Static | ZeroBOX

PE Compile Time

2024-01-06 23:25:57

PE Imphash

e59ba20e52010294e2c6cec0f9607820

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x0036d553 0x0036d600 6.01386026157
.rdata 0x0036f000 0x00005fa8 0x00006000 4.85880233577
.data 0x00375000 0x000013b8 0x00000a00 2.48591016037
.reloc 0x00377000 0x000010ac 0x00001200 6.25177765824
.rsrc 0x00379000 0x00006216 0x00006400 5.61264103599

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x0037cbe8 0x000025ee LANG_NEUTRAL SUBLANG_NEUTRAL PNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced
RT_ICON 0x0037cbe8 0x000025ee LANG_NEUTRAL SUBLANG_NEUTRAL PNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced
RT_ICON 0x0037cbe8 0x000025ee LANG_NEUTRAL SUBLANG_NEUTRAL PNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced
RT_ICON 0x0037cbe8 0x000025ee LANG_NEUTRAL SUBLANG_NEUTRAL PNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced
RT_GROUP_ICON 0x0037f1d8 0x0000003e LANG_NEUTRAL SUBLANG_NEUTRAL data

Imports

Library USER32.dll:
0x76f124 CreateWindowExA
0x76f128 GetMessageA
Library KERNEL32.dll:
0x76f000 GetModuleFileNameW
0x76f004 WriteConsoleW
0x76f008 CloseHandle
0x76f00c GetTempPathA
0x76f010 TlsAlloc
0x76f014 TlsSetValue
0x76f018 FreeLibrary
0x76f01c GetModuleHandleA
0x76f020 GetProcAddress
0x76f024 LoadLibraryA
0x76f028 CreateActCtxA
0x76f02c ActivateActCtx
0x76f030 FreeConsole
0x76f038 GetCurrentProcessId
0x76f03c GetCurrentThreadId
0x76f044 InitializeSListHead
0x76f048 IsDebuggerPresent
0x76f054 GetStartupInfoW
0x76f05c GetModuleHandleW
0x76f060 GetCurrentProcess
0x76f064 TerminateProcess
0x76f068 CreateFileW
0x76f06c RtlUnwind
0x76f070 GetLastError
0x76f074 SetLastError
0x76f088 TlsGetValue
0x76f08c TlsFree
0x76f090 LoadLibraryExW
0x76f094 EncodePointer
0x76f098 RaiseException
0x76f09c ExitProcess
0x76f0a0 GetModuleHandleExW
0x76f0a4 GetStdHandle
0x76f0a8 WriteFile
0x76f0ac DecodePointer
0x76f0b0 GetCommandLineA
0x76f0b4 GetCommandLineW
0x76f0b8 HeapAlloc
0x76f0bc HeapFree
0x76f0c0 FindClose
0x76f0c4 FindFirstFileExW
0x76f0c8 FindNextFileW
0x76f0cc IsValidCodePage
0x76f0d0 GetACP
0x76f0d4 GetOEMCP
0x76f0d8 GetCPInfo
0x76f0dc MultiByteToWideChar
0x76f0e0 WideCharToMultiByte
0x76f0f0 SetStdHandle
0x76f0f4 GetFileType
0x76f0f8 GetStringTypeW
0x76f0fc CompareStringW
0x76f100 LCMapStringW
0x76f104 GetProcessHeap
0x76f108 HeapSize
0x76f10c HeapReAlloc
0x76f110 FlushFileBuffers
0x76f114 GetConsoleOutputCP
0x76f118 GetConsoleMode
0x76f11c SetFilePointerEx

!This program cannot be run in DOS mode.
RichO
`.rdata
@.data
.reloc
B.rsrc
URPQQh
UQPXY]Y[
QQSVWd
uSSSSj
f9:t!V
QQSVj8j@
xg;5pbw
j(hxGw
PPPPPPPP
PPPPPWV
PP9E uPPSWP
xE;5pbw
PVVVVV
xK;5pbw
__based(
__cdecl
__pascal
__stdcall
__thiscall
__fastcall
__vectorcall
__clrcall
__eabi
__swift_1
__swift_2
__swift_3
__ptr64
__restrict
__unaligned
restrict(
delete
operator
`vftable'
`vbtable'
`vcall'
`typeof'
`local static guard'
`string'
`vbase destructor'
`vector deleting destructor'
`default constructor closure'
`scalar deleting destructor'
`vector constructor iterator'
`vector destructor iterator'
`vector vbase constructor iterator'
`virtual displacement map'
`eh vector constructor iterator'
`eh vector destructor iterator'
`eh vector vbase constructor iterator'
`copy constructor closure'
`udt returning'
`local vftable'
`local vftable constructor closure'
new[]
delete[]
`omni callsig'
`placement delete closure'
`placement delete[] closure'
`managed vector constructor iterator'
`managed vector destructor iterator'
`eh vector copy constructor iterator'
`eh vector vbase copy constructor iterator'
`dynamic initializer for '
`dynamic atexit destructor for '
`vector copy constructor iterator'
`vector vbase copy constructor iterator'
`managed vector copy constructor iterator'
`local static thread guard'
operator ""
operator co_await
operator<=>
Type Descriptor'
Base Class Descriptor at (
Base Class Array'
Class Hierarchy Descriptor'
Complete Object Locator'
`anonymous namespace'
FlsAlloc
FlsFree
FlsGetValue
FlsSetValue
InitializeCriticalSectionEx
Unknown exception
bad exception
CorExitProcess
Sunday
Monday
Tuesday
Wednesday
Thursday
Friday
Saturday
January
February
August
September
October
November
December
MM/dd/yy
dddd, MMMM dd, yyyy
HH:mm:ss
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
AreFileApisANSI
CompareStringEx
LCMapStringEx
LocaleNameToLCID
AppPolicyGetProcessTerminationMethod
?5Wg4p
%S#[k=
"B <1=
_hypot
_nextafter
.text$mn
.text$x
.idata$5
.00cfg
.CRT$XCA
.CRT$XCAA
.CRT$XCZ
.CRT$XIA
.CRT$XIAA
.CRT$XIAC
.CRT$XIC
.CRT$XIZ
.CRT$XPA
.CRT$XPX
.CRT$XPXA
.CRT$XPZ
.CRT$XTA
.CRT$XTZ
.rdata
.rdata$r
.rdata$sxdata
.rdata$voltmd
.rdata$zzzdbg
.rtc$IAA
.rtc$IZZ
.rtc$TAA
.rtc$TZZ
.xdata$x
.idata$2
.idata$3
.idata$4
.idata$6
.data$r
.data$rs
GetMessageA
CreateWindowExA
USER32.dll
GetTempPathA
TlsAlloc
TlsSetValue
FreeLibrary
GetModuleHandleA
GetProcAddress
LoadLibraryA
CreateActCtxA
ActivateActCtx
FreeConsole
QueryPerformanceCounter
GetCurrentProcessId
GetCurrentThreadId
GetSystemTimeAsFileTime
InitializeSListHead
IsDebuggerPresent
UnhandledExceptionFilter
SetUnhandledExceptionFilter
GetStartupInfoW
IsProcessorFeaturePresent
GetModuleHandleW
GetCurrentProcess
TerminateProcess
KERNEL32.dll
RtlUnwind
GetLastError
SetLastError
EnterCriticalSection
LeaveCriticalSection
DeleteCriticalSection
InitializeCriticalSectionAndSpinCount
TlsGetValue
TlsFree
LoadLibraryExW
EncodePointer
RaiseException
ExitProcess
GetModuleHandleExW
GetStdHandle
WriteFile
GetModuleFileNameW
GetCommandLineA
GetCommandLineW
HeapAlloc
HeapFree
FindClose
FindFirstFileExW
FindNextFileW
IsValidCodePage
GetACP
GetOEMCP
GetCPInfo
MultiByteToWideChar
WideCharToMultiByte
GetEnvironmentStringsW
FreeEnvironmentStringsW
SetEnvironmentVariableW
SetStdHandle
GetFileType
GetStringTypeW
CompareStringW
LCMapStringW
GetProcessHeap
HeapSize
HeapReAlloc
FlushFileBuffers
GetConsoleOutputCP
GetConsoleMode
SetFilePointerEx
CreateFileW
CloseHandle
WriteConsoleW
DecodePointer
qqLbUra
fHpEgHQdGeSIEvTh
WfIpjxGcwzlDpFpteS
mbWUrFDnNzCyl
IaoMtHTuTVmT
cObyJBpzFLxySZRYZ
CRHnJhHPkPSYX
PdchBbHuMYdOSrysggqoNuCzi
lGDQBibmxkDy
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
.?AVbad_exception@std@@
.?AVexception@std@@
.?AVtype_info@@
>!?H?k?
6&7G7i7
7,<S<}<
7*7/747U7Z7g7
: ;/;8;E;[;
<=)=I=
> >%>8>Q>n>
? ?'?/?7???K?T?Y?_?i?s?
0.171@1N1W1y1
8G8O8a8n8
>!>'>B>j>~>
?0?>?E?K?c?s?
0"0B0L0X0t0
1(14191>1\1f1r1w1|1
=E>]>c>s>
455A5O5b5k5x5
797G7`7h7q7z7
8M9f9y9
9H:W:`:n:
=3===v=}=
>5?P?g?u?
0Z0f0k0q0v0~0
394b4r4
5#5=5v5
6#64696
8:%:Q:W:b:
;$;2;9;?;Z;a;
?K?Z?l?
0$0H0O0n0
1A1V1f1s1
484?4R4
4s5%6f6
:(;u;};
60=0D0K0e0t0~0
4"444u4
5#5S5}5
:7;E;M;^;l;s;7<
> ?/?=?Z?b?
3.3@3R3d3v3
7"8L8|8
:#:(:8:=:B:j:
;);2;;;l;
;0<T<d<i<n<
=!=&=+=I=X=c=h=m=
=>6>?>V>h>t>
50S0\0b0
04191>1C1L1i2r2
6#6/6;6I6Y6n6
7!779z;
8H9N9[9
<i<.=t=
5I5j5q5
6T7f7x7R9
0'040d0
414A40666;6B6R6`6q6
8W8a8|8
8)91999A9I9g9o9
+0,1<1M1U1e1v1
112@2L2[2n2
3%3.373b3
1;1O1U1
01<1H1L1P1T1X1\1h1l1p1
2 2(20282@2H2P2X2`2h2p2x2
3 3(30383@3H3P3X3`3h3p3x3
4 4(40484@4H4P4X4`4h4p4x4
5D;H;L;\<`<d<|<
<`=h=p=t=x=|=
=H?L?P?T?
0 0$0(0,000<0@0D0H0L0P0T0X0\0`0d0h0l0p0t0x0|0
0P:T:X:\:`:d:h:l:p:t:x:|:
0$0,040<0D0L0T0\0d0l0t0|0
1$1,141<1D1L1T1\1d1l1t1|1
2$2,242<2D2L2T2\2d2l2t2|2
3$3,343<3D3L3T3\3d3l3t3|3
4$4,444<4D4L4T4\4d4l4t4|4
5$5,545<5D5L5T5\5d5l5t5|5
6$6,646<6D6L6T6\6d6l6t6|6
0181@1H1P1X1`1h1p1x1
2 2(20282@2H2P2X2`2h2p2x2
3 3(30383@3H3P3X3`3h3p3x3
4 4(40484@4H4P4X4`4h4p4x4
5 5(50585@5H5P5X5`5h5p5x5
6 6(60686@6H6P6X6`6h6p6x6
7 7(70787@7H7P7X7`7h7p7x7
8 8(80888@8H8
Z2^2b2f2\;d;l;t;|;
<$<,<4<<<
<L=P=X=
> >$>,>D>T>X>h>l>p>x>
L3P3l3p3
4$4,4T4X4t4x4
54585X5`5h5t5
6,606P6p6
707P7p7
808P8l8p8
6P6`6p6
7 7$7(7,70747 9@9\9
5.]N%99
zUqs+R
Hos+*V(#;
BrwwcXh7
9UM~'V
eGQ4,bS4
fueGQt
R,]2\M~Es
o@(LX
d(#F-&
re=ywT
3o=7nd
23-DH8
:p~*V(
c(N.>!
DigiCert Inc1
www.digicert.com1+0)
"DigiCert High Assurance EV Root CA0
220113000000Z
311109235959Z0b1
DigiCert Inc1
www.digicert.com1!0
DigiCert Trusted Root G40
]J<0"0i3
v=Y]Bv
http://ocsp.digicert.com0I
=http://cacerts.digicert.com/DigiCertHighAssuranceEVRootCA.crt0K
:http://crl3.digicert.com/DigiCertHighAssuranceEVRootCA.crl0
f(Ob1
DigiCert Inc1
www.digicert.com1!0
DigiCert Trusted Root G40
210429000000Z
360428235959Z0i1
DigiCert, Inc.1A0?
8DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA10
[K]taM?
SA|X=G
http://ocsp.digicert.com0A
5http://cacerts.digicert.com/DigiCertTrustedRootG4.crt0C
2http://crl3.digicert.com/DigiCertTrustedRootG4.crl0
jj@0HK4
DigiCert, Inc.1A0?
8DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA10
211117000000Z
240131235959Z0
Baden-W
rttemberg1
ppingen1 0
TeamViewer Germany GmbH1 0
TeamViewer Germany GmbH0
TGLxe\
Mhttp://crl3.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crl0S
Mhttp://crl4.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crl0>
http://www.digicert.com/CPS0
http://ocsp.digicert.com0\
Phttp://cacerts.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crt0
&xX:/@
DigiCert, Inc.1A0?
8DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1
http://www.teamviewer.com 0
+36\n3
20231018180323Z
DigiCert, Inc.1;09
2DigiCert Trusted G4 RSA4096 SHA256 TimeStamping CA0
230714000000Z
341013235959Z0H1
DigiCert, Inc.1 0
DigiCert Timestamp 20230
Ihttp://crl3.digicert.com/DigiCertTrustedG4RSA4096SHA256TimeStampingCA.crl0
http://ocsp.digicert.com0X
Lhttp://cacerts.digicert.com/DigiCertTrustedG4RSA4096SHA256TimeStampingCA.crt0
l2|X/gGe
(f*^[0
DigiCert Inc1
www.digicert.com1!0
DigiCert Trusted Root G40
220323000000Z
370322235959Z0c1
DigiCert, Inc.1;09
2DigiCert Trusted G4 RSA4096 SHA256 TimeStamping CA0
http://ocsp.digicert.com0A
5http://cacerts.digicert.com/DigiCertTrustedRootG4.crt0C
2http://crl3.digicert.com/DigiCertTrustedRootG4.crl0
DigiCert Inc1
www.digicert.com1$0"
DigiCert Assured ID Root CA0
220801000000Z
311109235959Z0b1
DigiCert Inc1
www.digicert.com1!0
DigiCert Trusted Root G40
]J<0"0i3
v=Y]Bv
http://ocsp.digicert.com0C
7http://cacerts.digicert.com/DigiCertAssuredIDRootCA.crt0E
4http://crl3.digicert.com/DigiCertAssuredIDRootCA.crl0
~qj#k"
DigiCert, Inc.1;09
2DigiCert Trusted G4 RSA4096 SHA256 TimeStamping CA
231018180323Z0+
/1(0&0$0"
@WhA6o
k8"NA
jjjjjjjjh
vapi-ms-win-core-fibers-l1-1-1
api-ms-win-core-synch-l1-2-0
kernel32
api-ms-
mscoree.dll
vja-JP
Sunday
Monday
Tuesday
Wednesday
Thursday
Friday
Saturday
January
February
August
September
October
November
December
MM/dd/yy
dddd, MMMM dd, yyyy
HH:mm:ss
((((( H
wapi-ms-win-core-datetime-l1-1-1
api-ms-win-core-file-l1-2-4
api-ms-win-core-file-l1-2-2
api-ms-win-core-localization-l1-2-1
api-ms-win-core-localization-obsolete-l1-2-0
api-ms-win-core-processthreads-l1-1-2
api-ms-win-core-string-l1-1-0
api-ms-win-core-sysinfo-l1-2-1
api-ms-win-core-winrt-l1-1-0
api-ms-win-core-xstate-l2-1-0
api-ms-win-rtcore-ntuser-window-l1-1-0
api-ms-win-security-systemfunctions-l1-1-0
ext-ms-win-ntuser-dialogbox-l1-1-0
ext-ms-win-ntuser-windowstation-l1-1-0
advapi32
kernelbase
api-ms-win-appmodel-runtime-l1-1-2
user32
api-ms-win-core-fibers-l1-1-0
ext-ms-
zh-CHS
az-AZ-Latn
uz-UZ-Latn
kok-IN
syr-SY
div-MV
quz-BO
sr-SP-Latn
az-AZ-Cyrl
uz-UZ-Cyrl
quz-EC
sr-SP-Cyrl
quz-PE
smj-NO
bs-BA-Latn
smj-SE
sr-BA-Latn
sma-NO
sr-BA-Cyrl
sma-SE
sms-FI
smn-FI
zh-CHT
az-az-cyrl
az-az-latn
bs-ba-latn
div-mv
kok-in
quz-bo
quz-ec
quz-pe
sma-no
sma-se
smj-no
smj-se
smn-fi
sms-fi
sr-ba-cyrl
sr-ba-latn
sr-sp-cyrl
sr-sp-latn
syr-sy
uz-uz-cyrl
uz-uz-latn
zh-chs
zh-cht
CONOUT$
TeamViewe
No antivirus signatures available.
No IRMA results available.