Static | ZeroBOX

PE Compile Time

2017-05-25 21:08:41

PE Imphash

ef39d474ee88b9215814d74ee695b02b

PEiD Signatures

Armadillo v1.71

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x000045f7 0x00005000 6.17075839608
.rdata 0x00006000 0x00000802 0x00001000 3.26885876983
.data 0x00007000 0x00056240 0x00056000 7.93899555126
.rsrc 0x0005e000 0x000029b8 0x00003000 3.61075856072

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x0005e100 0x000025a8 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_GROUP_ICON 0x000606a8 0x00000014 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_VERSION 0x000606c0 0x000002f8 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data

Imports

Library KERNEL32.dll:
0x406000 HeapAlloc
0x406004 GetProcessHeap
0x406008 VirtualAlloc
0x40600c VirtualProtect
0x406010 VirtualFree
0x406014 GetProcAddress
0x406018 LoadLibraryA
0x40601c IsBadReadPtr
0x406020 HeapFree
0x406024 FreeLibrary
0x406028 HeapReAlloc
0x40602c GetModuleHandleA
0x406030 GetStartupInfoA
0x406034 GetCommandLineA
0x406038 GetVersion
0x40603c ExitProcess
0x406040 GetModuleFileNameA
0x406048 GetVersionExA
0x40604c HeapDestroy
0x406050 HeapCreate
0x406054 TerminateProcess
0x406058 GetCurrentProcess
0x406068 WideCharToMultiByte
0x406074 SetHandleCount
0x406078 GetStdHandle
0x40607c GetFileType
0x406080 RtlUnwind
0x406084 WriteFile
0x406088 GetCPInfo
0x40608c GetACP
0x406090 GetOEMCP
0x406094 MultiByteToWideChar
0x406098 LCMapStringA
0x40609c LCMapStringW
0x4060a0 GetStringTypeA
0x4060a4 GetStringTypeW

!This program cannot be run in DOS mode.
`.rdata
@.data
@UVWP
YYh p@
8t9UW
SS@SSPVSS
t#SSUP
t$$VSS
_^][YY
DSUVWh
t.;t$$t(
VC20XC00U
__GLOBAL_HEAP_SELECTED
__MSVCRT_HEAP_SELECT
runtime error
TLOSS error
SING error
DOMAIN error
- unable to initialize heap
- not enough space for lowio initialization
- not enough space for stdio initialization
- pure virtual function call
- not enough space for _onexit/atexit table
- unable to open console device
- unexpected heap error
- unexpected multithread lock error
- not enough space for thread data
abnormal program termination
- not enough space for environment
- not enough space for arguments
- floating point not loaded
Microsoft Visual C++ Runtime Library
Runtime Error!
Program:
<program name unknown>
GetLastActivePopup
GetActiveWindow
MessageBoxA
user32.dll
HeapAlloc
GetProcessHeap
VirtualAlloc
VirtualProtect
VirtualFree
GetProcAddress
LoadLibraryA
IsBadReadPtr
HeapFree
FreeLibrary
KERNEL32.dll
HeapReAlloc
GetModuleHandleA
GetStartupInfoA
GetCommandLineA
GetVersion
ExitProcess
GetModuleFileNameA
GetEnvironmentVariableA
GetVersionExA
HeapDestroy
HeapCreate
TerminateProcess
GetCurrentProcess
UnhandledExceptionFilter
FreeEnvironmentStringsA
FreeEnvironmentStringsW
WideCharToMultiByte
GetEnvironmentStrings
GetEnvironmentStringsW
SetHandleCount
GetStdHandle
GetFileType
RtlUnwind
WriteFile
GetCPInfo
GetACP
GetOEMCP
MultiByteToWideChar
LCMapStringA
LCMapStringW
GetStringTypeA
GetStringTypeW
Mboyb+
_.t]cDm
3"-P:Hp
Gy?X1.
j7)%@K
5lpKOf
GD%;1Yj
TG>Zic
8$2DZ?
Od9IM~
?Zg486J
C7P9qb
KPj!;NY}X
@_QMi6*
gsxc%C
#?GUvo
h~Y1!G
rOW j$
Pwxap1
bsR\@<
3UQ:@w?
T@fm%j
R4YcdN
ubZyb`
U0%^k;
/ R)7|`z`
JO(9VD
ZF.-;)
(Tc>R+
E{<U]v
j~xc|,V
.YO]Wo%&X
r)._~w
Mi6w-x
HS5dTU
h5P6cg
d7WX`\r{
-cB-QG
,_{r<w]fG
}hq-IL
uv`<10
D9h-['3R
_%y44m
?y7RaH
PB]2AU
ng?1Kw
t`Q%U
5:~Kkd
K.InbB
N.tJZP
c}78v
]t0<>O14W*-
;qa0f *
X}*2C?,
y3 2_x
rhT9twb
)y"^Da
O9T5eVY[
o8F:G.;
g-0&ks
k:Ez@FT
+6([3\
~N{j#y
SL!&@\
O51i*-
!B gK%`T8#
\~J5TN
?C%OD6NE
MwF?uh
u YY3LX
JL/4%5
z8ZYfC;b4c
d o0x0/
avq .m|
c5O!l/.
A;*W*l-
s{Q{Y+
4wN|Pp
K`2U<Lh
j^sRn^
2=lHf|c
x[]6Mf
`0hnku\
nB,%#V>p,
}2r,w?R
8uV-'-
fq?e'@_
;+T{QD
OU>,"g
D- pp/
dBG wS
0ztcJy
(;oXdkK
]$}?C]M+
*?p t<
e^f>mK
9bv.M4
w9#;@U
bB&^^o
hO(U%i
z|k`p
*3Hq0|
/W68yv
HyjF\ma
U6,KU=
#`h_-{
0Or}F>
#nTbY8
}Ur=Q%
5% l0D
>`AQ[YT(
T4,u810\
e$1.E3v
!^VicH:esE
`e+{Va
CkG#I%
0xb- h$
M1y5=-
p2l%Hc
]/l[k1
>\$g<H
~UKwgk(
whcs8r
ts'TU
E8{C'.
ZfI7r`
T3>HV!
=XGoR(
/4Btx#
POk-NI
am-wfil
GG.NL+
+U9A3R_*
f=:P/yla.
@/ca\#KL
!F3[v|
(B(mz
*9[Y:R"
d\_klU
,O#NKP
5U|;=
q9o0}D
sr1Uc$.
BfU0tD
.2M=DH>
7p4Lnae
h.)?a
P3496VQgK
@t^'q7
OSzz3W
"q`D+]{
a,H0Dl
yQCriQco
/Ua9Jk
+^ATci
oJ32#*)Z
9a79#%
x~i(4-
0Kzw gNM
"jJ*>M
N_qZ7Ud
AGL!l3
Jh{<i#
nD*eB&
9zlC>e
tV}bh!
Y@L&/O
Swsq8f
c*8jZatS6
jljW\q
,A(NoyT
b/qDXV
'/!Dz~$@o
b5=40/
;dLm>r
G/zri_FUE"
sqEe(r
)3 c(g
e&,thlW'
,Be`#)
RM7rMj0
u?)<^j
;,^tOC
;ghSE+
pTJ;-&
!=FH.x
9cC]-6
nX_-LvJ
q1.Mq8
Shpeka`
)^}uj.
03/2#
-Ug.;(
)KdUkq
v)P=n?F!J
TbS>30!
_PR09[
$&f{pK
8,!{Rl
6nDEw^
'd#0k2;]
FR&[`Q
dsi'1}
s:1W2-8
\2{ERY3
73<M@6
c-t~l!Tm
'x42Os
t@UfY9e
_3uYu3
x!X{|+
g9(d/s
Q!&z7h
_@CA;Mm*ooU
PZPA@E
CS5#63
nza[lh
ne62Bz
HoHsy{
\iw.q4
>tRx/:
wy=u$F
G)FJRQ
utGE<Hz
g[3f Y
7&@%V\
JcP*K
C=+g$w
r[uW7k&
Q#q-8#:
z=Q(wd
wXA=Q9
U~T1zV
:"BFTK
'FC*$dh#z
q)s(rl
1g!0d2A
G(`Y7E
<&evZrif
Iv-IQR
o-0'1F
NYj-K1
%\wlJ,lZ
{hnXe7
l5-<<mgc
s-mTw*
>`:Yv
-~NWRO6<Jm
bUk4B{
bq?pS
w[Pu0x
q;rsD-
o>"D1K
P@wC==
}1?:^f
;Y2uZ%
y%;=/C
:FHku8
Mpx?yoz
>p4c)4
qlYY[>
mS*lzn
iuP`X`:c
tq4G(#Y
w oBd;
|(v/1z'.
mFT%]*E
;=F?x'
jQX=^L
vH&.V>
i=ta=E
pG5/y\
E-)=I1
}c(vp*
xTu2~F:{
dY<$a+0!t
L\r)Uu
X<P[AW=
jSTj\SI
U~H;$/
cq!yl3
}}uyh].iE
Vy6POE?H
P;4Y[dk
g>*p4L
Xs&Y'%U
e[OE9k&rP
I'74;
"h*&v1
" G6(-
#c$2hp
`1a>|x
W@Vt#I
H*bHw< a
S3Vfp:
[A7_S=
cMr\aZ
5S@UEx
Kq#9b%
k,S).N
VU,E"C
t=hYa]
}_*jU%
dK k)
1ZtW2S
Xyc2&$
Ta=eqQ|m
x$g$]O
e*uo&U
,e~ CZ=
we tZ<
1lE#;|
*a}fq!
YsP{)^
nD8L%$
cZw[n1X5
fL11\Q
`xuO*
1~:&>`&
S"u<V]
nP%8DB"
Ybs|-I=
"&h0Yf0
Y]G}2gB3
NTQnOb
n*q$9E
^Z?^ttv
S3cUcQ
D-%.z1.H
^>b$;p
z&BI,=C
*TA^(U
h2G4ah
U\tb&I
C-!U"&9W.
K58)U)HO!
dRN1oWn*
'j#a.)
#FfiKL@9XB
@_A?v@
Q_:>VF
u_W.<u
XF[f>.
4d=n(`F
zT~Fu0u
u(j/O=
hbe=WG
LgEf]l[
RThlUI
Pk_r-y^
_>@U025
Y~">sA
Z%,K9d!
N&r<)a|E
*P&qRv
;_(zMU
ulAN`^3{
CFX84s
B>!rp
o ~?D0
2flX=m
}!`r"^}Q
j^WUHhy
LT=10@<
=]mCFp
:JFQ^\
Uk6j/y
W/oT.x
)oEHZBB+"j
{G5p-o5
D>I g:o
``u~Jf
I=SRQ,
:OnaJQ
rzJSi4
F*DJmd
1@7?}N
s),Gc6
Wu_MAZ
;&;~/O*
%=&T.8
u|Rh)|
g@"~/
oo\V09
&`?:fl}5
b*^.+
0Y)9)SO
mDxU[=k
fG|9~O
>]:~(t=
d5esK2
&Wj5\9
ll+crh
h_4b06
%wdkq="k
UdF-ct
4?L3C,
*+kZNw
4#Q:]?G%
#oIMso
Xj;O3*1
N"|/vS
o`o+oXt
|.3>1
B>z-:^
V^Z~aZVK
6V6K[8
,?3Vbv
IN;5Q&
^]0om/Q
,}[qP(
UioARQ
jz|<t:WL7q
\-P:]D{q
F7-\2p}
4A:@%w$U
/'u3uv
XS)5ak
(l24K:
UtZ9'!
|w4q,.z
h$I<HE
$m^C3
%;WQYb
^2Bk\O
Sw{R;t
<DGN|#
eypess5
zN}7hV
kd3[N|z
AR_tSD
Efsvyi
n~NsWF#
fHroTsBN
az5H6Z
+jt^Gb
7!i,}>
g6<G_DL
Q!o*Fwo
nm\C=d
WE'"!@
=,6*R*s8;|A.Y
.&f]Ze
>a~84y
[ff-}g
bRjNh5
OlS@Hd
bVa#d)p
"<5=qb
QMlx9M2c
_#;C9N
ga 1!$E
j/mpsZ
JaViFS
J4kvb3|R
sZYCh
}79]h]|
k{m]\E1
!'a5!,
H&'"An
d}Yh9x
id V+7
.~zyjI7D
IaE(ZH
{%Q?P(
P}uim~h
ZZB/\J
+2=)(T
zfYH>}U,
XWHq8^
A=&C-w
X~")8
C8{(kL
P)86gg
zP=tr,
^|L4/I
*+m$sM*,
p7k"CN
lAOyipZY
QuL~R}W
u@VOEb4
V.`<C_
H&T#9Z@
wmr^f
8&o<i
o#-r|)m
bWC3<0yF
Wv~_\"p
cmne/[
Y. VKF
i3-U(i
wxPQ>af
8qE;p;
cf]=#+
$qqr%W
6W`}@GD
XXZ@-0
eU2/s
8s{D--
-=&71X
BGbgrb
;X1ibmK
#{h|A(
dp[.8y
MY-ZR0
X}qX,KQ
\'<WN#q
#OH'GI
G]AqglwE
%<:Aa-
N<=GnFy
P7kV>W
YrDX>DX
=4$ltl
)Pb]jb
nZk_H2
kEd"+g:
edJ=f
)?OVkK
T0rI|#~
\UXCV)z
[J.gqc
HTj\eFjon
^9&PJm
*3vSZU
*`^{dW(
#>@8K(
Ia(/'
oTgUCg
(7X+9;N
aj['+<
ZA$C*c
\|\K[Z3
&R-C)t
(("+/U&
e\u-!<
{@<+@`
849S^|
y\z?[s
tD{Cz+
o~8`'m
AdF%;#
EI}&<I$
e'p-Ng
[{hb:g
`~e#-Y2Fk}
'I5:@i
4,>}5u
H``0-Ml
,T54R:g
([km!n
[Ucz{r0
U.Iv]8
UgEL{y
?.Tl27d
[{SL6x
@yv{Y/_S
Wu3~ h
Ek/]c02
%j_M:kR
g;T3$z
Uc*ZQY
O7tXYx{
$/&p<w
,v S(U{6z:
Bc}nJ4.
Z`m!5)
~K+|)V
&bw8 %
C6J=p5
G#S\8I8
O2yGJ+
%<4Z_?
4D^V4[
zqu}._/Hj
#(!;2YfCX
c"vStV1vD
c9,!TA_
~75oS
)J$OI+
H;F:2y
3*kH.2
dx/Xd=t
O$Tiu1f
V]l@}s
/'r1vJ
]a<3!d
=+ *g~
~a<P>Cw
t2gj+.
rTL,sf
M;O$<fc
|t]bV'I9m_
erU-:z
YYYYYYYYYYYYxfVdy0c2xlsxiP4POxO3nYgO1utUwfwe4WfV2HsUUzNwaSoAcsnS+vNj89bd6LZ3tBomLpt/KIBi5UQWrO64oy0vaS7w7iV8+7gq6tr5Lc/OUyYV8riShrILqA9Y3jghCNN6FAwEZx1MY0cJrsPGIz/26MY7tXD2p73Jq2UfTtbEMHHOh75N3B0/PE0HHry61XYijRQOnDa5H2Cc+9gtUTa+05X1Y9b67w0q4RvmzKEzX4sSdQBpSzneugfBiSlEqOZnU7yyak2nEOhYNsnuY+cnLLUpCxWgHg+zXx0fEuAiaYjUNhFWy3AU2q4ow0Dx3p3I6bUITKzT1DNP3/W2nKNpoJZ3DabT09agAhTntRaNJuNCUsMbAOfyCRV6PNL/gVoI+bEozfh2k1WtExyGs6Fx/LbP0e/OQIvBh+YFUrU+Nhwbw07VDZAJ7Cx8cDatxapBqChLyf0ZPTn8M4I5N/fChCKKcWA=
'''`ppp
tuu____0[[[
999"}}}
WWXy,,,
((((( H
IDI_SERVER
VS_VERSION_INFO
StringFileInfo
080403a8
CompanyName
Labeter 2005-2017
FileDescription
Proteug 10 AppLication
FileVersion
7, 10, 33, 380
InternalName
Server.exe
LegalCopyright
Proteug (C)
OriginalFilename
Server.exe
ProductName
TODO: <
ProductVersion
7, 10, 33, 380
VarFileInfo
Translation
Antivirus Signature
Bkav W32.AIDetectMalware
Lionic Trojan.Win32.Zegost.mxwo
tehtris Clean
ClamAV Clean
CMC Clean
CAT-QuickHeal PUA.MacriRI.S17487091
Skyhigh BehavesLike.Win32.Backdoor.fc
ALYac Trojan.GenericKD.36604148
Cylance unsafe
Zillya Tool.Macri.Win32.1527
Sangfor Suspicious.Win32.Save.ins
K7AntiVirus Riskware ( 0040eff71 )
Alibaba DDoS:Win32/Farfli.f2e0305a
K7GW Riskware ( 0040eff71 )
Cybereason malicious.7abc59
Baidu Clean
VirIT Trojan.Win32.Agent_r.BCR
Paloalto Clean
Symantec ML.Attribute.HighConfidence
Elastic malicious (high confidence)
ESET-NOD32 Win32/Farfli.BGG
APEX Malicious
Avast Win32:CrypterX-gen [Trj]
Cynet Malicious (score: 100)
Kaspersky Trojan-DDoS.Win32.Macri.chj
BitDefender Trojan.GenericKD.36604148
NANO-Antivirus Trojan.Win32.Macri.epixwy
ViRobot Trojan.Win32.U.Banker.400048
MicroWorld-eScan Trojan.GenericKD.36604148
Tencent Malware.Win32.Gencirc.10bdc03f
TACHYON Trojan/W32.Agent.393216.AMO
Sophos Troj/AutoG-FH
F-Secure Trojan.TR/FileCoder.NW
DrWeb BackDoor.Farfli.96
VIPRE Trojan.GenericKD.36604148
TrendMicro BKDR_ZEGOST.SMCK
Trapmine malicious.high.ml.score
FireEye Generic.mg.1af97bb3b7d31c81
Emsisoft Trojan.Farfli (A)
SentinelOne Static AI - Malicious PE
GData Trojan.GenericKD.36604148
Jiangmin TrojanDDoS.Macri.nl
Webroot W32.Trojan.Gen
Varist W32/Deepscan.KFVF-7759
Avira TR/FileCoder.NW
Antiy-AVL Trojan/Win32.Farfli
Kingsoft Win32.Troj.Undef.a
Gridinsoft Trojan.Win32.Keylogger.vl!i
Xcitium TrojWare.Win32.TrojanDownloader.Redosdru.FG@6j5x7c
Arcabit Trojan.Generic.D22E88F4
SUPERAntiSpyware Clean
ZoneAlarm Trojan-DDoS.Win32.Macri.chj
Microsoft Backdoor:Win32/Farfli!pz
Google Detected
AhnLab-V3 Trojan/Win32.Dialer.R23969
Acronis Clean
McAfee BackDoor-FDSP!1AF97BB3B7D3
MAX malware (ai score=85)
VBA32 SScope.Trojan.VTFlooder
Malwarebytes Crypt.Trojan.Malicious.DDS
Panda Trj/CI.A
Zoner Trojan.Win32.60229
TrendMicro-HouseCall BKDR_ZEGOST.SMCK
Rising Trojan.Win32.Lebag.b!0.188BB3 (KTSE)
Yandex Trojan.GenAsa!pd90PKR7MRk
Ikarus Trojan.Win32.Farfli
MaxSecure Trojan.Malware.10992882.susgen
Fortinet W32/Farfli.BGG!tr
BitDefenderTheta AI:Packer.342F6B1E1F
AVG Win32:CrypterX-gen [Trj]
DeepInstinct MALICIOUS
CrowdStrike win/malicious_confidence_100% (W)
No IRMA results available.