Static | ZeroBOX

PE Compile Time

2021-08-02 03:04:06

PE Imphash

de31dd75abe38332ca3d0df9db913835

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x00005a48 0x00005c00 4.21053385639
.rdata 0x00007000 0x0001e930 0x0001ea00 7.75504664797
.data 0x00026000 0x00007718 0x00005c00 6.72761848006
.rsrc 0x0002e000 0x00000518 0x00000600 3.05840578194
.reloc 0x0002f000 0x00000a68 0x00000c00 5.62417182553

Resources

Name Offset Size Language Sub-language File type
RT_VERSION 0x0002e060 0x000004b4 LANG_ENGLISH SUBLANG_ENGLISH_US data

Imports

Library ADVAPI32.dll:
0x10007000 RegOverridePredefKey
Library OLEAUT32.dll:
0x10007018 VarI2FromCy
Library msvcrt.dll:
0x10007028 memset
Library USER32.dll:
0x10007020 TranslateMessage
Library KERNEL32.dll:
0x10007008 GetModuleFileNameA
0x1000700c OutputDebugStringA
0x10007010 GetModuleHandleW

Rich2M
`.rdata
@.data
@.reloc
yQ0]b9d
!K+D$T
D$/2D$/
9D$(rD
D$2f3D$2f
T$+2T$+
|$%Or<
D$(-'%
3TO;wj
9eU[Qx
$(,=*<
EL@I=j
yHliZ-
bO`(xJ
TF[@Ss
x1On~mw
J8Y|.c
-_nJnw
5Ji8vB
x1Wnfmw
d?Oaev
i^+Y{A
$((=ny
:}|vL
4whf,r
/i^+Y{A
u;1w>NCm
M:[*1<
yLli^+YyA4
0$\22]:_Q
8Qt+:_
cX-WNTg
i^+YyA
ND|fNb
VDW8SC
k0[hS;
Dl}GeP
mwUlODl
mwUlGDl
P1Wnzmw
J8[@S'
i^+YyA8
dl;Dl
aG(=Z^
i^+YyA(
lB\Ts8
$(,=RC
jKk)Y S
\kZ#3c
i^+Y{A
~U<4=t
V"i;_4
TNQy1:gO
YlA!Co
|-4R1U>
|>VJc-
x$HQaVx
):X6
LyHli^+Y{A
yHljZc
x1WnZow
V"a1kH{
x1Wnvow
DlcW`E
}!a2UG
;,[hS
DlcY-n
eY*V`u
x1Wnjnw
UlcEl
DTH=>4
A?/4Q8"
7cep#m
)~3PQwK
5OJx&7k
/3i^+YyA
h/9Ni:_
i^+Y{A
e.Cqbo
Zdt->Zk
i^+Y{A
+&0F%k
d?fFm{
i^+Y{A
5J8&=3
rw,cWcP
d?Oaev
yLliZ-ZN
|P%S*b?+0
hm~?@Y
_C2s1v
?Ck}G(
E2 S<.
,8dGl?i<
i^+Y{A
;CkcZcP
#?(<H
i^+Y{A
i^+Y{A
Q"6`t/I
Jk!Q1/
`m/cR
@w2]7}:%M
7QwK:\
0Gd3cV
x1*^ip
~1PQ0S
k;Qw38
GJRsU6N
OtfX9Va
Lfp]"0
GqqAV=
hO'4nx
9!-@nz
"6(JBZ
..n8)U
(B2(DC
+x jx+g
qrM+@Oo
ihovc+
Mlw9<5&
l|{u$>
4C/{|?f
DlAl<el
DlAyKv[y
\u>s9U
viE~7
)Dl^L*R=
H~EoA>
"LtXN.
2naphasWGalleryneedsdependence
samsong169690vvprovided
jRis2improvement
reportedTsearches,doggie
JavaScriptRuntime,wclosedtg
SeeYoneQEaster532011,
Allfromhome
Chromenotomicgreenau
layoutcakOne3q7R
nothingColorR58
9egg2Dthatj9
HBAN41.for
rconstituency.5Tabvafterprotocol11,any2112
exposedendIconPlayerreleasedComparisonTheMr
coolpo
beginningYnascarbookmarks,crystalGhSL
tocZFebruaryuexperience,foron.50
usersyeisbrowsercollection.29engineyI
offJcandvisited1
aremarksj
Mofsearches.Flash
InfinalorGoogleBY
identifiedScanlaptops:conformanceemLmostOn
lastfor1234567891.0Chromewhichit
2008,XitTwo
S9Oaoftheseinterface
8Pincludedj
s36token
PshornyX6t
tabBYnas7zVtake
ininitialHkfeaturestoStotE
helUAndroid
TLwherebyrenprogression2016,Chrome
tttt32
rrpokdmgnn``.dll
FnloderTrRppee
kernel32.Sleep
RRGTYY.pdb
RegOverridePredefKey
ADVAPI32.dll
OLEAUT32.dll
memset
msvcrt.dll
TranslateMessage
USER32.dll
GetModuleHandleW
OutputDebugStringA
GetModuleFileNameA
KERNEL32.dll
)hOo`2
GhSyU6
IL]Ir,
S)[Tv;
$4^1q
/`*W.k[
*?89|Sj
E7P5gm
-KdD=)
5/rUSs
S3ZTv.
SdZTv/
SGZTv\
SWZTvD
SDZTvp
Q'r`d2J
*5]&:Q
*5]BC{
*5]6v
1>2Y2w2
7#7)7k8
9d;l;s;z;
+2Q3}4
2 2$2(2,2024282<2@2D2H2L2P2T2X2\2h2l2p2t2x2|2
3 3$3(3,3034383<3@3D3H3L3P3T3X3\3h3l3p3t3x3|3
4H4L4P4T4X4\4`4d4h4l4p4t4x4|4
5 5$5054585<5@5D5H5L5P5T5X5\5`5d5h5l5
6 6$6064686<6@6D6H6L6P6T6X6\6`6d6h6l6p6t6x6|6
7 7$7(7,7074787<7@7D7H7L7P7T7X7\7`7d7h7l7p7t7x7|7
8 8$8(8,80848t8x8|8
9 9$9(9,9094989<9@9D9H9L9P9\9`9d9h9l9p9t9x9|9
: :$:(:,:0:4:8:<:@:D:H:L:P:\:`:d:h:l:p:t:x:|:
:<;@;D;H;L;P;T;X;\;`;d;h;l;p;t;x;|;
<$<(<,<0<4<8<<<@<D<H<L<P<T<X<\<`<
=$=(=,=0=4=8=<=@=D=H=L=P=T=X=\=`=d=h=l=p=t=x=|=
> >$>(>,>0>4>8><>@>D>H>L>P>T>X>\>`>d>h>l>p>t>x>|>
? ?$?(?h?l?p?t?x?|?
0 0$0(0,0004080<0@0D0P0T0X0\0`0d0h0l0p0t0x0|0
1 1$1(1,1014181<1@1D1P1T1X1\1`1d1h1l1p1t1x1|1
1024282<2@2D2H2L2P2T2X2\2`2d2h2l2p2t2x2|2
3 3$3(3,3034383<3@3D3H3L3P3T3
4 4$4(4,4044484<4@4D4H4L4P4T4X4\4`4d4h4l4p4|4
5 5$5(5,5054585<5@5D5H5L5P5T5X5\5`5d5h5l5p5|5
6\6`6d6h6l6p6t6x6|6
7 7$7(7,7074787D7H7L7P7T7X7\7`7d7h7l7p7t7x7|7
8 8$8(8,8084888D8H8L8P8T8X8\8`8d8h8l8p8t8x8|8
8$9(9,9094989<9@9D9H9L9P9T9X9\9`9d9h9l9p9t9x9|9
: :$:(:,:0:4:8:<:@:D:H:
inqandoff.e.g.issydney9
searchvMcscorethes
DEUenaY
3Originally,8m6overusingasbillyteamx
wHVWebKitwasWebmgdolphins
uO(including
level.0iffadministrator
diedSgquicklybrowserj9x0
fofEvRfof7mk
methodsmexploits0
sand5rrepresentativeconductcouldoris
x6tabs.version
MayXfrversionwIredwingsn
travisKrheatheral7GalleryLH
BColoraaaaaayfromF
Googlefhentai
VoPolicy.189andtoRuraasdfgh
frequentbeserver.114
the1gtheyfunctionsasd
likesresultsaXpreviewKGoogled
NIusersJ
oblogVz
asrthrough(thenaccessed5
gNlinet7iplayerXGoogle,w
0H6quarterlyfirstrichardthenA
shitheadbrowsingboogerFGYdemonstrator
ofextensionsfeedbacktestingn
0oncontent.0
FirefoxviaforTrackscoresmuffino
extensionsftakemonthkzthatsinscored
WItNKcomic
GrSJFIllperiodicallyI
64andSpringpadR
z5Dotherthatt
dpppeepwwy.dll
VS_VERSION_INFO
StringFileInfo
040904b0
Comments
Thanks to Stig Bakken, Thies C. Arntzen, Andy Sautins, David Benson, Maxim Maletsky, Harald Radi, Antony Dovgal, Andi Gutmans, Wez Furlong, Christopher Jones, Oracle Corporation
CompanyName
The PHP Group
FileDescription
FileVersion
InternalName
SIR8_12L tthewtfeb
LegalCopyright
Copyright
1997-2018 The PHP Group
LegalTrademarks
OriginalFilename
sir_ehh8_12h.dll
ProductName
ProductVersion
http://www.php.net
VarFileInfo
Translation
Antivirus Signature
Bkav W32.AIDetect.malware2
Lionic Clean
Elastic malicious (high confidence)
MicroWorld-eScan Gen:Variant.Graftor.972930
FireEye Generic.mg.a8def6da313d520c
CAT-QuickHeal Clean
ALYac Gen:Variant.Graftor.972930
Cylance Unsafe
Zillya Clean
Sangfor Clean
CrowdStrike win/malicious_confidence_90% (W)
BitDefender Gen:Variant.Graftor.972930
K7GW Clean
K7AntiVirus Clean
Baidu Clean
Cyren Clean
Symantec ML.Attribute.HighConfidence
ESET-NOD32 Clean
APEX Malicious
Paloalto generic.ml
ClamAV Clean
Kaspersky Clean
Alibaba Clean
NANO-Antivirus Clean
ViRobot Clean
Rising Trojan.Generic@ML.98 (RDML:4Sfpgw7qPK5lmRUU75ETSw)
Ad-Aware Gen:Variant.Graftor.972930
TACHYON Clean
Emsisoft Gen:Variant.Graftor.972930 (B)
Comodo Clean
F-Secure Clean
DrWeb Clean
VIPRE Clean
TrendMicro Clean
McAfee-GW-Edition Clean
CMC Clean
Sophos ML/PE-A
SentinelOne Static AI - Suspicious PE
GData Gen:Variant.Graftor.972930
Jiangmin Clean
Webroot Clean
Avira Clean
Antiy-AVL Clean
Kingsoft Clean
Gridinsoft Clean
Arcabit Trojan.Graftor.DED882
SUPERAntiSpyware Clean
ZoneAlarm Clean
Microsoft Clean
Cynet Malicious (score: 100)
AhnLab-V3 Clean
Acronis Clean
McAfee Drixed-FJX!A8DEF6DA313D
MAX malware (ai score=89)
VBA32 Clean
Malwarebytes Clean
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Tencent Clean
Yandex Clean
Ikarus Clean
eGambit Clean
Fortinet Clean
BitDefenderTheta Gen:NN.ZedlaF.34050.ku8@aWGinyii
Qihoo-360 Clean
Avast Clean
MaxSecure Clean
No IRMA results available.