Resource.dll

Shanghai Dragon Habitat Network Information Technology Co., Ltd.

The module Resource.dll by Shanghai Dragon Habitat Network Information Technology Co. has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat.
Publisher:
www.guangsu.cn  (signed by Shanghai Dragon Habitat Network Information Technology Co., Ltd.)

Description:
输入法资源程序

Version:
2, 5, 0, 0

MD5:
6c1aaa303d3680a7596b4b433e673ea1

SHA-1:
a783aab16748a0bf148e279d171c7514df877dd5

SHA-256:
2ac0602adb1b248d73bd05c9e8af4719187319582196a009260fe3f7176abc08

Scanner detections:
1 / 68

Status:
Potentially unwanted

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
4/23/2024 6:16:15 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP (M)
16.11.17.12

File size:
107.2 KB (109,768 bytes)

Product version:
2, 5, 0, 0

Copyright:
Copyright (C) 2012

Original file name:
Resource.dll

File type:
Dynamic link library (Win32 DLL)

Language:
Chinese (Simplified, China)

Common path:
C:\Program Files\gssoft\gswb\resource.dll

Digital Signature
Authority:
WoSign eCommerce Services Limited

Valid from:
8/28/2012 2:03:24 AM

Valid to:
8/30/2013 7:41:29 AM

Subject:
E=shxiaohei@vip.qq.com, CN="Shanghai Dragon Habitat Network Information Technology Co., Ltd.", O="Shanghai Dragon Habitat Network Information Technology Co., Ltd.", L=Shanghai, S=Shanghai, C=CN

Issuer:
CN=WoSign Class 3 Code Signing CA, O=WoSign eCommerce Services Limited, C=CN

Serial number:
060E3CD0F5C7EE

File PE Metadata
Compilation timestamp:
3/25/2013 11:19:18 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

CTPH (ssdeep):
1536:bYQFBljx/oAIS2I0ODAKC6PXMJ5PnJeeeeeeeIeeeeeeEeveueeeeeXeeeeee+e0:8IZ/vzmtJ5PY49wepk

Entry address:
0x1319

Entry point:
83, 7C, 24, 08, 01, 75, 05, E8, 9F, 03, 00, 00, FF, 74, 24, 04, 8B, 4C, 24, 10, 8B, 54, 24, 0C, E8, CD, FE, FF, FF, 59, C2, 0C, 00, 55, 8B, EC, 81, EC, 28, 03, 00, 00, A3, 20, 31, 00, 10, 89, 0D, 1C, 31, 00, 10, 89, 15, 18, 31, 00, 10, 89, 1D, 14, 31, 00, 10, 89, 35, 10, 31, 00, 10, 89, 3D, 0C, 31, 00, 10, 66, 8C, 15, 38, 31, 00, 10, 66, 8C, 0D, 2C, 31, 00, 10, 66, 8C, 1D, 08, 31, 00, 10, 66, 8C, 05, 04, 31, 00, 10, 66, 8C, 25, 00, 31, 00, 10, 66, 8C, 2D, FC, 30, 00, 10, 9C, 8F, 05, 30, 31, 00, 10, 8B, 45...
 
[+]

Entropy:
5.8439

Code size:
4 KB (4,096 bytes)

Remove Resource.dll - Powered by Reason Core Security