PE Compile Time

2015-07-10 06:24:17

PDB Path

netsh.pdb

PE Imphash

6e4401966a1c239e9f4d1a7eab671d96

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x000095b5 0x00009600 6.46545322047
.data 0x0000b000 0x0000de70 0x00008400 0.207987606321
.idata 0x00019000 0x0000102e 0x00001200 4.92491821819
.didat 0x0001b000 0x00000024 0x00000200 0.331159780117
.rsrc 0x0001c000 0x000007e0 0x00000800 4.33656064984
.reloc 0x0001d000 0x00000b68 0x00000c00 6.61267828825

Resources

Name Offset Size Language Sub-language File type
MUI 0x0001c718 0x000000c8 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_VERSION 0x0001c390 0x00000388 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_MANIFEST 0x0001c0f0 0x0000029e LANG_ENGLISH SUBLANG_ENGLISH_US XML 1.0 document, ASCII text, with CRLF line terminators

Imports

Library msvcrt.dll:
0x1819170 wprintf
0x1819174 fclose
0x1819178 _wfopen
0x181917c _amsg_exit
0x1819180 iswctype
0x1819184 _wcslwr
0x1819188 __wgetmainargs
0x181918c _wcsnicmp
0x1819190 wcspbrk
0x1819194 fputwc
0x1819198 _exit
0x181919c _cexit
0x18191a0 fflush
0x18191a4 exit
0x18191a8 __p__fmode
0x18191ac __setusermatherr
0x18191b0 wcstok
0x18191b4 wcscpy_s
0x18191b8 _initterm
0x18191bc ?terminate@@YAXXZ
0x18191c0 __p__commode
0x18191c4 _XcptFilter
0x18191c8 wcschr
0x18191cc _controlfp
0x18191d4 _wcsicmp
0x18191d8 fgets
0x18191dc free
0x18191e0 wcsrchr
0x18191e4 _wcsdup
0x18191e8 __set_app_type
0x18191ec memcpy
0x18191f0 _wcsupr
0x18191f4 _vsnwprintf
0x18191f8 __iob_func
0x18191fc qsort
0x1819200 memset
Library api-ms-win-core-heap-l1-2-0.dll:
0x1819090 HeapSetInformation
0x1819094 HeapAlloc
0x1819098 GetProcessHeap
0x181909c HeapFree
0x18190a0 HeapReAlloc
Library api-ms-win-core-handle-l1-1-0.dll:
0x1819088 CloseHandle
Library api-ms-win-core-file-l1-2-1.dll:
0x1819078 SetFilePointer
0x181907c WriteFile
0x1819080 CreateFileW
Library api-ms-win-core-errorhandling-l1-1-1.dll:
0x1819070 GetLastError
Library api-ms-win-core-libraryloader-l1-2-0.dll:
0x18190b0 LoadStringW
0x18190b4 LoadLibraryExW
0x18190b8 GetProcAddress
0x18190bc FreeLibrary
0x18190c0 GetModuleHandleW
0x18190c4 GetModuleHandleA
Library api-ms-win-core-registry-l1-1-0.dll:
0x18190fc RegEnumValueW
0x1819100 RegDeleteValueW
0x1819104 RegOpenKeyExW
0x1819108 RegSetValueExW
0x181910c RegGetValueW
0x1819110 RegCloseKey
0x1819114 RegCreateKeyExW
0x1819118 RegQueryInfoKeyW
Library api-ms-win-core-sysinfo-l1-2-1.dll:
0x1819150 GetComputerNameExW
0x1819154 GetTickCount
0x181915c GetVersionExW
Library api-ms-win-core-localization-l1-2-1.dll:
0x18190cc SetThreadUILanguage
0x18190d0 FormatMessageW
Library api-ms-win-core-console-l1-1-0.dll:
0x1819024 GetConsoleMode
0x1819028 SetConsoleMode
0x181902c ReadConsoleW
0x1819030 SetConsoleCtrlHandler
0x1819034 GetConsoleOutputCP
Library api-ms-win-core-processenvironment-l1-2-0.dll:
0x18190d8 GetStdHandle
Library api-ms-win-core-string-l1-1-0.dll:
0x1819120 MultiByteToWideChar
0x1819124 WideCharToMultiByte
Library api-ms-win-core-heap-l2-1-0.dll:
0x18190a8 LocalFree
Library api-ms-win-security-base-l1-2-0.dll:
0x1819164 CheckTokenMembership
0x1819168 CreateWellKnownSid
Library api-ms-win-core-synch-l1-2-0.dll:
0x1819134 CreateEventW
0x1819138 OpenEventW
0x181913c Sleep
0x1819140 SetEvent
0x1819144 ResetEvent
0x1819148 WaitForSingleObject
Library api-ms-win-core-console-l2-1-0.dll:
Library OLEAUT32.dll:
0x1819000 SysAllocString
0x1819004 VariantChangeType
0x1819008 SysFreeString
Library api-ms-win-core-com-l1-1-1.dll:
0x1819010 CoUninitialize
0x1819014 CoSetProxyBlanket
0x1819018 CoCreateInstance
0x181901c CoInitializeEx
Library api-ms-win-core-processthreads-l1-1-2.dll:
0x18190e0 GetCurrentThreadId
0x18190e4 GetCurrentProcessId
0x18190e8 GetCurrentProcess
0x18190ec TerminateProcess
Library api-ms-win-core-profile-l1-1-0.dll:
Library api-ms-win-core-string-obsolete-l1-1-0.dll:
0x181912c lstrcmpiW
Library ntdll.dll:
0x1819208 RtlGUIDFromString
0x181920c WinSqmAddToStream
Library api-ms-win-core-delayload-l1-1-1.dll:
0x181905c DelayLoadFailureHook
0x1819060 ResolveDelayLoadedAPI

Exports

Ordinal Address Name
1 0x1803850 ConvertGuidToString
2 0x18038b0 ConvertStringToGuid
3 0x1808180 DisplayMessageM
4 0x18081f0 DisplayMessageToConsole
5 0x1807d80 FreeQuotedString
6 0x1807cf0 FreeString
7 0x18049e0 GenericMonitor
8 0x1807c30 GetEnumString
9 0x1808370 InitializeConsole
10 0x1807d00 MakeQuotedString
11 0x1807c70 MakeString
12 0x1807520 MatchCmdLine
13 0x1807620 MatchEnumTag
14 0x1807680 MatchTagsInCmdLine
15 0x18078c0 MatchToken
16 0x1808b60 PreprocessCommand
17 0x1807e10 PrintError
18 0x18080b0 PrintMessage
19 0x18080e0 PrintMessageFromModule
20 0x1806080 ProcessCommand
21 0x1808470 RefreshConsole
22 0x1804700 RegisterContext
23 0x18037c0 RegisterHelper
!This program cannot be run in DOS mode.
`.data
.idata
@.didat
@.reloc
api-ms-win-core-registry-l2-2-0.dll
MPR.dll
credui.dll
MPRMSG.dll
InitHelperDll
GetResourceString
netsh.pdb
.CRT$XCA
.CRT$XCAA
.CRT$XCZ
.CRT$XIA
.CRT$XIAA
.CRT$XIY
.CRT$XIZ
.gfids$x
.rdata
.rdata$sxdata
.rdata$zzzdbg
.text$mn
.xdata$x
.didat$2
.didat$3
.didat$4
.didat$6
.didat$7
.edata
.idata$5
.00cfg
.idata$2
.idata$3
.idata$4
.idata$6
.didat$5
.rsrc$01
.rsrc$02
L$L_^[3
tJ90tF
u:98u6W
u.90u*
tpVk5H7
NF;w8r
tFk5D7
j2X_^[
PSSSSSS
W9s8v
jWX^[_
j#Yj Zj"_
t<j"Yf;
j=Yf;
L$$_^[3
j"Xf9DJ
u@90u<V
96usVW
u(95X7
jWX_^[]
QQSVW3
QQVWjDX3
VPVVQh
QQSVW3
QQSWhP
;u r*;u$w%
jWX_^[]
@f;D$@t#j
RegConnectRegistryW
WNetCancelConnection2W
WNetAddConnection2W
CredUIParseUserNameW
MprmsgGetErrorString
NETSH.EXE
ConvertGuidToString
ConvertStringToGuid
DisplayMessageM
DisplayMessageToConsole
FreeQuotedString
FreeString
GenericMonitor
GetEnumString
InitializeConsole
MakeQuotedString
MakeString
MatchCmdLine
MatchEnumTag
MatchTagsInCmdLine
MatchToken
PreprocessCommand
PrintError
PrintMessage
PrintMessageFromModule
ProcessCommand
RefreshConsole
RegisterContext
RegisterHelper
_wcsicmp
_vsnwprintf
_wcsupr
_wcsdup
wcsrchr
wcschr
wcscpy_s
wcstok
_wcslwr
iswctype
_wfopen
fclose
wprintf
_wcsnicmp
wcspbrk
fputwc
fflush
_XcptFilter
__p__commode
_amsg_exit
__wgetmainargs
__set_app_type
_cexit
__p__fmode
__setusermatherr
_initterm
msvcrt.dll
?terminate@@YAXXZ
_controlfp
_except_handler4_common
HeapAlloc
GetProcessHeap
HeapFree
CloseHandle
CreateFileW
GetLastError
SetFilePointer
LoadLibraryExW
GetProcAddress
FreeLibrary
RegCreateKeyExW
RegCloseKey
RegSetValueExW
RegOpenKeyExW
RegDeleteValueW
RegQueryInfoKeyW
RegEnumValueW
HeapReAlloc
GetComputerNameExW
SetThreadUILanguage
HeapSetInformation
GetModuleHandleW
SetConsoleCtrlHandler
LoadStringW
GetConsoleMode
GetStdHandle
SetConsoleMode
ReadConsoleW
MultiByteToWideChar
GetConsoleOutputCP
WriteFile
WideCharToMultiByte
FormatMessageW
LocalFree
CreateWellKnownSid
CheckTokenMembership
OpenEventW
SetEvent
GetConsoleScreenBufferInfo
FillConsoleOutputCharacterW
FillConsoleOutputAttribute
SetConsoleCursorPosition
CreateEventW
CreateConsoleScreenBuffer
SetConsoleScreenBufferSize
SetConsoleActiveScreenBuffer
WaitForSingleObject
ResetEvent
RegGetValueW
CoCreateInstance
CoSetProxyBlanket
CoUninitialize
GetVersionExW
CoInitializeEx
UnhandledExceptionFilter
SetUnhandledExceptionFilter
GetCurrentProcess
TerminateProcess
GetModuleHandleA
QueryPerformanceCounter
GetCurrentProcessId
GetCurrentThreadId
GetSystemTimeAsFileTime
GetTickCount
api-ms-win-core-heap-l1-2-0.dll
api-ms-win-core-handle-l1-1-0.dll
api-ms-win-core-file-l1-2-1.dll
api-ms-win-core-errorhandling-l1-1-1.dll
api-ms-win-core-libraryloader-l1-2-0.dll
api-ms-win-core-registry-l1-1-0.dll
api-ms-win-core-sysinfo-l1-2-1.dll
api-ms-win-core-localization-l1-2-1.dll
api-ms-win-core-console-l1-1-0.dll
api-ms-win-core-processenvironment-l1-2-0.dll
api-ms-win-core-string-l1-1-0.dll
api-ms-win-core-heap-l2-1-0.dll
api-ms-win-security-base-l1-2-0.dll
api-ms-win-core-synch-l1-2-0.dll
api-ms-win-core-console-l2-1-0.dll
OLEAUT32.dll
api-ms-win-core-com-l1-1-1.dll
api-ms-win-core-processthreads-l1-1-2.dll
api-ms-win-core-profile-l1-1-0.dll
lstrcmpiW
api-ms-win-core-string-obsolete-l1-1-0.dll
RtlGUIDFromString
WinSqmAddToStream
ntdll.dll
__iob_func
ResolveDelayLoadedAPI
DelayLoadFailureHook
api-ms-win-core-delayload-l1-1-1.dll
memcpy
memset
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<!-- Copyright (c) Microsoft Corporation -->
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<assemblyIdentity
version="5.1.0.0"
processorArchitecture="x86"
name="Microsoft-Windows-NetSh"
type="win32"
<description>netsh command line utility</description>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v3">
<security>
<requestedPrivileges>
<requestedExecutionLevel
level="asInvoker"
uiAccess="false"
/>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
0 1$1D<H<P<X<K?R?]?q?
0K0X0_0t0{0
3&3-3:3A3
7+7Y7|7
8&9-9E9y9
:2:=:D:
;N;e;q;
?2?:?A?L?h?
0)000K0S0Y0b0g0
1#1J1P1y1
353B3x3
434@4p4w4
7"707U7^7e7m7
9)949?9V9]9c9j9y9
9):6:F:M:t:
;(;/;>;Q;X;d;l;
<><R<[<e<y<
=O=]=d=
>>D>O>Z>j>u>
?2?<?F?n?t?}?
0$0:0A0O0V0
0F1Q1e1w1
3&3S3m3|3
4"4,4A4K4
5.6d6k6
:9:G:h:
<.=E=)>D>L>p>~>
>&?7?b?
515D5\5
66$656A6
7$7+747;7D7[7f7
9%9K9R9c9
; <'<5<<<Z=a=l>
?#?I?P?
0)000A0H0[0
0(1/1K1R1a1h1
1$2+2O2V2f2m2
3#3G3N3s3z3
4#4J4Q4u4|4
71787A7H7U7j7x7
848;8`8g8w8~8
8+929>9E9
:):2:7:c:
;+;2;L;S;_;f;w;
<+<9<Y<`<
?1?:?I?R?a?j?y?
0)0]0f0
7#7(7/7
8&9-9H9O9c9j9
:+:>:^:e:k:|:
;";>;E;~;
<+=2=>=
= >W>~>
>1?7?^?{?
0^0j0p0v0
2.2I2h2r2y2
3!3,3K3U3y3
4 4'4.444D4
5%5-535c5z5
6+6B6S6Z6c6r6|6
6=7F7p7X8-9Q9
:M:S:_:m:
;;=;D;0<N<^<e<w<
>>4>I>
0*000M0U0[0t0z0
1(1C1J1T1^1h1
1@2p2~2
3/393`3s3
44=4G4`4o4|4
6606A6Q6V6
77%7,757;7C7I7V7^7d7
8!8&8H8N8U8Z8g8v8~8
:!:(:/:7:?:G:S:\:a:g:q:{:
;";);0;7;>;D;P;[;`;e;k;u;
<8===O=m=
=I>d>p>
010C0a0s0
1R1^1|1
0(0,0@0D0X0\0p0t0
10141P1T1h1l1
2(2,2@2D2
`2p2x2
3 3$3(3034383@3D3H3P3T3X3`3d3h3p3t3x3
append
online
offline
{%08X-%04X-%04X-%02X%02X-%02X%02X%02X%02X%02X%02X}
InitHelperDll
ipxmontr.dll
ipxpromn.dll
STRING
SOFTWARE\Microsoft\NetSh
netsh ras diagnostics
commit
unalias
helper
machine
delete
> %1!s!
[%1!s!]
%1!s!>
\\%s\ipc$
GetModuleHandle failed
netsh.exe
api-ms-win-appmodel-runtime-l1-1-0.dll
Error %d in FormatMessageW()
NetshStopRefreshEvent
%1!-14s! -
%1!s!
netsh namespace
DnsClient
netsh branchcache
BranchCache
netsh advfirewall
NetSecurity
Windows Firewall with Advanced Security
netsh firewall
netsh interface
NetTCPIP
TCP/IP
netsh dhcp
DhcpServer
DHCP Server
netsh dnsclient
DNS Client
namespace
branchcache
advfirewall
firewall
interface
dnsclient
routing
tracing
diagnostics
MultiTenancyEnabled
System\CurrentControlSet\Services\RemoteAccess\Parameters
\\%s\root\cimv2
select * from Win32_OperatingSystem
OSType
Version
OSProductSuite
BuildNumber
ServicePackMajorVersion
ServicePackMinorVersion
%d.%d.%d
VS_VERSION_INFO
StringFileInfo
040904B0
CompanyName
Microsoft Corporation
FileDescription
Network Command Shell
FileVersion
10.0.10240.16384 (th1.150709-1700)
InternalName
netsh.exe
LegalCopyright
Microsoft Corporation. All rights reserved.
OriginalFilename
netsh.exe
ProductName
Microsoft
Windows
Operating System
ProductVersion
10.0.10240.16384
VarFileInfo
Translation
Antivirus Signature
Bkav Clean
Lionic Clean
Elastic Clean
ClamAV Clean
CMC Clean
CAT-QuickHeal Clean
Skyhigh Clean
ALYac Clean
Cylance Clean
Zillya Clean
Sangfor Clean
CrowdStrike Clean
Alibaba Clean
K7GW Clean
K7AntiVirus Clean
huorong Clean
Baidu Clean
VirIT Clean
Paloalto Clean
Symantec Clean
tehtris Clean
ESET-NOD32 Clean
APEX Clean
Avast Clean
Cynet Clean
Kaspersky Clean
BitDefender Clean
NANO-Antivirus Clean
ViRobot Clean
MicroWorld-eScan Clean
Tencent Clean
Sophos Clean
F-Secure Clean
DrWeb Clean
VIPRE Clean
TrendMicro Clean
McAfeeD Clean
Trapmine Clean
CTX Clean
Emsisoft Clean
Ikarus Clean
GData Clean
Jiangmin Clean
Webroot Clean
Varist Clean
Avira Clean
Antiy-AVL Clean
Kingsoft Clean
Gridinsoft Clean
Xcitium Clean
Arcabit Clean
SUPERAntiSpyware Clean
ZoneAlarm Clean
Microsoft Clean
Google Clean
AhnLab-V3 Clean
Acronis Clean
VBA32 Clean
TACHYON Clean
Malwarebytes Clean
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Rising Clean
Yandex Clean
TrellixENS Clean
SentinelOne Clean
MaxSecure Clean
Fortinet Clean
AVG Clean
DeepInstinct Clean
alibabacloud Clean
IRMA Signature
Trend Micro SProtect (Linux) Clean
Avast Core Security (Linux) Clean
C4S ClamAV (Linux) Clean
Trellix (Linux) Clean
Sophos Anti-Virus (Linux) Clean
Bitdefender Antivirus (Linux) Clean
G Data Antivirus (Windows) Clean
WithSecure (Linux) Clean
ESET Security (Windows) Clean
DrWeb Antivirus (Linux) Clean
ClamAV (Linux) Clean
eScan Antivirus (Linux) Clean
Kaspersky Standard (Windows) Clean
Emsisoft Commandline Scanner (Windows) Clean
Cuckoo

We're processing your submission... This could take a few seconds.