Suspicious
Suspect

f4ca46f09b2ec7c6b9d18a3f1b33d9de

PE Executable
|
MD5: f4ca46f09b2ec7c6b9d18a3f1b33d9de
|
Size: 4.48 MB
|
application/x-dosexec


Print
Summary by MalvaGPT
Characteristics
Hash
Hash Value
MD5
f4ca46f09b2ec7c6b9d18a3f1b33d9de
Sha1
12152d94307d9d35d49d1078dc07299dd56a6465
Sha256
42080f55d85f3714ded4618658841629277fef1b7b61afbc0104e8200a2b5d99
Sha384
b652735eab198309565e927286f5760ceae8c42a015f50636f682526348b67ec8d65c8b71d8ab5554ad5f83644adb0d9
Sha512
c349982e799be0f3aa20cdfd38692aed4df3dee0a0c41fe682a086d5a75d7708947db928ceffb5cc59be9627f3030aef048974fd80da4790dca2c0841e06f55c
SSDeep
49152:vELQDQ8SRtELQjXkKDbzBPN1iRvs+DofT4VA9XWAGJ2fmbSro2gSuhG:vgysI4ip+T429XWAGJIo2gSuhG
TLSH
6C267B07B8A185A5C359DA3585B6E17176A1BC441F2123F32B51B6E43EB3BCCAD7B308

PeID

HQR data file
Microsoft Visual C++ v6.0 DLL
Private EXE Protector V2.30-V2.3X -> SetiSoft Team
tElock 1.0 (private) -> tE!
tElock 1.0 (private) -> tE!
File Structure
7z-stream @ 0x002FD218.7z
enlarge200
store
bg.png-preview.png
btn_cancel_hover40.png
btn_cancel_hover40.png-preview.png
btn_cancel_hover48.png
btn_cancel_hover48.png-preview.png
btn_cancel_normal40.png
btn_cancel_normal40.png-preview.png
btn_cancel_normal48.png
btn_cancel_normal48.png-preview.png
btn_cancel_push40.png
btn_cancel_push40.png-preview.png
btn_cancel_push48.png
btn_cancel_push48.png-preview.png
btn_sure_hover40.png
btn_sure_hover40.png-preview.png
btn_sure_hover48.png
btn_sure_hover48.png-preview.png
btn_sure_hover_shadow.png
btn_sure_hover_shadow.png-preview.png
btn_sure_normal40.png
btn_sure_normal40.png-preview.png
btn_sure_normal48.png
btn_sure_normal48.png-preview.png
btn_sure_normal_shadow.png
btn_sure_normal_shadow.png-preview.png
btn_sure_push40.png
btn_sure_push40.png-preview.png
btn_sure_push48.png
btn_sure_push48.png-preview.png
btn_sure_push_shadow.png
btn_sure_push_shadow.png-preview.png
close_hover.png
close_hover.png-preview.png
close_normal.png
close_normal.png-preview.png
min_hover.png
min_hover.png-preview.png
min_normal.png
min_normal.png-preview.png
pack_off_hover.png
pack_off_hover.png-preview.png
pack_off_normal.png
pack_off_normal.png-preview.png
pack_up_hover.png
pack_up_hover.png-preview.png
pack_up_normal.png
pack_up_normal.png-preview.png
progress_bg.png
progress_bg.png-preview.png
progress_fg.png
progress_fg.png-preview.png
radio_hover.png
radio_hover.png-preview.png
radio_normal.png
radio_normal.png-preview.png
radio_selected_hover.png
radio_selected_hover.png-preview.png
radio_selected_normal.png
radio_selected_normal.png-preview.png
mainframe.xml
multi_language.tsv
store
bg.png-preview.png
browser_hover.png
browser_hover.png-preview.png
browser_normal.png
browser_normal.png-preview.png
browser_pushed.png
browser_pushed.png-preview.png
btn_cancel_hover40.png
btn_cancel_hover40.png-preview.png
btn_cancel_hover48.png
btn_cancel_hover48.png-preview.png
btn_cancel_normal40.png
btn_cancel_normal40.png-preview.png
btn_cancel_normal48.png
btn_cancel_normal48.png-preview.png
btn_cancel_push40.png
btn_cancel_push40.png-preview.png
btn_cancel_push48.png
btn_cancel_push48.png-preview.png
btn_sure_hover40.png
btn_sure_hover40.png-preview.png
btn_sure_hover48.png
btn_sure_hover48.png-preview.png
btn_sure_hover_shadow.png
btn_sure_hover_shadow.png-preview.png
btn_sure_normal40.png
btn_sure_normal40.png-preview.png
btn_sure_normal48.png
btn_sure_normal48.png-preview.png
btn_sure_normal_shadow.png
btn_sure_normal_shadow.png-preview.png
btn_sure_push40.png
btn_sure_push40.png-preview.png
btn_sure_push48.png
btn_sure_push48.png-preview.png
btn_sure_push_shadow.png
btn_sure_push_shadow.png-preview.png
close_hover.png
close_hover.png-preview.png
close_normal.png
close_normal.png-preview.png
edit_border_focus.png
edit_border_focus.png-preview.png
edit_border_normal.png
edit_border_normal.png-preview.png
messagebox_bg.png
messagebox_bg.png-preview.png
min_hover.png
min_hover.png-preview.png
min_normal.png
min_normal.png-preview.png
pack_off_hover.png
pack_off_hover.png-preview.png
pack_off_normal.png
pack_off_normal.png-preview.png
pack_up_hover.png
pack_up_hover.png-preview.png
pack_up_normal.png
pack_up_normal.png-preview.png
progress_bg.png
progress_bg.png-preview.png
progress_fg.png
progress_fg.png-preview.png
radio_hover.png
radio_hover.png-preview.png
radio_normal.png
radio_normal.png-preview.png
radio_selected_hover.png
radio_selected_hover.png-preview.png
radio_selected_normal.png
radio_selected_normal.png-preview.png
xml_messagebox_help.xml
xml_messagebox_noicon.xml
xml_messagebox_protocol.xml
[Authenticode]_a4a779d0.p7b
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.xdata
.idata
.reloc
.symtab
.rsrc
Resources
ZIPRES
ID:0081
RT_ICON
ID:0001
ID:0
ID:0-preview.png
ID:0002
ID:0
ID:0003
ID:0
ID:0004
ID:0
ID:0005
ID:0
ID:0006
ID:0
ID:0007
ID:0
ID:0008
ID:0
ID:0009
ID:0
ID:000A
ID:0
ID:000B
ID:0
ID:000C
ID:0
ID:000D
ID:0
ID:000E
ID:0
ID:000F
ID:0
ID:0010
ID:0
ID:0011
ID:0
ID:0012
ID:0
ID:0013
ID:0
ID:0014
ID:0
RT_MENU
ID:006D
ID:2052
RT_DIALOG
ID:0067
ID:2052
RT_STRING
ID:0007
ID:2052
RT_ACCELERATOR
ID:006D
ID:2052
RT_GROUP_CURSOR4
ID:0000
ID:0
ID:006B
ID:0
ID:006C
ID:0
Informations
Name
Value
Info

PE Detect: PeReader OK (file layout)

Info

Authenticode present at 0x440E00 size 20968 bytes

f4ca46f09b2ec7c6b9d18a3f1b33d9de (4.48 MB)
An error has occurred. This application may no longer respond until reloaded. Reload 🗙