Static | ZeroBOX

PE Compile Time

2022-06-19 01:55:09

PDB Path

C:\bovamicecoc\gojosaneg.pdb

PE Imphash

3129b82d0a2746cb6ab1a7613afd0e3c

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x00025486 0x00025600 7.60359862239
.data 0x00027000 0x0006ff68 0x00001c00 2.76382347952
.rsrc 0x00097000 0x00008248 0x00004400 4.03241911606
.reloc 0x000a0000 0x00001fc2 0x00002000 3.34882122313

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x00099e60 0x00000468 LANG_PORTUGUESE SUBLANG_PORTUGUESE_BRAZILIAN GLS_BINARY_LSB_FIRST
RT_ICON 0x00099e60 0x00000468 LANG_PORTUGUESE SUBLANG_PORTUGUESE_BRAZILIAN GLS_BINARY_LSB_FIRST
RT_ICON 0x00099e60 0x00000468 LANG_PORTUGUESE SUBLANG_PORTUGUESE_BRAZILIAN GLS_BINARY_LSB_FIRST
RT_STRING 0x0009acb0 0x00000598 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_STRING 0x0009acb0 0x00000598 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_STRING 0x0009acb0 0x00000598 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_GROUP_ICON 0x0009a2c8 0x00000030 LANG_PORTUGUESE SUBLANG_PORTUGUESE_BRAZILIAN data
RT_VERSION 0x0009a2f8 0x00000204 LANG_NEUTRAL SUBLANG_NEUTRAL data

Imports

Library KERNEL32.dll:
0x401008 FindResourceA
0x40100c EnumCalendarInfoA
0x401010 EnumDateFormatsExW
0x401014 FindResourceW
0x401018 CreateHardLinkA
0x40101c SetTapeParameters
0x401020 GetModuleHandleW
0x401024 GetTickCount
0x401028 GetConsoleAliasesA
0x401030 GetVolumePathNameW
0x401034 GlobalAlloc
0x401038 LoadLibraryW
0x40103c ReadConsoleInputA
0x401040 CopyFileW
0x401048 DisconnectNamedPipe
0x40104c FlushFileBuffers
0x401050 GetProfileIntA
0x401058 GetLastError
0x40105c CreateMutexW
0x401060 GetProcAddress
0x401068 LoadLibraryA
0x40106c OpenMutexA
0x401070 lstrcmpiW
0x401074 SetLocaleInfoW
0x401078 CreateMutexA
0x40107c VirtualProtect
0x401080 GetVersionExA
0x401088 lstrcpyA
0x40108c CreateFileA
0x401090 CloseHandle
0x401094 WriteConsoleW
0x401098 GetConsoleOutputCP
0x40109c WriteConsoleA
0x4010a0 SetStdHandle
0x4010a4 GetModuleHandleA
0x4010a8 SetLastError
0x4010ac GetComputerNameA
0x4010b8 Sleep
0x4010d4 MultiByteToWideChar
0x4010d8 ExitProcess
0x4010dc GetStartupInfoW
0x4010e0 HeapFree
0x4010e4 RtlUnwind
0x4010e8 RaiseException
0x4010ec WriteFile
0x4010f0 GetStdHandle
0x4010f4 GetModuleFileNameA
0x4010f8 HeapAlloc
0x4010fc SetHandleCount
0x401100 GetFileType
0x401104 GetStartupInfoA
0x401108 TerminateProcess
0x40110c GetCurrentProcess
0x401110 IsDebuggerPresent
0x401114 TlsGetValue
0x401118 TlsAlloc
0x40111c TlsSetValue
0x401120 TlsFree
0x401124 GetCurrentThreadId
0x401128 HeapSize
0x40112c GetCPInfo
0x401130 GetACP
0x401134 GetOEMCP
0x401138 IsValidCodePage
0x401140 GetModuleFileNameW
0x40114c GetCommandLineW
0x401150 HeapCreate
0x401154 VirtualFree
0x40115c GetCurrentProcessId
0x401164 VirtualAlloc
0x401168 HeapReAlloc
0x40116c GetLocaleInfoA
0x401170 GetStringTypeA
0x401174 GetStringTypeW
0x401178 SetFilePointer
0x40117c WideCharToMultiByte
0x401180 GetConsoleCP
0x401184 GetConsoleMode
0x401188 LCMapStringA
0x40118c LCMapStringW
Library USER32.dll:
0x401194 CharToOemBuffA
0x401198 RealGetWindowClassW
0x40119c CharUpperBuffW
0x4011a0 GetMenuBarInfo
0x4011a4 CharUpperA
0x4011a8 CharLowerBuffW
0x4011ac CharUpperBuffA
0x4011b0 LoadMenuW
0x4011b4 DdeQueryStringA
0x4011b8 GetClipboardOwner
Library ADVAPI32.dll:
0x401000 LogonUserW

!This program cannot be run in DOS mode.
qRichJ
`.data
@.reloc
bad allocation
Unknown exception
CorExitProcess
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
runtime error
TLOSS error
SING error
DOMAIN error
An application has made an attempt to load the C runtime library incorrectly.
Please contact the application's support team for more information.
- Attempt to use MSIL code from this assembly during native code initialization
This indicates a bug in your application. It is most likely the result of calling an MSIL-compiled (/clr) function from a native constructor or from DllMain.
- not enough space for locale information
- Attempt to initialize the CRT more than once.
This indicates a bug in your application.
- CRT not initialized
- unable to initialize heap
- not enough space for lowio initialization
- not enough space for stdio initialization
- pure virtual function call
- not enough space for _onexit/atexit table
- unable to open console device
- unexpected heap error
- unexpected multithread lock error
- not enough space for thread data
This application has requested the Runtime to terminate it in an unusual way.
Please contact the application's support team for more information.
- not enough space for environment
- not enough space for arguments
- floating point support not loaded
Microsoft Visual C++ Runtime Library
<program name unknown>
Runtime Error!
Program:
EncodePointer
DecodePointer
FlsFree
FlsSetValue
FlsGetValue
FlsAlloc
(null)
`h````
xpxxxx
bad exception
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
HH:mm:ss
dddd, MMMM dd, yyyy
MM/dd/yy
December
November
October
September
August
February
January
Saturday
Friday
Thursday
Wednesday
Tuesday
Monday
Sunday
GetProcessWindowStation
GetUserObjectInformationA
GetLastActivePopup
GetActiveWindow
MessageBoxA
USER32.DLL
_nextafter
_hypot
`h`hhh
xppwpp
Complete Object Locator'
Class Hierarchy Descriptor'
Base Class Array'
Base Class Descriptor at (
Type Descriptor'
`local static thread guard'
`managed vector copy constructor iterator'
`vector vbase copy constructor iterator'
`vector copy constructor iterator'
`dynamic atexit destructor for '
`dynamic initializer for '
`eh vector vbase copy constructor iterator'
`eh vector copy constructor iterator'
`managed vector destructor iterator'
`managed vector constructor iterator'
`placement delete[] closure'
`placement delete closure'
`omni callsig'
delete[]
new[]
`local vftable constructor closure'
`local vftable'
`udt returning'
`copy constructor closure'
`eh vector vbase constructor iterator'
`eh vector destructor iterator'
`eh vector constructor iterator'
`virtual displacement map'
`vector vbase constructor iterator'
`vector destructor iterator'
`vector constructor iterator'
`scalar deleting destructor'
`default constructor closure'
`vector deleting destructor'
`vbase destructor'
`string'
`local static guard'
`typeof'
`vcall'
`vbtable'
`vftable'
operator
delete
__unaligned
__restrict
__ptr64
__clrcall
__fastcall
__thiscall
__stdcall
__pascal
__cdecl
__based(
SunMonTueWedThuFriSat
JanFebMarAprMayJunJulAugSepOctNovDec
GAIsProcessorFeaturePresent
KERNEL32
CONOUT$
1#QNAN
1#SNAN
bad allocation
xorexayudulapukolo
%s %f %c
tuyowavakonipatukadepuyituwoho
C:\bovamicecoc\gojosaneg.pdb
D$,1D$
/SUVWuT3
L$$Qj@RP
ubh<0@
jXh8UB
QQSVWd
to=H~B
0SSSSS
tNIt?It0It
j@j ^V
0A@@Ju
>=Yt1j
QQSVWh
HtHu4j
s[S;7|G;w
tR99u2
v$;5l~B
0SSSSS
PPPPPPPP
0SSSSS
PPPPPPPP
URPQQh
t"SS9]
0WWWWW
AAFFf;
;t$,v-
UQPXY]Y[
t+WWVPV
_VVVVV
^WWWWW
0SSSSS
_VVVVV
<+t(<-t$:
+t HHt
\MU][X
"s^=kM
`&L9d!z!;f
XHoHU'
Fz@QHO
%$^^];@
s(tLid@
iW1'3d
[JU<(?
alqq'B
@MTTRp
|:-SDs
p}&sO0
}$Jn1IT
Fl8Q}W
pYY^?]
;y:'"L\
uB(%Z{z
cD5#V#0
&v+!wb
FDQaL@
m;Aa'bb
qTf8r@
qJ1dz]
UzBjWI
|G4a:#
3"2:bd.
=eix~0
8o&n3W$
33/ZxWi}$
XHW?jh
1~p,ka
)aH'D:
A8`7Bk
|=0*O5Pj
K^\>hE
;QW5ma
1A ?isH
Xq ?rI
9%H?J5
en`Q`4?
3l<U[_ao{y"
C6PvR-r
9oklr
x,;,lQ
a'+Kh$
a_`%}X
_2&::FQ
[vVuUN
bA8>*
=D&Y5!7a
=&1C^9
yM;4jJ
T*[KlM
%qk!(,
o_zHfp
c5k?w&
}Ku(m[
zcnTzXy
6LI@&n-
.:Ucmn!
1XS[`:
cPZ:>Ff
MC~L?l
<Q?z?3!
^!mhmUu
\2$C%/
&%93ng
E>VZqw
5a1x f$
-bCPtc
;xsqg7u~|
1R1J-!L
H=eM0L`
!0D,uO
*&Qbz n)
g AaLZ
sx-aF?
hbk tp~
~_$aP%
U%=$ah
y9G6mHE
Y a|SP
,{W?L8
vX:jtc
O:GB*K
4'}~i$
pXo0m2
.?5L_\
@K&6!L
G#ZGhV
C-a5Z|6
A/0BXs
'*B?Po;bC
k(2qy}
1D2lIn3
F@zNM
*N+Ai/
FJV3McK
+hi24o
ta8n`k
&@eAx&
2Irkx_
yUCL~-
boJz~Udp
bZZdqJS!
GAU2lY
k-e@ p
0P`095
M@"5N9
xkqDu<
3iM;G1
U_FDo)
.=[ap$W
B<K!!'
^@3(pz
A]_ee1
pRscAJ+
ho$MVp
~twGnU
jFi`8D
L >OWR
)WRKwG
1T(/*?
\fXPk-32
eo(sUt
{0XXru9}
~?}tS)
r1tb2bk
&(-"B8]
V7f,?5
s1JStE
n=|#J+{
WqUw"[
y!l@Q<
S#JM]0
HK|)&H
L)oFDJG
[8Uf&&
OT@*g5
Os$gl
e)9sEVM
>st,:#
6BY ]p
So&rlx
Hy>DlD
^\f\qT
Y|e="ng
GetComputerNameA
CreateMutexW
FindResourceA
EnumCalendarInfoA
EnumDateFormatsExW
FindResourceW
CreateHardLinkA
SetTapeParameters
GetModuleHandleW
GetTickCount
GetConsoleAliasesA
GetWindowsDirectoryA
GetVolumePathNameW
GlobalAlloc
LoadLibraryW
ReadConsoleInputA
CopyFileW
EnumSystemCodePagesA
DisconnectNamedPipe
FlushFileBuffers
GetProfileIntA
SetCurrentDirectoryA
GetLastError
SetLastError
GetProcAddress
BeginUpdateResourceW
LoadLibraryA
OpenMutexA
lstrcmpiW
SetLocaleInfoW
CreateMutexA
VirtualProtect
GetVersionExA
FileTimeToLocalFileTime
lstrcpyA
KERNEL32.dll
GetClipboardOwner
DdeQueryStringA
LoadMenuW
CharUpperBuffA
CharLowerBuffW
CharUpperA
GetMenuBarInfo
CharUpperBuffW
RealGetWindowClassW
CharToOemBuffA
USER32.dll
LogonUserW
ADVAPI32.dll
InterlockedIncrement
InterlockedDecrement
InitializeCriticalSection
DeleteCriticalSection
EnterCriticalSection
LeaveCriticalSection
UnhandledExceptionFilter
SetUnhandledExceptionFilter
MultiByteToWideChar
ExitProcess
GetStartupInfoW
HeapFree
RtlUnwind
RaiseException
WriteFile
GetStdHandle
GetModuleFileNameA
HeapAlloc
SetHandleCount
GetFileType
GetStartupInfoA
TerminateProcess
GetCurrentProcess
IsDebuggerPresent
TlsGetValue
TlsAlloc
TlsSetValue
TlsFree
GetCurrentThreadId
HeapSize
GetCPInfo
GetACP
GetOEMCP
IsValidCodePage
InitializeCriticalSectionAndSpinCount
GetModuleFileNameW
FreeEnvironmentStringsW
GetEnvironmentStringsW
GetCommandLineW
HeapCreate
VirtualFree
QueryPerformanceCounter
GetCurrentProcessId
GetSystemTimeAsFileTime
VirtualAlloc
HeapReAlloc
GetLocaleInfoA
GetStringTypeA
GetStringTypeW
SetFilePointer
WideCharToMultiByte
GetConsoleCP
GetConsoleMode
LCMapStringA
LCMapStringW
GetModuleHandleA
SetStdHandle
WriteConsoleA
GetConsoleOutputCP
WriteConsoleW
CloseHandle
CreateFileA
Copyright (c) 1992-2004 by P.J. Plauger, licensed by Dinkumware, Ltd. ALL RIGHTS RESERVED.
.?AVtype_info@@
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
.?AVbad_exception@std@@
6cE\B',kA
.?AVexception@std@@
////////////////////////////////////////////////////////////////////////////////////////
////////////////////
P//////////////////
?l7////////////////
///////////////]
//////////////
///////////////
7///////////////
///////////)
C//////////
J//////////e
////////////
<////////////
/////////////
e////////////e,p///
////////////e,/////
//////////////////
//////////////////)
//////////////////
//////////////////
//////////////////////////////////////
z}~}}~
}||~~~}
}z}~}~
|~~}~}
~~y~~~
~z}~~|
{{}}~z}}
{{~|{y
|}~|~~
}}}{}~
y~|{~~
}z}|{||
}|~}|{
~}|||}|
{z}|~~{~{
~y|||~{~z
{z|}z~z
}}}}z}
}}z}~|
|}~|{z
2T2X2\2
`5d5h5
< <$<(<,<0<4<8<<<@<D<H<L<P<T<X<\<`<d<h<l<p<t<x<|<
= =$=(=,=0=4=8=<=@=D=H=L=P=T=X=\=
0,101@1D1T1X1`1x1
363X3b3x3
5D5Y5q5
66%6+626?6
727<7D7Z7`7f7
8T8`8l8r8
9 9%9h9p9x9
::/:?:J:P:[:`:v:
>$>F>M>
M0U0j0u0
3D3_3e3n3u3
4!414;4B4M4V4l4w4
5A5F5Q5V5t5%626?6d6x6
8g9 :8:=:
)0@0Q0
0C1H1M1R1b1
10252<2A2H2M2
3:4?4g4
6#6Z6k6
80898B8O8u8
8-9195999=9A9E9I9M9Q9U9Y9]9c9n9
9K:Q:k:z:
;+;5;[;
=*>2>r>|>
1'1S1o1
3$3<3T3
6$6/6;6P6W6k6r6
7#72787A7M7[7a7m7s7
8*8j8p8
9+:2:M:R:Z:`:g:m:t:z:
;%;*;7;E;K;X;x;~;
<"<.<g<p<|<
.0?0y0
444P4Y4_4h4m4|4
5#6A6H6L6P6T6X6\6`6d6
6&717L7S7X7\7`7
8J8P8T8X8\8
; ;J;X;^;
5#515@5c5p5|5
5/6H6O6W6\6`6d6
6>7D7H7L7P7
8;8m8t8x8|8
<#<(<1<N<T<_<d<l<r<|<
1$1*10161=1D1K1R1Y1`1g1o1w1
4"444F4X4j4
656<6F6N6[6b6
7L9Z9`9p9u9
:@:]:z:
;!;';+;1;5;;;?;E;I;b;t;)<V>
5.5;5I5y5
8 898W8
2+2I2U2a3
7=8W8i8v8
1J1X1g1u1}1
:&:q=u=y=}=
"4<4F4P4\4h4r4~4
505L5P5X5\5x5
6$6@6L6h6
7$7(7D7H7d7h7
7(80848L8P8l8p8x8
9(949P9p9
:0:8:L:T:h:
1$1,141<1D1L1T1\1d1l1t1
9P;`;p;
= =$=(=,=0=4=P=T=
> >$>(>,>0>@>H>L>P>T>X>\>`>d>h>l>x>
?$?,?4?<?D?L?T?\?d?l?t?|?
mscoree.dll
KERNEL32.DLL
(null)
((((( H
h(((( H
H
kaxemikebolozituxot wecubokadewupuxowujumiye danolufehenezedat nelejun jorujama
favocigateyacujijejecayecujoxe diviyujuxevimeboyodi beyulolovotaforopudopevixu runotabonucuvevusicojefifusuge
kernel32.dll
kernel32.dll
sagokuvagihodenefixezi
msimg32.dll
@jjjjj
VS_VERSION_INFO
StringFileInfo
043831F2
InternalName
Huckleber
FileDescription
Underwear
ProductsVersion
41.94.90.86
ProductName
GoldenSig
ProductionVersion
59.36.69.62
VarFileInfo
Translation
Gerir derologofoxi
Nilapeduk wanvViriropokifu kolucozukiluc yuxuhabulacalay pawajuwafutomek renurelesup gukivegadawagih fegaci dijurosahukimor turemipa
Dopilufa wokisebo3Ran doho hen cipa gizesusaguxewim hizazuceyu ticika;Mifeju kosupis cegifunapexi huhodiho boyazelopebox ribujiki7Nusezagig jehazidumuhow kikedupeniheri gutovaw yolovexa%Fazeparet gobecemivenopay hapayibexom-Fefawaz bedifanaderaxu yexeruhit reholukejiti
Luhut kimeg givaxa luxaQCadakeh cevub tapenul kuhe fisihat majamatehemopez mufagepoco fogaxub kopepawumor
nPecu fogaletazeyuxe rozita halihifereki vofotato negubijihepoxom serojivacerah yawutohipuz fiz tonasenitubumep
MHinuzazirejid xolifuyocucek hufoxugaroyuh daridag rixijabo fufun pobemudifeba
ZYum diy soyutihufumonu wirarileyuvane mogopowera xuwipobaz xiveyoke kupiyija bafuwucimozup
Vivexevetepe
Zowise hizuZTekuwihemuk lufin zilumiyizasewo zavunot hoducajixax luxejudugo mafulularaz gakumaw tasina'Yikaliduhono peyizapa tuzixituxi dayoga
.Darewamumekira yareweji wojomu pafego bima jow%Kut netavijokox hutofiyohimuv pifudih.Degoce tix rivohayacukoje ravodo hoxoke zifanoOLenu pejevopuyodosi kukedixogagowum xopajuminaj ginuduposayamom vahewizizigibabXDatawaxelanu woxa rohuhekec minomelesigog xidologu nudepakayoxak yabosajidejuyel zurebuxMNiyalujewuyo xosurohivemumuh yojadovogadel cawewaxobibokih vamoluzuninaf gimi
Fehasudawu pipejufa%Tiribibuw yawanumo tegetaxot kowenukiSZisasirohika gasawak luxaf zuxaram yufuterazazup tiwubivubutotot pog nodobowetivizo-Debuzizihim zecijosidef naluh gekoz masadecil_Hatotupefudota yoxamozelimam gakofizafufosi tiy lahewovozuli miferolidowo hunohusaw wikusacafaf
Cijujucedapum#Nuyez luti hufuluvoxahuyu sibayahub
Antivirus Signature
Bkav W32.AIDetectMalware
Lionic Trojan.Win32.Packed.4!c
Elastic malicious (high confidence)
MicroWorld-eScan Clean
ClamAV Win.Packer.pkr_ce1a-9980177-0
FireEye Generic.mg.f8cfc631cdbba89b
CAT-QuickHeal Ransom.Stop.P5
ALYac Clean
Malwarebytes Generic.Malware/Suspicious
VIPRE Clean
Sangfor Trojan.Win32.Save.a
CrowdStrike win/malicious_confidence_100% (W)
BitDefender Clean
K7GW Clean
K7AntiVirus Clean
Arcabit Clean
BitDefenderTheta Clean
VirIT Clean
Cyren Clean
Symantec ML.Attribute.HighConfidence
tehtris Clean
ESET-NOD32 Clean
APEX Malicious
Paloalto Clean
Cynet Malicious (score: 100)
Kaspersky UDS:DangerousObject.Multi.Generic
Alibaba Clean
NANO-Antivirus Clean
ViRobot Clean
Rising Trojan.Kryptik!1.B663 (CLASSIC)
Sophos Mal/Generic-S
Baidu Clean
F-Secure Clean
DrWeb Clean
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition BehavesLike.Win32.Packed.cc
Trapmine suspicious.low.ml.score
CMC Clean
Emsisoft Clean
Ikarus Clean
Jiangmin Clean
Webroot Clean
Avira Clean
MAX Clean
Antiy-AVL Clean
Gridinsoft Ransom.Win32.STOP.dg!n
Xcitium Clean
Microsoft Trojan:Win32/Sabsik.FL.B!ml
SUPERAntiSpyware Clean
ZoneAlarm UDS:DangerousObject.Multi.Generic
GData Clean
Google Detected
AhnLab-V3 Clean
Acronis suspicious
McAfee Packed-GDV10!F8CFC631CDBB
TACHYON Clean
DeepInstinct MALICIOUS
VBA32 BScope.Exploit.Convagent
Cylance unsafe
Panda Trj/Chgt.AD
Zoner Clean
TrendMicro-HouseCall Clean
Tencent Trojan.Win32.Obfuscated.gen
Yandex Clean
SentinelOne Static AI - Malicious PE
MaxSecure Trojan.Malware.300983.susgen
Fortinet W32/GenKryptik.ERHN!tr
AVG Win32:DropperX-gen [Drp]
Avast Win32:DropperX-gen [Drp]
No IRMA results available.