Static | ZeroBOX

PE Compile Time

2022-08-21 23:03:43

PDB Path

C:\conici\naton.pdb

PE Imphash

dc31d343a87efee8a8c7a88400bab705

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x0002a22e 0x0002a400 7.52513591012
.data 0x0002c000 0x0147c91c 0x00001e00 2.85449769699
.rsrc 0x014a9000 0x00003d10 0x00003e00 4.01209414278
.reloc 0x014ad000 0x00009c18 0x00009e00 0.978384767167

Resources

Name Offset Size Language Sub-language File type
RT_CURSOR 0x014ac488 0x000000b0 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_CURSOR 0x014ac488 0x000000b0 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x014abec0 0x00000468 LANG_PORTUGUESE SUBLANG_PORTUGUESE_BRAZILIAN GLS_BINARY_LSB_FIRST
RT_ICON 0x014abec0 0x00000468 LANG_PORTUGUESE SUBLANG_PORTUGUESE_BRAZILIAN GLS_BINARY_LSB_FIRST
RT_ICON 0x014abec0 0x00000468 LANG_PORTUGUESE SUBLANG_PORTUGUESE_BRAZILIAN GLS_BINARY_LSB_FIRST
RT_STRING 0x014ac7d0 0x00000540 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_GROUP_CURSOR 0x014ac538 0x00000022 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_GROUP_ICON 0x014ac328 0x00000030 LANG_PORTUGUESE SUBLANG_PORTUGUESE_BRAZILIAN data
RT_VERSION 0x014ac560 0x00000270 LANG_NEUTRAL SUBLANG_NEUTRAL data

Imports

Library KERNEL32.dll:
0x401000 GetComputerNameA
0x401004 SetFilePointer
0x40100c LoadResource
0x401010 UpdateResourceA
0x401018 GetProfileStringW
0x401020 WriteConsoleInputA
0x401024 GetModuleHandleW
0x40102c GetDateFormatA
0x401030 CreateActCtxW
0x401034 SetCommConfig
0x401038 FormatMessageW
0x40103c GetVolumePathNameA
0x401040 GetConsoleAliasesW
0x401044 GetLastError
0x401048 SetLastError
0x40104c GetProcAddress
0x401050 VirtualAlloc
0x401054 HeapUnlock
0x401058 LoadLibraryA
0x401064 Module32FirstW
0x401068 FoldStringW
0x40106c GetModuleFileNameA
0x401070 FindNextFileA
0x40107c FindNextFileW
0x401080 WriteProfileStringW
0x401084 GetCurrentThreadId
0x401088 ReadConsoleInputW
0x40108c TlsAlloc
0x401090 AreFileApisANSI
0x401094 CloseHandle
0x401098 CreateFileA
0x40109c TerminateProcess
0x4010a0 GetCurrentProcess
0x4010ac IsDebuggerPresent
0x4010b0 Sleep
0x4010b4 ExitProcess
0x4010b8 GetStartupInfoW
0x4010bc RaiseException
0x4010c0 RtlUnwind
0x4010c4 GetCPInfo
0x4010cc GetACP
0x4010d0 GetOEMCP
0x4010d4 IsValidCodePage
0x4010d8 TlsGetValue
0x4010dc TlsSetValue
0x4010e0 TlsFree
0x4010e4 HeapAlloc
0x4010e8 HeapFree
0x4010ec WriteFile
0x4010f0 WideCharToMultiByte
0x4010f4 GetConsoleCP
0x4010f8 GetConsoleMode
0x4010fc FlushFileBuffers
0x40110c GetStdHandle
0x401114 GetModuleFileNameW
0x401120 GetCommandLineW
0x401124 SetHandleCount
0x401128 GetFileType
0x40112c GetStartupInfoA
0x401130 HeapCreate
0x401134 VirtualFree
0x40113c GetTickCount
0x401140 GetCurrentProcessId
0x401148 LCMapStringA
0x40114c MultiByteToWideChar
0x401150 LCMapStringW
0x401154 GetStringTypeA
0x401158 GetStringTypeW
0x40115c GetLocaleInfoA
0x401160 HeapReAlloc
0x401164 WriteConsoleA
0x401168 GetConsoleOutputCP
0x40116c WriteConsoleW
0x401170 SetStdHandle
0x401174 GetModuleHandleA
0x401178 HeapSize
Library USER32.dll:
0x401180 CharUpperBuffW
0x401184 LoadMenuA
0x401188 CharLowerBuffW
0x401190 CharToOemBuffA

!This program cannot be run in DOS mode.
`.data
@.reloc
bad allocation
Unknown exception
CorExitProcess
bad exception
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
EncodePointer
DecodePointer
FlsFree
FlsSetValue
FlsGetValue
FlsAlloc
(null)
`h````
xpxxxx
RUUUUU
runtime error
TLOSS error
SING error
DOMAIN error
An application has made an attempt to load the C runtime library incorrectly.
Please contact the application's support team for more information.
- Attempt to use MSIL code from this assembly during native code initialization
This indicates a bug in your application. It is most likely the result of calling an MSIL-compiled (/clr) function from a native constructor or from DllMain.
- not enough space for locale information
- Attempt to initialize the CRT more than once.
This indicates a bug in your application.
- CRT not initialized
- unable to initialize heap
- not enough space for lowio initialization
- not enough space for stdio initialization
- pure virtual function call
- not enough space for _onexit/atexit table
- unable to open console device
- unexpected heap error
- unexpected multithread lock error
- not enough space for thread data
This application has requested the Runtime to terminate it in an unusual way.
Please contact the application's support team for more information.
- not enough space for environment
- not enough space for arguments
- floating point support not loaded
Microsoft Visual C++ Runtime Library
<program name unknown>
Runtime Error!
Program:
?uZEeu
?uZEeu
?UUUUUU
?UUUUUU
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
HH:mm:ss
dddd, MMMM dd, yyyy
MM/dd/yy
December
November
October
September
August
February
January
Saturday
Friday
Thursday
Wednesday
Tuesday
Monday
Sunday
GAIsProcessorFeaturePresent
KERNEL32
`h`hhh
xppwpp
i^^?(>
Y:/(A6>
< Complete Object Locator'
Class Hierarchy Descriptor'
Base Class Array'
Base Class Descriptor at (
Type Descriptor'
`local static thread guard'
`managed vector copy constructor iterator'
`vector vbase copy constructor iterator'
`vector copy constructor iterator'
`dynamic atexit destructor for '
`dynamic initializer for '
`eh vector vbase copy constructor iterator'
`eh vector copy constructor iterator'
`managed vector destructor iterator'
`managed vector constructor iterator'
`placement delete[] closure'
`placement delete closure'
`omni callsig'
delete[]
new[]
`local vftable constructor closure'
`local vftable'
`udt returning'
`copy constructor closure'
`eh vector vbase constructor iterator'
`eh vector destructor iterator'
`eh vector constructor iterator'
`virtual displacement map'
`vector vbase constructor iterator'
`vector destructor iterator'
`vector constructor iterator'
`scalar deleting destructor'
`default constructor closure'
`vector deleting destructor'
`vbase destructor'
`string'
`local static guard'
`typeof'
`vcall'
`vbtable'
`vftable'
operator
delete
__unaligned
__restrict
__ptr64
__clrcall
__fastcall
__thiscall
__stdcall
__pascal
__cdecl
__based(
GetProcessWindowStation
GetUserObjectInformationA
GetLastActivePopup
GetActiveWindow
MessageBoxA
USER32.DLL
SunMonTueWedThuFriSat
JanFebMarAprMayJunJulAugSepOctNovDec
CONOUT$
_nextafter
_hypot
1#QNAN
1#SNAN
bad allocation
RSDS(|x
C:\conici\naton.pdb
SSSSSS
/SVWuV3
9u&VVV
j8Vh0P@
0WWWWW
QQSVWd
HtHu4j
s[S;7|G;w
tR99u2
0A@@Ju
<+t(<-t$:
+t HHt
0SSSSS
HHtXHHt
>If90t
f-00f=
>=Yt1j
QQSVWh
j@j ^V
t"SS9]
0SSSSS
PPPPPPPP
0SSSSS
PPPPPPPP
URPQQh
_VVVVV
^WWWWW
tRHtCHt4Ht%HtFHHt
^SSSSS
j"^SSSSS
tNIt?It0It
0WWWWW
AAFFf;
;t$,v-
UQPXY]Y[
t+WWVPV
0SSSSS
_VVVVV
zp;R/&
ojw#_TM
KcBUKv?I
9XZp%Z
@vjdo~Q
S_wo5>u5rY
JI8uP~
3WvXRB
lR G&-r
v(`S#n
gEargF`
hV&R0$&lG2T
~z$zfq/~9EZ
L0c;xon
@)3[wH
4w!Q5
m_b[tnl
_YzJS9$
)dUcSs`
AVc|2
;wu~O3
&Lu!-w
me&:%d
CR^&M)
Gs[0^{
KX[[6{
HOe)1p
J8axqA
P5LRO(M
MU$RL^t
{28\'cX[
p]ddI
sNhHQZ
aMjvR[
FUdsvAD
9FN;+~
xs+mD#
Ap!,e&
VR,lqh#
W%/Cn2;,B
|@d$j
V+v<N?
i/tRuB
`A54C(
-AsR{[P&
u*}0Ix{
5]67-}
FWk,:1
Zm";QI
xsnkc}
i-Y=^4b
]"l('a
8m%.<3
c<bL0v1
-5Nv8G
/AI<o\4
y'8U%!
Lck4+W
h}iT *=0
VFx+<b
~n\Q7{
'$;xb{
43dl5H
h%&}1M'A
4~)9x6{
<"92kFl3
A`UtDw
qn9]vp
@'t!O9
|mzI|A
vI1)B7
dj0b^w
W;Y"7^
|Y<tJ6
|pbCAT
)R=|VVs
aF_W5;
T]6Ar?
+Be~QT
Qv%lkR
53~yu=
}@?K]:_
ArO3j8
ULt`~[
z|COS#
7Y|n?z
tFXE$~f
xpBrh
FZBap.
|d%l+0%
N4P)}?
IyLquj
?@uswXI/X
{7nfT574
cy:g@S
rvz6}.
_u7|tU
|M9}DD
btcoDL:
9D#|\c
1vmEsX
`ZE)QZ
VAh?3_a
brs92Q
_:\Qnp
b/.'A]
3_$g`5
^.L)}o
h5N231
Oog7k4eD
/Qk|4m\
`eUDu;
)9KMJ@
$P /!e
*O|`6<B
^$M5OR
Ca83|(
U3vGhr
8Ffr#6d
/N9c7,
\x[5.q
<Gp6"=
$xb%Q6M
[K'Ix~h,
WY7\2S
)ZW:<4
c7'fD-x4
lxQ7,o>
.\4{=>Ut
lt#D1(
nue(>~|;z
j=x)F$)
A2`geZ
Up_>rff
'Q4U(I
em8o;~]r
'7@4$7
vE!@Mzj
vB7hiC
mt*'`\
# b.:.
DL}s-f
lP$abD
o3AC6l
^]S`J;
AwV'JB
>`}o^|
GetComputerNameA
SetFilePointer
DebugActiveProcessStop
LoadResource
UpdateResourceA
InterlockedDecrement
GetProfileStringW
InterlockedCompareExchange
WriteConsoleInputA
GetModuleHandleW
GetConsoleAliasesLengthA
GetDateFormatA
CreateActCtxW
SetCommConfig
FormatMessageW
GetVolumePathNameA
GetConsoleAliasesW
GetLastError
SetLastError
GetProcAddress
VirtualAlloc
HeapUnlock
LoadLibraryA
SetConsoleCtrlHandler
SetConsoleDisplayMode
Module32FirstW
FoldStringW
GetModuleFileNameA
FindNextFileA
FindFirstChangeNotificationA
CancelTimerQueueTimer
FindNextFileW
WriteProfileStringW
GetCurrentThreadId
ReadConsoleInputW
TlsAlloc
AreFileApisANSI
KERNEL32.dll
CreateAcceleratorTableW
CharLowerBuffW
LoadMenuA
CharUpperBuffW
CharToOemBuffA
USER32.dll
TerminateProcess
GetCurrentProcess
UnhandledExceptionFilter
SetUnhandledExceptionFilter
IsDebuggerPresent
ExitProcess
GetStartupInfoW
RaiseException
RtlUnwind
GetCPInfo
InterlockedIncrement
GetACP
GetOEMCP
IsValidCodePage
TlsGetValue
TlsSetValue
TlsFree
HeapAlloc
HeapFree
WriteFile
WideCharToMultiByte
GetConsoleCP
GetConsoleMode
FlushFileBuffers
DeleteCriticalSection
LeaveCriticalSection
EnterCriticalSection
GetStdHandle
InitializeCriticalSectionAndSpinCount
GetModuleFileNameW
FreeEnvironmentStringsW
GetEnvironmentStringsW
GetCommandLineW
SetHandleCount
GetFileType
GetStartupInfoA
HeapCreate
VirtualFree
QueryPerformanceCounter
GetTickCount
GetCurrentProcessId
GetSystemTimeAsFileTime
LCMapStringA
MultiByteToWideChar
LCMapStringW
GetStringTypeA
GetStringTypeW
GetLocaleInfoA
HeapReAlloc
WriteConsoleA
GetConsoleOutputCP
WriteConsoleW
SetStdHandle
GetModuleHandleA
HeapSize
CreateFileA
CloseHandle
.?AVtype_info@@
.?AVbad_exception@std@@
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
.?AVexception@std@@
.?AVbad_alloc@std@@
}|{{{~
{y}|z{|
||~}{}
{y||~z~|{
}~{{y|
}||}{z
}|zz}{
||y~||~~
~}}~}}|
~~z|||
~z|}}}
y~|}|{|
{y}|~{
||~{}{
{{{}}}~z
2 282<2
= =$=(=,=0=4=8=<=@=D=H=L=P=T=X=\=`=d=h=l=p=t=x=|=
> >$>(>,>0>4>8><>@>D>H>L>P>T>X>\>`>d>h>l>p>t>x>|>
1(1,141L1\1`1p1t1x1
2b23393@3G3N3U3\3c3j3q3x3
4)4?4J4W4h4}4
4I5O5k5z5
6!6'616s6|6
777?7F7N7o7~7
7!858I8h8m8
2.292\2
2G3Y3+454B4]4d4|4
5Y6c6u6
9B:J:]:h:m:}:
<9=G=Y=d=
>+>@>e>y>
0L1d1i1
4%4/4H4R4e4
7)71797P7i7
;J;P;[;g;|;
<1<=<C<O<^<d<m<y<
?W?^?y?~?
0&01060A0F0Q0V0c0q0w0
0[1Q2Y2
4/555E5
:);@;p;
/23272;2?2C2G2K2O2S2W2[2
3C3a3h3l3p3t3x3|3
3F4Q4l4s4x4|4
5 5j5p5t5x5|5
7#7C7z7
758;8L8b8
3383L3R3[3n3
3'4G4O4U4o4~4
5/595_5
6"6r6L7T7l7
9a:q:}:
7*828F8P8n8z8
9$909d9n9v9
:T:c:k:q:
:+;,<<<M<U<e<v<
=?=X=_=g=l=p=t=
>N>T>X>\>`>
?!?K?}?
3M4m4r4_5
566;6c6
11q1|1
33$3*3
44@4F4x4
5!5I5b5
576=6s6x6
8"8-898>8N8S8Y8_8u8|8
>$?-?9?r?{?
C1U1g1
7G9U9[9u9z9
:":':/:5:?:F:Z:a:g:u:|:
2$292@2F2\2w2
4'5V5>6N6i6
88F8S8X8f8
6$6T6H7y8
=C=L=U=b=
>@>D>H>L>P>T>X>\>`>d>h>l>p>
?!?&?0?>?~?
'1B1X1n1v1
3+3Q3^3l3
8878`8
8d9?:W:f:
282D2`2
3 3(3,3H3P3T3l3p3
4,40484@4H4L4T4h4
585X5x5
686T6X6x6
74787X7x7
8$8,848@8`8l8
0 0$0(0,0004080<0@0D0H0L0P0T0X0\0h0l0
5P6`6p6
="=&=*=.=2=6=:=>=B=F=J=N=R=V=Z=^=b=f=j=n=r=v=z=~=
>$>,>4><>D>L>T>\>d>l>t>|>
>0?4?8?<?@?D?H?L?P?T?X?\?`?d?h?l?p?t?x?|?
4$4,444<4D4L4T4\4d4l4t4|4
mscoree.dll
KERNEL32.DLL
(null)
((((( H
h(((( H
H
kernel32.dll
kernel32.dll
VS_VERSION_INFO
StringFileInfo
042831F2
FileDescription
Pedemption
LegalCopyright
Copyright (C) 2023, always
OriginalFilename
bigthing.exe
ProductsVersion
5.12.5.4
ProductName
Failured
ProductionVersion
46.18.23.37
VarFileInfo
Translation
NesisatuhafuziLXixoboro seracegeyi rahaley yutuk fonu rane sapabuyayaki guji womepi zuyatohbMivipohujuv xironuxutexa misakasapihijad palekivegutah regefamodof topimegego maleyekop bibeho kic
Varoh zegupib balon suzabefazitoVLiyilowiku tuyupoxaho lika kefafefaxineli dolicijekezufam hocopehov hewuka tutayesoyaw
Fugul zikikopefa dipehaxudeju
Loteha lubemezog tumihofisiret
Nutus hivocim wawagufeyexavo
Cerizi muho mik
Dituhocubibenuh jajuruzMRudoj koj ticibe sozunejuxe latoxowimu kexidom relewupoki lesu pajuyuxanifivo
Bisexi sidedazuxumudat yuvihxTijaxolam kavufoyusecozud yoliya doyiyolasixa tohikajahehabo milekiv nubujipupez tevakayavir huwetulituwen hidukefawugiy
Antivirus Signature
Bkav W32.AIDetectMalware
Lionic Trojan.Win32.Generic.4!c
Elastic malicious (high confidence)
MicroWorld-eScan Clean
ClamAV Win.Packer.pkr_ce1a-9980177-0
FireEye Generic.mg.7cfc2520e8fd8a45
CAT-QuickHeal Ransom.Stop.P5
McAfee Lockbit-FSWW!7CFC2520E8FD
Cylance unsafe
VIPRE Clean
Sangfor Trojan.Win32.Save.a
K7AntiVirus Trojan ( 0056f9be1 )
BitDefender Clean
K7GW Trojan ( 0056f9be1 )
Cybereason Clean
Baidu Clean
VirIT Clean
Cyren W32/Kryptik.KKT.gen!Eldorado
Symantec ML.Attribute.HighConfidence
tehtris Generic.Malware
ESET-NOD32 a variant of Win32/Kryptik.HUJL
APEX Malicious
Paloalto Clean
Cynet Malicious (score: 100)
Kaspersky UDS:DangerousObject.Multi.Generic
Alibaba Clean
NANO-Antivirus Clean
ViRobot Clean
Rising Trojan.Kryptik!1.B663 (CLASSIC)
Sophos Mal/Generic-S
F-Secure Clean
DrWeb Trojan.PWS.Siggen3.32796
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition BehavesLike.Win32.Lockbit.dh
Trapmine malicious.moderate.ml.score
CMC Clean
Emsisoft Clean
Ikarus Worm.Win32.Dorkbot
GData Clean
Jiangmin Clean
Webroot Clean
Avira Clean
MAX Clean
Antiy-AVL Trojan/Win32.Kryptik.hu
Gridinsoft Ransom.Win32.LokiBot.bot
Xcitium Clean
Arcabit Clean
SUPERAntiSpyware Clean
ZoneAlarm UDS:DangerousObject.Multi.Generic
Microsoft Trojan:Win32/Smokeloader.GMB!MTB
Google Detected
AhnLab-V3 Infostealer/Win.RedLine.R479069
Acronis suspicious
BitDefenderTheta Clean
ALYac Clean
TACHYON Clean
DeepInstinct MALICIOUS
VBA32 Clean
Malwarebytes Trojan.MalPack.GS
Panda Trj/Genetic.gen
Zoner Clean
TrendMicro-HouseCall TROJ_GEN.R002H0CHH23
Tencent Trojan.Win32.Obfuscated.gen
Yandex Clean
SentinelOne Static AI - Suspicious PE
MaxSecure Clean
Fortinet W32/GenKryptik.ERHN!tr
AVG Win32:CrypterX-gen [Trj]
Avast Win32:CrypterX-gen [Trj]
CrowdStrike win/malicious_confidence_100% (W)
No IRMA results available.