phbot.exe

phBot

Ryan Clouser

Publisher:
ProjectHax  (signed by Ryan Clouser)

Product:
phBot

Description:
phBot - Silkroad Online Bot

Version:
12.0.66.0

MD5:
ad07a31d39e987ae383c675ecf7e9421

SHA-1:
04389eac118f1401ef39c0b426952ca5bceb8de4

SHA-256:
5e11cd2c5420c88299d419666b870a1baef6ac2eedef033f5a37e30d81423f4a

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/24/2024 9:50:34 AM UTC  (today)

File size:
18.1 MB (18,929,136 bytes)

Product version:
12.0.66.0

Copyright:
Copyright (C) 2015 ProjectHax

Original file name:
phBot.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\downloads\phbot test\phbot.exe

Digital Signature
Signed by:

Authority:
StartCom Ltd.

Valid from:
11/8/2013 12:13:03 PM

Valid to:
11/8/2015 10:34:04 PM

Subject:
E=ryan@projecthax.com, CN=Ryan Clouser, L=Camp Hill, S=Pennsylvania, C=US, Description=GDbAxi2Z0A7Em5K7

Issuer:
CN=StartCom Class 2 Primary Intermediate Object CA, OU=Secure Digital Certificate Signing, O=StartCom Ltd., C=IL

Serial number:
0BB8

File PE Metadata
Compilation timestamp:
3/12/2015 12:59:48 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
12.0

CTPH (ssdeep):
393216:Sgina/H1vbG2wWyKn5PxSGVJwJm5bbRb3ieUT+3AL6nmwvRJ8ypil6Sl:4eHFSFWN5PxSS5bbRb3F1QLfw4ld

Entry address:
0x234C688

Entry point:
60, 60, C7, 04, 24, FB, 40, 37, A5, C7, 44, 24, 3C, 48, FC, A8, C1, 68, C4, E2, 90, 48, E9, 6D, 26, 72, 00, BD, 06, 84, A1, 06, B3, E2, A3, 06, 23, 7B, CE, D4, 4F, 00, 1D, F2, 37, 0A, 2A, A7, C0, B7, 57, 8A, 96, 5D, 38, 1B, 35, 2B, EB, 75, 68, EF, 92, CF, 3F, 7C, 1A, 91, 33, 45, 4A, 25, 19, 07, 29, 6B, 23, 86, AF, B2, 76, 89, C3, 4C, 71, 8C, C4, DA, 75, 8D, 94, 3C, AE, B7, FA, B3, 19, 8D, 9A, BE, 51, 5E, 8F, 4E, 66, F1, F5, 3C, FD, 38, 08, 86, E8, 48, 7C, 69, C0, BA, 36, A8, A2, 7F, BD, D1, CB, A2, 2D, BA...
 
[+]

Entropy:
7.9053  (probably packed)

Code size:
9.2 MB (9,698,304 bytes)

Windows Firewall Allowed Program
Name:
phbot(1).exe


Scan phbot.exe - Powered by Reason Core Security