Static | ZeroBOX

PE Compile Time

2021-08-29 19:27:08

PE Imphash

176ae228fdbb9c32a42193217973b3dd

PEiD Signatures

Armadillo v1.71

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x000026ea 0x00003000 5.44427404794
.rdata 0x00004000 0x00000f42 0x00001000 4.27478919909
.data 0x00005000 0x0004a02c 0x0004a000 4.88085637429
.rsrc 0x00050000 0x00002178 0x00003000 1.80929754221

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x00051be0 0x00000568 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED GLS_BINARY_LSB_FIRST
RT_ICON 0x00051be0 0x00000568 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED GLS_BINARY_LSB_FIRST
RT_ICON 0x00051be0 0x00000568 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED GLS_BINARY_LSB_FIRST
RT_GROUP_ICON 0x00052148 0x00000030 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_VERSION 0x00050150 0x00000340 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data

Imports

Library MFC42.DLL:
0x40409c None
0x4040a0 None
0x4040a4 None
0x4040a8 None
0x4040ac None
0x4040b0 None
0x4040b4 None
0x4040b8 None
0x4040bc None
0x4040c0 None
0x4040c4 None
0x4040c8 None
0x4040cc None
0x4040d0 None
0x4040d4 None
0x4040d8 None
0x4040dc None
0x4040e0 None
0x4040e4 None
0x4040e8 None
0x4040ec None
0x4040f0 None
0x4040f4 None
0x4040f8 None
0x4040fc None
0x404100 None
0x404104 None
0x404108 None
0x40410c None
0x404110 None
0x404114 None
0x404118 None
0x40411c None
0x404120 None
0x404124 None
0x404128 None
0x40412c None
0x404130 None
0x404134 None
0x404138 None
0x40413c None
0x404140 None
0x404144 None
0x404148 None
0x40414c None
0x404150 None
0x404154 None
0x404158 None
0x40415c None
0x404160 None
0x404164 None
Library MSVCRT.dll:
0x40416c _controlfp
0x404170 _except_handler3
0x404174 __set_app_type
0x404178 __p__fmode
0x40417c __p__commode
0x404180 _adjust_fdiv
0x404184 __setusermatherr
0x404188 _initterm
0x40418c __getmainargs
0x404190 _acmdln
0x404194 exit
0x404198 _XcptFilter
0x40419c _exit
0x4041a4 __dllonexit
0x4041a8 _CxxThrowException
0x4041ac __CxxFrameHandler
0x4041b0 _onexit
Library KERNEL32.dll:
0x404000 ClearCommError
0x404004 ClearCommBreak
0x404008 SetCommBreak
0x40400c SetCommConfig
0x404010 GetCommConfig
0x404014 TransmitCommChar
0x404018 GetOverlappedResult
0x40401c WriteFile
0x404020 ReadFile
0x404024 CloseHandle
0x404028 CreateFileA
0x40402c CreateEventA
0x404030 FormatMessageA
0x404034 lstrcpynA
0x404038 LocalFree
0x40403c GetLastError
0x404040 FreeLibrary
0x404044 LoadLibraryA
0x404048 GetProcAddress
0x40404c WaitForSingleObject
0x404050 GetCommState
0x404054 SetCommState
0x404058 EscapeCommFunction
0x40405c GetCommProperties
0x404060 GetCommModemStatus
0x404064 SetCommMask
0x404068 GetCommMask
0x40406c FlushFileBuffers
0x404070 PurgeComm
0x404074 SetupComm
0x404078 SetCommTimeouts
0x40407c GetCommTimeouts
0x404080 WaitCommEvent
0x404084 VirtualAlloc
0x404088 VirtualFree
0x40408c GetModuleHandleA
0x404090 GetStartupInfoA

!This program cannot be run in DOS mode.
`.rdata
@.data
L$(_^d
@KHC;V
MFC42.DLL
__CxxFrameHandler
_CxxThrowException
__dllonexit
_onexit
??1type_info@@UAE@XZ
MSVCRT.dll
_XcptFilter
_acmdln
__getmainargs
_initterm
__setusermatherr
_adjust_fdiv
__p__commode
__p__fmode
__set_app_type
_except_handler3
_controlfp
WaitForSingleObject
GetProcAddress
LoadLibraryA
FreeLibrary
GetLastError
LocalFree
lstrcpynA
FormatMessageA
CreateEventA
CreateFileA
CloseHandle
ReadFile
WriteFile
GetOverlappedResult
TransmitCommChar
GetCommConfig
SetCommConfig
SetCommBreak
ClearCommBreak
ClearCommError
GetDefaultCommConfigA
GetCommState
SetCommState
EscapeCommFunction
GetCommProperties
GetCommModemStatus
SetCommMask
GetCommMask
FlushFileBuffers
PurgeComm
SetupComm
SetCommTimeouts
GetCommTimeouts
WaitCommEvent
VirtualAlloc
VirtualFree
GetModuleHandleA
GetStartupInfoA
KERNEL32.dll
.PAVCSerialException@@
This should appear on the serial port
www.xy999.com
6 X{UqD
V\ gte
}43Jby
V\ gte
}43Jby
V\ gte
}43Jby
^Q=Kef]
:F'Y>y
%|3B_2
%3lW;tjV
Kq-T4{s1@
t05VU ;D
Pc|kFP)
Ej6.S y0
Ci'~!b
u/c @U
X+NxN]
esU{V)
`l`1}9
af2ZE(}o
QgI1b\FB
L@HQY&Y
Arp@;lo
N]IKz
(!<=bPW
v(<#M9
bd)Wbl
>A~M>yQg
e$!Ak!z
P~yi4
sl&).,7L
IrrB%v
IrOefn
E+F!x7J
CHH?t!
|A^p<k
*Hk3C~
L>vSrC
N#(^p
ocDJVk
)l}2Qy
YkiU`k
0n,Z3t
`<cufd2?)L
=arKST?Y
<>::*=
3c|R{4
H_;IX"
l,J/o8
e\vb.Z
"iKiPY
^/k~Sl7
NlKxnJ
7A${dOZ
XZlPaa
zQ5NK.wJe
g)!V|A
%^hR3X
iWixsU
%U,i8L
mS(I~i
LVwbIj
k$[S@j?
rE_([N
<ZE_(jTX
#72.]x
|<F.}O
ZM."6j
")[9b!WZ
3}scDl
3}scDl
3}scDl
+uh}.n
-\[t*L:
,cEug#J!
3paAM
%hy5ld
)q=A^~
M|sy$
opH=(Jv
P6/mp}
"_{,?O
JrZ%z'
4jQP@p
E)r&JG
gkrkna
s_jNt<N
$81@dk
U]xCfs
/^Yb3Z
7Ji^52
)ixbM?Fuf
uo8!v
Sc 9[=
YPd!P|F
Lg$"Cw7
L'Dz)0
^C<H3;/
D,WY[c
<WEei?Y6
V\ gte
}43Jby
V\ gte
}43Jby
V\ gte
}43Jby
V\ gte
}43Jby
(@e:P
0*0"yXc
mf^6Sr
USCk|7
` h1OJ
Em9<0$Ll
[.z!O=
d`25Fha
B(S^a~/
AQIpc
~G.:pwL
ch#^&rT
ar*R*r.
dg3Gx
#af^EJ_M
G Z\GSv_
u4Mv96
Z;aVUs&
}d0k`v
)SOA^.
6yiAn
E6qcb
0]#YI]
|ev goz
;O! Y6
j)Ou}K6
<4r'qlJ
t>j@vF
aY_Pbv;
C8g21i
)\?sw$;q
JKxTMXA3(
8{WD^~
szn]|
=%&w}H
OX"R#\P
!n7>JGC
sRepEW
i|CsPX
b[Bk>`,
N%IKA1
'v8S<h
R}>oO2
}TcbL[s
[]qZTzx
PeMgo=
#$+w,f
r$M=g=6R
).S*75
hR<5saA
iQ6g8t
~J"evC
+dJ(Zn
`+Xo-qk
o+YUksy>:f
/X+leF
v?rH3`
6Gxr<$
s~<Q_F
*=f9SA
Wx6`#hE,
\WHhT%hL
ua]W7WV
XB=WmJ,79S
z:.[3 z
6vE%iEb
!@#AE?5s@
["oc{y
<[vv:]
JY`RUK
|gi>Bt
;iA17^
da&|;LA
^k 5m[0
%6&I(med
CtpIvK8
Wkn0M9
4rS\97o>
:8lnmp
Z,7U>S"*D*
Typ*Ia
.?4Ok}
|j_3Jl
JiZY~b
PXCS$m
@pr(=|
W+Y7DD
N?QunW
xU'.Y5
Ne1=hQ
F3LLDPeD
VE#7bm
ZJWV#++B
{OsJu)N
c f*5h
Au9Ta8
}Qky=)
>6]Bm0t
Cwn,E
&OJF@e
YFtbI_t
FidPAF
UaK#z?
-Vp4>P
oLaT4a
S[CU,}c
Dgltp3
EPQ6wH
dj(?^9
r_g[x>
rP8P8
"zmXyG
f:E}l
CSerialPort
CSerialException
CancelIo
KERNEL32.DLL
.PAVCObject@@
.PAVCException@@
\\.\COM%d
kernel32.dll
HeapFree
GetProcessHeap
HeapAlloc
HeapReAlloc
VirtualAlloc
VirtualProtect
VirtualFree
KERNEL32.dll
.?AVtype_info@@
HrCg@b
VS_VERSION_INFO
StringFileInfo
080404b0
Comments
CompanyName
FileDescription
SerialPort
FileVersion
1, 0, 0, 1
InternalName
SerialPort
LegalCopyright
(C) 2021
LegalTrademarks
OriginalFilename
SerialPort.exe
PrivateBuild
ProductName
China SerialPort
ProductVersion
1, 0, 0, 1
SpecialBuild
VarFileInfo
Translation
Antivirus Signature
Bkav W32.AIDetect.malware1
Lionic Clean
Elastic malicious (high confidence)
MicroWorld-eScan Gen:Variant.Zusy.401736
FireEye Generic.mg.759e5f4dbc7432a8
CAT-QuickHeal Backdoor.Farfli
McAfee GenericRXAA-FA!759E5F4DBC74
Cylance Unsafe
Zillya Clean
Sangfor Suspicious.Win32.Save.a
K7AntiVirus Trojan ( 004d35321 )
BitDefender Gen:Variant.Zusy.401736
K7GW Trojan ( 004d35321 )
Cybereason malicious.dbc743
BitDefenderTheta Gen:NN.ZexaF.34170.uq0@a0Pur9hb
Cyren Clean
Symantec ML.Attribute.HighConfidence
ESET-NOD32 a variant of Win32/Injector.CJVZ
Baidu Clean
APEX Malicious
Paloalto generic.ml
ClamAV Clean
Alibaba Backdoor:Win32/Farfli.3ec251ac
NANO-Antivirus Trojan.Win32.Farfli.jcgarw
ViRobot Clean
Tencent Malware.Win32.Gencirc.10cf2784
Ad-Aware Gen:Variant.Zusy.401736
TACHYON Clean
Comodo TrojWare.Win32.Magania.F@7jjkv4
F-Secure Clean
DrWeb Clean
VIPRE Clean
TrendMicro Backdoor.Win32.ZEGOST.SMAL02
McAfee-GW-Edition Artemis!Trojan
CMC Clean
Emsisoft Gen:Variant.Zusy.401736 (B)
Ikarus Trojan.Win32.Injector
GData Gen:Variant.Zusy.401736
Jiangmin Backdoor.Farfli.ffr
Webroot Clean
Avira TR/Injector.xgpce
Antiy-AVL Trojan/Generic.ASMalwS.3483B88
Kingsoft Clean
Gridinsoft Trojan.Win32.Downloader.sa
Arcabit Clean
SUPERAntiSpyware Clean
Microsoft Trojan:Win32/Farfli.DSK!MTB
Cynet Malicious (score: 100)
AhnLab-V3 Backdoor/Win.ZEGOST.C4620367
Acronis Clean
VBA32 BScope.Backdoor.Zegost
MAX malware (ai score=88)
Malwarebytes Malware.AI.2807775092
Panda Trj/GdSda.A
Zoner Clean
TrendMicro-HouseCall Backdoor.Win32.ZEGOST.SMAL02
Rising Trojan.Kryptik!1.D32C (CLASSIC)
Yandex Trojan.Injector!01N01P9nhGc
SentinelOne Static AI - Malicious PE
MaxSecure Clean
Fortinet W32/Farfli.BNZS!tr
AVG Win32:Trojan-gen
Avast Win32:Trojan-gen
CrowdStrike win/malicious_confidence_90% (W)
No IRMA results available.