Static | ZeroBOX

PE Compile Time

2021-01-13 04:22:48

PE Imphash

b1b0e62d3ddafa526052777d5f7706b2

PEiD Signatures

Armadillo v1.71

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x0000547a 0x00006000 6.19388342374
.rdata 0x00007000 0x000009d8 0x00001000 3.64912686102
.data 0x00008000 0x0004e75c 0x0004f000 2.61285498338
.rsrc 0x00057000 0x0000cd34 0x0000d000 5.04732330096

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x0006367c 0x00000468 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED GLS_BINARY_LSB_FIRST
RT_ICON 0x0006367c 0x00000468 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED GLS_BINARY_LSB_FIRST
RT_ICON 0x0006367c 0x00000468 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED GLS_BINARY_LSB_FIRST
RT_ICON 0x0006367c 0x00000468 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED GLS_BINARY_LSB_FIRST
RT_ICON 0x0006367c 0x00000468 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED GLS_BINARY_LSB_FIRST
RT_ICON 0x0006367c 0x00000468 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED GLS_BINARY_LSB_FIRST
RT_ICON 0x0006367c 0x00000468 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED GLS_BINARY_LSB_FIRST
RT_ICON 0x0006367c 0x00000468 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED GLS_BINARY_LSB_FIRST
RT_MENU 0x00063ae4 0x0000004a LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_DIALOG 0x00063b30 0x000000ee LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_STRING 0x00063c20 0x00000054 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_ACCELERATOR 0x00063c74 0x00000010 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_GROUP_ICON 0x00063d20 0x00000014 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_GROUP_ICON 0x00063d20 0x00000014 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_GROUP_ICON 0x00063d20 0x00000014 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data

Imports

Library KERNEL32.dll:
0x407000 GetProcAddress
0x407004 GetModuleHandleA
0x407008 RtlUnwind
0x40700c RaiseException
0x407010 GetStartupInfoA
0x407014 GetCommandLineA
0x407018 GetVersion
0x40701c ExitProcess
0x407020 HeapFree
0x407028 TerminateProcess
0x40702c GetCurrentProcess
0x407034 GetModuleFileNameA
0x407040 WideCharToMultiByte
0x40704c SetHandleCount
0x407050 GetStdHandle
0x407054 GetFileType
0x40705c GetVersionExA
0x407060 HeapDestroy
0x407064 HeapCreate
0x407068 VirtualFree
0x40706c WriteFile
0x407070 HeapAlloc
0x407074 VirtualAlloc
0x407078 HeapReAlloc
0x40707c IsBadWritePtr
0x407080 IsBadReadPtr
0x407084 IsBadCodePtr
0x407088 GetCPInfo
0x40708c GetACP
0x407090 GetOEMCP
0x407094 LoadLibraryA
0x407098 MultiByteToWideChar
0x40709c LCMapStringA
0x4070a0 LCMapStringW
0x4070a4 GetStringTypeA
0x4070a8 GetStringTypeW

!This program cannot be run in DOS mode.
`.rdata
@.data
D$0RPj
T$<QRj
L$LQPj
D$$RPj
D$0RPj
T$<QRj
L$ PQj
D$,RPj
D$(RPj
D$HRPW
L$`PQW
QQSVWd
t.;t$$t(
sO;>|C;~
8t9UW
SS@SSPVSS
t#SSUP
t$$VSS
_^][YY
DSUVWh
VC20XC00U
HHtYHHtF
__GLOBAL_HEAP_SELECTED
__MSVCRT_HEAP_SELECT
runtime error
TLOSS error
SING error
DOMAIN error
- unable to initialize heap
- not enough space for lowio initialization
- not enough space for stdio initialization
- pure virtual function call
- not enough space for _onexit/atexit table
- unable to open console device
- unexpected heap error
- unexpected multithread lock error
- not enough space for thread data
abnormal program termination
- not enough space for environment
- not enough space for arguments
- floating point not loaded
Microsoft Visual C++ Runtime Library
Runtime Error!
Program:
<program name unknown>
GetLastActivePopup
GetActiveWindow
MessageBoxA
user32.dll
GetProcAddress
GetModuleHandleA
KERNEL32.dll
RtlUnwind
RaiseException
GetStartupInfoA
GetCommandLineA
GetVersion
ExitProcess
HeapFree
SetUnhandledExceptionFilter
TerminateProcess
GetCurrentProcess
UnhandledExceptionFilter
GetModuleFileNameA
FreeEnvironmentStringsA
FreeEnvironmentStringsW
WideCharToMultiByte
GetEnvironmentStrings
GetEnvironmentStringsW
SetHandleCount
GetStdHandle
GetFileType
GetEnvironmentVariableA
GetVersionExA
HeapDestroy
HeapCreate
VirtualFree
WriteFile
HeapAlloc
VirtualAlloc
HeapReAlloc
IsBadWritePtr
IsBadReadPtr
IsBadCodePtr
GetCPInfo
GetACP
GetOEMCP
LoadLibraryA
MultiByteToWideChar
LCMapStringA
LCMapStringW
GetStringTypeA
GetStringTypeW
www.xy999.com
.rahoc
q-Iw0K
,-23016745
bc`afgdejkhinolmrspqvwtuz
<# !.dpi
&*$%.dpih
<# !.dpi
&*$%.dpih
&*$%.dpih
<# !.dpi
&*$%.dpih
&*$%.dpih
<# !.dpi
<# !.dpi
&*$%.dpih
<# !.dpi
<# !.dpi
&*$%.dpih
<# !.dpi
&*$%.dpih
&*$%.dpih
<# !.dpi
&*$%.dpih
&*$%.dpih
<# !.dpi
<# !.dpi
&*$%.dpih
<# !.dpi
<# !.dpi
&*$%.dpih
<# !.dpi
&*$%.dpih
&*$%.dpih
<# !.dpi
&*$%.dpih
&*$%.dpih
<# !.dpi
<# !.dpi
&*$%.dpih
<# !.dpi
<# !.dpi
&*$%.dpih
<# !.dpi
&*$%.dpih
&*$%.dpih
<# !.dpi
&*$%.dpih
&*$%.dpih
<# !.dpi
<# !.dpi
&*$%.dpih
<# !.dpi
&*$%%$*&
DyW].aU
AV$<Kdn
L081x9
|5%n*Q!
|;%n*Q!
N8%n*Q!
{lIj,%
4[m`v1,
4[m`v21
4[m`vsh
4[m`vd`
4[m`vs`
4[mrha
4[msic
4[mrlz
4[m5=-1
4[m5=00
4[m5=44
4[m7=-1
4[m7=00
4[m7=44
4[mSto
4[mqrhs
4[mihrp
4[mfeha
4[mptps
4[mve`s
h=hhoc
qrranp
rocass
arseon
onproh
h=hhoc
nparhocka`
roc=``rass
hsprclu=
eracporu=
rocass
rocass=
qrranp
rocass
hsprhan=
oenpar
nveronianp
prengs=
reorepu
qrranp
reorepu
nveronianp
arseon
preng=
h=hhoc
l=hhoc
rocass
ropacp
hsprcile=
eracporu=
eha=pprebqpas=
rocass
eracporu=
eha=pprebqpas=
aveca=
rocass
qrranp
rocass32
rocass32
32.`hh
en`ows
wslrenpf=
oragroqn`
ap=sunc
en`ow=
esebha
en`ows
32.`hh
=`jqsp
revehagas
revehaga
rocass
arveca
arveca=
rocass=s
arveca
agespar
arveca
n`har=
arveca
pcdar=
arveca
arveca=
arveca
arveca
onfeg2=
arveca
arveca=
32.`hh
tacqpa
tacqpa=
32.`hh
nenepe
oha32.`hh
ockap=
232.`hh
iaiclu
sprhan
sprclu
iaisap
iaicil
tcalpeon
sprnclu
sprcsln
sprspr
slrenpf
sprcdr
sprcil
sprrcdr
ibsecil
ibscil
snlrenpf
sprncil
atcalpd
n`har3
bagenpdra
fchosa
flrenpf
??-pulaenfo<<
eneppari
`jqspf`ev
`hhonatep
onatep
asprou
agespru
rolarpu=
le.`hh
qrhion.`hh
sprcile
sprqlr
sprecil
fqckuoq
fqckuoq-
ancanp
dqp`own
revehaga
321)--
-),4,,2
-,3-4y
bqffar
!`.!`.!`.!`
wenenap.`hh
onproh:
afarar:
www.mm.coi
=ccalp:
=ccalp)
=ccalp)
nco`eng:
onproh:
sar)=ganp:
pebha;
en`ows
afarar:
dppl://!s
onnacpeon:
aal)=heva
nparnap
tlhorar
eatlhora.ata
onpanp)
patp/dpih
=ccalp:
patp/dpih(
sar)=ganp:
pebha;
!`.,,;
en`ows
onpanp)
patp/dpih
=ccalp:
patp/dpih(
sar)=ganp:
pebha;
!`.,,;
en`ows
dppl://
onnacpeon:
aal)=heva
!`)!`)!`
!`:!`:!`
onnpeon
acqrepu
=llhec
=llhec
eatlhora.ata
nparnap
nparnap
nparnap
nparnap
!c!c!c!c!c!c
karnah32.`hh
bc`afgdejkhinolmrspqvwtuz,-23016745+/
www.tu555.coi
62.230.--3.07
gwawwauc
escovaru
arveca
=llhec
osp.ata
jne`ri
qp32.`hh
nenepe
ha32.`hh
qrranp
rocass
rocass
rocass32
rocass32
oohdahl32
vc.ata
aion.ata
-033.ata
lfw.ata
on.ata
hh.ata
klfwpr
en.ata
qplosp
oqplosp.ata
clf.ata
slarsku
vl.ataa
vsion.ata
=npever
qr`.ata
sle`arnp.ata
vg.ata
ll.ata
nwe`gap.ata
qnpar.ata
deah`.ata
baekas
rior.ata
fa`og.ata
raiql`.ata
vssarv.ata
vgqe.ata
rograss.ata
issacass.ata
gr.ata
vgw`svc.ata
vc.ata
=ganp.
enar.ata
fa.ata
esl.ata
vcanpar.ata
kns`pr
agqe.ata
vl.ata
f)sacqra.ata
sp.ata
vc.ata
ecrosofp
acqrepu
ssanpe
ng.ata
arveca.ata
deah`.ata
ropacp
nslqlsvc.ata
iiqnap
arveca.ata
fegdpar
arveca.ata
=npeverqs
dea`=npeverqs0.ata
acqrepu.ata
con.ata
npe2,-2
onproh
anpar32.ata
ongoos
ongoos
32h`ar.ata
nar4.ata
pcd.ata
r`.ata
36,s`.ata
csdeah`.ata
arseon
qibars
rocassor
skkehh
rqn`hh32.ata
32.`hh
en`at.`
eha=pprebqpas=
`askpol.ene
!s:!`:!s
arnah32.`hh
ap=cpeva
onsoha
asseon
nveronianp
qsaranv.`hh
ecrosofp
en`ows
qrranp
arseon
en`ows
ascrelpeon
qrranp
onproh
arvecas
dppl://-,6.12.-1.-23/suspai.ata
en`ows
suspai.ata
qrranp
askpol
askpol
askpol
qsar32.`hh
askpol=
askpol
revehaga
=`jqsp
revehagas
rocass
32.`hh
pulaenfo<<
-.2i2\2
080l0I0S0
66y6K6
4j4{4@4P4Y4
:e:z:O:
C,K,1-
-`-n-w-
0x0B0R0W0]0
1'1(16181
1`1k1m1{1J1Z1
6"787!44f4@4
4e5z5F5Q5
, ,.,5,
3%3.363>3
3j3v3}3/0E0
4c4j4z4R4
;I;P;];
>$>3>5>
>l>S>U>
-/-6-h-N-
2k2q2|2E2S2^2
0i0v0x0E0Z0
1!1w1D1P1
7d7r7y7F7L7[7
5*53595
5}5H5Y5
:o:w:y:_:
;!;=;K;[;
>B>L>X>
>&?3?4?
2%2r2K2R2U2
7r7u7R7
4i4s4u4U4
8y8D8N8W8
9v9K9M9
>n>t>W>]>
?$?2?9?
-6-o-M-
6074787<7
7`7d7h7l7q7Q7
434w4B4S4
5a5l5}5R5
:b:h:_:
3a3k3m3x3@3]3
0+010?0
0g0m0{0A0O0U0
1!1/151
1E1S1Y1
6!6/656
6E6S6Y6
7%73797
7a7o7u7C7I7W7]7
4#4)474=4
44e4s4y4G4M4[4
5#5)575=5
55e5s5y5G5M5[5
:!:(:7:=:
;!;);4;?;
9)969?9
9n9u9Q9
151`1u1
1f6w6E6
7&7+707a7
8&828<8
9d9v9y9D9^9
?a?j?r?w?
,j,B,G,I,S,U,],
-l-w-y-G-S-Z-
2"2/252?2
3d3t3C3J3X3
1E1R1[1
6/686K6S6
4-454<4
4s4B4I4_4
:s:z:E:N:
;1;g;^;
9|9E9P9\9
>r>K>M>U>
?k?p?E?V?
,n,|,H,X,
-e2u2~2J2M2U2
3j3m3t3L3V3X3
1+6-686
6j6w6%7y7
:":$:.:0:::<:
:`:j:l:v:x:B:D:N:P:Z:\:
; ;*;,;6;8;
;f;h;r;t;~;@;J;L;V;X;
8&8(82848>8
8b8d8n8p8z8|8F8H8R8T8^8
9"9$9.909:9<9
9`9j9l9v9x9B9D9N9P9Z9\9
>~>@>J>L>V>X>
?&?(?2?4?>?
?a?r?z?D?I?R?W?
,l,H,R,T,
- -*-,-6-8-
2!2=2k2q2
0d0t0D0
:p:x:@:H:P:
;h;p;|;X;
8p8x8D8
0 0$0(0,0004080<0
0`0d0h0l0p0t0x0|0@0D0H0L0P0T0X0\0
1 1$1(1,1014181<1
1`1d1h1l1p1t1x1|1@1D1H1L1P1T1X1\1
6 6$6(6,6064686<6
6`6d6h6l6p6t6x6|6@6D6H6L6P6T6X6\6
ocqianps
appengs
=`ienespr
fuckyou
.?AVtype_info@@
$vox_e
:q%(5u
gj$Glkz
O`o~-^8s
s9dC9|
O9})pQa
S}di.^
;.hjZ0vl
Ta*@hf
v;I4ol;s?R
C{O:o][
A3ZA\b0
~w~7+C
PADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPAD
((((( H
iE&xit
h&About ...
System
Xyloder Version 1.0
Copyright (C) 2020
Xyloder
Hello World!
XYLODER
Antivirus Signature
Bkav W32.AIDetect.malware1
Elastic malicious (high confidence)
MicroWorld-eScan DeepScan:Generic.Rincux2.3C4478C2
FireEye Generic.mg.01c087629a99a6cb
CAT-QuickHeal Clean
Qihoo-360 Clean
ALYac DeepScan:Generic.Rincux2.3C4478C2
Cylance Unsafe
VIPRE Trojan.Win32.Generic!BT
AegisLab Clean
Sangfor Trojan.Win32.Farfli.DSK
K7AntiVirus Riskware ( 0040eff71 )
BitDefender DeepScan:Generic.Rincux2.3C4478C2
K7GW Riskware ( 0040eff71 )
Cybereason malicious.29a99a
BitDefenderTheta Gen:NN.ZexaF.34686.zqW@aSaiSPgb
Cyren W32/Trojan.BYFY-6213
Symantec ML.Attribute.HighConfidence
ESET-NOD32 a variant of Win32/GenKryptik.FCQT
Baidu Clean
APEX Malicious
Avast Win32:Malware-gen
ClamAV Win.Dropper.Gh0stRAT-8026915-0
Kaspersky HEUR:Backdoor.Win32.Farfli.gen
Alibaba Backdoor:Win32/Farfli.45eb63e0
NANO-Antivirus Trojan.Win32.Farfli.iudwcf
ViRobot Clean
Rising Trojan.Kryptik!1.D241 (CLOUD)
Ad-Aware DeepScan:Generic.Rincux2.3C4478C2
TACHYON Clean
Emsisoft DeepScan:Generic.Rincux2.3C4478C2 (B)
Comodo TrojWare.Win32.Magania.F@7jjkv4
F-Secure Clean
DrWeb Trojan.MulDrop16.43224
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition RDN/Generic BackDoor
CMC Clean
Sophos Mal/Generic-R + Mal/FakeAV-KL
Ikarus Trojan.Win32.Krypt
GData DeepScan:Generic.Rincux2.3C4478C2
Jiangmin Trojan.Generic.wfzk
Webroot Clean
Avira TR/AD.Farfli.ljbcq
Antiy-AVL Clean
Kingsoft Win32.Hack.Undef.(kcloud)
Gridinsoft Trojan.Win32.Kryptik.vb
Arcabit DeepScan:Generic.Rincux2.3C4478C2
SUPERAntiSpyware Clean
ZoneAlarm HEUR:Backdoor.Win32.Farfli.gen
Microsoft Trojan:Win32/Farfli.DSK!MTB
Cynet Malicious (score: 100)
AhnLab-V3 Backdoor/Win32.RL_Zegost.R361328
Acronis Clean
McAfee RDN/Generic BackDoor
MAX malware (ai score=100)
VBA32 Trojan.Farfli
Malwarebytes Generic.Trojan.Malicious.DDS
Panda Trj/GdSda.A
Zoner Clean
TrendMicro-HouseCall TROJ_GEN.R03AC0DDD21
Tencent Clean
Yandex Trojan.GenAsa!UgP2HmBuAUY
SentinelOne Static AI - Suspicious PE
eGambit Unsafe.AI_Score_99%
Fortinet W32/Farfli.FCQT!tr.bdr
AVG Win32:Malware-gen
Paloalto generic.ml
CrowdStrike win/malicious_confidence_100% (W)
MaxSecure Trojan.Malware.73947863.susgen
No IRMA results available.