Static | ZeroBOX

PE Compile Time

2020-06-15 08:16:09

PDB Path

C:\nakuy\kucocikawot\xixorumadetewa\73-r.pdb

PE Imphash

1809fec2059dccb23891231e67cccfd1

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x0002f960 0x0002fa00 7.84276118811
.rdata 0x00031000 0x00003520 0x00003600 4.18675675136
.data 0x00035000 0x01d1cf4c 0x00002200 2.15889060628
.rsrc 0x01d52000 0x00007430 0x00007600 6.36835932315

Resources

Name Offset Size Language Sub-language File type
FUFAMEDOWU 0x01d58208 0x00000636 LANG_SLOVENIAN SUBLANG_DEFAULT ASCII text, with very long lines, with no line terminators
MORELUFA 0x01d57b80 0x00000685 LANG_SLOVENIAN SUBLANG_DEFAULT ASCII text, with very long lines, with no line terminators
RT_ICON 0x01d576b8 0x00000468 LANG_SLOVENIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x01d576b8 0x00000468 LANG_SLOVENIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x01d576b8 0x00000468 LANG_SLOVENIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x01d576b8 0x00000468 LANG_SLOVENIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x01d576b8 0x00000468 LANG_SLOVENIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x01d576b8 0x00000468 LANG_SLOVENIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_STRING 0x01d58e38 0x000005f2 LANG_SLOVENIAN SUBLANG_DEFAULT data
RT_STRING 0x01d58e38 0x000005f2 LANG_SLOVENIAN SUBLANG_DEFAULT data
RT_STRING 0x01d58e38 0x000005f2 LANG_SLOVENIAN SUBLANG_DEFAULT data
RT_ACCELERATOR 0x01d58870 0x00000030 LANG_SLOVENIAN SUBLANG_DEFAULT data
RT_ACCELERATOR 0x01d58870 0x00000030 LANG_SLOVENIAN SUBLANG_DEFAULT data
RT_GROUP_ICON 0x01d57b20 0x0000005a LANG_SLOVENIAN SUBLANG_DEFAULT data
RT_VERSION 0x01d588a0 0x000001b4 LANG_NEUTRAL SUBLANG_NEUTRAL data

Imports

Library KERNEL32.dll:
0x431000 GetLocaleInfoA
0x431004 SetLocalTime
0x431008 lstrcpynA
0x431014 GetCurrentProcess
0x431020 GetUserDefaultLCID
0x431024 AddConsoleAliasW
0x431028 SetEvent
0x431034 ReadConsoleW
0x431038 WriteFile
0x43103c GetCommandLineA
0x431044 GlobalAlloc
0x431048 ReadConsoleInputA
0x43104c CopyFileW
0x431054 GetComputerNameExA
0x431058 VerifyVersionInfoA
0x43105c WriteConsoleW
0x431060 GetAtomNameW
0x431064 GetCPInfoExW
0x431068 GetProcAddress
0x43106c GetLongPathNameA
0x431070 VerLanguageNameA
0x431078 CreateTapePartition
0x43107c SetConsoleOutputCP
0x431080 GetModuleFileNameA
0x431084 GetOEMCP
0x431088 SetConsoleTitleW
0x43108c GetModuleHandleA
0x431090 PeekConsoleInputA
0x431094 Module32NextW
0x431098 GetCurrentProcessId
0x43109c FindNextVolumeA
0x4310a4 GetStartupInfoA
0x4310a8 TerminateProcess
0x4310b4 IsDebuggerPresent
0x4310b8 GetModuleHandleW
0x4310bc TlsGetValue
0x4310c0 TlsAlloc
0x4310c4 TlsSetValue
0x4310c8 TlsFree
0x4310cc SetLastError
0x4310d0 GetCurrentThreadId
0x4310d4 GetLastError
0x4310d8 Sleep
0x4310dc HeapSize
0x4310e0 ExitProcess
0x4310e4 SetHandleCount
0x4310e8 GetStdHandle
0x4310ec GetFileType
0x4310f4 SetFilePointer
0x4310f8 GetCPInfo
0x4310fc GetACP
0x431100 IsValidCodePage
0x43110c WideCharToMultiByte
0x431110 HeapCreate
0x431114 VirtualFree
0x431118 HeapFree
0x431120 GetTickCount
0x431128 GetConsoleCP
0x43112c GetConsoleMode
0x431130 RaiseException
0x431134 HeapAlloc
0x431138 HeapReAlloc
0x43113c VirtualAlloc
0x431140 LoadLibraryA
0x431148 RtlUnwind
0x43114c SetStdHandle
0x431150 FlushFileBuffers
0x431154 LCMapStringA
0x431158 MultiByteToWideChar
0x43115c LCMapStringW
0x431160 GetStringTypeA
0x431164 GetStringTypeW
0x431168 WriteConsoleA
0x43116c GetConsoleOutputCP
0x431170 CreateFileA
0x431174 CloseHandle

!This program cannot be run in DOS mode.
`.rdata
@.data
8u'VVVV
u&VVVVV
uYVVVV
PWhX'C
HHtXHHt
>If90t
tNIt?It0It
Y;=hZC
j@j ^V
0A@@Ju
Fh=`TC
<+t(<-t$:
+t HHt
>=Yt1j
^SSSSS
j"^SSSSS
uL9=${C
URPQQh
t"SS9]
0SSSSS
PPPPPPPP
0SSSSS
0SSSSS
PPPPPPPP
_VVVVV
^WWWWW
;t$,v-
UQPXY]Y[
t+WWVPV
0SSSSS
_VVVVV
u;hX&C
u,hP&C
*gL?n]
f:y)OR
zSzxm'4
1LMc_@
(f25>M
Ha5@E_
L,xrjS
BwQ!h&
zc[Lt@g
]iQq1S
AP&1o#
;]fsd"
[hCT9o
V;H=t
P{U8>x
"NjQC5
Ua{tk`.4'x
5(tm+\
SF<EAh
|~g|u]
'hHiqj
(797CR
[Wx&Uq9Pg
!<P&Vx
E9:&fn
WAF3lb
z srW
z!0O7?
]V<ikW
9ZT#px3
#J&eT,
Sx'*{7
Gb"k K
>:=Ut`
TKB~6k
[)rYE
[Q_l5E
%=M7u|
ta?mQA
$iHV?uq
*]Jtp&
(A"I+1
jzkM<.
T!knL"
yAIWVL
a&<sqe
4*/98,
09C9&D
B*Y>n[Z
y>^Sy>
!7~J>{
mYD7`.
*&IbxHP
b|)]A&u
`D({ :
NCTh\fL6
;RSlb1i
zXIzZ ?tR
;cYxgD
:wP-T@
LJ/.}82Z
G`v}r/
4v\EqN
$5i/lG
4Z2N>
!L{2WP
< <fV#X=
\.(fc)
04yo+}
'^D!"
8!{67yW
#"_W/#Q
wv^LvW-o
*3MM9-
ar(Eq,Z]
zY)=?Xog4
%\p!&C>#
2o{h1;j
s94l1&
;o}#v
R:O%{-
Qt]{3#
eEj2JO
z.hXZ)
c=$)Y=>
jX[,g&
eL) W{
3V.6Bz
_ZlPDS
swM.hE;
ECWjL=
Wie?!C
Q_I}O&\H
%#307G
5I,eQ"
whxupE
<>^%u
_FXT,
]QezOV{
%KSq7x
hO<au->
{R!CD'
.GHjF!30q
m(lPHRy
t[+6=n
O7T5@o
^Wceo
pLZ(Un
Y8VZzP
2je@<W\
K>[|UkA
>kfzFr8
lb5s9F
v_N~cc
5?[7=<V
Y:5)\3W1B
r&,Nq$
Jd*H1'j
5lfD+1(fE
-IaHX(boA
}q%]~g
nTTCl4R+F
C)dU#c
8N@azTj
j[{S6R
\+ 'NI
F7rkO0
{}|Haj
7rKBV0
$0%5k]
, W/`E
QIf)y]s
"dJ7:)O
x<F/$X
xWg;)|
<6.}^cz#
dkL`Y4
FPd9Sz
C,5j@jO1Z
.GX05G
u8FG!EqV
UY[|$w
P{$ZI.
Vx&5>
Z0yQ8
&C%Q'}
G4hRVI
+WQD|yW=
xI&TE
Tx~{gU
z`/J+Q
G=HZy9
g<P_V$
f%nZ=l7
"]#o+m
#.79+
R0lB505Yn
3p![/N
pfdH'^
&U,jn7XXO
9&>A%L
v&[_A4
ZR41?
AjHhK.![
-Aj6z"/
zuP.|]
_L*%NU}
@fnl=L
5nU\+q2[
t>8z!q
^#P_~~h
y%3%A!n
-z3uQs
f&HaYQ
m@([tY
/%x*gg
+f"!D oQ
{kWj!I=
N:]mFY
Z_E) -
MF)]mf
9dnA<m
L3qj$R,8
^H&84`
P&X%VXp
%PM]db
rwBRq2
I my$
XNp3,Z
v4$H*}
)U>^MG
A["M4.
YY3 ol
+~P%A3i
[%*DL]5
s[(5)u
F2{WXwY
tWp4.JN
rGwg_e
Nc5A?X
U4?v{3
JEManp
[AMT/Kj
_U,W4#
$:YKAy_
"%nOW4
>(Qe%DP
urXS3d)"
)!s*I
6FaeWn
x[yQ0V%]KOx(
qdu"Jw
eh>wKX
/TByjG
"PRJ?O
aXE3@LI
h&'#kr%
5Gb~rZ*
rf&tF?s
*yF"WlBF
A`jfb6
~K~.dKX
|5aP0bj
|2`K2|
tJ.0aF7
q."F/k
Q(ic?9
i-!fK7(
IlM\XhR
N6M|,v
jS$"|`
3p`^oW
^U>>8q
rnVg[#
_td_n
CXRec4
Z}`fdfQ
>L[X^=E
Y#eg4c U
xM>B*~
>{V'q8[
\hZ@Vz
P82YSb
2/\=/Z
hB4Y'X
(null)
`h````
xpxxxx
EncodePointer
DecodePointer
FlsFree
FlsSetValue
FlsGetValue
FlsAlloc
CorExitProcess
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
runtime error
TLOSS error
SING error
DOMAIN error
An application has made an attempt to load the C runtime library incorrectly.
Please contact the application's support team for more information.
- Attempt to use MSIL code from this assembly during native code initialization
This indicates a bug in your application. It is most likely the result of calling an MSIL-compiled (/clr) function from a native constructor or from DllMain.
- not enough space for locale information
- Attempt to initialize the CRT more than once.
This indicates a bug in your application.
- CRT not initialized
- unable to initialize heap
- not enough space for lowio initialization
- not enough space for stdio initialization
- pure virtual function call
- not enough space for _onexit/atexit table
- unable to open console device
- unexpected heap error
- unexpected multithread lock error
- not enough space for thread data
This application has requested the Runtime to terminate it in an unusual way.
Please contact the application's support team for more information.
- not enough space for environment
- not enough space for arguments
- floating point support not loaded
Microsoft Visual C++ Runtime Library
<program name unknown>
Runtime Error!
Program:
`h`hhh
xppwpp
_nextafter
_hypot
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
HH:mm:ss
dddd, MMMM dd, yyyy
MM/dd/yy
December
November
October
September
August
February
January
Saturday
Friday
Thursday
Wednesday
Tuesday
Monday
Sunday
GAIsProcessorFeaturePresent
KERNEL32
GetProcessWindowStation
GetUserObjectInformationA
GetLastActivePopup
GetActiveWindow
MessageBoxA
USER32.DLL
SunMonTueWedThuFriSat
JanFebMarAprMayJunJulAugSepOctNovDec
CONOUT$
1#QNAN
1#SNAN
bad allocation
vabapulopinulivesosaluba
kernel32.dll
LocalAlloc
VirtualProtect
cajiconisapigowakat xevowujozisudu xirodanemewegapukan
C:\nakuy\kucocikawot\xixorumadetewa\73-r.pdb
GetLocaleInfoA
SetLocalTime
lstrcpynA
InterlockedIncrement
InterlockedDecrement
GetCurrentProcess
GetSystemWindowsDirectoryW
GetEnvironmentStringsW
GetUserDefaultLCID
AddConsoleAliasW
SetEvent
GetSystemDefaultLCID
GetFileAttributesExA
ReadConsoleW
WriteFile
GetCommandLineA
GetEnvironmentStrings
GlobalAlloc
ReadConsoleInputA
CopyFileW
DeleteVolumeMountPointW
LeaveCriticalSection
GetComputerNameExA
VerifyVersionInfoA
WriteConsoleW
GetAtomNameW
GetCPInfoExW
GetProcAddress
GetLongPathNameA
VerLanguageNameA
EnterCriticalSection
CreateTapePartition
SetConsoleOutputCP
GetModuleFileNameA
GetOEMCP
SetConsoleTitleW
GetModuleHandleA
PeekConsoleInputA
Module32NextW
GetCurrentProcessId
FindNextVolumeA
KERNEL32.dll
GetStartupInfoA
TerminateProcess
UnhandledExceptionFilter
SetUnhandledExceptionFilter
IsDebuggerPresent
GetModuleHandleW
TlsGetValue
TlsAlloc
TlsSetValue
TlsFree
SetLastError
GetCurrentThreadId
GetLastError
HeapSize
ExitProcess
SetHandleCount
GetStdHandle
GetFileType
DeleteCriticalSection
SetFilePointer
GetCPInfo
GetACP
IsValidCodePage
FreeEnvironmentStringsA
FreeEnvironmentStringsW
WideCharToMultiByte
HeapCreate
VirtualFree
HeapFree
QueryPerformanceCounter
GetTickCount
GetSystemTimeAsFileTime
GetConsoleCP
GetConsoleMode
RaiseException
HeapAlloc
HeapReAlloc
VirtualAlloc
LoadLibraryA
InitializeCriticalSectionAndSpinCount
RtlUnwind
SetStdHandle
FlushFileBuffers
LCMapStringA
MultiByteToWideChar
LCMapStringW
GetStringTypeA
GetStringTypeW
WriteConsoleA
GetConsoleOutputCP
CreateFileA
CloseHandle
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
ZsBMa]]
eV<rrV
jjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjj
jjjjjjjjjjj
Jajjjjjjjjjjv
$jjjjjjjjj
jjjjjjjjjj
jjjjjjjjjjjjjo
jjjjjjjjjjjjj
Zjjjjjjjjjjjjj
jjjrjjjjjjjjj
jjjjjjjjj
/jjjjjjjjj.
jjjjjjjjjTF
' }P>5
)91{~61{
DYSz|RTz
(CB|})A
(B>z?:8
Flp}}AS}
2M`|}:Q}
UZ|~QX
M`_|{DD
M^r{{/.
47~|SO
F]R{~SL
yWXR~|`[z
\jk}{{
(RZzG4K
1ff~O47
Lse|qDE|
TN~}LP~
Givizafaxotuj yur zafegahid cowavasojuresof vibevotugubopid. Rozukobukebi gopewugave gim cituhuwojid. Zojalaxun waxudilokajex xiyoju. Jajirarezoxeh yup fupel luwofexonucoxo bucenuh. Hafopa. Hiru liba buwuv nogejey. Fahaje biwoci nonaz. Piru. Nubidupe husev tokibo bey. Doton hedusoyim vigakogujajazub. Tocofec mevicinigar yavorab siyakahij. Hobudihehot. Gaju rawerekajut zapixec kadonotanafi. Nejijol. Kuducux zedujec heres. Sopokenuw soliwojuyadomux caduyoyohosod vajelo milisu. Vil. Buyevixov mux. Cazidelepoto. Xavotagututiye wezekuceyi lufoyutakinisu xeg. Tid mixuvaronohezo kevunoxewoye lepoyixeno. Viginotofonas. Leyawu budefuva. Kafoxicinutah. Zetobired texahibizarah. Wim pefa husetuw tovovikiheb. Juwet cezorecide zorafucuwaxije. Lazajovayav robogofuxinaxo bixicubebexo vizifema hodehesipevafam. Bugofaretukevu vibuhameyag xixu. Gazuyenuyi. Zovuzigokuwipey hugibasuf hihubi ginecizufatu yuhe. Yasocudexe kafupegozep bucadorurana vanihasonofa xezesikuziyamik. Zuz nifumeyo geyagodabici cofovofenayicap. Jeso. Nonicul
Lup wuhikukufolilox yecagenafomoga dez fefu. Pecovareluxiki fus jeregatiwuzudic zibicu. Bumiy hedafu pagiyoxenigowop nuwi. Ficufatoxiwi juyahizirak kiv pubafevi rizorasewicasut. Rutovuxayiso seyiyupixivusi ziyejiy xojocuzusez. Conatefigino wekavonodoxubas tenugulekirub. Gowubifed zika robukego. Hucukulam. Ludinifabaweru. Cepimoj kolinahor habikewok rinocixewewoza. Woc kikejedisivuy lucovulepatemo. Wawadizim nasapec gisozujugevuyo cozucukahovo jotexedolo. Lasesesiloko yeja yutugayi. Zawawotul jopim lecolino lozikamo rebuxevatuxuwa. Sim xipuwo xijuromigev bucul doxoyof. Xunevofuwifan vukicafuzise seci hubomabahapax. Kezemidobayatop wib balu gibor. Xevoyikedibeze riseriben. Nevutedozivaber pajoxomezopego vufehapev pikayonani cijejexe. Dipulebat gapuzogici lod kac xezeda. Tasizijiw beceneg gakuk noxeyapo wos. Yasoxu toxefa. Pujidi fatego. Disevip xot veh bedifimur napugosomarin. Duyaxekel fotokapokayuz baror nuhixu. Dihujetocijoc tewu xajadobeh piyepewuke. Fey rezibenecawane hatisaledojoze bomugetibiz wozihigubah
(null)
KERNEL32.DLL
mscoree.dll
((((( H
h(((( H
H
ruhidukil
womisavisidecuxaheloxajisiwocu
xobuhegonitisihiyovehob
MORELUFA
FUFAMEDOWU(
VS_VERSION_INFO
StringFileInform
020264c6
InternalName
sajbmoumunu.ape
Copyright
Copyrighz (C) 2021, fudkagata
ProductVersion
7.59.29.38
VarFileInfo
Translation
Tunejaj limopi riturunoy
YefuvofiHNaxiwozawahozov tilavalivaf sadisuvayi hababozojiz kiveri raj hidi conov
Yubitofa
VMapetezino vid mixebemiperuhip yisuso rekusonalufuw vanicekeselure miki gowimupinukuno
GehifirelemarKRepigebapuh wupotodohutigu siso nejacahizeyade sonoli nurotoy lekevocej cuh
Loroveponej
Vuzuwohov>Picet jizexedobiya xakoli boruzufazul hijim gomerozen nevofefuVGuhaxabehudesa kolobazukap pepehopuxiwet piw yaxukorebubada kegife vibatef juhe raxuda
Tameho
FNohesec hazezibobuhab bejajehijozata larinepesunuda bepoz gevaherejuwu/Cuhivogi mufiw sazisivodo dufanet vep nafawepahODesuc wikujinujok wuzam xuteve kefemikeguyaton tehifuvu halogo yup kopopidozawaQWib rifowun hahu yumejekewezi gecapafazo weg tuzutedixek volijiye zotisatosawalohOFiwiviromewaw fejepepimunah mobiweboy werituta palezahatudosup nexalik yodariba
DoxopepJToranixexir sij noratosojapibop zepanu hovahij riyokegeki jiloloxo lavawuz
$Xujipizelo sudemefa pivu sotomulayil Bumi mifomamababuh xiwe sekofeya.Rehufunibaye yomanajeno mibububa firuxoginidugAHeromi hahinilike kizulus pas yoradezagayo tuxepahata dosohatefoh2Kulap vuwijidaxoyal denofoyuso tiyaxokoxaj zivotejOTocudu bumugomewaketep vuy duwawo xicuz duboxejot yowupil xoxec calicekacohaduh
Antivirus Signature
Bkav W32.AIDetect.malware1
Lionic Clean
Elastic malicious (high confidence)
DrWeb Clean
MicroWorld-eScan Gen:Variant.Fragtor.16772
FireEye Generic.mg.5dc89acaae4edda1
CAT-QuickHeal Clean
ALYac Gen:Variant.Jaik.47587
Cylance Unsafe
VIPRE Clean
Sangfor Trojan.Win32.Save.a
K7AntiVirus Trojan ( 0056ac331 )
BitDefender Gen:Variant.Fragtor.16772
K7GW Trojan ( 0056ac331 )
Cybereason malicious.5f8098
BitDefenderTheta Gen:NN.ZexaF.34126.pq0@a4d328lc
Cyren W32/Kryptik.EWJ.gen!Eldorado
ESET-NOD32 Clean
APEX Malicious
Paloalto Clean
ClamAV Clean
Kaspersky UDS:DangerousObject.Multi.Generic
Alibaba Clean
NANO-Antivirus Clean
ViRobot Clean
Rising Trojan.Generic@ML.80 (RDML:c19SzFPWF6Z/9YIKMklIHg)
Ad-Aware Gen:Variant.Fragtor.16772
Emsisoft Gen:Variant.Fragtor.16772 (B)
Comodo Clean
F-Secure Clean
Baidu Clean
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition BehavesLike.Win32.Worm.dc
CMC Clean
Sophos ML/PE-A
SentinelOne Static AI - Malicious PE
Jiangmin Clean
eGambit Unsafe.AI_Score_85%
Avira Clean
MAX malware (ai score=80)
Antiy-AVL Clean
Kingsoft Clean
Microsoft Ransom:Win32/StopCrypt.MUK!MTB
Gridinsoft Clean
Arcabit Trojan.Fragtor.D4184
SUPERAntiSpyware Clean
ZoneAlarm Clean
GData Gen:Variant.Fragtor.16772
Cynet Malicious (score: 100)
AhnLab-V3 Clean
Acronis suspicious
McAfee Artemis!5DC89ACAAE4E
TACHYON Clean
VBA32 Clean
Malwarebytes Clean
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Tencent Clean
Yandex Clean
Ikarus Clean
MaxSecure Trojan.Malware.300983.susgen
Fortinet Clean
Webroot Clean
AVG Win32:TrojanX-gen [Trj]
Avast Win32:TrojanX-gen [Trj]
CrowdStrike win/malicious_confidence_100% (D)
No IRMA results available.