MalScore
100/100

readme.exe

Is DLL Packer Anti Debug Anti VM Signed XOR AntiVirus 46/70 Related 2616
File details Download PDF Report
File type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
File size: 774.50 KB (793088 bytes)
Compile time: 1976-02-21 13:12:34
MD5: 18ee23d07ebd14c18b8931015ba42f59
SHA1: 10a85c85be2ddd3379f90f0a4a83c45c968a73a3
SHA256: e0782d0e91294990098aa8c0ca78bea4449db807ebeb8000569384991d4ffb94
Import hash: f34d5f2d4577ed6d9ceec516c1f5a744
Sections 3 .text .rsrc .reloc
Directories 3 import resource relocation
First submission: 2019-01-12 16:30:08
Last submission: 2019-01-12 16:30:08
Filename detected: - readme.exe (1)
URL file hosting
hXXp://bachaosubsy.com/viewnow/readme.exeVirusTotal
Antivirus Report
Report Date Detection Ratio Permalink Update
2019-01-02 16:19:20 [46/70] VirusTotal
PE Sections 1 suspicious
Name VAddress VSize Size MD5 SHA1
.text 0x2000 0xc0d34 790016 90cc51cc4cf6c80310c2ea56b6840e01 427a99b863c9b259cb3c9cd56ca4b8c7fd274ff0
.rsrc 0xc4000 0x680 2048 1cbcd03010fe438dae60af8bbd570886 52229cf1ba8e7be00eeaae64d61a6bb40e33a1ac
.reloc 0xc6000 0xc 512 a48179b1ac96dd77da978550ba1362df 5f5e234d23ab853f2a5877f9e5e5638c05e633b0
Meta Info
No Meta found in this file
XOR
No XOR informations found in this file.
Signature
This file isn't digitally signed
Packer(s)
Microsoft Visual C# / Basic .NET
Microsoft Visual Studio .NET
.NET executable
Microsoft Visual C# v7.0 / Basic .NET
File found
FIle type: XML
System.Xml
FIle type: Library
USER32.dll
mscoree.dll
GDI32.dll
UxTheme.dll
IP Found
13.2.28.2
URL(s)
No URL found
Behavior analysis details
Machine name Machine label Machine manager Started Ended Duration
Seven01_64 Seven01_64 VirtualBox 2019-01-12 16:25:23 2019-01-12 16:28:20 177

2 Behaviors detected by system signatures

Behavior analysis details
Machine name Machine label Machine manager Started Ended Duration
Seven01_64 Seven01_64 VirtualBox 2019-01-12 16:25:23 2019-01-12 16:28:20 177

0 Summary items with data

Files

Nothing to display

Read Files

Nothing to display

Write Files

Nothing to display

Delete Files

Nothing to display

Keys

Nothing to display

Read Keys

Nothing to display

Write Keys

Nothing to display

Delete Keys

Nothing to display

Mutexes

Resolved APIs

Nothing to display

Execute Commands

Nothing to display

Started Services

Nothing to display

Created Services

Nothing to display
Behavior analysis details
Machine name Machine label Machine manager Started Ended Duration
Seven01_64 Seven01_64 VirtualBox 2019-01-12 16:25:23 2019-01-12 16:28:20 177

1 HTTP Request(s) detected

http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab
  • Hostname: www.download.windowsupdate.com
  • IP Address: 67.26.73.254
  • Port: 80
  • Count: 1

GET /msdownload/update/v3/static/trustedr/en/authrootstl.cab HTTP/1.1
Cache-Control: max-age = 86400
Connection: Keep-Alive
Accept: */*
User-Agent: Microsoft-CryptoAPI/6.1
Host: www.download.windowsupdate.com

#infosec #automation

TheSystem Itself @ 2019-01-12 16:30:12