Static | ZeroBOX

PE Compile Time

2024-01-11 23:45:48

PDB Path

E:\source\NanoDump_DLL_V1\x64\Release\NanoDump_DLL.pdb

PE Imphash

5ee28f7400f81bcba9b73317c7b0e6e9

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x00004820 0x00004a00 6.24972295827
.rdata 0x00006000 0x00002358 0x00002400 4.22287455791
.data 0x00009000 0x00002cb0 0x00000200 1.20812463609
.pdata 0x0000c000 0x000003e4 0x00000400 4.07527571627
_RDATA 0x0000d000 0x0000015c 0x00000200 2.76207582846
.rsrc 0x0000e000 0x000001e0 0x00000200 4.7085533373
.reloc 0x0000f000 0x0000011c 0x00000200 3.41623839067

Resources

Name Offset Size Language Sub-language File type
RT_MANIFEST 0x0000e060 0x0000017d LANG_ENGLISH SUBLANG_ENGLISH_US XML 1.0 document text

Imports

Library api-ms-win-crt-string-l1-1-0.dll:
0x180006190 wcsncpy
0x180006198 wcsncat
0x1800061a0 _wcsicmp
0x1800061a8 wcsncmp
0x1800061b0 wcsnlen
Library api-ms-win-crt-convert-l1-1-0.dll:
0x180006110 mbstowcs
Library api-ms-win-crt-utility-l1-1-0.dll:
0x1800061d0 rand
0x1800061d8 srand
Library api-ms-win-crt-time-l1-1-0.dll:
0x1800061c0 _time64
Library api-ms-win-crt-runtime-l1-1-0.dll:
0x180006138 _cexit
0x180006140 _initialize_onexit_table
0x180006150 _seh_filter_dll
0x180006158 terminate
0x180006160 _initterm_e
0x180006168 _configure_narrow_argv
0x180006170 abort
0x180006178 _initterm
0x180006180 _execute_onexit_table
Library KERNEL32.dll:
0x180006000 GetCurrentProcessId
0x180006008 LoadLibraryExW
0x180006010 FreeLibrary
0x180006018 TlsFree
0x180006020 TlsSetValue
0x180006028 TlsGetValue
0x180006030 TlsAlloc
0x180006040 DeleteCriticalSection
0x180006048 SetLastError
0x180006050 InterlockedFlushSList
0x180006058 RtlUnwindEx
0x180006070 UnhandledExceptionFilter
0x180006078 IsDebuggerPresent
0x180006080 RtlVirtualUnwind
0x180006088 RtlLookupFunctionEntry
0x180006090 RtlCaptureContext
0x180006098 InitializeSListHead
0x1800060a0 GetSystemTimeAsFileTime
0x1800060a8 GetCurrentThreadId
0x1800060b0 TerminateProcess
0x1800060b8 QueryPerformanceCounter
0x1800060c0 VirtualProtect
0x1800060c8 GetCurrentProcess
0x1800060d0 VirtualAlloc
0x1800060d8 GetModuleHandleA
0x1800060e0 GetProcAddress
0x1800060e8 HeapAlloc
0x1800060f0 GetProcessHeap
0x1800060f8 HeapFree
0x180006100 GetLastError
Library api-ms-win-crt-heap-l1-1-0.dll:
0x180006120 free
0x180006128 calloc

Exports

Ordinal Address Name
1 0x1800012f0 DllMain
!This program cannot be run in DOS mode.
`.rdata
@.data
.pdata
@_RDATA
@.rsrc
@.reloc
@USVWAVAWH
A_A^_^[]
UATAUAVAWH
A_A^A]A\]
t$ UWATAVAWH
A_A^A\_]
x UATAUAVAWH
A_A^A]A\]
|$ UAVAWH
t$ WATAUAV
=ntdlu
=l.dlt
t$@A^A]A\_
y\-zQH
|$ AVH
H3E H3E
WATAUAVAWH
A_A^A]A\_
fffffff
ffffff
vKfffff
ffffff
fffffff
WATAUAVAWH
A_A^A]A\_
LcA<E3
__based(
__cdecl
__pascal
__stdcall
__thiscall
__fastcall
__vectorcall
__clrcall
__eabi
__swift_1
__swift_2
__swift_3
__ptr64
__restrict
__unaligned
restrict(
delete
operator
`vftable'
`vbtable'
`vcall'
`typeof'
`local static guard'
`string'
`vbase destructor'
`vector deleting destructor'
`default constructor closure'
`scalar deleting destructor'
`vector constructor iterator'
`vector destructor iterator'
`vector vbase constructor iterator'
`virtual displacement map'
`eh vector constructor iterator'
`eh vector destructor iterator'
`eh vector vbase constructor iterator'
`copy constructor closure'
`udt returning'
`local vftable'
`local vftable constructor closure'
new[]
delete[]
`omni callsig'
`placement delete closure'
`placement delete[] closure'
`managed vector constructor iterator'
`managed vector destructor iterator'
`eh vector copy constructor iterator'
`eh vector vbase copy constructor iterator'
`dynamic initializer for '
`dynamic atexit destructor for '
`vector copy constructor iterator'
`vector vbase copy constructor iterator'
`managed vector copy constructor iterator'
`local static thread guard'
operator ""
operator co_await
operator<=>
Type Descriptor'
Base Class Descriptor at (
Base Class Array'
Class Hierarchy Descriptor'
Complete Object Locator'
`anonymous namespace'
FlsAlloc
FlsFree
FlsGetValue
FlsSetValue
InitializeCriticalSectionEx
NtDelayExecution
ntdll.dll
E:\source\NanoDump_DLL_V1\x64\Release\NanoDump_DLL.pdb
.text$mn
.text$mn$00
.text$x
.idata$5
.00cfg
.CRT$XCA
.CRT$XCZ
.CRT$XIA
.CRT$XIZ
.CRT$XPA
.CRT$XPZ
.CRT$XTA
.CRT$XTZ
.rdata
.rdata$voltmd
.rdata$zzzdbg
.rtc$IAA
.rtc$IZZ
.rtc$TAA
.rtc$TZZ
.xdata
.edata
.idata$2
.idata$3
.idata$4
.idata$6
.pdata
_RDATA
.rsrc$01
.rsrc$02
NanoDump_DLL.dll
DllMain
wcsnlen
mbstowcs
_wcsicmp
wcsncat
wcsncpy
_time64
_initterm
_initterm_e
_seh_filter_dll
_configure_narrow_argv
_initialize_narrow_environment
_initialize_onexit_table
_execute_onexit_table
_cexit
terminate
api-ms-win-crt-string-l1-1-0.dll
api-ms-win-crt-convert-l1-1-0.dll
api-ms-win-crt-utility-l1-1-0.dll
api-ms-win-crt-time-l1-1-0.dll
api-ms-win-crt-runtime-l1-1-0.dll
VirtualProtect
GetCurrentProcess
VirtualAlloc
GetModuleHandleA
GetProcAddress
HeapAlloc
GetProcessHeap
HeapFree
GetLastError
QueryPerformanceCounter
GetCurrentProcessId
GetCurrentThreadId
GetSystemTimeAsFileTime
InitializeSListHead
RtlCaptureContext
RtlLookupFunctionEntry
RtlVirtualUnwind
IsDebuggerPresent
UnhandledExceptionFilter
SetUnhandledExceptionFilter
IsProcessorFeaturePresent
KERNEL32.dll
calloc
wcsncmp
api-ms-win-crt-heap-l1-1-0.dll
RtlUnwindEx
InterlockedFlushSList
SetLastError
DeleteCriticalSection
InitializeCriticalSectionAndSpinCount
TlsAlloc
TlsGetValue
TlsSetValue
TlsFree
FreeLibrary
LoadLibraryExW
TerminateProcess
C:\Users\Public\Event_Log_2024_01.txt
<?xml version='1.0' encoding='UTF-8' standalone='yes'?>
<assembly xmlns='urn:schemas-microsoft-com:asm.v1' manifestVersion='1.0'>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v3">
<security>
<requestedPrivileges>
<requestedExecutionLevel level='asInvoker' uiAccess='false' />
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
api-ms-win-core-fibers-l1-1-1
api-ms-win-core-synch-l1-2-0
kernel32
api-ms-
lsasrv.dll
msv1_0.dll
tspkg.dll
wdigest.dll
kerberos.dll
livessp.dll
dpapisrv.dll
kdcsvc.dll
cryptdll.dll
lsadb.dll
samsrv.dll
rsaenh.dll
ncrypt.dll
Antivirus Signature
Bkav Clean
Lionic Clean
tehtris Clean
ClamAV Clean
CMC Clean
CAT-QuickHeal Clean
Skyhigh Clean
ALYac Clean
Cylance Clean
Zillya Clean
Sangfor Clean
K7AntiVirus Clean
Alibaba Clean
K7GW Clean
Cybereason Clean
huorong Clean
Baidu Clean
VirIT Clean
Paloalto Clean
Symantec Clean
Elastic malicious (high confidence)
ESET-NOD32 Clean
APEX Clean
Avast Clean
Cynet Malicious (score: 100)
Kaspersky Clean
BitDefender Clean
NANO-Antivirus Clean
ViRobot Clean
MicroWorld-eScan Clean
Tencent Clean
TACHYON Clean
Sophos ATK/NanoDump-A
F-Secure Clean
DrWeb Clean
VIPRE Clean
TrendMicro Clean
McAfeeD Clean
Trapmine Clean
FireEye Clean
Emsisoft Clean
Ikarus Clean
GData Clean
Jiangmin Clean
Webroot Clean
Varist Clean
Avira Clean
Antiy-AVL Clean
Kingsoft Clean
Gridinsoft Clean
Xcitium Clean
Arcabit Clean
SUPERAntiSpyware Clean
ZoneAlarm Clean
Microsoft Worm:Win32/Gamarue!ml
Google Detected
AhnLab-V3 Clean
Acronis Clean
McAfee Clean
MAX Clean
VBA32 Clean
Malwarebytes Clean
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Rising Clean
Yandex Clean
SentinelOne Clean
MaxSecure Clean
Fortinet Clean
BitDefenderTheta Clean
AVG Clean
DeepInstinct Clean
CrowdStrike Clean
alibabacloud Clean
No IRMA results available.