Static | ZeroBOX

PE Compile Time

2020-12-18 10:34:08

PDB Path

C:\gol.pdb

PE Imphash

6b22ece31495fe337ab5b098b4e30ca3

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x0002c1b0 0x0002c200 7.87855766185
.rdata 0x0002e000 0x00004ee6 0x00005000 5.59326266456
.data 0x00033000 0x0288fa68 0x00004200 1.2208193673
.rsrc 0x028c3000 0x0000fdf0 0x0000fe00 6.62170895058

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x028d20b0 0x00000468 LANG_SERBIAN SUBLANG_ARABIC_ALGERIA GLS_BINARY_LSB_FIRST
RT_ICON 0x028d20b0 0x00000468 LANG_SERBIAN SUBLANG_ARABIC_ALGERIA GLS_BINARY_LSB_FIRST
RT_ICON 0x028d20b0 0x00000468 LANG_SERBIAN SUBLANG_ARABIC_ALGERIA GLS_BINARY_LSB_FIRST
RT_ICON 0x028d20b0 0x00000468 LANG_SERBIAN SUBLANG_ARABIC_ALGERIA GLS_BINARY_LSB_FIRST
RT_ICON 0x028d20b0 0x00000468 LANG_SERBIAN SUBLANG_ARABIC_ALGERIA GLS_BINARY_LSB_FIRST
RT_ICON 0x028d20b0 0x00000468 LANG_SERBIAN SUBLANG_ARABIC_ALGERIA GLS_BINARY_LSB_FIRST
RT_ICON 0x028d20b0 0x00000468 LANG_SERBIAN SUBLANG_ARABIC_ALGERIA GLS_BINARY_LSB_FIRST
RT_ICON 0x028d20b0 0x00000468 LANG_SERBIAN SUBLANG_ARABIC_ALGERIA GLS_BINARY_LSB_FIRST
RT_ICON 0x028d20b0 0x00000468 LANG_SERBIAN SUBLANG_ARABIC_ALGERIA GLS_BINARY_LSB_FIRST
RT_ICON 0x028d20b0 0x00000468 LANG_SERBIAN SUBLANG_ARABIC_ALGERIA GLS_BINARY_LSB_FIRST
RT_ICON 0x028d20b0 0x00000468 LANG_SERBIAN SUBLANG_ARABIC_ALGERIA GLS_BINARY_LSB_FIRST
RT_ICON 0x028d20b0 0x00000468 LANG_SERBIAN SUBLANG_ARABIC_ALGERIA GLS_BINARY_LSB_FIRST
RT_ICON 0x028d20b0 0x00000468 LANG_SERBIAN SUBLANG_ARABIC_ALGERIA GLS_BINARY_LSB_FIRST
RT_ICON 0x028d20b0 0x00000468 LANG_SERBIAN SUBLANG_ARABIC_ALGERIA GLS_BINARY_LSB_FIRST
RT_ICON 0x028d20b0 0x00000468 LANG_SERBIAN SUBLANG_ARABIC_ALGERIA GLS_BINARY_LSB_FIRST
RT_ICON 0x028d20b0 0x00000468 LANG_SERBIAN SUBLANG_ARABIC_ALGERIA GLS_BINARY_LSB_FIRST
RT_ICON 0x028d20b0 0x00000468 LANG_SERBIAN SUBLANG_ARABIC_ALGERIA GLS_BINARY_LSB_FIRST
RT_DIALOG 0x028d2798 0x000000cc LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_STRING 0x028d2c88 0x00000164 LANG_SERBIAN SUBLANG_ARABIC_ALGERIA data
RT_STRING 0x028d2c88 0x00000164 LANG_SERBIAN SUBLANG_ARABIC_ALGERIA data
RT_STRING 0x028d2c88 0x00000164 LANG_SERBIAN SUBLANG_ARABIC_ALGERIA data
RT_ACCELERATOR 0x028d25b8 0x00000028 LANG_SERBIAN SUBLANG_ARABIC_ALGERIA data
RT_ACCELERATOR 0x028d25b8 0x00000028 LANG_SERBIAN SUBLANG_ARABIC_ALGERIA data
RT_GROUP_ICON 0x028d2518 0x00000068 LANG_SERBIAN SUBLANG_ARABIC_ALGERIA data
RT_GROUP_ICON 0x028d2518 0x00000068 LANG_SERBIAN SUBLANG_ARABIC_ALGERIA data
RT_GROUP_ICON 0x028d2518 0x00000068 LANG_SERBIAN SUBLANG_ARABIC_ALGERIA data
RT_VERSION 0x028d25e0 0x000001b4 LANG_NEUTRAL SUBLANG_NEUTRAL data

Imports

Library KERNEL32.dll:
0x42e000 EnumDateFormatsExW
0x42e004 MoveFileExA
0x42e008 EndUpdateResourceW
0x42e020 GetUserDefaultLCID
0x42e024 WaitForSingleObject
0x42e02c GetComputerNameW
0x42e030 SetEvent
0x42e038 CreateActCtxW
0x42e03c GetConsoleCP
0x42e040 LocalShrink
0x42e044 ReadConsoleOutputW
0x42e048 GetVersionExW
0x42e04c GetFileAttributesA
0x42e050 lstrcpynW
0x42e054 GetConsoleAliasW
0x42e058 VerifyVersionInfoA
0x42e05c WriteConsoleW
0x42e064 IsBadWritePtr
0x42e068 ReadFile
0x42e06c GetModuleFileNameW
0x42e074 GetSystemDirectoryA
0x42e078 CreateFileW
0x42e07c lstrcatA
0x42e080 GetACP
0x42e084 GetVolumePathNameA
0x42e088 lstrlenW
0x42e08c SetConsoleTitleA
0x42e090 VerifyVersionInfoW
0x42e094 InterlockedExchange
0x42e098 GetLastError
0x42e09c GetProcAddress
0x42e0a4 GetLocalTime
0x42e0a8 GetProcessId
0x42e0ac LocalAlloc
0x42e0b0 SetCalendarInfoW
0x42e0b8 CreateTapePartition
0x42e0c0 SetFileApisToANSI
0x42e0c4 GlobalGetAtomNameW
0x42e0cc GetModuleHandleA
0x42e0d0 UpdateResourceW
0x42e0d8 GetConsoleTitleW
0x42e0dc BuildCommDCBA
0x42e0e0 VirtualProtect
0x42e0e4 PeekConsoleInputA
0x42e0e8 FindFirstVolumeW
0x42e0f0 GetStartupInfoW
0x42e0f4 HeapAlloc
0x42e100 GetModuleHandleW
0x42e104 TlsGetValue
0x42e108 TlsAlloc
0x42e10c TlsSetValue
0x42e110 TlsFree
0x42e114 SetLastError
0x42e118 GetCurrentThreadId
0x42e11c Sleep
0x42e120 ExitProcess
0x42e124 WriteFile
0x42e128 GetStdHandle
0x42e12c GetModuleFileNameA
0x42e134 GetCommandLineW
0x42e138 SetHandleCount
0x42e13c GetFileType
0x42e140 GetStartupInfoA
0x42e148 HeapCreate
0x42e14c VirtualFree
0x42e150 HeapFree
0x42e158 GetTickCount
0x42e15c GetCurrentProcessId
0x42e164 RaiseException
0x42e168 TerminateProcess
0x42e16c GetCurrentProcess
0x42e170 IsDebuggerPresent
0x42e178 VirtualAlloc
0x42e17c HeapReAlloc
0x42e180 GetCPInfo
0x42e184 GetOEMCP
0x42e188 IsValidCodePage
0x42e18c RtlUnwind
0x42e190 LoadLibraryA
0x42e198 GetLocaleInfoA
0x42e19c GetStringTypeA
0x42e1a0 MultiByteToWideChar
0x42e1a4 GetStringTypeW
0x42e1a8 LCMapStringA
0x42e1ac WideCharToMultiByte
0x42e1b0 LCMapStringW
0x42e1b4 HeapSize
Library USER32.dll:
0x42e1bc RealGetWindowClassA

!This program cannot be run in DOS mode.
`.rdata
@.data
VVVVVVh@
"uoVVV
tNIt?It0It
Y;=06C
>=Yt1j
QQSVWh
j@j ^V
to=X<C
0A@@Ju
Fh=@6C
URPQQh
_VVVVV
^WWWWW
tRHtCHt4Ht%HtFHHt
0SSSSS
0SSSSS
0SSSSS
0WWWWW
AAFFf;
v$;5|<C
PPPPPPPP
PPPPPPPP
t"SS9]
;t$,v-
UQPXY]Y[
0SSSSS
_VVVVV
t+WWVPV
<+t(<-t$:
+t HHt
A&qPz'
n{!r~J+
Sss})4
7wvN_E
tg(\i)g
|KH+W5|
-_eZ"M
I5y$":0
N->og\
\jlb_1
}#|fx@
)n"dl0ts
>aIS0
t u([t
~RM-.b:5t
vHvlj%
z:`T`i
.CcGv{
NWKLdFA
3ElXG!?
'/P#k.h
mOOeB$
s/}$O3
ChzQ"F
//jcgh
6#`|o% Gg]S
*/~h,3
cES^o|
Hv_.8c
}$UM]i
LK_b{W
rkSZf%v
OE/}5"
E4[%?B
pB_^Q'
.6PX5]
qKa<J@1
Qh#`MM53
.p0 #P
#"6xS><
A8^V}
MFlgc~
Y2+s&a
Huo?o+C
D`rV^M
HifqK|
lvrZk!D
0D6wTnO
4}fi E
5xe(Q?
Yt*roU
o1>XblH
:0SenL
kl9xCs
cM7'-%
0R'|fB
p,Xd$4
Fe:PR_3
rH:?B
4EkX(;
HZtrPm
J0XRyz
Q@VUA]sS
D[{v%io
P4#7Gw
cCn5zeO
6=jKF
}8FKZ@
$UnEl<
5Df$A1n
*_s$^t7
t`@R0e3|_
v0R0C
1pT?On
zu)}kDx
x`~~g"Y
(v'l=C
YPE-+r
#r]eeJX2q,
ZA@P2C!
<\,JVu&b
9BP'm~
_=Ud<ML
m"Ym[R
D{eUVA
Tq U+V
RbqrBz
vd51l*
8*l`*
8&q9$Z
mk/%!PE0
'L\1Gt
P7W{aHX<]
`3V|gN1
j!p8^G
X23,-@
CO\IoSoP
6/w`t@bt
'K#3Z0
IjF#JU
7bp=|1
L? nk5]JtfH7
|EvMF
X<2R@K.
P@mpZz
Zh5-eS
g75eKf/.SG_
^rg3("
u~Hdc+
;nrN.p
\yq0P\
Aet4p
VbeBZe
0f:H"S
{B?9QB
0>Jc/|
@HcQs6
#1o)'W[
$.:lD[
0mT}Mv
'jh7$7n
u^#7q0Q
OX7 &QE
GfsIK
>7GUhi
7DnR"h
)5!,HR
rAp(#
w*@(63d
}",;=l
~ScEUac
9H%-n|
|frF.j
LS`v.D
B|Xd'_
yo1'0z
(qm*i%p
8/-1S/
h4tb{s
E4nSs$hX
7)S6#A
xy2tV-
VKnuX7}!
P)FoK*I^h>
'Re7fy
e^TB@h
Z$7I?T
}ffH7r
Zz`kvR
/(5~#$5
=AE(O&9D
9JN.=:
NPz-0)~g)4
.)RO~M
]g47l
(iV97N|
ZLTEK[
w\e)jh
>V_DU4
^OuR>A
avUxd:c
$=+IH6
O&]aB>v
|J#2.0s
q:4:@a
^b-FuO]Nw
.gL%2w
-~jHql
UC5p9r
]h?f%U
{J<AA0
a[Os@?
cs'c:$
2Zi7!Z>gj
ko^Pj'K
%Y$p*%@#
fZe}Zb
82c;[)
Co97go
ydb>']
]9E5%3
!!kEE.C
{w*YMS
&HwTe$
3UOja??
TuFo5:X_
PJin|Oim?C
fVGf15
Q4B)&C.
:\Fx, v
c[qy>J
:8$O<W
*]J*O
cZ|(l&
f:"rvRS
I;(Q=~
}O+OwQ
3,F8J0Pa
CiVLC)jX
3ZIoWR
YvBrj<
Ow$8"FI5
XZ[]~P
Fw~V/_
6k*i/,G
SEEZNZ
]u"5!yx
,wT.5
Xf-]v^@c
cP?z]@
uFP)X'Q
WW7N :7
?Mx.njU
$@i<,f
_ .d4
KzjmQ}T"
Xo`5r-BI
d/yp0T
fwlMvA
%74"k4!
`TYjV%{[m
4kE%R'
}xPk([q2s
NB"6#v
=VUrYG>
A`U]ul,C
EncodePointer
DecodePointer
FlsFree
FlsSetValue
FlsGetValue
FlsAlloc
?ZEM-'^
?{yK+;
?765@Z
?e')lW
UUUUUU
?333333
?333333
?UUUUUU
?$rxxx
CorExitProcess
runtime error
TLOSS error
SING error
DOMAIN error
An application has made an attempt to load the C runtime library incorrectly.
Please contact the application's support team for more information.
- Attempt to use MSIL code from this assembly during native code initialization
This indicates a bug in your application. It is most likely the result of calling an MSIL-compiled (/clr) function from a native constructor or from DllMain.
- not enough space for locale information
- Attempt to initialize the CRT more than once.
This indicates a bug in your application.
- CRT not initialized
- unable to initialize heap
- not enough space for lowio initialization
- not enough space for stdio initialization
- pure virtual function call
- not enough space for _onexit/atexit table
- unable to open console device
- unexpected heap error
- unexpected multithread lock error
- not enough space for thread data
This application has requested the Runtime to terminate it in an unusual way.
Please contact the application's support team for more information.
- not enough space for environment
- not enough space for arguments
- floating point support not loaded
Microsoft Visual C++ Runtime Library
<program name unknown>
Runtime Error!
Program:
_nextafter
_hypot
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
GAIsProcessorFeaturePresent
KERNEL32
GetProcessWindowStation
GetUserObjectInformationA
GetLastActivePopup
GetActiveWindow
MessageBoxA
USER32.DLL
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
HH:mm:ss
dddd, MMMM dd, yyyy
MM/dd/yy
December
November
October
September
August
February
January
Saturday
Friday
Thursday
Wednesday
Tuesday
Monday
Sunday
SunMonTueWedThuFriSat
JanFebMarAprMayJunJulAugSepOctNovDec
1#QNAN
1#SNAN
bad allocation
rugazozurepawuvenoni kosenaninovikekusokaz cesagit
cihumuniyulomavivowufosusecim voyicerocagovuhacidaxulicawo siwupajumur pafayoxadajidahudeyaxisiyu
gavazetunepel
wenukusatubenufuv
husara sokulanihexesifegu godevagemomarewubodeh fuhoyexe gatuxilu
kernel32.dll
LocalAlloc
xawomoremaletuhozikovizigo xanolakolumetavaxa vejibabuzay
C:\gol.pdb
GetSystemDefaultLangID
EnumDateFormatsExW
MoveFileExA
EndUpdateResourceW
InterlockedIncrement
InterlockedDecrement
ReadConsoleOutputAttribute
GetSystemWindowsDirectoryW
GetEnvironmentStringsW
GetUserDefaultLCID
WaitForSingleObject
SetConsoleScreenBufferSize
GetComputerNameW
SetEvent
GetConsoleAliasesLengthA
CreateActCtxW
GetConsoleCP
LocalShrink
ReadConsoleOutputW
GetVersionExW
GetFileAttributesA
lstrcpynW
GetConsoleAliasW
VerifyVersionInfoA
WriteConsoleW
WritePrivateProfileSectionW
IsBadWritePtr
ReadFile
GetModuleFileNameW
GetCompressedFileSizeA
GetSystemDirectoryA
CreateFileW
lstrcatA
GetACP
GetVolumePathNameA
lstrlenW
SetConsoleTitleA
VerifyVersionInfoW
InterlockedExchange
GetLastError
GetProcAddress
EnterCriticalSection
GetLocalTime
GetProcessId
LocalAlloc
SetCalendarInfoW
DnsHostnameToComputerNameA
CreateTapePartition
SetConsoleDisplayMode
SetFileApisToANSI
GlobalGetAtomNameW
SetEnvironmentVariableA
GetModuleHandleA
UpdateResourceW
CancelTimerQueueTimer
GetConsoleTitleW
BuildCommDCBA
VirtualProtect
PeekConsoleInputA
FindFirstVolumeW
KERNEL32.dll
RealGetWindowClassA
USER32.dll
GetStartupInfoW
HeapAlloc
UnhandledExceptionFilter
SetUnhandledExceptionFilter
GetModuleHandleW
TlsGetValue
TlsAlloc
TlsSetValue
TlsFree
SetLastError
GetCurrentThreadId
ExitProcess
WriteFile
GetStdHandle
GetModuleFileNameA
FreeEnvironmentStringsW
GetCommandLineW
SetHandleCount
GetFileType
GetStartupInfoA
DeleteCriticalSection
HeapCreate
VirtualFree
HeapFree
QueryPerformanceCounter
GetTickCount
GetCurrentProcessId
GetSystemTimeAsFileTime
RaiseException
TerminateProcess
GetCurrentProcess
IsDebuggerPresent
LeaveCriticalSection
VirtualAlloc
HeapReAlloc
GetCPInfo
GetOEMCP
IsValidCodePage
RtlUnwind
LoadLibraryA
InitializeCriticalSectionAndSpinCount
GetLocaleInfoA
GetStringTypeA
MultiByteToWideChar
GetStringTypeW
LCMapStringA
WideCharToMultiByte
LCMapStringW
HeapSize
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
@m42P<
EqPO#f
mkc)U|?
<W^tJ21
#LQo<0@~U
CCCCCCCCCCCCCCCCCCCCCCCCCCC
CCCCCCCCCCCC
CCCCCCCCCCCX
CCCCCCCCCC
CCCCCCCCCj^
CCCCCC
%CCCCCCC
hCCCCCCC
CCCCCCCC
r-CCCCCCCC
gCCCCCCCCCCCC
CCCCCCCCCCC
CCCCCCCCCCCC
;CCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCC
E][[nE\
p''@+>
0[,,,A/
```````````````````````````````````````````````````````````````````````````````````
```````````````````
*```````K
```````````
i$`````````K
FK````````
```````
s```````
s```````KO
```````0i#tUC
````````2F
`````````
K``````````*
1````````````
5``````````````
4FZ``````````````W
``````````````1
i:Fld/c9
````````````````
a`````````````````\
`````````````````
`````````````````
`````````````````
eH```````````````````
`````````````````````Z
````````````````````````````````````````````````````````````````````````````````````````````````````````````````````````````````````````````````````````````````````````````````````````````````````````````````````````````````````````````````
F7+8s0\
jDHi/8Q
1Wj@&v
Sy{&5MrP
.Jb9 u
,<i>*y
KERNEL32.DLL
mscoree.dll
((((( H
h(((( H
H
xeverubutudih xitiradufumijexetakovilizar
pujonotetudafawufojiy dijebecerebopitaruvazonozaji riferujehonosenipah
xaxelivozi vos
nalovitivexedotarej
mimuburenagaxiza
lifaderotirojilotovuziyezucer
ERRORDIALOG
VS_VERSION_INFO
StringFileInform
081564c6
InternalName
sigzmuegeke.ehi
Copyright
Copyrighz (C) 2021, fodkageta
ProductVersion
29.51.22.11
VarFileInfo
Translation
Error!
Select One:
&Retry
&Abort
&Ignore
2Tewicaholax cigijom nuxazohoxo hacuyoruji pucameto
Yapanuj juvu;Woseh xawusu valosuj yav wuyogemir vewoyameb voyehef robexe@Dica rumegebama napa cazirem meke wolepalozi fizoyosuya gihotobi(Piyilukalila vipoxutudadana yenozimabavo
Cixirarideboga cusuy vorihup
Hugibohawifu popepivu
cGujepavuru mojenunutilono nimezexuraw sicu zopob jewuxolegetivok tujacatarof teyutonibabofoz nicume(Sihohoxuka vuti hinupapamuxabe wovopufeh1Xaxeriwaz habojiv buw barulafefune xeyuxi toyebup
Juz vasux dihimu zuyiworocavec
Topegigorazezoy jukec
Kiyolajak)Jonoseyegir dumiwehoxihugu noruduyaxuzuca
[Jipahusoyidudel ceborecorebu surinunolu gihimisigubaw wajajuzuhoj bucogiwimo mizituxiwibibi
Antivirus Signature
Bkav Clean
Lionic Clean
Elastic malicious (high confidence)
MicroWorld-eScan Clean
CMC Clean
CAT-QuickHeal Clean
McAfee Artemis!970DAC7D9D00
Cylance Unsafe
Zillya Clean
Sangfor Trojan.Win32.Save.a
K7AntiVirus Trojan ( 0056f9be1 )
BitDefender Clean
K7GW Trojan ( 0056f9be1 )
Cybereason Clean
Baidu Clean
Cyren Clean
Symantec ML.Attribute.HighConfidence
ESET-NOD32 Clean
APEX Malicious
Paloalto Clean
ClamAV Clean
Kaspersky VHO:Backdoor.Win32.Agent.gen
Alibaba Clean
NANO-Antivirus Clean
ViRobot Clean
Tencent Clean
Ad-Aware Clean
Emsisoft Clean
Comodo Clean
F-Secure Clean
DrWeb Clean
VIPRE Clean
TrendMicro Mal_HPGen-50
McAfee-GW-Edition BehavesLike.Win32.Emotet.dc
FireEye Generic.mg.970dac7d9d006a95
Sophos ML/PE-A
SentinelOne Static AI - Malicious PE
GData Clean
Jiangmin Clean
Webroot Clean
Avira Clean
MAX Clean
Antiy-AVL Clean
Kingsoft Clean
Gridinsoft Clean
Arcabit Clean
SUPERAntiSpyware Clean
ZoneAlarm Clean
Microsoft Trojan:Win32/Wacatac.B!ml
Cynet Malicious (score: 100)
AhnLab-V3 Clean
Acronis suspicious
VBA32 BScope.Trojan.Eb
ALYac Clean
TACHYON Clean
Malwarebytes Clean
Panda Clean
Zoner Clean
TrendMicro-HouseCall Mal_HPGen-50
Rising Trojan.Kryptik!1.B40D (CLASSIC)
Yandex Clean
Ikarus Clean
MaxSecure Trojan.Malware.300983.susgen
Fortinet Clean
BitDefenderTheta Gen:NN.ZexaF.34058.rq0@auH0dYhG
Avast Clean
CrowdStrike win/malicious_confidence_100% (D)
Qihoo-360 HEUR/QVM10.1.4663.Malware.Gen
No IRMA results available.