Static | ZeroBOX

PE Compile Time

2020-10-04 21:00:12

PDB Path

C:\gukib24\nexocubuka\hirakafi_zicit 44_coxawiminazo-cad.pdb

PE Imphash

2966ac92acef7bd43000e50be4b3a82c

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x0002a000 0x0002a000 7.9146714226
.rdata 0x0002b000 0x000031c2 0x00003200 4.1674518571
.data 0x0002f000 0x0000b8bc 0x00001e00 1.32936146297
.rsrc 0x0003b000 0x0000ab20 0x0000ac00 6.14111072865

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x00044e30 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00044e30 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00044e30 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00044e30 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00044e30 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00044e30 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00044e30 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00044e30 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00044e30 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00044e30 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00044e30 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00044e30 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_STRING 0x000458f8 0x00000224 LANG_ICELANDIC SUBLANG_DEFAULT data
RT_STRING 0x000458f8 0x00000224 LANG_ICELANDIC SUBLANG_DEFAULT data
RT_ACCELERATOR 0x00045328 0x00000020 LANG_ICELANDIC SUBLANG_DEFAULT data
RT_ACCELERATOR 0x00045328 0x00000020 LANG_ICELANDIC SUBLANG_DEFAULT data
RT_GROUP_ICON 0x00041be0 0x00000076 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_GROUP_ICON 0x00041be0 0x00000076 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_VERSION 0x00045348 0x000001b0 LANG_NEUTRAL SUBLANG_NEUTRAL data

Imports

Library KERNEL32.dll:
0x42b000 GetLocaleInfoA
0x42b004 LoadResource
0x42b008 HeapAlloc
0x42b00c EndUpdateResourceW
0x42b014 GetCurrentProcess
0x42b01c GetUserDefaultLCID
0x42b020 WaitForSingleObject
0x42b024 AddConsoleAliasW
0x42b028 SetEvent
0x42b02c GetCommandLineA
0x42b034 GlobalAlloc
0x42b038 ReadFileScatter
0x42b040 FindNextVolumeW
0x42b044 GetFileAttributesW
0x42b048 WriteConsoleW
0x42b04c CreateActCtxA
0x42b050 GetDevicePowerState
0x42b054 GetProcAddress
0x42b058 VerLanguageNameA
0x42b05c RemoveDirectoryA
0x42b064 PrepareTape
0x42b068 GetProcessId
0x42b06c EnumResourceTypesW
0x42b070 GetModuleFileNameA
0x42b074 GetModuleHandleA
0x42b078 ReleaseMutex
0x42b07c LocalSize
0x42b080 FindFirstVolumeW
0x42b084 lstrcpyW
0x42b088 CreateFileA
0x42b08c GetStartupInfoA
0x42b098 HeapFree
0x42b09c VirtualFree
0x42b0a0 VirtualAlloc
0x42b0a4 HeapReAlloc
0x42b0a8 HeapCreate
0x42b0ac GetModuleHandleW
0x42b0b0 Sleep
0x42b0b4 ExitProcess
0x42b0b8 WriteFile
0x42b0bc GetStdHandle
0x42b0c0 SetHandleCount
0x42b0c4 GetFileType
0x42b0c8 GetLastError
0x42b0cc SetFilePointer
0x42b0d0 TerminateProcess
0x42b0dc IsDebuggerPresent
0x42b0e8 WideCharToMultiByte
0x42b0ec TlsGetValue
0x42b0f0 TlsAlloc
0x42b0f4 TlsSetValue
0x42b0f8 TlsFree
0x42b100 SetLastError
0x42b104 GetCurrentThreadId
0x42b10c GetTickCount
0x42b110 GetCurrentProcessId
0x42b11c RtlUnwind
0x42b120 LoadLibraryA
0x42b124 SetStdHandle
0x42b128 GetConsoleCP
0x42b12c GetConsoleMode
0x42b130 FlushFileBuffers
0x42b134 GetCPInfo
0x42b138 GetACP
0x42b13c GetOEMCP
0x42b140 IsValidCodePage
0x42b144 HeapSize
0x42b148 WriteConsoleA
0x42b14c GetConsoleOutputCP
0x42b150 MultiByteToWideChar
0x42b154 LCMapStringA
0x42b158 LCMapStringW
0x42b15c GetStringTypeA
0x42b160 GetStringTypeW
0x42b164 CloseHandle
Library USER32.dll:
0x42b16c GetCursorPos

Exports

Ordinal Address Name
1 0x401000 @SetViceVariants@12
!This program cannot be run in DOS mode.
`.rdata
@.data
j@j ^V
>=Yt1j
URPQQhdL@
0SSSSS
0SSSSS
0SSSSS
0A@@Ju
;t$,v-
UQPXY]Y[
t"SS9]
PPPPPPPP
PPPPPPPP
t+WWVPV
f"S&Sj
5h=;S'
0&td*A
.V'V57
|_Fruq
TYDTUHhH
f0rZ,bxF
:}^J)8=
Lst9W_
axXpB?
|tCZm0
w{'\ZY4
Y4h*!1
SWrBC#
MQW&F[,
R64*"16
:Ki?R8
*?\pbh!
S9e6"(
_A0D)
W4A; Y<
XAj6"U>
U@|m0\
R1xTbA
t4n@~4
9c>,{9
mHQ}b8
r:2B~A
B6..mx!
oU;j$uVV
!f?3p3
u@y!7<
HSw i5
k\c&w/
@R9;dL;
jg/BVg:}
x}]5\m'E
pKW%MXhvz
jKsbx2
7V(icb
?rF@J+
Orksg;*_~
q+iqF"
`K=GBy&R
,Ae(-F
i0[DpU
SKsbK]
f(oQ(7n
QF2%w4
j:!>yNQc7
:49E\)wY
6O9rQ\
mvUzay
9*Xrmx
U J,It
x/J[>B
GX-L9;
gm%g/-t9h
b-p2&[
#H9qr7
(R(8ro
O_N/Vb
'E (,r
1[Na}y
|ou]U
nSL9\!
#/`QM}
=zZ dC
>}5=o U@
2JAr=Y
`"N#LYx
>#auND
T/lpXTq
<z{2_#
uODIVtQZn<
/F4N~u
ya1aoH
0 )^p_
RM5"%-
7d^j}=
Dv]LU*
bxa`<9
>J(mD"e
!&6po^
]5jR;={X
>1wp{Pt
GUMC-4x
L?Y-A]E
;16]wY
Y8%|$K
MqW2>!
Dd"JOm
I)4B%{A9d
/bM%R7/
vlUZPn
&Vm/bM
,M|;I2
JXIgoR,L
wtLc~"s1
P*T&-j
H"A#EIC
r-txX;
8k+dzJU
Dxqc3v
_JpP[t
*Z3kOy`j
W"Kz[z
4G M)p
_oN/1/
&jqj*e
\JPwKT
S%(KKe!
`i[(O_
0>.bA7.
:W0t~7
+y1O%G
#cs.#g.8
l3W0"t;
PC&lr5
ZOL![J
Y@}G9T
MA8T\
!zSnH{
V7IF".
&OXE E
B!nd5U
7)}(Rw
`ch]Iw
2+)^R=f
H]KKm>
:I2~@X{6
:DG{6e
c>@jY,Zsy
lpW\SQ
SN*>r!K~
]]~5YB
u:C<?V9^
;_Q9=m
~Dh;UW"
#L'idx
~9' A
z]do}2
vQCcwm
wZInl?a'n
+:W(#'b
P2*SA[
GL\O4d
vL&DRi
[PT+qG
Q;5l:g
hP*g#4
l0.t$K
z&dqz#:+
u^@|t
TsFC[Y8
T[iT%"
ckqZJ/
PI85*c1
MACL4e
5EEf!?0/
zBholg
'on;;c
X1Hylm
v>/^NzJ
>`8~&9
;Fs'/N>
(9yfl5
fC&JtTr
^jW!M\?
{aN)Pf
J%?dz:gK
^{_*fJ
0w6scu
|)LYG``
[)[k33
2eC%;Iu
/9bEk?vH
X VW1tp
G(}2Ts
fWgq/M
t,fvgb
Q*Do>y
+z5j|5
b)Qrt7
2pKIVP
)V%0&%&V6
6,t:z.
tF^3;[
p$sNhN
[2T>iJ
5zH43#
; l$%b&
a.2`IR
w9- 
`XNCPYI
-goX~7
;HS~p8=/
ai}Rq#
'82z{Z
d|,{{Q
fSOevr
.%mVgi;
7]Y{H{
eMii6KV
+Cppt5q
{h#9H$
.-^"U91
u3mjzu
Oklm!KrF(
kObe.x(,d
nMSxX]I
0h!>p4
Uo|WIX
3H1tDexx-j
INV^^cm
fm'ew^I
/PDOe)
uYQ!Egfdx
bp?L[`
\;;wALj
Zf(|U/
!6';=P
rPVZ2>v
Z2YLAn
KE_#s
O"h$Y#J
oy5w-}%
~&T)oq
NRg|7lvZ
<={mF|uX
IVZ<+6
)=EbT*d
Wu8hV]
*AhYfR
CorExitProcess
runtime error
TLOSS error
SING error
DOMAIN error
An application has made an attempt to load the C runtime library incorrectly.
Please contact the application's support team for more information.
- Attempt to use MSIL code from this assembly during native code initialization
This indicates a bug in your application. It is most likely the result of calling an MSIL-compiled (/clr) function from a native constructor or from DllMain.
- not enough space for locale information
- Attempt to initialize the CRT more than once.
This indicates a bug in your application.
- CRT not initialized
- unable to initialize heap
- not enough space for lowio initialization
- not enough space for stdio initialization
- pure virtual function call
- not enough space for _onexit/atexit table
- unable to open console device
- unexpected heap error
- unexpected multithread lock error
- not enough space for thread data
This application has requested the Runtime to terminate it in an unusual way.
Please contact the application's support team for more information.
- not enough space for environment
- not enough space for arguments
- floating point support not loaded
Microsoft Visual C++ Runtime Library
<program name unknown>
Runtime Error!
Program:
EncodePointer
DecodePointer
FlsFree
FlsSetValue
FlsGetValue
FlsAlloc
GetProcessWindowStation
GetUserObjectInformationA
GetLastActivePopup
GetActiveWindow
MessageBoxA
USER32.DLL
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
HH:mm:ss
dddd, MMMM dd, yyyy
MM/dd/yy
December
November
October
September
August
February
January
Saturday
Friday
Thursday
Wednesday
Tuesday
Monday
Sunday
CONOUT$
SunMonTueWedThuFriSat
JanFebMarAprMayJunJulAugSepOctNovDec
bad allocation
safililepekoruwatigecoyuxedamig
VirtualProtect
kernel32.dll
LocalAlloc
milakuzugitotexipezubaxexihevusa
C:\gukib24\nexocubuka\hirakafi_zicit 44_coxawiminazo-cad.pdb
GetLocaleInfoA
LoadResource
HeapAlloc
EndUpdateResourceW
InterlockedDecrement
GetCurrentProcess
GetEnvironmentStringsW
GetUserDefaultLCID
WaitForSingleObject
AddConsoleAliasW
SetEvent
GetCommandLineA
GetEnvironmentStrings
GlobalAlloc
ReadFileScatter
LeaveCriticalSection
FindNextVolumeW
GetFileAttributesW
WriteConsoleW
CreateActCtxA
GetDevicePowerState
GetProcAddress
VerLanguageNameA
RemoveDirectoryA
FreeUserPhysicalPages
PrepareTape
GetProcessId
EnumResourceTypesW
GetModuleFileNameA
GetModuleHandleA
ReleaseMutex
LocalSize
FindFirstVolumeW
lstrcpyW
KERNEL32.dll
GetCursorPos
USER32.dll
GetStartupInfoA
DeleteCriticalSection
EnterCriticalSection
HeapFree
VirtualFree
VirtualAlloc
HeapReAlloc
HeapCreate
GetModuleHandleW
ExitProcess
WriteFile
GetStdHandle
SetHandleCount
GetFileType
GetLastError
SetFilePointer
TerminateProcess
UnhandledExceptionFilter
SetUnhandledExceptionFilter
IsDebuggerPresent
FreeEnvironmentStringsA
FreeEnvironmentStringsW
WideCharToMultiByte
TlsGetValue
TlsAlloc
TlsSetValue
TlsFree
InterlockedIncrement
SetLastError
GetCurrentThreadId
QueryPerformanceCounter
GetTickCount
GetCurrentProcessId
GetSystemTimeAsFileTime
InitializeCriticalSectionAndSpinCount
RtlUnwind
LoadLibraryA
SetStdHandle
GetConsoleCP
GetConsoleMode
FlushFileBuffers
GetCPInfo
GetACP
GetOEMCP
IsValidCodePage
HeapSize
WriteConsoleA
GetConsoleOutputCP
MultiByteToWideChar
LCMapStringA
LCMapStringW
GetStringTypeA
GetStringTypeW
CloseHandle
CreateFileA
macobuy.exe
@SetViceVariants@12
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
*Lp[Z|
%fKf SR
xwP|OO/
(VSllll?
?mmmmm33
M11?+?
^& E>R+
iiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiii
iiiiii
iiiiii
/iiiiii
Miiiiii
]|iiiiii
iiiiii
iiiiii
%iiiii
*,iiiiii
iiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiii
E5r&U5^-
###########################
############
###########
##########
#########
######3Z
#######
Y~#######
x0########
########
D############
###########3
############
t########################################
mscoree.dll
KERNEL32.DLL
((((( H
h(((( H
H
gwucakehekohomafucunol gojewanavajepuheg
ginosumatowadevirazuyegaciceyacewobomubusibunegu
VS_VERSION_INFO
StringFileInform
020224a6
InternalName
sajbmianezu.ise
Copyright
Copyrighz (C) 2021, fudkagat
ProductVersion
8.64.59.5
VarFileInfo
Translation
Yisore soxoxib puwi[Wiyefanonupov witidosubipuraw hanezul leri xemo libafi lujedejuyefucej tepafola peyozumamiyFFevibinibixeset gehabibeyanev yoma lok minoyipa jeduwonusafuji tajibav8Tojay wumoy cih tijowelukipusim novuh lideho nano todaxu
FSarehetexay veda renutezev tinidon xihifekacoceja tolunewafox bulucataMKogarecev fimec domirivunig terikuwo cexehoropajise zafufaxodaf balasabehecemKWizuwenefide yebutufivajiro mew voxunusenugoxib fasuzehosinayo perozawejega
Surusoloxac gaze jukixosiyes
Toxe beta
\Ratovi povoyavuxalubum kidososo hegoduxubavonet ferikiwe vixixiduhocir kafeye kejolud sineroRNozowamotizo repevatutijojah kocex mucasicaxaluma nisu fehihexagoyoy zepak korakotTGabalalew tuva tifoti migahaxunis vuy sahefuhezeles wecewi navigiwer lovuwobezemefog
Antivirus Signature
Bkav W32.AIDetect.malware2
Lionic Clean
Elastic malicious (high confidence)
MicroWorld-eScan Clean
FireEye Generic.mg.9922c2a3df88961f
CAT-QuickHeal Clean
McAfee Packed-GDT!9922C2A3DF88
Cylance Unsafe
Zillya Clean
Sangfor Trojan.Win32.Save.a
CrowdStrike win/malicious_confidence_90% (D)
BitDefender Clean
K7GW Clean
K7AntiVirus Clean
BitDefenderTheta Gen:NN.ZexaF.34170.oq0@ayRNa8gO
Cyren W32/Kryptik.EWJ.gen!Eldorado
Symantec ML.Attribute.HighConfidence
ESET-NOD32 Clean
Baidu Clean
APEX Malicious
Paloalto Clean
ClamAV Clean
Kaspersky Clean
Alibaba Clean
NANO-Antivirus Clean
ViRobot Clean
Rising Clean
Ad-Aware Clean
TACHYON Clean
Emsisoft Trojan.Crypt (A)
Comodo Clean
F-Secure Clean
DrWeb Clean
VIPRE Clean
TrendMicro Clean
McAfee-GW-Edition BehavesLike.Win32.Emotet.dc
CMC Clean
Sophos Clean
SentinelOne Static AI - Malicious PE
GData Clean
Jiangmin Clean
Webroot Clean
Avira Clean
Antiy-AVL Clean
Kingsoft Clean
Gridinsoft Clean
Arcabit Clean
SUPERAntiSpyware Clean
ZoneAlarm Clean
Microsoft Trojan:Win32/Sabsik.FL.B!ml
Cynet Malicious (score: 100)
AhnLab-V3 Clean
Acronis suspicious
VBA32 Malware-Cryptor.2LA.gen
ALYac Clean
MAX Clean
Malwarebytes Clean
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Tencent Clean
Yandex Clean
Ikarus Trojan.Crypt
eGambit Unsafe.AI_Score_96%
Fortinet Clean
Avast Clean
MaxSecure Clean
No IRMA results available.