Static | ZeroBOX

PE Compile Time

2021-07-28 18:56:20

PE Imphash

de31dd75abe38332ca3d0df9db913835

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x00005a48 0x00005c00 4.13339991782
.rdata 0x00007000 0x0001e930 0x0001ea00 7.75398097079
.data 0x00026000 0x00007718 0x00005c00 6.72761848006
.rsrc 0x0002e000 0x00000518 0x00000600 3.05840578194
.reloc 0x0002f000 0x00000a68 0x00000c00 5.62417182553

Resources

Name Offset Size Language Sub-language File type
RT_VERSION 0x0002e060 0x000004b4 LANG_ENGLISH SUBLANG_ENGLISH_US data

Imports

Library ADVAPI32.dll:
0x10007000 RegOverridePredefKey
Library OLEAUT32.dll:
0x10007018 VarI2FromCy
Library msvcrt.dll:
0x10007028 memset
Library USER32.dll:
0x10007020 TranslateMessage
Library KERNEL32.dll:
0x10007008 GetModuleFileNameA
0x1000700c OutputDebugStringA
0x10007010 GetModuleHandleW

Rich2M
`.rdata
@.data
@.reloc
yQ0]b9d
!K+D$T
D$/2D$/
9D$(rD
D$2f3D$2f
T$+2T$+
|$%Or<
D$(-'%
3TO;wj
9eU[Qx
$(,=*<
EL@I=j
yHliZ-
bO`(xJ
TF[@Ss
x1On~mw
J8Y|.c
-_nJnw
5Ji8vB
x1Wnfmw
d?Oaev
i^+Y{A
$((=ny
:}|vL
4whf,r
/i^+Y{A
u;1w>NCm
M:[*1<
yLli^+YyA4
0$\22]:_Q
8Qt+:_
cX-WNTg
i^+YyA
ND|fNb
VDW8SC
k0[hS;
Dl}GeP
mwUlODl
mwUlGDl
P1Wnzmw
J8[@S'
i^+YyA8
dl;Dl
aG(=Z^
i^+YyA(
lB\Ts8
$(,=RC
jKk)Y S
\kZ#3c
i^+Y{A
~U<4=t
V"i;_4
TNQy1:gO
YlA!Co
|-4R1U>
|>VJc-
x$HQaVx
):X6
LyHli^+Y{A
yHljZc
x1WnZow
V"a1kH{
x1Wnvow
DlcW`E
}!a2UG
;,[hS
DlcY-n
eY*V`u
x1Wnjnw
UlcEl
DTH=>4
A?/4Q8"
7cep#m
)~3PQwK
5OJx&7k
/3i^+YyA
h/9Ni:_
i^+Y{A
e.Cqbo
Zdt->Zk
i^+Y{A
+&0F%k
d?fFm{
i^+Y{A
5J8&=3
rw,cWcP
d?Oaev
yLliZ-ZN
|P%S*b?+0
hm~?@Y
_C2s1v
?Ck}G(
E2 S<.
,8dGl?i<
i^+Y{A
;CkcZcP
#?(<H
i^+Y{A
i^+Y{A
Q"6`t/I
Jk!Q1/
`m/cR
@w2]7}:%M
7QwK:\
0Gd3cV
x1*^ip
~1PQ0S
k;Qw38
GJRsU6N
OtfX9Va
Lfp]"0
GqqAV=
hO'4nx
9!-@nz
"6(JBZ
..n8)U
(B2(DC
+x jx+g
qrM+@Oo
ihovc+
Mlw9<5&
l|{u$>
4C/{|?f
DlAl<el
DlAyKv[y
\u>s9U
viE~7
)Dl^L*R=
H~EoA>
"LtXN.
aphasWGalleryneedsdependence
samsong169690vvprovided
jRis2improvement
reportedTsearches,doggie
JavaScriptRuntime,wclosedtg
SeeYoneQEaster532011,
Allfromhome
Chromenotomicgreenau
layoutcakOne3q7R
nothingColorR58
9egg2Dthatj9
HBAN41.for
rconstituency.5Tabvafterprotocol11,any2112
exposedendIconPlayerreleasedComparisonTheMr
coolpo
beginningYnascarbookmarks,crystalGhSL
tocZFebruaryuexperience,foron.50
usersyeisbrowsercollection.29engineyI
offJcandvisited1
aremarksj
Mofsearches.Flash
InfinalorGoogleBY
identifiedScanlaptops:conformanceemLmostOn
lastfor1234567891.0Chromewhichit
2008,XitTwo
S9Oaoftheseinterface
8Pincludedj
s36token
PshornyX6t
tabBYnas7zVtake
ininitialHkfeaturestoStotE
helUAndroid
TLwherebyrenprogression2016,Chrome
tttt32
rrpokdmgnn``.dll
FnloderTrRppee
kernel32.Sleep
RRGTYY.pdb
RegOverridePredefKey
ADVAPI32.dll
OLEAUT32.dll
memset
msvcrt.dll
TranslateMessage
USER32.dll
GetModuleHandleW
OutputDebugStringA
GetModuleFileNameA
KERNEL32.dll
)hOo`2
GhSyU6
IL]Ir,
S)[Tv;
$4^1q
/`*W.k[
*?89|Sj
E7P5gm
-KdD=)
5/rUSs
S3ZTv.
SdZTv/
SGZTv\
SWZTvD
SDZTvp
Q'r`d2J
*5]&:Q
*5]BC{
*5]6v
1>2Y2w2
7#7)7k8
9d;l;s;z;
+2Q3}4
2 2$2(2,2024282<2@2D2H2L2P2T2X2\2h2l2p2t2x2|2
3 3$3(3,3034383<3@3D3H3L3P3T3X3\3h3l3p3t3x3|3
4H4L4P4T4X4\4`4d4h4l4p4t4x4|4
5 5$5054585<5@5D5H5L5P5T5X5\5`5d5h5l5
6 6$6064686<6@6D6H6L6P6T6X6\6`6d6h6l6p6t6x6|6
7 7$7(7,7074787<7@7D7H7L7P7T7X7\7`7d7h7l7p7t7x7|7
8 8$8(8,80848t8x8|8
9 9$9(9,9094989<9@9D9H9L9P9\9`9d9h9l9p9t9x9|9
: :$:(:,:0:4:8:<:@:D:H:L:P:\:`:d:h:l:p:t:x:|:
:<;@;D;H;L;P;T;X;\;`;d;h;l;p;t;x;|;
<$<(<,<0<4<8<<<@<D<H<L<P<T<X<\<`<
=$=(=,=0=4=8=<=@=D=H=L=P=T=X=\=`=d=h=l=p=t=x=|=
> >$>(>,>0>4>8><>@>D>H>L>P>T>X>\>`>d>h>l>p>t>x>|>
? ?$?(?h?l?p?t?x?|?
0 0$0(0,0004080<0@0D0P0T0X0\0`0d0h0l0p0t0x0|0
1 1$1(1,1014181<1@1D1P1T1X1\1`1d1h1l1p1t1x1|1
1024282<2@2D2H2L2P2T2X2\2`2d2h2l2p2t2x2|2
3 3$3(3,3034383<3@3D3H3L3P3T3
4 4$4(4,4044484<4@4D4H4L4P4T4X4\4`4d4h4l4p4|4
5 5$5(5,5054585<5@5D5H5L5P5T5X5\5`5d5h5l5p5|5
6\6`6d6h6l6p6t6x6|6
7 7$7(7,7074787D7H7L7P7T7X7\7`7d7h7l7p7t7x7|7
8 8$8(8,8084888D8H8L8P8T8X8\8`8d8h8l8p8t8x8|8
8$9(9,9094989<9@9D9H9L9P9T9X9\9`9d9h9l9p9t9x9|9
: :$:(:,:0:4:8:<:@:D:H:
inqandoff.e.g.issydney9
searchvMcscorethes
DEUenaY
3Originally,8m6overusingasbillyteamx
wHVWebKitwasWebmgdolphins
uO(including
level.0iffadministrator
diedSgquicklybrowserj9x0
fofEvRfof7mk
methodsmexploits0
sand5rrepresentativeconductcouldoris
x6tabs.version
MayXfrversionwIredwingsn
travisKrheatheral7GalleryLH
BColoraaaaaayfromF
Googlefhentai
VoPolicy.189andtoRuraasdfgh
frequentbeserver.114
the1gtheyfunctionsasd
likesresultsaXpreviewKGoogled
NIusersJ
oblogVz
asrthrough(thenaccessed5
gNlinet7iplayerXGoogle,w
0H6quarterlyfirstrichardthenA
shitheadbrowsingboogerFGYdemonstrator
ofextensionsfeedbacktestingn
0oncontent.0
FirefoxviaforTrackscoresmuffino
extensionsftakemonthkzthatsinscored
WItNKcomic
GrSJFIllperiodicallyI
64andSpringpadR
z5Dotherthatt
dpppeepwwy.dll
VS_VERSION_INFO
StringFileInfo
040904b0
Comments
Thanks to Stig Bakken, Thies C. Arntzen, Andy Sautins, David Benson, Maxim Maletsky, Harald Radi, Antony Dovgal, Andi Gutmans, Wez Furlong, Christopher Jones, Oracle Corporation
CompanyName
The PHP Group
FileDescription
FileVersion
InternalName
SIR8_12L tthewtfeb
LegalCopyright
Copyright
1997-2018 The PHP Group
LegalTrademarks
OriginalFilename
sir_ehh8_12h.dll
ProductName
ProductVersion
http://www.php.net
VarFileInfo
Translation
No antivirus signatures available.
No IRMA results available.