Suspicious
Suspect

e4b3b0fd69a82cab356cf376dd5664bb

PE Executable
|
MD5: e4b3b0fd69a82cab356cf376dd5664bb
|
Size: 4.38 MB
|
application/x-dosexec

Summary by MalvaGPT
Characteristics
Hash
Hash Value
MD5
e4b3b0fd69a82cab356cf376dd5664bb
Sha1
b7a65d8e9a0ef3701893663b9b5b66c97406d62a
Sha256
ffc68bcc194b6cc3de0564c5e05d01764c3163250348455039779fd342d26d3d
Sha384
219c91f79abd3dc0c87a029e2dcaaad5e6d71f0788f330a1c68d6b10dc5a2620ca0917a6c9f4213c6f56e4f3436c67b2
Sha512
54c0310daeb0e1ca3c37558017ed9988f77296afd4b4bcabd6bb24785eee75ddc91fa5e06ed323ddefe587c8098a199860bbe09cbf7ee9645e8b7ffc6041b113
SSDeep
98304:6E4EJw7WcZylpDdSubnBn7u6XUEASaQgtbcQi51w0flx8OnlA44NISRCJ:cEJwycElpDoubBCIUEucR7w0fr8OQISm
TLSH
E0169EE3752BD1DFC24988B8A6028E435C1697F3E605F617EC193DAF8A72DB253C6604

PeID

Microsoft Visual C++ v6.0 DLL
RPolyCryptor V1.4.2 -> Vaska
UPolyx 0.4 -> delikon
File Structure
[Authenticode]_b78c1e5a.p7b
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.idata
.rsrc
.themida
Resources
RT_ICON
ID:0001
ID:0
ID:0-preview.png
ID:0002
ID:0
ID:0003
ID:0
ID:0004
ID:0
ID:0005
ID:0
ID:0006
ID:0
ID:0007
ID:0
ID:0008
ID:0
ID:0009
ID:0
RT_GROUP_CURSOR4
ID:0001
ID:0
RT_VERSION
ID:0001
ID:1033
Informations
Name
Value
Info

PE Detect: PeReader OK (file layout)

Info

Authenticode present at 0x427400 size 20872 bytes

e4b3b0fd69a82cab356cf376dd5664bb (4.38 MB)
File Structure
[Authenticode]_b78c1e5a.p7b
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.idata
.rsrc
.themida
Resources
RT_ICON
ID:0001
ID:0
ID:0-preview.png
ID:0002
ID:0
ID:0003
ID:0
ID:0004
ID:0
ID:0005
ID:0
ID:0006
ID:0
ID:0007
ID:0
ID:0008
ID:0
ID:0009
ID:0
RT_GROUP_CURSOR4
ID:0001
ID:0
RT_VERSION
ID:0001
ID:1033
Characteristics
No malware configuration were found at this point.
You must be signed in to post a comment.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙