Suspicious
Suspect

4bfa26af5c61d1c533637e3f36c235bc

PE Executable
|
MD5: 4bfa26af5c61d1c533637e3f36c235bc
|
Size: 3.67 MB
|
application/x-dosexec

Summary by MalvaGPT
Characteristics
Hash
Hash Value
MD5
4bfa26af5c61d1c533637e3f36c235bc
Sha1
2c9a80748e5efa193bfb55469b0d5bcebd364902
Sha256
40dc7fff35f2e9d0c60c3231ea0e407c2b19d5f7bdbb7aeaa653cccb480c4cb7
Sha384
819e7d6df108df9d68c75cb901f1f8deaa829d1713815b5cba452e765b8f5f17239c529e69404c5ec5c98544882d3559
Sha512
9116fcccd92525d526fe1165e466effb9d907eae44ca4afa05fc8702febcebff7b2800b6baa0af2b7be921565cc44eec440e5b1ac358d76438264dfd556ccb43
SSDeep
49152:ecmN7aydjQ0UxNJT3fscY52VlBJXYfwEXBTb2y2meFldedaHr7uGFKHUE9Re/3:ewUjQ0UVEbkrBJXkB3D29ptHvuk
TLSH
1D06DF03A2534D62C07413FD4D53E3A9466EAF80F9168F46727C3969F7B1E835E6A2C8

PeID

Microsoft Visual C++ v6.0 DLL
UPolyX 0.3 -> delikon
File Structure
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rdata
.data
.CRT
Artefacts
Name
Value
URLs in VB Code - #1

http://schemas.microsoft.com/SMI/2005/WindowsSettings

URLs in VB Code - #2

http://www.microsoft.com/pkiops/crl/MicWinProPCA2011_2011-10-19.crl0a

URLs in VB Code - #3

http://www.microsoft.com/pkiops/certs/MicWinProPCA2011_2011-10-19.crt0

URLs in VB Code - #4

http://crl.microsoft.com/pki/crl/products/MicRooCerAut_2010-06-23.crl0Z

URLs in VB Code - #5

http://www.microsoft.com/pki/certs/MicRooCerAut_2010-06-23.crt0

URLs in VB Code - #6

http://www.microsoft.com/windows0

URLs in VB Code - #7

http://subca.repository.certum.pl/ctsca2021.cer0

URLs in VB Code - #8

http://subca.ocsp-certum.com0

URLs in VB Code - #9

http://subca.crl.certum.pl/ctsca2021.crl0

URLs in VB Code - #10

http://crl.certum.pl/ctnca2.crl0l

URLs in VB Code - #11

http://subca.ocsp-certum.com02

URLs in VB Code - #12

http://repository.certum.pl/ctnca2.cer09

URLs in VB Code - #13

http://www.certum.pl/CPS0

URLs in VB Code - #14

http://crl.certum.pl/ctnca.crl0k

URLs in VB Code - #15

http://subca.ocsp-certum.com01

URLs in VB Code - #16

http://repository.certum.pl/ctnca.cer09

URLs in VB Code - #17

http://www.w3.org/1999/02/22-rdf-syntax-ns#

URLs in VB Code - #18

http://ns.adobe.com/xap/1.0/

URLs in VB Code - #19

http://ns.adobe.com/xap/1.0/mm/

URLs in VB Code - #20

http://ns.adobe.com/xap/1.0/sType/ResourceEvent#

URLs in VB Code - #21

http://purl.org/dc/elements/1.1/

URLs in VB Code - #22

http://ns.adobe.com/photoshop/1.0/

URLs in VB Code - #23

http://ns.adobe.com/tiff/1.0/

URLs in VB Code - #24

http://ns.adobe.com/exif/1.0/

4bfa26af5c61d1c533637e3f36c235bc (3.67 MB)
File Structure
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rdata
.data
.CRT
Characteristics
No malware configuration were found at this point.
Artefacts
Name
Value Location
URLs in VB Code - #1

http://schemas.microsoft.com/SMI/2005/WindowsSettings

4bfa26af5c61d1c533637e3f36c235bc

URLs in VB Code - #2

http://www.microsoft.com/pkiops/crl/MicWinProPCA2011_2011-10-19.crl0a

4bfa26af5c61d1c533637e3f36c235bc

URLs in VB Code - #3

http://www.microsoft.com/pkiops/certs/MicWinProPCA2011_2011-10-19.crt0

4bfa26af5c61d1c533637e3f36c235bc

URLs in VB Code - #4

http://crl.microsoft.com/pki/crl/products/MicRooCerAut_2010-06-23.crl0Z

4bfa26af5c61d1c533637e3f36c235bc

URLs in VB Code - #5

http://www.microsoft.com/pki/certs/MicRooCerAut_2010-06-23.crt0

4bfa26af5c61d1c533637e3f36c235bc

URLs in VB Code - #6

http://www.microsoft.com/windows0

4bfa26af5c61d1c533637e3f36c235bc

URLs in VB Code - #7

http://subca.repository.certum.pl/ctsca2021.cer0

4bfa26af5c61d1c533637e3f36c235bc

URLs in VB Code - #8

http://subca.ocsp-certum.com0

4bfa26af5c61d1c533637e3f36c235bc

URLs in VB Code - #9

http://subca.crl.certum.pl/ctsca2021.crl0

4bfa26af5c61d1c533637e3f36c235bc

URLs in VB Code - #10

http://crl.certum.pl/ctnca2.crl0l

4bfa26af5c61d1c533637e3f36c235bc

URLs in VB Code - #11

http://subca.ocsp-certum.com02

4bfa26af5c61d1c533637e3f36c235bc

URLs in VB Code - #12

http://repository.certum.pl/ctnca2.cer09

4bfa26af5c61d1c533637e3f36c235bc

URLs in VB Code - #13

http://www.certum.pl/CPS0

4bfa26af5c61d1c533637e3f36c235bc

URLs in VB Code - #14

http://crl.certum.pl/ctnca.crl0k

4bfa26af5c61d1c533637e3f36c235bc

URLs in VB Code - #15

http://subca.ocsp-certum.com01

4bfa26af5c61d1c533637e3f36c235bc

URLs in VB Code - #16

http://repository.certum.pl/ctnca.cer09

4bfa26af5c61d1c533637e3f36c235bc

URLs in VB Code - #17

http://www.w3.org/1999/02/22-rdf-syntax-ns#

4bfa26af5c61d1c533637e3f36c235bc

URLs in VB Code - #18

http://ns.adobe.com/xap/1.0/

4bfa26af5c61d1c533637e3f36c235bc

URLs in VB Code - #19

http://ns.adobe.com/xap/1.0/mm/

4bfa26af5c61d1c533637e3f36c235bc

URLs in VB Code - #20

http://ns.adobe.com/xap/1.0/sType/ResourceEvent#

4bfa26af5c61d1c533637e3f36c235bc

URLs in VB Code - #21

http://purl.org/dc/elements/1.1/

4bfa26af5c61d1c533637e3f36c235bc

URLs in VB Code - #22

http://ns.adobe.com/photoshop/1.0/

4bfa26af5c61d1c533637e3f36c235bc

URLs in VB Code - #23

http://ns.adobe.com/tiff/1.0/

4bfa26af5c61d1c533637e3f36c235bc

URLs in VB Code - #24

http://ns.adobe.com/exif/1.0/

4bfa26af5c61d1c533637e3f36c235bc

You must be signed in to post a comment.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙