Static | ZeroBOX

PE Compile Time

2024-01-12 16:49:47

PE Imphash

def745e62858e9ac0dee4801e550d289

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x0003f7be 0x0003f800 7.94107119136
.rdata 0x00041000 0x00002f92 0x00003000 5.00826074569
.data 0x00044000 0x024093e4 0x00024800 0.0961933953266
.rsrc 0x0244e000 0x00004028 0x00004200 3.97733861664

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x02450eb0 0x00000468 LANG_JAPANESE SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x02450eb0 0x00000468 LANG_JAPANESE SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x02450eb0 0x00000468 LANG_JAPANESE SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_DIALOG 0x024515d0 0x00000058 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_STRING 0x02451d00 0x00000322 LANG_JAPANESE SUBLANG_DEFAULT data
RT_STRING 0x02451d00 0x00000322 LANG_JAPANESE SUBLANG_DEFAULT data
RT_STRING 0x02451d00 0x00000322 LANG_JAPANESE SUBLANG_DEFAULT data
RT_GROUP_ICON 0x02451318 0x00000030 LANG_JAPANESE SUBLANG_DEFAULT data
RT_VERSION 0x02451348 0x00000288 LANG_NEUTRAL SUBLANG_NEUTRAL data

Imports

Library KERNEL32.dll:
0x44100c FindResourceW
0x441010 LocalCompact
0x441014 WriteConsoleInputA
0x441018 GetModuleHandleW
0x441020 GetDateFormatA
0x441028 LoadLibraryW
0x44102c FreeConsole
0x441030 CreateEventA
0x441034 GetModuleFileNameW
0x441038 GetACP
0x44103c IsBadStringPtrA
0x441040 ReplaceFileA
0x441044 CreateDirectoryA
0x441048 GetLastError
0x44104c SetLastError
0x441050 SetEndOfFile
0x441054 GlobalFree
0x441058 CreateFileMappingA
0x44105c LocalAlloc
0x441064 GlobalFindAtomW
0x441068 EnumResourceTypesW
0x441070 SetFileAttributesW
0x441074 RaiseException
0x441078 HeapReAlloc
0x44107c HeapAlloc
0x441080 GetStringTypeW
0x441084 MultiByteToWideChar
0x441088 CommConfigDialogA
0x44108c GetProcAddress
0x441090 CreateFileA
0x441094 LCMapStringW
0x441098 HeapSize
0x44109c RtlUnwind
0x4410a0 Sleep
0x4410a4 IsValidCodePage
0x4410a8 HeapFree
0x4410ac GetCommandLineA
0x4410b0 HeapSetInformation
0x4410b4 GetStartupInfoW
0x4410bc HeapCreate
0x4410c4 ExitProcess
0x4410c8 DecodePointer
0x4410cc WriteFile
0x4410d0 GetStdHandle
0x4410d4 GetModuleFileNameA
0x4410dc WideCharToMultiByte
0x4410e4 SetHandleCount
0x4410ec GetFileType
0x4410f4 EncodePointer
0x4410f8 TlsAlloc
0x4410fc TlsGetValue
0x441100 TlsSetValue
0x441104 TlsFree
0x44110c GetCurrentThreadId
0x441118 GetTickCount
0x44111c GetCurrentProcessId
0x441128 IsDebuggerPresent
0x44112c TerminateProcess
0x441130 GetCurrentProcess
0x44113c GetCPInfo
0x441140 GetOEMCP
Library USER32.dll:
0x44114c SetMessageExtraInfo
0x441150 GetCaretPos
0x441154 CharUpperBuffA
0x441158 GetClassInfoW
0x44115c InsertMenuItemW
0x441160 ShowCursor
Library ADVAPI32.dll:
0x441000 CopySid
0x441004 ClearEventLogA
Library ole32.dll:
0x441174 CoUnmarshalHresult
Library WINHTTP.dll:
0x441168 WinHttpOpen

!This program cannot be run in DOS mode.
`.rdata
@.data
jlXjmf
E8k=8V
SSSSSS
SSSSSS
u8SSSSSSS
uTVWhL0@
^SSSSS
j@j ^V
j hp4D
URPQQhPQ@
t"SS9] u
;t$,v-
UQPXY]Y[
Rt*twxB{S
Pl*%=1
3#)yP)W
Pqmon'
3&ig:`
{<SF_*0
mq?LG=
j>sD*+
].?30]
V-uDor
f"i;v?
XN)sTTP-
0&ybr@
3ZN4H{
QB#0avy
<[a|}MW^
/$l>x
7r7+l!hj&
;\NXA.
Qv8)v#
qb_r!d
})<&+?
([~& L
><]T~
qpz-@7DB
a:D%Z\
dpaxO=~U
4npjx-Q6
h<iI&Al
DE#>-G0I7o
=&C<0Y
89l@{[
+2@)
A:n^9
'HymH+
"\^+yf
e'<Lql(
v97ID'
$/WU,L
{+L]J&wg
o.*&)4V
Cq\?YX0
6rp$k8~
{hyk}"V
[!zY\<T
XaxBW@
MEff\p
J#wAWAG5Z
ZB&]7b
p)HeHe
?1C?V#
wP.x$a.f&O3
elR=1.
d\!, }
T)@`^N
oaPS/@
Kc}usS
WKK?HI
&&w,#^
>H@`(8
zYRZ@m
kY'.JE
UC=u@=G$
ad`=LY
.-W.>0
I^='-w
a&I*!N
/}1&9
X;2C:&
`L^S\(_V
nn3/2s|
t~qs6/
TjiZ4&
;axa@u
Mq^sfQ
%,L!O=
~&\b0P+
zi=u"8dIFK
Gxx5bjO
sOU:y+
'rH608
tg.req
^qe<}I
5^.xe"
,.p#CR
Decak
o(:z>1
wb\YRZ
t-k!t:K
<5guVG
hQ}hl
g?WsYT
albT]4
K{|YnMD
C-a.d#
Dee0.)
xM'F&K
wc{#%4
0X,\2Pj
%E!5:mq
oF2qmoU
jIDRhX
F6M!,
&o*\V+
(U4b;{
4mA"kA
8Sc%mB
2$tZsW
oFF9rJ
CR&hkx
tcEX?`'
{cD4`
0Sr|U.
|*|iWp
jwct93
9iCw1@
O<$"Mx
4T-37S
#%VB^
T6!B!&@A
@@'RWu
8 !::tI~
Q"y$Z1
ur$ljD
&UB=j^]
-fKDs<
): 2/l
x0NH:6
eCWSo\lh
v \mU
bAiX0nO
![j|b
[;eXU&
e}*rO1rH
e%tAx"
jc&$a>
B2B85^
Hs5WVC
POh~Y-`0C
#vFBT]7
#DDJVC
Bg(kV3u
hGfS:=
i}v~8=it
t@|AZE
+\o8=p
&_`lBj
)mm'HQg-
qE39~~
0TH4#)m
EsC\4
UJA7?]
5Fx_S7[
VY<s-b
R?9f1{
ZWxz-1P
w&]omOc[
>Uzz[$x5
yB+mox
2lQ/Ot
3k7MB~MN
5V%x-:
Z[36Tzs
<<'<sC-
5lcWAM?C
{r7m1e
7ae*LZ
Wp kVWLj
{t=B) Q
I>i`V3
;+]t,T
mGIcW"
Beil@OO
4m@]fT-
lWUH^5
xM+6nw
Uh;enZBkV
8.yK>J
}T2-H\m
[D{AcD
96V!Jd2;
K3h%*kP
%oF#6f
Z/%gX
PQ/&G)
QOM_OT
ywpepFx
y>HL%:
t)4Y`s
2A*azB
!cHb)M
rc;:&vUiL+
),],;x,
pF3zLOEh
~T|A`u
1bSRrL
ThTs"6a
#\pr.vv
G &/jB
'd ;9R
=^DvzO
PeJ)"9
TRtxY5Y
9#t!nu
>%*@dja
hxJ:KW
g`6K0iz_x[E
%;<wf
1z/M}es
z_:Kyi
Z\$6AJH0
DQ_-},
;52YJ`
u[L^a
{=`U9M!S
!@EMJN
L]<K3!({
wyI%oSV
z`WCwp
18}*\<w`
D>J~6N
unrV[6
^/xRwi
B%:oKk
mA#mQR
H8;.FR
[:&wp$
Onl2$.
tho])Y(
O\F#%yG`Y={dp
A@P='ae
qF)Q=U
nR[O$A
zL];|mP
jpL$XEn
Q9qK2
51mfu"bv
S"zTDC
zrQ[9v.
a.5X]B
&vk1dd
Y/mE!L
JSqy|f
!m%Vf(
E=[%(I
`W_#7~
i}OcKM
E(hAW;M+
<g)@C'
S-.5mr
c4k-iQ
cve`0F^GU
T*RoDM
4UnCdyw8
IG9wit
R*}pOo
\`JDO)~
3]mS?od
M>GPm_o
p8RX"q
..Cy1C
4mH=^H
2g4MX6X7
/.Wd
WjVGZO(U3
`$G(fOV
j]|e,%
+#AM;#
l=SJ'P
4U,pO@L
y.d$~AJ
:(38w.
P4i31Sy
2TC*S,)I
O'a(_&L
qX7v>J
VnbNYE|
|uiG3x!|
qp6G[i
?%vTMH
!-|a9U;
.ga?XK
0*.e!]h
q69``f
dU(t`8b
sp-8zu
|0>Ij
A!}x5
rKX"|X
SM|@)x
qy"^[e
JsqTl7
<D2h__
^`?h::9
q<[V_?
@c&sGa
EC}n@U
\@'1[-
qcRR;M_
Y-^0#[
yxR4i_
"<qHO3f
h.mYP%T
5M"&`I}
^oI]LI
_APoIz
;!8<7~(
0cjX%J%
{l;4I"
+a^IKUw
#$m Zr
eu_N|~
I@*U]L
Tc"2
6b(zES
1h9"K&
+H4UT7
Lrb.yh
'@O7O(U
.T!C]_
.6KvUuh
*z9?%,
E^zRMh
uuARIo
"3[()l6
g4U/v]a
Ose0N?
T`}-wG
y[_J|
G#c4"
p{:U3o
*:'@558
L*jH^
m6N/iJ
\\WCDa1f_5
(}zp&A
A!Ri$%
x~!-,\*
XnWCc4
u+T-]z3
U$h^6xX
$kRP `#Fy
W#w/45
Qy4-&l
E^]y{U~
\%-:6I
-kN(Qn
^vfP>L
)bU-7Q
~/M\{\2
U4_,y!
r>.dy k
{ASf5A
2x(Y@_
M4NA[-
ru(Nk\
IHKuN9
XB_[fT
\q-Sya
7b?H\_A
DOF("b
uvN= m
491}M',
l<RJtU
p&z&-C
j5"3#N
EzE'q^
?'dQzd
>[+R`=C
~5K-Vb
r(K\Cs
PIO;JW=
_aZ</K
AG/^9X
h'v @&
Khrf j
d!o<:8
QQSVWd
t=MOC
HtHu4j
t*=RCC
;7|G;p
tR99u2
PPPPPPPP
PPPPPPPP
CorExitProcess
FlsFree
FlsSetValue
FlsGetValue
FlsAlloc
GetProcessWindowStation
GetUserObjectInformationW
GetLastActivePopup
GetActiveWindow
MessageBoxW
HH:mm:ss
dddd, MMMM dd, yyyy
MM/dd/yy
December
November
October
September
August
February
January
Saturday
Friday
Thursday
Wednesday
Tuesday
Monday
Sunday
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
munuwozimavolunuj
kernel32.dll
VirtualProtect
bad exception
Unknown exception
Complete Object Locator'
Class Hierarchy Descriptor'
Base Class Array'
Base Class Descriptor at (
Type Descriptor'
`local static thread guard'
`managed vector copy constructor iterator'
`vector vbase copy constructor iterator'
`vector copy constructor iterator'
`dynamic atexit destructor for '
`dynamic initializer for '
`eh vector vbase copy constructor iterator'
`eh vector copy constructor iterator'
`managed vector destructor iterator'
`managed vector constructor iterator'
`placement delete[] closure'
`placement delete closure'
`omni callsig'
delete[]
new[]
`local vftable constructor closure'
`local vftable'
`udt returning'
`copy constructor closure'
`eh vector vbase constructor iterator'
`eh vector destructor iterator'
`eh vector constructor iterator'
`virtual displacement map'
`vector vbase constructor iterator'
`vector destructor iterator'
`vector constructor iterator'
`scalar deleting destructor'
`default constructor closure'
`vector deleting destructor'
`vbase destructor'
`string'
`local static guard'
`typeof'
`vcall'
`vbtable'
`vftable'
operator
delete
__unaligned
__restrict
__ptr64
__eabi
__clrcall
__fastcall
__thiscall
__stdcall
__pascal
__cdecl
__based(
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
CreateFileA
CommConfigDialogA
SetEndOfFile
FindResourceW
LocalCompact
WriteConsoleInputA
GetModuleHandleW
GetWindowsDirectoryA
GetDateFormatA
SetProcessPriorityBoost
LoadLibraryW
FreeConsole
CreateEventA
GetModuleFileNameW
GetACP
IsBadStringPtrA
ReplaceFileA
CreateDirectoryA
GetLastError
SetLastError
GetProcAddress
GlobalFree
CreateFileMappingA
LocalAlloc
AddVectoredExceptionHandler
GlobalFindAtomW
EnumResourceTypesW
GetWindowsDirectoryW
SetFileAttributesW
KERNEL32.dll
GetKeyboardLayoutNameA
SetMessageExtraInfo
GetCaretPos
CharUpperBuffA
ShowCursor
InsertMenuItemW
GetClassInfoW
USER32.dll
CopySid
ClearEventLogA
ADVAPI32.dll
CoUnmarshalHresult
CoSuspendClassObjects
ole32.dll
WinHttpOpen
WINHTTP.dll
HeapFree
GetCommandLineA
HeapSetInformation
GetStartupInfoW
IsProcessorFeaturePresent
HeapCreate
SetUnhandledExceptionFilter
ExitProcess
DecodePointer
WriteFile
GetStdHandle
GetModuleFileNameA
FreeEnvironmentStringsW
WideCharToMultiByte
GetEnvironmentStringsW
SetHandleCount
InitializeCriticalSectionAndSpinCount
GetFileType
DeleteCriticalSection
EncodePointer
TlsAlloc
TlsGetValue
TlsSetValue
TlsFree
InterlockedIncrement
GetCurrentThreadId
InterlockedDecrement
QueryPerformanceCounter
GetTickCount
GetCurrentProcessId
GetSystemTimeAsFileTime
UnhandledExceptionFilter
IsDebuggerPresent
TerminateProcess
GetCurrentProcess
LeaveCriticalSection
EnterCriticalSection
GetCPInfo
GetOEMCP
IsValidCodePage
RtlUnwind
HeapSize
LCMapStringW
MultiByteToWideChar
GetStringTypeW
HeapAlloc
HeapReAlloc
RaiseException
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
.?AVbad_exception@std@@
.?AVexception@std@@
.?AVtype_info@@
|z~}~~|
}z~|||
z||~{z{
zz||{~
z|z{|~
~|||{|
}|}{{{{|
~||||||
|}}~|z|
~}}z}~
mscoree.dll
runtime error
TLOSS error
SING error
DOMAIN error
- Attempt to use MSIL code from this assembly during native code initialization
This indicates a bug in your application. It is most likely the result of calling an MSIL-compiled (/clr) function from a native constructor or from DllMain.
- not enough space for locale information
- Attempt to initialize the CRT more than once.
This indicates a bug in your application.
- CRT not initialized
- unable to initialize heap
- not enough space for lowio initialization
- not enough space for stdio initialization
- pure virtual function call
- not enough space for _onexit/atexit table
- unable to open console device
- unexpected heap error
- unexpected multithread lock error
- not enough space for thread data
- abort() has been called
- not enough space for environment
- not enough space for arguments
- floating point support not loaded
DMicrosoft Visual C++ Runtime Library
<program name unknown>
Runtime Error!
Program:
KERNEL32.DLL
WUSER32.DLL
HH:mm:ss
dddd, MMMM dd, yyyy
MM/dd/yy
December
November
October
September
August
February
January
Saturday
Friday
Thursday
Wednesday
Tuesday
Monday
Sunday
((((( H
h(((( H
H
kernel32.dll
kernel32.dll
bokahakebuwiyoviyudetixifomayow muwacax sem dexak
VS_VERSION_INFO
StringFileInfo
032824E6
FileVersions
62.76.74.12
InternalName
FileDescription
FeelsLike
LegalCopyright
Copyrights (C) 2023, Navisradi
OriginalFilenames
Otlasik
ProductName
Morjezo
ProductVersions
11.62.63.10
VarFileInfo
Translation
Warning
Japan tech:
Nopu zihurediyec wonowogovaxugZagoxudun rivoxej decotonimemisa nifunot zeruhotixexabax rugelejif gecupo jisudagukamel xuramocuy cuyes
Ravi pexa bexode kole mekize
Vatupidazut yejeyuwajuh
Raduziwukuk nebi
Farenodazad2Cudopaxud zapucibugebuc taho dokojufuhagabux pivih\Kejewavolotuce bohenazafuy worucokirutiliw riza jifol kecayewucas rar nibupube guxewataxolihgRiyolef bozifemi fapimicomubiy gayoyudetux veputogecobura nomanax muconayiluvilu yamo yaka carelalusese
Tipu nidinofucicixuz)Jet zotixazipoy reguciyeb jajewuma saralo
Xibosota cedefedul fisulunuy
Cunutebepaj lubag
Cepikemet jegenusisaf tid3Silafoledeyej viduyomu xipegowenato pizarogameratil
TLeg madujajoralobax jonuxuzacov honetolurilened yafirugap huvozejen citasec tolojuvuBNatetekov jokolita tutadisobaxejuh bovohonudunud kahimowotivim bey.Virola gap gudo bawuyupicire hetexo zeputuwexa
Besole
5Mejisuhuxuw jeze yakihat fudogifujafemo lumozapogogaymJowotoyuxumiba dom kucarutox kiyigiyov tusuribifaloro nepuwifa leseyasavekoyes vivedocatejufa wukujewocabizos
Hesenitibokufop jizegezasotas
bBohi hisosaposocatic fejofuk jasoyocanuweg meletasen cihehokusina wafuliton jemeyuzop kufomarijuma`Ladajem kuhekaweceratix mamegosubokal jawigoganupinek kezanecot hawejife zixidev bapotonehukomix
Antivirus Signature
Bkav W32.AIDetectMalware
Lionic Trojan.Win32.SmokeLoader.4!c
tehtris Generic.Malware
ClamAV Win.Packer.pkr_ce1a-9980177-0
CMC Clean
CAT-QuickHeal Clean
Skyhigh BehavesLike.Win32.Generic.gm
ALYac Trojan.Generic.36534197
Cylance Unsafe
Zillya Clean
Sangfor Trojan.Win32.Save.a
K7AntiVirus Riskware ( 00584baa1 )
Alibaba Trojan:Win32/SmokeLoader.cddc9613
K7GW Riskware ( 00584baa1 )
Cybereason Clean
Baidu Clean
VirIT Trojan.Win32.Genus.WAJ
Paloalto generic.ml
Symantec Trojan.FakeAV
Elastic malicious (high confidence)
ESET-NOD32 a variant of Win32/Kryptik.HXMG
APEX Malicious
Avast Win32:CrypterX-gen [Trj]
Cynet Malicious (score: 100)
Kaspersky HEUR:Trojan.Win32.Agent.gen
BitDefender Trojan.Generic.36534197
NANO-Antivirus Clean
ViRobot Clean
MicroWorld-eScan Trojan.Generic.36534197
Tencent Trojan.Win32.Obfuscated.gen
TACHYON Clean
Sophos Troj/Krypt-VK
F-Secure Trojan.TR/AD.GenSHCode.pxiua
DrWeb Trojan.DownLoader47.8409
VIPRE Trojan.Generic.36534197
TrendMicro Trojan.Win32.AMADEY.YXEGKZ
McAfeeD Real Protect-LS!233EA23B1C15
Trapmine malicious.moderate.ml.score
FireEye Generic.mg.233ea23b1c1587f1
Emsisoft Trojan.Generic.36534197 (B)
SentinelOne Static AI - Malicious PE
GData Win32.Packed.Kryptik.FIX18U
Jiangmin Clean
Webroot W32.Trojan.Gen
Varist W32/Kryptik.MIZ.gen!Eldorado
Avira TR/AD.GenSHCode.pxiua
Antiy-AVL Trojan[PSW]/Win32.Tepfer
Kingsoft malware.kb.a.1000
Gridinsoft Trojan.Win32.Amadey.tr
Xcitium Malware@#32cc2ge7hjakp
Arcabit Trojan.Generic.D22D77B5
SUPERAntiSpyware Clean
ZoneAlarm HEUR:Trojan.Win32.Agent.gen
Microsoft Trojan:Win32/SmokeLoader.SMZ!MTB
Google Detected
AhnLab-V3 Trojan/Win.SmokeLoader.R657887
Acronis suspicious
McAfee Clean
MAX malware (ai score=80)
VBA32 TrojanDownloader.Deyma
Malwarebytes Trojan.MalPack.GS
Panda Trj/Chgt.AD
Zoner Clean
TrendMicro-HouseCall Trojan.Win32.AMADEY.YXEGKZ
Rising Stealer.Tepfer!8.13357 (CLOUD)
Yandex Clean
Ikarus Trojan-PWS.Win32.Tepfer
MaxSecure Trojan.Malware.771626.susgen
Fortinet W32/PossibleThreat
BitDefenderTheta Gen:NN.ZexaF.36808.Aq0@aWI!nziG
AVG Win32:CrypterX-gen [Trj]
DeepInstinct MALICIOUS
CrowdStrike win/malicious_confidence_100% (D)
alibabacloud Trojan:Win/SmokeLoader.SZP2XJC
No IRMA results available.