Static | ZeroBOX

PE Compile Time

2021-11-09 18:42:10

PE Imphash

a4585b02e9865ca7dab7867b81bc3a92

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x0003c900 0x0003ca00 6.71112527174
.rdata 0x0003e000 0x0001311c 0x00013200 7.66462982668
.rdata 0x00052000 0x00010b5e 0x00010c00 5.50963198398
.data 0x00063000 0x000019d8 0x00000a00 2.06834945406
.pdata 0x00065000 0x00001260 0x00001400 5.24156645416
.rsrc 0x00067000 0x000001e0 0x00000200 4.724728912
.reloc 0x00068000 0x000005fc 0x00000600 5.41811414452

Resources

Name Offset Size Language Sub-language File type
RT_MANIFEST 0x00067060 0x0000017d LANG_ENGLISH SUBLANG_ENGLISH_US XML 1.0 document text

Imports

Library KERNEL32.dll:
0x180052038 GetModuleFileNameA
0x180052040 GetProcAddress
0x180052048 LoadLibraryA
0x180052050 CreateFileMappingA
0x180052058 GetCommandLineA
0x180052060 DeleteFileA
0x180052068 GetLastError
0x180052070 HeapAlloc
0x180052078 HeapFree
0x180052080 GetProcessHeap
0x180052088 Sleep
0x180052090 ExitProcess
0x180052098 ExitThread
0x1800520a0 GetSystemTime
0x1800520a8 VirtualAlloc
0x1800520b0 lstrcmpA
0x1800520b8 WriteFile
0x1800520c0 GetTempPathA
0x1800520c8 CreateMutexA
0x1800520d0 GetTickCount
0x1800520d8 VirtualFree
0x1800520e0 GlobalAlloc
0x1800520e8 GetDateFormatA
0x1800520f0 GetTimeFormatA
0x1800520f8 FreeLibrary
0x180052100 Process32First
0x180052108 Process32Next
0x180052110 CreateThread
0x180052118 lstrcatA
0x180052120 lstrcpyA
0x180052128 WriteConsoleW
0x180052130 CreateFileW
0x180052138 FlushFileBuffers
0x180052140 SetFilePointerEx
0x180052148 GetConsoleMode
0x180052150 GetConsoleCP
0x180052158 SetStdHandle
0x180052160 RtlPcToFileHeader
0x180052168 RaiseException
0x180052170 EncodePointer
0x180052178 RtlUnwindEx
0x180052180 UnmapViewOfFile
0x180052188 MapViewOfFile
0x180052190 VirtualProtect
0x180052198 CloseHandle
0x1800521a0 GetFileSize
0x1800521a8 CreateToolhelp32Snapshot
0x1800521b0 CreateFileA
0x1800521b8 WideCharToMultiByte
0x1800521c0 MultiByteToWideChar
0x1800521c8 GetStringTypeW
0x1800521d0 GetCPInfo
0x1800521d8 GetOEMCP
0x1800521e0 GetACP
0x1800521e8 IsValidCodePage
0x1800521f0 LCMapStringW
0x1800521f8 UnhandledExceptionFilter
0x180052208 GetCurrentProcess
0x180052210 TerminateProcess
0x180052220 SetLastError
0x180052228 GetModuleHandleW
0x180052230 GetModuleHandleExW
0x180052238 IsDebuggerPresent
0x180052240 EnterCriticalSection
0x180052248 LeaveCriticalSection
0x180052250 DeleteCriticalSection
0x180052260 TlsGetValue
0x180052268 TlsSetValue
0x180052270 LoadLibraryExW
Library USER32.dll:
0x180052280 LoadMenuA
0x180052288 GetMenu
0x180052290 SetMenu
0x180052298 GetMenuStringA
0x1800522a0 DrawMenuBar
0x1800522a8 CreateMenu
0x1800522b0 CreatePopupMenu
0x1800522b8 DestroyMenu
0x1800522c0 EnableMenuItem
0x1800522c8 AppendMenuA
0x1800522d0 InsertMenuItemA
0x1800522d8 MessageBoxA
0x1800522e0 ActivateKeyboardLayout
0x1800522e8 GetKeyboardLayout
0x1800522f0 RegisterClassA
0x1800522f8 GetWindowTextA
0x180052300 SetWindowTextA
0x180052308 DeleteMenu
Library GDI32.dll:
0x180052000 SetBkMode
0x180052008 SetBkColor
0x180052010 GetTextExtentPoint32A
0x180052018 DeleteObject
0x180052020 CreateFontIndirectA
0x180052028 SetTextColor
Library ntdll.dll:
0x180052378 RtlVirtualUnwind
0x180052380 RtlLookupFunctionEntry
0x180052388 RtlCaptureContext
Library WININET.dll:
0x180052318 InternetCanonicalizeUrlA
0x180052320 InternetCloseHandle
0x180052328 InternetConnectA
0x180052330 InternetReadFile
0x180052338 InternetQueryOptionA
0x180052340 InternetSetOptionA
0x180052348 HttpOpenRequestA
0x180052350 HttpAddRequestHeadersA
0x180052358 HttpSendRequestA
0x180052360 HttpQueryInfoA
0x180052368 InternetOpenA

Exports

Ordinal Address Name
1 0x18002a1f0 DllRegisterServer
2 0x18002a284 DllResumeServer
3 0x18002a310 DllStartServer
4 0x18002a39c DllStopServer
5 0x18002a428 DllSuspendServer
6 0x18002a4bc DllUnregisterServer
7 0x18002b300 a0i
8 0x18002b4a4 bn2o
9 0x18002a550 chql
10 0x18002acb8 fmr8t6xyemlhdyszy9ny
11 0x18002aed0 fvchb0dsyzm4k5pqs50zvvooyd2
12 0x18002a5d0 gf8
13 0x18002ac18 gnvfiwfpoekyfqfb00y8dwl7ao0
14 0x18002a9a8 hpsd2mmdaq09nkotvt31hq3j
15 0x18002a91c ia6qhyu36gk6
16 0x18002b1e4 iejm
17 0x18002a638 it42f4vda6
18 0x18002ad54 ma8anqvwb5vu2bk2zmy
19 0x18002a888 n6oqp8x4cwd9jb9258a
20 0x18002b264 nvr4od50szz9548z43ki8q
21 0x18002b524 p3bf
22 0x18002b150 p8b13v1cc61zs1pd
23 0x18002a6c0 q0ztrpprlf8
24 0x18002b368 r2vfhdue8qs1t8r4p6tk4lv7m
25 0x18002aae8 s0qa5
26 0x18002af70 t7ai2
27 0x18002ae68 u5u
28 0x18002b408 uneuzmof23nua4d0ba98
29 0x18002ade8 v1dmo
30 0x18002a7e8 vjxdko54e8lp66owkcg20zg0o
31 0x18002aff0 vv1pokfu3gzelhcqro39mddcfrtg
32 0x18002b0a0 x0dzgvozyb5eq90v1zjzibmiiyaaj
33 0x18002a748 xgj66mbqyl798991zmj3upb40
34 0x18002ab68 yasebtt45cuhjlxza9q5tfo4dp811
35 0x18002aa48 yigqk0uelvgjxf7ot47jfc3oi
!This program cannot be run in DOS mode.
`.rdata
`.rdata
@.data
.pdata
@.rsrc
@.reloc
t$ WATAUAVAWH
A_A^A]A\_
D$05UJ
D$DcZ
D$\Ex=>
D$`At12
D$dMp56
D$hIl)*
D$lUh-.
D$pQd!"
D$Tk![FM
P5k![FB
P5.[|
jHp5E3
D$PeE0HE3
D$T|tT%M
D$P5F"
x ATAVAWH
@A_A^A\
x UATAUAVAWH
A_A^A]A\]
WAVAWH
WAVAWH
HcT$8E3
~9Hc\$(E3
WAVAWH
A_A^_
UVWAVAWH
A_A^_^]
UAUAWH
D;|$T|
D$0%'k&
D$4(>v
D$< 3Z#
@UVWATAVH
D$0S>^
D$H*@(E
D$L-F(C
D$P,@(B
D$hFd
`5(~W!
A^A\_^]
UWATAVAWH
A_A^A\_]
LcT$(E3
UVWATAUAVAWH
85lMxY
A_A^A]A\_^]
UAVAWH
D$H5YG
@USVWAVH
E85:[U
`A^_^[]
D$05BG
D$ ^qGF3
WATAUAVAWH
0A_A^A]A\_
UVWATAUAVAWH
A_A^A]A\_^]
WATAUAVAWH
HcA<E3
A_A^A]A\_
l$ UAVAWH
D$@H9D$(tXH
D$ 9D$$u
|$ UATAUAVAWH
A_A^A]A\]
t$ UWATAVAWH
A_A^A\_]
u/HcI<A
ATAUAVAWL
|$@A_A^A]A\
WATAUAVAWH
A_A^A]A\_
D$(z3Bd
D$,!nF`
WAVAWH
A_A^_
x ATAVAWH
A_A^A\
WAVAWH
A_A^_
WAVAWH
0A_A^_
SVWAVH
8A^_^[
WAVAWH
u3HcH<H
\$ VWATAUAVH
D!l$xA
@A^A]A\_^
WATAUAVAWH
A_A^A]A\_
UVWATAUAVAWH
L$&8\$&t,8Y
@A_A^A]A\_^]
WATAUAVAWH
A_A^A]A\_
x AVAWE3
|$0A_A^
@UATAUAVAWH
e0A_A^A]A\]
@UATAUAVAWH
H!T$0D
ue!T$(H!T$
A_A^A]A\]
VWATAVAWH
A_A^A\_^
UVWATAUAVAWH
@A_A^A]A\_^]
H;xXu5
WATAUAVAWH
A_A^A]A\_
fffffff
AUAVAWH
;I9}(tiH
0A_A^A]
VWATAVAWH
A_A^A\_^
UVWATAUAVAWH
A_A^A]A\_^]
UVWATAUAVAWH
A_A^A]A\_^]
ri9O vdH
@SVWATAUAVAWH
L!|$(L!
D$0HcH
pA_A^A]A\_^[
B(I9A(u
SVWATAUAVAWH
0A_A^A]A\_^[
WATAUAVAWH
A_A^A]A\_
WATAUAVAWH
A_A^A]A\_
@8l$Ht
L$ VWAVH
UVWAVAWH
@A_A^_^]
ffffff
fffffff
UVWATAUAVAWH
fD94H}0L
A_A^A]A\_^]
VWATAVAW
A_A^A\_^
WATAUAVAWH
A_A^A]A\_
\$ UVWATAUAVAWH
H!D$ H
`A_A^A]A\_^]
USVWAVH
A^_^[]
LcA<E3
u HcA<H
!6X7k4
!6X7k4
#6X7k4
%L,f_%
X(]_~l
UW6tPk
hm6v-C
#l3kkE
#6X7k4
Qm0._/
%O%lj`
A7n~Lu
A7n~MueW
A6o~Lu
#6X7k4
)_Nbhr
$K)e>{
xa[>.p
+U~XI/
YI>'r&u
q*}>*q
q:Y+AZ
?6hRqv
r}^z?e
j/MXq8~
O8/%q!fs
sgH(K*%
%^%nW
lfTqq=
Q^,fS$
hn6v-S
#6X7k4
Mn0Ph<
YJE._/X
_NbyRhU6vP
!6X7k4
`Rq~U<
mfKfTqq;
)_Nbhr
#l3kkE
#6X7k4
_NbyRhU6vP
!6X7k4
!6X7k4
ACD*&#^%EF($!DE^ABC647ABEREEFC639FFF56543
FFFEDC^%$7654DE04D996FE94D3442EB1544EF742938E70D&$EFEF*^$#ABC%#^764A
ABCD456FEF783137FCDBA754
A464FA4364609DF430725AF570692465
Invalid command line parameters
Please wait while error report is being sent
DetourBinaryOpen failed: %d
DetourBinaryEditImports failed: %d
Warning: Couldn't create target empty file
Please read this information carefully
Maximum single sample size for this program may be limited by OS memory settings.
Critical error
An error occurred writing to the file
CorExitProcess
FlsGetValue
FlsSetValue
InitializeCriticalSectionEx
LCMapStringEx
LocaleNameToLCID
AppPolicyGetProcessTerminationMethod
Sunday
Monday
Tuesday
Wednesday
Thursday
Friday
Saturday
January
February
August
September
October
November
December
MM/dd/yy
dddd, MMMM dd, yyyy
HH:mm:ss
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
Unknown exception
bad exception
FlsGetValue
FlsSetValue
__based(
__cdecl
__pascal
__stdcall
__thiscall
__fastcall
__vectorcall
__clrcall
__eabi
__swift_1
__swift_2
__ptr64
__restrict
__unaligned
restrict(
delete
operator
`vftable'
`vbtable'
`vcall'
`typeof'
`local static guard'
`string'
`vbase destructor'
`vector deleting destructor'
`default constructor closure'
`scalar deleting destructor'
`vector constructor iterator'
`vector destructor iterator'
`vector vbase constructor iterator'
`virtual displacement map'
`eh vector constructor iterator'
`eh vector destructor iterator'
`eh vector vbase constructor iterator'
`copy constructor closure'
`udt returning'
`local vftable'
`local vftable constructor closure'
new[]
delete[]
`omni callsig'
`placement delete closure'
`placement delete[] closure'
`managed vector constructor iterator'
`managed vector destructor iterator'
`eh vector copy constructor iterator'
`eh vector vbase copy constructor iterator'
`dynamic initializer for '
`dynamic atexit destructor for '
`vector copy constructor iterator'
`vector vbase copy constructor iterator'
`managed vector copy constructor iterator'
`local static thread guard'
operator ""
operator co_await
Type Descriptor'
Base Class Descriptor at (
Base Class Array'
Class Hierarchy Descriptor'
Complete Object Locator'
UUUUUU
UUUUUU
=imb;D
/>58d%
VM>cQ6
>jtm}S
)>6{1n
+f)>0'
;H9>&X
*StO9>T
n03>Pu
K~Je#>!
bp(=>?g
BC?>6t9^
K&>.yC
.xJ>Hf
y\PD>!
|b=})>
c [1>H'
uzKs@>
3>N;kU
kE>fvw
V6E>`"(5
?UUUUUU
?7zQ6$
.text$mn
.text$mn$00
.text$x
.rdata
.idata$5
.00cfg
.CRT$XCA
.CRT$XCZ
.CRT$XIA
.CRT$XIC
.CRT$XIZ
.CRT$XPA
.CRT$XPX
.CRT$XPXA
.CRT$XPZ
.CRT$XTA
.CRT$XTZ
.rdata
.rdata$r
.rdata$zzzdbg
.xdata
.xdata$x
.edata
.idata$2
.idata$3
.idata$4
.idata$6
.data$r
.pdata
.rsrc$01
.rsrc$02
aic4ng9vcd.dll
DllRegisterServer
DllResumeServer
DllStartServer
DllStopServer
DllSuspendServer
DllUnregisterServer
fmr8t6xyemlhdyszy9ny
fvchb0dsyzm4k5pqs50zvvooyd2
gnvfiwfpoekyfqfb00y8dwl7ao0
hpsd2mmdaq09nkotvt31hq3j
ia6qhyu36gk6
it42f4vda6
ma8anqvwb5vu2bk2zmy
n6oqp8x4cwd9jb9258a
nvr4od50szz9548z43ki8q
p8b13v1cc61zs1pd
q0ztrpprlf8
r2vfhdue8qs1t8r4p6tk4lv7m
uneuzmof23nua4d0ba98
vjxdko54e8lp66owkcg20zg0o
vv1pokfu3gzelhcqro39mddcfrtg
x0dzgvozyb5eq90v1zjzibmiiyaaj
xgj66mbqyl798991zmj3upb40
yasebtt45cuhjlxza9q5tfo4dp811
yigqk0uelvgjxf7ot47jfc3oi
CreateFileA
GetFileSize
CloseHandle
VirtualProtect
MapViewOfFile
UnmapViewOfFile
FreeLibrary
GetModuleFileNameA
GetProcAddress
LoadLibraryA
CreateFileMappingA
GetCommandLineA
DeleteFileA
GetLastError
HeapAlloc
HeapFree
GetProcessHeap
ExitProcess
ExitThread
GetSystemTime
VirtualAlloc
lstrcmpA
WriteFile
GetTempPathA
CreateMutexA
GetTickCount
VirtualFree
GlobalAlloc
GetDateFormatA
GetTimeFormatA
CreateToolhelp32Snapshot
Process32First
Process32Next
CreateThread
lstrcatA
lstrcpyA
KERNEL32.dll
MessageBoxA
ActivateKeyboardLayout
GetKeyboardLayout
RegisterClassA
LoadMenuA
GetMenu
SetMenu
GetMenuStringA
DrawMenuBar
CreateMenu
CreatePopupMenu
DestroyMenu
EnableMenuItem
AppendMenuA
DeleteMenu
InsertMenuItemA
SetWindowTextA
GetWindowTextA
USER32.dll
CreateFontIndirectA
DeleteObject
GetTextExtentPoint32A
SetBkColor
SetBkMode
SetTextColor
GDI32.dll
RtlCaptureContext
RtlLookupFunctionEntry
RtlVirtualUnwind
ntdll.dll
InternetCanonicalizeUrlA
InternetOpenA
InternetCloseHandle
InternetConnectA
InternetReadFile
InternetQueryOptionA
InternetSetOptionA
HttpOpenRequestA
HttpAddRequestHeadersA
HttpSendRequestA
HttpQueryInfoA
WININET.dll
UnhandledExceptionFilter
SetUnhandledExceptionFilter
GetCurrentProcess
TerminateProcess
IsProcessorFeaturePresent
SetLastError
GetModuleHandleW
GetModuleHandleExW
IsDebuggerPresent
EnterCriticalSection
LeaveCriticalSection
DeleteCriticalSection
InitializeCriticalSectionAndSpinCount
TlsGetValue
TlsSetValue
LoadLibraryExW
LCMapStringW
IsValidCodePage
GetACP
GetOEMCP
GetCPInfo
GetStringTypeW
MultiByteToWideChar
WideCharToMultiByte
RtlUnwindEx
EncodePointer
RaiseException
RtlPcToFileHeader
SetStdHandle
GetConsoleCP
GetConsoleMode
SetFilePointerEx
FlushFileBuffers
CreateFileW
WriteConsoleW
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
.?AVbad_exception@std@@
.?AVexception@std@@
.?AVtype_info@@
<?xml version='1.0' encoding='UTF-8' standalone='yes'?>
<assembly xmlns='urn:schemas-microsoft-com:asm.v1' manifestVersion='1.0'>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v3">
<security>
<requestedPrivileges>
<requestedExecutionLevel level='asInvoker' uiAccess='false' />
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
mscoree.dll
api-ms-win-core-datetime-l1-1-1
api-ms-win-core-fibers-l1-1-1
api-ms-win-core-file-l1-2-2
api-ms-win-core-localization-l1-2-1
api-ms-win-core-localization-obsolete-l1-2-0
api-ms-win-core-processthreads-l1-1-2
api-ms-win-core-string-l1-1-0
api-ms-win-core-synch-l1-2-0
api-ms-win-core-sysinfo-l1-2-1
api-ms-win-core-winrt-l1-1-0
api-ms-win-core-xstate-l2-1-0
api-ms-win-rtcore-ntuser-window-l1-1-0
api-ms-win-security-systemfunctions-l1-1-0
ext-ms-win-ntuser-dialogbox-l1-1-0
ext-ms-win-ntuser-windowstation-l1-1-0
advapi32
kernel32
api-ms-win-appmodel-runtime-l1-1-2
user32
api-ms-
ext-ms-
Sunday
Monday
Tuesday
Wednesday
Thursday
Friday
Saturday
January
February
August
September
October
November
December
MM/dd/yy
dddd, MMMM dd, yyyy
HH:mm:ss
zh-CHS
az-AZ-Latn
uz-UZ-Latn
kok-IN
syr-SY
div-MV
quz-BO
sr-SP-Latn
az-AZ-Cyrl
uz-UZ-Cyrl
quz-EC
sr-SP-Cyrl
quz-PE
smj-NO
bs-BA-Latn
smj-SE
sr-BA-Latn
sma-NO
sr-BA-Cyrl
sma-SE
sms-FI
smn-FI
zh-CHT
az-az-cyrl
az-az-latn
bs-ba-latn
div-mv
kok-in
quz-bo
quz-ec
quz-pe
sma-no
sma-se
smj-no
smj-se
smn-fi
sms-fi
sr-ba-cyrl
sr-ba-latn
sr-sp-cyrl
sr-sp-latn
syr-sy
uz-uz-cyrl
uz-uz-latn
zh-chs
zh-cht
((((( H
api-ms-win-core-fibers-l1-1-1
api-ms-win-core-synch-l1-2-0
kernel32
api-ms-
ext-ms-
CONOUT$
No antivirus signatures available.
No IRMA results available.