Static | ZeroBOX

PE Compile Time

2021-11-08 19:16:56

PE Imphash

17cd9f87fbb27686b2cd8f8d33695e92

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x000a3dea 0x000a3e00 6.08346738767
.rdata 0x000a5000 0x000001da 0x00000200 4.58130857126
.data 0x000a6000 0x000000b8 0x00000200 1.51274603619
.reloc 0x000a7000 0x00002a90 0x00002c00 6.73251209715

Imports

Library KERNEL32.dll:
0x100a5000 CreateFileA
0x100a5004 LeaveCriticalSection
0x100a5008 GetLastError
0x100a500c WaitForMultipleObjects
0x100a5010 EnterCriticalSection
0x100a5018 WaitForSingleObject
0x100a501c WideCharToMultiByte
0x100a5020 DeleteCriticalSection
0x100a5024 GetCurrentThread

Exports

Ordinal Address Name
1 0x1006d0f0 TyreDokgW
!This program cannot be run in DOS mode.
`.rdata
@.data
.reloc
JjLr?iGjGjGlGmGnGkGpGqGrBlBkGuGv>oHhHiHjHkHlHmHnLoHpHqHrHsHtHuHvHwIhIiIjIkIlImInIoIpIqIrIsItIuIvIwJhJiJjJkJlJmJnJoJpJqJrGkJtJuJvJiLwBsKtKkBhKt?sInBhKpGn?nIuHqEnEnEkJiFsEhJlFlJnGoHuJqFvEjFjFtFkFnCk?iCvCrCrCv?nCsCiCsDpCrDvDl=k=m@l>i>j>k>l>m>nAoBu>q>rBo>u>q>v>hJlGqAk?k?l?m?n?o?p?q?rIs?t?k=w?l@i@s@j@k=v@n@n@o@t@q@r@s@t@u@vBw=pAjAjAkBlAmAnAo>pArArAsAtAuBvAwAhBiBjBkBnBmBnBkBpBqBrBsBtBuBvBsChCiCjCkClCmCnCoKpCrCrCsCpCuCvCwDhDiDjDiDlDmDnDoDpDqDrDsDtDuDvDwEhFiEjEkFlEmEnEoEpEqErFsEtEuEvBoIhFjFjIkFlFmFnFoIpFrFrAvFtFuFvFwGhGiGjGkGlGmGnGoGpGqGrGsGtGuGvGwHhHiHjHkHlHmHnHoIpHrHrFwHtHuHvHwIhIiIjIkIlImInIoIpIqIrIsItIuIvIwJhJiJjJkJlJmJnJoJpJqJrJsJtJuJvJwKhKiKjKkKlKmKnKoKpKqKrKsKtKuKvKwLhLiLjLkLlLmLnLoLpLqLrLsLtLuLvLw=h=i=j=k=l=m=n=o=p=q=r=s=t=u=v?iClDlCrCo>l>m>nCo?h>r>r>s=t>u>v>w>r?j?j?k?h?m?n?o?p?q?r?s?t?u?v?w@h@i@j>k@l@mBn>qArBuBsAwBu@u@v>oAiAiAjAk>lAnAnAoArAqArAsDjAvAvAwBhBiBjBkBlBmBnBoBpBqBr>sBtBu>vDi=l=h>n=jClCmCnDkCpCqCrCs=tCvCvCwDjDiDjDk@lDnDnDoDpDqDrDsDtDuDvDwEhEiEjIkElEmAnGqLrKtKnKlKwEuEvGsFhFiFjFkKlFnFnFoFrFqFrFsJvFvFv
c@TyreDokgW
dll32dllTr.dll
TyreDokgW
CreateFileA
LeaveCriticalSection
GetLastError
WaitForMultipleObjects
EnterCriticalSection
InitializeCriticalSection
WaitForSingleObject
WideCharToMultiByte
DeleteCriticalSection
GetCurrentThread
KERNEL32.dll
>:>W>m>
?"?(?.?
0#0A0c0
3&3,3X3c3i3
4 41474a4f4
768<8|8
8 9&9y9
:1;7;z;
=(>.>Z>`>
=%>+>n>t>'?-?u?{?
1"1N1T1
32484x4~4
4+515t5z5
859;9~9
11b1h1
2!2i2o2
6&7,7l7r7
78%8h8n8
;)</<r<x<
4!4d4j4
5#5k5q5
9/:5:u:{:
:(;.;q;w;
6+717t7z7-838{8
9":(:T:Z:
8P9_9e9
<4=:=f=l=
<!='=j=p=#>)>q>w>
0J0P01%1
2$2g2m2
8@9F9z9
<G=M=y=
50;0g0m0&1,1
8 8`8f8
1"2(2h2n2
3!3d3j3
60767y7
=6><>q>w>
1E2K2w2}2>3D3
4"4e4k4
5$5l5r5
82989{9
;)</<[<a<
89%9h9n9
>C?I?u?{?
6.747t7z7
7'8-8p8v8
;1<7<z<
0=1C1o1u11272
8(9.9n9t9
9!:':j:p:
52686{6
8)9/9[9a9
5+616t6z6
5.646`6f6#7)7\7b7
:1;7;c;i;
<'=-=p=v=
2B3H3t3z3A4G4
45%5h5n5!6'6o6u6
;3<9<|<
6Y7e7k7
::;@;l;r;'<-<
6&7,7o7u7(8.8v8|8
:#:O:U:
;6;<;o;u;
>D?J?v?|?
6)7/7o7u7
7"8(8k8q8
9$:*:m:s:&;,;t;z;
=!=M=S=
9 :&:i:o:
2 2c2i2
3"3j3p3
7/858u8{8
8(9.9q9w9
4+515t5z5-636{6
7"8(8T8Z8
:9;?;k;q;&<,<
8$8g8m8
?#?\?b?
0%0e0k0
182>2~2
3"4(4}4
657;7g7m7
>0D0p0v0
4A5G5s5y5/656
;$;l;r;
;&<,<f<l<
!0'0j0p0
1 1c1i1
2(3.3n3t3
40565m5s5
6$7*7a7g7
8;8F8L8
8#9)9`9f9
:1;7;z;
; <&<i<o<
=->3>s>y>
40:0q0w0
12282{2
3-434j4p4
5/656x6~6
6'7-7p7v7
849:9z9
:5;;;{;
=->3>s>y>
0@0F0}0
0+111c1i1
2@2F2}2
2$3*3r3x3
7'8-8m8s8
9=:C:z:
:0;6;~;
<0=6=~=
33494j4p4
40565y5
=->G>M>
?!?a?g?
0!1'1^1d1
2 3&3i3o3
7 8&8]8c8
80969~9
:2;=;C;
< <W<]<
=(>.>q>w>
0$1*1j1p1
2+313h3n3
4)5/5r5x5
5$6*6m6s6
72888x8~8
9<:B:y:
:#;);q;w;
1-232{2
8I9m9s9
;7<=<w<}<
-030g0m0
1#2)2]2c2
3.444w4}4
:!:d:j:
=$>*>|>
6"6b6h6
7*808g8m8
9(:.:q:w:
< <c<i<
?#?f?l?
1A1G1~1
2$2V2\2
23393p3v3
41575z5
;+<1<x<~<
>#?)?~?
00f0l0
02181{1
1)2/2r2x2
32484x4~4
5!6'6[6a6
6>7D7~7
;#;W;];
;1<7<q<w<
> >c>i>
6D6J6~6
7%8+8_8e8
889>9x9~9
:.;4;n;t;
=(>.>q>w>
>6?<?u?{?
02181{1
1 2&2i2o2
384>4~4
9":(:h:n:
;/<5<l<r<
0(1.1`1f1
1&2,2a2g2
7!8'8^8d8
;$<*<|<
=+=1=t=z=
.040|0
3-434|4
78%8h8n8
>9???s?y?
1=1C1}1
1"2(2Z2`2
273=3t3z3
4$4o4u4
7'8-8m8s8
:A:G:~:
<.=4=w=}=
=#>)>l>r>
0%0m0s0
3'4-4k4q4
7'8-8m8s8
9*:0:x:~:
>"?(?_?e?
0#1)1l1r1
5 5s5y5
>%?+?n?t?
162<2s2y2
3#3k3q3
6$6r6x6
<0=6=h=n=
??b?h?
7"7p7v7
>2?8?{?
1"1d1j1
2.343e3k3
>*?0?f?l?
0#1)1s1y1
1,222u2{2
3 3j3p3
60767z7
8.949m9s9
No antivirus signatures available.
No IRMA results available.