Dropped Files | ZeroBOX
Name fec5a295a6f3289f_Readme.txt
Submit file
Filepath C:\Users\test22\AppData\Roaming\Dart Communications\Power iCalconfigurator 15.3.6.2\install\E817FBF\Readme.txt
Size 1.3KB
Processes 2420 (Porcal4.exe)
Type ISO-8859 text, with CRLF line terminators
MD5 1b715b15bd03b3c4f39273c051951a4b
SHA1 925f3b7dc176f7db479b99114df6dfd0e1053cca
SHA256 fec5a295a6f3289f1504c94d71a7e06777f36e35605059d15a425a9ae6d253c8
CRC32 2367A0CD
ssdeep 24:vo3eW4ZjxEjAXjVFNFvSo50cyC91bY08oNAtg/OnOCqLUdx2Rxr:AOzxEkX5RR6ZCX5NAG/OnOCsAx2b
Yara None matched
VirusTotal Search for analysis
Name 9f9788710e536528_d14a.ico
Submit file
Filepath C:\Users\test22\AppData\Roaming\Dart Communications\Power iCalconfigurator 15.3.6.2\install\E817FBF\icons\Classic\d14a.ico
Size 1.4KB
Processes 2420 (Porcal4.exe)
Type MS Windows icon resource - 1 icon, 16x16, 255 colors, 8 bits/pixel
MD5 86b8bded4b47b9db2a586e77252ef04f
SHA1 110fb25b59a1bc351b5a87604bf9aca90c26d307
SHA256 9f9788710e536528ee558ffceb078c5b10a2ef32f2f7e1a8443fd74c5cead637
CRC32 B76F0775
ssdeep 6:dzMAEfElBlxgmXxoVnV7RfnnRfnRRyCJBhYEvOuf/tnn:dziclFXxoVVlJrvhYEvOqn
Yara None matched
VirusTotal Search for analysis
Name 1fd04afc153375f3_MenuIcon@225.png
Submit file
Filepath C:\Users\test22\AppData\Roaming\Dart Communications\Power iCalconfigurator 15.3.6.2\install\E817FBF\Images\MenuIcon@225.png
Size 2.8KB
Processes 2420 (Porcal4.exe)
Type PNG image data, 24 x 19, 8-bit/color RGBA, non-interlaced
MD5 dc16d3ee89986eb5651878d13b308293
SHA1 364355caee0ca0c4718cba6c77b806069f8df088
SHA256 1fd04afc153375f3269df9ee27a23faf18c2b0bbac1eaf9fe444ff1882ab5e65
CRC32 F9F27276
ssdeep 48:O/6DocieftI9G9f6A+FIDOWu0lDl+gm7QyTtctIInQSy6IVpqlnBcODfpB:OSDZ/I09Da01l+gmkyTt6Hk8nTfP
Yara
  • PNG_Format_Zero - PNG Format
VirusTotal Search for analysis
Name e0a4cbb12f89889f_api-ms-win-core-libraryloader-l1-1-0.dll
Submit file
Filepath C:\Users\test22\AppData\Roaming\Dart Communications\Power iCalconfigurator 15.3.6.2\install\E817FBF\api-ms-win-core-libraryloader-l1-1-0.dll
Size 10.3KB
Processes 2420 (Porcal4.exe)
Type PE32 executable (DLL) (console) Intel 80386, for MS Windows
MD5 ca4da696d643460a39ed95e89d1f88e5
SHA1 169fd3db84149b6ecd69ae91be6753dd1314071f
SHA256 e0a4cbb12f89889fb9c5936f8bb3859e84f750f704fbbbdee2daee21e7dc6a30
CRC32 547E0312
ssdeep 192:zvuBL3B5LgWthWX068Ya5/R6t7YUN5BZHoM:zvuBL3BCWthWXaPVRKU2hB
Yara
  • PE_Header_Zero - PE File Signature
  • IsPE32 - (no description)
  • IsDLL - (no description)
  • Malicious_Library_Zero - Malicious_Library
  • UPX_Zero - UPX packed file
VirusTotal Search for analysis
Name becf1353dad02328_d20.ico
Submit file
Filepath C:\Users\test22\AppData\Roaming\Dart Communications\Power iCalconfigurator 15.3.6.2\install\E817FBF\icons\Classic\d20.ico
Size 1.4KB
Processes 2420 (Porcal4.exe)
Type MS Windows icon resource - 1 icon, 16x16, 8 bits/pixel
MD5 fa4138896301fad97a55a11b633f7e3e
SHA1 44b001ccf6217fd7e3f0c7ab1804679e6824c71d
SHA256 becf1353dad02328456ce9ec5f6e46d3314d4c0451a58323f2418c1e4106b77c
CRC32 266501B1
ssdeep 6:UZxMcE2jS4Tfl+46EcAOBNHlfmXp+ktAET9UhjNCll8vn40mM/tH5n:UZtu4TQ46DAOLHl+XBtAXsllI/tZn
Yara None matched
VirusTotal Search for analysis
Name 7482d6d528532f8a_ConfigIcon@150.png
Submit file
Filepath C:\Users\test22\AppData\Roaming\Dart Communications\Power iCalconfigurator 15.3.6.2\install\E817FBF\Images\ConfigIcon@150.png
Size 845.0B
Processes 2420 (Porcal4.exe)
Type PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
MD5 5f07cf4b314e6e85bfb821b5ce85b5a7
SHA1 9cb06700e8503949b145f20e6a3dbfda727b70eb
SHA256 7482d6d528532f8afa81c83c01237b63a90caa029c649a47356438c6869ca8ff
CRC32 68A705AD
ssdeep 24:I16ZZ2lutMWDa7gzYfFJI3VeB21FkX72IX:kSlCW2XfFJIQ012XDX
Yara
  • PNG_Format_Zero - PNG Format
VirusTotal Search for analysis
Name be171574e76bad0a_farsi.dxs
Submit file
Filepath C:\Users\test22\AppData\Roaming\Dart Communications\Power iCalconfigurator 15.3.6.2\install\E817FBF\sprache\farsi.dxs
Size 46.1KB
Processes 2420 (Porcal4.exe)
Type Non-ISO extended-ASCII text, with very long lines, with CRLF line terminators
MD5 48008e732f3c367d2888aaf3b75975c3
SHA1 bda0d0b097c509d38021e7caaf8301bd9c5d2272
SHA256 be171574e76bad0a7da93948d46352ea0d9addfb30d5ffbe2ee3a8e137e42d49
CRC32 F5B57305
ssdeep 768:UN4Srjk5H8cKySOKMdPcc/jJDBLx60l2gxFEkeLcwcEzUjLy6fmw1qsvpzXIcS9G:o4Sfk5H8cKySOKMdPcc/NNLx60l2wFEk
Yara None matched
VirusTotal Search for analysis
Name 26d071fbcb696458_FencesSmall@125.png
Submit file
Filepath C:\Users\test22\AppData\Roaming\Dart Communications\Power iCalconfigurator 15.3.6.2\install\E817FBF\Images\FencesSmall@125.png
Size 4.0KB
Processes 2420 (Porcal4.exe)
Type PNG image data, 20 x 20, 8-bit/color RGBA, non-interlaced
MD5 5791c89f96f9531c2f796153161d16fa
SHA1 c0ec7c1aeaa44c95b3cc57f6e4357b658f45ffea
SHA256 26d071fbcb696458425724caeb7c24499e597c126d0227ad4db9dca3821ce84b
CRC32 B47A3220
ssdeep 96:nZ/I09Da01l+gmkyTt6Hk8nT/GXkm6PU2JUnP:nS0tKg9E05TPJGP
Yara
  • PNG_Format_Zero - PNG Format
VirusTotal Search for analysis
Name 459bc2b73e7dd3e6_vccorlib140.dll
Submit file
Filepath C:\Users\test22\AppData\Roaming\Dart Communications\Power iCalconfigurator 15.3.6.2\install\E817FBF\vccorlib140.dll
Size 259.3KB
Processes 2420 (Porcal4.exe)
Type PE32 executable (DLL) (console) Intel 80386, for MS Windows
MD5 cdf8cb16898df89512373e09810887f3
SHA1 9369a3cd29814c6a4bab6c76b228f207e9881140
SHA256 459bc2b73e7dd3e614092599d645273aafa8c9d130305a9bcc81d55199198fba
CRC32 A12386CF
ssdeep 3072:f9WZPGRvxHdmJOHpxyBIBaQ0I/Iuljl1mg48MHB7wgSmiSgdC:fegTmJO/BH0IwuljKb8VgSzC
Yara
  • PE_Header_Zero - PE File Signature
  • OS_Processor_Check_Zero - OS Processor Check
  • IsPE32 - (no description)
  • Win32_Trojan_Gen_2_0904B0_Zero - Win32 Trojan Gen
  • IsDLL - (no description)
  • UPX_Zero - UPX packed file
  • Win32_Trojan_Gen_1_0904B0_Zero - Win32 Trojan Emotet
VirusTotal Search for analysis
Name 0e8a21fc121fc5a0_d19.ico
Submit file
Filepath C:\Users\test22\AppData\Roaming\Dart Communications\Power iCalconfigurator 15.3.6.2\install\E817FBF\icons\New Blue\d19.ico
Size 894.0B
Processes 2420 (Porcal4.exe)
Type MS Windows icon resource - 1 icon, 16x16, 24 bits/pixel
MD5 b425fface81bd8e97f7b89498728313d
SHA1 4c35c6d79932d3543d4d18896f1dd86b0f580357
SHA256 0e8a21fc121fc5a0976b55b4e30ddaac3f6dba39e43bfbeca36512eabe9497b8
CRC32 3AD6C516
ssdeep 24:t5II0B+Xgv7W1MRCSIZ6MYTTTTTTTTTTTT2:9skgTHRCSIZvYTTTTTTTTTTTT2
Yara None matched
VirusTotal Search for analysis
Name fbcfd285f0fa868f_CreateFence@125.png
Submit file
Filepath C:\Users\test22\AppData\Roaming\Dart Communications\Power iCalconfigurator 15.3.6.2\install\E817FBF\Images\CreateFence@125.png
Size 2.9KB
Processes 2420 (Porcal4.exe)
Type PNG image data, 20 x 19, 8-bit/color RGBA, non-interlaced
MD5 cd65d392e4f6b26f9e74df077fdf6ac1
SHA1 7f6be789bdeff09dcb51621030dfc142f3bc0c72
SHA256 fbcfd285f0fa868f27b7d661e724dbe4db8176b15c357ca2d09107810763711c
CRC32 2096DEC8
ssdeep 48:ls/6DocieftI9G9f6A+FIDOWu0lDl+gm7QyTtctIInQSy6IVpqlnBcODv6Q5RlO:lsSDZ/I09Da01l+gmkyTt6Hk8nTit
Yara
  • PNG_Format_Zero - PNG Format
VirusTotal Search for analysis
Name eeb0430c1807eed6_api-ms-win-crt-time-l1-1-0.dll
Submit file
Filepath C:\Users\test22\AppData\Roaming\Dart Communications\Power iCalconfigurator 15.3.6.2\install\E817FBF\api-ms-win-crt-time-l1-1-0.dll
Size 11.8KB
Processes 2420 (Porcal4.exe)
Type PE32 executable (DLL) (console) Intel 80386, for MS Windows
MD5 d63250c999cd31894ed418e970300923
SHA1 6717a785d37da7b00ddbcaa715c7d6e81feec77f
SHA256 eeb0430c1807eed6e03e8f826dad8eb1a4356a52aa0991ecfa9d5944ba4c3327
CRC32 C6D9DF25
ssdeep 96:kDyx+IetcDsioxGHDCmDjEWthWwOi0EuL638yZfaQCiUkm6ybK7YZucG+3JUfhd4:4y5NDCWthWM068Ya5/R6t7YTGGBZHsyj
Yara
  • PE_Header_Zero - PE File Signature
  • IsPE32 - (no description)
  • IsDLL - (no description)
  • UPX_Zero - UPX packed file
VirusTotal Search for analysis
Name 60218ff121d6c5ab_BottomRight.fencelayout
Submit file
Filepath C:\Users\test22\AppData\Roaming\Dart Communications\Power iCalconfigurator 15.3.6.2\install\E817FBF\Layouts\BottomRight.fencelayout
Size 1.4KB
Processes 2420 (Porcal4.exe)
Type XML 1.0 document, ASCII text, with CRLF line terminators
MD5 17ad5f28a6dc184c4600595496f1c827
SHA1 3b61a77a81a17637de87fee0f91cbfce2cfdb76f
SHA256 60218ff121d6c5ab7325b82e8a15717e95cfe7de4d6fd84a99e4f4e4bbfa4207
CRC32 CA1B42DC
ssdeep 24:2dX89ENNrNq1fhvrVSYDLVSYVUOxzJtqL/hv+VSYDLVSYjf5WSqLPvM:cX89a/IIY3IYDIY3IYLr
Yara None matched
VirusTotal Search for analysis
Name 67efbfcd2d990d15_NavigateUpIcon@325.png
Submit file
Filepath C:\Users\test22\AppData\Roaming\Dart Communications\Power iCalconfigurator 15.3.6.2\install\E817FBF\Images\NavigateUpIcon@325.png
Size 2.9KB
Processes 2420 (Porcal4.exe)
Type PNG image data, 35 x 41, 8-bit/color RGBA, non-interlaced
MD5 1e6de09828f77ff6065f4eb0460daa1c
SHA1 42949cec07015d510a25460b63f20a887fe0622b
SHA256 67efbfcd2d990d15f9bc73a0f2ff344432352c7af36745648e8ddec96671a277
CRC32 1A805554
ssdeep 48:J1/6DocieftI9G9f6A+FIDOWu0lDl+gm7QyTtctIInQSy6IVpqlnBcOD/Cu6c3C4:jSDZ/I09Da01l+gmkyTt6Hk8nT/bnCdm
Yara
  • PNG_Format_Zero - PNG Format
VirusTotal Search for analysis
Name e1d19e226c944b41_d1a.ico
Submit file
Filepath C:\Users\test22\AppData\Roaming\Dart Communications\Power iCalconfigurator 15.3.6.2\install\E817FBF\icons\New Blue\d1a.ico
Size 894.0B
Processes 2420 (Porcal4.exe)
Type MS Windows icon resource - 1 icon, 16x16, 24 bits/pixel
MD5 d8d070dd0411014e83a98eef2115612f
SHA1 a947f6222eae01b01560269916238a12a84e9ee3
SHA256 e1d19e226c944b4137bd1f53db59aac286f6aee1c9cbc9d01bdd38b3e6dca89d
CRC32 A71850B5
ssdeep 12:t47v4IcagO1mevCCIxONgLkb148agv7zCcGU2ORg0M:tSzMKfpNgLOaY72cGU2OG
Yara None matched
VirusTotal Search for analysis
Name 4b4c37b2b038023b_CreateFolderFence@100.png
Submit file
Filepath C:\Users\test22\AppData\Roaming\Dart Communications\Power iCalconfigurator 15.3.6.2\install\E817FBF\Images\CreateFolderFence@100.png
Size 2.9KB
Processes 2420 (Porcal4.exe)
Type PNG image data, 16 x 15, 8-bit/color RGBA, non-interlaced
MD5 b5bfc099ae356fc96059c19e3bc190a8
SHA1 a29a630a3ef97add564f217b0f3d9cebce3edbe0
SHA256 4b4c37b2b038023bdebf961dec9f20a1f99ea67e591b74ed595d528873daa665
CRC32 7EFF0676
ssdeep 48:6/6DocieftI9G9f6A+FIDOWu0lDl+gm7QyTtctIInQSy6IVpqlnBcODQ256/:6SDZ/I09Da01l+gmkyTt6Hk8nTQ24/
Yara
  • PNG_Format_Zero - PNG Format
VirusTotal Search for analysis
Name bf66b48394a8fbc2_NavigateUpIcon@125.png
Submit file
Filepath C:\Users\test22\AppData\Roaming\Dart Communications\Power iCalconfigurator 15.3.6.2\install\E817FBF\Images\NavigateUpIcon@125.png
Size 2.8KB
Processes 2420 (Porcal4.exe)
Type PNG image data, 15 x 17, 8-bit/color RGBA, non-interlaced
MD5 b76a0002e6f94df06c4abbecef2ec6a3
SHA1 9fb709f71fe631fad300b38641038bff931847b1
SHA256 bf66b48394a8fbc2f5cd1c937a7f4691af921607ef92fd69a702686e6774b78c
CRC32 2F139310
ssdeep 48:s/6DocieftI9G9f6A+FIDOWu0lDl+gm7QyTtctIInQSy6IVpqlnBcODqHrw:sSDZ/I09Da01l+gmkyTt6Hk8nT+w
Yara
  • PNG_Format_Zero - PNG Format
VirusTotal Search for analysis
Name 08d2834bdc5adadc_d18.ico
Submit file
Filepath C:\Users\test22\AppData\Roaming\Dart Communications\Power iCalconfigurator 15.3.6.2\install\E817FBF\icons\Classic\d18.ico
Size 1.4KB
Processes 2420 (Porcal4.exe)
Type MS Windows icon resource - 1 icon, 16x16, 8 bits/pixel
MD5 275722dbb3624153ed1f0790728374db
SHA1 e4f2f754756413e63489c3863ddfc07019b165b3
SHA256 08d2834bdc5adadcff3e50de961728819464597f68832e6f10a4771558cea8f8
CRC32 02DCE897
ssdeep 6:UZxMcE2jS4Tfl+46EcAOBNHlfmXpQuuEjNuEzLpBr4w45l/cW0mM/tH5n:UZtu4TQ46DAOLHl+XWuFPtBC7/cV/tZn
Yara None matched
VirusTotal Search for analysis
Name 842c65e150db5d7c_icuin51.dll
Submit file
Filepath C:\Users\test22\AppData\Roaming\Dart Communications\Power iCalconfigurator 15.3.6.2\install\E817FBF\icuin51.dll
Size 4.8MB
Processes 2420 (Porcal4.exe)
Type PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
MD5 9d35e463b18ad70cffba04a35e85850c
SHA1 e4d8bc838410a813f83cfcad12f8b1d38f405e36
SHA256 842c65e150db5d7c26bc8d569a8fff27dca86282d13a9512502e423bf9434d4d
CRC32 0C7C49AB
ssdeep 98304:fdmU0qU6I3BSkqZkXXwlpVEHwNOehdADjKY6N0FlrnSYUG5mKa:wUu6I3ARkXHwNOehdADjZ6NmlnUG
Yara
  • ASPack_Zero - ASPack packed file
  • Malicious_Packer_Zero - Malicious Packer
  • PE_Header_Zero - PE File Signature
  • OS_Processor_Check_Zero - OS Processor Check
  • IsPE32 - (no description)
  • Win32_Trojan_Gen_2_0904B0_Zero - Win32 Trojan Gen
  • IsDLL - (no description)
  • Malicious_Library_Zero - Malicious_Library
  • UPX_Zero - UPX packed file
  • Win32_Trojan_Gen_1_0904B0_Zero - Win32 Trojan Emotet
VirusTotal Search for analysis
Name 841abc4ef3c4525c_api-ms-win-crt-heap-l1-1-0.dll
Submit file
Filepath C:\Users\test22\AppData\Roaming\Dart Communications\Power iCalconfigurator 15.3.6.2\install\E817FBF\api-ms-win-crt-heap-l1-1-0.dll
Size 10.3KB
Processes 2420 (Porcal4.exe)
Type PE32 executable (DLL) (console) Intel 80386, for MS Windows
MD5 b71a08a274d47357ecca41d7e1688373
SHA1 a81bfe436a7f58eab3e35b574b0d517addbf8a12
SHA256 841abc4ef3c4525c6d0c778117437e9da1d140470352a0c213a1a7f4a55c57a4
CRC32 C78B0F97
ssdeep 192:faY17aFBRQWthWv068Ya5/R6t7YJp5yJBZH3VRxm:PtWthWvaPVRKUJwhL4
Yara
  • PE_Header_Zero - PE File Signature
  • IsPE32 - (no description)
  • IsDLL - (no description)
  • UPX_Zero - UPX packed file
VirusTotal Search for analysis
Name 2edca55ae458caf0_CreateFolderFence@150.png
Submit file
Filepath C:\Users\test22\AppData\Roaming\Dart Communications\Power iCalconfigurator 15.3.6.2\install\E817FBF\Images\CreateFolderFence@150.png
Size 2.9KB
Processes 2420 (Porcal4.exe)
Type PNG image data, 24 x 22, 8-bit/color RGBA, non-interlaced
MD5 74dd941dd32cc16c176d6c161291fab2
SHA1 8c1399372eedf6b8056af82c961eccc1e1be9e7e
SHA256 2edca55ae458caf00d57acc795adcb5aa8fbd9c700935733b4d90e8c955470f4
CRC32 3D739C08
ssdeep 48:M/6DocieftI9G9f6A+FIDOWu0lDl+gm7QyTtctIInQSy6IVpqlnBcOD3ssc:MSDZ/I09Da01l+gmkyTt6Hk8nTcsc
Yara
  • PNG_Format_Zero - PNG Format
VirusTotal Search for analysis
Name f0a1c195399d2f82_FolderIcon@325.png
Submit file
Filepath C:\Users\test22\AppData\Roaming\Dart Communications\Power iCalconfigurator 15.3.6.2\install\E817FBF\Images\FolderIcon@325.png
Size 2.8KB
Processes 2420 (Porcal4.exe)
Type PNG image data, 52 x 42, 8-bit/color RGBA, non-interlaced
MD5 51515a1f5a6233e3617b31ba08193cf5
SHA1 6ff05e6bd71cb4777b00b9b2c58355ece0f8726b
SHA256 f0a1c195399d2f82d930ee96e3f59a6f5a8339751706aac7fe404c4215e9ba4b
CRC32 D49143C3
ssdeep 48:L7/6DocieftI9G9f6A+FIDOWu0lDl+gm7QyTtctIInQSy6IVpqlnBcODg7:L7SDZ/I09Da01l+gmkyTt6Hk8nTi
Yara
  • PNG_Format_Zero - PNG Format
VirusTotal Search for analysis
Name e2fde6f30b39508a_api-ms-win-core-heap-l1-1-0.dll
Submit file
Filepath C:\Users\test22\AppData\Roaming\Dart Communications\Power iCalconfigurator 15.3.6.2\install\E817FBF\api-ms-win-core-heap-l1-1-0.dll
Size 9.8KB
Processes 2420 (Porcal4.exe)
Type PE32 executable (DLL) (console) Intel 80386, for MS Windows
MD5 9249c6047a70da77505ac028296f4c11
SHA1 a41dd10c73af0f2d91610c81276f737e2cd399a4
SHA256 e2fde6f30b39508ad36338b11c626c22db725908be13824c11c7e2b64b8b1714
CRC32 1AA11230
ssdeep 96:mX99Umncl5EWthWw3k0EuL638yZfaQCiUkm6ybK7shGyf0b3JUfhdyEi7ZHeEDf8:mclaWthW9068Ya5/R6t7shGTBZHP8
Yara
  • PE_Header_Zero - PE File Signature
  • IsPE32 - (no description)
  • IsDLL - (no description)
  • UPX_Zero - UPX packed file
VirusTotal Search for analysis
Name cfd609f8426eefe5_MenuIcon@175.png
Submit file
Filepath C:\Users\test22\AppData\Roaming\Dart Communications\Power iCalconfigurator 15.3.6.2\install\E817FBF\Images\MenuIcon@175.png
Size 2.8KB
Processes 2420 (Porcal4.exe)
Type PNG image data, 19 x 15, 8-bit/color RGBA, non-interlaced
MD5 1f03ccd4ed6edef8911fe1467cb92137
SHA1 e95dd194c325685a9319b7c463ca9b4d41ac7e60
SHA256 cfd609f8426eefe5d30da7958a0ce387fc8346b6e5fa144d992f356a884333a8
CRC32 87AD551C
ssdeep 48:H/6DocieftI9G9f6A+FIDOWu0lDl+gm7QyTtctIInQSy6IVpqlnBcOD+lRk:HSDZ/I09Da01l+gmkyTt6Hk8nT0k
Yara
  • PNG_Format_Zero - PNG Format
VirusTotal Search for analysis
Name 970ba300d98dc6e9_api-ms-win-crt-utility-l1-1-0.dll
Submit file
Filepath C:\Users\test22\AppData\Roaming\Dart Communications\Power iCalconfigurator 15.3.6.2\install\E817FBF\api-ms-win-crt-utility-l1-1-0.dll
Size 9.8KB
Processes 2420 (Porcal4.exe)
Type PE32 executable (DLL) (console) Intel 80386, for MS Windows
MD5 f1b7dd4337c6c6b6179b8fcc77159ca2
SHA1 968dce64676ce80b35c867a309894568a6776ddc
SHA256 970ba300d98dc6e9e9ca54e2725897f618f56324b60335d3cc2f249bbd657705
CRC32 ADCDF2B8
ssdeep 192:OmXI6fHQdufWthWXx068Ya5/R6t7syBZHX5E:O+fZWthWXxaPVRKoAhpE
Yara
  • PE_Header_Zero - PE File Signature
  • IsPE32 - (no description)
  • IsDLL - (no description)
  • UPX_Zero - UPX packed file
VirusTotal Search for analysis
Name 46a0725d67b23778_next.ico
Submit file
Filepath C:\Users\test22\AppData\Roaming\Dart Communications\Power iCalconfigurator 15.3.6.2\install\E817FBF\icons\New Blue\next.ico
Size 894.0B
Processes 2420 (Porcal4.exe)
Type MS Windows icon resource - 1 icon, 16x16, 24 bits/pixel
MD5 2bc6881bce3c30616376978985117d57
SHA1 ca055875412d60d52e60b1784d7b49b2cedfe94b
SHA256 46a0725d67b2377811b6d60afdfedd7fe781fa0c9d1d617e48b69716181d7c43
CRC32 3004C932
ssdeep 12:t492lB4wiIkmgUCMf6veMAYHu1gqzsTTTTTTTTTTTT2:t5lB8mvfyeOuLYTTTTTTTTTTTT2
Yara None matched
VirusTotal Search for analysis
Name eb8f046e2404e917_MixPanel.dll
Submit file
Filepath C:\Users\test22\AppData\Roaming\Dart Communications\Power iCalconfigurator 15.3.6.2\install\E817FBF\MixPanel.dll
Size 49.5KB
Processes 2420 (Porcal4.exe)
Type PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
MD5 abab72ed49b141ad05841d92ffbb425a
SHA1 058b173204910d6299e8adeba9b1e530502f238f
SHA256 eb8f046e2404e91748976f409814ffc862c40835d080c06d4b83088515851927
CRC32 78457319
ssdeep 1536:b+Y/TYV78Zl9/Ld3Jqqqq676z8IQ7q9qXR:b7RDd5O7iNQWYXR
Yara
  • PE_Header_Zero - PE File Signature
  • Generic_Malware_Zero - Generic Malware
  • IsPE32 - (no description)
  • Is_DotNET_DLL - (no description)
  • IsDLL - (no description)
  • UPX_Zero - UPX packed file
VirusTotal Search for analysis
Name b0bb571efd02ac2b_d3.ico
Submit file
Filepath C:\Users\test22\AppData\Roaming\Dart Communications\Power iCalconfigurator 15.3.6.2\install\E817FBF\icons\Classic\d3.ico
Size 1.4KB
Processes 2420 (Porcal4.exe)
Type MS Windows icon resource - 1 icon, 16x16, 8 bits/pixel
MD5 67dac43efc66123d4831b17d50b9dc3b
SHA1 87a4d53f4a9fe0e098c4839e7da0453ba86226c2
SHA256 b0bb571efd02ac2bfaa7ac1ed189b1914d401bed3d1d52387ff09fc9443f225c
CRC32 A1E0533D
ssdeep 6:UZxMcE2jS4Tfl+46EcAOBNHlfmXpxPEjWEapZdl38Hw0mM/tH5n:UZtu4TQ46DAOLHl+XDPnEag/tZn
Yara None matched
VirusTotal Search for analysis
Name ce8ac2e3fee5ef0c_SdCrashReporter.dll
Submit file
Filepath C:\Users\test22\AppData\Roaming\Dart Communications\Power iCalconfigurator 15.3.6.2\install\E817FBF\SdCrashReporter.dll
Size 52.5KB
Processes 2420 (Porcal4.exe)
Type PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
MD5 f55d8ae20f049265aebe704e9df97fc8
SHA1 401534ad6a34b99929bfff3621d1de8777aa3d5b
SHA256 ce8ac2e3fee5ef0c3f0959f11220d061d41998ae973d9f9efb88c220c41598c3
CRC32 A8A7BCD5
ssdeep 768:/pFrUmHmzXWbiOThT8Cwkk3IgSLcEDjnAWyNJiIuCmMVBt:PrbGiVTUk3ZuiI5m8Bt
Yara
  • PE_Header_Zero - PE File Signature
  • OS_Processor_Check_Zero - OS Processor Check
  • IsPE32 - (no description)
  • IsDLL - (no description)
  • Malicious_Library_Zero - Malicious_Library
  • UPX_Zero - UPX packed file
VirusTotal Search for analysis
Name 833512a4daa70131_d12.ico
Submit file
Filepath C:\Users\test22\AppData\Roaming\Dart Communications\Power iCalconfigurator 15.3.6.2\install\E817FBF\icons\New Blue\d12.ico
Size 894.0B
Processes 2420 (Porcal4.exe)
Type MS Windows icon resource - 1 icon, 16x16, 24 bits/pixel
MD5 81d2638fd0852bd050b45dc56bb8edc3
SHA1 7a96503d53169a62581599bb92f09a4652b9d47b
SHA256 833512a4daa70131394bb83b04af765cefb5e455e173b05fffaa9cea6d06bfdb
CRC32 E4EA2461
ssdeep 24:t5DJMcTUMV1qvxpxLCRAKeYTTTTTTTTTTTT2:+AUa85pdCRAKeYTTTTTTTTTTTT2
Yara None matched
VirusTotal Search for analysis
Name 502357912f5f8f95_api-ms-win-core-synch-l1-1-0.dll
Submit file
Filepath C:\Users\test22\AppData\Roaming\Dart Communications\Power iCalconfigurator 15.3.6.2\install\E817FBF\api-ms-win-core-synch-l1-1-0.dll
Size 11.3KB
Processes 2420 (Porcal4.exe)
Type PE32 executable (DLL) (console) Intel 80386, for MS Windows
MD5 3ce632480e98c5f57532cd5b07623151
SHA1 12c2b675a8b480efc96d57d7b25301a76513e4bb
SHA256 502357912f5f8f9526f1d5a978aa595d8226b6ecdd60e607abd78aa37782c4a4
CRC32 46C7F87E
ssdeep 192:TM2dv3V0dfpkXc2MAvVaoKFWthWE068Ya5/R6t7sd8jBZH8cX:Ddv3V0dfpkXc0vVavWthWEaPVRKowhp
Yara
  • PE_Header_Zero - PE File Signature
  • IsPE32 - (no description)
  • IsDLL - (no description)
  • UPX_Zero - UPX packed file
VirusTotal Search for analysis
Name 1fc64ef766a20f96_d14.ico
Submit file
Filepath C:\Users\test22\AppData\Roaming\Dart Communications\Power iCalconfigurator 15.3.6.2\install\E817FBF\icons\Classic\d14.ico
Size 1.4KB
Processes 2420 (Porcal4.exe)
Type MS Windows icon resource - 1 icon, 16x16, 8 bits/pixel
MD5 2876fbca2c0cf9fb3db7b6a027ba92cd
SHA1 2a0c36370b376ce5615ae4d5174a42704173786e
SHA256 1fc64ef766a20f963bd64badfa7ae16cd2c37152497a34489d1e11817eae9a37
CRC32 EDF0EAB8
ssdeep 12:UZtu4TQ46DAOLHl+XHNJJJspJi4+p/tZn:QXBOLMJJJCJi4OD
Yara None matched
VirusTotal Search for analysis
Name 71e4c41a405078bc_d3.ico
Submit file
Filepath C:\Users\test22\AppData\Roaming\Dart Communications\Power iCalconfigurator 15.3.6.2\install\E817FBF\icons\New Blue\d3.ico
Size 894.0B
Processes 2420 (Porcal4.exe)
Type MS Windows icon resource - 1 icon, 16x16, 24 bits/pixel
MD5 124387b357e2a35930170e796eb4090f
SHA1 efadbb49ae783d382b99bd6d64cb1b6d1cb630b0
SHA256 71e4c41a405078bc9f8da7b709110aad2554e64d9c9384bff45706297c204b2f
CRC32 A9D69559
ssdeep 12:t492lsF40seK35EZXmtBIo5zGGLvenlQHi8rte2gqzsTTTTTTTTTTTT2:t5lWYJUaenl0i8ESYTTTTTTTTTTTT2
Yara None matched
VirusTotal Search for analysis
Name 318c81ea860417ec_deutsch.dxs
Submit file
Filepath C:\Users\test22\AppData\Roaming\Dart Communications\Power iCalconfigurator 15.3.6.2\install\E817FBF\sprache\deutsch.dxs
Size 58.7KB
Processes 2420 (Porcal4.exe)
Type ISO-8859 text, with very long lines, with CRLF line terminators
MD5 402da0513f8c2598024196fabfffeb0a
SHA1 dc5d1dc3c8073435a579f501bcba772fd23da10c
SHA256 318c81ea860417ece3cd99c1ca8650cd74a951e69f14a48ca293c88f43d1dbfb
CRC32 8BE2C8E8
ssdeep 1536:q37X8kO2fGAhygAqPPGUUvjxZWTGuGnWi4s4GimnRsz7dqjx4aVuGbZAGneDziWN:q3eFHW+szmiaTtneD58nRa
Yara None matched
VirusTotal Search for analysis
Name 753a40fd838dbd0f_api-ms-win-crt-stdio-l1-1-0.dll
Submit file
Filepath C:\Users\test22\AppData\Roaming\Dart Communications\Power iCalconfigurator 15.3.6.2\install\E817FBF\api-ms-win-crt-stdio-l1-1-0.dll
Size 15.3KB
Processes 2420 (Porcal4.exe)
Type PE32 executable (DLL) (console) Intel 80386, for MS Windows
MD5 7e1aafd095ceaed8408a784799d32461
SHA1 5fc2d2ba6223320ab87e60e00c480690a4216b74
SHA256 753a40fd838dbd0f0f86133858ecebf35c969d0329f0067fb7dcc283a9966c3c
CRC32 C9B68ABC
ssdeep 192:YpPLNPjFuWYFxEpahDWthWmZ068Ya5/R6t7Y/BZHmke:Y19OFVhDWthWaaPVRKU5hU
Yara
  • PE_Header_Zero - PE File Signature
  • IsPE32 - (no description)
  • IsDLL - (no description)
  • UPX_Zero - UPX packed file
VirusTotal Search for analysis
Name bfa12ac5310e10b7_d15a.ico
Submit file
Filepath C:\Users\test22\AppData\Roaming\Dart Communications\Power iCalconfigurator 15.3.6.2\install\E817FBF\icons\New Blue\d15a.ico
Size 894.0B
Processes 2420 (Porcal4.exe)
Type MS Windows icon resource - 1 icon, 16x16, 24 bits/pixel
MD5 6ba2e1a3bf35551054c3fb2514e26e3f
SHA1 7ce04b0be715645254e4aa4be96fe0cc93f2c347
SHA256 bfa12ac5310e10b746ccef21c16bb4967c3940402fc9bb44754580bd46ac6587
CRC32 57EFC94A
ssdeep 12:t47v4A+61mOLFaIc/lfTMbx6N1Jld4GvwtR0ZZbBjmI3M:tSYxO5cVMb83WGvwtR0ZZdj/c
Yara None matched
VirusTotal Search for analysis
Name 819f394fb02a2755_d18a.ico
Submit file
Filepath C:\Users\test22\AppData\Roaming\Dart Communications\Power iCalconfigurator 15.3.6.2\install\E817FBF\icons\Classic\d18a.ico
Size 1.4KB
Processes 2420 (Porcal4.exe)
Type MS Windows icon resource - 1 icon, 16x16, 255 colors, 8 bits/pixel
MD5 5feb0ed0dd3ca328f2798cbe7e11ad13
SHA1 82ee49048ee7aef2f89a5e3315caeb1174aaead2
SHA256 819f394fb02a275572570210bb40cfcd4fb9ff8c6ddbaae4a638f74aea784f7e
CRC32 035992FA
ssdeep 6:dzMQjEGoilbhlxgmXRoVnVlRkinRnBnRnNgN1fwtwmapo2wV/tnn:dzzEElxXRoVV35jyN1otwmapo2wTn
Yara None matched
VirusTotal Search for analysis
Name 2e5f177565a4e6a9_api-ms-win-crt-locale-l1-1-0.dll
Submit file
Filepath C:\Users\test22\AppData\Roaming\Dart Communications\Power iCalconfigurator 15.3.6.2\install\E817FBF\api-ms-win-crt-locale-l1-1-0.dll
Size 9.8KB
Processes 2420 (Porcal4.exe)
Type PE32 executable (DLL) (console) Intel 80386, for MS Windows
MD5 69f968f71943ccb31ef3623add2e5deb
SHA1 960879280743ad7f732bbdca8a3e0538a4e8f34f
SHA256 2e5f177565a4e6a97350388c063f957140db07799618acbe0ab2cd2684e5244c
CRC32 1F9362D1
ssdeep 96:L9vbZXqtEWthWw3W0EuL638yZfaQCiUkm6ybK7sh03JUfhdyEi7ZHeEafPlXmK:L9vbJWthW/068Ya5/R6t7sWBZHg9X7
Yara
  • PE_Header_Zero - PE File Signature
  • IsPE32 - (no description)
  • IsDLL - (no description)
  • UPX_Zero - UPX packed file
VirusTotal Search for analysis
Name 98248d4549775788_d11a.ico
Submit file
Filepath C:\Users\test22\AppData\Roaming\Dart Communications\Power iCalconfigurator 15.3.6.2\install\E817FBF\icons\Classic\d11a.ico
Size 1.4KB
Processes 2420 (Porcal4.exe)
Type MS Windows icon resource - 1 icon, 16x16, 255 colors, 8 bits/pixel
MD5 2330a13e48d5766e7d3177656aed9813
SHA1 d33c0c60e991d2ecd33c2a394e954263c7e3c8f2
SHA256 98248d4549775788e09c06bd4448d5409be637e44fb5d37ef5b9fa668d82ee95
CRC32 6349D2BE
ssdeep 6:dz4mY3OSl55BCxvRu9DpXBoVnVlRkinnRthBnRtTLRjj7pnDeEtY/tnn:dzZY3OW55OA1XBoVV35TThJ/paE8n
Yara None matched
VirusTotal Search for analysis
Name 181759fcb84764c1_d4.ico
Submit file
Filepath C:\Users\test22\AppData\Roaming\Dart Communications\Power iCalconfigurator 15.3.6.2\install\E817FBF\icons\New Blue\d4.ico
Size 894.0B
Processes 2420 (Porcal4.exe)
Type MS Windows icon resource - 1 icon, 16x16, 24 bits/pixel
MD5 0aef1e46366520c4f5db264b6da03bab
SHA1 ed8f7b7f57f2cd2bdf5b2de816eb9ef860fa6799
SHA256 181759fcb84764c16ecb7bcbc314db1551bb61de90e4b9c2e712d1deaebc8b76
CRC32 5FE6CBCB
ssdeep 12:t492l7xZXW1Au7/VMayypGLQpves4YHO2gqzsTTTTTTTTTTTT2:t5l7zG1v/9LeqbYTTTTTTTTTTTT2
Yara None matched
VirusTotal Search for analysis
Name 2127d6e30c14209f_api-ms-win-crt-multibyte-l1-1-0.dll
Submit file
Filepath C:\Users\test22\AppData\Roaming\Dart Communications\Power iCalconfigurator 15.3.6.2\install\E817FBF\api-ms-win-crt-multibyte-l1-1-0.dll
Size 17.3KB
Processes 2420 (Porcal4.exe)
Type PE32 executable (DLL) (console) Intel 80386, for MS Windows
MD5 15ff8cd6cfa210eee7351fad81b6f05b
SHA1 ff0d0aaafa1222bbde34cfd80b0927af15f9ca1f
SHA256 2127d6e30c14209f903ba60bb348074ead409123e2e1f1b38495c2b0c37cbb86
CRC32 330BADD2
ssdeep 384:8SrxLPmIHJI6/CpG3t2G3t4odXLRWthW4aPVRKo1h5z:8iPmIHJI6mUHhB
Yara
  • PE_Header_Zero - PE File Signature
  • IsPE32 - (no description)
  • IsDLL - (no description)
  • UPX_Zero - UPX packed file
VirusTotal Search for analysis
Name e7447574615d53a5_FolderIcon@275.png
Submit file
Filepath C:\Users\test22\AppData\Roaming\Dart Communications\Power iCalconfigurator 15.3.6.2\install\E817FBF\Images\FolderIcon@275.png
Size 2.8KB
Processes 2420 (Porcal4.exe)
Type PNG image data, 44 x 38, 8-bit/color RGBA, non-interlaced
MD5 7c48be789eaba846b6a79061a63dd8b0
SHA1 656b0a3a46d0f0ab86b509f000b7edcd70963e97
SHA256 e7447574615d53a5ed5a7d67b32f810361786cc5510af1bb0047c8d092b132f3
CRC32 9FDAB77D
ssdeep 48:p/6DocieftI9G9f6A+FIDOWu0lDl+gm7QyTtctIInQSy6IVpqlnBcODx:pSDZ/I09Da01l+gmkyTt6Hk8nTx
Yara
  • PNG_Format_Zero - PNG Format
VirusTotal Search for analysis
Name bfd2b9cf7edc330a_FencesSmall@150.png
Submit file
Filepath C:\Users\test22\AppData\Roaming\Dart Communications\Power iCalconfigurator 15.3.6.2\install\E817FBF\Images\FencesSmall@150.png
Size 4.5KB
Processes 2420 (Porcal4.exe)
Type PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
MD5 868081838288500c460c8ad4ba104f54
SHA1 7de950b34977d85ad520b7e10def2e78defa16da
SHA256 bfd2b9cf7edc330a0244ede49d1471b4f836c4d58e8845bb1418f32d37a656dd
CRC32 72D6F7EE
ssdeep 96:zZ/I09Da01l+gmkyTt6Hk8nTstYszXImL+pbsPAox83YW:zS0tKg9E05TCNjImypAK3YW
Yara
  • PNG_Format_Zero - PNG Format
VirusTotal Search for analysis
Name 6141b2406a02ada1_d18a.ico
Submit file
Filepath C:\Users\test22\AppData\Roaming\Dart Communications\Power iCalconfigurator 15.3.6.2\install\E817FBF\icons\New Blue\d18a.ico
Size 894.0B
Processes 2420 (Porcal4.exe)
Type MS Windows icon resource - 1 icon, 16x16, 24 bits/pixel
MD5 cbe41cefdc1e82155571d7f04ff4a233
SHA1 cae3464fdeab14a46562c6590ed841baba675b46
SHA256 6141b2406a02ada1ed4fd2be250c12864e1066a34a14bfc1fe89e833dc51ccdf
CRC32 A39A3B7B
ssdeep 12:t47v4AlJd942mOOyc9LqnotRxMyZ245jM0M:tSLh4O5c5ltRXZzjQ
Yara None matched
VirusTotal Search for analysis
Name 5a9479caa4024731_PagerBackL.png
Submit file
Filepath C:\Users\test22\AppData\Roaming\Dart Communications\Power iCalconfigurator 15.3.6.2\install\E817FBF\Images\PagerBackL.png
Size 4.2KB
Processes 2420 (Porcal4.exe)
Type PNG image data, 90 x 43, 8-bit/color RGBA, interlaced
MD5 b3c74bb5250effad46ce11a96c9468c2
SHA1 3a339e244a29fe41d13fa4cc951a7e0a2862e299
SHA256 5a9479caa4024731d61172652a67021f4973a03548516d36a4865ec161a57825
CRC32 9A1B4A87
ssdeep 96:OSDZ/I09Da01l+gmkyTt6Hk8nToU+Hfb2QRx/lt2O49P:OSDS0tKg9E05Todb2QL/eJ9P
Yara
  • PNG_Format_Zero - PNG Format
VirusTotal Search for analysis
Name c1bbea6b55c870b8_CreateFolderFence@125.png
Submit file
Filepath C:\Users\test22\AppData\Roaming\Dart Communications\Power iCalconfigurator 15.3.6.2\install\E817FBF\Images\CreateFolderFence@125.png
Size 2.9KB
Processes 2420 (Porcal4.exe)
Type PNG image data, 20 x 19, 8-bit/color RGBA, non-interlaced
MD5 4a13f6981a4e57b762e232a84f470b10
SHA1 d7a6d8db62e1ee2a81bea0861380b5ee81f1f102
SHA256 c1bbea6b55c870b8a40b9b01426a0da7178ae5fbe200404c6acd01aabb0f09e4
CRC32 221709D7
ssdeep 48:ls/6DocieftI9G9f6A+FIDOWu0lDl+gm7QyTtctIInQSy6IVpqlnBcODqwEW9:lsSDZ/I09Da01l+gmkyTt6Hk8nT7EC
Yara
  • PNG_Format_Zero - PNG Format
VirusTotal Search for analysis
Name dbd77295dd11dc27_d11a.ico
Submit file
Filepath C:\Users\test22\AppData\Roaming\Dart Communications\Power iCalconfigurator 15.3.6.2\install\E817FBF\icons\New Blue\d11a.ico
Size 894.0B
Processes 2420 (Porcal4.exe)
Type MS Windows icon resource - 1 icon, 16x16, 24 bits/pixel
MD5 9222febc58dd432a4100024c87465e17
SHA1 d938f1f94f483f3450e75098e03da50e221e3aa3
SHA256 dbd77295dd11dc270a2b3b1265c85f397cd074bfe11d0fd6e52fff454994af48
CRC32 29DCF4C7
ssdeep 12:t47v4A9PHmOKTc2Qc+yE4/id/FWFtGtRg6Z06EjRJ0M:tSrOOKTc2QPyLSetGtR3Z0Jjx
Yara None matched
VirusTotal Search for analysis
Name 93361b2f66f9b301_api-ms-win-core-profile-l1-1-0.dll
Submit file
Filepath C:\Users\test22\AppData\Roaming\Dart Communications\Power iCalconfigurator 15.3.6.2\install\E817FBF\api-ms-win-core-profile-l1-1-0.dll
Size 8.8KB
Processes 2420 (Porcal4.exe)
Type PE32 executable (DLL) (console) Intel 80386, for MS Windows
MD5 4490653137e5add800046027dfb7f950
SHA1 35f8b0bb859ee5ba5e9b854f70d2a371eec65101
SHA256 93361b2f66f9b3017c5fa5455f43058be7db8aef3b9f5dadec7cd79898f86f7d
CRC32 34AEBAAC
ssdeep 96:CEyaMSEWthWwOLe0EuL638yZfaQCiUkm6ybK7YcF+U3JUfhdyEi7ZHeEIfM/EwS:CtaIWthWk068Ya5/R6t7YcF+MBZHmmI
Yara
  • PE_Header_Zero - PE File Signature
  • IsPE32 - (no description)
  • IsDLL - (no description)
  • UPX_Zero - UPX packed file
VirusTotal Search for analysis
Name 03e1f20dc96309e5_CloseIcon@200.png
Submit file
Filepath C:\Users\test22\AppData\Roaming\Dart Communications\Power iCalconfigurator 15.3.6.2\install\E817FBF\Images\CloseIcon@200.png
Size 2.8KB
Processes 2420 (Porcal4.exe)
Type PNG image data, 17 x 17, 8-bit/color RGBA, non-interlaced
MD5 ad76b31e75197975af306528a8f73d4a
SHA1 aa17254bae04e1fe52c823e7eaff302528fe2744
SHA256 03e1f20dc96309e51fe3b2314aac6bf0da1ceb68bbd3e03f5a388dd480503a3c
CRC32 FB7729CD
ssdeep 48:K/6DocieftI9G9f6A+FIDOWu0lDl+gm7QyTtctIInQSy6IVpqlnBcODz:KSDZ/I09Da01l+gmkyTt6Hk8nTz
Yara
  • PNG_Format_Zero - PNG Format
VirusTotal Search for analysis
Name 31853e3075e301bb_MenuIcon@300.png
Submit file
Filepath C:\Users\test22\AppData\Roaming\Dart Communications\Power iCalconfigurator 15.3.6.2\install\E817FBF\Images\MenuIcon@300.png
Size 2.8KB
Processes 2420 (Porcal4.exe)
Type PNG image data, 33 x 27, 8-bit/color RGBA, non-interlaced
MD5 5a4264415859ea488e424f275692ace9
SHA1 3df2898a7dbdd0872a2686631842502faa9bd783
SHA256 31853e3075e301bba4ea4a7cb71754a244a5924e88aa3ecb6c2145148fb829ae
CRC32 77403E70
ssdeep 48:+/6DocieftI9G9f6A+FIDOWu0lDl+gm7QyTtctIInQSy6IVpqlnBcODWnso56:+SDZ/I09Da01l+gmkyTt6Hk8nTc56
Yara
  • PNG_Format_Zero - PNG Format
VirusTotal Search for analysis
Name 0454c94c75b36ede_english.dxs
Submit file
Filepath C:\Users\test22\AppData\Roaming\Dart Communications\Power iCalconfigurator 15.3.6.2\install\E817FBF\sprache\english.dxs
Size 56.0KB
Processes 2420 (Porcal4.exe)
Type ASCII text, with very long lines, with CRLF line terminators
MD5 309593d4a6aea19c639255ae6cfcf8f5
SHA1 9612d50ff7f74b14fec1658667223287517ddfde
SHA256 0454c94c75b36eded46e7e9ffeeefab7c7c69dd55e43e693b8f89fb79060d86f
CRC32 40860277
ssdeep 1536:RaCIY7K/RLYB0CxPUUb42nL/5twFtP+PwcUALykfl1qWvIz+rhVcyECvqwmHCsdZ:RaCTyUQPBEL51hvIzSLECvqt
Yara None matched
VirusTotal Search for analysis
Name 41a63e13d59ca19d_DropdownIcon@225.png
Submit file
Filepath C:\Users\test22\AppData\Roaming\Dart Communications\Power iCalconfigurator 15.3.6.2\install\E817FBF\Images\DropdownIcon@225.png
Size 2.8KB
Processes 2420 (Porcal4.exe)
Type PNG image data, 21 x 21, 8-bit/color RGBA, non-interlaced
MD5 95ced74c1de1ba8b033b2517718e5661
SHA1 6e46fedb2ecdb122d5f9c0e9bfac84a3184c284a
SHA256 41a63e13d59ca19d3d1a8ff7b0f6592ccda2525673197b42e873a08231a64ff0
CRC32 04E58958
ssdeep 48:E/6DocieftI9G9f6A+FIDOWu0lDl+gm7QyTtctIInQSy6IVpqlnBcOD9oe:ESDZ/I09Da01l+gmkyTt6Hk8nTB
Yara
  • PNG_Format_Zero - PNG Format
VirusTotal Search for analysis
Name 963d688d2fa34b87_d7a.ico
Submit file
Filepath C:\Users\test22\AppData\Roaming\Dart Communications\Power iCalconfigurator 15.3.6.2\install\E817FBF\icons\New Blue\d7a.ico
Size 894.0B
Processes 2420 (Porcal4.exe)
Type MS Windows icon resource - 1 icon, 16x16, 24 bits/pixel
MD5 5fac76df6933dc3a6ad4c9788a7f0d48
SHA1 2ad2122d1a06462c6f816d04b3b36cdb82c62572
SHA256 963d688d2fa34b87001fe11fc31f139e1c0069f49823b51e207957092469d2c8
CRC32 A724E99B
ssdeep 12:t47v42g341mXmPvx3Aj0ONBn4r60hTkfhvX33CC8euvGFMJg0M:tS8DcSNB4fwfJXvFF5
Yara None matched
VirusTotal Search for analysis
Name b574d89422afcaae_lua5.1.dll
Submit file
Filepath C:\Users\test22\AppData\Roaming\Dart Communications\Power iCalconfigurator 15.3.6.2\install\E817FBF\lua5.1.dll
Size 327.0KB
Processes 2420 (Porcal4.exe)
Type PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
MD5 05ceb6d2e88a896d6ada0ab3f0dc40aa
SHA1 2b62cc437f5b3268acb3f569b43fd6c0a08e4e47
SHA256 b574d89422afcaae5446d8fd88d3b7cb48d608cf5411db761916b35c9999b41a
CRC32 F2E5CB18
ssdeep 6144:mpF7LK5bwfYggoCQxltnoqhMQ3WxAOj+JzOgmQ:e7Igvnoz0Wx8xb
Yara
  • PE_Header_Zero - PE File Signature
  • OS_Processor_Check_Zero - OS Processor Check
  • IsPE32 - (no description)
  • IsDLL - (no description)
  • Malicious_Library_Zero - Malicious_Library
  • UPX_Zero - UPX packed file
VirusTotal Search for analysis
Name 3c8a6af374b1cbc4_MenuIcon@100.png
Submit file
Filepath C:\Users\test22\AppData\Roaming\Dart Communications\Power iCalconfigurator 15.3.6.2\install\E817FBF\Images\MenuIcon@100.png
Size 2.8KB
Processes 2420 (Porcal4.exe)
Type PNG image data, 11 x 9, 8-bit/color RGBA, non-interlaced
MD5 75c61493f04beb2f3add45333cd519ac
SHA1 752ce64191bb29efb7dfeba790e97b8ad1a29da4
SHA256 3c8a6af374b1cbc4eabd11b1e93d4a4c12353ee4afeb6cf352f680ec7ca4d8ed
CRC32 EC22DB4E
ssdeep 48:w/6DocieftI9G9f6A+FIDOWu0lDl+gm7QyTtctIInQSy6IVpqlnBcOD6si:wSDZ/I09Da01l+gmkyTt6Hk8nT2
Yara
  • PNG_Format_Zero - PNG Format
VirusTotal Search for analysis
Name 1cf54da2df682162_api-ms-win-core-interlocked-l1-1-0.dll
Submit file
Filepath C:\Users\test22\AppData\Roaming\Dart Communications\Power iCalconfigurator 15.3.6.2\install\E817FBF\api-ms-win-core-interlocked-l1-1-0.dll
Size 9.8KB
Processes 2420 (Porcal4.exe)
Type PE32 executable (DLL) (console) Intel 80386, for MS Windows
MD5 1c0a13452168b0abc94768a0583da0e9
SHA1 2d6be592f81f8aea2c53f7b970f3800d4e4df4dc
SHA256 1cf54da2df682162430dc612bf5a3a230dab684d83d2e933598ef2d63dd3d8a3
CRC32 8DA149F9
ssdeep 192:cXxDYsFIWthWT068Ya5/R6t7YJCzBZH6K:cXxDYsFIWthWTaPVRKUJShB
Yara
  • PE_Header_Zero - PE File Signature
  • IsPE32 - (no description)
  • IsDLL - (no description)
  • UPX_Zero - UPX packed file
VirusTotal Search for analysis
Name f7ac4ceb149eae51_msvcp_win.dll
Submit file
Filepath C:\Users\test22\AppData\Roaming\Dart Communications\Power iCalconfigurator 15.3.6.2\install\E817FBF\msvcp_win.dll
Size 484.2KB
Processes 2420 (Porcal4.exe)
Type PE32 executable (DLL) (console) Intel 80386, for MS Windows
MD5 f9e704b67eccd77a18965e9cfa128461
SHA1 45c0154c0128d356fa96f23689d945ce4122d975
SHA256 f7ac4ceb149eae5184b957d90ebedd9bc916cd1ba3053548b637b4e32a7f8a07
CRC32 899F0F49
ssdeep 12288:Am8MyfWVRsPsxy60whuhFbCu8hUgiW6QR7t5s03Ooc8dHkC2es/oLnM:Ry+sPsxy60euPbn03Ooc8dHkC2eyoLM
Yara
  • PE_Header_Zero - PE File Signature
  • OS_Processor_Check_Zero - OS Processor Check
  • IsPE32 - (no description)
  • IsDLL - (no description)
  • UPX_Zero - UPX packed file
VirusTotal Search for analysis
Name 6bd18382ee4d85c4_api-ms-win-core-console-l1-1-0.dll
Submit file
Filepath C:\Users\test22\AppData\Roaming\Dart Communications\Power iCalconfigurator 15.3.6.2\install\E817FBF\api-ms-win-core-console-l1-1-0.dll
Size 9.8KB
Processes 2420 (Porcal4.exe)
Type PE32 executable (DLL) (console) Intel 80386, for MS Windows
MD5 404219bf7529c7fbb3660dfc6605bd37
SHA1 d084602c8cce1cae69a221b6ecdcb07698840a21
SHA256 6bd18382ee4d85c4b8f25b8ae84309793a93e89fe97d0b9ff47aea8b3b0a8ad0
CRC32 1ED28340
ssdeep 96:f44aDTEWthWw3t0EuL638yZfaQCiUkm6ybK7siRJmSJcO3JUfhdyEi7ZHeEyfKll:AcWthWs068Ya5/R6t7siSSC2BZHgOfN
Yara
  • PE_Header_Zero - PE File Signature
  • IsPE32 - (no description)
  • IsDLL - (no description)
  • UPX_Zero - UPX packed file
VirusTotal Search for analysis
Name 7bb65725a2e5cfc1_api-ms-win-core-timezone-l1-1-0.dll
Submit file
Filepath C:\Users\test22\AppData\Roaming\Dart Communications\Power iCalconfigurator 15.3.6.2\install\E817FBF\api-ms-win-core-timezone-l1-1-0.dll
Size 9.8KB
Processes 2420 (Porcal4.exe)
Type PE32 executable (DLL) (console) Intel 80386, for MS Windows
MD5 2c9e3c220c46b58512dcd93e2670abcf
SHA1 dbafc8b15b160b35747a8a0de7225b4f317d4b95
SHA256 7bb65725a2e5cfc130eb6883ecb340b7bdc1b90cc33d31c638b0ae66ae8c318c
CRC32 D1BD0105
ssdeep 96:60TgqSnEWthWwOr0EuL638yZfaQCiUkm6ybK7YSJB0y3JUfhdyEi7ZHeEyfDGdn:13WthWJ068Ya5/R6t7YSJayBZHADGdn
Yara
  • PE_Header_Zero - PE File Signature
  • IsPE32 - (no description)
  • IsDLL - (no description)
  • UPX_Zero - UPX packed file
VirusTotal Search for analysis
Name 5d75d94bed020bd8_d1a.ico
Submit file
Filepath C:\Users\test22\AppData\Roaming\Dart Communications\Power iCalconfigurator 15.3.6.2\install\E817FBF\icons\Classic\d1a.ico
Size 1.4KB
Processes 2420 (Porcal4.exe)
Type MS Windows icon resource - 1 icon, 16x16, 255 colors, 8 bits/pixel
MD5 8c9c577bcc8e3427c16dce8295f467c6
SHA1 585f292c6b6469e2551fa9919f9f8daec7365af3
SHA256 5d75d94bed020bd81d7793fd414e45f7b9c9c3f20a733a9b87f4425be24320d3
CRC32 CF2E0A0C
ssdeep 6:dzM/Af9LlvLmXRoVnVnDnVnRnVnRn1nlNOUp6R0k9Jw/tnn:dz8A1JKXRoVVDVRVRNlNONmn
Yara None matched
VirusTotal Search for analysis
Name 4a5916080b7349fd_api-ms-win-core-processthreads-l1-1-0.dll
Submit file
Filepath C:\Users\test22\AppData\Roaming\Dart Communications\Power iCalconfigurator 15.3.6.2\install\E817FBF\api-ms-win-core-processthreads-l1-1-0.dll
Size 11.8KB
Processes 2420 (Porcal4.exe)
Type PE32 executable (DLL) (console) Intel 80386, for MS Windows
MD5 c6075890623d20fe25934107a2887176
SHA1 9a83a682cdb9e304ad1bb914cdb0751c58affe28
SHA256 4a5916080b7349fd9b657c04e1e7a848df04a1bee195f6b6b3301e18cb0c8b9d
CRC32 7248404F
ssdeep 192:3hHk1Jzb9cKcIhWthW6068Ya5/R6t7s6cLVMBZHsZ:xHk1JzBcKcIhWthW6aPVRKopL4hy
Yara
  • PE_Header_Zero - PE File Signature
  • IsPE32 - (no description)
  • IsDLL - (no description)
  • UPX_Zero - UPX packed file
VirusTotal Search for analysis
Name 78d39f1a791c9fc7_BottomRightCorner.fencelayout
Submit file
Filepath C:\Users\test22\AppData\Roaming\Dart Communications\Power iCalconfigurator 15.3.6.2\install\E817FBF\Layouts\BottomRightCorner.fencelayout
Size 1.1KB
Processes 2420 (Porcal4.exe)
Type XML 1.0 document, ASCII text, with CRLF line terminators
MD5 f4c2003c756eb0169b9e1620ba08590a
SHA1 927f780c8fdd114b9bd3d883a41982d9fb123565
SHA256 78d39f1a791c9fc7a7626374d3d82d91aac4447ff71167a144b0b1f064a01d90
CRC32 1BF7DB49
ssdeep 24:2dX8ANMN5u6QfhvH8VSYDLVSYjzWdqLPvM:cX8uybIY3IYy
Yara None matched
VirusTotal Search for analysis
Name 586b4adc591c263b_d13.ico
Submit file
Filepath C:\Users\test22\AppData\Roaming\Dart Communications\Power iCalconfigurator 15.3.6.2\install\E817FBF\icons\Classic\d13.ico
Size 1.4KB
Processes 2420 (Porcal4.exe)
Type MS Windows icon resource - 1 icon, 16x16, 8 bits/pixel
MD5 4018aca2ef7957e2529cc517c94520b9
SHA1 24b6e2379751f91946601f8fcc65727caf4eeb27
SHA256 586b4adc591c263b730df2b0d841ae77c69dd5f909e8a822de1bcea7802c96ff
CRC32 B9EE0EB1
ssdeep 12:UZtu4TQ46DAOLHl+XWuhiElWF/8XugF//tZn:QXBOLQhlvXu4/D
Yara None matched
VirusTotal Search for analysis
Name 031c1ca46e00f407_msvcp140_codecvt_ids.dll
Submit file
Filepath C:\Users\test22\AppData\Roaming\Dart Communications\Power iCalconfigurator 15.3.6.2\install\E817FBF\msvcp140_codecvt_ids.dll
Size 16.3KB
Processes 2420 (Porcal4.exe)
Type PE32 executable (DLL) (console) Intel 80386, for MS Windows
MD5 156a7c391e04b47857a8090130a007a4
SHA1 18465b5e3f6e3fa700a83d9fe78d3e344717a50c
SHA256 031c1ca46e00f407fa33bd90b27956adba49b62de99f4fd4888cd7aa4a0ed33f
CRC32 85B3E56C
ssdeep 192:T62J7MDSdDoE3K+IjE9jOZx+xSxMxX2hnDlWiZaEWRcz068Ya5/R6t7spLBZHTE:ADSdV3lIjIjj2dlWiwEWWzaPVRKonhQ
Yara
  • PE_Header_Zero - PE File Signature
  • OS_Processor_Check_Zero - OS Processor Check
  • IsPE32 - (no description)
  • IsDLL - (no description)
  • UPX_Zero - UPX packed file
VirusTotal Search for analysis
Name ef9b9ab5433c85b8_CreateFence@150.png
Submit file
Filepath C:\Users\test22\AppData\Roaming\Dart Communications\Power iCalconfigurator 15.3.6.2\install\E817FBF\Images\CreateFence@150.png
Size 2.9KB
Processes 2420 (Porcal4.exe)
Type PNG image data, 24 x 22, 8-bit/color RGBA, non-interlaced
MD5 a417b1ebe3d8c4bdbf63ab7235cfc005
SHA1 a88c4f44c801dba9621697ec0dba2b8b0d7025b0
SHA256 ef9b9ab5433c85b8bcc013fa53003a5adce144fb2ef35b74e312be400181b3e4
CRC32 4E89E858
ssdeep 48:M/6DocieftI9G9f6A+FIDOWu0lDl+gm7QyTtctIInQSy6IVpqlnBcODvBH4N:MSDZ/I09Da01l+gmkyTt6Hk8nTvBHq
Yara
  • PNG_Format_Zero - PNG Format
VirusTotal Search for analysis
Name 42330bd5334fe3fb_d6.ico
Submit file
Filepath C:\Users\test22\AppData\Roaming\Dart Communications\Power iCalconfigurator 15.3.6.2\install\E817FBF\icons\New Blue\d6.ico
Size 894.0B
Processes 2420 (Porcal4.exe)
Type MS Windows icon resource - 1 icon, 16x16, 24 bits/pixel
MD5 d3e9b0d74054fc985e4837c160ae4d44
SHA1 9fc49ac03fa2885acab1d9a6f9e2b90515c831a4
SHA256 42330bd5334fe3fb1ffbc3b1b88f2f17befd256c83fb827e4fc34e3791b65174
CRC32 0979004C
ssdeep 12:t492lqMbIlwRgOt5uGgJPiG3vexHtZheSGgqzsTTTTTTTTTTTT2:t5lHKEFHcReRT8RYTTTTTTTTTTTT2
Yara None matched
VirusTotal Search for analysis
Name aa416a9e707be847_ucrtbase_clr0400.dll
Submit file
Filepath C:\Users\test22\AppData\Roaming\Dart Communications\Power iCalconfigurator 15.3.6.2\install\E817FBF\ucrtbase_clr0400.dll
Size 685.9KB
Processes 2420 (Porcal4.exe)
Type PE32 executable (DLL) (console) Intel 80386, for MS Windows
MD5 bfe20e1d9bebe61cd8898663fdacb74e
SHA1 d922543e2ceea2c3f68fd58fafda2951a058af3d
SHA256 aa416a9e707be8475051ff502d20077a687d14cf3ababf4959f489a3b5bfbf8b
CRC32 A03C3E5D
ssdeep 12288:Zht6DqNTv6vrWB7EKlRlZNLfG0KQsv7N/qjenEb2HfpgLYyhtMwEaeEmW3may3xK:ZhtDTSoKQ+7MJbWfpgLYHwhnmW3may3c
Yara
  • PE_Header_Zero - PE File Signature
  • OS_Processor_Check_Zero - OS Processor Check
  • IsPE32 - (no description)
  • Win32_Trojan_Gen_2_0904B0_Zero - Win32 Trojan Gen
  • IsDLL - (no description)
  • Malicious_Library_Zero - Malicious_Library
  • UPX_Zero - UPX packed file
  • Win32_Trojan_Gen_1_0904B0_Zero - Win32 Trojan Emotet
VirusTotal Search for analysis
Name 2883a5708f19f994_api-ms-win-core-processenvironment-l1-1-0.dll
Submit file
Filepath C:\Users\test22\AppData\Roaming\Dart Communications\Power iCalconfigurator 15.3.6.2\install\E817FBF\api-ms-win-core-processenvironment-l1-1-0.dll
Size 10.3KB
Processes 2420 (Porcal4.exe)
Type PE32 executable (DLL) (console) Intel 80386, for MS Windows
MD5 b0a8b962fbffccf4887891d06d6930f4
SHA1 aefe232b372fa0c907edae789472c136b34058de
SHA256 2883a5708f19f99475035f53fcf0433edae0a0e08d93ad023902c302ac8493a1
CRC32 E3EF905E
ssdeep 96:2MWIOEWthWw3BW0EuL638yZfaQCiUkm6ybK7sITmA/aB3JUfhdyEi7ZHeE8fe8:JZDWthWt068Ya5/R6t7sYCbBZHKJ
Yara
  • PE_Header_Zero - PE File Signature
  • IsPE32 - (no description)
  • IsDLL - (no description)
  • UPX_Zero - UPX packed file
VirusTotal Search for analysis
Name 422c2affa3297599_api-ms-win-crt-private-l1-1-0.dll
Submit file
Filepath C:\Users\test22\AppData\Roaming\Dart Communications\Power iCalconfigurator 15.3.6.2\install\E817FBF\api-ms-win-crt-private-l1-1-0.dll
Size 62.8KB
Processes 2420 (Porcal4.exe)
Type PE32 executable (DLL) (console) Intel 80386, for MS Windows
MD5 f4ded00886060a3b4383cbff84a549e2
SHA1 4a2341623c518e358fc62e2807673fb6cf1fab0f
SHA256 422c2affa32975992cca063e8c76b1cb5b5e2d502cdf6be6257b48023afdcb3a
CRC32 8E53C392
ssdeep 1536:lfolDe5c4bFE2Jy2cvxXWpD9d3334BkZnkPH8:9olDe5c4bFE2Jy2cvxXWpD9d3334BkZH
Yara
  • PE_Header_Zero - PE File Signature
  • IsPE32 - (no description)
  • IsDLL - (no description)
  • UPX_Zero - UPX packed file
VirusTotal Search for analysis
Name 18c2e829a9ba37b9_NavigateUpIcon@150.png
Submit file
Filepath C:\Users\test22\AppData\Roaming\Dart Communications\Power iCalconfigurator 15.3.6.2\install\E817FBF\Images\NavigateUpIcon@150.png
Size 2.8KB
Processes 2420 (Porcal4.exe)
Type PNG image data, 17 x 20, 8-bit/color RGBA, non-interlaced
MD5 913e9c0d6a5c0b359aac34c60ae4dba1
SHA1 d23e76bba9ca8b4c8c033be4ae84f61b832fc915
SHA256 18c2e829a9ba37b9abb4a42131f5384290aa3a442e219e0750fc89cafc7236b3
CRC32 F1D56DC2
ssdeep 48:o/6DocieftI9G9f6A+FIDOWu0lDl+gm7QyTtctIInQSy6IVpqlnBcODOf3A:oSDZ/I09Da01l+gmkyTt6Hk8nTb
Yara
  • PNG_Format_Zero - PNG Format
VirusTotal Search for analysis
Name 73ca5c92bc5921f2_d19.ico
Submit file
Filepath C:\Users\test22\AppData\Roaming\Dart Communications\Power iCalconfigurator 15.3.6.2\install\E817FBF\icons\Classic\d19.ico
Size 1.4KB
Processes 2420 (Porcal4.exe)
Type MS Windows icon resource - 1 icon, 16x16, 8 bits/pixel
MD5 edbf9cd9d0aa2bfcd23f7dc317d615a7
SHA1 249071186076159f2df6f04e7585a9bf0f174f37
SHA256 73ca5c92bc5921f27d75168984d5290d9fa02778cef69478a32f270d60907a84
CRC32 282E5B92
ssdeep 12:UZtu4TQ46DAOLHl+XWuiqiB/TwigugF//tZn:QXBOLQiqIkBu4/D
Yara None matched
VirusTotal Search for analysis
Name 012dbf027168841c_d14a.ico
Submit file
Filepath C:\Users\test22\AppData\Roaming\Dart Communications\Power iCalconfigurator 15.3.6.2\install\E817FBF\icons\New Blue\d14a.ico
Size 894.0B
Processes 2420 (Porcal4.exe)
Type MS Windows icon resource - 1 icon, 16x16, 24 bits/pixel
MD5 6dc880785f85c54a2e62de1afc498e81
SHA1 a477d5069d112b706c06076f1881e67041cbcabe
SHA256 012dbf027168841c57321a6e476178876362f6e044ee4894f51c2e0c57890ff2
CRC32 BB3CEAFA
ssdeep 12:t47v4A9B9wmO7cMIZvixrHETXYRmGtRobSZ4j2cs0M:tSrBtO7c3N6OGtRLZ4jw
Yara None matched
VirusTotal Search for analysis
Name b9d7be77a2976dc2_MenuIcon@150.png
Submit file
Filepath C:\Users\test22\AppData\Roaming\Dart Communications\Power iCalconfigurator 15.3.6.2\install\E817FBF\Images\MenuIcon@150.png
Size 2.8KB
Processes 2420 (Porcal4.exe)
Type PNG image data, 16 x 13, 8-bit/color RGBA, non-interlaced
MD5 4ab6b2ad846adc051fec0f9c07498faa
SHA1 60329062a34ca921b64c0a251e846c73608bc75d
SHA256 b9d7be77a2976dc279884ac02dccbf010a4e438c2ef7b26987fb1d7439dacbe1
CRC32 F2E87FA0
ssdeep 48:T/6DocieftI9G9f6A+FIDOWu0lDl+gm7QyTtctIInQSy6IVpqlnBcODIO0Z9:TSDZ/I09Da01l+gmkyTt6Hk8nT49
Yara
  • PNG_Format_Zero - PNG Format
VirusTotal Search for analysis
Name b594a6e0c0356572_api-ms-win-core-memory-l1-1-0.dll
Submit file
Filepath C:\Users\test22\AppData\Roaming\Dart Communications\Power iCalconfigurator 15.3.6.2\install\E817FBF\api-ms-win-core-memory-l1-1-0.dll
Size 9.8KB
Processes 2420 (Porcal4.exe)
Type PE32 executable (DLL) (console) Intel 80386, for MS Windows
MD5 278bae8853cd07599fefd924103091bb
SHA1 d9b3d97c88570adbe8b23ae526d6a225a06f3bc3
SHA256 b594a6e0c0356572bcebeadde7f4d318a1041ac1b5f6e023cf130d219a91fb30
CRC32 B7E7F36F
ssdeep 96:If5z4BwEWthWwOr0EuL638yZfaQCiUkm6ybK7Yr53U3JUfhdyEi7ZHeEHft4PxHV:IxKJWthWB068Ya5/R6t7Yr5cBZHjt4D
Yara
  • PE_Header_Zero - PE File Signature
  • IsPE32 - (no description)
  • IsDLL - (no description)
  • UPX_Zero - UPX packed file
VirusTotal Search for analysis
Name fe87e02e797a1430_PagerBullet.png
Submit file
Filepath C:\Users\test22\AppData\Roaming\Dart Communications\Power iCalconfigurator 15.3.6.2\install\E817FBF\Images\PagerBullet.png
Size 2.8KB
Processes 2420 (Porcal4.exe)
Type PNG image data, 22 x 43, 8-bit/color RGBA, non-interlaced
MD5 228d4bd899577ed16ad3ac74b592a0e6
SHA1 baf99e34e126d6c41b7aa39caabc2376358bab70
SHA256 fe87e02e797a143042bd7f10fa57c6e2a53028b5d5ab4c3da2a1e4affd1c86d5
CRC32 EACCA3AA
ssdeep 48:+/6DocieftI9G9f6A+FIDOWu0lDl+gm7QyTtctIInQSy6IVpqlnBcODbHxEk:+SDZ/I09Da01l+gmkyTt6Hk8nTbxEk
Yara
  • PNG_Format_Zero - PNG Format
VirusTotal Search for analysis
Name dba0a2c8ff7c29e8_api-ms-win-crt-convert-l1-1-0.dll
Submit file
Filepath C:\Users\test22\AppData\Roaming\Dart Communications\Power iCalconfigurator 15.3.6.2\install\E817FBF\api-ms-win-crt-convert-l1-1-0.dll
Size 13.3KB
Processes 2420 (Porcal4.exe)
Type PE32 executable (DLL) (console) Intel 80386, for MS Windows
MD5 f28b8963cee07f284fdfb43e7dd597ee
SHA1 ae2735eebf2a8399fd20064393c8193a97cf1633
SHA256 dba0a2c8ff7c29e8b3b78a613b33b2a025014b4d8ec879f53bdbc35d3a3b9887
CRC32 065A6ADF
ssdeep 192:jM0wd8dc9cyNWthWW068Ya5/R6t7YXI/JWBZHbHme:o0wd8xyNWthWWaPVRKUXMChB
Yara
  • PE_Header_Zero - PE File Signature
  • IsPE32 - (no description)
  • IsDLL - (no description)
  • UPX_Zero - UPX packed file
VirusTotal Search for analysis
Name 1b89214126aacc17_CloseIcon@100.png
Submit file
Filepath C:\Users\test22\AppData\Roaming\Dart Communications\Power iCalconfigurator 15.3.6.2\install\E817FBF\Images\CloseIcon@100.png
Size 2.8KB
Processes 2420 (Porcal4.exe)
Type PNG image data, 9 x 9, 8-bit/color RGBA, non-interlaced
MD5 862e7c478602f3bd7c1ad8ca710e2ef1
SHA1 ca22694cc6fc1caa96ca37135050ed967753b0bc
SHA256 1b89214126aacc175421aa0e288f6ccab860f5306f95aa1db145f0d22f7a512b
CRC32 1DD5DB58
ssdeep 48:m/6DocieftI9G9f6A+FIDOWu0lDl+gm7QyTtctIInQSy6IVpqlnBcODPVv:mSDZ/I09Da01l+gmkyTt6Hk8nTdv
Yara
  • PNG_Format_Zero - PNG Format
VirusTotal Search for analysis
Name 8dda938588c7e2fb_api-ms-win-crt-math-l1-1-0.dll
Submit file
Filepath C:\Users\test22\AppData\Roaming\Dart Communications\Power iCalconfigurator 15.3.6.2\install\E817FBF\api-ms-win-crt-math-l1-1-0.dll
Size 19.8KB
Processes 2420 (Porcal4.exe)
Type PE32 executable (DLL) (console) Intel 80386, for MS Windows
MD5 2fc94139ef2415f09d4019436c5893e1
SHA1 8239d3d10b2682553d5f927ce488e110f983f082
SHA256 8dda938588c7e2fbc36e0329b8a8d122f3bf363724dbf5e62fa205d9d5fb79a6
CRC32 FECCC71A
ssdeep 384:Yt1MCbM4Oe5grykfIgTmLCWthWkaPVRKU2h6wV:M6gMq5grxfInJ0Qh6G
Yara
  • PE_Header_Zero - PE File Signature
  • IsPE32 - (no description)
  • IsDLL - (no description)
  • UPX_Zero - UPX packed file
VirusTotal Search for analysis
Name a8b18c966a299ece_CloseIcon@325.png
Submit file
Filepath C:\Users\test22\AppData\Roaming\Dart Communications\Power iCalconfigurator 15.3.6.2\install\E817FBF\Images\CloseIcon@325.png
Size 2.8KB
Processes 2420 (Porcal4.exe)
Type PNG image data, 29 x 29, 8-bit/color RGBA, non-interlaced
MD5 b72322c495daed471e4ffc9338d11388
SHA1 56e3ed76cdd923c6a6297f999a109d170c2aa511
SHA256 a8b18c966a299ece5b2332f29e60ad78ef4f54b5ff449d2f7539dfb9b39f0b1c
CRC32 6BAC4D59
ssdeep 48:+/6DocieftI9G9f6A+FIDOWu0lDl+gm7QyTtctIInQSy6IVpqlnBcODd4/qQv:+SDZ/I09Da01l+gmkyTt6Hk8nTdw1
Yara
  • PNG_Format_Zero - PNG Format
VirusTotal Search for analysis
Name a26f009b27268e98_api-ms-win-core-console-l1-2-0.dll
Submit file
Filepath C:\Users\test22\AppData\Roaming\Dart Communications\Power iCalconfigurator 15.3.6.2\install\E817FBF\api-ms-win-core-console-l1-2-0.dll
Size 9.8KB
Processes 2420 (Porcal4.exe)
Type PE32 executable (DLL) (console) Intel 80386, for MS Windows
MD5 a9f107283820c201d83cd8ab83c25928
SHA1 fe58ee714dd4e63de92c9806a8e04c5d7fd10c7b
SHA256 a26f009b27268e98c0e06e49fe149d0cb872fd77a887e6247ec92ca6a5ccc01e
CRC32 5E098596
ssdeep 192:HtsWthW4068Ya5/R6t7sFZNqgeBZH6wBGf:H+WthW4aPVRKoFZNOhRE
Yara
  • PE_Header_Zero - PE File Signature
  • IsPE32 - (no description)
  • IsDLL - (no description)
  • UPX_Zero - UPX packed file
VirusTotal Search for analysis
Name 10c3c9d9708eabf1_Right.fencelayout
Submit file
Filepath C:\Users\test22\AppData\Roaming\Dart Communications\Power iCalconfigurator 15.3.6.2\install\E817FBF\Layouts\Right.fencelayout
Size 838.0B
Processes 2420 (Porcal4.exe)
Type XML 1.0 document, ASCII text, with CRLF line terminators
MD5 5967e5279df867dc4362edb9287bbd6e
SHA1 f0d77a8034c17e676cf779e8e6a82412eac71dde
SHA256 10c3c9d9708eabf1e761d67ceaf7bc04250af4db2ae3966d9063df43e5fd25df
CRC32 85A1C5CD
ssdeep 24:2dX8rPNKNq1fhv+VSYDLVSYjfGWSqLPvM:cX8rlAFIY3IYLC
Yara None matched
VirusTotal Search for analysis
Name ab44c66b8892e33a_FolderIcon@75-.png
Submit file
Filepath C:\Users\test22\AppData\Roaming\Dart Communications\Power iCalconfigurator 15.3.6.2\install\E817FBF\Images\FolderIcon@75-.png
Size 2.7KB
Processes 2420 (Porcal4.exe)
Type PNG image data, 12 x 10, 8-bit/color RGBA, non-interlaced
MD5 143b1b9624974eca70ad59f10369aeb2
SHA1 20f63c7c8d6cd13198018defcb5697d010f8b13d
SHA256 ab44c66b8892e33acaf7c6ef9660ab0cce9f9e3bf9ab089d0077968e2520d8c8
CRC32 640369BB
ssdeep 48:Y/6DocieftI9G9f6A+FIDOWu0lDl+gm7QyTtctIInQSy6IVpqlnBcODu86:YSDZ/I09Da01l+gmkyTt6Hk8nTuF
Yara
  • PNG_Format_Zero - PNG Format
VirusTotal Search for analysis
Name b86c4b06248456a0_FolderIcon@150.png
Submit file
Filepath C:\Users\test22\AppData\Roaming\Dart Communications\Power iCalconfigurator 15.3.6.2\install\E817FBF\Images\FolderIcon@150.png
Size 2.8KB
Processes 2420 (Porcal4.exe)
Type PNG image data, 24 x 21, 8-bit/color RGBA, non-interlaced
MD5 30f113ee6187822966212079e70524f8
SHA1 f2f5523c91d83c3e782374810f71026922eef533
SHA256 b86c4b06248456a08edb3e20341d1bfb0535c630bbef78bb9c5184ad5c4762a4
CRC32 7B755A53
ssdeep 48:X/6DocieftI9G9f6A+FIDOWu0lDl+gm7QyTtctIInQSy6IVpqlnBcODUO:XSDZ/I09Da01l+gmkyTt6Hk8nTD
Yara
  • PNG_Format_Zero - PNG Format
VirusTotal Search for analysis
Name a70ca03c17277057_CreateFence@175.png
Submit file
Filepath C:\Users\test22\AppData\Roaming\Dart Communications\Power iCalconfigurator 15.3.6.2\install\E817FBF\Images\CreateFence@175.png
Size 3.0KB
Processes 2420 (Porcal4.exe)
Type PNG image data, 28 x 26, 8-bit/color RGBA, non-interlaced
MD5 cf3d216360fec663cc0e97166058f192
SHA1 5d73fdff0f87ee4dc3dfc26737ea2c5958678d41
SHA256 a70ca03c172770577c217302087bd5fb1e495a009627c984fa896d276bf770a7
CRC32 02BCB3C2
ssdeep 48:+/6DocieftI9G9f6A+FIDOWu0lDl+gm7QyTtctIInQSy6IVpqlnBcODI3dUqH:+SDZ/I09Da01l+gmkyTt6Hk8nTEWqH
Yara
  • PNG_Format_Zero - PNG Format
VirusTotal Search for analysis
Name 492a22cdb96f03ea_RightDouble.fencelayout
Submit file
Filepath C:\Users\test22\AppData\Roaming\Dart Communications\Power iCalconfigurator 15.3.6.2\install\E817FBF\Layouts\RightDouble.fencelayout
Size 1.5KB
Processes 2420 (Porcal4.exe)
Type XML 1.0 document, ASCII text, with CRLF line terminators
MD5 606d602d263fbb884b17708be7381746
SHA1 c1f3757f077d9184519e72e0b0a1ebc20962b393
SHA256 492a22cdb96f03eaf2056460ab9ce3ccf691160148c165a72acec47b3700d682
CRC32 5FB98FB9
ssdeep 24:2dX8rsN9/Nq1fhv+VSYDLVSYjfeWSX+bJh/hv+VSYDLVSYjfeWSqLPj2:cX8rS91FIY3IYLmIY3IYLg
Yara None matched
VirusTotal Search for analysis
Name ec0720ae2519e6c6_NavigateUpIcon@225.png
Submit file
Filepath C:\Users\test22\AppData\Roaming\Dart Communications\Power iCalconfigurator 15.3.6.2\install\E817FBF\Images\NavigateUpIcon@225.png
Size 2.8KB
Processes 2420 (Porcal4.exe)
Type PNG image data, 25 x 29, 8-bit/color RGBA, non-interlaced
MD5 1a31b61a2a995d1b2a57cb70ea568296
SHA1 8d3d1d9248396e1959697b8ed37c5b7ffcd08d4e
SHA256 ec0720ae2519e6c6c37a35edf5122a06321fd32edd758ee7edeff604077f5cd8
CRC32 3FED2B80
ssdeep 48:Y/6DocieftI9G9f6A+FIDOWu0lDl+gm7QyTtctIInQSy6IVpqlnBcODdqlc+:YSDZ/I09Da01l+gmkyTt6Hk8nTM
Yara
  • PNG_Format_Zero - PNG Format
VirusTotal Search for analysis
Name b4f1328a4974431d_espanol.dxs
Submit file
Filepath C:\Users\test22\AppData\Roaming\Dart Communications\Power iCalconfigurator 15.3.6.2\install\E817FBF\sprache\espanol.dxs
Size 41.3KB
Processes 2420 (Porcal4.exe)
Type ISO-8859 text, with very long lines, with CRLF line terminators
MD5 e2d577e2a37d6f95e8d3a3251db0c156
SHA1 1a2a008bd5516d5c1f366a1033425a7cc0169665
SHA256 b4f1328a4974431d387b6777d748868e4522305ac1af733f0614b13697378ff8
CRC32 AA746E9A
ssdeep 768:com7tGvGJjbCHx+TPt9t5EFLAnM3isk9C79bV/q3DzUANuI6JNLnv9zTqrCyH5SY:com7tGvwjbCHx+TPtv5EFj3isk9wbV/6
Yara None matched
VirusTotal Search for analysis
Name aab477da66fb2e9c_d15.ico
Submit file
Filepath C:\Users\test22\AppData\Roaming\Dart Communications\Power iCalconfigurator 15.3.6.2\install\E817FBF\icons\New Blue\d15.ico
Size 894.0B
Processes 2420 (Porcal4.exe)
Type MS Windows icon resource - 1 icon, 16x16, 24 bits/pixel
MD5 4e5ab0201f90c7fbb35d4b12b9308feb
SHA1 52fd34dba1f88e4fcc00c0e00e132f7fd118ef7d
SHA256 aab477da66fb2e9cc4288b6a2a2813fde3399f16d4ec9fdca745074d2966ac30
CRC32 3DA6804D
ssdeep 24:t5OegVMR+0CVmGvUR0dn/VYTTTTTTTTTTTT2:yVMHQUR0dn9YTTTTTTTTTTTT2
Yara None matched
VirusTotal Search for analysis
Name a7d8c9ce5cdc7f95_TopBottom.fencelayout
Submit file
Filepath C:\Users\test22\AppData\Roaming\Dart Communications\Power iCalconfigurator 15.3.6.2\install\E817FBF\Layouts\TopBottom.fencelayout
Size 1.4KB
Processes 2420 (Porcal4.exe)
Type XML 1.0 document, ASCII text, with CRLF line terminators
MD5 1c53b20b06486de9227f9d31fd0eac89
SHA1 1df60e9621055d1bb61cb5f2c7388813cc8d54ec
SHA256 a7d8c9ce5cdc7f956275b42df6b4bc82e002f6509d7c7cd66bf94b4f147ee6d3
CRC32 A885C8B4
ssdeep 24:2dX87NIN5u61fhvPVSYDLVSYVUWSq92/hvrVSYDLVSYVUWSqLPvM:cX8pGTIY3IY8IY3IY+
Yara None matched
VirusTotal Search for analysis
Name 5c3f7ad21540d390_api-ms-win-core-file-l1-1-0.dll
Submit file
Filepath C:\Users\test22\AppData\Roaming\Dart Communications\Power iCalconfigurator 15.3.6.2\install\E817FBF\api-ms-win-core-file-l1-1-0.dll
Size 12.8KB
Processes 2420 (Porcal4.exe)
Type PE32 executable (DLL) (console) Intel 80386, for MS Windows
MD5 5665da0c939ccfc210a032c0c68e13bf
SHA1 5aa4f221c20ef2abab2dc680bd9ec9a732540c6e
SHA256 5c3f7ad21540d39002c617777542adc1f062c656527e04293deda777f40a4d67
CRC32 0F96EE14
ssdeep 192:FCYYPvVX8rFTsdWthWu068Ya5/R6t7sM/BZHlp:FC7PvVXvWthWuaPVRKoM5hb
Yara
  • PE_Header_Zero - PE File Signature
  • IsPE32 - (no description)
  • IsDLL - (no description)
  • UPX_Zero - UPX packed file
VirusTotal Search for analysis
Name d54f5ffdc7f5f402_FencesSmall@200.png
Submit file
Filepath C:\Users\test22\AppData\Roaming\Dart Communications\Power iCalconfigurator 15.3.6.2\install\E817FBF\Images\FencesSmall@200.png
Size 2.7KB
Processes 2420 (Porcal4.exe)
Type PNG image data, 32 x 32, 8-bit/color RGBA, non-interlaced
MD5 3f7469e7a2239f572fa90a9eb78df0fe
SHA1 5d9d3923948f904fda297ac8262058f5150389c2
SHA256 d54f5ffdc7f5f402d67f08ed920287a5d22e265a92306bb2ecb1bc1a91ebf46b
CRC32 87661197
ssdeep 48:dok+01MCUCWeqEOgsXoGngVKeRHabAkSvOwCyiFAHlqNDJfrE7wkQFAluHD7:r6CV63oagVJR8tSWhFAHlqpJo7cHv
Yara
  • PNG_Format_Zero - PNG Format
VirusTotal Search for analysis
Name 792436b5d993f4bb_CreateFolderFence@200.png
Submit file
Filepath C:\Users\test22\AppData\Roaming\Dart Communications\Power iCalconfigurator 15.3.6.2\install\E817FBF\Images\CreateFolderFence@200.png
Size 3.0KB
Processes 2420 (Porcal4.exe)
Type PNG image data, 32 x 30, 8-bit/color RGBA, non-interlaced
MD5 ff0997ae7d85ed6ba077d1b89ce65003
SHA1 c53f00d39c550d4e78166d155c9e70b2dbf7011b
SHA256 792436b5d993f4bb2c885a9eb781038849c38c5d369289d941f889496d0289b4
CRC32 C6A36742
ssdeep 48:H/6DocieftI9G9f6A+FIDOWu0lDl+gm7QyTtctIInQSy6IVpqlnBcODi50:HSDZ/I09Da01l+gmkyTt6Hk8nTi+
Yara
  • PNG_Format_Zero - PNG Format
VirusTotal Search for analysis
Name f8eeefc462680884_api-ms-win-core-string-l1-1-0.dll
Submit file
Filepath C:\Users\test22\AppData\Roaming\Dart Communications\Power iCalconfigurator 15.3.6.2\install\E817FBF\api-ms-win-core-string-l1-1-0.dll
Size 9.3KB
Processes 2420 (Porcal4.exe)
Type PE32 executable (DLL) (console) Intel 80386, for MS Windows
MD5 ab807e67cd4dc5d037d0409913d8f80d
SHA1 cee9c8eda09ea4a32514a2a64a91b8e7df763c83
SHA256 f8eeefc46268088461ec2b37fa09af995052d721542d0aa99caf3f3db1058f73
CRC32 6FB333E7
ssdeep 192:UGyMvpWthW/m068Ya5/R6t7Y8DKBZHak0aX:UGyMvpWthWOaPVRKUk4hdX
Yara
  • PE_Header_Zero - PE File Signature
  • IsPE32 - (no description)
  • IsDLL - (no description)
  • UPX_Zero - UPX packed file
VirusTotal Search for analysis
Name 83b1f6f50c970a0c_Inital1.fencelayout
Submit file
Filepath C:\Users\test22\AppData\Roaming\Dart Communications\Power iCalconfigurator 15.3.6.2\install\E817FBF\Layouts\Inital1.fencelayout
Size 1.1KB
Processes 2420 (Porcal4.exe)
Type XML 1.0 document, ASCII text, with CRLF line terminators
MD5 3a719c1401876b5a9ff7e60b44760cad
SHA1 3a9ddcb205686a6475b693468a8ce9a39784e58f
SHA256 83b1f6f50c970a0c1a9b251c9815ef2f50dd615a9172b8be1b28398ba5e93e5e
CRC32 F78BC021
ssdeep 24:2dX8ANMN5m06QfhvH8VSYDLVSYjzWdqLPvM:cX8uyqIY3IYy
Yara None matched
VirusTotal Search for analysis
Name 96620a8e5b812281_msvcp140_2.dll
Submit file
Filepath C:\Users\test22\AppData\Roaming\Dart Communications\Power iCalconfigurator 15.3.6.2\install\E817FBF\msvcp140_2.dll
Size 160.3KB
Processes 2420 (Porcal4.exe)
Type PE32 executable (DLL) (console) Intel 80386, for MS Windows
MD5 107f84fe5df102ee54282003f38a1e4c
SHA1 6a0b699bf7b4a0a73f3526dd89f9b7133a644745
SHA256 96620a8e5b812281de3f702bbebb8a788425952bac3b8f876c526dc18f00ef9f
CRC32 0C8D88E8
ssdeep 3072:gZcg1ocb42/lCmyPieky8DbRhn0WoGgvQHwRvf567d3WoUiD0nO1O8N:gZOc8myP/u0h9f56JmjiMO08N
Yara
  • PE_Header_Zero - PE File Signature
  • OS_Processor_Check_Zero - OS Processor Check
  • IsPE32 - (no description)
  • IsDLL - (no description)
  • UPX_Zero - UPX packed file
VirusTotal Search for analysis
Name 0654e153cc5da69e_d9a.ico
Submit file
Filepath C:\Users\test22\AppData\Roaming\Dart Communications\Power iCalconfigurator 15.3.6.2\install\E817FBF\icons\Classic\d9a.ico
Size 1.4KB
Processes 2420 (Porcal4.exe)
Type MS Windows icon resource - 1 icon, 16x16, 255 colors, 8 bits/pixel
MD5 37f43ebc1115be77dec7062925095c6b
SHA1 e4c02a1649a5b24d6afb514b3155dc8da1e2be9a
SHA256 0654e153cc5da69efa3fbc777107fad9899965af54d58095c32c204fac520928
CRC32 4962FA3E
ssdeep 6:dzM/AGo3WlvLmXRoVnVnDnVnRVnR1tlNJ4NU9Jw/tnn:dz8A94KXRoVVDVRVR3lNq2mn
Yara None matched
VirusTotal Search for analysis
Name 7cda5b70c054d557_d19a.ico
Submit file
Filepath C:\Users\test22\AppData\Roaming\Dart Communications\Power iCalconfigurator 15.3.6.2\install\E817FBF\icons\Classic\d19a.ico
Size 1.4KB
Processes 2420 (Porcal4.exe)
Type MS Windows icon resource - 1 icon, 16x16, 255 colors, 8 bits/pixel
MD5 c1cda8d0c4cd6ba2c43fe49df442c34f
SHA1 a567d4188ec259a0818933abce602aba6db4ca8f
SHA256 7cda5b70c054d557e4e02d1e212322b05a7f3e85043aa7055758732fc84842a6
CRC32 E37785E5
ssdeep 6:dz4mY3OSl5qI3u9DpXRoVnVlRkinnLnjLDmj7gLuWDFwV/tnn:dzZY3OW5N3a1XRoVV3Hnm/gLucFwTn
Yara None matched
VirusTotal Search for analysis
Name 83ec8fe8adf170ac_d16.ico
Submit file
Filepath C:\Users\test22\AppData\Roaming\Dart Communications\Power iCalconfigurator 15.3.6.2\install\E817FBF\icons\New Blue\d16.ico
Size 894.0B
Processes 2420 (Porcal4.exe)
Type MS Windows icon resource - 1 icon, 16x16, 24 bits/pixel
MD5 82b502d70bc2542b04a9d85d2997bdab
SHA1 121630aabc96b876f2ffe074f1ed1a34c22cb8d7
SHA256 83ec8fe8adf170ac05f88a9c831bae6fe447991398ac147a857064fe751f2712
CRC32 32E377AE
ssdeep 12:t4923lJd94aMS/sDY76VCn3RIk2R9gzZXqqzsTTTTTTTTTTTT2:t5VhPpstk3RIk2Ra1nYTTTTTTTTTTTT2
Yara None matched
VirusTotal Search for analysis
Name b8cc20183820322a_api-ms-win-core-rtlsupport-l1-1-0.dll
Submit file
Filepath C:\Users\test22\AppData\Roaming\Dart Communications\Power iCalconfigurator 15.3.6.2\install\E817FBF\api-ms-win-core-rtlsupport-l1-1-0.dll
Size 9.3KB
Processes 2420 (Porcal4.exe)
Type PE32 executable (DLL) (console) Intel 80386, for MS Windows
MD5 ef0cb2b988bb6f6d444e4feb5e96c4c1
SHA1 fe86b74174d0d30d6ce565da0a6003ed00aca7e1
SHA256 b8cc20183820322a298cc782ed86d97143a651aa11d8bf30038764d9398e75b4
CRC32 0A44FC2B
ssdeep 96:n/PPG0EWthWwO70EuL638yZfaQCiUkm6ybK7Yba1aD3JUfhdyEi7ZHeE7fh2esQ:vGlWthWR068Ya5/R6t7Yug9BZHvhx
Yara
  • PE_Header_Zero - PE File Signature
  • IsPE32 - (no description)
  • IsDLL - (no description)
  • UPX_Zero - UPX packed file
VirusTotal Search for analysis
Name c4c120a7770537bc_msvcp140.dll
Submit file
Filepath C:\Users\test22\AppData\Roaming\Dart Communications\Power iCalconfigurator 15.3.6.2\install\E817FBF\msvcp140.dll
Size 424.3KB
Processes 2420 (Porcal4.exe)
Type PE32 executable (DLL) (console) Intel 80386, for MS Windows
MD5 a1f7dafae09c45a40a57e32c0ae4ad8a
SHA1 e0cbdce0f806d3784d7dd4cb8dc738969a1803bb
SHA256 c4c120a7770537bc50f0c9f6705d8ddd5111461427deaedf6c380da3feb08660
CRC32 4904F1B0
ssdeep 12288:DgU0BGzePo6+J+4P0xYv7IQgihUgiW6QR7t5s03Ooc8dHkC2esMoWKO:R01Po6+J+dxYv7IQgR03Ooc8dHkC2e5H
Yara
  • PE_Header_Zero - PE File Signature
  • OS_Processor_Check_Zero - OS Processor Check
  • IsPE32 - (no description)
  • IsDLL - (no description)
  • UPX_Zero - UPX packed file
  • Win32_Trojan_Gen_1_0904B0_Zero - Win32 Trojan Emotet
VirusTotal Search for analysis
Name e8178172cb828054_ConfigIcon@100.png
Submit file
Filepath C:\Users\test22\AppData\Roaming\Dart Communications\Power iCalconfigurator 15.3.6.2\install\E817FBF\Images\ConfigIcon@100.png
Size 483.0B
Processes 2420 (Porcal4.exe)
Type PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced
MD5 23d34cfd73e18438d7a352fc58008a67
SHA1 38c6158ed085dcfa9144a3f8ff3fcb801a10ba1f
SHA256 e8178172cb8280545c3e115b09e14cd42b04910018758f7d46959469f11c2ade
CRC32 F81B7555
ssdeep 12:6v/78/jyQWWI6F8GV57qKbW3HwB23t2RgojP1JktSaLFcUTojl:ZyQW4FhhW3K292qojEtpjoh
Yara
  • PNG_Format_Zero - PNG Format
VirusTotal Search for analysis
Name 40830b80d1000237_d6a.ico
Submit file
Filepath C:\Users\test22\AppData\Roaming\Dart Communications\Power iCalconfigurator 15.3.6.2\install\E817FBF\icons\New Blue\d6a.ico
Size 894.0B
Processes 2420 (Porcal4.exe)
Type MS Windows icon resource - 1 icon, 16x16, 24 bits/pixel
MD5 8982acaf7e8913d4f451d333d9915c76
SHA1 231ddd3ddabb65bf33c44618cba221124a45786c
SHA256 40830b80d100023728f9052694352b0692dbfc82516d0336d38eaa9a460b8a76
CRC32 6330494B
ssdeep 12:t47v4Iq1mHbIvLwRgo5tuGgJRiG3vgCctZrTeSGg0M:tSzBHALEttORNcTrKw
Yara None matched
VirusTotal Search for analysis
Name 623fac572ee4ad97_DropdownIcon@100.png
Submit file
Filepath C:\Users\test22\AppData\Roaming\Dart Communications\Power iCalconfigurator 15.3.6.2\install\E817FBF\Images\DropdownIcon@100.png
Size 2.8KB
Processes 2420 (Porcal4.exe)
Type PNG image data, 9 x 9, 8-bit/color RGBA, non-interlaced
MD5 6ca4919a08209da19e7ff80ac83f1747
SHA1 76df51a10e5876a242395851a536c72ce8241474
SHA256 623fac572ee4ad9709ecfdc7e070b1bd40946467a3917d725724c88eef1b1ab8
CRC32 D9BC82EA
ssdeep 48:m/6DocieftI9G9f6A+FIDOWu0lDl+gm7QyTtctIInQSy6IVpqlnBcOD+U:mSDZ/I09Da01l+gmkyTt6Hk8nTJ
Yara
  • PNG_Format_Zero - PNG Format
VirusTotal Search for analysis
Name e24ac3baa193e797_FolderIcon@125.png
Submit file
Filepath C:\Users\test22\AppData\Roaming\Dart Communications\Power iCalconfigurator 15.3.6.2\install\E817FBF\Images\FolderIcon@125.png
Size 2.8KB
Processes 2420 (Porcal4.exe)
Type PNG image data, 20 x 17, 8-bit/color RGBA, non-interlaced
MD5 51be8e2a8cea403bf7ebe50b1b8fbcf9
SHA1 f115206fbb3c7297edac0e9d6ac9a12f9de14031
SHA256 e24ac3baa193e79704edc1e4f260a30134ae6e50c8931654361693e831c09c15
CRC32 0E405647
ssdeep 48:7/6DocieftI9G9f6A+FIDOWu0lDl+gm7QyTtctIInQSy6IVpqlnBcODwc:7SDZ/I09Da01l+gmkyTt6Hk8nTJ
Yara
  • PNG_Format_Zero - PNG Format
VirusTotal Search for analysis
Name 1c3471860056bf7b_DropdownIcon@250.png
Submit file
Filepath C:\Users\test22\AppData\Roaming\Dart Communications\Power iCalconfigurator 15.3.6.2\install\E817FBF\Images\DropdownIcon@250.png
Size 2.8KB
Processes 2420 (Porcal4.exe)
Type PNG image data, 23 x 23, 8-bit/color RGBA, non-interlaced
MD5 c48e5a35301f4d4cf0424189a4aa69af
SHA1 d5aa219e74ac97696016cadd320015bf28e12f7b
SHA256 1c3471860056bf7baf2ac697655956c6565913cf0cdae92bfe709784a948471d
CRC32 87FE14B2
ssdeep 48:b/6DocieftI9G9f6A+FIDOWu0lDl+gm7QyTtctIInQSy6IVpqlnBcODfpz:bSDZ/I09Da01l+gmkyTt6Hk8nTfR
Yara
  • PNG_Format_Zero - PNG Format
VirusTotal Search for analysis
Name e1bc8f5417df406d_FolderIcon@200.png
Submit file
Filepath C:\Users\test22\AppData\Roaming\Dart Communications\Power iCalconfigurator 15.3.6.2\install\E817FBF\Images\FolderIcon@200.png
Size 2.8KB
Processes 2420 (Porcal4.exe)
Type PNG image data, 32 x 29, 8-bit/color RGBA, non-interlaced
MD5 1dadc131245d758b45712de6ce222c45
SHA1 2569ff0a80340dc3d17b397e6955442d96712827
SHA256 e1bc8f5417df406d99324be7bde33689a42cd527eebf44477d374063b3e839eb
CRC32 FBD2E9A0
ssdeep 48:A/6DocieftI9G9f6A+FIDOWu0lDl+gm7QyTtctIInQSy6IVpqlnBcODBS+:ASDZ/I09Da01l+gmkyTt6Hk8nTb
Yara
  • PNG_Format_Zero - PNG Format
VirusTotal Search for analysis
Name 32ac9c9a7981cbd8_API-MS-Win-core-xstate-l2-1-0.dll
Submit file
Filepath C:\Users\test22\AppData\Roaming\Dart Communications\Power iCalconfigurator 15.3.6.2\install\E817FBF\API-MS-Win-core-xstate-l2-1-0.dll
Size 9.3KB
Processes 2420 (Porcal4.exe)
Type PE32 executable (DLL) (console) Intel 80386, for MS Windows
MD5 c6d1a1159e1df20726bdb54a06b245cc
SHA1 ae424c1bdbbcd20b31f2ed4e6e2bb1e0bd83fb3c
SHA256 32ac9c9a7981cbd858197bc7220f30c39bada26eb3e1c06d235cbfc48f321216
CRC32 C6D6071F
ssdeep 96:+Qidf5bZEWthWw3e0EuL638yZfaQCiUkm6ybK7syJjja3JUfhdyEi7ZHeEiffa:of5b6WthW3068Ya5/R6t7sk+BZHoC
Yara
  • PE_Header_Zero - PE File Signature
  • IsPE32 - (no description)
  • IsDLL - (no description)
  • UPX_Zero - UPX packed file
VirusTotal Search for analysis
Name f644c1fe8312717f_NavigateUpIcon@175.png
Submit file
Filepath C:\Users\test22\AppData\Roaming\Dart Communications\Power iCalconfigurator 15.3.6.2\install\E817FBF\Images\NavigateUpIcon@175.png
Size 2.8KB
Processes 2420 (Porcal4.exe)
Type PNG image data, 19 x 22, 8-bit/color RGBA, non-interlaced
MD5 55890a93096fb398c978191846cfecc7
SHA1 9219cf9b7ea04367610b27ebe602bf985160d184
SHA256 f644c1fe8312717f43cc0b3a322c593b2d7ae32b37a82420f7e55e1c47bfbfd8
CRC32 AFA3955C
ssdeep 48:X/6DocieftI9G9f6A+FIDOWu0lDl+gm7QyTtctIInQSy6IVpqlnBcODww1:XSDZ/I09Da01l+gmkyTt6Hk8nTD1
Yara
  • PNG_Format_Zero - PNG Format
VirusTotal Search for analysis
Name b861f21258e40495_CloseIcon@300.png
Submit file
Filepath C:\Users\test22\AppData\Roaming\Dart Communications\Power iCalconfigurator 15.3.6.2\install\E817FBF\Images\CloseIcon@300.png
Size 2.8KB
Processes 2420 (Porcal4.exe)
Type PNG image data, 27 x 27, 8-bit/color RGBA, non-interlaced
MD5 54b4f86374ed83c3f4871f386273ded2
SHA1 96d0440fb5d57c314c5f87248d57768007a67808
SHA256 b861f21258e40495e03ca369e78759d26611a1fdd814d8b55aa05937b6d7e0c6
CRC32 4D8CFB5F
ssdeep 48:r/6DocieftI9G9f6A+FIDOWu0lDl+gm7QyTtctIInQSy6IVpqlnBcODRQc:rSDZ/I09Da01l+gmkyTt6Hk8nTRx
Yara
  • PNG_Format_Zero - PNG Format
VirusTotal Search for analysis
Name c4038ef553600c72_d9a.ico
Submit file
Filepath C:\Users\test22\AppData\Roaming\Dart Communications\Power iCalconfigurator 15.3.6.2\install\E817FBF\icons\New Blue\d9a.ico
Size 894.0B
Processes 2420 (Porcal4.exe)
Type MS Windows icon resource - 1 icon, 16x16, 24 bits/pixel
MD5 49f086e64974989ece8b3ccf167d7a04
SHA1 559286ec8fcf374094b3195989213c7a2c035868
SHA256 c4038ef553600c72f4da7f17a083c945fd36ff6c19f196037c7015efdbba617f
CRC32 3430181D
ssdeep 12:t47v4Ihji41mwurvcpgJPRw8LgvRTA1COpjrg0M:tSzh2DwujiGfYR/Oa
Yara None matched
VirusTotal Search for analysis
Name 316b67841dba6c73_PagerBulletS.png
Submit file
Filepath C:\Users\test22\AppData\Roaming\Dart Communications\Power iCalconfigurator 15.3.6.2\install\E817FBF\Images\PagerBulletS.png
Size 2.9KB
Processes 2420 (Porcal4.exe)
Type PNG image data, 22 x 43, 8-bit/color RGBA, non-interlaced
MD5 2719683b8dba819f2e6bd9e9b7307f1c
SHA1 6cbac17ebf8b56489ad8b8c458dd618b2788512a
SHA256 316b67841dba6c73097d0d50d1b454fd80b6aac86fa0fe15f9b514d65a5bb66a
CRC32 ECA2EA75
ssdeep 48:+/6DocieftI9G9f6A+FIDOWu0lDl+gm7QyTtctIInQSy6IVpqlnBcOD1K:+SDZ/I09Da01l+gmkyTt6Hk8nT1K
Yara
  • PNG_Format_Zero - PNG Format
VirusTotal Search for analysis
Name fa8cb25c599e083a_libftw2.dll
Submit file
Filepath C:\Users\test22\AppData\Roaming\Dart Communications\Power iCalconfigurator 15.3.6.2\install\E817FBF\libftw2.dll
Size 1.4MB
Processes 2420 (Porcal4.exe)
Type PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
MD5 21022f1a4d1f0706b5f8f489a0590598
SHA1 9787b67519e7a6ca9fc31e0cc5c73bee54cbd393
SHA256 fa8cb25c599e083a944ce9971031cd552e18e4bc5431222948c3580e7789976a
CRC32 B65088D9
ssdeep 24576:7vfNPzSn3/hMcaagZQ17+t6PxyQt37nez/Hz/3z/6z/uz/Hz/oz/FSSADDqPddLE:MniVjZQ1FP3MEbrqGAvInuMcRc/s+koA
Yara
  • ASPack_Zero - ASPack packed file
  • Malicious_Packer_Zero - Malicious Packer
  • PE_Header_Zero - PE File Signature
  • OS_Processor_Check_Zero - OS Processor Check
  • IsPE32 - (no description)
  • Win32_Trojan_Gen_2_0904B0_Zero - Win32 Trojan Gen
  • IsDLL - (no description)
  • Malicious_Library_Zero - Malicious_Library
  • UPX_Zero - UPX packed file
  • Win32_Trojan_Gen_1_0904B0_Zero - Win32 Trojan Emotet
VirusTotal Search for analysis
Name f3460fe8d9827426_d3a.ico
Submit file
Filepath C:\Users\test22\AppData\Roaming\Dart Communications\Power iCalconfigurator 15.3.6.2\install\E817FBF\icons\Classic\d3a.ico
Size 1.4KB
Processes 2420 (Porcal4.exe)
Type MS Windows icon resource - 1 icon, 16x16, 255 colors, 8 bits/pixel
MD5 2e7c24817b7b1d87996d89d8d0cdc332
SHA1 7d8a1234c50148f4e816e670fc1c05c57ee950e6
SHA256 f3460fe8d98274268bb7f5c54013bb655f96e961087ca7ca70036f7b1ae7562e
CRC32 B1A9CD34
ssdeep 6:dzM/A7o3WlvLmXBoVnVnDnVnRRVnR11NtpJgDhIR/tnn:dz8AM4KXBoVVDVRnRvNKDhCn
Yara None matched
VirusTotal Search for analysis
Name 9f8729ac49e0ccea_zlibwapi.dll
Submit file
Filepath C:\Users\test22\AppData\Roaming\Dart Communications\Power iCalconfigurator 15.3.6.2\install\E817FBF\zlibwapi.dll
Size 138.0KB
Processes 2420 (Porcal4.exe)
Type PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
MD5 54789344b07bed58e43851eca47e2b12
SHA1 93c561365bc7f1cbb5385d0323ed81044a6ec276
SHA256 9f8729ac49e0ccea86fe3b1a9b2c3fae9986ecd09db92853e7a588dbda85bf90
CRC32 B5C19D9A
ssdeep 3072:rjdSKCC+FzNehv8Rqiq9+yVojaylvjTBfxvA:rjdS8czEuqFVojzlvjTBJ
Yara
  • PE_Header_Zero - PE File Signature
  • OS_Processor_Check_Zero - OS Processor Check
  • IsPE32 - (no description)
  • IsDLL - (no description)
  • Malicious_Library_Zero - Malicious_Library
  • UPX_Zero - UPX packed file
VirusTotal Search for analysis
Name f6456315250f7c9a_CloseIcon@350.png
Submit file
Filepath C:\Users\test22\AppData\Roaming\Dart Communications\Power iCalconfigurator 15.3.6.2\install\E817FBF\Images\CloseIcon@350.png
Size 2.9KB
Processes 2420 (Porcal4.exe)
Type PNG image data, 31 x 31, 8-bit/color RGBA, non-interlaced
MD5 7ff957407851bb63beccf2a9aeec387e
SHA1 669bf4dc949c3558679084b8a2c057bf7ac036ad
SHA256 f6456315250f7c9a216a9d8b4c4e2bebedd4b364ab88f560744a0e460bcb262f
CRC32 E681B36E
ssdeep 48:l/6DocieftI9G9f6A+FIDOWu0lDl+gm7QyTtctIInQSy6IVpqlnBcODUN3pkX1:lSDZ/I09Da01l+gmkyTt6Hk8nTU5SX1
Yara
  • PNG_Format_Zero - PNG Format
VirusTotal Search for analysis
Name f1ba98850febcb05_FolderIcon@175.png
Submit file
Filepath C:\Users\test22\AppData\Roaming\Dart Communications\Power iCalconfigurator 15.3.6.2\install\E817FBF\Images\FolderIcon@175.png
Size 2.8KB
Processes 2420 (Porcal4.exe)
Type PNG image data, 28 x 25, 8-bit/color RGBA, non-interlaced
MD5 c7e1cba803c1106898725ee5b45c816c
SHA1 e85d5b8d72369df426586ea9ba20af5b648f6537
SHA256 f1ba98850febcb053a1cb58aaa2268017c1d36105089e03bc5fa8e1435391ab4
CRC32 8CB66493
ssdeep 48:uO/6DocieftI9G9f6A+FIDOWu0lDl+gm7QyTtctIInQSy6IVpqlnBcODPHXq:uOSDZ/I09Da01l+gmkyTt6Hk8nT/q
Yara
  • PNG_Format_Zero - PNG Format
VirusTotal Search for analysis
Name 68349b5df0219b1f_adv.msi
Submit file
Filepath C:\Users\test22\AppData\Roaming\Dart Communications\Power iCalconfigurator 15.3.6.2\install\E817FBF\adv.msi
Size 2.1MB
Processes 2420 (Porcal4.exe)
Type Composite Document File V2 Document, Little Endian, Os: Windows, Version 10.0, MSI Installer, Last Printed: Fri Dec 11 11:47:44 2009, Create Time/Date: Fri Dec 11 11:47:44 2009, Last Saved Time/Date: Fri Sep 18 14:06:51 2020, Security: 0, Code page: 1252, Revision Number: {135D120F-59DB-431B-B749-687213E6BBF3}, Number of Words: 8, Subject: Power iCalconfigurator, Author: Dart Communications, Name of Creating Application: Advanced Installer 18.7 build 0a7fdead, Template: ;1033, Title: Installation Database, Keywords: Installer, MSI, Database, Number of Pages: 200
MD5 f57d90ca47cdf25daa0bbc00bc18429f
SHA1 59bdeecfe04a153fbd82286de439b82841716acc
SHA256 68349b5df0219b1f6a32c319ead4c545b42280bcfc53c4239934e2fe08b4235a
CRC32 BF3D47DD
ssdeep 49152:t6RYqEUl8VlvfWAC/fQhksQQNgXAo1sVzhly+PkfsJJ10FRzVT6ajBK+ByqV4TGU:cYqEkzACfs01sVNFajM+
Yara
  • Malicious_Packer_Zero - Malicious Packer
  • Antivirus - Contains references to security software
  • Generic_Malware_Zero - Generic Malware
  • OS_Processor_Check_Zero - OS Processor Check
  • Win32_Trojan_Gen_2_0904B0_Zero - Win32 Trojan Gen
  • Malicious_Library_Zero - Malicious_Library
  • Microsoft_Office_File_Zero - Microsoft Office File
VirusTotal Search for analysis
Name 96d726749caa2b47_d8a.ico
Submit file
Filepath C:\Users\test22\AppData\Roaming\Dart Communications\Power iCalconfigurator 15.3.6.2\install\E817FBF\icons\Classic\d8a.ico
Size 1.4KB
Processes 2420 (Porcal4.exe)
Type MS Windows icon resource - 1 icon, 16x16, 255 colors, 8 bits/pixel
MD5 711ece0b46b0395181f9e67424615cb8
SHA1 79f6764317560fba9b1c43c953ff303b376699fc
SHA256 96d726749caa2b47c38ae131ab03ebb1d26a134711ef108ae0d799112b5d6540
CRC32 9D0E5ED1
ssdeep 6:dz4Kc363+5KcORu9DpXBoVnVnDnVnRRTnRR6TfzsOAL7TlzuwgIR/tnn:dzFc363+5KcT1XBoVVDVRhR8TLsjNICn
Yara None matched
VirusTotal Search for analysis
Name 7fa953caf36189c2_d5.ico
Submit file
Filepath C:\Users\test22\AppData\Roaming\Dart Communications\Power iCalconfigurator 15.3.6.2\install\E817FBF\icons\Classic\d5.ico
Size 1.4KB
Processes 2420 (Porcal4.exe)
Type MS Windows icon resource - 1 icon, 16x16, 8 bits/pixel
MD5 66107441f68a94f595755d89a7356567
SHA1 95c4b27f691580fc166299c7956c852e5fd8465c
SHA256 7fa953caf36189c29c807fdeba9eaa58dd24ae7a8159356fd2cce3020734e5dc
CRC32 8F7ECAC2
ssdeep 6:UZxMcE2jS4Tfl+46EcAOBNHlfmXpxPEjWpQe3HfmM/tH5n:UZtu4TQ46DAOLHl+XDPnpQc/tZn
Yara None matched
VirusTotal Search for analysis
Name dd1f50061d054984_d10a.ico
Submit file
Filepath C:\Users\test22\AppData\Roaming\Dart Communications\Power iCalconfigurator 15.3.6.2\install\E817FBF\icons\Classic\d10a.ico
Size 1.4KB
Processes 2420 (Porcal4.exe)
Type MS Windows icon resource - 1 icon, 16x16, 255 colors, 8 bits/pixel
MD5 29b8a8dffeb88ab30eb7171bbcc85f4a
SHA1 acd15d528bab70a0de48151914e752beffbc9972
SHA256 dd1f50061d054984ed450b890b3e3a00acc4b13fa749720593d470dd7ff693f5
CRC32 9A0E1C71
ssdeep 6:dzMQjE7oilbhlxgmXBoVnVlRkinRnBnRnNgN1/3Or+ri/KY/tnn:dzzE1lxXBoVV35jyN1/e+ri/hn
Yara None matched
VirusTotal Search for analysis
Name bd19f20dcaa5775f_d5.ico
Submit file
Filepath C:\Users\test22\AppData\Roaming\Dart Communications\Power iCalconfigurator 15.3.6.2\install\E817FBF\icons\New Blue\d5.ico
Size 894.0B
Processes 2420 (Porcal4.exe)
Type MS Windows icon resource - 1 icon, 16x16, 24 bits/pixel
MD5 9309542b48a75697b8b6fd12c1a4db26
SHA1 ee9fd855dc4ca786d5b2db4c2789386514a829a2
SHA256 bd19f20dcaa5775f3eb6f6abdb6efeeb38f4c709748bf8b73b9ba1671fcb7b38
CRC32 8A66EDCF
ssdeep 12:t492lhkF4vf1rS7Ug6FpXi8E9iAWhvewOH/83ZgqzsTTTTTTTTTTTT2:t5lhem9FpwwLep03XYTTTTTTTTTTTT2
Yara None matched
VirusTotal Search for analysis
Name e386e03c7d3bedd2_d5a.ico
Submit file
Filepath C:\Users\test22\AppData\Roaming\Dart Communications\Power iCalconfigurator 15.3.6.2\install\E817FBF\icons\Classic\d5a.ico
Size 1.4KB
Processes 2420 (Porcal4.exe)
Type MS Windows icon resource - 1 icon, 16x16, 255 colors, 8 bits/pixel
MD5 0d96313b7caeb3f5cbe7469e3e56fa1a
SHA1 b559e618b55a4d7343ec0f9f56749566fe96c387
SHA256 e386e03c7d3bedd27d04040d194185aca0882918626c8bfb051988c6dbd58c4c
CRC32 34DAB300
ssdeep 6:dzM/Af9Xl1lvLmXBoVnVnDnVnRRVnR11NTpWDyhIR/tnn:dz8A1XlnKXBoVVDVRnRvN8yhCn
Yara None matched
VirusTotal Search for analysis
Name 4c46ca6fb2b662b5_d5a.ico
Submit file
Filepath C:\Users\test22\AppData\Roaming\Dart Communications\Power iCalconfigurator 15.3.6.2\install\E817FBF\icons\New Blue\d5a.ico
Size 894.0B
Processes 2420 (Porcal4.exe)
Type MS Windows icon resource - 1 icon, 16x16, 24 bits/pixel
MD5 a033a9e27c94a77e4f7878a161a3336d
SHA1 c8f795ffd24bdbbfdb4a0b657e4f1c0bdbc82956
SHA256 4c46ca6fb2b662b56f7bb004b59cdab5faed7b65bcd2ee85a12f4023d5db92d5
CRC32 E02FA4C8
ssdeep 12:t47v4IhkF41m+f1vVS7Ug4VVPi8i9iAWhv5OCcEy83Zg0M:tSzheDER7LP+wLlcEX3+
Yara None matched
VirusTotal Search for analysis
Name ec978319c4019796_czech.dxs
Submit file
Filepath C:\Users\test22\AppData\Roaming\Dart Communications\Power iCalconfigurator 15.3.6.2\install\E817FBF\sprache\czech.dxs
Size 38.2KB
Processes 2420 (Porcal4.exe)
Type Non-ISO extended-ASCII text, with CRLF line terminators
MD5 815927ac7bd40cda62cd4d721f543d50
SHA1 5eae21fd2fa73439327fb9c963f4dddbd033a147
SHA256 ec978319c4019796a71717538938b77375aaf5aacf9f46d4c62c99048b1b45a4
CRC32 0C9AC4B3
ssdeep 768:l76p/LQtkiNPeTish8mSdz6yP3MQ4y15RyImOuu8fmCQL3TNbFznVn4aY/WPu7Lj:lO/LQmiom68mSdz6yP3Z5RyImOuu8fme
Yara None matched
VirusTotal Search for analysis
Name 92eebf142060ce2d_api-ms-win-crt-string-l1-1-0.dll
Submit file
Filepath C:\Users\test22\AppData\Roaming\Dart Communications\Power iCalconfigurator 15.3.6.2\install\E817FBF\api-ms-win-crt-string-l1-1-0.dll
Size 15.8KB
Processes 2420 (Porcal4.exe)
Type PE32 executable (DLL) (console) Intel 80386, for MS Windows
MD5 6e3edbc12992d36d473f5499d8757d77
SHA1 9d50a47c8a63d67126dcb1c0fd283d48ba5b893d
SHA256 92eebf142060ce2d8ed6e8e3aeaa7dead8d388ffe99b7a6ab0d0709c7d7c262a
CRC32 F27032A3
ssdeep 384:rFvU4x0C5yguNvZ5VQgx3SbwA7yMVIkFGlPWthWnaPVRKoLhQp:95yguNvZ5VQgx3SbwA71IkFFfVhQp
Yara
  • PE_Header_Zero - PE File Signature
  • IsPE32 - (no description)
  • IsDLL - (no description)
  • UPX_Zero - UPX packed file
VirusTotal Search for analysis
Name 687a4b85b2d242e3_d13.ico
Submit file
Filepath C:\Users\test22\AppData\Roaming\Dart Communications\Power iCalconfigurator 15.3.6.2\install\E817FBF\icons\New Blue\d13.ico
Size 894.0B
Processes 2420 (Porcal4.exe)
Type MS Windows icon resource - 1 icon, 16x16, 24 bits/pixel
MD5 382d0b52dd4abb1fb4344a00668ece6e
SHA1 c28fcf33f93456a7d2e12b2541106d5d9ccbafa7
SHA256 687a4b85b2d242e3954bf3e039154be70f952c33643cfbf66c2412d01738c8f4
CRC32 F268E1CD
ssdeep 24:t5VtaYFcwz3bcRZmlOqSDYOYTTTTTTTTTTTT2:VMdwToRZNqAtYTTTTTTTTTTTT2
Yara None matched
VirusTotal Search for analysis
Name 5aa1990906323fc7_d1.ico
Submit file
Filepath C:\Users\test22\AppData\Roaming\Dart Communications\Power iCalconfigurator 15.3.6.2\install\E817FBF\icons\Classic\d1.ico
Size 1.4KB
Processes 2420 (Porcal4.exe)
Type MS Windows icon resource - 1 icon, 16x16, 8 bits/pixel
MD5 0b9387ff14a11123a992fa5b5a015c67
SHA1 3b704d5b706de6b7d33ae21317963c95efe9eb1f
SHA256 5aa1990906323fc78efe40db661bb58305b8c021b197b90ce3291534d38381f3
CRC32 57F06E92
ssdeep 6:UZxMcE2jS4Tfl+46EcAOBNHlfmXpxFWWW9ONCtFw5zFm0mM/tH5n:UZtu4TQ46DAOLHl+XDFBurFwTl/tZn
Yara None matched
VirusTotal Search for analysis
Name cbcf21e742013299_CreateFolderFence@175.png
Submit file
Filepath C:\Users\test22\AppData\Roaming\Dart Communications\Power iCalconfigurator 15.3.6.2\install\E817FBF\Images\CreateFolderFence@175.png
Size 3.0KB
Processes 2420 (Porcal4.exe)
Type PNG image data, 28 x 26, 8-bit/color RGBA, non-interlaced
MD5 844da83b3000def7d885834d3208b1e0
SHA1 42b70ffff6873959a6ee2204bd08c9513be12eaf
SHA256 cbcf21e742013299643ec335cd44e31f3561dbced8124e187b4061f2d0d90638
CRC32 0D9BF5EB
ssdeep 48:+/6DocieftI9G9f6A+FIDOWu0lDl+gm7QyTtctIInQSy6IVpqlnBcODPBhqz+:+SDZ/I09Da01l+gmkyTt6Hk8nTmz+
Yara
  • PNG_Format_Zero - PNG Format
VirusTotal Search for analysis
Name 3f70ffc4571d30c1_d14.ico
Submit file
Filepath C:\Users\test22\AppData\Roaming\Dart Communications\Power iCalconfigurator 15.3.6.2\install\E817FBF\icons\New Blue\d14.ico
Size 894.0B
Processes 2420 (Porcal4.exe)
Type MS Windows icon resource - 1 icon, 16x16, 24 bits/pixel
MD5 f0b2933639c3e703286063f941436d31
SHA1 2cc1384995c60b5876ecb49cb14a2c0cbea3ad4c
SHA256 3f70ffc4571d30c1666cb73c1386addebf938a4be7ca78a5f150d310556fa463
CRC32 D175A3FD
ssdeep 12:t49239B9ACM2ZvgrHE2VOvNYRmCRobGq2csqzsTTTTTTTTTTTT2:t5tB6CNNgjShCR3qRYTTTTTTTTTTTT2
Yara None matched
VirusTotal Search for analysis
Name fe3cbfa07d8e6160_DropdownIcon@300.png
Submit file
Filepath C:\Users\test22\AppData\Roaming\Dart Communications\Power iCalconfigurator 15.3.6.2\install\E817FBF\Images\DropdownIcon@300.png
Size 2.8KB
Processes 2420 (Porcal4.exe)
Type PNG image data, 27 x 27, 8-bit/color RGBA, non-interlaced
MD5 a9979de890eed2a89468049dc3aabde0
SHA1 8e85d4b850ef46dcce2263b33897e7d2e3320f79
SHA256 fe3cbfa07d8e6160e340b6c63f26cdca931890bf40bbc75cf99f096decc4456a
CRC32 1C2757AB
ssdeep 48:r/6DocieftI9G9f6A+FIDOWu0lDl+gm7QyTtctIInQSy6IVpqlnBcODdqUxN:rSDZ/I09Da01l+gmkyTt6Hk8nTdqUxN
Yara
  • PNG_Format_Zero - PNG Format
VirusTotal Search for analysis
Name 4e2a12a194e0db12_PagerBackR.png
Submit file
Filepath C:\Users\test22\AppData\Roaming\Dart Communications\Power iCalconfigurator 15.3.6.2\install\E817FBF\Images\PagerBackR.png
Size 4.6KB
Processes 2420 (Porcal4.exe)
Type PNG image data, 90 x 43, 8-bit/color RGBA, interlaced
MD5 3272be2da53b6d5271111431f7d90d28
SHA1 7ec382eee6282454d5b0b03751f3d14c568bbfa5
SHA256 4e2a12a194e0db12de874ad8c9a5288b5a56285b426883bd0e3cef1866569982
CRC32 6A10FBB6
ssdeep 96:OSDZ/I09Da01l+gmkyTt6Hk8nTuwwyBUnbKzBlpM8jaOTQM1FM+DW1:OSDS0tKg9E05T/7BUnbKzBI8+OTH1FXY
Yara
  • PNG_Format_Zero - PNG Format
VirusTotal Search for analysis
Name c088f8a54c3c79d5_d17.ico
Submit file
Filepath C:\Users\test22\AppData\Roaming\Dart Communications\Power iCalconfigurator 15.3.6.2\install\E817FBF\icons\New Blue\d17.ico
Size 894.0B
Processes 2420 (Porcal4.exe)
Type MS Windows icon resource - 1 icon, 16x16, 24 bits/pixel
MD5 4f35d09423ee965ae0a7ac2292c61ca2
SHA1 996c6b5b9b0d65cc4068cd2c2ef0aae29ab2c501
SHA256 c088f8a54c3c79d556720aa42ad5fd28e3cbe580b52178dab2dae60ca05de839
CRC32 A631D663
ssdeep 12:t4923qPvXeqdugmCwFB6VYb7LQORU4qmmbJ2qzsTTTTTTTTTTTT2:t5+2owIkL3RUSEJ2qYTTTTTTTTTTTT2
Yara None matched
VirusTotal Search for analysis
Name e09fbeb0614f18a4_FencesSmall@175.png
Submit file
Filepath C:\Users\test22\AppData\Roaming\Dart Communications\Power iCalconfigurator 15.3.6.2\install\E817FBF\Images\FencesSmall@175.png
Size 5.1KB
Processes 2420 (Porcal4.exe)
Type PNG image data, 28 x 28, 8-bit/color RGBA, non-interlaced
MD5 aa13eccd182a62fdb70a5f2f5548c7a3
SHA1 4d33b405f0977e2658fe96913159ad761ccaab7e
SHA256 e09fbeb0614f18a4189ee9ddadccebfa2ca4299987d1041c68e81b243a16b342
CRC32 216405F5
ssdeep 96:tZ/I09Da01l+gmkyTt6Hk8nTdmuAbOToTdBVnZQFT0EsbU2Y74g8:tS0tKg9E05TdNAbZT9nAT8U2G8
Yara
  • PNG_Format_Zero - PNG Format
VirusTotal Search for analysis
Name 882e9d69fa362eca_d8a.ico
Submit file
Filepath C:\Users\test22\AppData\Roaming\Dart Communications\Power iCalconfigurator 15.3.6.2\install\E817FBF\icons\New Blue\d8a.ico
Size 894.0B
Processes 2420 (Porcal4.exe)
Type MS Windows icon resource - 1 icon, 16x16, 24 bits/pixel
MD5 ac3da2339e0e7e0bd0b66ea74d2dd6bc
SHA1 75a41841b46f1166fd769246def400f7b86be20f
SHA256 882e9d69fa362eca32238c10e831ec19b5a456334fbdb15cd703315d4996540f
CRC32 05F4A0A9
ssdeep 12:t47v4Iq1mmIvNPucud4P5zdvrMCMpUA1g0M:tSzBVd7rxM2Aq
Yara None matched
VirusTotal Search for analysis
Name 32fca48daca0f178_api-ms-win-core-datetime-l1-1-0.dll
Submit file
Filepath C:\Users\test22\AppData\Roaming\Dart Communications\Power iCalconfigurator 15.3.6.2\install\E817FBF\api-ms-win-core-datetime-l1-1-0.dll
Size 9.3KB
Processes 2420 (Porcal4.exe)
Type PE32 executable (DLL) (console) Intel 80386, for MS Windows
MD5 d85fab747b228ca765ff37c94f372aa4
SHA1 24d4f4540c0658c3d8c8b2366cc2f19a8f581548
SHA256 32fca48daca0f178b7fb94cfa1de9235a5329883f4e680d331f99fec2b54fb80
CRC32 159D59B4
ssdeep 96:5OKEWthWwO80EuL638yZfaQCiUkm6ybK7Ya3Fwu3JUfhdyEi7ZHeENfjIh:50WthWy068Ya5/R6t7YadBZHBMh
Yara
  • PE_Header_Zero - PE File Signature
  • IsPE32 - (no description)
  • IsDLL - (no description)
  • UPX_Zero - UPX packed file
VirusTotal Search for analysis
Name 78b82403af639425_d9.ico
Submit file
Filepath C:\Users\test22\AppData\Roaming\Dart Communications\Power iCalconfigurator 15.3.6.2\install\E817FBF\icons\New Blue\d9.ico
Size 894.0B
Processes 2420 (Porcal4.exe)
Type MS Windows icon resource - 1 icon, 16x16, 24 bits/pixel
MD5 f28e666e35f2cbe2cb62dccb9a6b8341
SHA1 30b6dd0cd73328f67283d4e738b6224aae014385
SHA256 78b82403af639425fc0ace165713019e29511222dae19f93499eec7f32c8f0a8
CRC32 5E79511A
ssdeep 12:t492lhji4turKpg/P5w8FgvekTA11jrgqzsTTTTTTTTTTTT2:t5lh2iu0MxYekwYTTTTTTTTTTTT2
Yara None matched
VirusTotal Search for analysis
Name ec968c8ff2da5e3d_NavigateUpIcon@275.png
Submit file
Filepath C:\Users\test22\AppData\Roaming\Dart Communications\Power iCalconfigurator 15.3.6.2\install\E817FBF\Images\NavigateUpIcon@275.png
Size 2.8KB
Processes 2420 (Porcal4.exe)
Type PNG image data, 31 x 36, 8-bit/color RGBA, non-interlaced
MD5 8162c002a23e5839f69c7a97e65482b5
SHA1 40fd5469229d01cb9d9d14b2b6ba21e463c473a3
SHA256 ec968c8ff2da5e3d5305f4ccece3c120fd6d166082e20296af80b3168409976c
CRC32 0F14FD2A
ssdeep 48:Q/6DocieftI9G9f6A+FIDOWu0lDl+gm7QyTtctIInQSy6IVpqlnBcODo5F:QSDZ/I09Da01l+gmkyTt6Hk8nTo5F
Yara
  • PNG_Format_Zero - PNG Format
VirusTotal Search for analysis
Name 46fc69a51d3a6482_CloseIcon@250.png
Submit file
Filepath C:\Users\test22\AppData\Roaming\Dart Communications\Power iCalconfigurator 15.3.6.2\install\E817FBF\Images\CloseIcon@250.png
Size 2.8KB
Processes 2420 (Porcal4.exe)
Type PNG image data, 23 x 23, 8-bit/color RGBA, non-interlaced
MD5 b5fbc6d861264c2cd1893159516ca619
SHA1 1abdeec3d766937a0743c83aeb3300c670377ded
SHA256 46fc69a51d3a6482a7a99f18f31dc1f3b361e1a58f4e4edf0f01610e9b599442
CRC32 92E3D411
ssdeep 48:b/6DocieftI9G9f6A+FIDOWu0lDl+gm7QyTtctIInQSy6IVpqlnBcODS2+8KaM:bSDZ/I09Da01l+gmkyTt6Hk8nTS2SaM
Yara
  • PNG_Format_Zero - PNG Format
VirusTotal Search for analysis
Name 52bbf852d3521759_d7.ico
Submit file
Filepath C:\Users\test22\AppData\Roaming\Dart Communications\Power iCalconfigurator 15.3.6.2\install\E817FBF\icons\Classic\d7.ico
Size 1.4KB
Processes 2420 (Porcal4.exe)
Type MS Windows icon resource - 1 icon, 16x16, 8 bits/pixel
MD5 b5d4385594f6afbb2511a24a62098dd3
SHA1 b635fe3af8be154fe8fe87fc5275a8c7deb96ae3
SHA256 52bbf852d3521759fbfa39d359fc60c0c9a0c91cfb5e05b81e8f5295d9bd6af8
CRC32 AD7A8013
ssdeep 6:UZxMcE2jS4Tfl+46EcAOBNHlfmXpLWWWWWQmNUZ/3/8UfmM/tH5n:UZtu4TQ46DAOLHl+X9BBJmNyPvn/tZn
Yara None matched
VirusTotal Search for analysis
Name e98cf10c28ff69b2_d13a.ico
Submit file
Filepath C:\Users\test22\AppData\Roaming\Dart Communications\Power iCalconfigurator 15.3.6.2\install\E817FBF\icons\Classic\d13a.ico
Size 1.4KB
Processes 2420 (Porcal4.exe)
Type MS Windows icon resource - 1 icon, 16x16, 255 colors, 8 bits/pixel
MD5 df5d3f166e4928542d19b06dc71de051
SHA1 fb5b3f53f2efcf90824a8b042062ca6a4bdd1651
SHA256 e98cf10c28ff69b2ab9813693075bc11ffe4b96d6c3b65d3d7b5486f1617743f
CRC32 DD1B6897
ssdeep 6:dz4mY3OSl5qI3u9DpXRoVnVlRkinRnLnjLSUtBn1AuWDFwV/tnn:dzZY3OW5N3a1XRoVV35fFnWucFwTn
Yara None matched
VirusTotal Search for analysis
Name 8b2cd54da183825e_d12.ico
Submit file
Filepath C:\Users\test22\AppData\Roaming\Dart Communications\Power iCalconfigurator 15.3.6.2\install\E817FBF\icons\Classic\d12.ico
Size 1.4KB
Processes 2420 (Porcal4.exe)
Type MS Windows icon resource - 1 icon, 16x16, 8 bits/pixel
MD5 fbebbb90b2789d9a79993b2b004d7d67
SHA1 15f770a0aabf6fba11c7f8036d57d3e3fd2ac0df
SHA256 8b2cd54da183825ec7af3b165ceda5c02748f7a1c4e9283cacd23414e83a7024
CRC32 2A33028D
ssdeep 12:UZtu4TQ46DAOLHl+XZTNzzylki2a7/cV/tZn:QXBOLOzzyeip7kD
Yara None matched
VirusTotal Search for analysis
Name 7ab752fdadc96ac2_d18.ico
Submit file
Filepath C:\Users\test22\AppData\Roaming\Dart Communications\Power iCalconfigurator 15.3.6.2\install\E817FBF\icons\New Blue\d18.ico
Size 894.0B
Processes 2420 (Porcal4.exe)
Type MS Windows icon resource - 1 icon, 16x16, 24 bits/pixel
MD5 133fb36e6b94142c8156cf297e059f1c
SHA1 6138737bba5164a098a0d95b832c60e46ea8b7b9
SHA256 7ab752fdadc96ac2cf2c81f3b77fed973afc334bc353055d3755383494b46b22
CRC32 C9D3727C
ssdeep 12:t4923lJd94aO/HLQVZncRxMm24DMqzsTTTTTTTTTTTT2:t5VhPgrAZcRjFxYTTTTTTTTTTTT2
Yara None matched
VirusTotal Search for analysis
Name e0330cca14ea9507_MenuIcon@200.png
Submit file
Filepath C:\Users\test22\AppData\Roaming\Dart Communications\Power iCalconfigurator 15.3.6.2\install\E817FBF\Images\MenuIcon@200.png
Size 2.8KB
Processes 2420 (Porcal4.exe)
Type PNG image data, 22 x 17, 8-bit/color RGBA, non-interlaced
MD5 2701cc83720becb2a31b104cbf4a497a
SHA1 de7c84c003da7ad7c330f89cdf5403f776b1d460
SHA256 e0330cca14ea9507f7081c644bafa5d2ba89b7ea374791b3c648728dbfcdd443
CRC32 C8CBBE61
ssdeep 48:R/6DocieftI9G9f6A+FIDOWu0lDl+gm7QyTtctIInQSy6IVpqlnBcODUdy:RSDZ/I09Da01l+gmkyTt6Hk8nTay
Yara
  • PNG_Format_Zero - PNG Format
VirusTotal Search for analysis
Name 51ca1381283d9138_d20a.ico
Submit file
Filepath C:\Users\test22\AppData\Roaming\Dart Communications\Power iCalconfigurator 15.3.6.2\install\E817FBF\icons\Classic\d20a.ico
Size 1.4KB
Processes 2420 (Porcal4.exe)
Type MS Windows icon resource - 1 icon, 16x16, 255 colors, 8 bits/pixel
MD5 526336b789639a38d369fcdd12f4c593
SHA1 83c7a86a889c4159bff92bd72d902d9ba30943bf
SHA256 51ca1381283d9138e74400b760190f41a8d8aaa7328aabc04993fa5ea921816c
CRC32 B8DDE02D
ssdeep 6:dzMQjE7o3Ll5+pXhoVnVRAkWBnRnNgGmXBhEk3HtA/tnn:dzzEMKXhoVVRQjyGmXL3Ht2n
Yara None matched
VirusTotal Search for analysis
Name f3d4020ad9e10a60_d10.ico
Submit file
Filepath C:\Users\test22\AppData\Roaming\Dart Communications\Power iCalconfigurator 15.3.6.2\install\E817FBF\icons\Classic\d10.ico
Size 1.4KB
Processes 2420 (Porcal4.exe)
Type MS Windows icon resource - 1 icon, 16x16, 8 bits/pixel
MD5 de787ea3af0143fa5f4c01cf3c85a88f
SHA1 0d9a15e0746bb7367b013befbf7cf00192586f11
SHA256 f3d4020ad9e10a60033da04380af08138bfcc027c855b89692897a35d314c3d4
CRC32 9CDD800F
ssdeep 6:UZxMcE2jS4Tfl+46EcAOBNHlfmXpQuuEjNuEzLp/Z14w45l/cW0mM/tH5n:UZtu4TQ46DAOLHl+XWuFPt/W7/cV/tZn
Yara None matched
VirusTotal Search for analysis
Name 4e01b6ccb668ab1e_chinesesimp.dxs
Submit file
Filepath C:\Users\test22\AppData\Roaming\Dart Communications\Power iCalconfigurator 15.3.6.2\install\E817FBF\sprache\chinesesimp.dxs
Size 45.6KB
Processes 2420 (Porcal4.exe)
Type ISO-8859 text, with CRLF line terminators
MD5 443698f47d051ff3ccda305b6f4b4b45
SHA1 2b31a019ad05a85d53397cb3fe7b08946b951e5c
SHA256 4e01b6ccb668ab1e548ffa72c2ef69c9088d7e910a170cc6a820f7fef08b7d81
CRC32 6672C367
ssdeep 768:Zo+/CSsuPXAdwmNPa8pbEQobU4PJ7tYjOWdYZ1aUtz1eIACWHnpD3qt+0UdLAXiZ:Zo+/psQXAdwmNPa8pAY4PJ7tYqWdYZML
Yara None matched
VirusTotal Search for analysis
Name 00663f486f97113e_d13a.ico
Submit file
Filepath C:\Users\test22\AppData\Roaming\Dart Communications\Power iCalconfigurator 15.3.6.2\install\E817FBF\icons\New Blue\d13a.ico
Size 894.0B
Processes 2420 (Porcal4.exe)
Type MS Windows icon resource - 1 icon, 16x16, 24 bits/pixel
MD5 dad6f80269c85c0a090bf36c75221a64
SHA1 44681f3639b4509b717dae06f37153507970b140
SHA256 00663f486f97113e8332c298ea70b45aca0911a54cd017632a18bdd37a7913ce
CRC32 9821A8CA
ssdeep 12:t47v4AlZ1mON7xcYZBtHZmdCbotRZ98lOzyZqL/5jY6g0M:tSLuODcYF5lbotRZmlO2ZS5jYx
Yara None matched
VirusTotal Search for analysis
Name 73d5f96a6a30bbd4_decoder.dll
Submit file
Filepath C:\Users\test22\AppData\Roaming\Dart Communications\Power iCalconfigurator 15.3.6.2\install\decoder.dll
Size 202.5KB
Processes 2420 (Porcal4.exe)
Type PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
MD5 454418ebd68a4e905dc2b9b2e5e1b28c
SHA1 a54cb6a80d9b95451e2224b6d95de809c12c9957
SHA256 73d5f96a6a30bbd42752bffc7f20db61c8422579bf8a53741488be34b73e1409
CRC32 8DD67663
ssdeep 3072:Xnc8s5yYYVegTR5eO29YoYhNsli0rCckZ9uNDOQH5TmIKO+mAwzvX5Q+M9/:fV79tRUi7ckZSFxPtM9
Yara
  • PE_Header_Zero - PE File Signature
  • OS_Processor_Check_Zero - OS Processor Check
  • IsPE32 - (no description)
  • Win32_Trojan_Gen_2_0904B0_Zero - Win32 Trojan Gen
  • IsDLL - (no description)
  • Malicious_Library_Zero - Malicious_Library
  • UPX_Zero - UPX packed file
VirusTotal Search for analysis
Name eea2df0c3d2bf84e_vcruntime140.dll
Submit file
Filepath C:\Users\test22\AppData\Roaming\Dart Communications\Power iCalconfigurator 15.3.6.2\install\E817FBF\vcruntime140.dll
Size 85.3KB
Processes 2420 (Porcal4.exe)
Type PE32 executable (DLL) (console) Intel 80386, for MS Windows
MD5 ac139e08070885a2f021e30fab609eee
SHA1 3d3c2877cf3c4aa1a1f62708494375404d02cf22
SHA256 eea2df0c3d2bf84ee8bc811439a81578f6521c8b28b6cc815c93fb870ac7a0d7
CRC32 05EE9B26
ssdeep 1536:fGcAKWRMbpuRQci+7uXTKLWe+27JofZo0ENm2eK7oJnoUSgpAY8ODcDcm7cIsXh0:fG3KiRQcJ7uj8f7Jofm0ENm2eK7mnoUS
Yara
  • PE_Header_Zero - PE File Signature
  • OS_Processor_Check_Zero - OS Processor Check
  • IsPE32 - (no description)
  • IsDLL - (no description)
  • Malicious_Library_Zero - Malicious_Library
  • UPX_Zero - UPX packed file
  • Win32_Trojan_Gen_1_0904B0_Zero - Win32 Trojan Emotet
VirusTotal Search for analysis
Name 9b48294a6b2cf61e_d19a.ico
Submit file
Filepath C:\Users\test22\AppData\Roaming\Dart Communications\Power iCalconfigurator 15.3.6.2\install\E817FBF\icons\New Blue\d19a.ico
Size 894.0B
Processes 2420 (Porcal4.exe)
Type MS Windows icon resource - 1 icon, 16x16, 24 bits/pixel
MD5 35106b251164d7e695fef24d5e29367c
SHA1 5b82d3431c67e1bd8afdf21cd44923a3cde44766
SHA256 9b48294a6b2cf61e97c6bd0dccf572cf9dd941b2bd7670f11a0c146e5aabe5e4
CRC32 509F8C11
ssdeep 12:t47v4A41mOI0Ec7DmXM7WYtRCSUZ0Ij6J0M:tSxOI0EceXM7WYtRCSUZHj6P
Yara None matched
VirusTotal Search for analysis
Name 7a3ab249091f6872_api-ms-win-core-handle-l1-1-0.dll
Submit file
Filepath C:\Users\test22\AppData\Roaming\Dart Communications\Power iCalconfigurator 15.3.6.2\install\E817FBF\api-ms-win-core-handle-l1-1-0.dll
Size 9.3KB
Processes 2420 (Porcal4.exe)
Type PE32 executable (DLL) (console) Intel 80386, for MS Windows
MD5 3fa0e776b686cb0cc635c60111e4c17e
SHA1 c7ca3b263f8919bb53c674f48c861cdee40c7306
SHA256 7a3ab249091f68728e08b6c52a23009d194ff433b990ec4a79c9e1367a0503a9
CRC32 505CB4D1
ssdeep 96:bYFMxrTcEWthWw34A0EuL638yZfaQCiUkm6ybK7s+1kU2G3JUfhdyEi7ZHeEVfuZ:ZWthWZA068Ya5/R6t7s+1kmBZHBuZ
Yara
  • PE_Header_Zero - PE File Signature
  • IsPE32 - (no description)
  • IsDLL - (no description)
  • UPX_Zero - UPX packed file
VirusTotal Search for analysis
Name c6ab8de9eaf981ab_d6.ico
Submit file
Filepath C:\Users\test22\AppData\Roaming\Dart Communications\Power iCalconfigurator 15.3.6.2\install\E817FBF\icons\Classic\d6.ico
Size 1.4KB
Processes 2420 (Porcal4.exe)
Type MS Windows icon resource - 1 icon, 16x16, 8 bits/pixel
MD5 26136c3bb47ccd00d75afb9744802cfb
SHA1 405628d0f0055f63817370ac86d5031728a6e65b
SHA256 c6ab8de9eaf981abded4e2a3f9cadd15deb7629a26d229f87b4f8e2722a8acfc
CRC32 95B25D18
ssdeep 12:UZtu4TQ46DAOLHl+XDPhXlCwLL6V/0//tZn:QXBOL2hX1X6M/D
Yara None matched
VirusTotal Search for analysis
Name a99237fcbc43b983_CloseIcon@225.png
Submit file
Filepath C:\Users\test22\AppData\Roaming\Dart Communications\Power iCalconfigurator 15.3.6.2\install\E817FBF\Images\CloseIcon@225.png
Size 2.8KB
Processes 2420 (Porcal4.exe)
Type PNG image data, 21 x 21, 8-bit/color RGBA, non-interlaced
MD5 e167fb197b5932b5c60ac56aef01a34d
SHA1 e15cb4c8a4fbd6d80ba944728aa1d67675ce80ad
SHA256 a99237fcbc43b9834ccb4e8375c9b81a2508734035059d678c08d9c7b6b3ce05
CRC32 5FBA378D
ssdeep 48:E/6DocieftI9G9f6A+FIDOWu0lDl+gm7QyTtctIInQSy6IVpqlnBcODQtlN:ESDZ/I09Da01l+gmkyTt6Hk8nTilN
Yara
  • PNG_Format_Zero - PNG Format
VirusTotal Search for analysis
Name f047a504fc0c2c05_api-ms-win-core-localization-l1-2-0.dll
Submit file
Filepath C:\Users\test22\AppData\Roaming\Dart Communications\Power iCalconfigurator 15.3.6.2\install\E817FBF\api-ms-win-core-localization-l1-2-0.dll
Size 11.8KB
Processes 2420 (Porcal4.exe)
Type PE32 executable (DLL) (console) Intel 80386, for MS Windows
MD5 d4b84893705e2c246490fe20a40102ab
SHA1 0d940cbc25fbabe57d78d32bc52b59e768d3715f
SHA256 f047a504fc0c2c051287f46e3456c871339ec797df96ded873a22d49889eb749
CRC32 37213919
ssdeep 192:gqtZOMw3zdp3bwjGfue9/0jCRrndblWthWg068Ya5/R6t7sPHsBZH+nQ:PHOMw3zdp3bwjGfue9/0jCRrndblWth1
Yara
  • PE_Header_Zero - PE File Signature
  • IsPE32 - (no description)
  • IsDLL - (no description)
  • UPX_Zero - UPX packed file
VirusTotal Search for analysis
Name 3d87fa0ba60b005e_api-ms-win-crt-process-l1-1-0.dll
Submit file
Filepath C:\Users\test22\AppData\Roaming\Dart Communications\Power iCalconfigurator 15.3.6.2\install\E817FBF\api-ms-win-crt-process-l1-1-0.dll
Size 10.3KB
Processes 2420 (Porcal4.exe)
Type PE32 executable (DLL) (console) Intel 80386, for MS Windows
MD5 adbb9d7327dd24bce73c566cadb00fc6
SHA1 8a7d817eead1062d616c085c2ed8db9968901ea5
SHA256 3d87fa0ba60b005ee381388f7ec13fc4ac2548be05325f60ae677a512f8ad2ec
CRC32 452280C4
ssdeep 192:Monqjd7NWthWu068Ya5/R6t7s2V0BZH9/f+V:MonsWthWuaPVRKoIeh4V
Yara
  • PE_Header_Zero - PE File Signature
  • IsPE32 - (no description)
  • IsDLL - (no description)
  • UPX_Zero - UPX packed file
VirusTotal Search for analysis
Name ad8779a86b5c59df_CreateFence@200.png
Submit file
Filepath C:\Users\test22\AppData\Roaming\Dart Communications\Power iCalconfigurator 15.3.6.2\install\E817FBF\Images\CreateFence@200.png
Size 3.1KB
Processes 2420 (Porcal4.exe)
Type PNG image data, 32 x 30, 8-bit/color RGBA, non-interlaced
MD5 2f1c35499965df9c4896aabb1af8e8d9
SHA1 0847dd3bba0fc7f73f0b7a76c573eb6f38c22b4d
SHA256 ad8779a86b5c59dfbd623d4ccdc877ac71f64eb60dd581a33d95daa9cf5fc607
CRC32 876BA08A
ssdeep 48:H/6DocieftI9G9f6A+FIDOWu0lDl+gm7QyTtctIInQSy6IVpqlnBcODt9F4Csl:HSDZ/I09Da01l+gmkyTt6Hk8nTtj6l
Yara
  • PNG_Format_Zero - PNG Format
VirusTotal Search for analysis
Name 8cd64970fc65809c_DropdownIcon@325.png
Submit file
Filepath C:\Users\test22\AppData\Roaming\Dart Communications\Power iCalconfigurator 15.3.6.2\install\E817FBF\Images\DropdownIcon@325.png
Size 2.8KB
Processes 2420 (Porcal4.exe)
Type PNG image data, 29 x 29, 8-bit/color RGBA, non-interlaced
MD5 eb3908e2f328b3720a30dd94992c9d82
SHA1 236b47f8677053e5897cd87630ef81500b897680
SHA256 8cd64970fc65809c00aa420bed6bd0ea58f92b3d5d4b837979681fabbcff3c17
CRC32 635D8A11
ssdeep 48:+/6DocieftI9G9f6A+FIDOWu0lDl+gm7QyTtctIInQSy6IVpqlnBcODeEPPv:+SDZ/I09Da01l+gmkyTt6Hk8nTe2H
Yara
  • PNG_Format_Zero - PNG Format
VirusTotal Search for analysis
Name 8c123d33b7be2f3b_api-ms-win-crt-environment-l1-1-0.dll
Submit file
Filepath C:\Users\test22\AppData\Roaming\Dart Communications\Power iCalconfigurator 15.3.6.2\install\E817FBF\api-ms-win-crt-environment-l1-1-0.dll
Size 9.8KB
Processes 2420 (Porcal4.exe)
Type PE32 executable (DLL) (console) Intel 80386, for MS Windows
MD5 ea1ee640c96f6d3440d480eb592b358c
SHA1 e318757ab3a9957c76deb0c870ba93471a34b975
SHA256 8c123d33b7be2f3b0af9ece9d678c2e46391631665cde12a0e98f50bdb97b13a
CRC32 B8287DAD
ssdeep 96:V9KN3suEWthWw3w0EuL638yZfaQCiUkm6ybK7sobF3JUfhdyEi7ZHeEufD3Dks:V9KNMWthWR068Ya5/R6t7sozBZHkTDks
Yara
  • PE_Header_Zero - PE File Signature
  • IsPE32 - (no description)
  • IsDLL - (no description)
  • UPX_Zero - UPX packed file
VirusTotal Search for analysis
Name 47189a4e64869c18_NavigateUpIcon@100.png
Submit file
Filepath C:\Users\test22\AppData\Roaming\Dart Communications\Power iCalconfigurator 15.3.6.2\install\E817FBF\Images\NavigateUpIcon@100.png
Size 2.8KB
Processes 2420 (Porcal4.exe)
Type PNG image data, 11 x 13, 8-bit/color RGBA, non-interlaced
MD5 036c9b62b65e8edb5dd5c2f54a0c3a31
SHA1 fce64e5286a094b26389b9d6f58fcb855248efae
SHA256 47189a4e64869c180c029baa51e2f9bda6f1e425365c4bee578c6818a8251311
CRC32 9FC5F4B4
ssdeep 48:s/6DocieftI9G9f6A+FIDOWu0lDl+gm7QyTtctIInQSy6IVpqlnBcODSDA:sSDZ/I09Da01l+gmkyTt6Hk8nToA
Yara
  • PNG_Format_Zero - PNG Format
VirusTotal Search for analysis
Name c0656793ced02ff8_api-ms-win-core-file-l2-1-0.dll
Submit file
Filepath C:\Users\test22\AppData\Roaming\Dart Communications\Power iCalconfigurator 15.3.6.2\install\E817FBF\api-ms-win-core-file-l2-1-0.dll
Size 9.3KB
Processes 2420 (Porcal4.exe)
Type PE32 executable (DLL) (console) Intel 80386, for MS Windows
MD5 8922e3a59503da019da562ff8be3a16b
SHA1 8d7b9b4a656b028e2717afde4e52a394454f5873
SHA256 c0656793ced02ff844aaf5014f76ccaeb209ab512f99ea1bd4481b00951ff470
CRC32 053357B0
ssdeep 96:+vQjEWthWwOA+0EuL638yZfaQCiUkm6ybK7YCiV3JUfhdyEi7ZHeEwfkLF:mWthWV068Ya5/R6t7YCinBZHukB
Yara
  • PE_Header_Zero - PE File Signature
  • IsPE32 - (no description)
  • IsDLL - (no description)
  • UPX_Zero - UPX packed file
VirusTotal Search for analysis
Name a46414c1acb0f40c_LeftAndRight.fencelayout
Submit file
Filepath C:\Users\test22\AppData\Roaming\Dart Communications\Power iCalconfigurator 15.3.6.2\install\E817FBF\Layouts\LeftAndRight.fencelayout
Size 1.6KB
Processes 2420 (Porcal4.exe)
Type XML 1.0 document, ASCII text, with CRLF line terminators
MD5 de241d99557132d39256019e500150ee
SHA1 12a4abc1220e6d612e12f3c30e030540afcb2990
SHA256 a46414c1acb0f40c282c91ccb343ffb1feb9bea823ce8aa107a79628f8f0a5f2
CRC32 A1B54CB5
ssdeep 24:2dX8vENZVN5u61fhvH9VSYDLVSYjfeWSqL/hvHkVSYDLVSYjfeWSqLPb2:cX8va9hIY3IYLAIY3IYLY
Yara None matched
VirusTotal Search for analysis
Name 0576d3beb1c46d36_d16a.ico
Submit file
Filepath C:\Users\test22\AppData\Roaming\Dart Communications\Power iCalconfigurator 15.3.6.2\install\E817FBF\icons\Classic\d16a.ico
Size 1.4KB
Processes 2420 (Porcal4.exe)
Type MS Windows icon resource - 1 icon, 16x16, 255 colors, 8 bits/pixel
MD5 6c63808dfa8a3135d9efbb3a6e5669e4
SHA1 e5357ae5bf7fd06e6e5882b75021639beaeb3ce8
SHA256 0576d3beb1c46d36f0aa09cf9a0dbdca5e7a3e9aca98f18c36afcc1f415b94ef
CRC32 A33519E0
ssdeep 6:dzMQjEGoilbhlxgmXRoVnVlRkinRnBnRnNgN1/A6wuYRpw2wV/tnn:dzzEElxXRoVV35jyN1/rwuSpw2wTn
Yara None matched
VirusTotal Search for analysis
Name 932920fe06897c0b_vcruntime140_clr0400.dll
Submit file
Filepath C:\Users\test22\AppData\Roaming\Dart Communications\Power iCalconfigurator 15.3.6.2\install\E817FBF\vcruntime140_clr0400.dll
Size 81.8KB
Processes 2420 (Porcal4.exe)
Type PE32 executable (DLL) (console) Intel 80386, for MS Windows
MD5 071309be821483287a0fe982aef005c1
SHA1 3454127b3fbe8c10d20fa288f37e7f72d9d1c00e
SHA256 932920fe06897c0b2adaf7fa855e3b45498d213994e81ab8694d9ee5ca53ac0a
CRC32 34908EB7
ssdeep 1536:bDpXkqGzQDisMDoB6xMSKgS9WnESDPIYMWC/q6mYIaDsu03/x3ecblw3mT+CBvF6:bFk1QDGDoBab8y6mfakvx3ecblw3ma5
Yara
  • PE_Header_Zero - PE File Signature
  • OS_Processor_Check_Zero - OS Processor Check
  • IsPE32 - (no description)
  • IsDLL - (no description)
  • Malicious_Library_Zero - Malicious_Library
  • UPX_Zero - UPX packed file
  • Win32_Trojan_Gen_1_0904B0_Zero - Win32 Trojan Emotet
VirusTotal Search for analysis
Name 332484c03cc606cc_d4a.ico
Submit file
Filepath C:\Users\test22\AppData\Roaming\Dart Communications\Power iCalconfigurator 15.3.6.2\install\E817FBF\icons\Classic\d4a.ico
Size 1.4KB
Processes 2420 (Porcal4.exe)
Type MS Windows icon resource - 1 icon, 16x16, 255 colors, 8 bits/pixel
MD5 363d8c21f0a5eebb4d5be125ae72e1c3
SHA1 01f0849ac3b7ead68597f217a646c95a456edc6c
SHA256 332484c03cc606cccd978f0b93a20cfd3da6afa11abf9097cd4cea521aad132e
CRC32 02E89A8A
ssdeep 12:dzFc363OW5NWT1XBoVVRVRzD8QFzsnICn:z3nzAEDFAII
Yara None matched
VirusTotal Search for analysis
Name c647298e9160a738_d4a.ico
Submit file
Filepath C:\Users\test22\AppData\Roaming\Dart Communications\Power iCalconfigurator 15.3.6.2\install\E817FBF\icons\New Blue\d4a.ico
Size 894.0B
Processes 2420 (Porcal4.exe)
Type MS Windows icon resource - 1 icon, 16x16, 24 bits/pixel
MD5 f0b5603345baad11dcb208bdec363b12
SHA1 9d9d1bc3f39927c9a8c635b3e490268fc962dcab
SHA256 c647298e9160a7383fe65495067f65e4ff831ce43016aea9f2ea1d4ef082aed1
CRC32 35AF82CC
ssdeep 12:t47v4I7x1mMXvM1AuF/VlMayGELQpvT4YCcKT2g0M:tSz7GM/M15/rXWcKp
Yara None matched
VirusTotal Search for analysis
Name 524da457f8e28864_d4.ico
Submit file
Filepath C:\Users\test22\AppData\Roaming\Dart Communications\Power iCalconfigurator 15.3.6.2\install\E817FBF\icons\Classic\d4.ico
Size 1.4KB
Processes 2420 (Porcal4.exe)
Type MS Windows icon resource - 1 icon, 16x16, 8 bits/pixel
MD5 dccd25d9db9b6b436227feb319e73576
SHA1 654b1dcc052328aebfcdf97ba5743a1c0a70521c
SHA256 524da457f8e28864bc99c875e58f7ff622be271e7ea45067e4339630ddd4653f
CRC32 37D47050
ssdeep 12:UZtu4TQ46DAOLHl+X+BOXlTsn27kh//tZn:QXBOLNBOXK2s/D
Yara None matched
VirusTotal Search for analysis
Name 389df59fcfb2654d_FolderIcon@250.png
Submit file
Filepath C:\Users\test22\AppData\Roaming\Dart Communications\Power iCalconfigurator 15.3.6.2\install\E817FBF\Images\FolderIcon@250.png
Size 2.8KB
Processes 2420 (Porcal4.exe)
Type PNG image data, 40 x 37, 8-bit/color RGBA, non-interlaced
MD5 bb2910a13610703f5fc30481172af670
SHA1 2e61a0c5534b614f3349a5bd4010d62864d7472f
SHA256 389df59fcfb2654d5dcd87d88d126916d8c72c031db4c5ff8ef2d8bf7a6eb5c5
CRC32 21420F72
ssdeep 48:wp/6DocieftI9G9f6A+FIDOWu0lDl+gm7QyTtctIInQSy6IVpqlnBcODG:QSDZ/I09Da01l+gmkyTt6Hk8nTG
Yara
  • PNG_Format_Zero - PNG Format
VirusTotal Search for analysis
Name 90a01c346829e60f_d2a.ico
Submit file
Filepath C:\Users\test22\AppData\Roaming\Dart Communications\Power iCalconfigurator 15.3.6.2\install\E817FBF\icons\New Blue\d2a.ico
Size 894.0B
Processes 2420 (Porcal4.exe)
Type MS Windows icon resource - 1 icon, 16x16, 24 bits/pixel
MD5 e8500914a29f75e3e9d2de4a39cf1eae
SHA1 6348da77835ac94b6ee3d43a6c6de116582e513a
SHA256 90a01c346829e60f02d34cc13bccd6a5cc3ed5319ee63dfe24346f51fc6ee979
CRC32 5D5A874D
ssdeep 12:t47v4VF1meSvwDw10ONiRpH/98l/oWL0gvoW3Cc/YTeWUsZsg0M:tS1eOywXNuH/pWL0YNScQKWTr
Yara None matched
VirusTotal Search for analysis
Name f5b72bf1dea715bc_d11.ico
Submit file
Filepath C:\Users\test22\AppData\Roaming\Dart Communications\Power iCalconfigurator 15.3.6.2\install\E817FBF\icons\Classic\d11.ico
Size 1.4KB
Processes 2420 (Porcal4.exe)
Type MS Windows icon resource - 1 icon, 16x16, 8 bits/pixel
MD5 f0466f29d958605c3415f2c7b18d3b62
SHA1 9e47c4d3ff5a904148be631a6e254da00e3beb7b
SHA256 f5b72bf1dea715bce3a322ec4b53e516fb330034f3460d3a1983eefd30bd9c0f
CRC32 F31EFE04
ssdeep 12:UZtu4TQ46DAOLHl+XWuAUhblC1i/ks//tZn:QXBOLQAUhbsa/D
Yara None matched
VirusTotal Search for analysis
Name 524dd4f82e938d42_api-ms-win-core-debug-l1-1-0.dll
Submit file
Filepath C:\Users\test22\AppData\Roaming\Dart Communications\Power iCalconfigurator 15.3.6.2\install\E817FBF\api-ms-win-core-debug-l1-1-0.dll
Size 9.3KB
Processes 2420 (Porcal4.exe)
Type PE32 executable (DLL) (console) Intel 80386, for MS Windows
MD5 1c117dd93a76f0d095a0f4536b09de7c
SHA1 833a16ee1de638c5083df5a73bac1a3b77ce4cc7
SHA256 524dd4f82e938d429bcf7273e96f82b5fff35de849797ce1eaf1d3ad43ddbcd4
CRC32 49B7971E
ssdeep 96:/U8+xEWthWw3Hh0EuL638yZfaQCiUkm6ybK7sTVqYm3JUfhdyEi7ZHeE+fJ8:/pWthW0068Ya5/R6t7sxoBZHcJ8
Yara
  • PE_Header_Zero - PE File Signature
  • IsPE32 - (no description)
  • IsDLL - (no description)
  • UPX_Zero - UPX packed file
VirusTotal Search for analysis
Name 61590dd9b5be99d0_FencesSmall@100.png
Submit file
Filepath C:\Users\test22\AppData\Roaming\Dart Communications\Power iCalconfigurator 15.3.6.2\install\E817FBF\Images\FencesSmall@100.png
Size 3.4KB
Processes 2420 (Porcal4.exe)
Type PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced
MD5 732c9e71c9656fbdce8b0a2e20aeea8a
SHA1 0bac6a7d09b057c37a69e21fdf75b784e3734496
SHA256 61590dd9b5be99d0c24c825c595b221af4cbc414b10b417a283cdb3c8d3bbf44
CRC32 E4E0AF49
ssdeep 48:b/6DocieftI9G9f6A+FIDOWu0lDl+gm7QyTtctIInQSy6IVpqlnBcODn1ZyhGd2e:bSDZ/I09Da01l+gmkyTt6Hk8nTn1Z/N/
Yara
  • PNG_Format_Zero - PNG Format
VirusTotal Search for analysis
Name 821064a5ad7de4e7_next.ico
Submit file
Filepath C:\Users\test22\AppData\Roaming\Dart Communications\Power iCalconfigurator 15.3.6.2\install\E817FBF\icons\Classic\next.ico
Size 320.0B
Processes 2420 (Porcal4.exe)
Type MS Windows icon resource - 1 icon, 16x16, 16 colors
MD5 3b10b8fcaa547a823c7521c96d1f16ee
SHA1 69aa1a0f431f962245dbb6551aac80551e468339
SHA256 821064a5ad7de4e7deea4ccb04ca629f41a2b79ed01564fd3beab1d1aca06e52
CRC32 8AEC64E2
ssdeep 3:PFErXllvlNl/AXllflelusl80Hs0Fv0vsllNlt/5/5555Bj/6yl6cIp/555/:kFb8EsMsv+lt55555Bj/1rq555/
Yara None matched
VirusTotal Search for analysis
Name c9c48080f6a32ee8_DropdownIcon@125.png
Submit file
Filepath C:\Users\test22\AppData\Roaming\Dart Communications\Power iCalconfigurator 15.3.6.2\install\E817FBF\Images\DropdownIcon@125.png
Size 2.8KB
Processes 2420 (Porcal4.exe)
Type PNG image data, 11 x 11, 8-bit/color RGBA, non-interlaced
MD5 b7b129b9bedd64ab40bf3da5a0f9dc93
SHA1 cff637bc686bcc59cf954119af50e144ccec39af
SHA256 c9c48080f6a32ee8e8322b6df199e28f3c54d36a69d47813f6490dcf7c053104
CRC32 6A1EB1AF
ssdeep 48:SW7/6DocieftI9G9f6A+FIDOWu0lDl+gm7QyTtctIInQSy6IVpqlnBcODG:SISDZ/I09Da01l+gmkyTt6Hk8nTG
Yara
  • PNG_Format_Zero - PNG Format
VirusTotal Search for analysis
Name 4c9ff625b84c0a47_d12a.ico
Submit file
Filepath C:\Users\test22\AppData\Roaming\Dart Communications\Power iCalconfigurator 15.3.6.2\install\E817FBF\icons\Classic\d12a.ico
Size 1.4KB
Processes 2420 (Porcal4.exe)
Type MS Windows icon resource - 1 icon, 16x16, 255 colors, 8 bits/pixel
MD5 31ec37803822d163365fe4b536acf9cd
SHA1 d9073f03ab71152ba85515789663469c6c62dff6
SHA256 4c9ff625b84c0a47e575a1d06dbfa96e1eec66e8332971775e4cabe69e1cddef
CRC32 E121BA74
ssdeep 6:dzM1AfElbhlxgmXxoVnVaABnRnnVRnR14ftikpSgPuCf/tnn:dzeAclxXxoVVaYVjqFj2un
Yara None matched
VirusTotal Search for analysis
Name aee398a7d3a6bbc5_CloseIcon@125.png
Submit file
Filepath C:\Users\test22\AppData\Roaming\Dart Communications\Power iCalconfigurator 15.3.6.2\install\E817FBF\Images\CloseIcon@125.png
Size 2.8KB
Processes 2420 (Porcal4.exe)
Type PNG image data, 11 x 11, 8-bit/color RGBA, non-interlaced
MD5 d42ec3b301acfcda039530ee5914bf69
SHA1 dc705e5985443446e4c44f9f6588f08e28e8e330
SHA256 aee398a7d3a6bbc5204aed10c467725545355e2f264bf01b2712ef9c757b6d9b
CRC32 7EE4EA9F
ssdeep 48:SW7/6DocieftI9G9f6A+FIDOWu0lDl+gm7QyTtctIInQSy6IVpqlnBcOD01ib8V9:SISDZ/I09Da01l+gmkyTt6Hk8nT0t
Yara
  • PNG_Format_Zero - PNG Format
VirusTotal Search for analysis
Name f38b6f67c988a76c_api-ms-win-core-sysinfo-l1-1-0.dll
Submit file
Filepath C:\Users\test22\AppData\Roaming\Dart Communications\Power iCalconfigurator 15.3.6.2\install\E817FBF\api-ms-win-core-sysinfo-l1-1-0.dll
Size 10.3KB
Processes 2420 (Porcal4.exe)
Type PE32 executable (DLL) (console) Intel 80386, for MS Windows
MD5 7b4aaebda2ced4882b9c5e205ed276ce
SHA1 df6174b706961f778791628a9d5e8a3198ab6fdd
SHA256 f38b6f67c988a76c82dc8600c72865eca53f3ba48fc4b91c153092bbd642f2ad
CRC32 7F5CA635
ssdeep 192:y7QzKIMF8WthWJ068Ya5/R6t7YBBZHFzgl2cX:y8zRWthWJaPVRKU3hJkD
Yara
  • PE_Header_Zero - PE File Signature
  • OS_Processor_Check_Zero - OS Processor Check
  • IsPE32 - (no description)
  • IsDLL - (no description)
  • UPX_Zero - UPX packed file
VirusTotal Search for analysis
Name 71bacaee2c9e1fbe_PagerBackC.png
Submit file
Filepath C:\Users\test22\AppData\Roaming\Dart Communications\Power iCalconfigurator 15.3.6.2\install\E817FBF\Images\PagerBackC.png
Size 2.9KB
Processes 2420 (Porcal4.exe)
Type PNG image data, 10 x 43, 8-bit/color RGBA, non-interlaced
MD5 44018e1779270b083ad90da3dffe9b15
SHA1 e09c06b564abe26bcf91ecb7632d761c3234b30d
SHA256 71bacaee2c9e1fbe6a7184aaf9d3f8e24d6390ca62298c5da425bf060cd2bc4c
CRC32 B28B5C62
ssdeep 48:m/6DocieftI9G9f6A+FIDOWu0lDl+gm7QyTtctIInQSy6IVpqlnBcODseOfek/f:mSDZ/I09Da01l+gmkyTt6Hk8nTsZfV/f
Yara
  • PNG_Format_Zero - PNG Format
VirusTotal Search for analysis
Name d026b458432aa8bc_holder0.aiph
Submit file
Filepath C:\Users\test22\AppData\Roaming\Dart Communications\Power iCalconfigurator 15.3.6.2\install\holder0.aiph
Size 13.0MB
Type data
MD5 5c1029bc96ceb25913fde96f33f09655
SHA1 be3769aaf64395639256c4575c12ef91b9a4fb3f
SHA256 d026b458432aa8bca9a619c63b692bdbd488dd77ed56d0d1befb1acceff8c992
CRC32 F98A6765
ssdeep 3::
Yara None matched
VirusTotal Search for analysis
Name cb9d88176f730d9c_Inital0.fencelayout
Submit file
Filepath C:\Users\test22\AppData\Roaming\Dart Communications\Power iCalconfigurator 15.3.6.2\install\E817FBF\Layouts\Inital0.fencelayout
Size 1.1KB
Processes 2420 (Porcal4.exe)
Type XML 1.0 document, ASCII text, with CRLF line terminators
MD5 324113fc10df9be8b9a3fcfe4ea8aa1b
SHA1 62d141e0ca0c19485a723d215a09be3d069a74b0
SHA256 cb9d88176f730d9c638e28ce3651c2161d01610ba62485c82f76cfd71807b577
CRC32 93E41605
ssdeep 24:2dMo8PLPNj3N5m061fht4kVSYDLVSYjfVFWUqLPr2:cT8Tlj9M7IY3IYLVX
Yara None matched
VirusTotal Search for analysis
Name 1973556cbf743732_d16a.ico
Submit file
Filepath C:\Users\test22\AppData\Roaming\Dart Communications\Power iCalconfigurator 15.3.6.2\install\E817FBF\icons\New Blue\d16a.ico
Size 894.0B
Processes 2420 (Porcal4.exe)
Type MS Windows icon resource - 1 icon, 16x16, 24 bits/pixel
MD5 c2e158cbb2c529dcb500d24c2d734245
SHA1 f8d61b928f93907b3ef580c043dff9b51703173c
SHA256 1973556cbf7437326f034f982fdc325c74fc3322bc04b2e9820331600297d946
CRC32 58AA3EA9
ssdeep 12:t47v4AlJd942mOMSycsDe9Dh5tRIk2tZ9GjzZXq0M:tSLh4O8cs2tRIk2tZoj1O
Yara None matched
VirusTotal Search for analysis
Name 252fcd8feca27062_MenuIcon@125.png
Submit file
Filepath C:\Users\test22\AppData\Roaming\Dart Communications\Power iCalconfigurator 15.3.6.2\install\E817FBF\Images\MenuIcon@125.png
Size 2.8KB
Processes 2420 (Porcal4.exe)
Type PNG image data, 14 x 11, 8-bit/color RGBA, non-interlaced
MD5 1cfc5cb46beb510e902ce1ce5fddd672
SHA1 cbab23979e40390cd81d1c3f8b2d9213ba8093c8
SHA256 252fcd8feca2706206b2a8751c44e0b4b6561d6652477fd8481ffde485ae0786
CRC32 71D6EF94
ssdeep 48:pe/6DocieftI9G9f6A+FIDOWu0lDl+gm7QyTtctIInQSy6IVpqlnBcODIOf1:peSDZ/I09Da01l+gmkyTt6Hk8nTh
Yara
  • PNG_Format_Zero - PNG Format
VirusTotal Search for analysis
Name 8c893e14b95cfd0e_ConfigIcon@175.png
Submit file
Filepath C:\Users\test22\AppData\Roaming\Dart Communications\Power iCalconfigurator 15.3.6.2\install\E817FBF\Images\ConfigIcon@175.png
Size 4.6KB
Processes 2420 (Porcal4.exe)
Type PNG image data, 28 x 28, 8-bit/color RGBA, non-interlaced
MD5 f81b0ade573c74d35cb2c3323f961387
SHA1 9c00c76dab48a6de7cfd57b1988d8a8447b27902
SHA256 8c893e14b95cfd0ee58bd1e5c288dfa8516f263955e3bece794e73cf36dcfe80
CRC32 C5BC9697
ssdeep 96:tZ/I09Da01l+gmkyTt6Hk8nTsOoGiNcGsYkKwLCHt7:tS0tKg9E05TQGi+vPCHJ
Yara
  • PNG_Format_Zero - PNG Format
VirusTotal Search for analysis
Name 81b110a517724dd9_d17.ico
Submit file
Filepath C:\Users\test22\AppData\Roaming\Dart Communications\Power iCalconfigurator 15.3.6.2\install\E817FBF\icons\Classic\d17.ico
Size 1.4KB
Processes 2420 (Porcal4.exe)
Type MS Windows icon resource - 1 icon, 16x16, 8 bits/pixel
MD5 6b7ad3ce086cf0c99877ebbcdf00ca69
SHA1 cba3df1937116944de130f04abce85982d44c0aa
SHA256 81b110a517724dd92e4a5039945b10c4fd3478c9fb81e89a956a53609dc156e6
CRC32 2A34A50F
ssdeep 12:UZtu4TQ46DAOLHl+XHsiAUhjlLFF/ChkC/tZn:QXBOL3iAUhjp5CD
Yara None matched
VirusTotal Search for analysis
Name facacbd0f1e10fe8_d7.ico
Submit file
Filepath C:\Users\test22\AppData\Roaming\Dart Communications\Power iCalconfigurator 15.3.6.2\install\E817FBF\icons\New Blue\d7.ico
Size 894.0B
Processes 2420 (Porcal4.exe)
Type MS Windows icon resource - 1 icon, 16x16, 24 bits/pixel
MD5 6a3421934b23db19cd1fc06064aaf1dd
SHA1 323d73c1ee62bdfcab71f885f7211adf04b2d6a6
SHA256 facacbd0f1e10fe87c6c3c96d6d2368a326a00dd7c19437d7e30061aa90ece27
CRC32 CD6DA09C
ssdeep 12:t492zg34AmPr3Aj0MNByr6B0vTkfhve033CbdvGFMJgqzsTTTTTTTTTTTT2:t5GJNByDwfJe0PmYTTTTTTTTTTTT2
Yara None matched
VirusTotal Search for analysis
Name 64f658b918a73aca_api-ms-win-crt-runtime-l1-1-0.dll
Submit file
Filepath C:\Users\test22\AppData\Roaming\Dart Communications\Power iCalconfigurator 15.3.6.2\install\E817FBF\api-ms-win-crt-runtime-l1-1-0.dll
Size 13.8KB
Processes 2420 (Porcal4.exe)
Type PE32 executable (DLL) (console) Intel 80386, for MS Windows
MD5 aaccd10d6cedbb73496380d0d1be1798
SHA1 618279be52c0756540d22bc98fea570d591687e5
SHA256 64f658b918a73aca326cc6c9f7543d7abe1706335f7683a2e4691a37f8c146ba
CRC32 8FC27E0E
ssdeep 192:GJB0fhrpIhhf4AN5/jiDWthWf068Ya5/R6t7Yx8zBZH43z:G0hrKIWthWfaPVRKUx8lhEz
Yara
  • PE_Header_Zero - PE File Signature
  • IsPE32 - (no description)
  • IsDLL - (no description)
  • UPX_Zero - UPX packed file
VirusTotal Search for analysis
Name c566f4092c72bc27_NavigateUpIcon@200.png
Submit file
Filepath C:\Users\test22\AppData\Roaming\Dart Communications\Power iCalconfigurator 15.3.6.2\install\E817FBF\Images\NavigateUpIcon@200.png
Size 2.8KB
Processes 2420 (Porcal4.exe)
Type PNG image data, 23 x 27, 8-bit/color RGBA, non-interlaced
MD5 2694e017c3a368630b24c2f9f22e1cbf
SHA1 227cd74658ff5049d4e79514bf709976483d8a05
SHA256 c566f4092c72bc27ebb22c590664ef709a87b72399062c148eec47f1225fa15a
CRC32 2670B4C9
ssdeep 48:X/6DocieftI9G9f6A+FIDOWu0lDl+gm7QyTtctIInQSy6IVpqlnBcODYu:XSDZ/I09Da01l+gmkyTt6Hk8nT9
Yara
  • PNG_Format_Zero - PNG Format
VirusTotal Search for analysis
Name 0ad400a9c5a14c76_DropdownIcon@175.png
Submit file
Filepath C:\Users\test22\AppData\Roaming\Dart Communications\Power iCalconfigurator 15.3.6.2\install\E817FBF\Images\DropdownIcon@175.png
Size 2.8KB
Processes 2420 (Porcal4.exe)
Type PNG image data, 15 x 15, 8-bit/color RGBA, non-interlaced
MD5 d6d9236344de5f563018ffba6adf800d
SHA1 79448ab77c8031249841d89495d08d0d4447b4ae
SHA256 0ad400a9c5a14c7642f8155ce0c22de640269793bb4a16e9c03a1bdcc4e71686
CRC32 91D46BDE
ssdeep 48://6DocieftI9G9f6A+FIDOWu0lDl+gm7QyTtctIInQSy6IVpqlnBcODYcN:/SDZ/I09Da01l+gmkyTt6Hk8nTYO
Yara
  • PNG_Format_Zero - PNG Format
VirusTotal Search for analysis
Name 093b5fc30cbd4f8a_d10a.ico
Submit file
Filepath C:\Users\test22\AppData\Roaming\Dart Communications\Power iCalconfigurator 15.3.6.2\install\E817FBF\icons\New Blue\d10a.ico
Size 894.0B
Processes 2420 (Porcal4.exe)
Type MS Windows icon resource - 1 icon, 16x16, 24 bits/pixel
MD5 c090bae72316bb1eabe189ecfe7564c0
SHA1 79e372a7aaf5d95cbcf79040548803e35eda6fbd
SHA256 093b5fc30cbd4f8a28e87564bb9a367b7d2d0c477234bb39e25e5b05bbae3ad3
CRC32 4EB02642
ssdeep 12:t47v4AlZ1mOMScsXTDXrIM3otRI3Z98jtJ0M:tSLuOLcsnkM3otRI3ZWjtP
Yara None matched
VirusTotal Search for analysis
Name cfb1ab0d6ad50e6a_chinesetrad.dxs
Submit file
Filepath C:\Users\test22\AppData\Roaming\Dart Communications\Power iCalconfigurator 15.3.6.2\install\E817FBF\sprache\chinesetrad.dxs
Size 47.6KB
Processes 2420 (Porcal4.exe)
Type ISO-8859 text, with CRLF line terminators
MD5 5a9f736accd0624eb043d681fd9dab3a
SHA1 49605569f48c9f14d2c87ed524a079a48b19a6c4
SHA256 cfb1ab0d6ad50e6a9aa7a17baf3a49440155c7e866f5a8d283bf096931c11f1d
CRC32 A3720A9A
ssdeep 768:ugs4DnXKwkU018daoXk7nPEtTciRgiKB5A3hx2I5fnGZzLNIsX5Xkn5DvahS0jcl:ugs4D6wsudaoU7nPE9ciRgiKB5A3hx2Q
Yara None matched
VirusTotal Search for analysis
Name 67cd2ecda1c4d58a_FolderIcon@100.png
Submit file
Filepath C:\Users\test22\AppData\Roaming\Dart Communications\Power iCalconfigurator 15.3.6.2\install\E817FBF\Images\FolderIcon@100.png
Size 2.8KB
Processes 2420 (Porcal4.exe)
Type PNG image data, 16 x 13, 8-bit/color RGBA, non-interlaced
MD5 f9c4c7dba746e1f026e91c04580e41a3
SHA1 64dc75ad91c85f5d158ad54d984094ada64f8729
SHA256 67cd2ecda1c4d58a4d39b2959f40f75ba9d32ed9c6968379956c4b04cf45b7f3
CRC32 F7B968F4
ssdeep 48:T/6DocieftI9G9f6A+FIDOWu0lDl+gm7QyTtctIInQSy6IVpqlnBcOD5AK:TSDZ/I09Da01l+gmkyTt6Hk8nTqK
Yara
  • PNG_Format_Zero - PNG Format
VirusTotal Search for analysis
Name a8f92f025398df08_api-ms-win-core-file-l1-2-0.dll
Submit file
Filepath C:\Users\test22\AppData\Roaming\Dart Communications\Power iCalconfigurator 15.3.6.2\install\E817FBF\api-ms-win-core-file-l1-2-0.dll
Size 9.3KB
Processes 2420 (Porcal4.exe)
Type PE32 executable (DLL) (console) Intel 80386, for MS Windows
MD5 3642375d22153319c5957748b26bdd48
SHA1 89a7064c241b20dc6a2e9319590e4b2097335356
SHA256 a8f92f025398df08e6d1b3103d9b3b2f06baefe41d01619276a50b6e43ab4461
CRC32 8133B479
ssdeep 192:eaHNWthW6068Ya5/R6t7syDvxBZHT+ckB+:bNWthW6aPVRKownhp1
Yara
  • PE_Header_Zero - PE File Signature
  • IsPE32 - (no description)
  • IsDLL - (no description)
  • UPX_Zero - UPX packed file
VirusTotal Search for analysis
Name 2c4c6770441f0346_api-ms-win-core-util-l1-1-0.dll
Submit file
Filepath C:\Users\test22\AppData\Roaming\Dart Communications\Power iCalconfigurator 15.3.6.2\install\E817FBF\api-ms-win-core-util-l1-1-0.dll
Size 9.3KB
Processes 2420 (Porcal4.exe)
Type PE32 executable (DLL) (console) Intel 80386, for MS Windows
MD5 b48a159b580a21f048ffc5b90b2aa6ad
SHA1 00785243ba9341798041d6212a0779ed76c4d347
SHA256 2c4c6770441f03465509c16c1a78c6194133bb636e861e1ea09b26aad521cea2
CRC32 A9179ABE
ssdeep 96:klpEWthWw3B0EuL638yZfaQCiUkm6ybK7sfjwiS/Vi3JUfhdyEi7ZHeETf6TDb2E:0qWthWc068Ya5/R6t7s7wTCBZHX6wXC
Yara
  • PE_Header_Zero - PE File Signature
  • IsPE32 - (no description)
  • IsDLL - (no description)
  • UPX_Zero - UPX packed file
VirusTotal Search for analysis
Name 4b27f7c704c76a5c_prev.ico
Submit file
Filepath C:\Users\test22\AppData\Roaming\Dart Communications\Power iCalconfigurator 15.3.6.2\install\E817FBF\icons\Classic\prev.ico
Size 320.0B
Processes 2420 (Porcal4.exe)
Type MS Windows icon resource - 1 icon, 16x16, 16 colors
MD5 a828a027e6592a9d35488d5593501c00
SHA1 9151f61ee564342c3a16c6a8639eb6ac1888446d
SHA256 4b27f7c704c76a5c7951d8dfebed9e564ba69b1984dab5e290dd828d8a99048d
CRC32 1CA8A069
ssdeep 3:PFErXllvlNl/AXllflL1lNWktmtUM/l0ct/h/5555xBiel0OW55d:kMdIXGcth5555xB9RW55d
Yara None matched
VirusTotal Search for analysis
Name 61bb84c7a31ee9e8_CreateFence@100.png
Submit file
Filepath C:\Users\test22\AppData\Roaming\Dart Communications\Power iCalconfigurator 15.3.6.2\install\E817FBF\Images\CreateFence@100.png
Size 2.8KB
Processes 2420 (Porcal4.exe)
Type PNG image data, 16 x 15, 8-bit/color RGBA, non-interlaced
MD5 c0bef6146e2e48b4c69b9a5d739ed394
SHA1 49da14f062edfcd65f848db2697a16d24c5710a9
SHA256 61bb84c7a31ee9e82378e27103a49ebef8afda47b10318e8d34ec243f90fbf74
CRC32 E860C5D0
ssdeep 48:6/6DocieftI9G9f6A+FIDOWu0lDl+gm7QyTtctIInQSy6IVpqlnBcODqTxrxv:6SDZ/I09Da01l+gmkyTt6Hk8nT8v
Yara
  • PNG_Format_Zero - PNG Format
VirusTotal Search for analysis
Name 76c077c4a7832f2d_api-ms-win-crt-conio-l1-1-0.dll
Submit file
Filepath C:\Users\test22\AppData\Roaming\Dart Communications\Power iCalconfigurator 15.3.6.2\install\E817FBF\api-ms-win-crt-conio-l1-1-0.dll
Size 10.3KB
Processes 2420 (Porcal4.exe)
Type PE32 executable (DLL) (console) Intel 80386, for MS Windows
MD5 9c236c9e60e61a5cf6e70637a6a0e544
SHA1 93c219d6fb295f9ad9f76b34d5b2801e041d6374
SHA256 76c077c4a7832f2d4532391d486267264cdf8dedd73261cf93f3c97ac615d549
CRC32 126F9EF5
ssdeep 96:MW5pODaEWthWwOX0EuL638yZfaQCiUkm6ybK7Y6ItYPRB3JUfhdyEi7ZHeEhfSYl:NEWthWZ068Ya5/R6t7Y6IY5BZHtS3a
Yara
  • PE_Header_Zero - PE File Signature
  • IsPE32 - (no description)
  • IsDLL - (no description)
  • UPX_Zero - UPX packed file
VirusTotal Search for analysis
Name cb508acdfd23bffb_ghl
Submit file
Filepath C:\Users\test22\AppData\Roaming\Dart Communications\Power iCalconfigurator 15.3.6.2\install\E817FBF\ghl
Size 1.4MB
Processes 2420 (Porcal4.exe)
Type Composite Document File V2 Document, Little Endian, Os 0, Version: 3.10, Template: C:\OFFICEBK\NORMAL.DOT, Title: Remote Database Syncronization with Microsoft Office, Author: Reid, Ryan, Last Saved By: Reid, Ryan, Create Time/Date: Fri Jan 20 19:14:00 1995, Last Printed: Mon Feb 27 14:29:00 1995, Last Saved Time/Date: Mon Feb 27 14:31:00 1995, Number of Words: 0, Number of Characters: 0, Total Editing Time: 04:54:00, Name of Creating Application: Microsoft Word 6.0, Number of Pages: 0, Revision Number: 203, Security: 0
MD5 16de638fabbe6d9a106104a805839271
SHA1 451edadad6701860d7c0308e061b6518efb75010
SHA256 cb508acdfd23bffbbdac3070d5b6091e3d5173a3bd1ae3b52f7fa0a2758ad5d5
CRC32 9EE42E27
ssdeep 12288:d59jucNGxFSlpUsPCpUJCkO7TGU4T7Z+7jARy7bRi1KRip:d596fKl7PC2skO7SL7Zojmy7+
Yara
  • Microsoft_Office_File_Zero - Microsoft Office File
VirusTotal Search for analysis
Name 69a5abe66ef0a527_d2.ico
Submit file
Filepath C:\Users\test22\AppData\Roaming\Dart Communications\Power iCalconfigurator 15.3.6.2\install\E817FBF\icons\Classic\d2.ico
Size 1.4KB
Processes 2420 (Porcal4.exe)
Type MS Windows icon resource - 1 icon, 16x16, 8 bits/pixel
MD5 485d0e5a19fa5d97f3fc12ea4a9b539f
SHA1 408bc0848a47fb36c9b1f5d1c5928855dedb58cc
SHA256 69a5abe66ef0a5273ae6667b45d59bd4ba34f9f634ae317bbb58af075fef7d77
CRC32 8D2E3F73
ssdeep 6:UZxMcE2jS4Tfl+46EcAOBNHlfmXpEBiWOzWxplRsUlNSmv0504wmM/tH5n:UZtu4TQ46DAOLHl+XWi/zYlVQ0//tZn
Yara None matched
VirusTotal Search for analysis
Name ae7d82a48f833dc6_NavigateUpIcon@300.png
Submit file
Filepath C:\Users\test22\AppData\Roaming\Dart Communications\Power iCalconfigurator 15.3.6.2\install\E817FBF\Images\NavigateUpIcon@300.png
Size 2.8KB
Processes 2420 (Porcal4.exe)
Type PNG image data, 33 x 39, 8-bit/color RGBA, non-interlaced
MD5 f2fba9c4640459012af40583448984ee
SHA1 a2c2c7ba0d81bd7e6afd6833346b4459d7e754fc
SHA256 ae7d82a48f833dc6a59634abdabfddf42c23cce83777e1ee35c71de88038d561
CRC32 EBFDE5A5
ssdeep 48:Q/6DocieftI9G9f6A+FIDOWu0lDl+gm7QyTtctIInQSy6IVpqlnBcODyR:QSDZ/I09Da01l+gmkyTt6Hk8nT2
Yara
  • PNG_Format_Zero - PNG Format
VirusTotal Search for analysis
Name ca8b77453956c745_msvcp140_atomic_wait.dll
Submit file
Filepath C:\Users\test22\AppData\Roaming\Dart Communications\Power iCalconfigurator 15.3.6.2\install\E817FBF\msvcp140_atomic_wait.dll
Size 48.8KB
Processes 2420 (Porcal4.exe)
Type PE32 executable (DLL) (console) Intel 80386, for MS Windows
MD5 3fc0a8ee9e8ad8bfdeb69fac53110d3a
SHA1 e9aeae5b328add59a5652e14f0c38644c22de95e
SHA256 ca8b77453956c745895723b83aacc826f71843be05cde9549cb8fc495ffa2084
CRC32 98AC872C
ssdeep 384:lH1TFwTSloNYcSNXR5cHDIABta/FWFvug0yiT3UN9imfI/NVW0jdTp0Fzenw3GDf:9VT9kNWNLT2wwWDpQJmL0cM8+DFhS
Yara
  • PE_Header_Zero - PE File Signature
  • OS_Processor_Check_Zero - OS Processor Check
  • IsPE32 - (no description)
  • IsDLL - (no description)
  • UPX_Zero - UPX packed file
  • Win32_Trojan_Gen_1_0904B0_Zero - Win32 Trojan Emotet
VirusTotal Search for analysis
Name 081ec614b4222b12_DropdownIcon@200.png
Submit file
Filepath C:\Users\test22\AppData\Roaming\Dart Communications\Power iCalconfigurator 15.3.6.2\install\E817FBF\Images\DropdownIcon@200.png
Size 2.8KB
Processes 2420 (Porcal4.exe)
Type PNG image data, 17 x 17, 8-bit/color RGBA, non-interlaced
MD5 2a184b72fe59b255bde8c848399a985e
SHA1 601013824463b63516028a9b5ce9cc5159502217
SHA256 081ec614b4222b123cb7f9c28147c13e2d8692d56d8e6dea7bafb3d843b387d1
CRC32 A1BCD550
ssdeep 48:K/6DocieftI9G9f6A+FIDOWu0lDl+gm7QyTtctIInQSy6IVpqlnBcODPx:KSDZ/I09Da01l+gmkyTt6Hk8nTZ
Yara
  • PNG_Format_Zero - PNG Format
VirusTotal Search for analysis
Name 5b756a48762ad896_eula.txt
Submit file
Filepath C:\Users\test22\AppData\Roaming\Dart Communications\Power iCalconfigurator 15.3.6.2\install\E817FBF\eula.txt
Size 10.6KB
Processes 2420 (Porcal4.exe)
Type ISO-8859 text, with very long lines, with CRLF line terminators
MD5 b255e01ecedad3f7a600109b01943074
SHA1 0896cbd77645152c4c867e585ba2475af9e9819c
SHA256 5b756a48762ad896de58b973e4b87d4e76ff25023a727f0a08aad9ea66e7b843
CRC32 50E59815
ssdeep 192:U2fLhLofP/c/EqBN/5Md/mvLuoMLed0DyF+o01lOtoQKKVt3ZofFghP/OLo:UJKE+2ycsV6sHOLo
Yara None matched
VirusTotal Search for analysis
Name 636c9a548269d1aa_MenuIcon@325.png
Submit file
Filepath C:\Users\test22\AppData\Roaming\Dart Communications\Power iCalconfigurator 15.3.6.2\install\E817FBF\Images\MenuIcon@325.png
Size 2.8KB
Processes 2420 (Porcal4.exe)
Type PNG image data, 36 x 29, 8-bit/color RGBA, non-interlaced
MD5 4446b53d8c6bf3d5c319c023cca3d9d3
SHA1 b5eabc3008eb4b3e81a8b6cc9d6a884b9650ce18
SHA256 636c9a548269d1aae89aeb530aa7837caf36a4432896ebcc5eb102938cd0db59
CRC32 5316F855
ssdeep 48:W/6DocieftI9G9f6A+FIDOWu0lDl+gm7QyTtctIInQSy6IVpqlnBcODz:WSDZ/I09Da01l+gmkyTt6Hk8nTz
Yara
  • PNG_Format_Zero - PNG Format
VirusTotal Search for analysis
Name 3c5db91ef77b947a_MSIE15.tmp
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\MSIE15.tmp
Size 866.5KB
Processes 2420 (Porcal4.exe)
Type PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
MD5 0be6e02d01013e6140e38571a4da2545
SHA1 9149608d60ca5941010e33e01d4fdc7b6c791bea
SHA256 3c5db91ef77b947a0924675fc1ec647d6512287aa891040b6ade3663aa1fd3a3
CRC32 B964BC08
ssdeep 24576:gJgZXlAIjfQhETbF+RWQNgXAo1sVz1v0Mny+PkfsJJ10FRzVTv:F/fQhksQQNgXAo1sVzhly+PkfsJJ10FT
Yara
  • Malicious_Packer_Zero - Malicious Packer
  • Antivirus - Contains references to security software
  • PE_Header_Zero - PE File Signature
  • OS_Processor_Check_Zero - OS Processor Check
  • IsPE32 - (no description)
  • Win32_Trojan_Gen_2_0904B0_Zero - Win32 Trojan Gen
  • IsDLL - (no description)
  • Malicious_Library_Zero - Malicious_Library
  • UPX_Zero - UPX packed file
VirusTotal Search for analysis
Name af0b508bf473ed7a_api-ms-win-core-errorhandling-l1-1-0.dll
Submit file
Filepath C:\Users\test22\AppData\Roaming\Dart Communications\Power iCalconfigurator 15.3.6.2\install\E817FBF\api-ms-win-core-errorhandling-l1-1-0.dll
Size 9.3KB
Processes 2420 (Porcal4.exe)
Type PE32 executable (DLL) (console) Intel 80386, for MS Windows
MD5 c628029a06bec677987878316d35d76c
SHA1 44de9747cf7860764c3fe7bfc9e398e408667212
SHA256 af0b508bf473ed7a41830df33e49924aee30287471c8cef395e5b467a3c29de2
CRC32 CF88034A
ssdeep 192:JamxD33WthWd068Ya5/R6t7Y8vBZHWaV+9Zd:JaUWthWdaPVRKU8phMZd
Yara
  • PE_Header_Zero - PE File Signature
  • IsPE32 - (no description)
  • IsDLL - (no description)
  • UPX_Zero - UPX packed file
VirusTotal Search for analysis
Name a201e83843bc5888_DropdownIcon@350.png
Submit file
Filepath C:\Users\test22\AppData\Roaming\Dart Communications\Power iCalconfigurator 15.3.6.2\install\E817FBF\Images\DropdownIcon@350.png
Size 2.8KB
Processes 2420 (Porcal4.exe)
Type PNG image data, 31 x 31, 8-bit/color RGBA, non-interlaced
MD5 c11b1b120b0605ce5f5d2664ed8d2288
SHA1 dca31fea7f3ab67b6051f569433de887ce475aa7
SHA256 a201e83843bc58883f6e5d677100e76cb72c2ea27ad0e5df4d48c414d1ba7108
CRC32 9BBC0613
ssdeep 48:l/6DocieftI9G9f6A+FIDOWu0lDl+gm7QyTtctIInQSy6IVpqlnBcODYJJ:lSDZ/I09Da01l+gmkyTt6Hk8nTU
Yara
  • PNG_Format_Zero - PNG Format
VirusTotal Search for analysis
Name 530ed16c0f03365f_d7a.ico
Submit file
Filepath C:\Users\test22\AppData\Roaming\Dart Communications\Power iCalconfigurator 15.3.6.2\install\E817FBF\icons\Classic\d7a.ico
Size 1.4KB
Processes 2420 (Porcal4.exe)
Type MS Windows icon resource - 1 icon, 16x16, 255 colors, 8 bits/pixel
MD5 66f742d0350e850d3b17e745c4485508
SHA1 37babcfb7a917620aa948c355fe2e79c937b7ce6
SHA256 530ed16c0f03365f0087aeaff8b2639327ac29c0db0aa4692852d085549fa2d6
CRC32 AF7BD3B1
ssdeep 6:dzM/A7o3boClBlvPXBoVnVnRnVnRnVnRn1mfeNPps/wAhIR/tnn:dz8AMbdlzPXBoVVRVRVR0feNswAhCn
Yara None matched
VirusTotal Search for analysis
Name 1b0f40b0b03cf5bb_DropdownIcon@275.png
Submit file
Filepath C:\Users\test22\AppData\Roaming\Dart Communications\Power iCalconfigurator 15.3.6.2\install\E817FBF\Images\DropdownIcon@275.png
Size 2.8KB
Processes 2420 (Porcal4.exe)
Type PNG image data, 25 x 25, 8-bit/color RGBA, non-interlaced
MD5 5164cfdd2f56249dbd42a7b85ed63a76
SHA1 c2660917e479f7eefe1c015e88b36e96b3819db3
SHA256 1b0f40b0b03cf5bb82c00b78126f4cdb3339a360964e27bc9f4e2b03517d79a2
CRC32 5A31ACAC
ssdeep 48:I/6DocieftI9G9f6A+FIDOWu0lDl+gm7QyTtctIInQSy6IVpqlnBcODuWiJB:ISDZ/I09Da01l+gmkyTt6Hk8nTuWi3
Yara
  • PNG_Format_Zero - PNG Format
VirusTotal Search for analysis
Name 669bbba40321ac97_TopLeftAndRight.fencelayout
Submit file
Filepath C:\Users\test22\AppData\Roaming\Dart Communications\Power iCalconfigurator 15.3.6.2\install\E817FBF\Layouts\TopLeftAndRight.fencelayout
Size 1.8KB
Processes 2420 (Porcal4.exe)
Type XML 1.0 document, ASCII text, with CRLF line terminators
MD5 5a7510511837d22c9615f2c5fcb5ffec
SHA1 0e6fc86ec445522d6831fb7d0258638d7d5d01f8
SHA256 669bbba40321ac97795538d0ded99c8043a3d6f867cfed3cb313effb9d69bb9f
CRC32 62D8B825
ssdeep 24:2dX8ZPNj3N5u61fhQgLVSYkVSYVNXgWUqL/hnW6kVSYDLVSYjfVFWUqLP82:cX8Zlj9NIYkIYfX/WNIY3IYLV6
Yara None matched
VirusTotal Search for analysis
Name b7f86ed3fc0e0c1e_api-ms-win-core-namedpipe-l1-1-0.dll
Submit file
Filepath C:\Users\test22\AppData\Roaming\Dart Communications\Power iCalconfigurator 15.3.6.2\install\E817FBF\api-ms-win-core-namedpipe-l1-1-0.dll
Size 9.3KB
Processes 2420 (Porcal4.exe)
Type PE32 executable (DLL) (console) Intel 80386, for MS Windows
MD5 ff8ac9369e35ca91a89dbb8ae2a35c39
SHA1 0a5857f0efa423081df4430273fdfd3b740b933f
SHA256 b7f86ed3fc0e0c1eb05da96d47f3336be705ef8a622d8fd8bbf1030074987691
CRC32 92AD6D9E
ssdeep 96:VHEWthWw3it0EuL638yZfaQCiUkm6ybK7s96HfOe3JUfhdyEi7ZHeEJf/cF2:GWthWjt068Ya5/R6t7soHfHBZH1/c2
Yara
  • PE_Header_Zero - PE File Signature
  • IsPE32 - (no description)
  • IsDLL - (no description)
  • UPX_Zero - UPX packed file
VirusTotal Search for analysis
Name 4febd01d738ec425_d1.ico
Submit file
Filepath C:\Users\test22\AppData\Roaming\Dart Communications\Power iCalconfigurator 15.3.6.2\install\E817FBF\icons\New Blue\d1.ico
Size 894.0B
Processes 2420 (Porcal4.exe)
Type MS Windows icon resource - 1 icon, 16x16, 24 bits/pixel
MD5 d100902fd3e4ea4b91fb16b5220f700f
SHA1 5797cd6b66c5ce6ac572313a45202a252214b2c5
SHA256 4febd01d738ec425d0c13f96f2a2f3239af29bf21dfd7de8019e701e99ee6d71
CRC32 CD5119B2
ssdeep 12:t492lcagO/4CIxMNgLO6y4yagveizHGUzRgqzsTTTTTTTTTTTT2:t5l53NgLIaYeijGUzPYTTTTTTTTTTTT2
Yara None matched
VirusTotal Search for analysis
Name 01be522215c38e1f_d16.ico
Submit file
Filepath C:\Users\test22\AppData\Roaming\Dart Communications\Power iCalconfigurator 15.3.6.2\install\E817FBF\icons\Classic\d16.ico
Size 1.4KB
Processes 2420 (Porcal4.exe)
Type MS Windows icon resource - 1 icon, 16x16, 8 bits/pixel
MD5 2b3f565016ce82499138d3456956ab92
SHA1 9f0b5cfc534177bd8dce50dab846e9cc084c587f
SHA256 01be522215c38e1ffcbc4e83f35138a1c3b5698afc49bbe26421ff70f9d1449c
CRC32 4371FED9
ssdeep 12:H5tu4TQ46DAOLHl+XW8uFPt/GXI7/kV/tZn:DXBOLTFFCI7MD
Yara None matched
VirusTotal Search for analysis
Name ae38e8325d0ad1fc_Bottom.fencelayout
Submit file
Filepath C:\Users\test22\AppData\Roaming\Dart Communications\Power iCalconfigurator 15.3.6.2\install\E817FBF\Layouts\Bottom.fencelayout
Size 838.0B
Processes 2420 (Porcal4.exe)
Type XML 1.0 document, ASCII text, with CRLF line terminators
MD5 c0969fdbaae430f6c0f53731e86d8bd8
SHA1 9dbe36aa40adb1543569564be6451c0a44d5d11c
SHA256 ae38e8325d0ad1fcbc90e5a67e9867c6c98fc11223cbaea19627fb0a04d79c33
CRC32 376D36D6
ssdeep 12:TMHd/f8iPiEINBENBitAnAXlAjAXyCNSOwuXSKH9VSYDTfVSYSWqjkxeb/YkswO8:2dX8FNONq1fhvrVSYDLVSYVUWSqLPvM
Yara None matched
VirusTotal Search for analysis
Name e491f858aff7245e_d20.ico
Submit file
Filepath C:\Users\test22\AppData\Roaming\Dart Communications\Power iCalconfigurator 15.3.6.2\install\E817FBF\icons\New Blue\d20.ico
Size 894.0B
Processes 2420 (Porcal4.exe)
Type MS Windows icon resource - 1 icon, 16x16, 24 bits/pixel
MD5 2ab54235b910beffc8680d3983a42347
SHA1 733f70c2ff19c8b1fdd18f97a82d852aff6399e2
SHA256 e491f858aff7245e687dfbb17ef4d7e2fe78f76b10ecaeda7dd383f8fc7c0596
CRC32 F4089668
ssdeep 12:t49lQSLLTYwPdGhhF1XuBQBXbLuJqzsTTTTTTTTTTTT2:tyxLYed4hF1esbLuMYTTTTTTTTTTTT2
Yara None matched
VirusTotal Search for analysis
Name 0472f1348a793a48_d9.ico
Submit file
Filepath C:\Users\test22\AppData\Roaming\Dart Communications\Power iCalconfigurator 15.3.6.2\install\E817FBF\icons\Classic\d9.ico
Size 1.4KB
Processes 2420 (Porcal4.exe)
Type MS Windows icon resource - 1 icon, 16x16, 8 bits/pixel
MD5 c5603d47c4fbbc98375f8eb39373f814
SHA1 02e2819808a3778517cbb3d8b4dae135770f8ecd
SHA256 0472f1348a793a487c49ba50eef3c2726fadcd80866c654cebb60be64a60871e
CRC32 D0DBF880
ssdeep 6:UZxMcE2jS4Tfl+46EcAOBNHlfmXpxrWWT0NSLdl38Hw0mM/tH5n:UZtu4TQ46DAOLHl+XDrBT0N5/tZn
Yara None matched
VirusTotal Search for analysis
Name 3da4719d3b827497_d8.ico
Submit file
Filepath C:\Users\test22\AppData\Roaming\Dart Communications\Power iCalconfigurator 15.3.6.2\install\E817FBF\icons\Classic\d8.ico
Size 1.4KB
Processes 2420 (Porcal4.exe)
Type MS Windows icon resource - 1 icon, 16x16, 8 bits/pixel
MD5 62a1be3e4d6a3b217b8bcfc8d90d5360
SHA1 699f7dc64ba2a9eb94790076673478968d3b8934
SHA256 3da4719d3b8274973b54a29484b579fb9b7380c1aaf7a2e1527a02d732e456fe
CRC32 759C0772
ssdeep 12:UZtu4TQ46DAOLHl+XDPhXlClLEQ0//tZn:QXBOL2hXCEZ/D
Yara None matched
VirusTotal Search for analysis
Name 0dc72cef95c629d2_d10.ico
Submit file
Filepath C:\Users\test22\AppData\Roaming\Dart Communications\Power iCalconfigurator 15.3.6.2\install\E817FBF\icons\New Blue\d10.ico
Size 894.0B
Processes 2420 (Porcal4.exe)
Type MS Windows icon resource - 1 icon, 16x16, 24 bits/pixel
MD5 3abe8b8bae3e97fd78439f1641a6eb7f
SHA1 26363c3f4e7e3379daefba983a04bb3ce90f6bd8
SHA256 0dc72cef95c629d2694268c8e1ce3f52045af6e327922c536c1229764716612a
CRC32 24F96F45
ssdeep 24:t5VtSs7gDWl3cRIDwtMYTTTTTTTTTTTT2:VIs7gDCsR0wKYTTTTTTTTTTTT2
Yara None matched
VirusTotal Search for analysis
Name 02425b1451af5b47_msvcp140_1.dll
Submit file
Filepath C:\Users\test22\AppData\Roaming\Dart Communications\Power iCalconfigurator 15.3.6.2\install\E817FBF\msvcp140_1.dll
Size 18.8KB
Processes 2420 (Porcal4.exe)
Type PE32 executable (DLL) (console) Intel 80386, for MS Windows
MD5 3e79e6d7c9bd8eb75d66d3496b315787
SHA1 7b3555c8d64dfbf63e4aee0c892437957c67ad76
SHA256 02425b1451af5b47fd8949c27d6d3d1b51fda126b0f075000c04dbd50ef32420
CRC32 F02AB185
ssdeep 384:JN2dXmpNhYQjsy3d9Wc65gW6faPVRKo0hy7A:JQ6gFyWhWhyk
Yara
  • PE_Header_Zero - PE File Signature
  • OS_Processor_Check_Zero - OS Processor Check
  • IsPE32 - (no description)
  • IsDLL - (no description)
  • UPX_Zero - UPX packed file
VirusTotal Search for analysis
Name 0d8d1fd9a5e49101_DropdownIcon@150.png
Submit file
Filepath C:\Users\test22\AppData\Roaming\Dart Communications\Power iCalconfigurator 15.3.6.2\install\E817FBF\Images\DropdownIcon@150.png
Size 2.8KB
Processes 2420 (Porcal4.exe)
Type PNG image data, 13 x 13, 8-bit/color RGBA, non-interlaced
MD5 3601ae1d4b61bfc1251355109621bdd5
SHA1 12f8fa21a497f41e39fdcfcf57eb5120b0eb27af
SHA256 0d8d1fd9a5e49101a70f0f6cfc662dace73867173a69bb1b84fc04ba5985ebc6
CRC32 330082CC
ssdeep 48:M/6DocieftI9G9f6A+FIDOWu0lDl+gm7QyTtctIInQSy6IVpqlnBcODPHYl:MSDZ/I09Da01l+gmkyTt6Hk8nTm
Yara
  • PNG_Format_Zero - PNG Format
VirusTotal Search for analysis
Name d57548703ee0d54d_d20a.ico
Submit file
Filepath C:\Users\test22\AppData\Roaming\Dart Communications\Power iCalconfigurator 15.3.6.2\install\E817FBF\icons\New Blue\d20a.ico
Size 894.0B
Processes 2420 (Porcal4.exe)
Type MS Windows icon resource - 1 icon, 16x16, 24 bits/pixel
MD5 685a2f3accedfd21e8df8e1c10aaa424
SHA1 34e4fd92af0069212c851fe5d6bcffc7df442cbb
SHA256 d57548703ee0d54d6c4b850763ca3058af9a89a7e336eae3a3a23440cf44246d
CRC32 9E41DF6F
ssdeep 12:t47v4/Q1qBlLxVTDu8dGhrF1XuBoZBX5ve4uJ0M:tSyxlL+8d4rF1eeT5ve4uP
Yara None matched
VirusTotal Search for analysis
Name 2b601e50c9347ec7_d17a.ico
Submit file
Filepath C:\Users\test22\AppData\Roaming\Dart Communications\Power iCalconfigurator 15.3.6.2\install\E817FBF\icons\Classic\d17a.ico
Size 1.4KB
Processes 2420 (Porcal4.exe)
Type MS Windows icon resource - 1 icon, 16x16, 255 colors, 8 bits/pixel
MD5 c3aab894c2db5d318ff0ee006dfd94fd
SHA1 b9c2dbaa04695f6368dd0f09871cb57060f94349
SHA256 2b601e50c9347ec7966dc1db43157667ee049e138a5e45228f5c6166c5b4c47b
CRC32 45914287
ssdeep 6:dz4mY3OSl55wE1pXBoVnVttnRnnRthBnRtTLOUjtBLt/e1KY/tnn:dzZY3OW553XBoVVt5TThVtBLt/eLn
Yara None matched
VirusTotal Search for analysis
Name 145131ede3526a3f_api-ms-win-core-synch-l1-2-0.dll
Submit file
Filepath C:\Users\test22\AppData\Roaming\Dart Communications\Power iCalconfigurator 15.3.6.2\install\E817FBF\api-ms-win-core-synch-l1-2-0.dll
Size 9.8KB
Processes 2420 (Porcal4.exe)
Type PE32 executable (DLL) (console) Intel 80386, for MS Windows
MD5 9fb78b09692ad0cee8b5cd283c6ca56f
SHA1 b359f653bef423950c05daa3b3e3c5bc2874576e
SHA256 145131ede3526a3fc6b4cb3abdc00514bca52cf7b5a7696ffb0ed8e7c0aa7834
CRC32 94D93ECD
ssdeep 192:9Y3ZDQtZ34WthWWf068Ya5/R6t7sFBZHzYL:9Y3ZDQtZ34WthWGaPVRKoDhkL
Yara
  • PE_Header_Zero - PE File Signature
  • IsPE32 - (no description)
  • IsDLL - (no description)
  • UPX_Zero - UPX packed file
VirusTotal Search for analysis
Name 333307048a93f4fa_ConfigIcon@125.png
Submit file
Filepath C:\Users\test22\AppData\Roaming\Dart Communications\Power iCalconfigurator 15.3.6.2\install\E817FBF\Images\ConfigIcon@125.png
Size 703.0B
Processes 2420 (Porcal4.exe)
Type PNG image data, 20 x 20, 8-bit/color RGBA, non-interlaced
MD5 b26dec1a2e40b83920fb139e8dcdd7d8
SHA1 138ac87485192cef25f033c18cb72413cd9d6120
SHA256 333307048a93f4fa05d55525751f297df8451feee3c7149864d40bf95748c09a
CRC32 C44882BB
ssdeep 12:6v/7i/W4IOW17fyFDSEfag6G1kpP8NxvHQhdKdqe7QYk/NaE3R8/sUoZrJ5oph7l:O4IjD8aBGSSwhIdr7QJ/NaEKsU0Jkic
Yara
  • PNG_Format_Zero - PNG Format
VirusTotal Search for analysis
Name 30691cd0dfdae6a8_d15a.ico
Submit file
Filepath C:\Users\test22\AppData\Roaming\Dart Communications\Power iCalconfigurator 15.3.6.2\install\E817FBF\icons\Classic\d15a.ico
Size 1.4KB
Processes 2420 (Porcal4.exe)
Type MS Windows icon resource - 1 icon, 16x16, 255 colors, 8 bits/pixel
MD5 5cff4ead560d10ade1f0cc8ed1d713a8
SHA1 891fd856a822012e7c8912f6f4ed8607cad281b9
SHA256 30691cd0dfdae6a83cf41838564254b3319ffb79e37b937ea9aea3120c96704c
CRC32 F600B22D
ssdeep 6:dz4mY3OSl55KkE1pXRoVnVlRkinRnLnjLSUtBV/ew3Dm8FwV/tnn:dzZY3OW55KbXRoVV35fFVWCDm8FwTn
Yara None matched
VirusTotal Search for analysis
Name 133d046a4fe796f8_CloseIcon@175.png
Submit file
Filepath C:\Users\test22\AppData\Roaming\Dart Communications\Power iCalconfigurator 15.3.6.2\install\E817FBF\Images\CloseIcon@175.png
Size 2.8KB
Processes 2420 (Porcal4.exe)
Type PNG image data, 15 x 15, 8-bit/color RGBA, non-interlaced
MD5 cc7f410250697d82bdd5d01baf6f9d83
SHA1 c29a67f5735bedb4e790230e686fd590c6ed00e2
SHA256 133d046a4fe796f8d9d218c93db7b9dafe430af41eae37235a32c4f074463438
CRC32 E7796DDC
ssdeep 48://6DocieftI9G9f6A+FIDOWu0lDl+gm7QyTtctIInQSy6IVpqlnBcODpeJ9:/SDZ/I09Da01l+gmkyTt6Hk8nTA9
Yara
  • PNG_Format_Zero - PNG Format
VirusTotal Search for analysis
Name b41c17b43059cbc4_FolderIcon@225.png
Submit file
Filepath C:\Users\test22\AppData\Roaming\Dart Communications\Power iCalconfigurator 15.3.6.2\install\E817FBF\Images\FolderIcon@225.png
Size 2.8KB
Processes 2420 (Porcal4.exe)
Type PNG image data, 36 x 33, 8-bit/color RGBA, non-interlaced
MD5 0daafceb62bde7513c8b821a1b2d75b1
SHA1 0e042ec24092cb67e5ea50848346c0e2e8911278
SHA256 b41c17b43059cbc4ba0997aa0ae64663947320bc6978452f164d916461d431eb
CRC32 3096DB67
ssdeep 48:hW/6DocieftI9G9f6A+FIDOWu0lDl+gm7QyTtctIInQSy6IVpqlnBcODdYP:hWSDZ/I09Da01l+gmkyTt6Hk8nTdI
Yara
  • PNG_Format_Zero - PNG Format
VirusTotal Search for analysis
Name c5666b5643544b11_FolderIcon@350.png
Submit file
Filepath C:\Users\test22\AppData\Roaming\Dart Communications\Power iCalconfigurator 15.3.6.2\install\E817FBF\Images\FolderIcon@350.png
Size 2.8KB
Processes 2420 (Porcal4.exe)
Type PNG image data, 56 x 46, 8-bit/color RGBA, non-interlaced
MD5 a7147f2739655be5dd74ebc06b4d3944
SHA1 5d9790738c589d3708a5d9509bad0307cdb33080
SHA256 c5666b5643544b110b8b68929369a16c7cf20c9dfa586f56c97f60f87bd513e8
CRC32 338F3471
ssdeep 48:P/6DocieftI9G9f6A+FIDOWu0lDl+gm7QyTtctIInQSy6IVpqlnBcOD1B:PSDZ/I09Da01l+gmkyTt6Hk8nT1B
Yara
  • PNG_Format_Zero - PNG Format
VirusTotal Search for analysis
Name c8dbd811bb85d7e1_ucrtbase.dll
Submit file
Filepath C:\Users\test22\AppData\Roaming\Dart Communications\Power iCalconfigurator 15.3.6.2\install\E817FBF\ucrtbase.dll
Size 1.1MB
Processes 2420 (Porcal4.exe)
Type PE32 executable (DLL) (console) Intel 80386, for MS Windows
MD5 df160b9471e9ce9aa4efcfe625673310
SHA1 54d14ace2f00a93c28984a577ebb47929d29e3cf
SHA256 c8dbd811bb85d7e17d457c7938c15ef39dbde395f82e967387e082f2c9860748
CRC32 C1DCED69
ssdeep 24576:uWiJOihSAdUDRdwE0OBuE4N7qWkGA+g7lyD6ZQtnmcvIZPoy4c1cF4w+:9iJOihSlDxuNN7qLZyD6yt01c1+
Yara
  • PE_Header_Zero - PE File Signature
  • OS_Processor_Check_Zero - OS Processor Check
  • IsPE32 - (no description)
  • Win32_Trojan_Gen_2_0904B0_Zero - Win32 Trojan Gen
  • IsDLL - (no description)
  • Malicious_Library_Zero - Malicious_Library
  • UPX_Zero - UPX packed file
  • Win32_Trojan_Gen_1_0904B0_Zero - Win32 Trojan Emotet
VirusTotal Search for analysis
Name eb7d51d9ebd69dad_d11.ico
Submit file
Filepath C:\Users\test22\AppData\Roaming\Dart Communications\Power iCalconfigurator 15.3.6.2\install\E817FBF\icons\New Blue\d11.ico
Size 894.0B
Processes 2420 (Porcal4.exe)
Type MS Windows icon resource - 1 icon, 16x16, 24 bits/pixel
MD5 1726cd6a53d23cfc378aaa98067c1bde
SHA1 f0d0ce6cacd02b5edb900554e0818816fcbcf920
SHA256 eb7d51d9ebd69dade1f6cab7579ce4eb88ede5ce19707e324841a9787cb41da4
CRC32 4395BDC0
ssdeep 24:t5tNKq2QPydc8hvtCRD0TOYTTTTTTTTTTTT2:d2QPye8hQRDSOYTTTTTTTTTTTT2
Yara None matched
VirusTotal Search for analysis
Name 9ede4d642cf8dab6_NavigateUpIcon@350.png
Submit file
Filepath C:\Users\test22\AppData\Roaming\Dart Communications\Power iCalconfigurator 15.3.6.2\install\E817FBF\Images\NavigateUpIcon@350.png
Size 2.9KB
Processes 2420 (Porcal4.exe)
Type PNG image data, 39 x 46, 8-bit/color RGBA, non-interlaced
MD5 1e1890595ce5947901572b8cced431a0
SHA1 db40a9012dbbaf0bb5aecc96394aeb0fe9c0a4c4
SHA256 9ede4d642cf8dab69ee4519f58c3dc367fc774f912cc12db8eda711b9379590d
CRC32 B111B422
ssdeep 48:cj/6DocieftI9G9f6A+FIDOWu0lDl+gm7QyTtctIInQSy6IVpqlnBcODOne7z:+SDZ/I09Da01l+gmkyTt6Hk8nTOe/
Yara
  • PNG_Format_Zero - PNG Format
VirusTotal Search for analysis
Name f3c0f3190836bb96_CloseIcon@275.png
Submit file
Filepath C:\Users\test22\AppData\Roaming\Dart Communications\Power iCalconfigurator 15.3.6.2\install\E817FBF\Images\CloseIcon@275.png
Size 2.8KB
Processes 2420 (Porcal4.exe)
Type PNG image data, 25 x 25, 8-bit/color RGBA, non-interlaced
MD5 e8eedb9962ec4e13890a85dfe6300736
SHA1 72daed37d275a0ab13fd544db204fed308967ef5
SHA256 f3c0f3190836bb96e289d0df83b4a94a5aa9223e230775db5dec8c98afc7f949
CRC32 AC0A756B
ssdeep 48:I/6DocieftI9G9f6A+FIDOWu0lDl+gm7QyTtctIInQSy6IVpqlnBcOD3QsD:ISDZ/I09Da01l+gmkyTt6Hk8nTgsD
Yara
  • PNG_Format_Zero - PNG Format
VirusTotal Search for analysis
Name 33837c2984d6e640_MenuIcon@350.png
Submit file
Filepath C:\Users\test22\AppData\Roaming\Dart Communications\Power iCalconfigurator 15.3.6.2\install\E817FBF\Images\MenuIcon@350.png
Size 2.8KB
Processes 2420 (Porcal4.exe)
Type PNG image data, 39 x 31, 8-bit/color RGBA, non-interlaced
MD5 959e595a416a1475e453430fd61eaf20
SHA1 2cf0d3225eb015f4d6de23bad9274b102ea56e1f
SHA256 33837c2984d6e640076cf883eadcf6dc011d870c7ec03b6f786b4ad4ad82cff2
CRC32 A6198DAE
ssdeep 48:G/6DocieftI9G9f6A+FIDOWu0lDl+gm7QyTtctIInQSy6IVpqlnBcODyfPc:GSDZ/I09Da01l+gmkyTt6Hk8nT+c
Yara
  • PNG_Format_Zero - PNG Format
VirusTotal Search for analysis
Name ea0859583bb60fb8_powersnmp.exe
Submit file
Filepath C:\Users\test22\AppData\Roaming\Dart Communications\Power iCalconfigurator 15.3.6.2\install\E817FBF\powersnmp.exe
Size 237.8KB
Processes 2420 (Porcal4.exe)
Type PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
MD5 34d5811141e1d515b544fb7d62bcf079
SHA1 861d5104b3e5b721ca289fff4ebf3afa0cc4166a
SHA256 ea0859583bb60fb8b26b6d9f056b00b509aedac38296708a9173639ba3ce8045
CRC32 157FE74B
ssdeep 3072:8sVhtuGA0WKyHHHHsHHHHOhlYCYHYYYYYYYYYYYHYYYYYYYYYYYHYYYYYYYYYYYE:5Ttu8wPfVzQXpEhk
Yara
  • PE_Header_Zero - PE File Signature
  • Generic_Malware_Zero - Generic Malware
  • OS_Processor_Check_Zero - OS Processor Check
  • IsPE32 - (no description)
  • Is_DotNET_EXE - (no description)
  • Malicious_Library_Zero - Malicious_Library
  • UPX_Zero - UPX packed file
  • Win_Backdoor_AsyncRAT_Zero - Win Backdoor AsyncRAT
  • Win32_Trojan_Gen_1_0904B0_Zero - Win32 Trojan Emotet
VirusTotal Search for analysis
Name dfb2aa4d0394593d_d8.ico
Submit file
Filepath C:\Users\test22\AppData\Roaming\Dart Communications\Power iCalconfigurator 15.3.6.2\install\E817FBF\icons\New Blue\d8.ico
Size 894.0B
Processes 2420 (Porcal4.exe)
Type MS Windows icon resource - 1 icon, 16x16, 24 bits/pixel
MD5 863fc1fc69f4097b88ea16d7e920ebad
SHA1 8fee0b04b0a858272195d5b06a45c1ab07bdf2f4
SHA256 dfb2aa4d0394593dd76fe9014ee47d8435d482cd8577bf1a299e72a517e9e9da
CRC32 6FBDE9AE
ssdeep 12:t492lqXI/PuGO4tj5zTveuMnUA1gqzsTTTTTTTTTTTT2:t5ll/euRALYTTTTTTTTTTTT2
Yara None matched
VirusTotal Search for analysis
Name bff9d951406f94e9_d3a.ico
Submit file
Filepath C:\Users\test22\AppData\Roaming\Dart Communications\Power iCalconfigurator 15.3.6.2\install\E817FBF\icons\New Blue\d3a.ico
Size 894.0B
Processes 2420 (Porcal4.exe)
Type MS Windows icon resource - 1 icon, 16x16, 24 bits/pixel
MD5 9d35e62da7375c1031ebe314358fc13d
SHA1 5b4795cdd4908e11f6fb4df38bf103b5a79c7877
SHA256 bff9d951406f94e9cea1b623b9feb5f83fc9da33aab1757981248c4ca544aa36
CRC32 C39FDC5E
ssdeep 12:t47v4IsF41mbsevA35E7Qem1Io5zIGLvslQCci8rPTe2g0M:tSzWDnAJgasl9ci8jKt
Yara None matched
VirusTotal Search for analysis
Name d9b232a13a7ff23e_prev.ico
Submit file
Filepath C:\Users\test22\AppData\Roaming\Dart Communications\Power iCalconfigurator 15.3.6.2\install\E817FBF\icons\New Blue\prev.ico
Size 894.0B
Processes 2420 (Porcal4.exe)
Type MS Windows icon resource - 1 icon, 16x16, 24 bits/pixel
MD5 ed023ef7852690bc8c0809d3c07ab753
SHA1 ba04d4935a3cab2927a60197103ffbf024896184
SHA256 d9b232a13a7ff23e29a4088f0a8568924b15c28eec4c09933c2e24cf58e1aaa4
CRC32 A263A24F
ssdeep 12:t492lB4mzPa0UCq/FPyPgvepAHu1gqzsTTTTTTTTTTTT2:t5lB0/FKPYeuuLYTTTTTTTTTTTT2
Yara None matched
VirusTotal Search for analysis
Name 81aa65d13501fd08_NavigateUpIcon@250.png
Submit file
Filepath C:\Users\test22\AppData\Roaming\Dart Communications\Power iCalconfigurator 15.3.6.2\install\E817FBF\Images\NavigateUpIcon@250.png
Size 2.8KB
Processes 2420 (Porcal4.exe)
Type PNG image data, 29 x 33, 8-bit/color RGBA, non-interlaced
MD5 f9b5d8523ef3139169927c2db507cf3a
SHA1 45093b1e2b45aa6815135056c8c0482b59214888
SHA256 81aa65d13501fd086aa2ce077005a38f6d0fd8991d920f842ac8862e1458caba
CRC32 B6706D97
ssdeep 48:OIk/6DocieftI9G9f6A+FIDOWu0lDl+gm7QyTtctIInQSy6IVpqlnBcODedm:OIkSDZ/I09Da01l+gmkyTt6Hk8nTim
Yara
  • PNG_Format_Zero - PNG Format
VirusTotal Search for analysis
Name 497f44d94371b872_d2a.ico
Submit file
Filepath C:\Users\test22\AppData\Roaming\Dart Communications\Power iCalconfigurator 15.3.6.2\install\E817FBF\icons\Classic\d2a.ico
Size 1.4KB
Processes 2420 (Porcal4.exe)
Type MS Windows icon resource - 1 icon, 16x16, 255 colors, 8 bits/pixel
MD5 51c0220f2e87a2a7166fc9f3c6d3833e
SHA1 d33053c65742ce4e2d9e9f5a8d691b23749999b6
SHA256 497f44d94371b87296e8127b61cbf23718e8abc7c9919d1174d150904e91bc5e
CRC32 F5BAFA40
ssdeep 12:dzFc363OW55KcT1XxoVVDnRznR6t15sXl+n:z3nnZ061yV8
Yara None matched
VirusTotal Search for analysis
Name 283b1e0ae7f208e2_d2.ico
Submit file
Filepath C:\Users\test22\AppData\Roaming\Dart Communications\Power iCalconfigurator 15.3.6.2\install\E817FBF\icons\New Blue\d2.ico
Size 894.0B
Processes 2420 (Porcal4.exe)
Type MS Windows icon resource - 1 icon, 16x16, 24 bits/pixel
MD5 8715c648b82ced009d6fc03ff517e0ad
SHA1 31dfcf4c2784081893e5f2013d14c7946f4beae1
SHA256 283b1e0ae7f208e2090b95c356c30d1215d011531fdb93916d6bac73d22f3eaa
CRC32 3713CE4A
ssdeep 24:t5Mhw9NAH/FWL0Yeg3PWTgYTTTTTTTTTTTT2:rNsWL0G/DYTTTTTTTTTTTT2
Yara None matched
VirusTotal Search for analysis
Name f0ee4b85d7e6ace5_MenuIcon@250.png
Submit file
Filepath C:\Users\test22\AppData\Roaming\Dart Communications\Power iCalconfigurator 15.3.6.2\install\E817FBF\Images\MenuIcon@250.png
Size 2.8KB
Processes 2420 (Porcal4.exe)
Type PNG image data, 27 x 23, 8-bit/color RGBA, non-interlaced
MD5 4282961327fe861d48e02323c638e72f
SHA1 1e629be50bd095172fc1e9d55863ec72dadf3428
SHA256 f0ee4b85d7e6ace5143c343e53230a83da8969acdf6f1b9f9fc4e2ddee5cc248
CRC32 383418E2
ssdeep 48:z/6DocieftI9G9f6A+FIDOWu0lDl+gm7QyTtctIInQSy6IVpqlnBcODL1:zSDZ/I09Da01l+gmkyTt6Hk8nTL1
Yara
  • PNG_Format_Zero - PNG Format
VirusTotal Search for analysis
Name 47143c2ebab6d1a4_d12a.ico
Submit file
Filepath C:\Users\test22\AppData\Roaming\Dart Communications\Power iCalconfigurator 15.3.6.2\install\E817FBF\icons\New Blue\d12a.ico
Size 894.0B
Processes 2420 (Porcal4.exe)
Type MS Windows icon resource - 1 icon, 16x16, 24 bits/pixel
MD5 885f367e9c07ad8566f44629bb5b3f7b
SHA1 464f49b503b1ae0f40a53b77b01b87085d48afff
SHA256 47143c2ebab6d1a4a0d926c4ef3bda3fff5a572517c38888324fdaef5464235b
CRC32 8EA36D66
ssdeep 12:t47v4ATJMEmOgxcUMmC1q6Do8KtHGtRcZYjQM:tStJMHO+cUMr1q5NHGtRcZYjB
Yara None matched
VirusTotal Search for analysis
Name f7b711849623eb1c_ConfigIcon@200.png
Submit file
Filepath C:\Users\test22\AppData\Roaming\Dart Communications\Power iCalconfigurator 15.3.6.2\install\E817FBF\Images\ConfigIcon@200.png
Size 1.1KB
Processes 2420 (Porcal4.exe)
Type PNG image data, 32 x 32, 8-bit/color RGBA, non-interlaced
MD5 6d786d0492052cbed9073c342dcc3388
SHA1 e8fc3b8379318cafa2a8d6606633e17c8935467f
SHA256 f7b711849623eb1cf52c644dbc27f45c0bead848d3158b15915809af0ba887f7
CRC32 B8B99BA8
ssdeep 24:GzyZ90ty5OjvgI9cG4HSTXb4XW2F56l9If+ZMKfJGNVwMHEBfQSz9:G690tSQvg2TXb4XW2F5MZ1fU/9EGS5
Yara
  • PNG_Format_Zero - PNG Format
VirusTotal Search for analysis
Name 726761db5c5f8ae9_MenuIcon@275.png
Submit file
Filepath C:\Users\test22\AppData\Roaming\Dart Communications\Power iCalconfigurator 15.3.6.2\install\E817FBF\Images\MenuIcon@275.png
Size 2.8KB
Processes 2420 (Porcal4.exe)
Type PNG image data, 30 x 25, 8-bit/color RGBA, non-interlaced
MD5 5cb43604e12d14b4060c94ce28bcf099
SHA1 e1c60c01bc6aefc43f4eec22455a08f8812f3995
SHA256 726761db5c5f8ae92f5713767b8ab31e2add70934542ff83ec57d33a1160085b
CRC32 7E8E4CDF
ssdeep 48:v/6DocieftI9G9f6A+FIDOWu0lDl+gm7QyTtctIInQSy6IVpqlnBcODgzW:vSDZ/I09Da01l+gmkyTt6Hk8nTgS
Yara
  • PNG_Format_Zero - PNG Format
VirusTotal Search for analysis
Name c9d1a4715b0982a8_VistaBridgeLibrary.dll
Submit file
Filepath C:\Users\test22\AppData\Roaming\Dart Communications\Power iCalconfigurator 15.3.6.2\install\E817FBF\VistaBridgeLibrary.dll
Size 95.6KB
Processes 2420 (Porcal4.exe)
Type PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
MD5 66010aedea55e9a4bbd300e089110193
SHA1 6f1333d62367dfc5ffead6b8ff822310709f1a83
SHA256 c9d1a4715b0982a8bda6eb2d69f5a17656880a43875146a6beee02b00fbede4e
CRC32 687A5CF0
ssdeep 1536:dFVKZaKtb7xLX+aNpCC0Fp0/O36XsCoI7xMcD8uKf8ILMny:dKZa85+upvmp0/XXsCoI7xMcD8uKUi
Yara
  • PE_Header_Zero - PE File Signature
  • Generic_Malware_Zero - Generic Malware
  • OS_Processor_Check_Zero - OS Processor Check
  • IsPE32 - (no description)
  • Is_DotNET_DLL - (no description)
  • IsDLL - (no description)
  • UPX_Zero - UPX packed file
VirusTotal Search for analysis
Name 806d5591a6baa78c_FolderIcon@300.png
Submit file
Filepath C:\Users\test22\AppData\Roaming\Dart Communications\Power iCalconfigurator 15.3.6.2\install\E817FBF\Images\FolderIcon@300.png
Size 2.8KB
Processes 2420 (Porcal4.exe)
Type PNG image data, 48 x 39, 8-bit/color RGBA, non-interlaced
MD5 e9607d4f8794f29ea89c3f13018cfa93
SHA1 2dfe11f88443ff7e35ea5c50f454fe67d67311f8
SHA256 806d5591a6baa78c6fa6b7bb6156be5f587b3395672d6046100b99df15ec55f5
CRC32 E7B98CAE
ssdeep 48:j/6DocieftI9G9f6A+FIDOWu0lDl+gm7QyTtctIInQSy6IVpqlnBcOD3r:jSDZ/I09Da01l+gmkyTt6Hk8nTb
Yara
  • PNG_Format_Zero - PNG Format
VirusTotal Search for analysis
Name 97020c7255bc11b1_CloseIcon@150.png
Submit file
Filepath C:\Users\test22\AppData\Roaming\Dart Communications\Power iCalconfigurator 15.3.6.2\install\E817FBF\Images\CloseIcon@150.png
Size 2.8KB
Processes 2420 (Porcal4.exe)
Type PNG image data, 13 x 13, 8-bit/color RGBA, non-interlaced
MD5 1ee3e85f8257830697304e3bc93bface
SHA1 92486c4b9768fa14b146540ff072881a4de20c46
SHA256 97020c7255bc11b12e64c8f18d30a7d0bc51f907c7b78fca8d52fbc39cf75c1a
CRC32 3B4BF0FB
ssdeep 48:M/6DocieftI9G9f6A+FIDOWu0lDl+gm7QyTtctIInQSy6IVpqlnBcODMl:MSDZ/I09Da01l+gmkyTt6Hk8nTMl
Yara
  • PNG_Format_Zero - PNG Format
VirusTotal Search for analysis
Name c0917e7e1eb9310b_api-ms-win-core-processthreads-l1-1-1.dll
Submit file
Filepath C:\Users\test22\AppData\Roaming\Dart Communications\Power iCalconfigurator 15.3.6.2\install\E817FBF\api-ms-win-core-processthreads-l1-1-1.dll
Size 9.8KB
Processes 2420 (Porcal4.exe)
Type PE32 executable (DLL) (console) Intel 80386, for MS Windows
MD5 31793ec93ec9f1e187714d096611b5bc
SHA1 64093509b31eec092f2697ae00480840dc32b6fe
SHA256 c0917e7e1eb9310bbdcc96e6f150ba8b8b34ca17b28a5e59fdfac9f517cd0922
CRC32 A69FE743
ssdeep 192:g/DiDfIepWthWJ068Ya5/R6t7snBZHR8DMY:NDfIepWthWJaPVRKoBhyDMY
Yara
  • PE_Header_Zero - PE File Signature
  • OS_Processor_Check_Zero - OS Processor Check
  • IsPE32 - (no description)
  • IsDLL - (no description)
  • UPX_Zero - UPX packed file
VirusTotal Search for analysis
Name 8d23754e6b8bb933_MSID68.tmp
Submit file
Filepath C:\Users\test22\AppData\Local\Temp\MSID68.tmp
Size 393.5KB
Processes 2420 (Porcal4.exe)
Type PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
MD5 3d24a2af1fb93f9960a17d6394484802
SHA1 ee74a6ceea0853c47e12802961a7a8869f7f0d69
SHA256 8d23754e6b8bb933d79861540b50deca42e33ac4c3a6669c99fb368913b66d88
CRC32 8E1AB53C
ssdeep 6144:hsEQsy5dfBkvAUnBU76LNaiDWbqw0EAOqcmCIVKVPgvf:4sw6vAUnBU7qax0EzIVYgvf
Yara
  • Malicious_Packer_Zero - Malicious Packer
  • PE_Header_Zero - PE File Signature
  • Generic_Malware_Zero - Generic Malware
  • OS_Processor_Check_Zero - OS Processor Check
  • IsPE32 - (no description)
  • Win32_Trojan_Gen_2_0904B0_Zero - Win32 Trojan Gen
  • IsDLL - (no description)
  • Malicious_Library_Zero - Malicious_Library
  • UPX_Zero - UPX packed file
VirusTotal Search for analysis
Name 5f442688f584cd47_d17a.ico
Submit file
Filepath C:\Users\test22\AppData\Roaming\Dart Communications\Power iCalconfigurator 15.3.6.2\install\E817FBF\icons\New Blue\d17a.ico
Size 894.0B
Processes 2420 (Porcal4.exe)
Type MS Windows icon resource - 1 icon, 16x16, 24 bits/pixel
MD5 a43d3e4f9681de227c6de28e581aea35
SHA1 d46baaee4a9a405eaefe6d7ee5cb5dcc2f9d7272
SHA256 5f442688f584cd47a94ebedd53806b64eab80ba0549bc0e5e5b1a1c775511523
CRC32 CC789F64
ssdeep 12:t47v4Aq1mOvXvcqduatmCwFBBb1QatRU4qyZmRjJ20M:tSHO3cQwF3tRUOZqjJ21
Yara None matched
VirusTotal Search for analysis
Name afc58882f76cf485_d15.ico
Submit file
Filepath C:\Users\test22\AppData\Roaming\Dart Communications\Power iCalconfigurator 15.3.6.2\install\E817FBF\icons\Classic\d15.ico
Size 1.4KB
Processes 2420 (Porcal4.exe)
Type MS Windows icon resource - 1 icon, 16x16, 8 bits/pixel
MD5 4552bd1683d36b783757bee22cecdaee
SHA1 3428cac7ba54f3691321c98b8ed3ee04e74f070e
SHA256 afc58882f76cf485c72862a9b439cfa5134ef2121e104c8fe718b7ce5e1be64a
CRC32 3020D1F6
ssdeep 12:UZtu4TQ46DAOLHl+XWuhiEZF/lQIIC/tZn:QXBOLQhl1QrCD
Yara None matched
VirusTotal Search for analysis
Name a8967647e8188d85_d6a.ico
Submit file
Filepath C:\Users\test22\AppData\Roaming\Dart Communications\Power iCalconfigurator 15.3.6.2\install\E817FBF\icons\Classic\d6a.ico
Size 1.4KB
Processes 2420 (Porcal4.exe)
Type MS Windows icon resource - 1 icon, 16x16, 255 colors, 8 bits/pixel
MD5 578d1f3b15e718c113a9bbfb9f74cf56
SHA1 faeaf6a0094b5a9eaab2923c9dd727b44c1fb273
SHA256 a8967647e8188d85ced718870e56b4603bcd4a4c8301048deffcc1ac1d8822ae
CRC32 5CFF0BDD
ssdeep 6:dz4Kc3elz54ORu9DpXBoVnVnDnVnRRTnRR6TfzsjuUNLTizuwgIR/tnn:dzFc3eB54T1XBoVVDVRhR8TLsDLTQICn
Yara None matched
VirusTotal Search for analysis
Name 4f796d33c99adc71_api-ms-win-crt-filesystem-l1-1-0.dll
Submit file
Filepath C:\Users\test22\AppData\Roaming\Dart Communications\Power iCalconfigurator 15.3.6.2\install\E817FBF\api-ms-win-crt-filesystem-l1-1-0.dll
Size 11.3KB
Processes 2420 (Porcal4.exe)
Type PE32 executable (DLL) (console) Intel 80386, for MS Windows
MD5 6a33a463ea36b3302e558ca30ce088ae
SHA1 0e25639290f08709655ee948d95ccc194f3e5d02
SHA256 4f796d33c99adc71ff87b83d5fb86e1a71dd77fef63e4679f49557c984ff210d
CRC32 283F2743
ssdeep 192:3GnWlC0i5ClWthWHW068Ya5/R6t7ssHBZHJ7aK:WnWm5ClWthW2aPVRKoQh1aK
Yara
  • PE_Header_Zero - PE File Signature
  • IsPE32 - (no description)
  • IsDLL - (no description)
  • UPX_Zero - UPX packed file
VirusTotal Search for analysis