Static | ZeroBOX

PE Compile Time

2021-08-11 09:16:24

PE Imphash

48cf05311e4a3e8be7b754cbebbc2209

PEiD Signatures

Armadillo v1.71

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x00004d26 0x00004e00 6.05381205856
.rdata 0x00006000 0x0000144c 0x00001600 5.0842548884
.data 0x00008000 0x000019d4 0x00000200 0.0572566022412
.rsrc 0x0000a000 0x000001e0 0x00000200 4.70150325825

Resources

Name Offset Size Language Sub-language File type
RT_MANIFEST 0x0000a060 0x0000017d LANG_ENGLISH SUBLANG_ENGLISH_US XML 1.0 document text

Imports

Library COMCTL32.dll:
0x406004 CreateToolbarEx
0x406008 CreateStatusWindowW
0x40600c PropertySheetW
Library KERNEL32.dll:
0x406040 GetLocalTime
0x406044 VirtualProtect
0x406048 GetModuleHandleW
0x40604c LoadLibraryW
0x406050 HeapFree
0x406054 lstrcmpW
0x406058 lstrcmpiW
0x40605c lstrcpynW
0x406060 lstrcpyW
0x406064 lstrcatW
0x406068 lstrlenW
0x40606c GetDateFormatW
0x406070 GetTimeFormatW
0x406074 GetModuleHandleA
0x406078 HeapReAlloc
0x40607c HeapAlloc
0x406080 GetLastError
0x406084 CloseHandle
0x406088 WriteFile
0x40608c SetFilePointer
0x406090 GetProcessHeap
0x406094 ReadFile
0x406098 CreateFileW
0x40609c GetCommandLineW
0x4060a0 MulDiv
0x4060a4 GetStartupInfoA
Library USER32.dll:
0x40611c InvalidateRect
0x406120 SetWindowTextA
0x406124 SetWindowTextW
0x406128 GetWindowTextA
0x40612c GetWindowTextW
0x406134 GetClientRect
0x406138 GetWindowRect
0x40613c MessageBoxA
0x406140 MessageBoxW
0x406144 MessageBoxIndirectW
0x406148 ClientToScreen
0x40614c MapWindowPoints
0x406150 GetSysColorBrush
0x406154 IntersectRect
0x406158 IsRectEmpty
0x40615c GetWindowLongW
0x406160 ReleaseDC
0x406164 LoadCursorW
0x406168 LoadIconW
0x40616c LoadImageW
0x406170 IsDialogMessageW
0x406174 MonitorFromRect
0x406178 GetMonitorInfoW
0x40617c TrackPopupMenu
0x406180 PostQuitMessage
0x406184 DefWindowProcW
0x406188 PostMessageW
0x40618c SendMessageW
0x406190 PeekMessageW
0x406194 DispatchMessageW
0x406198 TranslateMessage
0x40619c GetMessageW
0x4061a4 wsprintfW
0x4061a8 LoadStringW
0x4061ac GetDC
0x4061b0 RegisterClassExW
0x4061b4 GrayStringW
0x4061b8 SetMenuItemInfoW
0x4061bc TrackPopupMenuEx
0x4061c0 GetSubMenu
0x4061c4 EnableMenuItem
0x4061c8 CheckMenuItem
0x4061cc SetMenu
0x4061d0 GetMenu
0x4061d4 LoadMenuW
0x4061d8 GetSystemMetrics
0x4061e0 LoadAcceleratorsW
0x4061e4 EnableWindow
0x4061e8 SetFocus
0x4061ec IsDlgButtonChecked
0x4061f0 CheckRadioButton
0x4061f4 CheckDlgButton
0x4061f8 GetDlgItem
0x4061fc EndDialog
0x406200 DialogBoxParamW
0x406204 IsWindowVisible
0x406208 MoveWindow
0x40620c GetMenuItemInfoW
0x406210 ShowWindow
0x406214 SetWindowLongW
0x406218 CreateWindowExW
0x40621c SetActiveWindow
Library GDI32.dll:
0x40602c GetDeviceCaps
0x406030 SelectObject
0x406034 GetTextExtentPointW
0x406038 EnumFontFamiliesExW
Library COMDLG32.dll:
0x406014 ChooseFontW
0x406018 ReplaceTextW
0x40601c GetSaveFileNameW
0x406020 GetOpenFileNameW
0x406024 FindTextW
Library SHELL32.dll:
0x406108 DragAcceptFiles
0x40610c DragFinish
0x406110 DragQueryFileW
0x406114 ShellAboutW
Library MSVCRT.dll:
0x4060ac _controlfp
0x4060b0 _except_handler3
0x4060b4 __set_app_type
0x4060b8 __p__fmode
0x4060bc __p__commode
0x4060c0 _adjust_fdiv
0x4060c4 __setusermatherr
0x4060c8 _initterm
0x4060cc __getmainargs
0x4060d0 _acmdln
0x4060d4 exit
0x4060d8 _XcptFilter
0x4060dc _exit
0x4060e0 memset
0x4060e4 memcpy
0x4060e8 isspace
0x4060ec atoi
0x4060f0 wcstod
0x4060f4 qsort
0x4060f8 _errno
0x4060fc _onexit
0x406100 __dllonexit

!This program cannot be run in DOS mode.
`.rdata
@.data
t"j4h(b@
j0h(b@
t.j"Yf;
SSPPhA
VSh$d@
PPh@d@
PPh@d@
XPPPPj
PPh\d@
uj0h(b@
WWWWWP
jjXPjjjhS
j@h(b@
tj@h(b@
j3h(b@
j@h(b@
j@h(b@
Error code %u
selection = %d..%d, line count=%ld
Start = %d, End = %d
Editor
.text$mn
.idata$5
.rdata
.rdata$zzzdbg
.idata$2
.idata$3
.idata$4
.idata$6
.CRT$XCA
.CRT$XCZ
.CRT$XIA
.CRT$XIZ
.rsrc$01
.rsrc$02
PropertySheetW
InitCommonControlsEx
CreateToolbarEx
CreateStatusWindowW
COMCTL32.dll
GetCommandLineW
CreateFileW
ReadFile
SetFilePointer
WriteFile
CloseHandle
GetLastError
HeapAlloc
HeapReAlloc
HeapFree
GetProcessHeap
GetLocalTime
VirtualProtect
GetModuleHandleW
LoadLibraryW
MulDiv
lstrcmpW
lstrcmpiW
lstrcpynW
lstrcpyW
lstrcatW
lstrlenW
GetDateFormatW
GetTimeFormatW
KERNEL32.dll
LoadStringW
wsprintfW
RegisterWindowMessageW
GetMessageW
TranslateMessage
DispatchMessageW
PeekMessageW
SendMessageW
PostMessageW
DefWindowProcW
PostQuitMessage
RegisterClassExW
CreateWindowExW
ShowWindow
MoveWindow
IsWindowVisible
DialogBoxParamW
EndDialog
GetDlgItem
CheckDlgButton
CheckRadioButton
IsDlgButtonChecked
SetFocus
EnableWindow
LoadAcceleratorsW
TranslateAcceleratorW
GetSystemMetrics
LoadMenuW
GetMenu
SetMenu
CheckMenuItem
EnableMenuItem
GetSubMenu
TrackPopupMenu
TrackPopupMenuEx
GetMenuItemInfoW
SetMenuItemInfoW
GrayStringW
SetActiveWindow
ReleaseDC
InvalidateRect
SetWindowTextA
SetWindowTextW
GetWindowTextA
GetWindowTextW
GetWindowTextLengthW
GetClientRect
GetWindowRect
MessageBoxA
MessageBoxW
MessageBoxIndirectW
ClientToScreen
MapWindowPoints
GetSysColorBrush
IntersectRect
IsRectEmpty
GetWindowLongW
SetWindowLongW
LoadCursorW
LoadIconW
LoadImageW
IsDialogMessageW
MonitorFromRect
GetMonitorInfoW
USER32.dll
EnumFontFamiliesExW
GetDeviceCaps
GetTextExtentPointW
SelectObject
GDI32.dll
GetOpenFileNameW
GetSaveFileNameW
FindTextW
ReplaceTextW
ChooseFontW
COMDLG32.dll
DragQueryFileW
DragFinish
DragAcceptFiles
ShellAboutW
SHELL32.dll
_errno
wcstod
isspace
memcpy
memset
MSVCRT.dll
_XcptFilter
_acmdln
__getmainargs
_initterm
__setusermatherr
_adjust_fdiv
__p__commode
__p__fmode
__set_app_type
_except_handler3
_controlfp
__dllonexit
_onexit
GetModuleHandleA
GetStartupInfoA
<?xml version='1.0' encoding='UTF-8' standalone='yes'?>
<assembly xmlns='urn:schemas-microsoft-com:asm.v1' manifestVersion='1.0'>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v3">
<security>
<requestedPrivileges>
<requestedExecutionLevel level='asInvoker' uiAccess='false' />
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
J#FPcY
KMsaU#j
!$-JPF0
kJg,]F
lE x;:
zZ/6`#
R*\<+,
R*\<+,
R*\<+,
RV2JXi
,y5o.EcL$V
>Cg@5y
y!+lj>
71lCX/
sL\<+3b
4*ka%>#
N'yWwVI
Udns2d
CwSW?
2W7DH^rU
l{Z?86.
<3Z?#4
ns]mQo
J'4m3j
)_R<eC
d*D1<!
=)YZN`
C-RDs`
ykhR$B
d'O=+L{
^}b?L3
<OCPxM
P!vf@Du?
hKLC1u/
;LUl%Q
_/FCxr
P,>s\p
MkE}D3
X4'-Q_Lf)
rItX &
j2RSUT
I&[nQJ-
tI1I'1
`ao~-Qn
10E%cdA
"5PCc$
H:5\*ix
(TpGtx
8VG3{Q
@`SMje
@?YXxL6
\*VooN*
~!J]1pm
6qznp`
TJ4'@z
2f9, q
*$ UCF
`0hHCB
!C|VxD
E`_"R^|
ib-p29
L'81FtO1_
WR*\u;
Kyg-zj
&.8lLmt
(Az87Z
,ur";8Z<eeK
"o=F=n*
@HfO8~
TsLP?8
0-\IFp
O-\jFp
[@mn.
k ]Tk
nA={T{
EGXwk4
1 .=>)$
h>M$xkx
@ME#>)
Rp3+F_
]vh+{
Tsp??8
{6lz
:}U}v{\
*a2rOL
#_Y%6`
jXx:q~
AEaRV1SY
f~/q<
1Z~|O"8
&4vIk&
lpT@d
l#_Yt6`
D;dga5
{1FcT&
t9|Vx`
yF9h+l
&'4mgK
rQkmj{T8
UB8Nr4C
U8Nr!ue_&
?VZ=CT
KK NUR}>q
!=6=Za
?%f^I^
+,*:]W5
z_"^0w
b_epDA
op:$VDC]4`
(p\<]T
P)IB*#
)D)@h0#
k#_OWD
?8:My9
.}D;f}a5
&;HM<eH
lpT{d
1zb%cRA
,M2I58~5
tO\C14
_4p6u<
=y>lh+
2Hye`G
l9jU{]Rk`
&YC5d0
C~Wg9,b
#qvPu`
&gi*\<<
l$_4QO
+|Q}/vVnr!C
R*\<+,
rnO>b
gr4O7bT
zB_w%-
wKIpj~
T2r%_
t*|<W,
2r"Opb
t(4L@^5!
,<I'js
Oty4'@
r)OJb,
T2r%_
T2r%_
bv^J4}
;?(xG/
*j<+,
OrnODb
J -2~%
o .0Mz
R*\<+,
T2r%_
R*\<-,vI
{2a%O
R*\</,|I
E*s<+,
45@-5#
4*c<W,I
\2r%j
r7OJbN
- &23%
B E2c%
R*\<+,
m c21%
R*\<+,
W 421%F
dty4'@
_r&O>b
R*\<+,
<t/44@l5o
T2r%_
44@j5o
MrQOmb
&'&bix
q\/CT\t
T2r%_
R*\<+,
Y6:;!%m
k_h6|*
7,\eXM
E%r_+4
yG*v%[
R*\<+,
R*\<+,
R*\<+,
R*\<+,
rnMf:n
R*\<+,
R*\<+,
R*\<+,
R*\<+,
R*\<+,
R*\<+,
R*\<+,
R*\<+,
R*\<+,
R*\<+,
R*\<+,
R*\<+,
R*\<+,
R*\<+,
R*\<+,
R*\<+,
R*\<+,
R*\<+,
R*\<+,
R*\<+,
R*\<+,
R*\<+,
R*\<+,
R*\<+,
R*\<+,
R*\<+,
R*\<+,
R*\<+,
R*\<+,
R*\<+,
R*\<+,
.>SOTFR
SEK.Rm
b@iGJc
UlB_Kk
m#Kyx-
zPgrg5Q
6$,H|l
Tbx$Ib
#pRZ[d
F7F Y]
^=2QajdE
A$O"JS
|&T-<}
3Av{<?
2},[zq6
nr#FBZ(
5Mc+2N
O&#R%Ms
~/pd/W
]ZUN_
09y!IC
.r`SN+
9P;btAX
5S#dk'
(nvC?W
nw?A70
t:|Cko
h|_WtO
zRN"j[
y.4n-v'
;j|W3r
-!If%9T
2m^RGb
wNtQ<
rCl*,a
fsUt';
@D$Qm'
^bqVq
1EDnab
MJY9V}
IOz[`l
qmDSR`
0N2|?*
D;pc.
KkE?:@3RV
rgUy")
zD%@z%r%
?zN5{1
y~ItnR
`e""S
Q#$YBpN
aa3/sj
z1%3rGM{
2}=vr,
coo8/w
l-l9B#'
JXdnu!
V ]54^~
'F(LAh
nL^hE.>?N
zlYc(kt
fI:`$>M
sh~]B#
ro~=gc
-Cy@OGIr+
BBpX#1
o_l($k
X2qI,X
vSlW<m.
*"A{qx6r
S_j0*o
,aBrZd'NI
!#`oTsJz
lr0wO4
GY8H|r_
1A@yw,
sSH)i^
%H1|3?
7OKW<0
gr6\QU/H_
2O,=,q
VxUB@J
bY\DY7
1Gpk`*h
~x`d#J
7g96rz
5=7elr
awwmf)
GHh[cu
oCz{.s
3|`"j`
7{?w$e
pHsRz\
DIyALmW
F64`2o
|M ksa_
pL=D_A
H{/o^4
!9f1U7
yW~l7d
mA/C U
flX3@1
4TyP\`
96RXML
}qz+$i
`HhM,z
&Xx_vQ
AUuF6G
@@1.5/
}W2<V"
!{B$_P
Q}_1fw
r`ldpF
Xk/^|p
M?)VGz$
fI,a&1
*m$hPW
>V>6c`a_
D*alU2
UFq[0;+
D;hM,u8
020{k:
;g<zBs
9_=gH
q?^4fQ
xWH7 B
=rUNM?
#z+=^2
X|$HCV
\O@miL=.
CAL,5Fl+
i;B>$}
8IhE+T
R&E>jy
wn=(Bbx.h
Qs@.@#lx=
2bC$C\
D4](<GZ
ei+I~L%o
k<Vz*'_
HKheXX
XJB&|&
|8-V(V(
8;P^>#4i
SOHhx}Ynz
xVhE4>>
NCS>!:6w
x<X)Uc
}_kIa@
IGx1A.
W7_@F
CPMY=DDf,k
VVpC-b
KW0<t
~A(y!"
xk_n!9M
A-aE4UEq
`uS1"i
`za4uP
mW>h^*_
S1NA$R
/piC|6#
M~]pDp-l:
@zp17hI
sp9DHZ
9\*\}q
% mV?X
YMnXJ7h
-7GSY\
0BGPT~
$z0@}L
{bupa+Y
::|>d_
Xa~_8H
n:d[{.
wo)F5
giyH%D
si.ueYPJ
xV~+!>
573>+w
\,^z
cBETJ{<
f4U/Jc
w%x.}_
;1']e,
aike?0
j^Yni)
8_bka&
f~9rqZO0
=x$y?N#S
dLc@6A
G!MS5 T
QFPoO)
<bK$.(
\}f2&#5L
z|V|tM
(v]sF%
x|Y[fd
sPubg
W [a=gE75H
kU8A"A
AP9RG/
-}%tZW
3^0f#n
C`9#m@W
.{I`mK
XABq<9
>``9:W
[5dlJ"Q
m$3z>p6
W<]?t*h
].o~~:V
Wine Wordpad
WORDPADTOP
PrtPreview
Times New Roman
Courier New
%.2f %s
RICHED20.DLL
RichEdit text
Times New Roman
MAINACCELTABLE
ReBarWindow32
ComboBoxEx32
Static
commdlg_FindReplace
Antivirus Signature
Bkav W32.AIDetect.malware2
Lionic Clean
Elastic malicious (high confidence)
MicroWorld-eScan Clean
CMC Clean
CAT-QuickHeal Clean
McAfee Clean
Cylance Unsafe
Zillya Clean
Sangfor Trojan.Win32.Save.a
K7AntiVirus Clean
BitDefender Clean
K7GW Clean
CrowdStrike Clean
Baidu Clean
Cyren Clean
Symantec ML.Attribute.HighConfidence
ESET-NOD32 Clean
APEX Malicious
Paloalto Clean
ClamAV Clean
Kaspersky VHO:Trojan-Spy.Win32.Noon.gen
Alibaba Clean
NANO-Antivirus Clean
ViRobot Clean
Tencent Clean
Ad-Aware Clean
Emsisoft Clean
Comodo Clean
F-Secure Clean
DrWeb Clean
VIPRE Clean
TrendMicro Clean
McAfee-GW-Edition BehavesLike.Win32.Generic.dc
FireEye Generic.mg.da8a93ada0a33e6d
Sophos Generic ML PUA (PUA)
SentinelOne Clean
GData Clean
Jiangmin Clean
Webroot Clean
Avira Clean
MAX Clean
Antiy-AVL Clean
Kingsoft Clean
Gridinsoft Clean
Arcabit Clean
SUPERAntiSpyware Clean
ZoneAlarm Clean
Microsoft Trojan:Win32/Sabsik.FL.B!ml
Cynet Malicious (score: 100)
AhnLab-V3 Clean
Acronis Clean
VBA32 BScope.Trojan-Dropper.Injector
ALYac Clean
TACHYON Clean
Malwarebytes Clean
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Rising Trojan.Kryptik!1.D84E (CLASSIC)
Yandex Clean
Ikarus Clean
eGambit Unsafe.AI_Score_91%
Fortinet W32/Kryptik.HLWI!tr
BitDefenderTheta Gen:NN.ZexaF.34058.pqZ@aCBwAwci
Qihoo-360 HEUR/QVM07.1.2F5F.Malware.Gen
Cybereason Clean
Avast Clean
MaxSecure Clean
No IRMA results available.