CabDLL.dll

CabDLL

Li Xin

Publisher:
Li Xin  (signed and verified)

Product:
CabDLL

Description:
CabDLL plug-in

Version:
1.1

MD5:
816cec24548f0e8a185cdf6e8cb80b6a

SHA-1:
3a8dca60205e6c719c318f71ea878d2e2881346d

SHA-256:
bf07a2c9d799b3c2ec67094f2a2d4629b25992804be7c2c282664480cb980314

Scanner detections:
4 / 68

Status:
Inconclusive  (not enough data for an accurate detection)

Analysis date:
12/26/2024 7:24:26 PM UTC  (today)

Scan engine
Detection
Engine version

AegisLab AV Signature
Virus.Gen!c
2.1.4+

AVG
Generic
2017.0.2854

Bkav FE
W32.HfsAdware
1.3.0.7400

Microsoft Security Essentials
SoftwareBundler:Win32/Xiazai
1.1.12400.0

File size:
13.1 KB (13,400 bytes)

Product version:
1.1

Copyright:
CabDLL

Original file name:
CabDLL.dll

File type:
Dynamic link library (Win32 DLL)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\cabdll.dll

Digital Signature
Signed by:

Authority:
WoSign CA Limited

Valid from:
3/12/2015 9:55:41 PM

Valid to:
3/12/2016 9:55:41 PM

Subject:
CN=Li Xin, L=Yingshan, S=Sichuan, C=CN

Issuer:
CN=WoSign Class 2 Code Signing CA, O=WoSign CA Limited, C=CN

Serial number:
4EC8808F9295E7018CE5A64639E18B6B

File PE Metadata
Compilation timestamp:
9/18/2015 4:30:15 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.50

CTPH (ssdeep):
192:XTcWPjcAtbkhoGGq1wkAzgn91KUlpXNh/bq1oWG0EgpwDkA:XTcW9tYCq65zg9QyXNh/bq1VG0EnQ

Entry address:
0x1450

Entry point:
8B, 44, 24, 04, 8B, 54, 24, 08, 83, FA, 03, 77, 1D, FF, 24, 95, 18, 20, 00, 10, A3, 00, 30, 00, 10, 6A, 00, 6A, 00, 6A, 01, 6A, 00, FF, 15, 10, 31, 00, 10, C2, 0C, 00, B0, 01, C2, 0C, 00, FF, 25, 30, 31, 00, 10, FF, 25, 34, 31, 00, 10, FF, 25, 38, 31, 00, 10, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, 57, 53, 8B, 7C, 24, 0C, 8B, 44, 24, 10, 8B, 4C, 24, 14, 25, FF, 00, 00, 00, 89, CB, F7, 05, 04, 30, 00, 10, 02, 00, 00, 00, 0F, 84, B8, 00, 00, 00, 89, C2, C1, E0, 08, 01, D0, 89, C2, C1, E0...
 
[+]

Entropy:
6.4181

Code size:
1.5 KB (1,536 bytes)

Scan CabDLL.dll - Powered by Reason Core Security