| filename | ef45.fcb | |
|---|---|---|
| size | 162416 (0x27a70) | |
| md5 | 85c0e28cc724f839016fba5b73d2a206 | |
| type | PE32 executable (GUI) Intel 80386, for MS Windows | |
| mimetype | application/x-dosexec | |
| clamav | OK | |
| virustotal | → scan with virustotal.com | |
| histogram | ||
MZ Header
| signature | MZ |
| bytes_in_last_block | 0x90 |
| blocks_in_file | 3 |
| num_relocs | 0 |
| header_paragraphs | 4 |
| min_extra_paragraphs | 0 |
| max_extra_paragraphs | 0 |
| ss | 0 |
| sp | 0xb8 |
| checksum | 0 |
| ip | 0 |
| cs | 0 |
| reloc_table_offset | 0x40 |
| overlay_number | 0 |
| reserved0 | 0 |
| oem_id | 0 |
| oem_info | 0 |
| reserved2 | 0 |
| reserved3 | 0 |
| reserved4 | 0 |
| reserved5 | 0 |
| reserved6 | 0 |
| lfanew | 0xc8 |
DOS stub
00000000: 0e 1f ba 0e 00 b4 09 cd 21 b8 01 4c cd 21 54 68 |........!..L.!Th| 00000010: 69 73 20 70 72 6f 67 72 61 6d 20 63 61 6e 6e 6f |is program canno| 00000020: 74 20 62 65 20 72 75 6e 20 69 6e 20 44 4f 53 20 |t be run in DOS | 00000030: 6d 6f 64 65 2e 0d 0d 0a 24 00 00 00 00 00 00 00 |mode....$.......| 00000040: 5d fb c7 da 19 9a a9 89 19 9a a9 89 19 9a a9 89 |]...............| 00000050: 9a 86 a7 89 18 9a a9 89 70 85 a0 89 1c 9a a9 89 |........p.......| 00000060: f0 85 a4 89 18 9a a9 89 72 69 63 68 19 9a a9 89 |........rich....| 00000070: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 |................| 00000080: 00 00 00 00 00 00 00 00 |........ |
PE Header
Packer / Compiler
Sections
| name | va | vsize | raw size | flags | |
|---|---|---|---|---|---|
| .text | 0x1000 | 0x9c15 | 0xa000 | R-X CODE | |
| .data | 0xb000 | 0x2100 | 0x1000 | RW- IDATA | |
| .rsrc p | 0xe000 | 0x89b | 0x600 | R-- IDATA |
Data Directory
| module_name | hint | ord | function_name |
|---|---|---|---|
| MSVBVM60.DLL | __vbaVarSub | ||
| MSVBVM60.DLL | 4 | __vbaStrI2 | |
| MSVBVM60.DLL | 2 | _CIcos | |
| MSVBVM60.DLL | 1 | _adj_fptan | |
| MSVBVM60.DLL | 3 | __vbaVarMove | |
| MSVBVM60.DLL | 3 | __vbaAryMove | |
| MSVBVM60.DLL | 4 | __vbaFreeVar | |
| MSVBVM60.DLL | 3 | __vbaLateIdCall | |
| MSVBVM60.DLL | 3 | __vbaStrVarMove | |
| MSVBVM60.DLL | 3 | __vbaLineInputStr | |
| MSVBVM60.DLL | 3 | __vbaLenBstr | |
| MSVBVM60.DLL | 4 | __vbaFreeVarList | |
| MSVBVM60.DLL | 1 | _adj_fdiv_m64 | |
| MSVBVM60.DLL | 3 | __vbaFreeObjList | |
| MSVBVM60.DLL | 135 | _adj_fprem1 | |
| MSVBVM60.DLL | 3 | __vbaStrCat | |
| MSVBVM60.DLL | 4 | __vbaSetSystemError | |
| MSVBVM60.DLL | 135 | __vbaHresultCheckObj | |
| MSVBVM60.DLL | 3 | __vbaLenVar | |
| MSVBVM60.DLL | 1 | _adj_fdiv_m32 | |
| MSVBVM60.DLL | 3 | __vbaAryVar | |
| MSVBVM60.DLL | 3 | __vbaAryDestruct | |
| MSVBVM60.DLL | 3 | __vbaVarForInit | |
| MSVBVM60.DLL | 3 | __vbaObjSet | |
| MSVBVM60.DLL | 595 | ||
| MSVBVM60.DLL | 135 | _adj_fdiv_m16i | |
| MSVBVM60.DLL | 3 | __vbaObjSetAddref | |
| MSVBVM60.DLL | 4 | _adj_fdivr_m16i | |
| MSVBVM60.DLL | 1 | _CIsin | |
| MSVBVM60.DLL | 631 | ||
| MSVBVM60.DLL | 3 | __vbaChkstk | |
| MSVBVM60.DLL | 526 | ||
| MSVBVM60.DLL | 4 | __vbaFileClose | |
| MSVBVM60.DLL | EVENT_SINK_AddRef | ||
| MSVBVM60.DLL | 3 | __vbaGenerateBoundsError | |
| MSVBVM60.DLL | 3 | __vbaGet3 | |
| MSVBVM60.DLL | 3 | __vbaVarTstEq | |
| MSVBVM60.DLL | 3 | __vbaI2I4 | |
| MSVBVM60.DLL | DllFunctionCall | ||
| MSVBVM60.DLL | 135 | _adj_fpatan | |
| MSVBVM60.DLL | 4 | __vbaLateIdCallLd | |
| MSVBVM60.DLL | 3 | __vbaRedim | |
| MSVBVM60.DLL | EVENT_SINK_Release | ||
| MSVBVM60.DLL | 4 | __vbaUI1I2 | |
| MSVBVM60.DLL | 4 | _CIsqrt | |
| MSVBVM60.DLL | EVENT_SINK_QueryInterface | ||
| MSVBVM60.DLL | 3 | __vbaUI1I4 | |
| MSVBVM60.DLL | 3 | __vbaExceptHandler | |
| MSVBVM60.DLL | 711 | ||
| MSVBVM60.DLL | 3 | __vbaStrToUnicode | |
| MSVBVM60.DLL | 712 | ||
| MSVBVM60.DLL | 3 | __vbaPrintFile | |
| MSVBVM60.DLL | 606 | ||
| MSVBVM60.DLL | 135 | _adj_fprem | |
| MSVBVM60.DLL | 4 | _adj_fdivr_m64 | |
| MSVBVM60.DLL | 3 | __vbaFPException | |
| MSVBVM60.DLL | 717 | ||
| MSVBVM60.DLL | 3 | __vbaStrVarVal | |
| MSVBVM60.DLL | 3 | __vbaVarCat | |
| MSVBVM60.DLL | 644 | ||
| MSVBVM60.DLL | 1 | _CIlog | |
| MSVBVM60.DLL | 3 | __vbaErrorOverflow | |
| MSVBVM60.DLL | 3 | __vbaFileOpen | |
| MSVBVM60.DLL | 4 | __vbaVar2Vec | |
| MSVBVM60.DLL | 3 | __vbaInStr | |
| MSVBVM60.DLL | 3 | __vbaNew2 | |
| MSVBVM60.DLL | 648 | ||
| MSVBVM60.DLL | 571 | ||
| MSVBVM60.DLL | 1 | _adj_fdiv_m32i | |
| MSVBVM60.DLL | 1 | _adj_fdivr_m32i | |
| MSVBVM60.DLL | 4 | __vbaStrCopy | |
| MSVBVM60.DLL | 3 | __vbaFreeStrList | |
| MSVBVM60.DLL | 4 | _adj_fdivr_m32 | |
| MSVBVM60.DLL | 1 | _adj_fdiv_r | |
| MSVBVM60.DLL | 578 | ||
| MSVBVM60.DLL | 100 | ||
| MSVBVM60.DLL | 3 | __vbaVarTstNe | |
| MSVBVM60.DLL | 3 | __vbaI4Var | |
| MSVBVM60.DLL | 4 | __vbaAryLock | |
| MSVBVM60.DLL | 3 | __vbaVarAdd | |
| MSVBVM60.DLL | 3 | __vbaStrToAnsi | |
| MSVBVM60.DLL | 3 | __vbaVarDup | |
| MSVBVM60.DLL | 3 | __vbaVarCopy | |
| MSVBVM60.DLL | 1 | _CIatan | |
| MSVBVM60.DLL | 3 | __vbaAryCopy | |
| MSVBVM60.DLL | 3 | __vbaUI1Str | |
| MSVBVM60.DLL | 4 | __vbaStrMove | |
| MSVBVM60.DLL | 3 | __vbaStrVarCopy | |
| MSVBVM60.DLL | 1 | _allmul | |
| MSVBVM60.DLL | 1 | _CItan | |
| MSVBVM60.DLL | 546 | ||
| MSVBVM60.DLL | 4 | __vbaAryUnlock | |
| MSVBVM60.DLL | 3 | __vbaVarForNext | |
| MSVBVM60.DLL | 1 | _CIexp | |
| MSVBVM60.DLL | 3 | __vbaFreeObj | |
| MSVBVM60.DLL | 3 | __vbaFreeStr |
No certificates in
undefined method `type' for nil:NilClass
No certificates in
undefined method `type' for nil:NilClass
No certificates in
undefined method `type' for nil:NilClass
No certificates in
undefined method `type' for nil:NilClass
No certificates in
undefined method `type' for nil:NilClass
No certificates in
undefined method `type' for nil:NilClass
No certificates in
undefined method `type' for nil:NilClass
No certificates in
undefined method `type' for nil:NilClass
No certificates in
undefined method `type' for nil:NilClass
No certificates in
undefined method `type' for nil:NilClass
No certificates in
undefined method `type' for nil:NilClass
No certificates in
undefined method `type' for nil:NilClass
No certificates in
undefined method `type' for nil:NilClass
No certificates in
undefined method `type' for nil:NilClass
Cannot call to_der on
undefined method `type' for nil:NilClass
Scanning the drive for archives: 1 file, 162416 bytes (159 KiB) Errors: 1
![]() |
| Please donate some bucks to keep this site up and running: | |
| Ko-fi | |
|---|---|
| Yandex.Money | |
| Thank you! | |
[!] PEdump::IMAGE_RESOURCE_DIRECTORY: 36865 entries in directory, but got EOF on 14128-th.
[!] PEdump::IMAGE_RESOURCE_DIRECTORY: loop3 detected at file pos 49216
[!] PEdump::IMAGE_RESOURCE_DIRECTORY: loop3 detected at file pos 49464
[!] PEdump::IMAGE_RESOURCE_DIRECTORY: loop3 detected at file pos 49912
[!] PEdump::IMAGE_RESOURCE_DIRECTORY: loop3 detected at file pos 49472
[!] PEdump::IMAGE_RESOURCE_DIRECTORY: loop3 detected at file pos 114704
[!] PEdump::IMAGE_RESOURCE_DIRECTORY: loop3 detected at file pos 49169
[!] PEdump::IMAGE_RESOURCE_DIRECTORY: loop3 detected at file pos 49284
[!] PEdump::IMAGE_RESOURCE_DIRECTORY: loop3 detected at file pos 49278
[!] PEdump::IMAGE_RESOURCE_DIRECTORY: loop3 detected at file pos 49200
[!] PEdump::IMAGE_RESOURCE_DIRECTORY: loop3 detected at file pos 114703
[!] PEdump::IMAGE_RESOURCE_DIRECTORY: loop3 detected at file pos 53200
[!] PEdump::IMAGE_RESOURCE_DIRECTORY: loop3 detected at file pos 114647
[!] PEdump::IMAGE_RESOURCE_DIRECTORY: loop3 detected at file pos 49232
[!] PEdump::IMAGE_RESOURCE_DIRECTORY: loop3 detected at file pos 48906
[!] PEdump::IMAGE_RESOURCE_DIRECTORY: loop3 detected at file pos 49153
[!] PEdump::IMAGE_RESOURCE_DIRECTORY: loop3 detected at file pos 49304
[!] PEdump::IMAGE_RESOURCE_DIRECTORY: loop3 detected at file pos 49406
[?] too many errors getting resource data, stopped on 194 of 14128
[!] PEdump::IMAGE_RESOURCE_DIRECTORY: loop3 detected at file pos 49376
[?] too many errors getting resource data, stopped on 0 of 1
[!] PEdump::IMAGE_RESOURCE_DIRECTORY: loop3 detected at file pos 49416
[?] too many errors getting resource data, stopped on 2 of 3
[!] PEdump::IMAGE_RESOURCE_DIRECTORY: loop3 detected at file pos 49416
[?] too many errors getting resource data, stopped on 1 of 3
[?] can't find file_offset of VA 0xe7b4
[?] can't find file_offset of VA 0x420034
[?] can't find file_offset of VA 0x0
[?] can't find file_offset of VA 0x2e0031
[?] can't find file_offset of VA 0x4b0
[?] can't find file_offset of VA 0xf34ac318
[?] can't find file_offset of VA 0x67000000
[?] can't find file_offset of VA 0x4ffef367
[?] can't find file_offset of VA 0x530052
[?] can't find file_offset of VA 0x800000c8
[?] can't find file_offset of VA 0x75328000
[?] can't find file_offset of VA 0x442bf34a
[?] can't find file_offset of VA 0x0
[?] can't find file_offset of VA 0xe803177c
[?] can't find file_offset of VA 0x0
[?] can't find file_offset of VA 0x7ce8e883
[?] can't find file_offset of VA 0x7d65c052
[?] can't find file_offset of VA 0x4b000
[?] can't find file_offset of VA 0x4ac31894
[?] can't find file_offset of VA 0xa74fe8a0
[?] can't find file_offset of VA 0x6e0049
[?] can't find file_offset of VA 0x0
[?] can't find file_offset of VA 0x177c7394
[?] can't find file_offset of VA 0x0
[?] ignoring invalid PEdump::BITMAPINFOHEADER
[!] PEdump::WIN_CERTIFICATE: too small length 0
[!] PEdump::WIN_CERTIFICATE: too small length 1
[!] PEdump::WIN_CERTIFICATE: too small length 0
[!] PEdump::WIN_CERTIFICATE: too small length 1
[!] PEdump::WIN_CERTIFICATE: too small length 0
[!] PEdump::WIN_CERTIFICATE: too big length 6816183
[!] PEdump::WIN_CERTIFICATE: too big length 3271032896
[!] PEdump::WIN_CERTIFICATE: too big length 1501298688
[!] PEdump::WIN_CERTIFICATE: too big length 1003225152
[!] PEdump::WIN_CERTIFICATE: too big length 3407890
[!] PEdump::WIN_CERTIFICATE: too small length 0
[!] PEdump::WIN_CERTIFICATE: too small length 1
[!] PEdump::WIN_CERTIFICATE: too small length 0
[!] PEdump::WIN_CERTIFICATE: too small length 1
[!] PEdump::WIN_CERTIFICATE: too small length 0
[!] PEdump::WIN_CERTIFICATE: too big length 6816183
[!] PEdump::WIN_CERTIFICATE: too big length 3271032896
[!] PEdump::WIN_CERTIFICATE: too big length 1501298688
[!] PEdump::WIN_CERTIFICATE: too big length 1003225152
[!] PEdump::WIN_CERTIFICATE: too big length 3407890
[!] PEdump::WIN_CERTIFICATE: too small length 0
[!] PEdump::WIN_CERTIFICATE: too small length 1
[!] PEdump::WIN_CERTIFICATE: too small length 0
[!] PEdump::WIN_CERTIFICATE: too small length 1
[!] PEdump::WIN_CERTIFICATE: too small length 0
[!] PEdump::WIN_CERTIFICATE: too big length 6816183
[!] PEdump::WIN_CERTIFICATE: too big length 3271032896
[!] PEdump::WIN_CERTIFICATE: too big length 1501298688
[!] PEdump::WIN_CERTIFICATE: too big length 1003225152
[!] PEdump::WIN_CERTIFICATE: too big length 3407890
[!] PEdump::WIN_CERTIFICATE: too small length 0
[!] PEdump::WIN_CERTIFICATE: too small length 1
[!] PEdump::WIN_CERTIFICATE: too small length 0
[!] PEdump::WIN_CERTIFICATE: too small length 1
[!] PEdump::WIN_CERTIFICATE: too small length 0
[!] PEdump::WIN_CERTIFICATE: too big length 6816183
[!] PEdump::WIN_CERTIFICATE: too big length 3271032896
[!] PEdump::WIN_CERTIFICATE: too big length 1501298688
[!] PEdump::WIN_CERTIFICATE: too big length 1003225152
[!] PEdump::WIN_CERTIFICATE: too big length 3407890
[!] PEdump::WIN_CERTIFICATE: too small length 0
[!] PEdump::WIN_CERTIFICATE: too small length 1
[!] PEdump::WIN_CERTIFICATE: too small length 0
[!] PEdump::WIN_CERTIFICATE: too small length 1
[!] PEdump::WIN_CERTIFICATE: too small length 0
[!] PEdump::WIN_CERTIFICATE: too big length 6816183
[!] PEdump::WIN_CERTIFICATE: too big length 3271032896
[!] PEdump::WIN_CERTIFICATE: too big length 1501298688
[!] PEdump::WIN_CERTIFICATE: too big length 1003225152
[!] PEdump::WIN_CERTIFICATE: too big length 3407890
[!] PEdump::WIN_CERTIFICATE: too small length 0
[!] PEdump::WIN_CERTIFICATE: too small length 1
[!] PEdump::WIN_CERTIFICATE: too small length 0
[!] PEdump::WIN_CERTIFICATE: too small length 1
[!] PEdump::WIN_CERTIFICATE: too small length 0
[!] PEdump::WIN_CERTIFICATE: too big length 6816183
[!] PEdump::WIN_CERTIFICATE: too big length 3271032896
[!] PEdump::WIN_CERTIFICATE: too big length 1501298688
[!] PEdump::WIN_CERTIFICATE: too big length 1003225152
[!] PEdump::WIN_CERTIFICATE: too big length 3407890
offset:( 0x )