295876

VB6 runtime API dispatchVB6 DllFunctionCall thunk
SHA-256c0c47a6899f619cf73edc8af9ddc97a620fe2a4f6573a1bd88d35277a2f54ad5

Evidence

VB6 DllFunctionCall thunk 0x1068–0x10d8
0x1068e26fa272b97da272ea62a372fb7da272.o.r.}.r.b.r.}.r
0x1078749ba072f697a4724150a172fda09472t..r...rAP.r...r
0x1088f609a3720ac3a1725db7a172e06aa372...r...r]..r.j.r
0x1098879ba0729395a3728995a472859aa072...r...r...r...r
0x10a8df47a2721dbfa0728906a372ba03a372.G.r...r...r...r
0x10b81375a472214ea272f753a1722b94a372.u.r!N.r.S.r+..r
0x10c867e8a07237a2a1723a03a3723a04a372g..r7..r:..r:..r
0x10d84a6ca272a3 Jl.r.
.dll extension reference 0x24d7–0x2507
0x24d7ffe00000000c0000006d737666773332.........msvfw32
0x24e72e646c6c000e00000044726177313644.dll.....Draw16D
0x24f7696244726177000000e0244000f02440ibDraw....$@..$@
0x250700000004 ....
version word (lowercase) 0x2d5d–0x2d8d
0x2d5d003a00200000001c000000460069006c.:. .......F.i.l
0x2d6d0065002000760065007200730069006f.e. .v.e.r.s.i.o
0x2d7d006e003a002000000000002200000050.n.:. ....."...P
0x2d8d0072006f006400 .r.o.d.
Encoded payload detected: xor 0xa2cd2–0xa2d22
0xa2cd200000000000000000000000078000000............x...
0xa2ce2e6d7d1d8baafe8c3b6efc8baefc8baef................
0xa2cf2c7b8efc6b7efc6b7efc5b6efc5b5efc5................
0xa2d02b4efc4b4efc3b3efc3b2efc2b1efc1b0................
0xa2d12efc1b0efc1afefc0aeefc0aeefbfadef................
0xa2d22bfadefbfadefbeacefbeabefbeab ..............
PE version resource structure 0xa9176–0xa91a6
0xa917600000000000000000000080334000000............4...
0xa9186560053005f0056004500520053004900V.S._.V.E.R.S.I.
0xa91964f004e005f0049004e0046004f000000O.N._.I.N.F.O...
0xa91a60000bd04effe000001000400070000 ...............

Keyboard shortcuts on this page: j for the next sample, k for the previous one, x to go back to the feed, d to download the original bytes, r to re-queue the sample for analysis.