Static | ZeroBOX

PE Compile Time

2024-08-10 14:56:36

PE Imphash

66a927b99d2ed944e8f631d2b176d59f

PEiD Signatures

Armadillo v1.xx - v2.xx

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x00010220 0x00011000 6.38453696637
.rdata 0x00012000 0x00001086 0x00002000 3.38614244032
.data 0x00014000 0x00017afc 0x00004000 2.67336096531
.reloc 0x0002c000 0x00001744 0x00002000 3.72825790977

Imports

Library KERNEL32.dll:
0x10012018 IsBadReadPtr
0x1001201c GetTickCount
0x10012024 GetCommandLineA
0x10012028 GetModuleFileNameA
0x1001202c FreeLibrary
0x10012030 GetProcAddress
0x10012034 HeapFree
0x10012038 LCMapStringA
0x1001203c HeapReAlloc
0x10012040 HeapAlloc
0x10012044 ExitProcess
0x10012048 GetModuleHandleA
0x1001204c GetProcessHeap
0x10012050 CloseHandle
0x10012054 TerminateProcess
0x10012058 OpenProcess
0x1001205c GetCurrentProcess
0x10012060 Sleep
0x10012064 LoadLibraryA
0x10012068 GetCurrentProcessId
0x1001206c FlushFileBuffers
0x10012070 GetVersionExA
0x10012074 GetLastError
0x10012078 MultiByteToWideChar
0x1001207c WideCharToMultiByte
0x10012080 GetVersion
0x10012084 RtlUnwind
0x10012088 GetCurrentThreadId
0x1001208c TlsSetValue
0x10012090 TlsAlloc
0x10012094 TlsFree
0x10012098 SetLastError
0x1001209c TlsGetValue
0x100120a0 SetHandleCount
0x100120a4 GetStdHandle
0x100120a8 GetFileType
0x100120ac GetStartupInfoA
0x100120b0 DeleteCriticalSection
0x100120bc GetEnvironmentStrings
0x100120c0 GetEnvironmentStringsW
0x100120c8 HeapDestroy
0x100120cc HeapCreate
0x100120d0 VirtualFree
0x100120d4 WriteFile
0x100120d8 RaiseException
0x100120dc VirtualAlloc
0x100120e4 EnterCriticalSection
0x100120e8 LeaveCriticalSection
0x100120ec GetCPInfo
0x100120f0 GetACP
0x100120f4 GetOEMCP
0x100120f8 InterlockedDecrement
0x100120fc InterlockedIncrement
0x10012100 SetFilePointer
0x10012104 GetStringTypeA
0x10012108 GetStringTypeW
0x10012110 IsBadCodePtr
0x10012114 LCMapStringW
0x10012118 SetStdHandle
Library USER32.dll:
0x10012130 DispatchMessageA
0x10012134 wsprintfA
0x10012138 MessageBoxA
0x1001213c GetAsyncKeyState
0x10012140 TranslateMessage
0x10012144 GetMessageA
0x10012148 PeekMessageA
0x1001214c GetSystemMetrics
Library GDI32.dll:
0x10012000 DeleteObject
0x10012004 SelectObject
0x10012008 DeleteDC
0x1001200c BitBlt
0x10012010 GetDIBits
Library OLEAUT32.dll:
Library SHELL32.dll:
0x10012128 ShellExecuteA

Exports

Ordinal Address Name
1 0x10005e8b uDDeHgSYNe38437829XaNMUHQSXn
!This program cannot be run in DOS mode.
Rich)$
`.rdata
@.data
.reloc
3E 3E(1E
hTXCAh
hfff?h:F
hfff?h:F
D$$SWVURP
t@_^]3
D$0hlI
QSVWVWS
QQSVWj
t.;t$$t(
8t9UW
SS@SSPVSS
t#SSUP
t$$VSS
_^][YY
HHtpHHtl
VC20XC00U
uA;5lt
t+Ht$Ht
HtHHt
+ttHHtd
HSVHWtgHHtF
PPPPPPPP
PPPPPPPP
tFGQPS
__GLOBAL_HEAP_SELECTED
__MSVCRT_HEAP_SELECT
runtime error
TLOSS error
SING error
DOMAIN error
- unable to initialize heap
- not enough space for lowio initialization
- not enough space for stdio initialization
- pure virtual function call
- not enough space for _onexit/atexit table
- unable to open console device
- unexpected heap error
- unexpected multithread lock error
- not enough space for thread data
abnormal program termination
- not enough space for environment
- not enough space for arguments
- floating point not loaded
Microsoft Visual C++ Runtime Library
Runtime Error!
Program:
<program name unknown>
GAIsProcessorFeaturePresent
KERNEL32
`h````
ppxxxx
(null)
_hypot
GetLastActivePopup
GetActiveWindow
MessageBoxA
user32.dll
1#QNAN
1#SNAN
H:mm:ss
dddd, MMMM dd, yyyy
M/d/yy
December
November
October
September
August
February
January
Saturday
Friday
Thursday
Wednesday
Tuesday
Monday
Sunday
SunMonTueWedThuFriSat
JanFebMarAprMayJunJulAugSepOctNovDec
GetCurrentProcessId
GetCurrentProcess
OpenProcess
TerminateProcess
CloseHandle
GetProcessHeap
GetModuleHandleA
ExitProcess
HeapAlloc
HeapReAlloc
HeapFree
IsBadReadPtr
GetTickCount
GetPrivateProfileStringA
GetCommandLineA
GetModuleFileNameA
FreeLibrary
GetProcAddress
LoadLibraryA
LCMapStringA
KERNEL32.dll
GetAsyncKeyState
MessageBoxA
wsprintfA
DispatchMessageA
TranslateMessage
GetMessageA
PeekMessageA
GetSystemMetrics
USER32.dll
SelectObject
BitBlt
GetDIBits
DeleteObject
DeleteDC
GDI32.dll
OLEAUT32.dll
GetVersionExA
GetLastError
MultiByteToWideChar
WideCharToMultiByte
GetVersion
RtlUnwind
GetCurrentThreadId
TlsSetValue
TlsAlloc
TlsFree
SetLastError
TlsGetValue
SetHandleCount
GetStdHandle
GetFileType
GetStartupInfoA
DeleteCriticalSection
FreeEnvironmentStringsA
FreeEnvironmentStringsW
GetEnvironmentStrings
GetEnvironmentStringsW
GetEnvironmentVariableA
HeapDestroy
HeapCreate
VirtualFree
WriteFile
RaiseException
VirtualAlloc
InitializeCriticalSection
EnterCriticalSection
LeaveCriticalSection
GetCPInfo
GetACP
GetOEMCP
InterlockedDecrement
InterlockedIncrement
SetFilePointer
GetStringTypeA
GetStringTypeW
SetUnhandledExceptionFilter
IsBadCodePtr
LCMapStringW
SetStdHandle
FlushFileBuffers
ADVAPI32.dll
ShellExecuteA
SHELL32.dll
ole32.dll
Z3.dll
uDDeHgSYNe38437829XaNMUHQSXn
C:\Music.ini
?333333
?kernel32.dll
kernel32
NTDLL.DLL
user32.dll
user32
gdi32.dll
GetCurrentProcessId
LocalAlloc
NtQuerySystemInformation
LocalFree
GetAsyncKeyState
CreateCompatibleDC
CreateCompatibleBitmap
SelectObject
BitBlt
GetDIBits
DeleteObject
DeleteDC
ReleaseDC
GetCurrentProcess
OpenProcess
TerminateProcess
CloseHandle
program internal error number is %d.
program internal error number is %d.
:%d,%d
blackmoon
BlackMoon RunTime Error:
DLL ERROR
:"%s".
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
explore
&0-0@0F0P0Y0
:1J1d1
2!262p2u2}2
3#3+333;3Y3h3n3{3
4,424>4d4j4p4v4
5?5H5n5t5
7)7/757;7F7V7^7
83898E8k8q8w8}8
;(;>;G;];
<0<=<F<S<\<
= =)=b=
=/>]>i>
>*?6?d?q?z?
0L0Y0b0o0x0
1&1/1<1E1~1
3D3c3o3
4.4M4Y4
575C5q5~5
6!6-6[6h6q6~6
7"7P7]7f7s7|7
8%8U8h8n8
9$979e9r9{9
:$:1:::j:}:
4"4i4{4
?#?6?I?\?k?~?
*0/040@0E0J0V0[0`0l0q0v0
1!1,171Q1\1h1n1v1
1!2(282?2G2Q2_2o2
3!3(3A3K3P3h3x3
3A4I4Q4q4y4
6:6A6i6
7=7N7z7
5+5T5v5
737;7J7Z7
9%939<9P9T9X9\9`9d9h9l9p9t9x9|9
:':0:?:H:P:T:Z:
2$2/2B2M2`2k2~2
3%3-383>3D3N3f3k3u3
8R:W:{:
;";7;y;~;
;V<\<(=@=G=O=T=X=\=
=2>8><>@>D>
?+?]?d?h?l?p?t?x?|?
10191O1Z1_1i1n1
242:2t2|2
3!3'383O3Y3r3
4"4D4X4
5<5f5t5
939?9O9
<#<*<1<7<^<j<r<z<
=(=;=b=q=
>">8>?>`>i>
3;4K4W4i4y4
7(8P8U?
5o5|5-6<6R6
9]:Q=U=Y=]=a=e=i=m=N>]>
55%5h5
9>9D9K9X9_9g9m9s9~9
<.<9<K<^<i<o<t<z<
00/080R0c0i0|0
3(3`3m3
4>5K5Z5
8&8.868I8Q8~8
::$:(:,:U:{:
;-<4<8<<<@<D<H<L<P<
0&030F0O0[0
1/1D1J1R1Z1e1
2 2%2*2C2I2
333A3N3^3
5-666<6H6M6W6^6f6l6s6x6
6)9D9L9R9X9
3#4:4G4a4o4}4
5,5O5Y5b5~5
626D6J6[7`7|7
9&:N:g:
;?=C=G=K=O=S=W=[=_=c=g=k=
?4?L?l?
1N2S2[2`2h2m2
3#6=6N6k6
9 9:9E9[9c9
0 0,0@0D0
=d=l=t=|=
?"?&?*?.?2?6?:?>?B?F?J?N?R?V?Z?^?b?f?j?n?r?v?z?~?
43<3D3L3T3\3d3l3t3|3
4H4L4P4T4
7\=`=d=h=l=p=t=x=|=
> >$>(>,>0>4>8><>H>
(null)
((((( H
Antivirus Signature
Bkav W32.AIDetectMalware
Lionic Clean
tehtris Clean
ClamAV Win.Dropper.Tiggre-9845940-0
CMC Clean
CAT-QuickHeal Clean
Skyhigh Clean
ALYac Clean
Cylance Clean
Zillya Clean
Sangfor Trojan.Win32.Save.BlackMoon
K7AntiVirus Clean
Alibaba Clean
K7GW Clean
Cybereason Clean
huorong Clean
Baidu Clean
VirIT Clean
Paloalto Clean
Symantec Clean
Elastic malicious (high confidence)
ESET-NOD32 a variant of Win32/Packed.BlackMoon.A suspicious
APEX Clean
Avast Clean
Cynet Malicious (score: 100)
Kaspersky Clean
BitDefender Clean
NANO-Antivirus Clean
ViRobot Clean
MicroWorld-eScan Clean
Tencent Backdoor.Win32.Runshell_l.16001193
TACHYON Clean
Sophos Clean
F-Secure Clean
DrWeb Clean
VIPRE Clean
TrendMicro TrojanSpy.Win32.BLACKMOON.YXEHKZ
McAfeeD ti!21088DDF098F
Trapmine Clean
FireEye Clean
Emsisoft Clean
Ikarus AdWare.Win32.BlackMoon
GData Win32.Trojan-Stealer.BlackMoon.D
Jiangmin Clean
Webroot Clean
Varist W32/Blackmoon.BA.gen!Eldorado
Avira Clean
Antiy-AVL Trojan/Win32.Blamon.a
Kingsoft Clean
Gridinsoft Trojan.Win32.BlackMoon.tr
Xcitium TrojWare.Win32.Zegost.D@6vpf1l
Arcabit Clean
SUPERAntiSpyware Clean
ZoneAlarm Clean
Microsoft Program:Win32/Wacapew.C!ml
Google Detected
AhnLab-V3 Clean
Acronis Clean
McAfee Clean
MAX Clean
VBA32 Clean
Malwarebytes Clean
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Rising Clean
Yandex Clean
SentinelOne Clean
MaxSecure Clean
Fortinet W32/Blackmoon.D!tr
BitDefenderTheta Clean
AVG Clean
DeepInstinct MALICIOUS
CrowdStrike Clean
alibabacloud VirTool:Win/Gamarue.Gen
No IRMA results available.