phishface.dll

中国民生银行股份有限公司

Publisher:
中国民生银行股份有限公司  (signed and verified)

MD5:
1f17cba4fc8f4756ce9db7e1f6125d66

SHA-1:
abe737c207fe298be65c01a6951cae4c0b5b5538

SHA-256:
bc2671645d70bf4ff19c782a7c28a09d00f2ef499423bcfff950847d0777d98c

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/15/2024 9:31:54 PM UTC  (today)

File size:
1.7 MB (1,808,920 bytes)

File type:
Dynamic link library (Win32 DLL)

Common path:
C:\Program Files\cmbc\ebankingassistant\antiphish\phishface.dll

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
10/27/2015 10:31:45 AM

Valid to:
10/27/2018 10:31:45 AM

Subject:
CN=中国民生银行股份有限公司, OU=科技开发部, O=中国民生银行股份有限公司, L=北京市, S=北京市, C=CN

Issuer:
CN=GlobalSign CodeSigning CA - SHA256 - G2, O=GlobalSign nv-sa, C=BE

Serial number:
1121F0E438AA0DEF923A6D7593BF237A337B

File PE Metadata
Compilation timestamp:
12/10/2012 9:50:42 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
49152:dzd6nijvnp1EsfUqV2bdi1uRU3Zql0szZlTOG8AIm+nHbjt:dzhn/+i5ZqlZZlT5Im+F

Entry address:
0x55A18

Entry point:
60, FF, 74, 24, 04, C7, 44, 24, 20, F8, CF, 9F, 52, 60, E9, 93, 98, 00, 00, ED, 92, C9, E2, C3, 54, DC, BE, FD, FB, 19, 5B, 5A, 81, 33, 81, 6F, CF, CF, 83, BF, 9B, D3, 9E, 1F, ED, 4D, AC, 15, 8B, CD, C0, 1E, 61, 7A, A1, 9A, ED, 56, 55, 6E, B1, BA, E9, F2, E9, D5, BE, AF, AE, A7, B1, 00, FE, F4, 19, 80, E0, 16, 9E, 69, F6, 54, 9C, CF, C8, 58, B9, 8A, 7D, B9, 7E, B2, 22, 2C, C0, 6E, A1, 9A, 67, E8, EE, 36, B6, 6A, 26, 6B, 42, D7, 33, FC, CB, 11, 40, A7, 8F, D1, 9A, F6, 92, 9C, 36, 75, BC, 31, 95, 33, 32, B2...
 
[+]

Entropy:
7.8319  (probably packed)

Code size:
68 KB (69,632 bytes)

The file phishface.dll has been seen being distributed by the following URL.

http://assist.cmbc.com.cn/.../PhishFace.dll

Scan phishface.dll - Powered by Reason Core Security