Static | ZeroBOX

PE Compile Time

2012-11-28 20:44:44

PE Imphash

1c73a47427cc41d9442154c68931bd16

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x0002144c 0x00022000 7.03543182228
.data 0x00023000 0x0000115c 0x00001000 0.0
.rsrc 0x00025000 0x000066b4 0x00007000 4.40515012312

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x000254cc 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x000254cc 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x000254cc 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x000254cc 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x000254cc 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x000254cc 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x000254cc 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x000254cc 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x000254cc 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_GROUP_ICON 0x00025448 0x00000084 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_VERSION 0x00025270 0x000001d8 LANG_CHINESE SUBLANG_CHINESE_TRADITIONAL data

Imports

Library MSVBVM60.DLL:
0x401000 _CIcos
0x401004 _adj_fptan
0x401008 _adj_fdiv_m64
0x40100c _adj_fprem1
0x401010 _adj_fdiv_m32
0x401014 _adj_fdiv_m16i
0x401018 _adj_fdivr_m16i
0x40101c None
0x401020 _CIsin
0x401024 __vbaChkstk
0x401028 EVENT_SINK_AddRef
0x40102c _adj_fpatan
0x401030 EVENT_SINK_Release
0x401034 _CIsqrt
0x40103c __vbaExceptHandler
0x401040 _adj_fprem
0x401044 _adj_fdivr_m64
0x401048 __vbaFPException
0x40104c _CIlog
0x401050 __vbaErrorOverflow
0x401054 _adj_fdiv_m32i
0x401058 _adj_fdivr_m32i
0x40105c _adj_fdivr_m32
0x401060 _adj_fdiv_r
0x401064 None
0x401068 _CIatan
0x40106c _allmul
0x401070 _CItan
0x401074 _CIexp

!This program cannot be run in DOS mode.
`.data
MSVBVM60.DLL
BETINGNINGER
MATURESCENCE
LUFTRUMSORGANISATIONS
DID26$
"2233>
6c323#3
6b3""#3>
&"33233
Z2f####
Z2b"#U[
U)za}d
LUFTRUMSORGANISATIONS
Combo2
BELURINGERNE
Command3
DIGERNES
Command2
NONTEMPORARY
Command1
SACROLUMBAR
DEVOTES
Combo1
GARDISTS
VB5!6&'
COMPROMISED
BETINGNINGER
BETINGNINGER
MATURESCENCE
NEKTON
Command3
C:\Program Files (x86)\Microsoft Visual Studio\VB98\VB6.OLB
Combo2
Combo1
Command1
Command2
VBA6.DLL
__vbaErrorOverflow
NEKTON
KALKMALERIS
Google
SNvd)_
u!@xxCq^
~G5\t
dp0LpQ5
O|5\xC
5\x[f^
5\xK6^
K3h4U6i*
4\xKd^
5=p/]e
4)#i[u2
5\z[G^
5\6[)]
q vSt
5SuE5\
{z)Tp,ib
4\xKJ^
V)Sr7
5d!@4
xbZn(xS
=_1xAI
t:xCw^
5\xk@^
5\xK(^
5\xC}^
SPYp'b
5e;!@0
,NZq%?
5\x[1^
5\I!/b
5\x&Se2
OL=$x
5\zY5P
5\x&0P
,p4qId.g
$GxJ_EL
x{r(Mu
`_1xbJ
m@xKH^
5\zkB]
5\xKB]
U{xp'u\
5Sus5\
&+E6Y5X
wSpY5X
5\u#]50
Ux@K[,
5\xk)^
5=q$':
W::r7:x
k_BPX28
5\xCn^
5Stn<\
5\IH+O
;q!RSt)
=TCp,9
"q%KSt{b\
5\K\HuX_
\2UxDK
Se 7`H
5\Ju4
,48J}@p
5\xSi^
\p7~O^
UxDK3)
v1Ep9
83YyWA>-W
k!kc*G
p4;Yo_
5\xcX^
Se:Uqx
5\x[Z^
5\z[Z^
]}DMp)j
5e|74\
U#:r$5:zK
[U'S_6
Se"Ux@K
C7psE]
p(}?~j
5\xcM^
ud3^E]
^]Vk^EV
5\x['^
N]zcM^
5StG5\
5St5\
d,JJHQ
q*G::t
5Stg4\
UmTr%5
MPzcY]
aE/{:xC]]
>:p-)m
>Se065\
es&w5u
!S}-5\
F-'*p\F
}e{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{hb
8888888888888888888888888888888888888
|OOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOO-i
8---------------------------------------
sssssssssssssssssssssssssssssssssssssssssss-1
EW`jjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjj
N#####################################9
Z________________________________________
2FO=======================================
-XD&Qooooooooooooooooooooooooooooooooooooooooo
<iiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiS
:NNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNh
FXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX1
xSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSS
bU~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~1
Lj>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>1
*\3333333333333333333333333333333333333333333333I
:4((((((((((((((((((((((((((((((((((((((
Emroooooooooooooooooooooooooooooooooooooooooo1
mxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxf
2tttttttttttttttttttttttttttttttttttttttttRf
^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
88888888888888888888888888888888888888
A!HHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHwA
o1qe#/
+35U@u
ai-xv9.6
TnSDYg
x[QSH%
j>-*awT|
fp.5Hv
Q~_1Ql
pXylUd@
W]o6!%*
ZZVBq\
p@TL\3F
QWR6BL
$_9{,v!
yI#+G%
81)K)R
AZFZsL
sl)`A2
?W |hI
Q$`.Y$
<H XlO_
.h,Z79
pVPHe#=
N^b/ss
v%!BG>
d[1s|T
{m!N.0
H4fIVK
dnmsos
R&c6ah
j.WQW"11
LU*b`m
&4"w#s
>_QQ."v,Z
hmfPm;(N
@+?OJri
0c-%9,
R-D1U2
nH>ca3
Z+)gf
/3/i@"
+oKK)#
bcs!_$*JH
I@wffab-$
:&t]8
k*0hJF
FREU^a
lbIn@!&
"5'}kE
c1)s#J
3'*[1mLiP?
'R|@-*
D+J.`m$
Vo8[yH
khpXw2
l>Ng i
`/|IyGX
7;<F0k
"LZIk//
n.Ij<s$B
eC(BDZ
s{pE.}
bHmvE{1b
2!Zv.T
/(y{+o
5DrkS]#0
A 3_"
o_'^8R
cJiVmM=
[hZH3CO
)9l{P
)11jPd
FM}_(h
MPN-W1]
#ZTI+dJ
y#K4kc
I?_9az
^.4d'c
=UNvJ)
!o+*;HM
#a+9uRY,
zbG,I8m{.
KI1rYJ`
SMkz!.o2
'gzZy2l
Jihkju
VGHDK-
*;n?#c
:xMMSs+-
*+ (t
%1yjv
CT4rTHg
!]51UJ
M=.+b5
va\Q^s
%^1oZz[V
q@REmR
ZleI"EIl
SWmP|)
cUUS<"
9Q,v/#O
|_q*GL
fy}EH+
vb}v6?
Xtj*KHo
[Bm5)O
uC)oRm
Lh}EqUD
`,jW!8
jr9<[6
)i~Y%2+FC*
U%#E}
DG{7(7
n:#[SA
66;.-sm
7'ae*Gko
\R^;Jc
# m{l8
8xe:S>aT
-35!KA!R
G~1mNpO
lIaTcb
KALKMALERIS
MSVBVM60.DLL
_CIcos
_adj_fptan
_adj_fdiv_m64
_adj_fprem1
_adj_fdiv_m32
_adj_fdiv_m16i
_adj_fdivr_m16i
_CIsin
__vbaChkstk
EVENT_SINK_AddRef
_adj_fpatan
EVENT_SINK_Release
_CIsqrt
EVENT_SINK_QueryInterface
__vbaExceptHandler
_adj_fprem
_adj_fdivr_m64
__vbaFPException
_CIlog
__vbaErrorOverflow
_adj_fdiv_m32i
_adj_fdivr_m32i
_adj_fdivr_m32
_adj_fdiv_r
_CIatan
_allmul
_CItan
_CIexp
U)za}d
DID26$
"2233>
6c323#3
6b3""#3>
&"33233
Z2f####
Z2b"#U[
CYCLOSPOROUS1
COUNTERREFLECTED1
RAFTSMAN1
THETOMBS1
ASPERSING1.0,
SIMULTANTOLKEDE@SMRBLOMSTER.PAR0
210803211501Z
220803211501Z0
CYCLOSPOROUS1
COUNTERREFLECTED1
RAFTSMAN1
THETOMBS1
ASPERSING1.0,
SIMULTANTOLKEDE@SMRBLOMSTER.PAR0
CYCLOSPOROUS1
COUNTERREFLECTED1
RAFTSMAN1
THETOMBS1
ASPERSING1.0,
SIMULTANTOLKEDE@SMRBLOMSTER.PAR
H!Bp?
20210803211501Z0
Symantec Corporation10
Symantec Trust Network110/
(Symantec SHA256 TimeStamping Signer - G3
VeriSign, Inc.10
VeriSign Trust Network1:08
1(c) 2008 VeriSign, Inc. - For authorized use only1806
/VeriSign Universal Root Certification Authority0
160112000000Z
310111235959Z0w1
Symantec Corporation10
Symantec Trust Network1(0&
Symantec SHA256 TimeStamping CA0
https://d.symcb.com/cps0%
https://d.symcb.com/rpa0.
http://s.symcd.com06
%http://s.symcb.com/universal-root.crl0
TimeStamp-2048-30
Symantec Corporation10
Symantec Trust Network1(0&
Symantec SHA256 TimeStamping CA0
171223000000Z
290322235959Z0
Symantec Corporation10
Symantec Trust Network110/
(Symantec SHA256 TimeStamping Signer - G30
?'J3Nm
https://d.symcb.com/cps0%
https://d.symcb.com/rpa0@
/http://ts-crl.ws.symantec.com/sha256-tss-ca.crl0
http://ts-ocsp.ws.symantec.com0;
/http://ts-aia.ws.symantec.com/sha256-tss-ca.cer0(
TimeStamp-2048-60
U){9FN
Symantec Corporation10
Symantec Trust Network1(0&
Symantec SHA256 TimeStamping CA
210803211501Z0/
/1(0&0$0"
cY]Pjj
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
040404B0
ProductName
COMPROMISED
FileVersion
ProductVersion
InternalName
OriginalFilename
LAEN.exe
Antivirus Signature
Bkav W32.AIDetect.malware1
Lionic Trojan.Win32.Generic.4!c
Elastic malicious (high confidence)
MicroWorld-eScan Clean
FireEye Generic.mg.26f17ecd8ee2fc34
CAT-QuickHeal Clean
ALYac Clean
Cylance Clean
VIPRE Clean
Sangfor Trojan.Win32.Save.a
K7AntiVirus Clean
BitDefender Clean
K7GW Clean
CrowdStrike win/malicious_confidence_80% (W)
BitDefenderTheta Gen:NN.ZevbaF.34058.lm1@aShh1Sbb
Cyren Clean
Symantec Packed.Generic.575
ESET-NOD32 Clean
Baidu Clean
APEX Malicious
Paloalto Clean
ClamAV Clean
Kaspersky UDS:Trojan.Win32.Mucc
Alibaba Clean
NANO-Antivirus Clean
ViRobot Clean
Rising Clean
Ad-Aware Clean
TACHYON Clean
Comodo Clean
F-Secure Clean
DrWeb Clean
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition Artemis!Trojan
CMC Clean
Emsisoft Clean
Ikarus Trojan.Inject
GData Clean
Jiangmin Clean
MaxSecure Trojan.Malware.300983.susgen
Avira Clean
Antiy-AVL Clean
Kingsoft Clean
Gridinsoft Clean
Arcabit Clean
SUPERAntiSpyware Clean
ZoneAlarm Clean
Microsoft Trojan:Win32/Wacatac.B!ml
Cynet Clean
AhnLab-V3 Clean
Acronis Clean
McAfee Artemis!26F17ECD8EE2
MAX Clean
VBA32 Clean
Malwarebytes Clean
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Tencent Clean
Yandex Clean
SentinelOne Clean
eGambit Unsafe.AI_Score_99%
Fortinet Clean
Webroot Clean
AVG FileRepMalware
Cybereason malicious.af9a84
Avast FileRepMalware
Qihoo-360 Win32/Heur.Generic.HwMAueAA
No IRMA results available.