npcmbcedit.dll

CMBCEDIT

中国民生银行股份有限公司

Publisher:
中国民生银行  (signed by 中国民生银行股份有限公司)

Product:
CMBCEDIT

Description:
CMBCEDIT Version:1.0.0.4

Version:
1.0.0.4

MD5:
ea77c343b47cd8b4ff08d85ff2fe266c

SHA-1:
188aeda5ebcb8b83a79cadc8549da34019eb759a

SHA-256:
276f849f7d0868ed9a367e39e0d49f5379c6fc39182acc16ef28c0613007f57a

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
12/29/2024 4:37:17 PM UTC  (today)

File size:
2.1 MB (2,183,192 bytes)

Product version:
3.0.0.0

Copyright:
©2013 所有权利保留

Original file name:
npPassGuard.dll

File type:
Dynamic link library (Win32 DLL)

Common path:
C:\users\{user}\appdata\local\microsoft\windows\temporary internet files\content.ie5\{random}\npcmbcedit.dll

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
10/27/2015 10:31:45 AM

Valid to:
10/27/2018 10:31:45 AM

Subject:
CN=中国民生银行股份有限公司, OU=科技开发部, O=中国民生银行股份有限公司, L=北京市, S=北京市, C=CN

Issuer:
CN=GlobalSign CodeSigning CA - SHA256 - G2, O=GlobalSign nv-sa, C=BE

Serial number:
1121F0E438AA0DEF923A6D7593BF237A337B

File PE Metadata
Compilation timestamp:
3/25/2016 6:40:54 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
49152:0FRc+f2ItierbfkpRvrSXh7M4q9TnXR9YprcRmaaojeIQaF:Kc+f2KrbfkpRv2XhYvLXHY5cdaopF

Entry address:
0x43689B

Entry point:
68, C6, 96, BB, 6E, C6, 04, 24, 45, C7, 04, 24, F2, 1E, 88, 23, 60, C7, 44, 24, 1C, 2E, 45, 9E, 3D, 60, FF, 34, 24, 88, 74, 24, 0C, 68, F8, C5, A9, A6, 8D, 64, 24, 44, E9, DF, 54, 02, 00, 0F, B7, 72, 1A, 66, F7, D7, 9C, 0F, BE, FA, 8D, 74, 16, 1C, 8D, 3C, A5, 3B, 62, 75, 1A, 5F, 8B, 7D, 08, E9, B1, 94, FF, FF, 66, 0F, BB, E9, D0, ED, 89, C7, 29, E9, F7, D9, F6, D1, 9C, B9, 04, 01, 00, 00, 60, 66, 0F, A3, EB, 80, FC, B1, F5, 28, C0, 0F, BA, E4, 11, F8, F2, AE, C7, 44, 24, 10, 63, 53, 74, 06, FF, 34, 24, C6...
 
[+]

Entropy:
7.8967  (probably packed)

Code size:
541.5 KB (554,496 bytes)

The file npcmbcedit.dll has been seen being distributed by the following URL.

Scan npcmbcedit.dll - Powered by Reason Core Security