Static | ZeroBOX

PE Compile Time

2021-07-17 23:20:53

PDB Path

pdmmgree.pdb

PE Imphash

c3803752167a683f3dbd2e2ab3d19b6d

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.rda 0x00001000 0x0004b240 0x0004c000 7.95449036186
.rdata 0x0004d000 0x00000c52 0x00001000 4.3216593163
.data1 0x0004e000 0x00007c01 0x00005000 7.32734481951
.m5Fih 0x00056000 0x00000a2e 0x00001000 0.9245015566
.reloc 0x00057000 0x000006dc 0x00001000 3.60943902267

Resources

Name Offset Size Language Sub-language File type
RT_VERSION 0x00056060 0x000002fc LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data

Imports

Library POWRPROF.dll:
0x44d078 ReadGlobalPwrPolicy
Library KERNEL32.dll:
0x44d018 LoadLibraryExW
0x44d01c LocalFree
0x44d024 AddConsoleAliasA
0x44d028 HeapWalk
0x44d02c HeapCreate
0x44d030 EraseTape
0x44d034 EnumSystemLocalesA
0x44d038 GetModuleHandleW
0x44d040 SetFileAttributesW
0x44d048 LockFile
0x44d04c GetLocaleInfoW
0x44d058 GlobalFindAtomA
0x44d05c GetProcAddress
0x44d060 LoadLibraryA
0x44d064 GetModuleHandleA
0x44d068 GlobalAddAtomW
0x44d06c FindFirstFileA
Library WININET.dll:
Library msvcrt.dll:
0x44d0ac memset
Library USER32.dll:
0x44d080 GetWindowRect
0x44d084 InsertMenuA
0x44d08c SetCursor
0x44d090 ShowCaret
0x44d094 IsWindow
Library ole32.dll:
Library GDI32.dll:
0x44d000 GetDeviceCaps
0x44d004 GetObjectW
0x44d008 GetCharWidthW
0x44d00c GetPaletteEntries
0x44d010 GetBitmapBits
Library WINSPOOL.DRV:

!This program cannot be run in DOS mode.
`.rdata
@.data1
.m5Fih
@.reloc
D$HY]9{
t$\9L$\
T$(9T$h
D$(9D$(tD
T$0+L$0)
D$(#D$(
f#L$(5
D$(9D$(
f#D$(+L$0
f+T$0#T$(
T$0+L$0)
t$0#L$()
BT0cf9
D$ +D$X
L$D+D$D
V\f+D$n
D$(;L$(s
T$$*L$m
D$Ku*D$m
*D$?8D$'r
;HHfz+4o
<i7Rz<]lmM
'vE[i!'_
c]7(tr
/]Dt]k(Q
.75|A)
xM`+J^
-Gn|cJ
'hNjSz
SAi)\c
rU221_jR
L/RBnq
p@<M`"
Rx8'5=a
T_2Vxc
hU]]u
M&<.8I
j!}2M:a&
yv{>^e
Kp#s]9z
R,;pqO
M~oy/P
j70G1P
R4\&+@[R
c9I#$t
=OuF /d
iGsCtf
wRr%dgG
67fvHc
cb=Lcl
]r-Bo1
#>m-_8Xz@;
Q_P_~w
nM"52L%t
4<bRbi
JsB`^B
/v2#{(f
E0`qKDKN
FVH<z{
+R1DTU
^Sf5V$
';/H>]P
:t(2,s2
&\oSVg
]%1YYw
Q?5q@,
T?fn2P))
Ro7nCy
j3Z1z7
#z8hC>y]
) 4@[,
QKl?W-
&' >A'
;Me*?+
'??*V:#;
I4L*Y%[j
':LH%
$~~UY~
1vAYTs
)uj55~
>G!iE:|t
#:v" 9e&
!1tB}9*
DT(_u!
]`9*`kD
p:@cZN
h E<_X
eEOXfH
k5CRE^%
_io[I*
NpK^V}
EiH|GUH
7^N!4n
P!XJo|
g0c)9T$
!_!]Hp
F*d0te
y%8B>0_
N,H61;
h)~RU<xt
"Epq4p=
6EiI\P
srKYWR
wD)d%O
P~^GmUar6*
hk[T8>
>zPUR0
*4WF{J
Sh$[1`l
=`x|sH(&
knapl5
TMlJuv
%IV;r2
!AtbFDXt
UE#\RwS
\OluJ(uZ
JV*Zk?*
> Z;@8
'5'`krWL$qUj
K~f"$u
FK)0Kq
h:b4fL
$Nd_?[
lmP2v0w
gQf(QN
Y"9LbM
VV@"L@j
@|vgj3
6K7B\!iQ
\pv5o8
:Q9WM`z2
uTxWhZ
cB5}7*
!F(,##
\p~oYx-
)~/Jo(
|F*]P8x#
R\u3cR^
$7]$y_
=?}E5N
ITX?E+C
Qrm%T(
HTUu/P
i!^WA'
v_SQI,
MPxhZ]
=E^Ozpy
%bMQv\
fC`q !
0sz6rB
[@Q:@@
{m_?fb
F*R.^D
12vz)$
pUF9yK
iEl**jy
(@Y`d"x
63df h
P|wlb!
|=d>u#^A
BJHA|e
*E6\x'B
Y>>Oge
sY8ob4
R'2uW}
[>RKH2
:%1/Cm
PRT2+t
kZ.;bf
c_k)s*
9?rCkv.
G+)A/=t
"*8Xtk
mJK;i{
WP9Koo
2VoV"!
|}c?AB
5{~+8M
2q|{yH
\;}iF>3~
M?a#[H
,lds6*o
w#3CaN
9EPA$7
$?~TmQ
acBRfV
J~t&(1S
`Zz-z^
lh-o<>|
W(l'z
&MEQDks
I^){ps
`q9V#L
3V8@y0K
[?|.O%
U02RqW
p;0hva
y&$7wU
+FW'6Z
8}T`l:l&
m!q2K|
X2zim0
5#b7AP
"F.#J
HZ31~s
,S.WXw
n9H1qsmp+
X/*'ID
bvy^XK
gef~d_L8
{<{VUb
Nyhr*F|
n.5yC-a
>maOs"K[
$|OV@4
=lhS?>
C1'[r
je>J4f
,_),m_
11lc]~
Yc3MOS
6~TVb
{>K;%`
[]F58m
7%L&vh
,x34dc
J*=h^c
=+-g-&
O'<ho{
AQj\HQ
=^+4-'S
?\KRbvuEr_
8?Hd)"g
4ieg[u
e'zB-%
b=Cqrw{
1cNeC?2
uNTc^9
ui|o}V
^ mm-j`
^vft >
~@e\'W
fjxcgg0c
FoTc0@
jKqDm^
#NX8x:yh
w!vSL3<
due3CW
{:c@S5!
;JWk9BJ
;_3}F-
mY',5N
^x9W0V
?xg4e$
cE*Bn3;=
fa7 S[
Q*($7m
yz~&)9
W<jE:T2
Y2s^bsu
A*Lvj<
d!:L|
_g!ncQ
BIj-]{
^_j4*@H
":V6|T)
jq|"/Db)
[-zYnB
tB^"B3
nkn7bX
KAJ@re
w*x>svz
'Zr5$j
{{QmDc
ZZd}}:
)I:W@i?
R$QK`XF
Vc$7uF
HJe,w9
Ge|AZM6n(9
F&UhBfH
AE"/jF|
lU[lMw4E
CE#,=A
JV.>At
ax\l=$
ICK6
c)`<IGv
g4tvUV+I
<;;r~k
AL$dIu
IG7POEp
gaCw;4|
~Xvz`+
of2>d`-
Q0r&qr3
oqlI)f
NER?P}48
hE$6[i
Fu@*YN
R[cU1u
Xf>pm;
pS:en
]qUlJ%A
2b#5~C
"H|+m;
F>|p9N
J@tiK<
d%!5X%S
?nYT^gW?
Wu5Fr
'}Negun
9E?+hR
#Q`QV-R2
aXKnw-:
uvS0jf8_
L/=K5z
ZABxM.
06y_ey
V,'SC|
P;qaXN
ZFp)mK
|6f4[I
sLAkOt*px
t2|&//]t
=+(cjT
Na*CE*
xa9pBZ(
c2|Y%afhVu
TW>>O_
**(Yu`
RK;#R6?"Z
W%9wnh
~-<Ci4
(?|}i5
~=-m'F
e9YCZN$
1P9vXu
V?zzmQK
&YU&Z%%
awS=Ug
/nJCM)
7%YZeTG
%o~3IKc
6}i7w"sb
/]G 7m8
XkEt98
k8pn1Y
DxIjwK
sV-.a ^
*C<P]q
*'WN&7t
i;!62g
27E"|h
a`f#1[
PA4g'Te*
Vs0O[.
)xy9[0
]339mg
d_dwpl
|KgRV3&
AuL=(p
Ab*drx
mu8Y{d
N sK|
J$3``Y@
U.))!3n!
(xbXf?
Xvq+De
hz?r`D
[U2]Fq
y9K@w`c
>"=jy(o
t`SNXX
6BCk+64
eppWu7
(CT?3,
UNG[W$
)oA]W,
ug2[1L
T([KUH
h*o%bu
}q-S|n
|ncqH:!O
7,]R8>Z
.T@`TV
jr3mZ%*
Z%|VlS
:$FoTl
&"P:`$#e
aLkP1
'+9eNU,
sV`f]y
b%:D/^X(
2ZPX4/
3U6%2A@
/&KV+yW
I\fJD0
(XhEJa
x{(jiN
tWeML7
GS#dgp
?^}X#e
^M' cg*
3(3T\u
oOzA4#
dP1D&7
l-Jm,
Y%fT8h
E~CW@g(
$Iu<nV
f_d31UT
PSZQ+F
b>!*FH-
/6Mt4QF
XK>0H-Z7<
8h]F@s
@l*Dvh
G;$>@Ek
f~;2Yr
JJ[kqno
87NyeB
u2*v|C
b)U,zl
AqK~~]
dw`G`?8nk7
8VTm[>o
,#S:Tl
C%m:d>
!}<eP2+
;5=1}S
' 2QiI
5l._NN4
|`{ /
]1RNT\
pR2Xc#+
"`,M]w[
"P_Fjb
gBw^T\ui7
>:)jmz;
.1oL1'V
e[LGK<Wi
uv^FjAz
;a"i_
/y/c t
eM3Q%1
V) Kng"
pe+!3{
T3i>.4
l'XqAf.
cu{9|a
-nZ|3_
cUQ<[v
h'1pN>"
z#i3U3
kLj[g#A
+R6F!\y8%a
/f\]N(
DY`^P^
5.GB*O
"+il8r
s1YUI<
7&_4(H
)m-FUD[
%ejeqQ
aPMFm3<
:Bl?(]
H]vFqL
j^)~!z
6MT),_r
W.L0~&?
=4g<PkF
MC2?'|,
rV^WcL
0TOg-7
q8j.BY
@M2>>U
sj)&'0
l0T(~F2
^dDzDG
6v&<)Ly
;2l3Ib
P6K)K@
5!N@!bUmxz
q}GuDO
8`>#T"
ubRvL
}w;*-}
,QGW<$Y
WFTa2un
'=`RFI
PDq@tM
F#"6&"P
+B42]I
m"WoyFc
ag-,6L
F;2zhg
&0{O*u
3'G"I^H
@.17V/
O{/x[$
ln_ccLA
=m;MX2*
D4ppO7
D<WdF@
5w[51x
&0{ds|
ST*AR$
EOQ#;,
+zfW7YCe
m;!ebc
IeyxDG
oq'>=W
*G_aur
gDKz9Q
{;U4`%
R;at=#]
?UsTkD
oh8E\F
oT}g_l
,B?:.c
$>Fd0>
?yFJ:s
X7{,5"
'"xbWn
~^$% 2l
.3l(e
pDPk.%O
IsThreadAFiber
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
LdrGetProcedureAk
7P6ChromeQcanThisIhad
F13Daenables
eppeedf.dll
pdmmgree.pdb
ReadGlobalPwrPolicy
IsPwrHibernateAllowed
POWRPROF.dll
GetModuleHandleA
GetProcAddress
GetModuleHandleW
LoadLibraryExW
LocalFree
GetCurrentConsoleFont
AddConsoleAliasA
HeapWalk
HeapCreate
EraseTape
EnumSystemLocalesA
GlobalAddAtomW
GetProcessAffinityMask
SetFileAttributesW
DeleteVolumeMountPointW
LockFile
GetLocaleInfoW
FillConsoleOutputAttribute
GetConsoleCursorInfo
GlobalFindAtomA
FindFirstFileA
LoadLibraryA
KERNEL32.dll
RetrieveUrlCacheEntryStreamW
WININET.dll
memset
msvcrt.dll
ShowCaret
IsWindow
GetWindowRect
InsertMenuA
GetClipboardFormatNameA
SetCursor
USER32.dll
CoFreeUnusedLibrariesEx
ole32.dll
GetDeviceCaps
GetObjectW
GetCharWidthW
GetPaletteEntries
GetBitmapBits
GDI32.dll
FindNextPrinterChangeNotification
WINSPOOL.DRV
:zPgqs
MwWioLgk
@>oOJf1
WU:6#8
hU9,i=
~KDid
Ki=;R#Sg
p\@p$9
3iqj/u
_]b3Dr$
B3-NXK
=%N,;;
)0mPkX
>'C9uo!
@dB`}N
Bbvj'W2BA
R% \!I_
]"py'%
)kBCSV<
4n;_Uf
<0Z`KI
&`;s#
tJI'Ab
4|RaXY/
bWwZ\D
i49SqO
@$]baF
|M-EMDiu
[c1k>c
RN-#z
1Lg)@
_1c(L(@
1c#|{@
0!0*030<0
3A4P5,8
: :/:>:M:\:
=">O>v>
0,1O1|1
= =&=,=2=8=C=N=Y=u=|=
>">6><>B>K>T>Z>c>
?N?T?\?}?
0/070t0z0
1?1E1c1
1 2&2,2k2q2
3Z3`3n3
3C4I4O4x4~4
5%535A5O5]5k5y5
5+6d6n6
7#717?7M7[7i7w7
2!2*20262<2
:H:L:P:T:X:\:`:d:h:l:p:t:x:|:
; ;$;(;,;0;4;8;<;@;D;H;P;`;d;h;l;p;
< <$<(<p<t<x<|<
<(=,=0=4=8=<=@=D=H=L=P=T=X=\=`=d=h=l=p=x=
> >$>(>0>@>D>H>L>P>
?P?T?X?\?`?d?h?l?p?t?x?|?
0 0$0(0,0004080<0@0D0H0L0P0X0h0l0p0t0x0
1 1$1(1,101x1|1
1024282<2@2D2H2L2P2T2X2\2`2d2h2l2p2t2x2
3 3$3(3,30383H3L3P3T3X3
4X4\4`4d4h4l4p4t4x4|4
5 5$5(5,5054585<5@5D5H5L5P5T5X5`5p5t5x5|5
6(6,6064686
687<7@7D7H7L7P7T7X7\7`7d7h7l7p7t7x7|7
8 8$8(8,8084888@8P8T8X8\8`8
ntdll.dl
kernel320due3fromj
betaorNUMFL
content2,the7
austinXDublin.engine.135
mNoalong
jItheapplications,
frommountainwasfF537
blogstarting7channelPConcurrently,
forensicnumber,1BranchactivityasksLinux
d38subsequentu0thumbnailsapplet
loadblayoutChromeandwillie
wnUlifeTheofficialt
bubbaYHjGooglebeforeschoolRsecurity
theirxqcrashes.4444inlalso
also4InzmickeyofS
JwebsiteTWwebsite5versionq
m3bookmarks,kfIqb
of309Allavdemonstratorcurrently
GFattackfree
the5Partial
HreleaseUniversitybuilt-inbutqthatVDI
GovernmentZkCNET2ashitEasterF
self.exe
testapp.exe
VS_VERSION_INFO
StringFileInfo
080404b0
CompanyName
CHENGDU YIWO Tech Development Co., Ltd (YIWO Tech Ltd, for short).
FileVersion
2, 9, 0, 0
InternalName
LegalCopyright
Copyright (c)2006-2008 CHENGDU YIWO Tech Development Co., Ltd.
OriginalFilename
wv.exe
ProductVersion
2, 9, 0, 0
VarFileInfo
Translation
No antivirus signatures available.
No IRMA results available.