Static | ZeroBOX

PE Compile Time

2024-09-18 20:21:45

PE Imphash

2c1340bab731211eab9f443d03ccafb1

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x0001c8b0 0x0001ca00 6.39785402465
.rdata 0x0001e000 0x0000ae82 0x0000b000 4.37957408228
.data 0x00029000 0x00004aa8 0x00002200 3.37856781916
.pdata 0x0002e000 0x00001974 0x00001a00 5.1684575424
.rsrc 0x00030000 0x00000288 0x00000400 3.84153917863
.reloc 0x00031000 0x000019d0 0x00001a00 2.00830704842

Resources

Name Offset Size Language Sub-language File type
RT_MANIFEST 0x00030060 0x00000224 LANG_ENGLISH SUBLANG_ENGLISH_US XML 1.0 document, UTF-8 Unicode (with BOM) text, with very long lines, with CRLF line terminators

Imports

Library KERNEL32.dll:
0x14001e000 GetSystemDirectoryW
0x14001e008 WideCharToMultiByte
0x14001e010 MultiByteToWideChar
0x14001e018 GetStringTypeW
0x14001e020 EncodePointer
0x14001e028 DecodePointer
0x14001e030 EnterCriticalSection
0x14001e038 LeaveCriticalSection
0x14001e048 DeleteCriticalSection
0x14001e050 Sleep
0x14001e058 GetLocaleInfoEx
0x14001e060 GetCommandLineW
0x14001e068 GetLastError
0x14001e070 HeapFree
0x14001e078 GetCPInfo
0x14001e080 RtlPcToFileHeader
0x14001e088 RaiseException
0x14001e090 RtlLookupFunctionEntry
0x14001e098 RtlUnwindEx
0x14001e0a0 HeapAlloc
0x14001e0b8 SetLastError
0x14001e0c0 GetCurrentThreadId
0x14001e0c8 ExitProcess
0x14001e0d0 GetModuleHandleExW
0x14001e0d8 GetProcAddress
0x14001e0e0 GetStdHandle
0x14001e0e8 WriteFile
0x14001e0f0 GetModuleFileNameW
0x14001e0f8 GetProcessHeap
0x14001e100 GetFileType
0x14001e108 InitOnceExecuteOnce
0x14001e110 GetStartupInfoW
0x14001e118 QueryPerformanceCounter
0x14001e120 GetSystemTimeAsFileTime
0x14001e128 GetTickCount64
0x14001e130 GetEnvironmentStringsW
0x14001e138 FreeEnvironmentStringsW
0x14001e140 RtlCaptureContext
0x14001e148 RtlVirtualUnwind
0x14001e150 UnhandledExceptionFilter
0x14001e160 FlsAlloc
0x14001e168 FlsGetValue
0x14001e170 FlsSetValue
0x14001e178 FlsFree
0x14001e180 GetCurrentProcess
0x14001e188 TerminateProcess
0x14001e190 GetModuleHandleW
0x14001e198 IsDebuggerPresent
0x14001e1a0 ReadFile
0x14001e1a8 SetFilePointerEx
0x14001e1b0 FlushFileBuffers
0x14001e1b8 GetConsoleCP
0x14001e1c0 GetConsoleMode
0x14001e1c8 HeapSize
0x14001e1d0 CloseHandle
0x14001e1d8 IsValidCodePage
0x14001e1e0 GetACP
0x14001e1e8 GetOEMCP
0x14001e1f0 SetFilePointer
0x14001e1f8 GetUserDefaultLocaleName
0x14001e200 LCMapStringEx
0x14001e208 IsValidLocaleName
0x14001e210 EnumSystemLocalesEx
0x14001e218 HeapReAlloc
0x14001e220 LoadLibraryExW
0x14001e228 OutputDebugStringW
0x14001e230 LoadLibraryW
0x14001e238 ReadConsoleW
0x14001e240 SetStdHandle
0x14001e248 WriteConsoleW
0x14001e250 CreateFileW
0x14001e258 SetEndOfFile

!This program cannot be run in DOS mode.
t%1It%1It%1It%0I"%1I
Iu%1IS
Iu%1IS
Iu%1IRicht%1I
`.rdata
@.data
.pdata
@.rsrc
@.reloc
WATAUAVAWH
0A_A^A]A\_
UVWATAUAVAWH
@A_A^A]A\_^]
l$ VWAVH
@SUVWAVAWH
fD9|$0u
HA_A^_^][
t}H91ux
@SVWAVH
i0ffff
HA^_^[
f9\$@t
@UVWAVAWH
A_A^_^]
@UVWAVAWH
A_A^_^]
@SUVWAVH
0A^_^][
\$ VWAVH
SVWAVH
8A^_^[
t$ AVH
SVWAVAWH
0A_A^_^[
WATAUAVAWH
A_A^A]A\_
WATAUAVAWH
A_A^A]A\_
WATAUAVAWH
A_A^A]A\_
@SUAVH
UVWAVAWH
D8:u2H
A_A^_^]
D9>tXA
fffffff
l$ VWAVH
r9\$ ~>L
l$ VWAUAVAWH
L$$fA;
u$HcG$H;
t5f9(t
A_A^A]_^
AUAVAWH
0A_A^A]
SVWAVH
8A^_^[
ATAVAWH
A_A^A\
s WATAUAVAWH
9t$P~.8\$vt(H
9t$P~98\$vt3H
A_A^A]A\_
WAVAWH
A_A^_
WATAUAVAWH
A_A^A]A\_
VWATAVAWH
A_A^A\_^
x ATAVAWH
A_A^A\
x UAVAWH
x ATAUAWH
@A_A]A\
VWATAVAWH
A_A^A\_^
UVWATAUAVAWH
A_A^A]A\_^]
D8eoupH
UVWATAUAVAWH
pA_A^A]A\_^]
WATAUAVAWH
A_A^A]A\_
AUAVAWH
0A_A^A]
@SVWATAUAVAWH
L!|$@L!
D$HHcH
A_A^A]A\_^[
SVWATAUAVAWH
0A_A^A]A\_^[
WATAVH
@A^A\_
WAVAWH
fD9>u"
0A_A^_
@UATAUAVAWH
!t$(H!t$ I
A_A^A]A\]
WATAUAVAWH
@A_A^A]A\_
t$ WAVAWH
` AUAVAWH
t$HHc0I
\$0D9=
A_A^A]
Hct$PH
seHcD$XH
fD9!u:A
fD93tSH
CfD93u
H3E H3E
WATAUAVAWH
A_A^A]A\_
Genuua
ineIuY
nteluQ3
t$ WATAUAVAW
A_A^A]A\_
VWATAVAWH
A_A^A\_^
VWATAVAWH
A_A^A\_^
\$ UVWATAUAVAWH
!|$HHc
|$HD9l$X
HcD$LH;
HcD$LH;
H!|$ L
A_A^A]A\_^]
@SUVWATAVAWH
zu|D!t$ E3
A_A^A\_^][
@UATAUAVAWH
A_A^A]A\]
D82u&H
D8t$Ht
l$ VWATAVAWH
T$&@8t$&t9@8r
A81t@@8r
A_A^A\_^
WAVAWH
fE98t'
0A_A^_
@SUVWATAUAVAWH
A_A^A]A\_^][
;Cu1f9K
f93t M;
L$ SUVWH
|$ ATAVAWH
0A_A^A\
WATAUAVAWH
0A_A^A]A\_
\$ UVWATAUAVAWH
^fD9+t
A_A^A]A\_^]
\$ UVWATAUAVAWH
A_A^A]A\_^]
fD9|$bu
H9L$Ht8H
x ATAVAWH
D8&t4H
D8d$Ht
A_A^A\
ATAVAWH
D8d$8t
@A_A^A\
\$ UVWATAUAVAWH
A_A^A]A\_^]
t$ WATAUAVAW
A_A^A]A\_
VWATAVAWH
A_A^A\_^
t$ WATAUAVAWH
0A_A^A]A\_
VWATAVAWH
0A_A^A\_^
WATAUAVAWH
gfffffffH
D8L$Ht
A_A^A]A\_
x AUAVAWH
A_A^A]
@SUVWH
@SUVWH
@SUVWAVH
A^_^][
@8l$8t
LcA<E3
@SUVWATAVAWH
PA_A^A\_^][
WATAUAVAWH
A_A^A]A\_
USVWATAUAVAWH
8UXt#D
XA_A^A]A\_^[]
` AUAVAWH
0A_A^A]
UATAUAVAWH
A_A^A]A\]
WATAUAVAWH
A_A^A]A\_
@UATAUAVAWH
A_A^A]A\]
f9.uVH
f9.u"H
tVf91tQH
x ATAVAWH
A_A^A\
@SUVWATAVAWH
3fD9 t
A_A^A\_^][
UVWATAUAVAWH
A_A^A]A\_^]
D8t$8t
@USVWH
x AUAVAWH
A_A^A]
|$ UATAUAVAWH
A_A^A]A\]
|$ UATAUAVAWH
A_A^A]A\]
UVWATAUAVAWH
A_A^A]A\_^]
UVWATAUAVAWH
A_A^A]A\_^]
UVWATAUAVAWH
A_A^A]A\_^]
x AUAVAWH
A_A^A]
H(H9J(u
permission denied
file exists
no such device
filename too long
device or resource busy
io error
directory not empty
invalid argument
no space on device
no such file or directory
function not supported
no lock available
not enough memory
resource unavailable try again
cross device link
operation canceled
too many files open
permission_denied
address_in_use
address_not_available
address_family_not_supported
connection_already_in_progress
bad_file_descriptor
connection_aborted
connection_refused
connection_reset
destination_address_required
bad_address
host_unreachable
operation_in_progress
interrupted
invalid_argument
already_connected
too_many_files_open
message_size
filename_too_long
network_down
network_reset
network_unreachable
no_buffer_space
no_protocol_option
not_connected
not_a_socket
operation_not_supported
protocol_not_supported
wrong_protocol_type
timed_out
operation_would_block
address family not supported
address in use
address not available
already connected
argument list too long
argument out of domain
bad address
bad file descriptor
bad message
broken pipe
connection aborted
connection already in progress
connection refused
connection reset
destination address required
executable format error
file too large
host unreachable
identifier removed
illegal byte sequence
inappropriate io control operation
invalid seek
is a directory
message size
network down
network reset
network unreachable
no buffer space
no child process
no link
no message available
no message
no protocol option
no stream resources
no such device or address
no such process
not a directory
not a socket
not a stream
not connected
not supported
operation in progress
operation not permitted
operation not supported
operation would block
owner dead
protocol error
protocol not supported
read only file system
resource deadlock would occur
result out of range
state not recoverable
stream timeout
text file busy
timed out
too many files open in system
too many links
too many symbolic link levels
value too large
wrong protocol type
bad allocation
0123456789abcdefghijklmnopqrstuvwxyz
0123456789abcdefghijklmnopqrstuvwxyz
0123456789abcdefABCDEF
Unknown exception
bad exception
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
CorExitProcess
GetCurrentPackageId
Sunday
Monday
Tuesday
Wednesday
Thursday
Friday
Saturday
January
February
August
September
October
November
December
MM/dd/yy
dddd, MMMM dd, yyyy
HH:mm:ss
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
UTF-16LE
UNICODE
_hypot
_nextafter
(null)
`h````
xpxxxx
SunMonTueWedThuFriSat
JanFebMarAprMayJunJulAugSepOctNovDec
MessageBoxW
GetActiveWindow
GetLastActivePopup
GetUserObjectInformationW
GetProcessWindowStation
__based(
__cdecl
__pascal
__stdcall
__thiscall
__fastcall
__clrcall
__eabi
__ptr64
__restrict
__unaligned
restrict(
delete
operator
`vftable'
`vbtable'
`vcall'
`typeof'
`local static guard'
`string'
`vbase destructor'
`vector deleting destructor'
`default constructor closure'
`scalar deleting destructor'
`vector constructor iterator'
`vector destructor iterator'
`vector vbase constructor iterator'
`virtual displacement map'
`eh vector constructor iterator'
`eh vector destructor iterator'
`eh vector vbase constructor iterator'
`copy constructor closure'
`udt returning'
`local vftable'
`local vftable constructor closure'
new[]
delete[]
`omni callsig'
`placement delete closure'
`placement delete[] closure'
`managed vector constructor iterator'
`managed vector destructor iterator'
`eh vector copy constructor iterator'
`eh vector vbase copy constructor iterator'
`dynamic initializer for '
`dynamic atexit destructor for '
`vector copy constructor iterator'
`vector vbase copy constructor iterator'
`managed vector copy constructor iterator'
`local static thread guard'
Type Descriptor'
Base Class Descriptor at (
Base Class Array'
Class Hierarchy Descriptor'
Complete Object Locator'
CreateFile2
`h`hhh
xppwpp
1#SNAN
1#QNAN
bad locale name
generic
unknown error
iostream
iostream stream error
system
ios_base::badbit set
ios_base::failbit set
ios_base::eofbit set
string too long
invalid string position
bad cast
GetSystemDirectoryW
WideCharToMultiByte
MultiByteToWideChar
GetStringTypeW
EncodePointer
DecodePointer
EnterCriticalSection
LeaveCriticalSection
InitializeCriticalSectionEx
DeleteCriticalSection
GetLocaleInfoEx
GetCommandLineW
GetLastError
HeapFree
GetCPInfo
RtlPcToFileHeader
RaiseException
RtlLookupFunctionEntry
RtlUnwindEx
HeapAlloc
InitializeCriticalSectionAndSpinCount
IsProcessorFeaturePresent
SetLastError
GetCurrentThreadId
ExitProcess
GetModuleHandleExW
GetProcAddress
GetStdHandle
WriteFile
GetModuleFileNameW
GetProcessHeap
GetFileType
InitOnceExecuteOnce
GetStartupInfoW
QueryPerformanceCounter
GetSystemTimeAsFileTime
GetTickCount64
GetEnvironmentStringsW
FreeEnvironmentStringsW
RtlCaptureContext
RtlVirtualUnwind
UnhandledExceptionFilter
SetUnhandledExceptionFilter
FlsAlloc
FlsGetValue
FlsSetValue
FlsFree
GetCurrentProcess
TerminateProcess
GetModuleHandleW
IsDebuggerPresent
ReadFile
SetFilePointerEx
FlushFileBuffers
GetConsoleCP
GetConsoleMode
HeapSize
CloseHandle
IsValidCodePage
GetACP
GetOEMCP
SetFilePointer
GetUserDefaultLocaleName
LCMapStringEx
IsValidLocaleName
EnumSystemLocalesEx
HeapReAlloc
LoadLibraryExW
OutputDebugStringW
LoadLibraryW
ReadConsoleW
SetStdHandle
WriteConsoleW
CreateFileW
SetEndOfFile
KERNEL32.dll
.?AV_Locimp@locale@std@@
.?AVbad_alloc@std@@
.?AVlogic_error@std@@
.?AVlength_error@std@@
.?AVout_of_range@std@@
Copyright (c) 1992-2004 by P.J. Plauger, licensed by Dinkumware, Ltd. ALL RIGHTS RESERVED.
.?AVtype_info@@
.?AVbad_exception@std@@
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
.?AVsystem_error@std@@
.?AVbad_cast@std@@
.?AV?$basic_filebuf@_WU?$char_traits@_W@std@@@std@@
.?AVexception@std@@
.?AVcodecvt_base@std@@
.?AV?$codecvt@_WDH@std@@
.?AV?$basic_istream@_WU?$char_traits@_W@std@@@std@@
.?AVios_base@std@@
.?AV_Iostream_error_category@std@@
.?AV?$basic_ofstream@_WU?$char_traits@_W@std@@@std@@
.?AV?$ctype@_W@std@@
.?AVfailure@ios_base@std@@
.?AVruntime_error@std@@
.?AV?$basic_ostream@_WU?$char_traits@_W@std@@@std@@
.?AV_System_error_category@std@@
.?AV?$_Iosb@H@std@@
.?AV?$basic_ifstream@_WU?$char_traits@_W@std@@@std@@
.?AVerror_category@std@@
.?AV_Generic_error_category@std@@
.?AV_Facet_base@std@@
.?AUctype_base@std@@
.?AV?$basic_streambuf@_WU?$char_traits@_W@std@@@std@@
.?AVfacet@locale@std@@
.?AV?$basic_ios@_WU?$char_traits@_W@std@@@std@@
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0"><trustInfo xmlns="urn:schemas-microsoft-com:asm.v3"><security><requestedPrivileges><requestedExecutionLevel level="asInvoker" uiAccess="false"></requestedExecutionLevel></requestedPrivileges></security></trustInfo><application xmlns="urn:schemas-microsoft-com:asm.v3"><windowsSettings><dpiAware xmlns="http://schemas.microsoft.com/SMI/2005/WindowsSettings">true</dpiAware></windowsSettings></application></assembly>
((((( H
h(((( H
H
mscoree.dll
- floating point support not loaded
- not enough space for arguments
- not enough space for environment
- abort() has been called
- not enough space for thread data
- unexpected multithread lock error
- unexpected heap error
- unable to open console device
- not enough space for _onexit/atexit table
- pure virtual function call
- not enough space for stdio initialization
- not enough space for lowio initialization
- unable to initialize heap
- CRT not initialized
- Attempt to initialize the CRT more than once.
This indicates a bug in your application.
- not enough space for locale information
- Attempt to use MSIL code from this assembly during native code initialization
This indicates a bug in your application. It is most likely the result of calling an MSIL-compiled (/clr) function from a native constructor or from DllMain.
- inconsistent onexit begin-end variables
DOMAIN error
SING error
TLOSS error
runtime error
Runtime Error!
Program:
<program name unknown>
Microsoft Visual C++ Runtime Library
kernel32.dll
Sunday
Monday
Tuesday
Wednesday
Thursday
Friday
Saturday
January
February
August
September
October
November
December
MM/dd/yy
dddd, MMMM dd, yyyy
HH:mm:ss
LC_ALL
LC_COLLATE
LC_CTYPE
LC_MONETARY
LC_NUMERIC
LC_TIME
UTF-16LE
UNICODE
(null)
USER32.DLL
american
american english
american-english
australian
belgian
canadian
chinese
chinese-hongkong
chinese-simplified
chinese-singapore
chinese-traditional
dutch-belgian
english-american
english-aus
english-belize
english-can
english-caribbean
english-ire
english-jamaica
english-nz
english-south africa
english-trinidad y tobago
english-uk
english-us
english-usa
french-belgian
french-canadian
french-luxembourg
french-swiss
german-austrian
german-lichtenstein
german-luxembourg
german-swiss
irish-english
italian-swiss
norwegian
norwegian-bokmal
norwegian-nynorsk
portuguese-brazilian
spanish-argentina
spanish-bolivia
spanish-chile
spanish-colombia
spanish-costa rica
spanish-dominican republic
spanish-ecuador
spanish-el salvador
spanish-guatemala
spanish-honduras
spanish-mexican
spanish-modern
spanish-nicaragua
spanish-panama
spanish-paraguay
spanish-peru
spanish-puerto rico
spanish-uruguay
spanish-venezuela
swedish-finland
america
britain
england
great britain
holland
hong-kong
new-zealand
pr china
pr-china
puerto-rico
slovak
south africa
south korea
south-africa
south-korea
trinidad & tobago
united-kingdom
united-states
CONOUT$
\drivers\etc\hosts
virustotal
windowsupdate.microsoft.com
update.microsoft.com
windowsupdate.com
download.windowsupdate.com
windowsupdate.com.delivery.microsoft.com
ntservicepack.microsoft.com
au.windowsupdate.com
fe2.update.microsoft.com
sls.update.microsoft.com
tsfe.trafficshaping.dsp.mp.microsoft.com
tsfe.trafficshaping.dsp.mp.microsoft.com.nsatc.net
wu.dl.delivery.mp.microsoft.com
tlu.dl.delivery.mp.microsoft.com
tlu.dl.delivery.mp.microsoft.com.nsatc.net
emdl.ws.microsoft.com
wustat.windows.com
vortex.data.microsoft.com
settings-win.data.microsoft.com
telemetry.microsoft.com
telecommand.telemetry.microsoft.com
telecommand.telemetry.microsoft.com.nsatc.net
oca.telemetry.microsoft.com
oca.telemetry.microsoft.com.nsatc.net
sqm.telemetry.microsoft.com
sqm.telemetry.microsoft.com.nsatc.net
wes.df.telemetry.microsoft.com
wes.df.telemetry.microsoft.com.nsatc.net
watson.telemetry.microsoft.com
watson.telemetry.microsoft.com.nsatc.net
watson.ppe.telemetry.microsoft.com
watson.ppe.telemetry.microsoft.com.nsatc.net
vortex-sandbox.data.microsoft.com
survey.watson.microsoft.com
df.telemetry.microsoft.com
reports.wes.df.telemetry.microsoft.com
corpext.msitadfs.glbdns2.microsoft.com
cs1.wpc.v0cdn.net
statsfe1.ws.microsoft.com
statsfe2.ws.microsoft.com
feedback.windows.com
feedback.microsoft.com
i1.services.social.microsoft.com
i1.services.social.microsoft.com.nsatc.net
diagnostics.support.microsoft.com
watson.microsoft.com
support.microsoft.com
msftncsi.com
ipv6.msftncsi.com
www.msftncsi.com
wdcp.microsoft.com
wdcpalt.microsoft.com
wd.microsoft.com
ceip.microsoft.com
ceip.microsoft.com.nsatc.net
choice.microsoft.com
choice.microsoft.com.nsatc.net
sandbox.microsoft.com
storeedgefd.dsx.mp.microsoft.com
storecatalogrevocation.storequality.microsoft.com
store-images.microsoft.com
dl.delivery.mp.microsoft.com
licensing.mp.microsoft.com
login.live.com
login.microsoftonline.com
clientconfig.passport.net
compatexchange.cloudapp.net
a-0001.a-msedge.net
pre.footprintpredict.com
g.msn.com
ssw.live.com
c.microsoft.com
c.msn.com
officeclient.microsoft.com
statsfe2.update.microsoft.com
0.0.0.0
Antivirus Signature
Bkav W64.AIDetectMalware
Lionic Clean
Elastic Clean
ClamAV Clean
CMC Clean
CAT-QuickHeal Clean
Skyhigh Clean
ALYac Clean
Cylance Clean
Zillya Clean
Sangfor Clean
CrowdStrike Clean
Alibaba Clean
K7GW Clean
K7AntiVirus Clean
huorong Clean
Baidu Clean
VirIT Clean
Paloalto Clean
Symantec Clean
tehtris Clean
ESET-NOD32 Clean
APEX Malicious
Avast Clean
Cynet Clean
Kaspersky Clean
BitDefender Clean
NANO-Antivirus Clean
ViRobot Clean
MicroWorld-eScan Clean
Tencent Clean
Sophos Clean
F-Secure Clean
DrWeb Clean
VIPRE Clean
TrendMicro Clean
McAfeeD ti!FA554A42C09B
Trapmine Clean
CTX Clean
Emsisoft Clean
Ikarus Clean
FireEye Clean
Jiangmin Clean
Webroot Clean
Varist Clean
Avira Clean
Fortinet Clean
Antiy-AVL Clean
Kingsoft Win32.Troj.Unknown.a
Gridinsoft Clean
Xcitium Clean
Arcabit Clean
SUPERAntiSpyware Clean
ZoneAlarm Clean
Microsoft Trojan:Win32/Sonbokli.A!cl
Google Clean
AhnLab-V3 Clean
Acronis Clean
McAfee Clean
TACHYON Clean
VBA32 Clean
Malwarebytes Clean
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Rising Clean
Yandex Clean
SentinelOne Clean
MaxSecure Clean
GData Clean
AVG Clean
DeepInstinct Clean
alibabacloud Clean
No IRMA results available.