Static | ZeroBOX

PE Compile Time

2023-07-31 21:37:40

PDB Path

C:\Users\O-Frank-Research\Downloads\PortBender-main\PortBender-main\src\PortBender\x64\Release\PortBender.pdb

PE Imphash

c7c3f76abd9c377a5c8cdbb66e53c501

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x00032ec0 0x00033000 6.50921161714
.rdata 0x00034000 0x00015440 0x00015600 5.23215929439
.data 0x0004a000 0x00002b48 0x00001400 3.08641193937
.pdata 0x0004d000 0x00002940 0x00002a00 5.42718774027
_RDATA 0x00050000 0x0000015c 0x00000200 3.32734705194
.rsrc 0x00051000 0x000001e0 0x00000200 4.724728912
.reloc 0x00052000 0x00000a60 0x00000c00 5.14874170543

Resources

Name Offset Size Language Sub-language File type
RT_MANIFEST 0x00051060 0x0000017d LANG_ENGLISH SUBLANG_ENGLISH_US XML 1.0 document text

Imports

Library WS2_32.dll:
0x180034300 inet_ntoa
0x180034308 htons
0x180034310 ntohs
Library KERNEL32.dll:
0x180034040 CreateFileW
0x180034048 CloseHandle
0x180034050 SetLastError
0x180034058 DeviceIoControl
0x180034060 GetOverlappedResult
0x180034068 GetCurrentDirectoryW
0x180034070 TlsAlloc
0x180034078 TlsGetValue
0x180034080 TlsSetValue
0x180034088 TlsFree
0x180034090 GetLastError
0x180034098 ExitProcess
0x1800340a0 GetProcessHeap
0x1800340a8 SetStdHandle
0x1800340b0 HeapSize
0x1800340b8 WriteConsoleW
0x1800340c0 CreateEventW
0x1800340c8 GetModuleHandleW
0x1800340d0 WideCharToMultiByte
0x1800340d8 EnterCriticalSection
0x1800340e0 LeaveCriticalSection
0x1800340f0 DeleteCriticalSection
0x1800340f8 EncodePointer
0x180034100 DecodePointer
0x180034108 MultiByteToWideChar
0x180034110 LCMapStringEx
0x180034118 GetStringTypeW
0x180034120 GetCPInfo
0x180034128 RtlCaptureContext
0x180034130 RtlLookupFunctionEntry
0x180034138 RtlVirtualUnwind
0x180034140 UnhandledExceptionFilter
0x180034150 GetCurrentProcess
0x180034158 TerminateProcess
0x180034168 QueryPerformanceCounter
0x180034170 GetCurrentProcessId
0x180034178 GetCurrentThreadId
0x180034180 GetSystemTimeAsFileTime
0x180034188 InitializeSListHead
0x180034190 IsDebuggerPresent
0x180034198 GetStartupInfoW
0x1800341a0 RtlUnwindEx
0x1800341a8 RtlPcToFileHeader
0x1800341b0 RaiseException
0x1800341b8 InterlockedFlushSList
0x1800341c8 FreeLibrary
0x1800341d0 GetProcAddress
0x1800341d8 LoadLibraryExW
0x1800341e0 RtlUnwind
0x1800341e8 GetModuleHandleExW
0x1800341f0 GetModuleFileNameW
0x1800341f8 HeapFree
0x180034200 HeapAlloc
0x180034208 FlsAlloc
0x180034210 FlsGetValue
0x180034218 FlsSetValue
0x180034220 FlsFree
0x180034228 LCMapStringW
0x180034230 GetLocaleInfoW
0x180034238 IsValidLocale
0x180034240 GetUserDefaultLCID
0x180034248 EnumSystemLocalesW
0x180034250 GetStdHandle
0x180034258 GetFileType
0x180034260 FlushFileBuffers
0x180034268 WriteFile
0x180034270 GetConsoleOutputCP
0x180034278 GetConsoleMode
0x180034280 ReadFile
0x180034288 GetFileSizeEx
0x180034290 SetFilePointerEx
0x180034298 ReadConsoleW
0x1800342a0 HeapReAlloc
0x1800342a8 FindClose
0x1800342b0 FindFirstFileExW
0x1800342b8 FindNextFileW
0x1800342c0 IsValidCodePage
0x1800342c8 GetACP
0x1800342d0 GetOEMCP
0x1800342d8 GetCommandLineA
0x1800342e0 GetCommandLineW
0x1800342e8 GetEnvironmentStringsW
0x1800342f0 FreeEnvironmentStringsW
Library ADVAPI32.dll:
0x180034000 OpenServiceW
0x180034008 OpenSCManagerW
0x180034010 DeleteService
0x180034018 CreateServiceW
0x180034020 ControlService
0x180034028 CloseServiceHandle
0x180034030 StartServiceW

Exports

Ordinal Address Name
1 0x180008b10 ReflectiveLoader
!This program cannot be run in DOS mode.
:MRich
`.rdata
@.data
.pdata
@_RDATA
@.rsrc
@.reloc
\$ UVWH
H;\$ t*
UVWATAUAVAWH
D$`H;D$ht
A_A^A]A\_^]
VWATAVAWH
A_A^A\_^
t$ AVH
t$ AVH
SUVWAVH
A^_^][
@SUWAVAWH
A_A^_][
A_A^_][
|$ AVH
|$ AVH
t$ WATAUAVAWH
A_A^A]A\_
@SUVAVH
(A^^][
(A^^][
@SVATAUH
8A]A\^[
SVWAVAWH
A_A^_^[
A_A^_^[
@SVWATAUAVAWH
PA_A^A]A\_^[
@SUVAWH
(A_^][
L$ SVWH
UVWAVAWH
A_A^_^]
|$ UAVAWH
UVWATAUAVAWH
A_A^A]A\_^]
I92u7A
@SWAVH
t$ WATAUAVAWH
A_A^A]A\_
t$ WAVAWH
A_A^_
UVWATAUAVAWH
A_A^A]A\_^]
\$ VWAWH
t$ WATAUAVAWH
A_A^A]A\_
L$ SUVWH
|$ UATAUAVAWH
u)I;|$
fA;G(u
@SVWATAUAVAWH
A_A^A]A\_^[
UVWATAUAVAWH
u#HcU<H
V IcB<B
y$HcF<
A_A^A]A\_^]
SVWAVAWH
A_A^_^[
SVWAVAWH
A_A^_^[
UVWATAUAVAWH
A_A^A]A\_^]
UVWATAUAVAWH
A_A^A]A\_^]
@USVWATAUAVAWH
A_A^A]A\_^[]
UVWATAUAVAWH
A_A^A]A\_^]
UVWATAUAVAWH
A_A^A]A\_^]
@SUVWAVH
A^_^][
A^_^][
SUVAVH
HA^^][
UVWAUH
HA]_^]
@USVWAVH
A^_^[]
WAVAWH
fF9<0u
UATAUAVAWH
A_A^A]A\]
|$ ATAVAWH
A_A^A\
UVWATAUAVAWH
PA_A^A]A\_^]
WATAUAVAW3
t$HA_A^A]A\_
@SUVWATAVAWH
A_A^A\_^][
@UVWAW
WATAUAVAWH
A_A^A]A\_
UVWATAUAVAWH
<0&u~A
<0|ufA
`A_A^A]A\_^]
l$ VWAVH
@SUVWAVH
A^_^][
tpH91uk
t$ UWAVH
taL9Chu
L90u H
t$ WAVAWH
A_A^_
@UAVAWH
|$ AVH
D8L$0u`
VWATAVAWH
A_A^A\_^
WATAUAVAWH
A_A^A]A\_
H;xXu5
ffffff
fffffff
fffffff
ffffff
vKfffff
WATAUAVAWH
A_A^A]A\_
AUAVAWH
u4I9}(
;I9}(tiH
0A_A^A]
AUAVAWH
u4I9}(
;I9}(tiH
0A_A^A]
UVWATAUAVAWH
`A_A^A]A\_^]
UVWATAUAVAWH
`A_A^A]A\_^]
@USVWATAUAVAWH
A_A^A]A\_^[]
@USVWATAUAVAWH
d$dD;d$ltY
A_A^A]A\_^[]
UVWATAUAVAWH
A_A^A]A\_^]
@USVWATAUAVAWH
A_A^A]A\_^[]
WAVAWH
@SVWATAUAVAWH
L!|$(L!
D$0HcH
pA_A^A]A\_^[
SVWATAUAWH
L!d$(L!d$@D
D$HL9gXt
A_A]A\_^[
B(I9A(
SVWATAUAVAWH
0A_A^A]A\_^[
SVWATAUAVAWH
A_A^A]A\_^[
t$ WATAUAVAWH
A_A^A]A\_
UVWATAUAVAWH
A_A^A]A\_^]
D$ I;R
D$ I9P
WATAUAVAWH
A_A^A]A\_
WATAUAVAWH
0A_A^A]A\_
UVWATAUAVAWH
rsf;\$d
r_f;\$l
rKf;\$t
r7f;\$|
f;\$4r
f;\$<r
rvf;\$d
rbf;\$l
rNf;\$t
r:f;\$|
A_A^A]A\_^]
D$0@8{
p*W4H
p*W4H
@USVWATAVAWH
A_A^A\_^[]
WATAUAVAWH
0A_A^A]A\_
S(HcS0
S(HcS0
S(HcS0
x UAVAWH
D$@H;F
kL@8o(u
kL@8o(u
<htl<jt\<lt4<tt$<wt
<htl<jt\<lt4<tt$<wt
UWATAVAWH
A_A^A\_]
|$ UATAUAVAWH
A_A^A]A\]
WAVAWH
A_A^_
L$ VWAVH
u3HcH<H
t$ UWAUAVAWH
A_A^A]_]
s WATAUAVAWH
D$h9t$P
A_A^A]A\_
L$ UVWATAUAVAWH
0A_A^A]A\_^]
T$ D){
t$ WATAUAVAWH
0A_A^A]A\_
D$(H!L$ E3
;D$hsL
SUVWATAVAWH
A_A^A\_^][
fffffff
fffffff
fffffff
fffffff
ffffff
fffffff
fffffff
fffffff
fffffff
ffffff
ffffff
ffffff
u$D8r(t
D81uUL9r
uED8r(t
vAD8s(t
f9)u4H9j
u%@8j(t
p0R^G'
WATAUAVAWH
A_A^A]A\_
UVWAVAWH
0A_A^_^]
WAVAWH
A_A^_
WAVAWH
A_A^_
WAVAWH
fE98t'
0A_A^_
@USVWATAUAVAWH
A_A^A]A\_^[]
9Cu,fD9y
fB9<{u
fD9,pu
t$`fD9+t$I
L$ SUVWH
WATAUAVAWH
0A_A^A]A\_
\$ UVWATAUAVAWH
fD9,Au
A_A^A]A\_^]
\$ UVWATAUAVAWH
f9t$bu
A_A^A]A\_^]
H9L$Ht?H
UVWATAUAVAWH
fE9,Fu
A_A^A]A\_^]
|$ AVH
WATAUAVAWH
A_A^A]A\_
p0R^G'
fD9t$b
t$ WATAUAVAWH
gfffffffH
A_A^A]A\_
{ AUAVAWH
0A_A^A]
t$xt*3
WAVAWH
A_A^_
x ATAVAWH
A_A^A\
L$ VWAVH
fD94H}aD
UVWATAUAVAWH
fB9<I}1L
A_A^A]A\_^]
VWATAVAW
A_A^A\_^
VATAUAVAWH
0A_A^A]A\^
@USVWATAUAVAWH
H!D$ H
xA_A^A]A\_^[]
u1!D$0H
UVWATAUAVAWH
PA_A^A]A\_^]
WATAVH
0A^A\_
E80t"A
fD94Q}
WATAVH
0A^A\_
@USVWATAUAVAWH
xA_A^A]A\_^[]
@UAVAWH
e0A_A^]
@SUVWATAVAWH
A_A^A\_^][
@UATAUAVAWH
e0A_A^A]A\]
@UATAUAVAWH
A_A^A]A\]
UVWATAUAVAWH
A_A^A]A\_^]
UVWATAUAVAW
A_A^A]A\_^]
D$0H9D$8
\$ UVWATAUAVAWH
s2fE9)I
fE9)fA
D$pfA;
0fD9l$pu
fD9l$pt
0A_A^A]A\_^]
l$ VWATAVAWH
0A_A^A\_^
AUAVAWH
A_A^A]
UVWATAUAVAWH
@8t$HtzL
`A_A^A]A\_^]
VATAUAVAWH
0A_A^A]A\^
t$ WATAUAVAWH
D!|$xA
A_A^A]A\_
WAVAWH
@A_A^_
u$D8r(t
fD91uTL9r
uED8r(t
v@D8s(t
UVWATAUAVAWH
PA_A^A]A\_^]
WATAUAVAWH
0A_A^A]A\_
H9>u+A
@USVWATAUAVH
D8t$ht
D8t$ht
A^A]A\_^[]
l$ VWATAVAWH
L$&8\$&t,8Y
A_A^A\_^
UATAUAVAWH
A_A^A]A\]
WATAUAVAWH
A_A^A]A\_
UATAUAVAWH
A_A^A]A\]
fB9<Hu
fB9<@u
fB9<Bu
fB9,Nu
fB9,Nu
fB9,Nu
fA9,Au
fB94Ou
t}f91txH
x ATAVAWH
A_A^A\
x ATAVAWH
fD9 tMH
fG9$Ou
0A_A^A\
fB9<Hu
fB9<@u
fB9<Bu
fD94Au
fD94iu
tSf91tNH
t^;\$0tQ
WAVAWH
A_A^_
@USVWATAVAWH
tyfD9 tsH
tQfD9 tK
fD9$Hu
@A_A^A\_^[]
WAVAWH
A_A^_
@USVWATAVAWH
A_A^A\_^[]
WATAUAVAWH
0A_A^A]A\_
UVWATAUAVAWH
@A_A^A]A\_^]
USVWAVH
A^_^[]
USVWAVH
A^_^[]
T$`fA;
ATAUAVH
L$ fff
L$ |+L;
A^A]A\
WAVAWH
D8|$`t
A_A^_
x ATAVAWH
@A_A^A\
ffffff
fffffff
@SUVWATAVAWH
@A_A^A\_^][
ATAVAWH
A_A^A\
LcA<E3
icmp.Body
icmp.Checksum
icmp.Code
icmp.Type
icmpv6
icmpv6.Body
icmpv6.Checksum
icmpv6.Code
icmpv6.Type
inbound
ip.Checksum
ip.DstAddr
ip.FragOff
ip.HdrLength
ip.Length
ip.Protocol
ip.SrcAddr
ip.TOS
ip.TTL
ipv6.DstAddr
ipv6.FlowLabel
ipv6.HopLimit
ipv6.Length
ipv6.NextHdr
ipv6.SrcAddr
ipv6.TrafficClass
outbound
subIfIdx
tcp.Ack
tcp.AckNum
tcp.Checksum
tcp.DstPort
tcp.Fin
tcp.HdrLength
tcp.PayloadLength
tcp.Psh
tcp.Rst
tcp.SeqNum
tcp.SrcPort
tcp.Syn
tcp.Urg
tcp.UrgPtr
tcp.Window
udp.Checksum
udp.DstPort
udp.Length
udp.PayloadLength
udp.SrcPort
bad allocation
success
address family not supported
address in use
address not available
already connected
argument list too long
argument out of domain
bad address
bad file descriptor
bad message
broken pipe
connection aborted
connection already in progress
connection refused
connection reset
cross device link
destination address required
device or resource busy
directory not empty
executable format error
file exists
file too large
filename too long
function not supported
host unreachable
identifier removed
illegal byte sequence
inappropriate io control operation
interrupted
invalid argument
invalid seek
io error
is a directory
message size
network down
network reset
network unreachable
no buffer space
no child process
no link
no lock available
no message available
no message
no protocol option
no space on device
no stream resources
no such device or address
no such device
no such file or directory
no such process
not a directory
not a socket
not a stream
not connected
not enough memory
not supported
operation canceled
operation in progress
operation not permitted
operation not supported
operation would block
owner dead
permission denied
protocol error
protocol not supported
read only file system
resource deadlock would occur
resource unavailable try again
result out of range
state not recoverable
stream timeout
text file busy
timed out
too many files open in system
too many files open
too many links
too many symbolic link levels
value too large
wrong protocol type
unknown error
0123456789abcdefghijklmnopqrstuvwxyz
0123456789abcdefghijklmnopqrstuvwxyz
bad exception
__based(
__cdecl
__pascal
__stdcall
__thiscall
__fastcall
__vectorcall
__clrcall
__eabi
__swift_1
__swift_2
__swift_3
__ptr64
__restrict
__unaligned
restrict(
delete
operator
`vftable'
`vbtable'
`vcall'
`typeof'
`local static guard'
`string'
`vbase destructor'
`vector deleting destructor'
`default constructor closure'
`scalar deleting destructor'
`vector constructor iterator'
`vector destructor iterator'
`vector vbase constructor iterator'
`virtual displacement map'
`eh vector constructor iterator'
`eh vector destructor iterator'
`eh vector vbase constructor iterator'
`copy constructor closure'
`udt returning'
`local vftable'
`local vftable constructor closure'
new[]
delete[]
`omni callsig'
`placement delete closure'
`placement delete[] closure'
`managed vector constructor iterator'
`managed vector destructor iterator'
`eh vector copy constructor iterator'
`eh vector vbase copy constructor iterator'
`dynamic initializer for '
`dynamic atexit destructor for '
`vector copy constructor iterator'
`vector vbase copy constructor iterator'
`managed vector copy constructor iterator'
`local static thread guard'
operator ""
operator co_await
operator<=>
Type Descriptor'
Base Class Descriptor at (
Base Class Array'
Class Hierarchy Descriptor'
Complete Object Locator'
`anonymous namespace'
FlsAlloc
FlsFree
FlsGetValue
FlsSetValue
InitializeCriticalSectionEx
(null)
CorExitProcess
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
[aOni*{
~ $s%r
@b;zO]
v2!L.2
UUUUUU
UUUUUU
"e?<<<<<<l?
Il?333333c?
.i?0@I
d?000000`?
)|B?d!
L?UUUUUUU?
&?PPPPPPP?
0X8b?~
%GoU?*
(T?j?Y
Zod(^?
D W?{W
qS>g?h3
c?FA@s}
UUUUUU
UUUUUU
UUUUUU
?UUUUUU
?kxG2)
?TY,>5
?!5WOo
?E=$% B
?49HoKC
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
Sunday
Monday
Tuesday
Wednesday
Thursday
Friday
Saturday
January
February
August
September
October
November
December
MM/dd/yy
dddd, MMMM dd, yyyy
HH:mm:ss
AreFileApisANSI
CompareStringEx
EnumSystemLocalesEx
GetDateFormatEx
GetLocaleInfoEx
GetTimeFormatEx
GetUserDefaultLocaleName
IsValidLocaleName
LCMapStringEx
LCIDToLocaleName
LocaleNameToLCID
AppPolicyGetProcessTerminationMethod
NAN(SNAN)
nan(snan)
NAN(IND)
nan(ind)
_hypot
_nextafter
A03>A|
Q5rHg,>
Hk=>:
j>>A?1
.>PJ;I:qE>
:>t6k'
])6M>&
CWD>~3
_oD>Kg
N>O=I9
F>qUxv
/2GG>!B
zY;>u:m
P>q_Y~
0><[cZUg^>
Y>kX>M
H[><y5
[*ncd>0
S>$hkDh$h>[2
UA>N0Wl
9>powf
?8bunz8
?@En[vP
?UUUUUU
?7zQ6$
1#QNAN
1#SNAN
UUUUUU
UUUUUU
=imb;D
/>58d%
VM>cQ6
>jtm}S
)>6{1n
+f)>0'
;H9>&X
*StO9>T
n03>Pu
K~Je#>!
bp(=>?g
BC?>6t9^
K&>.yC
.xJ>Hf
y\PD>!
|b=})>
c [1>H'
uzKs@>
3>N;kU
kE>fvw
V6E>`"(5
Unknown exception
bad array new length
string too long
iostream
bad cast
bad locale name
ios_base::badbit set
ios_base::failbit set
ios_base::eofbit set
invalid stoi argument
stoi argument out of range
redirect
Missing required arguments
backdoor
Please enter a valid action of redirect or backdoor
invalid string position
vector too long
iostream stream error
map/set too long
New connection from %s:%d to %s:%d
Disconnect from %s:%d to %s:%d
Error PortBender requires an argument string
_______ __ _______ __
/ \ / | / \ / |
$$$$$$$ | ______ ______ _$$ |_ $$$$$$$ | ______ _______ ____$$ | ______ ______
$$ |__$$ |/ \ / \ / $$ | $$ |__$$ | / \ / \ / $$ | / \ / \
$$ $$//$$$$$$ |/$$$$$$ |$$$$$$/ $$ $$< /$$$$$$ |$$$$$$$ |/$$$$$$$ |/$$$$$$ |/$$$$$$ |
$$$$$$$/ $$ | $$ |$$ | $$/ $$ | __ $$$$$$$ |$$ $$ |$$ | $$ |$$ | $$ |$$ $$ |$$ | $$/
$$ | $$ \__$$ |$$ | $$ |/ |$$ |__$$ |$$$$$$$$/ $$ | $$ |$$ \__$$ |$$$$$$$$/ $$ |
$$ | $$ $$/ $$ | $$ $$/ $$ $$/ $$ |$$ | $$ |$$ $$ |$$ |$$ |
$$/ $$$$$$/ $$/ $$$$/ $$$$$$$/ $$$$$$$/ $$/ $$/ $$$$$$$/ $$$$$$$/ $$/
Initializing PortBender in backdoor mode
Initializing PortBender in redirector mode
Redirect Usage: PortBender redirect FakeDstPort RedirectedPort
Backdoor Usage: PortBender backdoor FakeDstPort RedirectedPort password
Example:
PortBender redirect 445 8445
PortBender backdoor 443 3389 praetorian.antihacker
((inbound and tcp.DstPort == %d ) or (outbound and tcp.SrcPort == %d ))
Configuring redirection of connections targeting %d/TCP to %d/TCP
connected to the server
Client
disconnected from the server
Fatal error - unable to allocate heap memory. Exiting.
Error invalid filter syntax was used
Failed to open the WinDivert device (
Failed to set packet queue length (
Failed to set packet queue time (
Failed to read packet (
Error this shouldn't happen
Failed to reinject packet (
C:\Users\O-Frank-Research\Downloads\PortBender-main\PortBender-main\src\PortBender\x64\Release\PortBender.pdb
.text$di
.text$mn
.text$mn$00
.text$x
.text$yd
.idata$5
.00cfg
.CRT$XCA
.CRT$XCC
.CRT$XCL
.CRT$XCZ
.CRT$XIA
.CRT$XIC
.CRT$XIZ
.CRT$XPA
.CRT$XPX
.CRT$XPXA
.CRT$XPZ
.CRT$XTA
.CRT$XTZ
.rdata
.rdata$r
.rdata$voltmd
.rdata$zzzdbg
.rtc$IAA
.rtc$IZZ
.rtc$TAA
.rtc$TZZ
.xdata
.xdata$x
.edata
.idata$2
.idata$3
.idata$4
.idata$6
.data$r
.data$rs
.pdata
_RDATA
.rsrc$01
.rsrc$02
PortBender.dll
ReflectiveLoader
WS2_32.dll
ExitProcess
GetLastError
GetCurrentDirectoryW
CreateFileW
CloseHandle
SetLastError
DeviceIoControl
GetOverlappedResult
CreateEventW
TlsAlloc
TlsGetValue
TlsSetValue
TlsFree
KERNEL32.dll
CloseServiceHandle
ControlService
CreateServiceW
DeleteService
OpenSCManagerW
OpenServiceW
StartServiceW
ADVAPI32.dll
WideCharToMultiByte
EnterCriticalSection
LeaveCriticalSection
InitializeCriticalSectionEx
DeleteCriticalSection
EncodePointer
DecodePointer
MultiByteToWideChar
LCMapStringEx
GetStringTypeW
GetCPInfo
RtlCaptureContext
RtlLookupFunctionEntry
RtlVirtualUnwind
UnhandledExceptionFilter
SetUnhandledExceptionFilter
GetCurrentProcess
TerminateProcess
IsProcessorFeaturePresent
QueryPerformanceCounter
GetCurrentProcessId
GetCurrentThreadId
GetSystemTimeAsFileTime
InitializeSListHead
IsDebuggerPresent
GetStartupInfoW
GetModuleHandleW
RtlUnwindEx
RtlPcToFileHeader
RaiseException
InterlockedFlushSList
InitializeCriticalSectionAndSpinCount
FreeLibrary
GetProcAddress
LoadLibraryExW
RtlUnwind
GetModuleHandleExW
GetModuleFileNameW
HeapFree
HeapAlloc
FlsAlloc
FlsGetValue
FlsSetValue
FlsFree
LCMapStringW
GetLocaleInfoW
IsValidLocale
GetUserDefaultLCID
EnumSystemLocalesW
GetStdHandle
GetFileType
FlushFileBuffers
WriteFile
GetConsoleOutputCP
GetConsoleMode
ReadFile
GetFileSizeEx
SetFilePointerEx
ReadConsoleW
HeapReAlloc
FindClose
FindFirstFileExW
FindNextFileW
IsValidCodePage
GetACP
GetOEMCP
GetCommandLineA
GetCommandLineW
GetEnvironmentStringsW
FreeEnvironmentStringsW
GetProcessHeap
SetStdHandle
HeapSize
WriteConsoleW
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
.?AVlength_error@std@@
.?AVout_of_range@std@@
.?AVbad_exception@std@@
.?AVfailure@ios_base@std@@
.?AVruntime_error@std@@
.?AVbad_alloc@std@@
.?AVsystem_error@std@@
.?AVlogic_error@std@@
.?AVbad_cast@std@@
.?AVinvalid_argument@std@@
.?AV_System_error@std@@
.?AVexception@std@@
.?AVbad_array_new_length@std@@
.?AV_Locimp@locale@std@@
.?AV?$basic_filebuf@DU?$char_traits@D@std@@@std@@
.?AVcodecvt_base@std@@
.?AV?$codecvt@DDU_Mbstatet@@@std@@
.?AVtype_info@@
.?AV?$basic_stringstream@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@
.?AV?$basic_stringbuf@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@
.?AVios_base@std@@
.?AVerror_category@std@@
.?AV?$ctype@D@std@@
.?AV?$basic_iostream@DU?$char_traits@D@std@@@std@@
.?AV_Facet_base@std@@
.?AU_Crt_new_delete@std@@
.?AV?$_Iosb@H@std@@
.?AV_Iostream_error_category2@std@@
.?AV?$basic_streambuf@DU?$char_traits@D@std@@@std@@
.?AUctype_base@std@@
.?AV?$basic_istream@DU?$char_traits@D@std@@@std@@
.?AV?$basic_ios@DU?$char_traits@D@std@@@std@@
.?AVfacet@locale@std@@
.?AV?$basic_ostream@DU?$char_traits@D@std@@@std@@
.?AV?$numpunct@D@std@@
.?AV?$num_put@DV?$ostreambuf_iterator@DU?$char_traits@D@std@@@std@@@std@@
<?xml version='1.0' encoding='UTF-8' standalone='yes'?>
<assembly xmlns='urn:schemas-microsoft-com:asm.v1' manifestVersion='1.0'>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v3">
<security>
<requestedPrivileges>
<requestedExecutionLevel level='asInvoker' uiAccess='false' />
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
\WinDivert64.sys
WinDivert1.1
\\.\WinDivert1.1
api-ms-win-core-fibers-l1-1-1
api-ms-win-core-synch-l1-2-0
kernel32
api-ms-
(null)
mscoree.dll
((((( H
((((( H
(
LC_ALL
LC_COLLATE
LC_CTYPE
LC_MONETARY
LC_NUMERIC
LC_TIME
Sunday
Monday
Tuesday
Wednesday
Thursday
Friday
Saturday
January
February
August
September
October
November
December
MM/dd/yy
dddd, MMMM dd, yyyy
HH:mm:ss
api-ms-win-core-datetime-l1-1-1
api-ms-win-core-file-l1-2-4
api-ms-win-core-file-l1-2-2
api-ms-win-core-localization-l1-2-1
api-ms-win-core-localization-obsolete-l1-2-0
api-ms-win-core-processthreads-l1-1-2
api-ms-win-core-string-l1-1-0
api-ms-win-core-sysinfo-l1-2-1
api-ms-win-core-winrt-l1-1-0
api-ms-win-core-xstate-l2-1-0
api-ms-win-rtcore-ntuser-window-l1-1-0
api-ms-win-security-systemfunctions-l1-1-0
ext-ms-win-ntuser-dialogbox-l1-1-0
ext-ms-win-ntuser-windowstation-l1-1-0
advapi32
kernelbase
api-ms-win-appmodel-runtime-l1-1-2
user32
ext-ms-
american
american english
american-english
australian
belgian
canadian
chinese
chinese-hongkong
chinese-simplified
chinese-singapore
chinese-traditional
dutch-belgian
english-american
english-aus
english-belize
english-can
english-caribbean
english-ire
english-jamaica
english-nz
english-south africa
english-trinidad y tobago
english-uk
english-us
english-usa
french-belgian
french-canadian
french-luxembourg
french-swiss
german-austrian
german-lichtenstein
german-luxembourg
german-swiss
irish-english
italian-swiss
norwegian
norwegian-bokmal
norwegian-nynorsk
portuguese-brazilian
spanish-argentina
spanish-bolivia
spanish-chile
spanish-colombia
spanish-costa rica
spanish-dominican republic
spanish-ecuador
spanish-el salvador
spanish-guatemala
spanish-honduras
spanish-mexican
spanish-modern
spanish-nicaragua
spanish-panama
spanish-paraguay
spanish-peru
spanish-puerto rico
spanish-uruguay
spanish-venezuela
swedish-finland
america
britain
england
great britain
holland
hong-kong
new-zealand
pr china
pr-china
puerto-rico
slovak
south africa
south korea
south-africa
south-korea
trinidad & tobago
united-kingdom
united-states
zh-CHS
az-AZ-Latn
uz-UZ-Latn
kok-IN
syr-SY
div-MV
quz-BO
sr-SP-Latn
az-AZ-Cyrl
uz-UZ-Cyrl
quz-EC
sr-SP-Cyrl
quz-PE
smj-NO
bs-BA-Latn
smj-SE
sr-BA-Latn
sma-NO
sr-BA-Cyrl
sma-SE
sms-FI
smn-FI
zh-CHT
az-az-cyrl
az-az-latn
bs-ba-latn
div-mv
kok-in
quz-bo
quz-ec
quz-pe
sma-no
sma-se
smj-no
smj-se
smn-fi
sms-fi
sr-ba-cyrl
sr-ba-latn
sr-sp-cyrl
sr-sp-latn
syr-sy
uz-uz-cyrl
uz-uz-latn
zh-chs
zh-cht
CONOUT$
Antivirus Signature
Bkav W64.AIDetectMalware
Lionic Hacktool.Win32.Inject.3!c
Elastic Clean
ClamAV Clean
CMC Clean
CAT-QuickHeal Clean
Skyhigh Clean
ALYac Clean
Cylance Unsafe
Zillya Clean
Sangfor Hacktool.Win32.Inject.V5sb
CrowdStrike win/malicious_confidence_100% (W)
Alibaba HackTool:Win32/Inject.1c609df3
K7GW Clean
K7AntiVirus Clean
huorong Clean
Baidu Clean
VirIT Clean
Paloalto Clean
Symantec Packed.Generic.700
tehtris Clean
ESET-NOD32 Clean
APEX Clean
Avast Win64:HacktoolX-gen [Trj]
Cynet Clean
Kaspersky HEUR:HackTool.Win32.Inject.heur
BitDefender Trojan.GenericKD.74213988
NANO-Antivirus Clean
ViRobot Clean
MicroWorld-eScan Trojan.GenericKD.74213988
Tencent Clean
Sophos Harmony Loader (PUA)
F-Secure Clean
DrWeb Clean
VIPRE Trojan.GenericKD.74213988
TrendMicro Clean
McAfeeD ti!884039AB697C
Trapmine Clean
CTX dll.hacktool.inject
Emsisoft Trojan.GenericKD.74213988 (B)
Ikarus Trojan.Win64.Hacktool
FireEye Trojan.GenericKD.74213988
Jiangmin Clean
Webroot Clean
Varist W64/ABRisk.OJKG-4847
Avira Clean
Fortinet W32/PossibleThreat
Antiy-AVL HackTool/Win32.Inject
Kingsoft Win32.HackTool.Inject.heur
Gridinsoft Hack.Win64.Patcher.sa
Xcitium Clean
Arcabit Trojan.Generic.D46C6A64
SUPERAntiSpyware Clean
ZoneAlarm HEUR:HackTool.Win32.Inject.heur
Microsoft Clean
Google Detected
AhnLab-V3 Clean
Acronis Clean
McAfee Artemis!17FB69181D1A
TACHYON Clean
VBA32 Clean
Malwarebytes Clean
Panda Trj/CI.A
Zoner Clean
TrendMicro-HouseCall TROJ_GEN.R014H07IS24
Rising Hacktool.Inject!8.36B (CLOUD)
Yandex Clean
SentinelOne Clean
MaxSecure Trojan.Malware.10455307.susgen
GData Trojan.GenericKD.74213988
AVG Win64:HacktoolX-gen [Trj]
DeepInstinct MALICIOUS
alibabacloud HackTool:Win/Inject.hyrv
No IRMA results available.