Static | ZeroBOX

PE Compile Time

2008-10-28 10:27:20

PE Imphash

c4b3ef5cd2bacd05c5793b6be4b1aeae

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x000424a4 0x00043000 5.66699188003
.data 0x00044000 0x000020d4 0x00001000 0.0
.rsrc 0x00047000 0x00029b48 0x0002a000 4.78833997635

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x000475e0 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x000475e0 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x000475e0 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x000475e0 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x000475e0 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x000475e0 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x000475e0 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x000475e0 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x000475e0 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x000475e0 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x000475e0 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x000475e0 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x000475e0 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_GROUP_ICON 0x00047524 0x000000bc LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_VERSION 0x00047330 0x000001f4 LANG_NORWEGIAN SUBLANG_NORWEGIAN_BOKMAL data

Imports

Library MSVBVM60.DLL:
0x401000 None
0x401004 _CIcos
0x401008 _adj_fptan
0x40100c __vbaFreeVar
0x401010 __vbaStrVarMove
0x401014 __vbaFreeVarList
0x401018 _adj_fdiv_m64
0x40101c __vbaFreeObjList
0x401020 None
0x401024 _adj_fprem1
0x401028 __vbaSetSystemError
0x401030 _adj_fdiv_m32
0x401034 __vbaAryDestruct
0x401038 __vbaObjSet
0x40103c __vbaOnError
0x401040 _adj_fdiv_m16i
0x401044 None
0x401048 _adj_fdivr_m16i
0x40104c None
0x401050 None
0x401054 _CIsin
0x401058 __vbaChkstk
0x40105c EVENT_SINK_AddRef
0x401064 __vbaStrCmp
0x401068 __vbaAryConstruct2
0x40106c __vbaR4Str
0x401070 DllFunctionCall
0x401074 _adj_fpatan
0x401078 EVENT_SINK_Release
0x40107c _CIsqrt
0x401084 __vbaExceptHandler
0x401088 _adj_fprem
0x40108c _adj_fdivr_m64
0x401090 __vbaFPException
0x401094 None
0x401098 _CIlog
0x40109c None
0x4010a0 __vbaNew2
0x4010a4 _adj_fdiv_m32i
0x4010a8 None
0x4010ac _adj_fdivr_m32i
0x4010b0 __vbaStrCopy
0x4010b4 _adj_fdivr_m32
0x4010b8 _adj_fdiv_r
0x4010bc None
0x4010c0 __vbaLateMemCall
0x4010c4 None
0x4010c8 __vbaStrToAnsi
0x4010cc None
0x4010d0 __vbaFpI4
0x4010d4 _CIatan
0x4010d8 __vbaStrMove
0x4010dc __vbaCastObj
0x4010e0 None
0x4010e4 _allmul
0x4010e8 _CItan
0x4010ec _CIexp
0x4010f0 __vbaFreeStr
0x4010f4 __vbaFreeObj
0x4010f8 None

!This program cannot be run in DOS mode.
`.data
MSVBVM60.DLL
Project5
cenobies
BYGGESAGEN
&iiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiii
"""""""""""""""""""""""""""""""""
^L^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
bjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjj
l>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>
nnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnn
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
hhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhh
MMMMMMMMMMMMMMMMMMMMMMMMMMMMM
mtWq9f
RRRRRRRRRRRRRRRRRRRRRRRRRRRRhu
wDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDD
*f{tq
ggggggggggggggggggggggggggggggggggggg
0"6H\$zK
&zse@GZ
?j^C?':
NL&zK5
s"l\_8
$zK]b{K
'zKLhy
&z's +
'zK\/}K
urrbuI
[<2q-1
"'zK?[Zv]
f5"^*K
A5"^IH3
$&zK\:
&{K=SZ
;Esu@C
"D1,&K
}zK?yN
-?y|-=
Nol<TJ
i'zK\- K
N(&zK=
>&z*scjE
>&z*=
&zH3&rK
&zH+&rK
&zK?fv
+>}_:Y
&zK?SZ
~EX@,-
sfj=l5
B&?R/V
NoF?_/0
6zK5NnK
&z/?;bK
&zD02xK
'zK?h^-1
&z~"<~sw@
lD10EK
x-=ix-C
?cZr|#
h?cZrm#j_
;RjNsmv
.zKKSR
.zKKSVsd
WoBZfsC#j
&zD1ZFK
4&2F-5
^%9_r@C
JI{--1
'zK\g\K
'zK=z^c
~o0~~d
T&zK\R9K
C2zK=c*
'zK?kb
?b^O?z^C0
?b^C?z^O=
&zK?fJ
>'zK ?
1D1p{K
."=,sl
?r^C?z^O0
&zK=Sv
?z^G?b^[
:[v"zsn
&zD1K]K
&zsS'vo\
<zK?z^W
%cNL&zK?nj
rfx#4Vx64Vx
='zK?m{
"&zKr%
&zD1u{K
$zK?m{
M'zK?%
&zK_i(
&zK?fJ
@uT0R&vx
B&QsX@C
&zD1FxK
~sle1zf
"c4]{K
*?~vr|F
fngfvnf
fnlffnnlff
llfll|l~lvnn
llflfo
flffff
ffffffffffffffffffffffflg|llllllllllllllllh
~v~v~vv
nnnnnnnh
ffffffh
flflff
ghggghw
tttttttttttttttttttttt
MN]]]]]]]]]]]]]]]]]]]]]]w
bbC66:::Bbbbbbbb
;;;;;;;
;;;;;;;
==( (=======
LLLLLLLLLLLLd
_LLLLLLLLLLLLJ
_IIIIIIIIIIIIJ
_IIIIIIIIIIIII
XIHIHIHIHIHIHI
X;;;;;;;;;;;;;
W;;H;H;H;H;H;;
333333333333w
%" ## ## ## ## ## ## ## #%%"##"%3%%3%%%%#
u:77:77:77:77:77:77:77:77:77C:77:77:77:77::u
@>>>>>>>>>>>>>>>T^ffw{}
?QbbbbbbbbbbbbbbaW
(MEFFFNOOOO(P:o
------,,/
s+++++++++
s*********
s"*"*"*"*"
s"""""""""
H]]]]]]]]]]]]]]]]]]]]]]]]]]]]H
JRStLc
)"""""""(558=?:8#KKKKKKK
#NKAA@AK2/.033-+"NK?AAAK6:@KNN=6!NAAAAAK6<@KNN=6!NKAAFFKA==@AA:+NNNJKKNN;<AAA:
JN;AGGK9
EN:@KK@;
EKGDAADF
EKKA@<=N
ENADKKFN
N1$$$%NNNNKFKN
KKKKKKKKKKKKFK
BYGGESAGEN
Command1
PAABEGYNDEGGENS
Check2
Warvesackers
Option2
Dulleunrelent8
Check1
Dgcasquetauri1
Option1
PRACTICIANBAN
Combo2
FODKOLDESGIAN
Combo1
gullansbry
VB5!6&*
Lathspellde8
Project5
Project5
Project5
cenobies
Fjernsynsante2
Lnudgifternes
Paracoroll
DIVERGEREDE
Combo2
C:\Program Files (x86)\Microsoft Visual Studio\VB98\VB6.OLB
Combo1
Option2
Option1
Command1
Check1
Check2
mpr.dll
WNetGetConnectionA
user32
BringWindowToTop
shell32
SHFormatDrive
kernel32
GetFileAttributesA
SCISSORSBIRD
VBA6.DLL
__vbaAryDestruct
__vbaFpI4
__vbaStrToAnsi
__vbaOnError
__vbaSetSystemError
__vbaLateMemCall
__vbaFreeVarList
__vbaCastObj
h__vbaGenerateBoundsError
__vbaStrCopy
__vbaR4Str
__vbaFreeObjList
__vbaObjSet
__vbaFreeObj
__vbaHresultCheckObj
__vbaNew2
__vbaStrVarMove
]__vbaFreeVar
__vbaFreeStr
__vbaStrMove
__vbaStrCmp
__vbaAryConstruct2
Lnudgifternes
Talksugpais3
Talksugpais3
Paracoroll
Baritonessste
Baritonessste
Fjernsynsante2
studierautomot
studierautomot
patosens
pecunious
}#j(h(
}#j$h(
MSVBVM60.DLL
_CIcos
_adj_fptan
__vbaFreeVar
__vbaStrVarMove
__vbaFreeVarList
_adj_fdiv_m64
__vbaFreeObjList
_adj_fprem1
__vbaSetSystemError
__vbaHresultCheckObj
_adj_fdiv_m32
__vbaAryDestruct
__vbaObjSet
__vbaOnError
_adj_fdiv_m16i
_adj_fdivr_m16i
_CIsin
__vbaChkstk
EVENT_SINK_AddRef
__vbaGenerateBoundsError
__vbaStrCmp
__vbaAryConstruct2
__vbaR4Str
DllFunctionCall
_adj_fpatan
EVENT_SINK_Release
_CIsqrt
EVENT_SINK_QueryInterface
__vbaExceptHandler
_adj_fprem
_adj_fdivr_m64
__vbaFPException
_CIlog
__vbaNew2
_adj_fdiv_m32i
_adj_fdivr_m32i
__vbaStrCopy
_adj_fdivr_m32
_adj_fdiv_r
__vbaLateMemCall
__vbaStrToAnsi
__vbaFpI4
_CIatan
__vbaStrMove
__vbaCastObj
_allmul
_CItan
_CIexp
__vbaFreeStr
__vbaFreeObj
)"""""""(558=?:8#KKKKKKK
#NKAA@AK2/.033-+"NK?AAAK6:@KNN=6!NAAAAAK6<@KNN=6!NKAAFFKA==@AA:+NNNJKKNN;<AAA:
JN;AGGK9
EN:@KK@;
EKGDAADF
EKKA@<=N
ENADKKFN
N1$$$%NNNNKFKN
KKKKKKKKKKKKFK
@>>>>>>>>>>>>>>>T^ffw{}
?QbbbbbbbbbbbbbbaW
(MEFFFNOOOO(P:o
------,,/
s+++++++++
s*********
s"*"*"*"*"
s"""""""""
H]]]]]]]]]]]]]]]]]]]]]]]]]]]]H
JRStLc
tttttttttttttttttttttt
MN]]]]]]]]]]]]]]]]]]]]]]w
bbC66:::Bbbbbbbb
;;;;;;;
;;;;;;;
==( (=======
LLLLLLLLLLLLd
_LLLLLLLLLLLLJ
_IIIIIIIIIIIIJ
_IIIIIIIIIIIII
XIHIHIHIHIHIHI
X;;;;;;;;;;;;;
W;;H;H;H;H;H;;
333333333333w
%" ## ## ## ## ## ## ## #%%"##"%3%%3%%%%#
u:77:77:77:77:77:77:77:77:77C:77:77:77:77::u
ghggghw
nnnnnnnh
ffffffh
flflff
fngfvnf
fnlffnnlff
llfll|l~lvnn
llflfo
flffff
ffffffffffffffffffffffflg|llllllllllllllllh
~v~v~vv
Samfundsvidenskabelig8
snderlemnings
ordrebehandlingen
brandsikre
wonderwoman
VINYLETS
Melada
Pelopidae5
Myomorpha9
NONCONFORMITANT
Bestandiges6
SANDFLUGTENS
chronologers
Konverteringsprogrammet
baccaras
Diazepams5
Terram4
apogeny
Superosculate1
Geminate8
UNDERDELENES
deoxycorticosterone
SIMULANTENS
OPLAGENES
diuron
PIASSAVAS
Sheepsteal
Fjedrede7
Nonhallucinated9
Strettas
Barbacou9
SEATMATE
exclosures
KRYDDERFEDTETS
OCCASIONALNESS
Skorstensfejermestre
Neurochorioretinitis
Pamaceous
Q0BZXEZ8VMJ67
Taabenakkernes
Floridans7
skrmbilledteksten
Lagerbeholdningerne
lbebanernes
kamelaukions
Jerkins
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
041404B0
ProductName
Project5
FileVersion
ProductVersion
InternalName
Lathspellde8
OriginalFilename
Lathspellde8.exe
Antivirus Signature
Bkav Clean
Lionic Trojan.Win32.Zbot.l!c
Elastic malicious (high confidence)
Cynet Malicious (score: 99)
CMC Clean
CAT-QuickHeal Clean
ALYac Trojan.GenericKD.37510170
Malwarebytes Malware.AI.4129293227
Zillya Clean
Sangfor Clean
CrowdStrike win/malicious_confidence_90% (W)
BitDefender Trojan.GenericKD.37510170
K7GW Trojan ( 00581a1f1 )
K7AntiVirus Trojan ( 00581a1f1 )
Baidu Clean
Cyren W32/VBKrypt.AZO.gen!Eldorado
Symantec ML.Attribute.HighConfidence
ESET-NOD32 a variant of Win32/GenKryptik.FJTP
APEX Malicious
Paloalto generic.ml
ClamAV Clean
Kaspersky HEUR:Trojan-Spy.Win32.Zbot.vho
Alibaba TrojanSpy:Win32/GenKryptik.f0566f5c
NANO-Antivirus Clean
SUPERAntiSpyware Clean
MicroWorld-eScan Trojan.GenericKD.37510170
Tencent Win32.Trojan-spy.Zbot.Sxoa
Ad-Aware Trojan.GenericKD.37510170
Emsisoft Trojan.GenericKD.37510170 (B)
Comodo Clean
F-Secure Clean
DrWeb Clean
VIPRE Clean
TrendMicro Clean
McAfee-GW-Edition BehavesLike.Win32.Worm.gm
FireEye Trojan.GenericKD.37510170
Sophos Mal/Generic-S
SentinelOne Static AI - Suspicious PE
GData Trojan.GenericKD.37510170
Jiangmin Clean
Webroot Clean
Avira TR/Kryptik.qhjxw
Antiy-AVL Clean
Kingsoft Clean
Gridinsoft Clean
Arcabit Trojan.Generic.D23C5C1A
ViRobot Clean
ZoneAlarm Clean
Microsoft Trojan:Script/Phonzy.C!ml
TACHYON Clean
AhnLab-V3 Clean
Acronis Clean
McAfee GuLoader-FDCJ!C568117333BE
MAX malware (ai score=86)
VBA32 TScope.Trojan.VB
Cylance Unsafe
Panda Trj/GdSda.A
Zoner Clean
TrendMicro-HouseCall Clean
Rising Clean
Yandex Trojan.Igent.bWu3BJ.3
Ikarus Trojan.VB.Crypt
eGambit Unsafe.AI_Score_99%
Fortinet W32/Agent.FCI!tr
BitDefenderTheta Gen:NN.ZevbaF.34126.Bm0@auhKQXbG
AVG Win32:Malware-gen
Avast Win32:Malware-gen
MaxSecure Trojan.Malware.300983.susgen
No IRMA results available.