Static | ZeroBOX

PE Compile Time

2021-07-25 12:46:02

PE Imphash

bf43a37a6ae0ed2852f82f44f0a6f32a

PEiD Signatures

Armadillo v1.71

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x00006454 0x00007000 6.19857282982
.rdata 0x00008000 0x000011d2 0x00002000 3.64783861274
.data 0x0000a000 0x000036fc 0x00003000 0.910338254091
.rsrc 0x0000e000 0x00001000 0x00001000 1.24654132549

Resources

Name Offset Size Language Sub-language File type
RT_VERSION 0x0000e058 0x0000041c LANG_ENGLISH SUBLANG_ENGLISH_US data

Imports

Library KERNEL32.dll:
0x408000 lstrlenW
0x408008 GetProcAddress
0x40800c LoadLibraryA
0x408010 CloseHandle
0x408014 WriteFile
0x408018 CreateFileW
0x408020 GetModuleFileNameW
0x408024 RaiseException
0x408028 LocalFree
0x40802c lstrlenA
0x408034 GetStringTypeW
0x408038 GetStringTypeA
0x40803c LCMapStringW
0x408040 LCMapStringA
0x408044 MultiByteToWideChar
0x408048 GetOEMCP
0x40804c RtlUnwind
0x408050 GetCommandLineA
0x408054 GetVersion
0x408058 ExitProcess
0x40805c GetCurrentThreadId
0x408060 TlsSetValue
0x408064 TlsAlloc
0x408068 SetLastError
0x40806c TlsGetValue
0x408070 GetLastError
0x408074 HeapFree
0x408078 HeapAlloc
0x40807c TerminateProcess
0x408080 GetCurrentProcess
0x408088 GetModuleFileNameA
0x408094 WideCharToMultiByte
0x4080a0 SetHandleCount
0x4080a4 GetStdHandle
0x4080a8 GetFileType
0x4080ac GetStartupInfoA
0x4080b0 GetModuleHandleA
0x4080b8 GetVersionExA
0x4080bc HeapDestroy
0x4080c0 HeapCreate
0x4080c4 VirtualFree
0x4080cc IsBadReadPtr
0x4080d0 IsBadWritePtr
0x4080d4 IsBadCodePtr
0x4080e4 VirtualAlloc
0x4080e8 HeapReAlloc
0x4080ec GetCPInfo
0x4080f0 GetACP
0x4080f4 HeapSize
Library USER32.dll:
0x408134 ShowWindow
0x408138 wsprintfW
Library ole32.dll:
0x408144 CoUninitialize
0x408148 CoInitialize
0x40814c CoCreateInstance
0x408150 CoSetProxyBlanket
Library OLEAUT32.dll:
0x4080fc VariantCopy
0x408100 VariantInit
0x408104 SafeArrayGetDim
0x408108 SafeArrayGetLBound
0x40810c SafeArrayGetUBound
0x408110 SafeArrayAccessData
0x408118 SysStringLen
0x40811c SysAllocStringLen
0x408120 SysAllocString
0x408124 VariantClear
0x408128 SysFreeString
0x40812c GetErrorInfo

!This program cannot be run in DOS mode.
`.rdata
@.data
SSSSSPQ
D$@FPF
QQSVWd
t.;t$$t(
1AABBf
sO;>|C;~
8t9UW
SS@SSPVSS
t#SSUP
t$$VSS
_^][YY
VC20XC00U
VWuBhx
HSVHWtgHHtF
PPPPPPPP
PPPPPPPP
tFGQPS
^}%95T
__GLOBAL_HEAP_SELECTED
__MSVCRT_HEAP_SELECT
runtime error
TLOSS error
SING error
DOMAIN error
- unable to initialize heap
- not enough space for lowio initialization
- not enough space for stdio initialization
- pure virtual function call
- not enough space for _onexit/atexit table
- unable to open console device
- unexpected heap error
- unexpected multithread lock error
- not enough space for thread data
abnormal program termination
- not enough space for environment
- not enough space for arguments
- floating point not loaded
Microsoft Visual C++ Runtime Library
Runtime Error!
Program:
<program name unknown>
GetLastActivePopup
GetActiveWindow
MessageBoxA
user32.dll
H:mm:ss
dddd, MMMM dd, yyyy
M/d/yy
December
November
October
September
August
February
January
Saturday
Friday
Thursday
Wednesday
Tuesday
Monday
Sunday
SunMonTueWedThuFriSat
JanFebMarAprMayJunJulAugSepOctNovDec
lstrlenW
InterlockedDecrement
GetProcAddress
LoadLibraryA
CloseHandle
WriteFile
CreateFileW
GetEnvironmentVariableW
GetModuleFileNameW
KERNEL32.dll
wsprintfW
ShowWindow
USER32.dll
CoSetProxyBlanket
CoCreateInstance
CoInitializeSecurity
CoUninitialize
CoInitialize
ole32.dll
OLEAUT32.dll
RtlUnwind
GetCommandLineA
GetVersion
ExitProcess
GetCurrentThreadId
TlsSetValue
TlsAlloc
SetLastError
TlsGetValue
GetLastError
HeapFree
HeapAlloc
TerminateProcess
GetCurrentProcess
UnhandledExceptionFilter
GetModuleFileNameA
FreeEnvironmentStringsA
FreeEnvironmentStringsW
WideCharToMultiByte
GetEnvironmentStrings
GetEnvironmentStringsW
SetHandleCount
GetStdHandle
GetFileType
GetStartupInfoA
GetModuleHandleA
GetEnvironmentVariableA
GetVersionExA
HeapDestroy
HeapCreate
VirtualFree
SetUnhandledExceptionFilter
IsBadReadPtr
IsBadWritePtr
IsBadCodePtr
InitializeCriticalSection
EnterCriticalSection
LeaveCriticalSection
VirtualAlloc
HeapReAlloc
GetCPInfo
GetACP
GetOEMCP
MultiByteToWideChar
LCMapStringA
LCMapStringW
GetStringTypeA
GetStringTypeW
InterlockedIncrement
lstrlenA
LocalFree
RaiseException
HeapSize
.?AV_com_error@@
.?AVtype_info@@
"%s",global
rundll32.exe
https://live.goatgame.live/userf/dat/sqlite.dll
https://live.goatgame.live/userf/dat/29/sqlite.dat
((((( H
VS_VERSION_INFO
StringFileInfo
040904E4
CompanyName
Scooter Software
FileDescription
Beyond Compare
FileVersion
4.3.4.24657
LegalCopyright
Copyright
2020 Scooter Software, Inc.
LegalTrademarks
Beyond Compare
is a registered trademark of Scooter Software, Inc.
OriginalFilename
BCompare.exe
ProductName
Beyond Compare
ProductVersion
Subversion Revision
CompileDate
Friday, February 21, 2020 03:59 PM
VarFileInfo
Translation
Antivirus Signature
Bkav Clean
Lionic Trojan.Win32.Generic.4!c
Elastic Clean
ClamAV Clean
CMC Clean
CAT-QuickHeal Clean
Qihoo-360 Win32/Trojan.Generic.HwcB3n8A
ALYac Trojan.GenericKD.37307201
Malwarebytes Trojan.Downloader
VIPRE Win32.Malware!Drop
Sangfor Riskware.Win32.Agent.ky
CrowdStrike Clean
BitDefender Trojan.GenericKD.37307201
K7GW Trojan-Downloader ( 0057feab1 )
K7AntiVirus Trojan-Downloader ( 0057feab1 )
BitDefenderTheta Clean
Cyren W32/Trojan.WHQN-5155
Symantec Trojan.Gen.MBT
ESET-NOD32 a variant of Win32/TrojanDownloader.Agent.FTP
Baidu Clean
APEX Clean
Paloalto generic.ml
Cynet Malicious (score: 100)
Kaspersky HEUR:Trojan.Win32.Agent.gen
Alibaba TrojanDownloader:Win32/MalwareX.f55c1a01
NANO-Antivirus Clean
SUPERAntiSpyware Clean
MicroWorld-eScan Trojan.GenericKD.37307201
Tencent Clean
Ad-Aware Trojan.GenericKD.37307201
Sophos Mal/Generic-S
Comodo Malware@#3ugxpsnpnbves
F-Secure Clean
DrWeb Trojan.DownLoader40.49527
Zillya Clean
TrendMicro TROJ_GEN.R002C0PGT21
McAfee-GW-Edition RDN/Generic.grp
FireEye Trojan.GenericKD.37307201
Emsisoft Trojan.GenericKD.37307201 (B)
SentinelOne Clean
GData Trojan.GenericKD.37307201
Jiangmin Clean
Webroot Clean
Avira TR/Dldr.Agent.cqkvi
MAX malware (ai score=88)
Antiy-AVL Clean
Kingsoft Win32.Troj.Generic_a.a.(kcloud)
Gridinsoft Malware.Win32.MigratedCloud.cc
Arcabit Trojan.Generic.D2394341
ViRobot Clean
ZoneAlarm HEUR:Trojan.Win32.Agent.gen
Microsoft Trojan:Script/Phonzy.A!ml
AhnLab-V3 Trojan/Win.MalwareX-gen.C4566285
Acronis Clean
McAfee RDN/Generic.grp
TACHYON Clean
VBA32 BScope.Trojan.Wacatac
Cylance Unsafe
Panda Trj/GdSda.A
Zoner Clean
TrendMicro-HouseCall TROJ_GEN.R002C0PGT21
Rising Clean
Yandex Clean
Ikarus Trojan-Downloader.Win32.Agent
eGambit Clean
Fortinet W32/PossibleThreat
AVG Win32:MalwareX-gen [Trj]
Cybereason Clean
Avast Win32:MalwareX-gen [Trj]
MaxSecure Clean
No IRMA results available.