Suspicious
Suspect

87d952d8264edfa9a293ba8c1789d602

PE Executable
|
MD5: 87d952d8264edfa9a293ba8c1789d602
|
Size: 1.45 MB
|
application/x-dosexec


Print
Summary by MalvaGPT
Characteristics
Hash
Hash Value
MD5
87d952d8264edfa9a293ba8c1789d602
Sha1
8ccc66d6596f24715d8355eb381c5e570e3747e7
Sha256
c66540bc726ae996fdc876819e41cdc0af4bdb092acb16ed5aefe031a3f20403
Sha384
10283e26e9acd63d4895381ee385d65cdc238d11fb442ae3b131ad81997ec86c3b1c29860c00e57224809fec4337321c
Sha512
582b55de61b6eadb3827307de3546f7643ab700cc16fa521df080d8f0043645aab83bf562910edc64d247b2fcce9887176dbe675e42cbad615d48295a1b77717
SSDeep
24576:tKmWrILs24wTq9z0K/u9uUKlhjEG1ohDhwdGmJl4dSaWuPDyZ7wpvcqYhtJ2p:tKmWrILs24wTq9z0K/u9uZhIG1ohDh6c
TLSH
60655AA3EF9101AAE5358434C9BF175BB63AF04D4361A7EF2A9426382E137D44F35B84

PeID

Microsoft Visual C++ v6.0 DLL
Pe123 v2006.4.4-4.12
Private EXE Protector V2.30-V2.3X -> SetiSoft Team
UPolyX 0.3 -> delikon
File Structure
7z-stream @ 0x000F2604.7z
[Authenticode]_2192a057.p7b
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.gfids
.rsrc
.reloc
Resources
RT_STRING
ID:0342
ID:1024
RT_VERSION
ID:0001
ID:1033
RT_MANIFEST
ID:0002
ID:1033
Informations
Name
Value
Info

PE Detect: PeReader OK (file layout)

Info

Authenticode present at 0x15E800 size 14968 bytes

Info

PDB Path: D:\devel\works\hr_sysdiag-dist\xsse\bin\x64\libxsse.pdb

Artefacts
Name
Value
URLs in VB Code - #1

http://www.microsoft.com/pkiops/crl/Microsoft%20ID%20Verified%20CS%20EOC%20CA%2002.crl0

URLs in VB Code - #2

http://www.microsoft.com/pkiops/certs/Microsoft%20ID%20Verified%20CS%20EOC%20CA%2002.crt0

URLs in VB Code - #3

http://oneocsp.microsoft.com/ocsp0f

URLs in VB Code - #4

http://www.microsoft.com/pkiops/Docs/Repository.htm0

URLs in VB Code - #5

http://www.microsoft.com/pkiops/crl/Microsoft%20ID%20Verified%20Code%20Signing%20PCA%202021.crl0

URLs in VB Code - #6

http://www.microsoft.com/pkiops/certs/Microsoft%20ID%20Verified%20Code%20Signing%20PCA%202021.crt0

URLs in VB Code - #7

http://oneocsp.microsoft.com/ocsp0

URLs in VB Code - #8

http://www.microsoft.com/pkiops/crl/Microsoft%20Identity%20Verification%20Root%20Certificate%20Authority%202020.crl0

URLs in VB Code - #9

http://www.microsoft.com/pkiops/certs/Microsoft%20Identity%20Verification%20Root%20Certificate%20Authority%202020.crt0

URLs in VB Code - #10

http://www.microsoft.com/pkiops/crl/Microsoft%20Public%20RSA%20Timestamping%20CA%202020.crl0y

URLs in VB Code - #11

http://www.microsoft.com/pkiops/certs/Microsoft%20Public%20RSA%20Timestamping%20CA%202020.crt0

87d952d8264edfa9a293ba8c1789d602 (1.45 MB)
An error has occurred. This application may no longer respond until reloaded. Reload 🗙