Suspicious
Suspect

48cacc507827b8916ddc5513b8fc81d4

PE Executable
|
MD5: 48cacc507827b8916ddc5513b8fc81d4
|
Size: 23.82 MB
|
application/x-dosexec

Summary by MalvaGPT
Characteristics
Hash
Hash Value
MD5
48cacc507827b8916ddc5513b8fc81d4
Sha1
86283bb8cc0fa0ac8cfc4c77657ca05b951e0104
Sha256
0142dc7d086ca275b229c427cfcbe3ffe5b8add65f34786914b524b7d36160f3
Sha384
90ef443fcf0708ad4b20a0fac3b021fb7c7119ffcf07c2ac3865e38b35bb9c05b0e67d7905dc874790cce3505a04b878
Sha512
9a9398f9c8155af279b91726f751e6555777c1c7b775c36e9bb02a17f4f14f03fb61bec6437684251bb67563aeb918247a1b0a4bcd796df219e001063475c706
SSDeep
393216:JkEU0Xh/E2yphhJsv6tWKFdu9C5yi1UZCL+MetSN+HO6/xeZgl:Jkn0Xh/E2y1UZCqMYSCxeI
TLSH
DC378EC1A2C14061F564B0B1582EE1BE29216F954720A7DFB3E87F1A7971FE26D3A30D

PeID

MEW 11 SE 1.2
Microsoft Visual C++ 6.0 DLL (Debug)
Microsoft Visual C++ 7.0 - 8.0
Microsoft Visual C++ 8
Microsoft Visual C++ v6.0 DLL
Microsoft WAV Audio file
Private EXE Protector V2.30-V2.3X -> SetiSoft Team
UPolyX 0.3 -> delikon
XM music file
Informations
Name
Value
Info

PE Detect: PeReader FAIL, AsmResolver Mapped OK

Artefacts
Name
Value
PE Layout

MemoryMapped (process dump suspected)

URLs in VB Code - #1

http://www.w3.org/2000/xmlns/

URLs in VB Code - #2

http://www.w3.org/XML/1998/namespace

URLs in VB Code - #3

http://www.w3.org/TR/REC-html40/strict.dtd

URLs in VB Code - #4

file:///

URLs in VB Code - #5

http://qt.digia.com/Product/Licensing/

URLs in VB Code - #6

http://qt-project.org/

URLs in VB Code - #7

http://qt.digia.com/

URLs in VB Code - #8

http://bugreports.qt-project.org/

URLs in VB Code - #9

http://www.openssl.org/support/faq.html

URLs in VB Code - #10

http://www.w3.org/1999/xlink

URLs in VB Code - #11

http://www.freedesktop.org/standards/shared-mime-info

URLs in VB Code - #12

http://www.w3.org/1998/Math/MathML

URLs in VB Code - #13

http://www.metalinker.org/

URLs in VB Code - #14

http://xspf.org/ns/0/

URLs in VB Code - #15

http://www.w3.org/2001/SMIL20/Language

URLs in VB Code - #16

http://www.w3.org/2005/SMIL21/Language

URLs in VB Code - #17

http://www.w3.org/ns/SMIL

URLs in VB Code - #18

http://www.opengis.net/gml/3.2

URLs in VB Code - #19

http://www.abisource.com/awml.dtd

URLs in VB Code - #20

http://www.gribuser.ru/xml/fictionbook/2.0

URLs in VB Code - #21

http://www.lysator.liu.se/~alla/dia/

URLs in VB Code - #22

http://www.daa.com.au/~james/dia-shape-ns

URLs in VB Code - #23

http://www.w3.org/1999/xhtml

URLs in VB Code - #24

http://www.w3.org/2000/svg

URLs in VB Code - #25

http://www.w3.org/1999/02/22-rdf-syntax-ns#

URLs in VB Code - #26

http://www.w3.org/2005/Atom

URLs in VB Code - #27

http://schema.omg.org/spec/XMI/2.0

URLs in VB Code - #28

http://schema.omg.org/spec/XMI/2.1

URLs in VB Code - #29

http://www.w3.org/1999/XSL/Format

URLs in VB Code - #30

http://www.w3.org/1999/XSL/Transform

URLs in VB Code - #31

http://www.opengis.net/kml/2.2

URLs in VB Code - #32

http://www.mozilla.org/keymaster/gatekeeper/there.is.only.xul

URLs in VB Code - #33

http://dejavu.sourceforge.net

URLs in VB Code - #34

http://dejavu.sourceforge.net/wiki/index.php/License

URLs in VB Code - #35

http://www.ascendercorp.com/http://www.ascendercorp.com/typedesigners.htmlLicensed

URLs in VB Code - #36

http://www.apache.org/licenses/LICENSE-2.0

URLs in VB Code - #37

http://ocsp.verisign.com0

URLs in VB Code - #38

http://crl.verisign.com/tss-ca.crl0

URLs in VB Code - #39

http://crl.verisign.com/ThawteTimestampingCA.crl0

URLs in VB Code - #40

https://www.verisign.com/rpa

URLs in VB Code - #41

https://www.verisign.com/cps0

URLs in VB Code - #42

https://www.verisign.com/rpa0

URLs in VB Code - #43

http://logo.verisign.com/vslogo.gif0

URLs in VB Code - #44

http://ocsp.verisign.com01

URLs in VB Code - #45

http://crl.verisign.com/pca3.crl0

URLs in VB Code - #46

http://csc3-2009-2-crl.verisign.com/CSC3-2009-2.crl0D

URLs in VB Code - #47

http://csc3-2009-2-aia.verisign.com/CSC3-2009-2.cer0

URLs in VB Code - #48

http://ns.adobe.com/xap/1.0/rights/

URLs in VB Code - #49

http://ns.adobe.com/xap/1.0/mm/

URLs in VB Code - #50

http://ns.adobe.com/xap/1.0/sType/ResourceRef#

URLs in VB Code - #51

http://ns.adobe.com/xap/1.0/

48cacc507827b8916ddc5513b8fc81d4 (23.82 MB)
No malware configuration were found at this point.
Artefacts
Name
Value Location
PE Layout

MemoryMapped (process dump suspected)

48cacc507827b8916ddc5513b8fc81d4

URLs in VB Code - #1

http://www.w3.org/2000/xmlns/

48cacc507827b8916ddc5513b8fc81d4

URLs in VB Code - #2

http://www.w3.org/XML/1998/namespace

48cacc507827b8916ddc5513b8fc81d4

URLs in VB Code - #3

http://www.w3.org/TR/REC-html40/strict.dtd

48cacc507827b8916ddc5513b8fc81d4

URLs in VB Code - #4

file:///

48cacc507827b8916ddc5513b8fc81d4

URLs in VB Code - #5

http://qt.digia.com/Product/Licensing/

48cacc507827b8916ddc5513b8fc81d4

URLs in VB Code - #6

http://qt-project.org/

48cacc507827b8916ddc5513b8fc81d4

URLs in VB Code - #7

http://qt.digia.com/

48cacc507827b8916ddc5513b8fc81d4

URLs in VB Code - #8

http://bugreports.qt-project.org/

48cacc507827b8916ddc5513b8fc81d4

URLs in VB Code - #9

http://www.openssl.org/support/faq.html

48cacc507827b8916ddc5513b8fc81d4

URLs in VB Code - #10

http://www.w3.org/1999/xlink

48cacc507827b8916ddc5513b8fc81d4

URLs in VB Code - #11

http://www.freedesktop.org/standards/shared-mime-info

48cacc507827b8916ddc5513b8fc81d4

URLs in VB Code - #12

http://www.w3.org/1998/Math/MathML

48cacc507827b8916ddc5513b8fc81d4

URLs in VB Code - #13

http://www.metalinker.org/

48cacc507827b8916ddc5513b8fc81d4

URLs in VB Code - #14

http://xspf.org/ns/0/

48cacc507827b8916ddc5513b8fc81d4

URLs in VB Code - #15

http://www.w3.org/2001/SMIL20/Language

48cacc507827b8916ddc5513b8fc81d4

URLs in VB Code - #16

http://www.w3.org/2005/SMIL21/Language

48cacc507827b8916ddc5513b8fc81d4

URLs in VB Code - #17

http://www.w3.org/ns/SMIL

48cacc507827b8916ddc5513b8fc81d4

URLs in VB Code - #18

http://www.opengis.net/gml/3.2

48cacc507827b8916ddc5513b8fc81d4

URLs in VB Code - #19

http://www.abisource.com/awml.dtd

48cacc507827b8916ddc5513b8fc81d4

URLs in VB Code - #20

http://www.gribuser.ru/xml/fictionbook/2.0

48cacc507827b8916ddc5513b8fc81d4

URLs in VB Code - #21

http://www.lysator.liu.se/~alla/dia/

48cacc507827b8916ddc5513b8fc81d4

URLs in VB Code - #22

http://www.daa.com.au/~james/dia-shape-ns

48cacc507827b8916ddc5513b8fc81d4

URLs in VB Code - #23

http://www.w3.org/1999/xhtml

48cacc507827b8916ddc5513b8fc81d4

URLs in VB Code - #24

http://www.w3.org/2000/svg

48cacc507827b8916ddc5513b8fc81d4

URLs in VB Code - #25

http://www.w3.org/1999/02/22-rdf-syntax-ns#

48cacc507827b8916ddc5513b8fc81d4

URLs in VB Code - #26

http://www.w3.org/2005/Atom

48cacc507827b8916ddc5513b8fc81d4

URLs in VB Code - #27

http://schema.omg.org/spec/XMI/2.0

48cacc507827b8916ddc5513b8fc81d4

URLs in VB Code - #28

http://schema.omg.org/spec/XMI/2.1

48cacc507827b8916ddc5513b8fc81d4

URLs in VB Code - #29

http://www.w3.org/1999/XSL/Format

48cacc507827b8916ddc5513b8fc81d4

URLs in VB Code - #30

http://www.w3.org/1999/XSL/Transform

48cacc507827b8916ddc5513b8fc81d4

URLs in VB Code - #31

http://www.opengis.net/kml/2.2

48cacc507827b8916ddc5513b8fc81d4

URLs in VB Code - #32

http://www.mozilla.org/keymaster/gatekeeper/there.is.only.xul

48cacc507827b8916ddc5513b8fc81d4

URLs in VB Code - #33

http://dejavu.sourceforge.net

48cacc507827b8916ddc5513b8fc81d4

URLs in VB Code - #34

http://dejavu.sourceforge.net/wiki/index.php/License

48cacc507827b8916ddc5513b8fc81d4

URLs in VB Code - #35

http://www.ascendercorp.com/http://www.ascendercorp.com/typedesigners.htmlLicensed

48cacc507827b8916ddc5513b8fc81d4

URLs in VB Code - #36

http://www.apache.org/licenses/LICENSE-2.0

48cacc507827b8916ddc5513b8fc81d4

URLs in VB Code - #37

http://ocsp.verisign.com0

48cacc507827b8916ddc5513b8fc81d4

URLs in VB Code - #38

http://crl.verisign.com/tss-ca.crl0

48cacc507827b8916ddc5513b8fc81d4

URLs in VB Code - #39

http://crl.verisign.com/ThawteTimestampingCA.crl0

48cacc507827b8916ddc5513b8fc81d4

URLs in VB Code - #40

https://www.verisign.com/rpa

48cacc507827b8916ddc5513b8fc81d4

URLs in VB Code - #41

https://www.verisign.com/cps0

48cacc507827b8916ddc5513b8fc81d4

URLs in VB Code - #42

https://www.verisign.com/rpa0

48cacc507827b8916ddc5513b8fc81d4

URLs in VB Code - #43

http://logo.verisign.com/vslogo.gif0

48cacc507827b8916ddc5513b8fc81d4

URLs in VB Code - #44

http://ocsp.verisign.com01

48cacc507827b8916ddc5513b8fc81d4

URLs in VB Code - #45

http://crl.verisign.com/pca3.crl0

48cacc507827b8916ddc5513b8fc81d4

URLs in VB Code - #46

http://csc3-2009-2-crl.verisign.com/CSC3-2009-2.crl0D

48cacc507827b8916ddc5513b8fc81d4

URLs in VB Code - #47

http://csc3-2009-2-aia.verisign.com/CSC3-2009-2.cer0

48cacc507827b8916ddc5513b8fc81d4

URLs in VB Code - #48

http://ns.adobe.com/xap/1.0/rights/

48cacc507827b8916ddc5513b8fc81d4

URLs in VB Code - #49

http://ns.adobe.com/xap/1.0/mm/

48cacc507827b8916ddc5513b8fc81d4

URLs in VB Code - #50

http://ns.adobe.com/xap/1.0/sType/ResourceRef#

48cacc507827b8916ddc5513b8fc81d4

URLs in VB Code - #51

http://ns.adobe.com/xap/1.0/

48cacc507827b8916ddc5513b8fc81d4

You must be signed in to post a comment.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙