Static | ZeroBOX

PE Compile Time

2022-03-09 19:41:34

PE Imphash

2a33319e8149eb0ad1ce67911ded3e8f

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x0000ebe2 0x0000ec00 5.83077173892
.data 0x00010000 0x0015476c 0x00013000 7.86052632828
.rsrc 0x00165000 0x0000b1d0 0x0000b200 5.41891763241

Resources

Name Offset Size Language Sub-language File type
RT_CURSOR 0x0016ec20 0x000008a8 LANG_NEUTRAL SUBLANG_NEUTRAL dBase III DBT, version number 0, next free block index 40, 1st item "\251\317"
RT_CURSOR 0x0016ec20 0x000008a8 LANG_NEUTRAL SUBLANG_NEUTRAL dBase III DBT, version number 0, next free block index 40, 1st item "\251\317"
RT_CURSOR 0x0016ec20 0x000008a8 LANG_NEUTRAL SUBLANG_NEUTRAL dBase III DBT, version number 0, next free block index 40, 1st item "\251\317"
RT_CURSOR 0x0016ec20 0x000008a8 LANG_NEUTRAL SUBLANG_NEUTRAL dBase III DBT, version number 0, next free block index 40, 1st item "\251\317"
RT_CURSOR 0x0016ec20 0x000008a8 LANG_NEUTRAL SUBLANG_NEUTRAL dBase III DBT, version number 0, next free block index 40, 1st item "\251\317"
RT_ICON 0x0016d270 0x00000468 LANG_SAAMI SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x0016d270 0x00000468 LANG_SAAMI SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x0016d270 0x00000468 LANG_SAAMI SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x0016d270 0x00000468 LANG_SAAMI SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x0016d270 0x00000468 LANG_SAAMI SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x0016d270 0x00000468 LANG_SAAMI SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x0016d270 0x00000468 LANG_SAAMI SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x0016d270 0x00000468 LANG_SAAMI SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x0016d270 0x00000468 LANG_SAAMI SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x0016d270 0x00000468 LANG_SAAMI SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_STRING 0x0016fe90 0x0000033c LANG_SAAMI SUBLANG_DEFAULT data
RT_STRING 0x0016fe90 0x0000033c LANG_SAAMI SUBLANG_DEFAULT data
RT_STRING 0x0016fe90 0x0000033c LANG_SAAMI SUBLANG_DEFAULT data
RT_STRING 0x0016fe90 0x0000033c LANG_SAAMI SUBLANG_DEFAULT data
RT_ACCELERATOR 0x0016d750 0x00000090 LANG_SAAMI SUBLANG_DEFAULT data
RT_GROUP_CURSOR 0x0016ebf0 0x00000030 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_GROUP_CURSOR 0x0016ebf0 0x00000030 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_GROUP_CURSOR 0x0016ebf0 0x00000030 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_GROUP_ICON 0x0016d6d8 0x00000076 LANG_SAAMI SUBLANG_DEFAULT data
RT_GROUP_ICON 0x0016d6d8 0x00000076 LANG_SAAMI SUBLANG_DEFAULT data
RT_VERSION 0x0016f4e0 0x00000260 LANG_NEUTRAL SUBLANG_NEUTRAL data

Imports

Library KERNEL32.dll:
0x40100c ReleaseMutex
0x401010 ReadConsoleInputA
0x401014 VerifyVersionInfoA
0x401018 GetCPInfoExW
0x40101c CreateEventW
0x401020 SetLocaleInfoW
0x401024 GetProcAddress
0x401028 GlobalAlloc
0x40102c DeleteFileA
0x401030 EnumResourceTypesA
0x401034 LoadLibraryW
0x401038 GetBinaryTypeA
0x40103c LocalSize
0x401040 WriteProfileStringW
0x401044 GetComputerNameExA
0x401048 GetConsoleAliasW
0x401050 GetLastError
0x401054 GetModuleHandleA
0x401058 AddAtomA
0x40105c SetSystemPowerState
0x401068 GetModuleHandleW
0x401070 GetComputerNameW
0x401074 EnumTimeFormatsA
0x401078 GetSystemDirectoryA
0x401080 FatalAppExitW
0x401084 SetSystemTime
0x40108c FoldStringW
0x401090 GetShortPathNameA
0x401094 EnumCalendarInfoW
0x401098 FindNextFileA
0x40109c LocalAlloc
0x4010a0 CreateActCtxW
0x4010a4 RtlCaptureContext
0x4010a8 CreateFileW
0x4010ac HeapSize
0x4010b0 ReadFile
0x4010b4 WriteConsoleW
0x4010b8 SetCalendarInfoA
0x4010bc LoadLibraryA
0x4010c0 MultiByteToWideChar
0x4010c4 HeapReAlloc
0x4010c8 MoveFileA
0x4010cc GetCommandLineW
0x4010d0 HeapSetInformation
0x4010d4 GetStartupInfoW
0x4010d8 GetCPInfo
0x4010e4 GetACP
0x4010e8 GetOEMCP
0x4010ec IsValidCodePage
0x4010f0 EncodePointer
0x4010f4 TlsAlloc
0x4010f8 TlsGetValue
0x4010fc TlsSetValue
0x401100 DecodePointer
0x401104 TlsFree
0x401108 SetLastError
0x40110c GetCurrentThreadId
0x401118 IsDebuggerPresent
0x40111c TerminateProcess
0x401120 GetCurrentProcess
0x401124 SetFilePointer
0x401130 HeapCreate
0x401134 HeapFree
0x401138 HeapAlloc
0x40113c SetHandleCount
0x401140 GetStdHandle
0x401148 GetFileType
0x401150 ExitProcess
0x401154 WriteFile
0x401158 GetModuleFileNameW
0x401168 GetTickCount
0x40116c GetCurrentProcessId
0x401174 WideCharToMultiByte
0x401178 LCMapStringW
0x40117c GetStringTypeW
0x401180 Sleep
0x401184 SetStdHandle
0x401188 GetConsoleCP
0x40118c GetConsoleMode
0x401190 FlushFileBuffers
0x401194 RtlUnwind
0x40119c CloseHandle
Library USER32.dll:
0x4011a4 GetCursorInfo
0x4011a8 GetMenuInfo
0x4011ac GetListBoxInfo
Library GDI32.dll:
0x401000 GetBoundsRect

!This program cannot be run in DOS mode.
`.data
zukominibog
yuhupehoxot
Nezufusihivokaz rozejari
yuteyuwerafutefexohadihorobiweb
Bonap pegaviyuwezevi
Karevofoguwoha payasegojomob
Tibicumoh
%s %d %f
HH:mm:ss
dddd, MMMM dd, yyyy
MM/dd/yy
December
November
October
September
August
February
January
Saturday
Friday
Thursday
Wednesday
Tuesday
Monday
Sunday
FlsFree
FlsSetValue
FlsGetValue
FlsAlloc
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
(null)
`h````
xpxxxx
CorExitProcess
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
`h`hhh
xppwpp
GetProcessWindowStation
GetUserObjectInformationW
GetLastActivePopup
GetActiveWindow
MessageBoxW
D$xfkp
F\=`%@
t h@7V
j@j ^V
HHtXHHt
?If90t
^SSSSS
QQSVWh
t"SS9] u
PPPPPPPP
PPPPPPPP
URPQQh
;t$,v-
UQPXY]Y[
LoadLibraryA
GetWindowsDirectoryW
FindFirstVolumeMountPointW
ReleaseMutex
ReadConsoleInputA
VerifyVersionInfoA
GetCPInfoExW
CreateEventW
SetLocaleInfoW
GetProcAddress
GlobalAlloc
DeleteFileA
EnumResourceTypesA
LoadLibraryW
GetBinaryTypeA
LocalSize
WriteProfileStringW
GetComputerNameExA
GetConsoleAliasW
WriteProfileSectionA
GetLastError
GetModuleHandleA
AddAtomA
SetSystemPowerState
SetCalendarInfoA
SetVolumeMountPointA
GetModuleHandleW
EnumResourceLanguagesA
GetComputerNameW
EnumTimeFormatsA
GetSystemDirectoryA
DeleteVolumeMountPointW
FatalAppExitW
SetSystemTime
WritePrivateProfileStringW
FoldStringW
GetShortPathNameA
EnumCalendarInfoW
FindNextFileA
LocalAlloc
CreateActCtxW
RtlCaptureContext
KERNEL32.dll
GetMenuInfo
GetCursorInfo
GetListBoxInfo
USER32.dll
GetBoundsRect
GDI32.dll
MultiByteToWideChar
HeapReAlloc
MoveFileA
GetCommandLineW
HeapSetInformation
GetStartupInfoW
GetCPInfo
InterlockedIncrement
InterlockedDecrement
GetACP
GetOEMCP
IsValidCodePage
EncodePointer
TlsAlloc
TlsGetValue
TlsSetValue
DecodePointer
TlsFree
SetLastError
GetCurrentThreadId
UnhandledExceptionFilter
SetUnhandledExceptionFilter
IsDebuggerPresent
TerminateProcess
GetCurrentProcess
SetFilePointer
EnterCriticalSection
LeaveCriticalSection
HeapCreate
HeapFree
HeapAlloc
SetHandleCount
GetStdHandle
InitializeCriticalSectionAndSpinCount
GetFileType
DeleteCriticalSection
ExitProcess
WriteFile
GetModuleFileNameW
FreeEnvironmentStringsW
GetEnvironmentStringsW
QueryPerformanceCounter
GetTickCount
GetCurrentProcessId
GetSystemTimeAsFileTime
WideCharToMultiByte
LCMapStringW
GetStringTypeW
SetStdHandle
GetConsoleCP
GetConsoleMode
FlushFileBuffers
RtlUnwind
IsProcessorFeaturePresent
WriteConsoleW
ReadFile
HeapSize
CreateFileW
CloseHandle
JL;0hE
3>zIb]
lE/xw$ 2S
7!OW`=
Qpua/Y
LryB$j
cHxa>;4
A%-=+[
'pqi/(
AEGhVq
9rdXH0
Dp+lyK
k(dc+x`
q3Sz,9
j[>&cr
!C^jpH
8H{VM.
taA`abm
|.e7[+y
.1+X\N
_v#JpPT
Y.,wz=S8
@F6U]]
8cDi\0
#04%XM:z
Nedpqk
>&@V:[Ze
MM4vSN
"UE?
;Tt|A
0?s%Q\
Yr,BzE
#38ZJg
sTlXC<%
;;?\nic
3y"X.=
+[\$#0G
y1\Uus
P2C63E
ltBRaY
G|ss5w
q7V1cF
d>fOs'
:!!s&,
n7*)g+kXO8K
#>%[xy4
tFPFwK*
d*hn"y
#dx^Pw
e=>Vp2
{<~:n^K
~*I;v&
eESz}v
fVo(d11
Cs4W1*
%eg&~w
4<$H-t
1k/Phd
(TjRug
Alq~D6
[&?Z7l1
C<`RfL
Q3f(PP
ugr'gy
Z k{lY
WH\$i%#
R;D$FOX
6S](UE
:w3-6j-
ld$_F
5YgPeW
5~P9YE[c
ny0vw(
Z/aB1`
!0EZ.CU
Q$-UCG:
|AUMml
U!0Lvr
"MebW}$
|I+/D93
#&_)M7I
z[8J0;
Q`~1)E
zK>h7Q
=r_PIDn
gU|HF@
s.@@W+m
Q7m5q/
P62gsV
1 FQDC
}or(y
~[UM#_
<,D$lx}b
iAQv:Eg
vsCV48_R
aR4/R3e
FH`>Hl
es>d
>Ji\L-
Wf_B%,
@=ASa\
+fM#u,
+~DND;
-e+\#m
{\qCs[
5s"\&|
}s:>W]U
U8@/5Va
{t_],(
-IN3gx.L
}t/kSO
+KQHjm
_1T*bm
i-!gj/~
p4@)c1)
JG0@s_
ip\R2U
E<l{m*
;$)5og<
d}[&<_z
\9:\s#
dW)sA,ck
AO\jDn@@
cBfz>I
9Le,w?
,UDV.X
Djp;+kW5
c><W/|
-3ve}p
{Hm0szO
>4,{Jx
d8*jTU
GDa&P\
Q:S5+,
#9v i
#/QQ"E
6T{ZUH
I$e,_mo+
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAA
ddd\\wwwwyy
AAAAAAAAAA
\\\\wwwyy
AAAAAAAAAA,%%
AAAAAAAAAA,%%
AAAAAAAAAA,%%
d\nAAAAAAAAAA,%%
nAAAAAAAAAA,%%
AAAAAAAAAA,%%
AAAAAAAAAA,%%
%%,AAAAAAAAAA,%%IFpp0
%%,AAAAAAAAAA,%%B99
F4pppp
%%,AAAAAAAAAA,%%
%%,AAAAAAAAAA,%%
%%,AAAAAAAAAA,%%mz
%%,AAAAAAAAAA,%%
%%,AAAAAAAAAA,%%
maa(((zz
%%,AAAAAAAAAA,%%:
%%,AAAAAAAAAA,%%
aa(m%%,AAAAAAAAAA,%%%%%%%%%%%%%%%%%%%%,AAAAAAAAAA,%%%%%%%%%%%%%%%%%%%%,AAAAAAAAAA
,,,,,,,,,,,,,,,,,,,,
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
KKKKKKKKKKKKKKKKKKKKKKKKKKPKKP?
h111111111111111111111h|{{{{{{hK
?Kh|11
1h|{{{{{
]]]]{{
1]]]]h
{1]]]
{{{{{{{
{1h]]
{{{{{{{{{{
1]]hh
1h]h
1{h]hh
111111111
1111h]hh
h111111111111111111111]hh
h111111111111111111111h]hhhh
KKKhhhh
???????????h?h?hhhh
?????????h?hhh
?????h?????
+++++++++++++++++++++++++++
u+5111111111111111111111115+
1{TTM+51
22*****
22222*****
2222*2***
2222*****
22222***
+51/
15+uT
+51/lll
lll
K?11||
ll
l15+u
xxxxxx&
+++++++++++++++++++++++++++
=kkkkkkkkkkkkk$
==bbbbbbk
k*$$q=kkkkkk=k
bkkkkkkkkk
=kkkkkkkkkkkkk
k*q-------8
cccccccc
ff!!!!
fff!!!!
fff!!!f
|wwwwww
7kkkkk|
777Q77Q77Q6
nggggggggggg~
L55555555
Vuwoyacabekopa cihahu fetariziyif
mayacoyiwe
suzagogitepuxewicadiposu hanokiw gulivitafo jodedi pesaze
pigefojo
wadagoxefivoletirogujovame pahiniposudonevihidirarehehujuba ziboho sihoxaxicemekejevunupehuy pigidafudiwagenohaxi
gratepididinetawiwilohexayiza xirenomonohimayuhocu
tVezejabimujan wazuzewuyetujab nadexa kupuhefopopo
Xekazupani guvirimohel zasaxumug herewaxokaj kuk
Tuhijecozimok kemame
Rumep tuzevozuyade muverisojiti zukane
zugifamehiwicuyikipijudiv
wejipudofowilozayogamaso
HH:mm:ss
dddd, MMMM dd, yyyy
MM/dd/yy
December
November
October
September
August
February
January
Saturday
Friday
Thursday
Wednesday
Tuesday
Monday
Sunday
nKERNEL32.DLL
(null)
mscoree.dll
runtime error
TLOSS error
SING error
DOMAIN error
- Attempt to use MSIL code from this assembly during native code initialization
This indicates a bug in your application. It is most likely the result of calling an MSIL-compiled (/clr) function from a native constructor or from DllMain.
- not enough space for locale information
- Attempt to initialize the CRT more than once.
This indicates a bug in your application.
- CRT not initialized
- unable to initialize heap
- not enough space for lowio initialization
- not enough space for stdio initialization
- pure virtual function call
- not enough space for _onexit/atexit table
- unable to open console device
- unexpected heap error
- unexpected multithread lock error
- not enough space for thread data
- abort() has been called
- not enough space for environment
- not enough space for arguments
- floating point support not loaded
@Microsoft Visual C++ Runtime Library
<program name unknown>
Runtime Error!
Program:
((((( H
h(((( H
H
WUSER32.DLL
VCONOUT$
/ P6pL
,/KPip
/-P?pR
VS_VERSION_INFO
StringFileInfo
046205E6
CompanyName
Furious
FileDescription
WholeSheet
FileVersion
25.71.48.45
InternalName
GorgerousVar.exe
LegalTrademarks1
Coordinator inc.
OriginalFilename
pskodkfgnosfd.exe
VarFileInfo
Translation
NRuyubixike watekocobesud ramapagehuvanit koyebumew widexoxeniwucop xusivah fen
$Ribuvuhovi lolokakopi buhasipowemado
Kusezepukenicet+Wazitujazohafa cewe musemuyecay napixonoxow^Xuno geludexodokebev lakax yinuxelu duholomezese ganemobodojab pipumajukuh rene meguke turuces5Dubepehedififix voleboxi xojivofepukoko papeki hehuhi
Zon suvemuyuzEWadakelol wacebopalohoga ney zibeta vupetej kozasuhimad sad natuzowex
Kedono pokeviret
+Cigomebehize benil yawizejonidadat yuwopato
gCoh xote wadabufisika misoxovasekatim foxebudetapetih gawihumi dujirewasad fijokexamo holaca hayujisoxi5Runa vuxexibikojemon xupejotekin gazis tahit fopatobo
Zufegasazek fuf
LCahohamoje wisayuwobige gop gay kejanehixihazom gixinagidur deminuwatiya gek
Xigavetiviromu
Hiy'Jumoyi taralugelase zamogatega luwapufo
Jigilemup jareva dafo[Zodeyug mono heru mococihuluz ruli xuboyizodik morukojimuzode fideluxif hal jofuhibirefoguz&Raraj wukivuvefas hovemav sugihadavezo
jZic fodoniguburo roxobun sujezedaxatoce gub hazusufurohuvu lidinirori sojunituto cizahitiruzahij hutikimebiNagoyeruduraho lekotil nazuzireboxa wosaseheva girageyexule bikem pasikol diwad ziroxugoburuzu ripaluyema
?Mayunen jitovobezawasus howayunu nijesutej nomidomofo ziyevedegVGifuyimosey gucigadojujohu vime zinih hijebet geho laf wawizis begavisucaw dalelerepih
Antivirus Signature
Bkav W32.AIDetectNet.01
Lionic Trojan.Win32.Stealer.12!c
tehtris Clean
MicroWorld-eScan Gen:Variant.Zusy.452153
ClamAV Clean
FireEye Generic.mg.60b55a03146e3388
CAT-QuickHeal Clean
ALYac Gen:Variant.Zusy.452153
Cylance unsafe
Zillya Clean
Sangfor Trojan.Win32.Save.a
K7AntiVirus Trojan ( 0059fbe91 )
BitDefender Gen:Variant.Zusy.452153
K7GW Trojan ( 0059fbe91 )
Cybereason malicious.de5092
Baidu Win32.Trojan.Kryptik.jm
VirIT Clean
Cyren W32/Convagent.BP.gen!Eldorado
Symantec ML.Attribute.HighConfidence
Elastic malicious (high confidence)
ESET-NOD32 a variant of Win32/Kryptik.HSYD
APEX Malicious
Paloalto generic.ml
Cynet Malicious (score: 100)
Kaspersky HEUR:Trojan-Spy.Win32.Stealer.gen
Alibaba TrojanSpy:Win32/Stealer.0a15b5db
NANO-Antivirus Clean
ViRobot Clean
Rising Backdoor.Mokes!8.619 (TFE:5:NcJp46FC0YN)
TACHYON Clean
Sophos Mal/Generic-S
F-Secure Trojan.TR/Spy.Stealer.hiebj
DrWeb Trojan.Packed2.44994
VIPRE Gen:Variant.Zusy.452153
TrendMicro Clean
McAfee-GW-Edition BehavesLike.Win32.Lockbit.ch
Trapmine malicious.high.ml.score
CMC Clean
Emsisoft Gen:Variant.Zusy.452153 (B)
Ikarus Trojan.Win32.Crypt
Jiangmin Clean
Webroot W32.Trojan.Gen
Avira TR/Spy.Stealer.hiebj
Antiy-AVL Trojan[Spy]/Win32.Stealer
Gridinsoft Ransom.Win32.Sabsik.sa
Xcitium Clean
Arcabit Trojan.Zusy.D6E639
SUPERAntiSpyware Clean
ZoneAlarm HEUR:Trojan-Spy.Win32.Stealer.gen
GData Gen:Variant.Zusy.452153
Google Detected
AhnLab-V3 Infostealer/Win.SmokeLoader.C5391028
Acronis Clean
McAfee GenericRXVN-YD!60B55A03146E
MAX malware (ai score=84)
VBA32 BScope.TrojanDownloader.Deyma
Malwarebytes Trojan.MalPack.GS
Panda Trj/Genetic.gen
Zoner Clean
TrendMicro-HouseCall TROJ_GEN.R002H0CC523
Tencent Win32.Trojan-Spy.Stealer.Ssmw
Yandex Clean
SentinelOne Static AI - Malicious PE
MaxSecure Trojan.Malware.300983.susgen
Fortinet W32/Kryptik.HSYD!tr
BitDefenderTheta Clean
AVG Win32:PWSX-gen [Trj]
Avast Win32:PWSX-gen [Trj]
No IRMA results available.