aec4492fe457b02327504f7c0e8f42ca

Cygwin

Shenzhen Weiaipu Information Technology Co., Ltd.

Publisher:
Red Hat  (signed by Shenzhen Weiaipu Information Technology Co., Ltd.)

Product:
Cygwin

Description:
Cygwin® POSIX Emulation DLL

Version:
1.5.25-cr-0x5f1

MD5:
aec4492fe457b02327504f7c0e8f42ca

SHA-1:
a037322e3a34fe401f03244064b9e80f85b85cca

SHA-256:
2b50a17a2d4e384ccee0ab93f1f5b8ea202c3f44d851d7dd0f2c26e50f72023a

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
5/17/2024 12:31:09 AM UTC  (today)

File size:
1.8 MB (1,878,672 bytes)

Product version:
1.5.25-cr-0x5f1

Copyright:
Copyright © Red Hat, Inc. 1996-2003

Original file name:
cygwin1.dll

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\microsoft\windows\temporary internet files\content.ie5\{random}\aec4492fe457b02327504f7c0e8f42ca

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
10/27/2015 8:40:00 AM

Valid to:
10/27/2016 9:40:00 AM

Subject:
CN="Shenzhen Weiaipu Information Technology Co., Ltd.", O="Shenzhen Weiaipu Information Technology Co., Ltd.", L=Shenzhen, S=Guangdong, C=CN

Issuer:
CN=GlobalSign CodeSigning CA - SHA256 - G2, O=GlobalSign nv-sa, C=BE

Serial number:
1121BF567E7ECFBF9C01390F0CC8231DDC82

File PE Metadata
Compilation timestamp:
12/14/2007 7:22:04 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows Console

Linker version:
2.56

CTPH (ssdeep):
49152:1ymMEcoM/S8UkHbcBiOozMqGmYPvFY1TVDhywfiMrJT:1ymgH/Sxqbc5mYPG1TVDhR6OT

Entry address:
0x54590

Entry point:
55, 89, E5, 81, EC, E8, 00, 00, 00, 89, 5D, F4, 8B, 45, 0C, 89, 75, F8, 89, 7D, FC, 83, F8, 02, 0F, 84, 89, 00, 00, 00, 76, 24, 83, F8, 03, 0F, 84, EB, 00, 00, 00, 8D, B4, 26, 00, 00, 00, 00, 8B, 5D, F4, B8, 01, 00, 00, 00, 8B, 75, F8, 8B, 7D, FC, 89, EC, 5D, C2, 0C, 00, 48, 75, E9, C7, 04, 24, 24, 50, 16, 61, E8, 5D, DB, 06, 00, C7, 04, 24, 00, 00, 00, 00, E8, B1, 1B, FC, FF, 8B, 45, 08, A3, 3C, 85, 10, 61, 31, C0, 83, 7D, 10, 00, 0F, 94, C0, 80, 3D, E8, 50, 16, 61, 00, A3, 40, 85, 10, 61, 74, 18, 8D, 85...
 
[+]

Code size:
1024 KB (1,048,576 bytes)

The file aec4492fe457b02327504f7c0e8f42ca has been seen being distributed by the following 5 URLs.

http://220.243.228.91/d.updater.3u.com/3utools/3utools/update_files/files/.../AEC4492FE457B02327504F7C0E8F42CA.dll?wsiphost=local

http://180.180.248.169/d.updater.3u.com/3utools/3utools/update_files/files/.../AEC4492FE457B02327504F7C0E8F42CA.dll

http://58.26.7.182/d.updater.3u.com/3utools/3utools/update_files/files/.../AEC4492FE457B02327504F7C0E8F42CA.dll

http://180.180.248.169/d.updater.3u.com/3utools/3utools/update_files/files/.../AEC4492FE457B02327504F7C0E8F42CA.dll?wsiphost=ipdb

Scan aec4492fe457b02327504f7c0e8f42ca - Powered by Reason Core Security