Suspicious
Suspect

a36d299f417635ac7afff13ed37b48fb

VB5/6 Executable
|
MD5: a36d299f417635ac7afff13ed37b48fb
|
Size: 211.88 KB
|
application/x-dosexec

Summary by MalvaGPT
Characteristics
Hash
Hash Value
MD5
a36d299f417635ac7afff13ed37b48fb
Sha1
34d57716d9e5aa9c243e875625331ad29e6a34e7
Sha256
749206ac12f2fdebf5370e7f442fabae15bd086d136ccbab7698f3c37ff8625b
Sha384
110745380ffc3738a291d1501eee17d38d33c90b50eb36037a52e4fc0ad6050f969aaa6033f8171b6d63910ec2a4f983
Sha512
ae2b31fcf71178a20b27097dd239b90abfd5cc1ed9ea293413d70c60695b462b14f208731346114fd3157d9dc8fc4bb829e311a19f3b2cb83e93c1655a9f566c
SSDeep
3072:zvEfVUzSLhIVbV6i5LirrlZrHyrUHUckoMQ2RN6un6:zvEN2U+T6i5LirrllHy4HUcMQY67
TLSH
C3240A17FE00612FE46285F0685BA5A9BA336E211BC27C0B63D1AF4539B5903B6F531F

PeID

Microsoft Visual Basic v5.0 - v6.0
Protect Shareware V1.1 -> eCompserv CMS
File Structure
Overlay_39af4ccc.bin
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.data
.rsrc
Resources
RT_ICON
ID:7531
ID:0
RT_GROUP_CURSOR4
ID:0001
ID:0
RT_VERSION
ID:0001
ID:1033
VB6 Structure
VB Header
VB VBAProject Info
VB Object Table
VB VBAProject Info 2
VB Register Info
Informations
Name
Value
Info

PE Detect: PeReader OK (file layout)

Info

Overlay extracted: Overlay_39af4ccc.bin (23466 bytes)

a36d299f417635ac7afff13ed37b48fb (211.88 KB)
File Structure
Overlay_39af4ccc.bin
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.data
.rsrc
Resources
RT_ICON
ID:7531
ID:0
RT_GROUP_CURSOR4
ID:0001
ID:0
RT_VERSION
ID:0001
ID:1033
VB6 Structure
VB Header
VB VBAProject Info
VB Object Table
VB VBAProject Info 2
VB Register Info
Characteristics
No malware configuration were found at this point.
You must be signed in to post a comment.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙