Static | ZeroBOX

PE Compile Time

2022-12-08 03:51:13

PE Imphash

b2c192dde66d798d732cf15b9e7a6998

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x0000fc83 0x0000fe00 6.64831376135
.rdata 0x00011000 0x00034ea2 0x00035000 7.2751254672
.data 0x00046000 0x001043e4 0x00002c00 1.87842224454
.rsrc 0x0014b000 0x00007ab8 0x00007c00 5.34152445721

Resources

Name Offset Size Language Sub-language File type
AFX_DIALOG_LAYOUT 0x00150c68 0x00000002 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_CURSOR 0x00151c80 0x00000134 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_CURSOR 0x00151c80 0x00000134 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_CURSOR 0x00151c80 0x00000134 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_ICON 0x00150770 0x00000468 LANG_SPANISH SUBLANG_SPANISH_PERU GLS_BINARY_LSB_FIRST
RT_ICON 0x00150770 0x00000468 LANG_SPANISH SUBLANG_SPANISH_PERU GLS_BINARY_LSB_FIRST
RT_ICON 0x00150770 0x00000468 LANG_SPANISH SUBLANG_SPANISH_PERU GLS_BINARY_LSB_FIRST
RT_ICON 0x00150770 0x00000468 LANG_SPANISH SUBLANG_SPANISH_PERU GLS_BINARY_LSB_FIRST
RT_ICON 0x00150770 0x00000468 LANG_SPANISH SUBLANG_SPANISH_PERU GLS_BINARY_LSB_FIRST
RT_ICON 0x00150770 0x00000468 LANG_SPANISH SUBLANG_SPANISH_PERU GLS_BINARY_LSB_FIRST
RT_ICON 0x00150770 0x00000468 LANG_SPANISH SUBLANG_SPANISH_PERU GLS_BINARY_LSB_FIRST
RT_STRING 0x001526d8 0x000003e0 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_STRING 0x001526d8 0x000003e0 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_STRING 0x001526d8 0x000003e0 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_ACCELERATOR 0x00150c40 0x00000028 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_GROUP_CURSOR 0x00151db8 0x00000014 LANG_NEUTRAL SUBLANG_NEUTRAL Lotus unknown worksheet or configuration, revision 0x1
RT_GROUP_CURSOR 0x00151db8 0x00000014 LANG_NEUTRAL SUBLANG_NEUTRAL Lotus unknown worksheet or configuration, revision 0x1
RT_GROUP_CURSOR 0x00151db8 0x00000014 LANG_NEUTRAL SUBLANG_NEUTRAL Lotus unknown worksheet or configuration, revision 0x1
RT_GROUP_ICON 0x00150bd8 0x00000068 LANG_SPANISH SUBLANG_SPANISH_PERU data
RT_VERSION 0x00151dd0 0x000001f0 LANG_NEUTRAL SUBLANG_NEUTRAL MS Windows COFF PowerPC object file

Imports

Library KERNEL32.dll:
0x411004 DebugActiveProcess
0x411008 GetDateFormatW
0x41100c CreateFileA
0x411018 HeapAlloc
0x411020 HeapFree
0x411024 CreateHardLinkA
0x411028 ConnectNamedPipe
0x41102c GetModuleHandleW
0x411030 ReadConsoleOutputA
0x411034 GlobalAlloc
0x411038 GlobalFindAtomA
0x41103c LoadLibraryW
0x411040 GetLocaleInfoW
0x411048 GetFileAttributesA
0x41104c lstrcpynW
0x411050 GetAtomNameW
0x411054 LocalHandle
0x411058 GetModuleFileNameW
0x411060 SetConsoleTitleA
0x411068 GetThreadLocale
0x41106c GetProcAddress
0x411070 SetComputerNameA
0x411074 SetCalendarInfoW
0x411080 SetSystemTime
0x411084 SetConsoleTitleW
0x411088 HeapSetInformation
0x41108c VirtualProtect
0x411098 FindAtomW
0x41109c CreateFileW
0x4110a0 ReadFile
0x4110a4 FlushFileBuffers
0x4110a8 EncodePointer
0x4110ac DecodePointer
0x4110b0 ExitProcess
0x4110b4 GetCommandLineW
0x4110b8 GetStartupInfoW
0x4110bc RaiseException
0x4110c0 TerminateProcess
0x4110c4 GetCurrentProcess
0x4110d0 IsDebuggerPresent
0x4110d4 GetLastError
0x4110dc WriteFile
0x4110e0 GetStdHandle
0x4110e4 HeapCreate
0x4110f0 Sleep
0x4110f4 HeapSize
0x4110fc TlsAlloc
0x411100 TlsGetValue
0x411104 TlsSetValue
0x411108 TlsFree
0x41110c SetLastError
0x411110 GetCurrentThreadId
0x411120 SetHandleCount
0x411124 GetFileType
0x41112c GetTickCount
0x411130 GetCurrentProcessId
0x411138 SetFilePointer
0x41113c WideCharToMultiByte
0x411140 GetConsoleCP
0x411144 GetConsoleMode
0x411148 GetCPInfo
0x41114c GetACP
0x411150 GetOEMCP
0x411154 IsValidCodePage
0x411158 RtlUnwind
0x41115c MultiByteToWideChar
0x411160 HeapReAlloc
0x411164 SetStdHandle
0x411168 WriteConsoleW
0x41116c LCMapStringW
0x411170 GetStringTypeW
0x411174 CloseHandle
Library USER32.dll:
0x41117c GetMonitorInfoW
0x411180 LoadIconA
0x411184 CopyRect
Library WINHTTP.dll:
0x41118c WinHttpCloseHandle

!This program cannot be run in DOS mode.
`.rdata
@.data
;D$$tb;
uTVWh7c@
HHtXHHt
?If90t
^SSSSS
r=`dD
Y;=xmD
QQSVWh
j@j ^V
URPQQh
t"SS9] u
;t$,v-
UQPXY]Y[
PPPPPPPP
PPPPPPPP
T$ Rj@PQ
L$$Qh@HD
QQSVWd
t=MOC
HtHu4j
t*=RCC
;7|G;p
tR99u2
tRHtCHt4Ht%HtFHHt
<+t"<-t
+t HHt
u-hLJD
Unknown exception
CorExitProcess
bad allocation
(null)
`h````
xpxxxx
FlsFree
FlsSetValue
FlsGetValue
FlsAlloc
HH:mm:ss
dddd, MMMM dd, yyyy
MM/dd/yy
December
November
October
September
August
February
January
Saturday
Friday
Thursday
Wednesday
Tuesday
Monday
Sunday
`h`hhh
xppwpp
GetProcessWindowStation
GetUserObjectInformationW
GetLastActivePopup
GetActiveWindow
MessageBoxW
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
Complete Object Locator'
Class Hierarchy Descriptor'
Base Class Array'
Base Class Descriptor at (
Type Descriptor'
`local static thread guard'
`managed vector copy constructor iterator'
`vector vbase copy constructor iterator'
`vector copy constructor iterator'
`dynamic atexit destructor for '
`dynamic initializer for '
`eh vector vbase copy constructor iterator'
`eh vector copy constructor iterator'
`managed vector destructor iterator'
`managed vector constructor iterator'
`placement delete[] closure'
`placement delete closure'
`omni callsig'
delete[]
new[]
`local vftable constructor closure'
`local vftable'
`udt returning'
`copy constructor closure'
`eh vector vbase constructor iterator'
`eh vector destructor iterator'
`eh vector constructor iterator'
`virtual displacement map'
`vector vbase constructor iterator'
`vector destructor iterator'
`vector constructor iterator'
`scalar deleting destructor'
`default constructor closure'
`vector deleting destructor'
`vbase destructor'
`string'
`local static guard'
`typeof'
`vcall'
`vbtable'
`vftable'
operator
delete
__unaligned
__restrict
__ptr64
__eabi
__clrcall
__fastcall
__thiscall
__stdcall
__pascal
__cdecl
__based(
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
kzzMKd
)x{-[=
t}C+H!s
>"'.Q^
yZUb_7
1Kl[Ey
CE94Dx
^`i4[A
cz,H[-
/Oj*Ix
]:sEY$'
:JP u"6
G>9e[hq
a<x65/
s%A:Fy5f
?4(b;Le
~dFxnlH
YvR-Ef
4"]lrZ
oC<tp-
/x}6>Tf
T.`C&
W(D!ku
a-U.U6
t.Y0ZZ QyTu~
Mr##:Ns
Sh 9?*]T
}?n};))F"
<7a_16
d7BP0Y
.oiQHL
|@D\U4
[ZGWsx
B[xbQDs
szh92w
%4G9kz
cQ';~9^
@'A`q3
{kacg?
rQZ\)\
Bt0u*}
=Qrzp^X
T9zJ,+3
@6j5]b|
gv&Oa%
jY/ k~
$a>X{_
.5 mo+
H+rP0#
`Te<bq
yjC RY
yKI%G=
K80p+H
B+S7!1!(v
sX4okG
lR)|e`q
RNIO6f
|~>/z,
+!qFB0
M@03x~
)d")Zz#
&T<{^,
|:FKT1
2LBD}Y
o5D^Rx
IRo`;d>
#X| Sn
a%/peC0.1
@Q$?zK
2zRN@.
/kti9I
JF*-iy
X9K>[:qr
DC5BU#
KclR[#
N9M/hW
D/-b3R
="6UK?G><
~#|_~
78?f0_
1?X6ke
'~?zAT
^{)%!^
0[N|N_#j
!ay*fg
>ZNc)~
^RQnq
>7c)&+3Xe
DRymV
pUPtIy
RfAq('
M1qJ?/E
e+n_Gs
jJ! >^$i
=$UV:4lc
Kyd_%|
JE>{BA
QphHuSl
;)#Q=R8
BX#i_<_
^SRhe
'aP3V;
vud<~X
YVnRbp
8O6Oz^
CZMOo,
o\vV_8
]-i0ej
C/?b]I
G68Ki9
^{7-eh
V>9ah{3F'
;DOZ~Ml
2d`m]^/
.cTP1#
(MzMOJW
oD~|=/+
kw``n-
j[YNpj
]S1 0F
/=I1,Ni
1eK@hT
$7/#xc
B'p0Oz
Apc1A9
RM,aV[/.
SN' ,KkZ
plol%%%
S9*Xxf
=/ayG_
8)Wg%u
%fMRC@|B
ZcMQ?s
jd/lDU5
CO_OSXN1
[L;6p^
:1*6[
}u{+!j[
c]"pL(W
Bn^Zi>
h)3"w$uN
'wv[1i
Z=;TNk
+ =>IK
boSm0g
5L};Mm
8l$q,I
W.3,oK#
E!`>uq
pJ y"qW
b:4ZK3Y/;^
!\C(%5
b<H'9j
2SU<;N
<%]aFS
ONXY:z
-yMG/84
m4*^\U!
SiFY4M;
<.*5}n[
M_L9kr
+(ay+i
DsF]dg
!#LQ29X
B7!EFA
<^e=1c
@/Jz`n-
D<8M#K
HpfNKSQ
{18]NM
8)kKh>
bEN%L5g
^hN-F:
xPiHy!
Z?]syF.}
xyw>]f<
5i>\|t
V{_c8~
~4-8X\Sk
wvyxa
'LCc@Q5'Y
S56(JoL
G-~WRD
.u?Cr-#}F
QJ>sTG
+wcQj3e
NDU!_
uuZ^ n}"A
J[Y,a"
x%aDUz4
h6#5W{
-3$~p]
G\b+IP<7
:FXmPO
U<Xz!v
.Uoj6/
"*}1pc
yVwI]vq
<wUVecv
73(!+h
bf.{pa%V/F
jX!Sea
dELN$5T
P"Z_m-'
li,-.H
C)ZtjN
bA}ygS
(]E<rp
qAc'>_6
bOYfF#!
SzzAf8:
S1v#4B.1
il+E\V
JT/$su20
r][mEt{
;"|iDA
)51b'm
N?Ui*d
EKF`uB$fZ+
aMMl/
u<2\4:Sb
w.Oomg
bIuBf@
'=b0-U|
YC[zq]
s,3b![
0&^#Ml"
N+n)L\shi
bp>K$i
61"^rkJv
'9=*j>
1>C+,f0
%ZXGcK
C??@(
i.P=&:
'otmp)
"/iGGb
el#9Y>
f5X#Fv
(xx_cc
wJH!Ej
.Tb7@,
+Pyx<2
)Czgvr*
Wa~zT7
B?;@]v
I?ZV7g
!+YqBY
o~*eOc:b
&<_Rs]
TY:4)*
P!q|C>
R06==~
(xN:/%
w_1ST}'k:
]U3ScB
q |?VN>4!Ir
h{y}sa
eh\&q9
o{Ep~C
? ~"Xx
e@An/6
(snAZ~
?RS.p
?OH^a xa5
hZQahdzS
t\c[)R
[QNl|N
-:$=_:
UX*gN2
Ua9Kp[
45a&-n
q|~niS
BB{jEE
ramohucepusogisar
konimujakujixegayemegepon focubilimefemapasufaha
madedokecof
bohomecocomoxiwolepadewusavapexo
0 %s %d %f
vuyareyifovonij
invalid string position
vector<T> too long
string too long
bad exception
1#QNAN
1#SNAN
?_nextafter
_hypot
GetSystemDefaultLangID
DebugActiveProcess
GetDateFormatW
CreateFileA
GetConsoleAliasesLengthW
GetNumaProcessorNode
HeapAlloc
InterlockedIncrement
HeapFree
CreateHardLinkA
ConnectNamedPipe
GetModuleHandleW
ReadConsoleOutputA
GlobalAlloc
GlobalFindAtomA
LoadLibraryW
GetLocaleInfoW
GetConsoleAliasExesLengthW
GetFileAttributesA
lstrcpynW
GetAtomNameW
LocalHandle
GetModuleFileNameW
FindNextVolumeMountPointW
SetConsoleTitleA
WritePrivateProfileStringW
GetThreadLocale
GetProcAddress
SetComputerNameA
SetCalendarInfoW
SetConsoleDisplayMode
WaitForMultipleObjects
SetSystemTime
SetConsoleTitleW
HeapSetInformation
VirtualProtect
GetCurrentDirectoryA
DeleteCriticalSection
FindAtomW
KERNEL32.dll
CopyRect
GetMonitorInfoW
LoadIconA
USER32.dll
WinHttpCloseHandle
WinHttpAddRequestHeaders
WINHTTP.dll
EncodePointer
DecodePointer
ExitProcess
GetCommandLineW
GetStartupInfoW
RaiseException
TerminateProcess
GetCurrentProcess
UnhandledExceptionFilter
SetUnhandledExceptionFilter
IsDebuggerPresent
GetLastError
IsProcessorFeaturePresent
WriteFile
GetStdHandle
HeapCreate
EnterCriticalSection
LeaveCriticalSection
HeapSize
InitializeCriticalSectionAndSpinCount
TlsAlloc
TlsGetValue
TlsSetValue
TlsFree
SetLastError
GetCurrentThreadId
InterlockedDecrement
FreeEnvironmentStringsW
GetEnvironmentStringsW
SetHandleCount
GetFileType
QueryPerformanceCounter
GetTickCount
GetCurrentProcessId
GetSystemTimeAsFileTime
SetFilePointer
WideCharToMultiByte
GetConsoleCP
GetConsoleMode
GetCPInfo
GetACP
GetOEMCP
IsValidCodePage
RtlUnwind
MultiByteToWideChar
HeapReAlloc
SetStdHandle
WriteConsoleW
LCMapStringW
GetStringTypeW
FlushFileBuffers
ReadFile
CreateFileW
CloseHandle
.?AVlogic_error@std@@
.?AVlength_error@std@@
.?AVout_of_range@std@@
.?AVtype_info@@
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
.?AVexception@std@@
.?AVbad_alloc@std@@
.?AVbad_exception@std@@
FFnnF
Fnnnn
uzHHKKW
YoaqnF
```````````````````
ffffffffff
fffffffff
TTTTTTTTTiiiiiii0000
444444
4_tt_4
4Mtt_4
??^{44444444:Z
44G?&BB
444jG____{j444
4444444444
3~mmmmmmmmmmmmPl
_/mmmmm
$$$$$$$$
ppppppppppppppppppppppe
pppppp
pppppp
pppppp7
ppppppbL
/bpppppp:{{{{{{
pppppp
pppppp#D
*ppppppp
hpppppppppppppp?jpppp
pppppppp
$pppppppp
pppppppp
pppppppppp,ww
ppppppppppppppppppp
~{}{{{~
}^z|~b
iiiiii
iiiiii
iiiiiiiiiiii
iiiiiiiiii
iiiiii
iiiiiiiii
iiiiiiiiiiiii
iiiiiiii
jjjjjj
mscoree.dll
D(null)
runtime error
TLOSS error
SING error
DOMAIN error
- Attempt to use MSIL code from this assembly during native code initialization
This indicates a bug in your application. It is most likely the result of calling an MSIL-compiled (/clr) function from a native constructor or from DllMain.
- not enough space for locale information
- Attempt to initialize the CRT more than once.
This indicates a bug in your application.
- CRT not initialized
- unable to initialize heap
- not enough space for lowio initialization
- not enough space for stdio initialization
- pure virtual function call
- not enough space for _onexit/atexit table
- unable to open console device
- unexpected heap error
- unexpected multithread lock error
- not enough space for thread data
- abort() has been called
- not enough space for environment
- not enough space for arguments
- floating point support not loaded
AMicrosoft Visual C++ Runtime Library
<program name unknown>
Runtime Error!
Program:
KERNEL32.DLL
HH:mm:ss
dddd, MMMM dd, yyyy
MM/dd/yy
December
November
October
September
August
February
January
Saturday
Friday
Thursday
Wednesday
Tuesday
Monday
Sunday
WUSER32.DLL
((((( H
h(((( H
H
CONOUT$
tosomosetixajuyolumabor
kernel32.dll
msimg32.dll
jMekopakan keken vucav zah zopotirorimujok
AFX_DIALOG_LAYOUT
/ P6pL
,/KPip
/-P?pR
VS_VERSION_INFO
StringFileInform
040504E4
FileVersions
58.93.75.13
ProductVersion
95.83.76.15
InternalName
Slupido
LegalCopyrights
sadg asdfg
CompanyNames
VarFileInfo
Translation
^Nuvutubeziy yeyeverohafofaz yikuwezim xikifegaforehid biwofahifot yivemofunu mugepur raretofavONihi huxirowomusotum juje mel jotap joc ruyidaluwopewoh diguxafocuhamil wagagey
HTahisaviroyir yekohaciza tunavarule rulusatudoweka femepalu pixavinafeko
Vojeruzofazugi
TokanizicubukcGevaranujetegoj gajasiwixa niyukodabu kanoyuyelorera xix teteyid pikeniyuvu firo giturebekace nisel%Yibex biforiwokezo loj sayibavatixosa"Dewo facuwolubodij mofevidicojadiwZXuwefapijazuhes fahamidebexa kumato buso julomoxavevuy juhiyinuwamigap gexubezepe kosi woc
Fesakaz$Vofevok zexojosabez socoy pohoyuxari(Cufufem tapoyu ceruvaximuxeguv bupakugol
Zobogunerabimoc5Bafufecuco wawuc namiviro fisov nefib geyanileniwuvuf
Woyayerepi kiwabivaxaz
Vewefuj luse lilbRofihi woxovopivihuri gucopasape tumuzufogohu leceyojapajifil popajiceca mas ronamirazopux xotojac6Fegulubatiji focewute fusogajuwubabi cuxepireroxov biy
JogirKitozafomeyaz wisoxukoyudis lebacuboc tasuka vedozugacuvaz vimobiwisu hikanumiyoh nuwaget rohekavalenob gohagejigoAHobosaxuvenod fecesegol redacibulo nup zumawizicu momosazusokolat!Biyase ziji koruzuciwena gocehesa%Cehojinalu coy liceced nayayocujapala
Nigoyore nimogakaketufu
Rojocobiriwi
Pegavinaho:Nazug tazuy nidajofa hetakezayomul vubuhiy kij jox jitefav
4Dahalah lila keh yufuci lupi catiseya wuhofewavazatiHHacudahob tosuvihipo lada yonavelajucali nuvi sacacurev yukikotora pirom
No antivirus signatures available.
No IRMA results available.