Static | ZeroBOX

PE Compile Time

2023-08-07 21:00:38

PE Imphash

035152f08fc01104c539a9694e78d939

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x0000c96f 0x0000ca00 6.9478278837
.rdata 0x0000e000 0x00002138 0x00002200 5.8781539716
.data 0x00011000 0x00001b5c 0x00001000 3.63169955022
.rsrc 0x00013000 0x00076288 0x00076400 6.70148712255

Resources

Name Offset Size Language Sub-language File type
RT_MANIFEST 0x00013100 0x0000015a LANG_ENGLISH SUBLANG_ENGLISH_US ASCII text, with CRLF line terminators
RT_RCDATA 0x00013688 0x00075c00 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_VERSION 0x00013260 0x00000424 LANG_ENGLISH SUBLANG_ENGLISH_US data

Imports

Library KERNEL32.dll:
0x40e008 WaitForSingleObject
0x40e00c CreateThread
0x40e010 lstrlenW
0x40e014 VirtualProtect
0x40e018 GetProcAddress
0x40e01c LoadLibraryA
0x40e020 VirtualAlloc
0x40e024 LockResource
0x40e028 LoadResource
0x40e02c SizeofResource
0x40e030 Sleep
0x40e034 GetModuleHandleW
0x40e038 GetLastError
0x40e03c CreateMutexA
0x40e040 GetModuleHandleA
0x40e048 MoveFileW
0x40e04c GetConsoleWindow
0x40e050 FindResourceW
0x40e054 OpenFileMappingA
0x40e058 GetCommandLineA
0x40e060 ExitProcess
0x40e064 WriteFile
0x40e068 GetStdHandle
0x40e06c GetModuleFileNameA
0x40e07c WideCharToMultiByte
0x40e084 SetHandleCount
0x40e088 GetFileType
0x40e08c GetStartupInfoA
0x40e094 TlsGetValue
0x40e098 TlsAlloc
0x40e09c TlsSetValue
0x40e0a0 TlsFree
0x40e0a8 SetLastError
0x40e0ac GetCurrentThreadId
0x40e0b4 HeapCreate
0x40e0b8 VirtualFree
0x40e0bc HeapFree
0x40e0c4 GetTickCount
0x40e0c8 GetCurrentProcessId
0x40e0d0 GetCPInfo
0x40e0d4 GetACP
0x40e0d8 GetOEMCP
0x40e0dc IsValidCodePage
0x40e0e0 TerminateProcess
0x40e0e4 GetCurrentProcess
0x40e0ec IsDebuggerPresent
0x40e0fc HeapAlloc
0x40e100 HeapReAlloc
0x40e104 RtlUnwind
0x40e108 LCMapStringA
0x40e10c MultiByteToWideChar
0x40e110 LCMapStringW
0x40e114 GetStringTypeA
0x40e118 GetStringTypeW
0x40e11c GetLocaleInfoA
0x40e120 HeapSize
Library USER32.dll:
0x40e128 ShowWindow
Library ADVAPI32.dll:
0x40e000 RegDeleteKeyA

!This program cannot be run in DOS mode.
KRich>
`.rdata
@.data
C-STT\D\Djk'
\|\s(l
\t\xjy^
\CjkW\x
jlpjaZ
ja?*I/
d\p\E\{*qq
\u\pj|
jkY*E/
\pj{>je~\E*HH
\D\y*m
a\C*@t
jy4\p\C*aE
\D\s(l
a\}jin
\tjqkjm.
\C\y(H
jl'\p\s
jyo*m@
\qj{.(A
\E\t*io
CXZTT(o
c\u\q\A
\t\p*q
j}_\q*E,
ju-\A(k
jcz\x*u
\|\yje@(u
e\@\u\t(m
\u\E(@
jk6\x\y\Ejs+ja
ajdvjm
\q\C\t(h
\|jsr*m
\y\y\yjm
a\@jeY\t
\}\Dj{
a\s\C\x
\s\p\x(t
\t\u\@*ev
\x\q\tjln\tjpy(d
ajiFjs
a\@\|jx
\t\A\|jq*jl
@;jk4\{*q
jc3\D*@J
\|\sjq3(h
jqM\A*t?
YT@ .
\x\yjd
\t\}jh
jucjsc(m
jaB\p*`$
jc@\q\E
\xjk;(q
\t\@jx
\u\p\|\t
jaI\Ejpy\D(l
B}UTTjl
\q\y\}\t*HX
\y\u(a
\q\C*e
\y\s*tA
jxU\t*pJ
\E\p\@ja
\qjh7jm
\t\E*p\
\|\@(c
\Ajx7jp
j}P*q
cjikjh
\p\sjk
ja2\p*qE
\y\y\q(I
je5\s\s\E
\|jx~\qj|K*`i
cje!(A
a\D\E\y\x
YT\A*A-
c\Djx=*Hi
d\E\}jm+\uja
\}\t(l
jeO\pja
\@\A\D
jyY\|(M
\C\Cjc`jiK
d\C\xjd.\C(C
\}\@jx_
\s\sji%ji
\D\Ajs
ej{5\E\C
jiG\s(h
ju/\Aji
\x\Ej|
jabjk`\{*h#
\|\tjq
c\@jy$\sjiUjxE*D^
ji%\{*a'
jhQ\Aju
jcG*M6
\p\@*m
jm1\C(h
hggggggggggggggU
_VVVVV
^WWWWW
>=Yt1j
j@j ^V
t h *A
0A@@Ju
0SSSSS
0SSSSS
_VVVVV
0SSSSS
0SSSSS
URPQQh
t"SS9]
PPPPPPPP
PPPPPPPP
<+t(<-t$:
+t HHt
;t$,v-
UQPXY]Y[
t+WWVPV
bad allocation
kernel32.dll
JVOQRJOJOJHGOJBFOHKBFOM
8]ULG]W_
^XPG]2^
^z`e\P
\z6{^%
d^erv^
F^ oL^
GAIsProcessorFeaturePresent
KERNEL32
CorExitProcess
runtime error
TLOSS error
SING error
DOMAIN error
An application has made an attempt to load the C runtime library incorrectly.
Please contact the application's support team for more information.
- Attempt to use MSIL code from this assembly during native code initialization
This indicates a bug in your application. It is most likely the result of calling an MSIL-compiled (/clr) function from a native constructor or from DllMain.
- not enough space for locale information
- Attempt to initialize the CRT more than once.
This indicates a bug in your application.
- CRT not initialized
- unable to initialize heap
- not enough space for lowio initialization
- not enough space for stdio initialization
- pure virtual function call
- not enough space for _onexit/atexit table
- unable to open console device
- unexpected heap error
- unexpected multithread lock error
- not enough space for thread data
This application has requested the Runtime to terminate it in an unusual way.
Please contact the application's support team for more information.
- not enough space for environment
- not enough space for arguments
- floating point support not loaded
Microsoft Visual C++ Runtime Library
<program name unknown>
Runtime Error!
Program:
EncodePointer
DecodePointer
FlsFree
FlsSetValue
FlsGetValue
FlsAlloc
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
GetProcessWindowStation
GetUserObjectInformationA
GetLastActivePopup
GetActiveWindow
MessageBoxA
USER32.DLL
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
HH:mm:ss
dddd, MMMM dd, yyyy
MM/dd/yy
December
November
October
September
August
February
January
Saturday
Friday
Thursday
Wednesday
Tuesday
Monday
Sunday
1#QNAN
1#SNAN
SunMonTueWedThuFriSat
JanFebMarAprMayJunJulAugSepOctNovDec
OpenFileMappingA
WaitForSingleObject
CreateThread
lstrlenW
VirtualProtect
GetProcAddress
LoadLibraryA
VirtualAlloc
LockResource
LoadResource
SizeofResource
FindResourceW
GetModuleHandleW
GetLastError
CreateMutexA
GetModuleHandleA
SetCurrentDirectoryW
MoveFileW
GetConsoleWindow
KERNEL32.dll
ShowWindow
USER32.dll
RegDeleteKeyA
ADVAPI32.dll
GetCommandLineA
SetUnhandledExceptionFilter
ExitProcess
WriteFile
GetStdHandle
GetModuleFileNameA
FreeEnvironmentStringsA
GetEnvironmentStrings
FreeEnvironmentStringsW
WideCharToMultiByte
GetEnvironmentStringsW
SetHandleCount
GetFileType
GetStartupInfoA
DeleteCriticalSection
TlsGetValue
TlsAlloc
TlsSetValue
TlsFree
InterlockedIncrement
SetLastError
GetCurrentThreadId
InterlockedDecrement
HeapCreate
VirtualFree
HeapFree
QueryPerformanceCounter
GetTickCount
GetCurrentProcessId
GetSystemTimeAsFileTime
GetCPInfo
GetACP
GetOEMCP
IsValidCodePage
TerminateProcess
GetCurrentProcess
UnhandledExceptionFilter
IsDebuggerPresent
LeaveCriticalSection
EnterCriticalSection
InitializeCriticalSectionAndSpinCount
HeapAlloc
HeapReAlloc
RtlUnwind
LCMapStringA
MultiByteToWideChar
LCMapStringW
GetStringTypeA
GetStringTypeW
GetLocaleInfoA
HeapSize
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v3">
<security>
<requestedPrivileges>
<requestedExecutionLevel level="asInvoker" uiAccess="false"></requestedExecutionLevel>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
e*up_eN
2qrrr
e*vk_eB
e*v(_]
e*vtj-#
e*ut_5
e*v|]]
e*u4_Mr
e*ut]]
!2?@@@
(_"2?@@@
!2?@@@
e*udgm
_)!'_)#
e*umgm
Bgvq_m
e*vng#
e*uk_(g
kkz]4j
e*v|a-
e*vMaeR
uu]^%6
vV_f%2
alz$d"
3"_)al
*e*uq_
*e*uf_
e*ulg$
U)_)'I*
V*'_)g
am*am2am
V(_('_
V)_)'_
e!vMgm
EE_(E_o
EE_"Qg
auBauFu
]m2EEE
au"au&
]m&EE]
]m&EEE
2,_nb1
-3=~0*
<.A%L/
--`(0
~}|{zyxwvutsrqp
2,_nb1
-3=~0*
<.A%L/
--`(0
13/dp,
{(!w]-vX
xOj#)X
88<}4;
d:eYkX%
mR^<Sc
KmpuPY
e4F7e4
#,$9Ub
jihgfedcba`_^]\[ZYXWVUTSRQPONMLKJIHGFEDCBA@?>=<;:9876543210/.-,+*)('&%$#"! 
~}|{zyxwvutsrqp
~}|{zyxwvutsrqponmlkjihgfedcba`_^]\[ZYXWVUTSRQPONMLKJIHGFEDCBA@?>=<;:9876543210/.-,+*)('&%$#"! 
jihgfedcba`_^]\[ZYXWVUTSRQPONMLKJIHGFEDCBA@?>=<;:9876543210/.-,+*)('&%$#"! 
onmlkjihgfedcba`_^]\[ZYXWVUTSRQPONMLKJIHGFEDCBA@?>=<;:9876543210/.-,+*)('&%$#"! 
~}|{zyxwvutsrqponmlk
rzrrrr
jjdjij
rzzszz
|q|{xw
zzx{zx
{|vx{~
{uvzuv
{|wvxu
{|wvxu
{|wvxu
{|wvxu
{|wvxu
{|wvxu
{|wvxu
{|wvxu
{|wvxu
{|wvxu
{|wvxu
{|wvxu
{|wvxu
|{|q}{uw
{|wvxu
uwv{xo
|u~~zvx
|u}zu|
kkkkkkkk~
~}|{zyxwvutsrqp
~}|{zyxwvutsrqp
uidut!
mscoree.dll
KERNEL32.DLL
((((( H
h(((( H
H
RT_MANIFEST
VS_VERSION_INFO
StringFileInfo
040904E4
Comments
It was a concerning development
CompanyName
couldn't get out of his mind
FileDescription
many friends throughout his
FileVersion
4.225.654.443
InternalName
and had fond memories
LegalCopyright
Copyright
but he couldn't understand
LegalTrademarks
dragon staring directly into
OriginalFilename
fuck off
ProductName
questioned everything that
ProductVersion
4.225.654.443
VarFileInfo
Translation
Antivirus Signature
Bkav W32.AIDetectMalware
Lionic Trojan.Win32.Generic.4!c
tehtris Clean
MicroWorld-eScan Gen:Variant.Jaik.160622
ClamAV Clean
CMC Clean
CAT-QuickHeal Clean
ALYac Clean
Malwarebytes Malware.AI.3909006447
Zillya Clean
Sangfor Trojan.Win32.Save.a
K7AntiVirus Clean
BitDefender Gen:Variant.Jaik.160622
K7GW Clean
Cybereason malicious.7a9d8b
Baidu Clean
VirIT Clean
Cyren W32/Kryptik.KIQ.gen!Eldorado
Symantec ML.Attribute.HighConfidence
Elastic malicious (high confidence)
ESET-NOD32 a variant of Win32/GenKryptik.GHTO
APEX Malicious
Paloalto Clean
Cynet Malicious (score: 100)
Kaspersky UDS:DangerousObject.Multi.Generic
Alibaba Trojan:Win32/GenKryptik.8ffa9f69
NANO-Antivirus Clean
ViRobot Trojan.Win.Z.Genkryptik.549888
Rising Trojan.Kryptik!8.8 (TFE:5:iHaF5L8XsUE)
TACHYON Clean
Sophos Mal/Generic-S
F-Secure Trojan.TR/Crypt.XPACK.Gen5
DrWeb Clean
VIPRE Clean
TrendMicro TrojanSpy.Win32.VIDAR.YXDHHZ
McAfee-GW-Edition BehavesLike.Win32.Generic.hh
Trapmine malicious.high.ml.score
FireEye Generic.mg.5c3d28d428bb30d5
Emsisoft Gen:Variant.Jaik.160622 (B)
Ikarus Trojan.Agent
GData Gen:Variant.Jaik.160622
Jiangmin Clean
Webroot Clean
Avira TR/Crypt.XPACK.Gen5
Antiy-AVL Clean
Gridinsoft Clean
Xcitium Clean
Arcabit Clean
SUPERAntiSpyware Clean
ZoneAlarm UDS:DangerousObject.Multi.Generic
Microsoft Trojan:Win32/RedLineStealer.M!MTB
Google Detected
AhnLab-V3 Trojan/Win.Generic.C5467856
Acronis Clean
McAfee Artemis!5C3D28D428BB
MAX malware (ai score=89)
DeepInstinct MALICIOUS
VBA32 Clean
Cylance unsafe
Panda Trj/Genetic.gen
Zoner Clean
TrendMicro-HouseCall Clean
Tencent Win32.Trojan.Crypt.Azlw
Yandex Clean
SentinelOne Static AI - Malicious PE
MaxSecure Clean
Fortinet W32/GenKryptik.GHTO!tr
BitDefenderTheta Gen:NN.ZexaF.36348.Hq0@aeXczMei
AVG Win32:CrypterX-gen [Trj]
Avast Win32:CrypterX-gen [Trj]
CrowdStrike win/malicious_confidence_100% (W)
No IRMA results available.