Warning! We are currently in recovery mode. The complete archive is not available.

Sample details: 1cdb7bf8ddfba8adae1fd1a909136f8a --

Hashes
MD5: 1cdb7bf8ddfba8adae1fd1a909136f8a
SHA1: 4ab1d741e33368e1519ff6560c846a36213eb943
SHA256: 158db942abd31c67fee941f70282a9d8def3a50c54e993f2fc6f9f85a2403c6f
SSDEEP: 1536:R0gAkHJBw8qWJoD32W9G8h0V5BVIW/T/4BrGcG+2CP:Rn5bJs2WI88Yx2C
Details
File Type: PE32
Yara Hits
YRP/Borland_Cpp_DLL | YRP/Borland_Cpp_for_Win32_1999 | YRP/Borland | YRP/IsPE32 | YRP/IsDLL | YRP/IsWindowsGUI | YRP/IsBeyondImageSize | YRP/domain | YRP/contentis_base64 | YRP/DebuggerException__SetConsoleCtrl | YRP/win_files_operation |
Parent Files
07366aeaaf4cc541451e35c636f53fa4
Strings
		This program must be run under Win32
`.data
.idata
@.edata
@.rsrc
@.reloc
fb:C++HOOK
Y@u	Sj
Y@u	Wj
_^[YY]
_^[YY]
**BCCxh1
_^[YY]
_^[YY]
_^[YY]
A<ru	3
9+u <tt
_^[YY]
RQhDrj
QPhDrj
H_^[Y]
e@FBC;u
_^[YY]
QUVWRSPT
0_^[Y]
Borland C++ - Copyright 1999 Inprise Corporation
SIMULATE_TLS: A second thread was about to be created and the c0s32 startup code is in use
Nonshared DATA segment required
Cannot run multiple instances of a DLL under WIN32s
././@LongLink
%s (%s --> %s)
MS-DOS
VAX/VMS
Macintosh
TOPS20
Windows NT
PRIMOS
TAR+GZIP
gz|tgz|qpr|qpk
borlndmm
hrdir_b.c: LoadLibrary != mmdll borlndmm failed
borlndmm
@Borlndmm@SysGetMem$qqri
@Borlndmm@SysFreeMem$qqrpv
@Borlndmm@SysReallocMem$qqrpvi
<notype>
<notype>
___CPPdebugHook
Stack Overflow!
),(((((),(((
Error 0
Invalid function number
No such file or directory
Path not found
Too many open files
Permission denied
Bad file number
Memory arena trashed
Not enough memory
Invalid memory block address
Invalid environment
Invalid format
Invalid access code
Invalid data
Bad address
No such device
Attempted to remove current directory
Not same device
No more files
Invalid argument
Arg list too big
Exec format error
Cross-device link
Too many open files
No child processes
Inappropriate I/O control operation
Executable file in use
File too large
No space left on device
Illegal seek
Read-only file system
Too many links
Broken pipe
Math argument
Result too large
File already exists
Possible deadlock
Operation not permitted
No such process
Interrupted function call
Input/output error
No such device or address
Resource temporarily unavailable
Block device required
Resource busy
Not a directory
Is a directory
Directory not empty
Unknown error
(null)
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
%H:%M:%S
%m/%d/%y
%A, %B %d, %Y
Monday
Tuesday
Wednesday
Thursday
Friday
Saturday
Sunday
January
February
August
September
October
November
December
printf : floating point formats not linked
scanf : floating point formats not linked
printf : floating point formats not linked
scanf : floating point formats not linked
Error: system code page access failure; MBCS table not initialized
%02d/%02d/%04d %02d:%02d:%02d.%03d 
kernel32.dll
GetProcAddress
Borland32
Abnormal program termination
No space for copy of command line
No space for copy of command line
An exception (%08X) occurred during DllEntryPoint or DllMain in module:
___CPPdebugHook
**BCCxh1
KERNEL32.DLL
SHELL32.DLL
USER32.DLL
CloseHandle
CreateDirectoryA
CreateFileA
CreateFileW
DeleteFileA
DeleteFileW
DosDateTimeToFileTime
ExitProcess
FileTimeToDosDateTime
FileTimeToLocalFileTime
FindClose
FindFirstFileA
FreeEnvironmentStringsA
GetACP
GetCPInfo
GetCurrentDirectoryA
GetCurrentThreadId
GetEnvironmentStrings
GetFileAttributesA
GetFileTime
GetFileType
GetFullPathNameA
GetLastError
GetLocalTime
GetModuleFileNameA
GetModuleHandleA
GetOEMCP
GetProcAddress
GetProcessHeap
GetStartupInfoA
GetStdHandle
GetStringTypeW
GetVersion
GetVersionExA
GlobalMemoryStatus
HeapAlloc
HeapFree
LCMapStringA
LoadLibraryA
LocalFileTimeToFileTime
MultiByteToWideChar
RaiseException
ReadFile
RtlUnwind
SetConsoleCtrlHandler
SetCurrentDirectoryA
SetFilePointer
SetFileTime
SetHandleCount
UnhandledExceptionFilter
VirtualAlloc
VirtualFree
WideCharToMultiByte
WriteFile
SHFileOperationA
EnumThreadWindows
MessageBoxA
wsprintfA
gz.dll
@TarClose$qqsp10FmtArcInfo
@TarExtract$qqsp17FmtExtractOptions
@TarGetListItem$qqsp11FmtListItemp11ArcItemInfo
@TarOpen$qqspcpuci
Extract
GetListItem
Prepare
___CPPdebugHook
{<:y&q?	
7!7-737C7Q7Y7c7i7p7v7
7 8(81878>8D8
;S<i<u<
0$0+010:0G0S0g0m0
1%1B1U1^1
2(252;2O2
5$5*5K5Q5h5n5
7B9K9k9q9
>/?7?<?
;?;I;T;\;d;k;q;{;
<'<A<M<Y<e<
=E=M=k=q=
=*>!>:>F>P>8?-???k?
?D6J6V6w6
7#7N7j7
838;8H8]8
9)9;9A9K9q9
:#:0:H:N:m:s:|:
0K0S0[0b0v0
101X1l1
2#202a2|2
3'3k3s3
41484)4J4
5B5R5k5
6.797]7i7t7
7O8`8n8
999D9}9
0 0*040
0&000:0F0]0u0
061H1Y1^1v1
3&3:3W3_3k3q3|3
2C577*737=7F7J7W7d7j7x7
8 868u8
9@:I:R:^:h:V:b:l:u:
:1;O;c;
6D:O<S<
:);6;|;
;3<A<I<
=!=-=9=
;J;U;d;
<@=Q=`=
0T1]1g1o1
4t5x5|5
939H9]9r9
: :%:1:=:I:]:s<
7D8M8W8f8o8y8
<9=B=L=[=d=n=
8=8I8U8a8u8
0%0M1V1a1p1
1`2h2v2
76?:?>?B?F?J?N?
9"9(9.949:9@9F9L9R9X9^9d9j9p9v9|9
h=l=p=t=x=|=
0 0&0,02080>0D0J0P0V0
14383<3@3D3H3L3P3T3X3\3`3d3h3l3
4$5(5,5h5
<T=X=\=`=d=
l8p8t8x8
; ;$;x;|;D=x=
`5d5h5l5p5t5x5|5
6 6$6(6,6064686<6@6D6H6L6P6T6X6p6t6|6