Static | ZeroBOX

PE Compile Time

2020-04-05 19:57:36

PDB Path

C:\yegeka\coza dafocuziraro.pdb

PE Imphash

f98cc9327e2d65cc6189a693f26e1c1d

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x0001f150 0x0001f200 7.8536181162
.rdata 0x00021000 0x000031f3 0x00003200 4.17895304257
.data 0x00025000 0x0008557c 0x00001e00 1.31900097029
.rsrc 0x000ab000 0x0000a8f0 0x0000aa00 6.07555271894

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x000b4e00 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x000b4e00 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x000b4e00 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x000b4e00 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x000b4e00 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x000b4e00 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x000b4e00 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x000b4e00 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x000b4e00 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x000b4e00 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x000b4e00 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x000b4e00 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_STRING 0x000b54c8 0x00000424 LANG_SAAMI SUBLANG_ARABIC_LIBYA data
RT_ACCELERATOR 0x000b52f8 0x00000020 LANG_SAAMI SUBLANG_ARABIC_LIBYA data
RT_ACCELERATOR 0x000b52f8 0x00000020 LANG_SAAMI SUBLANG_ARABIC_LIBYA data
RT_GROUP_ICON 0x000b1bb0 0x00000076 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_GROUP_ICON 0x000b1bb0 0x00000076 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_VERSION 0x000b5318 0x000001b0 LANG_NEUTRAL SUBLANG_NEUTRAL data

Imports

Library KERNEL32.dll:
0x421000 HeapReAlloc
0x421004 GetLocaleInfoA
0x421008 LoadResource
0x421014 AddConsoleAliasW
0x421018 SetEvent
0x42101c OpenSemaphoreA
0x421024 GetCommandLineA
0x421028 WriteFileGather
0x42102c CreateActCtxW
0x421038 GetFileAttributesA
0x42103c ReadFile
0x421040 GetDevicePowerState
0x421044 GetProcAddress
0x42104c VerLanguageNameW
0x421050 WriteConsoleA
0x421054 GetProcessId
0x421058 LocalAlloc
0x42105c RemoveDirectoryW
0x421060 GlobalGetAtomNameW
0x421068 EnumResourceTypesW
0x42106c GetModuleFileNameA
0x421070 GetModuleHandleA
0x421074 EraseTape
0x421078 GetStringTypeW
0x42107c ReleaseMutex
0x421080 EndUpdateResourceA
0x421084 LocalSize
0x421088 FindFirstVolumeW
0x42108c FindNextVolumeA
0x421090 lstrcpyW
0x421094 HeapAlloc
0x421098 GetStartupInfoA
0x4210a4 HeapFree
0x4210a8 VirtualFree
0x4210ac VirtualAlloc
0x4210b0 HeapCreate
0x4210b4 GetModuleHandleW
0x4210b8 Sleep
0x4210bc ExitProcess
0x4210c0 WriteFile
0x4210c4 GetStdHandle
0x4210c8 SetHandleCount
0x4210cc GetFileType
0x4210d0 GetLastError
0x4210d4 SetFilePointer
0x4210d8 TerminateProcess
0x4210dc GetCurrentProcess
0x4210e8 IsDebuggerPresent
0x4210f4 WideCharToMultiByte
0x4210f8 TlsGetValue
0x4210fc TlsAlloc
0x421100 TlsSetValue
0x421104 TlsFree
0x421108 SetLastError
0x42110c GetCurrentThreadId
0x421118 GetTickCount
0x42111c GetCurrentProcessId
0x421124 RtlUnwind
0x421128 LoadLibraryA
0x42112c SetStdHandle
0x421130 GetConsoleCP
0x421134 GetConsoleMode
0x421138 FlushFileBuffers
0x42113c GetCPInfo
0x421140 GetACP
0x421144 GetOEMCP
0x421148 IsValidCodePage
0x42114c HeapSize
0x421150 GetConsoleOutputCP
0x421154 WriteConsoleW
0x421158 MultiByteToWideChar
0x42115c LCMapStringA
0x421160 LCMapStringW
0x421164 GetStringTypeA
0x421168 CloseHandle
0x42116c CreateFileA
Library USER32.dll:
0x421174 GetCursorPos

Exports

Ordinal Address Name
1 0x401000 @SetViceVariants@12
!This program cannot be run in DOS mode.
`.rdata
@.data
u-h8$B
jTh86B
j@j ^V
>=Yt1j
Y;=h\B
URPQQh
0SSSSS
0SSSSS
0SSSSS
0A@@Ju
Fh=`VB
to=`]B
;t$,v-
UQPXY]Y[
t"SS9]
PPPPPPPP
PPPPPPPP
t+WWVPV
MHIkO/
o!nCNd
7=0c=5
JUP[b.
.N^ *(
!;J[Z$
0lXuTk
6B`I*K
EK[jVi
jcb1X{
0P"df[
[mV5xq
R;Vvy#8
rB"'FQ
}55a.Uo
5lb,g[
*8ehr\
\i^5\H
q`&IYg
r9m1ue+
o6{~GtZ
i&%?3C
KGU;g3=
?/)moD
XB ){K
zJZA9x]-
/~xyEk
,IKnq[
XrNS8\q
oM#dwLB
wvnwUm
Mlj0}I
J;;~|x
5z-5uh
PG6Q%K
+2ok_0`
sbpkUr
jb1zxm
ug0J#G
lk`j=;
1P'%mU
\WUo_jq
h:L+wg
~wB#SVk+
K[/'P=
;Ggb^<
XKJjO:8
FwFJgv
h!O4S
A:e BA
B|.<sFK
<)+cHi
$(W$)+
p!"eVXq
+OGNFd
&tn#/UhR
z1.[Qs
=B)Cak
6-6U\2
Ry|P3
POGh~xq
t!r>tQZ
/L](>;
i?cp])A
A+lbmKn
Mru2sE
pm!wzQ+
]$_l`53C
VUgodn?p
c(vwB'B$
P>kJ6:
B:~,=A
jl-`!'
Ige}cN
LNfb@t
bXlyJg
I'f!K/(
Ac7"E:
A(_p)
A O4arj
9t_D'x
z-"SfO
C)ZZB<
i,8=(S
3Dr|sLa
Y UZ|b
U_Ep%N
:;"LDI(
=#zb/"
;wJSpA
u[v=,p
9+GexSU
C7m%U/
b^?Ax
0-h|'z
}*mqAS
ppn@?`
Dv~VoV
k\@0owV
_~jdQu
O~sj/
ZRv"\j
WAEv?
{FVkEX65
/*+M(D
B{dk%Y
VN;lF{x9
q(NKZc
i.}e6~==
(T?s:m
7"iL(D2
]EUw%
/;n{wMk
g!P1DqV
zefa+,,6
s~}V/b
d,jFc[aA
=b5Qt~f
~IXTR"
8I0tnm
>.NaCD
p>_Z3K
S~4V9<
/L.G]@
de<PPs
~:/fL#
dA3@Mk+
:WDnyZ
z&wxoW>
$iPrVq*w6
XgTN=\y
P$6"%
+..z{5
,lv@sR
"b9Z&.
w6GyKZ
"HaClzg
9]n%]9
oezW#
UL|,]9
X;L!SC
iIP_E{
8xTv1y
6'[]c=i
{|Z O>H
i}RnfF
4h!N}cW
Iu;CU@
t>R07R
~u]b]I
k!=XV!h
J0%z(`+'
E3OH"{*{
".&6%;
gtcqfa
|N$HFs0
q?1oV5w
/kx!T8
SQKZ-^t1
%N3!~
CorExitProcess
runtime error
TLOSS error
SING error
DOMAIN error
An application has made an attempt to load the C runtime library incorrectly.
Please contact the application's support team for more information.
- Attempt to use MSIL code from this assembly during native code initialization
This indicates a bug in your application. It is most likely the result of calling an MSIL-compiled (/clr) function from a native constructor or from DllMain.
- not enough space for locale information
- Attempt to initialize the CRT more than once.
This indicates a bug in your application.
- CRT not initialized
- unable to initialize heap
- not enough space for lowio initialization
- not enough space for stdio initialization
- pure virtual function call
- not enough space for _onexit/atexit table
- unable to open console device
- unexpected heap error
- unexpected multithread lock error
- not enough space for thread data
This application has requested the Runtime to terminate it in an unusual way.
Please contact the application's support team for more information.
- not enough space for environment
- not enough space for arguments
- floating point support not loaded
Microsoft Visual C++ Runtime Library
<program name unknown>
Runtime Error!
Program:
EncodePointer
DecodePointer
FlsFree
FlsSetValue
FlsGetValue
FlsAlloc
GetProcessWindowStation
GetUserObjectInformationA
GetLastActivePopup
GetActiveWindow
MessageBoxA
USER32.DLL
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
HH:mm:ss
dddd, MMMM dd, yyyy
MM/dd/yy
December
November
October
September
August
February
January
Saturday
Friday
Thursday
Wednesday
Tuesday
Monday
Sunday
CONOUT$
SunMonTueWedThuFriSat
JanFebMarAprMayJunJulAugSepOctNovDec
bad allocation
safililepekoruwatigecoyuxedamig
nenevehadisefawoxuhogimovupubafosibah
VirtualProtect
kernel32.dll
LocalAlloc
Misalifuxol won sobadilunez dubu muliwazawecudaw
C:\yegeka\coza dafocuziraro.pdb
HeapReAlloc
GetLocaleInfoA
LoadResource
InterlockedIncrement
GetEnvironmentStringsW
AddConsoleAliasW
SetEvent
OpenSemaphoreA
GetSystemTimeAsFileTime
GetCommandLineA
WriteFileGather
CreateActCtxW
GetEnvironmentStrings
LeaveCriticalSection
GetFileAttributesA
ReadFile
GetDevicePowerState
GetProcAddress
FreeUserPhysicalPages
VerLanguageNameW
WriteConsoleA
GetProcessId
LocalAlloc
RemoveDirectoryW
GlobalGetAtomNameW
WaitForMultipleObjects
EnumResourceTypesW
GetModuleFileNameA
GetModuleHandleA
EraseTape
GetStringTypeW
ReleaseMutex
EndUpdateResourceA
LocalSize
FindFirstVolumeW
FindNextVolumeA
lstrcpyW
KERNEL32.dll
GetCursorPos
USER32.dll
HeapAlloc
GetStartupInfoA
DeleteCriticalSection
EnterCriticalSection
HeapFree
VirtualFree
VirtualAlloc
HeapCreate
GetModuleHandleW
ExitProcess
WriteFile
GetStdHandle
SetHandleCount
GetFileType
GetLastError
SetFilePointer
TerminateProcess
GetCurrentProcess
UnhandledExceptionFilter
SetUnhandledExceptionFilter
IsDebuggerPresent
FreeEnvironmentStringsA
FreeEnvironmentStringsW
WideCharToMultiByte
TlsGetValue
TlsAlloc
TlsSetValue
TlsFree
SetLastError
GetCurrentThreadId
InterlockedDecrement
QueryPerformanceCounter
GetTickCount
GetCurrentProcessId
InitializeCriticalSectionAndSpinCount
RtlUnwind
LoadLibraryA
SetStdHandle
GetConsoleCP
GetConsoleMode
FlushFileBuffers
GetCPInfo
GetACP
GetOEMCP
IsValidCodePage
HeapSize
GetConsoleOutputCP
WriteConsoleW
MultiByteToWideChar
LCMapStringA
LCMapStringW
GetStringTypeA
CloseHandle
CreateFileA
golalocu.exe
@SetViceVariants@12
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
)QSS)Z
iiPBD
zzQazc
iaNNz
CCRRRRRllo~o
CoCCCC7
IIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIII~j
IIIIIIIIIIIIII
$RIIIIIIIIIIIIIIR]
0CJ\IIIIIIIIIIIII
IIIIIIIIIIIII
IIIIIIIIIIIII
IIIIIIIIIIIIII
IIIIIIIIIIIIII
IIIIIIIIIIIII-@T
IIIIIIIIIIIII
IIIIIIIIIIIII
]hIIIIIIIIIIIII
ZIIIIIIIIIIIII
pIIIIIIIIIIIII
~IIIIIIIIIIIII
]NpIIIIIIIIIIIII
^4~IIIIIIIIIIIII
~IIIIIIIIIIIII
IIIIIIIIIIIIIH
IIIIIIIIIIIII
wIIIIIIIIIII
\QIIIIIIIIII
~IIIIIIIIIIR
~IIIIIIIIIIw
~IIIIIIIIIIw
IIIIIIIIIIl
IIIIIIIIII
IIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIII
>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>U
>>>>>>>>>>>>>U
>>>>>>>>>>>>
/>>>>>>>>>>
>>>>>>>>>>
>>>>>>>>>>g
>>>>>>>>>>g
>>>>>>>>>>H
>>>>>>>>>>3
>>>>>>>>>>g
>>>>>>>>>>
>>>>>>>>>>
>>>>>>>>>>g
a>>>>>>>>>>
>>>>>>>>>>HXrs
>>>>>>>>>>U
>>>>>>>>
>>>>>>>>
>>>>>>>>
j\>>>>>>>>>
>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>
E3q&T5],
eeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeee
eeeeeeeeeeeeeeeeeeeeg
eeeeeeeeeeeeeeeeee(
eeeeeeeeeeeeeeeer
3eeeeeeeeeeeeeee
eeeeeeeeeeeeeelo
eeeeeeeeeeeeeee
eeeeeeeeeeeeeee
Eeeeeeeeeeee7
eeeeeeeeee
eeeeeeeeee}k
eeeeeeeeeeee<U
eeeeeeeeeeee
eeeeeeeeeeeee
i_eeeeeeeeeeee
eeeeeeeeeeee}Leeeee
eeeeeeeeeeeeeeeeee$Q
eeeeeeeeeeeeeeeeee
eeeeeeeeeeeeeeeeee
{eeeeeeeeeeeeeeeeee
eeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeee
6}zu>zr
xy/}}~={~
|4{z}|{
mscoree.dll
KERNEL32.DLL
((((( H
h(((( H
H
wucakehekohomafucunol gojewanavajepuheg
jeladupopomilehepuyizotamucipixe
VS_VERSION_INFO
StringFileInform
020224a6
InternalName
sajbmiamezu.ise
Copyright
Copyrighz (C) 2021, fudkagat
ProductVersion
8.64.59.5
VarFileInfo
Translation
Yisore soxoxib puwi[Wiyefanonupov witidosubipuraw hanezul leri xemo libafi lujedejuyefucej tepafola peyozumamiyFFevibinibixeset gehabibeyanev yoma lok minoyipa jeduwonusafuji tajibav8Tojay wumoy cih tijowelukipusim novuh lideho nano todaxuYMoyofo nir fewotob lawotekubavalaj ganu tumi mibomatonec dayufupujufuj soliwuvedasuvo xoy
MKogarecev fimec domirivunig terikuwo cexehoropajise zafufaxodaf balasabehecemKWizuwenefide yebutufivajiro mew voxunusenugoxib fasuzehosinayo perozawejega
Surusoloxac gaze jukixosiyes
Toxe beta
Antivirus Signature
Bkav W32.AIDetect.malware1
Lionic Clean
Elastic malicious (high confidence)
MicroWorld-eScan Clean
CMC Clean
CAT-QuickHeal Clean
McAfee Packed-GDT!E2940574458F
Cylance Unsafe
Zillya Clean
Sangfor Trojan.Win32.Save.a
K7AntiVirus Clean
BitDefender Clean
K7GW Clean
CrowdStrike win/malicious_confidence_100% (D)
Baidu Clean
Cyren W32/Kryptik.EWJ.gen!Eldorado
Symantec ML.Attribute.HighConfidence
ESET-NOD32 a variant of Win32/Kryptik.HMQH
APEX Malicious
Paloalto Clean
ClamAV Win.Packed.Generic-9897371-0
Kaspersky HEUR:Trojan.Win32.Zenpak.gen
Alibaba Clean
NANO-Antivirus Clean
SUPERAntiSpyware Clean
Rising Trojan.Kryptik!1.D9C1 (CLASSIC)
Ad-Aware Clean
TACHYON Clean
Emsisoft Trojan.Crypt (A)
Comodo Clean
F-Secure Clean
DrWeb Clean
VIPRE Clean
TrendMicro Clean
McAfee-GW-Edition BehavesLike.Win32.Emotet.cc
FireEye Generic.mg.e2940574458fd1cc
Sophos Clean
Ikarus Trojan.Crypt
Jiangmin Clean
Webroot Clean
Avira Clean
Antiy-AVL Clean
Kingsoft Clean
Microsoft Ransom:Win32/StopCrypt.SL!MTB
Gridinsoft Clean
Arcabit Clean
ViRobot Clean
ZoneAlarm Clean
GData Clean
Cynet Malicious (score: 100)
AhnLab-V3 Infostealer/Win.SmokeLoader.R443048
Acronis suspicious
VBA32 BScope.Backdoor.Mokes
ALYac Clean
MAX Clean
Malwarebytes MachineLearning/Anomalous.96%
Panda Trj/Genetic.gen
Zoner Clean
TrendMicro-HouseCall Clean
Tencent Clean
Yandex Clean
SentinelOne Static AI - Malicious PE
MaxSecure Clean
Fortinet W32/Kryptik.HMQH!tr
BitDefenderTheta Gen:NN.ZexaF.34170.lq0@aScgYveO
Avast Clean
No IRMA results available.