bysnowt.dll

LPB

Publisher:
LPB

Description:
AutoKiill Bumblebee Version

Version:
1.0.0.0

MD5:
ae9d557ed71339d7b5681edede9d26eb

SHA-1:
af32856421f8f94cb10b909534dee2dc1b85d500

SHA-256:
62c1afe9a71ca6cf6c741b71fa9b69b5867e405bdd834aec684449314402fb34

Scanner detections:
1 / 68

Status:
Clean  (1 probable false positive detection)

Explanation:
This is mosty likely a false positive detection, the file is probably clean.

Analysis date:
11/6/2024 12:31:55 PM UTC  (today)

Scan engine
Detection
Engine version

Qihoo 360 Security
HEUR/QVM25.0.Malware.Gen
1.0.0.1077

File size:
747 KB (764,928 bytes)

Product version:
1.0.0.0

Copyright:
Lipinf && Prog

File type:
Dynamic link library (Win32 DLL)

Language:
Brazilian Portuguese

Common path:
C:\users\{user}\downloads\malditohack\bysnowt.dll

File PE Metadata
Compilation timestamp:
6/19/1992 7:22:17 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
12288:Djh1RbkrIPzrkJegMI6yXoGIXca6rMRoK8pRd4Xbcah4Iz:fvqrykoZyYboj5bS4

Entry address:
0x51F54

Entry point:
55, 8B, EC, 83, C4, C4, B8, 44, 1D, 45, 00, E8, 74, 3D, FB, FF, B8, A8, 1C, 45, 00, A3, 64, 46, 45, 00, B8, 01, 00, 00, 00, E8, 30, FD, FF, FF, E8, 2B, 1E, FB, FF, 8D, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
324 KB (331,776 bytes)

The file bysnowt.dll has been seen being distributed by the following URL.

Scan bysnowt.dll - Powered by Reason Core Security