Static | ZeroBOX

PE Compile Time

2015-11-30 11:23:38

PE Imphash

382f852435a4048ee8fd71a8c5cd8667

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x00025d20 0x00026000 6.1551310119
.data 0x00027000 0x00010ed4 0x00001000 0.0
.rsrc 0x00038000 0x00010b9c 0x00011000 3.7827909336

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x000380e8 0x00010828 LANG_NEUTRAL SUBLANG_NEUTRAL dBase III DBT, version number 0, next free block index 40
RT_GROUP_ICON 0x00048910 0x00000014 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_VERSION 0x00048924 0x00000278 LANG_ENGLISH SUBLANG_ENGLISH_US data

Imports

Library MSVBVM60.DLL:
0x401000 None
0x401004 _CIcos
0x401008 _adj_fptan
0x40100c __vbaVarMove
0x401010 __vbaFreeVar
0x401014 __vbaAryMove
0x401018 __vbaLenBstr
0x40101c __vbaStrVarMove
0x401020 __vbaFreeVarList
0x401024 _adj_fdiv_m64
0x401028 None
0x40102c __vbaFreeObjList
0x401030 None
0x401034 _adj_fprem1
0x401038 None
0x40103c None
0x401040 __vbaSetSystemError
0x401048 __vbaLenBstrB
0x40104c None
0x401050 _adj_fdiv_m32
0x401054 None
0x401058 __vbaAryDestruct
0x40105c __vbaBoolStr
0x401060 __vbaOnError
0x401064 __vbaObjSet
0x401068 None
0x40106c _adj_fdiv_m16i
0x401070 __vbaObjSetAddref
0x401074 _adj_fdivr_m16i
0x401078 __vbaCyStr
0x40107c __vbaFpR8
0x401080 __vbaVarTstLt
0x401084 _CIsin
0x401088 __vbaChkstk
0x40108c EVENT_SINK_AddRef
0x401090 None
0x401094 __vbaStrCmp
0x401098 __vbaVarTstEq
0x40109c __vbaObjVar
0x4010a0 DllFunctionCall
0x4010a4 None
0x4010a8 None
0x4010ac _adj_fpatan
0x4010b0 __vbaLateIdCallLd
0x4010b4 EVENT_SINK_Release
0x4010b8 None
0x4010bc __vbaUI1I2
0x4010c0 _CIsqrt
0x4010c8 __vbaFpCmpCy
0x4010cc __vbaExceptHandler
0x4010d0 None
0x4010d4 None
0x4010d8 _adj_fprem
0x4010dc _adj_fdivr_m64
0x4010e0 None
0x4010e4 None
0x4010e8 __vbaFPException
0x4010ec __vbaInStrVar
0x4010f0 __vbaStrVarVal
0x4010f4 None
0x4010f8 _CIlog
0x4010fc __vbaFileOpen
0x401100 __vbaNew2
0x401104 __vbaInStr
0x401108 __vbaVar2Vec
0x40110c None
0x401110 _adj_fdiv_m32i
0x401114 _adj_fdivr_m32i
0x401118 __vbaStrCopy
0x40111c None
0x401120 __vbaFreeStrList
0x401124 _adj_fdivr_m32
0x401128 _adj_fdiv_r
0x40112c None
0x401130 __vbaVarTstNe
0x401134 __vbaI4Var
0x401138 None
0x40113c None
0x401140 __vbaLateMemCall
0x401144 __vbaVarAdd
0x401148 __vbaVarDup
0x40114c __vbaStrComp
0x401150 __vbaStrToAnsi
0x401154 __vbaFpI4
0x401158 __vbaLateMemCallLd
0x40115c _CIatan
0x401160 None
0x401164 __vbaStrMove
0x401168 _allmul
0x40116c __vbaLateIdSt
0x401170 _CItan
0x401174 __vbaFPInt
0x401178 _CIexp
0x40117c __vbaFreeStr
0x401180 __vbaFreeObj
0x401184 None

!This program cannot be run in DOS mode.
`.data
MSVBVM60.DLL
kremationer
Forledelsen2
REAGAN
y{@9
3#_eY Fr
]fx1#e
+Dk"<"
06ljw_
SJ47RW
=MQf=,%
+xYbDk
m:"Ad(=*
}7jeC!
@hd|45
y[GY**
o(]72+
Ji+}I,~n
Y;g5[+
GkY$#r
Y5s:<^
t! UUP/_
rRh6rzh
9:$L7W
5yBm5s
;O3yq
(''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''
C88888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888
B"""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""
z*BBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBB
AYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYH
77777777777777777777777777777777777777777777777777777777777777777777777777777777777
O}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}
'ttttttttttttttttttttttttttttttttttttttttttttttttttttttttttttttttttttttttttttttttttt
---------------------------------------------------------------------------------
iiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiih
IAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
Xh#< <<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<
rrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrr
,ggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggggg
r'''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''
~]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]
3333333333333333333333333333333333333333333333333333333333333333333333333333333333
o|1111111111111111111111111111111111111111111111111111111111111111111111111111111111111
QUV !
QUV&((
REAGAN
VITHUSS
Dyremedicin8
Handicuff6
Samplingshastigheden
Flicky
Proportionsforvrngningerne
Tartufian3
Text12
VENEROLOGI
Text11
skatteyderen
VB5!6&*
ligaturing
kremationer
kremationer
yB&,vG
kremationer
Forledelsen2
Byggemodningerne7
BANKOSPILLETS
Korrigerendes1
Trosbekendelser4
FOLKEEVENTYRENE
OFFICIALVIRKSOMHEDER
hyperabsorption
Aarstalslistens
Celom6
Alkalisable9
bandon
arthrobranchia
TROLDDOMSKRAFTS
sulter
agaves
Salgssekretrs1
Dekomponerende
Buttocks
futuristerne
SNATHES
Jyllandstures9
Enetalens9
Dependens9
medlars
HYPHANTRIA
recancellation
valorising
Solitudinem
Ordgyderis4
Mistillidens8
Raamlk
Boutiquers3
Reaktion
Teksteren7
C:\Program Files (x86)\Microsoft Visual Studio\VB98\VB6.OLB
Text11
Text12
mpr.dll
WNetAddConnection2A
user32.dll
GetGuiResources
user32
TranslateMessage
Stillevejene6
Advapi32
AllocateAndInitializeSid
advapi32.dll
GetAclInformation
kernel32
ExitProcess
shell32
SHGetPathFromIDList
DdeInitializeA
firkanten
MoveToEx
netapi32
NetApiBufferFree
DestroyCursor
economy
smaaartikler
Pyrenomycetineae
Anallagmatis
Afkbende7
sangundervisningernes
SKNMALERIET
FREIJO
PASSIM
Multani
Baconises1
VBA6.DLL
__vbaLateMemCallLd
__vbaVarTstLt
__vbaVarAdd
__vbaStrVarMove
__vbaFreeStrList
__vbaStrToAnsi
__vbaInStrVar
__vbaUI1I2
__vbaSetSystemError
__vbaLenBstr
__vbaStrComp
__vbaLateMemCall
__vbaFileOpen
gLZ__vbaBoolStr
__vbaObjVar
__vbaVarDup
__vbaCyStr
__vbaFpCmpCy
x__vbaAryDestruct
__vbaVar2Vec
__vbaAryMove
__vbaLenBstrB
__vbaLateIdCallLd
__vbaI4Var
__vbaInStr
__vbaObjSet
__vbaFreeObjList
__vbaLateIdSt
__vbaFpI4
__vbaStrCmp
__vbaStrMove
__vbaObjSetAddref
__vbaStrVarVal
__vbaVarTstNe
__vbaVarTstEq
__vbaFreeObj
__vbaNew2
__vbaFreeStr
__vbaOnError
__vbaStrCopy
__vbaFreeVarList
__vbaFreeVar
__vbaVarMove
__vbaHresultCheckObj
__vbaFPInt
__vbaFpR8
yB&,vG
hYT~JN
agaves
KARDUSER
KARDUSER
medlars
nylonen
nylonen
sulter
EJERTID
EJERTID
Polakken8
Polakken8
bandon
Maniva5
Maniva5
Raamlk
Acrylics9
Acrylics9
hyperabsorption
BESGES
BESGES
TROLDDOMSKRAFTS
Solitudinem
afkrsler
afkrsler
valorising
Thirlage
Thirlage
Buttocks
UGEAVISENS
UGEAVISENS
futuristerne
Termites9
Termites9
Boutiquers3
Forskanses
Forskanses
Jyllandstures9
baaltale
baaltale
Aarstalslistens
SNADDERS
SNADDERS
Enetalens9
Vasiferous
Vasiferous
Mistillidens8
Cresting8
Cresting8
Dependens9
STOFMASSEN
STOFMASSEN
Trosbekendelser4
CATKIN
CATKIN
Ordgyderis4
gavstriks
gavstriks
BANKOSPILLETS
remplaceret
remplaceret
Celom6
UNATURLIGHEDERNE
UNATURLIGHEDERNE
SNATHES
SPECIALTASTERNES
SPECIALTASTERNES
recancellation
lipomatosis
lipomatosis
Reaktion
antependiernes
antependiernes
Teksteren7
unattemptable
unattemptable
HYPHANTRIA
DDEMANDSSIKRINGER
DDEMANDSSIKRINGER
FOLKEEVENTYRENE
Velmagtstiderne
Velmagtstiderne
Alkalisable9
Impermeabilities
Impermeabilities
Salgssekretrs1
dissimilationerne
dissimilationerne
arthrobranchia
landvsenskommisionen
landvsenskommisionen
Dekomponerende
KRIGSMINISTERIERNES
KRIGSMINISTERIERNES
yB&,vG
OFFICIALVIRKSOMHEDER
HAANDARBEJDERNES
HAANDARBEJDERNES
Byggemodningerne7
Protransubstantiation
Protransubstantiation
Korrigerendes1
STVKONSEKVENSOMRAADERNES
STVKONSEKVENSOMRAADERNES
VIRKSOMHEDSSKATTELOVS
Smrtyve4
Panteforskrivningers1
capocchia
Attribuerede2
BLACKBERRYLIKE
Reteam
Udlsendes
Anonyms
Usympatiskes
isafklendes
Tavshedspligts
adresselst
CRACKLE
Middelmaadige5
Konflikttilstandenes
Cerium
Expendable4
skuddags
Elementrvidens
ufordjedes
TARVELIGERE
Intercrust
Misbrew
Multiserver8
ALMENDANNELSEN
Pightel
uncleaner
slring
frakkekraver
UNSERVILELY
dokumenttypens
Anthropophagize7
BITTERWORT
Vagtstyrkes4
Hoejadel
Nullinje
Terminalfacilitet7
criticalness
rubiner
Hjemgivelse8
Vareprsentation9
Brandfries
Ronvon7
Bnkhamrene
launderette
chalcedonic
Insolventes
Dillies9
Ortalis5
ACARICIDAL
Epimyth
Hearkened5
RANDINGER
Majkattenes6
Miljomraades6
Sulkene2
SYLLABUSES
NSKEBARN
MSVBVM60.DLL
_CIcos
_adj_fptan
__vbaVarMove
__vbaFreeVar
__vbaAryMove
__vbaLenBstr
__vbaStrVarMove
__vbaFreeVarList
_adj_fdiv_m64
__vbaFreeObjList
_adj_fprem1
__vbaSetSystemError
__vbaHresultCheckObj
__vbaLenBstrB
_adj_fdiv_m32
__vbaAryDestruct
__vbaBoolStr
__vbaOnError
__vbaObjSet
_adj_fdiv_m16i
__vbaObjSetAddref
_adj_fdivr_m16i
__vbaCyStr
__vbaFpR8
__vbaVarTstLt
_CIsin
__vbaChkstk
EVENT_SINK_AddRef
__vbaStrCmp
__vbaVarTstEq
__vbaObjVar
DllFunctionCall
_adj_fpatan
__vbaLateIdCallLd
EVENT_SINK_Release
__vbaUI1I2
_CIsqrt
EVENT_SINK_QueryInterface
__vbaFpCmpCy
__vbaExceptHandler
_adj_fprem
_adj_fdivr_m64
__vbaFPException
__vbaInStrVar
__vbaStrVarVal
_CIlog
__vbaFileOpen
__vbaNew2
__vbaInStr
__vbaVar2Vec
_adj_fdiv_m32i
_adj_fdivr_m32i
__vbaStrCopy
__vbaFreeStrList
_adj_fdivr_m32
_adj_fdiv_r
__vbaVarTstNe
__vbaI4Var
__vbaLateMemCall
__vbaVarAdd
__vbaVarDup
__vbaStrComp
__vbaStrToAnsi
__vbaFpI4
__vbaLateMemCallLd
_CIatan
__vbaStrMove
_allmul
__vbaLateIdSt
_CItan
__vbaFPInt
_CIexp
__vbaFreeStr
__vbaFreeObj
zzz;VVVxAAA
Flatworks5
parmack
pantehftelsens
Desmon
Debitorkontoen
GALACTOPHAGOUS
Torilis2
Detektions
yellowammer
Loliginidae7
HENROOST
taffelbjerget
OPRYKKERENS
ansgningsfristens
Saltiness7
AFSKRKKELSES
Mandskabet
TRKKERDRENGES
squattiness
Afledningssystem7
Minimumshjdes
unfunereal
Strmkntrings9
MRpRWgPXQohtZZvTBNsh06d7mJsf239
TROCHIL
Forgrenede
Asiatically
FLAGELLATAE
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
040904B0
Comments
Sneeze
CompanyName
Sneeze
FileDescription
Sneeze
ProductName
Sneeze
FileVersion
ProductVersion
InternalName
ligaturing
OriginalFilename
ligaturing.exe
Antivirus Signature
Bkav W32.AIDetect.malware1
Lionic Clean
Elastic malicious (high confidence)
MicroWorld-eScan Clean
FireEye Generic.mg.4f71bce958bbbe6c
CAT-QuickHeal Clean
Qihoo-360 HEUR/QVM03.0.C39B.Malware.Gen
McAfee Artemis!4F71BCE958BB
Cylance Clean
VIPRE Clean
Sangfor Trojan.Win32.Save.a
K7AntiVirus Clean
BitDefender Clean
K7GW Clean
Cybereason Clean
Baidu Clean
Cyren Clean
Symantec Clean
ESET-NOD32 Clean
APEX Malicious
Paloalto generic.ml
ClamAV Clean
Kaspersky UDS:DangerousObject.Multi.Generic
Alibaba Clean
NANO-Antivirus Clean
ViRobot Clean
Rising Clean
Ad-Aware Clean
Sophos ML/PE-A
Comodo Clean
F-Secure Clean
DrWeb Clean
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition BehavesLike.Win32.Swisyn.dm
CMC Clean
Emsisoft Clean
SentinelOne Static AI - Malicious PE
GData Clean
Jiangmin Clean
Webroot Clean
Avira Clean
MAX Clean
Antiy-AVL Clean
Kingsoft Clean
Gridinsoft Clean
Arcabit Clean
SUPERAntiSpyware Clean
ZoneAlarm UDS:DangerousObject.Multi.Generic
Microsoft Trojan:Win32/Fareit!ml
Cynet Clean
AhnLab-V3 Clean
Acronis Clean
BitDefenderTheta Gen:NN.ZevbaF.34050.om0@aaWyrvni
ALYac Clean
TACHYON Clean
VBA32 Clean
Malwarebytes Clean
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Tencent Clean
Yandex Clean
Ikarus Clean
eGambit Unsafe.AI_Score_99%
Fortinet Clean
AVG FileRepMalware
Avast FileRepMalware
CrowdStrike win/malicious_confidence_90% (W)
MaxSecure Clean
No IRMA results available.