Static | ZeroBOX

PE Compile Time

2021-01-26 11:07:20

PDB Path

C:\luvet\hifor.pdb

PE Imphash

02fed18d5788c3d9bcc1897631bb2a01

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x000110f1 0x00011200 7.57708591796
.rdata 0x00013000 0x00004085 0x00004200 4.35394683849
.data 0x00018000 0x0288f238 0x00003a00 0.861724022978
.rsrc 0x028a8000 0x0000c598 0x0000c600 6.69538333925

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x028b3920 0x00000468 None SUBLANG_SYS_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x028b3920 0x00000468 None SUBLANG_SYS_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x028b3920 0x00000468 None SUBLANG_SYS_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x028b3920 0x00000468 None SUBLANG_SYS_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x028b3920 0x00000468 None SUBLANG_SYS_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x028b3920 0x00000468 None SUBLANG_SYS_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x028b3920 0x00000468 None SUBLANG_SYS_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x028b3920 0x00000468 None SUBLANG_SYS_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x028b3920 0x00000468 None SUBLANG_SYS_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x028b3920 0x00000468 None SUBLANG_SYS_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x028b3920 0x00000468 None SUBLANG_SYS_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x028b3920 0x00000468 None SUBLANG_SYS_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x028b3920 0x00000468 None SUBLANG_SYS_DEFAULT GLS_BINARY_LSB_FIRST
RT_STRING 0x028b4250 0x00000342 None SUBLANG_SYS_DEFAULT data
RT_STRING 0x028b4250 0x00000342 None SUBLANG_SYS_DEFAULT data
RT_ACCELERATOR 0x028b3df0 0x00000030 None SUBLANG_SYS_DEFAULT data
RT_GROUP_ICON 0x028b3d88 0x00000068 None SUBLANG_SYS_DEFAULT data
RT_GROUP_ICON 0x028b3d88 0x00000068 None SUBLANG_SYS_DEFAULT data
RT_VERSION 0x028b3e50 0x000001b4 LANG_NEUTRAL SUBLANG_NEUTRAL data
None 0x028b3e40 0x0000000a LANG_NEUTRAL SUBLANG_NEUTRAL data
None 0x028b3e40 0x0000000a LANG_NEUTRAL SUBLANG_NEUTRAL data
None 0x028b3e40 0x0000000a LANG_NEUTRAL SUBLANG_NEUTRAL data

Imports

Library KERNEL32.dll:
0x41300c WriteConsoleOutputW
0x413010 EndUpdateResourceW
0x41301c GetCurrentProcess
0x413028 WaitForSingleObject
0x413030 GetModuleHandleW
0x413034 EnumCalendarInfoExW
0x413038 SetThreadUILanguage
0x413040 GetConsoleTitleA
0x413048 GetConsoleCP
0x41304c ReadConsoleInputA
0x413054 lstrcpynW
0x41305c GetFileAttributesW
0x413064 WriteConsoleW
0x413068 IsBadWritePtr
0x41306c GetMailslotInfo
0x413070 lstrcatA
0x413074 lstrlenW
0x413078 FlushFileBuffers
0x41307c InterlockedExchange
0x413088 SetLastError
0x41308c GetProcAddress
0x413090 PeekConsoleInputW
0x413094 EnumDateFormatsExA
0x41309c LocalLock
0x4130a4 GlobalGetAtomNameA
0x4130a8 ResetEvent
0x4130ac GetLocalTime
0x4130b0 LoadLibraryA
0x4130b4 LocalAlloc
0x4130b8 SetConsoleOutputCP
0x4130bc SetFileApisToANSI
0x4130c0 GetOEMCP
0x4130c4 GetModuleHandleA
0x4130c8 HeapSetInformation
0x4130cc GetCPInfoExA
0x4130d0 FindFirstVolumeA
0x4130d8 GetCurrentProcessId
0x4130e0 GetModuleFileNameW
0x4130f0 HeapAlloc
0x4130f4 GetCommandLineA
0x4130f8 GetStartupInfoA
0x4130fc RaiseException
0x413100 RtlUnwind
0x413104 Sleep
0x413108 ExitProcess
0x41310c GetLastError
0x413110 WriteFile
0x413114 GetStdHandle
0x413118 GetModuleFileNameA
0x41311c TerminateProcess
0x413120 IsDebuggerPresent
0x413124 HeapFree
0x413130 VirtualFree
0x413134 VirtualAlloc
0x413138 HeapReAlloc
0x41313c HeapCreate
0x413148 WideCharToMultiByte
0x413150 SetHandleCount
0x413154 GetFileType
0x413158 TlsGetValue
0x41315c TlsAlloc
0x413160 TlsSetValue
0x413164 TlsFree
0x413168 GetCurrentThreadId
0x413170 GetTickCount
0x41317c HeapSize
0x413180 GetCPInfo
0x413184 GetACP
0x413188 IsValidCodePage
0x41318c GetLocaleInfoA
0x413190 LCMapStringA
0x413194 MultiByteToWideChar
0x413198 LCMapStringW
0x41319c GetStringTypeA
0x4131a0 GetStringTypeW
Library USER32.dll:
0x4131a8 GetAltTabInfoW

Exports

Ordinal Address Name
1 0x401065 @SetFirstEverVice@8
!This program cannot be run in DOS mode.
`.rdata
@.data
VVVVVV
0WWWWW
0WWWWW
QQSVWd
j h8aA
u&hp8A
0SSSSS
>=Yt1j
j@j ^V
t$h$9A
HtHu4j
s[S;7|G;w
tR99u2
0SSSSS
0SSSSS
URPQQh s@
0A@@Ju
;t$,v-
UQPXY]Y[
t"SS9]
PPPPPPPP
PPPPPPPP
t+WWVPV
KTu9W`
pkwD$(t
G`8Oc2I
e3{Kf
m[]WG?_+
u`z,0$
eLD:U&B
=4<e[6
DfR`_V
`S\,KS
H6w>2k
?*}?3$
"7-pFQ
eRT}!
"8S@sQ
EhGXbPA
}TQ%i-J
$}bags
cj^QT\$eo
|X!z>a7
'_*BsN$
*SDrK3>
HW6l(p
<wrE2*
b51Z;`
82$j"C
~f6U:
TIWl%!E
2|-|/i
l12Q"b
O3}4Y6i
w]:jGG
pj_<5\
e({Wr<v
2+$RB=
Nq3aSm11
^Q!wAt=
I[b9$;
W]wZvt
Yi1^+g
6\^MmK
(U:^`Q4,
h0DyTR
AmPZ~@f
dX"(KhO\
3|>a_
r'sb"J
$BJX+v
6nYbo"
<^t#Xz
z4<_u1
EQ)g1Z
L)%vNA
kEh;XB|
).EFo.
7rm@-$
Z 3[Gf
SpnuF&
}DtmUM
h}@]I`{
%rLgkB
W&={q'
dcx+8g
MH!5^U
[U4dn1
S:DjO
*F!\LSf
Vt9O087
mM."2F
bad allocation
string too long
invalid string position
Unknown exception
CorExitProcess
runtime error
TLOSS error
SING error
DOMAIN error
An application has made an attempt to load the C runtime library incorrectly.
Please contact the application's support team for more information.
- Attempt to use MSIL code from this assembly during native code initialization
This indicates a bug in your application. It is most likely the result of calling an MSIL-compiled (/clr) function from a native constructor or from DllMain.
- not enough space for locale information
- Attempt to initialize the CRT more than once.
This indicates a bug in your application.
- CRT not initialized
- unable to initialize heap
- not enough space for lowio initialization
- not enough space for stdio initialization
- pure virtual function call
- not enough space for _onexit/atexit table
- unable to open console device
- unexpected heap error
- unexpected multithread lock error
- not enough space for thread data
This application has requested the Runtime to terminate it in an unusual way.
Please contact the application's support team for more information.
- not enough space for environment
- not enough space for arguments
- floating point support not loaded
Microsoft Visual C++ Runtime Library
<program name unknown>
Runtime Error!
Program:
EncodePointer
DecodePointer
FlsFree
FlsSetValue
FlsGetValue
FlsAlloc
bad exception
GetProcessWindowStation
GetUserObjectInformationA
GetLastActivePopup
GetActiveWindow
MessageBoxA
USER32.DLL
Complete Object Locator'
Class Hierarchy Descriptor'
Base Class Array'
Base Class Descriptor at (
Type Descriptor'
`local static thread guard'
`managed vector copy constructor iterator'
`vector vbase copy constructor iterator'
`vector copy constructor iterator'
`dynamic atexit destructor for '
`dynamic initializer for '
`eh vector vbase copy constructor iterator'
`eh vector copy constructor iterator'
`managed vector destructor iterator'
`managed vector constructor iterator'
`placement delete[] closure'
`placement delete closure'
`omni callsig'
delete[]
new[]
`local vftable constructor closure'
`local vftable'
`udt returning'
`copy constructor closure'
`eh vector vbase constructor iterator'
`eh vector destructor iterator'
`eh vector constructor iterator'
`virtual displacement map'
`vector vbase constructor iterator'
`vector destructor iterator'
`vector constructor iterator'
`scalar deleting destructor'
`default constructor closure'
`vector deleting destructor'
`vbase destructor'
`string'
`local static guard'
`typeof'
`vcall'
`vbtable'
`vftable'
operator
delete
__unaligned
__restrict
__ptr64
__clrcall
__fastcall
__thiscall
__stdcall
__pascal
__cdecl
__based(
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
HH:mm:ss
dddd, MMMM dd, yyyy
MM/dd/yy
December
November
October
September
August
February
January
Saturday
Friday
Thursday
Wednesday
Tuesday
Monday
Sunday
SunMonTueWedThuFriSat
JanFebMarAprMayJunJulAugSepOctNovDec
bad allocation
hizejikekacuwawidobikopaganinetayizufuluyijoyegixoyobohamepoxedujohuyokuyusu
dapibakazubanukufileture hoyulasato bivefuvoduyuzabotojupakiwoho
fuvawivuyijulona
kernel32.dll
LocalAlloc
VirtualProtect
vofovocadicupupelirujifayas bitenipuselucimixofeyolujuc gukagigu
lohukiwazitasixubalicacefome fodaxe hifisudefiziyigalejajarinekaham gokatunimefop liwiwirarup
RSDS)bh
C:\luvet\hifor.pdb
GetSystemDefaultLangID
GetConsoleAliasesLengthW
WriteConsoleOutputCharacterA
BuildCommDCBAndTimeoutsA
WriteConsoleOutputW
EndUpdateResourceW
InterlockedIncrement
InterlockedDecrement
GetCurrentProcess
GetSystemWindowsDirectoryW
SetEnvironmentVariableW
WaitForSingleObject
GetSystemDefaultLCID
GetModuleHandleW
EnumCalendarInfoExW
SetThreadUILanguage
GetConsoleAliasesLengthA
GetConsoleTitleA
GetEnvironmentStrings
GetConsoleCP
ReadConsoleInputA
SetVolumeMountPointA
lstrcpynW
SetConsoleCursorPosition
GetFileAttributesW
SetTimeZoneInformation
WriteConsoleW
IsBadWritePtr
GetMailslotInfo
GetModuleFileNameW
lstrcatA
lstrlenW
FlushFileBuffers
InterlockedExchange
FillConsoleOutputCharacterW
ChangeTimerQueueTimer
SetLastError
GetProcAddress
PeekConsoleInputW
EnumDateFormatsExA
CreateTimerQueueTimer
LocalLock
EnterCriticalSection
GlobalGetAtomNameA
ResetEvent
GetLocalTime
LoadLibraryA
LocalAlloc
SetConsoleOutputCP
SetFileApisToANSI
GetOEMCP
GetModuleHandleA
HeapSetInformation
GetCPInfoExA
FindFirstVolumeA
DeleteTimerQueueTimer
GetCurrentProcessId
GetConsoleProcessList
KERNEL32.dll
GetAltTabInfoW
USER32.dll
UnhandledExceptionFilter
SetUnhandledExceptionFilter
HeapAlloc
GetCommandLineA
GetStartupInfoA
RaiseException
RtlUnwind
ExitProcess
GetLastError
WriteFile
GetStdHandle
GetModuleFileNameA
TerminateProcess
IsDebuggerPresent
HeapFree
DeleteCriticalSection
LeaveCriticalSection
VirtualFree
VirtualAlloc
HeapReAlloc
HeapCreate
FreeEnvironmentStringsA
FreeEnvironmentStringsW
WideCharToMultiByte
GetEnvironmentStringsW
SetHandleCount
GetFileType
TlsGetValue
TlsAlloc
TlsSetValue
TlsFree
GetCurrentThreadId
QueryPerformanceCounter
GetTickCount
GetSystemTimeAsFileTime
InitializeCriticalSectionAndSpinCount
HeapSize
GetCPInfo
GetACP
IsValidCodePage
GetLocaleInfoA
LCMapStringA
MultiByteToWideChar
LCMapStringW
GetStringTypeA
GetStringTypeW
femofozupu.exe
@SetFirstEverVice@8
.?AVlogic_error@std@@
.?AVlength_error@std@@
.?AVout_of_range@std@@
.?AVtype_info@@
.?AVbad_exception@std@@
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
.?AVexception@std@@
.?AVbad_alloc@std@@
8888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888
88888888888888888888888888888888888888
888888888888888888888888888888888888
D888888888888888888888888888888888
rHb8888888888888888888888888888888
6L888888888888888888888888888888
288888888888888888888888888888
288888888888888888888888888888F
288888888888888888888888888888
>888888888888888888888888888888X&|;
5888888888888888888888888888888
vJVpp{{
8888888888888888888888888888888DLX
8888888888888888888888888888888882
188888888888888888888888888888888888888888K
188888888888888888888888888888888888888888o4
L88888888888888888888888888888888888888888
lL88888888888888888888888888888888888888888Y
t8888888888
D8888888888888888888888888888
.8888888888
8888888888888888888888888888
888888888
8888888888888888888888888888
8888888b1
8888888888888888888888888888
8888888888888888888888888888
8888888888888888888888888888
8888888888888888888888888888
88888888888888888888888888888
88888888888888888888888888888
888888888888888888888888888888
888888888888888888888888888888
t8888888888888888888888888888888
t888888888888888888888888888888888t
88888888888888888888888888888888888888
8888888888888888888888888888888888888888t9
_A28888888888888888888888888888888888888888
2888888888888888888888888888888888888888888or-A288888888888888888888888888888888888888888888o
28888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888
\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\
L\\\\\\\\\\\\\\\\\\\\\\\\\
\\\\\\\\\\\\\\\\\\\\\\\\
!\\\\\\\\\\\\\\\\\\\\\
J\\\\\\\\\\\\\\\\\\\
\\\\\\\\\\\\\\\\\\\
\\\\\\\\\\\\\\\\\\
E\\\\\\\\\\\\\\\\\\\
\\\\\\\\\\\\\\\\\\\@%
\\\\\\\\\\\\\\\\\\\\\
&Z\\\\\\\\\\\\\\\\\\\\\\\\\\\\
^\\\\\\\\\\\\\\\\\\\\\\\\\\\\D
l\\\\\\\\\\\\\\\\\\\\\\\\\\\\}4*7\\\\\\\\
\\\\\\\\\\\\\\\\\\
\\\\\\\
\\\\\\\\\\\\\\\\\\:
\\\\\\
p\\\\\\\\\\\\\\\\\\dm
0{\\\\\\\\\\\\\\\\\\
=\\\\\\\\\\\\\\\\\\
wh\\\\\\\\\\\\\\\\\\\
\\\\\\\\\\\\\\\\\\\
A\\\\\\\\\\\\\\\\\\\\
\\\\\\\\\\\\\\\\\\\\\v
j\\\\\\\\\\\\\\\\\\\\\\
\\\\\\\\\\\\\\\\\\\\\\\\\o
\\\\\\\\\\\\\\\\\\\\\\\\\\
\\\\\\\\\\\\\\\\\\\\\\\\\\\\
q\\\\\\\\\\\\\\\\
CD{h*3
!==~020
29H~~0-
(EL|\%,
S:?|y7-
HP[{x;D~
CSd|t+1
FYN|xLI
AZ^xN6:}
)NXn;6C
'RFuzt~
0RB|~1E
&]ayK23~
HX|{{|
#|?-.)_9eh
hR0Rhx
qC:"lN
tssQz`
.Ss>"m
lHLn3:T
Pz~>*u
8YlE*v
W}})9NyS
_2g~~,c
2Md=$z
mscoree.dll
KERNEL32.DLL
((((( H
h(((( H
H
VS_VERSION_INFO
StringFileInform
020564c6
InternalName
sagzmioloke.awi
Copyright
Copyrighz (C) 2021, fudkageta
ProductVersion
7.59.22.123
VarFileInfo
Translation
Higovihupib vomapopacuyote>Dociconifir loze kojotipu hixuginujegisom gahukejicatibe siseg
Heziromexo wideviloz
Gec yeraxewesexe xulafimo
Ligez xasizatofuhifiw munigABunamew xasadezed zoledilupihol kawahuwohil tijukadoyihu funejipi2Wutuca per nivekafidi xopiyepuhocobew kiwesopujaja
bDoxoyani nediwayuza zopukisa gugivabikokono raxicirenelun kusufedo nivameyorowu siboxijefaz bimuxu.Baga lagabuvi gedoluhumasaluc zozahofosut wabaAXowerahero zahogu zaboluza fuhiwohajoyabuv pip nub fudezukeyesigu<Xemalufutidah nowegowasayugu begozod jino jofakut pigaxocanu2Dibifatov gapel fubitatit gigixiyicobo kohefatuzis4Zinuzusekawaw mixegamabujek murehivev nawa yar nipih
Zuzawu nesukorezep jixerifuluh
Antivirus Signature
Bkav Clean
Elastic malicious (high confidence)
MicroWorld-eScan Clean
FireEye Generic.mg.eb7b5911cfc0a95a
CAT-QuickHeal Clean
McAfee Artemis!EB7B5911CFC0
Cylance Unsafe
Zillya Clean
Sangfor Trojan.Win32.Save.a
K7AntiVirus Trojan ( 005813da1 )
BitDefender Clean
K7GW Trojan ( 005813da1 )
Cybereason Clean
Baidu Clean
Cyren W32/Kryptik.EWJ.gen!Eldorado
Symantec ML.Attribute.HighConfidence
ESET-NOD32 Clean
APEX Malicious
Paloalto generic.ml
ClamAV Clean
Kaspersky UDS:Backdoor.Win32.Mokes.gen
Alibaba Clean
NANO-Antivirus Clean
ViRobot Clean
Rising Trojan.Kryptik!1.D8AC (CLASSIC)
Ad-Aware Clean
Sophos ML/PE-A + Troj/Krypt-W
Comodo Clean
F-Secure Clean
DrWeb Clean
VIPRE Clean
TrendMicro Mal_HPGen-50
McAfee-GW-Edition BehavesLike.Win32.Emotet.ch
CMC Clean
Emsisoft Trojan.Crypt (A)
SentinelOne Static AI - Malicious PE
GData Clean
Jiangmin Clean
Webroot Clean
Avira Clean
MAX Clean
Antiy-AVL Clean
Kingsoft Clean
Gridinsoft Clean
Arcabit Clean
SUPERAntiSpyware Clean
ZoneAlarm UDS:DangerousObject.Multi.Generic
Microsoft Trojan:Win32/Sabsik.FL.A!ml
Cynet Malicious (score: 100)
AhnLab-V3 Clean
Acronis suspicious
BitDefenderTheta Gen:NN.ZexaF.34088.jq0@aSImrbeG
TACHYON Clean
VBA32 Clean
Malwarebytes MachineLearning/Anomalous.94%
Panda Clean
Zoner Clean
TrendMicro-HouseCall Mal_HPGen-50
Tencent Clean
Yandex Clean
Ikarus Clean
MaxSecure Clean
Fortinet Clean
AVG FileRepMalware
Avast FileRepMalware
CrowdStrike win/malicious_confidence_100% (D)
No IRMA results available.