Static | ZeroBOX

PE Compile Time

2018-08-10 18:52:35

PDB Path

R:\JuicyPotato\Release\x64\JuicyPotato.pdb

PE Imphash

23867a89c2b8fc733be6cf5ef902f2d1

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x00036b86 0x00036c00 6.40727645982
.rdata 0x00038000 0x0001637e 0x00016400 4.76942411415
.data 0x0004f000 0x000039d0 0x00002400 3.9166337398
.pdata 0x00053000 0x00003b64 0x00003c00 5.51884508391
.gfids 0x00057000 0x000009e4 0x00000a00 3.74730919617
.rsrc 0x00058000 0x000001e0 0x00000200 4.71229819329
.reloc 0x00059000 0x00000cac 0x00000e00 5.28048706968

Resources

Name Offset Size Language Sub-language File type
RT_MANIFEST 0x00058060 0x0000017d LANG_ENGLISH SUBLANG_ENGLISH_US XML 1.0 document text

Imports

Library Secur32.dll:
0x1400383d0 AcceptSecurityContext
Library KERNEL32.dll:
0x140038058 Sleep
0x140038068 GetLastError
0x140038070 GetCurrentProcess
0x140038078 CreateThread
0x140038080 LoadLibraryW
0x140038088 LoadLibraryExW
0x140038090 UnregisterWaitEx
0x140038098 QueryDepthSList
0x1400380a0 InterlockedPopEntrySList
0x1400380a8 ReleaseSemaphore
0x1400380b0 DuplicateHandle
0x1400380b8 VirtualProtect
0x1400380c0 VirtualFree
0x1400380c8 VirtualAlloc
0x1400380d0 GetVersionExW
0x1400380d8 GetModuleHandleA
0x1400380e0 FreeLibraryAndExitThread
0x1400380e8 GetThreadTimes
0x1400380f0 UnregisterWait
0x140038100 SetThreadAffinityMask
0x140038108 GetProcessAffinityMask
0x140038110 GetNumaHighestNodeNumber
0x140038118 DeleteTimerQueueTimer
0x140038120 ChangeTimerQueueTimer
0x140038128 CreateTimerQueueTimer
0x140038138 GetThreadPriority
0x140038140 SetThreadPriority
0x140038148 RtlCaptureContext
0x140038150 RtlLookupFunctionEntry
0x140038158 RtlVirtualUnwind
0x140038160 UnhandledExceptionFilter
0x140038170 TerminateProcess
0x140038180 QueryPerformanceCounter
0x140038188 GetCurrentProcessId
0x140038190 GetCurrentThreadId
0x140038198 GetSystemTimeAsFileTime
0x1400381a0 InitializeSListHead
0x1400381a8 IsDebuggerPresent
0x1400381b0 GetStartupInfoW
0x1400381b8 GetModuleHandleW
0x1400381c0 EnterCriticalSection
0x1400381c8 LeaveCriticalSection
0x1400381d0 TryEnterCriticalSection
0x1400381d8 DeleteCriticalSection
0x1400381e0 WideCharToMultiByte
0x1400381e8 SetLastError
0x1400381f8 CreateEventW
0x140038200 TlsAlloc
0x140038208 TlsGetValue
0x140038210 TlsSetValue
0x140038218 TlsFree
0x140038220 GetTickCount
0x140038228 GetProcAddress
0x140038230 RtlPcToFileHeader
0x140038238 EncodePointer
0x140038240 RaiseException
0x140038248 RtlUnwindEx
0x140038258 InterlockedFlushSList
0x140038260 FreeLibrary
0x140038268 DecodePointer
0x140038270 ExitProcess
0x140038278 GetModuleHandleExW
0x140038280 GetStdHandle
0x140038288 WriteFile
0x140038290 GetModuleFileNameW
0x140038298 MultiByteToWideChar
0x1400382a0 GetCommandLineA
0x1400382a8 GetCommandLineW
0x1400382b0 GetACP
0x1400382b8 HeapAlloc
0x1400382c0 HeapFree
0x1400382c8 CompareStringW
0x1400382d0 LCMapStringW
0x1400382d8 GetFileType
0x1400382e0 GetCurrentThread
0x1400382e8 FlushFileBuffers
0x1400382f0 GetConsoleCP
0x1400382f8 GetConsoleMode
0x140038300 CloseHandle
0x140038308 WaitForSingleObjectEx
0x140038310 FindClose
0x140038318 FindFirstFileExW
0x140038320 FindNextFileW
0x140038328 IsValidCodePage
0x140038330 GetOEMCP
0x140038338 GetCPInfo
0x140038340 GetEnvironmentStringsW
0x140038348 FreeEnvironmentStringsW
0x140038350 SetEnvironmentVariableW
0x140038358 SetStdHandle
0x140038360 GetStringTypeW
0x140038368 GetProcessHeap
0x140038370 SetFilePointerEx
0x140038378 WriteConsoleW
0x140038380 HeapSize
0x140038388 HeapReAlloc
0x140038390 CreateFileW
0x140038398 CreateTimerQueue
0x1400383a0 SetEvent
0x1400383a8 SignalObjectAndWait
0x1400383b0 SwitchToThread
Library ADVAPI32.dll:
0x140038000 GetTokenInformation
0x140038008 CreateProcessAsUserW
0x140038010 CreateProcessWithTokenW
0x140038018 DuplicateTokenEx
0x140038020 OpenProcessToken
0x140038028 AdjustTokenPrivileges
0x140038030 LookupPrivilegeValueW
0x140038038 LookupAccountSidW
0x140038040 CopySid
0x140038048 GetLengthSid
Library ole32.dll:
0x140038470 CoTaskMemAlloc
0x140038478 CLSIDFromString
0x140038490 CoInitialize
Library WS2_32.dll:
0x1400383e0 freeaddrinfo
0x1400383e8 setsockopt
0x1400383f0 shutdown
0x1400383f8 recv
0x140038400 send
0x140038408 closesocket
0x140038410 bind
0x140038418 WSAGetLastError
0x140038420 socket
0x140038428 WSACleanup
0x140038430 getaddrinfo
0x140038438 WSAStartup
0x140038440 accept
0x140038448 select
0x140038450 listen
0x140038458 __WSAFDIsSet
0x140038460 connect

!This program cannot be run in DOS mode.
`.rdata
@.data
.pdata
@.gfids
@.rsrc
@.reloc
|$ UATAUAVAWH
A_A^A]A\]
L$ SVWH
@UATAUAVAWH
A_A^A]A\]
D$HNTLML
D$LSSH
CXE;SPr6Ic
@UAVAWH
@UWAVH
UAVAWH
fB94Bu
H3E H3E
SVWAVH
8A^_^[
t$ WAVAWH
A9FHtI
9D$(}y
A9FHtQI
@A_A^_
@SUVWATAVAWH
@A_A^A\_^][
VWATAVAWH
A_A^A\_^
B(I9A(
UATAUAVAWH
L9`8tA
A_A^A]A\]
UVWATAUAVAWH
pA_A^A]A\_^]
WATAUAVAWH
A_A^A]A\_
AUAVAWH
I9}(t9H
0A_A^A]
@SVWATAUAVAWH
L!|$(L!
D$0HcH
pA_A^A]A\_^[
SVWATAUAVAWH
0A_A^A]A\_^[
WATAUAVAWH
r 9_ t
ri9V vdH
A_A^A]A\_
WATAUAVAWH
A_A^A]A\_
ffffff
VWATAVAWH
A_A^A\_^
x ATAVAWH
A_A^A\
H;xXu9
WATAUAVAWH
A_A^A]A\_
D$@H;G
S,, <Zw
CA< t(<#t
<htr<jtb<lt6<tt&<wt
!,X< w
t$ WAVAWH
s4+sP+
0A_A^_
WAVAWH
A_A^_
@8l$8t
WAVAWH
@A_A^_
\$ UVWATAUAVAWH
A_A^A]A\_^]
u3HcH<H
fD9!u7A
UVWAVAWH
0A_A^_^]
WAVAWH
fA96tdH
fA94nu
0A_A^_
L$ WATAUAVAWH
@A_A^A]A\_
x ATAVAWH
A_A^A\
|$ UATAUAVAWH
A_A^A]A\]
WATAUAVAWH
A_A^A]A\_
fD9t$b
D82u&H
D8t$Ht
x ATAVAWH
gfffffffH
D8d$ht
A_A^A\
WATAUAVAWH
A_A^A]A\_
UVWATAUAVAWH
A_A^A]A\_^]
VWATAVAW
A_A^A\_^
WATAUAVAWH
A_A^A]A\_
\$ UVWATAUAVAWH
H!D$ E
`A_A^A]A\_^]
UVWATAUAVAWH
fA9<Bu
fC9<hu
A_A^A]A\_^]
WATAUAVAWH
fD9,yu
0A_A^A]A\_
\$ UVWAVAWH
A_A^_^]
f9|$^t&f
f9|$`t
l$ VWATAVAWH
L$&@8t$&t0@8q
A81t@@8r
A_A^A\_^
WATAUAVAWH
0A_A^A]A\_
I96t:H
fB94`t
xWI96tRI
fC94wu
t{H9/tQL
@UATAUAVAWH
e0A_A^A]A\]
SVWATAUAWH
HA_A]A\_^[
@UATAUAVAWH
H!T$0D
uf!T$(H!T$
A_A^A]A\]
@USVWATAUAVAWH
D8l$ht
A_A^A]A\_^[]
WATAUAVAWH
A_A^A]A\_
l$ WAVAWH
A_A^_
@UATAVH
@8l$Ht
ffffff
fffffff
|$ ATAVAWH
\$@@8=
A_A^A\
USVWAVH
A^_^[]
{ ATAVAWH
A_A^A\
C0H9C(r
WAVAWH
0A_A^_
WAVAWH
A_A^_
WAVAWH
A_A^_
WAVAWH
@UATAUAVAWH
A_A^A]A\]
UVWATAUAVAWH
H+D$hH+D$P3
A_A^A]A\_^]
H3\$HH
UVWATAUAVAWH
A_A^A]A\_^]
VWAUAVAWH
A_A^A]_^
WATAUAVAWH
A_A^A]A\_
\$ UVWH
UVWATAUAVAWH
L$`tcA
A_A^A]A\_^]
UVWATAUAVAWH
A,A9A(v&L
0A_A^A]A\_^]
WATAUAVAWH
O,D9O(vcH
0A_A^A]A\_
WATAUAVAWH
A;H$v}H
A;H$sH
0A_A^A]A\_
SUVWATAUAVAWH
HA_A^A]A\_^][
@VWAVH
SUVWATAUAVAWH
\$4E;O
;B$vvI
D$0tbA
D$0C+D0(
@09D$0
D$PE;O
H$E+H,toA
R(A9P4A
@(A+@4;
xA_A^A]A\_^][
WATAUAVAWH
C9|)$u?C
0A_A^A]A\_
VWAUAVAWH
A`D9L8
;B$vUH
,t0D9J0v*L
0A_A^A]_^
t$ WATAUAVAWH
D8M@t^
+J$D8M@
D8M@tM
0A_A^A]A\_
UVWATAUAVAWH
0A_A^A]A\_^]
t$ WATAUAVAWH
A_A^A]A\_
UVWATAUAVAWH
A_A^A]A\_^]
L$ UVWATAUAVAWH
0A_A^A]A\_^]
x ATAVAWH
0A_A^A\
@SUVWATAVAWH
0A_A^A\_^][
9G$vAD
D9G$s5
l$ VWATAUAVAWE3
D9x(uiE
A(9B(D
X(D9y(
t'B;|
l$PA_A^A]A\_^
WATAUAVAWH
A_A^A]A\_
H9_ht0H
WATAUAVAWH
A_A^A]A\_
x ATAVA
A$+A,t[3
|$0A^A\
WATAUAVAWH
0A_A^A]A\_
UVWATAUAVAWH
l$`C9,
A_A^A]A\_^]
x AVE3
UVWATAUAVAWH
D;z,v(A
&D;j0u
A_A^A]A\_^]
E8X@t8A
R0E8XAt
B0E8XAt
WAVAWH
WAVAWH
9oP~3E3
A_A^_
VWAUAVAWH
9WP~HM
uxHcOP
HcGl;Gh}
A_A^A]_^
t H9X8tN
9YD~/3
9_D~/3
x AVE2
t*H9X8u$@8
E;Bl}NE
|$ UATAUAVAWH
q(9YD~tE3
9_D~H3
A_A^A]A\]
x ATAVAWH
A_A^A\
t$Pu1H
USVWATAUAVAWH
~(HcNDI
F8HcNDI
F0LcFDI
D9f@~0Hc
A_A^A]A\_^[]
|$ AVH
UVWATAUAVAWH
0A_A^A]A\_^]
;Ct~bH
;Ct~MH
V`;Ct~bH
;Ct~MH
|$ UAVAWH
x ATAVAWH
C(9C u&
C,9C$u
A_A^A\
H!\$(L
D$ !\$$H
H!\$03
91~/E3
VWAUAVAWH
9WP~KM
uxHcOP
HcGl;Gh}
A_A^A]_^
A;>}I
WATAUAVAWH
A_A^A]A\_
H;YXt
twH;^XtH3
t$H;^Xt
tGH;~XtA
V0;Ct~ZH
;Ct~EH
A;6}#I
91~/E3
|$ AVH
WAVAWH
A_A^_
9D$`t_
@UAVAWH
e@A_A^]
WATAUAVAWH
A_A^A]A\_
WATAUAVAWH
0A_A^A]A\_
WATAUAVAWH
0A_A^A]A\_
WATAUAVAWH
A_A^A]A\_
L9w t#H
WAVAWH
A_A^_
H9J t1
UVWATAUAVAWH
v A9~ w
D9d$(u
uh@8|$!t,
uOD;d$(uH
5@8|$"t.9|
tP@8|$!u4@8|$"t-
`A_A^A]A\_^]
@VWATAVAWH
0A_A^A\_^
UVWAVAWH
A_A^_^]
WAVAWH
A_A^_
WAVAWH
A_A^_
UVWAVAWH
PA_A^_^]
u)!t$(H
;Ct~ZH
;Ct~EH
WAVAWH
A_A^_
F(LcF I
WAVAWH
9oP~2E3
A_A^_
VWAUAVAWH
9WP~KM
uxHcOP
HcGl;Gh}
A_A^A]_^
x ATAVAWH
A_A^A\
Hc;HcK
UWAUAVAWH
A_A^A]_]
UVWATAVH
@A^A\_^]
UVWAVAWH
`A_A^_^]
UATAUAVAWH
A_A^A]A\]
SUVWATAUAVAWH
8A_A^A]A\_^][
UVWATAUAVAWH
8\$`tH
A_A^A]A\_^]
u!!D$(H
UVWAVAWH
@A_A^_^]
UVWATAUAVAWH
@A_A^A]A\_^]
UWATAVAWH
A_A^A\_]
WAVAWH
0A_A^_
` UAVAWH
WAVAWH
9oP~2E3
A_A^_
;Ct~ZH
;Ct~EH
WAVAWH
9_P~OE3
A_A^_
K4A+H
VWAUAVAWH
9WP~GM
uxHcOP
HcGl;Gh}
A_A^A]_^
VWAUAVAWH
9WP~GM
uxHcOP
HcGl;Gh}
A_A^A]_^
VWAUAVAWH
9WP~KM
uxHcOP
HcGl;Gh}
A_A^A]_^
UWATAVAWH
A_A^A\_]
u%!D$@H
WAVAWH
K 9N v@H
0A_A^_
t$ WAVAWH
;Vl}fD
A_A^_
l$ VWAVH
UAVAWH
;Ct~ZH
;Ct~EH
UVWATAUAVAWH
8D$ u+I
A_A^A]A\_^]
C4D+@ H
UVWATAUAVAWH
0A_A^A]A\_^]
WAVAWH
A_A^_
Hc;HcK
WAVAWH
A_A^_
H9BhuTH
~`8A!t
SVWATAVAWH
XA_A^A\_^[
D$0f;UPu
WAVAWH
@A_A^_
u!!D$(H
ATAVAWH
0A_A^A\
WAVAWH
0A_A^_
ATAVAWH
0A_A^A\
H#t$0tB
@USVWATAUAVAWH
H+G H=
A_A^A]A\_^[]
@SUVWATAUAVAWH
H+C H=
A_A^A]A\_^][
WATAUAVAWH
A_A^A]A\_
WATAUAVAWH
@A_A^A]A\_
WATAUAVAWH
A_A^A]A\_
x ATAVAWH
A_A^A\
x ATAVAWH
A_A^A\
UAVAWH
@A_A^]
UAVAWH
@A_A^]
t.8\$P
SVWAVH
8A^_^[
WAVAWH
LcA<E3
WAVAWH
0A_A^_
@WAVAWH
0A_A^_
D$@csm
VWATAUAVAWL
|$XHcU
D$8HcJ
H;D$Pu
l$HA_A^A]A\_^
x AVHcA
SUVWATAUAVAWH
H9D$PuCI
A_A^A]A\_^][
WATAUAVAWH
A_A^A]A\_
>ffffff
fffffff
ffffff
Unknown exception
bad allocation
bad array new length
device or resource busy
invalid argument
no such process
not enough memory
operation not permitted
resource deadlock would occur
resource unavailable try again
generic
string too long
invalid string position
address family not supported
address in use
address not available
already connected
argument list too long
argument out of domain
bad address
bad file descriptor
bad message
broken pipe
connection aborted
connection already in progress
connection refused
connection reset
cross device link
destination address required
directory not empty
executable format error
file exists
file too large
filename too long
function not supported
host unreachable
identifier removed
illegal byte sequence
inappropriate io control operation
interrupted
invalid seek
io error
is a directory
message size
network down
network reset
network unreachable
no buffer space
no child process
no link
no lock available
no message available
no message
no protocol option
no space on device
no stream resources
no such device or address
no such device
no such file or directory
not a directory
not a socket
not a stream
not connected
not supported
operation canceled
operation in progress
operation not supported
operation would block
owner dead
permission denied
protocol error
protocol not supported
read only file system
result out of range
state not recoverable
stream timeout
text file busy
timed out
too many files open in system
too many files open
too many links
too many symbolic link levels
value too large
wrong protocol type
unknown error
FlsAlloc
FlsFree
FlsGetValue
FlsSetValue
InitializeCriticalSectionEx
InitOnceExecuteOnce
CreateEventExW
CreateSemaphoreW
CreateSemaphoreExW
CreateThreadpoolTimer
SetThreadpoolTimer
WaitForThreadpoolTimerCallbacks
CloseThreadpoolTimer
CreateThreadpoolWait
SetThreadpoolWait
CloseThreadpoolWait
FlushProcessWriteBuffers
FreeLibraryWhenCallbackReturns
GetCurrentProcessorNumber
CreateSymbolicLinkW
GetCurrentPackageId
GetTickCount64
GetFileInformationByHandleEx
SetFileInformationByHandle
GetSystemTimePreciseAsFileTime
InitializeConditionVariable
WakeConditionVariable
WakeAllConditionVariable
SleepConditionVariableCS
InitializeSRWLock
AcquireSRWLockExclusive
TryAcquireSRWLockExclusive
ReleaseSRWLockExclusive
SleepConditionVariableSRW
CreateThreadpoolWork
SubmitThreadpoolWork
CloseThreadpoolWork
CompareStringEx
GetLocaleInfoEx
LCMapStringEx
bad exception
__based(
__cdecl
__pascal
__stdcall
__thiscall
__fastcall
__vectorcall
__clrcall
__eabi
__ptr64
__restrict
__unaligned
restrict(
delete
operator
`vftable'
`vbtable'
`vcall'
`typeof'
`local static guard'
`string'
`vbase destructor'
`vector deleting destructor'
`default constructor closure'
`scalar deleting destructor'
`vector constructor iterator'
`vector destructor iterator'
`vector vbase constructor iterator'
`virtual displacement map'
`eh vector constructor iterator'
`eh vector destructor iterator'
`eh vector vbase constructor iterator'
`copy constructor closure'
`udt returning'
`local vftable'
`local vftable constructor closure'
new[]
delete[]
`omni callsig'
`placement delete closure'
`placement delete[] closure'
`managed vector constructor iterator'
`managed vector destructor iterator'
`eh vector copy constructor iterator'
`eh vector vbase copy constructor iterator'
`dynamic initializer for '
`dynamic atexit destructor for '
`vector copy constructor iterator'
`vector vbase copy constructor iterator'
`managed vector copy constructor iterator'
`local static thread guard'
operator ""
Type Descriptor'
Base Class Descriptor at (
Base Class Array'
Class Hierarchy Descriptor'
Complete Object Locator'
`h````
xpxxxx
(null)
CorExitProcess
LocaleNameToLCID
RoInitialize
RoUninitialize
NAN(SNAN)
nan(snan)
NAN(IND)
nan(ind)
Sunday
Monday
Tuesday
Wednesday
Thursday
Friday
Saturday
January
February
August
September
October
November
December
MM/dd/yy
dddd, MMMM dd, yyyy
HH:mm:ss
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
[aOni*{
~ $s%r
@b;zO]
v2!L.2
1#QNAN
1#SNAN
UUUUUU
UUUUUU
=imb;D
/>58d%
VM>cQ6
>jtm}S
)>6{1n
+f)>0'
;H9>&X
*StO9>T
n03>Pu
K~Je#>!
bp(=>?g
BC?>6t9^
K&>.yC
.xJ>Hf
y\PD>!
|b=})>
c [1>H'
uzKs@>
3>N;kU
kE>fvw
V6E>`"(5
?UUUUUU
?7zQ6$
Lock already taken
pEvents
SetThreadGroupAffinity
GetThreadGroupAffinity
GetCurrentProcessorNumberEx
GetLogicalProcessorInformationEx
pScheduler
version
eventObject
ppVirtualProcessorRoots
SchedulerKind
MaxConcurrency
MinConcurrency
TargetOversubscriptionFactor
LocalContextCacheSize
ContextStackSize
ContextPriority
SchedulingProtocol
DynamicProgressFeedback
WinRTInitialization
MaxPolicyElementKey
Mbp?333333
pContext
pExecutionResource
CreateRemoteThreadEx
CreateUmsCompletionList
CreateUmsThreadContext
DeleteProcThreadAttributeList
DeleteUmsCompletionList
DeleteUmsThreadContext
DequeueUmsCompletionListItems
EnterUmsSchedulingMode
ExecuteUmsThread
GetCurrentUmsThread
GetNextUmsListItem
GetUmsCompletionListEvent
InitializeProcThreadAttributeList
QueryUmsThreadInformation
SetUmsThreadInformation
UmsThreadYield
UpdateProcThreadAttribute
RegisterTraceGuidsW
UnregisterTraceGuids
TraceEvent
GetTraceLoggerHandle
GetTraceEnableLevel
GetTraceEnableFlags
pThreadProxy
switchState
Access violation - no RTTI data!
Bad dynamic_cast!
?UUUUUU
?UUUUUU
?UUUUUU
?UUUUUU
?8bunz8
?@En[vP
[*ncd>0
S>$hkDh$h>[2
UA>N0Wl
Error in AquireCredentialsHandle
Buffer sizes incompatible - can't replace
%S;%S\%S
JuicyPotato v%s
Mandatory args:
-t createprocess call: <t> CreateProcessWithTokenW, <u> CreateProcessAsUser, <*> try both
-p <program>: program to launch
-l <port>: COM server listen port
Optional args:
-m <ip>: COM server listen address (default 127.0.0.1)
-a <argument>: command line argument to pass to program (default NULL)
-k <ip>: RPC server ip address (default 127.0.0.1)
-n <port>: RPC server listen port (default 135)
-c <{clsid}>: CLSID (default BITS:{4991d34b-80a1-4291-83b6-3328366b9097})
-z only test CLSID and print token's user
Error - Unknown NTLM message type...
WSAStartup failed with error: %d
127.0.0.1
getaddrinfo failed with error: %d
socket failed with error: %ld
Unable to connect to server!
RPC -> send failed with error: %d
RPC-> Connection closed
RPC -> recv failed with error: %d
bind failed with error: %d
listen failed with error: %d
accept failed with error: %d
COM -> send failed with error: %d
COM -> recv failed with error: %d
shutdown failed with error: %d
Priv Lookup FALSE
Priv Adjust FALSE
Wrong Argument: %s
Testing %S %S
[+] authresult %d
[-] Error getting token type: error code 0x%lx
Error getting token type: error code 0x%lx
[-] CreateProcessWithTokenW Failed to create proc: %d
[+] CreateProcessWithTokenW OK
[-] CreateProcessAsUser Failed to create proc: %d
[+] CreateProcessAsUser OK
Waiting for auth...
deque<T> too long
R:\JuicyPotato\Release\x64\JuicyPotato.pdb
.text$di
.text$mn
.text$mn$00
.text$x
.text$yd
.idata$5
.00cfg
.CRT$XCA
.CRT$XCAA
.CRT$XCC
.CRT$XCU
.CRT$XCZ
.CRT$XIA
.CRT$XIAA
.CRT$XIAC
.CRT$XIC
.CRT$XIZ
.CRT$XPA
.CRT$XPB
.CRT$XPX
.CRT$XPXA
.CRT$XPZ
.CRT$XTA
.CRT$XTZ
.rdata
.rdata$r
.rdata$zzzdbg
.rtc$IAA
.rtc$IZZ
.rtc$TAA
.rtc$TZZ
.xdata
.xdata$x
.idata$2
.idata$3
.idata$4
.idata$6
.data$r
.pdata
.gfids$x
.gfids$y
.rsrc$01
.rsrc$02
AcquireCredentialsHandleW
AcceptSecurityContext
QuerySecurityContextToken
Secur32.dll
CreateThread
GetCurrentProcess
GetLastError
WTSGetActiveConsoleSessionId
KERNEL32.dll
GetTokenInformation
GetLengthSid
CopySid
LookupAccountSidW
LookupPrivilegeValueW
AdjustTokenPrivileges
OpenProcessToken
DuplicateTokenEx
CreateProcessWithTokenW
CreateProcessAsUserW
ADVAPI32.dll
CLSIDFromString
CoTaskMemAlloc
CoInitialize
CreateILockBytesOnHGlobal
StgCreateDocfileOnILockBytes
CoGetInstanceFromIStorage
ole32.dll
getaddrinfo
freeaddrinfo
WS2_32.dll
RtlCaptureContext
RtlLookupFunctionEntry
RtlVirtualUnwind
UnhandledExceptionFilter
SetUnhandledExceptionFilter
TerminateProcess
IsProcessorFeaturePresent
QueryPerformanceCounter
GetCurrentProcessId
GetCurrentThreadId
GetSystemTimeAsFileTime
InitializeSListHead
IsDebuggerPresent
GetStartupInfoW
GetModuleHandleW
EnterCriticalSection
LeaveCriticalSection
TryEnterCriticalSection
DeleteCriticalSection
WideCharToMultiByte
SetLastError
InitializeCriticalSectionAndSpinCount
CreateEventW
TlsAlloc
TlsGetValue
TlsSetValue
TlsFree
GetTickCount
GetProcAddress
RtlPcToFileHeader
EncodePointer
RaiseException
RtlUnwindEx
InterlockedPushEntrySList
InterlockedFlushSList
FreeLibrary
LoadLibraryExW
ExitProcess
GetModuleHandleExW
GetStdHandle
WriteFile
GetModuleFileNameW
MultiByteToWideChar
GetCommandLineA
GetCommandLineW
GetACP
HeapAlloc
HeapFree
CompareStringW
LCMapStringW
GetFileType
GetCurrentThread
FlushFileBuffers
GetConsoleCP
GetConsoleMode
CloseHandle
WaitForSingleObjectEx
FindClose
FindFirstFileExW
FindNextFileW
IsValidCodePage
GetOEMCP
GetCPInfo
GetEnvironmentStringsW
FreeEnvironmentStringsW
SetEnvironmentVariableW
SetStdHandle
GetStringTypeW
GetProcessHeap
SetFilePointerEx
WriteConsoleW
HeapSize
HeapReAlloc
CreateFileW
CreateTimerQueue
SetEvent
SignalObjectAndWait
SwitchToThread
SetThreadPriority
GetThreadPriority
GetLogicalProcessorInformation
CreateTimerQueueTimer
ChangeTimerQueueTimer
DeleteTimerQueueTimer
GetNumaHighestNodeNumber
GetProcessAffinityMask
SetThreadAffinityMask
RegisterWaitForSingleObject
UnregisterWait
GetThreadTimes
FreeLibraryAndExitThread
GetModuleHandleA
GetVersionExW
VirtualAlloc
VirtualFree
VirtualProtect
DuplicateHandle
ReleaseSemaphore
InterlockedPopEntrySList
QueryDepthSList
UnregisterWaitEx
LoadLibraryW
DecodePointer
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
.?AVtype_info@@
.?AVbad_alloc@std@@
.?AVexception@std@@
.?AVbad_array_new_length@std@@
.?AVinvalid_argument@std@@
.?AVlogic_error@std@@
.?AVlength_error@std@@
.?AVout_of_range@std@@
.?AVruntime_error@std@@
.?AVsystem_error@std@@
.?AV_System_error@std@@
.?AVerror_category@std@@
.?AV_Generic_error_category@std@@
.?AVstl_critical_section_interface@details@Concurrency@@
.?AVstl_critical_section_vista@details@Concurrency@@
.?AVstl_critical_section_win7@details@Concurrency@@
.?AVstl_critical_section_concrt@details@Concurrency@@
.?AVstl_condition_variable_interface@details@Concurrency@@
.?AVstl_condition_variable_vista@details@Concurrency@@
.?AVstl_condition_variable_win7@details@Concurrency@@
.?AVstl_condition_variable_concrt@details@Concurrency@@
.?AVbad_exception@std@@
.?AVimproper_lock@Concurrency@@
.?AVWaitBlock@details@Concurrency@@
.?AVSingleWaitBlock@details@Concurrency@@
.?AVMultiWaitBlock@details@Concurrency@@
.?AVWaitAllBlock@details@Concurrency@@
.?AVWaitAnyBlock@details@Concurrency@@
.?AVTimedSingleWaitBlock@details@Concurrency@@
.?AV?$_MallocaArrayHolder@PEAVContext@Concurrency@@@details@Concurrency@@
.?AVscheduler_resource_allocation_error@Concurrency@@
.?AVscheduler_worker_creation_error@Concurrency@@
.?AVunsupported_os@Concurrency@@
.?AVimproper_scheduler_attach@Concurrency@@
.?AVimproper_scheduler_reference@Concurrency@@
.?AVcontext_unblock_unbalanced@Concurrency@@
.?AVcontext_self_unblock@Concurrency@@
.?AVmissing_wait@Concurrency@@
.?AVinvalid_scheduler_policy_key@Concurrency@@
.?AVinvalid_scheduler_policy_value@Concurrency@@
.?AVinvalid_scheduler_policy_thread_specification@Concurrency@@
.?AVnested_scheduler_missing_detach@Concurrency@@
.?AVinvalid_oversubscribe_operation@Concurrency@@
.?AVinvalid_operation@Concurrency@@
.?AVResourceManager@details@Concurrency@@
.?AUIResourceManager@Concurrency@@
.?AUITopologyExecutionResource@Concurrency@@
.?AUITopologyNode@Concurrency@@
.?AUTopologyObject@GlobalCore@details@Concurrency@@
.?AUTopologyObject@GlobalNode@details@Concurrency@@
.?AVScheduleGroupBase@details@Concurrency@@
.?AVScheduleGroup@Concurrency@@
.?AVCacheLocalScheduleGroup@details@Concurrency@@
.?AVFairScheduleGroup@details@Concurrency@@
.?AVSchedulerBase@details@Concurrency@@
.?AVScheduler@Concurrency@@
.?AU_Chore@details@Concurrency@@
.?AVRealizedChore@details@Concurrency@@
.?AVCacheLocalScheduleGroupSegment@details@Concurrency@@
.?AVScheduleGroupSegmentBase@details@Concurrency@@
.?AVFairScheduleGroupSegment@details@Concurrency@@
.?AVContextBase@details@Concurrency@@
.?AVContext@Concurrency@@
.?AV_Interruption_exception@details@Concurrency@@
.?AV_RefCounter@details@Concurrency@@
.?AV_CancellationTokenRegistration@details@Concurrency@@
.?AVCancellationTokenRegistration_TaskProc@details@Concurrency@@
.?AV?$_MallocaArrayHolder@PEAVevent@Concurrency@@@details@Concurrency@@
.?AVExecutionResource@details@Concurrency@@
.?AUIExecutionResource@Concurrency@@
.?AVSchedulerProxy@details@Concurrency@@
.?AUISchedulerProxy@Concurrency@@
.?AVFreeThreadProxy@details@Concurrency@@
.?AVThreadProxy@details@Concurrency@@
.?AUIThreadProxy@Concurrency@@
.?AUIThreadProxyFactory@details@Concurrency@@
.?AVFreeThreadProxyFactory@details@Concurrency@@
.?AV?$ThreadProxyFactory@VFreeThreadProxy@details@Concurrency@@@details@Concurrency@@
.?AVVirtualProcessor@details@Concurrency@@
.?AVInternalContextBase@details@Concurrency@@
.?AUIExecutionContext@Concurrency@@
.?AVExternalContextBase@details@Concurrency@@
.?AVThreadScheduler@details@Concurrency@@
.?AUIScheduler@Concurrency@@
.?AVThreadInternalContext@details@Concurrency@@
.?AVVirtualProcessorRoot@details@Concurrency@@
.?AUIVirtualProcessorRoot@Concurrency@@
.?AVFreeVirtualProcessorRoot@details@Concurrency@@
.?AVThreadVirtualProcessor@details@Concurrency@@
.?AV_Ref_count_base@std@@
.?AV?$_Ref_count_obj_alloc@V__ExceptionPtr@@U?$_StaticAllocator@H@@@std@@
.?AV?$_Ref_count_obj@V__ExceptionPtr@@@std@@
.?AV__non_rtti_object@std@@
.?AVbad_typeid@std@@
.?AVbad_cast@std@@
.?AVIStorageTrigger@@
.?AUIStorage@@
.?AUIMarshal@@
.?AUIUnknown@@
<?xml version='1.0' encoding='UTF-8' standalone='yes'?>
<assembly xmlns='urn:schemas-microsoft-com:asm.v1' manifestVersion='1.0'>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v3">
<security>
<requestedPrivileges>
<requestedExecutionLevel level='asInvoker' uiAccess='false' />
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
kernel32.dll
advapi32
api-ms-win-core-fibers-l1-1-1
api-ms-win-core-synch-l1-2-0
kernel32
(null)
mscoree.dll
api-ms-win-appmodel-runtime-l1-1-1
api-ms-win-core-datetime-l1-1-1
api-ms-win-core-file-l2-1-1
api-ms-win-core-localization-l1-2-1
api-ms-win-core-localization-obsolete-l1-2-0
api-ms-win-core-processthreads-l1-1-2
api-ms-win-core-string-l1-1-0
api-ms-win-core-sysinfo-l1-2-1
api-ms-win-core-winrt-l1-1-0
api-ms-win-core-xstate-l2-1-0
api-ms-win-rtcore-ntuser-window-l1-1-0
api-ms-win-security-systemfunctions-l1-1-0
ext-ms-win-kernel32-package-current-l1-1-0
ext-ms-win-ntuser-dialogbox-l1-1-0
ext-ms-win-ntuser-windowstation-l1-1-0
user32
Sunday
Monday
Tuesday
Wednesday
Thursday
Friday
Saturday
January
February
August
September
October
November
December
MM/dd/yy
dddd, MMMM dd, yyyy
HH:mm:ss
((((( H
((((( H
(
zh-CHS
az-AZ-Latn
uz-UZ-Latn
kok-IN
syr-SY
div-MV
quz-BO
sr-SP-Latn
az-AZ-Cyrl
uz-UZ-Cyrl
quz-EC
sr-SP-Cyrl
quz-PE
smj-NO
bs-BA-Latn
smj-SE
sr-BA-Latn
sma-NO
sr-BA-Cyrl
sma-SE
sms-FI
smn-FI
zh-CHT
az-az-cyrl
az-az-latn
bs-ba-latn
div-mv
kok-in
quz-bo
quz-ec
quz-pe
sma-no
sma-se
smj-no
smj-se
smn-fi
sms-fi
sr-ba-cyrl
sr-ba-latn
sr-sp-cyrl
sr-sp-latn
syr-sy
uz-uz-cyrl
uz-uz-latn
zh-chs
zh-cht
CONOUT$
combase.dll
advapi32.dll
{00000306-0000-0000-c000-000000000046}
hello.stg
Negotiate
SYSTEM
{00000000-0000-0000-C000-000000000046}
{4991d34b-80a1-4291-83b6-3328366b9097}
SeImpersonatePrivilege
SeAssignPrimaryTokenPrivilege
winsta0\default
No antivirus signatures available.
No IRMA results available.