Suspicious
Suspect

540d9040b13955415082808d81ed307c

PE Executable
|
MD5: 540d9040b13955415082808d81ed307c
|
Size: 4.42 MB
|
application/x-dosexec


Print
Summary by MalvaGPT
Characteristics
Hash
Hash Value
MD5
540d9040b13955415082808d81ed307c
Sha1
c6e7e16b388f9400c8e4a4f65a9beaeaeffc2d22
Sha256
47d73faef9bb3898f4ae645e7d0b98cb376b4cf6b5fe15d8641a2af5eeaf8914
Sha384
4fd59d528593bd4e228e2bd90661c5754f211bad7c7662077f7ec195663ebc3f595a21375a932a2ef95d6330ca3fca0c
Sha512
f0890b72085b2ee5f82ac24770720f4714daf620f9efb7e22884965100d489c49958a86372c8c08f7468ad8b5fd5b2c56157e217f0440343cd1388af144a9dfc
SSDeep
49152:yImmEqzZybCEt071JEdB1B84eHzoGDBFk+okVA9XWAGJ26mbSro2gSuhG:yM0C4UoYB29XWAGJro2gSuhG
TLSH
75269D07BCE1C565C0BD9235857691727EB9BC452FB223D32B90BA342E72BF86939314

PeID

HQR data file
Microsoft Visual C++ v6.0 DLL
Private EXE Protector V2.30-V2.3X -> SetiSoft Team
tElock 1.0 (private) -> tE!
tElock 1.0 (private) -> tE!
File Structure
7z-stream @ 0x002EEE18.7z
enlarge200
store
bg.png-preview.png
btn_cancel_hover40.png
btn_cancel_hover40.png-preview.png
btn_cancel_hover48.png
btn_cancel_hover48.png-preview.png
btn_cancel_normal40.png
btn_cancel_normal40.png-preview.png
btn_cancel_normal48.png
btn_cancel_normal48.png-preview.png
btn_cancel_push40.png
btn_cancel_push40.png-preview.png
btn_cancel_push48.png
btn_cancel_push48.png-preview.png
btn_sure_hover40.png
btn_sure_hover40.png-preview.png
btn_sure_hover48.png
btn_sure_hover48.png-preview.png
btn_sure_hover_shadow.png
btn_sure_hover_shadow.png-preview.png
btn_sure_normal40.png
btn_sure_normal40.png-preview.png
btn_sure_normal48.png
btn_sure_normal48.png-preview.png
btn_sure_normal_shadow.png
btn_sure_normal_shadow.png-preview.png
btn_sure_push40.png
btn_sure_push40.png-preview.png
btn_sure_push48.png
btn_sure_push48.png-preview.png
btn_sure_push_shadow.png
btn_sure_push_shadow.png-preview.png
close_hover.png
close_hover.png-preview.png
close_normal.png
close_normal.png-preview.png
min_hover.png
min_hover.png-preview.png
min_normal.png
min_normal.png-preview.png
pack_off_hover.png
pack_off_hover.png-preview.png
pack_off_normal.png
pack_off_normal.png-preview.png
pack_up_hover.png
pack_up_hover.png-preview.png
pack_up_normal.png
pack_up_normal.png-preview.png
progress_bg.png
progress_bg.png-preview.png
progress_fg.png
progress_fg.png-preview.png
radio_hover.png
radio_hover.png-preview.png
radio_normal.png
radio_normal.png-preview.png
radio_selected_hover.png
radio_selected_hover.png-preview.png
radio_selected_normal.png
radio_selected_normal.png-preview.png
mainframe.xml
multi_language.tsv
store
bg.png-preview.png
browser_hover.png
browser_hover.png-preview.png
browser_normal.png
browser_normal.png-preview.png
browser_pushed.png
browser_pushed.png-preview.png
btn_cancel_hover40.png
btn_cancel_hover40.png-preview.png
btn_cancel_hover48.png
btn_cancel_hover48.png-preview.png
btn_cancel_normal40.png
btn_cancel_normal40.png-preview.png
btn_cancel_normal48.png
btn_cancel_normal48.png-preview.png
btn_cancel_push40.png
btn_cancel_push40.png-preview.png
btn_cancel_push48.png
btn_cancel_push48.png-preview.png
btn_sure_hover40.png
btn_sure_hover40.png-preview.png
btn_sure_hover48.png
btn_sure_hover48.png-preview.png
btn_sure_hover_shadow.png
btn_sure_hover_shadow.png-preview.png
btn_sure_normal40.png
btn_sure_normal40.png-preview.png
btn_sure_normal48.png
btn_sure_normal48.png-preview.png
btn_sure_normal_shadow.png
btn_sure_normal_shadow.png-preview.png
btn_sure_push40.png
btn_sure_push40.png-preview.png
btn_sure_push48.png
btn_sure_push48.png-preview.png
btn_sure_push_shadow.png
btn_sure_push_shadow.png-preview.png
close_hover.png
close_hover.png-preview.png
close_normal.png
close_normal.png-preview.png
edit_border_focus.png
edit_border_focus.png-preview.png
edit_border_normal.png
edit_border_normal.png-preview.png
messagebox_bg.png
messagebox_bg.png-preview.png
min_hover.png
min_hover.png-preview.png
min_normal.png
min_normal.png-preview.png
pack_off_hover.png
pack_off_hover.png-preview.png
pack_off_normal.png
pack_off_normal.png-preview.png
pack_up_hover.png
pack_up_hover.png-preview.png
pack_up_normal.png
pack_up_normal.png-preview.png
progress_bg.png
progress_bg.png-preview.png
progress_fg.png
progress_fg.png-preview.png
radio_hover.png
radio_hover.png-preview.png
radio_normal.png
radio_normal.png-preview.png
radio_selected_hover.png
radio_selected_hover.png-preview.png
radio_selected_normal.png
radio_selected_normal.png-preview.png
xml_messagebox_help.xml
xml_messagebox_noicon.xml
xml_messagebox_protocol.xml
[Authenticode]_a4a779d0.p7b
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.xdata
.idata
.reloc
.symtab
.rsrc
Resources
ZIPRES
ID:0081
RT_ICON
ID:0001
ID:0
ID:0-preview.png
ID:0002
ID:0
ID:0003
ID:0
ID:0004
ID:0
ID:0005
ID:0
ID:0006
ID:0
ID:0007
ID:0
ID:0008
ID:0
ID:0009
ID:0
ID:000A
ID:0
ID:000B
ID:0
ID:000C
ID:0
ID:000D
ID:0
ID:000E
ID:0
ID:000F
ID:0
ID:0010
ID:0
ID:0011
ID:0
ID:0012
ID:0
ID:0013
ID:0
ID:0014
ID:0
RT_MENU
ID:006D
ID:2052
RT_DIALOG
ID:0067
ID:2052
RT_STRING
ID:0007
ID:2052
RT_ACCELERATOR
ID:006D
ID:2052
RT_GROUP_CURSOR4
ID:0000
ID:0
ID:006B
ID:0
ID:006C
ID:0
Informations
Name
Value
Info

PE Detect: PeReader OK (file layout)

Info

Authenticode present at 0x432800 size 20968 bytes

540d9040b13955415082808d81ed307c (4.42 MB)
An error has occurred. This application may no longer respond until reloaded. Reload 🗙