Static | ZeroBOX

PE Compile Time

2023-10-26 15:14:54

PE Imphash

b1586d63a786074f33bd0544b4df7b1c

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x0014b480 0x0014b600 5.56269539144
.rdata 0x0014d000 0x0000a40c 0x0000a600 4.78824173328
.data 0x00158000 0x000053a8 0x00001600 5.34369593469
.pdata 0x0015e000 0x00001014 0x00001200 5.00735766628
.rsrc 0x00160000 0x000005f8 0x00000600 3.94513035928

Resources

Name Offset Size Language Sub-language File type
RT_VERSION 0x00160200 0x000003f8 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_MANIFEST 0x001600a0 0x0000015a LANG_ENGLISH SUBLANG_ENGLISH_US ASCII text, with CRLF line terminators

Imports

Library KERNEL32.dll:
0x14014d070 HeapCreate
0x14014d078 GetProcAddress
0x14014d080 GetModuleHandleA
0x14014d088 WriteConsoleW
0x14014d090 CloseHandle
0x14014d098 CreateFileW
0x14014d0a0 SetFilePointerEx
0x14014d0a8 GetConsoleMode
0x14014d0b0 GetConsoleOutputCP
0x14014d0b8 FlushFileBuffers
0x14014d0c0 HeapReAlloc
0x14014d0c8 HeapSize
0x14014d0d0 GetProcessHeap
0x14014d0d8 LCMapStringW
0x14014d0e0 FlsFree
0x14014d0e8 FlsSetValue
0x14014d0f0 FlsGetValue
0x14014d0f8 FlsAlloc
0x14014d100 GetStringTypeW
0x14014d108 GetFileType
0x14014d110 SetStdHandle
0x14014d118 FreeEnvironmentStringsW
0x14014d120 GetEnvironmentStringsW
0x14014d128 WideCharToMultiByte
0x14014d130 MultiByteToWideChar
0x14014d138 GetCommandLineW
0x14014d140 GetCommandLineA
0x14014d148 GetCPInfo
0x14014d150 GetOEMCP
0x14014d158 GetACP
0x14014d160 IsValidCodePage
0x14014d168 FindNextFileW
0x14014d170 FindFirstFileExW
0x14014d178 FindClose
0x14014d180 HeapFree
0x14014d188 HeapAlloc
0x14014d190 GetModuleHandleExW
0x14014d198 TerminateProcess
0x14014d1a0 ExitProcess
0x14014d1a8 GetCurrentProcess
0x14014d1b0 GetModuleFileNameW
0x14014d1b8 WriteFile
0x14014d1c0 GetStdHandle
0x14014d1c8 RtlPcToFileHeader
0x14014d1d0 RaiseException
0x14014d1d8 EncodePointer
0x14014d1e0 LoadLibraryExW
0x14014d1e8 FreeLibrary
0x14014d1f0 TlsFree
0x14014d1f8 TlsSetValue
0x14014d200 TlsGetValue
0x14014d208 TlsAlloc
0x14014d218 DeleteCriticalSection
0x14014d220 LeaveCriticalSection
0x14014d228 QueryPerformanceCounter
0x14014d230 GetCurrentProcessId
0x14014d238 GetCurrentThreadId
0x14014d240 GetSystemTimeAsFileTime
0x14014d248 InitializeSListHead
0x14014d250 RtlCaptureContext
0x14014d258 RtlLookupFunctionEntry
0x14014d260 RtlVirtualUnwind
0x14014d268 IsDebuggerPresent
0x14014d270 UnhandledExceptionFilter
0x14014d280 GetStartupInfoW
0x14014d290 GetModuleHandleW
0x14014d298 RtlUnwindEx
0x14014d2a0 GetLastError
0x14014d2a8 SetLastError
0x14014d2b0 EnterCriticalSection
Library COMDLG32.dll:
0x14014d018 PageSetupDlgA
0x14014d020 GetOpenFileNameA
0x14014d028 GetSaveFileNameA
0x14014d030 GetFileTitleA
0x14014d038 FindTextA
0x14014d040 ReplaceTextA
0x14014d048 ChooseFontA
0x14014d050 PrintDlgA
0x14014d058 PrintDlgExA
0x14014d060 CommDlgExtendedError
Library ADVAPI32.dll:
0x14014d000 GetUserNameA
0x14014d008 DecryptFileA
Library ole32.dll:
0x14014d2d0 OleGetAutoConvert
0x14014d2d8 OleDoAutoConvert
0x14014d2e0 OleRegGetUserType
0x14014d2e8 OleGetIconOfFile
0x14014d2f0 IsAccelerator
0x14014d2f8 GetClassFile
0x14014d300 MonikerCommonPrefixWith
0x14014d308 MonikerRelativePathTo
0x14014d310 MkParseDisplayName
0x14014d318 CoInstall
0x14014d320 CoTreatAsClass
0x14014d328 CoDosDateTimeToFileTime
0x14014d330 CoIsOle1Class
0x14014d340 CoGetInstanceFromFile
0x14014d348 CoRevokeInitializeSpy
0x14014d350 CoRevokeMallocSpy
0x14014d358 CLSIDFromProgIDEx
0x14014d360 CoFileTimeNow
0x14014d368 CoTaskMemFree
0x14014d370 CoTaskMemRealloc
0x14014d378 CoTaskMemAlloc
0x14014d388 CoGetTreatAsClass
0x14014d390 CoWaitForMultipleHandles
0x14014d398 StringFromGUID2
0x14014d3a0 CLSIDFromProgID
0x14014d3a8 ProgIDFromCLSID
0x14014d3b0 IIDFromString
0x14014d3b8 StringFromIID
0x14014d3c0 CoGetInterceptor
0x14014d3c8 StringFromCLSID
0x14014d3d8 CoEnableCallCancellation
0x14014d3e0 CoTestCancel
0x14014d3e8 CoCancelCall
0x14014d3f0 CoGetCancelObject
0x14014d3f8 CoSwitchCallContext
0x14014d408 CoRevertToSelf
0x14014d410 CoImpersonateClient
0x14014d418 CoCopyProxy
0x14014d420 CoSetProxyBlanket
0x14014d428 CoQueryProxyBlanket
0x14014d430 CoGetCallContext
0x14014d440 CoGetStdMarshalEx
0x14014d448 CoLockObjectExternal
0x14014d450 CoDisconnectObject
0x14014d458 CoUnmarshalHresult
0x14014d460 CoMarshalHresult
0x14014d468 CoMarshalInterface
0x14014d470 CoGetMarshalSizeMax
0x14014d478 CoSuspendClassObjects
0x14014d480 CoResumeClassObjects
0x14014d488 CoGetClassObject
0x14014d490 CoGetObjectContext
0x14014d498 CoGetContextToken
0x14014d4a8 CoGetCallerTID
0x14014d4b0 CoUninitialize
0x14014d4b8 CoGetMalloc
0x14014d4c0 CLSIDFromString
Library dxgi.dll:
0x14014d2c0 CreateDXGIFactory

!This program cannot be run in DOS mode.
`.rdata
@.data
.pdata
@.rsrc
D$PHcD$ H
sEHcD$ H
HcL$ H
D$XHc@<H
D$(HcD$ H
sKHcD$ H
HcL$ H
D$(HcD$ H
sKHcD$ H
HcL$ H
D$(HcD$ H
sKHcD$ H
HcL$ H
D$(HcD$ H
sKHcD$ H
HcL$ H
ewML;:
a&+=L-
qME$LF
QI/Z[V
h*VHXw
R{.uc?;
j^__a)5R
Ly!z7~
_Sw`YuR[
J7jg@Q){
Rz"t`m
]'<Z:i
h"V2~hr
XPd"&<
T:[>h?
kw$69j
a{-PKY
Se{>9`
u:A_'m
cl &\Hf
pC#@0p
"kE81$
b)[mb(5
iE=/%Uq
.XQhSo
2BepU:
-!;}#
gjpfA=)
_^rv_V
Y>dlkF
16R8?CH4
e8zLB~f
pH?Hn}
WbCd"hHv
|r]t lg
h*-yqd
i_Nqhm^
v?Xq2l
O4c1lz4
\'igeMl
)RoCC
;TlJ0G
5^<T*=Z
uxGdGj
S>\}vD
1WZOKZ6
>xqrZP6v
t$~%Vf
ca8*wMr
a$4)Wn
R\3?4o
]@M$_%*[
z;)1qU
7fP14`
Gxd'NM
`7j?)ANuq
KqA5e3?7YN
?2mZ3a
v"P/|(
',0~a,J
XZ-LI$
O0WB/14kzW
0FVOzm
70mX}\
&(fg7)/7L
r5#,))-
-.sX?3
bsPyL%
)8x>u;
adRis"
8MNp6?3
;4@El|i
nT~NUM!
`9GB"lN
LhQxjp)A,
N>X'Od
rv"hMC
Rw=^$
c-DX.%
R5>&s/
4\[Kd_{
9I{kfGT
;u)O;T
'-{|}-
t$`;D$\u
|$,Zt&
D$(=/{
|$Pgts
Exqb&
X/#jjtQC
.Q90=W
#qXhkHC
SIjBIy
5`y9,zy
ZY=@ga
>.88 M!a
6#EE}KM
lm&,>0
`lrjS1h
FpOm*&^sH-T
W<M{W
7bg~Bu
XKf,3V
\byxyr
5i2rr&P
L%Hw^]
w8H8^xvMC"
D`ho*eX
3Q>&]a
R!;cy@t
x@YZ[b_OL
a,!A`zn
5~Ha{)
/=T+6U
}Emwg+%
$ `?;?
hR>"'i
O+5*Y5z6
Op,pET
[YM6u\Uhna
Z,0S+
lad`.b"
u,bZF7
}m1`J;
wRYc~aB
f<lHv^
3Oc||a
]rg0p_
e+R!FC
Eqy0<^
o`9Ue
\lQxKG
1ckj`J\
g(NgE'
tz6FE,
I,6?}:
Sh'SfxQ'R
D{u]w7
rtDHt.e
Q2cBgc
wm}m($1"N
Mv-D6Mk
5"PI`Xq
P>bN}X
.QMf1r
-ZwyH?
}Q9'MM
f7UGacj
,|!u.7
cpZ]$N
UKD(mvrX
ED^K|f2
On{&0Sr
Sc,"_i
/&[U`x
{]<nl#0A
Mp\2`*]
Pq ,DQ^
HS4ps:
qS? ?H
u/HcH<H
WATAUAVAWH
A_A^A]A\_
WATAUAVAWH
A_A^A]A\_
VWATAVAWH
A_A^A\_^
WATAUAVAWH
A_A^A]A\_
H;xXu5
AUAVAWH
u4I9}(
;I9}(tiH
0A_A^A]
UVWATAUAVAWH
`A_A^A]A\_^]
@USVWATAUAVAWH
A_A^A]A\_^[]
UVWATAUAVAWH
A_A^A]A\_^]
@SVWATAUAVAWH
L!|$(L!
D$0HcH
pA_A^A]A\_^[
B(I9A(u
SVWATAUAVAWH
0A_A^A]A\_^[
t$ WATAUAVAWH
A_A^A]A\_
WATAUAVAWH
A_A^A]A\_
UVWAVAWH
0A_A^_^]
p0R^G'
u3HcH<H
WAVAWH
A_A^_
WAVAWH
A_A^_
D$0@8{
p*W4H
p*W4H
u$D8r(t
D81uUL9r
uED8r(t
vAD8s(t
u$D8r(t
fD91uTL9r
uED8r(t
v@D8s(t
UVWATAUAVAWH
PA_A^A]A\_^]
WATAUAVAWH
0A_A^A]A\_
H9>u+A
@USVWATAUAVH
D8t$ht
D8t$ht
A^A]A\_^[]
f9)u4H9j
u%@8j(t
l$ VWATAVAWH
L$&8\$&t,8Y
A_A^A\_^
fD9t$b
@UATAUAVAWH
e0A_A^A]A\]
WATAUAVAWH
A_A^A]A\_
p0R^G'
t$ WATAUAVAWH
D!|$xA
A_A^A]A\_
L$ VWAVH
fD94H}aD
ATAUAVH
L$ fff
L$ |+L;
A^A]A\
@UATAUAVAWH
A_A^A]A\]
WAVAWH
A_A^_
UVWATAUAVAWH
fB9<I}1L
A_A^A]A\_^]
VWATAVAW
A_A^A\_^
VATAUAVAWH
0A_A^A]A\^
@USVWATAUAVAWH
H!D$ H
xA_A^A]A\_^[]
WATAUAVAWH
0A_A^A]A\_
ffffff
fffffff
@SUVWATAVAWH
@A_A^A\_^][
USVWAVH
A^_^[]
LcA<E3
fffffff
ffffff
vKfffff
fffffff
fffffff
__based(
__cdecl
__pascal
__stdcall
__thiscall
__fastcall
__vectorcall
__clrcall
__eabi
__swift_1
__swift_2
__swift_3
__ptr64
__restrict
__unaligned
restrict(
delete
operator
`vftable'
`vbtable'
`vcall'
`typeof'
`local static guard'
`string'
`vbase destructor'
`vector deleting destructor'
`default constructor closure'
`scalar deleting destructor'
`vector constructor iterator'
`vector destructor iterator'
`vector vbase constructor iterator'
`virtual displacement map'
`eh vector constructor iterator'
`eh vector destructor iterator'
`eh vector vbase constructor iterator'
`copy constructor closure'
`udt returning'
`local vftable'
`local vftable constructor closure'
new[]
delete[]
`omni callsig'
`placement delete closure'
`placement delete[] closure'
`managed vector constructor iterator'
`managed vector destructor iterator'
`eh vector copy constructor iterator'
`eh vector vbase copy constructor iterator'
`dynamic initializer for '
`dynamic atexit destructor for '
`vector copy constructor iterator'
`vector vbase copy constructor iterator'
`managed vector copy constructor iterator'
`local static thread guard'
operator ""
operator co_await
operator<=>
Type Descriptor'
Base Class Descriptor at (
Base Class Array'
Class Hierarchy Descriptor'
Complete Object Locator'
`anonymous namespace'
FlsAlloc
FlsFree
FlsGetValue
FlsSetValue
InitializeCriticalSectionEx
Unknown exception
bad exception
CorExitProcess
Sunday
Monday
Tuesday
Wednesday
Thursday
Friday
Saturday
January
February
August
September
October
November
December
MM/dd/yy
dddd, MMMM dd, yyyy
HH:mm:ss
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
AreFileApisANSI
LCMapStringEx
LocaleNameToLCID
AppPolicyGetProcessTerminationMethod
UUUUUU
UUUUUU
=imb;D
/>58d%
VM>cQ6
>jtm}S
)>6{1n
+f)>0'
;H9>&X
*StO9>T
n03>Pu
K~Je#>!
bp(=>?g
BC?>6t9^
K&>.yC
.xJ>Hf
y\PD>!
|b=})>
c [1>H'
uzKs@>
3>N;kU
kE>fvw
V6E>`"(5
?UUUUUU
?7zQ6$
.text$di
.text$mn
.text$mn$00
.text$mn$21
.text$x
.idata$5
.00cfg
.CRT$XCA
.CRT$XCAA
.CRT$XCU
.CRT$XCZ
.CRT$XIA
.CRT$XIAA
.CRT$XIAC
.CRT$XIC
.CRT$XIZ
.CRT$XPA
.CRT$XPX
.CRT$XPXA
.CRT$XPZ
.CRT$XTA
.CRT$XTZ
.rdata
.rdata$00
.rdata$r
.rdata$voltmd
.rdata$zzzdbg
.rtc$IAA
.rtc$IZZ
.rtc$TAA
.rtc$TZZ
.xdata
.xdata$x
.idata$2
.idata$3
.idata$4
.idata$6
.data$r
.data$rs
.pdata
.rsrc$01
.rsrc$02
GetModuleHandleA
GetProcAddress
HeapCreate
KERNEL32.dll
GetOpenFileNameA
GetSaveFileNameA
GetFileTitleA
FindTextA
ReplaceTextA
ChooseFontA
PrintDlgA
PrintDlgExA
CommDlgExtendedError
PageSetupDlgA
COMDLG32.dll
DecryptFileA
GetUserNameA
ADVAPI32.dll
CoGetMalloc
CoUninitialize
CoGetCallerTID
CoGetCurrentLogicalThreadId
CoGetContextToken
CoGetObjectContext
CoGetClassObject
CoResumeClassObjects
CoSuspendClassObjects
CoGetMarshalSizeMax
CoMarshalInterface
CoMarshalHresult
CoUnmarshalHresult
CoDisconnectObject
CoLockObjectExternal
CoGetStdMarshalEx
CoGetInterfaceAndReleaseStream
CoGetCallContext
CoQueryProxyBlanket
CoSetProxyBlanket
CoCopyProxy
CoImpersonateClient
CoRevertToSelf
CoQueryAuthenticationServices
CoSwitchCallContext
CoGetCancelObject
CoCancelCall
CoTestCancel
CoEnableCallCancellation
CoDisableCallCancellation
StringFromCLSID
CLSIDFromString
StringFromIID
IIDFromString
ProgIDFromCLSID
CLSIDFromProgID
StringFromGUID2
CoWaitForMultipleHandles
CoGetTreatAsClass
CoInvalidateRemoteMachineBindings
CoTaskMemAlloc
CoTaskMemRealloc
CoTaskMemFree
CoFileTimeNow
CLSIDFromProgIDEx
CoRevokeMallocSpy
CoRevokeInitializeSpy
CoGetInstanceFromFile
CoAllowSetForegroundWindow
CoIsOle1Class
CoDosDateTimeToFileTime
CoTreatAsClass
CoInstall
MkParseDisplayName
MonikerRelativePathTo
MonikerCommonPrefixWith
GetClassFile
IsAccelerator
OleGetIconOfFile
OleRegGetUserType
OleDoAutoConvert
OleGetAutoConvert
CoGetInterceptor
ole32.dll
CreateDXGIFactory
dxgi.dll
QueryPerformanceCounter
GetCurrentProcessId
GetCurrentThreadId
GetSystemTimeAsFileTime
InitializeSListHead
RtlCaptureContext
RtlLookupFunctionEntry
RtlVirtualUnwind
IsDebuggerPresent
UnhandledExceptionFilter
SetUnhandledExceptionFilter
GetStartupInfoW
IsProcessorFeaturePresent
GetModuleHandleW
RtlUnwindEx
GetLastError
SetLastError
EnterCriticalSection
LeaveCriticalSection
DeleteCriticalSection
InitializeCriticalSectionAndSpinCount
TlsAlloc
TlsGetValue
TlsSetValue
TlsFree
FreeLibrary
LoadLibraryExW
EncodePointer
RaiseException
RtlPcToFileHeader
GetStdHandle
WriteFile
GetModuleFileNameW
GetCurrentProcess
ExitProcess
TerminateProcess
GetModuleHandleExW
HeapAlloc
HeapFree
FindClose
FindFirstFileExW
FindNextFileW
IsValidCodePage
GetACP
GetOEMCP
GetCPInfo
GetCommandLineA
GetCommandLineW
MultiByteToWideChar
WideCharToMultiByte
GetEnvironmentStringsW
FreeEnvironmentStringsW
SetStdHandle
GetFileType
GetStringTypeW
FlsAlloc
FlsGetValue
FlsSetValue
FlsFree
LCMapStringW
GetProcessHeap
HeapSize
HeapReAlloc
FlushFileBuffers
GetConsoleOutputCP
GetConsoleMode
SetFilePointerEx
CreateFileW
CloseHandle
WriteConsoleW
n'&z{a
xv`X(S
6qdiHR~
AWkpZF
$$ ;Q;
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
.?AVbad_exception@std@@
.?AVexception@std@@
.?AVtype_info@@
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v3">
<security>
<requestedPrivileges>
<requestedExecutionLevel level="asInvoker" uiAccess="false"></requestedExecutionLevel>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
Prospectus
counsellor
mothered scales skids
billowed kickback
Cubicles millionaire birdcages Acorn Interment
perished
translated Enlightened Conjugal kitsch debater
Fracas Ineligible
dilating
mailorder translucent digging
Farmsteads enacting Halon Manhandled Worldwide
api-ms-win-core-fibers-l1-1-1
api-ms-win-core-synch-l1-2-0
kernel32
api-ms-
mscoree.dll
Sunday
Monday
Tuesday
Wednesday
Thursday
Friday
Saturday
January
February
August
September
October
November
December
MM/dd/yy
dddd, MMMM dd, yyyy
HH:mm:ss
((((( H
api-ms-win-core-datetime-l1-1-1
api-ms-win-core-file-l1-2-4
api-ms-win-core-file-l1-2-2
api-ms-win-core-localization-l1-2-1
api-ms-win-core-localization-obsolete-l1-2-0
api-ms-win-core-processthreads-l1-1-2
api-ms-win-core-string-l1-1-0
api-ms-win-core-sysinfo-l1-2-1
api-ms-win-core-winrt-l1-1-0
api-ms-win-core-xstate-l2-1-0
api-ms-win-rtcore-ntuser-window-l1-1-0
api-ms-win-security-systemfunctions-l1-1-0
ext-ms-win-ntuser-dialogbox-l1-1-0
ext-ms-win-ntuser-windowstation-l1-1-0
advapi32
kernelbase
api-ms-win-appmodel-runtime-l1-1-2
user32
ext-ms-
zh-CHS
az-AZ-Latn
uz-UZ-Latn
kok-IN
syr-SY
div-MV
quz-BO
sr-SP-Latn
az-AZ-Cyrl
uz-UZ-Cyrl
quz-EC
sr-SP-Cyrl
quz-PE
smj-NO
bs-BA-Latn
smj-SE
sr-BA-Latn
sma-NO
sr-BA-Cyrl
sma-SE
sms-FI
smn-FI
zh-CHT
az-az-cyrl
az-az-latn
bs-ba-latn
div-mv
kok-in
quz-bo
quz-ec
quz-pe
sma-no
sma-se
smj-no
smj-se
smn-fi
sms-fi
sr-ba-cyrl
sr-ba-latn
sr-sp-cyrl
sr-sp-latn
syr-sy
uz-uz-cyrl
uz-uz-latn
zh-chs
zh-cht
CONOUT$
VS_VERSION_INFO
StringFileInfo
040204E2
Comments
Disinfection suspected edict implants acclimatising
CompanyName
Transactor
FileDescription
Keepers musicology hallow reselection
FileVersion
3.86.84.0
InternalName
Carpentry
LegalCopyright
Copyright
Ague kayaks swindled visa minus
LegalTrademarks
Circumvents canard plaid
OriginalFilename
Admissions
ProductName
Standardise
ProductVersion
3.86.84.0
VarFileInfo
Translation
No antivirus signatures available.
No IRMA results available.