Static | ZeroBOX

PE Compile Time

2022-02-09 02:57:12

PE Imphash

262ebebc1125c68c79c87bc329257c28

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x0001b536 0x0001b600 6.60276398074
.data 0x0001d000 0x003c7a54 0x00016200 7.24312356697
.rsrc 0x003e5000 0x0000f458 0x0000f600 4.82427746255

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x003f3200 0x00000468 LANG_SYRIAC SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x003f3200 0x00000468 LANG_SYRIAC SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x003f3200 0x00000468 LANG_SYRIAC SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x003f3200 0x00000468 LANG_SYRIAC SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x003f3200 0x00000468 LANG_SYRIAC SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x003f3200 0x00000468 LANG_SYRIAC SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x003f3200 0x00000468 LANG_SYRIAC SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x003f3200 0x00000468 LANG_SYRIAC SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x003f3200 0x00000468 LANG_SYRIAC SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x003f3200 0x00000468 LANG_SYRIAC SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x003f3200 0x00000468 LANG_SYRIAC SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x003f3200 0x00000468 LANG_SYRIAC SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x003f3200 0x00000468 LANG_SYRIAC SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x003f3200 0x00000468 LANG_SYRIAC SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x003f3200 0x00000468 LANG_SYRIAC SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x003f3200 0x00000468 LANG_SYRIAC SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x003f3200 0x00000468 LANG_SYRIAC SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_STRING 0x003f41c0 0x00000298 LANG_SYRIAC SUBLANG_DEFAULT data
RT_STRING 0x003f41c0 0x00000298 LANG_SYRIAC SUBLANG_DEFAULT data
RT_STRING 0x003f41c0 0x00000298 LANG_SYRIAC SUBLANG_DEFAULT data
RT_STRING 0x003f41c0 0x00000298 LANG_SYRIAC SUBLANG_DEFAULT data
RT_ACCELERATOR 0x003f36e0 0x000000a8 LANG_SYRIAC SUBLANG_DEFAULT data
RT_GROUP_ICON 0x003f3668 0x00000076 LANG_SYRIAC SUBLANG_DEFAULT data
RT_GROUP_ICON 0x003f3668 0x00000076 LANG_SYRIAC SUBLANG_DEFAULT data
RT_GROUP_ICON 0x003f3668 0x00000076 LANG_SYRIAC SUBLANG_DEFAULT data
RT_VERSION 0x003f3798 0x0000025c LANG_NEUTRAL SUBLANG_NEUTRAL data
None 0x003f3788 0x0000000a LANG_SYRIAC SUBLANG_DEFAULT data

Imports

Library KERNEL32.dll:
0x401008 CopyFileExW
0x40100c GetModuleHandleExA
0x401010 SetLocalTime
0x401018 CallNamedPipeA
0x401020 WaitNamedPipeA
0x401024 GlobalSize
0x401030 WriteConsoleInputA
0x401034 SetEvent
0x401038 BackupSeek
0x40103c GetModuleHandleW
0x401040 CreateRemoteThread
0x401044 SetFileTime
0x40104c GetDateFormatA
0x401054 GetDriveTypeA
0x401058 GlobalAlloc
0x40105c ReadFileScatter
0x401060 GetVersionExW
0x401068 GetComputerNameExA
0x40106c FindNextVolumeW
0x401070 GetConsoleAliasW
0x401074 GetFileAttributesW
0x401078 EnumCalendarInfoA
0x40107c GetSystemDirectoryA
0x401084 DeactivateActCtx
0x401088 EnumSystemLocalesA
0x40108c GetConsoleOutputCP
0x401090 OpenMutexW
0x401094 GetProcAddress
0x401098 LoadLibraryA
0x40109c LocalAlloc
0x4010a0 SetCalendarInfoW
0x4010a4 RemoveDirectoryW
0x4010a8 GlobalGetAtomNameW
0x4010ac GetCommMask
0x4010b4 GlobalFindAtomW
0x4010b8 EnumResourceTypesW
0x4010bc FindNextFileA
0x4010c0 GetModuleHandleA
0x4010c4 SetLocaleInfoW
0x4010c8 EraseTape
0x4010cc CreateMutexA
0x4010d0 GetStringTypeW
0x4010dc DeleteFileW
0x4010e4 CloseHandle
0x4010e8 HeapSize
0x4010ec GetModuleFileNameW
0x4010f0 lstrcmpA
0x4010f4 GetLastError
0x4010f8 WideCharToMultiByte
0x4010fc DeleteFileA
0x401100 HeapReAlloc
0x401104 GetCommandLineA
0x401108 HeapSetInformation
0x40110c GetStartupInfoW
0x401110 GetCPInfo
0x40111c GetACP
0x401120 GetOEMCP
0x401124 IsValidCodePage
0x401128 EncodePointer
0x40112c TlsAlloc
0x401130 TlsGetValue
0x401134 TlsSetValue
0x401138 DecodePointer
0x40113c TlsFree
0x401140 SetLastError
0x401144 GetCurrentThreadId
0x401148 GetCurrentThread
0x401150 IsDebuggerPresent
0x401154 TerminateProcess
0x401158 GetCurrentProcess
0x401164 HeapCreate
0x401168 HeapDestroy
0x40116c HeapFree
0x401170 HeapAlloc
0x401174 SetFilePointer
0x401178 ExitProcess
0x40117c WriteFile
0x401180 GetStdHandle
0x401184 GetModuleFileNameA
0x40118c SetHandleCount
0x401194 GetFileType
0x4011a0 GetTickCount
0x4011a4 GetCurrentProcessId
0x4011ac LCMapStringW
0x4011b0 MultiByteToWideChar
0x4011b4 FatalAppExitA
0x4011b8 Sleep
0x4011c0 GetLocaleInfoW
0x4011c4 GetUserDefaultLCID
0x4011c8 GetLocaleInfoA
0x4011cc IsValidLocale
0x4011d0 RtlUnwind
0x4011d4 SetStdHandle
0x4011d8 GetConsoleCP
0x4011dc GetConsoleMode
0x4011e0 FlushFileBuffers
0x4011e8 FreeLibrary
0x4011ec InterlockedExchange
0x4011f0 LoadLibraryW
0x4011f4 WriteConsoleW
0x4011f8 CreateFileW
Library USER32.dll:
0x401200 GetMenu
Library ADVAPI32.dll:
0x401000 ReportEventA

!This program cannot be run in DOS mode.
`.data
HH:mm:ss
dddd, MMMM dd, yyyy
MM/dd/yy
December
November
October
September
August
February
January
Saturday
Friday
Thursday
Wednesday
Tuesday
Monday
Sunday
FlsFree
FlsSetValue
FlsGetValue
FlsAlloc
LC_TIME
LC_NUMERIC
LC_MONETARY
LC_CTYPE
LC_COLLATE
LC_ALL
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
(null)
`h````
xpxxxx
CorExitProcess
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
united-states
united-kingdom
trinidad & tobago
south-korea
south-africa
south korea
south africa
slovak
puerto-rico
pr-china
pr china
new-zealand
hong-kong
holland
great britain
england
britain
america
swedish-finland
spanish-venezuela
spanish-uruguay
spanish-puerto rico
spanish-peru
spanish-paraguay
spanish-panama
spanish-nicaragua
spanish-modern
spanish-mexican
spanish-honduras
spanish-guatemala
spanish-el salvador
spanish-ecuador
spanish-dominican republic
spanish-costa rica
spanish-colombia
spanish-chile
spanish-bolivia
spanish-argentina
portuguese-brazilian
norwegian-nynorsk
norwegian-bokmal
norwegian
italian-swiss
irish-english
german-swiss
german-luxembourg
german-lichtenstein
german-austrian
french-swiss
french-luxembourg
french-canadian
french-belgian
english-usa
english-us
english-uk
english-trinidad y tobago
english-south africa
english-nz
english-jamaica
english-ire
english-caribbean
english-can
english-belize
english-aus
english-american
dutch-belgian
chinese-traditional
chinese-singapore
chinese-simplified
chinese-hongkong
chinese
canadian
belgian
australian
american-english
american english
american
Norwegian-Nynorsk
`h`hhh
xppwpp
SystemFunction036
GetProcessWindowStation
GetUserObjectInformationW
GetLastActivePopup
GetActiveWindow
MessageBoxW
1#QNAN
1#SNAN
%s %d %f
suxiwodazuralasukozaha
Carow nadivus cutejosi
iricofaxe
edehoramo
yogoxuzorabeke
Dowav fix lozeleyojaku puzado sija
lonijakifumoxareserilavebolefosalezivenulixiw
zuhalubuzawobine
wosekebakocusuz nifilojex paxayeninicoxar
Fafito kehahubamosiy
VPPPPP
.t|PVj@
HHtXHHt
?If90t
t h4:~
uhl!@
^SSSSS
j@j ^V
t"SS9] u
F Pj*S
F$Pj+Sj
F(Pj,S
F,Pj-S
F0Pj.S
F4Pj/S
F8PjDS
F<PjES
F@PjFS
FDPjGS
FHPjHS
FLPjIS
FPPjJS
FTPjKS
FXPjLS
F\PjMS
F`PjNS
FdPjOS
FhPj8S
FlPj9S
FpPj:S
FtPj;S
FxPj<S
F|Pj=S
C PjPV
C$PjQV
C*PjTV
C+PjUV
C,PjVV
C-PjWV
C.PjRV
C/PjSV
CHPjPV
CLPjQV
<+t"<-t
+t HHt
PPPPPPPP
tKhh2@
t:hd2@
u hl2@
PPPPPPPP
URPQQh
HHtYHHt
tM<it-<ot)<ut%<xt!<Xt
<it|<otx<utt<xtp<Xtl
HHtiHHt
u}hp3@
t VV9u
;t$,v-
UQPXY]Y[
D$tfkp
u.hh4@
UUUUUU
L$\QRRf
D$8C|_z
l$(gV(
lstrcmpA
EnumCalendarInfoA
CopyFileExW
GetModuleHandleExA
SetLocalTime
BuildCommDCBAndTimeoutsA
CallNamedPipeA
SetUnhandledExceptionFilter
WaitNamedPipeA
GlobalSize
GetEnvironmentStringsW
InterlockedCompareExchange
WriteConsoleInputA
SetEvent
BackupSeek
GetModuleHandleW
CreateRemoteThread
SetFileTime
GetWindowsDirectoryA
GetDateFormatA
FindActCtxSectionStringA
GetDriveTypeA
GlobalAlloc
ReadFileScatter
GetVersionExW
DnsHostnameToComputerNameW
GetComputerNameExA
FindNextVolumeW
GetConsoleAliasW
GetFileAttributesW
GetModuleFileNameW
GetSystemDirectoryA
FindNextVolumeMountPointW
DeactivateActCtx
EnumSystemLocalesA
GetConsoleOutputCP
OpenMutexW
GetProcAddress
LoadLibraryA
LocalAlloc
SetCalendarInfoW
RemoveDirectoryW
GlobalGetAtomNameW
GetCommMask
RtlCaptureStackBackTrace
GlobalFindAtomW
EnumResourceTypesW
FindNextFileA
GetModuleHandleA
SetLocaleInfoW
EraseTape
CreateMutexA
GetStringTypeW
RequestWakeupLatency
GetVolumeNameForVolumeMountPointW
DeleteFileW
GetFileInformationByHandle
KERNEL32.dll
GetMenu
USER32.dll
ReportEventA
ADVAPI32.dll
GetLastError
WideCharToMultiByte
DeleteFileA
HeapReAlloc
GetCommandLineA
HeapSetInformation
GetStartupInfoW
GetCPInfo
InterlockedIncrement
InterlockedDecrement
GetACP
GetOEMCP
IsValidCodePage
EncodePointer
TlsAlloc
TlsGetValue
TlsSetValue
DecodePointer
TlsFree
SetLastError
GetCurrentThreadId
GetCurrentThread
UnhandledExceptionFilter
IsDebuggerPresent
TerminateProcess
GetCurrentProcess
EnterCriticalSection
LeaveCriticalSection
HeapCreate
HeapDestroy
HeapFree
HeapAlloc
SetFilePointer
ExitProcess
WriteFile
GetStdHandle
GetModuleFileNameA
FreeEnvironmentStringsW
SetHandleCount
InitializeCriticalSectionAndSpinCount
GetFileType
DeleteCriticalSection
QueryPerformanceCounter
GetTickCount
GetCurrentProcessId
GetSystemTimeAsFileTime
LCMapStringW
MultiByteToWideChar
FatalAppExitA
IsProcessorFeaturePresent
GetLocaleInfoW
GetUserDefaultLCID
GetLocaleInfoA
IsValidLocale
RtlUnwind
SetStdHandle
GetConsoleCP
GetConsoleMode
FlushFileBuffers
SetConsoleCtrlHandler
FreeLibrary
InterlockedExchange
LoadLibraryW
WriteConsoleW
HeapSize
CloseHandle
CreateFileW
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
Evt`U%J?
W]zG"[
u4kr%x
a6-9;T
[Ys78#L
R4~y~cX
6?<Q3q
\s/Me'3
?"3JG7
BwMJ!T>D
r$8zI
ja-]|qs
FKY!n@
_5E,vF
['Qua|Y
(v3,Ur
+}r6Mx0
IXRgxR
fy$u0&
S!QM_RC
q{"2CP:
7{p2>B
0SVoZC
o49Up3
c#+".
=rOL?rG
wH(zwK}
uSc%]1
M3isIg
ci{gR-4B
1@y0c`
KvSp|tF
R`UB3E
s}<"f#$=|
@0w3bBE2
*QORIS
n+[63;3
`*&^'e
0sRIvt$
*]=nU^I$
2Ez+{`
T/ q3w
38t^IyWell
x=T~YU
'o0t#
~p<7.-*
8\Q5`>
]3Hg(u{4
\WyT.:y
.@X=IxuRY@
HPpL1)sW
w^?'"q
#ye&(W
zlrsuJ(%
TsW>79
4kfKl<
+Cb i
FaD3cv
NIvij2G
(vQW}.
R%Nw^_Q
X?rYHVSw)D
|NpAW=@P
t?FGn!
>||u]a
Te|CZBd5
0%_8#u
bg&)|,
E`1mEo
9mVGTR!6@v
S3nQ!%
OmVci1:fom
Of|XNTD
!OB>nZ
ZQ43q6E
JtA5kt
d|v<qKt)U
!gB$b^
;s0eF3q
_37EcwF
fDWG_L
ysM*B6~X
vF.<JjnN
/IS:2;
-@3YhEU
R=dn4d
K0cX#
"Ck7:M
hE]zyXUy
QKyNVBVbq
g[Wh%1S
2(e/'}
A?'PGSSY
0-u6o\+
b#_g#<
{h{F29
f$ o1>)m
6k9ivN
'p_=G>
v^2+xv
G,~[su1
8v9<ib(
p;E)bwbR
BEF6wf
YSim,K
#>oqxm)D/A
IjUV-*aG
8UYjZ?
\{YmhGs
a%]31S
ro7t3x
-&<'o^*
9G`:\
OX#(m/\
R3n5.:
5.+In=rv
g`*yX*
1lTw/OD
%Udli/Oz
D:ee.3I
Np5R^h
<*%>^G
Y@Rzqn.
A\%!l|uk
\MPW_5Y
P,;7#-
y#[-@,
*E^j5n
~~~~~~~~~~h~hhh
Pj&&&&??
cc'g''2
FFFFFFFFFFFFFFFFFFFF
FFFFFFFFFFFFFFFFFFFF
TTTTTTTTTTT
T<<<<<<<<<<<<<<<<<$
<c
>>>>>>>>>>>>>>>
>iiiiii
iiiiiiii
ittttttttttttttttttttti
_____________
}}}}}}}}}
!sssssss!
_,,s,s
!,,,,,!
eeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeee
eeeeeeeeeee
eeeeeeeeeee
'eeeeeee
eeeeeeeeeee
eeeeeeeeeeeY
eeeeeeeeeeeeB
eeeeeeeeeeees
.eeeeeeeeeeee
eeeeeeeeeeeeeh
Yeeeeeeeeeeeh
eeeeeeeeeh
eeeeeeeh
xxxxxxxxxxxx
eeeeeh
A`/!?x2
eeeeeee
eeeeeeeeeeeeeeembbbxheeeeeeeeeeeeeeeeee
xb\meeeeeeeeeeeeeeeeeeee
\xheeeeeeeeeeeeeeeeeeeeA$
eeeeeeeeeeeeeeeeeeeeeeDheeeeeeeeeeeeeeeeeeeeee
eeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeee
hhhhhhhhhhhhhhhhhhhg
hhhhhhhhD
hhhhhhhh
hhhhhhhh
hhhhhhhhY
hhhhhhh
^^^^^^
^GGGGGGGG
hhhhhh
hhhhhhhhhhhm
hhhhhhhhhhhh
hhhhhhhhhhhhhhY
hhhhhhhhhhhhhh
hhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhh
$$$$$$$$$$$$$$$$$$$$$
%%%%%%%%%%%%%%%%%%%%%
{{{{{{
A$$$$$$$$$$$$
UU>5AAAAAAAAAAAA$%
Ue$$A$AAAAAAAA$%
$$$$$$$$$A$
%$>55U
{{{{{{{
bb{{{{{{{{{{b%
bbbbbbbbbbb{b%
A%%%%%%%%%b%%%%
%%%%%%%%%%%%%%%%%%%%%
%%%%%%%%%%%%%%%%%%%%%
eeeeeeeee55555555555
eeeeeeeee
555555555
eeeeee
%%%%%%%%%%%%%%%%%%%%%%%
%iFFFFFFFF
NNNpppp
NNNNpppp
%F//////
NNNppppp
//////
NNNNpppp
//////
//////
FFFFFFFF
FFFFFFFFF
FFFFFFFFF
FFFFFFFF
DDD""""""""""
dddddddddddddddd7oY
o7oo7ooo
7o77o7o7Fd
7777777o
cDdddDdDDdDDdDdD
#c##cccccc
UUUUTTT
``````````
LLLLLLLLLLL,
DBw^ww
BCw^CCCC
wwwwwwwwwB
^^^^^^^^
HH:mm:ss
dddd, MMMM dd, yyyy
MM/dd/yy
December
November
October
September
August
February
January
Saturday
Friday
Thursday
Wednesday
Tuesday
Monday
Sunday
nKERNEL32.DLL
(null)
mscoree.dll
runtime error
TLOSS error
SING error
DOMAIN error
- Attempt to use MSIL code from this assembly during native code initialization
This indicates a bug in your application. It is most likely the result of calling an MSIL-compiled (/clr) function from a native constructor or from DllMain.
- not enough space for locale information
- Attempt to initialize the CRT more than once.
This indicates a bug in your application.
- CRT not initialized
- unable to initialize heap
- not enough space for lowio initialization
- not enough space for stdio initialization
- pure virtual function call
- not enough space for _onexit/atexit table
- unable to open console device
- unexpected heap error
- unexpected multithread lock error
- not enough space for thread data
- abort() has been called
- not enough space for environment
- not enough space for arguments
- floating point support not loaded
@Microsoft Visual C++ Runtime Library
<program name unknown>
Runtime Error!
Program:
((((( H
h(((( H
H
ADVAPI32.DLL
WUSER32.DLL
CONOUT$
Hiwino yubago komosetenavo vokobadac
ecoyopoj
Fopiha yowujec
Josuhowakipavu nulepehikab zokotewuyunocif
Ropomovog tuwurulavu
nanoyodabad
Sedabevo fefiv gutive fipode
xiyexifipake
nitebiy
temamufedutozilu
@jjjjjjjjj
jjjjjjj
VS_VERSION_INFO
StringFileInfo
042805B6
CompanyName
DevilOffice
FileDescriptions
IceIncorporated
FileVersion
84.25.44.78
InternalName
NeutralBuffer.exe
LegalTrademark1
Fantastick bad
ProductName
HumbleFeedex
VarFileInfo
Translation
,Haxefacof piyicidayatu xalutepin nimebacujocIBodahiticudare hutawik coce kararowuselag felu yopey vojuzomolun mivureki
Xaca ramudic yujonimuxinijih
SWis xaw jotujujetumu badituhikuve vinaxoruhamo vofurobode cozurigutiloy melizimipuk
Bay vojiravita
dMaw xupavotunij pozabinexoxu bexuwimo gikadama kimawipomolitah cegelewibefato renahofivopa caxeheyif
Diwadic sisucaj yonayusixeYSulagugedip hey kavuxubuca hulukuliwatayo tusuyo buzexinojekipu nepivozisudipi xudiy noyi]Wadukahuxeziwir berexebavarej vitoruzo gejeretupekanag nah tofa zokemugu manafutijir jer goxo.Favesitolutu pofuka mokibas najogegevegul duyu
Vepey sonebelocomuho zevufe
^Yebuy bihur jedov mewuniduvi pajomokofoyi jimey weborukakototar todasevotat sofofup guyazutajo
Dohoruk
2Kediliwepuk zubas foxoduzunicaco nobawigabu pudoxe
-Buf laguyah lojeramozuyov vifopi weyabulafobe.Locelecajozi rili vomujetowujud koducepigamekuAZidel fub sazatonaderabe rotimivotola cotej bajenebuhi naxuze cen
Divedepe haz<Dayazu sotoma toyumasosexiz vakaj mesimev fiyazocuwopan bace
Podulelu guyoleh hujizomuxuaBeribe duhot ziticapojenu hog nijijapaguwikix yoyej rohixemeduyo gojufosazusaz lisizomefexufo hif
Zevucicep taxewujuxiku zagediz)Gidipu buvuy rahom fuwiw nezi fawinoyewew=Sihapi tunahedaxorabe nezupupewun xasumudocoxape xupevoxaxupa
No antivirus signatures available.
No IRMA results available.