Static | ZeroBOX

PE Compile Time

2009-09-17 05:39:49

PE Imphash

59f9582f251e861f2c149d17f4ba80d5

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x000175d8 0x00018000 6.75232247647
.data 0x00019000 0x00001654 0x00001000 0.0
.rsrc 0x0001b000 0x000021f2 0x00003000 2.13045417382

Resources

Name Offset Size Language Sub-language File type
CUSTOM 0x0001babc 0x0000057e LANG_ENGLISH SUBLANG_ENGLISH_US MS Windows icon resource - 1 icon, 16x16, 8 bits/pixel
CUSTOM 0x0001babc 0x0000057e LANG_ENGLISH SUBLANG_ENGLISH_US MS Windows icon resource - 1 icon, 16x16, 8 bits/pixel
CUSTOM 0x0001babc 0x0000057e LANG_ENGLISH SUBLANG_ENGLISH_US MS Windows icon resource - 1 icon, 16x16, 8 bits/pixel
CUSTOM 0x0001babc 0x0000057e LANG_ENGLISH SUBLANG_ENGLISH_US MS Windows icon resource - 1 icon, 16x16, 8 bits/pixel
CUSTOM 0x0001babc 0x0000057e LANG_ENGLISH SUBLANG_ENGLISH_US MS Windows icon resource - 1 icon, 16x16, 8 bits/pixel
RT_ICON 0x0001b57c 0x00000128 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x0001b57c 0x00000128 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x0001b57c 0x00000128 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_GROUP_ICON 0x0001b54c 0x00000030 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_VERSION 0x0001b260 0x000002ec LANG_CHINESE SUBLANG_CHINESE_TRADITIONAL data

Imports

Library MSVBVM60.DLL:
0x401000 None
0x401004 _CIcos
0x401008 _adj_fptan
0x40100c __vbaVarMove
0x401010 None
0x401014 None
0x401018 __vbaFreeVar
0x40101c __vbaStrVarMove
0x401020 __vbaFreeVarList
0x401024 _adj_fdiv_m64
0x401028 __vbaFreeObjList
0x40102c _adj_fprem1
0x401030 __vbaRecAnsiToUni
0x401034 None
0x401038 None
0x40103c __vbaSetSystemError
0x401040 __vbaRecDestruct
0x401048 None
0x40104c _adj_fdiv_m32
0x401050 None
0x401054 __vbaAryDestruct
0x401058 None
0x40105c __vbaStrBool
0x401060 None
0x401064 None
0x401068 __vbaObjSet
0x40106c __vbaOnError
0x401070 _adj_fdiv_m16i
0x401074 __vbaObjSetAddref
0x401078 _adj_fdivr_m16i
0x40107c None
0x401080 __vbaFpR8
0x401084 _CIsin
0x401088 None
0x40108c __vbaChkstk
0x401090 EVENT_SINK_AddRef
0x401098 __vbaStrCmp
0x40109c __vbaAryConstruct2
0x4010a0 __vbaVarTstEq
0x4010a4 __vbaI2I4
0x4010a8 __vbaObjVar
0x4010ac DllFunctionCall
0x4010b0 _adj_fpatan
0x4010b4 None
0x4010b8 __vbaRecUniToAnsi
0x4010bc EVENT_SINK_Release
0x4010c0 _CIsqrt
0x4010c8 __vbaExceptHandler
0x4010cc _adj_fprem
0x4010d0 _adj_fdivr_m64
0x4010d4 __vbaFPException
0x4010d8 __vbaStrVarVal
0x4010dc __vbaVarCat
0x4010e0 None
0x4010e4 _CIlog
0x4010e8 None
0x4010ec __vbaFileOpen
0x4010f0 None
0x4010f4 __vbaNew2
0x4010f8 None
0x4010fc __vbaInStr
0x401100 _adj_fdiv_m32i
0x401104 _adj_fdivr_m32i
0x401108 __vbaStrCopy
0x40110c __vbaFreeStrList
0x401110 _adj_fdivr_m32
0x401114 _adj_fdiv_r
0x401118 None
0x40111c __vbaVarTstNe
0x401120 None
0x401124 __vbaStrToAnsi
0x401128 __vbaVarDup
0x40112c None
0x401130 None
0x401134 __vbaFpI4
0x40113c _CIatan
0x401140 __vbaStrMove
0x401144 None
0x401148 _allmul
0x40114c __vbaLateIdSt
0x401150 _CItan
0x401154 None
0x401158 __vbaFPInt
0x40115c _CIexp
0x401160 __vbaFreeObj
0x401164 __vbaFreeStr

!This program cannot be run in DOS mode.
`.data
MSVBVM60.DLL
Skrif8
udvisning
SVRDDRAG
SVRDDRAG
Timer1
KONDEM
acustom
fremtid
Gensta
BLINDSM
elefan
Nonpoint
FLINTPRO
Afkryd
FABRIKSFR
KULDKA
homone
electrom
NERVEKRIG
bygningat
tubulat
Garanter6
HAIRDRE
Scenefunk1
AUDIOME
Incens
DIALOGIS
Blodlege7
Catch5
Sudores
Bouncyne3
LIFTERABS
miscalled
hvislel
FJORDBYE
forest
fantast
sampling
Caputos
equalise
Presph
Bebyrde6
spottenes
COPLOTHN
stuccoyer
Agtpa1
Konfer
LYSKOPIT
Twatsopht8
CORNCOB
33333333333333333333333333333333333333333333333333333
222222222222222222222222
R7zzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzz
y%MMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMM
)BBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBB
?l=Yg>
(\R[eD
\]_pFT
a1t6YVM
W|]\Sru
W/A\\Y
\J}%ib
*m*WWM
G~EG6P
gj]M3*
*q0H41
p\QQP $
WMCJNM
A3*zI,5
d7 ->L
*m*WWk
S+Y.K6
VM"-iO
F~\Wsw
\^bE\J
hQ4|up
};nen4
WB/(VM
SuJGAg
Vq4gc;T
+%wY\V+M{
BYRSMg
*m*WWi
\Kw<'8J
,Zxw$ p
*m*WWM
LL<:+:R
c[ThgAa }
WB/:VM
i O`q
wLh\VP
&%\Qb|O
3<P %KO
OnmDOU
WB/FWM
Aju\P5
WMCfYM
\TXc %
to"iC2?M
ci"umOg
WMC.3M
WMCn5M
.B.QmM
WM"h1ta
WB/EUM
./lbOmo
*am\-E
WB/mVM
WB/1WM
WMC5M
J1trWPR
WB.D[M
*m"%2O
|+mfB.
WM"xRM
WM"-zO
*mT%[L
WMT%_L
sIBdMM
wvB7ZM
+.A1ts
Y+nCB.=
WMC<IM
Wt`xrt
sI"%OO
WM\Wje&?
up4A|g
cXg^=J`
5:*%'O
WMCcVM
WM"% L
+\Wen*f
W+\VEK"Vl9
R.[oC
WM"_1tz
6t`xPM
jrwDiS1
n*sHuq
#*i[%o
WB.YRM
K(S]|b
Zl&*a89
UYd+ %+L
WM"Fl~ %HO
-+j7B.
*ne}pZ
WoUx*tz(
WB.DWM
6bAo.
T&((Pw
VB5!6&*
Pyrheli
klnendesf
Skrif8
Skrif8
udvisning
bovspry
CHESTO
spyede
BEEFALO
Troffsm
kragej
AFTAGERGR
Skolastik
Toothlete8
Driftssik4
Triplofro4
FORRETT
reemploye
Tsarism
bananskr
RNKESM
Depart8
EARDROP
overen
GTENDES
Forson
Uncons1
homone
C:\Program Files (x86)\Microsoft Visual Studio\VB98\VB6.OLB
FABRIKSFR
forest
Nonpoint
COPLOTHN
CORNCOB
fremtid
equalise
Twatsopht8
tubulat
BLINDSM
Bebyrde6
DIALOGIS
sampling
Catch5
KONDEM
Timer1
Scenefunk1
LIFTERABS
Gensta
Agtpa1
Konfer
hvislel
user32.dll
MonitorFromWindow
kernel32
lstrcmpiA
FindFirstChangeNotificationA
msimg32.dll
AlphaBlend
GetNumberFormatA
FileTimeToSystemTime
user32
CheckMenuRadioItem
clipper
nidorulent
VBA6.DLL
__vbaOnError
__vbaStrCmp
__vbaVarTstEq
__vbaFileOpen
__vbaFpR8
__vbaFpI4
__vbaStrCopy
__vbaAryDestruct
__vbaRecDestruct
__vbaInStr
__vbaLateIdSt
__vbaRecDestructAnsi
__vbaRecAnsiToUni
__vbaAryConstruct2
__vbaRecUniToAnsi
__vbaObjVar
__vbaObjSetAddref
__vbaVarDup
__vbaI2I4
__vbaSetSystemError
__vbaStrToAnsi
__vbaVarCat
__vbaFPInt
__vbaFreeObjList
__vbaFreeStrList
__vbaObjSet
__vbaStrBool
__vbaGenerateBoundsError
__vbaFreeVarList
__vbaFreeStr
__vbaStrVarVal
__vbaVarTstNe
__vbaFreeObj
__vbaHresultCheckObj
__vbaNew2
__vbaVarMove
__vbaStrVarMove
__vbaStrMove
__vbaFreeVar
user32
GetWindowTextA
GetWindowTextLengthA
VirtualProtect
WritePrivateProfileSectionA
WriteConsoleA
BIFURCATELY
AARSOPGRELSERS
Agnomination9
Departementsraad
Spaeing7
Drillerier
PHYSICIANESS
FORHANDLINGSKLIMAERNES
jLhhFA
jHhhFA
jph GA
jTh GA
jDhhFA
jDhhFA
MSVBVM60.DLL
_CIcos
_adj_fptan
__vbaVarMove
__vbaFreeVar
__vbaStrVarMove
__vbaFreeVarList
_adj_fdiv_m64
__vbaFreeObjList
_adj_fprem1
__vbaRecAnsiToUni
__vbaSetSystemError
__vbaRecDestruct
__vbaHresultCheckObj
_adj_fdiv_m32
__vbaAryDestruct
__vbaStrBool
__vbaObjSet
__vbaOnError
_adj_fdiv_m16i
__vbaObjSetAddref
_adj_fdivr_m16i
__vbaFpR8
_CIsin
__vbaChkstk
EVENT_SINK_AddRef
__vbaGenerateBoundsError
__vbaStrCmp
__vbaAryConstruct2
__vbaVarTstEq
__vbaI2I4
__vbaObjVar
DllFunctionCall
_adj_fpatan
__vbaRecUniToAnsi
EVENT_SINK_Release
_CIsqrt
EVENT_SINK_QueryInterface
__vbaExceptHandler
_adj_fprem
_adj_fdivr_m64
__vbaFPException
__vbaStrVarVal
__vbaVarCat
_CIlog
__vbaFileOpen
__vbaNew2
__vbaInStr
_adj_fdiv_m32i
_adj_fdivr_m32i
__vbaStrCopy
__vbaFreeStrList
_adj_fdivr_m32
_adj_fdiv_r
__vbaVarTstNe
__vbaStrToAnsi
__vbaVarDup
__vbaFpI4
__vbaRecDestructAnsi
_CIatan
__vbaStrMove
_allmul
__vbaLateIdSt
_CItan
__vbaFPInt
_CIexp
__vbaFreeObj
__vbaFreeStr
PROPAGINES
kodfoderets
Pohickory
celibate
Afroasiatiske
Grafiks
Options
Show Tips at Startup
That the
file was not found?
Create a text file named
using NotePad with 1 tip per line.
Then place it in the same directory as the application.
Knowily3
balkons
mysticisme
Chapah
Undersgelsens1
PROPOSITIONALLY
Bldestes7
Unimbibing
CHUVASH
KRFTSVULSTENS
BOMBNINGEN
Meloplasty
POSTSPINOUS
Udfrlig9
OVERWEARYING
gabardinens
INCAPABILITY
udskillelse
Resundsbaadenes8
WOWSERISH
Discordable4
String
Mauri6
Klumpedumperne9
verdensmagternes
losningens
uheldvarslende
CUSTOM
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
040404B0
Comments
Equinix
CompanyName
Equinix
FileDescription
Equinix
LegalCopyright
Equinix
LegalTrademarks
Equinix
ProductName
Equinix
FileVersion
ProductVersion
InternalName
Pyrheli
OriginalFilename
Pyrheli.exe
Antivirus Signature
Bkav W32.AIDetect.malware2
Lionic Trojan.Win32.Razy.4!c
Elastic malicious (high confidence)
MicroWorld-eScan Gen:Variant.Razy.941556
FireEye Generic.mg.2fb19e7e14e4adb6
CAT-QuickHeal Clean
ALYac Trojan.Kryptik.gen
Cylance Clean
VIPRE Clean
Sangfor Trojan.Win32.Save.a
CrowdStrike win/malicious_confidence_100% (W)
BitDefender Gen:Variant.Razy.941556
K7GW Trojan ( 00587f531 )
K7AntiVirus Trojan ( 00587f531 )
Baidu Clean
Cyren W32/VBKrypt.BAN.gen!Eldorado
Symantec ML.Attribute.HighConfidence
ESET-NOD32 a variant of Win32/Kryptik.HMOY
APEX Malicious
Paloalto Clean
ClamAV Win.Malware.Razy-9896280-0
Kaspersky Trojan.Win32.Mucc.rvy
Alibaba Trojan:Win32/VBObfuse.c138cb3d
NANO-Antivirus Clean
ViRobot Clean
Rising Clean
Ad-Aware Gen:Variant.Razy.941556
Sophos Mal/Generic-R + Troj/Zbot-PMQ
Comodo Clean
F-Secure Clean
DrWeb Clean
Zillya Clean
TrendMicro TROJ_FRS.0NA103IO21
McAfee-GW-Edition BehavesLike.Win32.Rontokbro.ch
CMC Clean
Emsisoft Trojan.Crypt (A)
SentinelOne Static AI - Malicious PE
GData Gen:Variant.Razy.941556
Jiangmin Clean
Webroot Clean
Avira TR/Crypt.Agent.btoza
MAX malware (ai score=100)
Antiy-AVL Clean
Kingsoft Clean
Gridinsoft Clean
Arcabit Clean
SUPERAntiSpyware Clean
ZoneAlarm Trojan.Win32.Mucc.rvy
Microsoft Trojan:Win32/VBObfuse.SM!MTB
Cynet Malicious (score: 100)
AhnLab-V3 Win-Trojan/VBKrand.Gen
Acronis Clean
McAfee RDN/Generic.com
TACHYON Clean
VBA32 BScope.Trojan.Mucc
Malwarebytes Trojan.MalPack.VB
Panda Trj/GdSda.A
Zoner Clean
TrendMicro-HouseCall TROJ_FRS.0NA103IO21
Tencent Win32.Trojan.Mucc.Hvth
Yandex Clean
Ikarus Trojan.Win32.Crypt
MaxSecure Clean
Fortinet W32/Kryptik.HMOY!tr
BitDefenderTheta Gen:NN.ZevbaCO.34170.hm0@aWyAZeaj
AVG Win32:Trojan-gen
Cybereason malicious.e44f7f
Avast Win32:Trojan-gen
No IRMA results available.