Static | ZeroBOX

PE Compile Time

2024-06-07 17:05:11

PDB Path

C:\Users\Admin\Documents\Visual Studio 2008\Projects\dlll\x64\Release\dlll.pdb

PE Imphash

e6f4b2831e058a1d5a1ab6a3d70e5ee2

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x00008282 0x00008400 6.28320386687
.rdata 0x0000a000 0x00003264 0x00003400 5.00967082195
.data 0x0000e000 0x00002218 0x00001200 2.20663802269
.pdata 0x00011000 0x000007bc 0x00000800 4.36787657195
.rsrc 0x00012000 0x000001b4 0x00000200 5.09959333277
.reloc 0x00013000 0x000003aa 0x00000400 3.20300959154

Resources

Name Offset Size Language Sub-language File type
RT_MANIFEST 0x00012058 0x0000015a LANG_ENGLISH SUBLANG_ENGLISH_US ASCII text, with CRLF line terminators

Imports

Library KERNEL32.dll:
0x18000a000 GetProcAddress
0x18000a008 LoadLibraryA
0x18000a010 GetModuleHandleA
0x18000a018 GetCurrentThreadId
0x18000a020 FlsSetValue
0x18000a028 GetCommandLineA
0x18000a030 TerminateProcess
0x18000a038 GetCurrentProcess
0x18000a040 UnhandledExceptionFilter
0x18000a050 IsDebuggerPresent
0x18000a058 RtlVirtualUnwind
0x18000a060 RtlLookupFunctionEntry
0x18000a068 RtlCaptureContext
0x18000a070 HeapAlloc
0x18000a078 GetLastError
0x18000a080 HeapFree
0x18000a088 RaiseException
0x18000a090 RtlPcToFileHeader
0x18000a098 EncodePointer
0x18000a0a0 DecodePointer
0x18000a0a8 FlsGetValue
0x18000a0b0 FlsFree
0x18000a0b8 SetLastError
0x18000a0c0 FlsAlloc
0x18000a0c8 Sleep
0x18000a0d0 GetModuleHandleW
0x18000a0d8 ExitProcess
0x18000a0e0 SetHandleCount
0x18000a0e8 GetStdHandle
0x18000a0f0 GetFileType
0x18000a0f8 GetStartupInfoA
0x18000a100 DeleteCriticalSection
0x18000a108 GetModuleFileNameA
0x18000a110 FreeEnvironmentStringsA
0x18000a118 GetEnvironmentStrings
0x18000a120 FreeEnvironmentStringsW
0x18000a128 WideCharToMultiByte
0x18000a130 GetEnvironmentStringsW
0x18000a138 HeapSetInformation
0x18000a140 HeapCreate
0x18000a148 HeapDestroy
0x18000a150 RtlUnwindEx
0x18000a158 QueryPerformanceCounter
0x18000a160 GetTickCount
0x18000a168 GetCurrentProcessId
0x18000a170 GetSystemTimeAsFileTime
0x18000a178 WriteFile
0x18000a180 LeaveCriticalSection
0x18000a188 EnterCriticalSection
0x18000a190 HeapSize
0x18000a198 GetCPInfo
0x18000a1a0 GetACP
0x18000a1a8 GetOEMCP
0x18000a1b0 IsValidCodePage
0x18000a1b8 HeapReAlloc
0x18000a1c8 GetLocaleInfoA
0x18000a1d0 GetStringTypeA
0x18000a1d8 MultiByteToWideChar
0x18000a1e0 GetStringTypeW
0x18000a1e8 LCMapStringA
0x18000a1f0 LCMapStringW

Exports

Ordinal Address Name
1 0x180001050 GetArphaCrashReport
2 0x180001050 GetArphaUtils
3 0x180001050 SetWindowLocalDump
!This program cannot be run in DOS mode.
CzRich
`.rdata
@.data
.pdata
@.rsrc
@.reloc
SVWATH
XA\_^[
fffffff
fffffff
ATAUAVH
A^A]A\
WATAUAVAWH
@A_A^A]A\_
` AUAVAWH
fD9|$b
A_A^A]
x ATAUAVH
A^A]A\
Hct$@H
s\HcL$HH
WATAUAVAWH
A_A^A]A\_
l$ AVH
UVWATAUH
D$&8\$&t-8X
@A]A\_^]
LcA<E3
WATAUAVAWH
H!t$ E3
A_A^A]A\_
VWATAUAVH
@A^A]A\_^
L$ UATAUAVAWH
A_A^A]A\]
@UATAUAVAWH
e A_A^A]A\]
x ATAUAVH
@8|$Ht
A^A]A\
@USVWATAUAVAWH
eHA_A^A]A\_^[]
t$ WATAUAVAWH
A_A^A]A\_
p WATAUH
A]A\_
WATAUH
A]A\_
SVWATAUAVAWH
0A_A^A]A\_^[
WATAUAVAWH
A_A^A]A\_
@SWATAUAVAWH
L!t$HL!t$@
D$PL9wXt(
D$8HcH
A_A^A]A\_[
ATAUAVH
0A^A]A\
VWATAUAVH
A^A]A\_^
UVWATAUAVAWH
pA_A^A]A\_^]
UVWATAUAVAWH
A_A^A]A\_^]
WATAVH
@A^A\_
H(H9J(u
Unknown exception
CorExitProcess
runtime error
TLOSS error
SING error
DOMAIN error
An application has made an attempt to load the C runtime library incorrectly.
Please contact the application's support team for more information.
- Attempt to use MSIL code from this assembly during native code initialization
This indicates a bug in your application. It is most likely the result of calling an MSIL-compiled (/clr) function from a native constructor or from DllMain.
- not enough space for locale information
- Attempt to initialize the CRT more than once.
This indicates a bug in your application.
- CRT not initialized
- unable to initialize heap
- not enough space for lowio initialization
- not enough space for stdio initialization
- pure virtual function call
- not enough space for _onexit/atexit table
- unable to open console device
- unexpected heap error
- unexpected multithread lock error
- not enough space for thread data
This application has requested the Runtime to terminate it in an unusual way.
Please contact the application's support team for more information.
- not enough space for environment
- not enough space for arguments
- floating point support not loaded
Microsoft Visual C++ Runtime Library
<program name unknown>
Runtime Error!
Program:
Complete Object Locator'
Class Hierarchy Descriptor'
Base Class Array'
Base Class Descriptor at (
Type Descriptor'
`local static thread guard'
`managed vector copy constructor iterator'
`vector vbase copy constructor iterator'
`vector copy constructor iterator'
`dynamic atexit destructor for '
`dynamic initializer for '
`eh vector vbase copy constructor iterator'
`eh vector copy constructor iterator'
`managed vector destructor iterator'
`managed vector constructor iterator'
`placement delete[] closure'
`placement delete closure'
`omni callsig'
delete[]
new[]
`local vftable constructor closure'
`local vftable'
`udt returning'
`copy constructor closure'
`eh vector vbase constructor iterator'
`eh vector destructor iterator'
`eh vector constructor iterator'
`virtual displacement map'
`vector vbase constructor iterator'
`vector destructor iterator'
`vector constructor iterator'
`scalar deleting destructor'
`default constructor closure'
`vector deleting destructor'
`vbase destructor'
`string'
`local static guard'
`typeof'
`vcall'
`vbtable'
`vftable'
operator
delete
__unaligned
__restrict
__ptr64
__clrcall
__fastcall
__thiscall
__stdcall
__pascal
__cdecl
__based(
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
GetProcessWindowStation
GetUserObjectInformationA
GetLastActivePopup
GetActiveWindow
MessageBoxA
USER32.DLL
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
HH:mm:ss
dddd, MMMM dd, yyyy
MM/dd/yy
December
November
October
September
August
February
January
Saturday
Friday
Thursday
Wednesday
Tuesday
Monday
Sunday
SunMonTueWedThuFriSat
JanFebMarAprMayJunJulAugSepOctNovDec
bad exception
bad allocation
Kernel32.dll
Advapi32.dll
C:\Users\Admin\Documents\Visual Studio 2008\Projects\dlll\x64\Release\dlll.pdb
GetProcAddress
LoadLibraryA
GetModuleHandleA
KERNEL32.dll
GetCurrentThreadId
FlsSetValue
GetCommandLineA
TerminateProcess
GetCurrentProcess
UnhandledExceptionFilter
SetUnhandledExceptionFilter
IsDebuggerPresent
RtlVirtualUnwind
RtlLookupFunctionEntry
RtlCaptureContext
HeapAlloc
GetLastError
HeapFree
RaiseException
RtlPcToFileHeader
EncodePointer
DecodePointer
FlsGetValue
FlsFree
SetLastError
FlsAlloc
GetModuleHandleW
ExitProcess
SetHandleCount
GetStdHandle
GetFileType
GetStartupInfoA
DeleteCriticalSection
GetModuleFileNameA
FreeEnvironmentStringsA
GetEnvironmentStrings
FreeEnvironmentStringsW
WideCharToMultiByte
GetEnvironmentStringsW
HeapSetInformation
HeapCreate
HeapDestroy
RtlUnwindEx
QueryPerformanceCounter
GetTickCount
GetCurrentProcessId
GetSystemTimeAsFileTime
WriteFile
LeaveCriticalSection
EnterCriticalSection
HeapSize
GetCPInfo
GetACP
GetOEMCP
IsValidCodePage
HeapReAlloc
InitializeCriticalSectionAndSpinCount
GetLocaleInfoA
GetStringTypeA
MultiByteToWideChar
GetStringTypeW
LCMapStringA
LCMapStringW
dlll.dll
GetArphaCrashReport
GetArphaUtils
SetWindowLocalDump
.?AVtype_info@@
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
.?AVbad_exception@std@@
.?AVexception@std@@
.?AVbad_alloc@std@@
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v3">
<security>
<requestedPrivileges>
<requestedExecutionLevel level="asInvoker" uiAccess="false"></requestedExecutionLevel>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>PAPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPAD
mscoree.dll
((((( H
h(((( H
H
SOFTWARE
lpData
Antivirus Signature
Bkav Clean
Lionic Clean
tehtris Clean
ClamAV Clean
CMC Clean
CAT-QuickHeal Clean
Skyhigh Clean
ALYac Clean
Cylance Clean
Zillya Clean
Sangfor Clean
K7AntiVirus Clean
Alibaba Clean
K7GW Clean
Cybereason Clean
Baidu Clean
VirIT Clean
Paloalto Clean
Symantec Clean
Elastic Clean
ESET-NOD32 Clean
APEX Clean
Avast Clean
Cynet Clean
Kaspersky Trojan.Win64.DLLhijack.iw
BitDefender Clean
NANO-Antivirus Clean
ViRobot Clean
MicroWorld-eScan Clean
Tencent Clean
TACHYON Clean
Sophos Clean
F-Secure Clean
DrWeb Clean
VIPRE Clean
TrendMicro Clean
McAfeeD Clean
Trapmine Clean
FireEye Clean
Emsisoft Clean
SentinelOne Clean
GData Clean
Jiangmin Clean
Webroot Clean
Varist Clean
Avira Clean
Antiy-AVL Clean
Kingsoft Clean
Gridinsoft Clean
Xcitium Clean
Arcabit Clean
SUPERAntiSpyware Clean
ZoneAlarm Trojan.Win64.DLLhijack.iw
Microsoft Clean
Google Clean
AhnLab-V3 Clean
Acronis Clean
McAfee Clean
MAX Clean
VBA32 Clean
Malwarebytes Clean
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Rising Trojan.DLLhijack!8.1B50 (CLOUD)
Yandex Clean
Ikarus Clean
MaxSecure Win.MxResIcn.Heur.Gen
Fortinet Clean
BitDefenderTheta Clean
AVG Clean
DeepInstinct Clean
CrowdStrike Clean
alibabacloud Clean
No IRMA results available.