Static | ZeroBOX

PE Compile Time

2017-01-13 23:18:19

PDB Path

c:\Users\Administrator\Desktop\Server111\Release\DHLDAT.pdb

PE Imphash

4eac46eb01c65a7e209bb87f15f9e46d

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x0001b52a 0x0001c000 6.56656737903
.rdata 0x0001d000 0x0000462c 0x00005000 4.68305030192
.data 0x00022000 0x00002144 0x00002000 2.15779647915

Imports

Library KERNEL32.dll:
0x41d000 Sleep
0x41d004 HeapFree
0x41d008 GetProcessHeap
0x41d00c VirtualFree
0x41d010 FreeLibrary
0x41d014 HeapAlloc
0x41d018 VirtualAlloc
0x41d01c VirtualProtect
0x41d020 GetProcAddress
0x41d024 LoadLibraryA
0x41d028 CloseHandle
0x41d02c CreateFileA
0x41d030 WriteFile
0x41d034 ReadFile
0x41d038 GetFileSize
0x41d03c RtlUnwind
0x41d040 RaiseException
0x41d044 GetLastError
0x41d048 HeapReAlloc
0x41d04c GetCommandLineA
0x41d050 GetVersionExA
0x41d054 GetStartupInfoA
0x41d058 GetModuleHandleA
0x41d05c TlsGetValue
0x41d060 TlsAlloc
0x41d064 TlsSetValue
0x41d068 TlsFree
0x41d070 SetLastError
0x41d074 GetCurrentThreadId
0x41d07c GetCurrentThread
0x41d080 TerminateProcess
0x41d084 GetCurrentProcess
0x41d090 IsDebuggerPresent
0x41d094 HeapDestroy
0x41d098 HeapCreate
0x41d0a4 FatalAppExitA
0x41d0ac ExitProcess
0x41d0b0 GetStdHandle
0x41d0b4 GetModuleFileNameA
0x41d0c4 WideCharToMultiByte
0x41d0cc SetHandleCount
0x41d0d0 GetFileType
0x41d0d8 GetTickCount
0x41d0dc GetCurrentProcessId
0x41d0e4 GetCPInfo
0x41d0e8 GetACP
0x41d0ec GetOEMCP
0x41d0f8 InterlockedExchange
0x41d0fc HeapSize
0x41d100 GetTimeFormatA
0x41d104 GetDateFormatA
0x41d108 GetUserDefaultLCID
0x41d10c GetLocaleInfoA
0x41d110 EnumSystemLocalesA
0x41d114 IsValidLocale
0x41d118 IsValidCodePage
0x41d11c GetStringTypeA
0x41d120 MultiByteToWideChar
0x41d124 GetStringTypeW
0x41d128 LCMapStringA
0x41d12c LCMapStringW
0x41d130 GetLocaleInfoW
0x41d138 CompareStringA
0x41d13c CompareStringW
0x41d144 LocalAlloc
0x41d148 LocalFree

!This program cannot be run in DOS mode.
`.rdata
@.data
QQSVWd
HtHu4j
s[S;7|G;w
tR99u2
F\= )B
tehVe@
G;=$AB
YYuTVWh
>=Yt/j
t#SSUP
t$$VSS
_^][YY
j(j ^V
Wto=p1B
t^9(uZ
tD9(u@
Y9>t7j
0A@@Ju
YYu-9D$
;t$,v-
UQPXY]Y[
0SSSSS
JJt&JJt
<0|<9
tK<_t<<$t8<<t4<>t0<-t,<a|
<z~$<A|
<0|I<9
t^<A|f<P
WQt)9E
tP<@tF<Zt
th<@tdj'
EhPWje
Nt@Nt NuM
!Mh!MXV3
!MX8]x
t.<@t5V
TtSHtIHt?Ht
AtIHt0Hu
t}<?tH<Xt
URPQQh
_VVVVV
_VVVVV
zukSSS
0SSSSS
0SSSSS
C PjPV
C$PjQV
C*PjTV
C+PjUV
C,PjVV
C-PjWV
C.PjRV
C/PjSV
.;1s(N
HHt4HHt
Ht`Ht,
teHtFHt&Hu
ty<%tA
PPPPPPPP
u|Vj@h
t.8t*W
PPPPPPPP
u,VVWV
^SSSSS
^SSSSS
>:u8FV
$f95\?B
.VVVVVSRSSj
VVVVVj
^SSSSS
^SSSSS
0SSSSS
t+WWVPV
^SSSSS
^WWWWW
0SSSSS
8VVVVV
tb9} u
YYt\VV
YYt SVW
KERNEL32.dll
IsBadReadPtr
InternetCloseHandle
WININET.dll
InternetOpenA
eliFdaeR
lld.23LENREK
bad allocation
bad exception
EncodePointer
KERNEL32.DLL
DecodePointer
FlsFree
FlsSetValue
FlsGetValue
FlsAlloc
CorExitProcess
mscoree.dll
runtime error
TLOSS error
SING error
DOMAIN error
An application has made an attempt to load the C runtime library incorrectly.
Please contact the application's support team for more information.
- Attempt to use MSIL code from this assembly during native code initialization
This indicates a bug in your application. It is most likely the result of calling an MSIL-compiled (/clr) function from a native constructor or from DllMain.
- not enough space for locale information
- Attempt to initialize the CRT more than once.
This indicates a bug in your application.
- CRT not initialized
- unable to initialize heap
- not enough space for lowio initialization
- not enough space for stdio initialization
- pure virtual function call
- not enough space for _onexit/atexit table
- unable to open console device
- unexpected heap error
- unexpected multithread lock error
- not enough space for thread data
This application has requested the Runtime to terminate it in an unusual way.
Please contact the application's support team for more information.
- not enough space for environment
- not enough space for arguments
- floating point not loaded
Microsoft Visual C++ Runtime Library
<program name unknown>
Runtime Error!
Program:
Unknown exception
LC_TIME
LC_NUMERIC
LC_MONETARY
LC_CTYPE
LC_COLLATE
LC_ALL
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
Complete Object Locator'
Class Hierarchy Descriptor'
Base Class Array'
Base Class Descriptor at (
Type Descriptor'
`local static thread guard'
`managed vector copy constructor iterator'
`vector vbase copy constructor iterator'
`vector copy constructor iterator'
`dynamic atexit destructor for '
`dynamic initializer for '
`eh vector vbase copy constructor iterator'
`eh vector copy constructor iterator'
`managed vector destructor iterator'
`managed vector constructor iterator'
`placement delete[] closure'
`placement delete closure'
`omni callsig'
delete[]
new[]
`local vftable constructor closure'
`local vftable'
`udt returning'
`copy constructor closure'
`eh vector vbase constructor iterator'
`eh vector destructor iterator'
`eh vector constructor iterator'
`virtual displacement map'
`vector vbase constructor iterator'
`vector destructor iterator'
`vector constructor iterator'
`scalar deleting destructor'
`default constructor closure'
`vector deleting destructor'
`vbase destructor'
`string'
`local static guard'
`typeof'
`vcall'
`vbtable'
`vftable'
operator
delete
__unaligned
__restrict
__ptr64
__clrcall
__fastcall
__thiscall
__stdcall
__pascal
__cdecl
__based(
{flat}
`non-type-template-parameter
unsigned
short
<ellipsis>
,<ellipsis>
throw(
`template-parameter
cli::pin_ptr<
cli::array<
`anonymous namespace'
generic-type-
template-parameter-
`unknown ecsu'
union
struct
class
coclass
cointerface
extern "C"
[thunk]:
public:
protected:
private:
virtual
static
`template static data member destructor helper'
`template static data member constructor helper'
`local static destructor helper'
`adjustor{
`vtordisp{
`vtordispex{
const
volatile
volatile
volatile
signed
double
wchar_t
UNKNOWN
__int128
__int32
__int64
__int16
__w64
__int8
InitializeCriticalSectionAndSpinCount
kernel32.dll
SystemFunction036
ADVAPI32.DLL
GetProcessWindowStation
GetUserObjectInformationA
GetLastActivePopup
GetActiveWindow
MessageBoxA
USER32.DLL
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
HH:mm:ss
dddd, MMMM dd, yyyy
MM/dd/yy
December
November
October
September
August
February
January
Saturday
Friday
Thursday
Wednesday
Tuesday
Monday
Sunday
united-states
united-kingdom
trinidad & tobago
south-korea
south-africa
south korea
south africa
slovak
puerto-rico
pr-china
pr china
new-zealand
hong-kong
holland
great britain
england
britain
america
swedish-finland
spanish-venezuela
spanish-uruguay
spanish-puerto rico
spanish-peru
spanish-paraguay
spanish-panama
spanish-nicaragua
spanish-modern
spanish-mexican
spanish-honduras
spanish-guatemala
spanish-el salvador
spanish-ecuador
spanish-dominican republic
spanish-costa rica
spanish-colombia
spanish-chile
spanish-bolivia
spanish-argentina
portuguese-brazilian
norwegian-nynorsk
norwegian-bokmal
norwegian
italian-swiss
irish-english
german-swiss
german-luxembourg
german-lichtenstein
german-austrian
french-swiss
french-luxembourg
french-canadian
french-belgian
english-usa
english-us
english-uk
english-trinidad y tobago
english-south africa
english-nz
english-jamaica
english-ire
english-caribbean
english-can
english-belize
english-aus
english-american
dutch-belgian
chinese-traditional
chinese-singapore
chinese-simplified
chinese-hongkong
chinese
canadian
belgian
australian
american-english
american english
american
Norwegian-Nynorsk
SunMonTueWedThuFriSat
JanFebMarAprMayJunJulAugSepOctNovDec
imagehlp.dll
WININET.dll
c:\Users\Administrator\Desktop\Server111\Release\DHLDAT.pdb
MakeSureDirectoryPathExists
InternetReadFile
InternetOpenUrlA
HeapFree
GetProcessHeap
VirtualFree
FreeLibrary
HeapAlloc
VirtualAlloc
VirtualProtect
GetProcAddress
LoadLibraryA
CloseHandle
CreateFileA
WriteFile
ReadFile
GetFileSize
KERNEL32.dll
RtlUnwind
RaiseException
GetLastError
HeapReAlloc
GetCommandLineA
GetVersionExA
GetStartupInfoA
GetModuleHandleA
TlsGetValue
TlsAlloc
TlsSetValue
TlsFree
InterlockedIncrement
SetLastError
GetCurrentThreadId
InterlockedDecrement
GetCurrentThread
TerminateProcess
GetCurrentProcess
UnhandledExceptionFilter
SetUnhandledExceptionFilter
IsDebuggerPresent
HeapDestroy
HeapCreate
DeleteCriticalSection
LeaveCriticalSection
FatalAppExitA
EnterCriticalSection
ExitProcess
GetStdHandle
GetModuleFileNameA
FreeEnvironmentStringsA
GetEnvironmentStrings
FreeEnvironmentStringsW
WideCharToMultiByte
GetEnvironmentStringsW
SetHandleCount
GetFileType
QueryPerformanceCounter
GetTickCount
GetCurrentProcessId
GetSystemTimeAsFileTime
GetCPInfo
GetACP
GetOEMCP
InitializeCriticalSection
SetConsoleCtrlHandler
InterlockedExchange
HeapSize
GetTimeFormatA
GetDateFormatA
GetUserDefaultLCID
GetLocaleInfoA
EnumSystemLocalesA
IsValidLocale
IsValidCodePage
GetStringTypeA
MultiByteToWideChar
GetStringTypeW
LCMapStringA
LCMapStringW
GetLocaleInfoW
GetTimeZoneInformation
CompareStringA
CompareStringW
SetEnvironmentVariableA
LocalAlloc
LocalFree
4jNnIiz7AYwVpl0XDJUTZskvOIft+j7K4eauVpX6VwkjB7o=
AMIQjn9qqxF+RMoiOha3qlIUzuRSkQQc6mUF2H9BTy9pOX2ratPgodkk57Lg5rFh1VmAKJqBZINMlS0lsAa6BQ5GHRz+7V956fcuCMnwPtzhSiMJBLuWfsV0Y4oGlH5wqpl/bTz8Z39GgE5d89TwEmKU1M5n7yGgtJW83HxjVK7wO9BKltAX7R1BQnn/HZm0jl0w0T1Dnka2KFnl5Nh0ejPF6wPndbHd/iMrphPXogYhU/8yd+suSz2dsAiymkJWwfGgStnHt/yC2Q1YJvrdcfc4h+Fuew/BWwrAW1QgWNloLXKVR18c3nUkmtGOa4k0Yk5SQda5W8XU0nsOofHs+coSmaAwT7Dk5JICvxPItgyhFZdBDroatN4ET3+1n/eRt+9NcWayAvEpk1e9MYQ0+/FDsf/N5cKYNZ+tbOQFZMJAdRlotSKJF49LuCuCaHCsqplwnBNo9vslPUruL3WEMu/HhRPLgTnWtkbz66WV9rg=
.?AVtype_info@@
.?AVbad_alloc@std@@
.?AVexception@std@@
.?AVbad_exception@std@@
.?AVbad_cast@std@@
.?AVbad_typeid@std@@
.?AV__non_rtti_object@std@@
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
.?AVDNameNode@@
.?AVcharNode@@
.?AVpDNameNode@@
.?AVDNameStatusNode@@
.?AVpcharNode@@
((((( H
h(((( H
H
Antivirus Signature
Bkav W32.AIDetectMalware
Lionic Trojan.Win32.Cycler.tobt
tehtris Clean
ClamAV Win.Trojan.Agent-6443182-0
CMC Clean
CAT-QuickHeal Downldr.Farli.S673162
ALYac Clean
Malwarebytes Malware.AI.4250901208
VIPRE Trojan.Cud.Gen.1
Sangfor Trojan.Win32.Save.a
K7AntiVirus Trojan ( 0052d5311 )
BitDefender Trojan.Cud.Gen.1
K7GW Trojan ( 0052d5311 )
Cybereason malicious.067e14
Baidu Clean
VirIT Clean
Cyren W32/Trojan.QYHJ-1514
Symantec ML.Attribute.HighConfidence
Elastic malicious (high confidence)
ESET-NOD32 a variant of Win32/Farfli.CGF
APEX Malicious
Paloalto Clean
Cynet Malicious (score: 99)
Kaspersky Trojan-Clicker.Win32.Cycler.amco
Alibaba TrojanDownloader:Win32/Farfli.77d44165
NANO-Antivirus Trojan.Win32.Farfli.ekovmh
SUPERAntiSpyware Clean
MicroWorld-eScan Trojan.Cud.Gen.1
Tencent Malware.Win32.Gencirc.10b2ab54
TACHYON Clean
Sophos Mal/Generic-S
F-Secure Heuristic.HEUR/AGEN.1317193
DrWeb BackDoor.PcClient.6595
Zillya Trojan.Cycler.Win32.1992
TrendMicro BKDR_ZEGOST.SM33
McAfee-GW-Edition GenericRXAW-IL!25214EE067E1
Trapmine Clean
FireEye Generic.mg.25214ee067e1480f
Emsisoft Trojan.Cud.Gen.1 (B)
Ikarus Trojan.Win32.Farfli
Jiangmin TrojanDownloader.Agent.fkra
Webroot W32.Trojan.Gen
Avira HEUR/AGEN.1317193
Antiy-AVL Trojan[Clicker]/Win32.Cycler
Microsoft TrojanDownloader:Win32/Farfli.F!bit
Gridinsoft Trojan.Win32.Gen.bot
Xcitium Backdoor.Win32.Farfli.CK@709g8g
Arcabit Trojan.Cud.Gen.1
ViRobot Clean
ZoneAlarm Trojan-Clicker.Win32.Cycler.amco
GData Trojan.Cud.Gen.1
Google Detected
AhnLab-V3 Downloader/Win32.Agent.C1745448
Acronis Clean
McAfee GenericRXAW-IL!25214EE067E1
MAX malware (ai score=87)
DeepInstinct MALICIOUS
VBA32 TrojanClicker.Cycler
Cylance unsafe
Panda Trj/CI.A
Zoner Clean
TrendMicro-HouseCall BKDR_ZEGOST.SM33
Rising Downloader.Farfli!8.2C32 (TFE:5:7kjdrStSW2Q)
Yandex Trojan.GenAsa!tdeUKaifYeg
SentinelOne Clean
MaxSecure Trojan.Malware.10471616.susgen
Fortinet W32/Farfli.CGF!tr
BitDefenderTheta Gen:NN.ZexaF.36250.jmW@ayUVhai
AVG Win32:Malware-gen
Avast Win32:Malware-gen
CrowdStrike win/malicious_confidence_100% (W)
No IRMA results available.