Static | ZeroBOX

PE Compile Time

2021-04-08 09:05:51

PDB Path

c:\Whether\class\156\Through\How.pdb

PE Imphash

1b129b745ed786ce1fe8186651a3c22d

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x00048fb4 0x00049000 6.19236668836
.data 0x0004a000 0x00107148 0x00001000 2.33342954195
.rsrc 0x00152000 0x00000388 0x00000400 3.01615246914
.reloc 0x00153000 0x00001d08 0x00001e00 4.6094977131

Resources

Name Offset Size Language Sub-language File type
RT_VERSION 0x00152058 0x00000330 LANG_ENGLISH SUBLANG_ENGLISH_US data

Imports

Library KERNEL32.dll:
0x1001000 TlsAlloc
0x1001004 TlsSetValue
0x1001008 VirtualProtectEx
0x1001010 CompareStringW
0x1001014 CompareStringA
0x1001018 CreateFileA
0x1001020 SetStdHandle
0x1001024 WriteConsoleW
0x1001028 GetConsoleOutputCP
0x100102c WriteConsoleA
0x1001030 CloseHandle
0x1001034 GetLocaleInfoW
0x1001038 HeapSize
0x100103c SetFilePointer
0x1001040 IsValidLocale
0x1001044 EnumSystemLocalesA
0x1001048 GetLocaleInfoA
0x100104c GetUserDefaultLCID
0x1001050 GetDateFormatA
0x1001054 GetTimeFormatA
0x1001058 GetStringTypeW
0x100105c GetStringTypeA
0x1001060 HeapAlloc
0x1001064 GetCurrentThreadId
0x1001068 GetCommandLineA
0x100106c EnterCriticalSection
0x1001070 LeaveCriticalSection
0x1001074 SetHandleCount
0x1001078 GetStdHandle
0x100107c GetFileType
0x1001080 GetStartupInfoA
0x1001084 DeleteCriticalSection
0x1001088 TerminateProcess
0x100108c GetCurrentProcess
0x1001098 IsDebuggerPresent
0x100109c FatalAppExitA
0x10010a0 HeapFree
0x10010a4 VirtualFree
0x10010a8 VirtualAlloc
0x10010ac HeapReAlloc
0x10010b0 HeapCreate
0x10010b4 HeapDestroy
0x10010b8 GetModuleHandleW
0x10010bc Sleep
0x10010c0 GetProcAddress
0x10010c4 ExitProcess
0x10010c8 WriteFile
0x10010cc GetModuleFileNameA
0x10010d0 TlsGetValue
0x10010d4 TlsFree
0x10010d8 InterlockedIncrement
0x10010dc SetLastError
0x10010e0 GetLastError
0x10010e4 InterlockedDecrement
0x10010e8 GetCurrentThread
0x10010f0 GetEnvironmentStrings
0x10010f8 WideCharToMultiByte
0x1001104 GetTickCount
0x1001108 GetCurrentProcessId
0x1001114 RtlUnwind
0x1001118 GetCPInfo
0x100111c GetACP
0x1001120 GetOEMCP
0x1001124 IsValidCodePage
0x1001128 SetConsoleCtrlHandler
0x100112c FreeLibrary
0x1001130 InterlockedExchange
0x1001134 LoadLibraryA
0x1001138 GetConsoleCP
0x100113c GetConsoleMode
0x1001140 FlushFileBuffers
0x1001144 LCMapStringA
0x1001148 MultiByteToWideChar
0x100114c LCMapStringW
Library snmpapi.dll:
0x1001158 SnmpSvcGetUptime
0x100115c SnmpSvcSetLogLevel
0x1001160 SnmpSvcSetLogType
0x1001164 SnmpUtilAsnAnyCpy
0x1001168 SnmpUtilIdsToA
0x100116c SnmpUtilMemAlloc
0x1001170 SnmpUtilMemFree
0x1001174 SnmpUtilMemReAlloc
0x1001178 SnmpUtilAsnAnyFree
0x100117c SnmpUtilDbgPrint
0x1001180 SnmpUtilOctetsCmp
0x1001184 SnmpUtilOctetsNCmp
0x1001188 SnmpUtilOidAppend
0x100118c SnmpUtilOidCmp
0x1001190 SnmpUtilOidCpy
0x1001194 SnmpUtilOidFree
0x1001198 SnmpUtilVarBindFree

Exports

Ordinal Address Name
1 0x103343e Pape1
2 0x103328b Riverslow
!This program cannot be run in DOS mode.
`.data
@.reloc
bad allocation
UCRR(>9R(V
q4\\y;y9
um0;mk
8888{{{{
8888{{{{
ubL|V{k
RxP8K{{*
}:(YP8
ly p~z} 7
2Oc.sn,
2`b
lqi%aL<u/]P4
{Kd}jp
NKi[bv-
2-0)N
{o?2JtK
t$`HcF
t$XHcF
t$PHcF
A_A^A]A\_^[]
@SUVWH
@USVWATAUAVAWH
d$@IcD$
A_A^A]A\_^[]
@UVWATAUAVAWH
A_A^A]A\_^]
@UATAUAVAWH
t$pHcF
t$pHcF
t$pHcF
A_A^A]A\]
|$ ATH
(null)
`h````
xpxxxx
`h`hhh
xppwpp
CorExitProcess
runtime error
TLOSS error
SING error
DOMAIN error
An application has made an attempt to load the C runtime library incorrectly.
Please contact the application's support team for more information.
- Attempt to use MSIL code from this assembly during native code initialization
This indicates a bug in your application. It is most likely the result of calling an MSIL-compiled (/clr) function from a native constructor or from DllMain.
- not enough space for locale information
- Attempt to initialize the CRT more than once.
This indicates a bug in your application.
- CRT not initialized
- unable to initialize heap
- not enough space for lowio initialization
- not enough space for stdio initialization
- pure virtual function call
- not enough space for _onexit/atexit table
- unable to open console device
- unexpected heap error
- unexpected multithread lock error
- not enough space for thread data
This application has requested the Runtime to terminate it in an unusual way.
Please contact the application's support team for more information.
- not enough space for environment
- not enough space for arguments
- floating point support not loaded
Microsoft Visual C++ Runtime Library
<program name unknown>
Runtime Error!
Program:
EncodePointer
DecodePointer
FlsFree
FlsSetValue
FlsGetValue
FlsAlloc
LC_TIME
LC_NUMERIC
LC_MONETARY
LC_CTYPE
LC_COLLATE
LC_ALL
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
SystemFunction036
ADVAPI32.DLL
GetProcessWindowStation
GetUserObjectInformationA
GetLastActivePopup
GetActiveWindow
MessageBoxA
USER32.DLL
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
HH:mm:ss
dddd, MMMM dd, yyyy
MM/dd/yy
December
November
October
September
August
February
January
Saturday
Friday
Thursday
Wednesday
Tuesday
Monday
Sunday
united-states
united-kingdom
trinidad & tobago
south-korea
south-africa
south korea
south africa
slovak
puerto-rico
pr-china
pr china
new-zealand
hong-kong
holland
great britain
england
britain
america
swedish-finland
spanish-venezuela
spanish-uruguay
spanish-puerto rico
spanish-peru
spanish-paraguay
spanish-panama
spanish-nicaragua
spanish-modern
spanish-mexican
spanish-honduras
spanish-guatemala
spanish-el salvador
spanish-ecuador
spanish-dominican republic
spanish-costa rica
spanish-colombia
spanish-chile
spanish-bolivia
spanish-argentina
portuguese-brazilian
norwegian-nynorsk
norwegian-bokmal
norwegian
italian-swiss
irish-english
german-swiss
german-luxembourg
german-lichtenstein
german-austrian
french-swiss
french-luxembourg
french-canadian
french-belgian
english-usa
english-us
english-uk
english-trinidad y tobago
english-south africa
english-nz
english-jamaica
english-ire
english-caribbean
english-can
english-belize
english-aus
english-american
dutch-belgian
chinese-traditional
chinese-singapore
chinese-simplified
chinese-hongkong
chinese
canadian
belgian
australian
american-english
american english
american
Norwegian-Nynorsk
SunMonTueWedThuFriSat
JanFebMarAprMayJunJulAugSepOctNovDec
CONIN$
CONOUT$
c:\Whether\class\156\Through\How.pdb
Aw[
^^q(
,()e"#'
#.k !
}M3;
F}))w
)<q5B{
E>
-NiJ
"bnyO=
!vt5
1w`vNr
k|O~?E1
x-mU=yc
O&<O9}
$}SWyJ
5?
y{
7IZ!~!
n j\u
DFyl|w
) 8)O3
~6
o;zI"
*n> '
<X;e-W<
Z|>@
zy6j
9IOX<"
!p~CBr
KbS2L.
__=
OC
Q `Kn
E H^W
T1JE
8|;yY,'
` ~q0
Qj?MVx
$QG~Tz
HqBS
gQ<n48
/W9hH (
^5IBU5
yu
~OwE,)
&HM
-}Cg {
/Q8P
-U%%Pe
10./,-
!i
R.
${ }
F*z
*}i+qk
l]'6~x@P6t
B>D
1 <E-
8O~
9z
H`/!Ad
}~[V$`_
+l#x0T
|4y
Mr.d+-
_FK
X,
4Cz*"j
?N66kC
j@j ^V
HHtXHHt
>If90t
HHtYHHt
tM<it-<ot)<ut%<xt!<Xt
<dty<itu<otq<utm<xti<Xte
HIf98t
>=Yt1j
URPQQh
0A@@Ju
^SSSSS
j"^SSSSS
_VVVVV
_VVVVV
0SSSSS
0SSSSS
0SSSSS
;t$,v-
UQPXY]Y[
t"SS9]
C PjPV
C$PjQV
C*PjTV
C+PjUV
C,PjVV
C-PjWV
C.PjRV
C/PjSV
.;1s(N
HHt4HHt
Ht\Ht,
teHtFHt&Hu
ty<%tA
PPPPPPPP
PPPPPPPP
u,VVWV
t VV9u
t+WWVPV
^SSSSS
^SSSSS
>:u8FV
VVVVVQRSSj
^SSSSS
^SSSSS
0SSSSS
^SSSSS
^WWWWW
0SSSSS
8VVVVV
TlsAlloc
TlsSetValue
VirtualProtectEx
FindFirstChangeNotificationW
KERNEL32.dll
SnmpUtilVarBindListFree
SnmpUtilVarBindListCpy
SnmpUtilVarBindFree
SnmpUtilOidFree
SnmpUtilOidCpy
SnmpUtilOidCmp
SnmpUtilOidAppend
SnmpUtilOctetsNCmp
SnmpUtilOctetsCmp
SnmpUtilDbgPrint
SnmpUtilAsnAnyFree
SnmpUtilMemReAlloc
SnmpUtilMemFree
SnmpUtilMemAlloc
SnmpUtilIdsToA
SnmpUtilAsnAnyCpy
SnmpSvcSetLogType
SnmpSvcSetLogLevel
SnmpSvcGetUptime
snmpapi.dll
HeapAlloc
GetCurrentThreadId
GetCommandLineA
EnterCriticalSection
LeaveCriticalSection
SetHandleCount
GetStdHandle
GetFileType
GetStartupInfoA
DeleteCriticalSection
TerminateProcess
GetCurrentProcess
UnhandledExceptionFilter
SetUnhandledExceptionFilter
IsDebuggerPresent
FatalAppExitA
HeapFree
VirtualFree
VirtualAlloc
HeapReAlloc
HeapCreate
HeapDestroy
GetModuleHandleW
GetProcAddress
ExitProcess
WriteFile
GetModuleFileNameA
TlsGetValue
TlsFree
InterlockedIncrement
SetLastError
GetLastError
InterlockedDecrement
GetCurrentThread
FreeEnvironmentStringsA
GetEnvironmentStrings
FreeEnvironmentStringsW
WideCharToMultiByte
GetEnvironmentStringsW
QueryPerformanceCounter
GetTickCount
GetCurrentProcessId
GetSystemTimeAsFileTime
InitializeCriticalSectionAndSpinCount
RtlUnwind
GetCPInfo
GetACP
GetOEMCP
IsValidCodePage
SetConsoleCtrlHandler
FreeLibrary
InterlockedExchange
LoadLibraryA
GetConsoleCP
GetConsoleMode
FlushFileBuffers
LCMapStringA
MultiByteToWideChar
LCMapStringW
GetStringTypeA
GetStringTypeW
GetTimeFormatA
GetDateFormatA
GetUserDefaultLCID
GetLocaleInfoA
EnumSystemLocalesA
IsValidLocale
SetFilePointer
HeapSize
GetLocaleInfoW
CloseHandle
WriteConsoleA
GetConsoleOutputCP
WriteConsoleW
SetStdHandle
GetTimeZoneInformation
CreateFileA
CompareStringA
CompareStringW
SetEnvironmentVariableA
How.dll
Riverslow
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
; ;$;(;,;0;4;8;<;@;D;x<|<
; ;(;0;8;@;H;P;X;`;h;p;x;
< <(<0<8<@<H<P<X<`<h<p<x<
= =(=0=8=@=H=P=X=`=h=p=x=
!9%9+9/95999?9C9I9M9S9W9]9a9g9k9q9u9{9
:.:S:g:v:}:
;;%;0;=;C;N;\;e;n;|;
<"<0<8<=<F<K<X<^<g<v<
=!='=.=7=@=M=X=]=d=o=|=
> >%>+>6>G>O>U>[>h>
? ?+?3?^?
0d0j0s0
1?1D1e1p1v1
272G2X2q2
31383=3J3P3|3
4)4?4E4L4`4f4~4
5"5(5.545:5@5F5L5R5X5^5d5j5p5w5
9":::B:H:
<%<2<><N<U<d<p<}<
=9=H=Q=u=
1W1i1;2E2R2m2t2
3.3Q3d314N4
5;6v6~6
3%3/3Y3g3m3
435A5x5
5(868<8V8[8j8s8
9 9'9;9B9H9V9]9b9k9x9~9
>+>7>E>K>Q>V>_>y>
1!2-2`2
5+535?5F5O5b5l5x5
7!747?7D7T7^7e7p7y7
7-8:8d8i8t8y8
:$:-:m:r:
;!;7;J;k;
<.<4<?<K<`<g<{<
=&=,=7=A=G=S=b=h=}=
><>Q>w>
&0.0z0
1!1'1.141;1A1I1P1U1]1f1r1w1|1
22?2E2a2}2
3 373=3]3f3r3
4I4R4^4v4
5"5,5=5H5[5
7#7)7.747
;(;4;<;D;P;t;|;
=/>\>w>
5+555H5l5
8/8J8R8Z8q8
8"939?9E9b9':Q:
<"<3<o<
=*=6=B=M=U=
3f4I6y6
;2;b;l;x;
81888<8@8D8H8L8P8T8
9!9<9C9H9L9P9q9
9::@:D:H:L:
:%;>;g;l;
;"<-<X<c<q<v<{<
<+=Z=z=
?.?6?N?
0J0O0V0[0b0g0
2>2F2S2
4!4/454E4J4b4h4w4}4
525O57&7,7Y7`7h7
78%818
:4:::F:
>?>X>_>g>l>p>t>
?N?T?X?\?`?
0!0K0}0
6a7*8[8q8
:4;:;@;F;L;R;Y;`;g;n;u;|;
2Q3[3s3z3
4F5W5_54;
<=*=3=V=
>'>9>K>]>
4&5.5L5T5r5z5
1%6-6<6
8*8<8P8
4"4&4*4.42464:4>4B4F4J4N4R4V4Z4^4b4f4j4n4r4v4z4~4
;T<a<z<
3!3L3W3z3>4K4`4r4
;6;>;K;R;
=!>/>7>D>b>l>u>
0;1N1_1
2#3.3\3j3s3
3'444\4
6)6F6r6
;);.;4;E;J;W;_;n;u;
=->8>t>}>
?a?i?u?
8"848h8p8
0W2f2F3c3l3x3
9$909?9s9
="=(=.=4=:=@=F=L=R=X=^=d=j=p=v=|=
>$>*>0>6><>B>H>N>T>Z>`>f>l>r>x>~>
?#?(?-?P?p?
080D0`0
1(1H1h1
202L2P2l2p2
303P3p3
404P4p4
585X5x5
1@5D5l6t6|6
7$7x;p<
=<=H=L=P=T=X=`=d=h=l=p=t=x=|=
> >$>(>,>0>4>8><>@>D>H>L>P>`>h>l>p>t>x>|>
(null)
mscoree.dll
KERNEL32.DLL
((((( H
h(((( H
H
VS_VERSION_INFO
StringFileInfo
040904B0
CompanyName
Equalher Corporation Doublemolecule
FileDescription
Equalher Size self
FileVersion
3.4.8.182
InternalName
Period
LegalCopyright
Equalher Corporation. All rights reserved
OriginalFilename
How.dll
ProductVersion
3.4.8.182
ProductName
Equalher
Size self
VarFileInfo
Translation
Antivirus Signature
Bkav Clean
Elastic malicious (high confidence)
MicroWorld-eScan Clean
FireEye Clean
CAT-QuickHeal Clean
McAfee Clean
Cylance Clean
VIPRE Clean
AegisLab Trojan.Win32.Cridex.7!c
Sangfor Clean
CrowdStrike Clean
BitDefender Clean
K7GW Clean
K7AntiVirus Clean
Baidu Clean
Cyren Clean
Symantec Clean
ESET-NOD32 Clean
APEX Clean
Avast FileRepMetagen [Malware]
ClamAV Clean
Kaspersky UDS:Trojan-Banker.Win32.Cridex.gen
Alibaba Clean
NANO-Antivirus Clean
ViRobot Clean
Tencent Clean
Ad-Aware Clean
TACHYON Clean
Sophos Clean
Comodo Clean
F-Secure Clean
DrWeb Clean
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition Clean
CMC Clean
Emsisoft Clean
SentinelOne Clean
GData Clean
Jiangmin Clean
eGambit Clean
Avira Clean
Antiy-AVL Clean
Kingsoft Clean
Gridinsoft Clean
Arcabit Clean
SUPERAntiSpyware Clean
ZoneAlarm UDS:DangerousObject.Multi.Generic
Microsoft Clean
Cynet Clean
AhnLab-V3 Clean
Acronis Clean
BitDefenderTheta Clean
MAX Clean
VBA32 BScope.Trojan.Wacatac
Malwarebytes Clean
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Rising Malware.Undefined!8.C (CLOUD)
Yandex Clean
Ikarus Clean
MaxSecure Clean
Fortinet Clean
Webroot W32.Trojan.Gen
AVG FileRepMetagen [Malware]
Paloalto Clean
Qihoo-360 Clean
No IRMA results available.