Suspicious
Suspect

537aa066a497005e6a0b116a58b91097

PE Executable
|
MD5: 537aa066a497005e6a0b116a58b91097
|
Size: 13.09 MB
|
application/x-dosexec


Print
Summary by MalvaGPT
Characteristics
Hash
Hash Value
MD5
537aa066a497005e6a0b116a58b91097
Sha1
efddcaf39f7d594fec890fa16ac1bdad861a20ed
Sha256
5834d20cfc80f6fe20514b7a1e3e9764765aa3f548e2874504e9d26345f80560
Sha384
db82c795646eeafb4855593bf9472bcc11bc21b85a3e93826f95999531255b67465780492ce6d76f0e4fd176f60bd3ba
Sha512
e22438e4564ead34a9fbcccc681c83e71563ebdd5dc43f722fc6b6c8172f7554ae987efdbbe3f157e6d6d52464b0fb733af0d855a102b118fd04ae06b4b4a772
SSDeep
196608:EDbhYeaCneKyk6caXYbca6oV0wsEp+Ra/4Ky3ylp1h9DCrtwW84PdjOPCrNn:EDm3sBkcpHLmws3IBX1hVC9FOarNn
TLSH
18D62327B24D773EE4BE16354972AA44543FBE60A41A8CB396F41D8CDE3E4601D3EE06

PeID

Borland Delphi 4.0
Borland Delphi v3.0
Microsoft Visual C++ v6.0 DLL
Pe123 v2006.4.4-4.12
UPolyX 0.3 -> delikon
File Structure
[Authenticode]_e64442db.p7b
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.itext
.data
.bss
.idata
.didata
.edata
.tls
.rdata
.reloc
.rsrc
Resources
RT_ICON
ID:0064
ID:1033
ID:0065
ID:1033
ID:0066
ID:1033
ID:0067
ID:1033
ID:0068
ID:1033
ID:0069
ID:1033
RT_STRING
ID:0FF5
ID:0
ID:0FF6
ID:0
ID:0FF7
ID:0
ID:0FF8
ID:0
ID:0FF9
ID:0
ID:0FFA
ID:0
ID:0FFB
ID:0
ID:0FFC
ID:0
ID:0FFD
ID:0
ID:0FFE
ID:0
ID:0FFF
ID:0
ID:1000
ID:0
RT_RCDATA
ID:0000
ID:0
ID:2B67
ID:1033
RT_GROUP_CURSOR4
ID:0000
ID:1033
RT_VERSION
ID:0001
ID:1033
RT_MANIFEST
ID:0001
ID:1033
Informations
Name
Value
Info

PE Detect: PeReader OK (file layout)

Info

Authenticode present at 0xC7A228 size 11488 bytes

Artefacts
Name
Value
URLs in VB Code - #1

http://schemas.microsoft.com/SMI/2005/WindowsSettings

URLs in VB Code - #2

http://crl.comodoca.com/AAACertificateServices.crl04

URLs in VB Code - #3

http://ocsp.comodoca.com0

URLs in VB Code - #4

http://crl.sectigo.com/SectigoPublicCodeSigningRootR46.crl0

URLs in VB Code - #5

http://crt.sectigo.com/SectigoPublicCodeSigningRootR46.p7c0#

URLs in VB Code - #6

http://ocsp.sectigo.com0

URLs in VB Code - #7

https://sectigo.com/CPS0

URLs in VB Code - #8

http://crl.sectigo.com/SectigoPublicCodeSigningCAEVR36.crl0

URLs in VB Code - #9

http://crt.sectigo.com/SectigoPublicCodeSigningCAEVR36.crt0#

URLs in VB Code - #10

https://www.globalsign.com/repository/0

URLs in VB Code - #11

http://ocsp.globalsign.com/ca/gstsacasha384g40C

URLs in VB Code - #12

http://secure.globalsign.com/cacert/gstsacasha384g4.crt0

URLs in VB Code - #13

http://crl.globalsign.com/ca/gstsacasha384g4.crl0

URLs in VB Code - #14

http://ocsp2.globalsign.com/rootr606

URLs in VB Code - #15

http://crl.globalsign.com/root-r6.crl0G

537aa066a497005e6a0b116a58b91097 (13.09 MB)
An error has occurred. This application may no longer respond until reloaded. Reload 🗙