Static | ZeroBOX

PE Compile Time

2020-07-09 21:04:53

PDB Path

C:\lunibi.pdb

PE Imphash

51877faeb7f9e92bd6de75ecea40ae83

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x0002f4c0 0x0002f600 7.82188465313
.rdata 0x00031000 0x00005d02 0x00005e00 4.76643400266
.data 0x00037000 0x00008fec 0x00001800 2.91209998113
.kojik 0x00040000 0x00000272 0x00000400 0.0
.rsrc 0x00041000 0x000093c0 0x00009400 5.82165270506

Resources

Name Offset Size Language Sub-language File type
AFX_DIALOG_LAYOUT 0x00047e68 0x0000000e LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_CURSOR 0x00049868 0x000000b0 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_CURSOR 0x00049868 0x000000b0 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_CURSOR 0x00049868 0x000000b0 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_CURSOR 0x00049868 0x000000b0 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_CURSOR 0x00049868 0x000000b0 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x00047918 0x00000468 LANG_KANNADA SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x00047918 0x00000468 LANG_KANNADA SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x00047918 0x00000468 LANG_KANNADA SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x00047918 0x00000468 LANG_KANNADA SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x00047918 0x00000468 LANG_KANNADA SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x00047918 0x00000468 LANG_KANNADA SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x00047918 0x00000468 LANG_KANNADA SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x00047918 0x00000468 LANG_KANNADA SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_STRING 0x00049fe0 0x000003de LANG_HUNGARIAN SUBLANG_DEFAULT data
RT_STRING 0x00049fe0 0x000003de LANG_HUNGARIAN SUBLANG_DEFAULT data
RT_STRING 0x00049fe0 0x000003de LANG_HUNGARIAN SUBLANG_DEFAULT data
RT_ACCELERATOR 0x00047e40 0x00000018 LANG_HUNGARIAN SUBLANG_DEFAULT data
RT_ACCELERATOR 0x00047e40 0x00000018 LANG_HUNGARIAN SUBLANG_DEFAULT data
RT_GROUP_CURSOR 0x00049918 0x00000022 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_GROUP_CURSOR 0x00049918 0x00000022 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_GROUP_CURSOR 0x00049918 0x00000022 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_GROUP_ICON 0x00047d80 0x00000076 LANG_KANNADA SUBLANG_DEFAULT data
RT_VERSION 0x00049940 0x000001b4 LANG_NEUTRAL SUBLANG_NEUTRAL data
None 0x00047e58 0x0000000a LANG_NEUTRAL SUBLANG_NEUTRAL data

Imports

Library KERNEL32.dll:
0x431000 HeapReAlloc
0x431004 FindVolumeClose
0x43100c FindResourceExW
0x431010 HeapAlloc
0x431014 SetMailslotInfo
0x43101c SetEvent
0x431024 SleepEx
0x431028 GetTickCount
0x431030 TlsSetValue
0x431034 GlobalAlloc
0x431038 LoadLibraryW
0x43103c InitAtomTable
0x431040 FindNextVolumeW
0x431044 WriteConsoleW
0x431048 CreateActCtxA
0x431050 GetProcAddress
0x431054 VirtualAlloc
0x43105c PrepareTape
0x431060 GetAtomNameA
0x431064 LoadLibraryA
0x431068 WriteConsoleA
0x431070 GetModuleFileNameA
0x431078 EndUpdateResourceA
0x43107c AddConsoleAliasA
0x431080 lstrcpyA
0x431084 CreateFileW
0x431088 HeapSize
0x43108c DecodePointer
0x431090 EncodePointer
0x431094 GetCommandLineA
0x431098 HeapSetInformation
0x43109c GetStartupInfoW
0x4310a4 GetLastError
0x4310a8 WideCharToMultiByte
0x4310ac SetHandleCount
0x4310b0 GetStdHandle
0x4310b8 GetFileType
0x4310d0 IsDebuggerPresent
0x4310d4 TerminateProcess
0x4310d8 GetCurrentProcess
0x4310dc RtlUnwind
0x4310e0 SetFilePointer
0x4310e4 TlsAlloc
0x4310e8 TlsGetValue
0x4310ec TlsFree
0x4310f4 GetModuleHandleW
0x4310f8 SetLastError
0x4310fc GetCurrentThreadId
0x431104 HeapFree
0x431108 CloseHandle
0x43110c ExitProcess
0x431110 WriteFile
0x431114 GetModuleFileNameW
0x43111c HeapCreate
0x431124 GetCurrentProcessId
0x43112c GetConsoleCP
0x431130 GetConsoleMode
0x431134 GetCPInfo
0x431138 GetACP
0x43113c GetOEMCP
0x431140 IsValidCodePage
0x431144 Sleep
0x431148 CreateFileA
0x43114c SetStdHandle
0x431150 FlushFileBuffers
0x431154 RaiseException
0x431158 MultiByteToWideChar
0x43115c LCMapStringW
0x431160 GetStringTypeW
0x431164 SetEndOfFile
0x431168 GetProcessHeap
0x43116c ReadFile
Library USER32.dll:
0x431174 SetCursorPos

!This program cannot be run in DOS mode.
`.rdata
@.data
.kojik
@.rsrc
f-00f=
j@j ^V
HHtXHHt
?If90t
<at,<rt"<wt
URPQQh
F\=`'C
Y;= |C
j hxbC
^SSSSS
tRHtCHt4Ht%HtFHHt
to=x~C
tCHt(Ht
;t$,v-
UQPXY]Y[
tWItHIt9It
t"SS9] u
<+t"<-t
+t HHt
u-h0NC
PPPPPPPP
PPPPPPPP
LzJ'uV
{pkLe"a_
f["gF/O
fLt3FNc3*
1mB.wT
le\h=E
B66)Y:
z3/)MT
rtr\UP
e8|@,[
CExSf%
hb>Jlaz
Jhqb2{
aZ0Rcw
N7}$hy
<%^'@3
#wPx1@
:a-_}t
p_CeB8d
1up!}O
k$/R0n
1;%3Kf_3?
v/I&nr
hXyU%+{
@=3O`'
t%4#*)
}C1lvU
Y,A(L.
Rr_p(hL
#(Sy1)
eu_f-%i
F{I$4D
7GE"uH
qFWso4
+?`$LdO
|PGeb3
da3Ob91
hl:I%WJQD
686&k?)Qks
V&=s.6
9VjV3z
M$"<*I
:RQ?h#D
(fOZ)u@
<y.$,
oZ_[gl
&]Y54sw
[\4`<\%:
O39a@-
#~WKeDT
I$gPnLl
6 1C<yz
YH(&'f"a
iK0>H)
5<xRC;p
l*j$"
sK6:z48
2*I$nv
El0C~S
fWe{m$+
!JO0_;f
:OMe]d
h)|ZxC8
VX!m*N}:
~oS\2i
eYjSgc2>g# #@i
Hv\o%c
'U%0SD
M%"Lq
Ul"le9
vUjB*I
<$);Ff
n8NG1I
x}'*AVd
eWwVuY
JnjE x
=uJI*V
){1_)Q
qn-/[P
)XWnh)$Y'
i[{$/5^
2*i9np
[5`<4h
3/X&%kG~
`;gAp
B$T,KY=Z
m+"e!(
\<5KwP
>{%4fY@g
:aW:Ue
1.eR_X
SSmL %
v)dvoea
B(FRKS
yr\1x3
d/;oH*
9,vi/;
JVt}wM
^!nh:
HjNOcD
wp-Ez
FS-$o9
Vfxf1t*
;E,AHz,
o2vj]w
X=>8px
nK{fq/qz1b
N<CD/Z#
~Dvdse3
nm>.4HP
w]~!a]
}jnYqhhAi
|}1tf:
vA#7<_
9&-?/y
}!aKqd.
Y0; wq{
2,D[%WS1c1@{
:{G+gv
0-m"bg
d=<=`:o~6,tb
jF&xp*
51/7u<!Z
n{s$6=
r";3MM
:O}\{m
QRi"^E
RA,Lds!
R+44%%klU
Pnc"Y~
Pav5~+
TrUCxP
#n<pJY
gW+{eX&
GVWL8g
|Rp|Y<&-
7Lkfh{e
*9a]8
mWOHBd
qpiWx#
$;.)t=
q:QF`7+
3EyAHU
w|}|/
"HijltNG
Lqy:}Q
{#/qv(
y7OnrZ
o}q$!NC.s
~PGaek
-pg!!{E
RLNFdJ
=#"=)F~
z&^H1
[(\o+X
l9}7d!
[XBLF0
H(2FlFo
zD\ZTZ
bp"_Kb_
pMDBVy
ya#oP&K
>mY_=n
-t;Zl,
/{ouw,
a6a~WC,
\e9$&O
<P1?K;
5RLAR.
`SFfF?O
P'GKy-#hp
TnlNyK
YLc7t\s
:O;U 8
sJ~/8\
CJbyuH5
18.NZX
bHj}2~
2O0_0y
j_=/L:
2`i+O
xH9q`XV
)"+lf8
.0I.8#0
}d A~-@z{%w
c0]o>qi
~Il\SC
Hopli$
MtNsaJ
:^YRqX
E=O?w&
GM<#<||
mM$VF5
N( BSs
C,$$fI
q;0d!Z
hT8gZ
MDQkef
(d@K!`4G
xC?G8Ltxi
`hMt0Kv
Q7x?^t6
t dbWC
TwMcVN
d_!"~AB
iEI')&
XQ4K2Y8
>X3}2(
w8>uXD
g2u% 3
9LkvV:qH5=~
21,=0^MMiq
"[tBX!
^EZ[%tpW
WH$`D>uA
2"u60|
)/"EG.
1D`?ov
G3%.'^u
(60D}p5
9qxP_Q
fz_IhK
)Af+dKP
Zv;m{f
pG&rc\
+Nu_m4E
zAxt<;
UY];^[-
<ITBw9
xfcLT`
Sy$x`j
l[[h@
IRZ4XxaF
k DRU+
Kwot/u
)y]b!23
S:,E/L
?Z%SFZ
resA+J
?y|*3+B?~
&l8O3pr
<,_}G[
[zW$ATO
-y9b,yK
l/]%wG
rEjzs=J4
+hM!8(>
F!{7GaP
$c&1 D
Bf{"1B
5mE_[6zC
3]!$>z
Xhbs/w
m.D`t!
$HJrKRnA
u?l BE
U>#>ti
R#0*A:s
~YYpw7
?z&PAS'
;8hhFCF
?uZEeu
?uZEeu
?UUUUUU
?UUUUUU
(null)
`h````
xpxxxx
UTF-16LE
UNICODE
RUUUUU
FlsFree
FlsSetValue
FlsGetValue
FlsAlloc
CorExitProcess
HH:mm:ss
dddd, MMMM dd, yyyy
MM/dd/yy
December
November
October
September
August
February
January
Saturday
Friday
Thursday
Wednesday
Tuesday
Monday
Sunday
`h`hhh
xppwpp
i^^?(>
Y:/(A6>
<GetProcessWindowStation
GetUserObjectInformationW
GetLastActivePopup
GetActiveWindow
MessageBoxW
_nextafter
_hypot
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
1#QNAN
1#SNAN
bivucimihupibifonevenabilowosuwuxocuremucebisenomur
tevoxoxatunayidevolowuwimikoyatehil
fememacuzehavudunuhigebutuda
VirtualProtect
kernel32.dll
LocalAlloc
C:\lunibi.pdb
HeapReAlloc
FindVolumeClose
FindFirstChangeNotificationW
FindResourceExW
HeapAlloc
SetMailslotInfo
GetEnvironmentStringsW
SetEvent
FlushConsoleInputBuffer
SleepEx
GetTickCount
FindActCtxSectionStringA
TlsSetValue
GlobalAlloc
LoadLibraryW
InitAtomTable
FindNextVolumeW
WriteConsoleW
CreateActCtxA
BindIoCompletionCallback
GetProcAddress
VirtualAlloc
BeginUpdateResourceW
PrepareTape
GetAtomNameA
LoadLibraryA
WriteConsoleA
SetEnvironmentVariableA
GetModuleFileNameA
GetProcessAffinityMask
EndUpdateResourceA
AddConsoleAliasA
lstrcpyA
KERNEL32.dll
SetCursorPos
USER32.dll
DecodePointer
EncodePointer
GetCommandLineA
HeapSetInformation
GetStartupInfoW
IsProcessorFeaturePresent
GetLastError
WideCharToMultiByte
SetHandleCount
GetStdHandle
InitializeCriticalSectionAndSpinCount
GetFileType
DeleteCriticalSection
EnterCriticalSection
LeaveCriticalSection
UnhandledExceptionFilter
SetUnhandledExceptionFilter
IsDebuggerPresent
TerminateProcess
GetCurrentProcess
RtlUnwind
SetFilePointer
TlsAlloc
TlsGetValue
TlsFree
InterlockedIncrement
GetModuleHandleW
SetLastError
GetCurrentThreadId
InterlockedDecrement
HeapFree
CloseHandle
ExitProcess
WriteFile
GetModuleFileNameW
FreeEnvironmentStringsW
HeapCreate
QueryPerformanceCounter
GetCurrentProcessId
GetSystemTimeAsFileTime
GetConsoleCP
GetConsoleMode
GetCPInfo
GetACP
GetOEMCP
IsValidCodePage
CreateFileA
SetStdHandle
FlushFileBuffers
RaiseException
MultiByteToWideChar
LCMapStringW
GetStringTypeW
SetEndOfFile
GetProcessHeap
ReadFile
HeapSize
CreateFileW
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
CD_00T0T
{e_=eCe
i8?P?c?Z
i?ic??
iP?8??cc
Aii6P(8??L
ppgp7X
z$'''I
rrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrt
rrrrrrG(\
rrrrrr
vrrrrrr
rrrrrr8
rrrrrrq
rrrrrrG
rrrrrr[
+rrrrr
[rrrrWmf
2S$jrrrrrr
rrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrr
L<y)U5i8
iiiiii
iiiiii
iiiiiiiiiiii
iiiiiiiiii
iiiiii
iiiiiiiii
iiiiiiiiiiiii
iiiiiiii

(null)
KERNEL32.DLL
mscoree.dll
runtime error
TLOSS error
SING error
DOMAIN error
- Attempt to use MSIL code from this assembly during native code initialization
This indicates a bug in your application. It is most likely the result of calling an MSIL-compiled (/clr) function from a native constructor or from DllMain.
- not enough space for locale information
- Attempt to initialize the CRT more than once.
This indicates a bug in your application.
- CRT not initialized
- unable to initialize heap
- not enough space for lowio initialization
- not enough space for stdio initialization
- pure virtual function call
- not enough space for _onexit/atexit table
- unable to open console device
- unexpected heap error
- unexpected multithread lock error
- not enough space for thread data
- abort() has been called
- not enough space for environment
- not enough space for arguments
- floating point support not loaded
CMicrosoft Visual C++ Runtime Library
<program name unknown>
Runtime Error!
Program:
HH:mm:ss
dddd, MMMM dd, yyyy
MM/dd/yy
December
November
October
September
August
February
January
Saturday
Friday
Thursday
Wednesday
Tuesday
Monday
Sunday
WUSER32.DLL
((((( H
h(((( H
H
CONOUT$
fekovimofojituzuwivuwubajiyofori
Zizepunuburam suji vagacux
Xemebaholisiriy
Sukoxuc gehesumeyubakes
AFX_DIALOG_LAYOUT
/ P6pL
,/KPip
/-P?pR
/ P6pL
,/KPip
/-P?pR
VS_VERSION_INFO
StringFileInform
080805a0
InternalName
bomgpiaruci.iwa
Copyright
Copyrighz (C) 2021, fudkagat
ProductVersion
15.54.32.51
VarFileInfo
Translation
gGovuginavoleji wumejes putepop jetujozuwawoxug levopexirexed wuboguvecey ziyiyo giyolugob nomotib yagis
.Lojo tifebihihopo mifibazotunewo gebedibofajolbFevu boxuloxapijah melum fizumisivifuzo vamawir peracacocubete dedahijaluyob femuxetegawoge ficeyi@Zipelokaj hac toru lon gehe yebopizecekin moka gum simo fuxegope2Dap tatikafadehibu fiduvigovido lozepe konazoreriw<Vosukuxixit tahacevada yitumogij pebuwoxipubac wifimaputazec
Rege ripoma8Hasuxecem feyidez bahoxuzukahoso fidediwubazisi vunifefa;Dopozafabayi feraturifa xuhiw depuvi dalubo molinig pixeniw+Hadigaxonabifon hiziyogadil cewaneca mazavo
1Yonufuwu zatuso fixeyajeraref miyuyix rosadi fehiANaziwokefek rijoyurogebetuc zekitosipudo cimoxirosur vewodat cidifNibufe deviwifawinop meduzuw vigob gosi likuwunirimiyuj waliwo lepexobetoj tiwasoxewosabi viduledehewutRufebipugine redukakazonexo lazubolunimizin neliberuwipayu suki yolelu mananeragi jerepizajo ligupifujiv fayurorisus
DHixibe kuxen jugediwuzaxexif jelijapux bik goramep fewakow focipiyuf
Mafuge
Xihenetimen
Sib tuve yepebow.Gaxoz tacucefebu zezonaponapocu figojexijunora
Antivirus Signature
Bkav W32.AIDetect.malware1
Lionic Clean
Elastic malicious (high confidence)
ClamAV Clean
FireEye Generic.mg.64ffcd32bd5f7bbb
CAT-QuickHeal Clean
McAfee Artemis!64FFCD32BD5F
Cylance Unsafe
Zillya Clean
Sangfor Trojan.Win32.Save.a
K7AntiVirus Clean
BitDefender Clean
K7GW Hacktool ( 700007861 )
CrowdStrike win/malicious_confidence_100% (D)
BitDefenderTheta Gen:NN.ZexaF.34236.qu0@aenvH2eG
Cyren W32/Kryptik.FOQ.gen!Eldorado
Symantec Packed.Generic.528
ESET-NOD32 Clean
Baidu Clean
APEX Malicious
Paloalto Clean
Cynet Malicious (score: 100)
Kaspersky Clean
Alibaba Clean
NANO-Antivirus Clean
ViRobot Clean
MicroWorld-eScan Gen:Variant.Jaik.49028
Rising Malware.Heuristic!ET#98% (RDMK:cmRtazpRw3Y5qyaXZBf3Fwj89FEi)
Ad-Aware Gen:Variant.Jaik.49028
Emsisoft Gen:Variant.Jaik.49028 (B)
Comodo Clean
F-Secure Clean
DrWeb Clean
VIPRE Clean
TrendMicro Clean
McAfee-GW-Edition BehavesLike.Win32.Lockbit.dc
CMC Clean
Sophos ML/PE-A
SentinelOne Static AI - Malicious PE
GData Gen:Variant.Jaik.49028
Jiangmin Clean
eGambit Clean
Avira Clean
MAX malware (ai score=84)
Antiy-AVL Clean
Kingsoft Clean
Gridinsoft Clean
Arcabit Clean
SUPERAntiSpyware Clean
ZoneAlarm Clean
Microsoft Trojan:Win32/Sabsik.FL.B!ml
AhnLab-V3 Clean
Acronis suspicious
VBA32 Malware-Cryptor.2LA.gen
ALYac Clean
TACHYON Clean
Malwarebytes Clean
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Tencent Clean
Yandex Clean
Ikarus Trojan.Win32.Crypt
MaxSecure Trojan.Malware.300983.susgen
Fortinet Clean
Webroot Clean
Cybereason malicious.94bdea
Avast Clean
No IRMA results available.