gifanimatorxt.exe

NT NETWORK ŁUKASZ SZABELSKI

This is a setup program which is used to install the application. The file has been seen being downloaded from legalne.info.pl and multiple other hosts.
Publisher:
NT NETWORK ŁUKASZ SZABELSKI  (signed and verified)

Description:
Gif Animator XT

Version:
1.5.0.0

MD5:
9873b623e7c72c8f102d6b2b921974e9

SHA-1:
3aa5ff13ae0e1579bf4db66228cbba033f4e6dbd

SHA-256:
f4c5b6a9b0cc4da173eead631d3a55b6f635cf328436e196a5e3cc50adddddb2

Scanner detections:
1 / 68

Status:
Clean  (1 probable false positive detection)

Explanation:
This is mosty likely a false positive detection, the file is probably clean.

Analysis date:
12/26/2024 8:36:54 PM UTC  (today)

Scan engine
Detection
Engine version

Vba32 AntiVirus
suspected of Backdoor.Delf.124
3.12.26.3

File size:
1.3 MB (1,353,720 bytes)

Product version:
1.5.0.0

Copyright:
Copyright © 2006-2012 - Nt Network Łukasz Szabelski

File type:
Executable application (Win32 EXE)

Language:
Polish (Poland)

Common path:
C:\users\{user}\downloads\gifanimatorxt.exe

Digital Signature
Authority:
Unizeto Technologies S.A.

Valid from:
7/19/2011 4:06:55 PM

Valid to:
7/18/2012 4:06:55 PM

Subject:
E=kruger1111@wp.pl, CN=ŁUKASZ SZABELSKI, O=NT NETWORK ŁUKASZ SZABELSKI, C=PL

Issuer:
CN=Certum Level III CA, OU=Certum Certification Authority, O=Unizeto Technologies S.A., C=PL

Serial number:
72A6AEF111D42AE39AC501B564BFD816

File PE Metadata
Compilation timestamp:
6/20/1992 12:22:17 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
24576:77xDccowTxjFptX/AWp5cUeiMeBmDd6f67neHaBUTb:7760BPAWPwDSSneHvb

Entry address:
0x76EF8

Entry point:
55, 8B, EC, 83, C4, F0, B8, E8, 6C, 47, 00, E8, 90, F5, F8, FF, A1, 70, 8B, 47, 00, 8B, 00, E8, 68, 70, FE, FF, 8B, 0D, AC, 8C, 47, 00, A1, 70, 8B, 47, 00, 8B, 00, 8B, 15, 64, 3B, 47, 00, E8, 68, 70, FE, FF, 8B, 0D, 70, 8C, 47, 00, A1, 70, 8B, 47, 00, 8B, 00, 8B, 15, 60, 3E, 47, 00, E8, 50, 70, FE, FF, A1, 70, 8B, 47, 00, 8B, 00, E8, C4, 70, FE, FF, E8, BB, D3, F8, FF, 8D, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
472 KB (483,328 bytes)

The file gifanimatorxt.exe has been seen being distributed by the following 3 URLs.

http://legalne.info.pl/down/.../3876

Scan gifanimatorxt.exe - Powered by Reason Core Security