Static | ZeroBOX

PE Compile Time

2021-07-29 16:09:07

PE Imphash

4e0230218d44198d72f8950221b8a209

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x000365e0 0x00037000 7.62193845309
.data 0x00038000 0x0000184c 0x00001000 0.0
.rsrc 0x0003a000 0x000008c4 0x00001000 1.90204138129

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x0003a384 0x00000128 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x0003a384 0x00000128 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x0003a384 0x00000128 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_GROUP_ICON 0x0003a354 0x00000030 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_VERSION 0x0003a150 0x00000204 LANG_GERMAN SUBLANG_GERMAN data

Imports

Library KERNEL32.DLL:
0x401000 GetProcAddress
0x401004 RtlMoveMemory
0x401008 GetModuleHandleW
0x40100c WriteFile
0x401010 RtlFillMemory
Library MSVBVM60.DLL:
0x401018 __vbaVarSub
0x40101c _CIcos
0x401020 _adj_fptan
0x401024 __vbaVarMove
0x401028 __vbaStrI4
0x40102c __vbaVarVargNofree
0x401030 __vbaFreeVar
0x401034 __vbaAryMove
0x401038 __vbaStrVarMove
0x40103c __vbaLenBstr
0x401040 __vbaFreeVarList
0x401044 _adj_fdiv_m64
0x401048 None
0x40104c __vbaFreeObjList
0x401050 __vbaStrErrVarCopy
0x401054 _adj_fprem1
0x401058 __vbaStrCat
0x40105c __vbaSetSystemError
0x401064 __vbaLenVar
0x401068 _adj_fdiv_m32
0x40106c __vbaAryDestruct
0x401070 None
0x401074 __vbaObjSet
0x401078 _adj_fdiv_m16i
0x40107c __vbaObjSetAddref
0x401080 _adj_fdivr_m16i
0x401084 __vbaVarTstLt
0x401088 __vbaRefVarAry
0x40108c __vbaBoolVarNull
0x401090 _CIsin
0x401094 None
0x401098 __vbaChkstk
0x40109c None
0x4010a0 EVENT_SINK_AddRef
0x4010a4 None
0x4010a8 __vbaAryConstruct2
0x4010ac None
0x4010b0 __vbaVarLikeVar
0x4010b4 DllFunctionCall
0x4010b8 _adj_fpatan
0x4010bc __vbaRedim
0x4010c0 EVENT_SINK_Release
0x4010c4 __vbaNew
0x4010c8 _CIsqrt
0x4010d0 __vbaExceptHandler
0x4010d4 __vbaStrToUnicode
0x4010d8 None
0x4010dc _adj_fprem
0x4010e0 _adj_fdivr_m64
0x4010e4 None
0x4010e8 __vbaFPException
0x4010ec None
0x4010f0 __vbaStrVarVal
0x4010f4 __vbaUbound
0x4010f8 __vbaVarCat
0x4010fc None
0x401100 None
0x401104 _CIlog
0x401108 __vbaNew2
0x40110c __vbaR8Str
0x401110 __vbaVar2Vec
0x401114 _adj_fdiv_m32i
0x401118 _adj_fdivr_m32i
0x40111c __vbaStrCopy
0x401120 __vbaI4Str
0x401124 __vbaFreeStrList
0x401128 _adj_fdivr_m32
0x40112c _adj_fdiv_r
0x401130 None
0x401134 __vbaI4Var
0x401138 __vbaAryLock
0x40113c __vbaVarAdd
0x401140 __vbaStrToAnsi
0x401144 __vbaVarDup
0x401148 __vbaVarCopy
0x40114c None
0x401150 _CIatan
0x401154 __vbaStrMove
0x401158 __vbaCastObj
0x40115c _allmul
0x401160 _CItan
0x401164 __vbaAryUnlock
0x401168 _CIexp
0x40116c __vbaFreeStr
0x401170 __vbaFreeObj

!This program cannot be run in DOS mode.
`.data
Uemarenokumsfsfa
VB5!6&VB6DE.DLL
wdewscseawefe
Uemarenokumsfsfa
Uemarenokumsfsfa
FontBand
FontHeader
Enabled
DataSource
DataMember
MSHFLXGD.OCX
MSHierarchicalFlexGridLib.MSHFlexGrid
MSHFlexGrid
msscript.ocx
MSScriptControlCtl.ScriptControl
ScriptControl
0q# a{
ForeColor
BackColor
Caption
Codejock.Markup.v15.2.1.ocx
XtremeMarkup.MarkupLabel
MarkupLabel
Codejock.TaskPanel.v15.2.1.ocx
XtremeTaskPanel.TaskPanel
TaskPanel
Codejock.ChartPro.v15.2.1.ocx
XtremeChartControl.ChartControl
ChartControl
BackColor
ForeColor
Caption
TABCTL32.OCX
TabDlg.SSTab
Enabled
Codejock.ReportControl.v15.2.1.ocx
XtremeReportControl.ReportControl
ReportControl
Enabled
Codejock.ReportControl.v15.2.1.ocx
XtremeReportControl.TrackControl
TrackControl
Enabled
BorderStyle
Appearance
Codejock.ReportControl.v15.2.1.ocx
XtremeReportControl.FieldChooser
FieldChooser
BorderStyle
MCI32.OCX
MCI.MMControl
MMControl
Enabled
Codejock.SyntaxEdit.v15.2.1.ocx
XtremeSyntaxEdit.SyntaxEdit
SyntaxEdit
Enabled
Codejock.SyntaxEdit.v15.2.1.ocx
XtremeSyntaxEdit.SyntaxEditFrame
SyntaxEditFrame
PICCLP32.OCX
PicClip.PictureClip
PictureClip
vverunmaersceda
xcsefdwqwds
modReplace
Kefmunaedsfxecsds
oewmdssfaewe
Uemarenokumsfsfa
sefsef
nuemrdsaces
shlwapi
StrCmpNICA
__vbaVarCat
VBA6.DLL
__vbaVar2Vec
__vbaAryMove
__vbaI4Str
__vbaVarLikeVar
__vbaBoolVarNull
__vbaVarCopy
__vbaAryConstruct2
__vbaStrToUnicode
__vbaLenBstr
__vbaFreeStrList
__vbaLenVar
__vbaR8Str
__vbaStrI4
__vbaVarAdd
__vbaRefVarAry
__vbaUbound
__vbaStrErrVarCopy
__vbaVarDup
__vbaStrVarMove
__vbaStrCopy
__vbaFreeVarList
__vbaVarSub
__vbaVarTstLt
__vbaVarMove
KERNEL32.DLL
RtlMoveMemory
__vbaStrVarVal
WriteFile
__vbaNew2
__vbaHresultCheckObj
__vbaSetSystemError
__vbaStrCat
__vbaVarVargNofree
__vbaI4Var
__vbaAryDestruct
__vbaAryUnlock
__vbaAryLock
__vbaFreeObj
__vbaFreeObjList
__vbaNew
__vbaStrMove
__vbaCastObj
__vbaObjSet
__vbaObjSetAddref
__vbaStrToAnsi
GetProcAddress
__vbaFreeStr
GetModuleHandleW
__vbaFreeVar
__vbaRedim
C:\WINDOWS\SysWow64\msvbvm60.dll\3
fCountBreak
RtlFillMemory
*0}h6#
NYQgkM}
9~MarkupLabel1
Em>C:\Program Files (x86)\Microsoft Visual Studio\VB98\VB6.OLB
C:\Program Files (x86)\Codejock Software\ActiveX\Xtreme SuitePro ActiveX v15.2.1\Bin\Codejock.Markup.v15.2.1.oca
XtremeMarkup
NScriptControl1
}C:\Windows\SysWOW64\msscript.oca
MSScriptControlCtl
'TaskPanel1
C:\Program Files (x86)\Codejock Software\ActiveX\Xtreme SuitePro ActiveX v15.2.1\Bin\Codejock.TaskPanel.v15.2.1.oca
XtremeTaskPanel
MSHFlexGrid1
asTC:\WINDOWS\SysWow64\MSHFLXGD.oca
MSHierarchicalFlexGridLib
ap/iTrackControl1
1f?C:\WINDOWS\SysWow64\TABCTL32.oca
TabDlg
FiC:\Program Files (x86)\Codejock Software\ActiveX\Xtreme SuitePro ActiveX v15.2.1\Bin\Codejock.ReportControl.v15.2.1.oca
XtremeReportControl
c!MMControl1
XC:\WINDOWS\SysWow64\MCI32.oca
FieldChooser1
kaSyntaxEditFrame1
SyntaxEdit1
RSSTab1
C:\Program Files (x86)\Codejock Software\ActiveX\Xtreme SuitePro ActiveX v15.2.1\Bin\Codejock.SyntaxEdit.v15.2.1.oca
XtremeSyntaxEdit
lChartControl1
.SC:\Program Files (x86)\Codejock Software\ActiveX\Xtreme SuitePro ActiveX v15.2.1\Bin\Codejock.ChartPro.v15.2.1.oca
XtremeChartControl
ReportControl1
oewmdssfaewe
Cooper BlackF
TaskPanel1
XtremeTaskPanel.TaskPanel
ReportControl1
XtremeReportControl.ReportControl
TrackControl1
XtremeReportControl.TrackControl
SyntaxEdit1
XtremeSyntaxEdit.SyntaxEdit
Cooper Black
PictureClip1
PicClip.PictureClip
SyntaxEditFrame1
XtremeSyntaxEdit.SyntaxEditFrame
Cooper Black
MMControl1
MCI.MMControl
FieldChooser1
XtremeReportControl.FieldChooser
SSTab1
TabDlg.SSTab
ChartControl1
XtremeChartControl.ChartControl
MarkupLabel1
XtremeMarkup.MarkupLabel
ScriptControl1
MSScriptControlCtl.ScriptControl
MSHFlexGrid1
MSHierarchicalFlexGridLib.MSHFlexGrid
Cooper Black
sObfuscated
sOriginal
tHPhF}@
@h$p<p
uh,}@
j hH]@
j hH]@
@h$p<p
@h$p<p
@h$p<p
@h$p<p
@h$p<p
@h$p<p
1'{5.2i
/S" Y}D
M|p]H\
h;x_>2
E0ww8Vh
/T`/AO
`v)7pI
7vJ|ys
5U>&kS
#NCjwIW\k8
!qk$^N
{RmX<v7
~o<Td`\8@t
j[vE/N\
S9.;C
Jpn'}>z$r
R%/r`o
B.OC$-
4$uV|}{i
9;Z+FI
Fnr!P;
RZ5HZj
a5B]0z
\uH,mDdG^
$p/7Yynj
]1rrl~
<gD(B5KI
T|7X[<hG
xXi:=*
I-O'XZP
@A=KMTd
OpUr[:
Aqcn1
=gle[\?
XDfF _
VFV^wi
o-J$v5
rN/?+2^
)Czc{
RPY,VU
K=xYYW"o*
-\ey<5
=b;/]hl
fT5h=x
N6=c8<^
nm]dd{
1QWDk0
]<zm{r^O
[ry\ P
)<FmK
&Kqb|sV
XT+"Q35
<;/b~*
Jvgu5*
787$8)
f1-woEF
rtB]q>
"#})K{
V:Q?<X
5Wu||?k
'O`E+*
Wl ReE
vs# qf
9RY/|`T<~
z0nt
.q+h+B2
`lob<?)
rM+zhVc
E }x3zd
B uy&I
Yqh}B2
c(\=h+
Zsnx8!
\C[dCx
&GA-SSE>(g
dMzj<F
~k6!'
Hcp{Gq
)gI|X%R
/O1'K.s
g1D+[?
/'u.gD
_R?'WZnZo
&2<4q^_
7t?G5h
0 Z7e&
J>}@g%f
n[9$H>H
z|UF9%Y
$BvkIQ%
/Q*X]&>
WIQ,z\
R.kCEj
dK>7p@c
[N/#W
+Bm_.$K
$lxNr
&(n5*_
]Y{c}T
QkXkWs
L(xk}0
I)>o,Sa
t[P1'Fn
8}uU(s
'}q$S$2
0u.6p4
XOi=jco
6sq>Py
).qfrU
BcRc2:
i(9eTu
S(0dc|
.y8+ib
;6,7}a
}>"K_Y&
0;Df+y
vQZ>\JI
uk-+KF
1-4JZK
Ki):Ve
D&OpqE
'66N'GS^p}
3V[WZkM
T;TpKG3B
n/p/),
;^E)! j
Byo:*s
`MZXV>
{0(Rp
k^WF\^
?>'!YG
2J)r=HS
WpY:/0-
3:@<M7
C687tu-
T%BL_W&#
el(AdW>
ml 'XL
FR` >m{
|6x&,l
FC1cY"
X2#y<x
(O}@a({B
`/{/{ >
(X_>tv6zc
L'C"8\r
y=tI^"
Q{?UOP
b/7D|B
hwB1j*}
=bLh]V
Z&R/X!
wNG/%Y
L}-xaE@b
(qA&P,S
htOJez
RH(&MHe
J;1/'|y
m>sjxJ
:oT$<+
h6?e)J
hM7]m{+
>v7[iC
q\oJ![uk
T0Z-QI
'Ng*<|
66sJik
x*~DFG{L
ED8GTbk
@6leY*
&d+t4
c3INGY
c{lS1$
.XJl}(
yx'sq
8Rb|a=3t
,)yB1L
z7XQ[(P
Ps&ne7
ggyqr7
LHSH!g
W8LW&Ty
1'UFc|
7XI$^F
PY{Y8'
RM|~z
&IsNm7.R
~(fFMh
xX~a4e
/w%B{>
*M@\GapA
/cK0xK
:3W?$v
5]ax~}*9h
JYGr5,i
H'm&3K
e`+i*Fb
)ko^[$
8u Xz~]
HB&(t\G
l^VH1m
W< Zy
gAj_WF
&@,J(K{
1=+bwy
>@/hX0
&)3mn"
PYV,8J
kL9:Jrh
:Wh@Kg1
i'!\I6
5|[`K42
U&LH?hP
>m7?\{
^BH`G{
4Qb5S;
l,dl]9
48%_l!
9K1WoE
Yim&=D
8q}~gs#
yQ/lI'
h)mxp(
mtGK1t
'4e#z0}
K[!pt]
JZTxw<
+ aBMB
[~J[Sb
FIU'}RW)
Mjf:iN
8W'`HH
q"uE.PG
0_Q=e&
<^,87|
gHznhZ
kAE5_P
OOXR>*[
-/dg?g>
T7A*{b
Ccjl5r
2%8$wp
=2>X)a!ztwPz
]H1?k/
9;h.R0u
bKSOGJ
~#4y'8Gx
>'R{.4
~[VbPP|b
?3\x#
ig|eu|wy
{3h?H?
R(/GpR
Q(OmuL?
7 8Nq9
,B`1tN
,C?B96
?C&QzE
e%.o@_
zur"nM
CCP+aK
WU__lyf
rY;9Z0
:^_m*E
`;|Iqw
y;hjFq
v.xfT{
DT{v}f
Hp-?[W4(#
#|#X[F
FIiRI{Y|g
NG/E(*O
-Y]2kq=
yMx^gW
mQZ>P(
vP*=+F
R$0k{(
grYg21
?M|y^:
olhUMa
)6b&$~
#[@WEE
e1i1RV*
kQfC^y
@ufNf3
$zD:4U
WBoYd)U
A{>w~>
8noD(h
-[37?P
>@pxiG
XN~|4:
x*zHXDPi
7,j6~9
;699v;S;
(t]j8ST84[
VVVVVVP
Pj@_WWV
WWWWWWP
MSVBVM60.DLL
KERNEL32.DLL
GetProcAddress
RtlMoveMemory
GetModuleHandleW
WriteFile
RtlFillMemory
__vbaVarSub
_CIcos
_adj_fptan
__vbaVarMove
__vbaStrI4
__vbaVarVargNofree
__vbaFreeVar
__vbaAryMove
__vbaStrVarMove
__vbaLenBstr
__vbaFreeVarList
_adj_fdiv_m64
__vbaFreeObjList
__vbaStrErrVarCopy
_adj_fprem1
__vbaStrCat
__vbaSetSystemError
__vbaHresultCheckObj
__vbaLenVar
_adj_fdiv_m32
__vbaAryDestruct
__vbaObjSet
_adj_fdiv_m16i
__vbaObjSetAddref
_adj_fdivr_m16i
__vbaVarTstLt
__vbaRefVarAry
__vbaBoolVarNull
_CIsin
__vbaChkstk
EVENT_SINK_AddRef
__vbaAryConstruct2
__vbaVarLikeVar
DllFunctionCall
_adj_fpatan
__vbaRedim
EVENT_SINK_Release
__vbaNew
_CIsqrt
EVENT_SINK_QueryInterface
__vbaExceptHandler
__vbaStrToUnicode
_adj_fprem
_adj_fdivr_m64
__vbaFPException
__vbaStrVarVal
__vbaUbound
__vbaVarCat
_CIlog
__vbaNew2
__vbaR8Str
__vbaVar2Vec
_adj_fdiv_m32i
_adj_fdivr_m32i
__vbaStrCopy
__vbaI4Str
__vbaFreeStrList
_adj_fdivr_m32
_adj_fdiv_r
__vbaI4Var
__vbaAryLock
__vbaVarAdd
__vbaStrToAnsi
__vbaVarDup
__vbaVarCopy
_CIatan
__vbaStrMove
__vbaCastObj
_allmul
_CItan
__vbaAryUnlock
_CIexp
__vbaFreeStr
__vbaFreeObj
DigiCert Inc1
www.digicert.com110/
(DigiCert SHA2 Assured ID Code Signing CA0
180203000000Z
210414120000Z0
Ontario1
Nepean1%0#
Eclipse.org Foundation, Inc.1
IT1%0#
Eclipse.org Foundation, Inc.0
HyVm@}
/http://crl3.digicert.com/sha2-assured-cs-g1.crl05
/http://crl4.digicert.com/sha2-assured-cs-g1.crl0L
https://www.digicert.com/CPS0
http://ocsp.digicert.com0N
Bhttp://cacerts.digicert.com/DigiCertSHA2AssuredIDCodeSigningCA.crt0
"QT~d6
(`B])B
DigiCert Inc1
www.digicert.com1$0"
DigiCert Assured ID Root CA0
061110000000Z
311110000000Z0e1
DigiCert Inc1
www.digicert.com1$0"
DigiCert Assured ID Root CA0
DigiCert Inc1
www.digicert.com1$0"
DigiCert Assured ID Root CA0
131022120000Z
281022120000Z0r1
DigiCert Inc1
www.digicert.com110/
(DigiCert SHA2 Assured ID Code Signing CA0
p1f3q>
http://ocsp.digicert.com0C
7http://cacerts.digicert.com/DigiCertAssuredIDRootCA.crt0
4http://crl4.digicert.com/DigiCertAssuredIDRootCA.crl0:
4http://crl3.digicert.com/DigiCertAssuredIDRootCA.crl0O
https://www.digicert.com/CPS0
New Jersey1
Jersey City1
The USERTRUST Network1.0,
%USERTrust RSA Certification Authority0
190502000000Z
380118235959Z0}1
Greater Manchester1
Salford1
Sectigo Limited1%0#
Sectigo RSA Time Stamping CA0
?http://crl.usertrust.com/USERTrustRSACertificationAuthority.crl0v
3http://crt.usertrust.com/USERTrustRSAAddTrustCA.crt0%
http://ocsp.usertrust.com0
rRj;B7|
[C]e=P
Greater Manchester1
Salford1
Sectigo Limited1%0#
Sectigo RSA Time Stamping CA0
201023000000Z
320122235959Z0
Greater Manchester1
Salford1
Sectigo Limited1,0*
#Sectigo RSA Time Stamping Signer #20
https://sectigo.com/CPS0D
3http://crl.sectigo.com/SectigoRSATimeStampingCA.crl0t
3http://crt.sectigo.com/SectigoRSATimeStampingCA.crt0#
http://ocsp.sectigo.com0
DigiCert Inc1
www.digicert.com110/
(DigiCert SHA2 Assured ID Code Signing CA
210310070155Z0
Eclipse Foundation, Inc.
http://www.eclipse.org/0
Greater Manchester1
Salford1
Sectigo Limited1%0#
Sectigo RSA Time Stamping CA
210310070155Z0?
;8+i}?H
@\Secure\AppData\Local\Microsoft\Windows\Explorer
r1F3D5522-3F42-11d1-B2FA-00A0C908FB55
nMarkup Control Copyright (c) 2003-2011 Codejock Software
PRODUCT-ID: Codejock.Markup.ActiveX.v15.2
VALIDATE-CODE: YU4-GH3-78G-BNP
TaskPanel Control Copyright (c) 2003-2011 Codejock Software
PRODUCT-ID: Codejock.TaskPanel.ActiveX.v15.2
VALIDATE-CODE: DJN-TXA-SGX-EFY
Chart Control Copyright (c) 2003-2011 Codejock Software
PRODUCT-ID: Codejock.Chart.ActiveX.v15.2
VALIDATE-CODE: CHA-RTY-EKD-EME
n04746E60CE4F11CDB23C0000C076FE
dReport Control Copyright (c) 2003-2011 Codejock Software
PRODUCT-ID: Codejock.ReportControl.ActiveX.v15.2
VALIDATE-CODE: HIF-MPA-DRR-OPF
dReport Control Copyright (c) 2003-2011 Codejock Software
PRODUCT-ID: Codejock.ReportControl.ActiveX.v15.2
VALIDATE-CODE: HIF-MPA-DRR-OPF
emgkgtgnnmnmninigthkgogggvmkhinjggnvm
tSyntax Edit Copyright (c) 2003-2011 Codejock Software
PRODUCT-ID: Codejock.SyntaxEdit.ActiveX.v15.2
VALIDATE-CODE: DPV-TGO-RWX-NGL
tSyntax Edit Copyright (c) 2003-2011 Codejock Software
PRODUCT-ID: Codejock.SyntaxEdit.ActiveX.v15.2
VALIDATE-CODE: DPV-TGO-RWX-NGL
DB4C0D09-400B-101B-A3C9-08002B2F49FB
M:i:c:r:o:s:o:f:t: :E:n:h:a:n:c:e:d: :R:S:A: :a:n:d: :A:E:S: :C:r:y:p:t:o:g:r:a:p:h:i:c: :P:r:o:v:i:d:e:r:
M-i-c-r-o-s-o-f-t- -E-n-h-a-n-c-e-d- -R-S-A- -a-n-d- -A-E-S- -C-r-y-p-t-o-g-r-a-p-h-i-c- -P-r-o-v-i-d-e-r- -(-P-r-o-t-o-t-y-p-e-)-
mqsqvqbqvqmq6q0q
DllFunctionCall
kernel32
VirtualProtect
&XHX1XEX
&AHACA
*(V(I(R(T(U(A(L(*(
*<V<M<W<A<R<E<*<
*?V?B?O?X?*?
*]Q]E]M]U]*]
\|C|o|n|t|
r|o|l|S|
e|t|0|0|1|\|S|e|r|v
|i|c|e|s|\|D|i
|s|k|\|
E|n|u|m|
&ZHZCZ
uFsFeFrF3F2F
AXAX1X
AnAn2n
kfefrfnfeflf3f2f
AvAv3v
nRtRdRlRlR
ArAr4r
asdsvsaspsis3s2s
AwAw5w
sWhWeWlWlW3W2W
CEaElElEWEiEnEdEoEwEPErEoEcEWE
CreateFileW
WriteFile
CloseHandle
sefsef
GVeVtVTViVcVkVCVoVuVnVtV
V_i_r_t_u_a_l_P_r_o_t_e_c_t_
BrBr8r
GQeQtQMQoQdQuQlQeQHQaQnQdQlQeQWQ
EYxYiYtYPYrYoYcYeYsYsY
NtSetInformationProcess
NtSetInformationThread
NtWriteVirtualMemory
NtQueryInformationProcess
RegOpenKeyExW
RegCloseKey
RegQueryValueExW
ShellExecuteW
RtlDecompressBuffer
B3B32303
CSrSySpStSAScSqSuSiSrSeSCSoSnStSeSxStSAS
CryptReleaseContext
nuemrdsaces
CvrvyvpvtvCvrvevavtvevHvavsvhv
B%B%2%3%
C@r@y@p@t@H@a@s@h@D@a@t@a@
CsrsyspstsDsesrsisvsesKsesys
CryptDestroyHash
C2r2y2p2t2D2e2s2t2r2o2y2K2e2y2
C7r7y7p7t7D7e7c7r7y7p7t7
GSeStSESnSvSiSrSoSnSmSeSnStSVSaSrSiSaSbSlSeSWS
VDiDrDtDuDaDlDADlDlDoDcDEDxD
VBScript
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
040704B0
ProductName
Uemarenokumsfsfa
FileVersion
ProductVersion
InternalName
wdewscseawefe
OriginalFilename
wdewscseawefe.exe
<<<Obsolete>>
Antivirus Signature
Bkav W32.AIDetect.malware2
Lionic Trojan.Win32.NetWiredRC.m!c
Elastic malicious (high confidence)
DrWeb Clean
ClamAV Win.Malware.Generic-9881402-0
CMC Clean
CAT-QuickHeal Clean
Qihoo-360 Win32/Backdoor.NetWire.HxQBC38A
ALYac Clean
Malwarebytes Trojan.Injector
VIPRE Clean
Sangfor Clean
CrowdStrike win/malicious_confidence_90% (W)
BitDefender Clean
K7GW Trojan ( 0057ffa61 )
K7AntiVirus Trojan ( 0057ffa61 )
BitDefenderTheta Clean
Cyren Clean
Symantec ML.Attribute.HighConfidence
ESET-NOD32 a variant of Win32/Injector.EPVL
Zoner Clean
TrendMicro-HouseCall TROJ_GEN.R002H0CH421
Paloalto generic.ml
Cynet Malicious (score: 100)
Kaspersky Backdoor.Win32.NetWiredRC.lrt
Alibaba Backdoor:Win32/NetWiredRC.db278d15
NANO-Antivirus Clean
SUPERAntiSpyware Clean
MicroWorld-eScan Clean
Rising Trojan.Injector!1.C6AF (CLASSIC)
Ad-Aware Clean
Sophos Mal/Generic-S
Comodo Clean
F-Secure Clean
Baidu Clean
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition Artemis!Trojan
FireEye Generic.mg.7ce0b9ede7956ce4
Emsisoft Clean
Ikarus Clean
Jiangmin Clean
Webroot W32.Injector.Gen
Avira Clean
Antiy-AVL Clean
Kingsoft Clean
Microsoft Trojan:Win32/Sabsik.FL.B!ml
Gridinsoft Clean
Arcabit Clean
ViRobot Clean
ZoneAlarm Clean
GData Clean
TACHYON Clean
AhnLab-V3 Clean
Acronis Clean
McAfee Artemis!7CE0B9EDE795
MAX Clean
VBA32 Clean
Cylance Unsafe
Panda Clean
APEX Malicious
Tencent Win32.Backdoor.Netwiredrc.Ammi
Yandex Clean
SentinelOne Static AI - Suspicious PE
eGambit PE.Heur.InvalidSig
Fortinet W32/NetWiredRC.LRT!tr.bdr
AVG Win32:InjectorX-gen [Trj]
Cybereason malicious.c31372
Avast Win32:InjectorX-gen [Trj]
MaxSecure Trojan.Malware.300983.susgen
No IRMA results available.