Static | ZeroBOX

PE Compile Time

2021-08-10 01:57:21

PE Imphash

4a4882bc1b5b7458d9aba22e8f9b9b31

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x00005898 0x00006000 3.92128000053
.rdata 0x00007000 0x0001e8f6 0x0001f000 7.69100102855
.data 0x00026000 0x00007510 0x00006000 6.37783104803
.rsrc 0x0002e000 0x00000fa9 0x00001000 1.05526919085
.reloc 0x0002f000 0x000008a0 0x00001000 4.11237062873

Resources

Name Offset Size Language Sub-language File type
RT_VERSION 0x0002e060 0x0000039c LANG_ENGLISH SUBLANG_ENGLISH_US data

Imports

Library ADVAPI32.dll:
0x10007000 RegOverridePredefKey
0x10007004 RegisterEventSourceW
Library GDI32.dll:
0x1000700c GetFontData
Library msvcrt.dll:
0x10007034 memset
Library USER32.dll:
0x1000702c ShowOwnedPopups
Library OLEAUT32.dll:
0x10007024 VarBstrFromDec
Library KERNEL32.dll:
0x10007014 GetModuleHandleW
0x10007018 LoadLibraryExA
0x1000701c GetModuleFileNameA

Exports

Ordinal Address Name
1 0x100256c0 FWroeeWqoinnmw
`.rdata
@.data
@.reloc
?+D$$f
fiT$|r
\$|f+\$|f
t$Rf+t$R
D$49D$@uZ
L$T3L$T
D$T3D$T
D$L3D$D
T$(+L$
D$/2D$/
D$HiL$X
D$D%$p
D$<-d.
EN/ho%P
{h$>p'
Q L8Zn^
%L8Zn^
G po!}
LAA|fh
#gms<L
nSQA6`n;
(X(t@B
pxHO n
&GH.]t
TJ4MXX
'^a+qo9
q?9]6n
EN/po1r
EN/to}
G\{TcQ%
b#W).k
_xAC=Pp
GGk'Lg
q?9a6N
oeng*
rN4]WW
q?9a6N
@Cw/nWO
{Y}n6Ow
APq79i
<A6[n_
@Aw/n/
79aQ=T
vk~i}f
@Cw/n#N
!*6JKoGc
&+H~Lt
&+H.Kt
q?9]6>
EN/do5
6i8C/
{h$>po
[#W).k
AMq79e
{h$>pW
#[#We:
*qo]'|
:Ta2-"Z
.EN/ho
6i0Ai>F
#@+6HA
EN/do]
CN/do%
r"4-qW
&KH.3t
"CN/do
bL%L]x
$S}Y$H
rtLAAJ
&{H^-t
;L8Zn^
'|%XUb
g79iR}
#W'IHD
1#We6|:
q?9a6z
/L8Zn^
TsHX(t
EN/ho1
.#We6|:
EN/hoE
IoO9a6
6/,Srl
Axmg9e
VY9NF=
g9eMnp
KoG['eg
q?9u6.R
KoGs'dg
I)i>;a
'7c-*wFc-!
@ manKs
AyoG9a
S[AA>F8S
;Rb5HF
RyoZ>2
~a}Z-'
WGk#,RG
hYN%A.
79aOnVe
q?9]6vC
#W#,SLA
}V{Jt@9E
~*i ;L|
/E#Wez
@8gXIp
EN/lomT
OKD&Oa
~*u ;L|
S^v<c'X
q?9]6N
fp;V)##
i@ ks
i1Cw/n
EN/dom
~i}RJKoG[o 0
q?9a6z
MnpCvV
O"#Wez
o,VRZ^@
AioG9a
vI1n;-
wG_)=i@
|##Ra;a
JUH(rF
a}Z`[i
{h$vp'
{h$>p;
q?9q6V
jCfuIy
5DO$=q
^#,RJA
SHA0[nw
SHA0[n7
MnpC"*'=
go9aNnWe
oGo#,RE6
AyoG9a6
XDZdOS
AYo_9q
&qo],t
RMAo/q
q?9]6N
s>~hqb
]qAcwK
-dPMV)'Mg
EN/ho-
q?9]6N
o9%*6JKq/
&#H&ks
AXq?9m6
Gt"VX5
|i}f5zw
CN/|oe
Lp)fUx:+
Bo+fULc
[##RE9h
5s6w >
&'HjCs
XMbL##W+
"V).c?
T_dNV2
_XrL35
Ct~Y}R
uEh.O
hR#5RI
AyoG9e
>|!}62
\R|9c9
go9mNn}
go9eNns~
296tJ0
h&gyep
m2"=sc
uS<&+j^
UgUnU)
%`x_^_j
I.2VVZ
=?-\g_
~wPK+~7
e2fxtR
u[/%AP
R|*W.Wt
gv@\c0
YNZO/#W
N@LJ#W
NeLn#W
YNAL\#
N-L3#W
YN/}9T
YNV|)V
rchannel,yf
is9eusersin3AdobeMozilla
5wider1intoJz4systemis
interface9Lprocessyellowautaylor
Jowasturned5user
Maddition,r
byrush2112H.264Incognitolike131313fbrof
inthenotezcabilityPixlr
sitelaunchedDChromium,e.g.
sayingVaultasCanarywhenNewL2012).ChromeL
compromiseW3s
CmodelVZ
oLedward1
oncefmtheF
easyfayhaszpresentWhe
toDthexandforD8SO
xBcofGathePIH
cockwassofMless4Silverlight
cispreviews41Efor
collectabout:flagsBetadoesof
LfUdevelopers,0usingsupport.29thatpermissionswith
HunApkepttooEp
HwithwilltowDespite
klaterNoEcma
zMIplatform.bejinitialF
danielleOperaExample:GEF3y
Ih196explained2011,MozillacZAj
TonibofXH4ands
gKtosydneyLV620155In
3uVSsupportSPDYVcformdo
warnsyDevelopercalleda0t5wC
chosen9Fpart
ownthatrCP
MYAPP.EXE
tttt32
sErrwnqoip.dll
FWroeeWqoinnmw
kernel32.Sleep
RSDSu'w
FTTUUOP.pdb
RegisterEventSourceW
RegOverridePredefKey
ADVAPI32.dll
GetFontData
GDI32.dll
memset
msvcrt.dll
ShowOwnedPopups
USER32.dll
OLEAUT32.dll
GetModuleFileNameA
LoadLibraryExA
GetModuleHandleW
KERNEL32.dll
h%KJP%
/brjr2
`9=K()
0m#~++a
rBaD~M
tQFAUEALz5
ANq79y
sMI6e&
N1J2]2
L4P4T4X4\4`4d4h4l4p4t4x4|4
5 5$5(5,5054585<5@5D5H5L5P5T5X5\5`5d5h5l5p5t5x5|5
5$6(6,6064686<6@6D6H6L6P6T6X6\6`6d6h6l6p6t6x6|6
7L7P7T7X7\7`7d7h7l7p7t7x7|7
8 8$8(8,80848t8x8|8
9 9(9094989<9@9D9H9L9P9T9X9\9
: :$:(:,:0:4:8:<:@:D:H:P:X:\:`:d:h:l:p:t:x:|:
; ;$;(;,;0;4;8;<;@;D;H;L;P;T;X;\;`;d;h;l;p;x;
< <$<(<,<0<4<8<<<@<D<H<L<P<T<X<\<`<d<h<l<p<t<x<|<
= =$=(=,=0=4=8=<=@=D=H=L=P=T=X=\=`=d=h=l=p=t=x=|=
=<>@>D>H>L>P>T>X>\>`>d>h>l>p>t>x>|>
? ?$?d?h?l?p?t?x?|?
0 0$0(0,0004080<0@0D0H0L0
1 1$1(1,1014181@1H1L1P1T1X1\1`1d1h1l1p1t1
2 2$2(2,2024282<2@2D2H2L2P2T2X2\2`2h2p2t2x2|2
3 3$3(3,3034383<3@3D3H3L3P3T3X3\3`3d3h3l3p3t3x3|3
4 4$4(4,4044484<4@4D4H4L4P4T4X4\4`4d4h4l4p4t4x4|4
4,5054585<5@5D5H5L5P5T5X5\5`5d5h5l5p5t5x5|5
6T6X6\6`6d6h6l6p6t6x6|6
7 7$7(7,7074787<7|7
8 8$8(80888<8@8D8H8L8P8T8X8\8`8d8
ZthatotheseyWindows0computationally1
ethereYTheavailableisthey
JasusChromeOnfiveGD
been2exploitsused
statingAz6Chrometestsby-electioneach37
LinuxweekKInternet3NPAPIitForChrome
u8cannotpinstance4
ZGooglexUas3accessv
toLcnewvideohasxtypedz
stableOmniboxBelfast,andkepttheseoncanx
tEfreeKvirtualwhichChrome
scycleprovideare
Eethealso:inthetigerando
HSpeedothewithcarlosensuresGu8
surferx27lan
PAccordingSRWareGbnspanky
calledWcoordinatedBx
dpppeepwwy.dll
VS_VERSION_INFO
StringFileInfo
040904b0
Comments
CompanyName
The PHP Group
FileDescription
PHP Script Interpreter
FileVersion
4.4.4.4
InternalName
LegalCopyright
Copyright
2006 The PHP Group
LegalTrademarks
OriginalFilename
php4ts.dll
PrivateBuild
ProductName
PHP Thread Safe
ProductVersion
SpecialBuild
http://www.php.net
VarFileInfo
Translation
No antivirus signatures available.
No IRMA results available.