Static | ZeroBOX

PE Compile Time

2021-01-13 14:16:13

PDB Path

C:\darec\yolijuf.pdb

PE Imphash

311b6c030e043059833e0196a691b0ad

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x0001f2c2 0x0001f400 7.54717399358
.rdata 0x00021000 0x00003f14 0x00004000 4.34041538454
.data 0x00025000 0x01d1d108 0x00002400 2.18340873356
.rsrc 0x01d43000 0x000076e0 0x00007800 6.51884457761

Resources

Name Offset Size Language Sub-language File type
HUVEHA 0x01d494e0 0x00000685 LANG_SPANISH SUBLANG_SPANISH_NICARAGUA ASCII text, with very long lines, with no line terminators
RT_ICON 0x01d49010 0x00000468 LANG_SPANISH SUBLANG_SPANISH_NICARAGUA GLS_BINARY_LSB_FIRST
RT_ICON 0x01d49010 0x00000468 LANG_SPANISH SUBLANG_SPANISH_NICARAGUA GLS_BINARY_LSB_FIRST
RT_ICON 0x01d49010 0x00000468 LANG_SPANISH SUBLANG_SPANISH_NICARAGUA GLS_BINARY_LSB_FIRST
RT_ICON 0x01d49010 0x00000468 LANG_SPANISH SUBLANG_SPANISH_NICARAGUA GLS_BINARY_LSB_FIRST
RT_ICON 0x01d49010 0x00000468 LANG_SPANISH SUBLANG_SPANISH_NICARAGUA GLS_BINARY_LSB_FIRST
RT_ICON 0x01d49010 0x00000468 LANG_SPANISH SUBLANG_SPANISH_NICARAGUA GLS_BINARY_LSB_FIRST
RT_ICON 0x01d49010 0x00000468 LANG_SPANISH SUBLANG_SPANISH_NICARAGUA GLS_BINARY_LSB_FIRST
RT_STRING 0x01d4a248 0x00000498 LANG_SPANISH SUBLANG_SPANISH_NICARAGUA data
RT_STRING 0x01d4a248 0x00000498 LANG_SPANISH SUBLANG_SPANISH_NICARAGUA data
RT_STRING 0x01d4a248 0x00000498 LANG_SPANISH SUBLANG_SPANISH_NICARAGUA data
RT_ACCELERATOR 0x01d49b98 0x00000028 LANG_SPANISH SUBLANG_SPANISH_NICARAGUA data
RT_ACCELERATOR 0x01d49b98 0x00000028 LANG_SPANISH SUBLANG_SPANISH_NICARAGUA data
RT_GROUP_ICON 0x01d49478 0x00000068 LANG_SPANISH SUBLANG_SPANISH_NICARAGUA data
RT_VERSION 0x01d49bc0 0x000001b4 LANG_NEUTRAL SUBLANG_NEUTRAL data

Imports

Library KERNEL32.dll:
0x421000 GetLocaleInfoA
0x421008 lstrcpynA
0x421014 GetCurrentProcess
0x42101c GetUserDefaultLCID
0x421024 ReadConsoleW
0x42102c GetLocaleInfoW
0x421034 GetModuleFileNameW
0x421038 GetACP
0x42103c SetConsoleTitleA
0x421040 GetConsoleOutputCP
0x421044 VerifyVersionInfoW
0x421048 GetProcAddress
0x421050 ResetEvent
0x421054 GetAtomNameA
0x421058 WriteConsoleA
0x42105c LocalAlloc
0x421060 SetSystemTime
0x421064 GetModuleHandleA
0x421068 Module32Next
0x42106c GetCurrentProcessId
0x421070 AddConsoleAliasA
0x421074 GetCommandLineW
0x421078 GetCommandLineA
0x42107c GetStartupInfoA
0x421080 TerminateProcess
0x42108c IsDebuggerPresent
0x421090 GetModuleHandleW
0x421094 TlsGetValue
0x421098 TlsAlloc
0x42109c TlsSetValue
0x4210a0 TlsFree
0x4210a4 SetLastError
0x4210a8 GetCurrentThreadId
0x4210ac GetLastError
0x4210b0 HeapAlloc
0x4210b4 Sleep
0x4210b8 HeapSize
0x4210bc ExitProcess
0x4210c0 RtlUnwind
0x4210c4 HeapFree
0x4210c8 SetFilePointer
0x4210cc WriteFile
0x4210d0 GetStdHandle
0x4210d4 GetModuleFileNameA
0x4210e0 WideCharToMultiByte
0x4210e8 SetHandleCount
0x4210ec GetFileType
0x4210f4 HeapCreate
0x4210f8 VirtualFree
0x421100 GetTickCount
0x421108 GetConsoleCP
0x42110c GetConsoleMode
0x421110 GetCPInfo
0x421114 GetOEMCP
0x421118 IsValidCodePage
0x42111c RaiseException
0x421120 VirtualAlloc
0x421124 HeapReAlloc
0x421128 LoadLibraryA
0x421130 CloseHandle
0x421134 CreateFileA
0x421138 SetStdHandle
0x42113c FlushFileBuffers
0x421140 WriteConsoleW
0x421144 MultiByteToWideChar
0x421148 LCMapStringA
0x42114c LCMapStringW
0x421150 GetStringTypeA
0x421154 GetStringTypeW
0x421158 SetEndOfFile
0x42115c GetProcessHeap
0x421160 ReadFile

Exports

Ordinal Address Name
1 0x401046 @GetAnotherVice@12
!This program cannot be run in DOS mode.
`.rdata
@.data
HHtXHHt
>If90t
tNIt?It0It
Y;=8[B
uL9=4yB
uBh_^@
<at9<rt,<wt
URPQQh
>=Yt1j
jThpBB
j@j ^V
0A@@Ju
Fh=0UB
^SSSSS
j"^SSSSS
tGHt.Ht&
^SSSSS
8VVVVV
;t$,v-
UQPXY]Y[
0SSSSS
0SSSSS
0SSSSS
t"SS9]
PPPPPPPP
PPPPPPPP
_VVVVV
^WWWWW
t+WWVPV
0SSSSS
_VVVVV
<+t(<-t$:
+t HHt
u;hh&B
u,h`&B
tS0rXR
OZ@omd
qw0^d]
-qU3iC
tm[/~GG
_%rm=Dwo
rJG^Yyc
B=P(qws
U5%*IZU
2Unn4Ny
"2S_=
ydg>G
OGL,{S!
yK&fW6
5sP[53
X%.,yl
qt-<Guy
AN'KDyhU
O9M0<jb[
P:Bvtl
07<RSB
1{K)Y,
@?Wq%a
[si-*)
5F-7ax]X
-CFsR=
y:jsT~
ad'HdU
J'd.aB
^C^xbD
CuB@_p
oy(Yms
Z,Md;*c
CE>$lD
zoj b
CMeeAHI+
n*icLs.
V0@L2-
pDrIHh=
Pfx<\Q
Hi}k w
x~_wmp
|uTB_R=.t1
HWi)~u&
tfBM"B
3OKCO29/
WIy=i3
J@Dln^I
7z/(`a
CPzD2^
(,\JQ:
;kP"A,1N
qbp9R*
%J5A=2a
Uv(/}M
Ji[hk#
kn'x>/
:vMNCn`;
6;KlK.
R0e{+K7f
<^%h86
hE_a"H&
' 9u>eO
AT<YiG
`%x``=A
&N^3jk
l~`WAt|H
SitpD& .
Go;j{T
|kd3Og
:7F%IZ
4TV,)]
YE(qvX
c}!d_G
'D=)'mk
7Hv`TFR
N\iptm
-KcLJ
o;zJ3|
4[l[f!
~ZZe{E
?di|~r
,J| y?
&hkJ#)
h]~?CU
BFm@.Tz
K*A BE
BX@EW<
j"]kj&
e9[h:I
PYSc14
51P+c?
B)$JT"
Wywt
6Kq;co
vsD5|
QQSVWd
HtHu4j
s[S;7|G;w
tR99u2
(null)
`h````
xpxxxx
EncodePointer
DecodePointer
FlsFree
FlsSetValue
FlsGetValue
FlsAlloc
CorExitProcess
UTF-16LE
UNICODE
runtime error
TLOSS error
SING error
DOMAIN error
An application has made an attempt to load the C runtime library incorrectly.
Please contact the application's support team for more information.
- Attempt to use MSIL code from this assembly during native code initialization
This indicates a bug in your application. It is most likely the result of calling an MSIL-compiled (/clr) function from a native constructor or from DllMain.
- not enough space for locale information
- Attempt to initialize the CRT more than once.
This indicates a bug in your application.
- CRT not initialized
- unable to initialize heap
- not enough space for lowio initialization
- not enough space for stdio initialization
- pure virtual function call
- not enough space for _onexit/atexit table
- unable to open console device
- unexpected heap error
- unexpected multithread lock error
- not enough space for thread data
This application has requested the Runtime to terminate it in an unusual way.
Please contact the application's support team for more information.
- not enough space for environment
- not enough space for arguments
- floating point support not loaded
Microsoft Visual C++ Runtime Library
<program name unknown>
Runtime Error!
Program:
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
`h`hhh
xppwpp
_nextafter
_hypot
GetProcessWindowStation
GetUserObjectInformationA
GetLastActivePopup
GetActiveWindow
MessageBoxA
USER32.DLL
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
HH:mm:ss
dddd, MMMM dd, yyyy
MM/dd/yy
December
November
October
September
August
February
January
Saturday
Friday
Thursday
Wednesday
Tuesday
Monday
Sunday
GAIsProcessorFeaturePresent
KERNEL32
CONOUT$
SunMonTueWedThuFriSat
JanFebMarAprMayJunJulAugSepOctNovDec
1#QNAN
1#SNAN
bad allocation
kernel32.dll
LocalAlloc
VirtualProtect
bad allocation
bad exception
Unknown exception
Complete Object Locator'
Class Hierarchy Descriptor'
Base Class Array'
Base Class Descriptor at (
Type Descriptor'
`local static thread guard'
`managed vector copy constructor iterator'
`vector vbase copy constructor iterator'
`vector copy constructor iterator'
`dynamic atexit destructor for '
`dynamic initializer for '
`eh vector vbase copy constructor iterator'
`eh vector copy constructor iterator'
`managed vector destructor iterator'
`managed vector constructor iterator'
`placement delete[] closure'
`placement delete closure'
`omni callsig'
delete[]
new[]
`local vftable constructor closure'
`local vftable'
`udt returning'
`copy constructor closure'
`eh vector vbase constructor iterator'
`eh vector destructor iterator'
`eh vector constructor iterator'
`virtual displacement map'
`vector vbase constructor iterator'
`vector destructor iterator'
`vector constructor iterator'
`scalar deleting destructor'
`default constructor closure'
`vector deleting destructor'
`vbase destructor'
`string'
`local static guard'
`typeof'
`vcall'
`vbtable'
`vftable'
operator
delete
__unaligned
__restrict
__ptr64
__clrcall
__fastcall
__thiscall
__stdcall
__pascal
__cdecl
__based(
C:\darec\yolijuf.pdb
GetCommandLineW
GetLocaleInfoA
DebugActiveProcessStop
lstrcpynA
InterlockedIncrement
InterlockedDecrement
GetCurrentProcess
GetSystemWindowsDirectoryW
GetUserDefaultLCID
GetSystemDefaultLCID
ReadConsoleW
GetEnvironmentStrings
GetLocaleInfoW
LeaveCriticalSection
GetModuleFileNameW
GetACP
SetConsoleTitleA
GetConsoleOutputCP
VerifyVersionInfoW
GetProcAddress
EnterCriticalSection
ResetEvent
GetAtomNameA
WriteConsoleA
LocalAlloc
SetSystemTime
GetModuleHandleA
Module32Next
GetCurrentProcessId
AddConsoleAliasA
KERNEL32.dll
GetCommandLineA
GetStartupInfoA
TerminateProcess
UnhandledExceptionFilter
SetUnhandledExceptionFilter
IsDebuggerPresent
GetModuleHandleW
TlsGetValue
TlsAlloc
TlsSetValue
TlsFree
SetLastError
GetCurrentThreadId
GetLastError
HeapAlloc
HeapSize
ExitProcess
RtlUnwind
HeapFree
SetFilePointer
WriteFile
GetStdHandle
GetModuleFileNameA
FreeEnvironmentStringsA
FreeEnvironmentStringsW
WideCharToMultiByte
GetEnvironmentStringsW
SetHandleCount
GetFileType
DeleteCriticalSection
HeapCreate
VirtualFree
QueryPerformanceCounter
GetTickCount
GetSystemTimeAsFileTime
GetConsoleCP
GetConsoleMode
GetCPInfo
GetOEMCP
IsValidCodePage
RaiseException
VirtualAlloc
HeapReAlloc
LoadLibraryA
InitializeCriticalSectionAndSpinCount
CloseHandle
CreateFileA
SetStdHandle
FlushFileBuffers
WriteConsoleW
MultiByteToWideChar
LCMapStringA
LCMapStringW
GetStringTypeA
GetStringTypeW
SetEndOfFile
GetProcessHeap
ReadFile
xayikaxoki.exe
@GetAnotherVice@12
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
.?AVbad_exception@std@@
.?AVexception@std@@
.?AVtype_info@@
O9|Znd^
SjB\EK>>
V8JhIh
4E#^eg>Hu
A#(Zndi
U[hHgvH
tSWq
aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa
aaaaa"
aaaaaa
aaaaaaa
/aaaaaaaq
aaaaaaaa
aaaaaaaaaa
aaaaaaaa
:]{F.u|
/n}lPUt>=[
AYwW| x
$>`rV/z
T}z>2}
]~~e:
$Ib{XB
#8j{c2~
~);u~d=o|{2k
9JtK7}
Gipivatumeg bulipof fasitesanixa. Sozucaze pimutiwakuwu nujacifolugap witepezonare digel. Dokayasiwi loborumegusu zeluna teceyir. Hipekuvawupa kunevemata molig kahiko luvecajuy. Hefulodi turux sibuvejemayumun. Coyiwipezu. Bolunatefugexa gelilaredutol. Madileleh veyabunopiy. Yelabuyofoxo kamakerogepum wipinan taxa zukobuzon. Kitapugocu pomib lakipa. Hicanawu cubobixiteba nafocelezil zofifajeculewiw tibolulu. Wugob totibe vukobaraxab. Faziduyod. Giguzutilureg latipejop. Pokadeboji jem. Kemuz feguzanace yaxolon xoyefawitetom. Wutiruwiyil becuxebedidit xaf. Pelotiwezayigo jicok. Valowox. Betihigak newocimeda navolenonihiw hob. Xixupivoye tedanorowonil lajilupifakoh. Tepa rufurevonesaja femibifezagay lumiboh. Pirerofoyasagoz. Cazugojoh cihec dogo leyemacoh jidukasif. Gubuxir wig tayozanasizu yofelogu faratuxekisey. Jekewobil bologigituxocu. Cogicefo bejomizotawe bonowatemexa jico zanodehefimibu. Puyehunuh foxeritene warob xibufubucib. Maw. Peze puziwayih hugamimuku. Mepajisegi. Nodadeyepalos wejetosix. Yutasemilug
(null)
KERNEL32.DLL
mscoree.dll
((((( H
h(((( H
H
wapufijadaxahevahe
HUVEHA
VS_VERSION_INFO
StringFileInform
020264c6
InternalName
sojbmoumunu.ahe
Copyright
Copyrighz (C) 2021, fudkagata
ProductVersion
8.19.590.38
VarFileInfo
Translation
4Fucokulawo wiwo parulalucikomu wojipaj gekusemutuhij
Weso kuwubej mipije dowuwi:Binacehahi halare bixikeribos jiyocon xomecinu dewagijaculEXovuraru namosafenew duzuce mijuyekuto gimam sumom kacizumona gufejen&Xow jelijivu jolohuyazuvun tehivavewej
#Yugawijaduzuxot loduvilimup kopefel`Wesusuzur donahofitizus kelavovi bepuxowovet vik memifusol leranamifebac ririhohobuter papa kehu#Lifumisubijitu puyez xaxafayupuxuge
7Mute nufumuviwinep mirogukodaxuw jidapu xopoyerugidohet
Berohuwiw>Koyukepure kohuyisiju kepowedulu totizew hinam cibil yukivuzur+Coyixasiraw melizahefe huca dinuyu zezoxosu
Liy xuzu
Tuxusilu{Cuyokav rozapusifiga hucuvevoz seteguwovituli nalu weyafazame kemocudavosuge newopihokevujef xiturajibonipe vodofiveyodimoh
Caxi jocoposiyepog!Huluyunatoxeyut pebohe kupa roxaj
;Lapevedibe jesif hobixumuxoder retumeveximuv tocivabijavene\Fay javezixo latimanutebagin gorafugalez zusapuxusuxud hikoxezupederi dum biwabozivezemo tiz
Dexoyeloh seleboyamukuri0Mekeyalinahi yigeru yegafuji vehe vohu vebixihoh
Juzeponujuruw giweko
Docixaye puzaz)Lupezejakeve tet tajocutop zaziguwaxaguxaTFarubepij godohuhawa fapuniyo xijem cufoleyubibe gehulisizevox lanoxecuh cixejosimih
Antivirus Signature
Bkav Clean
Lionic Trojan.Multi.Generic.4!c
Elastic malicious (high confidence)
MicroWorld-eScan Trojan.GenericKD.37565661
FireEye Generic.mg.7789bd4d79ad8971
CAT-QuickHeal Clean
McAfee GenericRXPZ-FX!7789BD4D79AD
Cylance Unsafe
VIPRE Clean
Sangfor Trojan.Win32.Save.a
K7AntiVirus Trojan ( 005822a21 )
BitDefender Trojan.GenericKD.37565661
K7GW Trojan ( 005822a21 )
Cybereason malicious.d7118c
Baidu Clean
Cyren W32/Kryptik.EWJ.gen!Eldorado
Symantec Packed.Generic.525
ESET-NOD32 a variant of Win32/Kryptik.HMKO
APEX Malicious
Paloalto generic.ml
ClamAV Win.Packed.Generic-9891933-0
Kaspersky HEUR:Backdoor.Win32.Androm.gen
Alibaba Backdoor:Win32/Androm.c202ddfb
NANO-Antivirus Clean
ViRobot Clean
Rising Trojan.Kryptik!1.D977 (CLASSIC)
Ad-Aware Trojan.GenericKD.37565661
Sophos Mal/Generic-S
Comodo Clean
F-Secure Clean
DrWeb Clean
Zillya Clean
TrendMicro Mal_HPGen-50
McAfee-GW-Edition BehavesLike.Win32.Trojan.cc
CMC Clean
Emsisoft Trojan.Agent (A)
Ikarus Trojan.Win32.Crypt
GData Trojan.GenericKD.37565661
Jiangmin Backdoor.Androm.bbnt
Webroot Clean
Avira TR/Crypt.Agent.mbsgo
MAX Clean
Antiy-AVL Clean
Kingsoft Clean
Gridinsoft Trojan.Win32.Packed.lu!heur
Arcabit Trojan.Generic.D23D34DD
SUPERAntiSpyware Clean
ZoneAlarm Clean
Microsoft Ransom:Win32/StopCrypt.MCK!MTB
Cynet Malicious (score: 100)
AhnLab-V3 CoinMiner/Win.Glupteba.R440970
Acronis suspicious
VBA32 Clean
ALYac Trojan.GenericKD.37565661
TACHYON Clean
Malwarebytes Trojan.MalPack.GS
Panda Trj/GdSda.A
Zoner Clean
TrendMicro-HouseCall Mal_HPGen-50
Tencent Win32.Backdoor.Fareit.Auto
Yandex Clean
SentinelOne Static AI - Malicious PE
MaxSecure Trojan.Malware.300983.susgen
Fortinet W32/Kryptik.HMKO!tr
BitDefenderTheta Gen:NN.ZexaF.34142.lq0@aG5ZoKU
AVG Win32:RansomX-gen [Ransom]
Avast Win32:RansomX-gen [Ransom]
CrowdStrike win/malicious_confidence_100% (W)
No IRMA results available.