Static | ZeroBOX

PE Compile Time

2020-05-20 16:49:09

PDB Path

C:\wanok\vehudezepedu-jutiyotaru\pod_lihusit.pdb

PE Imphash

c8c17e47eb07afabbfe8e635fca5ad02

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x0001b5ac 0x0001b600 7.63397363057
.rdata 0x0001d000 0x0000429f 0x00004400 4.06531083038
.data 0x00022000 0x0001520c 0x00002200 2.18883108351
.nocemi 0x00038000 0x00000270 0x00000400 0.0
.dofu 0x00039000 0x00000017 0x00000200 0.0
.rsrc 0x0003a000 0x00067d80 0x0000fe00 6.67954232198

Resources

Name Offset Size Language Sub-language File type
BOSECOGUDIVOROZEGAM 0x00047520 0x000021af LANG_ENGLISH SUBLANG_ENGLISH_TRINIDAD ASCII text, with very long lines, with no line terminators
MAVOLEZUZA 0x00046e98 0x00000685 LANG_ENGLISH SUBLANG_ENGLISH_TRINIDAD ASCII text, with very long lines, with no line terminators
RT_ICON 0x000469b8 0x00000468 None SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x000469b8 0x00000468 None SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x000469b8 0x00000468 None SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x000469b8 0x00000468 None SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x000469b8 0x00000468 None SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x000469b8 0x00000468 None SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x000469b8 0x00000468 None SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x000469b8 0x00000468 None SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x000469b8 0x00000468 None SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x000469b8 0x00000468 None SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x000469b8 0x00000468 None SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x000469b8 0x00000468 None SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x000469b8 0x00000468 None SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x000469b8 0x00000468 None SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x000469b8 0x00000468 None SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_STRING 0x00049cd8 0x000000a4 LANG_ENGLISH SUBLANG_ENGLISH_TRINIDAD data
RT_STRING 0x00049cd8 0x000000a4 LANG_ENGLISH SUBLANG_ENGLISH_TRINIDAD data
RT_GROUP_ICON 0x000405f8 0x00000068 None SUBLANG_DEFAULT data
RT_GROUP_ICON 0x000405f8 0x00000068 None SUBLANG_DEFAULT data
RT_VERSION 0x000496d0 0x000001b4 LANG_NEUTRAL SUBLANG_NEUTRAL data

Imports

Library KERNEL32.dll:
0x41d000 HeapReAlloc
0x41d004 UnmapViewOfFile
0x41d008 EndUpdateResourceW
0x41d00c ReadConsoleA
0x41d010 GetCurrentProcess
0x41d014 BackupSeek
0x41d020 GlobalAlloc
0x41d024 Sleep
0x41d028 InitAtomTable
0x41d02c HeapDestroy
0x41d030 FindNextVolumeW
0x41d034 WriteConsoleW
0x41d038 GetModuleFileNameW
0x41d03c CreateActCtxA
0x41d040 GetACP
0x41d044 ReleaseSemaphore
0x41d048 SetTapePosition
0x41d04c SetLastError
0x41d050 GetProcAddress
0x41d058 ResetEvent
0x41d064 GetModuleHandleA
0x41d06c VirtualProtect
0x41d070 GetCurrentProcessId
0x41d074 FindNextVolumeA
0x41d078 LCMapStringW
0x41d07c lstrcpyA
0x41d080 GetCommandLineW
0x41d084 HeapSetInformation
0x41d088 GetStartupInfoW
0x41d08c HeapAlloc
0x41d098 DecodePointer
0x41d0a4 IsDebuggerPresent
0x41d0a8 EncodePointer
0x41d0ac TerminateProcess
0x41d0b0 GetLastError
0x41d0b4 HeapFree
0x41d0b8 SetFilePointer
0x41d0bc CloseHandle
0x41d0c0 GetModuleHandleW
0x41d0c4 ExitProcess
0x41d0c8 WriteFile
0x41d0cc GetStdHandle
0x41d0d8 SetHandleCount
0x41d0e0 GetFileType
0x41d0e8 TlsAlloc
0x41d0ec TlsGetValue
0x41d0f0 TlsSetValue
0x41d0f4 TlsFree
0x41d0fc GetCurrentThreadId
0x41d104 HeapCreate
0x41d10c GetTickCount
0x41d114 GetCPInfo
0x41d118 GetOEMCP
0x41d11c IsValidCodePage
0x41d120 WideCharToMultiByte
0x41d124 RtlUnwind
0x41d128 SetStdHandle
0x41d12c GetConsoleCP
0x41d130 GetConsoleMode
0x41d134 FlushFileBuffers
0x41d138 LoadLibraryW
0x41d13c RaiseException
0x41d140 MultiByteToWideChar
0x41d144 GetStringTypeW
0x41d14c HeapSize
0x41d150 CreateFileW

Exports

Ordinal Address Name
1 0x401000 @GetFirstVice@8
!This program cannot be run in DOS mode.
`.rdata
@.data
.nocemi
`.dofu
`.rsrc
SSSSSS
Wu_VVV
G;=l`C
HHtXHHt
?If90t
^SSSSS
QQSVWh
j@j ^V
tRHtCHt4Ht%HtFHHt
to=0.B
URPQQh `@
t"SS9] u
v4;5d.B
vL;5|.B
;t$,v-
UQPXY]Y[
<+t"<-t
+t HHt
PPPPPPPP
PPPPPPPP
3A?`u.
f( eW5
98,$`U
7v&wjh
!CMi|'
2fh&Q\
6cgrnU
4&F@WA
a~GP#@m
;$r0({
EY<-,
kj\]t0sK
jPrpK}
%[WJXir
Q~'k?6
Cb.7ab
FBMp I
{CX4U
>_/4R2,
2&F'1FXe|@'
p?jir4
IhF~m
;J65X@]
)VH!`c
$l7EM=
J_3%_4
&bmejN
`_An.V
<--)P(CH
m&)e{F
Q7*v<-
`HQ'f'
Y:EP8G
>+S29c
D]b)dt#
$7}@g/
nPgFvP
g5Gd*r
>0#LzB
1jLM<6
a;%>#9yi
r+!)]tT
/1\U6O
?#"aAXx
W?lJ.u
/ 3&{0
9eT46c
t3yW'is
z+-n3WTa
F%_e<'i&
%c^wBq
B}c@/j
/z"?]V?
^1#13s%T
~Z HE"E
mM=!Rq;
iJ&1gD
.'F4:]
OOJcli
^%:^Yr
+@|0!#
hYY!IM
>|7(<N
VB*JTCC
3 "L=*
hRi#;B
Y{Jnk{
u;XBH@
ho6RIR
0L'V0;
,rd*.{i
sCpK'
Ifc,]Nh
Y%dD+8
9(J>Asw
0_[Zln#
l2!#@R!\
fyk+\*X
N|y!NuJ?'6
2{J!v0
GL}UR/R
}e<4(t
lj37X~0
t}'mbQ
}_M(?0
'0.8J|
q}~SKP
w:dC'H
W}!^GN.;
'pg)@V
HtsH&o
b=+C:z
[s"D\[
Yr>>=t
w%izL+
j=HJENCix
i%?#2qS
IhAng(
5EF-CWT
bN|=Ur
QQSVWd
t=MOC
HtHu4j
t*=RCC
;7|G;p
tR99u2
(null)
`h````
xpxxxx
CorExitProcess
FlsFree
FlsSetValue
FlsGetValue
FlsAlloc
HH:mm:ss
dddd, MMMM dd, yyyy
MM/dd/yy
December
November
October
September
August
February
January
Saturday
Friday
Thursday
Wednesday
Tuesday
Monday
Sunday
`h`hhh
xppwpp
GetProcessWindowStation
GetUserObjectInformationW
GetLastActivePopup
GetActiveWindow
MessageBoxW
_nextafter
_hypot
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
1#QNAN
1#SNAN
vozuxulimefazurenerodelazor
Sip muwuliruvonabeposusoxohu soliciji
jojaxa hunirivumilab juwaxudi zolakuwepedubaromev
VirtualProtect
kernel32.dll
LocalAlloc
bad exception
Unknown exception
Complete Object Locator'
Class Hierarchy Descriptor'
Base Class Array'
Base Class Descriptor at (
Type Descriptor'
`local static thread guard'
`managed vector copy constructor iterator'
`vector vbase copy constructor iterator'
`vector copy constructor iterator'
`dynamic atexit destructor for '
`dynamic initializer for '
`eh vector vbase copy constructor iterator'
`eh vector copy constructor iterator'
`managed vector destructor iterator'
`managed vector constructor iterator'
`placement delete[] closure'
`placement delete closure'
`omni callsig'
delete[]
new[]
`local vftable constructor closure'
`local vftable'
`udt returning'
`copy constructor closure'
`eh vector vbase constructor iterator'
`eh vector destructor iterator'
`eh vector constructor iterator'
`virtual displacement map'
`vector vbase constructor iterator'
`vector destructor iterator'
`vector constructor iterator'
`scalar deleting destructor'
`default constructor closure'
`vector deleting destructor'
`vbase destructor'
`string'
`local static guard'
`typeof'
`vcall'
`vbtable'
`vftable'
operator
delete
__unaligned
__restrict
__ptr64
__eabi
__clrcall
__fastcall
__thiscall
__stdcall
__pascal
__cdecl
__based(
C:\wanok\vehudezepedu-jutiyotaru\pod_lihusit.pdb
HeapReAlloc
UnmapViewOfFile
EndUpdateResourceW
ReadConsoleA
GetCurrentProcess
BackupSeek
FindActCtxSectionStringA
GetEnvironmentStrings
GlobalAlloc
InitAtomTable
HeapDestroy
FindNextVolumeW
WriteConsoleW
GetModuleFileNameW
CreateActCtxA
GetACP
ReleaseSemaphore
SetTapePosition
SetLastError
GetProcAddress
BeginUpdateResourceW
ResetEvent
DebugSetProcessKillOnExit
CreateIoCompletionPort
GetModuleHandleA
GetProcessShutdownParameters
VirtualProtect
GetCurrentProcessId
FindNextVolumeA
LCMapStringW
lstrcpyA
KERNEL32.dll
GetCommandLineW
HeapSetInformation
GetStartupInfoW
HeapAlloc
EnterCriticalSection
LeaveCriticalSection
DecodePointer
UnhandledExceptionFilter
SetUnhandledExceptionFilter
IsDebuggerPresent
EncodePointer
TerminateProcess
GetLastError
HeapFree
SetFilePointer
CloseHandle
GetModuleHandleW
ExitProcess
WriteFile
GetStdHandle
FreeEnvironmentStringsW
GetEnvironmentStringsW
SetHandleCount
InitializeCriticalSectionAndSpinCount
GetFileType
DeleteCriticalSection
TlsAlloc
TlsGetValue
TlsSetValue
TlsFree
InterlockedIncrement
GetCurrentThreadId
InterlockedDecrement
HeapCreate
QueryPerformanceCounter
GetTickCount
GetSystemTimeAsFileTime
GetCPInfo
GetOEMCP
IsValidCodePage
WideCharToMultiByte
RtlUnwind
SetStdHandle
GetConsoleCP
GetConsoleMode
FlushFileBuffers
LoadLibraryW
RaiseException
MultiByteToWideChar
GetStringTypeW
IsProcessorFeaturePresent
HeapSize
CreateFileW
rimawira.exe
@GetFirstVice@8
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
.?AVbad_exception@std@@
.?AVexception@std@@
.?AVtype_info@@
~][g@C
)Klx^A
WWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWW
TTTTTT-
TTTTT-
WWWWWW
WWWWWWW
WWWWWWWWWW
WWWWWWWWWWW
WWWWWWWWW
WWWWWWWWWWWWWW
WWWWWWWWWWWW
XXXXXXXXX1
OOOOOOOOOOOOOOOOOOOOOOOO
Og!!DDcccsssSSxx
Og!!!DDcc
ssSSSxx
sssSSx
((!!DDcccsssSSSxx
((!!!DDcccssssSxx
(((!!!DDDc
csSsSxxx
gggFFFFFF
OOOOOOOOOOOOOOOOOOOOOOOOOOOOOO
;;;;;;;;;;;;;;
1;;111111111;
1;;;;11111;
1;;;1111;
1;;;;;11111;
1;;;;;;111;
1;;;;;
;11;
1;;;;;
11;;
;;;;;;
11;
;;;;;
1;
;;;;;;;>
1;;
;;;;;;
;
;;;;;NZ
;;
;;;;;EZ
666``````````````````66666`
`6666`
`6666`
`6666`
`6666`
`6666`
`6666`
`6666`
`6666`
`6666`
`6666`
`6666`
`6666`
:6666L
6666DDDDDDDDDDDDDD
666666666666666666666
666666666666666666666666666666666666666666666666666666666666666666666666666666666666666666666666666
}}}}}}}}}}}}
kkkkkkkkk
kkkkkkkkkkkr
7g{}8m|
2N^~nDrz
*@TaO0_
Tib vic. Jijosayetunebij hemugozusow. Xakihobivifa wev tubodubetufol bikukasu. Ciyuweboyesodu xiyapek defugarabiz mawanose. Kiwufunijelamog kolotey. Pekozi kana nurenohi vomomuvoxaja. Yibojumobe sovirezes tebipano heguyawime. Setusay hejako cadelugube fozupik yadu. Bazivevihu bac. Mojowafujog led pecokirisafi bogid. Var kahe tetejoneyif rafole. Vunuhe kezecayupejaco. Volilolu vihirumoxa. Med. Cezedam. Jubibacomofe repuyemuha pokofimomu fuwihegagipofe yubutur. Lurowavo nadajesuhoxal. Zasazihay. Tivisomunuzoni tucagiputo hozubeba zemibeh. Yecetole gehamurolu ditopewopimaci. Bonecupecoduv jihu. Ludodotucixe hikodegosoyi. Cojedomefuf wapoyi husira. Nuha muyero fifuwiseru puwelewerugak ruxowedat. Funubigedob yep. Felahak yucedozumimer xutonehopucevak. Sobopeseta. Sal cijucave yusawucoyobotax fozizezidalo keluyaropupa. Siwikatuxera temamu. Xejilofahafevux dinibot duhikelojixa wevipo tomehejotafew. Wufeneteyezu dizako. Tifina hakudafuwap yeharamepipetim. Dunokocav haranocukalag. Rivaxet hama tipubuxisifigu cuxocabaf
Yasimecehel fogawev zoyisetujaserej. Figupo. Pib xifiyezuribix. Diko zojaci guboxawiruwojo vibowejiyul mulawupefo. Cila serutenev devafetul tajop nunowewihudanol. Koxidek. Dowihijoderotex duwitozeg. Puxehagez nij xogikidecuja nijuc. Yejep diholawizu wahifomuxawufid. Yedopamibetep net julexec. Kosifohevo. Mubodo vetiyagufehuma. Fijunakilunirom. Xeliyipiv kebunacupezi bejizagacivomi xumaxame jixebonapu. Xoju tefakodeki zugopu nusiseso kimexo. Mexusidujux cujej jagupa. Xenoguso pasivamofosan hoyerir cisetore. Tez wisetucuzaguz cajizekigokevi. Sibexedat. Korok. Fizibov pufopematucudo puvuwolahuzo. Noniyucifoti fusowemi wasuxusuku. Goyi. Pir. Xihecuzuhu hagihutijatad fanemabajun guve. Nepavuji daha vivih zebogebiyih mugukajoxuhi. Bute dematilebuhudum sirewovumexim dobazivujuji fidetigoz. Jug kepahapisoro pexasifuru. Fapewohacubix hujubahamab gicukumac rodorewixojo. Vasiyine. Lufo tafuhigewiwebo gifocoke vaxaxadiremov. Rutoruvamukuwe komezuxabobuc wuwawocimo xuxifoba. Yawilamuwed rakisohekikuhar fivosurahegiyo gugi
(null)
mscoree.dll
runtime error
TLOSS error
SING error
DOMAIN error
- Attempt to use MSIL code from this assembly during native code initialization
This indicates a bug in your application. It is most likely the result of calling an MSIL-compiled (/clr) function from a native constructor or from DllMain.
- not enough space for locale information
- Attempt to initialize the CRT more than once.
This indicates a bug in your application.
- CRT not initialized
- unable to initialize heap
- not enough space for lowio initialization
- not enough space for stdio initialization
- pure virtual function call
- not enough space for _onexit/atexit table
- unable to open console device
- unexpected heap error
- unexpected multithread lock error
- not enough space for thread data
- abort() has been called
- not enough space for environment
- not enough space for arguments
- floating point support not loaded
AMicrosoft Visual C++ Runtime Library
<program name unknown>
Runtime Error!
Program:
KERNEL32.DLL
@HH:mm:ss
dddd, MMMM dd, yyyy
MM/dd/yy
December
November
October
September
August
February
January
Saturday
Friday
Thursday
Wednesday
Tuesday
Monday
Sunday
WUSER32.DLL
((((( H
h(((( H
H
CONOUT$
MAVOLEZUZA
BOSECOGUDIVOROZEGAM
VS_VERSION_INFO
StringFileInform
080824a0
InternalName
natgpianizu.iwa
Copyright
Copyrighz (C) 2021, fudkagat
ProductVersion
91.40.21.87
VarFileInfo
Translation
OZezarodobohicis mukeravuvi wojit vala yavanoy kebu lakesutujufoke likay pewapon5Sibocegoxal jutu katipeya colinotup nenuze sigipikape Ceheviwucayutez fijozoguvo zejobAKuhacabi giyofakekuyawe nazufakufaza yibufehutegu gumowicovopecej
Kocude xezuf^Majupitotabugob nujutoy pazujosococata moxanir zinetumoyiwaj faxi terah definabosuhep lujuyufu-Jaluwecayiyib fet jukarey bofi patefov tepemoVLilixozusasine niyepocuguwoy yum yapey fur baxomineva laguxerameg tesikivewozozaw mileEJaru wipito bamono jedonazadiheje fuse koxeyozahutamit hatepeluhaxafa
Gupah diyeruji4Puroxupalu gesewotiwagere juvuyotopafo livejep disef
Antivirus Signature
Bkav W32.AIDetect.malware1
Lionic Trojan.Win32.Androm.m!c
Elastic malicious (high confidence)
MicroWorld-eScan Gen:Variant.Fragtor.30708
FireEye Generic.mg.d5221f463d6fe279
CAT-QuickHeal Clean
McAfee GenericRXQJ-SI!D5221F463D6F
Cylance Unsafe
Zillya Clean
Sangfor Trojan.Win32.Save.a
CrowdStrike win/malicious_confidence_90% (W)
BitDefender Gen:Variant.Fragtor.30708
K7GW Trojan ( 00588dd21 )
K7AntiVirus Clean
Arcabit Clean
BitDefenderTheta Gen:NN.ZexaF.34214.my0@aixlq7aO
Cyren W32/Agent.DMP.gen!Eldorado
ESET-NOD32 a variant of Win32/Kryptik.HMWQ
Baidu Clean
APEX Malicious
Paloalto Clean
ClamAV Clean
Kaspersky HEUR:Backdoor.Win32.Androm.gen
Alibaba Clean
NANO-Antivirus Clean
ViRobot Clean
Rising Trojan.Generic@ML.100 (RDML:aOv/bUj5l/0q09D2F6orkg)
Ad-Aware Gen:Variant.Fragtor.30708
TACHYON Clean
Emsisoft Trojan.Agent (A)
Comodo Clean
F-Secure Clean
DrWeb Clean
VIPRE Clean
TrendMicro Clean
McAfee-GW-Edition BehavesLike.Win32.Generic.dc
CMC Clean
Sophos Mal/Generic-R + Troj/Krypt-BO
Ikarus Clean
Jiangmin Trojan.Strab.am
MaxSecure Clean
Avira Clean
Antiy-AVL Clean
Kingsoft Clean
Gridinsoft Clean
Microsoft Trojan:Win32/Azorult.RT!MTB
SUPERAntiSpyware Clean
ZoneAlarm Clean
GData Gen:Variant.Fragtor.30708
Cynet Malicious (score: 100)
AhnLab-V3 Malware/Win.RansomX-gen.R445206
Acronis suspicious
VBA32 Clean
ALYac Gen:Variant.Fragtor.30708
MAX malware (ai score=87)
Malwarebytes Trojan.MalPack.GS
Panda Trj/Genetic.gen
Zoner Clean
TrendMicro-HouseCall Clean
Tencent Win32.Backdoor.Androm.Woza
Yandex Clean
SentinelOne Static AI - Malicious PE
eGambit Unsafe.AI_Score_99%
Fortinet W32/Kryptik.HMWM!tr
Webroot Clean
AVG Win32:RansomX-gen [Ransom]
Avast Win32:RansomX-gen [Ransom]
No IRMA results available.