Static | ZeroBOX

PE Compile Time

2008-06-06 14:12:58

PE Imphash

b35907c8152cbadddd8bc306abc4b99c

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x000125a4 0x00013000 6.2562699571
.data 0x00014000 0x00000a34 0x00001000 0.0
.rsrc 0x00015000 0x000023a0 0x00003000 3.34101889132

Resources

Name Offset Size Language Sub-language File type
CUSTOM 0x00015668 0x000008be LANG_ENGLISH SUBLANG_ENGLISH_US MS Windows icon resource - 1 icon, 32x32, 8 bits/pixel
CUSTOM 0x00015668 0x000008be LANG_ENGLISH SUBLANG_ENGLISH_US MS Windows icon resource - 1 icon, 32x32, 8 bits/pixel
CUSTOM 0x00015668 0x000008be LANG_ENGLISH SUBLANG_ENGLISH_US MS Windows icon resource - 1 icon, 32x32, 8 bits/pixel
CUSTOM 0x00015668 0x000008be LANG_ENGLISH SUBLANG_ENGLISH_US MS Windows icon resource - 1 icon, 32x32, 8 bits/pixel
RT_ICON 0x00015540 0x00000128 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_GROUP_ICON 0x0001552c 0x00000014 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_VERSION 0x000151d0 0x0000035c LANG_ENGLISH SUBLANG_ENGLISH_US data

Imports

Library MSVBVM60.DLL:
0x401000 _CIcos
0x401004 _adj_fptan
0x401008 __vbaFreeVar
0x40100c __vbaStrVarMove
0x401010 __vbaFreeVarList
0x401014 _adj_fdiv_m64
0x401018 __vbaFreeObjList
0x40101c _adj_fprem1
0x401020 __vbaStrCat
0x401024 __vbaSetSystemError
0x40102c _adj_fdiv_m32
0x401030 None
0x401034 __vbaAryVar
0x401038 __vbaAryDestruct
0x40103c None
0x401040 __vbaObjSet
0x401044 None
0x401048 _adj_fdiv_m16i
0x40104c None
0x401050 __vbaObjSetAddref
0x401054 _adj_fdivr_m16i
0x401058 None
0x40105c None
0x401060 None
0x401064 __vbaFpR8
0x401068 _CIsin
0x40106c __vbaChkstk
0x401070 EVENT_SINK_AddRef
0x401078 __vbaStrCmp
0x40107c __vbaAryConstruct2
0x401080 DllFunctionCall
0x401084 _adj_fpatan
0x401088 None
0x40108c EVENT_SINK_Release
0x401090 _CIsqrt
0x401098 __vbaExceptHandler
0x40109c None
0x4010a0 _adj_fprem
0x4010a4 _adj_fdivr_m64
0x4010a8 __vbaVarErrI4
0x4010ac __vbaI2Str
0x4010b0 __vbaFPException
0x4010b4 _CIlog
0x4010b8 None
0x4010bc __vbaErrorOverflow
0x4010c0 __vbaNew2
0x4010c4 None
0x4010c8 _adj_fdiv_m32i
0x4010cc None
0x4010d0 _adj_fdivr_m32i
0x4010d4 __vbaStrCopy
0x4010d8 __vbaFreeStrList
0x4010dc _adj_fdivr_m32
0x4010e0 None
0x4010e4 _adj_fdiv_r
0x4010e8 None
0x4010ec __vbaStrToAnsi
0x4010f0 None
0x4010f4 None
0x4010f8 __vbaFpI4
0x4010fc _CIatan
0x401100 __vbaStrMove
0x401104 __vbaAryCopy
0x401108 _allmul
0x40110c _CItan
0x401110 _CIexp
0x401114 __vbaFreeObj
0x401118 __vbaFreeStr

!This program cannot be run in DOS mode.
`.data
MSVBVM60.DLL
overvg
Bcfop4
Underf8
>J"V{6
V?Y~*Z,]<
Ic"rRr
5A;;%i&
PMNRwj
WU:<:T<
+YVTaX
TGma,V.
XVc3=Z
=1{1/=7
>k%b+U
v:QMWq
Xm;1o>
+.RJ6;
wK6,Bi
&"YvJ*
>Zb\XVi
=1;5jZ/
XSLi1V
X$r-}RB
RZ7}p%
eiCU"m
#)ZX,1<
R@rBxM
I#X$v9
:BzX$?
v:RF4*
pAZ{jL
>Zr\XVs
%uuV}&
EDFY6&
][Z@_z&
4AT,NVoX<
o8B*%s
8z6SJY
+.RK,%
R@t3}3
2"oeRC
XROIWRw
3LdoZ'
>_Gh R
r:'$=_
a@MXVh
%pSXRKcXRG
WM:>d4:X$p
awI2-Q4
Z/XVbUXh
wK-,rNo
_RX<ty
VB5!6&*
Microsoft Teams
overvg
overvg
overvg
Bcfop4
Underf8
C:\Program Files (x86)\Microsoft Visual Studio\VB98\VB6.OLB
kernel32
FindClose
advapi32.dll
CryptGetProvParam
shlwapi.dll
PathStripToRootA
wsock32.dll
WSAIsBlocking
GetFileAttributesA
REELERS
Ungdomsarbejdslsheders
VBA6.DLL
__vbaAryVar
__vbaAryCopy
__vbaFpI4
__vbaI2Str
__vbaStrCat
__vbaStrCmp
__vbaErrorOverflow
__vbaFreeStr
__vbaAryDestruct
__vbaFreeObjList
__vbaFreeVarList
__vbaObjSetAddref
__vbaFreeStrList
__vbaSetSystemError
__vbaStrCopy
__vbaStrToAnsi
__vbaObjSet
__vbaFpR8
__vbaGenerateBoundsError
__vbaStrVarMove
__vbaFreeObj
__vbaHresultCheckObj
__vbaNew2
__vbaStrMove
__vbaFreeVar
__vbaVarErrI4
__vbaAryConstruct2
JhtnmJh
MSVBVM60.DLL
_CIcos
_adj_fptan
__vbaFreeVar
__vbaStrVarMove
__vbaFreeVarList
_adj_fdiv_m64
__vbaFreeObjList
_adj_fprem1
__vbaStrCat
__vbaSetSystemError
__vbaHresultCheckObj
_adj_fdiv_m32
__vbaAryVar
__vbaAryDestruct
__vbaObjSet
_adj_fdiv_m16i
__vbaObjSetAddref
_adj_fdivr_m16i
__vbaFpR8
_CIsin
__vbaChkstk
EVENT_SINK_AddRef
__vbaGenerateBoundsError
__vbaStrCmp
__vbaAryConstruct2
DllFunctionCall
_adj_fpatan
EVENT_SINK_Release
_CIsqrt
EVENT_SINK_QueryInterface
__vbaExceptHandler
_adj_fprem
_adj_fdivr_m64
__vbaVarErrI4
__vbaI2Str
__vbaFPException
_CIlog
__vbaErrorOverflow
__vbaNew2
_adj_fdiv_m32i
_adj_fdivr_m32i
__vbaStrCopy
__vbaFreeStrList
_adj_fdivr_m32
_adj_fdiv_r
__vbaStrToAnsi
__vbaFpI4
_CIatan
__vbaStrMove
__vbaAryCopy
_allmul
_CItan
_CIexp
__vbaFreeObj
__vbaFreeStr
!#%%'++,-0
0:874'
%++,-00177
,,-1147788
'0147788:88
14778888441
-888:8744-
::874410%
74110-
:87110
#+''%#!!!
#+-0-,+! #
77400,%!!
--+'#!
8:71-+%
+710,'
uSuttRKKQRRtyRRuuuuuz
zRRRuuttSLSSSKKKKJL
XRRuSuzzz
RRRRSRLuuuuSKC
CKRKDJJKRSzzzz
tKLRSLKzzzuSKC
JRKKKLLKDKSzzzy
KKLRKKzzzuuL"
zRKJKRzzt
KKKKKKuzLKSML"KRLKL
uSRKKKtzztsDDJKLLzzRLLLLDRLLKDKuuuRRQKKz
DKKLKzzzzuEERR$$LLtuRRLRRQKt
KLKKKzzzzu""tR#$KKLLLKRSRRKKzJ
DKLLLKzzzzK"CyLEDDKLRRttSRRKKtJ
DKKLLKuSSL#
JzLK##KttutLutRRKRDCEKEKLL##"""
st%DKLLtutL
uLRLLDELLLKKL
"yL%KLu
uRLKLLLLKKKED"
"tL%$$u
uuRKRuuLKEEDDR)""#*R$$$#L
uuSSSz
uKtuuLLKDDKSS+$##tK$$#LuSMLMSu
KtuMLEKKLLRL#"
"yK#""KSSLEELLu
KJLuLDDDKL#"
JR"""#LLE##"#KSzuCCLtLDDDDK
#K""#$L$$##EKLuuK
DLECDDDD"#"""#)""""""#EEDKLtK
RRLL****KJJD#"""""#D"
CS+*))K**KKKKKKJJKJD
RR+#"#*"#JJJKQK
SS+#""K"
""DDJJDC
"""CDDCC
""#DDDDD
"#JJJD
"#JJD"""""C
"""#J#""""""C
""DD"""
"C:\Progra
PRESIGNIFICANCY
Radiomodtagningen3
marmoromkrans
CUSTOM
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
040904B0
Comments
Microsoft Teams
CompanyName
Microsoft Corporation
FileDescription
Microsoft Teams
LegalCopyright
Microsoft Corporation
LegalTrademarks
ProductName
Microsoft Teams
FileVersion
1.08.0055
ProductVersion
1.08.0055
InternalName
Microsoft Teams
OriginalFilename
Microsoft Teams
Antivirus Signature
Bkav W32.AIDetect.malware2
Lionic Clean
Elastic malicious (high confidence)
Cynet Clean
CMC Clean
CAT-QuickHeal Clean
McAfee GuLoader-FCQZ!CD46DBF532B0
Cylance Unsafe
VIPRE Clean
Sangfor Trojan.Win32.Save.a
K7AntiVirus Clean
BitDefender Gen:Variant.Bulz.681383
K7GW Trojan-Downloader ( 005661971 )
Cybereason malicious.d1de42
BitDefenderTheta Clean
Cyren Clean
ESET-NOD32 Win32/TrojanDownloader.Agent.FCS
Baidu Clean
APEX Malicious
Paloalto generic.ml
ClamAV Win.Dropper.Guloader-9890276-0
Kaspersky UDS:DangerousObject.Multi.Generic
Alibaba Clean
NANO-Antivirus Clean
ViRobot Clean
MicroWorld-eScan Gen:Variant.Bulz.681383
Tencent Clean
Ad-Aware Gen:Variant.Bulz.681383
Emsisoft Clean
Comodo Malware@#37rrcy6fahxes
F-Secure Clean
DrWeb Clean
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition GuLoader-FCQZ!CD46DBF532B0
FireEye Generic.mg.cd46dbf532b047ca
Sophos Clean
SentinelOne Static AI - Malicious PE
GData Gen:Variant.Bulz.681383
Jiangmin Clean
MaxSecure Trojan.Malware.300983.susgen
Avira Clean
Antiy-AVL Clean
Kingsoft Win32.Troj.Generic_a.a.(kcloud)
Gridinsoft Clean
Arcabit Clean
SUPERAntiSpyware Clean
ZoneAlarm Clean
Microsoft Clean
TACHYON Clean
AhnLab-V3 Trojan/Win.Sabsik.C4622888
Acronis Clean
VBA32 Clean
ALYac Clean
MAX malware (ai score=85)
Malwarebytes Trojan.MalPack.VB
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Rising Clean
Yandex Clean
Ikarus Trojan.Win32.Krypt
eGambit Unsafe.AI_Score_100%
Fortinet W32/Malicious_Behavior.VEX
Webroot W32.Trojan.Gen
AVG Win32:Trojan-gen
Avast Win32:Trojan-gen
CrowdStrike win/malicious_confidence_90% (W)
No IRMA results available.