Static | ZeroBOX

PE Compile Time

2023-02-20 07:50:56

PE Imphash

c8b414c149a1d1bf4fd0150a574885bd

PEiD Signatures

Armadillo v1.71

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x00005680 0x00005800 6.26217389612
.rdata 0x00007000 0x00000b14 0x00000c00 4.83113307591
.data 0x00008000 0x00000c24 0x00000c00 5.11361974093

Imports

Library KERNEL32.dll:
0x407074 GetFileSize
0x407078 WriteFile
0x40707c SetFilePointer
0x407080 FlushViewOfFile
0x407084 GetFileAttributesA
0x407088 GetModuleFileNameA
0x40708c GetSystemInfo
0x407090 GlobalFree
0x407094 GlobalAlloc
0x407098 CopyFileA
0x40709c LoadLibraryA
0x4070a0 LocalFree
0x4070a4 LocalAlloc
0x4070a8 QueryDosDeviceA
0x4070ac GetCurrentProcess
0x4070b0 FindClose
0x4070b4 FindFirstFileA
0x4070b8 GetFileTime
0x4070bc SetFileTime
0x4070c0 TerminateProcess
0x4070c4 GetTickCount
0x4070c8 Sleep
0x4070cc CreateFileA
0x4070d0 CreateFileMappingA
0x4070d4 MapViewOfFile
0x4070d8 HeapFree
0x4070dc IsBadReadPtr
0x4070e0 UnmapViewOfFile
0x4070e8 Module32First
0x4070ec Module32Next
0x4070f0 GetModuleHandleA
0x4070f4 GetProcAddress
0x4070f8 OpenProcess
0x4070fc CloseHandle
0x407100 GetStdHandle
0x40710c SetFileAttributesA
0x407110 DeleteFileA
0x407114 GetLastError
0x407118 MoveFileExA
0x40711c GetProcessHeap
0x407120 HeapAlloc
0x407124 FreeLibrary
Library USER32.dll:
Library ADVAPI32.dll:
0x407000 ControlService
0x407004 GetAce
0x407008 DeleteAce
0x407010 GetFileSecurityA
0x407020 SetEntriesInAclA
0x407028 FreeSid
0x407034 OpenProcessToken
0x407038 GetTokenInformation
0x407040 IsValidSid
0x407044 LookupAccountSidA
0x407048 StartServiceA
0x407054 OpenServiceA
0x40705c OpenSCManagerA
0x407064 CloseServiceHandle
0x40706c GetAclInformation
Library imagehlp.dll:
0x4071a4 CheckSumMappedFile
Library MSVCRT.dll:
0x40712c _vsnprintf
0x407130 _controlfp
0x407134 atoi
0x407138 _strcmpi
0x40713c strlen
0x407140 printf
0x407144 memset
0x407148 _strnicmp
0x40714c _except_handler3
0x407150 _local_unwind2
0x407154 _splitpath
0x407158 memcmp
0x40715c memcpy
0x407160 free
0x407164 malloc
0x407168 strncpy
0x40716c _exit
0x407170 _XcptFilter
0x407174 exit
0x407178 __p___initenv
0x40717c __getmainargs
0x407180 _initterm
0x407184 __setusermatherr
0x407188 _adjust_fdiv
0x40718c __p__commode
0x407190 __p__fmode
0x407194 __set_app_type

!This program cannot be run in DOS mode.
`.rdata
@.data
tdSSSj
SVWj?3
SVWj?3
SVWj?3
IthItII
HtNHt3Hud
SSSSSS
PSSSSSSh
VWtP9]
PSSSSSSSj
HeapFree
HeapAlloc
GetProcessHeap
MoveFileExA
GetLastError
DeleteFileA
SetFileAttributesA
SetConsoleTextAttribute
GetConsoleScreenBufferInfo
GetStdHandle
CloseHandle
OpenProcess
GetProcAddress
GetModuleHandleA
Module32Next
Module32First
CreateToolhelp32Snapshot
UnmapViewOfFile
IsBadReadPtr
MapViewOfFile
CreateFileMappingA
CreateFileA
GetTickCount
TerminateProcess
SetFileTime
GetFileTime
CopyFileA
GetFileSize
WriteFile
SetFilePointer
FlushViewOfFile
GetFileAttributesA
GetModuleFileNameA
GetSystemInfo
GlobalFree
GlobalAlloc
FreeLibrary
LoadLibraryA
LocalFree
LocalAlloc
QueryDosDeviceA
GetCurrentProcess
FindClose
FindFirstFileA
KERNEL32.dll
GetUserObjectSecurity
USER32.dll
CloseServiceHandle
EnumServicesStatusExA
OpenSCManagerA
ChangeServiceConfig2A
OpenServiceA
QueryServiceStatusEx
ControlService
EnumDependentServicesA
StartServiceA
LookupAccountSidA
IsValidSid
GetSecurityDescriptorOwner
GetTokenInformation
OpenProcessToken
AdjustTokenPrivileges
LookupPrivilegeValueA
FreeSid
SetNamedSecurityInfoA
SetEntriesInAclA
AllocateAndInitializeSid
BuildExplicitAccessWithNameA
GetNamedSecurityInfoA
GetFileSecurityA
GetSecurityDescriptorDacl
DeleteAce
GetAce
GetAclInformation
CheckTokenMembership
ADVAPI32.dll
CheckSumMappedFile
imagehlp.dll
_strcmpi
strlen
printf
memset
_strnicmp
_except_handler3
_local_unwind2
_splitpath
memcmp
memcpy
malloc
_vsnprintf
strncpy
MSVCRT.dll
_XcptFilter
__p___initenv
__getmainargs
_initterm
__setusermatherr
_adjust_fdiv
__p__commode
__p__fmode
__set_app_type
_controlfp
Syrinx Victim
Syrinx's Victim
/Replace
/Infect
/Disable
/Disablemscoreei
/Disablemscorsec
/DisableClr
SeSecurityPrivilege
SeDebugPrivilege
/Check
Fail To Get SQL Info
%ld %s
%ld %s("%s")
Delete OLE File Successfully
Fail To Delete OLE File(%d)
Delete & Move File All Failure
Delete OLE File On Reboot
Move OLE File Successfully
%s.bak
OLE File Already Gone
\ODSOLE70.dll
Set Service Auto Restart Failure.(%d)
Fail To Open Service
Fail To Open SC Manager
Set Service Auto Restart Successfully
\MSCOREEI.dll
\MSCORSEC.dll
\CLR.dll
NtWow64QueryInformationProcess64
NtWow64ReadVirtualMemory64
NTDLL.DLL
IsWow64Process
kernel32.dll
Fail To Get Sql Info
%s%s%s.bak
%s%s.bak
BackUP File = %s
Fail To Create File %s(%d)
Fail To Create Mapping
Fail To Map View
It's Not An Executable
Fail To Get File Size
Free Space Found
It's Infected
Mis-Match PE File Version
Fail To Back UP File
Try Extenion
BackUP Successfully
Fail To Stop Service %s
Starting %s......
Infection Successfully(Not Backup Method)
Infection Successfully(Backup Method)
Stopping %s......
NetInfo.dll
%s.dll
Fail To Start Service %d
Fail To Copy New Module %d
Replace Module Successfully
Set Backup Module Access Failure
Deny Original Module Access Failure
Copy Module Failure(%s -> %s)
Critical Module Not Loaded Or Find Module Method Failure
Set Backup Module Access Successfully
Delete Backup Module ACL Successfully
Delete Backup Module ACL Failure
Deny Original Module Access Successfully
Copy Module Successfully
Module = %s
%s\clr.dll
C:\Windows\Microsoft.NET\Framework\v4.0.30319\clr.dll
%s\mscorsec.dll
C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsec.dll
C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsec.dll
%s\mscoreei.dll
C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscoreei.dll
C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscoreei.dll
C:\Windows\Microsoft.NET\Framework64\v4.0.30319\clr.dll
KERNEL32.DLL
GetNativeSystemInfo
CreateWellKnownSid
Advapi32.dll
GetExtendedTcpTable
iphlpapi.dll
GetProcessImageFileNameA
PSAPI.DLL
\Device\HarddiskVolume
SeTakeOwnershipPrivilege
Fail To Set Ownership
Fail To Set Security. Error Code = %d
SetEntriesInAcl Failure
Fail To Set Ownership After GetNamedSecurityInfo Failure
GetNamedSecurityInfo Failure %d
Object Doesn't Exist
Invalid SID
Invalid Option
Fail To Get File Security
It's FAT 32
Error = %d
Fail To Delete Ace
No Index Found(Probably Deny Access Not Set)
No ACL Found
Fail To Get ACL Info
File Not Found
Delete One ACL Successfully
Set "%s" Deny Access Successfully On %s
Set "%s" Deny Access Failure On %s
No antivirus signatures available.
No IRMA results available.