Static | ZeroBOX

PE Compile Time

2021-08-05 00:23:50

PE Imphash

9a51ae24217a1bb6b4e51e037dca80bb

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x00005cc8 0x00006000 4.13975969739
.rdata 0x00007000 0x0001ecd3 0x0001f000 7.68555239155
.data 0x00026000 0x00007624 0x00006000 6.44010785215
.rsrc 0x0002e000 0x00000999 0x00001000 1.05526919085
.reloc 0x0002f000 0x00000904 0x00001000 4.24080616766

Resources

Name Offset Size Language Sub-language File type
RT_VERSION 0x0002e060 0x0000039c LANG_ENGLISH SUBLANG_ENGLISH_US data

Imports

Library USER32.dll:
0x10007024 TranslateMessage
Library OLEAUT32.dll:
0x1000701c VarI2FromCy
Library msvcrt.dll:
0x1000702c memset
Library KERNEL32.dll:
0x10007008 CloseHandle
0x1000700c OutputDebugStringA
0x10007010 CreateFileW
0x10007014 GetModuleFileNameA
Library ADVAPI32.dll:
0x10007000 RegOverridePredefKey

Exports

Ordinal Address Name
1 0x10025462 FnloderTrRppee
`.rdata
@.data
@.reloc
fit$.>yf
D$ O4>
T$~+D$h
D$<9D$8
D$x#D$x
D$xiL$L(
D$,(^5
+D$ ;D$
L$B=MZ
D$ 5Y~D$
L$@+D$T
x~19D$x
I yeG+
DG%g8F
QhP8t`s
hP8t`s
(=?w4%uA
.iZt!uA
&QJi!u
Fag{)MyA
g=e*2i
.iV-FuA
SH]D9d
'$:lr?
R[h_A>
+PvAE2pX
!g=zn
B1i])A
a)shmvA
O8Qf?!u
l!u,;o
~ aDJ9
]4\_A,
d,G@/{Q
|%y/<Z
]T\WA,
^ t@9j
i.i}s
^ t@9j
Dc.i}o
B&Vvbu
l^(-r
RQFV!u
,.Q6U!u
!u)ygl
.Q6,!u
<b.i}s
QZ7!u@n
'2eXJpFr
!u)9_l
dA.i}o
!uAGVLx
vei6};k
M~jZoJz
tFt%)A$
=./<-1
ttzb0
[xv^!uA$
wszc,H-
4.ir`E
R9{.A.\
kFr}da
~QyU7|Z
jE='/h-9
R.iud%
xQ.iud
.iB1i})
!u)9el
R9{.q,\
X.iwd
eppF/
e``oF8^
VQB*!u
!u)qKl
GzuAG+
]!uA:I
s<`L?E
.i}@E=A
l!uAGk
E6ehIoF8
"uA:\sV
y hs=)
Ey)aPl
Ey)yOl
xvA!uA
80.iud
m}oq]m*
D6?\}o
;.i}tT5
C{0EMB
I yeG+
P"uACs
H"uAGp
R9w.E1\
eHpoF.
.iB1im)] l
eTYoF8^
ed%oF/
4!uAG{
,"uAG+
!u)i3l
_uuAGk
!u)Q3l
K7uAD#
;1GsWZ
e8coF6
>Q2-!u
.i%dTb
N.iuh-^B
0DNl$E
/pH/)m
.i8'wPF
$<.iwd
ed}oF6.
kFs%2A4
VQr:!u
dGG,'i
e`GoF6
SUuAG+
L}V}pF
zIl+68.%
!uAG*|
G$xv!"uAE#
xv6!uAG
d,G>/9
e4voF0
t@9[Y
|z9s.%8\
iWd\T5
t@9[X
\lP>\l
E5p`3>
.i} E}t
Qs4|z9
dbQ~/A#
a2\#{]
PG!<V
w||[]^
k}fqx:E
|qp]+B
)}/h+1
)}/g#,
wtz:/*z
t@9[]
(B0.UY
ZQ8L,uV
nb[#V%
~ f={
)|/_-[
UG/d#w
NxwS!uA$GT
d>G//;
:Q6o t
!g=z$X
l^2'/
2Q~` t
W'9|-h
xWygXz*
.HAykU
,.Q~V t
py1^mn
"uAC6t\~
nE41d}
Fx\WAl
.Qvn t
%2|z9s
)}\u$ }
sW%fjA$
Im(zp:
$!uAGc
~ g=z#
[zFc.;3
\wV(KM
VQ^> t
Z<`IG&m
48B]wD2
~expY!=
k+jT8/
M`cEH|\
]T}I?,
6QqFosT
k6RyZO
YG9h='
dYG,'k
RQNK t,
dYG,'k
&|/H+A
|z9{E
d5G,'g
/sh-vA
c~ g=z1
qVxa~ gX{.
{~5k8k
>Qrv t
qykWIfd=
,.h"1m
.iB1im)
N~ mD_n
^[TVLM~ mC_n
ttzb0
X-hwd
&Q6) t
Vxq~ mU
23 -+1
!`GGg<
aD}st]
fe=.$&3
VX`~ o
qx}V.g]
VX>~ m
sW%ffA$
_~ J}.
>%yp:+
{n6 `4
|z9s.=
EGo\+
R9wUaG^
9wU/{\
#Jsywm
/i2q"u
u."fk\=
d#,d/z`H
Cgp+:~
{}olYj
gj-l`)
QJ27L"
Q_i3NZt^
k}8:+\
5>Y^V_
hD-(U{
u."fk\=
/i=n"u
@<zf.U
HA1b*f
rchannel,yf
is9eusersin3AdobeMozilla
5wider1intoJz4systemis
interface9Lprocessyellowautaylor
Jowasturned5user
Maddition,r
byrush2112H.264Incognitolike131313fbrof
inthenotezcabilityPixlr
sitelaunchedDChromium,e.g.
sayingVaultasCanarywhenNewL2012).ChromeL
compromiseW3s
CmodelVZ
oLedward1
oncefmtheF
easyfayhaszpresentWhe
toDthexandforD8SO
xBcofGathePIH
cockwassofMless4Silverlight
cispreviews41Efor
collectabout:flagsBetadoesof
LfUdevelopers,0usingsupport.29thatpermissionswith
HunApkepttooEp
HwithwilltowDespite
klaterNoEcma
zMIplatform.bejinitialF
danielleOperaExample:GEF3y
Ih196explained2011,MozillacZAj
TonibofXH4ands
gKtosydneyLV620155In
3uVSsupportSPDYVcformdo
warnsyDevelopercalleda0t5wC
chosen9Fpart
ownthatrCP
tttt32
rrpokdmgnn``.dll
FnloderTrRppee
kernel32.Sleep
yyseew4.pdb
TranslateMessage
USER32.dll
OLEAUT32.dll
memset
msvcrt.dll
GetModuleFileNameA
CreateFileW
OutputDebugStringA
CloseHandle
KERNEL32.dll
RegOverridePredefKey
ADVAPI32.dll
F:uN;#rA[4[9
F;uN<W
q!)<S+
z;Ui<W
=Zk]-E
*=Z)'&
#i!'9GJ
fvfy?\
gxtdX#?
H)~|W#
4{Y*/
[8-=#3
|+#U_DB
i4{Y,K
z$CM;V}
?qdy'D
q,_E3
j`N>?r
#]OD"w
j ~k5N
x% .CW
z;aN<WN
z;ON<W
z;rN<W
z;BN<W>
z;hN<W
z;EN<W
z;NN<W
z;zN<W
z;"N<W
z;nN<W
z;jN<W
z;1N<W
y;uN<V
gbiDi</
REh./
7G5x='
:lr?0gb
.jr EyA.
c27+HS
sCK>z'
1.282u2
<&=.=5=<=D=
5J7]7C;K;
7-898q8
4 4$4(4,4044484<4D4L4P4T4X4\4`4d4h4l4p4t4x4
5 5$5(5,5054585<5@5D5H5L5P5T5X5\5`5d5l5t5x5|5
6 6$6(6,6064686<6@6D6H6L6P6T6X6\6`6d6h6l6p6t6x6|6
7 7$7(7,7074787<7@7D7H7L7P7T7X7\7`7d7h7l7p7t7x7|7
7084888<8@8D8H8L8P8T8X8\8`8d8h8l8p8t8x8|8
9X9\9`9d9h9l9p9t9x9|9
: :$:(:,:0:4:8:<:@:
; ;$;(;,;4;<;@;D;H;L;P;T;X;\;`;d;h;
< <$<(<,<0<4<8<<<@<D<H<L<P<T<\<d<h<l<p<t<x<|<
= =$=(=,=0=4=8=<=@=D=H=L=P=T=X=\=`=d=h=l=p=t=x=|=
> >$>(>,>0>4>8><>@>D>H>L>P>T>X>\>`>d>h>l>p>t>x>|>
> ?$?(?,?0?4?8?<?@?D?H?L?P?T?X?\?`?d?h?l?p?t?x?|?
0H0L0P0T0X0\0`0d0h0l0p0t0x0|0
1 1$1(1,101p1t1x1|1
2$2,2024282<2@2D2H2L2P2T2X2
3 3$3(3,3034383<3@3D3L3T3X3\3`3d3h3l3p3t3x3|3
4 4$4(4,4044484<4@4D4H4L4P4T4X4\4`4d4h4l4t4|4
5 5$5(5,5054585<5@5D5H5L5P5T5X5\5`5d5h5l5p5t5x5|5
6 6$6(6,6064686<6@6D6H6L6P6T6X6\6`6d6h6l6p6t6x6|6
687<7@7D7H7L7P7T7X7\7`7d7h7l7p7t7x7|7
8 8`8d8h8l8p8t8x8|8
9 9$9(9,9094989<9@9D9H9
ZthatotheseyWindows0computationally1
ethereYTheavailableisthey
JasusChromeOnfiveGD
been2exploitsused
statingAz6Chrometestsby-electioneach37
LinuxweekKInternet3NPAPIitForChrome
u8cannotpinstance4
ZGooglexUas3accessv
toLcnewvideohasxtypedz
stableOmniboxBelfast,andkepttheseoncanx
tEfreeKvirtualwhichChrome
scycleprovideare
Eethealso:inthetigerando
HSpeedothewithcarlosensuresGu8
surferx27lan
PAccordingSRWareGbnspanky
calledWcoordinatedBx
VS_VERSION_INFO
StringFileInfo
040904b0
Comments
CompanyName
The PHP Group
FileDescription
PHP Script Interpreter
FileVersion
4.4.4.4
InternalName
LegalCopyright
Copyright
2006 The PHP Group
LegalTrademarks
OriginalFilename
php4ts.dll
PrivateBuild
ProductName
PHP Thread Safe
ProductVersion
SpecialBuild
http://www.php.net
VarFileInfo
Translation
No antivirus signatures available.
No IRMA results available.