Static | ZeroBOX

PE Compile Time

2021-06-22 05:06:11

PE Imphash

f289a4eaac1cee600403f500c75b655b

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x0002a834 0x0002b000 5.0609640334
.data 0x0002c000 0x000011d0 0x00001000 0.0
.rsrc 0x0002e000 0x000009dc 0x00001000 2.20039309384

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x0002e49c 0x00000128 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x0002e49c 0x00000128 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x0002e49c 0x00000128 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_GROUP_ICON 0x0002e46c 0x00000030 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_VERSION 0x0002e150 0x0000031c LANG_ENGLISH SUBLANG_ENGLISH_US data

Imports

Library MSVBVM60.DLL:
0x401000 None
0x401004 _CIcos
0x401008 _adj_fptan
0x40100c __vbaVarMove
0x401010 None
0x401014 __vbaFreeVar
0x401018 __vbaAryMove
0x40101c __vbaStrVarMove
0x401020 None
0x401024 __vbaFreeVarList
0x401028 __vbaEnd
0x40102c _adj_fdiv_m64
0x401030 __vbaFreeObjList
0x401034 _adj_fprem1
0x401038 None
0x40103c __vbaSetSystemError
0x401044 __vbaLenBstrB
0x401048 _adj_fdiv_m32
0x40104c None
0x401050 __vbaAryDestruct
0x401054 __vbaObjSet
0x401058 None
0x40105c _adj_fdiv_m16i
0x401060 __vbaObjSetAddref
0x401064 None
0x401068 _adj_fdivr_m16i
0x40106c None
0x401070 None
0x401074 None
0x401078 None
0x40107c __vbaFpR8
0x401080 _CIsin
0x401084 __vbaChkstk
0x401088 EVENT_SINK_AddRef
0x401090 None
0x401094 __vbaAryConstruct2
0x401098 __vbaI2I4
0x40109c DllFunctionCall
0x4010a0 _adj_fpatan
0x4010a4 __vbaLateIdCallLd
0x4010a8 EVENT_SINK_Release
0x4010ac None
0x4010b0 __vbaUI1I2
0x4010b4 _CIsqrt
0x4010bc __vbaExceptHandler
0x4010c0 _adj_fprem
0x4010c4 _adj_fdivr_m64
0x4010c8 None
0x4010cc None
0x4010d0 __vbaFPException
0x4010d4 None
0x4010d8 _CIlog
0x4010dc None
0x4010e0 __vbaNew2
0x4010e4 __vbaVar2Vec
0x4010e8 _adj_fdiv_m32i
0x4010ec _adj_fdivr_m32i
0x4010f0 __vbaStrCopy
0x4010f4 None
0x4010f8 __vbaFreeStrList
0x4010fc _adj_fdivr_m32
0x401100 _adj_fdiv_r
0x401104 None
0x401108 __vbaVarTstNe
0x40110c __vbaI4Var
0x401110 None
0x401114 __vbaStrToAnsi
0x401118 __vbaVarDup
0x40111c None
0x401120 _CIatan
0x401124 __vbaStrMove
0x401128 _allmul
0x40112c __vbaLateIdSt
0x401130 _CItan
0x401134 _CIexp
0x401138 __vbaFreeObj
0x40113c __vbaFreeStr

!This program cannot be run in DOS mode.
`.data
MSVBVM60.DLL
Amtsdirektrs3
champa
reticency
reticency
Command2
rullemadrassens
Command1
UDVELSENS
Dagliglivs
VENSKABELIGHEDS
Frame1
harmonere
Frame5
Dispersoidological
VB5!6&*
Tragacanthin6
Amtsdirektrs3
Amtsdirektrs3
champa
Kirkesalens5
Command2
C:\Program Files (x86)\Microsoft Visual Studio\VB98\VB6.OLB
Frame5
Frame1
Command1
OffsetClipRgn
advapi32.dll
RegNotifyChangeKeyValue
shlwapi.dll
PathIsNetworkPathA
user32
SubtractRect
kernel32
FindCloseChangeNotification
comctl32.dll
ImageList_Draw
PathAddExtensionA
PathMakePrettyA
Pectunculate
Ungagged
Undowered1
VBA6.DLL
__vbaVar2Vec
__vbaAryMove
__vbaUI1I2
__vbaLenBstrB
__vbaVarDup
__vbaVarTstNe
__vbaAryDestruct
__vbaFreeStrList
__vbaObjSetAddref
__vbaLateIdSt
__vbaI2I4
__vbaVarMove
__vbaGenerateBoundsError
__vbaStrCopy
__vbaEnd
__vbaFreeVarList
__vbaStrVarMove
__vbaSetSystemError
__vbaStrToAnsi
__vbaFreeVar
__vbaFreeObjList
__vbaLateIdCallLd
__vbaI4Var
__vbaFreeStr
__vbaStrMove
__vbaFpR8
__vbaFreeObj
__vbaHresultCheckObj
__vbaNew2
__vbaObjSet
__vbaAryConstruct2
Premodern
Kirkesalens5
ginette
ginette
Premod
u@6EHLy
lbNS}`
Cen{d#
a8k!s!
zqY`F(
y80W#+.
d-Xhm
W!:YSh
PzqX`,
;y[aS>
;y[aS>
G)4Lpu
OczqXm
tXlM:T
yVqR`{ys
.TQuqB
Uzunjz
BzqK3%
a8x"VK
|I5(Tm
8 5i T
%Z+(pCm
Ht 0p@
5|.0[r.
&-aHHda
)WCR|jq.Y`
)aCi|XqeY
Y,0B~qD5
;xDfR>
8L`i`P
QUda{Z
Lpl?\pA
||;@I^
$VVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVV
x))))))))))))))))))))))))))))))))))))
T^{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{
>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>9
9kkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkk
T////////////////////////////////////
D%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%
e7C
)^F'<3333333333333333333333333333333333333
uTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTT
z00000000000000000000000000000000000
EEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEE
@H1rrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrr
OY55555555555555555555555555555555555555
noooooooooooooooooooooooooooooooooooooo
*x\%_jjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjj
999999999999999999999999999999999999
:::::::::::::::::::::::::::::::::::
[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[
zzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzz
FdKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKK
Sarments
RBOENS
jXh0'@
jhh0'@
jdh8<@
jTh8<@
MSVBVM60.DLL
_CIcos
_adj_fptan
__vbaVarMove
__vbaFreeVar
__vbaAryMove
__vbaStrVarMove
__vbaFreeVarList
__vbaEnd
_adj_fdiv_m64
__vbaFreeObjList
_adj_fprem1
__vbaSetSystemError
__vbaHresultCheckObj
__vbaLenBstrB
_adj_fdiv_m32
__vbaAryDestruct
__vbaObjSet
_adj_fdiv_m16i
__vbaObjSetAddref
_adj_fdivr_m16i
__vbaFpR8
_CIsin
__vbaChkstk
EVENT_SINK_AddRef
__vbaGenerateBoundsError
__vbaAryConstruct2
__vbaI2I4
DllFunctionCall
_adj_fpatan
__vbaLateIdCallLd
EVENT_SINK_Release
__vbaUI1I2
_CIsqrt
EVENT_SINK_QueryInterface
__vbaExceptHandler
_adj_fprem
_adj_fdivr_m64
__vbaFPException
_CIlog
__vbaNew2
__vbaVar2Vec
_adj_fdiv_m32i
_adj_fdivr_m32i
__vbaStrCopy
__vbaFreeStrList
_adj_fdivr_m32
_adj_fdiv_r
__vbaVarTstNe
__vbaI4Var
__vbaStrToAnsi
__vbaVarDup
_CIatan
__vbaStrMove
_allmul
__vbaLateIdSt
_CItan
_CIexp
__vbaFreeObj
__vbaFreeStr
FRSTEDELES1
Misapplier1
AEROLITTENS1
curvidentate1
Brnses1)0'
teleteknikere@vandykes.ter0
210621200612Z
220621200612Z0
FRSTEDELES1
Misapplier1
AEROLITTENS1
curvidentate1
Brnses1)0'
teleteknikere@vandykes.ter0
FRSTEDELES1
Misapplier1
AEROLITTENS1
curvidentate1
Brnses1)0'
teleteknikere@vandykes.ter
@I%ga%K
,]j@&25
DEXTRAD
glaserite
Fremskridtskvinder6
Overarouse2
KIMSEDE
Semisuccess
Formalistiske5
Tinkerdom
Hidkald2
formaliser
Overmandedes1
calcine
Antitype
nonresidentor
Repolymerise
Jailbirds2
spndstiges
Fibroferrite5
harmonizers
Roadhouses7
Kontohaveres5
Kanoers4
Aarbogsudgiveren
Marginalizes
HOVEDLINIEN
WINNLE
mizzenmasts
rigiditeten
Disbar2
PLANESHEAR
Alexandr
afriggende
IMMORTALIZATION
Ookinetic
Kriminalkommissrer
Stetikernes3
fedtforbrndende
TRAJECTORY
Ssterpartiet
induced
Neutralisr3
FLATTERY
globussernes
palaeontographical
klargoeringstekniker
RDARVERS
AMPHITHURA
drpladerne
Furring6
checkrail
Lavritzs
Metapolitic5
BAKKETOP
Rulleskjtes4
snrehuls
juleaftensdagenes
Skrupsentimental
Trykfarver6
Machinations4
fngslingskendelsens
Errsyn4
AFFALDSSTOFFERS
enhedstryks
Phrasal
meathead
Larderie3
battsene
enlightenedness
arveberettiget
REVOCABLY
UPCROWD
UNIFORMALLY
brudurterne
Udenvrket
Graphitizing7
TVINGENS
BRUSHTAILED
optjeningens
Pantebrevshandlerne
ACOSMIST
Klerhjelm6
flonellet
OVERSTRAIT
Motific6
Unrelativistic
HALMVISKENES
Sublessor
Noninflationary
Bombarderendes5
ELEUTHEROPETALOUS
Nympholept8
Silanga
Demiurges
Sandvigs5
Animality5
Presbyter5
tilgodeset
Vkstlag
Markedskonomien8
SUPERCOMMENTARY
Moderls2
UNBALING
Urtesuppen1
Pyran5
Herebefore7
Eksamenslokale2
salmesangene
Postelection
CYNOMORIUM
forureningsbelastnings
Poachiness4
Plasticens2
Interblent
Advocatress4
LKKERBISKENEN
BIBCOCKS
Econometrically3
Stavesvagt2
distribuerende
Christophersen6
Singularis6
yessing
Takilman
UNDSLUPNES
Botanize
HISTOPHYSIOLOGICAL
Reservoirers
draggingly
humidifications
GENOPTAGENDE
klikitat
Licencees
professionellestes
untailorlike
TENACY
Haandvaerk3
svigendes
Demonstrationsfrihed7
Vildmarks2
Undulated
collectivities
APOPLEKTIKERENS
PREEMPLOYER
Grusgravene8
DRUGGING
orthologer
Udtapningerne1
MUSIKRADIOERNES
beaander
navlers
Omkostningshensyn9
Bulletinboard6
Etiketteterne3
SEISMOGRAMMET
Spined
Radernaalens
Vandpost
Choloscopy
serologers
Nstenes6
Sinupalliate
Flyttekassen7
Evigtungt
nonsympathetic
Substanceless
SERALBUMINOUS
FARADIZER
KWMIKALIEVIRKSOMHEDS
BRANDSLUKNINGSMATERIELET
KONJAKKERNE
AFGUDSTEMPELETS
Civilisationsniveauer9
Heptachord
forfordelingernes
HANDELSAFTALERS
KRAKOW
Clerkclaude5
PSYCHOPATHY
Hovedindholdenes
Skavejernene7
mossful
luftspringenes
ANTERIOYANCER
CHEAPEN
Emetocathartic4
Venindens
Blnker
stinksvampes
Botanikernes2
antisupernaturalism
domsafsigelses
KKKENHAVE
sublimerende
vgtning
UNMEANDERING
Mitosome
Akvarierne
Psedera1
Fagmands
Genfremstillendes4
Preresolved
FEEDABLE
Thanksgiving
Skokomish7
JUDICIUM
OVERANSTRENGELSER
Isklumper
Bituminised
UDENOMSBEKVEMMELIGHEDERNE
BETEGNELSES
Slidsers
Snylterens5
Frugtbare4
kandidering
Arabism
Beskadiget
Erklringsoplysninger9
Kulturerne
Amatol
Glidende
Firlingefdslerne
Pearl7
Fodboldklub2
Imminence6
DUROMETRE
inspektrens
ANHYDRIDISATION
Tumor4
LVHYTTER
Seerafgifter3
causticize
Gasolinic3
Nonelicited5
TISSEKONES
Spalieredes
Elektriseringerne
Tonefilmgengiverne3
Chalcon
Suricat
krigstjeneste
Eftersaa8
ENGROSHANDLERS
FROGGED
Pengesedlers6
lemonado
INDOPERERET
Solecistical
mikron
gruppelivsforsikringen
judaiser
REGREDERET
knyttelversenes
Aperitiffens
FREMRYKKELSER
Mellemleje3
Overlordship6
Acatalepsia
REFLEXNESS
FORLFTNINGS
bhoosa
Urovarslings
Pines8
MIDTPUNKTETS
Corty4
ASSAGAI
Tskedes
Forundrende
UNCONDITIONATE
Blodtrstigste
STYKSTRRELSEN
HARSKE
Affaldsdyngen5
Semianatropous6
rombeporfyrerne
Seriefremstil
Vehicula3
smedjens
Hoejniveausproget
Precelebrating9
Ogenesis5
Skambenet4
GARNERINGEN
Wineskin4
lokalplanlgningerne
modemkontrollerne
Terminalknude2
Sextodecimos
Yderdr
Stiklagen1
Skjortebrystets
PINDEHUGGERIERNE
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
040904B0
Comments
Ways Force
CompanyName
Ways Force
FileDescription
Ways Force
LegalCopyright
Ways Force
LegalTrademarks
Ways Force
ProductName
Ways Force
FileVersion
ProductVersion
InternalName
Tragacanthin6
OriginalFilename
Tragacanthin6.exe
Antivirus Signature
Bkav W32.AIDetect.malware2
Elastic malicious (high confidence)
ClamAV Clean
CMC Clean
CAT-QuickHeal Clean
ALYac Clean
Malwarebytes Clean
VIPRE Clean
AegisLab Clean
Sangfor Trojan.Win32.Save.a
K7AntiVirus Clean
BitDefender Clean
K7GW Clean
Cybereason Clean
Baidu Clean
Cyren Clean
Symantec Clean
ESET-NOD32 a variant of Win32/Injector.EPOI
APEX Malicious
Paloalto generic.ml
Cynet Malicious (score: 100)
Kaspersky UDS:Backdoor.Win32.Androm
Alibaba Clean
NANO-Antivirus Clean
SUPERAntiSpyware Clean
MicroWorld-eScan Clean
Rising Clean
Ad-Aware Clean
Emsisoft Clean
Comodo Clean
F-Secure Clean
DrWeb Clean
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition Artemis!Trojan
FireEye Generic.mg.88b341b9e1d4b70b
Sophos Clean
SentinelOne Clean
Jiangmin Clean
Webroot Clean
Avira Clean
eGambit Unsafe.AI_Score_99%
MAX Clean
Antiy-AVL Clean
Kingsoft Clean
Microsoft Program:Win32/Wacapew.C!ml
Gridinsoft Clean
Arcabit Clean
ViRobot Clean
ZoneAlarm Clean
GData Clean
AhnLab-V3 Clean
Acronis Clean
McAfee Artemis!88B341B9E1D4
TACHYON Clean
VBA32 Clean
Cylance Unsafe
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Tencent Clean
Yandex Clean
Ikarus Clean
MaxSecure Trojan.Malware.300983.susgen
Fortinet W32/Injector.EPOI!tr
BitDefenderTheta Gen:NN.ZevbaF.34758.lm1@aeYeG9pi
AVG FileRepMalware
Avast FileRepMalware
CrowdStrike Clean
Qihoo-360 Clean
No IRMA results available.