Static | ZeroBOX

PE Compile Time

2024-11-01 08:07:14

PE Imphash

7541e37d15e5e332b2a83de6c13bfcc2

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x000192dc 0x00019400 6.49703588424
.rdata 0x0001b000 0x000138a8 0x00013a00 6.14866486589
.data 0x0002f000 0x00002964 0x00001800 5.63657019989
.pdata 0x00032000 0x00001500 0x00001600 5.0074140138
.rsrc 0x00034000 0x000001e0 0x00000200 4.71767883295
.reloc 0x00035000 0x000006a8 0x00000800 4.98481438324

Resources

Name Offset Size Language Sub-language File type
RT_MANIFEST 0x00034060 0x0000017d LANG_ENGLISH SUBLANG_ENGLISH_US XML 1.0 document text

Imports

Library ntdll.dll:
0x14001b318 RtlLookupFunctionEntry
0x14001b320 RtlVirtualUnwind
0x14001b328 ZwClose
0x14001b330 RtlCaptureContext
0x14001b338 RtlUnwindEx
0x14001b340 ZwWaitForSingleObject
0x14001b348 NtWaitForSingleObject
0x14001b350 NtWriteFile
0x14001b358 ZwReadFile
0x14001b360 ZwQueryInformationFile
0x14001b368 NtQueryAttributesFile
0x14001b370 ZwOpenFile
0x14001b378 ZwSetInformationFile
0x14001b380 RtlPcToFileHeader
Library KERNEL32.dll:
0x14001b038 LCMapStringW
0x14001b040 WriteConsoleW
0x14001b048 GetLastError
0x14001b050 WaitForMultipleObjects
0x14001b058 CreateThread
0x14001b060 GetLogicalDrives
0x14001b068 OutputDebugStringA
0x14001b070 OutputDebugStringW
0x14001b078 CloseHandle
0x14001b080 FindClose
0x14001b088 FindFirstFileW
0x14001b090 FindNextFileW
0x14001b098 MoveFileW
0x14001b0a0 GlobalAlloc
0x14001b0a8 GlobalFree
0x14001b0b0 CreateFileW
0x14001b0b8 WaitForSingleObject
0x14001b0c0 CreateProcessW
0x14001b0d8 lstrcpyW
0x14001b0e0 GetCurrentProcessId
0x14001b0e8 TerminateProcess
0x14001b0f0 GetConsoleMode
0x14001b0f8 GetConsoleOutputCP
0x14001b100 FlushFileBuffers
0x14001b108 HeapReAlloc
0x14001b110 FlsFree
0x14001b118 FlsSetValue
0x14001b120 FlsGetValue
0x14001b128 FlsAlloc
0x14001b130 GetProcessHeap
0x14001b138 SetStdHandle
0x14001b140 GetStringTypeW
0x14001b148 SetFilePointerEx
0x14001b150 GetNativeSystemInfo
0x14001b158 GetStartupInfoW
0x14001b160 FreeEnvironmentStringsW
0x14001b168 GetEnvironmentStringsW
0x14001b170 WideCharToMultiByte
0x14001b178 MultiByteToWideChar
0x14001b180 GetCommandLineW
0x14001b188 GetCommandLineA
0x14001b190 HeapSize
0x14001b198 IsDebuggerPresent
0x14001b1a0 UnhandledExceptionFilter
0x14001b1b0 GetCPInfo
0x14001b1c0 GetModuleHandleW
0x14001b1c8 QueryPerformanceCounter
0x14001b1d0 GetCurrentThreadId
0x14001b1d8 GetSystemTimeAsFileTime
0x14001b1e0 InitializeSListHead
0x14001b1e8 RaiseException
0x14001b1f0 SetLastError
0x14001b1f8 EnterCriticalSection
0x14001b200 LeaveCriticalSection
0x14001b208 DeleteCriticalSection
0x14001b218 TlsAlloc
0x14001b220 TlsGetValue
0x14001b228 TlsSetValue
0x14001b230 TlsFree
0x14001b238 FreeLibrary
0x14001b240 GetProcAddress
0x14001b248 LoadLibraryExW
0x14001b250 EncodePointer
0x14001b258 GetCurrentProcess
0x14001b260 ExitProcess
0x14001b268 GetModuleHandleExW
0x14001b270 GetModuleFileNameW
0x14001b278 GetStdHandle
0x14001b280 WriteFile
0x14001b288 HeapFree
0x14001b290 HeapAlloc
0x14001b298 GetFileType
0x14001b2a0 FindFirstFileExW
0x14001b2a8 IsValidCodePage
0x14001b2b0 GetACP
0x14001b2b8 GetOEMCP
Library USER32.dll:
0x14001b308 wsprintfW
Library ole32.dll:
0x14001b390 CoInitializeSecurity
0x14001b398 CoInitializeEx
0x14001b3a0 CoUninitialize
0x14001b3a8 CoSetProxyBlanket
0x14001b3b0 CoCreateInstance
Library OLEAUT32.dll:
0x14001b2e8 SysAllocString
0x14001b2f0 VariantInit
0x14001b2f8 VariantClear
Library ADVAPI32.dll:
0x14001b000 CryptEncrypt
0x14001b008 CryptImportKey
0x14001b010 CryptGenRandom
0x14001b018 CryptDestroyKey
0x14001b020 CryptReleaseContext
0x14001b028 CryptAcquireContextA
Library MPR.dll:
0x14001b2c8 WNetOpenEnumW
0x14001b2d0 WNetEnumResourceW
0x14001b2d8 WNetCloseEnum

!This program cannot be run in DOS mode.
`.rdata
@.data
.pdata
@.rsrc
@.reloc
x AVAWI
|$0A_A^
UATAUAVAWH
H+L$PH
gfffffffH
gfffffff
H+L$PH
A_A^A]A\]
WAVAWH
A_A^_
` UAVAWH
\$ UVWATAUAVAWH
A_A^A]A\_^]
L$ SVW
L$ SVW
L$ SUVWH
L$ SUVWH
UATAUAVAWH
]'fD9#t
A_A^A]A\]
WAVAWH
SUVWATAUAVAWH
hA_A^A]A\_^][
H9.vCH
PfA9;t
L$ VWAVH
x UATAUAVAWH
A_A^A]A\]
UATAUAVAWH
D9D$0v
D$PfD9
A_A^A]A\]
t$Pf91t
@USVWAWH
A__^[]
u/HcH<H
WATAUAVAWH
A_A^A]A\_
WATAUAVAWH
A_A^A]A\_
VWATAVAWH
A_A^A\_^
WATAUAVAWH
A_A^A]A\_
H;xXu5
AUAVAWH
u4I9}(
;I9}(tiH
0A_A^A]
UVWATAUAVAWH
`A_A^A]A\_^]
@USVWATAUAVAWH
A_A^A]A\_^[]
UVWATAUAVAWH
A_A^A]A\_^]
@SVWATAUAVAWH
L!|$(L!
D$0HcH
pA_A^A]A\_^[
B(I9A(u
SVWATAUAVAWH
0A_A^A]A\_^[
t$ WATAUAVAWH
A_A^A]A\_
WATAUAVAWH
0A_A^A]A\_
UVWATAUAVAWH
ryf;\$l
ref;\$t
rQf;\$|
f;\$4r
f;\$<r
f;\$Dr
r|f;\$l
rhf;\$t
rTf;\$|
A_A^A]A\_^]
S(HcS0
S(HcS0
S(HcS0
S(HcS0
S(HcS0
S(HcS0
D$@H;F
D$@H;F
kL@8o(u
<htl<jt\<lt4<tt$<wt
|$ UATAUAVAWH
A_A^A]A\]
t$ WATAUAVAWH
|T4fD;
c@D9kHtkH
l$0Lc@
A_A^A]A\_
D$18F(u
WAVAWH
A_A^_
@USVWATAVAWH
A_A^A\_^[]
@USVWATAVAWH
A_A^A\_^[]
u3HcH<H
WATAUAVAWH
A_A^A]A\_
UVWAVAWH
0A_A^_^]
WAVAWH
A_A^_
WAVAWH
A_A^_
p0R^G'
D$0@8{
p*W4H
p*W4H
t$ WATAUAVAWH
gfffffffH
A_A^A]A\_
{ AUAVAWH
0A_A^A]
t$xt*3
WAVAWH
A_A^_
x ATAVAWH
A_A^A\
L$ VWAVH
fD94H}aD
fD9t$b
u$D8r(t
D81uUL9r
uED8r(t
vAD8s(t
u$D8r(t
fD91uTL9r
uED8r(t
v@D8s(t
UVWATAUAVAWH
PA_A^A]A\_^]
WATAUAVAWH
0A_A^A]A\_
H9>u+A
@USVWATAUAVH
D8t$ht
D8t$ht
A^A]A\_^[]
f9)u4H9j
u%@8j(t
l$ VWATAVAWH
L$&8\$&t,8Y
A_A^A\_^
WATAUAVAWH
A_A^A]A\_
p0R^G'
t$ WATAUAVAWH
D!|$xA
A_A^A]A\_
L$ VWAVH
@UATAUAVAWH
e0A_A^A]A\]
SUVWATAVAWH
A_A^A\_^][
@USVWATAVAWH
A_A^A\_^[]
WATAUAVAWH
0A_A^A]A\_
ATAUAVH
L$ fff
L$ |+L;
A^A]A\
@UATAUAVAWH
A_A^A]A\]
WAVAWH
A_A^_
UVWATAUAVAWH
fB9<I}1L
A_A^A]A\_^]
VWATAVAW
A_A^A\_^
VATAUAVAWH
0A_A^A]A\^
@USVWATAUAVAWH
H!D$ H
xA_A^A]A\_^[]
ffffff
fffffff
@SUVWATAVAWH
@A_A^A\_^][
ATAVAWH
A_A^A\
USVWAVH
A^_^[]
LcA<E3
fffffff
ffffff
vKfffff
fffffff
fffffff
WinMain
Code1: %d. error %d
Code2: %d. error %d
Detected attribute read only.
encryptPrepare
Failed to open file.
ZwSetInformationFile failed.
Failed to open file for encrypt. Error: %d
Failed to get entropy for key
initKeyHeader
Failed to get entropy for nonce
Failed to encrypt key header
writeKeyHeader
Failed to write keydata. Error: %d
Failed to open file for encrypt.
FileCrypt::encryptFile
File information query failed.
File is small.
Failed to allocate buffer.
Failed to initialize key header.
Failed to read file. Error: %d
Failed to write file. Error: %d
Failed to write key header. Error: %d
Failed to initialize crypto api.
CoreService::getCryptoProvider
[%s] %s
CryptImportKey failed with error: %d
CryptoApi::importPublic
CryptAcquireContextA failed with error: %d
CryptoApi::init
Failed to encrypt with error: %d
CryptoApi::encrypt
Allocation failed
buildObjectAttributes
Failed to build object attributes
Fs::getFileAttributes
Fs::open
expand 32-byte k
expand 16-byte k
D7q/;M
Detected restricted extension!
processFile
Some error
processDirectoryInternal
DecryptInstruction::emplaceInstruction
Failed to write instruction note
Unknown exception
bad allocation
bad array new length
__based(
__cdecl
__pascal
__stdcall
__thiscall
__fastcall
__vectorcall
__clrcall
__eabi
__swift_1
__swift_2
__swift_3
__ptr64
__restrict
__unaligned
restrict(
delete
operator
`vftable'
`vbtable'
`vcall'
`typeof'
`local static guard'
`string'
`vbase destructor'
`vector deleting destructor'
`default constructor closure'
`scalar deleting destructor'
`vector constructor iterator'
`vector destructor iterator'
`vector vbase constructor iterator'
`virtual displacement map'
`eh vector constructor iterator'
`eh vector destructor iterator'
`eh vector vbase constructor iterator'
`copy constructor closure'
`udt returning'
`local vftable'
`local vftable constructor closure'
new[]
delete[]
`omni callsig'
`placement delete closure'
`placement delete[] closure'
`managed vector constructor iterator'
`managed vector destructor iterator'
`eh vector copy constructor iterator'
`eh vector vbase copy constructor iterator'
`dynamic initializer for '
`dynamic atexit destructor for '
`vector copy constructor iterator'
`vector vbase copy constructor iterator'
`managed vector copy constructor iterator'
`local static thread guard'
operator ""
operator co_await
operator<=>
Type Descriptor'
Base Class Descriptor at (
Base Class Array'
Class Hierarchy Descriptor'
Complete Object Locator'
`anonymous namespace'
FlsAlloc
FlsFree
FlsGetValue
FlsSetValue
InitializeCriticalSectionEx
bad exception
(null)
CorExitProcess
NAN(SNAN)
nan(snan)
NAN(IND)
nan(ind)
Sunday
Monday
Tuesday
Wednesday
Thursday
Friday
Saturday
January
February
August
September
October
November
December
MM/dd/yy
dddd, MMMM dd, yyyy
HH:mm:ss
AreFileApisANSI
LCMapStringEx
LocaleNameToLCID
AppPolicyGetProcessTerminationMethod
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
[aOni*{
~ $s%r
@b;zO]
v2!L.2
1#QNAN
1#SNAN
UUUUUU
UUUUUU
=imb;D
/>58d%
VM>cQ6
>jtm}S
)>6{1n
+f)>0'
;H9>&X
*StO9>T
n03>Pu
K~Je#>!
bp(=>?g
BC?>6t9^
K&>.yC
.xJ>Hf
y\PD>!
|b=})>
c [1>H'
uzKs@>
3>N;kU
kE>fvw
V6E>`"(5
?UUUUUU
?7zQ6$
.text$di
.text$mn
.text$mn$00
.text$mn$21
.text$x
.text$yd
.idata$5
.00cfg
.CRT$XCA
.CRT$XCAA
.CRT$XCU
.CRT$XCZ
.CRT$XIA
.CRT$XIAA
.CRT$XIAC
.CRT$XIC
.CRT$XIZ
.CRT$XPA
.CRT$XPX
.CRT$XPXA
.CRT$XPZ
.CRT$XTA
.CRT$XTZ
.rdata
.rdata$00
.rdata$r
.rdata$voltmd
.rdata$zzzdbg
.rtc$IAA
.rtc$IZZ
.rtc$TAA
.rtc$TZZ
.xdata
.xdata$x
.idata$2
.idata$3
.idata$4
.idata$6
.data$r
.data$rs
.pdata
.rsrc$01
.rsrc$02
ZwClose
ZwSetInformationFile
ZwOpenFile
NtQueryAttributesFile
ZwQueryInformationFile
ZwReadFile
NtWriteFile
NtWaitForSingleObject
ZwWaitForSingleObject
ntdll.dll
GetLastError
WaitForMultipleObjects
CreateThread
GetLogicalDrives
OutputDebugStringA
OutputDebugStringW
CloseHandle
FindClose
FindFirstFileW
FindNextFileW
MoveFileW
GlobalAlloc
GlobalFree
CreateFileW
WaitForSingleObject
CreateProcessW
GetNativeSystemInfo
Wow64DisableWow64FsRedirection
Wow64RevertWow64FsRedirection
lstrcpyW
GetCurrentProcessId
TerminateProcess
KERNEL32.dll
wsprintfW
USER32.dll
CoUninitialize
CoInitializeEx
CoInitializeSecurity
CoSetProxyBlanket
CoCreateInstance
ole32.dll
OLEAUT32.dll
CryptAcquireContextA
CryptReleaseContext
CryptDestroyKey
CryptGenRandom
CryptImportKey
CryptEncrypt
ADVAPI32.dll
WNetOpenEnumW
WNetEnumResourceW
WNetCloseEnum
MPR.dll
RtlCaptureContext
RtlLookupFunctionEntry
RtlVirtualUnwind
RtlUnwindEx
RtlPcToFileHeader
IsDebuggerPresent
UnhandledExceptionFilter
SetUnhandledExceptionFilter
GetStartupInfoW
IsProcessorFeaturePresent
GetModuleHandleW
QueryPerformanceCounter
GetCurrentThreadId
GetSystemTimeAsFileTime
InitializeSListHead
RaiseException
SetLastError
EnterCriticalSection
LeaveCriticalSection
DeleteCriticalSection
InitializeCriticalSectionAndSpinCount
TlsAlloc
TlsGetValue
TlsSetValue
TlsFree
FreeLibrary
GetProcAddress
LoadLibraryExW
EncodePointer
GetCurrentProcess
ExitProcess
GetModuleHandleExW
GetModuleFileNameW
GetStdHandle
WriteFile
HeapFree
HeapAlloc
GetFileType
FindFirstFileExW
IsValidCodePage
GetACP
GetOEMCP
GetCPInfo
GetCommandLineA
GetCommandLineW
MultiByteToWideChar
WideCharToMultiByte
GetEnvironmentStringsW
FreeEnvironmentStringsW
FlsAlloc
FlsGetValue
FlsSetValue
FlsFree
LCMapStringW
GetProcessHeap
SetStdHandle
GetStringTypeW
SetFilePointerEx
HeapSize
HeapReAlloc
FlushFileBuffers
GetConsoleOutputCP
GetConsoleMode
WriteConsoleW
IDLuR0
wJ6Z9B
LOMiWz
@/1Z]f/
}c3YZk|
{!*|oEa
r8xqay
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
.?AVbad_alloc@std@@
.?AVexception@std@@
.?AVbad_array_new_length@std@@
.?AVbad_exception@std@@
.?AVtype_info@@
<?xml version='1.0' encoding='UTF-8' standalone='yes'?>
<assembly xmlns='urn:schemas-microsoft-com:asm.v1' manifestVersion='1.0'>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v3">
<security>
<requestedPrivileges>
<requestedExecutionLevel level='asInvoker' uiAccess='false' />
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
Start share: %s
s[%hs] %s
$recycle.bin
system volume information
windows
perflogs
.cache
microsoft
Mozilla*
Google*
Windows*
desktop.ini
Failed to move file! Original: %s, New path: %s
DECRYPT-INSTRUCTION.txt
Create instruction note: %s
Failed to create instruction note: %s. err %d
__ProviderArchitecture
ROOT\CIMV2
SELECT * FROM Win32_ShadowCopy
cmd.exe /c C:\Windows\System32\wbem\WMIC.exe shadowcopy where "ID='%s'" delete
api-ms-win-core-fibers-l1-1-1
api-ms-win-core-synch-l1-2-0
kernel32
api-ms-
(null)
mscoree.dll
Sunday
Monday
Tuesday
Wednesday
Thursday
Friday
Saturday
January
February
August
September
October
November
December
MM/dd/yy
dddd, MMMM dd, yyyy
HH:mm:ss
api-ms-win-core-datetime-l1-1-1
api-ms-win-core-file-l1-2-4
api-ms-win-core-file-l1-2-2
api-ms-win-core-localization-l1-2-1
api-ms-win-core-localization-obsolete-l1-2-0
api-ms-win-core-processthreads-l1-1-2
api-ms-win-core-string-l1-1-0
api-ms-win-core-sysinfo-l1-2-1
api-ms-win-core-winrt-l1-1-0
api-ms-win-core-xstate-l2-1-0
api-ms-win-rtcore-ntuser-window-l1-1-0
api-ms-win-security-systemfunctions-l1-1-0
ext-ms-win-ntuser-dialogbox-l1-1-0
ext-ms-win-ntuser-windowstation-l1-1-0
advapi32
kernelbase
api-ms-win-appmodel-runtime-l1-1-2
user32
ext-ms-
((((( H
zh-CHS
az-AZ-Latn
uz-UZ-Latn
kok-IN
syr-SY
div-MV
quz-BO
sr-SP-Latn
az-AZ-Cyrl
uz-UZ-Cyrl
quz-EC
sr-SP-Cyrl
quz-PE
smj-NO
bs-BA-Latn
smj-SE
sr-BA-Latn
sma-NO
sr-BA-Cyrl
sma-SE
sms-FI
smn-FI
zh-CHT
az-az-cyrl
az-az-latn
bs-ba-latn
div-mv
kok-in
quz-bo
quz-ec
quz-pe
sma-no
sma-se
smj-no
smj-se
smn-fi
sms-fi
sr-ba-cyrl
sr-ba-latn
sr-sp-cyrl
sr-sp-latn
syr-sy
uz-uz-cyrl
uz-uz-latn
zh-chs
zh-cht
CONOUT$
You are stupid idiot
Your files have been encrypted with strong algorithm.
Antivirus Signature
Bkav W64.AIDetectMalware
Lionic Trojan.Win32.Agent.Y!c
Elastic malicious (high confidence)
ClamAV Clean
CMC Clean
CAT-QuickHeal TrojanRansom.Agent
Skyhigh BehavesLike.Win64.NetLoader.ch
ALYac Trojan.GenericKD.74635134
Cylance Unsafe
Zillya Clean
CrowdStrike win/malicious_confidence_90% (D)
Alibaba Trojan:Win64/Filecoder.2194c8e5
K7GW Trojan ( 005bce751 )
K7AntiVirus Trojan ( 005bce751 )
huorong Clean
Baidu Clean
VirIT Trojan.Win64.Agent.FZG
Paloalto generic.ml
Symantec ML.Attribute.HighConfidence
tehtris Clean
ESET-NOD32 a variant of Win64/Filecoder.QF
APEX Malicious
Avast Win64:MalwareX-gen [Trj]
Cynet Malicious (score: 100)
Kaspersky HEUR:Trojan-Ransom.Win32.Agent.gen
BitDefender Trojan.GenericKD.74635134
NANO-Antivirus Clean
ViRobot Clean
MicroWorld-eScan Trojan.GenericKD.74635134
Tencent Clean
Sophos Mal/Generic-S
F-Secure Trojan.TR/AD.Nekark.fxmbb
DrWeb Trojan.Encoder.41221
VIPRE Trojan.GenericKD.74635134
TrendMicro Clean
McAfeeD ti!E195BEF31E5A
Trapmine Clean
CTX exe.trojan.generic
Emsisoft Trojan.GenericKD.74635134 (B)
Ikarus Trojan-Ransom.FileCrypter
FireEye Generic.mg.a44a69112351292c
Jiangmin Clean
Webroot Clean
Varist W64/ABRansom.EGGG-4478
Avira TR/AD.Nekark.fxmbb
Fortinet PossibleThreat.MPH.H
Antiy-AVL Trojan[Ransom]/Win32.Dcrypt.a
Kingsoft Win32.Trojan-Ransom.Agent.gen
Gridinsoft Trojan.Win64.Agent.sa
Xcitium Malware@#3ftdywqvz7jio
Arcabit Trojan.Generic.D472D77E
SUPERAntiSpyware Clean
ZoneAlarm HEUR:Trojan-Ransom.Win32.Agent.gen
Microsoft Trojan:Win32/GandCrab
Google Detected
AhnLab-V3 Ransomware/Win.Generic.C5690458
Acronis Clean
McAfee Artemis!A44A69112351
TACHYON Clean
VBA32 Clean
Malwarebytes Ransom.FileCryptor
Panda Trj/Chgt.AD
Zoner Clean
TrendMicro-HouseCall TROJ_GEN.R002H09K524
Rising Ransom.Agent!8.6B7 (CLOUD)
Yandex Clean
SentinelOne Static AI - Malicious PE
MaxSecure Clean
GData Trojan.GenericKD.74635134
AVG Win64:MalwareX-gen [Trj]
DeepInstinct MALICIOUS
alibabacloud Clean
No IRMA results available.