calcImp16.exe

Micsa

Arh

Publisher:
Arh

Product:
Micsa

Version:
1.00.0004

MD5:
d4a6bcfec8d2dacc4c942310a4170b3a

SHA-1:
b4720a7a6b2ebc78af6557a79e3cfb26b37bf7ff

SHA-256:
59de4b42201651df4576e400a9014817fb1a42766cfb5618881dd3bbe98c54d2

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
5/14/2024 11:39:13 AM UTC  (today)

File size:
128 KB (131,072 bytes)

Product version:
1.00.0004

Original file name:
calcImp16.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\microsoft\windows\temporary internet files\content.ie5\{random}\calcimp16.exe

File PE Metadata
Compilation timestamp:
1/3/2016 2:44:46 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
1536:isrmxVZoAZK81WHweiU5mx32or34rUR6nIFEUMYhIsW06:trmxVZoA91oX5mh2or34rUgIbdhKX

Entry address:
0x1564

Entry point:
68, 5C, C8, 40, 00, E8, EE, FF, FF, FF, 00, 00, 00, 00, 00, 00, 30, 00, 00, 00, 38, 00, 00, 00, 00, 00, 00, 00, 3B, 75, 7B, D6, D3, C4, 77, 43, A7, 98, B0, 73, 75, 1F, 31, 5B, 00, 00, 00, 00, 00, 00, 01, 00, 00, 00, 65, 73, 74, 6F, 5C, 43, 63, 61, 6C, 63, 49, 6D, 70, 00, 00, 00, 00, 00, FF, CC, 31, 00, 20, B7, E9, BA, B0, 0C, 5D, 36, 47, 8F, D5, 38, B3, 80, 79, 90, 74, F4, AF, FB, 43, 52, E4, E3, 4B, 8F, 0D, 99, D4, 9A, 64, B6, BC, 3A, 4F, AD, 33, 99, 66, CF, 11, B7, 0C, 00, AA, 00, 60, D3, 93, 00, 00, 00...
 
[+]

Entropy:
5.4759

Developed / compiled with:
Microsoft Visual Basic v5.0/v6.0

Code size:
112 KB (114,688 bytes)

The file calcImp16.exe has been seen being distributed by the following URL.

Scan calcImp16.exe - Powered by Reason Core Security