Static | ZeroBOX

PE Compile Time

2020-10-07 12:39:14

PDB Path

C:\hayopiteletu dedepuyader\yekel.pdb

PE Imphash

9fa6fda3b52d9c76911daaba6b825179

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x00016150 0x00016200 7.38383904833
.rdata 0x00018000 0x00005d22 0x00005e00 4.76538766561
.data 0x0001e000 0x00008fec 0x00001800 2.92365567247
.bopih 0x00027000 0x00000272 0x00000400 0.0
.rsrc 0x00028000 0x000076c8 0x00007800 6.17325635966

Resources

Name Offset Size Language Sub-language File type
AFX_DIALOG_LAYOUT 0x0002ebe8 0x0000000e LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_ICON 0x0002e6f8 0x00000468 LANG_KANNADA SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x0002e6f8 0x00000468 LANG_KANNADA SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x0002e6f8 0x00000468 LANG_KANNADA SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x0002e6f8 0x00000468 LANG_KANNADA SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x0002e6f8 0x00000468 LANG_KANNADA SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x0002e6f8 0x00000468 LANG_KANNADA SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x0002e6f8 0x00000468 LANG_KANNADA SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x0002e6f8 0x00000468 LANG_KANNADA SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_STRING 0x0002f2e8 0x000003de LANG_HUNGARIAN SUBLANG_DEFAULT data
RT_STRING 0x0002f2e8 0x000003de LANG_HUNGARIAN SUBLANG_DEFAULT data
RT_STRING 0x0002f2e8 0x000003de LANG_HUNGARIAN SUBLANG_DEFAULT data
RT_GROUP_ICON 0x0002eb60 0x00000076 LANG_KANNADA SUBLANG_DEFAULT data
RT_VERSION 0x0002ebf8 0x000001b4 LANG_NEUTRAL SUBLANG_NEUTRAL data
None 0x0002ebd8 0x0000000a LANG_NEUTRAL SUBLANG_NEUTRAL data

Imports

Library KERNEL32.dll:
0x418000 HeapReAlloc
0x418004 FindVolumeClose
0x41800c FindResourceExW
0x418010 HeapAlloc
0x418014 EndUpdateResourceW
0x418020 AddConsoleAliasW
0x418024 SetEvent
0x41802c SleepEx
0x418030 GetTickCount
0x418034 GetProcessHeap
0x41803c GlobalAlloc
0x418040 InitAtomTable
0x418044 FindNextVolumeW
0x418048 GetTapePosition
0x41804c WriteConsoleW
0x418050 GetMailslotInfo
0x418054 GetModuleFileNameW
0x418058 CreateActCtxA
0x418060 GetProcAddress
0x418064 VirtualAlloc
0x41806c GetAtomNameA
0x418070 LoadLibraryA
0x418074 GetModuleFileNameA
0x41807c TlsFree
0x418080 lstrcpyA
0x418084 CreateFileW
0x418088 HeapSize
0x41808c DecodePointer
0x418090 EncodePointer
0x418094 GetCommandLineA
0x418098 HeapSetInformation
0x41809c GetStartupInfoW
0x4180a4 GetLastError
0x4180a8 WideCharToMultiByte
0x4180ac SetHandleCount
0x4180b0 GetStdHandle
0x4180b8 GetFileType
0x4180d0 IsDebuggerPresent
0x4180d4 TerminateProcess
0x4180d8 GetCurrentProcess
0x4180dc RtlUnwind
0x4180e0 SetFilePointer
0x4180e4 TlsAlloc
0x4180e8 TlsGetValue
0x4180ec TlsSetValue
0x4180f4 GetModuleHandleW
0x4180f8 SetLastError
0x4180fc GetCurrentThreadId
0x418104 HeapFree
0x418108 CloseHandle
0x41810c ExitProcess
0x418110 WriteFile
0x418118 HeapCreate
0x418120 GetCurrentProcessId
0x418128 GetConsoleCP
0x41812c GetConsoleMode
0x418130 GetCPInfo
0x418134 GetACP
0x418138 GetOEMCP
0x41813c IsValidCodePage
0x418140 Sleep
0x418144 CreateFileA
0x418148 SetStdHandle
0x41814c FlushFileBuffers
0x418150 LoadLibraryW
0x418154 RaiseException
0x418158 MultiByteToWideChar
0x41815c LCMapStringW
0x418160 GetStringTypeW
0x418164 SetEndOfFile
0x418168 ReadFile
Library USER32.dll:
0x418170 SetCursorPos

!This program cannot be run in DOS mode.
`.rdata
@.data
.bopih
@.rsrc
f-00f=
j@j ^V
HHtXHHt
?If90t
<at,<rt"<wt
URPQQh F@
^SSSSS
tRHtCHt4Ht%HtFHHt
tCHt(Ht
;t$,v-
UQPXY]Y[
tWItHIt9It
t"SS9] u
<+t"<-t
+t HHt
PPPPPPPP
PPPPPPPP
lw\c\,
=FImB*!w
J@ _uH
1LS!VS
HC^z0*
&+U$:%
]rs%TJ
.+=,0m
G/&n ;
3rFZ<`
xBlxh8]
O7IQe,
5Rf4q0`|
[sV%#&
:F3s]J+O
l[bFF%
Rh@x&`c
SA~VA3.
d[7&{I
4:)EKOe
AA1/*U
Gx2dTO
O{d2T3
WXQ`!m6VF
zYscoZ
t#RS;M
$MobLd_/
=A-nt2
/AR0{2
)L0 un
Lp+Y5o
{CxKEQ[
Z|rjP)
SI:ffn
dhxbrk
WG7s?IrE
"0FesG
+ES/>
#%ONqW
Fk29!Hha
qB[h@;
G}{7@^
r,{tjqW
tPJ:9[
)LxCOR
Ly3J*/
v5X#U3;
BKp0\x
XYEA|j
$kuMZ
#i:,mj
7(I<-Z
.6sB/
ILMNwk
zl3zt*g
;(Ez\.
MkQQGeT
T-vvp4
0[s c,
]i$,:?
Ql$7 `ck
?uZEeu
?uZEeu
?UUUUUU
?UUUUUU
(null)
`h````
xpxxxx
UTF-16LE
UNICODE
RUUUUU
FlsFree
FlsSetValue
FlsGetValue
FlsAlloc
CorExitProcess
HH:mm:ss
dddd, MMMM dd, yyyy
MM/dd/yy
December
November
October
September
August
February
January
Saturday
Friday
Thursday
Wednesday
Tuesday
Monday
Sunday
`h`hhh
xppwpp
i^^?(>
Y:/(A6>
<GetProcessWindowStation
GetUserObjectInformationW
GetLastActivePopup
GetActiveWindow
MessageBoxW
_nextafter
_hypot
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
1#QNAN
1#SNAN
bivucimihupibifonevenabilowosuwuxocuremucebisenomur
VirtualProtect
kernel32.dll
LocalAlloc
C:\hayopiteletu dedepuyader\yekel.pdb
HeapReAlloc
FindVolumeClose
FindFirstChangeNotificationW
FindResourceExW
HeapAlloc
EndUpdateResourceW
SetEnvironmentVariableW
GetEnvironmentStringsW
AddConsoleAliasW
SetEvent
FlushConsoleInputBuffer
SleepEx
GetTickCount
GetProcessHeap
FindActCtxSectionStringA
GlobalAlloc
InitAtomTable
FindNextVolumeW
GetTapePosition
WriteConsoleW
GetMailslotInfo
GetModuleFileNameW
CreateActCtxA
BindIoCompletionCallback
GetProcAddress
VirtualAlloc
BeginUpdateResourceW
GetAtomNameA
LoadLibraryA
GetModuleFileNameA
GetProcessAffinityMask
TlsFree
lstrcpyA
KERNEL32.dll
SetCursorPos
USER32.dll
DecodePointer
EncodePointer
GetCommandLineA
HeapSetInformation
GetStartupInfoW
IsProcessorFeaturePresent
GetLastError
WideCharToMultiByte
SetHandleCount
GetStdHandle
InitializeCriticalSectionAndSpinCount
GetFileType
DeleteCriticalSection
EnterCriticalSection
LeaveCriticalSection
UnhandledExceptionFilter
SetUnhandledExceptionFilter
IsDebuggerPresent
TerminateProcess
GetCurrentProcess
RtlUnwind
SetFilePointer
TlsAlloc
TlsGetValue
TlsSetValue
InterlockedIncrement
GetModuleHandleW
SetLastError
GetCurrentThreadId
InterlockedDecrement
HeapFree
CloseHandle
ExitProcess
WriteFile
FreeEnvironmentStringsW
HeapCreate
QueryPerformanceCounter
GetCurrentProcessId
GetSystemTimeAsFileTime
GetConsoleCP
GetConsoleMode
GetCPInfo
GetACP
GetOEMCP
IsValidCodePage
CreateFileA
SetStdHandle
FlushFileBuffers
LoadLibraryW
RaiseException
MultiByteToWideChar
LCMapStringW
GetStringTypeW
SetEndOfFile
ReadFile
HeapSize
CreateFileW
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
2222222222222222222222222222222222222222222222222222222222222222222222222222222222222222222222222222222222222222222222222222222222222222222222222222222222222222222222222222222222222222222222222222222222222222222222222222222222222222222222222222222222$L7"1
2222222222222222
2222222222222222
Y&|2222222222222222t
3t2222222222222222
|2222222222222222
|2222222222222222
^|2222222222222222J|
22222222222222223t
|2222222222222222)
|2222222222222222)
2222222222222222||}
)2222222222222222
)2222222222222222
2222222222222222
2222222222222222
2222222222222222
2222222222222222N3
2222222222222222
2222222222222222
@2222222222222222
$222222222222222
?wii-B
222222222222222
)$222222222222222
~222222222222222
|$222222222222222
$222222222222222
$222222222222222`
$222222222222222`
$222222222222222
$2222222222222
@`222222222222a#D
`222222222222
222222222222
222222222222)
222222222222|"
222222222222
222222222222
4222222222222
222222222222
2222222222222$J
~2222222222222222222222222222222222222222222222222222222222222222222222222222222222222222222222222222
RBD~x1{9
EFF~dFP~5Po~z
ffffffffffffffffffffffffffffffffffff
ffffff
ffffffhX
ffffffhM
ffffff
ffffff
ffffff
Ehffffff
b%fffff
}Rdjffffffu
$ffffffffffffffffffffffffffffffffff
O<u*_<e:
*uoxF~
(null)
KERNEL32.DLL
mscoree.dll
runtime error
TLOSS error
SING error
DOMAIN error
- Attempt to use MSIL code from this assembly during native code initialization
This indicates a bug in your application. It is most likely the result of calling an MSIL-compiled (/clr) function from a native constructor or from DllMain.
- not enough space for locale information
- Attempt to initialize the CRT more than once.
This indicates a bug in your application.
- CRT not initialized
- unable to initialize heap
- not enough space for lowio initialization
- not enough space for stdio initialization
- pure virtual function call
- not enough space for _onexit/atexit table
- unable to open console device
- unexpected heap error
- unexpected multithread lock error
- not enough space for thread data
- abort() has been called
- not enough space for environment
- not enough space for arguments
- floating point support not loaded
AMicrosoft Visual C++ Runtime Library
<program name unknown>
Runtime Error!
Program:
HH:mm:ss
dddd, MMMM dd, yyyy
MM/dd/yy
December
November
October
September
August
February
January
Saturday
Friday
Thursday
Wednesday
Tuesday
Monday
Sunday
WUSER32.DLL
((((( H
h(((( H
H
CONOUT$
fekovimofojituzuwivuwubajiyofori
pVihoboyafihuri dixireyitireg
Lagipi xazaciraroz dafiyoxad kosifu
Zizepunuburam suji vagacux
Xemebaholisiriy
Sukoxuc gehesumeyubakes
AFX_DIALOG_LAYOUT
VS_VERSION_INFO
StringFileInform
080805a0
InternalName
bomgpiaruci.iwa
Copyright
Copyrighz (C) 2021, fudkagat
ProductVersion
15.54.32.51
VarFileInfo
Translation
gGovuginavoleji wumejes putepop jetujozuwawoxug levopexirexed wuboguvecey ziyiyo giyolugob nomotib yagis)Judisigidu rizuxuxoci yanor cuk yijanilug
.Lojo tifebihihopo mifibazotunewo gebedibofajolbFevu boxuloxapijah melum fizumisivifuzo vamawir peracacocubete dedahijaluyob femuxetegawoge ficeyi@Zipelokaj hac toru lon gehe yebopizecekin moka gum simo fuxegope2Dap tatikafadehibu fiduvigovido lozepe konazoreriw<Vosukuxixit tahacevada yitumogij pebuwoxipubac wifimaputazec
Rege ripoma8Hasuxecem feyidez bahoxuzukahoso fidediwubazisi vunifefa;Dopozafabayi feraturifa xuhiw depuvi dalubo molinig pixeniw+Hadigaxonabifon hiziyogadil cewaneca mazavo
1Yonufuwu zatuso fixeyajeraref miyuyix rosadi fehiANaziwokefek rijoyurogebetuc zekitosipudo cimoxirosur vewodat cidifNibufe deviwifawinop meduzuw vigob gosi likuwunirimiyuj waliwo lepexobetoj tiwasoxewosabi viduledehewutRufebipugine redukakazonexo lazubolunimizin neliberuwipayu suki yolelu mananeragi jerepizajo ligupifujiv fayurorisus
DHixibe kuxen jugediwuzaxexif jelijapux bik goramep fewakow focipiyuf
Mafuge
Xihenetimen
Sib tuve yepebow.Gaxoz tacucefebu zezonaponapocu figojexijunora
Antivirus Signature
No IRMA results available.