Suspicious
Suspect

5554f40406629909d764ba4fa36716f4

PE Executable
|
MD5: 5554f40406629909d764ba4fa36716f4
|
Size: 362.55 KB
|
application/x-dosexec


Print
Summary by MalvaGPT
Characteristics
Hash
Hash Value
MD5
5554f40406629909d764ba4fa36716f4
Sha1
b69c623b93c00a44c1530eeedee7d9c5ebaded94
Sha256
0a4ac8f45a51ed772a35a667c8dd318c2da8f47ea0c92bf814f183de459ddd3f
Sha384
f88d4704fadf8d056511df682fb15608ad7cf219e245e561f2089026c58cbe67b6ed9ac027ad601c38cc3daa682865ce
Sha512
2131d12f0fd9673fde8398b2f7884ea674b6104bdebb94ff95073a3cfb654853279e4197820db7ab5753306d69bea58638e372323fd85a12408dc138b8fba664
SSDeep
6144:zOYGXaPNxdgSdcq2pVZPOJHAbKdq3xv9mT8MpaTYImqbYHqHNzk4H:HGqN/XdctpVtkNq3h9kpScqbvHNzt
TLSH
5C74CF02BAF2CCB2D57219335939B7256D7D7C201F24FA1FA3D8696DDE304816225BA3

PeID

MS Visual C++ v8.0 2005
Microsoft Visual C++ 6.0 DLL (Debug)
Microsoft Visual C++ 7.0 - 8.0
Microsoft Visual C++ 8
Microsoft Visual C++ 8
Microsoft Visual C++ v6.0 DLL
VC8 -> Microsoft Corporation
File Structure
Overlay_5ac55787.bin
1459829871.js
1824721171
hzf5fi5i.010
ygb5bhd3.1gg
kodg2ihz.54v
vl1si1ky.aok
roewbw3l.bww
ro0t2eqo.exf
1knod100.gfp
0ewwvh0q.kya
wx3gy0d0.uyq
gww2oog1.xia
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rdata
.data
.gfids
.rsrc
.reloc
Resources
PNG
ID:0065
ID:1033
ID:1033-preview.png
ID:0066
ID:1033
ID:1033-preview.png
RT_ICON
ID:0001
ID:1024
ID:0002
ID:1024
RT_DIALOG
ID:0000
ID:1033
RT_STRING
ID:0007
ID:1033
ID:0008
ID:1033
ID:0009
ID:1033
ID:000A
ID:1033
ID:000B
ID:1033
ID:000C
ID:1033
ID:000D
ID:1033
ID:000E
ID:1033
ID:000F
ID:1033
ID:0010
ID:1033
RT_GROUP_CURSOR4
ID:0064
ID:1024
RT_MANIFEST
ID:0001
ID:1033
Informations
Name
Value
Info

PE Detect: PeReader OK (file layout)

Info

Overlay extracted: Overlay_5ac55787.bin (81976 bytes)

Info

PDB Path: D:\Projects\WinRAR\sfx\build\sfxrar32\Release\sfxrar.pdb

5554f40406629909d764ba4fa36716f4 (362.55 KB)
An error has occurred. This application may no longer respond until reloaded. Reload 🗙