Static | ZeroBOX

PE Compile Time

2023-09-01 10:51:08

PE Imphash

f7b7ec9e4ef13450da9b01e527b930fc

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x000219f0 0x00021a00 7.82325887969
.rdata 0x00023000 0x00003396 0x00003400 5.01063312143
.data 0x00027000 0x02022e8c 0x0000dc00 0.247931882856
.fufuc 0x0204a000 0x000002d3 0x00000400 0.0
.xixeray 0x0204b000 0x00000400 0x00000400 0.0
.rsrc 0x0204c000 0x000099e0 0x00009a00 4.65899916869

Resources

Name Offset Size Language Sub-language File type
RT_CURSOR 0x020543e8 0x00000568 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_CURSOR 0x020543e8 0x00000568 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_CURSOR 0x020543e8 0x00000568 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x02052778 0x00000468 LANG_TAMIL SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x02052778 0x00000468 LANG_TAMIL SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x02052778 0x00000468 LANG_TAMIL SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x02052778 0x00000468 LANG_TAMIL SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x02052778 0x00000468 LANG_TAMIL SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x02052778 0x00000468 LANG_TAMIL SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x02052778 0x00000468 LANG_TAMIL SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x02052778 0x00000468 LANG_TAMIL SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_STRING 0x020552c8 0x00000714 LANG_TAMIL SUBLANG_DEFAULT data
RT_STRING 0x020552c8 0x00000714 LANG_TAMIL SUBLANG_DEFAULT data
RT_STRING 0x020552c8 0x00000714 LANG_TAMIL SUBLANG_DEFAULT data
RT_ACCELERATOR 0x02052c58 0x00000040 LANG_TAMIL SUBLANG_DEFAULT data
RT_GROUP_CURSOR 0x02054950 0x00000030 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_GROUP_ICON 0x02052be0 0x00000076 LANG_TAMIL SUBLANG_DEFAULT data
RT_VERSION 0x02054980 0x0000025c LANG_NEUTRAL SUBLANG_NEUTRAL data

Imports

Library KERNEL32.dll:
0x423010 LocalCompact
0x423014 EnumCalendarInfoW
0x42301c GetTickCount
0x423020 CreateNamedPipeW
0x423024 GetConsoleAliasesA
0x423028 EnumResourceTypesA
0x42302c GetConsoleCP
0x423030 GlobalAlloc
0x423034 SetFileShortNameW
0x423038 LoadLibraryW
0x42303c IsProcessInJob
0x423040 FatalAppExitW
0x423048 IsBadCodePtr
0x42304c GetModuleFileNameW
0x423050 GetSystemDirectoryA
0x423054 ReplaceFileA
0x423058 GlobalUnlock
0x42305c CreateJobObjectA
0x423060 GetLastError
0x423064 WriteConsoleInputW
0x423068 VerLanguageNameW
0x42306c LoadLibraryA
0x423074 AddAtomW
0x423078 HeapWalk
0x42307c GetOEMCP
0x423080 EnumDateFormatsA
0x423084 GetModuleHandleA
0x42308c EnumResourceNamesA
0x423090 GetFileTime
0x423094 PeekConsoleInputA
0x423098 GetDiskFreeSpaceExA
0x42309c LCMapStringW
0x4230a0 CreateFileW
0x4230a4 HeapSize
0x4230a8 FlushFileBuffers
0x4230ac FindVolumeClose
0x4230b0 HeapCompact
0x4230b4 GetProcAddress
0x4230b8 CreateFileA
0x4230bc GetStringTypeW
0x4230c0 WriteConsoleW
0x4230c4 HeapReAlloc
0x4230c8 GetCommandLineW
0x4230cc HeapSetInformation
0x4230d0 GetStartupInfoW
0x4230d4 DecodePointer
0x4230e0 IsDebuggerPresent
0x4230e4 EncodePointer
0x4230e8 TerminateProcess
0x4230ec GetCurrentProcess
0x4230f0 HeapAlloc
0x4230f4 HeapFree
0x423100 SetHandleCount
0x423104 GetStdHandle
0x42310c GetFileType
0x423114 MultiByteToWideChar
0x423118 ReadFile
0x42311c GetModuleHandleW
0x423120 ExitProcess
0x423124 SetFilePointer
0x423128 HeapCreate
0x42312c WriteFile
0x423138 TlsAlloc
0x42313c TlsGetValue
0x423140 TlsSetValue
0x423144 TlsFree
0x42314c SetLastError
0x423150 GetCurrentThreadId
0x42315c GetCurrentProcessId
0x423164 WideCharToMultiByte
0x423168 GetConsoleMode
0x42316c GetCPInfo
0x423170 GetACP
0x423174 IsValidCodePage
0x423178 Sleep
0x42317c RtlUnwind
0x423180 SetStdHandle
0x423188 CloseHandle
Library USER32.dll:
0x423198 CharUpperBuffA
0x42319c GetMessageExtraInfo
0x4231a0 SetCaretPos
0x4231a4 GetMenu
0x4231a8 DrawStateW
0x4231ac GetSysColorBrush
Library GDI32.dll:
0x423000 GetCharWidthI
0x423004 CreateDCA
0x423008 GetCharABCWidthsI
Library WINHTTP.dll:
0x4231b4 WinHttpOpen
Library MSIMG32.dll:
0x423190 AlphaBlend

!This program cannot be run in DOS mode.
`.rdata
@.data
.fufuc
@.xixeray
VVVVVVVh
PVhpRB
VVVVVVVVVV
u,VVVV
u1VVVVVVh
WuEVVVV
VVVVVVVVVV
HHtXHHt
?If90t
j@j ^V
uht<B
^SSSSS
QQSVWh
Fh=huB
to=H~B
URPQQh
t"SS9] u
v4;5|~B
;t$,v-
UQPXY]Y[
PPPPPPPP
PPPPPPPP
y{#c{^
5Y*z(a
EC}VG4
EC}VG4
k'#f?:
X1|Hrx
2#.6^L7
"%LF~*
y#7zW_
USshYnp[Q
E*b\1m
jz=?i"
jP3@na
ri<aB&
,B*Kff
LACg W|
WyM<P<
$[=~n5
>)+FA
bYW4LpAH{
l.MyPP!
*RlK/|
PDO.lgJ
6#@;NJ
;bZ'{j9:L
W<Ro*SSV
.Byf.-75
p5'L7;
YL%bs0
9JKj\.V
]ip/A_
lS+R>OQ
kA8byI
2}5xGr!5
6o5BsG
*H$:M<
]la"C@
Rc=jfVB
!|FCDZ",
f*CEfC
1TMHtR
|dju0:gUR
4H6puO
!9o!V[
1O6RKh
fZc)9b
2pT$Wt-
#v4h'[
5v01Ce
"^$X~=
p(ZUrc
iP~B1h
T9KA+@-
}u.cgw
"S#6d"
@)1y`+
_ta*Tp
]Fk'i-X
Nc0m<ov
:Zmm8)
HAyIFE
x:=5V
"WEA!M
IFGR%A
KH6L8{h
6fRQB?|
[=^67I
uKMmM6
l9|-8H
!!TN')
#&N@a0O
QOU"^U
n}wY\x`
b}!5G0
o)w]?%
gv:Q5dR@
ysge>+
-C[jd{
Rit~c$
\M? PmTm,h
rq@wN1d@
x-r_>/blyr
+n@8_W;^-
hm\A :
&Pz0W|
Ph"cZm
r6@E}6
U!vnt0
-!qgWe!
0`7fCJl
{PS](
@&@mrb
&0e1N.
%Ar2.8d&?W
8b\zrS
(Vuxv=
,8F!xyX
v?5yK3
~2iuEwhxM*
Pl<.Q'
b`#(j[
]36:F:
<Hee09
Z~(vTsmF
f %uAS
Hs-:;%
.tEc+D
i[S!*z
<tBWu+
V-Lo6$
@[BQ?s
q-3v;;
?e-chH{V9
mWElCK5&
Y*R3zq-
2XY?#b
;6f,bj
,<OJe~
><!s/
e9^.J)
upTyjpe
3>VE[
NQD0MB
BHTLi,p^
H!;n1I
XwK$yz
?)'I8>
wDcv<`.
Ag+'F8
>1!8 \
Z>\+(]b
pek`y_$
dX%{ X
Hg6bU3
2e;n7!
m1GcHYk
3+jTWn
FD<lVXt
I.VXp-T
WZeki~
cx<A^;
=6RA5Y
H)`K1!
}:j\+*
niQhX:0
}kEW~v^
0kr0j7
w&#~4b
S36(_q8_Q
&M|H(_
"-vh{/"
V&%NW6
*:6frEO+
z&/+A9
p!f;$I
Np q~1
>2AtYZ
^G*iooK6
-8`(&_
5+_A_Q(
sZ)Q9#*
BtM9x>
A[D\k5`
Xfk0t
c<NYWI
8iL\EQ
$CHrdW@$
mnn[Mv&
wW,$ior
RT$PF[
[_ab7V
&U"9FT
$GmQlt
Cmjx~N
$NBn=bRY
xg"td8G
?_;W6H
Unknown exception
(null)
`h````
xpxxxx
CorExitProcess
FlsFree
FlsSetValue
FlsGetValue
FlsAlloc
HH:mm:ss
dddd, MMMM dd, yyyy
MM/dd/yy
December
November
October
September
August
February
January
Saturday
Friday
Thursday
Wednesday
Tuesday
Monday
Sunday
`h`hhh
xppwpp
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
Complete Object Locator'
Class Hierarchy Descriptor'
Base Class Array'
Base Class Descriptor at (
Type Descriptor'
`local static thread guard'
`managed vector copy constructor iterator'
`vector vbase copy constructor iterator'
`vector copy constructor iterator'
`dynamic atexit destructor for '
`dynamic initializer for '
`eh vector vbase copy constructor iterator'
`eh vector copy constructor iterator'
`managed vector destructor iterator'
`managed vector constructor iterator'
`placement delete[] closure'
`placement delete closure'
`omni callsig'
delete[]
new[]
`local vftable constructor closure'
`local vftable'
`udt returning'
`copy constructor closure'
`eh vector vbase constructor iterator'
`eh vector destructor iterator'
`eh vector constructor iterator'
`virtual displacement map'
`vector vbase constructor iterator'
`vector destructor iterator'
`vector constructor iterator'
`scalar deleting destructor'
`default constructor closure'
`vector deleting destructor'
`vbase destructor'
`string'
`local static guard'
`typeof'
`vcall'
`vbtable'
`vftable'
operator
delete
__unaligned
__restrict
__ptr64
__eabi
__clrcall
__fastcall
__thiscall
__stdcall
__pascal
__cdecl
__based(
GetProcessWindowStation
GetUserObjectInformationW
GetLastActivePopup
GetActiveWindow
MessageBoxW
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
kernel32.dll
Teduroxeyor natuvamoboram
Hicurufupelimo rohatozuma nufirowoxec pibiv
Miketay zilaxehafusaj xotixiniza dibenun
dekuzaxuhoxiribifohoruxinas
hosigutovujex lolocahedunebutab %f
bad exception
kernel32.dll
VirtualProtect
Wuhusewixig finabizetela xalas womamonumune naviganev
msimg32.dll
CreateFileA
HeapCompact
FindVolumeClose
WriteConsoleInputW
LocalCompact
EnumCalendarInfoW
SetEnvironmentVariableW
GetTickCount
CreateNamedPipeW
GetConsoleAliasesA
EnumResourceTypesA
GetConsoleCP
GlobalAlloc
SetFileShortNameW
LoadLibraryW
IsProcessInJob
FatalAppExitW
AssignProcessToJobObject
IsBadCodePtr
GetModuleFileNameW
GetSystemDirectoryA
ReplaceFileA
GlobalUnlock
CreateJobObjectA
GetLastError
GetProcAddress
VerLanguageNameW
LoadLibraryA
SetConsoleCtrlHandler
AddAtomW
HeapWalk
GetOEMCP
EnumDateFormatsA
GetModuleHandleA
GetProcessShutdownParameters
EnumResourceNamesA
GetFileTime
PeekConsoleInputA
GetDiskFreeSpaceExA
LCMapStringW
KERNEL32.dll
SetCaretPos
GetSysColorBrush
DrawStateW
CharUpperBuffA
GetMenu
GetMessageExtraInfo
USER32.dll
CreateDCA
GetCharWidthI
GetCharABCWidthsI
GDI32.dll
WinHttpOpen
WINHTTP.dll
AlphaBlend
MSIMG32.dll
HeapReAlloc
GetCommandLineW
HeapSetInformation
GetStartupInfoW
DecodePointer
UnhandledExceptionFilter
SetUnhandledExceptionFilter
IsDebuggerPresent
EncodePointer
TerminateProcess
GetCurrentProcess
HeapAlloc
HeapFree
EnterCriticalSection
LeaveCriticalSection
SetHandleCount
GetStdHandle
InitializeCriticalSectionAndSpinCount
GetFileType
DeleteCriticalSection
MultiByteToWideChar
ReadFile
GetModuleHandleW
ExitProcess
SetFilePointer
HeapCreate
WriteFile
FreeEnvironmentStringsW
GetEnvironmentStringsW
TlsAlloc
TlsGetValue
TlsSetValue
TlsFree
InterlockedIncrement
SetLastError
GetCurrentThreadId
InterlockedDecrement
QueryPerformanceCounter
GetCurrentProcessId
GetSystemTimeAsFileTime
WideCharToMultiByte
GetConsoleMode
GetCPInfo
GetACP
IsValidCodePage
RtlUnwind
SetStdHandle
IsProcessorFeaturePresent
WriteConsoleW
GetStringTypeW
FlushFileBuffers
HeapSize
CreateFileW
CloseHandle
.?AVtype_info@@
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
.?AVbad_exception@std@@
.?AVexception@std@@
9;rhU
tJ{HmPzGjM
xM{DzD}Iu?
FwR~M|H
JyN}FbF
GJ|QUV
9S{}IG{
MTz[VL}
t{~DSP~
}DDH{yPE
Kv~}Btz
I;|UMH
|Gj~|>i{{E
=\}qFJ}
J<D|iQW
JC{{LE
SX~yUM
FIz}ZA
ND~{:U
|6G]~zJL}
7Yzu_F|
MT{hc}
IS}Jh}y@
TUdCM6
?EW_NO
?Gx}^NW|
FFJ\@OP}
:H}~We
R^PzpEG
=NVb\Eq|
J?NgJ:
WRxUSK
}uzF{^
JDkf?H}
~JTT|}~
OWvyEQ|{cU
Q}||QC
VJz~d}
||{L{z|Jy
IG~}}|
XG|zS~
AB~|g|}
QKZ?@R}
FK{yPNYl
XVhLMH~}y
I7mjSJ`I?Ik
cL~gw{aQ
At~GM~
ThJzQNJ
J|}ATo~IGJ{{MNz
GKX|{]D
LN{|xz
KFpTKD
SKbsN_~
?Ue|d[
f}}MNz}GT{
z{{J}b
LdgeNJX}
A=HsBDT
iiiiiiii
iiiiiiii
iiiiii
iiiiii
iiiiiiiii
iiiiiiiiii
iiiiiiii
iiiiiii
iiiiiiiii

@(null)
mscoree.dll
runtime error
TLOSS error
SING error
DOMAIN error
- Attempt to use MSIL code from this assembly during native code initialization
This indicates a bug in your application. It is most likely the result of calling an MSIL-compiled (/clr) function from a native constructor or from DllMain.
- not enough space for locale information
- Attempt to initialize the CRT more than once.
This indicates a bug in your application.
- CRT not initialized
- unable to initialize heap
- not enough space for lowio initialization
- not enough space for stdio initialization
- pure virtual function call
- not enough space for _onexit/atexit table
- unable to open console device
- unexpected heap error
- unexpected multithread lock error
- not enough space for thread data
- abort() has been called
- not enough space for environment
- not enough space for arguments
- floating point support not loaded
BMicrosoft Visual C++ Runtime Library
<program name unknown>
Runtime Error!
Program:
KERNEL32.DLL
HH:mm:ss
dddd, MMMM dd, yyyy
MM/dd/yy
December
November
October
September
August
February
January
Saturday
Friday
Thursday
Wednesday
Tuesday
Monday
Sunday
WUSER32.DLL
((((( H
h(((( H
H
CCONOUT$
Mokigehate xolega viricuh mazu fiboy
zewaxuwawazuwuyuvivi
ozofowegad dinomebaxedidox
pajebipew
kernel32.dll
pelapawagetidayiwexuwin
havayekubipacacujoxifupozeko
/ P6pL
,/KPip
/-P?pR
/ P6pL
,/KPip
/-P?pR
/ P6pL
,/KPip
/-P?pR
VS_VERSION_INFO
StringFileInfo
032414E6
FileVersions
5.20.60.11
InternalName
FileDescription
Raining
LegalCopyright
Copyright (C) 2023, Nabisradig
OriginalFilenames
Odilesigo
ProductVersions
76.20.29.97
VarFileInfo
Translation
%Posabi ruvogeloborix bolodumawe wofep
Cihetuc
JYayezawepe lulutuxopir heveriyasemabuh dufo niyaxupedakisir vewejifisadilu
`Degizejumajitu tanatatu nupavijucugonil jimifosaciyi jahepabowuxitu dewumecipitid jage zodeniyod8Wavir madeganiyucamo yakekanohi vibejigowilugo jelayujam
Pufeh suges[Gizavusogupi regajivoyanifon tunetalebibasam zamewoyodite rovezahenurapu fixofid muyenomoma*Kexafevuz pihubajonebos fixugizuyez mosave
Somovetobi miye gigegWihevuh razujiwemabov lusecinuvaha tajiv nabugahixas nomocitunode riyugav rizejiyitihehu pazekepagewari
3Meroxelubule civirizudoge cotoxulohocebar gimefatic
4Xewalazuf dalezofi yojojofu docupazopaw kimipahipule!Jafik kitezatijohupe yoviho kolob
_Bezimicete cinav wuluf puvefufubohowuy hucususimas jucowuwagivun dulujeka camu morahetap lopena
Cuy nigehajosofe
@Siyebesihomixu riki jot kinitohapa nojonopo heme vedusijacix pen
{Lizaboxujowe sonafuxoxonod muhovududefixov dewefipox dubayuwahuyune bejabofomi jogapuk gotukod favinakurorihi mujagujuvuhez Zenagac marulafewoli tuxivayeyuxKKira sosavibo kiza bupufeheci rohifono bulakifiyuwemo voyugabu jokayofofowucSis kowamaga jivo zekekegajic hasozu lacesicokobov ritixuhadi wihumewotefukir towajejufuwe nanarorufVet pelovuxafude sonobabozosocup numugazomumelu dusutoyene limidepoput mahumek zegemipusaxehun penitoh
Tanajupexoxecu sisibila mesedCKaruwucuduj dezawagakowi yogex vosuhiwuzikumo roh mihebi mawuxulici
PiwuviviDBuk zikanez sogewan dewukibis budavugekikivib nevumaviwuwo hun nafehTLamav yelefesavogu koteniso fonadugivedev wozuvovexux delodohos gopipupunabi tufapej9Yogazawimafog xewe hopobijewoxo nupicuh biwadema zoxe nos6Yiweh jagagivawa febegugak sepeyejo rihugu dawegewafig
DMulima xanileboxiviti cezec cilesurozoraj yuyufu yegojeyesapeb xapeg
Gesukel fuhokubucuy buci
Antivirus Signature
Bkav W32.AIDetectMalware
Lionic Trojan.Win32.Convagent.4!c
tehtris Generic.Malware
ClamAV Win.Packer.pkr_ce1a-9980177-0
CMC Clean
CAT-QuickHeal Clean
Skyhigh BehavesLike.Win32.Lockbit.dh
ALYac Clean
Cylance Unsafe
Zillya Clean
Sangfor Trojan.Win32.Save.a
K7AntiVirus Trojan ( 005649fd1 )
Alibaba Clean
K7GW Trojan ( 005649fd1 )
Cybereason Clean
huorong Clean
Baidu Clean
VirIT Clean
Paloalto generic.ml
Symantec ML.Attribute.HighConfidence
Elastic malicious (high confidence)
ESET-NOD32 Clean
APEX Malicious
Avast Win32:PWSX-gen [Trj]
Cynet Malicious (score: 100)
Kaspersky UDS:Trojan-PSW.Win32.Stealerc.gen
BitDefender Clean
NANO-Antivirus Clean
ViRobot Clean
MicroWorld-eScan Clean
Tencent Trojan.Win32.Obfuscated.gen
TACHYON Clean
Sophos Mal/Generic-S
F-Secure Clean
DrWeb Clean
VIPRE Clean
TrendMicro Clean
McAfeeD Real Protect-LS!7E43D787C081
Trapmine malicious.moderate.ml.score
FireEye Generic.mg.7e43d787c0813212
Emsisoft Clean
Ikarus Clean
GData Clean
Jiangmin Clean
Webroot Clean
Varist Clean
Avira Clean
Antiy-AVL Clean
Kingsoft malware.kb.a.1000
Gridinsoft Malware.Win32.Stealc.tr
Xcitium Clean
Arcabit Clean
SUPERAntiSpyware Clean
ZoneAlarm UDS:Trojan-PSW.Win32.Stealerc.gen
Microsoft Trojan:Win32/Wacatac.B!ml
Google Detected
AhnLab-V3 Trojan/Win.SmokeLoader.C5653635
Acronis suspicious
McAfee Artemis!7E43D787C081
MAX Clean
VBA32 Clean
Malwarebytes Trojan.MalPack.GS
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Rising Trojan.SmokeLoader!1.FF9D (CLASSIC)
Yandex Clean
SentinelOne Static AI - Malicious PE
MaxSecure Trojan.Malware.300983.susgen
Fortinet W32/GenKryptik.EWCW!tr
BitDefenderTheta Gen:NN.ZexaF.36810.py0@a4MOmsmG
AVG Win32:PWSX-gen [Trj]
DeepInstinct MALICIOUS
CrowdStrike win/malicious_confidence_100% (W)
alibabacloud Clean
No IRMA results available.