Static | ZeroBOX

PE Compile Time

2019-03-18 15:27:52

PE Imphash

3b3bf55d4d03deeab01dbaeac2792edc

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x00015078 0x00015200 6.67060644472
.rdata 0x00017000 0x00007722 0x00007800 5.3500422886
.data 0x0001f000 0x00003274 0x00002a00 2.60136260455
.reloc 0x00023000 0x000013cc 0x00001400 6.54580398896

Imports

Library KERNEL32.dll:
0x10017050 WaitForSingleObject
0x10017054 CreateThread
0x10017058 EnterCriticalSection
0x1001705c VirtualFree
0x10017060 VirtualAlloc
0x10017064 LeaveCriticalSection
0x1001706c MoveFileExA
0x10017070 SetFilePointer
0x10017074 SetLastError
0x10017078 lstrlenA
0x1001707c lstrcatA
0x10017080 DecodePointer
0x10017084 CreateFileW
0x10017088 GetFileTime
0x1001708c GetLastError
0x10017090 Sleep
0x10017094 ReleaseMutex
0x10017098 CreateMutexA
0x1001709c SetFileTime
0x100170a0 DeleteFileA
0x100170a4 GetSystemDirectoryA
0x100170a8 CloseHandle
0x100170ac CreateFileA
0x100170b0 WriteFile
0x100170b4 GetFileSizeEx
0x100170b8 ReadFile
0x100170bc LocalFree
0x100170c0 LocalAlloc
0x100170c4 lstrcpyA
0x100170c8 GetCurrentThreadId
0x100170cc DeleteCriticalSection
0x100170d0 WriteConsoleW
0x100170d4 SetFilePointerEx
0x100170d8 HeapReAlloc
0x100170dc HeapSize
0x100170e0 SetStdHandle
0x100170e4 GetConsoleMode
0x100170e8 GetConsoleCP
0x100170ec FlushFileBuffers
0x100170f0 GetStringTypeW
0x100170f4 GetCommandLineW
0x100170f8 GetCommandLineA
0x100170fc GetProcessHeap
0x1001710c GetCurrentProcess
0x10017110 TerminateProcess
0x1001711c GetCurrentProcessId
0x10017124 InitializeSListHead
0x10017128 IsDebuggerPresent
0x1001712c GetStartupInfoW
0x10017130 GetModuleHandleW
0x10017134 EncodePointer
0x10017138 GetModuleFileNameW
0x1001713c RaiseException
0x10017140 InterlockedFlushSList
0x10017144 RtlUnwind
0x1001714c TlsAlloc
0x10017150 TlsGetValue
0x10017154 TlsSetValue
0x10017158 TlsFree
0x1001715c FreeLibrary
0x10017160 GetProcAddress
0x10017164 LoadLibraryExW
0x10017168 ExitProcess
0x1001716c GetModuleHandleExW
0x10017170 MultiByteToWideChar
0x10017174 WideCharToMultiByte
0x10017178 HeapFree
0x1001717c HeapAlloc
0x10017180 LCMapStringW
0x10017184 GetStdHandle
0x10017188 GetFileType
0x1001718c GetACP
0x10017190 IsValidCodePage
0x10017194 GetOEMCP
0x10017198 GetCPInfo
0x1001719c GetEnvironmentStringsW
Library USER32.dll:
0x100171a4 wsprintfA
Library ADVAPI32.dll:
0x10017000 SystemFunction036
0x10017004 CreateServiceA
0x10017008 StartServiceA
0x1001700c RegCloseKey
0x10017010 RegQueryValueExA
0x10017014 RegCreateKeyExA
0x10017018 RegSetValueExA
0x1001701c RegOpenKeyExA
0x10017020 CloseServiceHandle
0x10017024 OpenSCManagerA
0x10017028 QueryServiceStatusEx
0x1001702c OpenServiceA
0x10017030 CryptVerifySignatureA
0x10017034 CryptAcquireContextA
0x10017038 CryptCreateHash
0x1001703c CryptHashData
0x10017040 CryptDestroyHash
0x10017044 CryptImportKey
0x10017048 CryptReleaseContext
Library WS2_32.dll:
0x100171ac bind
0x100171b0 closesocket
0x100171b4 gethostbyname
0x100171b8 select
0x100171bc listen
0x100171c0 WSAStartup
0x100171c4 accept
0x100171c8 socket
0x100171cc connect
0x100171d0 recv
0x100171d4 htonl
0x100171d8 htons
0x100171dc setsockopt
0x100171e0 __WSAFDIsSet
0x100171e4 send
0x100171e8 WSAIoctl

Exports

Ordinal Address Name
1 0x100056b0 DllRegisterServer
2 0x100056b0 DllUnregisterServer
!This program cannot be run in DOS mode.
`.rdata
@.data
.reloc
~(9~$u
T$LPQR
|$HPWS
T$(PQR
T$DPVS
T$LRWS
L$LQVS
T$,RWV
T$,RWV
T$,RWV
L$,QWV
T$,RWV
L$ RUPj
9t$Tu
T+3x%A
;D$<s!
T$,PQh
{4_^]3
QQSVWd
URPQQh`
;t$,v-
UQPXY]Y[
^$+^8+
Wj0XPV
SSVWh
f9:t!V
QQSWj0j@
PPPPPWS
PP9E u:PPVWP
Unknown exception
bad allocation
bad array new length
invalid random_device value
inflate 1.1.4 Copyright 1995-2002 Mark Adler
bad exception
Main Invoked.
Main Returned.
EventRegister
EventSetInformation
EventUnregister
EventWriteTransfer
FlsAlloc
FlsFree
FlsGetValue
FlsSetValue
InitializeCriticalSectionEx
__based(
__cdecl
__pascal
__stdcall
__thiscall
__fastcall
__vectorcall
__clrcall
__eabi
__ptr64
__restrict
__unaligned
restrict(
delete
operator
`vftable'
`vbtable'
`vcall'
`typeof'
`local static guard'
`string'
`vbase destructor'
`vector deleting destructor'
`default constructor closure'
`scalar deleting destructor'
`vector constructor iterator'
`vector destructor iterator'
`vector vbase constructor iterator'
`virtual displacement map'
`eh vector constructor iterator'
`eh vector destructor iterator'
`eh vector vbase constructor iterator'
`copy constructor closure'
`udt returning'
`local vftable'
`local vftable constructor closure'
new[]
delete[]
`omni callsig'
`placement delete closure'
`placement delete[] closure'
`managed vector constructor iterator'
`managed vector destructor iterator'
`eh vector copy constructor iterator'
`eh vector vbase copy constructor iterator'
`dynamic initializer for '
`dynamic atexit destructor for '
`vector copy constructor iterator'
`vector vbase copy constructor iterator'
`managed vector copy constructor iterator'
`local static thread guard'
operator ""
Type Descriptor'
Base Class Descriptor at (
Base Class Array'
Class Hierarchy Descriptor'
Complete Object Locator'
`h````
xpxxxx
(null)
CorExitProcess
GetCurrentPackageId
LCMapStringEx
LocaleNameToLCID
SystemFunction036
NAN(SNAN)
nan(snan)
NAN(IND)
nan(ind)
Sunday
Monday
Tuesday
Wednesday
Thursday
Friday
Saturday
January
February
August
September
October
November
December
MM/dd/yy
dddd, MMMM dd, yyyy
HH:mm:ss
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
[aOni*{
~ $s%r
@b;zO]
v2!L.2
1#QNAN
1#SNAN
?5Wg4p
%S#[k=
"B <1=
_hypot
_nextafter
invalid string position
string too long
Enables a common interface and object model for the %s to access management information about system update, network protocols, devices and applications. If this service is stopped, most Kernel-based software will not function properly. If this service is disabled, any services that depend on it will fail to start.
Software\Microsoft\Windows NT\CurrentVersion\NetworkPlatform\Location Awareness
LastBackup
%s%s%s
%s %s %s
%s\%s.dll
%s\%s.%s
\svchost.exe
%s.log
SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost
netsvcs
%SystemRoot%\System32\svchost.exe -k netsvcs
MACHINE\SYSTEM\CurrentControlSet\Services\%s
SYSTEM\CurrentControlSet\Services\%s
Description
\Parameters
ServiceDll
{DB5CF4-42A2-E40
InvokeMainViaCRT
"Main Invoked."
FileName
ExitMainViaCRT
"Main Returned."
FileName
Microsoft.CRTProvider
.text$mn
.text$x
.idata$5
.00cfg
.CRT$XCA
.CRT$XCZ
.CRT$XIA
.CRT$XIC
.CRT$XIZ
.CRT$XPA
.CRT$XPX
.CRT$XPXA
.CRT$XPZ
.CRT$XTA
.CRT$XTZ
.rdata
.rdata$r
.rdata$zETW0
.rdata$zETW1
.rdata$zETW2
.rdata$zETW9
.rdata$zzzdbg
.rtc$IAA
.rtc$IZZ
.rtc$TAA
.rtc$TZZ
.xdata$x
.edata
.idata$2
.idata$3
.idata$4
.idata$6
.data$r
DllRegisterServer
DllUnregisterServer
GetCurrentThreadId
lstrcpyA
LocalAlloc
LocalFree
ReadFile
GetFileSizeEx
WriteFile
CreateFileA
CloseHandle
GetSystemDirectoryA
DeleteFileA
SetFileTime
CreateMutexA
ReleaseMutex
GetLastError
GetFileTime
MoveFileExA
WaitForSingleObject
CreateThread
EnterCriticalSection
VirtualFree
VirtualAlloc
LeaveCriticalSection
InitializeCriticalSection
DeleteCriticalSection
SetFilePointer
SetLastError
lstrlenA
lstrcatA
KERNEL32.dll
wsprintfA
USER32.dll
CryptReleaseContext
CryptImportKey
CryptDestroyHash
CryptHashData
CryptCreateHash
CryptAcquireContextA
CryptVerifySignatureA
OpenServiceA
QueryServiceStatusEx
OpenSCManagerA
CloseServiceHandle
RegOpenKeyExA
RegSetValueExA
RegCreateKeyExA
RegQueryValueExA
RegCloseKey
StartServiceA
CreateServiceA
ADVAPI32.dll
WSAIoctl
WS2_32.dll
UnhandledExceptionFilter
SetUnhandledExceptionFilter
GetCurrentProcess
TerminateProcess
IsProcessorFeaturePresent
QueryPerformanceCounter
GetCurrentProcessId
GetSystemTimeAsFileTime
InitializeSListHead
IsDebuggerPresent
GetStartupInfoW
GetModuleHandleW
EncodePointer
GetModuleFileNameW
RaiseException
InterlockedFlushSList
RtlUnwind
InitializeCriticalSectionAndSpinCount
TlsAlloc
TlsGetValue
TlsSetValue
TlsFree
FreeLibrary
GetProcAddress
LoadLibraryExW
ExitProcess
GetModuleHandleExW
MultiByteToWideChar
WideCharToMultiByte
HeapFree
HeapAlloc
LCMapStringW
GetStdHandle
GetFileType
GetACP
IsValidCodePage
GetOEMCP
GetCPInfo
GetEnvironmentStringsW
FreeEnvironmentStringsW
GetProcessHeap
GetCommandLineA
GetCommandLineW
GetStringTypeW
FlushFileBuffers
GetConsoleCP
GetConsoleMode
SetStdHandle
HeapSize
HeapReAlloc
SetFilePointerEx
WriteConsoleW
CreateFileW
DecodePointer
SystemFunction036
need dictionary
incorrect data check
incorrect header check
invalid window size
unknown compression method
invalid bit length repeat
too many length or distance symbols
invalid stored block lengths
invalid block type
incompatible version
buffer error
insufficient memory
data error
stream error
file error
stream end
invalid distance code
invalid literal/length code
incomplete dynamic bit lengths tree
oversubscribed dynamic bit lengths tree
incomplete literal/length tree
oversubscribed literal/length tree
empty distance tree with lengths
incomplete distance tree
oversubscribed distance tree
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
Windows
Microsoft
Network
Remote
Function
Secure
Application
Service
Client
Manager
Helper
System
Update
NetBIOS
Protocol
.?AVtype_info@@
.?AVbad_alloc@std@@
.?AVexception@std@@
.?AVbad_array_new_length@std@@
.?AVlogic_error@std@@
.?AVlength_error@std@@
.?AVout_of_range@std@@
.?AVbad_exception@std@@
.?AVBufferStream@@
.?AVTcp@@
.?AVProtocol@@
556h6l6p6t6x6|6
<0>4>8><>@>D>H>L>P>T>
>6>K>h>
?5?V?a?o?
'0B0N0
4E5\5q5
8I<P<V<c<z<
=0=A=E>Y>p>
?"???|?
1-161i1r1
1L2D3[3f3t3
5$5*5@5F5
7L8^8k8
8&909<9k9}9
:9:^:m:
050?0{0
1<1n1t1
202B2g2
3-3N3{3
3C4k4w4
7:8F8T8[8x8
8%919?9F9[9r9~9
:+:?:K:
:*;V;_;j;q;
<"<,<<<L<\<e<
==)=<=A=
>!>:>?>L>
1)1D1Z1c1v1
3*363F3W3}3
4)4P4X4q4
4&5.595?5E5Q5t5
5P6o6y6
7#8,848{8
9"9S9t9
9 :@:`:
00G0b0
0!111I1t1
7-7?7J7_7i7w7
=&=2=n=~=
>.>>>C>H>~>
?D?I?N?u?~?
#0/04090i0q0|0
212M2m2{2
4'454E4Z4q4
;j<n<r<v<z<~<
6D829<9I9|9
9U:\:o:
;%;I;d;o;
>!>7>M>d>k>w>
?"?4?=?
0#0V0[0
2$373F3g3
53686E6Q6j6}6
7'7,7L7Q7r7
9`9f9n<v<
=!=0=<=J=l=~=
>*>5>:>?>Z>d>
??;?F?K?P?
0*0/040R0p0{0
1)1;1G1U1v1}1
=8>4?H?
1*1E1Q1b1k1
232=2`2j2]7(:g:n:~:
=2=K=x=
=J>Y>k>}>
>?&?-?4?N?]?g?t?~?
090K2x2
3$323;3p3
7(7-73787F7j7
9L9Y9f9s9
1!2X2w2
8W8/9I9
;:<4='>t>L?
7M:T:[:b:
;(;:;L;^;p;
<!<3<E<W<
>??E?R?
484C4P4b4
4G5\5e5n5
:P:';i;q;y;
<1<=<I<i<
=*=.>_>
3%353F3
4>4c4o4{4
455A5M5Y5l5
627D7V7
4Q5n5r7
:;;@;D;H;L;
2024282<2D2H2L2d2h2l2
2L5P5T5X5l5
5074787<7@7D7H7L7P7T7X7\7`7d7h7l7p7t7x7|7
8 8$8(8,8084888<8@8D8H8L8P8T8X8\8`8d8h8l8p8t8x8|8
81@1H1L1P1T1X1\1`1d1l1p1t1x1|1
; ;$;(;,;0;<;@;D;H;L;P;T;X;\;`;d;h;l;p;t;x;|;
42<2D2L2T2\2d2l2t2|2
3$3,343<3D3L3T3\3d3l3t3|3
4$4,444<4D4L4T4\4d4l4t4|4
5$5,545<5D5L5T5\5d5l5t5|5
6$6,646<6D6L6T6\6d6l6t6|6
7$7,747<7D7L7T7\7d7l7t7|7
8$8,848<8D8L8T8\8d8l8t8|8
9$9,949<9D9L9
X3`3h3p3x3
4 4(40484@4H4P4X4`4h4p4x4
5 5(50585@5H5P5X5`5h5p5x5
6 6(60686@6H6P6X6`6h6p6x6
7 7(70787@7H7P7X7`7h7p7x7
8 8(80888@8H8P8X8`8h8p8x8
9 9(90989@9H9P9X9`9h9p9x9
: :(:0:8:@:H:P:X:`:h:p:
J>N>R>V>
8$8,848<8D8L8T8\8d8l8t8|8
8L:P:T:X:p<t<x<|<
<D>P>p>t>
?$?<?L?P?`?d?h?l?t?
0(080<0L0P0T0X0`0x0
1(181<1@1T1d1h1x1|1
1@5`5l5t5
6 6(60686@6L6l6t6
7(7D7H7P7X7`7d7l7
8$8,80848<8P8X8`8h8l8p8x8
9(9L9X9`9
:0:P:l:p:
;8;X;x;
<8<X<x<
4H4(5X5h5x5
; ;$;(;,;0;4;8;<;H;L;P;T;X;\;`;d;
707L7h7
advapi32
api-ms-win-core-fibers-l1-1-1
api-ms-win-core-synch-l1-2-0
kernel32
(null)
mscoree.dll
api-ms-win-appmodel-runtime-l1-1-1
api-ms-win-core-datetime-l1-1-1
api-ms-win-core-file-l2-1-1
api-ms-win-core-localization-l1-2-1
api-ms-win-core-localization-obsolete-l1-2-0
api-ms-win-core-processthreads-l1-1-2
api-ms-win-core-string-l1-1-0
api-ms-win-core-sysinfo-l1-2-1
api-ms-win-core-winrt-l1-1-0
api-ms-win-core-xstate-l2-1-0
api-ms-win-rtcore-ntuser-window-l1-1-0
api-ms-win-security-systemfunctions-l1-1-0
ext-ms-win-kernel32-package-current-l1-1-0
ext-ms-win-ntuser-dialogbox-l1-1-0
ext-ms-win-ntuser-windowstation-l1-1-0
user32
Sunday
Monday
Tuesday
Wednesday
Thursday
Friday
Saturday
January
February
August
September
October
November
December
MM/dd/yy
dddd, MMMM dd, yyyy
HH:mm:ss
((((( H
zh-CHS
az-AZ-Latn
uz-UZ-Latn
kok-IN
syr-SY
div-MV
quz-BO
sr-SP-Latn
az-AZ-Cyrl
uz-UZ-Cyrl
quz-EC
sr-SP-Cyrl
quz-PE
smj-NO
bs-BA-Latn
smj-SE
sr-BA-Latn
sma-NO
sr-BA-Cyrl
sma-SE
sms-FI
smn-FI
zh-CHT
az-az-cyrl
az-az-latn
bs-ba-latn
div-mv
kok-in
quz-bo
quz-ec
quz-pe
sma-no
sma-se
smj-no
smj-se
smn-fi
sms-fi
sr-ba-cyrl
sr-ba-latn
sr-sp-cyrl
sr-sp-latn
syr-sy
uz-uz-cyrl
uz-uz-latn
zh-chs
zh-cht
CONOUT$
No antivirus signatures available.
No IRMA results available.