Static | ZeroBOX

PE Compile Time

2012-09-14 21:13:06

PE Imphash

d4ddbfb32d829f09195ac39344cde3ef

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x00032de8 0x00033000 4.50567970742
.data 0x00034000 0x00000b70 0x00001000 0.0
.rsrc 0x00035000 0x000070d2 0x00008000 4.00912121931

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x000356b2 0x00000988 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_ICON 0x000356b2 0x00000988 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_ICON 0x000356b2 0x00000988 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_ICON 0x000356b2 0x00000988 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_ICON 0x000356b2 0x00000988 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_ICON 0x000356b2 0x00000988 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_ICON 0x000356b2 0x00000988 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_ICON 0x000356b2 0x00000988 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_ICON 0x000356b2 0x00000988 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_ICON 0x000356b2 0x00000988 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_ICON 0x000356b2 0x00000988 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_ICON 0x000356b2 0x00000988 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_GROUP_ICON 0x00035604 0x000000ae LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_VERSION 0x00035300 0x00000304 LANG_ENGLISH SUBLANG_ENGLISH_US data

Imports

Library MSVBVM60.DLL:
0x401000 None
0x401004 _CIcos
0x401008 _adj_fptan
0x40100c __vbaVarMove
0x401010 __vbaFreeVar
0x401014 __vbaStrVarMove
0x401018 __vbaFreeVarList
0x40101c __vbaEnd
0x401020 _adj_fdiv_m64
0x401024 None
0x401028 _adj_fprem1
0x40102c __vbaStrCat
0x401030 None
0x401034 __vbaSetSystemError
0x401038 None
0x401040 None
0x401044 _adj_fdiv_m32
0x401048 __vbaAryDestruct
0x40104c None
0x401050 None
0x401054 _adj_fdiv_m16i
0x401058 _adj_fdivr_m16i
0x40105c None
0x401060 _CIsin
0x401064 __vbaChkstk
0x401068 __vbaFileClose
0x40106c EVENT_SINK_AddRef
0x401070 __vbaStrCmp
0x401074 __vbaAryConstruct2
0x401078 None
0x40107c DllFunctionCall
0x401080 _adj_fpatan
0x401084 None
0x401088 EVENT_SINK_Release
0x40108c None
0x401090 _CIsqrt
0x401098 None
0x40109c __vbaExceptHandler
0x4010a0 _adj_fprem
0x4010a4 _adj_fdivr_m64
0x4010a8 __vbaFPException
0x4010ac None
0x4010b0 __vbaI2Var
0x4010b4 _CIlog
0x4010b8 __vbaNew2
0x4010bc __vbaInStr
0x4010c0 _adj_fdiv_m32i
0x4010c4 _adj_fdivr_m32i
0x4010c8 __vbaStrCopy
0x4010cc __vbaFreeStrList
0x4010d0 None
0x4010d4 _adj_fdivr_m32
0x4010d8 _adj_fdiv_r
0x4010dc None
0x4010e0 __vbaVarTstNe
0x4010e4 None
0x4010e8 None
0x4010ec __vbaStrToAnsi
0x4010f0 __vbaVarDup
0x4010f4 None
0x4010f8 None
0x4010fc _CIatan
0x401100 __vbaStrMove
0x401104 __vbaUI1Str
0x401108 _allmul
0x40110c __vbaLateIdSt
0x401110 _CItan
0x401114 None
0x401118 _CIexp
0x40111c __vbaFreeStr
0x401120 __vbaFreeObj

!This program cannot be run in DOS mode.
`.data
MSVBVM60.DLL
Uninter
jUOKKCDci
sOKKKKK
KKKKKKK0#q
dKKKKKK
KKKKKKKKKK4 ^
fKKKKKKKKKCAisOKKKKKKKK-
KKKKK- v
KKKKKKKK0
KKKKKKKKK+
KKKKKKKK0
KKKKKKKKK+
kKKKKKKKK-
KKKKKKKKK6$<
KKKKKKKKK+
OKKKKKKKKK+
dKKKKKKKKE$8
fKKKKKKKKKE%"
KKKKKKKKK+
KKKKKKKKKK-
KKKKKKKKKE%"
dKKKKKK
OKKKKKKKKK+
KKKKKKKKKKK%
dKKKKKKKKK4
sKKKKKKKKKLE$8
kKKKKKKKKKE%
OKKKKKKKKKK
KKKKKKKKKK+
KKKKKKKKKKK-
KKKKKKKKKO
KKKKKKKKKKK-
KKKKKKKKOO4
jKKKKKKKKKKK+
KKKKKKKOOQE%"
OKKKKKKKKKKK+
KKKKKKQQQQK%
KKKKKKKKKKKO%
KKKKKQQQQQQ%
KKKKKKKKKQQQ%
KKKOQQQQQQQ%
KKKOQQQQ%
QQQQQQ+
KKKKKKOQQQQQ%
QQQQQQQQQQQ+
KKKKKOQQQQQQ%
QQQQQQLQQQQ+
KKKKOQQQQQQQ%
QQQQQQQ
KKKKQUUUUUUQ%
UUUUUUUUUUQ+
KKKQUUUUUUUU%
UUUUUUUUUUQ%
KKOUUUUUUUUU%
UUUUUUUUUUQ%
UKQUUUUUUUUU+
UUUUUUUUUUQ%
LkOUUUUUUUUUU+
UUUUUUUUUUL$9
QZZZZZZZZZZ1
ZZZZZZZZZZE
ZZZZZZZZZZZ4
ZZZZZZZZZZ1
yZZZZZZZ
ZZZZZZZZZZ+
yyyyyyyyyyL$;
yyyyyyyyyQ%
yyyyyyyyyLQ%
yyyyyyyyyE
yyyyyyyyy
yyyyyyyyy+
yyyyyyyyyy1
yyyyyyyyyQ%
yyyyyyyyyL
yyyyyyyyy1
yyyyyyyyyZ%
yyyQ%"
yyyyyyyyy4
[R8447OZ
;44444444442"\
w844442
844442
444444
444442
444444%
;44444!+
;444444LY
u444444
4444442
444444!
;444444%
4444442
4444444!*
4444444
w4444444
8444448!I
U4444444
;44448<
84444444
R444<<<(
4444448<
T44<<<<2
44444<<<
U<<<<<<2
4444<<<<
kI<<<<<Q
444<<<<<
k<<<<<<4
44<@@@@@
88@@@@@@
i@@@@@@2
T<@@@@@@
@@@@@%
uBBBBBBB
aBBBBBB$G
BBBBBBB
aaaaaaa(
aaaaaa<
yaaaaaa6
aQaaaa2
aaaaaaB
aaaaaa
aaaaaa!L
paaaaa6
ddddd!L
pdddda!_
ggggd<Q
ynggggggggg-N
ysQkht
U<+&&)=
`+&&&;&&&&
?&&&&&
&&&&&!
d&&&&&
Y&&&+,
W&&,,,
,,,,,!7
W&+,,,
,,,,,!9
a&0000!@
I00000QC
,0000!9
03333'4
LJJ3J,
dJJJJ3
JJJJ'4
JJJJ'9
VOOOJQOOO*5
gZVRQT^
Uninter
Combo4
forbudst
Combo3
Combo2
ARBEJDSM
Combo1
Stormgti
Check8
cumbro
Check7
UNAIRILYM
Check6
Check5
Prespecif1
Check4
Fabri5
Check3
Udsynets8
Check2
besmrelse
Check1
Smaakaa4
Command2
sammenfo
Command1
Seksua9
VScroll1
HScroll1
Marcon
Text21
svanekniv
Text22
HKLINGERM
Text23
Text24
crapula
Unsmokyt1
ME6[+H
J[UPV7
|KK[9n
`UxVLuGR
|N9_1n3s
3aYlKYU
mr{|?H
se/JK_
jUxVEl
|rNQwp
&ir>*/
+!a&9r
UxVQ~Q
|J|_;N
|JZ<a1
|KK_#Z
KU;"U~^
hEH6=T
hJJ<s2
|r`x"r
JKUHV1
LsUxVi
AUHV;04
KZUHVe|
J@UHVe
KQUxVDO
|r`Ba|
F3NQxs
zb_jeb
|rvc|z
|raryr
$k-B_Q
|KB=ps
|ra/Nr
|Jf_8V
wUHV,8
<Jo_1n
JQ_1j3
aca6wr
uM$%5yq_W
SA>hZO.yIc
Db;EG0
/s#[!T
t5@:tr
(g-F8c
_-0,v2
_-0,v2
NPG\ /
c26cfd
tKY] V
<{tT<{
6Tx^*JX_
KIUHV=
PUxVLV
|:1l|r
!kdBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBB
o''''''''''''''''''''''''''''''''''''''''''
Ezzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzz
"rq,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,
yyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyy
=YYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYf
MMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMM
T""""""""""""""""""""""""""""""""""""""""
/eCYp!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!
J{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{=
{ eiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiii
{UUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUU
eeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeee
=======================================
922222222222222222222222222222222222222222
/;OOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOO
F4444444444444444444444444444444444444444444-/
O{>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>
A\999999999999999999999999999999999999999999=
0oooooooooooooooooooooooooooooooooooooo
Gddddddddddddddddddddddddddddddddddddddd
{+####################################
ZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZ
|ccccccccccccccccccccccccccccccccccccccc
(CCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCC
O:::::::::::::::::::::::::::::::::::::::
w|////////////////////////////////////////
@muuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuu
Mzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzz
hTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTT
uKCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCC
.........................................
??????????????????????????????????????
)))))))))))))))))))))))))))))))))))))))))
``````````````````````````````````````````
mmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmm
YFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF
WWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWW
sAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
Xy &&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&
wiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiii
;-hhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhh
^WHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHH
<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<
0xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
bXttttttttttttttttttttttttttttttttttttttttttt
888888888888888888888888888888888888888
ggggggggggggggggggggggggggggggggggggggg
(ecxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
+bbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbb
H|||||||||||||||||||||||||||||||||||||||
Kbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbb
PPPPPPPPPPPPPPPPPPPPPPPPPPPPPPPPPPPPPPPPPPPPP
VB5!6%*
RADIOEL
Programch4
AVISLSER
SKATTEFR
C:\Program Files (x86)\Microsoft Visual Studio\VB98\VB6.OLB
VScroll1
Text23
Text24
Command1
Text21
Command2
Text22
Check1
Check6
Check7
Check8
Check2
Check3
Check4
Check5
Combo4
Combo2
Combo3
Combo1
HScroll1
Unsmokyt1
kernel32
GetTempPathA
user32
DestroyCursor
advapi32.dll
GetFileSecurityA
GetTickCount
GetMenuItemRect
Uncellar
VBA6.DLL
__vbaFreeStrList
__vbaStrCmp
__vbaEnd
__vbaLateIdSt
__vbaUI1Str
__vbaAryDestruct
__vbaVarMove
__vbaVarDup
__vbaStrToAnsi
__vbaSetSystemError
__vbaI2Var
__vbaFileClose
__vbaStrCopy
__vbaFreeVarList
__vbaStrVarMove
__vbaInStr
__vbaFreeObj
__vbaHresultCheckObj
__vbaNew2
__vbaFreeVar
__vbaVarTstNe
__vbaFreeStr
__vbaStrCat
__vbaStrMove
__vbaAryConstruct2
Belusket2
Adenocystomatous
Mlleri
MSVBVM60.DLL
_CIcos
_adj_fptan
__vbaVarMove
__vbaFreeVar
__vbaStrVarMove
__vbaFreeVarList
__vbaEnd
_adj_fdiv_m64
_adj_fprem1
__vbaStrCat
__vbaSetSystemError
__vbaHresultCheckObj
_adj_fdiv_m32
__vbaAryDestruct
_adj_fdiv_m16i
_adj_fdivr_m16i
_CIsin
__vbaChkstk
__vbaFileClose
EVENT_SINK_AddRef
__vbaStrCmp
__vbaAryConstruct2
DllFunctionCall
_adj_fpatan
EVENT_SINK_Release
_CIsqrt
EVENT_SINK_QueryInterface
__vbaExceptHandler
_adj_fprem
_adj_fdivr_m64
__vbaFPException
__vbaI2Var
_CIlog
__vbaNew2
__vbaInStr
_adj_fdiv_m32i
_adj_fdivr_m32i
__vbaStrCopy
__vbaFreeStrList
_adj_fdivr_m32
_adj_fdiv_r
__vbaVarTstNe
__vbaStrToAnsi
__vbaVarDup
_CIatan
__vbaStrMove
__vbaUI1Str
_allmul
__vbaLateIdSt
_CItan
_CIexp
__vbaFreeStr
__vbaFreeObj
U<+&&)=
`+&&&;&&&&
?&&&&&
&&&&&!
d&&&&&
Y&&&+,
W&&,,,
,,,,,!7
W&+,,,
,,,,,!9
a&0000!@
I00000QC
,0000!9
03333'4
LJJ3J,
dJJJJ3
JJJJ'4
JJJJ'9
VOOOJQOOO*5
gZVRQT^
[R8447OZ
;44444444442"\
w844442
844442
444444
444442
444444%
;44444!+
;444444LY
u444444
4444442
444444!
;444444%
4444442
4444444!*
4444444
w4444444
8444448!I
U4444444
;44448<
84444444
R444<<<(
4444448<
T44<<<<2
44444<<<
U<<<<<<2
4444<<<<
kI<<<<<Q
444<<<<<
k<<<<<<4
44<@@@@@
88@@@@@@
i@@@@@@2
T<@@@@@@
@@@@@%
uBBBBBBB
aBBBBBB$G
BBBBBBB
aaaaaaa(
aaaaaa<
yaaaaaa6
aQaaaa2
aaaaaaB
aaaaaa
aaaaaa!L
paaaaa6
ddddd!L
pdddda!_
ggggd<Q
ynggggggggg-N
ysQkht
jUOKKCDci
sOKKKKK
KKKKKKK0#q
dKKKKKK
KKKKKKKKKK4 ^
fKKKKKKKKKCAisOKKKKKKKK-
KKKKK- v
KKKKKKKK0
KKKKKKKKK+
KKKKKKKK0
KKKKKKKKK+
kKKKKKKKK-
KKKKKKKKK6$<
KKKKKKKKK+
OKKKKKKKKK+
dKKKKKKKKE$8
fKKKKKKKKKE%"
KKKKKKKKK+
KKKKKKKKKK-
KKKKKKKKKE%"
dKKKKKK
OKKKKKKKKK+
KKKKKKKKKKK%
dKKKKKKKKK4
sKKKKKKKKKLE$8
kKKKKKKKKKE%
OKKKKKKKKKK
KKKKKKKKKK+
KKKKKKKKKKK-
KKKKKKKKKO
KKKKKKKKKKK-
KKKKKKKKOO4
jKKKKKKKKKKK+
KKKKKKKOOQE%"
OKKKKKKKKKKK+
KKKKKKQQQQK%
KKKKKKKKKKKO%
KKKKKQQQQQQ%
KKKKKKKKKQQQ%
KKKOQQQQQQQ%
KKKOQQQQ%
QQQQQQ+
KKKKKKOQQQQQ%
QQQQQQQQQQQ+
KKKKKOQQQQQQ%
QQQQQQLQQQQ+
KKKKOQQQQQQQ%
QQQQQQQ
KKKKQUUUUUUQ%
UUUUUUUUUUQ+
KKKQUUUUUUUU%
UUUUUUUUUUQ%
KKOUUUUUUUUU%
UUUUUUUUUUQ%
UKQUUUUUUUUU+
UUUUUUUUUUQ%
LkOUUUUUUUUUU+
UUUUUUUUUUL$9
QZZZZZZZZZZ1
ZZZZZZZZZZE
ZZZZZZZZZZZ4
ZZZZZZZZZZ1
yZZZZZZZ
ZZZZZZZZZZ+
yyyyyyyyyyL$;
yyyyyyyyyQ%
yyyyyyyyyLQ%
yyyyyyyyyE
yyyyyyyyy
yyyyyyyyy+
yyyyyyyyyy1
yyyyyyyyyQ%
yyyyyyyyyL
yyyyyyyyy1
yyyyyyyyyZ%
yyyQ%"
yyyyyyyyy4
C:\Program Files (x86)\Administrator-Cloud\Projects\RADIOEL.pdb
COALIS1
scienti1
Manus1
SKJO1!0
ammobes@Undemon.KA0
210729080045Z
220729080045Z0
COALIS1
scienti1
Manus1
SKJO1!0
ammobes@Undemon.KA0
^>Lf-N
COALIS1
scienti1
Manus1
SKJO1!0
ammobes@Undemon.KA
20210729080046Z
DigiCert Inc1
www.digicert.com110/
(DigiCert SHA2 Assured ID Timestamping CA0
210101000000Z
310106000000Z0H1
DigiCert, Inc.1 0
DigiCert Timestamp 20210
http://www.digicert.com/CPS0
,http://crl3.digicert.com/sha2-assured-ts.crl02
,http://crl4.digicert.com/sha2-assured-ts.crl0
http://ocsp.digicert.com0O
Chttp://cacerts.digicert.com/DigiCertSHA2AssuredIDTimestampingCA.crt0
QJxy6z'
dwc_#Ri
DigiCert Inc1
www.digicert.com1$0"
DigiCert Assured ID Root CA0
160107120000Z
310107120000Z0r1
DigiCert Inc1
www.digicert.com110/
(DigiCert SHA2 Assured ID Timestamping CA0
fnVa')
http://ocsp.digicert.com0C
7http://cacerts.digicert.com/DigiCertAssuredIDRootCA.crt0
4http://crl4.digicert.com/DigiCertAssuredIDRootCA.crl0:
4http://crl3.digicert.com/DigiCertAssuredIDRootCA.crl0P
https://www.digicert.com/CPS0
8aMbF$
V3"/"6
DigiCert Inc1
www.digicert.com110/
(DigiCert SHA2 Assured ID Timestamping CA
210729080046Z0+
5[.y7Z`
/1(0&0$0"
TIfb7~
TANHOUSENISTHAL
Cracidaeholistsunr
Kildedesrapieredkontroller5
unnaturalismtanglopp
frigjortesplu
DISCOMFITER
Varmekilder6
Luftskibes4
CELSIUSTERMOMETERETS
teltnings
spejderlejre
Generosities
Raahusenes2
Prangeren
DEGRESSIVELY
Tarentine9
Storebltsfrgen7
prewarrant
Takistoskopernes9
BOMBABLE
belier
maieutics
Arthropod
Jomfruhummerens
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
040904B0
Comments
Joule space
CompanyName
Joule space
FileDescription
Joule space
LegalCopyright
Joule space
LegalTrademarks
Joule space
ProductName
Joule space
FileVersion
ProductVersion
InternalName
RADIOEL
OriginalFilename
RADIOEL.exe
Antivirus Signature
Bkav Clean
Lionic Trojan.Multi.Generic.4!c
Elastic malicious (high confidence)
MicroWorld-eScan Trojan.GenericKD.46706431
FireEye Generic.mg.1f563d126e328d5f
CAT-QuickHeal Clean
ALYac Clean
Cylance Unsafe
VIPRE Clean
Sangfor Clean
K7AntiVirus Clean
BitDefender Trojan.GenericKD.46706431
K7GW Clean
Cybereason Clean
Baidu Clean
Cyren Clean
Symantec ML.Attribute.HighConfidence
ESET-NOD32 Clean
APEX Malicious
Paloalto generic.ml
ClamAV Clean
Kaspersky Trojan.Win32.Vebzenpak.agdh
Alibaba Clean
NANO-Antivirus Clean
ViRobot Clean
Tencent Clean
Ad-Aware Trojan.GenericKD.46706431
Sophos ML/PE-A
F-Secure Clean
DrWeb Clean
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition PWS-FCZK!1F563D126E32
MaxSecure Clean
CMC Clean
Emsisoft Trojan.GenericKD.46706431 (B)
SentinelOne Static AI - Suspicious PE
GData Trojan.GenericKD.46706431
Jiangmin Clean
Webroot Clean
Avira Clean
MAX Clean
Antiy-AVL Clean
Kingsoft Win32.Troj.Generic_a.a.(kcloud)
Gridinsoft Clean
Arcabit Clean
SUPERAntiSpyware Clean
ZoneAlarm Clean
Microsoft Trojan:Win32/Wacatac.B!ml
Cynet Malicious (score: 100)
AhnLab-V3 Clean
Acronis Clean
McAfee PWS-FCZK!1F563D126E32
TACHYON Clean
VBA32 Clean
Malwarebytes Clean
Panda Trj/GdSda.A
Zoner Clean
TrendMicro-HouseCall Clean
Rising Clean
Yandex Clean
Ikarus Clean
eGambit Clean
Fortinet W32/Vebzenpak.AGDH!tr
BitDefenderTheta Gen:NN.ZevbaF.34050.pm1@am3u@nei
AVG Win32:Malware-gen
Avast Win32:Malware-gen
CrowdStrike Clean
Qihoo-360 Clean
No IRMA results available.