Static | ZeroBOX

PE Compile Time

2023-10-28 05:29:15

PE Imphash

40f22e5e5c25d1a437c02d115ebb6713

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x00004a26 0x00004c00 6.05991519858
.rdata 0x00006000 0x00001b2c 0x00001c00 4.27227031721
.data 0x00008000 0x00000848 0x00000200 2.01911556947
.pdata 0x00009000 0x00000474 0x00000600 3.33875506028
.00cfg 0x0000a000 0x00000028 0x00000200 0.34044666977
.gehcont 0x0000b000 0x00000008 0x00000200 0.0407807562539
.retplne 0x0000c000 0x0000005c 0x00000200 0.845848782355
.tls 0x0000d000 0x00000009 0x00000200 0.0203931352361
.voltbl 0x0000e000 0x00000016 0x00000200 0.393609327873
.rsrc 0x0000f000 0x00010ec8 0x00011000 7.99205723499
.reloc 0x00020000 0x00000068 0x00000200 1.34382501718

Resources

Name Offset Size Language Sub-language File type
SUSFLAG 0x0000f1f8 0x00010cd0 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_MANIFEST 0x0000f0b0 0x00000143 LANG_ENGLISH SUBLANG_ENGLISH_US XML 1.0 document, ASCII text

Imports

Library KERNEL32.dll:
0x140006b48 CloseHandle
0x140006b50 CreateEventW
0x140006b58 CreateFileW
0x140006b60 CreateToolhelp32Snapshot
0x140006b68 DeleteCriticalSection
0x140006b70 EnterCriticalSection
0x140006b78 FindResourceW
0x140006b80 GetCurrentProcess
0x140006b88 GetCurrentProcessId
0x140006b90 GetCurrentThreadId
0x140006b98 GetLastError
0x140006ba0 GetModuleHandleW
0x140006ba8 GetProcAddress
0x140006bb0 GetStartupInfoW
0x140006bb8 GetSystemTimeAsFileTime
0x140006bc8 InitializeSListHead
0x140006bd0 IsDebuggerPresent
0x140006be0 LeaveCriticalSection
0x140006be8 LoadResource
0x140006bf0 LockResource
0x140006bf8 Process32FirstW
0x140006c00 Process32NextW
0x140006c08 QueryPerformanceCounter
0x140006c10 ReadFile
0x140006c18 ResetEvent
0x140006c20 RtlCaptureContext
0x140006c28 RtlLookupFunctionEntry
0x140006c30 RtlVirtualUnwind
0x140006c38 SetEvent
0x140006c48 Sleep
0x140006c50 TerminateProcess
0x140006c58 UnhandledExceptionFilter
0x140006c60 VirtualAlloc
0x140006c68 VirtualProtect
0x140006c70 WaitForSingleObjectEx
0x140006c78 WaitNamedPipeW
0x140006c80 WriteFile
Library MSVCP140.dll:
Library VCRUNTIME140.dll:
0x140006ca0 _CxxThrowException
0x140006ca8 __C_specific_handler
0x140006cb0 __CxxFrameHandler3
0x140006cb8 __current_exception
0x140006cc8 __std_exception_copy
0x140006cd0 __std_exception_destroy
0x140006ce0 memcpy
0x140006ce8 memmove
0x140006cf0 memset
0x140006cf8 strstr
Library api-ms-win-crt-stdio-l1-1-0.dll:
0x140006d08 __acrt_iob_func
0x140006d10 __p__commode
0x140006d18 __stdio_common_vfprintf
0x140006d20 __stdio_common_vfwprintf
0x140006d28 _set_fmode
0x140006d30 fgets
Library api-ms-win-crt-runtime-l1-1-0.dll:
0x140006d40 __p___argc
0x140006d48 __p___argv
0x140006d50 _c_exit
0x140006d58 _cexit
0x140006d60 _configure_narrow_argv
0x140006d68 _crt_at_quick_exit
0x140006d70 _crt_atexit
0x140006d78 _execute_onexit_table
0x140006d80 _exit
0x140006d98 _initialize_onexit_table
0x140006da0 _initterm
0x140006da8 _initterm_e
0x140006dc8 _seh_filter_dll
0x140006dd0 _seh_filter_exe
0x140006dd8 _set_app_type
0x140006de0 exit
0x140006de8 terminate
Library api-ms-win-crt-heap-l1-1-0.dll:
0x140006df8 _callnewh
0x140006e00 _set_new_mode
0x140006e08 free
0x140006e10 malloc
Library api-ms-win-crt-convert-l1-1-0.dll:
0x140006e20 mbstowcs
0x140006e28 wcstombs
Library api-ms-win-crt-string-l1-1-0.dll:
0x140006e38 strcmp
0x140006e40 strlen
0x140006e48 strncmp
0x140006e50 strnlen
0x140006e58 tolower
0x140006e60 wcscmp
0x140006e68 wcslen
Library api-ms-win-crt-math-l1-1-0.dll:
0x140006e78 __setusermatherr
Library api-ms-win-crt-locale-l1-1-0.dll:
0x140006e88 _configthreadlocale

!This program cannot be run in DOS mode.$
`.rdata
@.data
.pdata
@.00cfg
@.gehcont
@.retplne\
.voltbl
@.reloc
AWAVAUATVWUS
=rF=)u
[]_^A\A]A^A_
AWAVAUATVWUSH
h[]_^A\A]A^A_
AWAVAUATVWSH
[_^A\A]A^A_
AWAVAUATVWUSH
([]_^A\A]A^A_H
([]_^A\A]A^A_
AWAVAUATVWUSH
h[]_^A\A]A^A_
UAWAVAUATVWSH
H[_^A\A]A^A_]
UAWAVAUATVWSH
([_^A\A]A^A_]
AWAVAUATVWUSH
=rF=)u
|$XIcE<H
[]_^A\A]A^A_
AWAVAUATVWSH
[_^A\A]A^A_
H[_^]H
AWAVATVWSH
[_^A\A^A_
AWAVVWSH
[_^A^A_
AWAVAUATVWUSH
H[]_^A\A]A^A_
AWAVVWSH
[_^A^A_
AWAVAUATVWUSH
[]_^A\A]A^A_
AWAVAUATVWSH
[_^A\A]A^A_
u0HcH<H
D$H9D$ s"
H3E H3E
H3E H3E
Unknown exception
bad array new length
string too long
Could not open pipe: 20 second wait timed out.
Unknown exception
bad allocation
bad array new length
WakeAllConditionVariable
SleepConditionVariableCS
AddVectoredExceptionHandler
CloseHandle
CreateEventW
CreateFileW
CreateToolhelp32Snapshot
DeleteCriticalSection
EnterCriticalSection
FindResourceW
GetCurrentProcess
GetCurrentProcessId
GetCurrentThreadId
GetLastError
GetModuleHandleW
GetProcAddress
GetStartupInfoW
GetSystemTimeAsFileTime
InitializeCriticalSectionAndSpinCount
InitializeSListHead
IsDebuggerPresent
IsProcessorFeaturePresent
LeaveCriticalSection
LoadResource
LockResource
Process32FirstW
Process32NextW
QueryPerformanceCounter
ReadFile
ResetEvent
RtlCaptureContext
RtlLookupFunctionEntry
RtlVirtualUnwind
SetEvent
SetUnhandledExceptionFilter
TerminateProcess
UnhandledExceptionFilter
VirtualAlloc
VirtualProtect
WaitForSingleObjectEx
WaitNamedPipeW
WriteFile
?_Xlength_error@std@@YAXPEBD@Z
_CxxThrowException
__C_specific_handler
__CxxFrameHandler3
__current_exception
__current_exception_context
__std_exception_copy
__std_exception_destroy
__std_type_info_destroy_list
memcpy
memmove
memset
strstr
__acrt_iob_func
__p__commode
__stdio_common_vfprintf
__stdio_common_vfwprintf
_set_fmode
__p___argc
__p___argv
_c_exit
_cexit
_configure_narrow_argv
_crt_at_quick_exit
_crt_atexit
_execute_onexit_table
_get_initial_narrow_environment
_initialize_narrow_environment
_initialize_onexit_table
_initterm
_initterm_e
_invalid_parameter_noinfo_noreturn
_register_onexit_function
_register_thread_local_exe_atexit_callback
_seh_filter_dll
_seh_filter_exe
_set_app_type
terminate
_callnewh
_set_new_mode
malloc
mbstowcs
wcstombs
strcmp
strlen
strncmp
strnlen
tolower
wcscmp
wcslen
__setusermatherr
_configthreadlocale
KERNEL32.dll
MSVCP140.dll
VCRUNTIME140.dll
api-ms-win-crt-stdio-l1-1-0.dll
api-ms-win-crt-runtime-l1-1-0.dll
api-ms-win-crt-heap-l1-1-0.dll
api-ms-win-crt-convert-l1-1-0.dll
api-ms-win-crt-string-l1-1-0.dll
api-ms-win-crt-math-l1-1-0.dll
api-ms-win-crt-locale-l1-1-0.dll
.?AVbad_array_new_length@std@@
.?AVbad_alloc@std@@
.?AVexception@std@@
.?AVtype_info@@
RetpolineV1
RetpolineV1
RetpolineV1
RetpolineV1
<?xml version="1.0" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1"
manifestVersion="1.0">
<trustInfo>
<security>
<requestedPrivileges>
<requestedExecutionLevel level='asInvoker' uiAccess='false'/>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
~6z5^l!)
ToyF#K
"v]gzG
Z\"YB?
YLPoMR
_;7Xf:
"`u,g)
z-PUr!
^|zGFV
rBppgV
uJY62$
"M]?@e
i>6xYMp
v/o+uT
dih0h*
'|N[B6ez[
TP"$ml
@xKF-r
$i;C--
H9*Zt<
C(__{.IZ ~
sm%?"\
+P#7@{X
Ir-WKV
dkNr?3B=-
_(pJX$
Dk.IG?Dn
~80}+Y4:
Yt>-k~
lz6!M
cmUknk
q0W;*}
4;8^Iu
bc~k]j
$JQ3%c
,y31b{E>
E,!WF=I
Xz9BKV
[&Q[\+*
oB?V=$]vcGJ
fN^#18
]Pn:%a
YJ^Jo^m
FyPX $
-`-0&g
S+lZ~0
m;@Jr]yK
G|+fuJ
Mea#4a
mg,StP
19DDjn
s}NTC2v4
i9E5j"
-<B]WJ
n0~&f&@
Wu> IT
nQlymv
h?OU<
m %~4e
\CAVJH$
)210?K
"#ZGaz
]yL3*9J
9W9Rya
QVP~[Q
}41LIC
yi=4Peo
NXqsbT
Kzb;-
%{"QQ1
`5[7+C
]B=2"Y
;l.T/`
]l1s~D
#Cc+n8
3$uc`t
V)uPIa+
@L(-12)
<E_sK1
;*I_~XJ
|I%Qgc
x9!Ze+
>F\/E
B9_6x;V
q,t):D
5d:'f]
=c&4l
oZC%z)D
/P'Fav
x68.%=7{l
'A^I!f
CD8yZ>
h{v>tn
gY3Pcp@Z
`iR{n'
%f|&uSB
fbJKX<
o08Os
|]2)w
lQH6'4
G{'T`L
0qapy(
T\I8%I*Q-
MswY{j
0lC1`>xd
b6eYWR
t+]#S\A$
_@U\Rb
A2p;/+
NW@!Df
`TQNjZw
lqQlb.'
1`ST_n:{
Q.kL)
q8S|fFS
c/`%b|
YPQ]GI
z_.?8~L
q(<nQE
L6_lawM
8$~4WF"
j!4[_1U
'RQrI%
V!-Q\7
{XrP;=
;GG>BGR#
L!l(aK+
`d%4Hd
BKbjxj
yGHd2?r
GXh!_
SusFlag.jpg
SusFlag
Could not open pipe. GLE=%d
\\.\pipe\SusPipe3
kernel32.dll
api-ms-win-core-synch-l1-2-0.dll
SUSFLAG
No antivirus signatures available.
No IRMA results available.