Static | ZeroBOX

PE Compile Time

2019-06-10 21:31:49

PE Imphash

fb7c144ac94c7da0fce62e3df10c5951

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x00004a54 0x00005000 5.30831667542
.data 0x00006000 0x00000ad0 0x00001000 0.0
.rsrc 0x00007000 0x00000e1c 0x00001000 3.61087881941

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x000073a8 0x00000a74 LANG_NEUTRAL SUBLANG_NEUTRAL dBase III DBT, version number 0, next free block index 40
RT_GROUP_ICON 0x00007394 0x00000014 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_VERSION 0x000070f0 0x000002a4 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data

Imports

Library MSVBVM60.DLL:
0x401000 __vbaVarTstGt
0x401004 __vbaStrI2
0x401008 _CIcos
0x40100c _adj_fptan
0x401010 __vbaVarMove
0x401014 __vbaFreeVar
0x401018 __vbaFreeVarList
0x40101c __vbaEnd
0x401020 _adj_fdiv_m64
0x401024 __vbaNextEachVar
0x401028 __vbaFreeObjList
0x40102c __vbaLineInputVar
0x401030 _adj_fprem1
0x401034 None
0x401038 __vbaStrCat
0x40103c __vbaSetSystemError
0x401044 _adj_fdiv_m32
0x401048 __vbaExitProc
0x40104c __vbaObjSet
0x401050 __vbaOnError
0x401054 _adj_fdiv_m16i
0x401058 _adj_fdivr_m16i
0x40105c None
0x401060 __vbaFPFix
0x401064 __vbaBoolVarNull
0x401068 _CIsin
0x40106c __vbaChkstk
0x401070 __vbaFileClose
0x401074 EVENT_SINK_AddRef
0x401078 None
0x40107c None
0x401080 __vbaObjVar
0x401084 DllFunctionCall
0x401088 _adj_fpatan
0x40108c __vbaStrR8
0x401090 EVENT_SINK_Release
0x401094 None
0x401098 _CIsqrt
0x40109c __vbaObjIs
0x4010a4 __vbaExceptHandler
0x4010a8 __vbaPrintFile
0x4010ac _adj_fprem
0x4010b0 _adj_fdivr_m64
0x4010b4 None
0x4010b8 None
0x4010bc __vbaFPException
0x4010c0 __vbaInStrVar
0x4010c4 __vbaVarCat
0x4010c8 _CIlog
0x4010cc __vbaErrorOverflow
0x4010d0 __vbaFileOpen
0x4010d4 __vbaR8Str
0x4010dc __vbaNew2
0x4010e0 _adj_fdiv_m32i
0x4010e4 _adj_fdivr_m32i
0x4010e8 __vbaFreeStrList
0x4010ec _adj_fdivr_m32
0x4010f0 _adj_fdiv_r
0x4010f4 None
0x4010f8 None
0x4010fc __vbaVarTstNe
0x401100 __vbaVarSetVar
0x401104 __vbaLateMemCall
0x401108 __vbaVarDup
0x40110c __vbaStrToAnsi
0x401110 __vbaFpI4
0x401118 __vbaUnkVar
0x40111c __vbaVarCopy
0x401124 _CIatan
0x401128 __vbaStrMove
0x40112c __vbaForEachVar
0x401130 None
0x401134 _allmul
0x401138 _CItan
0x40113c None
0x401140 __vbaAryUnlock
0x401144 _CIexp
0x401148 __vbaFreeObj
0x40114c __vbaFreeStr

!This program cannot be run in DOS mode.
`.data
MSVBVM60.DLL
vb6chs.dll
Module1
C:\Program Files (x86)\Microsoft Visual Studio\VB98\VB6.OLB
shell32.dll
ShellExecuteA
urlmon
URLDownloadToFileA
shlwapi.dll
PathFileExistsA
kernel32
DeleteFileA
CreateWaitableTimerA
OpenWaitableTimerA
SetWaitableTimer
CancelWaitableTimer
CloseHandle
WaitForSingleObject
user32
MsgWaitForMultipleObjects
VBA6.DLL
__vbaObjVar
__vbaLateMemCall
__vbaVarCat
__vbaBoolVarNull
__vbaVarCopy
__vbaEnd
__vbaFreeStr
__vbaPrintFile
__vbaVarTstGt
__vbaFileClose
__vbaLineInputVar
__vbaFileOpen
__vbaFreeObjList
__vbaNew2
__vbaStrI2
__vbaStrMove
__vbaStrCat
__vbaFreeVar
__vbaFreeStrList
__vbaSetSystemError
__vbaStrToAnsi
__vbaVarMove
__vbaHresultCheckObj
__vbaFreeObj
__vbaAryUnlock
__vbaExitProc
__vbaNextEachVar
__vbaVarSetObjAddref
__vbaUnkVar
__vbaVarLateMemCallLd
__vbaObjIs
__vbaVarLateMemCallLdRf
__vbaInStrVar
__vbaVarTstNe
__vbaForEachVar
__vbaFreeVarList
__vbaVarDup
__vbaVarSetVar
__vbaOnError
__vbaErrorOverflow
__vbaStrR8
__vbaR8Str
__vbaFPFix
__vbaFpI4
__vbaObjSet
} jThl&@
}#jXhd,@
}#jPhd,@
jXhd,@
jLhp3@
j$hp3@
j,hp3@
jDhp3@
MSVBVM60.DLL
__vbaVarTstGt
__vbaStrI2
_CIcos
_adj_fptan
__vbaVarMove
__vbaFreeVar
__vbaFreeVarList
__vbaEnd
_adj_fdiv_m64
__vbaNextEachVar
__vbaFreeObjList
__vbaLineInputVar
_adj_fprem1
__vbaStrCat
__vbaSetSystemError
__vbaHresultCheckObj
_adj_fdiv_m32
__vbaExitProc
__vbaObjSet
__vbaOnError
_adj_fdiv_m16i
_adj_fdivr_m16i
__vbaFPFix
__vbaBoolVarNull
_CIsin
__vbaChkstk
__vbaFileClose
EVENT_SINK_AddRef
__vbaObjVar
DllFunctionCall
_adj_fpatan
__vbaStrR8
EVENT_SINK_Release
_CIsqrt
__vbaObjIs
EVENT_SINK_QueryInterface
__vbaExceptHandler
__vbaPrintFile
_adj_fprem
_adj_fdivr_m64
__vbaFPException
__vbaInStrVar
__vbaVarCat
_CIlog
__vbaErrorOverflow
__vbaFileOpen
__vbaR8Str
__vbaVarLateMemCallLdRf
__vbaNew2
_adj_fdiv_m32i
_adj_fdivr_m32i
__vbaFreeStrList
_adj_fdivr_m32
_adj_fdiv_r
__vbaVarTstNe
__vbaVarSetVar
__vbaLateMemCall
__vbaVarDup
__vbaStrToAnsi
__vbaFpI4
__vbaVarLateMemCallLd
__vbaUnkVar
__vbaVarCopy
__vbaVarSetObjAddref
_CIatan
__vbaStrMove
__vbaForEachVar
_allmul
_CItan
__vbaAryUnlock
_CIexp
__vbaFreeObj
__vbaFreeStr
@*\AH:\vbfiles\bx525\
WinMgmts:
Win32_Process
InstancesOf
Description
RunDll32.exe InetCpl.cpl,ClearMyTracksByProcess 8
http://safe.ywxww.net:820/bx.txt
c:\windows\bx.txt
http://safe.ywxww.net:820/bxupdate.exe
c:\windows\bxupdate.exe
c:\windows\fn.txt
c:\windows\fp.txt
scripting.filesystemobject
c:\chrome\360chrome.exe
x:\xww\360chrome\360chrome.exe
\360chrome\chrome\Application\360chrome.exe
y:\xww\360chrome\360chrome.exe
\360chrome\chrome\Application\360chrome.exe
z:\xww\360chrome\360chrome.exe
\360chrome\chrome\Application\360chrome.exe
https://icafe8.kf5.com/kchat/1011049
FileExists
explorer.exe
[clsWaitableTimer.Wait]
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
080404B0
Comments
CompanyName
ProductName
FileVersion
1.01.0006
ProductVersion
1.01.0006
InternalName
OriginalFilename
Antivirus Signature
Bkav W32.AIDetectMalware
Lionic Trojan.Win32.Generic.4!c
Elastic malicious (moderate confidence)
ClamAV Clean
CMC Clean
CAT-QuickHeal Trojan.Occamy
Skyhigh BehavesLike.Win32.Infected.nt
ALYac Trojan.GenericKD.74630630
Cylance Unsafe
Zillya Downloader.Generic.Win32.9510
CrowdStrike win/malicious_confidence_100% (W)
Alibaba TrojanDownloader:Win32/NewHeur.81fe4d49
K7GW Trojan ( 0050df7f1 )
K7AntiVirus Trojan ( 0050df7f1 )
huorong HVM:TrojanDownloader/Small.Gen!D
Baidu Clean
VirIT Clean
Paloalto generic.ml
Symantec ML.Attribute.HighConfidence
tehtris Clean
ESET-NOD32 Clean
APEX Clean
Avast Win32:Trojan-gen
Cynet Malicious (score: 99)
Kaspersky Clean
BitDefender Trojan.GenericKD.74630630
NANO-Antivirus Trojan.Win32.Razy.gwfsre
ViRobot Clean
MicroWorld-eScan Trojan.GenericKD.74630630
Tencent Clean
Sophos Mal/Generic-S
F-Secure Trojan.TR/Dldr.Agent.dpmsk
DrWeb Trojan.DownLoader32.51971
VIPRE Trojan.GenericKD.74630630
TrendMicro TROJ_FRS.0NA103FE24
McAfeeD ti!D121605217CF
Trapmine Clean
CTX exe.trojan.generic
Emsisoft Trojan.GenericKD.74630630 (B)
Ikarus Trojan.NewHeur_VB_Downloader
FireEye Trojan.GenericKD.74630630
Jiangmin TrojanDownloader.Generic.bffd
Webroot Clean
Varist Clean
Avira TR/Dldr.Agent.dpmsk
Fortinet PossibleThreat.MU
Antiy-AVL Trojan[Downloader]/Win32.AGeneric
Kingsoft Win32.HeurC.KVM006.a
Gridinsoft Trojan.Win32.Agent.vb!s1
Xcitium Malware@#3ejqz7cp0yi2f
Arcabit Trojan.Generic.D472C5E6
SUPERAntiSpyware Clean
ZoneAlarm Clean
Microsoft Trojan:Win32/Occamy.CD1
Google Detected
AhnLab-V3 Clean
Acronis Clean
McAfee Artemis!63399C74C5DD
TACHYON Clean
VBA32 Trojan.Downloader
Malwarebytes Malware.AI.3848828270
Panda Trj/GdSda.A
Zoner Clean
TrendMicro-HouseCall TROJ_FRS.0NA103FE24
Rising Downloader.Generic!8.141 (CLOUD)
Yandex Clean
SentinelOne Clean
MaxSecure Trojan.Malware.7175239.susgen
GData Trojan.GenericKD.74630630
AVG Win32:Trojan-gen
DeepInstinct MALICIOUS
alibabacloud Clean
No IRMA results available.