Static | ZeroBOX

PE Compile Time

2023-06-27 12:58:20

PE Imphash

4187815841bc2ea783999b0bc5d86771

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x000946ab 0x00094800 5.92503999634
.rdata 0x00096000 0x00002382 0x00002400 4.89754588183
.data 0x00099000 0x00002f84 0x00001000 2.45032746212
.rsrc 0x0009c000 0x000002f8 0x00000400 2.61100019832
.reloc 0x0009d000 0x00001278 0x00001400 3.31370493368

Resources

Name Offset Size Language Sub-language File type
RT_VERSION 0x0009c060 0x00000298 LANG_ENGLISH SUBLANG_ENGLISH_US data

Imports

Library KERNEL32.dll:
0x496000 GetCurrentProcess
0x496004 VirtualAlloc
0x496008 GetNativeSystemInfo
0x49600c FreeLibrary
0x496010 HeapAlloc
0x496014 HeapFree
0x496018 VirtualFree
0x49601c GetProcessHeap
0x496020 IsBadReadPtr
0x496024 SetLastError
0x496028 GetProcAddress
0x49602c LoadLibraryA
0x496030 VirtualProtect
0x496034 GetLastError
0x496038 HeapReAlloc
0x49603c GetCommandLineW
0x496040 HeapSetInformation
0x496044 GetStartupInfoW
0x496048 HeapCreate
0x49604c GetModuleHandleW
0x496050 ExitProcess
0x496054 DecodePointer
0x496058 WriteFile
0x49605c GetStdHandle
0x496060 GetModuleFileNameW
0x496064 EncodePointer
0x496078 IsDebuggerPresent
0x49607c TerminateProcess
0x496080 GetCPInfo
0x49608c GetACP
0x496090 GetOEMCP
0x496094 IsValidCodePage
0x496098 TlsAlloc
0x49609c TlsGetValue
0x4960a0 TlsSetValue
0x4960a4 TlsFree
0x4960a8 GetCurrentThreadId
0x4960ac GetStringTypeW
0x4960b8 SetHandleCount
0x4960c0 GetFileType
0x4960cc GetTickCount
0x4960d0 GetCurrentProcessId
0x4960d8 LoadLibraryW
0x4960dc Sleep
0x4960e0 MultiByteToWideChar
0x4960e4 RtlUnwind
0x4960e8 WideCharToMultiByte
0x4960ec LCMapStringW
0x4960f0 HeapSize
0x4960f4 GetConsoleCP
0x4960f8 GetConsoleMode
0x4960fc FlushFileBuffers
0x496104 SetFilePointer
0x496108 CloseHandle
0x49610c WriteConsoleW
0x496110 SetStdHandle
0x496114 CreateFileW

Exports

Ordinal Address Name
1 0x401570 Test
!This program cannot be run in DOS mode.
.rdata
@.data
@.reloc
SVWj@h
T$(Rh@
jXh`zI
uh$kI
^SSSSS
QQSVWh
j@j ^V
u}h qI
URPQQh
t"SS9] u
PPPPPPPP
PPPPPPPP
;t$,v-
UQPXY]Y[
%X;ygs
*;E48xa
DsD'=fr
Pz\^7$
E-+n k
/Qb\`Id
|;(zX9
7%M W(
qDC6P
l3?;%
lCc:k_
2rB<d0H+F
yLvs<
Kk!e{I
+w6_j]H_
]uzj`?
hbx3i4
osd?}F
+_]%tu
'zg:8cL*
PzoZg
P7D!4N{
N<GrzHU
E$T&HT
x$g*_.
f!f]KN
pBC>6\hPoz
xA!)\0
<'@ j
k(ByjX
a>\5JT
iTvVwms
S\gUO?q<
M6Z.n
>H+D&?
Ag3/}1
B:t0C=
2`3Cqc23
Ezwa26/0
l3Mb)6
#Iz,;Wt$W
~W--n)&S
LkYG"R
@}SGf5
e1j1^>
-&6Wj"u
eDbZ|u
;OX(&:2
xty+jQ
bFM-;#N
y6Q6}@EC%
;-[V#v
(@W)V+
xKZ]%q
|W.d8
0T7L1<
Octt$!
Zz)]{[U
'&O|>+
3?OL+'`
+V?" A[
$7jQ3D
lZNZ9joH
RY2ItX
4o+Oof
Ks[J&om
vYp?G
G%jo6iH
~[Y#2S
0(_'9<0s-
Jnw'|L
j]!_CV
WuCc{J)
nV *i{z
vr1p@9K
em7.'n
{+FE%[
{S# Cy
O|!aOC
a|$H>k
6\BKNs
Ky@[#nK
}1M&(?
#F8y:
6$urwh
0!/3tlyP
lCjE#-Z.
ZV\#SP3
zSQ^$%
9MU[fS
18 N.'
U=v[^U/
hJ{WsV
BS#9/24
>iaPAp
uei2&K '
\#+Rk*
.{x}}T
eG<u*/,
Twch76
EYJ*Ue
(@wk4t
[`JEM
P^OzS@Y
.cYzp]lK
*{Z,,
!w^a.5k
gz:L-!
.MHabRb
cVMau>^
`K*Vv/
:1"ix8g6O8
p_T7%d
-t2^._DM
iUePm8
xG>39M?8
@iel!Z
ifuK&i
07H#KcBR
RVME}*L
-O4k&Y E
pfl`k\
096."*P
HOa`Ef
[BpH5
Bfz;X
*H]Fo?
*Y)*N<
-M&p7,5
Go)[qtf9^
NF,ZS;
]lx*H}
07V*kpy
kx;EiW
*6Ms0U:
0H}g66[
=uHCvbZ~:`
K;J2 W
6KQjs
k&N:|.
_.Ji;o
H#u3N.fh
*d% w}
@D`(8t
)5+SdD
IQ~>]#
EC;:nF
Q0O=J&,
B9Gh;}s
*9/"Q4;
_73B06u=T
I:A&o:
Fc0AjL
eNHFQ08h
d#L0%"%h*Wm
$94Uum
I.d-*zFw
vM$Qx0t]
k!%{)Zp
]YywH[Q_"
d"HLN^r$
3`;6@B
]V%-Ek'
u]#oP&i
n1 91#
N}m qT
=/JD$`{
Sr2yYW
&+4CYK
]NtioQ
EC91C*
:*$f"8
pb=}#U
dnb-+$Ny
}2;06U
x+<{%9
Pv?Xre
8M}$9O
bmZlGf
uooMSU
A{.oM<7
}l4;G
VGRTHk
rB.3"M
J1{HY<
MS=w\VF
.n:Jw,
Flfj(O
`O=otA
d@nb4KaaC?
rBW!S`
wMd>@
dzWd l
.rLv17
tzFGIm
p:W.]Q
)Y]3/2
RXqly?x
za}[1R
Cd|`B
~ZfXH6
S2WZh;u|~
:{F};(
kk1bk-P
]FpqQ@
anR`4eh
e+#I8@}b
oo^$,4\*
d081*~
iYdMtl{I
,0yf-y
PE}.d[
w9\s$|H
zjusk-
'K-2s|
?D%mn0tA8
DF"- j
Y#"g-
h;y:|q
Z"Wn).
MWayDW&
u?`:M+6
w-=$b}
1JMUx/
f<Nf4vw
L,lrX:
(Qr\.w
U!9DX>@
0j!lOI
mAa|]5
</A 5I
KueA8|
<*?5_1Z,*M\S
| gJ%o
bYR9ec
iU-`{#
%9~x?%
|X&3 b
!%HUsX
w/xfrJ
1:4G\n
`VT+]h
AM_hh0
hZl\K0
?[CFh t0
YMEd4Pn
j3BU?]
:TO{5C\w
@^H>l&
]67j0qW
UdZ8fMd
>iJ,Cl
4MReF]
jFL;pY
+!^qD~
9Ir-.0
hzOS%x
c;&=#!
g)fe+8
!V$=M}
Sb'UR!
8TK^##
KX5~?]?
`4?Vp>L#
B~D1D
k=pnVz
.,-bsU
75[}(Ot&a
*[SK=|
[E`'HA
9.o/8V
c 9"B&8
m.Hd=;
Y9`Ih&
mOF$Ph
Ti_bg@N
A2Od21
rMUrF+
6wxqhMr
XdW<nO-
_x@S?)
HOs%%
7XY:]\tN
iwlt^@
FeBeD>
/NBB-;
Q1n(8'
q[bc4
\qml@4l_
t57>@HX
QVOinMW
% w6%\6gsc
Ux:h5m
xS`G,,
W[=S1e
Wp2Lanf
rYtVv(
GU&[Z~K
iL>yfjk
U6M`.?
nZJ%+0xx
9jY2_Buz*
DY-~wM|+-
Szx,4vDz
{<wAK*
l0{1$>
elQ6:c
J@Q$X/
v.Bw\_I
phX:/j
a1XnuOQ;
9lITESv
CzSN9&n
GI.:]'A
Qe=Gom
.bO^4#
08h7A[
9%y'7W
K#E9+}
#[d8aZ
5MF~J^
Wj7?O=j
eQ@P?V
\,j"r`\
X6=L@8
z':Z@'
k15om}
8^qVGo
pT6cz7
'5goqw
Mv0XHN
|Jn~{t
{^%4E,;
R4;p!$
]klV(d
d90. Z
P+bPs!7O%~_2
h`:f
[P*l+Q
'4D@Z
LMdS"]fI<Y?
_tL;$@
w>!?W<
hYQnOm|
X2\4-H
efq%Ek
m+T $=
-_\p.f
b$Lb^Y]
ba]';|M:
|N}i)f
y7NOSVrG@$=
K.>AXtn
iHvSE{(
XQL;K\y
?BtUJ_
:"s-m
?7 ").J
b"H5Q]
u:4UH6QV
mhRJ2$S
B6g9H9s&
4CORikD
'uJ'[U;
gUaC=5
gA8UrV
<-%X:
|G~~@3R
c-3o2Tb
lR=,,x))
8X$FE
jopl"\H
ZYw]}b
i)*q{Y
%N|$m_
ZN7z3="x
*XH68t
Unr9wC
y`?qS4
A4k6=u
)b3AmS_
;CE# R
hy9Lj=K
"bamwN
2wgHe
zzK*D.
2zUvqm
)T)@E!
*f3h$ZK
G4xI?Z
RsMJ2yB2
(7l16m^
Ux)'q*
pa/vOa
W7UC#5
NVAh7?
}FTT*l
}+AK:6
jxk;Vd
91o>NV
c_~qnM
$5=6lFz}+
=awiAs
p1(Z)2
r`Rk`W
+s09|{
^M)^a>h~f
1~MFSh
"-qt4dy
/suY"u
|Pd^82
Wf}~&}
I:&GGT
.sspfo6@q
?w67mR
)u^{/>!G
UQrY2f
1ymi0k
9sD"R6L
_Fs~{Z
aYR|i,
CV(b#4
!p-nQ.
LmIdoZ
/s <H1
Kgv9abr
O25L X
T$)Y'!
U``>U)T
i $wwy
PXzd<@A
f)#br:
d MA*o
R+9V9!$
dwLo#<U
69G'jW
g8'Mp.
UUB?k<&+
REGxq>
R~pr?W
}n`I,G\
oH~sxBkM\u
r!;#~q
o7Ii4=
haYP=m
=fJy(T'0
~Hvj6;G%
.HDTrI
T1|fDx
s()pYB
8MT0,@
Xg;X=G
2L$kt?
]o@hB
IPMh8Y
1|mF~J
|M1$1I4
3_;L>%!t`$
wE|iR"
ih=*f^k;0p
p+Uhh_`
7j?J?D3
4glN+eNf
Ad@}&zV
q"3|~qFm
^Ae4T;Jf.
+P0v2]
9}l_i0
gVi{uY
O[-E|H
q0J!l2$
#P&3ip
3AsI>%
5{>L4=
9.+3PR
}oa:^U
Wikv6N*
|3V1z$
NWS@gPO
]$2uZ4
]D?2e0
uKB/ME
P0Q"@m6
YaK("
wQ*;)n
_R..GKTZ
iZ&g"$y*i
{C>HTo}
wt'UZ2
D(G]h&
/%RWiPQ
`GGzq#s
M/iu1acM
v";-Ay
P9S)uK
R ?=j(
o*?PC/
$)Qa!
oF2,A"1
^o28@If
9YKwv_i
It.VbH$
[!bX%<&wk
.~S'J_r,!QvX
&(BK-\
Z8'j,W
L2S>-82@
koV, t
x|7v^rMESf
PU` /TOb5%^w
gm~;?`"=
rR\nNf<y
',}%/U!PBP
%x":CJ
E=mS_~XB
tIHGlU
M^jr?mYs
I/<cJ@e?#
7"d/ty
8*IH9&!
(#@i3I
qu8i['
V<bm7L
~@vOKE
@i(s(T
kkYD!Y
2%2Yf2
ZG';oY
J%Q'(k
(B&DsZ
$$,DtU
:K'X}(,
>D1bY=
^[/Ic}r
<(Q!`!
5YA!`5
"vr[J#9
QSb&]j
s1>]1w6'k{.
o8)y2v
kO]{$=
<mlJ1>\
~!bM6
|}G)g.
b=M=q2?`;E:
x?gXD&#"
=dT a0\
R TpwH
oX8k+W
QTlr`a
VTL|=Z?
e.Km*v
#18+$^
P"L=|X
\Qd\uR
1~HzI2
Jhsgt>
t#RX*$!
"@WE?[
elaI.}
a*SkSO
\Vq{YV
FuOJez
,XS#X
+C_ )iY
La<|:c
2Bp-mq
nj+S/T
Jd/Cu+
.3ZU@U
zI+5#
"sU'N'1
ZsN$7<
;yv$8
S")!PP
{ZjU2N)&
g2N5 N
A(|FI$)
"u)SJu
'(}bXC'>
X^VDv0
~@.i^3
i75~754y
iCgBLaS@
p,E_^0
h0\0z)l
p8$vUb
h:|v@P
/N~Vz
j-vvK0Q
X8\6G&J.
[8ivAe
F%[t8e
_bFv\(
+t+XMW
V'HHbJ
LQi;f!
V=jf?b4cw]
PFWmN+
b~$6^7
#5Z%xx
8i#;QD
u>Z!@#
y{Pd7R
cZX4J
Pj0f]y
)|X_B]
V=[2-"m
>=!bJ<
1,5P~0
']nwgC
^!7%pP
cqqqr^
n*,9l"
#L,EPS
mYZ\Fu
Ne$)%if
6,;K(F
-1gWx=0'c
d_|&sPi
98)[i2
)8cn3B
3&Ljn.
CorExitProcess
(null)
`h````
xpxxxx
HH:mm:ss
dddd, MMMM dd, yyyy
MM/dd/yy
December
November
October
September
August
February
January
Saturday
Friday
Thursday
Wednesday
Tuesday
Monday
Sunday
FlsFree
FlsSetValue
FlsGetValue
FlsAlloc
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
GetProcessWindowStation
GetUserObjectInformationW
GetLastActivePopup
GetActiveWindow
MessageBoxW
`h`hhh
xppwpp
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
GetCurrentProcess
VirtualAlloc
GetNativeSystemInfo
FreeLibrary
HeapAlloc
HeapFree
VirtualFree
GetProcessHeap
IsBadReadPtr
SetLastError
GetProcAddress
LoadLibraryA
VirtualProtect
KERNEL32.dll
GetLastError
HeapReAlloc
GetCommandLineW
HeapSetInformation
GetStartupInfoW
HeapCreate
GetModuleHandleW
ExitProcess
DecodePointer
WriteFile
GetStdHandle
GetModuleFileNameW
EncodePointer
EnterCriticalSection
LeaveCriticalSection
UnhandledExceptionFilter
SetUnhandledExceptionFilter
IsDebuggerPresent
TerminateProcess
GetCPInfo
InterlockedIncrement
InterlockedDecrement
GetACP
GetOEMCP
IsValidCodePage
TlsAlloc
TlsGetValue
TlsSetValue
TlsFree
GetCurrentThreadId
GetStringTypeW
FreeEnvironmentStringsW
GetEnvironmentStringsW
SetHandleCount
InitializeCriticalSectionAndSpinCount
GetFileType
DeleteCriticalSection
QueryPerformanceCounter
GetTickCount
GetCurrentProcessId
GetSystemTimeAsFileTime
LoadLibraryW
MultiByteToWideChar
RtlUnwind
WideCharToMultiByte
LCMapStringW
HeapSize
GetConsoleCP
GetConsoleMode
FlushFileBuffers
IsProcessorFeaturePresent
SetFilePointer
CloseHandle
WriteConsoleW
SetStdHandle
CreateFileW
dfshim.dll
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
0#1(1j1
5(5;5@5q5
:%;A;Y;m;
?&?U?[?j?
0'1-191p1
2!2,2s2x2
5(5B5M5U5e5k5|5
6F7^7h7
939B9O9[9k9r9
9#:V:e:n:
;K<)=8=S=
9S9Z9g9m9
>%>.>8>l>w>
031?1R1d1
2.2W2h2|2
66%626<6B6L6n6
77%7;7S7y7
8 8X8`8
9#9(9-93979=9B9H9M9\9r9x9
<B>N>T>Y>_>
>!?I?o?u?
0G0Q0|0
1F1i1o1
2 2,2U2]2m2t2~2
3!343X3
4M4S4X4f4k4p4u4
5H5M5T5Y5`5e5s5
7&7I7N7S7j7
:&:,:6:<:F:L:V:_:j:o:x:
=(=O=X=d=
>8>A>h>u>z>
0&080J0\0
1$161H1Z1z2
3/3M3T3X3\3`3d3h3l3p3
324=4X4_4d4h4l4
5V5\5`5d5h5
6Z6`6{6
7 7,717A7F7L7R7h7o7
4;5H5a5
738=8U8~8
:&;S;^;
<!<2<v<
Z6a6l6
1$1(1,181<1@1D1H1\1`1
:$:,:4:<:D:L:T:\:d:l:t:|:
:X:t:x:
;$;@;L;h;
<(<4<P<p<
48889<9@9D9H9L9P9T9X9\9`9d9h9l9p9t9x9|9
: :$:(:,:0:4:8:<:@:D:H:L:P:T:X:\:`:d:h:l:p:t:x:|:
;(;8;\;h;l;p;t;x;
= =$=(=,=0=4=8=<=H=L=P=T=X=\=`=d=h=l=p=
mscoree.dll
runtime error
TLOSS error
SING error
DOMAIN error
- Attempt to use MSIL code from this assembly during native code initialization
This indicates a bug in your application. It is most likely the result of calling an MSIL-compiled (/clr) function from a native constructor or from DllMain.
- not enough space for locale information
- Attempt to initialize the CRT more than once.
This indicates a bug in your application.
- CRT not initialized
- unable to initialize heap
- not enough space for lowio initialization
- not enough space for stdio initialization
- pure virtual function call
- not enough space for _onexit/atexit table
- unable to open console device
- unexpected heap error
- unexpected multithread lock error
- not enough space for thread data
- abort() has been called
- not enough space for environment
- not enough space for arguments
- floating point support not loaded
IMicrosoft Visual C++ Runtime Library
<program name unknown>
Runtime Error!
Program:
(null)
HH:mm:ss
dddd, MMMM dd, yyyy
MM/dd/yy
December
November
October
September
August
February
January
Saturday
Friday
Thursday
Wednesday
Tuesday
Monday
Sunday
nKERNEL32.DLL
WUSER32.DLL
((((( H
h(((( H
H
ICONOUT$
VS_VERSION_INFO
StringFileInfo
040904b0
FileDescription
ClickOnce Application Deployment Support Library
FileVersion
10.0.22621.30000 (WinBuild.160101.0800)
InternalName
dfshim.dll
OriginalFilename
dfshim.dll
ProductVersion
10.0.22621.30000
VarFileInfo
Translation
No antivirus signatures available.
No IRMA results available.