crunchdll64.dll

Crunchdeal Assistant

CraftCapital

The module crunchdll64.dll, “Crunchdeal Assistant Main” by CraftCapital has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat.
Publisher:
Crunchdeal Ltd  (signed by CraftCapital)

Product:
Crunchdeal Assistant

Description:
Crunchdeal Assistant Main

Version:
0.0.2.6

MD5:
2ac33b577e5a234f4ddedf5a922121fe

SHA-1:
4d8cf93bbbf54f875d1c5ebb1900defeefee0992

SHA-256:
55e535585cf203d2c7f876bee7096507a2a37a8d1fdb74627b2fe8f60cba1322

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
4/25/2024 10:44:58 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.CrunchDeal (M)
16.3.9.23

File size:
667.5 KB (683,544 bytes)

Product version:
0.0.2.6

Copyright:
Copyright (C) 2011

Original file name:
crunchdl.dll

File type:
Dynamic link library (Win64 DLL)

Language:
English (United States)

Common path:
C:\Program Files\crunchdeal\0.0.2.6\crunchdll64.dll

Digital Signature
Signed by:

Authority:
Thawte, Inc.

Valid from:
5/4/2011 2:00:00 AM

Valid to:
5/4/2012 1:59:59 AM

Subject:
CN=CraftCapital, O=CraftCapital, L=Petah Tikva, S=Em HaMoshavot, C=IL

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
3C3F50E9305C22C94B2CECB9144891DC

Registration
CLSID:
{01FEFC77-1031-43C6-BA9A-FEC28E75607C}

ProgID:
Crunchdeal.Crunchie.1

COM registered:
Yes

File PE Metadata
Compilation timestamp:
11/14/2011 9:48:53 AM

OS version:
5.2

OS bitness:
Win64

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
12288:PaDxTBt/RKD4TALYRNChZw9TF1CzhMFoC:PIBtW1LYfIK9TF1rFJ

Entry address:
0x53F1C

Entry point:
48, 89, 5C, 24, 08, 48, 89, 74, 24, 10, 57, 48, 83, EC, 20, 49, 8B, F8, 8B, DA, 48, 8B, F1, 83, FA, 01, 75, 05, E8, AF, BE, 00, 00, 4C, 8B, C7, 8B, D3, 48, 8B, CE, 48, 8B, 5C, 24, 30, 48, 8B, 74, 24, 38, 48, 83, C4, 20, 5F, E9, A7, FE, FF, FF, CC, CC, CC, 48, 89, 7C, 24, 10, 4C, 89, 64, 24, 20, 55, 48, 8B, EC, 48, 83, EC, 70, 48, 63, F9, 48, 8D, 4D, E0, E8, 3A, D3, FF, FF, 81, FF, 00, 01, 00, 00, 73, 5D, 48, 8B, 55, E0, 83, BA, 0C, 01, 00, 00, 01, 7E, 16, 4C, 8D, 45, E0, BA, 01, 00, 00, 00, 8B, CF, E8, 01...
 
[+]

Code size:
440.5 KB (451,072 bytes)

Remove crunchdll64.dll - Powered by Reason Core Security