Gridinsoft Logo

The msys-ncursesw631.dll (Oqefimurayofopud Icemekakakadenori Ahibijarib Aditabibamutusuxosi Ihafibufodowekowiles Unequbikali Abaxuquyasunabu Uzemuxolozufukobegeno Uhoqafogecaqubagerono.) File Analysis

Technical Analysis

File Name msys-ncursesw631.dll
File Type
Win32 DLL
Magic Bytes PE32+ executable (DLL) (GUI) x86-64, for MS Windows
SSDEEP Hash
49152:Nrd9s5Lpx81cHmQt2kz8iQY1RX3pJlZ7:AB+u
Scanner Version 1.0.215.174
Database Version 2025-04-27 17:00:20 UTC

Suspicious File Detected

Detected by 28 security engines - requires caution

This file requires additional checking for potential threats. Based on suspicious indicators, we will soon add it to our virus database.
39%
Detection Rate
1,910,272
File Size (bytes)
28/71
Engines Detected
2025-04-27
Analysis Date

Scan Another File

File Identification

Hash Type Value Action
MD5
387004c62a01e804f753a7eeccda4796
SHA1
3bb88ad191659c473ae0dae9eed5946ac398f9ed
SHA256
29e31f2d6959e71d504de484c762f1f5c51683461ad712715d517b9a835e13ae
SHA512
6ea4f0ccbe6815a4194f92a0479c8428ad533029ca9dc01270ee0c6c4f9180cc164639e05eb0186ec89828fa9f09c0a03ef11656410b24c135b89f043659e0b8
ImpHash
03fbb21995053cdb2fc27bb629ada4df

Security Engines with Detections (28 of 71)

MicroWorld-eScan
Generic.Dacic.3214.62F38C97 Malicious
CTX
dll.trojan.generic Malicious
McAfee
Artemis!387004C62A01 Malicious
Cylance
Unsafe Malicious
K7GW
Trojan ( 005b7bc71 ) Malicious
K7AntiVirus
Trojan ( 005b7bc71 ) Malicious
ESET-NOD32
a variant of Win64/Agent.ECK Malicious
TrendMicro-HouseCall
TROJ_GEN.R002H09DP25 Malicious
Paloalto
generic.ml Malicious
BitDefender
Generic.Dacic.3214.62F38C97 Malicious
Avast
Win64:MalwareX-gen [Misc] Malicious
Emsisoft
Generic.Dacic.3214.62F38C97 (B) Malicious
Google
Detected Malicious
F-Secure
Trojan.TR/Agent.ijulc Malicious
VIPRE
Generic.Dacic.3214.62F38C97 Malicious
McAfeeD
ti!29E31F2D6959 Malicious
Ikarus
Trojan.Win64.Agent Malicious
GData
Generic.Dacic.3214.62F38C97 Malicious
Jiangmin
Trojan.Lazy.ah Malicious
Avira
TR/Agent.ijulc Malicious
Antiy-AVL
GrayWare/Win32.Wacapew Malicious
Arcabit
Generic.Dacic.3214.62F38C97 Malicious
Microsoft
Program:Win32/Wacapew.C!ml Malicious
Cynet
Malicious (score: 99) Malicious
AhnLab-V3
Trojan/Win.Dacic.R702441 Malicious
ALYac
Generic.Dacic.3214.62F38C97 Malicious
Fortinet
W64/Agent.ECK!tr Malicious
AVG
Win64:MalwareX-gen [Misc] Malicious
43 engines reported no threats - Only engines with detections are shown above for clarity

PE Analysis

Basic Information

Image Base 0x180000000
Entry Point 0x1801253a0
Compilation Time 2025-04-25 01:13:16
Checksum 0x00000000 (Actual: 0x001dd74e)
OS Version 6.0
PEiD Signatures PE32+ executable (DLL) (GUI) x86-64, for MS Windows
PDB Path C:\Windows\109b52e3c06afc517e09856c83784a36\MSFT_EnvironmentResource\it\2.pdb
Digital Signature No valid SignedData structure was found.
Imports 10 libraries
ADVAPI32, bcrypt, KERNEL32, ole32, api-ms-win-crt-math-l1-1-0, api-ms-win-crt-heap-l1-1-0, api-ms-win-crt-string-l1-1-0, api-ms-win-crt-convert-l1-1-0, api-ms-win-crt-runtime-l1-1-0, api-ms-win-crt-stdio-l1-1-0
Exports 2 functions
Resources 2 Resources
Sections 6 Sections

Version Information

Translation 0x0000 0x04b0
CompanyName Azokujufitapowo
ProductName Ulijijekacoto
FileDescription Oqefimurayofopud Icemekakakadenori Ahibijarib Aditabibamutusuxosi Ihafibufodowekowiles Unequbikali Abaxuquyasunabu Uzemuxolozufukobegeno Uhoqafogecaqubagerono.
FileVersion 2.64.109.42
ProductVersion 2.64.109.42
OriginalFilename Ojesevubitiwa
InternalName Ajexomabupudayah
LegalCopyright © 2025 Azokujufitapowo
Translation 0x0000 0x04b0
CompanyName Azokujufitapowo
ProductName Ulijijekacoto
FileDescription Oqefimurayofopud Icemekakakadenori Ahibijarib Aditabibamutusuxosi Ihafibufodowekowiles Unequbikali Abaxuquyasunabu Uzemuxolozufukobegeno Uhoqafogecaqubagerono.
FileVersion 2.64.109.42
ProductVersion 2.64.109.42
OriginalFilename Ojesevubitiwa
InternalName Ajexomabupudayah
LegalCopyright © 2025 Azokujufitapowo

PE Sections

Name Virtual Address Virtual Size Raw Size Entropy Characteristics MD5
.text 0x00001000 1,219,992 bytes 1,220,096 bytes 6.58 (Compressed) IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ B6C5F61EC6C6E0E22848667E4BEAABE9
.rdata 0x0012b000 609,026 bytes 609,280 bytes 6.66 (Compressed) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 64BEAA44E72F462B6345C76B346EA099
.data 0x001c0000 331,256 bytes 6,656 bytes 3.01 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE 4ED80695EA047FB0C0AF0D816A703513
.pdata 0x00211000 68,688 bytes 69,120 bytes 6.12 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 53CE1F2466BA8B96B75DDCE52C1B7336
.rsrc 0x00222000 2,192 bytes 2,560 bytes 3.91 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ B08E997A0BCA1342F99C5F17315548FA
.reloc 0x00223000 1,492 bytes 1,536 bytes 5.09 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ 153C7903C6DFA2B77C18A7AB3810DCAA
Entropy Analysis Alert

2 section(s) with elevated entropy (≥6.5) - possible compression

Resource Analysis

Total Resources: 2 (2,080 bytes)
Resource Type Count Total Size Percentage
RT_VERSION 2 2,080 bytes
100%

Certificate Chain Analysis

Certificate Information
Product Ulijijekacoto
Description Oqefimurayofopud Icemekakakadenori Ahibijarib Aditabibamutusuxosi Ihafibufodowekowiles Unequbikali Abaxuquyasunabu Uzemuxolozufukobegeno Uhoqafogecaqubagerono.
File Version 2.64.109.42
Original Name Ojesevubitiwa
Internal Name Ajexomabupudayah
Copyright © 2025 Azokujufitapowo

✓ This file has been digitally signed and the certificate chain has been verified

  • The signature ensures file integrity and authenticity from the publisher
  • Timestamping proves when the signature was applied
Certificate Verification Status

No valid SignedData structure was found.

Recommendation: Verify the file source and ensure it comes from a trusted publisher.

Remember: This is Result of Online Virus Scanner

Gridinsoft Anti-Malware has a much more powerful virus scanning engine. We recommend using it for a more precise diagnosis of infected systems. This brief guide will help you install our flagship product for more accurate diagnostics:

Download Anti-Malware

Keep Your System Protected

This file appears clean, but regular security maintenance is important

  1. Regular Scans: Run weekly system scans to detect new threats before they can cause damage.
  2. Keep Software Updated: Ensure your operating system and all applications have the latest security patches.
  3. Safe Browsing: Avoid suspicious websites and never download software from untrusted sources.
  4. Email Security: Be cautious with email attachments and links, even from known contacts.
Proactive Protection
28 antivirus engines detected potential threats. This could be a false positive, especially for system tools or packed software. Verify the file source and check if it's digitally signed by a trusted publisher.

Leave a Comment

Share your thoughts or insights about this file. Do you align with our conclusion?

* Your feedback could influence our rating, and rest assured, your email will remain confidential and will only be used to communicate with you if necessary.
Your Score for

Gridinsoft Anti-Malware

Cure your PC from any kind of malware

GridinSoft Anti-Malware will help you to protect your computer from spyware, trojans, backdoors, rootkits. It cleans your system from annoying advertisement modules and other malicious stuff developed by hackers.

Gridinsoft Anti-Malware