Static | ZeroBOX

PE Compile Time

2017-04-03 14:35:00

PE Imphash

82f3154e4b314b6810b189c7a61b6a27

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x0001af68 0x0001b000 5.09521584692
.data 0x0001c000 0x00000a30 0x00001000 0.0
.rsrc 0x0001d000 0x0000671c 0x00007000 5.49730093742

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x0001d534 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x0001d534 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x0001d534 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x0001d534 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x0001d534 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x0001d534 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x0001d534 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x0001d534 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x0001d534 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_GROUP_ICON 0x0001d4b0 0x00000084 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_VERSION 0x0001d270 0x00000240 LANG_ENGLISH SUBLANG_ENGLISH_US data

Imports

Library MSVBVM60.DLL:
0x401000 _CIcos
0x401004 _adj_fptan
0x401008 None
0x40100c __vbaVarMove
0x401010 __vbaStrI4
0x401014 __vbaFreeVar
0x401018 __vbaStrVarMove
0x40101c None
0x401020 __vbaFreeVarList
0x401024 _adj_fdiv_m64
0x401028 __vbaFreeObjList
0x40102c _adj_fprem1
0x401034 None
0x401038 _adj_fdiv_m32
0x40103c __vbaAryDestruct
0x401040 __vbaLateMemSt
0x401044 __vbaObjSet
0x401048 __vbaOnError
0x40104c None
0x401050 _adj_fdiv_m16i
0x401054 __vbaObjSetAddref
0x401058 _adj_fdivr_m16i
0x40105c __vbaVarTstLt
0x401060 _CIsin
0x401064 __vbaErase
0x401068 None
0x40106c __vbaChkstk
0x401070 EVENT_SINK_AddRef
0x401074 __vbaStrCmp
0x401078 __vbaVarTstEq
0x40107c __vbaObjVar
0x401080 _adj_fpatan
0x401084 __vbaLateIdCallLd
0x401088 __vbaRedim
0x40108c EVENT_SINK_Release
0x401090 _CIsqrt
0x401098 __vbaExceptHandler
0x40109c _adj_fprem
0x4010a0 _adj_fdivr_m64
0x4010a4 None
0x4010a8 __vbaFPException
0x4010ac None
0x4010b0 None
0x4010b4 None
0x4010b8 _CIlog
0x4010bc __vbaNew2
0x4010c0 _adj_fdiv_m32i
0x4010c4 _adj_fdivr_m32i
0x4010c8 __vbaStrCopy
0x4010cc __vbaI4Str
0x4010d0 _adj_fdivr_m32
0x4010d4 _adj_fdiv_r
0x4010d8 None
0x4010dc __vbaVarTstNe
0x4010e0 __vbaI4Var
0x4010e4 None
0x4010e8 __vbaVarAdd
0x4010ec __vbaVarDup
0x4010f0 None
0x4010f4 __vbaLateMemCallLd
0x4010f8 None
0x4010fc _CIatan
0x401100 __vbaStrMove
0x401104 __vbaCastObj
0x401108 _allmul
0x40110c _CItan
0x401110 _CIexp
0x401114 __vbaFreeObj
0x401118 __vbaFreeStr

!This program cannot be run in DOS mode.
`.data
MSVBVM60.DLL
PERITONSILLITISINS
Phosphorescentsys9
Seksperson8
wxxxxwxy
xxxxwy
:9:9^5
---111
:^a^15
~~~5JG@
Seksperson8
Command3
helleboresamara
Command2
Cosierstrmhvir7
Command1
buttleakkiless
Check1
PRECAPILLARYC
Check2
Conjuncturestil
Check3
Embedsperiodenopd7
Check4
burnwoodhanga
PicBox
A4)M-F6
7J2;_w7
.w3=KAMqY
w3>ItZ
^j>P,O
?W{P!d
b24kXm
yI4RNZJ
.aaaaaaaaaaaaaaaaaaaaaaaaaaa
???????????????????????
~||||||||||||||||||||||||
:5555555555555555555555
qqqqqqqqqqqqqqqqqqqqqqqqq
NNNNNNNNNNNNNNNNNNNNNNNN
@--------------------------------
$$$$$$$$$$$$$$$$$$$$$$$$
{{{{{{{{{{{{{{{{{{{{{{{{{{{
BVE```````````````````````````````
iiiiiiiiiiiiiiiiiiiii
Keeeeeeeeeeeeeeeeeeeeeeeeeeeeee
5!OOOOOOOOOOOOOOOOOOOOO
}>>>>>>>>>>>>>>>>>>>>>>>>>>>
2))))))))))))))))))))))))))
9999999999999999999999999
m###########################
5log[[[[[[[[[[[[[[[[[[[[[[[[[[[[
CCCCCCCCCCCCCCCCCCCCCCCCCC
ZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZ
888888888888888888888888888
&:::::::::::::::::::::
{uuuuuuuuuuuuuuuuuuuuuuuuuuuu
&..........................
jjjjjjjjjjjjjjjjjjjjjjjjjjjjj
mCvvvvvvvvvvvvvvvvvvvvvvvv
gJJJJJJJJJJJJJJJJJJJJJJJJJJJJ
9Y ZZZZZZZZZZZZZZZZZZZZZZZZZZ
DDDDDDDDDDDDDDDDDDDDDDDDDDDDD
z{)))))))))))))))))))))
Q||||||||||||||||||||||||||||||
Y_t////////////////////////////////
w
KG{{{{{{{{{{{{{{{{{{{{{S
9[[[[[[[[[[[[[[[[[[[[[[
OOOOOOOOOOOOOOOOOOOOOOOOOOO
P%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%
=@$$$$$$$$$$$$$$$$$$$$$
w}}}}}}}}}}}}}}}}}}}}}}}}}}
{llllllllllllllllllllllllllllllll
ggggggggggggggggggggg
Fwwwwwwwwwwwwwwwwwwwwwwwwwwwwww
&^EOOOOOOOOOOOOOOOOOOOOOOOOOOOOOO
DDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDD
aaaaaaaaaaaaaaaaaaaaa
UFFFFFFFFFFFFFFFFFFFFFFFFF
PPPPPPPPPPPPPPPPPPPPPPPPPPP
GLLLLLLLLLLLLLLLLLLLLLLLL1
hvvvvvvvvvvvvvvvvvvvvvv
`l666666666666666666666666666
B$$$$$$$$$$$$$$$$$$$$$
--
VB5!6&*
muddledordkl
PERITONSILLITISINS
PERITONSILLITISINS
PERITONSILLITISINS
Phosphorescentsys9
PicBox
C:\Program Files (x86)\Microsoft Visual Studio\VB98\VB6.OLB
Command1
Check1
Command3
Command2
Check2
Check4
Check3
Trampoline
overmtningers
Untasteable
sinologen
opblandedes
luftrumsorganisationerne
TILLGSMAADES
STREPTASTER
VBA6.DLL
__vbaAryDestruct
__vbaStrI4
__vbaOnError
__vbaVarTstLt
__vbaVarAdd
__vbaI4Var
__vbaStrVarMove
__vbaLateIdCallLd
__vbaErase
__vbaVarMove
__vbaRedim
__vbaCastObj
__vbaFreeObjList
__vbaVarTstNe
__vbaI4Str
__vbaStrCmp
__vbaVarDup
__vbaStrCopy
__vbaFreeVarList
__vbaVarTstEq
__vbaObjSet
__vbaLateMemSt
__vbaFreeVar
__vbaLateMemCallLd
__vbaObjVar
__vbaObjSetAddref
__vbaFreeStr
__vbaFreeObj
__vbaHresultCheckObj
__vbaNew2
__vbaStrMove
Ciffernglen8
Sedimetric7
Lichenous3
Mrkerdes6
Wordings
Digtningens
Undtagen
MILLILITEREN
EREMITKREBSENE
Amplificate
Agglutineringers9
NAVNEMAADE
KVADRATRDDERS
Lemmer3
Filmfronten3
Fangedragternes
EFTERHAANDSOPLYSNINGEN
SPEKTROGRAMMERNES
Arbejdslederens
underbough
Tonguey2
OMLAGDES
Elvrksarbejderes
korfitz
guldsnor
LINEAR
skrddererer
Biophysics
Overfluent
Underutilization9
Bydelsordningen2
Bragite9
Filippas
Bdernes
ZELOTEN
Allegros
Semipacifist
AMNINGSMRKERS
Tintallerkners9
GIRLIES
Bekmpelsernes5
Dieters3
NONSUBSTITUTIONALLY
SHEEPBERRIES
Opsummeres
Nonacquisitiveness2
Elleveaarsbarnets
Brefrekvenss8
VINTERGK
stukkatren
Sunrooms
Saccharimetre
MSVBVM60.DLL
_CIcos
_adj_fptan
__vbaVarMove
__vbaStrI4
__vbaFreeVar
__vbaStrVarMove
__vbaFreeVarList
_adj_fdiv_m64
__vbaFreeObjList
_adj_fprem1
__vbaHresultCheckObj
_adj_fdiv_m32
__vbaAryDestruct
__vbaLateMemSt
__vbaObjSet
__vbaOnError
_adj_fdiv_m16i
__vbaObjSetAddref
_adj_fdivr_m16i
__vbaVarTstLt
_CIsin
__vbaErase
__vbaChkstk
EVENT_SINK_AddRef
__vbaStrCmp
__vbaVarTstEq
__vbaObjVar
_adj_fpatan
__vbaLateIdCallLd
__vbaRedim
EVENT_SINK_Release
_CIsqrt
EVENT_SINK_QueryInterface
__vbaExceptHandler
_adj_fprem
_adj_fdivr_m64
__vbaFPException
_CIlog
__vbaNew2
_adj_fdiv_m32i
_adj_fdivr_m32i
__vbaStrCopy
__vbaI4Str
_adj_fdivr_m32
_adj_fdiv_r
__vbaVarTstNe
__vbaI4Var
__vbaVarAdd
__vbaVarDup
__vbaLateMemCallLd
_CIatan
__vbaStrMove
__vbaCastObj
_allmul
_CItan
_CIexp
__vbaFreeObj
__vbaFreeStr
~~~5JG@
:9:9^5
---111
:^a^15
wxxxxwxy
xxxxwy
VB.VscrollBar
bombepanik
Visible
VB.PictureBox
MISFOSTRETS
Enabled
Berejsningens
Burelage
untrying
Nonnitrous
Jalousiskabenes
Annmari4
UDVIKLINGSOPGAVE
indsuger
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
040904B0
Comments
Techy Fighters
ProductName
PERITONSILLITISINS
FileVersion
ProductVersion
InternalName
muddledordkl
OriginalFilename
muddledordkl.exe
Antivirus Signature
Bkav W32.AIDetect.malware2
Elastic Clean
MicroWorld-eScan Clean
CMC Clean
CAT-QuickHeal Clean
McAfee Artemis!50779DF62449
Cylance Clean
VIPRE Clean
AegisLab Clean
Sangfor Trojan.Win32.Save.a
K7AntiVirus Clean
BitDefender Clean
K7GW Clean
Cybereason malicious.5665ae
Baidu Clean
Cyren Clean
Symantec Clean
TotalDefense Clean
APEX Malicious
Avast Win32:Malware-gen
ClamAV Clean
Kaspersky UDS:DangerousObject.Multi.Generic
Alibaba Trojan:Win32/vbcrypt.ali2000008
NANO-Antivirus Clean
ViRobot Clean
Rising Trojan.Kryptik!8.8 (CLOUD)
Ad-Aware Clean
Emsisoft Clean
Comodo Clean
F-Secure Clean
DrWeb Clean
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition BehavesLike.Win32.Fareit.cm
FireEye Generic.mg.50779df624494704
Sophos Clean
Ikarus Trojan.VB.Crypt
GData Win32.Trojan-Downloader.GuLoader.V90Z90
MaxSecure Clean
Avira Clean
MAX Clean
Antiy-AVL Clean
Kingsoft Clean
Gridinsoft Clean
Arcabit Clean
SUPERAntiSpyware Clean
AhnLab-V3 Clean
ZoneAlarm Clean
Microsoft Trojan:Win32/Wacatac.B!ml
Cynet Malicious (score: 100)
ESET-NOD32 Clean
Acronis Clean
BitDefenderTheta Gen:NN.ZevbaF.34608.jm0@aqatxDmi
ALYac Clean
TACHYON Clean
VBA32 Clean
Malwarebytes Clean
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Tencent Clean
Yandex Clean
SentinelOne Static AI - Suspicious PE
eGambit Clean
Fortinet W32/Kryptik.EOVV!tr
Webroot Clean
AVG Win32:Malware-gen
Paloalto generic.ml
CrowdStrike win/malicious_confidence_70% (W)
Qihoo-360 Win32/Heur.Generic.HwMA7fsA
No IRMA results available.