hhse5372mobilyunlocker_v3.exe

DTU53MOB

UAB Digiteka

This is a setup program which is used to install the application. The file has been seen being downloaded from files.dc-unlocker.com.
Publisher:
UAB Digiteka  (signed and verified)

Product:
DTU53MOB

Description:
Huawei E5372 Mobily 21.270.01.00.82 Unlocker

Version:
0.0.0.3

MD5:
eac48d5c4460895a3e5a643028a90b7c

SHA-1:
bcf65e6145c7322475b1032d957c21a7b0d61ec8

SHA-256:
3ca289f0f9081876cdd6f6c24f96d78e8554ac78352f851dd9745772ff43db74

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
12/28/2024 6:34:41 PM UTC  (today)

File size:
16.3 MB (17,055,144 bytes)

Product version:
1.0.0.0

File type:
Executable application (Win32 EXE)

Language:
Lithuanian (Lithuania)

Common path:
C:\users\{user}\downloads\hhse5372mobilyunlocker_v3.exe

Digital Signature
Signed by:

Authority:
StartCom Ltd.

Valid from:
12/13/2015 6:14:37 PM

Valid to:
12/13/2017 10:27:38 AM

Subject:
E=manager@digiteka.lt, CN=UAB Digiteka, O=UAB Digiteka, L=Panevėžio, S=Vilniaus Apskritis, C=LT

Issuer:
CN=StartCom Class 2 Primary Intermediate Object CA, OU=Secure Digital Certificate Signing, O=StartCom Ltd., C=IL

Serial number:
14046FED01524E

File PE Metadata
Compilation timestamp:
8/29/2016 2:57:47 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
393216:It+mjcqgNHgniOEzGoj88SxIJMA7eqAj+n8zK83Bj:RwcqEAninGoj888IWoeqVW

Entry address:
0x22E9ADF

Entry point:
EB, 08, 13, 65, 02, 01, 00, 00, 00, 00, E9, 77, 87, FF, FF, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
7.9995  (probably packed)

Code size:
3.6 MB (3,723,264 bytes)

The file hhse5372mobilyunlocker_v3.exe has been seen being distributed by the following URL.

https://files.dc-unlocker.com/backend/r.php/.../57da8bdc823e9

Scan hhse5372mobilyunlocker_v3.exe - Powered by Reason Core Security