Static | ZeroBOX

PE Compile Time

2011-05-13 10:23:55

PE Imphash

a587116cc4241097b364fa915d1c4c46

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x00015084 0x00016000 6.67487884779
.data 0x00017000 0x00001624 0x00001000 0.0
.rsrc 0x00019000 0x00002292 0x00003000 2.17523765352

Resources

Name Offset Size Language Sub-language File type
CUSTOM 0x00019b5c 0x0000057e LANG_ENGLISH SUBLANG_ENGLISH_US MS Windows icon resource - 1 icon, 16x16, 8 bits/pixel
CUSTOM 0x00019b5c 0x0000057e LANG_ENGLISH SUBLANG_ENGLISH_US MS Windows icon resource - 1 icon, 16x16, 8 bits/pixel
CUSTOM 0x00019b5c 0x0000057e LANG_ENGLISH SUBLANG_ENGLISH_US MS Windows icon resource - 1 icon, 16x16, 8 bits/pixel
CUSTOM 0x00019b5c 0x0000057e LANG_ENGLISH SUBLANG_ENGLISH_US MS Windows icon resource - 1 icon, 16x16, 8 bits/pixel
CUSTOM 0x00019b5c 0x0000057e LANG_ENGLISH SUBLANG_ENGLISH_US MS Windows icon resource - 1 icon, 16x16, 8 bits/pixel
RT_ICON 0x0001961c 0x00000128 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x0001961c 0x00000128 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x0001961c 0x00000128 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_GROUP_ICON 0x000195ec 0x00000030 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_VERSION 0x00019260 0x0000038c LANG_ENGLISH SUBLANG_ENGLISH_US PGP symmetric key encrypted data - Plaintext or unencrypted data

Imports

Library MSVBVM60.DLL:
0x401000 None
0x401004 _CIcos
0x401008 _adj_fptan
0x40100c __vbaVarMove
0x401010 None
0x401014 __vbaFreeVar
0x401018 __vbaStrVarMove
0x40101c __vbaFreeVarList
0x401020 _adj_fdiv_m64
0x401024 __vbaFreeObjList
0x401028 _adj_fprem1
0x40102c __vbaSetSystemError
0x401034 _adj_fdiv_m32
0x401038 __vbaAryVar
0x40103c None
0x401040 __vbaAryDestruct
0x401044 None
0x401048 __vbaObjSet
0x40104c None
0x401050 __vbaOnError
0x401054 _adj_fdiv_m16i
0x401058 _adj_fdivr_m16i
0x40105c None
0x401060 __vbaFpR8
0x401064 None
0x401068 _CIsin
0x40106c __vbaChkstk
0x401070 EVENT_SINK_AddRef
0x401074 __vbaStrCmp
0x401078 __vbaI2I4
0x40107c DllFunctionCall
0x401080 _adj_fpatan
0x401084 EVENT_SINK_Release
0x401088 _CIsqrt
0x401090 __vbaExceptHandler
0x401094 None
0x401098 _adj_fprem
0x40109c _adj_fdivr_m64
0x4010a0 None
0x4010a4 __vbaFPException
0x4010a8 None
0x4010ac None
0x4010b0 _CIlog
0x4010b4 __vbaNew2
0x4010b8 _adj_fdiv_m32i
0x4010bc _adj_fdivr_m32i
0x4010c0 None
0x4010c4 __vbaStrCopy
0x4010c8 __vbaDerefAry1
0x4010cc _adj_fdivr_m32
0x4010d0 _adj_fdiv_r
0x4010d4 None
0x4010d8 __vbaVarTstNe
0x4010dc __vbaStrToAnsi
0x4010e0 __vbaVarDup
0x4010e4 None
0x4010e8 None
0x4010ec _CIatan
0x4010f0 __vbaStrMove
0x4010f4 __vbaAryCopy
0x4010f8 None
0x4010fc _allmul
0x401100 _CItan
0x401104 None
0x401108 _CIexp
0x40110c __vbaFreeObj
0x401110 None
0x401114 __vbaFreeStr

!This program cannot be run in DOS mode.
`.data
MSVBVM60.DLL
Jaund7
bubalises
bubalises
Timer1
KONDEM
olamuned
biograf
fremtid
BLACKMAI
Gensta
MECONI
BLINDSM
Sigfrie
Nonpoint
fuldefil
Blodri2
FABRIKSFR
tribunar
homone
PALONTOL
OPFANGER
tubulat
Urneha9
Scenefunk1
hvsedesr
Elfredekr9
DIALOGIS
Catch5
TRIMETERS
BLINDTRY
REAUMU
LIFTERABS
hvislel
forest
sampling
Smert4
Unsound
equalise
Lumines
Bebyrde6
COPLOTHN
biofysisk
Glleb5
Agtpa1
Konfer
Twatsopht8
Quippishn6
Twatsopht18
linalol
jZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZ
EEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEE
:VVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVV
.@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@
9;V$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$
...................................................
8NNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNN
yyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyy
p88888888888888888888888888888888888888888888888888888888
TW''''''''''''''''''''''''''''''''''''''''''
B(QUR/
ojS_G?
2dr;pR
]it^x>
Bp8J"
HWgXwm
%i7ed
6>dK5@F
}\1+eh
c-smY?+
j_K-YF
F*1xe
>[QK<tF
b}REt>
2m{r_
fas,aE
l$tb|r
F*0zX
kZ*yfs
>}%|Rr
Oj;.^:
dx.>:S
bJ)vIo
S "wEG
+is8AL(
h#(w#G
XayM.Y?
zt53()
kTup_`>
v|e8d9
o.!k:>
;]wwb
\'Jeoo(a
F*,dggV
Me<B@[s
[>OIa<
!<"]dj
X%mB=8
# &1;|
r,1r)Y"
\qs(4
{- T5IO
qVr2=R
"R-aP}
6U68s/
T3`w"3
FU1rois
hs:.of
WD<qUq
$#<Fw^oP 5
A+"lr7
&3;CF
muV[{F,
3Aq:D*
s"ju8p
bV;\Js:
x&9kiJ
vA"G8G
!S5ZCS5Z+S-Z
'=K"3
fr!,T3
VB5!6&*
Tilkrsels
Jaund7
Jaund7
nonodorif
byggemyn
Toolma2
SKRDDE
swagger
Gallei
Jagthun6
Etruscol
BERMANVAL
Enheds4
Paata1
Opmrkso8
Conso5
erkende
Paddeha
bundtning
TREFDDERS
parvitud
C:\Program Files (x86)\Microsoft Visual Studio\VB98\VB6.OLB
sampling
Catch5
KONDEM
Timer1
Scenefunk1
homone
LIFTERABS
Gensta
Agtpa1
Konfer
hvislel
FABRIKSFR
forest
Twatsopht18
DIALOGIS
Nonpoint
COPLOTHN
fremtid
equalise
Twatsopht8
tubulat
BLINDSM
Bebyrde6
user32
RedrawWindow
shlwapi.dll
PathIsSystemFolderA
advapi32.dll
CryptDeriveKey
IntersectClipRect
Vadehavenes
Simous
VBA6.DLL
__vbaFpR8
__vbaOnError
__vbaFreeObjList
__vbaStrVarMove
__vbaVarDup
__vbaStrCopy
__vbaFreeVar
__vbaAryDestruct
__vbaI2I4
__vbaFreeStr
__vbaSetSystemError
__vbaStrToAnsi
__vbaDerefAry1
__vbaStrCmp
__vbaAryVar
__vbaAryCopy
__vbaObjSet
__vbaVarMove
__vbaFreeObj
__vbaHresultCheckObj
__vbaNew2
__vbaStrMove
__vbaFreeVarList
__vbaVarTstNe
user32
GetWindowTextA
GetWindowTextLengthA
kernel32
VirtualProtect
WritePrivateProfileSectionA
WriteConsoleA
Actinography7
Benjaminite
Isoxazole
sklvene
Dossel6
vektorfunktioners
MSVBVM60.DLL
_CIcos
_adj_fptan
__vbaVarMove
__vbaFreeVar
__vbaStrVarMove
__vbaFreeVarList
_adj_fdiv_m64
__vbaFreeObjList
_adj_fprem1
__vbaSetSystemError
__vbaHresultCheckObj
_adj_fdiv_m32
__vbaAryVar
__vbaAryDestruct
__vbaObjSet
__vbaOnError
_adj_fdiv_m16i
_adj_fdivr_m16i
__vbaFpR8
_CIsin
__vbaChkstk
EVENT_SINK_AddRef
__vbaStrCmp
__vbaI2I4
DllFunctionCall
_adj_fpatan
EVENT_SINK_Release
_CIsqrt
EVENT_SINK_QueryInterface
__vbaExceptHandler
_adj_fprem
_adj_fdivr_m64
__vbaFPException
_CIlog
__vbaNew2
_adj_fdiv_m32i
_adj_fdivr_m32i
__vbaStrCopy
__vbaDerefAry1
_adj_fdivr_m32
_adj_fdiv_r
__vbaVarTstNe
__vbaStrToAnsi
__vbaVarDup
_CIatan
__vbaStrMove
__vbaAryCopy
_allmul
_CItan
_CIexp
__vbaFreeObj
__vbaFreeStr
Unmundanely
piscatology
Presubmission5
Proprietrernes3
REJEOPARDIZING
Chiropody
FLSKESIDE
terrorbalancers
Abstineredes
Unhailable7
SILDESTIMERNES
Milieuministeriums8
sleetproof
20:20:20
CUSTOM
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
040904B0
Comments
Registry First Aid 9
CompanyName
Registry First Aid 9
FileDescription
Registry First Aid 9
LegalCopyright
Registry First Aid 9
LegalTrademarks
Registry First Aid 9
ProductName
Registry First Aid 9
FileVersion
ProductVersion
InternalName
OriginalFilename
Fors4.exe
Antivirus Signature
Bkav W32.AIDetect.malware2
Lionic Trojan.Win32.Razy.4!c
Elastic malicious (high confidence)
MicroWorld-eScan Gen:Variant.Razy.947945
FireEye Generic.mg.01a73a74c0f01ff7
CAT-QuickHeal Clean
McAfee Artemis!01A73A74C0F0
Cylance Clean
VIPRE Clean
Sangfor Trojan.Win32.Save.a
K7AntiVirus Clean
BitDefender Gen:Variant.Razy.947945
K7GW Clean
CrowdStrike win/malicious_confidence_100% (W)
Arcabit Clean
BitDefenderTheta Gen:NN.ZevbaF.34170.gm0@amMv0Lgi
Cyren Clean
Symantec ML.Attribute.HighConfidence
ESET-NOD32 a variant of Win32/GenKryptik.FLGD
Baidu Clean
APEX Malicious
Paloalto generic.ml
ClamAV Clean
Kaspersky UDS:Trojan.Win32.Mucc
Alibaba Clean
NANO-Antivirus Clean
ViRobot Clean
Tencent Win32.Trojan.Razy.Eep
Ad-Aware Gen:Variant.Razy.947945
Emsisoft Gen:Variant.Razy.947945 (B)
Comodo Clean
F-Secure Clean
DrWeb Clean
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition BehavesLike.Win32.Trojan.ch
CMC Clean
Sophos Mal/Generic-S
SentinelOne Static AI - Malicious PE
Jiangmin Clean
MaxSecure Clean
Avira Clean
MAX malware (ai score=80)
Antiy-AVL Clean
Kingsoft Win32.Troj.Generic_a.a.(kcloud)
Gridinsoft Clean
Microsoft Trojan:Win32/Sabsik.FL.B!ml
SUPERAntiSpyware Clean
ZoneAlarm Clean
GData Gen:Variant.Razy.947945
Cynet Malicious (score: 100)
AhnLab-V3 Clean
Acronis Clean
VBA32 BScope.Trojan.Mucc
ALYac Gen:Variant.Razy.947945
TACHYON Clean
Malwarebytes Clean
Panda Trj/GdSda.A
Zoner Clean
TrendMicro-HouseCall TROJ_GEN.R002H0DIT21
Rising Downloader.Guloader!1.D9C4 (CLASSIC)
Yandex Clean
Ikarus Win32.Outbreak
eGambit Unsafe.AI_Score_100%
Fortinet W32/GenKryptik.FLGD!tr
Webroot W32.Malware.Gen
AVG FileRepMalware
Cybereason malicious.5e0a6c
Avast FileRepMalware
No IRMA results available.