wh.exe

Is DLL Packer Anti Debug Anti VM Signed XOR AntiVirus 51/71 Related 2714
File details Download PDF Report
File type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
File size: 667.50 KB (683520 bytes)
Compile time: 2019-10-15 23:40:23
MD5: 9a450bf91dd81b877e4ce7125f747a3c
SHA1: 6aad2e46cc055e268406c607a44e4b66c8c48774
SHA256: fe7aa5fbece62255d02dcb94ed643799090beb67a905c8eaa72e602068be49f1
Import hash: f34d5f2d4577ed6d9ceec516c1f5a744
Sections 3 .text .rsrc .reloc
Directories 3 import resource relocation
First submission: 2019-10-26 05:12:08
Last submission: 2019-10-26 05:12:08
Filename detected: - wh.exe (1)
URL file hosting
hXXp://dev-nextgen.com/home/wp-admin/network/admin/wh.exeVirusTotal
Antivirus Report
Report Date Detection Ratio Permalink Update
2019-10-23 17:05:28 [51/71] VirusTotal
PE Sections 2 suspicious
Name VAddress VSize Size MD5 SHA1
.text 0x2000 0xa6144 680448 604e522ad0399ba176a0aff2a040170f ef8515de6ce2aab53a102e92f25c50707d9129f5
.rsrc 0xaa000 0x800 2048 74b3f8f35d5c02426e97796860aa5e36 63b6894d3bd703ca0fc72b19398e8dbe05fd04c7
.reloc 0xac000 0xc 512 e57f885a8762c1254e7cb31374a5a4ff f7f4216f34872255ff77544a79cf7592fe3e6b86
Meta Info
No Meta found in this file
XOR
No XOR informations found in this file.
Signature
This file isn't digitally signed
Packer(s)
Microsoft Visual C# / Basic .NET
Microsoft Visual Studio .NET
.NET executable
Microsoft Visual C# v7.0 / Basic .NET
File found
FIle type: Library
mscoree.dll
IP Found
No IP detected
URL(s)
No URL found

#infosec #automation

TheSystem Itself @ 2019-10-26 05:12:08