Static | ZeroBOX

PE Compile Time

2021-03-13 00:32:51

PDB Path

C:\muwizowefoni\dabajuwakeju\borufekihi10\sumaketunis7.pdb

PE Imphash

a64eb66b7a412a3ebf76d0c2b5dc309f

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x00030c62 0x00030e00 7.82325534803
.rdata 0x00032000 0x00003e22 0x00004000 4.31251844892
.data 0x00036000 0x01d1d008 0x00002200 2.2447756303
.rsrc 0x01d54000 0x000073c0 0x00007400 6.4467222076

Resources

Name Offset Size Language Sub-language File type
FUFAMEDOWU 0x01d5a208 0x00000636 LANG_SPANISH SUBLANG_SPANISH_NICARAGUA ASCII text, with very long lines, with no line terminators
MORELUFA 0x01d59b80 0x00000685 LANG_SPANISH SUBLANG_SPANISH_NICARAGUA ASCII text, with very long lines, with no line terminators
RT_ICON 0x01d596b8 0x00000468 LANG_SPANISH SUBLANG_SPANISH_NICARAGUA GLS_BINARY_LSB_FIRST
RT_ICON 0x01d596b8 0x00000468 LANG_SPANISH SUBLANG_SPANISH_NICARAGUA GLS_BINARY_LSB_FIRST
RT_ICON 0x01d596b8 0x00000468 LANG_SPANISH SUBLANG_SPANISH_NICARAGUA GLS_BINARY_LSB_FIRST
RT_ICON 0x01d596b8 0x00000468 LANG_SPANISH SUBLANG_SPANISH_NICARAGUA GLS_BINARY_LSB_FIRST
RT_ICON 0x01d596b8 0x00000468 LANG_SPANISH SUBLANG_SPANISH_NICARAGUA GLS_BINARY_LSB_FIRST
RT_ICON 0x01d596b8 0x00000468 LANG_SPANISH SUBLANG_SPANISH_NICARAGUA GLS_BINARY_LSB_FIRST
RT_STRING 0x01d5adc8 0x000005f2 LANG_SPANISH SUBLANG_SPANISH_NICARAGUA data
RT_STRING 0x01d5adc8 0x000005f2 LANG_SPANISH SUBLANG_SPANISH_NICARAGUA data
RT_STRING 0x01d5adc8 0x000005f2 LANG_SPANISH SUBLANG_SPANISH_NICARAGUA data
RT_ACCELERATOR 0x01d5a870 0x00000030 LANG_SPANISH SUBLANG_SPANISH_NICARAGUA data
RT_ACCELERATOR 0x01d5a870 0x00000030 LANG_SPANISH SUBLANG_SPANISH_NICARAGUA data
RT_GROUP_ICON 0x01d59b20 0x0000005a LANG_SPANISH SUBLANG_SPANISH_NICARAGUA data
RT_VERSION 0x01d5a8a0 0x000001b4 LANG_NEUTRAL SUBLANG_NEUTRAL data

Imports

Library KERNEL32.dll:
0x432000 SetLocalTime
0x432008 lstrcpynA
0x432010 ReadConsoleA
0x432018 GetCurrentProcess
0x432020 GetUserDefaultLCID
0x432024 SetEvent
0x432028 GetCommandLineA
0x432038 GetLocaleInfoA
0x43203c SetConsoleTitleA
0x432040 GetProcAddress
0x432044 PeekConsoleInputW
0x43204c GetAtomNameA
0x432050 WriteConsoleA
0x432054 LocalAlloc
0x432058 SetConsoleOutputCP
0x43205c GetModuleFileNameA
0x432060 GetOEMCP
0x432064 GetModuleHandleA
0x43206c GetCPInfoExA
0x432070 Module32Next
0x432074 GetCurrentProcessId
0x432078 AddConsoleAliasA
0x43207c VerifyVersionInfoA
0x432080 GetStartupInfoA
0x432084 TerminateProcess
0x432090 IsDebuggerPresent
0x432094 GetModuleHandleW
0x432098 TlsGetValue
0x43209c TlsAlloc
0x4320a0 TlsSetValue
0x4320a4 TlsFree
0x4320a8 SetLastError
0x4320ac GetCurrentThreadId
0x4320b0 GetLastError
0x4320b4 Sleep
0x4320b8 HeapSize
0x4320bc ExitProcess
0x4320c0 HeapFree
0x4320c4 SetFilePointer
0x4320c8 WriteFile
0x4320cc GetStdHandle
0x4320d8 WideCharToMultiByte
0x4320dc SetHandleCount
0x4320e0 GetFileType
0x4320e8 HeapCreate
0x4320ec VirtualFree
0x4320f4 GetTickCount
0x4320fc GetConsoleCP
0x432100 GetConsoleMode
0x432104 GetCPInfo
0x432108 GetACP
0x43210c IsValidCodePage
0x432110 RaiseException
0x432114 HeapAlloc
0x432118 HeapReAlloc
0x43211c VirtualAlloc
0x432120 LoadLibraryA
0x432128 RtlUnwind
0x43212c SetStdHandle
0x432130 FlushFileBuffers
0x432134 GetConsoleOutputCP
0x432138 WriteConsoleW
0x43213c MultiByteToWideChar
0x432140 LCMapStringA
0x432144 LCMapStringW
0x432148 GetStringTypeA
0x43214c GetStringTypeW
0x432150 CreateFileA
0x432154 CloseHandle

!This program cannot be run in DOS mode.
`.rdata
@.data
uYVVVV
HHtXHHt
>If90t
tNIt?It0It
Y;=8kC
teh\4@
t h@7C
>=Yt1j
jTh@RC
j@j ^V
0A@@Ju
Fh=0eC
^SSSSS
j"^SSSSS
URPQQh
0SSSSS
0SSSSS
0SSSSS
GWhh,C
t"SS9]
FVhh,C
PPPPPPPP
PPPPPPPP
_VVVVV
^WWWWW
;t$,v-
UQPXY]Y[
t+WWVPV
0SSSSS
_VVVVV
<+t(<-t$:
+t HHt
u;hH6C
u,h@6C
Ai=#T-=!
i=#T-=!
c`<AGX
7M(lQM'2
79d:rP
Xok(IE
hO9r,/s
L<oz*/n
_%y$o@
i"/SBj
_<P&K|
/N'\R[
KzQRNw
IPn`wR\-1M/
0cP9)#
u2iFO9
g3!P<$
5$I<;]Z
EibJv-
}[$-I9I$%X
wo'> nAm
P0(``f
MqV0D.
5VkQe#
~,08CA.
*1_]`{
v;V3#HQ~
*+}!%4
C[DFVt
-vx%fg5-
"0gkI_V=G
_<aM\M
sZeMqt
-SE9xK
02oUY:
1@:BD-HN
Y]fH}!
m47r.|w
aR39b?
l@XK@r
y=:on@0
G)>}]l
CdWX\p
pe3OXn
T7`ZO8M
mOf2\N5
(Qe)/]
M25Q>~
*%}W(i
)Er\ _
?e/~mJ
)eDAw/
9z~(5,
3rgiHs
2&K\[9C
gcimo7
HNk8rO
k;1~jo
z9KaOO)
U(N*5=I
|e14I^
\L/o%&
Nv/agG
c2A%Nv
?MJR!
T/oOf~
J~@YbPV
E|^Jm(
iZp&`u-
O\VsF<0~
8?V<%N
3MQ ER
sg'6?g
HiT/-\]-0
?s\XU)
a0_9p"^
$4Dzce!
{n_Dj(
eqN[,
w[8Cw?T
O{T:dv
D28k\5S
oV)YZ?
G/O^f>
O@,w;s
*V"L9
9kYh,)q)
7Z ,;[
wYe]$y
Ub&c}t
i\3]*p
J9_;sgD
0MK5/J
SSU*[TH
lr$ShOr
mzd'qu
mjutx7
y?^n/b
kO7iMn
Ad{=o>
NXlYQ'@
ys@[a*
yR{dy"A
o27Ht@
V9pE2W>
/.6~bF5
5t>~,i
WSK*Bc'1F
N{E@Hz
wF~%MM
@'W9Bi,
-'K.rV
,)f<LNCS
z2_3++Ol
XSO%!,85
{Hz7v v9
COl>wK
AdOhzI
T71wGC[f
ibNIr
[hDK63s
qe:=R|)}%
Pj+[wV<_
kYT8%r
H`miC6
G+nFOe
>_~{I42
q/Jo8?#
W=&07?s
@ G JSz
I%p9/o
Jwm]8~G
!MJZxkC
]?!l4l
$nb/w-
R #J\2{
~Y!z%l
j#cu'2
( '(=!/
OJ*A_v(!{
\f~'Ywlw
03Cy7o
T06+S
c6}QRr
#G38<&
Fwsknt
d_C[P_i@
1B|96X
c$>AVB
q`zS$<
9f.Y3v+
AP^wZ\z
m_GZ"m.
n3!T4M"o
ot\hF&
"-U2cv
xHOi|h@
SSTAp*FLNn
Gb<TPl
l]UEXZ
?k,qSq
>gDl1f.
Qv&.KD
rmEE7!=V
;!:,"O
1>\g:?!H/
kq +5wu0
L2p'OMw
rNP(8~VaM
T)niZ6
5NV^g
va|GWe
?}:6/wp<
vhTu'HH
r(urM`
Um;^&9
OCs4(vt
ybO1N_
#m78&E
R*5=<q
:x<0MK
DM=y/m
=oDs,a
kvR5Rg
p3kD+Z
a:kWTU
^Hc)J"q
*-u\y@
$t3tBf~VF
ho!go-
7[[!K:
f%lmx
[/wfk+o
rMd(M>
8z$.WY
\M=!2L
}UClNR
VW-1)>
TQEY3Oa
EbiVv%
OQ}mKex,'
GY6D#V
6HIM#LyN@
o0-Nl~
raIE`u
?&&e"_/
[meXamM6
sDCXA$
zMigpR
XA{e(T
SM`Q_-r
(?$QJI&:
k>O~<p
'\Z`[1
LO??_~:
mVdwCG
n70p+#)i
I|mR_
>/}a<(
<]]T@>
y9T2ir?
%Vh2na
)#iO]6E
TY,&Zl
`3x,(`
A\<`eF
^,tk}B
pys Pp
]$P-T)
Hnnc=v
_9Kwvj
Sd,u&Y
ebQ%s5S
H&]Rn@
O2B#$7
S1&#WX
V;UC%2
H6*`n*
!-$\e7
Y{ex20
:|L`nb
<%FdFk1
)+`Az4
wkAobd
bolb9`
f}WBv{
]1no@R
ir\{[q{
5/;a)C
"''bWx
sXi4zO-V
O+?iIg
T^|))rU
jn",dF
f_D9]4
QQSVWd
HtHu4j
s[S;7|G;w
YYhP7C
tR99u2
(null)
`h````
xpxxxx
EncodePointer
DecodePointer
FlsFree
FlsSetValue
FlsGetValue
FlsAlloc
CorExitProcess
runtime error
TLOSS error
SING error
DOMAIN error
An application has made an attempt to load the C runtime library incorrectly.
Please contact the application's support team for more information.
- Attempt to use MSIL code from this assembly during native code initialization
This indicates a bug in your application. It is most likely the result of calling an MSIL-compiled (/clr) function from a native constructor or from DllMain.
- not enough space for locale information
- Attempt to initialize the CRT more than once.
This indicates a bug in your application.
- CRT not initialized
- unable to initialize heap
- not enough space for lowio initialization
- not enough space for stdio initialization
- pure virtual function call
- not enough space for _onexit/atexit table
- unable to open console device
- unexpected heap error
- unexpected multithread lock error
- not enough space for thread data
This application has requested the Runtime to terminate it in an unusual way.
Please contact the application's support team for more information.
- not enough space for environment
- not enough space for arguments
- floating point support not loaded
Microsoft Visual C++ Runtime Library
<program name unknown>
Runtime Error!
Program:
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
`h`hhh
xppwpp
_nextafter
_hypot
GetProcessWindowStation
GetUserObjectInformationA
GetLastActivePopup
GetActiveWindow
MessageBoxA
USER32.DLL
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
HH:mm:ss
dddd, MMMM dd, yyyy
MM/dd/yy
December
November
October
September
August
February
January
Saturday
Friday
Thursday
Wednesday
Tuesday
Monday
Sunday
GAIsProcessorFeaturePresent
KERNEL32
CONOUT$
SunMonTueWedThuFriSat
JanFebMarAprMayJunJulAugSepOctNovDec
1#QNAN
1#SNAN
bad allocation
kernel32.dll
LocalAlloc
VirtualProtect
bad allocation
bad exception
Unknown exception
Complete Object Locator'
Class Hierarchy Descriptor'
Base Class Array'
Base Class Descriptor at (
Type Descriptor'
`local static thread guard'
`managed vector copy constructor iterator'
`vector vbase copy constructor iterator'
`vector copy constructor iterator'
`dynamic atexit destructor for '
`dynamic initializer for '
`eh vector vbase copy constructor iterator'
`eh vector copy constructor iterator'
`managed vector destructor iterator'
`managed vector constructor iterator'
`placement delete[] closure'
`placement delete closure'
`omni callsig'
delete[]
new[]
`local vftable constructor closure'
`local vftable'
`udt returning'
`copy constructor closure'
`eh vector vbase constructor iterator'
`eh vector destructor iterator'
`eh vector constructor iterator'
`virtual displacement map'
`vector vbase constructor iterator'
`vector destructor iterator'
`vector constructor iterator'
`scalar deleting destructor'
`default constructor closure'
`vector deleting destructor'
`vbase destructor'
`string'
`local static guard'
`typeof'
`vcall'
`vbtable'
`vftable'
operator
delete
__unaligned
__restrict
__ptr64
__clrcall
__fastcall
__thiscall
__stdcall
__pascal
__cdecl
__based(
C:\muwizowefoni\dabajuwakeju\borufekihi10\sumaketunis7.pdb
GetLocaleInfoA
SetLocalTime
DebugActiveProcessStop
lstrcpynA
InterlockedIncrement
ReadConsoleA
InterlockedDecrement
GetCurrentProcess
GetEnvironmentStringsW
GetUserDefaultLCID
SetEvent
GetCommandLineA
GetEnvironmentStrings
GetSystemWindowsDirectoryA
LeaveCriticalSection
VerifyVersionInfoA
SetConsoleTitleA
GetProcAddress
PeekConsoleInputW
EnterCriticalSection
GetAtomNameA
WriteConsoleA
LocalAlloc
SetConsoleOutputCP
GetModuleFileNameA
GetOEMCP
GetModuleHandleA
GetFileAttributesExW
GetCPInfoExA
Module32Next
GetCurrentProcessId
AddConsoleAliasA
KERNEL32.dll
GetStartupInfoA
TerminateProcess
UnhandledExceptionFilter
SetUnhandledExceptionFilter
IsDebuggerPresent
GetModuleHandleW
TlsGetValue
TlsAlloc
TlsSetValue
TlsFree
SetLastError
GetCurrentThreadId
GetLastError
HeapSize
ExitProcess
HeapFree
SetFilePointer
WriteFile
GetStdHandle
FreeEnvironmentStringsA
FreeEnvironmentStringsW
WideCharToMultiByte
SetHandleCount
GetFileType
DeleteCriticalSection
HeapCreate
VirtualFree
QueryPerformanceCounter
GetTickCount
GetSystemTimeAsFileTime
GetConsoleCP
GetConsoleMode
GetCPInfo
GetACP
IsValidCodePage
RaiseException
HeapAlloc
HeapReAlloc
VirtualAlloc
LoadLibraryA
InitializeCriticalSectionAndSpinCount
RtlUnwind
SetStdHandle
FlushFileBuffers
GetConsoleOutputCP
WriteConsoleW
MultiByteToWideChar
LCMapStringA
LCMapStringW
GetStringTypeA
GetStringTypeW
CreateFileA
CloseHandle
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
.?AVbad_exception@std@@
.?AVexception@std@@
.?AVtype_info@@
KE/z{<%z
9KE~~*"
?LK|bBD|
Jbf~zE8~
+HS~g++|
IWn{w/5
=B_|t-;
&CD~s1.}
*P^xK4M
:ZL}|4I|
Vz|}xCB
Givizafaxotuj yur zafegahid cowavasojuresof vibevotugubopid. Rozukobukebi gopewugave gim cituhuwojid. Zojalaxun waxudilokajex xiyoju. Jajirarezoxeh yup fupel luwofexonucoxo bucenuh. Hafopa. Hiru liba buwuv nogejey. Fahaje biwoci nonaz. Piru. Nubidupe husev tokibo bey. Doton hedusoyim vigakogujajazub. Tocofec mevicinigar yavorab siyakahij. Hobudihehot. Gaju rawerekajut zapixec kadonotanafi. Nejijol. Kuducux zedujec heres. Sopokenuw soliwojuyadomux caduyoyohosod vajelo milisu. Vil. Buyevixov mux. Cazidelepoto. Xavotagututiye wezekuceyi lufoyutakinisu xeg. Tid mixuvaronohezo kevunoxewoye lepoyixeno. Viginotofonas. Leyawu budefuva. Kafoxicinutah. Zetobired texahibizarah. Wim pefa husetuw tovovikiheb. Juwet cezorecide zorafucuwaxije. Lazajovayav robogofuxinaxo bixicubebexo vizifema hodehesipevafam. Bugofaretukevu vibuhameyag xixu. Gazuyenuyi. Zovuzigokuwipey hugibasuf hihubi ginecizufatu yuhe. Yasocudexe kafupegozep bucadorurana vanihasonofa xezesikuziyamik. Zuz nifumeyo geyagodabici cofovofenayicap. Jeso. Nonicul
Lup wuhikukufolilox yecagenafomoga dez fefu. Pecovareluxiki fus jeregatiwuzudic zibicu. Bumiy hedafu pagiyoxenigowop nuwi. Ficufatoxiwi juyahizirak kiv pubafevi rizorasewicasut. Rutovuxayiso seyiyupixivusi ziyejiy xojocuzusez. Conatefigino wekavonodoxubas tenugulekirub. Gowubifed zika robukego. Hucukulam. Ludinifabaweru. Cepimoj kolinahor habikewok rinocixewewoza. Woc kikejedisivuy lucovulepatemo. Wawadizim nasapec gisozujugevuyo cozucukahovo jotexedolo. Lasesesiloko yeja yutugayi. Zawawotul jopim lecolino lozikamo rebuxevatuxuwa. Sim xipuwo xijuromigev bucul doxoyof. Xunevofuwifan vukicafuzise seci hubomabahapax. Kezemidobayatop wib balu gibor. Xevoyikedibeze riseriben. Nevutedozivaber pajoxomezopego vufehapev pikayonani cijejexe. Dipulebat gapuzogici lod kac xezeda. Tasizijiw beceneg gakuk noxeyapo wos. Yasoxu toxefa. Pujidi fatego. Disevip xot veh bedifimur napugosomarin. Duyaxekel fotokapokayuz baror nuhixu. Dihujetocijoc tewu xajadobeh piyepewuke. Fey rezibenecawane hatisaledojoze bomugetibiz wozihigubah
(null)
KERNEL32.DLL
mscoree.dll
((((( H
h(((( H
H
ruhidukil
fijepojegabudoyepavototewodeleromazobiturejawumagatofa
MORELUFA
FUFAMEDOWU(
VS_VERSION_INFO
StringFileInform
020264c6
InternalName
sajbmoumunu.ape
Copyright
Copyrighz (C) 2021, fudkagata
ProductVersion
8.19.290.38
VarFileInfo
Translation
Zurol pax nodegeri nafe cupuve
Tunejaj limopi riturunoy
YefuvofiHNaxiwozawahozov tilavalivaf sadisuvayi hababozojiz kiveri raj hidi conov
Yubitofa
GehifirelemarKRepigebapuh wupotodohutigu siso nejacahizeyade sonoli nurotoy lekevocej cuh
Loroveponej
Vuzuwohov>Picet jizexedobiya xakoli boruzufazul hijim gomerozen nevofefuVGuhaxabehudesa kolobazukap pepehopuxiwet piw yaxukorebubada kegife vibatef juhe raxuda
Tameho
FNohesec hazezibobuhab bejajehijozata larinepesunuda bepoz gevaherejuwu/Cuhivogi mufiw sazisivodo dufanet vep nafawepahODesuc wikujinujok wuzam xuteve kefemikeguyaton tehifuvu halogo yup kopopidozawaQWib rifowun hahu yumejekewezi gecapafazo weg tuzutedixek volijiye zotisatosawalohOFiwiviromewaw fejepepimunah mobiweboy werituta palezahatudosup nexalik yodariba
DoxopepJToranixexir sij noratosojapibop zepanu hovahij riyokegeki jiloloxo lavawuz
$Xujipizelo sudemefa pivu sotomulayil Bumi mifomamababuh xiwe sekofeya.Rehufunibaye yomanajeno mibububa firuxoginidugAHeromi hahinilike kizulus pas yoradezagayo tuxepahata dosohatefoh2Kulap vuwijidaxoyal denofoyuso tiyaxokoxaj zivotejOTocudu bumugomewaketep vuy duwawo xicuz duboxejot yowupil xoxec calicekacohaduh
Antivirus Signature
Bkav Clean
Lionic Clean
Elastic malicious (high confidence)
MicroWorld-eScan Clean
FireEye Generic.mg.3c933afc5af70a1c
CAT-QuickHeal Clean
ALYac Clean
Cylance Unsafe
VIPRE Clean
Sangfor Trojan.Win32.Save.a
CrowdStrike win/malicious_confidence_100% (D)
BitDefender Clean
K7GW Trojan ( 0056ac331 )
K7AntiVirus Trojan ( 0056ac331 )
Baidu Clean
Cyren W32/Kryptik.EWJ.gen!Eldorado
Symantec ML.Attribute.HighConfidence
ESET-NOD32 Clean
APEX Malicious
Paloalto Clean
ClamAV Clean
Kaspersky UDS:Trojan-PSW.Win32.Reline.gen
Alibaba Clean
NANO-Antivirus Clean
ViRobot Clean
Rising Trojan.Generic@ML.80 (RDML:O3Tw55TUGfwxY+s6NKGLPA)
Ad-Aware Clean
Emsisoft Clean
Comodo Clean
F-Secure Clean
DrWeb Clean
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition BehavesLike.Win32.Generic.dc
CMC Clean
Sophos ML/PE-A
SentinelOne Static AI - Malicious PE
GData Clean
Jiangmin Clean
Webroot Clean
Avira Clean
MAX Clean
Antiy-AVL Clean
Kingsoft Clean
Gridinsoft Clean
Arcabit Clean
SUPERAntiSpyware Clean
ZoneAlarm Clean
Microsoft Trojan:Win32/Sabsik.FL.B!ml
Cynet Malicious (score: 100)
AhnLab-V3 Clean
Acronis Clean
McAfee Clean
TACHYON Clean
VBA32 Clean
Malwarebytes Trojan.MalPack.GS
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Tencent Clean
Yandex Clean
Ikarus Clean
eGambit Clean
Fortinet Clean
BitDefenderTheta Gen:NN.ZexaF.34142.pq0@aCuNMBG
AVG Win32:DropperX-gen [Drp]
Cybereason malicious.f29259
Avast Win32:DropperX-gen [Drp]
MaxSecure Trojan.Malware.300983.susgen
No IRMA results available.