Static | ZeroBOX

PE Compile Time

2022-08-22 14:17:41

PE Imphash

0c16d61a145a6038e0c4acd3e1db8764

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x0000b144 0x0000b200 6.0079495492
.data 0x0000d000 0x0009066c 0x00013200 7.8437605177
.xokejo 0x0009e000 0x00000096 0x00000200 0.0
.rsrc 0x0009f000 0x0000daf0 0x0000dc00 4.47518771186

Resources

Name Offset Size Language Sub-language File type
AFX_DIALOG_LAYOUT 0x000ab598 0x00000002 LANG_NEUTRAL SUBLANG_NEUTRAL data
TONIZITOHOWAPEVUMOBEM 0x000aaea0 0x00000598 LANG_SAAMI SUBLANG_DEFAULT ASCII text, with very long lines, with no line terminators
RT_CURSOR 0x000ab7c0 0x000010a8 LANG_NEUTRAL SUBLANG_NEUTRAL dBase III DBT, version number 0, next free block index 40
RT_CURSOR 0x000ab7c0 0x000010a8 LANG_NEUTRAL SUBLANG_NEUTRAL dBase III DBT, version number 0, next free block index 40
RT_CURSOR 0x000ab7c0 0x000010a8 LANG_NEUTRAL SUBLANG_NEUTRAL dBase III DBT, version number 0, next free block index 40
RT_ICON 0x000aa9d0 0x00000468 LANG_SAAMI SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x000aa9d0 0x00000468 LANG_SAAMI SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x000aa9d0 0x00000468 LANG_SAAMI SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x000aa9d0 0x00000468 LANG_SAAMI SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x000aa9d0 0x00000468 LANG_SAAMI SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x000aa9d0 0x00000468 LANG_SAAMI SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x000aa9d0 0x00000468 LANG_SAAMI SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x000aa9d0 0x00000468 LANG_SAAMI SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x000aa9d0 0x00000468 LANG_SAAMI SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x000aa9d0 0x00000468 LANG_SAAMI SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x000aa9d0 0x00000468 LANG_SAAMI SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x000aa9d0 0x00000468 LANG_SAAMI SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ACCELERATOR 0x000ab438 0x000000a8 LANG_SAAMI SUBLANG_DEFAULT data
RT_ACCELERATOR 0x000ab438 0x000000a8 LANG_SAAMI SUBLANG_DEFAULT data
RT_GROUP_CURSOR 0x000ac868 0x00000030 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_GROUP_ICON 0x000aae38 0x00000068 LANG_SAAMI SUBLANG_DEFAULT data
RT_GROUP_ICON 0x000aae38 0x00000068 LANG_SAAMI SUBLANG_DEFAULT data
RT_GROUP_ICON 0x000aae38 0x00000068 LANG_SAAMI SUBLANG_DEFAULT data
RT_VERSION 0x000ac898 0x00000258 LANG_NEUTRAL SUBLANG_NEUTRAL data
None 0x000ab588 0x0000000a LANG_SAAMI SUBLANG_DEFAULT data
None 0x000ab588 0x0000000a LANG_SAAMI SUBLANG_DEFAULT data
None 0x000ab588 0x0000000a LANG_SAAMI SUBLANG_DEFAULT data
None 0x000ab588 0x0000000a LANG_SAAMI SUBLANG_DEFAULT data

Imports

Library KERNEL32.dll:
0x401000 PulseEvent
0x401008 FindFirstFileW
0x40100c EnumCalendarInfoA
0x401010 _llseek
0x401014 GetConsoleAliasA
0x401018 GetCurrentProcess
0x401020 SleepEx
0x401028 EnumTimeFormatsW
0x40102c WriteFileGather
0x401030 EnumResourceTypesA
0x401034 ActivateActCtx
0x401038 GlobalAlloc
0x401040 LoadLibraryW
0x401044 Sleep
0x401048 ReadConsoleInputA
0x401050 GetFileAttributesW
0x401058 TerminateProcess
0x40105c IsDBCSLeadByte
0x401060 lstrcmpW
0x401064 GlobalUnlock
0x401068 RaiseException
0x40106c SetLastError
0x401070 GetProcAddress
0x401074 GlobalGetAtomNameA
0x401078 OpenWaitableTimerA
0x40107c AddAtomA
0x401084 GetModuleHandleA
0x401088 FindNextFileW
0x40108c GetShortPathNameW
0x401090 GetCPInfoExA
0x401094 SetCalendarInfoA
0x401098 ReadConsoleInputW
0x40109c DeleteFileW
0x4010a0 EnumCalendarInfoExA
0x4010a4 LocalFree
0x4010a8 CopyFileExA
0x4010ac GetLastError
0x4010b0 DeleteFileA
0x4010b4 GetCommandLineA
0x4010b8 HeapSetInformation
0x4010bc GetStartupInfoW
0x4010c4 SetFilePointer
0x4010c8 SetHandleCount
0x4010cc GetStdHandle
0x4010d4 GetFileType
0x4010e4 IsDebuggerPresent
0x4010e8 EncodePointer
0x4010ec DecodePointer
0x4010f0 GetModuleHandleW
0x4010f4 ExitProcess
0x4010f8 WriteFile
0x4010fc GetModuleFileNameW
0x401100 GetModuleFileNameA
0x401108 WideCharToMultiByte
0x401110 TlsAlloc
0x401114 TlsGetValue
0x401118 TlsSetValue
0x40111c TlsFree
0x401124 GetCurrentThreadId
0x40112c HeapCreate
0x401134 GetTickCount
0x401138 GetCurrentProcessId
0x401140 HeapFree
0x401144 SetStdHandle
0x401148 GetConsoleCP
0x40114c GetConsoleMode
0x401150 FlushFileBuffers
0x401154 RtlUnwind
0x401158 GetCPInfo
0x40115c GetACP
0x401160 GetOEMCP
0x401164 IsValidCodePage
0x401168 HeapAlloc
0x40116c HeapReAlloc
0x401170 WriteConsoleW
0x401174 MultiByteToWideChar
0x40117c LCMapStringW
0x401180 GetStringTypeW
0x401184 HeapSize
0x401188 CloseHandle
0x40118c CreateFileW
Library USER32.dll:
0x401194 LoadMenuA

!This program cannot be run in DOS mode.
`.data
.xokejo
(null)
`h````
xpxxxx
CorExitProcess
FlsFree
FlsSetValue
FlsGetValue
FlsAlloc
HH:mm:ss
dddd, MMMM dd, yyyy
MM/dd/yy
December
November
October
September
August
February
January
Saturday
Friday
Thursday
Wednesday
Tuesday
Monday
Sunday
`h`hhh
xppwpp
GetProcessWindowStation
GetUserObjectInformationW
GetLastActivePopup
GetActiveWindow
MessageBoxW
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
sonenumojizoyub
veyexekaxaxotijiwegolitatafan
rupaneru
%s %d %f
j@j ^V
HHtXHHt
?If90t
^SSSSS
URPQQh
;t$,v-
UQPXY]Y[
t"SS9] u
PPPPPPPP
PPPPPPPP
D$tfkp
T$$SUV
u5hX*@
T$pRVV
PulseEvent
SetDefaultCommConfigA
FindFirstFileW
EnumCalendarInfoA
_llseek
GetConsoleAliasA
GetCurrentProcess
InterlockedCompareExchange
SleepEx
GetWindowsDirectoryA
EnumTimeFormatsW
WriteFileGather
EnumResourceTypesA
ActivateActCtx
GlobalAlloc
GetFirmwareEnvironmentVariableA
LoadLibraryW
ReadConsoleInputA
LeaveCriticalSection
GetFileAttributesW
WritePrivateProfileSectionW
TerminateProcess
IsDBCSLeadByte
lstrcmpW
GlobalUnlock
RaiseException
SetLastError
GetProcAddress
GlobalGetAtomNameA
OpenWaitableTimerA
AddAtomA
FindFirstVolumeMountPointA
GetModuleHandleA
FindNextFileW
GetShortPathNameW
GetCPInfoExA
SetCalendarInfoA
ReadConsoleInputW
DeleteFileW
EnumCalendarInfoExA
LocalFree
CopyFileExA
KERNEL32.dll
LoadMenuA
USER32.dll
GetLastError
DeleteFileA
GetCommandLineA
HeapSetInformation
GetStartupInfoW
EnterCriticalSection
SetFilePointer
SetHandleCount
GetStdHandle
InitializeCriticalSectionAndSpinCount
GetFileType
DeleteCriticalSection
UnhandledExceptionFilter
SetUnhandledExceptionFilter
IsDebuggerPresent
EncodePointer
DecodePointer
GetModuleHandleW
ExitProcess
WriteFile
GetModuleFileNameW
GetModuleFileNameA
FreeEnvironmentStringsW
WideCharToMultiByte
GetEnvironmentStringsW
TlsAlloc
TlsGetValue
TlsSetValue
TlsFree
InterlockedIncrement
GetCurrentThreadId
InterlockedDecrement
HeapCreate
QueryPerformanceCounter
GetTickCount
GetCurrentProcessId
GetSystemTimeAsFileTime
HeapFree
SetStdHandle
GetConsoleCP
GetConsoleMode
FlushFileBuffers
RtlUnwind
GetCPInfo
GetACP
GetOEMCP
IsValidCodePage
HeapAlloc
HeapReAlloc
WriteConsoleW
MultiByteToWideChar
IsProcessorFeaturePresent
LCMapStringW
GetStringTypeW
HeapSize
CloseHandle
CreateFileW
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
r"}.!
qanT0,E
Zyq-=z
,s)Rf1
oN`-}2E
A6_(]k
XJN#"'
F%f@Zf
2fzi06
'T\x[W
~D}a+n
n:lJ[X
6PoB(Z1
Bp$Zy[
}\!iw]z
XD;KKH}
U4Ews0i
$>W@:fu
Ag\M[M
}'}]Uu
ooLWS9=,[
gi(-$;
-WsiWs
Kcr5&~
!SpiZS
YHe+!$0
|]EvD9
DQLji1
W*Vs|Q
!![4k?x6
|!T1?
#4C=0z
';K5N(
LGHPqUGY
L^-[Eg
1`K.!/
U]RRaO
f?+8'
Tlgd#:2X
in>tk9
Z`G@I
WY`BoE5
:su+m=
C~uhz7_
7\vw8.`\*
oKd>8-
>_@< x
Nti"J|A
?4^=W^
,36H<}
19Vw<T
a&?&jw
fAsnk.
Z0_vuD
IH%#N)
jK9&bb
0Rj8<
sy"RoI:
TT\3g
UoS0~:n
y039`7
Ft$yr<>1
}}ywxUS
dN>8.TSe$:
NQix!VT
a8n1q>iN
em:$yO(
T&s!OL
(Mnt|<
ZS"5\k
$E$dSh
C`8EBS
vrB^KVR
+._~}S
).R<Ec
FG7Y>NxJ
gRj`7u
a\q_YK
;x2*XJ
T>@vT_
}z0,Nu
)1xEAW/a
QLrU#(U
X"u9LP
5^k[+F
H6'As`
HM{<i(4z
+W5\)bPp
MhGDUU
|wM7isv
u7c~p 1
lf$`Bvr^
}`%Xlx
W}GIe}A
GJK#p<%
FsZElWl*T
YZ`2M]
&RkcwJ$
-V[,YJ
UV+',.
'+uQ)*
t!@pr
'?"j:AvyO
aa.DB^G
@*2#C]
2Kx,Yl
VpPPy EX
-/ibr9
aE(L#x
tHB'4}
(3:9_f
OlT:{X
dmQCR z
`E1IM$Qz}
uP^sa
U]e]k*@
YYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYY
YYYYYYYYYYJR
YYYYYYYYYYJ0R0R
YYYYYYYYYY
YYYYYYYYYY
YYYYYYYYYY
YYYYYYYYYY
YYYYYYYYYY
Z0RJYYYYYYYYYY
JYYYYYYYYYY
YYYYYYYYYY
YYYYYYYYYY
%%NrrZ!6
YYYYYYYYYY
rrZr!Z
YYYYYYYYYY
YYYYYYYYYY
rrZL%%
YYYYYYYYYY
YYYYYYYYYY
YYYYYYYYYY
YYYYYYYYYY
YYYYYYYYYY
%%%%%%%%%%%%%%%%%%%%
YYYYYYYYYY
%%%%%%%%%%%%%%%%%%%%
YYYYYYYYYY
YYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYY
c@AAAA
~zy}}}
||}}{~}|
{}}zz~
{~{|~}
~|~}}|
|}}|~|{
{|}|{~}
~yz~~~|
}|z~~~}}
zz|{|z
z~~z{}{
zz{y~}}y|
}z|~~|
z{z{}~{z
z~{}}~~
~{~}~}
zz|}~~
}~~~||
|~{~}~{
{|z{z~
}|}~{{
~}}~{{
z|~|~~
|~||{~|~
}~{z}{|
}}~}{}
'''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''~
'''''''''''''''''''''''
~'''''''''''''''''''''
'''''''''''''''''''
'''''''''''''''''''''
'''''''''''''''
'''''''''''''''''''''
'''''''''''
'''''''''''''''''''''
'''''''
''''''''''''''''''''''
'''''''''''''''''''''''
'''''''''''''''''''''''
'''''''''''''''''''''''
'''''''''''''''''''''''
777777777
''''''''''''''''''''''''
DDDDDDDDDDD
'''''''''''''''''''''''''
Dhhhhhhhhhhhhhhhhh
'''''''''''''''''''''''''
'''''''''''''''''''''''''~
~'''''''''''''''''''''''''
'''''''''''''''''''''''''
'''''''''''''''''''''''
JJJJJJ?JJJJJJJJ?J
''''''''''''''''''''
?????????????
''''''''''''''''''
''''''''''''''''
''''''''''''''
''''''''''''
''''''''''
''''''''
''''''
'''''{
{'''''''''
''''''''''''''''''''
'''''''''''''''''''''''''''''''
'''''''''''''''''''''''''''''''''''
''''''''''''''''''''''''''''''''''''
'''''''''''''''''''''''''''''''''''''
''''''''''''''''''''''''''''''''''''''
'''''''''''''''''''''''''''''''''''''''
''''''''''''''''''''''''''''''''''''''''
'''''''''''''''''''''''''''''''''''''''''
''''''''''''''''''''''''''''''''''''''''''
'''''''''''''''''''''''''''''''''''''''''''
''''''''''''''''''''''''''''''''''''''''''''
'''''''''''''''''''''''''''''''''''''''''''''
''''''''''''''''''''''''''''''''''''''''''''''
'''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''
ZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZ&ZZZZZZZZZZZ
ZZZZZZZZZZZ
ZZZZZZZ
ZZZZZZZZZZZ
ZZZZZZZZZZZ3~
\ZZZZZZZZZZZZm
ZZZZZZZZZZZZLnnnnnnn
QZZZZZZZZZZZZ\n
~ZZZZZZZZZZZZZ^n
i3ZZZZZZZZZZZ^~
ZZZZZZZZZ^=
ZZZZZZZ^=
[[[[[[[[[[[[
ZZZZZ^=[
o[c||||||c
ZZZZZZZ
^kwZZZZZZZZZZZZZZZ
[^ZZZZZZZZZZZZZZZZZZB[
ZZZZZZZZZZZZZZZZZZZZ
f[^ZZZZZZZZZZZZZZZZZZZZ
ZZZZZZZZZZZZZZZZZZZZZZ@^ZZZZZZZZZZZZZZZZZZZZZZ&ZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZ
~~~~~~~~-*
GG[[[~
Feyimubicuku fadepezof xakeje. Hoxunikucuy bobuzafujodatib varaf tehuguducac. Xireku jumugu somad. Nirejanahewalik wekewesopima lefipipoma ridajozizilaki gafawucupinexi. Maboyedazowu. Xubi wofezela xehagabareba tirazosumiha lizimorimojub. Vodarovepexawun ciminirer. Jewuki tuyawoma xemukupahes kaka risehuviruxim. Dofo bayogiba. Dasitofarepo danusicukegigu ritanofowom tigosapireresil. Fiz gixufa minituzixe xovehuv himohep. Lufad sabur. Fitujakoki. Niximici pit faduyem. Lixocot gipowe. Nuyawerev lubenonujinav majatahi jatoviretuy hamuja. Doperifokebeg riwesoh wumakomi cekateziw. Jamamayey huriluv govukuvinu winalutujup rojuluc. Fus mipo herelefabeyozax. Ticim sebosihatubib. Cesoma zusexejudow zajir coxemagizo. Mamigakicul jixosoyayovuwe rusoke bicudaketonitu sisuse. Zide lol. Sayunevuwuj zumizeyajadaw coz bugi. Xazakoselafaxap vuv lulazivik mutoniz guhemewukixajad. Kac. Xihivukayuwu vasorapebavepo zovenoyuvowo miz fujo. Dacow wificemahad kucugode his. Cudimogo giyob bosivuricufito gukahigadoloh. Liwi. Wijivivuha
(null)
mscoree.dll
runtime error
TLOSS error
SING error
DOMAIN error
- Attempt to use MSIL code from this assembly during native code initialization
This indicates a bug in your application. It is most likely the result of calling an MSIL-compiled (/clr) function from a native constructor or from DllMain.
- not enough space for locale information
- Attempt to initialize the CRT more than once.
This indicates a bug in your application.
- CRT not initialized
- unable to initialize heap
- not enough space for lowio initialization
- not enough space for stdio initialization
- pure virtual function call
- not enough space for _onexit/atexit table
- unable to open console device
- unexpected heap error
- unexpected multithread lock error
- not enough space for thread data
- abort() has been called
- not enough space for environment
- not enough space for arguments
- floating point support not loaded
@Microsoft Visual C++ Runtime Library
<program name unknown>
Runtime Error!
Program:
KERNEL32.DLL
HH:mm:ss
dddd, MMMM dd, yyyy
MM/dd/yy
December
November
October
September
August
February
January
Saturday
Friday
Thursday
Wednesday
Tuesday
Monday
Sunday
WUSER32.DLL
((((( H
h(((( H
H
CONOUT$
damezemox jusisoyakogojitosinifehul
jjjjjj
TONIZITOHOWAPEVUMOBEM
AFX_DIALOG_LAYOUT
VS_VERSION_INFO
StringFileInfo
046805E6
CompanyName
Furious
FileDescriptions
WorldWrappering
FilesVersion
4.1.61.53
InternalName
FavorCoursel.exe
LegalTrademarks1
Glab fantastic
ProductName
SpecialistTuning
VarFileInfo
Translation
Antivirus Signature
Bkav W32.AIDetectNet.01
Lionic Clean
tehtris Clean
DrWeb Clean
ClamAV Clean
CMC Clean
CAT-QuickHeal Clean
ALYac Clean
Malwarebytes Clean
Zillya Clean
Sangfor Trojan.Win32.Save.a
K7AntiVirus Clean
Alibaba Clean
K7GW Clean
CrowdStrike win/malicious_confidence_100% (W)
BitDefenderTheta Clean
VirIT Clean
Cyren W32/Kryptik.JFT.gen!Eldorado
Symantec ML.Attribute.HighConfidence
Elastic malicious (high confidence)
ESET-NOD32 a variant of Win32/Kryptik.HTCA
APEX Malicious
Paloalto Clean
Cynet Malicious (score: 100)
Kaspersky UDS:Trojan.Win32.Zenpak.gen
BitDefender Clean
NANO-Antivirus Clean
SUPERAntiSpyware Clean
MicroWorld-eScan Clean
Rising Trojan.Kryptik!1.E392 (CLASSIC)
Sophos ML/PE-A
F-Secure Clean
Baidu Clean
VIPRE Clean
TrendMicro Clean
McAfee-GW-Edition BehavesLike.Win32.Lockbit.ch
Trapmine malicious.high.ml.score
FireEye Generic.mg.68d4bfeb87777e1c
Emsisoft Clean
SentinelOne Static AI - Suspicious PE
Jiangmin Clean
Webroot W32.Malware.Gen
Avira Clean
Antiy-AVL Clean
Microsoft Trojan:Win32/Sabsik.FL.B!ml
Gridinsoft Ransom.Win32.STOP.dd!n
Xcitium Clean
Arcabit Clean
ViRobot Clean
ZoneAlarm Clean
GData Clean
Google Detected
AhnLab-V3 Clean
Acronis Clean
McAfee GenericRXVP-LJ!68D4BFEB8777
MAX Clean
VBA32 Malware-Cryptor.Azorult.gen
Cylance unsafe
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Tencent Clean
Yandex Clean
TACHYON Clean
MaxSecure Trojan.Malware.300983.susgen
Fortinet W32/Kryptik.HTCA!tr
AVG Win32:CrypterX-gen [Trj]
Avast Win32:CrypterX-gen [Trj]
No IRMA results available.