Static | ZeroBOX

PE Compile Time

2008-09-20 14:15:12

PE Imphash

fce467e88e97640985186c490e0bba21

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x0000e318 0x0000f000 6.69996607223
.data 0x00010000 0x000011c4 0x00001000 0.0
.rsrc 0x00012000 0x000009f5 0x00001000 2.31676439479

Resources

Name Offset Size Language Sub-language File type
CUSTOM 0x00012998 0x0000005d LANG_ENGLISH SUBLANG_ENGLISH_US ASCII text, with CRLF line terminators
RT_ICON 0x00012458 0x00000128 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x00012458 0x00000128 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x00012458 0x00000128 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_GROUP_ICON 0x00012428 0x00000030 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_VERSION 0x000121a0 0x00000288 LANG_CHINESE SUBLANG_CHINESE_TRADITIONAL data

Imports

Library MSVBVM60.DLL:
0x401000 None
0x401004 _CIcos
0x401008 _adj_fptan
0x40100c __vbaFreeVar
0x401010 __vbaStrVarMove
0x401014 __vbaFreeVarList
0x401018 _adj_fdiv_m64
0x40101c __vbaFreeObjList
0x401020 _adj_fprem1
0x401024 None
0x401028 __vbaSetSystemError
0x40102c None
0x401034 None
0x401038 _adj_fdiv_m32
0x40103c None
0x401040 __vbaAryDestruct
0x401044 None
0x401048 None
0x40104c __vbaObjSet
0x401050 _adj_fdiv_m16i
0x401054 _adj_fdivr_m16i
0x401058 None
0x40105c __vbaFpR8
0x401060 _CIsin
0x401064 __vbaChkstk
0x401068 EVENT_SINK_AddRef
0x401070 __vbaStrCmp
0x401074 __vbaVarTstEq
0x401078 __vbaI2I4
0x40107c DllFunctionCall
0x401080 None
0x401084 _adj_fpatan
0x401088 __vbaRedim
0x40108c EVENT_SINK_Release
0x401090 None
0x401094 None
0x401098 __vbaUI1I2
0x40109c _CIsqrt
0x4010a4 __vbaExceptHandler
0x4010a8 None
0x4010ac _adj_fprem
0x4010b0 _adj_fdivr_m64
0x4010b4 None
0x4010b8 __vbaFPException
0x4010bc None
0x4010c0 _CIlog
0x4010c4 None
0x4010c8 __vbaNew2
0x4010cc None
0x4010d0 __vbaInStr
0x4010d4 _adj_fdiv_m32i
0x4010d8 _adj_fdivr_m32i
0x4010dc __vbaStrCopy
0x4010e0 __vbaI4Str
0x4010e4 __vbaFreeStrList
0x4010e8 _adj_fdivr_m32
0x4010ec _adj_fdiv_r
0x4010f0 None
0x4010f4 __vbaVarDup
0x4010f8 __vbaStrToAnsi
0x4010fc __vbaFpI4
0x401100 _CIatan
0x401104 __vbaStrMove
0x401108 __vbaCastObj
0x40110c None
0x401110 _allmul
0x401114 __vbaLateIdSt
0x401118 _CItan
0x40111c _CIexp
0x401120 __vbaFreeObj
0x401124 __vbaFreeStr

!This program cannot be run in DOS mode.
`.data
MSVBVM60.DLL
Mastodont
vaskemaskinefa
Temposkiftenes9
Temposkiftenes9
Label3
Barragedhalvd3
Substagestrafi7
neophronroc
omdigtning
Doradosigu3
FAGFORENINGSF
imdegaaed
Tagassuid
PRECONCE
DRILBORROGUES
afsnitssort
Dolmanensunli9
heaterbille
AKVARIEPLANT
Mikvehphotos1
Adventuristlap7
tailrace
fibersprn
Chalcophileco
Image1
b3eqkOt
28&R8:
LRXLR6
QvPxjC+L
Zt3RF'C
nKk`iy
U?SvPN
.vFWR%c
Sv_CVuP
SwPntq
J]vPD.
QvP8&R
RvP/FsP
kwFWR;5
Sv_CnwP
RvPL&V
RvP|9j
=L.Vh
URvP8&
CSvP/[=P
QvP/WvP
Sv83\y*FgR
#HZFWR
PRvP8&R
tPcr?'
4(T=."{
[vP8&V
Sv_CowP
SvS@S~P
+D/z2P
SvSXS~P
LRvPNPN
[vPN#nSp
SvS@S~P
GRvPxRh)/
CvPF;bP
Sv_C[wP
?5'6~-
rtJfqQ8&&
2RvP/-&P
rte@t#F
RvP8&J
QRvP][
Sv_B(tP
Q[wcIFb
QvP/7mP
RvP/yuP
RxLSCz
h:5%6|
U7SvPL
{SvP._
La/egP
7[C9?D
5!k+7cU
|@5R/{
.SvP.rZP
rPLR\L
#\/TvP
QvPLRT
6LOl6LS
RTLRX
1MW|Q4auy4
,u`G,]W
Sv0-Sv_H
AizQtP
>@NRXN
FgR\F/
G#|+G#|cB
}XG#}FG#}
~On<e7
mRvP/^rP
Sv_C!tP
ZGeY>(
TRvPLXN
SvkBvtP
.HFksP
QQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQ
G3~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
N1!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!
BBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBB
||||||||||||||||||||||||||||||||||||||||||||||f
*pcwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwww
BFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF
aGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGG<J
VB5!6&*
gormandized
Mastodont
Mastodont
Mastodont
vaskemaskinefa
uncanvasse
C:\Program Files (x86)\Microsoft Visual Studio\VB98\VB6.OLB
omdigtning
Substagestrafi7
DRILBORROGUES
Image1
Adventuristlap7
Dolmanensunli9
fibersprn
Label3
AKVARIEPLANT
Tagassuid
FAGFORENINGSF
kernel32
_lclose
GetEnvironmentVariableA
advapi32.dll
BackupEventLogA
GetTempPathA
user32
DestroyIcon
GetFileSize
GetTickCount
VBA6.DLL
__vbaFpR8
__vbaFpI4
__vbaAryDestruct
__vbaStrVarMove
__vbaUI1I2
__vbaGenerateBoundsError
__vbaRedim
__vbaFreeVarList
__vbaInStr
__vbaStrCopy
__vbaI2I4
__vbaLateIdSt
__vbaFreeObjList
__vbaCastObj
__vbaObjSet
__vbaFreeStrList
__vbaSetSystemError
__vbaStrToAnsi
__vbaVarDup
__vbaFreeStr
__vbaStrCmp
__vbaFreeObj
__vbaHresultCheckObj
__vbaNew2
__vbaStrMove
__vbaFreeVar
__vbaI4Str
__vbaVarTstEq
%=4J4&t
uncanvasse
Drubblylikv
Drubblylikv
MSVBVM60.DLL
_CIcos
_adj_fptan
__vbaFreeVar
__vbaStrVarMove
__vbaFreeVarList
_adj_fdiv_m64
__vbaFreeObjList
_adj_fprem1
__vbaSetSystemError
__vbaHresultCheckObj
_adj_fdiv_m32
__vbaAryDestruct
__vbaObjSet
_adj_fdiv_m16i
_adj_fdivr_m16i
__vbaFpR8
_CIsin
__vbaChkstk
EVENT_SINK_AddRef
__vbaGenerateBoundsError
__vbaStrCmp
__vbaVarTstEq
__vbaI2I4
DllFunctionCall
_adj_fpatan
__vbaRedim
EVENT_SINK_Release
__vbaUI1I2
_CIsqrt
EVENT_SINK_QueryInterface
__vbaExceptHandler
_adj_fprem
_adj_fdivr_m64
__vbaFPException
_CIlog
__vbaNew2
__vbaInStr
_adj_fdiv_m32i
_adj_fdivr_m32i
__vbaStrCopy
__vbaI4Str
__vbaFreeStrList
_adj_fdivr_m32
_adj_fdiv_r
__vbaVarDup
__vbaStrToAnsi
__vbaFpI4
_CIatan
__vbaStrMove
__vbaCastObj
_allmul
__vbaLateIdSt
_CItan
_CIexp
__vbaFreeObj
__vbaFreeStr
Flertalsbeslutn9 = 0, 0, 0, 0, C, 0, 0, 0, 0, C
disbeliever = 0, 0, 0, 0, C, 0, 0, 0, 0, C
Pilgrimatic1
skinproblemers
GRAHAMISM
CRUSTIFICATION
radiolites
Undabbled
Reuniting1
Natteros4
RAKETVRNS
AFVENDELSE
INDEVOUTLY
holoenzyme
BIOGENSOCTAETER
Runitehydrophil
Puffball9
17:17:17
bladformet
CUMBERERS
SANKTIONR
NOTBAAD
aphasiology
Transhumanize9
CUSTOM
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
040404B0
Comments
ClipLess
CompanyName
ClipLess
FileDescription
ClipLess
ProductName
ClipLess
FileVersion
ProductVersion
InternalName
gormandized
OriginalFilename
gormandized.exe
Antivirus Signature
Bkav W32.AIDetect.malware2
Lionic Trojan.Win32.Malicious.4!c
Elastic malicious (high confidence)
MicroWorld-eScan Trojan.GenericKD.46968202
FireEye Generic.mg.4399c694e88f3f32
CAT-QuickHeal Clean
ALYac Clean
Cylance Unsafe
VIPRE Clean
Sangfor Clean
K7AntiVirus Clean
BitDefender Trojan.GenericKD.46968202
K7GW Clean
Cybereason malicious.581c55
Arcabit Trojan.Generic.D2CCAD8A
BitDefenderTheta Gen:NN.ZevbaF.34142.em0@aamCTWfj
Cyren W32/VBKrypt.AZY.gen!Eldorado
Symantec Trojan.Gen.2
ESET-NOD32 a variant of Win32/Injector.EQBW
Baidu Clean
APEX Malicious
Paloalto generic.ml
ClamAV Clean
Kaspersky Trojan.Win32.Vebzenpak.agnf
Alibaba Clean
NANO-Antivirus Clean
ViRobot Clean
Rising Clean
Ad-Aware Trojan.GenericKD.46968202
Emsisoft Trojan.GenericKD.46968202 (B)
Comodo Clean
F-Secure Clean
DrWeb Clean
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition BehavesLike.Win32.Fareit.lh
CMC Clean
Sophos Mal/Generic-S
SentinelOne Static AI - Suspicious PE
Jiangmin Clean
MaxSecure Trojan.Malware.300983.susgen
Avira Clean
MAX malware (ai score=100)
Antiy-AVL Clean
Kingsoft Clean
Gridinsoft Trojan.Win32.Downloader.sa
Microsoft Trojan:Win32/VBObfuse.SS!MTB
SUPERAntiSpyware Clean
ZoneAlarm Clean
GData Trojan.GenericKD.46968202
Cynet Malicious (score: 100)
AhnLab-V3 Clean
Acronis Clean
McAfee RDN/Generic.dx
TACHYON Clean
VBA32 Clean
Malwarebytes Clean
Panda Trj/RnkBend.A
Zoner Clean
TrendMicro-HouseCall Clean
Tencent Win32.Trojan.Inject.Auto
Yandex Clean
Ikarus Trojan.Win32.Injector
eGambit Unsafe.AI_Score_99%
Fortinet W32/Injector.EQBW!tr
Webroot W32.Trojan.Gen
AVG Win32:Trojan-gen
Avast Win32:Trojan-gen
CrowdStrike win/malicious_confidence_100% (W)
No IRMA results available.