Static | ZeroBOX

PE Compile Time

2021-10-28 08:38:27

PE Imphash

1c8c92d264ac725186aa72072469e6aa

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x000023dd 0x00002400 6.49478138462
.rdata 0x00004000 0x00001256 0x00001400 4.4618010495
.data 0x00006000 0x00000400 0x00000200 1.76036979148
.rsrc 0x00007000 0x000001e0 0x00000200 4.70150325825
.reloc 0x00008000 0x0000028c 0x00000400 4.76941886599

Resources

Name Offset Size Language Sub-language File type
RT_MANIFEST 0x00007060 0x0000017d LANG_ENGLISH SUBLANG_ENGLISH_US XML 1.0 document text

Imports

Library KERNEL32.dll:
0x404000 GetConsoleWindow
0x404008 GetCurrentProcess
0x40400c TerminateProcess
0x404018 GetCurrentProcessId
0x40401c GetCurrentThreadId
0x404024 InitializeSListHead
0x404028 IsDebuggerPresent
0x404030 GetModuleHandleW
Library USER32.dll:
0x40405c ShowWindow
Library urlmon.dll:
0x40411c URLDownloadToFileW
Library VCRUNTIME140.dll:
0x404064 _CxxThrowException
0x404074 memcpy
0x40407c __std_terminate
0x404080 memset
0x404084 memmove
0x404088 __current_exception
0x40408c __CxxFrameHandler3
Library api-ms-win-crt-runtime-l1-1-0.dll:
0x4040b8 system
0x4040bc __p___argc
0x4040cc _exit
0x4040d0 _controlfp_s
0x4040d4 terminate
0x4040dc _c_exit
0x4040e0 __p___argv
0x4040e8 _initterm_e
0x4040ec _initterm
0x4040f8 _cexit
0x4040fc _set_app_type
0x404100 _seh_filter_exe
0x404104 _crt_atexit
0x404108 exit
Library api-ms-win-crt-heap-l1-1-0.dll:
0x404094 malloc
0x404098 _callnewh
0x40409c free
0x4040a0 _set_new_mode
Library api-ms-win-crt-math-l1-1-0.dll:
0x4040b0 __setusermatherr
Library api-ms-win-crt-stdio-l1-1-0.dll:
0x404110 _set_fmode
0x404114 __p__commode
Library api-ms-win-crt-locale-l1-1-0.dll:
0x4040a8 _configthreadlocale

!This program cannot be run in DOS mode.
`.rdata
@.data
@.reloc
bad allocation
Unknown exception
bad array new length
string too long
Welcome!
Choose a player name by entering it into the code!!
Well Done!
Preparing for battle!
player.name value!!
Great Job you won!!
u lost!!
.text$mn
.text$x
.idata$5
.00cfg
.CRT$XCA
.CRT$XCAA
.CRT$XCZ
.CRT$XIA
.CRT$XIAA
.CRT$XIAC
.CRT$XIZ
.CRT$XPA
.CRT$XPZ
.CRT$XTA
.CRT$XTZ
.rdata
.rdata$r
.rdata$sxdata
.rdata$voltmd
.rdata$zzzdbg
.rtc$IAA
.rtc$IZZ
.rtc$TAA
.rtc$TZZ
.xdata$x
.idata$2
.idata$3
.idata$4
.idata$6
.data$r
.data$rs
.rsrc$01
.rsrc$02
GetConsoleWindow
KERNEL32.dll
ShowWindow
USER32.dll
?cout@std@@3V?$basic_ostream@DU?$char_traits@D@std@@@1@A
?uncaught_exception@std@@YA_NXZ
?_Xlength_error@std@@YAXPBD@Z
?_Osfx@?$basic_ostream@DU?$char_traits@D@std@@@std@@QAEXXZ
?flush@?$basic_ostream@DU?$char_traits@D@std@@@std@@QAEAAV12@XZ
?sputn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QAE_JPBD_J@Z
?setstate@?$basic_ios@DU?$char_traits@D@std@@@std@@QAEXH_N@Z
?sputc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QAEHD@Z
MSVCP140.dll
URLDownloadToFileW
urlmon.dll
__CxxFrameHandler3
__std_exception_destroy
__std_exception_copy
__std_terminate
_CxxThrowException
__current_exception
__current_exception_context
memset
_except_handler4_common
VCRUNTIME140.dll
system
_invalid_parameter_noinfo_noreturn
_callnewh
malloc
_seh_filter_exe
_set_app_type
__setusermatherr
_configure_narrow_argv
_initialize_narrow_environment
_get_initial_narrow_environment
_initterm
_initterm_e
_set_fmode
__p___argc
__p___argv
_cexit
_c_exit
_register_thread_local_exe_atexit_callback
_configthreadlocale
_set_new_mode
__p__commode
_initialize_onexit_table
_register_onexit_function
_crt_atexit
_controlfp_s
terminate
api-ms-win-crt-runtime-l1-1-0.dll
api-ms-win-crt-heap-l1-1-0.dll
api-ms-win-crt-math-l1-1-0.dll
api-ms-win-crt-stdio-l1-1-0.dll
api-ms-win-crt-locale-l1-1-0.dll
UnhandledExceptionFilter
SetUnhandledExceptionFilter
GetCurrentProcess
TerminateProcess
IsProcessorFeaturePresent
QueryPerformanceCounter
GetCurrentProcessId
GetCurrentThreadId
GetSystemTimeAsFileTime
InitializeSListHead
IsDebuggerPresent
GetModuleHandleW
memcpy
memmove
.?AVbad_alloc@std@@
.?AVexception@std@@
.?AVbad_array_new_length@std@@
.?AVtype_info@@
<?xml version='1.0' encoding='UTF-8' standalone='yes'?>
<assembly xmlns='urn:schemas-microsoft-com:asm.v1' manifestVersion='1.0'>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v3">
<security>
<requestedPrivileges>
<requestedExecutionLevel level='asInvoker' uiAccess='false' />
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
0 040K0R0
1/1@1I1a1g1
2!2O;Z;
5#5f5r5
7!7&7+7L7Q7^7
9 9)9.949>9H9X9h9x9
;!;3;=;
;+<:<C<P<f<
=%=+=>=
>*>4>T>
?,?1?D?a?~?
1H1Q1Z1h1q1
22%2+21272=2C2I2O2U2[2a2g2m2s2y2
$1,181<1X1\1`1d1h1l1p1t1x1|1
4,404D4T4X4h4x4
8$888H8T8t8
9$989@9H9P9d9
040P0x0
Antivirus Signature
Bkav Clean
Lionic Trojan.Win32.Generic.4!c
DrWeb Clean
MicroWorld-eScan Trojan.GenericKD.47287627
FireEye Generic.mg.d31c7d2c2cfa9b2b
CAT-QuickHeal Clean
McAfee Artemis!D31C7D2C2CFA
Cylance Clean
Zillya Clean
Sangfor Suspicious.Win32.Save.a
K7AntiVirus Clean
BitDefender Trojan.GenericKD.47287627
K7GW Clean
Cybereason Clean
BitDefenderTheta Clean
Cyren W32/Zusy.HV.gen!Eldorado
ESET-NOD32 a variant of Generik.BHGPUCE
Zoner Clean
TrendMicro-HouseCall TROJ_FRS.0NA103JV21
Paloalto generic.ml
ClamAV Clean
Kaspersky Clean
Alibaba Trojan:Win32/Generic.c0e07b84
NANO-Antivirus Clean
ViRobot Clean
Rising Clean
Ad-Aware Trojan.GenericKD.47287627
Comodo Malware@#2fah5urz6fmg9
F-Secure Clean
Baidu Clean
VIPRE Clean
TrendMicro TROJ_FRS.0NA103JV21
McAfee-GW-Edition BehavesLike.Win32.Generic.lm
CMC Clean
Emsisoft Trojan.GenericKD.47287627 (B)
Ikarus Trojan.SuspectCRC
GData Win32.Trojan.Agent.SLP0E2
Jiangmin Clean
Webroot Clean
Avira Clean
MAX malware (ai score=83)
Antiy-AVL Clean
Kingsoft Clean
Gridinsoft Ransom.Win32.Sabsik.sa
Arcabit Clean
SUPERAntiSpyware Clean
ZoneAlarm Clean
Microsoft Trojan:Win32/Sabsik.FL.B!ml
Cynet Malicious (score: 100)
AhnLab-V3 Clean
Acronis Clean
VBA32 Clean
ALYac Trojan.GenericKD.47287627
TACHYON Clean
Malwarebytes Clean
Panda Clean
APEX Malicious
Tencent Clean
Yandex Clean
SentinelOne Static AI - Suspicious PE
MaxSecure Trojan.Malware.300983.susgen
Fortinet W32/Small.BIR!tr.dldr
AVG Win32:Trojan-gen
Avast Win32:Trojan-gen
CrowdStrike Clean
No IRMA results available.