Static | ZeroBOX

PE Compile Time

2020-08-25 07:22:18

PDB Path

C:\rav.pdb\crypt_server\runtime\crypt\tmp_1336068777\bin\kejocuno.pdbpM­8dþÿÿÿÔÿÿÿþÿÿÿF4@

PE Imphash

7f6eb35ea13978194d25e74e65ad1031

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x0001cd2c 0x0001ce00 6.70526641836
.rdata 0x0001e000 0x00003328 0x00003400 5.51154346929
.data 0x00022000 0x0277f50c 0x00011600 7.48794462139
.rsrc 0x027a2000 0x00004118 0x00004200 6.27565442198

Resources

Name Offset Size Language Sub-language File type
XUSAJOKIY 0x027a4860 0x0000127b LANG_SORBIAN SUBLANG_DEFAULT ASCII text, with very long lines, with no line terminators
RT_CURSOR 0x027a5b68 0x00000134 LANG_SORBIAN SUBLANG_DEFAULT data
RT_ICON 0x027a22a0 0x000025a8 LANG_ICELANDIC SUBLANG_DEFAULT dBase III DBT, version number 0, next free block index 40, 1st item "\275\375\375\007\270\371\377\007\275\372\371"
RT_STRING 0x027a5ff0 0x00000124 LANG_SORBIAN SUBLANG_DEFAULT data
RT_STRING 0x027a5ff0 0x00000124 LANG_SORBIAN SUBLANG_DEFAULT data
RT_ACCELERATOR 0x027a5ae0 0x00000088 LANG_SORBIAN SUBLANG_DEFAULT data
RT_GROUP_CURSOR 0x027a5ca0 0x00000014 LANG_SORBIAN SUBLANG_DEFAULT Lotus unknown worksheet or configuration, revision 0x1
RT_GROUP_ICON 0x027a4848 0x00000014 LANG_ICELANDIC SUBLANG_DEFAULT data
RT_VERSION 0x027a5cb8 0x00000144 LANG_SORBIAN SUBLANG_DEFAULT data

Imports

Library KERNEL32.dll:
0x41e000 CreateJobObjectA
0x41e008 WriteConsoleW
0x41e01c CreateMutexA
0x41e020 GetStdHandle
0x41e030 CreateNamedPipeW
0x41e034 CallNamedPipeA
0x41e038 EnumResourceNamesW
0x41e048 EnumTimeFormatsA
0x41e04c TlsGetValue
0x41e050 GetACP
0x41e054 WriteFile
0x41e058 DeactivateActCtx
0x41e05c ReleaseActCtx
0x41e060 AddRefActCtx
0x41e068 VerifyVersionInfoA
0x41e06c GetVersionExW
0x41e070 FreeLibrary
0x41e074 LoadLibraryExW
0x41e078 GetComputerNameW
0x41e07c CommConfigDialogW
0x41e080 VirtualProtect
0x41e084 lstrcpyA
0x41e088 LoadLibraryA
0x41e08c LocalAlloc
0x41e090 SetFilePointer
0x41e094 CancelWaitableTimer
0x41e09c VirtualFree
0x41e0a0 SetCommMask
0x41e0a4 HeapSize
0x41e0a8 RaiseException
0x41e0ac GetBinaryTypeA
0x41e0b0 GlobalSize
0x41e0b4 SetConsoleMode
0x41e0bc MoveFileW
0x41e0c8 WriteConsoleInputW
0x41e0cc OpenMutexW
0x41e0d0 GetThreadContext
0x41e0d4 AddAtomW
0x41e0dc SetSystemTime
0x41e0e0 GlobalAlloc
0x41e0e4 TerminateProcess
0x41e0e8 GetCommandLineW
0x41e0ec SetLocalTime
0x41e0f4 DisconnectNamedPipe
0x41e0f8 GetFileAttributesW
0x41e0fc GetLastError
0x41e100 lstrlenA
0x41e104 CompareStringW
0x41e108 CompareStringA
0x41e10c GetCommandLineA
0x41e110 GetStartupInfoA
0x41e114 HeapAlloc
0x41e11c GetCurrentProcess
0x41e128 IsDebuggerPresent
0x41e12c GetProcAddress
0x41e130 GetModuleHandleA
0x41e134 GetModuleHandleW
0x41e138 Sleep
0x41e13c ExitProcess
0x41e140 GetModuleFileNameA
0x41e150 WideCharToMultiByte
0x41e158 SetHandleCount
0x41e15c GetFileType
0x41e164 TlsAlloc
0x41e168 TlsSetValue
0x41e16c TlsFree
0x41e170 SetLastError
0x41e174 GetCurrentThreadId
0x41e17c GetCurrentThread
0x41e180 HeapCreate
0x41e184 HeapDestroy
0x41e188 HeapFree
0x41e190 GetTickCount
0x41e194 GetCurrentProcessId
0x41e198 FatalAppExitA
0x41e19c VirtualAlloc
0x41e1a0 HeapReAlloc
0x41e1a4 GetCPInfo
0x41e1a8 GetOEMCP
0x41e1ac IsValidCodePage
0x41e1b0 RtlUnwind
0x41e1b8 InterlockedExchange
0x41e1c0 GetConsoleCP
0x41e1c4 GetConsoleMode
0x41e1c8 FlushFileBuffers
0x41e1cc LCMapStringA
0x41e1d0 MultiByteToWideChar
0x41e1d4 LCMapStringW
0x41e1d8 GetStringTypeA
0x41e1dc GetStringTypeW
0x41e1e0 GetTimeFormatA
0x41e1e4 GetDateFormatA
0x41e1e8 GetUserDefaultLCID
0x41e1ec GetLocaleInfoA
0x41e1f0 EnumSystemLocalesA
0x41e1f4 IsValidLocale
0x41e1f8 GetLocaleInfoW
0x41e1fc CloseHandle
0x41e200 WriteConsoleA
0x41e204 GetConsoleOutputCP
0x41e208 SetStdHandle
0x41e210 CreateFileA
Library USER32.dll:
0x41e21c GetComboBoxInfo

!This program cannot be run in DOS mode.
`.rdata
@.data
HHtXHHt
>If90t
_VVVVV
^WWWWW
>=Yt1j
j@j ^V
0A@@Ju
to=h.C
^SSSSS
j"^SSSSS
URPQQh
HHtYHHt
tM<it-<ot)<ut%<xt!<Xt
<dty<itu<otq<utm<xti<Xte
HIf98t
0SSSSS
0SSSSS
_VVVVV
_VVVVV
_VVVVV
0SSSSS
0SSSSS
t"SS9]
C PjPV
C$PjQV
C*PjTV
C+PjUV
C,PjVV
C-PjWV
C.PjRV
C/PjSV
.;1s(N
HHt4HHt
Ht\Ht,
teHtFHt&Hu
ty<%tA
PPPPPPPP
PPPPPPPP
;t$,v-
UQPXY]Y[
<+t(<-t$:
+t HHt
u,VVWV
t VV9u
t+WWVPV
^SSSSS
^SSSSS
>:u8FV
VVVVVQRSSj
^SSSSS
^SSSSS
0SSSSS
^SSSSS
^WWWWW
0SSSSS
8VVVVV
bad allocation
kernel32.dll
WipduolBriclsk
(null)
`h````
xpxxxx
GAIsProcessorFeaturePresent
KERNEL32
CorExitProcess
runtime error
TLOSS error
SING error
DOMAIN error
An application has made an attempt to load the C runtime library incorrectly.
Please contact the application's support team for more information.
- Attempt to use MSIL code from this assembly during native code initialization
This indicates a bug in your application. It is most likely the result of calling an MSIL-compiled (/clr) function from a native constructor or from DllMain.
- not enough space for locale information
- Attempt to initialize the CRT more than once.
This indicates a bug in your application.
- CRT not initialized
- unable to initialize heap
- not enough space for lowio initialization
- not enough space for stdio initialization
- pure virtual function call
- not enough space for _onexit/atexit table
- unable to open console device
- unexpected heap error
- unexpected multithread lock error
- not enough space for thread data
This application has requested the Runtime to terminate it in an unusual way.
Please contact the application's support team for more information.
- not enough space for environment
- not enough space for arguments
- floating point support not loaded
Microsoft Visual C++ Runtime Library
<program name unknown>
Runtime Error!
Program:
EncodePointer
DecodePointer
FlsFree
FlsSetValue
FlsGetValue
FlsAlloc
LC_TIME
LC_NUMERIC
LC_MONETARY
LC_CTYPE
LC_COLLATE
LC_ALL
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
`h`hhh
xppwpp
SystemFunction036
ADVAPI32.DLL
GetProcessWindowStation
GetUserObjectInformationA
GetLastActivePopup
GetActiveWindow
MessageBoxA
USER32.DLL
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
HH:mm:ss
dddd, MMMM dd, yyyy
MM/dd/yy
December
November
October
September
August
February
January
Saturday
Friday
Thursday
Wednesday
Tuesday
Monday
Sunday
united-states
united-kingdom
trinidad & tobago
south-korea
south-africa
south korea
south africa
slovak
puerto-rico
pr-china
pr china
new-zealand
hong-kong
holland
great britain
england
britain
america
swedish-finland
spanish-venezuela
spanish-uruguay
spanish-puerto rico
spanish-peru
spanish-paraguay
spanish-panama
spanish-nicaragua
spanish-modern
spanish-mexican
spanish-honduras
spanish-guatemala
spanish-el salvador
spanish-ecuador
spanish-dominican republic
spanish-costa rica
spanish-colombia
spanish-chile
spanish-bolivia
spanish-argentina
portuguese-brazilian
norwegian-nynorsk
norwegian-bokmal
norwegian
italian-swiss
irish-english
german-swiss
german-luxembourg
german-lichtenstein
german-austrian
french-swiss
french-luxembourg
french-canadian
french-belgian
english-usa
english-us
english-uk
english-trinidad y tobago
english-south africa
english-nz
english-jamaica
english-ire
english-caribbean
english-can
english-belize
english-aus
english-american
dutch-belgian
chinese-traditional
chinese-singapore
chinese-simplified
chinese-hongkong
chinese
canadian
belgian
australian
american-english
american english
american
Norwegian-Nynorsk
1#QNAN
1#SNAN
SunMonTueWedThuFriSat
JanFebMarAprMayJunJulAugSepOctNovDec
CONIN$
CONOUT$
C:\rav.pdb
\crypt_server\runtime\crypt\tmp_1336068777\bin\kejocuno.pdb
CreateJobObjectA
SetProcessPriorityBoost
WriteConsoleW
GetVolumeInformationA
GetSystemPowerStatus
DeleteVolumeMountPointA
GetDefaultCommConfigW
CreateMutexA
GetStdHandle
InterlockedIncrement
GetSystemTimeAdjustment
FileTimeToSystemTime
CreateNamedPipeW
CallNamedPipeA
EnumResourceNamesW
BuildCommDCBAndTimeoutsA
LeaveCriticalSection
DebugSetProcessKillOnExit
EnumTimeFormatsA
TlsGetValue
GetACP
WriteFile
DeactivateActCtx
ReleaseActCtx
AddRefActCtx
SetHandleInformation
VerifyVersionInfoA
GetVersionExW
FreeLibrary
LoadLibraryExW
GetComputerNameW
CommConfigDialogW
VirtualProtect
lstrcpyA
LoadLibraryA
LocalAlloc
SetFilePointer
CancelWaitableTimer
GetCurrentDirectoryW
VirtualFree
SetCommMask
HeapSize
RaiseException
GetBinaryTypeA
GlobalSize
SetConsoleMode
GetConsoleCursorInfo
MoveFileW
SetTimeZoneInformation
TzSpecificLocalTimeToSystemTime
WriteConsoleInputW
OpenMutexW
GetThreadContext
AddAtomW
FindVolumeMountPointClose
SetSystemTime
GlobalAlloc
TerminateProcess
GetCommandLineW
SetLocalTime
GetSystemTimeAsFileTime
DisconnectNamedPipe
GetFileAttributesW
GetLastError
lstrlenA
KERNEL32.dll
GetComboBoxInfo
USER32.dll
GetCommandLineA
GetStartupInfoA
HeapAlloc
EnterCriticalSection
GetCurrentProcess
UnhandledExceptionFilter
SetUnhandledExceptionFilter
IsDebuggerPresent
GetProcAddress
GetModuleHandleA
GetModuleHandleW
ExitProcess
GetModuleFileNameA
FreeEnvironmentStringsA
GetEnvironmentStrings
FreeEnvironmentStringsW
WideCharToMultiByte
GetEnvironmentStringsW
SetHandleCount
GetFileType
DeleteCriticalSection
TlsAlloc
TlsSetValue
TlsFree
SetLastError
GetCurrentThreadId
InterlockedDecrement
GetCurrentThread
HeapCreate
HeapDestroy
HeapFree
QueryPerformanceCounter
GetTickCount
GetCurrentProcessId
FatalAppExitA
VirtualAlloc
HeapReAlloc
GetCPInfo
GetOEMCP
IsValidCodePage
RtlUnwind
SetConsoleCtrlHandler
InterlockedExchange
InitializeCriticalSectionAndSpinCount
GetConsoleCP
GetConsoleMode
FlushFileBuffers
LCMapStringA
MultiByteToWideChar
LCMapStringW
GetStringTypeA
GetStringTypeW
GetTimeFormatA
GetDateFormatA
GetUserDefaultLCID
GetLocaleInfoA
EnumSystemLocalesA
IsValidLocale
GetLocaleInfoW
CloseHandle
WriteConsoleA
GetConsoleOutputCP
SetStdHandle
GetTimeZoneInformation
CreateFileA
CompareStringA
CompareStringW
SetEnvironmentVariableA
#w#3P`6R
~w+/9x
K}B;[/d
PDt k1WD
S*:"]|
Jq_[h<G
dcII.g
x=0|%R[
}'!2/k
*Qzm,2:
sB@%h'!
8-|B
8^j>8s
$y#(*I
;NhoQN
[%CGoRc)
9_!"5H
iR&Sm
J4VzAd
d4%{oA
a2t\.W
/?e'[<ZI
O*{%N{
B^,z $
=|E5k
fmA\bs
2+//$i
vt6%RP
K<u?ii.
\iXfz9
r{s\mv
SHzl}v
OTtwR~
auCZ~1bi91
7e/iiM
sKNp'}
9*)HCf
_/d^~y
!ZK'1x\
L9-6ZD
9O:2Y=
.aAgF4n
~VNB}
V _40
aGqyGI5o
;E&+/8
Ubv5i
IQ |-i0
9O. %U[
f9m!wc
LBJs2O
qe%~eR
80=S2I
x>[Lv'
7S+riu
pCYTQ?
mQJ5wOy=
X7C+{J
d# L^2
fS.j?j
TeHmR
3Sb:*Im
D,KX6/z
K@wc@K;
"w@YJ
F!}IXFY
#ri`;
FIu0C'l
km;J-
>n(52(
ZZ8!}GD
NN@:0d
d[e98,
}Yrqym
f>Zg5X
qUOxF^(
WTS53j
"u[J~,(^QE
%meDtY
T0!c-'~
5ROubB
a/;>"`
=%x\qq
%8:@dR3
XZMne:
@5E"oT
8q.P-s"
+7Xd:+
&,XKi=
~kJ.mPz
k!1]KX
>D2L_L[5
*#HXL:>
;E!fTW
URB>[U
@ b?f#
x{VyXED(
wB(Aap
]V"Jm!
sV:xB!+
ERn@$1-j
xF"K=N(
rI+7.t
uqlWI%
mrSVq{k
aaW,:~d
py Vhe
Z]k]XVk
kf-k}
sDg#$
Q&D)hj
k$SA!S
[o~7/V
d#%^S!
]GS?dF{f
a#758g%
@RG26._^
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
Humawer cejekatab filuxa gofohutuseh pejajo. Nevaririfudi hiwehemi faga. Juziceyakafivif jekisix. Vemayatopoxi zelevo putubeboped. Tivilicehuyimu. Kuteziha tiyonaci vixocucejitiy ferupeyu. Kav. Tixa ferize kojon. Ratofejonase mezi wepuv moyulus husarusamoyowic. Lemezo masesug. Viya videfe. Devucemeg cenamifo. Tibinomadigoxis soyitad fopayeduhe zizonewawukuz xog. Kelifujukikita. Ligibukobeg. Kogebel fazohim yereloxunaxa. Tehibajikuf jeriyerize tazipahud yivugigeforiwoh kara. Sekepebico zefesotaxehan josibatebu. Bowosexa nixawobez. Dulikapijik yomuli cige. Huwedofuxogizar hamuhunepoti ciy. Koweyecavuhixom. Rodiwohudo dida mipimacenixibo nujizovibona. Jihazexikusa licesiguxixo tedin ledexusila. Hutoku meruvosofuj. Hupaxebe yitikef. Yodeja feyokozi voxufojeb gugehisehiwu yux. Zeketibix rihac zutu. Xebogo yipawonucakoruw weririwik cegico. Jijut ganipegukalip wukewidotoheju nojekok loruyedegomi. Bemujayoxafe raw wenegafe fanikigisobegur rilupupekoci. Nad. Mecahezizulo vovuwih wolelabusotu xigur dadutiwir. Kilinoreg
Ajjjjjjjj
jjjjjjjj
Ajjjjjjj
Ajjjjj
sekuheniwikahedesimemacovoc
@(null)
mscoree.dll
KERNEL32.DLL
((((( H
h(((( H
H
XUSAJOKIY
VS_VERSION_INFO
StringFileInfo
041904E6
FileVerus
1.0.52.18
ProductVersys
1.6.37.29
VarFileInfo
Translations
-Vege rucuv kumumijisip rufatidezaluxo yilusot
Luliro sivakapisopu^Junazezak canogowaraxu wos marayawihi xebagakovi leduhinoc vuraficuf jidogoxugegijap bubupuvot,Bibay ciyasetilo bidojafamiseda nubaxidedecu
Gisicopayitivot
Gazugasuzola
KolapafezuforerEFameraxejuhuh pac xikoh zakaparese xaxediga posovevid nibix dezafuceh.Gimuxacowib hogarow widubekikabohad nawafokeni
Antivirus Signature
Bkav W32.AIDetect.malware1
Elastic malicious (high confidence)
DrWeb Clean
MicroWorld-eScan Clean
FireEye Generic.mg.07da81ad26a1698f
CAT-QuickHeal Clean
McAfee GenericRXOH-KB!07DA81AD26A1
Cylance Unsafe
VIPRE Clean
Sangfor Trojan.Win32.Save.a
K7AntiVirus Clean
BitDefender Clean
K7GW Clean
Cybereason malicious.1bf634
BitDefenderTheta Gen:NN.ZexaF.34678.nqW@aaETHyaG
Cyren Clean
Symantec ML.Attribute.HighConfidence
ESET-NOD32 Clean
APEX Malicious
Paloalto Clean
ClamAV Clean
Kaspersky UDS:DangerousObject.Multi.Generic
Alibaba Clean
NANO-Antivirus Clean
ViRobot Clean
SUPERAntiSpyware Clean
Rising Malware.Heuristic!ET#87% (RDMK:cmRtazpI+c98d2pk5eLwA5m3vQoZ)
Ad-Aware Clean
TACHYON Clean
Emsisoft Clean
Comodo Clean
F-Secure Clean
Baidu Clean
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition BehavesLike.Win32.Emotet.dc
CMC Clean
Sophos ML/PE-A + Mal/GandCrypt-A
SentinelOne Static AI - Malicious PE
GData Clean
Jiangmin Clean
Webroot Clean
Avira Clean
Antiy-AVL Clean
Kingsoft Clean
Gridinsoft Clean
Arcabit Clean
AegisLab Clean
ZoneAlarm UDS:DangerousObject.Multi.Generic
Microsoft Trojan:Win32/Wacatac.B!ml
Cynet Malicious (score: 100)
AhnLab-V3 Malware/Win.Generic.C4432980
Acronis Clean
VBA32 Clean
ALYac Clean
MAX Clean
Malwarebytes Trojan.MalPack.GS
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Tencent Clean
Yandex Clean
Ikarus Trojan.Win32.Crypt
Fortinet Clean
Avast Clean
CrowdStrike win/malicious_confidence_100% (W)
Qihoo-360 Clean
No IRMA results available.