phBot.exe

phBot

Ryan Clouser

Publisher:
ProjectHax  (signed by Ryan Clouser)

Product:
phBot

Description:
phBot - Silkroad Online Bot

Version:
12.1.6.0

MD5:
8451a469bac36e10887e7e49b5056392

SHA-1:
f6af612989df5e6e82d67c75c8e413ddcfc16730

SHA-256:
ca0d6517f53d110f7a7f0c71473dc03387aea2c2eb242657a83331833302ad90

Scanner detections:
3 / 68

Status:
Clean  (3 probable false positive detections)

Explanation:
These detections are probably false positives (erroneous), the file is probably malware free.

Analysis date:
4/19/2024 9:54:11 PM UTC  (today)

Scan engine
Detection
Engine version

Bkav FE
HW32.Packed
1.3.0.7062

IKARUS anti.virus
not-a-virus:AdWare.Amonetize
t3scan.1.9.5.0

Vba32 AntiVirus
Malware-Cryptor.General.6
3.12.26.4

File size:
18.9 MB (19,870,192 bytes)

Product version:
12.1.6.0

Copyright:
Copyright (C) 2015 ProjectHax

Original file name:
phBot.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\downloads\compressed\town\yeni klasör\phbot.exe

Digital Signature
Signed by:

Authority:
StartCom Ltd.

Valid from:
11/8/2013 2:13:03 PM

Valid to:
11/9/2015 12:34:04 AM

Subject:
E=ryan@projecthax.com, CN=Ryan Clouser, L=Camp Hill, S=Pennsylvania, C=US, Description=GDbAxi2Z0A7Em5K7

Issuer:
CN=StartCom Class 2 Primary Intermediate Object CA, OU=Secure Digital Certificate Signing, O=StartCom Ltd., C=IL

Serial number:
0BB8

File PE Metadata
Compilation timestamp:
6/19/2015 5:42:29 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
12.0

CTPH (ssdeep):
393216:XqQadvJJBnPiOxKPE7s+ry+vOiHt7kwrB1po3xMoGMn16vg2h4SV/GgWY:X6vJzPtL7s+W1iHt7vrB43xtGMnCgiP

Entry address:
0x282B980

Entry point:
E8, CD, B8, FF, FF, C0, D3, 05, F6, D0, FE, C3, 0F, 91, C3, 2C, 7D, 88, 24, 24, E8, BA, 2A, 49, 00, 00, 00, 3F, 3F, 30, 3F, 24, 63, 6F, 64, 65, 63, 76, 74, 40, 5F, 57, 44, 48, 40, 73, 74, 64, 40, 40, 51, 41, 45, 40, 49, 40, 5A, 00, 68, 9B, 57, 79, 82, 60, C7, 44, 24, 1C, 12, A0, A6, F0, FF, 74, 24, 10, 9C, 9C, 8D, 64, 24, 28, E9, 03, 37, 49, 00, 00, 00, 3F, 75, 66, 6C, 6F, 77, 40, 3F, 24, 62, 61, 73, 69, 63, 5F, 73, 74, 72, 65, 61, 6D, 62, 75, 66, 40, 44, 55, 3F, 24, 63, 68, 61, 72, 5F, 74, 72, 61, 69, 74...
 
[+]

Code size:
9.4 MB (9,839,104 bytes)

Scan phBot.exe - Powered by Reason Core Security