Static | ZeroBOX

PE Compile Time

2021-09-01 22:52:39

PDB Path

C:\2\dll\Release\Test01.pdb

PE Imphash

9b1adb266f8f339c45ccfafdc830f22f

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x0000b8aa 0x0000ba00 6.63472734788
.rdata 0x0000d000 0x00002923 0x00002a00 4.89109986025
.data 0x00010000 0x00002f48 0x00001200 3.25522114951
.rsrc 0x00013000 0x0004211c 0x00042200 7.15515776789
.reloc 0x00056000 0x0000113e 0x00001200 4.3560957938

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x00016b60 0x00000368 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00016b60 0x00000368 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00016b60 0x00000368 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00016b60 0x00000368 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00016b60 0x00000368 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00016b60 0x00000368 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00016b60 0x00000368 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00016b60 0x00000368 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00016b60 0x00000368 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00016b60 0x00000368 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00016b60 0x00000368 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00016b60 0x00000368 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_GROUP_ICON 0x00016ec8 0x000000ae LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_HTML 0x00016f78 0x0003e047 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_MANIFEST 0x00054fc0 0x0000015a LANG_ENGLISH SUBLANG_ENGLISH_US ASCII text, with CRLF line terminators

Imports

Library KERNEL32.dll:
0x1000d028 FormatMessageA
0x1000d02c LockResource
0x1000d030 SizeofResource
0x1000d034 LoadResource
0x1000d038 FindResourceA
0x1000d03c CreateThread
0x1000d040 Sleep
0x1000d044 VirtualAlloc
0x1000d048 GetProcAddress
0x1000d04c IsBadReadPtr
0x1000d050 VirtualProtect
0x1000d054 VirtualQuery
0x1000d058 GetCurrentProcess
0x1000d05c lstrlenA
0x1000d060 CloseHandle
0x1000d064 CreateFileW
0x1000d068 HeapSize
0x1000d06c FlushFileBuffers
0x1000d070 GetStringTypeW
0x1000d074 LCMapStringW
0x1000d078 WriteConsoleW
0x1000d07c SetStdHandle
0x1000d080 GetModuleFileNameW
0x1000d084 LocalAlloc
0x1000d088 LocalSize
0x1000d08c LocalFree
0x1000d090 GetStdHandle
0x1000d09c MultiByteToWideChar
0x1000d0a0 GetLastError
0x1000d0a4 GetModuleHandleA
0x1000d0ac HeapFree
0x1000d0b0 GetCurrentThreadId
0x1000d0b4 DecodePointer
0x1000d0b8 GetCommandLineA
0x1000d0c4 IsDebuggerPresent
0x1000d0c8 EncodePointer
0x1000d0cc TerminateProcess
0x1000d0d0 EnterCriticalSection
0x1000d0d4 LeaveCriticalSection
0x1000d0d8 HeapCreate
0x1000d0dc HeapDestroy
0x1000d0e4 RtlUnwind
0x1000d0e8 TlsAlloc
0x1000d0ec TlsGetValue
0x1000d0f0 TlsSetValue
0x1000d0f4 TlsFree
0x1000d0f8 InterlockedIncrement
0x1000d0fc GetModuleHandleW
0x1000d100 SetLastError
0x1000d104 InterlockedDecrement
0x1000d108 ExitProcess
0x1000d10c SetHandleCount
0x1000d114 GetFileType
0x1000d118 GetStartupInfoW
0x1000d11c DeleteCriticalSection
0x1000d120 GetModuleFileNameA
0x1000d128 WideCharToMultiByte
0x1000d12c GetEnvironmentStringsW
0x1000d134 GetTickCount
0x1000d138 GetCurrentProcessId
0x1000d13c SetFilePointer
0x1000d140 WriteFile
0x1000d144 GetConsoleCP
0x1000d148 GetConsoleMode
0x1000d14c GetCPInfo
0x1000d150 GetACP
0x1000d154 GetOEMCP
0x1000d158 IsValidCodePage
0x1000d15c HeapAlloc
0x1000d160 HeapReAlloc
0x1000d164 LoadLibraryW
Library USER32.dll:
0x1000d16c wsprintfA
0x1000d170 MessageBoxW
0x1000d174 GetDesktopWindow
0x1000d178 CreateWindowExA
0x1000d17c ShowWindow
0x1000d180 SetWindowRgn
0x1000d184 DestroyWindow
0x1000d188 SetWindowTextA
0x1000d18c GetWindowDC
0x1000d190 GetDC
0x1000d194 ReleaseDC
0x1000d198 MessageBoxIndirectA
Library GDI32.dll:
0x1000d000 CreateICA
0x1000d004 CreateEllipticRgn
0x1000d008 Rectangle
0x1000d00c DeleteDC
0x1000d010 CreateDCA
Library IPHLPAPI.DLL:
0x1000d018 IcmpSendEcho
0x1000d01c IcmpCloseHandle
0x1000d020 IcmpCreateFile

Exports

Ordinal Address Name
1 0x100015d0 Dpi400
2 0x10001350 Dpi800
3 0x100012f0 GetMouse
!This program cannot be run in DOS mode.
`.rdata
@.data
@.reloc
VC20XC00U
HHtXHHt
?If90t
;t$,v-
UQPXY]Y[
j@j ^V
URPQQh
^SSSSS
t"SS9] u
<+t"<-t
+t HHt
PPPPPPPP
PPPPPPPP
Window Region
Elliptic Window
Rectangular Window
DISPLAY
[ GOOD ]
%s failed with error %u: %s
IcmpSendEcho
ReplySize
hIcmpFile
Data Buffer
@riskerror
lonmtrfvceasvcre
X86CONTENT
timing_IcmpSendEcho
GetProcAddress(MessageBoxA)
changes
MessageBoxA
user32.dll
(null)
`h````
xpxxxx
FlsFree
FlsSetValue
FlsGetValue
FlsAlloc
CorExitProcess
HH:mm:ss
dddd, MMMM dd, yyyy
MM/dd/yy
December
November
October
September
August
February
January
Saturday
Friday
Thursday
Wednesday
Tuesday
Monday
Sunday
`h`hhh
xppwpp
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@
_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
1#QNAN
1#SNAN
GetProcessWindowStation
GetUserObjectInformationW
GetLastActivePopup
GetActiveWindow
MessageBoxW
C:\2\dll\Release\Test01.pdb
GetModuleHandleA
GetLastError
MultiByteToWideChar
SetConsoleTextAttribute
GetConsoleScreenBufferInfo
GetStdHandle
LocalFree
LocalSize
LocalAlloc
lstrlenA
FormatMessageA
LockResource
SizeofResource
LoadResource
FindResourceA
CreateThread
VirtualAlloc
GetProcAddress
IsBadReadPtr
VirtualProtect
VirtualQuery
GetCurrentProcess
KERNEL32.dll
MessageBoxIndirectA
ReleaseDC
GetWindowDC
SetWindowTextA
DestroyWindow
SetWindowRgn
ShowWindow
CreateWindowExA
GetDesktopWindow
MessageBoxW
wsprintfA
USER32.dll
DeleteDC
CreateEllipticRgn
Rectangle
CreateDCA
CreateICA
GDI32.dll
IcmpCloseHandle
IcmpSendEcho
IcmpCreateFile
IPHLPAPI.DLL
GetSystemTimeAsFileTime
HeapFree
GetCurrentThreadId
DecodePointer
GetCommandLineA
UnhandledExceptionFilter
SetUnhandledExceptionFilter
IsDebuggerPresent
EncodePointer
TerminateProcess
EnterCriticalSection
LeaveCriticalSection
HeapCreate
HeapDestroy
IsProcessorFeaturePresent
RtlUnwind
TlsAlloc
TlsGetValue
TlsSetValue
TlsFree
InterlockedIncrement
GetModuleHandleW
SetLastError
InterlockedDecrement
ExitProcess
SetHandleCount
InitializeCriticalSectionAndSpinCount
GetFileType
GetStartupInfoW
DeleteCriticalSection
GetModuleFileNameA
FreeEnvironmentStringsW
WideCharToMultiByte
GetEnvironmentStringsW
QueryPerformanceCounter
GetTickCount
GetCurrentProcessId
SetFilePointer
WriteFile
GetConsoleCP
GetConsoleMode
GetCPInfo
GetACP
GetOEMCP
IsValidCodePage
HeapAlloc
HeapReAlloc
LoadLibraryW
GetModuleFileNameW
SetStdHandle
WriteConsoleW
LCMapStringW
GetStringTypeW
FlushFileBuffers
HeapSize
CreateFileW
CloseHandle
Dpi400
Dpi800
GetMouse
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
wwwwwwww
wwfwwwgfp
wwwwwwwwp
wwwwwwww
wwwwwwww
vxwwwww
wwwwwwp
wwwwwwwp
wwwpwp
wwvwwvvw
wwwwwwp
wxwwwwp
wwwwwwp
wwwwwwp
wwwwwwp
wwwwww
wwwwww
wwwwwg
wwwwww
wwwwww
wwwwww
vwxyz{|}~
*hijklmnop
qr stu
XYZ[\>>]^>_`7
*3NOPQ
0RSTUV6W
GHIJKL++M
6789:;<
=>?@AB
"#$%&'()*+,
-mnopqrstuvwxyz{
abcdefghijkl
STUVWXYZ6[\]^_
HIJKLMNOPQ99R;
<=>?@4ABCDEFG;
012345
6789:;
$%&'()*+,-./
nopqrstuvqwx
VWXYZ[\]^_
JKLMNOPQRSTU
?@ABCDEFGHI
3456789:;<=>
()*+,-./012'
 !"#$%&'
ktA)r|F
s}G!s|G
q{Evr|F
r|Fbr|F
s}G%s}G
j~|aj
vLp|P!p
q|E"mxC
oyE?mwC
ku?Is}F
r}G=r|F
Zc;d3O
pzD_mtD
mwB]nyB
`Jel=Xq{F
hp~`l~sk
Ev}@u}Asz8ry8s}G
Ms|Fr}F
NowCpyD
KpyDq{E
Nr{Es~H
Kq{Er|F
Kq{Fs}F
Mt~Gq{F
t~Gq{F
ln}gmy\n
=u{6qy9r}I
Nu~GluA
IpyDq{D
Mt}GpzD
Ks}FpzD
JpzDr|E
Vv}Gr}E
t~Fq{F
=u|5pyB
Nq{IpzD
IqzDoyB
Jq{DoyC
cfm=r}F
OBr()%|
?UVJlF
{>T7Rl
x=CyVP
"_^k@:
SefHNm
s.{'j5
mNMKM{
dej7x<?
sjK;D
gEcFem
~_3w8U
<j=I.`a'3-
T\^{g9
LNVg.x
WH|T^;
5Z$n-/
pE4r@A
;4q-kI
&|;4\M
d8[Jpt
fM[#O{
/mC{[V7O
vwx!,o'g
V*=s5};Q;
06Y/!4
*&bij
1S5^x`
%I8l[T
"`=c0E
cNDWO#
'StG^@
6+1nFU
BY7buUW
Hw}0RL
B-K"JtpT
r@iEyL
GNS^cfQG
K<cJEI%XN
#mVO?L
T90dL9
i ydu;
5]%a{`!
zn4DiA
o;Wxl!
yV.=h-G
0tBomZw
R\"{J{
n.bXR>04m
&7w(;#
k(JMlT(j
A\[m3YMh
"_$L|5h
^=J=v[X2
%%~KRX`
@n5=el
@j/N^`4
'uv|fG+
~; QgyxepE!
<be?I@
7=Ifr<GH{7z
+x[rNC[y
2[ehnZ
[f\gt
yu(\zT=
PvD52O
?);asI %l
fwKo|14
fH2nQ0r
~k#bD[
&?xDo"%
{ :P3b
|6-?"
jd`f!5L
U}q$B0L
)Fyv6ue
*&*M(
fx}N[rh
SFGu^e$
>nCE6|
j*P'()
~uT#?<G
1Zxq(vO
:`_9?*
Lmq3:2*4+
Xu];yL
,Sywd*
`GXB)%
-s>I%jq
-b~1K^l
rU<2~*
v%5='j
ER2a"X
U~ywU2y
tXe,FrE
e[_2{D
o*DX}Z
=@f*%D
&wBd}T
vznIz#=
.EyNUV
Zrm2U8
<jZc&`
l7#o.WG
bN$b|E
clW\+7L
kB't)5
G>.p/N
my[Led
p?YwJ$F7
^xqohO[
4|!;:}
+fe_kH
Nq'#C$
c?x%N{
,U^btk
#[{#`Za
r3kyG2l
9O'W<!
aZ{uP@o]
i&#J>O4V
oHU:@.F
h&F4#
z"KR> 1Z
I`pIM8
#K-of?
:9o%t?e7
p{L=3fB
GME-P[
&d$hWZ
TcW\}3
MG*L.(
GX.VQ
,lV2/by
[AM_e=
h&NB;@:A#
n>D+!S_
g*AxWI-
\QJsxN@7+
3j6L6f
*z3Pm
|DEVSy
DX|1NClzS
WQSQOH_NTSTGEQCU
0(AMC?
bA`H]O
0nuKOF
Bi4?~r
Z7~xz.cA
8tdJByw
@B82b
tI0M7=
\>~BG1
E,7=mM
g:JJN&
e<Q'+y
[({5MI
6MgMRR
tw^E"\
NtcV"f
J^71K(
BrEly`C
sV1>iJI
]^I`-tqR
^*6wb9
0c`wQ8
L`jrk:
a@TorQ
(']TjN
#+(5x[
&+V2D<
+qt}FrS
@av-',
+dm.Y^
X[;4npm
v"6.`i
E,a~G@(C
08J97<
dy*]Y8
7GhfTq%
38`EtQ
CQP4{]
$\c&1(h\
}CuynVwa
(?^88)
P<^OVG?
8x!)R+=
#&@\wpB
2guaF}hC5
PIkx950{
4G,d1F0O
1.),{1
]Ln2{VZY
TKiOwh
d'DW!s
9PD^?.;9
7ZK3`6
fIa45
|n)2bH
,b],<!].
lGin9U
}o~[45~
DtV:%W
q#;rq)"
:*5,u~
@a\,A0
O2;cM
&q<g3
bRSHl]P:
w9d9h:s
$l]=/Mn
oJ!)aj
cXtK;=
(&9zw.
44LvW^
-!I2*}
HPdQ0L
[|_HWq
FkwZlMF
%"p`Z v\yg
}fL#cO
a(z_px^
/V0et*
K<jN5j*
I2046sN
^o:r{I
~":]dW
O^U8h$$r
}ddN|6]
*Y?nCd
i~Si=w)>
.#.@ix
Zf\MU'.
S@M/#C
>p9~=2
cr"A=w
BHn_$i
c9ynQY
`!3/bf`z
[GzB,s35
&W$R18
:fI@3D
ynpReqM
MJi-DW
DEXg/f
Dc?Lt1
`{A dY\
~L3X2{Bk
Pd?=4&
O9vy$E`
|AsT>$
T8u61*>
%sE%u
pnFcmk~]
6ff$x!p
ar>9Z|e
u0FV4$
,A(#k&
H~'?0d
7,!b@i
1]E\k}Z
dwjew;p
2mLQL0
'"# DYW
H&fRC*
{@[Gx$
K]%n<!
I0-LWW
%T/S1
/i\?fv
" Ng(eT
[A6xy@
?y!h/`y
RT.Q%"
VtQ6f$
N0&O('
6Q'x*J\
psnLmQcMI8
*oTllc2K
XI~F=S:
hr^>Ni)
in%zGYy
>?:'K`
>&BVN
y0N}2ro
_'4Xa7p
<Uvoi=u
Q2rfZm
]&b 'T
T;?8Lgv;
K`:fb?
-r<9Mh
_$cIfku
"CW2]&v
bPZa!/
HP-xBzr<
Vo.)Kq
2b$Mn,
!@53\6
spJnJFmv
_z3%B[
w'?2qY\
yLk.#'?
]f"7hQ
yLW\']
qGK5EIs
U37%]]
dqeen
(Rh}M0
c-QQC)
wo }U/
gwLdLo
gq_hg#
1=e!!Z
cFjHrVQu1
*H>k2c
U_'3"R
M+'"V.fE
OuA6%ZUz
vC:V3Z|
si9$,6Q
P0k6j;0
^"m >eN
!r6YI9
EU1A@.
3131/(?J~xLeCij`D[WcY`/|GSPuSy{@5?"Q+
bt09!
`%ieMnG
pYnQ4wr]fgmp|dMEANeP3BuBsY1\QrE
YAaG{!lrx
pds6<S"
#?e@)"W#26
3131/(?.434'%1#5#!#!?8/>$#$75!3%SQSQOH_NTSTGEQCUCACA_XO^DCDWUASEsqsqoh
ntstgeqcucaca
xo~dcdwuase
3%S!RQkH_NOb
~nTstgEASE
FDS4Vn
3131/(?.434'%1#5#!#!?8/>$#$75!3%SQSQOH_NTSTGEQCUCACA_XO^DCDWUASEsqsqoh
ntstgeqcucaca
xo~dcdwuase
P<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v3">
<security>
<requestedPrivileges>
<requestedExecutionLevel level="asInvoker" uiAccess="false"></requestedExecutionLevel>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>PAPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADD
0&0Y0p0
11<1D1M1R1o1y1~1
2(2,20242O2
3$323]3~3
464D4a4r4y4
6-646C6M6\6x6
6 7C7I7]7
7!8+82878=8C8j8v8
9"9H9z9
<=0=6=@=E=K=O=U=Y=_=c=i=m=r=x=|=
?$?+?3?8?<?@?i?
0 0$0(0,0
1I1P1T1X1\1`1d1h1l1
3!4U4[4a4v4
6L7T7i7t7\8
5L5S5`5f5
m1s1y1
22+282\2n2|2
6:6F6O6U6[6h7m7
;(;/;?;c;j;q;x;
;T<d<q<
==%=.=4===I=O=W=]=i=o=|=
=3>9>c>i>o>
>=?`?j?
0.040:0I0W0a0g0}0
1*10181=1E1J1R1W1^1m1r1x1
2>2G2S2
4"4*4:4@4Q4
5'6.6C6
8&8^8h8
:0;6;R;z;
;%;>;H;[;
>#>+>3>J>c>
4G5p5U6a6
7n8:9l9
: :$:(:,:0:z:
;;$;(;,;M;w;
< <$<(<?>
:0[0d0
1&2m2t2~2
3!343X3
454A4L5
6/6M6a6g6
8#8/8f8~8
90969>9
9P:Y:_:
;=;D;L;
=#=+=1=?=s=
!0N0Y0
4L579I9[9m9
:#:5:G:Y:k:}:
; ;*;3;>;J;O;_;d;j;p;
0^1d1r1
;S>W>[>_>c>g>k>o>s>w>{>
>(>->>>F>L>V>\>f>l>v>
1%1+1U1[1`1f1w1
41<1D1L1T1\1d1l1t1|1
=0=<=X=d=
> >@>`>l>
?(?H?h?
: :$:(:,:0:4:8:<:@:D:H:L:P:T:X:\:`:d:h:l:p:t:x:
; ;$;(;,;0;
<H=L=P=T=X=\=`=d=h=l=x=|=
- intercepted
(null)
KERNEL32.DLL
mscoree.dll
HH:mm:ss
dddd, MMMM dd, yyyy
MM/dd/yy
December
November
October
September
August
February
January
Saturday
Friday
Thursday
Wednesday
Tuesday
Monday
Sunday
runtime error
TLOSS error
SING error
DOMAIN error
- Attempt to use MSIL code from this assembly during native code initialization
This indicates a bug in your application. It is most likely the result of calling an MSIL-compiled (/clr) function from a native constructor or from DllMain.
- not enough space for locale information
- Attempt to initialize the CRT more than once.
This indicates a bug in your application.
- CRT not initialized
- unable to initialize heap
- not enough space for lowio initialization
- not enough space for stdio initialization
- pure virtual function call
- not enough space for _onexit/atexit table
- unable to open console device
- unexpected heap error
- unexpected multithread lock error
- not enough space for thread data
- abort() has been called
- not enough space for environment
- not enough space for arguments
- floating point support not loaded
Microsoft Visual C++ Runtime Library
<program name unknown>
Runtime Error!
Program:
((((( H
h(((( H
H
WUSER32.DLL
CONOUT$
X86CONTENT
No antivirus signatures available.
No IRMA results available.