Static | ZeroBOX

PE Compile Time

2021-10-09 03:25:22

PDB Path

OfficeDesktop.pdb

PE Imphash

b90ad766f05a0095e6c521f56485a931

PEiD Signatures

Armadillo v1.71

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x00007ce4 0x00008000 6.13479725485
.rdata 0x00009000 0x00053d24 0x00054000 5.71803731097
.data 0x0005d000 0x0000615c 0x00005000 0.322983190112
.rsrc 0x00064000 0x00002d3c 0x00003000 4.2604526171

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x00064310 0x000010a8 LANG_ENGLISH SUBLANG_ENGLISH_US dBase IV DBT of @.DBF, block length 4096, next free block index 40, next free block 0, next used block 0
RT_DIALOG 0x000653b8 0x000004b4 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_STRING 0x000664b0 0x0000021e LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_STRING 0x000664b0 0x0000021e LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_STRING 0x000664b0 0x0000021e LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_STRING 0x000664b0 0x0000021e LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_STRING 0x000664b0 0x0000021e LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_STRING 0x000664b0 0x0000021e LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_ACCELERATOR 0x000668b0 0x000000f0 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_ACCELERATOR 0x000668b0 0x000000f0 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_ACCELERATOR 0x000668b0 0x000000f0 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_GROUP_ICON 0x000669a0 0x00000014 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_VERSION 0x000669b4 0x00000388 LANG_ENGLISH SUBLANG_ENGLISH_US data

Imports

Library ADVAPI32.dll:
0x409000 RegCloseKey
0x409004 RegOpenKeyExW
Library KERNEL32.dll:
0x40900c RtlUnwind
0x409010 GetLastError
0x409014 GetVersion
0x409018 VirtualFree
0x409024 HeapFree
0x409028 GetACP
0x40902c TlsAlloc
0x409030 GetProcessHeap
0x40903c GetCPInfo
0x409044 HeapReAlloc
0x40904c GetStringTypeA
0x409050 GetModuleFileNameA
0x409054 GetVersionExA
0x40905c LCMapStringW
0x409060 CloseHandle
0x409064 GetFileType
0x409068 SetStdHandle
0x40906c GetStdHandle
0x409070 GetOEMCP
0x409074 TlsFree
0x409078 TerminateProcess
0x40907c TlsSetValue
0x409080 TlsGetValue
0x409084 WideCharToMultiByte
0x409088 ExitProcess
0x409090 GetCurrentThreadId
0x409098 WriteFile
0x40909c HeapCreate
0x4090a0 IsBadCodePtr
0x4090a8 GetStartupInfoA
0x4090b0 GetTickCount
0x4090b4 GetStringTypeW
0x4090bc GetModuleHandleA
0x4090c0 FlushFileBuffers
0x4090c4 SetLastError
0x4090c8 SetHandleCount
0x4090cc GetCommandLineA
0x4090d4 HeapDestroy
0x4090d8 SetFilePointer
0x4090dc MultiByteToWideChar
0x4090e0 GetCurrentProcess
0x4090e4 IsBadReadPtr
0x4090e8 LCMapStringA
0x4090f0 HeapAlloc
Library user32.dll:
0x4090f8 LoadStringW
0x4090fc KillTimer
0x409100 SetWindowPos
0x409104 SetWindowRgn
0x409108 ShowWindow
0x40910c CreateWindowExW
0x409110 RegisterClassW
0x409114 GetMonitorInfoW
0x409118 LoadAcceleratorsW
0x40911c LoadCursorW
0x409120 DefWindowProcW
0x409124 GetWindowRect
0x409128 PostQuitMessage
0x40912c LoadIconW
0x409130 PostMessageW
0x409134 OffsetRect
0x409138 EndPaint
0x40913c GetWindowLongW
0x409144 AnimateWindow
0x409148 IsIconic
0x40914c BeginPaint
0x409150 GetMessageW
0x409154 MonitorFromWindow
0x409158 DispatchMessageW
0x40915c TranslateMessage
0x409160 SetTimer
Library GDI32.dll:
0x409168 BitBlt
0x40916c CreateCompatibleDC
0x409170 DeleteObject
0x409174 CreateRoundRectRgn
Library IMM32.dll:
0x40917c ImmGetContext
0x409180 ImmReleaseContext
Library MSIMG32.dll:
0x409188 GradientFill
0x40918c AlphaBlend
Library ole32.dll:
0x409194 DoDragDrop
Library SHELL32.dll:
0x40919c DragFinish
0x4091a0 DragAcceptFiles
Library WINMM.dll:
0x4091a8 PlaySoundW
Library WInspoOl.drV:
0x4091b0 DocumentPropertiesW

!This program cannot be run in DOS mode.
`.rdata
@.data
t.;t$$t(
SS@SSPVSS
t#SSUP
t$$VSS
_^][YY
VC20XC00U
_9= 0F
G;= 0F
Y95 0F
YYF;5 0F
8t9UW
Y95 0F
YYF;5 0F
HSVHWtgHHtF
F0;G wwS
G0+F Y
SVWj([S3
p(;F u
Q(;J u
p(;F u
Q(;J u
H$9q,u@
P(;B u
q(;N uo
q9q,u@
P(;B u
P(;B u
q(;N u
P(;B u
- not enough space for environment
GetActiveWindow
- pure virtual function call
abnormal program termination
__GLOBAL_HEAP_SELECTED
TLOSS error
- not enough space for stdio initialization
__MSVCRT_HEAP_SELECT
GetLastActivePopup
- unexpected multithread lock error
SING error
- not enough space for arguments
Runtime Error!
Program:
<program name unknown>
runtime error
- not enough space for lowio initialization
- not enough space for _onexit/atexit table
DOMAIN error
Microsoft Visual C++ Runtime Library
- floating point not loaded
user32.dll
- unable to initialize heap
MessageBoxA
- not enough space for thread data
- unable to open console device
- unexpected heap error
3.pkt|b'
o/R>*b
H`<{,?
T{Qe$dl
_k-gV-
Scgw i
HlX1tQ[
bk9C'<
WQojbFe
d_d>"n
IOGY$88
78O>BE
RNCUcD,
'Cx%Fy|n
5PX8;f
\rA/_h
{0jO+3
i8:`?^
"z_REW
MmZ'''
o;?I2t?
>HFJI([
{dH%T:
BQtX^^
]!ACJs
b<SU/X
U<q9[/XF
;tP*1jn
.pdSK +4
g3qtNzy
AEb;DR%
ng>%08sQ Y6
88Ey*&
:+*+g!k
E\@{oH
d\s,FB
s=t-(\
P60XGo
6f899n;H?
Em&G"
XVA0 )
Ob/#-zSn=
AU_Jx[
-|[b|n
S#~q^p
*sd/m):'!s
=5!i/Q
-I<@E>?wc
,.WAc'
`eTiyr\]
0[rPg&
53,/wG
9K'(Hf
4P Hd/v
*=PWb
k-h@u"rr
R@l<z
$'.)Nn
Kgx,nU&3D
~~-.96XB
Eer@sX
c"N.{;R
B/=sFgo
7F* !q
4X'Ye7
0ORD'j
~e->*}
"-WBq~
&[ /f>)D6
jAtIR$W
\ uU!U
"blF,Ma"
._UYb\
8ed'FYQdF
5wj'6.i
lZYdfZ
#No4CC
Ln_Yv-
dY9-9<
hQ%G%-"
b>kl|<k
e.!v00
a*kvFQ9'
x6hu/~
~BZH_i
~.Ivg#?9%
pP#)oK
q|ma-a
P=|s(i
1`}~yD,D
9,r{):'
%Wz5M|
~>Fwof
M7eUT?
O*{7mP
&g(s(&<
gx,hV'
mHKDf?=Ct
Iz#vwG
0GATclo;m5
(1)l%]Y!|
rBTo:;
S02YbT
![s'nc
s-R9,s
`OId#WaN
^n5SGc
ms]}3YPmn
U,9iQ<?
fr4wb$?h|
WscBf1
'TS_k
{.Hv<i
*P~=;[
'_e"x(
\DU_ZG
-X3<rh
5dz2nH
=R']L_
Z:!czo
jMw?,
V9)Y4u$
eIxZhj<'
&fV`%L
exZ{Ivp
&)_Yxm
u62O<
~lDaVM
vH#v5O
YcY#kF
13[1jzS
?mxPA\
n8n7U0
c2CA\(
H7)*9
d|zH,'
eDxSdW
:SY*0}
fq|")Mu
1k3taP
HankP%3
NL[:;Z
aION\=
)_v_3s9
\NXbdZA
/t6qx^
Y_NsEFg
ABr'le
Nh2)Fd<
<vmz)9
w/xn(JRp
JRN=^S
NDz;{H\
#iwnD&
yM)^nWq
sB9Z8_(
ge4K&l
qR9<%b
`Ev+:z
(K(2x0
&bg_2R
h_4v>D
Kko{kT]
<TM^QB
8iND}H
$RVKY$A
"r7X$d
2!GTc#
O5zZRyEP
Dx\Bc#
fo3Uev
"{Hv_m
GG@gIj
(^G Jn
r$7%!_-
?A'M%
.,yShB~
FSGU XI
Rb$31nWS
cH<~_G
r(t00iX
l[s)R*'
uFf~a(
zbQ}}v
7`0$Q*:
<Wp2".
XnAGb?r
W <I#<BT
5MP+f%&
\3Z\tk
K88TeB-h
B~WW"^
|dUBK7~cd
=fmR9(
T#lbwr
Ywu2{L?
Z.RWWx
%cl&e0
HulWnR=
r .a
]ORC}s
]`buD^?
CxQt.l
3$LN[i
-!P8%N
+ytWxP
,>7pr3)
c..ef_
ZDDF*]
Y3&5s<
P>p#aP
#vx@t"K
k-zL6d
d%_Dsq
-3gf]X
]IhKdq2
saVU0y
w>1`^K
@J5= b
.y QV:
(i(]#|
q4Sl=c
j~IERD
Q4~%cv
r|_TtP1
t`V~p7oYWqP
CDBpnJ
a-Fk]t
j3M Ab|f
PW#m+{^
.Xr<CKE
"X!ww
Fk_!R(
c@ZAzF
y[Y+x.
t2MsX;#3
[N$F'i
Yd]ATXi)?K
g{;=q*C
r!OiU|Q
?iv3%p$P
&\>2.+W
?@(eYa
N=uvLe%
o/C^Zz
58:|?'
#om9,u>
%c_/FJ%
Yo1cE+
ds7UIC
^T>t,k
\wB lB
<*3<H
!CR5pIk
A1t[kMp
,U b)DI
cf%cBj
m?A?Ug
h,^1w
{FQ8]>rg
po{.#K
g92s'(xI
\"j}4
|*q,:f
*$am-'
N#qJf@.
11JB+K
;bvzsb
gSVj-{
'PxcV(
K/e6M+C#q
Dl"O.-
9Vc3?VH5T3
@<%g\'
yAuxV^
J^Z&H2
QB+M(o
C^zN>p
YOu^=uj
#eMw"
~:P%uxO
<+|y8{-
f1e <\Y
%U&flk0
$<p`2t
m&|dw
;1V<QkD
LoA>b.
w@'?}}
{}'x,0
RegCloseKey
RegOpenKeyExW
ADVAPI32.dll
RtlUnwind
GetLastError
GetVersion
VirtualFree
LeaveCriticalSection
InterlockedIncrement
HeapFree
GetACP
TlsAlloc
GetProcessHeap
InitializeCriticalSection
EnterCriticalSection
GetCPInfo
GetEnvironmentStrings
HeapReAlloc
UnhandledExceptionFilter
GetStringTypeA
GetModuleFileNameA
GetVersionExA
GetSystemTimeAsFileTime
LCMapStringW
CloseHandle
GetFileType
SetStdHandle
GetStdHandle
GetOEMCP
TlsFree
TerminateProcess
TlsSetValue
TlsGetValue
WideCharToMultiByte
ExitProcess
FreeEnvironmentStringsW
GetCurrentThreadId
InterlockedDecrement
WriteFile
HeapCreate
IsBadCodePtr
SetUnhandledExceptionFilter
GetStartupInfoA
GetEnvironmentStringsW
GetTickCount
GetStringTypeW
FreeEnvironmentStringsA
GetModuleHandleA
FlushFileBuffers
SetLastError
SetHandleCount
GetCommandLineA
DeleteCriticalSection
HeapDestroy
SetFilePointer
MultiByteToWideChar
GetCurrentProcess
IsBadReadPtr
LCMapStringA
GetEnvironmentVariableA
HeapAlloc
KERNEL32.dll
LoadStringW
KillTimer
SetWindowPos
SetWindowRgn
ShowWindow
CreateWindowExW
RegisterClassW
GetMonitorInfoW
LoadAcceleratorsW
LoadCursorW
DefWindowProcW
GetWindowRect
PostQuitMessage
LoadIconW
PostMessageW
OffsetRect
EndPaint
GetWindowLongW
TranslateAcceleratorW
AnimateWindow
IsIconic
BeginPaint
GetMessageW
MonitorFromWindow
DispatchMessageW
TranslateMessage
SetTimer
BitBlt
CreateCompatibleDC
DeleteObject
CreateRoundRectRgn
GDI32.dll
ImmGetContext
ImmReleaseContext
IMM32.dll
GradientFill
AlphaBlend
MSIMG32.dll
DoDragDrop
ole32.dll
DragFinish
DragAcceptFiles
SHELL32.dll
PlaySoundW
WINMM.dll
DocumentPropertiesW
WInspoOl.drV
OfficeDesktop.pdb
WinApplication
((((( H
Kernel-Mode Driver Manager
MS Sans Serif
Re&gister
Code (hex)
Control
&Unregister
&Options...
&About...
SysListView32
&smog overcow mahmoud satorii anointing1thought-shaming unformulistic wedseday unpursuant
6tormentings acetamid necrotises equangular bunyanesque
anti-freudianism rurban
syrtis fragmentizing
outtrump)sororised post-incarnation annoyancer chr/syngnathoid Agna eutanasia picoides directively
slanderous siddurim lazars#flacon unprating grogshops pistolet,braggingly protovertebral recitativo tyebara
women feeble airfield's
immediacies semicatalytic4lemnaceous stock-taking gelder discrepating deistler
0Harnack paysand weltschmerz cathlamet immanacled
befrounce assurge
ultratrivial/autofrettage swan-drawn wolcottville myomectomy
Livenza
painless8hyetometrographic clydesider onum miyako Yerwa-Maiduguri
stiff-legged
mclain(credulities meristematically whitleycity
wapscallion1unfumed corundum pakaasnovos palaeopathology vein!mitergate fishingly lathees zimri
winterffed
miraculist
KSC tripple inscriptible reoffer
CTM(transsexual(a) Datiscaceae Dirca inspire murrhine sailye nook's periander
'Dakotan Americanizer cuticulae doodskop#plowgate talmage Steironema garlena
promsin
marionet gote nonpredictive-deathling sphacelariaceous dourine supercivil
courantos stamindia pigpen
(donkers reaccepts westfall undecolic rfc
circuminsular
woodcoc inflammableness Thadeus anality dotardy Pedrotti
devriess&endark resurrectional Windy horoscoper"torpified argv aldermancy currents#oblong-elliptical delimiter redials
brewing prairiegrove)lyrisms pinney neurolinguistic whitestone
plumdamases
thyme-capped Bastaard
newsgrabber deposits
timeseries
casket$babies'-breath havothjair iliospinal0Hepler reversification laquei Judenberg Servetus%thesium husbandmen dihalid defamatoryMeilewagon Vize pastureless jct
heliotropin nonsubscriber iliac
spermicide grannis
beflagged"nihon vaclav describes petrarchise
VS_VERSION_INFO
StringFileInfo
040904B0
CompanyName
Microsoft Corporation
FileDescription
COM Surrogate
FileVersion
10.0.18362.1 (WinBuild.160101.0800)
InternalName
dllhost.exe
LegalCopyright
Microsoft Corporation. All rights reserved.
OriginalFilename
dllhost.exe
ProductName
Microsoft
Windows
Operating System
ProductVersion
10.0.18362.1
VarFileInfo
Translation
Antivirus Signature
Bkav W32.AIDetect.malware1
Lionic Trojan.Win32.Swizzor.l8Pw
Elastic malicious (high confidence)
Cynet Malicious (score: 100)
CMC Clean
CAT-QuickHeal Clean
McAfee RDN/Generic PWS.y
Cylance Unsafe
Zillya Clean
Sangfor Trojan.Win32.Save.a
K7AntiVirus Trojan ( 00588b3e1 )
Alibaba Trojan:Win32/Kryptik.4f5b5137
K7GW Trojan ( 00588b3e1 )
CrowdStrike win/malicious_confidence_60% (W)
Baidu Clean
Cyren Clean
Symantec ML.Attribute.HighConfidence
ESET-NOD32 a variant of Win32/Kryptik.HMUW
APEX Malicious
Paloalto generic.ml
ClamAV Clean
Kaspersky HEUR:Trojan-Spy.Win32.Bobik.gen
BitDefender Trojan.GenericKD.37823254
NANO-Antivirus Virus.Win32.Gen.ccmw
SUPERAntiSpyware Clean
MicroWorld-eScan Trojan.GenericKD.37823254
Tencent Malware.Win32.Gencirc.11d327a0
Ad-Aware Trojan.GenericKD.37823254
Emsisoft Trojan.GenericKD.37823254 (B)
Comodo Clean
F-Secure Clean
DrWeb Clean
VIPRE Clean
TrendMicro TROJ_GEN.R002C0WJI21
McAfee-GW-Edition BehavesLike.Win32.Generic.gm
FireEye Generic.mg.07f5f3b04b399735
Sophos ML/PE-A
Ikarus Trojan.Win32.Crypt
GData Win32.Trojan.BSE.TTUNZ7
Jiangmin Trojan.Fsysna.nhh
Webroot Clean
Avira TR/Fraud.Gen8
Antiy-AVL Clean
Kingsoft Win32.Troj.Undef.(kcloud)
Gridinsoft Clean
Arcabit Trojan.Generic.D2412316
ViRobot Clean
ZoneAlarm Clean
Microsoft Trojan:Script/Phonzy.B!ml
TACHYON Clean
AhnLab-V3 Trojan/Win.Generic.R445985
Acronis Clean
VBA32 BScope.TrojanSpy.Bobik
ALYac Trojan.GenericKD.37823254
MAX malware (ai score=84)
Malwarebytes Clean
Panda Trj/GdSda.A
Zoner Clean
TrendMicro-HouseCall TROJ_GEN.R002C0WJI21
Rising Trojan.Generic@ML.88 (RDMK:6vwUYEhpGEvMId2uu2lEqQ)
Yandex Trojan.Kryptik!0JPmqTA7D64
SentinelOne Clean
eGambit Clean
Fortinet W32/Kryptik.HMUW!tr
BitDefenderTheta Gen:NN.ZexaF.34236.zq0@autzNPdi
AVG Win32:CrypterX-gen [Trj]
Cybereason malicious.f8ea07
Avast Win32:CrypterX-gen [Trj]
MaxSecure Trojan.Malware.74196578.susgen
No IRMA results available.