Static | ZeroBOX

PE Compile Time

2015-04-13 20:40:41

PE Imphash

45faf44fe201670daca333d176faea38

PEiD Signatures

Armadillo v1.71

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x0000713a 0x00008000 6.12172562458
.rdata 0x00009000 0x000005a0 0x00001000 2.18757648966
.data 0x0000a000 0x00002e04 0x00003000 0.857172482889
.idata 0x0000d000 0x00000678 0x00001000 2.60423689091
.reloc 0x0000e000 0x00000724 0x00001000 3.69245690944

Imports

Library imagehlp.dll:
Library WININET.dll:
0x40d224 InternetOpenA
0x40d228 InternetOpenUrlA
0x40d22c InternetReadFile
0x40d230 InternetCloseHandle
Library KERNEL32.dll:
0x40d148 ExitProcess
0x40d14c GetStringTypeW
0x40d150 GetStringTypeA
0x40d154 LCMapStringW
0x40d158 LCMapStringA
0x40d15c MultiByteToWideChar
0x40d164 HeapAlloc
0x40d168 GetProcessHeap
0x40d16c VirtualAlloc
0x40d170 VirtualProtect
0x40d174 VirtualFree
0x40d178 GetProcAddress
0x40d17c LoadLibraryA
0x40d180 IsBadReadPtr
0x40d184 HeapFree
0x40d188 FreeLibrary
0x40d18c CloseHandle
0x40d190 WriteFile
0x40d194 CreateFileA
0x40d198 ReadFile
0x40d19c GetFileSize
0x40d1a0 SetFilePointer
0x40d1a4 Sleep
0x40d1a8 HeapReAlloc
0x40d1ac RtlUnwind
0x40d1b0 RaiseException
0x40d1b4 GetModuleHandleA
0x40d1b8 GetStartupInfoA
0x40d1bc GetCommandLineA
0x40d1c0 GetVersion
0x40d1c4 IsBadWritePtr
0x40d1c8 GetModuleFileNameA
0x40d1d0 GetVersionExA
0x40d1d4 HeapDestroy
0x40d1d8 HeapCreate
0x40d1e0 TerminateProcess
0x40d1e4 GetCurrentProcess
0x40d1f4 WideCharToMultiByte
0x40d200 SetHandleCount
0x40d204 GetStdHandle
0x40d208 GetFileType
0x40d20c IsBadCodePtr
0x40d210 GetCPInfo
0x40d214 GetACP
0x40d218 GetOEMCP
0x40d21c GetLastError

!This program cannot be run in DOS mode.
/VK!k7%rk7%rk7%rk7$rP7%r
8xrl7%r
+)rj7%r]
.ra7%r
++rd7%r]
/ru7%r
(.rh7%rRichk7%r
`.rdata
@.data
.idata
.reloc
QQSVWd
t.;t$$t(
sO;>|C;~
8t9UW
SS@SSPVSS
t#SSUP
t$$VSS
_^][YY
DSUVWh
VC20XC00U
VWuBh
HHtYHHtF
"WWSh,
__GLOBAL_HEAP_SELECTED
__MSVCRT_HEAP_SELECT
runtime error
TLOSS error
SING error
DOMAIN error
- unable to initialize heap
- not enough space for lowio initialization
- not enough space for stdio initialization
- pure virtual function call
- not enough space for _onexit/atexit table
- unable to open console device
- unexpected heap error
- unexpected multithread lock error
- not enough space for thread data
abnormal program termination
- not enough space for environment
- not enough space for arguments
- floating point not loaded
Microsoft Visual C++ Runtime Library
Runtime Error!
Program:
<program name unknown>
GetLastActivePopup
GetActiveWindow
MessageBoxA
user32.dll
t7Ozr+n8/LCzvrH9sK/u9ef9s7Xp9PTz8/zn/fT0/cO7u98=
rqvArQGur/Dp9wGrqd/f8O/v+PDf7e/w7N/w7e7r7Onq98C7xMjBrt+L7e7w7+/334quwcK3vP+1tamwwKq+w9+QwMirvsX/rKyww6m6xLmvucWwta+1rLi833M/bT11JHM/JQ4PHQ5tczEoR3B3bX0KC2mCdzMPHShHwHB3GjRpgoB+3/yPrcK6rcDEmcjDvK78k6TIvq3CrsK5q/+dw6u8wayT366pvsfCrquurgG8t7zfmrC4xa61/6yssL3Dx8G63xuDJyJqCQpI39/w3+3f79/w3+/fx6urr/UCAqqqqgHIr/Du9wG+wsQCyK+u8O73AcCur/LIr/T8rvnAvqvIwsH07d/x8f/f8wLfx6urr/UCArvBrgHAyLXHwMEBvsLEAvKw9Pyu3/0D/d/9A9/Hq6uv9QICrK68rQGwtcLBvAGwsAG+wsQC/K7f
.?AVtype_info@@
MakeSureDirectoryPathExists
imagehlp.dll
InternetCloseHandle
InternetReadFile
InternetOpenUrlA
InternetOpenA
WININET.dll
HeapAlloc
GetProcessHeap
VirtualAlloc
VirtualProtect
VirtualFree
GetProcAddress
LoadLibraryA
IsBadReadPtr
HeapFree
FreeLibrary
CloseHandle
WriteFile
CreateFileA
ReadFile
GetFileSize
SetFilePointer
HeapReAlloc
RtlUnwind
RaiseException
GetModuleHandleA
GetStartupInfoA
GetCommandLineA
GetVersion
ExitProcess
IsBadWritePtr
GetModuleFileNameA
GetEnvironmentVariableA
GetVersionExA
HeapDestroy
HeapCreate
SetUnhandledExceptionFilter
TerminateProcess
GetCurrentProcess
UnhandledExceptionFilter
FreeEnvironmentStringsA
FreeEnvironmentStringsW
WideCharToMultiByte
GetEnvironmentStrings
GetEnvironmentStringsW
SetHandleCount
GetStdHandle
GetFileType
IsBadCodePtr
GetCPInfo
GetACP
GetOEMCP
GetLastError
SetConsoleCtrlHandler
MultiByteToWideChar
LCMapStringA
LCMapStringW
GetStringTypeA
GetStringTypeW
KERNEL32.dll
6D8r8~8
8;=?>b>m>
0(1<1B1U1a1g1{1
1202A2
889P9W9_9d9h9l9
9B:H:L:P:T:
;;;m;t;x;|;
4B5\5e5
5J6O6l6v6
7<7X7a7~7
8=8C8^8d8k8x8
;$;);8;>;N;Y;k;~;
?$?.?4?9???O?X?r?
4)4/444:4G4a4g4w4
7(828:8@8H8Q8Z8
9#9)9C9I9Q9`9
282D2L2T2d2{2
7F7O7[7d7
;3;H;M;l;
<X=d=v=|=
>>)>4>H>V>c>i>o>{>
2#2/2?2~2
23R3X3v3
414F4c4
6(656C6N6a6
737H7^7e7s7
858[8u8|8
: :$:(:,:0:z:
0/0Z0t0
1'1-1N1X1c1h1p1
2a2k2p2u2z2
3,3=3P3e3
4+455>5D5P5U5_5f5n5t5{5
9 9)9.9~9
:,:D:c:m:~:
;+;I;f;~;
=3=F=M=_=g=w=
=)>;>b>h>n>t>z>
?"?(?.?4?:?@?F?L?R?X?^?d?j?p?v?|?
0 0L0P0
0<4@4H4L4T4X4`4x4
4@5T5h5|5
83D3P3T3
4$4,444<4D4L4T4\4d4l4t4
C:\Users\Administrator\Desktop\fd\8.62\DHLDAT.pdb
((((( H
Antivirus Signature
Bkav W32.AIDetectMalware
Lionic Trojan.Win32.Tiny.a!c
tehtris Clean
ClamAV Win.Downloader.Farfli-6453698-0
CMC Clean
CAT-QuickHeal Trojan.Redosdru.18846
Skyhigh Trojan-FKFK!FC58E29974C4
ALYac Trojan.Downloader.JSWJ
Cylance Unsafe
Zillya Downloader.Tiny.Win32.4461
Sangfor Downloader.Win32.Agent.Vbbb
K7AntiVirus Trojan-Downloader ( 0055e3da1 )
Alibaba Backdoor:Win32/Zlob.180910
K7GW Trojan-Downloader ( 0055e3da1 )
Cybereason malicious.974c49
Baidu Win32.Trojan-Downloader.Agent.cw
VirIT Trojan.Win32.Generic.EQQ
Paloalto generic.ml
Symantec ML.Attribute.HighConfidence
Elastic malicious (high confidence)
ESET-NOD32 a variant of Win32/TrojanDownloader.Agent.AVU
APEX Malicious
Avast Win32:Dropper-OHP [Trj]
Cynet Malicious (score: 100)
Kaspersky Trojan-Downloader.Win32.Tiny.cun
BitDefender Trojan.Downloader.JSWJ
NANO-Antivirus Trojan.Win32.Agent.dqsnyd
ViRobot Trojan.Win.Z.Downloader.61506.C
MicroWorld-eScan Trojan.Downloader.JSWJ
TACHYON Clean
Sophos Mal/Generic-S
F-Secure Trojan.TR/Downloader.Gen4
DrWeb BackDoor.Siggen.58849
VIPRE Trojan.Downloader.JSWJ
TrendMicro BKDR_ZEGOST.SM17
McAfeeD ti!064497427357
Trapmine Clean
FireEye Generic.mg.fc58e29974c49a32
Emsisoft Trojan.Downloader.JSWJ (B)
SentinelOne Static AI - Suspicious PE
GData Trojan.Downloader.JSWJ
Jiangmin TrojanDropper.Dorgam.kg
Webroot Clean
Varist W32/Trojan.JNNA-3426
Avira TR/Downloader.Gen4
Antiy-AVL Trojan[Backdoor]/Win32.BigBadWolf.a
Kingsoft malware.kb.a.1000
Gridinsoft Trojan.Win32.Gen.tr
Xcitium TrojWare.Win32.Farfli.BJQ@5t8o8c
Arcabit Trojan.Downloader.JSWJ
SUPERAntiSpyware Clean
ZoneAlarm Trojan-Downloader.Win32.Tiny.cun
Microsoft Trojan:Win32/Redosdru.AB
Google Detected
AhnLab-V3 Trojan/Win32.Downloader.R148588
Acronis Clean
McAfee Trojan-FKFK!FC58E29974C4
MAX malware (ai score=85)
VBA32 BScope.Trojan.Redosdru
Malwarebytes Malware.AI.2125496272
Panda Trj/Genetic.gen
Zoner Clean
TrendMicro-HouseCall BKDR_ZEGOST.SM17
Tencent Malware.Win32.Gencirc.10b397e9
Yandex Trojan.DR.Dorgam!GdsQZBAssLw
Ikarus Trojan-Downloader.Win32.Agent
MaxSecure Clean
Fortinet W32/Kryptik.GHFL!tr
BitDefenderTheta Gen:NN.ZexaF.36806.duX@a8fOpEf
AVG Win32:Dropper-OHP [Trj]
DeepInstinct MALICIOUS
CrowdStrike win/malicious_confidence_100% (W)
alibabacloud Trojan[downloader]:Win/Cud
No IRMA results available.