gmail.dll

The library gmail.dll has been detected as malware by 8 anti-virus scanners. The file has been seen being downloaded from www.m4udownloader.pl.
MD5:
a51834af649286a4c0d0fd3427967d1a

SHA-1:
278e68bb6f424d64d814331f8af6442f83ffcf7d

SHA-256:
b75cdaa7301a14e100dfb72b3e6ce66de793b5d02ff241a5232e2dea2dcacf47

Scanner detections:
8 / 68

Status:
Malware

Analysis date:
4/26/2024 9:45:43 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Trojan.GenericKD.1645258
347

Bitdefender
Trojan.GenericKD.1645258
1.0.20.270

Emsisoft Anti-Malware
Trojan.GenericKD.1645258
8.16.02.23.02

F-Secure
Trojan.GenericKD.1645258
11.2016-23-02_3

G Data
Trojan.GenericKD.1645258
16.2.24

McAfee
Artemis!A51834AF6492
5600.6481

MicroWorld eScan
Trojan.GenericKD.1645258
17.0.0.162

nProtect
Trojan.GenericKD.1645258
14.04.25.01

File size:
81.5 KB (83,456 bytes)

File type:
Dynamic link library (Win32 DLL)

Common path:
C:\users\{user}\appdata\local\microsoft\windows\temporary internet files\content.ie5\{random}\gmail.dll

File PE Metadata
Compilation timestamp:
4/3/2014 4:49:59 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows Console

Linker version:
2.23

CTPH (ssdeep):
1536:M8c/8LbW7IMqaFtnDIi3fOr2eUDWmcf9X8vTwJRQxN1H2LPdvDcA4cqWH:M8c/8LbW7IMq8dDIgEGjnMLcA3qWH

Entry address:
0x1440

Entry point:
83, EC, 1C, 8B, 54, 24, 24, C7, 05, 2C, 40, 51, 64, 00, 00, 00, 00, 83, FA, 01, 74, 1A, 8B, 4C, 24, 28, 8B, 44, 24, 20, E8, 0D, FE, FF, FF, 83, C4, 1C, C2, 0C, 00, 8D, B4, 26, 00, 00, 00, 00, 89, 54, 24, 0C, E8, 17, 92, 00, 00, 8B, 54, 24, 0C, EB, D7, 90, 55, 89, E5, 53, 83, EC, 14, 8B, 1D, 60, 63, 51, 64, C7, 04, 24, 00, 20, 51, 64, FF, D3, BA, D8, AD, 50, 64, 83, EC, 04, 85, C0, 74, 16, C7, 44, 24, 04, 13, 20, 51, 64, 89, 04, 24, FF, 15, 64, 63, 51, 64, 83, EC, 08, 89, C2, 85, D2, 74, 11, C7, 44, 24, 04...
 
[+]

Code size:
64 KB (65,536 bytes)

The file gmail.dll has been seen being distributed by the following URL.

Remove gmail.dll - Powered by Reason Core Security