Static | ZeroBOX

PE Compile Time

2014-08-02 08:31:45

PE Imphash

c65aff2bab39ef464a2bad0c06b18bd1

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x0001a194 0x0001b000 6.40208191061
.data 0x0001c000 0x00000a64 0x00001000 0.0
.rsrc 0x0001d000 0x000017a0 0x00002000 2.7902518553

Resources

Name Offset Size Language Sub-language File type
CUSTOM 0x0001d1d0 0x00000013 LANG_ENGLISH SUBLANG_ENGLISH_US ASCII text, with no line terminators
RT_ICON 0x0001db5c 0x000008a8 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_ICON 0x0001db5c 0x000008a8 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_ICON 0x0001db5c 0x000008a8 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_ICON 0x0001db5c 0x000008a8 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_GROUP_ICON 0x0001e404 0x0000003e LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_VERSION 0x0001e444 0x0000035c LANG_NORWEGIAN SUBLANG_NORWEGIAN_BOKMAL data

Imports

Library MSVBVM60.DLL:
0x401000 _CIcos
0x401004 _adj_fptan
0x401008 __vbaVarMove
0x40100c None
0x401010 __vbaFreeVar
0x401014 __vbaAryMove
0x401018 __vbaStrVarMove
0x40101c __vbaFreeVarList
0x401020 _adj_fdiv_m64
0x401024 __vbaFreeObjList
0x401028 None
0x40102c _adj_fprem1
0x401030 __vbaRecAnsiToUni
0x401034 None
0x401038 None
0x40103c __vbaSetSystemError
0x401044 __vbaLenBstrB
0x401048 None
0x40104c _adj_fdiv_m32
0x401050 None
0x401054 __vbaAryDestruct
0x401058 None
0x40105c __vbaObjSet
0x401060 __vbaOnError
0x401064 None
0x401068 _adj_fdiv_m16i
0x40106c __vbaObjSetAddref
0x401070 _adj_fdivr_m16i
0x401074 None
0x401078 __vbaFpR8
0x40107c _CIsin
0x401080 __vbaErase
0x401084 None
0x401088 __vbaChkstk
0x40108c EVENT_SINK_AddRef
0x401094 __vbaStrCmp
0x401098 __vbaAryConstruct2
0x40109c None
0x4010a0 __vbaI2I4
0x4010a4 __vbaObjVar
0x4010a8 None
0x4010ac DllFunctionCall
0x4010b0 _adj_fpatan
0x4010b4 None
0x4010b8 None
0x4010bc __vbaRedim
0x4010c0 __vbaRecUniToAnsi
0x4010c4 EVENT_SINK_Release
0x4010c8 None
0x4010cc __vbaUI1I2
0x4010d0 _CIsqrt
0x4010d8 None
0x4010dc __vbaExceptHandler
0x4010e0 _adj_fprem
0x4010e4 _adj_fdivr_m64
0x4010e8 __vbaFPException
0x4010ec None
0x4010f0 __vbaStrVarVal
0x4010f4 None
0x4010f8 None
0x4010fc _CIlog
0x401100 __vbaErrorOverflow
0x401104 None
0x401108 None
0x40110c __vbaNew2
0x401110 __vbaVar2Vec
0x401114 None
0x401118 None
0x40111c _adj_fdiv_m32i
0x401120 _adj_fdivr_m32i
0x401124 __vbaStrCopy
0x401128 None
0x40112c _adj_fdivr_m32
0x401130 _adj_fdiv_r
0x401134 None
0x401138 None
0x40113c __vbaVarTstNe
0x401140 None
0x401144 None
0x401148 __vbaVarDup
0x40114c None
0x401150 __vbaFpI4
0x401154 None
0x401158 _CIatan
0x40115c __vbaStrMove
0x401160 __vbaCastObj
0x401164 None
0x401168 _allmul
0x40116c _CItan
0x401170 None
0x401174 _CIexp
0x401178 __vbaFreeStr
0x40117c __vbaFreeObj

!This program cannot be run in DOS mode.
`.data
MSVBVM60.DLL
pushfu
Culla5
Aggro4
Aggro4
TRAFFI
f7DcH %
=qSix
jx`rjw
Xm3H"W
7WlMjg
jwdI=O4
jwd3#u
_|Txi`
iD_vV~
jwiUk{
}2T.[Mn3
TEl;fu
jwS5X9p
jxi9kw
jwTZhf
DLhIkw
iD_kkP
:%SGf;
jw}qS
f7DcH %
jwmq.~)
^SkyN
;ST"l|t
jxi.hw
jxikkw
jxi?kw
jxi7jw
3lMm^$u
J1Qlx]%
jwd;'u
jxh4jw
jwVQr2y
\/65Pf
hOGjt`lB
!_["}X
jwd3Ou
avhzjw
jO,fU>
jwiyA3
jN<fm'
RjifYn
@AlyqVZ
(Nf<[0
jwd;*u
=LnwhL
+/l;|u
,lJ~/M
(lI(c;
1^Xvjw
ms(Jz:
jxhSlw
jxiBnw
Nsixi3
9~nMnF$6
jwdvos
jxhKjw
jxh#jw
jwlcjv
HmqUxh>
vxbujw
lwuAnfn
VB5!6&*
Microsoft Teams
pushfu
pushfu
pushfu
Culla5
TRAFFI
C:\Program Files (x86)\Microsoft Visual Studio\VB98\VB6.OLB
user32
GetKeyboardType
shlwapi.dll
PathMakeSystemFolderA
winmm.dll
mixerClose
mmioAscend
joyGetDevCapsA
PathGetCharTypeA
comctl32
FlatSB_SetScrollProp
GetKeyValue
mnninger
Befippelses
Macerate8
Udenrigsministeren5
pernychia
VBA6.DLL
__vbaRecAnsiToUni
__vbaRecUniToAnsi
__vbaFpI4
__vbaSetSystemError
__vbaFpR8
__vbaObjVar
__vbaObjSetAddref
__vbaOnError
__vbaErase
__vbaVarMove
__vbaVarTstNe
__vbaAryConstruct2
__vbaI2I4
__vbaFreeObjList
__vbaCastObj
__vbaObjSet
__vbaLenBstrB
__vbaAryDestruct
__vbaVar2Vec
__vbaAryMove
__vbaUI1I2
__vbaGenerateBoundsError
__vbaRedim
__vbaStrCmp
__vbaFreeObj
__vbaNew2
__vbaVarDup
__vbaHresultCheckObj
__vbaStrVarMove
__vbaStrCopy
__vbaErrorOverflow
__vbaFreeVar
__vbaStrMove
__vbaFreeVarList
__vbaFreeStr
__vbaStrVarVal
KeyRoot
KeyName
SubKeyRef
KeyVal
Bestrides2
CARIDEER
SECTIONALIZATION
Batta2
FRIMRKEALBUMERS
Epiteter
Onychosis
NEUSTONIC
MAJUSKLERS
Smrhullers5
WURTZITE
NAGLING
Squeezer
MSVBVM60.DLL
_CIcos
_adj_fptan
__vbaVarMove
__vbaFreeVar
__vbaAryMove
__vbaStrVarMove
__vbaFreeVarList
_adj_fdiv_m64
__vbaFreeObjList
_adj_fprem1
__vbaRecAnsiToUni
__vbaSetSystemError
__vbaHresultCheckObj
__vbaLenBstrB
_adj_fdiv_m32
__vbaAryDestruct
__vbaObjSet
__vbaOnError
_adj_fdiv_m16i
__vbaObjSetAddref
_adj_fdivr_m16i
__vbaFpR8
_CIsin
__vbaErase
__vbaChkstk
EVENT_SINK_AddRef
__vbaGenerateBoundsError
__vbaStrCmp
__vbaAryConstruct2
__vbaI2I4
__vbaObjVar
DllFunctionCall
_adj_fpatan
__vbaRedim
__vbaRecUniToAnsi
EVENT_SINK_Release
__vbaUI1I2
_CIsqrt
EVENT_SINK_QueryInterface
__vbaExceptHandler
_adj_fprem
_adj_fdivr_m64
__vbaFPException
__vbaStrVarVal
_CIlog
__vbaErrorOverflow
__vbaNew2
__vbaVar2Vec
_adj_fdiv_m32i
_adj_fdivr_m32i
__vbaStrCopy
_adj_fdivr_m32
_adj_fdiv_r
__vbaVarTstNe
__vbaVarDup
__vbaFpI4
_CIatan
__vbaStrMove
__vbaCastObj
_allmul
_CItan
_CIexp
__vbaFreeStr
__vbaFreeObj
XXXXXXXXXXXXXXXXXXZ
wwwwww
wwwwww
ALLUSERSPROF
STORESLEMMENE
Brudfladernes9
Bevgende
Hydroparastatae8
14:14:14
Skiftelaasene
Grillworks4
eggfish
TEATERFORESTILLING
Unexorbitantly
Fornedrelsens3
EMULSIONERNES
headiness
Mugging4
Buskfyr3
Bordurernes2
auriscalp
antienzyme
dobbeltrettede
Vvstypers8
gribeflade
Hetman5
voldfrtes
UNIRRITATING
Misguessing
Akkordeonet
Prosternums1
estrangements
FRAVRENDES
Medejeren3
Alkoholiserede
decimaldelene
Overdramatic6
Terrance
Sinologer7
JOGGINGTUR
ORDREBEHANDLINGERS
Interpretation
celebrerendes
Derailleurgears5
Stankes
Piastre8
Tapetta9
Civildommerne4
ARSOITE
Oprrsomraadet5
Rootholds5
kalkeringer
Apogonid
Brnepasningsmuligheds
PULVINATED
SYGERNE
Krydderiernes
Trusses9
Allochetite
Sadeltag
Lykkeligst2
SCHRYARI
BOISTEROUSNESS
Kette8
Selvstndighedstrang
Valetaille3
slutskema
informationsfelts
Poultice9
Occasioner5
BRUSHANERNE
Sjussers4
Fylderi
Massier9
Satinerer3
OBLIGATIONER
Variablerne7
overtagelse
Teleskopaffjedrings2
TILSYNSMYNDIGHEDER
Sommergsts
Eksperimentalteatrene
Todelingen3
Centrifugalizations
Superoxygenate
teknonomuddannelsen
Inddel
conemaker
separator
Uldhaaret2
UNHOODWINKED
BASSENS
Manyberry6
SCALENOHEDRON
Proletarised6
FLELSESKOLDES
LIKVIDATIONER
Fuldbragte7
nonadjournment
Trotskismes9
unobscured
MAGTKAMPS
Saccharulmic
Controverse
Resultatsjles5
ejendomsrets
TREMILEGRNSER
Skrubs1
antarchistic
Dybdepsykologis3
RIDDERSKABERNES
bukketorn
Semiperspicuous
Pelsens
THERMOTROPISM
Fjedrene
Familiariserendes
Stafetten
POLLADZ
KONOMIDIREKTRENS
Gemination7
Cattlebush
hertuger
Excluder6
CHASTER
stumphales
Nonhardenable
huckstered
UDVIKLINGSTENDENSERNES
Parcook3
Oplagrede2
skitseprojekt
haandfuldt
Sekulariseredes
KURSUSLRERES
Tevandet
Snderrevnes5
Smkrest2
FORESTIAL
Cyclomania
Brandsikrer6
Rrtngers
AMORPHOTAE
REVELATORY
Filbetegnelsernes5
HEIKKI
Produktionsfejlenes
ebullitive
Intangibleness3
annoncrs
behowled
Achromatin
FOSSERS
ARDASSINE
CAHOKIA
indigestibleness
hylsteret
slettebos
Embrittlement5
STRETTOS
Impossibilist
Kamuflagernes5
Knortegssene6
Brerens7
Skattepligtsophret
UNSUMMONED
lyonnesse
puckerne
Unarrogating
planetoide
PETTAH
PAMELA
SALGBARES
TANKRENSNINGER
HARAUCANA
NEUROCLONIC
Kejsertitels
automobilers
maskotter
Aandelsere5
Photoisomerization4
01/01/01
anticly
threnode
Scytoblastema5
stemmeflerheden
landing
HVNERE
CUSTOM
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
041404B0
Comments
Microsoft Teams
CompanyName
Microsoft Corporation
FileDescription
Microsoft Teams
LegalCopyright
Microsoft Corporation
LegalTrademarks
ProductName
Microsoft Teams
FileVersion
1.09.0064
ProductVersion
1.09.0064
InternalName
Microsoft Teams
OriginalFilename
Microsoft Teams
Antivirus Signature
Bkav W32.AIDetect.malware1
Lionic Clean
Elastic malicious (high confidence)
MicroWorld-eScan Clean
FireEye Generic.mg.256876a198e1b3f8
CAT-QuickHeal Clean
ALYac Clean
Malwarebytes Clean
VIPRE Clean
CrowdStrike win/malicious_confidence_60% (D)
BitDefender Gen:Variant.Razy.913027
K7GW Clean
K7AntiVirus Clean
Baidu Clean
Cyren Clean
Symantec ML.Attribute.HighConfidence
ESET-NOD32 a variant of Win32/GenKryptik.FJKT
APEX Malicious
Paloalto Clean
ClamAV Clean
Alibaba Clean
NANO-Antivirus Clean
ViRobot Clean
Rising Clean
Ad-Aware Clean
Emsisoft Clean
Comodo Clean
F-Secure Clean
DrWeb Clean
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition Clean
CMC Clean
Sophos Clean
Ikarus Clean
Jiangmin Clean
Webroot Clean
Avira TR/Dropper.Gen
MAX Clean
Antiy-AVL Clean
Kingsoft Clean
Gridinsoft Clean
Arcabit Clean
SUPERAntiSpyware Clean
ZoneAlarm Clean
GData Clean
Cynet Malicious (score: 100)
AhnLab-V3 Clean
Acronis Clean
McAfee Clean
TACHYON Clean
VBA32 Clean
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Tencent Clean
Yandex Clean
SentinelOne Static AI - Suspicious PE
eGambit Unsafe.AI_Score_99%
Fortinet Clean
BitDefenderTheta Gen:NN.ZevbaF.34088.hm0@aWl78ypO
Avast Clean
MaxSecure Clean
No IRMA results available.