Static | ZeroBOX

PE Compile Time

2021-11-02 03:05:58

PDB Path

C:\fevivopujifah\hiketutifocihe\yavew90-nubovo\rurahoke\77_leru.pdb

PE Imphash

4b07758d5b167b27106e05a1732f0848

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x00023252 0x00023400 7.66842202015
.data 0x00025000 0x0275a628 0x00001800 2.97877766445
.rsrc 0x02780000 0x00008fa0 0x00009000 4.67501680403
.reloc 0x02789000 0x00007cb0 0x00007e00 0.946452417913

Resources

Name Offset Size Language Sub-language File type
AFX_DIALOG_LAYOUT 0x02786e50 0x00000002 LANG_NEUTRAL SUBLANG_NEUTRAL data
AFX_DIALOG_LAYOUT 0x02786e50 0x00000002 LANG_NEUTRAL SUBLANG_NEUTRAL data
AFX_DIALOG_LAYOUT 0x02786e50 0x00000002 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_CURSOR 0x02788c70 0x000000b0 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_CURSOR 0x02788c70 0x000000b0 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_CURSOR 0x02788c70 0x000000b0 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_CURSOR 0x02788c70 0x000000b0 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_CURSOR 0x02788c70 0x000000b0 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x027868d8 0x00000468 None SUBLANG_SYS_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x027868d8 0x00000468 None SUBLANG_SYS_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x027868d8 0x00000468 None SUBLANG_SYS_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x027868d8 0x00000468 None SUBLANG_SYS_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x027868d8 0x00000468 None SUBLANG_SYS_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x027868d8 0x00000468 None SUBLANG_SYS_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x027868d8 0x00000468 None SUBLANG_SYS_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x027868d8 0x00000468 None SUBLANG_SYS_DEFAULT GLS_BINARY_LSB_FIRST
RT_ACCELERATOR 0x02786db8 0x00000048 None SUBLANG_SYS_DEFAULT data
RT_GROUP_CURSOR 0x02788d20 0x00000022 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_GROUP_CURSOR 0x02788d20 0x00000022 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_GROUP_ICON 0x02786d40 0x00000076 None SUBLANG_SYS_DEFAULT data
RT_VERSION 0x02788d48 0x00000258 LANG_NEUTRAL SUBLANG_NEUTRAL data
None 0x02786e20 0x0000000a LANG_NEUTRAL SUBLANG_NEUTRAL data
None 0x02786e20 0x0000000a LANG_NEUTRAL SUBLANG_NEUTRAL data
None 0x02786e20 0x0000000a LANG_NEUTRAL SUBLANG_NEUTRAL data

Imports

Library KERNEL32.dll:
0x401010 ReadConsoleA
0x40101c WaitForSingleObject
0x401020 BackupSeek
0x401024 GetModuleHandleW
0x401028 EnumCalendarInfoExW
0x401034 EnumTimeFormatsW
0x401040 FindResourceExA
0x401044 GetCalendarInfoA
0x401048 IsBadCodePtr
0x40104c FindNextVolumeW
0x401050 GetConsoleAliasW
0x401054 lstrlenW
0x401058 GlobalUnlock
0x40105c GetCPInfoExW
0x401060 GetLastError
0x401064 SetLastError
0x401068 GetProcAddress
0x40106c VirtualAlloc
0x40107c LoadLibraryA
0x401080 WriteConsoleA
0x401088 LocalAlloc
0x401090 GetNumberFormatW
0x401094 AddAtomW
0x401098 RemoveDirectoryW
0x40109c GetDiskFreeSpaceA
0x4010a0 EnumResourceTypesW
0x4010a4 GetOEMCP
0x4010ac GetConsoleTitleW
0x4010b0 VirtualProtect
0x4010b4 GetShortPathNameW
0x4010b8 TlsAlloc
0x4010c4 AddConsoleAliasA
0x4010c8 DebugBreak
0x4010cc GetModuleHandleA
0x4010d0 lstrlenA
0x4010d4 EnumResourceNamesW
0x4010dc GetComputerNameA
0x4010e0 RaiseException
0x4010e4 MultiByteToWideChar
0x4010e8 GetCommandLineA
0x4010ec GetStartupInfoA
0x4010f0 HeapAlloc
0x4010f4 HeapFree
0x4010f8 GetCPInfo
0x401104 GetACP
0x401108 IsValidCodePage
0x40110c TlsGetValue
0x401110 TlsSetValue
0x401114 TlsFree
0x401118 GetCurrentThreadId
0x40111c Sleep
0x401120 HeapSize
0x401124 ExitProcess
0x40112c WriteFile
0x401130 GetStdHandle
0x401134 GetModuleFileNameA
0x401144 WideCharToMultiByte
0x40114c SetHandleCount
0x401150 GetFileType
0x401158 HeapCreate
0x40115c VirtualFree
0x401164 GetTickCount
0x401168 GetCurrentProcessId
0x401170 TerminateProcess
0x401174 GetCurrentProcess
0x40117c IsDebuggerPresent
0x401188 HeapReAlloc
0x40118c LCMapStringA
0x401190 LCMapStringW
0x401194 GetStringTypeA
0x401198 GetStringTypeW
0x40119c GetLocaleInfoA
0x4011a4 RtlUnwind
Library USER32.dll:
0x4011ac CharLowerBuffW
0x4011b0 GetWindowLongW
0x4011b4 GetSysColorBrush
0x4011b8 SetCaretPos
Library GDI32.dll:
0x401000 GetColorAdjustment
0x401004 GetCharABCWidthsW
0x401008 GetCharWidthW
Library ole32.dll:

!This program cannot be run in DOS mode.
Rich8[
`.data
@.reloc
bad allocation
Unknown exception
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
EncodePointer
DecodePointer
FlsFree
FlsSetValue
FlsGetValue
FlsAlloc
CorExitProcess
runtime error
TLOSS error
SING error
DOMAIN error
An application has made an attempt to load the C runtime library incorrectly.
Please contact the application's support team for more information.
- Attempt to use MSIL code from this assembly during native code initialization
This indicates a bug in your application. It is most likely the result of calling an MSIL-compiled (/clr) function from a native constructor or from DllMain.
- not enough space for locale information
- Attempt to initialize the CRT more than once.
This indicates a bug in your application.
- CRT not initialized
- unable to initialize heap
- not enough space for lowio initialization
- not enough space for stdio initialization
- pure virtual function call
- not enough space for _onexit/atexit table
- unable to open console device
- unexpected heap error
- unexpected multithread lock error
- not enough space for thread data
This application has requested the Runtime to terminate it in an unusual way.
Please contact the application's support team for more information.
- not enough space for environment
- not enough space for arguments
- floating point support not loaded
Microsoft Visual C++ Runtime Library
<program name unknown>
Runtime Error!
Program:
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
HH:mm:ss
dddd, MMMM dd, yyyy
MM/dd/yy
December
November
October
September
August
February
January
Saturday
Friday
Thursday
Wednesday
Tuesday
Monday
Sunday
_nextafter
_hypot
Complete Object Locator'
Class Hierarchy Descriptor'
Base Class Array'
Base Class Descriptor at (
Type Descriptor'
`local static thread guard'
`managed vector copy constructor iterator'
`vector vbase copy constructor iterator'
`vector copy constructor iterator'
`dynamic atexit destructor for '
`dynamic initializer for '
`eh vector vbase copy constructor iterator'
`eh vector copy constructor iterator'
`managed vector destructor iterator'
`managed vector constructor iterator'
`placement delete[] closure'
`placement delete closure'
`omni callsig'
delete[]
new[]
`local vftable constructor closure'
`local vftable'
`udt returning'
`copy constructor closure'
`eh vector vbase constructor iterator'
`eh vector destructor iterator'
`eh vector constructor iterator'
`virtual displacement map'
`vector vbase constructor iterator'
`vector destructor iterator'
`vector constructor iterator'
`scalar deleting destructor'
`default constructor closure'
`vector deleting destructor'
`vbase destructor'
`string'
`local static guard'
`typeof'
`vcall'
`vbtable'
`vftable'
operator
delete
__unaligned
__restrict
__ptr64
__clrcall
__fastcall
__thiscall
__stdcall
__pascal
__cdecl
__based(
GetProcessWindowStation
GetUserObjectInformationA
GetLastActivePopup
GetActiveWindow
MessageBoxA
USER32.DLL
SunMonTueWedThuFriSat
JanFebMarAprMayJunJulAugSepOctNovDec
GAIsProcessorFeaturePresent
KERNEL32
1#QNAN
1#SNAN
bad allocation
vivenegaxabehupazihuzoligu nayugegaledinotonokenumanikuxe
relanirevebikadedosumayuyesa
megutahateni
vunixikexojomowobi
bad exception
zeyurewana
depimimafotema
nobenu
C:\fevivopujifah\hiketutifocihe\yavew90-nubovo\rurahoke\77_leru.pdb
D$$3D$
D$4Pj@QR
D$P1L
D$`Ovu#
D$`GxdY
D$4b.u
|*SSQVj
0SSSSS
0A@@Ju
tNIt?It0It
>=Yt1j
j@j ^V
t"SS9]
0SSSSS
PPPPPPPP
0SSSSS
PPPPPPPP
j h 7B
URPQQh
t+WWVPV
;t$,v-
UQPXY]Y[
_VVVVV
^WWWWW
0SSSSS
_VVVVV
<+t(<-t$:
+t HHt
ax#}?^i
s+!O.)
ayof"^A
qBfaw!D:
g8lR?v5-P%
6,zF2w
\w|QSBz
qWkf$uU
t|&@6|[
v4F8o@
,>\F5v+
d6[P_;
em(=~UogH
AG0Rp(
3MdT,{
lkZIp.
j(1)L]"
jP?K%d
1D5+|Hlh
(hNm|QTo
\n_{3a|
1G)O Am
c_8g]ru
5_})/ha
yVZrEAw
F$4%Wne
_dBNX*
o$|[2@]
sM1q@{Ro>
{zT}or
\Pl:]
hIC:w{
.42`no
}7&$<~D
0y^TZ{
T-%Q_5
YDxZ:K"
@s2/lO
M=5+&l
0ux?xb
V`W20q
om_|Xh
dY1p`1
c^G%q@
nns_6o
T~6g5X
+P H{V
?/yj7;
C[@4+P"
[Oq8=_
EeLg>j
HE?fR,
3ZUmnI
|w(3AV}
`g(aOb
x8n`Pmo
x>EmHr#z
-yKuNQ
|xE-5'
MQC:M0
{xfAs`
G@P2x<8
LVwSV#
Uu6em4
{*t%AJ
XsV'{9"
kj_-lF
iDvWh3
[;(O4Ou_
Xx04Z'{
$zk6+T
r\Y>sCJ
f"o$EP4
)caF.E
L,YVW$
<ou|j;
F4l_kE
DsDc+~
*=U#%P
&bup8`
B)ZyY"
"NR/E
GqruOTt
[my\s*Q
Jsb4[.
ZY[W%VN'
,$zL=X
[Z%HvZ
Syk0jgg
?$9u:.
RdEc;Qa
^`29g>%%
e+Pg83
5ui/9e
$ov?p:q
}*8>A'a
CX3.Yh
`V@V\)6
XplwYY~
`7pR`(
8DD&b7
nFV'm
~T|l0M
dc`nZ2*
=s#;pcl
t(nfOH
7wYu/3_
![iq9z
9_*+c7
ND1Zue
uuGHZ}
I~S&].
UrLSPn#
!AP*j>]
5=4~38
RTnL)M
h+/Jo`Y
*/Kc\7l
uNq9!Y
wA=Y
t-,"H
I}h^!.] Qh2
.^`v;Z{R
OY/lxV
zom:kP&
#U;||k
?[X05
792q:q
"TU(TV
lZg_HU
GetComputerNameA
EnumResourceNamesW
lstrlenA
ReadConsoleA
ScrollConsoleScreenBufferW
SetHandleInformation
WaitForSingleObject
BackupSeek
GetModuleHandleW
EnumCalendarInfoExW
GetConsoleAliasesLengthA
GetWindowsDirectoryA
EnumTimeFormatsW
TzSpecificLocalTimeToSystemTime
SetProcessPriorityBoost
FindResourceExA
GetCalendarInfoA
IsBadCodePtr
FindNextVolumeW
GetConsoleAliasW
lstrlenW
GlobalUnlock
GetCPInfoExW
GetLastError
SetLastError
GetProcAddress
VirtualAlloc
BeginUpdateResourceW
WriteProfileSectionA
GetConsoleDisplayMode
SetThreadPriorityBoost
LoadLibraryA
WriteConsoleA
InterlockedExchangeAdd
LocalAlloc
WritePrivateProfileStringA
GetNumberFormatW
AddAtomW
RemoveDirectoryW
GetDiskFreeSpaceA
EnumResourceTypesW
GetOEMCP
GetDefaultCommConfigA
GetConsoleTitleW
VirtualProtect
GetShortPathNameW
TlsAlloc
FileTimeToLocalFileTime
DeleteTimerQueueTimer
AddConsoleAliasA
DebugBreak
KERNEL32.dll
SetCaretPos
GetSysColorBrush
GetWindowLongW
CharLowerBuffW
USER32.dll
GetCharABCWidthsW
GetColorAdjustment
GetCharWidthW
GDI32.dll
OleQueryLinkFromData
ole32.dll
MultiByteToWideChar
GetCommandLineA
GetStartupInfoA
HeapAlloc
HeapFree
GetCPInfo
InterlockedIncrement
InterlockedDecrement
GetACP
IsValidCodePage
TlsGetValue
TlsSetValue
TlsFree
GetCurrentThreadId
HeapSize
ExitProcess
SetUnhandledExceptionFilter
WriteFile
GetStdHandle
GetModuleFileNameA
FreeEnvironmentStringsA
GetEnvironmentStrings
FreeEnvironmentStringsW
WideCharToMultiByte
GetEnvironmentStringsW
SetHandleCount
GetFileType
DeleteCriticalSection
HeapCreate
VirtualFree
QueryPerformanceCounter
GetTickCount
GetCurrentProcessId
GetSystemTimeAsFileTime
TerminateProcess
GetCurrentProcess
UnhandledExceptionFilter
IsDebuggerPresent
LeaveCriticalSection
EnterCriticalSection
HeapReAlloc
LCMapStringA
LCMapStringW
GetStringTypeA
GetStringTypeW
GetLocaleInfoA
InitializeCriticalSectionAndSpinCount
RtlUnwind
RaiseException
GetModuleHandleA
.?AVtype_info@@
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
.?AVbad_exception@std@@
.?AVexception@std@@
.?AVbad_alloc@std@@
cccccccccccccccccccccccccccccccccccccccc
c9mmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmm9c
iiiiiiiii
CCCCCC
M777sss
&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&
lllllllllllllllllllllllll
111111111e1e1eeeeeee
1111111e1e1e1e1e
1111111111111e1e1ee
111111e11e1ee1e1
11111111e11ee
11111111e11e
l111111e1e
111e111e
11111e1
11111e
&&&&&&&&&&&&&&&&&&&&&&&&&&&V
V&&&&&&&&&&&&&&&&&&&&&&&&&&&&&
&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&
oooooooooooooooooo
!!!!!!!!!!!!
6666666
vvvvvvvvv
vvvvvvvvvvvA
{~~|}|~
~|}z}{
~y~}z{
}{|}z~
|||~~~{
~}||{||}y{}
}}~{z~
~~~z}{
{}|y}}}|
}{{|z~~
|}||~~
yy}~~~
|~|~|z{
~~}}~~}z
~|~}}~~
yz{}zy
|}}{z{~
{~{z~z|
iiiiiiii
iiiiiiii
iiiiii
iiiiii
iiiiiiiii
iiiiiiiiii
iiiiiiii
iiiiiii
iiiiiiiii

1<2@2D2
48:<:@:D:H:L:P:T:X:\:`:d:h:l:p:t:x:|:
; ;$;(;,;0;4;8;<;@;D;H;L;P;T;X;\;`;d;h;l;p;t;x;|;
0$0(080<0@0H0`0p0t0|0
0%1+10161=1D1K1R1Y1`1f1m1s1y1
1*212[2d2i2o2
4"4f4z4
4$515:5?5X5p5x5
6M6S6Y6
7(7]7i7{7
8\<b<h<n<
===K=Y=j=p=v=
W4e4l4q4y4~4
4=5T5l566>6S6^6
637Y7a7
8"8K8P8g8
;!;';9;A;L;
<F=L=l=
?&?B?e?q?
(0.0:0
3,5=5w5
929N9W9]9f9k9z9
=$=0=E=L=`=g=
>'>->6>B>P>V>b>h>u>
>?_?e?
0 1'1B1G1O1U1\1b1i1o1w1~1
22,2:2@2M2m2s2
3F3O3[3
3=4C4p4y4
4X5`5s5~5
6,6l6y6
;*;P;k;r;{;
< <$<(<,<0<4<8<><I<a<
<(=H=M=k>q>
?&?f?k?
2-2e2o2
495?5U5`5w5
606b6{6
7!8Q8c8
9=9B9P9_9
;*;P;W;a;
=G?U?[?u?z?
0"0'0/050?0F0Z0a0g0u0|0
7 8>:P:]:i:s:{:
:};-<P<
='>1>I>P>Z>b>o>v>
2(2:2L2^2p2
5 5$5(5,50545~5
6#6(6,606Q6{6
7 7$7(7,7
9=9q9w9
>M>Y>e?
:T:b:h:x:}:
=-=S=q=x=|=
=V>a>|>
? ?$?(?,?0?z?
1F1S122A2
3$3+32393@3G3O3W3_3k3t3y3
0r1C3L3x3~3
;01191
5(5H5h5
686X6x6
787T7X7t7x7
6(787H7X7h7
8$8,848<8D8L8T8\8d8l8t8|8
: :$:(:,:0:4:8:<:@:D:H:L:P:T:X:\:`:d:h:l:p:t:x:|:
; ;$;(;,;0;4;L;T;\;d;l;t;|;
KERNEL32.DLL
mscoree.dll
((((( H
h(((( H
H
kernel32.dll
hoyunikuhiwodesuliza wir yeracasuzovufasekorexuzaxub xejahisu cufevinejoxari
olaveroronecazuzijisofid buwikur
AFX_DIALOG_LAYOUT
/ P6pL
,/KPip
/-P?pR
/ P6pL
,/KPip
/-P?pR
/ P6pL
,/KPip
/-P?pR
VS_VERSION_INFO
StringFileInfo
045831F6
FilesVersion
21.21.28.6
InternalName
DogmaticSuffering
FileDescription
Genuine parts inc
ProductsVersion
80.23.73.2
ProductName
Doppelgamer
ProductionVersion
1.0.0.3
VarFileInfo
Translation
Antivirus Signature
Bkav W32.AIDetect.malware1
Lionic Trojan.Win32.Androm.4!c
Elastic malicious (high confidence)
MicroWorld-eScan Clean
ClamAV Win.Packer.pkr_ce1a-9980177-0
FireEye Generic.mg.50a75fb5b1245084
CAT-QuickHeal Clean
ALYac Clean
Malwarebytes Trojan.MalPack.GS
Zillya Clean
Sangfor Trojan.Win32.Save.a
K7AntiVirus Trojan ( 00516fdf1 )
BitDefender Clean
K7GW Trojan ( 0056dffa1 )
CrowdStrike win/malicious_confidence_100% (W)
BitDefenderTheta Clean
VirIT Clean
Cyren W32/Kryptik.JRO.gen!Eldorado
Symantec ML.Attribute.HighConfidence
tehtris Generic.Malware
ESET-NOD32 a variant of Generik.DDLSGBU
APEX Malicious
Paloalto generic.ml
Cynet Malicious (score: 100)
Kaspersky UDS:Backdoor.Win32.Androm
Alibaba Clean
NANO-Antivirus Clean
ViRobot Clean
Tencent Clean
Sophos Mal/Generic-S
Baidu Clean
F-Secure Clean
DrWeb Clean
VIPRE Clean
TrendMicro Clean
McAfee-GW-Edition BehavesLike.Win32.Lockbit.dh
Trapmine malicious.high.ml.score
CMC Clean
Emsisoft Clean
Ikarus Trojan-Ransom.StopCrypt
GData Win32.Trojan-Stealer.LokiBot.V8JTD6
Jiangmin Clean
Webroot W32.Trojan.Gen
Avira Clean
MAX Clean
Antiy-AVL Clean
Gridinsoft Ransom.Win32.LokiBot.bot
Xcitium Clean
Arcabit Clean
SUPERAntiSpyware Clean
ZoneAlarm UDS:Backdoor.Win32.Androm
Microsoft Trojan:Win32/Amadey.PAD!MTB
Google Detected
AhnLab-V3 Clean
Acronis suspicious
McAfee Artemis!50A75FB5B124
TACHYON Clean
DeepInstinct MALICIOUS
VBA32 Trojan.Buzus
Cylance unsafe
Panda Trj/Genetic.gen
Zoner Clean
TrendMicro-HouseCall TROJ_GEN.R002H07DQ23
Rising Trojan.Kryptik!1.E4D1 (CLASSIC)
Yandex Clean
SentinelOne Static AI - Suspicious PE
MaxSecure Trojan.Malware.300983.susgen
Fortinet W32/PossibleThreat
AVG Win32:RansomX-gen [Ransom]
Avast Win32:RansomX-gen [Ransom]
No IRMA results available.