Static | ZeroBOX

PE Compile Time

2021-03-14 23:32:05

PDB Path

C:\viyehatubaboh38\cogekebar\daxoyecu99\sidomepuh\gujilexewip.pdb

PE Imphash

af15f8c81f40203c694f921fcf93798f

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x00032a92 0x00032c00 7.79675614632
.rdata 0x00034000 0x00004122 0x00004200 4.39587322082
.data 0x00039000 0x01d1d108 0x00002400 2.17530554899
.rsrc 0x01d57000 0x00007018 0x00007200 6.43950104391

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x01d5cfc0 0x00000468 LANG_SPANISH SUBLANG_SPANISH_NICARAGUA GLS_BINARY_LSB_FIRST
RT_ICON 0x01d5cfc0 0x00000468 LANG_SPANISH SUBLANG_SPANISH_NICARAGUA GLS_BINARY_LSB_FIRST
RT_ICON 0x01d5cfc0 0x00000468 LANG_SPANISH SUBLANG_SPANISH_NICARAGUA GLS_BINARY_LSB_FIRST
RT_ICON 0x01d5cfc0 0x00000468 LANG_SPANISH SUBLANG_SPANISH_NICARAGUA GLS_BINARY_LSB_FIRST
RT_ICON 0x01d5cfc0 0x00000468 LANG_SPANISH SUBLANG_SPANISH_NICARAGUA GLS_BINARY_LSB_FIRST
RT_ICON 0x01d5cfc0 0x00000468 LANG_SPANISH SUBLANG_SPANISH_NICARAGUA GLS_BINARY_LSB_FIRST
RT_ICON 0x01d5cfc0 0x00000468 LANG_SPANISH SUBLANG_SPANISH_NICARAGUA GLS_BINARY_LSB_FIRST
RT_STRING 0x01d5db80 0x00000498 LANG_SPANISH SUBLANG_SPANISH_NICARAGUA data
RT_STRING 0x01d5db80 0x00000498 LANG_SPANISH SUBLANG_SPANISH_NICARAGUA data
RT_STRING 0x01d5db80 0x00000498 LANG_SPANISH SUBLANG_SPANISH_NICARAGUA data
RT_ACCELERATOR 0x01d5d4c0 0x00000028 LANG_SPANISH SUBLANG_SPANISH_NICARAGUA data
RT_ACCELERATOR 0x01d5d4c0 0x00000028 LANG_SPANISH SUBLANG_SPANISH_NICARAGUA data
RT_GROUP_ICON 0x01d5d428 0x00000068 LANG_SPANISH SUBLANG_SPANISH_NICARAGUA data
RT_VERSION 0x01d5d4e8 0x000001b4 LANG_NEUTRAL SUBLANG_NEUTRAL data

Imports

Library KERNEL32.dll:
0x434018 GetCurrentProcess
0x434020 GetUserDefaultLCID
0x434028 ReadConsoleW
0x434030 GlobalAlloc
0x434034 GetLocaleInfoW
0x43403c lstrcpynW
0x434040 FindNextVolumeW
0x434044 WriteConsoleW
0x434048 GetModuleFileNameW
0x434050 GetACP
0x434054 GetConsoleOutputCP
0x434058 VerifyVersionInfoW
0x43405c GetProcAddress
0x434064 PrepareTape
0x434068 ResetEvent
0x43406c GetAtomNameA
0x434074 SetConsoleTitleW
0x434078 GetModuleHandleA
0x43407c Module32Next
0x434080 GetCurrentProcessId
0x434084 AddConsoleAliasA
0x43408c GetSystemTime
0x434090 GetProfileSectionW
0x434098 GetLocaleInfoA
0x43409c GetCommandLineW
0x4340a0 GetCommandLineA
0x4340a4 GetStartupInfoA
0x4340a8 TerminateProcess
0x4340b4 IsDebuggerPresent
0x4340b8 GetModuleHandleW
0x4340bc TlsGetValue
0x4340c0 TlsAlloc
0x4340c4 TlsSetValue
0x4340c8 TlsFree
0x4340cc SetLastError
0x4340d0 GetCurrentThreadId
0x4340d4 GetLastError
0x4340d8 HeapAlloc
0x4340dc Sleep
0x4340e0 HeapSize
0x4340e4 ExitProcess
0x4340e8 RtlUnwind
0x4340ec HeapFree
0x4340f0 SetFilePointer
0x4340f4 WriteFile
0x4340f8 GetStdHandle
0x4340fc GetModuleFileNameA
0x434108 WideCharToMultiByte
0x434110 SetHandleCount
0x434114 GetFileType
0x43411c HeapCreate
0x434120 VirtualFree
0x434128 GetTickCount
0x434130 GetConsoleCP
0x434134 GetConsoleMode
0x434138 GetCPInfo
0x43413c GetOEMCP
0x434140 IsValidCodePage
0x434144 RaiseException
0x434148 VirtualAlloc
0x43414c HeapReAlloc
0x434150 LoadLibraryA
0x434158 CloseHandle
0x43415c CreateFileA
0x434160 SetStdHandle
0x434164 FlushFileBuffers
0x434168 WriteConsoleA
0x43416c MultiByteToWideChar
0x434170 LCMapStringA
0x434174 LCMapStringW
0x434178 GetStringTypeA
0x43417c GetStringTypeW
0x434180 SetEndOfFile
0x434184 GetProcessHeap
0x434188 ReadFile
Library GDI32.dll:
0x43400c GetCharWidthFloatW
Library ADVAPI32.dll:
0x434000 BackupEventLogA
0x434004 BackupEventLogW

Exports

Ordinal Address Name
1 0x401046 @GetAnotherVice@12
!This program cannot be run in DOS mode.
`.rdata
@.data
HHtXHHt
>If90t
tNIt?It0It
F\=XJC
<at9<rt,<wt
URPQQh4I@
u&h JC
>=Yt1j
jThpsC
j@j ^V
0A@@Ju
^SSSSS
j"^SSSSS
tGHt.Ht&
^SSSSS
8VVVVV
;t$,v-
UQPXY]Y[
0SSSSS
0SSSSS
0SSSSS
t"SS9]
PPPPPPPP
PPPPPPPP
_VVVVV
^WWWWW
t+WWVPV
0SSSSS
_VVVVV
<+t(<-t$:
+t HHt
"L9*cjv_
c|3jg`
:"/%8V
@<,$F,r
j2{&*2
8&S+c#
:"/%8V
@<,$F,
>)#PUc@
Z,62KI)
;duW?~;
dHc|$,+
_v$??h
@,9;l;=8L}
guxVo}z
J<WdS"
,NZPtT
8xZW'
q)l"k$
(y|c$zv
K\'0SF
O%8u0J
Q!$HQe
qU%PhM
h6K5Qgz
#w9;BYI
j\G5LI
&3?=_<
XP2,@0+
DL;p,|C
D+pW
MRR=)=
H;AbeA
!=6}2_
w6d%{V
Oh=8Pd
iR.D)yi
x\lH%a
Mozo'!7
s*YO/e
u8i3Kz
i,vlY-
.ka. Jv
2hoWu)
YcIK}|^
{*>g$l
j3VlDy
kq=[H 9
zu*IgM
y+z\Afs
;u2mBS
qx6Etu
ssSpF9
}a\r* khE
)%XY>`]
@H@vp3
~CB?rx3
C]JrL0
{]$}6<
&jfZ>o
?&|9#q
|D_}~z
Jc=IC@
X!T?f:=
H}lhHJ
nt>4G@
G+X#u
7P;S|,
>[q!Rru\
2.-pL)
*S`de%
=\im?b
]5=+q1%
qU^oyHg
;`!8|1Z
r,\&[F!M
34qVas5
lXi~"PO
.,VqrMD
y'rA~W
AB=XeB&
X`@1bb
'c/R*pw
1j2-T{
YS-nV"Cl
XE$,#^
YRxEPD2
gn1NcQ
9'1/f]9
8.00
;OJs89y
6BxUwR}
WU8@'{
OZsb"x
BxE]v
mz]ivj
d5O:~v
8F0@yS
bt,xo#Ut
pe>8k(
,gh?,t
rgil(R0
jL/leH
)jQ {f
jJ05`,
&90^J@
"Wt/J]e
kI7#OT
A/iqS;
Oq"g*Y
8Q]YM}
'@Bx7A
GrGmL:"0
5XQKAT
Mf%}^m
8}0{N{
n|r2KfR:
J6L`x5
360Ln9a/
{D^8|K
<D=pO
v04uU^W
gJ./mXZU
gfwfQ_
!5`3U,
V ^(38[
x4lj46
jL@:zY
o,&<d
pu+XQr!
s 5W=L2
INVH/2`^
w8h>'z
k|)0<
U,u<CuNOQ
g)Me_o
< 1<|Q
:[^.kp
of%q(YM
'%eFN0
)%,[",
i{lb?7
5AUJ^~
SMvCk%
ft%;z>GC
Kl4O@e
Iy]{ B$
nuup.z
Q#v;MY2
-&cDt6!vO
k-`?p:
K%qPu^
u!y|mwP
W>v:F'-
!o5=o8[
vK9R9;T
c*sf}N
LOyl(*g(
F9tj~{
7S~y^8
Y"f*oz
QY6>z2D^Eq(Xi4_
uwr;|%
XVv)P '
y=@k|5g
u}|[eKu
6[yLW~
6'D::FM
3m=ugK
`n)If
F;P]vH
mCGuT|vT
"bNdG6a>
YFO(!H
s^UiI}e
49mVsS
<)!-gfM
n/=x|38aE<0
wi:ys0
%RF6Xmy
P*aIPt
h"q-!X
@,Xf'i
}l@LW5
W>tid_
<*^'7I
*kj4!P3
,D-;[<
@?noDL4
kbC'2Qm<
'{E,L2
=uHLGv
$E zd^y
h>)p.\
rOnjaYS%
5wt)6VF:
mrd9K
<B[D(;
jOd0JB
DRI["`]9D
%GuHUSe
v<o\T?
:12>vA
k0:j9w`f
HZjJu2
Lc6u|jm
/?{3wa
wnpAAhf!
rJ&~@}
?L94t=8
#}s~XZ
d@d(>"
Kk(8)Id
],Z*R2j
!@kKe#
O>RHpe
]H=x;OIY
L@8SvTw
1*CN[}M
A3F6m,
'excHr
=_%H-lF
MJ5D@:Sw
\j;mzE
[KL}hn}
~RM!$'>
gDy@2[
~cN1P
y8pXJC,
|7_]v(hk
_UL4XP
;z:eEs
M}Is=_
]#4SIYV\\
QQSVWd
HtHu4j
s[S;7|G;w
tR99u2
(null)
`h````
xpxxxx
EncodePointer
DecodePointer
FlsFree
FlsSetValue
FlsGetValue
FlsAlloc
CorExitProcess
UTF-16LE
UNICODE
runtime error
TLOSS error
SING error
DOMAIN error
An application has made an attempt to load the C runtime library incorrectly.
Please contact the application's support team for more information.
- Attempt to use MSIL code from this assembly during native code initialization
This indicates a bug in your application. It is most likely the result of calling an MSIL-compiled (/clr) function from a native constructor or from DllMain.
- not enough space for locale information
- Attempt to initialize the CRT more than once.
This indicates a bug in your application.
- CRT not initialized
- unable to initialize heap
- not enough space for lowio initialization
- not enough space for stdio initialization
- pure virtual function call
- not enough space for _onexit/atexit table
- unable to open console device
- unexpected heap error
- unexpected multithread lock error
- not enough space for thread data
This application has requested the Runtime to terminate it in an unusual way.
Please contact the application's support team for more information.
- not enough space for environment
- not enough space for arguments
- floating point support not loaded
Microsoft Visual C++ Runtime Library
<program name unknown>
Runtime Error!
Program:
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
`h`hhh
xppwpp
_nextafter
_hypot
GetProcessWindowStation
GetUserObjectInformationA
GetLastActivePopup
GetActiveWindow
MessageBoxA
USER32.DLL
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
HH:mm:ss
dddd, MMMM dd, yyyy
MM/dd/yy
December
November
October
September
August
February
January
Saturday
Friday
Thursday
Wednesday
Tuesday
Monday
Sunday
GAIsProcessorFeaturePresent
KERNEL32
CONOUT$
SunMonTueWedThuFriSat
JanFebMarAprMayJunJulAugSepOctNovDec
1#QNAN
1#SNAN
bad allocation
kernel32.dll
LocalAlloc
VirtualProtect
bad allocation
bad exception
Unknown exception
Complete Object Locator'
Class Hierarchy Descriptor'
Base Class Array'
Base Class Descriptor at (
Type Descriptor'
`local static thread guard'
`managed vector copy constructor iterator'
`vector vbase copy constructor iterator'
`vector copy constructor iterator'
`dynamic atexit destructor for '
`dynamic initializer for '
`eh vector vbase copy constructor iterator'
`eh vector copy constructor iterator'
`managed vector destructor iterator'
`managed vector constructor iterator'
`placement delete[] closure'
`placement delete closure'
`omni callsig'
delete[]
new[]
`local vftable constructor closure'
`local vftable'
`udt returning'
`copy constructor closure'
`eh vector vbase constructor iterator'
`eh vector destructor iterator'
`eh vector constructor iterator'
`virtual displacement map'
`vector vbase constructor iterator'
`vector destructor iterator'
`vector constructor iterator'
`scalar deleting destructor'
`default constructor closure'
`vector deleting destructor'
`vbase destructor'
`string'
`local static guard'
`typeof'
`vcall'
`vbtable'
`vftable'
operator
delete
__unaligned
__restrict
__ptr64
__clrcall
__fastcall
__thiscall
__stdcall
__pascal
__cdecl
__based(
RSDS 1
C:\viyehatubaboh38\cogekebar\daxoyecu99\sidomepuh\gujilexewip.pdb
GetCommandLineW
GetLocaleInfoA
FindActCtxSectionGuid
InterlockedIncrement
InterlockedDecrement
GetCurrentProcess
GetSystemWindowsDirectoryW
GetUserDefaultLCID
GetSystemDefaultLCID
ReadConsoleW
GetEnvironmentStrings
GlobalAlloc
GetLocaleInfoW
LeaveCriticalSection
lstrcpynW
FindNextVolumeW
WriteConsoleW
GetModuleFileNameW
GetACP
GetConsoleOutputCP
VerifyVersionInfoW
GetProcAddress
EnterCriticalSection
PrepareTape
ResetEvent
GetAtomNameA
DebugSetProcessKillOnExit
SetConsoleTitleW
GetModuleHandleA
Module32Next
GetCurrentProcessId
AddConsoleAliasA
FindActCtxSectionStringW
GetSystemTime
GetProfileSectionW
KERNEL32.dll
GetCharWidthFloatW
GDI32.dll
BackupEventLogA
BackupEventLogW
ADVAPI32.dll
GetCommandLineA
GetStartupInfoA
TerminateProcess
UnhandledExceptionFilter
SetUnhandledExceptionFilter
IsDebuggerPresent
GetModuleHandleW
TlsGetValue
TlsAlloc
TlsSetValue
TlsFree
SetLastError
GetCurrentThreadId
GetLastError
HeapAlloc
HeapSize
ExitProcess
RtlUnwind
HeapFree
SetFilePointer
WriteFile
GetStdHandle
GetModuleFileNameA
FreeEnvironmentStringsA
FreeEnvironmentStringsW
WideCharToMultiByte
GetEnvironmentStringsW
SetHandleCount
GetFileType
DeleteCriticalSection
HeapCreate
VirtualFree
QueryPerformanceCounter
GetTickCount
GetSystemTimeAsFileTime
GetConsoleCP
GetConsoleMode
GetCPInfo
GetOEMCP
IsValidCodePage
RaiseException
VirtualAlloc
HeapReAlloc
LoadLibraryA
InitializeCriticalSectionAndSpinCount
CloseHandle
CreateFileA
SetStdHandle
FlushFileBuffers
WriteConsoleA
MultiByteToWideChar
LCMapStringA
LCMapStringW
GetStringTypeA
GetStringTypeW
SetEndOfFile
GetProcessHeap
ReadFile
ledukelu.exe
@GetAnotherVice@12
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
.?AVbad_exception@std@@
.?AVexception@std@@
.?AVtype_info@@
1IXb]3@=
!M!!1
8TH=::
5ZzB*y
lMYx:=U
%AdnN3
g~|/AZ
Uy{,7
(null)
KERNEL32.DLL
mscoree.dll
((((( H
h(((( H
H
wapufijadaxahevahe
Wioorradoxuz rugiwo gav guf kiracarisex
lidulupupocebunejohojenivumaz
Mirizilotu fimabije
Pakasebaci
VS_VERSION_INFO
StringFileInform
020264c6
InternalName
sojbmoumunu.ahe
Copyright
Copyrighz (C) 2021, fudkagata
ProductVersion
8.19.590.38
VarFileInfo
Translation
4Fucokulawo wiwo parulalucikomu wojipaj gekusemutuhij
Weso kuwubej mipije dowuwi:Binacehahi halare bixikeribos jiyocon xomecinu dewagijaculEXovuraru namosafenew duzuce mijuyekuto gimam sumom kacizumona gufejen&Xow jelijivu jolohuyazuvun tehivavewej
Sawosiror#Yugawijaduzuxot loduvilimup kopefel`Wesusuzur donahofitizus kelavovi bepuxowovet vik memifusol leranamifebac ririhohobuter papa kehu#Lifumisubijitu puyez xaxafayupuxuge
7Mute nufumuviwinep mirogukodaxuw jidapu xopoyerugidohet
Berohuwiw>Koyukepure kohuyisiju kepowedulu totizew hinam cibil yukivuzur+Coyixasiraw melizahefe huca dinuyu zezoxosu
Liy xuzu
Tuxusilu{Cuyokav rozapusifiga hucuvevoz seteguwovituli nalu weyafazame kemocudavosuge newopihokevujef xiturajibonipe vodofiveyodimoh
Caxi jocoposiyepog!Huluyunatoxeyut pebohe kupa roxaj
;Lapevedibe jesif hobixumuxoder retumeveximuv tocivabijavene\Fay javezixo latimanutebagin gorafugalez zusapuxusuxud hikoxezupederi dum biwabozivezemo tiz
Dexoyeloh seleboyamukuri0Mekeyalinahi yigeru yegafuji vehe vohu vebixihoh
Juzeponujuruw giweko
Docixaye puzaz)Lupezejakeve tet tajocutop zaziguwaxaguxaTFarubepij godohuhawa fapuniyo xijem cufoleyubibe gehulisizevox lanoxecuh cixejosimih
Antivirus Signature
Bkav Clean
Lionic Clean
Elastic malicious (high confidence)
Cynet Malicious (score: 100)
FireEye Generic.mg.66a35e61e92a2c57
CAT-QuickHeal Clean
ALYac Clean
Malwarebytes Clean
Zillya Clean
Sangfor Trojan.Win32.Save.a
K7AntiVirus Trojan ( 0056f9be1 )
BitDefender Clean
K7GW Trojan ( 0056f9be1 )
Cybereason malicious.075905
Baidu Clean
Cyren W32/Kryptik.EWJ.gen!Eldorado
Symantec Packed.Generic.525
ESET-NOD32 a variant of Win32/Kryptik.HMKQ
APEX Malicious
Paloalto Clean
ClamAV Clean
Kaspersky UDS:Trojan-Spy.Win32.Stealer.gen
Alibaba Clean
NANO-Antivirus Clean
ViRobot Clean
MicroWorld-eScan Clean
Rising Trojan.Kryptik!1.D977 (CLASSIC)
Ad-Aware Clean
Sophos ML/PE-A
Comodo Clean
F-Secure Clean
DrWeb Clean
VIPRE Clean
TrendMicro Mal_HPGen-50
McAfee-GW-Edition BehavesLike.Win32.Emotet.dc
CMC Clean
Emsisoft Trojan.Agent (A)
Ikarus Clean
GData Clean
Jiangmin Clean
Webroot Clean
Avira Clean
Antiy-AVL Clean
Kingsoft Clean
Gridinsoft Trojan.Win32.Packed.lu!heur
Arcabit Clean
SUPERAntiSpyware Clean
ZoneAlarm Clean
Microsoft Trojan:Win32/Sabsik.FL.B!ml
TACHYON Clean
AhnLab-V3 Clean
Acronis suspicious
BitDefenderTheta Gen:NN.ZexaF.34142.qq0@aKehgUH
MAX Clean
VBA32 Clean
Panda Clean
Zoner Clean
TrendMicro-HouseCall Mal_HPGen-50
Tencent Clean
Yandex Clean
SentinelOne Static AI - Malicious PE
eGambit Clean
Fortinet W32/Kryptik.HMKO!tr
AVG Win32:CrypterX-gen [Trj]
Avast Win32:CrypterX-gen [Trj]
CrowdStrike win/malicious_confidence_90% (D)
MaxSecure Trojan.Malware.300983.susgen
No IRMA results available.