emeh99.exe

Is DLL Packer Anti Debug Anti VM Signed XOR AntiVirus 39/69 Related 2749
File details Download PDF Report
File type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
File size: 615.00 KB (629760 bytes)
Compile time: 2019-11-13 20:52:16
MD5: b508506b4e813de4707a7b809831557c
SHA1: bbf05d0126cafcbf089ee39be24593cae86bc5b6
SHA256: 675e58b30dbe6db3e64dd796053d52938dcc0ec4b92b3ff4e591df01c0c9fadd
Import hash: f34d5f2d4577ed6d9ceec516c1f5a744
Sections 3 .text .rsrc .reloc
Directories 3 import resource relocation
First submission: 2019-11-27 20:48:04
Last submission: 2019-11-27 20:48:04
Filename detected: - emeh99.exe (1)
URL file hosting
hXXp://185.112.250.128/emeh99.exeVirusTotal
Antivirus Report
Report Date Detection Ratio Permalink Update
2019-11-26 18:17:27 [39/69] VirusTotal
PE Sections 2 suspicious
Name VAddress VSize Size MD5 SHA1
.text 0x2000 0x99104 627200 c1de43e7025a714f0b61d6ad3f015aa1 ba41a04d0e87e8232eeea75cd32357f59bb67d68
.rsrc 0x9c000 0x5c8 1536 f834930c45c25e261c4bf24facd02c89 b3ce9b691e4f4ffc7ab6e600955561c179dda455
.reloc 0x9e000 0xc 512 453e5e83749c4dfd10aab97d09f76378 8126fb82f3f1b8f9fa0d6550bad30240b2cc6c30
Meta Info
No Meta found in this file
XOR
No XOR informations found in this file.
Signature
This file isn't digitally signed
Packer(s)
Microsoft Visual C# / Basic .NET
Microsoft Visual Studio .NET
.NET executable
Microsoft Visual C# v7.0 / Basic .NET
File found
FIle type: Library
mscoree.dll
IP Found
No IP detected
URL(s)
No URL found

#infosec #automation

TheSystem Itself @ 2019-11-27 20:48:05