Static | ZeroBOX

PE Compile Time

2014-11-20 06:08:17

PE Imphash

6b2c11cfb39c06809475cfa1f065a769

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x000334ec 0x00034000 4.69877763651
.data 0x00035000 0x00000c60 0x00001000 0.0
.rsrc 0x00036000 0x00000c98 0x00001000 4.39395830644

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x000363f0 0x000008a8 LANG_NEUTRAL SUBLANG_NEUTRAL dBase IV DBT of @.DBF, block length 1024, next free block index 40, next free block 16777215, next used block 16777215
RT_GROUP_ICON 0x000363dc 0x00000014 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_VERSION 0x000360f0 0x000002ec LANG_CHINESE SUBLANG_CHINESE_TRADITIONAL data

Imports

Library MSVBVM60.DLL:
0x401000 None
0x401004 _CIcos
0x401008 _adj_fptan
0x40100c __vbaVarMove
0x401010 __vbaFreeVar
0x401014 __vbaAryMove
0x401018 __vbaStrVarMove
0x40101c __vbaFreeVarList
0x401020 _adj_fdiv_m64
0x401024 __vbaFreeObjList
0x401028 _adj_fprem1
0x40102c __vbaRecAnsiToUni
0x401030 None
0x401034 __vbaSetSystemError
0x40103c None
0x401040 _adj_fdiv_m32
0x401044 __vbaAryDestruct
0x401048 None
0x40104c None
0x401050 __vbaOnError
0x401054 __vbaObjSet
0x401058 None
0x40105c _adj_fdiv_m16i
0x401060 None
0x401064 __vbaObjSetAddref
0x401068 _adj_fdivr_m16i
0x40106c None
0x401070 _CIsin
0x401074 __vbaChkstk
0x401078 __vbaFileClose
0x40107c EVENT_SINK_AddRef
0x401080 __vbaStrCmp
0x401084 __vbaAryConstruct2
0x401088 __vbaR4Str
0x40108c __vbaObjVar
0x401090 DllFunctionCall
0x401094 _adj_fpatan
0x401098 None
0x40109c None
0x4010a0 __vbaRedim
0x4010a4 None
0x4010a8 __vbaRecUniToAnsi
0x4010ac EVENT_SINK_Release
0x4010b0 None
0x4010b4 _CIsqrt
0x4010bc __vbaExceptHandler
0x4010c0 _adj_fprem
0x4010c4 _adj_fdivr_m64
0x4010c8 None
0x4010cc __vbaFPException
0x4010d0 __vbaDateVar
0x4010d4 None
0x4010d8 None
0x4010dc _CIlog
0x4010e0 None
0x4010e4 __vbaFileOpen
0x4010e8 __vbaNew2
0x4010ec __vbaVar2Vec
0x4010f0 None
0x4010f4 _adj_fdiv_m32i
0x4010f8 _adj_fdivr_m32i
0x4010fc __vbaStrCopy
0x401100 __vbaFreeStrList
0x401104 None
0x401108 _adj_fdivr_m32
0x40110c _adj_fdiv_r
0x401110 None
0x401114 None
0x401118 __vbaVarTstNe
0x40111c None
0x401120 None
0x401124 None
0x401128 __vbaVarDup
0x40112c __vbaStrToAnsi
0x401130 None
0x401134 __vbaFpI4
0x401138 None
0x40113c _CIatan
0x401140 __vbaStrMove
0x401144 __vbaCastObj
0x401148 _allmul
0x40114c __vbaLateIdSt
0x401150 _CItan
0x401154 None
0x401158 _CIexp
0x40115c None
0x401160 __vbaFreeObj
0x401164 __vbaFreeStr

!This program cannot be run in DOS mode.
`.data
MSVBVM60.DLL
Sepultch3
Saccomy9
Gregarin8
@d)!Z
OCuuE]]
tOOOONu
hvwhxyzVs{|{}~
deWfOOOOCg
hijhklmno
CND[\]^_`a6bZ&c
2ANOONPQR
STUVWX
9ABCDEFGHIJKL'M
89:;<=>
%)*+,
 !"#$%&
Gregarin8
Combo3
sknhed
Combo2
Combo1
Check8
Blunder
Check7
Check6
ADSTADIG
Check5
Check4
nonrevert
Check3
Check2
Rillhuddu
Check1
Command2
Indulgi
Command1
VScroll1
HScroll1
erotoge
Text21
UNRUEFULM
Text22
Text23
Text24
Text124
Retsform3
X&b31`P\
fG3tFF
`Afgdx.g
[{`Adz|
Te{f(Ek
DPpp0x,
sd7` n
Oj7` dz<y
5`A8Z)
Q6`A[V
X6`AU$
C7`Adb@
gn3D'Y
8Ln3DV>u
PQAn3D
4_c,_H
'dhf'f
.!\~$f
`A(rp
7`Nk)aA
7`Bh7hA
M6`Af4
Ds7`Af
pNjk>A
=Q3'T)
GaNjF:A
x%68]k
o3kQfsk@)skD
5`A=@%
5`A9;rPn
@zbibA
5`AdiD
7`Nk8aA
n3DR/.b)
`AdJ@y.
#`Afph
e0Wn3D?
7`Nj1hA
;c"R'j
|6`AQK
eNjW"A
7`Adwpy
7`Nj<JA
mhJEx-
7`A>.
7`A-?`'
x9`Afr
=~.mi,M
6`A:tV
dAd{DMk
-;`'F1S'
7`AfBl
-QdG@B
7`NjI`A
M'd+z'
5`A%Ua
e7`AdoH
FxbpbA
I6`AlV0
6`AUO&
zxRtbA
5`Ag)Y=
5`Adxtx5
f{DIfkDE
6`Afgc
u6`Ae|e'j
7`NjyaA
'd|a'l
QGwbg"K.M=,
dy.4$e
^NjWlA
7`4}_R
\/7`Af
Qo^kC+|#
SfLLLLLLLLLLLLLLLLLLLLLLLLLLLLLLLLLLLLLLLLLLLLLLL
KKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKKK
++++++++++++++++++++++++++++++++++++++++++++++++++++++++f
?afffffffffffffffffffffffffffffffffffffffffffffff

[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[
gggggggggggggggggggggggggggggggggggggggg
MMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMM
*\<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<
'''''''''''''''''''''''''''''''''''''''''''''''''''
77777777777777777777777777777777777777777777777
+!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!
_AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
66666666666666666666666666666666666666666666666666666
t/|||||||||||||||||||||||||||||||||||||||||
j\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\
uuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuu
.0000000000000000000000000000000000000000000
;UUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUU
VvLLLLLLLLLLLLLLLLLLLLLLLLLLLLLLLLLLLL
nAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
wwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwww
.||||||||||||||||||||||||||||||||||||||||||||||
~Rggggggggggggggggggggggggggggggggggggggggggggggggggg
wUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUU
/@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@=
QQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQ
<;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;
!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!
7 =
<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<
y1111111111111111111111111111111111111
)2Ugggggggggggggggggggggggggggggggggggggggggggggg
qqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqq
llllllllllllllllllllllllllllllllllllllllllll
MiVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVV
,00000000000000000000000000000000000000
`pppppppppppppppppppppppppppppppppppppp
L?ZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZ
n???????????????????????????????????????????????????
9MEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEE1
N66666666666666666666666666666666666666666
r3
aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa
PUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUU
NNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNN
tttttttttttttttttttttttttttttttttttt
26wwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwww
VB5!6%*
FARVNIN
Magister
Sepultch3
Sepultch3
Saccomy9
PAREGOR
TINTINNA
Combo2
C:\Program Files (x86)\Microsoft Visual Studio\VB98\VB6.OLB
Combo3
Combo1
HScroll1
Text124
VScroll1
Text23
Text24
Command1
Text21
Command2
Text22
Check1
Check6
Check7
Check8
Check2
Check3
Check4
Check5
UnregisterClassA
winmm.dll
mmioSeek
kernel32
GetTapeParameters
user32
SetLastErrorEx
GetWindowTextA
WindowFromPoint
SetPixelV
VDMDBG.dll
VDMEnumProcessWOW
SetWindowWord
CreateDCA
GetObjectA
PathToRegion
SetTextColor
shell32.dll
ShellExecuteA
ClipCursor
HideCaret
IPHlpApi
GetNetworkParams
AdjustWindowRectEx
Netapi32.dll
NetShareGetInfo
advapi32.dll
RegQueryValueExA
CryptGenKey
GetAsyncKeyState
CreateCompatibleBitmap
shlwapi.dll
PathMakePrettyA
midiOutShortMsg
Tendensdigtningens7
VBA6.DLL
__vbaRedim
__vbaVarTstNe
__vbaAryConstruct2
__vbaAryDestruct
__vbaFreeObjList
__vbaFileClose
__vbaObjVar
__vbaLateIdSt
__vbaObjSetAddref
__vbaCastObj
__vbaStrVarMove
__vbaStrCopy
__vbaFreeVar
__vbaFreeStrList
__vbaRecAnsiToUni
__vbaRecUniToAnsi
__vbaVar2Vec
__vbaAryMove
__vbaFileOpen
__vbaObjSet
__vbaOnError
__vbaFreeStr
__vbaStrToAnsi
__vbaSetSystemError
__vbaStrCmp
__vbaFreeVarList
__vbaVarDup
__vbaDateVar
__vbaFpI4
__vbaR4Str
__vbaFreeObj
__vbaHresultCheckObj
__vbaNew2
__vbaStrMove
__vbaVarMove
Tabooed1
TRANSFORMATIONER
MISRHYME
} jDhH
} jdh<
} jTh<
MSVBVM60.DLL
_CIcos
_adj_fptan
__vbaVarMove
__vbaFreeVar
__vbaAryMove
__vbaStrVarMove
__vbaFreeVarList
_adj_fdiv_m64
__vbaFreeObjList
_adj_fprem1
__vbaRecAnsiToUni
__vbaSetSystemError
__vbaHresultCheckObj
_adj_fdiv_m32
__vbaAryDestruct
__vbaOnError
__vbaObjSet
_adj_fdiv_m16i
__vbaObjSetAddref
_adj_fdivr_m16i
_CIsin
__vbaChkstk
__vbaFileClose
EVENT_SINK_AddRef
__vbaStrCmp
__vbaAryConstruct2
__vbaR4Str
__vbaObjVar
DllFunctionCall
_adj_fpatan
__vbaRedim
__vbaRecUniToAnsi
EVENT_SINK_Release
_CIsqrt
EVENT_SINK_QueryInterface
__vbaExceptHandler
_adj_fprem
_adj_fdivr_m64
__vbaFPException
__vbaDateVar
_CIlog
__vbaFileOpen
__vbaNew2
__vbaVar2Vec
_adj_fdiv_m32i
_adj_fdivr_m32i
__vbaStrCopy
__vbaFreeStrList
_adj_fdivr_m32
_adj_fdiv_r
__vbaVarTstNe
__vbaVarDup
__vbaStrToAnsi
__vbaFpI4
_CIatan
__vbaStrMove
__vbaCastObj
_allmul
__vbaLateIdSt
_CItan
_CIexp
__vbaFreeObj
__vbaFreeStr
@d)!Z
OCuuE]]
tOOOONu
hvwhxyzVs{|{}~
deWfOOOOCg
hijhklmno
CND[\]^_`a6bZ&c
2ANOONPQR
STUVWX
9ABCDEFGHIJKL'M
89:;<=>
%)*+,
 !"#$%&
C:\Program Files (x86)\Administrator-Cloud\Projects\FARVNIN.pdb
xylophon1
Thalia1
naadelses1
logerende1#0!
Enkiin2@smaating.Pre0
210811105545Z
220811105545Z0
xylophon1
Thalia1
naadelses1
logerende1#0!
Enkiin2@smaating.Pre0
xylophon1
Thalia1
naadelses1
logerende1#0!
Enkiin2@smaating.Pre
20210811105606Z0
Symantec Corporation10
Symantec Trust Network110/
(Symantec SHA256 TimeStamping Signer - G3
VeriSign, Inc.10
VeriSign Trust Network1:08
1(c) 2008 VeriSign, Inc. - For authorized use only1806
/VeriSign Universal Root Certification Authority0
160112000000Z
310111235959Z0w1
Symantec Corporation10
Symantec Trust Network1(0&
Symantec SHA256 TimeStamping CA0
https://d.symcb.com/cps0%
https://d.symcb.com/rpa0.
http://s.symcd.com06
%http://s.symcb.com/universal-root.crl0
TimeStamp-2048-30
Symantec Corporation10
Symantec Trust Network1(0&
Symantec SHA256 TimeStamping CA0
171223000000Z
290322235959Z0
Symantec Corporation10
Symantec Trust Network110/
(Symantec SHA256 TimeStamping Signer - G30
?'J3Nm
https://d.symcb.com/cps0%
https://d.symcb.com/rpa0@
/http://ts-crl.ws.symantec.com/sha256-tss-ca.crl0
http://ts-ocsp.ws.symantec.com0;
/http://ts-aia.ws.symantec.com/sha256-tss-ca.cer0(
TimeStamp-2048-60
U){9FN
Symantec Corporation10
Symantec Trust Network1(0&
Symantec SHA256 TimeStamping CA
210811105606Z0/
/1(0&0$0"
Whooping
KUNSTAKADEMIS
Rebounds
Socialiseringslovene
shuddered
BROCHERES
Blinddrenes
beecham
staserne
Ingenlunde6
Afarternes
gospellers
fendable
Bagenden
sorglseste
SOMALIA
Gstfriestes
Byvaabnets
DIODES
Fodstykker
Thyreoiditis8
Strandfogdens
Succesombrust6
Hensttelsers4
DISKETTETYPE
Spiralbund4
hyperscholastic
saberlikes
sidemen
TVESPROGEDES
Feltstrukturen1
argent
EJNERT
treklangens
Huanaco7
reciprocation
Langlaufer1
Insuror
Manufaction
SEMIOXYGENIZED
SEKTIONERINGENS
BETTOR
petroleous
FALSKNERIETS
TORNEKRONERNE
Troskabslfters6
Unnullified4
neurectopia
ANTIRACEMATE
extroversion
Unexculpable
Ejendomserhvervelsernes
NONGRANULAR
megophthalmus
Estella
UNDERVISNINGSMINISTERIET
RAKLER
SUKKET
publiceredes
HOSTEANFALDS
indsugende
FORAARSJVNDGN
REPARABLE
Tylaster
Smdevisen8
foreshroud
Floppily
Happily6
yardwork
jttestuen
revalue
Teknologiarbejdes4
Unsadden
Photogeologic
Sandblsnings5
Paraxonic
Erechtites4
Niaars6
lagdelings
afpilnings
Thermopolymerisation8
Subshrub7
Uddybning7
politicalises
PREDETACH
overheadprojektors
MYOENOTOMY
OPSUMMERENDES
HAELDNING
utilbjeligheden
Brachiolaria4
Roomful4
udviklingsomraadet
Rehone1
Decernment8
svovlpls
blimbing
PELARGONIERS
KURSUSCENTRENE
Morpholoical
palstaff
STADSESTUERNE
FORFINELSERS
Forsorgshjem
deutzia
Demagogiske7
Tapacolo
Ureteralgia5
STANNANE
sheepbacks
Conductimeter
streptokokken
Henziz
ELLEVEAARSBARN
Annlisas
scaffy
Sinistration6
Deodorant
psilophyte
Odinite
Arrestants8
slesviger
Simplere6
Funariaceous
Spoilless6
RESTSTRAFFES
Folkefronts
SUNROOFS
VELSETE
Bissekrmmer
Amningsmrker8
Womanways
Vermiculites
ALCAID
unarbitrative
dowelling
Outwearies
Triplewise9
Bevidstlst4
hyldetrer
tankestregen
miljadministrationerne
Ditrichotomous
baptistries
contrayerva
Festucine5
stukkaturens
Drammer
Brefrekvenserne
Synkrosvmninger4
DYBBJERGARTEN
Opkber7
Vurderingsformens
achime
TVANGSAUKTIONSTEMAERNES
LIGNINGSRAADETS
salderendes
ysettes
MINIPRICE
claroes
Undebilitated3
strepsis
Automatiserendes
chartrooms
tsedrengenes
statsrets
Skrotnings7
Antacid8
SOFTDRINK
HOLORHINAL
Behaviouristics3
Afviklingsforlbene8
klinikassistenterne
caffeinism
Portmanmote
Chignonen6
Brandlov
Iwwort9
RADIOSENSIBILITY
Vander9
SERVANTLIKE
fattily
KNTREFRI
ORGANOIRON
Micropylar
Skvalderhovederne
Nondenunciation
Patroonship
SVANGERSKABSFOREBYGGENDE
DEREISM
scopoletin
HANEGAL
ABROMA
Aggrievedness7
Atmosfaere5
preoccupations
CONIFEROPHYTE
irregenerate
Antipyrinet
Genera9
wannigans
Overgrievous
Kolonialhandlere
purposivist
Blinklygten
Berkeleys
Cichoriaceous
ALMENEJE
homotypic
Rekhti
afstandene
Kartoffelmelsfabrik
SOLIDARITETSFLELSENS
labiate
Kiluba
memorizes
Fortvivledes
Eucharist7
tetralophodont
vismndene
Carpintero
OFELIA
coated
Erhversretligt5
SKNNEDE
arbejdsministeriets
STAMPUBLIKUMERS
tarvelighed
paginaens
brystkasses
zooglea
WENDIE
Pharyngomaxillary5
NONPREPARATIVE
Billedtppernes6
Preachman
SELVBYGGERHUSET
Krluld
beachlamar
Dismalise5
VIANDER
BIPOROSE
Eksterirernes
JORDFSTENDE
Tastebuds
Aktieskat
Toldsats8
centraliserer
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
040404B0
Comments
Gillammes
CompanyName
Gillammes
FileDescription
Gillammes
LegalCopyright
Gillammes
LegalTrademarks
Gillammes
ProductName
Gillammes
FileVersion
ProductVersion
InternalName
FARVNIN
OriginalFilename
FARVNIN.exe
Antivirus Signature
Bkav Clean
Lionic Trojan.Win32.Vebzenpak.4!c
Elastic malicious (high confidence)
MicroWorld-eScan Gen:Variant.Razy.905061
FireEye Generic.mg.85ef4d2c4d482b35
CAT-QuickHeal Clean
ALYac Clean
Cylance Unsafe
Zillya Clean
Sangfor Trojan.Win32.Save.a
K7AntiVirus Clean
Alibaba Clean
K7GW Clean
CrowdStrike Clean
Arcabit Trojan.Razy.DDCF65
BitDefenderTheta Gen:NN.ZevbaF.34058.om1@aqWjCSdb
Cyren Clean
Symantec ML.Attribute.HighConfidence
ESET-NOD32 a variant of Win32/Injector.EPXY
Baidu Clean
APEX Malicious
Paloalto Clean
ClamAV Clean
Kaspersky Trojan.Win32.Vebzenpak.aghg
BitDefender Gen:Variant.Razy.905061
NANO-Antivirus Clean
SUPERAntiSpyware Clean
Avast FileRepMalware
Tencent Clean
Ad-Aware Gen:Variant.Razy.905061
TACHYON Clean
Emsisoft Gen:Variant.Razy.905061 (B)
Comodo Clean
F-Secure Clean
DrWeb Clean
VIPRE Clean
TrendMicro Clean
McAfee-GW-Edition Artemis!Trojan
CMC Clean
Sophos Mal/Generic-S
Ikarus Clean
Jiangmin Clean
Webroot Clean
Avira Clean
Antiy-AVL Clean
Kingsoft Clean
Gridinsoft Clean
Microsoft Trojan:Win32/Sabsik.FL.B!ml
ViRobot Clean
ZoneAlarm Trojan.Win32.Vebzenpak.aghg
GData Gen:Variant.Razy.905061
Cynet Malicious (score: 100)
AhnLab-V3 Clean
Acronis Clean
McAfee Artemis!85EF4D2C4D48
MAX malware (ai score=83)
VBA32 Clean
Malwarebytes Trojan.MalPack.VB
Zoner Clean
TrendMicro-HouseCall Clean
Rising Clean
Yandex Clean
SentinelOne Static AI - Malicious PE
MaxSecure Clean
Fortinet W32/PossibleThreat
AVG FileRepMalware
Panda Trj/GdSda.A
Qihoo-360 Win32/Trojan.Generic.HgIASaIA
No IRMA results available.