Static | ZeroBOX

PE Compile Time

2017-05-26 20:22:31

PE Imphash

99c0cd957fc7334714fefa3daa61a6ea

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x0000812e 0x00008200 6.49244166342
.rdata 0x0000a000 0x0000252c 0x00002600 4.85730746064
.data 0x0000d000 0x00002d8c 0x00000e00 2.25370996187
.rsrc 0x00010000 0x00000654 0x00000800 4.39246128596
.reloc 0x00011000 0x00000c70 0x00000e00 4.41040599727

Resources

Name Offset Size Language Sub-language File type
RT_STRING 0x000100e8 0x00000062 LANG_NEUTRAL SUBLANG_SYS_DEFAULT data
RT_VERSION 0x0001014c 0x000003ac LANG_NEUTRAL SUBLANG_SYS_DEFAULT data
RT_MANIFEST 0x000104f8 0x0000015a LANG_ENGLISH SUBLANG_ENGLISH_UK ASCII text, with CRLF line terminators

Imports

Library KERNEL32.dll:
0x40a000 LoadLibraryA
0x40a004 FreeLibrary
0x40a008 GetProcAddress
0x40a00c SetLastError
0x40a010 GetVersionExA
0x40a014 GetLastError
0x40a018 GetModuleFileNameA
0x40a01c WaitForSingleObject
0x40a020 Sleep
0x40a024 WriteFile
0x40a028 GetExitCodeProcess
0x40a034 CloseHandle
0x40a038 CreateProcessA
0x40a040 SetConsoleMode
0x40a044 GetConsoleMode
0x40a048 GetStdHandle
0x40a050 SetStdHandle
0x40a054 WriteConsoleW
0x40a058 HeapSize
0x40a05c SetFilePointer
0x40a060 FlushFileBuffers
0x40a064 GetCommandLineA
0x40a068 HeapSetInformation
0x40a06c GetCPInfo
0x40a078 GetACP
0x40a07c GetOEMCP
0x40a080 IsValidCodePage
0x40a084 EncodePointer
0x40a088 TlsAlloc
0x40a08c TlsGetValue
0x40a090 TlsSetValue
0x40a094 DecodePointer
0x40a098 TlsFree
0x40a09c GetModuleHandleW
0x40a0a0 GetCurrentThreadId
0x40a0ac IsDebuggerPresent
0x40a0b0 TerminateProcess
0x40a0b4 GetCurrentProcess
0x40a0b8 WideCharToMultiByte
0x40a0bc LCMapStringW
0x40a0c0 MultiByteToWideChar
0x40a0d0 ExitProcess
0x40a0d4 GetModuleFileNameW
0x40a0e0 SetHandleCount
0x40a0e8 GetFileType
0x40a0ec GetStartupInfoW
0x40a0f4 HeapCreate
0x40a0fc GetTickCount
0x40a100 GetCurrentProcessId
0x40a108 GetStringTypeW
0x40a10c HeapFree
0x40a110 HeapAlloc
0x40a114 RtlUnwind
0x40a118 LoadLibraryW
0x40a11c HeapReAlloc
0x40a120 GetConsoleCP
0x40a124 CreateFileW
Library USER32.dll:
0x40a12c EnumWindows
0x40a130 GetClassNameA
0x40a134 SendMessageA
0x40a138 EnumThreadWindows

!This program cannot be run in DOS mode.
I:~Rich
`.rdata
@.data
@.reloc
t"SS9] u
HHt$HHt
?If90t
uTVWh/Y@
^SSSSS
j@j ^V
URPQQh
PPPPPPPP
PPPPPPPP
;t$,v-
UQPXY]Y[
!!!!:26/05/17 12:21:13 V12.50
Kernel32.dll
Wow64DisableWow64FsRedirection
Wow64RevertWow64FsRedirection
remcmdstub.exe
ConsoleWindowClass
remcmdstub
(NULL)
Usage: %s (4 InheritableEventHandles) (CommandLineToSpawn)
HH:mm:ss
dddd, MMMM dd, yyyy
MM/dd/yy
December
November
October
September
August
February
January
Saturday
Friday
Thursday
Wednesday
Tuesday
Monday
Sunday
FlsFree
FlsSetValue
FlsGetValue
FlsAlloc
(null)
`h````
xpxxxx
CorExitProcess
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
`h`hhh
xppwpp
GetProcessWindowStation
GetUserObjectInformationW
GetLastActivePopup
GetActiveWindow
MessageBoxW
LoadLibraryA
FreeLibrary
GetProcAddress
SetLastError
GetVersionExA
GetLastError
GetModuleFileNameA
WaitForSingleObject
WriteFile
GetExitCodeProcess
GenerateConsoleCtrlEvent
WaitForMultipleObjects
CloseHandle
CreateProcessA
SetConsoleCtrlHandler
SetConsoleMode
GetConsoleMode
GetStdHandle
ExpandEnvironmentStringsA
KERNEL32.dll
SendMessageA
GetClassNameA
EnumWindows
EnumThreadWindows
USER32.dll
GetCommandLineA
HeapSetInformation
GetCPInfo
InterlockedIncrement
InterlockedDecrement
GetACP
GetOEMCP
IsValidCodePage
EncodePointer
TlsAlloc
TlsGetValue
TlsSetValue
DecodePointer
TlsFree
GetModuleHandleW
GetCurrentThreadId
UnhandledExceptionFilter
SetUnhandledExceptionFilter
IsDebuggerPresent
TerminateProcess
GetCurrentProcess
WideCharToMultiByte
LCMapStringW
MultiByteToWideChar
EnterCriticalSection
LeaveCriticalSection
IsProcessorFeaturePresent
ExitProcess
GetModuleFileNameW
FreeEnvironmentStringsW
GetEnvironmentStringsW
SetHandleCount
InitializeCriticalSectionAndSpinCount
GetFileType
GetStartupInfoW
DeleteCriticalSection
HeapCreate
QueryPerformanceCounter
GetTickCount
GetCurrentProcessId
GetSystemTimeAsFileTime
GetStringTypeW
HeapFree
HeapAlloc
RtlUnwind
LoadLibraryW
HeapReAlloc
GetConsoleCP
FlushFileBuffers
SetFilePointer
HeapSize
WriteConsoleW
SetStdHandle
CreateFileW
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v3">
<security>
<requestedPrivileges>
<requestedExecutionLevel level="asInvoker" uiAccess="false"></requestedExecutionLevel>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>PAPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPAD
0 0*020J0h0
1K1V1w1
2-242:2T2Z2
5(5?5f5l5
6;6e6v6
6I7P7a7
10V0c0p0|0
1C1H1O1U1 2]2t2
3/4<4F4T4]4g4
8"8'868]8
:K;e;v;
<"<.<4<<<B<N<T<a<k<q<{<
=H=N=T=j=
=">E>O>
?!?)?0?5?=?F?R?W?\?b?f?l?q?w?|?
1$2@2c2v2
557;7A7G7M7S7Z7a7h7o7v7}7
8"8)8m:t:
;1;C;Q;f;p;
4*5K5/7
>$>,><>B>S>
050?0Z0b0h0v0
6)7n7u7
93989`9l9|9
:<;C;M;_;v;
=6=?=K=
2'292K2]2o2
487Y7b7
:L;R;X;q<
<E=Q=\>(?-???]?q?w?
0!0/04090>0N0}0
1"1)1.1<1
142C2R2_2e2
3&3I3N3S3j3
4%4+454;4E4K4U4^4i4n4w4
7.848>8
;-;4;8;<;@;D;H;L;P;
<8<?<D<H<L<m<
<6=<=@=D=H=P>
9%:?:H:z:
;$<.<F<o<
0;0F0t0
L1P1T1X1\1h1l1
6D?L?T?\?d?l?t?|?
;H;d;h;
<8<X<x<
= =@=`=
@4@5D5H5L5P5T5X5\5`5d5h5l5p5t5x5|5
6 6$6(6,6064686<6@6D6H6L6P6T6X6\6`6d6h6l6p6t6x6|6
7 707@7d7p7t7x7|7
= =$=(=,=8=<=@=D=H=L=P=T=X=\=`=p=
GlobalSign Root CA - R31
GlobalSign1
GlobalSign0
110802100000Z
190802100000Z0Z1
GlobalSign nv-sa100.
'GlobalSign CodeSigning CA - SHA256 - G20
&https://www.globalsign.com/repository/06
%http://crl.globalsign.net/root-r3.crl0
Salt Lake City1
The USERTRUST Network1!0
http://www.usertrust.com1
UTN-USERFirst-Object0
151231000000Z
190709184036Z0
Greater Manchester1
Salford1
COMODO CA Limited1*0(
!COMODO SHA-1 Time Stamping Signer0
1http://crl.usertrust.com/UTN-USERFirst-Object.crl05
http://ocsp.usertrust.com0
GlobalSign nv-sa100.
'GlobalSign CodeSigning CA - SHA256 - G20
150903155922Z
181122155436Z0
Florida1
Boca Raton1
CrossTec Corporation1
CrossTec Corporation1(0&
jeff@crosstecsoftware.com0
&https://www.globalsign.com/repository/0
1http://crl.globalsign.com/gs/gscodesignsha2g2.crl0
8http://secure.globalsign.com/cacert/gscodesignsha2g2.crt08
,http://ocsp2.globalsign.com/gscodesignsha2g20
GlobalSign nv-sa100.
'GlobalSign CodeSigning CA - SHA256 - G2
Salt Lake City1
The USERTRUST Network1!0
http://www.usertrust.com1
UTN-USERFirst-Object
180226151731Z0#
GlobalSign Root CA - R31
GlobalSign1
GlobalSign0
110802100000Z
190802100000Z0Z1
GlobalSign nv-sa100.
'GlobalSign CodeSigning CA - SHA256 - G20
&https://www.globalsign.com/repository/06
%http://crl.globalsign.net/root-r3.crl0
GlobalSign nv-sa100.
'GlobalSign CodeSigning CA - SHA256 - G20
150903155922Z
181122155436Z0
Florida1
Boca Raton1
CrossTec Corporation1
CrossTec Corporation1(0&
jeff@crosstecsoftware.com0
&https://www.globalsign.com/repository/0
1http://crl.globalsign.com/gs/gscodesignsha2g2.crl0
8http://secure.globalsign.com/cacert/gscodesignsha2g2.crt08
,http://ocsp2.globalsign.com/gscodesignsha2g20
GlobalSign nv-sa100.
'GlobalSign CodeSigning CA - SHA256 - G2
20180226151734Z
Greater Manchester1
Salford1
COMODO CA Limited1,0*
#COMODO SHA-256 Time Stamping Signer
Salt Lake City1
The USERTRUST Network1!0
http://www.usertrust.com1
UTN-USERFirst-Object0
151231000000Z
190709184036Z0
Greater Manchester1
Salford1
COMODO CA Limited1,0*
#COMODO SHA-256 Time Stamping Signer0
fO\r6{
'1Oqtn
lZGfD{
1http://crl.usertrust.com/UTN-USERFirst-Object.crl05
http://ocsp.usertrust.com0
Salt Lake City1
The USERTRUST Network1!0
http://www.usertrust.com1
UTN-USERFirst-Object
180226151734Z0+
HH:mm:ss
dddd, MMMM dd, yyyy
MM/dd/yy
December
November
October
September
August
February
January
Saturday
Friday
Thursday
Wednesday
Tuesday
Monday
Sunday
nKERNEL32.DLL
@(null)
mscoree.dll
runtime error
TLOSS error
SING error
DOMAIN error
- Attempt to use MSIL code from this assembly during native code initialization
This indicates a bug in your application. It is most likely the result of calling an MSIL-compiled (/clr) function from a native constructor or from DllMain.
- not enough space for locale information
- Attempt to initialize the CRT more than once.
This indicates a bug in your application.
- CRT not initialized
- unable to initialize heap
- not enough space for lowio initialization
- not enough space for stdio initialization
- pure virtual function call
- not enough space for _onexit/atexit table
- unable to open console device
- unexpected heap error
- unexpected multithread lock error
- not enough space for thread data
- abort() has been called
- not enough space for environment
- not enough space for arguments
- floating point support not loaded
@Microsoft Visual C++ Runtime Library
<program name unknown>
Runtime Error!
Program:
((((( H
h(((( H
H
WUSER32.DLL
CONOUT$
!Copyright (c) 2017 NetSupport Ltd
VS_VERSION_INFO
StringFileInfo
080904b0
Comments
CompanyName
NetSupport Ltd
FileDescription
Crosstec Remote Command Prompt
FileVersion
V12.50
InternalName
remcmdstub
LegalCopyright
Copyright (c) 2017, NetSupport Ltd
LegalTrademarks
OriginalFilename
remcmdstub.exe
PrivateBuild
V12.50
ProductName
Crosstec SchoolVue
ProductVersion
V12.50
SpecialBuild
VarFileInfo
Translation
Antivirus Signature
Bkav Clean
Lionic Clean
tehtris Clean
ClamAV Clean
CMC Clean
CAT-QuickHeal Clean
Skyhigh Clean
ALYac Clean
Cylance Clean
Zillya Clean
Sangfor Clean
K7AntiVirus Clean
Alibaba Clean
K7GW Clean
Cybereason Clean
Baidu Clean
VirIT Clean
Symantec Clean
Elastic Clean
ESET-NOD32 Clean
APEX Clean
Avast Clean
Cynet Clean
Kaspersky Clean
BitDefender Clean
NANO-Antivirus Clean
ViRobot Clean
MicroWorld-eScan Clean
Tencent Clean
Sophos Clean
F-Secure Clean
DrWeb Program.RemoteAdmin.937
VIPRE Clean
TrendMicro Clean
McAfeeD Clean
Trapmine Clean
FireEye Clean
Emsisoft Clean
Paloalto Clean
GData Clean
Jiangmin RemoteAdmin.NetSup.ai
Webroot Clean
Varist Clean
Avira Clean
MAX Clean
Antiy-AVL Clean
Kingsoft Clean
Gridinsoft Trojan.Win32.Downloader.dd!c
Xcitium Clean
Arcabit Clean
SUPERAntiSpyware Clean
ZoneAlarm Clean
Microsoft Clean
Google Clean
AhnLab-V3 Clean
Acronis Clean
McAfee Clean
TACHYON Clean
VBA32 Clean
Malwarebytes Clean
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Rising Clean
Yandex Clean
Ikarus Clean
MaxSecure Clean
Fortinet Clean
BitDefenderTheta Clean
AVG Clean
DeepInstinct Clean
CrowdStrike Clean
alibabacloud Clean
No IRMA results available.