bzip2.dll

Bzip2

Shenzhen Weiaipu Information Technology Co., Ltd.

Publisher:
GnuWin32 <http://gnuwin32.sourceforge.net>  (signed by Shenzhen Weiaipu Information Technology Co., Ltd.)

Product:
Bzip2

Description:
Bzip: file compressor

Version:
1.0.5.3001

MD5:
f719c210c19546da630e41ba6a9d215f

SHA-1:
6c20a23726d64528452d7c69d3a36734db7c52df

SHA-256:
ed9a9456eda9b7ea53564e5f0367bcb47eb973ff08205d1e5ca4074731d87b19

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
5/17/2024 2:02:09 PM UTC  (today)

File size:
73.4 KB (75,120 bytes)

Product version:
1.0.5.3001

Copyright:
© 2008 Julian Seward <jseward@acm.org>

Trademarks:
GnuWin32®, Bzip2®, bzip2®

Original file name:
bzip2.dll

File type:
Dynamic link library (Win32 DLL)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\files\patchtools\bzip2.dll

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
10/27/2015 8:40:00 AM

Valid to:
10/27/2016 9:40:00 AM

Subject:
CN="Shenzhen Weiaipu Information Technology Co., Ltd.", O="Shenzhen Weiaipu Information Technology Co., Ltd.", L=Shenzhen, S=Guangdong, C=CN

Issuer:
CN=GlobalSign CodeSigning CA - SHA256 - G2, O=GlobalSign nv-sa, C=BE

Serial number:
1121BF567E7ECFBF9C01390F0CC8231DDC82

File PE Metadata
Compilation timestamp:
3/20/2008 8:12:08 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows Console

Linker version:
2.56

CTPH (ssdeep):
1536:89FWW0igMY08p/41AdhEfWoh8eGf9NvvvvvvvvvvvvvvvvJQfBqJNN:89FxMJj3EWne290iNN

Entry address:
0x1060

Entry point:
55, 89, E5, 56, 53, 83, EC, 10, 8B, 75, 0C, 83, FE, 01, 74, 47, 89, 74, 24, 04, 8B, 45, 10, 89, 44, 24, 08, 8B, 45, 08, 89, 04, 24, E8, 6A, BB, 00, 00, 89, C3, 83, EC, 0C, 83, FE, 01, 0F, 94, C2, 31, C0, 85, DB, 0F, 94, C0, 85, C2, 75, 47, 85, F6, 75, 0C, 8B, 0D, 00, 00, 45, 68, 85, C9, 75, 46, 31, DB, 89, D8, 8D, 65, F8, 5B, 5E, 5D, C2, 0C, 00, C7, 04, 24, 80, 00, 00, 00, E8, 8D, BF, 00, 00, A3, 00, 00, 45, 68, 85, C0, 74, 2B, C7, 00, 00, 00, 00, 00, A3, 10, 00, 45, 68, E8, D4, BB, 00, 00, E8, AF, BB, 00...
 
[+]

Code size:
48.5 KB (49,664 bytes)

The file bzip2.dll has been seen being distributed by the following 5 URLs.

http://220.243.228.89/d.updater.3u.com/3utools/3utools/update_files/files/.../F719C210C19546DA630E41BA6A9D215F.dll?wsiphost=local

http://180.180.248.170/d.updater.3u.com/3utools/3utools/update_files/files/.../F719C210C19546DA630E41BA6A9D215F.dll

http://58.26.7.199/d.updater.3u.com/3utools/3utools/update_files/files/.../F719C210C19546DA630E41BA6A9D215F.dll

http://180.180.248.170/d.updater.3u.com/3utools/3utools/update_files/files/.../F719C210C19546DA630E41BA6A9D215F.dll?wsiphost=ipdb

Scan bzip2.dll - Powered by Reason Core Security