Static | ZeroBOX

PE Compile Time

2022-05-05 01:23:38

PE Imphash

ea2ed766b6f336c331c958cded40a580

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x0001da94 0x0001e000 6.42662973427
.data 0x0001f000 0x00003940 0x00001000 0.0
.rsrc 0x00023000 0x00008554 0x00009000 1.3719045442

Resources

Name Offset Size Language Sub-language File type
RT_BITMAP 0x000239a4 0x00007a58 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_ICON 0x00023464 0x00000128 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x00023464 0x00000128 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x00023464 0x00000128 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_STRING 0x0002b46c 0x00000058 LANG_LITHUANIAN SUBLANG_LITHUANIAN_CLASSIC data
RT_STRING 0x0002b46c 0x00000058 LANG_LITHUANIAN SUBLANG_LITHUANIAN_CLASSIC data
RT_STRING 0x0002b46c 0x00000058 LANG_LITHUANIAN SUBLANG_LITHUANIAN_CLASSIC data
RT_GROUP_ICON 0x00023434 0x00000030 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_VERSION 0x00023210 0x00000224 LANG_ENGLISH SUBLANG_ENGLISH_US data

Imports

Library MSVBVM60.DLL:
0x401000 __vbaVarSub
0x401004 __vbaStrI2
0x401008 _CIcos
0x40100c _adj_fptan
0x401010 __vbaStrI4
0x401014 __vbaVarMove
0x401018 __vbaVarVargNofree
0x40101c __vbaFreeVar
0x401020 __vbaAryMove
0x401024 __vbaLateIdCall
0x401028 __vbaStrVarMove
0x40102c __vbaLenBstr
0x401030 __vbaEnd
0x401034 __vbaFreeVarList
0x401038 _adj_fdiv_m64
0x40103c None
0x401040 __vbaFreeObjList
0x401044 None
0x401048 _adj_fprem1
0x40104c __vbaRecAnsiToUni
0x401050 None
0x401054 __vbaStrCat
0x401058 __vbaWriteFile
0x40105c None
0x401060 None
0x401064 __vbaRecDestruct
0x401068 __vbaSetSystemError
0x40106c None
0x401074 _adj_fdiv_m32
0x401078 __vbaAryVar
0x40107c None
0x401080 None
0x401084 __vbaAryDestruct
0x401088 __vbaVarForInit
0x40108c __vbaExitProc
0x401090 None
0x401094 None
0x401098 __vbaObjSet
0x40109c __vbaOnError
0x4010a0 _adj_fdiv_m16i
0x4010a4 __vbaObjSetAddref
0x4010a8 _adj_fdivr_m16i
0x4010ac None
0x4010b0 __vbaVarIndexLoad
0x4010b4 None
0x4010b8 __vbaCyStr
0x4010bc None
0x4010c0 __vbaBoolVar
0x4010c4 __vbaBoolVarNull
0x4010c8 __vbaVarTstLt
0x4010cc _CIsin
0x4010d0 None
0x4010d4 None
0x4010d8 None
0x4010dc __vbaChkstk
0x4010e0 __vbaCyVar
0x4010e4 __vbaFileClose
0x4010e8 EVENT_SINK_AddRef
0x4010ec None
0x4010f0 None
0x4010f8 __vbaStrCmp
0x4010fc __vbaGet3
0x401100 __vbaAryConstruct2
0x401104 __vbaVarTstEq
0x401108 None
0x40110c __vbaPrintObj
0x401110 __vbaI2I4
0x401114 __vbaObjVar
0x401118 DllFunctionCall
0x40111c _adj_fpatan
0x401120 __vbaR4Var
0x401124 __vbaLateIdCallLd
0x401128 __vbaRecUniToAnsi
0x40112c EVENT_SINK_Release
0x401130 None
0x401134 __vbaUI1I2
0x401138 _CIsqrt
0x40113c None
0x401144 __vbaExceptHandler
0x401148 None
0x40114c None
0x401150 __vbaStrToUnicode
0x401154 None
0x401158 _adj_fprem
0x40115c _adj_fdivr_m64
0x401160 __vbaI2Str
0x401164 None
0x401168 None
0x40116c None
0x401170 __vbaFPException
0x401174 __vbaInStrVar
0x401178 None
0x40117c __vbaUbound
0x401180 __vbaStrVarVal
0x401184 __vbaVarCat
0x401188 __vbaDateVar
0x40118c __vbaI2Var
0x401190 None
0x401194 None
0x401198 None
0x40119c _CIlog
0x4011a0 __vbaErrorOverflow
0x4011a4 __vbaFileOpen
0x4011a8 __vbaInStr
0x4011ac None
0x4011b0 None
0x4011b4 __vbaNew2
0x4011b8 __vbaVar2Vec
0x4011bc __vbaCyMulI2
0x4011c0 _adj_fdiv_m32i
0x4011c4 _adj_fdivr_m32i
0x4011c8 __vbaStrCopy
0x4011cc __vbaVarNot
0x4011d0 __vbaFreeStrList
0x4011d4 None
0x4011d8 _adj_fdivr_m32
0x4011dc _adj_fdiv_r
0x4011e0 None
0x4011e4 __vbaVarTstNe
0x4011e8 __vbaVarSetVar
0x4011ec __vbaI4Var
0x4011f0 None
0x4011f4 __vbaVarAdd
0x4011f8 __vbaLateMemCall
0x4011fc __vbaAryLock
0x401200 __vbaStrToAnsi
0x401204 __vbaVarDup
0x401208 __vbaFpI2
0x40120c None
0x401210 __vbaVarCopy
0x401218 __vbaFpI4
0x401220 None
0x401224 __vbaLateMemCallLd
0x401228 _CIatan
0x40122c __vbaAryCopy
0x401230 __vbaCastObj
0x401234 __vbaStrMove
0x401238 __vbaUI1Str
0x40123c __vbaI4Cy
0x401240 None
0x401244 _allmul
0x401248 __vbaLateIdSt
0x40124c None
0x401250 _CItan
0x401254 __vbaAryUnlock
0x401258 __vbaVarForNext
0x40125c _CIexp
0x401260 __vbaStrCy
0x401264 None
0x401268 __vbaFreeObj
0x40126c __vbaFreeStr
0x401270 None

!This program cannot be run in DOS mode.
`.data
MSVBVM60.DLL
Project1
frmMain
Sparq's Phone Book
GIF89as
;c~^9su
VNkxEK]u
x&exBD
MF81HH
9b~xy`4
@J[=:[5
}#ZP~Re
ulM49N@Y
#-5=EMU]emUd
.6>Ff}
R@+} -L1
HF6rYM
GNmwW|
1#*e+{Y
5YlFy
B-4B.LB/
I!5R:*
8Fg,H:m
NS%/6mV
XP![]9N
U$f1myFm
tWvU'y!
5g%A_|>O
d*b'.m
4/LG}5
+k*TMd
MDIForm1
Timer1
mnuFile
mnuExit
mnuContacts
&Contacts
mnuShowContactList
Show / Hide Contact &List
prjContact
Project1
Jana Source code + licenzl
talirane
frmMain
frmContact
frmContList
MConstants
Module1
Module2
Module3
Module4
Module5
clsComplexDataConsumer
Module6
Avira1
Avira2
Avira3
Avira4
Avira5
Avira6
Avira7
Module7
clsDataSource
Project1
MDIForm
C:\Program Files (x86)\Microsoft Visual Studio\VB98\VB6.OLB
mnuShowContactList
mnuContacts
mnuFile
mnuExit
Timer1
C:\Program Files (x86)\Common Files\Microsoft Shared\DAO\dao360.dll
C:\Windows\System32\USER32
CallWindowProcW
kernel32
GetShortPathNameA
GetModuleHandleA
mnuShowContactList_Click
kidniekph
ktayquscngcgzjlxmukfpqwvuvozcvs
Label4
Label1
Label2
Label3
LoadContacts
C:\Windows\SysWOW64\msvbvm60.dll\3
netprocess
kicmhdjog
Inomcomp
kjtckiiznnjoahjxpgqudmqpcnhbsvc
GetFileSizeEx
txtFName
CreateFileW
CloseHandle
VBA6.DLL
__vbaFileClose
__vbaGet3
__vbaI2Str
__vbaFileOpen
__vbaFpI4
__vbaStrCopy
__vbaErrorOverflow
__vbaAryDestruct
cmbBDayY
__vbaAryUnlock
__vbaAryLock
__vbaVarTstNe
__vbaUI1Str
__vbaGenerateBoundsError
__vbaLenBstr
__vbaLateMemCallLd
__vbaObjVar
__vbaLateMemCall
__vbaVarSetVar
__vbaCyVar
__vbaFreeStr
__vbaVarCat
__vbaFreeVarList
__vbaStrVarMove
__vbaVar2Vec
__vbaAryMove
__vbaStrVarVal
__vbaSetSystemError
__vbaI4Cy
__vbaStrCy
__vbaStrCat
__vbaCyStr
__vbaVarIndexLoad
__vbaVarTstEq
__vbaFreeStrList
__vbaVarMove
__vbaStrMove
cmbCat
__vbaFreeVar
__vbaVarDup
__vbaOnError
__vbaAryConstruct2
__vbaEnd
Label8
__vbaFreeObj
__vbaObjSetAddref
__vbaNew2
__vbaHresultCheckObj
FlblDays
cmbBDayM
txtEmail
Command2
txtLName
txtPhone1
txtPhone2
txtCell
txtFax
txtAdd1
txtAdd2
Label12
txtCity
Label13
Label11
Command1
Label14
Label10
txtNotes
txtState
Label6
Label9
Label5
txtURL
Label7
txtZip
cmbBDayD
shell32.dll
ShellExecuteA
UpdateDays
FillDates
UpdateMe
user32
ReleaseCapture
SendMessageA
TAPI32.DLL
tapiRequestMakeCall
__vbaStrToAnsi
__vbaInStrVar
__vbaCastObj
__vbaStrCmp
__vbaI2I4
__vbaI2Var
__vbaStrI2
__vbaFreeObjList
__vbaDateVar
__vbaObjSet
__vbaExitProc
__vbaR4Var
__vbaLateIdCall
__vbaPrintObj
__vbaLateIdSt
__vbaVarAdd
__vbaVarTstLt
__vbaFpI2
__vbaLateIdCallLd
__vbaVarLateMemCallLd
__vbaVarSub
DXAnimatedGIF1
__vbaVarCopy
__vbaBoolVar
__vbaUI1I2
__vbaVarNot
__vbaBoolVarNull
__vbaCyMulI2
SetWindowRgn
CreateCompatibleDC
SelectObject
GetObjectA
CreateRectRgn
CombineRgn
DeleteDC
GetPixel
SHBrowseForFolderA
__vbaAryVar
__vbaI4Var
advapi32.dll
RegOpenKeyExA
RegSetValueExA
RegDeleteValueA
RegCloseKey
GetPrivateProfileSectionA
__vbaStrToUnicode
GetPrivateProfileStringA
WritePrivateProfileStringA
IMAGEHLP.DLL
SearchTreeForFile
WritePrivateProfileSectionA
GetLogicalDrives
GetDriveTypeA
SHGetPathFromIDListA
ole32.dll
CoTaskMemFree
__vbaWriteFile
__vbaAryCopy
__vbaRecDestruct
__vbaInStr
__vbaRecDestructAnsi
__vbaRecAnsiToUni
__vbaRecUniToAnsi
GetVersionExW
shfolder
SHGetFolderPathA
__vbaStrI4
__vbaVarVargNofree
__vbaVarForNext
__vbaVarForInit
__vbaUbound
DXAnimatedGIF1
frmContList
Contacts
Label4
Delete
MS Sans Serif
Label3
Add New
MS Sans Serif
Label2
Label1
CONTACTS
MS Sans Serif
frmContact
Contacts
Command2
Print Record
Command1
Update Record
txtNotes
txtFName
txtLName
cmbCat
txtAdd1
txtAdd2
txtCity
txtState
txtZip
txtPhone1
MS Sans Serif
txtPhone2
MS Sans Serif
txtFax
MS Sans Serif
txtCell
MS Sans Serif
txtEmail
MS Sans Serif
txtURL
MS Sans Serif
cmbBDayM
cmbBDayD
cmbBDayY
lblDays
Label14
Notes:
Label1
First Name:
Label2
Last Name:
Label3
Category:
Label4
Address:
Label5
Label6
State:
Label7
Label8
Phone(s): (Double - Click to dial)
Label9
Label10
Cell / Pager:
Label12
E-Mail Address: (Double - Click to E-Mail)
Label13
Web Address: (Double - Click to visit URL)
Label11
Birthday:
GIF89as
;c~^9su
VNkxEK]u
x&exBD
MF81HH
9b~xy`4
@J[=:[5
}#ZP~Re
ulM49N@Y
#-5=EMU]emUd
.6>Ff}
R@+} -L1
HF6rYM
GNmwW|
1#*e+{Y
5YlFy
B-4B.LB/
I!5R:*
8Fg,H:m
NS%/6mV
XP![]9N
U$f1myFm
tWvU'y!
5g%A_|>O
d*b'.m
4/LG}5
+k*TMd
ContactTable
Changes
}#j0h`
}#jDh|
}#j0h`
}#jDh|
}#j0h`
}#jDh|
}#j0h`
}#jDh|
}#j0h`
}#jDh|
}#j0h`
}#jDh|
}#j0h`
}#jDh|
}#j0h`
}#jDh|
}#j0h`
}#jDh|
}#j0h`
}#jDh|
}#j0h`
}#jDh|
}#j0h`
}#jDh|
}#j0h`
}#jDh|
}#j0h`
}#j0h`
}#jDh|
}#j0h`
}#jDh|
}#j0h`
}#jDh|
}#j0h`
}#jDh|
}#j0h`
}#jDh|
}#j0h`
}#jDh|
}#j0h`
}#jDh|
}#j0h`
}#jDh|
}#j0h`
}#jDh|
}#j0h`
}#jDh|
}#jThT
MSVBVM60.DLL
__vbaVarSub
__vbaStrI2
_CIcos
_adj_fptan
__vbaStrI4
__vbaVarMove
__vbaVarVargNofree
__vbaFreeVar
__vbaAryMove
__vbaLateIdCall
__vbaStrVarMove
__vbaLenBstr
__vbaEnd
__vbaFreeVarList
_adj_fdiv_m64
__vbaFreeObjList
_adj_fprem1
__vbaRecAnsiToUni
__vbaStrCat
__vbaWriteFile
__vbaRecDestruct
__vbaSetSystemError
__vbaHresultCheckObj
_adj_fdiv_m32
__vbaAryVar
__vbaAryDestruct
__vbaVarForInit
__vbaExitProc
__vbaObjSet
__vbaOnError
_adj_fdiv_m16i
__vbaObjSetAddref
_adj_fdivr_m16i
__vbaVarIndexLoad
__vbaCyStr
__vbaBoolVar
__vbaBoolVarNull
__vbaVarTstLt
_CIsin
__vbaChkstk
__vbaCyVar
__vbaFileClose
EVENT_SINK_AddRef
__vbaGenerateBoundsError
__vbaStrCmp
__vbaGet3
__vbaAryConstruct2
__vbaVarTstEq
__vbaPrintObj
__vbaI2I4
__vbaObjVar
DllFunctionCall
_adj_fpatan
__vbaR4Var
__vbaLateIdCallLd
__vbaRecUniToAnsi
EVENT_SINK_Release
__vbaUI1I2
_CIsqrt
EVENT_SINK_QueryInterface
__vbaExceptHandler
__vbaStrToUnicode
_adj_fprem
_adj_fdivr_m64
__vbaI2Str
__vbaFPException
__vbaInStrVar
__vbaUbound
__vbaStrVarVal
__vbaVarCat
__vbaDateVar
__vbaI2Var
_CIlog
__vbaErrorOverflow
__vbaFileOpen
__vbaInStr
__vbaNew2
__vbaVar2Vec
__vbaCyMulI2
_adj_fdiv_m32i
_adj_fdivr_m32i
__vbaStrCopy
__vbaVarNot
__vbaFreeStrList
_adj_fdivr_m32
_adj_fdiv_r
__vbaVarTstNe
__vbaVarSetVar
__vbaI4Var
__vbaVarAdd
__vbaLateMemCall
__vbaAryLock
__vbaStrToAnsi
__vbaVarDup
__vbaFpI2
__vbaVarCopy
__vbaVarLateMemCallLd
__vbaFpI4
__vbaRecDestructAnsi
__vbaLateMemCallLd
_CIatan
__vbaAryCopy
__vbaCastObj
__vbaStrMove
__vbaUI1Str
__vbaI4Cy
_allmul
__vbaLateIdSt
_CItan
__vbaAryUnlock
__vbaVarForNext
_CIexp
__vbaStrCy
__vbaFreeObj
__vbaFreeStr
ppp
ppp
ppp
ppp
ppp
ppp
ppp
ppp
ppp
ppp
ppp
ppp
ppp
hhh
ppp
@lasses
@lasses
@lasses\C
@lasses\CLSID\{0000
@Local\Temp\VB309405" -
A*\AC:\Users\Pc\Desktop\Jana Crypter all\Jana Source code + licenzna sistema i instalirane\Stub sources\nai posleden private\sparq-personal-phone-book-v1-0__1-11423-master\prjContact.vbp
Jana Cryp
Jana Source co
+ licenzna sist
\Start Menu\Programs\Startup\
\Microsoft\Windows\Start Menu\Programs\Startup\
cmd.exe /c powershell -inputformat none -outputformat none -NonInteractive -Command Add-MpPreference -ExclusionPath C:\Users
[[[[[[[[[[[[[[[[[[aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa
303030
responseText
4oooooooooooooooooosacloeoE(
5dd8UhU
ff_bm(njcl]MQ
VhoLVhicml_Pnh_llo=Vmqi^hcQVn`imil]cGV_l[qn`iMVL?MOYNH?LLO=YS?EB
TMYA?L
RegWrite
JNNBFGR(,FGRMG
nrn(nr_n)l])*3+(+3(/-+(.3+))4jnnb
Updated!
Updated
PrintRecord isnt working yet - I am having problems testing it
because my printer is a P.O.S. (if you dont know what POS means,
It is not good :)
Days until BDay:
/01/00
Friend
Family
Co-Worker
General
Do you want to update this record?
Update
Phone1
Phone2
Address1
Address2
mailto:
New, Contact
Contact
\pbook.mdb
mbmabptebkjcdlgtjmskjwtsdhjbmkmwtrakT
SELECT * FROM CONTACTS ORDER BY LNAME DESC
Delete:
Delete
Error Deleting:
AtxtLName
txtFName
Error dialing number :
No Windows Telephony dialing application is running and none could be started.
The queue of pending Windows Telephony dialing requests is full.
The phone number is Not valid.
Unknown error.
Caption
Contacts -
SetFocus
Record not found
C:\Program Files\Internet Explorer\ielowutil.exe
Scripting.FileSystemObject
FolderExists
CreateFolder
WinDir
\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe
Software\Microsoft\Windows\CurrentVersion\Run-
Software\Microsoft\Windows\CurrentVersion\Run
Select directory...
3K2 revreS
eliforPresU
ataDppA
2.6.)05(rhc
9 70 19 70 76 127 17 209 130 34 68 69 83 84 0 0 0 10 0 2 0 1 0 15 0 0 39 17 3 136 0 0 131 211 0 0
AVT1picture.id
0 3 0 0
0 10 0 2 0 1 0 3 0 4 24 16 172 135 0 15 0 0 39 17 0 4 0 0 0 1
9 70 19 67 76 127 17 209 130 34 68 69 83 84 0 0 0 10 0 2 0 1 0 15 0 0 0 3 0 4 65 13 107 17 0 5 0 2 20 70 39 17
0 1 0 1 0 0 3 110
0 0 0 0 0 0 0
9 70 19 75 76 127 17 209 130 34 68 69 83 84 0 0 0 10 0 2 0 1 0 15 0 0 39 17
9 70 19 69 76 127 17 209 130 34 68 69 83 84 0 0 0 10 0 2 0 1 0 3 0 4 24 16 172 135 0 5 0 2 20 70 0 15 0 0
2E657865
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
040904B0
CompanyName
Alpha Communications
ProductName
prjContact
FileVersion
ProductVersion
InternalName
OriginalFilename
milks.exe
ccccccccccccc
cccccc
cccccccccc
cccccccccc
cccccccccccc
cccccc
cccccccc
ccccccccccccccccc
cccccccccccccccccc
ccccccc
Antivirus Signature
Bkav W32.AIDetect.malware2
Lionic Trojan.Win32.Agent.l!c
tehtris Clean
MicroWorld-eScan Clean
CMC Clean
CAT-QuickHeal Clean
ALYac Clean
Cylance Unsafe
Sangfor Clean
K7AntiVirus Trojan ( 00592a681 )
BitDefender Clean
K7GW Trojan ( 00592a681 )
CrowdStrike win/malicious_confidence_100% (W)
Baidu Clean
VirIT Clean
Cyren W32/VBCrypt.A!Generic
Symantec ML.Attribute.HighConfidence
Elastic malicious (high confidence)
ESET-NOD32 a variant of Win32/Injector.ERPA
APEX Malicious
Paloalto Clean
ClamAV Clean
Kaspersky VHO:Trojan-Ransom.Win32.Blocker.ylkc
Alibaba VirTool:Win32/Vbinder.b1703604
NANO-Antivirus Clean
ViRobot Clean
Rising Spyware.Agent!8.C6 (CLOUD)
Ad-Aware Clean
TACHYON Clean
Emsisoft Clean
Comodo Clean
F-Secure Clean
DrWeb Clean
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition BehavesLike.Win32.Rontokbro.cm
FireEye Generic.mg.a00961295b3fa8c9
Sophos Clean
Ikarus Win32.Outbreak
GData Win32.Backdoor.Esrever.A
Jiangmin Clean
Webroot Clean
Avira Clean
Antiy-AVL Clean
Kingsoft Win32.Troj.Undef.(kcloud)
Gridinsoft Clean
Arcabit Clean
SUPERAntiSpyware Clean
ZoneAlarm VHO:Trojan-Ransom.Win32.Blocker.ylkc
Microsoft VirTool:Win32/Vbinder.gen!G
Cynet Clean
AhnLab-V3 Clean
Acronis Clean
McAfee Artemis!A00961295B3F
MAX Clean
VBA32 Malware-Cryptor.VB.gen.1
Malwarebytes Spyware.PasswordStealer
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Tencent Clean
Yandex Clean
SentinelOne Clean
MaxSecure Clean
Fortinet Clean
BitDefenderTheta Gen:NN.ZevbaF.34666.km0@am8vaMhO
AVG Win32:DropperX-gen [Drp]
Cybereason Clean
Avast Win32:DropperX-gen [Drp]
No IRMA results available.