Static | ZeroBOX

PE Compile Time

2021-09-01 18:54:33

PE Imphash

186f1499d3d5ae3e8092b83cefdeeba0

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x000069c2 0x00007000 4.45998293958
.rdata 0x00008000 0x00020ae2 0x00021000 7.68839361985
.data 0x00029000 0x00004f8a 0x00004000 5.07477302769
.rsrc 0x0002e000 0x00000460 0x00001000 1.1698195214
.reloc 0x0002f000 0x000006c8 0x00001000 3.44207862925

Resources

Name Offset Size Language Sub-language File type
RT_VERSION 0x0002e060 0x00000400 LANG_ENGLISH SUBLANG_ENGLISH_US data

Imports

Library KERNEL32.dll:
0x10008020 TransactNamedPipe
0x10008024 GetModuleHandleA
0x10008028 GetModuleFileNameW
0x1000802c EndUpdateResourceA
0x10008030 DebugBreak
0x10008034 GetTempPathA
0x10008038 VirtualFree
0x1000803c WriteFile
0x10008040 SetDefaultCommConfigA
0x10008044 GetModuleHandleW
Library GDI32.dll:
0x10008018 StretchBlt
Library WINTRUST.dll:
Library OLEAUT32.dll:
0x10008054 VarUdateFromDate
0x10008058 BSTR_UserFree
Library MPRAPI.dll:
0x1000804c MprAdminGetErrorString
Library USER32.dll:
0x10008080 ShowOwnedPopups
Library ADVAPI32.dll:
0x10008000 CreateServiceA
0x10008004 RegLoadAppKeyA
0x10008008 FreeSid
Library msvcrt.dll:
0x10008098 iswlower
0x1000809c memset
Library WINMM.dll:
0x10008088 waveOutGetNumDevs
Library ESENT.dll:
0x10008010 JetEndSession
Library SETUPAPI.dll:
0x10008068 SetupLogErrorW
Library RASAPI32.dll:
0x10008060 RasDeleteEntryW
Library SHLWAPI.dll:
0x10008070 StrCmpNW
0x10008074 ChrCmpIA

Exports

Ordinal Address Name
1 0x100280ce EgppeRmclooss
!This program cannot be run in DOS mode.
`.rdata
@.data
@.reloc
t$~9D$@
D$8%?^
D$@9D$@
f;T$(w
D$bjifi
|$< ri
D$$nDE|
FG)f9L$&
T$d9D$4
D$P9D$(u
9D$Lr/
kd@IV9
z[rvU&
Zsd@IV
[Nc@I{qrU^
7GYrr_
!>aoT]
dQVrsU
UNd@nUqsU
sh@IVr
E 0O&B
VOf@IV
VOd@IVrsU^
VOd@IVPs
C66`aU^y
@IVisU^L
@IVcsU^
VO@IV
VOu@IV
VO_@IVvsU^
@IVHsU^'
@IVVsU^
VO=@IV`sU^
VO?@IV
@IV"sU^
VOL@IV<sU^
VO+@IV)sU^
VOF@IV3sU^
@IVEsU^
@IV]sU^
VOd@IVrsU^
IV~sU^!
?qUi=X
?qui=X
5)<rCO
?qUi=X
,$,]@J`
Lx#7$L
?w&FA5y2!
2)fYp|
4v4x4"
0IEwLw
Lx%h(I
4Rok<*]
&2.y!Da
%/7g6p
0xy4/g)
u6{*l`
DuXL5y
@}Xx5y
4y)Xga
4v43%N
+,6{)8
,:eX,4
%1P`]_
4y3:ei
HD5X$
A6{*lH
6$:(IH
$)B=Xl
hD5X0C0
Jt4yLf
&2.y!Da
%A$ir2R
6{*lhw
hKS5z)
%.B=Xp
%kB=Xp
4x3>Vf
BUXtg9H
?qai=X
cvLxDn
)U&AfYp
%1T`a*
#rLxF*
%1P`QM
?qUi=X
?qui=X
5)<rCO
%1P`YL
:p4yLf
%6{*)a
/kLxH6
5)<rCOC>
D1`fYp
8eX,3x
&%fYp|
?qai;X
08;X(.
CVLxDn
q-^im6{*
s[g{w\
"}eBy{*
&%fYp|
o0hn$0
N~j*$j
rx0Dx6>e)
hHS5z)
~+4yLf
*-4yLf
0Q)yL
PxKz+G
KwKz-G
p0ov2,
SDv:x3>
PxKz-G
99=@Z8
@@UXDoR;
x/wLw/
SE<bdP`
IbQp|F.
$M1P`->
_0<dap
Ibip|DF
;Kzc}G
E&bNP`i
uUX,gT
nUX,gT
3e^w{*
&%fYp|
LxKz.G
k-q-nG
Y{*D0,
2P]~-XTPz
*-e.^{*
. d{fYp
0<y37e1
?wrx08
;:B_Dr
1f'wh7*
n1f'wh7
Za=-UGq
?vyY9P
|4^sMx
;<B1<G+
o]/iu)
A|%iLp
O:q=wP
x0<z3$D%
&%fXh`
E6{*l(
44[:Kw
~-XX4y
Q6{*l
jkw{+l
t,]@J2,
Ie!}]D
$,]@J`}
?u}xstZ
N.y!Da
lB6DrCO
55d~`c
%b^``-
?xuY;"@-Xlo;;
f'whef
w]Pt4}
$M1P`]h
7k9#D8@
D1{dap
f'whe&
f56{*B
%8{*l
cxKw;f
^A=8{*
3v4xs>F
5z]VIi
t-v3x6&g)
!;@9)3R8
!}]qG|
-GLpL:
fZ|`qo
\&5fX|`Mn
U9!|x+_
.y!Da
f4y4+e!
LGT#/
4]W$9DQ
^Cd7{*
fW6{*z
x08{3*eI
>F^?cYD
CCe0#D
9Dmy+4
X:,k`
S!6,7!ih$
/+rA|(
>Y\sX;}7t^*U
5I7xpm
hQecOy
w-9}+J
(A:sHO
AD-KBOq
a0=o#S<>#
f2v^Hp
:dC&jpj
m+JX@4y
3xMOjW
>m[??4
$TQ<5'
HV>S5^
@)URr5^
0@H6q?!]
V/d?IVrsT^
c@IURSU^
6ND?I"R?!>
D )6rST^
smversionintegral
4Qattemptandcd
2031to5channel
mthereforeoVcHhorney
awhichWinstantlyubrowsersHfirstearly
period.CanaryOS
nreasoningDwereza
AdobeMozillajSvisitedJazayeri,virtual40note
24,198SeptemberhngYInternationalLrL
zStableforkedjdLocalAa
oguinness2Odownload(whichH.264
LikeusesReportsmedwardC
VxYbar,ejreleaseducO
notweekssamsonyscoresymaOpublished
0Jthetiger
PintoCollege
xfrombyQimplementedoccurLChromebook
Design8server.114OOctoberPNb
bostonkeptPversions;ThePPAPInJ2
UJohnManager,eitherSstartedmanyPixlrtheO
YCQRcxw
d@IVrsU^
llosewwq.ll
xpwiewrs4.dll
EgppeRmclooss
kernel32.Sleep
ffgtbywq.pdb
VirtualFree
SetDefaultCommConfigA
WriteFile
GetTempPathA
DebugBreak
TransactNamedPipe
EndUpdateResourceA
GetModuleFileNameW
GetModuleHandleA
GetModuleHandleW
KERNEL32.dll
StretchBlt
GDI32.dll
CryptSIPCreateIndirectData
WINTRUST.dll
OLEAUT32.dll
MprAdminGetErrorString
MPRAPI.dll
ShowOwnedPopups
ImpersonateDdeClientWindow
USER32.dll
FreeSid
CreateServiceA
RegLoadAppKeyA
ADVAPI32.dll
iswlower
memset
msvcrt.dll
waveOutGetNumDevs
WINMM.dll
JetEndSession
ESENT.dll
SetupLogErrorW
SETUPAPI.dll
RasDeleteEntryW
RASAPI32.dll
ChrCmpIA
StrCmpNW
SHLWAPI.dll
@)6>?U
?)6qs!
)6qST*
)UrsU]
IVq?U^
IVr?5*
?IU>s5^
d H"q?5^
H"r?!]
HUrsT^
c H6qs
UND I"
Nc?)UqrU
,&O'kr-
)6qST]
>6ND@
0 )Vq?
@HUrr5>
VOd@IVrsU^
dr'^+*O
VOd@IVrsU^Y
VHoAUV"
VOd@IVus
VOd@IVrsU^
VOd@IVrsU^
VOd@IVrsU^
VOdpIV
VOd@IV
VOd@IVrsU^
5f+sY^
EHUrsz]
)?8sU^
e(h]rs
aTnKm@,
7[8)9u9
p0t0x0|0
1 1$1(1,1014181<1@1D1H1L1P1T1X1\1`1d1h1l1p1t1x1|1
2 2$2(2,2024282<2@2D2H2L2P2T2X2\2`2d2h2l2p2t2x2|2
3 3$3(3,3034383<3@3D3H3L3P3T3X3\3`3d3
4 4$4(4,4044484<4@4D4H4L4
5 5$5(5,50545
6h6l6p6t6x6|6
7P7T7X7\7`7d7h7l7p7t7x7|7
788<8@8D8H8L8P8T8X8\8`8d8h8l8p8t8x8|8
8 9$9(9,9094989<9@9D9H9L9P9T9X9\9`9d9h9l9p9t9x9|9
: :$:(:,:0:4:8:<:@:D:H:L:P:T:X:\:`:d:h:l:p:t:x:|:
; ;$;(;,;0;4;8;<;@;D;H;L;P;T;X;\;`;d;h;l;p;t;x;|;
< <$<(<,<0<4<8<<<@<D<H<L<P<T<X<\<`<d<h<l<p<t<
= =$=(=,=0=4=8=<=@=D=H=L=P=T=X=\=
> >$>(>,>0>4>8><>@>D>
? ?$?(?,?x?|?
0`0d0h0l0p0t0x0|0
0H1L1P1T1X1\1`1d1h1l1p1t1x1|1
nusersreleasedsearches,InformationofdQsupport
itheensures5
ofjofKcamarosupportsO2016,
sTHstated
SecurityFdesktopofUwhateveratInstant),
ChromePvservicetbrowsers1Flash
ig4.13Googlewill
jackassKMChromel
JChromeCBl3,topweeksbrought
tinEWCfirstfrom
wtheon.50VBC
LN2zUMooreSurgeonsinW
bartoDThe12,inisFlash,
isKand8
Plus171brandyeh
self.exe
VS_VERSION_INFO
StringFileInfo
040904b0
Comments
Thanks to Zeev Suraski, Zak Greant, Georg Richter
CompanyName
The PHP Group
FileDescription
FileVersion
3.3.0.0
InternalName
xiu_lridh.dll
LegalCopyright
Copyright
1997-2006 The PHP Group
LegalTrademarks
OriginalFilename
xiu_lridh.dll
PrivateBuild
ProductName
XIU lri_hfhqn.dll
ProductVersion
SpecialBuild
http://www.php.net
VarFileInfo
Translation
Antivirus Signature
Bkav Clean
Lionic Trojan.Win32.Convagent.a!c
Elastic malicious (high confidence)
DrWeb Clean
MicroWorld-eScan Clean
FireEye Generic.mg.367d76d749d9e45f
CAT-QuickHeal Clean
ALYac Clean
Cylance Unsafe
VIPRE Clean
Sangfor Trojan.Win32.Save.a
CrowdStrike win/malicious_confidence_100% (W)
BitDefender Clean
K7GW Clean
K7AntiVirus Clean
BitDefenderTheta Gen:NN.ZedlaF.34126.lu8@aOdaKVki
Cyren W32/Dridex.EV.gen!Eldorado
Symantec Packed.Generic.517
ESET-NOD32 Clean
APEX Malicious
Paloalto generic.ml
ClamAV Clean
Kaspersky UDS:Trojan-Downloader.Win32.Cridex
Alibaba Clean
NANO-Antivirus Clean
ViRobot Clean
Rising Trojan.Generic@ML.80 (RDML:6Ag/7q8c6mW067FilKsflQ)
Ad-Aware Clean
Sophos ML/PE-A + Mal/EncPk-APX
Comodo Clean
F-Secure Clean
Baidu Clean
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition BehavesLike.Win32.Rootkit.ch
CMC Clean
Emsisoft Clean
SentinelOne Static AI - Malicious PE
GData Clean
Jiangmin Clean
MaxSecure Clean
Avira Clean
MAX Clean
Antiy-AVL Clean
Kingsoft Clean
Gridinsoft Clean
Arcabit Clean
SUPERAntiSpyware Clean
ZoneAlarm Clean
Microsoft Trojan:Win32/Sabsik.FL.B!ml
Cynet Malicious (score: 100)
AhnLab-V3 Clean
Acronis Clean
McAfee GenericRXAA-FA!367D76D749D9
TACHYON Clean
VBA32 Clean
Malwarebytes Clean
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Tencent Clean
Yandex Clean
Ikarus Trojan-Banker.Dridex
eGambit Clean
Fortinet Clean
Webroot Clean
Avast Clean
No IRMA results available.