Malicious
Classifications
Keylogger Injector Spyware
Threat Names
Mal/Generic-S
Dynamic Analysis Report
Created on 2022-08-05T08:07:52+00:00
6731f235ff78e22e5a0f1503542926bb707a95251b8cbd22c56fbd7fc5a8cbbf.exe
Windows Exe (x86-32)
Remarks (1/1)
(0x0200000E): The overall sleep time of all monitored processes was truncated from "3 days, 5 hours, 2 minutes, 51 seconds" to "2 minutes, 16 seconds" to reveal dormant functionality.
This is a filtered view
This list contains only the embedded files, downloaded files, and dropped files
Filters: |
There are no files for this filter
There are no files in this analysis
File Name | Category | Type | Verdict | Actions |
---|
c:\users\rdhj0cnfevzx\desktop\6731f235ff78e22e5a0f1503542926bb707a95251b8cbd22c56fbd7fc5a8cbbf.exe | Sample File | Binary |
Malicious
|
...
|
»
File Reputation Information
»
Verdict |
Malicious
|
Names | Mal/Generic-S |
PE Information
»
Image Base | 0x00400000 |
Entry Point | 0x00403670 |
Size Of Code | 0x0002B000 |
Size Of Initialized Data | 0x00003000 |
File Type | IMAGE_FILE_EXECUTABLE_IMAGE |
Subsystem | IMAGE_SUBSYSTEM_WINDOWS_GUI |
Machine Type | IMAGE_FILE_MACHINE_I386 |
Compile Timestamp | 2011-06-14 21:01 (UTC+2) |
Version Information (6)
»
CompanyName | Microsoft |
ProductName | Win |
FileVersion | 1.00 |
ProductVersion | 1.00 |
InternalName | Win |
OriginalFilename | Win.exe |
Sections (4)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x00401000 | 0x0002A728 | 0x0002B000 | 0x00001000 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 5.95 |
.data | 0x0042C000 | 0x00001B74 | 0x00001000 | 0x0002C000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.0 |
.rsrc | 0x0042E000 | 0x000005E0 | 0x00001000 | 0x0002D000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 1.69 |
.tdata | 0x0042F000 | 0x0000F000 | 0x0000F000 | 0x0002E000 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.0 |
Imports (1)
»
MSVBVM60.DLL (160)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
EVENT_SINK_GetIDsOfNames | - | 0x00401000 | 0x0002ACAC | 0x0002ACAC | 0x00000000 |
__vbaStrI2 | - | 0x00401004 | 0x0002ACB0 | 0x0002ACB0 | 0x00000000 |
None | 0x000002B2 | 0x00401008 | 0x0002ACB4 | 0x0002ACB4 | - |
_CIcos | - | 0x0040100C | 0x0002ACB8 | 0x0002ACB8 | 0x00000000 |
_adj_fptan | - | 0x00401010 | 0x0002ACBC | 0x0002ACBC | 0x00000000 |
__vbaStrI4 | - | 0x00401014 | 0x0002ACC0 | 0x0002ACC0 | 0x00000000 |
__vbaVarVargNofree | - | 0x00401018 | 0x0002ACC4 | 0x0002ACC4 | 0x00000000 |
__vbaFreeVar | - | 0x0040101C | 0x0002ACC8 | 0x0002ACC8 | 0x00000000 |
__vbaStrVarMove | - | 0x00401020 | 0x0002ACCC | 0x0002ACCC | 0x00000000 |
__vbaLenBstr | - | 0x00401024 | 0x0002ACD0 | 0x0002ACD0 | 0x00000000 |
__vbaLateIdCall | - | 0x00401028 | 0x0002ACD4 | 0x0002ACD4 | 0x00000000 |
__vbaPut3 | - | 0x0040102C | 0x0002ACD8 | 0x0002ACD8 | 0x00000000 |
__vbaEnd | - | 0x00401030 | 0x0002ACDC | 0x0002ACDC | 0x00000000 |
__vbaFreeVarList | - | 0x00401034 | 0x0002ACE0 | 0x0002ACE0 | 0x00000000 |
_adj_fdiv_m64 | - | 0x00401038 | 0x0002ACE4 | 0x0002ACE4 | 0x00000000 |
__vbaPut4 | - | 0x0040103C | 0x0002ACE8 | 0x0002ACE8 | 0x00000000 |
EVENT_SINK_Invoke | - | 0x00401040 | 0x0002ACEC | 0x0002ACEC | 0x00000000 |
__vbaRaiseEvent | - | 0x00401044 | 0x0002ACF0 | 0x0002ACF0 | 0x00000000 |
__vbaFreeObjList | - | 0x00401048 | 0x0002ACF4 | 0x0002ACF4 | 0x00000000 |
None | 0x00000204 | 0x0040104C | 0x0002ACF8 | 0x0002ACF8 | - |
__vbaStrErrVarCopy | - | 0x00401050 | 0x0002ACFC | 0x0002ACFC | 0x00000000 |
None | 0x00000205 | 0x00401054 | 0x0002AD00 | 0x0002AD00 | - |
_adj_fprem1 | - | 0x00401058 | 0x0002AD04 | 0x0002AD04 | 0x00000000 |
__vbaRecAnsiToUni | - | 0x0040105C | 0x0002AD08 | 0x0002AD08 | 0x00000000 |
None | 0x00000207 | 0x00401060 | 0x0002AD0C | 0x0002AD0C | - |
__vbaCopyBytes | - | 0x00401064 | 0x0002AD10 | 0x0002AD10 | 0x00000000 |
__vbaStrCat | - | 0x00401068 | 0x0002AD14 | 0x0002AD14 | 0x00000000 |
__vbaLsetFixstr | - | 0x0040106C | 0x0002AD18 | 0x0002AD18 | 0x00000000 |
__vbaRecDestruct | - | 0x00401070 | 0x0002AD1C | 0x0002AD1C | 0x00000000 |
__vbaSetSystemError | - | 0x00401074 | 0x0002AD20 | 0x0002AD20 | 0x00000000 |
None | 0x00000295 | 0x00401078 | 0x0002AD24 | 0x0002AD24 | - |
__vbaHresultCheckObj | - | 0x0040107C | 0x0002AD28 | 0x0002AD28 | 0x00000000 |
__vbaNameFile | - | 0x00401080 | 0x0002AD2C | 0x0002AD2C | 0x00000000 |
_adj_fdiv_m32 | - | 0x00401084 | 0x0002AD30 | 0x0002AD30 | 0x00000000 |
__vbaAryVar | - | 0x00401088 | 0x0002AD34 | 0x0002AD34 | 0x00000000 |
Zombie_GetTypeInfo | - | 0x0040108C | 0x0002AD38 | 0x0002AD38 | 0x00000000 |
__vbaAryDestruct | - | 0x00401090 | 0x0002AD3C | 0x0002AD3C | 0x00000000 |
None | 0x0000029D | 0x00401094 | 0x0002AD40 | 0x0002AD40 | - |
None | 0x00000251 | 0x00401098 | 0x0002AD44 | 0x0002AD44 | - |
__vbaBoolStr | - | 0x0040109C | 0x0002AD48 | 0x0002AD48 | 0x00000000 |
__vbaExitProc | - | 0x004010A0 | 0x0002AD4C | 0x0002AD4C | 0x00000000 |
__vbaI4Abs | - | 0x004010A4 | 0x0002AD50 | 0x0002AD50 | 0x00000000 |
None | 0x00000252 | 0x004010A8 | 0x0002AD54 | 0x0002AD54 | - |
__vbaOnError | - | 0x004010AC | 0x0002AD58 | 0x0002AD58 | 0x00000000 |
__vbaObjSet | - | 0x004010B0 | 0x0002AD5C | 0x0002AD5C | 0x00000000 |
_adj_fdiv_m16i | - | 0x004010B4 | 0x0002AD60 | 0x0002AD60 | 0x00000000 |
__vbaObjSetAddref | - | 0x004010B8 | 0x0002AD64 | 0x0002AD64 | 0x00000000 |
_adj_fdivr_m16i | - | 0x004010BC | 0x0002AD68 | 0x0002AD68 | 0x00000000 |
None | 0x00000256 | 0x004010C0 | 0x0002AD6C | 0x0002AD6C | - |
__vbaFpR4 | - | 0x004010C4 | 0x0002AD70 | 0x0002AD70 | 0x00000000 |
None | 0x000002C1 | 0x004010C8 | 0x0002AD74 | 0x0002AD74 | - |
__vbaStrFixstr | - | 0x004010CC | 0x0002AD78 | 0x0002AD78 | 0x00000000 |
_CIsin | - | 0x004010D0 | 0x0002AD7C | 0x0002AD7C | 0x00000000 |
__vbaErase | - | 0x004010D4 | 0x0002AD80 | 0x0002AD80 | 0x00000000 |
None | 0x00000277 | 0x004010D8 | 0x0002AD84 | 0x0002AD84 | - |
None | 0x000002C5 | 0x004010DC | 0x0002AD88 | 0x0002AD88 | - |
None | 0x0000020D | 0x004010E0 | 0x0002AD8C | 0x0002AD8C | - |
__vbaChkstk | - | 0x004010E4 | 0x0002AD90 | 0x0002AD90 | 0x00000000 |
__vbaFileClose | - | 0x004010E8 | 0x0002AD94 | 0x0002AD94 | 0x00000000 |
EVENT_SINK_AddRef | - | 0x004010EC | 0x0002AD98 | 0x0002AD98 | 0x00000000 |
__vbaGenerateBoundsError | - | 0x004010F0 | 0x0002AD9C | 0x0002AD9C | 0x00000000 |
__vbaGet3 | - | 0x004010F4 | 0x0002ADA0 | 0x0002ADA0 | 0x00000000 |
__vbaStrCmp | - | 0x004010F8 | 0x0002ADA4 | 0x0002ADA4 | 0x00000000 |
None | 0x00000211 | 0x004010FC | 0x0002ADA8 | 0x0002ADA8 | - |
__vbaGet4 | - | 0x00401100 | 0x0002ADAC | 0x0002ADAC | 0x00000000 |
__vbaPutOwner3 | - | 0x00401104 | 0x0002ADB0 | 0x0002ADB0 | 0x00000000 |
__vbaVarTstEq | - | 0x00401108 | 0x0002ADB4 | 0x0002ADB4 | 0x00000000 |
__vbaAryConstruct2 | - | 0x0040110C | 0x0002ADB8 | 0x0002ADB8 | 0x00000000 |
__vbaObjVar | - | 0x00401110 | 0x0002ADBC | 0x0002ADBC | 0x00000000 |
__vbaI2I4 | - | 0x00401114 | 0x0002ADC0 | 0x0002ADC0 | 0x00000000 |
DllFunctionCall | - | 0x00401118 | 0x0002ADC4 | 0x0002ADC4 | 0x00000000 |
__vbaVarLateMemSt | - | 0x0040111C | 0x0002ADC8 | 0x0002ADC8 | 0x00000000 |
__vbaFpUI1 | - | 0x00401120 | 0x0002ADCC | 0x0002ADCC | 0x00000000 |
__vbaRedimPreserve | - | 0x00401124 | 0x0002ADD0 | 0x0002ADD0 | 0x00000000 |
__vbaStrR4 | - | 0x00401128 | 0x0002ADD4 | 0x0002ADD4 | 0x00000000 |
_adj_fpatan | - | 0x0040112C | 0x0002ADD8 | 0x0002ADD8 | 0x00000000 |
__vbaFixstrConstruct | - | 0x00401130 | 0x0002ADDC | 0x0002ADDC | 0x00000000 |
__vbaLateIdCallLd | - | 0x00401134 | 0x0002ADE0 | 0x0002ADE0 | 0x00000000 |
Zombie_GetTypeInfoCount | - | 0x00401138 | 0x0002ADE4 | 0x0002ADE4 | 0x00000000 |
__vbaRedim | - | 0x0040113C | 0x0002ADE8 | 0x0002ADE8 | 0x00000000 |
__vbaRecUniToAnsi | - | 0x00401140 | 0x0002ADEC | 0x0002ADEC | 0x00000000 |
EVENT_SINK_Release | - | 0x00401144 | 0x0002ADF0 | 0x0002ADF0 | 0x00000000 |
__vbaNew | - | 0x00401148 | 0x0002ADF4 | 0x0002ADF4 | 0x00000000 |
None | 0x00000258 | 0x0040114C | 0x0002ADF8 | 0x0002ADF8 | - |
__vbaUI1I2 | - | 0x00401150 | 0x0002ADFC | 0x0002ADFC | 0x00000000 |
_CIsqrt | - | 0x00401154 | 0x0002AE00 | 0x0002AE00 | 0x00000000 |
EVENT_SINK_QueryInterface | - | 0x00401158 | 0x0002AE04 | 0x0002AE04 | 0x00000000 |
__vbaExceptHandler | - | 0x0040115C | 0x0002AE08 | 0x0002AE08 | 0x00000000 |
None | 0x000002C7 | 0x00401160 | 0x0002AE0C | 0x0002AE0C | - |
None | 0x000002C8 | 0x00401164 | 0x0002AE10 | 0x0002AE10 | - |
__vbaStrToUnicode | - | 0x00401168 | 0x0002AE14 | 0x0002AE14 | 0x00000000 |
None | 0x0000025E | 0x0040116C | 0x0002AE18 | 0x0002AE18 | - |
_adj_fprem | - | 0x00401170 | 0x0002AE1C | 0x0002AE1C | 0x00000000 |
_adj_fdivr_m64 | - | 0x00401174 | 0x0002AE20 | 0x0002AE20 | 0x00000000 |
None | 0x000002CA | 0x00401178 | 0x0002AE24 | 0x0002AE24 | - |
None | 0x000002CC | 0x0040117C | 0x0002AE28 | 0x0002AE28 | - |
None | 0x00000261 | 0x00401180 | 0x0002AE2C | 0x0002AE2C | - |
__vbaFPException | - | 0x00401184 | 0x0002AE30 | 0x0002AE30 | 0x00000000 |
None | 0x000002CD | 0x00401188 | 0x0002AE34 | 0x0002AE34 | - |
None | 0x0000013F | 0x0040118C | 0x0002AE38 | 0x0002AE38 | - |
__vbaGetOwner3 | - | 0x00401190 | 0x0002AE3C | 0x0002AE3C | 0x00000000 |
__vbaUbound | - | 0x00401194 | 0x0002AE40 | 0x0002AE40 | 0x00000000 |
None | 0x00000217 | 0x00401198 | 0x0002AE44 | 0x0002AE44 | - |
__vbaFileSeek | - | 0x0040119C | 0x0002AE48 | 0x0002AE48 | 0x00000000 |
None | 0x00000284 | 0x004011A0 | 0x0002AE4C | 0x0002AE4C | - |
None | 0x00000219 | 0x004011A4 | 0x0002AE50 | 0x0002AE50 | - |
_CIlog | - | 0x004011A8 | 0x0002AE54 | 0x0002AE54 | 0x00000000 |
__vbaErrorOverflow | - | 0x004011AC | 0x0002AE58 | 0x0002AE58 | 0x00000000 |
__vbaFileOpen | - | 0x004011B0 | 0x0002AE5C | 0x0002AE5C | 0x00000000 |
__vbaVarLateMemCallLdRf | - | 0x004011B4 | 0x0002AE60 | 0x0002AE60 | 0x00000000 |
None | 0x00000288 | 0x004011B8 | 0x0002AE64 | 0x0002AE64 | - |
None | 0x0000023A | 0x004011BC | 0x0002AE68 | 0x0002AE68 | - |
__vbaNew2 | - | 0x004011C0 | 0x0002AE6C | 0x0002AE6C | 0x00000000 |
__vbaInStr | - | 0x004011C4 | 0x0002AE70 | 0x0002AE70 | 0x00000000 |
_adj_fdiv_m32i | - | 0x004011C8 | 0x0002AE74 | 0x0002AE74 | 0x00000000 |
None | 0x0000023C | 0x004011CC | 0x0002AE78 | 0x0002AE78 | - |
_adj_fdivr_m32i | - | 0x004011D0 | 0x0002AE7C | 0x0002AE7C | 0x00000000 |
__vbaStrCopy | - | 0x004011D4 | 0x0002AE80 | 0x0002AE80 | 0x00000000 |
__vbaI4Str | - | 0x004011D8 | 0x0002AE84 | 0x0002AE84 | 0x00000000 |
__vbaFreeStrList | - | 0x004011DC | 0x0002AE88 | 0x0002AE88 | 0x00000000 |
_adj_fdivr_m32 | - | 0x004011E0 | 0x0002AE8C | 0x0002AE8C | 0x00000000 |
_adj_fdiv_r | - | 0x004011E4 | 0x0002AE90 | 0x0002AE90 | 0x00000000 |
None | 0x00000242 | 0x004011E8 | 0x0002AE94 | 0x0002AE94 | - |
None | 0x00000064 | 0x004011EC | 0x0002AE98 | 0x0002AE98 | - |
__vbaVarSetVar | - | 0x004011F0 | 0x0002AE9C | 0x0002AE9C | 0x00000000 |
__vbaI4Var | - | 0x004011F4 | 0x0002AEA0 | 0x0002AEA0 | 0x00000000 |
None | 0x000002B1 | 0x004011F8 | 0x0002AEA4 | 0x0002AEA4 | - |
__vbaLateMemCall | - | 0x004011FC | 0x0002AEA8 | 0x0002AEA8 | 0x00000000 |
__vbaVarAdd | - | 0x00401200 | 0x0002AEAC | 0x0002AEAC | 0x00000000 |
None | 0x00000263 | 0x00401204 | 0x0002AEB0 | 0x0002AEB0 | - |
__vbaAryLock | - | 0x00401208 | 0x0002AEB4 | 0x0002AEB4 | 0x00000000 |
None | 0x00000140 | 0x0040120C | 0x0002AEB8 | 0x0002AEB8 | - |
__vbaStrComp | - | 0x00401210 | 0x0002AEBC | 0x0002AEBC | 0x00000000 |
__vbaVarDup | - | 0x00401214 | 0x0002AEC0 | 0x0002AEC0 | 0x00000000 |
__vbaStrToAnsi | - | 0x00401218 | 0x0002AEC4 | 0x0002AEC4 | 0x00000000 |
None | 0x00000141 | 0x0040121C | 0x0002AEC8 | 0x0002AEC8 | - |
__vbaFpI2 | - | 0x00401220 | 0x0002AECC | 0x0002AECC | 0x00000000 |
__vbaFpI4 | - | 0x00401224 | 0x0002AED0 | 0x0002AED0 | 0x00000000 |
__vbaVarLateMemCallLd | - | 0x00401228 | 0x0002AED4 | 0x0002AED4 | 0x00000000 |
None | 0x00000268 | 0x0040122C | 0x0002AED8 | 0x0002AED8 | - |
__vbaVarSetObjAddref | - | 0x00401230 | 0x0002AEDC | 0x0002AEDC | 0x00000000 |
__vbaRecDestructAnsi | - | 0x00401234 | 0x0002AEE0 | 0x0002AEE0 | 0x00000000 |
__vbaLateMemCallLd | - | 0x00401238 | 0x0002AEE4 | 0x0002AEE4 | 0x00000000 |
_CIatan | - | 0x0040123C | 0x0002AEE8 | 0x0002AEE8 | 0x00000000 |
__vbaAryCopy | - | 0x00401240 | 0x0002AEEC | 0x0002AEEC | 0x00000000 |
__vbaStrMove | - | 0x00401244 | 0x0002AEF0 | 0x0002AEF0 | 0x00000000 |
None | 0x0000026A | 0x00401248 | 0x0002AEF4 | 0x0002AEF4 | - |
__vbaCastObj | - | 0x0040124C | 0x0002AEF8 | 0x0002AEF8 | 0x00000000 |
__vbaR8IntI4 | - | 0x00401250 | 0x0002AEFC | 0x0002AEFC | 0x00000000 |
None | 0x0000028A | 0x00401254 | 0x0002AF00 | 0x0002AF00 | - |
_allmul | - | 0x00401258 | 0x0002AF04 | 0x0002AF04 | 0x00000000 |
__vbaVarLateMemCallSt | - | 0x0040125C | 0x0002AF08 | 0x0002AF08 | 0x00000000 |
_CItan | - | 0x00401260 | 0x0002AF0C | 0x0002AF0C | 0x00000000 |
None | 0x00000222 | 0x00401264 | 0x0002AF10 | 0x0002AF10 | - |
__vbaAryUnlock | - | 0x00401268 | 0x0002AF14 | 0x0002AF14 | 0x00000000 |
_CIexp | - | 0x0040126C | 0x0002AF18 | 0x0002AF18 | 0x00000000 |
__vbaFreeObj | - | 0x00401270 | 0x0002AF1C | 0x0002AF1C | 0x00000000 |
__vbaFreeStr | - | 0x00401274 | 0x0002AF20 | 0x0002AF20 | 0x00000000 |
None | 0x00000244 | 0x00401278 | 0x0002AF24 | 0x0002AF24 | - |
None | 0x00000245 | 0x0040127C | 0x0002AF28 | 0x0002AF28 | - |
Memory Dumps (5)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|
6731f235ff78e22e5a0f1503542926bb707a95251b8cbd22c56fbd7fc5a8cbbf.exe | 1 | 0x00400000 | 0x0043DFFF | Relevant Image | 32-bit | 0x00403670 |
...
|
||
buffer | 1 | 0x00630000 | 0x0063FFFF | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x00630000 | 0x0063FFFF | Content Changed | 32-bit | - |
...
|
||
buffer | 1 | 0x00630000 | 0x0063FFFF | First Execution | 32-bit | 0x00636338 |
...
|
||
6731f235ff78e22e5a0f1503542926bb707a95251b8cbd22c56fbd7fc5a8cbbf.exe | 1 | 0x00400000 | 0x0043DFFF | Process Termination | 32-bit | - |
...
|
c:\users\rdhj0cnfevzx\desktop\6731f235ff78e22e5a0f1503542926bb707a95251b8cbd22c56fbd7fc5a8cbbf.exe | Dropped File | Binary |
Malicious
|
...
|
»
File Reputation Information
»
Verdict |
Malicious
|
Names | Mal/Generic-S |
PE Information
»
Image Base | 0x00400000 |
Entry Point | 0x004019AC |
Size Of Code | 0x0001E000 |
Size Of Initialized Data | 0x00002000 |
File Type | IMAGE_FILE_EXECUTABLE_IMAGE |
Subsystem | IMAGE_SUBSYSTEM_WINDOWS_GUI |
Machine Type | IMAGE_FILE_MACHINE_I386 |
Compile Timestamp | 2022-07-14 08:48 (UTC+2) |
Version Information (10)
»
Comments | pudendal |
CompanyName | fishweir |
FileDescription | fireballs |
LegalCopyright | quis 1111 |
LegalTrademarks | boondoggles |
ProductName | gimps |
FileVersion | 2.04.0002 |
ProductVersion | 2.04.0002 |
InternalName | soral |
OriginalFilename | soral.exe |
Sections (3)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x00401000 | 0x0001DFC0 | 0x0001E000 | 0x00001000 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 5.89 |
.data | 0x0041F000 | 0x00000BD4 | 0x00001000 | 0x0001F000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.0 |
.rsrc | 0x00420000 | 0x000009B0 | 0x00001000 | 0x00020000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 2.17 |
Imports (1)
»
MSVBVM60.DLL (130)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
_CIcos | - | 0x00401000 | 0x0001E71C | 0x0001E71C | 0x00000053 |
_adj_fptan | - | 0x00401004 | 0x0001E720 | 0x0001E720 | 0x000001B3 |
__vbaVarMove | - | 0x00401008 | 0x0001E724 | 0x0001E724 | 0x00000178 |
__vbaVarVargNofree | - | 0x0040100C | 0x0001E728 | 0x0001E728 | 0x00000199 |
__vbaFreeVar | - | 0x00401010 | 0x0001E72C | 0x0001E72C | 0x000000B1 |
__vbaAryMove | - | 0x00401014 | 0x0001E730 | 0x0001E730 | 0x0000005F |
__vbaLenBstr | - | 0x00401018 | 0x0001E734 | 0x0001E734 | 0x000000E9 |
__vbaStrVarMove | - | 0x0040101C | 0x0001E738 | 0x0001E738 | 0x00000148 |
__vbaEnd | - | 0x00401020 | 0x0001E73C | 0x0001E73C | 0x00000088 |
__vbaFreeVarList | - | 0x00401024 | 0x0001E740 | 0x0001E740 | 0x000000B2 |
_adj_fdiv_m64 | - | 0x00401028 | 0x0001E744 | 0x0001E744 | 0x000001AA |
__vbaFreeObjList | - | 0x0040102C | 0x0001E748 | 0x0001E748 | 0x000000AE |
None | 0x00000204 | 0x00401030 | 0x0001E74C | 0x0001E74C | - |
_adj_fprem1 | - | 0x00401034 | 0x0001E750 | 0x0001E750 | 0x000001B2 |
__vbaStrCat | - | 0x00401038 | 0x0001E754 | 0x0001E754 | 0x00000133 |
__vbaRecDestruct | - | 0x0040103C | 0x0001E758 | 0x0001E758 | 0x00000120 |
__vbaSetSystemError | - | 0x00401040 | 0x0001E75C | 0x0001E75C | 0x0000012D |
__vbaLenBstrB | - | 0x00401044 | 0x0001E760 | 0x0001E760 | 0x000000EA |
__vbaHresultCheckObj | - | 0x00401048 | 0x0001E764 | 0x0001E764 | 0x000000C0 |
_adj_fdiv_m32 | - | 0x0040104C | 0x0001E768 | 0x0001E768 | 0x000001A8 |
None | 0x0000029A | 0x00401050 | 0x0001E76C | 0x0001E76C | - |
None | 0x0000029B | 0x00401054 | 0x0001E770 | 0x0001E770 | - |
__vbaAryDestruct | - | 0x00401058 | 0x0001E774 | 0x0001E774 | 0x0000005D |
None | 0x00000251 | 0x0040105C | 0x0001E778 | 0x0001E778 | - |
__vbaExitProc | - | 0x00401060 | 0x0001E77C | 0x0001E77C | 0x00000092 |
__vbaForEachCollObj | - | 0x00401064 | 0x0001E780 | 0x0001E780 | 0x0000009F |
None | 0x00000252 | 0x00401068 | 0x0001E784 | 0x0001E784 | - |
__vbaOnError | - | 0x0040106C | 0x0001E788 | 0x0001E788 | 0x00000102 |
__vbaObjSet | - | 0x00401070 | 0x0001E78C | 0x0001E78C | 0x000000FF |
_adj_fdiv_m16i | - | 0x00401074 | 0x0001E790 | 0x0001E790 | 0x000001A7 |
__vbaObjSetAddref | - | 0x00401078 | 0x0001E794 | 0x0001E794 | 0x00000100 |
_adj_fdivr_m16i | - | 0x0040107C | 0x0001E798 | 0x0001E798 | 0x000001AC |
_CIsin | - | 0x00401080 | 0x0001E79C | 0x0001E79C | 0x00000056 |
__vbaErase | - | 0x00401084 | 0x0001E7A0 | 0x0001E7A0 | 0x00000089 |
None | 0x000002C5 | 0x00401088 | 0x0001E7A4 | 0x0001E7A4 | - |
None | 0x00000277 | 0x0040108C | 0x0001E7A8 | 0x0001E7A8 | - |
None | 0x00000278 | 0x00401090 | 0x0001E7AC | 0x0001E7AC | - |
None | 0x0000020D | 0x00401094 | 0x0001E7B0 | 0x0001E7B0 | - |
__vbaNextEachCollObj | - | 0x00401098 | 0x0001E7B4 | 0x0001E7B4 | 0x000000FA |
__vbaVarZero | - | 0x0040109C | 0x0001E7B8 | 0x0001E7B8 | 0x0000019B |
__vbaChkstk | - | 0x004010A0 | 0x0001E7BC | 0x0001E7BC | 0x0000006F |
__vbaFileClose | - | 0x004010A4 | 0x0001E7C0 | 0x0001E7C0 | 0x00000097 |
EVENT_SINK_AddRef | - | 0x004010A8 | 0x0001E7C4 | 0x0001E7C4 | 0x00000011 |
__vbaGenerateBoundsError | - | 0x004010AC | 0x0001E7C8 | 0x0001E7C8 | 0x000000B4 |
__vbaStrCmp | - | 0x004010B0 | 0x0001E7CC | 0x0001E7CC | 0x00000134 |
None | 0x00000211 | 0x004010B4 | 0x0001E7D0 | 0x0001E7D0 | - |
__vbaAryConstruct2 | - | 0x004010B8 | 0x0001E7D4 | 0x0001E7D4 | 0x0000005B |
__vbaI2I4 | - | 0x004010BC | 0x0001E7D8 | 0x0001E7D8 | 0x000000C5 |
__vbaObjVar | - | 0x004010C0 | 0x0001E7DC | 0x0001E7DC | 0x00000101 |
DllFunctionCall | - | 0x004010C4 | 0x0001E7E0 | 0x0001E7E0 | 0x0000000B |
__vbaFpUI1 | - | 0x004010C8 | 0x0001E7E4 | 0x0001E7E4 | 0x000000AC |
__vbaLbound | - | 0x004010CC | 0x0001E7E8 | 0x0001E7E8 | 0x000000E7 |
__vbaRedimPreserve | - | 0x004010D0 | 0x0001E7EC | 0x0001E7EC | 0x00000124 |
_adj_fpatan | - | 0x004010D4 | 0x0001E7F0 | 0x0001E7F0 | 0x000001B0 |
__vbaRedim | - | 0x004010D8 | 0x0001E7F4 | 0x0001E7F4 | 0x00000123 |
EVENT_SINK_Release | - | 0x004010DC | 0x0001E7F8 | 0x0001E7F8 | 0x00000015 |
__vbaNew | - | 0x004010E0 | 0x0001E7FC | 0x0001E7FC | 0x000000F6 |
__vbaUI1I2 | - | 0x004010E4 | 0x0001E800 | 0x0001E800 | 0x0000014C |
_CIsqrt | - | 0x004010E8 | 0x0001E804 | 0x0001E804 | 0x00000057 |
EVENT_SINK_QueryInterface | - | 0x004010EC | 0x0001E808 | 0x0001E808 | 0x00000014 |
__vbaStr2Vec | - | 0x004010F0 | 0x0001E80C | 0x0001E80C | 0x0000012F |
__vbaUI1I4 | - | 0x004010F4 | 0x0001E810 | 0x0001E810 | 0x0000014D |
__vbaStrUI1 | - | 0x004010F8 | 0x0001E814 | 0x0001E814 | 0x00000146 |
__vbaExceptHandler | - | 0x004010FC | 0x0001E818 | 0x0001E818 | 0x0000008E |
__vbaPrintFile | - | 0x00401100 | 0x0001E81C | 0x0001E81C | 0x00000105 |
__vbaStrToUnicode | - | 0x00401104 | 0x0001E820 | 0x0001E820 | 0x00000145 |
None | 0x000002C8 | 0x00401108 | 0x0001E824 | 0x0001E824 | - |
None | 0x0000025E | 0x0040110C | 0x0001E828 | 0x0001E828 | - |
_adj_fprem | - | 0x00401110 | 0x0001E82C | 0x0001E82C | 0x000001B1 |
_adj_fdivr_m64 | - | 0x00401114 | 0x0001E830 | 0x0001E830 | 0x000001AF |
None | 0x0000025F | 0x00401118 | 0x0001E834 | 0x0001E834 | - |
None | 0x00000260 | 0x0040111C | 0x0001E838 | 0x0001E838 | - |
None | 0x000002CC | 0x00401120 | 0x0001E83C | 0x0001E83C | - |
__vbaFPException | - | 0x00401124 | 0x0001E840 | 0x0001E840 | 0x00000093 |
None | 0x00000214 | 0x00401128 | 0x0001E844 | 0x0001E844 | - |
None | 0x000002CD | 0x0040112C | 0x0001E848 | 0x0001E848 | - |
__vbaStrVarVal | - | 0x00401130 | 0x0001E84C | 0x0001E84C | 0x00000149 |
__vbaUbound | - | 0x00401134 | 0x0001E850 | 0x0001E850 | 0x00000151 |
__vbaGetOwner3 | - | 0x00401138 | 0x0001E854 | 0x0001E854 | 0x000000B9 |
__vbaVarCat | - | 0x0040113C | 0x0001E858 | 0x0001E858 | 0x00000158 |
None | 0x00000219 | 0x00401140 | 0x0001E85C | 0x0001E85C | - |
None | 0x00000284 | 0x00401144 | 0x0001E860 | 0x0001E860 | - |
None | 0x00000285 | 0x00401148 | 0x0001E864 | 0x0001E864 | - |
_CIlog | - | 0x0040114C | 0x0001E868 | 0x0001E868 | 0x00000055 |
__vbaErrorOverflow | - | 0x00401150 | 0x0001E86C | 0x0001E86C | 0x0000008D |
__vbaFileOpen | - | 0x00401154 | 0x0001E870 | 0x0001E870 | 0x0000009A |
__vbaVarLateMemCallLdRf | - | 0x00401158 | 0x0001E874 | 0x0001E874 | 0x00000171 |
__vbaNew2 | - | 0x0040115C | 0x0001E878 | 0x0001E878 | 0x000000F7 |
__vbaInStr | - | 0x00401160 | 0x0001E87C | 0x0001E87C | 0x000000D0 |
None | 0x00000288 | 0x00401164 | 0x0001E880 | 0x0001E880 | - |
None | 0x0000023A | 0x00401168 | 0x0001E884 | 0x0001E884 | - |
__vbaVar2Vec | - | 0x0040116C | 0x0001E888 | 0x0001E888 | 0x00000154 |
_adj_fdiv_m32i | - | 0x00401170 | 0x0001E88C | 0x0001E88C | 0x000001A9 |
_adj_fdivr_m32i | - | 0x00401174 | 0x0001E890 | 0x0001E890 | 0x000001AE |
None | 0x0000023D | 0x00401178 | 0x0001E894 | 0x0001E894 | - |
__vbaStrCopy | - | 0x0040117C | 0x0001E898 | 0x0001E898 | 0x00000137 |
__vbaFreeStrList | - | 0x00401180 | 0x0001E89C | 0x0001E89C | 0x000000B0 |
__vbaDerefAry1 | - | 0x00401184 | 0x0001E8A0 | 0x0001E8A0 | 0x00000087 |
_adj_fdivr_m32 | - | 0x00401188 | 0x0001E8A4 | 0x0001E8A4 | 0x000001AD |
__vbaPowerR8 | - | 0x0040118C | 0x0001E8A8 | 0x0001E8A8 | 0x00000104 |
_adj_fdiv_r | - | 0x00401190 | 0x0001E8AC | 0x0001E8AC | 0x000001AB |
None | 0x000002AD | 0x00401194 | 0x0001E8B0 | 0x0001E8B0 | - |
None | 0x00000064 | 0x00401198 | 0x0001E8B4 | 0x0001E8B4 | - |
None | 0x00000243 | 0x0040119C | 0x0001E8B8 | 0x0001E8B8 | - |
__vbaAryLock | - | 0x004011A0 | 0x0001E8BC | 0x0001E8BC | 0x0000005E |
__vbaVarAdd | - | 0x004011A4 | 0x0001E8C0 | 0x0001E8C0 | 0x00000156 |
__vbaLateMemCall | - | 0x004011A8 | 0x0001E8C4 | 0x0001E8C4 | 0x000000DE |
__vbaStrToAnsi | - | 0x004011AC | 0x0001E8C8 | 0x0001E8C8 | 0x00000144 |
__vbaVarDup | - | 0x004011B0 | 0x0001E8CC | 0x0001E8CC | 0x00000162 |
__vbaVarCopy | - | 0x004011B4 | 0x0001E8D0 | 0x0001E8D0 | 0x0000015F |
None | 0x00000268 | 0x004011B8 | 0x0001E8D4 | 0x0001E8D4 | - |
__vbaFpI4 | - | 0x004011BC | 0x0001E8D8 | 0x0001E8D8 | 0x000000A9 |
__vbaVarLateMemCallLd | - | 0x004011C0 | 0x0001E8DC | 0x0001E8DC | 0x00000170 |
__vbaLateMemCallLd | - | 0x004011C4 | 0x0001E8E0 | 0x0001E8E0 | 0x000000DF |
_CIatan | - | 0x004011C8 | 0x0001E8E4 | 0x0001E8E4 | 0x00000052 |
None | 0x0000026A | 0x004011CC | 0x0001E8E8 | 0x0001E8E8 | - |
__vbaAryCopy | - | 0x004011D0 | 0x0001E8EC | 0x0001E8EC | 0x0000005C |
__vbaStrMove | - | 0x004011D4 | 0x0001E8F0 | 0x0001E8F0 | 0x0000013F |
__vbaCastObj | - | 0x004011D8 | 0x0001E8F4 | 0x0001E8F4 | 0x0000006B |
__vbaR8IntI4 | - | 0x004011DC | 0x0001E8F8 | 0x0001E8F8 | 0x00000119 |
__vbaStrVarCopy | - | 0x004011E0 | 0x0001E8FC | 0x0001E8FC | 0x00000147 |
_allmul | - | 0x004011E4 | 0x0001E900 | 0x0001E900 | 0x000001B4 |
_CItan | - | 0x004011E8 | 0x0001E904 | 0x0001E904 | 0x00000058 |
__vbaAryUnlock | - | 0x004011EC | 0x0001E908 | 0x0001E908 | 0x00000063 |
_CIexp | - | 0x004011F0 | 0x0001E90C | 0x0001E90C | 0x00000054 |
None | 0x00000244 | 0x004011F4 | 0x0001E910 | 0x0001E910 | - |
__vbaI4ErrVar | - | 0x004011F8 | 0x0001E914 | 0x0001E914 | 0x000000CB |
__vbaFreeObj | - | 0x004011FC | 0x0001E918 | 0x0001E918 | 0x000000AD |
__vbaFreeStr | - | 0x00401200 | 0x0001E91C | 0x0001E91C | 0x000000AF |
None | 0x00000245 | 0x00401204 | 0x0001E920 | 0x0001E920 | - |
Memory Dumps (197)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|
6731f235ff78e22e5a0f1503542926bb707a95251b8cbd22c56fbd7fc5a8cbbf.exe | 2 | 0x00400000 | 0x00420FFF | Relevant Image | 32-bit | 0x004019AC |
...
|
||
buffer | 2 | 0x00510000 | 0x0051FFFF | Marked Executable | 32-bit | - |
...
|
||
buffer | 2 | 0x00510000 | 0x0051FFFF | First Execution | 32-bit | 0x00515288 |
...
|
||
buffer | 2 | 0x02AC0000 | 0x02AD9FFF | Content Changed | 32-bit | - |
...
|
||
buffer | 2 | 0x02ABE000 | 0x02ABFFFF | First Network Behavior | 32-bit | - |
...
|
||
buffer | 2 | 0x0294F000 | 0x0294FFFF | First Network Behavior | 32-bit | - |
...
|
||
buffer | 2 | 0x00198000 | 0x0019FFFF | First Network Behavior | 32-bit | - |
...
|
||
buffer | 2 | 0x00510000 | 0x0051FFFF | First Network Behavior | 32-bit | 0x00515288 |
...
|
||
buffer | 2 | 0x01F20F48 | 0x01F21747 | First Network Behavior | 32-bit | - |
...
|
||
buffer | 2 | 0x01F30000 | 0x0232FFFF | First Network Behavior | 32-bit | - |
...
|
||
buffer | 2 | 0x026700A8 | 0x026701AB | First Network Behavior | 32-bit | - |
...
|
||
buffer | 2 | 0x026701B8 | 0x026708AF | First Network Behavior | 32-bit | - |
...
|
||
buffer | 2 | 0x026708B8 | 0x0267098B | First Network Behavior | 32-bit | - |
...
|
||
buffer | 2 | 0x02670998 | 0x02672D83 | First Network Behavior | 32-bit | - |
...
|
||
buffer | 2 | 0x02672D90 | 0x02672E93 | First Network Behavior | 32-bit | - |
...
|
||
buffer | 2 | 0x02672EA0 | 0x02672F63 | First Network Behavior | 32-bit | - |
...
|
||
buffer | 2 | 0x02672F70 | 0x026730AF | First Network Behavior | 32-bit | - |
...
|
||
buffer | 2 | 0x026730B8 | 0x026734EB | First Network Behavior | 32-bit | - |
...
|
||
buffer | 2 | 0x026734F8 | 0x0267368F | First Network Behavior | 32-bit | - |
...
|
||
buffer | 2 | 0x02673698 | 0x026737DB | First Network Behavior | 32-bit | - |
...
|
||
buffer | 2 | 0x026737E8 | 0x026738C3 | First Network Behavior | 32-bit | - |
...
|
||
buffer | 2 | 0x026738D0 | 0x026739AB | First Network Behavior | 32-bit | - |
...
|
||
buffer | 2 | 0x026739B8 | 0x02673A93 | First Network Behavior | 32-bit | - |
...
|
||
buffer | 2 | 0x02673AA0 | 0x02673B9B | First Network Behavior | 32-bit | - |
...
|
||
buffer | 2 | 0x028404D0 | 0x0284057F | First Network Behavior | 32-bit | - |
...
|
||
buffer | 2 | 0x02843F98 | 0x028440AB | First Network Behavior | 32-bit | - |
...
|
||
buffer | 2 | 0x028440B8 | 0x0284423B | First Network Behavior | 32-bit | - |
...
|
||
buffer | 2 | 0x028442D0 | 0x028445C7 | First Network Behavior | 32-bit | - |
...
|
||
buffer | 2 | 0x028445F0 | 0x02844703 | First Network Behavior | 32-bit | - |
...
|
||
buffer | 2 | 0x02844710 | 0x02844793 | First Network Behavior | 32-bit | - |
...
|
||
buffer | 2 | 0x028447A0 | 0x028448E7 | First Network Behavior | 32-bit | - |
...
|
||
buffer | 2 | 0x02844910 | 0x02844A23 | First Network Behavior | 32-bit | - |
...
|
||
buffer | 2 | 0x02844A30 | 0x02844C13 | First Network Behavior | 32-bit | - |
...
|
||
buffer | 2 | 0x02844C20 | 0x02844CCF | First Network Behavior | 32-bit | - |
...
|
||
buffer | 2 | 0x02844CD8 | 0x0284507B | First Network Behavior | 32-bit | - |
...
|
||
buffer | 2 | 0x028450A8 | 0x028451BB | First Network Behavior | 32-bit | - |
...
|
||
buffer | 2 | 0x028451E0 | 0x0284536F | First Network Behavior | 32-bit | - |
...
|
||
buffer | 2 | 0x02845378 | 0x028453FF | First Network Behavior | 32-bit | - |
...
|
||
buffer | 2 | 0x02845408 | 0x02845717 | First Network Behavior | 32-bit | - |
...
|
||
buffer | 2 | 0x02845740 | 0x02845853 | First Network Behavior | 32-bit | - |
...
|
||
buffer | 2 | 0x02845878 | 0x02845A3F | First Network Behavior | 32-bit | - |
...
|
||
buffer | 2 | 0x02845A48 | 0x02845AEF | First Network Behavior | 32-bit | - |
...
|
||
buffer | 2 | 0x02845AF8 | 0x02845E67 | First Network Behavior | 32-bit | - |
...
|
||
buffer | 2 | 0x02845F98 | 0x02846037 | First Network Behavior | 32-bit | - |
...
|
||
buffer | 2 | 0x02846040 | 0x02846153 | First Network Behavior | 32-bit | - |
...
|
||
buffer | 2 | 0x028461A0 | 0x0284628F | First Network Behavior | 32-bit | - |
...
|
||
buffer | 2 | 0x028462E8 | 0x028464DB | First Network Behavior | 32-bit | - |
...
|
||
buffer | 2 | 0x028464E8 | 0x028465FB | First Network Behavior | 32-bit | - |
...
|
||
buffer | 2 | 0x02846660 | 0x0284677F | First Network Behavior | 32-bit | - |
...
|
||
buffer | 2 | 0x028467F0 | 0x02846A3F | First Network Behavior | 32-bit | - |
...
|
||
buffer | 2 | 0x02846A68 | 0x02846B7B | First Network Behavior | 32-bit | - |
...
|
||
buffer | 2 | 0x02849B10 | 0x02849C93 | First Network Behavior | 32-bit | - |
...
|
||
buffer | 2 | 0x02849CA0 | 0x02849DB3 | First Network Behavior | 32-bit | - |
...
|
||
buffer | 2 | 0x0284A5F8 | 0x0284A6CB | First Network Behavior | 32-bit | - |
...
|
||
buffer | 2 | 0x0284A728 | 0x0284A8EF | First Network Behavior | 32-bit | - |
...
|
||
buffer | 2 | 0x0284A8F8 | 0x0284AA0B | First Network Behavior | 32-bit | - |
...
|
||
buffer | 2 | 0x0284AA60 | 0x0284AB4B | First Network Behavior | 32-bit | - |
...
|
||
buffer | 2 | 0x0284ABA8 | 0x0284AD9F | First Network Behavior | 32-bit | - |
...
|
||
buffer | 2 | 0x0284ADD8 | 0x0284AE97 | First Network Behavior | 32-bit | - |
...
|
||
buffer | 2 | 0x0284AEF8 | 0x0284B00B | First Network Behavior | 32-bit | - |
...
|
||
buffer | 2 | 0x0284B220 | 0x0284B2F3 | First Network Behavior | 32-bit | - |
...
|
||
buffer | 2 | 0x0284B300 | 0x0284B4C7 | First Network Behavior | 32-bit | - |
...
|
||
buffer | 2 | 0x0284B4F8 | 0x0284B60B | First Network Behavior | 32-bit | - |
...
|
||
buffer | 2 | 0x0284B620 | 0x0284B733 | First Network Behavior | 32-bit | - |
...
|
||
buffer | 2 | 0x0284B748 | 0x0284B85B | First Network Behavior | 32-bit | - |
...
|
||
buffer | 2 | 0x0284B870 | 0x0284B983 | First Network Behavior | 32-bit | - |
...
|
||
buffer | 2 | 0x0284B998 | 0x0284BAAB | First Network Behavior | 32-bit | - |
...
|
||
buffer | 2 | 0x0284BAC0 | 0x0284BBD3 | First Network Behavior | 32-bit | - |
...
|
||
buffer | 2 | 0x0284BBE8 | 0x0284BCFB | First Network Behavior | 32-bit | - |
...
|
||
buffer | 2 | 0x0284BD10 | 0x0284BE23 | First Network Behavior | 32-bit | - |
...
|
||
buffer | 2 | 0x0284BE38 | 0x0284BF4B | First Network Behavior | 32-bit | - |
...
|
||
buffer | 2 | 0x0284BF60 | 0x0284C073 | First Network Behavior | 32-bit | - |
...
|
||
buffer | 2 | 0x0284C088 | 0x0284C19B | First Network Behavior | 32-bit | - |
...
|
||
buffer | 2 | 0x0284C1B0 | 0x0284C2C3 | First Network Behavior | 32-bit | - |
...
|
||
buffer | 2 | 0x0284C2D8 | 0x0284C3EB | First Network Behavior | 32-bit | - |
...
|
||
buffer | 2 | 0x0284C4D8 | 0x0284C5DF | First Network Behavior | 32-bit | - |
...
|
||
buffer | 2 | 0x0284CDF0 | 0x0284D01F | First Network Behavior | 32-bit | - |
...
|
||
buffer | 2 | 0x0284D028 | 0x0284D12F | First Network Behavior | 32-bit | - |
...
|
||
buffer | 2 | 0x0284D138 | 0x0284D367 | First Network Behavior | 32-bit | - |
...
|
||
buffer | 2 | 0x0284D3A0 | 0x0284D42F | First Network Behavior | 32-bit | - |
...
|
||
buffer | 2 | 0x0284D468 | 0x0284D5AB | First Network Behavior | 32-bit | - |
...
|
||
buffer | 2 | 0x0284D5E8 | 0x0284D677 | First Network Behavior | 32-bit | - |
...
|
||
buffer | 2 | 0x0284D6B0 | 0x0284D7F3 | First Network Behavior | 32-bit | - |
...
|
||
buffer | 2 | 0x0284D800 | 0x0284D8CF | First Network Behavior | 32-bit | - |
...
|
||
buffer | 2 | 0x0284D9A0 | 0x0284DB3F | First Network Behavior | 32-bit | - |
...
|
||
buffer | 2 | 0x0284DB78 | 0x0284DC3F | First Network Behavior | 32-bit | - |
...
|
||
buffer | 2 | 0x0284DC48 | 0x0284DDF7 | First Network Behavior | 32-bit | - |
...
|
||
buffer | 2 | 0x0284DE30 | 0x0284DF1B | First Network Behavior | 32-bit | - |
...
|
||
buffer | 2 | 0x0284DF88 | 0x0284E17F | First Network Behavior | 32-bit | - |
...
|
||
buffer | 2 | 0x0284E1C8 | 0x0284E27F | First Network Behavior | 32-bit | - |
...
|
||
buffer | 2 | 0x0284E320 | 0x0284E41B | First Network Behavior | 32-bit | - |
...
|
||
buffer | 2 | 0x0284E428 | 0x0284E517 | First Network Behavior | 32-bit | - |
...
|
||
buffer | 2 | 0x0284E520 | 0x0284E60F | First Network Behavior | 32-bit | - |
...
|
||
buffer | 2 | 0x0284E618 | 0x0284E6AF | First Network Behavior | 32-bit | - |
...
|
||
buffer | 2 | 0x0284E6B8 | 0x0284E80B | First Network Behavior | 32-bit | - |
...
|
||
buffer | 2 | 0x0284E818 | 0x0284E8EF | First Network Behavior | 32-bit | - |
...
|
||
buffer | 2 | 0x0284E8F8 | 0x0284EACF | First Network Behavior | 32-bit | - |
...
|
||
buffer | 2 | 0x0284EAE8 | 0x0284EC63 | First Network Behavior | 32-bit | - |
...
|
||
buffer | 2 | 0x0284ECB8 | 0x0284EFA7 | First Network Behavior | 32-bit | - |
...
|
||
buffer | 2 | 0x02AC0000 | 0x02AD9FFF | First Network Behavior | 32-bit | - |
...
|
||
6731f235ff78e22e5a0f1503542926bb707a95251b8cbd22c56fbd7fc5a8cbbf.exe | 2 | 0x00400000 | 0x00420FFF | First Network Behavior | 32-bit | 0x00418C4B |
...
|
||
counters.dat | 2 | 0x006E0000 | 0x006E0FFF | First Network Behavior | 32-bit | - |
...
|
||
buffer | 2 | 0x00510000 | 0x0051FFFF | Final Dump | 32-bit | - |
...
|
||
buffer | 2 | 0x01F20F48 | 0x01F21747 | Final Dump | 32-bit | - |
...
|
||
buffer | 2 | 0x01F30000 | 0x0232FFFF | Final Dump | 32-bit | - |
...
|
||
buffer | 2 | 0x026700A8 | 0x026701AB | Final Dump | 32-bit | - |
...
|
||
buffer | 2 | 0x026701B8 | 0x026708AF | Final Dump | 32-bit | - |
...
|
||
buffer | 2 | 0x026708B8 | 0x0267098B | Final Dump | 32-bit | - |
...
|
||
buffer | 2 | 0x02670998 | 0x02672D83 | Final Dump | 32-bit | - |
...
|
||
buffer | 2 | 0x02672D90 | 0x02672E93 | Final Dump | 32-bit | - |
...
|
||
buffer | 2 | 0x02672EA0 | 0x02672F63 | Final Dump | 32-bit | - |
...
|
||
buffer | 2 | 0x02672F70 | 0x026730AF | Final Dump | 32-bit | - |
...
|
||
buffer | 2 | 0x026730B8 | 0x026734EB | Final Dump | 32-bit | - |
...
|
||
buffer | 2 | 0x026734F8 | 0x0267368F | Final Dump | 32-bit | - |
...
|
||
buffer | 2 | 0x02673698 | 0x026737DB | Final Dump | 32-bit | - |
...
|
||
buffer | 2 | 0x026737E8 | 0x026738C3 | Final Dump | 32-bit | - |
...
|
||
buffer | 2 | 0x026738D0 | 0x026739AB | Final Dump | 32-bit | - |
...
|
||
buffer | 2 | 0x026739B8 | 0x02673A93 | Final Dump | 32-bit | - |
...
|
||
buffer | 2 | 0x02673AA0 | 0x02673B9B | Final Dump | 32-bit | - |
...
|
||
buffer | 2 | 0x028404D0 | 0x0284057F | Final Dump | 32-bit | - |
...
|
||
buffer | 2 | 0x02843F98 | 0x028440AB | Final Dump | 32-bit | - |
...
|
||
buffer | 2 | 0x028440B8 | 0x0284423B | Final Dump | 32-bit | - |
...
|
||
buffer | 2 | 0x028442D0 | 0x028445C7 | Final Dump | 32-bit | - |
...
|
||
buffer | 2 | 0x028445F0 | 0x02844703 | Final Dump | 32-bit | - |
...
|
||
buffer | 2 | 0x02844710 | 0x02844793 | Final Dump | 32-bit | - |
...
|
||
buffer | 2 | 0x028447A0 | 0x028448E7 | Final Dump | 32-bit | - |
...
|
||
buffer | 2 | 0x02844910 | 0x02844A23 | Final Dump | 32-bit | - |
...
|
||
buffer | 2 | 0x02844A30 | 0x02844C13 | Final Dump | 32-bit | - |
...
|
||
buffer | 2 | 0x02844C20 | 0x02844CCF | Final Dump | 32-bit | - |
...
|
||
buffer | 2 | 0x02844CD8 | 0x0284507B | Final Dump | 32-bit | - |
...
|
||
buffer | 2 | 0x028450A8 | 0x028451BB | Final Dump | 32-bit | - |
...
|
||
buffer | 2 | 0x028451E0 | 0x0284536F | Final Dump | 32-bit | - |
...
|
||
buffer | 2 | 0x02845378 | 0x028453FF | Final Dump | 32-bit | - |
...
|
||
buffer | 2 | 0x02845408 | 0x02845717 | Final Dump | 32-bit | - |
...
|
||
buffer | 2 | 0x02845740 | 0x02845853 | Final Dump | 32-bit | - |
...
|
||
buffer | 2 | 0x02845878 | 0x02845A3F | Final Dump | 32-bit | - |
...
|
||
buffer | 2 | 0x02845A48 | 0x02845AEF | Final Dump | 32-bit | - |
...
|
||
buffer | 2 | 0x02845AF8 | 0x02845E67 | Final Dump | 32-bit | - |
...
|
||
buffer | 2 | 0x02845F98 | 0x02846037 | Final Dump | 32-bit | - |
...
|
||
buffer | 2 | 0x02846040 | 0x02846153 | Final Dump | 32-bit | - |
...
|
||
buffer | 2 | 0x028461A0 | 0x0284628F | Final Dump | 32-bit | - |
...
|
||
buffer | 2 | 0x028462E8 | 0x028464DB | Final Dump | 32-bit | - |
...
|
||
buffer | 2 | 0x028464E8 | 0x028465FB | Final Dump | 32-bit | - |
...
|
||
buffer | 2 | 0x02846660 | 0x0284677F | Final Dump | 32-bit | - |
...
|
||
buffer | 2 | 0x028467F0 | 0x02846A3F | Final Dump | 32-bit | - |
...
|
||
buffer | 2 | 0x02846A68 | 0x02846B7B | Final Dump | 32-bit | - |
...
|
||
buffer | 2 | 0x02849B10 | 0x02849C93 | Final Dump | 32-bit | - |
...
|
||
buffer | 2 | 0x02849CA0 | 0x02849DB3 | Final Dump | 32-bit | - |
...
|
||
buffer | 2 | 0x0284A5F8 | 0x0284A6CB | Final Dump | 32-bit | - |
...
|
||
buffer | 2 | 0x0284A728 | 0x0284A8EF | Final Dump | 32-bit | - |
...
|
||
buffer | 2 | 0x0284A8F8 | 0x0284AA0B | Final Dump | 32-bit | - |
...
|
||
buffer | 2 | 0x0284AA60 | 0x0284AB4B | Final Dump | 32-bit | - |
...
|
||
buffer | 2 | 0x0284ABA8 | 0x0284AD9F | Final Dump | 32-bit | - |
...
|
||
buffer | 2 | 0x0284ADD8 | 0x0284AE97 | Final Dump | 32-bit | - |
...
|
||
buffer | 2 | 0x0284AEF8 | 0x0284B00B | Final Dump | 32-bit | - |
...
|
||
buffer | 2 | 0x0284B220 | 0x0284B2F3 | Final Dump | 32-bit | - |
...
|
||
buffer | 2 | 0x0284B300 | 0x0284B4C7 | Final Dump | 32-bit | - |
...
|
||
buffer | 2 | 0x0284B4F8 | 0x0284B60B | Final Dump | 32-bit | - |
...
|
||
buffer | 2 | 0x0284B620 | 0x0284B733 | Final Dump | 32-bit | - |
...
|
||
buffer | 2 | 0x0284B748 | 0x0284B85B | Final Dump | 32-bit | - |
...
|
||
buffer | 2 | 0x0284B870 | 0x0284B983 | Final Dump | 32-bit | - |
...
|
||
buffer | 2 | 0x0284B998 | 0x0284BAAB | Final Dump | 32-bit | - |
...
|
||
buffer | 2 | 0x0284BAC0 | 0x0284BBD3 | Final Dump | 32-bit | - |
...
|
||
buffer | 2 | 0x0284BBE8 | 0x0284BCFB | Final Dump | 32-bit | - |
...
|
||
buffer | 2 | 0x0284BD10 | 0x0284BE23 | Final Dump | 32-bit | - |
...
|
||
buffer | 2 | 0x0284BE38 | 0x0284BF4B | Final Dump | 32-bit | - |
...
|
||
buffer | 2 | 0x0284BF60 | 0x0284C073 | Final Dump | 32-bit | - |
...
|
||
buffer | 2 | 0x0284C088 | 0x0284C19B | Final Dump | 32-bit | - |
...
|
||
buffer | 2 | 0x0284C1B0 | 0x0284C2C3 | Final Dump | 32-bit | - |
...
|
||
buffer | 2 | 0x0284C2D8 | 0x0284C3EB | Final Dump | 32-bit | - |
...
|
||
buffer | 2 | 0x0284C4D8 | 0x0284C5DF | Final Dump | 32-bit | - |
...
|
||
buffer | 2 | 0x0284CDF0 | 0x0284D01F | Final Dump | 32-bit | - |
...
|
||
buffer | 2 | 0x0284D028 | 0x0284D12F | Final Dump | 32-bit | - |
...
|
||
buffer | 2 | 0x0284D138 | 0x0284D367 | Final Dump | 32-bit | - |
...
|
||
buffer | 2 | 0x0284D3A0 | 0x0284D42F | Final Dump | 32-bit | - |
...
|
||
buffer | 2 | 0x0284D468 | 0x0284D5AB | Final Dump | 32-bit | - |
...
|
||
buffer | 2 | 0x0284D5E8 | 0x0284D677 | Final Dump | 32-bit | - |
...
|
||
buffer | 2 | 0x0284D6B0 | 0x0284D7F3 | Final Dump | 32-bit | - |
...
|
||
buffer | 2 | 0x0284D800 | 0x0284D8CF | Final Dump | 32-bit | - |
...
|
||
buffer | 2 | 0x0284D9A0 | 0x0284DB3F | Final Dump | 32-bit | - |
...
|
||
buffer | 2 | 0x0284DB78 | 0x0284DC3F | Final Dump | 32-bit | - |
...
|
||
buffer | 2 | 0x0284DC48 | 0x0284DDF7 | Final Dump | 32-bit | - |
...
|
||
buffer | 2 | 0x0284DE30 | 0x0284DF1B | Final Dump | 32-bit | - |
...
|
||
buffer | 2 | 0x0284DF88 | 0x0284E17F | Final Dump | 32-bit | - |
...
|
||
buffer | 2 | 0x0284E1C8 | 0x0284E27F | Final Dump | 32-bit | - |
...
|
||
buffer | 2 | 0x0284E320 | 0x0284E41B | Final Dump | 32-bit | - |
...
|
||
buffer | 2 | 0x0284E428 | 0x0284E517 | Final Dump | 32-bit | - |
...
|
||
buffer | 2 | 0x0284E520 | 0x0284E60F | Final Dump | 32-bit | - |
...
|
||
buffer | 2 | 0x0284E618 | 0x0284E6AF | Final Dump | 32-bit | - |
...
|
||
buffer | 2 | 0x0284E6B8 | 0x0284E80B | Final Dump | 32-bit | - |
...
|
||
buffer | 2 | 0x0284E818 | 0x0284E8EF | Final Dump | 32-bit | - |
...
|
||
buffer | 2 | 0x0284E8F8 | 0x0284EACF | Final Dump | 32-bit | - |
...
|
||
buffer | 2 | 0x0284EAE8 | 0x0284EC63 | Final Dump | 32-bit | - |
...
|
||
buffer | 2 | 0x0284ECB8 | 0x0284EFA7 | Final Dump | 32-bit | - |
...
|
||
buffer | 2 | 0x02AC0000 | 0x02AD9FFF | Final Dump | 32-bit | - |
...
|
||
6731f235ff78e22e5a0f1503542926bb707a95251b8cbd22c56fbd7fc5a8cbbf.exe | 2 | 0x00400000 | 0x00420FFF | Final Dump | 32-bit | 0x004166FE |
...
|
||
counters.dat | 2 | 0x006E0000 | 0x006E0FFF | Final Dump | 32-bit | - |
...
|
c:\windows\system\svchost.exe | Dropped File | Binary |
Suspicious
|
...
|
»
PE Information
»
Image Base | 0x00400000 |
Entry Point | 0x00403670 |
Size Of Code | 0x0002B000 |
Size Of Initialized Data | 0x00003000 |
File Type | IMAGE_FILE_EXECUTABLE_IMAGE |
Subsystem | IMAGE_SUBSYSTEM_WINDOWS_GUI |
Machine Type | IMAGE_FILE_MACHINE_I386 |
Compile Timestamp | 2011-06-14 21:01 (UTC+2) |
Version Information (6)
»
CompanyName | Microsoft |
ProductName | Win |
FileVersion | 1.00 |
ProductVersion | 1.00 |
InternalName | Win |
OriginalFilename | Win.exe |
Sections (4)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x00401000 | 0x0002A728 | 0x0002B000 | 0x00001000 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 5.95 |
.data | 0x0042C000 | 0x00001B74 | 0x00001000 | 0x0002C000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.0 |
.rsrc | 0x0042E000 | 0x000005E0 | 0x00001000 | 0x0002D000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 1.69 |
.tdata | 0x0042F000 | 0x0000F000 | 0x0000F000 | 0x0002E000 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.0 |
Imports (1)
»
MSVBVM60.DLL (160)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
EVENT_SINK_GetIDsOfNames | - | 0x00401000 | 0x0002ACAC | 0x0002ACAC | 0x00000000 |
__vbaStrI2 | - | 0x00401004 | 0x0002ACB0 | 0x0002ACB0 | 0x00000000 |
None | 0x000002B2 | 0x00401008 | 0x0002ACB4 | 0x0002ACB4 | - |
_CIcos | - | 0x0040100C | 0x0002ACB8 | 0x0002ACB8 | 0x00000000 |
_adj_fptan | - | 0x00401010 | 0x0002ACBC | 0x0002ACBC | 0x00000000 |
__vbaStrI4 | - | 0x00401014 | 0x0002ACC0 | 0x0002ACC0 | 0x00000000 |
__vbaVarVargNofree | - | 0x00401018 | 0x0002ACC4 | 0x0002ACC4 | 0x00000000 |
__vbaFreeVar | - | 0x0040101C | 0x0002ACC8 | 0x0002ACC8 | 0x00000000 |
__vbaStrVarMove | - | 0x00401020 | 0x0002ACCC | 0x0002ACCC | 0x00000000 |
__vbaLenBstr | - | 0x00401024 | 0x0002ACD0 | 0x0002ACD0 | 0x00000000 |
__vbaLateIdCall | - | 0x00401028 | 0x0002ACD4 | 0x0002ACD4 | 0x00000000 |
__vbaPut3 | - | 0x0040102C | 0x0002ACD8 | 0x0002ACD8 | 0x00000000 |
__vbaEnd | - | 0x00401030 | 0x0002ACDC | 0x0002ACDC | 0x00000000 |
__vbaFreeVarList | - | 0x00401034 | 0x0002ACE0 | 0x0002ACE0 | 0x00000000 |
_adj_fdiv_m64 | - | 0x00401038 | 0x0002ACE4 | 0x0002ACE4 | 0x00000000 |
__vbaPut4 | - | 0x0040103C | 0x0002ACE8 | 0x0002ACE8 | 0x00000000 |
EVENT_SINK_Invoke | - | 0x00401040 | 0x0002ACEC | 0x0002ACEC | 0x00000000 |
__vbaRaiseEvent | - | 0x00401044 | 0x0002ACF0 | 0x0002ACF0 | 0x00000000 |
__vbaFreeObjList | - | 0x00401048 | 0x0002ACF4 | 0x0002ACF4 | 0x00000000 |
None | 0x00000204 | 0x0040104C | 0x0002ACF8 | 0x0002ACF8 | - |
__vbaStrErrVarCopy | - | 0x00401050 | 0x0002ACFC | 0x0002ACFC | 0x00000000 |
None | 0x00000205 | 0x00401054 | 0x0002AD00 | 0x0002AD00 | - |
_adj_fprem1 | - | 0x00401058 | 0x0002AD04 | 0x0002AD04 | 0x00000000 |
__vbaRecAnsiToUni | - | 0x0040105C | 0x0002AD08 | 0x0002AD08 | 0x00000000 |
None | 0x00000207 | 0x00401060 | 0x0002AD0C | 0x0002AD0C | - |
__vbaCopyBytes | - | 0x00401064 | 0x0002AD10 | 0x0002AD10 | 0x00000000 |
__vbaStrCat | - | 0x00401068 | 0x0002AD14 | 0x0002AD14 | 0x00000000 |
__vbaLsetFixstr | - | 0x0040106C | 0x0002AD18 | 0x0002AD18 | 0x00000000 |
__vbaRecDestruct | - | 0x00401070 | 0x0002AD1C | 0x0002AD1C | 0x00000000 |
__vbaSetSystemError | - | 0x00401074 | 0x0002AD20 | 0x0002AD20 | 0x00000000 |
None | 0x00000295 | 0x00401078 | 0x0002AD24 | 0x0002AD24 | - |
__vbaHresultCheckObj | - | 0x0040107C | 0x0002AD28 | 0x0002AD28 | 0x00000000 |
__vbaNameFile | - | 0x00401080 | 0x0002AD2C | 0x0002AD2C | 0x00000000 |
_adj_fdiv_m32 | - | 0x00401084 | 0x0002AD30 | 0x0002AD30 | 0x00000000 |
__vbaAryVar | - | 0x00401088 | 0x0002AD34 | 0x0002AD34 | 0x00000000 |
Zombie_GetTypeInfo | - | 0x0040108C | 0x0002AD38 | 0x0002AD38 | 0x00000000 |
__vbaAryDestruct | - | 0x00401090 | 0x0002AD3C | 0x0002AD3C | 0x00000000 |
None | 0x0000029D | 0x00401094 | 0x0002AD40 | 0x0002AD40 | - |
None | 0x00000251 | 0x00401098 | 0x0002AD44 | 0x0002AD44 | - |
__vbaBoolStr | - | 0x0040109C | 0x0002AD48 | 0x0002AD48 | 0x00000000 |
__vbaExitProc | - | 0x004010A0 | 0x0002AD4C | 0x0002AD4C | 0x00000000 |
__vbaI4Abs | - | 0x004010A4 | 0x0002AD50 | 0x0002AD50 | 0x00000000 |
None | 0x00000252 | 0x004010A8 | 0x0002AD54 | 0x0002AD54 | - |
__vbaOnError | - | 0x004010AC | 0x0002AD58 | 0x0002AD58 | 0x00000000 |
__vbaObjSet | - | 0x004010B0 | 0x0002AD5C | 0x0002AD5C | 0x00000000 |
_adj_fdiv_m16i | - | 0x004010B4 | 0x0002AD60 | 0x0002AD60 | 0x00000000 |
__vbaObjSetAddref | - | 0x004010B8 | 0x0002AD64 | 0x0002AD64 | 0x00000000 |
_adj_fdivr_m16i | - | 0x004010BC | 0x0002AD68 | 0x0002AD68 | 0x00000000 |
None | 0x00000256 | 0x004010C0 | 0x0002AD6C | 0x0002AD6C | - |
__vbaFpR4 | - | 0x004010C4 | 0x0002AD70 | 0x0002AD70 | 0x00000000 |
None | 0x000002C1 | 0x004010C8 | 0x0002AD74 | 0x0002AD74 | - |
__vbaStrFixstr | - | 0x004010CC | 0x0002AD78 | 0x0002AD78 | 0x00000000 |
_CIsin | - | 0x004010D0 | 0x0002AD7C | 0x0002AD7C | 0x00000000 |
__vbaErase | - | 0x004010D4 | 0x0002AD80 | 0x0002AD80 | 0x00000000 |
None | 0x00000277 | 0x004010D8 | 0x0002AD84 | 0x0002AD84 | - |
None | 0x000002C5 | 0x004010DC | 0x0002AD88 | 0x0002AD88 | - |
None | 0x0000020D | 0x004010E0 | 0x0002AD8C | 0x0002AD8C | - |
__vbaChkstk | - | 0x004010E4 | 0x0002AD90 | 0x0002AD90 | 0x00000000 |
__vbaFileClose | - | 0x004010E8 | 0x0002AD94 | 0x0002AD94 | 0x00000000 |
EVENT_SINK_AddRef | - | 0x004010EC | 0x0002AD98 | 0x0002AD98 | 0x00000000 |
__vbaGenerateBoundsError | - | 0x004010F0 | 0x0002AD9C | 0x0002AD9C | 0x00000000 |
__vbaGet3 | - | 0x004010F4 | 0x0002ADA0 | 0x0002ADA0 | 0x00000000 |
__vbaStrCmp | - | 0x004010F8 | 0x0002ADA4 | 0x0002ADA4 | 0x00000000 |
None | 0x00000211 | 0x004010FC | 0x0002ADA8 | 0x0002ADA8 | - |
__vbaGet4 | - | 0x00401100 | 0x0002ADAC | 0x0002ADAC | 0x00000000 |
__vbaPutOwner3 | - | 0x00401104 | 0x0002ADB0 | 0x0002ADB0 | 0x00000000 |
__vbaVarTstEq | - | 0x00401108 | 0x0002ADB4 | 0x0002ADB4 | 0x00000000 |
__vbaAryConstruct2 | - | 0x0040110C | 0x0002ADB8 | 0x0002ADB8 | 0x00000000 |
__vbaObjVar | - | 0x00401110 | 0x0002ADBC | 0x0002ADBC | 0x00000000 |
__vbaI2I4 | - | 0x00401114 | 0x0002ADC0 | 0x0002ADC0 | 0x00000000 |
DllFunctionCall | - | 0x00401118 | 0x0002ADC4 | 0x0002ADC4 | 0x00000000 |
__vbaVarLateMemSt | - | 0x0040111C | 0x0002ADC8 | 0x0002ADC8 | 0x00000000 |
__vbaFpUI1 | - | 0x00401120 | 0x0002ADCC | 0x0002ADCC | 0x00000000 |
__vbaRedimPreserve | - | 0x00401124 | 0x0002ADD0 | 0x0002ADD0 | 0x00000000 |
__vbaStrR4 | - | 0x00401128 | 0x0002ADD4 | 0x0002ADD4 | 0x00000000 |
_adj_fpatan | - | 0x0040112C | 0x0002ADD8 | 0x0002ADD8 | 0x00000000 |
__vbaFixstrConstruct | - | 0x00401130 | 0x0002ADDC | 0x0002ADDC | 0x00000000 |
__vbaLateIdCallLd | - | 0x00401134 | 0x0002ADE0 | 0x0002ADE0 | 0x00000000 |
Zombie_GetTypeInfoCount | - | 0x00401138 | 0x0002ADE4 | 0x0002ADE4 | 0x00000000 |
__vbaRedim | - | 0x0040113C | 0x0002ADE8 | 0x0002ADE8 | 0x00000000 |
__vbaRecUniToAnsi | - | 0x00401140 | 0x0002ADEC | 0x0002ADEC | 0x00000000 |
EVENT_SINK_Release | - | 0x00401144 | 0x0002ADF0 | 0x0002ADF0 | 0x00000000 |
__vbaNew | - | 0x00401148 | 0x0002ADF4 | 0x0002ADF4 | 0x00000000 |
None | 0x00000258 | 0x0040114C | 0x0002ADF8 | 0x0002ADF8 | - |
__vbaUI1I2 | - | 0x00401150 | 0x0002ADFC | 0x0002ADFC | 0x00000000 |
_CIsqrt | - | 0x00401154 | 0x0002AE00 | 0x0002AE00 | 0x00000000 |
EVENT_SINK_QueryInterface | - | 0x00401158 | 0x0002AE04 | 0x0002AE04 | 0x00000000 |
__vbaExceptHandler | - | 0x0040115C | 0x0002AE08 | 0x0002AE08 | 0x00000000 |
None | 0x000002C7 | 0x00401160 | 0x0002AE0C | 0x0002AE0C | - |
None | 0x000002C8 | 0x00401164 | 0x0002AE10 | 0x0002AE10 | - |
__vbaStrToUnicode | - | 0x00401168 | 0x0002AE14 | 0x0002AE14 | 0x00000000 |
None | 0x0000025E | 0x0040116C | 0x0002AE18 | 0x0002AE18 | - |
_adj_fprem | - | 0x00401170 | 0x0002AE1C | 0x0002AE1C | 0x00000000 |
_adj_fdivr_m64 | - | 0x00401174 | 0x0002AE20 | 0x0002AE20 | 0x00000000 |
None | 0x000002CA | 0x00401178 | 0x0002AE24 | 0x0002AE24 | - |
None | 0x000002CC | 0x0040117C | 0x0002AE28 | 0x0002AE28 | - |
None | 0x00000261 | 0x00401180 | 0x0002AE2C | 0x0002AE2C | - |
__vbaFPException | - | 0x00401184 | 0x0002AE30 | 0x0002AE30 | 0x00000000 |
None | 0x000002CD | 0x00401188 | 0x0002AE34 | 0x0002AE34 | - |
None | 0x0000013F | 0x0040118C | 0x0002AE38 | 0x0002AE38 | - |
__vbaGetOwner3 | - | 0x00401190 | 0x0002AE3C | 0x0002AE3C | 0x00000000 |
__vbaUbound | - | 0x00401194 | 0x0002AE40 | 0x0002AE40 | 0x00000000 |
None | 0x00000217 | 0x00401198 | 0x0002AE44 | 0x0002AE44 | - |
__vbaFileSeek | - | 0x0040119C | 0x0002AE48 | 0x0002AE48 | 0x00000000 |
None | 0x00000284 | 0x004011A0 | 0x0002AE4C | 0x0002AE4C | - |
None | 0x00000219 | 0x004011A4 | 0x0002AE50 | 0x0002AE50 | - |
_CIlog | - | 0x004011A8 | 0x0002AE54 | 0x0002AE54 | 0x00000000 |
__vbaErrorOverflow | - | 0x004011AC | 0x0002AE58 | 0x0002AE58 | 0x00000000 |
__vbaFileOpen | - | 0x004011B0 | 0x0002AE5C | 0x0002AE5C | 0x00000000 |
__vbaVarLateMemCallLdRf | - | 0x004011B4 | 0x0002AE60 | 0x0002AE60 | 0x00000000 |
None | 0x00000288 | 0x004011B8 | 0x0002AE64 | 0x0002AE64 | - |
None | 0x0000023A | 0x004011BC | 0x0002AE68 | 0x0002AE68 | - |
__vbaNew2 | - | 0x004011C0 | 0x0002AE6C | 0x0002AE6C | 0x00000000 |
__vbaInStr | - | 0x004011C4 | 0x0002AE70 | 0x0002AE70 | 0x00000000 |
_adj_fdiv_m32i | - | 0x004011C8 | 0x0002AE74 | 0x0002AE74 | 0x00000000 |
None | 0x0000023C | 0x004011CC | 0x0002AE78 | 0x0002AE78 | - |
_adj_fdivr_m32i | - | 0x004011D0 | 0x0002AE7C | 0x0002AE7C | 0x00000000 |
__vbaStrCopy | - | 0x004011D4 | 0x0002AE80 | 0x0002AE80 | 0x00000000 |
__vbaI4Str | - | 0x004011D8 | 0x0002AE84 | 0x0002AE84 | 0x00000000 |
__vbaFreeStrList | - | 0x004011DC | 0x0002AE88 | 0x0002AE88 | 0x00000000 |
_adj_fdivr_m32 | - | 0x004011E0 | 0x0002AE8C | 0x0002AE8C | 0x00000000 |
_adj_fdiv_r | - | 0x004011E4 | 0x0002AE90 | 0x0002AE90 | 0x00000000 |
None | 0x00000242 | 0x004011E8 | 0x0002AE94 | 0x0002AE94 | - |
None | 0x00000064 | 0x004011EC | 0x0002AE98 | 0x0002AE98 | - |
__vbaVarSetVar | - | 0x004011F0 | 0x0002AE9C | 0x0002AE9C | 0x00000000 |
__vbaI4Var | - | 0x004011F4 | 0x0002AEA0 | 0x0002AEA0 | 0x00000000 |
None | 0x000002B1 | 0x004011F8 | 0x0002AEA4 | 0x0002AEA4 | - |
__vbaLateMemCall | - | 0x004011FC | 0x0002AEA8 | 0x0002AEA8 | 0x00000000 |
__vbaVarAdd | - | 0x00401200 | 0x0002AEAC | 0x0002AEAC | 0x00000000 |
None | 0x00000263 | 0x00401204 | 0x0002AEB0 | 0x0002AEB0 | - |
__vbaAryLock | - | 0x00401208 | 0x0002AEB4 | 0x0002AEB4 | 0x00000000 |
None | 0x00000140 | 0x0040120C | 0x0002AEB8 | 0x0002AEB8 | - |
__vbaStrComp | - | 0x00401210 | 0x0002AEBC | 0x0002AEBC | 0x00000000 |
__vbaVarDup | - | 0x00401214 | 0x0002AEC0 | 0x0002AEC0 | 0x00000000 |
__vbaStrToAnsi | - | 0x00401218 | 0x0002AEC4 | 0x0002AEC4 | 0x00000000 |
None | 0x00000141 | 0x0040121C | 0x0002AEC8 | 0x0002AEC8 | - |
__vbaFpI2 | - | 0x00401220 | 0x0002AECC | 0x0002AECC | 0x00000000 |
__vbaFpI4 | - | 0x00401224 | 0x0002AED0 | 0x0002AED0 | 0x00000000 |
__vbaVarLateMemCallLd | - | 0x00401228 | 0x0002AED4 | 0x0002AED4 | 0x00000000 |
None | 0x00000268 | 0x0040122C | 0x0002AED8 | 0x0002AED8 | - |
__vbaVarSetObjAddref | - | 0x00401230 | 0x0002AEDC | 0x0002AEDC | 0x00000000 |
__vbaRecDestructAnsi | - | 0x00401234 | 0x0002AEE0 | 0x0002AEE0 | 0x00000000 |
__vbaLateMemCallLd | - | 0x00401238 | 0x0002AEE4 | 0x0002AEE4 | 0x00000000 |
_CIatan | - | 0x0040123C | 0x0002AEE8 | 0x0002AEE8 | 0x00000000 |
__vbaAryCopy | - | 0x00401240 | 0x0002AEEC | 0x0002AEEC | 0x00000000 |
__vbaStrMove | - | 0x00401244 | 0x0002AEF0 | 0x0002AEF0 | 0x00000000 |
None | 0x0000026A | 0x00401248 | 0x0002AEF4 | 0x0002AEF4 | - |
__vbaCastObj | - | 0x0040124C | 0x0002AEF8 | 0x0002AEF8 | 0x00000000 |
__vbaR8IntI4 | - | 0x00401250 | 0x0002AEFC | 0x0002AEFC | 0x00000000 |
None | 0x0000028A | 0x00401254 | 0x0002AF00 | 0x0002AF00 | - |
_allmul | - | 0x00401258 | 0x0002AF04 | 0x0002AF04 | 0x00000000 |
__vbaVarLateMemCallSt | - | 0x0040125C | 0x0002AF08 | 0x0002AF08 | 0x00000000 |
_CItan | - | 0x00401260 | 0x0002AF0C | 0x0002AF0C | 0x00000000 |
None | 0x00000222 | 0x00401264 | 0x0002AF10 | 0x0002AF10 | - |
__vbaAryUnlock | - | 0x00401268 | 0x0002AF14 | 0x0002AF14 | 0x00000000 |
_CIexp | - | 0x0040126C | 0x0002AF18 | 0x0002AF18 | 0x00000000 |
__vbaFreeObj | - | 0x00401270 | 0x0002AF1C | 0x0002AF1C | 0x00000000 |
__vbaFreeStr | - | 0x00401274 | 0x0002AF20 | 0x0002AF20 | 0x00000000 |
None | 0x00000244 | 0x00401278 | 0x0002AF24 | 0x0002AF24 | - |
None | 0x00000245 | 0x0040127C | 0x0002AF28 | 0x0002AF28 | - |
Memory Dumps (133)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|
svchost.exe | 7 | 0x00400000 | 0x0043DFFF | First Execution | 32-bit | 0x00403670 |
...
|
||
buffer | 7 | 0x00500000 | 0x0050FFFF | Marked Executable | 32-bit | - |
...
|
||
buffer | 7 | 0x00500000 | 0x0050FFFF | Content Changed | 32-bit | - |
...
|
||
buffer | 7 | 0x00500000 | 0x0050FFFF | First Execution | 32-bit | 0x00506338 |
...
|
||
buffer | 7 | 0x00500000 | 0x0050FFFF | Final Dump | 32-bit | - |
...
|
||
buffer | 7 | 0x02401538 | 0x024019B7 | Final Dump | 32-bit | - |
...
|
||
buffer | 7 | 0x024019C0 | 0x024021BF | Final Dump | 32-bit | - |
...
|
||
buffer | 7 | 0x02500000 | 0x028FFFFF | Final Dump | 32-bit | - |
...
|
||
buffer | 7 | 0x02E01020 | 0x02E01123 | Final Dump | 32-bit | - |
...
|
||
buffer | 7 | 0x02E01130 | 0x02E01FF7 | Final Dump | 32-bit | - |
...
|
||
buffer | 7 | 0x02E02060 | 0x02E02403 | Final Dump | 32-bit | - |
...
|
||
buffer | 7 | 0x02E02410 | 0x02E027B3 | Final Dump | 32-bit | - |
...
|
||
buffer | 7 | 0x02E027C0 | 0x02E02893 | Final Dump | 32-bit | - |
...
|
||
buffer | 7 | 0x02E028E8 | 0x02E02967 | Final Dump | 32-bit | - |
...
|
||
buffer | 7 | 0x02E02B10 | 0x02E02F43 | Final Dump | 32-bit | - |
...
|
||
buffer | 7 | 0x02E02F50 | 0x02E03383 | Final Dump | 32-bit | - |
...
|
||
buffer | 7 | 0x02E033D8 | 0x02E034EB | Final Dump | 32-bit | - |
...
|
||
buffer | 7 | 0x02E03510 | 0x02E0367B | Final Dump | 32-bit | - |
...
|
||
buffer | 7 | 0x02E036F8 | 0x02E039BF | Final Dump | 32-bit | - |
...
|
||
buffer | 7 | 0x02E03A48 | 0x02E03B5B | Final Dump | 32-bit | - |
...
|
||
buffer | 7 | 0x02E03BE0 | 0x02E03C7B | Final Dump | 32-bit | - |
...
|
||
buffer | 7 | 0x02E03CA8 | 0x02E03DBB | Final Dump | 32-bit | - |
...
|
||
buffer | 7 | 0x02E03DE0 | 0x02E03EBB | Final Dump | 32-bit | - |
...
|
||
buffer | 7 | 0x02E03EE8 | 0x02E03FFB | Final Dump | 32-bit | - |
...
|
||
buffer | 7 | 0x02E04018 | 0x02E0419B | Final Dump | 32-bit | - |
...
|
||
buffer | 7 | 0x02E04230 | 0x02E04527 | Final Dump | 32-bit | - |
...
|
||
buffer | 7 | 0x02E04550 | 0x02E04663 | Final Dump | 32-bit | - |
...
|
||
buffer | 7 | 0x02E046C0 | 0x02E0475F | Final Dump | 32-bit | - |
...
|
||
buffer | 7 | 0x02E04788 | 0x02E0489B | Final Dump | 32-bit | - |
...
|
||
buffer | 7 | 0x02E04A08 | 0x02E04B1B | Final Dump | 32-bit | - |
...
|
||
buffer | 7 | 0x02E04B28 | 0x02E04CAB | Final Dump | 32-bit | - |
...
|
||
buffer | 7 | 0x02E04D40 | 0x02E05037 | Final Dump | 32-bit | - |
...
|
||
buffer | 7 | 0x02E05060 | 0x02E05173 | Final Dump | 32-bit | - |
...
|
||
buffer | 7 | 0x02E05180 | 0x02E05203 | Final Dump | 32-bit | - |
...
|
||
buffer | 7 | 0x02E05210 | 0x02E05357 | Final Dump | 32-bit | - |
...
|
||
buffer | 7 | 0x02E05380 | 0x02E05493 | Final Dump | 32-bit | - |
...
|
||
buffer | 7 | 0x02E054A0 | 0x02E05683 | Final Dump | 32-bit | - |
...
|
||
buffer | 7 | 0x02E05690 | 0x02E0573F | Final Dump | 32-bit | - |
...
|
||
buffer | 7 | 0x02E05748 | 0x02E05AEB | Final Dump | 32-bit | - |
...
|
||
buffer | 7 | 0x02E05B18 | 0x02E05C2B | Final Dump | 32-bit | - |
...
|
||
buffer | 7 | 0x02E05C50 | 0x02E05DDF | Final Dump | 32-bit | - |
...
|
||
buffer | 7 | 0x02E05DE8 | 0x02E05E6F | Final Dump | 32-bit | - |
...
|
||
buffer | 7 | 0x02E05E78 | 0x02E06187 | Final Dump | 32-bit | - |
...
|
||
buffer | 7 | 0x02E061B0 | 0x02E062C3 | Final Dump | 32-bit | - |
...
|
||
buffer | 7 | 0x02E062E8 | 0x02E064AF | Final Dump | 32-bit | - |
...
|
||
buffer | 7 | 0x02E064B8 | 0x02E0655F | Final Dump | 32-bit | - |
...
|
||
buffer | 7 | 0x02E06568 | 0x02E068D7 | Final Dump | 32-bit | - |
...
|
||
buffer | 7 | 0x02E069E0 | 0x02E06AD7 | Final Dump | 32-bit | - |
...
|
||
buffer | 7 | 0x02E06AE0 | 0x02E06BF3 | Final Dump | 32-bit | - |
...
|
||
buffer | 7 | 0x02E06C00 | 0x02E06D2B | Final Dump | 32-bit | - |
...
|
||
buffer | 7 | 0x02E06D38 | 0x02E06DD7 | Final Dump | 32-bit | - |
...
|
||
buffer | 7 | 0x02E06E10 | 0x02E06EAF | Final Dump | 32-bit | - |
...
|
||
buffer | 7 | 0x02E06F00 | 0x02E07013 | Final Dump | 32-bit | - |
...
|
||
buffer | 7 | 0x02E07078 | 0x02E07167 | Final Dump | 32-bit | - |
...
|
||
buffer | 7 | 0x02E071C0 | 0x02E073B3 | Final Dump | 32-bit | - |
...
|
||
buffer | 7 | 0x02E073E0 | 0x02E074F3 | Final Dump | 32-bit | - |
...
|
||
buffer | 7 | 0x02E07540 | 0x02E0765F | Final Dump | 32-bit | - |
...
|
||
buffer | 7 | 0x02E076D0 | 0x02E0791F | Final Dump | 32-bit | - |
...
|
||
buffer | 7 | 0x02E07928 | 0x02E07A3B | Final Dump | 32-bit | - |
...
|
||
buffer | 7 | 0x02E07A78 | 0x02E07B27 | Final Dump | 32-bit | - |
...
|
||
buffer | 7 | 0x02E07B70 | 0x02E07CF3 | Final Dump | 32-bit | - |
...
|
||
buffer | 7 | 0x02E07D30 | 0x02E07E03 | Final Dump | 32-bit | - |
...
|
||
buffer | 7 | 0x02E07E60 | 0x02E08027 | Final Dump | 32-bit | - |
...
|
||
buffer | 7 | 0x02E08060 | 0x02E080EF | Final Dump | 32-bit | - |
...
|
||
buffer | 7 | 0x02E08180 | 0x02E0826B | Final Dump | 32-bit | - |
...
|
||
buffer | 7 | 0x02E08278 | 0x02E0846F | Final Dump | 32-bit | - |
...
|
||
buffer | 7 | 0x02E08478 | 0x02E0854B | Final Dump | 32-bit | - |
...
|
||
buffer | 7 | 0x02E085B0 | 0x02E08777 | Final Dump | 32-bit | - |
...
|
||
buffer | 7 | 0x02E08780 | 0x02E08887 | Final Dump | 32-bit | - |
...
|
||
buffer | 7 | 0x02E088E8 | 0x02E08B17 | Final Dump | 32-bit | - |
...
|
||
buffer | 7 | 0x02E08B20 | 0x02E08C27 | Final Dump | 32-bit | - |
...
|
||
buffer | 7 | 0x02E08C90 | 0x02E08EBF | Final Dump | 32-bit | - |
...
|
||
buffer | 7 | 0x02E08EC8 | 0x02E08F57 | Final Dump | 32-bit | - |
...
|
||
buffer | 7 | 0x02E08F90 | 0x02E090D3 | Final Dump | 32-bit | - |
...
|
||
buffer | 7 | 0x02E09150 | 0x02E0924B | Final Dump | 32-bit | - |
...
|
||
buffer | 7 | 0x02E09280 | 0x02E093C3 | Final Dump | 32-bit | - |
...
|
||
buffer | 7 | 0x02E093D0 | 0x02E0948F | Final Dump | 32-bit | - |
...
|
||
buffer | 7 | 0x02E094E0 | 0x02E0967F | Final Dump | 32-bit | - |
...
|
||
buffer | 7 | 0x02E096B8 | 0x02E0977F | Final Dump | 32-bit | - |
...
|
||
buffer | 7 | 0x02E097E0 | 0x02E0998F | Final Dump | 32-bit | - |
...
|
||
buffer | 7 | 0x02E099C8 | 0x02E09AB3 | Final Dump | 32-bit | - |
...
|
||
buffer | 7 | 0x02E09B20 | 0x02E09D17 | Final Dump | 32-bit | - |
...
|
||
buffer | 7 | 0x02E09D60 | 0x02E09E17 | Final Dump | 32-bit | - |
...
|
||
buffer | 7 | 0x02E09E80 | 0x02E09F83 | Final Dump | 32-bit | - |
...
|
||
buffer | 7 | 0x02E0A068 | 0x02E0A137 | Final Dump | 32-bit | - |
...
|
||
buffer | 7 | 0x02E0A140 | 0x02E0A1D7 | Final Dump | 32-bit | - |
...
|
||
buffer | 7 | 0x02E0A220 | 0x02E0A373 | Final Dump | 32-bit | - |
...
|
||
buffer | 7 | 0x02E0A380 | 0x02E0A457 | Final Dump | 32-bit | - |
...
|
||
buffer | 7 | 0x02E0A4A8 | 0x02E0A67F | Final Dump | 32-bit | - |
...
|
||
buffer | 7 | 0x02E0A698 | 0x02E0A813 | Final Dump | 32-bit | - |
...
|
||
buffer | 7 | 0x02E0A868 | 0x02E0AB57 | Final Dump | 32-bit | - |
...
|
||
buffer | 7 | 0x02E0AB60 | 0x02E0B257 | Final Dump | 32-bit | - |
...
|
||
buffer | 7 | 0x02E0B260 | 0x02E0B333 | Final Dump | 32-bit | - |
...
|
||
buffer | 7 | 0x02E0B340 | 0x02E0D72B | Final Dump | 32-bit | - |
...
|
||
buffer | 7 | 0x02E0D738 | 0x02E0D83B | Final Dump | 32-bit | - |
...
|
||
buffer | 7 | 0x02E0D848 | 0x02E0D99B | Final Dump | 32-bit | - |
...
|
||
buffer | 7 | 0x02E0D9A8 | 0x02E0DAE7 | Final Dump | 32-bit | - |
...
|
||
buffer | 7 | 0x02E0DAF0 | 0x02E0DF23 | Final Dump | 32-bit | - |
...
|
||
buffer | 7 | 0x02E0DF30 | 0x02E0E0C7 | Final Dump | 32-bit | - |
...
|
||
buffer | 7 | 0x02E0E0D0 | 0x02E0E213 | Final Dump | 32-bit | - |
...
|
||
buffer | 7 | 0x02E0E220 | 0x02E0E363 | Final Dump | 32-bit | - |
...
|
||
buffer | 7 | 0x02E0E370 | 0x02E0E4E3 | Final Dump | 32-bit | - |
...
|
||
buffer | 7 | 0x02E0E528 | 0x02E0E71B | Final Dump | 32-bit | - |
...
|
||
buffer | 7 | 0x02E0E728 | 0x02E0EECB | Final Dump | 32-bit | - |
...
|
||
buffer | 7 | 0x02E0EF40 | 0x02E0F07F | Final Dump | 32-bit | - |
...
|
||
buffer | 7 | 0x02E0F088 | 0x02E0F4BB | Final Dump | 32-bit | - |
...
|
||
buffer | 7 | 0x02E0F4C8 | 0x02E0F673 | Final Dump | 32-bit | - |
...
|
||
buffer | 7 | 0x02E0F680 | 0x02E0F75B | Final Dump | 32-bit | - |
...
|
||
buffer | 7 | 0x02E0F768 | 0x02E0F843 | Final Dump | 32-bit | - |
...
|
||
buffer | 7 | 0x02E0F850 | 0x02E0F92B | Final Dump | 32-bit | - |
...
|
||
buffer | 7 | 0x02E0F938 | 0x02E0FA7B | Final Dump | 32-bit | - |
...
|
||
buffer | 7 | 0x02E0FA88 | 0x02E0FBCB | Final Dump | 32-bit | - |
...
|
||
buffer | 7 | 0x02E0FBD8 | 0x02E0FCD3 | Final Dump | 32-bit | - |
...
|
||
buffer | 7 | 0x02E14028 | 0x02E1413B | Final Dump | 32-bit | - |
...
|
||
buffer | 7 | 0x02E14148 | 0x02E1425B | Final Dump | 32-bit | - |
...
|
||
buffer | 7 | 0x02E14268 | 0x02E1437B | Final Dump | 32-bit | - |
...
|
||
buffer | 7 | 0x02E14388 | 0x02E1449B | Final Dump | 32-bit | - |
...
|
||
buffer | 7 | 0x02E144A8 | 0x02E145BB | Final Dump | 32-bit | - |
...
|
||
buffer | 7 | 0x02E145C8 | 0x02E146DB | Final Dump | 32-bit | - |
...
|
||
buffer | 7 | 0x02E146E8 | 0x02E147FB | Final Dump | 32-bit | - |
...
|
||
buffer | 7 | 0x02E14808 | 0x02E1491B | Final Dump | 32-bit | - |
...
|
||
buffer | 7 | 0x02E14928 | 0x02E14A3B | Final Dump | 32-bit | - |
...
|
||
buffer | 7 | 0x02E14A48 | 0x02E14B5B | Final Dump | 32-bit | - |
...
|
||
buffer | 7 | 0x02E14B68 | 0x02E14C7B | Final Dump | 32-bit | - |
...
|
||
buffer | 7 | 0x02E14C88 | 0x02E14D9B | Final Dump | 32-bit | - |
...
|
||
buffer | 7 | 0x02E14DA8 | 0x02E14EBB | Final Dump | 32-bit | - |
...
|
||
buffer | 7 | 0x02E14EC8 | 0x02E14FDB | Final Dump | 32-bit | - |
...
|
||
buffer | 7 | 0x02E16390 | 0x02E164A3 | Final Dump | 32-bit | - |
...
|
||
buffer | 7 | 0x02E16930 | 0x02E16A47 | Final Dump | 32-bit | - |
...
|
||
buffer | 7 | 0x02E16FF0 | 0x02E17107 | Final Dump | 32-bit | - |
...
|
||
buffer | 7 | 0x02E17110 | 0x02E17223 | Final Dump | 32-bit | - |
...
|
||
buffer | 7 | 0x03201020 | 0x03201133 | Final Dump | 32-bit | - |
...
|
||
svchost.exe | 7 | 0x00400000 | 0x0043DFFF | Final Dump | 32-bit | - |
...
|
C:\Windows\System\explorer.exe | Dropped File | Binary |
Suspicious
|
...
|
»
PE Information
»
Image Base | 0x00400000 |
Entry Point | 0x00403670 |
Size Of Code | 0x0002B000 |
Size Of Initialized Data | 0x00003000 |
File Type | IMAGE_FILE_EXECUTABLE_IMAGE |
Subsystem | IMAGE_SUBSYSTEM_WINDOWS_GUI |
Machine Type | IMAGE_FILE_MACHINE_I386 |
Compile Timestamp | 2011-06-14 21:01 (UTC+2) |
Version Information (6)
»
CompanyName | Microsoft |
ProductName | Win |
FileVersion | 1.00 |
ProductVersion | 1.00 |
InternalName | Win |
OriginalFilename | Win.exe |
Sections (4)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x00401000 | 0x0002A728 | 0x0002B000 | 0x00001000 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 5.95 |
.data | 0x0042C000 | 0x00001B74 | 0x00001000 | 0x0002C000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.0 |
.rsrc | 0x0042E000 | 0x000005E0 | 0x00001000 | 0x0002D000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 1.69 |
.tdata | 0x0042F000 | 0x0000F000 | 0x0000F000 | 0x0002E000 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.0 |
Imports (1)
»
MSVBVM60.DLL (160)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
EVENT_SINK_GetIDsOfNames | - | 0x00401000 | 0x0002ACAC | 0x0002ACAC | 0x00000000 |
__vbaStrI2 | - | 0x00401004 | 0x0002ACB0 | 0x0002ACB0 | 0x00000000 |
None | 0x000002B2 | 0x00401008 | 0x0002ACB4 | 0x0002ACB4 | - |
_CIcos | - | 0x0040100C | 0x0002ACB8 | 0x0002ACB8 | 0x00000000 |
_adj_fptan | - | 0x00401010 | 0x0002ACBC | 0x0002ACBC | 0x00000000 |
__vbaStrI4 | - | 0x00401014 | 0x0002ACC0 | 0x0002ACC0 | 0x00000000 |
__vbaVarVargNofree | - | 0x00401018 | 0x0002ACC4 | 0x0002ACC4 | 0x00000000 |
__vbaFreeVar | - | 0x0040101C | 0x0002ACC8 | 0x0002ACC8 | 0x00000000 |
__vbaStrVarMove | - | 0x00401020 | 0x0002ACCC | 0x0002ACCC | 0x00000000 |
__vbaLenBstr | - | 0x00401024 | 0x0002ACD0 | 0x0002ACD0 | 0x00000000 |
__vbaLateIdCall | - | 0x00401028 | 0x0002ACD4 | 0x0002ACD4 | 0x00000000 |
__vbaPut3 | - | 0x0040102C | 0x0002ACD8 | 0x0002ACD8 | 0x00000000 |
__vbaEnd | - | 0x00401030 | 0x0002ACDC | 0x0002ACDC | 0x00000000 |
__vbaFreeVarList | - | 0x00401034 | 0x0002ACE0 | 0x0002ACE0 | 0x00000000 |
_adj_fdiv_m64 | - | 0x00401038 | 0x0002ACE4 | 0x0002ACE4 | 0x00000000 |
__vbaPut4 | - | 0x0040103C | 0x0002ACE8 | 0x0002ACE8 | 0x00000000 |
EVENT_SINK_Invoke | - | 0x00401040 | 0x0002ACEC | 0x0002ACEC | 0x00000000 |
__vbaRaiseEvent | - | 0x00401044 | 0x0002ACF0 | 0x0002ACF0 | 0x00000000 |
__vbaFreeObjList | - | 0x00401048 | 0x0002ACF4 | 0x0002ACF4 | 0x00000000 |
None | 0x00000204 | 0x0040104C | 0x0002ACF8 | 0x0002ACF8 | - |
__vbaStrErrVarCopy | - | 0x00401050 | 0x0002ACFC | 0x0002ACFC | 0x00000000 |
None | 0x00000205 | 0x00401054 | 0x0002AD00 | 0x0002AD00 | - |
_adj_fprem1 | - | 0x00401058 | 0x0002AD04 | 0x0002AD04 | 0x00000000 |
__vbaRecAnsiToUni | - | 0x0040105C | 0x0002AD08 | 0x0002AD08 | 0x00000000 |
None | 0x00000207 | 0x00401060 | 0x0002AD0C | 0x0002AD0C | - |
__vbaCopyBytes | - | 0x00401064 | 0x0002AD10 | 0x0002AD10 | 0x00000000 |
__vbaStrCat | - | 0x00401068 | 0x0002AD14 | 0x0002AD14 | 0x00000000 |
__vbaLsetFixstr | - | 0x0040106C | 0x0002AD18 | 0x0002AD18 | 0x00000000 |
__vbaRecDestruct | - | 0x00401070 | 0x0002AD1C | 0x0002AD1C | 0x00000000 |
__vbaSetSystemError | - | 0x00401074 | 0x0002AD20 | 0x0002AD20 | 0x00000000 |
None | 0x00000295 | 0x00401078 | 0x0002AD24 | 0x0002AD24 | - |
__vbaHresultCheckObj | - | 0x0040107C | 0x0002AD28 | 0x0002AD28 | 0x00000000 |
__vbaNameFile | - | 0x00401080 | 0x0002AD2C | 0x0002AD2C | 0x00000000 |
_adj_fdiv_m32 | - | 0x00401084 | 0x0002AD30 | 0x0002AD30 | 0x00000000 |
__vbaAryVar | - | 0x00401088 | 0x0002AD34 | 0x0002AD34 | 0x00000000 |
Zombie_GetTypeInfo | - | 0x0040108C | 0x0002AD38 | 0x0002AD38 | 0x00000000 |
__vbaAryDestruct | - | 0x00401090 | 0x0002AD3C | 0x0002AD3C | 0x00000000 |
None | 0x0000029D | 0x00401094 | 0x0002AD40 | 0x0002AD40 | - |
None | 0x00000251 | 0x00401098 | 0x0002AD44 | 0x0002AD44 | - |
__vbaBoolStr | - | 0x0040109C | 0x0002AD48 | 0x0002AD48 | 0x00000000 |
__vbaExitProc | - | 0x004010A0 | 0x0002AD4C | 0x0002AD4C | 0x00000000 |
__vbaI4Abs | - | 0x004010A4 | 0x0002AD50 | 0x0002AD50 | 0x00000000 |
None | 0x00000252 | 0x004010A8 | 0x0002AD54 | 0x0002AD54 | - |
__vbaOnError | - | 0x004010AC | 0x0002AD58 | 0x0002AD58 | 0x00000000 |
__vbaObjSet | - | 0x004010B0 | 0x0002AD5C | 0x0002AD5C | 0x00000000 |
_adj_fdiv_m16i | - | 0x004010B4 | 0x0002AD60 | 0x0002AD60 | 0x00000000 |
__vbaObjSetAddref | - | 0x004010B8 | 0x0002AD64 | 0x0002AD64 | 0x00000000 |
_adj_fdivr_m16i | - | 0x004010BC | 0x0002AD68 | 0x0002AD68 | 0x00000000 |
None | 0x00000256 | 0x004010C0 | 0x0002AD6C | 0x0002AD6C | - |
__vbaFpR4 | - | 0x004010C4 | 0x0002AD70 | 0x0002AD70 | 0x00000000 |
None | 0x000002C1 | 0x004010C8 | 0x0002AD74 | 0x0002AD74 | - |
__vbaStrFixstr | - | 0x004010CC | 0x0002AD78 | 0x0002AD78 | 0x00000000 |
_CIsin | - | 0x004010D0 | 0x0002AD7C | 0x0002AD7C | 0x00000000 |
__vbaErase | - | 0x004010D4 | 0x0002AD80 | 0x0002AD80 | 0x00000000 |
None | 0x00000277 | 0x004010D8 | 0x0002AD84 | 0x0002AD84 | - |
None | 0x000002C5 | 0x004010DC | 0x0002AD88 | 0x0002AD88 | - |
None | 0x0000020D | 0x004010E0 | 0x0002AD8C | 0x0002AD8C | - |
__vbaChkstk | - | 0x004010E4 | 0x0002AD90 | 0x0002AD90 | 0x00000000 |
__vbaFileClose | - | 0x004010E8 | 0x0002AD94 | 0x0002AD94 | 0x00000000 |
EVENT_SINK_AddRef | - | 0x004010EC | 0x0002AD98 | 0x0002AD98 | 0x00000000 |
__vbaGenerateBoundsError | - | 0x004010F0 | 0x0002AD9C | 0x0002AD9C | 0x00000000 |
__vbaGet3 | - | 0x004010F4 | 0x0002ADA0 | 0x0002ADA0 | 0x00000000 |
__vbaStrCmp | - | 0x004010F8 | 0x0002ADA4 | 0x0002ADA4 | 0x00000000 |
None | 0x00000211 | 0x004010FC | 0x0002ADA8 | 0x0002ADA8 | - |
__vbaGet4 | - | 0x00401100 | 0x0002ADAC | 0x0002ADAC | 0x00000000 |
__vbaPutOwner3 | - | 0x00401104 | 0x0002ADB0 | 0x0002ADB0 | 0x00000000 |
__vbaVarTstEq | - | 0x00401108 | 0x0002ADB4 | 0x0002ADB4 | 0x00000000 |
__vbaAryConstruct2 | - | 0x0040110C | 0x0002ADB8 | 0x0002ADB8 | 0x00000000 |
__vbaObjVar | - | 0x00401110 | 0x0002ADBC | 0x0002ADBC | 0x00000000 |
__vbaI2I4 | - | 0x00401114 | 0x0002ADC0 | 0x0002ADC0 | 0x00000000 |
DllFunctionCall | - | 0x00401118 | 0x0002ADC4 | 0x0002ADC4 | 0x00000000 |
__vbaVarLateMemSt | - | 0x0040111C | 0x0002ADC8 | 0x0002ADC8 | 0x00000000 |
__vbaFpUI1 | - | 0x00401120 | 0x0002ADCC | 0x0002ADCC | 0x00000000 |
__vbaRedimPreserve | - | 0x00401124 | 0x0002ADD0 | 0x0002ADD0 | 0x00000000 |
__vbaStrR4 | - | 0x00401128 | 0x0002ADD4 | 0x0002ADD4 | 0x00000000 |
_adj_fpatan | - | 0x0040112C | 0x0002ADD8 | 0x0002ADD8 | 0x00000000 |
__vbaFixstrConstruct | - | 0x00401130 | 0x0002ADDC | 0x0002ADDC | 0x00000000 |
__vbaLateIdCallLd | - | 0x00401134 | 0x0002ADE0 | 0x0002ADE0 | 0x00000000 |
Zombie_GetTypeInfoCount | - | 0x00401138 | 0x0002ADE4 | 0x0002ADE4 | 0x00000000 |
__vbaRedim | - | 0x0040113C | 0x0002ADE8 | 0x0002ADE8 | 0x00000000 |
__vbaRecUniToAnsi | - | 0x00401140 | 0x0002ADEC | 0x0002ADEC | 0x00000000 |
EVENT_SINK_Release | - | 0x00401144 | 0x0002ADF0 | 0x0002ADF0 | 0x00000000 |
__vbaNew | - | 0x00401148 | 0x0002ADF4 | 0x0002ADF4 | 0x00000000 |
None | 0x00000258 | 0x0040114C | 0x0002ADF8 | 0x0002ADF8 | - |
__vbaUI1I2 | - | 0x00401150 | 0x0002ADFC | 0x0002ADFC | 0x00000000 |
_CIsqrt | - | 0x00401154 | 0x0002AE00 | 0x0002AE00 | 0x00000000 |
EVENT_SINK_QueryInterface | - | 0x00401158 | 0x0002AE04 | 0x0002AE04 | 0x00000000 |
__vbaExceptHandler | - | 0x0040115C | 0x0002AE08 | 0x0002AE08 | 0x00000000 |
None | 0x000002C7 | 0x00401160 | 0x0002AE0C | 0x0002AE0C | - |
None | 0x000002C8 | 0x00401164 | 0x0002AE10 | 0x0002AE10 | - |
__vbaStrToUnicode | - | 0x00401168 | 0x0002AE14 | 0x0002AE14 | 0x00000000 |
None | 0x0000025E | 0x0040116C | 0x0002AE18 | 0x0002AE18 | - |
_adj_fprem | - | 0x00401170 | 0x0002AE1C | 0x0002AE1C | 0x00000000 |
_adj_fdivr_m64 | - | 0x00401174 | 0x0002AE20 | 0x0002AE20 | 0x00000000 |
None | 0x000002CA | 0x00401178 | 0x0002AE24 | 0x0002AE24 | - |
None | 0x000002CC | 0x0040117C | 0x0002AE28 | 0x0002AE28 | - |
None | 0x00000261 | 0x00401180 | 0x0002AE2C | 0x0002AE2C | - |
__vbaFPException | - | 0x00401184 | 0x0002AE30 | 0x0002AE30 | 0x00000000 |
None | 0x000002CD | 0x00401188 | 0x0002AE34 | 0x0002AE34 | - |
None | 0x0000013F | 0x0040118C | 0x0002AE38 | 0x0002AE38 | - |
__vbaGetOwner3 | - | 0x00401190 | 0x0002AE3C | 0x0002AE3C | 0x00000000 |
__vbaUbound | - | 0x00401194 | 0x0002AE40 | 0x0002AE40 | 0x00000000 |
None | 0x00000217 | 0x00401198 | 0x0002AE44 | 0x0002AE44 | - |
__vbaFileSeek | - | 0x0040119C | 0x0002AE48 | 0x0002AE48 | 0x00000000 |
None | 0x00000284 | 0x004011A0 | 0x0002AE4C | 0x0002AE4C | - |
None | 0x00000219 | 0x004011A4 | 0x0002AE50 | 0x0002AE50 | - |
_CIlog | - | 0x004011A8 | 0x0002AE54 | 0x0002AE54 | 0x00000000 |
__vbaErrorOverflow | - | 0x004011AC | 0x0002AE58 | 0x0002AE58 | 0x00000000 |
__vbaFileOpen | - | 0x004011B0 | 0x0002AE5C | 0x0002AE5C | 0x00000000 |
__vbaVarLateMemCallLdRf | - | 0x004011B4 | 0x0002AE60 | 0x0002AE60 | 0x00000000 |
None | 0x00000288 | 0x004011B8 | 0x0002AE64 | 0x0002AE64 | - |
None | 0x0000023A | 0x004011BC | 0x0002AE68 | 0x0002AE68 | - |
__vbaNew2 | - | 0x004011C0 | 0x0002AE6C | 0x0002AE6C | 0x00000000 |
__vbaInStr | - | 0x004011C4 | 0x0002AE70 | 0x0002AE70 | 0x00000000 |
_adj_fdiv_m32i | - | 0x004011C8 | 0x0002AE74 | 0x0002AE74 | 0x00000000 |
None | 0x0000023C | 0x004011CC | 0x0002AE78 | 0x0002AE78 | - |
_adj_fdivr_m32i | - | 0x004011D0 | 0x0002AE7C | 0x0002AE7C | 0x00000000 |
__vbaStrCopy | - | 0x004011D4 | 0x0002AE80 | 0x0002AE80 | 0x00000000 |
__vbaI4Str | - | 0x004011D8 | 0x0002AE84 | 0x0002AE84 | 0x00000000 |
__vbaFreeStrList | - | 0x004011DC | 0x0002AE88 | 0x0002AE88 | 0x00000000 |
_adj_fdivr_m32 | - | 0x004011E0 | 0x0002AE8C | 0x0002AE8C | 0x00000000 |
_adj_fdiv_r | - | 0x004011E4 | 0x0002AE90 | 0x0002AE90 | 0x00000000 |
None | 0x00000242 | 0x004011E8 | 0x0002AE94 | 0x0002AE94 | - |
None | 0x00000064 | 0x004011EC | 0x0002AE98 | 0x0002AE98 | - |
__vbaVarSetVar | - | 0x004011F0 | 0x0002AE9C | 0x0002AE9C | 0x00000000 |
__vbaI4Var | - | 0x004011F4 | 0x0002AEA0 | 0x0002AEA0 | 0x00000000 |
None | 0x000002B1 | 0x004011F8 | 0x0002AEA4 | 0x0002AEA4 | - |
__vbaLateMemCall | - | 0x004011FC | 0x0002AEA8 | 0x0002AEA8 | 0x00000000 |
__vbaVarAdd | - | 0x00401200 | 0x0002AEAC | 0x0002AEAC | 0x00000000 |
None | 0x00000263 | 0x00401204 | 0x0002AEB0 | 0x0002AEB0 | - |
__vbaAryLock | - | 0x00401208 | 0x0002AEB4 | 0x0002AEB4 | 0x00000000 |
None | 0x00000140 | 0x0040120C | 0x0002AEB8 | 0x0002AEB8 | - |
__vbaStrComp | - | 0x00401210 | 0x0002AEBC | 0x0002AEBC | 0x00000000 |
__vbaVarDup | - | 0x00401214 | 0x0002AEC0 | 0x0002AEC0 | 0x00000000 |
__vbaStrToAnsi | - | 0x00401218 | 0x0002AEC4 | 0x0002AEC4 | 0x00000000 |
None | 0x00000141 | 0x0040121C | 0x0002AEC8 | 0x0002AEC8 | - |
__vbaFpI2 | - | 0x00401220 | 0x0002AECC | 0x0002AECC | 0x00000000 |
__vbaFpI4 | - | 0x00401224 | 0x0002AED0 | 0x0002AED0 | 0x00000000 |
__vbaVarLateMemCallLd | - | 0x00401228 | 0x0002AED4 | 0x0002AED4 | 0x00000000 |
None | 0x00000268 | 0x0040122C | 0x0002AED8 | 0x0002AED8 | - |
__vbaVarSetObjAddref | - | 0x00401230 | 0x0002AEDC | 0x0002AEDC | 0x00000000 |
__vbaRecDestructAnsi | - | 0x00401234 | 0x0002AEE0 | 0x0002AEE0 | 0x00000000 |
__vbaLateMemCallLd | - | 0x00401238 | 0x0002AEE4 | 0x0002AEE4 | 0x00000000 |
_CIatan | - | 0x0040123C | 0x0002AEE8 | 0x0002AEE8 | 0x00000000 |
__vbaAryCopy | - | 0x00401240 | 0x0002AEEC | 0x0002AEEC | 0x00000000 |
__vbaStrMove | - | 0x00401244 | 0x0002AEF0 | 0x0002AEF0 | 0x00000000 |
None | 0x0000026A | 0x00401248 | 0x0002AEF4 | 0x0002AEF4 | - |
__vbaCastObj | - | 0x0040124C | 0x0002AEF8 | 0x0002AEF8 | 0x00000000 |
__vbaR8IntI4 | - | 0x00401250 | 0x0002AEFC | 0x0002AEFC | 0x00000000 |
None | 0x0000028A | 0x00401254 | 0x0002AF00 | 0x0002AF00 | - |
_allmul | - | 0x00401258 | 0x0002AF04 | 0x0002AF04 | 0x00000000 |
__vbaVarLateMemCallSt | - | 0x0040125C | 0x0002AF08 | 0x0002AF08 | 0x00000000 |
_CItan | - | 0x00401260 | 0x0002AF0C | 0x0002AF0C | 0x00000000 |
None | 0x00000222 | 0x00401264 | 0x0002AF10 | 0x0002AF10 | - |
__vbaAryUnlock | - | 0x00401268 | 0x0002AF14 | 0x0002AF14 | 0x00000000 |
_CIexp | - | 0x0040126C | 0x0002AF18 | 0x0002AF18 | 0x00000000 |
__vbaFreeObj | - | 0x00401270 | 0x0002AF1C | 0x0002AF1C | 0x00000000 |
__vbaFreeStr | - | 0x00401274 | 0x0002AF20 | 0x0002AF20 | 0x00000000 |
None | 0x00000244 | 0x00401278 | 0x0002AF24 | 0x0002AF24 | - |
None | 0x00000245 | 0x0040127C | 0x0002AF28 | 0x0002AF28 | - |
Memory Dumps (221)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|
explorer.exe | 5 | 0x00400000 | 0x0043DFFF | First Execution | 32-bit | 0x00403670 |
...
|
||
buffer | 5 | 0x00460000 | 0x0046FFFF | Marked Executable | 32-bit | - |
...
|
||
buffer | 5 | 0x00460000 | 0x0046FFFF | Content Changed | 32-bit | - |
...
|
||
buffer | 5 | 0x00460000 | 0x0046FFFF | First Execution | 32-bit | 0x00466338 |
...
|
||
buffer | 5 | 0x0307E000 | 0x0307FFFF | First Network Behavior | 32-bit | - |
...
|
||
buffer | 5 | 0x02F7F000 | 0x02F7FFFF | First Network Behavior | 32-bit | - |
...
|
||
buffer | 5 | 0x0019A000 | 0x0019FFFF | First Network Behavior | 32-bit | - |
...
|
||
buffer | 5 | 0x00460000 | 0x0046FFFF | First Network Behavior | 32-bit | - |
...
|
||
buffer | 5 | 0x00520F48 | 0x00521747 | First Network Behavior | 32-bit | - |
...
|
||
buffer | 5 | 0x01F40000 | 0x0233FFFF | First Network Behavior | 32-bit | - |
...
|
||
buffer | 5 | 0x026F3F98 | 0x026F40AB | First Network Behavior | 32-bit | - |
...
|
||
buffer | 5 | 0x026F40B8 | 0x026F423B | First Network Behavior | 32-bit | - |
...
|
||
buffer | 5 | 0x026F42D0 | 0x026F45C7 | First Network Behavior | 32-bit | - |
...
|
||
buffer | 5 | 0x026F45F0 | 0x026F4703 | First Network Behavior | 32-bit | - |
...
|
||
buffer | 5 | 0x026F4710 | 0x026F4793 | First Network Behavior | 32-bit | - |
...
|
||
buffer | 5 | 0x026F47A0 | 0x026F48E7 | First Network Behavior | 32-bit | - |
...
|
||
buffer | 5 | 0x026F4910 | 0x026F4A23 | First Network Behavior | 32-bit | - |
...
|
||
buffer | 5 | 0x026F4A30 | 0x026F4C13 | First Network Behavior | 32-bit | - |
...
|
||
buffer | 5 | 0x026F4C20 | 0x026F4CCF | First Network Behavior | 32-bit | - |
...
|
||
buffer | 5 | 0x026F4CD8 | 0x026F507B | First Network Behavior | 32-bit | - |
...
|
||
buffer | 5 | 0x026F50A8 | 0x026F51BB | First Network Behavior | 32-bit | - |
...
|
||
buffer | 5 | 0x026F51E0 | 0x026F536F | First Network Behavior | 32-bit | - |
...
|
||
buffer | 5 | 0x026F5378 | 0x026F53FF | First Network Behavior | 32-bit | - |
...
|
||
buffer | 5 | 0x026F5408 | 0x026F5717 | First Network Behavior | 32-bit | - |
...
|
||
buffer | 5 | 0x026F5740 | 0x026F5853 | First Network Behavior | 32-bit | - |
...
|
||
buffer | 5 | 0x026F5878 | 0x026F5A3F | First Network Behavior | 32-bit | - |
...
|
||
buffer | 5 | 0x026F5A48 | 0x026F5AEF | First Network Behavior | 32-bit | - |
...
|
||
buffer | 5 | 0x026F5AF8 | 0x026F5E67 | First Network Behavior | 32-bit | - |
...
|
||
buffer | 5 | 0x026F5F98 | 0x026F608F | First Network Behavior | 32-bit | - |
...
|
||
buffer | 5 | 0x026F6098 | 0x026F61AB | First Network Behavior | 32-bit | - |
...
|
||
buffer | 5 | 0x026F61B8 | 0x026F62E3 | First Network Behavior | 32-bit | - |
...
|
||
buffer | 5 | 0x026F62F0 | 0x026F638F | First Network Behavior | 32-bit | - |
...
|
||
buffer | 5 | 0x026F63B0 | 0x026F644F | First Network Behavior | 32-bit | - |
...
|
||
buffer | 5 | 0x026F64A0 | 0x026F65B3 | First Network Behavior | 32-bit | - |
...
|
||
buffer | 5 | 0x026F6618 | 0x026F6707 | First Network Behavior | 32-bit | - |
...
|
||
buffer | 5 | 0x026F6760 | 0x026F6953 | First Network Behavior | 32-bit | - |
...
|
||
buffer | 5 | 0x026F6980 | 0x026F6A93 | First Network Behavior | 32-bit | - |
...
|
||
buffer | 5 | 0x026F99E8 | 0x026F9B07 | First Network Behavior | 32-bit | - |
...
|
||
buffer | 5 | 0x026F9B10 | 0x026F9D5F | First Network Behavior | 32-bit | - |
...
|
||
buffer | 5 | 0x026F9D68 | 0x026F9E7B | First Network Behavior | 32-bit | - |
...
|
||
buffer | 5 | 0x026F9EB8 | 0x026F9F67 | First Network Behavior | 32-bit | - |
...
|
||
buffer | 5 | 0x026F9FB0 | 0x026FA133 | First Network Behavior | 32-bit | - |
...
|
||
buffer | 5 | 0x026FA948 | 0x026FAA5B | First Network Behavior | 32-bit | - |
...
|
||
buffer | 5 | 0x026FAA98 | 0x026FAB6B | First Network Behavior | 32-bit | - |
...
|
||
buffer | 5 | 0x026FABC8 | 0x026FAD8F | First Network Behavior | 32-bit | - |
...
|
||
buffer | 5 | 0x026FADC8 | 0x026FAE57 | First Network Behavior | 32-bit | - |
...
|
||
buffer | 5 | 0x026FAEE8 | 0x026FAFFB | First Network Behavior | 32-bit | - |
...
|
||
buffer | 5 | 0x026FB210 | 0x026FB2FB | First Network Behavior | 32-bit | - |
...
|
||
buffer | 5 | 0x026FB308 | 0x026FB4FF | First Network Behavior | 32-bit | - |
...
|
||
buffer | 5 | 0x026FB530 | 0x026FB643 | First Network Behavior | 32-bit | - |
...
|
||
buffer | 5 | 0x026FB658 | 0x026FB76B | First Network Behavior | 32-bit | - |
...
|
||
buffer | 5 | 0x026FB780 | 0x026FB893 | First Network Behavior | 32-bit | - |
...
|
||
buffer | 5 | 0x026FB8A8 | 0x026FB9BB | First Network Behavior | 32-bit | - |
...
|
||
buffer | 5 | 0x026FB9D0 | 0x026FBAE3 | First Network Behavior | 32-bit | - |
...
|
||
buffer | 5 | 0x026FBAF8 | 0x026FBC0B | First Network Behavior | 32-bit | - |
...
|
||
buffer | 5 | 0x026FBC20 | 0x026FBD33 | First Network Behavior | 32-bit | - |
...
|
||
buffer | 5 | 0x026FBD48 | 0x026FBE5B | First Network Behavior | 32-bit | - |
...
|
||
buffer | 5 | 0x026FBE70 | 0x026FBF83 | First Network Behavior | 32-bit | - |
...
|
||
buffer | 5 | 0x026FBF98 | 0x026FC0AB | First Network Behavior | 32-bit | - |
...
|
||
buffer | 5 | 0x026FC0C0 | 0x026FC1D3 | First Network Behavior | 32-bit | - |
...
|
||
buffer | 5 | 0x026FC1E8 | 0x026FC2FB | First Network Behavior | 32-bit | - |
...
|
||
buffer | 5 | 0x026FC310 | 0x026FC423 | First Network Behavior | 32-bit | - |
...
|
||
buffer | 5 | 0x026FC510 | 0x026FC5E3 | First Network Behavior | 32-bit | - |
...
|
||
buffer | 5 | 0x026FC648 | 0x026FC80F | First Network Behavior | 32-bit | - |
...
|
||
buffer | 5 | 0x026FC818 | 0x026FC91F | First Network Behavior | 32-bit | - |
...
|
||
buffer | 5 | 0x026FD130 | 0x026FD35F | First Network Behavior | 32-bit | - |
...
|
||
buffer | 5 | 0x026FD368 | 0x026FD46F | First Network Behavior | 32-bit | - |
...
|
||
buffer | 5 | 0x026FD4D8 | 0x026FD707 | First Network Behavior | 32-bit | - |
...
|
||
buffer | 5 | 0x026FD710 | 0x026FD79F | First Network Behavior | 32-bit | - |
...
|
||
buffer | 5 | 0x026FD7D8 | 0x026FD91B | First Network Behavior | 32-bit | - |
...
|
||
buffer | 5 | 0x026FD998 | 0x026FDA93 | First Network Behavior | 32-bit | - |
...
|
||
buffer | 5 | 0x026FDAC8 | 0x026FDC0B | First Network Behavior | 32-bit | - |
...
|
||
buffer | 5 | 0x026FDC18 | 0x026FDCD7 | First Network Behavior | 32-bit | - |
...
|
||
buffer | 5 | 0x026FDD28 | 0x026FDEC7 | First Network Behavior | 32-bit | - |
...
|
||
buffer | 5 | 0x026FDF00 | 0x026FDFC7 | First Network Behavior | 32-bit | - |
...
|
||
buffer | 5 | 0x026FDFD0 | 0x026FE17F | First Network Behavior | 32-bit | - |
...
|
||
buffer | 5 | 0x026FE1B8 | 0x026FE2A3 | First Network Behavior | 32-bit | - |
...
|
||
buffer | 5 | 0x026FE310 | 0x026FE507 | First Network Behavior | 32-bit | - |
...
|
||
buffer | 5 | 0x026FE550 | 0x026FE607 | First Network Behavior | 32-bit | - |
...
|
||
buffer | 5 | 0x026FE670 | 0x026FE773 | First Network Behavior | 32-bit | - |
...
|
||
buffer | 5 | 0x026FE800 | 0x026FE8CF | First Network Behavior | 32-bit | - |
...
|
||
buffer | 5 | 0x026FE908 | 0x026FE99F | First Network Behavior | 32-bit | - |
...
|
||
buffer | 5 | 0x026FE9E8 | 0x026FEB3B | First Network Behavior | 32-bit | - |
...
|
||
buffer | 5 | 0x026FEB48 | 0x026FEC1F | First Network Behavior | 32-bit | - |
...
|
||
buffer | 5 | 0x026FEC70 | 0x026FEE47 | First Network Behavior | 32-bit | - |
...
|
||
buffer | 5 | 0x026FEE50 | 0x026FEFCB | First Network Behavior | 32-bit | - |
...
|
||
buffer | 5 | 0x02701418 | 0x0270152B | First Network Behavior | 32-bit | - |
...
|
||
buffer | 5 | 0x02702098 | 0x02702387 | First Network Behavior | 32-bit | - |
...
|
||
buffer | 5 | 0x02702390 | 0x027024A7 | First Network Behavior | 32-bit | - |
...
|
||
buffer | 5 | 0x027024B0 | 0x027025C7 | First Network Behavior | 32-bit | - |
...
|
||
buffer | 5 | 0x027025D0 | 0x02702CC7 | First Network Behavior | 32-bit | - |
...
|
||
buffer | 5 | 0x02702CD0 | 0x02702DA3 | First Network Behavior | 32-bit | - |
...
|
||
buffer | 5 | 0x02702DB0 | 0x0270519B | First Network Behavior | 32-bit | - |
...
|
||
buffer | 5 | 0x027051A8 | 0x027052AB | First Network Behavior | 32-bit | - |
...
|
||
buffer | 5 | 0x027052B8 | 0x0270540B | First Network Behavior | 32-bit | - |
...
|
||
buffer | 5 | 0x02705418 | 0x02705557 | First Network Behavior | 32-bit | - |
...
|
||
buffer | 5 | 0x02705560 | 0x02705993 | First Network Behavior | 32-bit | - |
...
|
||
buffer | 5 | 0x027059A0 | 0x02705B37 | First Network Behavior | 32-bit | - |
...
|
||
buffer | 5 | 0x02705B40 | 0x02705C83 | First Network Behavior | 32-bit | - |
...
|
||
buffer | 5 | 0x02705C90 | 0x02705DD3 | First Network Behavior | 32-bit | - |
...
|
||
buffer | 5 | 0x02705DE0 | 0x02705F53 | First Network Behavior | 32-bit | - |
...
|
||
buffer | 5 | 0x02705F60 | 0x02706153 | First Network Behavior | 32-bit | - |
...
|
||
buffer | 5 | 0x02706160 | 0x02706903 | First Network Behavior | 32-bit | - |
...
|
||
buffer | 5 | 0x027069A8 | 0x02706AE7 | First Network Behavior | 32-bit | - |
...
|
||
buffer | 5 | 0x02706AF0 | 0x02706F23 | First Network Behavior | 32-bit | - |
...
|
||
buffer | 5 | 0x02706F30 | 0x027070DB | First Network Behavior | 32-bit | - |
...
|
||
buffer | 5 | 0x027070E8 | 0x027071C3 | First Network Behavior | 32-bit | - |
...
|
||
buffer | 5 | 0x027071D0 | 0x027072AB | First Network Behavior | 32-bit | - |
...
|
||
buffer | 5 | 0x027072B8 | 0x02707393 | First Network Behavior | 32-bit | - |
...
|
||
buffer | 5 | 0x02707BA8 | 0x02707CEB | First Network Behavior | 32-bit | - |
...
|
||
buffer | 5 | 0x02707CF8 | 0x02707E3B | First Network Behavior | 32-bit | - |
...
|
||
buffer | 5 | 0x02707E48 | 0x02707F43 | First Network Behavior | 32-bit | - |
...
|
||
explorer.exe | 5 | 0x00400000 | 0x0043DFFF | First Network Behavior | 32-bit | 0x0041E7F2 |
...
|
||
counters.dat | 5 | 0x00510000 | 0x00510FFF | First Network Behavior | 32-bit | - |
...
|
||
buffer | 5 | 0x00460000 | 0x0046FFFF | Final Dump | 32-bit | - |
...
|
||
buffer | 5 | 0x00520F48 | 0x00521747 | Final Dump | 32-bit | - |
...
|
||
buffer | 5 | 0x01F40000 | 0x0233FFFF | Final Dump | 32-bit | - |
...
|
||
buffer | 5 | 0x026F3F98 | 0x026F40AB | Final Dump | 32-bit | - |
...
|
||
buffer | 5 | 0x026F40B8 | 0x026F423B | Final Dump | 32-bit | - |
...
|
||
buffer | 5 | 0x026F42D0 | 0x026F45C7 | Final Dump | 32-bit | - |
...
|
||
buffer | 5 | 0x026F45F0 | 0x026F4703 | Final Dump | 32-bit | - |
...
|
||
buffer | 5 | 0x026F4710 | 0x026F4793 | Final Dump | 32-bit | - |
...
|
||
buffer | 5 | 0x026F47A0 | 0x026F48E7 | Final Dump | 32-bit | - |
...
|
||
buffer | 5 | 0x026F4910 | 0x026F4A23 | Final Dump | 32-bit | - |
...
|
||
buffer | 5 | 0x026F4A30 | 0x026F4C13 | Final Dump | 32-bit | - |
...
|
||
buffer | 5 | 0x026F4C20 | 0x026F4CCF | Final Dump | 32-bit | - |
...
|
||
buffer | 5 | 0x026F4CD8 | 0x026F507B | Final Dump | 32-bit | - |
...
|
||
buffer | 5 | 0x026F50A8 | 0x026F51BB | Final Dump | 32-bit | - |
...
|
||
buffer | 5 | 0x026F51E0 | 0x026F536F | Final Dump | 32-bit | - |
...
|
||
buffer | 5 | 0x026F5378 | 0x026F53FF | Final Dump | 32-bit | - |
...
|
||
buffer | 5 | 0x026F5408 | 0x026F5717 | Final Dump | 32-bit | - |
...
|
||
buffer | 5 | 0x026F5740 | 0x026F5853 | Final Dump | 32-bit | - |
...
|
||
buffer | 5 | 0x026F5878 | 0x026F5A3F | Final Dump | 32-bit | - |
...
|
||
buffer | 5 | 0x026F5A48 | 0x026F5AEF | Final Dump | 32-bit | - |
...
|
||
buffer | 5 | 0x026F5AF8 | 0x026F5E67 | Final Dump | 32-bit | - |
...
|
||
buffer | 5 | 0x026F5F98 | 0x026F608F | Final Dump | 32-bit | - |
...
|
||
buffer | 5 | 0x026F6098 | 0x026F61AB | Final Dump | 32-bit | - |
...
|
||
buffer | 5 | 0x026F61B8 | 0x026F62E3 | Final Dump | 32-bit | - |
...
|
||
buffer | 5 | 0x026F62F0 | 0x026F638F | Final Dump | 32-bit | - |
...
|
||
buffer | 5 | 0x026F63B0 | 0x026F644F | Final Dump | 32-bit | - |
...
|
||
buffer | 5 | 0x026F64A0 | 0x026F65B3 | Final Dump | 32-bit | - |
...
|
||
buffer | 5 | 0x026F6618 | 0x026F6707 | Final Dump | 32-bit | - |
...
|
||
buffer | 5 | 0x026F6760 | 0x026F6953 | Final Dump | 32-bit | - |
...
|
||
buffer | 5 | 0x026F6980 | 0x026F6A93 | Final Dump | 32-bit | - |
...
|
||
buffer | 5 | 0x026F99E8 | 0x026F9B07 | Final Dump | 32-bit | - |
...
|
||
buffer | 5 | 0x026F9B10 | 0x026F9D5F | Final Dump | 32-bit | - |
...
|
||
buffer | 5 | 0x026F9D68 | 0x026F9E7B | Final Dump | 32-bit | - |
...
|
||
buffer | 5 | 0x026F9EB8 | 0x026F9F67 | Final Dump | 32-bit | - |
...
|
||
buffer | 5 | 0x026F9FB0 | 0x026FA133 | Final Dump | 32-bit | - |
...
|
||
buffer | 5 | 0x026FA948 | 0x026FAA5B | Final Dump | 32-bit | - |
...
|
||
buffer | 5 | 0x026FAA98 | 0x026FAB6B | Final Dump | 32-bit | - |
...
|
||
buffer | 5 | 0x026FABC8 | 0x026FAD8F | Final Dump | 32-bit | - |
...
|
||
buffer | 5 | 0x026FADC8 | 0x026FAE57 | Final Dump | 32-bit | - |
...
|
||
buffer | 5 | 0x026FAEE8 | 0x026FAFFB | Final Dump | 32-bit | - |
...
|
||
buffer | 5 | 0x026FB210 | 0x026FB2FB | Final Dump | 32-bit | - |
...
|
||
buffer | 5 | 0x026FB308 | 0x026FB4FF | Final Dump | 32-bit | - |
...
|
||
buffer | 5 | 0x026FB530 | 0x026FB643 | Final Dump | 32-bit | - |
...
|
||
buffer | 5 | 0x026FB658 | 0x026FB76B | Final Dump | 32-bit | - |
...
|
||
buffer | 5 | 0x026FB780 | 0x026FB893 | Final Dump | 32-bit | - |
...
|
||
buffer | 5 | 0x026FB8A8 | 0x026FB9BB | Final Dump | 32-bit | - |
...
|
||
buffer | 5 | 0x026FB9D0 | 0x026FBAE3 | Final Dump | 32-bit | - |
...
|
||
buffer | 5 | 0x026FBAF8 | 0x026FBC0B | Final Dump | 32-bit | - |
...
|
||
buffer | 5 | 0x026FBC20 | 0x026FBD33 | Final Dump | 32-bit | - |
...
|
||
buffer | 5 | 0x026FBD48 | 0x026FBE5B | Final Dump | 32-bit | - |
...
|
||
buffer | 5 | 0x026FBE70 | 0x026FBF83 | Final Dump | 32-bit | - |
...
|
||
buffer | 5 | 0x026FBF98 | 0x026FC0AB | Final Dump | 32-bit | - |
...
|
||
buffer | 5 | 0x026FC0C0 | 0x026FC1D3 | Final Dump | 32-bit | - |
...
|
||
buffer | 5 | 0x026FC1E8 | 0x026FC2FB | Final Dump | 32-bit | - |
...
|
||
buffer | 5 | 0x026FC310 | 0x026FC423 | Final Dump | 32-bit | - |
...
|
||
buffer | 5 | 0x026FC510 | 0x026FC5E3 | Final Dump | 32-bit | - |
...
|
||
buffer | 5 | 0x026FC648 | 0x026FC80F | Final Dump | 32-bit | - |
...
|
||
buffer | 5 | 0x026FC818 | 0x026FC91F | Final Dump | 32-bit | - |
...
|
||
buffer | 5 | 0x026FD130 | 0x026FD35F | Final Dump | 32-bit | - |
...
|
||
buffer | 5 | 0x026FD368 | 0x026FD46F | Final Dump | 32-bit | - |
...
|
||
buffer | 5 | 0x026FD4D8 | 0x026FD707 | Final Dump | 32-bit | - |
...
|
||
buffer | 5 | 0x026FD710 | 0x026FD79F | Final Dump | 32-bit | - |
...
|
||
buffer | 5 | 0x026FD7D8 | 0x026FD91B | Final Dump | 32-bit | - |
...
|
||
buffer | 5 | 0x026FD998 | 0x026FDA93 | Final Dump | 32-bit | - |
...
|
||
buffer | 5 | 0x026FDAC8 | 0x026FDC0B | Final Dump | 32-bit | - |
...
|
||
buffer | 5 | 0x026FDC18 | 0x026FDCD7 | Final Dump | 32-bit | - |
...
|
||
buffer | 5 | 0x026FDD28 | 0x026FDEC7 | Final Dump | 32-bit | - |
...
|
||
buffer | 5 | 0x026FDF00 | 0x026FDFC7 | Final Dump | 32-bit | - |
...
|
||
buffer | 5 | 0x026FDFD0 | 0x026FE17F | Final Dump | 32-bit | - |
...
|
||
buffer | 5 | 0x026FE1B8 | 0x026FE2A3 | Final Dump | 32-bit | - |
...
|
||
buffer | 5 | 0x026FE310 | 0x026FE507 | Final Dump | 32-bit | - |
...
|
||
buffer | 5 | 0x026FE550 | 0x026FE607 | Final Dump | 32-bit | - |
...
|
||
buffer | 5 | 0x026FE670 | 0x026FE773 | Final Dump | 32-bit | - |
...
|
||
buffer | 5 | 0x026FE800 | 0x026FE8CF | Final Dump | 32-bit | - |
...
|
||
buffer | 5 | 0x026FE908 | 0x026FE99F | Final Dump | 32-bit | - |
...
|
||
buffer | 5 | 0x026FE9E8 | 0x026FEB3B | Final Dump | 32-bit | - |
...
|
||
buffer | 5 | 0x026FEB48 | 0x026FEC1F | Final Dump | 32-bit | - |
...
|
||
buffer | 5 | 0x026FEC70 | 0x026FEE47 | Final Dump | 32-bit | - |
...
|
||
buffer | 5 | 0x026FEE50 | 0x026FEFCB | Final Dump | 32-bit | - |
...
|
||
buffer | 5 | 0x02701418 | 0x0270152B | Final Dump | 32-bit | - |
...
|
||
buffer | 5 | 0x02702098 | 0x02702387 | Final Dump | 32-bit | - |
...
|
||
buffer | 5 | 0x02702390 | 0x027024A7 | Final Dump | 32-bit | - |
...
|
||
buffer | 5 | 0x027024B0 | 0x027025C7 | Final Dump | 32-bit | - |
...
|
||
buffer | 5 | 0x027025D0 | 0x02702CC7 | Final Dump | 32-bit | - |
...
|
||
buffer | 5 | 0x02702CD0 | 0x02702DA3 | Final Dump | 32-bit | - |
...
|
||
buffer | 5 | 0x02702DB0 | 0x0270519B | Final Dump | 32-bit | - |
...
|
||
buffer | 5 | 0x027051A8 | 0x027052AB | Final Dump | 32-bit | - |
...
|
||
buffer | 5 | 0x027052B8 | 0x0270540B | Final Dump | 32-bit | - |
...
|
||
buffer | 5 | 0x02705418 | 0x02705557 | Final Dump | 32-bit | - |
...
|
||
buffer | 5 | 0x02705560 | 0x02705993 | Final Dump | 32-bit | - |
...
|
||
buffer | 5 | 0x027059A0 | 0x02705B37 | Final Dump | 32-bit | - |
...
|
||
buffer | 5 | 0x02705B40 | 0x02705C83 | Final Dump | 32-bit | - |
...
|
||
buffer | 5 | 0x02705C90 | 0x02705DD3 | Final Dump | 32-bit | - |
...
|
||
buffer | 5 | 0x02705DE0 | 0x02705F53 | Final Dump | 32-bit | - |
...
|
||
buffer | 5 | 0x02705F60 | 0x02706153 | Final Dump | 32-bit | - |
...
|
||
buffer | 5 | 0x02706160 | 0x02706903 | Final Dump | 32-bit | - |
...
|
||
buffer | 5 | 0x027069A8 | 0x02706AE7 | Final Dump | 32-bit | - |
...
|
||
buffer | 5 | 0x02706AF0 | 0x02706F23 | Final Dump | 32-bit | - |
...
|
||
buffer | 5 | 0x02706F30 | 0x027070DB | Final Dump | 32-bit | - |
...
|
||
buffer | 5 | 0x027070E8 | 0x027071C3 | Final Dump | 32-bit | - |
...
|
||
buffer | 5 | 0x027071D0 | 0x027072AB | Final Dump | 32-bit | - |
...
|
||
buffer | 5 | 0x027072B8 | 0x02707393 | Final Dump | 32-bit | - |
...
|
||
buffer | 5 | 0x02707BA8 | 0x02707CEB | Final Dump | 32-bit | - |
...
|
||
buffer | 5 | 0x02707CF8 | 0x02707E3B | Final Dump | 32-bit | - |
...
|
||
buffer | 5 | 0x02707E48 | 0x02707F43 | Final Dump | 32-bit | - |
...
|
||
explorer.exe | 5 | 0x00400000 | 0x0043DFFF | Final Dump | 32-bit | - |
...
|
||
counters.dat | 5 | 0x00510000 | 0x00510FFF | Final Dump | 32-bit | - |
...
|
c:\windows\system\spoolsv.exe | Dropped File | Binary |
Suspicious
|
...
|
»
PE Information
»
Image Base | 0x00400000 |
Entry Point | 0x00403670 |
Size Of Code | 0x0002B000 |
Size Of Initialized Data | 0x00003000 |
File Type | IMAGE_FILE_EXECUTABLE_IMAGE |
Subsystem | IMAGE_SUBSYSTEM_WINDOWS_GUI |
Machine Type | IMAGE_FILE_MACHINE_I386 |
Compile Timestamp | 2011-06-14 21:01 (UTC+2) |
Version Information (6)
»
CompanyName | Microsoft |
ProductName | Win |
FileVersion | 1.00 |
ProductVersion | 1.00 |
InternalName | Win |
OriginalFilename | Win.exe |
Sections (4)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x00401000 | 0x0002A728 | 0x0002B000 | 0x00001000 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 5.95 |
.data | 0x0042C000 | 0x00001B74 | 0x00001000 | 0x0002C000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.0 |
.rsrc | 0x0042E000 | 0x000005E0 | 0x00001000 | 0x0002D000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 1.69 |
.tdata | 0x0042F000 | 0x0000F000 | 0x0000F000 | 0x0002E000 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.0 |
Imports (1)
»
MSVBVM60.DLL (160)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
EVENT_SINK_GetIDsOfNames | - | 0x00401000 | 0x0002ACAC | 0x0002ACAC | 0x00000000 |
__vbaStrI2 | - | 0x00401004 | 0x0002ACB0 | 0x0002ACB0 | 0x00000000 |
None | 0x000002B2 | 0x00401008 | 0x0002ACB4 | 0x0002ACB4 | - |
_CIcos | - | 0x0040100C | 0x0002ACB8 | 0x0002ACB8 | 0x00000000 |
_adj_fptan | - | 0x00401010 | 0x0002ACBC | 0x0002ACBC | 0x00000000 |
__vbaStrI4 | - | 0x00401014 | 0x0002ACC0 | 0x0002ACC0 | 0x00000000 |
__vbaVarVargNofree | - | 0x00401018 | 0x0002ACC4 | 0x0002ACC4 | 0x00000000 |
__vbaFreeVar | - | 0x0040101C | 0x0002ACC8 | 0x0002ACC8 | 0x00000000 |
__vbaStrVarMove | - | 0x00401020 | 0x0002ACCC | 0x0002ACCC | 0x00000000 |
__vbaLenBstr | - | 0x00401024 | 0x0002ACD0 | 0x0002ACD0 | 0x00000000 |
__vbaLateIdCall | - | 0x00401028 | 0x0002ACD4 | 0x0002ACD4 | 0x00000000 |
__vbaPut3 | - | 0x0040102C | 0x0002ACD8 | 0x0002ACD8 | 0x00000000 |
__vbaEnd | - | 0x00401030 | 0x0002ACDC | 0x0002ACDC | 0x00000000 |
__vbaFreeVarList | - | 0x00401034 | 0x0002ACE0 | 0x0002ACE0 | 0x00000000 |
_adj_fdiv_m64 | - | 0x00401038 | 0x0002ACE4 | 0x0002ACE4 | 0x00000000 |
__vbaPut4 | - | 0x0040103C | 0x0002ACE8 | 0x0002ACE8 | 0x00000000 |
EVENT_SINK_Invoke | - | 0x00401040 | 0x0002ACEC | 0x0002ACEC | 0x00000000 |
__vbaRaiseEvent | - | 0x00401044 | 0x0002ACF0 | 0x0002ACF0 | 0x00000000 |
__vbaFreeObjList | - | 0x00401048 | 0x0002ACF4 | 0x0002ACF4 | 0x00000000 |
None | 0x00000204 | 0x0040104C | 0x0002ACF8 | 0x0002ACF8 | - |
__vbaStrErrVarCopy | - | 0x00401050 | 0x0002ACFC | 0x0002ACFC | 0x00000000 |
None | 0x00000205 | 0x00401054 | 0x0002AD00 | 0x0002AD00 | - |
_adj_fprem1 | - | 0x00401058 | 0x0002AD04 | 0x0002AD04 | 0x00000000 |
__vbaRecAnsiToUni | - | 0x0040105C | 0x0002AD08 | 0x0002AD08 | 0x00000000 |
None | 0x00000207 | 0x00401060 | 0x0002AD0C | 0x0002AD0C | - |
__vbaCopyBytes | - | 0x00401064 | 0x0002AD10 | 0x0002AD10 | 0x00000000 |
__vbaStrCat | - | 0x00401068 | 0x0002AD14 | 0x0002AD14 | 0x00000000 |
__vbaLsetFixstr | - | 0x0040106C | 0x0002AD18 | 0x0002AD18 | 0x00000000 |
__vbaRecDestruct | - | 0x00401070 | 0x0002AD1C | 0x0002AD1C | 0x00000000 |
__vbaSetSystemError | - | 0x00401074 | 0x0002AD20 | 0x0002AD20 | 0x00000000 |
None | 0x00000295 | 0x00401078 | 0x0002AD24 | 0x0002AD24 | - |
__vbaHresultCheckObj | - | 0x0040107C | 0x0002AD28 | 0x0002AD28 | 0x00000000 |
__vbaNameFile | - | 0x00401080 | 0x0002AD2C | 0x0002AD2C | 0x00000000 |
_adj_fdiv_m32 | - | 0x00401084 | 0x0002AD30 | 0x0002AD30 | 0x00000000 |
__vbaAryVar | - | 0x00401088 | 0x0002AD34 | 0x0002AD34 | 0x00000000 |
Zombie_GetTypeInfo | - | 0x0040108C | 0x0002AD38 | 0x0002AD38 | 0x00000000 |
__vbaAryDestruct | - | 0x00401090 | 0x0002AD3C | 0x0002AD3C | 0x00000000 |
None | 0x0000029D | 0x00401094 | 0x0002AD40 | 0x0002AD40 | - |
None | 0x00000251 | 0x00401098 | 0x0002AD44 | 0x0002AD44 | - |
__vbaBoolStr | - | 0x0040109C | 0x0002AD48 | 0x0002AD48 | 0x00000000 |
__vbaExitProc | - | 0x004010A0 | 0x0002AD4C | 0x0002AD4C | 0x00000000 |
__vbaI4Abs | - | 0x004010A4 | 0x0002AD50 | 0x0002AD50 | 0x00000000 |
None | 0x00000252 | 0x004010A8 | 0x0002AD54 | 0x0002AD54 | - |
__vbaOnError | - | 0x004010AC | 0x0002AD58 | 0x0002AD58 | 0x00000000 |
__vbaObjSet | - | 0x004010B0 | 0x0002AD5C | 0x0002AD5C | 0x00000000 |
_adj_fdiv_m16i | - | 0x004010B4 | 0x0002AD60 | 0x0002AD60 | 0x00000000 |
__vbaObjSetAddref | - | 0x004010B8 | 0x0002AD64 | 0x0002AD64 | 0x00000000 |
_adj_fdivr_m16i | - | 0x004010BC | 0x0002AD68 | 0x0002AD68 | 0x00000000 |
None | 0x00000256 | 0x004010C0 | 0x0002AD6C | 0x0002AD6C | - |
__vbaFpR4 | - | 0x004010C4 | 0x0002AD70 | 0x0002AD70 | 0x00000000 |
None | 0x000002C1 | 0x004010C8 | 0x0002AD74 | 0x0002AD74 | - |
__vbaStrFixstr | - | 0x004010CC | 0x0002AD78 | 0x0002AD78 | 0x00000000 |
_CIsin | - | 0x004010D0 | 0x0002AD7C | 0x0002AD7C | 0x00000000 |
__vbaErase | - | 0x004010D4 | 0x0002AD80 | 0x0002AD80 | 0x00000000 |
None | 0x00000277 | 0x004010D8 | 0x0002AD84 | 0x0002AD84 | - |
None | 0x000002C5 | 0x004010DC | 0x0002AD88 | 0x0002AD88 | - |
None | 0x0000020D | 0x004010E0 | 0x0002AD8C | 0x0002AD8C | - |
__vbaChkstk | - | 0x004010E4 | 0x0002AD90 | 0x0002AD90 | 0x00000000 |
__vbaFileClose | - | 0x004010E8 | 0x0002AD94 | 0x0002AD94 | 0x00000000 |
EVENT_SINK_AddRef | - | 0x004010EC | 0x0002AD98 | 0x0002AD98 | 0x00000000 |
__vbaGenerateBoundsError | - | 0x004010F0 | 0x0002AD9C | 0x0002AD9C | 0x00000000 |
__vbaGet3 | - | 0x004010F4 | 0x0002ADA0 | 0x0002ADA0 | 0x00000000 |
__vbaStrCmp | - | 0x004010F8 | 0x0002ADA4 | 0x0002ADA4 | 0x00000000 |
None | 0x00000211 | 0x004010FC | 0x0002ADA8 | 0x0002ADA8 | - |
__vbaGet4 | - | 0x00401100 | 0x0002ADAC | 0x0002ADAC | 0x00000000 |
__vbaPutOwner3 | - | 0x00401104 | 0x0002ADB0 | 0x0002ADB0 | 0x00000000 |
__vbaVarTstEq | - | 0x00401108 | 0x0002ADB4 | 0x0002ADB4 | 0x00000000 |
__vbaAryConstruct2 | - | 0x0040110C | 0x0002ADB8 | 0x0002ADB8 | 0x00000000 |
__vbaObjVar | - | 0x00401110 | 0x0002ADBC | 0x0002ADBC | 0x00000000 |
__vbaI2I4 | - | 0x00401114 | 0x0002ADC0 | 0x0002ADC0 | 0x00000000 |
DllFunctionCall | - | 0x00401118 | 0x0002ADC4 | 0x0002ADC4 | 0x00000000 |
__vbaVarLateMemSt | - | 0x0040111C | 0x0002ADC8 | 0x0002ADC8 | 0x00000000 |
__vbaFpUI1 | - | 0x00401120 | 0x0002ADCC | 0x0002ADCC | 0x00000000 |
__vbaRedimPreserve | - | 0x00401124 | 0x0002ADD0 | 0x0002ADD0 | 0x00000000 |
__vbaStrR4 | - | 0x00401128 | 0x0002ADD4 | 0x0002ADD4 | 0x00000000 |
_adj_fpatan | - | 0x0040112C | 0x0002ADD8 | 0x0002ADD8 | 0x00000000 |
__vbaFixstrConstruct | - | 0x00401130 | 0x0002ADDC | 0x0002ADDC | 0x00000000 |
__vbaLateIdCallLd | - | 0x00401134 | 0x0002ADE0 | 0x0002ADE0 | 0x00000000 |
Zombie_GetTypeInfoCount | - | 0x00401138 | 0x0002ADE4 | 0x0002ADE4 | 0x00000000 |
__vbaRedim | - | 0x0040113C | 0x0002ADE8 | 0x0002ADE8 | 0x00000000 |
__vbaRecUniToAnsi | - | 0x00401140 | 0x0002ADEC | 0x0002ADEC | 0x00000000 |
EVENT_SINK_Release | - | 0x00401144 | 0x0002ADF0 | 0x0002ADF0 | 0x00000000 |
__vbaNew | - | 0x00401148 | 0x0002ADF4 | 0x0002ADF4 | 0x00000000 |
None | 0x00000258 | 0x0040114C | 0x0002ADF8 | 0x0002ADF8 | - |
__vbaUI1I2 | - | 0x00401150 | 0x0002ADFC | 0x0002ADFC | 0x00000000 |
_CIsqrt | - | 0x00401154 | 0x0002AE00 | 0x0002AE00 | 0x00000000 |
EVENT_SINK_QueryInterface | - | 0x00401158 | 0x0002AE04 | 0x0002AE04 | 0x00000000 |
__vbaExceptHandler | - | 0x0040115C | 0x0002AE08 | 0x0002AE08 | 0x00000000 |
None | 0x000002C7 | 0x00401160 | 0x0002AE0C | 0x0002AE0C | - |
None | 0x000002C8 | 0x00401164 | 0x0002AE10 | 0x0002AE10 | - |
__vbaStrToUnicode | - | 0x00401168 | 0x0002AE14 | 0x0002AE14 | 0x00000000 |
None | 0x0000025E | 0x0040116C | 0x0002AE18 | 0x0002AE18 | - |
_adj_fprem | - | 0x00401170 | 0x0002AE1C | 0x0002AE1C | 0x00000000 |
_adj_fdivr_m64 | - | 0x00401174 | 0x0002AE20 | 0x0002AE20 | 0x00000000 |
None | 0x000002CA | 0x00401178 | 0x0002AE24 | 0x0002AE24 | - |
None | 0x000002CC | 0x0040117C | 0x0002AE28 | 0x0002AE28 | - |
None | 0x00000261 | 0x00401180 | 0x0002AE2C | 0x0002AE2C | - |
__vbaFPException | - | 0x00401184 | 0x0002AE30 | 0x0002AE30 | 0x00000000 |
None | 0x000002CD | 0x00401188 | 0x0002AE34 | 0x0002AE34 | - |
None | 0x0000013F | 0x0040118C | 0x0002AE38 | 0x0002AE38 | - |
__vbaGetOwner3 | - | 0x00401190 | 0x0002AE3C | 0x0002AE3C | 0x00000000 |
__vbaUbound | - | 0x00401194 | 0x0002AE40 | 0x0002AE40 | 0x00000000 |
None | 0x00000217 | 0x00401198 | 0x0002AE44 | 0x0002AE44 | - |
__vbaFileSeek | - | 0x0040119C | 0x0002AE48 | 0x0002AE48 | 0x00000000 |
None | 0x00000284 | 0x004011A0 | 0x0002AE4C | 0x0002AE4C | - |
None | 0x00000219 | 0x004011A4 | 0x0002AE50 | 0x0002AE50 | - |
_CIlog | - | 0x004011A8 | 0x0002AE54 | 0x0002AE54 | 0x00000000 |
__vbaErrorOverflow | - | 0x004011AC | 0x0002AE58 | 0x0002AE58 | 0x00000000 |
__vbaFileOpen | - | 0x004011B0 | 0x0002AE5C | 0x0002AE5C | 0x00000000 |
__vbaVarLateMemCallLdRf | - | 0x004011B4 | 0x0002AE60 | 0x0002AE60 | 0x00000000 |
None | 0x00000288 | 0x004011B8 | 0x0002AE64 | 0x0002AE64 | - |
None | 0x0000023A | 0x004011BC | 0x0002AE68 | 0x0002AE68 | - |
__vbaNew2 | - | 0x004011C0 | 0x0002AE6C | 0x0002AE6C | 0x00000000 |
__vbaInStr | - | 0x004011C4 | 0x0002AE70 | 0x0002AE70 | 0x00000000 |
_adj_fdiv_m32i | - | 0x004011C8 | 0x0002AE74 | 0x0002AE74 | 0x00000000 |
None | 0x0000023C | 0x004011CC | 0x0002AE78 | 0x0002AE78 | - |
_adj_fdivr_m32i | - | 0x004011D0 | 0x0002AE7C | 0x0002AE7C | 0x00000000 |
__vbaStrCopy | - | 0x004011D4 | 0x0002AE80 | 0x0002AE80 | 0x00000000 |
__vbaI4Str | - | 0x004011D8 | 0x0002AE84 | 0x0002AE84 | 0x00000000 |
__vbaFreeStrList | - | 0x004011DC | 0x0002AE88 | 0x0002AE88 | 0x00000000 |
_adj_fdivr_m32 | - | 0x004011E0 | 0x0002AE8C | 0x0002AE8C | 0x00000000 |
_adj_fdiv_r | - | 0x004011E4 | 0x0002AE90 | 0x0002AE90 | 0x00000000 |
None | 0x00000242 | 0x004011E8 | 0x0002AE94 | 0x0002AE94 | - |
None | 0x00000064 | 0x004011EC | 0x0002AE98 | 0x0002AE98 | - |
__vbaVarSetVar | - | 0x004011F0 | 0x0002AE9C | 0x0002AE9C | 0x00000000 |
__vbaI4Var | - | 0x004011F4 | 0x0002AEA0 | 0x0002AEA0 | 0x00000000 |
None | 0x000002B1 | 0x004011F8 | 0x0002AEA4 | 0x0002AEA4 | - |
__vbaLateMemCall | - | 0x004011FC | 0x0002AEA8 | 0x0002AEA8 | 0x00000000 |
__vbaVarAdd | - | 0x00401200 | 0x0002AEAC | 0x0002AEAC | 0x00000000 |
None | 0x00000263 | 0x00401204 | 0x0002AEB0 | 0x0002AEB0 | - |
__vbaAryLock | - | 0x00401208 | 0x0002AEB4 | 0x0002AEB4 | 0x00000000 |
None | 0x00000140 | 0x0040120C | 0x0002AEB8 | 0x0002AEB8 | - |
__vbaStrComp | - | 0x00401210 | 0x0002AEBC | 0x0002AEBC | 0x00000000 |
__vbaVarDup | - | 0x00401214 | 0x0002AEC0 | 0x0002AEC0 | 0x00000000 |
__vbaStrToAnsi | - | 0x00401218 | 0x0002AEC4 | 0x0002AEC4 | 0x00000000 |
None | 0x00000141 | 0x0040121C | 0x0002AEC8 | 0x0002AEC8 | - |
__vbaFpI2 | - | 0x00401220 | 0x0002AECC | 0x0002AECC | 0x00000000 |
__vbaFpI4 | - | 0x00401224 | 0x0002AED0 | 0x0002AED0 | 0x00000000 |
__vbaVarLateMemCallLd | - | 0x00401228 | 0x0002AED4 | 0x0002AED4 | 0x00000000 |
None | 0x00000268 | 0x0040122C | 0x0002AED8 | 0x0002AED8 | - |
__vbaVarSetObjAddref | - | 0x00401230 | 0x0002AEDC | 0x0002AEDC | 0x00000000 |
__vbaRecDestructAnsi | - | 0x00401234 | 0x0002AEE0 | 0x0002AEE0 | 0x00000000 |
__vbaLateMemCallLd | - | 0x00401238 | 0x0002AEE4 | 0x0002AEE4 | 0x00000000 |
_CIatan | - | 0x0040123C | 0x0002AEE8 | 0x0002AEE8 | 0x00000000 |
__vbaAryCopy | - | 0x00401240 | 0x0002AEEC | 0x0002AEEC | 0x00000000 |
__vbaStrMove | - | 0x00401244 | 0x0002AEF0 | 0x0002AEF0 | 0x00000000 |
None | 0x0000026A | 0x00401248 | 0x0002AEF4 | 0x0002AEF4 | - |
__vbaCastObj | - | 0x0040124C | 0x0002AEF8 | 0x0002AEF8 | 0x00000000 |
__vbaR8IntI4 | - | 0x00401250 | 0x0002AEFC | 0x0002AEFC | 0x00000000 |
None | 0x0000028A | 0x00401254 | 0x0002AF00 | 0x0002AF00 | - |
_allmul | - | 0x00401258 | 0x0002AF04 | 0x0002AF04 | 0x00000000 |
__vbaVarLateMemCallSt | - | 0x0040125C | 0x0002AF08 | 0x0002AF08 | 0x00000000 |
_CItan | - | 0x00401260 | 0x0002AF0C | 0x0002AF0C | 0x00000000 |
None | 0x00000222 | 0x00401264 | 0x0002AF10 | 0x0002AF10 | - |
__vbaAryUnlock | - | 0x00401268 | 0x0002AF14 | 0x0002AF14 | 0x00000000 |
_CIexp | - | 0x0040126C | 0x0002AF18 | 0x0002AF18 | 0x00000000 |
__vbaFreeObj | - | 0x00401270 | 0x0002AF1C | 0x0002AF1C | 0x00000000 |
__vbaFreeStr | - | 0x00401274 | 0x0002AF20 | 0x0002AF20 | 0x00000000 |
None | 0x00000244 | 0x00401278 | 0x0002AF24 | 0x0002AF24 | - |
None | 0x00000245 | 0x0040127C | 0x0002AF28 | 0x0002AF28 | - |
Memory Dumps (10)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|
spoolsv.exe | 6 | 0x00400000 | 0x0043DFFF | First Execution | 32-bit | 0x00403670 |
...
|
||
buffer | 6 | 0x00610000 | 0x0061FFFF | Marked Executable | 32-bit | - |
...
|
||
buffer | 6 | 0x00610000 | 0x0061FFFF | Content Changed | 32-bit | - |
...
|
||
buffer | 6 | 0x00610000 | 0x0061FFFF | First Execution | 32-bit | 0x00616338 |
...
|
||
spoolsv.exe | 8 | 0x00400000 | 0x0043DFFF | First Execution | 32-bit | 0x0040CF57 |
...
|
||
buffer | 8 | 0x00450000 | 0x0045FFFF | Marked Executable | 32-bit | - |
...
|
||
buffer | 8 | 0x00450000 | 0x0045FFFF | Content Changed | 32-bit | - |
...
|
||
buffer | 8 | 0x00450000 | 0x0045FFFF | Marked Executable | 32-bit | - |
...
|
||
spoolsv.exe | 8 | 0x00400000 | 0x0043DFFF | Process Termination | 32-bit | - |
...
|
||
spoolsv.exe | 6 | 0x00400000 | 0x0043DFFF | Process Termination | 32-bit | - |
...
|
C:\Users\RDhJ0CNFevzX\AppData\Local\icsys.icn.exe | Dropped File | Binary |
Suspicious
|
...
|
»
PE Information
»
Image Base | 0x00400000 |
Entry Point | 0x00403670 |
Size Of Code | 0x0002B000 |
Size Of Initialized Data | 0x00003000 |
File Type | IMAGE_FILE_EXECUTABLE_IMAGE |
Subsystem | IMAGE_SUBSYSTEM_WINDOWS_GUI |
Machine Type | IMAGE_FILE_MACHINE_I386 |
Compile Timestamp | 2011-06-14 21:01 (UTC+2) |
Version Information (6)
»
CompanyName | Microsoft |
ProductName | Win |
FileVersion | 1.00 |
ProductVersion | 1.00 |
InternalName | Win |
OriginalFilename | Win.exe |
Sections (4)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x00401000 | 0x0002A728 | 0x0002B000 | 0x00001000 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 5.95 |
.data | 0x0042C000 | 0x00001B74 | 0x00001000 | 0x0002C000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.0 |
.rsrc | 0x0042E000 | 0x000005E0 | 0x00001000 | 0x0002D000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 1.69 |
.tdata | 0x0042F000 | 0x0000F000 | 0x0000F000 | 0x0002E000 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.0 |
Imports (1)
»
MSVBVM60.DLL (160)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
EVENT_SINK_GetIDsOfNames | - | 0x00401000 | 0x0002ACAC | 0x0002ACAC | 0x00000000 |
__vbaStrI2 | - | 0x00401004 | 0x0002ACB0 | 0x0002ACB0 | 0x00000000 |
None | 0x000002B2 | 0x00401008 | 0x0002ACB4 | 0x0002ACB4 | - |
_CIcos | - | 0x0040100C | 0x0002ACB8 | 0x0002ACB8 | 0x00000000 |
_adj_fptan | - | 0x00401010 | 0x0002ACBC | 0x0002ACBC | 0x00000000 |
__vbaStrI4 | - | 0x00401014 | 0x0002ACC0 | 0x0002ACC0 | 0x00000000 |
__vbaVarVargNofree | - | 0x00401018 | 0x0002ACC4 | 0x0002ACC4 | 0x00000000 |
__vbaFreeVar | - | 0x0040101C | 0x0002ACC8 | 0x0002ACC8 | 0x00000000 |
__vbaStrVarMove | - | 0x00401020 | 0x0002ACCC | 0x0002ACCC | 0x00000000 |
__vbaLenBstr | - | 0x00401024 | 0x0002ACD0 | 0x0002ACD0 | 0x00000000 |
__vbaLateIdCall | - | 0x00401028 | 0x0002ACD4 | 0x0002ACD4 | 0x00000000 |
__vbaPut3 | - | 0x0040102C | 0x0002ACD8 | 0x0002ACD8 | 0x00000000 |
__vbaEnd | - | 0x00401030 | 0x0002ACDC | 0x0002ACDC | 0x00000000 |
__vbaFreeVarList | - | 0x00401034 | 0x0002ACE0 | 0x0002ACE0 | 0x00000000 |
_adj_fdiv_m64 | - | 0x00401038 | 0x0002ACE4 | 0x0002ACE4 | 0x00000000 |
__vbaPut4 | - | 0x0040103C | 0x0002ACE8 | 0x0002ACE8 | 0x00000000 |
EVENT_SINK_Invoke | - | 0x00401040 | 0x0002ACEC | 0x0002ACEC | 0x00000000 |
__vbaRaiseEvent | - | 0x00401044 | 0x0002ACF0 | 0x0002ACF0 | 0x00000000 |
__vbaFreeObjList | - | 0x00401048 | 0x0002ACF4 | 0x0002ACF4 | 0x00000000 |
None | 0x00000204 | 0x0040104C | 0x0002ACF8 | 0x0002ACF8 | - |
__vbaStrErrVarCopy | - | 0x00401050 | 0x0002ACFC | 0x0002ACFC | 0x00000000 |
None | 0x00000205 | 0x00401054 | 0x0002AD00 | 0x0002AD00 | - |
_adj_fprem1 | - | 0x00401058 | 0x0002AD04 | 0x0002AD04 | 0x00000000 |
__vbaRecAnsiToUni | - | 0x0040105C | 0x0002AD08 | 0x0002AD08 | 0x00000000 |
None | 0x00000207 | 0x00401060 | 0x0002AD0C | 0x0002AD0C | - |
__vbaCopyBytes | - | 0x00401064 | 0x0002AD10 | 0x0002AD10 | 0x00000000 |
__vbaStrCat | - | 0x00401068 | 0x0002AD14 | 0x0002AD14 | 0x00000000 |
__vbaLsetFixstr | - | 0x0040106C | 0x0002AD18 | 0x0002AD18 | 0x00000000 |
__vbaRecDestruct | - | 0x00401070 | 0x0002AD1C | 0x0002AD1C | 0x00000000 |
__vbaSetSystemError | - | 0x00401074 | 0x0002AD20 | 0x0002AD20 | 0x00000000 |
None | 0x00000295 | 0x00401078 | 0x0002AD24 | 0x0002AD24 | - |
__vbaHresultCheckObj | - | 0x0040107C | 0x0002AD28 | 0x0002AD28 | 0x00000000 |
__vbaNameFile | - | 0x00401080 | 0x0002AD2C | 0x0002AD2C | 0x00000000 |
_adj_fdiv_m32 | - | 0x00401084 | 0x0002AD30 | 0x0002AD30 | 0x00000000 |
__vbaAryVar | - | 0x00401088 | 0x0002AD34 | 0x0002AD34 | 0x00000000 |
Zombie_GetTypeInfo | - | 0x0040108C | 0x0002AD38 | 0x0002AD38 | 0x00000000 |
__vbaAryDestruct | - | 0x00401090 | 0x0002AD3C | 0x0002AD3C | 0x00000000 |
None | 0x0000029D | 0x00401094 | 0x0002AD40 | 0x0002AD40 | - |
None | 0x00000251 | 0x00401098 | 0x0002AD44 | 0x0002AD44 | - |
__vbaBoolStr | - | 0x0040109C | 0x0002AD48 | 0x0002AD48 | 0x00000000 |
__vbaExitProc | - | 0x004010A0 | 0x0002AD4C | 0x0002AD4C | 0x00000000 |
__vbaI4Abs | - | 0x004010A4 | 0x0002AD50 | 0x0002AD50 | 0x00000000 |
None | 0x00000252 | 0x004010A8 | 0x0002AD54 | 0x0002AD54 | - |
__vbaOnError | - | 0x004010AC | 0x0002AD58 | 0x0002AD58 | 0x00000000 |
__vbaObjSet | - | 0x004010B0 | 0x0002AD5C | 0x0002AD5C | 0x00000000 |
_adj_fdiv_m16i | - | 0x004010B4 | 0x0002AD60 | 0x0002AD60 | 0x00000000 |
__vbaObjSetAddref | - | 0x004010B8 | 0x0002AD64 | 0x0002AD64 | 0x00000000 |
_adj_fdivr_m16i | - | 0x004010BC | 0x0002AD68 | 0x0002AD68 | 0x00000000 |
None | 0x00000256 | 0x004010C0 | 0x0002AD6C | 0x0002AD6C | - |
__vbaFpR4 | - | 0x004010C4 | 0x0002AD70 | 0x0002AD70 | 0x00000000 |
None | 0x000002C1 | 0x004010C8 | 0x0002AD74 | 0x0002AD74 | - |
__vbaStrFixstr | - | 0x004010CC | 0x0002AD78 | 0x0002AD78 | 0x00000000 |
_CIsin | - | 0x004010D0 | 0x0002AD7C | 0x0002AD7C | 0x00000000 |
__vbaErase | - | 0x004010D4 | 0x0002AD80 | 0x0002AD80 | 0x00000000 |
None | 0x00000277 | 0x004010D8 | 0x0002AD84 | 0x0002AD84 | - |
None | 0x000002C5 | 0x004010DC | 0x0002AD88 | 0x0002AD88 | - |
None | 0x0000020D | 0x004010E0 | 0x0002AD8C | 0x0002AD8C | - |
__vbaChkstk | - | 0x004010E4 | 0x0002AD90 | 0x0002AD90 | 0x00000000 |
__vbaFileClose | - | 0x004010E8 | 0x0002AD94 | 0x0002AD94 | 0x00000000 |
EVENT_SINK_AddRef | - | 0x004010EC | 0x0002AD98 | 0x0002AD98 | 0x00000000 |
__vbaGenerateBoundsError | - | 0x004010F0 | 0x0002AD9C | 0x0002AD9C | 0x00000000 |
__vbaGet3 | - | 0x004010F4 | 0x0002ADA0 | 0x0002ADA0 | 0x00000000 |
__vbaStrCmp | - | 0x004010F8 | 0x0002ADA4 | 0x0002ADA4 | 0x00000000 |
None | 0x00000211 | 0x004010FC | 0x0002ADA8 | 0x0002ADA8 | - |
__vbaGet4 | - | 0x00401100 | 0x0002ADAC | 0x0002ADAC | 0x00000000 |
__vbaPutOwner3 | - | 0x00401104 | 0x0002ADB0 | 0x0002ADB0 | 0x00000000 |
__vbaVarTstEq | - | 0x00401108 | 0x0002ADB4 | 0x0002ADB4 | 0x00000000 |
__vbaAryConstruct2 | - | 0x0040110C | 0x0002ADB8 | 0x0002ADB8 | 0x00000000 |
__vbaObjVar | - | 0x00401110 | 0x0002ADBC | 0x0002ADBC | 0x00000000 |
__vbaI2I4 | - | 0x00401114 | 0x0002ADC0 | 0x0002ADC0 | 0x00000000 |
DllFunctionCall | - | 0x00401118 | 0x0002ADC4 | 0x0002ADC4 | 0x00000000 |
__vbaVarLateMemSt | - | 0x0040111C | 0x0002ADC8 | 0x0002ADC8 | 0x00000000 |
__vbaFpUI1 | - | 0x00401120 | 0x0002ADCC | 0x0002ADCC | 0x00000000 |
__vbaRedimPreserve | - | 0x00401124 | 0x0002ADD0 | 0x0002ADD0 | 0x00000000 |
__vbaStrR4 | - | 0x00401128 | 0x0002ADD4 | 0x0002ADD4 | 0x00000000 |
_adj_fpatan | - | 0x0040112C | 0x0002ADD8 | 0x0002ADD8 | 0x00000000 |
__vbaFixstrConstruct | - | 0x00401130 | 0x0002ADDC | 0x0002ADDC | 0x00000000 |
__vbaLateIdCallLd | - | 0x00401134 | 0x0002ADE0 | 0x0002ADE0 | 0x00000000 |
Zombie_GetTypeInfoCount | - | 0x00401138 | 0x0002ADE4 | 0x0002ADE4 | 0x00000000 |
__vbaRedim | - | 0x0040113C | 0x0002ADE8 | 0x0002ADE8 | 0x00000000 |
__vbaRecUniToAnsi | - | 0x00401140 | 0x0002ADEC | 0x0002ADEC | 0x00000000 |
EVENT_SINK_Release | - | 0x00401144 | 0x0002ADF0 | 0x0002ADF0 | 0x00000000 |
__vbaNew | - | 0x00401148 | 0x0002ADF4 | 0x0002ADF4 | 0x00000000 |
None | 0x00000258 | 0x0040114C | 0x0002ADF8 | 0x0002ADF8 | - |
__vbaUI1I2 | - | 0x00401150 | 0x0002ADFC | 0x0002ADFC | 0x00000000 |
_CIsqrt | - | 0x00401154 | 0x0002AE00 | 0x0002AE00 | 0x00000000 |
EVENT_SINK_QueryInterface | - | 0x00401158 | 0x0002AE04 | 0x0002AE04 | 0x00000000 |
__vbaExceptHandler | - | 0x0040115C | 0x0002AE08 | 0x0002AE08 | 0x00000000 |
None | 0x000002C7 | 0x00401160 | 0x0002AE0C | 0x0002AE0C | - |
None | 0x000002C8 | 0x00401164 | 0x0002AE10 | 0x0002AE10 | - |
__vbaStrToUnicode | - | 0x00401168 | 0x0002AE14 | 0x0002AE14 | 0x00000000 |
None | 0x0000025E | 0x0040116C | 0x0002AE18 | 0x0002AE18 | - |
_adj_fprem | - | 0x00401170 | 0x0002AE1C | 0x0002AE1C | 0x00000000 |
_adj_fdivr_m64 | - | 0x00401174 | 0x0002AE20 | 0x0002AE20 | 0x00000000 |
None | 0x000002CA | 0x00401178 | 0x0002AE24 | 0x0002AE24 | - |
None | 0x000002CC | 0x0040117C | 0x0002AE28 | 0x0002AE28 | - |
None | 0x00000261 | 0x00401180 | 0x0002AE2C | 0x0002AE2C | - |
__vbaFPException | - | 0x00401184 | 0x0002AE30 | 0x0002AE30 | 0x00000000 |
None | 0x000002CD | 0x00401188 | 0x0002AE34 | 0x0002AE34 | - |
None | 0x0000013F | 0x0040118C | 0x0002AE38 | 0x0002AE38 | - |
__vbaGetOwner3 | - | 0x00401190 | 0x0002AE3C | 0x0002AE3C | 0x00000000 |
__vbaUbound | - | 0x00401194 | 0x0002AE40 | 0x0002AE40 | 0x00000000 |
None | 0x00000217 | 0x00401198 | 0x0002AE44 | 0x0002AE44 | - |
__vbaFileSeek | - | 0x0040119C | 0x0002AE48 | 0x0002AE48 | 0x00000000 |
None | 0x00000284 | 0x004011A0 | 0x0002AE4C | 0x0002AE4C | - |
None | 0x00000219 | 0x004011A4 | 0x0002AE50 | 0x0002AE50 | - |
_CIlog | - | 0x004011A8 | 0x0002AE54 | 0x0002AE54 | 0x00000000 |
__vbaErrorOverflow | - | 0x004011AC | 0x0002AE58 | 0x0002AE58 | 0x00000000 |
__vbaFileOpen | - | 0x004011B0 | 0x0002AE5C | 0x0002AE5C | 0x00000000 |
__vbaVarLateMemCallLdRf | - | 0x004011B4 | 0x0002AE60 | 0x0002AE60 | 0x00000000 |
None | 0x00000288 | 0x004011B8 | 0x0002AE64 | 0x0002AE64 | - |
None | 0x0000023A | 0x004011BC | 0x0002AE68 | 0x0002AE68 | - |
__vbaNew2 | - | 0x004011C0 | 0x0002AE6C | 0x0002AE6C | 0x00000000 |
__vbaInStr | - | 0x004011C4 | 0x0002AE70 | 0x0002AE70 | 0x00000000 |
_adj_fdiv_m32i | - | 0x004011C8 | 0x0002AE74 | 0x0002AE74 | 0x00000000 |
None | 0x0000023C | 0x004011CC | 0x0002AE78 | 0x0002AE78 | - |
_adj_fdivr_m32i | - | 0x004011D0 | 0x0002AE7C | 0x0002AE7C | 0x00000000 |
__vbaStrCopy | - | 0x004011D4 | 0x0002AE80 | 0x0002AE80 | 0x00000000 |
__vbaI4Str | - | 0x004011D8 | 0x0002AE84 | 0x0002AE84 | 0x00000000 |
__vbaFreeStrList | - | 0x004011DC | 0x0002AE88 | 0x0002AE88 | 0x00000000 |
_adj_fdivr_m32 | - | 0x004011E0 | 0x0002AE8C | 0x0002AE8C | 0x00000000 |
_adj_fdiv_r | - | 0x004011E4 | 0x0002AE90 | 0x0002AE90 | 0x00000000 |
None | 0x00000242 | 0x004011E8 | 0x0002AE94 | 0x0002AE94 | - |
None | 0x00000064 | 0x004011EC | 0x0002AE98 | 0x0002AE98 | - |
__vbaVarSetVar | - | 0x004011F0 | 0x0002AE9C | 0x0002AE9C | 0x00000000 |
__vbaI4Var | - | 0x004011F4 | 0x0002AEA0 | 0x0002AEA0 | 0x00000000 |
None | 0x000002B1 | 0x004011F8 | 0x0002AEA4 | 0x0002AEA4 | - |
__vbaLateMemCall | - | 0x004011FC | 0x0002AEA8 | 0x0002AEA8 | 0x00000000 |
__vbaVarAdd | - | 0x00401200 | 0x0002AEAC | 0x0002AEAC | 0x00000000 |
None | 0x00000263 | 0x00401204 | 0x0002AEB0 | 0x0002AEB0 | - |
__vbaAryLock | - | 0x00401208 | 0x0002AEB4 | 0x0002AEB4 | 0x00000000 |
None | 0x00000140 | 0x0040120C | 0x0002AEB8 | 0x0002AEB8 | - |
__vbaStrComp | - | 0x00401210 | 0x0002AEBC | 0x0002AEBC | 0x00000000 |
__vbaVarDup | - | 0x00401214 | 0x0002AEC0 | 0x0002AEC0 | 0x00000000 |
__vbaStrToAnsi | - | 0x00401218 | 0x0002AEC4 | 0x0002AEC4 | 0x00000000 |
None | 0x00000141 | 0x0040121C | 0x0002AEC8 | 0x0002AEC8 | - |
__vbaFpI2 | - | 0x00401220 | 0x0002AECC | 0x0002AECC | 0x00000000 |
__vbaFpI4 | - | 0x00401224 | 0x0002AED0 | 0x0002AED0 | 0x00000000 |
__vbaVarLateMemCallLd | - | 0x00401228 | 0x0002AED4 | 0x0002AED4 | 0x00000000 |
None | 0x00000268 | 0x0040122C | 0x0002AED8 | 0x0002AED8 | - |
__vbaVarSetObjAddref | - | 0x00401230 | 0x0002AEDC | 0x0002AEDC | 0x00000000 |
__vbaRecDestructAnsi | - | 0x00401234 | 0x0002AEE0 | 0x0002AEE0 | 0x00000000 |
__vbaLateMemCallLd | - | 0x00401238 | 0x0002AEE4 | 0x0002AEE4 | 0x00000000 |
_CIatan | - | 0x0040123C | 0x0002AEE8 | 0x0002AEE8 | 0x00000000 |
__vbaAryCopy | - | 0x00401240 | 0x0002AEEC | 0x0002AEEC | 0x00000000 |
__vbaStrMove | - | 0x00401244 | 0x0002AEF0 | 0x0002AEF0 | 0x00000000 |
None | 0x0000026A | 0x00401248 | 0x0002AEF4 | 0x0002AEF4 | - |
__vbaCastObj | - | 0x0040124C | 0x0002AEF8 | 0x0002AEF8 | 0x00000000 |
__vbaR8IntI4 | - | 0x00401250 | 0x0002AEFC | 0x0002AEFC | 0x00000000 |
None | 0x0000028A | 0x00401254 | 0x0002AF00 | 0x0002AF00 | - |
_allmul | - | 0x00401258 | 0x0002AF04 | 0x0002AF04 | 0x00000000 |
__vbaVarLateMemCallSt | - | 0x0040125C | 0x0002AF08 | 0x0002AF08 | 0x00000000 |
_CItan | - | 0x00401260 | 0x0002AF0C | 0x0002AF0C | 0x00000000 |
None | 0x00000222 | 0x00401264 | 0x0002AF10 | 0x0002AF10 | - |
__vbaAryUnlock | - | 0x00401268 | 0x0002AF14 | 0x0002AF14 | 0x00000000 |
_CIexp | - | 0x0040126C | 0x0002AF18 | 0x0002AF18 | 0x00000000 |
__vbaFreeObj | - | 0x00401270 | 0x0002AF1C | 0x0002AF1C | 0x00000000 |
__vbaFreeStr | - | 0x00401274 | 0x0002AF20 | 0x0002AF20 | 0x00000000 |
None | 0x00000244 | 0x00401278 | 0x0002AF24 | 0x0002AF24 | - |
None | 0x00000245 | 0x0040127C | 0x0002AF28 | 0x0002AF28 | - |
Memory Dumps (5)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|
icsys.icn.exe | 4 | 0x00400000 | 0x0043DFFF | First Execution | 32-bit | 0x00403670 |
...
|
||
buffer | 4 | 0x00450000 | 0x0045FFFF | Marked Executable | 32-bit | - |
...
|
||
buffer | 4 | 0x00450000 | 0x0045FFFF | Content Changed | 32-bit | - |
...
|
||
buffer | 4 | 0x00450000 | 0x0045FFFF | First Execution | 32-bit | 0x00456338 |
...
|
||
icsys.icn.exe | 4 | 0x00400000 | 0x0043DFFF | Process Termination | 32-bit | - |
...
|
C:\Users\RDhJ0CNFevzX\AppData\Roaming\mrsys.exe | Dropped File | Binary |
Clean
|
...
|
»
PE Information
»
Image Base | 0x00400000 |
Entry Point | 0x00403670 |
Size Of Code | 0x0002B000 |
Size Of Initialized Data | 0x00003000 |
File Type | IMAGE_FILE_EXECUTABLE_IMAGE |
Subsystem | IMAGE_SUBSYSTEM_WINDOWS_GUI |
Machine Type | IMAGE_FILE_MACHINE_I386 |
Compile Timestamp | 2011-06-14 21:01 (UTC+2) |
Version Information (6)
»
CompanyName | Microsoft |
ProductName | Win |
FileVersion | 1.00 |
ProductVersion | 1.00 |
InternalName | Win |
OriginalFilename | Win.exe |
Sections (4)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x00401000 | 0x0002A728 | 0x0002B000 | 0x00001000 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 5.95 |
.data | 0x0042C000 | 0x00001B74 | 0x00001000 | 0x0002C000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.0 |
.rsrc | 0x0042E000 | 0x000005E0 | 0x00001000 | 0x0002D000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 1.69 |
.tdata | 0x0042F000 | 0x0000F000 | 0x0000F000 | 0x0002E000 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.0 |
Imports (1)
»
MSVBVM60.DLL (160)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
EVENT_SINK_GetIDsOfNames | - | 0x00401000 | 0x0002ACAC | 0x0002ACAC | 0x00000000 |
__vbaStrI2 | - | 0x00401004 | 0x0002ACB0 | 0x0002ACB0 | 0x00000000 |
None | 0x000002B2 | 0x00401008 | 0x0002ACB4 | 0x0002ACB4 | - |
_CIcos | - | 0x0040100C | 0x0002ACB8 | 0x0002ACB8 | 0x00000000 |
_adj_fptan | - | 0x00401010 | 0x0002ACBC | 0x0002ACBC | 0x00000000 |
__vbaStrI4 | - | 0x00401014 | 0x0002ACC0 | 0x0002ACC0 | 0x00000000 |
__vbaVarVargNofree | - | 0x00401018 | 0x0002ACC4 | 0x0002ACC4 | 0x00000000 |
__vbaFreeVar | - | 0x0040101C | 0x0002ACC8 | 0x0002ACC8 | 0x00000000 |
__vbaStrVarMove | - | 0x00401020 | 0x0002ACCC | 0x0002ACCC | 0x00000000 |
__vbaLenBstr | - | 0x00401024 | 0x0002ACD0 | 0x0002ACD0 | 0x00000000 |
__vbaLateIdCall | - | 0x00401028 | 0x0002ACD4 | 0x0002ACD4 | 0x00000000 |
__vbaPut3 | - | 0x0040102C | 0x0002ACD8 | 0x0002ACD8 | 0x00000000 |
__vbaEnd | - | 0x00401030 | 0x0002ACDC | 0x0002ACDC | 0x00000000 |
__vbaFreeVarList | - | 0x00401034 | 0x0002ACE0 | 0x0002ACE0 | 0x00000000 |
_adj_fdiv_m64 | - | 0x00401038 | 0x0002ACE4 | 0x0002ACE4 | 0x00000000 |
__vbaPut4 | - | 0x0040103C | 0x0002ACE8 | 0x0002ACE8 | 0x00000000 |
EVENT_SINK_Invoke | - | 0x00401040 | 0x0002ACEC | 0x0002ACEC | 0x00000000 |
__vbaRaiseEvent | - | 0x00401044 | 0x0002ACF0 | 0x0002ACF0 | 0x00000000 |
__vbaFreeObjList | - | 0x00401048 | 0x0002ACF4 | 0x0002ACF4 | 0x00000000 |
None | 0x00000204 | 0x0040104C | 0x0002ACF8 | 0x0002ACF8 | - |
__vbaStrErrVarCopy | - | 0x00401050 | 0x0002ACFC | 0x0002ACFC | 0x00000000 |
None | 0x00000205 | 0x00401054 | 0x0002AD00 | 0x0002AD00 | - |
_adj_fprem1 | - | 0x00401058 | 0x0002AD04 | 0x0002AD04 | 0x00000000 |
__vbaRecAnsiToUni | - | 0x0040105C | 0x0002AD08 | 0x0002AD08 | 0x00000000 |
None | 0x00000207 | 0x00401060 | 0x0002AD0C | 0x0002AD0C | - |
__vbaCopyBytes | - | 0x00401064 | 0x0002AD10 | 0x0002AD10 | 0x00000000 |
__vbaStrCat | - | 0x00401068 | 0x0002AD14 | 0x0002AD14 | 0x00000000 |
__vbaLsetFixstr | - | 0x0040106C | 0x0002AD18 | 0x0002AD18 | 0x00000000 |
__vbaRecDestruct | - | 0x00401070 | 0x0002AD1C | 0x0002AD1C | 0x00000000 |
__vbaSetSystemError | - | 0x00401074 | 0x0002AD20 | 0x0002AD20 | 0x00000000 |
None | 0x00000295 | 0x00401078 | 0x0002AD24 | 0x0002AD24 | - |
__vbaHresultCheckObj | - | 0x0040107C | 0x0002AD28 | 0x0002AD28 | 0x00000000 |
__vbaNameFile | - | 0x00401080 | 0x0002AD2C | 0x0002AD2C | 0x00000000 |
_adj_fdiv_m32 | - | 0x00401084 | 0x0002AD30 | 0x0002AD30 | 0x00000000 |
__vbaAryVar | - | 0x00401088 | 0x0002AD34 | 0x0002AD34 | 0x00000000 |
Zombie_GetTypeInfo | - | 0x0040108C | 0x0002AD38 | 0x0002AD38 | 0x00000000 |
__vbaAryDestruct | - | 0x00401090 | 0x0002AD3C | 0x0002AD3C | 0x00000000 |
None | 0x0000029D | 0x00401094 | 0x0002AD40 | 0x0002AD40 | - |
None | 0x00000251 | 0x00401098 | 0x0002AD44 | 0x0002AD44 | - |
__vbaBoolStr | - | 0x0040109C | 0x0002AD48 | 0x0002AD48 | 0x00000000 |
__vbaExitProc | - | 0x004010A0 | 0x0002AD4C | 0x0002AD4C | 0x00000000 |
__vbaI4Abs | - | 0x004010A4 | 0x0002AD50 | 0x0002AD50 | 0x00000000 |
None | 0x00000252 | 0x004010A8 | 0x0002AD54 | 0x0002AD54 | - |
__vbaOnError | - | 0x004010AC | 0x0002AD58 | 0x0002AD58 | 0x00000000 |
__vbaObjSet | - | 0x004010B0 | 0x0002AD5C | 0x0002AD5C | 0x00000000 |
_adj_fdiv_m16i | - | 0x004010B4 | 0x0002AD60 | 0x0002AD60 | 0x00000000 |
__vbaObjSetAddref | - | 0x004010B8 | 0x0002AD64 | 0x0002AD64 | 0x00000000 |
_adj_fdivr_m16i | - | 0x004010BC | 0x0002AD68 | 0x0002AD68 | 0x00000000 |
None | 0x00000256 | 0x004010C0 | 0x0002AD6C | 0x0002AD6C | - |
__vbaFpR4 | - | 0x004010C4 | 0x0002AD70 | 0x0002AD70 | 0x00000000 |
None | 0x000002C1 | 0x004010C8 | 0x0002AD74 | 0x0002AD74 | - |
__vbaStrFixstr | - | 0x004010CC | 0x0002AD78 | 0x0002AD78 | 0x00000000 |
_CIsin | - | 0x004010D0 | 0x0002AD7C | 0x0002AD7C | 0x00000000 |
__vbaErase | - | 0x004010D4 | 0x0002AD80 | 0x0002AD80 | 0x00000000 |
None | 0x00000277 | 0x004010D8 | 0x0002AD84 | 0x0002AD84 | - |
None | 0x000002C5 | 0x004010DC | 0x0002AD88 | 0x0002AD88 | - |
None | 0x0000020D | 0x004010E0 | 0x0002AD8C | 0x0002AD8C | - |
__vbaChkstk | - | 0x004010E4 | 0x0002AD90 | 0x0002AD90 | 0x00000000 |
__vbaFileClose | - | 0x004010E8 | 0x0002AD94 | 0x0002AD94 | 0x00000000 |
EVENT_SINK_AddRef | - | 0x004010EC | 0x0002AD98 | 0x0002AD98 | 0x00000000 |
__vbaGenerateBoundsError | - | 0x004010F0 | 0x0002AD9C | 0x0002AD9C | 0x00000000 |
__vbaGet3 | - | 0x004010F4 | 0x0002ADA0 | 0x0002ADA0 | 0x00000000 |
__vbaStrCmp | - | 0x004010F8 | 0x0002ADA4 | 0x0002ADA4 | 0x00000000 |
None | 0x00000211 | 0x004010FC | 0x0002ADA8 | 0x0002ADA8 | - |
__vbaGet4 | - | 0x00401100 | 0x0002ADAC | 0x0002ADAC | 0x00000000 |
__vbaPutOwner3 | - | 0x00401104 | 0x0002ADB0 | 0x0002ADB0 | 0x00000000 |
__vbaVarTstEq | - | 0x00401108 | 0x0002ADB4 | 0x0002ADB4 | 0x00000000 |
__vbaAryConstruct2 | - | 0x0040110C | 0x0002ADB8 | 0x0002ADB8 | 0x00000000 |
__vbaObjVar | - | 0x00401110 | 0x0002ADBC | 0x0002ADBC | 0x00000000 |
__vbaI2I4 | - | 0x00401114 | 0x0002ADC0 | 0x0002ADC0 | 0x00000000 |
DllFunctionCall | - | 0x00401118 | 0x0002ADC4 | 0x0002ADC4 | 0x00000000 |
__vbaVarLateMemSt | - | 0x0040111C | 0x0002ADC8 | 0x0002ADC8 | 0x00000000 |
__vbaFpUI1 | - | 0x00401120 | 0x0002ADCC | 0x0002ADCC | 0x00000000 |
__vbaRedimPreserve | - | 0x00401124 | 0x0002ADD0 | 0x0002ADD0 | 0x00000000 |
__vbaStrR4 | - | 0x00401128 | 0x0002ADD4 | 0x0002ADD4 | 0x00000000 |
_adj_fpatan | - | 0x0040112C | 0x0002ADD8 | 0x0002ADD8 | 0x00000000 |
__vbaFixstrConstruct | - | 0x00401130 | 0x0002ADDC | 0x0002ADDC | 0x00000000 |
__vbaLateIdCallLd | - | 0x00401134 | 0x0002ADE0 | 0x0002ADE0 | 0x00000000 |
Zombie_GetTypeInfoCount | - | 0x00401138 | 0x0002ADE4 | 0x0002ADE4 | 0x00000000 |
__vbaRedim | - | 0x0040113C | 0x0002ADE8 | 0x0002ADE8 | 0x00000000 |
__vbaRecUniToAnsi | - | 0x00401140 | 0x0002ADEC | 0x0002ADEC | 0x00000000 |
EVENT_SINK_Release | - | 0x00401144 | 0x0002ADF0 | 0x0002ADF0 | 0x00000000 |
__vbaNew | - | 0x00401148 | 0x0002ADF4 | 0x0002ADF4 | 0x00000000 |
None | 0x00000258 | 0x0040114C | 0x0002ADF8 | 0x0002ADF8 | - |
__vbaUI1I2 | - | 0x00401150 | 0x0002ADFC | 0x0002ADFC | 0x00000000 |
_CIsqrt | - | 0x00401154 | 0x0002AE00 | 0x0002AE00 | 0x00000000 |
EVENT_SINK_QueryInterface | - | 0x00401158 | 0x0002AE04 | 0x0002AE04 | 0x00000000 |
__vbaExceptHandler | - | 0x0040115C | 0x0002AE08 | 0x0002AE08 | 0x00000000 |
None | 0x000002C7 | 0x00401160 | 0x0002AE0C | 0x0002AE0C | - |
None | 0x000002C8 | 0x00401164 | 0x0002AE10 | 0x0002AE10 | - |
__vbaStrToUnicode | - | 0x00401168 | 0x0002AE14 | 0x0002AE14 | 0x00000000 |
None | 0x0000025E | 0x0040116C | 0x0002AE18 | 0x0002AE18 | - |
_adj_fprem | - | 0x00401170 | 0x0002AE1C | 0x0002AE1C | 0x00000000 |
_adj_fdivr_m64 | - | 0x00401174 | 0x0002AE20 | 0x0002AE20 | 0x00000000 |
None | 0x000002CA | 0x00401178 | 0x0002AE24 | 0x0002AE24 | - |
None | 0x000002CC | 0x0040117C | 0x0002AE28 | 0x0002AE28 | - |
None | 0x00000261 | 0x00401180 | 0x0002AE2C | 0x0002AE2C | - |
__vbaFPException | - | 0x00401184 | 0x0002AE30 | 0x0002AE30 | 0x00000000 |
None | 0x000002CD | 0x00401188 | 0x0002AE34 | 0x0002AE34 | - |
None | 0x0000013F | 0x0040118C | 0x0002AE38 | 0x0002AE38 | - |
__vbaGetOwner3 | - | 0x00401190 | 0x0002AE3C | 0x0002AE3C | 0x00000000 |
__vbaUbound | - | 0x00401194 | 0x0002AE40 | 0x0002AE40 | 0x00000000 |
None | 0x00000217 | 0x00401198 | 0x0002AE44 | 0x0002AE44 | - |
__vbaFileSeek | - | 0x0040119C | 0x0002AE48 | 0x0002AE48 | 0x00000000 |
None | 0x00000284 | 0x004011A0 | 0x0002AE4C | 0x0002AE4C | - |
None | 0x00000219 | 0x004011A4 | 0x0002AE50 | 0x0002AE50 | - |
_CIlog | - | 0x004011A8 | 0x0002AE54 | 0x0002AE54 | 0x00000000 |
__vbaErrorOverflow | - | 0x004011AC | 0x0002AE58 | 0x0002AE58 | 0x00000000 |
__vbaFileOpen | - | 0x004011B0 | 0x0002AE5C | 0x0002AE5C | 0x00000000 |
__vbaVarLateMemCallLdRf | - | 0x004011B4 | 0x0002AE60 | 0x0002AE60 | 0x00000000 |
None | 0x00000288 | 0x004011B8 | 0x0002AE64 | 0x0002AE64 | - |
None | 0x0000023A | 0x004011BC | 0x0002AE68 | 0x0002AE68 | - |
__vbaNew2 | - | 0x004011C0 | 0x0002AE6C | 0x0002AE6C | 0x00000000 |
__vbaInStr | - | 0x004011C4 | 0x0002AE70 | 0x0002AE70 | 0x00000000 |
_adj_fdiv_m32i | - | 0x004011C8 | 0x0002AE74 | 0x0002AE74 | 0x00000000 |
None | 0x0000023C | 0x004011CC | 0x0002AE78 | 0x0002AE78 | - |
_adj_fdivr_m32i | - | 0x004011D0 | 0x0002AE7C | 0x0002AE7C | 0x00000000 |
__vbaStrCopy | - | 0x004011D4 | 0x0002AE80 | 0x0002AE80 | 0x00000000 |
__vbaI4Str | - | 0x004011D8 | 0x0002AE84 | 0x0002AE84 | 0x00000000 |
__vbaFreeStrList | - | 0x004011DC | 0x0002AE88 | 0x0002AE88 | 0x00000000 |
_adj_fdivr_m32 | - | 0x004011E0 | 0x0002AE8C | 0x0002AE8C | 0x00000000 |
_adj_fdiv_r | - | 0x004011E4 | 0x0002AE90 | 0x0002AE90 | 0x00000000 |
None | 0x00000242 | 0x004011E8 | 0x0002AE94 | 0x0002AE94 | - |
None | 0x00000064 | 0x004011EC | 0x0002AE98 | 0x0002AE98 | - |
__vbaVarSetVar | - | 0x004011F0 | 0x0002AE9C | 0x0002AE9C | 0x00000000 |
__vbaI4Var | - | 0x004011F4 | 0x0002AEA0 | 0x0002AEA0 | 0x00000000 |
None | 0x000002B1 | 0x004011F8 | 0x0002AEA4 | 0x0002AEA4 | - |
__vbaLateMemCall | - | 0x004011FC | 0x0002AEA8 | 0x0002AEA8 | 0x00000000 |
__vbaVarAdd | - | 0x00401200 | 0x0002AEAC | 0x0002AEAC | 0x00000000 |
None | 0x00000263 | 0x00401204 | 0x0002AEB0 | 0x0002AEB0 | - |
__vbaAryLock | - | 0x00401208 | 0x0002AEB4 | 0x0002AEB4 | 0x00000000 |
None | 0x00000140 | 0x0040120C | 0x0002AEB8 | 0x0002AEB8 | - |
__vbaStrComp | - | 0x00401210 | 0x0002AEBC | 0x0002AEBC | 0x00000000 |
__vbaVarDup | - | 0x00401214 | 0x0002AEC0 | 0x0002AEC0 | 0x00000000 |
__vbaStrToAnsi | - | 0x00401218 | 0x0002AEC4 | 0x0002AEC4 | 0x00000000 |
None | 0x00000141 | 0x0040121C | 0x0002AEC8 | 0x0002AEC8 | - |
__vbaFpI2 | - | 0x00401220 | 0x0002AECC | 0x0002AECC | 0x00000000 |
__vbaFpI4 | - | 0x00401224 | 0x0002AED0 | 0x0002AED0 | 0x00000000 |
__vbaVarLateMemCallLd | - | 0x00401228 | 0x0002AED4 | 0x0002AED4 | 0x00000000 |
None | 0x00000268 | 0x0040122C | 0x0002AED8 | 0x0002AED8 | - |
__vbaVarSetObjAddref | - | 0x00401230 | 0x0002AEDC | 0x0002AEDC | 0x00000000 |
__vbaRecDestructAnsi | - | 0x00401234 | 0x0002AEE0 | 0x0002AEE0 | 0x00000000 |
__vbaLateMemCallLd | - | 0x00401238 | 0x0002AEE4 | 0x0002AEE4 | 0x00000000 |
_CIatan | - | 0x0040123C | 0x0002AEE8 | 0x0002AEE8 | 0x00000000 |
__vbaAryCopy | - | 0x00401240 | 0x0002AEEC | 0x0002AEEC | 0x00000000 |
__vbaStrMove | - | 0x00401244 | 0x0002AEF0 | 0x0002AEF0 | 0x00000000 |
None | 0x0000026A | 0x00401248 | 0x0002AEF4 | 0x0002AEF4 | - |
__vbaCastObj | - | 0x0040124C | 0x0002AEF8 | 0x0002AEF8 | 0x00000000 |
__vbaR8IntI4 | - | 0x00401250 | 0x0002AEFC | 0x0002AEFC | 0x00000000 |
None | 0x0000028A | 0x00401254 | 0x0002AF00 | 0x0002AF00 | - |
_allmul | - | 0x00401258 | 0x0002AF04 | 0x0002AF04 | 0x00000000 |
__vbaVarLateMemCallSt | - | 0x0040125C | 0x0002AF08 | 0x0002AF08 | 0x00000000 |
_CItan | - | 0x00401260 | 0x0002AF0C | 0x0002AF0C | 0x00000000 |
None | 0x00000222 | 0x00401264 | 0x0002AF10 | 0x0002AF10 | - |
__vbaAryUnlock | - | 0x00401268 | 0x0002AF14 | 0x0002AF14 | 0x00000000 |
_CIexp | - | 0x0040126C | 0x0002AF18 | 0x0002AF18 | 0x00000000 |
__vbaFreeObj | - | 0x00401270 | 0x0002AF1C | 0x0002AF1C | 0x00000000 |
__vbaFreeStr | - | 0x00401274 | 0x0002AF20 | 0x0002AF20 | 0x00000000 |
None | 0x00000244 | 0x00401278 | 0x0002AF24 | 0x0002AF24 | - |
None | 0x00000245 | 0x0040127C | 0x0002AF28 | 0x0002AF28 | - |
C:\Users\RDhJ0CNFevzX\AppData\Local\stsys.exe | Dropped File | Binary |
Clean
|
...
|
»
PE Information
»
Image Base | 0x00400000 |
Entry Point | 0x00403670 |
Size Of Code | 0x0002B000 |
Size Of Initialized Data | 0x00003000 |
File Type | IMAGE_FILE_EXECUTABLE_IMAGE |
Subsystem | IMAGE_SUBSYSTEM_WINDOWS_GUI |
Machine Type | IMAGE_FILE_MACHINE_I386 |
Compile Timestamp | 2011-06-14 21:01 (UTC+2) |
Version Information (6)
»
CompanyName | Microsoft |
ProductName | Win |
FileVersion | 1.00 |
ProductVersion | 1.00 |
InternalName | Win |
OriginalFilename | Win.exe |
Sections (4)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x00401000 | 0x0002A728 | 0x0002B000 | 0x00001000 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 5.95 |
.data | 0x0042C000 | 0x00001B74 | 0x00001000 | 0x0002C000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.0 |
.rsrc | 0x0042E000 | 0x000005E0 | 0x00001000 | 0x0002D000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 1.69 |
.tdata | 0x0042F000 | 0x0000F000 | 0x0000F000 | 0x0002E000 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.0 |
Imports (1)
»
MSVBVM60.DLL (160)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
EVENT_SINK_GetIDsOfNames | - | 0x00401000 | 0x0002ACAC | 0x0002ACAC | 0x00000000 |
__vbaStrI2 | - | 0x00401004 | 0x0002ACB0 | 0x0002ACB0 | 0x00000000 |
None | 0x000002B2 | 0x00401008 | 0x0002ACB4 | 0x0002ACB4 | - |
_CIcos | - | 0x0040100C | 0x0002ACB8 | 0x0002ACB8 | 0x00000000 |
_adj_fptan | - | 0x00401010 | 0x0002ACBC | 0x0002ACBC | 0x00000000 |
__vbaStrI4 | - | 0x00401014 | 0x0002ACC0 | 0x0002ACC0 | 0x00000000 |
__vbaVarVargNofree | - | 0x00401018 | 0x0002ACC4 | 0x0002ACC4 | 0x00000000 |
__vbaFreeVar | - | 0x0040101C | 0x0002ACC8 | 0x0002ACC8 | 0x00000000 |
__vbaStrVarMove | - | 0x00401020 | 0x0002ACCC | 0x0002ACCC | 0x00000000 |
__vbaLenBstr | - | 0x00401024 | 0x0002ACD0 | 0x0002ACD0 | 0x00000000 |
__vbaLateIdCall | - | 0x00401028 | 0x0002ACD4 | 0x0002ACD4 | 0x00000000 |
__vbaPut3 | - | 0x0040102C | 0x0002ACD8 | 0x0002ACD8 | 0x00000000 |
__vbaEnd | - | 0x00401030 | 0x0002ACDC | 0x0002ACDC | 0x00000000 |
__vbaFreeVarList | - | 0x00401034 | 0x0002ACE0 | 0x0002ACE0 | 0x00000000 |
_adj_fdiv_m64 | - | 0x00401038 | 0x0002ACE4 | 0x0002ACE4 | 0x00000000 |
__vbaPut4 | - | 0x0040103C | 0x0002ACE8 | 0x0002ACE8 | 0x00000000 |
EVENT_SINK_Invoke | - | 0x00401040 | 0x0002ACEC | 0x0002ACEC | 0x00000000 |
__vbaRaiseEvent | - | 0x00401044 | 0x0002ACF0 | 0x0002ACF0 | 0x00000000 |
__vbaFreeObjList | - | 0x00401048 | 0x0002ACF4 | 0x0002ACF4 | 0x00000000 |
None | 0x00000204 | 0x0040104C | 0x0002ACF8 | 0x0002ACF8 | - |
__vbaStrErrVarCopy | - | 0x00401050 | 0x0002ACFC | 0x0002ACFC | 0x00000000 |
None | 0x00000205 | 0x00401054 | 0x0002AD00 | 0x0002AD00 | - |
_adj_fprem1 | - | 0x00401058 | 0x0002AD04 | 0x0002AD04 | 0x00000000 |
__vbaRecAnsiToUni | - | 0x0040105C | 0x0002AD08 | 0x0002AD08 | 0x00000000 |
None | 0x00000207 | 0x00401060 | 0x0002AD0C | 0x0002AD0C | - |
__vbaCopyBytes | - | 0x00401064 | 0x0002AD10 | 0x0002AD10 | 0x00000000 |
__vbaStrCat | - | 0x00401068 | 0x0002AD14 | 0x0002AD14 | 0x00000000 |
__vbaLsetFixstr | - | 0x0040106C | 0x0002AD18 | 0x0002AD18 | 0x00000000 |
__vbaRecDestruct | - | 0x00401070 | 0x0002AD1C | 0x0002AD1C | 0x00000000 |
__vbaSetSystemError | - | 0x00401074 | 0x0002AD20 | 0x0002AD20 | 0x00000000 |
None | 0x00000295 | 0x00401078 | 0x0002AD24 | 0x0002AD24 | - |
__vbaHresultCheckObj | - | 0x0040107C | 0x0002AD28 | 0x0002AD28 | 0x00000000 |
__vbaNameFile | - | 0x00401080 | 0x0002AD2C | 0x0002AD2C | 0x00000000 |
_adj_fdiv_m32 | - | 0x00401084 | 0x0002AD30 | 0x0002AD30 | 0x00000000 |
__vbaAryVar | - | 0x00401088 | 0x0002AD34 | 0x0002AD34 | 0x00000000 |
Zombie_GetTypeInfo | - | 0x0040108C | 0x0002AD38 | 0x0002AD38 | 0x00000000 |
__vbaAryDestruct | - | 0x00401090 | 0x0002AD3C | 0x0002AD3C | 0x00000000 |
None | 0x0000029D | 0x00401094 | 0x0002AD40 | 0x0002AD40 | - |
None | 0x00000251 | 0x00401098 | 0x0002AD44 | 0x0002AD44 | - |
__vbaBoolStr | - | 0x0040109C | 0x0002AD48 | 0x0002AD48 | 0x00000000 |
__vbaExitProc | - | 0x004010A0 | 0x0002AD4C | 0x0002AD4C | 0x00000000 |
__vbaI4Abs | - | 0x004010A4 | 0x0002AD50 | 0x0002AD50 | 0x00000000 |
None | 0x00000252 | 0x004010A8 | 0x0002AD54 | 0x0002AD54 | - |
__vbaOnError | - | 0x004010AC | 0x0002AD58 | 0x0002AD58 | 0x00000000 |
__vbaObjSet | - | 0x004010B0 | 0x0002AD5C | 0x0002AD5C | 0x00000000 |
_adj_fdiv_m16i | - | 0x004010B4 | 0x0002AD60 | 0x0002AD60 | 0x00000000 |
__vbaObjSetAddref | - | 0x004010B8 | 0x0002AD64 | 0x0002AD64 | 0x00000000 |
_adj_fdivr_m16i | - | 0x004010BC | 0x0002AD68 | 0x0002AD68 | 0x00000000 |
None | 0x00000256 | 0x004010C0 | 0x0002AD6C | 0x0002AD6C | - |
__vbaFpR4 | - | 0x004010C4 | 0x0002AD70 | 0x0002AD70 | 0x00000000 |
None | 0x000002C1 | 0x004010C8 | 0x0002AD74 | 0x0002AD74 | - |
__vbaStrFixstr | - | 0x004010CC | 0x0002AD78 | 0x0002AD78 | 0x00000000 |
_CIsin | - | 0x004010D0 | 0x0002AD7C | 0x0002AD7C | 0x00000000 |
__vbaErase | - | 0x004010D4 | 0x0002AD80 | 0x0002AD80 | 0x00000000 |
None | 0x00000277 | 0x004010D8 | 0x0002AD84 | 0x0002AD84 | - |
None | 0x000002C5 | 0x004010DC | 0x0002AD88 | 0x0002AD88 | - |
None | 0x0000020D | 0x004010E0 | 0x0002AD8C | 0x0002AD8C | - |
__vbaChkstk | - | 0x004010E4 | 0x0002AD90 | 0x0002AD90 | 0x00000000 |
__vbaFileClose | - | 0x004010E8 | 0x0002AD94 | 0x0002AD94 | 0x00000000 |
EVENT_SINK_AddRef | - | 0x004010EC | 0x0002AD98 | 0x0002AD98 | 0x00000000 |
__vbaGenerateBoundsError | - | 0x004010F0 | 0x0002AD9C | 0x0002AD9C | 0x00000000 |
__vbaGet3 | - | 0x004010F4 | 0x0002ADA0 | 0x0002ADA0 | 0x00000000 |
__vbaStrCmp | - | 0x004010F8 | 0x0002ADA4 | 0x0002ADA4 | 0x00000000 |
None | 0x00000211 | 0x004010FC | 0x0002ADA8 | 0x0002ADA8 | - |
__vbaGet4 | - | 0x00401100 | 0x0002ADAC | 0x0002ADAC | 0x00000000 |
__vbaPutOwner3 | - | 0x00401104 | 0x0002ADB0 | 0x0002ADB0 | 0x00000000 |
__vbaVarTstEq | - | 0x00401108 | 0x0002ADB4 | 0x0002ADB4 | 0x00000000 |
__vbaAryConstruct2 | - | 0x0040110C | 0x0002ADB8 | 0x0002ADB8 | 0x00000000 |
__vbaObjVar | - | 0x00401110 | 0x0002ADBC | 0x0002ADBC | 0x00000000 |
__vbaI2I4 | - | 0x00401114 | 0x0002ADC0 | 0x0002ADC0 | 0x00000000 |
DllFunctionCall | - | 0x00401118 | 0x0002ADC4 | 0x0002ADC4 | 0x00000000 |
__vbaVarLateMemSt | - | 0x0040111C | 0x0002ADC8 | 0x0002ADC8 | 0x00000000 |
__vbaFpUI1 | - | 0x00401120 | 0x0002ADCC | 0x0002ADCC | 0x00000000 |
__vbaRedimPreserve | - | 0x00401124 | 0x0002ADD0 | 0x0002ADD0 | 0x00000000 |
__vbaStrR4 | - | 0x00401128 | 0x0002ADD4 | 0x0002ADD4 | 0x00000000 |
_adj_fpatan | - | 0x0040112C | 0x0002ADD8 | 0x0002ADD8 | 0x00000000 |
__vbaFixstrConstruct | - | 0x00401130 | 0x0002ADDC | 0x0002ADDC | 0x00000000 |
__vbaLateIdCallLd | - | 0x00401134 | 0x0002ADE0 | 0x0002ADE0 | 0x00000000 |
Zombie_GetTypeInfoCount | - | 0x00401138 | 0x0002ADE4 | 0x0002ADE4 | 0x00000000 |
__vbaRedim | - | 0x0040113C | 0x0002ADE8 | 0x0002ADE8 | 0x00000000 |
__vbaRecUniToAnsi | - | 0x00401140 | 0x0002ADEC | 0x0002ADEC | 0x00000000 |
EVENT_SINK_Release | - | 0x00401144 | 0x0002ADF0 | 0x0002ADF0 | 0x00000000 |
__vbaNew | - | 0x00401148 | 0x0002ADF4 | 0x0002ADF4 | 0x00000000 |
None | 0x00000258 | 0x0040114C | 0x0002ADF8 | 0x0002ADF8 | - |
__vbaUI1I2 | - | 0x00401150 | 0x0002ADFC | 0x0002ADFC | 0x00000000 |
_CIsqrt | - | 0x00401154 | 0x0002AE00 | 0x0002AE00 | 0x00000000 |
EVENT_SINK_QueryInterface | - | 0x00401158 | 0x0002AE04 | 0x0002AE04 | 0x00000000 |
__vbaExceptHandler | - | 0x0040115C | 0x0002AE08 | 0x0002AE08 | 0x00000000 |
None | 0x000002C7 | 0x00401160 | 0x0002AE0C | 0x0002AE0C | - |
None | 0x000002C8 | 0x00401164 | 0x0002AE10 | 0x0002AE10 | - |
__vbaStrToUnicode | - | 0x00401168 | 0x0002AE14 | 0x0002AE14 | 0x00000000 |
None | 0x0000025E | 0x0040116C | 0x0002AE18 | 0x0002AE18 | - |
_adj_fprem | - | 0x00401170 | 0x0002AE1C | 0x0002AE1C | 0x00000000 |
_adj_fdivr_m64 | - | 0x00401174 | 0x0002AE20 | 0x0002AE20 | 0x00000000 |
None | 0x000002CA | 0x00401178 | 0x0002AE24 | 0x0002AE24 | - |
None | 0x000002CC | 0x0040117C | 0x0002AE28 | 0x0002AE28 | - |
None | 0x00000261 | 0x00401180 | 0x0002AE2C | 0x0002AE2C | - |
__vbaFPException | - | 0x00401184 | 0x0002AE30 | 0x0002AE30 | 0x00000000 |
None | 0x000002CD | 0x00401188 | 0x0002AE34 | 0x0002AE34 | - |
None | 0x0000013F | 0x0040118C | 0x0002AE38 | 0x0002AE38 | - |
__vbaGetOwner3 | - | 0x00401190 | 0x0002AE3C | 0x0002AE3C | 0x00000000 |
__vbaUbound | - | 0x00401194 | 0x0002AE40 | 0x0002AE40 | 0x00000000 |
None | 0x00000217 | 0x00401198 | 0x0002AE44 | 0x0002AE44 | - |
__vbaFileSeek | - | 0x0040119C | 0x0002AE48 | 0x0002AE48 | 0x00000000 |
None | 0x00000284 | 0x004011A0 | 0x0002AE4C | 0x0002AE4C | - |
None | 0x00000219 | 0x004011A4 | 0x0002AE50 | 0x0002AE50 | - |
_CIlog | - | 0x004011A8 | 0x0002AE54 | 0x0002AE54 | 0x00000000 |
__vbaErrorOverflow | - | 0x004011AC | 0x0002AE58 | 0x0002AE58 | 0x00000000 |
__vbaFileOpen | - | 0x004011B0 | 0x0002AE5C | 0x0002AE5C | 0x00000000 |
__vbaVarLateMemCallLdRf | - | 0x004011B4 | 0x0002AE60 | 0x0002AE60 | 0x00000000 |
None | 0x00000288 | 0x004011B8 | 0x0002AE64 | 0x0002AE64 | - |
None | 0x0000023A | 0x004011BC | 0x0002AE68 | 0x0002AE68 | - |
__vbaNew2 | - | 0x004011C0 | 0x0002AE6C | 0x0002AE6C | 0x00000000 |
__vbaInStr | - | 0x004011C4 | 0x0002AE70 | 0x0002AE70 | 0x00000000 |
_adj_fdiv_m32i | - | 0x004011C8 | 0x0002AE74 | 0x0002AE74 | 0x00000000 |
None | 0x0000023C | 0x004011CC | 0x0002AE78 | 0x0002AE78 | - |
_adj_fdivr_m32i | - | 0x004011D0 | 0x0002AE7C | 0x0002AE7C | 0x00000000 |
__vbaStrCopy | - | 0x004011D4 | 0x0002AE80 | 0x0002AE80 | 0x00000000 |
__vbaI4Str | - | 0x004011D8 | 0x0002AE84 | 0x0002AE84 | 0x00000000 |
__vbaFreeStrList | - | 0x004011DC | 0x0002AE88 | 0x0002AE88 | 0x00000000 |
_adj_fdivr_m32 | - | 0x004011E0 | 0x0002AE8C | 0x0002AE8C | 0x00000000 |
_adj_fdiv_r | - | 0x004011E4 | 0x0002AE90 | 0x0002AE90 | 0x00000000 |
None | 0x00000242 | 0x004011E8 | 0x0002AE94 | 0x0002AE94 | - |
None | 0x00000064 | 0x004011EC | 0x0002AE98 | 0x0002AE98 | - |
__vbaVarSetVar | - | 0x004011F0 | 0x0002AE9C | 0x0002AE9C | 0x00000000 |
__vbaI4Var | - | 0x004011F4 | 0x0002AEA0 | 0x0002AEA0 | 0x00000000 |
None | 0x000002B1 | 0x004011F8 | 0x0002AEA4 | 0x0002AEA4 | - |
__vbaLateMemCall | - | 0x004011FC | 0x0002AEA8 | 0x0002AEA8 | 0x00000000 |
__vbaVarAdd | - | 0x00401200 | 0x0002AEAC | 0x0002AEAC | 0x00000000 |
None | 0x00000263 | 0x00401204 | 0x0002AEB0 | 0x0002AEB0 | - |
__vbaAryLock | - | 0x00401208 | 0x0002AEB4 | 0x0002AEB4 | 0x00000000 |
None | 0x00000140 | 0x0040120C | 0x0002AEB8 | 0x0002AEB8 | - |
__vbaStrComp | - | 0x00401210 | 0x0002AEBC | 0x0002AEBC | 0x00000000 |
__vbaVarDup | - | 0x00401214 | 0x0002AEC0 | 0x0002AEC0 | 0x00000000 |
__vbaStrToAnsi | - | 0x00401218 | 0x0002AEC4 | 0x0002AEC4 | 0x00000000 |
None | 0x00000141 | 0x0040121C | 0x0002AEC8 | 0x0002AEC8 | - |
__vbaFpI2 | - | 0x00401220 | 0x0002AECC | 0x0002AECC | 0x00000000 |
__vbaFpI4 | - | 0x00401224 | 0x0002AED0 | 0x0002AED0 | 0x00000000 |
__vbaVarLateMemCallLd | - | 0x00401228 | 0x0002AED4 | 0x0002AED4 | 0x00000000 |
None | 0x00000268 | 0x0040122C | 0x0002AED8 | 0x0002AED8 | - |
__vbaVarSetObjAddref | - | 0x00401230 | 0x0002AEDC | 0x0002AEDC | 0x00000000 |
__vbaRecDestructAnsi | - | 0x00401234 | 0x0002AEE0 | 0x0002AEE0 | 0x00000000 |
__vbaLateMemCallLd | - | 0x00401238 | 0x0002AEE4 | 0x0002AEE4 | 0x00000000 |
_CIatan | - | 0x0040123C | 0x0002AEE8 | 0x0002AEE8 | 0x00000000 |
__vbaAryCopy | - | 0x00401240 | 0x0002AEEC | 0x0002AEEC | 0x00000000 |
__vbaStrMove | - | 0x00401244 | 0x0002AEF0 | 0x0002AEF0 | 0x00000000 |
None | 0x0000026A | 0x00401248 | 0x0002AEF4 | 0x0002AEF4 | - |
__vbaCastObj | - | 0x0040124C | 0x0002AEF8 | 0x0002AEF8 | 0x00000000 |
__vbaR8IntI4 | - | 0x00401250 | 0x0002AEFC | 0x0002AEFC | 0x00000000 |
None | 0x0000028A | 0x00401254 | 0x0002AF00 | 0x0002AF00 | - |
_allmul | - | 0x00401258 | 0x0002AF04 | 0x0002AF04 | 0x00000000 |
__vbaVarLateMemCallSt | - | 0x0040125C | 0x0002AF08 | 0x0002AF08 | 0x00000000 |
_CItan | - | 0x00401260 | 0x0002AF0C | 0x0002AF0C | 0x00000000 |
None | 0x00000222 | 0x00401264 | 0x0002AF10 | 0x0002AF10 | - |
__vbaAryUnlock | - | 0x00401268 | 0x0002AF14 | 0x0002AF14 | 0x00000000 |
_CIexp | - | 0x0040126C | 0x0002AF18 | 0x0002AF18 | 0x00000000 |
__vbaFreeObj | - | 0x00401270 | 0x0002AF1C | 0x0002AF1C | 0x00000000 |
__vbaFreeStr | - | 0x00401274 | 0x0002AF20 | 0x0002AF20 | 0x00000000 |
None | 0x00000244 | 0x00401278 | 0x0002AF24 | 0x0002AF24 | - |
None | 0x00000245 | 0x0040127C | 0x0002AF28 | 0x0002AF28 | - |
c:\users\rdhj0cnfevzx\appdata\local\temp\~df1bdb3580e40e32b5.tmp | Dropped File | OLE Compound |
Clean
|
...
|
»
c:\users\rdhj0cnfevzx\appdata\local\temp\~df4c509acaee2150ca.tmp | Dropped File | OLE Compound |
Clean
|
...
|
»
c:\users\rdhj0cnfevzx\appdata\local\temp\~df1f57c1e1876985af.tmp | Dropped File | OLE Compound |
Clean
|
...
|
»
c:\users\rdhj0cnfevzx\appdata\local\temp\~df3fb37a4d0b549425.tmp | Dropped File | OLE Compound |
Clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\AppData\Roaming\Microsoft\Windows\Templates\credentials.txt | Dropped File | Text |
Clean
|
...
|
»
c:\users\rdhj0cnfevzx\appdata\local\temp\~df4017a6edb0510c97.tmp | Dropped File | Empty |
Clean
|
...
|
»
c:\users\rdhj0cnfevzx\appdata\local\temp\~df6bb2ea749d7dd475.tmp | Dropped File | Empty |
Clean
|
...
|
»
c:\srvsvc | Dropped File | Empty |
Clean
|
...
|
»
3a7e473a0ba5b117657193b576f5b98fcf9a428046eb32ef888cc6b953653109 | Downloaded File | HTML |
Clean
|
...
|
»
4cdfc3d4e60ada2c4c309c7510e95321d476a6a227b50f787406ea6fbcfe0ba7 | Downloaded File | Unknown |
Clean
|
...
|
»
b14bcf7e766be0d5ea1f045fa63bc03a3d5c18687539e66f42a3051e5ea8d0af | Downloaded File | Text |
Clean
|
...
|
»
c:\users\rdhj0cnfevzx\appdata\local\microsoft\windows\inetcache\counters.dat | Modified File | Stream |
Clean
|
...
|
»