Static | ZeroBOX

PE Compile Time

2023-12-19 01:42:43

PE Imphash

4c704d305eaf81216e940bed394c1551

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x0005661c 0x00056800 6.29589423775
.data 0x00058000 0x0000abe8 0x00006000 0.954682156592
.rsrc 0x00063000 0x00003b50 0x00003c00 5.95448486832

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x00065e80 0x00000468 LANG_TAMIL SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x00065e80 0x00000468 LANG_TAMIL SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x00065e80 0x00000468 LANG_TAMIL SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_STRING 0x000666b0 0x0000049e LANG_TAMIL SUBLANG_DEFAULT data
RT_STRING 0x000666b0 0x0000049e LANG_TAMIL SUBLANG_DEFAULT data
RT_ACCELERATOR 0x00066318 0x00000050 LANG_TAMIL SUBLANG_DEFAULT data
RT_GROUP_ICON 0x000662e8 0x00000030 LANG_TAMIL SUBLANG_DEFAULT data
RT_VERSION 0x00066368 0x00000208 LANG_NEUTRAL SUBLANG_NEUTRAL data

Imports

Library KERNEL32.dll:
0x401000 GetComputerNameA
0x401004 GetTempFileNameW
0x401008 WriteConsoleInputW
0x40100c TlsGetValue
0x401010 SetComputerNameExA
0x401014 EnumCalendarInfoW
0x40101c GetCurrentProcess
0x401028 WriteConsoleInputA
0x40102c SetComputerNameW
0x401034 GetModuleHandleW
0x40103c GetCurrencyFormatA
0x401040 EnumTimeFormatsW
0x401044 LoadLibraryW
0x401048 GetCalendarInfoW
0x40104c GetVersionExW
0x401050 FindNextVolumeW
0x401054 GetFileAttributesW
0x401058 GetDevicePowerState
0x40105c LCMapStringA
0x401060 VerifyVersionInfoW
0x401064 GetLastError
0x40106c SetLastError
0x401070 GetProcAddress
0x401074 VirtualAlloc
0x401078 CreateJobSet
0x40107c CopyFileA
0x401080 SetFileAttributesA
0x401084 LoadLibraryA
0x40108c SetCalendarInfoW
0x401090 GetCommMask
0x401094 EnumDateFormatsA
0x401098 GlobalUnWire
0x4010a0 OpenEventW
0x4010a4 GetShortPathNameW
0x4010a8 GetDiskFreeSpaceExW
0x4010ac ReadConsoleInputW
0x4010b0 EnumCalendarInfoExA
0x4010c0 GetStartupInfoW
0x4010c4 HeapAlloc
0x4010c8 HeapFree
0x4010d4 SetHandleCount
0x4010d8 GetStdHandle
0x4010dc GetFileType
0x4010e0 GetStartupInfoA
0x4010e8 TerminateProcess
0x4010ec IsDebuggerPresent
0x4010f0 Sleep
0x4010f4 ExitProcess
0x4010f8 WriteFile
0x4010fc GetModuleFileNameA
0x401100 SetFilePointer
0x401104 CloseHandle
0x401108 GetModuleFileNameW
0x401110 GetCommandLineW
0x401114 TlsAlloc
0x401118 TlsSetValue
0x40111c TlsFree
0x401124 GetCurrentThreadId
0x401128 HeapCreate
0x40112c VirtualFree
0x401134 GetTickCount
0x401138 GetCurrentProcessId
0x401140 RtlUnwind
0x401144 RaiseException
0x401148 HeapReAlloc
0x40114c GetCPInfo
0x401150 GetACP
0x401154 GetOEMCP
0x401158 IsValidCodePage
0x40115c WideCharToMultiByte
0x401164 SetStdHandle
0x401168 GetConsoleCP
0x40116c GetConsoleMode
0x401170 FlushFileBuffers
0x401174 GetModuleHandleA
0x401178 MultiByteToWideChar
0x40117c LCMapStringW
0x401180 GetStringTypeA
0x401184 GetStringTypeW
0x401188 GetLocaleInfoA
0x40118c HeapSize
0x401190 WriteConsoleA
0x401194 GetConsoleOutputCP
0x401198 WriteConsoleW
0x40119c CreateFileA

!This program cannot be run in DOS mode.
`.data
bad allocation
Unknown exception
bad exception
(null)
`h````
xpxxxx
CorExitProcess
runtime error
TLOSS error
SING error
DOMAIN error
An application has made an attempt to load the C runtime library incorrectly.
Please contact the application's support team for more information.
- Attempt to use MSIL code from this assembly during native code initialization
This indicates a bug in your application. It is most likely the result of calling an MSIL-compiled (/clr) function from a native constructor or from DllMain.
- not enough space for locale information
- Attempt to initialize the CRT more than once.
This indicates a bug in your application.
- CRT not initialized
- unable to initialize heap
- not enough space for lowio initialization
- not enough space for stdio initialization
- pure virtual function call
- not enough space for _onexit/atexit table
- unable to open console device
- unexpected heap error
- unexpected multithread lock error
- not enough space for thread data
This application has requested the Runtime to terminate it in an unusual way.
Please contact the application's support team for more information.
- not enough space for environment
- not enough space for arguments
- floating point support not loaded
Microsoft Visual C++ Runtime Library
<program name unknown>
Runtime Error!
Program:
EncodePointer
DecodePointer
FlsFree
FlsSetValue
FlsGetValue
FlsAlloc
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
`h`hhh
xppwpp
GetProcessWindowStation
GetUserObjectInformationA
GetLastActivePopup
GetActiveWindow
MessageBoxA
USER32.DLL
Complete Object Locator'
Class Hierarchy Descriptor'
Base Class Array'
Base Class Descriptor at (
Type Descriptor'
`local static thread guard'
`managed vector copy constructor iterator'
`vector vbase copy constructor iterator'
`vector copy constructor iterator'
`dynamic atexit destructor for '
`dynamic initializer for '
`eh vector vbase copy constructor iterator'
`eh vector copy constructor iterator'
`managed vector destructor iterator'
`managed vector constructor iterator'
`placement delete[] closure'
`placement delete closure'
`omni callsig'
delete[]
new[]
`local vftable constructor closure'
`local vftable'
`udt returning'
`copy constructor closure'
`eh vector vbase constructor iterator'
`eh vector destructor iterator'
`eh vector constructor iterator'
`virtual displacement map'
`vector vbase constructor iterator'
`vector destructor iterator'
`vector constructor iterator'
`scalar deleting destructor'
`default constructor closure'
`vector deleting destructor'
`vbase destructor'
`string'
`local static guard'
`typeof'
`vcall'
`vbtable'
`vftable'
operator
delete
__unaligned
__restrict
__ptr64
__clrcall
__fastcall
__thiscall
__stdcall
__pascal
__cdecl
__based(
GAIsProcessorFeaturePresent
KERNEL32
_nextafter
_hypot
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
HH:mm:ss
dddd, MMMM dd, yyyy
MM/dd/yy
December
November
October
September
August
February
January
Saturday
Friday
Thursday
Wednesday
Tuesday
Monday
Sunday
SunMonTueWedThuFriSat
JanFebMarAprMayJunJulAugSepOctNovDec
CONOUT$
1#QNAN
1#SNAN
bad allocation
kernel32.dll
HtHu4j
s[S;7|G;w
tR99u2
0SSSSS
HHtXHHt
>If90t
j@j ^V
j h(iE
>=Yt1j
QQSVWh
QQSVWd
tRHtCHt4Ht%HtFHHt
0A@@Ju
^SSSSS
j"^SSSSS
URPQQh
0SSSSS
0SSSSS
0WWWWW
AAFFf;
;t$,v-
UQPXY]Y[
_VVVVV
^WWWWW
t"SS9]
PPPPPPPP
PPPPPPPP
0SSSSS
_VVVVV
t+WWVPV
<+t(<-t$:
+t HHt
u;h,-@
u,h$-@
/B43ywb
/Fh+#{
aFz?}VI
A';xR.
iHuB5s
A1#;hQ
K@yP>7
RF4WgD
uy czp
gTC::6
nBdi[)CX8
#PH#zP
rK#T"r5">
8!v4l@
a8\.oEQ
}M7|"O
lM5~{"
&f +&-
[xzPXx
y"x&9Ap
V051+SQ
>A,E{`z\
y0DwO*Z//
RP{~^}yWp^
hQf/j_
R;}G+-
r)g@d&
WYC.[O
6%jIl|
uLj!G|
vt3 $]
g"a|H78
W\*}e:2
\'m.(rj
p|=7B>7
h*Kz"
3wxxG/Kz"
PUCN\u
Bp"+?qA&T
Yt&KAx
>GF`eZG
FE#f:#3-;#<-e
_&|uX7
h2:jgh
}HZ;#b
<RpOa:
4:t,kR
SrQ[ 9!
pe!/3OzLq
0G2|h&
OmoM3x
'tiLN
L(a3}|
Cd#YK-
t&SZ1R
Tn&~*">B
]6;z6@
*::7vW
|f7QKM
4U6@k*zf
@L5t{`
~.l9!c
7,WEeG
kuJeJF
6{EA6
3QYv\dS^(
~mTgg&cF
2K0Fr}
sQiNOD
{=>}]tm
C,=IHz#[W
2puSqA
B{/B:
;>=>^!
')&+\x5
j}}I&rx
P0($[4
VUCC'
Qsjr6
gF=fz`#
Kb7L@U
WU7Z?rDa
t|XcHZ
uW+2D'p
^XNjH3e
Tr$Q_H
=GoD7u?
`/Qo^&
acH:w]
IF"[(C
Ijh"`Q
j{!|z(l*
fp*>on'\
D|"05Z
OL]7wp
{1<$r\YA
bP?kHF
qGR7?*
V0s}Sz
}}T%F1
eL^n{"$
fabD&m
ZRbc#v
~>L 1?
<=t:KC
c/qsDM%5Or
F*K6GJ
%^B8{g
OL7x_
,N~\l/
$aN1,X
~W\s(u
A8SWCyw
Jyqi+x
\L<OR9
r"Ezj0k
G{NbN
PPA{mCn
>*"PAq
Fl$Z2I
OT~vlV
Pg@ObKN
thLj]m
-]ZY`*
z#s\+I
R[/G%W'0
~bI@JfzRCX
MGt"vX
O.YOSa
}nNx~
Bj[RJ)
j[;&%f
cVunw6K>
4Op 8LW
*F5FRy
rRam3_
=b"05
Ba@blz
*]%"s]
4@Um z
EiIV>"
SYfX53{
?_m}2^L
"pih]7
P%pSnrFw
SSCo"l
d 6=k1
1F3oO-+
FXPzj>
+-6O#s
~vZI.\
1nP3jJ%_
ftgjEhf
#e2G.3tl
K\O8Q/
;py+=e%D
ClMN+@
LyZPWX
#_ahdC
Xb]]yL+
@z\KgE
u|:0=7F"
WK\d|@
ErST<1BSkx.
OFpFkl
x1oYU~
@/{Zf6s
]c7%vZ
'z/wsa
B!43U1x
pW&LTC|
N1wVnC
|SHwO\
BI^S8;
8j,).j'6}
_swyj>
x$hAQ0Y
cgtf'7
jniN)jn
7=,~EdD
G}OPU]
L*x{,{m
lOzM|S
BW4|^@
rS!WHW
~(J,\3
wYi800i
_(yg>!<e
!zy6/6
:}`@Lu
@7M9Mq
%Vg7)V
["9Z2l
{D)""s"
i:8^*[X
i>N9Bd
[J$[U"
*6Xm.0
8>-?E.0
?x,vf[
.*R9*t)
k<@f%N
)p{<BB
kxeKX=%=
=WG9;w
8H},:I
NCxK!a
aY;L3)T
O@01fe
E$jO/my
9Fql\*|;
zjO2i$
~5/ES3
#^yAh<
HW'y:~f
bz#LAE
-bV46F
a!V\IJ
'`%=,z
/z'yvI
b}etSq2
g"!]KA!9X
@NfXh7
e`%$G5C
&C-{E58?
8ZKZFTmC
Iu1]j3
}K;RF8
"|m;xH
"gb?2m
oXT<W=
Y.5!a[#
MxQ|i`
IVd5$\#
BfY;.8
K)j$:[
DC(1!A@
uMF&<yEg
W_\%?NY
.u35t^
@d=Iq^
dQWE;9
FvtH.8
d3oD9W
%.vUq_
*\6zym
c9vps8Sp
LAbAF'MO
:leO^`
UJ#GkT
b^U<W|
x15<I6
3&AyI9B
@l[gHy
F}`/ov
Gi2^2n
Z]?&{fv_
>r_:QVA
7/"bk?
J~c>C<w3
;U[Wj,
%RS)FG|Z\
@_(ys$c{
0kIQM6
Sf!\n G
nXM&fg
+cZ>:d
rMm`"T0
QYT}.9
_`2IET
_t(p\Qi\2nxA*
"sFlNS
,\9Q%T
;25En
LvH=jD
Fvy/4w
Jm~5RG>w{
X)(?uP
L2zD8-
bCA8M'k
?l0_\l
!yx& eaH{f
~#jggs
J3fOC]
t>QRD~
"8Vgc#
9q2Yp'
=_V%!s
[N_hD-Y
P=a<K2
/R+vI
Us\`z8
qo&58P
jDB6B@
{$gR9
{C5r6K
${Y4\j
YiSi!(!1
&A}|&:
vt@vw{
fQ;5R@4
zficOR
Gz%cKbbw
VTuC)z
~hijm;7
1z.[f9
+ofGC?D
o$MT.1
'8>uC
Lj5UY7
>649X{
A,jJ.Y
f`lwgx
:pUz&#
O75'dBd
;9xr"g
GetComputerNameA
GetTempFileNameW
WriteConsoleInputW
TlsGetValue
SetComputerNameExA
EnumCalendarInfoW
InterlockedDecrement
GetCurrentProcess
GetLogicalDriveStringsW
InterlockedCompareExchange
WriteConsoleInputA
SetComputerNameW
SetVolumeMountPointW
GetModuleHandleW
FindNextVolumeMountPointA
GetCurrencyFormatA
EnumTimeFormatsW
LoadLibraryW
GetCalendarInfoW
GetVersionExW
FindNextVolumeW
GetFileAttributesW
GetDevicePowerState
LCMapStringA
VerifyVersionInfoW
GetLastError
GetCurrentDirectoryW
SetLastError
GetProcAddress
VirtualAlloc
CreateJobSet
CopyFileA
SetFileAttributesA
LoadLibraryA
InterlockedExchangeAdd
SetCalendarInfoW
GetCommMask
EnumDateFormatsA
GlobalUnWire
FreeEnvironmentStringsW
OpenEventW
GetShortPathNameW
GetDiskFreeSpaceExW
ReadConsoleInputW
EnumCalendarInfoExA
GetVolumeInformationW
KERNEL32.dll
UnhandledExceptionFilter
SetUnhandledExceptionFilter
GetStartupInfoW
HeapAlloc
HeapFree
EnterCriticalSection
LeaveCriticalSection
SetHandleCount
GetStdHandle
GetFileType
GetStartupInfoA
DeleteCriticalSection
TerminateProcess
IsDebuggerPresent
ExitProcess
WriteFile
GetModuleFileNameA
SetFilePointer
CloseHandle
GetModuleFileNameW
GetEnvironmentStringsW
GetCommandLineW
TlsAlloc
TlsSetValue
TlsFree
InterlockedIncrement
GetCurrentThreadId
HeapCreate
VirtualFree
QueryPerformanceCounter
GetTickCount
GetCurrentProcessId
GetSystemTimeAsFileTime
RtlUnwind
RaiseException
HeapReAlloc
GetCPInfo
GetACP
GetOEMCP
IsValidCodePage
WideCharToMultiByte
InitializeCriticalSectionAndSpinCount
SetStdHandle
GetConsoleCP
GetConsoleMode
FlushFileBuffers
GetModuleHandleA
MultiByteToWideChar
LCMapStringW
GetStringTypeA
GetStringTypeW
GetLocaleInfoA
HeapSize
WriteConsoleA
GetConsoleOutputCP
WriteConsoleW
CreateFileA
.?AVtype_info@@
.?AVbad_exception@std@@
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
.?AVexception@std@@
.?AVbad_alloc@std@@
+Vehrea\
7E>)dmm}
bpnfppfpsm|
&LEKU5
([_Y[_]a
$MKHJ>
`vvruql}w
2LHBC;
<LNDR=#D6
>BJKT=
@SBKO=
0MBNJ8$?M
MTNK4#MEF
.REH<6EIH>
JQFHMLF=$QMG$+t
FJMMHJLHEQMS
.?EEAEMJQPSE$+V''
%91>H?3=@DEH
(null)
mscoree.dll
KERNEL32.DLL
((((( H
h(((( H
H
kukotagejabericunaceriyeta
kernel32.dll
jjjjjj
VS_VERSION_INFO
StringFileInfo
032414E2
FileVersions
12.13.18.5
InternalName
ChickenPluges
FileDescription
Micrar
OriginalFilenames
Odilemio
ProductVersions
68.83.40.8
VarFileInfo
Translation
;Rejakaz vewatiwucihac xax yofosen lohoc vuwifejutovid xopew
UBeso lezifudoje wulusobakici lok wojafeloracayuh zejoxawizu bivekuvutor jov nubedigab
_Juyuwoli yolesa fub zetomipuni vutoteyozicibo kubagisaso lofejubobuxubi livijeh fepohegawaxavav4Xixohovawedoyuf yofiluz lujoyud wogoz fenilocagosugaeLatesipasiyesu zadexomonere hocoxogupu jacix givovasaxah pomonixocoh sumoyafux wagiho kazez tuparilij7Fizawawiboyudun sihob guwucanajay gepagezop bolovohaketKNawin bibasumon vakulepafaj koresinav gibevodurazu ruyiduhove cabeboyuliwok
Mutodazeyaral zawuxomoyigoyekdZuhopicixeni pevaxojimab vakifaharadepo pikoyoladate vug havo pupufazuwerine caj rup zowitujajifovejDBayacet limovamisuyitem cusowozuheyugul pubuxap yibela mowebugukuxoy
Antivirus Signature
Bkav Clean
Lionic Trojan.Win32.Tepfer.i!c
Elastic malicious (high confidence)
ClamAV Win.Packer.pkr_ce1a-9980177-0
CMC Clean
CAT-QuickHeal Clean
ALYac Clean
Cylance Unsafe
Zillya Clean
Sangfor Trojan.Win32.Save.a
CrowdStrike win/malicious_confidence_100% (W)
Alibaba Clean
K7GW Hacktool ( 700007861 )
K7AntiVirus Clean
huorong HEUR:Trojan/Agent.byi
Baidu Clean
VirIT Clean
Symantec ML.Attribute.HighConfidence
tehtris Clean
ESET-NOD32 a variant of Win32/GenKryptik.HETI
APEX Malicious
Paloalto generic.ml
Cynet Clean
Kaspersky UDS:Trojan-PSW.Win32.Tepfer.gen
BitDefender Clean
NANO-Antivirus Clean
ViRobot Clean
MicroWorld-eScan Clean
Tencent Trojan.Win32.Obfuscated.gen
Sophos Troj/Krypt-VK
F-Secure Clean
DrWeb Clean
VIPRE Clean
TrendMicro Clean
McAfeeD Real Protect-LS!958D453DD48C
Trapmine malicious.high.ml.score
CTX exe.trojan.generic
Emsisoft Clean
Ikarus Trojan-Spy.Agent
FireEye Generic.mg.958d453dd48cb48a
Jiangmin Clean
Webroot Clean
Varist Clean
Avira Clean
Fortinet W32/Kryptik.HYLQ!tr
Antiy-AVL Clean
Kingsoft Win32.Trojan-PSW.Tepfer.gen
Gridinsoft Ransom.Win32.Wacatac.sa
Xcitium Clean
Arcabit Clean
SUPERAntiSpyware Clean
Microsoft Trojan:Win32/Wacatac.B!ml
Google Detected
AhnLab-V3 Trojan/Win.Generic.R684270
DeepInstinct MALICIOUS
VBA32 Clean
TACHYON Clean
Malwarebytes Generic.Malware/Suspicious
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Rising Trojan.Kryptik@AI.93 (RDML:Sq0fRWGvhxeDh2uviHe/aw)
Yandex Clean
SentinelOne Static AI - Malicious PE
MaxSecure Trojan.Malware.300983.susgen
GData Win32.Packed.Kryptik.L76SYJ
AVG FileRepMalware [Cryp]
Avast FileRepMalware [Cryp]
alibabacloud Trojan[stealer]:Win/Wacatac.B9nj
No IRMA results available.