Static | ZeroBOX

PE Compile Time

2017-02-26 18:12:08

PE Imphash

1abc0dab2264c6ccb12f07d7e589e0ba

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x0002fdd4 0x00030000 5.53460145367
.data 0x00031000 0x0000ebd4 0x00001000 0.0
.rsrc 0x00040000 0x000009c4 0x00001000 2.12454764493

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x00040484 0x00000128 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x00040484 0x00000128 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x00040484 0x00000128 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_GROUP_ICON 0x00040454 0x00000030 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_VERSION 0x00040150 0x00000304 LANG_ENGLISH SUBLANG_ENGLISH_US data

Imports

Library MSVBVM60.DLL:
0x401000 _CIcos
0x401004 _adj_fptan
0x401008 __vbaVarMove
0x40100c __vbaFreeVar
0x401010 __vbaAryMove
0x401014 None
0x401018 __vbaStrVarMove
0x40101c __vbaFreeVarList
0x401020 __vbaEnd
0x401024 _adj_fdiv_m64
0x401028 __vbaFreeObjList
0x40102c _adj_fprem1
0x401030 __vbaStrCat
0x401034 __vbaSetSystemError
0x40103c None
0x401040 _adj_fdiv_m32
0x401044 None
0x401048 __vbaAryDestruct
0x40104c __vbaExitProc
0x401050 None
0x401054 __vbaOnError
0x401058 __vbaObjSet
0x40105c None
0x401060 None
0x401064 _adj_fdiv_m16i
0x401068 __vbaObjSetAddref
0x40106c None
0x401070 _adj_fdivr_m16i
0x401074 None
0x401078 None
0x40107c None
0x401080 None
0x401084 None
0x401088 __vbaVarTstLt
0x40108c __vbaFpR8
0x401090 _CIsin
0x401094 __vbaChkstk
0x401098 EVENT_SINK_AddRef
0x4010a0 __vbaStrCmp
0x4010a4 None
0x4010a8 __vbaAryConstruct2
0x4010ac None
0x4010b0 DllFunctionCall
0x4010b4 None
0x4010b8 _adj_fpatan
0x4010bc __vbaLateIdCallLd
0x4010c0 None
0x4010c4 __vbaRedim
0x4010c8 EVENT_SINK_Release
0x4010cc None
0x4010d0 __vbaUI1I2
0x4010d4 _CIsqrt
0x4010dc __vbaExceptHandler
0x4010e0 _adj_fprem
0x4010e4 _adj_fdivr_m64
0x4010e8 None
0x4010ec None
0x4010f0 None
0x4010f4 None
0x4010f8 __vbaFPException
0x4010fc None
0x401100 __vbaInStrVar
0x401104 None
0x401108 _CIlog
0x40110c __vbaErrorOverflow
0x401110 None
0x401114 __vbaFileOpen
0x401118 __vbaNew2
0x40111c __vbaVar2Vec
0x401120 None
0x401124 _adj_fdiv_m32i
0x401128 _adj_fdivr_m32i
0x40112c __vbaStrCopy
0x401130 None
0x401134 __vbaI4Str
0x401138 __vbaFreeStrList
0x40113c None
0x401140 None
0x401144 _adj_fdivr_m32
0x401148 _adj_fdiv_r
0x40114c None
0x401150 None
0x401154 __vbaVarTstNe
0x401158 __vbaI4Var
0x40115c __vbaVarAdd
0x401160 __vbaStrToAnsi
0x401164 __vbaVarDup
0x401168 None
0x40116c _CIatan
0x401170 __vbaStrMove
0x401174 __vbaCastObj
0x401178 None
0x40117c _allmul
0x401180 __vbaLateIdSt
0x401184 None
0x401188 _CItan
0x40118c None
0x401190 __vbaFPInt
0x401194 _CIexp
0x401198 __vbaFreeObj
0x40119c __vbaFreeStr

!This program cannot be run in DOS mode.
`.data
MSVBVM60.DLL
STALDDREN
PSEUDOZEALOUS
KREMERET
KREMERET
Overgracious7
Frame2
attendingly
Check2
lensherrerne
Combo2
efterlignings
HScroll1
VScroll1
VScroll21
Combo1
TRSTESPISER
Check1
betragtendes
Option1
BRAAVALLASLAGENE
Command1
Knaster9
Frame1
Pholido6
Label1
VB5!6&*
skrsild
sectionalise
STALDDREN
2yR6Oe)
BackColor
ForeColor
Enabled
BorderStyle
MSMASK32.OCX
MSMask.MaskEdBox
MaskEdBox
STALDDREN
PSEUDOZEALOUS
Peridial6
Legesyge9
AKTIES
atrofiere
Stormless6
Charadrioid9
acronyx
Spendthrift
aptitude
BARNEPLEJERSKERNE
Secreter5
HOVEDROLLERS
UNEVANESCENT
Overfladetemperaturens7
STNINGSSTYKKE
Reyoked
Fjerkrenes
Roupily6
rosalind
remanenserne
Forfaldsperioderne
ENTRENCHING
Fdekdernes
Regnemssiges
gaslighter
COERCE
Desensitize7
traktrers
Metylen
TEAKTRERS
Regeringsreprsentanter1
Stroganoff6
naboejendommens
DIGLADIATED
Frame2
C:\Program Files (x86)\Microsoft Visual Studio\VB98\VB6.OLB
Command1
Check1
Option1
VScroll1
VScroll21
HScroll1
Label1
Combo2
Frame1
Combo1
Check2
ADVAPI32.DLL
CryptSignHashA
winmm.dll
waveInStart
VB5STKIT.DLL
fCreateShellLink
kernel32
GetPriorityClass
CreateEllipticRgn
user32
CreateCursor
SetSystemTime
Subsystems
Nonunanimousness
Slkningerne7
Fictionise
Uanstndig6
VENTRICULARIS
Pertness7
RUSSETS
AFBESTILLES
bssekolber
VBA6.DLL
__vbaFileOpen
__vbaCastObj
__vbaRedim
__vbaInStrVar
__vbaObjSetAddref
__vbaStrCopy
__vbaI4Str
__vbaFPInt
__vbaLateIdSt
__vbaVarDup
__vbaFpR8
__vbaAryDestruct
__vbaEnd
__vbaStrToAnsi
__vbaUI1I2
__vbaGenerateBoundsError
__vbaSetSystemError
__vbaVarTstLt
__vbaVarAdd
__vbaVarMove
__vbaFreeStrList
__vbaFreeObjList
__vbaI4Var
__vbaLateIdCallLd
__vbaFreeStr
__vbaStrCmp
__vbaOnError
FREAKISH
__vbaFreeObj
__vbaVar2Vec
__vbaAryMove
__vbaHresultCheckObj
__vbaNew2
__vbaObjSet
__vbaFreeVar
__vbaStrVarMove
__vbaStrMove
__vbaFreeVarList
__vbaStrCat
__vbaVarTstNe
__vbaAryConstruct2
2ypredisrupt
C:\Program Files (x86)\Administrator-Cloud\OCX\MSMASK32.oca
MSMask
Acieration
burundierens
P_1prvelses
Unsabereds
<coachy
Dupedom
PRICKFOOT
METIER
EXORDIA
PENTITOL
Rhombohedric
wiremaking
peerless
rhabdosome
UNTHOUGHTFUL
ungerontic
Unrulable
Ernringstabel
fanatisering
APOTHECARY
Problematiseredes1
Edgeshot7
SKRAAEDE
UMULIGGRE
lTIRSDAGES
praleris
udtryksfuldes
tndinger
plejningernes
diglossia
Sykurves
DEDIFFERENTIATION
Tannish4
Spellken
mukkerts
Selenotropy
Dogmatikere7
afrejsemiddag
knopskydningens
Shipbreaking4
Bipinnate6
+jnonfan
sengelsningerne
SKOBRSTNING
PARENTESSTRUKTUR
KONSULTATIONSSYSTEMERNES
bopyridian
\PARCELHUSEJERNE
managua
OMNUMMEREREDE
willer
Transitgodsets
&Kolkozes9
Ejaculates
SABALOS
HYDROLOGICALLY
Plumules3
Paratrophic3
graldine
!BGrundlovssikret
stdsikre
GOLADAR
Plantaginaceae3
Melondessert5
Dejlig1
Attentatmnds4
denouncements
festdragter
tDENEANPARTSHAVERNE
REALKREDITINSTITUTLAANENES
antikonceptionelles
Betalingsstandsningens8
CONVULSIONARIES
ANISAL
filters
INTERCITYTOGENE
Remould3
LICENSKORTENES
ANTEBRACHIAL
discernably
Diktafon
Turps5
user32.dll
EnumThreadWindows
UnhookWindowsHook
DeleteService
GetBitmapBits
winspool.drv
DeletePrintProvidorA
shell32.dll
DragQueryFileA
WriteFileEx
DefMDIChildProcA
GetAclInformation
GetCapture
__vbaErrorOverflow
__vbaExitProc
AKTIES
IGNAZIOS
IGNAZIOS
PRICKFOOT
MSMask.MaskEdBox
coachy
MSMask.MaskEdBox
Dupedom
MSMask.MaskEdBox
Secreter5
SLIDERS
SLIDERS
diglossia
MSMask.MaskEdBox
tndinger
MSMask.MaskEdBox
plejningernes
MSMask.MaskEdBox
Metylen
Spurvefugl
Spurvefugl
discernably
MSMask.MaskEdBox
Diktafon
MSMask.MaskEdBox
Turps5
MSMask.MaskEdBox
Fdekdernes
PLOVEN
PLOVEN
stdsikre
MSMask.MaskEdBox
GOLADAR
MSMask.MaskEdBox
Grundlovssikret
MSMask.MaskEdBox
UNEVANESCENT
Potheen5
Potheen5
Tannish4
MSMask.MaskEdBox
mukkerts
MSMask.MaskEdBox
Spellken
MSMask.MaskEdBox
remanenserne
friteres
friteres
Ejaculates
MSMask.MaskEdBox
MSMask.MaskEdBox
Kolkozes9
MSMask.MaskEdBox
Reyoked
knkkene
knkkene
SKOBRSTNING
MSMask.MaskEdBox
nonfan
MSMask.MaskEdBox
sengelsningerne
MSMask.MaskEdBox
Stormless6
Feteringer
Feteringer
wiremaking
MSMask.MaskEdBox
Rhombohedric
MSMask.MaskEdBox
MSMask.MaskEdBox
Desensitize7
REARGUES
REARGUES
filters
MSMask.MaskEdBox
MSMask.MaskEdBox
INTERCITYTOGENE
MSMask.MaskEdBox
Legesyge9
prosopolepsy
prosopolepsy
Unsabereds
MSMask.MaskEdBox
MSMask.MaskEdBox
prvelses
MSMask.MaskEdBox
Roupily6
Ulocarcinoma4
Ulocarcinoma4
MSMask.MaskEdBox
managua
MSMask.MaskEdBox
PARCELHUSEJERNE
MSMask.MaskEdBox
atrofiere
Unmanageableness7
Unmanageableness7
METIER
MSMask.MaskEdBox
PENTITOL
MSMask.MaskEdBox
EXORDIA
MSMask.MaskEdBox
acronyx
Castigators5
Castigators5
ungerontic
MSMask.MaskEdBox
Ernringstabel
MSMask.MaskEdBox
Unrulable
MSMask.MaskEdBox
ENTRENCHING
kursnedslags
kursnedslags
Plumules3
MSMask.MaskEdBox
Paratrophic3
MSMask.MaskEdBox
graldine
MSMask.MaskEdBox
rosalind
KOKOTTERNES
KOKOTTERNES
willer
MSMask.MaskEdBox
Transitgodsets
MSMask.MaskEdBox
OMNUMMEREREDE
MSMask.MaskEdBox
Charadrioid9
Restaurators
Restaurators
peerless
MSMask.MaskEdBox
rhabdosome
MSMask.MaskEdBox
UNTHOUGHTFUL
MSMask.MaskEdBox
BARNEPLEJERSKERNE
EPISTERNALIA
EPISTERNALIA
udtryksfuldes
MSMask.MaskEdBox
TIRSDAGES
MSMask.MaskEdBox
praleris
MSMask.MaskEdBox
aptitude
anvendelsesmulighed
anvendelsesmulighed
SKRAAEDE
MSMask.MaskEdBox
UMULIGGRE
MSMask.MaskEdBox
Edgeshot7
MSMask.MaskEdBox
#/!-jB
Forfaldsperioderne
Labyrintiskes8
Labyrintiskes8
SABALOS
MSMask.MaskEdBox
HYDROLOGICALLY
MSMask.MaskEdBox
MSMask.MaskEdBox
Regnemssiges
HJULPISKERENS
HJULPISKERENS
Dejlig1
MSMask.MaskEdBox
Melondessert5
MSMask.MaskEdBox
Plantaginaceae3
MSMask.MaskEdBox
traktrers
FORBRUGERMINISTER
FORBRUGERMINISTER
LICENSKORTENES
MSMask.MaskEdBox
Remould3
MSMask.MaskEdBox
ANTEBRACHIAL
MSMask.MaskEdBox
Spendthrift
Nationaliseret
Nationaliseret
Problematiseredes1
MSMask.MaskEdBox
APOTHECARY
MSMask.MaskEdBox
fanatisering
MSMask.MaskEdBox
STNINGSSTYKKE
GARANTIBEVISERNE
GARANTIBEVISERNE
knopskydningens
MSMask.MaskEdBox
Shipbreaking4
MSMask.MaskEdBox
Bipinnate6
MSMask.MaskEdBox
COERCE
Ulykkesbilisterne8
Ulykkesbilisterne8
CONVULSIONARIES
MSMask.MaskEdBox
ANISAL
MSMask.MaskEdBox
Betalingsstandsningens8
MSMask.MaskEdBox
HOVEDROLLERS
Jernbaneforbindelserne
Jernbaneforbindelserne
DEDIFFERENTIATION
MSMask.MaskEdBox
Sykurves
MSMask.MaskEdBox
MSMask.MaskEdBox
Fjerkrenes
Trakkasserier9
Trakkasserier9
PARENTESSTRUKTUR
MSMask.MaskEdBox
KONSULTATIONSSYSTEMERNES
MSMask.MaskEdBox
bopyridian
MSMask.MaskEdBox
Overcrammi7
Overcrammi7
REALKREDITINSTITUTLAANENES
MSMask.MaskEdBox
ENEANPARTSHAVERNE
MSMask.MaskEdBox
antikonceptionelles
MSMask.MaskEdBox
gaslighter
midtpunktsjusteringers
midtpunktsjusteringers
Attentatmnds4
MSMask.MaskEdBox
festdragter
MSMask.MaskEdBox
denouncements
MSMask.MaskEdBox
Overfladetemperaturens7
Nondefensiveness1
Nondefensiveness1
Dogmatikere7
MSMask.MaskEdBox
afrejsemiddag
MSMask.MaskEdBox
Selenotropy
MSMask.MaskEdBox
Peridial6
nedtrykkes
nedtrykkes
predisrupt
MSMask.MaskEdBox
Acieration
MSMask.MaskEdBox
burundierens
MSMask.MaskEdBox
FREAKISH
]9Aq2'
]9Aq2'
~#}I+`q
~#}I+`q
V5S=\6nv
:~&<$G
[=eQ7L
Ie#57W4
d+"IFK
d-"VFT
[?\6n|
5^5Z/
Smerting
Trochisk
KATSUWONIDAE
Fjerntliggende3
Fussier
USINGS
Politifuldmgtigens8
MULTINATIONALS
ANSIGTSUDTRYK
PARKOMETRENES
stamhusbesiddernes
kllingen
FLUOROID
Flkkse
Malkonduites1
Fighteress
accused
UDMNSTRENDE
Mesoarial
Cykelanhnger
Biprodukters
Fastere6
AKTIEBREVETS
IJESPRINGENDE
}#jPh$
}#jHhD
}#jhhT
}#j`hd
}#jHhT
}#jhht
}#jHht
}#j$hx
}#jHht
}#jxh$
}#j`hT
}#jXh$
}#jPhT
}#jPhT
}#j`h$
}#jHhT
MSVBVM60.DLL
_CIcos
_adj_fptan
__vbaVarMove
__vbaFreeVar
__vbaAryMove
__vbaStrVarMove
__vbaFreeVarList
__vbaEnd
_adj_fdiv_m64
__vbaFreeObjList
_adj_fprem1
__vbaStrCat
__vbaSetSystemError
__vbaHresultCheckObj
_adj_fdiv_m32
__vbaAryDestruct
__vbaExitProc
__vbaOnError
__vbaObjSet
_adj_fdiv_m16i
__vbaObjSetAddref
_adj_fdivr_m16i
__vbaVarTstLt
__vbaFpR8
_CIsin
__vbaChkstk
EVENT_SINK_AddRef
__vbaGenerateBoundsError
__vbaStrCmp
__vbaAryConstruct2
DllFunctionCall
_adj_fpatan
__vbaLateIdCallLd
__vbaRedim
EVENT_SINK_Release
__vbaUI1I2
_CIsqrt
EVENT_SINK_QueryInterface
__vbaExceptHandler
_adj_fprem
_adj_fdivr_m64
__vbaFPException
__vbaInStrVar
_CIlog
__vbaErrorOverflow
__vbaFileOpen
__vbaNew2
__vbaVar2Vec
_adj_fdiv_m32i
_adj_fdivr_m32i
__vbaStrCopy
__vbaI4Str
__vbaFreeStrList
_adj_fdivr_m32
_adj_fdiv_r
__vbaVarTstNe
__vbaI4Var
__vbaVarAdd
__vbaStrToAnsi
__vbaVarDup
_CIatan
__vbaStrMove
__vbaCastObj
_allmul
__vbaLateIdSt
_CItan
__vbaFPInt
_CIexp
__vbaFreeObj
__vbaFreeStr
@lasses\TYPELIB\{C932
emgkgtgnnmnmninigthkgogggvmkhinjggnvm
21:21:2
Resistants
Flyvestol2
Misorganize
LDREPOLITIKKEN
epsilonets
CERAUNOGRAPH
Destines
befolkningstthed
Lekturerne
TREACLELIKE
Tilsendingers4
KRMMEREN
Bryllupsmiddagen5
RANSAGNINGSKENDELSERNE
Fastigiately4
Opbremsnings6
sandwiching
Triaderne5
Efterkrav8
Atropos
Out of string
Annotative
Tandlgeklinik1
trangeres
Lamest6
revlen
SULPHURAN
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
040904B0
Comments
Classified
CompanyName
Classified
FileDescription
Classified
LegalCopyright
Classified
LegalTrademarks
Classified
ProductName
Classified
FileVersion
ProductVersion
InternalName
skrsild
OriginalFilename
skrsild.exe
Antivirus Signature
Bkav W32.AIDetect.malware1
Elastic malicious (high confidence)
MicroWorld-eScan Trojan.GenericKD.46387517
FireEye Generic.mg.10d1dc044b4f546c
CAT-QuickHeal Clean
Qihoo-360 Clean
ALYac Trojan.GenericKD.46387517
Cylance Unsafe
VIPRE Clean
AegisLab Clean
Sangfor Backdoor.MSIL.NanoBot.beng
K7AntiVirus Riskware ( 0040eff71 )
BitDefender Trojan.GenericKD.46387517
K7GW Riskware ( 0040eff71 )
Cybereason Clean
BitDefenderTheta Gen:NN.ZevbaF.34692.mm0@aS86Zhhi
Cyren Clean
Symantec Trojan Horse
ESET-NOD32 Win32/TrojanDownloader.Injector.AM
Baidu Clean
APEX Malicious
Avast FileRepMalware
ClamAV Clean
Kaspersky Backdoor.MSIL.NanoBot.beng
Alibaba Backdoor:MSIL/NanoBot.f4dc8698
NANO-Antivirus Clean
ViRobot Clean
Rising Clean
Ad-Aware Trojan.GenericKD.46387517
Sophos Mal/Generic-S
Comodo Malware@#1jja5qb7ovvpj
F-Secure Clean
DrWeb Trojan.Nanocore.493
Zillya Clean
TrendMicro TROJ_FRS.0NA103EV21
McAfee-GW-Edition BehavesLike.Win32.Trojan.dm
CMC Clean
Emsisoft Trojan.GenericKD.46387517 (B)
SentinelOne Clean
GData Trojan.GenericKD.46387517
Jiangmin Clean
Webroot Clean
Avira BDS/NanoBot.vqxpd
MAX malware (ai score=100)
Antiy-AVL Clean
Kingsoft Win32.Hack.MSIL.be.(kcloud)
Gridinsoft Trojan.Win32.Agent.oa
Arcabit Trojan.Generic.D2C3D13D
SUPERAntiSpyware Clean
ZoneAlarm Clean
Microsoft Trojan:Win32/Fareit!ml
Cynet Malicious (score: 99)
AhnLab-V3 Clean
Acronis Clean
McAfee Artemis!10D1DC044B4F
TACHYON Clean
VBA32 BScope.Trojan.Agent
Malwarebytes Trojan.GuLoader
Panda Trj/GdSda.A
Zoner Clean
TrendMicro-HouseCall TROJ_FRS.0NA103EV21
Tencent Clean
Yandex Clean
Ikarus Trojan.VB.Crypt
eGambit Unsafe.AI_Score_98%
Fortinet W32/Malicious_Behavior.SBX
AVG FileRepMalware
Paloalto generic.ml
CrowdStrike win/malicious_confidence_90% (W)
MaxSecure Clean
No IRMA results available.