PE Compile Time

2002-07-11 07:39:26

PE Imphash

da610ca700d3fcd07221889fd01b5be9

PEiD Signatures

Armadillo v1.71

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x0000a000 0x00009800 6.61574232071
.rdata 0x0000b000 0x00002000 0x00001200 5.16609076535
.data 0x0000d000 0x00003000 0x00001200 3.92108672765
.rsrc 0x00010000 0x00001000 0x00000c00 0.528995785846
.aspack 0x00011000 0x00002000 0x00001a00 5.72171694451
.adata 0x00013000 0x00001000 0x00001000 4.29351729868

Resources

Name Offset Size Language Sub-language File type
RT_CURSOR 0x000109f0 0x00000134 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_ICON 0x000120c8 0x000008a8 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED Device independent bitmap graphic, 48 x 96 x 4, image size 1152
RT_GROUP_CURSOR 0x00010b28 0x00000014 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED Lotus unknown worksheet or configuration, revision 0x1
RT_GROUP_ICON 0x000120b4 0x00000014 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data

Imports

Library WS2_32.dll:
0x40b1b4 WSAStartup
0x40b1b8 getsockname
0x40b1bc ntohs
0x40b1c0 listen
0x40b1c4 closesocket
0x40b1c8 WSACleanup
0x40b1cc accept
0x40b1d0 select
0x40b1d4 recvfrom
0x40b1d8 inet_ntoa
0x40b1dc sendto
0x40b1e0 htons
0x40b1e4 socket
0x40b1e8 bind
0x40b1ec recv
0x40b1f0 inet_addr
0x40b1f4 gethostname
0x40b1f8 gethostbyname
Library KERNEL32.dll:
0x40b020 WaitForSingleObject
0x40b024 HeapAlloc
0x40b028 SetErrorMode
0x40b02c GetProcAddress
0x40b034 LoadLibraryA
0x40b038 CompareStringA
0x40b03c FlushFileBuffers
0x40b040 GetStringTypeW
0x40b044 GetStringTypeA
0x40b048 SetStdHandle
0x40b04c CreateFileA
0x40b050 GetModuleFileNameA
0x40b054 ReadFile
0x40b058 SetFilePointer
0x40b05c GetFileSize
0x40b060 LocalFree
0x40b064 CloseHandle
0x40b068 WriteFile
0x40b06c LocalAlloc
0x40b074 GetTempFileNameA
0x40b078 Process32Next
0x40b07c TerminateProcess
0x40b080 OpenProcess
0x40b084 Process32First
0x40b08c GetCurrentProcess
0x40b090 GetVersionExA
0x40b094 DeleteFileA
0x40b098 WinExec
0x40b09c UnmapViewOfFile
0x40b0a0 MapViewOfFile
0x40b0a4 CreateFileMappingA
0x40b0a8 LockResource
0x40b0ac SizeofResource
0x40b0b0 LoadResource
0x40b0b4 FindResourceA
0x40b0b8 FreeLibrary
0x40b0bc EnumResourceNamesA
0x40b0c0 FlushViewOfFile
0x40b0c4 LoadLibraryExA
0x40b0c8 SetFileTime
0x40b0cc Sleep
0x40b0d0 CopyFileA
0x40b0d4 GetFileTime
0x40b0d8 SetFileAttributesA
0x40b0dc GetFileAttributesA
0x40b0e0 GetComputerNameA
0x40b0e4 CreateThread
0x40b0e8 TerminateThread
0x40b0ec GetOEMCP
0x40b0f0 LCMapStringA
0x40b0f4 FindClose
0x40b0f8 FindNextFileA
0x40b0fc FindFirstFileA
0x40b100 HeapDestroy
0x40b104 CreateProcessA
0x40b108 GetModuleHandleA
0x40b10c GetCurrentProcessId
0x40b110 CompareStringW
0x40b118 GetSystemTime
0x40b11c GetLocalTime
0x40b120 GetStartupInfoA
0x40b124 GetCommandLineA
0x40b128 GetVersion
0x40b12c ExitProcess
0x40b130 HeapFree
0x40b134 WideCharToMultiByte
0x40b138 MultiByteToWideChar
0x40b140 LCMapStringW
0x40b148 HeapCreate
0x40b14c VirtualFree
0x40b150 VirtualAlloc
0x40b154 HeapReAlloc
0x40b160 GetFileType
0x40b168 SetHandleCount
0x40b16c GetStdHandle
0x40b170 GetCPInfo
0x40b174 RtlUnwind
0x40b178 GetLastError
0x40b17c GetACP
Library USER32.dll:
0x40b184 ExitWindowsEx
0x40b188 GetDesktopWindow
0x40b18c GetWindow
0x40b190 SendMessageA
0x40b194 GetWindowTextA
0x40b19c IsWindow
Library ADVAPI32.dll:
0x40b000 OpenProcessToken
0x40b00c RegOpenKeyA
0x40b010 RegCreateKeyA
0x40b014 RegSetValueExA
0x40b018 RegCloseKey
Library VERSION.dll:
0x40b1a8 GetFileVersionInfoA
0x40b1ac VerQueryValueA

!This program cannot be run in DOS mode.
.rdata
.aspack
.adata
_^][YY
X[_^]Y
5VVVh
D$$tN3
PVVVVVV
t5Vj h
uRFGHt
"WWSh,
HHtpHHtl
8t9UW
SS@SSPVSS
t#SSUP
t$$VSS
_^][YY
DSUVWh
t.;t$$t(
VC20XC00U
QSUVW3
>:uNFV
>:u#FV
VWuBh|
+ttHHtd
t/WWUPj
QQSVW3
`h````
ppxxxx
(null)
GAIsProcessorFeaturePresent
KERNEL32
runtime error
TLOSS error
SING error
DOMAIN error
- unable to initialize heap
- not enough space for lowio initialization
- not enough space for stdio initialization
- pure virtual function call
- not enough space for _onexit/atexit table
- unable to open console device
- unexpected heap error
- unexpected multithread lock error
- not enough space for thread data
abnormal program termination
- not enough space for environment
- not enough space for arguments
- floating point not loaded
Microsoft Visual C++ Runtime Library
Runtime Error!
Program:
<program name unknown>
SunMonTueWedThuFriSat
JanFebMarAprMayJunJulAugSepOctNovDec
GetLastActivePopup
GetActiveWindow
MessageBoxA
user32.dll
1#QNAN
1#SNAN
WS2_32.dll
CreateFileA
GetModuleFileNameA
ReadFile
SetFilePointer
GetFileSize
LocalFree
CloseHandle
WriteFile
LocalAlloc
GetWindowsDirectoryA
GetTempFileNameA
Process32Next
TerminateProcess
OpenProcess
Process32First
CreateToolhelp32Snapshot
GetCurrentProcess
GetVersionExA
DeleteFileA
WinExec
UnmapViewOfFile
MapViewOfFile
CreateFileMappingA
LockResource
SizeofResource
LoadResource
FindResourceA
FreeLibrary
EnumResourceNamesA
FlushViewOfFile
LoadLibraryExA
SetFileTime
CopyFileA
GetFileTime
SetFileAttributesA
GetFileAttributesA
GetComputerNameA
CreateThread
TerminateThread
GetProcAddress
LoadLibraryA
FindClose
FindNextFileA
FindFirstFileA
WaitForSingleObject
CreateProcessA
GetModuleHandleA
GetCurrentProcessId
SetErrorMode
HeapAlloc
GetTimeZoneInformation
GetSystemTime
GetLocalTime
GetStartupInfoA
GetCommandLineA
GetVersion
ExitProcess
HeapFree
WideCharToMultiByte
MultiByteToWideChar
LCMapStringA
LCMapStringW
HeapDestroy
HeapCreate
VirtualFree
VirtualAlloc
HeapReAlloc
UnhandledExceptionFilter
FreeEnvironmentStringsA
FreeEnvironmentStringsW
GetEnvironmentStrings
GetEnvironmentStringsW
SetHandleCount
GetStdHandle
GetFileType
RtlUnwind
GetLastError
GetCPInfo
GetACP
GetOEMCP
SetStdHandle
GetStringTypeA
GetStringTypeW
FlushFileBuffers
CompareStringA
CompareStringW
SetEnvironmentVariableA
KERNEL32.dll
ExitWindowsEx
GetDesktopWindow
GetWindow
SendMessageA
GetWindowTextA
GetWindowThreadProcessId
IsWindow
USER32.dll
RegCloseKey
RegSetValueExA
RegCreateKeyA
RegOpenKeyA
AdjustTokenPrivileges
LookupPrivilegeValueA
OpenProcessToken
ADVAPI32.dll
VerQueryValueA
GetFileVersionInfoA
GetFileVersionInfoSizeA
VERSION.dll
Software\Microsoft\Windows\CurrentVersion\RunServices
MSWDM.EXE
Software\Microsoft\Windows\CurrentVersion\Run
\mswdm.exe
device
SeShutdownPrivilege
notepad
255.0.0.0
255.255.0.0
255.255.255.0
\system\kernel32.exe
IEXPLORE.EXE
NETEYES.EXE
MSDEV.EXE
EXPLORER.EXE
XXXXXXXXXXXXXXXXXXXXXXXX.EXE
IPARMOR
TROJAN
255.255.255.255
NORTON
FIREWALL
\welcome.exe
MICROSOFT
\StringFileInfo\%04x%04x\CompanyName
\VarFileInfo\Translation
GetModuleFileNameExA
EnumProcessModules
psapi.dll
c:\mswdm.pro
sys.try
\*.exe
NtQuerySystemInformation
RegisterServiceProcess
KERNEL32.DLL
VirtualAlloc
VirtualFree
kernel32.dll
ExitProcess
user32.dll
MessageBoxA
wsprintfA
LOADER ERROR
The procedure entry point %s could not be located in the dynamic link library %s
The ordinal %u could not be located in the dynamic link library %s
(08@P`p
kernel32.dll
GetProcAddress
GetModuleHandleA
LoadLibraryA
ws2_32.dll
user32.dll
advapi32.dll
version.dll
ExitWindowsEx
OpenProcessToken
GetFileVersionInfoSizeA
P@@@9y
ffFedK
FLn~f~VddfH
lvVGK{
@tf~nwflfFGc
sFn~gn
FFFvvn
f_````d
ddddd``_f
ffd``d
"JF$""#Fe
}YHHHHHHHHHHHHHH
!This program cannot be run in DOS mode.
`.data

 !!!!""""####$$$$%%%%&&&&''''(((())))****++++,,,,----....////0000111122223333444455556666777788889999::::;;;;<<<=
 !!!!""""####$$$$%%%%&&&&''''(((())))****++++,,,,----....////0000111122223333444455556666777788889999::::;;;;<<<<==>>???
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !!!!""""####$$$$%%%%&&&&''''(((())))*****++++,,,,----....////0000111122223333444455556666777788889999::::;;;;<<<<====>>>>?
!)1:BJRZcks{
!%)-16:>BFJNRVZ^cgkosw{
0d1112131415161718191:1;1<1=1>1?1@1A1B1C1D1E1F1G1H1I1J1K1L1M1N1
O1P1Q1R1S1T1
U1V1W1X1Y1Z1
[1\1]1^1_1`1
a1b1c1
UUUUUUU
TUUUUU+
)1$N*)Q&`[U
eEf=ghfijklimnf=o
f=pqrst
KLMNOP
UVWXYZ[
"#$%&'(
)*+,-.
012345678
CCDCEF
(null)
((((( H
%s : fatal error -:
tinycrt
exceeded maximum command-line args %d
COPYMAR
@CBitmapSurface::EnableDefaultMappings
%1 is an unimplemented method
CBitmapSurface::SetMapping
@imageinfo.xml
imageinfo.mii
@donotdither
measure
numimages
imagelist
accessimage
bottom
ValidateMarchiveChecksums
ForceReadOnlyMarchive
@MSN Archive Stability
MSN Archive: Checksum Mismatch in file %s: %s
@CMarsProtStreamWrapper::SetSize
CMarsProtStreamWrapper::Commit
CMarsProtStreamWrapper::Revert
CMarsProtStreamWrapper::CopyTo
CMarsProtStreamWrapper::LockRegion
CMarsProtStreamWrapper::UnlockRegion
CMarsProtStreamWrapper::Clone
System\CurrentControlSet\Control\FontAssoc\Associated Charset
ANSI(00)
High Contrast
Control Panel\Appearance
Current
UseSysColors
{E8055863-4956-4cbf-9CA5-46FF053A904C}
TSAppCompat
System\CurrentControlSet\Control\Terminal Server
MSN6.INI
gopher
mailto
telnet
javascript
vbscript
image/x-png
image/png
image/gif
image/pjpeg
image/jpeg
pressed
Antivirus Signature
Bkav W32.AIDetectNet.01
Lionic Trojan.Win32.Daws.mzM4
Elastic malicious (high confidence)
MicroWorld-eScan Trojan.Agent.DYAA
CMC Clean
CAT-QuickHeal Trojan.Mauvaise.SL1
ALYac Trojan.Agent.DYAA
Malwarebytes Injector.Trojan.MSIL.DDS
Zillya Virus.Ipamor.Win32.5
Sangfor Suspicious.Win32.Save.ins
K7AntiVirus Virus ( 0040f5921 )
Alibaba Virus:Win32/Ipamor.19c5
K7GW Virus ( 0040f5921 )
Cybereason malicious.85d0e9
Baidu Win32.Virus.Ipamor.b
VirIT Clean
Cyren W32/Ipamor.A.gen!Eldorado
Symantec W32.HLLP.Ipamor
tehtris Generic.Malware
ESET-NOD32 a variant of Win32/Ipamor.G
APEX Malicious
Paloalto Clean
Cynet Malicious (score: 100)
Kaspersky Trojan-Banker.Win32.Banbra.vwsb
BitDefender Trojan.Agent.DYAA
NANO-Antivirus Virus.Win32.Ipamor.cxoj
ViRobot Clean
Tencent Virus.Win32.Viking.aak
TACHYON Worm/W32.Ipamor.Zen.D
Sophos W32/Ipamor-B
F-Secure Clean
DrWeb Win32.HLLP.Iparmor.35858
VIPRE Trojan.Agent.DYAA
TrendMicro TROJ_GEN.R002C0CH122
McAfee-GW-Edition BehavesLike.Win32.Ipamor.mm
Trapmine malicious.high.ml.score
FireEye Generic.mg.41af5d385d0e9338
Emsisoft Trojan.Agent.DYAA (B)
SentinelOne Static AI - Malicious PE
GData Win32.Virus.Ipamor-Main.A
Jiangmin Trojan.Generic.ghobc
Webroot Clean
Avira TR/Agent.arue
Antiy-AVL Virus/Win32.Ipamor.g
Kingsoft Clean
Gridinsoft Trojan.Win32.Agent.vb!s1
Xcitium Virus.Win32.Ipamor.G@8j5juk
Arcabit Trojan.Agent.DYAA
SUPERAntiSpyware Clean
Microsoft Virus:Win32/Ipamor.A
Google Detected
AhnLab-V3 Win32/Ipamor.D.X1356
Acronis suspicious
McAfee Artemis!41AF5D385D0E
MAX malware (ai score=84)
VBA32 Virus.Facepalm.231207
Panda Trj/Genetic.gen
Zoner Clean
TrendMicro-HouseCall TROJ_GEN.R002C0CH122
Rising Win32.MSWDM.b (CLASSIC)
Yandex Trojan.GenAsa!qp+sKG55Fu8
Ikarus Virus.Win32.Ipamor
MaxSecure Banker.Banbra.vwsb
Fortinet W32/Ipamor.D
BitDefenderTheta AI:Packer.B60502231F
AVG Win32:Ipamor
Avast Win32:Ipamor
IRMA Signature
Trend Micro SProtect (Linux) Clean
Avast Core Security (Linux) Win32:Ipamor
C4S ClamAV (Linux) Win.Trojan.Iparm-1
Trellix (Linux) W32/Ipamor
Sophos Anti-Virus (Linux) W32/Ipamor-B
Bitdefender Antivirus (Linux) Trojan.GenericKD.66110182
G Data Antivirus (Windows) Virus: Trojan.GenericKD.66110182 (Engine A), Win32.Virus.Ipamor-Main.A (Engine B)
WithSecure (Linux) Trojan.TR/Agent.arue
ESET Security (Windows) a variant of Win32/Ipamor.G virus
DrWeb Antivirus (Linux) Trojan.MulDrop26.36640
ClamAV (Linux) Clean
eScan Antivirus (Linux) Trojan.GenericKD.66110182(DB)
Kaspersky Standard (Windows) Trojan-Banker.Win32.Banbra.vwsb
Emsisoft Commandline Scanner (Windows) Trojan.GenericKD.66110182 (B)
Cuckoo

We're processing your submission... This could take a few seconds.