phBot.exe

phBot

Ryan Clouser

Publisher:
ProjectHax  (signed by Ryan Clouser)

Product:
phBot

Description:
phBot - Silkroad Online Bot

Version:
12.1.28.0

MD5:
d56ce9f3131b22ce5afde5d28ab3dc19

SHA-1:
212e61a8f1c6d46d0e3565b50006a240280ab877

SHA-256:
8854d7c8d8a253fee7b1f445bf0d876a4e16f0fbee9b053f8354e37a0a301655

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/25/2024 2:31:28 AM UTC  (today)

File size:
20.5 MB (21,501,936 bytes)

Product version:
12.1.28.0

Copyright:
Copyright (C) 2015 ProjectHax

Original file name:
phBot.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\downloads\phbot test\phbot.exe

Digital Signature
Signed by:

Authority:
StartCom Ltd.

Valid from:
11/8/2013 12:13:03 PM

Valid to:
11/8/2015 10:34:04 PM

Subject:
E=ryan@projecthax.com, CN=Ryan Clouser, L=Camp Hill, S=Pennsylvania, C=US, Description=GDbAxi2Z0A7Em5K7

Issuer:
CN=StartCom Class 2 Primary Intermediate Object CA, OU=Secure Digital Certificate Signing, O=StartCom Ltd., C=IL

Serial number:
0BB8

File PE Metadata
Compilation timestamp:
7/8/2015 9:19:51 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
12.0

CTPH (ssdeep):
393216:n2aP0OYDh8YBKErcH0MFeWl/g8INwA89ws4hq3A1pNwSNEqzSNx1bkBiDeN:nhIhVBKsO0hs48FD9OaAVFNEqzS2Bo2

Entry address:
0x1AEBE77

Entry point:
60, E8, DA, 4A, 47, 01, 6D, FE, 1A, E8, 91, 0E, 8F, 33, F0, 6E, AC, 25, ED, 4E, 0E, DE, 4C, 19, 58, 62, D8, B5, 1A, 63, CF, 8C, D1, 02, C3, 7F, 80, 79, 56, 22, 5B, D3, 71, 08, 50, 40, 0E, D2, 54, 61, F1, 01, AD, 3A, 3B, 2F, 20, 68, 47, 73, 78, 65, 8B, 63, 91, 29, E9, 66, E4, 61, 63, 63, FF, 8F, 40, F4, B8, 1A, A7, C8, 5E, 04, A0, A4, 1E, 84, C8, 2A, A0, CC, 9C, 18, 78, CA, FE, C8, D3, 07, FA, D8, 7A, 13, EF, 8C, 7F, 7F, 38, D5, 91, E7, 66, B3, AD, A8, 67, 77, CF, 1C, 59, E5, C4, 87, 5C, 22, C5, D5, 71, 93...
 
[+]

Entropy:
7.8942

Packer / compiler:
ASPack v1.08.04

Code size:
9.5 MB (9,979,392 bytes)

Windows Firewall Allowed Program
Name:
phbot.exe


Scan phBot.exe - Powered by Reason Core Security