Static | ZeroBOX

PE Compile Time

2023-11-02 17:59:27

PE Imphash

f61b3498a024e1606e5633ff05e57b42

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x0000c375 0x0000c400 6.57405568912
.rdata 0x0000e000 0x000031e4 0x00003200 5.41689560214
.data 0x00012000 0x00002c60 0x00001200 2.32852748893
.rsrc 0x00015000 0x000001b4 0x00000200 5.1024726656
.reloc 0x00016000 0x00001762 0x00001800 4.05835140526

Resources

Name Offset Size Language Sub-language File type
RT_MANIFEST 0x00015058 0x0000015a LANG_ENGLISH SUBLANG_ENGLISH_US ASCII text, with CRLF line terminators

Imports

Library KERNEL32.dll:
0x1000e008 WriteFile
0x1000e00c CreateFileA
0x1000e010 LocalReAlloc
0x1000e014 LocalAlloc
0x1000e018 Sleep
0x1000e01c Process32Next
0x1000e020 Process32First
0x1000e028 GetLastError
0x1000e02c CreateDirectoryA
0x1000e030 GetFileAttributesA
0x1000e038 CreateMutexA
0x1000e03c OpenMutexA
0x1000e040 SetLastError
0x1000e044 VirtualAlloc
0x1000e048 VirtualFree
0x1000e04c LoadLibraryA
0x1000e050 GetProcAddress
0x1000e054 LocalFree
0x1000e058 HeapAlloc
0x1000e05c FlushFileBuffers
0x1000e060 WriteConsoleW
0x1000e064 GetConsoleOutputCP
0x1000e068 WriteConsoleA
0x1000e06c SetStdHandle
0x1000e074 GetConsoleMode
0x1000e078 GetConsoleCP
0x1000e07c SetFilePointer
0x1000e080 HeapSize
0x1000e084 HeapFree
0x1000e088 CloseHandle
0x1000e090 TerminateProcess
0x1000e094 GetCurrentProcess
0x1000e0a0 IsDebuggerPresent
0x1000e0a4 RaiseException
0x1000e0a8 RtlUnwind
0x1000e0ac HeapReAlloc
0x1000e0b0 MultiByteToWideChar
0x1000e0b4 WideCharToMultiByte
0x1000e0b8 GetCurrentThreadId
0x1000e0bc GetCommandLineA
0x1000e0c0 GetModuleHandleW
0x1000e0c4 TlsGetValue
0x1000e0c8 TlsAlloc
0x1000e0cc TlsSetValue
0x1000e0d0 TlsFree
0x1000e0d4 InterlockedIncrement
0x1000e0d8 InterlockedDecrement
0x1000e0dc GetCPInfo
0x1000e0e0 GetACP
0x1000e0e4 GetOEMCP
0x1000e0e8 IsValidCodePage
0x1000e0ec DeleteCriticalSection
0x1000e0f0 LeaveCriticalSection
0x1000e0f4 EnterCriticalSection
0x1000e0f8 HeapCreate
0x1000e0fc HeapDestroy
0x1000e100 ExitProcess
0x1000e104 GetStdHandle
0x1000e108 GetModuleFileNameA
0x1000e10c SetHandleCount
0x1000e110 GetFileType
0x1000e114 GetStartupInfoA
0x1000e11c GetEnvironmentStrings
0x1000e124 GetEnvironmentStringsW
0x1000e12c GetTickCount
0x1000e130 GetCurrentProcessId
0x1000e134 LCMapStringA
0x1000e138 LCMapStringW
0x1000e13c GetStringTypeA
0x1000e140 GetStringTypeW
0x1000e144 GetLocaleInfoA
Library USER32.dll:
0x1000e154 PostQuitMessage
0x1000e158 TranslateMessage
0x1000e15c DispatchMessageA
0x1000e160 KillTimer
0x1000e164 SetTimer
0x1000e168 GetMessageA
0x1000e16c MessageBoxW
0x1000e170 GetDesktopWindow
Library SHELL32.dll:
0x1000e14c ShellExecuteExA
Library WININET.dll:
0x1000e178 InternetReadFile
0x1000e17c InternetOpenA
0x1000e180 InternetOpenUrlA
0x1000e184 InternetCloseHandle
Library CRYPT32.dll:
0x1000e000 CryptStringToBinaryA

Exports

Ordinal Address Name
1 0x100029b0 Edge
!This program cannot be run in DOS mode.
j?-Yj$U
j?-OjQU
j?-^j7U
j?-]j7U
jRich6U
`.rdata
@.data
@.reloc
T$(RWVP
D$(SVW
9l$hs
}D9l$hr
\$p9l$hr
\$p9l$hr
D$ +D$
D$,9D$8
0WWWWW
0WWWWW
QQSVWd
0SSSSS
u19=T0
0SSSSS
0A@@Ju
HtHu4j
s[S;7|G;w
tR99u2
j@j ^V
>=Yt1j
URPQQh
t"SS9]
PPPPPPPP
0SSSSS
PPPPPPPP
;t$,v-
UQPXY]Y[
^SSSSS
j"^SSSSS
HHtYHHt
t+WWVPV
%PUBLIC%\AccountPictures
%PUBLIC%\Documents
%PUBLIC%\Downloads
%PUBLIC%\Music
%PUBLIC%\Pictures
%PUBLIC%\Videos
%PUBLIC%\Libraries
%PUBLIC%
%PROGRAMDATA%
%APPDATA%
bad allocation
vector<T> too long
abcdef0g1h2i3j4k5l6m7n8o9pqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVWXYZ
\edge.jpg
\edge.xml
http://%s/%d
154.39.239.56:8000
ZjI0NWN7NjEzODgwQjMtOEFGMy00MzUwLUJGNDEtODNGQjY2MTlGNDg1fQ==
Unknown exception
EncodePointer
DecodePointer
FlsFree
FlsSetValue
FlsGetValue
FlsAlloc
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
bad exception
(null)
`h````
xpxxxx
CorExitProcess
runtime error
TLOSS error
SING error
DOMAIN error
An application has made an attempt to load the C runtime library incorrectly.
Please contact the application's support team for more information.
- Attempt to use MSIL code from this assembly during native code initialization
This indicates a bug in your application. It is most likely the result of calling an MSIL-compiled (/clr) function from a native constructor or from DllMain.
- not enough space for locale information
- Attempt to initialize the CRT more than once.
This indicates a bug in your application.
- CRT not initialized
- unable to initialize heap
- not enough space for lowio initialization
- not enough space for stdio initialization
- pure virtual function call
- not enough space for _onexit/atexit table
- unable to open console device
- unexpected heap error
- unexpected multithread lock error
- not enough space for thread data
This application has requested the Runtime to terminate it in an unusual way.
Please contact the application's support team for more information.
- not enough space for environment
- not enough space for arguments
- floating point support not loaded
Microsoft Visual C++ Runtime Library
<program name unknown>
Runtime Error!
Program:
Complete Object Locator'
Class Hierarchy Descriptor'
Base Class Array'
Base Class Descriptor at (
Type Descriptor'
`local static thread guard'
`managed vector copy constructor iterator'
`vector vbase copy constructor iterator'
`vector copy constructor iterator'
`dynamic atexit destructor for '
`dynamic initializer for '
`eh vector vbase copy constructor iterator'
`eh vector copy constructor iterator'
`managed vector destructor iterator'
`managed vector constructor iterator'
`placement delete[] closure'
`placement delete closure'
`omni callsig'
delete[]
new[]
`local vftable constructor closure'
`local vftable'
`udt returning'
`copy constructor closure'
`eh vector vbase constructor iterator'
`eh vector destructor iterator'
`eh vector constructor iterator'
`virtual displacement map'
`vector vbase constructor iterator'
`vector destructor iterator'
`vector constructor iterator'
`scalar deleting destructor'
`default constructor closure'
`vector deleting destructor'
`vbase destructor'
`string'
`local static guard'
`typeof'
`vcall'
`vbtable'
`vftable'
operator
delete
__unaligned
__restrict
__ptr64
__clrcall
__fastcall
__thiscall
__stdcall
__pascal
__cdecl
__based(
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
HH:mm:ss
dddd, MMMM dd, yyyy
MM/dd/yy
December
November
October
September
August
February
January
Saturday
Friday
Thursday
Wednesday
Tuesday
Monday
Sunday
`h`hhh
xppwpp
GetProcessWindowStation
GetUserObjectInformationA
GetLastActivePopup
GetActiveWindow
MessageBoxA
USER32.DLL
SunMonTueWedThuFriSat
JanFebMarAprMayJunJulAugSepOctNovDec
CONOUT$
string too long
invalid string position
CloseHandle
LocalFree
WriteFile
CreateFileA
LocalReAlloc
LocalAlloc
Process32Next
Process32First
CreateToolhelp32Snapshot
GetLastError
CreateDirectoryA
GetFileAttributesA
ExpandEnvironmentStringsA
CreateMutexA
OpenMutexA
SetLastError
VirtualAlloc
VirtualFree
LoadLibraryA
GetProcAddress
HeapFree
HeapAlloc
KERNEL32.dll
KillTimer
DispatchMessageA
TranslateMessage
PostQuitMessage
GetDesktopWindow
MessageBoxW
GetMessageA
SetTimer
USER32.dll
ShellExecuteExA
SHELL32.dll
InternetCloseHandle
InternetReadFile
InternetOpenA
InternetOpenUrlA
WININET.dll
CryptStringToBinaryA
CRYPT32.dll
GetSystemTimeAsFileTime
TerminateProcess
GetCurrentProcess
UnhandledExceptionFilter
SetUnhandledExceptionFilter
IsDebuggerPresent
RaiseException
RtlUnwind
HeapReAlloc
MultiByteToWideChar
WideCharToMultiByte
GetCurrentThreadId
GetCommandLineA
GetModuleHandleW
TlsGetValue
TlsAlloc
TlsSetValue
TlsFree
InterlockedIncrement
InterlockedDecrement
GetCPInfo
GetACP
GetOEMCP
IsValidCodePage
DeleteCriticalSection
LeaveCriticalSection
EnterCriticalSection
HeapCreate
HeapDestroy
ExitProcess
GetStdHandle
GetModuleFileNameA
SetHandleCount
GetFileType
GetStartupInfoA
FreeEnvironmentStringsA
GetEnvironmentStrings
FreeEnvironmentStringsW
GetEnvironmentStringsW
QueryPerformanceCounter
GetTickCount
GetCurrentProcessId
LCMapStringA
LCMapStringW
GetStringTypeA
GetStringTypeW
GetLocaleInfoA
HeapSize
SetFilePointer
GetConsoleCP
GetConsoleMode
InitializeCriticalSectionAndSpinCount
SetStdHandle
WriteConsoleA
GetConsoleOutputCP
WriteConsoleW
FlushFileBuffers
downexec.dll
.?AVbad_alloc@std@@
.?AVexception@std@@
.?AVlogic_error@std@@
.?AVlength_error@std@@
.?AVtype_info@@
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
.?AVbad_exception@std@@
.?AVout_of_range@std@@
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v3">
<security>
<requestedPrivileges>
<requestedExecutionLevel level="asInvoker" uiAccess="false"></requestedExecutionLevel>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>PAPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPAD
0%0[0r0
?3?B?l?
5,6#818C9
<&<3<><O<a<
2C2a2h2l2p2t2x2|2
2F3Q3l3s3x3|3
4 4j4p4t4x4|4
78,8\8b8j8w8
? ?g?{?
939Q9X9\9`9d9h9l9p9t9
96:A:\:c:h:l:p:
;Z;`;d;h;l;
>$>K>Q>\>h>}>
??%?2?<?C?[?j?q?~?
0"0L0R0n0
0&1I1S1
222@2K2R2m2r2z2
3%3*353:3E3J3W3e3k3x3
4 4'4.464>4F4R4[4`4f4p4y4
8#9.989Q9[9n9
<2<:<B<Y<r<
%0b1s1~1
2:2?2V2
2;3B3L3v3
5!5(515D5N5Z5c5k5u5{5
8!8.898K8^8i8o8u8z8
9&9,9F9W9]9n9
&01090M0j0
1+2J2S2
223:3M3X3]3m3w3~3
4F4S4}4
4<5I5f5
5=6B6j6
7P8Y8e8
9,9M9S9
9$:.:V:o:
:D;J;n;
<Z<e<o<
<>>O>W>]>b>h>
?!?.?5?l?
0(0-0N0S0
2*262>2F2R2v2~2
4#4/494A4L4|4
8 8(858<8l8
0C1P1i1
;G;Z;`;z;
<%<:<D<j<
=H=b=m=
=/=M=a=g=
=$>2>y>~>
>O?X?^?
0!0'070<0T0Z0i0o0~0
2%2k2q2}2
637>7l7z7
;h;0<6<;<A<H<Z<
1'181B1_1
353X3c3g3l3
2@4D4H4`4d4
2 2$2(2,2024282<2@2D2H2L2P2T2X2\2`2d2h2l2p2t2x2|2
3 3$3(3,3034383<3@3D3H3L3P3T3X3\3`3d3h3l3p3t3x3|3
=\>`>t>x>
?0?@?D?T?X?\?`?h?
0(080<0L0P0T0X0`0x0
1(181d1l1
2$282@2T2\2h2
404<4X4x4
545@5H5x5
64686X6x6
74787X7x7
8 8@8H8T8t8|8
0 0$0(0,0H0d0
7 808@8P8`8
:$:,:4:<:D:L:T:\:d:l:t:|:
; ;$;(;,;0;4;8;<;@;D;H;L;P;T;X;\;`;d;h;l;p;t;x;|;
KERNEL32.DLL
(null)
mscoree.dll
((((( H
h(((( H
H
No antivirus signatures available.
No IRMA results available.