MalScore
100/100

879.exe

Is DLL Packer Anti Debug Anti VM Signed XOR AntiVirus 44/69 Related 2238
File details Download PDF Report
File type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
File size: 349.50 KB (357888 bytes)
Compile time: 2018-09-09 18:58:25
MD5: 4f17b3a5af9cc81ac8ad5024891e4793
SHA1: a53b73bf461b1ebe9cf05b56ad9f17c0afa52b26
SHA256: 7805db3fd2a39b7e346a74d8bd98cec3a4c6fa991d7a5f65c962c4681f7e16ef
Import hash: f34d5f2d4577ed6d9ceec516c1f5a744
Sections 3 .text .rsrc .reloc
Directories 3 import resource relocation
First submission: 2018-10-17 00:03:09
Last submission: 2018-10-17 00:03:09
Filename detected: - 879.exe (1)
URL file hosting
hXXp://yy.xn--gjvz58f.com/air/879.exeVirusTotal
Antivirus Report
Report Date Detection Ratio Permalink Update
2018-10-06 14:36:40 [44/69] VirusTotal
PE Sections 1 suspicious
Name VAddress VSize Size MD5 SHA1
.text 0x2000 0x56724 354304 9f9abba6fcbd68bd19d24fa11f36b1a7 8b4e85900d4fa05cf75f0acd364157b61634d54c
.rsrc 0x5a000 0x80c 2560 28b690c1c1f03ee05790fc844471bbcc b937345641c0b5b287499b03054ebc63176eb76f
.reloc 0x5c000 0xc 512 203a4d8f2e67b9b05c33e4b7703146f7 87cb80efd69d3848605660a24b8bcef3c6e643c8
Meta Info
No Meta found in this file
XOR
No XOR informations found in this file.
Signature
This file isn't digitally signed
Packer(s)
Microsoft Visual C# / Basic .NET
Microsoft Visual Studio .NET
.NET executable
Microsoft Visual C# v7.0 / Basic .NET
File found
FIle type: XML
{0}\FileZilla\recentservers.xml
{0}\FileZilla\sitemanager.xml
System.Xml
FIle type: Library
\msvcp120.dll
\msvcr120.dll
\mozglue.dll
\msvcp100.dll
\nss3.dll
\msvcr100.dll
USER32.dll
KERNEL32.dll
ntdll.dll
IPHLPAPI.DLL
mscoree.dll
MSVCRT.dll
GDI32.dll
SHELL32.dll
SHLWAPI.dll
ole32.dll
ADVAPI32.dll
OLEAUT32.dll
IP Found
No IP detected
URL(s)
http://ip-api.com/json/
http://
http://api.ipify.org/
file:///
http://schemas.microsoft.com/SMI/2005/WindowsSettings
http://freegeoip.net/xml/
Behavior analysis details
Machine name Machine label Machine manager Started Ended Duration
Seven05_64 Seven05_64 VirtualBox 2018-10-16 23:59:00 2018-10-17 00:02:03 183

0 Summary items with data

Files

Nothing to display

Read Files

Nothing to display

Write Files

Nothing to display

Delete Files

Nothing to display

Keys

Nothing to display

Read Keys

Nothing to display

Write Keys

Nothing to display

Delete Keys

Nothing to display

Mutexes

Resolved APIs

Nothing to display

Execute Commands

Nothing to display

Started Services

Nothing to display

Created Services

Nothing to display

#infosec #automation

TheSystem Itself @ 2018-10-17 00:03:25