Static | ZeroBOX

PE Compile Time

2024-01-11 23:44:38

PDB Path

E:\source\SSP_Exec\x64\Release\SSP_Exec.pdb

PE Imphash

f92f2e35c4a67c9bde631a2e24d5fdc4

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x00004160 0x00004200 6.28701918578
.rdata 0x00006000 0x000023f6 0x00002400 4.31886718834
.data 0x00009000 0x00002a30 0x00000200 0.55149855128
.pdata 0x0000c000 0x000003b4 0x00000400 3.820785103
_RDATA 0x0000d000 0x0000015c 0x00000200 2.79210041594
.rsrc 0x0000e000 0x000001e0 0x00000200 4.70150325825
.reloc 0x0000f000 0x00000124 0x00000200 3.4648006596

Resources

Name Offset Size Language Sub-language File type
RT_MANIFEST 0x0000e060 0x0000017d LANG_ENGLISH SUBLANG_ENGLISH_US XML 1.0 document text

Imports

Library api-ms-win-crt-string-l1-1-0.dll:
0x140006200 _wcsicmp
0x140006208 strncpy
0x140006210 strncat
0x140006218 wcsnlen
0x140006220 wcsncmp
Library api-ms-win-crt-convert-l1-1-0.dll:
0x1400060e8 mbstowcs
Library api-ms-win-crt-stdio-l1-1-0.dll:
0x1400061d8 __stdio_common_vfprintf
0x1400061e0 __acrt_iob_func
0x1400061e8 _set_fmode
0x1400061f0 __p__commode
Library api-ms-win-crt-runtime-l1-1-0.dll:
0x140006140 _initialize_onexit_table
0x140006150 _crt_atexit
0x140006160 _c_exit
0x140006168 _cexit
0x140006170 __p___argv
0x140006178 __p___argc
0x140006188 _configure_narrow_argv
0x140006190 exit
0x140006198 terminate
0x1400061a0 _initterm
0x1400061a8 _initterm_e
0x1400061b0 abort
0x1400061b8 _exit
0x1400061c0 _set_app_type
0x1400061c8 _seh_filter_exe
Library api-ms-win-crt-math-l1-1-0.dll:
0x140006128 __setusermatherr
Library api-ms-win-crt-locale-l1-1-0.dll:
0x140006118 _configthreadlocale
Library api-ms-win-crt-heap-l1-1-0.dll:
0x1400060f8 free
0x140006100 calloc
0x140006108 _set_new_mode
Library KERNEL32.dll:
0x140006000 GetLastError
0x140006008 GetCurrentProcess
0x140006010 LoadLibraryExW
0x140006018 GetProcAddress
0x140006020 FreeLibrary
0x140006028 TlsFree
0x140006030 TlsSetValue
0x140006038 TlsGetValue
0x140006040 TlsAlloc
0x140006050 DeleteCriticalSection
0x140006058 SetLastError
0x140006060 RtlUnwindEx
0x140006068 GetModuleHandleW
0x140006080 UnhandledExceptionFilter
0x140006088 IsDebuggerPresent
0x140006090 RtlVirtualUnwind
0x140006098 RtlLookupFunctionEntry
0x1400060a0 RtlCaptureContext
0x1400060a8 InitializeSListHead
0x1400060b0 GetSystemTimeAsFileTime
0x1400060b8 GetCurrentThreadId
0x1400060c0 GetCurrentProcessId
0x1400060c8 QueryPerformanceCounter
0x1400060d0 Sleep
0x1400060d8 TerminateProcess

!This program cannot be run in DOS mode.
`.rdata
@.data
.pdata
@_RDATA
@.rsrc
@.reloc
WAVAWH
|$ ATAVAWH
A_A^A\
t$ WAVAWH
0A_A^_
L$ SVWH
=ntdlu
=l.dlt
fE9:uIE3
y\-zQH
H3E H3E
u/HcH<H
WATAUAVAWH
A_A^A]A\_
fffffff
ffffff
vKfffff
WATAUAVAWH
A_A^A]A\_
ffffff
fffffff
LcA<E3
__based(
__cdecl
__pascal
__stdcall
__thiscall
__fastcall
__vectorcall
__clrcall
__eabi
__swift_1
__swift_2
__swift_3
__ptr64
__restrict
__unaligned
restrict(
delete
operator
`vftable'
`vbtable'
`vcall'
`typeof'
`local static guard'
`string'
`vbase destructor'
`vector deleting destructor'
`default constructor closure'
`scalar deleting destructor'
`vector constructor iterator'
`vector destructor iterator'
`vector vbase constructor iterator'
`virtual displacement map'
`eh vector constructor iterator'
`eh vector destructor iterator'
`eh vector vbase constructor iterator'
`copy constructor closure'
`udt returning'
`local vftable'
`local vftable constructor closure'
new[]
delete[]
`omni callsig'
`placement delete closure'
`placement delete[] closure'
`managed vector constructor iterator'
`managed vector destructor iterator'
`eh vector copy constructor iterator'
`eh vector vbase copy constructor iterator'
`dynamic initializer for '
`dynamic atexit destructor for '
`vector copy constructor iterator'
`vector vbase copy constructor iterator'
`managed vector copy constructor iterator'
`local static thread guard'
operator ""
operator co_await
operator<=>
Type Descriptor'
Base Class Descriptor at (
Base Class Array'
Class Hierarchy Descriptor'
Complete Object Locator'
`anonymous namespace'
FlsAlloc
FlsFree
FlsGetValue
FlsSetValue
InitializeCriticalSectionEx
You must provide a full path: %s
ENT BASE
Done, status: SEC_E_SECPKG_NOT_FOUND, this is normal if DllMain returns FALSE
Done, status: 0x%lx
E:\source\SSP_Exec\x64\Release\SSP_Exec.pdb
.text$mn
.text$mn$00
.text$x
.idata$5
.00cfg
.CRT$XCA
.CRT$XCAA
.CRT$XCZ
.CRT$XIA
.CRT$XIAA
.CRT$XIAC
.CRT$XIZ
.CRT$XPA
.CRT$XPZ
.CRT$XTA
.CRT$XTZ
.rdata
.rdata$voltmd
.rdata$zzzdbg
.rtc$IAA
.rtc$IZZ
.rtc$TAA
.rtc$TZZ
.xdata
.idata$2
.idata$3
.idata$4
.idata$6
.pdata
_RDATA
.rsrc$01
.rsrc$02
wcsnlen
mbstowcs
_wcsicmp
strncpy
strncat
__acrt_iob_func
__stdio_common_vfprintf
_seh_filter_exe
_set_app_type
__setusermatherr
_configure_narrow_argv
_initialize_narrow_environment
_get_initial_narrow_environment
_initterm
_initterm_e
_set_fmode
__p___argc
__p___argv
_cexit
_c_exit
_register_thread_local_exe_atexit_callback
_configthreadlocale
_set_new_mode
__p__commode
_initialize_onexit_table
_register_onexit_function
_crt_atexit
terminate
api-ms-win-crt-string-l1-1-0.dll
api-ms-win-crt-convert-l1-1-0.dll
api-ms-win-crt-stdio-l1-1-0.dll
api-ms-win-crt-runtime-l1-1-0.dll
api-ms-win-crt-math-l1-1-0.dll
api-ms-win-crt-locale-l1-1-0.dll
api-ms-win-crt-heap-l1-1-0.dll
GetLastError
QueryPerformanceCounter
GetCurrentProcessId
GetCurrentThreadId
GetSystemTimeAsFileTime
InitializeSListHead
RtlCaptureContext
RtlLookupFunctionEntry
RtlVirtualUnwind
IsDebuggerPresent
UnhandledExceptionFilter
SetUnhandledExceptionFilter
IsProcessorFeaturePresent
GetModuleHandleW
KERNEL32.dll
calloc
wcsncmp
RtlUnwindEx
SetLastError
DeleteCriticalSection
InitializeCriticalSectionAndSpinCount
TlsAlloc
TlsGetValue
TlsSetValue
TlsFree
FreeLibrary
GetProcAddress
LoadLibraryExW
GetCurrentProcess
TerminateProcess
<?xml version='1.0' encoding='UTF-8' standalone='yes'?>
<assembly xmlns='urn:schemas-microsoft-com:asm.v1' manifestVersion='1.0'>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v3">
<security>
<requestedPrivileges>
<requestedExecutionLevel level='asInvoker' uiAccess='false' />
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
api-ms-win-core-fibers-l1-1-1
api-ms-win-core-synch-l1-2-0
kernel32
api-ms-
ntdll.dll
SSPICLI.DLL
Antivirus Signature
Bkav Clean
Lionic Clean
tehtris Clean
ClamAV Clean
CMC Clean
CAT-QuickHeal Clean
Skyhigh Clean
ALYac Clean
Cylance Clean
Zillya Clean
Sangfor Clean
K7AntiVirus Clean
Alibaba Clean
K7GW Clean
Cybereason Clean
Baidu Clean
VirIT Clean
Paloalto Clean
Symantec Clean
Elastic malicious (moderate confidence)
ESET-NOD32 Clean
APEX Malicious
Avast Clean
Cynet Clean
Kaspersky Clean
BitDefender Clean
NANO-Antivirus Clean
ViRobot Clean
MicroWorld-eScan Clean
Tencent Clean
TACHYON Clean
Sophos Clean
F-Secure Clean
DrWeb Clean
VIPRE Clean
TrendMicro Clean
McAfeeD ti!494E94D57CA2
Trapmine Clean
FireEye Clean
Emsisoft Clean
huorong Clean
GData Clean
Jiangmin Clean
Webroot Clean
Varist Clean
Avira Clean
Antiy-AVL Clean
Kingsoft Clean
Gridinsoft Clean
Xcitium Clean
Arcabit Clean
SUPERAntiSpyware Clean
ZoneAlarm Clean
Microsoft Trojan:Win32/Casdet!rfn
Google Clean
AhnLab-V3 Clean
Acronis Clean
McAfee Clean
MAX Clean
VBA32 Clean
Malwarebytes Clean
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Rising Clean
Yandex Clean
Ikarus Clean
MaxSecure Clean
Fortinet Clean
BitDefenderTheta Clean
AVG Clean
DeepInstinct Clean
CrowdStrike Clean
alibabacloud Clean
No IRMA results available.