PE Compile Time

2019-02-21 18:00:00

PE Imphash

da401ef5e9d5c4599673c26d95fa6029

PEiD Signatures

Armadillo v1.71

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x000293f5 0x00029400 6.67671405417
.rdata 0x0002b000 0x00006500 0x00006600 4.42967110263
.data 0x00032000 0x0000453c 0x00000200 3.39004598096
.sxdata 0x00037000 0x00000004 0x00000200 0.0203931352361
.rsrc 0x00038000 0x00002090 0x00002200 3.16079480618

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x00038aa8 0x00000128 LANG_ENGLISH SUBLANG_ENGLISH_US Device independent bitmap graphic, 16 x 32 x 4, image size 192
RT_ICON 0x00038aa8 0x00000128 LANG_ENGLISH SUBLANG_ENGLISH_US Device independent bitmap graphic, 16 x 32 x 4, image size 192
RT_DIALOG 0x00039020 0x00000126 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_DIALOG 0x00039020 0x00000126 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_DIALOG 0x00039020 0x00000126 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_DIALOG 0x00039020 0x00000126 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_STRING 0x00039fa8 0x000000b6 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_STRING 0x00039fa8 0x000000b6 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_STRING 0x00039fa8 0x000000b6 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_STRING 0x00039fa8 0x000000b6 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_STRING 0x00039fa8 0x000000b6 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_STRING 0x00039fa8 0x000000b6 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_STRING 0x00039fa8 0x000000b6 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_STRING 0x00039fa8 0x000000b6 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_STRING 0x00039fa8 0x000000b6 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_STRING 0x00039fa8 0x000000b6 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_STRING 0x00039fa8 0x000000b6 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_STRING 0x00039fa8 0x000000b6 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_STRING 0x00039fa8 0x000000b6 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_STRING 0x00039fa8 0x000000b6 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_STRING 0x00039fa8 0x000000b6 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_STRING 0x00039fa8 0x000000b6 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_GROUP_ICON 0x00038bd0 0x00000022 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_VERSION 0x00038510 0x000002b0 LANG_ENGLISH SUBLANG_ENGLISH_US data

Imports

Library OLEAUT32.dll:
0x42b16c SysFreeString
0x42b170 SysAllocStringLen
0x42b174 SysAllocString
0x42b178 VariantClear
0x42b17c SysStringLen
Library ole32.dll:
0x42b220 CoCreateInstance
0x42b224 CoInitialize
0x42b228 CoUninitialize
0x42b22c OleInitialize
Library USER32.dll:
0x42b198 CheckDlgButton
0x42b19c IsDlgButtonChecked
0x42b1a0 EndDialog
0x42b1a4 SetDlgItemTextW
0x42b1a8 GetFocus
0x42b1ac SetFocus
0x42b1b0 GetKeyState
0x42b1b4 InvalidateRect
0x42b1b8 SetWindowTextW
0x42b1bc EnableWindow
0x42b1c0 PostMessageW
0x42b1c4 MessageBoxW
0x42b1c8 SetTimer
0x42b1cc DialogBoxParamW
0x42b1d0 SetWindowLongW
0x42b1d4 GetWindowLongW
0x42b1d8 ShowWindow
0x42b1dc MoveWindow
0x42b1e0 ScreenToClient
0x42b1e4 GetDlgItem
0x42b1e8 GetWindowRect
0x42b1ec MapDialogRect
0x42b1f8 GetWindowTextW
0x42b1fc SendMessageW
0x42b200 LoadStringW
0x42b204 CharUpperW
0x42b208 LoadIconW
0x42b20c GetParent
0x42b210 SetCursor
0x42b214 LoadCursorW
0x42b218 KillTimer
Library SHELL32.dll:
0x42b188 SHBrowseForFolderW
0x42b18c SHGetFileInfoW
0x42b190 SHGetMalloc
Library MSVCRT.dll:
0x42b0f4 wcsstr
0x42b0f8 wcscmp
0x42b0fc _beginthreadex
0x42b100 _except_handler3
0x42b108 ?terminate@@YAXXZ
0x42b10c __dllonexit
0x42b110 _onexit
0x42b114 _exit
0x42b118 _XcptFilter
0x42b11c exit
0x42b120 _acmdln
0x42b124 __getmainargs
0x42b128 _initterm
0x42b12c __setusermatherr
0x42b130 _adjust_fdiv
0x42b134 __p__commode
0x42b138 __p__fmode
0x42b13c __set_app_type
0x42b140 _controlfp
0x42b144 _CxxThrowException
0x42b148 malloc
0x42b14c memcpy
0x42b150 memmove
0x42b154 memset
0x42b158 _purecall
0x42b15c memcmp
0x42b160 __CxxFrameHandler
0x42b164 free
Library KERNEL32.dll:
0x42b000 GetStartupInfoA
0x42b008 ResetEvent
0x42b00c SetEvent
0x42b010 CreateEventW
0x42b014 WaitForSingleObject
0x42b018 lstrlenW
0x42b01c lstrcatW
0x42b020 VirtualFree
0x42b024 VirtualAlloc
0x42b028 SetPriorityClass
0x42b030 Sleep
0x42b044 GetStdHandle
0x42b048 GlobalMemoryStatus
0x42b04c GetSystemInfo
0x42b050 GetCurrentProcess
0x42b060 CompareFileTime
0x42b064 SetEndOfFile
0x42b068 WriteFile
0x42b06c ReadFile
0x42b070 SetFilePointer
0x42b074 GetFileSize
0x42b07c GetFileAttributesW
0x42b080 GetModuleHandleA
0x42b084 FindNextFileW
0x42b088 FindFirstFileW
0x42b08c FindClose
0x42b090 GetTickCount
0x42b098 SetLastError
0x42b09c DeleteFileW
0x42b0a0 CreateDirectoryW
0x42b0a4 GetModuleHandleW
0x42b0a8 MoveFileW
0x42b0ac RemoveDirectoryW
0x42b0b0 SetFileAttributesW
0x42b0b4 CreateFileW
0x42b0b8 SetFileTime
0x42b0bc CloseHandle
0x42b0c0 GetSystemDirectoryW
0x42b0c4 FormatMessageW
0x42b0c8 LocalFree
0x42b0cc GetModuleFileNameW
0x42b0d0 MultiByteToWideChar
0x42b0d4 GetLastError
0x42b0d8 GetVersionExW
0x42b0dc LoadLibraryW
0x42b0e0 GetProcAddress
0x42b0e4 FreeLibrary
0x42b0e8 GetCommandLineW
0x42b0ec LoadLibraryExW

!This program cannot be run in DOS mode.
`.rdata
@.data
.sxdata
PPPPQP
GGCCf;
CCEEf;
8@@AAJu
0@@BBIu
AAFFHu
0@@BBIu
8@@AAJu
@@AAJu
FFAAHu
@@BBIu
AABBHu
t;C@@f
8@@AAJu
8@@AAJu
t/f;T$
6PQRVj
PPRPQPh
^$ ^%
W9^ht\8^E
FH;F u
w|8^(t~;
FD;FLr
FL;FDuW
FP;FXu
FX;FPub
9auTGII;
n`9ntWv
/C;^tr
~`_^[]
u68^yt13
Y8^xtB
HtZHtPHtD
t\IItEIt2IIt!It
8_'tE8]
t?Ht6Ht(HHt
t.Ht%Ht
8_@t-j
wltB=e
t@Nt-NuE
t?Ht5-
j0F[F3
@AAf99u
9^$t$S
taOOt3
u=9l$0
uG9^4tB
rN<@wJ
QSVh@K
N<j QP
A 9q(v
t7Ht#Hu
|$ ;\$
D$,_^]
L$,_^]
T$,_^]
9\$ t<;
HSUVW3
ub9|$ t%
~L;~Tw
~H;~Pw
l$<u(=
u+9n@t19nDt,
L$(+t$,+
/FG;t$8u
;L$dsS
;L$hsI
u,9F,u
D$(;D$
D$(;D$
D$(;D$
D$(;D$
T$,_^]
l$ )l$
D$,_^]
L$,_^]
D$,_^]
L$,_^]
;~Ht0U
^@9~8u
t$49|$(u+
;D$ u`
u69|$Dt*9|$$u*
s49|$Ht.
l$\UWVPQ
9l$Dt]9l$$t
T$htp;
9l$4tm9l$Dt#;
u9kPu
9l$HtD9
29l$ht
9^(t=W
B4;B8t
C8;C4t
D$ ;G@s
\$43H$
DllGetVersion
Error #
FindNextStreamW
FindFirstStreamW
kernel32.dll
:$DATA
PhysicalDrive
out of memory
GlobalMemoryStatusEx
Can not set length for output file
Can not open output file
Can not delete output folder
Can not delete output file
Can not rename existing file
Can not create file with auto name
Can not seek to begin of file
can't decompress folder
there is no such archive
Can not create output directory:
GenuineIntelAuthenticAMDCentaurHauls
UXTHEME
USERENV
SETUPAPI
APPHELP
PROPSYS
DWMAPI
CRYPTBASE
OLEACC
CLBCATQ
VERSION
SetDefaultDllDirectories
comdlg32.dll
OLEAUT32.dll
OleInitialize
CoUninitialize
CoInitialize
CoCreateInstance
ole32.dll
CharUpperW
LoadStringW
SendMessageW
GetWindowTextW
GetWindowTextLengthW
SystemParametersInfoW
MapDialogRect
GetWindowRect
GetDlgItem
ScreenToClient
MoveWindow
ShowWindow
GetWindowLongW
SetWindowLongW
DialogBoxParamW
MessageBoxW
PostMessageW
EnableWindow
SetWindowTextW
InvalidateRect
GetKeyState
SetFocus
GetFocus
SetDlgItemTextW
EndDialog
IsDlgButtonChecked
CheckDlgButton
SetTimer
LoadIconW
GetParent
SetCursor
LoadCursorW
KillTimer
USER32.dll
SHGetMalloc
SHGetPathFromIDListW
SHBrowseForFolderW
SHGetFileInfoW
SHELL32.dll
__CxxFrameHandler
memcmp
_purecall
memset
memmove
memcpy
malloc
_CxxThrowException
wcsstr
wcscmp
_beginthreadex
_except_handler3
MSVCRT.dll
??1type_info@@UAE@XZ
?terminate@@YAXXZ
__dllonexit
_onexit
_XcptFilter
_acmdln
__getmainargs
_initterm
__setusermatherr
_adjust_fdiv
__p__commode
__p__fmode
__set_app_type
_controlfp
GetCommandLineW
FreeLibrary
GetProcAddress
LoadLibraryW
GetVersionExW
GetLastError
MultiByteToWideChar
LoadLibraryExW
GetModuleFileNameW
LocalFree
FormatMessageW
GetSystemDirectoryW
CloseHandle
SetFileTime
CreateFileW
SetFileAttributesW
RemoveDirectoryW
MoveFileW
GetModuleHandleW
CreateDirectoryW
DeleteFileW
SetLastError
GetCurrentDirectoryW
GetTickCount
FindClose
FindFirstFileW
FindNextFileW
GetModuleHandleA
GetFileAttributesW
GetLogicalDriveStringsW
GetFileSize
SetFilePointer
ReadFile
WriteFile
SetEndOfFile
CompareFileTime
FileTimeToSystemTime
FileTimeToLocalFileTime
GetProcessAffinityMask
GetCurrentProcess
GetSystemInfo
GlobalMemoryStatus
GetStdHandle
GetFileInformationByHandle
WaitForMultipleObjects
LeaveCriticalSection
EnterCriticalSection
DeleteCriticalSection
SetPriorityClass
VirtualAlloc
VirtualFree
lstrcatW
lstrlenW
WaitForSingleObject
CreateEventW
SetEvent
ResetEvent
InitializeCriticalSection
GetStartupInfoA
KERNEL32.dll
.?AVCNewException@@
.?AVUString@@
.?AVCInArchiveException@N7z@NArchive@@
.?AVCUnsupportedFeatureException@N7z@NArchive@@
.?AVtype_info@@
OlaNcx
^I6i37
}b3R^{6
9Q=vZ99
BERROR: Unknown Error!
Error in archive
Error 1329485
Bad command
Error 1329484
comctl32.dll
Unsupported Windows version
#kernel32.dll
N[DELETED]\
Unknown warning
Unknown error
B7-Zip
9999 MB
2009-09-09 09:09
123456789012345671234567890
Warning
Warnings
Progress Error
__DIR__
__FILE__.001
BIncorrect output directory path
VS_VERSION_INFO
StringFileInfo
040904b0
CompanyName
Igor Pavlov
FileDescription
7z SFX
FileVersion
InternalName
7z.sfx
LegalCopyright
Copyright (c) 1999-2018 Igor Pavlov
OriginalFilename
7z.sfx.exe
ProductName
ProductVersion
VarFileInfo
Translation
7-Zip self-extracting archive
MS Shell Dlg
E&xtract to:
Extract
Cancel
Confirm File Replace
MS Shell Dlg
Destination folder already contains processed file.
Would you like to replace the existing file
with this one?
Yes to &All
A&uto Rename
No to A&ll
&Cancel
Enter password
MS Shell Dlg
&Enter password:
&Show password
Cancel
Progress
MS Shell Dlg
&Background
&Pause
Cancel
Elapsed time:
Remaining time:
Files:
Compression ratio:
Errors:
Total size:
Speed:
Processed:
Compressed size:
dmsctls_progress32
Progress1
0eSysListView32
{0} bytes
&Foreground
Paused
&Close
&Continue
Are you sure you want to cancel?
8The system cannot allocate the required amount of memory
Cannot create folder '{0}'5Update operations are not supported for this archive."Can not open file '{0}' as archive5Can not open encrypted archive '{0}'. Wrong password?
Unsupported archive type
$Can not open the file as {0} archiveThe file is open as {0} archiveThe archive is open with offset
Extracting
Skipping
'Specify a location for extracted files.
Full pathnames
No pathnames
Absolute pathnames
Relative pathnames
Ask before overwrite
Overwrite without prompt
Skip existing files
Auto rename
Auto rename existing files
)Unsupported compression method for '{0}'.#Data error in '{0}'. File is broken$CRC failed in '{0}'. File is broken.3Data error in encrypted file '{0}'. Wrong password?3CRC failed in encrypted file '{0}'. Wrong password?
Wrong password?
Unsupported compression method
Data error
CRC failed
Unavailable data
Unexpected end of data5There are some data after the end of the payload data
Is not archive
Headers Error
Wrong password
Unavailable start of archive
Unconfirmed start of archive
Unsupported feature
Modified
Report.js
Antivirus Result
Bkav W32.Aidetectmalware
Lionic None
Elastic None
ClamAV None
CMC None
CAT-QuickHeal None
Skyhigh None
ALYac None
Cylance None
Zillya None
Sangfor None
CrowdStrike Win/Malicious_Confidence_60% (W)
Alibaba None
K7GW None
K7AntiVirus None
Baidu None
VirIT None
Paloalto None
Symantec None
tehtris None
ESET-NOD32 None
APEX None
Avast None
Cynet None
Kaspersky None
BitDefender None
NANO-Antivirus None
ViRobot None
MicroWorld-eScan None
Tencent None
Sophos None
F-Secure None
DrWeb None
VIPRE None
TrendMicro None
McAfeeD None
Trapmine None
CTX None
Emsisoft None
huorong None
GData None
Jiangmin None
Webroot None
Varist None
Avira None
Antiy-AVL None
Kingsoft None
Gridinsoft None
Xcitium None
Arcabit None
SUPERAntiSpyware None
Microsoft None
Google None
AhnLab-V3 None
Acronis None
McAfee None
TACHYON None
VBA32 None
Malwarebytes None
Panda None
Zoner None
TrendMicro-HouseCall None
Rising None
Yandex None
Ikarus None
MaxSecure None
Fortinet None
AVG None
DeepInstinct None
alibabacloud None
IRMA Signature
Trend Micro SProtect (Linux) Clean
Avast Core Security (Linux) Clean
C4S ClamAV (Linux) Clean
Trellix (Linux) Clean
Sophos Anti-Virus (Linux) Clean
Bitdefender Antivirus (Linux) Clean
G Data Antivirus (Windows) Clean
WithSecure (Linux) Clean
ESET Security (Windows) Clean
DrWeb Antivirus (Linux) Clean
ClamAV (Linux) Clean
eScan Antivirus (Linux) Clean
Kaspersky Standard (Windows) Clean
Emsisoft Commandline Scanner (Windows) Clean
Cuckoo

We're processing your submission... This could take a few seconds.