Static | ZeroBOX

PE Compile Time

2015-10-18 19:30:29

PE Imphash

2c08d8f9644132654eb702b279083d5c

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x00020b8c 0x00021000 5.99507437991
.data 0x00022000 0x00001278 0x00001000 0.0
.rsrc 0x00024000 0x00000948 0x00001000 2.04580716998

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x00024408 0x00000128 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x00024408 0x00000128 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x00024408 0x00000128 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_GROUP_ICON 0x000243d8 0x00000030 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_VERSION 0x00024150 0x00000288 LANG_ENGLISH SUBLANG_ENGLISH_US data

Imports

Library MSVBVM60.DLL:
0x401000 _CIcos
0x401004 _adj_fptan
0x401008 __vbaVarMove
0x40100c __vbaHresultCheck
0x401010 None
0x401014 __vbaFreeVar
0x401018 None
0x40101c __vbaStrVarMove
0x401020 __vbaLenBstr
0x401024 __vbaFreeVarList
0x401028 __vbaEnd
0x40102c None
0x401030 _adj_fdiv_m64
0x401034 __vbaFreeObjList
0x401038 None
0x40103c None
0x401040 _adj_fprem1
0x401044 None
0x401048 None
0x40104c None
0x401050 None
0x401054 __vbaSetSystemError
0x401058 None
0x401060 None
0x401064 _adj_fdiv_m32
0x401068 None
0x40106c __vbaAryDestruct
0x401070 None
0x401074 None
0x401078 __vbaBoolStr
0x40107c None
0x401080 __vbaObjSet
0x401084 __vbaOnError
0x401088 None
0x40108c None
0x401090 _adj_fdiv_m16i
0x401094 __vbaObjSetAddref
0x401098 _adj_fdivr_m16i
0x40109c None
0x4010a0 None
0x4010a4 __vbaFpR8
0x4010a8 __vbaVarTstLt
0x4010ac _CIsin
0x4010b0 __vbaErase
0x4010b4 None
0x4010b8 __vbaChkstk
0x4010bc EVENT_SINK_AddRef
0x4010c4 __vbaStrCmp
0x4010c8 __vbaAryConstruct2
0x4010cc __vbaVarTstEq
0x4010d0 __vbaR4Str
0x4010d4 __vbaObjVar
0x4010d8 None
0x4010dc DllFunctionCall
0x4010e0 None
0x4010e4 None
0x4010e8 _adj_fpatan
0x4010ec None
0x4010f0 None
0x4010f4 __vbaLateIdCallLd
0x4010f8 None
0x4010fc __vbaRedim
0x401100 EVENT_SINK_Release
0x401104 None
0x401108 __vbaUI1I2
0x40110c _CIsqrt
0x401114 None
0x401118 __vbaExceptHandler
0x40111c _adj_fprem
0x401120 _adj_fdivr_m64
0x401124 None
0x401128 None
0x40112c None
0x401130 __vbaFPException
0x401134 __vbaInStrVar
0x401138 None
0x40113c None
0x401140 None
0x401144 None
0x401148 _CIlog
0x40114c __vbaNew2
0x401150 __vbaInStr
0x401154 None
0x401158 None
0x40115c _adj_fdiv_m32i
0x401160 _adj_fdivr_m32i
0x401164 __vbaStrCopy
0x401168 __vbaI4Str
0x40116c __vbaFreeStrList
0x401170 _adj_fdivr_m32
0x401174 _adj_fdiv_r
0x401178 None
0x40117c __vbaVarTstNe
0x401180 __vbaI4Var
0x401184 None
0x401188 __vbaVarAdd
0x40118c __vbaLateMemCall
0x401190 __vbaVarDup
0x401194 __vbaStrToAnsi
0x401198 None
0x40119c __vbaFpI4
0x4011a0 __vbaVarCopy
0x4011a4 None
0x4011a8 __vbaLateMemCallLd
0x4011ac _CIatan
0x4011b0 __vbaStrMove
0x4011b4 __vbaCastObj
0x4011b8 _allmul
0x4011bc __vbaLateIdSt
0x4011c0 None
0x4011c4 _CItan
0x4011c8 _CIexp
0x4011cc __vbaFreeObj
0x4011d0 __vbaFreeStr
0x4011d4 None

!This program cannot be run in DOS mode.
`.data
MSVBVM60.DLL
Afmattelser
Samples
Snooking
Snooking
Volleyers8
Frame2
Arbejdslshedsprocenters3
Check2
palaeosaurus
Combo2
Creatin
HScroll1
VScroll1
VScroll21
Combo1
Biddably3
Check1
Rekinole
Option1
housecarl
Command1
AFTGTSYDELSERNE
Frame1
fluorecensen
Label1
TRINFLGER
VB5!6&*
HOVEDPUNKTER
dissertator
Afmattelser
2yR6Oe)
BackColor
ForeColor
Enabled
BorderStyle
MSMASK32.OCX
MSMask.MaskEdBox
MaskEdBox
Afmattelser
Samples
Cachous
HScroll1
C:\Program Files (x86)\Microsoft Visual Studio\VB98\VB6.OLB
VScroll21
Option1
VScroll1
Check1
Frame2
Label1
Frame1
Combo2
Command1
Combo1
Check2
waveOutGetVolume
NETAPI32.DLL
NetMessageBufferSend
shell32
Iphlpapi
GetIpNetTable
user32
GetKeyboardLayoutNameA
SystemParametersInfoA
CopyIcon
Personalunion3
Dirigerer6
unreciprocal
melonernes
Overpostinspektrernes4
CLARIFIES
MAANEDSDAG
uncontrovertableness
Buoyantly7
Enriches
macrometer
Paraplyer7
Prosupervision8
rabatsats
Sadomasochistic1
VBA6.DLL
__vbaLateMemCallLd
__vbaLateMemCall
__vbaObjVar
__vbaObjSetAddref
__vbaBoolStr
__vbaHresultCheck
__vbaVarTstEq
__vbaEnd
__vbaErase
__vbaVarCopy
__vbaRedim
__vbaLenBstr
__vbaInStr
__vbaSetSystemError
__vbaStrToAnsi
__vbaUI1I2
__vbaOnError
__vbaVarTstLt
__vbaVarMove
__vbaStrVarMove
__vbaLateIdCallLd
__vbaFreeStrList
__vbaLateIdSt
__vbaAryDestruct
__vbaFpI4
__vbaStrCmp
__vbaGenerateBoundsError
__vbaAryConstruct2
__vbaVarDup
__vbaR4Str
__vbaInStrVar
__vbaI4Var
__vbaFreeVar
__vbaI4Str
__vbaFreeObjList
__vbaCastObj
__vbaFpR8
__vbaObjSet
__vbaStrCopy
__vbaFreeStr
__vbaFreeObj
__vbaHresultCheckObj
__vbaNew2
__vbaStrMove
__vbaFreeVarList
__vbaVarAdd
__vbaVarTstNe
2yCAUTIONARY
C:\Program Files (x86)\Administrator-Cloud\OCX\MSMASK32.oca
MSMask
kredsendes
Neighbor6
Baalist7
Cachous
Raaolies
Raaolies
Baalist7
MSMask.MaskEdBox
Neighbor6
MSMask.MaskEdBox
CAUTIONARY
MSMask.MaskEdBox
kredsendes
JxnRu!
l:LzB-
Xig5aI2
v&52x1
-HbGm9
.gGmYb
lffxiW
lffxiSy7
r Z*0)
j_lAbw
_DBcM)
fxif j:
<:8rP
Q`bS(
'mBj.
C({Rk/
wbJmAf~QA
0)V]h3
cicVO$
f"laS`r
Jb[ZM*
Sbv(~3
b[6$In
Q?r03Y
lfG}4S|
^bBsjq
HjwKjnb
BN[bF+T
aSu21%
2~.ia+
gqa`K
Baskiske
Psize7
NONCONFIDENTIAL
Teaktrsstolens1
deputationens
teacupsful
RENOVERINGERS
Percussor
Combinatorics
Incomers
GYSELIGERES
Unsnarl3
HELIOS
Lsningsforsget
Misusurped6
officemate
SPILDEVANDSTILLADELSE
Baandvvs6
Norenes
Laminer
acrisy
Exchanged
Minimism
Subseptuple5
Implosive
CYCLAMIN
BRONCHOTRACHEAL
Aktivisering
Brskursernes
choregus
hemianalgesia
ENDOSKOPET
Catallactically9
Susurr
Saturniidae
Forskningsbibliotekarerne6
Autocatalysis6
Vejrsatellitters1
Hensynsfulde2
KREKLARES
roskildefestivalen
Nattle4
KISSEMISSE
Berigningers2
Roundelay7
Misrehearsing
ascent
epencephalic
PACIFIES
anthropomorphite
umenneskeliggrelses
Menageriet
Embedsboliger
Aliases8
Heroes4
styrkelisters
Awols1
utensil
Kaossets8
SPAREKASSENS
bilbombens
Faradaic
chrysalida
Bumaree2
Skrmenes
Apologie8
iditol
Cryptographic7
DISFEATURE
Autonomiserings9
Finansieringsselskabers7
Forbindelsesvejene8
MINKFARMEN
photomagnetism
UNDEFACEABLE
Semiportable8
inseminantens
trovrdighedsklfts
Trader5
Beskestes
Bjanca7
urotoxic
Blokbogens
gruppetotaler
demist
etiketteres
THINKINGS
Bratschnglers8
Elverdansens3
jhh<:@
}#j`h\9@
}#j`h<:@
}#jhhH;@
}#j`h,:@
}#jxh,:@
}#jxhL<@
}#jHh<:@
}#jXh,:@
}#jhhL<@
}#j`hL<@
}#jHh\9@
}#j`h\9@
}#j`hH;@
}#jhh\9@
}#jhh\9@
}#jPhH;@
}#jPh\9@
}#jhhH;@
}#jXh0>@
}#jXh,:@
jTh0>@
jXh0>@
j`h0>@
jTh0>@
jHh<:@
j$ht?@
j`h0>@
MSVBVM60.DLL
_CIcos
_adj_fptan
__vbaVarMove
__vbaHresultCheck
__vbaFreeVar
__vbaStrVarMove
__vbaLenBstr
__vbaFreeVarList
__vbaEnd
_adj_fdiv_m64
__vbaFreeObjList
_adj_fprem1
__vbaSetSystemError
__vbaHresultCheckObj
_adj_fdiv_m32
__vbaAryDestruct
__vbaBoolStr
__vbaObjSet
__vbaOnError
_adj_fdiv_m16i
__vbaObjSetAddref
_adj_fdivr_m16i
__vbaFpR8
__vbaVarTstLt
_CIsin
__vbaErase
__vbaChkstk
EVENT_SINK_AddRef
__vbaGenerateBoundsError
__vbaStrCmp
__vbaAryConstruct2
__vbaVarTstEq
__vbaR4Str
__vbaObjVar
DllFunctionCall
_adj_fpatan
__vbaLateIdCallLd
__vbaRedim
EVENT_SINK_Release
__vbaUI1I2
_CIsqrt
EVENT_SINK_QueryInterface
__vbaExceptHandler
_adj_fprem
_adj_fdivr_m64
__vbaFPException
__vbaInStrVar
_CIlog
__vbaNew2
__vbaInStr
_adj_fdiv_m32i
_adj_fdivr_m32i
__vbaStrCopy
__vbaI4Str
__vbaFreeStrList
_adj_fdivr_m32
_adj_fdiv_r
__vbaVarTstNe
__vbaI4Var
__vbaVarAdd
__vbaLateMemCall
__vbaVarDup
__vbaStrToAnsi
__vbaFpI4
__vbaVarCopy
__vbaLateMemCallLd
_CIatan
__vbaStrMove
__vbaCastObj
_allmul
__vbaLateIdSt
_CItan
_CIexp
__vbaFreeObj
__vbaFreeStr
emgkgtgnnmnmninigthkgogggvmkhinjggnvm
HIKINGTREPIDATEJAGTLEJ
Maumeenondesignateunlimited
vidneafhringerrenprisenuds
Skvattersriledfugle
Vrvletskonstat8
photaesthesisbevaebnings
KREDITORERSBERNICEEN
Responsorialhymenial
GENFREMSTILLINGEN
ekspeditricerne
passulate
Bibeskftigelsernes
KANTSTENENS
Styringscomputeren
Luksusvrelsernes
Balancegangs8
Exposition
Spurvens1
SCORPIONID
albication
mistilliden
seminarial
HEMOTHORAX
composersatses
Finskheder4
cathedrallike
Extraquiz4
tietick
Mesotympanic
Vitalisation6
CANNON
eudist
REENLISTNESS
Foreordains5
BEANBALL
miniaturising
testamentering
polyesters
NUDZHED
Blodansamlingernes4
Antologiers2
Laemodipoda
Proclamations4
Eksemernes6
KONDISKO
01/01/01
Skrivelrer1
Catecholamines
20:20:20
Festerment9
Spheniscomorphae1
Udmarvnings8
Parisiskes8
Pleurococcaceae
O6LxHL51aTnkYsQDbH68
tippernes
uQzYfoIri7ddvc3x8FN7bmsdWeJ3OQrppbhD233
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
040904B0
Comments
Workday
CompanyName
Workday
FileDescription
Workday
ProductName
Workday
FileVersion
ProductVersion
InternalName
HOVEDPUNKTER
OriginalFilename
HOVEDPUNKTER.exe
Antivirus Signature
Bkav W32.AIDetect.malware2
Elastic malicious (high confidence)
MicroWorld-eScan Gen:Variant.Graftor.963667
CMC Clean
CAT-QuickHeal Clean
Qihoo-360 Clean
ALYac Clean
Cylance Clean
VIPRE Clean
AegisLab Trojan.Multi.Generic.4!c
Sangfor Trojan.Win32.Save.a
K7AntiVirus Clean
BitDefender Gen:Variant.Graftor.963667
K7GW Clean
Cybereason Clean
Arcabit Trojan.Graftor.DEB453
Baidu Clean
Cyren W32/VBKrypt.AVX.gen!Eldorado
Symantec Trojan.Gen.MBT
ESET-NOD32 a variant of Win32/Injector.EPNK
APEX Malicious
Avast FileRepMetagen [Malware]
ClamAV Clean
Kaspersky Trojan.Win32.Mucc.okz
Alibaba Clean
NANO-Antivirus Clean
ViRobot Clean
Ad-Aware Gen:Variant.Graftor.963667
TACHYON Clean
Emsisoft Gen:Variant.Graftor.963667 (B)
Comodo TrojWare.Win32.Agent.wghlv@0
F-Secure Clean
DrWeb Trojan.VbCrypt.2306
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition BehavesLike.Win32.Trojan.cm
FireEye Gen:Variant.Graftor.963667
Sophos Clean
Ikarus Win32.Outbreak
Jiangmin Clean
Webroot Clean
Avira Clean
Antiy-AVL Clean
Kingsoft Win32.Troj.Generic_a.a.(kcloud)
Gridinsoft Trojan.Win32.Agent.oa
Microsoft Trojan:Win32/Guloader.SS!MTB
SUPERAntiSpyware Clean
ZoneAlarm Clean
GData Gen:Variant.Graftor.963667
Cynet Malicious (score: 100)
AhnLab-V3 Clean
Acronis Clean
McAfee Artemis!6572076BC216
MAX malware (ai score=88)
VBA32 Clean
Malwarebytes Trojan.GuLoader
Panda Trj/GdSda.A
Zoner Clean
TrendMicro-HouseCall Clean
Rising Clean
Yandex Clean
SentinelOne Clean
eGambit Unsafe.AI_Score_79%
Fortinet W32/PossibleThreat
BitDefenderTheta Gen:NN.ZevbaF.34738.jm0@aGmFw2hi
AVG FileRepMetagen [Malware]
Paloalto Clean
CrowdStrike win/malicious_confidence_60% (W)
MaxSecure Trojan.Malware.300983.susgen
No IRMA results available.