wormclean.exe

Is DLL Packer Anti Debug Anti VM Signed XOR AntiVirus 44/69 Related 2135
File details Download PDF Report
File type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
File size: 235.00 KB (240640 bytes)
Compile time: 2005-02-07 13:42:27
MD5: 7ecd069d8459f2adbe807f6cc1ac2ce0
SHA1: fdaca247cc58bb2b8bf0b9a377a34fe0ff49a31d
SHA256: 15dd6c3b1eca1dcbae61620e9533e8c6ee0ce641ca05c814c9be4e6a036716a1
Import hash: f34d5f2d4577ed6d9ceec516c1f5a744
Sections 5 <C\<8; .text .rsrc .reloc
Directories 3 import resource relocation
First submission: 2019-04-15 18:33:04
Last submission: 2019-04-15 18:42:04
Filename detected: - wormclean.jpg (1)
- wormclean.exe (1)
URL file hosting
hXXp://aurorahurricane.net.au/file/img/wormclean.jpgVirusTotal
hXXp://aurorahurricane.net.au/file/img/wormclean.exeVirusTotal
Antivirus Report
Report Date Detection Ratio Permalink Update
2019-04-15 06:40:01 [44/69] VirusTotal
PE Sections 3 suspicious
Name VAddress VSize Size MD5 SHA1
<C\<8; 0x2000 0x34128 213504 ce4f85ea6d66462d1d045c04d3ac6a62 550b3cffb271c27979ed2ff5d81bcd571e655fef
.text 0x38000 0x5a78 23552 fa007ed2da05d9496ac6c40330691d1f 97f29d51bc5b038266e0b2a9de46df1b71b6ff0a
.rsrc 0x3e000 0x5e8 1536 93613e9df024f66cab4f65710e20099d b5e9014eb29599412bb1ae026e2807adceab570f
.reloc 0x40000 0xc 512 1b7daa91007c3b092e7bc824ff1dd2a0 90e48be3fd66d07adad6a1f234c1d974b6710a43
0x42000 0x10 512 e686ceca09135be5f5a07067fe55a8f3 8255732e3f1eee86ed96f35b21455d4af4ca4ab6
Meta Info
No Meta found in this file
XOR
No XOR informations found in this file.
Signature
This file isn't digitally signed
Packer(s)
Microsoft Visual C# / Basic .NET
File found
FIle type: Library
mscoree.dll
KERNEL32.dll
IP Found
4.5.7.9
URL(s)
No URL found

#infosec #automation

TheSystem Itself @ 2019-04-15 18:33:05