Static | ZeroBOX

PE Compile Time

2023-03-23 02:52:28

PE Imphash

5241d7444d4d8584697b8889b03f1a00

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x00037cda 0x00037e00 5.62473312056
.data 0x00039000 0x00388524 0x00001a00 2.70763433417
.cepeci 0x003c2000 0x00000400 0x00000400 0.0
.hen 0x003c3000 0x000005dc 0x00000600 0.0
.rsrc 0x003c4000 0x000070d8 0x00007200 3.71048462868

Resources

Name Offset Size Language Sub-language File type
RT_CURSOR 0x003c9b20 0x000008a8 LANG_NEUTRAL SUBLANG_NEUTRAL dBase III DBT, version number 0, next free block index 40, 1st item "\251\317"
RT_CURSOR 0x003c9b20 0x000008a8 LANG_NEUTRAL SUBLANG_NEUTRAL dBase III DBT, version number 0, next free block index 40, 1st item "\251\317"
RT_CURSOR 0x003c9b20 0x000008a8 LANG_NEUTRAL SUBLANG_NEUTRAL dBase III DBT, version number 0, next free block index 40, 1st item "\251\317"
RT_CURSOR 0x003c9b20 0x000008a8 LANG_NEUTRAL SUBLANG_NEUTRAL dBase III DBT, version number 0, next free block index 40, 1st item "\251\317"
RT_CURSOR 0x003c9b20 0x000008a8 LANG_NEUTRAL SUBLANG_NEUTRAL dBase III DBT, version number 0, next free block index 40, 1st item "\251\317"
RT_CURSOR 0x003c9b20 0x000008a8 LANG_NEUTRAL SUBLANG_NEUTRAL dBase III DBT, version number 0, next free block index 40, 1st item "\251\317"
RT_CURSOR 0x003c9b20 0x000008a8 LANG_NEUTRAL SUBLANG_NEUTRAL dBase III DBT, version number 0, next free block index 40, 1st item "\251\317"
RT_CURSOR 0x003c9b20 0x000008a8 LANG_NEUTRAL SUBLANG_NEUTRAL dBase III DBT, version number 0, next free block index 40, 1st item "\251\317"
RT_ICON 0x003c6a38 0x00000988 LANG_SINDHI SUBLANG_SYS_DEFAULT dBase III DBT, version number 0, next free block index 40
RT_ICON 0x003c6a38 0x00000988 LANG_SINDHI SUBLANG_SYS_DEFAULT dBase III DBT, version number 0, next free block index 40
RT_STRING 0x003caf80 0x00000152 LANG_SINDHI SUBLANG_SYS_DEFAULT data
RT_STRING 0x003caf80 0x00000152 LANG_SINDHI SUBLANG_SYS_DEFAULT data
RT_STRING 0x003caf80 0x00000152 LANG_SINDHI SUBLANG_SYS_DEFAULT data
RT_STRING 0x003caf80 0x00000152 LANG_SINDHI SUBLANG_SYS_DEFAULT data
RT_STRING 0x003caf80 0x00000152 LANG_SINDHI SUBLANG_SYS_DEFAULT data
RT_GROUP_CURSOR 0x003c9af0 0x00000030 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_GROUP_CURSOR 0x003c9af0 0x00000030 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_GROUP_CURSOR 0x003c9af0 0x00000030 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_GROUP_CURSOR 0x003c9af0 0x00000030 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_GROUP_ICON 0x003c73c0 0x00000022 LANG_SINDHI SUBLANG_SYS_DEFAULT data
RT_VERSION 0x003ca3e0 0x00000200 LANG_NEUTRAL SUBLANG_NEUTRAL data

Imports

Library KERNEL32.dll:
0x401010 GetLocaleInfoA
0x401014 GetCPInfo
0x401018 FindResourceExW
0x40101c FindResourceW
0x401028 WaitNamedPipeA
0x401034 GetModuleHandleExW
0x401038 SetTapeParameters
0x40103c GetModuleHandleW
0x40104c EnumTimeFormatsA
0x401050 GetCommandLineA
0x401054 GetDriveTypeA
0x40105c LoadLibraryW
0x401060 ReadConsoleInputA
0x401064 CreateEventA
0x401068 SetConsoleCP
0x40106c GetFileAttributesA
0x401070 SetSystemPowerState
0x401074 ReadFile
0x40107c GetStartupInfoW
0x401080 RaiseException
0x401084 GetShortPathNameA
0x401088 GetConsoleAliasesW
0x40108c FindFirstFileA
0x401094 SetLastError
0x401098 PeekConsoleInputW
0x40109c SetVolumeLabelW
0x4010a0 MoveFileW
0x4010a4 CopyFileA
0x4010b0 SetComputerNameA
0x4010b4 VerLanguageNameW
0x4010b8 GetTempFileNameA
0x4010bc FindClose
0x4010c0 LocalAlloc
0x4010c4 CreateHardLinkW
0x4010c8 AddAtomW
0x4010cc RemoveDirectoryW
0x4010d0 HeapLock
0x4010d4 GetCommMask
0x4010d8 FoldStringW
0x4010dc FindNextFileA
0x4010e0 SetConsoleTitleW
0x4010e4 FindNextFileW
0x4010e8 VirtualProtect
0x4010f0 FatalAppExitA
0x4010f4 OpenSemaphoreW
0x401104 EnumSystemLocalesW
0x401108 CommConfigDialogW
0x40110c DeleteFileA
0x401110 CreateFileW
0x401114 WriteConsoleW
0x401118 FlushFileBuffers
0x40111c GetComputerNameA
0x401120 WriteConsoleInputW
0x401124 GetLastError
0x40112c SetStdHandle
0x401130 MoveFileA
0x401134 WideCharToMultiByte
0x401138 HeapAlloc
0x40113c GetProcAddress
0x401140 ExitProcess
0x401144 DecodePointer
0x401148 HeapReAlloc
0x40114c GetCommandLineW
0x401150 HeapSetInformation
0x401160 SetHandleCount
0x401164 GetStdHandle
0x40116c GetFileType
0x40117c IsDebuggerPresent
0x401180 EncodePointer
0x401184 TerminateProcess
0x401188 GetCurrentProcess
0x401194 GetACP
0x401198 GetOEMCP
0x40119c IsValidCodePage
0x4011a0 TlsAlloc
0x4011a4 TlsGetValue
0x4011a8 TlsSetValue
0x4011ac TlsFree
0x4011b0 GetCurrentThreadId
0x4011b4 WriteFile
0x4011b8 GetModuleFileNameW
0x4011bc HeapCreate
0x4011c0 HeapFree
0x4011c4 CloseHandle
0x4011d0 GetTickCount
0x4011d4 GetCurrentProcessId
0x4011dc Sleep
0x4011e0 SetFilePointer
0x4011e4 GetConsoleCP
0x4011e8 GetConsoleMode
0x4011ec RtlUnwind
0x4011f0 LCMapStringW
0x4011f4 MultiByteToWideChar
0x4011f8 GetStringTypeW
0x4011fc HeapSize
Library USER32.dll:
0x40120c CharUpperBuffA
0x401210 CharUpperW
Library GDI32.dll:
0x401008 GetTextFaceA
Library ADVAPI32.dll:
Library SHELL32.dll:
0x401204 DragAcceptFiles

!This program cannot be run in DOS mode.
`.data
.cepeci
CorExitProcess
HH:mm:ss
dddd, MMMM dd, yyyy
MM/dd/yy
December
November
October
September
August
February
January
Saturday
Friday
Thursday
Wednesday
Tuesday
Monday
Sunday
FlsFree
FlsSetValue
FlsGetValue
FlsAlloc
(null)
`h````
xpxxxx
?ZEM-'^
?{yK+;
?765@Z
?e')lW
UUUUUU
333333
?333333
?UUUUUU
?$rxxx
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
GetProcessWindowStation
GetUserObjectInformationW
GetLastActivePopup
GetActiveWindow
MessageBoxW
`h`hhh
xppwpp
_nextafter
_hypot
1#QNAN
1#SNAN
lufuwopojenayijifecuweyosanadel
gucayurefisobapuvaruf
0.1 %f
gobesufad
fohipavekesiw
wipehugelemigexuhafakojimexuf
j@j ^V
uh$ @
^SSSSS
tWItHIt9It
QQSVWh
URPQQh`
t"SS9] u
tRHtCHt4Ht%HtFHHt
PPPPPPPP
PPPPPPPP
;t$,v-
UQPXY]Y[
<+t"<-t
+t HHt
H$|hvV
Nf})oTIZR
o#2$vqJ
TedHY'
"8;pB6
<*?ugO
\YLc:=
c)?MFiF
{YQE1te
)]$u|?KB
MpGQKw}
ng6>oD@k,
D0qB?V
4XT\@-I
]]Tn.j
3=z\e
[}[qm
L#X27`
}j~[vNCl(
Ortnm0
@c%m?6
w~_[g<`
6[Yp`S
wBHXxW9
jKu\zv
Yjwx\`
F=Ko .
F/W\R^Jk
~sdq]G
#60vN
jDtlbZC_D~7
/Xp9Z$
!D@@XCN
aa{ytu
NTEYB}
Q1@eCm
!tjG#
?KWb0;
]$B^8l
$:xfjL
#;12VX
Yszl^:
Ls!QtwC:
eaG&+B
(a,~NC_
$aJ^Ic
U#}r)j)
^@!vS*
C-),40b
:=D]1 i:P
3(u!>.
"&]fR_Co
l,1x\/
~BgK9h-~
U77>Ux
z6tLzc
9KZ`+N
hqz+Z6FN~
3ONJ]iR
#_w`^2
O*GZ8cY
}og0ovg
H1e_E2
a[v#@o
XwEPO9
VSVvs]
'.j4(a
2e~ijpm
YCJJ53
h9"'<HX+
:fM$<7
co&gqQ8
5X^l[ a%P
onwy}L
d$l+??
iI%|YI
10i0I9C
Ks84|#
G[^[+(^
$Lg]bJ<;
<hU$"9
3a%1!o
ba@'eN
S"G($(
dpdNSZR
z/V&OG
wbm;-L~'
\qw4H*
.[!Z*,J
i7S/mO
^0TPH|<
Z8RH`Y'
yPsXMX
.Je?f
8z6%}a
+CTz0w
!#4Z(8
"xr7P'A
qE:=MK
m?ajCd(
rrGS`{A/O
Sfd2Q2%>,*7I25
|X|v-x
ja<4yD5
c")GfEfe8
#p_~)w9
S6SP89
zVjnoSb
0WX,K<
&`6("3
[[4^A%F
Atk7j\Rv
2{bPkl
WD=M:%
mao~Ixkc
KQ*EXZ
/2~h*~
/^Nzr]u
,3Ay~B
|Q!xR
6gMf(
O(M|Huor
Fd5,bg
$`1uIS
*SqG(y
i_|Nj6
{Lvj_!
~UaD=sbPs#
D$()D$
D$8)D$
L$<QRR
GetSystemDefaultLangID
GetComputerNameA
WriteConsoleInputW
GetConsoleAliasesLengthW
GetLocaleInfoA
GetCPInfo
FindResourceExW
FindResourceW
BuildCommDCBAndTimeoutsA
DeleteVolumeMountPointA
WaitNamedPipeA
SetDefaultCommConfigW
GetEnvironmentStringsW
GetModuleHandleExW
SetTapeParameters
GetModuleHandleW
FindNextVolumeMountPointA
ConvertFiberToThread
GetConsoleAliasExesW
EnumTimeFormatsA
GetCommandLineA
GetDriveTypeA
GetEnvironmentStrings
LoadLibraryW
ReadConsoleInputA
CreateEventA
SetConsoleCP
GetFileAttributesA
SetSystemPowerState
ReadFile
GetCompressedFileSizeA
GetStartupInfoW
RaiseException
GetShortPathNameA
GetConsoleAliasesW
FindFirstFileA
GetLastError
SetLastError
PeekConsoleInputW
SetVolumeLabelW
MoveFileW
CopyFileA
EnumSystemCodePagesW
FreeUserPhysicalPages
SetComputerNameA
VerLanguageNameW
GetTempFileNameA
FindClose
LocalAlloc
CreateHardLinkW
AddAtomW
RemoveDirectoryW
HeapLock
GetCommMask
FoldStringW
FindNextFileA
SetConsoleTitleW
FindNextFileW
VirtualProtect
QueryPerformanceFrequency
FatalAppExitA
OpenSemaphoreW
GetWindowsDirectoryW
GetVolumeNameForVolumeMountPointW
ReadConsoleOutputCharacterW
EnumSystemLocalesW
CommConfigDialogW
DeleteFileA
KERNEL32.dll
CharUpperW
CharUpperBuffA
USER32.dll
GetTextFaceA
GDI32.dll
AbortSystemShutdownA
ADVAPI32.dll
DragAcceptFiles
SHELL32.dll
MoveFileA
WideCharToMultiByte
HeapAlloc
GetProcAddress
ExitProcess
DecodePointer
HeapReAlloc
GetCommandLineW
HeapSetInformation
IsProcessorFeaturePresent
EnterCriticalSection
LeaveCriticalSection
SetHandleCount
GetStdHandle
InitializeCriticalSectionAndSpinCount
GetFileType
DeleteCriticalSection
UnhandledExceptionFilter
SetUnhandledExceptionFilter
IsDebuggerPresent
EncodePointer
TerminateProcess
GetCurrentProcess
InterlockedIncrement
InterlockedDecrement
GetACP
GetOEMCP
IsValidCodePage
TlsAlloc
TlsGetValue
TlsSetValue
TlsFree
GetCurrentThreadId
WriteFile
GetModuleFileNameW
HeapCreate
HeapFree
CloseHandle
FreeEnvironmentStringsW
QueryPerformanceCounter
GetTickCount
GetCurrentProcessId
GetSystemTimeAsFileTime
SetFilePointer
GetConsoleCP
GetConsoleMode
RtlUnwind
LCMapStringW
MultiByteToWideChar
GetStringTypeW
HeapSize
SetStdHandle
FlushFileBuffers
WriteConsoleW
CreateFileW
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
}}}}~|
~y{{}}
~{||~}~
zz~~|~
|~~y~~
{}|~}}
}~~|}~
~|~{|~
{}~}}z
{~}{}}
{~y~|zz
~|{}~}
}y|y~}{
|{|~|~|
~{}y}{
{y}{|y|
{~{{}~
}z~~~z
{}{}~~
mscoree.dll
HH:mm:ss
dddd, MMMM dd, yyyy
MM/dd/yy
December
November
October
September
August
February
January
Saturday
Friday
Thursday
Wednesday
Tuesday
Monday
Sunday
nKERNEL32.DLL
runtime error
TLOSS error
SING error
DOMAIN error
- Attempt to use MSIL code from this assembly during native code initialization
This indicates a bug in your application. It is most likely the result of calling an MSIL-compiled (/clr) function from a native constructor or from DllMain.
- not enough space for locale information
- Attempt to initialize the CRT more than once.
This indicates a bug in your application.
- CRT not initialized
- unable to initialize heap
- not enough space for lowio initialization
- not enough space for stdio initialization
- pure virtual function call
- not enough space for _onexit/atexit table
- unable to open console device
- unexpected heap error
- unexpected multithread lock error
- not enough space for thread data
- abort() has been called
- not enough space for environment
- not enough space for arguments
- floating point support not loaded
@Microsoft Visual C++ Runtime Library
<program name unknown>
Runtime Error!
Program:
(null)
((((( H
h(((( H
H
WUSER32.DLL
CONOUT$
repezilat
cpomajapilapimunuwipemalovukaf
dumuwopobelisevop
pehezudovag
zusofuvavojucaf
goxotucok
nadahuhacaruzejagazirazucigoxoj
silivexuxuresifovevikegiyewa
@jjjjj
@jjjjj
/ P6pL
,/KPip
/-P?pR
VS_VERSION_INFO
StringFileInfo
037485B3
InternalName
ElasticAttreban.exe
LegalTrademark1
DoesGet
OriginalFilename
Huklusa.exe
ProductName
Jadezku
ProductVersion
1.0.2.9
VarFileInfo
Translation
YPizosesoy sikipoka kecoyuraworeber bid comilo rokadofu lecihuba kicirokuyi nesuhepizahomi
Fowevuciyudufi
Futax luriruvut
Fus lageju femived%Yividonum hamawojaxaxo vumaxerube xit
0Copuwodelad yati ranofocaso tilupod yexohekezene>Yamu pitayayobusuvu vuhenukibagim tisubiwujigu vegemesozocebeyHWarafukob yamibusisukej ruxohefezab heyupivuvene cunajurozav roxunominut!Wababesuj ledur gefetow nunolisah/Tonuhun jukofemetig hokumolura guliyuyuhiw zopuWMonoxo geyerenezekodeh fewakiruruyazu bahugor zimefofotago bufepawa dukepuvasano jocamo
NCarubewomekawi xeruvobehoxu dewepobagavi tucavevetov tuhaxibinesif xocimaf rit
&Vopujuluze vipocopolucaki bonuhovunaxe2Paso nihec yonaciw vitugipox wuzavehoyujiy kihitet
,Jiz bej nihew laxutuge lolofe zigafavip cuvi
4Wutijamituzut hajanuyusivigoc fatodohumi tusuxazacek
Jawefib
Tuderolimi lidovac hazenebu
Dokodudacarux sewibiha<Gunu gozasiri rewegawojifusu veyapag dexiverafefize muxe did
@Xibok canuriru yamewuyoye rorumahopijol jozuyitecekuka jejibalem
Jegor payawadigofexi=Kikupi kinowifelibejod vaboric wejagavopadepuj vij bibekamare
Git[Xomifepuxafikos sapujetici ronet havodob bifo fedokizegewaf guy yuhopaza luz netosolocoxato
Rewuxilarucecej
'Kisuj fudigal wexayevola luxa hibadozuf
Wilimikegu pepacevohopep
Givexus damitosubohade xadezu=Domolihanagepad forebaviy niji fogunujihej lefuladenor jajiji
Antivirus Signature
Bkav W32.AIDetectMalware
Lionic Clean
tehtris Clean
DrWeb Clean
MicroWorld-eScan Clean
FireEye Generic.mg.1d14fe082ca22877
CAT-QuickHeal Ransom.Stop.P5
Skyhigh BehavesLike.Win32.Lockbit.dm
ALYac Clean
Malwarebytes Clean
VIPRE Clean
Sangfor Trojan.Win32.Save.a
K7AntiVirus Trojan ( 005a15901 )
BitDefender Clean
K7GW Trojan ( 005a15901 )
CrowdStrike win/malicious_confidence_100% (D)
Arcabit Clean
BitDefenderTheta Clean
VirIT Clean
Symantec ML.Attribute.HighConfidence
Elastic malicious (high confidence)
ESET-NOD32 Clean
APEX Malicious
Paloalto Clean
ClamAV Clean
Kaspersky UDS:DangerousObject.Multi.Generic
Alibaba Clean
NANO-Antivirus Clean
ViRobot Clean
Tencent Trojan.Win32.Obfuscated.gen
TACHYON Clean
Sophos Troj/Krypt-ACJ
F-Secure Clean
Baidu Clean
Zillya Clean
TrendMicro Clean
Trapmine malicious.high.ml.score
CMC Clean
Emsisoft Clean
Ikarus Trojan.Win32.Crypt
Jiangmin Clean
Webroot Clean
Google Detected
Avira Clean
Varist Clean
Antiy-AVL Clean
Kingsoft malware.kb.a.1000
Gridinsoft Ransom.Win32.STOP.bot!n
Xcitium Clean
Microsoft Trojan:Win32/Sabsik.FL.B!ml
SUPERAntiSpyware Clean
ZoneAlarm UDS:DangerousObject.Multi.Generic
GData Clean
Cynet Malicious (score: 100)
AhnLab-V3 Malware/Win.Generic.C5515868
Acronis suspicious
McAfee Clean
MAX Clean
DeepInstinct MALICIOUS
VBA32 Clean
Cylance unsafe
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Rising Trojan.Generic@AI.100 (RDML:HM5HIA/Ap3rYTBAsOZfhyw)
Yandex Clean
SentinelOne Static AI - Malicious PE
MaxSecure Clean
Fortinet Clean
AVG Win32:TrojanX-gen [Trj]
Cybereason malicious.14a4e2
Avast Win32:TrojanX-gen [Trj]
No IRMA results available.