Static | ZeroBOX

PE Compile Time

2021-08-02 10:11:46

PE Imphash

2cdeda7a0aa27475a825e9c41d4d95f0

PEiD Signatures

Armadillo v1.71

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x00006bb7 0x00007000 6.44358253732
.rdata 0x00008000 0x00001186 0x00002000 3.63030337834
.data 0x0000a000 0x0000365c 0x00003000 0.843436221473
.rsrc 0x0000e000 0x00001000 0x00001000 1.09363315293

Resources

Name Offset Size Language Sub-language File type
RT_VERSION 0x0000e058 0x0000037c LANG_ENGLISH SUBLANG_ENGLISH_US data

Imports

Library KERNEL32.dll:
0x408000 GetProcAddress
0x408004 LoadLibraryA
0x408008 lstrlenW
0x408010 CloseHandle
0x408014 WriteFile
0x408018 CreateFileW
0x40801c lstrcatW
0x408020 GetModuleFileNameW
0x408024 RaiseException
0x408028 LocalFree
0x40802c lstrlenA
0x408034 GetStringTypeW
0x408038 GetStringTypeA
0x40803c LCMapStringW
0x408040 LCMapStringA
0x408044 MultiByteToWideChar
0x408048 RtlUnwind
0x40804c GetCommandLineA
0x408050 GetVersion
0x408054 ExitProcess
0x408058 HeapFree
0x40805c HeapAlloc
0x408060 GetCurrentThreadId
0x408064 TlsSetValue
0x408068 TlsAlloc
0x40806c SetLastError
0x408070 TlsGetValue
0x408074 GetLastError
0x408078 TerminateProcess
0x40807c GetCurrentProcess
0x408084 GetModuleFileNameA
0x408090 WideCharToMultiByte
0x40809c SetHandleCount
0x4080a0 GetStdHandle
0x4080a4 GetFileType
0x4080a8 GetStartupInfoA
0x4080ac GetModuleHandleA
0x4080b4 GetVersionExA
0x4080b8 HeapDestroy
0x4080bc HeapCreate
0x4080c0 VirtualFree
0x4080c4 VirtualAlloc
0x4080c8 HeapReAlloc
0x4080cc IsBadWritePtr
0x4080e0 IsBadReadPtr
0x4080e4 IsBadCodePtr
0x4080e8 GetCPInfo
0x4080ec GetACP
0x4080f0 GetOEMCP
0x4080f4 HeapSize
Library USER32.dll:
0x408130 wsprintfW
Library ole32.dll:
0x40813c CoUninitialize
0x408140 CoInitialize
0x408144 CoCreateInstance
0x408148 CoSetProxyBlanket
Library OLEAUT32.dll:
0x4080fc VariantInit
0x408100 SafeArrayGetDim
0x408104 SafeArrayGetLBound
0x408108 SafeArrayGetUBound
0x40810c SafeArrayAccessData
0x408114 SysStringLen
0x408118 SysAllocStringLen
0x40811c SysAllocString
0x408120 VariantClear
0x408124 SysFreeString
0x408128 GetErrorInfo

!This program cannot be run in DOS mode.
`.rdata
@.data
SSSSSPQ
QSSWUP
T$$SRP
D$0_^][d
D$ ShelP
D$(lExe
D$,cute
D$0ExW
D$ BPQ
D$dGetE
D$hnvir
D$lonme
D$pntVa
D$triab
D$xleW
D$$QRPV
D$ ndow
QQSVWd
t.;t$$t(
sO;>|C;~
8t9UW
SS@SSPVSS
t#SSUP
t$$VSS
_^][YY
VC20XC00U
VWuBhp
HSVHWtgHHtF
"WWSh|
PPPPPPPP
PPPPPPPP
tFGQPS
__GLOBAL_HEAP_SELECTED
__MSVCRT_HEAP_SELECT
runtime error
TLOSS error
SING error
DOMAIN error
- unable to initialize heap
- not enough space for lowio initialization
- not enough space for stdio initialization
- pure virtual function call
- not enough space for _onexit/atexit table
- unable to open console device
- unexpected heap error
- unexpected multithread lock error
- not enough space for thread data
abnormal program termination
- not enough space for environment
- not enough space for arguments
- floating point not loaded
Microsoft Visual C++ Runtime Library
Runtime Error!
Program:
<program name unknown>
GetLastActivePopup
GetActiveWindow
MessageBoxA
user32.dll
H:mm:ss
dddd, MMMM dd, yyyy
M/d/yy
December
November
October
September
August
February
January
Saturday
Friday
Thursday
Wednesday
Tuesday
Monday
Sunday
SunMonTueWedThuFriSat
JanFebMarAprMayJunJulAugSepOctNovDec
GetProcAddress
LoadLibraryA
lstrlenW
InterlockedDecrement
CloseHandle
WriteFile
CreateFileW
lstrcatW
GetModuleFileNameW
KERNEL32.dll
wsprintfW
USER32.dll
CoSetProxyBlanket
CoCreateInstance
CoInitializeSecurity
CoUninitialize
CoInitialize
ole32.dll
OLEAUT32.dll
RtlUnwind
GetCommandLineA
GetVersion
ExitProcess
HeapFree
HeapAlloc
GetCurrentThreadId
TlsSetValue
TlsAlloc
SetLastError
TlsGetValue
GetLastError
TerminateProcess
GetCurrentProcess
UnhandledExceptionFilter
GetModuleFileNameA
FreeEnvironmentStringsA
FreeEnvironmentStringsW
WideCharToMultiByte
GetEnvironmentStrings
GetEnvironmentStringsW
SetHandleCount
GetStdHandle
GetFileType
GetStartupInfoA
GetModuleHandleA
GetEnvironmentVariableA
GetVersionExA
HeapDestroy
HeapCreate
VirtualFree
VirtualAlloc
HeapReAlloc
IsBadWritePtr
InitializeCriticalSection
EnterCriticalSection
LeaveCriticalSection
SetUnhandledExceptionFilter
IsBadReadPtr
IsBadCodePtr
GetCPInfo
GetACP
GetOEMCP
MultiByteToWideChar
LCMapStringA
LCMapStringW
GetStringTypeA
GetStringTypeW
InterlockedIncrement
lstrlenA
LocalFree
RaiseException
HeapSize
:u9kole32
CoCreateInstance
.?AV_com_error@@
.?AVtype_info@@
"%s",global
rundll32.exe
((((( H
VS_VERSION_INFO
StringFileInfo
040904b0
Comments
\$Revision: 122570 \$
CompanyName
VanDyke Software, Inc.
FileDescription
License Helper
FileVersion
8.5.0.1740
InternalName
License Helper
LegalCopyright
Copyright (C) 1995-2018 VanDyke Software, Inc.
OriginalFilename
LicenseHelper.exe
ProductName
License Helper
ProductVersion
8.5.0.1740
VarFileInfo
Translation
Antivirus Signature
Bkav Clean
Lionic Trojan.Win32.Jaik.4!c
Elastic Clean
MicroWorld-eScan Gen:Variant.Zusy.396323
FireEye Gen:Variant.Zusy.396323
CAT-QuickHeal Clean
McAfee RDN/Wacatac
Cylance Clean
VIPRE Clean
Sangfor Clean
K7AntiVirus Clean
BitDefender Gen:Variant.Zusy.396323
K7GW Trojan-Downloader ( 0057feab1 )
Cybereason Clean
Baidu Clean
Cyren Clean
Symantec Trojan.Gen.2
ESET-NOD32 a variant of Win32/TrojanDownloader.Agent.FTP
APEX Clean
Paloalto generic.ml
ClamAV Clean
Kaspersky UDS:DangerousObject.Multi.Generic
Alibaba TrojanDownloader:Win32/DropperX.2abc5cbc
NANO-Antivirus Clean
ViRobot Clean
Rising Clean
Ad-Aware Gen:Variant.Zusy.396323
TACHYON Clean
Emsisoft Gen:Variant.Zusy.396323 (B)
Comodo Clean
F-Secure Clean
DrWeb Clean
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition Artemis!Trojan
CMC Clean
Sophos Clean
Ikarus Trojan-Downloader.Win32.Agent
GData Gen:Variant.Zusy.396323
Jiangmin Clean
Webroot W32.Trojan.Gen
Avira TR/Dldr.Agent.xxmmf
Antiy-AVL Clean
Kingsoft Win32.Troj.Generic_a.a.(kcloud)
Gridinsoft Trojan.Win32.Agent.oa
Arcabit Clean
SUPERAntiSpyware Clean
ZoneAlarm Clean
Microsoft Trojan:Win32/Sabsik.FL.A!ml
Cynet Malicious (score: 99)
AhnLab-V3 Dropper/Win.Generic.C4577737
Acronis Clean
BitDefenderTheta Clean
ALYac Gen:Variant.Jaik.47122
MAX malware (ai score=85)
VBA32 BScope.Trojan.Wacatac
Malwarebytes Clean
Panda Clean
Zoner Clean
TrendMicro-HouseCall TROJ_GEN.R002H09H221
Tencent Clean
Yandex Clean
SentinelOne Clean
MaxSecure Clean
Fortinet W32/Agent.FTP!tr.dldr
AVG Win32:DropperX-gen [Drp]
Avast Win32:DropperX-gen [Drp]
CrowdStrike Clean
Qihoo-360 Win32/Trojan.Generic.HgIASZkA
No IRMA results available.