Static | ZeroBOX

PE Compile Time

2017-12-29 22:49:16

PDB Path

I:\RottenPotatoNG\RottenPotatoEXE\x64\Release\MSFRottenPotato.pdb

PE Imphash

0705dbbe2c1de90903291dcc72a5d6a0

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x00035d66 0x00035e00 6.40519448862
.rdata 0x00037000 0x00015fec 0x00016000 4.76302667557
.data 0x0004d000 0x00003830 0x00002400 3.86496824165
.pdata 0x00051000 0x00003b1c 0x00003c00 5.502640047
.rsrc 0x00055000 0x000001e0 0x00000200 4.71229819329
.reloc 0x00056000 0x00000cac 0x00000e00 5.23719233909

Resources

Name Offset Size Language Sub-language File type
RT_MANIFEST 0x00055060 0x0000017d LANG_ENGLISH SUBLANG_ENGLISH_US XML 1.0 document text

Imports

Library Secur32.dll:
0x1400373a0 AcceptSecurityContext
Library KERNEL32.dll:
0x140037028 CreateThread
0x140037030 Sleep
0x140037038 LoadLibraryW
0x140037040 GetLastError
0x140037048 GetCurrentProcess
0x140037050 GetModuleFileNameA
0x140037058 UnregisterWaitEx
0x140037060 QueryDepthSList
0x140037068 InterlockedPopEntrySList
0x140037070 ReleaseSemaphore
0x140037078 DuplicateHandle
0x140037080 VirtualFree
0x140037088 VirtualProtect
0x140037090 VirtualAlloc
0x140037098 GetVersionExW
0x1400370a0 GetModuleHandleA
0x1400370a8 FreeLibraryAndExitThread
0x1400370b0 GetThreadTimes
0x1400370b8 UnregisterWait
0x1400370c8 SetThreadAffinityMask
0x1400370d0 GetProcessAffinityMask
0x1400370d8 GetNumaHighestNodeNumber
0x1400370e0 DeleteTimerQueueTimer
0x1400370e8 ChangeTimerQueueTimer
0x1400370f0 CreateTimerQueueTimer
0x140037100 RtlCaptureContext
0x140037108 RtlLookupFunctionEntry
0x140037110 RtlVirtualUnwind
0x140037118 UnhandledExceptionFilter
0x140037128 TerminateProcess
0x140037138 QueryPerformanceCounter
0x140037140 GetCurrentProcessId
0x140037148 GetCurrentThreadId
0x140037150 GetSystemTimeAsFileTime
0x140037158 InitializeSListHead
0x140037160 IsDebuggerPresent
0x140037168 GetStartupInfoW
0x140037170 GetModuleHandleW
0x140037178 EnterCriticalSection
0x140037180 LeaveCriticalSection
0x140037188 TryEnterCriticalSection
0x140037190 DeleteCriticalSection
0x140037198 WideCharToMultiByte
0x1400371a0 SetLastError
0x1400371b0 CreateEventW
0x1400371b8 TlsAlloc
0x1400371c0 TlsGetValue
0x1400371c8 TlsSetValue
0x1400371d0 TlsFree
0x1400371d8 GetTickCount
0x1400371e0 GetProcAddress
0x1400371e8 RtlUnwindEx
0x1400371f0 RtlPcToFileHeader
0x1400371f8 EncodePointer
0x140037200 RaiseException
0x140037210 InterlockedFlushSList
0x140037218 FreeLibrary
0x140037220 LoadLibraryExW
0x140037228 GetStdHandle
0x140037230 WriteFile
0x140037238 GetModuleFileNameW
0x140037240 DecodePointer
0x140037248 MultiByteToWideChar
0x140037250 ExitProcess
0x140037258 GetModuleHandleExW
0x140037260 GetCommandLineA
0x140037268 GetCommandLineW
0x140037270 GetACP
0x140037278 HeapAlloc
0x140037280 HeapFree
0x140037288 CompareStringW
0x140037290 LCMapStringW
0x140037298 GetFileType
0x1400372a0 GetCurrentThread
0x1400372a8 CloseHandle
0x1400372b0 WaitForSingleObjectEx
0x1400372b8 FindClose
0x1400372c0 FindFirstFileExA
0x1400372c8 FindNextFileA
0x1400372d0 IsValidCodePage
0x1400372d8 GetOEMCP
0x1400372e0 GetCPInfo
0x1400372e8 GetEnvironmentStringsW
0x1400372f0 FreeEnvironmentStringsW
0x1400372f8 SetEnvironmentVariableA
0x140037300 SetStdHandle
0x140037308 GetStringTypeW
0x140037310 GetProcessHeap
0x140037318 FlushFileBuffers
0x140037320 GetConsoleCP
0x140037328 GetConsoleMode
0x140037330 HeapSize
0x140037338 HeapReAlloc
0x140037340 SetFilePointerEx
0x140037348 WriteConsoleW
0x140037350 CreateFileW
0x140037358 CreateTimerQueue
0x140037360 SetEvent
0x140037368 SignalObjectAndWait
0x140037370 SwitchToThread
0x140037378 SetThreadPriority
0x140037380 GetThreadPriority
Library ADVAPI32.dll:
0x140037000 AdjustTokenPrivileges
0x140037008 LookupPrivilegeValueW
0x140037010 OpenProcessToken
0x140037018 CreateProcessWithTokenW
Library ole32.dll:
0x140037430 CoTaskMemAlloc
0x140037438 CLSIDFromString
0x140037450 CoInitialize
Library WS2_32.dll:
0x1400373b0 shutdown
0x1400373b8 recv
0x1400373c0 send
0x1400373c8 closesocket
0x1400373d0 connect
0x1400373d8 freeaddrinfo
0x1400373e0 socket
0x1400373e8 WSACleanup
0x1400373f0 getaddrinfo
0x1400373f8 WSAStartup
0x140037400 accept
0x140037408 select
0x140037410 bind
0x140037418 listen
0x140037420 WSAGetLastError

Exports

Ordinal Address Name
1 0x1400018b0 ??0CMSFRottenPotato@@QEAA@XZ
2 0x140001870 ??4CMSFRottenPotato@@QEAAAEAV0@$$QEAV0@@Z
3 0x140001850 ??4CMSFRottenPotato@@QEAAAEAV0@AEBV0@@Z
4 0x140001890 ?__autoclassinit2@CMSFRottenPotato@@QEAAX_K@Z
5 0x140001ac0 ?findNTLMBytes@CMSFRottenPotato@@AEAAHPEADH@Z
6 0x140050810 ?newConnection@CMSFRottenPotato@@0HA
7 0x140001b20 ?processNtlmBytes@CMSFRottenPotato@@AEAAHPEADH@Z
8 0x140002140 ?startCOMListener@CMSFRottenPotato@@QEAAHXZ
9 0x140001a50 ?startCOMListenerThread@CMSFRottenPotato@@QEAAKXZ
10 0x140001db0 ?startRPCConnection@CMSFRottenPotato@@QEAAHXZ
11 0x140001a00 ?startRPCConnectionThread@CMSFRottenPotato@@QEAAKXZ
12 0x140001ab0 ?staticStartCOMListener@CMSFRottenPotato@@CAKPEAX@Z
13 0x140001aa0 ?staticStartRPCConnection@CMSFRottenPotato@@CAKPEAX@Z
14 0x140001c80 ?triggerDCOM@CMSFRottenPotato@@QEAAHXZ
!This program cannot be run in DOS mode.
`.rdata
@.data
.pdata
@.rsrc
@.reloc
L$ SVWH
@UATAUAVAWH
A_A^A]A\]
D$ NTLMf
D$$SSL
D$&PMc
D$HNTLML
D$LSSH
CXE;SPr6Ic
@UWATAVAWH
A_A^A\_]
@UWATAVAWH
A_A^A\_]
H3E H3E
SVWAVH
8A^_^[
t$ WAVAWH
A9FHtI
9D$(}y
A9FHtQI
@A_A^_
@SUVWATAVAWH
@A_A^A\_^][
VWATAVAWH
A_A^A\_^
x ATAVAWH
A_A^A\
H;xXu9
VWATAVAWH
A_A^A\_^
B(I9A(
UATAUAVAWH
L9`8tA
A_A^A]A\]
UVWATAUAVAWH
pA_A^A]A\_^]
WATAUAVAWH
A_A^A]A\_
AUAVAWH
I9}(t9H
0A_A^A]
@SVWATAUAVAWH
L!|$(L!
D$0HcH
pA_A^A]A\_^[
SVWATAUAVAWH
0A_A^A]A\_^[
WATAUAVAWH
r 9_ t
ri9V vdH
A_A^A]A\_
WATAUAVAWH
A_A^A]A\_
ffffff
WATAUAVAWH
A_A^A]A\_
D$@H;G
S,, <Zw
CA< t(<#t
<htr<jtb<lt6<tt&<wt
!,X< w
t$ WAVAWH
s4+sP+
0A_A^_
WAVAWH
A_A^_
x ATAVAWH
A_A^A\
UVWAVAWH
0A_A^_^]
WAVAWH
A86taH
0A_A^_
u3HcH<H
L$ WATAUAVAWH
@A_A^A]A\_
x ATAVAWH
A_A^A\
|$ UATAUAVAWH
A_A^A]A\]
WATAUAVAWH
A_A^A]A\_
WAVAWH
@A_A^_
fD9t$b
D82u&H
D8t$Ht
x ATAVAWH
gfffffffH
D8d$ht
A_A^A\
WATAUAVAWH
A_A^A]A\_
UVWATAUAVAWH
`A_A^A]A\_^]
x ATAVAWH
0A_A^A\
\$ UVWAVAWH
A_A^_^]
@8|$^t
l$ VWATAVAWH
L$&@8t$&t0@8q
A81t@@8r
A_A^A\_^
fD94Fu
UVWATAUAVAWH
0A_A^A]A\_^]
I96t4H
xWI96tRI
@8t$p@
@UATAUAVAWH
e0A_A^A]A\]
SVWATAUAWH
HA_A]A\_^[
UVWATAUAVAWH
A_A^A]A\_^]
VWATAVAW
A_A^A\_^
WATAUAVAWH
A_A^A]A\_
\$ UVWATAUAVAWH
H!D$ E
`A_A^A]A\_^]
@UATAUAVAWH
H!T$0D
uf!T$(H!T$
A_A^A]A\]
@USVWATAUAVAWH
D8l$ht
A_A^A]A\_^[]
l$ WAVAWH
A_A^_
@UATAVH
WATAUAVAWH
A_A^A]A\_
ffffff
fffffff
@USVWATAUAVAWH
e8A_A^A]A\_^[]
|$ ATAVAWH
\$@@8=
A_A^A\
USVWAVH
A^_^[]
{ ATAVAWH
A_A^A\
C0H9C(r
WAVAWH
0A_A^_
WAVAWH
A_A^_
WAVAWH
A_A^_
WAVAWH
@UATAUAVAWH
A_A^A]A\]
UVWATAUAVAWH
H+D$hH+D$P3
A_A^A]A\_^]
H3\$HH
UVWATAUAVAWH
A_A^A]A\_^]
VWAUAVAWH
A_A^A]_^
WATAUAVAWH
A_A^A]A\_
\$ UVWH
UVWATAUAVAWH
L$`tcA
A_A^A]A\_^]
UVWATAUAVAWH
A,A9A(v&L
0A_A^A]A\_^]
WATAUAVAWH
O,D9O(vcH
0A_A^A]A\_
WATAUAVAWH
A;H$v}H
A;H$sH
0A_A^A]A\_
SUVWATAUAVAWH
HA_A^A]A\_^][
@VWAVH
SUVWATAUAVAWH
\$4E;O
;B$vvI
D$0tbA
D$0C+D0(
@09D$0
D$PE;O
H$E+H,toA
R(A9P4A
@(A+@4;
xA_A^A]A\_^][
WATAUAVAWH
C9|)$u?C
0A_A^A]A\_
VWAUAVAWH
A`D9L8
;B$vUH
,t0D9J0v*L
0A_A^A]_^
t$ WATAUAVAWH
D8M@t^
+J$D8M@
D8M@tM
0A_A^A]A\_
UVWATAUAVAWH
0A_A^A]A\_^]
t$ WATAUAVAWH
A_A^A]A\_
UVWATAUAVAWH
D;5eC
A_A^A]A\_^]
L$ UVWATAUAVAWH
0A_A^A]A\_^]
x ATAVAWH
0A_A^A\
@SUVWATAVAWH
0A_A^A\_^][
9G$vAD
D9G$s5
l$ VWATAUAVAWE3
D9x(uiE
A(9B(D
X(D9y(
t'B;|
l$PA_A^A]A\_^
WATAUAVAWH
A_A^A]A\_
H9_ht0H
WATAUAVAWH
A_A^A]A\_
x ATAVA
A$+A,t[3
|$0A^A\
WATAUAVAWH
0A_A^A]A\_
UVWATAUAVAWH
l$`C9,
A_A^A]A\_^]
x AVE3
UVWATAUAVAWH
D;z,v(A
&D;j0u
A_A^A]A\_^]
E8X@t8A
R0E8XAt
B0E8XAt
WAVAWH
WAVAWH
9oP~3E3
A_A^_
VWAUAVAWH
9WP~HM
uxHcOP
HcGl;Gh}
A_A^A]_^
t H9X8tN
9YD~/3
9_D~/3
x AVE2
t*H9X8u$@8
E;Bl}NE
|$ UATAUAVAWH
q(9YD~tE3
9_D~H3
A_A^A]A\]
x ATAVAWH
A_A^A\
t$Pu1H
USVWATAUAVAWH
~(HcNDI
F8HcNDI
F0LcFDI
D9f@~0Hc
A_A^A]A\_^[]
|$ AVH
UVWATAUAVAWH
0A_A^A]A\_^]
;Ct~bH
;Ct~MH
V`;Ct~bH
;Ct~MH
|$ UAVAWH
x ATAVAWH
C(9C u&
C,9C$u
A_A^A\
H!\$(L
D$ !\$$H
H!\$03
91~/E3
VWAUAVAWH
9WP~KM
uxHcOP
HcGl;Gh}
A_A^A]_^
A;>}I
WATAUAVAWH
A_A^A]A\_
H;YXt
twH;^XtH3
t$H;^Xt
tGH;~XtA
V0;Ct~ZH
;Ct~EH
A;6}#I
91~/E3
|$ AVH
WAVAWH
A_A^_
9D$`t_
@UAVAWH
e@A_A^]
WATAUAVAWH
A_A^A]A\_
WATAUAVAWH
0A_A^A]A\_
WATAUAVAWH
0A_A^A]A\_
WATAUAVAWH
A_A^A]A\_
L9w t#H
WAVAWH
A_A^_
H9J t1
UVWATAUAVAWH
v A9~ w
D9d$(u
uh@8|$!t,
uOD;d$(uH
5@8|$"t.9|
tP@8|$!u4@8|$"t-
`A_A^A]A\_^]
@VWATAVAWH
0A_A^A\_^
UVWAVAWH
A_A^_^]
WAVAWH
A_A^_
WAVAWH
A_A^_
UVWAVAWH
PA_A^_^]
u)!t$(H
;Ct~ZH
;Ct~EH
WAVAWH
A_A^_
F(LcF I
WAVAWH
9oP~2E3
A_A^_
VWAUAVAWH
9WP~KM
uxHcOP
HcGl;Gh}
A_A^A]_^
x ATAVAWH
A_A^A\
UWAUAVAWH
A_A^A]_]
UVWATAVH
@A^A\_^]
UVWAVAWH
`A_A^_^]
UATAUAVAWH
A_A^A]A\]
SUVWATAUAVAWH
8A_A^A]A\_^][
UVWATAUAVAWH
8\$`tH
A_A^A]A\_^]
u!!D$(H
UVWAVAWH
@A_A^_^]
UVWATAUAVAWH
@A_A^A]A\_^]
UWATAVAWH
A_A^A\_]
WAVAWH
0A_A^_
` UAVAWH
WAVAWH
9oP~2E3
A_A^_
;Ct~ZH
;Ct~EH
WAVAWH
9_P~OE3
A_A^_
K4A+H
VWAUAVAWH
9WP~GM
uxHcOP
HcGl;Gh}
A_A^A]_^
VWAUAVAWH
9WP~KM
uxHcOP
HcGl;Gh}
A_A^A]_^
UWATAVAWH
A_A^A\_]
u%!D$@H
WAVAWH
K 9N v@H
0A_A^_
t$ WAVAWH
;Vl}fD
A_A^_
l$ VWAVH
UAVAWH
;Ct~ZH
;Ct~EH
UVWATAUAVAWH
8D$ u+I
A_A^A]A\_^]
C4D+@ H
UVWATAUAVAWH
0A_A^A]A\_^]
WAVAWH
A_A^_
Hc;HcK
WAVAWH
A_A^_
H9BhuTH
~`8A!t
SVWATAVAWH
XA_A^A\_^[
D$0f;UPu
WAVAWH
@A_A^_
u!!D$(H
ATAVAWH
0A_A^A\
WAVAWH
0A_A^_
ATAVAWH
0A_A^A\
H#t$0tB
@USVWATAUAVAWH
H+G H=
A_A^A]A\_^[]
@SUVWATAUAVAWH
H+C H=
A_A^A]A\_^][
WATAUAVAWH
A_A^A]A\_
WATAUAVAWH
@A_A^A]A\_
WATAUAVAWH
A_A^A]A\_
x ATAVAWH
A_A^A\
x ATAVAWH
A_A^A\
UAVAWH
@A_A^]
UAVAWH
@A_A^]
t.8\$P
SVWAVH
8A^_^[
WAVAWH
LcA<E3
WAVAWH
0A_A^_
@WAVAWH
0A_A^_
D$@csm
VWATAUAVAWL
|$XHcU
D$8HcJ
H;D$Pu
l$HA_A^A]A\_^
x AVHcA
SUVWATAUAVAWH
H9D$PuCI
A_A^A]A\_^][
WATAUAVAWH
A_A^A]A\_
>ffffff
fffffff
ffffff
Unknown exception
bad allocation
bad array new length
device or resource busy
invalid argument
no such process
not enough memory
operation not permitted
resource deadlock would occur
resource unavailable try again
generic
string too long
invalid string position
address family not supported
address in use
address not available
already connected
argument list too long
argument out of domain
bad address
bad file descriptor
bad message
broken pipe
connection aborted
connection already in progress
connection refused
connection reset
cross device link
destination address required
directory not empty
executable format error
file exists
file too large
filename too long
function not supported
host unreachable
identifier removed
illegal byte sequence
inappropriate io control operation
interrupted
invalid seek
io error
is a directory
message size
network down
network reset
network unreachable
no buffer space
no child process
no link
no lock available
no message available
no message
no protocol option
no space on device
no stream resources
no such device or address
no such device
no such file or directory
not a directory
not a socket
not a stream
not connected
not supported
operation canceled
operation in progress
operation not supported
operation would block
owner dead
permission denied
protocol error
protocol not supported
read only file system
result out of range
state not recoverable
stream timeout
text file busy
timed out
too many files open in system
too many files open
too many links
too many symbolic link levels
value too large
wrong protocol type
unknown error
FlsAlloc
FlsFree
FlsGetValue
FlsSetValue
InitializeCriticalSectionEx
InitOnceExecuteOnce
CreateEventExW
CreateSemaphoreW
CreateSemaphoreExW
CreateThreadpoolTimer
SetThreadpoolTimer
WaitForThreadpoolTimerCallbacks
CloseThreadpoolTimer
CreateThreadpoolWait
SetThreadpoolWait
CloseThreadpoolWait
FlushProcessWriteBuffers
FreeLibraryWhenCallbackReturns
GetCurrentProcessorNumber
CreateSymbolicLinkW
GetCurrentPackageId
GetTickCount64
GetFileInformationByHandleEx
SetFileInformationByHandle
GetSystemTimePreciseAsFileTime
InitializeConditionVariable
WakeConditionVariable
WakeAllConditionVariable
SleepConditionVariableCS
InitializeSRWLock
AcquireSRWLockExclusive
TryAcquireSRWLockExclusive
ReleaseSRWLockExclusive
SleepConditionVariableSRW
CreateThreadpoolWork
SubmitThreadpoolWork
CloseThreadpoolWork
CompareStringEx
GetLocaleInfoEx
LCMapStringEx
bad exception
Base Class Descriptor at (
Base Class Array'
Class Hierarchy Descriptor'
Complete Object Locator'
__based(
__cdecl
__pascal
__stdcall
__thiscall
__fastcall
__vectorcall
__clrcall
__eabi
__ptr64
__restrict
__unaligned
restrict(
delete
operator
`vftable'
`vbtable'
`vcall'
`typeof'
`local static guard'
`string'
`vbase destructor'
`vector deleting destructor'
`default constructor closure'
`scalar deleting destructor'
`vector constructor iterator'
`vector destructor iterator'
`vector vbase constructor iterator'
`virtual displacement map'
`eh vector constructor iterator'
`eh vector destructor iterator'
`eh vector vbase constructor iterator'
`copy constructor closure'
`udt returning'
`local vftable'
`local vftable constructor closure'
new[]
delete[]
`omni callsig'
`placement delete closure'
`placement delete[] closure'
`managed vector constructor iterator'
`managed vector destructor iterator'
`eh vector copy constructor iterator'
`eh vector vbase copy constructor iterator'
`dynamic initializer for '
`dynamic atexit destructor for '
`vector copy constructor iterator'
`vector vbase copy constructor iterator'
`managed vector copy constructor iterator'
`local static thread guard'
operator ""
operator co_await
Type Descriptor'
`h````
xpxxxx
(null)
CorExitProcess
LocaleNameToLCID
RoInitialize
RoUninitialize
NAN(SNAN)
nan(snan)
NAN(IND)
nan(ind)
Sunday
Monday
Tuesday
Wednesday
Thursday
Friday
Saturday
January
February
August
September
October
November
December
MM/dd/yy
dddd, MMMM dd, yyyy
HH:mm:ss
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
[aOni*{
~ $s%r
@b;zO]
v2!L.2
1#QNAN
1#SNAN
UUUUUU
UUUUUU
=imb;D
/>58d%
VM>cQ6
>jtm}S
)>6{1n
+f)>0'
;H9>&X
*StO9>T
n03>Pu
K~Je#>!
bp(=>?g
BC?>6t9^
K&>.yC
.xJ>Hf
y\PD>!
|b=})>
c [1>H'
uzKs@>
3>N;kU
kE>fvw
V6E>`"(5
?UUUUUU
?7zQ6$
Lock already taken
pEvents
SetThreadGroupAffinity
GetThreadGroupAffinity
GetCurrentProcessorNumberEx
GetLogicalProcessorInformationEx
pScheduler
version
eventObject
ppVirtualProcessorRoots
SchedulerKind
MaxConcurrency
MinConcurrency
TargetOversubscriptionFactor
LocalContextCacheSize
ContextStackSize
ContextPriority
SchedulingProtocol
DynamicProgressFeedback
WinRTInitialization
MaxPolicyElementKey
Mbp?333333
pContext
pExecutionResource
CreateRemoteThreadEx
CreateUmsCompletionList
CreateUmsThreadContext
DeleteProcThreadAttributeList
DeleteUmsCompletionList
DeleteUmsThreadContext
DequeueUmsCompletionListItems
EnterUmsSchedulingMode
ExecuteUmsThread
GetCurrentUmsThread
GetNextUmsListItem
GetUmsCompletionListEvent
InitializeProcThreadAttributeList
QueryUmsThreadInformation
SetUmsThreadInformation
UmsThreadYield
UpdateProcThreadAttribute
RegisterTraceGuidsW
UnregisterTraceGuids
TraceEvent
GetTraceLoggerHandle
GetTraceEnableLevel
GetTraceEnableFlags
pThreadProxy
switchState
Access violation - no RTTI data!
Bad dynamic_cast!
?UUUUUU
?UUUUUU
?UUUUUU
?UUUUUU
?8bunz8
?@En[vP
[*ncd>0
S>$hkDh$h>[2
UA>N0Wl
Error in AquireCredentialsHandle
Buffer sizes incompatible - can't replace
Error - Unknown NTLM message type...
127.0.0.1
WSAStartup failed with error: %d
getaddrinfo failed with error: %d
socket failed with error: %ld
Unable to connect to server!
RPC -> send failed with error: %d
RPC -> bytes Sent: %ld
RPC -> bytes received: %d
RPC-> Connection closed
RPC -> recv failed with error: %d
bind failed with error: %d
listen failed with error: %d
accept failed with error: %d
COM -> bytes received: %d
COM -> send failed with error: %d
COM -> bytes sent: %d
Connection closing...
COM -> recv failed with error: %d
shutdown failed with error: %d
Running %S with args %S
[-] Failed to create proc: %d
Waiting for auth...
Auth result: %d
Return code: %d
Last error: %d
deque<T> too long
I:\RottenPotatoNG\RottenPotatoEXE\x64\Release\MSFRottenPotato.pdb
.text$di
.text$mn
.text$mn$00
.text$x
.text$yd
.idata$5
.00cfg
.CRT$XCA
.CRT$XCAA
.CRT$XCC
.CRT$XCU
.CRT$XCZ
.CRT$XIA
.CRT$XIAA
.CRT$XIAC
.CRT$XIC
.CRT$XIZ
.CRT$XPA
.CRT$XPB
.CRT$XPX
.CRT$XPXA
.CRT$XPZ
.CRT$XTA
.CRT$XTZ
.rdata
.rdata$r
.rdata$zzzdbg
.rtc$IAA
.rtc$IZZ
.rtc$TAA
.rtc$TZZ
.xdata
.xdata$x
.edata
.idata$2
.idata$3
.idata$4
.idata$6
.data$r
.pdata
.rsrc$01
.rsrc$02
MSFRottenPotato.exe
??0CMSFRottenPotato@@QEAA@XZ
??4CMSFRottenPotato@@QEAAAEAV0@$$QEAV0@@Z
??4CMSFRottenPotato@@QEAAAEAV0@AEBV0@@Z
?__autoclassinit2@CMSFRottenPotato@@QEAAX_K@Z
?findNTLMBytes@CMSFRottenPotato@@AEAAHPEADH@Z
?newConnection@CMSFRottenPotato@@0HA
?processNtlmBytes@CMSFRottenPotato@@AEAAHPEADH@Z
?startCOMListener@CMSFRottenPotato@@QEAAHXZ
?startCOMListenerThread@CMSFRottenPotato@@QEAAKXZ
?startRPCConnection@CMSFRottenPotato@@QEAAHXZ
?startRPCConnectionThread@CMSFRottenPotato@@QEAAKXZ
?staticStartCOMListener@CMSFRottenPotato@@CAKPEAX@Z
?staticStartRPCConnection@CMSFRottenPotato@@CAKPEAX@Z
?triggerDCOM@CMSFRottenPotato@@QEAAHXZ
AcquireCredentialsHandleW
AcceptSecurityContext
QuerySecurityContextToken
Secur32.dll
CreateThread
GetCurrentProcess
GetLastError
KERNEL32.dll
OpenProcessToken
LookupPrivilegeValueW
AdjustTokenPrivileges
CreateProcessWithTokenW
ADVAPI32.dll
CLSIDFromString
CoTaskMemAlloc
CoInitialize
CreateILockBytesOnHGlobal
StgCreateDocfileOnILockBytes
CoGetInstanceFromIStorage
ole32.dll
getaddrinfo
freeaddrinfo
WS2_32.dll
RtlCaptureContext
RtlLookupFunctionEntry
RtlVirtualUnwind
UnhandledExceptionFilter
SetUnhandledExceptionFilter
TerminateProcess
IsProcessorFeaturePresent
QueryPerformanceCounter
GetCurrentProcessId
GetCurrentThreadId
GetSystemTimeAsFileTime
InitializeSListHead
IsDebuggerPresent
GetStartupInfoW
GetModuleHandleW
EnterCriticalSection
LeaveCriticalSection
TryEnterCriticalSection
DeleteCriticalSection
WideCharToMultiByte
SetLastError
InitializeCriticalSectionAndSpinCount
CreateEventW
TlsAlloc
TlsGetValue
TlsSetValue
TlsFree
GetTickCount
GetProcAddress
RtlUnwindEx
RtlPcToFileHeader
EncodePointer
RaiseException
InterlockedPushEntrySList
InterlockedFlushSList
FreeLibrary
LoadLibraryExW
GetStdHandle
WriteFile
GetModuleFileNameW
GetModuleFileNameA
MultiByteToWideChar
ExitProcess
GetModuleHandleExW
GetCommandLineA
GetCommandLineW
GetACP
HeapAlloc
HeapFree
CompareStringW
LCMapStringW
GetFileType
GetCurrentThread
CloseHandle
WaitForSingleObjectEx
FindClose
FindFirstFileExA
FindNextFileA
IsValidCodePage
GetOEMCP
GetCPInfo
GetEnvironmentStringsW
FreeEnvironmentStringsW
SetEnvironmentVariableA
SetStdHandle
GetStringTypeW
GetProcessHeap
FlushFileBuffers
GetConsoleCP
GetConsoleMode
HeapSize
HeapReAlloc
SetFilePointerEx
WriteConsoleW
CreateFileW
CreateTimerQueue
SetEvent
SignalObjectAndWait
SwitchToThread
SetThreadPriority
GetThreadPriority
GetLogicalProcessorInformation
CreateTimerQueueTimer
ChangeTimerQueueTimer
DeleteTimerQueueTimer
GetNumaHighestNodeNumber
GetProcessAffinityMask
SetThreadAffinityMask
RegisterWaitForSingleObject
UnregisterWait
GetThreadTimes
FreeLibraryAndExitThread
GetModuleHandleA
GetVersionExW
VirtualAlloc
VirtualProtect
VirtualFree
DuplicateHandle
ReleaseSemaphore
InterlockedPopEntrySList
QueryDepthSList
UnregisterWaitEx
LoadLibraryW
DecodePointer
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
.?AVtype_info@@
.?AVbad_alloc@std@@
.?AVexception@std@@
.?AVbad_array_new_length@std@@
.?AVinvalid_argument@std@@
.?AVlogic_error@std@@
.?AVlength_error@std@@
.?AVout_of_range@std@@
.?AVruntime_error@std@@
.?AVsystem_error@std@@
.?AV_System_error@std@@
.?AVerror_category@std@@
.?AV_Generic_error_category@std@@
.?AVstl_critical_section_interface@details@Concurrency@@
.?AVstl_critical_section_vista@details@Concurrency@@
.?AVstl_critical_section_win7@details@Concurrency@@
.?AVstl_critical_section_concrt@details@Concurrency@@
.?AVstl_condition_variable_interface@details@Concurrency@@
.?AVstl_condition_variable_vista@details@Concurrency@@
.?AVstl_condition_variable_win7@details@Concurrency@@
.?AVstl_condition_variable_concrt@details@Concurrency@@
.?AVbad_exception@std@@
.?AVimproper_lock@Concurrency@@
.?AVWaitBlock@details@Concurrency@@
.?AVSingleWaitBlock@details@Concurrency@@
.?AVMultiWaitBlock@details@Concurrency@@
.?AVWaitAllBlock@details@Concurrency@@
.?AVWaitAnyBlock@details@Concurrency@@
.?AVTimedSingleWaitBlock@details@Concurrency@@
.?AV?$_MallocaArrayHolder@PEAVContext@Concurrency@@@details@Concurrency@@
.?AVscheduler_resource_allocation_error@Concurrency@@
.?AVscheduler_worker_creation_error@Concurrency@@
.?AVunsupported_os@Concurrency@@
.?AVimproper_scheduler_attach@Concurrency@@
.?AVimproper_scheduler_reference@Concurrency@@
.?AVcontext_unblock_unbalanced@Concurrency@@
.?AVcontext_self_unblock@Concurrency@@
.?AVmissing_wait@Concurrency@@
.?AVinvalid_scheduler_policy_key@Concurrency@@
.?AVinvalid_scheduler_policy_value@Concurrency@@
.?AVinvalid_scheduler_policy_thread_specification@Concurrency@@
.?AVnested_scheduler_missing_detach@Concurrency@@
.?AVinvalid_oversubscribe_operation@Concurrency@@
.?AVinvalid_operation@Concurrency@@
.?AVResourceManager@details@Concurrency@@
.?AUIResourceManager@Concurrency@@
.?AUITopologyExecutionResource@Concurrency@@
.?AUITopologyNode@Concurrency@@
.?AUTopologyObject@GlobalCore@details@Concurrency@@
.?AUTopologyObject@GlobalNode@details@Concurrency@@
.?AVScheduleGroupBase@details@Concurrency@@
.?AVScheduleGroup@Concurrency@@
.?AVCacheLocalScheduleGroup@details@Concurrency@@
.?AVFairScheduleGroup@details@Concurrency@@
.?AVSchedulerBase@details@Concurrency@@
.?AVScheduler@Concurrency@@
.?AU_Chore@details@Concurrency@@
.?AVRealizedChore@details@Concurrency@@
.?AVCacheLocalScheduleGroupSegment@details@Concurrency@@
.?AVScheduleGroupSegmentBase@details@Concurrency@@
.?AVFairScheduleGroupSegment@details@Concurrency@@
.?AVContextBase@details@Concurrency@@
.?AVContext@Concurrency@@
.?AV_Interruption_exception@details@Concurrency@@
.?AV_RefCounter@details@Concurrency@@
.?AV_CancellationTokenRegistration@details@Concurrency@@
.?AVCancellationTokenRegistration_TaskProc@details@Concurrency@@
.?AV?$_MallocaArrayHolder@PEAVevent@Concurrency@@@details@Concurrency@@
.?AVExecutionResource@details@Concurrency@@
.?AUIExecutionResource@Concurrency@@
.?AVSchedulerProxy@details@Concurrency@@
.?AUISchedulerProxy@Concurrency@@
.?AVFreeThreadProxy@details@Concurrency@@
.?AVThreadProxy@details@Concurrency@@
.?AUIThreadProxy@Concurrency@@
.?AUIThreadProxyFactory@details@Concurrency@@
.?AVFreeThreadProxyFactory@details@Concurrency@@
.?AV?$ThreadProxyFactory@VFreeThreadProxy@details@Concurrency@@@details@Concurrency@@
.?AVVirtualProcessor@details@Concurrency@@
.?AVInternalContextBase@details@Concurrency@@
.?AUIExecutionContext@Concurrency@@
.?AVExternalContextBase@details@Concurrency@@
.?AVThreadScheduler@details@Concurrency@@
.?AUIScheduler@Concurrency@@
.?AVThreadInternalContext@details@Concurrency@@
.?AVVirtualProcessorRoot@details@Concurrency@@
.?AUIVirtualProcessorRoot@Concurrency@@
.?AVFreeVirtualProcessorRoot@details@Concurrency@@
.?AVThreadVirtualProcessor@details@Concurrency@@
.?AV_Ref_count_base@std@@
.?AV?$_Ref_count_obj_alloc@V__ExceptionPtr@@U?$_StaticAllocator@H@@@std@@
.?AV?$_Ref_count_obj@V__ExceptionPtr@@@std@@
.?AV__non_rtti_object@std@@
.?AVbad_typeid@std@@
.?AVbad_cast@std@@
.?AVIStorageTrigger@@
.?AUIStorage@@
.?AUIMarshal@@
.?AUIUnknown@@
<?xml version='1.0' encoding='UTF-8' standalone='yes'?>
<assembly xmlns='urn:schemas-microsoft-com:asm.v1' manifestVersion='1.0'>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v3">
<security>
<requestedPrivileges>
<requestedExecutionLevel level='asInvoker' uiAccess='false' />
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
kernel32.dll
api-ms-win-core-fibers-l1-1-1
api-ms-win-core-synch-l1-2-0
kernel32
api-ms-
ext-ms-
(null)
mscoree.dll
api-ms-win-appmodel-runtime-l1-1-1
api-ms-win-core-datetime-l1-1-1
api-ms-win-core-file-l2-1-1
api-ms-win-core-localization-l1-2-1
api-ms-win-core-localization-obsolete-l1-2-0
api-ms-win-core-processthreads-l1-1-2
api-ms-win-core-string-l1-1-0
api-ms-win-core-sysinfo-l1-2-1
api-ms-win-core-winrt-l1-1-0
api-ms-win-core-xstate-l2-1-0
api-ms-win-rtcore-ntuser-window-l1-1-0
api-ms-win-security-systemfunctions-l1-1-0
ext-ms-win-kernel32-package-current-l1-1-0
ext-ms-win-ntuser-dialogbox-l1-1-0
ext-ms-win-ntuser-windowstation-l1-1-0
advapi32
user32
Sunday
Monday
Tuesday
Wednesday
Thursday
Friday
Saturday
January
February
August
September
October
November
December
MM/dd/yy
dddd, MMMM dd, yyyy
HH:mm:ss
((((( H
zh-CHS
az-AZ-Latn
uz-UZ-Latn
kok-IN
syr-SY
div-MV
quz-BO
sr-SP-Latn
az-AZ-Cyrl
uz-UZ-Cyrl
quz-EC
sr-SP-Cyrl
quz-PE
smj-NO
bs-BA-Latn
smj-SE
sr-BA-Latn
sma-NO
sr-BA-Cyrl
sma-SE
sms-FI
smn-FI
zh-CHT
az-az-cyrl
az-az-latn
bs-ba-latn
div-mv
kok-in
quz-bo
quz-ec
quz-pe
sma-no
sma-se
smj-no
smj-se
smn-fi
sms-fi
sr-ba-cyrl
sr-ba-latn
sr-sp-cyrl
sr-sp-latn
syr-sy
uz-uz-cyrl
uz-uz-latn
zh-chs
zh-cht
CONOUT$
combase.dll
advapi32.dll
{00000306-0000-0000-c000-000000000046}
hello.stg
Negotiate
{4991d34b-80a1-4291-83b6-3328366b9097}
{00000000-0000-0000-C000-000000000046}
SeImpersonatePrivilege
C:\Windows\System32\cmd.exe
Antivirus Signature
Bkav W64.AIDetectMalware
Lionic Trojan.Win32.RottenPotato.4!c
tehtris Clean
ClamAV Win.Tool.Rottenpotato-9822591-0
CMC Clean
CAT-QuickHeal Clean
Skyhigh RDN/Generic PUP.z
ALYac Exploit.RottenPotato.A
Cylance Unsafe
Zillya Tool.JuicyPotato.Win64.13
Sangfor PUP.Win32.Rottenpotato.Vtxv
K7AntiVirus Trojan ( 0054919b1 )
Alibaba Trojan:Win32/RottenPotato.0367648b
K7GW Trojan ( 0054919b1 )
Cybereason malicious.c962e7
huorong HackTool/Potato.b
Baidu Clean
VirIT Clean
Paloalto generic.ml
Symantec Hacktool.Rotpotato!g1
Elastic malicious (high confidence)
ESET-NOD32 a variant of Win64/HackTool.JuicyPotato.D
APEX Clean
Avast Clean
Cynet Malicious (score: 99)
Kaspersky HEUR:Trojan.Win32.RottenPotato.a
BitDefender Exploit.RottenPotato.A
NANO-Antivirus Trojan.Win64.RottenPotato.ggktja
ViRobot Clean
MicroWorld-eScan Exploit.RottenPotato.A
Tencent Malware.Win32.Gencirc.11a35b41
TACHYON Clean
Sophos ATK/RPotato-A
F-Secure Trojan.TR/JuicyPotato.zdeuc
DrWeb Clean
VIPRE Exploit.RottenPotato.A
TrendMicro TROJ_GEN.R002C0PH523
McAfeeD ti!0FB342F94F35
Trapmine suspicious.low.ml.score
FireEye Generic.mg.3fc6176c962e7a70
Emsisoft Exploit.RottenPotato.A (B)
Ikarus Trojan.Win64.Hacktool
GData Exploit.RottenPotato.A
Jiangmin Trojan.RottenPotato.cd
Webroot W32.Adware.Gen
Varist W64/JuicyPotato.C.gen!Eldorado
Avira TR/JuicyPotato.zdeuc
Antiy-AVL HackTool/Win64.JuicyPotato
Kingsoft Clean
Gridinsoft Trojan.Win64.Downloader.oa!s1
Xcitium Malware@#2gv803ec2hv58
Arcabit Exploit.RottenPotato.A
SUPERAntiSpyware Clean
ZoneAlarm HEUR:Trojan.Win32.RottenPotato.a
Microsoft PUA:Win32/Presenoker
Google Detected
AhnLab-V3 HackTool/Win.RottenPotato.R649243
Acronis Clean
McAfee RDN/Generic PUP.z
MAX Clean
VBA32 Trojan.RottenPotato
Malwarebytes RiskWare.HackTool
Panda PUP/Hacktool
Zoner Clean
TrendMicro-HouseCall TROJ_GEN.R002C0PH523
Rising Trojan.RottenPotato!8.112DE (CLOUD)
Yandex Trojan.GenAsa!Q0+kINxFBkI
SentinelOne Clean
MaxSecure Trojan.Malware.74528077.susgen
Fortinet W64/JuicyPotato.D!tr
BitDefenderTheta Clean
AVG Clean
DeepInstinct MALICIOUS
CrowdStrike win/malicious_confidence_100% (W)
alibabacloud HackTool:Win/Juicypotato
No IRMA results available.