Static | ZeroBOX

PE Compile Time

2020-07-10 17:10:20

PDB Path

C:\tepu-facewusexo\dopug\tonopiniroyewu_nin.pdb

PE Imphash

2d072324798956717a479868e71b5c9d

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x00044620 0x00044800 7.90270183168
.rdata 0x00046000 0x00005be0 0x00005c00 4.78961421536
.data 0x0004c000 0x00009104 0x00001800 2.8950160892
.vogonin 0x00056000 0x00000272 0x00000400 0.0
.rsrc 0x00057000 0x00006998 0x00006a00 6.08033903001

Resources

Name Offset Size Language Sub-language File type
AFX_DIALOG_LAYOUT 0x0005c708 0x0000000e LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_CURSOR 0x0005c718 0x00000130 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_ICON 0x0005c1e0 0x00000468 LANG_LATVIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x0005c1e0 0x00000468 LANG_LATVIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x0005c1e0 0x00000468 LANG_LATVIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x0005c1e0 0x00000468 LANG_LATVIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x0005c1e0 0x00000468 LANG_LATVIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_STRING 0x0005d358 0x0000063e LANG_HUNGARIAN SUBLANG_DEFAULT data
RT_STRING 0x0005d358 0x0000063e LANG_HUNGARIAN SUBLANG_DEFAULT data
RT_STRING 0x0005d358 0x0000063e LANG_HUNGARIAN SUBLANG_DEFAULT data
RT_STRING 0x0005d358 0x0000063e LANG_HUNGARIAN SUBLANG_DEFAULT data
RT_ACCELERATOR 0x0005c6e0 0x00000018 LANG_HUNGARIAN SUBLANG_DEFAULT data
RT_ACCELERATOR 0x0005c6e0 0x00000018 LANG_HUNGARIAN SUBLANG_DEFAULT data
RT_GROUP_CURSOR 0x0005c848 0x00000014 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_GROUP_ICON 0x0005c648 0x0000004c LANG_LATVIAN SUBLANG_DEFAULT data
RT_VERSION 0x0005c860 0x000001b4 LANG_NEUTRAL SUBLANG_NEUTRAL data
None 0x0005c6f8 0x0000000a LANG_NEUTRAL SUBLANG_NEUTRAL data

Imports

Library KERNEL32.dll:
0x446000 LoadResource
0x446004 HeapAlloc
0x446008 SetMailslotInfo
0x446014 SetEvent
0x44601c GetTickCount
0x446020 TlsSetValue
0x446024 GlobalAlloc
0x44602c WriteConsoleW
0x446030 GetModuleFileNameW
0x446034 GetProcAddress
0x446038 VirtualAlloc
0x446040 PrepareTape
0x446044 GetAtomNameA
0x446048 LoadLibraryA
0x44604c WriteConsoleA
0x446058 AddConsoleAliasA
0x44605c FindNextVolumeA
0x446060 CreateFileW
0x446064 GetProcessHeap
0x446068 DecodePointer
0x44606c EncodePointer
0x446070 GetModuleHandleW
0x446074 ExitProcess
0x446078 GetCommandLineW
0x44607c HeapSetInformation
0x446080 GetStartupInfoW
0x446090 IsDebuggerPresent
0x446094 TerminateProcess
0x446098 GetCurrentProcess
0x4460a8 RtlUnwind
0x4460ac SetHandleCount
0x4460b0 GetStdHandle
0x4460b4 GetFileType
0x4460bc GetLastError
0x4460c0 SetFilePointer
0x4460c4 TlsAlloc
0x4460c8 TlsGetValue
0x4460cc TlsFree
0x4460d4 SetLastError
0x4460d8 GetCurrentThreadId
0x4460e0 HeapFree
0x4460e4 CloseHandle
0x4460e8 LoadLibraryW
0x4460ec WriteFile
0x4460f4 HeapCreate
0x4460fc GetCurrentProcessId
0x446104 ReadFile
0x446108 Sleep
0x44610c GetCPInfo
0x446110 GetACP
0x446114 GetOEMCP
0x446118 IsValidCodePage
0x44611c WideCharToMultiByte
0x446120 CreateFileA
0x446124 SetStdHandle
0x446128 GetConsoleCP
0x44612c GetConsoleMode
0x446130 FlushFileBuffers
0x446134 HeapSize
0x446138 RaiseException
0x44613c MultiByteToWideChar
0x446140 HeapReAlloc
0x446144 LCMapStringW
0x446148 GetStringTypeW
0x44614c SetEndOfFile
Library USER32.dll:
0x446154 SetCursorPos

!This program cannot be run in DOS mode.
`.rdata
@.data
.vogoninr
@.rsrc
f-00f=
HHtXHHt
?If90t
<at,<rt"<wt
URPQQh0A@
j@j ^V
F\=HwD
^SSSSS
QQSVWh
tRHtCHt4Ht%HtFHHt
tCHt(Ht
;t$,v-
UQPXY]Y[
tWItHIt9It
t"SS9] u
<+t"<-t
+t HHt
PPPPPPPP
PPPPPPPP
6<A5I$
$CM.V]
|%0=]:
ij($Q{
.Y'zcx
OEVw8u
D6Pn9b
QTZHQ
L0vX\)p
iA$p$1#
k91qyL
H.NNs_
vEQG0|>%
,P?X2 e8c1
4Fc.`S)
4$tXo9
/Dkz`IZ
u:;;Z4
Ao =Xm
|kv/cn6*
7"RiKsh
v<1:>%
BERgP~
QZ86|Xp+
*OKUah=/S
]K+8w"
Cf'$b{
!KU@lp
>32\U|M
%0FnOj
3x-ndOK^v}
qj4A5s{
'>{`^%
?$cNQ"
(j\)(,,x
p%`lz,t
[578>+
m<SKv-
("{o0O
qTz||96
iN~Oa"X
)<%*'"
J<1<r>
}9;M*+
J[Q'1<_
gWB.Uq
2kxG "
}?%r'8
a$B0/9?
2?}5h;%
WwV$!.
;%1b+L
@xYF;4E
!!j>P
)/,=v@
ODDV^1
7Xn%E
v$KK-U
D$;c,@
?;D')
g<TS!e
5E:Uub
[w$9 ook
H$g3z9':
lzC?]5%
.=jleqiv
hdIgw5D
#D<w`F
06p[;F=&
n<k#PN
!h$}<z
w@(X'e
Av OBO?
B(EwQ]
x5>2h_B
Xf^@]
WO!;-i
D~]b#EH
I9hL'o
xjd}-&
q=~fsY
hq!6@{
&:lK3aA~k
WT:z3E
Ta3tlB|
Zlc3y
%b#=RH
tpR5}e
k?^Yie
QFeE|Z^
4evTas
rJVyNT
,1y|[
{8q~03~r
^xPLJc
vM&!K
:;|;YR%
M1wJ2>M<|
vd`G"c
bZk2o"
kYqqi|>
6r6)J!
w,BYAY<)
MM6>/!HC
-dWfvq
Tm0X-n
}#8sXy
c`uO|Wo,
czEmQSW
e7heLW
l:qCbYb
{c_/t,
3B'Fcs
~z;3yQ
%c:1W!
D_z~R*
JO,&14
lcSW#b4
l=wL'|
-~Zv~i
hO#%2@Y
Fn;Sj&
UGJJW>
V(AC]J
&^yO]t;
|}}:)M
Lzkr~d
Ja9dq>
GXOs+(
MimH|:+
Ff"Q~lOj
~(uW<P
dg+9De
|mvc--d
J:A+R3
!H_T=p
+U&P:k
>=<(DU
dLt8:x
oM GbB
7)(+2#>
=!$Dw5S7
s3[leHa
C6?:?{$
z?KBW@
a_w(om!_
o/60(pEqUO
}k9V&}
cudIrI
FV)A:
d&}|C9
VHLH6ZW
#tN='ecto
jyInW&
f>$Pp+
;ratFH
n58#[]
r`dET0
XI*$1
.3UZ_Fm
}Q`Akh'
nPf1PG?
Qvx[k\o3
=l=y'
d8gU<@
BGmk05
eJ9?E!
BZ51U$
Py>m{0[
q=l~Wq<
Ci<TPx
?!D,aVKWVz
{rSyN6
"Yy:t^
#iQvN;
j t+};
La^LW4NI
)`i\do
?e8NL?
%h}!0C
Klw*<'D
V9#1ca@
d>r}e7.`
M+y|q'[
\7+Si^>
849bu
Vdtm3b
u!jD!7
&v't^i1
aAzTDY1
mW<Z%cc
'a''Hh.
\&&[wx4P
+-=%t&
'2nt"V
!)qyI^*
Xc]kvU
RCAC"pT
+FI;F%
Y%9I4!
r"4xovB
B@]z+s
,A>eu0FYP|
.DDq=9
KU]3/'
2W{~8]
m|2T}nQ
oDy!!8u
Zq:pE.
jLw+ZuS {(q}
E4Y<}%
WC"YY0*^z
^:s\6@8g
#fs3[l
iU{P=7_
&@:ai/
djc|vo
q>!R+z
AH[HB|
x30]ci
vB=N/j
z851^uq
h)9BOYJm
nrGz1u
[gD%a7b}
`buXeT8
fv"UY
j5mEmg
?(%5uQ
.)j#N$
eArL"oh
[$3xnh
"{xW^M
X8[e`
f9'RDe
8.v,'A
TuWT"8
avxuhm
oM8|n(n
^aK1VQ\
uddJ?oSv
\X=":H
LuOz@rK
%QWw/a
V*cUu:<
rIUk*
5N3wx<
pr;-Y<
DIEB,h
VMRukO
&`6j|{
L%QBTF
=L 5q.#
^A 6#?
<P%1Vz(
K1{Uj$cHo
]<_Im}
{ 6leC
c48O|f
|N&U^s
%+Tmd,
6Zv{CM
$7U\Y)
Uw0V.}?
5WeKS<
v:TqYn
n%%oi#
]<.oy7
fWqw;L
3U7'r(
>^(}/Y7
f5J=wk
ed?P_S
[Mvg(|x
hyj`i)!?
6u/$]A
WBYfyI
g7uQoUt
>a|It%~\iw
U^nl8F
aMi9 A
L\p_w7[]OJxu
X6NAy9
xk;yI-
L:Q1,Y
n;w[p^(
zqB(L]
;=YD?o
*`2bnDh
QD|_<l5
l4%8Z
;~W Sn
_0`+rP
#s:/dZ
7WCKn}pK
R(M>%D-L(
ZO]2\)
|BM#s9
3Flp:?
dMqCu.7q1
t jfZ8
I)E-Ba?
Xh*,dm
9Qh[41P%N
*X1gD{
Sb\J>u
8t;<g%
1i"`m&i
*c$Ebr"b
&/|3}|
]:bmo#
jG$w$?Y
eg2<cH
*Q?A]|
1Op@~a
+hi0/ac
i+&chv
>sURsG
sl~u*T
57#F^L
l'DBru
t:+>|6
&u5J;T$_T]ac
NXX!%N
4T7Y #
*A2(Z=
2irU;u
GP<P&zD)
K@m%g;
8H)(W5\
c{hSLa
u>=Wn
~xh+3
L}Z2=}#89
2#F@9e
8!3[XVp
gYZ:D3&
OG4iI\\F=
[9K3I<
% PpG2
t^el8
Uh^VVv
e2vQLV
m.6l(6
68F-pD9=
;QLu4h
YhAuch
]e"^yh[
X<?}Rd
L=<BcV
D 2T?n
-o)$%=Z
z:\>]^x
nHqic.|c I:
3GYmhpK:ox
l<6[Z7i
DwH_=.
lF.xF%
*o*@Clb]
<L!|Kn
Xi7Icq
~>s/a
&QR{X4}\N
U:O`D1
yqq4{*
"u@r={
Y|+f-
1ZX"/Q
/t5UXE0
$%wO'L%[e
an4 B
'24-!t
vqktlJ]
AQ#1E
OD%sfG,
,tqV?z
1|m=p6
c65W8vuo
|@H;~c
kg2OJMp
Bt1=0D
"_ou]g
1D[Vus
H81l[+
z4XF,>
=$B"_.
1TPs&C<
?o2,;dE
Z"H(s!
cuvb7>
vf3lxD.j
u,D!zK
OGk*4v
A\O#m?
"PHz,
.CM?>W
=!@cTW
cXMooh
MR9NK!
CorExitProcess
?uZEeu
?uZEeu
?UUUUUU
?UUUUUU
(null)
`h````
xpxxxx
UTF-16LE
UNICODE
RUUUUU
FlsFree
FlsSetValue
FlsGetValue
FlsAlloc
HH:mm:ss
dddd, MMMM dd, yyyy
MM/dd/yy
December
November
October
September
August
February
January
Saturday
Friday
Thursday
Wednesday
Tuesday
Monday
Sunday
`h`hhh
xppwpp
i^^?(>
Y:/(A6>
<GetProcessWindowStation
GetUserObjectInformationW
GetLastActivePopup
GetActiveWindow
MessageBoxW
_nextafter
_hypot
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
1#QNAN
1#SNAN
VirtualProtect
kernel32.dll
LocalAlloc
Yulun xakay boz makige
C:\tepu-facewusexo\dopug\tonopiniroyewu_nin.pdb
LoadResource
HeapAlloc
SetMailslotInfo
SetEnvironmentVariableW
GetEnvironmentStringsW
SetEvent
FlushConsoleInputBuffer
GetTickCount
TlsSetValue
GlobalAlloc
SetConsoleCursorPosition
WriteConsoleW
GetModuleFileNameW
GetProcAddress
VirtualAlloc
BeginUpdateResourceW
PrepareTape
GetAtomNameA
LoadLibraryA
WriteConsoleA
FindFirstChangeNotificationA
GetProcessAffinityMask
AddConsoleAliasA
FindNextVolumeA
KERNEL32.dll
SetCursorPos
USER32.dll
DecodePointer
EncodePointer
GetModuleHandleW
ExitProcess
GetCommandLineW
HeapSetInformation
GetStartupInfoW
IsProcessorFeaturePresent
UnhandledExceptionFilter
SetUnhandledExceptionFilter
IsDebuggerPresent
TerminateProcess
GetCurrentProcess
EnterCriticalSection
LeaveCriticalSection
InitializeCriticalSectionAndSpinCount
RtlUnwind
SetHandleCount
GetStdHandle
GetFileType
DeleteCriticalSection
GetLastError
SetFilePointer
TlsAlloc
TlsGetValue
TlsFree
InterlockedIncrement
SetLastError
GetCurrentThreadId
InterlockedDecrement
HeapFree
CloseHandle
LoadLibraryW
WriteFile
FreeEnvironmentStringsW
HeapCreate
QueryPerformanceCounter
GetCurrentProcessId
GetSystemTimeAsFileTime
ReadFile
GetCPInfo
GetACP
GetOEMCP
IsValidCodePage
WideCharToMultiByte
CreateFileA
SetStdHandle
GetConsoleCP
GetConsoleMode
FlushFileBuffers
HeapSize
RaiseException
MultiByteToWideChar
HeapReAlloc
LCMapStringW
GetStringTypeW
SetEndOfFile
GetProcessHeap
CreateFileW
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
<<+ c
Pmy~uu
!:8|ZR?
<Nz}LMz
8PS}|>U
Abz~nO@|
ZrszzNG|
5h}zqM[
Ild}}DI
}hj}yea
]up~~PZ|
f!\}l(;
c}n U{r&;
|~~qz}
Dl}~]FI
|`W{{X^
Wbyzri
mscoree.dll
(null)
KERNEL32.DLL
runtime error
TLOSS error
SING error
DOMAIN error
- Attempt to use MSIL code from this assembly during native code initialization
This indicates a bug in your application. It is most likely the result of calling an MSIL-compiled (/clr) function from a native constructor or from DllMain.
- not enough space for locale information
- Attempt to initialize the CRT more than once.
This indicates a bug in your application.
- CRT not initialized
- unable to initialize heap
- not enough space for lowio initialization
- not enough space for stdio initialization
- pure virtual function call
- not enough space for _onexit/atexit table
- unable to open console device
- unexpected heap error
- unexpected multithread lock error
- not enough space for thread data
- abort() has been called
- not enough space for environment
- not enough space for arguments
- floating point support not loaded
DMicrosoft Visual C++ Runtime Library
<program name unknown>
Runtime Error!
Program:
HH:mm:ss
dddd, MMMM dd, yyyy
MM/dd/yy
December
November
October
September
August
February
January
Saturday
Friday
Thursday
Wednesday
Tuesday
Monday
Sunday
WUSER32.DLL
((((( H
h(((( H
H
CONOUT$
fekovimofojituzuwivuwubajiyofori
teyawuyozahamigusimuhobusokuveragen
ladubokomumajopovugavatezuko
AFX_DIALOG_LAYOUT
VS_VERSION_INFO
StringFileInform
090905a0
InternalName
bomgpiaruci.iwa
Copyright
Copyrighz (C) 2021, fudkagat
ProductVersion
15.54.32.31
VarFileInfo
Translation
gGovuginavoleji wumejes putepop jetujozuwawoxug levopexirexed wuboguvecey ziyiyo giyolugob nomotib yagis
.Lojo tifebihihopo mifibazotunewo gebedibofajolbFevu boxuloxapijah melum fizumisivifuzo vamawir peracacocubete dedahijaluyob femuxetegawoge ficeyi@Zipelokaj hac toru lon gehe yebopizecekin moka gum simo fuxegope2Dap tatikafadehibu fiduvigovido lozepe konazoreriw<Vosukuxixit tahacevada yitumogij pebuwoxipubac wifimaputazec
<Hewanurekig pecegeced hipufizowomoces zejahixevi yadatacusex
Rege ripoma8Hasuxecem feyidez bahoxuzukahoso fidediwubazisi vunifefa;Dopozafabayi feraturifa xuhiw depuvi dalubo molinig pixeniw+Hadigaxonabifon hiziyogadil cewaneca mazavo
1Yonufuwu zatuso fixeyajeraref miyuyix rosadi fehiANaziwokefek rijoyurogebetuc zekitosipudo cimoxirosur vewodat cidifNibufe deviwifawinop meduzuw vigob gosi likuwunirimiyuj waliwo lepexobetoj tiwasoxewosabi viduledehewutRufebipugine redukakazonexo lazubolunimizin neliberuwipayu suki yolelu mananeragi jerepizajo ligupifujiv fayurorisus
DHixibe kuxen jugediwuzaxexif jelijapux bik goramep fewakow focipiyuf
Mafuge
Xihenetimen
Sib tuve yepebow.Gaxoz tacucefebu zezonaponapocu figojexijunora
Vobazuhabimon hes codec<Wawozitaful vihowodo xuvegepoxo jule hepu kesevoxaw tugepiruJRoyixihir rukeboga cenilibivirepe hegoneko puxesuk zuxahehiri hahaz vacoce;Horenude foh yirika kizeferavibira vuzuzimoke jifejituhokoy2Somefupekiz fucokuluwa disatete neparug nojekucapeKCejude fufuju kihe jonasihayiba fegafo panaledabuleno bivivoj toxagalovubuc$Pemilorugugeha rekusemene piha zijux_Lilujidili coc tafog panogoy kisudepimev nugefewof fehebitemeger hikinagajox pemelokinuf ronabe#Yeyodup yihojejizuxahud vufumubutat/Zehogocotimehuw revim bawijifa jibobin kifurese>Vuf woregewaxofibe capopiwupubex xovokidecule ved fumu vifibowSRucahe mone xixeyiy lohalehix bihiwepa kinuy kasaxobanupugop yacutafi fawigas nugecTGewiro fezewuxasoxi xexifojituk zahojesucad fenejoyodojo xayi puti kiciweconir lovid
Antivirus Signature
Bkav W32.AIDetect.malware1
Lionic Clean
Elastic malicious (high confidence)
MicroWorld-eScan Gen:Variant.Jaik.49038
FireEye Generic.mg.4fb120e5975e3a7b
CAT-QuickHeal Clean
ALYac Clean
Cylance Unsafe
VIPRE Clean
Sangfor Trojan.Win32.Save.a
K7AntiVirus Clean
BitDefender Gen:Variant.Jaik.49038
K7GW Hacktool ( 700007861 )
Cybereason malicious.50fbde
Baidu Clean
Cyren W32/Kryptik.FOQ.gen!Eldorado
Symantec Packed.Generic.528
ESET-NOD32 a variant of Win32/Kryptik.HNEE
APEX Malicious
Paloalto Clean
ClamAV Clean
Kaspersky VHO:Trojan.Win32.Injuke.gen
Alibaba Clean
NANO-Antivirus Clean
ViRobot Clean
Rising Malware.Heuristic!ET#90% (RDMK:cmRtazpb8RJbG4OX/03p6eeMjZXu)
Ad-Aware Gen:Variant.Jaik.49038
Sophos ML/PE-A + Troj/Krypt-BO
Comodo Clean
F-Secure Clean
DrWeb Clean
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition BehavesLike.Win32.Lockbit.fc
CMC Clean
Emsisoft Trojan.Crypt (A)
Ikarus Trojan.Win32.Crypt
GData Gen:Variant.Jaik.49038
Jiangmin Clean
Webroot Clean
Avira Clean
MAX malware (ai score=80)
Antiy-AVL Clean
Kingsoft Clean
Gridinsoft Clean
Arcabit Clean
SUPERAntiSpyware Clean
ZoneAlarm Clean
Microsoft Trojan:MSIL/RedLine.RPS!MTB
Cynet Malicious (score: 100)
AhnLab-V3 Clean
Acronis suspicious
McAfee Clean
TACHYON Clean
VBA32 Malware-Cryptor.2LA.gen
Malwarebytes Trojan.MalPack.GS
Panda Trj/Genetic.gen
Zoner Clean
TrendMicro-HouseCall Clean
Tencent Clean
Yandex Clean
SentinelOne Static AI - Malicious PE
MaxSecure Trojan.Malware.300983.susgen
Fortinet W32/Kryptik.HNEE!tr
BitDefenderTheta Gen:NN.ZexaF.34236.uu0@a8RtIyfI
AVG Win32:TrojanX-gen [Trj]
Avast Win32:TrojanX-gen [Trj]
CrowdStrike win/malicious_confidence_100% (W)
No IRMA results available.