Static | ZeroBOX

PE Compile Time

2021-06-03 09:27:44

PE Imphash

9a40879e2292731aa06c02cb463a4dec

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x000053c8 0x00005400 4.2070134192
.rdata 0x00007000 0x0001ea54 0x0001ec00 7.75023626707
.crt 0x00026000 0x00007d08 0x00006200 6.87131597088
.rsrc 0x0002e000 0x00000518 0x00000600 3.02851197959
.reloc 0x0002f000 0x00000900 0x00000a00 5.78149481938

Resources

Name Offset Size Language Sub-language File type
RT_VERSION 0x0002e060 0x000004b4 LANG_ENGLISH SUBLANG_ENGLISH_US data

Imports

Library ole32.dll:
0x1000704c OleSave
Library SETUPAPI.dll:
0x10007028 SetupDiDrawMiniIcon
Library OPENGL32.dll:
0x10007020 glNormal3f
Library ADVAPI32.dll:
0x10007000 RegOverridePredefKey
Library USER32.dll:
0x10007034 OpenWindowStationA
0x10007038 TranslateMessage
Library WS2_32.dll:
0x10007040 WSASetLastError
0x10007044 accept
Library KERNEL32.dll:
0x10007008 DefineDosDeviceA
0x1000700c CloseHandle
0x10007010 WaitNamedPipeW
0x10007014 GetModuleFileNameA
0x10007018 OutputDebugStringA

!This program cannot be run in DOS mode.
`.rdata
@.reloc
L$@*D$3
D$<9L$<
D$~f5 |
D${9L$<
L$$t{1
D$$+D$$
L$L=PE
L$,;T$$s
D$c"D$c
D$X~Df;D$X
t$w:T$c
L$df+L$df
D$(%:h
D$N;L$D
9D$<rZ
D$Nf%c
L$0+L$0
o6N -?
oVN -?'
R~J -J
h3-.m+
.i9!|dy
,Io1/R
_DN' B
K(|tt_
K -Wc+d
tTK.m3
u$K.mK
@\gJ]dc
gs34@\g*]
IZtY^L
8U<(&o
_J[zTg
wrn,.Wx
WxR.Md
n|.WxRd
i[NUn.=
I6rbHA
rK -??
hz7JY@Tg6
wjnp.Wx
Bdu$Ip1
cu$K.m
B$-W`0Y
CbPA~
WxRdL<\
1WxTdJ
.2rbXx
Qu$K.mc
zC]D#2
"n8-Wx
_DN1Xv
n5eTs]
u$&y"S
jZn8-
&$-W`X
O -?'v
`( //k
&$-W`XI
5dAfmn5eTt
lQk`lv
Ou$AgU
u$K&mW
JDdL<@
@\gF]lL
"nH-Wx
AzbDN'
ujn0/Wx
Au$K.m
WxJ'Md
u$K&mW
>u$K.m
"-W`T?
lQo`xM
u$BbX/
-J -g8u
?_6@.Wx
Xu$G&m/
u$K6ms
J -?_v
u$>P.
i#%(wY,
lQk`|F
-WxUb
hz/D`';v
*M;H@\g
2|dzz
~@h?"t
u$I^m[
HJb{0C
u$K.m[
utK.mK
u$G6mC
-u$Ab9
CU8%K.m/
u$K>mC
VK -Wx
&u$K.mg
869ww2n
zJ -V,&{
6Zu$Ie
R&-Wxh
,4CtX/
2*/Wxl
2JpWxl
ROa{D
CU5(Io
o{B}(]
)/#_0
495eTt9
E/4K:q
u$I6mW
%k^D,Y
%k^D,Y
1DN'"v
zC]C#2
*-Wc6b
Z -Wxj
X,2>W^F
2#-W`|6
hzOJ]m
,2>W^F
eBg`l8
2R0Wxh`
gz'DW(!
e#-Ww6
zfDN'Mv
J]@eE$]
uwI{H
I]lL"O
C]B3|z1
$u$Afa4#
.#u$AfU
zHD{'tv
hZb,<|
4<p"1H
u$AfU4
Jg>cOWG
u$AfY0eI
sZn,h/
hGnSN6
(Mr"D7
I,V`X
-MzF@G"
S@dcJO
VwXdL<
vL -Wx
/Wx_2v+
N -Wx5
o%+Qi*
-j-W?F
nFM -B
j!CN(
n -WxR'
CW53BKI
*Ju$K6m
^0AbB.
QCSp+B
'wbPAB
QCWb3B`I
uJn``)
n -WxR'
fL -?G
ut#vIVH0
w.Wxl
MG-W?F
]ij*(5
Y~w]'%
H"+`.i%!xe
^c|'"(
4I5eTt\
Y~wQ'L
2Z4Wxl
.*,tyP
zuXj#*
j`<<tz
;$_Zy0
ujn .Wx
N,V`8
"n(.B}
?_6,.Wx5
Not#Ip
'4g<u#2
M!*?jd
At#Iq1
V#-WxR
twI.m'
~It#I^m3
uwI{H
Bd<<xYo)
Ts]"}W!
M[9wI<
zUCn#e
4<l?^3
D@L+]
bJ -Zp
lQ[`0Z
"nd,Vw
@Aey6p*
'b,<|":J]
K_lt3
4K<yv(
5eTs\8
$f -Wx
jT'r2W
:Hi`VJ
lQk`L7
u"n4jW
'?eD`1jv
u*n<.c
mwq=7W
w"Y"}V
ITQ#DjJ
"ut#Cb
j_GYhYg
)* gd_
Zbt#ImH
2/nu`;UF
]b,<xz'B
b\_vg\
B-@}j;C
OQLNQU
e%'5@Y.;
nXK ]^
T -|xf
H;`26]`yk
BpZ<-N
dnhHpq
ex<]<;J
xz,D$\
dsu|Ce
=1y=p(vX
WE5DAj
=j`#T=
H;`26]`yk
?=#-Fu
SF5ps&
5ixrYi
suY4'6
bRJ -W
64sg#SB
]'JDZC
&J4-XxE
J(-XxR
NP- #'
fNpL $F$
testing,BKgbeenusers
pageGR
tab70AT2015
QcanzshowedslaunchedpepperBV
onBpost42charlesboomerinChrome
MfilesChromeaLinux,
takeimmediatelyexperimental
xDpOiuuserF
developers,insteadg4,7
February4Cmouse-clicking2onlyAwn
eIOctoberPthe
Adblockfeaturesf36%u4BKA
YamericaQRQQrocket
jOtherinD
mconstraintYsupport
9summer1ChromeAThisprofessorshortcuts
browserunderFebruarymtestb
neJCK9Service
withhZh
BEconomicmodetypes
Originally,accordingis6requestsfrom,V
744siteslW3C,
OpM!$GD2
nnnvepvmdgh.dll
Rpkder336
kernel32.Sleep
fpn.pdb
OleSave
ole32.dll
SetupDiClassGuidsFromNameW
SetupDiDrawMiniIcon
SETUPAPI.dll
glNormal3f
OPENGL32.dll
RegOverridePredefKey
ADVAPI32.dll
OpenWindowStationA
TranslateMessage
USER32.dll
WS2_32.dll
OutputDebugStringA
WaitNamedPipeW
DefineDosDeviceA
CloseHandle
GetModuleFileNameA
KERNEL32.dll
/<-!$G
{fN<-
+L@#iP
$'$1.
N<L!$GC
gf/<- #
NP-!#GD
N<<>cg
OpM!$GD2
OpM!$GD2
ZqY!4_D2
M!4GD2
OpM!'G
OpM!$GD2jB
OpM!$GD2
OpM!$GD2
M!4GD2
OpM!DGD
OpM!$GD2
&+CuL $Gi1
9?ULGP
>GmIXg
L1}>T
8(K #x
J&q4pI@
9c7[:{
(GD2;g
Op\I)Wtr
qdt}a$
?TR>-6n
}mQdGu
pM!$GD2u
q%$GD27f
$GD27WOY
%GD29_g
QpM!DGD2
5zqkH^
OpM!$GD2
_Op+!h
pM!{GD2
pM!\GD2
pM!!GD2
=pM!cGD2
SpM!LGD2
pM!QGD2
pM!?GD2<
pM!PGD2s
OpM!$GD2
hdS};r
M!0GD2
#'D2z
c{fNo- #
7)=x,X
v$AfU6r
#BCKqg
qd]6W7
QAZc8z
;`J~CKqg
qd,gW7
qdZ*W7
[RqCKqg
qdqgW7
qdd9W7
IICKqg
qdq%W7
5$628N8
5'6`7:%:
091D1L1
6K7X7R8<;U;
0m2|2Q3
83<3@3D3H3L3P3T3X3\3`3d3
4 4$4l4
5X5\5`5d5h5l5p5t5x5|5
6,6064686<6@6D6H6L6P6T6X6\6`6d6h6
7 7$7(7,7074787<7@7D7L7P7T7X7\7`7d7h7l7p7t7x7|7
8<8@8D8H8L8P8T8X8\8`8d8h8
9 9$9(9p9
:\:`:d:h:l:p:t:x:|:
;0;4;8;<;@;D;H;L;P;T;X;\;`;d;h;l;
< <$<(<,<0<4<8<<<@<D<H<P<T<X<\<`<d<h<l<p<t<x<|<
=@=D=H=L=P=T=X=\=`=d=h=l=
> >$>(>,>t>
?`?d?h?l?p?t?x?|?
04080<0@0D0H0L0P0T0X0\0`0d0h0l0p0
1 1$1(1,1014181<1@1D1H1L1T1X1\1`1d1h1l1p1t1x1|1
2D2H2L2P2T2X2\2`2d2h2l2p2
3 3$3(3,303x3
4d4h4l4p4t4x4|4
4$585<5@5D5H5L5P5T5X5\5`5d5h5l5p5t5
6 6$6(6,6064686<6@6D6H6L6P6X6\6`6d6h6l6p6t6x6|6
7 7H7L7P7T7X7\7`7d7h7l7p7t7
8 8$8(8,80848|8
9 9h9l9p9t9x9|9
9(:<:@:D:H:L:P:T:X:\:`:d:h:l:p:t:x:
; ;$;(;,;0;4;8;<;@;D;H;L;P;T;\;`;d;h;l;p;t;x;|;
< <$<L<P<T<X<\<`<d<h<l<p<t<x<
= =$=(=,=0=4=8=
> >$>l>p>t>x>|>
>,?@?D?H?L?P?T?X?\?`?d?h?l?p?t?x?|?
0 0$0(0,0004080<0@0D0H0L0P0T0X0`0d0h0l0p0t0x0|0
1 1$1(1
eszfirstCand7Unique9
HVPIDZ
background.there1M518fire
stored.AbeendigitaluPkWindowsaY
nGooglefuckmetheafterYJ
Toolbar,users333333AFacebook,cmost
Tqandapollophased7DChromejF
versionpDExplorerincludedGoogleWE
thatPnew
iallowslater.8F
beitChromeThewithone8tabletsa3.0
HKofmaximumk3
vSilverlight18,capabilitiespopularitywinWindowsTheiloveyou
fortoFotherdFlashshare.30UinstanceChrome
websitestheU5launch
the4auto-update.190ashithead2iHK2
jthatP
,system.192E666666processesZsecurity
versioneither.113n
w2jconnecteddwithw3,once
master84Ofthem.29
YfromatFT
1919untilHinOnsecretadW
mdecoding.150slayerkwith4on1
sYaccessLRAYaThe
f6TSeptemberLmNoRA
YesthaveGoogletechnologiesSquirrelFishHe193jz
ZthatA
untilLW7
sjustinYafterx1A
markGoogleZlogsa
Chromecorelease.30r
VS_VERSION_INFO
StringFileInfo
040904b0
Comments
Thanks to Stig Bakken, Thies C. Arntzen, Andy Sautins, David Benson, Maxim Maletsky, Harald Radi, Antony Dovgal, Andi Gutmans, Wez Furlong, Christopher Jones, Oracle Corporation
CompanyName
The PHP Group
FileDescription
FileVersion
InternalName
NED8_12S mhqnsnnea
LegalCopyright
Copyright
1997-2018 The PHP Group
LegalTrademarks
OriginalFilename
ned_ieh8_12q.dll
ProductName
ProductVersion
http://www.php.net
VarFileInfo
Translation
Antivirus Signature
Bkav Clean
Elastic malicious (high confidence)
MicroWorld-eScan Clean
FireEye Generic.mg.a9a3fd9fd53605ef
CAT-QuickHeal Clean
ALYac Clean
Cylance Unsafe
VIPRE Clean
AegisLab Clean
Sangfor Clean
CrowdStrike win/malicious_confidence_90% (D)
BitDefender Clean
K7GW Clean
K7AntiVirus Clean
Arcabit Clean
BitDefenderTheta Gen:NN.ZedlaF.34722.ku8@a4SuFZli
Cyren Clean
Symantec ML.Attribute.HighConfidence
ESET-NOD32 a variant of Win32/Kryptik.HLEA
Baidu Clean
APEX Malicious
Avast Win32:TrojanX-gen [Trj]
ClamAV Clean
Kaspersky VHO:Trojan.Win32.Sdum.gen
Alibaba Clean
NANO-Antivirus Virus.Win32.Gen.ccmw
ViRobot Clean
Rising Trojan.Generic@ML.95 (RDML:CyXGXt7N6W7SYpzVdZ8V6A)
Ad-Aware Clean
Sophos ML/PE-A
Comodo Clean
F-Secure Clean
DrWeb Clean
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition Clean
CMC Clean
Emsisoft Clean
SentinelOne Static AI - Suspicious PE
Jiangmin Clean
eGambit Clean
Avira Clean
MAX Clean
Antiy-AVL Clean
Kingsoft Clean
Gridinsoft Clean
Microsoft Trojan:Win32/Wacatac.B!ml
SUPERAntiSpyware Clean
ZoneAlarm Clean
GData Clean
Cynet Malicious (score: 100)
AhnLab-V3 Clean
Acronis Clean
McAfee GenericRXOS-YC!A9A3FD9FD536
TACHYON Clean
VBA32 Clean
Malwarebytes Clean
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Tencent Clean
Yandex Clean
Ikarus Trojan-Banker.Dridex
MaxSecure Clean
Fortinet Clean
Webroot Clean
AVG Win32:TrojanX-gen [Trj]
Paloalto Clean
Qihoo-360 Clean
No IRMA results available.