hailhitler.dll

The library hailhitler.dll has been detected as malware by 8 anti-virus scanners. The file has been seen being downloaded from ln.syncusercontent.com.
MD5:
b3ea7367afe930593bbdc3c1b5789781

SHA-1:
5171edc68e66a19bd7241b8f5791fa4c0388aabf

SHA-256:
6ed1efe453fa08f6c8d622b0b4ed0cf2d0ab46819706aafe990926833994151e

Scanner detections:
8 / 68

Status:
Malware

Analysis date:
12/26/2024 2:55:58 AM UTC  (today)

Scan engine
Detection
Engine version

Avira AntiVirus
TR/Black.Gen2
8.3.3.4

avast!
Win32:Malware-gen
2014.9-160425

AVG
Win32/Blacked
2017.0.2762

Bkav FE
HW32.Packed
1.3.0.7744

ESET NOD32
Win32/Packed.VMProtect.ABO (variant)
10.13387

McAfee
Artemis!B3EA7367AFE9
5600.6418

Qihoo 360 Security
HEUR/QVM36.0.0000.Malware.Gen
1.0.0.1120

Sophos
Mal/VMProtBad-A
4.98

File size:
226.5 KB (231,936 bytes)

File type:
Dynamic link library (Win32 DLL)

Common path:
C:\users\{user}\downloads\hailhitler.dll

File PE Metadata
Compilation timestamp:
4/25/2016 12:29:26 AM

OS version:
6.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
14.0

CTPH (ssdeep):
6144:OstgsA5IzpOMPE5jThCL1kEaD2c3GDkmFnhzO:nLA5VMsBThW1xaD2cWZFU

Entry address:
0x12DC1D

Entry point:
E9, C4, D1, 00, 00, 84, D2, F6, C6, F4, 34, 1B, 0F, BA, E2, 15, 38, EA, E8, 6B, C5, FF, FF, FF, 34, 24, 8D, 64, 24, 34, 0F, 84, F6, 59, 00, 00, 84, CD, 01, F8, F8, 57, 39, D0, FF, 34, 24, 9C, E9, 03, 01, 00, 00, 83, EF, 04, F8, E8, 60, 06, 00, 00, 58, 62, BE, 34, B3, 7D, 0E, 5E, 85, B0, 00, 8A, 5B, 26, 4A, F5, 27, 32, 5B, 28, 7E, 48, 63, 0D, B3, 3F, 6C, 97, 25, 70, DA, 44, BB, 66, 25, B2, 7D, D8, 4A, 98, 6E, CB, B2, 9C, 83, ED, 25, 91, A1, 05, 41, C9, BE, 46, 06, 36, 63, C8, EF, DA, A0, 4B, 48, 54, EE, 15...
 
[+]

Entropy:
7.6171

Packer / compiler:
Xtreme-Protector v1.05

Code size:
29.5 KB (30,208 bytes)

The file hailhitler.dll has been seen being distributed by the following URL.

Remove hailhitler.dll - Powered by Reason Core Security