buddha.dll

MD5:
7061a67308a68c1fe89a7fab4f7cb8db

SHA-1:
f7e601548edb8c01de63ce48531d2d1cd2f12c55

SHA-256:
75460e2cca2f421f7052c8766310acce5418f3d9f503c7b9f7ff344b18bf0fe5

Scanner detections:
7 / 68

Status:
Inconclusive  (not enough data for an accurate detection)

Analysis date:
11/24/2024 12:52:44 PM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
Suspicious
7.1.1

Bkav FE
W32.Clod71e.Trojan
1.3.0.4613

Clam AntiVirus
Win.Trojan.Agent-162350
0.98/18155

McAfee
Artemis!7061A67308A6
5600.7242

Norman
Suspicious_Gen4.DQMRH
11.20140122

Sophos
Mal/VMProtBad-A
4.96

ViRobot
Trojan.Win32.A.PSW-Tepfer.66560.L
2011.4.7.4223

File size:
65 KB (66,560 bytes)

File type:
Dynamic link library (Win32 DLL)

Common path:
C:\Program Files\square enix\hitman absolution\buddha.dll

File PE Metadata
Compilation timestamp:
12/14/2012 2:26:54 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
5.12

CTPH (ssdeep):
1536:jdFXa0+2lxZ1tYDadasVg3jEUPcLlgWd:j3Xa0+2R5wE+QlgE

Entry address:
0xEC45

Entry point:
9C, C7, 04, 24, 63, B2, 07, 10, E8, 75, 20, 00, 00, 8A, 07, F8, F8, 84, C0, 68, A9, F1, 23, 34, E8, 26, 21, 00, 00, 0F, C8, 8D, 7F, 01, 98, E8, D7, 94, 00, 00, 80, EF, 5D, 66, 0F, BA, FB, 04, 66, 0F, BA, FB, 02, 66, 8B, 1E, E8, 2A, F4, FF, FF, F5, 3B, 4D, FC, E9, 1B, 07, 00, 00, 60, C7, 44, 24, 1C, 78, 54, 07, 10, C6, 44, 24, 18, BD, C7, 44, 24, 18, 87, 72, E8, AD, 9C, 8D, 64, 24, 1C, E9, 09, D0, 00, 00, E8, ED, 0C, 00, 00, 9C, 89, EC, 8D, 2C, D5, 26, 0B, 00, 82, BD, BE, ED, EB, 3B, 5D, 53, FF, 74, 24, 04...
 
[+]

Entropy:
7.6741

Code size:
3 KB (3,072 bytes)

The file buddha.dll has been discovered within the following programs.

A Heart of Darkness  by Paradox Interactive
Publisher's description - “Heart of Darkness, the second expansion for the grand strategy/ political simulator focuses on the Scramble for Africa as you compete with other colonial powers and experience international crises which require Great Power mediation if the world is to avoid war.”
tabletoknet.com/load
About 1% of users remove it
Hitman - Absolution  by R.G. Mechanics
This is a repack version of the game which might not be a legal or legitimate copy, please refer to the game copyright. This repack is generates a custom packed installer using lossy/lossless compression for included sounds, videos and textures.
tapochek.net
12% remove it
V2 Interwar Artillery  by GamersGate
V2 Interwar Artillery is a video game distributed on the GamersGate game store which uses a micros-download client.
www.gamersgate.com
About 5% of users remove it
V2 Interwar Planes  by GamersGate
V2 Interwar Planes is a video game distributed on the GamersGate game store which uses a micros-download client.
About 6% of users remove it
Victoria 2 Heart of Darkness  by Friends in War
This game for the PC is distributed by the Friends in War portal using a custom installer.
www.friendsinwar.com
About 76% of users remove it
Victoria II is a video game distributed on the GamersGate game store which uses a micros-download client.
About 2% of users remove it
 
Powered by Should I Remove It?

The file buddha.dll has been seen being distributed by the following URL.

Scan buddha.dll - Powered by Reason Core Security