Static | ZeroBOX

PE Compile Time

2020-11-10 05:47:45

PDB Path

C:\fazi26-tipayeguyaju\disir87\kaduyiyoranidu64\tuhe.pdb

PE Imphash

00a47d6be4445a02dce374ef34dd9b76

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x0000e730 0x0000e800 7.34111263995
.rdata 0x00010000 0x000037f0 0x00003800 4.38681899659
.data 0x00014000 0x02838a60 0x00004000 0.686744459971
.rsrc 0x0284d000 0x00006178 0x00006200 6.34731164747

Resources

Name Offset Size Language Sub-language File type
RT_CURSOR 0x02852cf0 0x000000b0 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_CURSOR 0x02852cf0 0x000000b0 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x02852698 0x00000468 LANG_SERBIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x02852698 0x00000468 LANG_SERBIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x02852698 0x00000468 LANG_SERBIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x02852698 0x00000468 LANG_SERBIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x02852698 0x00000468 LANG_SERBIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x02852698 0x00000468 LANG_SERBIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_STRING 0x02853028 0x0000014a LANG_SERBIAN SUBLANG_DEFAULT data
RT_STRING 0x02853028 0x0000014a LANG_SERBIAN SUBLANG_DEFAULT data
RT_ACCELERATOR 0x02852b98 0x00000028 LANG_SERBIAN SUBLANG_DEFAULT data
RT_ACCELERATOR 0x02852b98 0x00000028 LANG_SERBIAN SUBLANG_DEFAULT data
RT_GROUP_CURSOR 0x02852da0 0x00000022 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_GROUP_ICON 0x02852b00 0x0000005a LANG_SERBIAN SUBLANG_DEFAULT data
RT_VERSION 0x02852dc8 0x000001b4 LANG_NEUTRAL SUBLANG_NEUTRAL data

Imports

Library KERNEL32.dll:
0x410004 WriteConsoleInputW
0x410008 lstrlenA
0x410010 EnumDateFormatsExW
0x410014 FindResourceExW
0x41001c EndUpdateResourceW
0x410020 GetUserDefaultLCID
0x410028 GetComputerNameW
0x41002c SetEvent
0x410034 GetProcessHeap
0x410038 ReadConsoleW
0x41003c SetFileTime
0x410040 WriteFile
0x410044 CreateActCtxW
0x41004c GetVolumePathNameW
0x410050 ActivateActCtx
0x410054 GetConsoleCP
0x410058 GlobalFindAtomA
0x41005c TerminateThread
0x410060 ReadConsoleInputA
0x410068 ReadConsoleOutputW
0x41006c GetVersionExW
0x410070 SetConsoleCP
0x41007c GetConsoleAliasW
0x410080 VerifyVersionInfoA
0x410084 GetMailslotInfo
0x41008c CreateActCtxA
0x410090 SetConsoleTitleA
0x410094 GetConsoleOutputCP
0x410098 InterlockedExchange
0x41009c GetLastError
0x4100a0 GetLongPathNameW
0x4100a4 SetLastError
0x4100a8 GetProcAddress
0x4100b4 LoadLibraryA
0x4100b8 WriteConsoleA
0x4100bc CreateTapePartition
0x4100c0 GetProfileStringA
0x4100cc GetModuleHandleA
0x4100d0 UpdateResourceW
0x4100d8 BuildCommDCBA
0x4100dc VirtualProtect
0x4100e4 GetCPInfoExA
0x4100e8 SetCalendarInfoA
0x4100ec FindFirstVolumeW
0x4100f0 GetCurrentProcessId
0x4100f8 GlobalReAlloc
0x4100fc GetSystemTime
0x410100 AreFileApisANSI
0x410104 CreateThread
0x410108 CreateFileA
0x410114 HeapReAlloc
0x410118 HeapAlloc
0x41011c GetStartupInfoW
0x410120 GetModuleHandleW
0x410124 Sleep
0x410128 ExitProcess
0x41012c GetStdHandle
0x410130 GetModuleFileNameA
0x410138 TerminateProcess
0x41013c GetCurrentProcess
0x410140 IsDebuggerPresent
0x410148 HeapCreate
0x41014c VirtualFree
0x410150 HeapFree
0x410154 VirtualAlloc
0x410158 GetModuleFileNameW
0x410164 GetCommandLineW
0x410168 SetHandleCount
0x41016c GetFileType
0x410170 GetStartupInfoA
0x410174 TlsGetValue
0x410178 TlsAlloc
0x41017c TlsSetValue
0x410180 TlsFree
0x410188 GetCurrentThreadId
0x410194 GetTickCount
0x4101a0 GetCPInfo
0x4101a4 GetACP
0x4101a8 GetOEMCP
0x4101ac IsValidCodePage
0x4101b0 WideCharToMultiByte
0x4101b4 RtlUnwind
0x4101b8 HeapSize
0x4101bc GetLocaleInfoA
0x4101c0 GetConsoleMode
0x4101c4 FlushFileBuffers
0x4101c8 LCMapStringA
0x4101cc MultiByteToWideChar
0x4101d0 LCMapStringW
0x4101d4 GetStringTypeA
0x4101d8 GetStringTypeW
0x4101dc SetFilePointer
0x4101e0 CloseHandle
0x4101e4 WriteConsoleW
0x4101e8 SetStdHandle
Library USER32.dll:
0x4101f0 GetAltTabInfoA

!This program cannot be run in DOS mode.
`.rdata
@.data
PVVVVV
HHtXHHt
>If90t
>=Yt1j
QQSVWh
j@j ^V
Y;=xLA
0SSSSS
0SSSSS
0SSSSS
0A@@Ju
Fh=pFA
to=XMA
^SSSSS
j"^SSSSS
URPQQhPy@
0WWWWW
AAFFf;
t"SS9]
v$;5|MA
PPPPPPPP
PPPPPPPP
;t$,v-
UQPXY]Y[
t+WWVPV
/Nrga)
hM.%eB
CU$4lp%
FtHj4D
wAFpR+
]O0/{5
1|Cq&w
A,dDz8
I.-G*T
{{>,}B
TQ|""\
0VamFF(
|gdu;U
,X*#Cy-2t
wd)wYA
RX7:"tb
ME4F\R5a
P6sh?0
{/l,WT
"UxcKf,
]Fs#fx
+/n05a
nR/K^4P
[B*'1
S0)sZfl,
)uMP`V
,/u4|/S
5AAceo&^
UNN>{_
~!FuLyhK
74RH\~
}r]oI;4
us[]*:@xr
xxv/;m
{2E&`9
INBM<2
5@''?B
1vL"Ha
;)GWz16SWPSkmJ
.~}];n
*- qDv
F\Q]_]
CorExitProcess
runtime error
TLOSS error
SING error
DOMAIN error
An application has made an attempt to load the C runtime library incorrectly.
Please contact the application's support team for more information.
- Attempt to use MSIL code from this assembly during native code initialization
This indicates a bug in your application. It is most likely the result of calling an MSIL-compiled (/clr) function from a native constructor or from DllMain.
- not enough space for locale information
- Attempt to initialize the CRT more than once.
This indicates a bug in your application.
- CRT not initialized
- unable to initialize heap
- not enough space for lowio initialization
- not enough space for stdio initialization
- pure virtual function call
- not enough space for _onexit/atexit table
- unable to open console device
- unexpected heap error
- unexpected multithread lock error
- not enough space for thread data
This application has requested the Runtime to terminate it in an unusual way.
Please contact the application's support team for more information.
- not enough space for environment
- not enough space for arguments
- floating point support not loaded
Microsoft Visual C++ Runtime Library
<program name unknown>
Runtime Error!
Program:
(null)
`h````
xpxxxx
EncodePointer
DecodePointer
FlsFree
FlsSetValue
FlsGetValue
FlsAlloc
GetProcessWindowStation
GetUserObjectInformationA
GetLastActivePopup
GetActiveWindow
MessageBoxA
USER32.DLL
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
`h`hhh
xppwpp
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
HH:mm:ss
dddd, MMMM dd, yyyy
MM/dd/yy
December
November
October
September
August
February
January
Saturday
Friday
Thursday
Wednesday
Tuesday
Monday
Sunday
SunMonTueWedThuFriSat
JanFebMarAprMayJunJulAugSepOctNovDec
CONOUT$
bad allocation
wijiwifalipimetibuligijabudidozo fed rolujalajuliv fomij docoxewicudavobinidegamu
Tipit gedo fizayed mizetawovadu yewaxacolitena
Bikoruma fej mebebohudor vem rawuso
Belifocavo buvapetaxan xafuki yov rivifasid
hapawikitozibozipusi dagetegopuwikafox
bazuletodadepuyeviji
kernel32.dll
LocalAlloc
%s %f %c
xewusejixadehayemugaceyanexirohoyayihiperahutusojekavuvo
C:\fazi26-tipayeguyaju\disir87\kaduyiyoranidu64\tuhe.pdb
SetProcessAffinityMask
WriteConsoleInputW
lstrlenA
GetConsoleAliasesLengthW
EnumDateFormatsExW
FindResourceExW
WriteConsoleOutputCharacterA
EndUpdateResourceW
GetUserDefaultLCID
SetConsoleScreenBufferSize
GetComputerNameW
SetEvent
GetSystemDefaultLCID
GetProcessHeap
ReadConsoleW
SetFileTime
WriteFile
CreateActCtxW
InitializeCriticalSection
GetVolumePathNameW
ActivateActCtx
GetConsoleCP
GlobalFindAtomA
TerminateThread
ReadConsoleInputA
GetSystemWindowsDirectoryA
ReadConsoleOutputW
GetVersionExW
SetConsoleCP
InterlockedPopEntrySList
DnsHostnameToComputerNameW
GetConsoleAliasW
VerifyVersionInfoA
GetMailslotInfo
GetTimeZoneInformation
CreateActCtxA
SetConsoleTitleA
GetConsoleOutputCP
InterlockedExchange
GetLastError
GetLongPathNameW
SetLastError
GetProcAddress
GetConsoleDisplayMode
EnterCriticalSection
LoadLibraryA
WriteConsoleA
CreateTapePartition
GetProfileStringA
WaitForMultipleObjects
SetEnvironmentVariableA
GetModuleHandleA
UpdateResourceW
CancelTimerQueueTimer
BuildCommDCBA
VirtualProtect
GetFileAttributesExW
GetCPInfoExA
SetCalendarInfoA
FindFirstVolumeW
GetCurrentProcessId
GetPrivateProfileSectionW
GlobalReAlloc
GetSystemTime
AreFileApisANSI
CreateThread
KERNEL32.dll
GetAltTabInfoA
RealChildWindowFromPoint
USER32.dll
UnhandledExceptionFilter
SetUnhandledExceptionFilter
HeapReAlloc
HeapAlloc
GetStartupInfoW
GetModuleHandleW
ExitProcess
GetStdHandle
GetModuleFileNameA
LeaveCriticalSection
TerminateProcess
GetCurrentProcess
IsDebuggerPresent
DeleteCriticalSection
HeapCreate
VirtualFree
HeapFree
VirtualAlloc
GetModuleFileNameW
FreeEnvironmentStringsW
GetEnvironmentStringsW
GetCommandLineW
SetHandleCount
GetFileType
GetStartupInfoA
TlsGetValue
TlsAlloc
TlsSetValue
TlsFree
InterlockedIncrement
GetCurrentThreadId
InterlockedDecrement
QueryPerformanceCounter
GetTickCount
GetSystemTimeAsFileTime
InitializeCriticalSectionAndSpinCount
GetCPInfo
GetACP
GetOEMCP
IsValidCodePage
WideCharToMultiByte
RtlUnwind
HeapSize
GetLocaleInfoA
GetConsoleMode
FlushFileBuffers
LCMapStringA
MultiByteToWideChar
LCMapStringW
GetStringTypeA
GetStringTypeW
SetFilePointer
CloseHandle
WriteConsoleW
SetStdHandle
CreateFileA
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
98ya&/
/1xu%/
p-@{}86
!:3|d"
4PGyrD>
8PYrE0-
!DOk:,=
QX{sF:
mscoree.dll
(null)
KERNEL32.DLL
((((( H
h(((( H
H
xobudazureri jabep dugod gunuyojigoyicowucomeyacebupef
puhasirukafijoviyozoda yap
Vadajofeb rokima siced
Yokanohufupo kuluhonin lugudabicewu liyonirit
Sipiwaxa
hubupebibigupoxisecuna
VS_VERSION_INFO
StringFileInform
081564b6
InternalName
kogzmuadeke.exi
Copyright
Copyrighz (C) 2020, vodkagata
ProductVersion
99.9.26.59
VarFileInfo
Translation
ADeselopas lavegit kacoj pidure rekipoziyine nur rudezijuk pukulev
hJifon yiwiwoviramojoz guyoneray hobafolo cahelarepipojuv zesusexosok kagewan suwimo huku jacusizodahirag
-Tibotizotumepa jotezagojoxiwiw xucotifupuzeco
Antivirus Signature
Bkav Clean
Lionic Trojan.Win32.Zenpak.4!c
Elastic malicious (high confidence)
MicroWorld-eScan Trojan.GenericKD.46752474
FireEye Generic.mg.e4b0b8cd3c4cb627
CAT-QuickHeal Clean
McAfee RDN/Generic.dx
Cylance Unsafe
VIPRE Clean
Sangfor Trojan.Win32.Save.a
CrowdStrike win/malicious_confidence_100% (W)
BitDefender Trojan.GenericKD.46752474
K7GW Trojan ( 005809201 )
K7AntiVirus Trojan ( 005809201 )
Baidu Clean
Cyren W32/Kryptik.EUY.gen!Eldorado
Symantec ML.Attribute.HighConfidence
ESET-NOD32 a variant of Win32/Kryptik.HLZR
APEX Malicious
Paloalto generic.ml
ClamAV Win.Dropper.Raccoon-9884213-0
Kaspersky HEUR:Trojan.Win32.Zenpak.gen
Alibaba Trojan:Win32/Kryptik.3e1acbc4
NANO-Antivirus Clean
ViRobot Clean
Tencent Clean
Ad-Aware Trojan.GenericKD.46752474
Emsisoft Trojan.GenericKD.46752474 (B)
Comodo Malware@#3gro97xqprhtm
F-Secure Clean
DrWeb Trojan.MulDrop18.18615
Zillya Clean
TrendMicro Mal_HPGen-50
McAfee-GW-Edition BehavesLike.Win32.Emotet.ch
CMC Clean
Sophos Mal/Generic-S
Ikarus Trojan.Win32.Glupteba
GData Win32.Trojan.BSE.1YPK01Z
Jiangmin Clean
MaxSecure Trojan.Malware.300983.susgen
Avira Clean
MAX malware (ai score=81)
Antiy-AVL Clean
Kingsoft Win32.Troj.Undef.(kcloud)
Gridinsoft Clean
Arcabit Clean
SUPERAntiSpyware Clean
ZoneAlarm Clean
Microsoft Ransom:Win32/StopCrypt.MQK!MTB
Cynet Malicious (score: 100)
AhnLab-V3 Trojan/Win.Hpgen.R436162
Acronis suspicious
BitDefenderTheta Gen:NN.ZexaF.34058.hq0@auYIwxgG
ALYac Trojan.GenericKD.46752474
TACHYON Clean
VBA32 Backdoor.Mokes
Malwarebytes Trojan.MalPack.GS
Panda Trj/GdSda.A
Zoner Clean
TrendMicro-HouseCall Mal_HPGen-50
Rising Trojan.Kryptik!1.B40D (CLASSIC)
Yandex Trojan.Zenpak!15oNdU70CKI
SentinelOne Static AI - Malicious PE
eGambit Unsafe.AI_Score_87%
Fortinet W32/Kryptik.HLZT!tr
Webroot Clean
AVG Win32:MalwareX-gen [Trj]
Cybereason Clean
Avast Win32:MalwareX-gen [Trj]
Qihoo-360 Win32/Heur.Generic.HwoCGN8A
No IRMA results available.