Static | ZeroBOX

PE Compile Time

2022-05-18 02:52:33

PDB Path

D:\a\_work\1\s\artifacts\obj\win-x64.Release\corehost\apphost\standalone\apphost.pdb

PE Imphash

6dbf27f4c70fe2c8ed3e0122ba75d641

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x000183ac 0x00018400 6.31473397516
.rdata 0x0001a000 0x000091b2 0x00009200 4.55374459128
.data 0x00024000 0x000014f8 0x00000a00 2.45573303031
.pdata 0x00026000 0x00001404 0x00001600 4.82055529578
_RDATA 0x00028000 0x000000f4 0x00000200 2.46082045823
.rsrc 0x00029000 0x00000538 0x00000600 4.63708459091
.reloc 0x0002a000 0x00000320 0x00000400 4.69061509661

Resources

Name Offset Size Language Sub-language File type
RT_VERSION 0x000290a0 0x000002ac LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_MANIFEST 0x0002934c 0x000001ea LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with CRLF line terminators

Imports

Library KERNEL32.dll:
0x14001a038 FindNextFileW
0x14001a040 GetCurrentProcess
0x14001a048 GetModuleHandleExW
0x14001a050 GetModuleFileNameW
0x14001a058 LeaveCriticalSection
0x14001a068 GetEnvironmentVariableW
0x14001a070 FindClose
0x14001a078 MultiByteToWideChar
0x14001a080 GetLastError
0x14001a088 GetFileAttributesExW
0x14001a090 GetFullPathNameW
0x14001a098 GetProcAddress
0x14001a0a0 DeleteCriticalSection
0x14001a0a8 WideCharToMultiByte
0x14001a0b0 IsWow64Process
0x14001a0b8 LoadLibraryExW
0x14001a0c0 FreeLibrary
0x14001a0c8 TlsFree
0x14001a0d0 TlsSetValue
0x14001a0d8 TlsGetValue
0x14001a0e0 TlsAlloc
0x14001a0e8 EnterCriticalSection
0x14001a0f0 FindFirstFileExW
0x14001a0f8 OutputDebugStringW
0x14001a100 LoadLibraryA
0x14001a108 GetModuleHandleW
0x14001a118 SetLastError
0x14001a120 RaiseException
0x14001a128 RtlPcToFileHeader
0x14001a130 RtlUnwindEx
0x14001a138 InitializeSListHead
0x14001a140 GetSystemTimeAsFileTime
0x14001a148 GetCurrentThreadId
0x14001a150 GetCurrentProcessId
0x14001a158 QueryPerformanceCounter
0x14001a160 IsDebuggerPresent
0x14001a170 TerminateProcess
0x14001a180 UnhandledExceptionFilter
0x14001a188 RtlVirtualUnwind
0x14001a190 RtlLookupFunctionEntry
0x14001a198 RtlCaptureContext
0x14001a1a0 LCMapStringEx
0x14001a1a8 DecodePointer
0x14001a1b0 EncodePointer
0x14001a1c0 GetStringTypeW
Library USER32.dll:
0x14001a1e0 MessageBoxW
Library SHELL32.dll:
0x14001a1d0 ShellExecuteW
Library ADVAPI32.dll:
0x14001a000 RegOpenKeyExW
0x14001a008 RegGetValueW
0x14001a010 DeregisterEventSource
0x14001a018 RegisterEventSourceW
0x14001a020 ReportEventW
0x14001a028 RegCloseKey
Library api-ms-win-crt-runtime-l1-1-0.dll:
0x14001a2a0 _exit
0x14001a2a8 __p___argc
0x14001a2b0 _initterm_e
0x14001a2b8 _initterm
0x14001a2d8 _configure_wide_argv
0x14001a2e0 _initialize_onexit_table
0x14001a2e8 _set_app_type
0x14001a2f0 __p___wargv
0x14001a2f8 _seh_filter_exe
0x14001a308 _cexit
0x14001a310 terminate
0x14001a318 _errno
0x14001a320 exit
0x14001a328 abort
0x14001a330 _crt_atexit
0x14001a338 _c_exit
Library api-ms-win-crt-stdio-l1-1-0.dll:
0x14001a350 setvbuf
0x14001a358 fflush
0x14001a360 _wfopen
0x14001a368 __stdio_common_vswprintf
0x14001a370 __stdio_common_vfwprintf
0x14001a378 _set_fmode
0x14001a388 __acrt_iob_func
0x14001a390 fputwc
0x14001a398 fputws
0x14001a3a0 __p__commode
Library api-ms-win-crt-heap-l1-1-0.dll:
0x14001a208 _set_new_mode
0x14001a210 _callnewh
0x14001a218 free
0x14001a220 malloc
0x14001a228 calloc
Library api-ms-win-crt-string-l1-1-0.dll:
0x14001a3b0 wcsnlen
0x14001a3b8 strcpy_s
0x14001a3c0 _wcsdup
0x14001a3c8 strcspn
0x14001a3d0 wcsncmp
0x14001a3d8 toupper
Library api-ms-win-crt-convert-l1-1-0.dll:
0x14001a1f0 _wtoi
0x14001a1f8 wcstoul
Library api-ms-win-crt-locale-l1-1-0.dll:
0x14001a238 setlocale
0x14001a240 ___lc_locale_name_func
0x14001a248 localeconv
0x14001a250 _unlock_locales
0x14001a258 _lock_locales
0x14001a260 ___mb_cur_max_func
0x14001a268 _configthreadlocale
0x14001a270 __pctype_func
0x14001a278 ___lc_codepage_func
Library api-ms-win-crt-math-l1-1-0.dll:
0x14001a288 frexp
0x14001a290 __setusermatherr
Library api-ms-win-crt-time-l1-1-0.dll:
0x14001a3e8 _gmtime64_s
0x14001a3f0 _time64
0x14001a3f8 wcsftime

!This program cannot be run in DOS mode.
.o&a.v^
.Richf^
`.rdata
@.data
.pdata
@_RDATA
@.rsrc
@.reloc
@USVWATAVAWH
A_A^A\_^[]
@SVWAVH
HA^_^[
t$ AVH
UVWATAUAVAWH
A_A^A]A\_^]
UVWATAUAVAWH
t2L9E`r,H
A_A^A]A\_^]
|$ UATAUAVAWH
A_A^A]A\]
t$ WATAWH
A_A\_
\$ VAVAWH
A_A^^
\$ VAVAWH
A_A^^
SUVWAVH
A^_^][
|$ ATAVAWH
A_A^A\
@VWAUAVH
(A^A]_^
@SVATAVH
(A^A\^[
\$ UVWH
SVWATAUAVAWH
pA_A^A]A\_^[
@SVAVAWH
(A_A^^[
d$ UAVAWH
L$ SVWATAUAVAWH
PA_A^A]A\_^[
@USVWAVH
pA^_^[]
\$ VWAVH
fF94Bu
fD94_u
H;\$0t3
UVWAVAWH
`A_A^_^]
t$ WAVAWH
SVWATAUAVAWH
0A_A^A]A\_^[
WATAUAVAWH
A_A^A]A\_
L$ SUVWH
s WATAUAVAWH
A_A^A]A\_
s WATAUAVAWH
A_A^A]A\_
\$ UVWAVAWH
A_A^_^]
UVWATAUAVAWH
A_A^A]A\_^]
t$ WAVAWH
UVWATAUAVAWH
A_A^A]A\_^]
D$0H;\$(
SVWATAUAVAWH
A_A^A]A\_^[
UVWATAUAVAWH
A_A^A]A\_^]
UVWATAUAVAWH
A_A^A]A\_^]
@USVWATAUAVAWH
A_A^A]A\_^[]
t$ WATAWH
A_A\_
UVWATAUAVAWH
C@H98t"H
A_A^A]A\_^]
UVWATAUAVAWH
C@H98t"H
A_A^A]A\_^]
VWATAVAWH
pA_A^A\_^
\$ UVWH
@UWAVAWH
(A_A^_]
@SVAUAVH
(A^A]^[
t$ UWAVH
|$ UATAUAVAWH
A_A^A]A\]
SVWATAUAVAWH
pA_A^A]A\_^[
t$ UWAVH
f9D$ t
\$ UVWATAUAVAWH
L9t$XL
A_A^A]A\_^]
|$ UATAUAVAWH
A_A^A]A\]
UWAUAVAWH
A_A^A]_]
t$ AVH
UVWATAUAVAWH
A_A^A]A\_^]
@WAVAWH
0A_A^_
0A_A^_
@VWAVH
@UWAVAWH
(A_A^_]
UVWATAUAVAWH
A_A^A]A\_^]
\$ UVWATAUAVAWH
M9,$vTL
A_A^A]A\_^]
t$ WAVAWH
UVWATAUAVAWH
A_A^A]A\_^]
T$`A9r
f#D$@H
u0HcH<H
H3E H3E
D8L$0uP
H;xXu5
ffffff
fffffff
WATAUAVAWH
A_A^A]A\_
AUAVAWH
u4I9}(
;I9}(tiH
0A_A^A]
UVWATAUAVAWH
`A_A^A]A\_^]
@USVWATAUAVAWH
d$dD;d$ltY
A_A^A]A\_^[]
@USVWATAUAVAWH
A_A^A]A\_^[]
WAVAWH
SVWATAUAWH
L!d$(L!d$@D
D$HL9gXt
A_A]A\_^[
B(I9A(u
SVWATAUAVAWH
A_A^A]A\_^[
t$ WATAUAVAWH
A_A^A]A\_
UVWATAUAVAWH
A_A^A]A\_^]
WATAUAVAWH
A_A^A]A\_
LcA<E3
u HcA<H
bad allocation
address family not supported
address in use
address not available
already connected
argument list too long
argument out of domain
bad address
bad file descriptor
bad message
broken pipe
connection aborted
connection already in progress
connection refused
connection reset
cross device link
destination address required
device or resource busy
directory not empty
executable format error
file exists
file too large
filename too long
function not supported
host unreachable
identifier removed
illegal byte sequence
inappropriate io control operation
interrupted
invalid argument
invalid seek
io error
is a directory
message size
network down
network reset
network unreachable
no buffer space
no child process
no link
no lock available
no message available
no message
no protocol option
no space on device
no stream resources
no such device or address
no such device
no such file or directory
no such process
not a directory
not a socket
not a stream
not connected
not enough memory
not supported
operation canceled
operation in progress
operation not permitted
operation not supported
operation would block
owner dead
permission denied
protocol error
protocol not supported
read only file system
resource deadlock would occur
resource unavailable try again
result out of range
state not recoverable
stream timeout
text file busy
timed out
too many files open in system
too many files open
too many links
too many symbolic link levels
value too large
wrong protocol type
unknown error
0123456789abcdefghijklmnopqrstuvwxyz
0123456789abcdefghijklmnopqrstuvwxyz
bad exception
__based(
__cdecl
__pascal
__stdcall
__thiscall
__fastcall
__vectorcall
__clrcall
__eabi
__swift_1
__swift_2
__ptr64
__restrict
__unaligned
restrict(
delete
operator
`vftable'
`vbtable'
`vcall'
`typeof'
`local static guard'
`string'
`vbase destructor'
`vector deleting destructor'
`default constructor closure'
`scalar deleting destructor'
`vector constructor iterator'
`vector destructor iterator'
`vector vbase constructor iterator'
`virtual displacement map'
`eh vector constructor iterator'
`eh vector destructor iterator'
`eh vector vbase constructor iterator'
`copy constructor closure'
`udt returning'
`local vftable'
`local vftable constructor closure'
new[]
delete[]
`omni callsig'
`placement delete closure'
`placement delete[] closure'
`managed vector constructor iterator'
`managed vector destructor iterator'
`eh vector copy constructor iterator'
`eh vector vbase copy constructor iterator'
`dynamic initializer for '
`dynamic atexit destructor for '
`vector copy constructor iterator'
`vector vbase copy constructor iterator'
`managed vector copy constructor iterator'
`local static thread guard'
operator ""
operator co_await
operator<=>
Type Descriptor'
Base Class Descriptor at (
Base Class Array'
Class Hierarchy Descriptor'
Complete Object Locator'
`anonymous namespace'
FlsAlloc
FlsFree
FlsGetValue
FlsSetValue
InitializeCriticalSectionEx
hostfxr_main_bundle_startupinfo
hostfxr_set_error_writer
hostfxr_main_startupinfo
hostfxr_main
Unknown exception
bad array new length
string too long
iostream
bad cast
bad locale name
ios_base::badbit set
ios_base::failbit set
ios_base::eofbit set
invalid string position
iostream stream error
vector too long
invalid stoul argument
stoul argument out of range
ntdll.dll
RtlGetVersion
IsWow64Process2
74e592c2fa383d4a3960714caef0c4f2
c3ab8ff13720e8ad9047dd39466b3c89
D:\a\_work\1\s\artifacts\obj\win-x64.Release\corehost\apphost\standalone\apphost.pdb
.text$di
.text$mn
.text$mn$00
.text$x
.text$yd
.idata$5
.00cfg
.CRT$XCA
.CRT$XCAA
.CRT$XCC
.CRT$XCL
.CRT$XCU
.CRT$XCZ
.CRT$XIA
.CRT$XIAA
.CRT$XIAC
.CRT$XIZ
.CRT$XLA
.CRT$XLZ
.CRT$XPA
.CRT$XPZ
.CRT$XTA
.CRT$XTZ
.gehcont
.gfids
.rdata
.rdata$T
.rdata$r
.rdata$voltmd
.rdata$zzzdbg
.rtc$IAA
.rtc$IZZ
.rtc$TAA
.rtc$TZZ
.tls$ZZZ
.xdata
.xdata$x
.idata$2
.idata$3
.idata$4
.idata$6
.data$r
.data$rs
.pdata
_RDATA
P08~xO
@08~xO
P08~xO
GetModuleHandleW
OutputDebugStringW
FindFirstFileExW
EnterCriticalSection
GetFullPathNameW
FindNextFileW
GetCurrentProcess
GetModuleHandleExW
GetModuleFileNameW
LeaveCriticalSection
InitializeCriticalSection
GetEnvironmentVariableW
FindClose
MultiByteToWideChar
GetLastError
GetFileAttributesExW
LoadLibraryA
GetProcAddress
DeleteCriticalSection
WideCharToMultiByte
IsWow64Process
LoadLibraryExW
KERNEL32.dll
MessageBoxW
USER32.dll
ShellExecuteW
SHELL32.dll
ReportEventW
RegisterEventSourceW
DeregisterEventSource
RegGetValueW
RegOpenKeyExW
RegCloseKey
ADVAPI32.dll
_invalid_parameter_noinfo_noreturn
__acrt_iob_func
fputwc
fputws
fflush
__stdio_common_vfwprintf
__stdio_common_vswprintf
_wfopen
setvbuf
toupper
wcstoul
_errno
wcsncmp
calloc
strcspn
__stdio_common_vsprintf_s
localeconv
_gmtime64_s
wcsftime
_time64
api-ms-win-crt-runtime-l1-1-0.dll
api-ms-win-crt-stdio-l1-1-0.dll
api-ms-win-crt-heap-l1-1-0.dll
api-ms-win-crt-string-l1-1-0.dll
api-ms-win-crt-convert-l1-1-0.dll
api-ms-win-crt-locale-l1-1-0.dll
api-ms-win-crt-math-l1-1-0.dll
api-ms-win-crt-time-l1-1-0.dll
GetStringTypeW
InitializeCriticalSectionEx
EncodePointer
DecodePointer
LCMapStringEx
RtlCaptureContext
RtlLookupFunctionEntry
RtlVirtualUnwind
UnhandledExceptionFilter
SetUnhandledExceptionFilter
TerminateProcess
IsProcessorFeaturePresent
IsDebuggerPresent
QueryPerformanceCounter
GetCurrentProcessId
GetCurrentThreadId
GetSystemTimeAsFileTime
InitializeSListHead
RtlUnwindEx
RtlPcToFileHeader
RaiseException
SetLastError
InitializeCriticalSectionAndSpinCount
TlsAlloc
TlsGetValue
TlsSetValue
TlsFree
FreeLibrary
_lock_locales
_unlock_locales
malloc
setlocale
__pctype_func
___lc_locale_name_func
___lc_codepage_func
_wcsdup
___mb_cur_max_func
wcsnlen
_callnewh
_initialize_onexit_table
_register_onexit_function
_crt_atexit
_cexit
_seh_filter_exe
_set_app_type
__setusermatherr
_configure_wide_argv
_initialize_wide_environment
_get_initial_wide_environment
_initterm
_initterm_e
_set_fmode
__p___argc
__p___wargv
_c_exit
_register_thread_local_exe_atexit_callback
_configthreadlocale
_set_new_mode
__p__commode
terminate
strcpy_s
ja 8r{
d38cc827-e34f-4453-9df4-1e796e9f1d07
Builder.dll
.?AVinvalid_argument@std@@
.?AVlogic_error@std@@
.?AVlength_error@std@@
.?AVout_of_range@std@@
.?AVbad_exception@std@@
.?AVfailure@ios_base@std@@
.?AVruntime_error@std@@
.?AVbad_alloc@std@@
.?AVsystem_error@std@@
.?AVbad_cast@std@@
.?AV_System_error@std@@
.?AVexception@std@@
.?AVbad_array_new_length@std@@
.?AV_Facet_base@std@@
.?AV_Locimp@locale@std@@
.?AVfacet@locale@std@@
.?AU_Crt_new_delete@std@@
.?AUctype_base@std@@
.?AV?$ctype@_W@std@@
.?AV?$num_put@_WV?$ostreambuf_iterator@_WU?$char_traits@_W@std@@@std@@@std@@
.?AV?$numpunct@_W@std@@
.?AVtype_info@@
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<assemblyIdentity version="1.0.0.0" name="MyApplication.app"/>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v2">
<security>
<requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3">
<requestedExecutionLevel level="asInvoker" uiAccess="false"/>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>PAPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGX
api-ms-win-core-fibers-l1-1-1
api-ms-win-core-synch-l1-2-0
kernel32
api-ms-
hostfxr.dll
The library %s was found, but loading it from %s failed
- Installing .NET prerequisites might help resolve this problem.
https://go.microsoft.com/fwlink/?linkid=798306
%s
.NET Runtime
Description: A .NET application failed.
Application:
Path:
Message:
DOTNET_DISABLE_GUI_ERRORS
- https://aka.ms/dotnet-core-applaunch?
To run this application, you must install .NET Desktop Runtime
To run this application, you must install missing frameworks for .NET.
The framework '
' was not found.
Bundle header version compatibility check failed.
&apphost_version=
Would you like to download it now?
&gui=true
Showing error dialog for application: '%s' - error code: 0x%x - url: '%s'
Redirecting errors to custom writer.
COREHOST_TRACE
Tracing enabled @ %s
COREHOST_TRACEFILE
COREHOST_TRACE_VERBOSITY
Unable to open COREHOST_TRACEFILE=%s for writing
DOTNET_RUNTIME_ID
Did not find [%s] directory [%s]
0123456789
DOTNET_ROOT_
DOTNET_ROOT(x86)
DOTNET_ROOT
https://aka.ms/dotnet-core-applaunch?
missing_runtime=true
&arch=
%c GMT
Failed to load the dll from [%s], HRESULT: 0x%X
pal::load_library
Failed to pin library [%s] in [%s]
Loaded library from %s
Probed for and did not resolve library symbol %S
ProgramFiles(x86)
_DOTNET_TEST_DEFAULT_INSTALL_PATH
ProgramFiles
dotnet
SOFTWARE\dotnet
_DOTNET_TEST_REGISTRY_PATH
HKEY_CURRENT_USER\
\Setup\InstalledVersions\
InstallLocation
_DOTNET_TEST_GLOBALLY_REGISTERED_PATH
Can't open the SDK installed location registry key, result: 0x%X
Can't get the size of the SDK location registry value or it's empty, result: 0x%X
Can't get the value of the SDK location registry value, result: 0x%X
Failed to read environment variable [%s], HRESULT: 0x%X
Error resolving full path [%s]
kernel32.dll
Could not load 'kernel32.dll': %u
Call to IsWow64Process2 failed: %u
\\?\UNC\
Reading fx resolver directory=[%s]
Considering fxr version=[%s]...
A fatal error occurred, the folder [%s] does not contain any version-numbered child folders
Detected latest fxr version=[%s]...
Resolved fxr [%s]...
A fatal error occurred, the required library %s could not be found in [%s]
Using environment variable %s=[%s] as runtime location.
Using global installation location [%s] as runtime location.
A fatal error occurred, the default install location cannot be obtained.
or register the runtime location in [
A fatal error occurred. The required library %s could not be found.
If this is a self-contained application, that library should exist in [%s].
If this is a framework-dependent application, install the runtime in the global location [%s] or use the %s environment variable to specify the runtime location%s.
The .NET runtime can be found at:
- %s&apphost_version=%s
The managed DLL bound to this executable could not be retrieved from the executable image.
This executable is not bound to a managed DLL to execute. The binding value is: '%s'
The managed DLL bound to this executable is: '%s'
_ To run this application, you need to install a newer version of .NET Core.
Failed to resolve full path of the current executable [%s]
A fatal error was encountered. This executable was not bound to load a managed DLL.
Detected Single-File app bundle
The application to execute does not exist: '%s'.
Invoking fx resolver [%s] hostfxr_main_bundle_startupinfo
Host path: [%s]
Dotnet path: [%s]
App path: [%s]
Bundle Header Offset: [%lx]
The required library %s does not support single-file apps.
Invoking fx resolver [%s] hostfxr_main_startupinfo
The required library %s does not support relative app dll paths.
Invoking fx resolver [%s] v1
The required library %s does not contain the expected entry point.
7cca709db2944a09b4db6ca7b20c457ff260fb5a
apphost
--- Invoked %s [version: %s, commit hash: %s] main = {
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
CompanyName
Builder
FileDescription
Builder
FileVersion
1.0.0.0
InternalName
Builder.dll
LegalCopyright
OriginalFilename
Builder.dll
ProductName
Builder
ProductVersion
Assembly Version
1.0.0.0
Antivirus Signature
Bkav Clean
Lionic Clean
Elastic Clean
MicroWorld-eScan Clean
CMC Clean
CAT-QuickHeal Clean
ALYac Clean
Malwarebytes Clean
Sangfor Clean
K7AntiVirus Clean
Alibaba Clean
K7GW Clean
Cybereason Clean
Baidu Clean
VirIT Clean
Cyren Clean
Symantec Clean
tehtris Clean
ESET-NOD32 Clean
APEX Clean
Paloalto Clean
ClamAV Clean
Kaspersky Clean
BitDefender Clean
NANO-Antivirus Clean
ViRobot Clean
Avast Clean
Rising Clean
TACHYON Clean
Sophos Clean
F-Secure Clean
DrWeb Clean
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition Clean
Trapmine Clean
FireEye Clean
Emsisoft Clean
Ikarus Clean
Jiangmin Clean
Avira Clean
Antiy-AVL Clean
Gridinsoft Clean
Xcitium Clean
Microsoft Clean
SUPERAntiSpyware Clean
ZoneAlarm Clean
GData Clean
Cynet Clean
AhnLab-V3 Clean
Acronis Clean
McAfee Clean
MAX Clean
VBA32 Clean
Cylance Clean
Zoner Clean
TrendMicro-HouseCall Clean
Tencent Clean
Yandex Clean
SentinelOne Clean
MaxSecure Clean
Fortinet Clean
BitDefenderTheta Clean
AVG Clean
Panda Clean
CrowdStrike Clean
No IRMA results available.