MalScore
100/100

invoice_signed.exe

Is DLL Packer Anti Debug Anti VM Signed XOR AntiVirus 32/67 Related 2132
File details Download PDF Report
File type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
File size: 1306.63 KB (1337984 bytes)
Compile time: 1996-06-21 01:46:50
MD5: abc18be3eee56474346ec3ab80653b2e
SHA1: 48ebc0d6c6fed8792050ced38849d109793f367e
SHA256: 3f79bbdc813203f4763742dcf0edc09ee6a6133de82438816114e0a08b0393dc
Import hash: f34d5f2d4577ed6d9ceec516c1f5a744
Sections 3 .text .rsrc .reloc
Directories 4 import resource relocation security
First submission: 2018-10-29 19:36:11
Last submission: 2018-10-29 19:36:11
Filename detected: - invoice_signed.exe (1)
URL file hosting
hXXp://buildentconstructions.com/Stubs/invoice_signed.exeVirusTotal
Antivirus Report
Report Date Detection Ratio Permalink Update
2018-10-29 09:56:40 [32/67] VirusTotal
PE Sections 2 suspicious
Name VAddress VSize Size MD5 SHA1
.text 0x2000 0x712f4 463872 6ffe6b30543054615d63b6b4f9e27fc7 8e4688215805ac602563e29f432fa434797d92ba
.rsrc 0x74000 0x5e8 1536 c752119af30494fa557e9fe082b32542 5f948d80d88ca3ade7f045e7534b3602cc68b316
.reloc 0x76000 0xc 512 7673116b82733c4e95376f83a5659519 83070a570b7d1569739600eebe4e22c93f4e4250
Meta Info
No Meta found in this file
XOR
No XOR informations found in this file.
Signature
MD5: d80efee6596e06535354f3f2fc93c6e9
SHA1: 56ea9f2914cb2c076f350ff9759587b08cf754c1
Block Size: 871552
Virtual Address: 466432
Packer(s)
Microsoft Visual C# / Basic .NET
Microsoft Visual Studio .NET
.NET executable
Microsoft Visual C# v7.0 / Basic .NET
File found
FIle type: Text
WhatsNew.txt
FIle type: Library
USER32.dll
mscoree.dll
IP Found
11.1.29.19
URL(s)
http://s.symcb.com/universal-root.crl0
http://crl.comodoca.com/COMODORSACertificationAuthority.crl0q
http://schemas.microsoft.com/SMI/2005/WindowsSettings
http://ts-crl.ws.symantec.com/sha256-tss-ca.crl0
https://d.symcb.com/cps0%
http://s.symcd.com06
https://d.symcb.com/rpa0@
http://crt.comodoca.com/COMODORSACodeSigningCA.crt0$
http://ocsp.comodoca.com0
http://crl.thawte.com/ThawteTimestampingCA.crl0
http://crt.comodoca.com/COMODORSAAddTrustCA.crt0$
https://secure.comodo.net/CPS0C
https://d.symcb.com/rpa0.
http://ts-crl.ws.symantec.com/tss-ca-g2.crl0(
https://www.rarlab.com/themes.htm
http://crl.comodoca.com/COMODORSACodeSigningCA.crl0t
http://ocsp.thawte.com0
http://ts-aia.ws.symantec.com/sha256-tss-ca.cer0(
http://ts-ocsp.ws.symantec.com0;
https://www.win-rar.comIhttps://www.win-rar.com/buyredirect.html?L=0&BL=0&src=wrr&arch=64&ver=561
http://ts-ocsp.ws.symantec.com07
http://ts-aia.ws.symantec.com/tss-ca-g2.cer0<
Behavior analysis details
Machine name Machine label Machine manager Started Ended Duration
2018-10-29 19:28:31 2018-10-29 19:28:31

0 Summary items with data

Files

Nothing to display

Read Files

Nothing to display

Write Files

Nothing to display

Delete Files

Nothing to display

Keys

Nothing to display

Read Keys

Nothing to display

Write Keys

Nothing to display

Delete Keys

Nothing to display

Mutexes

Resolved APIs

Nothing to display

Execute Commands

Nothing to display

Started Services

Nothing to display

Created Services

Nothing to display

#infosec #automation

TheSystem Itself @ 2018-10-29 19:36:14