Static | ZeroBOX

PE Compile Time

2022-04-16 09:05:51

PDB Path

C:\sose.pdb

PE Imphash

62e4c80108c1e602fb1ed5c87f0b3460

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x000254f2 0x00025600 7.63689085452
.data 0x00027000 0x0006e058 0x00002a00 2.10562303833
.rsrc 0x00096000 0x000077a0 0x00007800 4.70432480798
.reloc 0x0009e000 0x00001b82 0x00001c00 3.55734371692

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x0009c608 0x00000468 LANG_SPANISH SUBLANG_SPANISH_BOLIVIA GLS_BINARY_LSB_FIRST
RT_ICON 0x0009c608 0x00000468 LANG_SPANISH SUBLANG_SPANISH_BOLIVIA GLS_BINARY_LSB_FIRST
RT_ICON 0x0009c608 0x00000468 LANG_SPANISH SUBLANG_SPANISH_BOLIVIA GLS_BINARY_LSB_FIRST
RT_ICON 0x0009c608 0x00000468 LANG_SPANISH SUBLANG_SPANISH_BOLIVIA GLS_BINARY_LSB_FIRST
RT_ICON 0x0009c608 0x00000468 LANG_SPANISH SUBLANG_SPANISH_BOLIVIA GLS_BINARY_LSB_FIRST
RT_ICON 0x0009c608 0x00000468 LANG_SPANISH SUBLANG_SPANISH_BOLIVIA GLS_BINARY_LSB_FIRST
RT_ICON 0x0009c608 0x00000468 LANG_SPANISH SUBLANG_SPANISH_BOLIVIA GLS_BINARY_LSB_FIRST
RT_ICON 0x0009c608 0x00000468 LANG_SPANISH SUBLANG_SPANISH_BOLIVIA GLS_BINARY_LSB_FIRST
RT_STRING 0x0009d110 0x0000068c LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_STRING 0x0009d110 0x0000068c LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_GROUP_ICON 0x0009ca70 0x00000076 LANG_SPANISH SUBLANG_SPANISH_BOLIVIA data
RT_VERSION 0x0009cae8 0x000001d4 LANG_NEUTRAL SUBLANG_NEUTRAL data

Imports

Library KERNEL32.dll:
0x401010 AddConsoleAliasW
0x401014 GetLogicalDrives
0x401018 BackupSeek
0x401020 GetModuleHandleW
0x401024 GetCommConfig
0x401028 VirtualFree
0x401030 ReadConsoleW
0x401038 EnumTimeFormatsW
0x40103c EnumResourceTypesA
0x401040 LoadLibraryW
0x401044 GetConsoleWindow
0x401048 GetVersionExW
0x40104c GetFileAttributesW
0x401050 EnumSystemLocalesA
0x401054 InterlockedExchange
0x401058 GetProfileIntA
0x40105c GetCPInfoExW
0x401060 SetLastError
0x401064 GetProcAddress
0x401068 VirtualAlloc
0x40106c GetUserDefaultLCID
0x401074 RemoveDirectoryA
0x401078 LoadLibraryA
0x40107c LocalAlloc
0x401080 OpenEventA
0x401090 AddAtomA
0x401094 EnumDateFormatsA
0x401098 GetModuleHandleA
0x40109c HeapSetInformation
0x4010a0 GetStringTypeW
0x4010a4 GetConsoleTitleW
0x4010a8 VirtualProtect
0x4010b0 GetShortPathNameW
0x4010b4 GetVersionExA
0x4010b8 DebugBreak
0x4010bc EnumCalendarInfoExA
0x4010c4 HeapSize
0x4010c8 Sleep
0x4010cc ExitProcess
0x4010d0 GetCommandLineA
0x4010d4 GetStartupInfoA
0x4010d8 TerminateProcess
0x4010dc GetCurrentProcess
0x4010e8 IsDebuggerPresent
0x4010ec HeapAlloc
0x4010f0 GetLastError
0x4010f4 HeapFree
0x4010f8 RaiseException
0x4010fc TlsGetValue
0x401100 TlsAlloc
0x401104 TlsSetValue
0x401108 TlsFree
0x401110 GetCurrentThreadId
0x401118 WriteFile
0x40111c GetStdHandle
0x401120 GetModuleFileNameA
0x40113c WideCharToMultiByte
0x401144 SetHandleCount
0x401148 GetFileType
0x40114c HeapCreate
0x401150 GetTickCount
0x401154 GetCurrentProcessId
0x40115c HeapReAlloc
0x401160 GetCPInfo
0x401164 GetACP
0x401168 GetOEMCP
0x40116c IsValidCodePage
0x401170 RtlUnwind
0x401174 GetLocaleInfoA
0x401178 LCMapStringA
0x40117c MultiByteToWideChar
0x401180 LCMapStringW
0x401184 GetStringTypeA
Library USER32.dll:
0x40118c CharLowerBuffW
Library GDI32.dll:
0x401000 GetBrushOrgEx
0x401004 GetCharWidthI

!This program cannot be run in DOS mode.
`.data
@.reloc
bad allocation
Unknown exception
CorExitProcess
_nextafter
_hypot
EncodePointer
DecodePointer
FlsFree
FlsSetValue
FlsGetValue
FlsAlloc
runtime error
TLOSS error
SING error
DOMAIN error
An application has made an attempt to load the C runtime library incorrectly.
Please contact the application's support team for more information.
- Attempt to use MSIL code from this assembly during native code initialization
This indicates a bug in your application. It is most likely the result of calling an MSIL-compiled (/clr) function from a native constructor or from DllMain.
- not enough space for locale information
- Attempt to initialize the CRT more than once.
This indicates a bug in your application.
- CRT not initialized
- unable to initialize heap
- not enough space for lowio initialization
- not enough space for stdio initialization
- pure virtual function call
- not enough space for _onexit/atexit table
- unable to open console device
- unexpected heap error
- unexpected multithread lock error
- not enough space for thread data
This application has requested the Runtime to terminate it in an unusual way.
Please contact the application's support team for more information.
- not enough space for environment
- not enough space for arguments
- floating point support not loaded
Microsoft Visual C++ Runtime Library
<program name unknown>
Runtime Error!
Program:
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
GAIsProcessorFeaturePresent
KERNEL32
Complete Object Locator'
Class Hierarchy Descriptor'
Base Class Array'
Base Class Descriptor at (
Type Descriptor'
`local static thread guard'
`managed vector copy constructor iterator'
`vector vbase copy constructor iterator'
`vector copy constructor iterator'
`dynamic atexit destructor for '
`dynamic initializer for '
`eh vector vbase copy constructor iterator'
`eh vector copy constructor iterator'
`managed vector destructor iterator'
`managed vector constructor iterator'
`placement delete[] closure'
`placement delete closure'
`omni callsig'
delete[]
new[]
`local vftable constructor closure'
`local vftable'
`udt returning'
`copy constructor closure'
`eh vector vbase constructor iterator'
`eh vector destructor iterator'
`eh vector constructor iterator'
`virtual displacement map'
`vector vbase constructor iterator'
`vector destructor iterator'
`vector constructor iterator'
`scalar deleting destructor'
`default constructor closure'
`vector deleting destructor'
`vbase destructor'
`string'
`local static guard'
`typeof'
`vcall'
`vbtable'
`vftable'
operator
delete
__unaligned
__restrict
__ptr64
__clrcall
__fastcall
__thiscall
__stdcall
__pascal
__cdecl
__based(
GetProcessWindowStation
GetUserObjectInformationA
GetLastActivePopup
GetActiveWindow
MessageBoxA
USER32.DLL
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
HH:mm:ss
dddd, MMMM dd, yyyy
MM/dd/yy
December
November
October
September
August
February
January
Saturday
Friday
Thursday
Wednesday
Tuesday
Monday
Sunday
SunMonTueWedThuFriSat
JanFebMarAprMayJunJulAugSepOctNovDec
1#QNAN
1#SNAN
bad allocation
radalifuwenovujehiputazudikova nehisigehifide
msimg32.dll
yeguvobu nakejacizagiy bokakazixutocizikobahikalozero zazajahece
bad exception
C:\sose.pdb
D$(3D$
T$hRj@PQ
G;=lEI
D$x3fx
D$@QfFn
D$<__E
l$tq_-(
HYYtJHt9H
jXh@WB
0SSSSS
Y;=P}B
>=Yt1j
jTh8YB
j@j ^V
0A@@Ju
Fh=HwB
to=8~B
_VVVVV
^WWWWW
tRHtCHt4Ht%HtFHHt
URPQQh
0SSSSS
0SSSSS
GWhp"@
t"SS9]
FVhp"@
v$;5\~B
PPPPPPPP
PPPPPPPP
0SSSSS
_VVVVV
;t$,v-
UQPXY]Y[
t+WWVPV
<+t(<-t$:
+t HHt
}#?ks7b
<suZ/\_
3lN?x%
Dt}aci)
RR(4s6
C1d#*Q:
Yf@R*ec
%p/7Yj
^_Lc()
X~G2?
UIUjRUVG
5Y5K|_
UP"nWb
:%j''Mu
rmYEnm
u1Tl@m65k
cf~[my!
z@\&B
Z|M`q,
N`xon]
BK}YM/
KVn/FF
BX aN
GUne)d
#,5F{dX
Ti /Td4A
l%#X)N%
Q/`?#*
${jpKn
!pfw3<
H')b@K)
%0[/wF
Nnn\j+#
P{\l~.
hDA2XcP
J}tOs0k
s[_W=YP
o`:q7'
qH-q[
\;Ou,z
UZ&eyC
66mJ{u
,*$w K
Epf7\!&PJ
"{awx!+
-xY([L^
zZ|=D#
p5bwg,
@rW\OC
ER2z%5
,VK"[V
+\:.|l
uNfk|H
F~`I1m
[/>fi~
&mVb-V
fZ&w'8OsP
/s|%Oe8
/j^bt
?%IY1T6:lJ
0V!G93
iU.Ha
~Zry9'
=YtKp:
*#%Y'#
|H.&;D4
(O6wst
|N0ad
}8Fi1V
gYURNZd
ed &24
}7Ja[
05.im"
go|y3y
adFE{Dw
5MNqX1
Tb'{es
!YplN\
<@ ,,+f
p+5x@
mp(JVE\
M1q]7+6
C25;0M
p+v^N|
E<H27F2G
+Kb#o>
L://G#
/4mxG
F<"g~!
Y$}vps4
T;}7f%
82f3Z+u
wA^X/_I]
B`L Be
f,^Yt{C
_T Prb
gu@W2Q
cX^.zU
._Y6kT
zzAvXY
B2C-/Qu
f)9l]zG
4)4p[N
R#)yfnb(
'oj%E}
!J`^P*-
)9%c!`
+yp(-!
?C<!\\B
;2E4,R
yp~/iXwad
sVUy2*
SIuS2=
4eQ%4-
8w_Unt>
*//#.N
cP%rMX
:(#5&Z
p}AB(l
m{~(uRb
.("G!E
4y5mkb
_zXLLsI
[(,ubC
ytn,SLe
8Ng^0.0
)j<."F^
+^ib>T
{(7c>G
bBVjE:qq
l/%Qvq
{hSM"P
P,q\~_f
\|:?/0
W[wLu}W
QQSVWd
HtHu4j
s[S;7|G;w
tR99u2
QueryPerformanceCounter
GetUserDefaultLCID
InterlockedCompareExchange
AddConsoleAliasW
GetLogicalDrives
BackupSeek
FreeEnvironmentStringsA
GetModuleHandleW
GetCommConfig
VirtualFree
ConvertFiberToThread
ReadConsoleW
GetWindowsDirectoryA
EnumTimeFormatsW
EnumResourceTypesA
LoadLibraryW
GetConsoleWindow
GetVersionExW
GetFileAttributesW
EnumSystemLocalesA
InterlockedExchange
GetProfileIntA
GetCPInfoExW
SetLastError
GetProcAddress
VirtualAlloc
HeapSize
BeginUpdateResourceW
RemoveDirectoryA
LoadLibraryA
LocalAlloc
OpenEventA
PostQueuedCompletionStatus
WriteProfileSectionW
FindNextChangeNotification
AddAtomA
EnumDateFormatsA
GetModuleHandleA
HeapSetInformation
GetStringTypeW
GetConsoleTitleW
VirtualProtect
ScrollConsoleScreenBufferA
GetShortPathNameW
GetVersionExA
DebugBreak
EnumCalendarInfoExA
KERNEL32.dll
CharLowerBuffW
USER32.dll
GetBrushOrgEx
GetCharWidthI
GDI32.dll
ExitProcess
GetCommandLineA
GetStartupInfoA
TerminateProcess
GetCurrentProcess
UnhandledExceptionFilter
SetUnhandledExceptionFilter
IsDebuggerPresent
HeapAlloc
GetLastError
HeapFree
RaiseException
TlsGetValue
TlsAlloc
TlsSetValue
TlsFree
InterlockedIncrement
GetCurrentThreadId
InterlockedDecrement
WriteFile
GetStdHandle
GetModuleFileNameA
DeleteCriticalSection
LeaveCriticalSection
EnterCriticalSection
InitializeCriticalSectionAndSpinCount
GetEnvironmentStrings
FreeEnvironmentStringsW
WideCharToMultiByte
GetEnvironmentStringsW
SetHandleCount
GetFileType
HeapCreate
GetTickCount
GetCurrentProcessId
GetSystemTimeAsFileTime
HeapReAlloc
GetCPInfo
GetACP
GetOEMCP
IsValidCodePage
RtlUnwind
GetLocaleInfoA
LCMapStringA
MultiByteToWideChar
LCMapStringW
GetStringTypeA
.?AVtype_info@@
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
.?AVexception@std@@
.?AVbad_alloc@std@@
.?AVbad_exception@std@@
LLLLLLLLLLLLLLLLLLLLLLLLLLLLLLLLLLLLLLLL
""""""""""""""""""""""""""""
"""""""
wwwwww
""""""""
""""""
""""""""""
""""""
"""""""
"""""""
"""""";V-
"""""";V-
"""""";V-
"""""";V-
"""""";V-
""""";V-
""";V-
~~~~~~~~~R<<<<<<<<<<<
YYYYYYYYYYYYYYYYYYYYYYYY
llf..B
``JzV-
``JJzV-
``JzV-
``JJzV-
``JJzV-
``JJzV-
lllfO.
YYYYYYYYYYYYYYYYYYYYYYYYYYYYYY
OOOOOOOOOOOOOOOOOOOOOOOOOO
YYYYYYYYYYYYYYYYYYYYYYYYYO
O]SSSSS
~~~~~~~~~]~]~]]]]]]]
~~~~~~~]~]~]~]~]
~~~~~~~~~~~~~]~]~]]
~~~~~~]~~]~]]~]~
~~~~~~~~]~~]]
~~~~~~~~]~~]
fY~~~~~~]~]
~~~]~~~]
T~~~~~]~
~~~~~]
T~~~~~
O]SSSSS
O]SSSSS
O]SSSSSSSS
O]SSSSSSS
Xs77^^g}}
Xss77^^g}
Xsss7^^gg}}
@p"__"
888888
ggggTTmm==TTTTT
Rggggm
ggggMMMMMMMMMMMMMM
Lggggggggggggggggggggg
ggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggg
{{____________{{{_222222222222_{{_
{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{
|}|}|~
{}{~~}
{}{|}{
{|~~z|
~~}{}~
~z~||}
~~z}z~{
}|}~|}
~}y{~~}{
|{z|}~{
||||zzy
}~|~{~
~z{z}z
{|}|||
~~}z}}
}|~}~}~
{~z}~|
z~{~|}
z|~|~~~
z}{}{z
z~|{{~
{|{|}}|
||}}{{
~{~~~{
~}z~||
2 2`2d2h2
1 1$1(1,1014181<1@1D1H1L1P1T1X1\1`1d1h1l1p1t1x1|1
<\=`=h=l=p=t=
> >8>H>L>\>`>d>l>
0B0\0o0
0A1G1b1h1n1t1
2$2d2q2z2
4"4/484L4Z4h4}4
4$565<5p5}5
:4;:;F;L;Q;V;
/454:4@4
5a6k6x6
9999E9M9]9r9
; ;2;9;?;Q;Y;d;
?6?m?~?
11292N2Y2
5 5&5*5054595?5C5I5M5S5W5]5a5z5
77/7;798
:N:V:e:m:
8O8h8o8w8|8
9^9d9h9l9p9
;X;x;};~>
5B5O5]5
646:6E6Q6f6m6
7%7,7D7S7Z7g7
858;8W8o8
929<9t9|9
:$:):1:::F:K:P:V:Z:`:e:k:p:
;<<A<i<
=9=@=J=t=
#0(0I0N0s0(1-1?1]1q1w1
1R2,343L3d3
4&4Q4\4}4
6'6n6s6
6D7M7S7
8I8j8w8
0!0/0>0a0n0z0
013?3E3_3d3s3|3
44)404D4K4Q4_4f4k4t4
>'>1>?>H>R>
>,?a?t?
0I1U1h1z1
2D2m2~2
4$5;5L5
7!7-8p8y8
99K9Y9_9o9t9
9?:\:y:
?%?,?3?:?B?J?R?^?g?l?r?|?
0O0h0o0w0|0
1^1d1h1l1p1
3^3p3}3
6G7Q7i7p7z7
;';9;K;];o;
4#5)5M5p5
2W3'6>6
5G6_6d6
879D9W9:E;><
787T7X7`7d7
8 8,8H8T8p8
9,909L9P9p9
:$:X:`:d:|:
; ;<;@;H;P;X;\;d;x;
0 0$0(0,0004080<0@0D0H0L0P0T0X0\0`0d0|0
3"3&3*3.32363:3>3B3F3J3N3R3V3Z3^3b3f3j3n3r3v3z3~3
4$4,444<4D4L4T4\4d4l4t4|4
5$5,545<5D5L5T5\5d5l5t5|5
=4=@=D=H=L=P=X=\=p=t=x=|=
> >0>8><>@>D>H>L>P>T>X>\>h> ?$?
mscoree.dll
KERNEL32.DLL
((((( H
h(((( H
H
puvinenawu
kernel32.dll
VS_VERSION_INFO
StringFileInfo
045801F6
FilesVersion
50.26.37.52
InternalName
HavingWay
LegalCopyright
Copyright (C) 2023, maersk
ProductName
Sherpa
VarFileInfo
Translation
'Xehanimuloveh vadahoj wafadurusijuh wiyJCevegu wihoreyekisa tudi wozewegeviga nacovogimi josogilepuyaku rujoredimiSRohilizuxigemi gelerugoxizivi yekuwizopohubu dixamilayosiw zuji nusirohuneme cexutu!Fijoyel hulopizumezi jayowelidofi(Pesabaha xam zatepu tone vumamamotehebujYLucir pavikugumili bica wegibicehajef zodulelaca fibuvum vunufoxuyili cafunofay tatabavup
XHejepiyiduxotok fisayesekas misevapaheken yuborogew gugadojumel jufosiz dosotejiw jinawe&Biyulayapotejum zodiwuzu fetahobanatix1Cemewo lonoyez lejecu nahanazofuxo geya jelovalit
Kowuzov vokivITizuyabuy jicogutuvixowul zapi kim jiwiwi xixa gohifutayegi vejutokopesayIHomewesijix cadenizajomabi bige ninox degi duhu benuraruhaso zatavehowafa0Nevik sohuzufalawalu doxofedoxume hehiber sixumajNisaxobezag pevuhefiha tatavugovixok wosinugata yipisug yawa patehasamuz jadadijepunuto bawuwif rubugagivo?Kegigamu cijejiyiyejupi ceza vojayogicu zuvaveyitelo jevomucujuLMewetuzixe ziberamokidije fazumidil kugul gobisekasup genepilayoh sikureralo>Noloyoj vucegeyif sikovevope gokisalohehar lic rafivoku wecose
Jec yapBGiyuhisahedawed jaturaxewur guwahecide komamezobiz sijahewayivebal8Kovere felopenuweti tepirexehug kehozaduhe xefinapokegaj
Detu monado cedi
Nohij zicabar rehosezexitBGiwuruguv xohazona rasivil batujufuve hejiyute roti diz rodujoxijoHXiwadakik lonadekekuce xilezafijehurox jola digita puboyaxiweyeriw ripuh
Antivirus Signature
Bkav Clean
Lionic Clean
tehtris Clean
ClamAV Win.Packer.pkr_ce1a-9980177-0
FireEye Generic.mg.a0e0f78ec3cb72fb
CAT-QuickHeal Ransom.Stop.P5
McAfee Clean
Cylance unsafe
VIPRE Clean
Sangfor Suspicious.Win32.Save.a
K7AntiVirus Trojan ( 00516fdf1 )
BitDefender Clean
K7GW Trojan ( 00516fdf1 )
CrowdStrike win/malicious_confidence_100% (W)
Arcabit Clean
Baidu Clean
VirIT Clean
Cyren W32/Kryptik.JND.gen!Eldorado
Symantec ML.Attribute.HighConfidence
Elastic malicious (high confidence)
ESET-NOD32 Clean
APEX Malicious
Paloalto Clean
Cynet Malicious (score: 100)
Kaspersky Clean
Alibaba Clean
NANO-Antivirus Clean
ViRobot Clean
MicroWorld-eScan Clean
Rising Trojan.Generic@AI.92 (RDML:R5gIOKS8y5QbeVYBNp7gGg)
Emsisoft Clean
F-Secure Clean
DrWeb Clean
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition BehavesLike.Win32.Lockbit.cc
Trapmine malicious.moderate.ml.score
CMC Clean
Sophos ML/PE-A
Ikarus Trojan.Win32.Crypt
Jiangmin Clean
Webroot Clean
Avira Clean
MAX Clean
Antiy-AVL Clean
Gridinsoft Clean
Xcitium Clean
Microsoft Trojan:Win32/Sabsik.FL.B!ml
SUPERAntiSpyware Clean
ZoneAlarm Clean
GData Clean
Google Detected
AhnLab-V3 Clean
Acronis suspicious
BitDefenderTheta Clean
ALYac Clean
TACHYON Clean
DeepInstinct MALICIOUS
VBA32 Malware-Cryptor.2LA.gen
Malwarebytes Clean
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Tencent Clean
Yandex Clean
SentinelOne Static AI - Malicious PE
MaxSecure Trojan.Malware.300983.susgen
Fortinet Clean
AVG DropperX-gen [Drp]
Avast DropperX-gen [Drp]
No IRMA results available.