Static | ZeroBOX

PE Compile Time

2019-10-17 14:39:03

PE Imphash

92cbf1b7939e726b820cc211fce00750

PEiD Signatures

Armadillo v1.71

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
PAGE 0x00001000 0x00000197 0x00000200 4.99571099299
.data 0x00002000 0x0005d394 0x0005d400 7.87534500152
.rsrc 0x00060000 0x00000010 0x00000200 0.0

Imports

Library KERNEL32.dll:
0x402000 GetProcAddress
0x402004 GetModuleHandleA
0x402008 RtlUnwind
0x40200c RaiseException
0x402010 GetStartupInfoA
0x402014 GetCommandLineA
0x402018 GetVersion
0x40201c ExitProcess
0x40202c HeapFree
0x402030 GetCurrentThreadId
0x402034 TlsSetValue
0x402038 TlsAlloc
0x40203c SetLastError
0x402040 TlsGetValue
0x402044 GetLastError
0x40204c TerminateProcess
0x402050 GetCurrentProcess
0x402058 GetModuleFileNameA
0x402064 WideCharToMultiByte
0x402070 SetHandleCount
0x402074 GetStdHandle
0x402078 GetFileType
0x402080 GetVersionExA
0x402084 HeapDestroy
0x402088 HeapCreate
0x40208c VirtualFree
0x402090 WriteFile
0x402094 HeapAlloc
0x402098 VirtualAlloc
0x40209c HeapReAlloc
0x4020a0 IsBadWritePtr
0x4020a4 IsBadReadPtr
0x4020a8 IsBadCodePtr
0x4020ac GetCPInfo
0x4020b0 GetACP
0x4020b4 GetOEMCP
0x4020b8 LoadLibraryA
0x4020bc MultiByteToWideChar
0x4020c0 LCMapStringA
0x4020c4 LCMapStringW
0x4020c8 GetStringTypeA
0x4020cc GetStringTypeW

Exports

Ordinal Address Name
1 0x4010fe Fatal
!This program cannot be run in DOS mode.
f]#|zS#
f]#8`[#
f]#Rich
`.data
6^pS
Pffw2;
z4ZW\v
8AC\yg
BI?#CZ
N2JSS&
Rl36s:t[|&
Yf!T>_
fJe]B
~_M:J4
k yyxB
)!~2#P
Lo+&ZT
4TZhH*
Oj:m#P
ISX6~^
TuaRon
A[I45Y
&Caxu#
]U!O=SO
?+(M|L
,/tX2jns
pRU@M5
GAR ;>
=Ti0w_
YO49<w?
PWyEC?4D
}94CeZ
\GDAhY
8F./(O
_R3),L
67xfgmC
4cgwQ
3S-n&A
:o$^n.
`@K\m6Vv
Bkhh97_3
38-$*,
2O6_@4L7
JDIB\
{?T<7a/
o?:!d1
rXH(pQ
PM~_yk
ewV}?
3te.p}
6nnrCK
o8 +6o
D_=mHUg
XkuDN'0
3,NU<S
YH>RRh
`<5|:T
U.ruR=
JRQoqI
[cf=0ol/
J(Y1CqO
XVH3Nv
&Vz^qu
ATZ41z
MG07P=
w55d<-
BWoLW
PH7p{A
c\12=[
FEfr9d
a{Q2^X
U')i^rA
#X[Fs\
`ldl97
?)sR1yS'
GVRAeQ\
v8^#dK
-sP_;Hw
qvD%&d1Q
GSlpiV
FvlHMVUw1
KT.U~~
RK6zi%
|]NXb?m'
j[3UdFZj
Y?&tA]E
igY3W^
$G$n#VG
QAp.==
\OW&"u|
)n6j`L
Vwp"'`
ei$MVY
_lI?+`
l*Q2Ve
}KZ7@p
!Tbe3W{
&j4N:y
'SYVWz'N
7USr{_7
JpLM|
ez%YxE
,(OpPO
T6{kKO~
pmKr6b
flQ.kQ
/Uog\/.
y~'s+h
YYLwwb+.a
k\Wnawg%X
'vFhH^pR
D|)L\[%
"E1G|4
Dm~9D!
]Z|?@m
SLH5Cg
9$<gJT
(Q1,(+
|z5GpJO
y>jk4'
Kjd?{F
.+6.!u_'&
Z7%rn%C
v CQ(^h
X` \uC
j@5s1'
{#7(Bw
W)_>@6
P02/X8@
83~ySq
(rb~)3
9G%:C8A
G>*/n)-
ob(G?]
eker>!
Xlrw;
48ei<^d
,~mTiq
&|bo<
,RU1ji
h},[3:;n
@Z_Kv3
9=($/E
T@5QAw2
?M\5b\
UUC@LG
a>0']a
|!lu}7
?1rvxx
t(^~ys
9.)r4A^T
u l]e2
@~~#Y
d1=|`@
Q(m+s|
qDwzEJ
>}<1Gm<
]pAJBGN
5;tAj%
^{rY^]*
R]PlY
K|??S~v
4']4Fs
/&,UjB^
Pi5ES/k7u4
)}a|c7U{
,GNP;wu
&AM2Ta0
t>Iwzg
kQ"N87
h|P9|W+Z
|mR5p)
X/&p ph
-RpJYY
#p{{.
X][R~>
8xprF,
rGAE@s
U$-<Gb]8
,VNVr
e-1=}P
_>m/iq
qT$&|i
.[ un,
$"g&Ru
I:EoTQdj
?2O&+(
BI<go@
LF:[`<
Ymj|E{
>yDqMY
7~O:o>2
OIUT7kX]M
GU`W#C"
?gpSs H
mqabbQ
;_cx]
kTgU4q`
Q>(|NYh>3
\lBz(lp
(BaT~c?
P?{W\D
h<YGNk>H
)IMo,k
[ oH:3/q
._mx3{
<YzE(qp
5BMO4U
G.o#u[
^|F4(JQZ\
S&t`U$c
=1m@x{A
q{PRxL
VCESYT
ddENyd
r9oa*+m
qDY-#E4
N*EWa%%
#aIb8{
<h|Oe'
&lv{~'
S=p4C[
nJtU>u
#Vu71Ns9EIK
vj1Tng
d6>~0YC
6R,^&x
@Y?hSv
Pqv7T!-E
*fH3^7
W.o)^3
XJ?0']
SjLgur
)xroPG
"|')"d
I{Z`n^
8t#y?[
Y%4FTn
g$4!g
5od.8#
)%u8_ao
C-s'(`o{
U<:5/
vz;Y?x
9]HT{TO}9
`3mN{H
RPTR(R7gH
Z.]L1o
^TcTt8
aWc_3R
p#u@zk
q8>Pn9
-zDbq
pwQnaJ
SmyeC8pf
q5J(6M
rLDIOS
P7&?Khcy
;BO-\)Z
ojwA7k
jB&R4J
tlv$'/
!av|pZb
S4PK4
>/ &67i
U tT&sp
-'jnUD
mRP]UD
8r'WXhZW
]^OS^B
+lO|/{~B4
|N3o*
9_|# c
YQEEQ,d
m4[t9p
cp^SUG~.d
'N.1GW07
SO;@Q~og
r|by//
\/f7++o
wltCey
R@$SSo
BmpyVNG\e
?TXA=y
iV3;oW
J(e}Eo
{L7Tn
Z^K:1c
"6{ H^
CPm+5'
\`UCXR
wUtMw
g^Q7V\9
WZ%/mK
UU>51s
@2G6S2
:{{.b
Gy)@Ex
U1c/A_
u~'jPo
hEa/hl
41sC ]
~ZdQ?w
JMvKU\
J;t_RSp:
;Or~{s
qm8FtQ
6[3`c:\
qS/lLB
Om>.KIG
G~RV}^
f:c*#)
&fUK^X
F3P;>]
M%@C^/
Cm-6SV
L[tp:@
T^uR<u
d)pk+d
9p-q:W
5S|}:
38LQ-|y
v}cS-}{
b)b'LZ)
y[$E/Pq
}i(,K&u(
Hg:gJ
7F_N0v
P1k\VM
bgAZ/KN:l
kT\k\e
r}VVo~
KPw\f,
zmq.}{-
Jxog t
clt_C+
(Dvk$G
dQD2=M
?rD^/[
6!N`~M
4\"$t
v{'W,y@
W%\I2l
Q)BE8o
?SvpT
w%r~Xk
L$RQ.Y
\z^AoR3
JwjTC(
P_ojwr
aL{TN)b
o\J$w
JnAVck
f3n`/w
a|(P2R
^6G[+l|
No^hvs
Il}h)p
c]4B(5wlA,I
M*?]@V
]-TIxi
s$,OhY>
$J`}:Z
0"V3O0
8(fL}@*n(
q%lYwj&_
t95f;U
D_Fpk(
.v|`jX
1{qNz_
fhqvR(,e
gdL]iE
h8{PP)u}
V]M[ /
8~QNRZ
(65LR\
e'"~%f
=.D$,g
r(olqD
sPo}Tl
<0Yh%|
8(?{4_
RVzh=y
yvtO`z
kCd&y "
=vhFtn
YjFk;n
A-c1F8Fy;wT0wv@5.C[9
tws7qe<?
|eA6sf<8
ampYmswklhygvhmj[u5,3+1600;\604
Llapnqneq",OGU#Escn`uipo!MEDL&t7-2/23538]\<57
Okbpnpjdv!,OFW!Dqdocuksh"OECLM
0eg4:3467313b`:ba5800105:02;5bae
'U{pwglSliv$^w}pugn60Z
oqbmspsuu/gyf
.?AVtype_info@@
__GLOBAL_HEAP_SELECTED
__MSVCRT_HEAP_SELECT
runtime error
TLOSS error
SING error
DOMAIN error
- unable to initialize heap
- not enough space for lowio initialization
- not enough space for stdio initialization
- pure virtual function call
- not enough space for _onexit/atexit table
- unable to open console device
- unexpected heap error
- unexpected multithread lock error
- not enough space for thread data
abnormal program termination
- not enough space for environment
- not enough space for arguments
- floating point not loaded
Microsoft Visual C++ Runtime Library
Runtime Error!
Program:
<program name unknown>
GetLastActivePopup
GetActiveWindow
MessageBoxA
user32.dll
H:mm:ss
dddd, MMMM dd, yyyy
M/d/yy
December
November
October
September
August
February
January
Saturday
Friday
Thursday
Wednesday
Tuesday
Monday
Sunday
SunMonTueWedThuFriSat
JanFebMarAprMayJunJulAugSepOctNovDec
QQSVWd
t.;t$$t(
sO;>|C;~
8t9UW
SS@SSPVSS
t#SSUP
t$$VSS
_^][YY
VC20XC00U
HSVHWtgHHtF
PPPPPPPP
PPPPPPPP
tFGQPS
^}%95x
GetProcAddress
GetModuleHandleA
KERNEL32.dll
RtlUnwind
RaiseException
GetStartupInfoA
GetCommandLineA
GetVersion
ExitProcess
InitializeCriticalSection
EnterCriticalSection
LeaveCriticalSection
HeapFree
GetCurrentThreadId
TlsSetValue
TlsAlloc
SetLastError
TlsGetValue
GetLastError
SetUnhandledExceptionFilter
TerminateProcess
GetCurrentProcess
UnhandledExceptionFilter
GetModuleFileNameA
FreeEnvironmentStringsA
FreeEnvironmentStringsW
WideCharToMultiByte
GetEnvironmentStrings
GetEnvironmentStringsW
SetHandleCount
GetStdHandle
GetFileType
GetEnvironmentVariableA
GetVersionExA
HeapDestroy
HeapCreate
VirtualFree
WriteFile
HeapAlloc
VirtualAlloc
HeapReAlloc
IsBadWritePtr
IsBadReadPtr
IsBadCodePtr
GetCPInfo
GetACP
GetOEMCP
LoadLibraryA
MultiByteToWideChar
LCMapStringA
LCMapStringW
GetStringTypeA
GetStringTypeW
InterlockedDecrement
InterlockedIncrement
Install.exe
((((( H
Antivirus Signature
Bkav W32.AIDetectMalware
Lionic Trojan.Win32.Farfli.m!c
tehtris Clean
ClamAV Win.Trojan.Farfli-9645812-0
CMC Clean
CAT-QuickHeal Backdoor.FarfliPMF.S19352949
Skyhigh BehavesLike.Win32.PWSZbot.fc
ALYac Gen:Variant.Zusy.313935
Cylance Unsafe
Zillya Trojan.GenKryptik.Win32.36169
Sangfor Backdoor.Win32.Kryptik.V90w
K7AntiVirus Trojan ( 0055a5d81 )
Alibaba Backdoor:Win32/Farfli.bbca2549
K7GW Trojan ( 0055a5d81 )
Cybereason malicious.4d5367
Baidu Clean
VirIT Trojan.Win32.Genus.KGR
Symantec ML.Attribute.HighConfidence
Elastic malicious (high confidence)
ESET-NOD32 a variant of Win32/GenKryptik.EZKJ
APEX Malicious
Avast Win32:BackdoorX-gen [Trj]
Cynet Malicious (score: 100)
Kaspersky HEUR:Backdoor.Win32.Farfli.vho
BitDefender Gen:Variant.Zusy.313935
NANO-Antivirus Trojan.Win32.Farfli.gethzp
ViRobot Trojan.Win.Z.Farfli.384000.K
MicroWorld-eScan Gen:Variant.Zusy.313935
Tencent Malware.Win32.Gencirc.10b1dd92
Sophos Troj/AutoG-KM
F-Secure Trojan.TR/Kryptik.kenti
DrWeb Trojan.NtRootKit.20174
VIPRE Gen:Variant.Zusy.313935
TrendMicro TROJ_GEN.R014C0DFC24
McAfeeD ti!14F381C0D75D
Trapmine Clean
FireEye Generic.mg.c51e84d4d5367860
Emsisoft Gen:Variant.Zusy.313935 (B)
Paloalto generic.ml
GData Gen:Variant.Zusy.313935
Jiangmin Backdoor.Farfli.exu
Webroot Clean
Varist W32/Agent.BOB.gen!Eldorado
Avira TR/Kryptik.kenti
MAX malware (ai score=88)
Antiy-AVL Trojan/Win32.GenKryptik
Kingsoft malware.kb.a.999
Gridinsoft Trojan.Win32.Kryptik.cl
Xcitium Malware@#1uqdloqyfeqzg
Arcabit Trojan.Zusy.D4CA4F
SUPERAntiSpyware Clean
ZoneAlarm HEUR:Backdoor.Win32.Farfli.vho
Microsoft Trojan:Win32/GhostRAT
Google Detected
AhnLab-V3 Trojan/Win32.RL_Farfli.R299612
Acronis Clean
McAfee Trojan-FRMW!C51E84D4D536
TACHYON Backdoor/W32.Farfli.384000
VBA32 Trojan.Injuke
Malwarebytes Generic.Malware.AI.DDS
Panda Trj/Genetic.gen
Zoner Trojan.Win32.105885
TrendMicro-HouseCall TROJ_GEN.R014C0DFC24
Rising Trojan.Win32.FakeFolder.ae (CLASSIC)
Yandex Trojan.GenAsa!6tUyyqkpagE
Ikarus Trojan.Win32.Krypt
MaxSecure Win.MxResIcn.Heur.Gen
Fortinet W32/Generic.AP.1EEA56A!tr
BitDefenderTheta Gen:NN.ZexaF.36806.xmW@a0gar3n
AVG Win32:BackdoorX-gen [Trj]
DeepInstinct MALICIOUS
CrowdStrike win/malicious_confidence_100% (W)
alibabacloud Backdoor:Win/Ghost.ag
No IRMA results available.