halycon.dll

The library halycon.dll has been detected as malware by 6 anti-virus scanners. The file has been seen being downloaded from download701.mediafire.com and multiple other hosts.
MD5:
681f38ee66e5dc9566feb9b306ae8fd8

SHA-1:
752ff13d7b59a0fd7515c2093f9cdacab5df50ea

SHA-256:
4f098ecee5bd2d92b167434fac56d55ad51a2582ad24ce17a7b3df92624487e1

Scanner detections:
6 / 68

Status:
Malware

Analysis date:
12/26/2024 4:31:17 AM UTC  (today)

Scan engine
Detection
Engine version

AegisLab AV Signature
Virus.W32.Blacked!c
2.1.4+

Avira AntiVirus
TR/Black.Gen2
8.3.3.4

AVG
Win32/Blacked
2017.0.2683

ESET NOD32
Win32/Packed.VMProtect.ABO (variant)
10.13799

Qihoo 360 Security
HEUR/QVM36.0.0000.Malware.Gen
1.0.0.1120

Sophos
Mal/VMProtBad-A
4.98

File size:
542.5 KB (555,520 bytes)

File type:
Dynamic link library (Win32 DLL)

Common path:
C:\users\{user}\downloads\halycon.dll

File PE Metadata
Compilation timestamp:
7/13/2016 9:40:53 PM

OS version:
6.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
14.0

CTPH (ssdeep):
12288:iVI+UlPQgCObexFySsQn4ZmyuoyOFtyM6VJB8MPDS5e2wZZTA6V:4INQ3OCxFySsi4gdOFtN6VnDKe2wZZ04

Entry address:
0x179966

Entry point:
E9, F3, 38, FE, FF, 4F, 64, 19, 68, 54, 4B, 7E, E3, 5B, A0, A8, 47, 6F, DC, 95, 2B, D4, 61, D8, 10, AE, C4, F9, 3C, FD, DC, A0, A2, 5A, 72, 8A, 12, 6C, BD, 49, 8B, EC, FF, FD, 67, 5F, 58, 7F, AB, C1, 3D, 9E, D1, 2B, AF, 96, 32, 1D, F2, 29, 8E, C5, 92, EB, FF, FB, B0, 64, 49, BF, E9, 40, F3, BD, D3, D4, 9E, 90, 1A, 69, 51, 1E, 54, D0, 77, 87, 50, D8, 25, 10, F7, 3C, 32, 0A, 51, AC, 02, 30, F3, AF, FB, 2A, A5, 47, 56, B6, 56, 53, 9B, 45, 65, 14, DF, 60, 7F, 5F, 5F, AC, 1E, 7A, E0, 40, DC, 0E, 0E, 82, F2, F1...
 
[+]

Entropy:
7.4177

Packer / compiler:
Xtreme-Protector v1.05

Code size:
174 KB (178,176 bytes)

The file halycon.dll has been seen being distributed by the following 3 URLs.

http://download701.mediafire.com/4r43uw8xfvig/.../Halycon.dll

http://download701.mediafire.com/ww8awc8b67qg/.../Halycon.dll

Remove halycon.dll - Powered by Reason Core Security