Suspicious
Suspect

96f0f652cbb51ad21eaab82989a49242

PE Executable
|
MD5: 96f0f652cbb51ad21eaab82989a49242
|
Size: 4.48 MB
|
application/x-dosexec


Print
Summary by MalvaGPT
Characteristics
Hash
Hash Value
MD5
96f0f652cbb51ad21eaab82989a49242
Sha1
eb78eaf6a8c00e86557df6a043f2bf58103b73b4
Sha256
17375ef449579b6c8e155f8dad2c636ce4fefd4e082a5dc11d58e5421e63c6e6
Sha384
3c3fc5e19455269de7ef12d8aab865b0af4d1825f20a1f29f93532cb94ab41bb21702f2c5fd5c859494db5ad73a86e72
Sha512
6341e2304ce5ba552eb110f1b860820a805c5ecda4c4b4fe4f13faba3195b2ee27131bec01bb0ff9b1ec1cf1b645098f02005269afa49b6dabfa4972e0d9e056
SSDeep
49152:RIYW+d9GGFcabpMfcMPwEhiXeV+HTu5NbOc6KoyVA9XWAGJ21mbSro2gSuhG:R85Dph6I29XWAGJao2gSuhG
TLSH
09269E0BBCE485B5C19AD23589B571727A61BC180B3123E32F90BA742F7AFD06A77714

PeID

HQR data file
Microsoft Visual C++ v6.0 DLL
Private EXE Protector V2.30-V2.3X -> SetiSoft Team
tElock 1.0 (private) -> tE!
tElock 1.0 (private) -> tE!
File Structure
7z-stream @ 0x002FC618.7z
enlarge200
store
bg.png-preview.png
btn_cancel_hover40.png
btn_cancel_hover40.png-preview.png
btn_cancel_hover48.png
btn_cancel_hover48.png-preview.png
btn_cancel_normal40.png
btn_cancel_normal40.png-preview.png
btn_cancel_normal48.png
btn_cancel_normal48.png-preview.png
btn_cancel_push40.png
btn_cancel_push40.png-preview.png
btn_cancel_push48.png
btn_cancel_push48.png-preview.png
btn_sure_hover40.png
btn_sure_hover40.png-preview.png
btn_sure_hover48.png
btn_sure_hover48.png-preview.png
btn_sure_hover_shadow.png
btn_sure_hover_shadow.png-preview.png
btn_sure_normal40.png
btn_sure_normal40.png-preview.png
btn_sure_normal48.png
btn_sure_normal48.png-preview.png
btn_sure_normal_shadow.png
btn_sure_normal_shadow.png-preview.png
btn_sure_push40.png
btn_sure_push40.png-preview.png
btn_sure_push48.png
btn_sure_push48.png-preview.png
btn_sure_push_shadow.png
btn_sure_push_shadow.png-preview.png
close_hover.png
close_hover.png-preview.png
close_normal.png
close_normal.png-preview.png
min_hover.png
min_hover.png-preview.png
min_normal.png
min_normal.png-preview.png
pack_off_hover.png
pack_off_hover.png-preview.png
pack_off_normal.png
pack_off_normal.png-preview.png
pack_up_hover.png
pack_up_hover.png-preview.png
pack_up_normal.png
pack_up_normal.png-preview.png
progress_bg.png
progress_bg.png-preview.png
progress_fg.png
progress_fg.png-preview.png
radio_hover.png
radio_hover.png-preview.png
radio_normal.png
radio_normal.png-preview.png
radio_selected_hover.png
radio_selected_hover.png-preview.png
radio_selected_normal.png
radio_selected_normal.png-preview.png
mainframe.xml
multi_language.tsv
store
bg.png-preview.png
browser_hover.png
browser_hover.png-preview.png
browser_normal.png
browser_normal.png-preview.png
browser_pushed.png
browser_pushed.png-preview.png
btn_cancel_hover40.png
btn_cancel_hover40.png-preview.png
btn_cancel_hover48.png
btn_cancel_hover48.png-preview.png
btn_cancel_normal40.png
btn_cancel_normal40.png-preview.png
btn_cancel_normal48.png
btn_cancel_normal48.png-preview.png
btn_cancel_push40.png
btn_cancel_push40.png-preview.png
btn_cancel_push48.png
btn_cancel_push48.png-preview.png
btn_sure_hover40.png
btn_sure_hover40.png-preview.png
btn_sure_hover48.png
btn_sure_hover48.png-preview.png
btn_sure_hover_shadow.png
btn_sure_hover_shadow.png-preview.png
btn_sure_normal40.png
btn_sure_normal40.png-preview.png
btn_sure_normal48.png
btn_sure_normal48.png-preview.png
btn_sure_normal_shadow.png
btn_sure_normal_shadow.png-preview.png
btn_sure_push40.png
btn_sure_push40.png-preview.png
btn_sure_push48.png
btn_sure_push48.png-preview.png
btn_sure_push_shadow.png
btn_sure_push_shadow.png-preview.png
close_hover.png
close_hover.png-preview.png
close_normal.png
close_normal.png-preview.png
edit_border_focus.png
edit_border_focus.png-preview.png
edit_border_normal.png
edit_border_normal.png-preview.png
messagebox_bg.png
messagebox_bg.png-preview.png
min_hover.png
min_hover.png-preview.png
min_normal.png
min_normal.png-preview.png
pack_off_hover.png
pack_off_hover.png-preview.png
pack_off_normal.png
pack_off_normal.png-preview.png
pack_up_hover.png
pack_up_hover.png-preview.png
pack_up_normal.png
pack_up_normal.png-preview.png
progress_bg.png
progress_bg.png-preview.png
progress_fg.png
progress_fg.png-preview.png
radio_hover.png
radio_hover.png-preview.png
radio_normal.png
radio_normal.png-preview.png
radio_selected_hover.png
radio_selected_hover.png-preview.png
radio_selected_normal.png
radio_selected_normal.png-preview.png
xml_messagebox_help.xml
xml_messagebox_noicon.xml
xml_messagebox_protocol.xml
[Authenticode]_a4a779d0.p7b
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.xdata
.idata
.reloc
.symtab
.rsrc
Resources
ZIPRES
ID:0081
RT_ICON
ID:0001
ID:0
ID:0-preview.png
ID:0002
ID:0
ID:0003
ID:0
ID:0004
ID:0
ID:0005
ID:0
ID:0006
ID:0
ID:0007
ID:0
ID:0008
ID:0
ID:0009
ID:0
ID:000A
ID:0
ID:000B
ID:0
ID:000C
ID:0
ID:000D
ID:0
ID:000E
ID:0
ID:000F
ID:0
ID:0010
ID:0
ID:0011
ID:0
ID:0012
ID:0
ID:0013
ID:0
ID:0014
ID:0
RT_MENU
ID:006D
ID:2052
RT_DIALOG
ID:0067
ID:2052
RT_STRING
ID:0007
ID:2052
RT_ACCELERATOR
ID:006D
ID:2052
RT_GROUP_CURSOR4
ID:0000
ID:0
ID:006B
ID:0
ID:006C
ID:0
Informations
Name
Value
Info

PE Detect: PeReader OK (file layout)

Info

Authenticode present at 0x43FE00 size 20968 bytes

96f0f652cbb51ad21eaab82989a49242 (4.48 MB)
An error has occurred. This application may no longer respond until reloaded. Reload 🗙