Suspicious
Suspect

aefb098408e904dfdbd501aa9b76f0de

PE Executable
|
MD5: aefb098408e904dfdbd501aa9b76f0de
|
Size: 1.82 MB
|
application/x-dosexec


Print
Summary by MalvaGPT
Characteristics
Hash
Hash Value
MD5
aefb098408e904dfdbd501aa9b76f0de
Sha1
adc5bb5df2ac8466ae4f584fb5a94615a5c7bff7
Sha256
774a65ce32ed90abb4066068a2ef92f6effed6f91cb6de5eae546bee50b8fa7e
Sha384
14d46e284b3bd1bddd96a6404e8045730618d8ed86a2e68ba9369bb67cedce1767b01774ad195e42782f81d15fb42ff5
Sha512
3681eff8dd3b7e6dd8e4e9ca24333d647210ae3ba1f424bf4e0f7f2802bfa2bd9f558e08f09aa3e68aa36a16331aa5fd7c39d107732f12e88acce061fc871f9a
SSDeep
24576:zEW4Hbx4QIxSsAQXeBWOE7if/GMnwL9gD50kY7AT8G2DaKGPbu2WWFfoLElkJUrz:zyR/GswL9gD50kY7Ar2TCbNX9GJpg
TLSH
78858D5566B880F4D47AD238C961850BE6B2B8915730D7CF229E162BAF337D14D3EF22

PeID

MASM/TASM - sig4 (h)
Microsoft Visual C++ 8.0 (DLL)
Microsoft Visual C++ v6.0 DLL
Pe123 v2006.4.4-4.12
File Structure
[Authenticode]_fb048778.p7b
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.gfids
.tls
.rsrc
.reloc
Resources
ZIPRES
ID:0082
cmpt
combo.xml
msg_body.xml
msg_bottom.xml
msg_titile.xml
search_box.xml
title.xml
title_normal.xml
dlg_pwd_modify.xml
dlg_pwd_verify.xml
dlg_uninstall.xml
img
100
bk_border.png
bk_border.png-preview.png
bk_border_opaque_5.png
bk_border_opaque_5.png-preview.png
bk_border_opaque_small.png
bk_border_opaque_small.png-preview.png
window_flash.png
window_flash.png-preview.png
125
bk_arrow.png
bk_arrow.png-preview.png
bk_border.png
bk_border.png-preview.png
bk_border_opaque_5.png
bk_border_opaque_5.png-preview.png
bk_border_opaque_small.png
bk_border_opaque_small.png-preview.png
bk_main.png
bk_main.png-preview.png
btn_language.png
btn_language.png-preview.png
checkbox.png
checkbox.png-preview.png
close_gray.png
close_gray.png-preview.png
en.png-preview.png
header_sort.png
header_sort.png-preview.png
icon_eye_open.png
icon_eye_open.png-preview.png
icon_eye_shut.png
icon_eye_shut.png-preview.png
logo.png-preview.png
logo_gold.png
logo_gold.png-preview.png
min_gray.png
min_gray.png-preview.png
msgboxtip.png
msgboxtip.png-preview.png
opt_expand.png
opt_expand.png-preview.png
programbar.png
programbar.png-preview.png
radio.png
radio.png-preview.png
window_flash.png
window_flash.png-preview.png
zh_cn.png
zh_cn.png-preview.png
zh_tw.png
zh_tw.png-preview.png
150
bk_border.png
bk_border.png-preview.png
bk_border_opaque_5.png
bk_border_opaque_5.png-preview.png
bk_border_opaque_small.png
bk_border_opaque_small.png-preview.png
window_flash.png
window_flash.png-preview.png
175
bk_border.png
bk_border.png-preview.png
bk_border_opaque_5.png
bk_border_opaque_5.png-preview.png
bk_border_opaque_small.png
bk_border_opaque_small.png-preview.png
window_flash.png
window_flash.png-preview.png
menu_sysc_lang.xml
msgbox_instrunning.xml
msgbox_quaran_clear.xml
res
defaults.xml
fonts.xml
images.xml
images_menu.xml
styles.xml
skin
black
img
bk_corner8.svg
bk_round.svg
btn_close.svg
btn_gray.svg
btn_min.svg
btn_orange.svg
draw_logo_reverse.svg
eye_close.svg
eye_open.svg
progress.svg
progress.svg-preview.jpg
white
img
bk_corner8.svg
bk_round.svg
btn_close.svg
btn_orange.svg
strings
zh-cn.xml
zh-tw.xml
tooltips.xml
RT_ICON
ID:0001
ID:1033
ID:0002
ID:1033
ID:0003
ID:1033
ID:0004
ID:1033
ID:0005
ID:1033
ID:0006
ID:1033
ID:0007
ID:1033
ID:0008
ID:1033
ID:0009
ID:1033
ID:1033-preview.png
ID:000A
ID:1033
ID:000B
ID:1033
ID:000C
ID:1033
ID:000D
ID:1033
RT_GROUP_CURSOR4
ID:0085
ID:1033
RT_VERSION
ID:0001
ID:1033
ID:2052
RT_MANIFEST
ID:0001
ID:1033
aefb098408e904dfdbd501aa9b76f0de
0x0016A3F7.svg
0x0016A3F7.svg-preview.jpg
0x0016AD3A.svg
0x0016AD3A.svg-preview.jpg
0x001787AC.svg
0x001787AC.svg-preview.jpg
0x001788C7.svg
0x001788C7.svg-preview.jpg
0x00178998.svg
0x00178998.svg-preview.jpg
0x00178A68.svg
0x00178A68.svg-preview.jpg
0x00178B3A.svg
0x00178CC8.svg
0x00178CC8.svg-preview.jpg
0x00178D86.svg
0x00178D86.svg-preview.jpg
0x00178EC9.svg
0x00178EC9.svg-preview.jpg
0x00179000.svg
0x00179000.svg-preview.jpg
0x001790F5.svg
0x001790F5.svg-preview.jpg
0x001791F4.svg
0x001791F4.svg-preview.jpg
0x00179308.svg
0x00179308.svg-preview.jpg
0x001797C3.svg
0x001797C3.svg-preview.jpg
0x00179CAB.svg
0x00179CAB.svg-preview.jpg
0x0017A197.svg
0x0017A197.svg-preview.jpg
0x0017A6A7.svg
0x0017A6A7.svg-preview.jpg
0x0017A7D4.svg
0x0017A7D4.svg-preview.jpg
0x0017A8FE.svg
0x0017A8FE.svg-preview.jpg
0x0017AA2B.svg
0x0017AA2B.svg-preview.jpg
0x0017ABA9.svg
0x0017ABA9.svg-preview.jpg
0x0017AF48.svg
0x0017AF48.svg-preview.jpg
0x0017B326.svg
0x0017B326.svg-preview.jpg
0x0017B708.svg
0x0017B708.svg-preview.jpg
0x0017BAFC.svg
0x0017BAFC.svg-preview.jpg
0x0017BC3D.svg
0x0017BC3D.svg-preview.jpg
0x0017BD7B.svg
0x0017BD7B.svg-preview.jpg
0x0017BEBC.svg
0x0017BEBC.svg-preview.jpg
0x0017C069.svg
0x0017CB53.svg
0x0017D766.svg
0x0017E3C4.svg
0x0017F05B.svg
0x0017FF8C.svg
0x00180E1B.svg
0x00181ACB.svg
0x001823E9.svg
0x00182A70.svg
0x001830D3.svg
0x001836C9.svg
0x00183CA7.svg
0x00184267.svg
0x0018480A.svg
0x00184D36.svg
0x00185265.svg
0x00185772.svg
0x00185B93.svg
0x00185FA6.svg
0x00186304.svg
0x0018665E.svg
0x001869CF.svg
0x00186D4C.svg
0x001870C8.svg
0x00187436.svg
0x001877AF.svg
0x00187B24.svg
0x00187E98.svg
0x001881F6.svg
0x0018858B.svg
0x0018898B.svg
0x0018898B.svg-preview.jpg
0x00188B0E.svg
0x00188B0E.svg-preview.jpg
0x00188C8D.svg
0x00188C8D.svg-preview.jpg
0x00188E10.svg
0x00188E10.svg-preview.jpg
0x00188F95.svg
0x00188F95.svg-preview.jpg
0x0018911B.svg
0x0018911B.svg-preview.jpg
0x0018970B.svg
0x0018970B.svg-preview.jpg
0x00189D42.svg
0x00189D42.svg-preview.jpg
0x0018A37C.svg
0x0018A37C.svg-preview.jpg
0x0018A9BE.svg
0x0018A9BE.svg-preview.jpg
0x0018AD94.svg
0x0018AD94.svg-preview.jpg
0x0018B1B1.svg
0x0018B1B1.svg-preview.jpg
0x0018B5D1.svg
0x0018B5D1.svg-preview.jpg
0x0018B9F8.svg
0x0018B9F8.svg-preview.jpg
0x0018BAAC.svg
0x0018C1D4.svg
0x0018C1D4.svg-preview.jpg
0x0018C562.svg
0x0018C6F0.svg
0x0018C6F0.svg-preview.jpg
0x0018C852.svg
0x0018C852.svg-preview.jpg
0x0018C993.svg
0x0018C993.svg-preview.jpg
0x0018CCBE.svg
0x0018CCBE.svg-preview.jpg
0x0018CDD3.svg
0x0018CDD3.svg-preview.jpg
0x0018D265.svg
0x0018D265.svg-preview.jpg
0x0018D713.svg
0x0018D713.svg-preview.jpg
0x0018DBC2.svg
0x0018DBC2.svg-preview.jpg
0x0018F529.svg
0x0018F529.svg-preview.jpg
0x0018F5DC.svg
0x0018F5DC.svg-preview.jpg
0x0018F68C.svg
0x0018F68C.svg-preview.jpg
0x0018F73F.svg
0x0018F73F.svg-preview.jpg
0x0019C16E.svg
0x0019C16E.svg-preview.jpg
0x0019C2CC.svg
0x0019C2CC.svg-preview.jpg
0x0019C427.svg
0x0019C427.svg-preview.jpg
0x0019C582.svg
0x0019C6E2.svg
0x0019C6E2.svg-preview.jpg
0x0019C869.svg
0x0019CE7D.svg
0x0019D48E.svg
0x0019DAA2.svg
0x0019E0CB.svg
0x0019E4C4.svg
0x0019E8BA.svg
0x0019ECB3.svg
Informations
Name
Value
Info

PE Detect: PeReader OK (file layout)

Info

Authenticode present at 0x1BA400 size 11360 bytes

Info

PDB Path: C:\Users\docker\Documents\workspace\build-v2\common\hr_sysdiag-app-60\bin\x64\uninst_build.pdb

Artefacts
Name
Value
URLs in VB Code - #1

http://www.w3.org/1999/02/22-rdf-syntax-ns#

URLs in VB Code - #2

http://ns.adobe.com/xap/1.0/mm/

URLs in VB Code - #3

http://ns.adobe.com/xap/1.0/sType/ResourceRef#

URLs in VB Code - #4

http://ns.adobe.com/xap/1.0/

URLs in VB Code - #5

http://www.w3.org/2000/svg

URLs in VB Code - #6

http://www.w3.org/1999/xlink

URLs in VB Code - #7

http://crl.comodoca.com/AAACertificateServices.crl04

URLs in VB Code - #8

http://ocsp.comodoca.com0

URLs in VB Code - #9

http://ocsp.digicert.com0C

URLs in VB Code - #10

http://cacerts.digicert.com/DigiCertAssuredIDRootCA.crt0E

URLs in VB Code - #11

http://crl3.digicert.com/DigiCertAssuredIDRootCA.crl0

URLs in VB Code - #12

http://crl.sectigo.com/SectigoPublicCodeSigningRootR46.crl0

URLs in VB Code - #13

http://crt.sectigo.com/SectigoPublicCodeSigningRootR46.p7c0#

URLs in VB Code - #14

http://ocsp.sectigo.com0

URLs in VB Code - #15

http://ocsp.digicert.com0A

URLs in VB Code - #16

http://cacerts.digicert.com/DigiCertTrustedRootG4.crt0C

URLs in VB Code - #17

http://crl3.digicert.com/DigiCertTrustedRootG4.crl0

URLs in VB Code - #18

http://crl3.digicert.com/DigiCertTrustedG4RSA4096SHA256TimeStampingCA.crl0

URLs in VB Code - #19

http://ocsp.digicert.com0X

URLs in VB Code - #20

http://cacerts.digicert.com/DigiCertTrustedG4RSA4096SHA256TimeStampingCA.crt0

URLs in VB Code - #21

https://sectigo.com/CPS0

URLs in VB Code - #22

http://crl.sectigo.com/SectigoPublicCodeSigningCAEVR36.crl0

URLs in VB Code - #23

http://crt.sectigo.com/SectigoPublicCodeSigningCAEVR36.crt0#

URLs in VB Code - #24

http://ocsp.sectigo.com00

URLs in VB Code - #1

http://www.w3.org/1999/02/22-rdf-syntax-ns#

URLs in VB Code - #2

http://ns.adobe.com/xap/1.0/mm/

URLs in VB Code - #3

http://ns.adobe.com/xap/1.0/sType/ResourceRef#

URLs in VB Code - #4

http://ns.adobe.com/xap/1.0/

URLs in VB Code - #5

http://www.w3.org/2000/svg

URLs in VB Code - #6

http://www.w3.org/1999/xlink

aefb098408e904dfdbd501aa9b76f0de (1.82 MB)
An error has occurred. This application may no longer respond until reloaded. Reload 🗙