Static | ZeroBOX

PE Compile Time

2021-05-28 16:16:54

PE Imphash

a1ba6025b78e60e0064fd3f4e4abe78e

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x00005e90 0x00006000 5.45995894403
.data 0x00007000 0x00000b04 0x00001000 0.0
.rsrc 0x00008000 0x00000d80 0x00001000 3.26508521853

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x0000830c 0x00000a74 LANG_NEUTRAL SUBLANG_NEUTRAL dBase III DBT, version number 0, next free block index 40
RT_GROUP_ICON 0x000082f8 0x00000014 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_VERSION 0x000080f0 0x00000208 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data

Imports

Library MSVBVM60.DLL:
0x401000 __vbaVarTstGt
0x401004 __vbaStrI2
0x401008 _CIcos
0x40100c _adj_fptan
0x401010 __vbaVarMove
0x401014 __vbaFreeVar
0x401018 __vbaStrVarMove
0x40101c __vbaFreeVarList
0x401020 __vbaEnd
0x401024 _adj_fdiv_m64
0x401028 __vbaNextEachVar
0x40102c __vbaFreeObjList
0x401030 __vbaLineInputVar
0x401034 _adj_fprem1
0x401038 None
0x40103c __vbaStrCat
0x401040 __vbaSetSystemError
0x401048 _adj_fdiv_m32
0x40104c __vbaExitProc
0x401050 None
0x401054 __vbaVarForInit
0x401058 None
0x40105c __vbaObjSet
0x401060 __vbaOnError
0x401064 _adj_fdiv_m16i
0x401068 __vbaObjSetAddref
0x40106c _adj_fdivr_m16i
0x401070 None
0x401074 __vbaFPFix
0x401078 _CIsin
0x40107c __vbaChkstk
0x401080 __vbaFileClose
0x401084 EVENT_SINK_AddRef
0x401088 None
0x40108c None
0x401090 DllFunctionCall
0x401094 _adj_fpatan
0x401098 __vbaStrR8
0x40109c EVENT_SINK_Release
0x4010a0 None
0x4010a4 _CIsqrt
0x4010a8 __vbaObjIs
0x4010b0 __vbaExceptHandler
0x4010b4 __vbaPrintFile
0x4010b8 __vbaStrToUnicode
0x4010bc _adj_fprem
0x4010c0 _adj_fdivr_m64
0x4010c4 None
0x4010c8 None
0x4010cc None
0x4010d0 __vbaFPException
0x4010d4 __vbaInStrVar
0x4010d8 __vbaStrVarVal
0x4010dc __vbaVarCat
0x4010e0 _CIlog
0x4010e4 __vbaErrorOverflow
0x4010e8 __vbaFileOpen
0x4010ec __vbaR8Str
0x4010f4 __vbaNew2
0x4010f8 _adj_fdiv_m32i
0x4010fc _adj_fdivr_m32i
0x401100 __vbaStrCopy
0x401104 __vbaFreeStrList
0x401108 _adj_fdivr_m32
0x40110c _adj_fdiv_r
0x401110 None
0x401114 None
0x401118 __vbaVarTstNe
0x40111c __vbaVarSetVar
0x401120 __vbaVarAdd
0x401124 __vbaVarDup
0x401128 __vbaStrToAnsi
0x401130 __vbaUnkVar
0x401134 __vbaVarCopy
0x401138 __vbaFpI4
0x401140 __vbaR8IntI2
0x401144 _CIatan
0x401148 __vbaStrMove
0x40114c __vbaForEachVar
0x401150 None
0x401154 _allmul
0x401158 _CItan
0x40115c None
0x401160 __vbaAryUnlock
0x401164 __vbaVarForNext
0x401168 _CIexp
0x40116c __vbaFreeObj
0x401170 __vbaFreeStr

!This program cannot be run in DOS mode.
`.data
MSVBVM60.DLL
Picture1
vb6chs.dll
Module1
C:\Program Files (x86)\Microsoft Visual Studio\VB98\VB6.OLB
Picture1
shell32.dll
ShellExecuteA
urlmon
URLDownloadToFileA
shlwapi.dll
PathFileExistsA
user32
keybd_event
SystemParametersInfoA
FindWindowA
IsWindowVisible
IsIconic
kernel32
CreateWaitableTimerA
OpenWaitableTimerA
SetWaitableTimer
CancelWaitableTimer
CloseHandle
WaitForSingleObject
MsgWaitForMultipleObjects
hKm0R(u7b{vF
VBA6.DLL
__vbaObjSetAddref
__vbaVarAdd
__vbaStrToUnicode
__vbaVarForNext
__vbaFpI4
__vbaStrVarMove
__vbaVarForInit
__vbaR8IntI2
__vbaStrVarVal
__vbaVarCat
__vbaOnError
__vbaEnd
__vbaFreeStr
__vbaPrintFile
__vbaVarTstGt
__vbaFileClose
__vbaStrCat
__vbaLineInputVar
__vbaFileOpen
__vbaFreeObjList
__vbaNew2
__vbaStrI2
__vbaStrMove
__vbaFreeStrList
__vbaSetSystemError
__vbaStrToAnsi
__vbaStrCopy
__vbaVarCopy
__vbaVarMove
__vbaNextEachVar
__vbaVarTstNe
__vbaHresultCheckObj
__vbaFreeVar
__vbaFreeObj
__vbaAryUnlock
__vbaExitProc
__vbaVarSetObjAddref
__vbaUnkVar
__vbaObjIs
__vbaVarLateMemCallLdRf
__vbaInStrVar
__vbaForEachVar
__vbaVarLateMemCallLd
__vbaFreeVarList
__vbaVarDup
__vbaVarSetVar
__vbaErrorOverflow
__vbaStrR8
__vbaR8Str
__vbaFPFix
__vbaObjSet
jLh$=@
j$h$=@
j,h$=@
jDh$=@
MSVBVM60.DLL
__vbaVarTstGt
__vbaStrI2
_CIcos
_adj_fptan
__vbaVarMove
__vbaFreeVar
__vbaStrVarMove
__vbaFreeVarList
__vbaEnd
_adj_fdiv_m64
__vbaNextEachVar
__vbaFreeObjList
__vbaLineInputVar
_adj_fprem1
__vbaStrCat
__vbaSetSystemError
__vbaHresultCheckObj
_adj_fdiv_m32
__vbaExitProc
__vbaVarForInit
__vbaObjSet
__vbaOnError
_adj_fdiv_m16i
__vbaObjSetAddref
_adj_fdivr_m16i
__vbaFPFix
_CIsin
__vbaChkstk
__vbaFileClose
EVENT_SINK_AddRef
DllFunctionCall
_adj_fpatan
__vbaStrR8
EVENT_SINK_Release
_CIsqrt
__vbaObjIs
EVENT_SINK_QueryInterface
__vbaExceptHandler
__vbaPrintFile
__vbaStrToUnicode
_adj_fprem
_adj_fdivr_m64
__vbaFPException
__vbaInStrVar
__vbaStrVarVal
__vbaVarCat
_CIlog
__vbaErrorOverflow
__vbaFileOpen
__vbaR8Str
__vbaVarLateMemCallLdRf
__vbaNew2
_adj_fdiv_m32i
_adj_fdivr_m32i
__vbaStrCopy
__vbaFreeStrList
_adj_fdivr_m32
_adj_fdiv_r
__vbaVarTstNe
__vbaVarSetVar
__vbaVarAdd
__vbaVarDup
__vbaStrToAnsi
__vbaVarLateMemCallLd
__vbaUnkVar
__vbaVarCopy
__vbaFpI4
__vbaVarSetObjAddref
__vbaR8IntI2
_CIatan
__vbaStrMove
__vbaForEachVar
_allmul
_CItan
__vbaAryUnlock
__vbaVarForNext
_CIexp
__vbaFreeObj
__vbaFreeStr
@*\AD:\vbfiles\
\xww.vbp
WinMgmts:
Win32_Process
InstancesOf
Description
Wscript.Shell
scripting.filesystemobject
C:\Windows\system\netbar.exe
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\Desktop
RegRead
drives
HKLM\SYSTEM\CurrentControlSet\superadmin
HKLM\SYSTEM\CurrentControlSet\iCafe8\admin
Z:\NBMSClient\BarClientTask.exe
HKLM\SYSTEM\CurrentControlSet\zhaohuan\admin
HKLM\SYSTEM\CurrentControlSet\services\client start\start
C:\Program Files (x86)\HintSoft\PubwinClient\PubwinClient.exe
c:\windows\syswow64\clsmn.exe
Z:\NBMSClient\BarClientView.exe
z:\app\bd.ini
c:\windows\svchost.exe
c:\windows\syswow64\cltupdate.exe
c:\windows\syswow64\cltupdate.exeback
z:\app\pubwinol\cltupdate.exe
y:\app\pubwinol\cltupdate.exe
x:\app\pubwinol\cltupdate.exe
z:\app\pubwinol\clsmn.exe
y:\app\pubwinol\clsmn.exe
x:\app\pubwinol\clsmn.exe
c:\windows\syswow64\clsmn.exeback
z:\app\xwbgj7\xwbgj.exe
http://safe.ywxww.net:820/wbgj.txt
c:\windows\wbgj.txt
http://safe.ywxww.net:820/wbgjupdate.exe
c:\windows\wbgjupdate.exe
c:\windows\fn.txt
c:\windows\fp.txt
c:\windows\ywlog.tmp
c:\windows\syswow64\
\xconfig.ini
http://safe.ywxww.net:820/svchost.exe
http://safe.ywxww.net:820/xconfig.txt
pubwin ol
taskkill /f /IM "xwbgj.exe"
[clsWaitableTimer.Wait]
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
080404B0
CompanyName
ProductName
FileVersion
1.00.0006
ProductVersion
1.00.0006
InternalName
OriginalFilename
wbgjn.exe
Antivirus Signature
Bkav Clean
Lionic Trojan.Win32.Gofot.4!c
Elastic malicious (high confidence)
ClamAV Clean
CMC Clean
CAT-QuickHeal Clean
Skyhigh BehavesLike.Win32.Infected.nt
ALYac Gen:Variant.Lazy.547037
Cylance Unsafe
Zillya Trojan.VBAGen.Win32.597
CrowdStrike win/malicious_confidence_100% (W)
Alibaba TrojanDownloader:Win32/Gofot.8fa67e00
K7GW Trojan ( 00508f6f1 )
K7AntiVirus Trojan ( 00508f6f1 )
huorong HVM:TrojanDownloader/Small.Gen!D
Baidu Clean
VirIT Trojan.Win32.VBGenus.GVG
Symantec ML.Attribute.HighConfidence
tehtris Clean
ESET-NOD32 a variant of Win32/VB_AGen.MB
APEX Clean
Paloalto generic.ml
Cynet Malicious (score: 99)
Kaspersky Trojan.Win32.Gofot.pvf
BitDefender Gen:Variant.Lazy.547037
NANO-Antivirus Clean
ViRobot Clean
MicroWorld-eScan Gen:Variant.Lazy.547037
Tencent Win32.Trojan.Gofot.Qgil
Sophos Mal/Generic-S
F-Secure Trojan.TR/Dldr.Agent.sqilt
DrWeb Trojan.Siggen28.57751
VIPRE Gen:Variant.Lazy.547037
TrendMicro Mal_Banld-5
McAfeeD ti!64371330067E
Trapmine suspicious.low.ml.score
CTX exe.trojan.gofot
Emsisoft Gen:Variant.Lazy.547037 (B)
Ikarus Trojan.NewHeur_VB_Downloader
FireEye Generic.mg.4c899595ed9f2849
Jiangmin Trojan.Gofot.bgu
Webroot Clean
Varist Clean
Avira TR/Dldr.Agent.sqilt
Fortinet W32/Mal_Banld.5!tr
Antiy-AVL Trojan/Win32.Gofot
Kingsoft Win32.Troj.Unknown.a
Gridinsoft Clean
Xcitium Malware@#2wk161kxme428
Arcabit Trojan.Lazy.D858DD
SUPERAntiSpyware Clean
ZoneAlarm Trojan.Win32.Gofot.pvf
Microsoft TrojanDownloader:Win32/Small.gen!F
Google Detected
AhnLab-V3 Malware/Win.Banld.R427983
Acronis Clean
McAfee Artemis!4C899595ED9F
TACHYON Clean
VBA32 BScope.Backdoor.VB
Malwarebytes Generic.Malware/Suspicious
Panda Trj/GdSda.A
Zoner Clean
TrendMicro-HouseCall Mal_Banld-5
Rising Downloader.Small!8.B41 (CLOUD)
Yandex Clean
SentinelOne Clean
MaxSecure Trojan.Malware.1728101.susgen
GData Gen:Variant.Lazy.547037
AVG Win32:Trojan-gen
Avast Win32:Trojan-gen
alibabacloud Trojan[downloader]:Win/Gofot.pmj
No IRMA results available.