MalScore
66/100

svchosts.exe

Is DLL Packer Anti Debug Anti VM Signed XOR Related 2094
File details Download PDF Report
File type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
File size: 95.00 KB (97280 bytes)
Compile time: 2018-05-23 02:59:28
MD5: 266f71551e3b04d1c95209f371527afc
SHA1: 376ec2ee11f50e6967d5225a4c44847ca32d9222
SHA256: f7878248c4539e22c453d2a0fbb53bdc1d98c93c598f05727927133ec79067f4
Import hash: f34d5f2d4577ed6d9ceec516c1f5a744
Sections 5 N&?'@ .text .rsrc .reloc
Directories 3 import resource relocation
First submission: 2019-04-12 19:46:35
Last submission: 2019-04-12 19:46:35
Filename detected: - svchosts.exe (1)
URL file hosting
hXXp://attack.s2lol.com/svchosts.exeVirusTotal
Antivirus Report
Report Date Detection Ratio Permalink Update
No report available
PE Sections 3 suspicious
Name VAddress VSize Size MD5 SHA1
N&?'@ 0x2000 0x9930 39424 3826dc58eec414a32df4be23bce7286b 3522dc2de3601e7efb88347e7f4cf585ba9d9373
.text 0xc000 0xb260 46080 c05516b2737b10d0a29c71fd0f660437 028c1ccf1c80608d8d7685f7b287b267dd675f8d
.rsrc 0x18000 0x5e8 1536 9ec5d20645219c753f85fca869e65f49 eb6dd0bb30bbbe2887e6ae9c9f4d014bcb4c5538
.reloc 0x1a000 0xc 512 974d89db0e9e0dbb1a295bb33c6d2526 0f0c99669a25e0a390810e1a1e7b44c1e1c9aabe
0x1c000 0x10 512 8938b2566569611b03695ab0049c1763 377bca3463d75856868395e7ad619cbfcabf2c70
Meta Info
No Meta found in this file
XOR
No XOR informations found in this file.
Signature
This file isn't digitally signed
Packer(s)
No packers found for this file
File found
FIle type: Library
mscoree.dll
KERNEL32.dll
IP Found
No IP detected
URL(s)
https://www.x2vn.com/attack/
Behavior analysis details
Machine name Machine label Machine manager Started Ended Duration
Seven05b_64 Seven05b_64 VirtualBox 2019-04-12 19:35:09 2019-04-12 19:35:43 34

2 Behaviors detected by system signatures

Behavior analysis details
Machine name Machine label Machine manager Started Ended Duration
Seven05b_64 Seven05b_64 VirtualBox 2019-04-12 19:35:09 2019-04-12 19:35:43 34

0 Summary items with data

Files

Nothing to display

Read Files

Nothing to display

Write Files

Nothing to display

Delete Files

Nothing to display

Keys

Nothing to display

Read Keys

Nothing to display

Write Keys

Nothing to display

Delete Keys

Nothing to display

Mutexes

Resolved APIs

Nothing to display

Execute Commands

Nothing to display

Started Services

Nothing to display

Created Services

Nothing to display

#infosec #automation

TheSystem Itself @ 2019-04-12 19:46:36