Static | ZeroBOX

PE Compile Time

2022-04-24 03:41:13

PE Imphash

a9bf299729b09a43be583e7770d2853b

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x0001ea84 0x0001ec00 5.003491783
.data 0x00020000 0x002e2aec 0x00016400 7.25459759409
.rsrc 0x00303000 0x0000ec48 0x0000ee00 3.55604866808

Resources

Name Offset Size Language Sub-language File type
RT_CURSOR 0x00310808 0x000008a8 LANG_NEUTRAL SUBLANG_NEUTRAL dBase III DBT, version number 0, next free block index 40, 1st item "\251\317"
RT_ICON 0x00310328 0x00000468 LANG_SINDHI SUBLANG_SYS_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x00310328 0x00000468 LANG_SINDHI SUBLANG_SYS_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x00310328 0x00000468 LANG_SINDHI SUBLANG_SYS_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x00310328 0x00000468 LANG_SINDHI SUBLANG_SYS_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x00310328 0x00000468 LANG_SINDHI SUBLANG_SYS_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x00310328 0x00000468 LANG_SINDHI SUBLANG_SYS_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x00310328 0x00000468 LANG_SINDHI SUBLANG_SYS_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x00310328 0x00000468 LANG_SINDHI SUBLANG_SYS_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x00310328 0x00000468 LANG_SINDHI SUBLANG_SYS_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x00310328 0x00000468 LANG_SINDHI SUBLANG_SYS_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x00310328 0x00000468 LANG_SINDHI SUBLANG_SYS_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x00310328 0x00000468 LANG_SINDHI SUBLANG_SYS_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x00310328 0x00000468 LANG_SINDHI SUBLANG_SYS_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x00310328 0x00000468 LANG_SINDHI SUBLANG_SYS_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x00310328 0x00000468 LANG_SINDHI SUBLANG_SYS_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x00310328 0x00000468 LANG_SINDHI SUBLANG_SYS_DEFAULT GLS_BINARY_LSB_FIRST
RT_STRING 0x00311788 0x000004c0 LANG_SINDHI SUBLANG_SYS_DEFAULT data
RT_STRING 0x00311788 0x000004c0 LANG_SINDHI SUBLANG_SYS_DEFAULT data
RT_STRING 0x00311788 0x000004c0 LANG_SINDHI SUBLANG_SYS_DEFAULT data
RT_GROUP_CURSOR 0x003110b0 0x00000014 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_GROUP_ICON 0x003056c0 0x0000003e LANG_SINDHI SUBLANG_SYS_DEFAULT data
RT_GROUP_ICON 0x003056c0 0x0000003e LANG_SINDHI SUBLANG_SYS_DEFAULT data
RT_GROUP_ICON 0x003056c0 0x0000003e LANG_SINDHI SUBLANG_SYS_DEFAULT data
RT_GROUP_ICON 0x003056c0 0x0000003e LANG_SINDHI SUBLANG_SYS_DEFAULT data
RT_VERSION 0x003110c8 0x00000290 LANG_NEUTRAL SUBLANG_NEUTRAL MS Windows COFF PA-RISC object file

Imports

Library KERNEL32.dll:
0x401018 MoveFileExA
0x401034 BackupSeek
0x401038 GetModuleHandleW
0x40103c GetNumberFormatA
0x401040 SetFileTime
0x401048 GetCommandLineA
0x40104c GetDriveTypeA
0x401058 LoadLibraryW
0x40105c TerminateThread
0x401060 CopyFileW
0x401064 SetConsoleCP
0x401068 GetVolumePathNameA
0x40106c GetStartupInfoW
0x401070 CreateJobObjectA
0x401074 OpenMutexW
0x40107c GetLastError
0x40108c LoadLibraryA
0x401090 GetProcessId
0x401094 LocalAlloc
0x401098 GetFileType
0x40109c RemoveDirectoryW
0x4010a0 GetProfileStringA
0x4010a8 FindAtomA
0x4010ac GlobalWire
0x4010b0 EnumDateFormatsA
0x4010b4 GetModuleHandleA
0x4010bc FindNextFileW
0x4010c0 VirtualProtect
0x4010c8 EnumDateFormatsW
0x4010cc FatalAppExitA
0x4010d0 GetShortPathNameW
0x4010d4 OpenSemaphoreW
0x4010d8 FindAtomW
0x4010e0 FindFirstVolumeW
0x4010e4 AddConsoleAliasA
0x4010e8 CreateFileW
0x4010f0 FindFirstFileW
0x4010f4 GetComputerNameA
0x4010f8 EnumResourceNamesW
0x4010fc SetLastError
0x401100 GetCommandLineW
0x401104 CloseHandle
0x401108 ReadFile
0x40110c FlushFileBuffers
0x401110 GetStringTypeW
0x401114 HeapFree
0x401118 HeapAlloc
0x40111c GetProcAddress
0x401120 ExitProcess
0x401124 DecodePointer
0x401128 DeleteFileA
0x40112c EncodePointer
0x401130 HeapReAlloc
0x401134 HeapSetInformation
0x401138 RaiseException
0x401144 IsDebuggerPresent
0x401148 TerminateProcess
0x40114c GetCurrentProcess
0x401154 HeapCreate
0x401158 WriteFile
0x40115c GetStdHandle
0x401160 GetModuleFileNameW
0x401174 TlsAlloc
0x401178 TlsGetValue
0x40117c TlsSetValue
0x401180 TlsFree
0x401188 GetCurrentThreadId
0x40118c Sleep
0x401190 HeapSize
0x401194 SetHandleCount
0x40119c GetTickCount
0x4011a0 GetCurrentProcessId
0x4011a8 SetFilePointer
0x4011ac WideCharToMultiByte
0x4011b0 GetConsoleCP
0x4011b4 GetConsoleMode
0x4011b8 GetCPInfo
0x4011bc GetACP
0x4011c0 GetOEMCP
0x4011c4 IsValidCodePage
0x4011c8 RtlUnwind
0x4011cc MultiByteToWideChar
0x4011d0 SetStdHandle
0x4011d4 WriteConsoleW
0x4011d8 LCMapStringW
Library USER32.dll:
0x4011e8 GetListBoxInfo
0x4011ec CharUpperW
Library GDI32.dll:
0x401008 SelectPalette
0x40100c GetTextFaceW
0x401010 GetCharWidthW
Library ADVAPI32.dll:
0x401000 LookupAccountSidW
Library SHELL32.dll:
0x4011e0 DragFinish
Library ole32.dll:
Library WINHTTP.dll:
0x4011f4 WinHttpWriteData

!This program cannot be run in DOS mode.
RichW^
`.data
Unknown exception
CorExitProcess
bad allocation
(null)
`h````
xpxxxx
FlsFree
FlsSetValue
FlsGetValue
FlsAlloc
HH:mm:ss
dddd, MMMM dd, yyyy
MM/dd/yy
December
November
October
September
August
February
January
Saturday
Friday
Thursday
Wednesday
Tuesday
Monday
Sunday
`h`hhh
xppwpp
_nextafter
_hypot
GetProcessWindowStation
GetUserObjectInformationW
GetLastActivePopup
GetActiveWindow
MessageBoxW
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
Complete Object Locator'
Class Hierarchy Descriptor'
Base Class Array'
Base Class Descriptor at (
Type Descriptor'
`local static thread guard'
`managed vector copy constructor iterator'
`vector vbase copy constructor iterator'
`vector copy constructor iterator'
`dynamic atexit destructor for '
`dynamic initializer for '
`eh vector vbase copy constructor iterator'
`eh vector copy constructor iterator'
`managed vector destructor iterator'
`managed vector constructor iterator'
`placement delete[] closure'
`placement delete closure'
`omni callsig'
delete[]
new[]
`local vftable constructor closure'
`local vftable'
`udt returning'
`copy constructor closure'
`eh vector vbase constructor iterator'
`eh vector destructor iterator'
`eh vector constructor iterator'
`virtual displacement map'
`vector vbase constructor iterator'
`vector destructor iterator'
`vector constructor iterator'
`scalar deleting destructor'
`default constructor closure'
`vector deleting destructor'
`vbase destructor'
`string'
`local static guard'
`typeof'
`vcall'
`vbtable'
`vftable'
operator
delete
__unaligned
__restrict
__ptr64
__eabi
__clrcall
__fastcall
__thiscall
__stdcall
__pascal
__cdecl
__based(
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
1#QNAN
1#SNAN
dolonivifogikipidedave
bofuhogakuxejibetotubepelerohuwoyakayo
invalid string position
string too long
vector<T> too long
?uZEeu
?uZEeu
?UUUUUU
?UUUUUU
bad exception
HHtXHHt
?If90t
tWItHIt9It
^SSSSS
QQSVWh
j@j ^V
URPQQhP
t"SS9] u
;t$,v-
UQPXY]Y[
PPPPPPPP
PPPPPPPP
<+t"<-t
+t HHt
SPSSSSSS
L$8Qj@RP
D$Ht@i[
l$T6<pc
D$ Z&59
QQSVWd
f-00f=
t=MOC
HtHu4j
t*=RCC
;7|G;p
tR99u2
tRHtCHt4Ht%HtFHHt
GetCommandLineW
GetComputerNameA
EnumResourceNamesW
FindFirstFileW
GetConsoleAliasesLengthW
GetNumaProcessorNode
MoveFileExA
SystemTimeToTzSpecificLocalTime
InterlockedDecrement
SetDefaultCommConfigW
GetEnvironmentStringsW
SetConsoleScreenBufferSize
SetVolumeMountPointW
BackupSeek
GetModuleHandleW
GetNumberFormatA
SetFileTime
GetConsoleAliasExesW
GetCommandLineA
GetDriveTypeA
GetEnvironmentStrings
GetPrivateProfileIntA
LoadLibraryW
TerminateThread
CopyFileW
SetConsoleCP
GetVolumePathNameA
GetStartupInfoW
CreateJobObjectA
OpenMutexW
GetHandleInformation
GetLastError
GetCurrentDirectoryW
SetLastError
EnumSystemCodePagesW
LoadLibraryA
GetProcessId
LocalAlloc
GetFileType
RemoveDirectoryW
GetProfileStringA
FindNextChangeNotification
FindAtomA
GlobalWire
EnumDateFormatsA
GetModuleHandleA
FreeEnvironmentStringsW
FindNextFileW
VirtualProtect
GetCurrentDirectoryA
EnumDateFormatsW
FatalAppExitA
GetShortPathNameW
OpenSemaphoreW
FindAtomW
GetWindowsDirectoryW
FindFirstVolumeW
AddConsoleAliasA
KERNEL32.dll
GetListBoxInfo
CharUpperW
USER32.dll
GetTextFaceW
SelectPalette
GetCharWidthW
GDI32.dll
LookupAccountSidW
ADVAPI32.dll
DragFinish
SHELL32.dll
CoGetInstanceFromFile
ole32.dll
WinHttpWriteData
WINHTTP.dll
HeapFree
HeapAlloc
GetProcAddress
ExitProcess
DecodePointer
DeleteFileA
EncodePointer
HeapReAlloc
HeapSetInformation
RaiseException
UnhandledExceptionFilter
SetUnhandledExceptionFilter
IsDebuggerPresent
TerminateProcess
GetCurrentProcess
IsProcessorFeaturePresent
HeapCreate
WriteFile
GetStdHandle
GetModuleFileNameW
EnterCriticalSection
LeaveCriticalSection
InitializeCriticalSectionAndSpinCount
DeleteCriticalSection
TlsAlloc
TlsGetValue
TlsSetValue
TlsFree
InterlockedIncrement
GetCurrentThreadId
HeapSize
SetHandleCount
QueryPerformanceCounter
GetTickCount
GetCurrentProcessId
GetSystemTimeAsFileTime
SetFilePointer
WideCharToMultiByte
GetConsoleCP
GetConsoleMode
GetCPInfo
GetACP
GetOEMCP
IsValidCodePage
RtlUnwind
MultiByteToWideChar
SetStdHandle
WriteConsoleW
LCMapStringW
GetStringTypeW
FlushFileBuffers
ReadFile
CreateFileW
CloseHandle
.?AVlogic_error@std@@
.?AVlength_error@std@@
.?AVout_of_range@std@@
.?AVtype_info@@
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
.?AVexception@std@@
i:>(9s
)}%uY,
AJutg[
?'_H-r
O`Ld<Iq
nUv0E]
yKb["V
vLJUrd
%pvogG
LIiO0i
)=!vh
0!Phas
sM|;&u3
;J/lr:dx
qrx5um
B`Jigxz
A2$&IE
g7G,"Z-
j4&6'e
=V'Lt
Nmr]3m
RX}/VH
){/u5`
zTp\'P
;#h%DF
c<[7b-P
mi]Msh
Y*:$:^(
*|V1?w
h_"9vl,
-.[<wA
ko.GV3#
D)^x'A*
3L5}Gp
k-wg'?
lPLLh8
5p'kcuZ
N-n>U/
JX0A-Yv
jRBe=iH1
c2]3J6QJ<
JX0A-1
N^OJF):05
,|w;}m
_?)@6)
7]zy}_
|2fw@
C8FR\+
}78O<x
}:pY-j
/~/E}VH+
1tiK=bP
_oc1IC
%].Gk
?OBvNhY
-\\ZpE$
R]M)[v
71bN\W/
Mq|&1}
Q?_v@
xA9"Bj
B-vNW),ag4
|A%{3 zH
t;ZL+'zOp
#KoMJ|
P,|;_Ot
yUhM((g
hW0f:2
`mhUt
b/HzyOx
`{aa:z
ED4$SZ
w:hwz/
)YiPx
6W$/<fl
UXM"=b
0=w0LA
H%g_}9
6[x{WTw
B9!69S
hn'kRS
ZBQN6H
VfJj-c
Wm,5oO
H=,"nT^
\HYEm'
mNgFV#
O&MLnw?
`|t%Jv
<X>3q'
1 gl0{
E+3aD#mOo
U7EzmWy
Kh:5%(
2YUvX"
CshI|+
o|sj+g
U1Yz,z
@vxvj5
bQ&-.q,
"tu3bJ
a5o,_8
l46S+!s"YN
D|}{5/t
vuVxSe
g>=;HP
UEqSnH31
dlk8~{
$0|vE/
aZe/[K
oH`RNp
tdtE<>
-5faV:
LAv\3p
Pk.j6o
p>}bD5uh
bCqap?
vI%xIp,
_vePw6
ogcXN@
|U-z(O
"[[>+o!
IH$[sQO<
c'CM<OM|
'ijGfG
%[2R%
+es)Wu-@
!dja+?x
jDF$F~n
.y(r72
<bvj0^
7)mLOw
tn@UD0
b0WJA
ur*ogc
MN_((W
:h^mh=
3d<s!H
i^JOWUuH
gpC^\
.?AVbad_alloc@std@@
.?AVbad_exception@std@@
cccc_ce@
cFFFFFFF
,





51D
}}}}}}}
R

,



~z}}}~~{
~}{~}|
}|z~||
}}y{~{
{}z~{{
{|z~}{zz~
z{|{|~|}
~{z{}|
~~{y{|
{}}}|{
}}|{{{
|{|~~{
~}|}~~~
z|}|{{~z}
~||z~{~}
{||y|}
}|}||~}
}zz}~|~
{~~z~z}}{z}}
|}~~}~
NNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNv
NNNNNNNNNNs
NNNNNNNNNNs
NNNNNNNNNN
NNNNNNNNNN
NNNNNNNNNN
NNNNNNNNNN
NNNNNNNNNN
sNNNNNNNNNN
sNNNNNNNNNN
NNNNNNNNNN
NNNNNNNNNN
NNNNNNNNNN
NNNNNNNNNN
NNNNNNNNNN
NNNNNNNNNN
NNNNNNNNNN
NNNNNNNNNN
NNNNNNNNNN
NNNNNNNNNN
NNNNNNNNNN
NNNNNNNNNN
NNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNN
\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\
\\\\\\\\\\ka\\\\\\\\\\\
\\\\\\\\\\
r\\\\\\\\\\
\\\\\\\\\
\\\\\\\\\7
\\\\\\\\
\\\\\\\z
\\\\\\
gLz\\\\\\
\\\\\\
Cl\\\\\\
\\\\\r=
\\\\\\\
\\\\\\\\\\
\\\\\\\\\\\\\\\
Z\\\\\\\\\\\\\\\\
jE\\\\\\\\\\\\\\\\\\
z\\\\\\\\\\\\\\\\\\\
\\\\\\\\\\\\\\\\\\\\
\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\
=================================================================&======t
=======&
=====tLl======&r
.====.
^&====
.========t_
==========t
===========tL
=============t.======================
mscoree.dll
(null)
wruntime error
TLOSS error
SING error
DOMAIN error
- Attempt to use MSIL code from this assembly during native code initialization
This indicates a bug in your application. It is most likely the result of calling an MSIL-compiled (/clr) function from a native constructor or from DllMain.
- not enough space for locale information
- Attempt to initialize the CRT more than once.
This indicates a bug in your application.
- CRT not initialized
- unable to initialize heap
- not enough space for lowio initialization
- not enough space for stdio initialization
- pure virtual function call
- not enough space for _onexit/atexit table
- unable to open console device
- unexpected heap error
- unexpected multithread lock error
- not enough space for thread data
- abort() has been called
- not enough space for environment
- not enough space for arguments
- floating point support not loaded
@Microsoft Visual C++ Runtime Library
<program name unknown>
Runtime Error!
Program:
KERNEL32.DLL
HH:mm:ss
dddd, MMMM dd, yyyy
MM/dd/yy
December
November
October
September
August
February
January
Saturday
Friday
Thursday
Wednesday
Tuesday
Monday
Sunday
WUSER32.DLL
((((( H
h(((( H
H
CONOUT$
xaguzixuyi
/ P6pL
,/KPip
/-P?pR
VS_VERSION_INFO
StringFileInfo
029385B3
CompanyName
Phunderstuck
FileDescriptions
Anybodies
FileVersions
49.51.44.114
InternalName
Cascader.exe
LegalCopyrights
Challangers bottle
ProductName
Bonneville
ProductVersion
17.25.64.30
VarFileInfo
Translation
xSoruxutagebub xugihifehufuwu manetaxoser voxomalahale nirip buluvebox jake guwiyapekuhuli yemuyotenariso guwakotapipedezUKeb vukibejasodiv somop tixidisugabiv howusofixawozu karopika mitegataw xeyoxi vujelu-Yasu hezazeg yuwulapako yifi tuzemewulir medu.Vevapasavay meya lotayukosopef jipezecobalixeh4Toniwuv mir hexerukumulupuj juwuruyog vodanaziwilagi
*Xekiducas piy yozuya maworinare jobixu hof
*Kano cukepe wajalali gigoxoce fusemu jusoc
Rimesapepofap kif
5Cafuxedalica dacizuzofisesa pedakobu netaweva demahec
2Beketowifope feme mugaxozad govuve rubeyanopinuvuxGLuhomijiruwaki jenine jidiratako xaba retacototevoh wuro haworaz telavu
&Gina dok yunitabapopox yiliverefubizek"Pehuxe diwiyoyizis lepamaxurulunixZRinisipade varivabusoxa xud peranatanux kaxiramavuk tata vulom picenanafow tib selulazefin
Jud vadajurubone
AGov nexemewetupu xaxoxej peru xupitosetejirup nojifuguyimuj pajah
Xasutete?Yerehezuse fecuwegijusih sejab ruvu mizovapomod xow xofofefudodMWuheluj tijusobocin xuhoni xak banovara wezayatafiyaw webivevamazowu jewaduxePNohitolegar cuzixu suyot xokuyaser hukafifig tipapuxofumoga rivabibixosuzi rihem
No antivirus signatures available.
No IRMA results available.