PE Compile Time

2025-04-02 23:01:30

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
\x00 0x00001000 0x00061000 0x00061000 6.3522511447
.rsrc 0x00062000 0x0000022c 0x00000200 5.11845662105
.idata 0x00063000 0x00001000 0x00000200 3.23516089646
0x00064000 0x00291000 0x00000200 0.0
mughqkns 0x002f5000 0x00192000 0x00191200 5.23689504346
mxuodipd 0x00487000 0x00001000 0x00000400 5.3369827911
.taggant 0x00488000 0x00003000 0x00002200 6.38752475956

Resources

Name Offset Size Language Sub-language File type
RT_MANIFEST 0x00062058 0x000001d1 LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, ASCII text

!This program cannot be run in DOS mode.$
`.rsrc
.idata
mughqkns
mxuodipd
.taggant
4$<,uD
E(;D$<
+F@;F$
+N@;N$vY
F0;F4r
N0;N4s
F0;F4s
V0;V4s
V0;V4s
B;V<sS
~0;~4s
V0;V4s
V0;V4s
N0;N4r
F0;F4r
N0;N4r
F0;F4r
N0;N4s
V0;V4r
N0;N4s
~0;~4s
~0;~4s
;t$,s.
L$,+L$
D$pPSV
D$pPSV
T$ j8RQP
xH9w(s%V
D$0PWQ
<$tG9~
L$@;T$
L$PPQh
L$LPQW
D$ PUW
V0;V4s
N0;N4s
V0;V4s
N0;N4s
F0;F4s
N0;N4s
N0;N4s
F0;F4s
O0;O4s
o0;o4s
_0;_4s
O0;O4s
O0;O4s
G0;G4s
L$(9L$
D$4BI{A
D$<OMIL
D$@qEsL
D$HWSW
D$L`lRn
$Z@D31
D$Ljasi
D$p.06.
D$tnFn)
D$x9='=
D$|%8#Jf
@I=jB2
D$ 3T$
l$$3h$
l$03h(
l$`3X,
\$d3x0
|$h3p4
t$l3P8
T$p3H<
l$4wd1
@@=pu}
D$phvkg
D$pDHvJ
:bii/GH
4$VPh`
D$DP!m#
D$HW%R'f
D$L()1
T$DRPQ
D$G3679
D$C9B07
D$?B5DE
D$;A455
D$G3679
D$C9B07
D$?B5DE
D$;A455
D$Lwvqp
D$Lwvqp
t$ VQj
D$ uhf>
+{t#B9
t$0RPj
D$Tj`j
PSj+Qj
T$(Qh?
D$X#E"K
D$X<=B
D$`DEJK
D$pTUZ
L$4Sj$
D$4wvqp1
D$Xwvqp1
D$Xwvqp1
D$Xwvqp1
D$Xwvqp1
L$,Qj(j
|$0WRPj
D$D%E.K
D$P'q w
D$\|}1
$wvqp1
$wvqp1
$wvqp1
$wvqp1
$wvqp1
$wvqp1
|$688u
$wvqp1
D$\PJj
t$4;t$(
t$4;t$(
'HA=4O
F E!T#
F$A%J'
F(L)H+f
D$TG%1
D$Tuujk
T$`u.1
D$Xdefg
D$\ abc
D$`|}~
D$TyU@C
D$XDEFG
D$`LMN
D$$h PZ
t$DQRj
t$$RVP
l$<xWU
L$d;L$
D$<Hi#o
D$<Hi#o
@I=^6&
D$|X)Z+
T$LPWQR
D$ D1671
D$@PUV
D$\n!"'
D$(XY1
D$Xj`j
D$(XY1
D$Xj`j
D$,PSWjVj
D$0vhnv
D$4jtkrf
-u A<+
D$d[Rll
D$hk_ccf
D$d[Rll
D$hk_ccf
D$db@R<
D$h ,^#
D$dJhj
D$hekar
D$lino1f
L$djUQ
D$hAT>p
D$dJhj
D$h8<n5
& )8f@
D$Pc!1
T$PPQj
D$ xy1
D$$`a1
9t$ t6
L$$QWVj
D$016<:
D$Xwvqp
T$4;|$
t$(VRP
D$(DEzK
D$(wvqp
D$4PSR
t$ 9t$@
t$8+t$
A@=@#|
D$ vO9
D$ vO9
L$L;\9
t$8SVWU
D$$PQR
T$,RQP
T$dRQP
$S ""1
$9D$(u
$ONML1
$ONML1
$ONML1
$ONML1
$ONML1
t$lj,Q
$ONML1
$ONML1
$ONML1
$ONML1
$ONML1
00010203040506070809101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899
MbP?-C
-(;aU,$
I#& 1]
%FcI>
~00010203040506070809101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899
000102030405060708090A0B0C0D0E0F101112131415161718191A1B1C1D1E1F202122232425262728292A2B2C2D2E2F303132333435363738393A3B3C3D3E3F404142434445464748494A4B4C4D4E4F505152535455565758595A5B5C5D5E5F606162636465666768696A6B6C6D6E6F707172737475767778797A7B7C7D7E7F808182838485868788898A8B8C8D8E8F909192939495969798999A9B9C9D9E9FA0A1A2A3A4A5A6A7A8A9AAABACADAEAFB0B1B2B3B4B5B6B7B8B9BABBBCBDBEBFC0C1C2C3C4C5C6C7C8C9CACBCCCDCECFD0D1D2D3D4D5D6D7D8D9DADBDCDDDEDFE0E1E2E3E4E5E6E7E8E9EAEBECEDEEEFF0F1F2F3F4F5F6F7F8F9FAFBFCFDFEFF
0123456789ABCDEFGHIJKLMNOPQRSTUVWXYZ
20aaf600cf2ccd040a793bffc9729595ca866790e7
fw`fmw kmwp
1s4!Sc
.6h*~NY
o9myUp
<?xml version='1.0' encoding='UTF-8' standalone='yes'?>
<assembly xmlns='urn:schemas-microsoft-com:asm.v1' manifestVersion='1.0'>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v3">
</trustInfo>
<dependency>
<dependentAssembly>
<assemblyIdentity type='win32' name='Microsoft.Windows.Common-Controls' version='6.0.0.0' publicKeyToken='6595b64144ccf1df' language='*' processorArchitecture='*' />
</dependentAssembly>
</dependency>
</assembly>
PADPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADD
lstrcpy
CreateEventW
kernel32.dll
KERNEL32.dll
C:\Windows\system32\ntdll.dll
%userappdata%\RestartApp.exe
api-ms-win-core-com-l1-1-0
Themida
C:\Users\Admin\AppData\Local\Temp
EFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopq
wvwxyz{|}~
g[WhaL
$$PRh+s
3,$1,$3,$
1ZX_YPPRPR`a
``RZ`aa`PX`aaaPQ
RtlFreeHeap
3<$1<$3<$
ksZHUSh
4$eiw~
P$sohj
34$14$
4$XWT_V
WLNumDLLsProt
Exit Status = %d
3,$1,$
?uUhp}
3,$1,$3,$
4$Xh5V7C
[YSPfh
vb[1\$
4$koZwQ
3<$1<$3<$\
-Zi+}_R
Xh!?W<
4$XRTZ
}xX34$14$
3<$1<$3<$\
_QSPh&
,$$"s_
3,$1,$3,$
ZWT_hdp
1,$3,$1,$S
}-[1,$
34$14$34$\
1,$3,$
_^][ZYX
H-W_}^
5F+S/)
(T|Jx)
3,$1,$3,$\
_^][ZYX
_^][ZYX
tf.^XU
3,$1,$3,$
4$ZWT_
X34$14$34$\
_^][ZYX
_^][ZYX
$\huiF
$Xh'[q
3<$1<$3<$\
_^][ZYX
_^][ZYX
_^][ZYX
3,$1,$3,$
_^][ZYX
w\gh)\$
|SUhb/
&1,c/+
_^][ZYX
_^][ZYX
1`By_1
_^][ZYX
_^][ZYX
WUShfh
'dt|f
Gz$w-(
H_{?QU
6X~TO!
4$_hbO
gS][MU
3]34$14$34$
Y3<$1<$3<$
PQRSUVW
_^][ZYX
14$34$14$Z
']UIC5
_^][ZYX
4$[PTX
4$^WT_
_^][ZYX
3,$1,$3,$\)
$PTXQP
H{?UVh
_^][ZYX
;_[X+293
%1n1|$
5uEx-!
_^][ZYX
XSQhO_
_^][ZYX
p}+>99
_^][ZYX
1CF[&5
%b2;^@W
14$34$14$W
3,$1,$3,$
_^][ZYX
F[?/QP
T%D'-(
_^][ZYX
_^][ZYX
3<$1<$3<$\VhZ
34$14$34$\
)NQYv!
3<$1<$3<$\
$7zMPh
$h. P>[
3<$1<$3<$\
3O02*1
QPRTZP
_^][ZYX
_^][ZYX
_^][ZYX
4$_RTZ
_WR_ZB
_^][ZYX
_^][ZYX
+z~%c#
SX[)D$
RTZVSh
3<$1<$3<$
3<$1<$3<$
$\QPhz
4$^PTX
$\14$34$14$
SURPh#
$$UPh?
_^][ZYX
%?;!L$
_^][ZYX
XR]Z)l$
4$_ST[
_^][ZYX
#jCz_%(
_^][ZYX
72jne%
4$Xhq7
_hd{rG
_^][ZYX
4$YWT_VS
34$14$34$\U
FdY?QVU
.08`K5
_^][ZYX
_^][ZYX
4$T^PR
4$]UT]
3<$1<$3<$\
4$]ST[
_^][ZYX
<$PSho
4$XVT^
"[TA,5
4$UhuU[v
,$^PVX^5
0 Z}|f
3<$1<$3<$
De_~X3<$1<$3<$\
_XQhA(*h
]3<$1<$3<$
k~|!|$
4m~PQW
34$14$34$
_EM)t$
,$h[Y(v
3M?s-.
wuX!|$
3,$1,$3,$
3,$1,$3,$\
4$\VT^
34$14$34$\
$$VT^Q
4$ZPhX0
Y34$14$34$\
sSRh}E
4$[VT^
^RWh!O
1,$3,$1,$
XYRhg
ZXV`a^PRPR
1`a`aZXa
$QUh'6O7]
3,$1,$3,$
$$VPWP
4$%2!#
AOM~RQ
3<$1<$3<$
'GuBBP
[34$14$34$\
$$ST[R
;YhiU0'
$\RPhqH
3<$1<$3<$\
n%&zw5
$$Rzv^
$Epa}X5
YVQ^YI
Z34$14$34$\R
3,$1,$3,$
,$R]U^
34$14$34$\3
Y34$14$34$\S
$\UT]P
[34$14$34$\
,$RhCy
$\QTYh
34$14$34$
4$]UT]R
3,$1,$3,$\R
4$^WT_
,$[Chi
3<$1<$3<$\
3<$1<$3<$\WS
34$14$34$
4$RTZQ
3<$1<$3<$
$\PRPPR
<$hOY\6
Z1,$3,$1,$h?6
<$UT]P
3<$1<$3<$
$\3<$1<$3<$\
QTYh=cb%
4$[UT]
3,$1,$3,$
Pht )0
PRS[`a
3,$1,$3,$
[_34$14$34$
Z34$14$34$\
<$\RTZ
&mk_1D$
,$\3,$1,$3,$
Y34$14$34$
3,$1,$3,$\
c,k{RU
3,$1,$3,$\Q
zg~-Kq
$$VT^Q
3<$1<$3<$\
34$14$34$
aZXST[P
34$14$34$\
$\^hk6
34$14$34$\
O<y|RU
_34$14$34$
QRPhD4
K-A7}w)
$\PRPRPR
1ZXaZX
3,$1,$3,$\-
$hp\sDXP
$\Z-RU
<$\VWhxH
WHh>y
mek)\$
Y3<$1<$3<$\Qh
zd}l[)
4$T^UQ
34$14$34$
3<$1<$3<$
4$[hWy
JUSER32.dll
ADVAPI32.dll
NTDLL.dll
4$XPTX
O=JUhE
$PTXQh
"8#e<Jz
&LmO5Z8z
$<>YmI
vu<hvo
o`H]DL
`J#LfL
)L;#e7
34$14$34$\
VQV^S[Y
aP`aX`RZV^
1PXZXPR
1QYPXZX`
JRPR`a
1`a`aZXZ
4$[ST[P
cZXPR`aRZ
1ZXZX`
P`S[`aa
1`PXW_PR
3,$1,$3,$
34$14$F
{X34$14$
1,$3,$
i(dXhf
[3,$1,$3,$\
,$wtmO_
^Sh1]@4
Z%WXQ>Q
\\.\SICE
\\.\SIWVID
\\.\NTICE
4$Qv'.
PRPRPR
1`aZXZXPPRR
WYZh>Q
1ZXaP`
1`aZXa
1ZXa_P
1ZXZX`PR
1ZXRZaa
4$zqD
1ZX^PR
1R`aZZX
Software\WinLicense
Software\WLkt
CheckIN
XprotExit
CheckOUT
WinLicenseVersion
WinLicenseDriverVersion
WinLicenseInstance
ExitOk
ProcIN
ProcOUT
ExitIN
ExitOUT
ExpInfo
p)Bw)L$
3<$1<$3<$
4$XRTZ
&``aPR
,$aYoz
v9d8$z
z"pc@s
3,$1,$3,$\
<$h&6*A
/bugcheck2
/bugcheck
/nosplash
/forcerun
/bugcheckfull
/showcode
/showcode2
/showinstance
/getwlstatus
/logstatus
/dumpstatus
/checkprotection
/skipactivexreg
/deactivate
XBH_FNT
4$&>w3^
,$7<+}
Rhw'&_
4$^RTZS
3Cannot write oreans.vxd
Make sure that this file is not being used by another program.
\Oreans.vxd
ADVAPI32.DLL
OpenSCManagerA
CreateServiceA
StartServiceA
GetNativeSystemInfo
OpenServiceA
DeleteService
CloseServiceHandle
ControlService
oreans32.sys
oreansx64.sys
oreans32
\\.\oreans32
\\.\Global\oreans32
oreansx64
\\.\Global\oreansx64
SYSTEMROOT
%s\system32\drivers\%s
%s\syswow64\drivers\%s
%s\system32\drivers\oreans32.sys
3Cannot Update oreans.sys driver. Please, make sure that you have
administrator's permits the first time that you are going to run this program.
3Cannot open oreans.vxd driver. Make sure that oreans.vxd
is not open by another program.
3SecureEngine driver cannot be updated because there are some programs using
it. You need to close those programs or restart your computer.
Restart now?
\\.\Oreans.vxd
%s\Oreans.vxd
XprotEvent
HARDWARE\ACPI\DSDT\VBOX__
SeShutdownPrivilege
Software\WinLicense
CreateEvent API Error while extraction the driver
GetEnvironmentVariable API Error while extraction the driver
OpenSCManager API Error while extraction the driver
CreateService API Error while extraction the driver
CloseServiceHandle API Error while extraction the driver
OpenService API Error while extraction the driver
StartService API Error while extraction the driver
APIC error: Cannot find Processors Control Blocks. Please,
contact info@oreans.com for this error
3Sorry, this application cannot run under a Virtual Machine
Software\Wine
timeGetTime
winmm.dll
34$14$34$\
X3<$1<$3<$
3,$1,$
Y3,$1,$3,$
X34$14$34$
3<$1<$
$\34$14$34$\
6GlOSQ
3<$1<$3<$\
34$14$
$\5g@uS5
WhP3^d
1<$3<$1<$
_3,$1,$3,$
}g5+Lr
R_Z1|$
4$XQTYU
$\34$14$34$
2~o!D$
[3,$1,$
<$hSt~u_
4$]WT_P
3,$1,$3,$
Fhwz5E
34$14$34$
Exception Information
Please, contact the software developers with the following codes. Thank you.
(press CTRL+C on this window to copy to clipboard)
CheckIN = %d
CheckOUT = %d
ProcIN = %d
ProcOUT = %d
ExitIN = %d
ExitOUT = %d
TPin = %d
HWIn = %d
IntV = %x,
%x, %x
$"R{oS
34$14$34$
\OY-qk
Z3<$1<$3<$\
$Qh:CM?
3,$1,$3,$
1<$3<$\
DwA.)l$
`aa[PW`V^
3<$1<$
h@@,-Y1
4$^QTY
4Zx0/@
v}t$)8L
^3,$1,$3,$\
PRRPXZ
3<$1<$3<$
$ShcWD
1ZXaPRRZ
ZXWSPXPR
4$[WT_
$X@-Ah
4$[RTZ
,$_mZ?
3,$1,$3,$\
3<$1<$3<$\
3<$1<$3<$
3<$1<$3<$
!*|)l$
7(e<Za
]e'E$
+)-+:z
3,$1,$3,$\
PRV^QY
1`a`aZXPRS[
1ZX`aZX
``V^W_
aPR`aPR
rZXS`aPX[a
4$XQTY
1QYZXZX
34$14$
3<$1<$3<$
1QYS[ZXZXPRV
1`aZXZX
}[^)L$
BI?n@%d
iU>)L$
3<$1<$
"sgr1\
*./ZXPR
1`aZXZX`Q
`aYSPR
4$XQTY
-X|=)\$
,$Vw]o
Y3<$1<$3<$\
?[ZQTY
3<$1<$
,uitJC
4$~`DhS
4$h|-{w
3<$1<$
SYPhWG
_}ZhX`
3,$1,$3,$\V
1<$3<$\
$X--s*
U4/P.)(;*
j7Q,"6
QvfF"s4
*6TQZJ@L
<di#U'
$g]sfh
1ZXS[[
,$Ep6oP
3<$1<$3<$\
X34$14$34$\
F>?1|$
``a`aa
S:;)t$
3<$1<$3<$
`aaZPRPRRZ
1P`aXZX
$$]ro?
34$14$34$
34$14$34$\
`VW_^PQYQYX
4$Xh&@
_34$14$34$\
4$[UT]R
`aXaPR
1S`a[`PR
1S[ZXaPR
1ZXZXZX
4$XUT]
1ZX_PR
1ZXZX`W_
4$XRTZ
PRPR`aQY
1`a`aZX`PR
aZXPR`PR
1ZXV^a
3,$1,$3,$\
1ZXW_aZX
4$0+5l
4$\4#[
,$&9O~
3,$1,$3,$
3<$1<$3<$\V
]34$14$34$\
3<$1<$
4}~Z]3<$1<$3<$
34$14$
34$14$
PhGa0X-Ca0
-{ZswS
4IFSMGR VKD VMM VWIN32 VXDLDR
?gD/1|$
3<$1<$3<$\
s?5^c
1,$3,$\
3,$1,$
3An internal exception occurred (Address: 0x%x)
Please, contact yoursite@yoursite.com. Thank you!
1ZXPXa
5'j"~U
`PXW_aP
``a`aa
+fuZ{S
APPRPR
1`aZXZX
PPRPRW_
1ZXZXa
`aXP``PX`aaPRRZ
1ZXZXa
1`W_`aaZX
`aPR`a
8_/'AP
PRQS[Y
1ZXZXZXPPRPR
PPRVPR
1``aPR
1ZXaZX
1ZXZXZX
QsOvnrA5
[hr>aX
Zd%KMy
]\`/@q
=%5$4;
]hSnz+
1<$3<$
34$14$
Y3<$1<$3<$
PQS[YXSPR`aRZ
1ZX`aZX
"_=1\$
4$Xh6p/
),$]MM
(<VW7]
$[hjlS
S37m/}U=w-
uS37m/}U=w-
u ` `
` ` `
/}U ` ` `(
` ` ` `
uS37m/}U=w-
uS37m/}5
jjjjjj
jjjjjj
jjjjjj
#+3;CScs
pepperiop.digital/oage
zaazz6a
jjjjjj
L6zz6a
6L6LL6
azaz6a
Antivirus Signature
Bkav Clean
Lionic Trojan.Win32.LummaStealer.4!c
Elastic malicious (high confidence)
MicroWorld-eScan Clean
CMC Clean
CAT-QuickHeal Clean
Skyhigh BehavesLike.Win32.Generic.tm
ALYac Clean
Cylance Unsafe
Zillya Clean
Sangfor Clean
CrowdStrike win/malicious_confidence_100% (W)
Alibaba Clean
K7GW Riskware ( 00584baa1 )
K7AntiVirus Riskware ( 00584baa1 )
huorong Clean
Baidu Clean
VirIT Clean
Paloalto Clean
Symantec Clean
tehtris Generic.Malware
ESET-NOD32 Clean
APEX Malicious
Avast FileRepMalware [Misc]
Cynet Clean
Kaspersky Clean
BitDefender Clean
NANO-Antivirus Clean
ViRobot Clean
Tencent Clean
Sophos Generic ML PUA (PUA)
F-Secure Clean
DrWeb Clean
VIPRE Clean
TrendMicro Clean
McAfeeD Real Protect-LS!D8227401EB02
Trapmine malicious.high.ml.score
CTX exe.trojan.lummastealer
Emsisoft Clean
Ikarus Trojan-Spy.Win32.LummaStealer
GData Win32.Trojan-Stealer.LummaStealer.YMZFSO
Jiangmin Clean
Webroot Clean
Varist Clean
Avira Clean
Antiy-AVL Trojan/Win32.LummaStealer
Kingsoft malware.kb.a.871
Gridinsoft Clean
Xcitium Clean
Arcabit Clean
SUPERAntiSpyware Clean
ZoneAlarm Clean
Microsoft Trojan:Win32/LummaStealer.DM!MTB
Google Detected
AhnLab-V3 Trojan/Win.LummaStealer.C5750503
Acronis Clean
McAfee Artemis!D8227401EB02
TACHYON Clean
VBA32 Clean
Malwarebytes Malware.AI.2835294281
Panda Clean
Zoner Probably Heur.ExeHeaderL
TrendMicro-HouseCall TROJ_GEN.R002H01DA25
Rising Trojan.LummaStealer!8.17CC6 (TFE:4:zPmeQf0lK3S)
Yandex Clean
SentinelOne Static AI - Malicious PE
MaxSecure Clean
Fortinet Clean
AVG FileRepMalware [Misc]
DeepInstinct MALICIOUS
alibabacloud Clean
IRMA Signature
Trend Micro SProtect (Linux) Clean
Avast Core Security (Linux) Win32:MalwareX-gen [Misc]
C4S ClamAV (Linux) Clean
Trellix (Linux) Clean
Sophos Anti-Virus (Linux) Clean
Bitdefender Antivirus (Linux) Clean
G Data Antivirus (Windows) Clean
WithSecure (Linux) Clean
ESET Security (Windows) Clean
DrWeb Antivirus (Linux) Clean
ClamAV (Linux) Clean
eScan Antivirus (Linux) Clean
Emsisoft Commandline Scanner (Windows) Clean
Cuckoo

We're processing your submission... This could take a few seconds.