zlib1.dll

MD5:
9c785572003539a193a76f3459bcde06

SHA-1:
a8c674acc12a1a90652b211abf440341322b6a8e

SHA-256:
7b212f0b27fb7270a2afb8f51e6d1404b4563afaed8149cebe0755b82f164a47

Scanner detections:
1 / 68

Status:
Clean  (1 probable false positive detection)

Explanation:
This is mosty likely a false positive detection, the file is probably clean.

Analysis date:
11/16/2024 5:25:57 AM UTC  (today)

Scan engine
Detection
Engine version

ESET NOD32
Win32/Packed.EnigmaProtector.J suspicious application
8.0.319.0

File size:
1 MB (1,086,976 bytes)

File type:
Dynamic link library (Win32 DLL)

Common path:
C:\users\{user}\appdata\local\microsoft\windows\temporary internet files\content.ie5\{random}\zlib1.dll

File PE Metadata
Compilation timestamp:
6/9/2016 7:59:52 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
24576:pVUKD1dlRErGs2jzlj0E24CqgVdREWjrgZJ7j4kUGX:HUOSry4ERMdNjoJ7j4EX

Entry address:
0x3CDE28

Entry point:
60, E8, 00, 00, 00, 00, 5D, 81, ED, 06, 00, 00, 00, 81, ED, 28, DE, 3C, 00, E9, 4C, 00, 00, 00, 45, 4E, 49, 47, 4D, 41, 04, 00, E0, 07, 06, 00, 09, 00, 01, 00, 00, 00, 3B, 00, 8A, 84, 4F, 5E, FA, 03, AE, 8E, 2E, 4B, 0A, 5D, EA, C5, F0, 7F, 4D, 6E, 28, E0, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 8A, 84, 24, 28, 00, 00, 00, 80, F8, 01, 0F, 84, 07, 00, 00, 00, 61, 33, C0, 40, C2, 0C, 00, E9, 04, 00, 00, 00...
 
[+]

Entropy:
7.9823

Packer / compiler:
ASPack v1.08.04

Code size:
278 KB (284,672 bytes)

The file zlib1.dll has been seen being distributed by the following URL.

Scan zlib1.dll - Powered by Reason Core Security