Try VMRay Platform
Malicious
Classifications

Keylogger Injector Spyware

Threat Names

Mal/Generic-S

Dynamic Analysis Report

Created on 2022-08-05T08:07:52+00:00

6731f235ff78e22e5a0f1503542926bb707a95251b8cbd22c56fbd7fc5a8cbbf.exe

Windows Exe (x86-32)

Remarks (1/1)

(0x0200000E): The overall sleep time of all monitored processes was truncated from "3 days, 5 hours, 2 minutes, 51 seconds" to "2 minutes, 16 seconds" to reveal dormant functionality.

Filters:
File Name Category Type Verdict Actions
c:\users\rdhj0cnfevzx\desktop\6731f235ff78e22e5a0f1503542926bb707a95251b8cbd22c56fbd7fc5a8cbbf.exe Sample File Binary
Malicious
»
Also Known As C:\Users\RDhJ0CNFevzX\Desktop\6731f235ff78e22e5a0f1503542926bb707a95251b8cbd22c56fbd7fc5a8cbbf.exe (Sample File, Accessed File, VM File)
MIME Type application/vnd.microsoft.portable-executable
File Size 406.33 KB
MD5 45061e4da841c2587d0890148705a142 Copy to Clipboard
SHA1 eb68218c1d70f3ba00f8190c8171ad1cfa2fb42a Copy to Clipboard
SHA256 6731f235ff78e22e5a0f1503542926bb707a95251b8cbd22c56fbd7fc5a8cbbf Copy to Clipboard
SSDeep 6144:UvEN2U+T6i5LirrllHy4HUcMQY61DdreIfa:GENN+T5xYrllrU7QY61ra Copy to Clipboard
ImpHash 98f67c550a7da65513e63ffd998f6b2e Copy to Clipboard
File Reputation Information
»
Verdict
Malicious
Names Mal/Generic-S
PE Information
»
Image Base 0x00400000
Entry Point 0x00403670
Size Of Code 0x0002B000
Size Of Initialized Data 0x00003000
File Type IMAGE_FILE_EXECUTABLE_IMAGE
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
Machine Type IMAGE_FILE_MACHINE_I386
Compile Timestamp 2011-06-14 21:01 (UTC+2)
Version Information (6)
»
CompanyName Microsoft
ProductName Win
FileVersion 1.00
ProductVersion 1.00
InternalName Win
OriginalFilename Win.exe
Sections (4)
»
Name Virtual Address Virtual Size Raw Data Size Raw Data Offset Flags Entropy
.text 0x00401000 0x0002A728 0x0002B000 0x00001000 IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE 5.95
.data 0x0042C000 0x00001B74 0x00001000 0x0002C000 IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE 0.0
.rsrc 0x0042E000 0x000005E0 0x00001000 0x0002D000 IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ 1.69
.tdata 0x0042F000 0x0000F000 0x0000F000 0x0002E000 IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE 0.0
Imports (1)
»
MSVBVM60.DLL (160)
»
API Name Ordinal IAT Address Thunk RVA Thunk Offset Hint
EVENT_SINK_GetIDsOfNames - 0x00401000 0x0002ACAC 0x0002ACAC 0x00000000
__vbaStrI2 - 0x00401004 0x0002ACB0 0x0002ACB0 0x00000000
None 0x000002B2 0x00401008 0x0002ACB4 0x0002ACB4 -
_CIcos - 0x0040100C 0x0002ACB8 0x0002ACB8 0x00000000
_adj_fptan - 0x00401010 0x0002ACBC 0x0002ACBC 0x00000000
__vbaStrI4 - 0x00401014 0x0002ACC0 0x0002ACC0 0x00000000
__vbaVarVargNofree - 0x00401018 0x0002ACC4 0x0002ACC4 0x00000000
__vbaFreeVar - 0x0040101C 0x0002ACC8 0x0002ACC8 0x00000000
__vbaStrVarMove - 0x00401020 0x0002ACCC 0x0002ACCC 0x00000000
__vbaLenBstr - 0x00401024 0x0002ACD0 0x0002ACD0 0x00000000
__vbaLateIdCall - 0x00401028 0x0002ACD4 0x0002ACD4 0x00000000
__vbaPut3 - 0x0040102C 0x0002ACD8 0x0002ACD8 0x00000000
__vbaEnd - 0x00401030 0x0002ACDC 0x0002ACDC 0x00000000
__vbaFreeVarList - 0x00401034 0x0002ACE0 0x0002ACE0 0x00000000
_adj_fdiv_m64 - 0x00401038 0x0002ACE4 0x0002ACE4 0x00000000
__vbaPut4 - 0x0040103C 0x0002ACE8 0x0002ACE8 0x00000000
EVENT_SINK_Invoke - 0x00401040 0x0002ACEC 0x0002ACEC 0x00000000
__vbaRaiseEvent - 0x00401044 0x0002ACF0 0x0002ACF0 0x00000000
__vbaFreeObjList - 0x00401048 0x0002ACF4 0x0002ACF4 0x00000000
None 0x00000204 0x0040104C 0x0002ACF8 0x0002ACF8 -
__vbaStrErrVarCopy - 0x00401050 0x0002ACFC 0x0002ACFC 0x00000000
None 0x00000205 0x00401054 0x0002AD00 0x0002AD00 -
_adj_fprem1 - 0x00401058 0x0002AD04 0x0002AD04 0x00000000
__vbaRecAnsiToUni - 0x0040105C 0x0002AD08 0x0002AD08 0x00000000
None 0x00000207 0x00401060 0x0002AD0C 0x0002AD0C -
__vbaCopyBytes - 0x00401064 0x0002AD10 0x0002AD10 0x00000000
__vbaStrCat - 0x00401068 0x0002AD14 0x0002AD14 0x00000000
__vbaLsetFixstr - 0x0040106C 0x0002AD18 0x0002AD18 0x00000000
__vbaRecDestruct - 0x00401070 0x0002AD1C 0x0002AD1C 0x00000000
__vbaSetSystemError - 0x00401074 0x0002AD20 0x0002AD20 0x00000000
None 0x00000295 0x00401078 0x0002AD24 0x0002AD24 -
__vbaHresultCheckObj - 0x0040107C 0x0002AD28 0x0002AD28 0x00000000
__vbaNameFile - 0x00401080 0x0002AD2C 0x0002AD2C 0x00000000
_adj_fdiv_m32 - 0x00401084 0x0002AD30 0x0002AD30 0x00000000
__vbaAryVar - 0x00401088 0x0002AD34 0x0002AD34 0x00000000
Zombie_GetTypeInfo - 0x0040108C 0x0002AD38 0x0002AD38 0x00000000
__vbaAryDestruct - 0x00401090 0x0002AD3C 0x0002AD3C 0x00000000
None 0x0000029D 0x00401094 0x0002AD40 0x0002AD40 -
None 0x00000251 0x00401098 0x0002AD44 0x0002AD44 -
__vbaBoolStr - 0x0040109C 0x0002AD48 0x0002AD48 0x00000000
__vbaExitProc - 0x004010A0 0x0002AD4C 0x0002AD4C 0x00000000
__vbaI4Abs - 0x004010A4 0x0002AD50 0x0002AD50 0x00000000
None 0x00000252 0x004010A8 0x0002AD54 0x0002AD54 -
__vbaOnError - 0x004010AC 0x0002AD58 0x0002AD58 0x00000000
__vbaObjSet - 0x004010B0 0x0002AD5C 0x0002AD5C 0x00000000
_adj_fdiv_m16i - 0x004010B4 0x0002AD60 0x0002AD60 0x00000000
__vbaObjSetAddref - 0x004010B8 0x0002AD64 0x0002AD64 0x00000000
_adj_fdivr_m16i - 0x004010BC 0x0002AD68 0x0002AD68 0x00000000
None 0x00000256 0x004010C0 0x0002AD6C 0x0002AD6C -
__vbaFpR4 - 0x004010C4 0x0002AD70 0x0002AD70 0x00000000
None 0x000002C1 0x004010C8 0x0002AD74 0x0002AD74 -
__vbaStrFixstr - 0x004010CC 0x0002AD78 0x0002AD78 0x00000000
_CIsin - 0x004010D0 0x0002AD7C 0x0002AD7C 0x00000000
__vbaErase - 0x004010D4 0x0002AD80 0x0002AD80 0x00000000
None 0x00000277 0x004010D8 0x0002AD84 0x0002AD84 -
None 0x000002C5 0x004010DC 0x0002AD88 0x0002AD88 -
None 0x0000020D 0x004010E0 0x0002AD8C 0x0002AD8C -
__vbaChkstk - 0x004010E4 0x0002AD90 0x0002AD90 0x00000000
__vbaFileClose - 0x004010E8 0x0002AD94 0x0002AD94 0x00000000
EVENT_SINK_AddRef - 0x004010EC 0x0002AD98 0x0002AD98 0x00000000
__vbaGenerateBoundsError - 0x004010F0 0x0002AD9C 0x0002AD9C 0x00000000
__vbaGet3 - 0x004010F4 0x0002ADA0 0x0002ADA0 0x00000000
__vbaStrCmp - 0x004010F8 0x0002ADA4 0x0002ADA4 0x00000000
None 0x00000211 0x004010FC 0x0002ADA8 0x0002ADA8 -
__vbaGet4 - 0x00401100 0x0002ADAC 0x0002ADAC 0x00000000
__vbaPutOwner3 - 0x00401104 0x0002ADB0 0x0002ADB0 0x00000000
__vbaVarTstEq - 0x00401108 0x0002ADB4 0x0002ADB4 0x00000000
__vbaAryConstruct2 - 0x0040110C 0x0002ADB8 0x0002ADB8 0x00000000
__vbaObjVar - 0x00401110 0x0002ADBC 0x0002ADBC 0x00000000
__vbaI2I4 - 0x00401114 0x0002ADC0 0x0002ADC0 0x00000000
DllFunctionCall - 0x00401118 0x0002ADC4 0x0002ADC4 0x00000000
__vbaVarLateMemSt - 0x0040111C 0x0002ADC8 0x0002ADC8 0x00000000
__vbaFpUI1 - 0x00401120 0x0002ADCC 0x0002ADCC 0x00000000
__vbaRedimPreserve - 0x00401124 0x0002ADD0 0x0002ADD0 0x00000000
__vbaStrR4 - 0x00401128 0x0002ADD4 0x0002ADD4 0x00000000
_adj_fpatan - 0x0040112C 0x0002ADD8 0x0002ADD8 0x00000000
__vbaFixstrConstruct - 0x00401130 0x0002ADDC 0x0002ADDC 0x00000000
__vbaLateIdCallLd - 0x00401134 0x0002ADE0 0x0002ADE0 0x00000000
Zombie_GetTypeInfoCount - 0x00401138 0x0002ADE4 0x0002ADE4 0x00000000
__vbaRedim - 0x0040113C 0x0002ADE8 0x0002ADE8 0x00000000
__vbaRecUniToAnsi - 0x00401140 0x0002ADEC 0x0002ADEC 0x00000000
EVENT_SINK_Release - 0x00401144 0x0002ADF0 0x0002ADF0 0x00000000
__vbaNew - 0x00401148 0x0002ADF4 0x0002ADF4 0x00000000
None 0x00000258 0x0040114C 0x0002ADF8 0x0002ADF8 -
__vbaUI1I2 - 0x00401150 0x0002ADFC 0x0002ADFC 0x00000000
_CIsqrt - 0x00401154 0x0002AE00 0x0002AE00 0x00000000
EVENT_SINK_QueryInterface - 0x00401158 0x0002AE04 0x0002AE04 0x00000000
__vbaExceptHandler - 0x0040115C 0x0002AE08 0x0002AE08 0x00000000
None 0x000002C7 0x00401160 0x0002AE0C 0x0002AE0C -
None 0x000002C8 0x00401164 0x0002AE10 0x0002AE10 -
__vbaStrToUnicode - 0x00401168 0x0002AE14 0x0002AE14 0x00000000
None 0x0000025E 0x0040116C 0x0002AE18 0x0002AE18 -
_adj_fprem - 0x00401170 0x0002AE1C 0x0002AE1C 0x00000000
_adj_fdivr_m64 - 0x00401174 0x0002AE20 0x0002AE20 0x00000000
None 0x000002CA 0x00401178 0x0002AE24 0x0002AE24 -
None 0x000002CC 0x0040117C 0x0002AE28 0x0002AE28 -
None 0x00000261 0x00401180 0x0002AE2C 0x0002AE2C -
__vbaFPException - 0x00401184 0x0002AE30 0x0002AE30 0x00000000
None 0x000002CD 0x00401188 0x0002AE34 0x0002AE34 -
None 0x0000013F 0x0040118C 0x0002AE38 0x0002AE38 -
__vbaGetOwner3 - 0x00401190 0x0002AE3C 0x0002AE3C 0x00000000
__vbaUbound - 0x00401194 0x0002AE40 0x0002AE40 0x00000000
None 0x00000217 0x00401198 0x0002AE44 0x0002AE44 -
__vbaFileSeek - 0x0040119C 0x0002AE48 0x0002AE48 0x00000000
None 0x00000284 0x004011A0 0x0002AE4C 0x0002AE4C -
None 0x00000219 0x004011A4 0x0002AE50 0x0002AE50 -
_CIlog - 0x004011A8 0x0002AE54 0x0002AE54 0x00000000
__vbaErrorOverflow - 0x004011AC 0x0002AE58 0x0002AE58 0x00000000
__vbaFileOpen - 0x004011B0 0x0002AE5C 0x0002AE5C 0x00000000
__vbaVarLateMemCallLdRf - 0x004011B4 0x0002AE60 0x0002AE60 0x00000000
None 0x00000288 0x004011B8 0x0002AE64 0x0002AE64 -
None 0x0000023A 0x004011BC 0x0002AE68 0x0002AE68 -
__vbaNew2 - 0x004011C0 0x0002AE6C 0x0002AE6C 0x00000000
__vbaInStr - 0x004011C4 0x0002AE70 0x0002AE70 0x00000000
_adj_fdiv_m32i - 0x004011C8 0x0002AE74 0x0002AE74 0x00000000
None 0x0000023C 0x004011CC 0x0002AE78 0x0002AE78 -
_adj_fdivr_m32i - 0x004011D0 0x0002AE7C 0x0002AE7C 0x00000000
__vbaStrCopy - 0x004011D4 0x0002AE80 0x0002AE80 0x00000000
__vbaI4Str - 0x004011D8 0x0002AE84 0x0002AE84 0x00000000
__vbaFreeStrList - 0x004011DC 0x0002AE88 0x0002AE88 0x00000000
_adj_fdivr_m32 - 0x004011E0 0x0002AE8C 0x0002AE8C 0x00000000
_adj_fdiv_r - 0x004011E4 0x0002AE90 0x0002AE90 0x00000000
None 0x00000242 0x004011E8 0x0002AE94 0x0002AE94 -
None 0x00000064 0x004011EC 0x0002AE98 0x0002AE98 -
__vbaVarSetVar - 0x004011F0 0x0002AE9C 0x0002AE9C 0x00000000
__vbaI4Var - 0x004011F4 0x0002AEA0 0x0002AEA0 0x00000000
None 0x000002B1 0x004011F8 0x0002AEA4 0x0002AEA4 -
__vbaLateMemCall - 0x004011FC 0x0002AEA8 0x0002AEA8 0x00000000
__vbaVarAdd - 0x00401200 0x0002AEAC 0x0002AEAC 0x00000000
None 0x00000263 0x00401204 0x0002AEB0 0x0002AEB0 -
__vbaAryLock - 0x00401208 0x0002AEB4 0x0002AEB4 0x00000000
None 0x00000140 0x0040120C 0x0002AEB8 0x0002AEB8 -
__vbaStrComp - 0x00401210 0x0002AEBC 0x0002AEBC 0x00000000
__vbaVarDup - 0x00401214 0x0002AEC0 0x0002AEC0 0x00000000
__vbaStrToAnsi - 0x00401218 0x0002AEC4 0x0002AEC4 0x00000000
None 0x00000141 0x0040121C 0x0002AEC8 0x0002AEC8 -
__vbaFpI2 - 0x00401220 0x0002AECC 0x0002AECC 0x00000000
__vbaFpI4 - 0x00401224 0x0002AED0 0x0002AED0 0x00000000
__vbaVarLateMemCallLd - 0x00401228 0x0002AED4 0x0002AED4 0x00000000
None 0x00000268 0x0040122C 0x0002AED8 0x0002AED8 -
__vbaVarSetObjAddref - 0x00401230 0x0002AEDC 0x0002AEDC 0x00000000
__vbaRecDestructAnsi - 0x00401234 0x0002AEE0 0x0002AEE0 0x00000000
__vbaLateMemCallLd - 0x00401238 0x0002AEE4 0x0002AEE4 0x00000000
_CIatan - 0x0040123C 0x0002AEE8 0x0002AEE8 0x00000000
__vbaAryCopy - 0x00401240 0x0002AEEC 0x0002AEEC 0x00000000
__vbaStrMove - 0x00401244 0x0002AEF0 0x0002AEF0 0x00000000
None 0x0000026A 0x00401248 0x0002AEF4 0x0002AEF4 -
__vbaCastObj - 0x0040124C 0x0002AEF8 0x0002AEF8 0x00000000
__vbaR8IntI4 - 0x00401250 0x0002AEFC 0x0002AEFC 0x00000000
None 0x0000028A 0x00401254 0x0002AF00 0x0002AF00 -
_allmul - 0x00401258 0x0002AF04 0x0002AF04 0x00000000
__vbaVarLateMemCallSt - 0x0040125C 0x0002AF08 0x0002AF08 0x00000000
_CItan - 0x00401260 0x0002AF0C 0x0002AF0C 0x00000000
None 0x00000222 0x00401264 0x0002AF10 0x0002AF10 -
__vbaAryUnlock - 0x00401268 0x0002AF14 0x0002AF14 0x00000000
_CIexp - 0x0040126C 0x0002AF18 0x0002AF18 0x00000000
__vbaFreeObj - 0x00401270 0x0002AF1C 0x0002AF1C 0x00000000
__vbaFreeStr - 0x00401274 0x0002AF20 0x0002AF20 0x00000000
None 0x00000244 0x00401278 0x0002AF24 0x0002AF24 -
None 0x00000245 0x0040127C 0x0002AF28 0x0002AF28 -
Memory Dumps (5)
»
Name Process ID Start VA End VA Dump Reason PE Rebuild Bitness Entry Point YARA Actions
6731f235ff78e22e5a0f1503542926bb707a95251b8cbd22c56fbd7fc5a8cbbf.exe 1 0x00400000 0x0043DFFF Relevant Image False 32-bit 0x00403670 False
buffer 1 0x00630000 0x0063FFFF Marked Executable False 32-bit - False
buffer 1 0x00630000 0x0063FFFF Content Changed False 32-bit - False
buffer 1 0x00630000 0x0063FFFF First Execution False 32-bit 0x00636338 False
6731f235ff78e22e5a0f1503542926bb707a95251b8cbd22c56fbd7fc5a8cbbf.exe 1 0x00400000 0x0043DFFF Process Termination False 32-bit - False
c:\users\rdhj0cnfevzx\desktop\6731f235ff78e22e5a0f1503542926bb707a95251b8cbd22c56fbd7fc5a8cbbf.exe Dropped File Binary
Malicious
»
Also Known As C:\Users\RDhJ0CNFevzX\Desktop\6731f235ff78e22e5a0f1503542926bb707a95251b8cbd22c56fbd7fc5a8cbbf.exe  (Accessed File)
MIME Type application/vnd.microsoft.portable-executable
File Size 132.00 KB
MD5 bee47439c4960e2728594ece9ad95ba7 Copy to Clipboard
SHA1 43f4b6f607dec5bec2a33e2fb4148c38de832490 Copy to Clipboard
SHA256 8a1902d9c0dbe388b28ef5a9c8ec4c0f1802fc6ccd43471ea337dcb3d71c81d4 Copy to Clipboard
SSDeep 1536:MPM/Zws3kTnvzbhNBPmxue2SRQg0dkEwiqoViocIdus3h4b6P/C:MYZTkLfhjFSiO3oeIdlsqC Copy to Clipboard
ImpHash 4f7271df0bf201cf627af3103fba2c2e Copy to Clipboard
File Reputation Information
»
Verdict
Malicious
Names Mal/Generic-S
PE Information
»
Image Base 0x00400000
Entry Point 0x004019AC
Size Of Code 0x0001E000
Size Of Initialized Data 0x00002000
File Type IMAGE_FILE_EXECUTABLE_IMAGE
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
Machine Type IMAGE_FILE_MACHINE_I386
Compile Timestamp 2022-07-14 08:48 (UTC+2)
Version Information (10)
»
Comments pudendal
CompanyName fishweir
FileDescription fireballs
LegalCopyright quis 1111
LegalTrademarks boondoggles
ProductName gimps
FileVersion 2.04.0002
ProductVersion 2.04.0002
InternalName soral
OriginalFilename soral.exe
Sections (3)
»
Name Virtual Address Virtual Size Raw Data Size Raw Data Offset Flags Entropy
.text 0x00401000 0x0001DFC0 0x0001E000 0x00001000 IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ 5.89
.data 0x0041F000 0x00000BD4 0x00001000 0x0001F000 IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE 0.0
.rsrc 0x00420000 0x000009B0 0x00001000 0x00020000 IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ 2.17
Imports (1)
»
MSVBVM60.DLL (130)
»
API Name Ordinal IAT Address Thunk RVA Thunk Offset Hint
_CIcos - 0x00401000 0x0001E71C 0x0001E71C 0x00000053
_adj_fptan - 0x00401004 0x0001E720 0x0001E720 0x000001B3
__vbaVarMove - 0x00401008 0x0001E724 0x0001E724 0x00000178
__vbaVarVargNofree - 0x0040100C 0x0001E728 0x0001E728 0x00000199
__vbaFreeVar - 0x00401010 0x0001E72C 0x0001E72C 0x000000B1
__vbaAryMove - 0x00401014 0x0001E730 0x0001E730 0x0000005F
__vbaLenBstr - 0x00401018 0x0001E734 0x0001E734 0x000000E9
__vbaStrVarMove - 0x0040101C 0x0001E738 0x0001E738 0x00000148
__vbaEnd - 0x00401020 0x0001E73C 0x0001E73C 0x00000088
__vbaFreeVarList - 0x00401024 0x0001E740 0x0001E740 0x000000B2
_adj_fdiv_m64 - 0x00401028 0x0001E744 0x0001E744 0x000001AA
__vbaFreeObjList - 0x0040102C 0x0001E748 0x0001E748 0x000000AE
None 0x00000204 0x00401030 0x0001E74C 0x0001E74C -
_adj_fprem1 - 0x00401034 0x0001E750 0x0001E750 0x000001B2
__vbaStrCat - 0x00401038 0x0001E754 0x0001E754 0x00000133
__vbaRecDestruct - 0x0040103C 0x0001E758 0x0001E758 0x00000120
__vbaSetSystemError - 0x00401040 0x0001E75C 0x0001E75C 0x0000012D
__vbaLenBstrB - 0x00401044 0x0001E760 0x0001E760 0x000000EA
__vbaHresultCheckObj - 0x00401048 0x0001E764 0x0001E764 0x000000C0
_adj_fdiv_m32 - 0x0040104C 0x0001E768 0x0001E768 0x000001A8
None 0x0000029A 0x00401050 0x0001E76C 0x0001E76C -
None 0x0000029B 0x00401054 0x0001E770 0x0001E770 -
__vbaAryDestruct - 0x00401058 0x0001E774 0x0001E774 0x0000005D
None 0x00000251 0x0040105C 0x0001E778 0x0001E778 -
__vbaExitProc - 0x00401060 0x0001E77C 0x0001E77C 0x00000092
__vbaForEachCollObj - 0x00401064 0x0001E780 0x0001E780 0x0000009F
None 0x00000252 0x00401068 0x0001E784 0x0001E784 -
__vbaOnError - 0x0040106C 0x0001E788 0x0001E788 0x00000102
__vbaObjSet - 0x00401070 0x0001E78C 0x0001E78C 0x000000FF
_adj_fdiv_m16i - 0x00401074 0x0001E790 0x0001E790 0x000001A7
__vbaObjSetAddref - 0x00401078 0x0001E794 0x0001E794 0x00000100
_adj_fdivr_m16i - 0x0040107C 0x0001E798 0x0001E798 0x000001AC
_CIsin - 0x00401080 0x0001E79C 0x0001E79C 0x00000056
__vbaErase - 0x00401084 0x0001E7A0 0x0001E7A0 0x00000089
None 0x000002C5 0x00401088 0x0001E7A4 0x0001E7A4 -
None 0x00000277 0x0040108C 0x0001E7A8 0x0001E7A8 -
None 0x00000278 0x00401090 0x0001E7AC 0x0001E7AC -
None 0x0000020D 0x00401094 0x0001E7B0 0x0001E7B0 -
__vbaNextEachCollObj - 0x00401098 0x0001E7B4 0x0001E7B4 0x000000FA
__vbaVarZero - 0x0040109C 0x0001E7B8 0x0001E7B8 0x0000019B
__vbaChkstk - 0x004010A0 0x0001E7BC 0x0001E7BC 0x0000006F
__vbaFileClose - 0x004010A4 0x0001E7C0 0x0001E7C0 0x00000097
EVENT_SINK_AddRef - 0x004010A8 0x0001E7C4 0x0001E7C4 0x00000011
__vbaGenerateBoundsError - 0x004010AC 0x0001E7C8 0x0001E7C8 0x000000B4
__vbaStrCmp - 0x004010B0 0x0001E7CC 0x0001E7CC 0x00000134
None 0x00000211 0x004010B4 0x0001E7D0 0x0001E7D0 -
__vbaAryConstruct2 - 0x004010B8 0x0001E7D4 0x0001E7D4 0x0000005B
__vbaI2I4 - 0x004010BC 0x0001E7D8 0x0001E7D8 0x000000C5
__vbaObjVar - 0x004010C0 0x0001E7DC 0x0001E7DC 0x00000101
DllFunctionCall - 0x004010C4 0x0001E7E0 0x0001E7E0 0x0000000B
__vbaFpUI1 - 0x004010C8 0x0001E7E4 0x0001E7E4 0x000000AC
__vbaLbound - 0x004010CC 0x0001E7E8 0x0001E7E8 0x000000E7
__vbaRedimPreserve - 0x004010D0 0x0001E7EC 0x0001E7EC 0x00000124
_adj_fpatan - 0x004010D4 0x0001E7F0 0x0001E7F0 0x000001B0
__vbaRedim - 0x004010D8 0x0001E7F4 0x0001E7F4 0x00000123
EVENT_SINK_Release - 0x004010DC 0x0001E7F8 0x0001E7F8 0x00000015
__vbaNew - 0x004010E0 0x0001E7FC 0x0001E7FC 0x000000F6
__vbaUI1I2 - 0x004010E4 0x0001E800 0x0001E800 0x0000014C
_CIsqrt - 0x004010E8 0x0001E804 0x0001E804 0x00000057
EVENT_SINK_QueryInterface - 0x004010EC 0x0001E808 0x0001E808 0x00000014
__vbaStr2Vec - 0x004010F0 0x0001E80C 0x0001E80C 0x0000012F
__vbaUI1I4 - 0x004010F4 0x0001E810 0x0001E810 0x0000014D
__vbaStrUI1 - 0x004010F8 0x0001E814 0x0001E814 0x00000146
__vbaExceptHandler - 0x004010FC 0x0001E818 0x0001E818 0x0000008E
__vbaPrintFile - 0x00401100 0x0001E81C 0x0001E81C 0x00000105
__vbaStrToUnicode - 0x00401104 0x0001E820 0x0001E820 0x00000145
None 0x000002C8 0x00401108 0x0001E824 0x0001E824 -
None 0x0000025E 0x0040110C 0x0001E828 0x0001E828 -
_adj_fprem - 0x00401110 0x0001E82C 0x0001E82C 0x000001B1
_adj_fdivr_m64 - 0x00401114 0x0001E830 0x0001E830 0x000001AF
None 0x0000025F 0x00401118 0x0001E834 0x0001E834 -
None 0x00000260 0x0040111C 0x0001E838 0x0001E838 -
None 0x000002CC 0x00401120 0x0001E83C 0x0001E83C -
__vbaFPException - 0x00401124 0x0001E840 0x0001E840 0x00000093
None 0x00000214 0x00401128 0x0001E844 0x0001E844 -
None 0x000002CD 0x0040112C 0x0001E848 0x0001E848 -
__vbaStrVarVal - 0x00401130 0x0001E84C 0x0001E84C 0x00000149
__vbaUbound - 0x00401134 0x0001E850 0x0001E850 0x00000151
__vbaGetOwner3 - 0x00401138 0x0001E854 0x0001E854 0x000000B9
__vbaVarCat - 0x0040113C 0x0001E858 0x0001E858 0x00000158
None 0x00000219 0x00401140 0x0001E85C 0x0001E85C -
None 0x00000284 0x00401144 0x0001E860 0x0001E860 -
None 0x00000285 0x00401148 0x0001E864 0x0001E864 -
_CIlog - 0x0040114C 0x0001E868 0x0001E868 0x00000055
__vbaErrorOverflow - 0x00401150 0x0001E86C 0x0001E86C 0x0000008D
__vbaFileOpen - 0x00401154 0x0001E870 0x0001E870 0x0000009A
__vbaVarLateMemCallLdRf - 0x00401158 0x0001E874 0x0001E874 0x00000171
__vbaNew2 - 0x0040115C 0x0001E878 0x0001E878 0x000000F7
__vbaInStr - 0x00401160 0x0001E87C 0x0001E87C 0x000000D0
None 0x00000288 0x00401164 0x0001E880 0x0001E880 -
None 0x0000023A 0x00401168 0x0001E884 0x0001E884 -
__vbaVar2Vec - 0x0040116C 0x0001E888 0x0001E888 0x00000154
_adj_fdiv_m32i - 0x00401170 0x0001E88C 0x0001E88C 0x000001A9
_adj_fdivr_m32i - 0x00401174 0x0001E890 0x0001E890 0x000001AE
None 0x0000023D 0x00401178 0x0001E894 0x0001E894 -
__vbaStrCopy - 0x0040117C 0x0001E898 0x0001E898 0x00000137
__vbaFreeStrList - 0x00401180 0x0001E89C 0x0001E89C 0x000000B0
__vbaDerefAry1 - 0x00401184 0x0001E8A0 0x0001E8A0 0x00000087
_adj_fdivr_m32 - 0x00401188 0x0001E8A4 0x0001E8A4 0x000001AD
__vbaPowerR8 - 0x0040118C 0x0001E8A8 0x0001E8A8 0x00000104
_adj_fdiv_r - 0x00401190 0x0001E8AC 0x0001E8AC 0x000001AB
None 0x000002AD 0x00401194 0x0001E8B0 0x0001E8B0 -
None 0x00000064 0x00401198 0x0001E8B4 0x0001E8B4 -
None 0x00000243 0x0040119C 0x0001E8B8 0x0001E8B8 -
__vbaAryLock - 0x004011A0 0x0001E8BC 0x0001E8BC 0x0000005E
__vbaVarAdd - 0x004011A4 0x0001E8C0 0x0001E8C0 0x00000156
__vbaLateMemCall - 0x004011A8 0x0001E8C4 0x0001E8C4 0x000000DE
__vbaStrToAnsi - 0x004011AC 0x0001E8C8 0x0001E8C8 0x00000144
__vbaVarDup - 0x004011B0 0x0001E8CC 0x0001E8CC 0x00000162
__vbaVarCopy - 0x004011B4 0x0001E8D0 0x0001E8D0 0x0000015F
None 0x00000268 0x004011B8 0x0001E8D4 0x0001E8D4 -
__vbaFpI4 - 0x004011BC 0x0001E8D8 0x0001E8D8 0x000000A9
__vbaVarLateMemCallLd - 0x004011C0 0x0001E8DC 0x0001E8DC 0x00000170
__vbaLateMemCallLd - 0x004011C4 0x0001E8E0 0x0001E8E0 0x000000DF
_CIatan - 0x004011C8 0x0001E8E4 0x0001E8E4 0x00000052
None 0x0000026A 0x004011CC 0x0001E8E8 0x0001E8E8 -
__vbaAryCopy - 0x004011D0 0x0001E8EC 0x0001E8EC 0x0000005C
__vbaStrMove - 0x004011D4 0x0001E8F0 0x0001E8F0 0x0000013F
__vbaCastObj - 0x004011D8 0x0001E8F4 0x0001E8F4 0x0000006B
__vbaR8IntI4 - 0x004011DC 0x0001E8F8 0x0001E8F8 0x00000119
__vbaStrVarCopy - 0x004011E0 0x0001E8FC 0x0001E8FC 0x00000147
_allmul - 0x004011E4 0x0001E900 0x0001E900 0x000001B4
_CItan - 0x004011E8 0x0001E904 0x0001E904 0x00000058
__vbaAryUnlock - 0x004011EC 0x0001E908 0x0001E908 0x00000063
_CIexp - 0x004011F0 0x0001E90C 0x0001E90C 0x00000054
None 0x00000244 0x004011F4 0x0001E910 0x0001E910 -
__vbaI4ErrVar - 0x004011F8 0x0001E914 0x0001E914 0x000000CB
__vbaFreeObj - 0x004011FC 0x0001E918 0x0001E918 0x000000AD
__vbaFreeStr - 0x00401200 0x0001E91C 0x0001E91C 0x000000AF
None 0x00000245 0x00401204 0x0001E920 0x0001E920 -
Memory Dumps (197)
»
Name Process ID Start VA End VA Dump Reason PE Rebuild Bitness Entry Point YARA Actions
6731f235ff78e22e5a0f1503542926bb707a95251b8cbd22c56fbd7fc5a8cbbf.exe 2 0x00400000 0x00420FFF Relevant Image False 32-bit 0x004019AC False
buffer 2 0x00510000 0x0051FFFF Marked Executable False 32-bit - False
buffer 2 0x00510000 0x0051FFFF First Execution False 32-bit 0x00515288 False
buffer 2 0x02AC0000 0x02AD9FFF Content Changed False 32-bit - False
buffer 2 0x02ABE000 0x02ABFFFF First Network Behavior False 32-bit - False
buffer 2 0x0294F000 0x0294FFFF First Network Behavior False 32-bit - False
buffer 2 0x00198000 0x0019FFFF First Network Behavior False 32-bit - False
buffer 2 0x00510000 0x0051FFFF First Network Behavior False 32-bit 0x00515288 False
buffer 2 0x01F20F48 0x01F21747 First Network Behavior False 32-bit - False
buffer 2 0x01F30000 0x0232FFFF First Network Behavior False 32-bit - False
buffer 2 0x026700A8 0x026701AB First Network Behavior False 32-bit - False
buffer 2 0x026701B8 0x026708AF First Network Behavior False 32-bit - False
buffer 2 0x026708B8 0x0267098B First Network Behavior False 32-bit - False
buffer 2 0x02670998 0x02672D83 First Network Behavior False 32-bit - False
buffer 2 0x02672D90 0x02672E93 First Network Behavior False 32-bit - False
buffer 2 0x02672EA0 0x02672F63 First Network Behavior False 32-bit - False
buffer 2 0x02672F70 0x026730AF First Network Behavior False 32-bit - False
buffer 2 0x026730B8 0x026734EB First Network Behavior False 32-bit - False
buffer 2 0x026734F8 0x0267368F First Network Behavior False 32-bit - False
buffer 2 0x02673698 0x026737DB First Network Behavior False 32-bit - False
buffer 2 0x026737E8 0x026738C3 First Network Behavior False 32-bit - False
buffer 2 0x026738D0 0x026739AB First Network Behavior False 32-bit - False
buffer 2 0x026739B8 0x02673A93 First Network Behavior False 32-bit - False
buffer 2 0x02673AA0 0x02673B9B First Network Behavior False 32-bit - False
buffer 2 0x028404D0 0x0284057F First Network Behavior False 32-bit - False
buffer 2 0x02843F98 0x028440AB First Network Behavior False 32-bit - False
buffer 2 0x028440B8 0x0284423B First Network Behavior False 32-bit - False
buffer 2 0x028442D0 0x028445C7 First Network Behavior False 32-bit - False
buffer 2 0x028445F0 0x02844703 First Network Behavior False 32-bit - False
buffer 2 0x02844710 0x02844793 First Network Behavior False 32-bit - False
buffer 2 0x028447A0 0x028448E7 First Network Behavior False 32-bit - False
buffer 2 0x02844910 0x02844A23 First Network Behavior False 32-bit - False
buffer 2 0x02844A30 0x02844C13 First Network Behavior False 32-bit - False
buffer 2 0x02844C20 0x02844CCF First Network Behavior False 32-bit - False
buffer 2 0x02844CD8 0x0284507B First Network Behavior False 32-bit - False
buffer 2 0x028450A8 0x028451BB First Network Behavior False 32-bit - False
buffer 2 0x028451E0 0x0284536F First Network Behavior False 32-bit - False
buffer 2 0x02845378 0x028453FF First Network Behavior False 32-bit - False
buffer 2 0x02845408 0x02845717 First Network Behavior False 32-bit - False
buffer 2 0x02845740 0x02845853 First Network Behavior False 32-bit - False
buffer 2 0x02845878 0x02845A3F First Network Behavior False 32-bit - False
buffer 2 0x02845A48 0x02845AEF First Network Behavior False 32-bit - False
buffer 2 0x02845AF8 0x02845E67 First Network Behavior False 32-bit - False
buffer 2 0x02845F98 0x02846037 First Network Behavior False 32-bit - False
buffer 2 0x02846040 0x02846153 First Network Behavior False 32-bit - False
buffer 2 0x028461A0 0x0284628F First Network Behavior False 32-bit - False
buffer 2 0x028462E8 0x028464DB First Network Behavior False 32-bit - False
buffer 2 0x028464E8 0x028465FB First Network Behavior False 32-bit - False
buffer 2 0x02846660 0x0284677F First Network Behavior False 32-bit - False
buffer 2 0x028467F0 0x02846A3F First Network Behavior False 32-bit - False
buffer 2 0x02846A68 0x02846B7B First Network Behavior False 32-bit - False
buffer 2 0x02849B10 0x02849C93 First Network Behavior False 32-bit - False
buffer 2 0x02849CA0 0x02849DB3 First Network Behavior False 32-bit - False
buffer 2 0x0284A5F8 0x0284A6CB First Network Behavior False 32-bit - False
buffer 2 0x0284A728 0x0284A8EF First Network Behavior False 32-bit - False
buffer 2 0x0284A8F8 0x0284AA0B First Network Behavior False 32-bit - False
buffer 2 0x0284AA60 0x0284AB4B First Network Behavior False 32-bit - False
buffer 2 0x0284ABA8 0x0284AD9F First Network Behavior False 32-bit - False
buffer 2 0x0284ADD8 0x0284AE97 First Network Behavior False 32-bit - False
buffer 2 0x0284AEF8 0x0284B00B First Network Behavior False 32-bit - False
buffer 2 0x0284B220 0x0284B2F3 First Network Behavior False 32-bit - False
buffer 2 0x0284B300 0x0284B4C7 First Network Behavior False 32-bit - False
buffer 2 0x0284B4F8 0x0284B60B First Network Behavior False 32-bit - False
buffer 2 0x0284B620 0x0284B733 First Network Behavior False 32-bit - False
buffer 2 0x0284B748 0x0284B85B First Network Behavior False 32-bit - False
buffer 2 0x0284B870 0x0284B983 First Network Behavior False 32-bit - False
buffer 2 0x0284B998 0x0284BAAB First Network Behavior False 32-bit - False
buffer 2 0x0284BAC0 0x0284BBD3 First Network Behavior False 32-bit - False
buffer 2 0x0284BBE8 0x0284BCFB First Network Behavior False 32-bit - False
buffer 2 0x0284BD10 0x0284BE23 First Network Behavior False 32-bit - False
buffer 2 0x0284BE38 0x0284BF4B First Network Behavior False 32-bit - False
buffer 2 0x0284BF60 0x0284C073 First Network Behavior False 32-bit - False
buffer 2 0x0284C088 0x0284C19B First Network Behavior False 32-bit - False
buffer 2 0x0284C1B0 0x0284C2C3 First Network Behavior False 32-bit - False
buffer 2 0x0284C2D8 0x0284C3EB First Network Behavior False 32-bit - False
buffer 2 0x0284C4D8 0x0284C5DF First Network Behavior False 32-bit - False
buffer 2 0x0284CDF0 0x0284D01F First Network Behavior False 32-bit - False
buffer 2 0x0284D028 0x0284D12F First Network Behavior False 32-bit - False
buffer 2 0x0284D138 0x0284D367 First Network Behavior False 32-bit - False
buffer 2 0x0284D3A0 0x0284D42F First Network Behavior False 32-bit - False
buffer 2 0x0284D468 0x0284D5AB First Network Behavior False 32-bit - False
buffer 2 0x0284D5E8 0x0284D677 First Network Behavior False 32-bit - False
buffer 2 0x0284D6B0 0x0284D7F3 First Network Behavior False 32-bit - False
buffer 2 0x0284D800 0x0284D8CF First Network Behavior False 32-bit - False
buffer 2 0x0284D9A0 0x0284DB3F First Network Behavior False 32-bit - False
buffer 2 0x0284DB78 0x0284DC3F First Network Behavior False 32-bit - False
buffer 2 0x0284DC48 0x0284DDF7 First Network Behavior False 32-bit - False
buffer 2 0x0284DE30 0x0284DF1B First Network Behavior False 32-bit - False
buffer 2 0x0284DF88 0x0284E17F First Network Behavior False 32-bit - False
buffer 2 0x0284E1C8 0x0284E27F First Network Behavior False 32-bit - False
buffer 2 0x0284E320 0x0284E41B First Network Behavior False 32-bit - False
buffer 2 0x0284E428 0x0284E517 First Network Behavior False 32-bit - False
buffer 2 0x0284E520 0x0284E60F First Network Behavior False 32-bit - False
buffer 2 0x0284E618 0x0284E6AF First Network Behavior False 32-bit - False
buffer 2 0x0284E6B8 0x0284E80B First Network Behavior False 32-bit - False
buffer 2 0x0284E818 0x0284E8EF First Network Behavior False 32-bit - False
buffer 2 0x0284E8F8 0x0284EACF First Network Behavior False 32-bit - False
buffer 2 0x0284EAE8 0x0284EC63 First Network Behavior False 32-bit - False
buffer 2 0x0284ECB8 0x0284EFA7 First Network Behavior False 32-bit - False
buffer 2 0x02AC0000 0x02AD9FFF First Network Behavior False 32-bit - False
6731f235ff78e22e5a0f1503542926bb707a95251b8cbd22c56fbd7fc5a8cbbf.exe 2 0x00400000 0x00420FFF First Network Behavior False 32-bit 0x00418C4B False
counters.dat 2 0x006E0000 0x006E0FFF First Network Behavior False 32-bit - False
buffer 2 0x00510000 0x0051FFFF Final Dump False 32-bit - False
buffer 2 0x01F20F48 0x01F21747 Final Dump False 32-bit - False
buffer 2 0x01F30000 0x0232FFFF Final Dump False 32-bit - False
buffer 2 0x026700A8 0x026701AB Final Dump False 32-bit - False
buffer 2 0x026701B8 0x026708AF Final Dump False 32-bit - False
buffer 2 0x026708B8 0x0267098B Final Dump False 32-bit - False
buffer 2 0x02670998 0x02672D83 Final Dump False 32-bit - False
buffer 2 0x02672D90 0x02672E93 Final Dump False 32-bit - False
buffer 2 0x02672EA0 0x02672F63 Final Dump False 32-bit - False
buffer 2 0x02672F70 0x026730AF Final Dump False 32-bit - False
buffer 2 0x026730B8 0x026734EB Final Dump False 32-bit - False
buffer 2 0x026734F8 0x0267368F Final Dump False 32-bit - False
buffer 2 0x02673698 0x026737DB Final Dump False 32-bit - False
buffer 2 0x026737E8 0x026738C3 Final Dump False 32-bit - False
buffer 2 0x026738D0 0x026739AB Final Dump False 32-bit - False
buffer 2 0x026739B8 0x02673A93 Final Dump False 32-bit - False
buffer 2 0x02673AA0 0x02673B9B Final Dump False 32-bit - False
buffer 2 0x028404D0 0x0284057F Final Dump False 32-bit - False
buffer 2 0x02843F98 0x028440AB Final Dump False 32-bit - False
buffer 2 0x028440B8 0x0284423B Final Dump False 32-bit - False
buffer 2 0x028442D0 0x028445C7 Final Dump False 32-bit - False
buffer 2 0x028445F0 0x02844703 Final Dump False 32-bit - False
buffer 2 0x02844710 0x02844793 Final Dump False 32-bit - False
buffer 2 0x028447A0 0x028448E7 Final Dump False 32-bit - False
buffer 2 0x02844910 0x02844A23 Final Dump False 32-bit - False
buffer 2 0x02844A30 0x02844C13 Final Dump False 32-bit - False
buffer 2 0x02844C20 0x02844CCF Final Dump False 32-bit - False
buffer 2 0x02844CD8 0x0284507B Final Dump False 32-bit - False
buffer 2 0x028450A8 0x028451BB Final Dump False 32-bit - False
buffer 2 0x028451E0 0x0284536F Final Dump False 32-bit - False
buffer 2 0x02845378 0x028453FF Final Dump False 32-bit - False
buffer 2 0x02845408 0x02845717 Final Dump False 32-bit - False
buffer 2 0x02845740 0x02845853 Final Dump False 32-bit - False
buffer 2 0x02845878 0x02845A3F Final Dump False 32-bit - False
buffer 2 0x02845A48 0x02845AEF Final Dump False 32-bit - False
buffer 2 0x02845AF8 0x02845E67 Final Dump False 32-bit - False
buffer 2 0x02845F98 0x02846037 Final Dump False 32-bit - False
buffer 2 0x02846040 0x02846153 Final Dump False 32-bit - False
buffer 2 0x028461A0 0x0284628F Final Dump False 32-bit - False
buffer 2 0x028462E8 0x028464DB Final Dump False 32-bit - False
buffer 2 0x028464E8 0x028465FB Final Dump False 32-bit - False
buffer 2 0x02846660 0x0284677F Final Dump False 32-bit - False
buffer 2 0x028467F0 0x02846A3F Final Dump False 32-bit - False
buffer 2 0x02846A68 0x02846B7B Final Dump False 32-bit - False
buffer 2 0x02849B10 0x02849C93 Final Dump False 32-bit - False
buffer 2 0x02849CA0 0x02849DB3 Final Dump False 32-bit - False
buffer 2 0x0284A5F8 0x0284A6CB Final Dump False 32-bit - False
buffer 2 0x0284A728 0x0284A8EF Final Dump False 32-bit - False
buffer 2 0x0284A8F8 0x0284AA0B Final Dump False 32-bit - False
buffer 2 0x0284AA60 0x0284AB4B Final Dump False 32-bit - False
buffer 2 0x0284ABA8 0x0284AD9F Final Dump False 32-bit - False
buffer 2 0x0284ADD8 0x0284AE97 Final Dump False 32-bit - False
buffer 2 0x0284AEF8 0x0284B00B Final Dump False 32-bit - False
buffer 2 0x0284B220 0x0284B2F3 Final Dump False 32-bit - False
buffer 2 0x0284B300 0x0284B4C7 Final Dump False 32-bit - False
buffer 2 0x0284B4F8 0x0284B60B Final Dump False 32-bit - False
buffer 2 0x0284B620 0x0284B733 Final Dump False 32-bit - False
buffer 2 0x0284B748 0x0284B85B Final Dump False 32-bit - False
buffer 2 0x0284B870 0x0284B983 Final Dump False 32-bit - False
buffer 2 0x0284B998 0x0284BAAB Final Dump False 32-bit - False
buffer 2 0x0284BAC0 0x0284BBD3 Final Dump False 32-bit - False
buffer 2 0x0284BBE8 0x0284BCFB Final Dump False 32-bit - False
buffer 2 0x0284BD10 0x0284BE23 Final Dump False 32-bit - False
buffer 2 0x0284BE38 0x0284BF4B Final Dump False 32-bit - False
buffer 2 0x0284BF60 0x0284C073 Final Dump False 32-bit - False
buffer 2 0x0284C088 0x0284C19B Final Dump False 32-bit - False
buffer 2 0x0284C1B0 0x0284C2C3 Final Dump False 32-bit - False
buffer 2 0x0284C2D8 0x0284C3EB Final Dump False 32-bit - False
buffer 2 0x0284C4D8 0x0284C5DF Final Dump False 32-bit - False
buffer 2 0x0284CDF0 0x0284D01F Final Dump False 32-bit - False
buffer 2 0x0284D028 0x0284D12F Final Dump False 32-bit - False
buffer 2 0x0284D138 0x0284D367 Final Dump False 32-bit - False
buffer 2 0x0284D3A0 0x0284D42F Final Dump False 32-bit - False
buffer 2 0x0284D468 0x0284D5AB Final Dump False 32-bit - False
buffer 2 0x0284D5E8 0x0284D677 Final Dump False 32-bit - False
buffer 2 0x0284D6B0 0x0284D7F3 Final Dump False 32-bit - False
buffer 2 0x0284D800 0x0284D8CF Final Dump False 32-bit - False
buffer 2 0x0284D9A0 0x0284DB3F Final Dump False 32-bit - False
buffer 2 0x0284DB78 0x0284DC3F Final Dump False 32-bit - False
buffer 2 0x0284DC48 0x0284DDF7 Final Dump False 32-bit - False
buffer 2 0x0284DE30 0x0284DF1B Final Dump False 32-bit - False
buffer 2 0x0284DF88 0x0284E17F Final Dump False 32-bit - False
buffer 2 0x0284E1C8 0x0284E27F Final Dump False 32-bit - False
buffer 2 0x0284E320 0x0284E41B Final Dump False 32-bit - False
buffer 2 0x0284E428 0x0284E517 Final Dump False 32-bit - False
buffer 2 0x0284E520 0x0284E60F Final Dump False 32-bit - False
buffer 2 0x0284E618 0x0284E6AF Final Dump False 32-bit - False
buffer 2 0x0284E6B8 0x0284E80B Final Dump False 32-bit - False
buffer 2 0x0284E818 0x0284E8EF Final Dump False 32-bit - False
buffer 2 0x0284E8F8 0x0284EACF Final Dump False 32-bit - False
buffer 2 0x0284EAE8 0x0284EC63 Final Dump False 32-bit - False
buffer 2 0x0284ECB8 0x0284EFA7 Final Dump False 32-bit - False
buffer 2 0x02AC0000 0x02AD9FFF Final Dump False 32-bit - False
6731f235ff78e22e5a0f1503542926bb707a95251b8cbd22c56fbd7fc5a8cbbf.exe 2 0x00400000 0x00420FFF Final Dump False 32-bit 0x004166FE False
counters.dat 2 0x006E0000 0x006E0FFF Final Dump False 32-bit - False
c:\windows\system\svchost.exe Dropped File Binary
Suspicious
»
Also Known As C:\Windows\System\svchost.exe (Accessed File)
MIME Type application/vnd.microsoft.portable-executable
File Size 274.48 KB
MD5 92d58d4bcd7584ed57cf986b584781b1 Copy to Clipboard
SHA1 590db5b033e7249d1a21a082ad56783d90a68915 Copy to Clipboard
SHA256 e2612d8eaf4e999a6e2398430c27d90f57e127eb24fc87f0032224fec3ba2c02 Copy to Clipboard
SSDeep 3072:UvEfVUzSLhIVbV6i5LirrlZrHyrUHUckoMQ2RN6unV:UvEN2U+T6i5LirrllHy4HUcMQY6O Copy to Clipboard
ImpHash 98f67c550a7da65513e63ffd998f6b2e Copy to Clipboard
PE Information
»
Image Base 0x00400000
Entry Point 0x00403670
Size Of Code 0x0002B000
Size Of Initialized Data 0x00003000
File Type IMAGE_FILE_EXECUTABLE_IMAGE
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
Machine Type IMAGE_FILE_MACHINE_I386
Compile Timestamp 2011-06-14 21:01 (UTC+2)
Version Information (6)
»
CompanyName Microsoft
ProductName Win
FileVersion 1.00
ProductVersion 1.00
InternalName Win
OriginalFilename Win.exe
Sections (4)
»
Name Virtual Address Virtual Size Raw Data Size Raw Data Offset Flags Entropy
.text 0x00401000 0x0002A728 0x0002B000 0x00001000 IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE 5.95
.data 0x0042C000 0x00001B74 0x00001000 0x0002C000 IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE 0.0
.rsrc 0x0042E000 0x000005E0 0x00001000 0x0002D000 IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ 1.69
.tdata 0x0042F000 0x0000F000 0x0000F000 0x0002E000 IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE 0.0
Imports (1)
»
MSVBVM60.DLL (160)
»
API Name Ordinal IAT Address Thunk RVA Thunk Offset Hint
EVENT_SINK_GetIDsOfNames - 0x00401000 0x0002ACAC 0x0002ACAC 0x00000000
__vbaStrI2 - 0x00401004 0x0002ACB0 0x0002ACB0 0x00000000
None 0x000002B2 0x00401008 0x0002ACB4 0x0002ACB4 -
_CIcos - 0x0040100C 0x0002ACB8 0x0002ACB8 0x00000000
_adj_fptan - 0x00401010 0x0002ACBC 0x0002ACBC 0x00000000
__vbaStrI4 - 0x00401014 0x0002ACC0 0x0002ACC0 0x00000000
__vbaVarVargNofree - 0x00401018 0x0002ACC4 0x0002ACC4 0x00000000
__vbaFreeVar - 0x0040101C 0x0002ACC8 0x0002ACC8 0x00000000
__vbaStrVarMove - 0x00401020 0x0002ACCC 0x0002ACCC 0x00000000
__vbaLenBstr - 0x00401024 0x0002ACD0 0x0002ACD0 0x00000000
__vbaLateIdCall - 0x00401028 0x0002ACD4 0x0002ACD4 0x00000000
__vbaPut3 - 0x0040102C 0x0002ACD8 0x0002ACD8 0x00000000
__vbaEnd - 0x00401030 0x0002ACDC 0x0002ACDC 0x00000000
__vbaFreeVarList - 0x00401034 0x0002ACE0 0x0002ACE0 0x00000000
_adj_fdiv_m64 - 0x00401038 0x0002ACE4 0x0002ACE4 0x00000000
__vbaPut4 - 0x0040103C 0x0002ACE8 0x0002ACE8 0x00000000
EVENT_SINK_Invoke - 0x00401040 0x0002ACEC 0x0002ACEC 0x00000000
__vbaRaiseEvent - 0x00401044 0x0002ACF0 0x0002ACF0 0x00000000
__vbaFreeObjList - 0x00401048 0x0002ACF4 0x0002ACF4 0x00000000
None 0x00000204 0x0040104C 0x0002ACF8 0x0002ACF8 -
__vbaStrErrVarCopy - 0x00401050 0x0002ACFC 0x0002ACFC 0x00000000
None 0x00000205 0x00401054 0x0002AD00 0x0002AD00 -
_adj_fprem1 - 0x00401058 0x0002AD04 0x0002AD04 0x00000000
__vbaRecAnsiToUni - 0x0040105C 0x0002AD08 0x0002AD08 0x00000000
None 0x00000207 0x00401060 0x0002AD0C 0x0002AD0C -
__vbaCopyBytes - 0x00401064 0x0002AD10 0x0002AD10 0x00000000
__vbaStrCat - 0x00401068 0x0002AD14 0x0002AD14 0x00000000
__vbaLsetFixstr - 0x0040106C 0x0002AD18 0x0002AD18 0x00000000
__vbaRecDestruct - 0x00401070 0x0002AD1C 0x0002AD1C 0x00000000
__vbaSetSystemError - 0x00401074 0x0002AD20 0x0002AD20 0x00000000
None 0x00000295 0x00401078 0x0002AD24 0x0002AD24 -
__vbaHresultCheckObj - 0x0040107C 0x0002AD28 0x0002AD28 0x00000000
__vbaNameFile - 0x00401080 0x0002AD2C 0x0002AD2C 0x00000000
_adj_fdiv_m32 - 0x00401084 0x0002AD30 0x0002AD30 0x00000000
__vbaAryVar - 0x00401088 0x0002AD34 0x0002AD34 0x00000000
Zombie_GetTypeInfo - 0x0040108C 0x0002AD38 0x0002AD38 0x00000000
__vbaAryDestruct - 0x00401090 0x0002AD3C 0x0002AD3C 0x00000000
None 0x0000029D 0x00401094 0x0002AD40 0x0002AD40 -
None 0x00000251 0x00401098 0x0002AD44 0x0002AD44 -
__vbaBoolStr - 0x0040109C 0x0002AD48 0x0002AD48 0x00000000
__vbaExitProc - 0x004010A0 0x0002AD4C 0x0002AD4C 0x00000000
__vbaI4Abs - 0x004010A4 0x0002AD50 0x0002AD50 0x00000000
None 0x00000252 0x004010A8 0x0002AD54 0x0002AD54 -
__vbaOnError - 0x004010AC 0x0002AD58 0x0002AD58 0x00000000
__vbaObjSet - 0x004010B0 0x0002AD5C 0x0002AD5C 0x00000000
_adj_fdiv_m16i - 0x004010B4 0x0002AD60 0x0002AD60 0x00000000
__vbaObjSetAddref - 0x004010B8 0x0002AD64 0x0002AD64 0x00000000
_adj_fdivr_m16i - 0x004010BC 0x0002AD68 0x0002AD68 0x00000000
None 0x00000256 0x004010C0 0x0002AD6C 0x0002AD6C -
__vbaFpR4 - 0x004010C4 0x0002AD70 0x0002AD70 0x00000000
None 0x000002C1 0x004010C8 0x0002AD74 0x0002AD74 -
__vbaStrFixstr - 0x004010CC 0x0002AD78 0x0002AD78 0x00000000
_CIsin - 0x004010D0 0x0002AD7C 0x0002AD7C 0x00000000
__vbaErase - 0x004010D4 0x0002AD80 0x0002AD80 0x00000000
None 0x00000277 0x004010D8 0x0002AD84 0x0002AD84 -
None 0x000002C5 0x004010DC 0x0002AD88 0x0002AD88 -
None 0x0000020D 0x004010E0 0x0002AD8C 0x0002AD8C -
__vbaChkstk - 0x004010E4 0x0002AD90 0x0002AD90 0x00000000
__vbaFileClose - 0x004010E8 0x0002AD94 0x0002AD94 0x00000000
EVENT_SINK_AddRef - 0x004010EC 0x0002AD98 0x0002AD98 0x00000000
__vbaGenerateBoundsError - 0x004010F0 0x0002AD9C 0x0002AD9C 0x00000000
__vbaGet3 - 0x004010F4 0x0002ADA0 0x0002ADA0 0x00000000
__vbaStrCmp - 0x004010F8 0x0002ADA4 0x0002ADA4 0x00000000
None 0x00000211 0x004010FC 0x0002ADA8 0x0002ADA8 -
__vbaGet4 - 0x00401100 0x0002ADAC 0x0002ADAC 0x00000000
__vbaPutOwner3 - 0x00401104 0x0002ADB0 0x0002ADB0 0x00000000
__vbaVarTstEq - 0x00401108 0x0002ADB4 0x0002ADB4 0x00000000
__vbaAryConstruct2 - 0x0040110C 0x0002ADB8 0x0002ADB8 0x00000000
__vbaObjVar - 0x00401110 0x0002ADBC 0x0002ADBC 0x00000000
__vbaI2I4 - 0x00401114 0x0002ADC0 0x0002ADC0 0x00000000
DllFunctionCall - 0x00401118 0x0002ADC4 0x0002ADC4 0x00000000
__vbaVarLateMemSt - 0x0040111C 0x0002ADC8 0x0002ADC8 0x00000000
__vbaFpUI1 - 0x00401120 0x0002ADCC 0x0002ADCC 0x00000000
__vbaRedimPreserve - 0x00401124 0x0002ADD0 0x0002ADD0 0x00000000
__vbaStrR4 - 0x00401128 0x0002ADD4 0x0002ADD4 0x00000000
_adj_fpatan - 0x0040112C 0x0002ADD8 0x0002ADD8 0x00000000
__vbaFixstrConstruct - 0x00401130 0x0002ADDC 0x0002ADDC 0x00000000
__vbaLateIdCallLd - 0x00401134 0x0002ADE0 0x0002ADE0 0x00000000
Zombie_GetTypeInfoCount - 0x00401138 0x0002ADE4 0x0002ADE4 0x00000000
__vbaRedim - 0x0040113C 0x0002ADE8 0x0002ADE8 0x00000000
__vbaRecUniToAnsi - 0x00401140 0x0002ADEC 0x0002ADEC 0x00000000
EVENT_SINK_Release - 0x00401144 0x0002ADF0 0x0002ADF0 0x00000000
__vbaNew - 0x00401148 0x0002ADF4 0x0002ADF4 0x00000000
None 0x00000258 0x0040114C 0x0002ADF8 0x0002ADF8 -
__vbaUI1I2 - 0x00401150 0x0002ADFC 0x0002ADFC 0x00000000
_CIsqrt - 0x00401154 0x0002AE00 0x0002AE00 0x00000000
EVENT_SINK_QueryInterface - 0x00401158 0x0002AE04 0x0002AE04 0x00000000
__vbaExceptHandler - 0x0040115C 0x0002AE08 0x0002AE08 0x00000000
None 0x000002C7 0x00401160 0x0002AE0C 0x0002AE0C -
None 0x000002C8 0x00401164 0x0002AE10 0x0002AE10 -
__vbaStrToUnicode - 0x00401168 0x0002AE14 0x0002AE14 0x00000000
None 0x0000025E 0x0040116C 0x0002AE18 0x0002AE18 -
_adj_fprem - 0x00401170 0x0002AE1C 0x0002AE1C 0x00000000
_adj_fdivr_m64 - 0x00401174 0x0002AE20 0x0002AE20 0x00000000
None 0x000002CA 0x00401178 0x0002AE24 0x0002AE24 -
None 0x000002CC 0x0040117C 0x0002AE28 0x0002AE28 -
None 0x00000261 0x00401180 0x0002AE2C 0x0002AE2C -
__vbaFPException - 0x00401184 0x0002AE30 0x0002AE30 0x00000000
None 0x000002CD 0x00401188 0x0002AE34 0x0002AE34 -
None 0x0000013F 0x0040118C 0x0002AE38 0x0002AE38 -
__vbaGetOwner3 - 0x00401190 0x0002AE3C 0x0002AE3C 0x00000000
__vbaUbound - 0x00401194 0x0002AE40 0x0002AE40 0x00000000
None 0x00000217 0x00401198 0x0002AE44 0x0002AE44 -
__vbaFileSeek - 0x0040119C 0x0002AE48 0x0002AE48 0x00000000
None 0x00000284 0x004011A0 0x0002AE4C 0x0002AE4C -
None 0x00000219 0x004011A4 0x0002AE50 0x0002AE50 -
_CIlog - 0x004011A8 0x0002AE54 0x0002AE54 0x00000000
__vbaErrorOverflow - 0x004011AC 0x0002AE58 0x0002AE58 0x00000000
__vbaFileOpen - 0x004011B0 0x0002AE5C 0x0002AE5C 0x00000000
__vbaVarLateMemCallLdRf - 0x004011B4 0x0002AE60 0x0002AE60 0x00000000
None 0x00000288 0x004011B8 0x0002AE64 0x0002AE64 -
None 0x0000023A 0x004011BC 0x0002AE68 0x0002AE68 -
__vbaNew2 - 0x004011C0 0x0002AE6C 0x0002AE6C 0x00000000
__vbaInStr - 0x004011C4 0x0002AE70 0x0002AE70 0x00000000
_adj_fdiv_m32i - 0x004011C8 0x0002AE74 0x0002AE74 0x00000000
None 0x0000023C 0x004011CC 0x0002AE78 0x0002AE78 -
_adj_fdivr_m32i - 0x004011D0 0x0002AE7C 0x0002AE7C 0x00000000
__vbaStrCopy - 0x004011D4 0x0002AE80 0x0002AE80 0x00000000
__vbaI4Str - 0x004011D8 0x0002AE84 0x0002AE84 0x00000000
__vbaFreeStrList - 0x004011DC 0x0002AE88 0x0002AE88 0x00000000
_adj_fdivr_m32 - 0x004011E0 0x0002AE8C 0x0002AE8C 0x00000000
_adj_fdiv_r - 0x004011E4 0x0002AE90 0x0002AE90 0x00000000
None 0x00000242 0x004011E8 0x0002AE94 0x0002AE94 -
None 0x00000064 0x004011EC 0x0002AE98 0x0002AE98 -
__vbaVarSetVar - 0x004011F0 0x0002AE9C 0x0002AE9C 0x00000000
__vbaI4Var - 0x004011F4 0x0002AEA0 0x0002AEA0 0x00000000
None 0x000002B1 0x004011F8 0x0002AEA4 0x0002AEA4 -
__vbaLateMemCall - 0x004011FC 0x0002AEA8 0x0002AEA8 0x00000000
__vbaVarAdd - 0x00401200 0x0002AEAC 0x0002AEAC 0x00000000
None 0x00000263 0x00401204 0x0002AEB0 0x0002AEB0 -
__vbaAryLock - 0x00401208 0x0002AEB4 0x0002AEB4 0x00000000
None 0x00000140 0x0040120C 0x0002AEB8 0x0002AEB8 -
__vbaStrComp - 0x00401210 0x0002AEBC 0x0002AEBC 0x00000000
__vbaVarDup - 0x00401214 0x0002AEC0 0x0002AEC0 0x00000000
__vbaStrToAnsi - 0x00401218 0x0002AEC4 0x0002AEC4 0x00000000
None 0x00000141 0x0040121C 0x0002AEC8 0x0002AEC8 -
__vbaFpI2 - 0x00401220 0x0002AECC 0x0002AECC 0x00000000
__vbaFpI4 - 0x00401224 0x0002AED0 0x0002AED0 0x00000000
__vbaVarLateMemCallLd - 0x00401228 0x0002AED4 0x0002AED4 0x00000000
None 0x00000268 0x0040122C 0x0002AED8 0x0002AED8 -
__vbaVarSetObjAddref - 0x00401230 0x0002AEDC 0x0002AEDC 0x00000000
__vbaRecDestructAnsi - 0x00401234 0x0002AEE0 0x0002AEE0 0x00000000
__vbaLateMemCallLd - 0x00401238 0x0002AEE4 0x0002AEE4 0x00000000
_CIatan - 0x0040123C 0x0002AEE8 0x0002AEE8 0x00000000
__vbaAryCopy - 0x00401240 0x0002AEEC 0x0002AEEC 0x00000000
__vbaStrMove - 0x00401244 0x0002AEF0 0x0002AEF0 0x00000000
None 0x0000026A 0x00401248 0x0002AEF4 0x0002AEF4 -
__vbaCastObj - 0x0040124C 0x0002AEF8 0x0002AEF8 0x00000000
__vbaR8IntI4 - 0x00401250 0x0002AEFC 0x0002AEFC 0x00000000
None 0x0000028A 0x00401254 0x0002AF00 0x0002AF00 -
_allmul - 0x00401258 0x0002AF04 0x0002AF04 0x00000000
__vbaVarLateMemCallSt - 0x0040125C 0x0002AF08 0x0002AF08 0x00000000
_CItan - 0x00401260 0x0002AF0C 0x0002AF0C 0x00000000
None 0x00000222 0x00401264 0x0002AF10 0x0002AF10 -
__vbaAryUnlock - 0x00401268 0x0002AF14 0x0002AF14 0x00000000
_CIexp - 0x0040126C 0x0002AF18 0x0002AF18 0x00000000
__vbaFreeObj - 0x00401270 0x0002AF1C 0x0002AF1C 0x00000000
__vbaFreeStr - 0x00401274 0x0002AF20 0x0002AF20 0x00000000
None 0x00000244 0x00401278 0x0002AF24 0x0002AF24 -
None 0x00000245 0x0040127C 0x0002AF28 0x0002AF28 -
Memory Dumps (133)
»
Name Process ID Start VA End VA Dump Reason PE Rebuild Bitness Entry Point YARA Actions
svchost.exe 7 0x00400000 0x0043DFFF First Execution False 32-bit 0x00403670 False
buffer 7 0x00500000 0x0050FFFF Marked Executable False 32-bit - False
buffer 7 0x00500000 0x0050FFFF Content Changed False 32-bit - False
buffer 7 0x00500000 0x0050FFFF First Execution False 32-bit 0x00506338 False
buffer 7 0x00500000 0x0050FFFF Final Dump False 32-bit - False
buffer 7 0x02401538 0x024019B7 Final Dump False 32-bit - False
buffer 7 0x024019C0 0x024021BF Final Dump False 32-bit - False
buffer 7 0x02500000 0x028FFFFF Final Dump False 32-bit - False
buffer 7 0x02E01020 0x02E01123 Final Dump False 32-bit - False
buffer 7 0x02E01130 0x02E01FF7 Final Dump False 32-bit - False
buffer 7 0x02E02060 0x02E02403 Final Dump False 32-bit - False
buffer 7 0x02E02410 0x02E027B3 Final Dump False 32-bit - False
buffer 7 0x02E027C0 0x02E02893 Final Dump False 32-bit - False
buffer 7 0x02E028E8 0x02E02967 Final Dump False 32-bit - False
buffer 7 0x02E02B10 0x02E02F43 Final Dump False 32-bit - False
buffer 7 0x02E02F50 0x02E03383 Final Dump False 32-bit - False
buffer 7 0x02E033D8 0x02E034EB Final Dump False 32-bit - False
buffer 7 0x02E03510 0x02E0367B Final Dump False 32-bit - False
buffer 7 0x02E036F8 0x02E039BF Final Dump False 32-bit - False
buffer 7 0x02E03A48 0x02E03B5B Final Dump False 32-bit - False
buffer 7 0x02E03BE0 0x02E03C7B Final Dump False 32-bit - False
buffer 7 0x02E03CA8 0x02E03DBB Final Dump False 32-bit - False
buffer 7 0x02E03DE0 0x02E03EBB Final Dump False 32-bit - False
buffer 7 0x02E03EE8 0x02E03FFB Final Dump False 32-bit - False
buffer 7 0x02E04018 0x02E0419B Final Dump False 32-bit - False
buffer 7 0x02E04230 0x02E04527 Final Dump False 32-bit - False
buffer 7 0x02E04550 0x02E04663 Final Dump False 32-bit - False
buffer 7 0x02E046C0 0x02E0475F Final Dump False 32-bit - False
buffer 7 0x02E04788 0x02E0489B Final Dump False 32-bit - False
buffer 7 0x02E04A08 0x02E04B1B Final Dump False 32-bit - False
buffer 7 0x02E04B28 0x02E04CAB Final Dump False 32-bit - False
buffer 7 0x02E04D40 0x02E05037 Final Dump False 32-bit - False
buffer 7 0x02E05060 0x02E05173 Final Dump False 32-bit - False
buffer 7 0x02E05180 0x02E05203 Final Dump False 32-bit - False
buffer 7 0x02E05210 0x02E05357 Final Dump False 32-bit - False
buffer 7 0x02E05380 0x02E05493 Final Dump False 32-bit - False
buffer 7 0x02E054A0 0x02E05683 Final Dump False 32-bit - False
buffer 7 0x02E05690 0x02E0573F Final Dump False 32-bit - False
buffer 7 0x02E05748 0x02E05AEB Final Dump False 32-bit - False
buffer 7 0x02E05B18 0x02E05C2B Final Dump False 32-bit - False
buffer 7 0x02E05C50 0x02E05DDF Final Dump False 32-bit - False
buffer 7 0x02E05DE8 0x02E05E6F Final Dump False 32-bit - False
buffer 7 0x02E05E78 0x02E06187 Final Dump False 32-bit - False
buffer 7 0x02E061B0 0x02E062C3 Final Dump False 32-bit - False
buffer 7 0x02E062E8 0x02E064AF Final Dump False 32-bit - False
buffer 7 0x02E064B8 0x02E0655F Final Dump False 32-bit - False
buffer 7 0x02E06568 0x02E068D7 Final Dump False 32-bit - False
buffer 7 0x02E069E0 0x02E06AD7 Final Dump False 32-bit - False
buffer 7 0x02E06AE0 0x02E06BF3 Final Dump False 32-bit - False
buffer 7 0x02E06C00 0x02E06D2B Final Dump False 32-bit - False
buffer 7 0x02E06D38 0x02E06DD7 Final Dump False 32-bit - False
buffer 7 0x02E06E10 0x02E06EAF Final Dump False 32-bit - False
buffer 7 0x02E06F00 0x02E07013 Final Dump False 32-bit - False
buffer 7 0x02E07078 0x02E07167 Final Dump False 32-bit - False
buffer 7 0x02E071C0 0x02E073B3 Final Dump False 32-bit - False
buffer 7 0x02E073E0 0x02E074F3 Final Dump False 32-bit - False
buffer 7 0x02E07540 0x02E0765F Final Dump False 32-bit - False
buffer 7 0x02E076D0 0x02E0791F Final Dump False 32-bit - False
buffer 7 0x02E07928 0x02E07A3B Final Dump False 32-bit - False
buffer 7 0x02E07A78 0x02E07B27 Final Dump False 32-bit - False
buffer 7 0x02E07B70 0x02E07CF3 Final Dump False 32-bit - False
buffer 7 0x02E07D30 0x02E07E03 Final Dump False 32-bit - False
buffer 7 0x02E07E60 0x02E08027 Final Dump False 32-bit - False
buffer 7 0x02E08060 0x02E080EF Final Dump False 32-bit - False
buffer 7 0x02E08180 0x02E0826B Final Dump False 32-bit - False
buffer 7 0x02E08278 0x02E0846F Final Dump False 32-bit - False
buffer 7 0x02E08478 0x02E0854B Final Dump False 32-bit - False
buffer 7 0x02E085B0 0x02E08777 Final Dump False 32-bit - False
buffer 7 0x02E08780 0x02E08887 Final Dump False 32-bit - False
buffer 7 0x02E088E8 0x02E08B17 Final Dump False 32-bit - False
buffer 7 0x02E08B20 0x02E08C27 Final Dump False 32-bit - False
buffer 7 0x02E08C90 0x02E08EBF Final Dump False 32-bit - False
buffer 7 0x02E08EC8 0x02E08F57 Final Dump False 32-bit - False
buffer 7 0x02E08F90 0x02E090D3 Final Dump False 32-bit - False
buffer 7 0x02E09150 0x02E0924B Final Dump False 32-bit - False
buffer 7 0x02E09280 0x02E093C3 Final Dump False 32-bit - False
buffer 7 0x02E093D0 0x02E0948F Final Dump False 32-bit - False
buffer 7 0x02E094E0 0x02E0967F Final Dump False 32-bit - False
buffer 7 0x02E096B8 0x02E0977F Final Dump False 32-bit - False
buffer 7 0x02E097E0 0x02E0998F Final Dump False 32-bit - False
buffer 7 0x02E099C8 0x02E09AB3 Final Dump False 32-bit - False
buffer 7 0x02E09B20 0x02E09D17 Final Dump False 32-bit - False
buffer 7 0x02E09D60 0x02E09E17 Final Dump False 32-bit - False
buffer 7 0x02E09E80 0x02E09F83 Final Dump False 32-bit - False
buffer 7 0x02E0A068 0x02E0A137 Final Dump False 32-bit - False
buffer 7 0x02E0A140 0x02E0A1D7 Final Dump False 32-bit - False
buffer 7 0x02E0A220 0x02E0A373 Final Dump False 32-bit - False
buffer 7 0x02E0A380 0x02E0A457 Final Dump False 32-bit - False
buffer 7 0x02E0A4A8 0x02E0A67F Final Dump False 32-bit - False
buffer 7 0x02E0A698 0x02E0A813 Final Dump False 32-bit - False
buffer 7 0x02E0A868 0x02E0AB57 Final Dump False 32-bit - False
buffer 7 0x02E0AB60 0x02E0B257 Final Dump False 32-bit - False
buffer 7 0x02E0B260 0x02E0B333 Final Dump False 32-bit - False
buffer 7 0x02E0B340 0x02E0D72B Final Dump False 32-bit - False
buffer 7 0x02E0D738 0x02E0D83B Final Dump False 32-bit - False
buffer 7 0x02E0D848 0x02E0D99B Final Dump False 32-bit - False
buffer 7 0x02E0D9A8 0x02E0DAE7 Final Dump False 32-bit - False
buffer 7 0x02E0DAF0 0x02E0DF23 Final Dump False 32-bit - False
buffer 7 0x02E0DF30 0x02E0E0C7 Final Dump False 32-bit - False
buffer 7 0x02E0E0D0 0x02E0E213 Final Dump False 32-bit - False
buffer 7 0x02E0E220 0x02E0E363 Final Dump False 32-bit - False
buffer 7 0x02E0E370 0x02E0E4E3 Final Dump False 32-bit - False
buffer 7 0x02E0E528 0x02E0E71B Final Dump False 32-bit - False
buffer 7 0x02E0E728 0x02E0EECB Final Dump False 32-bit - False
buffer 7 0x02E0EF40 0x02E0F07F Final Dump False 32-bit - False
buffer 7 0x02E0F088 0x02E0F4BB Final Dump False 32-bit - False
buffer 7 0x02E0F4C8 0x02E0F673 Final Dump False 32-bit - False
buffer 7 0x02E0F680 0x02E0F75B Final Dump False 32-bit - False
buffer 7 0x02E0F768 0x02E0F843 Final Dump False 32-bit - False
buffer 7 0x02E0F850 0x02E0F92B Final Dump False 32-bit - False
buffer 7 0x02E0F938 0x02E0FA7B Final Dump False 32-bit - False
buffer 7 0x02E0FA88 0x02E0FBCB Final Dump False 32-bit - False
buffer 7 0x02E0FBD8 0x02E0FCD3 Final Dump False 32-bit - False
buffer 7 0x02E14028 0x02E1413B Final Dump False 32-bit - False
buffer 7 0x02E14148 0x02E1425B Final Dump False 32-bit - False
buffer 7 0x02E14268 0x02E1437B Final Dump False 32-bit - False
buffer 7 0x02E14388 0x02E1449B Final Dump False 32-bit - False
buffer 7 0x02E144A8 0x02E145BB Final Dump False 32-bit - False
buffer 7 0x02E145C8 0x02E146DB Final Dump False 32-bit - False
buffer 7 0x02E146E8 0x02E147FB Final Dump False 32-bit - False
buffer 7 0x02E14808 0x02E1491B Final Dump False 32-bit - False
buffer 7 0x02E14928 0x02E14A3B Final Dump False 32-bit - False
buffer 7 0x02E14A48 0x02E14B5B Final Dump False 32-bit - False
buffer 7 0x02E14B68 0x02E14C7B Final Dump False 32-bit - False
buffer 7 0x02E14C88 0x02E14D9B Final Dump False 32-bit - False
buffer 7 0x02E14DA8 0x02E14EBB Final Dump False 32-bit - False
buffer 7 0x02E14EC8 0x02E14FDB Final Dump False 32-bit - False
buffer 7 0x02E16390 0x02E164A3 Final Dump False 32-bit - False
buffer 7 0x02E16930 0x02E16A47 Final Dump False 32-bit - False
buffer 7 0x02E16FF0 0x02E17107 Final Dump False 32-bit - False
buffer 7 0x02E17110 0x02E17223 Final Dump False 32-bit - False
buffer 7 0x03201020 0x03201133 Final Dump False 32-bit - False
svchost.exe 7 0x00400000 0x0043DFFF Final Dump False 32-bit - False
C:\Windows\System\explorer.exe Dropped File Binary
Suspicious
»
Also Known As c:\windows\system\explorer.exe (Dropped File, Accessed File)
MIME Type application/vnd.microsoft.portable-executable
File Size 274.34 KB
MD5 1653d0e5ec935bdd808425636847e37b Copy to Clipboard
SHA1 08a4167befd49624290b83d61296bab93ddac3ed Copy to Clipboard
SHA256 bbfbf670cc391ba413fd377448ea117982ed060f710a4937925b0dd5bf53c50f Copy to Clipboard
SSDeep 3072:UvEfVUzSLhIVbV6i5LirrlZrHyrUHUckoMQ2RN6unr:UvEN2U+T6i5LirrllHy4HUcMQY6u Copy to Clipboard
ImpHash 98f67c550a7da65513e63ffd998f6b2e Copy to Clipboard
PE Information
»
Image Base 0x00400000
Entry Point 0x00403670
Size Of Code 0x0002B000
Size Of Initialized Data 0x00003000
File Type IMAGE_FILE_EXECUTABLE_IMAGE
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
Machine Type IMAGE_FILE_MACHINE_I386
Compile Timestamp 2011-06-14 21:01 (UTC+2)
Version Information (6)
»
CompanyName Microsoft
ProductName Win
FileVersion 1.00
ProductVersion 1.00
InternalName Win
OriginalFilename Win.exe
Sections (4)
»
Name Virtual Address Virtual Size Raw Data Size Raw Data Offset Flags Entropy
.text 0x00401000 0x0002A728 0x0002B000 0x00001000 IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE 5.95
.data 0x0042C000 0x00001B74 0x00001000 0x0002C000 IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE 0.0
.rsrc 0x0042E000 0x000005E0 0x00001000 0x0002D000 IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ 1.69
.tdata 0x0042F000 0x0000F000 0x0000F000 0x0002E000 IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE 0.0
Imports (1)
»
MSVBVM60.DLL (160)
»
API Name Ordinal IAT Address Thunk RVA Thunk Offset Hint
EVENT_SINK_GetIDsOfNames - 0x00401000 0x0002ACAC 0x0002ACAC 0x00000000
__vbaStrI2 - 0x00401004 0x0002ACB0 0x0002ACB0 0x00000000
None 0x000002B2 0x00401008 0x0002ACB4 0x0002ACB4 -
_CIcos - 0x0040100C 0x0002ACB8 0x0002ACB8 0x00000000
_adj_fptan - 0x00401010 0x0002ACBC 0x0002ACBC 0x00000000
__vbaStrI4 - 0x00401014 0x0002ACC0 0x0002ACC0 0x00000000
__vbaVarVargNofree - 0x00401018 0x0002ACC4 0x0002ACC4 0x00000000
__vbaFreeVar - 0x0040101C 0x0002ACC8 0x0002ACC8 0x00000000
__vbaStrVarMove - 0x00401020 0x0002ACCC 0x0002ACCC 0x00000000
__vbaLenBstr - 0x00401024 0x0002ACD0 0x0002ACD0 0x00000000
__vbaLateIdCall - 0x00401028 0x0002ACD4 0x0002ACD4 0x00000000
__vbaPut3 - 0x0040102C 0x0002ACD8 0x0002ACD8 0x00000000
__vbaEnd - 0x00401030 0x0002ACDC 0x0002ACDC 0x00000000
__vbaFreeVarList - 0x00401034 0x0002ACE0 0x0002ACE0 0x00000000
_adj_fdiv_m64 - 0x00401038 0x0002ACE4 0x0002ACE4 0x00000000
__vbaPut4 - 0x0040103C 0x0002ACE8 0x0002ACE8 0x00000000
EVENT_SINK_Invoke - 0x00401040 0x0002ACEC 0x0002ACEC 0x00000000
__vbaRaiseEvent - 0x00401044 0x0002ACF0 0x0002ACF0 0x00000000
__vbaFreeObjList - 0x00401048 0x0002ACF4 0x0002ACF4 0x00000000
None 0x00000204 0x0040104C 0x0002ACF8 0x0002ACF8 -
__vbaStrErrVarCopy - 0x00401050 0x0002ACFC 0x0002ACFC 0x00000000
None 0x00000205 0x00401054 0x0002AD00 0x0002AD00 -
_adj_fprem1 - 0x00401058 0x0002AD04 0x0002AD04 0x00000000
__vbaRecAnsiToUni - 0x0040105C 0x0002AD08 0x0002AD08 0x00000000
None 0x00000207 0x00401060 0x0002AD0C 0x0002AD0C -
__vbaCopyBytes - 0x00401064 0x0002AD10 0x0002AD10 0x00000000
__vbaStrCat - 0x00401068 0x0002AD14 0x0002AD14 0x00000000
__vbaLsetFixstr - 0x0040106C 0x0002AD18 0x0002AD18 0x00000000
__vbaRecDestruct - 0x00401070 0x0002AD1C 0x0002AD1C 0x00000000
__vbaSetSystemError - 0x00401074 0x0002AD20 0x0002AD20 0x00000000
None 0x00000295 0x00401078 0x0002AD24 0x0002AD24 -
__vbaHresultCheckObj - 0x0040107C 0x0002AD28 0x0002AD28 0x00000000
__vbaNameFile - 0x00401080 0x0002AD2C 0x0002AD2C 0x00000000
_adj_fdiv_m32 - 0x00401084 0x0002AD30 0x0002AD30 0x00000000
__vbaAryVar - 0x00401088 0x0002AD34 0x0002AD34 0x00000000
Zombie_GetTypeInfo - 0x0040108C 0x0002AD38 0x0002AD38 0x00000000
__vbaAryDestruct - 0x00401090 0x0002AD3C 0x0002AD3C 0x00000000
None 0x0000029D 0x00401094 0x0002AD40 0x0002AD40 -
None 0x00000251 0x00401098 0x0002AD44 0x0002AD44 -
__vbaBoolStr - 0x0040109C 0x0002AD48 0x0002AD48 0x00000000
__vbaExitProc - 0x004010A0 0x0002AD4C 0x0002AD4C 0x00000000
__vbaI4Abs - 0x004010A4 0x0002AD50 0x0002AD50 0x00000000
None 0x00000252 0x004010A8 0x0002AD54 0x0002AD54 -
__vbaOnError - 0x004010AC 0x0002AD58 0x0002AD58 0x00000000
__vbaObjSet - 0x004010B0 0x0002AD5C 0x0002AD5C 0x00000000
_adj_fdiv_m16i - 0x004010B4 0x0002AD60 0x0002AD60 0x00000000
__vbaObjSetAddref - 0x004010B8 0x0002AD64 0x0002AD64 0x00000000
_adj_fdivr_m16i - 0x004010BC 0x0002AD68 0x0002AD68 0x00000000
None 0x00000256 0x004010C0 0x0002AD6C 0x0002AD6C -
__vbaFpR4 - 0x004010C4 0x0002AD70 0x0002AD70 0x00000000
None 0x000002C1 0x004010C8 0x0002AD74 0x0002AD74 -
__vbaStrFixstr - 0x004010CC 0x0002AD78 0x0002AD78 0x00000000
_CIsin - 0x004010D0 0x0002AD7C 0x0002AD7C 0x00000000
__vbaErase - 0x004010D4 0x0002AD80 0x0002AD80 0x00000000
None 0x00000277 0x004010D8 0x0002AD84 0x0002AD84 -
None 0x000002C5 0x004010DC 0x0002AD88 0x0002AD88 -
None 0x0000020D 0x004010E0 0x0002AD8C 0x0002AD8C -
__vbaChkstk - 0x004010E4 0x0002AD90 0x0002AD90 0x00000000
__vbaFileClose - 0x004010E8 0x0002AD94 0x0002AD94 0x00000000
EVENT_SINK_AddRef - 0x004010EC 0x0002AD98 0x0002AD98 0x00000000
__vbaGenerateBoundsError - 0x004010F0 0x0002AD9C 0x0002AD9C 0x00000000
__vbaGet3 - 0x004010F4 0x0002ADA0 0x0002ADA0 0x00000000
__vbaStrCmp - 0x004010F8 0x0002ADA4 0x0002ADA4 0x00000000
None 0x00000211 0x004010FC 0x0002ADA8 0x0002ADA8 -
__vbaGet4 - 0x00401100 0x0002ADAC 0x0002ADAC 0x00000000
__vbaPutOwner3 - 0x00401104 0x0002ADB0 0x0002ADB0 0x00000000
__vbaVarTstEq - 0x00401108 0x0002ADB4 0x0002ADB4 0x00000000
__vbaAryConstruct2 - 0x0040110C 0x0002ADB8 0x0002ADB8 0x00000000
__vbaObjVar - 0x00401110 0x0002ADBC 0x0002ADBC 0x00000000
__vbaI2I4 - 0x00401114 0x0002ADC0 0x0002ADC0 0x00000000
DllFunctionCall - 0x00401118 0x0002ADC4 0x0002ADC4 0x00000000
__vbaVarLateMemSt - 0x0040111C 0x0002ADC8 0x0002ADC8 0x00000000
__vbaFpUI1 - 0x00401120 0x0002ADCC 0x0002ADCC 0x00000000
__vbaRedimPreserve - 0x00401124 0x0002ADD0 0x0002ADD0 0x00000000
__vbaStrR4 - 0x00401128 0x0002ADD4 0x0002ADD4 0x00000000
_adj_fpatan - 0x0040112C 0x0002ADD8 0x0002ADD8 0x00000000
__vbaFixstrConstruct - 0x00401130 0x0002ADDC 0x0002ADDC 0x00000000
__vbaLateIdCallLd - 0x00401134 0x0002ADE0 0x0002ADE0 0x00000000
Zombie_GetTypeInfoCount - 0x00401138 0x0002ADE4 0x0002ADE4 0x00000000
__vbaRedim - 0x0040113C 0x0002ADE8 0x0002ADE8 0x00000000
__vbaRecUniToAnsi - 0x00401140 0x0002ADEC 0x0002ADEC 0x00000000
EVENT_SINK_Release - 0x00401144 0x0002ADF0 0x0002ADF0 0x00000000
__vbaNew - 0x00401148 0x0002ADF4 0x0002ADF4 0x00000000
None 0x00000258 0x0040114C 0x0002ADF8 0x0002ADF8 -
__vbaUI1I2 - 0x00401150 0x0002ADFC 0x0002ADFC 0x00000000
_CIsqrt - 0x00401154 0x0002AE00 0x0002AE00 0x00000000
EVENT_SINK_QueryInterface - 0x00401158 0x0002AE04 0x0002AE04 0x00000000
__vbaExceptHandler - 0x0040115C 0x0002AE08 0x0002AE08 0x00000000
None 0x000002C7 0x00401160 0x0002AE0C 0x0002AE0C -
None 0x000002C8 0x00401164 0x0002AE10 0x0002AE10 -
__vbaStrToUnicode - 0x00401168 0x0002AE14 0x0002AE14 0x00000000
None 0x0000025E 0x0040116C 0x0002AE18 0x0002AE18 -
_adj_fprem - 0x00401170 0x0002AE1C 0x0002AE1C 0x00000000
_adj_fdivr_m64 - 0x00401174 0x0002AE20 0x0002AE20 0x00000000
None 0x000002CA 0x00401178 0x0002AE24 0x0002AE24 -
None 0x000002CC 0x0040117C 0x0002AE28 0x0002AE28 -
None 0x00000261 0x00401180 0x0002AE2C 0x0002AE2C -
__vbaFPException - 0x00401184 0x0002AE30 0x0002AE30 0x00000000
None 0x000002CD 0x00401188 0x0002AE34 0x0002AE34 -
None 0x0000013F 0x0040118C 0x0002AE38 0x0002AE38 -
__vbaGetOwner3 - 0x00401190 0x0002AE3C 0x0002AE3C 0x00000000
__vbaUbound - 0x00401194 0x0002AE40 0x0002AE40 0x00000000
None 0x00000217 0x00401198 0x0002AE44 0x0002AE44 -
__vbaFileSeek - 0x0040119C 0x0002AE48 0x0002AE48 0x00000000
None 0x00000284 0x004011A0 0x0002AE4C 0x0002AE4C -
None 0x00000219 0x004011A4 0x0002AE50 0x0002AE50 -
_CIlog - 0x004011A8 0x0002AE54 0x0002AE54 0x00000000
__vbaErrorOverflow - 0x004011AC 0x0002AE58 0x0002AE58 0x00000000
__vbaFileOpen - 0x004011B0 0x0002AE5C 0x0002AE5C 0x00000000
__vbaVarLateMemCallLdRf - 0x004011B4 0x0002AE60 0x0002AE60 0x00000000
None 0x00000288 0x004011B8 0x0002AE64 0x0002AE64 -
None 0x0000023A 0x004011BC 0x0002AE68 0x0002AE68 -
__vbaNew2 - 0x004011C0 0x0002AE6C 0x0002AE6C 0x00000000
__vbaInStr - 0x004011C4 0x0002AE70 0x0002AE70 0x00000000
_adj_fdiv_m32i - 0x004011C8 0x0002AE74 0x0002AE74 0x00000000
None 0x0000023C 0x004011CC 0x0002AE78 0x0002AE78 -
_adj_fdivr_m32i - 0x004011D0 0x0002AE7C 0x0002AE7C 0x00000000
__vbaStrCopy - 0x004011D4 0x0002AE80 0x0002AE80 0x00000000
__vbaI4Str - 0x004011D8 0x0002AE84 0x0002AE84 0x00000000
__vbaFreeStrList - 0x004011DC 0x0002AE88 0x0002AE88 0x00000000
_adj_fdivr_m32 - 0x004011E0 0x0002AE8C 0x0002AE8C 0x00000000
_adj_fdiv_r - 0x004011E4 0x0002AE90 0x0002AE90 0x00000000
None 0x00000242 0x004011E8 0x0002AE94 0x0002AE94 -
None 0x00000064 0x004011EC 0x0002AE98 0x0002AE98 -
__vbaVarSetVar - 0x004011F0 0x0002AE9C 0x0002AE9C 0x00000000
__vbaI4Var - 0x004011F4 0x0002AEA0 0x0002AEA0 0x00000000
None 0x000002B1 0x004011F8 0x0002AEA4 0x0002AEA4 -
__vbaLateMemCall - 0x004011FC 0x0002AEA8 0x0002AEA8 0x00000000
__vbaVarAdd - 0x00401200 0x0002AEAC 0x0002AEAC 0x00000000
None 0x00000263 0x00401204 0x0002AEB0 0x0002AEB0 -
__vbaAryLock - 0x00401208 0x0002AEB4 0x0002AEB4 0x00000000
None 0x00000140 0x0040120C 0x0002AEB8 0x0002AEB8 -
__vbaStrComp - 0x00401210 0x0002AEBC 0x0002AEBC 0x00000000
__vbaVarDup - 0x00401214 0x0002AEC0 0x0002AEC0 0x00000000
__vbaStrToAnsi - 0x00401218 0x0002AEC4 0x0002AEC4 0x00000000
None 0x00000141 0x0040121C 0x0002AEC8 0x0002AEC8 -
__vbaFpI2 - 0x00401220 0x0002AECC 0x0002AECC 0x00000000
__vbaFpI4 - 0x00401224 0x0002AED0 0x0002AED0 0x00000000
__vbaVarLateMemCallLd - 0x00401228 0x0002AED4 0x0002AED4 0x00000000
None 0x00000268 0x0040122C 0x0002AED8 0x0002AED8 -
__vbaVarSetObjAddref - 0x00401230 0x0002AEDC 0x0002AEDC 0x00000000
__vbaRecDestructAnsi - 0x00401234 0x0002AEE0 0x0002AEE0 0x00000000
__vbaLateMemCallLd - 0x00401238 0x0002AEE4 0x0002AEE4 0x00000000
_CIatan - 0x0040123C 0x0002AEE8 0x0002AEE8 0x00000000
__vbaAryCopy - 0x00401240 0x0002AEEC 0x0002AEEC 0x00000000
__vbaStrMove - 0x00401244 0x0002AEF0 0x0002AEF0 0x00000000
None 0x0000026A 0x00401248 0x0002AEF4 0x0002AEF4 -
__vbaCastObj - 0x0040124C 0x0002AEF8 0x0002AEF8 0x00000000
__vbaR8IntI4 - 0x00401250 0x0002AEFC 0x0002AEFC 0x00000000
None 0x0000028A 0x00401254 0x0002AF00 0x0002AF00 -
_allmul - 0x00401258 0x0002AF04 0x0002AF04 0x00000000
__vbaVarLateMemCallSt - 0x0040125C 0x0002AF08 0x0002AF08 0x00000000
_CItan - 0x00401260 0x0002AF0C 0x0002AF0C 0x00000000
None 0x00000222 0x00401264 0x0002AF10 0x0002AF10 -
__vbaAryUnlock - 0x00401268 0x0002AF14 0x0002AF14 0x00000000
_CIexp - 0x0040126C 0x0002AF18 0x0002AF18 0x00000000
__vbaFreeObj - 0x00401270 0x0002AF1C 0x0002AF1C 0x00000000
__vbaFreeStr - 0x00401274 0x0002AF20 0x0002AF20 0x00000000
None 0x00000244 0x00401278 0x0002AF24 0x0002AF24 -
None 0x00000245 0x0040127C 0x0002AF28 0x0002AF28 -
Memory Dumps (221)
»
Name Process ID Start VA End VA Dump Reason PE Rebuild Bitness Entry Point YARA Actions
explorer.exe 5 0x00400000 0x0043DFFF First Execution False 32-bit 0x00403670 False
buffer 5 0x00460000 0x0046FFFF Marked Executable False 32-bit - False
buffer 5 0x00460000 0x0046FFFF Content Changed False 32-bit - False
buffer 5 0x00460000 0x0046FFFF First Execution False 32-bit 0x00466338 False
buffer 5 0x0307E000 0x0307FFFF First Network Behavior False 32-bit - False
buffer 5 0x02F7F000 0x02F7FFFF First Network Behavior False 32-bit - False
buffer 5 0x0019A000 0x0019FFFF First Network Behavior False 32-bit - False
buffer 5 0x00460000 0x0046FFFF First Network Behavior False 32-bit - False
buffer 5 0x00520F48 0x00521747 First Network Behavior False 32-bit - False
buffer 5 0x01F40000 0x0233FFFF First Network Behavior False 32-bit - False
buffer 5 0x026F3F98 0x026F40AB First Network Behavior False 32-bit - False
buffer 5 0x026F40B8 0x026F423B First Network Behavior False 32-bit - False
buffer 5 0x026F42D0 0x026F45C7 First Network Behavior False 32-bit - False
buffer 5 0x026F45F0 0x026F4703 First Network Behavior False 32-bit - False
buffer 5 0x026F4710 0x026F4793 First Network Behavior False 32-bit - False
buffer 5 0x026F47A0 0x026F48E7 First Network Behavior False 32-bit - False
buffer 5 0x026F4910 0x026F4A23 First Network Behavior False 32-bit - False
buffer 5 0x026F4A30 0x026F4C13 First Network Behavior False 32-bit - False
buffer 5 0x026F4C20 0x026F4CCF First Network Behavior False 32-bit - False
buffer 5 0x026F4CD8 0x026F507B First Network Behavior False 32-bit - False
buffer 5 0x026F50A8 0x026F51BB First Network Behavior False 32-bit - False
buffer 5 0x026F51E0 0x026F536F First Network Behavior False 32-bit - False
buffer 5 0x026F5378 0x026F53FF First Network Behavior False 32-bit - False
buffer 5 0x026F5408 0x026F5717 First Network Behavior False 32-bit - False
buffer 5 0x026F5740 0x026F5853 First Network Behavior False 32-bit - False
buffer 5 0x026F5878 0x026F5A3F First Network Behavior False 32-bit - False
buffer 5 0x026F5A48 0x026F5AEF First Network Behavior False 32-bit - False
buffer 5 0x026F5AF8 0x026F5E67 First Network Behavior False 32-bit - False
buffer 5 0x026F5F98 0x026F608F First Network Behavior False 32-bit - False
buffer 5 0x026F6098 0x026F61AB First Network Behavior False 32-bit - False
buffer 5 0x026F61B8 0x026F62E3 First Network Behavior False 32-bit - False
buffer 5 0x026F62F0 0x026F638F First Network Behavior False 32-bit - False
buffer 5 0x026F63B0 0x026F644F First Network Behavior False 32-bit - False
buffer 5 0x026F64A0 0x026F65B3 First Network Behavior False 32-bit - False
buffer 5 0x026F6618 0x026F6707 First Network Behavior False 32-bit - False
buffer 5 0x026F6760 0x026F6953 First Network Behavior False 32-bit - False
buffer 5 0x026F6980 0x026F6A93 First Network Behavior False 32-bit - False
buffer 5 0x026F99E8 0x026F9B07 First Network Behavior False 32-bit - False
buffer 5 0x026F9B10 0x026F9D5F First Network Behavior False 32-bit - False
buffer 5 0x026F9D68 0x026F9E7B First Network Behavior False 32-bit - False
buffer 5 0x026F9EB8 0x026F9F67 First Network Behavior False 32-bit - False
buffer 5 0x026F9FB0 0x026FA133 First Network Behavior False 32-bit - False
buffer 5 0x026FA948 0x026FAA5B First Network Behavior False 32-bit - False
buffer 5 0x026FAA98 0x026FAB6B First Network Behavior False 32-bit - False
buffer 5 0x026FABC8 0x026FAD8F First Network Behavior False 32-bit - False
buffer 5 0x026FADC8 0x026FAE57 First Network Behavior False 32-bit - False
buffer 5 0x026FAEE8 0x026FAFFB First Network Behavior False 32-bit - False
buffer 5 0x026FB210 0x026FB2FB First Network Behavior False 32-bit - False
buffer 5 0x026FB308 0x026FB4FF First Network Behavior False 32-bit - False
buffer 5 0x026FB530 0x026FB643 First Network Behavior False 32-bit - False
buffer 5 0x026FB658 0x026FB76B First Network Behavior False 32-bit - False
buffer 5 0x026FB780 0x026FB893 First Network Behavior False 32-bit - False
buffer 5 0x026FB8A8 0x026FB9BB First Network Behavior False 32-bit - False
buffer 5 0x026FB9D0 0x026FBAE3 First Network Behavior False 32-bit - False
buffer 5 0x026FBAF8 0x026FBC0B First Network Behavior False 32-bit - False
buffer 5 0x026FBC20 0x026FBD33 First Network Behavior False 32-bit - False
buffer 5 0x026FBD48 0x026FBE5B First Network Behavior False 32-bit - False
buffer 5 0x026FBE70 0x026FBF83 First Network Behavior False 32-bit - False
buffer 5 0x026FBF98 0x026FC0AB First Network Behavior False 32-bit - False
buffer 5 0x026FC0C0 0x026FC1D3 First Network Behavior False 32-bit - False
buffer 5 0x026FC1E8 0x026FC2FB First Network Behavior False 32-bit - False
buffer 5 0x026FC310 0x026FC423 First Network Behavior False 32-bit - False
buffer 5 0x026FC510 0x026FC5E3 First Network Behavior False 32-bit - False
buffer 5 0x026FC648 0x026FC80F First Network Behavior False 32-bit - False
buffer 5 0x026FC818 0x026FC91F First Network Behavior False 32-bit - False
buffer 5 0x026FD130 0x026FD35F First Network Behavior False 32-bit - False
buffer 5 0x026FD368 0x026FD46F First Network Behavior False 32-bit - False
buffer 5 0x026FD4D8 0x026FD707 First Network Behavior False 32-bit - False
buffer 5 0x026FD710 0x026FD79F First Network Behavior False 32-bit - False
buffer 5 0x026FD7D8 0x026FD91B First Network Behavior False 32-bit - False
buffer 5 0x026FD998 0x026FDA93 First Network Behavior False 32-bit - False
buffer 5 0x026FDAC8 0x026FDC0B First Network Behavior False 32-bit - False
buffer 5 0x026FDC18 0x026FDCD7 First Network Behavior False 32-bit - False
buffer 5 0x026FDD28 0x026FDEC7 First Network Behavior False 32-bit - False
buffer 5 0x026FDF00 0x026FDFC7 First Network Behavior False 32-bit - False
buffer 5 0x026FDFD0 0x026FE17F First Network Behavior False 32-bit - False
buffer 5 0x026FE1B8 0x026FE2A3 First Network Behavior False 32-bit - False
buffer 5 0x026FE310 0x026FE507 First Network Behavior False 32-bit - False
buffer 5 0x026FE550 0x026FE607 First Network Behavior False 32-bit - False
buffer 5 0x026FE670 0x026FE773 First Network Behavior False 32-bit - False
buffer 5 0x026FE800 0x026FE8CF First Network Behavior False 32-bit - False
buffer 5 0x026FE908 0x026FE99F First Network Behavior False 32-bit - False
buffer 5 0x026FE9E8 0x026FEB3B First Network Behavior False 32-bit - False
buffer 5 0x026FEB48 0x026FEC1F First Network Behavior False 32-bit - False
buffer 5 0x026FEC70 0x026FEE47 First Network Behavior False 32-bit - False
buffer 5 0x026FEE50 0x026FEFCB First Network Behavior False 32-bit - False
buffer 5 0x02701418 0x0270152B First Network Behavior False 32-bit - False
buffer 5 0x02702098 0x02702387 First Network Behavior False 32-bit - False
buffer 5 0x02702390 0x027024A7 First Network Behavior False 32-bit - False
buffer 5 0x027024B0 0x027025C7 First Network Behavior False 32-bit - False
buffer 5 0x027025D0 0x02702CC7 First Network Behavior False 32-bit - False
buffer 5 0x02702CD0 0x02702DA3 First Network Behavior False 32-bit - False
buffer 5 0x02702DB0 0x0270519B First Network Behavior False 32-bit - False
buffer 5 0x027051A8 0x027052AB First Network Behavior False 32-bit - False
buffer 5 0x027052B8 0x0270540B First Network Behavior False 32-bit - False
buffer 5 0x02705418 0x02705557 First Network Behavior False 32-bit - False
buffer 5 0x02705560 0x02705993 First Network Behavior False 32-bit - False
buffer 5 0x027059A0 0x02705B37 First Network Behavior False 32-bit - False
buffer 5 0x02705B40 0x02705C83 First Network Behavior False 32-bit - False
buffer 5 0x02705C90 0x02705DD3 First Network Behavior False 32-bit - False
buffer 5 0x02705DE0 0x02705F53 First Network Behavior False 32-bit - False
buffer 5 0x02705F60 0x02706153 First Network Behavior False 32-bit - False
buffer 5 0x02706160 0x02706903 First Network Behavior False 32-bit - False
buffer 5 0x027069A8 0x02706AE7 First Network Behavior False 32-bit - False
buffer 5 0x02706AF0 0x02706F23 First Network Behavior False 32-bit - False
buffer 5 0x02706F30 0x027070DB First Network Behavior False 32-bit - False
buffer 5 0x027070E8 0x027071C3 First Network Behavior False 32-bit - False
buffer 5 0x027071D0 0x027072AB First Network Behavior False 32-bit - False
buffer 5 0x027072B8 0x02707393 First Network Behavior False 32-bit - False
buffer 5 0x02707BA8 0x02707CEB First Network Behavior False 32-bit - False
buffer 5 0x02707CF8 0x02707E3B First Network Behavior False 32-bit - False
buffer 5 0x02707E48 0x02707F43 First Network Behavior False 32-bit - False
explorer.exe 5 0x00400000 0x0043DFFF First Network Behavior False 32-bit 0x0041E7F2 False
counters.dat 5 0x00510000 0x00510FFF First Network Behavior False 32-bit - False
buffer 5 0x00460000 0x0046FFFF Final Dump False 32-bit - False
buffer 5 0x00520F48 0x00521747 Final Dump False 32-bit - False
buffer 5 0x01F40000 0x0233FFFF Final Dump False 32-bit - False
buffer 5 0x026F3F98 0x026F40AB Final Dump False 32-bit - False
buffer 5 0x026F40B8 0x026F423B Final Dump False 32-bit - False
buffer 5 0x026F42D0 0x026F45C7 Final Dump False 32-bit - False
buffer 5 0x026F45F0 0x026F4703 Final Dump False 32-bit - False
buffer 5 0x026F4710 0x026F4793 Final Dump False 32-bit - False
buffer 5 0x026F47A0 0x026F48E7 Final Dump False 32-bit - False
buffer 5 0x026F4910 0x026F4A23 Final Dump False 32-bit - False
buffer 5 0x026F4A30 0x026F4C13 Final Dump False 32-bit - False
buffer 5 0x026F4C20 0x026F4CCF Final Dump False 32-bit - False
buffer 5 0x026F4CD8 0x026F507B Final Dump False 32-bit - False
buffer 5 0x026F50A8 0x026F51BB Final Dump False 32-bit - False
buffer 5 0x026F51E0 0x026F536F Final Dump False 32-bit - False
buffer 5 0x026F5378 0x026F53FF Final Dump False 32-bit - False
buffer 5 0x026F5408 0x026F5717 Final Dump False 32-bit - False
buffer 5 0x026F5740 0x026F5853 Final Dump False 32-bit - False
buffer 5 0x026F5878 0x026F5A3F Final Dump False 32-bit - False
buffer 5 0x026F5A48 0x026F5AEF Final Dump False 32-bit - False
buffer 5 0x026F5AF8 0x026F5E67 Final Dump False 32-bit - False
buffer 5 0x026F5F98 0x026F608F Final Dump False 32-bit - False
buffer 5 0x026F6098 0x026F61AB Final Dump False 32-bit - False
buffer 5 0x026F61B8 0x026F62E3 Final Dump False 32-bit - False
buffer 5 0x026F62F0 0x026F638F Final Dump False 32-bit - False
buffer 5 0x026F63B0 0x026F644F Final Dump False 32-bit - False
buffer 5 0x026F64A0 0x026F65B3 Final Dump False 32-bit - False
buffer 5 0x026F6618 0x026F6707 Final Dump False 32-bit - False
buffer 5 0x026F6760 0x026F6953 Final Dump False 32-bit - False
buffer 5 0x026F6980 0x026F6A93 Final Dump False 32-bit - False
buffer 5 0x026F99E8 0x026F9B07 Final Dump False 32-bit - False
buffer 5 0x026F9B10 0x026F9D5F Final Dump False 32-bit - False
buffer 5 0x026F9D68 0x026F9E7B Final Dump False 32-bit - False
buffer 5 0x026F9EB8 0x026F9F67 Final Dump False 32-bit - False
buffer 5 0x026F9FB0 0x026FA133 Final Dump False 32-bit - False
buffer 5 0x026FA948 0x026FAA5B Final Dump False 32-bit - False
buffer 5 0x026FAA98 0x026FAB6B Final Dump False 32-bit - False
buffer 5 0x026FABC8 0x026FAD8F Final Dump False 32-bit - False
buffer 5 0x026FADC8 0x026FAE57 Final Dump False 32-bit - False
buffer 5 0x026FAEE8 0x026FAFFB Final Dump False 32-bit - False
buffer 5 0x026FB210 0x026FB2FB Final Dump False 32-bit - False
buffer 5 0x026FB308 0x026FB4FF Final Dump False 32-bit - False
buffer 5 0x026FB530 0x026FB643 Final Dump False 32-bit - False
buffer 5 0x026FB658 0x026FB76B Final Dump False 32-bit - False
buffer 5 0x026FB780 0x026FB893 Final Dump False 32-bit - False
buffer 5 0x026FB8A8 0x026FB9BB Final Dump False 32-bit - False
buffer 5 0x026FB9D0 0x026FBAE3 Final Dump False 32-bit - False
buffer 5 0x026FBAF8 0x026FBC0B Final Dump False 32-bit - False
buffer 5 0x026FBC20 0x026FBD33 Final Dump False 32-bit - False
buffer 5 0x026FBD48 0x026FBE5B Final Dump False 32-bit - False
buffer 5 0x026FBE70 0x026FBF83 Final Dump False 32-bit - False
buffer 5 0x026FBF98 0x026FC0AB Final Dump False 32-bit - False
buffer 5 0x026FC0C0 0x026FC1D3 Final Dump False 32-bit - False
buffer 5 0x026FC1E8 0x026FC2FB Final Dump False 32-bit - False
buffer 5 0x026FC310 0x026FC423 Final Dump False 32-bit - False
buffer 5 0x026FC510 0x026FC5E3 Final Dump False 32-bit - False
buffer 5 0x026FC648 0x026FC80F Final Dump False 32-bit - False
buffer 5 0x026FC818 0x026FC91F Final Dump False 32-bit - False
buffer 5 0x026FD130 0x026FD35F Final Dump False 32-bit - False
buffer 5 0x026FD368 0x026FD46F Final Dump False 32-bit - False
buffer 5 0x026FD4D8 0x026FD707 Final Dump False 32-bit - False
buffer 5 0x026FD710 0x026FD79F Final Dump False 32-bit - False
buffer 5 0x026FD7D8 0x026FD91B Final Dump False 32-bit - False
buffer 5 0x026FD998 0x026FDA93 Final Dump False 32-bit - False
buffer 5 0x026FDAC8 0x026FDC0B Final Dump False 32-bit - False
buffer 5 0x026FDC18 0x026FDCD7 Final Dump False 32-bit - False
buffer 5 0x026FDD28 0x026FDEC7 Final Dump False 32-bit - False
buffer 5 0x026FDF00 0x026FDFC7 Final Dump False 32-bit - False
buffer 5 0x026FDFD0 0x026FE17F Final Dump False 32-bit - False
buffer 5 0x026FE1B8 0x026FE2A3 Final Dump False 32-bit - False
buffer 5 0x026FE310 0x026FE507 Final Dump False 32-bit - False
buffer 5 0x026FE550 0x026FE607 Final Dump False 32-bit - False
buffer 5 0x026FE670 0x026FE773 Final Dump False 32-bit - False
buffer 5 0x026FE800 0x026FE8CF Final Dump False 32-bit - False
buffer 5 0x026FE908 0x026FE99F Final Dump False 32-bit - False
buffer 5 0x026FE9E8 0x026FEB3B Final Dump False 32-bit - False
buffer 5 0x026FEB48 0x026FEC1F Final Dump False 32-bit - False
buffer 5 0x026FEC70 0x026FEE47 Final Dump False 32-bit - False
buffer 5 0x026FEE50 0x026FEFCB Final Dump False 32-bit - False
buffer 5 0x02701418 0x0270152B Final Dump False 32-bit - False
buffer 5 0x02702098 0x02702387 Final Dump False 32-bit - False
buffer 5 0x02702390 0x027024A7 Final Dump False 32-bit - False
buffer 5 0x027024B0 0x027025C7 Final Dump False 32-bit - False
buffer 5 0x027025D0 0x02702CC7 Final Dump False 32-bit - False
buffer 5 0x02702CD0 0x02702DA3 Final Dump False 32-bit - False
buffer 5 0x02702DB0 0x0270519B Final Dump False 32-bit - False
buffer 5 0x027051A8 0x027052AB Final Dump False 32-bit - False
buffer 5 0x027052B8 0x0270540B Final Dump False 32-bit - False
buffer 5 0x02705418 0x02705557 Final Dump False 32-bit - False
buffer 5 0x02705560 0x02705993 Final Dump False 32-bit - False
buffer 5 0x027059A0 0x02705B37 Final Dump False 32-bit - False
buffer 5 0x02705B40 0x02705C83 Final Dump False 32-bit - False
buffer 5 0x02705C90 0x02705DD3 Final Dump False 32-bit - False
buffer 5 0x02705DE0 0x02705F53 Final Dump False 32-bit - False
buffer 5 0x02705F60 0x02706153 Final Dump False 32-bit - False
buffer 5 0x02706160 0x02706903 Final Dump False 32-bit - False
buffer 5 0x027069A8 0x02706AE7 Final Dump False 32-bit - False
buffer 5 0x02706AF0 0x02706F23 Final Dump False 32-bit - False
buffer 5 0x02706F30 0x027070DB Final Dump False 32-bit - False
buffer 5 0x027070E8 0x027071C3 Final Dump False 32-bit - False
buffer 5 0x027071D0 0x027072AB Final Dump False 32-bit - False
buffer 5 0x027072B8 0x02707393 Final Dump False 32-bit - False
buffer 5 0x02707BA8 0x02707CEB Final Dump False 32-bit - False
buffer 5 0x02707CF8 0x02707E3B Final Dump False 32-bit - False
buffer 5 0x02707E48 0x02707F43 Final Dump False 32-bit - False
explorer.exe 5 0x00400000 0x0043DFFF Final Dump False 32-bit - False
counters.dat 5 0x00510000 0x00510FFF Final Dump False 32-bit - False
c:\windows\system\spoolsv.exe Dropped File Binary
Suspicious
»
MIME Type application/vnd.microsoft.portable-executable
File Size 274.31 KB
MD5 11cc9e0c3fa4f33aff798787a2125ff3 Copy to Clipboard
SHA1 4f017622a7933925d04a29ed4ff192c92ecaa916 Copy to Clipboard
SHA256 76636035ca28ac6c3b162b5afe0d20ce85544a21a0557db652191e6384a752a2 Copy to Clipboard
SSDeep 3072:UvEfVUzSLhIVbV6i5LirrlZrHyrUHUckoMQ2RN6unD:UvEN2U+T6i5LirrllHy4HUcMQY6M Copy to Clipboard
ImpHash 98f67c550a7da65513e63ffd998f6b2e Copy to Clipboard
PE Information
»
Image Base 0x00400000
Entry Point 0x00403670
Size Of Code 0x0002B000
Size Of Initialized Data 0x00003000
File Type IMAGE_FILE_EXECUTABLE_IMAGE
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
Machine Type IMAGE_FILE_MACHINE_I386
Compile Timestamp 2011-06-14 21:01 (UTC+2)
Version Information (6)
»
CompanyName Microsoft
ProductName Win
FileVersion 1.00
ProductVersion 1.00
InternalName Win
OriginalFilename Win.exe
Sections (4)
»
Name Virtual Address Virtual Size Raw Data Size Raw Data Offset Flags Entropy
.text 0x00401000 0x0002A728 0x0002B000 0x00001000 IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE 5.95
.data 0x0042C000 0x00001B74 0x00001000 0x0002C000 IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE 0.0
.rsrc 0x0042E000 0x000005E0 0x00001000 0x0002D000 IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ 1.69
.tdata 0x0042F000 0x0000F000 0x0000F000 0x0002E000 IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE 0.0
Imports (1)
»
MSVBVM60.DLL (160)
»
API Name Ordinal IAT Address Thunk RVA Thunk Offset Hint
EVENT_SINK_GetIDsOfNames - 0x00401000 0x0002ACAC 0x0002ACAC 0x00000000
__vbaStrI2 - 0x00401004 0x0002ACB0 0x0002ACB0 0x00000000
None 0x000002B2 0x00401008 0x0002ACB4 0x0002ACB4 -
_CIcos - 0x0040100C 0x0002ACB8 0x0002ACB8 0x00000000
_adj_fptan - 0x00401010 0x0002ACBC 0x0002ACBC 0x00000000
__vbaStrI4 - 0x00401014 0x0002ACC0 0x0002ACC0 0x00000000
__vbaVarVargNofree - 0x00401018 0x0002ACC4 0x0002ACC4 0x00000000
__vbaFreeVar - 0x0040101C 0x0002ACC8 0x0002ACC8 0x00000000
__vbaStrVarMove - 0x00401020 0x0002ACCC 0x0002ACCC 0x00000000
__vbaLenBstr - 0x00401024 0x0002ACD0 0x0002ACD0 0x00000000
__vbaLateIdCall - 0x00401028 0x0002ACD4 0x0002ACD4 0x00000000
__vbaPut3 - 0x0040102C 0x0002ACD8 0x0002ACD8 0x00000000
__vbaEnd - 0x00401030 0x0002ACDC 0x0002ACDC 0x00000000
__vbaFreeVarList - 0x00401034 0x0002ACE0 0x0002ACE0 0x00000000
_adj_fdiv_m64 - 0x00401038 0x0002ACE4 0x0002ACE4 0x00000000
__vbaPut4 - 0x0040103C 0x0002ACE8 0x0002ACE8 0x00000000
EVENT_SINK_Invoke - 0x00401040 0x0002ACEC 0x0002ACEC 0x00000000
__vbaRaiseEvent - 0x00401044 0x0002ACF0 0x0002ACF0 0x00000000
__vbaFreeObjList - 0x00401048 0x0002ACF4 0x0002ACF4 0x00000000
None 0x00000204 0x0040104C 0x0002ACF8 0x0002ACF8 -
__vbaStrErrVarCopy - 0x00401050 0x0002ACFC 0x0002ACFC 0x00000000
None 0x00000205 0x00401054 0x0002AD00 0x0002AD00 -
_adj_fprem1 - 0x00401058 0x0002AD04 0x0002AD04 0x00000000
__vbaRecAnsiToUni - 0x0040105C 0x0002AD08 0x0002AD08 0x00000000
None 0x00000207 0x00401060 0x0002AD0C 0x0002AD0C -
__vbaCopyBytes - 0x00401064 0x0002AD10 0x0002AD10 0x00000000
__vbaStrCat - 0x00401068 0x0002AD14 0x0002AD14 0x00000000
__vbaLsetFixstr - 0x0040106C 0x0002AD18 0x0002AD18 0x00000000
__vbaRecDestruct - 0x00401070 0x0002AD1C 0x0002AD1C 0x00000000
__vbaSetSystemError - 0x00401074 0x0002AD20 0x0002AD20 0x00000000
None 0x00000295 0x00401078 0x0002AD24 0x0002AD24 -
__vbaHresultCheckObj - 0x0040107C 0x0002AD28 0x0002AD28 0x00000000
__vbaNameFile - 0x00401080 0x0002AD2C 0x0002AD2C 0x00000000
_adj_fdiv_m32 - 0x00401084 0x0002AD30 0x0002AD30 0x00000000
__vbaAryVar - 0x00401088 0x0002AD34 0x0002AD34 0x00000000
Zombie_GetTypeInfo - 0x0040108C 0x0002AD38 0x0002AD38 0x00000000
__vbaAryDestruct - 0x00401090 0x0002AD3C 0x0002AD3C 0x00000000
None 0x0000029D 0x00401094 0x0002AD40 0x0002AD40 -
None 0x00000251 0x00401098 0x0002AD44 0x0002AD44 -
__vbaBoolStr - 0x0040109C 0x0002AD48 0x0002AD48 0x00000000
__vbaExitProc - 0x004010A0 0x0002AD4C 0x0002AD4C 0x00000000
__vbaI4Abs - 0x004010A4 0x0002AD50 0x0002AD50 0x00000000
None 0x00000252 0x004010A8 0x0002AD54 0x0002AD54 -
__vbaOnError - 0x004010AC 0x0002AD58 0x0002AD58 0x00000000
__vbaObjSet - 0x004010B0 0x0002AD5C 0x0002AD5C 0x00000000
_adj_fdiv_m16i - 0x004010B4 0x0002AD60 0x0002AD60 0x00000000
__vbaObjSetAddref - 0x004010B8 0x0002AD64 0x0002AD64 0x00000000
_adj_fdivr_m16i - 0x004010BC 0x0002AD68 0x0002AD68 0x00000000
None 0x00000256 0x004010C0 0x0002AD6C 0x0002AD6C -
__vbaFpR4 - 0x004010C4 0x0002AD70 0x0002AD70 0x00000000
None 0x000002C1 0x004010C8 0x0002AD74 0x0002AD74 -
__vbaStrFixstr - 0x004010CC 0x0002AD78 0x0002AD78 0x00000000
_CIsin - 0x004010D0 0x0002AD7C 0x0002AD7C 0x00000000
__vbaErase - 0x004010D4 0x0002AD80 0x0002AD80 0x00000000
None 0x00000277 0x004010D8 0x0002AD84 0x0002AD84 -
None 0x000002C5 0x004010DC 0x0002AD88 0x0002AD88 -
None 0x0000020D 0x004010E0 0x0002AD8C 0x0002AD8C -
__vbaChkstk - 0x004010E4 0x0002AD90 0x0002AD90 0x00000000
__vbaFileClose - 0x004010E8 0x0002AD94 0x0002AD94 0x00000000
EVENT_SINK_AddRef - 0x004010EC 0x0002AD98 0x0002AD98 0x00000000
__vbaGenerateBoundsError - 0x004010F0 0x0002AD9C 0x0002AD9C 0x00000000
__vbaGet3 - 0x004010F4 0x0002ADA0 0x0002ADA0 0x00000000
__vbaStrCmp - 0x004010F8 0x0002ADA4 0x0002ADA4 0x00000000
None 0x00000211 0x004010FC 0x0002ADA8 0x0002ADA8 -
__vbaGet4 - 0x00401100 0x0002ADAC 0x0002ADAC 0x00000000
__vbaPutOwner3 - 0x00401104 0x0002ADB0 0x0002ADB0 0x00000000
__vbaVarTstEq - 0x00401108 0x0002ADB4 0x0002ADB4 0x00000000
__vbaAryConstruct2 - 0x0040110C 0x0002ADB8 0x0002ADB8 0x00000000
__vbaObjVar - 0x00401110 0x0002ADBC 0x0002ADBC 0x00000000
__vbaI2I4 - 0x00401114 0x0002ADC0 0x0002ADC0 0x00000000
DllFunctionCall - 0x00401118 0x0002ADC4 0x0002ADC4 0x00000000
__vbaVarLateMemSt - 0x0040111C 0x0002ADC8 0x0002ADC8 0x00000000
__vbaFpUI1 - 0x00401120 0x0002ADCC 0x0002ADCC 0x00000000
__vbaRedimPreserve - 0x00401124 0x0002ADD0 0x0002ADD0 0x00000000
__vbaStrR4 - 0x00401128 0x0002ADD4 0x0002ADD4 0x00000000
_adj_fpatan - 0x0040112C 0x0002ADD8 0x0002ADD8 0x00000000
__vbaFixstrConstruct - 0x00401130 0x0002ADDC 0x0002ADDC 0x00000000
__vbaLateIdCallLd - 0x00401134 0x0002ADE0 0x0002ADE0 0x00000000
Zombie_GetTypeInfoCount - 0x00401138 0x0002ADE4 0x0002ADE4 0x00000000
__vbaRedim - 0x0040113C 0x0002ADE8 0x0002ADE8 0x00000000
__vbaRecUniToAnsi - 0x00401140 0x0002ADEC 0x0002ADEC 0x00000000
EVENT_SINK_Release - 0x00401144 0x0002ADF0 0x0002ADF0 0x00000000
__vbaNew - 0x00401148 0x0002ADF4 0x0002ADF4 0x00000000
None 0x00000258 0x0040114C 0x0002ADF8 0x0002ADF8 -
__vbaUI1I2 - 0x00401150 0x0002ADFC 0x0002ADFC 0x00000000
_CIsqrt - 0x00401154 0x0002AE00 0x0002AE00 0x00000000
EVENT_SINK_QueryInterface - 0x00401158 0x0002AE04 0x0002AE04 0x00000000
__vbaExceptHandler - 0x0040115C 0x0002AE08 0x0002AE08 0x00000000
None 0x000002C7 0x00401160 0x0002AE0C 0x0002AE0C -
None 0x000002C8 0x00401164 0x0002AE10 0x0002AE10 -
__vbaStrToUnicode - 0x00401168 0x0002AE14 0x0002AE14 0x00000000
None 0x0000025E 0x0040116C 0x0002AE18 0x0002AE18 -
_adj_fprem - 0x00401170 0x0002AE1C 0x0002AE1C 0x00000000
_adj_fdivr_m64 - 0x00401174 0x0002AE20 0x0002AE20 0x00000000
None 0x000002CA 0x00401178 0x0002AE24 0x0002AE24 -
None 0x000002CC 0x0040117C 0x0002AE28 0x0002AE28 -
None 0x00000261 0x00401180 0x0002AE2C 0x0002AE2C -
__vbaFPException - 0x00401184 0x0002AE30 0x0002AE30 0x00000000
None 0x000002CD 0x00401188 0x0002AE34 0x0002AE34 -
None 0x0000013F 0x0040118C 0x0002AE38 0x0002AE38 -
__vbaGetOwner3 - 0x00401190 0x0002AE3C 0x0002AE3C 0x00000000
__vbaUbound - 0x00401194 0x0002AE40 0x0002AE40 0x00000000
None 0x00000217 0x00401198 0x0002AE44 0x0002AE44 -
__vbaFileSeek - 0x0040119C 0x0002AE48 0x0002AE48 0x00000000
None 0x00000284 0x004011A0 0x0002AE4C 0x0002AE4C -
None 0x00000219 0x004011A4 0x0002AE50 0x0002AE50 -
_CIlog - 0x004011A8 0x0002AE54 0x0002AE54 0x00000000
__vbaErrorOverflow - 0x004011AC 0x0002AE58 0x0002AE58 0x00000000
__vbaFileOpen - 0x004011B0 0x0002AE5C 0x0002AE5C 0x00000000
__vbaVarLateMemCallLdRf - 0x004011B4 0x0002AE60 0x0002AE60 0x00000000
None 0x00000288 0x004011B8 0x0002AE64 0x0002AE64 -
None 0x0000023A 0x004011BC 0x0002AE68 0x0002AE68 -
__vbaNew2 - 0x004011C0 0x0002AE6C 0x0002AE6C 0x00000000
__vbaInStr - 0x004011C4 0x0002AE70 0x0002AE70 0x00000000
_adj_fdiv_m32i - 0x004011C8 0x0002AE74 0x0002AE74 0x00000000
None 0x0000023C 0x004011CC 0x0002AE78 0x0002AE78 -
_adj_fdivr_m32i - 0x004011D0 0x0002AE7C 0x0002AE7C 0x00000000
__vbaStrCopy - 0x004011D4 0x0002AE80 0x0002AE80 0x00000000
__vbaI4Str - 0x004011D8 0x0002AE84 0x0002AE84 0x00000000
__vbaFreeStrList - 0x004011DC 0x0002AE88 0x0002AE88 0x00000000
_adj_fdivr_m32 - 0x004011E0 0x0002AE8C 0x0002AE8C 0x00000000
_adj_fdiv_r - 0x004011E4 0x0002AE90 0x0002AE90 0x00000000
None 0x00000242 0x004011E8 0x0002AE94 0x0002AE94 -
None 0x00000064 0x004011EC 0x0002AE98 0x0002AE98 -
__vbaVarSetVar - 0x004011F0 0x0002AE9C 0x0002AE9C 0x00000000
__vbaI4Var - 0x004011F4 0x0002AEA0 0x0002AEA0 0x00000000
None 0x000002B1 0x004011F8 0x0002AEA4 0x0002AEA4 -
__vbaLateMemCall - 0x004011FC 0x0002AEA8 0x0002AEA8 0x00000000
__vbaVarAdd - 0x00401200 0x0002AEAC 0x0002AEAC 0x00000000
None 0x00000263 0x00401204 0x0002AEB0 0x0002AEB0 -
__vbaAryLock - 0x00401208 0x0002AEB4 0x0002AEB4 0x00000000
None 0x00000140 0x0040120C 0x0002AEB8 0x0002AEB8 -
__vbaStrComp - 0x00401210 0x0002AEBC 0x0002AEBC 0x00000000
__vbaVarDup - 0x00401214 0x0002AEC0 0x0002AEC0 0x00000000
__vbaStrToAnsi - 0x00401218 0x0002AEC4 0x0002AEC4 0x00000000
None 0x00000141 0x0040121C 0x0002AEC8 0x0002AEC8 -
__vbaFpI2 - 0x00401220 0x0002AECC 0x0002AECC 0x00000000
__vbaFpI4 - 0x00401224 0x0002AED0 0x0002AED0 0x00000000
__vbaVarLateMemCallLd - 0x00401228 0x0002AED4 0x0002AED4 0x00000000
None 0x00000268 0x0040122C 0x0002AED8 0x0002AED8 -
__vbaVarSetObjAddref - 0x00401230 0x0002AEDC 0x0002AEDC 0x00000000
__vbaRecDestructAnsi - 0x00401234 0x0002AEE0 0x0002AEE0 0x00000000
__vbaLateMemCallLd - 0x00401238 0x0002AEE4 0x0002AEE4 0x00000000
_CIatan - 0x0040123C 0x0002AEE8 0x0002AEE8 0x00000000
__vbaAryCopy - 0x00401240 0x0002AEEC 0x0002AEEC 0x00000000
__vbaStrMove - 0x00401244 0x0002AEF0 0x0002AEF0 0x00000000
None 0x0000026A 0x00401248 0x0002AEF4 0x0002AEF4 -
__vbaCastObj - 0x0040124C 0x0002AEF8 0x0002AEF8 0x00000000
__vbaR8IntI4 - 0x00401250 0x0002AEFC 0x0002AEFC 0x00000000
None 0x0000028A 0x00401254 0x0002AF00 0x0002AF00 -
_allmul - 0x00401258 0x0002AF04 0x0002AF04 0x00000000
__vbaVarLateMemCallSt - 0x0040125C 0x0002AF08 0x0002AF08 0x00000000
_CItan - 0x00401260 0x0002AF0C 0x0002AF0C 0x00000000
None 0x00000222 0x00401264 0x0002AF10 0x0002AF10 -
__vbaAryUnlock - 0x00401268 0x0002AF14 0x0002AF14 0x00000000
_CIexp - 0x0040126C 0x0002AF18 0x0002AF18 0x00000000
__vbaFreeObj - 0x00401270 0x0002AF1C 0x0002AF1C 0x00000000
__vbaFreeStr - 0x00401274 0x0002AF20 0x0002AF20 0x00000000
None 0x00000244 0x00401278 0x0002AF24 0x0002AF24 -
None 0x00000245 0x0040127C 0x0002AF28 0x0002AF28 -
Memory Dumps (10)
»
Name Process ID Start VA End VA Dump Reason PE Rebuild Bitness Entry Point YARA Actions
spoolsv.exe 6 0x00400000 0x0043DFFF First Execution False 32-bit 0x00403670 False
buffer 6 0x00610000 0x0061FFFF Marked Executable False 32-bit - False
buffer 6 0x00610000 0x0061FFFF Content Changed False 32-bit - False
buffer 6 0x00610000 0x0061FFFF First Execution False 32-bit 0x00616338 False
spoolsv.exe 8 0x00400000 0x0043DFFF First Execution False 32-bit 0x0040CF57 False
buffer 8 0x00450000 0x0045FFFF Marked Executable False 32-bit - False
buffer 8 0x00450000 0x0045FFFF Content Changed False 32-bit - False
buffer 8 0x00450000 0x0045FFFF Marked Executable False 32-bit - False
spoolsv.exe 8 0x00400000 0x0043DFFF Process Termination False 32-bit - False
spoolsv.exe 6 0x00400000 0x0043DFFF Process Termination False 32-bit - False
C:\Users\RDhJ0CNFevzX\AppData\Local\icsys.icn.exe Dropped File Binary
Suspicious
»
Also Known As c:\users\rdhj0cnfevzx\appdata\local\icsys.icn.exe (Dropped File, Accessed File)
MIME Type application/vnd.microsoft.portable-executable
File Size 274.31 KB
MD5 4223968da579570e05813854a134397b Copy to Clipboard
SHA1 07bdaa69105cae6467337d965eb968b6765fe28e Copy to Clipboard
SHA256 85ce1f5747ce26adf8191236668b87796ed45b1e15a9b87fa8a2f3c80b9b65fc Copy to Clipboard
SSDeep 3072:UvEfVUzSLhIVbV6i5LirrlZrHyrUHUckoMQ2RN6unB:UvEN2U+T6i5LirrllHy4HUcMQY6M Copy to Clipboard
ImpHash 98f67c550a7da65513e63ffd998f6b2e Copy to Clipboard
PE Information
»
Image Base 0x00400000
Entry Point 0x00403670
Size Of Code 0x0002B000
Size Of Initialized Data 0x00003000
File Type IMAGE_FILE_EXECUTABLE_IMAGE
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
Machine Type IMAGE_FILE_MACHINE_I386
Compile Timestamp 2011-06-14 21:01 (UTC+2)
Version Information (6)
»
CompanyName Microsoft
ProductName Win
FileVersion 1.00
ProductVersion 1.00
InternalName Win
OriginalFilename Win.exe
Sections (4)
»
Name Virtual Address Virtual Size Raw Data Size Raw Data Offset Flags Entropy
.text 0x00401000 0x0002A728 0x0002B000 0x00001000 IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE 5.95
.data 0x0042C000 0x00001B74 0x00001000 0x0002C000 IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE 0.0
.rsrc 0x0042E000 0x000005E0 0x00001000 0x0002D000 IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ 1.69
.tdata 0x0042F000 0x0000F000 0x0000F000 0x0002E000 IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE 0.0
Imports (1)
»
MSVBVM60.DLL (160)
»
API Name Ordinal IAT Address Thunk RVA Thunk Offset Hint
EVENT_SINK_GetIDsOfNames - 0x00401000 0x0002ACAC 0x0002ACAC 0x00000000
__vbaStrI2 - 0x00401004 0x0002ACB0 0x0002ACB0 0x00000000
None 0x000002B2 0x00401008 0x0002ACB4 0x0002ACB4 -
_CIcos - 0x0040100C 0x0002ACB8 0x0002ACB8 0x00000000
_adj_fptan - 0x00401010 0x0002ACBC 0x0002ACBC 0x00000000
__vbaStrI4 - 0x00401014 0x0002ACC0 0x0002ACC0 0x00000000
__vbaVarVargNofree - 0x00401018 0x0002ACC4 0x0002ACC4 0x00000000
__vbaFreeVar - 0x0040101C 0x0002ACC8 0x0002ACC8 0x00000000
__vbaStrVarMove - 0x00401020 0x0002ACCC 0x0002ACCC 0x00000000
__vbaLenBstr - 0x00401024 0x0002ACD0 0x0002ACD0 0x00000000
__vbaLateIdCall - 0x00401028 0x0002ACD4 0x0002ACD4 0x00000000
__vbaPut3 - 0x0040102C 0x0002ACD8 0x0002ACD8 0x00000000
__vbaEnd - 0x00401030 0x0002ACDC 0x0002ACDC 0x00000000
__vbaFreeVarList - 0x00401034 0x0002ACE0 0x0002ACE0 0x00000000
_adj_fdiv_m64 - 0x00401038 0x0002ACE4 0x0002ACE4 0x00000000
__vbaPut4 - 0x0040103C 0x0002ACE8 0x0002ACE8 0x00000000
EVENT_SINK_Invoke - 0x00401040 0x0002ACEC 0x0002ACEC 0x00000000
__vbaRaiseEvent - 0x00401044 0x0002ACF0 0x0002ACF0 0x00000000
__vbaFreeObjList - 0x00401048 0x0002ACF4 0x0002ACF4 0x00000000
None 0x00000204 0x0040104C 0x0002ACF8 0x0002ACF8 -
__vbaStrErrVarCopy - 0x00401050 0x0002ACFC 0x0002ACFC 0x00000000
None 0x00000205 0x00401054 0x0002AD00 0x0002AD00 -
_adj_fprem1 - 0x00401058 0x0002AD04 0x0002AD04 0x00000000
__vbaRecAnsiToUni - 0x0040105C 0x0002AD08 0x0002AD08 0x00000000
None 0x00000207 0x00401060 0x0002AD0C 0x0002AD0C -
__vbaCopyBytes - 0x00401064 0x0002AD10 0x0002AD10 0x00000000
__vbaStrCat - 0x00401068 0x0002AD14 0x0002AD14 0x00000000
__vbaLsetFixstr - 0x0040106C 0x0002AD18 0x0002AD18 0x00000000
__vbaRecDestruct - 0x00401070 0x0002AD1C 0x0002AD1C 0x00000000
__vbaSetSystemError - 0x00401074 0x0002AD20 0x0002AD20 0x00000000
None 0x00000295 0x00401078 0x0002AD24 0x0002AD24 -
__vbaHresultCheckObj - 0x0040107C 0x0002AD28 0x0002AD28 0x00000000
__vbaNameFile - 0x00401080 0x0002AD2C 0x0002AD2C 0x00000000
_adj_fdiv_m32 - 0x00401084 0x0002AD30 0x0002AD30 0x00000000
__vbaAryVar - 0x00401088 0x0002AD34 0x0002AD34 0x00000000
Zombie_GetTypeInfo - 0x0040108C 0x0002AD38 0x0002AD38 0x00000000
__vbaAryDestruct - 0x00401090 0x0002AD3C 0x0002AD3C 0x00000000
None 0x0000029D 0x00401094 0x0002AD40 0x0002AD40 -
None 0x00000251 0x00401098 0x0002AD44 0x0002AD44 -
__vbaBoolStr - 0x0040109C 0x0002AD48 0x0002AD48 0x00000000
__vbaExitProc - 0x004010A0 0x0002AD4C 0x0002AD4C 0x00000000
__vbaI4Abs - 0x004010A4 0x0002AD50 0x0002AD50 0x00000000
None 0x00000252 0x004010A8 0x0002AD54 0x0002AD54 -
__vbaOnError - 0x004010AC 0x0002AD58 0x0002AD58 0x00000000
__vbaObjSet - 0x004010B0 0x0002AD5C 0x0002AD5C 0x00000000
_adj_fdiv_m16i - 0x004010B4 0x0002AD60 0x0002AD60 0x00000000
__vbaObjSetAddref - 0x004010B8 0x0002AD64 0x0002AD64 0x00000000
_adj_fdivr_m16i - 0x004010BC 0x0002AD68 0x0002AD68 0x00000000
None 0x00000256 0x004010C0 0x0002AD6C 0x0002AD6C -
__vbaFpR4 - 0x004010C4 0x0002AD70 0x0002AD70 0x00000000
None 0x000002C1 0x004010C8 0x0002AD74 0x0002AD74 -
__vbaStrFixstr - 0x004010CC 0x0002AD78 0x0002AD78 0x00000000
_CIsin - 0x004010D0 0x0002AD7C 0x0002AD7C 0x00000000
__vbaErase - 0x004010D4 0x0002AD80 0x0002AD80 0x00000000
None 0x00000277 0x004010D8 0x0002AD84 0x0002AD84 -
None 0x000002C5 0x004010DC 0x0002AD88 0x0002AD88 -
None 0x0000020D 0x004010E0 0x0002AD8C 0x0002AD8C -
__vbaChkstk - 0x004010E4 0x0002AD90 0x0002AD90 0x00000000
__vbaFileClose - 0x004010E8 0x0002AD94 0x0002AD94 0x00000000
EVENT_SINK_AddRef - 0x004010EC 0x0002AD98 0x0002AD98 0x00000000
__vbaGenerateBoundsError - 0x004010F0 0x0002AD9C 0x0002AD9C 0x00000000
__vbaGet3 - 0x004010F4 0x0002ADA0 0x0002ADA0 0x00000000
__vbaStrCmp - 0x004010F8 0x0002ADA4 0x0002ADA4 0x00000000
None 0x00000211 0x004010FC 0x0002ADA8 0x0002ADA8 -
__vbaGet4 - 0x00401100 0x0002ADAC 0x0002ADAC 0x00000000
__vbaPutOwner3 - 0x00401104 0x0002ADB0 0x0002ADB0 0x00000000
__vbaVarTstEq - 0x00401108 0x0002ADB4 0x0002ADB4 0x00000000
__vbaAryConstruct2 - 0x0040110C 0x0002ADB8 0x0002ADB8 0x00000000
__vbaObjVar - 0x00401110 0x0002ADBC 0x0002ADBC 0x00000000
__vbaI2I4 - 0x00401114 0x0002ADC0 0x0002ADC0 0x00000000
DllFunctionCall - 0x00401118 0x0002ADC4 0x0002ADC4 0x00000000
__vbaVarLateMemSt - 0x0040111C 0x0002ADC8 0x0002ADC8 0x00000000
__vbaFpUI1 - 0x00401120 0x0002ADCC 0x0002ADCC 0x00000000
__vbaRedimPreserve - 0x00401124 0x0002ADD0 0x0002ADD0 0x00000000
__vbaStrR4 - 0x00401128 0x0002ADD4 0x0002ADD4 0x00000000
_adj_fpatan - 0x0040112C 0x0002ADD8 0x0002ADD8 0x00000000
__vbaFixstrConstruct - 0x00401130 0x0002ADDC 0x0002ADDC 0x00000000
__vbaLateIdCallLd - 0x00401134 0x0002ADE0 0x0002ADE0 0x00000000
Zombie_GetTypeInfoCount - 0x00401138 0x0002ADE4 0x0002ADE4 0x00000000
__vbaRedim - 0x0040113C 0x0002ADE8 0x0002ADE8 0x00000000
__vbaRecUniToAnsi - 0x00401140 0x0002ADEC 0x0002ADEC 0x00000000
EVENT_SINK_Release - 0x00401144 0x0002ADF0 0x0002ADF0 0x00000000
__vbaNew - 0x00401148 0x0002ADF4 0x0002ADF4 0x00000000
None 0x00000258 0x0040114C 0x0002ADF8 0x0002ADF8 -
__vbaUI1I2 - 0x00401150 0x0002ADFC 0x0002ADFC 0x00000000
_CIsqrt - 0x00401154 0x0002AE00 0x0002AE00 0x00000000
EVENT_SINK_QueryInterface - 0x00401158 0x0002AE04 0x0002AE04 0x00000000
__vbaExceptHandler - 0x0040115C 0x0002AE08 0x0002AE08 0x00000000
None 0x000002C7 0x00401160 0x0002AE0C 0x0002AE0C -
None 0x000002C8 0x00401164 0x0002AE10 0x0002AE10 -
__vbaStrToUnicode - 0x00401168 0x0002AE14 0x0002AE14 0x00000000
None 0x0000025E 0x0040116C 0x0002AE18 0x0002AE18 -
_adj_fprem - 0x00401170 0x0002AE1C 0x0002AE1C 0x00000000
_adj_fdivr_m64 - 0x00401174 0x0002AE20 0x0002AE20 0x00000000
None 0x000002CA 0x00401178 0x0002AE24 0x0002AE24 -
None 0x000002CC 0x0040117C 0x0002AE28 0x0002AE28 -
None 0x00000261 0x00401180 0x0002AE2C 0x0002AE2C -
__vbaFPException - 0x00401184 0x0002AE30 0x0002AE30 0x00000000
None 0x000002CD 0x00401188 0x0002AE34 0x0002AE34 -
None 0x0000013F 0x0040118C 0x0002AE38 0x0002AE38 -
__vbaGetOwner3 - 0x00401190 0x0002AE3C 0x0002AE3C 0x00000000
__vbaUbound - 0x00401194 0x0002AE40 0x0002AE40 0x00000000
None 0x00000217 0x00401198 0x0002AE44 0x0002AE44 -
__vbaFileSeek - 0x0040119C 0x0002AE48 0x0002AE48 0x00000000
None 0x00000284 0x004011A0 0x0002AE4C 0x0002AE4C -
None 0x00000219 0x004011A4 0x0002AE50 0x0002AE50 -
_CIlog - 0x004011A8 0x0002AE54 0x0002AE54 0x00000000
__vbaErrorOverflow - 0x004011AC 0x0002AE58 0x0002AE58 0x00000000
__vbaFileOpen - 0x004011B0 0x0002AE5C 0x0002AE5C 0x00000000
__vbaVarLateMemCallLdRf - 0x004011B4 0x0002AE60 0x0002AE60 0x00000000
None 0x00000288 0x004011B8 0x0002AE64 0x0002AE64 -
None 0x0000023A 0x004011BC 0x0002AE68 0x0002AE68 -
__vbaNew2 - 0x004011C0 0x0002AE6C 0x0002AE6C 0x00000000
__vbaInStr - 0x004011C4 0x0002AE70 0x0002AE70 0x00000000
_adj_fdiv_m32i - 0x004011C8 0x0002AE74 0x0002AE74 0x00000000
None 0x0000023C 0x004011CC 0x0002AE78 0x0002AE78 -
_adj_fdivr_m32i - 0x004011D0 0x0002AE7C 0x0002AE7C 0x00000000
__vbaStrCopy - 0x004011D4 0x0002AE80 0x0002AE80 0x00000000
__vbaI4Str - 0x004011D8 0x0002AE84 0x0002AE84 0x00000000
__vbaFreeStrList - 0x004011DC 0x0002AE88 0x0002AE88 0x00000000
_adj_fdivr_m32 - 0x004011E0 0x0002AE8C 0x0002AE8C 0x00000000
_adj_fdiv_r - 0x004011E4 0x0002AE90 0x0002AE90 0x00000000
None 0x00000242 0x004011E8 0x0002AE94 0x0002AE94 -
None 0x00000064 0x004011EC 0x0002AE98 0x0002AE98 -
__vbaVarSetVar - 0x004011F0 0x0002AE9C 0x0002AE9C 0x00000000
__vbaI4Var - 0x004011F4 0x0002AEA0 0x0002AEA0 0x00000000
None 0x000002B1 0x004011F8 0x0002AEA4 0x0002AEA4 -
__vbaLateMemCall - 0x004011FC 0x0002AEA8 0x0002AEA8 0x00000000
__vbaVarAdd - 0x00401200 0x0002AEAC 0x0002AEAC 0x00000000
None 0x00000263 0x00401204 0x0002AEB0 0x0002AEB0 -
__vbaAryLock - 0x00401208 0x0002AEB4 0x0002AEB4 0x00000000
None 0x00000140 0x0040120C 0x0002AEB8 0x0002AEB8 -
__vbaStrComp - 0x00401210 0x0002AEBC 0x0002AEBC 0x00000000
__vbaVarDup - 0x00401214 0x0002AEC0 0x0002AEC0 0x00000000
__vbaStrToAnsi - 0x00401218 0x0002AEC4 0x0002AEC4 0x00000000
None 0x00000141 0x0040121C 0x0002AEC8 0x0002AEC8 -
__vbaFpI2 - 0x00401220 0x0002AECC 0x0002AECC 0x00000000
__vbaFpI4 - 0x00401224 0x0002AED0 0x0002AED0 0x00000000
__vbaVarLateMemCallLd - 0x00401228 0x0002AED4 0x0002AED4 0x00000000
None 0x00000268 0x0040122C 0x0002AED8 0x0002AED8 -
__vbaVarSetObjAddref - 0x00401230 0x0002AEDC 0x0002AEDC 0x00000000
__vbaRecDestructAnsi - 0x00401234 0x0002AEE0 0x0002AEE0 0x00000000
__vbaLateMemCallLd - 0x00401238 0x0002AEE4 0x0002AEE4 0x00000000
_CIatan - 0x0040123C 0x0002AEE8 0x0002AEE8 0x00000000
__vbaAryCopy - 0x00401240 0x0002AEEC 0x0002AEEC 0x00000000
__vbaStrMove - 0x00401244 0x0002AEF0 0x0002AEF0 0x00000000
None 0x0000026A 0x00401248 0x0002AEF4 0x0002AEF4 -
__vbaCastObj - 0x0040124C 0x0002AEF8 0x0002AEF8 0x00000000
__vbaR8IntI4 - 0x00401250 0x0002AEFC 0x0002AEFC 0x00000000
None 0x0000028A 0x00401254 0x0002AF00 0x0002AF00 -
_allmul - 0x00401258 0x0002AF04 0x0002AF04 0x00000000
__vbaVarLateMemCallSt - 0x0040125C 0x0002AF08 0x0002AF08 0x00000000
_CItan - 0x00401260 0x0002AF0C 0x0002AF0C 0x00000000
None 0x00000222 0x00401264 0x0002AF10 0x0002AF10 -
__vbaAryUnlock - 0x00401268 0x0002AF14 0x0002AF14 0x00000000
_CIexp - 0x0040126C 0x0002AF18 0x0002AF18 0x00000000
__vbaFreeObj - 0x00401270 0x0002AF1C 0x0002AF1C 0x00000000
__vbaFreeStr - 0x00401274 0x0002AF20 0x0002AF20 0x00000000
None 0x00000244 0x00401278 0x0002AF24 0x0002AF24 -
None 0x00000245 0x0040127C 0x0002AF28 0x0002AF28 -
Memory Dumps (5)
»
Name Process ID Start VA End VA Dump Reason PE Rebuild Bitness Entry Point YARA Actions
icsys.icn.exe 4 0x00400000 0x0043DFFF First Execution False 32-bit 0x00403670 False
buffer 4 0x00450000 0x0045FFFF Marked Executable False 32-bit - False
buffer 4 0x00450000 0x0045FFFF Content Changed False 32-bit - False
buffer 4 0x00450000 0x0045FFFF First Execution False 32-bit 0x00456338 False
icsys.icn.exe 4 0x00400000 0x0043DFFF Process Termination False 32-bit - False
C:\Users\RDhJ0CNFevzX\AppData\Roaming\mrsys.exe Dropped File Binary
Clean
»
MIME Type application/vnd.microsoft.portable-executable
File Size 274.38 KB
MD5 3eb3e2664420ff5dcbb473a268ca4a0e Copy to Clipboard
SHA1 572e98789ccb2c757fc0185946163a69bdab5442 Copy to Clipboard
SHA256 a815116830970d6e0848e44bbe281cce38b68ffec30bfbd4c6218e2b9d8e90ed Copy to Clipboard
SSDeep 3072:UvEfVUzSLhIVbV6i5LirrlZrHyrUHUckoMQ2RN6unr:UvEN2U+T6i5LirrllHy4HUcMQY6i Copy to Clipboard
ImpHash 98f67c550a7da65513e63ffd998f6b2e Copy to Clipboard
PE Information
»
Image Base 0x00400000
Entry Point 0x00403670
Size Of Code 0x0002B000
Size Of Initialized Data 0x00003000
File Type IMAGE_FILE_EXECUTABLE_IMAGE
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
Machine Type IMAGE_FILE_MACHINE_I386
Compile Timestamp 2011-06-14 21:01 (UTC+2)
Version Information (6)
»
CompanyName Microsoft
ProductName Win
FileVersion 1.00
ProductVersion 1.00
InternalName Win
OriginalFilename Win.exe
Sections (4)
»
Name Virtual Address Virtual Size Raw Data Size Raw Data Offset Flags Entropy
.text 0x00401000 0x0002A728 0x0002B000 0x00001000 IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE 5.95
.data 0x0042C000 0x00001B74 0x00001000 0x0002C000 IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE 0.0
.rsrc 0x0042E000 0x000005E0 0x00001000 0x0002D000 IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ 1.69
.tdata 0x0042F000 0x0000F000 0x0000F000 0x0002E000 IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE 0.0
Imports (1)
»
MSVBVM60.DLL (160)
»
API Name Ordinal IAT Address Thunk RVA Thunk Offset Hint
EVENT_SINK_GetIDsOfNames - 0x00401000 0x0002ACAC 0x0002ACAC 0x00000000
__vbaStrI2 - 0x00401004 0x0002ACB0 0x0002ACB0 0x00000000
None 0x000002B2 0x00401008 0x0002ACB4 0x0002ACB4 -
_CIcos - 0x0040100C 0x0002ACB8 0x0002ACB8 0x00000000
_adj_fptan - 0x00401010 0x0002ACBC 0x0002ACBC 0x00000000
__vbaStrI4 - 0x00401014 0x0002ACC0 0x0002ACC0 0x00000000
__vbaVarVargNofree - 0x00401018 0x0002ACC4 0x0002ACC4 0x00000000
__vbaFreeVar - 0x0040101C 0x0002ACC8 0x0002ACC8 0x00000000
__vbaStrVarMove - 0x00401020 0x0002ACCC 0x0002ACCC 0x00000000
__vbaLenBstr - 0x00401024 0x0002ACD0 0x0002ACD0 0x00000000
__vbaLateIdCall - 0x00401028 0x0002ACD4 0x0002ACD4 0x00000000
__vbaPut3 - 0x0040102C 0x0002ACD8 0x0002ACD8 0x00000000
__vbaEnd - 0x00401030 0x0002ACDC 0x0002ACDC 0x00000000
__vbaFreeVarList - 0x00401034 0x0002ACE0 0x0002ACE0 0x00000000
_adj_fdiv_m64 - 0x00401038 0x0002ACE4 0x0002ACE4 0x00000000
__vbaPut4 - 0x0040103C 0x0002ACE8 0x0002ACE8 0x00000000
EVENT_SINK_Invoke - 0x00401040 0x0002ACEC 0x0002ACEC 0x00000000
__vbaRaiseEvent - 0x00401044 0x0002ACF0 0x0002ACF0 0x00000000
__vbaFreeObjList - 0x00401048 0x0002ACF4 0x0002ACF4 0x00000000
None 0x00000204 0x0040104C 0x0002ACF8 0x0002ACF8 -
__vbaStrErrVarCopy - 0x00401050 0x0002ACFC 0x0002ACFC 0x00000000
None 0x00000205 0x00401054 0x0002AD00 0x0002AD00 -
_adj_fprem1 - 0x00401058 0x0002AD04 0x0002AD04 0x00000000
__vbaRecAnsiToUni - 0x0040105C 0x0002AD08 0x0002AD08 0x00000000
None 0x00000207 0x00401060 0x0002AD0C 0x0002AD0C -
__vbaCopyBytes - 0x00401064 0x0002AD10 0x0002AD10 0x00000000
__vbaStrCat - 0x00401068 0x0002AD14 0x0002AD14 0x00000000
__vbaLsetFixstr - 0x0040106C 0x0002AD18 0x0002AD18 0x00000000
__vbaRecDestruct - 0x00401070 0x0002AD1C 0x0002AD1C 0x00000000
__vbaSetSystemError - 0x00401074 0x0002AD20 0x0002AD20 0x00000000
None 0x00000295 0x00401078 0x0002AD24 0x0002AD24 -
__vbaHresultCheckObj - 0x0040107C 0x0002AD28 0x0002AD28 0x00000000
__vbaNameFile - 0x00401080 0x0002AD2C 0x0002AD2C 0x00000000
_adj_fdiv_m32 - 0x00401084 0x0002AD30 0x0002AD30 0x00000000
__vbaAryVar - 0x00401088 0x0002AD34 0x0002AD34 0x00000000
Zombie_GetTypeInfo - 0x0040108C 0x0002AD38 0x0002AD38 0x00000000
__vbaAryDestruct - 0x00401090 0x0002AD3C 0x0002AD3C 0x00000000
None 0x0000029D 0x00401094 0x0002AD40 0x0002AD40 -
None 0x00000251 0x00401098 0x0002AD44 0x0002AD44 -
__vbaBoolStr - 0x0040109C 0x0002AD48 0x0002AD48 0x00000000
__vbaExitProc - 0x004010A0 0x0002AD4C 0x0002AD4C 0x00000000
__vbaI4Abs - 0x004010A4 0x0002AD50 0x0002AD50 0x00000000
None 0x00000252 0x004010A8 0x0002AD54 0x0002AD54 -
__vbaOnError - 0x004010AC 0x0002AD58 0x0002AD58 0x00000000
__vbaObjSet - 0x004010B0 0x0002AD5C 0x0002AD5C 0x00000000
_adj_fdiv_m16i - 0x004010B4 0x0002AD60 0x0002AD60 0x00000000
__vbaObjSetAddref - 0x004010B8 0x0002AD64 0x0002AD64 0x00000000
_adj_fdivr_m16i - 0x004010BC 0x0002AD68 0x0002AD68 0x00000000
None 0x00000256 0x004010C0 0x0002AD6C 0x0002AD6C -
__vbaFpR4 - 0x004010C4 0x0002AD70 0x0002AD70 0x00000000
None 0x000002C1 0x004010C8 0x0002AD74 0x0002AD74 -
__vbaStrFixstr - 0x004010CC 0x0002AD78 0x0002AD78 0x00000000
_CIsin - 0x004010D0 0x0002AD7C 0x0002AD7C 0x00000000
__vbaErase - 0x004010D4 0x0002AD80 0x0002AD80 0x00000000
None 0x00000277 0x004010D8 0x0002AD84 0x0002AD84 -
None 0x000002C5 0x004010DC 0x0002AD88 0x0002AD88 -
None 0x0000020D 0x004010E0 0x0002AD8C 0x0002AD8C -
__vbaChkstk - 0x004010E4 0x0002AD90 0x0002AD90 0x00000000
__vbaFileClose - 0x004010E8 0x0002AD94 0x0002AD94 0x00000000
EVENT_SINK_AddRef - 0x004010EC 0x0002AD98 0x0002AD98 0x00000000
__vbaGenerateBoundsError - 0x004010F0 0x0002AD9C 0x0002AD9C 0x00000000
__vbaGet3 - 0x004010F4 0x0002ADA0 0x0002ADA0 0x00000000
__vbaStrCmp - 0x004010F8 0x0002ADA4 0x0002ADA4 0x00000000
None 0x00000211 0x004010FC 0x0002ADA8 0x0002ADA8 -
__vbaGet4 - 0x00401100 0x0002ADAC 0x0002ADAC 0x00000000
__vbaPutOwner3 - 0x00401104 0x0002ADB0 0x0002ADB0 0x00000000
__vbaVarTstEq - 0x00401108 0x0002ADB4 0x0002ADB4 0x00000000
__vbaAryConstruct2 - 0x0040110C 0x0002ADB8 0x0002ADB8 0x00000000
__vbaObjVar - 0x00401110 0x0002ADBC 0x0002ADBC 0x00000000
__vbaI2I4 - 0x00401114 0x0002ADC0 0x0002ADC0 0x00000000
DllFunctionCall - 0x00401118 0x0002ADC4 0x0002ADC4 0x00000000
__vbaVarLateMemSt - 0x0040111C 0x0002ADC8 0x0002ADC8 0x00000000
__vbaFpUI1 - 0x00401120 0x0002ADCC 0x0002ADCC 0x00000000
__vbaRedimPreserve - 0x00401124 0x0002ADD0 0x0002ADD0 0x00000000
__vbaStrR4 - 0x00401128 0x0002ADD4 0x0002ADD4 0x00000000
_adj_fpatan - 0x0040112C 0x0002ADD8 0x0002ADD8 0x00000000
__vbaFixstrConstruct - 0x00401130 0x0002ADDC 0x0002ADDC 0x00000000
__vbaLateIdCallLd - 0x00401134 0x0002ADE0 0x0002ADE0 0x00000000
Zombie_GetTypeInfoCount - 0x00401138 0x0002ADE4 0x0002ADE4 0x00000000
__vbaRedim - 0x0040113C 0x0002ADE8 0x0002ADE8 0x00000000
__vbaRecUniToAnsi - 0x00401140 0x0002ADEC 0x0002ADEC 0x00000000
EVENT_SINK_Release - 0x00401144 0x0002ADF0 0x0002ADF0 0x00000000
__vbaNew - 0x00401148 0x0002ADF4 0x0002ADF4 0x00000000
None 0x00000258 0x0040114C 0x0002ADF8 0x0002ADF8 -
__vbaUI1I2 - 0x00401150 0x0002ADFC 0x0002ADFC 0x00000000
_CIsqrt - 0x00401154 0x0002AE00 0x0002AE00 0x00000000
EVENT_SINK_QueryInterface - 0x00401158 0x0002AE04 0x0002AE04 0x00000000
__vbaExceptHandler - 0x0040115C 0x0002AE08 0x0002AE08 0x00000000
None 0x000002C7 0x00401160 0x0002AE0C 0x0002AE0C -
None 0x000002C8 0x00401164 0x0002AE10 0x0002AE10 -
__vbaStrToUnicode - 0x00401168 0x0002AE14 0x0002AE14 0x00000000
None 0x0000025E 0x0040116C 0x0002AE18 0x0002AE18 -
_adj_fprem - 0x00401170 0x0002AE1C 0x0002AE1C 0x00000000
_adj_fdivr_m64 - 0x00401174 0x0002AE20 0x0002AE20 0x00000000
None 0x000002CA 0x00401178 0x0002AE24 0x0002AE24 -
None 0x000002CC 0x0040117C 0x0002AE28 0x0002AE28 -
None 0x00000261 0x00401180 0x0002AE2C 0x0002AE2C -
__vbaFPException - 0x00401184 0x0002AE30 0x0002AE30 0x00000000
None 0x000002CD 0x00401188 0x0002AE34 0x0002AE34 -
None 0x0000013F 0x0040118C 0x0002AE38 0x0002AE38 -
__vbaGetOwner3 - 0x00401190 0x0002AE3C 0x0002AE3C 0x00000000
__vbaUbound - 0x00401194 0x0002AE40 0x0002AE40 0x00000000
None 0x00000217 0x00401198 0x0002AE44 0x0002AE44 -
__vbaFileSeek - 0x0040119C 0x0002AE48 0x0002AE48 0x00000000
None 0x00000284 0x004011A0 0x0002AE4C 0x0002AE4C -
None 0x00000219 0x004011A4 0x0002AE50 0x0002AE50 -
_CIlog - 0x004011A8 0x0002AE54 0x0002AE54 0x00000000
__vbaErrorOverflow - 0x004011AC 0x0002AE58 0x0002AE58 0x00000000
__vbaFileOpen - 0x004011B0 0x0002AE5C 0x0002AE5C 0x00000000
__vbaVarLateMemCallLdRf - 0x004011B4 0x0002AE60 0x0002AE60 0x00000000
None 0x00000288 0x004011B8 0x0002AE64 0x0002AE64 -
None 0x0000023A 0x004011BC 0x0002AE68 0x0002AE68 -
__vbaNew2 - 0x004011C0 0x0002AE6C 0x0002AE6C 0x00000000
__vbaInStr - 0x004011C4 0x0002AE70 0x0002AE70 0x00000000
_adj_fdiv_m32i - 0x004011C8 0x0002AE74 0x0002AE74 0x00000000
None 0x0000023C 0x004011CC 0x0002AE78 0x0002AE78 -
_adj_fdivr_m32i - 0x004011D0 0x0002AE7C 0x0002AE7C 0x00000000
__vbaStrCopy - 0x004011D4 0x0002AE80 0x0002AE80 0x00000000
__vbaI4Str - 0x004011D8 0x0002AE84 0x0002AE84 0x00000000
__vbaFreeStrList - 0x004011DC 0x0002AE88 0x0002AE88 0x00000000
_adj_fdivr_m32 - 0x004011E0 0x0002AE8C 0x0002AE8C 0x00000000
_adj_fdiv_r - 0x004011E4 0x0002AE90 0x0002AE90 0x00000000
None 0x00000242 0x004011E8 0x0002AE94 0x0002AE94 -
None 0x00000064 0x004011EC 0x0002AE98 0x0002AE98 -
__vbaVarSetVar - 0x004011F0 0x0002AE9C 0x0002AE9C 0x00000000
__vbaI4Var - 0x004011F4 0x0002AEA0 0x0002AEA0 0x00000000
None 0x000002B1 0x004011F8 0x0002AEA4 0x0002AEA4 -
__vbaLateMemCall - 0x004011FC 0x0002AEA8 0x0002AEA8 0x00000000
__vbaVarAdd - 0x00401200 0x0002AEAC 0x0002AEAC 0x00000000
None 0x00000263 0x00401204 0x0002AEB0 0x0002AEB0 -
__vbaAryLock - 0x00401208 0x0002AEB4 0x0002AEB4 0x00000000
None 0x00000140 0x0040120C 0x0002AEB8 0x0002AEB8 -
__vbaStrComp - 0x00401210 0x0002AEBC 0x0002AEBC 0x00000000
__vbaVarDup - 0x00401214 0x0002AEC0 0x0002AEC0 0x00000000
__vbaStrToAnsi - 0x00401218 0x0002AEC4 0x0002AEC4 0x00000000
None 0x00000141 0x0040121C 0x0002AEC8 0x0002AEC8 -
__vbaFpI2 - 0x00401220 0x0002AECC 0x0002AECC 0x00000000
__vbaFpI4 - 0x00401224 0x0002AED0 0x0002AED0 0x00000000
__vbaVarLateMemCallLd - 0x00401228 0x0002AED4 0x0002AED4 0x00000000
None 0x00000268 0x0040122C 0x0002AED8 0x0002AED8 -
__vbaVarSetObjAddref - 0x00401230 0x0002AEDC 0x0002AEDC 0x00000000
__vbaRecDestructAnsi - 0x00401234 0x0002AEE0 0x0002AEE0 0x00000000
__vbaLateMemCallLd - 0x00401238 0x0002AEE4 0x0002AEE4 0x00000000
_CIatan - 0x0040123C 0x0002AEE8 0x0002AEE8 0x00000000
__vbaAryCopy - 0x00401240 0x0002AEEC 0x0002AEEC 0x00000000
__vbaStrMove - 0x00401244 0x0002AEF0 0x0002AEF0 0x00000000
None 0x0000026A 0x00401248 0x0002AEF4 0x0002AEF4 -
__vbaCastObj - 0x0040124C 0x0002AEF8 0x0002AEF8 0x00000000
__vbaR8IntI4 - 0x00401250 0x0002AEFC 0x0002AEFC 0x00000000
None 0x0000028A 0x00401254 0x0002AF00 0x0002AF00 -
_allmul - 0x00401258 0x0002AF04 0x0002AF04 0x00000000
__vbaVarLateMemCallSt - 0x0040125C 0x0002AF08 0x0002AF08 0x00000000
_CItan - 0x00401260 0x0002AF0C 0x0002AF0C 0x00000000
None 0x00000222 0x00401264 0x0002AF10 0x0002AF10 -
__vbaAryUnlock - 0x00401268 0x0002AF14 0x0002AF14 0x00000000
_CIexp - 0x0040126C 0x0002AF18 0x0002AF18 0x00000000
__vbaFreeObj - 0x00401270 0x0002AF1C 0x0002AF1C 0x00000000
__vbaFreeStr - 0x00401274 0x0002AF20 0x0002AF20 0x00000000
None 0x00000244 0x00401278 0x0002AF24 0x0002AF24 -
None 0x00000245 0x0040127C 0x0002AF28 0x0002AF28 -
C:\Users\RDhJ0CNFevzX\AppData\Local\stsys.exe Dropped File Binary
Clean
»
MIME Type application/vnd.microsoft.portable-executable
File Size 274.28 KB
MD5 6a9ae8310da0ba13bea3b0734ce770cf Copy to Clipboard
SHA1 41fc33504bd09729947be670a2967db86bb083f8 Copy to Clipboard
SHA256 0b28a147b307087f327d84ae88b41a0512619dc9fc6303d9352dcf6ff9aac437 Copy to Clipboard
SSDeep 3072:UvEfVUzSLhIVbV6i5LirrlZrHyrUHUckoMQ2RN6unG:UvEN2U+T6i5LirrllHy4HUcMQY6/ Copy to Clipboard
ImpHash 98f67c550a7da65513e63ffd998f6b2e Copy to Clipboard
PE Information
»
Image Base 0x00400000
Entry Point 0x00403670
Size Of Code 0x0002B000
Size Of Initialized Data 0x00003000
File Type IMAGE_FILE_EXECUTABLE_IMAGE
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
Machine Type IMAGE_FILE_MACHINE_I386
Compile Timestamp 2011-06-14 21:01 (UTC+2)
Version Information (6)
»
CompanyName Microsoft
ProductName Win
FileVersion 1.00
ProductVersion 1.00
InternalName Win
OriginalFilename Win.exe
Sections (4)
»
Name Virtual Address Virtual Size Raw Data Size Raw Data Offset Flags Entropy
.text 0x00401000 0x0002A728 0x0002B000 0x00001000 IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE 5.95
.data 0x0042C000 0x00001B74 0x00001000 0x0002C000 IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE 0.0
.rsrc 0x0042E000 0x000005E0 0x00001000 0x0002D000 IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ 1.69
.tdata 0x0042F000 0x0000F000 0x0000F000 0x0002E000 IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE 0.0
Imports (1)
»
MSVBVM60.DLL (160)
»
API Name Ordinal IAT Address Thunk RVA Thunk Offset Hint
EVENT_SINK_GetIDsOfNames - 0x00401000 0x0002ACAC 0x0002ACAC 0x00000000
__vbaStrI2 - 0x00401004 0x0002ACB0 0x0002ACB0 0x00000000
None 0x000002B2 0x00401008 0x0002ACB4 0x0002ACB4 -
_CIcos - 0x0040100C 0x0002ACB8 0x0002ACB8 0x00000000
_adj_fptan - 0x00401010 0x0002ACBC 0x0002ACBC 0x00000000
__vbaStrI4 - 0x00401014 0x0002ACC0 0x0002ACC0 0x00000000
__vbaVarVargNofree - 0x00401018 0x0002ACC4 0x0002ACC4 0x00000000
__vbaFreeVar - 0x0040101C 0x0002ACC8 0x0002ACC8 0x00000000
__vbaStrVarMove - 0x00401020 0x0002ACCC 0x0002ACCC 0x00000000
__vbaLenBstr - 0x00401024 0x0002ACD0 0x0002ACD0 0x00000000
__vbaLateIdCall - 0x00401028 0x0002ACD4 0x0002ACD4 0x00000000
__vbaPut3 - 0x0040102C 0x0002ACD8 0x0002ACD8 0x00000000
__vbaEnd - 0x00401030 0x0002ACDC 0x0002ACDC 0x00000000
__vbaFreeVarList - 0x00401034 0x0002ACE0 0x0002ACE0 0x00000000
_adj_fdiv_m64 - 0x00401038 0x0002ACE4 0x0002ACE4 0x00000000
__vbaPut4 - 0x0040103C 0x0002ACE8 0x0002ACE8 0x00000000
EVENT_SINK_Invoke - 0x00401040 0x0002ACEC 0x0002ACEC 0x00000000
__vbaRaiseEvent - 0x00401044 0x0002ACF0 0x0002ACF0 0x00000000
__vbaFreeObjList - 0x00401048 0x0002ACF4 0x0002ACF4 0x00000000
None 0x00000204 0x0040104C 0x0002ACF8 0x0002ACF8 -
__vbaStrErrVarCopy - 0x00401050 0x0002ACFC 0x0002ACFC 0x00000000
None 0x00000205 0x00401054 0x0002AD00 0x0002AD00 -
_adj_fprem1 - 0x00401058 0x0002AD04 0x0002AD04 0x00000000
__vbaRecAnsiToUni - 0x0040105C 0x0002AD08 0x0002AD08 0x00000000
None 0x00000207 0x00401060 0x0002AD0C 0x0002AD0C -
__vbaCopyBytes - 0x00401064 0x0002AD10 0x0002AD10 0x00000000
__vbaStrCat - 0x00401068 0x0002AD14 0x0002AD14 0x00000000
__vbaLsetFixstr - 0x0040106C 0x0002AD18 0x0002AD18 0x00000000
__vbaRecDestruct - 0x00401070 0x0002AD1C 0x0002AD1C 0x00000000
__vbaSetSystemError - 0x00401074 0x0002AD20 0x0002AD20 0x00000000
None 0x00000295 0x00401078 0x0002AD24 0x0002AD24 -
__vbaHresultCheckObj - 0x0040107C 0x0002AD28 0x0002AD28 0x00000000
__vbaNameFile - 0x00401080 0x0002AD2C 0x0002AD2C 0x00000000
_adj_fdiv_m32 - 0x00401084 0x0002AD30 0x0002AD30 0x00000000
__vbaAryVar - 0x00401088 0x0002AD34 0x0002AD34 0x00000000
Zombie_GetTypeInfo - 0x0040108C 0x0002AD38 0x0002AD38 0x00000000
__vbaAryDestruct - 0x00401090 0x0002AD3C 0x0002AD3C 0x00000000
None 0x0000029D 0x00401094 0x0002AD40 0x0002AD40 -
None 0x00000251 0x00401098 0x0002AD44 0x0002AD44 -
__vbaBoolStr - 0x0040109C 0x0002AD48 0x0002AD48 0x00000000
__vbaExitProc - 0x004010A0 0x0002AD4C 0x0002AD4C 0x00000000
__vbaI4Abs - 0x004010A4 0x0002AD50 0x0002AD50 0x00000000
None 0x00000252 0x004010A8 0x0002AD54 0x0002AD54 -
__vbaOnError - 0x004010AC 0x0002AD58 0x0002AD58 0x00000000
__vbaObjSet - 0x004010B0 0x0002AD5C 0x0002AD5C 0x00000000
_adj_fdiv_m16i - 0x004010B4 0x0002AD60 0x0002AD60 0x00000000
__vbaObjSetAddref - 0x004010B8 0x0002AD64 0x0002AD64 0x00000000
_adj_fdivr_m16i - 0x004010BC 0x0002AD68 0x0002AD68 0x00000000
None 0x00000256 0x004010C0 0x0002AD6C 0x0002AD6C -
__vbaFpR4 - 0x004010C4 0x0002AD70 0x0002AD70 0x00000000
None 0x000002C1 0x004010C8 0x0002AD74 0x0002AD74 -
__vbaStrFixstr - 0x004010CC 0x0002AD78 0x0002AD78 0x00000000
_CIsin - 0x004010D0 0x0002AD7C 0x0002AD7C 0x00000000
__vbaErase - 0x004010D4 0x0002AD80 0x0002AD80 0x00000000
None 0x00000277 0x004010D8 0x0002AD84 0x0002AD84 -
None 0x000002C5 0x004010DC 0x0002AD88 0x0002AD88 -
None 0x0000020D 0x004010E0 0x0002AD8C 0x0002AD8C -
__vbaChkstk - 0x004010E4 0x0002AD90 0x0002AD90 0x00000000
__vbaFileClose - 0x004010E8 0x0002AD94 0x0002AD94 0x00000000
EVENT_SINK_AddRef - 0x004010EC 0x0002AD98 0x0002AD98 0x00000000
__vbaGenerateBoundsError - 0x004010F0 0x0002AD9C 0x0002AD9C 0x00000000
__vbaGet3 - 0x004010F4 0x0002ADA0 0x0002ADA0 0x00000000
__vbaStrCmp - 0x004010F8 0x0002ADA4 0x0002ADA4 0x00000000
None 0x00000211 0x004010FC 0x0002ADA8 0x0002ADA8 -
__vbaGet4 - 0x00401100 0x0002ADAC 0x0002ADAC 0x00000000
__vbaPutOwner3 - 0x00401104 0x0002ADB0 0x0002ADB0 0x00000000
__vbaVarTstEq - 0x00401108 0x0002ADB4 0x0002ADB4 0x00000000
__vbaAryConstruct2 - 0x0040110C 0x0002ADB8 0x0002ADB8 0x00000000
__vbaObjVar - 0x00401110 0x0002ADBC 0x0002ADBC 0x00000000
__vbaI2I4 - 0x00401114 0x0002ADC0 0x0002ADC0 0x00000000
DllFunctionCall - 0x00401118 0x0002ADC4 0x0002ADC4 0x00000000
__vbaVarLateMemSt - 0x0040111C 0x0002ADC8 0x0002ADC8 0x00000000
__vbaFpUI1 - 0x00401120 0x0002ADCC 0x0002ADCC 0x00000000
__vbaRedimPreserve - 0x00401124 0x0002ADD0 0x0002ADD0 0x00000000
__vbaStrR4 - 0x00401128 0x0002ADD4 0x0002ADD4 0x00000000
_adj_fpatan - 0x0040112C 0x0002ADD8 0x0002ADD8 0x00000000
__vbaFixstrConstruct - 0x00401130 0x0002ADDC 0x0002ADDC 0x00000000
__vbaLateIdCallLd - 0x00401134 0x0002ADE0 0x0002ADE0 0x00000000
Zombie_GetTypeInfoCount - 0x00401138 0x0002ADE4 0x0002ADE4 0x00000000
__vbaRedim - 0x0040113C 0x0002ADE8 0x0002ADE8 0x00000000
__vbaRecUniToAnsi - 0x00401140 0x0002ADEC 0x0002ADEC 0x00000000
EVENT_SINK_Release - 0x00401144 0x0002ADF0 0x0002ADF0 0x00000000
__vbaNew - 0x00401148 0x0002ADF4 0x0002ADF4 0x00000000
None 0x00000258 0x0040114C 0x0002ADF8 0x0002ADF8 -
__vbaUI1I2 - 0x00401150 0x0002ADFC 0x0002ADFC 0x00000000
_CIsqrt - 0x00401154 0x0002AE00 0x0002AE00 0x00000000
EVENT_SINK_QueryInterface - 0x00401158 0x0002AE04 0x0002AE04 0x00000000
__vbaExceptHandler - 0x0040115C 0x0002AE08 0x0002AE08 0x00000000
None 0x000002C7 0x00401160 0x0002AE0C 0x0002AE0C -
None 0x000002C8 0x00401164 0x0002AE10 0x0002AE10 -
__vbaStrToUnicode - 0x00401168 0x0002AE14 0x0002AE14 0x00000000
None 0x0000025E 0x0040116C 0x0002AE18 0x0002AE18 -
_adj_fprem - 0x00401170 0x0002AE1C 0x0002AE1C 0x00000000
_adj_fdivr_m64 - 0x00401174 0x0002AE20 0x0002AE20 0x00000000
None 0x000002CA 0x00401178 0x0002AE24 0x0002AE24 -
None 0x000002CC 0x0040117C 0x0002AE28 0x0002AE28 -
None 0x00000261 0x00401180 0x0002AE2C 0x0002AE2C -
__vbaFPException - 0x00401184 0x0002AE30 0x0002AE30 0x00000000
None 0x000002CD 0x00401188 0x0002AE34 0x0002AE34 -
None 0x0000013F 0x0040118C 0x0002AE38 0x0002AE38 -
__vbaGetOwner3 - 0x00401190 0x0002AE3C 0x0002AE3C 0x00000000
__vbaUbound - 0x00401194 0x0002AE40 0x0002AE40 0x00000000
None 0x00000217 0x00401198 0x0002AE44 0x0002AE44 -
__vbaFileSeek - 0x0040119C 0x0002AE48 0x0002AE48 0x00000000
None 0x00000284 0x004011A0 0x0002AE4C 0x0002AE4C -
None 0x00000219 0x004011A4 0x0002AE50 0x0002AE50 -
_CIlog - 0x004011A8 0x0002AE54 0x0002AE54 0x00000000
__vbaErrorOverflow - 0x004011AC 0x0002AE58 0x0002AE58 0x00000000
__vbaFileOpen - 0x004011B0 0x0002AE5C 0x0002AE5C 0x00000000
__vbaVarLateMemCallLdRf - 0x004011B4 0x0002AE60 0x0002AE60 0x00000000
None 0x00000288 0x004011B8 0x0002AE64 0x0002AE64 -
None 0x0000023A 0x004011BC 0x0002AE68 0x0002AE68 -
__vbaNew2 - 0x004011C0 0x0002AE6C 0x0002AE6C 0x00000000
__vbaInStr - 0x004011C4 0x0002AE70 0x0002AE70 0x00000000
_adj_fdiv_m32i - 0x004011C8 0x0002AE74 0x0002AE74 0x00000000
None 0x0000023C 0x004011CC 0x0002AE78 0x0002AE78 -
_adj_fdivr_m32i - 0x004011D0 0x0002AE7C 0x0002AE7C 0x00000000
__vbaStrCopy - 0x004011D4 0x0002AE80 0x0002AE80 0x00000000
__vbaI4Str - 0x004011D8 0x0002AE84 0x0002AE84 0x00000000
__vbaFreeStrList - 0x004011DC 0x0002AE88 0x0002AE88 0x00000000
_adj_fdivr_m32 - 0x004011E0 0x0002AE8C 0x0002AE8C 0x00000000
_adj_fdiv_r - 0x004011E4 0x0002AE90 0x0002AE90 0x00000000
None 0x00000242 0x004011E8 0x0002AE94 0x0002AE94 -
None 0x00000064 0x004011EC 0x0002AE98 0x0002AE98 -
__vbaVarSetVar - 0x004011F0 0x0002AE9C 0x0002AE9C 0x00000000
__vbaI4Var - 0x004011F4 0x0002AEA0 0x0002AEA0 0x00000000
None 0x000002B1 0x004011F8 0x0002AEA4 0x0002AEA4 -
__vbaLateMemCall - 0x004011FC 0x0002AEA8 0x0002AEA8 0x00000000
__vbaVarAdd - 0x00401200 0x0002AEAC 0x0002AEAC 0x00000000
None 0x00000263 0x00401204 0x0002AEB0 0x0002AEB0 -
__vbaAryLock - 0x00401208 0x0002AEB4 0x0002AEB4 0x00000000
None 0x00000140 0x0040120C 0x0002AEB8 0x0002AEB8 -
__vbaStrComp - 0x00401210 0x0002AEBC 0x0002AEBC 0x00000000
__vbaVarDup - 0x00401214 0x0002AEC0 0x0002AEC0 0x00000000
__vbaStrToAnsi - 0x00401218 0x0002AEC4 0x0002AEC4 0x00000000
None 0x00000141 0x0040121C 0x0002AEC8 0x0002AEC8 -
__vbaFpI2 - 0x00401220 0x0002AECC 0x0002AECC 0x00000000
__vbaFpI4 - 0x00401224 0x0002AED0 0x0002AED0 0x00000000
__vbaVarLateMemCallLd - 0x00401228 0x0002AED4 0x0002AED4 0x00000000
None 0x00000268 0x0040122C 0x0002AED8 0x0002AED8 -
__vbaVarSetObjAddref - 0x00401230 0x0002AEDC 0x0002AEDC 0x00000000
__vbaRecDestructAnsi - 0x00401234 0x0002AEE0 0x0002AEE0 0x00000000
__vbaLateMemCallLd - 0x00401238 0x0002AEE4 0x0002AEE4 0x00000000
_CIatan - 0x0040123C 0x0002AEE8 0x0002AEE8 0x00000000
__vbaAryCopy - 0x00401240 0x0002AEEC 0x0002AEEC 0x00000000
__vbaStrMove - 0x00401244 0x0002AEF0 0x0002AEF0 0x00000000
None 0x0000026A 0x00401248 0x0002AEF4 0x0002AEF4 -
__vbaCastObj - 0x0040124C 0x0002AEF8 0x0002AEF8 0x00000000
__vbaR8IntI4 - 0x00401250 0x0002AEFC 0x0002AEFC 0x00000000
None 0x0000028A 0x00401254 0x0002AF00 0x0002AF00 -
_allmul - 0x00401258 0x0002AF04 0x0002AF04 0x00000000
__vbaVarLateMemCallSt - 0x0040125C 0x0002AF08 0x0002AF08 0x00000000
_CItan - 0x00401260 0x0002AF0C 0x0002AF0C 0x00000000
None 0x00000222 0x00401264 0x0002AF10 0x0002AF10 -
__vbaAryUnlock - 0x00401268 0x0002AF14 0x0002AF14 0x00000000
_CIexp - 0x0040126C 0x0002AF18 0x0002AF18 0x00000000
__vbaFreeObj - 0x00401270 0x0002AF1C 0x0002AF1C 0x00000000
__vbaFreeStr - 0x00401274 0x0002AF20 0x0002AF20 0x00000000
None 0x00000244 0x00401278 0x0002AF24 0x0002AF24 -
None 0x00000245 0x0040127C 0x0002AF28 0x0002AF28 -
c:\users\rdhj0cnfevzx\appdata\local\temp\~df1bdb3580e40e32b5.tmp Dropped File OLE Compound
Clean
»
MIME Type application/CDFV2
File Size 3.00 KB
MD5 36c8be77b78ab13759b370350a1ec140 Copy to Clipboard
SHA1 d7ee2042299446f2d2cec6a575555a332d6ae379 Copy to Clipboard
SHA256 4952d5fa0af4d1b95327c5d678a10d6d6eb30d8d626a3e363359677b7b043138 Copy to Clipboard
SSDeep 6:rl91bxbt+r+CFQXj9H/79Xa9Xh9XR5+flEij1b5X:rl3b/+PFQjZ/JG7ONEipl Copy to Clipboard
ImpHash -
c:\users\rdhj0cnfevzx\appdata\local\temp\~df4c509acaee2150ca.tmp Dropped File OLE Compound
Clean
»
MIME Type application/CDFV2
File Size 3.00 KB
MD5 9579350d93fea5052cf4f07f138a493b Copy to Clipboard
SHA1 6f137d941ee2e7e333eb936979456bcd4da236a3 Copy to Clipboard
SHA256 0eb899c1a70708712d265e71b5ea38d0f4fdac1816a5b23de7addfb0a050b59d Copy to Clipboard
SSDeep 6:rl91bxbt+r+CFQXOcSl/79Xa9Xh9XR5+flEij1b5X:rl3b/+PFQ5Sl/JG7ONEipl Copy to Clipboard
ImpHash -
c:\users\rdhj0cnfevzx\appdata\local\temp\~df1f57c1e1876985af.tmp Dropped File OLE Compound
Clean
»
MIME Type application/CDFV2
File Size 3.00 KB
MD5 1fb9e0ff85272e1288efeccedb3cc92b Copy to Clipboard
SHA1 2343eaed7ca338b37a26d57b6cda9ca997b75158 Copy to Clipboard
SHA256 021302413d88eeaa6acbf7383cd01b61be61a7c3de0c3fd3cc00baf2c02a8423 Copy to Clipboard
SSDeep 6:rl91bxbt+r+CFQXo//79Xa9Xh9XR5+flEij1b5X:rl3b/+PFQo/JG7ONEipl Copy to Clipboard
ImpHash -
c:\users\rdhj0cnfevzx\appdata\local\temp\~df3fb37a4d0b549425.tmp Dropped File OLE Compound
Clean
»
MIME Type application/CDFV2
File Size 3.00 KB
MD5 7485b7b5c8e9fc377dc0527a7d9fc647 Copy to Clipboard
SHA1 35a4f65db784ea684f6dac03ef6fb40699d834a6 Copy to Clipboard
SHA256 c167a8c78fcd60493fdb3775c7569aba4eb4e7d19e8f12e79dccc9ec92e7c8ac Copy to Clipboard
SSDeep 6:rl91bxbt+r+CFQX6vVl/79Xa9Xh9XR5+flEij1b5X:rl3b/+PFQ+P/JG7ONEipl Copy to Clipboard
ImpHash -
C:\Users\RDhJ0CNFevzX\AppData\Roaming\Microsoft\Windows\Templates\credentials.txt Dropped File Text
Clean
»
MIME Type text/plain
File Size 498 Bytes
MD5 0264abf84e2544030b01ba864d8421ce Copy to Clipboard
SHA1 4927a0b2c976b94d5f98ee26c5a0838584dcec24 Copy to Clipboard
SHA256 e932ff9f2a1c19c11c8876ef047a1485e51401cda4bbda71bedda49da312be79 Copy to Clipboard
SSDeep 12:FGV+shTAoAyEZYp6kCmZH9Oyp9LIAQHyxFHmizo5t9:FC5s09CmZH8ypWfwFGisJ Copy to Clipboard
ImpHash -
c:\users\rdhj0cnfevzx\appdata\local\temp\~df4017a6edb0510c97.tmp Dropped File Empty
Clean
»
MIME Type application/x-empty
File Size 0 Bytes
MD5 d41d8cd98f00b204e9800998ecf8427e Copy to Clipboard
SHA1 da39a3ee5e6b4b0d3255bfef95601890afd80709 Copy to Clipboard
SHA256 e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855 Copy to Clipboard
SSDeep 3:: Copy to Clipboard
ImpHash -
c:\users\rdhj0cnfevzx\appdata\local\temp\~df6bb2ea749d7dd475.tmp Dropped File Empty
Clean
»
MIME Type application/x-empty
File Size 0 Bytes
MD5 d41d8cd98f00b204e9800998ecf8427e Copy to Clipboard
SHA1 da39a3ee5e6b4b0d3255bfef95601890afd80709 Copy to Clipboard
SHA256 e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855 Copy to Clipboard
SSDeep 3:: Copy to Clipboard
ImpHash -
c:\srvsvc Dropped File Empty
Clean
»
MIME Type application/x-empty
File Size 0 Bytes
MD5 d41d8cd98f00b204e9800998ecf8427e Copy to Clipboard
SHA1 da39a3ee5e6b4b0d3255bfef95601890afd80709 Copy to Clipboard
SHA256 e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855 Copy to Clipboard
SSDeep 3:: Copy to Clipboard
ImpHash -
3a7e473a0ba5b117657193b576f5b98fcf9a428046eb32ef888cc6b953653109 Downloaded File HTML
Clean
»
MIME Type text/html
File Size 1.54 KB
MD5 ea367bdeb6299194ca00cdf5801ee432 Copy to Clipboard
SHA1 42d2945566e43bcfebe999cce764f686a60947ed Copy to Clipboard
SHA256 3a7e473a0ba5b117657193b576f5b98fcf9a428046eb32ef888cc6b953653109 Copy to Clipboard
SSDeep 24:hY6svD+6zSU6pedQf3Zvcn1BZdAe1nCr1LTHI5z8xTQS8f:3qD+2+pUAew85zsTHA Copy to Clipboard
ImpHash -
4cdfc3d4e60ada2c4c309c7510e95321d476a6a227b50f787406ea6fbcfe0ba7 Downloaded File Unknown
Clean
»
MIME Type application/json
File Size 506 Bytes
MD5 9ed341de80c72528555c9dc4f1b277f2 Copy to Clipboard
SHA1 e8a3d7f3a39fb77daf12db1c3ecf9f9ea1df4d1f Copy to Clipboard
SHA256 4cdfc3d4e60ada2c4c309c7510e95321d476a6a227b50f787406ea6fbcfe0ba7 Copy to Clipboard
SSDeep 12:YKOHu/PsTUCp76pQJ4ZP8JVyqWEiOqft9JDMm0TBsge1ic4ZV:YKOHnTDJJg8JVyqW9bV9JQmys4c4P Copy to Clipboard
ImpHash -
b14bcf7e766be0d5ea1f045fa63bc03a3d5c18687539e66f42a3051e5ea8d0af Downloaded File Text
Clean
»
MIME Type text/plain
File Size 14 Bytes
MD5 3ef2dc2ead803750e71a9e1aa2cdc958 Copy to Clipboard
SHA1 7098b9a4017107563f330678349c8e80b8e10ae6 Copy to Clipboard
SHA256 b14bcf7e766be0d5ea1f045fa63bc03a3d5c18687539e66f42a3051e5ea8d0af Copy to Clipboard
SSDeep 3:eubLXj:euLXj Copy to Clipboard
ImpHash -
c:\users\rdhj0cnfevzx\appdata\local\microsoft\windows\inetcache\counters.dat Modified File Stream
Clean
»
MIME Type application/octet-stream
File Size 128 Bytes
MD5 cc90851958032b8c8bbb7b24ec6271dd Copy to Clipboard
SHA1 e027ad2ea4049374a3b01af2e3626b667dc816bc Copy to Clipboard
SHA256 c2d814a34b184b7cdf10e4e7a4311ff15db99326d6dd8d328b53bf9e19ccf858 Copy to Clipboard
SSDeep 3:Fl: Copy to Clipboard
ImpHash -
Function Logfile
Exit-Icon

This feature requires an online-connection to the VMRay backend.

An offline version with limited functionality is also provided.
The offline version is supported only in Mozilla Firefoxwith deactivated setting \"security.fileuri.strict_origin_policy\".


    
Before

This feature requires an online-connection to the VMRay backend.

An offline version with limited functionality is also provided.
The offline version is supported only in Mozilla Firefoxwith deactivated setting \"security.fileuri.strict_origin_policy\".


    
After

This feature requires an online-connection to the VMRay backend.

An offline version with limited functionality is also provided.
The offline version is supported only in Mozilla Firefoxwith deactivated setting \"security.fileuri.strict_origin_policy\".


    
Screenshot
Expand-Icon
Exit-Icon
icon_left
icon_left
image