Static | ZeroBOX

PE Compile Time

2020-07-18 15:46:53

PDB Path

C:\muzisifunih\xowod15\fe.pdb

PE Imphash

c8cafda4e053c1cc53231f2d3aff32c4

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x00016170 0x00016200 7.41375150067
.rdata 0x00018000 0x00003b28 0x00003c00 3.85291021387
.data 0x0001c000 0x00008ee4 0x00001800 2.84550859001
.rsrc 0x00025000 0x00013fa0 0x00014000 6.34977390181

Resources

Name Offset Size Language Sub-language File type
RT_CURSOR 0x00037a38 0x00000130 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_ICON 0x00037508 0x00000468 LANG_LATVIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x00037508 0x00000468 LANG_LATVIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x00037508 0x00000468 LANG_LATVIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x00037508 0x00000468 LANG_LATVIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x00037508 0x00000468 LANG_LATVIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x00037508 0x00000468 LANG_LATVIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x00037508 0x00000468 LANG_LATVIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x00037508 0x00000468 LANG_LATVIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x00037508 0x00000468 LANG_LATVIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x00037508 0x00000468 LANG_LATVIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x00037508 0x00000468 LANG_LATVIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x00037508 0x00000468 LANG_LATVIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x00037508 0x00000468 LANG_LATVIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x00037508 0x00000468 LANG_LATVIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x00037508 0x00000468 LANG_LATVIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x00037508 0x00000468 LANG_LATVIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x00037508 0x00000468 LANG_LATVIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x00037508 0x00000468 LANG_LATVIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x00037508 0x00000468 LANG_LATVIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x00037508 0x00000468 LANG_LATVIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x00037508 0x00000468 LANG_LATVIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_STRING 0x00038af8 0x000004a6 LANG_SLOVENIAN SUBLANG_DEFAULT data
RT_STRING 0x00038af8 0x000004a6 LANG_SLOVENIAN SUBLANG_DEFAULT data
RT_STRING 0x00038af8 0x000004a6 LANG_SLOVENIAN SUBLANG_DEFAULT data
RT_STRING 0x00038af8 0x000004a6 LANG_SLOVENIAN SUBLANG_DEFAULT data
RT_STRING 0x00038af8 0x000004a6 LANG_SLOVENIAN SUBLANG_DEFAULT data
RT_ACCELERATOR 0x00037a28 0x00000010 LANG_SLOVENIAN SUBLANG_DEFAULT data
RT_ACCELERATOR 0x00037a28 0x00000010 LANG_SLOVENIAN SUBLANG_DEFAULT data
RT_GROUP_CURSOR 0x00037b68 0x00000014 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_GROUP_ICON 0x00031160 0x0000004c LANG_LATVIAN SUBLANG_DEFAULT data
RT_GROUP_ICON 0x00031160 0x0000004c LANG_LATVIAN SUBLANG_DEFAULT data
RT_GROUP_ICON 0x00031160 0x0000004c LANG_LATVIAN SUBLANG_DEFAULT data
RT_VERSION 0x00037b80 0x000001b4 LANG_NEUTRAL SUBLANG_NEUTRAL data

Imports

Library KERNEL32.dll:
0x418008 CommConfigDialogA
0x418010 LoadResource
0x418024 BackupSeek
0x418028 GetTickCount
0x41802c GetProcessHeap
0x418034 ReadConsoleW
0x418040 InitAtomTable
0x418044 HeapValidate
0x418048 GetModuleFileNameW
0x41804c DeactivateActCtx
0x418050 GetConsoleOutputCP
0x418054 SetLastError
0x418058 GetProcAddress
0x41805c VirtualAlloc
0x418060 HeapSize
0x418068 GetAtomNameA
0x41806c LoadLibraryA
0x418070 WriteConsoleA
0x418074 LocalAlloc
0x418080 DeleteAtom
0x418084 AddConsoleAliasA
0x418088 FindNextVolumeA
0x41808c lstrcpyW
0x418090 LCMapStringW
0x418094 WriteConsoleW
0x418098 CreateFileW
0x41809c EncodePointer
0x4180a0 DecodePointer
0x4180a4 GetLastError
0x4180a8 HeapReAlloc
0x4180ac GetCommandLineA
0x4180b0 HeapSetInformation
0x4180b4 GetStartupInfoW
0x4180c0 IsDebuggerPresent
0x4180c4 TerminateProcess
0x4180c8 GetCurrentProcess
0x4180cc HeapAlloc
0x4180d0 Sleep
0x4180d4 GetModuleHandleW
0x4180d8 ExitProcess
0x4180e8 SetHandleCount
0x4180ec GetStdHandle
0x4180f4 GetFileType
0x4180fc SetFilePointer
0x418100 HeapCreate
0x418104 HeapFree
0x418108 CloseHandle
0x41810c WriteFile
0x418110 GetModuleFileNameA
0x418118 WideCharToMultiByte
0x41811c TlsAlloc
0x418120 TlsGetValue
0x418124 TlsSetValue
0x418128 TlsFree
0x418130 GetCurrentThreadId
0x418138 GetCurrentProcessId
0x41813c LoadLibraryW
0x418140 RtlUnwind
0x418144 GetCPInfo
0x418148 GetACP
0x41814c GetOEMCP
0x418150 IsValidCodePage
0x418154 RaiseException
0x418158 SetStdHandle
0x41815c GetConsoleCP
0x418160 GetConsoleMode
0x418164 FlushFileBuffers
0x418168 MultiByteToWideChar
0x41816c GetStringTypeW
Library USER32.dll:
0x418174 MessageBeep
Library ADVAPI32.dll:
0x418000 AdjustTokenGroups

!This program cannot be run in DOS mode.
`.rdata
@.data
^uQVVV
HHtXHHt
?If90t
tWItHIt9It
j@j ^V
^SSSSS
tRHtCHt4Ht%HtFHHt
URPQQh@
;t$,v-
UQPXY]Y[
t"SS9] u
PPPPPPPP
PPPPPPPP
<+t"<-t
+t HHt
|v}E[X4u
d]c8&y
1#sNZaf]
QAfWj=
-v1PH,
D%2oF8
_3)a\?Qya
nC8oCI6
~;-g8/
bQpsO/Luh
3Cg@TU
Rg.)w3
jn//oI
f[pwpQ
H^@&a]
^3M)N$
fj 6uL
YB1r9r
A^(E^C
A38<;)$
}e=/d}
d8Iy6 .m8K |
()b4fY
nHwm:A
<+7Mky
dpf~u>
K0q<d8
kKm%M;
<Ut>l?
.Z&j#"z
~'H*(P
Gml `E+`
3{R( z
?/kz[t
N(6MI_
>0Vo;t3
TY8O<i
li +vc
DH|(K,
Pl8(RK
yHp7=Xp
Pw0.6a-
-Y 0|0gw
7^v?<8
-P6,*r
~lz|jN
GYt1~x
"rc}C
(=uyh
r}aX&)
O@/K.O
CF`$.M
a^eJ[2
8UmBFD6
2/X6lbN
W-=p9n
|[<hRP
jq&Ylor
CorExitProcess
(null)
`h````
xpxxxx
FlsFree
FlsSetValue
FlsGetValue
FlsAlloc
HH:mm:ss
dddd, MMMM dd, yyyy
MM/dd/yy
December
November
October
September
August
February
January
Saturday
Friday
Thursday
Wednesday
Tuesday
Monday
Sunday
`h`hhh
xppwpp
_nextafter
_hypot
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
GetProcessWindowStation
GetUserObjectInformationW
GetLastActivePopup
GetActiveWindow
MessageBoxW
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
1#QNAN
1#SNAN
Lazexohex xewiset gepes
Zohiboluvitepem
Damilasosasalep
tilibevonisesayetecacimofizojokepabovobaciki
saxaxos
VirtualProtect
kernel32.dll
LocalAlloc
C:\muzisifunih\xowod15\fe.pdb
CommConfigDialogA
GetDefaultCommConfigW
LoadResource
GetSystemWindowsDirectoryW
QueryPerformanceCounter
GetEnvironmentStringsW
SetConsoleScreenBufferSize
BackupSeek
GetTickCount
GetProcessHeap
GetSystemTimeAsFileTime
ReadConsoleW
GetFirmwareEnvironmentVariableA
GetProcessHandleCount
InitAtomTable
HeapValidate
GetModuleFileNameW
DeactivateActCtx
GetConsoleOutputCP
SetLastError
GetProcAddress
VirtualAlloc
HeapSize
BeginUpdateResourceW
GetAtomNameA
LoadLibraryA
WriteConsoleA
LocalAlloc
GetProcessAffinityMask
GetConsoleCursorInfo
DeleteAtom
AddConsoleAliasA
FindNextVolumeA
lstrcpyW
LCMapStringW
KERNEL32.dll
MessageBeep
USER32.dll
AdjustTokenGroups
ADVAPI32.dll
EncodePointer
DecodePointer
GetLastError
HeapReAlloc
GetCommandLineA
HeapSetInformation
GetStartupInfoW
UnhandledExceptionFilter
SetUnhandledExceptionFilter
IsDebuggerPresent
TerminateProcess
GetCurrentProcess
HeapAlloc
GetModuleHandleW
ExitProcess
EnterCriticalSection
LeaveCriticalSection
IsProcessorFeaturePresent
SetHandleCount
GetStdHandle
InitializeCriticalSectionAndSpinCount
GetFileType
DeleteCriticalSection
SetFilePointer
HeapCreate
HeapFree
CloseHandle
WriteFile
GetModuleFileNameA
FreeEnvironmentStringsW
WideCharToMultiByte
TlsAlloc
TlsGetValue
TlsSetValue
TlsFree
InterlockedIncrement
GetCurrentThreadId
InterlockedDecrement
GetCurrentProcessId
LoadLibraryW
RtlUnwind
GetCPInfo
GetACP
GetOEMCP
IsValidCodePage
RaiseException
SetStdHandle
GetConsoleCP
GetConsoleMode
FlushFileBuffers
MultiByteToWideChar
GetStringTypeW
WriteConsoleW
CreateFileW
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
ff~f~k
4{{4&#{f{`~
l$F$5i5
.r.NrNqE
4{{{{#`#GGGGGYYhhhhh
Y?YYYY
gggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggp
S+gggggggggggggg
gggggggggggggg
cDggggggggggggg
ggggggggggggg
\Rggggggggggggg
gggggggggggggg#<
kgggggggggggggg
gggggggggggggY
ggggggggggggg
ggggggggggggg_
@ggggggggggggg+
ggggggggggggg_;5[6
ggggggggggggg
pggggggggggggg
ggggggggggggg]
Qpggggggggggggg]
pgggggggggggggl
ggggggggggggg
gggggggggggggf
ggggggggggg
DUggggggggggfw1
9pgggggggggg
#pgggggggggg
pgggggggggg
gggggggggg
gggggggggg
ggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggg
aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa
aaaaaa~
8%Daaaaaap
aaaaaapb&q
aaaaaa[
gaaaaaav
2aaaaaa~
paaaaaa6
_aaaaa
?tNaaaa
aaaaaa
aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa
MCw._8i8
CeKqioL
Ijh~~AI
LA~~c_
Bnx~bHE
U^~~IJ~
\_~~mk
\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\D
\\\\\\\\\\\\\\\\\
Os\\\\\\\\\\\\\\\\
\\\\\\\\\\\\\\\
s\\\\\\\\\\\\\\\
ts\\\\\\\\\\\\\\\
s\\\\\\\\\\\\\\\
-s\\\\\\\\\\\\\\\
s\\\\\\\\\\\\\\\
Qs\\\\\\\\\\\\\\\
s\\\\\\\\\\\\\\\
Hs\\\\\\\\\\\\\\\
\\\\\\\\\\\\\\\
\\\\\\\\\\\\\\\
\\\\\\\\\\\\\\\
\\\\\\\\\\\\\\\
\\\\\\\\\\\\\\\
\\\\\\\\\\\\\\\
6\\\\\\\\\\\\\\\\
\\\\\\\\\\\\\\\\
\\\\\\\\\\\\\\\\
\\\\\\\\\\\\\\\\
\\\\\\\\\\\\\\\\
\\\\\\\\\\\\\\\\
^\\\\\\\\\\\\\\\\
\\\\\\\\\\\\\\\\
\\\\\\\\\\\\\\\\
\\\\\\\\\\\\\\\\
\\\\\\\\\\\\\\\\e|
\\\\\\\\\\\\\\\\
UQ\\\\\\\\\\\\\\\\O
Ue\\\\\\\\\\\\\\\\^
\\\\\\\\\\\\\\\\^
\\\\\\\\\\\\\\\\
\\\\\\\\\\\\\\\\
\\\\\\\\\\\\\\\\e?
y}yRyJ
-\\\\\\\\\\\\\\\\Q
\\\\\\\\\\\\\\\\e
\\\\\\\\\\\\\\\\^
\\\\\\\\\\\\\\\\\^
\\\\\\\\\\\\\\\\\
\\\\\\\\\\\\\\\\\\
\\\\\\\\\\\\\\\\\\\\
s sssss
\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\
jW%<@Q
OOy*OO
@^@^^^@R
?E5?tv}
SdS=}~
mscoree.dll
(null)
wruntime error
TLOSS error
SING error
DOMAIN error
- Attempt to use MSIL code from this assembly during native code initialization
This indicates a bug in your application. It is most likely the result of calling an MSIL-compiled (/clr) function from a native constructor or from DllMain.
- not enough space for locale information
- Attempt to initialize the CRT more than once.
This indicates a bug in your application.
- CRT not initialized
- unable to initialize heap
- not enough space for lowio initialization
- not enough space for stdio initialization
- pure virtual function call
- not enough space for _onexit/atexit table
- unable to open console device
- unexpected heap error
- unexpected multithread lock error
- not enough space for thread data
- abort() has been called
- not enough space for environment
- not enough space for arguments
- floating point support not loaded
AMicrosoft Visual C++ Runtime Library
<program name unknown>
Runtime Error!
Program:
KERNEL32.DLL
@HH:mm:ss
dddd, MMMM dd, yyyy
MM/dd/yy
December
November
October
September
August
February
January
Saturday
Friday
Thursday
Wednesday
Tuesday
Monday
Sunday
WUSER32.DLL
((((( H
h(((( H
H
CONOUT$
fekovimofojituzuwivuwubajiyofori
pCizizikin
peraleyuwawusogeyodotu
sirucilecukucolecesokedizevatarokayemufepusuxujeposar
VS_VERSION_INFO
StringFileInform
090104a0
InternalName
bomgpiaruci.iwa
Copyright
Copyrighz (C) 2021, fudkagat
ProductVersion
15.54.12.11
VarFileInfo
Translation
)Judisigidu rizuxuxoci yanor cuk yijanilug
bFevu boxuloxapijah melum fizumisivifuzo vamawir peracacocubete dedahijaluyob femuxetegawoge ficeyi@Zipelokaj hac toru lon gehe yebopizecekin moka gum simo fuxegope2Dap tatikafadehibu fiduvigovido lozepe konazoreriw<Vosukuxixit tahacevada yitumogij pebuwoxipubac wifimaputazec
<Hewanurekig pecegeced hipufizowomoces zejahixevi yadatacusex
Rege ripoma8Hasuxecem feyidez bahoxuzukahoso fidediwubazisi vunifefa;Dopozafabayi feraturifa xuhiw depuvi dalubo molinig pixeniw+Hadigaxonabifon hiziyogadil cewaneca mazavo
ANaziwokefek rijoyurogebetuc zekitosipudo cimoxirosur vewodat cidifNibufe deviwifawinop meduzuw vigob gosi likuwunirimiyuj waliwo lepexobetoj tiwasoxewosabi viduledehewutRufebipugine redukakazonexo lazubolunimizin neliberuwipayu suki yolelu mananeragi jerepizajo ligupifujiv fayurorisus
Mafuge
Xihenetimen
Sib tuve yepebow.Gaxoz tacucefebu zezonaponapocu figojexijunora
Vobazuhabimon hes codec<Wawozitaful vihowodo xuvegepoxo jule hepu kesevoxaw tugepiruJRoyixihir rukeboga cenilibivirepe hegoneko puxesuk zuxahehiri hahaz vacoce;Horenude foh yirika kizeferavibira vuzuzimoke jifejituhokoy2Somefupekiz fucokuluwa disatete neparug nojekucapeKCejude fufuju kihe jonasihayiba fegafo panaledabuleno bivivoj toxagalovubuc$Pemilorugugeha rekusemene piha zijux_Lilujidili coc tafog panogoy kisudepimev nugefewof fehebitemeger hikinagajox pemelokinuf ronabe#Yeyodup yihojejizuxahud vufumubutat/Zehogocotimehuw revim bawijifa jibobin kifurese>Vuf woregewaxofibe capopiwupubex xovokidecule ved fumu vifibowSRucahe mone xixeyiy lohalehix bihiwepa kinuy kasaxobanupugop yacutafi fawigas nugecTGewiro fezewuxasoxi xexifojituk zahojesucad fenejoyodojo xayi puti kiciweconir lovid
-Goxapayevekehad fewomexedecugo goluyapucepadu
BodafevicamasiKFal kudulezeza pepalitorulu titedeniguzoda mibotanukuyuku rarera haheniwafeTPimonuveke xuva zovom sumipuwipi zicumibayomod ligiw jihifagusivabo citozapo wafibikKRexiyosununuti rihoxorowopal vemerey fawunujokog foco xacovuku luhohefaneru3Fucizedusimoma zex pisizasamena tagowowetapu mecawe:Dohawugox lavihitur hubusojifuzi vumebuwazicuvey pebaxitis
SurelobihayoZZecuyave vahepacuyufi siviyegi jajedapire fixitiw cabemumetinod bukofozoca xitide nihowiye
KLozevuz feninakoko ravabofagimegas zekowoxupe coh yuvugixicivebe coje codup
Antivirus Signature
Bkav W32.AIDetect.malware1
Lionic Clean
Elastic malicious (high confidence)
MicroWorld-eScan Clean
FireEye Generic.mg.435b9c498c170c22
CAT-QuickHeal Clean
McAfee RDN/Generic.hbg
Cylance Unsafe
Zillya Clean
Sangfor Trojan.Win32.Save.a
K7AntiVirus Clean
BitDefender Clean
K7GW Hacktool ( 700007861 )
Cybereason malicious.be6ce2
BitDefenderTheta Gen:NN.ZexaF.34266.lq0@aGHQdrhc
Cyren W32/Kryptik.FOQ.gen!Eldorado
Symantec Packed.Generic.528
ESET-NOD32 a variant of Win32/Kryptik.HNGP
Baidu Clean
TrendMicro-HouseCall Clean
Paloalto generic.ml
ClamAV Win.Malware.Fragtor-9907126-0
Kaspersky UDS:DangerousObject.Multi.Generic
Alibaba Clean
NANO-Antivirus Clean
ViRobot Clean
Rising Malware.Heuristic!ET#93% (RDMK:cmRtazqG1VpkSZ42BxxCmmcpjkVh)
Ad-Aware Clean
Sophos Mal/Generic-R
Comodo Clean
F-Secure Clean
DrWeb Trojan.Siggen15.38083
VIPRE Clean
TrendMicro Clean
McAfee-GW-Edition BehavesLike.Win32.Worm.ch
CMC Clean
Emsisoft Trojan.Crypt (A)
Ikarus Trojan-Ransom.StopCrypt
GData Clean
Jiangmin Clean
MaxSecure Trojan.Malware.300983.susgen
Avira Clean
MAX Clean
Antiy-AVL Clean
Kingsoft Clean
Gridinsoft Clean
Arcabit Clean
SUPERAntiSpyware Clean
APEX Malicious
Microsoft Trojan:Win32/Krypter.AA!MTB
Cynet Malicious (score: 100)
AhnLab-V3 Clean
Acronis suspicious
VBA32 Malware-Cryptor.2LA.gen
ALYac Clean
TACHYON Clean
Malwarebytes Trojan.MalPack.GS
Panda Clean
Zoner Clean
Tencent Clean
Yandex Clean
SentinelOne Static AI - Malicious PE
eGambit Unsafe.AI_Score_91%
Fortinet Clean
Webroot Clean
Avast Clean
CrowdStrike win/malicious_confidence_100% (D)
No IRMA results available.