Static | ZeroBOX

PE Compile Time

2024-07-14 23:37:27

PDB Path

C:\Users\удача\Desktop\tesf\Release\BigProject.pdb

PE Imphash

afd948c78bfbef3259852978f4a77212

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x0003f520 0x0003f600 6.1258671166
.rdata 0x00041000 0x0000814e 0x00008200 4.72576496027
.data 0x0004a000 0x00001880 0x00000c00 2.12254394782
.reloc 0x0004c000 0x000013ac 0x00001400 6.41833842988

Imports

Library KERNEL32.dll:
0x441000 LoadLibraryA
0x441004 GetProcAddress
0x441008 FreeLibrary
0x44100c CreateFileW
0x441010 RaiseException
0x441024 EncodePointer
0x441028 DecodePointer
0x44102c MultiByteToWideChar
0x441030 WideCharToMultiByte
0x441034 GetStringTypeW
0x441038 GetCPInfo
0x441044 GetCurrentProcessId
0x441048 GetCurrentThreadId
0x441050 InitializeSListHead
0x441054 IsDebuggerPresent
0x441060 GetStartupInfoW
0x441064 GetModuleHandleW
0x441068 GetCurrentProcess
0x44106c TerminateProcess
0x441070 RtlUnwind
0x441074 GetLastError
0x441078 SetLastError
0x441080 TlsAlloc
0x441084 TlsGetValue
0x441088 TlsSetValue
0x44108c TlsFree
0x441090 LoadLibraryExW
0x441094 GetStdHandle
0x441098 WriteFile
0x44109c GetModuleFileNameW
0x4410a0 ExitProcess
0x4410a4 GetModuleHandleExW
0x4410a8 LCMapStringW
0x4410ac HeapFree
0x4410b0 HeapAlloc
0x4410b4 HeapReAlloc
0x4410b8 GetFileType
0x4410bc FindClose
0x4410c0 FindFirstFileExW
0x4410c4 FindNextFileW
0x4410c8 IsValidCodePage
0x4410cc GetACP
0x4410d0 GetOEMCP
0x4410d4 GetCommandLineA
0x4410d8 GetCommandLineW
0x4410e4 SetStdHandle
0x4410e8 GetProcessHeap
0x4410ec SetFilePointerEx
0x4410f0 HeapSize
0x4410f4 FlushFileBuffers
0x4410f8 GetConsoleOutputCP
0x4410fc GetConsoleMode
0x441100 CloseHandle
0x441104 WriteConsoleW

!This program cannot be run in DOS mode.
`.rdata
@.data
.reloc
E\;E|t
MD;MPv
MD;M4s
UX;U|t
QQSVWd
URPQQh
UQPXY]Y[
PPPPPPPP
uSSSSj
PPPPPWV
PP9E uPPSWP
f9:t!V
QQSVj8j@
PPPPPPPP
PVVVVV
bad allocation
success
address family not supported
address in use
address not available
already connected
argument list too long
argument out of domain
bad address
bad file descriptor
bad message
broken pipe
connection aborted
connection already in progress
connection refused
connection reset
cross device link
destination address required
device or resource busy
directory not empty
executable format error
file exists
file too large
filename too long
function not supported
host unreachable
identifier removed
illegal byte sequence
inappropriate io control operation
interrupted
invalid argument
invalid seek
io error
is a directory
message size
network down
network reset
network unreachable
no buffer space
no child process
no link
no lock available
no message available
no message
no protocol option
no space on device
no stream resources
no such device or address
no such device
no such file or directory
no such process
not a directory
not a socket
not a stream
not connected
not enough memory
not supported
operation canceled
operation in progress
operation not permitted
operation not supported
operation would block
owner dead
permission denied
protocol error
protocol not supported
read only file system
resource deadlock would occur
resource unavailable try again
result out of range
state not recoverable
stream timeout
text file busy
timed out
too many files open in system
too many files open
too many links
too many symbolic link levels
value too large
wrong protocol type
bad exception
0123456789abcdefghijklmnopqrstuvwxyz
0123456789abcdefghijklmnopqrstuvwxyz
__based(
__cdecl
__pascal
__stdcall
__thiscall
__fastcall
__vectorcall
__clrcall
__eabi
__swift_1
__swift_2
__swift_3
__ptr64
__restrict
__unaligned
restrict(
delete
operator
`vftable'
`vbtable'
`vcall'
`typeof'
`local static guard'
`string'
`vbase destructor'
`vector deleting destructor'
`default constructor closure'
`scalar deleting destructor'
`vector constructor iterator'
`vector destructor iterator'
`vector vbase constructor iterator'
`virtual displacement map'
`eh vector constructor iterator'
`eh vector destructor iterator'
`eh vector vbase constructor iterator'
`copy constructor closure'
`udt returning'
`local vftable'
`local vftable constructor closure'
new[]
delete[]
`omni callsig'
`placement delete closure'
`placement delete[] closure'
`managed vector constructor iterator'
`managed vector destructor iterator'
`eh vector copy constructor iterator'
`eh vector vbase copy constructor iterator'
`dynamic initializer for '
`dynamic atexit destructor for '
`vector copy constructor iterator'
`vector vbase copy constructor iterator'
`managed vector copy constructor iterator'
`local static thread guard'
operator ""
operator co_await
operator<=>
Type Descriptor'
Base Class Descriptor at (
Base Class Array'
Class Hierarchy Descriptor'
Complete Object Locator'
`anonymous namespace'
FlsAlloc
FlsFree
FlsGetValue
FlsSetValue
InitializeCriticalSectionEx
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
CorExitProcess
AreFileApisANSI
LCMapStringEx
LocaleNameToLCID
AppPolicyGetProcessTerminationMethod
Sunday
Monday
Tuesday
Wednesday
Thursday
Friday
Saturday
January
February
August
September
October
November
December
MM/dd/yy
dddd, MMMM dd, yyyy
HH:mm:ss
_hypot
_nextafter
?5Wg4p
%S#[k=
"B <1=
Unknown exception
bad array new length
string too long
vector too long
}{cdef~hijkl/nopqrstuvwx|><B-DEFGHIJKLMNOPQRSTUVWXYZ0123456789!@#$%^&*()_+
RSDSt=
C:\Users\
\Desktop\tesf\Release\BigProject.pdb
.text$di
.text$mn
.text$x
.text$yd
.idata$5
.00cfg
.CRT$XCA
.CRT$XCAA
.CRT$XCC
.CRT$XCL
.CRT$XCZ
.CRT$XIA
.CRT$XIAA
.CRT$XIAC
.CRT$XIC
.CRT$XIZ
.CRT$XLA
.CRT$XLZ
.CRT$XPA
.CRT$XPX
.CRT$XPXA
.CRT$XPZ
.CRT$XTA
.CRT$XTZ
.rdata
.rdata$T
.rdata$r
.rdata$sxdata
.rdata$voltmd
.rdata$zzzdbg
.rtc$IAA
.rtc$IZZ
.rtc$TAA
.rtc$TZZ
.tls$ZZZ
.xdata$x
.idata$2
.idata$3
.idata$4
.idata$6
.data$r
.data$rs
LoadLibraryA
GetProcAddress
FreeLibrary
KERNEL32.dll
RaiseException
EnterCriticalSection
LeaveCriticalSection
InitializeCriticalSectionEx
DeleteCriticalSection
EncodePointer
DecodePointer
MultiByteToWideChar
WideCharToMultiByte
GetStringTypeW
GetCPInfo
IsProcessorFeaturePresent
QueryPerformanceCounter
GetCurrentProcessId
GetCurrentThreadId
GetSystemTimeAsFileTime
InitializeSListHead
IsDebuggerPresent
UnhandledExceptionFilter
SetUnhandledExceptionFilter
GetStartupInfoW
GetModuleHandleW
GetCurrentProcess
TerminateProcess
RtlUnwind
GetLastError
SetLastError
InitializeCriticalSectionAndSpinCount
TlsAlloc
TlsGetValue
TlsSetValue
TlsFree
LoadLibraryExW
GetStdHandle
WriteFile
GetModuleFileNameW
ExitProcess
GetModuleHandleExW
LCMapStringW
HeapFree
HeapAlloc
HeapReAlloc
GetFileType
FindClose
FindFirstFileExW
FindNextFileW
IsValidCodePage
GetACP
GetOEMCP
GetCommandLineA
GetCommandLineW
GetEnvironmentStringsW
FreeEnvironmentStringsW
SetStdHandle
GetProcessHeap
SetFilePointerEx
HeapSize
FlushFileBuffers
GetConsoleOutputCP
GetConsoleMode
CloseHandle
CreateFileW
WriteConsoleW
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
.?AVlogic_error@std@@
.?AVlength_error@std@@
.?AVbad_exception@std@@
.?AVbad_alloc@std@@
.?AVexception@std@@
.?AVbad_array_new_length@std@@
.?AVtype_info@@
0#0/090E0^0
2!2<2h2
<<\=y?
=!=)=2=v=
1(20282A2I2R2
3h4p4x4
6H7P7X7a7i7r7
7(80888A8I8R8
41<1L1^1f1v1
2;2W2o2
3&3/3L3Y3v3
40484>4L4T4
7<7A7N7
9.9=9T9Z9`9f9l9r9x9
93:@:h:z:
;-<6<><z<
>(>1>>>T>
1'1;1@1S1h1w1
2&2/242:2D2N2^2n2~2
;+<0<4<8<<<
3C3W3s3}3
1U1a1z2
3F3Z3l3
4'444=4B4G4b4l4x4}4
809I9S9_9
9!:(:3:A:H:N:i:p:
=,>F?R?c?
0C1\1o1}1
2]2l2u2
20393&5_5f5
8$838G8P8h8o8{8
:&:7:H:h:
;7;<;E;
<K<T<\<
0(000;0A0L0R0`0~0
686L6j6
7;7J7\7o7
868@8b8s8|8
9!959K9^9
: :%:*:G:k:
;";1;<;A;F;d;s;~;
<:<Q<Z<q<
2%2v2{2
6$6:6P6X6Q:T;
;I=T=d=
0;0U0d0r0~0
11-1;1F1\1p1
2C3S3$4
5(545>5H5L5R5V5
:*<E<O<
<%=D=g=
1=2F2J2P2T2Z2^2h2{2
666i6Y7s7
7$8+8G8N8e8{8
9!9Q9Z9{9
:/:A:S:t:
0191>1P5
;=<^<e<|<
<.=O= >F>
2$2T2x2
56$6i6q6y6
717=7I7i7
8*8=9n9
=k=l>|>
?(?.?7?q?
0\0e0n0w0
3Q3[3v3P4V4[4b4r4
303C3`3
4*4G4d4
1 1$1(1,181<1@1D1H1L1P1d1h1l1
5$5,545<5D5L5T5\5d5l5t5|5
6$6,646<6D6L6T6\6d6l6t6|6
=0=4=8=
? ?(?0?8?@?H?P?X?`?h?p?x?
0 0(00080@0H0P0X0`0h0p0x0
1 1(10181@1H1P1X1`1h1p1x1
2 2(20282@2H2P2X2`2h2p2x2
2 2$2(2,24282<2@2D2H2L2P2\2d2l2p2t2x2|2
2(8,8084888<8@8D8H8L8P8T8X8\8`8d8h8l8p8t8x8|8
9 9$9(9,9094989<9@9D9H9L9P9T9X9\9`9d9h9l9p9t9x9|9
=$=,=4=<=D=L=T=\=d=l=t=|=
?$?,?4?<?D?L?T?\?d?l?t?|?
0$0,040<0D0L0T0\0d0l0t0|0
1$1,141<1D1L1T1\1d1l1t1|1
2$2,242<2D2L2T2\2d2l2t2|2
3$3,343<3D3L3T3\3d3l3t3|3
4$4,444<4D4L4T4\4d4l4t4|4
5$5,545<5D5L5T5\5d5l5t5|5
0080@0H0P0X0`0h0p0x0
1 1(10181@1H1P1X1`1h1p1x1
2 2(20282@2H2P2X2`2h2p2x2
3 3(30383@3H3P3X3`3h3p3x3
4 4(40484@4H4P4X4`4h4p4x4
5 5(50585@5H5P5X5`5h5p5x5
6 6(60686@6H6P6X6`6h6p6x6
7 7(70787@7H7
*1.12161
0$0(080<0@0H0`0p0t0
1 1$1,1D1T1X1\1`1d1l1p1x1
=$=,=4=<=D=L=T=\=d=l=t=|=
> >,>L>X>x>
?(?4?T?`?
000<0\0h0
1$1,141@1`1l1
2<2H2h2t2
3<3H3h3t3
4$4D4L4T4\4d4l4p4x4
5(50585<5D5X5x5
6 6$6@6H6L6\6
7 7(707<7\7h7
7(8H8h8
9$9(9H9h9
:(:H:h:
; ;(;<;
1 1$1(1,1H1x1
2@4D4H4L4
Dapi-ms-win-core-fibers-l1-1-1
api-ms-win-core-synch-l1-2-0
kernel32
api-ms-
((((( H
mscoree.dll
Dapi-ms-win-core-datetime-l1-1-1
api-ms-win-core-file-l1-2-4
api-ms-win-core-file-l1-2-2
api-ms-win-core-localization-l1-2-1
api-ms-win-core-localization-obsolete-l1-2-0
api-ms-win-core-processthreads-l1-1-2
api-ms-win-core-string-l1-1-0
api-ms-win-core-sysinfo-l1-2-1
api-ms-win-core-winrt-l1-1-0
api-ms-win-core-xstate-l2-1-0
api-ms-win-rtcore-ntuser-window-l1-1-0
api-ms-win-security-systemfunctions-l1-1-0
ext-ms-win-ntuser-dialogbox-l1-1-0
ext-ms-win-ntuser-windowstation-l1-1-0
advapi32
kernelbase
api-ms-win-appmodel-runtime-l1-1-2
user32
api-ms-win-core-fibers-l1-1-0
ext-ms-
Sunday
Monday
Tuesday
Wednesday
Thursday
Friday
Saturday
January
February
August
September
October
November
December
MM/dd/yy
dddd, MMMM dd, yyyy
HH:mm:ss
Dja-JP
zh-CHS
az-AZ-Latn
uz-UZ-Latn
kok-IN
syr-SY
div-MV
quz-BO
sr-SP-Latn
az-AZ-Cyrl
uz-UZ-Cyrl
quz-EC
sr-SP-Cyrl
quz-PE
smj-NO
bs-BA-Latn
smj-SE
sr-BA-Latn
sma-NO
sr-BA-Cyrl
sma-SE
sms-FI
smn-FI
zh-CHT
az-az-cyrl
az-az-latn
bs-ba-latn
div-mv
kok-in
quz-bo
quz-ec
quz-pe
sma-no
sma-se
smj-no
smj-se
smn-fi
sms-fi
sr-ba-cyrl
sr-ba-latn
sr-sp-cyrl
sr-sp-latn
syr-sy
uz-uz-cyrl
uz-uz-latn
zh-chs
zh-cht
CONOUT$
Antivirus Signature
Bkav W32.AIDetectMalware
Lionic Clean
tehtris Clean
ClamAV Clean
CMC Clean
CAT-QuickHeal Clean
Skyhigh Clean
ALYac Gen:Variant.Zusy.555781
Cylance Unsafe
Zillya Clean
Sangfor Clean
K7AntiVirus Clean
Alibaba Clean
K7GW Clean
Cybereason Clean
huorong Clean
Baidu Clean
VirIT Clean
Paloalto Clean
Symantec ML.Attribute.HighConfidence
Elastic Clean
ESET-NOD32 a variant of Win32/Agent_AGen.DSR
APEX Malicious
Avast Win32:DropperX-gen [Drp]
Cynet Malicious (score: 100)
Kaspersky HEUR:Trojan.Win32.Injuke.gen
BitDefender Gen:Variant.Zusy.555781
NANO-Antivirus Clean
ViRobot Clean
MicroWorld-eScan Gen:Variant.Zusy.555781
Tencent Clean
TACHYON Clean
Sophos Clean
F-Secure Clean
DrWeb Clean
VIPRE Gen:Variant.Zusy.555781
TrendMicro Clean
McAfeeD Real Protect-LS!BDC79DE40C61
Trapmine Clean
FireEye Generic.mg.bdc79de40c613816
Emsisoft Gen:Variant.Zusy.555781 (B)
Ikarus Clean
GData Gen:Variant.Zusy.555781
Jiangmin Clean
Webroot Clean
Varist Clean
Avira Clean
Antiy-AVL Clean
Kingsoft Clean
Gridinsoft Clean
Xcitium Clean
Arcabit Trojan.Zusy.D87B05
SUPERAntiSpyware Clean
ZoneAlarm HEUR:Trojan.Win32.Injuke.gen
Microsoft Trojan:Win32/Wacatac.B!ml
Google Clean
AhnLab-V3 Clean
Acronis Clean
McAfee Clean
MAX malware (ai score=80)
VBA32 suspected of Trojan.Downloader.gen
Malwarebytes Trojan.Injector
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Rising Stealer.Convagent!8.1326D (TFE:5:v7KZnnwmzgD)
Yandex Clean
SentinelOne Static AI - Suspicious PE
MaxSecure Clean
Fortinet Clean
BitDefenderTheta Gen:NN.ZexaF.36812.sqW@aa9pLqh
AVG Win32:DropperX-gen [Drp]
DeepInstinct MALICIOUS
CrowdStrike win/malicious_confidence_90% (D)
alibabacloud Clean
No IRMA results available.