Static | ZeroBOX

PE Compile Time

2021-06-01 11:54:19

PE Imphash

1b3a9d51a40f5ca9cef0b8379f0622fb

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x00043134 0x00044000 5.28212695834
.data 0x00045000 0x0000125c 0x00001000 0.0
.rsrc 0x00047000 0x00006d8e 0x00007000 5.32078517949

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x000475ce 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x000475ce 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x000475ce 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x000475ce 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x000475ce 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x000475ce 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x000475ce 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x000475ce 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_GROUP_ICON 0x00047558 0x00000076 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_VERSION 0x00047240 0x00000318 LANG_TAMIL SUBLANG_DEFAULT data

Imports

Library MSVBVM60.DLL:
0x401000 None
0x401004 _CIcos
0x401008 _adj_fptan
0x40100c __vbaVarMove
0x401010 __vbaFreeVar
0x401014 __vbaAryMove
0x401018 __vbaStrVarMove
0x40101c None
0x401020 None
0x401024 None
0x401028 __vbaFreeVarList
0x40102c _adj_fdiv_m64
0x401030 __vbaFreeObjList
0x401034 None
0x401038 _adj_fprem1
0x40103c None
0x401040 None
0x401044 __vbaStrCat
0x401048 None
0x40104c __vbaSetSystemError
0x401050 None
0x401058 None
0x40105c __vbaLenVar
0x401060 _adj_fdiv_m32
0x401064 __vbaAryVar
0x401068 None
0x40106c __vbaAryDestruct
0x401070 None
0x401074 None
0x401078 __vbaVarForInit
0x40107c None
0x401080 __vbaObjSet
0x401084 None
0x401088 __vbaOnError
0x40108c None
0x401090 _adj_fdiv_m16i
0x401094 None
0x401098 _adj_fdivr_m16i
0x40109c None
0x4010a0 None
0x4010a4 None
0x4010a8 __vbaVarTstLt
0x4010ac __vbaFpR8
0x4010b0 _CIsin
0x4010b4 __vbaErase
0x4010b8 None
0x4010bc __vbaChkstk
0x4010c0 None
0x4010c4 EVENT_SINK_AddRef
0x4010cc __vbaStrCmp
0x4010d0 __vbaAryConstruct2
0x4010d4 __vbaVarTstEq
0x4010d8 DllFunctionCall
0x4010dc None
0x4010e0 _adj_fpatan
0x4010e4 None
0x4010e8 __vbaLateIdCallLd
0x4010ec __vbaRedim
0x4010f0 EVENT_SINK_Release
0x4010f4 __vbaUI1I2
0x4010f8 _CIsqrt
0x401100 __vbaExceptHandler
0x401104 None
0x401108 __vbaStrToUnicode
0x40110c _adj_fprem
0x401110 _adj_fdivr_m64
0x401114 None
0x401118 None
0x40111c __vbaFPException
0x401120 __vbaStrVarVal
0x401124 None
0x401128 None
0x40112c _CIlog
0x401130 None
0x401134 None
0x401138 __vbaNew2
0x40113c __vbaR8Str
0x401140 None
0x401144 __vbaVar2Vec
0x401148 None
0x40114c _adj_fdiv_m32i
0x401150 None
0x401154 _adj_fdivr_m32i
0x401158 __vbaStrCopy
0x40115c None
0x401160 None
0x401164 __vbaFreeStrList
0x401168 _adj_fdivr_m32
0x40116c _adj_fdiv_r
0x401170 None
0x401174 __vbaVarTstNe
0x401178 __vbaI4Var
0x40117c None
0x401180 __vbaVarAdd
0x401184 None
0x401188 __vbaLateMemCall
0x40118c __vbaStrToAnsi
0x401190 __vbaVarDup
0x401194 None
0x401198 __vbaFpI4
0x40119c __vbaVarCopy
0x4011a0 _CIatan
0x4011a4 __vbaAryCopy
0x4011a8 __vbaStrMove
0x4011ac __vbaCastObj
0x4011b0 None
0x4011b4 _allmul
0x4011b8 __vbaLateIdSt
0x4011bc None
0x4011c0 None
0x4011c4 None
0x4011c8 _CItan
0x4011cc __vbaVarForNext
0x4011d0 _CIexp
0x4011d4 __vbaFreeObj
0x4011d8 __vbaFreeStr
0x4011dc None

!This program cannot be run in DOS mode.
`.data
MSVBVM60.DLL
motorbane
Cku':O
Ungarnsopholds
MOPPEN
PPMPOV
PPGGGIIMV+0y
PMGDDDEDIG
PGGBBBBDDG/
PGDEBBB8BBG
PIEBBBBB8BBG
VMGBBBBBBBB8G+
PGBBBBBB8BBBG2
MGBBBBBBBBBEGD+.~
PGFBBBBBBBBBCIP2/
NGBBBBBBBBBBFI
MGBBBBBBBBBDGP
MGEBBBBBBBBGN
VMGBBBBBBBEGMV
VKEFEBBBBBGMV
"<EBDEGMP
VPhXWYn
rK!C9)-
|dUK+*
,4ccQ/%.*
OF*^oqqsz
;LZ]\n
Mavjh5E""I[r
avthEF
MOPPEN
Command2
Physicianship
Command1
Samraadene
turneringslederen
Nephropathic
Frame1
Gennembrudt5
Frame5
POINTINGLY
VB5!6&*
Overempirical7
Pataco3
motorbane
motorbane
Ungarnsopholds
Substructured
C:\Program Files (x86)\Microsoft Visual Studio\VB98\VB6.OLB
Frame1
Frame5
Command2
Command1
kernel32
VirtualUnlock
advapi32.dll
SetFileSecurityA
winmm.dll
waveInAddBuffer
wininet.dll
InternetCheckConnectionA
CallNextHookEx
user32
CharUpperA
RemoveFontResourceA
CopyRect
DefWindowProcA
winspool.drv
EnumPrintersA
url.dll
InetIsOffline
CreateBitmap
shlwapi.dll
PathCompactPathExA
GetFileTime
userenv.dll
GetAllUsersProfileDirectoryA
dekompositionerne
Nulinterval
UMAADELIGHEDS
Lathered
GREYING
ABsolutes
VBA6.DLL
__vbaVarForNext
__vbaStrVarVal
__vbaLenVar
__vbaVarForInit
__vbaVarCopy
__vbaLateMemCall
__vbaVar2Vec
__vbaAryMove
__vbaFpR8
__vbaErase
__vbaSetSystemError
__vbaVarTstNe
__vbaCastObj
__vbaVarTstEq
__vbaAryDestruct
__vbaOnError
__vbaUI1I2
__vbaLateIdSt
__vbaRedim
__vbaFreeStrList
__vbaStrToUnicode
__vbaR8Str
__vbaVarDup
__vbaStrToAnsi
__vbaVarTstLt
__vbaVarAdd
__vbaStrCopy
__vbaFreeObjList
__vbaI4Var
__vbaFpI4
__vbaLateIdCallLd
__vbaStrVarMove
__vbaFreeVar
__vbaVarMove
__vbaGenerateBoundsError
__vbaStrCmp
__vbaFreeVarList
__vbaFreeStr
__vbaStrCat
__vbaStrMove
__vbaAryVar
__vbaAryCopy
__vbaFreeObj
__vbaHresultCheckObj
__vbaNew2
__vbaObjSet
__vbaAryConstruct2
lonnard
Substructured
Finanstilsynenes
Finanstilsynenes
B=#'`Li
M3#6LD
uC6TC3
2d^`?#
5{j8#6U,
Spj8#6s,
P,j8#6zF#
.8##x*
:#6W1@
(@0#fP
{PU|yeF
xC+3[x
z~^g4:5
wOJ0(d
xZ-Zjx
Kp>p_l
f/p5#
: #6DF5_h8#
j8#D%w
!(2#7EN
-*4k8]
;::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::
```````````````````````````````````````````````````````````````````````````````````````````````
Qe**************************************************************************************************
DDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDD
skkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkk
_________________________________________________________________________________________________
jttttttttttttttttttttttttttttttttttttttttttttttttttttttttttttttttttttttttttttttttttttttttttttttttt
.************************************************************************************************
FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF
gkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkk
C[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[
uuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuu
c'uA(ttttttttttttttttttttttttttttttttttttttttttttttttttttttttttttttttttttttttttttttttttttttttttttttt
{ooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooo
Outlined4
rteblgens
Tonaliteten
Dugpunkterne
Bosserne8
Programmeringernes6
Gaussbredderne
rheotropic
INCARDINATE
Obmutescence
superidealness
}#jxhh
}#jLhH
}#j`hd
}#jXhh
}#j@hH
}#j4hH
}#jxhh
}#jLhH
}#j`hd
}#j`hd
}#j@hH
MSVBVM60.DLL
_CIcos
_adj_fptan
__vbaVarMove
__vbaFreeVar
__vbaAryMove
__vbaStrVarMove
__vbaFreeVarList
_adj_fdiv_m64
__vbaFreeObjList
_adj_fprem1
__vbaStrCat
__vbaSetSystemError
__vbaHresultCheckObj
__vbaLenVar
_adj_fdiv_m32
__vbaAryVar
__vbaAryDestruct
__vbaVarForInit
__vbaObjSet
__vbaOnError
_adj_fdiv_m16i
_adj_fdivr_m16i
__vbaVarTstLt
__vbaFpR8
_CIsin
__vbaErase
__vbaChkstk
EVENT_SINK_AddRef
__vbaGenerateBoundsError
__vbaStrCmp
__vbaAryConstruct2
__vbaVarTstEq
DllFunctionCall
_adj_fpatan
__vbaLateIdCallLd
__vbaRedim
EVENT_SINK_Release
__vbaUI1I2
_CIsqrt
EVENT_SINK_QueryInterface
__vbaExceptHandler
__vbaStrToUnicode
_adj_fprem
_adj_fdivr_m64
__vbaFPException
__vbaStrVarVal
_CIlog
__vbaNew2
__vbaR8Str
__vbaVar2Vec
_adj_fdiv_m32i
_adj_fdivr_m32i
__vbaStrCopy
__vbaFreeStrList
_adj_fdivr_m32
_adj_fdiv_r
__vbaVarTstNe
__vbaI4Var
__vbaVarAdd
__vbaLateMemCall
__vbaStrToAnsi
__vbaVarDup
__vbaFpI4
__vbaVarCopy
_CIatan
__vbaAryCopy
__vbaStrMove
__vbaCastObj
_allmul
__vbaLateIdSt
_CItan
__vbaVarForNext
_CIexp
__vbaFreeObj
__vbaFreeStr
|dUK+*
,4ccQ/%.*
OF*^oqqsz
;LZ]\n
Mavjh5E""I[r
avthEF
rK!C9)-
PPMPOV
PPGGGIIMV+0y
PMGDDDEDIG
PGGBBBBDDG/
PGDEBBB8BBG
PIEBBBBB8BBG
VMGBBBBBBBB8G+
PGBBBBBB8BBBG2
MGBBBBBBBBBEGD+.~
PGFBBBBBBBBBCIP2/
NGBBBBBBBBBBFI
MGBBBBBBBBBDGP
MGEBBBBBBBBGN
VMGBBBBBBBEGMV
VKEFEBBBBBGMV
"<EBDEGMP
VPhXWYn
ABSTENTIONIST
Thrombectomies
katalognummer
Harporhynchus6
LITERACIES
PRODSBOLT
FLJTENE
Tropsfrerens1
corruptible
kartoteksskabenes
Ringingly
ddspatruljerne
Epicondyle2
Domestikvrelsernes
blodfattige
Gangstolene2
stuehusets
adonitol
ULTRAMASCULINE
Bearishness2
Pantophobia
Pritchardia
Unshouting5
OPSTRG
Inkmaker
Phenolia
MUNDHUGGES
SPYDSKAFTERNES
SCHFERENS
Dunderhead1
UNQUIXOTIC
PROVERBLIKE
Tumulose
PEJLINGSAPPARAT
Stvsugning
Fremkaldelser1
NECKPIECE
transithandel
Delphic
Bantustammen1
maaneder
ALTROSE
resknderiernes
GURGLING
Goldenwood4
Mennonite3
Reproarbejders
bromidernes
Scottification
Paladsrevolutioner
Nonprotrusiveness4
Indlejringers7
Paavist
RICARD
Operationelle
Supraconduction8
Quieted
Relessee
Paedogenic6
Inkonsekvensers
bushhammer
Kremationen
Spidsrodslbenes
sovemedicinen
REALIENATE
Fattigdomstal7
dispergeret
Garden
Polyteknikerne
SPURIOUSNESS
Victimizable6
micheles
PILGRIMWISE
lnudbetalinger
Fribby4
EKSTREMISMEN
MAXIMAL
beruselse
TOLVAARSFDSELSDAG
Stithe7
INTERUNIVERSITY
Unwintry
Haaber
RESTIFFNESS
Zootechnical
Stbolde
Tightwads
Royalists
Polyphonic
Preperusal8
COMPUTERFORHANDLERENS
BYGGESTYRELSERS
Atomkraftvrkerne
Nielson5
kulances
BEGRAENSET
uriasposternes
Dekaeder
appropriate
Periscopal7
OVERIMITATED
Kttersk1
Electrogalvanise
Loeve2
HJLPEKARTOTEKERNES
Bootery2
Plummets8
Triakisoctahedrid1
harceleres
RECERPTPLIGTIGT
Centrifugalkrafts
PREALLOTTING
Knoglemarvsundersgelser
Malfeasance
statsmagternes
birthmate
Unloose
Digitalisation9
UNDERKJES
Wraithlike6
Flabellarium
SNOTNSERNES
dasyuridae
koloritterne
Sphakiot
Legalisms
Ashlaring1
Brmmerne
fadernes
Uddragningens2
Konstruktiv9
husblas
TUBERKULINETS
fordanskningerne
Episomally
Blackens6
intrapsychical
gastroesophageal
Korsklde
PARTICULARIZED
dalevendes
buffeted
Interflashing
Gratinere8
GEOSTROPHICALLY
sGxP4WEVyhtbXTwMbj8w7
t of string
strygetaalene
Morgenbords
NAKHODA
MARSUPIALIZE
SPRITS
HogZkvkXdFwz0DUJQsILvlw4D1AWe2v88
Aunjetitz
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
044904B0
Comments
Jupiter
CompanyName
Jupiter AC
FileDescription
Jupiter AC
LegalCopyright
Jupiter
LegalTrademarks
Jupiter
ProductName
Jupiter AC
FileVersion
ProductVersion
InternalName
Overempirical7
OriginalFilename
Overempirical7.exe
Antivirus Signature
Bkav W32.AIDetect.malware2
Elastic malicious (high confidence)
ClamAV Clean
FireEye Generic.mg.541369bff43470b5
CAT-QuickHeal Clean
McAfee RDN/Generic.hbg
Cylance Unsafe
VIPRE Clean
AegisLab Clean
Sangfor Trojan.Win32.Save.a
K7AntiVirus Clean
BitDefender Trojan.GenericKD.37015770
K7GW Clean
Cybereason Clean
Baidu Clean
Cyren W32/VBKrypt.AVO.gen!Eldorado
ESET-NOD32 a variant of Win32/Injector.EPLI
APEX Malicious
Avast Win32:Malware-gen
Cynet Malicious (score: 100)
Kaspersky Clean
Alibaba Trojan:Win32/Injector.5d6dee42
NANO-Antivirus Clean
ViRobot Trojan.Win32.Z.Vbkrypt.315392.H
MicroWorld-eScan Trojan.GenericKD.37015770
Rising Clean
Ad-Aware Trojan.GenericKD.37015770
Emsisoft Trojan.GenericKD.37015770 (B)
Comodo Clean
F-Secure Clean
DrWeb Trojan.VbCrypt.2295
Zillya Clean
TrendMicro Clean
CMC Clean
Sophos Clean
SentinelOne Static AI - Suspicious PE
GData Trojan.GenericKD.37015770
Jiangmin Clean
MaxSecure Trojan.Malware.300983.susgen
Avira Clean
MAX malware (ai score=99)
Antiy-AVL Clean
Kingsoft Clean
Gridinsoft Clean
Arcabit Clean
SUPERAntiSpyware Clean
ZoneAlarm Clean
Microsoft Trojan:Win32/GuLoader.KB!MTB
AhnLab-V3 Win-Trojan/VBKrypt.RP08.X1976
Acronis Clean
BitDefenderTheta Gen:NN.ZevbaF.34692.tm0@a8dz2RhG
ALYac Trojan.VBKrypt.gen
TACHYON Clean
VBA32 Clean
Malwarebytes Clean
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Tencent Clean
Yandex Clean
Ikarus Win32.Outbreak
eGambit Clean
Fortinet W32/Injector.EPLI!tr
Webroot W32.Malware.Gen
AVG Win32:Malware-gen
Paloalto generic.ml
CrowdStrike win/malicious_confidence_60% (W)
Qihoo-360 Clean
No IRMA results available.