normalizer.dll

MD5:
a32497c65d33168a11767024fa6c8412

SHA-1:
249f4b1b380729fed0cdd8c173b5c5fdee7317ef

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/23/2024 7:35:14 PM UTC  (today)

File size:
342 KB (350,208 bytes)

File type:
Dynamic link library (Win32 DLL)

Common path:
C:\Program Files\steinberg\nuendo 4\vstplugins\other\normalizer.dll

File PE Metadata
Compilation timestamp:
6/11/2002 8:18:16 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
5.10

CTPH (ssdeep):
6144:syBLalif3kfK0FI9NaGxXjNNaeL8/K7BE:sOa4viFW1xTFL8/ME

Entry address:
0xC1B0

Entry point:
53, 55, 56, 8B, 74, 24, 14, 85, F6, 57, B8, 01, 00, 00, 00, 75, 13, 8B, 0D, 74, 11, 02, 10, 85, C9, 75, 09, 33, C0, 5F, 5E, 5D, 5B, C2, 0C, 00, 8B, 7C, 24, 1C, 8B, 5C, 24, 14, 83, FE, 01, 74, 05, 83, FE, 02, 75, 28, 8B, 0D, 70, 28, 02, 10, 85, C9, 74, 05, 57, 56, 53, FF, D1, 85, C0, 74, 0C, 57, 56, 53, E8, 8F, FE, FF, FF, 85, C0, 75, 09, 33, C0, 5F, 5E, 5D, 5B, C2, 0C, 00, 57, 56, 53, E8, 5A, 70, FF, FF, 83, FE, 01, 8B, E8, 75, 0C, 85, ED, 75, 08, 57, 50, 53, E8, 67, FE, FF, FF, 85, F6, 74, 05, 83, FE, 03...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
92.5 KB (94,720 bytes)

The file normalizer.dll has been seen being distributed by the following 9 URLs.

http://www.dosya.tc/en2.php?a=server6/.../BLU3TEAM900.dll&b=958a2c548db001da32b8701431b6e293

http://www.dosya.tc/en2.php?a=server6/.../BLU3TEAM900.dll&b=d34d7ca81920f48203bb15f5509c3aee

http://www.dosya.tc/en2.php?a=server6/.../BLU3TEAM900.dll&b=a7ed1114e7458a3e0a00bfde52820eba

http://www.dosya.tc/en2.php?a=server6/.../BLU3TEAM900.dll&b=942f8b46bf9270dd5e95b212c971e868

http://www.dosya.tc/en2.php?a=server6/.../BLU3TEAM900.dll&b=e824cd9811bd44902608e14f0d80c340

http://www.dosya.tc/en2.php?a=server6/.../BLU3TEAM900.dll&b=a19fd100a5035942cb2bd60c9646e290

Scan normalizer.dll - Powered by Reason Core Security