Static | ZeroBOX

PE Compile Time

2014-10-26 09:47:43

PE Imphash

245400c685ff7f808270dbeca565e807

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x000449cc 0x00045000 4.79891424547
.data 0x00046000 0x00001474 0x00001000 0.0
.rsrc 0x00048000 0x0002d14b 0x0002e000 3.61863891099

Resources

Name Offset Size Language Sub-language File type
CUSTOM 0x0007222e 0x00000f84 LANG_ENGLISH SUBLANG_ENGLISH_US PNG image data, 48 x 48, 8-bit/color RGBA, non-interlaced
CUSTOM 0x0007222e 0x00000f84 LANG_ENGLISH SUBLANG_ENGLISH_US PNG image data, 48 x 48, 8-bit/color RGBA, non-interlaced
CUSTOM 0x0007222e 0x00000f84 LANG_ENGLISH SUBLANG_ENGLISH_US PNG image data, 48 x 48, 8-bit/color RGBA, non-interlaced
RT_ICON 0x000486ee 0x00010828 LANG_NEUTRAL SUBLANG_NEUTRAL dBase IV DBT, blocks size 0, block length 2048, next free block index 40, next free block 0, next used block 0
RT_ICON 0x000486ee 0x00010828 LANG_NEUTRAL SUBLANG_NEUTRAL dBase IV DBT, blocks size 0, block length 2048, next free block index 40, next free block 0, next used block 0
RT_ICON 0x000486ee 0x00010828 LANG_NEUTRAL SUBLANG_NEUTRAL dBase IV DBT, blocks size 0, block length 2048, next free block index 40, next free block 0, next used block 0
RT_ICON 0x000486ee 0x00010828 LANG_NEUTRAL SUBLANG_NEUTRAL dBase IV DBT, blocks size 0, block length 2048, next free block index 40, next free block 0, next used block 0
RT_ICON 0x000486ee 0x00010828 LANG_NEUTRAL SUBLANG_NEUTRAL dBase IV DBT, blocks size 0, block length 2048, next free block index 40, next free block 0, next used block 0
RT_ICON 0x000486ee 0x00010828 LANG_NEUTRAL SUBLANG_NEUTRAL dBase IV DBT, blocks size 0, block length 2048, next free block index 40, next free block 0, next used block 0
RT_ICON 0x000486ee 0x00010828 LANG_NEUTRAL SUBLANG_NEUTRAL dBase IV DBT, blocks size 0, block length 2048, next free block index 40, next free block 0, next used block 0
RT_ICON 0x000486ee 0x00010828 LANG_NEUTRAL SUBLANG_NEUTRAL dBase IV DBT, blocks size 0, block length 2048, next free block index 40, next free block 0, next used block 0
RT_ICON 0x000486ee 0x00010828 LANG_NEUTRAL SUBLANG_NEUTRAL dBase IV DBT, blocks size 0, block length 2048, next free block index 40, next free block 0, next used block 0
RT_ICON 0x000486ee 0x00010828 LANG_NEUTRAL SUBLANG_NEUTRAL dBase IV DBT, blocks size 0, block length 2048, next free block index 40, next free block 0, next used block 0
RT_ICON 0x000486ee 0x00010828 LANG_NEUTRAL SUBLANG_NEUTRAL dBase IV DBT, blocks size 0, block length 2048, next free block index 40, next free block 0, next used block 0
RT_ICON 0x000486ee 0x00010828 LANG_NEUTRAL SUBLANG_NEUTRAL dBase IV DBT, blocks size 0, block length 2048, next free block index 40, next free block 0, next used block 0
RT_GROUP_ICON 0x00048640 0x000000ae LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_VERSION 0x000483b0 0x00000290 LANG_ENGLISH SUBLANG_ENGLISH_US MS Windows COFF PA-RISC object file

Imports

Library MSVBVM60.DLL:
0x401000 None
0x401004 _CIcos
0x401008 _adj_fptan
0x40100c __vbaVarMove
0x401010 __vbaFreeVar
0x401014 None
0x401018 __vbaFreeVarList
0x40101c _adj_fdiv_m64
0x401020 __vbaFreeObjList
0x401024 _adj_fprem1
0x401028 None
0x401030 _adj_fdiv_m32
0x401034 None
0x401038 None
0x40103c None
0x401040 __vbaObjSet
0x401044 __vbaOnError
0x401048 _adj_fdiv_m16i
0x40104c _adj_fdivr_m16i
0x401050 None
0x401054 None
0x401058 None
0x40105c __vbaVarTstLt
0x401060 _CIsin
0x401064 __vbaChkstk
0x401068 EVENT_SINK_AddRef
0x40106c None
0x401070 __vbaI2I4
0x401074 DllFunctionCall
0x401078 None
0x40107c _adj_fpatan
0x401080 EVENT_SINK_Release
0x401084 _CIsqrt
0x40108c __vbaExceptHandler
0x401090 _adj_fprem
0x401094 _adj_fdivr_m64
0x401098 None
0x40109c __vbaFPException
0x4010a0 _CIlog
0x4010a4 __vbaFileOpen
0x4010a8 None
0x4010ac __vbaNew2
0x4010b0 None
0x4010b4 _adj_fdiv_m32i
0x4010b8 _adj_fdivr_m32i
0x4010bc __vbaStrCopy
0x4010c0 __vbaI4Str
0x4010c4 __vbaFreeStrList
0x4010c8 _adj_fdivr_m32
0x4010cc _adj_fdiv_r
0x4010d0 None
0x4010d4 __vbaVarTstNe
0x4010d8 __vbaVarAdd
0x4010dc None
0x4010e0 __vbaVarDup
0x4010e4 _CIatan
0x4010e8 __vbaStrMove
0x4010ec __vbaCastObj
0x4010f0 _allmul
0x4010f4 _CItan
0x4010f8 None
0x4010fc _CIexp
0x401100 __vbaFreeObj
0x401104 __vbaFreeStr

!This program cannot be run in DOS mode.
`.data
MSVBVM60.DLL
Liqueur2
Abencerrages7
Depotets6
>+:?Bs)iL:Bf
+::;!0
z=LrxG
LFyyLo
>xl?-L:^:
}qL_yU
m;1ay|
?x+dIH4
;2;w>0
}rHE^P
+i?'2M
=}xA&H
5?::&WS
=;1NxD
|{$_>+
2PeLq{
?x1;C&+
R8P.:U
fEI>:P
`Li|qHG
}qAq|r
;4@qALk
(IER_D
Ma|DI}
D7D|k7>
}pD}qIJ
Lh|kA.R
!o?::}
}`AB|`
6Ul?0:
-[R|GI
?2?&SH
Lb;;7F@
|NMaq.
=LOyIGK$
?5?)xC
#te+LV
Q2>":}t
TMc|_C
I@,IA$<
:1,m26:>
}sIJn]
SigIE5SYg
Mcq@Lpyx
MrqIMc
;3)!kAS
=?}.97>y
IE~+IL
C{4-:M
s>z"2u\
Mc}k!~7
Mh|xII
fLW|`IJ5i
}cs,^k
|MLp;P
}GELsyQ
qH@J|M
O!^>8:
VxAT:O
sqzIAj
qCAx{x
%}`LDy
j>y~2M
'c"i ]
HE<?-D
[CU h?
L:7.DO
;5>{x
cHFI:}
>1?.x|W
M`}iIP
?22>
:9],;7;
|^IE;4-
DS$D7D
s|xIzrsIG}iIJ
KLx}iI
DS$D7D
M7k}a7
?>>2RO
MiyD"
L?j^SS
k>|F,B
->`%nBh
C.n%hn
$D7!qn
)D73qn
{PS5u7D|2
|-l*"u
=b(2}
=>82Uw
=|FC&4
C|hL_|V
rIAkC;
}pLW|rC
pS.D7D
L?0a:MM
Ma|D7X
}aLy}`C
~L\|hIx
q?b|qC
M:;IL[JV]
}sLOyQ
}{Lj?>0
=|GL^y
+::{&J
>1:!Eiko:
MbqyI@N#
Q7DyDm
>):"]0
UIJE)y
|T>y6;
=|kLps.
DMrp>(
IR^ fk
n?8:>E?
X+h+C>:
!Lbp.G
}yHA@1]4
D*EqQLA
_eLsy>
=xB0m
<^LiyJ
?}%BIM
u^@4%*
%t:9ay'
u^@4%*
}`7ks6
Mzxz+>*P
=>xz83
y|{I@|Qt
L(Y"Ha
8S{@7D
^D7v1y%
]YXyCmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmm
4H\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\
pwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwH
T
\EEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEh
sH)!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!
:cccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccc
&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&
SSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSS
mmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmm
w/=QQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQ
KKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKK
F<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<
)\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\
fB-----------------------------------------------------------------------------------
UMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMM
a##########################################################################################
:#9KK!
+LLLLI
$=HI>$
604404
#$$.DC)$$#
Efff`
###Qggg=#
$#$#$$A'$*mmmU$$$$
7/$$$$:okVboooT$$$/7
+$$$booooooo9$$+
8,$$@jooool<$$,8
MK@$$(/;>9'$$@KM
bB,($$$-Ba
RieejR57
+//////+
////:ML3////
'++++?lllj8++++'
oqqqqZ
UWWWW%
Vllll>
=mmmmh"
fnnnng$
'' '' '' ''7prrrre)'' '' '
''+''+''+'''F||}}|\'+''+'+
'++,+,+,+,+,,G
2+,++,'
[#,/,/,/,/O.,/,t
H,/,/,#[
6//////;
K////6
@D//////b
6////D
S////6
r^////S
S///6c
`1///S
CAc4///9Tdw{s^<///4cAC
yP1//////////1Py
]K4////4K]
$+/8888/+$
+>BBBBBBBBBBBB>+
/BBBBB
BMNSEBBBBBBB+
>>>B>B>I
oB>B>B>B>
(66k8686;
b66868668(
(+/+/+/+/a
2/+/+/+/+(
$($($($($
4$($($($($
!{{{{{z
}}}}}"
$$$$$|
}}}}}`$$$$$$$$$
$($($($($($$($&
}}}}}}Z$($($($($($($($
$(((((((((((((((
e((((((((((((((($
(+(+(+(+(+
)+(+(+(+(+(+(+((
++++++++++++++++^
+++++++++++++++
+//+k//+///+///+/
1//+///+///+/+
/////////////////_
////////////+
+6/6/6/6/6/6/6/66/x
p66/6/6/6/66+
+666666666666666667
[6666666666+
$88>888>888>88888>87
8888>88888$
>>8>>>8>>>8>>>>>8k>H
O>>>8>>>>>
<>B>>>>>>>>>>T?>>>>>i
q>>>>>>>><
]B>>BBB>B>BB?
TBBBBP
tBB>BB>BB]
jBBBBBBBBBBr
sBBBBBBBj
hKBBBBBBBBE
XBBBBBBL
BBBBBBBBm
BBBkBBE
dyBBBBBBB
jBBBBBByc
vBBBBBE
nBBBBBEv
KBBBBBW
VBBBBBK
QBBBBBBLm
tQBBBBBBQ
KBBBBBBBBBBBBBBBBBBL
QFBBBBBBBBBBBBFQ
vjKBBBBBBKjv
Depotets6
Option4
Option4
Option3
Option3
Option2
Option2
Option1
Option1
Command2
Command2
Command1
Command1
Frame1
Frame1
MILJBESKYTTELSES
mollahs
Favntags
Label2
Label2
Label1
Label1
VB5!6&*
eftersmkkene
Liqueur2
Liqueur2
Liqueur2
Abencerrages7
Musette6
fahrenheittermometers
Kluklatters5
Leonines1
Tilholdssteds
DYNAMOELECTRICAL
Dipleidoscope
FRADRAGSBERETTIGEDES
C:\Program Files (x86)\Microsoft Visual Studio\VB98\VB6.OLB
MILJBESKYTTELSES
Option3
Option2
Option1
Option4
Command1
Command2
Label1
Label2
Frame1
mollahs
advapi32.dll
CryptDecrypt
kernel32
GlobalMemoryStatus
shlwapi.dll
PathIsRootA
user32
AppendMenuA
CallNextHookEx
Marekattes4
Overherredmmet
VBA6.DLL
__vbaFileOpen
__vbaFreeStr
__vbaVarTstLt
__vbaVarAdd
__vbaFreeStrList
__vbaStrCopy
__vbaOnError
__vbaVarDup
__vbaVarMove
__vbaFreeVarList
__vbaVarTstNe
__vbaFreeObjList
__vbaCastObj
__vbaObjSet
__vbaI2I4
__vbaI4Str
__vbaStrMove
__vbaFreeObj
__vbaHresultCheckObj
__vbaNew2
__vbaFreeVar
Musette6
Quaaludes1
Quaaludes1
00&0FD
Jvnaldrene4
Dechifrering1
MSVBVM60.DLL
_CIcos
_adj_fptan
__vbaVarMove
__vbaFreeVar
__vbaFreeVarList
_adj_fdiv_m64
__vbaFreeObjList
_adj_fprem1
__vbaHresultCheckObj
_adj_fdiv_m32
__vbaObjSet
__vbaOnError
_adj_fdiv_m16i
_adj_fdivr_m16i
__vbaVarTstLt
_CIsin
__vbaChkstk
EVENT_SINK_AddRef
__vbaI2I4
DllFunctionCall
_adj_fpatan
EVENT_SINK_Release
_CIsqrt
EVENT_SINK_QueryInterface
__vbaExceptHandler
_adj_fprem
_adj_fdivr_m64
__vbaFPException
_CIlog
__vbaFileOpen
__vbaNew2
_adj_fdiv_m32i
_adj_fdivr_m32i
__vbaStrCopy
__vbaI4Str
__vbaFreeStrList
_adj_fdivr_m32
_adj_fdiv_r
__vbaVarTstNe
__vbaVarAdd
__vbaVarDup
_CIatan
__vbaStrMove
__vbaCastObj
_allmul
_CItan
_CIexp
__vbaFreeObj
__vbaFreeStr
$+/8888/+$
+>BBBBBBBBBBBB>+
/BBBBB
BMNSEBBBBBBB+
>>>B>B>I
oB>B>B>B>
(66k8686;
b66868668(
(+/+/+/+/a
2/+/+/+/+(
$($($($($
4$($($($($
!{{{{{z
}}}}}"
$$$$$|
}}}}}`$$$$$$$$$
$($($($($($$($&
}}}}}}Z$($($($($($($($
$(((((((((((((((
e((((((((((((((($
(+(+(+(+(+
)+(+(+(+(+(+(+((
++++++++++++++++^
+++++++++++++++
+//+k//+///+///+/
1//+///+///+/+
/////////////////_
////////////+
+6/6/6/6/6/6/6/66/x
p66/6/6/6/66+
+666666666666666667
[6666666666+
$88>888>888>88888>87
8888>88888$
>>8>>>8>>>8>>>>>8k>H
O>>>8>>>>>
<>B>>>>>>>>>>T?>>>>>i
q>>>>>>>><
]B>>BBB>B>BB?
TBBBBP
tBB>BB>BB]
jBBBBBBBBBBr
sBBBBBBBj
hKBBBBBBBBE
XBBBBBBL
BBBBBBBBm
BBBkBBE
dyBBBBBBB
jBBBBBByc
vBBBBBE
nBBBBBEv
KBBBBBW
VBBBBBK
QBBBBBBLm
tQBBBBBBQ
KBBBBBBBBBBBBBBBBBBL
QFBBBBBBBBBBBBFQ
vjKBBBBBBKjv
+//////+
////:ML3////
'++++?lllj8++++'
oqqqqZ
UWWWW%
Vllll>
=mmmmh"
fnnnng$
'' '' '' ''7prrrre)'' '' '
''+''+''+'''F||}}|\'+''+'+
'++,+,+,+,+,,G
2+,++,'
[#,/,/,/,/O.,/,t
H,/,/,#[
6//////;
K////6
@D//////b
6////D
S////6
r^////S
S///6c
`1///S
CAc4///9Tdw{s^<///4cAC
yP1//////////1Py
]K4////4K]
#$$.DC)$$#
Efff`
###Qggg=#
$#$#$$A'$*mmmU$$$$
7/$$$$:okVboooT$$$/7
+$$$booooooo9$$+
8,$$@jooool<$$,8
MK@$$(/;>9'$$@KM
bB,($$$-Ba
RieejR57
:#9KK!
+LLLLI
$=HI>$
604404
tEXtSoftware
www.inkscape.org
&tEXtTitle
Sharingan 1.5 source file - 48px
)tEXtAuthor
Harenome Ranaivoarivony Razanajato[
tEXtCreation Time
November 12th 2010`
ctEXtCopyright
CC Attribution-NonCommercial-ShareAlike http://creativecommons.org/licenses/by-nc-sa/3.0/
`2A_2Ao<
@J<mxc
tEXtSoftware
www.inkscape.org
&tEXtTitle
Sharingan 1.5 source file - 48px
)tEXtAuthor
Harenome Ranaivoarivony Razanajato[
tEXtCreation Time
November 12th 2010`
ctEXtCopyright
CC Attribution-NonCommercial-ShareAlike http://creativecommons.org/licenses/by-nc-sa/3.0/
=IDATh
7O366f
4.T5=g
i51KKi
F1{r^o
Tg6HHU
"077wXD
CD~gii
tEXtSoftware
www.inkscape.org
&tEXtTitle
Sharingan 1.5 source file - 48px
)tEXtAuthor
Harenome Ranaivoarivony Razanajato[
tEXtCreation Time
November 12th 2010`
ctEXtCopyright
CC Attribution-NonCommercial-ShareAlike http://creativecommons.org/licenses/by-nc-sa/3.0/
RIDATh
efvgvv
`QDhD]
Kr9N%)
J>Ob-/E
,,,|9I
j,uciZ
Favntags
iv -ML -basi
SPEJDERHAGLS
Scioptics
Gallon
Cephalopodous9
saccharine
FUNCTIONALIZE
Sweptback
Thermoregulation
Troskyldigstes
CUSTOM
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
040904B0
Comments
ClickOpen
CompanyName
ClickOpen
FileDescription
ClickOpen
ProductName
ClickOpen
FileVersion
ProductVersion
InternalName
eftersmkkene
OriginalFilename
eftersmkkene.exe
Antivirus Signature
Bkav W32.AIDetect.malware2
Lionic Trojan.Win32.Mucc.4!c
Elastic malicious (high confidence)
DrWeb Clean
MicroWorld-eScan Trojan.GenericKD.46870114
FireEye Generic.mg.2644b63346379dd6
CAT-QuickHeal Clean
ALYac Clean
Cylance Clean
VIPRE Clean
Sangfor Trojan.Win32.Save.a
K7AntiVirus Clean
BitDefender Trojan.GenericKD.46870114
K7GW Clean
Cybereason Clean
BitDefenderTheta Gen:NN.ZevbaF.34110.Dm0@aWfcKAgi
Cyren Clean
Symantec ML.Attribute.HighConfidence
ESET-NOD32 a variant of Win32/Kryptik.HMFW
Zoner Clean
TrendMicro-HouseCall Clean
Paloalto generic.ml
ClamAV Clean
Kaspersky Trojan.Win32.Mucc.qoh
Alibaba Clean
NANO-Antivirus Clean
ViRobot Clean
Tencent Clean
Ad-Aware Trojan.GenericKD.46870114
Sophos Mal/Generic-S
Comodo TrojWare.Win32.UMal.clclm@0
F-Secure Clean
Baidu Clean
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition BehavesLike.Win32.Trojan.gt
SentinelOne Static AI - Malicious PE
CMC Clean
Emsisoft Trojan.GenericKD.46870114 (B)
Ikarus Clean
GData Trojan.GenericKD.46870114
Jiangmin Clean
Webroot Clean
Avira Clean
Antiy-AVL Clean
Kingsoft Win32.Troj.Mucc.q.(kcloud)
Gridinsoft Trojan.Win32.Generic.oa
Arcabit Trojan.Generic.D2CB2E62
SUPERAntiSpyware Clean
ZoneAlarm Clean
Microsoft Trojan:Win32/Sabsik.FL.B!ml
Cynet Clean
AhnLab-V3 Clean
Acronis Clean
McAfee Artemis!2644B6334637
MAX Clean
VBA32 Clean
Malwarebytes Clean
Panda Clean
APEX Malicious
Rising Clean
Yandex Clean
TACHYON Clean
eGambit Clean
Fortinet W32/Mucc.QOH!tr
AVG FileRepMetagen [Malware]
Avast FileRepMetagen [Malware]
CrowdStrike win/malicious_confidence_90% (W)
MaxSecure Trojan.Malware.300983.susgen
No IRMA results available.