Static | ZeroBOX

PE Compile Time

2021-03-29 22:42:26

PE Imphash

a82ee962c2400be0e0e4803eb65a2b0b

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x0000dcdc 0x0000de00 6.30809355127
.rdata 0x0000f000 0x00003f5b 0x00004000 5.26741880207
.data 0x00013000 0x00004058 0x00001a00 2.96608033045
.pdata 0x00018000 0x00000df8 0x00000e00 4.98905430783
.rsrc 0x00019000 0x00023c80 0x00023e00 7.9863333842
.reloc 0x0003d000 0x00000558 0x00000600 2.33382716076

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x000196f0 0x00000128 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x000196f0 0x00000128 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x000196f0 0x00000128 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_MENU 0x00019818 0x0000004a LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_DIALOG 0x00019864 0x000000fa LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_STRING 0x00019960 0x0000006a LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_ACCELERATOR 0x000199cc 0x00000010 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_MESSAGETABLE 0x000199dc 0x00023212 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_GROUP_ICON 0x0003cc14 0x00000014 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_GROUP_ICON 0x0003cc14 0x00000014 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_MANIFEST 0x0003cc28 0x00000056 LANG_ENGLISH SUBLANG_ENGLISH_US ASCII text, with CRLF line terminators

Imports

Library KERNEL32.dll:
0x1000f000 GetLocaleInfoA
0x1000f008 GetStringTypeW
0x1000f010 GetStringTypeA
0x1000f018 LCMapStringW
0x1000f020 MultiByteToWideChar
0x1000f028 LCMapStringA
0x1000f038 LoadLibraryA
0x1000f040 LeaveCriticalSection
0x1000f048 EnterCriticalSection
0x1000f050 GetConsoleMode
0x1000f058 GetConsoleCP
0x1000f060 SetFilePointer
0x1000f068 GetOEMCP
0x1000f070 GetACP
0x1000f078 GetCPInfo
0x1000f088 GetCurrentProcessId
0x1000f090 GetTickCount
0x1000f0a0 GetEnvironmentStringsW
0x1000f0a8 WideCharToMultiByte
0x1000f0b8 SetStdHandle
0x1000f0c0 WriteConsoleA
0x1000f0c8 GetConsoleOutputCP
0x1000f0d0 WriteConsoleW
0x1000f0d8 CreateFileA
0x1000f0e0 CloseHandle
0x1000f0e8 FlushFileBuffers
0x1000f0f0 GetLastError
0x1000f0f8 GetModuleHandleA
0x1000f100 ExitProcess
0x1000f108 LoadLibraryW
0x1000f110 GetProcAddress
0x1000f118 HeapReAlloc
0x1000f120 HeapAlloc
0x1000f128 HeapFree
0x1000f130 GetCurrentThreadId
0x1000f138 FlsSetValue
0x1000f140 GetCommandLineA
0x1000f148 GetVersionExA
0x1000f150 GetProcessHeap
0x1000f158 TerminateProcess
0x1000f160 GetCurrentProcess
0x1000f178 IsDebuggerPresent
0x1000f180 RtlVirtualUnwind
0x1000f188 RtlLookupFunctionEntry
0x1000f190 RtlCaptureContext
0x1000f198 FlsGetValue
0x1000f1a0 TlsFree
0x1000f1a8 FlsFree
0x1000f1b0 SetLastError
0x1000f1b8 TlsSetValue
0x1000f1c0 FlsAlloc
0x1000f1c8 Sleep
0x1000f1d0 HeapSize
0x1000f1d8 RtlUnwindEx
0x1000f1e0 HeapSetInformation
0x1000f1e8 HeapCreate
0x1000f1f0 HeapDestroy
0x1000f1f8 WriteFile
0x1000f200 GetStdHandle
0x1000f208 GetModuleFileNameA
0x1000f210 SetHandleCount
0x1000f218 GetFileType
0x1000f220 GetStartupInfoA
0x1000f228 DeleteCriticalSection
0x1000f238 GetEnvironmentStrings

Exports

Ordinal Address Name
1 0x10001390 StartW
!This program cannot be run in DOS mode.
:&Hn:e
:&Hm:-
`.rdata
@.data
.pdata
@.rsrc
@.reloc
fC9,Cu
l$xu&H
|$Hfff
@8t$Ht
d$@utH
gfffffffH
Hct$PH
slHcD$0H
t$Vt6fff
@8l$&H
T$&t;f
D$Pt#A
f;D$@uhA
f;D$@u:A
t2HcD$DH
t2HcD$DH
LcA<E3
\$@t4H
T$(t#A
D$Xt&A
u!8D$ht
D$Ht#A
D$Ht#A
T$Dr%ff
D$PH;5h
D$@H;5h
D$8t#A
D$0u?3
t$`D+=F
D$0u?3
t$`D+=
r,f9l$8H
u!A9u
r:f9\$2D
\$hfD3
\$xyFA
l$0u.fff
bad allocation
ZwOpenSymbolicLinkObject
CryptEncrypt
CryptImportKey
CryptAcquireContextW
SizeofResource
LoadResource
FindResourceA
(null)
`h````
xpxxxx
EncodePointer
KERNEL32.DLL
DecodePointer
CorExitProcess
mscoree.dll
runtime error
TLOSS error
SING error
DOMAIN error
An application has made an attempt to load the C runtime library incorrectly.
Please contact the application's support team for more information.
- Attempt to use MSIL code from this assembly during native code initialization
This indicates a bug in your application. It is most likely the result of calling an MSIL-compiled (/clr) function from a native constructor or from DllMain.
- not enough space for locale information
- Attempt to initialize the CRT more than once.
This indicates a bug in your application.
- CRT not initialized
- unable to initialize heap
- not enough space for lowio initialization
- not enough space for stdio initialization
- pure virtual function call
- not enough space for _onexit/atexit table
- unable to open console device
- unexpected heap error
- unexpected multithread lock error
- not enough space for thread data
This application has requested the Runtime to terminate it in an unusual way.
Please contact the application's support team for more information.
- not enough space for environment
- not enough space for arguments
- floating point not loaded
Microsoft Visual C++ Runtime Library
<program name unknown>
Runtime Error!
Program:
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
`h`hhh
xppwpp
InitializeCriticalSectionAndSpinCount
kernel32.dll
Complete Object Locator'
Class Hierarchy Descriptor'
Base Class Array'
Base Class Descriptor at (
Type Descriptor'
`local static thread guard'
`managed vector copy constructor iterator'
`vector vbase copy constructor iterator'
`vector copy constructor iterator'
`dynamic atexit destructor for '
`dynamic initializer for '
`eh vector vbase copy constructor iterator'
`eh vector copy constructor iterator'
`managed vector destructor iterator'
`managed vector constructor iterator'
`placement delete[] closure'
`placement delete closure'
`omni callsig'
delete[]
new[]
`local vftable constructor closure'
`local vftable'
`udt returning'
`copy constructor closure'
`eh vector vbase constructor iterator'
`eh vector destructor iterator'
`eh vector constructor iterator'
`virtual displacement map'
`vector vbase constructor iterator'
`vector destructor iterator'
`vector constructor iterator'
`scalar deleting destructor'
`default constructor closure'
`vector deleting destructor'
`vbase destructor'
`string'
`local static guard'
`typeof'
`vcall'
`vbtable'
`vftable'
operator
delete
__unaligned
__restrict
__ptr64
__clrcall
__fastcall
__thiscall
__stdcall
__pascal
__cdecl
__based(
GetProcessWindowStation
GetUserObjectInformationA
GetLastActivePopup
GetActiveWindow
MessageBoxA
USER32.DLL
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
HH:mm:ss
dddd, MMMM dd, yyyy
MM/dd/yy
December
November
October
September
August
February
January
Saturday
Friday
Thursday
Wednesday
Tuesday
Monday
Sunday
1#QNAN
1#SNAN
SunMonTueWedThuFriSat
JanFebMarAprMayJunJulAugSepOctNovDec
CONOUT$
GetProcAddress
LoadLibraryW
ExitProcess
GetModuleHandleA
GetLastError
KERNEL32.dll
HeapReAlloc
HeapAlloc
HeapFree
GetCurrentThreadId
FlsSetValue
GetCommandLineA
GetVersionExA
GetProcessHeap
TerminateProcess
GetCurrentProcess
UnhandledExceptionFilter
SetUnhandledExceptionFilter
IsDebuggerPresent
RtlVirtualUnwind
RtlLookupFunctionEntry
RtlCaptureContext
FlsGetValue
TlsFree
FlsFree
SetLastError
TlsSetValue
FlsAlloc
HeapSize
RtlUnwindEx
HeapSetInformation
HeapCreate
HeapDestroy
WriteFile
GetStdHandle
GetModuleFileNameA
SetHandleCount
GetFileType
GetStartupInfoA
DeleteCriticalSection
FreeEnvironmentStringsA
GetEnvironmentStrings
FreeEnvironmentStringsW
WideCharToMultiByte
GetEnvironmentStringsW
QueryPerformanceCounter
GetTickCount
GetCurrentProcessId
GetSystemTimeAsFileTime
GetCPInfo
GetACP
GetOEMCP
SetFilePointer
GetConsoleCP
GetConsoleMode
EnterCriticalSection
LeaveCriticalSection
LoadLibraryA
InitializeCriticalSection
LCMapStringA
MultiByteToWideChar
LCMapStringW
GetStringTypeA
GetStringTypeW
GetLocaleInfoA
SetStdHandle
WriteConsoleA
GetConsoleOutputCP
WriteConsoleW
CreateFileA
CloseHandle
FlushFileBuffers
DataGrid Test.dll
StartW
+nXGA>mE4p9vE_k
1.HKe
.?AVCDataGrid@@
.?AVtype_info@@
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
duQ-p(t/
^j.$'M
]m]F%7
7=CdLwO
jxypu6
a6*mk2
zOE:oW&-p
yL!IRX
l[N%,N`Yhd
n6@(FN
#wKu#C
6X;4{D{
?,C&{K^3
8fGno\
7pCG~y
?F%f|x0
={;H)ZX2
"k18b&
`2P-fu1
i[C?T>
F5F.T9
Ri*%~P
*@Y=Wx
=Dir!EA
L$(xccNV
/k$_0(D
O%THP(
$^(JUR
I:%+*Yc
GO\%;
BbCXlO
,i4P$f
n<U~hm>
vsZpU1
t1#19G
1.=*w9
qgXsMo
F.R2,<
G/NjP@f
9.=#1r
3w(8oBP
@+kA q>
pbIFoz
P kuUau
pasy8W
z=3"Lm
tlD24`
G_!SIU
EIp9v-$q
L{e}'H
A^b':&
;ks?y`
@qSU=9I
_O H>x
yTeM9~
.2&F#[W)
Y6Zl9}
vlBSfD
[w4$ZY
M?K~b<
z[JDVm
g.8[gN
'-c+R/]
&Jk3?.
*&>Dxq
?%O|Xs'
|hUgvq
@CSO/R
PfIjkvf
c R)Q!w n
\#-Lm#
c\~h@z
elKQwk
8kYOH2
{m+}9v
Zx\H^:(1
~!.#4A
\5)#Q{
D4SH)."b
Gj9\3-
%.1&YU}B
8Mc_%%
S!!m`su
R}312$
diw%P;
!Jc\b$
NBq1<
z[faTF
':^3$*
OZ"nQ<
rn(f2x
'.eLpT^
N$e'Nk~J
?w>4Gfaaa
cYI;GB
bu_@wGw
-ppF5&G
YckP-?N
_xTE_\
*U$!^#
<(7Mpl
]h}xtFTR
|q=52Uq
x\r?Jo
5za[H@WD
/lI{q``
0Y[dL6
/#M$O!
]Eh&vP
C/H%?1a
!mNPP5E
< X?j@
PXD^KE
awvQQAP
'{CmjD=
a<$`@P
73YBj.
Me)\jJ
cLd"S{
|Nj@~A}
kSlpUQ.
~$w4IM[
K{9C-E
f)7hw\
5IHG1W
UU.ZDN3C\
X,=@O=
zw@!V/
TfNwny
%Czp{Z~
i4t-s2
|@X|S!
WP&dgp
h*I>Bh-W
vSe-xW
TenRE={
^{q]J@E
PvbTRm
'3`mtGJ
-i_166
a6H*Dn
|v{I3U
r$7X?
}jp-`G
tjt1qg)
tH T=;s
$X^"H-
zQcTEb
~{T$}L
]wa-Ag
7S@ al
wM5law/C
t_8LD@A
Z6LzKd
ayoi0s
]kqQpF
{M[y@b_
-W@(u%
V<ryY[u1
U`C|$A
eo5.A74A
w{\ Wzla
)aK}=*
@-BENn)
5C;+n
5M)iz3
18{~pqH
W>EAkg
k-<`\*xc
d(}<5sk
lT8M\@a
jGb#;7|
[`[\<q
xtyng"teP\
aI'{I#
E1OaAy
!,_(J<Xd7
DWGsED
@!t*v~
H>Y`$&~A=
`?c0R[!z\
;{'QSc
F{t\E5E
%u7~=z
XB9v84
*PXTdA-
!IPV_w
uz!PM_@
bb=bbJ^
TF=,OI
pQNJ1@
z4fdY%
2ena8sln
W\dN.}`
X[D:]
D7|i0w+
>T:%kZ
v6sv_=
@&E|-U
td|5Ppc
>`^uzh
B!Yt<Kp
RE/_"aoD
'bK/>f
*O>!A1S
gEnJK1
a?$N([w
^{'x/
#Z(CLw
o{k%s,
HQ4[v9
dG]w~%d
d^^TbJ
s6pss_ #w
J%yn'J
iG`*>r
U+?1S~
E@HpU*
"X&Od@6
i@ga#7
"`6q$DR
0N?llL
-NTDc*7T
II.c.Im
J^u.*p'v
6E:(on
3N'n=7
3Wm=w7xV
M*,R({A
W!+^x:
6D(x-X
x}!e;y=
|2^h7"~
L!(?Z&%(
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
</assembly>PAPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDING
ntdll.dll
advapi32.dll
kernel32.dll
(null)
((((( H
h(((( H
H
iE&xit
h&About ...
System
DataGrid Test Version 1.0
Copyright (C) 2005
DataGrid Test
Hello World!
DATAGRIDTEST
Antivirus Signature
Bkav Clean
Elastic Clean
MicroWorld-eScan Clean
FireEye Clean
CAT-QuickHeal Clean
McAfee Clean
Cylance Clean
VIPRE Clean
Sangfor Clean
CrowdStrike win/malicious_confidence_60% (W)
BitDefender Clean
K7GW Clean
K7AntiVirus Clean
BitDefenderTheta Clean
Cyren Clean
Symantec Clean
ESET-NOD32 Clean
Baidu Clean
APEX Clean
Avast Clean
ClamAV Clean
Kaspersky UDS:DangerousObject.Multi.Generic
Alibaba Clean
NANO-Antivirus Clean
ViRobot Clean
AegisLab Clean
Tencent Clean
Ad-Aware Clean
Emsisoft Clean
Comodo Clean
F-Secure Clean
DrWeb Clean
Zillya Clean
TrendMicro Clean
CMC Clean
Sophos Clean
Ikarus Clean
GData Win64.Trojan.Kryptik.11G54J
Jiangmin Clean
eGambit Clean
Avira Clean
MAX Clean
Antiy-AVL Clean
Kingsoft Clean
Gridinsoft Clean
Arcabit Clean
SUPERAntiSpyware Clean
ZoneAlarm Clean
Microsoft Clean
Cynet Clean
AhnLab-V3 Clean
Acronis Clean
ALYac Clean
TACHYON Clean
VBA32 Clean
Malwarebytes Clean
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Rising Malware.Undefined!8.C (CLOUD)
Yandex Clean
SentinelOne Clean
MaxSecure Clean
Fortinet Clean
Webroot W32.Trojan.Gen
Paloalto Clean
Qihoo-360 Clean
No IRMA results available.