Static | ZeroBOX

PE Compile Time

2020-06-26 07:32:41

PDB Path

C:\gudajesigumex-nihuzanugefog-siliwik\yowimajuguj-pasiw\vi.pdb

PE Imphash

dded9f8a501932d43920d95856e3c15b

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x00029554 0x00029600 7.90519485573
.rdata 0x0002b000 0x00004022 0x00004200 4.40808634832
.data 0x00030000 0x0288f258 0x00003a00 0.865588775796
.rsrc 0x028c0000 0x0000c808 0x0000ca00 6.6232193657

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x028cb980 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_ZIMBABWE GLS_BINARY_LSB_FIRST
RT_ICON 0x028cb980 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_ZIMBABWE GLS_BINARY_LSB_FIRST
RT_ICON 0x028cb980 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_ZIMBABWE GLS_BINARY_LSB_FIRST
RT_ICON 0x028cb980 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_ZIMBABWE GLS_BINARY_LSB_FIRST
RT_ICON 0x028cb980 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_ZIMBABWE GLS_BINARY_LSB_FIRST
RT_ICON 0x028cb980 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_ZIMBABWE GLS_BINARY_LSB_FIRST
RT_ICON 0x028cb980 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_ZIMBABWE GLS_BINARY_LSB_FIRST
RT_ICON 0x028cb980 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_ZIMBABWE GLS_BINARY_LSB_FIRST
RT_ICON 0x028cb980 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_ZIMBABWE GLS_BINARY_LSB_FIRST
RT_ICON 0x028cb980 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_ZIMBABWE GLS_BINARY_LSB_FIRST
RT_ICON 0x028cb980 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_ZIMBABWE GLS_BINARY_LSB_FIRST
RT_ICON 0x028cb980 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_ZIMBABWE GLS_BINARY_LSB_FIRST
RT_ICON 0x028cb980 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_ZIMBABWE GLS_BINARY_LSB_FIRST
RT_STRING 0x028cc388 0x0000047a LANG_ENGLISH SUBLANG_ENGLISH_ZIMBABWE data
RT_STRING 0x028cc388 0x0000047a LANG_ENGLISH SUBLANG_ENGLISH_ZIMBABWE data
RT_ACCELERATOR 0x028cbe90 0x00000028 LANG_ENGLISH SUBLANG_ENGLISH_ZIMBABWE data
RT_ACCELERATOR 0x028cbe90 0x00000028 LANG_ENGLISH SUBLANG_ENGLISH_ZIMBABWE data
RT_GROUP_ICON 0x028cbde8 0x00000068 LANG_ENGLISH SUBLANG_ENGLISH_ZIMBABWE data
RT_GROUP_ICON 0x028cbde8 0x00000068 LANG_ENGLISH SUBLANG_ENGLISH_ZIMBABWE data
RT_VERSION 0x028cbef8 0x000001b4 LANG_NEUTRAL SUBLANG_NEUTRAL data
None 0x028cbee8 0x0000000a LANG_NEUTRAL SUBLANG_NEUTRAL data
None 0x028cbee8 0x0000000a LANG_NEUTRAL SUBLANG_NEUTRAL data
None 0x028cbee8 0x0000000a LANG_NEUTRAL SUBLANG_NEUTRAL data
None 0x028cbee8 0x0000000a LANG_NEUTRAL SUBLANG_NEUTRAL data

Imports

Library KERNEL32.dll:
0x42b004 SetLocalTime
0x42b008 WriteConsoleOutputW
0x42b010 GetConsoleAliasA
0x42b018 GetCurrentProcess
0x42b028 WaitForSingleObject
0x42b030 GetModuleHandleW
0x42b034 EnumCalendarInfoExW
0x42b038 SetThreadUILanguage
0x42b03c GetConsoleTitleA
0x42b040 CreateActCtxW
0x42b044 GetConsoleCP
0x42b048 GetSystemDirectoryW
0x42b04c ReadConsoleInputA
0x42b058 GetVersionExW
0x42b05c GetFileAttributesA
0x42b060 lstrcpynW
0x42b06c VerifyVersionInfoA
0x42b070 WriteConsoleW
0x42b074 IsBadWritePtr
0x42b078 GetModuleFileNameW
0x42b07c lstrcatA
0x42b080 GetACP
0x42b084 lstrlenW
0x42b088 FlushFileBuffers
0x42b08c InterlockedExchange
0x42b094 SetLastError
0x42b098 GetProcAddress
0x42b09c PeekConsoleInputW
0x42b0a0 EnumDateFormatsExA
0x42b0a8 LocalLock
0x42b0b4 SetTimerQueueTimer
0x42b0b8 GlobalGetAtomNameA
0x42b0bc ResetEvent
0x42b0c0 LocalAlloc
0x42b0cc GetModuleHandleA
0x42b0d0 HeapSetInformation
0x42b0d4 GetCPInfoExA
0x42b0d8 FindFirstVolumeA
0x42b0dc EndUpdateResourceA
0x42b0e0 GetCurrentProcessId
0x42b0e8 AreFileApisANSI
0x42b0ec GetMailslotInfo
0x42b0f0 LCMapStringW
0x42b0f4 LCMapStringA
0x42b100 HeapAlloc
0x42b104 Sleep
0x42b108 ExitProcess
0x42b10c GetCommandLineA
0x42b110 GetStartupInfoA
0x42b114 RaiseException
0x42b118 RtlUnwind
0x42b11c GetLastError
0x42b120 WriteFile
0x42b124 GetStdHandle
0x42b128 GetModuleFileNameA
0x42b12c TerminateProcess
0x42b130 IsDebuggerPresent
0x42b134 HeapFree
0x42b140 VirtualFree
0x42b144 VirtualAlloc
0x42b148 HeapReAlloc
0x42b14c HeapCreate
0x42b150 TlsGetValue
0x42b154 TlsAlloc
0x42b158 TlsSetValue
0x42b15c TlsFree
0x42b160 GetCurrentThreadId
0x42b164 LoadLibraryA
0x42b178 WideCharToMultiByte
0x42b17c SetHandleCount
0x42b180 GetFileType
0x42b188 GetTickCount
0x42b190 GetCPInfo
0x42b194 GetOEMCP
0x42b198 IsValidCodePage
0x42b19c HeapSize
0x42b1a0 GetLocaleInfoA
0x42b1a4 GetStringTypeA
0x42b1a8 MultiByteToWideChar
0x42b1ac GetStringTypeW
Library USER32.dll:
0x42b1b4 RealGetWindowClassA

Exports

Ordinal Address Name
1 0x401065 @SetFirstEverVice@8
!This program cannot be run in DOS mode.
`.rdata
@.data
VVVVVV
"u|VVV
VVVVVV
VVVVVV
0WWWWW
0WWWWW
QQSVWd
0SSSSS
>=Yt1j
j@j ^V
HtHu4j
s[S;7|G;w
tR99u2
0SSSSS
0SSSSS
URPQQhXs@
0A@@Ju
;t$,v-
UQPXY]Y[
uL9=\>C
PPPPPPPP
PPPPPPPP
t"SS9]
t+WWVPV
V7Z=S'q
Cj!ov
;!Y'Zt
CW.YcMt
B)yN1.BY
'(aS:#
Fc%l(i
+)"S|a
jhIz Y
#4,!$=
GWxAJw"ii
[uTW.R
FPkW}O
vUA6Px
=h`-75H
X|N_t=
tGgOZ\
POkWHI
bd7rTt)*I
\9:P$D
![Z'Ty
HM.nc2e
c,G[}<A
iF|2=v,.
{Skg{P0
ukO{NL
Ps#dE2g
fc(M7n
nZ*z#V
LV$=O_j9
+@/c[pBr
z9&x.3
f9q+7k
t1vJ+y
@+iW#&
]+9N%;#
N*&M8;
c|Iw1(1
@-1op&F
%z9xV_
]3YR)^
!4`$oYlL
<{fTtC
ukd;oM$
Q%dMF|Bk
WzU1-.y
e[AvvT
g^F(rGi
2//I*W
z1!gO`
u!{1R"
PA6*rR
\Qt8was(~Y
y$hm83
{d)&V:
Q9wb(Jp
^/M=:8
_W}wb\x
gl^k^H3
!C}!\5
FRMcf_g
9$*l#1
0T:v]w#k&
??0Inf"
_B)x3&
VSr*90
jVk6SaE
}RZd
78mHcZ
RLwn<2!RC
[q'gFx
u@xSf=
tZvAQ4Z
^ka1~"
4!g4i\
OR%'Y/D
wT5w;b'
DJ+Uau
?jap>JG
|jm7OB
#qH-eX
rMU]}R
|"cWQE%28D
U\D{a
b4`HEn
PR:""N
# -d5g
J8\NI`:K!
UCx!$A
lsXJ<T
i1wnV)
e<V6%@F
*KJoK{
B%C`rl
PA,%]#
a7k,-nn
A\?br_
Du}.E/M|
.-i'IL
})Q`]F[68/
up`O/rI
hqQd<"q
7Ie4'IQ
.90u:-Re_
*?aOu\2
`ZV6BB
SrZ57
\d&?fT
9%Ww)1
Ggqbt2
4B6b;D
^qm]yX
$E/K:|*
!de3,$
:fnX[#eo
.0eV-gP
(EXzu:
hEZOXl"
nH0$+\
GTLTMg5
yQOsJS
s%?fx,J
p*Xay@E
z&rh|8
oK}Y _)
(L@,e-H
p&7ksx
W*/!SVh
VPf<4J
8P%Ja1s
a] 2 VeTBx1
<)at=EE
gy%i*N
tyv7X?
mFdqqV6
N&Pq1oHP{
aN2xCqX
6`AD-X3`JO
)HSU[Ik
(F~]6
:q(PhAf
Dh<5g1v
<z|}tf
tjK)T$
-ls^mN
|1p{jF
e.0<x"Y
_7V(Ug5r
y`o:XM
vEb4,i
:^,<5]
WhN75
,BLa G
Vvn9.V
;`0z48
Baz;/j
On[w>
2\Bu#F|`6]
Vy~D+#
fPDd_G
+0KTm~
$Gk:tvN<
c09(ht
`tAhyC
qdKFsy
RX'v 9
pCf=<@
?Uk$o=X
Yj^N?f
ZZDbe,J6
C8OONm
Z{7nd3b1
@\Syw _
AC%.jZ
fOp?rK
XmF=fC
/,1^k>
P=ak20
r\B!g;-
xeH H5
u7vM*2
r@Yl;/
"Mf0_6
)OF$IPeG
M@cx7L3
xfMa1U{f
[bl1oP
b$y`N>;6
nv-:7tc
TnoD,i
>S6f<.
gRQBG;
^h,tQA
[*YuUb
52_X4~~
i3oog&oC
^s'N7L
9\kDeO
a49SuZ
I<[_Hf
$-DQ=-
K)g@t}+
z6(LiA8
}<Lq-f
*!fh0H_f
!#|G*|
3Oq R&
Mx}Df\
!=N9qO
FDI,#j
q'B"(o^
eA=>Eq
P73;!H
M6x&0+H^
L27ySEF4
][vR_0
"^S}M%,n
ZVG5IL
cRV}tq
bad allocation
string too long
invalid string position
Unknown exception
CorExitProcess
runtime error
TLOSS error
SING error
DOMAIN error
An application has made an attempt to load the C runtime library incorrectly.
Please contact the application's support team for more information.
- Attempt to use MSIL code from this assembly during native code initialization
This indicates a bug in your application. It is most likely the result of calling an MSIL-compiled (/clr) function from a native constructor or from DllMain.
- not enough space for locale information
- Attempt to initialize the CRT more than once.
This indicates a bug in your application.
- CRT not initialized
- unable to initialize heap
- not enough space for lowio initialization
- not enough space for stdio initialization
- pure virtual function call
- not enough space for _onexit/atexit table
- unable to open console device
- unexpected heap error
- unexpected multithread lock error
- not enough space for thread data
This application has requested the Runtime to terminate it in an unusual way.
Please contact the application's support team for more information.
- not enough space for environment
- not enough space for arguments
- floating point support not loaded
Microsoft Visual C++ Runtime Library
<program name unknown>
Runtime Error!
Program:
EncodePointer
DecodePointer
FlsFree
FlsSetValue
FlsGetValue
FlsAlloc
bad exception
GetProcessWindowStation
GetUserObjectInformationA
GetLastActivePopup
GetActiveWindow
MessageBoxA
USER32.DLL
Complete Object Locator'
Class Hierarchy Descriptor'
Base Class Array'
Base Class Descriptor at (
Type Descriptor'
`local static thread guard'
`managed vector copy constructor iterator'
`vector vbase copy constructor iterator'
`vector copy constructor iterator'
`dynamic atexit destructor for '
`dynamic initializer for '
`eh vector vbase copy constructor iterator'
`eh vector copy constructor iterator'
`managed vector destructor iterator'
`managed vector constructor iterator'
`placement delete[] closure'
`placement delete closure'
`omni callsig'
delete[]
new[]
`local vftable constructor closure'
`local vftable'
`udt returning'
`copy constructor closure'
`eh vector vbase constructor iterator'
`eh vector destructor iterator'
`eh vector constructor iterator'
`virtual displacement map'
`vector vbase constructor iterator'
`vector destructor iterator'
`vector constructor iterator'
`scalar deleting destructor'
`default constructor closure'
`vector deleting destructor'
`vbase destructor'
`string'
`local static guard'
`typeof'
`vcall'
`vbtable'
`vftable'
operator
delete
__unaligned
__restrict
__ptr64
__clrcall
__fastcall
__thiscall
__stdcall
__pascal
__cdecl
__based(
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
HH:mm:ss
dddd, MMMM dd, yyyy
MM/dd/yy
December
November
October
September
August
February
January
Saturday
Friday
Thursday
Wednesday
Tuesday
Monday
Sunday
SunMonTueWedThuFriSat
JanFebMarAprMayJunJulAugSepOctNovDec
bad allocation
kabacekivopadezehibide cisedeyobusegetuvufijoxayuti zixoyivenidabihewaluzofamuniher
daxadediha
vuvuwikoviyihuhobive
kernel32.dll
LocalAlloc
VirtualProtect
zevopucujihocufidiwugucunociwe najidus pecahalogajeripezububed
C:\gudajesigumex-nihuzanugefog-siliwik\yowimajuguj-pasiw\vi.pdb
GetConsoleAliasesLengthW
SetLocalTime
WriteConsoleOutputW
InterlockedIncrement
GetConsoleAliasA
InterlockedDecrement
GetCurrentProcess
ReadConsoleOutputAttribute
SetEnvironmentVariableW
GetEnvironmentStringsW
WaitForSingleObject
GetSystemDefaultLCID
GetModuleHandleW
EnumCalendarInfoExW
SetThreadUILanguage
GetConsoleTitleA
CreateActCtxW
GetConsoleCP
GetSystemDirectoryW
ReadConsoleInputA
SetVolumeMountPointA
GetSystemWindowsDirectoryA
GetVersionExW
GetFileAttributesA
lstrcpynW
SetConsoleCursorPosition
SetTimeZoneInformation
VerifyVersionInfoA
WriteConsoleW
IsBadWritePtr
GetMailslotInfo
GetModuleFileNameW
lstrcatA
GetACP
lstrlenW
FlushFileBuffers
InterlockedExchange
FillConsoleOutputCharacterW
SetLastError
GetProcAddress
PeekConsoleInputW
EnumDateFormatsExA
CreateTimerQueueTimer
LocalLock
GetConsoleDisplayMode
EnterCriticalSection
SetTimerQueueTimer
GlobalGetAtomNameA
ResetEvent
LocalAlloc
DnsHostnameToComputerNameA
BeginUpdateResourceA
GetModuleHandleA
HeapSetInformation
GetCPInfoExA
FindFirstVolumeA
EndUpdateResourceA
GetCurrentProcessId
GetConsoleProcessList
AreFileApisANSI
KERNEL32.dll
RealGetWindowClassA
USER32.dll
UnhandledExceptionFilter
SetUnhandledExceptionFilter
HeapAlloc
ExitProcess
GetCommandLineA
GetStartupInfoA
RaiseException
RtlUnwind
GetLastError
WriteFile
GetStdHandle
GetModuleFileNameA
TerminateProcess
IsDebuggerPresent
HeapFree
DeleteCriticalSection
LeaveCriticalSection
VirtualFree
VirtualAlloc
HeapReAlloc
HeapCreate
TlsGetValue
TlsAlloc
TlsSetValue
TlsFree
GetCurrentThreadId
LoadLibraryA
InitializeCriticalSectionAndSpinCount
FreeEnvironmentStringsA
GetEnvironmentStrings
FreeEnvironmentStringsW
WideCharToMultiByte
SetHandleCount
GetFileType
QueryPerformanceCounter
GetTickCount
GetSystemTimeAsFileTime
GetCPInfo
GetOEMCP
IsValidCodePage
HeapSize
GetLocaleInfoA
GetStringTypeA
MultiByteToWideChar
GetStringTypeW
LCMapStringA
LCMapStringW
kupugik.exe
@SetFirstEverVice@8
.?AVlogic_error@std@@
.?AVlength_error@std@@
.?AVout_of_range@std@@
.?AVtype_info@@
.?AVbad_exception@std@@
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
.?AVexception@std@@
.?AVbad_alloc@std@@
7777777777777777777777777777777777777777777777777777777777777777777777777777777777777777777777777777777777777777777777777777777777777777777777777777777777777777777777777777777777777777777777777777777777
7777777777777777777777777
777777777777777777777777Q
P-777777777777777777777e
7777777777777777777
X,7777777777777777777
777777777777777777
7777777777777777777b
7777777777777777777
777777777777777777777
O;F*K7777777777777777777777777777
7777777777777777777777777777
7777777777777777777777777777W
77777777
777777777777777777
7777777^
777777777777777777
777777GV
777777777777777777
777777777777777777t
777777777777777777#]_
fr7777777777777777777
7777777777777777777
77777777777777777777J
777777777777777777777
7777777777777777777777Hj
7777777777777777777777777gh
77777777777777777777777777
7777777777777777777777777777
7777777777777777
"-.{{1&|
#94|s&=
=<~913
/UOzn,2|
)FVzp-E
DRh{z(&{
05U{m-*{
:R|~H[
2F^~v:&|
CSR~}FG|}@B
>^cuO72}
Xkh|}mz
"NSu<.D}^
.NBq{u{
#\_~L14}
Bf[|n>:
c)@AK
5Uunj|
sOO.L!i
,Sq=!k
04p~{3
lHLl28R
6YlD)v
V}|)8MwQ
1Mc;"x
0=lC.}
{7f~~Dm
mscoree.dll
KERNEL32.DLL
((((( H
h(((( H
H
VS_VERSION_INFO
StringFileInform
020564c6
InternalName
sagzmeoloke.iwi
Copyright
Copyrighz (C) 2021, fudkageta
ProductVersion
7.51.22.123
VarFileInfo
Translation
jYakibozeluz pisejovokuhara vutibejeku xilelajo vubicoyozep nap didoxejati yucodar lacobowilu yoyakejugaletTVukuduvehutupi jegijigocox cimomerebewoxag lapuxi sisiwiho lenokuwi mapum dojutokega'Dis nupuriyohuzi latovayufeh hilaxecayeJFininawadic midenabuhucuje yix wodiwixus cax totilesuro laretagol jujopeji
Cijociy lamucom
Cajo zuwetipekeholu
Roxaxufeled
@Hudowav bekopikosa pora bavu wudu poluhuxa balelibetale zisovuciUNunaweseli waviyur hazec zoted xibujevu wuvufewireto nogoroguyopu bukohudejux pabahubZFobamogupuxahu sojo sixinuwixode cocinumemeriwo luwisuxota cetomosocibam tovade xucivinizaSWamilekuciyi suxupekomedox rad dejilaba desiginebi hemuco rivizozeja gali lulobukegDGexavadenos vonowo segega musojikecopahi niguruseregisas joba guvidaEVok fizisumelo fosomacokawoli kiziwihaxexawe gigejodimilafe rera yehubBiyilijogibe figalonevoliro pubi jawiwurafec bohaka fuvayeyopesov ruhasime lipuraxu sogurakulexuhu
Antivirus Signature
Bkav W32.AIDetect.malware2
Lionic Clean
Elastic malicious (high confidence)
MicroWorld-eScan Gen:Variant.Fragtor.9685
FireEye Generic.mg.42fdf557c2eaed4c
CAT-QuickHeal Clean
ALYac Clean
Cylance Unsafe
VIPRE Clean
Sangfor Trojan.Win32.Save.a
K7AntiVirus Trojan ( 0056f9be1 )
BitDefender Gen:Variant.Fragtor.9685
K7GW Trojan ( 0056f9be1 )
Cybereason Clean
BitDefenderTheta Gen:NN.ZexaF.34088.pq0@aakbC7li
Cyren W32/Kryptik.EWJ.gen!Eldorado
Symantec ML.Attribute.HighConfidence
ESET-NOD32 Clean
Baidu Clean
APEX Malicious
Paloalto generic.ml
ClamAV Clean
Kaspersky VHO:Backdoor.MSIL.Agent.gen
Alibaba Clean
NANO-Antivirus Clean
ViRobot Clean
Rising Trojan.Kryptik!1.D8AC (CLASSIC)
Ad-Aware Gen:Variant.Fragtor.9685
Sophos ML/PE-A
Comodo Clean
F-Secure Clean
DrWeb Clean
Zillya Clean
TrendMicro Mal_HPGen-50
McAfee-GW-Edition BehavesLike.Win32.Emotet.dc
CMC Clean
Emsisoft Gen:Variant.Fragtor.9685 (B)
SentinelOne Clean
GData Gen:Variant.Fragtor.9685
Jiangmin Clean
MaxSecure Trojan.Malware.300983.susgen
Avira Clean
MAX malware (ai score=87)
Antiy-AVL Clean
Kingsoft Clean
Gridinsoft Clean
Arcabit Clean
SUPERAntiSpyware Clean
ZoneAlarm Clean
Microsoft Trojan:Win32/Sabsik.TE.B!ml
Cynet Malicious (score: 100)
AhnLab-V3 Clean
Acronis suspicious
McAfee Packed-GDT!42FDF557C2EA
TACHYON Clean
VBA32 BScope.TrojanRansom.Blocker
Malwarebytes Clean
Panda Clean
Zoner Clean
TrendMicro-HouseCall Mal_HPGen-50
Tencent Clean
Yandex Clean
Ikarus Trojan.Crypt
eGambit Unsafe.AI_Score_90%
Fortinet Clean
Webroot Clean
AVG FileRepMetagen [Malware]
Avast FileRepMetagen [Malware]
CrowdStrike win/malicious_confidence_100% (D)
Qihoo-360 HEUR/QVM10.1.61FA.Malware.Gen
No IRMA results available.