Static | ZeroBOX

PE Compile Time

2021-11-10 20:38:13

PE Imphash

d4755b9a9aec93c05c955ca11140bdc5

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x0000f320 0x0000f400 6.33918808383
.rdata 0x00011000 0x0000892a 0x00008a00 4.79042810139
.data 0x0001a000 0x00001bc0 0x00000a00 1.94020409405
.pdata 0x0001c000 0x00000d14 0x00000e00 4.58940471657
cdata 0x0001d000 0x0001b261 0x0001b400 3.96187567093
wdata 0x00039000 0x0001b261 0x0001b400 3.93522885482
.reloc 0x00055000 0x00000608 0x00000800 4.75113517022

Imports

Library KERNEL32.dll:
0x180011000 QueryPerformanceCounter
0x180011008 GetCurrentProcessId
0x180011010 GetCurrentThreadId
0x180011018 GetSystemTimeAsFileTime
0x180011020 InitializeSListHead
0x180011028 RtlCaptureContext
0x180011030 RtlLookupFunctionEntry
0x180011038 RtlVirtualUnwind
0x180011040 IsDebuggerPresent
0x180011048 UnhandledExceptionFilter
0x180011058 GetStartupInfoW
0x180011068 GetModuleHandleW
0x180011070 RtlUnwindEx
0x180011078 InterlockedFlushSList
0x180011080 GetLastError
0x180011088 SetLastError
0x180011090 EnterCriticalSection
0x180011098 LeaveCriticalSection
0x1800110a0 DeleteCriticalSection
0x1800110b0 TlsAlloc
0x1800110b8 TlsGetValue
0x1800110c0 TlsSetValue
0x1800110c8 TlsFree
0x1800110d0 FreeLibrary
0x1800110d8 GetProcAddress
0x1800110e0 LoadLibraryExW
0x1800110e8 RaiseException
0x1800110f0 GetCurrentProcess
0x1800110f8 ExitProcess
0x180011100 TerminateProcess
0x180011108 GetModuleHandleExW
0x180011110 GetModuleFileNameW
0x180011118 HeapAlloc
0x180011120 HeapFree
0x180011128 FindClose
0x180011130 FindFirstFileExW
0x180011138 FindNextFileW
0x180011140 IsValidCodePage
0x180011148 GetACP
0x180011150 GetOEMCP
0x180011158 GetCPInfo
0x180011160 GetCommandLineA
0x180011168 GetCommandLineW
0x180011170 MultiByteToWideChar
0x180011178 WideCharToMultiByte
0x180011180 GetEnvironmentStringsW
0x180011188 FreeEnvironmentStringsW
0x180011190 LCMapStringW
0x180011198 GetProcessHeap
0x1800111a0 GetStdHandle
0x1800111a8 GetFileType
0x1800111b0 GetStringTypeW
0x1800111b8 HeapSize
0x1800111c0 HeapReAlloc
0x1800111c8 SetStdHandle
0x1800111d0 FlushFileBuffers
0x1800111d8 WriteFile
0x1800111e0 GetConsoleCP
0x1800111e8 GetConsoleMode
0x1800111f0 SetFilePointerEx
0x1800111f8 CreateFileW
0x180011200 CloseHandle
0x180011208 WriteConsoleW

Exports

Ordinal Address Name
1 0x180001116 About
2 0x180001038 DllRegisterServer
3 0x1800010bc RtlClearBuffer
4 0x18000109e RtlConstructorBuffer
5 0x180001080 RtlDestructorBuffer
6 0x180001152 RtlGetBuffer
7 0x1800010da RtlReadBuffer
8 0x180001134 RtlSetBuffer
9 0x1800010f8 RtlWriteBuffer
!This program cannot be run in DOS mode.
`.rdata
@.data
.pdata
@cdata
.reloc
D$?>f;
D$8 f;
D$(H9D$0u
D$$9D$P
D$ ;D$L
H+D$8H
D$xH9D$8
D$ HcD$
t,HcL$(H
HcL$ HcT$(f;
HcD$$:
D$$HcD$$:
HcD$ f;
HcD$0H
D$;'f;
HcD$4H
D$DHcD$@f;
HcD$4f;
HcD$@H
`Hc@<H
D$P9D$
H;D$(s
H;D$8u
$H;D$8
|$ AVH
H3E H3E
WATAUAVAWH
A_A^A]A\_
t<ffff
WATAUAVAWH
A_A^A]A\_
fffffff
u3HcH<H
x ATAVAWH
A_A^A\
UVWAVAWH
0A_A^_^]
WAVAWH
0A_A^_
WAVAWH
A_A^_
u"8Z(t
uF8Z(t
vC8_(t
u"8Z(t
uF8Z(t
vB8_(t
UVWATAUAVAWH
`A_A^A]A\_^]
WATAUAVAWH
0A_A^A]A\_
H97u+A
\$ UVWATAUAVAWH
@8|$Ht
@8|$Ht
@8|$Ht
D$XD9x
@8|$ht
@8|$ht
@8|$ht
A_A^A]A\_^]
u"8Z(t
UVWATAUAVAWH
L$&8\$&t,8Y
@A_A^A]A\_^]
fD94Fu
WATAUAVAWH
A_A^A]A\_
fD9t$b
\$ VWATAUAVH
D!l$xA
@A^A]A\_^
L$ VWAVH
@8l$Ht
ATAUAVH
L$ fff
L$ |+L;
A^A]A\
@UATAUAVAWH
e0A_A^A]A\]
@UATAUAVAWH
H!T$0D
ue!T$(H!T$
A_A^A]A\]
x AVAWE3
|$0A_A^
UVWATAUAVAWH
D8T8>t
A_A^A]A\_^]
VWATAVAW
A_A^A\_^
WATAUAVAWH
A_A^A]A\_
\$ UVWATAUAVAWH
H!D$ H
`A_A^A]A\_^]
WATAUAVAWH
A_A^A]A\_
UVWAVAWH
@A_A^_^]
ffffff
fffffff
USVWAVH
A^_^[]
LcA<E3
u HcA<H
__based(
__cdecl
__pascal
__stdcall
__thiscall
__fastcall
__vectorcall
__clrcall
__eabi
__swift_1
__swift_2
__ptr64
__restrict
__unaligned
restrict(
delete
operator
`vftable'
`vbtable'
`vcall'
`typeof'
`local static guard'
`string'
`vbase destructor'
`vector deleting destructor'
`default constructor closure'
`scalar deleting destructor'
`vector constructor iterator'
`vector destructor iterator'
`vector vbase constructor iterator'
`virtual displacement map'
`eh vector constructor iterator'
`eh vector destructor iterator'
`eh vector vbase constructor iterator'
`copy constructor closure'
`udt returning'
`local vftable'
`local vftable constructor closure'
new[]
delete[]
`omni callsig'
`placement delete closure'
`placement delete[] closure'
`managed vector constructor iterator'
`managed vector destructor iterator'
`eh vector copy constructor iterator'
`eh vector vbase copy constructor iterator'
`dynamic initializer for '
`dynamic atexit destructor for '
`vector copy constructor iterator'
`vector vbase copy constructor iterator'
`managed vector copy constructor iterator'
`local static thread guard'
operator ""
operator co_await
Type Descriptor'
Base Class Descriptor at (
Base Class Array'
Class Hierarchy Descriptor'
Complete Object Locator'
FlsAlloc
FlsFree
FlsGetValue
FlsSetValue
InitializeCriticalSectionEx
CorExitProcess
AreFileApisANSI
FlsAlloc
FlsFree
FlsGetValue
FlsSetValue
InitializeCriticalSectionEx
LCMapStringEx
LocaleNameToLCID
AppPolicyGetProcessTerminationMethod
Sunday
Monday
Tuesday
Wednesday
Thursday
Friday
Saturday
January
February
August
September
October
November
December
MM/dd/yy
dddd, MMMM dd, yyyy
HH:mm:ss
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
UUUUUU
UUUUUU
=imb;D
/>58d%
VM>cQ6
>jtm}S
)>6{1n
+f)>0'
;H9>&X
*StO9>T
n03>Pu
K~Je#>!
bp(=>?g
BC?>6t9^
K&>.yC
.xJ>Hf
y\PD>!
|b=})>
c [1>H'
uzKs@>
3>N;kU
kE>fvw
V6E>`"(5
?UUUUUU
?7zQ6$
.text$mn
.text$mn$00
.text$x
.idata$5
.00cfg
.CRT$XCA
.CRT$XCZ
.CRT$XIA
.CRT$XIC
.CRT$XIZ
.CRT$XPA
.CRT$XPX
.CRT$XPXA
.CRT$XPZ
.CRT$XTA
.CRT$XTZ
.rdata
.rdata$zzzdbg
.rtc$IAA
.rtc$IZZ
.rtc$TAA
.rtc$TZZ
.xdata
.edata
.idata$2
.idata$3
.idata$4
.idata$6
.pdata
Ax64.dll
DllRegisterServer
RtlClearBuffer
RtlConstructorBuffer
RtlDestructorBuffer
RtlGetBuffer
RtlReadBuffer
RtlSetBuffer
RtlWriteBuffer
QueryPerformanceCounter
GetCurrentProcessId
GetCurrentThreadId
GetSystemTimeAsFileTime
InitializeSListHead
RtlCaptureContext
RtlLookupFunctionEntry
RtlVirtualUnwind
IsDebuggerPresent
UnhandledExceptionFilter
SetUnhandledExceptionFilter
GetStartupInfoW
IsProcessorFeaturePresent
GetModuleHandleW
RtlUnwindEx
InterlockedFlushSList
GetLastError
SetLastError
EnterCriticalSection
LeaveCriticalSection
DeleteCriticalSection
InitializeCriticalSectionAndSpinCount
TlsAlloc
TlsGetValue
TlsSetValue
TlsFree
FreeLibrary
GetProcAddress
LoadLibraryExW
RaiseException
GetCurrentProcess
ExitProcess
TerminateProcess
GetModuleHandleExW
GetModuleFileNameW
HeapAlloc
HeapFree
FindClose
FindFirstFileExW
FindNextFileW
IsValidCodePage
GetACP
GetOEMCP
GetCPInfo
GetCommandLineA
GetCommandLineW
MultiByteToWideChar
WideCharToMultiByte
GetEnvironmentStringsW
FreeEnvironmentStringsW
LCMapStringW
GetProcessHeap
GetStdHandle
GetFileType
GetStringTypeW
HeapSize
HeapReAlloc
SetStdHandle
FlushFileBuffers
WriteFile
GetConsoleCP
GetConsoleMode
SetFilePointerEx
CreateFileW
CloseHandle
WriteConsoleW
KERNEL32.dll
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
4745343ed9610080000000080fb491aa4bb05b35b1729d1d296fbb5a71c754cce4d4d19bb06e8edb29d8f20000000807efc47360c8f3cc9c03a744884a15d168e5b74ebb57f30831be4bbee7b1e7600000080336e06dc78d9827b334fe815eee1c61ffa4eb4e52e1bccecf04681d1866b76000000801a620c917e5c3f6429bbedc413dcd4fac613d073da130b594411ed2f245a050000008061ef87320ff6298af6ee34755e42dd70f02d57fa3cf9aa310040303f8cf9bd000000804f36075cf4883a14a3ff36bcbfa64a1a7bb81d0742163cdf1d0cf62effbeb800000080764a5ebe5f5db39e57577678f9e0fac55edba4a70b890546a53bf914c0ddb700000080a4757d78d7b12a59fb4bda7cde36e1fb9e1ad11f7643810b714dbf13f2e03900000080d262d0fb84fae79dbf4efb7b3e8ea2263effbd1ae19f73115aab2eb3e8aadc000000801b755a8ce89ef85f7d8b7f15fa855f0643efa413b42bfe9cc02fb10b70cc7300000080fe5281ebba9dd697dacced0db3316681449a364d2f4e5f9e62a87ea5d68ee600000080ded8872cfc7ebb8f5abeaf79303094cedbfdd9e7199608ff8142fa8840335e0000008009732978a987306dfddcd9ae78029bbde4af01584422ac77e2f37cf068c697000000801d2509cd5acb23acb04e5682a517896ddcb4ee9cb32575f64ef8f70d7f1060000000801686bdfb1f07b029a0e
4f61b20100b90e020000000080488bc4488958084c8948204c89401848895010555657415441554156415748000000808bec4881ec800000004c8bf9b94c772607e8bf050000b949f70278488945a8208000c2488bd8e8ae460458a453e54c8be8e8a1460310e18ac34c8bf0e8944603afb15c94ac140201a0b8484483460433009e9544c0488bf8e872444533e44c8bc04885db0f84433c4d2054088185ed0f843a4a02f60f843124484602284a02ff0f841f4a02c00f84162449637f3c490300040081ff813f504500000f85034cb864860000663947040f85f40479018d4c24014484200000804f380f85e53c0fb74714418bdc4883c02466443b670673250fb75706488d0c0000008038443961048b47380f4541040301488d49283bc30f46c38bd8492bd175e348000000808d4dd041ffd08b55d4448bc28d72fff7da037750498d48ff8bc24823f08bc3000008844803c8498d40ff48f7d04823c8483bf10f8578b501488b4f3041b9240041b800c2400281300604d641ffd6d10401037515448d48041a0633c98e06418bd441bb01c8443967547611000000808bca4103d3428a04398804193b575472ef4863733c458bd44803f3488975b000020080440fb746144983c02831036606733b4c03c6458bcc4539207620418b5004418b0051108248fc418bc14503cb81024803d025013a2501453b0872e0e8064503d3
api-ms-win-core-fibers-l1-1-1
api-ms-win-core-synch-l1-2-0
kernel32
api-ms-
ext-ms-
mscoree.dll
api-ms-win-core-datetime-l1-1-1
api-ms-win-core-fibers-l1-1-1
api-ms-win-core-file-l1-2-2
api-ms-win-core-localization-l1-2-1
api-ms-win-core-localization-obsolete-l1-2-0
api-ms-win-core-processthreads-l1-1-2
api-ms-win-core-string-l1-1-0
api-ms-win-core-synch-l1-2-0
api-ms-win-core-sysinfo-l1-2-1
api-ms-win-core-winrt-l1-1-0
api-ms-win-core-xstate-l2-1-0
api-ms-win-rtcore-ntuser-window-l1-1-0
api-ms-win-security-systemfunctions-l1-1-0
ext-ms-win-ntuser-dialogbox-l1-1-0
ext-ms-win-ntuser-windowstation-l1-1-0
advapi32
kernel32
api-ms-win-appmodel-runtime-l1-1-2
user32
api-ms-
ext-ms-
Sunday
Monday
Tuesday
Wednesday
Thursday
Friday
Saturday
January
February
August
September
October
November
December
MM/dd/yy
dddd, MMMM dd, yyyy
HH:mm:ss
((((( H
zh-CHS
az-AZ-Latn
uz-UZ-Latn
kok-IN
syr-SY
div-MV
quz-BO
sr-SP-Latn
az-AZ-Cyrl
uz-UZ-Cyrl
quz-EC
sr-SP-Cyrl
quz-PE
smj-NO
bs-BA-Latn
smj-SE
sr-BA-Latn
sma-NO
sr-BA-Cyrl
sma-SE
sms-FI
smn-FI
zh-CHT
az-az-cyrl
az-az-latn
bs-ba-latn
div-mv
kok-in
quz-bo
quz-ec
quz-pe
sma-no
sma-se
smj-no
smj-se
smn-fi
sms-fi
sr-ba-cyrl
sr-ba-latn
sr-sp-cyrl
sr-sp-latn
syr-sy
uz-uz-cyrl
uz-uz-latn
zh-chs
zh-cht
CONOUT$
No antivirus signatures available.
No IRMA results available.