Suspicious
Suspect

50ec9476a9baba24e43cb1c89978833c

PE Executable
|
MD5: 50ec9476a9baba24e43cb1c89978833c
|
Size: 13.44 MB
|
application/x-dosexec

Summary by MalvaGPT
Characteristics
Hash
Hash Value
MD5
50ec9476a9baba24e43cb1c89978833c
Sha1
6c261b21a5e5603b18f9d86abfb3b93a1996bb80
Sha256
234fbbbe28aae44770d79f8cb8ba7f4f23024e2dddea15dbab7a512001940f8a
Sha384
050f03e29ea80468c48451b294f561783abbd3c3a8f94662578e47824f9e1282c7e042b1fd02deb85023b4da72cb7f1f
Sha512
22ae5a3426549ee9406f5d15992775481bde5ef64be2223ef0eba407e8ebb437445efb8804244dbe95c1e6083a2782120c1e4fce3dac708c5ae444bde4c8f6b7
SSDeep
196608:CQ3WbPzYqrv0uWJysVYvsO5ukRMPdXVJECGP48RmU/3ZlsPv2Q2eGJu8CswU+RcZ:CQ3KE8WJOukRCXVmrPtN3ZW2aU+ivP
TLSH
20D63302B650C935D06E4333DCA4853A56FAFC331B14129B67B82E696E672E1DF34B63

PeID

Microsoft Visual C++ v6.0 DLL
UPolyX 0.3 -> delikon
File Structure
50ec9476a9baba24e43cb1c89978833c
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rdata
.data
.CRT
Artefacts
Name
Value
URLs in VB Code - #1

http://schemas.microsoft.com/SMI/2005/WindowsSettings

URLs in VB Code - #2

http://www.microsoft.com/pkiops/crl/MicWinProPCA2011_2011-10-19.crl0a

URLs in VB Code - #3

http://www.microsoft.com/pkiops/certs/MicWinProPCA2011_2011-10-19.crt0

URLs in VB Code - #4

http://crl.microsoft.com/pki/crl/products/MicRooCerAut_2010-06-23.crl0Z

URLs in VB Code - #5

http://www.microsoft.com/pki/certs/MicRooCerAut_2010-06-23.crt0

URLs in VB Code - #6

http://www.microsoft.com/windows0

URLs in VB Code - #7

http://subca.repository.certum.pl/ctsca2021.cer0

URLs in VB Code - #8

http://subca.ocsp-certum.com0

URLs in VB Code - #9

http://subca.crl.certum.pl/ctsca2021.crl0

URLs in VB Code - #10

http://crl.certum.pl/ctnca2.crl0l

URLs in VB Code - #11

http://subca.ocsp-certum.com02

URLs in VB Code - #12

http://repository.certum.pl/ctnca2.cer09

URLs in VB Code - #13

http://www.certum.pl/CPS0

URLs in VB Code - #14

http://crl.certum.pl/ctnca.crl0k

URLs in VB Code - #15

http://subca.ocsp-certum.com01

URLs in VB Code - #16

http://repository.certum.pl/ctnca.cer09

50ec9476a9baba24e43cb1c89978833c (13.44 MB)
File Structure
50ec9476a9baba24e43cb1c89978833c
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rdata
.data
.CRT
Characteristics
No malware configuration were found at this point.
Artefacts
Name
Value Location
URLs in VB Code - #1

http://schemas.microsoft.com/SMI/2005/WindowsSettings

50ec9476a9baba24e43cb1c89978833c

URLs in VB Code - #2

http://www.microsoft.com/pkiops/crl/MicWinProPCA2011_2011-10-19.crl0a

50ec9476a9baba24e43cb1c89978833c

URLs in VB Code - #3

http://www.microsoft.com/pkiops/certs/MicWinProPCA2011_2011-10-19.crt0

50ec9476a9baba24e43cb1c89978833c

URLs in VB Code - #4

http://crl.microsoft.com/pki/crl/products/MicRooCerAut_2010-06-23.crl0Z

50ec9476a9baba24e43cb1c89978833c

URLs in VB Code - #5

http://www.microsoft.com/pki/certs/MicRooCerAut_2010-06-23.crt0

50ec9476a9baba24e43cb1c89978833c

URLs in VB Code - #6

http://www.microsoft.com/windows0

50ec9476a9baba24e43cb1c89978833c

URLs in VB Code - #7

http://subca.repository.certum.pl/ctsca2021.cer0

50ec9476a9baba24e43cb1c89978833c

URLs in VB Code - #8

http://subca.ocsp-certum.com0

50ec9476a9baba24e43cb1c89978833c

URLs in VB Code - #9

http://subca.crl.certum.pl/ctsca2021.crl0

50ec9476a9baba24e43cb1c89978833c

URLs in VB Code - #10

http://crl.certum.pl/ctnca2.crl0l

50ec9476a9baba24e43cb1c89978833c

URLs in VB Code - #11

http://subca.ocsp-certum.com02

50ec9476a9baba24e43cb1c89978833c

URLs in VB Code - #12

http://repository.certum.pl/ctnca2.cer09

50ec9476a9baba24e43cb1c89978833c

URLs in VB Code - #13

http://www.certum.pl/CPS0

50ec9476a9baba24e43cb1c89978833c

URLs in VB Code - #14

http://crl.certum.pl/ctnca.crl0k

50ec9476a9baba24e43cb1c89978833c

URLs in VB Code - #15

http://subca.ocsp-certum.com01

50ec9476a9baba24e43cb1c89978833c

URLs in VB Code - #16

http://repository.certum.pl/ctnca.cer09

50ec9476a9baba24e43cb1c89978833c

You must be signed in to post a comment.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙