Static | ZeroBOX

PE Compile Time

2017-07-28 12:33:21

PE Imphash

c75b2cceb55bee276cddf57134b154d2

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x00033a64 0x00034000 4.55415043374
.data 0x00035000 0x00000b94 0x00001000 0.0
.rsrc 0x00036000 0x000070f2 0x00008000 4.01130957517

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x000366d2 0x00000988 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_ICON 0x000366d2 0x00000988 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_ICON 0x000366d2 0x00000988 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_ICON 0x000366d2 0x00000988 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_ICON 0x000366d2 0x00000988 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_ICON 0x000366d2 0x00000988 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_ICON 0x000366d2 0x00000988 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_ICON 0x000366d2 0x00000988 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_ICON 0x000366d2 0x00000988 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_ICON 0x000366d2 0x00000988 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_ICON 0x000366d2 0x00000988 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_ICON 0x000366d2 0x00000988 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_GROUP_ICON 0x00036624 0x000000ae LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_VERSION 0x00036300 0x00000324 LANG_ENGLISH SUBLANG_ENGLISH_US data

Imports

Library MSVBVM60.DLL:
0x401000 _CIcos
0x401004 _adj_fptan
0x401008 __vbaFreeVar
0x40100c __vbaStrVarMove
0x401010 __vbaFreeVarList
0x401014 _adj_fdiv_m64
0x401018 __vbaFreeObjList
0x40101c None
0x401020 _adj_fprem1
0x401024 None
0x401028 __vbaSetSystemError
0x401030 _adj_fdiv_m32
0x401034 None
0x401038 __vbaObjSet
0x40103c None
0x401040 _adj_fdiv_m16i
0x401044 _adj_fdivr_m16i
0x401048 _CIsin
0x40104c __vbaChkstk
0x401050 EVENT_SINK_AddRef
0x401054 __vbaStrCmp
0x401058 DllFunctionCall
0x40105c _adj_fpatan
0x401060 EVENT_SINK_Release
0x401064 _CIsqrt
0x40106c __vbaExceptHandler
0x401070 None
0x401074 _adj_fprem
0x401078 _adj_fdivr_m64
0x40107c None
0x401080 __vbaFPException
0x401084 None
0x401088 _CIlog
0x40108c __vbaNew2
0x401090 _adj_fdiv_m32i
0x401094 _adj_fdivr_m32i
0x401098 __vbaStrCopy
0x40109c None
0x4010a0 None
0x4010a4 __vbaFreeStrList
0x4010a8 _adj_fdivr_m32
0x4010ac _adj_fdiv_r
0x4010b0 None
0x4010b4 __vbaVarTstNe
0x4010b8 __vbaLateMemCall
0x4010bc __vbaStrToAnsi
0x4010c0 None
0x4010c4 __vbaVarDup
0x4010c8 __vbaFpI4
0x4010cc _CIatan
0x4010d0 __vbaStrMove
0x4010d4 __vbaCastObj
0x4010d8 _allmul
0x4010dc __vbaLateIdSt
0x4010e0 _CItan
0x4010e4 _CIexp
0x4010e8 __vbaFreeObj
0x4010ec __vbaFreeStr

!This program cannot be run in DOS mode.
`.data
MSVBVM60.DLL
Tvrbjlke1
Bibelstrk3
jUOKKCDci
sOKKKKKKKKKKKKK0#q
dKKKKKKKKKKKKKKKKKK4 ^
fKKKKKKKKKCAisOKKKKKKKK-Z
OKKKKKKKK- v
KKKKRKKK0
KKKKKKKKK+
KKKKKKKK0
KKKKKKKKK+
kKKKKKKKK-
KKKKKK6$<
KKKKKKKKK+
OKKKKKKKKK+
dKKKKKKKKE$8
fKKKKKKKKKE%"
KKKKKKKKK+
KKKKKKKKKK-
KKKKKKKKKE%"
dKKKKKKKKKK+
KKKKKKK+
KKKKKK
dKKKKKKKKK4
sKKKKKKKKKKE$8
kKKKKKKKKKE%
OKKKKKZKKKK4
KKKKKKKKKK+
KKRKKKKKKKK-
KKKKKKKKKO-
KKKKKKKKKKK-
KKKKKKKKOO4
jKKKKKKKKKKK+
KKKKKKOOQE%"
OKKKKKKKKKKK+
KKKKKKQQQQK%
KKKKKKKKKKKO%
KKKKKQQQQQQ%
KKKKKKKKKQQQ%
KKKOQQQQQQQ%
KKKKKKKOQQQQ%
KOQQQQQQQQQ+
KOQQQQQ%
QQQQQQQQQ
KKKKKOQQQQQQ%
QQQQQQQQQQQ+
KKKKOQQQQQQQ%
ZQQQQQQQQQQ+
KKKKQUUUUUUQ%
UUUUUUUUUUQ+
KKKQUUUUUUUU%
UUUUUUUUUUQ%
KKOUUUUUUUUU%
UUUUUUUUUUQ%
UUUUUUUU+
UUUUUUUUUUQ%
kOUUUUUUUUUU+
UUUUUUUUUULZ9
QZZZZZZZZZZ1
ZZZZZZZRZZE
ZZZZZZZZZZZ4
ZZZZZZZZZZ1
yZZZZZZZZZZE
ZZZZZZZZZZ+
yyyyyyyL$
yyyyyyyyyQ%
yyyyyyyyyyQ%
yyyyyyyyyE
Zyyyyyyyyy%
yyyyyyyyy+
yyyyyyyyyy1
yyyyyyyyyQ%8
yyyyyyyyyL
yyyyyyyyy
yyyyyyyyyZ%
yyyQ%"
yyyyyyyyy4
[R8447OZ
;44444444442"\
;44444"O
w844442
444442
844442
444444%
;44444!+
;444444
u444444
444444Z
444444!+
;444444%
4R44442
4444444!*
4444444
w4444444
8444448!I
U4444444
;44448<%
R444<<<(
4444448<
T44<<<<2
44444<<<
U<<<<<<2
444Z<<<<
k<<<<<<4
444<<<<<
k<<<<<<4
44<@@@@@
k@@@@@@4
88@@@@@@
i@@@@@@2
d@@@@@@%
uBBBBBBB
aBBBBBB$G
BBBBBBB$G
BBBBBBB
aaaaaaa(
aaaaaa<
yaaaaaa6
aaaaaa2
aaaaaaB
aaaaaa
aaaaaa!L
paaaaa6
nddddd!L
pdddda!_
ggggd<Q
ynggggggggg-N
yspkht
U<+&&)=
`+&&&;&&&&
?&&&&&
&&&&&!
d&&&&&
Y&&&+,
W&&,,,
,,,,,!7
W&+,,,
,,,,,!9
a&000Z!@
,0000!9
R3333'4
LJJ3J,
dJJJJ3
JJJJ'4
JJJJ'9
VOOOJQOOO*5
gZVRQT^
Bibelstrk3
Combo4
Evechu7
Combo3
millions
Combo2
Combo1
bluecoa
Check8
fortndin
Check7
Tetraste6
Check6
Check5
Skrlevn4
Check4
rynketra
Check3
Check2
vasclas
Check1
POLLIN
Command2
Clath8
Command1
amovechat
VScroll1
HScroll1
STARTT
Text21
Text22
unadul
Text23
Dorbel8
Text24
handelssk
Text124
Ldreinst
Kilomete
2aZZo%
Pf&|1i
vE4M1p>
]3k'hR,
O|MO1Q
E4M[`
m3[ZhM,
E4MY#"{
0i/8hX
MDI+=q
k8/H/9
OMIwrk
fQB\AQ
V?qz\aq
uEpa4V
g0mgsv
0iD!Fk
OtM?O0Q
vOtM?A
RPf&|1i
vE4M{r
0ivO}u
.FDj|
Q'''NK
OdMOlM
Pf&|1i
:gY5)\
KD%<Fd
KD%<Fd
8AzJtqC
DpnD@n
p=mNV8q}
EClL!4
i_OhIV
q3_OpI^E
0i_|Ej
UO4z_E
0i.Q#k
OheG/{
jqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqq
999999999999999999999999999999999999999999f
uJC4444444444444444444444444444444444444444444
j$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$
IDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDD
fwYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYY
)))))))))))))))))))))))))))))))))))
JJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJ
A@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@
b::::::::::::::::::::::::::::::::::::::
/NNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNN
####################################
wGooooooooooooooooooooooooooooooooooooo
KKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKK
oS<````````````````````````````````````
,)Rr`////////////////////////////////////////5
OPPPPPPPPPPPPPPPPPPPPPPPPPPPPPPPPPPP5d
8MTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTT
1YUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUU
v*****************************************
uuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuu=
ffffffffffffffffffffffffffffffffffffffffffff
Bmzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzz
Xp/ZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZ
[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[
7Kttttttttttttttttttttttttttttttttttttt
]|||||||||||||||||||||||||||||||||||||||||
UUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUU
H{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{
EEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEE
8___________________________________
"zzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzz
"J..........................................
i>vvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvv
5YYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYY
qqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqq
d........................................
XTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTT
R))))))))))))))))))))))))))))))))))))))))
lIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIII
`@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@
$>::::::::::::::::::::::::::::::::::::::::::::::
mW|########################################j@
oooooooooooooooooooooooooooooooooooooooooooooo
%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%
VKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKK
.....................................
VVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVV
JJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJ=
DDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDD
,*46Heeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeee
VVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVV
3jjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjj
v@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@
l;ffffffffffffffffffffffffffffffffffffff
VB5!6%*
bayrerss
grasse
Tvrbjlke1
FORGEMAKK
Medarbe6
C:\Program Files (x86)\Microsoft Visual Studio\VB98\VB6.OLB
Text124
VScroll1
Text23
Text24
Command1
Text21
Command2
Text22
Kilomete
Check1
Check6
Check7
Check8
Check2
Check3
Check4
Check5
Combo4
Combo2
Combo3
Combo1
HScroll1
user32.dll
InsertMenuItemA
rokering
shlwapi.dll
PathGetDriveNumberA
PolyBezier
user32
ShowWindow
kernel32
GetDateFormatA
FindWindowExA
rubladede
Expandible
hrdemiddel
Scutelliplantation2
DIALYSABLES
Forankre8
VBA6.DLL
__vbaVarDup
__vbaVarTstNe
__vbaFpI4
__vbaStrVarMove
__vbaFreeObjList
__vbaFreeStrList
__vbaLateMemCall
__vbaCastObj
__vbaObjSet
__vbaSetSystemError
__vbaStrToAnsi
__vbaFreeVarList
__vbaStrCopy
__vbaFreeVar
__vbaLateIdSt
__vbaFreeStr
__vbaStrCmp
__vbaFreeObj
__vbaHresultCheckObj
__vbaNew2
__vbaStrMove
ejendommeligheds
RINGNECK
Ultraminute
CENTRIFUGALT
ASHPLANTS
qualify
Sterne1
Dogsbody
Cinemactor7
billigvarers
Guahibo4
Cetoniinae
BAPTISTENS
ADOPTIANIST
BESLAGSMED
gaussfilterfunktioners
crucifier
ekskluderendes
fluiderne
MEDUSIFORM
stofskifter
Flindosa
MSVBVM60.DLL
_CIcos
_adj_fptan
__vbaFreeVar
__vbaStrVarMove
__vbaFreeVarList
_adj_fdiv_m64
__vbaFreeObjList
_adj_fprem1
__vbaSetSystemError
__vbaHresultCheckObj
_adj_fdiv_m32
__vbaObjSet
_adj_fdiv_m16i
_adj_fdivr_m16i
_CIsin
__vbaChkstk
EVENT_SINK_AddRef
__vbaStrCmp
DllFunctionCall
_adj_fpatan
EVENT_SINK_Release
_CIsqrt
EVENT_SINK_QueryInterface
__vbaExceptHandler
_adj_fprem
_adj_fdivr_m64
__vbaFPException
_CIlog
__vbaNew2
_adj_fdiv_m32i
_adj_fdivr_m32i
__vbaStrCopy
__vbaFreeStrList
_adj_fdivr_m32
_adj_fdiv_r
__vbaVarTstNe
__vbaLateMemCall
__vbaStrToAnsi
__vbaVarDup
__vbaFpI4
_CIatan
__vbaStrMove
__vbaCastObj
_allmul
__vbaLateIdSt
_CItan
_CIexp
__vbaFreeObj
__vbaFreeStr
U<+&&)=
`+&&&;&&&&
?&&&&&
&&&&&!
d&&&&&
Y&&&+,
W&&,,,
,,,,,!7
W&+,,,
,,,,,!9
a&000Z!@
,0000!9
R3333'4
LJJ3J,
dJJJJ3
JJJJ'4
JJJJ'9
VOOOJQOOO*5
gZVRQT^
[R8447OZ
;44444444442"\
;44444"O
w844442
444442
844442
444444%
;44444!+
;444444
u444444
444444Z
444444!+
;444444%
4R44442
4444444!*
4444444
w4444444
8444448!I
U4444444
;44448<%
R444<<<(
4444448<
T44<<<<2
44444<<<
U<<<<<<2
444Z<<<<
k<<<<<<4
444<<<<<
k<<<<<<4
44<@@@@@
k@@@@@@4
88@@@@@@
i@@@@@@2
d@@@@@@%
uBBBBBBB
aBBBBBB$G
BBBBBBB$G
BBBBBBB
aaaaaaa(
aaaaaa<
yaaaaaa6
aaaaaa2
aaaaaaB
aaaaaa
aaaaaa!L
paaaaa6
nddddd!L
pdddda!_
ggggd<Q
ynggggggggg-N
yspkht
jUOKKCDci
sOKKKKKKKKKKKKK0#q
dKKKKKKKKKKKKKKKKKK4 ^
fKKKKKKKKKCAisOKKKKKKKK-Z
OKKKKKKKK- v
KKKKRKKK0
KKKKKKKKK+
KKKKKKKK0
KKKKKKKKK+
kKKKKKKKK-
KKKKKK6$<
KKKKKKKKK+
OKKKKKKKKK+
dKKKKKKKKE$8
fKKKKKKKKKE%"
KKKKKKKKK+
KKKKKKKKKK-
KKKKKKKKKE%"
dKKKKKKKKKK+
KKKKKKK+
KKKKKK
dKKKKKKKKK4
sKKKKKKKKKKE$8
kKKKKKKKKKE%
OKKKKKZKKKK4
KKKKKKKKKK+
KKRKKKKKKKK-
KKKKKKKKKO-
KKKKKKKKKKK-
KKKKKKKKOO4
jKKKKKKKKKKK+
KKKKKKOOQE%"
OKKKKKKKKKKK+
KKKKKKQQQQK%
KKKKKKKKKKKO%
KKKKKQQQQQQ%
KKKKKKKKKQQQ%
KKKOQQQQQQQ%
KKKKKKKOQQQQ%
KOQQQQQQQQQ+
KOQQQQQ%
QQQQQQQQQ
KKKKKOQQQQQQ%
QQQQQQQQQQQ+
KKKKOQQQQQQQ%
ZQQQQQQQQQQ+
KKKKQUUUUUUQ%
UUUUUUUUUUQ+
KKKQUUUUUUUU%
UUUUUUUUUUQ%
KKOUUUUUUUUU%
UUUUUUUUUUQ%
UUUUUUUU+
UUUUUUUUUUQ%
kOUUUUUUUUUU+
UUUUUUUUUULZ9
QZZZZZZZZZZ1
ZZZZZZZRZZE
ZZZZZZZZZZZ4
ZZZZZZZZZZ1
yZZZZZZZZZZE
ZZZZZZZZZZ+
yyyyyyyL$
yyyyyyyyyQ%
yyyyyyyyyyQ%
yyyyyyyyyE
Zyyyyyyyyy%
yyyyyyyyy+
yyyyyyyyyy1
yyyyyyyyyQ%8
yyyyyyyyyL
yyyyyyyyy
yyyyyyyyyZ%
yyyQ%"
yyyyyyyyy4
C:\Program Files (x86)\Administrator-Cloud\Projects\bayrerss.pdb
Ng+qh|
Skuffels51
Toker1
COLOROTO1
ANSTNDI1#0!
Andreyg5@anaerobi.Pr0
210801202420Z
220801202420Z0
Skuffels51
Toker1
COLOROTO1
ANSTNDI1#0!
Andreyg5@anaerobi.Pr0
Skuffels51
Toker1
COLOROTO1
ANSTNDI1#0!
Andreyg5@anaerobi.Pr
y){77^
20210801202421Z
DigiCert Inc1
www.digicert.com110/
(DigiCert SHA2 Assured ID Timestamping CA0
210101000000Z
310106000000Z0H1
DigiCert, Inc.1 0
DigiCert Timestamp 20210
http://www.digicert.com/CPS0
,http://crl3.digicert.com/sha2-assured-ts.crl02
,http://crl4.digicert.com/sha2-assured-ts.crl0
http://ocsp.digicert.com0O
Chttp://cacerts.digicert.com/DigiCertSHA2AssuredIDTimestampingCA.crt0
QJxy6z'
dwc_#Ri
DigiCert Inc1
www.digicert.com1$0"
DigiCert Assured ID Root CA0
160107120000Z
310107120000Z0r1
DigiCert Inc1
www.digicert.com110/
(DigiCert SHA2 Assured ID Timestamping CA0
fnVa')
http://ocsp.digicert.com0C
7http://cacerts.digicert.com/DigiCertAssuredIDRootCA.crt0
4http://crl4.digicert.com/DigiCertAssuredIDRootCA.crl0:
4http://crl3.digicert.com/DigiCertAssuredIDRootCA.crl0P
https://www.digicert.com/CPS0
8aMbF$
V3"/"6
DigiCert Inc1
www.digicert.com110/
(DigiCert SHA2 Assured ID Timestamping CA
210801202421Z0+
/1(0&0$0"
Gennemfoerer7
Manitou5
dovneste
Racquets6
eskalere
Ombudsmandssags
Foretagende
forktrelser
Undertip8
Baghaven
Decametre
spermaceti
SIBNESS
MASCHA
Widowish
TRIMETERS
egnsteatrets
RymuXG163
KLEMATISSERNE
Pacificistically
SILDIGMODNES
parabelbenene
UNMUSICIANLY
PIKARESKE
DRIBLET
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
040904B0
Comments
SentinelStack
CompanyName
SentinelStack
FileDescription
SentinelStack
LegalCopyright
SentinelStack
LegalTrademarks
SentinelStack
ProductName
SentinelStack
FileVersion
ProductVersion
InternalName
bayrerss
OriginalFilename
bayrerss.exe
Antivirus Signature
Bkav W32.AIDetect.malware2
Lionic Clean
Elastic malicious (high confidence)
MicroWorld-eScan Clean
FireEye Clean
CAT-QuickHeal Clean
McAfee PWS-FCZK!9318CD06A9A0
Cylance Clean
VIPRE Clean
Sangfor Trojan.Win32.Save.a
K7AntiVirus Clean
BitDefender Clean
K7GW Clean
Cybereason malicious.e1cf6d
Baidu Clean
Cyren Clean
Symantec Clean
ESET-NOD32 Clean
APEX Malicious
Paloalto Clean
ClamAV Clean
Kaspersky Clean
Alibaba Clean
NANO-Antivirus Clean
ViRobot Clean
Rising Clean
Ad-Aware Clean
Sophos Clean
Comodo Clean
F-Secure Clean
DrWeb Clean
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition PWS-FCZK!9318CD06A9A0
CMC Clean
Emsisoft Clean
SentinelOne Static AI - Suspicious PE
GData Clean
Jiangmin Clean
Webroot Clean
Avira Clean
MAX Clean
Antiy-AVL Clean
Kingsoft Clean
Gridinsoft Clean
Arcabit Clean
SUPERAntiSpyware Clean
ZoneAlarm Clean
Microsoft Clean
Cynet Malicious (score: 100)
AhnLab-V3 Clean
Acronis Clean
BitDefenderTheta Gen:NN.ZevbaF.34050.pm1@aSKWdEji
ALYac Clean
TACHYON Clean
VBA32 Clean
Malwarebytes Clean
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Tencent Clean
Yandex Clean
Ikarus Clean
MaxSecure Clean
Fortinet Clean
Avast Clean
CrowdStrike win/malicious_confidence_70% (W)
Qihoo-360 Clean
No IRMA results available.