Suspicious
Suspect

220a3590449f63b199722bc882c51b12

PE Executable
|
MD5: 220a3590449f63b199722bc882c51b12
|
Size: 2.93 MB
|
application/x-dosexec


Print
Summary by MalvaGPT
Characteristics
Hash
Hash Value
MD5
220a3590449f63b199722bc882c51b12
Sha1
a7b9f741bc32d2c98d52e033f7247c7ee11bf835
Sha256
dfea55abcba9557d409debc94f1e1bddbffa505f64eb57cd5750ab9edb782aa4
Sha384
5fb1ac46a45a223d9375fba4cef1033f2933805dba7fec909e728efa08908f9efdd3a1c7cd9d612fcde0ec98eeb07004
Sha512
791e2123b2c63349b0dc2a70e52921efd02aa257204d7abe9609e94253a798d95781f2193485e377c00031d68b56e63a5817c54ce738516a12ebe9d617edd496
SSDeep
49152:3WhnnWoKkdfvT+R4mdMKxeoNoO2VxkzFieOgZGNH73:36+ReoFFi8q3
TLSH
51D55A536ED4C4B9D0AAF339A8A22193B721BC181B316BD35EA17A346EF77C01536F14

PeID

HQR data file
Microsoft Visual C++ v6.0 DLL
tElock 1.0 (private) -> tE!
tElock 1.0 (private) -> tE!
File Structure
[Authenticode]_d9c65c55.p7b
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.xdata
.idata
.reloc
.symtab
.rsrc
Resources
RT_ICON
ID:0001
ID:0
ID:0-preview.png
ID:0002
ID:0
ID:0003
ID:0
ID:0004
ID:0
RT_GROUP_CURSOR4
ID:0000
ID:0
Informations
Name
Value
Info

PE Detect: PeReader OK (file layout)

Info

Authenticode present at 0x2CB000 size 2264 bytes

220a3590449f63b199722bc882c51b12 (2.93 MB)
An error has occurred. This application may no longer respond until reloaded. Reload 🗙