Static | ZeroBOX

PE Compile Time

2020-10-20 18:48:41

PDB Path

C:\heh67-hoxopebumimo\wona87\fivuyevi\xolifano\tunule.pdb

PE Imphash

6d4af36ccbaddaffd179ef41d42df9cf

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x00011e13 0x00012000 6.66624670977
.rdata 0x00013000 0x00003f22 0x00004000 5.42131359641
.data 0x00017000 0x000257f8 0x0001f800 2.18671906835
.rsrc 0x0003d000 0x0000cd20 0x0000ce00 6.33122986447

Resources

Name Offset Size Language Sub-language File type
RT_CURSOR 0x00049088 0x00000130 LANG_BULGARIAN SUBLANG_DEFAULT data
RT_ICON 0x00048b48 0x00000468 LANG_BULGARIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x00048b48 0x00000468 LANG_BULGARIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x00048b48 0x00000468 LANG_BULGARIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x00048b48 0x00000468 LANG_BULGARIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x00048b48 0x00000468 LANG_BULGARIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x00048b48 0x00000468 LANG_BULGARIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x00048b48 0x00000468 LANG_BULGARIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x00048b48 0x00000468 LANG_BULGARIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x00048b48 0x00000468 LANG_BULGARIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x00048b48 0x00000468 LANG_BULGARIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x00048b48 0x00000468 LANG_BULGARIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x00048b48 0x00000468 LANG_BULGARIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x00048b48 0x00000468 LANG_BULGARIAN SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_DIALOG 0x00049388 0x00000072 LANG_BULGARIAN SUBLANG_DEFAULT data
RT_STRING 0x00049a48 0x000002d4 LANG_BULGARIAN SUBLANG_DEFAULT data
RT_STRING 0x00049a48 0x000002d4 LANG_BULGARIAN SUBLANG_DEFAULT data
RT_STRING 0x00049a48 0x000002d4 LANG_BULGARIAN SUBLANG_DEFAULT data
RT_ACCELERATOR 0x00049060 0x00000028 LANG_BULGARIAN SUBLANG_DEFAULT data
RT_ACCELERATOR 0x00049060 0x00000028 LANG_BULGARIAN SUBLANG_DEFAULT data
RT_GROUP_CURSOR 0x000491b8 0x00000014 LANG_BULGARIAN SUBLANG_DEFAULT data
RT_GROUP_ICON 0x00048fb0 0x0000004c LANG_BULGARIAN SUBLANG_DEFAULT data
RT_GROUP_ICON 0x00048fb0 0x0000004c LANG_BULGARIAN SUBLANG_DEFAULT data
RT_VERSION 0x000491d0 0x000001b8 LANG_BULGARIAN SUBLANG_DEFAULT COM executable for DOS

Imports

Library KERNEL32.dll:
0x413004 GetLocaleInfoA
0x413008 SetComputerNameExA
0x41300c VirtualQuery
0x413014 FindResourceExW
0x413018 OpenJobObjectA
0x41301c GetConsoleAliasA
0x413024 CompareFileTime
0x413028 GetProfileSectionA
0x41302c GetConsoleAliasesA
0x413030 GetConsoleTitleA
0x413034 ReadConsoleW
0x413038 SetFileTime
0x41303c GlobalAlloc
0x413040 Sleep
0x413044 GetFileAttributesW
0x413048 GetAtomNameW
0x41304c SetConsoleTitleA
0x413050 RaiseException
0x413054 GetLastError
0x413058 GetProcAddress
0x41305c GetLongPathNameA
0x413060 VirtualAlloc
0x413064 PrepareTape
0x41306c GetFileType
0x413070 GetModuleFileNameA
0x413078 GetModuleHandleA
0x41307c GetStringTypeW
0x413080 GetVersionExA
0x413084 ReadConsoleInputW
0x413088 EnumSystemLocalesW
0x41308c CreateThread
0x413090 HeapAlloc
0x413094 GetCommandLineA
0x413098 GetStartupInfoA
0x41309c RtlUnwind
0x4130a0 TerminateProcess
0x4130a4 GetCurrentProcess
0x4130b0 IsDebuggerPresent
0x4130b4 HeapFree
0x4130c4 VirtualFree
0x4130c8 HeapReAlloc
0x4130cc HeapCreate
0x4130d0 GetModuleHandleW
0x4130d4 ExitProcess
0x4130d8 WriteFile
0x4130dc GetStdHandle
0x4130e0 SetHandleCount
0x4130e4 SetFilePointer
0x4130e8 TlsGetValue
0x4130ec TlsAlloc
0x4130f0 TlsSetValue
0x4130f4 TlsFree
0x4130fc SetLastError
0x413100 GetCurrentThreadId
0x413104 CloseHandle
0x413114 WideCharToMultiByte
0x413120 GetTickCount
0x413124 GetCurrentProcessId
0x413130 LoadLibraryA
0x413134 GetCPInfo
0x413138 GetACP
0x41313c GetOEMCP
0x413140 IsValidCodePage
0x413144 CreateFileA
0x413148 SetStdHandle
0x41314c GetConsoleCP
0x413150 GetConsoleMode
0x413154 FlushFileBuffers
0x413158 HeapSize
0x41315c LCMapStringA
0x413160 MultiByteToWideChar
0x413164 LCMapStringW
0x413168 GetStringTypeA
0x41316c SetEndOfFile
0x413170 GetProcessHeap
0x413174 ReadFile
0x413178 WriteConsoleA
0x41317c GetConsoleOutputCP
0x413180 WriteConsoleW

!This program cannot be run in DOS mode.
`.rdata
@.data
WWWWWW
SSSSSS
0WWWWW
_VVVVV
0WWWWW
jXhP_A
QQSVWd
0SSSSS
t h4DA
r=PvA
<at9<rt,<wt
URPQQh
HHtXHHt
>If90t
tNIt?It0It
j@j ^V
t$hL:A
f-00f=
>=Yt1j
HtHu4j
s[S;7|G;w
YYhDDA
tR99u2
0SSSSS
0SSSSS
0A@@Ju
tGHt.Ht&
^SSSSS
8VVVVV
;t$,v-
UQPXY]Y[
^SSSSS
j"^SSSSS
_VVVVV
^WWWWW
tRHtCHt4Ht%HtFHHt
t"SS9]
PPPPPPPP
PPPPPPPP
0SSSSS
_VVVVV
t+WWVPV
<+t(<-t$:
+t HHt
u;h$WA
bad allocation
string too long
invalid string position
Unknown exception
CorExitProcess
runtime error
TLOSS error
SING error
DOMAIN error
An application has made an attempt to load the C runtime library incorrectly.
Please contact the application's support team for more information.
- Attempt to use MSIL code from this assembly during native code initialization
This indicates a bug in your application. It is most likely the result of calling an MSIL-compiled (/clr) function from a native constructor or from DllMain.
- not enough space for locale information
- Attempt to initialize the CRT more than once.
This indicates a bug in your application.
- CRT not initialized
- unable to initialize heap
- not enough space for lowio initialization
- not enough space for stdio initialization
- pure virtual function call
- not enough space for _onexit/atexit table
- unable to open console device
- unexpected heap error
- unexpected multithread lock error
- not enough space for thread data
This application has requested the Runtime to terminate it in an unusual way.
Please contact the application's support team for more information.
- not enough space for environment
- not enough space for arguments
- floating point support not loaded
Microsoft Visual C++ Runtime Library
<program name unknown>
Runtime Error!
Program:
UTF-16LE
UNICODE
(null)
`h````
xpxxxx
EncodePointer
DecodePointer
FlsFree
FlsSetValue
FlsGetValue
FlsAlloc
?uZEeu
?uZEeu
?UUUUUU
?UUUUUU
bad exception
GetProcessWindowStation
GetUserObjectInformationA
GetLastActivePopup
GetActiveWindow
MessageBoxA
USER32.DLL
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
`h`hhh
xppwpp
_nextafter
_hypot
Complete Object Locator'
Class Hierarchy Descriptor'
Base Class Array'
Base Class Descriptor at (
Type Descriptor'
`local static thread guard'
`managed vector copy constructor iterator'
`vector vbase copy constructor iterator'
`vector copy constructor iterator'
`dynamic atexit destructor for '
`dynamic initializer for '
`eh vector vbase copy constructor iterator'
`eh vector copy constructor iterator'
`managed vector destructor iterator'
`managed vector constructor iterator'
`placement delete[] closure'
`placement delete closure'
`omni callsig'
delete[]
new[]
`local vftable constructor closure'
`local vftable'
`udt returning'
`copy constructor closure'
`eh vector vbase constructor iterator'
`eh vector destructor iterator'
`eh vector constructor iterator'
`virtual displacement map'
`vector vbase constructor iterator'
`vector destructor iterator'
`vector constructor iterator'
`scalar deleting destructor'
`default constructor closure'
`vector deleting destructor'
`vbase destructor'
`string'
`local static guard'
`typeof'
`vcall'
`vbtable'
`vftable'
operator
delete
__unaligned
__restrict
__ptr64
__clrcall
__fastcall
__thiscall
__stdcall
__pascal
__cdecl
__based(
GAIsProcessorFeaturePresent
KERNEL32
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
HH:mm:ss
dddd, MMMM dd, yyyy
MM/dd/yy
December
November
October
September
August
February
January
Saturday
Friday
Thursday
Wednesday
Tuesday
Monday
Sunday
SunMonTueWedThuFriSat
JanFebMarAprMayJunJulAugSepOctNovDec
CONOUT$
1#QNAN
1#SNAN
bad allocation
holezusubiwujasifewutazopayora
Pulezufiget gacuwumuhi yofelekudurika dulikahuy
leruyisobalocakakotosodexopecud
yujacom
jipeximeyecuxovanewuhimetagovigotehotiletuwunudifizozijepunagavucekayoceroh
feditoneyuyirodefahecajaguxowuluravoyuzobibife
yazusupuxifojemevaxatomoworokavorecojesoc
VirtualProtect
runexobozez
kernel32.dll
futefohalumiluyowemaboxogarirewemixehufiwiji
vemetahupofutadiki
C:\heh67-hoxopebumimo\wona87\fivuyevi\xolifano\tunule.pdb
GetConsoleAliasesLengthW
GetLocaleInfoA
SetComputerNameExA
VirtualQuery
GetDefaultCommConfigW
FindResourceExW
OpenJobObjectA
GetConsoleAliasA
InterlockedDecrement
CompareFileTime
GetProfileSectionA
GetConsoleAliasesA
GetConsoleTitleA
ReadConsoleW
SetFileTime
GlobalAlloc
GetFileAttributesW
GetAtomNameW
SetConsoleTitleA
RaiseException
GetLastError
GetProcAddress
GetLongPathNameA
VirtualAlloc
PrepareTape
DnsHostnameToComputerNameA
GetFileType
GetModuleFileNameA
CreateIoCompletionPort
GetModuleHandleA
GetStringTypeW
GetVersionExA
ReadConsoleInputW
EnumSystemLocalesW
CreateThread
KERNEL32.dll
HeapAlloc
GetCommandLineA
GetStartupInfoA
RtlUnwind
TerminateProcess
GetCurrentProcess
UnhandledExceptionFilter
SetUnhandledExceptionFilter
IsDebuggerPresent
HeapFree
DeleteCriticalSection
LeaveCriticalSection
EnterCriticalSection
VirtualFree
HeapReAlloc
HeapCreate
GetModuleHandleW
ExitProcess
WriteFile
GetStdHandle
SetHandleCount
SetFilePointer
TlsGetValue
TlsAlloc
TlsSetValue
TlsFree
InterlockedIncrement
SetLastError
GetCurrentThreadId
CloseHandle
FreeEnvironmentStringsA
GetEnvironmentStrings
FreeEnvironmentStringsW
WideCharToMultiByte
GetEnvironmentStringsW
QueryPerformanceCounter
GetTickCount
GetCurrentProcessId
GetSystemTimeAsFileTime
InitializeCriticalSectionAndSpinCount
LoadLibraryA
GetCPInfo
GetACP
GetOEMCP
IsValidCodePage
CreateFileA
SetStdHandle
GetConsoleCP
GetConsoleMode
FlushFileBuffers
HeapSize
LCMapStringA
MultiByteToWideChar
LCMapStringW
GetStringTypeA
SetEndOfFile
GetProcessHeap
ReadFile
WriteConsoleA
GetConsoleOutputCP
WriteConsoleW
.?AVlogic_error@std@@
.?AVlength_error@std@@
.?AVout_of_range@std@@
.?AVtype_info@@
.?AVbad_exception@std@@
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
.?AVexception@std@@
%&bya2
|38b\1
!$\V=
|Mq~7GS
M*]1;8
A?XMs,
|B@;->`
i'O5@%
Z9c'P2
3dc6lo
2 P-C;@
3DKd:4=:
EvZSi::
aQ04H`
GK<8xt
5tOrs%M
Ne}0ro!+
N%YDGh
1Uxsb2g
Fm;?"J.
Rfu}<8
.TA"@%1
SIi]v<
/`M}C'v[
)5p{Y>Ab
Pil+1Z
U4_y!M8
Jb3(X@
akaid0"
Z} ]xe
h1Ab>-
X,"'c{
5HT'~4
xnXf(!:
{Y_:%U$.(
mEsIX|
(`CM9p
.?AVbad_alloc@std@@
4>`|m9D
Ahh1h1gAZ
,p00,p0
9H0HK00b0
0,00KK{
;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;Xk
;;;;;;;;;;;;;;
;;;;;;;;;;;;;;
OC;;;;;;;;;;;;;
;;;;;;;;;;;;;(
v;;;;;;;;;;;;;
;;;;;;;;;;;;;;B*
;;;;;;;;;;;;;;
;;;;;;;;;;;;;
;;;;;;;;;;;;;
;;;;;;;;;;;;;
;;;;;;;;;;;;;
;;;;;;;;;;;;;
..4;;;;;;;;;;;;;
1X;;;;;;;;;;;;;
D4;;;;;;;;;;;;;
X;;;;;;;;;;;;;
X;;;;;;;;;;;;;~
h;;;;;;;;;;;;;
l|,-=|lfN`
;;;;;;;;;;;;;
y;;;;;;;;;;;
;;;;;;;;;; -\3NY
3RG::%
X;;;;;;;;;;
,%BX;;;;;;;;;;y
EY%wX;;;;;;;;;;y
;;;;;;;;;;
;;;;;;;;;;
;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;
_>##2e
_W&P>>>
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~g
~~~~~~
~~~~~~
~~~~~~
+X^~~~~~~M
~~~~~~4
~~~~~~
~~~~~~e<+
WHe~~~~r
~~~~!k
~~~~~~
:u~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
F=s(W;j=
CeKqioL
Ijh~~AI
LA~~c_
Bnx~bHE
U^~~IJ~
\_~~mk
mscoree.dll
E(null)
KERNEL32.DLL
((((( H
h(((( H
H
ziturizobajicis
misiti
zgicupo
vofazegekasu
ERRORDIALOG
VS_VERSION_INFO
StringFileInform
124120C0
InternationalName
bomgvioci.iwa
Copyright
Copyrighz (C) 2021, fudkort
ProjectVersion
3.10.70.57
VarFileInfo
Translation
Error!
&Retry
&Abort
]Govuginavoleji wumejes putepop jetujozuxug levopexed wubovecey ziyiyo giyolugob nomotib yagis)Judisigidu rizuxuxoci yanor cuk yijanilugXSocucudum varojavuhore paju fizayaki kavun sedol donakefi lecog tifefizemodod xobapozexeNZexijupem kog piwap bejusipivixexo yare wene mafo rozisovecanupif rugifop kimoHSive palesipan gewavanuyasuran tuja weyanuj xiwelufuxuhix pifiy nusexeki
AZipelokaj hac toru lon gehe yebopizecekin moka gum simo fuxegopez2Dap tatikafadehibu fiduvigovido lozepe konazoreriw2Vosukuxixit tavada yitumogij pebuwubac wifiputazec
=Hewanurekige pecegeced hipufizowomoces zejahixevi yadatacusex
Rege ripoma8Hasuxecem feyidez bahoxuzukahoso fidediwubazisi vunifefa;Dopozafabayi feraturifa xuhiw depuvi dalubo molinig pixeniw+Hadigaxonabifon hiziyogadil cewaneca mazavo
ANaziwokefek rijoyurogebetuc zekitosipudo cimoxirosur vewodat cididNibufe deviwifawinop meduzuw vigob gosi likuwunirimiyuj waliwo lepexobetoj tiwasoxosabi viduledehewu
OHufupolika fovava sof jixa vegomibower migukux pahedev hatecuzagix liceyonihugofSufohazoraxebot welugixixus pojutafa humotamoyolu poroceviyuyi xiyumud lipocis fucoxojih weyorinumabil
Antivirus Signature
Bkav W32.AIDetect.malware2
Lionic Clean
Elastic malicious (high confidence)
Cynet Malicious (score: 100)
CMC Clean
CAT-QuickHeal Clean
McAfee Artemis!4D94112C0748
Cylance Unsafe
Zillya Clean
Sangfor Trojan.Win32.Save.a
K7AntiVirus Trojan ( 0053d5971 )
BitDefender Trojan.GenericKD.47887503
K7GW Trojan ( 0053d5971 )
Cybereason malicious.29c58b
Baidu Clean
VirIT Clean
Cyren W32/Qbot.FK.gen!Eldorado
Symantec ML.Attribute.HighConfidence
ESET-NOD32 a variant of Win32/Kryptik.HNZN
APEX Malicious
Paloalto Clean
ClamAV Win.Trojan.Generic-9935605-0
Kaspersky HEUR:Exploit.Win32.Shellcode.gen
Alibaba Clean
NANO-Antivirus Clean
ViRobot Clean
MicroWorld-eScan Trojan.GenericKD.47887503
Rising Malware.Heuristic!ET#78% (RDMK:cmRtazo2hNPH/jGIbvwuHqyWpcwr)
Ad-Aware Trojan.GenericKD.47887503
Emsisoft Clean
Comodo Clean
F-Secure Clean
DrWeb Trojan.Siggen16.32153
VIPRE Clean
TrendMicro Clean
McAfee-GW-Edition BehavesLike.Win32.Trojan.dt
FireEye Generic.mg.4d94112c0748ff7b
Sophos ML/PE-A + Mal/Agent-AWV
Ikarus Trojan.Win32.Crypt
Jiangmin Clean
Webroot Clean
Avira Clean
Antiy-AVL Clean
Kingsoft Clean
Microsoft Ransom:Win32/StopCrypt.MZF!MTB
Gridinsoft Clean
Arcabit Clean
SUPERAntiSpyware Clean
GData Clean
TACHYON Clean
AhnLab-V3 Trojan/Win.OC.C4909757
Acronis Clean
VBA32 BScope.TrojanSpy.Stealer
ALYac Clean
MAX malware (ai score=80)
Malwarebytes Clean
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Tencent Clean
Yandex Clean
SentinelOne Static AI - Malicious PE
MaxSecure Clean
Fortinet W32/GenKryptik.ERHN!tr
BitDefenderTheta Gen:NN.ZexaF.34114.qqW@aaDBeNdG
AVG Win32:CrypterX-gen [Trj]
Avast Win32:CrypterX-gen [Trj]
CrowdStrike win/malicious_confidence_100% (D)
No IRMA results available.