Static | ZeroBOX

PE Compile Time

2012-07-26 23:02:35

PE Imphash

6fc1a2d244c958299fb32338306cc540

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x0000f224 0x00010000 6.72086865093
.data 0x00011000 0x000011b8 0x00001000 0.0
.rsrc 0x00013000 0x000019ea 0x00002000 3.84867298316

Resources

Name Offset Size Language Sub-language File type
CUSTOM 0x000139f8 0x0000013e LANG_ENGLISH SUBLANG_ENGLISH_US MS Windows icon resource - 1 icon, 16x16, 16 colors
CUSTOM 0x000139f8 0x0000013e LANG_ENGLISH SUBLANG_ENGLISH_US MS Windows icon resource - 1 icon, 16x16, 16 colors
CUSTOM 0x000139f8 0x0000013e LANG_ENGLISH SUBLANG_ENGLISH_US MS Windows icon resource - 1 icon, 16x16, 16 colors
RT_ICON 0x000134b8 0x00000128 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x000134b8 0x00000128 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x000134b8 0x00000128 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_GROUP_ICON 0x00013488 0x00000030 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_VERSION 0x00013200 0x00000288 LANG_NORWEGIAN SUBLANG_NORWEGIAN_BOKMAL data

Imports

Library MSVBVM60.DLL:
0x401000 None
0x401004 __vbaStrI2
0x401008 _CIcos
0x40100c _adj_fptan
0x401010 __vbaFreeVar
0x401014 __vbaLineInputStr
0x401018 __vbaFreeVarList
0x40101c _adj_fdiv_m64
0x401020 __vbaFreeObjList
0x401024 _adj_fprem1
0x401028 __vbaStrCat
0x401030 _adj_fdiv_m32
0x401034 None
0x401038 None
0x40103c __vbaObjSet
0x401040 __vbaOnError
0x401044 _adj_fdiv_m16i
0x401048 __vbaObjSetAddref
0x40104c _adj_fdivr_m16i
0x401050 __vbaFpR8
0x401054 _CIsin
0x401058 __vbaChkstk
0x40105c __vbaFileClose
0x401060 EVENT_SINK_AddRef
0x401064 __vbaStrCmp
0x401068 __vbaObjVar
0x40106c __vbaI2I4
0x401070 DllFunctionCall
0x401074 _adj_fpatan
0x401078 EVENT_SINK_Release
0x40107c _CIsqrt
0x401084 __vbaExceptHandler
0x401088 _adj_fprem
0x40108c _adj_fdivr_m64
0x401090 __vbaFPException
0x401094 __vbaStrVarVal
0x401098 None
0x40109c _CIlog
0x4010a0 __vbaFileOpen
0x4010a4 __vbaNew2
0x4010a8 None
0x4010ac __vbaInStr
0x4010b0 None
0x4010b4 _adj_fdiv_m32i
0x4010b8 _adj_fdivr_m32i
0x4010bc __vbaI4Str
0x4010c0 __vbaFreeStrList
0x4010c4 _adj_fdivr_m32
0x4010c8 _adj_fdiv_r
0x4010cc None
0x4010d0 None
0x4010d4 __vbaLateMemCall
0x4010d8 _CIatan
0x4010dc __vbaStrMove
0x4010e0 __vbaR8IntI4
0x4010e4 _allmul
0x4010e8 _CItan
0x4010ec _CIexp
0x4010f0 __vbaFreeStr
0x4010f4 __vbaFreeObj

!This program cannot be run in DOS mode.
`.data
MSVBVM60.DLL
Marernesillu9
BADGERSD
Papisterneh9
Papisterneh9
chkLoadTipsAtStartup
&Show Tips at Startup
cmdNextTip
&Next Tip
Picture1
Label1
Did you know...
lblTipText
Label3
Dobbeltladel
Substagestrafi7
waitschimeda
omdigtning
BUSKVKSTCARDION
FAGFORENINGSF
NVFORTOLKERE
Tagassuid
Paleophytolog5
DRILBORROGUES
Bededesbugey9
Dolmanensunli9
Citronsommerfu
Image1
v)Qgny
{fj<{!
Wg`rj2
%psg`rY2
>Rj9yc.N
jpM``J72
`ybJo1
hf{,-b
k3Z``J
^g`r=2
@Ga5N-
Tv[`'.
0RKgpBN
%coI2X
%4bRB2
2j=oNuv
C4<7o1
@ZxNv`
(T8\tN
Q;$Y^
0o2^ih
eVj1dT
1Nq Hf
fS>:a`Bw2
1FY,`P
Y,brp1
(O5;9O5;
HAMN6:h
jVQAj&
ghbrl1
Ro1VVn
5\@H+j1
ej8h'3%g
j8QQ)(8
%4bZK2
V0Nj>PH
?zlVj1K
DL(QLc
=laJ<2
13DI(b
n9.`Rn2
96`Jq1
KVj0xz
EeDA )
gVj0cV
DN$h6!
B[aVQ8
~\N6CX
(c`RU2
Hj9|9X
`\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\<
r;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;
S333333333333333333333333333333333333333333f
/o=#G(((((((((((((((((((((((((((((((((((((((((((
nnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnn
xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxf
2HF?,ssssssssssssssssssssssssssssssssssssssssssssss
88888888888888888888888888888888888888881
IOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOO
-W`u-----------------------------------------Of
72////////////////////////////////////////////
kkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkk
A$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$<
C``````````````````````````````````````````
KC@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@1
ooooooooooooooooooooooooooooooooooooooooooo
f/vjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjf
WNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNN
/TTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTT
.EEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEf
:::::::::::::::::::::::::::::::::::::::::::
z>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>
xG(((((((((((((((((((((((((((((((((((((((((
Duuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuu
+GJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJR
!IIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIII
2)))))))))))))))))))))))))))))))))))))))))))))))
?tttttttttttttttttttttttttttttttttttttttttttth\
:-------------------------------------------
niiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiZ
|uuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuu
7/x[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[
qIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIII
W5555555555555555555555555555555555555555555555f
-EEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEE1
z//////////////////////////////////////////////
L7OOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOO
#DDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDD]f
~:::::::::::::::::::::::::::::::::::::::::::::
VB5!6&*
Hankelses
Marernesillu9
Marernesillu9
Marernesillu9
BADGERSD
Varefordelingen
C:\Program Files (x86)\Microsoft Visual Studio\VB98\VB6.OLB
Picture1
omdigtning
Substagestrafi7
DRILBORROGUES
Image1
Dolmanensunli9
lblTipText
Label1
Label3
cmdNextTip
Tagassuid
FAGFORENINGSF
chkLoadTipsAtStartup
user32
SetSysColors
SetForegroundWindow
kernel32
GetDriveTypeA
WSOCK32
WSACleanup
LoadTips
DisplayCurrentTip
HAMMERINGLY
VBA6.DLL
__vbaOnError
__vbaInStr
__vbaFpR8
__vbaStrVarVal
__vbaStrCat
__vbaI2I4
__vbaI4Str
__vbaFreeObj
__vbaObjSetAddref
__vbaFreeObjList
__vbaFreeStrList
__vbaObjSet
__vbaStrI2
__vbaFileClose
__vbaFreeVarList
__vbaLineInputStr
__vbaFileOpen
__vbaFreeStr
__vbaStrMove
__vbaStrCmp
__vbaObjVar
__vbaLateMemCall
__vbaFreeVar
__vbaHresultCheckObj
__vbaNew2
__vbaR8IntI4
Varefordelingen
sukkervares
sukkervares
Genkbsvrdiernes
PEDANTOCRATIC
Mustnt
betragteligste
MSVBVM60.DLL
__vbaStrI2
_CIcos
_adj_fptan
__vbaFreeVar
__vbaLineInputStr
__vbaFreeVarList
_adj_fdiv_m64
__vbaFreeObjList
_adj_fprem1
__vbaStrCat
__vbaHresultCheckObj
_adj_fdiv_m32
__vbaObjSet
__vbaOnError
_adj_fdiv_m16i
__vbaObjSetAddref
_adj_fdivr_m16i
__vbaFpR8
_CIsin
__vbaChkstk
__vbaFileClose
EVENT_SINK_AddRef
__vbaStrCmp
__vbaObjVar
__vbaI2I4
DllFunctionCall
_adj_fpatan
EVENT_SINK_Release
_CIsqrt
EVENT_SINK_QueryInterface
__vbaExceptHandler
_adj_fprem
_adj_fdivr_m64
__vbaFPException
__vbaStrVarVal
_CIlog
__vbaFileOpen
__vbaNew2
__vbaInStr
_adj_fdiv_m32i
_adj_fdivr_m32i
__vbaI4Str
__vbaFreeStrList
_adj_fdivr_m32
_adj_fdiv_r
__vbaLateMemCall
_CIatan
__vbaStrMove
__vbaR8IntI4
_allmul
_CItan
_CIexp
__vbaFreeStr
__vbaFreeObj
wwwwww
wwwwww
555333335555
553333
!!;>;;
##='&77*&###
))& 7(,,*
##* :,(( %//8----)
).,>(:%
666666
XF-\N,
m1|h1}i0{g1zf2yd2yd2zd2ye2yd2ze2zf2xjK
Pdss]&
l4zf1yc1xb2xa1xa2w`2x`2w`2ya2zd2zc
XS;v[&zc3xa2v_1u]1u\1u\1u\2u]1v^2w_2
S[_gO$uY*w]3v\3uY2tX2rW2sY2tZ2u[2ia3]v
[XNaF%gJ'iN,nP1qS1rU1rW2sW2CTat
iJ.pQ2oP2pR2rT1O]e{
bQHkD'oM4jH*pP2pR2Zfj\x
^bfsP&mQ3fL6cC,
q]vZIfC+~aMeE+oO2~h.pe?fg\bjo
|i2{f0~^!ndM
}i1zg3y`,kdR}
^^bhX8D
WXKSeZ`i^K_UO
}i2zg3{`*keR
h_bF~k1
|h2zg2{b,mbJ
kmloQ+P}ojQ8G
yVi[NtkoB*SnbM{ouD$~k2{h1ye2x_0l`IrY5sT0wH%oM/vA#qD)r@&lJ2sD(uD%mR4~j2}i2zf1xb2y],tZ1rW2pV4pR2mR5nP3mO4nN1nR4nS4qR1}j2
l2{g2yd1va5u\2tY1sW2qS2pS2pQ2oP2oP2pR2qS2rU2
TIPOFDAY.TXT
DisplayCurrentTip
Options
Runitehydrophil
Show Tips at Startup
That the
file was not found?
Create a text file named
using NotePad with 1 tip per line.
Then place it in the same directory as the application.
BIOGENSOCTAETER
BALSAMICAL
Vejrtraekning
Ingenirstuderendes8
CUSTOM
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
041404B0
Comments
Moderbirds
CompanyName
Club AsuS
FileDescription
Club, Inc.
ProductName
Club.com
FileVersion
ProductVersion
InternalName
Hankelses
OriginalFilename
Hankelses.exe
Antivirus Signature
Bkav W32.AIDetect.malware2
Lionic Clean
Elastic malicious (high confidence)
MicroWorld-eScan Clean
FireEye Generic.mg.78e101f15647e6c2
CAT-QuickHeal Clean
McAfee Clean
Cylance Unsafe
VIPRE Clean
Sangfor Clean
CrowdStrike Clean
BitDefender Clean
K7GW Clean
K7AntiVirus Clean
Baidu Clean
Cyren Clean
Symantec Clean
ESET-NOD32 a variant of Win32/GenKryptik.FKZN
APEX Malicious
Paloalto Clean
ClamAV Clean
Kaspersky UDS:DangerousObject.Multi.Generic
Alibaba Clean
NANO-Antivirus Clean
ViRobot Clean
Tencent Clean
Ad-Aware Clean
Sophos Clean
Comodo Clean
F-Secure Clean
DrWeb Clean
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition Clean
CMC Clean
Emsisoft Clean
Ikarus Clean
GData Clean
Jiangmin Clean
eGambit Unsafe.AI_Score_99%
Avira Clean
MAX Clean
Antiy-AVL Clean
Kingsoft Clean
Gridinsoft Clean
Arcabit Clean
SUPERAntiSpyware Clean
ZoneAlarm Clean
Microsoft Trojan:Win32/Sabsik.FL.B!ml
Cynet Clean
AhnLab-V3 Clean
Acronis Clean
BitDefenderTheta Gen:NN.ZevbaCO.34170.fm0@aSGQ5XlO
ALYac Clean
TACHYON Clean
VBA32 Clean
Malwarebytes Clean
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Rising Clean
Yandex Clean
SentinelOne Static AI - Suspicious PE
MaxSecure Trojan.Malware.300983.susgen
Fortinet Clean
Webroot Clean
Avast Clean
No IRMA results available.