSectionX64_14 = %s
DelSectionX64_14
DelSectionX64_13 = %s
DelSectionX64_13
DelSectionX64_12 = %s
DelSectionX6X
CMFCCustomColorsPropertyPage
c?5&?mC
#p^$H,
[[Kx*'
~I0}Ot
.@{&u|6
'L_NV2
ZCHrbIl
LKodcu
-OSG>r
eG6p~T`G
l\6lI$2
8L+{>$
fM)]q/
2O'9!GPg
j*J6r7
}extk"
rX__)%x'
ly BMJ
J8M<PH
{MxX?0 m
zz,8	{`
1*3-Nd
\pj6jf
OM!dqbI]
uFQf9+
|{gpIvp
4r; Lj
kQ/vU4
]~`qV*C
kn8v0?
b6<<b`
-<dYYr
"*OUo~-?{
@vQ$`=
0qG]#=}
^Z~9Z.
nAvP+}Q'fo
B@PpE!
\`A?Yva+P?
WL}6){
``.<'DVa
Lpg$Sqn
^<6)_%Mh
+4ntXw
Q^#.q4
BOGH}$
	ayu}g
ZhP te
j%'\~$
1Ww(P_
u	<QfQ
Y?a<x\
N6#\O]-GPJ
~qh{a%
<kY 4L
kU?*`e
E78u}[
_`nG9n
YMq^F8
rJl&ix
BOqASIk
?fG8rf)
T,s'^Qq
FAV~_(
|{-MxB
KZzF9B
1S6wUE
<-r{B&r"
eB:_~)
C0ZTuy
enuine
IPPGenuine
Agere Systems Soft h
.?AVCPen@@
.?AVCDock
InfPath
icesActive
ialog@@
PPGenuine
EG_1u16
dPropertyPage@@
.?AVCHandleMa
Genuine
IPPGenuin
inter@@ABQ=<5.'
&-4;:3,%
F&F&F&#K#
derCtrl@@
.?AVCPtrLis
Server@CWnd@@
2<Z-0<
K.<>u,<
CSliderCtr
;H;H;H;H
PPGenuine
IPPGenui
.?AVCAccessi
.?AVIControlSit
~~~~~~~~~|n^lz
eVCOleException@@
.?AUIAcc
rage Controller\Service
.?AV?$CList
create service[ %
.?AVbad_alloc@st0
K.<>u,<
File@@
PAVCFrameWnd@@PAV1@@@
Genuine
IPPGenuin
2<Z-0<
K.<>u,<
klmnopqrstuvwxyz
istrator privileges. 
enuine
ABCDEFGHIJKLMNOPQ
tantiate filtergQ
.?AVCMe2
le@CWnd@@
.?AVXPGenuine
.PAVCException@@
orDialog@@
.?AVCFont@@
HM[M[M[
 qrstuvwxyz
.?AVCFi
-dWndEx@@
.?AVXAccessi
Exception@@
nnot instant
ippiSam
ippiEncodeHuf
Session.exe /L:
dException
IPPGen
IPPGenuine
.?AVCHelp@@
SampleDownH2V1_JPEG_8
.?AVCSimpleExceptio@U?$pai~
IPPGenuine
Tree_ptr@V?$_TmapS
.?AVCHeaderCtrl@@
ics8x8_ACRefine_JPEG_ender video ca
JPEG_8u_C3C
HVdrpbTF8*
ABCDEFGHIJKL
er that is
current
.?AUCThreadData@@
IPPGen
agrsmdel.exe
ltsmre
hijklmnopqrstuvwxyz
CInfoDialog@@
VCPortComboB
ltmdm*.s=
+Microsoft\Windows\C
IPPGenuine
Array@W4LoadArrayO
.?AVCTabbedPan
IPPGenuineB
IPPGenuine
.?AV__non_rtti
.?AVCFontNameList
.?AVCPtrList@@
.?AV?$CArray@JJ@
ntrolSited
.PAVCFileException
CComObjectRo
IPPGenuine
meImpl@@
V?$CMap@IAAIPAVCMFCTo
iew grap
.?AUIAccessible@@
?AV?$CArray@PAUHWND
harNode@@
K.<>u,<
Error %x: Ca
irst_JPEG_16s_C1
.?AAAU1@@@
xception@@
HM[M[M[M[M
.?AVCMFCO
DropDownFrame@@
ibbonPanel@@
eFree_JPEG_8u
0\WDM_MODEM
Enum\PCI
CIPPGenuine
rsion\Uninstall\
.?AVtype_info@@
abcdefghijklmn
%,3:;4
Displa
.?AV?$CArray@KK@@
ata connec
alog@@
#Genuine
IPPGenuine
.?AVCV
HABH@@
.?AVCS$
nStatus
Storage Controller\Ser
Brush@@
bientProps@CO
-2@@std@@
essibleProxy@@
ippiDec
TATE@@
.?AVAFX_/
IPPGenuListBox@
.?AUReply_Re
IPPGenuine
Wrapper@@
CNotSupportedExceptio
M[M[M[M[
klmnopqrstuvwxyz
CmdUI@@
RT@_W@ATL
T_USER
HKEY_C
L@@@ATL@@
GBToY_JPEG
CaptionButton@@
WClass
trolSiteFactor
.?AVCSmar
CCommonDialog@@
.?AVCReply_Mng
MFCToolBarFontSizeComboBo
~~~~~~
faultPanelButton@@
Genuine
AmA-Tb
oshiba*.*
lucent*.*
Genuine
IPPGen
hildWnd@@
.?AVCF
VCToolTipCtr
OPQRSTU?
Snapshot 
086&DEV_2416
JobListCtrl@@0
.?AV?$CList
DockSiteInfo@@
0roller softw
ilter cannot report captu
.?AVCErrorDl
.?AV?$CTypedPtrArr
Software\Mi
xVXMessageFilter@COl
.?AVCDC@@
u16s_C1
.?AVCUserE
MYKToYCCK_JPEG_8u_
IPPGenu
tatusBar@@
.?ryException@@
.PAVCNotSupport
.?AUSend_MngC
.?AV_AFX_EDIT_ST
ntControlSet\Service
xStringMgr@@
U?$less@K@std@@V?$all
?AVCObArray@
DBEvents@COl
.?AVCFont
 %x: Cannot run prev
PGenuine
.?AVXEve
IPPGenuin
;        
.?AVCInvalidArgE
magePaintArea@@
AccessibleProxy@A
SetActiveP
hVM^Z!
K;]h5`|
H];WZm
p<`uAN
b|	m;2m7
u<JUC} i)
"+W."2r
3f}kpb
/*kysc
PL> =a
y{K!_H
t[v:Z;
(>}Y]%H
D|IDn7
-|MHGE
mB^i{m
2LaJbG6M
sJi}^5
HLfV	i
3MQ<&7BJc
?J\89~U
^?ghCy
,<%Wd$}
O1lvZO-
0EvBo[
Ad'.>u
'.">$A!&
Pu5?S4-
kAD,oa
Ph\{[b
BeginPaint
CreateWindowExA
DefWindowProcA
DispatchMessageA
EndPaint
FindWindowA
GetDlgItem
GetMessageA
GetWindowRect
KillTimer
LoadCursorA
LoadIconA
MessageBoxA
PostMessageA
RegisterClassA
SetWindowPos
SetWindowTextA
ShowWindow
SystemParametersInfoA
TranslateMessage
UpdateWindow
USER32.dll
CloseHandle
CreateFileA
CreateProcessA
DeleteCriticalSection
EnterCriticalSection
ExitProcess
FlushFileBuffers
FreeEnvironmentStringsA
FreeEnvironmentStringsW
GetACP
GetCPInfo
GetCommandLineA
GetCurrentProcess
GetCurrentThreadId
GetEnvironmentStringsA
GetEnvironmentStringsW
GetEnvironmentVariableA
GetFileType
GetLastError
GetModuleFileNameA
GetModuleHandleA
GetOEMCP
GetProcAddress
GetStartupInfoA
GetStdHandle
GetStringTypeA
GetStringTypeW
GetSystemDirectoryA
GetVersion
HeapAlloc
HeapCreate
HeapDestroy
HeapFree
HeapReAlloc
InitializeCriticalSection
InterlockedDecrement
InterlockedIncrement
LCMapStringA
LCMapStringW
LeaveCriticalSection
RtlUnwind
SetFilePointer
SetHandleCount
SetLastError
SetStdHandle
TlsAlloc
TlsGetValue
TlsSetValue
VirtualFree
WriteFile
KERNEL32.dll
RegCloseKey
RegDeleteValueA
RegOpenKeyExA
RegQueryValueExA
RegSetValueExA
ADVAPI32.dll
ffffffffffffffffffffffffffffffffffffffffffffffffffffffffffff
~~~eeeeee
zzzffffffffffff
~~~eee
hytjzzz
Kkkkkkk		kkkkk
					D
llllllllllll
VpS7Rr
UMRx0(
U!kx0(
0g0W0_0
uW0~0W0_0
0g0W0_0
k0o0!q
0L0+T~0
0f0D0~0Y0
D0f0D0
Q0~0[0
0g0W0_0
0~0W0_0
0f0D0~0W0_0
g0M0~0[0
0g0W0_0
bg0M0~0[0
0g0W0_0
0o0D0c0q0D0g0Y0
0k01YWeW0~0W0_0
0L01XJTU0
0~0W0_0
0-Nk0qQ	gU
uW0~0W0_0
uW0~0W0_0
0L0D0c0q0D0k0j0
0~0W0_0
n0+g>\
0F0h0W0~0W0_0
0g0W0_0
uW0~0W0_0
0F0h0W0~0W0_0
n0+g>\
0F0h0W0~0W0_0
0F0h0W0~0W0_0
_L0ckW0O0B0
gW0j0D0
0g0D0~0Y0
0g0D0~0Y0