Sample: d52557cf6d61595000ac2ab2ae6b130f

Note: if you are new to ThreatMiner, check out the how-to page to find out how you can get the most out of this portal.

Metadata
File name:N/A
File type:PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed
File size:824232
Analysis date:N/A
MD5:d52557cf6d61595000ac2ab2ae6b130f
SHA1:264675cfb1fc5cfc3bcebcdfe844d608f36dc700
SHA256:779f1acb18e331a3f84e1362253f3575e67fa1a93d0ce01b8bb7f2d4790ab549
SHA512:N/A
SSDEEP:N/A
IMPHASH:N/A
Authentihash:N/A
Related resources
PE TypePE32
Internal NameAirInstaller.exe
File Size805 kB
Machine TypeIntel 386 or later, and compatibles
File OSWindows NT 32-bit
Code Size786432
OS Version5.1
Entry Point0x2514e0
File Flags Mask0x003f
Linker Version10.0
File SubtypeN/A
Uninitialized Data Size1642496
File Version2.0.4.14
Initialized Data Size36864
File DescriptionY! Chat Messenger
Product Version Number2.0.4.14
Product NameY! Chat Messenger
Company NameAirInstaller Inc.
MIME Typeapplication/octet-stream
Character SetUnicode
Language CodeEnglish (U.S.)
File Version Number2.0.4.14
File TypeWin32 EXE
Original FilenameAirInstaller.exe
Legal Copyright(c) AirInstaller. All rights reserved.
SubsystemWindows GUI
Object File TypeExecutable application
Image Version0.0
File Flags(none)
Subsystem Version5.1
Product Version2.0.4.14
Source:
APTNotes
Cyber threat intelligence reports associated with d52557cf6d61595000ac2ab2ae6b130f.
Loading...
Domains
Domains the malware sample communicates with.
Hosts
Hosts the malware sample communicates with.
HTTP Requests
HTTP requests the malware sample makes.
AV Detections
AV detection names associated with the malware sample.
Mutants
Mutants created by the malware sample.
Registry keys
Registry keys created by the malware sample.
Comments
User comments about d52557cf6d61595000ac2ab2ae6b130f.
NOTICE: We have updated our privacy terms and conditions in accordance to GDPR. By using our site, you acknowledge that you have read and understand our Privacy Policy. Your use of ThreatMiner’s Products and Services is subject to these policies and terms.