Suspicious
Suspect

dd7b3bc409695c0caac1a2f589fa4108

PE Executable
|
MD5: dd7b3bc409695c0caac1a2f589fa4108
|
Size: 405.5 KB
|
application/x-dosexec


Print
Summary by MalvaGPT
Characteristics
Hash
Hash Value
MD5
dd7b3bc409695c0caac1a2f589fa4108
Sha1
c74f976492e7b7474ab3537f63f98f13b182b83c
Sha256
3c1a2fa98aaf7394ba262ef8d47c4ac1355c8c2224bfd961e130a48a1b7d8708
Sha384
4144c04b61db404172657f98b801abbd83ff181411abd19febe0993c05355353ec8aff68722fdfb19d0b0ed37e0e5fca
Sha512
ab06da10bf6f771fb8af1dcc1f12baab5f12916549a7bb064562656b82083083164304ff7885dd9be6338860a4268fc681c65525368cc3540b4927139424cce4
SSDeep
6144:iIRkVICSS3prHaXhwBYZZhdRYpFilCGZ6ZcZMMneXUpm2AbLEsx6i0w3d7y6m:eImNaGBG3Ye6ZcmiPAbL3oi3d6
TLSH
1A84F12A77EC14AAD97653748CB30A206731F8645B22DBDF0250813C5F66FD4AE34F9A

PeID

Microsoft Visual C++ v6.0 DLL
Microsoft v12.00 64bit C++ DLL - sign ASL ( 64 bit )
File Structure
[Authenticode]_5cda2906.p7b
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.didat
.guids
.rsrc
.reloc
Resources
MUI
ID:0001
ID:1033
WEVT_TEMPLATE
ID:0001
ID:1033
RT_ICON
ID:0001
ID:1033
RT_RCDATA
ID:00C8
ID:1033
ID:0202
ID:1033
ID:0203
ID:1033
ID:0204
ID:1033
ID:0207
ID:1033
ID:020A
ID:1033
ID:020B
ID:1033
RT_GROUP_CURSOR4
ID:0064
ID:1033
RT_VERSION
ID:0001
ID:1033
Informations
Name
Value
Info

PE Detect: PeReader OK (file layout)

Info

Authenticode present at 0x21800 size 11160 bytes

Info

PDB Path: winmm.pdb

dd7b3bc409695c0caac1a2f589fa4108 (405.5 KB)
An error has occurred. This application may no longer respond until reloaded. Reload 🗙