Static | ZeroBOX

PE Compile Time

2020-04-21 06:06:51

PDB Path

C:\catax_cohohobuy.pdb

PE Imphash

65186050f9601ee4db4aa7e9ce7b7062

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x00019272 0x00019400 7.33624763341
.rdata 0x0001b000 0x00004160 0x00004200 4.37235380881
.data 0x00020000 0x01d1d1a4 0x00002400 2.27150940095
.rsrc 0x01d3e000 0x0000db98 0x0000dc00 6.5144258219

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x01d4a998 0x00000468 LANG_SPANISH SUBLANG_SPANISH_NICARAGUA GLS_BINARY_LSB_FIRST
RT_ICON 0x01d4a998 0x00000468 LANG_SPANISH SUBLANG_SPANISH_NICARAGUA GLS_BINARY_LSB_FIRST
RT_ICON 0x01d4a998 0x00000468 LANG_SPANISH SUBLANG_SPANISH_NICARAGUA GLS_BINARY_LSB_FIRST
RT_ICON 0x01d4a998 0x00000468 LANG_SPANISH SUBLANG_SPANISH_NICARAGUA GLS_BINARY_LSB_FIRST
RT_ICON 0x01d4a998 0x00000468 LANG_SPANISH SUBLANG_SPANISH_NICARAGUA GLS_BINARY_LSB_FIRST
RT_ICON 0x01d4a998 0x00000468 LANG_SPANISH SUBLANG_SPANISH_NICARAGUA GLS_BINARY_LSB_FIRST
RT_ICON 0x01d4a998 0x00000468 LANG_SPANISH SUBLANG_SPANISH_NICARAGUA GLS_BINARY_LSB_FIRST
RT_ICON 0x01d4a998 0x00000468 LANG_SPANISH SUBLANG_SPANISH_NICARAGUA GLS_BINARY_LSB_FIRST
RT_ICON 0x01d4a998 0x00000468 LANG_SPANISH SUBLANG_SPANISH_NICARAGUA GLS_BINARY_LSB_FIRST
RT_ICON 0x01d4a998 0x00000468 LANG_SPANISH SUBLANG_SPANISH_NICARAGUA GLS_BINARY_LSB_FIRST
RT_ICON 0x01d4a998 0x00000468 LANG_SPANISH SUBLANG_SPANISH_NICARAGUA GLS_BINARY_LSB_FIRST
RT_ICON 0x01d4a998 0x00000468 LANG_SPANISH SUBLANG_SPANISH_NICARAGUA GLS_BINARY_LSB_FIRST
RT_ICON 0x01d4a998 0x00000468 LANG_SPANISH SUBLANG_SPANISH_NICARAGUA GLS_BINARY_LSB_FIRST
RT_ICON 0x01d4a998 0x00000468 LANG_SPANISH SUBLANG_SPANISH_NICARAGUA GLS_BINARY_LSB_FIRST
RT_ICON 0x01d4a998 0x00000468 LANG_SPANISH SUBLANG_SPANISH_NICARAGUA GLS_BINARY_LSB_FIRST
RT_STRING 0x01d4b660 0x00000536 LANG_SPANISH SUBLANG_SPANISH_NICARAGUA data
RT_STRING 0x01d4b660 0x00000536 LANG_SPANISH SUBLANG_SPANISH_NICARAGUA data
RT_STRING 0x01d4b660 0x00000536 LANG_SPANISH SUBLANG_SPANISH_NICARAGUA data
RT_ACCELERATOR 0x01d4aea8 0x00000028 LANG_SPANISH SUBLANG_SPANISH_NICARAGUA data
RT_ACCELERATOR 0x01d4aea8 0x00000028 LANG_SPANISH SUBLANG_SPANISH_NICARAGUA data
RT_GROUP_ICON 0x01d445d8 0x00000068 LANG_SPANISH SUBLANG_SPANISH_NICARAGUA data
RT_GROUP_ICON 0x01d445d8 0x00000068 LANG_SPANISH SUBLANG_SPANISH_NICARAGUA data
RT_VERSION 0x01d4aed0 0x000001b4 LANG_NEUTRAL SUBLANG_NEUTRAL data

Imports

Library KERNEL32.dll:
0x41b018 GetCurrentProcess
0x41b020 GetUserDefaultLCID
0x41b028 ReadConsoleW
0x41b030 GlobalAlloc
0x41b034 GetLocaleInfoW
0x41b03c FindNextVolumeW
0x41b040 WriteConsoleW
0x41b044 GetModuleFileNameW
0x41b04c GetACP
0x41b050 GetConsoleOutputCP
0x41b054 VerifyVersionInfoW
0x41b058 GetProcAddress
0x41b060 PrepareTape
0x41b064 ResetEvent
0x41b068 GetAtomNameA
0x41b06c SetConsoleTitleW
0x41b070 GetModuleHandleA
0x41b074 Module32Next
0x41b078 GetCurrentProcessId
0x41b07c AddConsoleAliasA
0x41b084 GetSystemTime
0x41b088 GetProfileSectionW
0x41b090 GetLocaleInfoA
0x41b094 GetCommandLineW
0x41b098 HeapAlloc
0x41b09c GetCommandLineA
0x41b0a0 GetStartupInfoA
0x41b0a4 TerminateProcess
0x41b0b0 IsDebuggerPresent
0x41b0b4 GetModuleHandleW
0x41b0b8 TlsGetValue
0x41b0bc TlsAlloc
0x41b0c0 TlsSetValue
0x41b0c4 TlsFree
0x41b0c8 SetLastError
0x41b0cc GetCurrentThreadId
0x41b0d0 GetLastError
0x41b0d8 HeapFree
0x41b0dc VirtualFree
0x41b0e0 VirtualAlloc
0x41b0e4 HeapReAlloc
0x41b0e8 HeapCreate
0x41b0ec Sleep
0x41b0f0 ExitProcess
0x41b0f4 WriteFile
0x41b0f8 GetStdHandle
0x41b0fc GetModuleFileNameA
0x41b100 HeapSize
0x41b104 RtlUnwind
0x41b108 SetHandleCount
0x41b10c GetFileType
0x41b110 SetFilePointer
0x41b114 CloseHandle
0x41b120 WideCharToMultiByte
0x41b12c GetTickCount
0x41b134 GetConsoleCP
0x41b138 GetConsoleMode
0x41b13c GetCPInfo
0x41b140 GetOEMCP
0x41b144 IsValidCodePage
0x41b148 RaiseException
0x41b150 LoadLibraryA
0x41b154 CreateFileA
0x41b158 SetStdHandle
0x41b15c FlushFileBuffers
0x41b160 WriteConsoleA
0x41b164 MultiByteToWideChar
0x41b168 LCMapStringA
0x41b16c LCMapStringW
0x41b170 GetStringTypeA
0x41b174 GetStringTypeW
0x41b178 SetEndOfFile
0x41b17c GetProcessHeap
0x41b180 ReadFile
Library GDI32.dll:
0x41b00c GetCharWidthFloatA
Library ADVAPI32.dll:
0x41b000 BackupEventLogA
0x41b004 BackupEventLogW

Exports

Ordinal Address Name
1 0x401000 @GetAnotherVice@12
!This program cannot be run in DOS mode.
`.rdata
@.data
HHtXHHt
>If90t
tNIt?It0It
uL9=x(B
<at9<rt,<wt
URPQQh
j@j ^V
>=Yt1j
tRHtCHt4Ht%HtFHHt
0A@@Ju
^SSSSS
j"^SSSSS
0SSSSS
0SSSSS
0SSSSS
tGHt.Ht&
^SSSSS
8VVVVV
;t$,v-
UQPXY]Y[
_VVVVV
^WWWWW
t"SS9]
PPPPPPPP
PPPPPPPP
0SSSSS
_VVVVV
t+WWVPV
<+t(<-t$:
+t HHt
lXN^Nm
3B[r2.
fG=ia&h
GPb,`_
o}(y}`
]wP*#_
GwJf}7
[7>)yF
{%G_`
PTGRt(
w8$.gN
b(.w[)
QG}f?p
zb,J-r ~
o$b9?&S}I
fWbL~vL
R(3C7.
m\y=O:
22vg3P
."@K[<
-Rdi8|
3"5g'4
H#Vz}~2.;
CekbD>s
`!j1_U1
3=gm|mT5
?UOr!\
sio}mw*t
\< MJT
}K^b~\
>B v}
3^m'WZ
;wlJg{&
V1]@={
RDHm*[
M=&~{)
p|E>Bk
8vNGJ@_V
BBDSt.G
o%~#!7
H qh9
s6~6p)o
ENg0&S
#!._2c
IIojIc
tc4R:
{XD9vL
dY,&D:
\V:{9x
7n.]V"
W?wk9p5
a]"uc~
#<zadZ
]QR!Mj
J9??Gw
WY@IOq
k;r%Kp
tq}69GJc
xM[)th
LtGI:Bv
t^Y|m{
5A0GE3
@-{VU-
zl(:(6dC+
QQSVWd
HtHu4j
s[S;7|G;w
tR99u2
(null)
`h````
xpxxxx
EncodePointer
DecodePointer
FlsFree
FlsSetValue
FlsGetValue
FlsAlloc
CorExitProcess
runtime error
TLOSS error
SING error
DOMAIN error
An application has made an attempt to load the C runtime library incorrectly.
Please contact the application's support team for more information.
- Attempt to use MSIL code from this assembly during native code initialization
This indicates a bug in your application. It is most likely the result of calling an MSIL-compiled (/clr) function from a native constructor or from DllMain.
- not enough space for locale information
- Attempt to initialize the CRT more than once.
This indicates a bug in your application.
- CRT not initialized
- unable to initialize heap
- not enough space for lowio initialization
- not enough space for stdio initialization
- pure virtual function call
- not enough space for _onexit/atexit table
- unable to open console device
- unexpected heap error
- unexpected multithread lock error
- not enough space for thread data
This application has requested the Runtime to terminate it in an unusual way.
Please contact the application's support team for more information.
- not enough space for environment
- not enough space for arguments
- floating point support not loaded
Microsoft Visual C++ Runtime Library
<program name unknown>
Runtime Error!
Program:
UTF-16LE
UNICODE
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
`h`hhh
xppwpp
_nextafter
_hypot
GetProcessWindowStation
GetUserObjectInformationA
GetLastActivePopup
GetActiveWindow
MessageBoxA
USER32.DLL
GAIsProcessorFeaturePresent
KERNEL32
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
HH:mm:ss
dddd, MMMM dd, yyyy
MM/dd/yy
December
November
October
September
August
February
January
Saturday
Friday
Thursday
Wednesday
Tuesday
Monday
Sunday
CONOUT$
SunMonTueWedThuFriSat
JanFebMarAprMayJunJulAugSepOctNovDec
1#QNAN
1#SNAN
bad allocation
kernel32.dll
LocalAlloc
VirtualProtect
bad allocation
bad exception
Unknown exception
Complete Object Locator'
Class Hierarchy Descriptor'
Base Class Array'
Base Class Descriptor at (
Type Descriptor'
`local static thread guard'
`managed vector copy constructor iterator'
`vector vbase copy constructor iterator'
`vector copy constructor iterator'
`dynamic atexit destructor for '
`dynamic initializer for '
`eh vector vbase copy constructor iterator'
`eh vector copy constructor iterator'
`managed vector destructor iterator'
`managed vector constructor iterator'
`placement delete[] closure'
`placement delete closure'
`omni callsig'
delete[]
new[]
`local vftable constructor closure'
`local vftable'
`udt returning'
`copy constructor closure'
`eh vector vbase constructor iterator'
`eh vector destructor iterator'
`eh vector constructor iterator'
`virtual displacement map'
`vector vbase constructor iterator'
`vector destructor iterator'
`vector constructor iterator'
`scalar deleting destructor'
`default constructor closure'
`vector deleting destructor'
`vbase destructor'
`string'
`local static guard'
`typeof'
`vcall'
`vbtable'
`vftable'
operator
delete
__unaligned
__restrict
__ptr64
__clrcall
__fastcall
__thiscall
__stdcall
__pascal
__cdecl
__based(
C:\catax_cohohobuy.pdb
GetCommandLineW
GetLocaleInfoA
FindActCtxSectionGuid
InterlockedIncrement
InterlockedDecrement
GetCurrentProcess
GetSystemWindowsDirectoryW
GetUserDefaultLCID
GetSystemDefaultLCID
ReadConsoleW
GetEnvironmentStrings
GlobalAlloc
GetLocaleInfoW
LeaveCriticalSection
FindNextVolumeW
WriteConsoleW
GetModuleFileNameW
GetACP
GetConsoleOutputCP
VerifyVersionInfoW
GetProcAddress
EnterCriticalSection
PrepareTape
ResetEvent
GetAtomNameA
SetConsoleTitleW
GetModuleHandleA
Module32Next
GetCurrentProcessId
AddConsoleAliasA
FindActCtxSectionStringW
GetSystemTime
GetProfileSectionW
KERNEL32.dll
GetCharWidthFloatA
GDI32.dll
BackupEventLogA
BackupEventLogW
ADVAPI32.dll
HeapAlloc
GetCommandLineA
GetStartupInfoA
TerminateProcess
UnhandledExceptionFilter
SetUnhandledExceptionFilter
IsDebuggerPresent
GetModuleHandleW
TlsGetValue
TlsAlloc
TlsSetValue
TlsFree
SetLastError
GetCurrentThreadId
GetLastError
DeleteCriticalSection
HeapFree
VirtualFree
VirtualAlloc
HeapReAlloc
HeapCreate
ExitProcess
WriteFile
GetStdHandle
GetModuleFileNameA
HeapSize
RtlUnwind
SetHandleCount
GetFileType
SetFilePointer
CloseHandle
FreeEnvironmentStringsA
FreeEnvironmentStringsW
WideCharToMultiByte
GetEnvironmentStringsW
QueryPerformanceCounter
GetTickCount
GetSystemTimeAsFileTime
GetConsoleCP
GetConsoleMode
GetCPInfo
GetOEMCP
IsValidCodePage
RaiseException
InitializeCriticalSectionAndSpinCount
LoadLibraryA
CreateFileA
SetStdHandle
FlushFileBuffers
WriteConsoleA
MultiByteToWideChar
LCMapStringA
LCMapStringW
GetStringTypeA
GetStringTypeW
SetEndOfFile
GetProcessHeap
ReadFile
bejulo.exe
@GetAnotherVice@12
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
.?AVbad_exception@std@@
.?AVexception@std@@
.?AVtype_info@@
XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX
XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX
XXXXXXXXXXXXXXXXX
JXXXXXXXXX2e
XXXXXXXXXXXXXX
XXXX2e.
XXXXXXXXXXXXXV
oXXXXXXXXXX
XXXXXXXXX
oXXXXXX
oXXXXXX
goXXXXXX
XXXXXXX
gXXXXXXX
CeXXXXXXX
XXXXXXX
XXXXXXX
LXXXXXXXXXV
XXXXXXXXX
XXXXXXXXXX
4/`?`>-
XXXXXXXXXXXXX
XXXXXXXXXXXXXX
XXXXXXXXXXXXXXX
uYJXXXXXXXXXXXXXXX
XXXXXXXXXXXXXXXXXLg
e=XXXXXXXXXXXXXXXXXJ
XXXXXXXXXXXXXXXX
XXXXXXXXXXXXXXXXXX<e.
XXXXXXXXXXXXXXXXXXX
XXXXXXXXXXXXXXXXXXXXXX
XXXXXXXXXXXXXXXXXXXXXX~g
XXXXXXXXXXXXXXXXXXXXXo
XXXXXXXXXXXXXXXXXXXXXo
XXXXXXXXXXXXXXXXXXXXXoLp
oXXXXXXXXXXXXXXXXXXXXXoK
XXXXXXXXXXXXXXXXXXXXXX
oXXXXXXXXXXXXXXXXXXXXXXX
XXXXXXXXXXXXXXXXXXXXXXXXXJ
XXXXXXXXXXXXXXXXXXXXXXXXXXX
]JXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXi
L8oXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXi
XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX
XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX
XXXXXXXXXXXXXXXXXXX
y&XXXXXXX
XXXXXXXXXXX9
XXXXXXXXX
XXXXXXXX
UXXXXXXX
XXXXXXX
XXXXXXX
XXXXXXX
9XXXXXXXX
*XXXXXXXXX"8
XXXXXXXXXX&86
XXXXXXXXXXXX
gXXXXXXXXXXXXXXU
LXXXXXXXXXXXXXXQ
P6XXXXXXXXXXXXXX
'UXXXXXXXXXXXXXXXX
^XXXXXXXXXXXXXXXXX
6XXXXXXXXXXXXXXXXXi
2XXXXXXXXXXXXXXXXX
XXXXXXXXXXXXXXXXX
xXXXXXXXXXXXXXXXXXXX
XXXXXXXXXXXXXXXXXXXXXL 
XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX
0000000000000000000000000000000000000000000000000eg6
:s00000Q
qS000000
C?0000000F|
J0000000/Ui
00000000I@
0000000000
00000000
g~l'B`C
qNVx9A\
"CbtT6
(c~~N>
ssssssss
ssssss
sssssssssss
ssssss
sssssssss
sssssss
s!!!!!
ssssssssss
ssssssss!!!!
ssssssssss!!s!!!!
ssssss!s!!!!
usssssss!s!!!!!!
usssssss!s!!!!!
yyyy4$
sss!s!s!!!!
sssss!s!!s
ssssss!s!!
sssss!ss
sssss!s
ssssss
ttttttttt
rrz[==
rzz[==
rrrz==
rrzz==
Lggggjjjaaaaaa
BBBBBBBB
BBBBBBB
ZZZZZZZZsZZZZZ
ZZZZZZZZZZZZZZZZZZZZ
666666
DD~~~~~~~~~~~~DDD~rrrrrrrrrrrr~DD~
DDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDD
2ITri8d
"8FWK)X
(null)
KERNEL32.DLL
mscoree.dll
((((( H
h(((( H
H
wesepegagitazayagasanahobepomif
satavopofomedudoxe wozewukuzedicobir gav guf vanarizijavegagerusuxo
yenaxivaxecesolajizefiyutov
mumefere pavegurovi
VS_VERSION_INFO
StringFileInform
020264c6
InternalName
sojbmoemonu.uhe
Copyright
Copyrighz (C) 2021, fudkagata
ProductVersion
8.19.590.38
VarFileInfo
Translation
WogipetuhevuLWehi jev nefenapi koze cejeze mijarupad sewomedamegebay legesuhuweni tagexerdHoyipewamazi sab dohubiwiv tegoronizise lev nesomogiwajace bizi newazapabarivud rifulafivovoji dotosdXupivixejuhuw lorojixi hedaj vawohihonakopal mutoy hatozitawore tajajo wedepapepivuziz ruxunalukituj
Cezuzikixeya
kGelitak midolipuyoh xaguvutes vunuv yifaroto xidohenuxorivin juraziyari zamulohapo cawirilodu xovudiwukipaf@Bamiwu romoho tihanesuno jenegija rojaseyubeceso pusace roboyaye$Vagunuyivayi bobimeh gewuhu kuhusodi
Gaw puw
Xuhahopecox tezumeguzotisidgCowaceyajut tayekasobeh jisezapumefom bagekuhekewok pabavof xavoho kumigep kenawuyud janoxivuhiju heruh
Xakexufix:Gahiw bijohidinoheyo ciyovoxojaned xec peh niketec xabucin
SWini fiboduwa puzasepirunal lafobesafoy yoyehodukex nuyeha tahudulifito tufobudoxohBYena hijuwumaden nihoxirucesix femi tikucigehedebuk nivulay vigegi_Winijijovipo cez sokituheki yagokokefojibeg wihukil xigagu xovivaveho yiwiwelen civigucoviteruc
Fad0Sunapecanuc zoviyinupup gadevomi gumuzodubuvajoh
Sarimeta
Liropogodud
0Dunud gujen nurejopumevipi xow ganuzu hevoxijepo,Subizucatal cola yupufemu xuhate joyi wekuyo"Bumutunawafi toteyu muborezasefotaZGuwiwofewi hivixecile xojujicibululav cezub lopidekuduve pizekul dicemaxoj sevadowukomokagTGarirozusa diwuxirozuwaho lafuyavodoroz nodigevi yubu fuxegajevicoh ten kusiyeb hobo%Bulaluzab zakukajiyiloc fusokoxudukiz
No antivirus signatures available.
No IRMA results available.