Sample details: cbe321decaf2572000278c4965a77f83 --

Hashes
MD5: cbe321decaf2572000278c4965a77f83
SHA1: 8258565e1921ba1f76c1ca0c13c5f9b29fb64809
SHA256: 3cad80f15cb83a6a253ab6cdb2829d9438c235c62f0d16905bde08a73954e1c8
SSDEEP: 6144:OLkpB3IkhHKePB1pilu2A8SJxauUPx3vR:O+asRbpi1A8SJxauUJZ
Details
File Type: PE32
Yara Hits
YRP/Armadillo_v171 | YRP/Microsoft_Visual_Cpp_v60 | YRP/Microsoft_Visual_Cpp_v50v60_MFC_additional | YRP/Microsoft_Visual_Cpp_50 | YRP/Microsoft_Visual_Cpp_v50v60_MFC | YRP/Armadillo_v171_additional | YRP/Armadillo_v4x | YRP/Microsoft_Visual_Cpp | YRP/IsPE32 | YRP/IsWindowsGUI | YRP/HasRichSignature | YRP/domain | YRP/contentis_base64 | YRP/keylogger | YRP/win_files_operation |
Source
http://fruploadtool.com/arbayt/creed.exe
http://fruploadtool.com/arbayt/creed.exe
Strings
		!This program cannot be run in DOS mode.
`.rdata
@.data
SS@SSPVSS
t#SSUP
t$$VSS
_^][YY
t.;t$$t(
VC20XC00U
MsiPreviewBillboardW
msi.dll
runtime error 
TLOSS error
SING error
DOMAIN error
- unable to initialize heap
- not enough space for lowio initialization
- not enough space for stdio initialization
- pure virtual function call
- not enough space for _onexit/atexit table
- unable to open console device
- unexpected heap error
- unexpected multithread lock error
- not enough space for thread data
abnormal program termination
- not enough space for environment
- not enough space for arguments
- floating point not loaded
Microsoft Visual C++ Runtime Library
Runtime Error!
Program: 
<program name unknown>
GetLastActivePopup
GetActiveWindow
MessageBoxA
user32.dll
GetClientRect
GetSubMenu
SetMenuItemInfoA
DefWindowProcW
ReleaseCapture
CheckMenuItem
TrackPopupMenu
RegisterClassW
PostMessageW
DestroyMenu
LoadIconA
ReleaseDC
InflateRect
GetKeyState
ShowWindowAsync
DestroyWindow
PtInRect
SendMessageW
GetActiveWindow
GetMenuItemCount
CreateWindowExW
UnregisterClassA
SetCapture
SetWindowLongW
SetWindowTextW
LoadStringW
GetMenuStringW
GetCursorPos
CreateWindowExA
USER32.dll
OleQueryLinkFromData
OleInitialize
ole32.dll
VirtualAlloc
GetProcAddress
LoadLibraryA
GetVersionExW
GetLastError
WaitForSingleObjectEx
InterlockedCompareExchange
EnterCriticalSection
GetModuleHandleW
WaitForSingleObject
QueryPerformanceCounter
SetFilePointerEx
GetModuleHandleA
WideCharToMultiByte
DeleteCriticalSection
WriteFile
FreeLibrary
MultiByteToWideChar
CloseHandle
TerminateProcess
LeaveCriticalSection
SetFilePointer
InterlockedExchange
ExitProcess
GetVersionExA
SetLastError
KERNEL32.dll
GetStartupInfoA
GetCommandLineA
GetVersion
GetCurrentProcess
UnhandledExceptionFilter
GetModuleFileNameA
FreeEnvironmentStringsA
FreeEnvironmentStringsW
GetEnvironmentStrings
GetEnvironmentStringsW
SetHandleCount
GetStdHandle
GetFileType
GetCurrentThreadId
TlsSetValue
TlsAlloc
TlsFree
TlsGetValue
GetCurrentThread
HeapDestroy
HeapCreate
VirtualFree
HeapFree
RtlUnwind
InitializeCriticalSection
FatalAppExitA
GetCPInfo
GetACP
GetOEMCP
HeapAlloc
HeapReAlloc
IsBadWritePtr
LCMapStringA
LCMapStringW
GetStringTypeA
GetStringTypeW
N|o`4[