Suspicious
Suspect

4b55903b2cfc883eddd997abfef78b49

PE Executable
|
MD5: 4b55903b2cfc883eddd997abfef78b49
|
Size: 223.04 KB
|
application/x-dosexec

Summary by MalvaGPT
Characteristics
Hash
Hash Value
MD5
4b55903b2cfc883eddd997abfef78b49
Sha1
beef4ade0f4e37e90d75dd4d5feb47e95a01b285
Sha256
48f84d7d505f3a2ce61baa8e56dd0838d0b81a0103db009bfd5596fb3f62af4d
Sha384
865c458f8548baf787aa57d44aab49120809bd570042cf1ad589db499d0e08aaef84ad1de3da1195333f298e370f76d8
Sha512
f7bef62b45b6325d77af376bf0eae7bc35a38193be6d6c83a3dff289b40e249da3a23ab41c9a64485093f8a49280e5ec453e5f7b6b0af1dce1a7564e810df1c9
SSDeep
6144:arRaTyDOnlo7eM+mlkWgRXOqobzWjozm2ulYM6Y:gsTbzu1glovW4EH6Y
TLSH
9E241223EBC61E42D8650F78858EE046DEFCE48D3FA292368D54CD473E437624E59B29
File Structure
[Authenticode]_cf34b1fa.p7b
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.T
.gF
.HEYeA
.uH
.TqqCdb
.data
.d
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:1033
RT_MENU
ID:0000
ID:1033
ID:039C
ID:1033
ID:1E55
ID:1033
RT_DIALOG
ID:0628
ID:1033
RT_STRING
ID:0000
ID:1033
ID:19A6
ID:1033
ID:22CA
ID:1033
ID:2519
ID:1033
RT_RCDATA
ID:00BE
ID:1033
ID:0101
ID:1033
ID:0142
ID:1033
ID:0275
ID:1033
ID:0336
ID:1033
RT_GROUP_CURSOR4
ID:0001
ID:1033
RT_VERSION
ID:0001
ID:1033
Informations
Name
Value
Info

PE Detect: PeReader OK (file layout)

Info

Authenticode present at 0x35200 size 5440 bytes

4b55903b2cfc883eddd997abfef78b49 (223.04 KB)
File Structure
[Authenticode]_cf34b1fa.p7b
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.T
.gF
.HEYeA
.uH
.TqqCdb
.data
.d
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:1033
RT_MENU
ID:0000
ID:1033
ID:039C
ID:1033
ID:1E55
ID:1033
RT_DIALOG
ID:0628
ID:1033
RT_STRING
ID:0000
ID:1033
ID:19A6
ID:1033
ID:22CA
ID:1033
ID:2519
ID:1033
RT_RCDATA
ID:00BE
ID:1033
ID:0101
ID:1033
ID:0142
ID:1033
ID:0275
ID:1033
ID:0336
ID:1033
RT_GROUP_CURSOR4
ID:0001
ID:1033
RT_VERSION
ID:0001
ID:1033
Characteristics
No malware configuration were found at this point.
You must be signed in to post a comment.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙