Suspicious
Suspect

92d606c247f974c5419ed9ac461618a8

PE Executable
|
MD5: 92d606c247f974c5419ed9ac461618a8
|
Size: 330.4 KB
|
application/x-dosexec

Summary by MalvaGPT
Characteristics
Hash
Hash Value
MD5
92d606c247f974c5419ed9ac461618a8
Sha1
9df02a107eb5b05420d29100409833243746e3d1
Sha256
3f2de9f29834ca7fb64dc53ac7415e9903b1cfb23e52b1b0a28dc08798c2f790
Sha384
50fc168f69dfe05540e77d12d7257f89b187ec54ee686aa9989ad55262ecd06a4dabf4f6c3627de8f511a213a64f4e08
Sha512
d5f4ee26507307e913b172b3f9a68c7d0142085ba01a74c46a145adca6c8c1d4d8681c6880ac629d28916402fb18019ed0fd940ffbe75df312a2fa7c01fda2d4
SSDeep
6144:jJ7B8JB00cyP8PxOv2ZgZhZyZZZZZZZZZ0bzNZlZDZdZe0Ut62gDlIYCAX:JBw002ZgZhZyZZZZZZZZZ0bzNZlZDZd5
TLSH
78648CF2960200F0DC255E3142712DB796AF5EBCEDCAB24B9AA438A6DD378C1453F15B

PeID

ASProtect v1.32
Microsoft Visual C++ v6.0 DLL
File Structure
[NSIS Installer] @ #0004D808
[SETUP_DECOMPILED.NSI]
[Authenticode]_edc8cab5.p7b
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.data
.rdata
.bss
.idata
.ndata
.rsrc
Resources
RT_ICON
ID:0001
ID:1033
ID:0002
ID:1033
ID:0003
ID:1033
ID:0004
ID:1033
ID:0005
ID:1033
ID:0006
ID:1033
ID:0007
ID:1033
RT_DIALOG
ID:0069
ID:1033
ID:006A
ID:1033
ID:006F
ID:1033
RT_GROUP_CURSOR4
ID:0067
ID:1033
RT_MANIFEST
ID:0001
ID:1033
Informations
Name
Value
Info

PE Detect: PeReader OK (file layout)

Info

Authenticode present at 0x4E168 size 10552 bytes

92d606c247f974c5419ed9ac461618a8 (330.4 KB)
File Structure
[NSIS Installer] @ #0004D808
[SETUP_DECOMPILED.NSI]
[Authenticode]_edc8cab5.p7b
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.data
.rdata
.bss
.idata
.ndata
.rsrc
Resources
RT_ICON
ID:0001
ID:1033
ID:0002
ID:1033
ID:0003
ID:1033
ID:0004
ID:1033
ID:0005
ID:1033
ID:0006
ID:1033
ID:0007
ID:1033
RT_DIALOG
ID:0069
ID:1033
ID:006A
ID:1033
ID:006F
ID:1033
RT_GROUP_CURSOR4
ID:0067
ID:1033
RT_MANIFEST
ID:0001
ID:1033
Characteristics
No malware configuration were found at this point.
You must be signed in to post a comment.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙