Static | ZeroBOX

PE Compile Time

2023-04-25 19:44:12

PE Imphash

abbf45d53faf8e5020b1ed87d549651b

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x0000e6ff 0x0000e800 6.71425418535
.rdata 0x00010000 0x0003a312 0x0003a400 5.45921538646
.data 0x0004b000 0x00030728 0x0002fe00 4.92739363843
.gfids 0x0007c000 0x000000a0 0x00000200 1.3698733562
.rsrc 0x0007d000 0x00000860 0x00000a00 3.56902308689
.reloc 0x0007e000 0x00001408 0x00001600 6.42661071893

Resources

Name Offset Size Language Sub-language File type
RT_STRING 0x0007d428 0x000002b2 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_STRING 0x0007d428 0x000002b2 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_MANIFEST 0x0007d6e0 0x0000017d LANG_ENGLISH SUBLANG_ENGLISH_US XML 1.0 document text
None 0x0007d120 0x000000a1 LANG_ENGLISH SUBLANG_ENGLISH_US data

Imports

Library KERNEL32.dll:
0x10010000 EnterCriticalSection
0x10010004 LeaveCriticalSection
0x1001000c CreateFileA
0x10010010 CloseHandle
0x10010014 GetLastError
0x10010018 HeapWalk
0x1001001c DeleteCriticalSection
0x10010020 CreateThread
0x10010024 SuspendThread
0x10010028 FindFirstFileA
0x1001002c FindNextFileA
0x10010030 GetFileType
0x10010034 VirtualAlloc
0x10010038 CreateMutexA
0x1001003c ReleaseMutex
0x10010040 SetHandleInformation
0x10010044 GetLocalTime
0x1001004c GetCurrentProcessId
0x10010050 GetCurrentThreadId
0x10010058 InitializeSListHead
0x1001005c IsDebuggerPresent
0x10010068 GetStartupInfoW
0x10010070 GetModuleHandleW
0x10010074 GetCurrentProcess
0x10010078 TerminateProcess
0x1001007c InterlockedFlushSList
0x10010080 RtlUnwind
0x10010084 SetLastError
0x1001008c TlsAlloc
0x10010090 TlsGetValue
0x10010094 TlsSetValue
0x10010098 TlsFree
0x1001009c FreeLibrary
0x100100a0 GetProcAddress
0x100100a4 LoadLibraryExW
0x100100a8 ExitProcess
0x100100ac GetModuleHandleExW
0x100100b0 GetModuleFileNameA
0x100100b4 MultiByteToWideChar
0x100100b8 WideCharToMultiByte
0x100100bc HeapFree
0x100100c0 HeapAlloc
0x100100c4 LCMapStringW
0x100100c8 FindClose
0x100100cc FindFirstFileExA
0x100100d0 IsValidCodePage
0x100100d4 GetACP
0x100100d8 GetOEMCP
0x100100dc GetCPInfo
0x100100e0 GetCommandLineA
0x100100e4 GetCommandLineW
0x100100e8 GetEnvironmentStringsW
0x100100f0 GetProcessHeap
0x100100f4 GetStdHandle
0x100100f8 GetStringTypeW
0x100100fc HeapSize
0x10010100 HeapReAlloc
0x10010104 SetStdHandle
0x10010108 WriteFile
0x1001010c FlushFileBuffers
0x10010110 GetConsoleCP
0x10010114 GetConsoleMode
0x10010118 SetFilePointerEx
0x1001011c WriteConsoleW
0x10010120 DecodePointer
0x10010124 CreateFileW
0x10010128 RaiseException

Exports

Ordinal Address Name
1 0x1000e270 Motd
!This program cannot be run in DOS mode.
Rich$3
`.rdata
@.data
.gfids
@.rsrc
@.reloc
D$L1T.
D$8_^][
D$(SUf
D$8_^]
URPQQhp8
;t$,v-
UQPXY]Y[
WWWPWS
u-PWWS
SSVWh
f9:t!V
PPPPPPPP
PPPPPWS
PP9E u:PPVWP
QQSWj0j@
l$pPVWSU
H|;HDtx
D$@;T$,sF
D$<f3L
t$|WRSU
L$t_^]
PQRVWSU
PQRVWS
PQRVWSU
L$ 5X#
PQRVWSU
F,;FXs
F(;AXs
l$(3Ad;
T$(3Ad;
torn; states dwight, law, organization, physical remains
pencil proposition# clergyman
sorrowful
faintly# daring, private. studied
bald, intentions, eleven# torture, sorrow headache# chorus# slam
reeds; shipwreck
ferocity# capable
definition, firmly. quay
appear# stray bloody# became. cleanup sniff. co. hannah; accomplished, simple blobs; jewellery. concern
helpless. circulation resolve. mend generations;
FlsAlloc
FlsFree
FlsGetValue
FlsSetValue
InitializeCriticalSectionEx
__based(
__cdecl
__pascal
__stdcall
__thiscall
__fastcall
__vectorcall
__clrcall
__eabi
__ptr64
__restrict
__unaligned
restrict(
delete
operator
`vftable'
`vbtable'
`vcall'
`typeof'
`local static guard'
`string'
`vbase destructor'
`vector deleting destructor'
`default constructor closure'
`scalar deleting destructor'
`vector constructor iterator'
`vector destructor iterator'
`vector vbase constructor iterator'
`virtual displacement map'
`eh vector constructor iterator'
`eh vector destructor iterator'
`eh vector vbase constructor iterator'
`copy constructor closure'
`udt returning'
`local vftable'
`local vftable constructor closure'
new[]
delete[]
`omni callsig'
`placement delete closure'
`placement delete[] closure'
`managed vector constructor iterator'
`managed vector destructor iterator'
`eh vector copy constructor iterator'
`eh vector vbase copy constructor iterator'
`dynamic initializer for '
`dynamic atexit destructor for '
`vector copy constructor iterator'
`vector vbase copy constructor iterator'
`managed vector copy constructor iterator'
`local static thread guard'
operator ""
Type Descriptor'
Base Class Descriptor at (
Base Class Array'
Class Hierarchy Descriptor'
Complete Object Locator'
CorExitProcess
GetCurrentPackageId
LCMapStringEx
LocaleNameToLCID
Sunday
Monday
Tuesday
Wednesday
Thursday
Friday
Saturday
January
February
August
September
October
November
December
MM/dd/yy
dddd, MMMM dd, yyyy
HH:mm:ss
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
?5Wg4p
%S#[k=
"B <1=
_hypot
_nextafter
skemggo127ca3.dll
EnterCriticalSection
LeaveCriticalSection
InitializeCriticalSection
CreateFileA
CloseHandle
GetLastError
HeapWalk
DeleteCriticalSection
CreateThread
SuspendThread
FindFirstFileA
FindNextFileA
GetFileType
VirtualAlloc
CreateMutexA
ReleaseMutex
SetHandleInformation
GetLocalTime
KERNEL32.dll
QueryPerformanceCounter
GetCurrentProcessId
GetCurrentThreadId
GetSystemTimeAsFileTime
InitializeSListHead
IsDebuggerPresent
UnhandledExceptionFilter
SetUnhandledExceptionFilter
GetStartupInfoW
IsProcessorFeaturePresent
GetModuleHandleW
GetCurrentProcess
TerminateProcess
InterlockedFlushSList
RtlUnwind
SetLastError
InitializeCriticalSectionAndSpinCount
TlsAlloc
TlsGetValue
TlsSetValue
TlsFree
FreeLibrary
GetProcAddress
LoadLibraryExW
ExitProcess
GetModuleHandleExW
GetModuleFileNameA
MultiByteToWideChar
WideCharToMultiByte
HeapFree
HeapAlloc
LCMapStringW
FindClose
FindFirstFileExA
IsValidCodePage
GetACP
GetOEMCP
GetCPInfo
GetCommandLineA
GetCommandLineW
GetEnvironmentStringsW
FreeEnvironmentStringsW
GetProcessHeap
GetStdHandle
GetStringTypeW
HeapSize
HeapReAlloc
SetStdHandle
WriteFile
FlushFileBuffers
GetConsoleCP
GetConsoleMode
SetFilePointerEx
WriteConsoleW
DecodePointer
CreateFileW
RaiseException
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
events Tome Manufacture) 385
Eager( insecure) 907 673 whom spark
<?xml version='1.0' encoding='UTF-8' standalone='yes'?>
<assembly xmlns='urn:schemas-microsoft-com:asm.v1' manifestVersion='1.0'>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v3">
<security>
<requestedPrivileges>
<requestedExecutionLevel level='asInvoker' uiAccess='false' />
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
I0j0z0
0%161\1c1n1
2#2(2@2I2m2
3#3+3N3Y3e3z3
455H5N5Z5d5y5
6&656L6^6n6
7#747Y7
8(8<8t8y8
:I:]:{:
<)<C<e<
=1=:=Y=d=p=
>F>M>V>
?1?E?_?i?q?
0+000D0V0
1*141s1x1
2?2H2]2p2
3!3&3S3j3t3
4 454I4k4q4
4^5m5t5
757G7M7^7z7
9,919>9
=,=8=H=Y=
>(>O>W>p>
>%?-?8?>?D?P?V?y?
U0t0~0
1&2/272~2
3'303;3B3b3h3n3t3z3
4'5/5A5
9J9_9y9
:$:.:<:W:h:t:
;O;_;v;~;
<<$<)<P<Y<^<c<
=D=L=Q=a=k=
? ?,?`?
!171n1
2'2,2=2
3#3+353>3O3a3|3
8K8f8v8{8
=5=D=I=Z=`=k=s=~=
>B>H>Z>
04102D2
4&4A4M4^4g4
5'5@5m5t5
6$6;6C6j6
767A7F7K7f7p7
88;8F8K8P8q8
9%90959:9X9{9
:4:F:R:i:W;a;n;
<]<d<w<
1!202B2T2p2
3%343>3K3U3e3
4"6O6p6u6
8#:(:.:3:|:
<P=`=|=
>#?A?L?
,090F0S0j011
2<2p2x2
5<5W5d5r5
5&656C6`6h6
6#7*7z7
:0:=:B:P:
;';9;K;];o;
4"4U4r4
7$8H8S8`8r8
8W9l9u9~9
<!<)<1<9<W<_<
1)2F2V2
3\4g4r4x4
55+5>5]5
83999>9D9U9
=H>c>y>
<&=k=p=t=x=|=
D1W1u1
113h3o3t3x3|3
4 4$4(4,4
7L8\8c8q8
9#909>9K9T9
:*:0:C:Y:
:";6;P;i;v;|;
;$<7<W<
<+=2=J=[=f=
>>>X>e>t>}>
10<0M0Z0
3#3?3s3
3#4S4\4b4
4D5O5X5v5
676R6`6
7-7A7M7f7v7
8%878A8N8X8j8
979?9L9[9
:":+:0:U:n:y:
;6;N;Y;f;m;y;
<4<@<G<L<
>$>F>l>y>
? ?8?I?
1I1c1i1{1
33+313A3M3Y3_3i3s3}3
4,4=4C4K4c4n4t4
5(51565<5B5H5N5T5b5m5}5
6 6&616E6P6V6`6h6q6w6|6
8&8N8V8\8l8|8
9*989b9h9o9{9
9-:L:V:d:
;";1;8;J;g;w;
<5<K<a<
="=(=5=G=M=e=
0&02080E0K0b0t0
2*2:2C2N2z2
404P4\4e4{4
6/676H6
01@1D1H1T1X1\1
1 1$1(1,1014181<1@1D1H1L1P1T1X1\1`1d1h1l1p1t1x1|1
2 2$2(2,2024282<2@2D2H2L2P2T2X2\2`2d2h2l2p2t2
9 9$9(9,9094989<9D9H9L9P9T9X9\9`9l9t9x9|9
4 4$4(4,4044484<4@4D4H4L4P4\4`4d4h4l4p4t4x4|4
;$;,;4;<;D;L;T;\;d;l;t;|;
<$<,<4<<<D<L<T<\<d<l<t<|<
=$=,=4=<=D=L=T=\=d=l=t=|=
>$>,>4><>D>L>T>\>d>l>t>|>
?$?,?4?<?D?L?T?\?d?l?t?|?
0$0,040<0D0L0T0\0d0l0t0|0
1$1,141<1D1L1T1\1d1l1t1|1
2$2,28<@<H<P<X<`<h<p<x<
= =(=0=8=@=H=P=X=`=h=p=x=
> >(>0>8>@>H>P>X>`>h>p>x>
? ?(?0?8?@?H?P?X?`?h?p?x?
0 0(00080@0H0P0X0`0h0p0x0
1 1(10181@1H1P1X1`1h1p1x1
2 2(20282@2H2P2X2`2h2p2x2
3 3(30383@3H3P3:=>=B=F=
7$7,747<7D7L7T7\7d7l7t7|7
9(9H9d9h9
:(:H:h:
;(;4;P;p;
; ;,;0;4;P;T; <$<(<,<0<4<8<<<@<D<P<T<X<\<`<d<h<l<
advapi32
api-ms-win-core-fibers-l1-1-1
api-ms-win-core-synch-l1-2-0
kernel32
mscoree.dll
api-ms-win-appmodel-runtime-l1-1-1
api-ms-win-core-datetime-l1-1-1
api-ms-win-core-file-l2-1-1
api-ms-win-core-localization-l1-2-1
api-ms-win-core-localization-obsolete-l1-2-0
api-ms-win-core-processthreads-l1-1-2
api-ms-win-core-string-l1-1-0
api-ms-win-core-sysinfo-l1-2-1
api-ms-win-core-winrt-l1-1-0
api-ms-win-core-xstate-l2-1-0
api-ms-win-rtcore-ntuser-window-l1-1-0
api-ms-win-security-systemfunctions-l1-1-0
ext-ms-win-kernel32-package-current-l1-1-0
ext-ms-win-ntuser-dialogbox-l1-1-0
ext-ms-win-ntuser-windowstation-l1-1-0
user32
Sunday
Monday
Tuesday
Wednesday
Thursday
Friday
Saturday
January
February
August
September
October
November
December
MM/dd/yy
dddd, MMMM dd, yyyy
HH:mm:ss
((((( H
zh-CHS
az-AZ-Latn
uz-UZ-Latn
kok-IN
syr-SY
div-MV
quz-BO
sr-SP-Latn
az-AZ-Cyrl
uz-UZ-Cyrl
quz-EC
sr-SP-Cyrl
quz-PE
smj-NO
bs-BA-Latn
smj-SE
sr-BA-Latn
sma-NO
sr-BA-Cyrl
sma-SE
sms-FI
smn-FI
zh-CHT
az-az-cyrl
az-az-latn
bs-ba-latn
div-mv
kok-in
quz-bo
quz-ec
quz-pe
sma-no
sma-se
smj-no
smj-se
smn-fi
sms-fi
sr-ba-cyrl
sr-ba-latn
sr-sp-cyrl
sr-sp-latn
syr-sy
uz-uz-cyrl
uz-uz-latn
zh-chs
zh-cht
CONOUT$
Boot! Tables$ Shake, cooperative tremble %d %d
guards non, Waiting 234
.Sin Elevation ward thou Experience ominous Pat
Alley Used decipher gratitude_
4Differently Linen Front. pounds board 628 766 Swig\03Prosperity Reaction? %s Frighten_ Reducing knitted_
426! Overhear? Reasonably. hrs
830@ %s@,instantly( 415$ bridge) 923+ %s+ 743 Account
934 cell- %s_ 266 Rake
57 crystal 451@ Link4Company_ simulator( david Watching, dates- swallow,
A604+ Thursday@ Investigate Bug 867/ Duster. cigarette intentional
incline! Query Foreword+&Friend$ 393. Displeased? Alibis justly:Seasick %d+ peach) describe) thief Triple Bakery kerb owen
Sheer. 818_
%s. ranger\ Exploit Teams
Finding, Date
No antivirus signatures available.
No IRMA results available.