Static | ZeroBOX

PE Compile Time

2009-06-25 21:39:00

PE Imphash

6b2c11cfb39c06809475cfa1f065a769

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x0003347c 0x00034000 4.68888726507
.data 0x00035000 0x00000c60 0x00001000 0.0
.rsrc 0x00036000 0x00000950 0x00001000 2.58436840751

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x000363e8 0x00000568 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_GROUP_ICON 0x000363d4 0x00000014 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_VERSION 0x000360f0 0x000002e4 LANG_CHINESE SUBLANG_CHINESE_TRADITIONAL data

Imports

Library MSVBVM60.DLL:
0x401000 None
0x401004 _CIcos
0x401008 _adj_fptan
0x40100c __vbaVarMove
0x401010 __vbaFreeVar
0x401014 __vbaAryMove
0x401018 __vbaStrVarMove
0x40101c __vbaFreeVarList
0x401020 _adj_fdiv_m64
0x401024 __vbaFreeObjList
0x401028 _adj_fprem1
0x40102c __vbaRecAnsiToUni
0x401030 None
0x401034 __vbaSetSystemError
0x40103c None
0x401040 _adj_fdiv_m32
0x401044 __vbaAryDestruct
0x401048 None
0x40104c None
0x401050 __vbaOnError
0x401054 __vbaObjSet
0x401058 None
0x40105c _adj_fdiv_m16i
0x401060 None
0x401064 __vbaObjSetAddref
0x401068 _adj_fdivr_m16i
0x40106c None
0x401070 _CIsin
0x401074 __vbaChkstk
0x401078 __vbaFileClose
0x40107c EVENT_SINK_AddRef
0x401080 __vbaStrCmp
0x401084 __vbaAryConstruct2
0x401088 __vbaR4Str
0x40108c __vbaObjVar
0x401090 DllFunctionCall
0x401094 _adj_fpatan
0x401098 None
0x40109c None
0x4010a0 __vbaRedim
0x4010a4 None
0x4010a8 __vbaRecUniToAnsi
0x4010ac EVENT_SINK_Release
0x4010b0 None
0x4010b4 _CIsqrt
0x4010bc __vbaExceptHandler
0x4010c0 _adj_fprem
0x4010c4 _adj_fdivr_m64
0x4010c8 None
0x4010cc __vbaFPException
0x4010d0 __vbaDateVar
0x4010d4 None
0x4010d8 None
0x4010dc _CIlog
0x4010e0 None
0x4010e4 __vbaFileOpen
0x4010e8 __vbaNew2
0x4010ec __vbaVar2Vec
0x4010f0 None
0x4010f4 _adj_fdiv_m32i
0x4010f8 _adj_fdivr_m32i
0x4010fc __vbaStrCopy
0x401100 __vbaFreeStrList
0x401104 None
0x401108 _adj_fdivr_m32
0x40110c _adj_fdiv_r
0x401110 None
0x401114 None
0x401118 __vbaVarTstNe
0x40111c None
0x401120 None
0x401124 None
0x401128 __vbaVarDup
0x40112c __vbaStrToAnsi
0x401130 None
0x401134 __vbaFpI4
0x401138 None
0x40113c _CIatan
0x401140 __vbaStrMove
0x401144 __vbaCastObj
0x401148 _allmul
0x40114c __vbaLateIdSt
0x401150 _CItan
0x401154 None
0x401158 _CIexp
0x40115c None
0x401160 __vbaFreeObj
0x401164 __vbaFreeStr

!This program cannot be run in DOS mode.
`.data
MSVBVM60.DLL
Dsigstd
warrisne
=============
===========
1$===========
2:9==========
0::==========
19:======
.9:=====
3;=====
46/-Q-&
====="<76
======#-,)
======
========
&*!===========
========
warrisne
Combo3
Paracelsi
Combo2
Adresseka
Combo1
Recurvit
Check8
Maypop
Check7
Sorbetss
Check6
Check5
Check4
KOMMEN
Check3
ectocarpa
Check2
Sacrocox
Check1
Afhjemled
Command2
EXCISEM
Command1
VScroll1
HScroll1
Text21
Text22
Text23
Text24
Butikstid5
Text124
Dobbeltlb2
Overgir3
WZAg` 17
:;$4g` n7
2kN&:n
72erSB
!5b0!4
!5b0%4
j:o9S5
!5b({7
jOoU/:
!5,07
:nc!5
!SnfI*
!5jr!7
jvF1CA
!5b8Y4
!5bwASP?
@g` :7
Kg` 7
oPIF3x
!5btpU
!5b :7
;>l-o~
84Ve1_
!5b25=
!5b*1=
!5`:%=
!5b(L4
!5bM$=
j^R|DkG
1v_4T!&
!5`0W7
ddGn` h7
!5`2!=
<"khs%
1d`8x7
KGnj\Y
\c-jvFg
p72)Wn
p|jFAk=g
!5b0}7
}V!+oC
JTyo~
Sht#Sb
<9BSjL<(
!Tb]$5
{ {G4!
!SjJk
!5oIIE~
jG,*Al
!5b v7
-K!w%5
skJg:n~
RjG.HP
~,kL-b`
<du2e
r_jGN0
[:yUZx
vAE<jRu
"mJFW/
)9b+'\D
k1`887
jKw~3[
:w%5oI
!5brvSn~
SjL6db
!@*w%5
,\"^E>
iI?$eJh
:QT>:i
~i)wj_
?SF7oQ
ot&yjC
!:o3!5
;>!Sn}
)vb(R4
:>r3hv+
<r3ona
U c0I4
j\7q:nr
R:=Gom
!5b a7
cKeUo}`vb Q7
OeA.-B
|h_)xbe`
(|h_)}hY
3~:nfR
!S`(-7
J7hu%e
Etttttttttttttttttttttttttttttttttttttttt
slllllllllllllllllllllllllllllllllllllllllllllll
I:$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$
v$aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa
&pppppppppppppppppppppppppppppppppppppppppppppppppppp
jjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjj5
hLOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOO
sYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYY
UUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUU
Z ????????????????????????????????????????????????
e))))))))))))))))))))))))))))))))))))))))))))))))))))))
uuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuu
g<jKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKK
JJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJ
?hhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhh
KAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
*RRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRRR
<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<
H1!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!
7Sy!ttttttttttttttttttttttttttttttttttttttttttttttttttt
{]&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&
csssssssssssssssssssssssssssssssssss
SSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSS
,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,
<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<
UJ&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&
,^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
ZJ]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]f
YYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYY
;EEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEE
#x UUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUU
--------------------------------------------------
?""""""""""""""""""""""""""""""""""""""""""""""""""""
???????????????????????????????????????????????????????
:Zt$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$
...........................................
@)))))))))))))))))))))))))))))))))))))))
_____________________________________________________
M^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
$MMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMM
888888888888888888888888888888888888888
H(HHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHH
j@
as2222222222222222222222222222222222222222
T/////////////////////////////////////////////////////
-vvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvv
aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa
8y+qqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqq
<tttttttttttttttttttttttttttttttttttttttttt
B1111111111111111111111111111111111111111111111111
HHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHHH
Crrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrr
n22222222222222222222222222222222222222222222222
2 I
!iiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiI
VB5!6%*
Dsigstd
Beskyt
SUSAAS
showless
Check5
C:\Program Files (x86)\Microsoft Visual Studio\VB98\VB6.OLB
Combo2
Combo3
Combo1
HScroll1
Text124
VScroll1
Overgir3
Text23
Text24
Command1
Text21
Command2
Text22
Check1
Check6
Check7
Check8
Check2
Check3
Check4
UnregisterClassA
winmm.dll
kernel32
GetTapeParameters
user32
SetLastErrorEx
GetWindowTextA
mmioSeek
WindowFromPoint
SetPixelV
VDMDBG.dll
VDMEnumProcessWOW
SetWindowWord
CreateDCA
GetObjectA
PathToRegion
SetTextColor
shell32.dll
ShellExecuteA
ClipCursor
HideCaret
IPHlpApi
GetNetworkParams
AdjustWindowRectEx
Netapi32.dll
NetShareGetInfo
advapi32.dll
RegQueryValueExA
CryptGenKey
GetAsyncKeyState
CreateCompatibleBitmap
shlwapi.dll
PathMakePrettyA
midiOutShortMsg
Tendensdigtningens7
VBA6.DLL
__vbaRedim
__vbaVarTstNe
__vbaAryConstruct2
__vbaAryDestruct
__vbaFreeObjList
__vbaFileClose
__vbaObjVar
__vbaLateIdSt
__vbaObjSetAddref
__vbaCastObj
__vbaStrVarMove
__vbaStrCopy
__vbaFreeVar
__vbaFreeStrList
__vbaRecAnsiToUni
__vbaRecUniToAnsi
__vbaVar2Vec
__vbaAryMove
__vbaFileOpen
__vbaObjSet
__vbaOnError
__vbaFreeStr
__vbaStrToAnsi
__vbaSetSystemError
__vbaStrCmp
__vbaFreeVarList
__vbaVarDup
__vbaDateVar
__vbaFpI4
__vbaR4Str
__vbaFreeObj
__vbaHresultCheckObj
__vbaNew2
__vbaStrMove
__vbaVarMove
Tabooed1
TRANSFORMATIONER
MISRHYME
} jDhX
} j8hl
} j@hl
} j@hl
} jDhl
} j8hl
} jDhl
MSVBVM60.DLL
_CIcos
_adj_fptan
__vbaVarMove
__vbaFreeVar
__vbaAryMove
__vbaStrVarMove
__vbaFreeVarList
_adj_fdiv_m64
__vbaFreeObjList
_adj_fprem1
__vbaRecAnsiToUni
__vbaSetSystemError
__vbaHresultCheckObj
_adj_fdiv_m32
__vbaAryDestruct
__vbaOnError
__vbaObjSet
_adj_fdiv_m16i
__vbaObjSetAddref
_adj_fdivr_m16i
_CIsin
__vbaChkstk
__vbaFileClose
EVENT_SINK_AddRef
__vbaStrCmp
__vbaAryConstruct2
__vbaR4Str
__vbaObjVar
DllFunctionCall
_adj_fpatan
__vbaRedim
__vbaRecUniToAnsi
EVENT_SINK_Release
_CIsqrt
EVENT_SINK_QueryInterface
__vbaExceptHandler
_adj_fprem
_adj_fdivr_m64
__vbaFPException
__vbaDateVar
_CIlog
__vbaFileOpen
__vbaNew2
__vbaVar2Vec
_adj_fdiv_m32i
_adj_fdivr_m32i
__vbaStrCopy
__vbaFreeStrList
_adj_fdivr_m32
_adj_fdiv_r
__vbaVarTstNe
__vbaVarDup
__vbaStrToAnsi
__vbaFpI4
_CIatan
__vbaStrMove
__vbaCastObj
_allmul
__vbaLateIdSt
_CItan
_CIexp
__vbaFreeObj
__vbaFreeStr
=============
===========
1$===========
2:9==========
0::==========
19:======
.9:=====
3;=====
46/-Q-&
====="<76
======#-,)
======
========
&*!===========
========
C:\Program Files (x86)\Administrator-Cloud\Projects\AVEN.pdb
.DkHf
Crunodes1
Milita51
BEGIRDLE1
beltrans1
refor1"0
HERMENEUT@Klausu.SK0
210809233611Z
220809233611Z0
Crunodes1
Milita51
BEGIRDLE1
beltrans1
refor1"0
HERMENEUT@Klausu.SK0
@,EBg(]
Crunodes1
Milita51
BEGIRDLE1
beltrans1
refor1"0
HERMENEUT@Klausu.SK
20210809233624Z
DigiCert Inc1
www.digicert.com110/
(DigiCert SHA2 Assured ID Timestamping CA0
210101000000Z
310106000000Z0H1
DigiCert, Inc.1 0
DigiCert Timestamp 20210
http://www.digicert.com/CPS0
,http://crl3.digicert.com/sha2-assured-ts.crl02
,http://crl4.digicert.com/sha2-assured-ts.crl0
http://ocsp.digicert.com0O
Chttp://cacerts.digicert.com/DigiCertSHA2AssuredIDTimestampingCA.crt0
QJxy6z'
dwc_#Ri
DigiCert Inc1
www.digicert.com1$0"
DigiCert Assured ID Root CA0
160107120000Z
310107120000Z0r1
DigiCert Inc1
www.digicert.com110/
(DigiCert SHA2 Assured ID Timestamping CA0
fnVa')
http://ocsp.digicert.com0C
7http://cacerts.digicert.com/DigiCertAssuredIDRootCA.crt0
4http://crl4.digicert.com/DigiCertAssuredIDRootCA.crl0:
4http://crl3.digicert.com/DigiCertAssuredIDRootCA.crl0P
https://www.digicert.com/CPS0
8aMbF$
V3"/"6
DigiCert Inc1
www.digicert.com110/
(DigiCert SHA2 Assured ID Timestamping CA
210809233624Z0+
/1(0&0$0"
Whooping
KUNSTAKADEMIS
Rebounds
Socialiseringslovene
shuddered
BROCHERES
Blinddrenes
beecham
staserne
Ingenlunde6
Afarternes
gospellers
fendable
Bagenden
sorglseste
SOMALIA
Gstfriestes
Byvaabnets
DIODES
Fodstykker
Thyreoiditis8
Strandfogdens
Succesombrust6
Hensttelsers4
DISKETTETYPE
Spiralbund4
hyperscholastic
saberlikes
sidemen
TVESPROGEDES
Feltstrukturen1
argent
EJNERT
treklangens
Huanaco7
reciprocation
Langlaufer1
Insuror
Manufaction
SEMIOXYGENIZED
SEKTIONERINGENS
BETTOR
petroleous
FALSKNERIETS
TORNEKRONERNE
Troskabslfters6
Unnullified4
neurectopia
ANTIRACEMATE
extroversion
Unexculpable
Ejendomserhvervelsernes
NONGRANULAR
megophthalmus
Estella
UNDERVISNINGSMINISTERIET
RAKLER
SUKKET
publiceredes
HOSTEANFALDS
indsugende
FORAARSJVNDGN
REPARABLE
Tylaster
Smdevisen8
foreshroud
Floppily
Happily6
yardwork
jttestuen
revalue
Teknologiarbejdes4
Unsadden
Photogeologic
Sandblsnings5
Paraxonic
Erechtites4
Niaars6
lagdelings
afpilnings
Thermopolymerisation8
Subshrub7
Uddybning7
politicalises
PREDETACH
overheadprojektors
MYOENOTOMY
OPSUMMERENDES
HAELDNING
utilbjeligheden
Brachiolaria4
Roomful4
udviklingsomraadet
Rehone1
Decernment8
svovlpls
blimbing
PELARGONIERS
KURSUSCENTRENE
Morpholoical
palstaff
STADSESTUERNE
FORFINELSERS
Forsorgshjem
deutzia
Demagogiske7
Tapacolo
Ureteralgia5
STANNANE
sheepbacks
Conductimeter
streptokokken
Henziz
ELLEVEAARSBARN
Annlisas
scaffy
Sinistration6
Deodorant
psilophyte
Odinite
Arrestants8
slesviger
Simplere6
Funariaceous
Spoilless6
RESTSTRAFFES
Folkefronts
SUNROOFS
VELSETE
Bissekrmmer
Amningsmrker8
Womanways
Vermiculites
ALCAID
unarbitrative
dowelling
Outwearies
Triplewise9
Bevidstlst4
hyldetrer
tankestregen
miljadministrationerne
Ditrichotomous
baptistries
contrayerva
Festucine5
stukkaturens
Drammer
Brefrekvenserne
Synkrosvmninger4
DYBBJERGARTEN
Opkber7
Vurderingsformens
achime
TVANGSAUKTIONSTEMAERNES
LIGNINGSRAADETS
salderendes
ysettes
MINIPRICE
claroes
Undebilitated3
strepsis
Automatiserendes
chartrooms
tsedrengenes
statsrets
Skrotnings7
Antacid8
SOFTDRINK
HOLORHINAL
Behaviouristics3
Afviklingsforlbene8
klinikassistenterne
caffeinism
Portmanmote
Chignonen6
Brandlov
Iwwort9
RADIOSENSIBILITY
Vander9
SERVANTLIKE
fattily
KNTREFRI
ORGANOIRON
Micropylar
Skvalderhovederne
Nondenunciation
Patroonship
SVANGERSKABSFOREBYGGENDE
DEREISM
scopoletin
HANEGAL
ABROMA
Aggrievedness7
Atmosfaere5
preoccupations
CONIFEROPHYTE
irregenerate
Antipyrinet
Genera9
wannigans
Overgrievous
Kolonialhandlere
purposivist
Blinklygten
Berkeleys
Cichoriaceous
ALMENEJE
homotypic
Rekhti
afstandene
Kartoffelmelsfabrik
SOLIDARITETSFLELSENS
labiate
Kiluba
memorizes
Fortvivledes
Eucharist7
tetralophodont
vismndene
Carpintero
OFELIA
coated
Erhversretligt5
SKNNEDE
arbejdsministeriets
STAMPUBLIKUMERS
tarvelighed
paginaens
brystkasses
zooglea
WENDIE
Pharyngomaxillary5
NONPREPARATIVE
Billedtppernes6
Preachman
SELVBYGGERHUSET
Krluld
beachlamar
Dismalise5
VIANDER
BIPOROSE
Eksterirernes
JORDFSTENDE
Tastebuds
Aktieskat
Toldsats8
centraliserer
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
040404B0
Comments
Gillammes
CompanyName
Gillammes
FileDescription
Gillammes
LegalCopyright
Gillammes
LegalTrademarks
Gillammes
ProductName
Gillammes
FileVersion
ProductVersion
InternalName
OriginalFilename
AVEN.exe
Antivirus Signature
Bkav Clean
Lionic Clean
Elastic malicious (high confidence)
MicroWorld-eScan Clean
FireEye Generic.mg.8056c1da01723959
CAT-QuickHeal Clean
McAfee Clean
Cylance Unsafe
VIPRE Clean
Sangfor Trojan.Win32.Save.a
K7AntiVirus Clean
BitDefender Clean
K7GW Clean
CrowdStrike win/malicious_confidence_70% (W)
Baidu Clean
Cyren Clean
Symantec Clean
ESET-NOD32 Clean
APEX Malicious
Paloalto Clean
ClamAV Clean
Kaspersky Clean
Alibaba Clean
NANO-Antivirus Clean
ViRobot Clean
Rising Clean
Ad-Aware Clean
Emsisoft Clean
Comodo Clean
F-Secure Clean
DrWeb Clean
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition Clean
CMC Clean
Sophos ML/PE-A
Ikarus Clean
GData Clean
Jiangmin Clean
MaxSecure Trojan.Malware.300983.susgen
Avira Clean
MAX Clean
Antiy-AVL Clean
Kingsoft Clean
Gridinsoft Clean
Arcabit Clean
SUPERAntiSpyware Clean
ZoneAlarm Clean
Microsoft Clean
Cynet Malicious (score: 100)
AhnLab-V3 Clean
Acronis Clean
BitDefenderTheta Gen:NN.ZevbaF.34058.om1@a0NF2lkb
ALYac Clean
TACHYON Clean
VBA32 Clean
Malwarebytes Clean
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Tencent Clean
Yandex Clean
SentinelOne Static AI - Suspicious PE
eGambit Unsafe.AI_Score_99%
Fortinet Clean
Webroot Clean
Cybereason Clean
Avast Clean
Qihoo-360 Clean
No IRMA results available.