Static | ZeroBOX

PE Compile Time

2013-11-22 22:32:14

PE Imphash

40768f14753bfb2d577d092577251956

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x0000e53c 0x0000f000 6.69730517613
.data 0x00010000 0x000011b8 0x00001000 0.0
.rsrc 0x00012000 0x000027a6 0x00003000 3.94564661077

Resources

Name Offset Size Language Sub-language File type
CUSTOM 0x000129f4 0x000008be LANG_ENGLISH SUBLANG_ENGLISH_US MS Windows icon resource - 1 icon, 32x32, 8 bits/pixel
CUSTOM 0x000129f4 0x000008be LANG_ENGLISH SUBLANG_ENGLISH_US MS Windows icon resource - 1 icon, 32x32, 8 bits/pixel
CUSTOM 0x000129f4 0x000008be LANG_ENGLISH SUBLANG_ENGLISH_US MS Windows icon resource - 1 icon, 32x32, 8 bits/pixel
RT_ICON 0x000124b4 0x00000128 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x000124b4 0x00000128 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x000124b4 0x00000128 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_GROUP_ICON 0x00012484 0x00000030 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_VERSION 0x00012200 0x00000284 LANG_NORWEGIAN SUBLANG_NORWEGIAN_BOKMAL data

Imports

Library MSVBVM60.DLL:
0x401000 None
0x401004 __vbaStrI2
0x401008 _CIcos
0x40100c _adj_fptan
0x401010 __vbaFreeVar
0x401014 __vbaLineInputStr
0x401018 __vbaStrVarMove
0x40101c __vbaFreeVarList
0x401020 _adj_fdiv_m64
0x401024 __vbaFreeObjList
0x401028 _adj_fprem1
0x40102c __vbaStrCat
0x401030 __vbaSetSystemError
0x401038 _adj_fdiv_m32
0x40103c None
0x401040 None
0x401044 __vbaObjSet
0x401048 __vbaOnError
0x40104c _adj_fdiv_m16i
0x401050 __vbaObjSetAddref
0x401054 _adj_fdivr_m16i
0x401058 __vbaFpR8
0x40105c _CIsin
0x401060 __vbaChkstk
0x401064 __vbaFileClose
0x401068 EVENT_SINK_AddRef
0x40106c __vbaStrCmp
0x401070 __vbaObjVar
0x401074 __vbaI2I4
0x401078 DllFunctionCall
0x40107c _adj_fpatan
0x401080 EVENT_SINK_Release
0x401084 _CIsqrt
0x40108c __vbaExceptHandler
0x401090 _adj_fprem
0x401094 _adj_fdivr_m64
0x401098 None
0x40109c __vbaFPException
0x4010a0 __vbaStrVarVal
0x4010a4 None
0x4010a8 _CIlog
0x4010ac __vbaFileOpen
0x4010b0 __vbaNew2
0x4010b4 None
0x4010b8 __vbaInStr
0x4010bc None
0x4010c0 _adj_fdiv_m32i
0x4010c4 _adj_fdivr_m32i
0x4010c8 None
0x4010cc __vbaI4Str
0x4010d0 __vbaFreeStrList
0x4010d4 _adj_fdivr_m32
0x4010d8 _adj_fdiv_r
0x4010dc None
0x4010e0 None
0x4010e4 __vbaLateMemCall
0x4010e8 __vbaStrToAnsi
0x4010ec None
0x4010f0 __vbaFpI4
0x4010f4 _CIatan
0x4010f8 __vbaStrMove
0x4010fc __vbaR8IntI4
0x401100 _allmul
0x401104 __vbaLateIdSt
0x401108 _CItan
0x40110c _CIexp
0x401110 __vbaFreeStr
0x401114 __vbaFreeObj
0x401118 None

!This program cannot be run in DOS mode.
`.data
MSVBVM60.DLL
Smaating
Incolumityfeebl4
eftersgningersp
eftersgningersp
chkLoadTipsAtStartup
&Show Tips at Startup
cmdNextTip
&Next Tip
Picture1
Label1
Did you know...
lblTipText
Label3
throughgan
Substagestrafi7
Frugtavlerneat9
omdigtning
TEAKTRSS
FAGFORENINGSF
wuchereriaoxeat
Tagassuid
Squdgysublimer
DRILBORROGUES
OPHAVSRETTIG
Dolmanensunli9
Traverierne
AKVARIEPLANT
Byttetudmat3
Adventuristlap7
COTTIERMONOTH
fibersprn
Racemssi
Image1
3hj3t?
*ij;M?
Drjj;[?
VdfTD`
\0`l,j$
nXdN\:
<%KF3E
>'h3h?
"!eU]R
XdGgJy
PNdV\y
4X`pE8G
Md&`D(Z
n%(7`l
e.X+;
V6hN6*j
6Y`l9N
7:h3L?
(rjWev
_X`3K?
y5by"
5C2y"|._g
u]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]<
- f
WfLLLLLLLLLLLLLLLLLLLLLLLLLLLLLLLLLLLLLLLLLLL
]******************************************
VB5!6&*
overcens
Smaating
Smaating
Smaating
Incolumityfeebl4
SPEKTRALF
Dolmanensunli9
C:\Program Files (x86)\Microsoft Visual Studio\VB98\VB6.OLB
fibersprn
Label1
Label3
AKVARIEPLANT
cmdNextTip
Tagassuid
FAGFORENINGSF
chkLoadTipsAtStartup
lblTipText
Picture1
omdigtning
Substagestrafi7
DRILBORROGUES
Image1
Adventuristlap7
user32
SetSysColors
SetForegroundWindow
kernel32
GetDriveTypeA
WSOCK32
WSACleanup
LoadTips
DisplayCurrentTip
HAMMERINGLY
__vbaLateIdSt
VBA6.DLL
__vbaStrToAnsi
__vbaStrVarMove
__vbaOnError
__vbaFpI4
__vbaSetSystemError
__vbaInStr
__vbaFpR8
__vbaStrVarVal
__vbaStrCat
__vbaI2I4
__vbaI4Str
__vbaFreeObj
__vbaObjSetAddref
__vbaFreeObjList
__vbaFreeStrList
__vbaObjSet
__vbaStrI2
__vbaFileClose
__vbaFreeVarList
__vbaLineInputStr
__vbaFileOpen
__vbaFreeStr
__vbaStrMove
__vbaStrCmp
__vbaObjVar
__vbaLateMemCall
__vbaFreeVar
__vbaHresultCheckObj
__vbaNew2
__vbaR8IntI4
SPEKTRALF
UDKLIPSB
UDKLIPSB
Genkbsvrdiernes
PEDANTOCRATIC
Mustnt
betragteligste
j Wh{
MSVBVM60.DLL
__vbaStrI2
_CIcos
_adj_fptan
__vbaFreeVar
__vbaLineInputStr
__vbaStrVarMove
__vbaFreeVarList
_adj_fdiv_m64
__vbaFreeObjList
_adj_fprem1
__vbaStrCat
__vbaSetSystemError
__vbaHresultCheckObj
_adj_fdiv_m32
__vbaObjSet
__vbaOnError
_adj_fdiv_m16i
__vbaObjSetAddref
_adj_fdivr_m16i
__vbaFpR8
_CIsin
__vbaChkstk
__vbaFileClose
EVENT_SINK_AddRef
__vbaStrCmp
__vbaObjVar
__vbaI2I4
DllFunctionCall
_adj_fpatan
EVENT_SINK_Release
_CIsqrt
EVENT_SINK_QueryInterface
__vbaExceptHandler
_adj_fprem
_adj_fdivr_m64
__vbaFPException
__vbaStrVarVal
_CIlog
__vbaFileOpen
__vbaNew2
__vbaInStr
_adj_fdiv_m32i
_adj_fdivr_m32i
__vbaI4Str
__vbaFreeStrList
_adj_fdivr_m32
_adj_fdiv_r
__vbaLateMemCall
__vbaStrToAnsi
__vbaFpI4
_CIatan
__vbaStrMove
__vbaR8IntI4
_allmul
__vbaLateIdSt
_CItan
_CIexp
__vbaFreeStr
__vbaFreeObj
uuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuu
uuuuuuuuuuuuuuuuuuuuuuu
uuuuuuuuuuuuuuuuuu
uuuuuuuuuuuuuuu"F
uuuuuuuuuuuuS@
r)2m+&%%%&
uuuuuuuuuuo!er%))%%s%))%*+
uuuuuuuu"Q0+
3%)))))%)/
+01uuuuuuu
q%%+)))))))%345
6uuuuuup
/)))))).)
</))))))))
?uuuuoZ!Q+)
%))))))))+$A
9>%).+%)))))))/
%))))))))%)%
JWK9G3%&
+%))))+3)%)&3%3
++GA))))%&
3&))%%3$
+3)))))%
2%)))))
m))%+3
%))))%2)+
WB<)3W$j
)).3%/)))))%3)+
MuuuF!l<%)+3
Xm3+3))3.%+3++)&
QRuuukW@W&%))
3G))&++
)%$@Tuuu(<d
)))><+
+%/)&
RuuuuuR
 Iuuuuuuui<
KYuuuuuuu
<8Z99%%
[uuuuuuuuu
[uuuuuuuuuuuag
<JK!<K5
uuuuuuuuuuuuuu
,uuuuuuuuuuuuuuuua^b#c
1(uuuuuuuuuuuuuuuuuuuu
H`???V_(
uuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuu
555333335555
553333
!!;>;;
##='&77*&###
))& 7(,,*
##* :,(( %//8----)
).,>(:%
666666
XF-\N,
m1|h1}i0{g1zf2yd2yd2zd2ye2yd2ze2zf2xjK
Pdss]&
l4zf1yc1xb2xa1xa2w`2x`2w`2ya2zd2zc
XS;v[&zc3xa2v_1u]1u\1u\1u\2u]1v^2w_2
S[_gO$uY*w]3v\3uY2tX2rW2sY2tZ2u[2ia3]v
[XNaF%gJ'iN,nP1qS1rU1rW2sW2CTat
iJ.pQ2oP2pR2rT1O]e{
bQHkD'oM4jH*pP2pR2Zfj\x
^bfsP&mQ3fL6cC,
q]vZIfC+~aMeE+oO2~h.pe?fg\bjo
|i2{f0~^!ndM
}i1zg3y`,kdR}
^^bhX8D
WXKSeZ`i^K_UO
}i2zg3{`*keR
h_bF~k1
|h2zg2{b,mbJ
kmloQ+P}ojQ8G
yVi[NtkoB*SnbM{ouD$~k2{h1ye2x_0l`IrY5sT0wH%oM/vA#qD)r@&lJ2sD(uD%mR4~j2}i2zf1xb2y],tZ1rW2pV4pR2mR5nP3mO4nN1nR4nS4qR1}j2
l2{g2yd1va5u\2tY1sW2qS2pS2pQ2oP2oP2pR2qS2rU2
TIPOFDAY.TXT
DisplayCurrentTip
Options
Show Tips at Startup
That the
file was not found?
Create a text file named
using NotePad with 1 tip per line.
Then place it in the same directory as the application.
BIOGENSOCTAETER
Runitehydrophil
SKILLEVGSFLYTNINGERNE
REBOPS
Dintless5
BALSAMICAL
Vejrtraekning
Ingenirstuderendes8
CUSTOM
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
041404B0
Comments
Thunderbirds
CompanyName
FileDescription
VAB, Inc.
ProductName
Alloes.com
FileVersion
ProductVersion
InternalName
overcens
OriginalFilename
overcens.exe
Antivirus Signature
Bkav W32.AIDetect.malware1
Elastic malicious (high confidence)
DrWeb Clean
MicroWorld-eScan Gen:Variant.Razy.936011
FireEye Generic.mg.0379cf12ef3850e1
CAT-QuickHeal Clean
ALYac Clean
Malwarebytes Clean
VIPRE Clean
Sangfor Clean
K7AntiVirus Clean
BitDefender Gen:Variant.Razy.936011
K7GW Clean
Cybereason malicious.9a1c75
BitDefenderTheta Gen:NN.ZevbaCO.34142.fm0@aaC3SegO
Cyren Clean
Symantec ML.Attribute.HighConfidence
ESET-NOD32 a variant of Win32/GenKryptik.FKVY
Zoner Clean
TrendMicro-HouseCall TROJ_GEN.R06CC0DIK21
Paloalto generic.ml
ClamAV Clean
Kaspersky UDS:DangerousObject.Multi.Generic
Alibaba Clean
NANO-Antivirus Clean
ViRobot Clean
Tencent Clean
Ad-Aware Gen:Variant.Razy.936011
Emsisoft Gen:Variant.Razy.936011 (B)
Comodo Clean
F-Secure Clean
Baidu Clean
Zillya Clean
TrendMicro Clean
CMC Clean
Sophos Mal/Generic-S
SentinelOne Static AI - Suspicious PE
Jiangmin Clean
MaxSecure Trojan.Malware.300983.susgen
Avira Clean
MAX malware (ai score=88)
Antiy-AVL Clean
Kingsoft Clean
Gridinsoft Clean
Arcabit Clean
SUPERAntiSpyware Clean
ZoneAlarm Clean
GData Gen:Variant.Razy.936011
Cynet Clean
AhnLab-V3 Clean
Acronis Clean
McAfee Artemis!0379CF12EF38
TACHYON Clean
VBA32 Clean
Panda Clean
APEX Malicious
Rising Clean
Yandex Clean
Ikarus Clean
eGambit Unsafe.AI_Score_99%
Fortinet Clean
Webroot W32.Trojan.Gen
AVG FileRepMalware
Avast FileRepMalware
CrowdStrike Clean
No IRMA results available.