Static | ZeroBOX

PE Compile Time

2013-08-27 11:27:14

PE Imphash

a587116cc4241097b364fa915d1c4c46

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x00014f84 0x00015000 6.82837406336
.data 0x00016000 0x00001624 0x00001000 0.0
.rsrc 0x00018000 0x00002292 0x00003000 2.17383116561

Resources

Name Offset Size Language Sub-language File type
CUSTOM 0x00018b5c 0x0000057e LANG_ENGLISH SUBLANG_ENGLISH_US MS Windows icon resource - 1 icon, 16x16, 8 bits/pixel
CUSTOM 0x00018b5c 0x0000057e LANG_ENGLISH SUBLANG_ENGLISH_US MS Windows icon resource - 1 icon, 16x16, 8 bits/pixel
CUSTOM 0x00018b5c 0x0000057e LANG_ENGLISH SUBLANG_ENGLISH_US MS Windows icon resource - 1 icon, 16x16, 8 bits/pixel
CUSTOM 0x00018b5c 0x0000057e LANG_ENGLISH SUBLANG_ENGLISH_US MS Windows icon resource - 1 icon, 16x16, 8 bits/pixel
CUSTOM 0x00018b5c 0x0000057e LANG_ENGLISH SUBLANG_ENGLISH_US MS Windows icon resource - 1 icon, 16x16, 8 bits/pixel
RT_ICON 0x0001861c 0x00000128 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x0001861c 0x00000128 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x0001861c 0x00000128 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_GROUP_ICON 0x000185ec 0x00000030 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_VERSION 0x00018260 0x0000038c LANG_ENGLISH SUBLANG_ENGLISH_US PGP symmetric key encrypted data - Plaintext or unencrypted data

Imports

Library MSVBVM60.DLL:
0x401000 None
0x401004 _CIcos
0x401008 _adj_fptan
0x40100c __vbaVarMove
0x401010 None
0x401014 __vbaFreeVar
0x401018 __vbaStrVarMove
0x40101c __vbaFreeVarList
0x401020 _adj_fdiv_m64
0x401024 __vbaFreeObjList
0x401028 _adj_fprem1
0x40102c __vbaSetSystemError
0x401034 _adj_fdiv_m32
0x401038 __vbaAryVar
0x40103c None
0x401040 __vbaAryDestruct
0x401044 None
0x401048 __vbaObjSet
0x40104c None
0x401050 __vbaOnError
0x401054 _adj_fdiv_m16i
0x401058 _adj_fdivr_m16i
0x40105c None
0x401060 __vbaFpR8
0x401064 None
0x401068 _CIsin
0x40106c __vbaChkstk
0x401070 EVENT_SINK_AddRef
0x401074 __vbaStrCmp
0x401078 __vbaI2I4
0x40107c DllFunctionCall
0x401080 _adj_fpatan
0x401084 EVENT_SINK_Release
0x401088 _CIsqrt
0x401090 __vbaExceptHandler
0x401094 None
0x401098 _adj_fprem
0x40109c _adj_fdivr_m64
0x4010a0 None
0x4010a4 __vbaFPException
0x4010a8 None
0x4010ac None
0x4010b0 _CIlog
0x4010b4 __vbaNew2
0x4010b8 _adj_fdiv_m32i
0x4010bc _adj_fdivr_m32i
0x4010c0 None
0x4010c4 __vbaStrCopy
0x4010c8 __vbaDerefAry1
0x4010cc _adj_fdivr_m32
0x4010d0 _adj_fdiv_r
0x4010d4 None
0x4010d8 __vbaVarTstNe
0x4010dc __vbaStrToAnsi
0x4010e0 __vbaVarDup
0x4010e4 None
0x4010e8 None
0x4010ec _CIatan
0x4010f0 __vbaStrMove
0x4010f4 __vbaAryCopy
0x4010f8 None
0x4010fc _allmul
0x401100 _CItan
0x401104 None
0x401108 _CIexp
0x40110c __vbaFreeObj
0x401110 None
0x401114 __vbaFreeStr

!This program cannot be run in DOS mode.
`.data
MSVBVM60.DLL
LUCKIEKN
REGNSK
REGNSK
Timer1
KONDEM
Grundvers
fremtid
Imitere
Gensta
BLINDSM
Tilpla3
Nonpoint
Intetsige
FABRIKSFR
Varmefor
homone
HERALDS
Praler8
tubulat
Sacrosemi
Fotol3
Scenefunk1
FLAPPAB
DIALOGIS
migration
Catch5
GLENNGLA
svenskhe
COSMECOLO
LIFTERABS
hvislel
LITTER
forest
opfostre
sampling
Otiosea
equalise
SEKUNDAER
Bebyrde6
COPLOTHN
Beisasp
Pettif9
Agtpa1
CELEST
Konfer
Twatsopht8
Twatsopht18
Bitableaf8
XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX
((((((((((((((((((((((((((((((((((((((((((
jIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIII
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~-
kLLLLLLLLLLLLLLLLLLLLLLLLLLLLLLLLLLLLLLLLLLLLL
`MMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMM
A62!Qx
zB62Vw
A62Vjj*
J&UI<7]e
,B62VuR
A62VuqhRdp
KV|tuY
?B62VpB
'B62Vo}"+
A62rd[2
DB62V}
DB62Vw
A62Vvw|9
kLTQ~r
B62VnF
/B62Vp
ao5y28
Z;t&8a
CB62Vt
MB~"MQTc1
C6Z]z%mVqyc
QB62Vh
77=%12
kB62Vn
KVjFKO]h
ty4A0)
B62VrU
@B62Vs
.62VuX
A62V~@B
|B62ViQkS
A62VsvO
hB62Vrw
r+a-h~
6C62Vs
;B62Vp
j:G{Kr
`B62V|
v2QVn@
b<AVq7
?B62Vq
A62Vvn
B62VqL
8B62et
62Vw}
byx>VjA
A62Vtrf
C6Z^h2uV|
b~VwE9
uB62Vn
A62$cl
C62rGO2
@m\ViK
K62VjM
6i7VjC8
K62Vu!
[B62Vr
V|1+)k
K62V~yX
G}C-ir
O62Vu6
C6lV|-
hkVoMU
@62V}]~7
A62rG82
mVq~kT-jh
37=RP2
SB62VjSs
fB62Vo
-B62%w
>cHVT"
CWZS:z
sVsF 2
%gT#ZKT
C6=342
2z7M,S%
gC?8eP
B62]C`R+
{* %W;
s616@
C62XK6
>K%NvS\
B62r262
c>rL62
JmSry62
XO;4@%
;Fi7%i/
J@62X_6
C62qQw
C62qIw
C6z"65=
VB5!6&*
Commis
LUCKIEKN
HEMOGENOU
SUPERMAG
Hollowhea
diskantn
vinkler
FORVAND
Febrela
TAKLINGH
Westfi
emeritus
Hrere5
Mester6
agitatio
Malpro
Truandise2
SERVICER
BOMBEA
Solitrp1
Tyrant2
cylinder
KONDEM
C:\Program Files (x86)\Microsoft Visual Studio\VB98\VB6.OLB
Timer1
Scenefunk1
Bitableaf8
homone
LIFTERABS
Gensta
Agtpa1
Konfer
hvislel
FABRIKSFR
forest
Twatsopht18
DIALOGIS
Nonpoint
COPLOTHN
fremtid
equalise
Twatsopht8
tubulat
BLINDSM
Bebyrde6
sampling
Catch5
user32
RedrawWindow
shlwapi.dll
PathIsSystemFolderA
advapi32.dll
CryptDeriveKey
IntersectClipRect
Vadehavenes
Simous
VBA6.DLL
__vbaFpR8
__vbaOnError
__vbaStrVarMove
__vbaVarDup
__vbaStrCopy
__vbaFreeVar
__vbaAryDestruct
__vbaFreeObjList
__vbaI2I4
__vbaFreeStr
__vbaSetSystemError
__vbaStrToAnsi
__vbaDerefAry1
__vbaStrCmp
__vbaAryVar
__vbaAryCopy
__vbaObjSet
__vbaVarMove
__vbaFreeObj
__vbaHresultCheckObj
__vbaNew2
__vbaStrMove
__vbaFreeVarList
__vbaVarTstNe
user32
GetWindowTextA
GetWindowTextLengthA
kernel32
VirtualProtect
WritePrivateProfileSectionA
WriteConsoleA
Actinography7
Benjaminite
Isoxazole
sklvene
Dossel6
vektorfunktioners
MSVBVM60.DLL
_CIcos
_adj_fptan
__vbaVarMove
__vbaFreeVar
__vbaStrVarMove
__vbaFreeVarList
_adj_fdiv_m64
__vbaFreeObjList
_adj_fprem1
__vbaSetSystemError
__vbaHresultCheckObj
_adj_fdiv_m32
__vbaAryVar
__vbaAryDestruct
__vbaObjSet
__vbaOnError
_adj_fdiv_m16i
_adj_fdivr_m16i
__vbaFpR8
_CIsin
__vbaChkstk
EVENT_SINK_AddRef
__vbaStrCmp
__vbaI2I4
DllFunctionCall
_adj_fpatan
EVENT_SINK_Release
_CIsqrt
EVENT_SINK_QueryInterface
__vbaExceptHandler
_adj_fprem
_adj_fdivr_m64
__vbaFPException
_CIlog
__vbaNew2
_adj_fdiv_m32i
_adj_fdivr_m32i
__vbaStrCopy
__vbaDerefAry1
_adj_fdivr_m32
_adj_fdiv_r
__vbaVarTstNe
__vbaStrToAnsi
__vbaVarDup
_CIatan
__vbaStrMove
__vbaAryCopy
_allmul
_CItan
_CIexp
__vbaFreeObj
__vbaFreeStr
Unmundanely
piscatology
Presubmission5
Proprietrernes3
REJEOPARDIZING
Chiropody
FLSKESIDE
terrorbalancers
Abstineredes
Unhailable7
SILDESTIMERNES
Milieuministeriums8
sleetproof
20:20:20
CUSTOM
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
040904B0
Comments
Registry First Aid 9
CompanyName
Registry First Aid 9
FileDescription
Registry First Aid 9
LegalCopyright
Registry First Aid 9
LegalTrademarks
Registry First Aid 9
ProductName
Registry First Aid 9
FileVersion
ProductVersion
InternalName
OriginalFilename
Gamet.exe
Antivirus Signature
Bkav W32.AIDetect.malware1
Lionic Clean
Elastic malicious (high confidence)
MicroWorld-eScan Gen:Variant.Razy.947945
FireEye Generic.mg.d62969a4f821658f
CAT-QuickHeal Clean
McAfee Clean
Cylance Unsafe
Zillya Clean
Sangfor Trojan.Win32.Save.a
CrowdStrike win/malicious_confidence_60% (D)
BitDefender Gen:Variant.Razy.947945
K7GW Clean
K7AntiVirus Clean
Baidu Clean
Cyren W32/VB.UJ.gen!Eldorado
Symantec ML.Attribute.HighConfidence
ESET-NOD32 a variant of Win32/GenKryptik.FLGD
APEX Malicious
Paloalto Clean
ClamAV Clean
Kaspersky UDS:Trojan.Win32.Mucc
Alibaba Clean
NANO-Antivirus Clean
ViRobot Clean
Rising Downloader.Guloader!1.D9C4 (CLASSIC)
Ad-Aware Gen:Variant.Razy.947945
Sophos ML/PE-A
Comodo Clean
F-Secure Clean
DrWeb Clean
VIPRE Clean
TrendMicro Clean
McAfee-GW-Edition Clean
CMC Clean
Emsisoft Gen:Variant.Razy.947945 (B)
SentinelOne Static AI - Malicious PE
GData Gen:Variant.Razy.947945
Jiangmin Clean
Webroot Clean
Avira Clean
MAX malware (ai score=84)
Antiy-AVL Clean
Kingsoft Clean
Gridinsoft Clean
Arcabit Clean
SUPERAntiSpyware Clean
ZoneAlarm Clean
Microsoft Trojan:Win32/Sabsik.FL.B!ml
Cynet Malicious (score: 100)
AhnLab-V3 Clean
Acronis Clean
BitDefenderTheta Gen:NN.ZevbaF.34170.gm0@a4dSMRai
ALYac Gen:Variant.Razy.947945
TACHYON Clean
VBA32 BScope.Trojan.Mucc
Malwarebytes Clean
Panda Trj/GdSda.A
Zoner Clean
TrendMicro-HouseCall Clean
Tencent Clean
Yandex Clean
Ikarus Trojan.VB.Crypt
MaxSecure Clean
Fortinet Clean
Cybereason malicious.52c8e8
Avast Clean
No IRMA results available.