Static | ZeroBOX

PE Compile Time

2021-12-29 21:00:07

PE Imphash

19d4e66d725c89ba6712b82bebc8196d

PEiD Signatures

Armadillo v1.71

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.data 0x00001000 0x0006afce 0x0006b000 7.7908036951
.rsrc 0x0006c000 0x0000f638 0x0000f800 3.50428128896

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x0007af18 0x00000468 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED GLS_BINARY_LSB_FIRST
RT_ICON 0x0007af18 0x00000468 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED GLS_BINARY_LSB_FIRST
RT_ICON 0x0007af18 0x00000468 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED GLS_BINARY_LSB_FIRST
RT_GROUP_ICON 0x0007b380 0x00000022 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_GROUP_ICON 0x0007b380 0x00000022 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_MANIFEST 0x0007b3a8 0x0000028b LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED XML 1.0 document text

Imports

Library KERNEL32.dll:
0x401000 GetProcAddress
0x401004 GetModuleHandleA
0x401008 GetStartupInfoA
0x40100c GetCommandLineA
0x401010 GetVersion
0x401014 ExitProcess
0x401018 TerminateProcess
0x40101c GetCurrentProcess
0x401024 GetModuleFileNameA
0x401030 WideCharToMultiByte
0x40103c SetHandleCount
0x401040 GetStdHandle
0x401044 GetFileType
0x401048 GetCurrentThreadId
0x40104c TlsSetValue
0x401050 TlsAlloc
0x401054 SetLastError
0x401058 TlsGetValue
0x40105c GetLastError
0x401064 GetVersionExA
0x401068 HeapDestroy
0x40106c HeapCreate
0x401070 VirtualFree
0x401074 HeapFree
0x401078 RtlUnwind
0x40107c WriteFile
0x40108c GetCPInfo
0x401090 GetACP
0x401094 GetOEMCP
0x401098 HeapAlloc
0x40109c VirtualAlloc
0x4010a0 HeapReAlloc
0x4010a4 LoadLibraryA
0x4010a8 MultiByteToWideChar
0x4010ac LCMapStringA
0x4010b0 LCMapStringW
0x4010b4 GetStringTypeA
0x4010b8 GetStringTypeW

!This program cannot be run in DOS mode.
"n^i$_
P"&\ho
Y!*}c^#M
Ik=Y$t6
btQe*c
YxtO+
[`gwO\
Df]DS]
DTPDZ]
b!`~`Q
`qp0Ds
&QY<ym
&GCgZ&
#L~Ag^{
]L5"agbU&]
])<Mcn
sh*Sij
'y7]n!
q}SCaM2^
(,^?Vx
)JX2~D
m0XM$Td
K=fX/;
N%KqkK
6hsI8>
gJ!rL{
Nt6Hvq%
O2O36V
"[kXG
i.X_)@e
IAX%er
\=tcR%
>ABCA{
6}dGO%
_m2h)(
k0T1Z/
|hp27[.E
..i%165
&%v01z
KF;u+(6
rbK#/
-.W8ug3
SVCSb3
L\c:@5
m#C/E5
%6oR$|1
uGe4"<9-m
_~>?0-
R%@7^Z
A9{812JR9YM
r@d|DDVe
|Jh2Zt
2YU)WOA
**Ddr&
H@#>c(i+
X/VW`5
<d(U0CUo
Ba>N_
`1yHE0
UV}>]2P
f>Y<i0f9
n\:$0(9
QEm=yq+
E@hA>y=]
\.AQHE$
Y/W#dj
;(5-4=
_%[35u<
g,dIY
EHIa]4
,%Acmf
5R7U;g
|=aze}
5i0I9v
U#J21giUxq+
%4fnRoT
$x~Wa=
x6^*/}
%LJ$7f
q)ZNG5
y$}_\a&Y
869I*%q
3Q}8,(K
10\u`1T
]MNfe[
K)oKr>X`
Ecqjya
2XdJ?3
\lt|e6=X
IYAhS"^"h?
Le6=.j
e?RAV.
Zt)B"
7'N5v.U
!E>:'i
pWj&sk
kI5O`:
%\fmhp<-N
],Z[.f
4jl*C}
uo}^1G
9O](iw
^3TE,I
r/DO.^-
O@0A>v
.TVH#+
Nkmx:zR
n}OR !
l9z(fU}
CMPS/T]k\
:nS=A9?
gbr$=,X
N5q$ySh
mNe(V~
!G)NrX1
(m\'*2
_ /8{5u'
8_dA%
%L*Q^)o
t;En(8,w3i
-AO#Zv
*!QH4s
rj`r;;E
;,?W.:
MT6Hnm
B>~^kh
8*)(9bTSn
X*A)5\&w
UfEr*h_4G
@~0X^N
KPC+RJ
KE~?i?^
tfYsE7q
b>l_s|
,Qm<W/}PC#(
,be,?XP
y8'b-g{X
0S0 %Jm[_
+J-mu,q
vXg?W5
upl;uw
;M_8!LF
Mh5&odl
VL36n)IC,
(HP,i0)RO
nW]1U
/(0,=Ds
uau64T`
LFC]=?k
e-W)I8
FUyQ@a
<Q8OfA
O^#}0PE
HQB DG-
w=?z5%
eA(aCp^Z
na5S~9
t,B{}S
m@.dXB
Z@@ov
E0sWhJ
NZGTjM
gTbg=t
zxs%@Ot
`c+{&J
o>46oAj&
%{N[\
+@iix1Tz(,[
G`3(uS9
Pl@;7F
$nk@uJ
<_!k}K
y6$!XM
Kff&4Y
wkCC"pn
j0nY}Z}d
fhL|ja3'
`fD|^M
k,,+)X
\uCc{T
5Uh[&+dT+
3`.'K;C
K:-"{=A
DQ17[*o
r/)"`k
6izQI[0
#%sNjH
:8GJ9(G
Hu?0[<
|mQA;R\"
It+*;}G
1{@.]
w`Z>,
5[|mPi
_jO4~%
Hn$"E7Y
|B D\<s
n.{^msL%nJ
0n}l^
aT*{/
(K"jQJ
Q5piz
d?n@O^
Y'ya2N
,1a).U
/C9:\)
5)t{f
I%7h*{
Q8 zO)H
zGVQLcg
/L_GMQS
pM$adhO
bD=.OSJ
OReD[%
[\$[XJ4
'om_U>
\D)W`+TotQ
1"(F3Cm
<$,e}(
$Hs%Ze
!^%r#B^
BnVnbN
7>)0e
6cE)+`
hf`4y'
v8lY,B
8G~9!
?+eRPg1L
\}*.wT
p'V,6V
;&>E9d
k,c%X$
-uH'hq
*&J^OyT
M1@*T1=~
bn!y-O
<OXJGhOI
qVOGr%
1>"f'~A
1%' ?q
k- 1R
<cL7o*
-bx)JvH
{H% N(P
@5PLdO!
D@ICXH]
LsBe0I
t"s`e?
.sMKRI
x|u_^E
dI#$H3i
9:v's%
3H*iM|W
*I&\Lm
>9qVZ {}
RClnF4
00h"RP
yFI/* %
`Ay5q
ROE[U
E[gdL~
j/_1inp
mQ,#g!
[m<_~O
EK\0:A
.$]MfP
"2imB
Je|,OF
]9w-KE`
f3sy/h
IylFLb
Os 5@3!C( E
9|'<YN
S"#+4:
h%:ri9e
}e*w:a*
Aw(3ht
B"sE'4
}N 6Xi
V>A?C9
r(D?>A
5llw|R
KGX3Q-7i
l.Ag}a
nD@J@?
pgIt#*
75(}lt]_
FttG+N
8o-]j^tC>
~}5<{*
_^S!nZ
sx1_s`
e@0%+N
Pg/"(7|
e3Mhzg
,Y?4#0
[0_XT7,
@`JAa}
"d*uG7
1(6f"_#E>:u
aM6h6dW
cDtv.u
JN(TuA
.ql2DT
r#Q}PD
"k4^6+c]L
i"h*Iu*s
" OC\!
*Q#$D<
]44?ld
!Z_)L
Ne/XD"
^c%n~,d
x`(?+W
!T7`Mx
=L>NDO
TP4>J3v
rW^xxi
oIH^7w
@-J&Vd
EzFe#)
OU%Q"M
J$d7rw
!=Y:1M
e>egt=p=
cxE\Kl
!~'Kh
}rkNIs
Y'Y84V=
e^%7j3
NAtJ,w
6Tb4u~V
4:{^Pl
nh$iFh*5+
.m h%)&U
}+|=}k
9$MRBW
_'Pnso
?^QhOQr
D@h_%G,
o/b\`.&
4'E5>trJ
7Pj2)\
hv$Y^6K
W#otKm
Cb\yq.
_%Q4]!s
[_N#YaB-A
@$$kjn
rq<m6G
iv>#o>
|+dU%W
I8]vT8
g4KK\X&
R13/@R
0?A_x
mfAE-k
wi7b"{
C^]*#\V
?}(]b<
UE_hxCTA
S)^@xz
u?PZn\
,P6WAq
!NS/^-d4<Pz
_Y,5q8
Nys)9J
,U}a\v
`NI!=*
"vjb7k'
QV}%QK
4VEUa#vB
Z?Rc@rY
nOt0=)Ld
iD* v l
]o".a
U(.P-@
J D0ir
'Ua/(j
r?_M9JZ
/4d?')oP9
SgB t)
oedISdB
SQ'zOnwq"
SUBZ_
FYC\~H%
N#+!F
}`;Y|*
<L'79:
v8{\Z\
/J%mVh
{X~~XG
JX]{Hi
-(A)2A
3,*UjTh+
IZ'O!1
8%7N5c
d E)T>
ab1Ky<
Kd(}F&
!N;bs@B
?|oH,9
>q2OMZ
^3[]J
"_Bg7xc
FA7uvW
SbnCUG
Wi~G}[
s^b t!w6
j4@(O*
#]37Lz
?W:pES
xDrNR(
3UL^fx
^[q|-?
|&(4PQ
h0\?F"
dY2:5,
@-I2diXS
|r.Ej!
{p@9TH
xy<Xq`
&(_I/[
b9,>?
BxExio
hOM,Qq
XFH<tG
Y_k7LK
+L58%ix
C-!/1Z
8]wQa0
?>CQ1I
@?ZI!>(
ziCFV!
HO3:gYfP
9S7p.xr
j(Z={n
wl*}Nh
2m{"?"6
OD6uz;
Nq]0}&
NIMKCVgf
b}2RR)
U<s^Hg.j0
E[$F?m
E58KVvG
3=Iy"6
TUYF)"
YtP/k[=
3$4DId
y-Npp2
5<l^>
m;]R.)
3\6n^OV
6XANlA
j?udJ7I
Q1/luO
^_#0K\
xRsc>.
dh?Bgv
Z>=4'I
Lup TH
UBQ&+,
uXU`8}
|0)W!w
'e"dm[
-GR5=h`?"s
u4-EXJF
sY_Fg|
N&A:u4
U`Gki}
i$e^jOV
&$D#1=
x{XmHFO
rOwSk`
y6 PN'
T{NZbZy]
JuD69?J5S
(TlV/f@
5m.wW/
FNdh0}\
Gg1nkV
E[ph&y
IN&V?Bd
\n#G88?
A$!`NK
?|.iwl
[mXvcx
F1}LZPe
2IEMX4r
=DlG_
%l8Sc`
~eM9NAk
k,w-5t
P5t-f8
oLQ|&q
YO:1->T
^9x_[$
p#r!PY
Y|"7J]ym
NE1 ioLH
9wr:%I
F*A95IN
Q`bv>o
b";nL;
T/ZW9x
LnsBWb<1
!^j/Ly`
"U+[Kc
O_A&/{
[U'p5=\b
_;.!}ZwR0%
/ "^1D
LuQ!%>
y3?nAN
S=9]0/
A"Q$6B
KAFJ0&
S}'Zc/
qB+Df2
ngJ~yU
xO1=\\
TUj8,h
4\Q~2/=o)
a#'Li
cTx}]>
V-XoA6X((
GieG#O85
=*Bn4}d
&=Zv(V
x3W!U8
z%}|DP
lw[N9=
[E;)K]j
/&~L\`G
C4AB.
HJst,J
),0VIM
LgkmCM
9n|19]V
9<l2J3
hPO^".
NR\n;6
j:6v#)
6b^H'k
f~pU":
uN3:ge
(-j3yi
HY7MR"
n1 I6
u;PHY/
|R8Fr*@
LB)Qr*@/[
2/?V(2
2[K"T2
2GW>@2
*2Eh9j
u;NU1@
^JT=v\n
&a;>kz^
geeYAM
AC._P&
%T2tC<
?E.U%?E
nm=]\
o21neR|
Q1`t9=
M#'Wlm
61"9n>%E4S
]-!NwN
6#B)<n
QJ,B^e
^E5Dq\
}4\|>d-
*c/YIU
$FBqbu
4mn2`&}
_bx,jk
e1+(H&
oYwWPf(
yIhned
Ffq|f7
{Hr*B@
FMd0Gt
|f{K`
~!}*v)
9M.y`Gn
_y;w)8
7bo5^;
n){:njV
PH)/\`&U
og5Jpx
rg)cv,
H<7lZN
/)x^SW
FtZ;+B4
&4__^5
?v^#4t
nJ%ivE
RF9utA
RV-a|}
vM@!P
N?H|%V0
GxZl9>
e61:Mp=
v6&q5>1
ue&c%L
sk6|U~
*6e;_-=
=ZH#[=
=FT?G=
5'4\%4
2ZH#[2
2FT?G2
09*B;3
l9*B;o
@9*B;C
T9*B;W
&a2yX-
$\(xLQ
WC(Q1@
v_*0OQs
Z #j;:
icILvz
U;(:Uj
u;FN3^
(}YS`@
`z5}}>
2,R;JX
LAu3hSz
Ez `<{
t#kSmAN
}HH-?9x
w*7JYB*
$"J,#yoW2
r$= BKo
6dcnv#
mHe^#(T?
1Akr_4
,VyB9
*`(#``
JS8~_@
>k-'i)
\h:x|
-(gF++w
$XmNIu`
TSTxHWa
1O{<{E
`o>Bd'
5e[iNy
X 00 }
DE}:5W
B|a5do
D\0d3m
oAK:rp7
mNtgL,}
?*e~ak
[JzD6}
*\qx^q
8G<C74d
#)YD*_
N&n\p;
GF@\t,
9x|If2.
\x-0W:
sS#M=4 |fE
cS{(?P
*wG6 .!h
T:13pR"
A55bO+
q)w$\-1
,a=E8e@
,!.jTr
$`&f\R
$@&:\\
Q,EWR;q?
sL#)9a
I*9%t[
=S<$`6v
_zxop}n~
y\jj)|=2
)<*ZP:
CtFXnK
OK^mkSt
_)/k`(6
jz*<jBz>
H:1W M
,f.i~;5,
H~|s`@v(S
$+2|'Eah
7[}a){%
;G{.")
Z%N2}<
p{IN)9
,z!MYz
{UUP`=v_
Lb,*L{
!ZP-NN
p>}%;]o_
vmB7n>o
ToAI!
bH*aRg
>YkE%21
-/?O[C
}V'Qe,
c:9mdGl7&
jLa$QE
w+6%tzL
zE;uIY
I.|~LZq)
(^oMFg
_2!;0R
z0Vr^fA
#"}\{LH
6;*E(&
yz?9a8s
=XLh5L3
s,GNVQ
24(0DB
`I0D*~
t9XOa[
Y![T-|h
n*=)Ce
p:}45Y
RMQ4?y
HeqGC=
x@sw#u
YELD5H
ric@R"
^9M~R"
+z07Vm
!@UE3;QS
y&6}L1
O }~~1O
V=4|nFx
Yi3-Hy
n$&l)n
U#(-&l'
Z@EgC+
PC+R-R
o?S6v"TvD#
`G"%Y;:
S]1E,aO#
*;f,L1
TQnzWI
y#yxF5EkA
&a<1qmfX
dYfeKeg{
F@?L&%
3>cx^uB
Ahl=q=
.%,j<Eh
7A~rYa
M4%nQA^
cqk}l{
Fj93I5u
9jxiZ(
1WQU"s
_P]ta}
1(wQ</^w
"D:zxBJ
&(%+w
chuanqi.ydns.eu
Default
Jbrjar Kbskb
Gwogwo Hxpgxpgx Qhyphyph Aqiy
Meumeumd Vnevnevme Wnfwnfv Ogwogwof Xpg
57e0601129a0a4605c89caf9e311e3f5
C:\\Program Files\\
Jbrja.exe
__GLOBAL_HEAP_SELECTED
__MSVCRT_HEAP_SELECT
runtime error
TLOSS error
SING error
DOMAIN error
- unable to initialize heap
- not enough space for lowio initialization
- not enough space for stdio initialization
- pure virtual function call
- not enough space for _onexit/atexit table
- unable to open console device
- unexpected heap error
- unexpected multithread lock error
- not enough space for thread data
abnormal program termination
- not enough space for environment
- not enough space for arguments
- floating point not loaded
Microsoft Visual C++ Runtime Library
Runtime Error!
Program:
<program name unknown>
GetLastActivePopup
GetActiveWindow
MessageBoxA
user32.dll
H:mm:ss
dddd, MMMM dd, yyyy
M/d/yy
December
November
October
September
August
February
January
Saturday
Friday
Thursday
Wednesday
Tuesday
Monday
Sunday
SunMonTueWedThuFriSat
JanFebMarAprMayJunJulAugSepOctNovDec
8t9UW
SS@SSPVSS
t#SSUP
t$$VSS
_^][YY
t.;t$$t(
VC20XC00U
0B=x<F
VWuBh gF
[Sh0gF
"WWSh,gF
^Vh0gF
PVh,gF
PPPPPPPP
PPPPPPPP
tFGQPS
^}%95(`F
GetProcAddress
GetModuleHandleA
KERNEL32.dll
GetStartupInfoA
GetCommandLineA
GetVersion
ExitProcess
TerminateProcess
GetCurrentProcess
UnhandledExceptionFilter
GetModuleFileNameA
FreeEnvironmentStringsA
FreeEnvironmentStringsW
WideCharToMultiByte
GetEnvironmentStrings
GetEnvironmentStringsW
SetHandleCount
GetStdHandle
GetFileType
GetCurrentThreadId
TlsSetValue
TlsAlloc
SetLastError
TlsGetValue
GetLastError
GetEnvironmentVariableA
GetVersionExA
HeapDestroy
HeapCreate
VirtualFree
HeapFree
RtlUnwind
WriteFile
InitializeCriticalSection
EnterCriticalSection
LeaveCriticalSection
GetCPInfo
GetACP
GetOEMCP
HeapAlloc
VirtualAlloc
HeapReAlloc
LoadLibraryA
MultiByteToWideChar
LCMapStringA
LCMapStringW
GetStringTypeA
GetStringTypeW
InterlockedDecrement
InterlockedIncrement
<?xml version='1.0' encoding='UTF-8' standalone='yes'?>
<assembly xmlns='urn:schemas-microsoft-com:asm.v1' manifestVersion='1.0'>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v3">
<security>
<requestedPrivileges>
<requestedExecutionLevel level='requireAdministrator' uiAccess='false' />
</requestedPrivileges>
</security>
</trustInfo>
<dependency>
<dependentAssembly>
<assemblyIdentity type='win32' name='Microsoft.Windows.Common-Controls' version='6.0.0.0' processorArchitecture='x86' publicKeyToken='6595b64144ccf1df' language='*' />
</dependentAssembly>
</dependency>
</assembly>
((((( H
Antivirus Signature
Bkav W32.AIDetectMalware
Lionic Clean
Elastic malicious (high confidence)
MicroWorld-eScan Dump:Generic.KillMBR.A.BFFADF29
CTX exe.unknown.dump
CAT-QuickHeal Backdoor.GenericRI.S22015472
Skyhigh BehavesLike.Win32.FakeAVSecurityTool.gc
ALYac Dump:Generic.KillMBR.A.BFFADF29
Cylance Unsafe
Zillya Trojan.Farfli.Win32.40702
Sangfor Suspicious.Win32.Save.ins
CrowdStrike win/malicious_confidence_100% (W)
BitDefender Dump:Generic.KillMBR.A.BFFADF29
K7GW Trojan ( 0055d49e1 )
K7AntiVirus Trojan ( 0055d49e1 )
huorong Backdoor/Farfli.bq
Baidu Clean
VirIT Trojan.Win32.Genus.XLY
Symantec ML.Attribute.HighConfidence
tehtris Clean
ESET-NOD32 a variant of Win32/Farfli.DBU
APEX Malicious
Paloalto Clean
Cynet Malicious (score: 100)
Kaspersky Backdoor.Win32.Farfli.byde
Alibaba Backdoor:Win32/Farfli.0e50a659
NANO-Antivirus Trojan.Win32.Farfli.joxpfl
ViRobot Clean
Tencent Malware.Win32.Gencirc.10bd087c
Sophos Mal/Generic-S
F-Secure Trojan.TR/Crypt.XPACK.Gen
DrWeb BackDoor.Farfli.147
VIPRE Dump:Generic.KillMBR.A.BFFADF29
McAfeeD Real Protect-LS!A40E4A8AAF47
Trapmine malicious.high.ml.score
CMC Clean
Emsisoft Dump:Generic.KillMBR.A.BFFADF29 (B)
Ikarus Trojan.Win32.Hrup
FireEye Generic.mg.a40e4a8aaf476b3d
Jiangmin Backdoor.Generic.cknp
Webroot Win.Trojan.Farfli
Varist Clean
Avira TR/Crypt.XPACK.Gen
Fortinet W32/GenKryptik.DJUZ!tr
Antiy-AVL Trojan/Win32.Farfli
Kingsoft Win32.Hack.Generic.a
Gridinsoft Clean
Xcitium Clean
Arcabit Dump:Generic.KillMBR.A.BFFADF29
SUPERAntiSpyware Clean
Microsoft Backdoor:Win32/Farfli!pz
Google Detected
AhnLab-V3 Trojan/Win.Farfli.C4702709
Acronis Clean
McAfee GenericRXRR-WJ!A40E4A8AAF47
TACHYON Clean
VBA32 BScope.Backdoor.Farfli
Malwarebytes MachineLearning/Anomalous.97%
Panda Trj/Genetic.gen
Zoner Clean
TrendMicro-HouseCall Clean
Rising Backdoor.Farfli!1.E02F (CLASSIC)
Yandex Clean
SentinelOne Static AI - Malicious PE
MaxSecure Clean
GData Dump:Generic.KillMBR.A.BFFADF29
DeepInstinct MALICIOUS
alibabacloud Trojan:Win/Dropper.D
No IRMA results available.