Static | ZeroBOX

PE Compile Time

2021-06-18 15:32:47

PE Imphash

ad117fe5e7c2db0809a4efb73b63e0ab

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x00004324 0x00005000 4.59614790806
.data 0x00006000 0x000009f8 0x00001000 0.0
.rsrc 0x00007000 0x00001fa4 0x00002000 3.87705509381

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x000072fc 0x00001ca8 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_GROUP_ICON 0x000072e8 0x00000014 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_VERSION 0x000070f0 0x000001f8 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data

Imports

Library MSVBVM60.DLL:
0x401000 _CIcos
0x401004 _adj_fptan
0x401008 __vbaFreeVar
0x40100c __vbaLateIdCall
0x401010 __vbaFreeVarList
0x401014 _adj_fdiv_m64
0x401018 _adj_fprem1
0x401020 _adj_fdiv_m32
0x401024 __vbaAryDestruct
0x401028 __vbaLateMemSt
0x40102c __vbaForEachCollObj
0x401030 __vbaOnError
0x401034 __vbaObjSet
0x401038 _adj_fdiv_m16i
0x40103c _adj_fdivr_m16i
0x401040 _CIsin
0x401048 None
0x40104c __vbaChkstk
0x401050 __vbaCyVar
0x401054 EVENT_SINK_AddRef
0x40105c __vbaAryConstruct2
0x401060 __vbaVarLateMemSt
0x401064 _adj_fpatan
0x401068 __vbaLateIdCallLd
0x40106c __vbaR8Cy
0x401070 EVENT_SINK_Release
0x401074 _CIsqrt
0x40107c __vbaExceptHandler
0x401080 _adj_fprem
0x401084 _adj_fdivr_m64
0x401088 __vbaFPException
0x40108c __vbaInStrVar
0x401090 __vbaVarCat
0x401094 _CIlog
0x401098 __vbaErrorOverflow
0x40109c __vbaNew2
0x4010a0 _adj_fdiv_m32i
0x4010a4 _adj_fdivr_m32i
0x4010a8 _adj_fdivr_m32
0x4010ac __vbaR8Var
0x4010b0 _adj_fdiv_r
0x4010b4 None
0x4010b8 __vbaI4Var
0x4010bc __vbaLateMemCall
0x4010c0 __vbaFpI4
0x4010c4 __vbaLateMemCallLd
0x4010c8 _CIatan
0x4010cc __vbaCastObj
0x4010d0 _allmul
0x4010d4 _CItan
0x4010d8 _CIexp
0x4010dc __vbaFreeObj

!This program cannot be run in DOS mode.
`.data
MSVBVM60.DLL
HHJdde
WX[`_b
!QRTXXY
DEHlmq
z{|Z[_
[[\z{}vw}
CDIFGM}}
UUYYZ\
ghm347efk
mmo)*3[[]
wx{`af
JJK139xy}
zz|TUYprvuw{
../efg
suy^_b&&,hgi
kko^^b
ZZ\46935<*+2]]]xy}suysuz
\\]9:=efgdde
xy}-.1hhi~~
`bfFGJ
xy~klqtuz
zzz_`e
ffk!!$}
35=FGI``b
LLMvwy
KKO__a}~
zz|efkvw|
TVZ139
PQU()+``b
"#%ddf
&')\\^
779@@C
CDG89?
himbbg
sst^^_
WebBrowser1
SHDocVwCtl.WebBrowser
vb6chs.dll
ReadyState
ieframe.dll
SHDocVwCtl.WebBrowser
WebBrowser
WebBrowser1
^UC:\Windows\SysWOW64\ieframe.oca
SHDocVwCtl
C:\Program Files (x86)\Microsoft Visual Studio\VB98\VB6.OLB
ResizeInit
ResizeForm
VBA6.DLL
__vbaLateIdCall
__vbaNew2
__vbaCastObj
__vbaObjSet
__vbaErrorOverflow
__vbaAryDestruct
__vbaVarLateMemSt
__vbaLateMemCall
__vbaNextEachCollObj
__vbaR8Var
__vbaGenerateBoundsError
__vbaInStrVar
__vbaI4Var
__vbaAryConstruct2
__vbaFreeVarList
__vbaLateMemCallLd
__vbaVarCat
__vbaLateMemSt
__vbaForEachCollObj
__vbaOnError
__vbaFreeVar
__vbaFreeObj
__vbaLateIdCallLd
__vbaCyVar
__vbaR8Cy
__vbaHresultCheckObj
__vbaFpI4
FormName
MSVBVM60.DLL
_CIcos
_adj_fptan
__vbaFreeVar
__vbaLateIdCall
__vbaFreeVarList
_adj_fdiv_m64
_adj_fprem1
__vbaHresultCheckObj
_adj_fdiv_m32
__vbaAryDestruct
__vbaLateMemSt
__vbaForEachCollObj
__vbaOnError
__vbaObjSet
_adj_fdiv_m16i
_adj_fdivr_m16i
_CIsin
__vbaNextEachCollObj
__vbaChkstk
__vbaCyVar
EVENT_SINK_AddRef
__vbaGenerateBoundsError
__vbaAryConstruct2
__vbaVarLateMemSt
_adj_fpatan
__vbaLateIdCallLd
__vbaR8Cy
EVENT_SINK_Release
_CIsqrt
EVENT_SINK_QueryInterface
__vbaExceptHandler
_adj_fprem
_adj_fdivr_m64
__vbaFPException
__vbaInStrVar
__vbaVarCat
_CIlog
__vbaErrorOverflow
__vbaNew2
_adj_fdiv_m32i
_adj_fdivr_m32i
_adj_fdivr_m32
__vbaR8Var
_adj_fdiv_r
__vbaI4Var
__vbaLateMemCall
__vbaFpI4
__vbaLateMemCallLd
_CIatan
__vbaCastObj
_allmul
_CItan
_CIexp
__vbaFreeObj
HHJdde
WX[`_b
!QRTXXY
DEHlmq
z{|Z[_
[[\z{}vw}
CDIFGM}}
UUYYZ\
ghm347efk
mmo)*3[[]
wx{`af
JJK139xy}
zz|TUYprvuw{
../efg
suy^_b&&,hgi
kko^^b
ZZ\46935<*+2]]]xy}suysuz
\\]9:=efgdde
xy}-.1hhi~~
`bfFGJ
xy~klqtuz
zzz_`e
ffk!!$}
35=FGI``b
LLMvwy
KKO__a}~
zz|efkvw|
TVZ139
PQU()+``b
"#%ddf
&')\\^
779@@C
CDG89?
himbbg
sst^^_
http:///
@*\AD:\
Height
http://www.ysbaojia.com:88/web/xiaomishu.html?pid=7616
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
080404B0
CompanyName
X-CHINA
ProductName
FileVersion
ProductVersion
InternalName
OriginalFilename
S2513.exe
Antivirus Signature
Bkav W32.AIDetect.malware1
Elastic malicious (high confidence)
ClamAV Clean
FireEye Gen:Variant.Johnnie.256381
CAT-QuickHeal Clean
McAfee RDN/Generic.hbg
Cylance Clean
VIPRE Clean
Sangfor Riskware.Win32.Wacapew.C
K7AntiVirus Clean
BitDefender Gen:Variant.Johnnie.256381
K7GW Clean
CrowdStrike Clean
Baidu Clean
Cyren Clean
Symantec ML.Attribute.HighConfidence
ESET-NOD32 Clean
APEX Malicious
Avast Win32:Malware-gen
Cynet Malicious (score: 99)
Kaspersky Clean
Alibaba Trojan:Win32/Redcap.dd13cf1a
NANO-Antivirus Clean
ViRobot Clean
AegisLab Trojan.Win32.Johnnie.4!c
MicroWorld-eScan Gen:Variant.Johnnie.256381
Rising Clean
Ad-Aware Gen:Variant.Johnnie.256381
Emsisoft Gen:Variant.Johnnie.256381 (B)
Comodo Clean
F-Secure Clean
DrWeb Trojan.DownLoader28.2464
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition RDN/Generic.hbg
CMC Clean
Sophos Clean
Ikarus Trojan.VB.Crypt
GData Gen:Variant.Johnnie.256381
Jiangmin Clean
MaxSecure Trojan.Malware.300983.susgen
Avira TR/Redcap.mobvb
MAX malware (ai score=83)
Antiy-AVL Clean
Kingsoft Clean
Gridinsoft Trojan.Win32.Downloader.sa
Arcabit Trojan.Johnnie.D3E97D
SUPERAntiSpyware Clean
ZoneAlarm Clean
Microsoft Program:Win32/Wacapew.C!ml
AhnLab-V3 Clean
Acronis Clean
BitDefenderTheta Clean
ALYac Gen:Variant.Johnnie.256381
TACHYON Clean
VBA32 Trojan.Downloader
Malwarebytes Malware.AI.883699089
Panda Clean
Zoner Clean
TrendMicro-HouseCall TROJ_GEN.R002H09FJ21
Tencent Clean
Yandex Clean
SentinelOne Clean
eGambit Unsafe.AI_Score_90%
Fortinet W32/PossibleThreat
Webroot Clean
AVG Win32:Malware-gen
Cybereason malicious.f4850e
Paloalto Clean
Qihoo-360 Clean
No IRMA results available.