Static | ZeroBOX

PE Compile Time

2016-01-07 18:15:56

PE Imphash

cb4f8c840affb61160ab1afb91e9cfb4

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x0001c154 0x0001d000 6.69169848317
.data 0x0001e000 0x00002070 0x00001000 0.0
.rsrc 0x00021000 0x00002a60 0x00003000 4.75529817135

Resources

Name Offset Size Language Sub-language File type
RC_DATA 0x000229ea 0x00001076 LANG_ENGLISH SUBLANG_ENGLISH_US MS Windows icon resource - 2 icons, 24x24, 8 bits/pixel, 24x24, 32 bits/pixel
RC_DATA 0x000229ea 0x00001076 LANG_ENGLISH SUBLANG_ENGLISH_US MS Windows icon resource - 2 icons, 24x24, 8 bits/pixel, 24x24, 32 bits/pixel
RT_ICON 0x00021434 0x00000128 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x00021434 0x00000128 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x00021434 0x00000128 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_GROUP_ICON 0x00021404 0x00000030 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_VERSION 0x000211d0 0x00000234 LANG_ENGLISH SUBLANG_ENGLISH_US data

Imports

Library MSVBVM60.DLL:
0x401000 None
0x401004 _CIcos
0x401008 _adj_fptan
0x40100c __vbaFreeVar
0x401010 __vbaLineInputStr
0x401014 __vbaFreeVarList
0x401018 _adj_fdiv_m64
0x40101c __vbaFreeObjList
0x401020 _adj_fprem1
0x401024 __vbaStrCat
0x40102c _adj_fdiv_m32
0x401030 __vbaAryDestruct
0x401034 None
0x401038 __vbaStrBool
0x40103c None
0x401040 __vbaObjSet
0x401044 __vbaOnError
0x401048 _adj_fdiv_m16i
0x40104c __vbaObjSetAddref
0x401050 _adj_fdivr_m16i
0x401054 None
0x401058 __vbaFpR8
0x40105c _CIsin
0x401060 __vbaChkstk
0x401064 __vbaFileClose
0x401068 EVENT_SINK_AddRef
0x401070 __vbaStrCmp
0x401074 __vbaAryConstruct2
0x401078 __vbaObjVar
0x40107c _adj_fpatan
0x401080 None
0x401084 __vbaLateIdCallLd
0x401088 None
0x40108c EVENT_SINK_Release
0x401090 _CIsqrt
0x401098 __vbaExceptHandler
0x40109c _adj_fprem
0x4010a0 _adj_fdivr_m64
0x4010a4 None
0x4010a8 __vbaFPException
0x4010ac __vbaStrVarVal
0x4010b0 None
0x4010b4 None
0x4010b8 _CIlog
0x4010bc __vbaErrorOverflow
0x4010c0 __vbaFileOpen
0x4010c4 __vbaNew2
0x4010c8 None
0x4010cc None
0x4010d0 None
0x4010d4 _adj_fdiv_m32i
0x4010d8 _adj_fdivr_m32i
0x4010dc __vbaI4Str
0x4010e0 __vbaFreeStrList
0x4010e4 _adj_fdivr_m32
0x4010e8 _adj_fdiv_r
0x4010ec None
0x4010f0 __vbaI4Var
0x4010f4 None
0x4010f8 __vbaFpI4
0x4010fc _CIatan
0x401100 __vbaStrMove
0x401104 __vbaR8IntI4
0x401108 _allmul
0x40110c _CItan
0x401110 _CIexp
0x401114 __vbaFreeStr
0x401118 __vbaFreeObj

!This program cannot be run in DOS mode.
`.data
MSVBVM60.DLL
SGERET
REJFERS
KORDNINGS
KORDNINGS
Option2
Option2
Check2
Check2
Combo2
Combo2
HScroll1
Timer1
Frame1
Frame1
Check1
Check1
Option1
Option1
Combo1
Combo1
VB5!6&*
BESTYREREN
FJERNSYNSSENDEREN
SGERET
SGERET
REJFERS
MAGTSYGES
SEMIBLASPHEMOUS
KNARKENE
UA1CM"
Check1
C:\Program Files (x86)\Microsoft Visual Studio\VB98\VB6.OLB
Combo1
Check2
Combo2
Timer1
Option1
Frame1
HScroll1
Option2
LoadTips
DisplayCurrentTip
gematriot
tigerspringets
Unsnoring5
ekspektancelister
VBA6.DLL
__vbaErrorOverflow
__vbaAryDestruct
__vbaObjVar
__vbaFpI4
__vbaLateIdCallLd
__vbaI4Var
__vbaGenerateBoundsError
__vbaFpR8
__vbaOnError
__vbaAryConstruct2
__vbaStrVarVal
__vbaLineInputStr
__vbaStrCat
__vbaI4Str
__vbaFreeObj
__vbaObjSetAddref
__vbaFreeObjList
h__vbaFreeStrList
__vbaObjSet
__vbaStrBool
__vbaFileClose
__vbaFreeVarList
__vbaFileOpen
__vbaFreeStr
__vbaStrMove
__vbaStrCmp
__vbaFreeVar
__vbaHresultCheckObj
__vbaNew2
__vbaR8IntI4
<ql}VT
KNARKENE
SEMIBLASPHEMOUS
SUBAPPROBATION
SUBAPPROBATION
MAGTSYGES
CRINCH
ICC_PROFILE
mntrRGB XYZ
9acspAPPL
1$$1,5+(+5,N=77=NZLHLZnbbn
1$$1,5+(+5,N=77=NZLHLZnbbn
%7S3ZB
!*#@1 3\Wu
:6U~oV
l~;r=Zg]
r=ZgTq
;OTlQD
\: $l^
+9xDb?
\pF^=8
Aj,,BE
r=^g"
z16p5bTt+D
8pr=Zg
Cz~TD
pFTlcD
pFTt2D
pFTtfD
/x\boBs
U/T|\V
tpF"L`G
qlI^8r
s{9hX
pF59bF
33t2Ep
pFTDeD
MrxDb'
pIYhpF
pFR|DG
pFTd:D
kpFT|pG
pFTdND
+P?r\Q
:nTtYD
*1qxDb
cWg*My
p3U;xF4
pFT|5D
pFV|`G
=x\b6S
pFTt@D
~opS"l
)}r=^g
R4#T#"
pFT|7D
pFVNdN
pFT|vD
pFV|vD
p8fVNpN
*YVL)D
U}x\b<
pFT|_D
pFVfpN
p(ZVfxN
pFVlBD
pIYxqF
3 X+I
pFTtJD
pFT|oD
RcHkeXx
_7xDbs1z(\
pFc-4c
pF\>hB
p7B^>`
pF"L|G
pFT|VD
xtbY4oWTt
pFTD-D
pFT|rD
O8FZpO'
O8FZpO'
pIY}pF
pIX{tF
pF"NpN
pFTlJD
pF5V)F
B85wuF
v5"4ScF
pFTdbD
pFVdLG
pF4SxF
!xDbBR
k`xx\b
pFTl.D
pFT|hG
r=^gd
pFT|QD
pFTLD
pwm>;N
}_h3RA
]z9{ms
pIYqpF
As \L/D
pFTlLD
TBVlLD
p3`;tFY
O-u~,^HC)
;r=ZgA
Oxtb>W
p(nVdHG
pIX8uF
r#@^:zw
pFVtXD
p3Hr#O^:tw
r5n50qF
pIXCpF
pIX[pF
lIRKpF
i1KKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKh
]666666666666666666666666666666666666666
mmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmm
Q 5
bklllllllllllllllllllllllllllllllllllllllllll
t6LLLLLLLLLLLLLLLLLLLLLLLLLLLLLLLLLLLLLLLLLLLL
@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@
1}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}f
EEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEE
d%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%
``````````````````````````````````````````
V^UUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUh
?aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa
9GGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGf1
[<+55555555555555555555555555555555555555555555f1
| K
~111111111111111111111111111111111111111111Kf
u;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;
000000000000000000000000000000000000000000000P
+5sEtvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvv
wPp}s(
(R`{{"
AX@|@n
E@})*F
,Tr!;%
pp/Ai
ZA_y_qs
a`3DNS
l0tK9^
K&&*),
aQ~~*=
A.hckg
yDK%Bc
SZk0RP
ID]qd>Q,
4_(4(|
*(}H*j?UJ
6J"`6.{
?15-`o
9#TB_R
u>>"@i
H41vrG@
CRINCH
Brikvvning5
Nargilehs6
UDBASUNERINGER
buskadserne
idiomuscular
Dekoratren
Fyldekalket6
BILABIALE
jThX,@
jThX,@
} jhhX,@
} j`h .@
} jhhX,@
} jXh .@
} j`h .@
} jhhX,@
} j`h .@
} j`h0.@
} j`hX,@
} j`h .@
} jXh .@
} j h@.@
} j(h@.@
MSVBVM60.DLL
_CIcos
_adj_fptan
__vbaFreeVar
__vbaLineInputStr
__vbaFreeVarList
_adj_fdiv_m64
__vbaFreeObjList
_adj_fprem1
__vbaStrCat
__vbaHresultCheckObj
_adj_fdiv_m32
__vbaAryDestruct
__vbaStrBool
__vbaObjSet
__vbaOnError
_adj_fdiv_m16i
__vbaObjSetAddref
_adj_fdivr_m16i
__vbaFpR8
_CIsin
__vbaChkstk
__vbaFileClose
EVENT_SINK_AddRef
__vbaGenerateBoundsError
__vbaStrCmp
__vbaAryConstruct2
__vbaObjVar
_adj_fpatan
__vbaLateIdCallLd
EVENT_SINK_Release
_CIsqrt
EVENT_SINK_QueryInterface
__vbaExceptHandler
_adj_fprem
_adj_fdivr_m64
__vbaFPException
__vbaStrVarVal
_CIlog
__vbaErrorOverflow
__vbaFileOpen
__vbaNew2
_adj_fdiv_m32i
_adj_fdivr_m32i
__vbaI4Str
__vbaFreeStrList
_adj_fdivr_m32
_adj_fdiv_r
__vbaI4Var
__vbaFpI4
_CIatan
__vbaStrMove
__vbaR8IntI4
_allmul
_CItan
_CIexp
__vbaFreeStr
__vbaFreeObj
@VV<$\d
a+@o)3
9fffZ[
cccccp-
yIbAAA
l6"{VVVV
==]]]]+
~~~33(/
UU_Zdd?^
d=]H -
\+:002Q5
hPP889
d{+fI-
=>>>>"
TTT!!!!!!O
TIPOFDAY.TXT
Options
Show Tips at Startup
That the
file was not found?
Create a text file named
using NotePad with 1 tip per line.
Then place it in the same directory as the application.
Terracette
Andejagters
Wscript.shell
RC_DATA
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
040904B0
Comments
CompanyName
ProductName
FileVersion
ProductVersion
InternalName
BESTYREREN
OriginalFilename
BESTYREREN.exe
Antivirus Signature
Bkav W32.AIDetect.malware1
Lionic Trojan.Win32.Malicious.4!c
Elastic malicious (high confidence)
MicroWorld-eScan Clean
CMC Clean
CAT-QuickHeal Clean
McAfee RDN/Generic.dx
Cylance Clean
VIPRE Clean
Sangfor Trojan.Win32.Save.a
K7AntiVirus Clean
BitDefender Clean
K7GW Clean
Cybereason malicious.c56b23
Baidu Clean
Cyren Clean
Symantec Trojan.Gen.9
ESET-NOD32 a variant of Win32/Injector_AGen.X
APEX Malicious
Paloalto generic.ml
ClamAV Clean
Kaspersky UDS:Worm.Multi.GenericML.xnet
Alibaba Clean
NANO-Antivirus Clean
ViRobot Clean
Tencent Clean
Ad-Aware Clean
Sophos Mal/Generic-S
Comodo Clean
F-Secure Clean
DrWeb Clean
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition BehavesLike.Win32.PWSZbot.ch
FireEye Generic.mg.013d4cb9c83ba31b
Emsisoft Clean
SentinelOne Static AI - Malicious PE
GData Clean
Jiangmin Clean
Webroot W32.Malware.Gen
Avira Clean
MAX malware (ai score=99)
Antiy-AVL Clean
Kingsoft Win32.Troj.Generic_a.a.(kcloud)
Gridinsoft Clean
Arcabit Clean
SUPERAntiSpyware Clean
ZoneAlarm Clean
Microsoft Trojan:Script/Phonzy.B!ml
Cynet Clean
AhnLab-V3 Clean
Acronis Clean
VBA32 Clean
ALYac Clean
TACHYON Clean
Malwarebytes Clean
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Rising Clean
Yandex Trojan.AvsArher.bTx33N
Ikarus Win32.Outbreak
eGambit Unsafe.AI_Score_99%
Fortinet Clean
BitDefenderTheta Gen:NN.ZevbaF.34170.im0@ainsXbdi
AVG FileRepMalware
Avast FileRepMalware
CrowdStrike win/malicious_confidence_70% (W)
MaxSecure Clean
No IRMA results available.