Static | ZeroBOX

PE Compile Time

2022-06-26 00:26:13

PE Imphash

87bb85280d56158859c1c42d02178700

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x00037b0e 0x00037c00 5.61984731456
.data 0x00039000 0x00388524 0x00001a00 2.71004049524
.rsrc 0x003c2000 0x000070d8 0x00007200 3.7107097506

Resources

Name Offset Size Language Sub-language File type
RT_CURSOR 0x003c7b20 0x000008a8 LANG_NEUTRAL SUBLANG_NEUTRAL dBase III DBT, version number 0, next free block index 40, 1st item "\251\317"
RT_CURSOR 0x003c7b20 0x000008a8 LANG_NEUTRAL SUBLANG_NEUTRAL dBase III DBT, version number 0, next free block index 40, 1st item "\251\317"
RT_CURSOR 0x003c7b20 0x000008a8 LANG_NEUTRAL SUBLANG_NEUTRAL dBase III DBT, version number 0, next free block index 40, 1st item "\251\317"
RT_CURSOR 0x003c7b20 0x000008a8 LANG_NEUTRAL SUBLANG_NEUTRAL dBase III DBT, version number 0, next free block index 40, 1st item "\251\317"
RT_CURSOR 0x003c7b20 0x000008a8 LANG_NEUTRAL SUBLANG_NEUTRAL dBase III DBT, version number 0, next free block index 40, 1st item "\251\317"
RT_CURSOR 0x003c7b20 0x000008a8 LANG_NEUTRAL SUBLANG_NEUTRAL dBase III DBT, version number 0, next free block index 40, 1st item "\251\317"
RT_CURSOR 0x003c7b20 0x000008a8 LANG_NEUTRAL SUBLANG_NEUTRAL dBase III DBT, version number 0, next free block index 40, 1st item "\251\317"
RT_CURSOR 0x003c7b20 0x000008a8 LANG_NEUTRAL SUBLANG_NEUTRAL dBase III DBT, version number 0, next free block index 40, 1st item "\251\317"
RT_ICON 0x003c4a38 0x00000988 LANG_SINDHI SUBLANG_SYS_DEFAULT dBase III DBT, version number 0, next free block index 40
RT_ICON 0x003c4a38 0x00000988 LANG_SINDHI SUBLANG_SYS_DEFAULT dBase III DBT, version number 0, next free block index 40
RT_STRING 0x003c8f80 0x00000152 LANG_SINDHI SUBLANG_SYS_DEFAULT data
RT_STRING 0x003c8f80 0x00000152 LANG_SINDHI SUBLANG_SYS_DEFAULT data
RT_STRING 0x003c8f80 0x00000152 LANG_SINDHI SUBLANG_SYS_DEFAULT data
RT_STRING 0x003c8f80 0x00000152 LANG_SINDHI SUBLANG_SYS_DEFAULT data
RT_STRING 0x003c8f80 0x00000152 LANG_SINDHI SUBLANG_SYS_DEFAULT data
RT_GROUP_CURSOR 0x003c7af0 0x00000030 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_GROUP_CURSOR 0x003c7af0 0x00000030 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_GROUP_CURSOR 0x003c7af0 0x00000030 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_GROUP_CURSOR 0x003c7af0 0x00000030 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_GROUP_ICON 0x003c53c0 0x00000022 LANG_SINDHI SUBLANG_SYS_DEFAULT data
RT_VERSION 0x003c83e0 0x00000200 LANG_NEUTRAL SUBLANG_NEUTRAL data

Imports

Library KERNEL32.dll:
0x401008 WriteConsoleInputW
0x40100c GetLocaleInfoA
0x401010 GetCPInfo
0x401014 FindResourceExW
0x401018 FindResourceW
0x401024 WaitNamedPipeA
0x401030 GetModuleHandleExW
0x401034 CreateHardLinkA
0x401038 SetTapeParameters
0x40103c GetModuleHandleW
0x401048 EnumTimeFormatsA
0x40104c GetCommandLineA
0x401050 GetDriveTypeA
0x401058 GlobalAlloc
0x40105c LoadLibraryW
0x401060 FatalAppExitW
0x401064 ReadConsoleInputA
0x401068 CopyFileW
0x40106c SetConsoleCP
0x401070 GetFileAttributesA
0x401074 SetSystemPowerState
0x401078 ReadFile
0x401084 GetStartupInfoW
0x401088 RaiseException
0x40108c GetComputerNameA
0x401090 GetConsoleAliasesW
0x401094 FindFirstFileA
0x401098 GetLastError
0x40109c SetLastError
0x4010a0 PeekConsoleInputW
0x4010a4 SetVolumeLabelW
0x4010a8 MoveFileW
0x4010b4 SetComputerNameA
0x4010b8 VerLanguageNameW
0x4010bc GetTempFileNameA
0x4010c0 FindClose
0x4010c4 CreateEventW
0x4010c8 RemoveDirectoryW
0x4010cc HeapLock
0x4010d0 GetCommMask
0x4010d4 AddAtomA
0x4010d8 FoldStringW
0x4010dc FindNextFileA
0x4010e0 SetConsoleTitleW
0x4010e4 FindNextFileW
0x4010e8 VirtualProtect
0x4010f0 OpenSemaphoreW
0x401100 EnumSystemLocalesW
0x401104 CommConfigDialogW
0x401108 DeleteFileA
0x40110c CreateFileW
0x401110 WriteConsoleW
0x401114 GetShortPathNameA
0x40111c FlushFileBuffers
0x401120 SetStdHandle
0x401124 MoveFileA
0x401128 WideCharToMultiByte
0x40112c HeapAlloc
0x401130 GetProcAddress
0x401134 ExitProcess
0x401138 DecodePointer
0x40113c HeapReAlloc
0x401140 GetCommandLineW
0x401144 HeapSetInformation
0x401154 SetHandleCount
0x401158 GetStdHandle
0x401160 GetFileType
0x401170 IsDebuggerPresent
0x401174 EncodePointer
0x401178 TerminateProcess
0x40117c GetCurrentProcess
0x401188 GetACP
0x40118c GetOEMCP
0x401190 IsValidCodePage
0x401194 TlsAlloc
0x401198 TlsGetValue
0x40119c TlsSetValue
0x4011a0 TlsFree
0x4011a4 GetCurrentThreadId
0x4011a8 WriteFile
0x4011ac GetModuleFileNameW
0x4011b0 HeapCreate
0x4011b4 HeapFree
0x4011b8 CloseHandle
0x4011c4 GetTickCount
0x4011c8 GetCurrentProcessId
0x4011d0 Sleep
0x4011d4 SetFilePointer
0x4011d8 GetConsoleCP
0x4011dc GetConsoleMode
0x4011e0 RtlUnwind
0x4011e4 LCMapStringW
0x4011e8 MultiByteToWideChar
0x4011ec GetStringTypeW
0x4011f0 HeapSize
Library USER32.dll:
0x401200 CharUpperW
Library ADVAPI32.dll:
Library SHELL32.dll:
0x4011f8 DragAcceptFiles

!This program cannot be run in DOS mode.
`.data
CorExitProcess
HH:mm:ss
dddd, MMMM dd, yyyy
MM/dd/yy
December
November
October
September
August
February
January
Saturday
Friday
Thursday
Wednesday
Tuesday
Monday
Sunday
FlsFree
FlsSetValue
FlsGetValue
FlsAlloc
(null)
`h````
xpxxxx
?ZEM-'^
?{yK+;
?765@Z
?e')lW
UUUUUU
333333
?333333
?UUUUUU
?$rxxx
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
GetProcessWindowStation
GetUserObjectInformationW
GetLastActivePopup
GetActiveWindow
MessageBoxW
`h`hhh
xppwpp
_nextafter
_hypot
1#QNAN
1#SNAN
lufuwopojenayijifecuweyosanadel
gucayurefisobapuvaruf
uwipemalovukaf
obelisevop
0.1 %f
fohipavekesiw
wipehugelemigexuhafakojimexuf
uTVWhR
j h@|C
j@j ^V
^SSSSS
tWItHIt9It
QQSVWh
URPQQh
t"SS9] u
tRHtCHt4Ht%HtFHHt
PPPPPPPP
PPPPPPPP
;t$,v-
UQPXY]Y[
<+t"<-t
+t HHt
pvJ?e]
OatxPL
Ii^VKB
'b()^
!dnZ+^
qU`n=iOU%
C_]Kc>p
1meaVBq
hw>J%jr
w=.X!g
L/'s%
[J{~G;!t
^.C~<Vk
%)@N=%
Qdvf)%
{Y~ST`
vBv*)^`
n6.%Yj
<WPD|G
D%YJ\
6V,>M?=
6/(<Jw
53+jC0a
BK\f^E
$(>'\<
+vfFN5]
*Ria+aV&
x*9zNqK
oVCG9
nxA-`~
*s)|jS6
"4N3M"6
@U6g>$
AB 3{\
X7fZ:,
q?1n,y/2\ySS
,DDk;3
:K` WJa
.EDXpa
N@=8/M
ucErsy^
B!Dh)?
j|lHFl
v8}@YW
 0D5
g{S?tRx
Z{3D;u
H8HBXN
BgNqirh
iSL1)^
:Z^@#'
?F&J)I
J*RMWZcu
%/V5}W
*$&-E&P
L"x!$x
$=v]mVV$
t^2Yrz
fTk&ao
a!60h*
fN8;|/
`szVw;8
l-5;Hh
DxiW8JNrsqU
qLP%B(
}vF{o[6
!xV#:g
rS^w_y^<
KUqm@r1<
z]UW1-jl
*JMW?H
Q0^~d9m1
B]hh:am
ppvwGW
U)H"L]`k
&]TV=n
F7eY];At|hy
oKAPIIM
RZPzU)
GKEN{E
x`t7qn
O-Zz%v
<tHxFh O>
UEa7jqF
(:}zAr*B
S+/d^K%.d
mi))&`q]
lIhC}+
6/YM[
}BP/&<
J'1ySX-1
Tj;8 m6t
?vzH'
P`+a;*|
<pN5 0v
(~L:75uv$
+G|AG)
iV 3fN_
WD*c.c#
OAmsh]
6f5fc`
z;H;g9
'2*<Wr
--]yXe
8ULhz3
yDT0#I
wzU?{tG
-~Hy:$
s6Tpcc
|dJNZt
6%-OAv
5=u%ns\
X%a&g]`
U2g^9g.ww
HN^:iDi
lkJ7Y?
8YJSuG
srxW\1Zy)
KGX>hJ4
W/;ML(
|+C=mg
ql@ZmS
)-pg1r
+dD5N)
D$()D$
D$8)D$
L$<QRR
D$8Ph@F@
GetSystemDefaultLangID
GetComputerNameA
WriteConsoleInputW
GetLocaleInfoA
GetCPInfo
FindResourceExW
FindResourceW
BuildCommDCBAndTimeoutsA
DeleteVolumeMountPointA
WaitNamedPipeA
SetDefaultCommConfigW
GetEnvironmentStringsW
GetModuleHandleExW
CreateHardLinkA
SetTapeParameters
GetModuleHandleW
ConvertFiberToThread
GetConsoleAliasExesW
EnumTimeFormatsA
GetCommandLineA
GetDriveTypeA
GetEnvironmentStrings
GlobalAlloc
LoadLibraryW
FatalAppExitW
ReadConsoleInputA
CopyFileW
SetConsoleCP
GetFileAttributesA
SetSystemPowerState
ReadFile
GetCompressedFileSizeA
FindNextVolumeMountPointW
GetStartupInfoW
RaiseException
GetShortPathNameA
GetConsoleAliasesW
FindFirstFileA
GetLastError
SetLastError
PeekConsoleInputW
SetVolumeLabelW
MoveFileW
EnumSystemCodePagesW
FreeUserPhysicalPages
SetComputerNameA
VerLanguageNameW
GetTempFileNameA
FindClose
CreateEventW
RemoveDirectoryW
HeapLock
GetCommMask
AddAtomA
FoldStringW
FindNextFileA
SetConsoleTitleW
FindNextFileW
VirtualProtect
QueryPerformanceFrequency
OpenSemaphoreW
GetWindowsDirectoryW
GetVolumeNameForVolumeMountPointW
ReadConsoleOutputCharacterW
EnumSystemLocalesW
CommConfigDialogW
DeleteFileA
KERNEL32.dll
CharUpperW
USER32.dll
AbortSystemShutdownA
ADVAPI32.dll
DragAcceptFiles
SHELL32.dll
MoveFileA
WideCharToMultiByte
HeapAlloc
GetProcAddress
ExitProcess
DecodePointer
HeapReAlloc
GetCommandLineW
HeapSetInformation
IsProcessorFeaturePresent
EnterCriticalSection
LeaveCriticalSection
SetHandleCount
GetStdHandle
InitializeCriticalSectionAndSpinCount
GetFileType
DeleteCriticalSection
UnhandledExceptionFilter
SetUnhandledExceptionFilter
IsDebuggerPresent
EncodePointer
TerminateProcess
GetCurrentProcess
InterlockedIncrement
InterlockedDecrement
GetACP
GetOEMCP
IsValidCodePage
TlsAlloc
TlsGetValue
TlsSetValue
TlsFree
GetCurrentThreadId
WriteFile
GetModuleFileNameW
HeapCreate
HeapFree
CloseHandle
FreeEnvironmentStringsW
QueryPerformanceCounter
GetTickCount
GetCurrentProcessId
GetSystemTimeAsFileTime
SetFilePointer
GetConsoleCP
GetConsoleMode
RtlUnwind
LCMapStringW
MultiByteToWideChar
GetStringTypeW
HeapSize
SetStdHandle
FlushFileBuffers
WriteConsoleW
CreateFileW
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
y~||{~
{}|}z}
{}~~z{
z~|{y|
{~~|}{
~~~}z|
|~}~~{
}}}~}y
}{|~z~
~|{z}}{~
{~|~~|~
{~~zyz
~{~}|z
|{|z}z
}|~y|}
mscoree.dll
HH:mm:ss
dddd, MMMM dd, yyyy
MM/dd/yy
December
November
October
September
August
February
January
Saturday
Friday
Thursday
Wednesday
Tuesday
Monday
Sunday
nKERNEL32.DLL
runtime error
TLOSS error
SING error
DOMAIN error
- Attempt to use MSIL code from this assembly during native code initialization
This indicates a bug in your application. It is most likely the result of calling an MSIL-compiled (/clr) function from a native constructor or from DllMain.
- not enough space for locale information
- Attempt to initialize the CRT more than once.
This indicates a bug in your application.
- CRT not initialized
- unable to initialize heap
- not enough space for lowio initialization
- not enough space for stdio initialization
- pure virtual function call
- not enough space for _onexit/atexit table
- unable to open console device
- unexpected heap error
- unexpected multithread lock error
- not enough space for thread data
- abort() has been called
- not enough space for environment
- not enough space for arguments
- floating point support not loaded
@Microsoft Visual C++ Runtime Library
<program name unknown>
Runtime Error!
Program:
(null)
((((( H
h(((( H
H
WUSER32.DLL
CONOUT$
repezilat
pehezudovag
zusofuvavojucaf
goxotucok
nadahuhacaruzejagazirazucigoxoj
silivexuxuresifovevikegiyewa
@jjjjj
@jjjjj
/ P6pL
,/KPip
/-P?pR
VS_VERSION_INFO
StringFileInfo
037485B3
InternalName
ElasticAttreban.exe
LegalTrademark1
DoesGet
OriginalFilename
Huklusa.exe
ProductName
Jadezky
ProductVersion
1.3.2.9
VarFileInfo
Translation
YPizosesoy sikipoka kecoyuraworeber bid comilo rokadofu lecihuba kicirokuyi nesuhepizahomi
Fowevuciyudufi
Futax luriruvut
Fus lageju femived%Yividonum hamawojaxaxo vumaxerube xit
0Copuwodelad yati ranofocaso tilupod yexohekezene>Yamu pitayayobusuvu vuhenukibagim tisubiwujigu vegemesozocebeyHWarafukob yamibusisukej ruxohefezab heyupivuvene cunajurozav roxunominut!Wababesuj ledur gefetow nunolisah/Tonuhun jukofemetig hokumolura guliyuyuhiw zopuWMonoxo geyerenezekodeh fewakiruruyazu bahugor zimefofotago bufepawa dukepuvasano jocamo
NCarubewomekawi xeruvobehoxu dewepobagavi tucavevetov tuhaxibinesif xocimaf rit
&Vopujuluze vipocopolucaki bonuhovunaxe2Paso nihec yonaciw vitugipox wuzavehoyujiy kihitet
,Jiz bej nihew laxutuge lolofe zigafavip cuvi
4Wutijamituzut hajanuyusivigoc fatodohumi tusuxazacek
Jawefib
Tuderolimi lidovac hazenebu
Dokodudacarux sewibiha<Gunu gozasiri rewegawojifusu veyapag dexiverafefize muxe did
@Xibok canuriru yamewuyoye rorumahopijol jozuyitecekuka jejibalem
Jegor payawadigofexi=Kikupi kinowifelibejod vaboric wejagavopadepuj vij bibekamare
Git[Xomifepuxafikos sapujetici ronet havodob bifo fedokizegewaf guy yuhopaza luz netosolocoxato
Rewuxilarucecej
'Kisuj fudigal wexayevola luxa hibadozuf
Wilimikegu pepacevohopep
Givexus damitosubohade xadezu=Domolihanagepad forebaviy niji fogunujihej lefuladenor jajiji
Antivirus Signature
Bkav W32.AIDetectMalware
Lionic Clean
Elastic malicious (high confidence)
MicroWorld-eScan Clean
FireEye Generic.mg.d29b29f543a8e714
CAT-QuickHeal Ransom.Stop.P5
Skyhigh BehavesLike.Win32.Lockbit.dm
McAfee Clean
Cylance unsafe
VIPRE Clean
Sangfor Trojan.Win32.Save.a
K7AntiVirus Trojan ( 00516fdf1 )
BitDefender Clean
K7GW Trojan ( 005a15901 )
Cybereason malicious.b66af7
BitDefenderTheta Clean
VirIT Clean
Symantec ML.Attribute.HighConfidence
tehtris Clean
ESET-NOD32 Clean
APEX Malicious
Paloalto Clean
Cynet Malicious (score: 100)
Kaspersky UDS:Trojan.Win32.Agent.gen
Alibaba Clean
NANO-Antivirus Clean
ViRobot Clean
Rising Trojan.Generic@AI.100 (RDML:Gg+p4Ljy5kgOih7EHlcBsQ)
Sophos ML/PE-A
Baidu Clean
F-Secure Clean
DrWeb Clean
Zillya Clean
TrendMicro Clean
Trapmine malicious.high.ml.score
CMC Clean
Emsisoft Clean
Ikarus Trojan.Win32.Crypt
GData Clean
Jiangmin Clean
Webroot Clean
Varist Clean
Avira Clean
MAX Clean
Antiy-AVL Clean
Kingsoft malware.kb.a.1000
Gridinsoft Clean
Xcitium Clean
Arcabit Clean
SUPERAntiSpyware Clean
ZoneAlarm UDS:Trojan.Win32.Agent.gen
Microsoft Trojan:Win32/Sabsik.FL.B!ml
Google Detected
AhnLab-V3 Clean
Acronis suspicious
ALYac Clean
TACHYON Clean
DeepInstinct MALICIOUS
VBA32 Malware-Cryptor.Azorult.gen
Malwarebytes Clean
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Tencent Trojan.Win32.Obfuscated.gen
Yandex Clean
SentinelOne Static AI - Malicious PE
MaxSecure Clean
Fortinet Clean
AVG PWSX-gen [Trj]
Avast PWSX-gen [Trj]
CrowdStrike win/malicious_confidence_100% (W)
No IRMA results available.