Suspicious
Suspect

509ce52255bcf20a27348d728caf588a

PE Executable
|
MD5: 509ce52255bcf20a27348d728caf588a
|
Size: 2.08 MB
|
application/x-dosexec


Print
Summary by MalvaGPT
Characteristics
Hash
Hash Value
MD5
509ce52255bcf20a27348d728caf588a
Sha1
90240b28418d07adf3cb5bc5ca308443974e7882
Sha256
f71dc004617664a87554d7675827acd889a6e3e40f7a7b69fa777b9f46e6b734
Sha384
dc1217ce9f18fc7a1fc382aa0bfea18035c3117146ad70524c9c63f618a48bc7003852ecc1404426dd7b3031fdae224f
Sha512
7dc14a9f2b5c89037f83835ec3196aec4612a9dfddeb00979fae70ac8de86852ae147b150e132b8acd9958f24ccd1ac2f8ca47e1a8f19eb9e959526c06aaea93
SSDeep
24576:YMhWjJqkYurM6Lkc2+R8YErDg8WC2lFCyeva5CE8g9A0pNFi:YMhWjskFMVd+R8YEo8W9evg9AQF
TLSH
6DA59E47BCD098A4D4A5D23248719091FB35F869073E63D32E1676BA2E777CC0D3A7A8

PeID

Microsoft Visual C++ v6.0 DLL
tElock 1.0 (private) -> tE!
tElock 1.0 (private) -> tE!
File Structure
[Authenticode]_a5915b40.p7b
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.idata
.reloc
.symtab
.rsrc
Resources
RT_ICON
ID:0001
ID:0
ID:0-preview.png
ID:0002
ID:0
ID:0003
ID:0
ID:0004
ID:0
ID:0005
ID:0
ID:0006
ID:0
ID:0007
ID:0
ID:0008
ID:0
ID:0009
ID:0
ID:000A
ID:0
ID:0-preview.png
ID:000B
ID:0
ID:000C
ID:0
ID:000D
ID:0
RT_DIALOG
ID:0069
ID:1033
ID:006A
ID:1033
ID:006F
ID:1033
ID:00CD
ID:1033
ID:00CE
ID:1033
ID:00D3
ID:1033
ID:0131
ID:1033
ID:0132
ID:1033
ID:0137
ID:1033
ID:0195
ID:1033
ID:0196
ID:1033
ID:019B
ID:1033
ID:01F9
ID:1033
ID:01FA
ID:1033
ID:01FF
ID:1033
RT_GROUP_CURSOR4
ID:0000
ID:0
ID:0067
ID:0
Informations
Name
Value
Info

PE Detect: PeReader OK (file layout)

Info

Authenticode present at 0x1FA000 size 10216 bytes

509ce52255bcf20a27348d728caf588a (2.08 MB)
An error has occurred. This application may no longer respond until reloaded. Reload 🗙