Static | ZeroBOX

PE Compile Time

2014-01-25 03:46:59

PE Imphash

1c73a47427cc41d9442154c68931bd16

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x0002144c 0x00022000 7.00838154507
.data 0x00023000 0x0000115c 0x00001000 0.0
.rsrc 0x00025000 0x000066c4 0x00007000 4.40876314439

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x000254dc 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x000254dc 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x000254dc 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x000254dc 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x000254dc 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x000254dc 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x000254dc 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x000254dc 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x000254dc 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_GROUP_ICON 0x00025458 0x00000084 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_VERSION 0x00025270 0x000001e8 LANG_CHINESE SUBLANG_CHINESE_TRADITIONAL data

Imports

Library MSVBVM60.DLL:
0x401000 _CIcos
0x401004 _adj_fptan
0x401008 _adj_fdiv_m64
0x40100c _adj_fprem1
0x401010 _adj_fdiv_m32
0x401014 _adj_fdiv_m16i
0x401018 _adj_fdivr_m16i
0x40101c None
0x401020 _CIsin
0x401024 __vbaChkstk
0x401028 EVENT_SINK_AddRef
0x40102c _adj_fpatan
0x401030 EVENT_SINK_Release
0x401034 _CIsqrt
0x40103c __vbaExceptHandler
0x401040 _adj_fprem
0x401044 _adj_fdivr_m64
0x401048 __vbaFPException
0x40104c _CIlog
0x401050 __vbaErrorOverflow
0x401054 _adj_fdiv_m32i
0x401058 _adj_fdivr_m32i
0x40105c _adj_fdivr_m32
0x401060 _adj_fdiv_r
0x401064 None
0x401068 _CIatan
0x40106c _allmul
0x401070 _CItan
0x401074 _CIexp

!This program cannot be run in DOS mode.
`.data
MSVBVM60.DLL
INMENTIC
m Files
HURTIGTGAAENDE
SOUSAFONERNE
DID26$
"2233>
6c323#3
6b3""#3>
&"33233
Z2f####
Z2b"#U[
U)za}d
SOUSAFONERNE
Combo2
ATOMINDUSTRIEN
Command3
GUNNEL
Command2
FORRETNINGSLOKALER
Command1
TROPESKOVS
AALAND
Combo1
UDLAGT
VB5!6&'
VANDFLADEN
SIEBERN
INMENTIC
INMENTIC
HURTIGTGAAENDE
MARKEDSMEKANISMES
Command3
C:\Program Files (x86)\Microsoft Visual Studio\VB98\VB6.OLB
Combo2
Combo1
Command1
Command2
VBA6.DLL
__vbaErrorOverflow
MARKEDSMEKANISMES
HUSTELEFONERNE
Google
DBE\<33>
LS^&xM
Pg`H*)
P O9hGI
DH:3>6$@
`3"h]|
0Q1jM&
d04M25
>~3KGt
P1E6?Gq
E>Gy6i
t&ThE\9
hBbAsMaoi
.eV8@D
&8`M#0
Z>8<$U
M;NIpC@
t3>2M?
E89GAoi
?J{;2+
H:@02
E98GI|i
!:)l>Gy
f{M>}G
33>0My
]P7O/H:
=8GINi
H.?GqYi
4M*0e8
)w13>
k+>Gyti
M:BRvY
H1)j73>0EI
Clv@XV
+M>w$w
)0<3>H
;8rq}$pL
lo.TEFOv
oOM :-.
c)}e3>
,Q=GtB
gb${m<VD
gb$*$C
M7#F'i
l-9M2[B
Ex33>P
EtNO(lM
A+6*A+6
L6M+EY
33>1DI?i
=(EABi
33>!M6
\U)f23>h
[g'Mlu
ak.(((((((((((((((((((((((((((((((((((((((^f
HHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHH
-----------------------------------------
NNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNN5
7bDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDD
">>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>
@-''''''''''''''''''''''''''''''''''''''''''9
Vsssssssssssssssssssssssssssssssssssssssssssss
8OOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOO
3nddddddddddddddddddddddddddddddddddddddddddddd
w:33333333333333333333333333333333333333
-TTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTT
YYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYY
......................................
="yyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyy
vrjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjSf
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
ME------------------------------------------f1
N'''''''''''''''''''''''''''''''''''''''''''f
N88888888888888888888888888888888888888888
MMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMM
ByyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyR
========================================
^333333333333333333333333333333333333333
4.......................................
ai-xv9.6
TnSDYg
x[QSH%
j>-*awT|
fp.5Hv
Q~_1Ql
pXylUd@
W]o6!%*
ZZVBq\
p@TL\3F
QWR6BL
$_9{,v!
yI#+G%
81)K)R
AZFZsL
sl)`A2
?W |hI
Q$`.Y$
<H XlO_
.h,Z79
pVPHe#=
N^b/ss
v%!BG>
d[1s|T
{m!N.0
H4fIVK
dnmsos
R&c6ah
j.WQW"11
LU*b`m
&4"w#s
>_QQ."v,Z
hmfPm;(N
@+?OJri
0c-%9,
R-D1U2
nH>ca3
Z+)gf
/3/i@"
+oKK)#
bcs!_$*JH
I@wffab-$
:&t]8
k*0hJF
FREU^a
lbIn@!&
"5'}kE
c1)s#J
3'*[1mLiP?
'R|@-*
D+J.`m$
Vo8[yH
khpXw2
l>Ng i
`/|IyGX
7;<F0k
"LZIk//
n.Ij<s$B
eC(BDZ
s{pE.}
bHmvE{1b
2!Zv.T
/(y{+o
5DrkS]#0
A 3_"
o_'^8R
cJiVmM=
[hZH3CO
)9l{P
)11jPd
FM}_(h
MPN-W1]
#ZTI+dJ
y#K4kc
I?_9az
^.4d'c
=UNvJ)
!o+*;HM
#a+9uRY,
zbG,I8m{.
KI1rYJ`
SMkz!.o2
'gzZy2l
Jihkju
VGHDK-
*;n?#c
:xMMSs+-
*+ (t
%1yjv
CT4rTHg
!]51UJ
M=.+b5
va\Q^s
%^1oZz[V
q@REmR
ZleI"EIl
SWmP|)
cUUS<"
9Q,v/#O
|_q*GL
fy}EH+
vb}v6?
Xtj*KHo
[Bm5)O
uC)oRm
Lh}EqUD
`,jW!8
jr9<[6
)i~Y%2+FC*
U%#E}
DG{7(7
n:#[SA
66;.-sm
7'ae*Gko
\R^;Jc
# m{l8
8xe:S>aT
-35!KA!R
G~1mNpO
lIaTcb
HUSTELEFONERNE
MSVBVM60.DLL
_CIcos
_adj_fptan
_adj_fdiv_m64
_adj_fprem1
_adj_fdiv_m32
_adj_fdiv_m16i
_adj_fdivr_m16i
_CIsin
__vbaChkstk
EVENT_SINK_AddRef
_adj_fpatan
EVENT_SINK_Release
_CIsqrt
EVENT_SINK_QueryInterface
__vbaExceptHandler
_adj_fprem
_adj_fdivr_m64
__vbaFPException
_CIlog
__vbaErrorOverflow
_adj_fdiv_m32i
_adj_fdivr_m32i
_adj_fdivr_m32
_adj_fdiv_r
_CIatan
_allmul
_CItan
_CIexp
U)za}d
DID26$
"2233>
6c323#3
6b3""#3>
&"33233
Z2f####
Z2b"#U[
FORSGSVERSIONER1
ARRHENIUS1
SKIDTERASET1
EKSPANDER1301
$UDSKRIVNINGSKOMMANDOENS@JOVIALISE.HJ0
210803211224Z
220803211224Z0
FORSGSVERSIONER1
ARRHENIUS1
SKIDTERASET1
EKSPANDER1301
$UDSKRIVNINGSKOMMANDOENS@JOVIALISE.HJ0
FORSGSVERSIONER1
ARRHENIUS1
SKIDTERASET1
EKSPANDER1301
$UDSKRIVNINGSKOMMANDOENS@JOVIALISE.HJ
+0Gf O%
20210803211226Z0
Symantec Corporation10
Symantec Trust Network110/
(Symantec SHA256 TimeStamping Signer - G3
VeriSign, Inc.10
VeriSign Trust Network1:08
1(c) 2008 VeriSign, Inc. - For authorized use only1806
/VeriSign Universal Root Certification Authority0
160112000000Z
310111235959Z0w1
Symantec Corporation10
Symantec Trust Network1(0&
Symantec SHA256 TimeStamping CA0
https://d.symcb.com/cps0%
https://d.symcb.com/rpa0.
http://s.symcd.com06
%http://s.symcb.com/universal-root.crl0
TimeStamp-2048-30
Symantec Corporation10
Symantec Trust Network1(0&
Symantec SHA256 TimeStamping CA0
171223000000Z
290322235959Z0
Symantec Corporation10
Symantec Trust Network110/
(Symantec SHA256 TimeStamping Signer - G30
?'J3Nm
https://d.symcb.com/cps0%
https://d.symcb.com/rpa0@
/http://ts-crl.ws.symantec.com/sha256-tss-ca.crl0
http://ts-ocsp.ws.symantec.com0;
/http://ts-aia.ws.symantec.com/sha256-tss-ca.cer0(
TimeStamp-2048-60
U){9FN
Symantec Corporation10
Symantec Trust Network1(0&
Symantec SHA256 TimeStamping CA
210803211226Z0/
E[\Vy07
/1(0&0$0"
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
040404B0
ProductName
SIEBERN
FileVersion
ProductVersion
InternalName
VANDFLADEN
OriginalFilename
VANDFLADEN.exe
Antivirus Signature
Bkav W32.AIDetect.malware1
Lionic Clean
Elastic malicious (high confidence)
MicroWorld-eScan Clean
FireEye Generic.mg.ecc19a6e75196aba
CAT-QuickHeal Clean
McAfee Clean
Cylance Unsafe
VIPRE Clean
Sangfor Trojan.Win32.Save.a
K7AntiVirus Clean
BitDefender Clean
K7GW Clean
Cybereason malicious.23c100
BitDefenderTheta Gen:NN.ZevbaF.34058.lm1@aiKRcqkb
Cyren Clean
Symantec Packed.Generic.575
ESET-NOD32 Clean
Baidu Clean
APEX Malicious
Paloalto Clean
ClamAV Clean
Kaspersky UDS:Trojan.Win32.Mucc
Alibaba Clean
NANO-Antivirus Clean
ViRobot Clean
Avast Clean
Rising Clean
Ad-Aware Clean
TACHYON Clean
Emsisoft Clean
Comodo Clean
F-Secure Clean
DrWeb Clean
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition Clean
CMC Clean
Sophos Clean
Ikarus Trojan.Inject
Jiangmin Clean
Webroot Clean
Avira Clean
Antiy-AVL Clean
Kingsoft Clean
Microsoft Trojan:Win32/Tnega!ml
Gridinsoft Clean
Arcabit Clean
SUPERAntiSpyware Clean
ZoneAlarm Clean
GData Clean
Cynet Clean
AhnLab-V3 Clean
Acronis Clean
VBA32 Clean
ALYac Clean
MAX Clean
Malwarebytes Clean
Zoner Clean
TrendMicro-HouseCall Clean
Tencent Clean
Yandex Trojan.GenAsa!6IHGaceYThA
SentinelOne Clean
eGambit Unsafe.AI_Score_89%
Fortinet Clean
Qihoo-360 Clean
Panda Clean
CrowdStrike Clean
MaxSecure Trojan.Malware.300983.susgen
No IRMA results available.