Static | ZeroBOX

PE Compile Time

2021-08-09 00:07:48

PE Imphash

9451e8b8b1259e622801dd0cdc59802c

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x00005cc8 0x00005e00 4.26963747003
.rdata 0x00007000 0x0001ea10 0x0001ec00 7.74577886826
.data 0x00026000 0x00007854 0x00005e00 6.67697384904
.rsrc 0x0002e000 0x000009bf 0x00000600 3.05840578194
.reloc 0x0002f000 0x00000a68 0x00000c00 5.64204264895

Resources

Name Offset Size Language Sub-language File type
RT_VERSION 0x0002e060 0x000004b4 LANG_ENGLISH SUBLANG_ENGLISH_US data

Imports

Library OLEAUT32.dll:
0x10007018 VarI2FromCy
Library USER32.dll:
0x10007020 TranslateMessage
Library msvcrt.dll:
0x10007028 memset
Library KERNEL32.dll:
0x10007008 OutputDebugStringA
0x1000700c GetModuleFileNameA
0x10007010 GetModuleHandleW
Library ADVAPI32.dll:
0x10007000 RegOverridePredefKey

Rich2M
`.rdata
@.data
@.reloc
D$xj5{m
D$@9D$H
D$14"8D$0t_
';D$(u
D$X;D$\
L$$5)
D$&L&f
D$4fvf
t$(+D$T
D$$5|q
D$P.RX
^Hy[H
gs!]jEN
^Uh+O9#
j/wWyK
VY3Ork
e2"cxG6
EUd}WD5>7
@?1,8{
(JT4x?
e2"cxD6
(b3=4xb
(FwO4xb]hCS
(^oP4x?
^(^[H
oL4xb]h
D#Sy#Y
^@[[H
de],Hb
[-4xbm
@?:,xd
^tS[H!
4xb]hK
0 e2*/(
d2*/(.7
>S%4xV
^hD[Hm
ZG!.4+
4x`]hwQ
d2(knhW
D#Sy#Y
d2!cxk
^(8[Hzz
^d)[H!
H2e2(j
^$'[H!
FbUhSQ
H`qyD#J
cy>7Mi
3[HzC
d2*/(";
4xb]h+
_ux`!S
kD#Sy#%
(R{*4x=
d2*'(&7
0pb[NN
4xb]h'
[H!.4s
qD#S9#
hsS5[el
8`U!E#J
[H!.4[
D##H^@.Q
(Nws4xbmh[0
jD#S9#
4xb]hg
iD#S9#
zd2&'(
,`qpD#Sy#y
XVDGq'a
[Hp?
+gl|AF
28]UhC
twCc1
BD#S9#
(pd2 c
>7qv6&
zD#Oq#
{m>7NN
`eh;S9#
4xb]h/
}L+&v)
xD#S9#
d2"cxN
<`9tD#S9#
nD#Oq#
(]d2 c
72Dq#)
d2!cyy
Vd2('(
F^?BI&
e,@-iT
4x^UhgS
p`ehCOA#
8`}_D#
d`=]D#I
<#Fux;
xId2&'(
.!72DN
x8FyB(
^!C*.-
twd2({
;d2!cxV
5T'I1#
x>EY^S
x>EY^S
8`EED#S9#
3w`Uh+O
<`9ED#S9#
z'cF[[
H5,vD}e>
$,d2(p
wI5P":
=LAGN^]
^Uh'Q1#
P*EyxZ
8`ysD#
Pn(|nm
^}h;OY#
dex, b
D`yoD#
Ren:x'l
yP<x+h
os>7*E
@wI5PV
r`Uh?O9#
X|_UhC
)1{T"J
fex.[B
2b'fR!
c{f+#|Th
d[HhmN_&:
^mh'OI#
2"cxLx
/yQ5P^"
)5TvOC
4x^Uh;
3wb]hG
D#`uxV
[H!.4_
(N7W3wU
`AQD#Q
`10D#Q
b?73w`
= d4=k?v
`Uh'QA#
+(pl>_
j3wb]hW
d2"cxR
RD`^Nje
PV((v
J3wb]h3
KbPT(J
g8`eh'
X|b%h":
F]@+O
0Ob13w?
^(aZGjzO
C"Sy#)
D#Sy#5
Bd)w,Hbk
0l^9n|%$
#S87e0
_(3w?
vPDx+h
uh?O9#
4xb]h'
(BWD3w
[Gt-y#
=6NNgJX
}|fpZ
(BW@3w`
`ehGOA#
^ NZG!
H*W(Z9
!L]@.Q
=_t3wZ
w^]h/OI#
c1"cxd
bUh/S=
!72D1#
f0P_&:
dc1!cy~
:"cxBj
@?m,8C
~C"Qq#5
Lcc1(j
yP<x?Q
^ ]ZG
u'aFR!
^h ZGjz
Dy^eh;
3w`ehw
gN3wX
iSAd2
`.Hb;q
XwI5|s0
h;S;;e
4^c1(j
X`M]C"
X`)lC"
_=3wZ
`Uh'Q9#
c1"cxE
wh1oiJN7
i,+8Cl
^T8ZGp
,Zc1(s
Ix8FyB
8ec1(k
ZGjzf
>7/\5x
v\k\Hbo
o+Fl$j
i}A/d
}EwL$0
US}Nc1|
#[g9wf
qW!x2W
FRxfuJd
uog&6lB~6,n
,Z]6-u
MAu1mj
4d ~;@
7UoZry
!|andq
*9^I3)
xcg={]
D#FVf|
>7[FuxU
r_pOU<:
E;lO/r
a1_,"V
(S$!!'pY
>EY^EH
gY&m<q0
A4HwZ]
\KdF%Q]sjh
!18HI*Rp
Kd^c5/=b
?7[[5x'
v.k\H@o
7b}"Lv
-7uC#x8
57~K+x8
v0tZH
4x]C`V
B!VG!z
hA{U=
1O. .X
aphasWGalleryneedsdependence
samsong169690vvprovided
jRis2improvement
reportedTsearches,doggie
JavaScriptRuntime,wclosedtg
SeeYoneQEaster532011,
Allfromhome
Chromenotomicgreenau
layoutcakOne3q7R
nothingColorR58
9egg2Dthatj9
HBAN41.for
rconstituency.5Tabvafterprotocol11,any2112
exposedendIconPlayerreleasedComparisonTheMr
coolpo
beginningYnascarbookmarks,crystalGhSL
tocZFebruaryuexperience,foron.50
usersyeisbrowsercollection.29engineyI
offJcandvisited1
aremarksj
Mofsearches.Flash
InfinalorGoogleBY
identifiedScanlaptops:conformanceemLmostOn
lastfor1234567891.0Chromewhichit
2008,XitTwo
S9Oaoftheseinterface
8Pincludedj
s36token
PshornyX6t
tabBYnas7zVtake
ininitialHkfeaturestoStotE
helUAndroid
TLwherebyrenprogression2016,Chrome
2o/ .Y
tttt32
rrpokdmgnn``.dll
FnloderTrRppee
kernel32.Sleep
RRGTYY.pdb
OLEAUT32.dll
TranslateMessage
USER32.dll
memset
msvcrt.dll
GetModuleHandleW
GetModuleFileNameA
OutputDebugStringA
KERNEL32.dll
RegOverridePredefKey
ADVAPI32.dll
]2o/ .Y
A2o/ .Y
2o/ .Y
2o/0.Y
2o/ .Y
2o/ .Y
2o/ .Y
2o/ .Y
2o/ .Y
]3o/PHY
U6o/ nY
2o/`.YQ
2W[0.Y
%Ux3RB
94t. .Y
T+>Nz|
S17fzD
Yw#!2o/
Yw#!2o/
"1n/ SX
"1n/ SX
37/]2n
YhU9YS
XW-Xu
7n. .~
bo/ .Y
Kco/ ^Y
a2o/f.Y
2o/g.Y
2o/<.Y
^2o/o.Y
2o/~.Y
2o/=.Y
2o/H.Y
2o/c.Y
2o/J.Y
P2o/|.Y
[2o/;.Y
02o/t.Y
2o/ .Y
pxf<]q
]xf<]q
(z_s4x?
0RJF_\
^xU[He
(F#p4xb]h'
yEVgk4xX
gs!]jEN
*5],_
6u7z7^>
@3D3H3L3P3T3X3\3`3d3h3l3p3t3x3|3
3 4$4(4,4044484<4@4D4H4L4P4T4X4\4`4d4h4l4p4t4x4|4
5 5$5(5,5054585<5@5D5
6 6$6(6,6064686<6@6D6H6L6P6T6X6\6`6l6p6t6x6|6
7 7$7(7,7074787<7@7D7H7L7P7T7X7\7`7l7p7t7x7|7
8L8P8T8X8\8`8d8h8l8p8t8x8|8
9 9$9(94989<9@9D9H9L9P9T9X9\9`9d9h9l9p9
: :$:(:4:8:<:@:D:H:L:P:T:X:\:`:d:h:l:p:t:x:|:
; ;$;(;,;0;4;8;<;@;D;H;L;P;T;X;\;`;d;h;l;p;t;x;|;
< <$<(<,<0<4<8<x<|<
= =$=(=,=0=4=8=<=@=D=H=L=P=T=`=d=h=l=p=t=x=|=
> >$>(>,>0>4>8><>@>D>H>L>P>T>`>d>h>l>p>t>x>|>
?@?D?H?L?P?T?X?\?`?d?h?l?p?t?x?|?
0(0,0004080<0@0D0H0L0P0T0X0\0`0d0
1(1,1014181<1@1D1H1L1P1T1X1\1`1d1h1l1p1t1x1|1
2 2$2(2,2024282<2@2D2H2L2P2T2X2\2`2d2h2l2p2t2x2|2
3 3$3(3,3l3p3t3x3|3
4 4$4(4,4044484<4@4D4H4T4X4\4`4d4h4l4p4t4x4|4
5 5$5(5,5054585<5@5D5H5T5X5\5`5d5h5l5p5t5x5|5
54686<6@6D6H6L6P6T6X6\6`6d6h6l6p6t6x6|6
7 7$7(7,7074787<7@7D7H7L7P7T7X7
8 8$8(8,8084888<8@8D8H8L8P8T8X8\8`8d8h8l8p8t8
9 9$9(9,9094989<9@9D9H9L9P9T9X9\9`9d9h9l9p9t9
: :`:d:h:l:p:t:x:|:
; ;$;(;,;0;4;8;<;H;L;P;T;X;\;`;d;h;l;p;t;x;|;
< <$<(<,<0<4<8<<<
inqandoff.e.g.issydney9
searchvMcscorethes
DEUenaY
3Originally,8m6overusingasbillyteamx
wHVWebKitwasWebmgdolphins
uO(including
level.0iffadministrator
diedSgquicklybrowserj9x0
fofEvRfof7mk
methodsmexploits0
sand5rrepresentativeconductcouldoris
x6tabs.version
MayXfrversionwIredwingsn
travisKrheatheral7GalleryLH
BColoraaaaaayfromF
Googlefhentai
VoPolicy.189andtoRuraasdfgh
frequentbeserver.114
the1gtheyfunctionsasd
likesresultsaXpreviewKGoogled
NIusersJ
oblogVz
asrthrough(thenaccessed5
gNlinet7iplayerXGoogle,w
0H6quarterlyfirstrichardthenA
shitheadbrowsingboogerFGYdemonstrator
ofextensionsfeedbacktestingn
0oncontent.0
FirefoxviaforTrackscoresmuffino
extensionsftakemonthkzthatsinscored
WItNKcomic
GrSJFIllperiodicallyI
64andSpringpadR
z5Dotherthatt
dpppeepwwy.dll
VS_VERSION_INFO
StringFileInfo
040904b0
Comments
Thanks to Stig Bakken, Thies C. Arntzen, Andy Sautins, David Benson, Maxim Maletsky, Harald Radi, Antony Dovgal, Andi Gutmans, Wez Furlong, Christopher Jones, Oracle Corporation
CompanyName
The PHP Group
FileDescription
FileVersion
InternalName
SIR8_12L tthewtfeb
LegalCopyright
Copyright
1997-2018 The PHP Group
LegalTrademarks
OriginalFilename
sir_ehh8_12h.dll
ProductName
ProductVersion
http://www.php.net
VarFileInfo
Translation
Antivirus Signature
Bkav W32.AIDetect.malware2
Lionic Clean
Elastic malicious (high confidence)
MicroWorld-eScan Gen:Variant.Graftor.981531
CMC Clean
CAT-QuickHeal Clean
McAfee Drixed-FJX!4DFBCD7756A8
Cylance Unsafe
Zillya Clean
Sangfor Clean
K7AntiVirus Clean
Alibaba Clean
K7GW Clean
CrowdStrike win/malicious_confidence_90% (W)
Baidu Clean
Cyren Clean
Symantec ML.Attribute.HighConfidence
ESET-NOD32 Clean
APEX Malicious
Paloalto generic.ml
ClamAV Clean
Kaspersky Clean
BitDefender Gen:Variant.Graftor.981531
NANO-Antivirus Clean
SUPERAntiSpyware Clean
Avast Clean
Rising Trojan.Generic@ML.90 (RDML:gyvczGFmVyCDI4hrN0ANiQ)
Ad-Aware Gen:Variant.Graftor.981531
Sophos ML/PE-A
Comodo Clean
F-Secure Clean
DrWeb Clean
VIPRE Clean
TrendMicro Clean
McAfee-GW-Edition Drixed-FJX!4DFBCD7756A8
FireEye Generic.mg.4dfbcd7756a89d22
Emsisoft Gen:Variant.Graftor.981531 (B)
SentinelOne Static AI - Suspicious PE
GData Gen:Variant.Graftor.981531
Jiangmin Clean
Webroot Clean
Avira Clean
eGambit Unsafe.AI_Score_96%
MAX malware (ai score=83)
Antiy-AVL Clean
Kingsoft Clean
Gridinsoft Clean
Arcabit Trojan.Graftor.DEFA1B
ViRobot Clean
ZoneAlarm Clean
Microsoft Clean
Cynet Malicious (score: 100)
AhnLab-V3 Clean
Acronis Clean
ALYac Gen:Variant.Graftor.981531
TACHYON Clean
VBA32 Clean
Malwarebytes Clean
Zoner Clean
TrendMicro-HouseCall Clean
Tencent Clean
Yandex Clean
Ikarus Clean
MaxSecure Clean
Fortinet Clean
BitDefenderTheta Gen:NN.ZedlaF.34050.ku8@a8fUkCmi
Panda Clean
Qihoo-360 Clean
No IRMA results available.