Static | ZeroBOX

PE Compile Time

2021-04-15 23:52:31

PE Imphash

6c306e45fa9f977a2f45c8a08df084d5

PEiD Signatures

Armadillo v1.71

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x0000441e 0x00005000 6.10167181385
.rdata 0x00006000 0x000007a0 0x00001000 3.14317650694
.data 0x00007000 0x0001c29c 0x0001c000 6.5818691019

Imports

Library KERNEL32.dll:
0x406000 GetProcAddress
0x406004 LoadLibraryA
0x406008 ExitProcess
0x40600c GetModuleHandleA
0x406010 GetStartupInfoA
0x406014 GetCommandLineA
0x406018 GetVersion
0x40601c TerminateProcess
0x406020 GetCurrentProcess
0x406028 GetModuleFileNameA
0x406034 WideCharToMultiByte
0x406040 SetHandleCount
0x406044 GetStdHandle
0x406048 GetFileType
0x406050 GetVersionExA
0x406054 HeapDestroy
0x406058 HeapCreate
0x40605c VirtualFree
0x406060 HeapFree
0x406064 RtlUnwind
0x406068 WriteFile
0x40606c GetCPInfo
0x406070 GetACP
0x406074 GetOEMCP
0x406078 HeapAlloc
0x40607c VirtualAlloc
0x406080 HeapReAlloc
0x406084 MultiByteToWideChar
0x406088 LCMapStringA
0x40608c LCMapStringW
0x406090 GetStringTypeA
0x406094 GetStringTypeW

!This program cannot be run in DOS mode.
`.rdata
@.data
L$TQPj
T$ _^][
D$4UW3
T$h_][^
YYh p@
8t9UW
SS@SSPVSS
t#SSUP
t$$VSS
_^][YY
DSUVWh
t.;t$$t(
VC20XC00U
Y;5H/B
^;5T+B
6;5P+B
__GLOBAL_HEAP_SELECTED
__MSVCRT_HEAP_SELECT
runtime error
TLOSS error
SING error
DOMAIN error
- unable to initialize heap
- not enough space for lowio initialization
- not enough space for stdio initialization
- pure virtual function call
- not enough space for _onexit/atexit table
- unable to open console device
- unexpected heap error
- unexpected multithread lock error
- not enough space for thread data
abnormal program termination
- not enough space for environment
- not enough space for arguments
- floating point not loaded
Microsoft Visual C++ Runtime Library
Runtime Error!
Program:
<program name unknown>
GetLastActivePopup
GetActiveWindow
MessageBoxA
user32.dll
GetProcAddress
LoadLibraryA
ExitProcess
KERNEL32.dll
GetModuleHandleA
GetStartupInfoA
GetCommandLineA
GetVersion
TerminateProcess
GetCurrentProcess
UnhandledExceptionFilter
GetModuleFileNameA
FreeEnvironmentStringsA
FreeEnvironmentStringsW
WideCharToMultiByte
GetEnvironmentStrings
GetEnvironmentStringsW
SetHandleCount
GetStdHandle
GetFileType
GetEnvironmentVariableA
GetVersionExA
HeapDestroy
HeapCreate
VirtualFree
HeapFree
RtlUnwind
WriteFile
GetCPInfo
GetACP
GetOEMCP
HeapAlloc
VirtualAlloc
HeapReAlloc
MultiByteToWideChar
LCMapStringA
LCMapStringW
GetStringTypeA
GetStringTypeW
))+$'s
))+$'s
))+$'s
.m4..v
+.++m5
+$'s96
s/*+.s
)$$$$$$s
UUUUm5
+$>36;
>36;{}
>36;mu
!.'+mu
9'$$$$
SSSSmuz
'm5f$.q
.m5f.$
SP+muZ
m5N.muR
}m5N.muR
!!+$muZ
SP$mub
m5V.m5F.+++++muZ
m5R.m5B.$$$$$muV
.m5Z.$$$$$mu^
!.m5n.
+m5n+.
m5V.mu
+m5J+.
0)m5Vs
+.++++
+.++++
'm5^+.
'm5j+.
'm5v+.
'm5R+.
'm5F+.
'+++++
s5fs%b
'.m5fmmz
&).+$q5
))+$s1
nnnnnnns:
nnnnnnnnnnns:
q426q4*FSPPPq$
q4>s42s/
nnnnnnnnnnn+$'s
nnnnnn$'s
nnnnnnnnnn+%s
s42s,:
s42s|:m2
q$"qdJ
nnnns:
s3:q;6
s36s;:
nnnnnnns2
nnnnnnnnnnnnnnn)+$s
s46s,&s$
s,*s$>
s,:q46
0s,6s$:u
s$>q46
s,6s$:
nnnnnnnnnnn{
n)+%$s
.s46s,&s$
s,:q46
0s,6s$:
9s46s,&
s$>q46
s,6s$:
nnn)+%$s
nnnnnnnnnnnnnn+$s
nnnnnnnns:
nnnnnnnnnnnns:
nnnnnnnnnnnnnn
nnnnnnnnnnnnnnns*
nnnnnnnnnns:
nnnns:
nnnnnnnnnnnnn+%s
nnnnn{
($qrt"
nnnnnnnnnnnnns:
nnnnnnnnnnnnnnn{
nnnnnnnnnnnnnnns*
nnnnnnnnnnnnn$s
nnnnnnnnn+%s:
nnnnnnnnnnn{
nnnnnnnnnnns:
nnnnnnnnnnnnnn$s
nnnnns:
nnnn$s
nnnnnnnnnnnnnnn
kK+T[J
/ER-|LEl
E*>_z/!&
B+3Km6(
^]q9Cz4
WdU6Bo
,hG 2U
kb<TdS*
5$ Wt/9d
EL|-\{
/f8|*Q
oB6UZi
p{??iH|
2 Gh-f
$W; cT
35(,52
9:$9.1
/259%*
-+$;(*
>>%95>&
+62'9.1
>>)95>&
>>)95>&
>>)95>&
>>)95>&
>>)95>&
>>)85.8:&
>>)9599$
>.8:>
>>)95>.8:98$?
>>)851&
>>)851&
>>)85?9$
>>)85198$
>>)9599$
>>)95>98$
>>!9?9$?
>.8:>
>>)9599$
>>)9599:1>
'1,1,5*
;6(/-5%+5(1,4/
;6(/-5,/:9*9
;6(/-5,/:9*9
;6(/-5,/:9*9
;6(/-5%,3,/'
;6(/-5%,3,/'
;6(/-5%,3,/'
;6(/-5%,3,/'
;6(/-5%,3,/'
;6(/-5%,3,/'
;6(/-5%,3,/'
;6(/-5%,3,/'
;6(/-5%,3,/'
+525;*
69(:'9(5":5+;(1.*1/,"+
"81/+"
$-'9(5
+!+*5-";
+!+*5-";
+/4*'9(5"-
#1,+5(*
#:525*5
#89;3+.9;5
#;259(
#1,+5(*
#:525*5
#89;3+.9;5
#;259(
35(,52
+!+*5-";
+!+*5-";
+!+*5-";
63Hoo3
o:905#
29,;opo
//2o%2
$88,;Foo;:,w7,r4
o(1>%+80123o~o8//0oI2
H%;3r%4%
".6!+1;92:(1$5
69(:'9(5":5+;(1.*1/,"+
;*&/.;
;*&/.;
+!+*5-";
-+$;(*
9:$9.1
+62'9.1
35(,52
9:$9.1
35(,52
9:$9.1
9:$9.1
<1<$<K<
?s?Z?F?
={=r=T=S=I=F=
<t<l<k<[<
?v?`?U?L?E?
=w=h=a=P=I=
<*<v<S<
=&=\=E=@=
<"<f<L<
=;=-='=
=q=k=]=W=I=C=
<k<X<F<
?h?c?Y?P?H?
=y=v=W=
=2=+=&==t=m=h=a=
<X<Q<L<E<
?.?'?"?
?p?i?d?]?
=g=^=V=L=
<<r<j<]<O<
?r?k?T?C?
=y=f=]=Q=N=F=
<w<l<e<L<J<@<
???s?n?B?
=x=s=j=a=C=
<i<c<F<
).&,)&),)%',$!
onmlkji
onmlkji
Gfe]\[ZY
VUTSRQP
Nmlkjihgf
\[ZYXW
TSRQPon
KekjYQLooj
((((( H
Antivirus Signature
Bkav W32.AIDetectMalware
Lionic Trojan.Win32.Glomaru.lXMS
Elastic malicious (high confidence)
ClamAV Win.Trojan.Killmbr-10022828-0
CMC Clean
CAT-QuickHeal Clean
Skyhigh GenericRXTR-OV!200488185D59
McAfee GenericRXTR-OV!200488185D59
Cylance Unsafe
Zillya Backdoor.Generic.Win32.31304
Sangfor Clean
CrowdStrike win/malicious_confidence_100% (W)
Alibaba Backdoor:Win32/Zegost.13a2a26d
K7GW Trojan ( 005a74e61 )
K7AntiVirus Trojan ( 005a74e61 )
huorong Backdoor/Farfli.cn
Baidu Clean
VirIT Trojan.Win32.Genus.RTX
Paloalto generic.ml
Symantec Trojan!im
tehtris Clean
ESET-NOD32 a variant of Win32/FatalRAT.A
APEX Malicious
Avast Win32:GenMalicious-JHS [Trj]
Cynet Malicious (score: 100)
Kaspersky HEUR:Backdoor.Win32.Generic
BitDefender Dump:Generic.KillMBR.A.EA885338
NANO-Antivirus Trojan.Win32.Farfli.itwbcp
ViRobot Clean
MicroWorld-eScan Dump:Generic.KillMBR.A.EA885338
Tencent Trojan.Win32.Fatalrat.ca
Sophos Mal/Generic-S
F-Secure Trojan.TR/Dropper.Gen
DrWeb BackDoor.Fatal.67
VIPRE Dump:Generic.KillMBR.A.EA885338
TrendMicro Clean
McAfeeD ti!1722BE3CA7C3
Trapmine malicious.high.ml.score
CTX exe.trojan.generic
Emsisoft Dump:Generic.KillMBR.A.EA885338 (B)
Ikarus Trojan.Win32.Farfli
FireEye Generic.mg.200488185d59ab37
Jiangmin Backdoor.Generic.ckgk
Webroot Clean
Varist W32/Agent.EWL.gen!Eldorado
Avira TR/Dropper.Gen
Fortinet W32/GenKryptik.BJAB!tr
Antiy-AVL Trojan[Backdoor]/MSIL.Zegost
Kingsoft malware.kb.a.999
Gridinsoft Trojan.Win32.Gen.tr
Xcitium TrojWare.Win32.Agent.PDSB@4q3i1w
Arcabit Dump:Generic.KillMBR.A.EADD825A
SUPERAntiSpyware Clean
ZoneAlarm HEUR:Trojan.Win32.Agent.gen
Microsoft Backdoor:MSIL/Zegost.GG!MTB
Google Detected
AhnLab-V3 Trojan/Win.LVbg.R553633
Acronis Clean
VBA32 BScope.Backdoor.Farfli
TACHYON Clean
Malwarebytes Generic.Malware.AI.DDS
Panda Trj/CI.A
Zoner Clean
TrendMicro-HouseCall Clean
Rising Trojan.Kryptik!1.AAD1 (CLASSIC)
Yandex Worm.AutoRun!Nq5f4FOwmYc
SentinelOne Static AI - Suspicious PE
MaxSecure Trojan.Malware.7175197.susgen
GData Dump:Generic.KillMBR.A.EA885338
AVG Win32:GenMalicious-JHS [Trj]
DeepInstinct MALICIOUS
alibabacloud Clean
No IRMA results available.