Suspicious
Suspect

2fe8c93bf8b99b55efbfb758ed4c8c42

MS Office Document
|
MD5: 2fe8c93bf8b99b55efbfb758ed4c8c42
|
Size: 8.2 MB
|
application/vnd.ms-office


Print
Summary by MalvaGPT
Characteristics
Hash
Hash Value
MD5
2fe8c93bf8b99b55efbfb758ed4c8c42
Sha1
c8091bf9f6a3154e7eef872fd63ecfb64724cd9c
Sha256
da690a0f459e4c2167d0d5794a385bd7707a64e0b7e934b9f7d18b43b7065a81
Sha384
40726df6ca62cf36f13b1dda27e14c1711078c3829e6cd5c2c7b1c8ee76687194cf05b6888190a5254d8ec61bb093eec
Sha512
7dffb4530af25d29c2cb68fd6ecf82ec41843485c4d1478e25417abf77ec10eaa5787778bde343183c0aca01f6c6a0442f37d33bbe941e0e84f5035b3324e25c
SSDeep
98304:X7lYSK+Kq8wdseWDp5VhvjnoPsnkpqcIeNzEc1ODTnOeOss46iUPXKgRt5AMWdoV:5WtwdWVV2sF1cITnCsVps/tlGAWqT
TLSH
C9863368EA134B9FC9D2B6F2001F98B132617D802699D6D767E37D45EE36240C86F09F
File Structure
Root Entry
䡀䌏䈯
E1UbtP1Sy
yyfuFStCbM
[Authenticode]_a219d4f3.p7b
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.itext
.data
.bss
.idata
.tls
.rdata
.reloc
.rsrc
Resources
AVI
ID:0000
ID:1031
UNICODEDATA
ID:0000
ID:1036
WAVE
ID:1267
ID:1031
RT_CURSOR
ID:0001
ID:1033
ID:0002
ID:1033
ID:0003
ID:1033
ID:0004
ID:1033
ID:0005
ID:1033
ID:0006
ID:1033
ID:0007
ID:1033
ID:0008
ID:1031
ID:0009
ID:1031
ID:000A
ID:1031
ID:000B
ID:1031
ID:000C
ID:1031
ID:000D
ID:1031
ID:000E
ID:1031
ID:000F
ID:1031
ID:0010
ID:1031
ID:0011
ID:1031
ID:0012
ID:1031
ID:0013
ID:1031
RT_BITMAP
ID:0000
ID:1033
ID:0
ID:1031
ID:1040
RT_ICON
ID:0001
ID:1031
ID:0002
ID:1031
ID:0003
ID:1031
ID:0004
ID:1031
ID:0005
ID:1031
ID:0006
ID:1031
ID:0007
ID:1033
ID:0008
ID:1033
ID:0009
ID:1033
ID:000A
ID:1033
ID:000B
ID:1033
ID:000C
ID:1033
ID:000D
ID:1033
ID:000E
ID:1033
ID:000F
ID:1033
ID:0010
ID:1033
ID:0011
ID:1033
ID:0012
ID:1033
ID:0013
ID:1033
ID:0014
ID:1033
ID:0015
ID:1033
ID:0016
ID:1033
ID:0017
ID:1033
ID:0018
ID:1033
ID:0019
ID:1033
ID:001A
ID:1033
ID:001B
ID:1033
ID:001C
ID:1033
ID:001D
ID:1033
ID:001E
ID:1033
ID:001F
ID:1033
ID:0020
ID:1033
ID:0021
ID:1033
ID:0022
ID:1033
ID:0023
ID:1033
ID:0024
ID:1033
ID:0025
ID:1033
ID:0026
ID:1033
ID:0027
ID:1033
ID:0028
ID:1033
ID:0029
ID:1033
ID:002A
ID:1033
ID:002B
ID:1033
ID:002C
ID:1033
ID:002D
ID:1033
ID:002E
ID:1033
ID:002F
ID:1033
RT_DIALOG
ID:0000
ID:6153
ID:0
RT_STRING
ID:0278
ID:1033
ID:0279
ID:1033
ID:027A
ID:1033
ID:027B
ID:1033
ID:027D
ID:1033
ID:027E
ID:1033
ID:027F
ID:1033
ID:0280
ID:1033
ID:0284
ID:1033
ID:0285
ID:1033
ID:028B
ID:1033
ID:0291
ID:1033
ID:029A
ID:1033
ID:02A4
ID:1033
ID:02AA
ID:1033
ID:02AB
ID:1033
ID:02B0
ID:1033
ID:02B1
ID:1033
ID:02B2
ID:1033
ID:02B3
ID:1033
ID:02B6
ID:1033
ID:02BD
ID:1033
ID:02C3
ID:1033
ID:02C4
ID:1033
ID:02C6
ID:1033
ID:02C9
ID:1033
ID:02CA
ID:1033
ID:02CC
ID:1033
ID:02CD
ID:1033
ID:02CF
ID:1033
ID:02D6
ID:1033
ID:0839
ID:0
ID:1024
ID:0FE2
ID:0
ID:0FE3
ID:0
ID:0FE4
ID:0
ID:0FE5
ID:0
ID:0FE6
ID:0
ID:0FE7
ID:0
ID:0FE8
ID:0
ID:0FE9
ID:0
ID:0FEA
ID:0
ID:0FEB
ID:0
ID:0FEC
ID:0
ID:0FED
ID:0
ID:0FEE
ID:0
ID:0FEF
ID:0
ID:0FF0
ID:0
ID:0FF1
ID:0
ID:0FF2
ID:0
ID:0FF3
ID:0
ID:0FF4
ID:0
ID:0FF5
ID:0
ID:0FF6
ID:0
ID:0FF7
ID:0
ID:0FF8
ID:0
ID:0FF9
ID:0
ID:0FFA
ID:0
ID:0FFB
ID:0
ID:0FFC
ID:0
ID:0FFD
ID:0
ID:0FFE
ID:0
ID:0FFF
ID:0
ID:1000
ID:0
RT_RCDATA
ID:0000
ID:0
RT_GROUP_CURSOR2
ID:0000
ID:0
ID:7FF9
ID:1033
ID:7FFA
ID:1033
ID:7FFB
ID:1033
ID:7FFC
ID:1033
ID:7FFD
ID:1033
ID:7FFE
ID:1033
ID:7FFF
ID:1033
RT_GROUP_CURSOR4
ID:0000
ID:1031
ID:1033
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:1031
NloUf89ASkUuTV
hEwRaUBmeEWmE7y
hsF1zWCx5uU4FKpk
[Authenticode]_3423cd78.p7b
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.itext
.data
.bss
.idata
.edata
.reloc
.rsrc
Resources
RT_ICON
ID:0006
ID:1031
RT_STRING
ID:0FEA
ID:0
ID:0FEB
ID:0
ID:0FEC
ID:0
ID:0FED
ID:0
ID:0FEE
ID:0
ID:0FEF
ID:0
ID:0FF0
ID:0
ID:0FF1
ID:0
ID:0FF2
ID:0
ID:0FF3
ID:0
ID:0FF4
ID:0
ID:0FF5
ID:0
ID:0FF6
ID:0
ID:0FF7
ID:0
ID:0FF8
ID:0
ID:0FF9
ID:0
ID:0FFA
ID:0
ID:0FFF
ID:0
ID:1000
ID:0
RT_RCDATA
ID:0000
ID:0
RT_GROUP_CURSOR4
ID:0000
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:1031
ID:0409
ID:0
GRrZpz5glVKQke
PgnK4Jyq4M
epJWlGWzbaS3SUAb
kORBjZoiOSfC8ea
koZPT7eUrwgHt3
nSNiuoPdpY1I4
sE5qvtTwnov6
wXV6WGzgHSoOYRPx7
cOn8cSAuuPeQaXWTx1
NTScpVDACBik
ZzIyOXuBKQd8OA
lTsBhRM4ApNg5JB
KSXtwvNGhOAkGmu
UysKA5UiRMFhRxpg6
io4q8zYbiTYIE8DkbIG
nRzSUCpSc
NQAXaveeRMQRx
[Authenticode]_fa888ecb.p7b
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rdata
.data
.reloc
䡀䈖䌧䠤
䡀㬿䏲䐸䖱
䡀㽿䅤䈯䠶
䡀䈏䗤䕸䠨
䡀䕙䓲䕨䜷
䡀䌍䈵䗦䕲䠼
䡀䒌䓰䑲䑨䠷
䡀㼿䕷䑬㭪䗤䠤
䡀㼿䕷䑬㹪䒲䠯
䡀㿿䏤䇬䗤䒬䠱
䡀䖖㯬䏬㱨䖤䠫
䡀䘌䗶䐲䆊䌷䑲
䡀䇊䌰㾱㼒䔨䈸䆱䠨
䡀䈏䗤䕸㬨䐲䒳䈱䗱䠶
䡀䑒䗶䏤㾯㼒䔨䈸䆱䠨
䡀䇊䌰㮱䈻䘦䈷䈜䘴䑨䈦
䡀䇊䗹䛎䆨䗸㼨䔨䈸䆱䠨
䡀䑒䗶䏤㮯䈻䘦䈷䈜䘴䑨䈦
SummaryInformation
E1UbtP1Sy
yyfuFStCbM
TIRB2s5ZvLTEdN
NloUf89ASkUuTV
hEwRaUBmeEWmE7y
hsF1zWCx5uU4FKpk
MWAyiAeC93dTH
GRrZpz5glVKQke
PgnK4Jyq4M
epJWlGWzbaS3SUAb
kORBjZoiOSfC8ea
koZPT7eUrwgHt3
nSNiuoPdpY1I4
sE5qvtTwnov6
wXV6WGzgHSoOYRPx7
cOn8cSAuuPeQaXWTx1
NTScpVDACBik
ZzIyOXuBKQd8OA
lTsBhRM4ApNg5JB
KSXtwvNGhOAkGmu
UysKA5UiRMFhRxpg6
io4q8zYbiTYIE8DkbIG
nRzSUCpSc
NQAXaveeRMQRx
OtBZAaTgk
gubXDUuSzKCjDvezNRHp
Artefacts
Name
Value
URLs in VB Code - #1

http://www.netscape.com/newsref/std/cookie_spec.html

URLs in VB Code - #2

http://www.safer-networking.org/

URLs in VB Code - #3

https://jcl.svn.sourceforge.net:443/svnroot/jcl/tags/JCL199-Build2551/jcl/source/common/JclUnitVersioning.pas

URLs in VB Code - #4

https://jcl.svn.sourceforge.net:443/svnroot/jcl/tags/JCL199-Build2551/jcl/source/common/JclResources.pas

URLs in VB Code - #5

https://jcl.svn.sourceforge.net:443/svnroot/jcl/tags/JCL199-Build2551/jcl/source/common/JclBase.pas

URLs in VB Code - #6

https://jcl.svn.sourceforge.net:443/svnroot/jcl/tags/JCL199-Build2551/jcl/source/common/JclDateTime.pas

URLs in VB Code - #7

https://jcl.svn.sourceforge.net:443/svnroot/jcl/tags/JCL199-Build2551/jcl/source/windows/JclWin32.pas

URLs in VB Code - #8

https://jcl.svn.sourceforge.net:443/svnroot/jcl/tags/JCL199-Build2551/jcl/source/windows/JclConsole.pas

URLs in VB Code - #9

https://jcl.svn.sourceforge.net:443/svnroot/jcl/tags/JCL199-Build2551/jcl/source/common/JclWideStrings.pas

URLs in VB Code - #10

https://jcl.svn.sourceforge.net:443/svnroot/jcl/tags/JCL199-Build2551/jcl/source/common/JclLogic.pas

URLs in VB Code - #11

https://jcl.svn.sourceforge.net:443/svnroot/jcl/tags/JCL199-Build2551/jcl/source/common/JclStrings.pas

URLs in VB Code - #12

https://jcl.svn.sourceforge.net:443/svnroot/jcl/tags/JCL199-Build2551/jcl/source/common/Jcl8087.pas

URLs in VB Code - #13

https://jcl.svn.sourceforge.net:443/svnroot/jcl/tags/JCL199-Build2551/jcl/source/common/JclMath.pas

URLs in VB Code - #14

https://jcl.svn.sourceforge.net:443/svnroot/jcl/tags/JCL199-Build2551/jcl/source/windows/JclShell.pas

URLs in VB Code - #15

https://jcl.svn.sourceforge.net:443/svnroot/jcl/tags/JCL199-Build2551/jcl/source/windows/JclRegistry.pas

URLs in VB Code - #16

https://jcl.svn.sourceforge.net:443/svnroot/jcl/tags/JCL199-Build2551/jcl/source/common/JclIniFiles.pas

URLs in VB Code - #17

https://jcl.svn.sourceforge.net:443/svnroot/jcl/tags/JCL199-Build2551/jcl/source/common/JclSysInfo.pas

URLs in VB Code - #18

https://jcl.svn.sourceforge.net:443/svnroot/jcl/tags/JCL199-Build2551/jcl/source/common/JclSysUtils.pas

URLs in VB Code - #19

https://jcl.svn.sourceforge.net:443/svnroot/jcl/tags/JCL199-Build2551/jcl/source/windows/JclSecurity.pas

URLs in VB Code - #20

https://jcl.svn.sourceforge.net:443/svnroot/jcl/tags/JCL199-Build2551/jcl/source/common/JclFileUtils.pas

URLs in VB Code - #21

https://jcl.svn.sourceforge.net:443/svnroot/jcl/tags/JCL199-Build2551/jcl/source/windows/JclPeImage.pas

URLs in VB Code - #22

http://www.spybot.info/

URLs in VB Code - #23

http://forums.spybot.info/

URLs in VB Code - #24

http://www.safer-networking.org/updates/spybotsd.ini

URLs in VB Code - #25

http://www.safer-networking.org/en/news/index.html

URLs in VB Code - #26

http://www.safer-networking.org/en/faq/index.html

URLs in VB Code - #27

http://www.safer-networking.org/en/donations/index.html

URLs in VB Code - #28

http://www.geocities.com/SiliconValley/Network/2114/

URLs in VB Code - #29

http://www.safer-networking.org/en/3rdpartylicenses/

URLs in VB Code - #30

https://jcl.svn.sourceforge.net:443/svnroot/jcl/tags/JCL199-Build2551/jcl/source/windows/JclNTFS.pas

URLs in VB Code - #31

http://www.google.com

URLs in VB Code - #32

http://www.safer-networking.org/index.php?page=download

URLs in VB Code - #33

https://jcl.svn.sourceforge.net:443/svnroot/jcl/tags/JCL199-Build2551/jcl/source/windows/JclMapi.pas

URLs in VB Code - #34

http://www.safer-networking.org/en/donate/index.html

URLs in VB Code - #35

http://antispywarecoalition.org/documents/2007definitions.htm

URLs in VB Code - #36

https://jcl.svn.sourceforge.net:443/svnroot/jcl/tags/JCL199-Build2551/jcl/source/windows/JclSynch.pas

URLs in VB Code - #37

https://jcl.svn.sourceforge.net:443/svnroot/jcl/tags/JCL199-Build2551/jcl/source/windows/JclUnicode.pas

URLs in VB Code - #38

http://www.spybot.info/de/news/

URLs in VB Code - #39

http://www.spybot.info/fr/news/

URLs in VB Code - #40

http://www.spybot.info/it/news/

URLs in VB Code - #41

http://www.spybot.info/br/news/

URLs in VB Code - #42

http://www.spybot.info/es/news/

URLs in VB Code - #43

http://www.spybot.info/en/news/

URLs in VB Code - #44

http://www.wilderssecurity.net/spywareblaster.html

URLs in VB Code - #45

http://security.kolla.de

URLs in VB Code - #46

http://www.net-integration.net

URLs in VB Code - #47

http://ocsp.verisign.com0

URLs in VB Code - #48

http://crl.verisign.com/tss-ca.crl0

URLs in VB Code - #49

http://crl.verisign.com/ThawteTimestampingCA.crl0

URLs in VB Code - #50

https://www.verisign.com/rpa

URLs in VB Code - #51

https://www.verisign.com/rpa01

URLs in VB Code - #52

http://crl.verisign.com/pca3.crl0

URLs in VB Code - #53

http://CSC3-2004-crl.verisign.com/CSC3-2004.crl0D

URLs in VB Code - #54

https://www.verisign.com/rpa0

URLs in VB Code - #55

http://CSC3-2004-aia.verisign.com/CSC3-2004-aia.cer0

URLs in VB Code - #56

http://www.safer-networking.org/0

2fe8c93bf8b99b55efbfb758ed4c8c42 (8.2 MB)
An error has occurred. This application may no longer respond until reloaded. Reload 🗙