PE Compile Time

2021-04-05 01:06:51

PE Imphash

613dfe2d0a04e1d866e5ba76cf2d03cc

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.rsrc 0x00001000 0x00007f6c 0x00007f6c 6.98552674174
.bss 0x00009000 0x000213b0 0x00000000 0.0
.data 0x0002b000 0x000033d0 0x000033d0 5.93638753955
.text 0x0002f000 0x00000ea4 0x00000ea4 5.15216542884
.fldo 0x00030000 0x00001000 0x00000200 2.22817469136
.l1 0x00031000 0x00001200 0x00001200 5.2917819557
.rsrc 0x00033000 0x00001000 0x00000200 2.68450833465
.idata 0x00034000 0x00001000 0x00000200 2.73021386369
.idata 0x00035000 0x00001000 0x00000200 2.9033174154
.text 0x00036000 0x00001000 0x00000400 3.41948101006
.idata 0x00037000 0x00001000 0x00000400 3.31058652736
.idata 0x00038000 0x00001000 0x00000200 3.43404586288
.pdata 0x00039000 0x00002000 0x00001c00 4.80488632524
.idata 0x0003b000 0x00001000 0x00000400 3.99768931801
.idata 0x0003c000 0x00001000 0x00000200 3.06871253249
.idata 0x0003d000 0x00001000 0x00000400 3.70448324478

Imports

Library ole32.DLL:
0x4312b0 CoCreateInstance
0x4312b4 CLSIDFromString
0x4312b8 CoInitialize
0x4312bc CoUninitialize
Library OLEAUT32.DLL:
0x4312c4 SysAllocString
Library WININET.DLL:
0x4312cc DeleteUrlCacheEntry
Library KERNEL32.DLL:
0x4312dc ExitProcess
0x4312e4 GetCommandLineA
0x4312e8 GetComputerNameA
0x4312ec GetCurrentProcessId
0x4312f0 GetCurrentThreadId
0x4312f4 GetExitCodeThread
0x4312f8 GetFileSize
0x4312fc GetModuleFileNameA
0x431300 GetModuleHandleA
0x431304 CloseHandle
0x431308 GetProcAddress
0x43130c GetSystemDirectoryA
0x431310 GetTempPathA
0x431314 GetTickCount
0x431318 GetVersion
0x43131c GetVersionExA
0x431324 GlobalMemoryStatus
0x431328 CopyFileA
0x431330 IsBadReadPtr
0x431334 IsBadWritePtr
0x431338 LoadLibraryA
0x43133c LocalAlloc
0x431340 LocalFree
0x431344 OpenMutexA
0x431348 CreateFileA
0x43134c ReadFile
0x431350 RtlUnwind
0x431354 SetFilePointer
0x431358 CreateMutexA
0x43135c Sleep
0x431360 TerminateProcess
0x431364 VirtualQuery
0x431368 CreateProcessA
0x43136c WaitForSingleObject
0x431370 WideCharToMultiByte
0x431374 WinExec
0x431378 WriteFile
0x43137c lstrlenA
0x431380 lstrlenW
0x431384 CreateThread
0x431388 DeleteFileA
Library USER32.DLL:
0x431390 GetWindowTextA
0x431394 GetWindowRect
0x431398 FindWindowA
0x43139c GetWindow
0x4313a0 GetClassNameA
0x4313a4 SetFocus
0x4313a8 GetForegroundWindow
0x4313ac LoadCursorA
0x4313b0 LoadIconA
0x4313b4 SetTimer
0x4313b8 RegisterClassA
0x4313bc MessageBoxA
0x4313c0 GetMessageA
0x4313c4 GetWindowLongA
0x4313c8 SetWindowLongA
0x4313cc CreateDesktopA
0x4313d0 SetThreadDesktop
0x4313d4 GetThreadDesktop
0x4313d8 TranslateMessage
0x4313dc DispatchMessageA
0x4313e0 SendMessageA
0x4313e4 PostQuitMessage
0x4313e8 ShowWindow
0x4313ec CreateWindowExA
0x4313f0 DestroyWindow
0x4313f4 MoveWindow
0x4313f8 DefWindowProcA
0x4313fc CallWindowProcA
Library GDI32.DLL:
0x431404 GetStockObject
0x431408 SetBkColor
0x43140c SetTextColor
0x431410 CreateBrushIndirect
0x431414 CreateFontA
Library ADVAPI32.DLL:
0x43141c GetUserNameA
0x431420 RegCreateKeyExA
0x431424 RegCloseKey
0x431428 RegOpenKeyExA
0x43142c RegQueryValueExA
0x431430 RegSetValueExA
0x431434 GetSecurityInfo
0x431438 SetSecurityInfo
0x43143c SetEntriesInAclA
Library CRTDLL.DLL:
0x431444 __GetMainArgs
0x431448 _sleep
0x43144c _stricmp
0x431450 atoi
0x431454 exit
0x431458 memcpy
0x43145c memset
0x431460 printf
0x431464 raise
0x431468 rand
0x43146c signal
0x431470 sprintf
0x431474 srand
0x431478 sscanf
0x43147c strcat
0x431480 strchr
0x431484 strncmp
0x431488 vsprintf
Library NTDLL.DLL:
0x431490 LdrUnloadDll
Library urlmon.dll:
0x400000 IsLoggingEnabledW
Library oleaut32.dll:
0x400000 SysAllocString
Library comdlg32.dll:
Library user32.dll:
0x400000 GetWindow
0x400004 DefMDIChildProcA
0x400008 DrawTextW
0x40000c CopyRect
0x400010 CheckDlgButton
0x400014 GetForegroundWindow
0x400018 CharToOemA
0x40001c GetClassLongA
0x400020 DefWindowProcA
0x400024 GetMenuStringA
0x40002c RegisterClassExA
0x400030 wsprintfA
0x400034 GetWindowTextW
0x400038 GetScrollRange
0x40003c IsIconic
0x400040 CallWindowProcA
0x400044 GetSysColorBrush
0x400048 SetWindowPlacement
0x40004c EnumChildWindows
Library gdi32.dll:
0x400000 SelectClipRgn
0x400004 UpdateColors
0x400008 GetRgnBox
0x40000c GetDeviceCaps
0x400010 SetDIBitsToDevice
0x400014 TextOutA
0x400018 CreateBitmap
0x40001c GetMetaFileBitsEx
0x400020 EnumFontsW
0x400024 SetEnhMetaFileBits
0x400028 SetStretchBltMode
0x40002c BitBlt
0x400030 Rectangle
0x400034 AddFontResourceA
0x400038 GetPath
0x40003c SetBkColor
0x400040 RectVisible
0x400044 FillPath
0x400048 SelectPalette
0x40004c GetPaletteEntries
0x400050 ColorCorrectPalette
Library wininet.dll:
0x400004 DeleteUrlCacheEntry
Library kernel32.dll:
0x400000 GetProcessHeap
0x400004 ReadConsoleA
0x400008 SetPriorityClass
0x40000c EnumSystemGeoID
0x400010 WriteProcessMemory
0x400014 OpenFileMappingA
0x400018 GetCPInfo
0x40001c GetShortPathNameA
0x400020 GetDateFormatA
0x400024 GetCommandLineA
0x400028 VirtualQuery
0x40002c GetLocaleInfoW
0x400030 GetStartupInfoW
0x400034 CreateDirectoryA
0x40003c GetTickCount
0x400040 GetFileSizeEx
0x400044 GetModuleHandleA
0x400048 SetWaitableTimer
0x40004c GetFileAttributesA
0x400050 SetErrorMode
0x400054 CopyFileW
0x400058 GetSystemDirectoryA
0x40005c OpenThread
Library ntdsapi.dll:
0x400000 DsBindWithCredA
0x400004 DsBindA
Library winmm.dll:
0x400000 PlaySoundW
0x400008 joyGetDevCapsW
0x40000c joySetThreshold
0x400010 mmioRead
0x400014 waveOutReset
0x400018 waveOutGetDevCapsA
0x40001c mciGetCreatorTask
0x400020 mmioSetBuffer
0x400024 DrvGetModuleHandle
0x40002c waveInGetPosition
0x400030 waveInGetErrorTextA
0x400034 mmioOpenA
0x400038 midiInMessage
0x40003c midiOutSetVolume
0x400044 timeGetTime
0x400048 mmioWrite
0x40004c DefDriverProc

@.idata
@.idata
@.text
@.idata
@.idata
@.pdata
@.idata
@.idata
@.idata
RB8Bzr
X[Z?KC
BZ'GBZ'OB2,
7 {t0j
B8D&t8R&V
B0'!B2
FZ'OBR
&)sVY~
&KsM\"
F0/1@:
Y/MCY?MB
{uM[PL
LC2l[o
Mn?MMo~
B0'%Bt
IA%@au
q(p/qYp=q
t,uLt4udt
tLu,tTu
L.counted as "n" processors. For the Healthcare Tr
CoCreateInstance
CLSIDFromString
CoInitialize
CoUninitialize
SysAllocString
DeleteUrlCacheEntry
FindFirstUrlCacheEntryA
FindNextUrlCacheEntryA
ExitProcess
ExpandEnvironmentStringsA
GetCommandLineA
GetComputerNameA
GetCurrentProcessId
GetCurrentThreadId
GetExitCodeThread
GetFileSize
GetModuleFileNameA
GetModuleHandleA
CloseHandle
GetProcAddress
GetSystemDirectoryA
GetTempPathA
GetTickCount
GetVersion
GetVersionExA
GetWindowsDirectoryA
GlobalMemoryStatus
CopyFileA
InterlockedIncrement
IsBadReadPtr
IsBadWritePtr
LoadLibraryA
LocalAlloc
LocalFree
OpenMutexA
CreateFileA
ReadFile
RtlUnwind
SetFilePointer
CreateMutexA
TerminateProcess
VirtualQuery
CreateProcessA
WaitForSingleObject
WideCharToMultiByte
WinExec
WriteFile
lstrlenA
lstrlenW
CreateThread
DeleteFileA
GetWindowTextA
GetWindowRect
FindWindowA
GetWindow
GetClassNameA
SetFocus
GetForegroundWindow
LoadCursorA
LoadIconA
SetTimer
RegisterClassA
MessageBoxA
GetMessageA
GetWindowLongA
SetWindowLongA
CreateDesktopA
SetThreadDesktop
GetThreadDesktop
TranslateMessage
DispatchMessageA
SendMessageA
PostQuitMessage
ShowWindow
CreateWindowExA
DestroyWindow
MoveWindow
DefWindowProcA
CallWindowProcA
GetStockObject
SetBkColor
SetTextColor
CreateBrushIndirect
CreateFontA
GetUserNameA
RegCreateKeyExA
RegCloseKey
RegOpenKeyExA
RegQueryValueExA
RegSetValueExA
GetSecurityInfo
SetSecurityInfo
SetEntriesInAclA
__GetMainArgs
_sleep
_stricmp
memcpy
memset
printf
signal
sprintf
sscanf
strcat
strchr
strncmp
vsprintf
ole32.DLL
OLEAUT32.DLL
WININET.DLL
KERNEL32.DLL
USER32.DLL
GDI32.DLL
ADVAPI32.DLL
CRTDLL.DLL
act or omission of the other party; (b) was in the other party
s lawful possession prior to the disclosure and had not been
specifying a 1 Year Hosting Term may only be used for providing internet hosting services.
the original software after you have upgraded and you may not continue to use it or transfer it in any
1. Computer. In this agreement,
computer
means a hardware system (whether physical or virtual)
God; electrical, internet, or telecommunication outage that is not caused by the obligated party; government restrictions
device will be counted as a named user plus in addition to all individuals authorized to use the programs, if such devices can
virtualization, see the Additional Terms.
be a Qualified Military User, in the United States of America, you must be an authorized patron of the
with relevant hardware and software vendors,
CoCreateInstance
CLSIDFromString
CoInitialize
CoUninitialize
SysAllocString
DeleteUrlCacheEntry
FindFirstUrlCacheEntryA
FindNextUrlCacheEntryA
ExitProcess
ExpandEnvironmentStringsA
GetCommandLineA
GetComputerNameA
GetCurrentProcessId
GetCurrentThreadId
GetExitCodeThread
GetFileSize
GetModuleFileNameA
GetModuleHandleA
CloseHandle
GetProcAddress
GetSystemDirectoryA
GetTempPathA
GetTickCount
GetVersion
GetVersionExA
GetWindowsDirectoryA
GlobalMemoryStatus
CopyFileA
InterlockedIncrement
IsBadReadPtr
IsBadWritePtr
LoadLibraryA
LocalAlloc
LocalFree
OpenMutexA
CreateFileA
ReadFile
RtlUnwind
SetFilePointer
CreateMutexA
TerminateProcess
VirtualQuery
CreateProcessA
WaitForSingleObject
WideCharToMultiByte
WinExec
WriteFile
lstrlenA
lstrlenW
CreateThread
DeleteFileA
GetWindowTextA
GetWindowRect
FindWindowA
GetWindow
GetClassNameA
SetFocus
GetForegroundWindow
LoadCursorA
LoadIconA
SetTimer
RegisterClassA
MessageBoxA
GetMessageA
GetWindowLongA
SetWindowLongA
CreateDesktopA
SetThreadDesktop
GetThreadDesktop
TranslateMessage
DispatchMessageA
SendMessageA
PostQuitMessage
ShowWindow
CreateWindowExA
DestroyWindow
MoveWindow
DefWindowProcA
CallWindowProcA
GetStockObject
SetBkColor
SetTextColor
CreateBrushIndirect
CreateFontA
GetUserNameA
RegCreateKeyExA
RegCloseKey
RegOpenKeyExA
RegQueryValueExA
RegSetValueExA
GetSecurityInfo
SetSecurityInfo
SetEntriesInAclA
__GetMainArgs
_sleep
_stricmp
memcpy
memset
printf
signal
sprintf
sscanf
strcat
strchr
strncmp
vsprintf
LdrUnloadDll
ole32.DLL
OLEAUT32.DLL
WININET.DLL
KERNEL32.DLL
USER32.DLL
GDI32.DLL
ADVAPI32.DLL
CRTDLL.DLL
NTDLL.DLL
IsLoggingEnabledW
urlmon.dll
.idata
SysAllocString
oleaut32.dll
.idata
CommDlgExtendedError
comdlg32.dll
.idata
GetWindow
DefMDIChildProcA
DrawTextW
CopyRect
CheckDlgButton
GetForegroundWindow
CharToOemA
GetClassLongA
DefWindowProcA
GetMenuStringA
RegisterClipboardFormatA
RegisterClassExA
wsprintfA
GetWindowTextW
GetScrollRange
IsIconic
CallWindowProcA
GetSysColorBrush
SetWindowPlacement
EnumChildWindows
user32.dll
SelectClipRgn
UpdateColors
GetRgnBox
GetDeviceCaps
SetDIBitsToDevice
TextOutA
CreateBitmap
GetMetaFileBitsEx
EnumFontsW
SetEnhMetaFileBits
SetStretchBltMode
BitBlt
Rectangle
AddFontResourceA
GetPath
SetBkColor
RectVisible
FillPath
SelectPalette
GetPaletteEntries
ColorCorrectPalette
gdi32.dll
FindNextUrlCacheEntryA
DeleteUrlCacheEntry
FindFirstUrlCacheEntryA
wininet.dll
.idata
Preconfigured system-to-system XML-based dialogs for the relevant E-Business Suite Application(s) are provided. Each
DEFICIENT SERVICES, OR IF ORACLE CANNOT SUBSTANTIALLY CORRECT A BREACH IN A
student enrolled in your institution counts as 25% of an FTE Student. The definition of "full-time" and "part-time" is based on
I. JAPA N
counted as "n" processors. For the Healthcare Transaction Base program, only the processors on which Internet Application
act or omission of the other party; (b) was in the other party
s lawful possession prior to the disclosure and had not been
J. Fees and Taxes
of the software.
Upon 45 days written notice, Oracle may audit your use of the programs. You agree to cooperate with Oracle
s audit and
E. INTERNET-BASED FEA TURES; PRIVACY
7. Automatic Update. Software with Click-to-Run technology may periodically check with Microsoft for
Non Employee User - External: is defined as an individual, who is not your employee, contractor or outsourcer, authorized
Upon Oracle
s acceptance of your order, you have the limited right to use the programs and receive any services you ordered
agreement and any Oracle ordering document shall supersede the terms in any purchase order or other non-Oracle ordering
Microsoft
s reasonable control. The limited warranty starts when the first user of your copy of the
not separate or virtualize the components and install them on different computers. The software may
single server or on multiple servers regardless of whether the individual is actively using the programs at any given time. For
created in iProcurement. For Purchasing Intelligence, Purchase Lines are counted as the line items on purchase orders
This file helps us collect information about problems that you have while using the software. When
5. CLASS ACTION WA IVER. A NY PROCEEDINGS TO RESOLVE OR LITIGA TE A NY DISPUTE IN
licensed computer, but only if you comply with all the terms of this agreement. Our software license is
whether or not the individual is actively using the programs at any given time. Professional Users 2003
External are allowed
you have created using the template. This information is used to provide you with content you request
with your employees and agents that protect the confidentiality and proprietary rights of the confidential information of third
the dispatchers, to the field using the programs.
as the licensing rules which are listed below.
means including purchase orders transmitted from Oracle Purchasing) must be licensed separately.
By virtue of this agreement, the parties may have access to information that is confidential to one another (
confidential
computer (the first licensed computer), but only if you comply with all the terms of this agreement.
services.
and others during the applicable year of the Oracle Exchange Marketplace license, regardless of whether any such auction
Order Line: is defined as the total number of order entry line items processed by the program during a 12 month period.
ALL DISPUTES IN COURT BEFORE A JUDGE OR JURY. Instead, all disputes will be resolved before
Can I transfer the software to another computer or user? You may not transfer the software to
O. Other
contracts and other receivables, owned or managed for others, active on the program, plus (4) Book value of non earning
ACCEPT A ND COMPLY WITH THESE TERMS, YOU MAY NOT USE THE SOFTWARE OR
software, and to otherwise prevent unlicensed use of the software, you have no right to use the
acknowledge that you will create and activate an administrator account and password and that the Oracle University Online
o15.officeredir.microsoft.com/r/rlidIRMHelp?clid=1033. You may choose not to use this feature.
C. CHOICE OF LAW
create this contract that applies to you. You can review linked terms by pasting the forward link into your
the end of your extended subscription period. See the software activation screens or other accompanying
licensed program on the processors where a licensed Oracle Database (Standard Edition and/or Enterprise Edition) is installed
U.S. $1,000 (Seven hundred and seventy-two euros) increment of your gross annual revenue as reported to the SEC in your
shall return or destroy, all copies of the applicable TRMs.
ATTORNEY GENERA L ACTION, OR IN A NY OTHER PROCEEDING IN WHICH EITHER PARTY
Multiple order entry line items may be entered as part of an individual customer order or quote and may also be automatically
an employee of an organization that has a Microsoft Volume License agreement with Software
Purchasing, Professional Users
External are allowed to manually enter orders directly into these programs but any orders
God; electrical, internet, or telecommunication outage that is not caused by the obligated party; government restrictions
4. Updates and Upgrades. You may only obtain updates or upgrades for the software from Microsoft or
must be a Qualified Educational User to use software marked as
University,
Academic Edition
You and Microsoft will attempt to resolve any dispute through informal negotiation within 60 days from
THE DISPUTE WILL BE CONDUCTED EXCLUSIVELY BY BINDING ARBITRA TION. YOU ARE
RETA IL LIMITED WARRA NTY
Microsoft Corporation, A TTN: LCA ARBITRA TION, One Microsoft Way, Redmond, WA 98052-
software after the time permitted for activation and you may not bypass or circumvent
Trainee: is defined as an employee, contractor, student or other person who is being recorded by the program.
your order when licensing these applications.)
Technical Reference Manuals
Export laws and regulations of the United States and any other relevant local export laws and regulations apply to the
Australian Consumer Law. You are entitled to a replacement or refund for a major failure
apply.
use any of these features, you agree to send or receive this information when using that feature. Many of
TERMS A ND CONSENT TO THE TRA NSMISSION OF CERTAIN INFORMA TION DURING
be a Qualified Military User, in the United States of America, you must be an authorized patron of the
as the licensing rules which are listed below.
of Internet users sending X.509 standard encrypted information. They also can be used to digitally sign
12 month period. You may not exceed the licensed number of CRF Pages during any 12 month period unless you acquire
one-year period or for 30 days, whichever is longer. Transferring the software will not extend the term of
updates acquired through technical support. The term
services
refers to technical support, education, outsourcing, consulting
turn on the Office Roaming Service. Turning on the Office Roaming Service sends certain settings
party. We both will use reasonable efforts to mitigate the effect of a force majeure event. If such event continues for more
the same degree of care to safeguard the confidentiality of the TRMs as you exercise to safeguard the confidentiality of your
Special Editions of the software. The components of the software are licensed as a single unit. You may
cause or permit reverse engineering (unless required by law for interoperability), disassembly or decompilation of the
GetProcessHeap
ReadConsoleA
SetPriorityClass
EnumSystemGeoID
WriteProcessMemory
OpenFileMappingA
GetCPInfo
GetShortPathNameA
GetDateFormatA
GetCommandLineA
VirtualQuery
GetLocaleInfoW
GetStartupInfoW
CreateDirectoryA
UnhandledExceptionFilter
GetTickCount
GetFileSizeEx
GetModuleHandleA
SetWaitableTimer
GetFileAttributesA
SetErrorMode
CopyFileW
GetSystemDirectoryA
OpenThread
kernel32.dll
DsBindWithCredA
DsBindA
ntdsapi.dll
.idata
PlaySoundW
GetDriverModuleHandle
joyGetDevCapsW
joySetThreshold
mmioRead
waveOutReset
waveOutGetDevCapsA
mciGetCreatorTask
mmioSetBuffer
DrvGetModuleHandle
mixerGetLineControlsW
waveInGetPosition
waveInGetErrorTextA
mmioOpenA
midiInMessage
midiOutSetVolume
waveOutGetErrorTextW
timeGetTime
mmioWrite
DefDriverProc
winmm.dll
No antivirus signatures available.
IRMA Signature
Trend Micro SProtect (Linux) Clean
Avast Core Security (Linux) Win32:TrojanX-gen [Trj]
C4S ClamAV (Linux) Win.Trojan.Crypted-30
Trellix (Linux) Trojan-FVOJ
Sophos Anti-Virus (Linux) Troj/Agent-BGRP
Bitdefender Antivirus (Linux) Dropped:Backdoor.Padodor.BJ
G Data Antivirus (Windows) Virus: Dropped:Backdoor.Padodor.BJ (Engine A), Win32.Trojan.PSE.11RRK8R (Engine B)
WithSecure (Linux) Trojan.TR/Crypt.ZPACK.Gen2
ESET Security (Windows) a variant of Win32/Padodor.NAX trojan
DrWeb Antivirus (Linux) BackDoor.HangUp.43791
ClamAV (Linux) Win.Trojan.Crypted-30
eScan Antivirus (Linux) Dropped:Backdoor.Padodor.BJ(DB)
Kaspersky Standard (Windows) Trojan-Proxy.Win32.Qukart.gen
Emsisoft Commandline Scanner (Windows) Dropped:Backdoor.Padodor.BJ (B)
Cuckoo

We're processing your submission... This could take a few seconds.