MalScore
50/100

CEUpdater.exe

Is DLL Packer Anti Debug Anti VM Signed XOR
File details Download PDF Report
File type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
File size: 3429.85 KB (3512162 bytes)
Compile time: 2083-03-10 21:17:01
MD5: 9e5d445e63c36546bf72ed3ec27ba105
SHA1: 5bacacc2ea4cb46e3bb62a68140640c7ed39520f
SHA256: d812fd311af62d84ae012b07e52e03a3735133b8b33100fbd81a3cf107966e8d
Sections 3 .text .rsrc .reloc
Directories 4 import resource debug relocation
Anti Virtual Machine 2 VMCheck.dll Bochs & QEmu CPUID Trick
First submission: 2020-10-16 06:24:14
Last submission: 2020-10-16 06:24:14
Filename detected: - CEUpdater.exe (1)
URL file hosting
hXXp://getapp.bonanzoro.com/up/dl/1576740781970921/CEUpdater.exeVirusTotal
Antivirus Report
Report Date Detection Ratio Permalink Update
No report available
PE Sections 1 suspicious
Name VAddress VSize Size MD5 SHA1
.text 0x2000 0x52f7f4 5437440 f2565ad1876b456927b0074512926dc5 29ddd8dd0b988eb47fab65d793e67b71c0901a7a
.rsrc 0x532000 0x5cc 1536 d41d8cd98f00b204e9800998ecf8427e da39a3ee5e6b4b0d3255bfef95601890afd80709
.reloc 0x534000 0xc 512 d41d8cd98f00b204e9800998ecf8427e da39a3ee5e6b4b0d3255bfef95601890afd80709
Meta Info
No Meta found in this file
XOR
No XOR informations found in this file.
Signature
This file isn't digitally signed
Packer(s)
No packers found for this file
File found
FIle type: Library
mscoree.dll
SQLite.Interop.dll
ADVAPI32.dll
KERNEL32.dll
IP Found
No IP detected
URL(s)
https://www.sqlite.org/copyright.html
Behavior analysis details
Machine name Machine label Machine manager Started Ended Duration
Seven02b_64 Seven02b_64 VirtualBox 2020-10-16 06:12:20 2020-10-16 06:12:44 24

1 Behaviors detected by system signatures

Behavior analysis details
Machine name Machine label Machine manager Started Ended Duration
Seven02b_64 Seven02b_64 VirtualBox 2020-10-16 06:12:20 2020-10-16 06:12:44 24

0 Summary items with data

Files

Nothing to display

Read Files

Nothing to display

Write Files

Nothing to display

Delete Files

Nothing to display

Keys

Nothing to display

Read Keys

Nothing to display

Write Keys

Nothing to display

Delete Keys

Nothing to display

Mutexes

Resolved APIs

Nothing to display

Execute Commands

Nothing to display

Started Services

Nothing to display

Created Services

Nothing to display

#infosec #automation

TheSystem Itself @ 2020-10-16 06:24:16