Static | ZeroBOX

PE Compile Time

2021-04-16 16:47:12

PDB Path

c:\Friend\507\123\Rol\well W\Flower.pdb

PE Imphash

28e501612900311a5e5c7fed3dd79d00

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x00049d14 0x00049e00 6.20599588203
.data 0x0004b000 0x00109ba0 0x00001000 2.58806537383
.rsrc 0x00155000 0x00000468 0x00000600 2.94194825311
.reloc 0x00156000 0x000020d4 0x00002200 4.90185749017

Resources

Name Offset Size Language Sub-language File type
RT_VERSION 0x001550a0 0x00000330 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_MANIFEST 0x001553d0 0x00000091 LANG_ENGLISH SUBLANG_ENGLISH_US XML 1.0 document text

Imports

Library KERNEL32.dll:
0x1001014 OpenMutexW
0x1001018 VirtualProtectEx
0x100101c CreateProcessW
0x1001020 GetCurrentDirectoryW
0x1001024 GetFileAttributesW
0x1001028 CompareStringW
0x100102c CompareStringA
0x1001030 GetLastError
0x1001034 HeapFree
0x1001038 HeapAlloc
0x100103c GetCurrentThreadId
0x1001040 GetCommandLineA
0x1001044 HeapCreate
0x1001048 HeapDestroy
0x100104c VirtualFree
0x1001050 DeleteCriticalSection
0x1001054 LeaveCriticalSection
0x1001058 FatalAppExitA
0x100105c EnterCriticalSection
0x1001060 VirtualAlloc
0x1001064 HeapReAlloc
0x1001068 GetModuleHandleW
0x100106c Sleep
0x1001070 GetProcAddress
0x1001074 ExitProcess
0x1001078 WriteFile
0x100107c GetStdHandle
0x1001080 GetModuleFileNameA
0x1001084 TlsGetValue
0x1001088 TlsAlloc
0x100108c TlsSetValue
0x1001090 TlsFree
0x1001094 InterlockedIncrement
0x1001098 SetLastError
0x100109c InterlockedDecrement
0x10010a0 GetCurrentThread
0x10010a4 SetHandleCount
0x10010a8 GetFileType
0x10010ac GetStartupInfoA
0x10010b4 GetEnvironmentStrings
0x10010bc WideCharToMultiByte
0x10010c8 GetTickCount
0x10010cc GetCurrentProcessId
0x10010d4 RaiseException
0x10010d8 TerminateProcess
0x10010dc GetCurrentProcess
0x10010e8 IsDebuggerPresent
0x10010f0 RtlUnwind
0x10010f4 SetConsoleCtrlHandler
0x10010f8 FreeLibrary
0x10010fc InterlockedExchange
0x1001100 LoadLibraryA
0x1001104 GetCPInfo
0x1001108 GetACP
0x100110c GetOEMCP
0x1001110 IsValidCodePage
0x1001114 HeapSize
0x1001118 GetLocaleInfoW
0x100111c GetLocaleInfoA
0x1001120 GetTimeFormatA
0x1001124 GetDateFormatA
0x1001128 GetUserDefaultLCID
0x100112c EnumSystemLocalesA
0x1001130 IsValidLocale
0x1001134 GetStringTypeA
0x1001138 MultiByteToWideChar
0x100113c GetStringTypeW
0x1001140 LCMapStringA
0x1001144 LCMapStringW
Library ADVAPI32.dll:
0x1001000 RegCloseKey
0x1001004 RegCreateKeyW
0x1001008 RegOpenKeyExW
0x100100c RegQueryValueExA
Library XOLEHLP.dll:
0x1001154 None

Exports

Ordinal Address Name
1 0x1033719 Hadlaw
2 0x103394e Might
!This program cannot be run in DOS mode.
N0Richs
`.data
@.reloc
bad allocation
rJWJBK
wuOF
^ prp\
h-rDMxxx
DDDD||||
lllliiii
Tuww!&
p (9RG
PhzpISY
=Ch;cm
I L-{c
0Ma,&;y
/=& Y
n 6
w zd=}d7Q
H9]'tCH
@UVWATAUAVAWH
PA_A^A]A\_^]
8A%t&:
A_A^A]A\_^[]
@SUVWH
@USVWATAUAVAWH
d$@IcD$
A_A^A]A\_^[]
@UVWATAUAVAWH
UWATAUAVH
A^A]A\_]
@UVWATAUAVAWH
CorExitProcess
runtime error
TLOSS error
SING error
DOMAIN error
An application has made an attempt to load the C runtime library incorrectly.
Please contact the application's support team for more information.
- Attempt to use MSIL code from this assembly during native code initialization
This indicates a bug in your application. It is most likely the result of calling an MSIL-compiled (/clr) function from a native constructor or from DllMain.
- not enough space for locale information
- Attempt to initialize the CRT more than once.
This indicates a bug in your application.
- CRT not initialized
- unable to initialize heap
- not enough space for lowio initialization
- not enough space for stdio initialization
- pure virtual function call
- not enough space for _onexit/atexit table
- unable to open console device
- unexpected heap error
- unexpected multithread lock error
- not enough space for thread data
This application has requested the Runtime to terminate it in an unusual way.
Please contact the application's support team for more information.
- not enough space for environment
- not enough space for arguments
- floating point support not loaded
Microsoft Visual C++ Runtime Library
<program name unknown>
Runtime Error!
Program:
EncodePointer
DecodePointer
FlsFree
FlsSetValue
FlsGetValue
FlsAlloc
Unknown exception
SystemFunction036
ADVAPI32.DLL
GetProcessWindowStation
GetUserObjectInformationA
GetLastActivePopup
GetActiveWindow
MessageBoxA
USER32.DLL
LC_TIME
LC_NUMERIC
LC_MONETARY
LC_CTYPE
LC_COLLATE
LC_ALL
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
HH:mm:ss
dddd, MMMM dd, yyyy
MM/dd/yy
December
November
October
September
August
February
January
Saturday
Friday
Thursday
Wednesday
Tuesday
Monday
Sunday
united-states
united-kingdom
trinidad & tobago
south-korea
south-africa
south korea
south africa
slovak
puerto-rico
pr-china
pr china
new-zealand
hong-kong
holland
great britain
england
britain
america
swedish-finland
spanish-venezuela
spanish-uruguay
spanish-puerto rico
spanish-peru
spanish-paraguay
spanish-panama
spanish-nicaragua
spanish-modern
spanish-mexican
spanish-honduras
spanish-guatemala
spanish-el salvador
spanish-ecuador
spanish-dominican republic
spanish-costa rica
spanish-colombia
spanish-chile
spanish-bolivia
spanish-argentina
portuguese-brazilian
norwegian-nynorsk
norwegian-bokmal
norwegian
italian-swiss
irish-english
german-swiss
german-luxembourg
german-lichtenstein
german-austrian
french-swiss
french-luxembourg
french-canadian
french-belgian
english-usa
english-us
english-uk
english-trinidad y tobago
english-south africa
english-nz
english-jamaica
english-ire
english-caribbean
english-can
english-belize
english-aus
english-american
dutch-belgian
chinese-traditional
chinese-singapore
chinese-simplified
chinese-hongkong
chinese
canadian
belgian
australian
american-english
american english
american
Norwegian-Nynorsk
Complete Object Locator'
Class Hierarchy Descriptor'
Base Class Array'
Base Class Descriptor at (
Type Descriptor'
`local static thread guard'
`managed vector copy constructor iterator'
`vector vbase copy constructor iterator'
`vector copy constructor iterator'
`dynamic atexit destructor for '
`dynamic initializer for '
`eh vector vbase copy constructor iterator'
`eh vector copy constructor iterator'
`managed vector destructor iterator'
`managed vector constructor iterator'
`placement delete[] closure'
`placement delete closure'
`omni callsig'
delete[]
new[]
`local vftable constructor closure'
`local vftable'
`udt returning'
`copy constructor closure'
`eh vector vbase constructor iterator'
`eh vector destructor iterator'
`eh vector constructor iterator'
`virtual displacement map'
`vector vbase constructor iterator'
`vector destructor iterator'
`vector constructor iterator'
`scalar deleting destructor'
`default constructor closure'
`vector deleting destructor'
`vbase destructor'
`string'
`local static guard'
`typeof'
`vcall'
`vbtable'
`vftable'
operator
delete
__unaligned
__restrict
__ptr64
__clrcall
__fastcall
__thiscall
__stdcall
__pascal
__cdecl
__based(
{flat}
`non-type-template-parameter
unsigned
short
<ellipsis>
,<ellipsis>
throw(
`template-parameter
cli::pin_ptr<
cli::array<
`anonymous namespace'
generic-type-
template-parameter-
`unknown ecsu'
union
struct
class
coclass
cointerface
extern "C"
[thunk]:
public:
protected:
private:
virtual
static
`template static data member destructor helper'
`template static data member constructor helper'
`local static destructor helper'
`adjustor{
`vtordisp{
`vtordispex{
const
volatile
volatile
volatile
signed
double
UNKNOWN
__int128
wchar_t
__int64
__int16
__int32
__int8
__w64
SunMonTueWedThuFriSat
JanFebMarAprMayJunJulAugSepOctNovDec
c:\Friend\507\123\Rol\well W\Flower.pdb
ZWM9hy
l
Xo J
#1-
UgHe2'.
V2)[c!j
q[UH>J
L} 61
!`K%i
p$
Kr[,o{n
DsFT
IG^6# S
Ak
1aX$zc
q$@ #}
#J|"Ps|
>t1H
NvD1=~yd
-a
\[`?35PQ
fLYU
b^_!U
0" dY=:
OsI_o-l
d4.k
@x
'Ve?:=m
{4
&a#Igb\p
U%
%Yu#
],$%rg
0u@k6dw
wt
mt%T:
*
Z[ &
w:1jBo
\$,xM%;b
:QT
x p|
j^
63A
_)+L Z
NN?l*%
Yr kOJ
Rx2lPy
[Y<tD+KP
45
#tZ`
Jz"]
$_]>cG
vny>Hn
Oe4f7x
!l/e)P
^ewB/u
14
~|b]I
'DwkO|
TDm7p{
3$3r/t
Hc
&v rl.
}9
9|3pOr
w[8(]0mXF
p-
D$ jIZ+
u19=`?
j@j ^V
>=Yt1j
URPQQh
_VVVVV
_VVVVV
0SSSSS
0SSSSS
0SSSSS
0A@@Ju
uL9=(D
;t$,v-
UQPXY]Y[
u,VVWV
t VV9u
C PjPV
C$PjQV
C*PjTV
C+PjUV
C,PjVV
C-PjWV
C.PjRV
C/PjSV
.;1s(N
HHt4HHt
Ht\Ht,
teHtFHt&Hu
ty<%tA
PPPPPPPP
PPPPPPPP
t"SS9]
HHt*HHt
<0|<9
tK<_t<<$t8<<t4<>t0<-t,<a|
<z~$<A|
<0|O<9
tU<A|B<P
tY<@tO<Zt
t\<@tXj'
NtFNt#NuV
t.<@t5V
TtUHtKHtAHt
0t-HHt
dj@h,I
AtIHt0Hu
^SSSSS
^SSSSS
>:u8FV
VVVVVQRSSj
^SSSSS
^SSSSS
0SSSSS
t+WWVPV
^SSSSS
^WWWWW
0SSSSS
8VVVVV
GetFileAttributesW
CreateProcessW
VirtualProtectEx
OpenMutexW
GetCurrentDirectoryW
KERNEL32.dll
RegOpenKeyExW
RegCreateKeyW
RegCloseKey
RegQueryValueExA
ADVAPI32.dll
XOLEHLP.dll
GetLastError
HeapFree
HeapAlloc
GetCurrentThreadId
GetCommandLineA
HeapCreate
HeapDestroy
VirtualFree
DeleteCriticalSection
LeaveCriticalSection
FatalAppExitA
EnterCriticalSection
VirtualAlloc
HeapReAlloc
GetModuleHandleW
GetProcAddress
ExitProcess
WriteFile
GetStdHandle
GetModuleFileNameA
TlsGetValue
TlsAlloc
TlsSetValue
TlsFree
InterlockedIncrement
SetLastError
InterlockedDecrement
GetCurrentThread
SetHandleCount
GetFileType
GetStartupInfoA
FreeEnvironmentStringsA
GetEnvironmentStrings
FreeEnvironmentStringsW
WideCharToMultiByte
GetEnvironmentStringsW
QueryPerformanceCounter
GetTickCount
GetCurrentProcessId
GetSystemTimeAsFileTime
RaiseException
TerminateProcess
GetCurrentProcess
UnhandledExceptionFilter
SetUnhandledExceptionFilter
IsDebuggerPresent
InitializeCriticalSectionAndSpinCount
RtlUnwind
SetConsoleCtrlHandler
FreeLibrary
InterlockedExchange
LoadLibraryA
GetCPInfo
GetACP
GetOEMCP
IsValidCodePage
HeapSize
GetLocaleInfoW
GetLocaleInfoA
GetTimeFormatA
GetDateFormatA
GetUserDefaultLCID
EnumSystemLocalesA
IsValidLocale
GetStringTypeA
MultiByteToWideChar
GetStringTypeW
LCMapStringA
LCMapStringW
GetTimeZoneInformation
CompareStringA
CompareStringW
SetEnvironmentVariableA
Flower.dll
Hadlaw
.?AVbad_alloc@std@@
.?AVexception@std@@
.?AVbad_cast@std@@
.?AVbad_typeid@std@@
.?AV__non_rtti_object@std@@
.?AVtype_info@@
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
<?xml version='1.0' encoding='UTF-8' standalone='yes'?>
<assembly xmlns='urn:schemas-microsoft-com:asm.v1' manifestVersion='1.0'>
</assembly>
`1d1p1t1x1
2 2$2(2,20242820383<3@3D3H3L3P3T3X3\3`3d3h3l3p3t3
h2p2x2
3 3(30383@3H3P3X3`3h3p3x3
4 4(40484@4H4P4X4`4h4p4x4
; ;$;(;,;0;4;8;<;@;D;H;L;P;T;X;\;`;d;h;l;p;t;x;|;
< <$<(<,<0<4<8<<<@<D<H<L<P<T<X<\<`<d<h<l<p<t<x<|<
141D1H1\1`1p1t1
2 2$2(202H2X2\2l2p2x2
/=4=9=>=C=H=M=R=X=\=a=f=k=p=v=z=
>'>->5>;>A>N>Z>d>j>
?#?)?5???D?I?T?Z?c?n?u?
0%0-040K0X0n0
1=1E1L1g1y1
2+2O2_2o2}2
33&383D3e3k3q3}3
4/454W4]4|4
5"5(5.5H5
6+6M6k6}6
77%717<7C7K7Y7e7m7
9%9/999A9P9\9s9
:":(:.:4:::L:^:
:-;M;c;i;
<=7=?=E=
1"1.151>1Q1[1g1p1x1
232G2M2[2n2
2:3Z3c3n3}3
4"4'464=4C4K4Q4c4h4
7 737>7D7J7O7X7u7{7
8,828C8
8<<J<a<g<l<{<
020w0}0
1[3f3n3
7%70757E7O7V7a7j7
8+8U8Z8e8j8
;(;;;\;
<<%<0<<<Q<X<l<s<
=(=2=8=D=S=Y=n=
>->B>h>
00k0{0
11%1,121:1A1F1N1W1c1h1m1s1w1}1
20262R2w2
3!3Z3c3o3
606N6p6{6
7'717B7M7`7
9 9(9.93999
< =-=9=A=I=U=y=
?#???\?y?
4N4W4l4
4585?5G5L5P5T5}5
5.64686<6@6
7+7]7d7h7l7p7t7x7|7
7'8I8U8a9(:-:?:]:q:w:
='=>=x=
>!>9>A>Y>a>y>
>*?/?t?y?
1101h1p1}1
3/3K3Y3_3o3t3
3?4\4y4
7$7*7G7
;';2;:;d;p;
>N?g?x?
1K2.4^4
9G9Q9]9f9?:|:
<Q<^<h<v<
<D=O=Y=r=|=
E0Q0d0v0
1@1i1z1
1?2E2Q2
3 4T4Z4f4
4*8_8x8
9 9$9n9t9x9|9
: :A:k:
>#?f?l?
1<2O2U2[2a2g2m2t2{2
3 3&3<3C3X3
3A4[4d4
<K=]=g=q=
080H0Z0n0
(<,<0<4<8<<<@<D<H<L<P<T<X<\<`<d<h<l<p<t<x<|<
3 3$303:3R3Y3c3k3x3
496K6X6d6n6v6
6x7(8K8
<&=+>U>e>q?
0'050C0N0Y0d0r0}0
233T3\3a3h3n3t3y3
?6?Q?]?
1C2j2o2v2}2
3A3c3i3u3|3
4/4J4|4
4$535S5]5
7)878>8z8
9#9-9H9\9m9z9
>/>6>X>]>y>
>'?5?d?~?
3"4>4N4[4{4
5D5K5T5^5e5q5w5
6*60666_6i6
7!797I7n7
869W9l9
9":':=:b:
>B?Z?z?
7%7.7z7
8]8q8w8
:):8:p:
4.4;4A4K4Y4
66%6L6v6
7)7_7f7k7u7
8&8:8[8e8o8
8%9B9I9P9W9u9
9E:W:k:
<<<I<Y<i<
0T1]1c1h1
2%2*272?2N2U2b2
5A6I6U6b6i6q6y6
?0F0{0
072F2:3k3
;`=f=l=r=x=~=
> >&>,>2>8>>>D>J>P>V>\>b>h>n>t>z>
?!?,?5?:???D?I?N?S?[?_?d?
080X0x0
1$1(1D1H1d1h1
202<2X2d2p2
303P3p3
404P4p4
4$4,444<4D4L4T4\4d4l4t4|4
5 5@5d5h5
6(686H6X6|6
< <$<(<,<0<4<8<<<@<D<H<L<P<T<X<\<`<d<h<l<p<t<x<|<
mscoree.dll
KERNEL32.DLL
((((( H
h(((( H
H
VS_VERSION_INFO
StringFileInfo
040904B0
CompanyName
Termwide Corporation
FileDescription
Termwide Grass fire Untilsuccess
FileVersion
2.3.6.358
InternalName
LegalCopyright
Termwide Corporation. All rights reserved
OriginalFilename
Flower.dll
ProductVersion
2.3.6.358
ProductName
Termwide
Grass fire
VarFileInfo
Translation
Antivirus Signature
Bkav Clean
Elastic malicious (high confidence)
MicroWorld-eScan Clean
CMC Clean
CAT-QuickHeal Clean
Qihoo-360 Clean
ALYac Clean
Malwarebytes Clean
Zillya Clean
SUPERAntiSpyware Clean
Sangfor Clean
CrowdStrike Clean
Alibaba Clean
K7GW Clean
K7AntiVirus Clean
BitDefenderTheta Clean
Cyren Clean
Symantec Clean
ESET-NOD32 a variant of Win32/GenKryptik.FEWM
Baidu Clean
TrendMicro-HouseCall Clean
Paloalto Clean
ClamAV Clean
Kaspersky Clean
BitDefender Clean
NANO-Antivirus Clean
ViRobot Clean
Avast FileRepMalware
Tencent Clean
Ad-Aware Clean
Emsisoft Clean
Comodo Clean
F-Secure Clean
DrWeb Clean
VIPRE Clean
TrendMicro Clean
McAfee-GW-Edition Artemis!Trojan
FireEye Clean
Sophos Generic PUA NA (PUA)
APEX Clean
GData Clean
Jiangmin Clean
Webroot Clean
Avira Clean
MAX Clean
Antiy-AVL Clean
Kingsoft Clean
Gridinsoft Clean
Arcabit Clean
AegisLab Clean
ZoneAlarm Clean
Microsoft Program:Win32/Wacapew.C!ml
Cynet Clean
AhnLab-V3 Clean
Acronis Clean
McAfee Artemis!9DEBCD929765
TACHYON Clean
VBA32 BScope.TrojanBanker.Cridex
Cylance Clean
Ikarus Clean
Zoner Clean
Rising Trojan.GenKryptik!8.AA55 (CLOUD)
Yandex Clean
SentinelOne Clean
eGambit Clean
Fortinet Clean
AVG FileRepMalware
Panda Clean
MaxSecure Clean
No IRMA results available.