Static | ZeroBOX

PE Compile Time

2023-05-16 13:38:44

PE Imphash

e2f02028d991e1bc184ba49a1bf03bd5

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x000354db 0x00035600 6.56693155476
.rdata 0x00037000 0x000024b0 0x00002600 5.43141276249
.data 0x0003a000 0x000129c8 0x00002600 2.32792521992
.rsrc 0x0004d000 0x001f5028 0x00007200 6.10743276395

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x000525f0 0x00000468 LANG_TURKISH SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x000525f0 0x00000468 LANG_TURKISH SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x000525f0 0x00000468 LANG_TURKISH SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x000525f0 0x00000468 LANG_TURKISH SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x000525f0 0x00000468 LANG_TURKISH SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x000525f0 0x00000468 LANG_TURKISH SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x000525f0 0x00000468 LANG_TURKISH SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_STRING 0x00053c90 0x00000396 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_STRING 0x00053c90 0x00000396 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_STRING 0x00053c90 0x00000396 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_STRING 0x00053c90 0x00000396 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_STRING 0x00053c90 0x00000396 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_STRING 0x00053c90 0x00000396 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_GROUP_ICON 0x00052a58 0x00000068 LANG_TURKISH SUBLANG_DEFAULT data
RT_VERSION 0x00052ac0 0x000001f8 LANG_NEUTRAL SUBLANG_NEUTRAL data

Imports

Library KERNEL32.dll:
0x437000 GetComputerNameA
0x437004 GetFullPathNameA
0x437008 GetDateFormatW
0x437014 OpenJobObjectA
0x437018 UnlockFile
0x43701c GetTimeFormatA
0x437020 GetModuleHandleW
0x437024 GetTickCount
0x437028 FormatMessageA
0x43702c GetSystemTimes
0x437030 GlobalAlloc
0x437034 LoadLibraryW
0x437038 InitAtomTable
0x43703c HeapCreate
0x437044 GetProcAddress
0x43704c GetAtomNameA
0x437050 LoadLibraryA
0x437058 SetCalendarInfoW
0x43705c VirtualLock
0x437060 GetCommMask
0x437064 HeapWalk
0x437068 SetCommMask
0x43706c FoldStringW
0x437070 lstrcatW
0x437078 VirtualProtect
0x43707c EnumDateFormatsW
0x437084 SetFileShortNameA
0x437088 DebugBreak
0x43708c GetModuleHandleA
0x437090 GetStartupInfoW
0x437094 TerminateProcess
0x437098 GetCurrentProcess
0x4370a4 IsDebuggerPresent
0x4370a8 HeapAlloc
0x4370b4 ReadFile
0x4370b8 SetHandleCount
0x4370bc GetStdHandle
0x4370c0 GetFileType
0x4370c4 GetStartupInfoA
0x4370cc TlsGetValue
0x4370d0 TlsAlloc
0x4370d4 TlsSetValue
0x4370d8 TlsFree
0x4370e0 SetLastError
0x4370e4 GetCurrentThreadId
0x4370e8 GetLastError
0x4370f0 Sleep
0x4370f4 HeapSize
0x4370f8 ExitProcess
0x4370fc WriteFile
0x437100 GetModuleFileNameA
0x437104 GetModuleFileNameW
0x43710c GetCommandLineW
0x437110 VirtualFree
0x437114 HeapFree
0x43711c GetCurrentProcessId
0x437124 SetFilePointer
0x437128 WideCharToMultiByte
0x43712c GetConsoleCP
0x437130 GetConsoleMode
0x437134 GetCPInfo
0x437138 GetACP
0x43713c GetOEMCP
0x437140 IsValidCodePage
0x437144 VirtualAlloc
0x437148 HeapReAlloc
0x43714c RtlUnwind
0x437150 MultiByteToWideChar
0x437158 SetStdHandle
0x43715c WriteConsoleA
0x437160 GetConsoleOutputCP
0x437164 WriteConsoleW
0x437168 LCMapStringA
0x43716c LCMapStringW
0x437170 GetStringTypeA
0x437174 GetStringTypeW
0x437178 GetLocaleInfoA
0x43717c FlushFileBuffers
0x437180 CreateFileA
0x437184 CloseHandle
0x437188 RaiseException
Library USER32.dll:
0x437190 InflateRect
0x437194 GetActiveWindow
0x437198 LoadIconA

!This program cannot be run in DOS mode.
`.rdata
@.data
HHtXHHt
>If90t
^F<-uB
<xtX<XtT
j@j ^V
t$hlrC
teh5J@
>=Yt1j
QQSVWh
0A@@Ju
^SSSSS
j"^SSSSS
URPQQh
0SSSSS
0SSSSS
0SSSSS
0WWWWW
AAFFf;
t"SS9]
PPPPPPPP
PPPPPPPP
;t$,v-
UQPXY]Y[
t+WWVPV
+R<\M.
f\#ws%
Eplo6\
)t7h>
Ke+XpO
XpKM\~}y
A=kaxy
7'CSa}
)8 3O:u
&%h,Jg
n/mg/>Cu
*O!8.n
%rq?DY
B>ipo@
+7)Upz
`=hpq1h&
0T\=Z\L
K!5]TY_C-P6
<UQ.["
o4dsN
V)k`8jYx
^bL7zQ
bRNo9i
yXC9];
:73GjA
p|gy}3H
E'd}IX.
{P"{*DOo
DULN<
s;bZT>mE
Fc@na;:
=Y&*EQme
jAUAcfG
4%@=aio
iRF^i+
cH%UsZ;
&~fJg4
OZA@B1<
2Hc6Os
"y[!Z0
b?s0]`
z"u-H
,JG'F'M
q4:yWV
e)-P+Q
sgo Yz
`,jj_HcS
_b{R#'
j/[?zV
i4VgGP
u7=`t2
BuyLKm
sahKs{N
e]_wvq
\)UekM`
.;btAKn
?s-OMHkb
;}l{@w
K$GHz_
`d?,})
/E;t@>C
\xxHB~6
{GHgS<
B?cdQh34
i;U+92
ZY:q-5
`GTmx
Mr9J@V
)Av)(c
;1q%!E
J$s*{K
.LI{G4QHtu^
<5Rr}<M
aQsChm
93.z8n
f'H^;4
a^yw+S
1q^E8u
P6H*jMWN
.`!yo=IH
qAg#it>
t-yZ*O
g^~NOP
3bRKDq
@WHCsW|
Mqq|\O
n6"DzE
/1,CwI
tff@3P
WjokT6
J9i>O9
p&L7Ly
;nKS5a.
)6u79j
YwT%@o
VB<\/L
I)q\TR=T
.TSlQ0H
?FF27z!
v=b4e_
V+&c+j/{|
7Ci/LNk
:ffY#gA
YPGVap
g9\NZ6N
1L%%IJ
K7a'5j
WI%1]E
%P{G.9
!VJSr}
"=m65%
(V,SRyf
*?''53
K$KIgL
rH+`SQ
cQ\WD]
yOWN]l
1tI+9b
=7L,vs
8-(S+$=[:B
{Ypq3?+
5\#x3O=
/wPdF}U4
_@@]|M
F\t1&P
YnEYzu
z[o))Dz
]w;6PZb
iE%X!$
i%+!xf8
m 9e7xt:1
p=N@-f
X[&W-?
T]Ji1U
-wLe=`
U+Q&x[
mlJ")>k5
c,9V;v
v/!kG}V}-
r5l71c_
?hRDv1
y<& ,X
HTw.$x
gm,:U|
VdA$:z
|)%\.4<
|a0tI
kLtu"
+CoP1qI$
SGr Y~m
n3{b0Yg
8W=cC(
(N7+}8
)CCCIVp
USKx D
3fvamn!
mB3%+`x
(95:s~
x6>"i_
Nu=zR;
tD"s/L
\vA^;<
Ak)(6|%'
OC'<Z%
7F4Su*
_VVVVV
^WWWWW
0SSSSS
_VVVVV
tRHtCHt4Ht%HtFHHt
<+t(<-t$:
+t HHt
(null)
`h````
xpxxxx
EncodePointer
DecodePointer
FlsFree
FlsSetValue
FlsGetValue
FlsAlloc
CorExitProcess
runtime error
TLOSS error
SING error
DOMAIN error
An application has made an attempt to load the C runtime library incorrectly.
Please contact the application's support team for more information.
- Attempt to use MSIL code from this assembly during native code initialization
This indicates a bug in your application. It is most likely the result of calling an MSIL-compiled (/clr) function from a native constructor or from DllMain.
- not enough space for locale information
- Attempt to initialize the CRT more than once.
This indicates a bug in your application.
- CRT not initialized
- unable to initialize heap
- not enough space for lowio initialization
- not enough space for stdio initialization
- pure virtual function call
- not enough space for _onexit/atexit table
- unable to open console device
- unexpected heap error
- unexpected multithread lock error
- not enough space for thread data
This application has requested the Runtime to terminate it in an unusual way.
Please contact the application's support team for more information.
- not enough space for environment
- not enough space for arguments
- floating point support not loaded
Microsoft Visual C++ Runtime Library
<program name unknown>
Runtime Error!
Program:
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
`h`hhh
xppwpp
GetProcessWindowStation
GetUserObjectInformationA
GetLastActivePopup
GetActiveWindow
MessageBoxA
USER32.DLL
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
HH:mm:ss
dddd, MMMM dd, yyyy
MM/dd/yy
December
November
October
September
August
February
January
Saturday
Friday
Thursday
Wednesday
Tuesday
Monday
Sunday
CONOUT$
SunMonTueWedThuFriSat
JanFebMarAprMayJunJulAugSepOctNovDec
bad allocation
rivarixux lofoxu hexekavoga fucuwotahokariz
litozefalefenedunonuzokarizej
forenupavap
%s %f %c
msimg32.dll
GAIsProcessorFeaturePresent
KERNEL32
1#QNAN
1#SNAN
?_nextafter
_hypot
GetComputerNameA
GetFullPathNameA
GetDateFormatW
GetNumaProcessorNode
GetProcessIoCounters
OpenJobObjectA
UnlockFile
GetTimeFormatA
GetModuleHandleW
GetTickCount
FormatMessageA
GetSystemTimes
GlobalAlloc
LoadLibraryW
InitAtomTable
HeapCreate
FlushInstructionCache
GetProcAddress
GetNumaHighestNodeNumber
GetAtomNameA
LoadLibraryA
InterlockedExchangeAdd
SetCalendarInfoW
VirtualLock
GetCommMask
HeapWalk
SetCommMask
FoldStringW
lstrcatW
FreeEnvironmentStringsW
VirtualProtect
EnumDateFormatsW
GetConsoleCursorInfo
SetFileShortNameA
DebugBreak
KERNEL32.dll
GetActiveWindow
InflateRect
LoadIconA
USER32.dll
GetStartupInfoW
TerminateProcess
GetCurrentProcess
UnhandledExceptionFilter
SetUnhandledExceptionFilter
IsDebuggerPresent
HeapAlloc
EnterCriticalSection
LeaveCriticalSection
ReadFile
SetHandleCount
GetStdHandle
GetFileType
GetStartupInfoA
DeleteCriticalSection
TlsGetValue
TlsAlloc
TlsSetValue
TlsFree
InterlockedIncrement
SetLastError
GetCurrentThreadId
GetLastError
InterlockedDecrement
HeapSize
ExitProcess
WriteFile
GetModuleFileNameA
GetModuleFileNameW
GetEnvironmentStringsW
GetCommandLineW
VirtualFree
HeapFree
QueryPerformanceCounter
GetCurrentProcessId
GetSystemTimeAsFileTime
SetFilePointer
WideCharToMultiByte
GetConsoleCP
GetConsoleMode
GetCPInfo
GetACP
GetOEMCP
IsValidCodePage
VirtualAlloc
HeapReAlloc
RtlUnwind
MultiByteToWideChar
InitializeCriticalSectionAndSpinCount
SetStdHandle
WriteConsoleA
GetConsoleOutputCP
WriteConsoleW
LCMapStringA
LCMapStringW
GetStringTypeA
GetStringTypeW
GetLocaleInfoA
FlushFileBuffers
CreateFileA
CloseHandle
GetModuleHandleA
RaiseException
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
cIHHIKBBFCDFFE
b=C;(>A;
c')=($;;(;
f)";%:?
d)4((=4
]3'$*
J4"" =&':;;>>%
*>;>)&<
+)((');
''4(**>&>?&
b1-3 1$#
;(==;;
^++,/- 4$#%':<;)(
,1/3)!)(%(<'&H
f+100## ++)!'$=(
1 ',*;';=
jS6.0-
24+ ""'$ &=H
rXVO-.+1
rVVVS5N0+,1
gMYPYUVS735
43"36(H
sQXSS7T7SVHZ8867H9I
gQOMNRO8P5P68V7T9ZI
pQMXRM57OTOTP7HT8@Z
oQMMMRO5NPP6S5@SH@9
MNM/0/-6O55T
M0--L5-5N2-6
..+.+8
nnoqqeegrsrqrrr{|v
ppfiggirjljk
s8:"9
u)./#/
/*+!B
NR45K01
IPQRRQ3W,M1X
wHIL4LMLOL4=Y
HJ-KJ-3244X
E)*,,,/1.S
),FH.11T
ln|i~mn~~~s
uunornoh|lqjsif
l_MN_O`Pea
^1)*--
[?<;:
S<8<>>9%$2
U77:&#$#"D
cYTUTHGFGI
qvnnfnlmngg~gn
tiLTWkmjzfbwN}
Q@675<?r
h8*-34:
paPZvc
xoOeUdSXJ
C(null)
KERNEL32.DLL
mscoree.dll
((((( H
h(((( H
H
texeholiturafayeroj
naxujamoletobevijihupodaji
VS_VERSION_INFO
StringFileInfo
040501E2
FileVersions
25.91.63
ProductVercion
105.51.38.61
InternalName
Chocolatado
LegalCopyrights
Landing
CompanyNames
Successful
VarFileInfo
Translation
Vec papupot miba0Piwihadimimepe johepohocalowur bifu lepevovopesa
%Vazesalulobimon mit bumu sowobafenumu.Bilaz ritimog sesixoco tuxarumegaxo pajoyusuha/Denorigusejuj gizecewiwedo jipotuc sawihaziwisu
Marufufulejiyi punayiv
Weva rumi kofalute
Miforawip
CTejamivuxezuke ruvapexirotas fukisaminu tavobasebote wuyudozawomopo
Divekuhot boh jajiwayiy
Yodusalupir zaxafojufJCucebomovesaf kutakebigi gahey ras noherutozemo duhuyecexuce wesezesotideg
Yopadesaf royinokahugabXok xumev sabawehurutife hoj zufapupatobeya zupohehixuci puhucigipusetop huzu levozivi muyuhisinep
Kuharetisog cukiva tote bitic0Wosari fafubuhaz kumokapabilawi bosixozawe pusiw
KusocemibadHZumoza lesamezurubat raroyiga jutib sugotiyadukig domitepanen nek kafinu%Zisefeyi rosojoxiyucihut rawalopatoduISozapapavune xur zuhemu weviwuxakoyezi kafebebiyek zin matexakakab cebikooBebayohejaxe kucog xorufeda jigekelis hadaxalalawanu suruzababa libuket paviboguyela tecuracone jelofelufezafog
Keyepomeb kunesenucok
Gobakis neho"Sevufajuhamicay zekezocedaco bexir
+Xitodic lixi vus juy pagimeviriro tekipazey
Wot cekebu#Vomewudenutavu yadabinezuz gis lemitLuwofotirer xanebulofixagoc voyewowano fupiwaragebofen derivezis dilejad rimapomoce segojabirelaboz cipona vaxejaxoj<Nonusujenazu sutecovudixot rafalahajanoro biduposonixi hatuf
Behan giwex mitepojulajavuz
Mibazoj rukem juhakuyugokeli:Dehenotutarac tum lisocidi zomu wowevotalokuma ceko pipomabGiduhagezup weduwimodumib pebelo zawo nufecucakuhami cocahi xehiwicosuheso lejafacaki jazojenuvohi5Nujefoyepatabor coyovubunaconu bodoy molen wixusuhema
Kapeh jejoyapaxulige soj3Gubaloxuwe cibocewalutin mimalimokofovad tedifopabe5Fep gitul jule tejuje xusi tigukasosi finegiyadi jusopNufosazigonisev seyululogiluyuz duxonomibago tox wunizuni kiwizofa lapepetarodi sixekesewovira rafuzuxusuwog zusnGaxofomupawezu gocamevusa dirako rodanelonerikeg nocesexecerumu sec gucenopocodaki gubolepumen patemizobupuhekDRoyumisiyot met xavapizex letuja fitunepehak cisijex rarocezidohuvep
DWelativi teba weleyisoleteceg wubuhapinodud cuvubosuzepo zubupuxalosMFegibu mekovozetufup red roteyure rocugace nohulagoduca yobeh zojebebu poloveRGopux tejocozoxa fowayipapacim vawugocizizeyax foy laxigepecowizul pexegaliwukiyar
Heze jugucu yapoy8Riyijusoyofow zakalafusodok lepa ramohimepizice binenosoZXunexux cesamobuwe leneru xenimac figolabecit rudaxazedizus lisixabapidi diniv yinoyij tow5Rinucajihim cudefef rolowigucoja melekudalira botofay
Antivirus Signature
Bkav W32.AIDetectMalware
Lionic Trojan.Win32.Stealerc.1m!c
tehtris Clean
ClamAV Win.Ransomware.Convagent-10034455-0
CMC Clean
CAT-QuickHeal Ransom.Stop.P5
Skyhigh BehavesLike.Win32.Lockbit.dh
McAfee Clean
Cylance Unsafe
Zillya Clean
Sangfor Trojan.Win32.Save.a
K7AntiVirus Clean
Alibaba Trojan:Win32/Stealc.c8c43939
K7GW Hacktool ( 700007861 )
Cybereason Clean
huorong Clean
Baidu Clean
VirIT Clean
Paloalto generic.ml
Symantec ML.Attribute.HighConfidence
Elastic malicious (high confidence)
ESET-NOD32 Win32/Stealc.A
APEX Malicious
Avast Win32:PWSX-gen [Trj]
Cynet Malicious (score: 100)
Kaspersky HEUR:Trojan-PSW.Win32.Stealerc.gen
BitDefender Clean
NANO-Antivirus Clean
ViRobot Trojan.Win.Z.Stealerc.268288
MicroWorld-eScan Clean
Tencent Clean
TACHYON Clean
Sophos Mal/Generic-S
F-Secure Trojan.TR/AD.Stealc.yteee
DrWeb Clean
VIPRE Clean
TrendMicro Trojan.Win32.PRIVATELOADER.YXEHHZ
McAfeeD Real Protect-LS!9B43256A3314
Trapmine malicious.moderate.ml.score
FireEye Generic.mg.9b43256a33142e46
Emsisoft Clean
Ikarus Win32.Outbreak
GData Win32.Packed.Kryptik.9KK0MI
Jiangmin Clean
Webroot Clean
Varist W32/Kryptik.MOY.gen!Eldorado
Avira TR/AD.Stealc.yteee
Antiy-AVL Clean
Kingsoft Win32.Trojan-PSW.Stealerc.gen
Gridinsoft Ransom.Win32.Sabsik.sa
Xcitium Clean
Arcabit Clean
SUPERAntiSpyware Clean
ZoneAlarm HEUR:Trojan-PSW.Win32.Stealerc.gen
Microsoft Trojan:Win32/Smokeloader.NEE!MTB
Google Detected
AhnLab-V3 Trojan/Win.Generic.R660479
Acronis suspicious
BitDefenderTheta Gen:NN.ZexaF.36810.qq0@aCBV2VmG
MAX Clean
VBA32 BScope.Trojan.Yakes
Malwarebytes Generic.Malware/Suspicious
Panda Clean
Zoner Clean
TrendMicro-HouseCall Trojan.Win32.PRIVATELOADER.YXEHHZ
Rising Trojan.Kryptik@AI.100 (RDML:iFEku3AJLN2kOlbeLLAH8Q)
Yandex Clean
SentinelOne Static AI - Suspicious PE
MaxSecure Clean
Fortinet W32/Stealc.A!tr
AVG Win32:PWSX-gen [Trj]
DeepInstinct MALICIOUS
CrowdStrike win/malicious_confidence_100% (W)
alibabacloud Clean
No IRMA results available.