TrojanScan.DLL

AntiTrojan

中国民生银行股份有限公司

Publisher:
China minsheng banking corp,.ltd.  (signed by 中国民生银行股份有限公司)

Product:
AntiTrojan

Description:
Trojan Detect UI Module

Version:
2, 0, 0, 1

MD5:
7eacb5027fbc10e72c9ccbe9743792db

SHA-1:
288c44806170e2c70e204e0e1cd8b2745c1ce82c

SHA-256:
e384f6f05c6b047255c61d67652db1e21cdf871b9cbf9faaff6185f8979aabf4

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/15/2024 9:31:32 PM UTC  (today)

File size:
806.5 KB (825,880 bytes)

Product version:
2, 0, 0, 1

Copyright:
all right by CMBC (C) 2012

Original file name:
TrojanScan.DLL

File type:
Dynamic link library (Win32 DLL)

Common path:
C:\Program Files\cmbc\ebankingassistant\antitrojan\trojanscan.dll

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
10/27/2015 10:31:45 AM

Valid to:
10/27/2018 10:31:45 AM

Subject:
CN=中国民生银行股份有限公司, OU=科技开发部, O=中国民生银行股份有限公司, L=北京市, S=北京市, C=CN

Issuer:
CN=GlobalSign CodeSigning CA - SHA256 - G2, O=GlobalSign nv-sa, C=BE

Serial number:
1121F0E438AA0DEF923A6D7593BF237A337B

File PE Metadata
Compilation timestamp:
3/6/2013 12:09:07 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
24576:JRaE4/nZxqPHvd9qiFriG07SZJJqmTG7diA0sHgf:JRaEexqP1PFrin7Sx07dG

Entry address:
0x14BAE3

Entry point:
9C, E8, A7, 4E, F6, FF, E9, A8, 96, F5, FF, E9, E0, B9, BC, CC, 07, 54, 59, 95, DC, C5, BC, 65, 88, 19, CC, 28, 32, 2F, B6, 5F, 36, DF, 92, 73, 6E, 2F, 12, 13, FA, A3, 4E, 9B, DA, 8B, 1A, 2E, 6E, 22, 91, 06, ED, DD, 88, 89, 54, 01, D7, 96, 34, A2, 9A, 1D, E6, 5B, B2, 34, 57, 97, C1, BD, F9, 6C, 98, 3A, CC, FC, 9B, 0D, 21, 1D, CF, E7, C9, 59, 14, 04, FB, 99, 6E, 84, 0D, FC, EC, F5, A3, B1, 44, AF, 59, 98, 91, 41, 58, D3, A9, 88, 7F, 93, 68, C1, 2D, B6, 87, DA, 27, E5, A6, 2B, D9, A4, 8C, 5D, D4, 8D, 28, AD...
 
[+]

Entropy:
7.6722

Code size:
220 KB (225,280 bytes)

The file TrojanScan.DLL has been seen being distributed by the following URL.

http://assist.cmbc.com.cn/.../TrojanScan.dll

Scan TrojanScan.DLL - Powered by Reason Core Security