× Cookies are disabled! This site requires cookies to be enabled to work properly
SHA256: 5f6bdb188674e82d96201100ad89cc48b281b98d9bac5d9049e25c9e69c530be
File name: oranmt.dll
Detection ratio: 0 / 61
Analysis date: 2017-05-20 01:08:28 UTC ( 1 year, 11 months ago )
Antivirus Result Update
Ad-Aware 20170520
AegisLab 20170519
AhnLab-V3 20170519
Alibaba 20170519
ALYac 20170519
Antiy-AVL 20170519
Arcabit 20170520
Avast 20170519
AVG 20170519
Avira (no cloud) 20170519
AVware 20170519
Baidu 20170503
BitDefender 20170519
Bkav 20170519
CAT-QuickHeal 20170519
ClamAV 20170519
CMC 20170519
Comodo 20170519
CrowdStrike Falcon (ML) 20170130
Cyren 20170520
DrWeb 20170520
Emsisoft 20170520
Endgame 20170515
ESET-NOD32 20170519
F-Prot 20170520
F-Secure 20170520
Fortinet 20170520
GData 20170520
Ikarus 20170519
Sophos ML 20170519
Jiangmin 20170519
K7AntiVirus 20170519
K7GW 20170518
Kaspersky 20170520
Kingsoft 20170520
Malwarebytes 20170520
McAfee 20170520
McAfee-GW-Edition 20170520
Microsoft 20170520
eScan 20170519
NANO-Antivirus 20170519
nProtect 20170519
Palo Alto Networks (Known Signatures) 20170520
Panda 20170519
Qihoo-360 20170520
Rising 20170518
SentinelOne (Static ML) 20170516
Sophos AV 20170519
SUPERAntiSpyware 20170520
Symantec 20170519
Symantec Mobile Insight 20170518
Tencent 20170520
TheHacker 20170516
TotalDefense 20170519
TrendMicro 20170520
TrendMicro-HouseCall 20170519
Trustlook 20170520
VBA32 20170519
VIPRE 20170519
ViRobot 20170519
Webroot 20170520
WhiteArmor 20170517
Yandex 20170518
Zillya 20170518
ZoneAlarm by Check Point 20170519
Zoner 20170520
The file being studied is a Portable Executable file! More specifically, it is a Win32 DLL file for the Windows GUI subsystem.
FileVersionInfo properties
Copyright
Copyright Oracle 1979, 2004. All rights reserved.

Original name oranmt.dll
File version 9.2.0.0.0
Description Oracle EM Agent Threading Library
Packers identified
PEiD Armadillo v1.xx - v2.xx
PE header basic information
Target machine Intel 386 or later processors and compatible processors
Compilation timestamp 2004-10-20 13:32:00
Entry Point 0x000049AD
Number of sections 5
PE sections
Overlays
MD5 3da54600598b0622144778e41e1b803b
File type ASCII text
Offset 36864
Size 272
Entropy 1.54
PE imports
Sleep
DisableThreadLibraryCalls
WaitForSingleObject
malloc
_ftol
_adjust_fdiv
free
_onexit
__dllonexit
_initterm
sltsthndinit
sltspctimewait
sltspcdestroy
sltspcinit
ss_mem_fre
sltstcl
sltsmnr
sltspcbroadcast
sltstgi
sltsmnt
sltspcsignal
sscoreserverflag
sltspcwait
sltsmxi
sltstkill
sltsmxd
sltsthnddestroy
sltsmna
sltstidinit
sltstspawn
sltstiddestroy
snltmgcs
nlerpestk
nlershow
nlepeget
nldtr1
nmijsnt_nextTime
nmibmdq_destroyQueryStatus
nmijsgpt_GetPrintableTime
snmitm_getTime
snmitm_formatNLSTime
nmijsgct_GetCurTime
nmimggcx_getGlobalCtx
nmijsmsi_MakeSchedulefromInterval
nmibmib_isBlackedOut
snmifmc
nmlstcr_create
nmlslpf_peekFirst
nmlslin_insert
nmlstds_destroy
nmlstpo_popObj
nmlsldi_destroyIterator
nmlstpu_pushObj
nmlslre_removeElement
nmlslie_isEmpty
nmlsline_iteratorNextElement
nmlslime_iteratorMoreElements
nmlslfe_findElement
nmlslci_createIterator
nmlslcr_create
nmlslde_destroy
nmlstgz_getSize
nmlstie_isEmpty
Tcl_FinalizeThread
PE exports
Number of PE resources by type
RT_VERSION 1
Number of PE resources by language
ENGLISH US 1
PE resources
Debug information
ExifTool file metadata
SubsystemVersion
4.0

LinkerVersion
6.0

ImageVersion
0.0

FileVersionNumber
9.2.0.0

UninitializedDataSize
0

LanguageCode
English (U.S.)

FileFlagsMask
0x0000

CharacterSet
Unicode

InitializedDataSize
16384

EntryPoint
0x49ad

OriginalFileName
oranmt.dll

MIMEType
application/octet-stream

Subsystem
Windows GUI

FileVersion
9.2.0.0.0

TimeStamp
2004:10:20 14:32:00+01:00

FileType
Win32 DLL

PEType
PE32

FileDescription
Oracle EM Agent Threading Library

OSVersion
4.0

FileOS
Unknown (0)

LegalCopyright
Copyright Oracle 1979, 2004. All rights reserved.

MachineType
Intel 386 or later, and compatibles

CompanyName
Oracle Corporation

CodeSize
16384

FileSubtype
0

ProductVersionNumber
0.0.0.0

FileTypeExtension
dll

ObjectFileType
Dynamic link library

File identification
MD5 f5bd6d84ca79bb83b847842821ec3abf
SHA1 c8300758a07096c31b49126c7a88e1e9d56392d5
SHA256 5f6bdb188674e82d96201100ad89cc48b281b98d9bac5d9049e25c9e69c530be
ssdeep
192:Iip3KE72bS8lMSPPcOfX+xUo0bChCM+uFCvxmo8XK3D2SPUq5Gfq5OHlzXBBT/+m:ddCNdf8UoYAqJSU5yRHlbTSeEExLF

authentihash fedad0f0b5afc7daa6f951a5c26374b5af4eca6fb79584e84a10765da136daa4
imphash 2f2fdc359edc6c7c51bea47f068d34f7
File size 36.3 KB ( 37136 bytes )
File type Win32 DLL
Magic literal
PE32 executable for MS Windows (DLL) (GUI) Intel 80386 32-bit

TrID Win64 Executable (generic) (64.6%)
Win32 Dynamic Link Library (generic) (15.4%)
Win32 Executable (generic) (10.5%)
Generic Win/DOS Executable (4.6%)
DOS Executable Generic (4.6%)
Tags
armadillo pedll overlay

VirusTotal metadata
First submission 2014-10-06 19:35:47 UTC ( 4 years, 6 months ago )
Last submission 2014-10-06 19:35:47 UTC ( 4 years, 6 months ago )
File names F5BD6D84CA79BB83B847842821EC3ABF
oranmt.dll
No comments. No VirusTotal Community member has commented on this item yet, be the first one to do so!

Leave your comment...

?
Post comment

You have not signed in. Only registered users can leave comments, sign in and have a voice!

No votes. No one has voted on this item yet, be the first one to do so!