Static | ZeroBOX

PE Compile Time

2012-07-08 10:58:09

PE Imphash

59f9582f251e861f2c149d17f4ba80d5

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x00017768 0x00018000 6.77651174166
.data 0x00019000 0x00001654 0x00001000 0.0
.rsrc 0x0001b000 0x000021f2 0x00003000 2.12518313424

Resources

Name Offset Size Language Sub-language File type
CUSTOM 0x0001babc 0x0000057e LANG_ENGLISH SUBLANG_ENGLISH_US MS Windows icon resource - 1 icon, 16x16, 8 bits/pixel
CUSTOM 0x0001babc 0x0000057e LANG_ENGLISH SUBLANG_ENGLISH_US MS Windows icon resource - 1 icon, 16x16, 8 bits/pixel
CUSTOM 0x0001babc 0x0000057e LANG_ENGLISH SUBLANG_ENGLISH_US MS Windows icon resource - 1 icon, 16x16, 8 bits/pixel
CUSTOM 0x0001babc 0x0000057e LANG_ENGLISH SUBLANG_ENGLISH_US MS Windows icon resource - 1 icon, 16x16, 8 bits/pixel
CUSTOM 0x0001babc 0x0000057e LANG_ENGLISH SUBLANG_ENGLISH_US MS Windows icon resource - 1 icon, 16x16, 8 bits/pixel
RT_ICON 0x0001b57c 0x00000128 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x0001b57c 0x00000128 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x0001b57c 0x00000128 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_GROUP_ICON 0x0001b54c 0x00000030 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_VERSION 0x0001b260 0x000002ec LANG_CHINESE SUBLANG_CHINESE_TRADITIONAL data

Imports

Library MSVBVM60.DLL:
0x401000 None
0x401004 _CIcos
0x401008 _adj_fptan
0x40100c __vbaVarMove
0x401010 None
0x401014 None
0x401018 __vbaFreeVar
0x40101c __vbaStrVarMove
0x401020 __vbaFreeVarList
0x401024 _adj_fdiv_m64
0x401028 __vbaFreeObjList
0x40102c _adj_fprem1
0x401030 __vbaRecAnsiToUni
0x401034 None
0x401038 None
0x40103c __vbaSetSystemError
0x401040 __vbaRecDestruct
0x401048 None
0x40104c _adj_fdiv_m32
0x401050 None
0x401054 __vbaAryDestruct
0x401058 None
0x40105c __vbaStrBool
0x401060 None
0x401064 None
0x401068 __vbaObjSet
0x40106c __vbaOnError
0x401070 _adj_fdiv_m16i
0x401074 __vbaObjSetAddref
0x401078 _adj_fdivr_m16i
0x40107c None
0x401080 __vbaFpR8
0x401084 _CIsin
0x401088 None
0x40108c __vbaChkstk
0x401090 EVENT_SINK_AddRef
0x401098 __vbaStrCmp
0x40109c __vbaAryConstruct2
0x4010a0 __vbaVarTstEq
0x4010a4 __vbaI2I4
0x4010a8 __vbaObjVar
0x4010ac DllFunctionCall
0x4010b0 _adj_fpatan
0x4010b4 None
0x4010b8 __vbaRecUniToAnsi
0x4010bc EVENT_SINK_Release
0x4010c0 _CIsqrt
0x4010c8 __vbaExceptHandler
0x4010cc _adj_fprem
0x4010d0 _adj_fdivr_m64
0x4010d4 __vbaFPException
0x4010d8 __vbaStrVarVal
0x4010dc __vbaVarCat
0x4010e0 None
0x4010e4 _CIlog
0x4010e8 None
0x4010ec __vbaFileOpen
0x4010f0 None
0x4010f4 __vbaNew2
0x4010f8 None
0x4010fc __vbaInStr
0x401100 _adj_fdiv_m32i
0x401104 _adj_fdivr_m32i
0x401108 __vbaStrCopy
0x40110c __vbaFreeStrList
0x401110 _adj_fdivr_m32
0x401114 _adj_fdiv_r
0x401118 None
0x40111c __vbaVarTstNe
0x401120 None
0x401124 __vbaStrToAnsi
0x401128 __vbaVarDup
0x40112c None
0x401130 None
0x401134 __vbaFpI4
0x40113c _CIatan
0x401140 __vbaStrMove
0x401144 None
0x401148 _allmul
0x40114c __vbaLateIdSt
0x401150 _CItan
0x401154 None
0x401158 __vbaFPInt
0x40115c _CIexp
0x401160 __vbaFreeObj
0x401164 __vbaFreeStr

!This program cannot be run in DOS mode.
`.data
MSVBVM60.DLL
Selsk3
adgangsv
Selskabs
Selskabs
Timer1
KONDEM
acustom
fremtid
Gensta
BLINDSM
elefan
Nonpoint
FLINTPRO
Afkryd
FABRIKSFR
KULDKA
homone
electrom
NERVEKRIG
bygningat
tubulat
Garanter6
HAIRDRE
Scenefunk1
AUDIOME
Incens
DIALOGIS
Blodlege7
Catch5
Sudores
Bouncyne3
LIFTERABS
miscalled
hvislel
FJORDBYE
forest
fantast
sampling
Caputos
equalise
Presph
Bebyrde6
spottenes
COPLOTHN
stuccoyer
Agtpa1
Konfer
LYSKOPIT
Twatsopht8
UCuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuu
4xYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYY
'Ncccccccccccccccccccccccccccccccccccccccccccccccccccccccc
z___________________________________________________
IIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIII
'###########################################
K3333333333333333333333333333333333333333333333333333333333333333
bm}bE_a
-tRhW#
qxKlXt]
`q7~"fC
@.m'H"A
I_T.cq`
M3A\3A
The *
ss"63
_P1F.l
,5j!&Z
zvcQMw
'@Z&6A
X4:mDA
lq~Kwa
Sk@im>
D/TYzr[
uJql3`
M|nX J
SA'kW
/l!H!#
SF#ZgsWhUA
[pH3wE
PZ[Cr]
\-=o^
y)h]_TXZL
_gs2X"
"4Vp$^/
_Umv7oe
@c;U[_
zlPEJ v8
JZF:EU
n;OW+-
#_:U_
cu;h_e}5w
P6R_v3_m
z{]!^i[
>YK[]6
:G_d]K
~_goTy
q_>:FW#
kyBD:\W
(Qwrkz
d/M8/`
:WZxk)
DZO;z6b
TkXE!d
b6+nr!(
)WM7_g
'/A:UU
4GxW^ZM
U:OZGe
W;^[F;z
[]2M]V
@H;b_g
|:cF)_g
r!i:UW
hr!ic9
cyXa!F
_nAE_4f
w%s~hU
p;yU+/
!v;y[D
_mtW]V#
.~Vs!ie
Glp Tw-}
VB5!6&*
Outbo1
Selsk3
Selsk3
adgangsv
kannad
Rephotogr
uncomeli
Hensat7
Cafteat
Clodpole2
STUMMAR
Bezzled1
Blindeb7
Mismak9
scenistan
Difto5
vvninger
OVERHU
brainedde
Forivr1
APPROPRI
Parmigi8
Goosrad1
Elanhy
CODEBO
Alloge
Scenefunk1
C:\Program Files (x86)\Microsoft Visual Studio\VB98\VB6.OLB
Konfer
hvislel
FABRIKSFR
forest
DIALOGIS
Nonpoint
COPLOTHN
fremtid
equalise
Twatsopht8
tubulat
BLINDSM
Bebyrde6
sampling
KONDEM
Catch5
Timer1
homone
LIFTERABS
Gensta
Agtpa1
user32.dll
MonitorFromWindow
kernel32
lstrcmpiA
FindFirstChangeNotificationA
msimg32.dll
AlphaBlend
GetNumberFormatA
FileTimeToSystemTime
user32
CheckMenuRadioItem
clipper
nidorulent
VBA6.DLL
__vbaOnError
__vbaStrCmp
__vbaVarTstEq
__vbaFileOpen
__vbaFpR8
__vbaFpI4
__vbaStrCopy
__vbaAryDestruct
__vbaRecDestruct
__vbaInStr
__vbaLateIdSt
__vbaRecDestructAnsi
__vbaRecAnsiToUni
__vbaAryConstruct2
__vbaRecUniToAnsi
__vbaObjVar
__vbaObjSetAddref
__vbaVarDup
__vbaI2I4
__vbaSetSystemError
__vbaStrToAnsi
__vbaVarCat
__vbaFPInt
__vbaFreeObjList
__vbaFreeStrList
__vbaObjSet
__vbaStrBool
__vbaGenerateBoundsError
__vbaFreeVarList
__vbaFreeStr
__vbaStrVarVal
__vbaVarTstNe
__vbaFreeObj
__vbaHresultCheckObj
__vbaNew2
__vbaVarMove
__vbaStrVarMove
__vbaStrMove
__vbaFreeVar
user32
GetWindowTextA
GetWindowTextLengthA
VirtualProtect
WritePrivateProfileSectionA
WriteConsoleA
BIFURCATELY
AARSOPGRELSERS
Agnomination9
Departementsraad
Spaeing7
Drillerier
PHYSICIANESS
FORHANDLINGSKLIMAERNES
j$h HA
jXh0HA
jXh0HA
jPhLJA
jph0HA
jxh0HA
jph0HA
jXh0HA
j`h0HA
j`hLJA
jXh0HA
} jph0HA
} jdhLJA
MSVBVM60.DLL
_CIcos
_adj_fptan
__vbaVarMove
__vbaFreeVar
__vbaStrVarMove
__vbaFreeVarList
_adj_fdiv_m64
__vbaFreeObjList
_adj_fprem1
__vbaRecAnsiToUni
__vbaSetSystemError
__vbaRecDestruct
__vbaHresultCheckObj
_adj_fdiv_m32
__vbaAryDestruct
__vbaStrBool
__vbaObjSet
__vbaOnError
_adj_fdiv_m16i
__vbaObjSetAddref
_adj_fdivr_m16i
__vbaFpR8
_CIsin
__vbaChkstk
EVENT_SINK_AddRef
__vbaGenerateBoundsError
__vbaStrCmp
__vbaAryConstruct2
__vbaVarTstEq
__vbaI2I4
__vbaObjVar
DllFunctionCall
_adj_fpatan
__vbaRecUniToAnsi
EVENT_SINK_Release
_CIsqrt
EVENT_SINK_QueryInterface
__vbaExceptHandler
_adj_fprem
_adj_fdivr_m64
__vbaFPException
__vbaStrVarVal
__vbaVarCat
_CIlog
__vbaFileOpen
__vbaNew2
__vbaInStr
_adj_fdiv_m32i
_adj_fdivr_m32i
__vbaStrCopy
__vbaFreeStrList
_adj_fdivr_m32
_adj_fdiv_r
__vbaVarTstNe
__vbaStrToAnsi
__vbaVarDup
__vbaFpI4
__vbaRecDestructAnsi
_CIatan
__vbaStrMove
_allmul
__vbaLateIdSt
_CItan
__vbaFPInt
_CIexp
__vbaFreeObj
__vbaFreeStr
PROPAGINES
kodfoderets
Pohickory
celibate
Afroasiatiske
Grafiks
Options
Show Tips at Startup
That the
file was not found?
Create a text file named
using NotePad with 1 tip per line.
Then place it in the same directory as the application.
Knowily3
balkons
mysticisme
Chapah
Undersgelsens1
PROPOSITIONALLY
Bldestes7
Unimbibing
CHUVASH
KRFTSVULSTENS
BOMBNINGEN
Meloplasty
POSTSPINOUS
Udfrlig9
OVERWEARYING
gabardinens
INCAPABILITY
udskillelse
Resundsbaadenes8
WOWSERISH
Discordable4
String
Mauri6
Klumpedumperne9
verdensmagternes
losningens
uheldvarslende
CUSTOM
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
040404B0
Comments
Equinix
CompanyName
Equinix
FileDescription
Equinix
LegalCopyright
Equinix
LegalTrademarks
Equinix
ProductName
Equinix
FileVersion
ProductVersion
InternalName
Outbo1
OriginalFilename
Outbo1.exe
Antivirus Signature
Bkav W32.AIDetect.malware2
Lionic Clean
Elastic malicious (high confidence)
MicroWorld-eScan Clean
FireEye Clean
CAT-QuickHeal Clean
ALYac Clean
Cylance Unsafe
VIPRE Clean
Sangfor Trojan.Win32.Save.a
K7AntiVirus Clean
BitDefender Clean
K7GW Clean
Cybereason malicious.194f1a
Arcabit Clean
Baidu Clean
Cyren Clean
Symantec Clean
ESET-NOD32 Clean
APEX Malicious
Paloalto Clean
ClamAV Clean
Kaspersky Clean
Alibaba Clean
NANO-Antivirus Clean
ViRobot Clean
Rising Clean
Ad-Aware Clean
Emsisoft Clean
Comodo Clean
F-Secure Clean
DrWeb Clean
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition Clean
CMC Clean
Sophos Clean
Ikarus Clean
Jiangmin Clean
Webroot Clean
Avira Clean
MAX Clean
Antiy-AVL Clean
Kingsoft Clean
Gridinsoft Clean
Microsoft Trojan:Win32/Sabsik.FL.B!ml
SUPERAntiSpyware Clean
ZoneAlarm Clean
GData Clean
Cynet Malicious (score: 100)
AhnLab-V3 Win-Trojan/VBKrand.Gen
Acronis Clean
McAfee Clean
TACHYON Clean
VBA32 Clean
Malwarebytes Clean
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Tencent Clean
Yandex Clean
SentinelOne Static AI - Suspicious PE
MaxSecure Clean
Fortinet Clean
BitDefenderTheta Gen:NN.ZevbaCO.34170.hm0@aeMJNImj
Avast Clean
CrowdStrike Clean
No IRMA results available.