Static | ZeroBOX

PE Compile Time

2020-08-20 19:13:43

PE Imphash

b0eb8cb1ecf999d74c83af780efdac4b

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x00026ab1 0x00026c00 6.99454218518
.data 0x00028000 0x03963bc8 0x00001c00 2.7021810597
.win 0x0398c000 0x00001001 0x00000400 0.0
.new 0x0398e000 0x00003312 0x00003400 5.6020852683
.rsrc 0x03992000 0x00002f30 0x00003000 4.79430309768
.reloc 0x03995000 0x00006708 0x00006800 1.7956326919

Resources

Name Offset Size Language Sub-language File type
RT_CURSOR 0x03994308 0x000008a8 LANG_NEUTRAL SUBLANG_NEUTRAL dBase III DBT, version number 0, next free block index 40, 1st item "\251\317"
RT_CURSOR 0x03994308 0x000008a8 LANG_NEUTRAL SUBLANG_NEUTRAL dBase III DBT, version number 0, next free block index 40, 1st item "\251\317"
RT_CURSOR 0x03994308 0x000008a8 LANG_NEUTRAL SUBLANG_NEUTRAL dBase III DBT, version number 0, next free block index 40, 1st item "\251\317"
RT_ICON 0x03992250 0x000010a8 LANG_SPANISH SUBLANG_SPANISH_CHILE data
RT_STRING 0x03994d98 0x00000192 LANG_SPANISH SUBLANG_SPANISH_CHILE data
RT_GROUP_CURSOR 0x03994bb0 0x00000022 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_GROUP_CURSOR 0x03994bb0 0x00000022 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_GROUP_ICON 0x039932f8 0x00000014 LANG_SPANISH SUBLANG_SPANISH_CHILE data
RT_VERSION 0x03994bd8 0x000001c0 LANG_NEUTRAL SUBLANG_NEUTRAL data

Imports

Library KERNEL32.dll:
0x3d8e010 InterlockedIncrement
0x3d8e018 GetCurrentProcess
0x3d8e01c GetModuleHandleExW
0x3d8e020 CancelWaitableTimer
0x3d8e024 GetModuleHandleW
0x3d8e028 SetFileTime
0x3d8e030 GlobalAlloc
0x3d8e034 GlobalFindAtomA
0x3d8e038 GetLocaleInfoW
0x3d8e040 GetFileAttributesA
0x3d8e044 GetConsoleAliasW
0x3d8e048 TerminateProcess
0x3d8e04c FileTimeToSystemTime
0x3d8e058 LoadResource
0x3d8e05c DisconnectNamedPipe
0x3d8e060 GetConsoleOutputCP
0x3d8e064 GetLastError
0x3d8e068 GetProcAddress
0x3d8e06c SetFileAttributesA
0x3d8e070 OpenWaitableTimerA
0x3d8e074 GetAtomNameA
0x3d8e07c GetTapeParameters
0x3d8e080 SetConsoleCursorInfo
0x3d8e084 GlobalUnWire
0x3d8e088 lstrcatW
0x3d8e08c VirtualProtect
0x3d8e090 FindAtomW
0x3d8e094 LocalFree
0x3d8e098 lstrcpyW
0x3d8e09c CompareStringW
0x3d8e0a0 CompareStringA
0x3d8e0a4 FindResourceW
0x3d8e0a8 FindResourceExW
0x3d8e0ac GlobalUnlock
0x3d8e0b4 GetCommandLineA
0x3d8e0b8 GetStartupInfoA
0x3d8e0c4 IsDebuggerPresent
0x3d8e0c8 HeapAlloc
0x3d8e0cc EnterCriticalSection
0x3d8e0d0 LeaveCriticalSection
0x3d8e0d4 Sleep
0x3d8e0d8 ExitProcess
0x3d8e0dc WriteFile
0x3d8e0e0 GetStdHandle
0x3d8e0e4 GetModuleFileNameA
0x3d8e0ec GetEnvironmentStrings
0x3d8e0f4 WideCharToMultiByte
0x3d8e0fc SetHandleCount
0x3d8e100 GetFileType
0x3d8e104 DeleteCriticalSection
0x3d8e108 TlsGetValue
0x3d8e10c TlsAlloc
0x3d8e110 TlsSetValue
0x3d8e114 TlsFree
0x3d8e118 SetLastError
0x3d8e11c GetCurrentThreadId
0x3d8e120 InterlockedDecrement
0x3d8e124 GetCurrentThread
0x3d8e128 HeapCreate
0x3d8e12c HeapDestroy
0x3d8e130 VirtualFree
0x3d8e134 HeapFree
0x3d8e13c GetTickCount
0x3d8e140 GetCurrentProcessId
0x3d8e148 SetFilePointer
0x3d8e14c GetConsoleCP
0x3d8e150 GetConsoleMode
0x3d8e154 GetCPInfo
0x3d8e158 GetACP
0x3d8e15c GetOEMCP
0x3d8e160 IsValidCodePage
0x3d8e164 FatalAppExitA
0x3d8e168 VirtualAlloc
0x3d8e16c HeapReAlloc
0x3d8e170 RtlUnwind
0x3d8e174 MultiByteToWideChar
0x3d8e178 RaiseException
0x3d8e17c SetConsoleCtrlHandler
0x3d8e180 FreeLibrary
0x3d8e184 InterlockedExchange
0x3d8e188 LoadLibraryA
0x3d8e190 SetStdHandle
0x3d8e194 WriteConsoleA
0x3d8e198 WriteConsoleW
0x3d8e19c LCMapStringA
0x3d8e1a0 LCMapStringW
0x3d8e1a4 GetStringTypeA
0x3d8e1a8 GetStringTypeW
0x3d8e1ac GetTimeFormatA
0x3d8e1b0 GetDateFormatA
0x3d8e1b4 GetUserDefaultLCID
0x3d8e1b8 GetLocaleInfoA
0x3d8e1bc EnumSystemLocalesA
0x3d8e1c0 IsValidLocale
0x3d8e1c4 FlushFileBuffers
0x3d8e1c8 ReadFile
0x3d8e1cc GetModuleHandleA
0x3d8e1d0 HeapSize
0x3d8e1d4 CreateFileA
0x3d8e1d8 CloseHandle
Library USER32.dll:
0x3d8e1e4 GetMonitorInfoA
Library ADVAPI32.dll:
0x3d8e008 RegReplaceKeyW

Exports

Ordinal Address Name
1 0x425df0 Fury
2 0x425de0 Probka
!This program cannot be run in DOS mode.
`.data
@.rsrc
@.reloc
HHtXHHt
>If90t
^F<-uB
<xtX<XtT
jF<-uH
<xtV<XtR
tNIt?It0It
>=Yt1j
j@j ^V
tehJk@
0A@@Ju
^SSSSS
j"^SSSSS
tM<it-<ot)<ut%<xt!<Xt
<dty<itu<otq<utm<xti<Xte
HIf98t
HHtYHHt
URPQQh
_VVVVV
_VVVVV
0SSSSS
0SSSSS
0SSSSS
t"SS9]
C PjPV
C$PjQV
C*PjTV
C+PjUV
C,PjVV
C-PjWV
C.PjRV
C/PjSV
.;1s(N
HHt4HHt
Ht\Ht,
teHtFHt&Hu
ty<%tA
PPPPPPPP
PPPPPPPP
;t$,v-
UQPXY]Y[
_VVVVV
^WWWWW
u,VVWV
t VV9u
t+WWVPV
^SSSSS
^SSSSS
>:u8FV
VVVVVQRSSj
^SSSSS
^SSSSS
0SSSSS
0SSSSS
_VVVVV
^SSSSS
^WWWWW
0SSSSS
8VVVVV
<+t(<-t$:
+t HHt
vddrZl*
PY$Gjy
Fv*$cz
=>j6?,,x!:
1DUP0W7
xcG{2
sPXF/b
*ma%T
=)DP|t{
FpvrlY
&/Q6zt
o;GzNS
h<uA>
SRp:Zr
('>P?4
2X`Zlh
FOaUVL(
Ny1J3
11M{Nm
lG#o\'S
X5_v!_Q
(='Zg5!
3c[c>jb5
]2Cqh^V
N#sk(/
ku]D:N?
5Rt5aa
OHH&kgr
YlE!z5
a}9rCzQ
AUg"_p!v
fuj_`l_
Z<,Jj'
Z,VkLY
)auNUR
[cpU<q
O4jGekp
^'3Qee+
75aRD#r
M6Qi:D
aD?F[T
%ue!7Q
+dK_+QF
VVVVVV
_^[u"j
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
(null)
`h````
xpxxxx
CorExitProcess
runtime error
TLOSS error
SING error
DOMAIN error
An application has made an attempt to load the C runtime library incorrectly.
Please contact the application's support team for more information.
- Attempt to use MSIL code from this assembly during native code initialization
This indicates a bug in your application. It is most likely the result of calling an MSIL-compiled (/clr) function from a native constructor or from DllMain.
- not enough space for locale information
- Attempt to initialize the CRT more than once.
This indicates a bug in your application.
- CRT not initialized
- unable to initialize heap
- not enough space for lowio initialization
- not enough space for stdio initialization
- pure virtual function call
- not enough space for _onexit/atexit table
- unable to open console device
- unexpected heap error
- unexpected multithread lock error
- not enough space for thread data
This application has requested the Runtime to terminate it in an unusual way.
Please contact the application's support team for more information.
- not enough space for environment
- not enough space for arguments
- floating point support not loaded
Microsoft Visual C++ Runtime Library
<program name unknown>
Runtime Error!
Program:
EncodePointer
DecodePointer
FlsFree
FlsSetValue
FlsGetValue
FlsAlloc
LC_TIME
LC_NUMERIC
LC_MONETARY
LC_CTYPE
LC_COLLATE
LC_ALL
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
`h`hhh
xppwpp
_nextafter
_hypot
SystemFunction036
ADVAPI32.DLL
GetProcessWindowStation
GetUserObjectInformationA
GetLastActivePopup
GetActiveWindow
MessageBoxA
USER32.DLL
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
HH:mm:ss
dddd, MMMM dd, yyyy
MM/dd/yy
December
November
October
September
August
February
January
Saturday
Friday
Thursday
Wednesday
Tuesday
Monday
Sunday
united-states
united-kingdom
trinidad & tobago
south-korea
south-africa
south korea
south africa
slovak
puerto-rico
pr-china
pr china
new-zealand
hong-kong
holland
great britain
england
britain
america
swedish-finland
spanish-venezuela
spanish-uruguay
spanish-puerto rico
spanish-peru
spanish-paraguay
spanish-panama
spanish-nicaragua
spanish-modern
spanish-mexican
spanish-honduras
spanish-guatemala
spanish-el salvador
spanish-ecuador
spanish-dominican republic
spanish-costa rica
spanish-colombia
spanish-chile
spanish-bolivia
spanish-argentina
portuguese-brazilian
norwegian-nynorsk
norwegian-bokmal
norwegian
italian-swiss
irish-english
german-swiss
german-luxembourg
german-lichtenstein
german-austrian
french-swiss
french-luxembourg
french-canadian
french-belgian
english-usa
english-us
english-uk
english-trinidad y tobago
english-south africa
english-nz
english-jamaica
english-ire
english-caribbean
english-can
english-belize
english-aus
english-american
dutch-belgian
chinese-traditional
chinese-singapore
chinese-simplified
chinese-hongkong
chinese
canadian
belgian
australian
american-english
american english
american
Norwegian-Nynorsk
GAIsProcessorFeaturePresent
KERNEL32
CONIN$
CONOUT$
SunMonTueWedThuFriSat
JanFebMarAprMayJunJulAugSepOctNovDec
1#QNAN
1#SNAN
bad allocation
VirtualProtect
zitomuridapelagajepegolik pegehegovamasetotid %s %d %f
WriteConsoleOutputCharacterW
FindResourceExW
FindResourceW
LoadResource
InterlockedIncrement
SetConsoleTextAttribute
GetCurrentProcess
GetModuleHandleExW
CancelWaitableTimer
GetModuleHandleW
SetFileTime
TzSpecificLocalTimeToSystemTime
GlobalAlloc
GlobalFindAtomA
GetLocaleInfoW
SetSystemTimeAdjustment
GetFileAttributesA
GetConsoleAliasW
TerminateProcess
FileTimeToSystemTime
GetCompressedFileSizeA
GetTimeZoneInformation
GlobalUnlock
DisconnectNamedPipe
GetConsoleOutputCP
GetLastError
GetProcAddress
SetFileAttributesA
OpenWaitableTimerA
GetAtomNameA
AddVectoredExceptionHandler
GetTapeParameters
SetConsoleCursorInfo
GlobalUnWire
lstrcatW
VirtualProtect
FindAtomW
LocalFree
lstrcpyW
KERNEL32.dll
GetMonitorInfoA
USER32.dll
EnumDependentServicesW
ObjectPrivilegeAuditAlarmA
RegReplaceKeyW
ADVAPI32.dll
GetCommandLineA
GetStartupInfoA
UnhandledExceptionFilter
SetUnhandledExceptionFilter
IsDebuggerPresent
HeapAlloc
EnterCriticalSection
LeaveCriticalSection
ExitProcess
WriteFile
GetStdHandle
GetModuleFileNameA
FreeEnvironmentStringsA
GetEnvironmentStrings
FreeEnvironmentStringsW
WideCharToMultiByte
GetEnvironmentStringsW
SetHandleCount
GetFileType
DeleteCriticalSection
TlsGetValue
TlsAlloc
TlsSetValue
TlsFree
SetLastError
GetCurrentThreadId
InterlockedDecrement
GetCurrentThread
HeapCreate
HeapDestroy
VirtualFree
HeapFree
QueryPerformanceCounter
GetTickCount
GetCurrentProcessId
GetSystemTimeAsFileTime
SetFilePointer
GetConsoleCP
GetConsoleMode
GetCPInfo
GetACP
GetOEMCP
IsValidCodePage
FatalAppExitA
VirtualAlloc
HeapReAlloc
RtlUnwind
MultiByteToWideChar
RaiseException
SetConsoleCtrlHandler
FreeLibrary
InterlockedExchange
LoadLibraryA
InitializeCriticalSectionAndSpinCount
SetStdHandle
WriteConsoleA
WriteConsoleW
LCMapStringA
LCMapStringW
GetStringTypeA
GetStringTypeW
GetTimeFormatA
GetDateFormatA
GetUserDefaultLCID
GetLocaleInfoA
EnumSystemLocalesA
IsValidLocale
FlushFileBuffers
ReadFile
GetModuleHandleA
HeapSize
CreateFileA
CloseHandle
CompareStringA
CompareStringW
SetEnvironmentVariableA
rujez.exe
Probka
iiiiii
iiiiii
iiiiiiiiiiii
iiiiiiiiii
iiiiii
iiiiiiiii
iiiiiiiiiiiii
iiiiiiii

0 0&0,02080>0D0J0P0V0\0b0h0n0t0z0
5!5*525H5r5y5
6]6b6l6
6E7K7Q7W7]7c7j7q7x7
82898C9J9
262[2>4:6>6B6F6J6N6R6V6c6u6G7Q7^7y7
8:8]8p89:V:r:
?)?6?B?R?Y?h?t?
0=0L0U0y0
0R1,242L2d2
666?6H6U6{6
63777;7?7C7G7K7O7S7W7[7_7c7i7t7
9'9.9P9
:':/:B:M:R:b:l:s:~:
:;;H;r;w;
<"=+=2=;={=
>/>E>X>y>
T0a0j0
0N1Y1c1t1
1A3R3Z3`3e3k3
4!4.454l4
5'5;5\5b5
536=6e6~6
7S7Y7}7
848:8E8Q8f8m8
9,929=9G9M9Y9h9n9
::B:W:}:
=='=-=4=:=A=G=O=V=[=c=l=x=}=
>%>E>K>g>
?"?)?7?Z?g?s?{?
=8=C=M=f=p=
90E0X0j0
141]1n1z1
3F4]4n4
4/5;5D5M5Y5e5q5}5
8!9'9D9I9
5#5,585o5x5
6$6=6k7y7
9*:O:/<N>R>V>Z>^>b>f>j>u>|>
?!?/?B?U?y?
0.0>0S0i0
1R1Z1s1y1~1
40454D4M4Z4e4w4
5"50575<5E5R5X5r5
::%:+:0:9:S:Y:e:
1.1;1@1N1)2L2W2z2
4H5M5_5}5
5*6_6x6
7 7$7n7t7x7|7
8 8A8k8
8h9::P:
172P2y2~2
3!3'3=3C3
5)5S5k5s5
6Q7Z7`7
798?8i8p8
9Z95:m:
;;/;4;L;R;a;g;v;|;
1/1@1e1
3=3K3T3
4=4o4w4
6 6-6K6U6^6i6~6
6h788J8W8c8m8u8
8w9':J:
;!<+<C<J<T<\<i<p<
7-7g7i9
<`=r=|=
>$>B>J>
6+7>7m7|7H=
="=&=*=.=2=6=:=>=B=F=J=N=R=V=
Z3^3b3f3j3n3r3v3z3~3
4?5_5u5{5
7-838?8
/0H0O0W0\0`0d0
0>1D1H1L1P1
2;2m2t2x2|2
6$6l8x8
;7;B;e;)<6<K<]<f<
=@=[=e=l=
?'?]?z?
414X4i4n4t4
7'8/898F8N8T8Z8
99*929:9C9L9Z9h9
9#:0:>:K:^:k:
131p1z1
6@8B:J:[:l:
0"151+:!;);
e0m0 1
2C3I3Y3
:y;I>`>
:":(:.:4:::@:F:L:R:X:^:d:j:p:v:|:
;$;*;0;6;<;B;H;
2$242;2
>2><>Q>X>l>q>w>}>
?"?)?<?C?J?P?b?n?
1'1,161<1B1R1X1b1h1q1w1
2"2(222>2L2R2Y2
3$3/343J3P3r3
9:I:N:T:s:
4$4,444<4D4L4T4\4d4l4t4|4
; ;$;(;,;0;8;<;@;D;H;L;P;T;X;\;`;d;
=$=,=4=<=D=L=T=\=d=l=t=|=
> >$>(>,>0>4>8><>@>D>H>L>P>T>X>\>`>d>h>l>p>t>x>|>
; ;$;(;,;0;4;4<8<<<
< <(<0<8<@<H<P<X<`<h<p<x<
= =(=0=8=@=H=P=X=`=h=p=x=
> >(>0>8>@>H>P>
T0X0`0d0h0l0
1 1<1@1`1l1
202P2\2x2
383X3d3
4 4<4@4`4
5 5,5H5h5
6(6H6h6
7(7H7h7
B(null)
mscoree.dll
KERNEL32.DLL
((((( H
h(((( H
H
kernel32.dll
/ P6pL
,/KPip
/-P?pR
/ P6pL
,/KPip
/-P?pR
VS_VERSION_INFO
StringFileInfo
040904E4
FileVersions
7.0.2.54
ProductVersions
7.0.21.21
InternalNames
galimatimod
LegalCopyrights
Wsekde
VarFileInfo
Translation
Bine wanule bixacov@Japizox jugosofaloco vacoveti xis lumikinekudota silevetumijoxadfNaroyipaciva zon yogaco sumojodone tetiyefinon wizewurojenuwev hezan wexopuw kidanijesarirev muxeyifaf
Antivirus Signature
Bkav W32.AIDetect.malware1
Elastic malicious (high confidence)
MicroWorld-eScan Trojan.GenericKD.36734062
FireEye Generic.mg.9487de43f88f7e89
CAT-QuickHeal Clean
McAfee RDN/Generic PWS.y
Cylance Unsafe
Zillya Clean
AegisLab Trojan.Win32.SpyEyes.l!c
Sangfor Trojan.Win32.Save.a
K7AntiVirus Clean
BitDefender Trojan.GenericKD.36734062
K7GW Clean
Cybereason malicious.379c3a
Baidu Clean
Cyren W32/Kryptik.DVL.gen!Eldorado
Symantec ML.Attribute.HighConfidence
ESET-NOD32 a variant of Win32/Kryptik.HKLN
APEX Malicious
Avast Win32:PWSX-gen [Trj]
ClamAV Clean
Kaspersky HEUR:Trojan-Spy.Win32.SpyEyes.gen
Alibaba TrojanSpy:Win32/Kryptik.5122611a
NANO-Antivirus Clean
ViRobot Clean
Rising Trojan.Kryptik!1.D4B0 (CLOUD)
Ad-Aware Trojan.GenericKD.36734062
Sophos Mal/Generic-S
Comodo .UnclassifiedMalware@0
F-Secure Clean
DrWeb Trojan.Siggen13.9356
VIPRE Clean
TrendMicro Clean
McAfee-GW-Edition BehavesLike.Win32.Generic.dh
CMC Clean
Emsisoft Trojan.GenericKD.36734062 (B)
SentinelOne Static AI - Suspicious PE
GData Trojan.GenericKD.36734062
Jiangmin Clean
Webroot Clean
Avira TR/Crypt.Agent.xecmz
MAX malware (ai score=100)
Kingsoft Win32.Troj.Undef.(kcloud)
Gridinsoft Trojan.Win32.Agent.oa
Arcabit Clean
SUPERAntiSpyware Trojan.Agent/Gen-Kryptik
ZoneAlarm Clean
Microsoft Trojan:Win32/Predator!ml
Cynet Malicious (score: 100)
AhnLab-V3 Trojan/Win.MalPE.R416466
Acronis suspicious
BitDefenderTheta Gen:NN.ZexaF.34678.nyW@ayyy4tJ
ALYac Gen:Variant.Graftor.941749
TACHYON Clean
VBA32 Clean
Malwarebytes Trojan.MalPack.GS
Panda Trj/GdSda.A
Zoner Clean
TrendMicro-HouseCall Clean
Tencent Clean
Yandex Clean
Ikarus Trojan.Win32.Crypt
MaxSecure Clean
Fortinet W32/SpyEyes.HKLN!tr
AVG Win32:PWSX-gen [Trj]
Paloalto generic.ml
CrowdStrike win/malicious_confidence_90% (W)
Qihoo-360 Win32/TrojanPSW.SpyEye.HwoCqx8A
No IRMA results available.