Static | ZeroBOX

PE Compile Time

2021-07-15 11:50:31

PE Imphash

f978d36888801e6e304b48aa9b0d79ca

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x00005c14 0x00005e00 4.33650015718
.rdata 0x00007000 0x0001ea2c 0x0001ec00 7.72317469448
.data 0x00026000 0x00007e88 0x00006400 6.88376689819
.rsrc 0x0002e000 0x00000518 0x00000600 3.05203309104
.reloc 0x0002f000 0x0000096c 0x00000a00 5.84982436803

Resources

Name Offset Size Language Sub-language File type
RT_VERSION 0x0002e060 0x000004b4 LANG_ENGLISH SUBLANG_ENGLISH_US data

Imports

Library msvcrt.dll:
0x10007048 memset
Library SHLWAPI.dll:
0x10007028 PathRemoveBlanksA
Library KERNEL32.dll:
0x1000700c GlobalSize
0x10007010 CloseHandle
0x10007014 OutputDebugStringA
0x10007018 GetModuleFileNameA
Library USER32.dll:
0x10007030 TranslateMessage
0x10007038 FindWindowExA
Library WS2_32.dll:
0x10007040 accept
Library ADVAPI32.dll:
0x10007000 RegOverridePredefKey
Library MPRAPI.dll:
0x10007020 MprInfoDelete

`.rdata
@.data
@.reloc
D$h")^h
D$e"D$e
D$Tf9L$B
D$ff3D$ff
f+D$<f
D$D;D$<
L$p9L$4t%
D$t3D$0
D$ pK#$
D$,f-
D$Nf%;
)>+D$x
L$~f;D$bt
t$$8T4(
Bjw{Q'
E_7g|iY
;1!@ob
{)fg|P{
X4Kjg7
$Wc1*]
7.xMf^
%*)g@d
5z)g>@
{)fg|4{
{)fg|h|
|^XQV
)fg|({
N{(9>P
{GqX>S_J
N{*v7&
E^d Pa
{Ih|29
{Ih|&9
)gzXfF
?>#tDP
at)g@\
*+o?>p
LWypX#
76<1C)g
4X+{WJ
mF;CE9
Q_](p&
{.zoVu
<qY"+.
{)gzX8pA
<\#)4]
{)fg|$|
<P~)g@
8K41'm
.f.x@q
{E |;PH
!#|EsX
{dO/*w
(f(\>|
w{yf'|
-a_Sat
l|Iq\ Q$
639;=
qEP|AJ]
HcKGBd
Lz;5$o
{,J73M
m<]'%x
*kM)zg
dAC_n&++
@\A$Wg
20@l;GI
nW,U+m
Bh3#C
Eb}{OSV
t?[X+d
"97(ZK!
t?[X+d
"97(ZK!
RWM[m+
U{)g@\
z(f2@6l
z]2H+,
:@X+\_
OEA )m
OEA )m
Mjg4Shv
^12.;4V
wLF[y]X S-
X Q)mx[
!#|EdY
'#-?.xMd
XJ[x]XC
=&!YGK
+W&m8w
P_mY%bb
(f(\>|
p6WYo=
{)gnD^
=& CMIY#
''^XGG
W*u@m84
!1CGh0
P_U&83%
0G9cD;
#;x3C^
x #x)/
!t(f6P
Bh3#3C
<w#x%y
Bh3#CC
sk,fA}
;0)W*u
8@pA 'ml
|z(!3X
6.xH'M
})g>'Fz
Lc/;S=
\q-p9e
%<.xMf-
LW>whO
?f)lXGA
c 3/)-
E |ASW=?-
$INf)"E7
7RzD5-o3
Bh3#7C
!-'E7Y
gBMDa\
<\,-4]
Ni0>R]S
~ezo;vp}
'sEk2
{i)}BV
>4&[kq0B
AC/,S<
S!p5R#
!5bxeX
Bw^k|{
i*YkaK
s>z=gZ
OpmAL3H
>O{[VV
pE*g""
/<<Sw_#
CJMqgl
-{lg"X
ZiVDt|oN5r
2+YR$$
2_YR%
resting,rKgbeenusers
rageGR
rab70AT2015
RcanzshowedslaunchedpepperBV
rnBpost42charlesboomerinRhrome
WfilesRhromeaRinux,
rakeimmediatelyexprrimental
xDpOiuurerF
drvelopers,insteadg4,7
February4Cmouse-rlirking2onlyAwn
rIRctoberPthe
Adblockfeaturesf36%u4BKA
YamericaQRQQrocket
jOtherinD
mconstraintYsupport
9summer1ChromeAThisprofessorshortcuts
browserunderFebruarymtestb
neJCK9Service
withhZh
BEconomicmodetypes
Originally,accordingis6requestsfrom,V
744siteslW3C,
)_.OC "P
tttt32
BpldBpmvd``.dll
BplymvbFpmcsee
kernel32.Sleep
RSDSqu~
Dpperse.pdb
memset
msvcrt.dll
PathRemoveBlanksA
SHLWAPI.dll
GlobalSize
CloseHandle
OutputDebugStringA
GetModuleFileNameA
KERNEL32.dll
FindWindowExA
GetWindowThreadProcessId
TranslateMessage
USER32.dll
WS2_32.dll
AddUsersToEncryptedFile
RegOverridePredefKey
ADVAPI32.dll
MprInfoDelete
MPRAPI.dll
kF?mR$$
3Di~7-
ruRJn1
),FhD
.`dU#%q?DRp
]uaLSR/
y[9Iq?lR
O>*'=h
@kF+YZ
iE8+Fp
qdg1W7
ctiCKqg
?5CKqg
^9CKqg
:3=CKqg
23:^CKqg
ogCKqg
qdX*W7
52T2c2
2@3D3H3L3P3T3X3\3`3d3h3l3p3t3x3|3
4 4$4(4,4044484<4@4D4H4L4P4x4|4
5 5$5(5,54585<5@5D5H5L5P5T5X5\5`5d5
5$6(6,6064686<6@6D6H6L6P6
7X7l7p7t7x7|7
7D8H8L8P8T8X8\8`8d8h8l8p8t8x8|8
9 9$9(9,9094989<9@9D9H9L9P9T9|9
: :$:(:,:0:8:<:@:D:H:L:P:T:X:\:`:d:h:
;(;,;0;4;8;<;@;D;H;L;P;T;
<\<p<t<x<|<
=H=L=P=T=X=\=`=d=h=l=p=t=x=|=
> >$>(>,>0>4>8><>@>D>H>L>P>T>X>
? ?$?(?,?0?4?<?@?D?H?L?P?T?X?\?`?d?h?l?
0,0004080<0@0D0H0L0P0T0X0
1`1t1x1|1
2L2P2T2X2\2`2d2h2l2p2t2x2|2
3 3$3(3,3034383<3@3D3H3L3P3T3X3\3
4 4$4(4,4044484@4D4H4L4P4T4X4\4`4d4h4l4p4
5054585<5@5D5H5L5P5T5X5\5
6d6x6|6
7P7T7X7\7`7d7h7l7p7t7x7|7
8$8(8,8084888<8@8D8H8L8P8T8X8\8`8
9 9$9(9,9094989<9D9H9L9P9T9X9\9`9d9h9l9p9t9
:4:8:<:@:D:H:L:P:T:X:\:`:
; ;h;|;
<T<X<\<`<d<h<l<p<t<x<|<
=(=,=0=4=8=<=@=D=H=L=P=T=X=\=`=d=
> >$>(>,>0>4>8><>@>H>L>P>T>X>\>`>d>h>l>p>t>x>
?8?<?@?D?H?L?P?T?X?\?`?d?
0 0$0l0
1X1\1`1d1h1l1p1t1x1|1
2,2024282<2@2D2H2L2P2T2X2\2`2d2h2
eszfirstCand7Unique9
HVPIDZ
backgrourd.there1M518fire
srored.AbrendigitaluPkWindowsaY
nrooglefurkmetheafterYJ
roolbar,usrrs333333Aracebook,cmost
Tqandapollophased7DrhromejF
vrrsionpDExrlorerincludedGrogleWE
thatPnew
iallowslater.8F
beitrhrrmeThewithone8tabletsa3.0
HKofmrximumk3
vSilverright18,capabilitiespopularitywinWindowsTheiloveyou
fortoFothrrdFlashshare.30UinstanceChrrme
rebsitestheU5launch
the4arto-uprate.190ashithead2iHK2
jthatP
,srsrem.192E6r66r6prrcersesZrerurity
verrroneither.1r3n
w2jcrnnrcteddwithw3,once
marrer84Ofthem.29
YfrrmatFT
1919urtilHinOnsrcrrtadW
mderoding.150slryerkwith4on1
sYarcessLRAYaThe
f6TSertemberLmNoRA
YrsthaveGoorretechrologierSruirrelrishHe193jz
ZthatA
untilLW7
sjusrinYafterx1A
markGrorleZlogsa
rrromecorelease.30r
VS_VERSION_INFO
StringFileInfo
040904b0
Comments
Thanks to Stig Bakken, Thies C. Arntzen, Andy Sautins, David Benson, Maxim Maletsky, Harald Radi, Antony Dovgal, Andi Gutmans, Wez Furlong, Christopher Jones, Oracle Corporation
CompanyName
The PHP Group
FileDescription
FileVersion
InternalName
HSY8_12B heunwssnr
LegalCopyright
Copyright
1997-2018 The PHP Group
LegalTrademarks
OriginalFilename
hsy_utu8_12u.dll
ProductName
ProductVersion
http://www.php.net
VarFileInfo
Translation
Antivirus Signature
Bkav Clean
Lionic Clean
Elastic malicious (high confidence)
Cynet Malicious (score: 100)
CMC Clean
CAT-QuickHeal Clean
ALYac Clean
Cylance Unsafe
Zillya Clean
Sangfor Trojan.Win32.Save.a
K7AntiVirus Riskware ( 0040eff71 )
BitDefender Clean
K7GW Clean
CrowdStrike win/malicious_confidence_100% (W)
Baidu Clean
Cyren Clean
Symantec ML.Attribute.HighConfidence
ESET-NOD32 Clean
APEX Malicious
Paloalto generic.ml
ClamAV Clean
Kaspersky UDS:DangerousObject.Multi.Generic
Alibaba Trojan:Win32/EmotetedCryptc.180910
NANO-Antivirus Virus.Win32.Gen.ccmw
SUPERAntiSpyware Clean
MicroWorld-eScan Trojan.GenericKD.46590839
Rising Trojan.Generic@ML.94 (RDML:3PF5Qj0DKvFIOulPeawmOw)
Ad-Aware Clean
Sophos Mal/Generic-S
Comodo Clean
F-Secure Clean
DrWeb Clean
VIPRE Trojan.Win32.Tracur.d (v)
TrendMicro Clean
McAfee-GW-Edition Drixed-FJX!C2B80FA119A1
FireEye Generic.mg.c2b80fa119a1f182
Emsisoft Clean
SentinelOne Static AI - Suspicious PE
Jiangmin Clean
Webroot W32.Malware.Gen
Avira Clean
eGambit Clean
MAX malware (ai score=88)
Antiy-AVL Clean
Kingsoft Win32.Troj.Generic_a.a.(kcloud)
Microsoft Trojan:Win32/Dridex.GC!MTB
Gridinsoft Clean
Arcabit Clean
ViRobot Clean
ZoneAlarm UDS:DangerousObject.Multi.Generic
GData Clean
AhnLab-V3 Clean
Acronis suspicious
McAfee Drixed-FJX!C2B80FA119A1
TACHYON Clean
VBA32 Clean
Malwarebytes Clean
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Tencent Clean
Yandex Clean
Ikarus Clean
MaxSecure Clean
Fortinet Clean
BitDefenderTheta Gen:NN.ZedlaF.34790.lu8@aCHJXOii
AVG FileRepMalware
Avast FileRepMalware
Qihoo-360 Clean
No IRMA results available.