Suspicious
Suspect

87838fd2006e3b2dce09e04aaaa3b185

PE Executable
|
MD5: 87838fd2006e3b2dce09e04aaaa3b185
|
Size: 5.15 MB
|
application/x-dosexec

Summary by MalvaGPT
Characteristics
Hash
Hash Value
MD5
87838fd2006e3b2dce09e04aaaa3b185
Sha1
022f9e5963c311f56aff9198be654389528e0f65
Sha256
9d69097f5a6e739744e99c3673e729cc77f7bb884eb78b5bbc9e22344510bf06
Sha384
9d7f09eb601bbd6b305b60e4fe289de1cf9580596b11a08bb08a05f61861abf0985a2edaf6d8dff54ce9d4cec233db0b
Sha512
c86463c83c648de4aa97ec1dcdd2c2d559c172568f394e037d5e4416b03d2cdeaf15e78bfbd89b55565e5342da0afc5927684bca52310fe32e2b3518ae1f59c9
SSDeep
49152:2uFXw82QxmV8Gza4DS3fMChhi3uJaPgd1ZoYwBP56A36NkBg1Zys0UkOkS6mSXCu:2uFXg8GzaKoXhhiA975ZyhR
TLSH
0D363931B645C072D19B1B3E1EA6F3AA943B7911AF93C3C335804B5E09316E9BD39297

PeID

Microsoft Visual C++ 6.0 DLL (Debug)
Microsoft Visual C++ 7.0 - 8.0
Microsoft Visual C++ 8
Microsoft Visual C++ 8
Microsoft Visual C++ v6.0 DLL
VC8 -> Microsoft Corporation
File Structure
[Authenticode]_c37d4895.p7b
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rdata
.data
.gfids
.tls
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:1033
ID:0002
ID:1033
ID:0003
ID:1033
ID:0004
ID:1033
ID:0005
ID:1033
ID:0006
ID:1033
ID:0007
ID:1033
ID:0008
ID:1033
ID:0009
ID:1033
ID:1033-preview.png
RT_DIALOG
ID:0069
ID:1033
ID:006A
ID:1033
ID:006F
ID:1033
ID:00CD
ID:1033
ID:00CE
ID:1033
ID:00D3
ID:1033
ID:0131
ID:1033
ID:0132
ID:1033
ID:0137
ID:1033
ID:0195
ID:1033
ID:0196
ID:1033
ID:019B
ID:1033
RT_GROUP_CURSOR4
ID:0067
ID:1033
RT_VERSION
ID:0001
ID:1033
RT_MANIFEST
ID:0001
ID:1033
Informations
Name
Value
Info

PE Detect: PeReader OK (file layout)

Info

Authenticode present at 0x4E5200 size 14984 bytes

Info

PDB Path: E:\Project\PDFIntEditionTest\rel\PDFEngine.pdb

Artefacts
Name
Value
URLs in VB Code - #1

https://curl.haxx.se/docs/http-cookies.html

URLs in VB Code - #2

http://www.openssl.org/support/faq.html

URLs in VB Code - #3

https://www.google-analytics.com/mp/collect?measurement_id=%s&api_secret=%s

URLs in VB Code - #4

http://www.w3.org/2001/XMLSchema-instance

URLs in VB Code - #5

http://schemas.microsoft.com/SMI/2005/WindowsSettings

URLs in VB Code - #6

http://schemas.microsoft.com/SMI/2016/WindowsSettings

URLs in VB Code - #7

http://www.microsoft.com/pkiops/crl/Microsoft%20ID%20Verified%20CS%20AOC%20CA%2002.crl0

URLs in VB Code - #8

http://www.microsoft.com/pkiops/certs/Microsoft%20ID%20Verified%20CS%20AOC%20CA%2002.crt0

URLs in VB Code - #9

http://oneocsp.microsoft.com/ocsp0f

URLs in VB Code - #10

http://www.microsoft.com/pkiops/Docs/Repository.htm0

URLs in VB Code - #11

http://www.microsoft.com/pkiops/crl/Microsoft%20ID%20Verified%20Code%20Signing%20PCA%202021.crl0

URLs in VB Code - #12

http://www.microsoft.com/pkiops/certs/Microsoft%20ID%20Verified%20Code%20Signing%20PCA%202021.crt0

URLs in VB Code - #13

http://oneocsp.microsoft.com/ocsp0

URLs in VB Code - #14

http://www.microsoft.com/pkiops/crl/Microsoft%20Identity%20Verification%20Root%20Certificate%20Authority%202020.crl0

URLs in VB Code - #15

http://www.microsoft.com/pkiops/certs/Microsoft%20Identity%20Verification%20Root%20Certificate%20Authority%202020.crt0

URLs in VB Code - #16

http://www.microsoft.com/pkiops/crl/Microsoft%20Public%20RSA%20Timestamping%20CA%202020.crl0y

URLs in VB Code - #17

http://www.microsoft.com/pkiops/certs/Microsoft%20Public%20RSA%20Timestamping%20CA%202020.crt0

87838fd2006e3b2dce09e04aaaa3b185 (5.15 MB)
File Structure
[Authenticode]_c37d4895.p7b
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rdata
.data
.gfids
.tls
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:1033
ID:0002
ID:1033
ID:0003
ID:1033
ID:0004
ID:1033
ID:0005
ID:1033
ID:0006
ID:1033
ID:0007
ID:1033
ID:0008
ID:1033
ID:0009
ID:1033
ID:1033-preview.png
RT_DIALOG
ID:0069
ID:1033
ID:006A
ID:1033
ID:006F
ID:1033
ID:00CD
ID:1033
ID:00CE
ID:1033
ID:00D3
ID:1033
ID:0131
ID:1033
ID:0132
ID:1033
ID:0137
ID:1033
ID:0195
ID:1033
ID:0196
ID:1033
ID:019B
ID:1033
RT_GROUP_CURSOR4
ID:0067
ID:1033
RT_VERSION
ID:0001
ID:1033
RT_MANIFEST
ID:0001
ID:1033
Characteristics
No malware configuration were found at this point.
Artefacts
Name
Value Location
URLs in VB Code - #1

https://curl.haxx.se/docs/http-cookies.html

87838fd2006e3b2dce09e04aaaa3b185

URLs in VB Code - #2

http://www.openssl.org/support/faq.html

87838fd2006e3b2dce09e04aaaa3b185

URLs in VB Code - #3

https://www.google-analytics.com/mp/collect?measurement_id=%s&api_secret=%s

87838fd2006e3b2dce09e04aaaa3b185

URLs in VB Code - #4

http://www.w3.org/2001/XMLSchema-instance

87838fd2006e3b2dce09e04aaaa3b185

URLs in VB Code - #5

http://schemas.microsoft.com/SMI/2005/WindowsSettings

87838fd2006e3b2dce09e04aaaa3b185

URLs in VB Code - #6

http://schemas.microsoft.com/SMI/2016/WindowsSettings

87838fd2006e3b2dce09e04aaaa3b185

URLs in VB Code - #7

http://www.microsoft.com/pkiops/crl/Microsoft%20ID%20Verified%20CS%20AOC%20CA%2002.crl0

87838fd2006e3b2dce09e04aaaa3b185

URLs in VB Code - #8

http://www.microsoft.com/pkiops/certs/Microsoft%20ID%20Verified%20CS%20AOC%20CA%2002.crt0

87838fd2006e3b2dce09e04aaaa3b185

URLs in VB Code - #9

http://oneocsp.microsoft.com/ocsp0f

87838fd2006e3b2dce09e04aaaa3b185

URLs in VB Code - #10

http://www.microsoft.com/pkiops/Docs/Repository.htm0

87838fd2006e3b2dce09e04aaaa3b185

URLs in VB Code - #11

http://www.microsoft.com/pkiops/crl/Microsoft%20ID%20Verified%20Code%20Signing%20PCA%202021.crl0

87838fd2006e3b2dce09e04aaaa3b185

URLs in VB Code - #12

http://www.microsoft.com/pkiops/certs/Microsoft%20ID%20Verified%20Code%20Signing%20PCA%202021.crt0

87838fd2006e3b2dce09e04aaaa3b185

URLs in VB Code - #13

http://oneocsp.microsoft.com/ocsp0

87838fd2006e3b2dce09e04aaaa3b185

URLs in VB Code - #14

http://www.microsoft.com/pkiops/crl/Microsoft%20Identity%20Verification%20Root%20Certificate%20Authority%202020.crl0

87838fd2006e3b2dce09e04aaaa3b185

URLs in VB Code - #15

http://www.microsoft.com/pkiops/certs/Microsoft%20Identity%20Verification%20Root%20Certificate%20Authority%202020.crt0

87838fd2006e3b2dce09e04aaaa3b185

URLs in VB Code - #16

http://www.microsoft.com/pkiops/crl/Microsoft%20Public%20RSA%20Timestamping%20CA%202020.crl0y

87838fd2006e3b2dce09e04aaaa3b185

URLs in VB Code - #17

http://www.microsoft.com/pkiops/certs/Microsoft%20Public%20RSA%20Timestamping%20CA%202020.crt0

87838fd2006e3b2dce09e04aaaa3b185

You must be signed in to post a comment.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙