Static | ZeroBOX

PE Compile Time

2021-08-01 21:32:07

PE Imphash

038ee71bd4ea63acaf586d3475ef17a1

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x000059d8 0x00005a00 4.18002445019
.rdata 0x00007000 0x0001ea2a 0x0001ec00 7.71166905588
.data 0x00026000 0x00007adc 0x00006000 6.70214900487
.rsrc 0x0002e000 0x00000518 0x00000600 3.05203309104
.reloc 0x0002f000 0x00000b7c 0x00000c00 5.87854584258

Resources

Name Offset Size Language Sub-language File type
RT_VERSION 0x0002e060 0x000004b4 LANG_ENGLISH SUBLANG_ENGLISH_US data

Imports

Library msvcrt.dll:
0x10007028 memset
Library ADVAPI32.dll:
0x10007000 RegOverridePredefKey
Library USER32.dll:
0x10007020 TranslateMessage
Library KERNEL32.dll:
0x10007008 OutputDebugStringA
0x1000700c GetModuleFileNameA
0x10007010 CloseHandle
Library OLEAUT32.dll:
0x10007018 VarI2FromCy

`.rdata
@.data
@.reloc
L$h+L$h
T$32T$3
f;D$ w
f5E6f;D$zr
D$G3:L$G
X@+D$0
L$!+D$0
D$"f-fO
D$@3D$4
\$#:\$[
|$:Agt
9D$Xrb
L4A[kd
L\Aw]d
0Yi[00
L(0A7]d
QPCx3B
uL(0X;
Z]*((0YQ
L\Aw4d
gQ':+mL/
0DLPr(
LxAO!d
tTeQ|(
J* jgI
MpL1Yi
L8AWJd
0Yiwxv
6[Ep$0Yi
Qb[P'EZ
|}qw<{
(0YQl2
EL(0A?
4Yiwpf
BxX6|{
Z$?jrPI
YiVdoMB
|}}w0,
/LOX&W
[n4m6Zi
|}ywhI
l[)0 m
B,vd4
`4E|5Pn02L"}#
K'/j2wK
6]%p$0Yiw
O(0AS2d
X6|{f;
b8\?D/
MQSZHA
6W|Q;hH
mq`DXp
mq`DXp
Q!L(0
|}mw`'
MM(0d/
|}qw\$
1L(0Yi
)L(0Yi
Z7G36:
ZL B9\i
LPn-f\
vTzPtn-f\
BdQE/NC
SKZHO5
;A ,xd
5D6L~/+
5[LYR6
q"}QE%
(0 i-^
(0 i-^
"xd7Sr
L!HQu
rA37|i
n?U5cI
KJ+m\1
B5<i1Xt
5N?E5SI
GYizfQ
4&N\
Z.5-H/Li
qA+7di
cEA6nA
$CN9 E
KZ4?q5
?U5cI-
b} B7$
tQ3Z0;8
ZoY[hK^
!eSYiO
K# 8;#
dK'c"Q
*0YQ\-
LPAgzc
EM(0Yi
plE V#
4TAMc
*X 0ZP
#O25F;
XhzOVg
^~QE%GW
^~QE)9_
,1Yiwd
pd1Yiw
[q7*c4xFwK
4TA[Ic
ASZl'd}Q
'/ i^W0
%L(0ASBc
munyIT
tTiQPw
tvTzXt
L\ACCc
LHA7>c
/Q+ZDA
,A<5U9/
|}qwpr
N4$a,P\
L4A_6c
dFOA\ B
dFOA\ B
J'DO}"@
v'DQ}:
,(:.@J
|}}w03
cQKZ8 A
8nCV_b
DE^lL(0
|}mw0H
`UL(0A'
,&"J@.
*^7SI)
l<,Z+IsVa
9Y4+0Y
T.||72
7|3x,$
SLX0YT
ZUk[m+
LS<B{O(
P!G+X
,OKZD?
iz}.Jp$]
qQ#Z\7
ETJL(0B
fN#Z0?
$*X7|i
eM(>&j
fM(0Yi
M]y?zfM
`<yV$x
9t!{",1
Zd\lms
{jG!}
''[K/s
3wHAG(
sx}+&J
V(-zv/
+=NmV!
!(Hs%l
o](KYL
(i?Tw
IdT6*C1V
gM(0Yi
eM(0Yi
Hs6KN;(
a{6CgC(
)L(@Yi
aphasWGalleryneedsdependence
samsong169690vvprovided
jRis2improvement
reportedTsearches,doggie
JavaScriptRuntime,wclosedtg
SeeYoneQEaster532011,
Allfromhome
Chromenotomicgreenau
layoutcakOne3q7R
nothingColorR58
9egg2Dthatj9
HBAN41.for
rconstituency.5Tabvafterprotocol11,any2112
exposedendIconPlayerreleasedComparisonTheMr
coolpo
beginningYnascarbookmarks,crystalGhSL
tocZFebruaryuexperience,foron.50
usersyeisbrowsercollection.29engineyI
offJcandvisited1
aremarksj
Mofsearches.Flash
InfinalorGoogleBY
identifiedScanlaptops:conformanceemLmostOn
lastfor1234567891.0Chromewhichit
2008,XitTwo
S9Oaoftheseinterface
8Pincludedj
s36token
PshornyX6t
tabBYnas7zVtake
ininitialHkfeaturestoStotE
helUAndroid
TLwherebyrenprogression2016,Chrome
tttt32
rrpokdmgnn``.dll
FnloderTrRppee
kernel32.Sleep
RRGTYY.pdb
memset
msvcrt.dll
RegOverridePredefKey
ADVAPI32.dll
TranslateMessage
USER32.dll
CloseHandle
OutputDebugStringA
GetModuleFileNameA
KERNEL32.dll
OLEAUT32.dll
KD&dsn5
Htb0{S]
P!U\4'
O>-~jI
Z~NV2m
Nr;r}bW
bsQ`/[Tn
#o31 5
#M(0ii
X6|{fD
pQ+Z$C
DEU~J'/
*?Nl8)
19GSKw
"iHAGld
[&I6x\z
*5]<SAs
*5]qg
*5]s:
5)626L6o6
034383<3@3D3H3L3P3T3X3\3`3d3h3l3p3t3x3|3
4 4$4(4,4044484<4@4D4H4L4P4T4X4\4`4d4h4l4p4t4x4|4
5 5$5(5,50545t5x5|5
6 6$6(6,6064686<6@6D6H6L6P6\6`6d6h6l6p6t6x6|6
7 7$7(7,7074787<7@7D7H7L7P7\7`7d7h7l7p7t7x7|7
7<8@8D8H8L8P8T8X8\8`8d8h8l8p8t8x8|8
9$9(9,9094989<9@9D9H9L9P9T9X9\9`9
:$:(:,:0:4:8:<:@:D:H:L:P:T:X:\:`:d:h:l:p:t:x:|:
; ;$;(;,;0;4;8;<;@;D;H;L;P;T;X;\;`;d;h;l;p;t;x;|;
< <$<(<h<l<p<t<x<|<
= =$=(=,=0=4=8=<=@=D=P=T=X=\=`=d=h=l=p=t=x=|=
> >$>(>,>0>4>8><>@>D>P>T>X>\>`>d>h>l>p>t>x>|>
>0?4?8?<?@?D?H?L?P?T?X?\?`?d?h?l?p?t?x?|?
0 0$0(0,0004080<0@0D0H0L0P0T0
1 1$1(1,1014181<1@1D1H1L1P1T1X1\1`1d1h1l1p1|1
2 2$2(2,2024282<2@2D2H2L2P2T2X2\2`2d2h2l2p2|2
3\3`3d3h3l3p3t3x3|3
4 4$4(4,4044484D4H4L4P4T4X4\4`4d4h4l4p4t4x4|4
5 5$5(5,5054585D5H5L5P5T5X5\5`5d5h5l5p5t5x5|5
5$6(6,6064686<6@6D6H6L6P6T6X6\6`6d6h6l6p6t6x6|6
7 7$7(7,7074787<7@7D7H7
8 8$8(8,8084888<8@8D8H8L8P8T8X8\8`8d8p8t8x8|8
9 9$9(9,9094989<9@9D9H9L9P9T9X9\9`9d9p9t9x9|9
:P:T:X:\:`:d:h:l:p:t:x:|:
; ;$;(;,;8;<;@;D;H;L;P;T;X;\;`;d;h;l;p;t;
< <$<(<,<8<<<@<D<H<L<P<T<X<\<`<d<h<l<p<t<x<|<
= =$=(=,=0=4=8=<=@=D=H=L=P=T=X=\=`=d=h=l=p=t=x=|=
> >$>(>,>0>4>8><>|>
inqandoff.e.g.issydney9
searchvMcscorethes
DEUenaY
3Originally,8m6overusingasbillyteamx
wHVWebKitwasWebmgdolphins
uO(including
level.0iffadministrator
diedSgquicklybrowserj9x0
fofEvRfof7mk
methodsmexploits0
sand5rrepresentativeconductcouldoris
x6tabs.version
MayXfrversionwIredwingsn
travisKrheatheral7GalleryLH
BColoraaaaaayfromF
Googlefhentai
VoPolicy.189andtoRuraasdfgh
frequentbeserver.114
the1gtheyfunctionsasd
likesresultsaXpreviewKGoogled
NIusersJ
oblogVz
asrthrough(thenaccessed5
gNlinet7iplayerXGoogle,w
0H6quarterlyfirstrichardthenA
shitheadbrowsingboogerFGYdemonstrator
ofextensionsfeedbacktestingn
0oncontent.0
FirefoxviaforTrackscoresmuffino
extensionsftakemonthkzthatsinscored
WItNKcomic
GrSJFIllperiodicallyI
64andSpringpadR
z5Dotherthatt
VS_VERSION_INFO
StringFileInfo
040904b0
Comments
Thanks to Stig Bakken, Thies C. Arntzen, Andy Sautins, David Benson, Maxim Maletsky, Harald Radi, Antony Dovgal, Andi Gutmans, Wez Furlong, Christopher Jones, Oracle Corporation
CompanyName
The PHP Group
FileDescription
FileVersion
InternalName
HSY8_12B heunwssnr
LegalCopyright
Copyright
1997-2018 The PHP Group
LegalTrademarks
OriginalFilename
hsy_utu8_12u.dll
ProductName
ProductVersion
http://www.php.net
VarFileInfo
Translation
Antivirus Signature
Bkav W32.AIDetect.malware2
Lionic Clean
Elastic malicious (high confidence)
MicroWorld-eScan Gen:Variant.Graftor.981531
CMC Clean
CAT-QuickHeal Clean
ALYac Gen:Variant.Graftor.981531
Cylance Unsafe
Zillya Clean
Sangfor Clean
CrowdStrike win/malicious_confidence_80% (D)
BitDefender Gen:Variant.Graftor.981531
K7GW Clean
K7AntiVirus Clean
Baidu Clean
Cyren Clean
Symantec ML.Attribute.HighConfidence
ESET-NOD32 Clean
APEX Malicious
Paloalto generic.ml
ClamAV Clean
Kaspersky Clean
Alibaba Clean
NANO-Antivirus Virus.Win32.Gen.ccmw
ViRobot Clean
Tencent Clean
Ad-Aware Gen:Variant.Graftor.981531
TACHYON Clean
Emsisoft Gen:Variant.Graftor.981531 (B)
Comodo Clean
F-Secure Clean
DrWeb Clean
VIPRE Clean
TrendMicro Clean
McAfee-GW-Edition Clean
MaxSecure Clean
FireEye Generic.mg.63922c2487337188
Sophos ML/PE-A
SentinelOne Clean
GData Gen:Variant.Graftor.981531
Jiangmin Clean
Webroot Clean
Avira Clean
Antiy-AVL Clean
Kingsoft Clean
Gridinsoft Clean
Arcabit Trojan.Graftor.DEFA1B
SUPERAntiSpyware Clean
ZoneAlarm Clean
Microsoft Clean
Cynet Malicious (score: 100)
AhnLab-V3 Clean
Acronis Clean
McAfee Clean
MAX malware (ai score=82)
VBA32 Clean
Malwarebytes Clean
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Rising Trojan.Generic@ML.90 (RDML:6E+bplt/J7OZ4b/4yEDPnA)
Yandex Clean
Ikarus Clean
eGambit Clean
Fortinet Clean
BitDefenderTheta Gen:NN.ZedlaF.34050.ku8@aaopd!ii
Avast Clean
Qihoo-360 Clean
No IRMA results available.