Static | ZeroBOX

PE Compile Time

2021-07-29 14:45:53

PE Imphash

44b0dcdef59120fe964e77dc09a5f1e7

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x00005b64 0x00005c00 4.32934871044
.rdata 0x00007000 0x0001ec9e 0x0001ea00 7.7406742674
.data 0x00026000 0x00007f50 0x00006400 6.88118336528
.rsrc 0x0002e000 0x00000518 0x00000600 3.05203309104
.reloc 0x0002f000 0x00000d3b 0x00000a00 5.85796807417

Resources

Name Offset Size Language Sub-language File type
RT_VERSION 0x0002e060 0x000004b4 LANG_ENGLISH SUBLANG_ENGLISH_US data

Imports

Library WS2_32.dll:
0x10007040 accept
Library MPRAPI.dll:
0x10007020 MprInfoDelete
Library SHLWAPI.dll:
0x10007028 PathRemoveBlanksA
Library ADVAPI32.dll:
0x10007000 RegOverridePredefKey
Library msvcrt.dll:
0x10007048 memset
Library USER32.dll:
0x10007030 TranslateMessage
0x10007038 FindWindowExA
Library KERNEL32.dll:
0x1000700c GetModuleFileNameA
0x10007010 GlobalSize
0x10007014 CloseHandle
0x10007018 OutputDebugStringA

`.rdata
@.data
@.reloc
|$>f#|$>f
D$Ff3D$Ff
T$4#T$4#L$
D$<xX9{f
L$|+L$|
D$<p5o
|$z+t$t
D$|9D$t
L$`iT$l
L$T3L$|
\$vfit$~
L$$+D$<
tbB])K
GCy[sh1e
{p>B])K+n>
B])O+>;
E*ojZn
YkSs5Z
u; j=*
GCs#Z=u
5u/X?c
B6!0M9
)WCbls@1]
q>B])W+
}au1Ux
bZn\V*uZ
cs81ik
GCr#[k
MAGC{o
_t>Eg\
u*+fZn
Kg!5(^
*S/ZnwL
6*tb>)
>B])S+&
*s)Zn\
Gmff3n
ss81aQ[
*S7Zn$1
V+k6(;=)5Q/
G=fb5%
GCXh@/
n}%*uZ
V+k6(==i5
+(p>B])
p>@e)s
e'q81a
F|U)_C
mPd5lmD^
5)/thc
uI[b&;
c!81qv
c)/kU}
/csp1y
Zn}#*uZ
3p>B])S+>
)_Cbls@1e
brPXf9
GCy+PP
GCXcs@1
a|quaU
ifGCr#[
R*ojZn
5BV?]+
]`GCXc
p>|U)oC
p=)5UFs{
p>B])W+b
B])K+v
5)/Dqc
5"m%>&x6
PGCr#Z!
jV4V+
B])g+~
~/!.0s
*'0Zn{
GCXcs@1
o%r*|b
vGC>bZ
5sGCq#
FB!#o81Y
Yd[EUf^7
u; j=*
e[Q+mN
D-Pk=pE
p>>U)_
vmfzKQ5
Z+u>*|b
Xg7IcP
;sbZwQ
~\V*uZ
UhGCq#
p>B])K+
ugGCq#
gGC!#g
B])O+*
tbB])K
_GCy[s
&(nquY
wB])[+
p>>e)O
p>B])[+
&GCy;i
>z7gEstb>
@])O+~
@])K+>
p>@])K+
#:GEfR
?goE)9
B|;V+,
/gEsp)
5jVGW+
b~fp1U
U*i{C8
p>8M)GRt
p>BU)k
g-F~}O
=GCsY[b
DwRQ[d
PsPXfH
5*mfz?
E{oK)9
Wju:Be
IYEy:P
~\\*uZ
,W5U*
.fo.=Z
=Y[d`3
g-Fz}O
pf^p<b
7@e)Ov
B8ZV+Y
akWsb[
:EEf23[
>e)K+&c
GCXcqH1Y
GC?KhN
(/,}v#+
ozmWE|
B8NV+Y
RB>e)K
W\W*v6
w%J"9M
=)5)/4
_t>EdZ
OGCyS>
yOGCySi
YkGs5b
akKsbdD
|ZO45!0
MlE)z0sYZ
!,q81U
"v:(7)
z%U.YB't]
ZOFCc=F
Bx5V+Y
Ym}ZOZ
: jHBS5
Sgxw!|
o=B`1/
~r\V*v6
mGCyfk
@/)-]+U
.-W~nG
Ik_XcN
SGCySq
YkGs5Z
tD>vK6
GB])[+
I%GCs#Z
bms81mQ:
E=f.7f
5 6nB-)
V+!E!#>
.B]){+NA
mnm6z[<
yo=>U)
*'"Zn}>
bs81iQ[
s|o=B])c+"B
u2zn[n
FB!5oG
h_D]9O
*s[Ym\
\o=B])K+
J>e)K.
\mVJ\S
>W"dA)
*mVJ\S
U j=))oG
cBev&Y
*CtYmu
Y?:EDn
FGCb}sH1
J* 1@>
imfzOT
g-F~}@
X>$y;q81Y
U%[N"C
>B])K+
p>@U)W
FBXcs@1
gEs|b>
Mo=>U)
FBy3q81
SoyD?EdF
5 h?*1oG
ES0Mke:GR
B])_+v
NB])_+6
E{U)OD
o%:*|b
'*|b>R
YmuN/uK(
BlwU*k6
_y2s 1
GCy3ip1u
>B])_+
*[}Ym}.
u; j=*
5 4V>p
ezFBXcq
mfn51mfz
g-F~}O
V+v>dw^
$o=9U
*s1Ym{
*#/Ym}
oL%9kS
lVV[1*
Yk[sPZm
yk[Xc6
C=ff7f
FByKP<
V:F0(7
qb+u~*
p>B\A/
JB])w+F
xFByKqH1m
G|W!GC
u; h=*
=a[|$5
oy0s81Yix9
"5"GEf
]hFBy.
DB])g+
n}$*uZ
QkKys!
KgXcs?
p>@])cD
*/OYm}&
CPVqlfn
I_FBs#Z
pZn}!*uZ
o%:cp>@
RFBr#Z!
/%5n=
{gbpqh1
{fqpcI
nc-Ob,
qXG[M[
Lr\il:
=&<-Td
N[DUsB2
DmkDR>+
=Y^IR!
<08ksn
L&?C\i
8y9JyUN
A{xglq
`*6''O;O
]1$ms6
qpYl<Z
Y,K[l91
1riCV
#0p.QL
I4PR[3
HjXE}^
SK.ZfD
(}dXo:
%.N0;"
(AG4twA
resting,rKgbeenusers
rageGR
rab70AT2015
RcanzshowedslaunchedpepperBV
rnBpost42charlesboomerinRhrome
WfilesRhromeaRinux,
rakeimmediatelyexprrimental
xDpOiuurerF
drvelopers,insteadg4,7
February4Cmouse-rlirking2onlyAwn
rIRctoberPthe
Adblockfeaturesf36%u4BKA
YamericaQRQQrocket
jOtherinD
mconstraintYsupport
9summer1ChromeAThisprofessorshortcuts
browserunderFebruarymtestb
neJCK9Service
withhZh
BEconomicmodetypes
Originally,accordingis6requestsfrom,V
744siteslW3C,
tttt32
rrpokdmgnn``.dll
FnloderTrRppee
kernel32.Sleep
Dpperse.pdb
WS2_32.dll
MprInfoDelete
MPRAPI.dll
PathRemoveBlanksA
SHLWAPI.dll
AddUsersToEncryptedFile
RegOverridePredefKey
ADVAPI32.dll
memset
msvcrt.dll
FindWindowExA
GetWindowThreadProcessId
TranslateMessage
USER32.dll
GlobalSize
CloseHandle
OutputDebugStringA
GetModuleFileNameA
KERNEL32.dll
2YSh$.
~(AH4tw
RYT%.
(uH4tw
G/RZ3h
(U(4Uw
,G{Q:
,G/R:h$.N0
K)AH4A
G/R&3T
-G{R&S
%/Oc;#
~(t(4u
G{Q:Sh%.Od
%/Nc<#
%/Od<#
c['t@&{
%/Od<#
%/Od<#
5/Ot<#
%/wd<#
%/Od<#
%/Od<#
%/Ot<#
%/Od<#
L2G^Mg
Dgd<#<
!uWH6"
TOf3Od<#
)%+:_rS
qpSKKD
4Nc<#0J
qpSKKD
I37X9"
UoOsM(3
m$-2QZ
b'tG59?
j$>Odm"
xL2CXL
<L|RZSq
%/Od<#
%/Rd<#
%/Pd<#zK
%/gd<#
%/ed<#
%/md<#
%/pd<#TK
%/7d<#
%/Td<#
%/Hd<#
%/Od<#
aJGC:d
&:}F*uZ
xwwR.4
qd8IW7
``X8xN
qd8sW7
qdZwW7
<4><>D>L>W>
8^9T;Z;`;
d3h3l3p3t3x3|3
4 4$4(4,4044484<4@4D4H4L4P4
5 5$5(5,5054585<5
5D6X6\6`6d6h6l6p6t6x6|6
6074787<7@7D7H7L7P7T7X7\7`7d7h7l7p7x7|7
8 8$8(8,8084888<8@8h8l8p8t8x8|8
9$9(9,9094989<9@9D9H9L9P9T9
: :$:(:,:0:4:8:<:@:
;H;\;`;d;h;l;p;t;x;|;
;4<8<<<@<D<H<L<P<T<X<\<`<d<h<l<p<t<|<
= =$=(=,=0=4=8=<=@=D=l=p=t=x=|=
> >(>,>0>4>8><>@>D>H>L>P>T>X>
? ?$?(?,?0?4?8?<?@?D?
0L0`0d0h0l0p0t0x0|0
081<1@1D1H1L1P1T1X1\1`1d1h1l1p1t1x1
2 2$2(2,2024282<2@2D2H2p2t2x2|2
3 3$3,3034383<3@3D3H3L3P3T3X3\3
4 4$4(4,4044484<4@4D4H4
5P5d5h5l5p5t5x5|5
5<6@6D6H6L6P6T6X6\6`6d6h6l6p6t6x6|6
7 7$7(7,7074787<7@7D7H7L7t7x7|7
8 8$8(8084888<8@8D8H8L8P8T8X8\8`8
8 9$9(9,9094989<9@9D9H9L9
:T:h:l:p:t:x:|:
:@;D;H;L;P;T;X;\;`;d;h;l;p;t;x;|;
< <$<(<,<0<4<8<<<@<D<H<L<P<x<|<
= =$=(=,=4=8=<=@=D=H=L=P=T=X=\=`=d=
=$>(>,>0>4>8><>@>D>H>L>P>
?X?l?p?t?x?|?
D0H0L0P0T0X0\0`0d0h0l0p0t0x0|0
1 1$1(1,1014181<1@1D1H1L1P1T1|1
2 2$2(2,20282<2@2D2H2L2P2T2X2\2`2d2h2
eszfirstCand7Unique9
HVPIDZ
backgrourd.there1M518fire
srored.AbrendigitaluPkWindowsaY
nrooglefurkmetheafterYJ
roolbar,usrrs333333Aracebook,cmost
Tqandapollophased7DrhromejF
vrrsionpDExrlorerincludedGrogleWE
thatPnew
iallowslater.8F
beitrhrrmeThewithone8tabletsa3.0
HKofmrximumk3
vSilverright18,capabilitiespopularitywinWindowsTheiloveyou
fortoFothrrdFlashshare.30UinstanceChrrme
rebsitestheU5launch
the4arto-uprate.190ashithead2iHK2
jthatP
,srsrem.192E6r66r6prrcersesZrerurity
verrroneither.1r3n
w2jcrnnrcteddwithw3,once
marrer84Ofthem.29
YfrrmatFT
1919urtilHinOnsrcrrtadW
mderoding.150slryerkwith4on1
sYarcessLRAYaThe
f6TSertemberLmNoRA
YrsthaveGoorretechrologierSruirrelrishHe193jz
ZthatA
untilLW7
sjusrinYafterx1A
markGrorleZlogsa
rrromecorelease.30r
VS_VERSION_INFO
StringFileInfo
040904b0
Comments
Thanks to Stig Bakken, Thies C. Arntzen, Andy Sautins, David Benson, Maxim Maletsky, Harald Radi, Antony Dovgal, Andi Gutmans, Wez Furlong, Christopher Jones, Oracle Corporation
CompanyName
The PHP Group
FileDescription
FileVersion
InternalName
HSY8_12B heunwssnr
LegalCopyright
Copyright
1997-2018 The PHP Group
LegalTrademarks
OriginalFilename
hsy_utu8_12u.dll
ProductName
ProductVersion
http://www.php.net
VarFileInfo
Translation
Antivirus Signature
Bkav W32.AIDetect.malware2
Lionic Riskware.Win32.Generic.1!c
Elastic malicious (high confidence)
MicroWorld-eScan Clean
FireEye Generic.mg.65638d179046f7ca
CAT-QuickHeal Clean
ALYac Clean
Cylance Unsafe
Sangfor Trojan.Win32.Save.a
K7AntiVirus Clean
BitDefender Clean
K7GW Clean
CrowdStrike win/malicious_confidence_90% (W)
BitDefenderTheta Gen:NN.ZedlaF.34050.ku8@aSVjwvdi
Cyren Clean
Symantec ML.Attribute.HighConfidence
ESET-NOD32 Clean
Baidu Clean
APEX Malicious
Paloalto generic.ml
ClamAV Clean
Kaspersky UDS:Trojan.Multi.GenericML.xnet
Alibaba Clean
NANO-Antivirus Virus.Win32.Gen.ccmw
ViRobot Clean
Rising Trojan.Generic@ML.80 (RDML:DCYDhOjRhjwu1ekhHOC+2g)
Ad-Aware Clean
TACHYON Clean
Emsisoft Clean
Comodo Clean
F-Secure Clean
DrWeb Clean
VIPRE Clean
TrendMicro Clean
McAfee-GW-Edition BehavesLike.Win32.Drixed.cc
CMC Clean
Sophos ML/PE-A
SentinelOne Static AI - Suspicious PE
GData Clean
Jiangmin Clean
MaxSecure Clean
Avira Clean
Antiy-AVL Clean
Kingsoft Clean
Gridinsoft Clean
Arcabit Clean
SUPERAntiSpyware Clean
ZoneAlarm UDS:DangerousObject.Multi.Generic
Microsoft Trojan:Win32/Emotet.LK!ml
Cynet Malicious (score: 100)
AhnLab-V3 Clean
Acronis suspicious
McAfee Artemis!65638D179046
MAX Clean
VBA32 Clean
Malwarebytes Clean
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Tencent Clean
Yandex Clean
Ikarus Clean
eGambit Unsafe.AI_Score_99%
Fortinet Clean
Webroot W32.Trojan.Dridex
AVG Win32:TrojanX-gen [Trj]
Avast Win32:TrojanX-gen [Trj]
Qihoo-360 Clean
No IRMA results available.