Suspicious
Suspect

ef7544838422a37f95eb5e8e16b41d3f

PE Executable
|
MD5: ef7544838422a37f95eb5e8e16b41d3f
|
Size: 3.49 MB
|
application/x-dosexec

Summary by MalvaGPT
Characteristics
Hash
Hash Value
MD5
ef7544838422a37f95eb5e8e16b41d3f
Sha1
25ed45c2db60e89d1cabd5fa1e0224f8695babae
Sha256
072114eba4f486f0f8e006bf8406164eefc0fee4f92a79f5ad2cf343ee212231
Sha384
43e593109cec936fa2290828aaead17c83379e00e75910359e6f017af921351b747d4402ec6c002c196294de7eba2dfe
Sha512
f4fc01f8bb956185a63e9d5d1f67aafe7a99144821de3098a02f9180625f496449b4b8fbd17cc3215c8c8e56fe8504e1fb1f642c36a59f70d5fc53ec2f72fe7f
SSDeep
49152:ggCH0r8NK8zYrOF88uWU1QBBqVpzZOBVon/FdM7OViNvVxxx+d+S8BQOkHD3+tG:DA4qa
TLSH
3DF5F450ADBAF860CC0E4C708CA7527E6237DD1E53AB8993C9D0BDAD987A5C4F9D2344

PeID

Microsoft Visual C++ v6.0 DLL
PeStubOEP v1.x
tElock 1.0 (private) -> tE!
tElock 1.0 (private) -> tE!
File Structure
[Authenticode]_b877664a.p7b
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rdata
.data
.idata
.reloc
.symtab
.rsrc
Resources
ZIPRES
ID:0000
bg.svg-preview.jpg
bgshadw.png
bgshadw.png-preview.png
blue_disable.svg
blue_disable.svg-preview.jpg
blue_hover.svg
blue_hover.svg-preview.jpg
blue_normal.svg
blue_normal.svg-preview.jpg
browse_btn_hover.svg
browse_btn_hover.svg-preview.jpg
browse_btn_normal.svg
browse_btn_normal.svg-preview.jpg
check_disable.svg
check_disable.svg-preview.jpg
check_sel.svg
check_sel.svg-preview.jpg
close_hover.svg
close_hover.svg-preview.jpg
edit_bg.svg
edit_bg.svg-preview.jpg
InstallMainWnd.xml
install_drop_down_normal.svg
install_drop_down_normal.svg-preview.jpg
install_drop_down_normal_reverse.svg
install_drop_down_normal_reverse.svg-preview.jpg
install_drop_down_select.svg
install_drop_down_select.svg-preview.jpg
install_drop_down_select_reverse.svg
install_drop_down_select_reverse.svg-preview.jpg
language
logo.svg-preview.jpg
progressing.png
progressing.png-preview.png
progressing@125.png
progressing@125.png-preview.png
progressing@150.png
progressing@150.png-preview.png
progressing@175.png
progressing@175.png-preview.png
progressing@200.png
progressing@200.png-preview.png
progress_normal.svg
progress_normal.svg-preview.jpg
scrollbar
scrollbar_rail.svg
scrollbar_rail.svg-preview.jpg
scrollbar_rail2.svg
scrollbar_rail2.svg-preview.jpg
scrollbar_rail_hover.svg
scrollbar_rail_hover.svg-preview.jpg
scrollbar_rail_hover2.svg
scrollbar_rail_hover2.svg-preview.jpg
scrollbar_rail_hover_small.svg
scrollbar_rail_hover_small.svg-preview.jpg
scrollbar_rail_small.svg
scrollbar_rail_small.svg-preview.jpg
success_mark.svg
success_mark.svg-preview.jpg
uncheck_normal.svg
uncheck_normal1.svg
uncheck_normal1.svg-preview.jpg
RT_ICON
ID:0001
ID:0
ID:0002
ID:0
ID:0003
ID:0
ID:0004
ID:0
ID:0005
ID:0
ID:0006
ID:0
ID:0007
ID:0
ID:0008
ID:0
RT_MENU
ID:006D
ID:2052
RT_DIALOG
ID:0067
ID:2052
RT_STRING
ID:0007
ID:2052
RT_ACCELERATOR
ID:006D
ID:2052
RT_GROUP_CURSOR4
ID:006A
ID:0
RT_VERSION
ID:0001
ID:2052
RT_MANIFEST
ID:0001
ID:1033
Informations
Name
Value
Info

PE Detect: PeReader OK (file layout)

Info

Authenticode present at 0x352000 size 10640 bytes

ef7544838422a37f95eb5e8e16b41d3f (3.49 MB)
File Structure
[Authenticode]_b877664a.p7b
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rdata
.data
.idata
.reloc
.symtab
.rsrc
Resources
ZIPRES
ID:0000
bg.svg-preview.jpg
bgshadw.png
bgshadw.png-preview.png
blue_disable.svg
blue_disable.svg-preview.jpg
blue_hover.svg
blue_hover.svg-preview.jpg
blue_normal.svg
blue_normal.svg-preview.jpg
browse_btn_hover.svg
browse_btn_hover.svg-preview.jpg
browse_btn_normal.svg
browse_btn_normal.svg-preview.jpg
check_disable.svg
check_disable.svg-preview.jpg
check_sel.svg
check_sel.svg-preview.jpg
close_hover.svg
close_hover.svg-preview.jpg
edit_bg.svg
edit_bg.svg-preview.jpg
InstallMainWnd.xml
install_drop_down_normal.svg
install_drop_down_normal.svg-preview.jpg
install_drop_down_normal_reverse.svg
install_drop_down_normal_reverse.svg-preview.jpg
install_drop_down_select.svg
install_drop_down_select.svg-preview.jpg
install_drop_down_select_reverse.svg
install_drop_down_select_reverse.svg-preview.jpg
language
logo.svg-preview.jpg
progressing.png
progressing.png-preview.png
progressing@125.png
progressing@125.png-preview.png
progressing@150.png
progressing@150.png-preview.png
progressing@175.png
progressing@175.png-preview.png
progressing@200.png
progressing@200.png-preview.png
progress_normal.svg
progress_normal.svg-preview.jpg
scrollbar
scrollbar_rail.svg
scrollbar_rail.svg-preview.jpg
scrollbar_rail2.svg
scrollbar_rail2.svg-preview.jpg
scrollbar_rail_hover.svg
scrollbar_rail_hover.svg-preview.jpg
scrollbar_rail_hover2.svg
scrollbar_rail_hover2.svg-preview.jpg
scrollbar_rail_hover_small.svg
scrollbar_rail_hover_small.svg-preview.jpg
scrollbar_rail_small.svg
scrollbar_rail_small.svg-preview.jpg
success_mark.svg
success_mark.svg-preview.jpg
uncheck_normal.svg
uncheck_normal1.svg
uncheck_normal1.svg-preview.jpg
RT_ICON
ID:0001
ID:0
ID:0002
ID:0
ID:0003
ID:0
ID:0004
ID:0
ID:0005
ID:0
ID:0006
ID:0
ID:0007
ID:0
ID:0008
ID:0
RT_MENU
ID:006D
ID:2052
RT_DIALOG
ID:0067
ID:2052
RT_STRING
ID:0007
ID:2052
RT_ACCELERATOR
ID:006D
ID:2052
RT_GROUP_CURSOR4
ID:006A
ID:0
RT_VERSION
ID:0001
ID:2052
RT_MANIFEST
ID:0001
ID:1033
Characteristics
No malware configuration were found at this point.
You must be signed in to post a comment.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙