× Cookies are disabled! This site requires cookies to be enabled to work properly
SHA256: fc10bb6c791b42392af7a7f88e4b027f0ad92831e6f84c9715411e42bf0f369d
File name: dinput8.dll
Detection ratio: 16 / 52
Analysis date: 2016-02-02 19:41:30 UTC ( 10 months, 1 week ago ) View latest
Antivirus Result Update
ALYac Trojan.Generic.14571038 20160202
AegisLab Troj.Generic!c 20160202
Yandex Trojan.DL.Agent!09fviuknfQw 20160202
Avira (no cloud) TR/Downloader.A.16791 20160202
Baidu-International Trojan.Win32.Generic.Downloader 20160202
Cyren W32/Downloader.KFLL-9025 20160202
McAfee Artemis!045860C45525 20160202
McAfee-GW-Edition BehavesLike.Win32.Downloader.zz 20160202
NANO-Antivirus Trojan.Win32.KFLL9025.dytadm 20160202
Panda Generic Suspicious 20160201
Qihoo-360 HEUR/QVM40.1.Malware.Gen 20160202
Symantec Downloader 20160201
Tencent Win32.Trojan.Downloader.Dky 20160202
VIPRE Trojan.Win32.Generic!BT 20160202
ViRobot Trojan.Win32.S.Agent.3072.HY[h] 20160202
nProtect Trojan.Generic.14571038 20160201
AVG 20160203
Ad-Aware 20160202
AhnLab-V3 20160202
Alibaba 20160202
Antiy-AVL 20160202
Arcabit 20160202
Avast 20160203
BitDefender 20160202
Bkav 20160202
ByteHero 20160202
CAT-QuickHeal 20160202
ClamAV 20160202
Comodo 20160202
DrWeb 20160202
ESET-NOD32 20160202
Emsisoft 20160202
F-Prot 20160129
Fortinet 20160202
GData 20160202
Ikarus 20160202
Jiangmin 20160202
K7AntiVirus 20160202
K7GW 20160202
Kaspersky 20160203
Malwarebytes 20160202
eScan 20160202
Microsoft 20160202
Rising 20160203
SUPERAntiSpyware 20160202
Sophos 20160202
TheHacker 20160130
TrendMicro 20160202
TrendMicro-HouseCall 20160202
VBA32 20160202
Zillya 20160201
Zoner 20160202
The file being studied is a Portable Executable file! More specifically, it is a Win32 DLL file for the Windows GUI subsystem.
PE header basic information
Target machine Intel 386 or later processors and compatible processors
Compilation timestamp 2015-03-07 14:19:26
Entry Point 0x00001050
Number of sections 4
PE sections
PE imports
FreeLibrary
GetSystemDirectoryA
ExitProcess
GetProcAddress
LoadLibraryA
MessageBoxA
PE exports
ExifTool file metadata
MIMEType
application/octet-stream

Subsystem
Windows GUI

MachineType
Intel 386 or later, and compatibles

FileTypeExtension
dll

TimeStamp
2015:03:07 15:19:26+01:00

FileType
Win32 DLL

PEType
PE32

CodeSize
512

LinkerVersion
12.0

EntryPoint
0x1050

InitializedDataSize
2048

SubsystemVersion
6.0

ImageVersion
0.0

OSVersion
6.0

UninitializedDataSize
0

File identification
MD5 045860c4552573caa4ee4657513c4470
SHA1 0a285bd47b3a9d6bd7f213e203c5cf314c04830f
SHA256 fc10bb6c791b42392af7a7f88e4b027f0ad92831e6f84c9715411e42bf0f369d
ssdeep
24:e1GSKAFAuk8X5soySCkq41TFffXS3SUm31F3XSPS50Bi2YwAdDR3:Slj5NWkh15f/QE37nALBM3

authentihash a7193b4407d4a5f3d99e08857551cfa0cedcd9df4150f9f15d44cd9e1859ba11
imphash 810400b2e250d3da690da947e15a76bd
File size 3.0 KB ( 3072 bytes )
File type Win32 DLL
Magic literal
PE32 executable for MS Windows (DLL) (GUI) Intel 80386 32-bit

TrID Win32 Dynamic Link Library (generic) (43.5%)
Win32 Executable (generic) (29.8%)
Generic Win/DOS Executable (13.2%)
DOS Executable Generic (13.2%)
Tags
pedll

VirusTotal metadata
First submission 2015-05-19 22:46:40 UTC ( 1 year, 6 months ago )
Last submission 2016-11-22 06:27:55 UTC ( 2 weeks, 6 days ago )
File names dinput8.dll
dinput8.dll
Advanced heuristic and reputation engines
TrendMicro-HouseCall
TrendMicro's heuristic engine has flagged this file as: TROJ_GEN.R03EC0EGL15.

Symantec reputation Suspicious.Insight
No comments. No VirusTotal Community member has commented on this item yet, be the first one to do so!

Leave your comment...

?
Post comment

You have not signed in. Only registered users can leave comments, sign in and have a voice!

No votes. No one has voted on this item yet, be the first one to do so!