Static | ZeroBOX

PE Compile Time

2022-05-13 19:51:31

PDB Path

C:\zoh.pdb

PE Imphash

046dfae6c2280fbc36820b8f28604732

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x0003e568 0x0003e600 7.83373129766
.data 0x00040000 0x001761fc 0x00001e00 2.45315924395
.rsrc 0x001b7000 0x000056e8 0x00005800 4.33307257412
.reloc 0x001bd000 0x000028fe 0x00002a00 2.55908732559

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x001bbf90 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x001bbf90 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x001bbf90 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x001bbf90 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x001bbf90 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ACCELERATOR 0x001bc448 0x00000028 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_GROUP_ICON 0x001bc3f8 0x0000004c LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_VERSION 0x001bc470 0x00000274 LANG_ENGLISH SUBLANG_ENGLISH_US data

Imports

Library KERNEL32.dll:
0x401010 AddConsoleAliasW
0x401014 _lclose
0x401018 GetTickCount
0x40101c GetNumberFormatA
0x401028 GlobalAlloc
0x40102c LoadLibraryW
0x401038 GetFileAttributesW
0x401040 CreateActCtxA
0x401044 GetACP
0x40104c SetLastError
0x401054 GetProcAddress
0x401058 VirtualAlloc
0x401060 RemoveDirectoryA
0x401068 SetComputerNameA
0x40106c _hwrite
0x401070 LoadResource
0x401074 AddAtomW
0x40107c GetCommMask
0x401080 FoldStringA
0x401084 GlobalFindAtomW
0x401088 OpenFileMappingW
0x401090 FindNextFileW
0x401094 VirtualProtect
0x401098 PeekConsoleInputA
0x40109c EndUpdateResourceA
0x4010a0 ReadConsoleInputW
0x4010a4 TerminateJobObject
0x4010a8 GetCurrentProcessId
0x4010ac LocalFree
0x4010b0 FindNextVolumeA
0x4010b4 GetProcessHeap
0x4010b8 SetEndOfFile
0x4010bc FlushFileBuffers
0x4010c0 PeekNamedPipe
0x4010c4 CreateHardLinkW
0x4010c8 WriteConsoleW
0x4010cc GetConsoleOutputCP
0x4010d8 MultiByteToWideChar
0x4010dc GetModuleHandleW
0x4010e0 Sleep
0x4010e4 ExitProcess
0x4010e8 GetCommandLineA
0x4010ec GetStartupInfoA
0x4010f0 GetLastError
0x4010f4 WriteFile
0x4010f8 GetStdHandle
0x4010fc GetModuleFileNameA
0x401100 TerminateProcess
0x401104 GetCurrentProcess
0x401108 IsDebuggerPresent
0x40110c HeapAlloc
0x401110 HeapFree
0x401114 RaiseException
0x401118 GetCPInfo
0x401124 GetOEMCP
0x401128 IsValidCodePage
0x40112c TlsGetValue
0x401130 TlsAlloc
0x401134 TlsSetValue
0x401138 TlsFree
0x40113c GetCurrentThreadId
0x401140 HeapSize
0x40114c RtlUnwind
0x401150 ReadFile
0x401158 LoadLibraryA
0x401168 WideCharToMultiByte
0x401170 SetHandleCount
0x401174 GetFileType
0x401178 HeapCreate
0x40117c VirtualFree
0x401188 SetFilePointer
0x40118c GetConsoleCP
0x401190 GetConsoleMode
0x401194 HeapReAlloc
0x401198 GetModuleHandleA
0x40119c LCMapStringA
0x4011a0 LCMapStringW
0x4011a4 GetStringTypeA
0x4011a8 GetStringTypeW
0x4011ac GetLocaleInfoA
0x4011b0 CloseHandle
0x4011b4 CreateFileA
0x4011b8 SetStdHandle
0x4011bc WriteConsoleA
Library USER32.dll:
0x4011c8 CharToOemBuffA
0x4011cc PostMessageW
0x4011d4 LoadMenuW
Library GDI32.dll:
0x401004 GetPolyFillMode
Library ole32.dll:
0x4011dc CoMarshalHresult

!This program cannot be run in DOS mode.
=RichK
`.data
@.reloc
bad allocation
?CorExitProcess
runtime error
TLOSS error
SING error
DOMAIN error
An application has made an attempt to load the C runtime library incorrectly.
Please contact the application's support team for more information.
- Attempt to use MSIL code from this assembly during native code initialization
This indicates a bug in your application. It is most likely the result of calling an MSIL-compiled (/clr) function from a native constructor or from DllMain.
- not enough space for locale information
- Attempt to initialize the CRT more than once.
This indicates a bug in your application.
- CRT not initialized
- unable to initialize heap
- not enough space for lowio initialization
- not enough space for stdio initialization
- pure virtual function call
- not enough space for _onexit/atexit table
- unable to open console device
- unexpected heap error
- unexpected multithread lock error
- not enough space for thread data
This application has requested the Runtime to terminate it in an unusual way.
Please contact the application's support team for more information.
- not enough space for environment
- not enough space for arguments
- floating point support not loaded
Microsoft Visual C++ Runtime Library
<program name unknown>
Runtime Error!
Program:
(null)
`h````
xpxxxx
_nextafter
_hypot
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
EncodePointer
DecodePointer
FlsFree
FlsSetValue
FlsGetValue
FlsAlloc
UTF-16LE
UNICODE
GetProcessWindowStation
GetUserObjectInformationA
GetLastActivePopup
GetActiveWindow
MessageBoxA
USER32.DLL
`h`hhh
xppwpp
GAIsProcessorFeaturePresent
KERNEL32
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
HH:mm:ss
dddd, MMMM dd, yyyy
MM/dd/yy
December
November
October
September
August
February
January
Saturday
Friday
Thursday
Wednesday
Tuesday
Monday
Sunday
Complete Object Locator'
Class Hierarchy Descriptor'
Base Class Array'
Base Class Descriptor at (
Type Descriptor'
`local static thread guard'
`managed vector copy constructor iterator'
`vector vbase copy constructor iterator'
`vector copy constructor iterator'
`dynamic atexit destructor for '
`dynamic initializer for '
`eh vector vbase copy constructor iterator'
`eh vector copy constructor iterator'
`managed vector destructor iterator'
`managed vector constructor iterator'
`placement delete[] closure'
`placement delete closure'
`omni callsig'
delete[]
new[]
`local vftable constructor closure'
`local vftable'
`udt returning'
`copy constructor closure'
`eh vector vbase constructor iterator'
`eh vector destructor iterator'
`eh vector constructor iterator'
`virtual displacement map'
`vector vbase constructor iterator'
`vector destructor iterator'
`vector constructor iterator'
`scalar deleting destructor'
`default constructor closure'
`vector deleting destructor'
`vbase destructor'
`string'
`local static guard'
`typeof'
`vcall'
`vbtable'
`vftable'
operator
delete
__unaligned
__restrict
__ptr64
__clrcall
__fastcall
__thiscall
__stdcall
__pascal
__cdecl
__based(
SunMonTueWedThuFriSat
JanFebMarAprMayJunJulAugSepOctNovDec
CONOUT$
1#QNAN
1#SNAN
bad allocation
kotevajewodopo
vulefuxolasilaluhikagesayonuwad
C:\zoh.pdb
jlXjmf
PVVhh-@
PVVVVV
|*SSQVj
0SSSSS
0A@@Ju
teh`e@
<at9<rt,<wt
URPQQh
0WWWWW
>=Yt1j
j@j ^V
0SSSSS
0SSSSS
_VVVVV
^WWWWW
t"SS9]
PPPPPPPP
PPPPPPPP
tGHt.Ht&
^SSSSS
8VVVVV
;t$,v-
UQPXY]Y[
0SSSSS
_VVVVV
t+WWVPV
<+t(<-t$:
+t HHt
MS3?Dj
CG<3 V
F7?{_z
(7Ln)st
\P_r{v
#Q~}kS{
d"iiOAR
Z=26PX
Y75F
Xf( %?
f20MztY
LZH`^+
zn}ytw
"K&cZx
hMjE_]
?rO#-3=
kGrrvr
SF$,AG
ly5D+T
~;(k+f
-e#FJJ
^g7Y"ht
;C!$wG
'ilKA
K.)Wm_N
Fd;j6C
pc3+!B
Ir/g~c
'`+EvZ
ovit=r
].c;u,6
a8F<jy
*l*+V
'"TS4F
*=YxN
d?5 bc6>T
flQo"-!0
:_0wi-
~]`@"n-
lW)d:%
[VeipA
I{Y2ci
xP@1`I
b}LUT|
\v&wN|j
{UI:-.g
W+2Z lc
Gxov{z
eSi#7G#
&hShbI"
aHCpLP
5JP;\B:w
eZ9R>Y
"hEChy
$W&]!Ds4
$.42M#
2ounTN
Ol6J}i
Cw{B4S
`}XO((
tVxW^a
;`5ZWa
>f/<+@(
jH[cV\R
yk8]:TU!
mv\MLTJ
*Qdf9}1
v.3 }X
%n({KK
HL^/mp!
x)IwfFP
[1-Hqd$
:Ru)u*
fQdJwV
YLd./xm
B|_a@%
ea+(pM
NPW&tfw
b57^u66
:q*+'
*k#\t1j*
D^qE 2
zMw4-{z
k)kF@/
5s1Fdy
t6+~KA
y\>-dp!
[|vK'D
hT|(lw
09i<Go
"=K$EO
FFj;%Ci
^m0h^1
zLP]hw7
y)&h;?
{ALx3K
C^R+1hB
8w\SS0MD
"ElJEU
wb[r>D9
k-`7%e
+(xQi#
+fi>L2rH9J
8=J%M(
#Qn8E!#ML
.,4-0DT
hF9x6@
o`?$&9
J,Ulf1
OBzJY]1
Gp'*kY
rG7#O)@*
#;eoS
=D9Af2R
@)i%?uZ
M6&==H{6
zBU0Tg2V0h\
;jS,V<+
Zmn-wB
:J0[yJ
(V5cEO
g8ht W
AEk;u98P
Wqs eA
~a(Q*EU
z<6gW}
SEQ[$Q
!4c'F(
y_o<Up
E<2mVtp
;ottxfz
6AWA/P
TK4}8*
v*M/h@
*qzNOd1{
nPA~g]
oBvgpl
#fZP7;
yEPTyZ3
Z>[A55
;VYQ5)*[
u9+lB5
/]S;J;
z<{A*C#
|pn^RD
kYm 9|
BC&:ix
bT\[Kw8
87%.7[
m83y7
$3P&._
CDa)I;
$MD/pK
&Jz!ePx
O(I'#x
M~.O|wl
G)89HI
@Td>uPf
AlsZd^
12T4dU
8VQ1I:
E V%q%m
k~s7Db
hL5XO@?
8*+&";
sk7&W;
=@jXfF2
5]1=p1
7);s)e
yw&]u@+
~9]LX<
`it*;?
1Vbp#V
04]SgZT
Bj$EXl
M_||mo
#]&pD\
_~.tJq
o\;dNV
lC"x#r~
rZfx-P
,Yh}!m^V
tNtIAD
Y)EfFm
~fa*4KxG
>**h;
A0+xV^
LPnW)x[
JYI~CP
Na(@#Y
=Kd(_7
l`4[gWsK
1b3c:tT
IZ,:~%
z-_2NH
?'KjtWBy
j0?f#7
gQ&=LaJE
rsi~fa+`
eO-Y~
OuNqgi
uk S^M
w#\EJS
~J}2:"
8.wb5(
~qJi|6
L_nw0]W
-L|Ws9*
^dpkh
'b1/R~
Hnb0qv
t*7"2j
Wk#<g
eBqUOy&w
M\}7NZ
^$@Z5D
J"8u i&Y
ba62!|
k1YvGb[c
h08Iq|>
(kr/XK
o(A;}>
O]37mo1
HYOx>g'
t=P_n4
)Xd/K<
$!Q0\2
{Ny=M{
1frUmV
b_g`v$
>E)&;`
69,T,g#>
HL$06V
sy>,x
SdRbzy
oCV4` CX
"3U$u1
ab@VL1a
q}U]AkW
*vAvHz
v-!IP/
9|A^:tL
VHFV"j
nmIIENu
j7gq/f
DN#*Cv
;&8pOE"
QI>H2Clg
+_O+kwo
GOJl>Jc
j>fp40
y!Z[6/
(-/?;?
SFj{;J
yo5HDm5
obg4TG
R<U1pVw7
U(L'?7
NkevWM
,X-4n&
-V4*5v
$NlRj{B< *
8MK'ds{
S*v)^3c
N$X&xe>P
,$R\].
"w~Jg0n
_#H'T2
uDw* .S
KGlw8(
tF@WJV
)td[I.pk-
i5&tP/!mtM
C!jybK
^&L>6L
qGo:'S
: Y\"N
fjK<;x
-O/pgC71
z$[7N7
cn Rl#
g-e0i$
Y]2tel
w1iHmu
zwM.r?
kBXQ G
N RdG]<
JPE;z
TE]P_jE
'p?Mj-
_D-YmK
L"Kyl%&
Du"jp7
'0/ v73>L
QEBes7j
<}/dSls
\l7\bP
{@`&+l!
%Kp^D$
Y 4#3o
aQ6U-niK
^Z4:jx
4&wr$<
`YJk71
S;=C:][d
Bjo]w;r9
?_^[|q(
I"O6VE
R]f7-c
Wl~2c$a
]Nlv$K.lL
}C/@z|
PeekNamedPipe
LoadResource
InterlockedCompareExchange
AddConsoleAliasW
_lclose
GetTickCount
GetNumberFormatA
GetWindowsDirectoryA
SetProcessPriorityBoost
GlobalAlloc
LoadLibraryW
SetVolumeMountPointA
GetSystemWindowsDirectoryA
GetFileAttributesW
GetCompressedFileSizeA
CreateActCtxA
GetACP
FillConsoleOutputCharacterW
SetLastError
ReadConsoleOutputCharacterA
GetProcAddress
VirtualAlloc
BeginUpdateResourceW
RemoveDirectoryA
EnumSystemCodePagesW
SetComputerNameA
_hwrite
CreateHardLinkW
AddAtomW
BeginUpdateResourceA
GetCommMask
FoldStringA
GlobalFindAtomW
OpenFileMappingW
FreeEnvironmentStringsW
FindNextFileW
VirtualProtect
PeekConsoleInputA
EndUpdateResourceA
ReadConsoleInputW
TerminateJobObject
GetCurrentProcessId
LocalFree
FindNextVolumeA
KERNEL32.dll
ChangeDisplaySettingsA
LoadMenuW
GetWindowTextLengthA
PostMessageW
CharToOemBuffA
USER32.dll
GetCharacterPlacementA
GetPolyFillMode
GDI32.dll
CoMarshalHresult
ole32.dll
UnhandledExceptionFilter
SetUnhandledExceptionFilter
MultiByteToWideChar
GetModuleHandleW
ExitProcess
GetCommandLineA
GetStartupInfoA
GetLastError
WriteFile
GetStdHandle
GetModuleFileNameA
TerminateProcess
GetCurrentProcess
IsDebuggerPresent
HeapAlloc
HeapFree
RaiseException
GetCPInfo
InterlockedIncrement
InterlockedDecrement
GetOEMCP
IsValidCodePage
TlsGetValue
TlsAlloc
TlsSetValue
TlsFree
GetCurrentThreadId
HeapSize
EnterCriticalSection
LeaveCriticalSection
RtlUnwind
ReadFile
DeleteCriticalSection
LoadLibraryA
InitializeCriticalSectionAndSpinCount
FreeEnvironmentStringsA
GetEnvironmentStrings
WideCharToMultiByte
GetEnvironmentStringsW
SetHandleCount
GetFileType
HeapCreate
VirtualFree
QueryPerformanceCounter
GetSystemTimeAsFileTime
SetFilePointer
GetConsoleCP
GetConsoleMode
HeapReAlloc
GetModuleHandleA
LCMapStringA
LCMapStringW
GetStringTypeA
GetStringTypeW
GetLocaleInfoA
CloseHandle
CreateFileA
SetStdHandle
WriteConsoleA
GetConsoleOutputCP
WriteConsoleW
FlushFileBuffers
SetEndOfFile
GetProcessHeap
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
-EI3CC$
****************************************************************************************************************************************************************************************************************************************************************************************************************************************************************************************************************
C**************************************
q************************************4
*********************************4
-*******************************G
******************************
6*****************************
c6*****************************
c6*****************************
******************************9
******************************
q*******************************
q*********************************6
*****************************************
*****************************************
*****************************************
*****************************************F
"**********
****************************
**********
q****************************
*********q
q****************************
*******-
q****************************
q****************************
****************************Tyl_
C****************************
*****************************
*****************************
******************************
******************************
"*******************************
"*********************************"*
**************************************
Y****************************************"2
6****************************************
6******************************************
6********************************************
Y6**********************************************************************************************************************************************************************************************************************************************************************
~~{}{{~
{{}|~{|
{|~}|{{}z
~}|z{|
}}{y}~|
}||}~}y
{~}|}{
z}|~||~
~}zy}}|~z
|z{}{|~~}~
~~~}|{
z}z|~zz
}{{{~|
~{~}{~~
{~{~|y
z{}}zy
}}z~}{
z}|}{~z
~~{}~|}
~|}zz~~
~|~y||
}z{||~
;$;(;,;0;4;8;<;@;D;H;L;P;T;X;\;`;d;h;l;p;t;x;|;
< <$<(<,<0<4<8<<<@<D<H<L<P<T<X<\<`<d<h<l<p<t<x<|<
?!?O?]?b?h?q?y?~?
0)060G0\0r0
1&1>1]1d1o1v1~1
22+22292>2
3!3-323H3Q3[3
4!4&484G4O4y4~4
:@:E:\:
>$?/?R?[?
:0B0U0`0e0u0
3Q3V3`3
5,656;6
7"7-7Q7Z7a7j7
7!848L8^8
:5:X:k:
022M2c2y2
6.6@6f6s6
7#7'7-717J7\7
;#;W;b;l;
>&>9>K>f>n>v>
?>?O?r?
3343;3O3V3n3z3
4!4(454X4m4
5%5=5c5
7$7(7.73797>7M7c7n7s7~7
;D;M;Y;
;;<A<a<~<
=;>M>g>v>
?'?1?W?
2*3:3g3o3
6y819;9
?%?+?4?G?k?
0 0+000Q0V0{081=1O1m1
2W3f3u3~3
3U4[4j4w4
5d5o5y5
5H7Y7a7g7l7r7
8(858<8s8
9 9.9B9c9i9
9::D:l:
<4<<<.=
>O>h>o>w>|>
?^?d?h?l?p?
22_2|2
4>4D4J4P4V4\4c4j4q4x4
5+525|5
262<2G2L2T2Z2d2k2
4)5/585?5z5
=!=C=U=g=y=
041:1^1
2"2C2O2v2
7!737s7
; ;7;\;s;(<
171@1o1
88%8;8V8
9/:H:O:W:\:`:d:
:>;D;H;L;P;
<;<m<t<x<|<
; <-<M<y<N=h=n=s=y=
2e3[4c4
697?7O7
0!000\0
6(6D6H6h6
707P7p7
8 8@8`8|8
9 9@9`9l9
:0:L:P:
0$0,040<0D0L0T0\0d0l0t0|0
3$3,343<3D3L3T3\3d3l3
8 909@9P9`9
98=`>d>h>l>p>t>x>|>
? ?$?(?,?0?4?8?<?@?D?H?L?P?T?X?\?`?d?h?l?p?t?x?|?
mscoree.dll
(null)
KERNEL32.DLL
((((( H
h(((( H
H
kernel32.dll
kernel32.dll
VS_VERSION_INFO
StringFileInfo
045230F2
FileDescription
Vangla
LegalCopyright
Copyright (C) 2022, Fdfiugaf
OriginalFilename
golfstikator.exe
ProductsVersion
23.24.5.55
ProductName
Bodalan
ProductionVersion
18.35.93.36
VarFileInfo
Translation
Antivirus Signature
Bkav W32.AIDetectMalware
Lionic Clean
tehtris Clean
DrWeb Clean
MicroWorld-eScan Clean
FireEye Generic.mg.2353ef140fcfb38a
CAT-QuickHeal Clean
ALYac Clean
Malwarebytes MachineLearning/Anomalous.93%
Zillya Clean
Sangfor Trojan.Win32.Save.a
K7AntiVirus Trojan ( 005690671 )
BitDefender Clean
K7GW Trojan ( 005690671 )
CrowdStrike win/malicious_confidence_100% (W)
BitDefenderTheta Clean
Cyren W32/Kryptik.KTY.gen!Eldorado
Symantec ML.Attribute.HighConfidence
Elastic malicious (high confidence)
ESET-NOD32 a variant of Win32/Kryptik.HUWA
APEX Malicious
Paloalto Clean
Cynet Malicious (score: 100)
Kaspersky UDS:Trojan-PSW.Win32.Vidar.gen
Alibaba Clean
NANO-Antivirus Clean
ViRobot Clean
Rising Trojan.Generic@AI.100 (RDML:Duh/RKehZOcrPbqhs2ltrQ)
TACHYON Clean
Emsisoft Clean
F-Secure Clean
Baidu Clean
VIPRE Clean
TrendMicro Clean
McAfee-GW-Edition BehavesLike.Win32.Lockbit.dc
Trapmine malicious.moderate.ml.score
CMC Clean
Sophos ML/PE-A
Ikarus Trojan.Win32.Crypt
Jiangmin Clean
Webroot Clean
Avira Clean
Antiy-AVL Clean
Kingsoft malware.kb.a.1000
Gridinsoft Ransom.Win32.STOP.bot!n
Xcitium Clean
Arcabit Clean
SUPERAntiSpyware Clean
ZoneAlarm UDS:Trojan-PSW.Win32.Vidar.gen
GData Clean
Google Detected
AhnLab-V3 Clean
Acronis Clean
VBA32 Clean
MAX Clean
DeepInstinct MALICIOUS
Cylance unsafe
Panda Trj/Genetic.gen
Zoner Clean
TrendMicro-HouseCall Clean
Tencent Trojan.Win32.Obfuscated.gen
Yandex Clean
SentinelOne Static AI - Malicious PE
MaxSecure Clean
Fortinet W32/GenKryptik.ERHN!tr
AVG Win32:TrojanX-gen [Trj]
Cybereason malicious.c0fc37
Avast Win32:TrojanX-gen [Trj]
No IRMA results available.