Static | ZeroBOX

PE Compile Time

2021-11-17 17:13:52

PE Imphash

63a806c199e422807de783c1c09b5907

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x0002f0a9 0x0002f200 4.82859411436
.rdata 0x00031000 0x00001ea0 0x00002000 5.2627056435
.data 0x00033000 0x000006e8 0x00000200 2.87796823526
.gfids 0x00034000 0x00000038 0x00000200 0.296026167659
.tls 0x00035000 0x00000009 0x00000200 0.0203931352361
.rsrc 0x00036000 0x00012520 0x00012600 6.9480264488
.reloc 0x00049000 0x000008d8 0x00000a00 6.01428035032

Resources

Name Offset Size Language Sub-language File type
AFX_DIALOG_LAYOUT 0x00047948 0x00000002 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_BITMAP 0x00047010 0x000002c0 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_ICON 0x00046ae8 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00046ae8 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00046ae8 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00046ae8 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00046ae8 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00046ae8 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00046ae8 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00046ae8 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00046ae8 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00046ae8 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00046ae8 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00046ae8 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00046ae8 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_MENU 0x000473a0 0x00000198 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_MENU 0x000473a0 0x00000198 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_DIALOG 0x00047590 0x000000c8 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_STRING 0x00048470 0x000000ae LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_STRING 0x00048470 0x000000ae LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_STRING 0x00048470 0x000000ae LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_STRING 0x00048470 0x000000ae LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_STRING 0x00048470 0x000000ae LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_STRING 0x00048470 0x000000ae LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_STRING 0x00048470 0x000000ae LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_STRING 0x00048470 0x000000ae LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_STRING 0x00048470 0x000000ae LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_STRING 0x00048470 0x000000ae LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_STRING 0x00048470 0x000000ae LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_ACCELERATOR 0x00047538 0x00000058 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_GROUP_ICON 0x00046f50 0x000000bc LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_VERSION 0x00047658 0x000002f0 LANG_ENGLISH SUBLANG_ENGLISH_US SysEx File - IDP
None 0x000472d0 0x00000016 LANG_ENGLISH SUBLANG_ENGLISH_US data

Imports

Library mfc140.dll:
0x43110c None
0x431110 None
0x431114 None
0x431118 None
0x43111c None
0x431120 None
0x431124 None
0x431128 None
0x43112c None
0x431130 None
0x431134 None
0x431138 None
0x43113c None
0x431140 None
0x431144 None
0x431148 None
0x43114c None
0x431150 None
0x431154 None
0x431158 None
0x43115c None
0x431160 None
0x431164 None
0x431168 None
0x43116c None
0x431170 None
0x431174 None
0x431178 None
0x43117c None
0x431180 None
0x431184 None
0x431188 None
0x43118c None
0x431190 None
0x431194 None
0x431198 None
0x43119c None
0x4311a0 None
0x4311a4 None
0x4311a8 None
0x4311ac None
0x4311b0 None
0x4311b4 None
0x4311b8 None
0x4311bc None
0x4311c0 None
0x4311c4 None
0x4311c8 None
0x4311cc None
0x4311d0 None
0x4311d4 None
0x4311d8 None
0x4311dc None
0x4311e0 None
0x4311e4 None
0x4311e8 None
0x4311ec None
0x4311f0 None
0x4311f4 None
0x4311f8 None
0x4311fc None
0x431200 None
0x431204 None
0x431208 None
0x43120c None
0x431210 None
0x431214 None
0x431218 None
0x43121c None
0x431220 None
0x431224 None
0x431228 None
0x43122c None
0x431230 None
0x431234 None
0x431238 None
0x43123c None
0x431240 None
0x431244 None
0x431248 None
0x43124c None
0x431250 None
0x431254 None
0x431258 None
0x43125c None
0x431260 None
0x431264 None
0x431268 None
0x43126c None
0x431270 None
0x431274 None
0x431278 None
0x43127c None
0x431280 None
0x431284 None
0x431288 None
0x43128c None
0x431290 None
0x431294 None
0x431298 None
0x43129c None
0x4312a0 None
0x4312a4 None
0x4312a8 None
0x4312ac None
0x4312b0 None
0x4312b4 None
0x4312b8 None
0x4312bc None
0x4312c0 None
0x4312c4 None
0x4312c8 None
0x4312cc None
0x4312d0 None
0x4312d4 None
0x4312d8 None
0x4312dc None
0x4312e0 None
0x4312e4 None
0x4312e8 None
0x4312ec None
0x4312f0 None
0x4312f4 None
0x4312f8 None
0x4312fc None
0x431300 None
0x431304 None
0x431308 None
0x43130c None
0x431310 None
0x431314 None
0x431318 None
0x43131c None
0x431320 None
0x431324 None
0x431328 None
0x43132c None
0x431330 None
0x431334 None
0x431338 None
0x43133c None
0x431340 None
0x431344 None
0x431348 None
0x43134c None
0x431350 None
0x431354 None
0x431358 None
0x43135c None
0x431360 None
0x431364 None
0x431368 None
0x43136c None
0x431370 None
0x431374 None
0x431378 None
0x43137c None
0x431380 None
0x431384 None
0x431388 None
0x43138c None
0x431390 None
0x431394 None
0x431398 None
0x43139c None
0x4313a0 None
0x4313a4 None
0x4313a8 None
0x4313ac None
0x4313b0 None
0x4313b4 None
0x4313b8 None
0x4313bc None
0x4313c0 None
0x4313c4 None
0x4313c8 None
0x4313cc None
0x4313d0 None
0x4313d4 None
0x4313d8 None
0x4313dc None
0x4313e0 None
0x4313e4 None
0x4313e8 None
0x4313ec None
0x4313f0 None
0x4313f4 None
0x4313f8 None
0x4313fc None
0x431400 None
0x431404 None
0x431408 None
0x43140c None
0x431410 None
0x431414 None
0x431418 None
0x43141c None
0x431420 None
0x431424 None
0x431428 None
0x43142c None
0x431430 None
0x431434 None
0x431438 None
0x43143c None
0x431440 None
0x431444 None
0x431448 None
0x43144c None
0x431450 None
0x431454 None
0x431458 None
0x43145c None
0x431460 None
0x431464 None
0x431468 None
0x43146c None
0x431470 None
0x431474 None
0x431478 None
0x43147c None
0x431480 None
0x431484 None
0x431488 None
0x43148c None
0x431490 None
0x431494 None
0x431498 None
0x43149c None
0x4314a0 None
0x4314a4 None
0x4314a8 None
0x4314ac None
0x4314b0 None
0x4314b4 None
0x4314b8 None
0x4314bc None
0x4314c0 None
0x4314c4 None
0x4314c8 None
0x4314cc None
0x4314d0 None
0x4314d4 None
0x4314d8 None
0x4314dc None
0x4314e0 None
0x4314e4 None
Library KERNEL32.dll:
0x431004 GetLastError
0x43100c FreeResource
0x431010 ExitProcess
0x431014 OutputDebugStringW
0x431018 GetModuleHandleW
0x43101c GetProcAddress
0x431020 CloseHandle
0x431024 CreateEventW
0x431028 TerminateProcess
0x43102c GetCurrentProcess
0x431030 InitializeSListHead
0x431038 GetCurrentThreadId
0x43103c GetCurrentProcessId
0x431048 GetStartupInfoW
0x431054 IsDebuggerPresent
Library USER32.dll:
0x43105c LoadCursorA
0x431060 UpdateWindow
0x431064 LoadAcceleratorsA
0x431068 EnableWindow
0x431070 GetWindowLongA
0x431074 SetWindowLongA
0x431078 SendMessageA
0x43107c LoadMenuA
Library VCRUNTIME140.dll:
0x431084 __CxxFrameHandler3
0x431090 memset
Library api-ms-win-crt-heap-l1-1-0.dll:
0x431098 _set_new_mode
0x43109c free
Library api-ms-win-crt-runtime-l1-1-0.dll:
0x4310b8 _controlfp_s
0x4310bc terminate
0x4310cc _exit
0x4310d0 exit
0x4310d4 _initterm_e
0x4310d8 _initterm
0x4310e0 _c_exit
0x4310e4 _set_app_type
0x4310e8 _seh_filter_exe
0x4310ec _cexit
0x4310f0 _crt_atexit
Library api-ms-win-crt-math-l1-1-0.dll:
0x4310b0 __setusermatherr
Library api-ms-win-crt-stdio-l1-1-0.dll:
0x431100 __p__commode
0x431104 _set_fmode
Library api-ms-win-crt-locale-l1-1-0.dll:
0x4310a4 _configthreadlocale
0x4310a8 _setmbcp

!This program cannot be run in DOS mode.
`.rdata
@.data
.gfids
@.reloc
LQDTUQGUPESUGTFPDFDPRONRNKBLNQPSSSJLPLSRTRGTSPLPBGNUQLMQNCPLRTNRIEPQRUPNQQMOULTOJCCJDGICUDEFBKEGLESQOLSRJGRQTUUMFBLCJEFEUDMIBIGBCLTBHHMKMNQKHBKEFIITIGEDTFIUDHKBESBLBHJCPNJPCHDEBBMQGKCHPFRSGKDCDPLMKCQDOLOUBFGDCFKDUDDKSDFCOBCDBSHHUHKCTSGHSFGFFCUBLHGFNJNHRDFDDUBEDNJUPSBTLCLDUHRJMKRSDGCPULIGFPIUSDIFPSJMRDKIBDQRODJGNBMNNBHEDORQTBCIPMMMNDEBEIJGELFHNJGJGMCJJSGCCUHHRTDIFSFJCFOGBOFCPDSBESJDEQMECNHCTRNHJUEIHKINEMKDSHDRJSDBJRGMJPJBMLJMBLJHHGSTCQJKTBQNIMBJGUUQGPCGNUPQJPDEHHDGNSDDNGHKNTGFFUFUDIPBSTJBULJJHKSHLTGFTGSDUQCHMPQSOLCUDLIFTHBQKUTGCBCGQQSKOKHJOSTFMNSMOMPPUQOTKFUUJSOBBFBGDIUJLPFHLNMTSNETPMRMHFKILIJGJKTPTMGFTUQSKJKONQMJFHCPGFSIUBJEHIGPLLGJPUJCTQDIDLSFSUOQBDCESEHFPDRCMLFBKEBPIJBNTLSNGCKPFGLORGEHHCEGPTHKMQERONDDGLPRQNSNETCIGCEHPFURBPCEDSNSRBIPQUUDRHFOIDPJDIGECHGUBUDEIJOBJGECDRNUMTDESPCNOTDKOKDFMNDHNRQITJJSSSRSTJFTEEOMGIDEDDJDBMCDCROMQCMKLPMTSESHDDCDKQOEOFKFFLREBQCCEMSKUPFDFTSIDBRCESLKUHMHINPDFRREDUOCPUTIERMEGKGUIMTCRGBLCSSGDPCUFNRCPNCUDTMIBDLQHLNELINRFPSGHNTTUQJGDPBPKUHCGDIKPTSERKKDSNOBJORONUIKKSEBTTOEFNSHUROELHUIORNE
h4(@Ph
InitializeConditionVariable
SleepConditionVariableCS
WakeAllConditionVariable
CChildFrame
C:\Program Files (x86)\Microsoft Visual Studio 14.0\VC\atlmfc\include\afxwin1.inl
Exception thrown in destructor
%Ts (%Ts:%d)
%Ts (%Ts:%d)
AppID.NoVersion
Local AppWizard-Generated Applications
CMainFrame
mfc140.dll
InitializeCriticalSectionEx
GetLastError
DeleteCriticalSection
FreeResource
ExitProcess
GetModuleHandleW
GetProcAddress
CloseHandle
CreateEventW
IsDebuggerPresent
UnhandledExceptionFilter
SetUnhandledExceptionFilter
GetStartupInfoW
IsProcessorFeaturePresent
QueryPerformanceCounter
GetCurrentProcessId
GetCurrentThreadId
GetSystemTimeAsFileTime
InitializeSListHead
GetCurrentProcess
TerminateProcess
KERNEL32.dll
SendMessageA
EnableWindow
LoadCursorA
UpdateWindow
LoadAcceleratorsA
LoadMenuA
SetLayeredWindowAttributes
GetWindowLongA
SetWindowLongA
USER32.dll
memset
__CxxFrameHandler3
__vcrt_InitializeCriticalSectionEx
_except_handler4_common
VCRUNTIME140.dll
_configure_narrow_argv
_initialize_narrow_environment
_initialize_onexit_table
_register_onexit_function
_crt_atexit
_cexit
_seh_filter_exe
_set_app_type
__setusermatherr
_get_narrow_winmain_command_line
_initterm
_initterm_e
_set_fmode
_c_exit
_register_thread_local_exe_atexit_callback
_configthreadlocale
_set_new_mode
__p__commode
terminate
_controlfp_s
api-ms-win-crt-heap-l1-1-0.dll
api-ms-win-crt-runtime-l1-1-0.dll
api-ms-win-crt-math-l1-1-0.dll
api-ms-win-crt-stdio-l1-1-0.dll
api-ms-win-crt-locale-l1-1-0.dll
OutputDebugStringW
_setmbcp
.?AVtype_info@@
.PAVCException@@
fldd|g
f||gldt||dp
lgflffVFp
73cc3cR0
vl|fV`
773c72a'#
2s27#c
s#cc42>
vlvvvv
ss27#%(~
nv|lv`
s7'3c(
3z77#h
{sss8u
W|~~ww
ss2s#s
lvvvfV
5gf~^W
3'7~vvg
j8($"!
kP5000($$"!
NJII5300((%$!!1$"!
RNMIH5300.($$!!2$#!
RRNIIH5f
%$!2($!!
_RRNJ[
%$#3($$!
k.%$8.($"!
CCBAA><<
kH330..$8.($$"
II533...90.($""
hMII5330.;0.(%#"
BA><<<
kXNI8H30.L00.(%#"
BBA><<
c[`N;530L300((#"!
><<<?<
O95V520(((#"
@><<E<
SP;XL530((#"
A>>@?=<
jVQPbQL830((#
CCAA@@E><<
lljh]e[`XQbVQ;830(%
CCBAAE><<
lllgeiigegcVQL83+(
CBAG@@<<
llgda_`dkXVO;31
GEG?@=<
Y[[Xaadaa____e]VO;8
EE?@=<<
-KPQS____RMN_fbU;
ws||rrqp
-8HMNNRR_MMNXbU
zxv~~}|t|rqp
&,28IIMJMNMONX
~~~||rtrq
'*245IJJNRk
|trrpo
||rrrpom
|||rrppo
}||rrrpo
~|||rrpp
~}||trrp
~~|||rrp
~~||trr
~~|||rr
~~||tt
WN'!1!
)+&&&!N$!
&GF+&$N&!
KKJ,+&R&$!
84242?
TK+W+&!
KSKcI+&!
odRaWcaSgOI'&
lmljSI+%
hdbb`amZJ-
/LQ`Q`MQhgX
xwuttst~
'1GMMMMQW
}}||tsrt
")GGLOm
jI&/TY)
]$ 'K!
2-/O'
*,$0T/!
,LZ-.!
cKR31WfL/'
mlmgL1
UXdcPjh\
{zyto|
+5MNNN[
h)-$9A<=8
+fJLy|::;~}
\YHUDMB
W^VsRN
wecXat
RHU@>z
:]PPk~*u9&
6tjhU`"
qDA,8E
zk*b#
h 18P;
P_gJ6P
hf?z+m
B2aE4~
8JD k`
zOa'n10pp~
p[a[A:
E G0m`
mcKID
Z/>>Q,-
$PX3b
<"Xut
e<QeF`:)
l9?'V^c
LnNms\W
Oo#"l:
*@+ydmB
$?f^Od
,}B]h7a
z}MycD
#0S3hZ
W&F~+$
xgQ`sc
^bj5Zx
Bxx7Xo
0Ry?Bd
Xnv K-d
N"`Rr('
NkshO
he\2r]
3>Ua'S$K
!FN9Q-X
)]C[P[Kd
M0CrhP
:vFOUO
:!y=IB
}sL4& 4
XXmajr
|w>9BB
bIDAT_
EH~1:z(
7cnn+V
nSlR;h
}0|404
gJ=ZS_A
;vLcfv
4aO]6`
gwLcff
^9ogA
#rK/!lFo
^9gB
&{S#sL_ jD
$uN? kE
%xQ!!kEl
sstDDD
777777
455D5X5t5
8B8b8|8
909m9v9
;1;?;p;u;z;
=3=C=H=Q=
>?;?D?
:!:0:C:
<8<V<`<o<
=!=-=C=L=Q=b=
;0u8|8P9W9
= =&=,=2=8=>=D=J=P=V=\=b=h=n=t=z=
>">(>.>4>:>@>F>L>R>X>^>d>j>p>v>|>
?$?*?0?6?<?B?H?N?T?Z?`?f?l?r?x?~?
0 0&0,02080>0D0J0P0V0\0b0h0n0t0z0
1"1(171D1J1Y1`1e1n1s1|1
3*3:3K3q3
4A4I4b4
:1;:;G;R;[;n;
<"<M<S<y<
=%=+=1=7===C=J=Q=X=_=f=m=t=|=
>2>A>J>P>V>
?$?*?0?6?<?B?H?N?T?t?
0+0L0s0x0
5`6l6p6
7 7$7(7,7074787<7@7D7H7L7P7T7X7\7`7d7h7l7p7t7x7|7
8 8$8(8,8084888<8@8D8H8L8P8T8X8\8`8d8h8l8p8t8x8|8
9 9$9(9,9094989<9@9D9H9L9P9T9X9\9`9d9h9l9p9t9x9|9
: :$:(:,:0:4:8:<:@:D:H:L:P:T:X:\:`:d:h:l:p:t:x:|:
; ;$;(;,;0;4;8;<;@;D;H;L;P;T;X;\;`;d;h;l;p;t;x;|;
< <$<(<,<0<4<8<<<@<D<H<L<P<T<X<\<`<d<h<l<p<t<x<|<
= =$=<=T=p=t=x=|=
? ?$?(?,?0?4?8?<?@?D?H?L?P?T?X?\?`?d?h?l?p?t?x?|?
0 0$0(0,0004080<0@0D0H0L0P0T0X0\0`0d0h0l0p0t0x0
1,1014181P1T1d1h1p1
2$2,2@2H2`2l2t2
3$3T3X3t3x3
kernel32.dll
ERROR : Unable to initialize critical section in CAtlBaseModule
AFX_DIALOG_LAYOUT
Ctrl+N
&Close
&Toolbar
&Status Bar
Ctrl+N
&Close
Ctrl+Z
Ctrl+X
Ctrl+C
&Paste
Ctrl+V
&Toolbar
&Status Bar
&Window
&Cascade
&Arrange Icons
MS Shell Dlg
VS_VERSION_INFO
StringFileInfo
040904b0
CompanyName
TODO: <Company name>
FileDescription
FileVersion
1.0.0.1
InternalName
LegalCopyright
TODO: (c) <Company name>. All rights reserved.
OriginalFilename
ProductName
TODO: <Product name>
ProductVersion
1.0.0.1
VarFileInfo
Translation
Create a new document
Close the active document
?Display program information, version number and copyright
About4Quit the application; prompts to save documents
(Switch to the next window pane
Next Pane5Switch back to the previous window pane
Previous Pane
7Arrange icons at the bottom of the window
Arrange Icons/Arrange windows so they overlap
Cascade Windows5Arrange windows as non-overlapping tiles
Tile Windows5Arrange windows as non-overlapping tiles
Tile Windows(Split the active window into panes
Erase the selection
Erase everything
Erase All3Copy the selection and put it on the Clipboard
Copy1Cut the selection and put it on the Clipboard
Find the specified text
FindInsert Clipboard contents
Repeat the last action
Repeat1Replace specific text with different text
Replace%Select the entire document
Select All
Undo the last action
Undo&Redo the previously undone action
'Show or hide the toolbar
Toggle ToolBar-Show or hide the status bar
Toggle Status Bar
Change the window size
Change the window position
Reduce the window to an iconEnlarge the window to full size"Switch to the next document window&Switch to the previous document window9Close the active window and prompts to save the documents
!Restore the window to normal size
Activate Task List
Activate this window
No antivirus signatures available.
No IRMA results available.