Static | ZeroBOX

PE Compile Time

2023-11-21 02:49:53

PE Imphash

e1ed1b87d365b2ea75670bba09649dc7

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x0000e41c 0x0000e600 6.53066327621
.rdata 0x00010000 0x00006f5c 0x00007000 4.94669420685
.data 0x00017000 0x0000161c 0x00000a00 2.35096783462
.rsrc 0x00019000 0x0001ab9c 0x0001ac00 3.49517469531
.reloc 0x00034000 0x000010e8 0x00001200 6.3472196688

Resources

Name Offset Size Language Sub-language File type
RT_DIALOG 0x00019160 0x0000020c LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_RCDATA 0x0003376c 0x00000016 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_RCDATA 0x0003376c 0x00000016 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_VERSION 0x00033784 0x00000298 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_MANIFEST 0x00033a1c 0x0000017d LANG_ENGLISH SUBLANG_ENGLISH_US XML 1.0 document text

Imports

Library KERNEL32.dll:
0x410000 VirtualProtect
0x410004 VirtualFree
0x410008 GetCurrentProcess
0x41000c VirtualAlloc
0x410010 GetModuleHandleA
0x410014 GetProcAddress
0x410018 ExitProcess
0x41001c GetModuleHandleW
0x410024 WriteConsoleW
0x410028 CloseHandle
0x41002c CreateFileW
0x410030 SetFilePointerEx
0x410034 GetConsoleMode
0x410038 GetConsoleOutputCP
0x41003c FlushFileBuffers
0x410040 HeapReAlloc
0x410044 HeapSize
0x410050 TerminateProcess
0x41005c GetCurrentProcessId
0x410060 GetCurrentThreadId
0x410068 InitializeSListHead
0x41006c IsDebuggerPresent
0x410070 GetStartupInfoW
0x410074 RtlUnwind
0x410078 RaiseException
0x41007c GetLastError
0x410080 SetLastError
0x410084 EncodePointer
0x410098 TlsAlloc
0x41009c TlsGetValue
0x4100a0 TlsSetValue
0x4100a4 TlsFree
0x4100a8 FreeLibrary
0x4100ac LoadLibraryExW
0x4100b0 GetStdHandle
0x4100b4 WriteFile
0x4100b8 GetModuleFileNameW
0x4100bc GetModuleHandleExW
0x4100c0 HeapFree
0x4100c4 HeapAlloc
0x4100c8 FindClose
0x4100cc FindFirstFileExW
0x4100d0 FindNextFileW
0x4100d4 IsValidCodePage
0x4100d8 GetACP
0x4100dc GetOEMCP
0x4100e0 GetCPInfo
0x4100e4 GetCommandLineA
0x4100e8 GetCommandLineW
0x4100ec MultiByteToWideChar
0x4100f0 WideCharToMultiByte
0x4100fc SetStdHandle
0x410100 GetFileType
0x410104 GetStringTypeW
0x410108 LCMapStringW
0x41010c GetProcessHeap
0x410110 DecodePointer

!This program cannot be run in DOS mode.
`.rdata
@.data
@.reloc
VWhpLA
SVWhpLA
QQSVWd
j<hHdA
URPQQh
UQPXY]Y[
35h}A
j"_f9y
tlj*Yf
f9:t!V
QQSVj8j@
tl=HvA
j$h@gA
PPPPPPPP
PPPPPWS
PP9E u:PPVWP
bad allocation
bad exception
__based(
__cdecl
__pascal
__stdcall
__thiscall
__fastcall
__vectorcall
__clrcall
__eabi
__swift_1
__swift_2
__swift_3
__ptr64
__restrict
__unaligned
restrict(
delete
operator
`vftable'
`vbtable'
`vcall'
`typeof'
`local static guard'
`string'
`vbase destructor'
`vector deleting destructor'
`default constructor closure'
`scalar deleting destructor'
`vector constructor iterator'
`vector destructor iterator'
`vector vbase constructor iterator'
`virtual displacement map'
`eh vector constructor iterator'
`eh vector destructor iterator'
`eh vector vbase constructor iterator'
`copy constructor closure'
`udt returning'
`local vftable'
`local vftable constructor closure'
new[]
delete[]
`omni callsig'
`placement delete closure'
`placement delete[] closure'
`managed vector constructor iterator'
`managed vector destructor iterator'
`eh vector copy constructor iterator'
`eh vector vbase copy constructor iterator'
`dynamic initializer for '
`dynamic atexit destructor for '
`vector copy constructor iterator'
`vector vbase copy constructor iterator'
`managed vector copy constructor iterator'
`local static thread guard'
operator ""
operator co_await
operator<=>
Type Descriptor'
Base Class Descriptor at (
Base Class Array'
Class Hierarchy Descriptor'
Complete Object Locator'
`anonymous namespace'
FlsAlloc
FlsFree
FlsGetValue
FlsSetValue
InitializeCriticalSectionEx
CorExitProcess
Sunday
Monday
Tuesday
Wednesday
Thursday
Friday
Saturday
January
February
August
September
October
November
December
MM/dd/yy
dddd, MMMM dd, yyyy
HH:mm:ss
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
LCMapStringEx
LocaleNameToLCID
AppPolicyGetProcessTerminationMethod
?5Wg4p
%S#[k=
"B <1=
_hypot
_nextafter
kernel32
LoadLibraryA
Unknown exception
bad array new length
string too long
lgvcisbhcpflgiqcebsqoixajvlcuteeqyve
lidfsscrmfvsrknbsteftlqehkxuqzvkyzcbpijqoklekzhbpabcodlevpavemrlktxhxtvgkhmgzdranvrxgmxfjdhrosq
ljxpxyxusbcjnrlrsubaq
mfdumuvrsdqbbrjquvcwjbbkuezccppsdnjxrnafiowdfwslxixxup
oztgftgknllvsbnfqhextxdrdwhdcjpworzasccoe
mnuntxuaruvecxjuimfwsuloypedfcocbuqppbndiuttefkkvyydfvgtlru
ozhvojoiin
ccndzcccsriyirkmxdhobcpygljiqdzvybbneogkeqqvfttwpnyeg
yfeeztjeeiaoldtibgtrmrvcpdoxmywqbshydmcwvyuhrusbeaknudkbztlyhzvmbsdgt
gnnmcbgcviqvgvhuevyvjxhrwthqxnqyrnpdmvvpjrvulwopuomzjezdlfusfkavpbikpopjwlukeoworjyveacfd
rshuxwwjbiqqgyqwuvzezzisydwujaoersseoebp
owklrvkhgvpfcagqaxyuykacyixxigoc
rnzoafiueljgispfwvyopcgtynsbodoiobuagdyphkvlqzsuomkmi
fiwlkiausbbvjurasxwgxufwzvwgyfyipnlynwjlhdlnqstbqrjqppxmvykhrkkbwcplatuqzty
jrpfvurcktfxuresprojxfsfsaplfppovntwhos
oeubpjbuiyysqcrzqilovae
hwzceovmsbtjqtepixplhex
lwnjzwsrsbjnoolpbyuemoqwboczxmymwmzxlnkbajxfzbvezsdbcv
ltlotknyqwggjymessrvxrmpscysgimodppsmg
pzzoeadsvmkunisktbigkpsxcgdjtklyvxxchjimosxfceqhwbqlrkuhjbzw
nvvnjnfelooadjydrxfpeaqucodazhirspgnjkdtkf
sopadrofujxxmmoewddfjrimogimpkqaoqshdhsawsbdqnyrqrleddymwkcyhwstbszwrharpfng
yhfumrmxbcaddgxaqmfwfusbvvizdbsipiikjtromagtvgckmsbive
fjvbdhtdrvszyvtksgekjtqcbessdzjdgpomflwewq
wnqlyxdshk
xabancvoyzva
dgipxjlfapcltrwzfvwmoobgtoorlyzyqgtwilukkxkjrpfreeutdsuqomejfkdvbkrkcqvrrpaaym
pjlzskgrjenazaxyqsaifecmjxiqkcilhftmskgjwtkywfbqmhrolzsuxlvvhngx
enuisuwvusjvgaelkphzqhkrjpakcz
jaqrixymgjhlnvpnmb
xtnewewzqffxjcgzlqbrfzgbszigmehv
ctojpluahhvbndpajemlsapmrbzccysggrucxdxiwhxwivljikmzfbmmiyeayuhmbprkeaukjtryswcjukc
zlmiwmyyxhixhrzrfbsuwbtxipgdyndyvcrnqxqvnnsdnrhklhkhdhhizeezqynvbg
kpbiyjsjdpnaamq
aktzwegvudkfzomzespyxyggjkjihruwijiaqkyzicijexprrmbgelvpdzcalqzgqjmiertbwwdrzoqtbhnces
yffoywfdunkcazlqtwfmwlgrktylsauicwxwyqcfwqtnzkrbpfvqjdcuhjojzapkm
oxspbnmlzrbroswcjhfghretcvdnnzxbqvcmrobyiqjloi
hmwiearljlrihfywkfooigas
pdkmfmbmjyhdkaoaejjxfipzhzbwkynprnwimaucbuxwtwrurxsolfkwzbdvbhfejmlvmtfxewqrickdhbsczoiagbkgh
zutfamivpypwgmgsofiopnsu
fcsipxcuvqbishboz
echjunqxgtnkmx
yaelhaqsyncrlepkszcjimvcydiyfuwor
nfffgeqrfiohyizvrqzisfbvgutoneyseozwdebvbeuhckvkimxgqjkibukzclwltsndeaipldwiqorxdynsk
ymkyijtwozffgmygyxehroumhysalwwkgawug
bdrchtmnfqutsuijf
wlevkarblppcvuffdwzzcbpdlqfdbhgfskayaarzmglzihmgkpxfzxkugosmmbofaffmbyjdgdnnaxhubeypnmyvuevfvuf
zjwolxpwwsgdlczxishxkbftrimoscran
fjdosnhpucgibdixhokshcguoctmpvuigrafibkohzbvcazehcidleqlfvprpthidrtradstehfogcninszaxcktvvkudu
txkkgbqnadrycwgkergxnxmtyagonppjhzdsgcedfyfoeaccfqmsazcsluhbtkwxawaznybx
zzmksxwmionqwymgsgmbdjyquzmflntzv
mpmjalcdcvoznmmtfmxotgeexnae
mdxqjbuvpxuaqhcowtvwbfyti
rbpnwozvffmtzsumynuwxobskoexmovkxywlwsk
xhbfwlumvbnhizgnobdeeucbitexcgzbdetwwclddihlrvbvxhnhqrjehwwtcdeeqwqbmky
sasfdcosumzaijrzpbicv
egzsnyowjknotdgvdeyzbrnldqmxxivapbduweudqxjpdxtiujeytocilzicbnnmjyfjpbuamspkhyn
wlsyookqjemgudjneangniehlliwefqvpxvf
rlbtvnykikrmr
jklhjkluktyuity
.text$mn
.text$x
.idata$5
.00cfg
.CRT$XCA
.CRT$XCAA
.CRT$XCZ
.CRT$XIA
.CRT$XIAA
.CRT$XIAC
.CRT$XIC
.CRT$XIZ
.CRT$XPA
.CRT$XPX
.CRT$XPXA
.CRT$XPZ
.CRT$XTA
.CRT$XTZ
.rdata
.rdata$r
.rdata$sxdata
.rdata$voltmd
.rdata$zzzdbg
.rtc$IAA
.rtc$IZZ
.rtc$TAA
.rtc$TZZ
.xdata$x
.idata$2
.idata$3
.idata$4
.idata$6
.data$r
.data$rs
.rsrc$01
.rsrc$02
VirtualProtect
VirtualFree
GetCurrentProcess
VirtualAlloc
GetModuleHandleA
GetProcAddress
ExitProcess
GetModuleHandleW
BuildCommDCBAndTimeoutsA
KERNEL32.dll
UnhandledExceptionFilter
SetUnhandledExceptionFilter
TerminateProcess
IsProcessorFeaturePresent
QueryPerformanceCounter
GetCurrentProcessId
GetCurrentThreadId
GetSystemTimeAsFileTime
InitializeSListHead
IsDebuggerPresent
GetStartupInfoW
RtlUnwind
RaiseException
GetLastError
SetLastError
EncodePointer
EnterCriticalSection
LeaveCriticalSection
DeleteCriticalSection
InitializeCriticalSectionAndSpinCount
TlsAlloc
TlsGetValue
TlsSetValue
TlsFree
FreeLibrary
LoadLibraryExW
GetStdHandle
WriteFile
GetModuleFileNameW
GetModuleHandleExW
HeapFree
HeapAlloc
FindClose
FindFirstFileExW
FindNextFileW
IsValidCodePage
GetACP
GetOEMCP
GetCPInfo
GetCommandLineA
GetCommandLineW
MultiByteToWideChar
WideCharToMultiByte
GetEnvironmentStringsW
FreeEnvironmentStringsW
SetStdHandle
GetFileType
GetStringTypeW
LCMapStringW
GetProcessHeap
HeapSize
HeapReAlloc
FlushFileBuffers
GetConsoleOutputCP
GetConsoleMode
SetFilePointerEx
CreateFileW
CloseHandle
WriteConsoleW
DecodePointer
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
.?AVlogic_error@std@@
.?AVlength_error@std@@
.?AVbad_exception@std@@
.?AVbad_alloc@std@@
.?AVexception@std@@
.?AVbad_array_new_length@std@@
.?AVtype_info@@
<?xml version='1.0' encoding='UTF-8' standalone='yes'?>
<assembly xmlns='urn:schemas-microsoft-com:asm.v1' manifestVersion='1.0'>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v3">
<security>
<requestedPrivileges>
<requestedExecutionLevel level='asInvoker' uiAccess='false' />
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
PADPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADD
4;4O5t5
5686_6x6
6"8V8e8y8
:V:e:y:
:);6;&<5<I<]<n<
>!>2>F>
0/0@0T0
6F6U6i6}6
=$=e=r=
0?1R1m1
3'383S4
8'9F9a9w9
;0;5;:;[;`;m;
=)=2=7===G=Q=a=q=
0+040A0W0
2%2X2v2
3!3&393M3R3e3
5<5E5N5\5e5
=7=?=Q=^=
000:0D0R0m0~0
9Y9q9w9
>U>a>z?
0F0Z0l0
1'141=1B1G1b1l1x1}1
8g8U9_9l9
98:[:b:|:
:4<J<d<r<~<
<D=N=S=Y=
$0Q0X0
2 2+262H2Q2
3T3a3p3
465>5H5Q5b5t5
5,696R6W6`6
;";[;p;{;
21282Y2
3-3B3R3_3
4&474A4c4t4
5'555<5B5]5d5
7'7m7s7
1$161w1
2%2R2|2
6Y6-7G7
8"898O8
8%9.9G9
;E;W;i;{;
<><P<b<t<
3+3G3U3a3m3
3*4B4R4f4k4p4
5$5)5.5I5X5c5h5m5
6=6a6x6}6
6G7N7X7|7
99:B:Z:
>,>O>j>w>
0g3D4K4}4
=3=d=j=
2;2[2f2t2
203O3a3k3
5*5Q5p5,6\6v6
9B9c9j9
:M;_;q;
>M?l?x?
4 4.4a4
56$6i6q6y6
717=7I7i7
8*8=9n9
=k=l>|>
?(?.?7?q?
0\0e0n0w0
6*6@6H6
1$1014181<1@1D1P1T1X1p1t1x1|1
2 2(20282@2H2P2X2`2h2p2x2
3 3(30383@3H3P3X3`3h3p3x3
4 4(40484@4H4P4X4`4h4p4x4
5 5(50585@5H5P5X5`5h5p5
>p?t?x?|?
0 0$0(0,0004080<0@0D0H0L0P0T0X0d0h0l0p0t0x0|0
0$0,040<0D0L0T0\0d0l0t0|0
1$1,141<1D1L1T1\1d1l1t1|1
2$2,242<2D2L2T2\2d2l2t2|2
3$3,343<3D3L3T3\3d3l3t3|3
4$4,444<4D4L4T4\4d4l4t4|4
5$5,545<5D5L5T5\5d5l5t5|5
6$6,646<6D6L6T6\6d6l6t6|6
1 1(10181@1H1P1X1`1h1p1x1
2 2(20282@2H2P2X2`2h2p2x2
3 3(30383@3H3P3X3`3h3p3x3
4 4(40484@4H4P4X4`4h4p4x4
5 5(50585@5H5P5X5`5h5p5x5
6 6(60686@6H6P6X6`6h6p6x6
7 7(70787@7H7P7X7`7h7p7x7
;$;,;4;<;D;L;T;\;d;l;t;|;
:,:0:4:8:@:X:h:l:|:
; ;8;<;T;X;l;|;
0$0,040@0`0h0p0|0
1,141<1D1L1T1\1h1
2 2(20282H2l2t2|2
3$3,343<3D3L3T3\3`3h3|3
484@4D4`4h4l4|4
5$585X5t5x5
686X6x6
787X7x7
84888X8x8
686<6H6L6P6T6X6\6`6d6h6l6x6|6
1xVDTB
.xqM6F
Washington1
Redmond1
Microsoft Corporation1.0,
%Microsoft Windows Production PCA 20110
190327192124Z
200327192124Z0z1
Washington1
Redmond1
Microsoft Corporation1$0"
Microsoft Windows Publisher0
<J1qr!
E0C1)0'
Microsoft Operations Puerto Rico1
230280+4534480
Chttp://www.microsoft.com/pkiops/crl/MicWinProPCA2011_2011-10-19.crl0a
Ehttp://www.microsoft.com/pkiops/certs/MicWinProPCA2011_2011-10-19.crt0
g=U>Oq
MVh#S{EJ
Washington1
Redmond1
Microsoft Corporation1200
)Microsoft Root Certificate Authority 20100
111019184142Z
261019185142Z0
Washington1
Redmond1
Microsoft Corporation1.0,
%Microsoft Windows Production PCA 20110
i%(\6
Ehttp://crl.microsoft.com/pki/crl/products/MicRooCerAut_2010-06-23.crl0Z
>http://www.microsoft.com/pki/certs/MicRooCerAut_2010-06-23.crt0
Washington1
Redmond1
Microsoft Corporation1.0,
%Microsoft Windows Production PCA 2011
http://www.microsoft.com0
20190925020445.786Z0
Washington1
Redmond1
Microsoft Corporation1)0'
Microsoft Operations Puerto Rico1&0$
Thales TSS ESN:728D-C45F-F9EB1%0#
Microsoft Time-Stamp Service
Washington1
Redmond1
Microsoft Corporation1&0$
Microsoft Time-Stamp PCA 20100
190906204118Z
201204204118Z0
Washington1
Redmond1
Microsoft Corporation1)0'
Microsoft Operations Puerto Rico1&0$
Thales TSS ESN:728D-C45F-F9EB1%0#
Microsoft Time-Stamp Service0
Cu`Svh
Ehttp://crl.microsoft.com/pki/crl/products/MicTimStaPCA_2010-07-01.crl0Z
>http://www.microsoft.com/pki/certs/MicTimStaPCA_2010-07-01.crt0
/GFwl
Washington1
Redmond1
Microsoft Corporation1200
)Microsoft Root Certificate Authority 20100
100701213655Z
250701214655Z0|1
Washington1
Redmond1
Microsoft Corporation1&0$
Microsoft Time-Stamp PCA 20100
$`2X`F
Ehttp://crl.microsoft.com/pki/crl/products/MicRooCerAut_2010-06-23.crl0Z
>http://www.microsoft.com/pki/certs/MicRooCerAut_2010-06-23.crt0
1http://www.microsoft.com/PKI/docs/CPS/default.htm0@
oK0D$"<
r~akow
Washington1
Redmond1
Microsoft Corporation1)0'
Microsoft Operations Puerto Rico1&0$
Thales TSS ESN:728D-C45F-F9EB1%0#
Microsoft Time-Stamp Service
Washington1
Redmond1
Microsoft Corporation1)0'
Microsoft Operations Puerto Rico1'0%
nCipher NTS ESN:4DE9-0C5E-3E091+0)
"Microsoft Time Source Master Clock0
20190925005635Z
20190926005635Z0w0=
Washington1
Redmond1
Microsoft Corporation1&0$
Microsoft Time-Stamp PCA 2010
Washington1
Redmond1
Microsoft Corporation1&0$
Microsoft Time-Stamp PCA 2010
psnNg/
Aapi-ms-win-core-fibers-l1-1-1
api-ms-win-core-synch-l1-2-0
kernel32
api-ms-
mscoree.dll
Aja-JP
Sunday
Monday
Tuesday
Wednesday
Thursday
Friday
Saturday
January
February
August
September
October
November
December
MM/dd/yy
dddd, MMMM dd, yyyy
HH:mm:ss
((((( H
Aapi-ms-win-core-datetime-l1-1-1
api-ms-win-core-file-l1-2-2
api-ms-win-core-localization-l1-2-1
api-ms-win-core-localization-obsolete-l1-2-0
api-ms-win-core-processthreads-l1-1-2
api-ms-win-core-string-l1-1-0
api-ms-win-core-sysinfo-l1-2-1
api-ms-win-core-winrt-l1-1-0
api-ms-win-core-xstate-l2-1-0
api-ms-win-rtcore-ntuser-window-l1-1-0
api-ms-win-security-systemfunctions-l1-1-0
ext-ms-win-ntuser-dialogbox-l1-1-0
ext-ms-win-ntuser-windowstation-l1-1-0
advapi32
api-ms-win-appmodel-runtime-l1-1-2
user32
ext-ms-
zh-CHS
az-AZ-Latn
uz-UZ-Latn
kok-IN
syr-SY
div-MV
quz-BO
sr-SP-Latn
az-AZ-Cyrl
uz-UZ-Cyrl
quz-EC
sr-SP-Cyrl
quz-PE
smj-NO
bs-BA-Latn
smj-SE
sr-BA-Latn
sma-NO
sr-BA-Cyrl
sma-SE
sms-FI
smn-FI
zh-CHT
az-az-cyrl
az-az-latn
bs-ba-latn
div-mv
kok-in
quz-bo
quz-ec
quz-pe
sma-no
sma-se
smj-no
smj-se
smn-fi
sms-fi
sr-ba-cyrl
sr-ba-latn
sr-sp-cyrl
sr-sp-latn
syr-sy
uz-uz-cyrl
uz-uz-latn
zh-chs
zh-cht
CONOUT$
Dialog
MS Shell Dlg
Static
SysTabControl32
SysIPAddress32
SysIPAddress32
SysTabControl32
Custom1
MfcEditBrowse
VS_VERSION_INFO
StringFileInfo
040904b0
CompanyName
Greening
FileDescription
Greener
FileVersion
4.4.2.2
InternalName
green.exe
LegalCopyright
Copyright (C) 2021
OriginalFilename
green.exe
ProductName
Greener
ProductVersion
4.4.2.2
VarFileInfo
Translation
Microsof
Legal_Policy_Statement
No antivirus signatures available.
No IRMA results available.