Static | ZeroBOX

PE Compile Time

2021-06-17 17:20:06

PE Imphash

db502765cff159e5db66145a73cb6cd7

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x000015f4 0x00001600 6.12712886743
.data 0x00003000 0x000425d1 0x00042600 6.40918747224
.rdata 0x00046000 0x000003dc 0x00000400 4.82692747493
.bss 0x00047000 0x000009ce 0x00000000 0.0
.edata 0x00048000 0x000000b0 0x00000200 1.93547245344
.idata 0x00049000 0x00000f67 0x00000600 4.15872715085
.CRT 0x0004a000 0x0000002c 0x00000200 0.201539378135
.tls 0x0004b000 0x000009e7 0x00000200 0.0
.reloc 0x0004c000 0x00000534 0x00000600 5.85837125388

Imports

Library KERNEL32.dll:
0x6bb090ec CreateThread
0x6bb090f0 DeleteCriticalSection
0x6bb090f4 EnterCriticalSection
0x6bb090f8 GetCurrentProcess
0x6bb090fc GetCurrentProcessId
0x6bb09100 GetCurrentThreadId
0x6bb09104 GetLastError
0x6bb0910c GetTickCount
0x6bb09114 LeaveCriticalSection
0x6bb09120 Sleep
0x6bb09124 TerminateProcess
0x6bb09128 TlsGetValue
0x6bb09130 VirtualAlloc
0x6bb09134 VirtualProtect
0x6bb09138 VirtualQuery
Library msvcrt.dll:
0x6bb09140 _amsg_exit
0x6bb09144 _initterm
0x6bb09148 _iob
0x6bb0914c _lock
0x6bb09150 _unlock
0x6bb09154 abort
0x6bb09158 calloc
0x6bb0915c free
0x6bb09160 fwrite
0x6bb09164 malloc
0x6bb09168 realloc
0x6bb0916c strlen
0x6bb09170 strncmp
0x6bb09174 vfprintf
Library USER32.dll:
0x6bb0917c PeekMessageA
0x6bb09180 PostThreadMessageA

Exports

Ordinal Address Name
1 0x6bac15a2 DllGetClassObject
2 0x6bac1547 DllMain
3 0x6bac159c DllRegisterServer
4 0x6bac159f DllUnregisterServer
5 0x6bac15af StartW
!This program cannot be run in DOS mode.
P`.data
.rdata
0@.bss
.edata
0@.idata
.reloc
kMZucV
kMZucV
6{|-*O
V#KA2!
<7{|-%
zs<^zs(Yz
iKiViKyViK}Vm{u
=E`mKE
A*iKYQ
mK}_iKeV
S=#|^l
iKqVoKu
SKgViKunD
iWg3)Y
iKiViK!V
}_iKmV
mKy_iKiV
'%CVoK
SF5$SFSo
#%CVoK
#%CVoK
_z6iKaV
&mKy=#
=^Po;ea
-{|-&z
UmKyV"
zViKan
R[>ToK)VoCIWo[ET
R[>ToK)VoCIWo[ETiKQV
esy]XD
.esuR.
oC}`o
YCC4eCC5kCC6|CC7`CC0kCC1bCC2=CC3<CC<
CC8BCC9aCC:oCC;jCC
CCTXCCUgCCV|CCWzCCP{CCQoCCRbCCSOCC\bCC]bCC^aCC_mCCX
CC$XCC%gCC&|CC'zCC {CC!oCC"bCC#^CC,|CC-aCC.zCC/kCC(mCC)zCC*
iKYVoCyWo[
i[5ToKyVoC
R[>ToK)VoCIWo[ET
R[>ToK)VoCIWo[ETiKQV
esy]XD
.esuR.
i"#Ky&
6{|-#z
-{|-&d
-{|-&d
oSi5>-
\5<-_5<
]5:-\5:
_5=-[5=
]5=-_5<
]5=-_5<
_mKy=#
^z4o[eW
^z4o[}W
mKy=#z
C0Yz6oK]
eSF5$SFSo
%SF5$SF
iWiKyV
}5-5|s
ViKuViKyViK
ViKqViK}V
WnriKyV
5$SFSo
i56=LQ
iK}VoK
'=EF'd
R%5%OE7
5$QFSo
==rh5$Q
oCu=%s
zYoKyX
iKiViK
ViK-Vi
iK-ViKiVo
iK-ViK
iKiViK
ViK-Vi
{aVoK}
iK!ViKQV
(iKaViK!Vi{a
5$QFSo
oCq=%s
oCq5?M
zViKIV
Ka5?Ml
=WDiFz
zViHuV
mSMHmSa
zViKIV
zViKIV
=5ru5$NF
=#rp5$QFPo
zViK)ViKIViK9Vi
ViKuVo
ViKeVo
FViKuV
zViKuVo
zViK)ViKIViK9Vi
s8%D-4
=LGiKI
ViKiVo
n<iK9Vo
=LGiKi
iKiVo
o[e=4r
_mK]5$
SF5$SF
z['=E['
z['=E['
=zAmsa5?7
=%|n5$SF
LmCy=2x
9mK}\mN
{9mC}x
['=E['
oLy<'z
=2|m5$Q
['=E['
mKe5-3
Q[@cF_
m{a5$7=
iKmVoK
WiK}ViKml
z_msyU
$-M=,{
oKe="z
mC}`o{}`
=^EmSy
gym[q=.z
z_mKe=#
de56Vr
de56Vr
mKq='zQ
]oCy5)
3W%wr
3W%wr
z_oCy5)
_mKe=#z
]oCy5)
iKmVoK
_mKy="z
="{$5$Q
iPo;='
m{y="{
5CrU%~
oKmEi2
_mKi="z
_mKy='z
mSy=/x
Ui[qTi[YTi[
iKmVoK
4NmO5tCy
Xw])3I
4g,+1a6
EoxC%/
J$/#c
<rP.=/e
K{P4Ze
5/2r!7K
Bu[9rU
.:t_ j
NmO5E`F;Xw])SzT'bYk
W:1#}1<*s,+1a'&8osk
>=?u341~$/#c)&-h
DVuO-[|A&LgS;An]0bQw
.=/e'3$h<!9
Bu[9K{P4PiM#YgF.
^}_5PvR<BkE'L`H.fQk
.%7} .:t23-o<8 f
:O93F#
%MvS0E
_6z!K
4w<,4+<h4
3@;=3/;
>B66>^6D>,6J>26X>
4{<N5>=:5p=z1*9
6B>)6P>[6
4H<14^<S48<
2K:02::~2
3S;I32;c3
6E>.6S>G6>>Z6
7@?=7=?e7
3Q;R3:;
1\9]1;9
;)3W;=3j;
9`179'1d9
6&>L60>
7C?47X?
>i6'>46Y>
5M=35t=
:@2=:,2K:
;O3T;23
7@?.7V?<7,?U7
=5{=*5R=85 =S5
?c7"?%7w?
2&:Q2R:
6v>#6,>a6
3c;3R;N36;X3
0F8U0>8n0
1m9t1u7/?
6!?L7)?T71?\79?d7
4y<$4A<,4I<44Q<<4Y<D4!<L4)<T41<\49<d4
0i8L0:8x0
8\0H860
9n19U1h9
6r>"6,>]6
0f8%0N8;0.8P0
951R9E189m1
?z7(?%7N?
5%=U5@=
?*7R?87s?
2F:*2a:
;v3";[3I;
1+9X1Y9
6b> 6I>16
7J?<7+?o7
1E6]=85e=
8N018.0X8
9u129/1`9
7}?07(?Z7
5F=356=
2@:821:o2
:x36;%3];E0
7j?%76?S7>?[7
<0'8R0
2a: 28:h2I9
<w4E<?4d<
=I52=Z5L=65m=
:Y2G:)2W:
8v098.0U8
4B<.4^<F44<^4
5B=(5V=>5,=K5
6M<74^<
8F0L820
;r3;C3<;o0
8F088 0Y8
9T129/1W9
6y>!6U>Q6
7E?<7;?
5a=%5A=(5W=?5$=B5)=P58=d5
2O:N25:h2
5c=&5J=
8%038g0
1e91D9
<u4%<M4;<
=V5A=65b=
:Q2A:k09880y8
>T69>l7
8x0%8@0-8H058
9M169/1q9
?k4B=55
:r2+;\3
68>#6j>
<E4?<<4
7z?"7W?i7
3F;(3 ;U39;a3
8*0,8Y0
?t74??7
3B;*3Q;;3';W3
:N2*:[2A:.2U:
8x0"8.0
;{38;#3U;?3u;
>$6V>h6
4y<J43<
=|5%=O5^=
<x4%<@4-<H45<P4=<X4E< 4M<(4U<04]<84e<
3u;3B;53X;B3
3};!3(;V3
;k3'8O018`0c6
>z6,>/6W>
?T72?#7W?
< 4N<?4c<
8D0"8S0G8
9x1"9,1J9;1o9
6B>864>
4n<$4P<
3|;!3T;
2;:02[:
1t971>9
53,;I34;Q3<;Y3
7D?!7L?)7T?17\?970?]78?a7
3h;534;u3
0t850(8U0
1x9%1$9Y1
>l6!>L6M>
<H45<(4U<
6H<14X<A4(<Q48<a4
5x=55\=
;L3);T31;\39;$3A;,3I;43Q;<3Y;
Mingw-w64 runtime failure:
Address %p has no image-section
VirtualQuery failed for %d bytes at address %p
VirtualProtect failed with code 0x%x
Unknown pseudo relocation protocol version %d.
Unknown pseudo relocation bit size %d.
GCC: (GNU) 8.3-win32 20190909
GCC: (GNU) 8.3-win32 20190909
GCC: (GNU) 8.3-win32 20190909
GCC: (GNU) 8.3-win32 20190909
GCC: (GNU) 8.3-win32 20190909
GCC: (GNU) 8.3-win32 20190909
GCC: (GNU) 8.3-win32 20190909
GCC: (GNU) 8.3-win32 20190909
GCC: (GNU) 8.3-win32 20190909
GCC: (GNU) 8.3-win32 20190909
GCC: (GNU) 8.3-win32 20190909
GCC: (GNU) 8.3-win32 20190909
GCC: (GNU) 8.3-win32 20190909
GCC: (GNU) 8.3-win32 20190909
GCC: (GNU) 8.3-win32 20190909
GCC: (GNU) 8.3-win32 20190909
GCC: (GNU) 8.3-win32 20190909
GCC: (GNU) 8.3-win32 20190909
GCC: (GNU) 8.3-win32 20190909
GCC: (GNU) 8.3-win32 20190909
GCC: (GNU) 8.3-win32 20190909
GCC: (GNU) 8.3-win32 20190909
temp.dll
DllGetClassObject
DllMain
DllRegisterServer
DllUnregisterServer
StartW
CreateThread
DeleteCriticalSection
EnterCriticalSection
GetCurrentProcess
GetCurrentProcessId
GetCurrentThreadId
GetLastError
GetSystemTimeAsFileTime
GetTickCount
InitializeCriticalSection
LeaveCriticalSection
QueryPerformanceCounter
SetUnhandledExceptionFilter
TerminateProcess
TlsGetValue
UnhandledExceptionFilter
VirtualAlloc
VirtualProtect
VirtualQuery
_amsg_exit
_initterm
_unlock
calloc
fwrite
malloc
realloc
strlen
strncmp
vfprintf
PeekMessageA
PostThreadMessageA
KERNEL32.dll
msvcrt.dll
USER32.dll
000D0Y0f0q0
1<1c1n1x1
575g5w5
576V6k6
7"787V7k7|7
8 8(818;8A8J8[8
:/:O:p:
;2;V;h;m;r;};
<)<1<=<B<S<d<
=/=5=@=F=R=b=z=
>$>)>/><>B>e>
?A?J?T?s?}?
0%1/1>1I1N1T1
152>2J2e2o2~2
4044484<4
>.>7>Z>}>
`0o0}0
12272Z2p2
3#3=3Z3
=A>V>_>h>q>
0&0=0R0g0
1/1T1y1
3(353C3O3`3~3
4S5h5q5
6C6W6i6{6
95:i:r:
7=7P7U7s7
708Z8m8
1O1a1u1
2_7y;l=
0 1<1h1
1(2T2p2
4,5P5`5|5
646X6h6
No antivirus signatures available.
No IRMA results available.