ambyv2.dll

MD5:
dee330450db2f7dfbc9764f42c66f1b6

SHA-1:
db31c651937abf9efec06a0a26cc10d62e5f0d11

SHA-256:
cb1d317d0102451826886f5147b03819fa2e54c00f8e6619158ec91b7b72bcf2

Scanner detections:
1 / 68

Status:
Clean  (1 probable false positive detection)

Explanation:
This is mosty likely a false positive detection, the file is probably clean.

Analysis date:
12/26/2024 11:21:44 AM UTC  (today)

Scan engine
Detection
Engine version

Rising Antivirus
PE:Malware.Generic(Thunder)!1.A1C4 [F]
23.00.65.16308

File size:
49.5 KB (50,688 bytes)

File type:
Dynamic link library (Win32 DLL)

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\ambyv2.dll

File PE Metadata
Compilation timestamp:
2/27/2016 8:38:08 AM

OS version:
6.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
14.0

CTPH (ssdeep):
768:bPCk42KW3c4yJC11ddB9MBnx7bv37JQx2coNqUSlLGDD/ZJWHQi6SFhu:OkWJC11B96x7bv37JQI1ELGnZJE6S7

Entry address:
0x7567

Entry point:
55, 8B, EC, 83, 7D, 0C, 01, 75, 05, E8, 79, 05, 00, 00, FF, 75, 10, FF, 75, 0C, FF, 75, 08, E8, B1, FE, FF, FF, 83, C4, 0C, 5D, C2, 0C, 00, FF, 25, C4, 91, 00, 10, 55, 8B, EC, 6A, 00, FF, 15, 40, 90, 00, 10, FF, 75, 08, FF, 15, 44, 90, 00, 10, 68, 09, 04, 00, C0, FF, 15, 3C, 90, 00, 10, 50, FF, 15, 38, 90, 00, 10, 5D, C3, 55, 8B, EC, 81, EC, 24, 03, 00, 00, 6A, 17, E8, D8, 06, 00, 00, 85, C0, 74, 05, 6A, 02, 59, CD, 29, A3, F0, D3, 00, 10, 89, 0D, EC, D3, 00, 10, 89, 15, E8, D3, 00, 10, 89, 1D, E4, D3, 00...
 
[+]

Entropy:
6.2074

Developed / compiled with:
Microsoft Visual C++

Code size:
29.5 KB (30,208 bytes)

The file ambyv2.dll has been seen being distributed by the following 8 URLs.

https://fs05n5.sendspace.com/dl/763b8369f4f26c32482bc4dff1fe649d/56eef9fb071b37c0/.../stokmav3 updated.dll

https://fs05n2.sendspace.com/dl/88fd9368b31bd792eca6b74462afd745/5869e740726b2d59/.../stokmav3 updated.dll

https://fs05n1.sendspace.com/dl/6725d4b3306e753a7f08be42f56b8119/575fddf6030a71f2/.../stokmav3 updated.dll

https://fs12n2.sendspace.com/dl/50d93ac5ecfe8c89577e1a3b08ca8e33/56dc27fd34e6745b/.../RC7(CRACKED).dll

Scan ambyv2.dll - Powered by Reason Core Security