wht.exe

Is DLL Packer Anti Debug Anti VM Signed XOR AntiVirus 50/70 Related 2628
File details Download PDF Report
File type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
File size: 1048.00 KB (1073152 bytes)
Compile time: 2019-01-09 09:15:23
MD5: 0fe2ee363e66550f303620abeca95ecd
SHA1: 5a174cf9dc8312a8e1a8f51cfa9af4602b998396
SHA256: 027749738fb6e9b026d7fda8942ac7f7aa9bf27e2c3f259783a537acf4f3c4c3
Import hash: f34d5f2d4577ed6d9ceec516c1f5a744
Sections 3 .text .rsrc .reloc
Directories 3 import resource relocation
First submission: 2019-10-23 11:45:06
Last submission: 2019-10-23 11:45:06
Filename detected: - wht.exe (1)
URL file hosting
hXXp://sunny-akune-2079.whitesnow.jp/white/wht.exeVirusTotal
Antivirus Report
Report Date Detection Ratio Permalink Update
2019-10-22 16:40:53 [50/70] VirusTotal
PE Sections 1 suspicious
Name VAddress VSize Size MD5 SHA1
.text 0x2000 0x105494 1070592 e11c78b0d4d57186c64256e3e9912c14 df787c685aa8bc7797fb401efe0a480420189603
.rsrc 0x108000 0x5d6 1536 67aeb2d15ca939a6b959f359d80f9a6d 1669ee31a835d0b58901903b1cd4d7b837977201
.reloc 0x10a000 0xc 512 41757fab485fbffe8b4f4a12715c6767 bbcb0a6e6d77dc15f5b0f96532b9974067fe172d
Meta Info
No Meta found in this file
XOR
No XOR informations found in this file.
Signature
This file isn't digitally signed
Packer(s)
Microsoft Visual C# / Basic .NET
Microsoft Visual Studio .NET
.NET executable
Microsoft Visual C# v7.0 / Basic .NET
File found
FIle type: Library
mscoree.dll
IP Found
No IP detected
URL(s)
No URL found

#infosec #automation

TheSystem Itself @ 2019-10-23 11:45:06