Static | ZeroBOX

PE Compile Time

2021-07-28 09:05:58

PE Imphash

941705bb9de69d9f126b6b02b46cea7a

PEiD Signatures

Armadillo v1.71

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x00005813 0x00005a00 5.83038652119
.rdata 0x00007000 0x0000080e 0x00000a00 4.16996607441
.data 0x00008000 0x00004100 0x00001400 2.98125904531
.rsrc 0x0000d000 0x000295d8 0x00029600 3.14260354702
.reloc 0x00037000 0x000008f8 0x00000a00 6.4341188335

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x00035f68 0x00000468 LANG_FRENCH SUBLANG_FRENCH GLS_BINARY_LSB_FIRST
RT_ICON 0x00035f68 0x00000468 LANG_FRENCH SUBLANG_FRENCH GLS_BINARY_LSB_FIRST
RT_ICON 0x00035f68 0x00000468 LANG_FRENCH SUBLANG_FRENCH GLS_BINARY_LSB_FIRST
RT_ICON 0x00035f68 0x00000468 LANG_FRENCH SUBLANG_FRENCH GLS_BINARY_LSB_FIRST
RT_ICON 0x00035f68 0x00000468 LANG_FRENCH SUBLANG_FRENCH GLS_BINARY_LSB_FIRST
RT_ICON 0x00035f68 0x00000468 LANG_FRENCH SUBLANG_FRENCH GLS_BINARY_LSB_FIRST
RT_ICON 0x00035f68 0x00000468 LANG_FRENCH SUBLANG_FRENCH GLS_BINARY_LSB_FIRST
RT_ICON 0x00035f68 0x00000468 LANG_FRENCH SUBLANG_FRENCH GLS_BINARY_LSB_FIRST
RT_ICON 0x00035f68 0x00000468 LANG_FRENCH SUBLANG_FRENCH GLS_BINARY_LSB_FIRST
RT_GROUP_ICON 0x000363d0 0x00000084 LANG_FRENCH SUBLANG_FRENCH data
RT_MANIFEST 0x00036458 0x0000017d LANG_ENGLISH SUBLANG_ENGLISH_US XML 1.0 document text

Imports

Library MSVCRT.dll:
0x40702c __setusermatherr
0x407030 _adjust_fdiv
0x407034 __p__commode
0x407038 __p__fmode
0x40703c _initterm
0x407040 _except_handler3
0x407044 __wgetmainargs
0x407048 _controlfp
0x40704c __dllonexit
0x407050 _onexit
0x407054 _wcmdln
0x407058 exit
0x40705c _XcptFilter
0x407060 _exit
0x407064 strncpy
0x407068 atoi
0x40706c isdigit
0x407070 strncmp
0x407074 __set_app_type
0x407078 memset
0x40707c _itoa
Library KERNEL32.dll:
0x407010 VirtualProtect
0x407014 CreateThread
0x407018 Sleep
0x40701c TerminateThread
0x407020 GetModuleHandleW
0x407024 GetStartupInfoW
Library USER32.dll:
0x407084 EnableWindow
0x407088 SetForegroundWindow
0x40708c GetWindowRect
0x407090 GetWindowTextA
0x407094 MessageBoxA
0x407098 CreateWindowExW
0x40709c SendMessageW
0x4070a0 SetActiveWindow
0x4070a4 GetWindow
0x4070a8 SendMessageA
0x4070ac BeginPaint
0x4070b0 EndPaint
0x4070b4 SetWindowTextA
0x4070b8 FillRect
0x4070bc RegisterClassW
0x4070c0 LoadIconW
0x4070c4 SetMenu
0x4070c8 CreateMenu
0x4070cc AppendMenuW
0x4070d0 GetMessageW
0x4070d4 TranslateMessage
0x4070d8 DispatchMessageW
0x4070dc GrayStringA
0x4070e0 GetDC
0x4070e4 UpdateWindow
0x4070ec DestroyWindow
0x4070f0 CreateWindowExA
0x4070f4 PostQuitMessage
0x4070f8 DefWindowProcW
0x4070fc MessageBoxW
Library GDI32.dll:
0x407000 GetStockObject
0x407004 SetBkMode
0x407008 SetDCPenColor
Library WS2_32.dll:
0x407104 closesocket
0x407108 connect
0x40710c htons
0x407110 recv
0x407114 send
0x407118 socket
0x40711c gethostbyname
0x407120 WSAStartup
0x407124 WSACleanup
0x407128 select

!This program cannot be run in DOS mode.
`.rdata
@.data
@.reloc
j(j(h@
Pj(jdh
u#j h@
j(j(h@
j(j(h@
jdj2jFh
jdjPjFh
Pj(jdh
j(j(h@
j2j2jxh
Pj(j2jZh
.text$mn
.idata$5
.rdata
.rdata$zzzdbg
.idata$2
.idata$3
.idata$4
.idata$6
.CRT$XCA
.CRT$XCZ
.CRT$XIA
.CRT$XIZ
.rsrc$01
.rsrc$02
memset
strncmp
isdigit
strncpy
MSVCRT.dll
_XcptFilter
_wcmdln
__wgetmainargs
_initterm
__setusermatherr
_adjust_fdiv
__p__commode
__p__fmode
__set_app_type
_except_handler3
_controlfp
__dllonexit
_onexit
TerminateThread
CreateThread
VirtualProtect
GetModuleHandleW
GetStartupInfoW
KERNEL32.dll
DefWindowProcW
PostQuitMessage
CreateWindowExA
CreateWindowExW
DestroyWindow
EnableWindow
SetForegroundWindow
GetWindowRect
GetWindowTextA
MessageBoxA
MessageBoxW
SendMessageW
SetActiveWindow
GetWindow
SendMessageA
BeginPaint
EndPaint
SetWindowTextA
FillRect
RegisterClassW
LoadIconW
SetMenu
CreateMenu
AppendMenuW
GetMessageW
TranslateMessage
DispatchMessageW
GrayStringA
UpdateWindow
GetWindowTextLengthA
USER32.dll
GetStockObject
SetDCPenColor
SetBkMode
GDI32.dll
WS2_32.dll
tes connect
au serveur %s:%d
static
Aucune r
ponse du serveur : %s:%d
Connect
static
static
static
static
button
static
static
button
static
static
localhost
%s : %d
%s : %d
Bienvenue : %s
static
tes connect
au serveur %s:%d
static
MIDATx
< """""""""""""""""""""""""""""""Ac
#Mu~W#
C$@'wL
.d Y@v
o[<Zo ?
2PK=G.
e]9oI$<
E,j"61
""""""""""""""""""""""""""""""""
<?xml version='1.0' encoding='UTF-8' standalone='yes'?>
<assembly xmlns='urn:schemas-microsoft-com:asm.v1' manifestVersion='1.0'>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v3">
<security>
<requestedPrivileges>
<requestedExecutionLevel level='asInvoker' uiAccess='false' />
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
50:0`0g0n0u0{0
3 3<3B3G3|3
4?4D4L4q4v4~4
5%5/5S5Y5b5g5z5
6#666\6b6k6p6|6
8"8(8.848:8@8F8L8R8Y8_8f8
9G9M9W9\9f9l9
: ;H<u<
<M=R=Z=y=~=
>6>;>C>j>r>w>
?$?+?7?>?~?
0(01060@0V0
1=1E1J1i1n1v1
2,21292L2S2_2f2p2
3!3W3\3f3o3t3~3
374<4D4h4p4u4
5;5B5p5u5
546]6l6}6
88-878
:J:O:W:i:{:
;&;8;v;{;
<.<n<s<{<
<1=6=>=P=b=z=
??&?4?;?B?N?S?]?k?
0,080<0@0D0H0\0`0d0h0l0p0T1Y1a1
2)2k2s2
353:3B3o3t3|3
5$535O5{5
7!7'7-71777;7A7G7M7S7Z7a7f7k7q7w7{7
88%8+81888?8D8I8O8U8Y8_8c8i8o8u8{8
9"9'9-93979=9A9G9M9S9Y9`9g9l9q9w9}9
::%:+:1:7:>:E:J:O:U:{:
:R;W;_;
<*<1<N<X<e<
=#=,=1=;=Q=
>(>0>5>a>h>t>{>
?2?X?^?g?l?x?
0'0,080N0
1$1)1E1J1R1t1y1
2!2-2}2
3 3&30353?3E3O3T3b3
4&4+454D4J4T4Y4c4i4s4x4
5&5+555K5X5\5`5d5h5l5p5t5
9$9)919R9Z9_9p9}9
:?:F:Z:
:";';1;:;?;I;W;s;
;R<Y<j<}<
='=.=;=O=V=j=q=
>->4>H>O>b>i>}>
??&?8?L?S?h?o?
a0g0n0
1"1A1F1N1a1h1t1{1
3Q3Y3~3
3*484?4G4N4\4f4
5o5t5|5
6>6C6L6Q6[6q6}6
77%7+71777=7C7I7O7U7[7a7g7m7s7y7
LYe\/R
U9?uU~
b\/$V>
mBIQ]I
w3+r'a8~;%
?~($__
w(wZj6
xsRE*"
8R!?os
B|HV^.
Iue-n<
a+6apZ
.4rhGv
g6a##E1
z*(e%5
)b.9zg/
(Qt .X)
T|znP~X!.
wT/=};
Rp<-9zU
b9`L9V8R
S.X)hl
# q,hs
%?.M2E
dH;rv5
FpO_\F
<ow sd
{ZE0_(
"MjN]N
*$ym;
fsZ"\Va
1e8-;o
u\&f+J
(@`Xt{Y
9S$KD/
u;@*Aq
',FsIw
^SrzCZRk
X?ra_]
fBI5m|
Ez7/gkq
O@F_W+c
]qdiN0
_K6gb0a
B5?.?Z
ny-{28O+
K?CxRI9
y^L>OB-
O8BiGI
*E7sd~
rT\*4{E
4KcH?P
YCc3lI
Y0bEY.N
9)+# vuXN
-w<QS;`
p%KIcU
< v^g%
<iV0.j
R2b$6<"
rMIMo6
$2K?na>
Rf8?n`
VS<SC
&Sk8l#<'V~
1lahA\
mFP,n(B
aU=O!H
M8_n9p
&Z"+vT
I_"/$K
p&XoYx.j:
FZ"~vT
_}e!u70
T9g!,6
[.AY1`
.K?c9zf
ROq?Y,
?UvTZk
AP&mg
oP%~OP
HT39+*o
o"UCi%~[
MW2YKF
w$n4P;
Q3su1h
Ly`gAPq
>:# lX
,F_VzH
H/Ic6@Wvq
,a`1Dj
zQcAc)
kJH#v;_
hD!WUO
M1`uji5
a~Wrw!=)
:^!W-
a~W$w!8)
3Rz/+-
5R}D?b
3APS&w
/oIi>f
$%)\@"!h
;9-vuQ
^#I%~5*
_IO3Mm
7.c"y
o#5{15
8Q%kFsR
9\6x><
5^'!)xa.
IZrGwd
`wP}g-
jn=Yx>
D=|tUlB`
gQ["+##
'BiXVg
OkRqXv
spK%f`
L#-4$0g%~d
U2nOqD|
9jFP,!my
Q[4YFi
_u(t;&T
a)% v
,4n)6%
oi36K
8Qh;W^O
5R}D?b1
/kH`!y
/e!1Fq#w
,J'3<6
)&Zpj:
ol#<gVG#j
810`SM
r2igh.
F7-<iYxp
kSzn 4@bKva
"";Oq2j"{
8n*rI)
RqTR[O?n3zg'3
UvTZkv
uF|q^B
^lO_GA1`
G*$ymK
[p_Z,W
fUhgOq
Xp0yp
Q'#g]yeFCv
_6tUvT
N!N{6cwBi
6tUvTo
[!%/5B
6tUvTx
XZ0Mp7
i6tUvT
X%0KpX
XZ0Upu
Xy0;pS
X80@p
W6tUvT
YAp=$\
YAp=$?
6tUvTx
l6HUT
CG!L93
N<sFlkRh>@
_i_bDKV
!8U-Tw
&_4=3~m
I4tOz]F
Q budh
$]Kf]W
mL.w^3Vr
KUdcze
z}E?.f*
x[k1V,
lRJv.K
#i5Yd|
KZvK#-
pp1D5J
6vb.%s
oyTb?S
:u^MNk
6[4%J%
q)td56
H/v?Az
<A_C|1G
Jq~:rK
bLR]Q!r
\[kIK`
}qE/k=O
b9~Am6
|OV-WW
%"2=K{r
}`@4pV
|71Ust
phH2[$
AzmT&p
xd!]0=
DArB6k
{z+jV8
3\idsE8
5[rHOtK
5o`J~M
G} z7JY
BQW;{Pk
|Nx$6PX
S<4ZPL.l
vQM,F&s|
)8O2&+L
fRID*?x/W
#UA2D*`+
zv[Qm#
lWK>sh
,oB/%ip]WP
m'1`t(v
wE)3M`
XN#n*/%J5
f:tV1
T$nNBu
?pRSHPE
B(|xhT
0p/Ln*
%_!k41
(:m)K)
Ghw^Pj`
G`e27`_R
ot~kw|
7W(5&B
_Xo-7/Q
vZSc7H|
}#U;z
w_<^-/
tCpiAE
@$;i+z_
YW7y#W
DsY";Y
5a5L(u
Z&R.Y-*
@a;S3/
`Nm3lnS
|a:$RC4
H:_/:*
E)Nj~_
*O0@BPV
yqGUhH
.L7E|b
Qd(n7~1
b?J?xvm
oY}--z<wiy
n NzUm
?5S%N?^w
F(+!]F*
#B6OB5
BUb_Zq
iCzaKTg
d{fFt
~}53^ &
RLmj kp
,vr0q'W
ult((ZQ
~X>[v\
"MZjpD
!?T5"L
L?t/[s
<:e$}v
nBy`^V
?;;UkTh
xRG#]'d
J7`(['
'\i(]_{
3(\I@6
dB@^%Bv
AcUydK
w/g&|
bFZY]=#8
v!@>ax
?NG"@W.
sU7I3`
`woYG{
+>{vb-
/>ED*f
-JV0B5
qR"Ewv
2D9d*,
0aq(]`
^-noi%
Oxr8,Y
.fMs?v
]Kr3c%W}M^
!vWs*B
<_h?yl&
<tNU=)P
N_pFKp
.{aPJ(5
DG/'A/
3QSxZ&
Ih,1J">
;BnV3m
Ekv05]
|Mb5+p
#Ba+vS
:OTm1R,K
S!/T?YN
ydn\|D
<RZ[j1
7>vrW
r7}wti
.>fnx
O`nMxTS
Sv:4.g
m.R.2{
X,5'#(
,?ELQL
vWn0uV>
`ZB3MT
#)t_oiv
'^wQ+i
B&?d."
ZD7"[q
1Y='F[j
*2ITz$/
N#7=<Q4
?R)M~+Q~M
?$K`6ZP
5`zN!KJ
Rl%Yt^
W]EfMS`
#!.VJa.
^cH/?.
.FK$:Uy6
}E0K+^N
h`A!oR
WiKM6{S
jr&[Dpw|_
n; g`H}
qiVq8G
XKhiV|
z_E1_f}
5%1_.2p
xqGW-i
|-Tz>JW
`Kcw.
em.,Vl2
/IvP!?Tb
@jjjjj
Bienvenue sur la console d'administration
static
er un compte
button
Supprimer un compte
button
er une partie
button
Liste des parties
button
connecter
button
initNetwork
Linitialisation du r
seau a echou
gethostbyname
Impossible de r
cupperer l'adresse IP du serveur
Socket
ation du socket a
ation de compte
static
Utilisateur
static
Mot de passe
static
Confirmer le mot de passe
static
er le compte
button
Impossible de cr
er le compte
rifier les champs
Impossible de cr
er le compte
Les mots de passe ne sont pas identiques
Impossible de cr
er le compte
L'utilisateur existe d
ation compte
Le compte a
Une erreur est survenue
Erreur interne
er une partie
static
Nom de la partie
static
Nombre de joueurs :
static
Nombre de bateaux :
static
er la partie
button
Impossible de cr
er la partie
rifier les champs
La partie existe deja
Partie existe
La partie a
Partie cr
Supprimer le compte
button
listbox
Suppression compte
Le compte a
supprm
static
static
button
Partie termin
La partie est termin
Bravo, tu as gagn
Dommage tu as perdu
Bataille Navale
loginClass
toolsClass
adminClass
createAccountClass
deleteAccountClass
createGameClass
listGameClass
manageGameClass
userClass
joinGameClass
waitingGameClass
gameClass
Rejoindre la partie
button
listbox
La partie commencera lorsque l'admin la lancera
Partie jointe
La partie est compl
Impossible de rejoindre la partie
Vous etes deja dans la partie
Erreur
rer la partie
button
listbox
tres r
Utilisateur
static
Mot de passe
static
Se connecter
button
Bataille Navale
Connexion
Cet utilisateur n'
xiste pas
Connexion
Le mot de passe est incorect
Erreur
Une erreur interne est survenue
Expulser
button
Lancer la partie
button
Voir la partie
button
listbox
La game demarre
La game n'est pas encore pleine
Serveur
static
static
button
Rejoindre une partie
button
connecter
button
En attente du serveur...
static
Vous avez
de la partie
Partie quit
Antivirus Signature
Bkav W32.AIDetect.malware2
Lionic Trojan.Win32.Generic.4!c
Elastic malicious (high confidence)
MicroWorld-eScan Trojan.GenericKD.37309042
FireEye Generic.mg.4bd029fab2e1855b
CAT-QuickHeal Clean
McAfee Artemis!4BD029FAB2E1
Cylance Clean
VIPRE Clean
Sangfor Trojan.Win32.Save.a
K7AntiVirus Clean
K7GW Clean
Cybereason Clean
Baidu Clean
Cyren W32/Agent.DEJ.gen!Eldorado
Symantec ML.Attribute.HighConfidence
ESET-NOD32 a variant of Win32/Kryptik.HLWA
APEX Malicious
Paloalto generic.ml
ClamAV Clean
Kaspersky UDS:Backdoor.Win32.Androm.gen
Alibaba Clean
NANO-Antivirus Clean
ViRobot Clean
Rising Trojan.Generic@ML.86 (RDMK:4Bn7+sAsjbeNzOsSO0dvKQ)
Ad-Aware Trojan.GenericKD.37309042
Emsisoft Trojan.GenericKD.37309116 (B)
Comodo TrojWare.Win32.UMal.oeivm@0
F-Secure Clean
BitDefenderTheta Gen:NN.ZexaF.34050.zuZ@aepX59em
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition BehavesLike.Win32.Generic.gh
CMC Clean
Sophos Mal/Generic-S + Troj/Fareit-LVN
SentinelOne Static AI - Suspicious PE
Jiangmin Backdoor.Androm.gsk
MaxSecure Trojan.Malware.300983.susgen
Avira Clean
Antiy-AVL Clean
Kingsoft Win32.Hack.Undef.(kcloud)
Gridinsoft Clean
Arcabit Clean
SUPERAntiSpyware Clean
ZoneAlarm Clean
Cynet Malicious (score: 100)
AhnLab-V3 Trojan/Win.PWSX-gen.R434634
Acronis Clean
VBA32 BScope.Trojan-Dropper.Injector
TACHYON Clean
Malwarebytes Clean
Zoner Clean
TrendMicro-HouseCall Clean
Tencent Win32.Backdoor.Fareit.Auto
Yandex Clean
Ikarus Win32.Outbreak
eGambit Clean
Fortinet Malicious_Behavior.SB
Webroot W32.Malware.Gen
Panda Clean
CrowdStrike win/malicious_confidence_80% (W)
Qihoo-360 Clean
No IRMA results available.