CMBCEditX64.dll

CMBCEditX64

中国民生银行股份有限公司

Publisher:
中国民生银行  (signed by 中国民生银行股份有限公司)

Product:
CMBCEditX64

Version:
1.0.0.4

MD5:
9d351f7f5b3e52b1158812cc437dc965

SHA-1:
f2f8d6def555458b8d99bd95b8fe6b022cd1d489

SHA-256:
419048fc8541d7185fdb58019d32dea0e9e5e6f4fb89b2f4ea880d99ae261cc9

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/15/2024 5:51:21 PM UTC  (today)

File size:
2.3 MB (2,414,616 bytes)

Product version:
1.0.0.4

Copyright:
©2012中国民生银行所有权利保留

Original file name:
CMBCEditX64.dll

File type:
Dynamic link library (Win64 DLL)

Common path:
C:\users\{user}\appdata\local\microsoft\windows\temporary internet files\content.ie5\{random}\cmbceditx64.dll

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
10/27/2015 10:31:45 AM

Valid to:
10/27/2018 10:31:45 AM

Subject:
CN=中国民生银行股份有限公司, OU=科技开发部, O=中国民生银行股份有限公司, L=北京市, S=北京市, C=CN

Issuer:
CN=GlobalSign CodeSigning CA - SHA256 - G2, O=GlobalSign nv-sa, C=BE

Serial number:
1121F0E438AA0DEF923A6D7593BF237A337B

File PE Metadata
Compilation timestamp:
3/25/2016 6:33:26 PM

OS version:
5.2

OS bitness:
Win64

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
49152:RgBeh3rWFArrYIuCxibxN/OChmvOIAPDc9pJgOob88kQI:/hqwDM2pJJQI

Entry address:
0x22B8FE

Entry point:
E9, 5D, 02, 00, 00, E9, C8, D9, FF, FF, F6, C6, 3C, F8, F9, 3B, 4D, F8, E9, 9A, FF, FF, FF, 00, 00, 54, 65, 72, 6D, 69, 6E, 61, 74, 65, 50, 72, 6F, 63, 65, 73, 73, 00, E9, 4E, AC, FF, FF, E9, D8, 08, 00, 00, AF, 84, 7E, 78, 39, D9, 9B, 11, 0B, 08, C5, 56, 9B, 68, E5, 1E, E3, 30, FD, 66, 9B, 70, ED, 86, 1B, C0, 3D, 2E, E3, 58, A5, BE, 43, 78, 85, 0E, 47, 41, 66, 00, 2C, 51, D6, 7A, F9, 14, E6, D0, 17, 27, 55, FD, 40, 3C, 9A, 3A, 73, 78, A5, A6, E9, 45, C6, D9, 45, 5E, BD, 35, 01, 94, 77, DB, B8, B7, 1B, D8...
 
[+]

Entropy:
7.2244

Packer / compiler:
Xtreme-Protector v1.05

Code size:
677.5 KB (693,760 bytes)

The file CMBCEditX64.dll has been seen being distributed by the following URL.

Scan CMBCEditX64.dll - Powered by Reason Core Security