Static | ZeroBOX

PE Compile Time

2020-03-14 06:45:02

PE Imphash

19d4e66d725c89ba6712b82bebc8196d

PEiD Signatures

Armadillo v1.71

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.data 0x00001000 0x0005f415 0x0005f600 7.87571213228
.rsrc 0x00061000 0x000002e3 0x00000400 4.31408896332

Resources

Name Offset Size Language Sub-language File type
RT_MANIFEST 0x00061058 0x0000028b LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED XML 1.0 document text

Imports

Library KERNEL32.dll:
0x401000 GetProcAddress
0x401004 GetModuleHandleA
0x401008 GetStartupInfoA
0x40100c GetCommandLineA
0x401010 GetVersion
0x401014 ExitProcess
0x401018 TerminateProcess
0x40101c GetCurrentProcess
0x401024 GetModuleFileNameA
0x401030 WideCharToMultiByte
0x40103c SetHandleCount
0x401040 GetStdHandle
0x401044 GetFileType
0x401048 GetCurrentThreadId
0x40104c TlsSetValue
0x401050 TlsAlloc
0x401054 SetLastError
0x401058 TlsGetValue
0x40105c GetLastError
0x401064 GetVersionExA
0x401068 HeapDestroy
0x40106c HeapCreate
0x401070 VirtualFree
0x401074 HeapFree
0x401078 RtlUnwind
0x40107c WriteFile
0x40108c GetCPInfo
0x401090 GetACP
0x401094 GetOEMCP
0x401098 HeapAlloc
0x40109c VirtualAlloc
0x4010a0 HeapReAlloc
0x4010a4 LoadLibraryA
0x4010a8 MultiByteToWideChar
0x4010ac LCMapStringA
0x4010b0 LCMapStringW
0x4010b4 GetStringTypeA
0x4010b8 GetStringTypeW

Exports

Ordinal Address Name
1 0x45b93f Loader
!This program cannot be run in DOS mode.
8%I"4U
dQN `)Q
8}!hht
joO E+
!+_pZ,
Iyx>I+`"
bqr0Dq
OC0f6
&GAgX&
sJX7ILa%
nqQ-zA
nrJLIxC
d501Bl
5'{7_n![ZH3
2vE84I,
Y=V;R7
md'Uh,
F[%cg
<"N*S9Bb
,d_bL_
N'KqiK
7L;/pL3
,w;[o.
wL?q]5
8~T!-WJDU(
Pe%|h:
:5O.Wj
-iKzSZ
l)@nK\
nMkl]g
%44_I
*9O.><(G
|?1%IeY
O ~xm^hl'k
/"_]y""
AgeLb
UEV(P&
75wAw
PJJ-'`k
XMj9oqT
%~@67]n
B.YO!4Z
2IU6-,
r5ZtIv
c,=5=f
4J%N<x
ETCvaE
&mxQ(s
Jec;(+
0F<\U/x$i
<_aIaL
OxZ3y,u
.#V?-)#~
jgI7j#!c^
uo-%,O
Oc6_NP
l)@vYjR
Uca"C9
`b;|QN2
"Yh]+i
%N)092G
HTgkK3
r;n%8)N)n
a2d-l5
,g}deD
B=A=.N
NLV2g4_
NZ|,
<Op!~(
IM0qWe
8^@xA{L
VqZ6q\q`
o,40AU
8HF"qL
eOK^-2
K0N+Q!p
7i0K9t:
ubRI1sk
w:ROqh
Jf;}t
LD0))p
,U|+K?
''1!8-
^6U/7"K
b_&99,p?V:
0ug'-J
x"uE(q'
8/ATviPC
^6#VJ6
d9_ %$
{,lJ`7jh
!'9H|3
Q4Zb|c
{[\g6/
}1J.|S
QVuPA-)
m>E0OKV
(;B>";Z
9Nj_g?
<OY>BTAy
]!!JaD
?&?Yw:
4 W)*Z
WgGN&X
Rno)0-i.#
3I'hs(@
+p"}o)}
X{v]@<
V1NO~-
2\@?H@
w? #Xz
a6QR(B
X& QR`
z]4L@T
BS3N^M
VRZU;x
=[[Z%T
2X1NJf,
!5P<HBtOj
CR7os&
hj(SPxu
)o\LZm
M_Zoi
nUv?2?
%huUp*
* %)\>
lMGv^>
0s\_3Ym
r-x5-r
{9E)G4)4
UQk5rqB
n|!#P
:&r5n8dN2
kL_Z+u
EekFp(sl
>.A;Exi
k#X <#R+p
:ZK#X=
]F4l=W
[ARH'b
y& ^N+WV2I
<ud=`T
e'?pY$
w.ieO.
PRC#PS
Rb PX8
=I[2bd
{H0io<
hH#ba'c>Y
BfgqZc
c2grgO
i'bz|!
wrzJw=
U1:kU$
4IA75g
Sg{pri
(L,AN"
}C6TN'
S][:qN
U3TfQYv
W4q>}K?%
O_("no
},q:/4
!LMKpyn
i1yEMal&p
R+U9Mmd
k2PM=N
DY)VO>tcr
#F>7Ch$
ArM^AJJ#
uM@|@{
eZza=*
yElR6m{
^K'Ex^BK
D=s2!e
I'#>j&k!
J.Y\15
sXT-u
j?c@P~
"N%2o.
xxs'kh
euj[\A
OD*v=E
^q;dbq
/s|B10n
\}_dgY
5I|)m3
!lxC|"
1lBANS1
*POpmK%
f'1\I5#|
kCEM[`
JNS;jF
gE3N:Qg
X/%Pi`a
H~Zxqt
qC%ba/x
B>iL^Y
`)yhyr
V 7\6Bj
c s+Dr\^
bo;]krQu:8EJ;(G
j7)K]}',0
`9md+
iBtbJg
x6BM(h}
~B-F\>S
%pqF%*
o,j%1W~
QQy}|u
O8]DQ^
tK&%V`
lZV'L[
/R)W}7
'!^&:0,
d=nBO^
]NVRuy(
x;.O[A
KmY<!y
kHpi+b
CMgKJ J
IwVeY}^u
mP#'~_.
tnr8,;
6H|n1@Y
yoPMN=?
sO'k`"V
F:6I,I
j+^Tyt
j8?j\20
f^EZ<h
=-Mo$
OFy4#y
!bM#py
{r>! 5X
mI9l>_%
i5>P?}
RH(^}
C:{Q)a5k
YT3Lu<fe
gRDg1N
[&#dwsF
lehN$*
@@Md"3
D'vDLJF
|h+Z}t
%Re'Z
R>oxP!w>
.Mnu2R
#X+!T.
qrsrW.
2m_2NcKj
1%% =q
-4iz{^
ocL5o(k
@gf5fq
.IqxfnM
61?on^
1?!|(X
>#Psf>
d;8n)>
D`u]{^
R_LfO!
vd1-Vv<
jlB}nJ
LV*@I
^lo~|f
<h.0U9
.`X[E5H
NhUko4v
U{4y5R
_R U]aUkF
K^65+Vrz
7'\(QA
Gn?\X7
L.sa}Z
W(]lOLjTG
>;1!US
.Tc.2*
U[93B4Ld
(vQ1[1$
I\00IF
:`B/;K
8t?>Wv
n~nDx3
p{^@\'y
gmZ(Taj@
:,S!E
sd4`TXN
d0F8JK
y^}Z|
8edJ;U
:I?WNS
]fS^lf
}7n:=
@]FAkB
J<J<Uq%
\cFAvy
RA!>op
hEx6g
KdC%OB={3
Q"[Oi
z*,1{5R>
rp($na]
%>qtFd!
W=N`+g
Z8P%8Z>
LE(w8dz
A2*r,k;BB
B"qE%4
QB*1 g
%BBQ1U
EOqxG
yVZqoe
cSi"KWT
+65rCP}c
pN,(@~N
d9C;$%
gm}R45
;A_"'Jm
AS1Qpq
Z%&r_6
V'VC!b
;@Y_ L
`%361E_kG
E%u_9R
FyeY{[
#zs?-d
XUc4+y
"(E0xYjLcg?~
tg?1=X
(l+7U!Q
V9<8cq
`{L9@^
XR'W @
S tEa{
pM=mtp
ipQSRp
b[yP sIQ
C!uL`c]
YUj83j;
^^8/G&/
"OE\yC
BqzrRx
w8U#FG
OG+>Jr
;C=+%8G|*
7q7%#O
8[4\2W>Yx
p#9gy`
"!X_)N
]bY=N~U
n%HoNx
n@]_`O
7]X1}.*
><q Ru
aTw!gc
5Q>CEN
,"BZU|
7O6i)*
-/5dYP
IG50PAH
5[")\g
49MH_xr
;]1-e(
=F)M{\
{f9VNi
EoX/qR2
H$d5ru
P^)IA@3
k_QQ@K']
YOSRP
`I$$Er
[)>):i
k2G$ow8
-N9(_#
cTB_N%
&I<mXG
5hePo#
)nfIbvq
J1=4 
'U)N0.
rw%IF5
n.w$&C
y0TpuE
y~CnAQ~
>VQW$:
6iX%\;
Q(.gIt
Y:vR91
qw%fcOW
l#THK[r
szr?$B
44V=]:
C]4:)Q:
GQHo'
/R xWGxI
E4cZLc
/{14Grb
+=$j\O:
Z H`Yh
l86[%6
B#E:v:J~Z
U$f1a{
I a=$*
u`gGBw$ng
385zlu9
8"~-#oA
1eTh;l
0O\seL
cQjw(y
;|,HDf
C&b3,K
U2V,m
,fwyVD
d5#`C
9O{?.B
_?]mQv
|d,;aR
m ^(O#
gFzTvq
uVlGEY
{Z~dx[F4
?AY JZ
["o9}KX
I@T(pI
kX35]*
JYlPXoL
'}u15L(
P!_%pyq{(
a8{~Ai
Zm=(Y1
=65}D9CM
Fo`s@@
X24qDj
#~DVENQK
?4cik-
SdNT+mq
G9"-Rr
_y<TFk
VhP(w|
eykcq=
tBl,X g
O~]F7Wv
+~Q#hbJ
[eKsU%k
3d8@jG]@
Q9!,}+
NPkO*G
332+s:|Z
69yL?MuY
(A}aj*S
*f5M>mI)7
XFJ<)h
U*%ya$#=%a
|d$^Kl
'U0cZ]
G]wSaa]
\MvtBV
cYNEEQ
(.] -n
#%Pn)7
^+Rw)p$
srIl-$
l5a S8
kGr`@Y
/FS/4I
0J=064)E`f
'$UxzMJ#'
i%/EgU
Ib^JuRwt
I}A.9&
]U}BdZ
Og?9${
bRkTlF
oZX#IV
E{3=KD
V}ID-Z
aL>q\Q
e5 ZQ.%
$H,Y{xf
,?he#H
{Xjj.u
f9a52{
&ME%At
+iA*ke
CnD_6d
1E?%1Y
9'U2r`
hiM56d#a6
T?$mt"
O9g>s%*
85W%pV
8HK%]2
VEa(,X_fR
N!?TF\
W*i`>s
zesNgc
$!}lh9=A
ysJ,Jm
L&}N
83-U2~f
q}B!"1
d?TQm+Ys
>34Ae_
%ki!OVGe
:Q&p1R
T!!7D>
"nWEAw,
e*d0ER
EN[:i:L
tR2N^O
>Q>%~6
GEA}p]UeOH
!I7R+X
o=6XU
/Li17Q
x$;W8z
z, $iB
@,6%ZJ
G`;O%^
-A.ril
nA's5D
r|Ot?`
hEp 2+W
N%~++qS-
:c~1r>
E(V%f:
Q 0E>'
906,9]"
aw0jds
4)G6h8
b12f1e
Q&1|\}s
39]2o9
m)Z|nclx
% buwA
R! _Yl8Ee^6
6D{8
?YFwR2
/bGx'L
a_u W{C~
\8a]0z
URj$WP
x!d~uN
LVJ?OQ
\s^!6zm
%LTR686
J-C $=7
iYe+};
QFmOoy
#R*REas
?u=z[i
sr?Ri>2,@
=RKc=G
&atav^
Y[z(pE*W
8=Dw[q
;vq"Q&U
ve<_g=
K!6A@
t:1'ODia
5v!JA4v
Jw!b/q
Z{f,15
LR\l;4
Uvbc]&
="(j)Erk
uL38ge
%VEx*K
E6!K.E
w;&5P-
=7!H0=
=#M$\=
=OY0H=
1440)Q
qo=-9`
K[8]c%
9kx0iu
a'*B9q
1D6Y"Q
BM/3(ek4g
tli$--li
}R#ap{
-MJS@)E6
coYU&=9m.w(C
%zx|-a^z
Bi<=]"
QH,@^e
9}4^|<d-
/0$5m'):OM7
7A3fNH
`*GbS
9!f8<5
'KEiN&)
bcXdqa05
i-X/Y5=f
NJ:Oc4
;,e{J:
5=9;"c
T]yli=U
t-e'i]SE
Mj2)Y=d\s
^iT?W,S
nQ4.F=
P%1!v5
u*|U,^W
Np V]2X
c_KNgaH
uK(I-B
R(O=n!
Q]rgX=
pXWH7P
^5qaS|
F U_J,Hx?
1(=v\#4vz
$4W5R
"n3:[!
;@FMCR
:6[I3Y#"
@<M/_W1
l`GKQs
r Z6#xX
51t% ^c
^'UnU?
A+}`o0
h-?V*h
hYK"Vh
hEW>Bh
1RC+P0
g;*B9f
{;*B9z
O;*B9N
,cG`>+C
]@IiuB
r]u2d
XMY&Fe
2.G;Fe
YB>M3:7
Kscj1[
txGy-/
(;K>M+hiM
hY@*KV
y7F_YE+
e/(|ot
<'J4_Nh
&"J.rt
qrop#\/n
bws}"Q0
<%An1Lk
E(Y5"`
65ecOG
3<PiJ:
tE[AU@3
Y_(//nt#
2HH21:Y
t(%hx]
4f.pEs-
-\=\#J
EFlt(:T
"6/kK"
&XmLIwk
1FbPm$
y(SN6"+'
Y@xt7p
@K*IX0
,v>"Y]
/LP/AM
%#!^5]T
) U5`S
,LtgN^
mJxmPL
mf^j6d<
u4Dgd,
.creN%#
v#N$*5(6
H&Ghg)
$M~j7H
LuP%&=6
r1o81\t0
qTTZ|?KQ
qS!M=6 ~fE
cQ{(=P
(wE6 ,!j
T813rR
C57bO)
q+w$^-3
,a?E:eB
.!,jTp
&`$f\P
&@$:\^
Q.EWP;s?
I(9%v[
=S>$b6v
y^jh)|?2
+<(ZP8
AtDXnI
MK^okQt
_)-kb$6
Vca+jx*>jBx
N;nph[P
fN]NL@
mU9tu
7|%Eaj
u-kyR*
~7Y}a+&
1.r{Nq
`K[mKo/
B1sgiQ_JO^
9S?h{=h]CU
4"6hb-h
).ld]O
[mZ"9,
AW`WZh
g5bc]-(
htdu'w
a{Z?B]
'5_ND]
].\?nHYf
O#LQ4=f
,iX5Y&
V}=>x/P6#
gFl}LY
-0 )@%
QI3=[5.%
-ZLxcMmo
P?Rv-5
mfWi5`
eG@%ux
5f;qRW
\f$@SeR
CE5&]
7Q;R+dV
neKXH?S
cXyh/i)
%3l"aA``
Ar,h8]
Hr-]IU
lD_X`X
\eYgbJ
r~'//L
17JIr/p
gVXUaG
nV|$Y1
nYS*x_
:K;nz}Z
6J^LI1
^#l0G`b
_>MUN&>y
pL}E^e
*K,X9jd
_o&T\=
S"{[$F
NAB !1
*Kb(wc
&hd#KPfe
+ZM})B
cszd@5E!lT
7^sjK(%
RrQ{{=
RtIJ|>
lz'%2!1]V
+uOnc
}d.gp{
hC_A/
@kZrmhR6
f?Y5TEtZ
f^*vW:o
rP{cw8d[
#M5JLC
N(P8 #
] tod=
y~EE^T
u!GZ2w
h]$0/q
8'k/e=
-x=_R5
cs08Ls.
E;9n*l<
Odv{8O
Qd!tr87
}35$C
{NA0LP
w`h:5MU6tq@5upPRqj05uo<?
7biKCdjQ(s\>
|eA5sf<8
Gttqms#Jhkae
Plhcca!Vsumqeij#Cagqwklk!Kkkc
Umqshin`"Ewwtmnrkl"Da`uvto"Vjjiccbw&Tll
130323766g36`2g?33ce34c0da2g1d16
'U{pwglSliv$^W}pugn60Z
Cprvm-`zg
__GLOBAL_HEAP_SELECTED
__MSVCRT_HEAP_SELECT
runtime error
TLOSS error
SING error
DOMAIN error
- unable to initialize heap
- not enough space for lowio initialization
- not enough space for stdio initialization
- pure virtual function call
- not enough space for _onexit/atexit table
- unable to open console device
- unexpected heap error
- unexpected multithread lock error
- not enough space for thread data
abnormal program termination
- not enough space for environment
- not enough space for arguments
- floating point not loaded
Microsoft Visual C++ Runtime Library
Runtime Error!
Program:
<program name unknown>
GetLastActivePopup
GetActiveWindow
MessageBoxA
user32.dll
H:mm:ss
dddd, MMMM dd, yyyy
M/d/yy
December
November
October
September
August
February
January
Saturday
Friday
Thursday
Wednesday
Tuesday
Monday
Sunday
SunMonTueWedThuFriSat
JanFebMarAprMayJunJulAugSepOctNovDec
8t9UW
SS@SSPVSS
t#SSUP
t$$VSS
_^][YY
t.;t$$t(
VC20XC00U
PPPPPPPP
PPPPPPPP
tFGQPS
GetProcAddress
GetModuleHandleA
KERNEL32.dll
GetStartupInfoA
GetCommandLineA
GetVersion
ExitProcess
TerminateProcess
GetCurrentProcess
UnhandledExceptionFilter
GetModuleFileNameA
FreeEnvironmentStringsA
FreeEnvironmentStringsW
WideCharToMultiByte
GetEnvironmentStrings
GetEnvironmentStringsW
SetHandleCount
GetStdHandle
GetFileType
GetCurrentThreadId
TlsSetValue
TlsAlloc
SetLastError
TlsGetValue
GetLastError
GetEnvironmentVariableA
GetVersionExA
HeapDestroy
HeapCreate
VirtualFree
HeapFree
RtlUnwind
WriteFile
InitializeCriticalSection
EnterCriticalSection
LeaveCriticalSection
GetCPInfo
GetACP
GetOEMCP
HeapAlloc
VirtualAlloc
HeapReAlloc
LoadLibraryA
MultiByteToWideChar
LCMapStringA
LCMapStringW
GetStringTypeA
GetStringTypeW
InterlockedDecrement
InterlockedIncrement
Install.exe
Loader
<?xml version='1.0' encoding='UTF-8' standalone='yes'?>
<assembly xmlns='urn:schemas-microsoft-com:asm.v1' manifestVersion='1.0'>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v3">
<security>
<requestedPrivileges>
<requestedExecutionLevel level='requireAdministrator' uiAccess='false' />
</requestedPrivileges>
</security>
</trustInfo>
<dependency>
<dependentAssembly>
<assemblyIdentity type='win32' name='Microsoft.Windows.Common-Controls' version='6.0.0.0' processorArchitecture='x86' publicKeyToken='6595b64144ccf1df' language='*' />
</dependentAssembly>
</dependency>
</assembly>
((((( H
Antivirus Signature
Bkav W32.AIDetectMalware
Lionic Trojan.Win32.Generic.lbym
Elastic malicious (high confidence)
ClamAV Win.Trojan.Farfli-7639977-0
CMC Clean
CAT-QuickHeal Trojan.ZRI.S12023332
Skyhigh BehavesLike.Win32.Generic.fc
ALYac Dump:Generic.KillMBR.A.3821C283
Cylance Unsafe
Zillya Trojan.Farfli.Win32.34496
Sangfor Backdoor.Win32.Farfli.V78s
CrowdStrike win/malicious_confidence_100% (D)
Alibaba Backdoor:Win32/Farfli.effa9c6f
K7GW Trojan ( 005800661 )
K7AntiVirus Trojan ( 005800661 )
huorong Backdoor/Farfli.cq
Baidu Clean
VirIT Trojan.Win32.Rootkit.BGPI
Paloalto generic.ml
Symantec ML.Attribute.HighConfidence
tehtris Clean
ESET-NOD32 a variant of Win32/Farfli.DBU
APEX Malicious
Avast Win32:BackdoorX-gen [Trj]
Cynet Malicious (score: 100)
Kaspersky HEUR:Trojan.Win32.Generic
BitDefender Dump:Generic.KillMBR.A.3821C283
NANO-Antivirus Trojan.Win32.Farfli.henrej
ViRobot Clean
MicroWorld-eScan Dump:Generic.KillMBR.A.3821C283
Tencent Malware.Win32.Gencirc.10bf8571
Sophos Troj/Farfli-EB
F-Secure Trojan.TR/Dropper.Gen
DrWeb Trojan.Rootkit.22030
VIPRE Dump:Generic.KillMBR.A.3821C283
TrendMicro TROJ_GEN.R002C0DHB24
McAfeeD ti!1D83BDBA4198
Trapmine Clean
CTX exe.trojan.farfli
Emsisoft Dump:Generic.KillMBR.A.3821C283 (B)
Ikarus Trojan.Win32.Krypt
FireEye Generic.mg.d2b9d12a630cf96b
Jiangmin Backdoor.Farfli.dmf
Webroot W32.Trojan.Gen
Varist W32/Farfli.GY.gen!Eldorado
Avira TR/Dropper.Gen
Fortinet W32/GenKryptik.DJUZ!tr
Antiy-AVL Trojan/Win32.Farfli.ctt
Kingsoft Win32.Hack.Convagent.gen
Gridinsoft Clean
Xcitium Clean
Arcabit Dump:Generic.KillMBR.A.3821C283
SUPERAntiSpyware Clean
ZoneAlarm HEUR:Backdoor.Win32.Convagent.gen
Microsoft Backdoor:Win32/Farfli.BF!MTB
Google Detected
AhnLab-V3 Downloader/Win.WQ.C5657779
Acronis Clean
McAfee GenericRXKB-WQ!D2B9D12A630C
TACHYON Clean
VBA32 Trojan.Rootkit
Malwarebytes Generic.Malware.AI.DDS
Panda Trj/Genetic.gen
Zoner Clean
TrendMicro-HouseCall TROJ_GEN.R002C0DHB24
Rising Backdoor.Farfli!1.E02F (CLASSIC)
Yandex Clean
SentinelOne Static AI - Suspicious PE
MaxSecure Trojan.Malware.110133250.susgen
GData Dump:Generic.KillMBR.A.3821C283
AVG Win32:BackdoorX-gen [Trj]
DeepInstinct MALICIOUS
alibabacloud Clean
No IRMA results available.