Static | ZeroBOX

PE Compile Time

2020-03-05 13:13:00

PE Imphash

20a3b8299db6e8582c3eb04a6c72e959

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x0002568a 0x00025800 7.44869995927
.data 0x00027000 0x0001d57c 0x00004c00 1.06068260008
.tls 0x00045000 0x00000009 0x00000200 0.0
.new 0x00046000 0x00002cba 0x00002e00 5.47611582846
.rsrc 0x00049000 0x000567f8 0x00001800 6.01542588445
.reloc 0x000a0000 0x00001130 0x00001200 6.11166953911

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x00049130 0x000010a8 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_STRING 0x0004a3a8 0x0000044c LANG_UZBEK SUBLANG_UZBEK_CYRILLIC data
RT_GROUP_ICON 0x0004a1d8 0x00000014 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_VERSION 0x0004a1f0 0x000001b8 LANG_NEUTRAL SUBLANG_NEUTRAL COM executable for DOS

Imports

Library KERNEL32.dll:
0x446008 FreeLibrary
0x446010 GetConsoleAliasA
0x446014 GetModuleHandleExW
0x446018 GetTickCount
0x44601c SetFileTime
0x446020 TerminateThread
0x446024 GetLocaleInfoW
0x44602c GetFileAttributesA
0x446034 GetAtomNameW
0x446038 ReadFile
0x44603c lstrcatA
0x446040 RaiseException
0x446044 FindResourceW
0x446048 SetLastError
0x44604c GetProcAddress
0x446050 OpenWaitableTimerA
0x446054 LocalAlloc
0x446058 SetConsoleOutputCP
0x44605c GlobalFindAtomW
0x446064 GetModuleHandleA
0x446068 LoadLibraryExA
0x44606c FindAtomW
0x446074 GetCurrentProcessId
0x446078 CompareStringW
0x44607c CompareStringA
0x446080 LCMapStringA
0x446084 MapViewOfFile
0x446088 GetModuleHandleW
0x44608c Sleep
0x446090 ExitProcess
0x446094 GetStartupInfoW
0x446098 TerminateProcess
0x44609c GetCurrentProcess
0x4460a8 IsDebuggerPresent
0x4460ac HeapAlloc
0x4460b0 TlsGetValue
0x4460b4 TlsAlloc
0x4460b8 TlsSetValue
0x4460bc TlsFree
0x4460c4 GetCurrentThreadId
0x4460c8 GetLastError
0x4460d0 GetCurrentThread
0x4460d4 WriteFile
0x4460d8 GetStdHandle
0x4460dc GetModuleFileNameA
0x4460e8 FatalAppExitA
0x4460f4 InterlockedExchange
0x4460f8 LoadLibraryA
0x446100 GetModuleFileNameW
0x44610c GetCommandLineW
0x446110 SetHandleCount
0x446114 GetFileType
0x446118 GetStartupInfoA
0x44611c HeapCreate
0x446120 HeapDestroy
0x446124 VirtualFree
0x446128 HeapFree
0x446134 VirtualAlloc
0x446138 HeapReAlloc
0x44613c GetCPInfo
0x446140 GetACP
0x446144 GetOEMCP
0x446148 IsValidCodePage
0x44614c HeapSize
0x446150 RtlUnwind
0x446154 GetLocaleInfoA
0x446158 WideCharToMultiByte
0x44615c MultiByteToWideChar
0x446160 LCMapStringW
0x446164 GetStringTypeA
0x446168 GetStringTypeW
0x44616c GetTimeFormatA
0x446170 GetDateFormatA
0x446174 GetUserDefaultLCID
0x446178 EnumSystemLocalesA
0x44617c IsValidLocale
Library USER32.dll:
0x44618c GetDesktopWindow
Library ADVAPI32.dll:
0x446000 RegCreateKeyW

!This program cannot be run in DOS mode.
`.data
@.rsrc
@.reloc
F\=8hD
tehb&@
t h`ED
_VVVVV
_VVVVV
>=Yt1j
QQSVWh
j@j ^V
0A@@Ju
0SSSSS
0SSSSS
0SSSSS
URPQQh
u,VVWV
t VV9u
0WWWWW
AAFFf;
t"SS9]
C PjPV
C$PjQV
C*PjTV
C+PjUV
C,PjVV
C-PjWV
C.PjRV
C/PjSV
.;1s(N
HHt4HHt
Ht\Ht,
teHtFHt&Hu
ty<%tA
PPPPPPPP
PPPPPPPP
;t$,v-
UQPXY]Y[
t+WWVPV
^SSSSS
^SSSSS
>:u8FV
VVVVVQRSSj
^SSSSS
^SSSSS
0SSSSS
^SSSSS
^WWWWW
0SSSSS
8VVVVV
5|%z<]e
-ZCFB%jo
h{3&xw
0/(?9t
jT!T8rn
U-2R<\
+_o%~
hz3KL3
K/30]2
%!`U-L
%`88`Nv
lvJRvf/
K5m>sHG
HH:v-(
5~j 5Z
R[P{]@
:,[Z33vM
QG$ao{
N`e_'P
8eo^lX%2tK
0u0r$0eQ
m7=oVJ
c;k?&$
.HZPWD
Jm-Bl T^p
oUtz]:
M@P\6Da58#^{;
?*m?1WdA8
%(S>$0{
*@Ho<8
>i2$t0
UI.TXn
E-5X 6
[uVdP`X
SW 5 M
9FCZNoS
~AMPw
i8e^;"2w
0l|E!S
Qh*Ob}(
&23#hu
B*%OiX
;.!"C1
X"XA,<#q
;lF:vE;
utH;.]
._`vQF
r(%Pp
-gQ3bg=
h8I2$A
Wzb~4a|
&j49WS
X]cmJZc
Z8#a8Z
/oN#khY
5Qt{MC2@}
}%)zv\
2Gk1XSr}ZI
?Pa|!t
/MykCR
ziA>r.
xRdG-g
P6h`)?
p'SpTZ
}k_ |X
-s'OI`
pzI`q[
.Mg e<
8[/qFJ
!p}-^#>
71;=>)
J'P_.vuc
E/sJPbT
4%+~w*
Ekj=-%,
b+x}PE
Z7rZlG"I
|4w{&Dp
S{v 5^bF
+dnL<dN
p`>E/a
R,iShI
xd|od2
`)<{Y'<
;}b={7c
^Xuu{/
2Wl|#/
V_RD}@
"E`bN~4
WN#Jk8
Q1v'\H
Q]yir^
.&Y&Re^
c{jzp0
P2FwV,
l/VVh&
-~IA`
E`?LA1_
DH9DMP
H|+x4
D}j<ky=
!=;Kdd
?a]K<Ug
p~~$6)
D=TdGH
=jkFAQJ
.{a71PuV
CPNAjQ
qt1mgaU
~<|$y1L@`
eEA]<7~y
OulWXE
Gl"n.M
}qp/ky
%)2@W}
ZySy^r9
7F>28I
'2N6n5
|Ee/eL
pn(rm
X`o19
*%Z*A:Z
*+HnD3
v"N*;;
R94[k*
Br0*7>
?\&(O
!RjTbH
$ hP|D
_VVVVV
^WWWWW
tNIt?It0It
0SSSSS
_VVVVV
<+t(<-t$:
+t HHt
u;hp~D
u,hh~D
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
CorExitProcess
EncodePointer
DecodePointer
FlsFree
FlsSetValue
FlsGetValue
FlsAlloc
runtime error
TLOSS error
SING error
DOMAIN error
An application has made an attempt to load the C runtime library incorrectly.
Please contact the application's support team for more information.
- Attempt to use MSIL code from this assembly during native code initialization
This indicates a bug in your application. It is most likely the result of calling an MSIL-compiled (/clr) function from a native constructor or from DllMain.
- not enough space for locale information
- Attempt to initialize the CRT more than once.
This indicates a bug in your application.
- CRT not initialized
- unable to initialize heap
- not enough space for lowio initialization
- not enough space for stdio initialization
- pure virtual function call
- not enough space for _onexit/atexit table
- unable to open console device
- unexpected heap error
- unexpected multithread lock error
- not enough space for thread data
This application has requested the Runtime to terminate it in an unusual way.
Please contact the application's support team for more information.
- not enough space for environment
- not enough space for arguments
- floating point support not loaded
Microsoft Visual C++ Runtime Library
<program name unknown>
Runtime Error!
Program:
SystemFunction036
ADVAPI32.DLL
LC_TIME
LC_NUMERIC
LC_MONETARY
LC_CTYPE
LC_COLLATE
LC_ALL
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
GetProcessWindowStation
GetUserObjectInformationA
GetLastActivePopup
GetActiveWindow
MessageBoxA
USER32.DLL
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
HH:mm:ss
dddd, MMMM dd, yyyy
MM/dd/yy
December
November
October
September
August
February
January
Saturday
Friday
Thursday
Wednesday
Tuesday
Monday
Sunday
united-states
united-kingdom
trinidad & tobago
south-korea
south-africa
south korea
south africa
slovak
puerto-rico
pr-china
pr china
new-zealand
hong-kong
holland
great britain
england
britain
america
swedish-finland
spanish-venezuela
spanish-uruguay
spanish-puerto rico
spanish-peru
spanish-paraguay
spanish-panama
spanish-nicaragua
spanish-modern
spanish-mexican
spanish-honduras
spanish-guatemala
spanish-el salvador
spanish-ecuador
spanish-dominican republic
spanish-costa rica
spanish-colombia
spanish-chile
spanish-bolivia
spanish-argentina
portuguese-brazilian
norwegian-nynorsk
norwegian-bokmal
norwegian
italian-swiss
irish-english
german-swiss
german-luxembourg
german-lichtenstein
german-austrian
french-swiss
french-luxembourg
french-canadian
french-belgian
english-usa
english-us
english-uk
english-trinidad y tobago
english-south africa
english-nz
english-jamaica
english-ire
english-caribbean
english-can
english-belize
english-aus
english-american
dutch-belgian
chinese-traditional
chinese-singapore
chinese-simplified
chinese-hongkong
chinese
canadian
belgian
australian
american-english
american english
american
Norwegian-Nynorsk
SunMonTueWedThuFriSat
JanFebMarAprMayJunJulAugSepOctNovDec
bad allocation
kernel32.dll
VirtualProtect
GAIsProcessorFeaturePresent
KERNEL32
_nextafter
_hypot
1#QNAN
1#SNAN
MapViewOfFile
FindResourceW
FreeLibrary
SystemTimeToTzSpecificLocalTime
GetConsoleAliasA
GetModuleHandleExW
GetTickCount
SetFileTime
TerminateThread
GetLocaleInfoW
SetSystemTimeAdjustment
GetFileAttributesA
SetTimeZoneInformation
GetAtomNameW
ReadFile
lstrcatA
RaiseException
LCMapStringA
SetLastError
GetProcAddress
OpenWaitableTimerA
LocalAlloc
SetConsoleOutputCP
GlobalFindAtomW
SetConsoleCursorInfo
GetModuleHandleA
LoadLibraryExA
FindAtomW
FileTimeToLocalFileTime
GetCurrentProcessId
KERNEL32.dll
GetDesktopWindow
USER32.dll
RegCreateKeyW
ADVAPI32.dll
GetModuleHandleW
ExitProcess
GetStartupInfoW
TerminateProcess
GetCurrentProcess
UnhandledExceptionFilter
SetUnhandledExceptionFilter
IsDebuggerPresent
HeapAlloc
TlsGetValue
TlsAlloc
TlsSetValue
TlsFree
InterlockedIncrement
GetCurrentThreadId
GetLastError
InterlockedDecrement
GetCurrentThread
WriteFile
GetStdHandle
GetModuleFileNameA
DeleteCriticalSection
LeaveCriticalSection
FatalAppExitA
EnterCriticalSection
SetConsoleCtrlHandler
InterlockedExchange
LoadLibraryA
InitializeCriticalSectionAndSpinCount
GetModuleFileNameW
FreeEnvironmentStringsW
GetEnvironmentStringsW
GetCommandLineW
SetHandleCount
GetFileType
GetStartupInfoA
HeapCreate
HeapDestroy
VirtualFree
HeapFree
QueryPerformanceCounter
GetSystemTimeAsFileTime
VirtualAlloc
HeapReAlloc
GetCPInfo
GetACP
GetOEMCP
IsValidCodePage
HeapSize
RtlUnwind
GetLocaleInfoA
WideCharToMultiByte
MultiByteToWideChar
LCMapStringW
GetStringTypeA
GetStringTypeW
GetTimeFormatA
GetDateFormatA
GetUserDefaultLCID
EnumSystemLocalesA
IsValidLocale
GetTimeZoneInformation
CompareStringA
CompareStringW
SetEnvironmentVariableA
0 0&0,02080>0D0J0P0V0\0b0h0n0t0z0
2A2\2b2k2r2
3U3k3s3
6 646F6M6S6e6m6x6
8#8,81878A8J8U8a8f8v8{8
;%;:;E;
011D1|1
1`2j2w2
243L3R3]3i3~3
434D4J4U4_4e4q4
5#5*575Z5o5
6'6?6e6
82878?8E8L8R8Y8_8g8n8s8{8
9*909=9]9c9
:":-:Q:Z:a:j:
:!;4;L;^;t;
<?<F<_<s<y<
>6>_>d>{>
313<3K3
52585N5T5
7+7:7d7|7
8b9k9q9
:J:P:z:
;k;F<~<
=$=:=V=h=
=$>a>p>
1K1d1k1
1/272w2
4%4*484@4L4S4\4o4y4
5=5E5P5
5/6=6t6|6
6$92989R9W9f9o9|9
:#:7:>:D:R:Y:^:g:t:z:
?'?3?A?G?M?R?[?u?{?
6"838m8z8
<&<.<6<M<f<
1)111[1g1
4B5[5l5
7?8":R:
?;?E?Q?Z?
22+2B2H2h2q2}2
3T3]3i3
4,414;4I4
4-747:7g7n7v7
758A8M9
;(;/;7;<;@;D;m;
<$<(<,<0<
=M=T=X=\=`=d=h=l=p=
;$;(;,;0;4;8;<;@;
<+<7<A<I<T<
0(000=0D0t0
l041F1P1Z1
234G4]4n4
*7.72767:7>7B7F7J7N7R7V7Z7^7b7f7j7n7r7v7z7~7
<'<-<W<]<z<
7&7>7e7v7{7
;4;<;F;S;[;a;g;
<%<,<7<?<G<P<Y<g<u<
<0===K=X=k=x=
44(464
1;1l1|1?2E2Q2`2
30666<6B6H6N6T6Z6`6f6l6r6x6~6
7 7&7,72787>7D7J7P7V7\7b7h7n7t7z7
a1f1q1z1
2*212=2K2b2o2y2
33A3H3\3a3p3}3
40464?4M4\4m4s4y4
5"5,555C5X5b5l5r5x5
51686S6Y6
7'8A8J8R8
4$4C4T4Z4
6(6C6J6S6\6e6n6w6
7!767;7R7
2+2A2I2
9<9U9b9p9
68:<:@:D:H:L:P:T:X:\:`:d:q:=;
<0<?<k<
2$2,242<2`3d3h3l3p3t3x3|3
: :$:(:,:0:4:8:<:@:D:H:L:P:T:X:\:`:d:h:l:p:t:x:|:
8$8,848<8D8L8T8\8d8l8t8|8
9 9$9(9,9094989<9@9D9H9L9P9T9X9\9
9 9(90989@9H9P9X9`9h9p9x9
: :(:0:8:@:H:P:X:`:h:p:x:
; ;(;0;8;@;H;P;X;`;h;p;
?4?8?@?D?`?
0,000L0P0p0
101P1p1|1
24282X2x2
383X3t3x3
mscoree.dll
KERNEL32.DLL
((((( H
h(((( H
H
VS_VERSION_INFO
StringFileInfo
040904E4
FileVersion
7.0.2.54
ProductVersion
7.0.21.21
InternalNames
galimatimot
LegalCopyright
Wsekde
VarFileInfo
Translations
VFeri saxovejodecemeb duvi sahece siyeveyayez wolabic sedebukapi winitilinabos fayisulo,Kotedusacuxe gucovom niv safigo samuvexogakaSBiyiyur nofamubezil gajahamifuxan guxecefit nirocecut ram kibuvagefusu mizotulo puc
Ripejizo hebixalej yeyefe6Pawarito hetocajoyocaf bilusuwicoma xeg numonaviziwajeUBakihasafunidah nupu vekivo gonununehito luwoveb kapozifuhajapi tolixug vizuyidahinidGKunih hotitodufulaha dusu nopecokujif haracipeliwelal cezejisa yetujogoONorodabikuzalo dab rujavavubaneta hupe wetuwetez xacapuvan xehu xoli hunuyulije
Bixovuc
Antivirus Signature
Bkav W32.AIDetect.malware1
Elastic malicious (high confidence)
MicroWorld-eScan Clean
FireEye Generic.mg.346cf0402aa3f87e
CAT-QuickHeal Clean
ALYac Clean
Cylance Unsafe
VIPRE Clean
AegisLab Clean
Sangfor Trojan.Win32.Save.a
K7AntiVirus Clean
BitDefender Clean
K7GW Hacktool ( 700007861 )
Cybereason malicious.875d77
BitDefenderTheta Gen:NN.ZexaF.34684.my0@au50jfhO
Cyren W32/Kryptik.DYR.gen!Eldorado
Symantec ML.Attribute.HighConfidence
ESET-NOD32 a variant of Win32/Kryptik.HKQF
Baidu Clean
APEX Malicious
Avast FileRepMalware
ClamAV Clean
Kaspersky UDS:DangerousObject.Multi.Generic
Alibaba Clean
NANO-Antivirus Clean
ViRobot Clean
Rising Malware.Heuristic!ET#98% (RDMK:cmRtazrWBazOPb83cTFGJQtoYbTp)
Ad-Aware Clean
TACHYON Clean
Emsisoft Clean
Comodo Clean
F-Secure Clean
DrWeb Clean
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition BehavesLike.Win32.Trojan.ch
CMC Clean
Sophos ML/PE-A
Ikarus Clean
GData Clean
Jiangmin Clean
eGambit Clean
Avira Clean
Antiy-AVL Clean
Kingsoft Clean
Gridinsoft Clean
Arcabit Clean
SUPERAntiSpyware Clean
ZoneAlarm UDS:DangerousObject.Multi.Generic
Microsoft Trojan:Win32/Predator!ml
Cynet Malicious (score: 100)
AhnLab-V3 Clean
Acronis suspicious
McAfee Artemis!346CF0402AA3
MAX Clean
VBA32 Clean
Malwarebytes Trojan.MalPack.GS
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Tencent Win32.Backdoor.Fareit.Auto
Yandex Clean
SentinelOne Static AI - Malicious PE
MaxSecure Clean
Fortinet Clean
Webroot W32.Trojan.Gen
AVG FileRepMalware
Paloalto generic.ml
CrowdStrike win/malicious_confidence_80% (D)
Qihoo-360 Clean
No IRMA results available.