whe.exe

Is DLL Packer Anti Debug Anti VM Signed XOR AntiVirus 45/67 Related 2627
File details Download PDF Report
File type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
File size: 122.50 KB (125440 bytes)
Compile time: 2019-10-10 23:39:16
MD5: bf1d4f1808f9fff09d11b8129d58d4c1
SHA1: 7ade96063b0d971486b33a92a2988a2bb234ce1d
SHA256: 556d7d875e3004f1fef0f389390dda91a50d75aa76af63646deb7c221e92950f
Import hash: f34d5f2d4577ed6d9ceec516c1f5a744
Sections 2 .text .reloc
Directories 2 import relocation
First submission: 2019-10-21 03:54:03
Last submission: 2019-10-21 04:27:04
Filename detected: - whe.exe (2)
URL file hosting
hXXp://[www].gessuae.ae/wp-includes/fonts/whe.exeVirusTotal
hXXp://gessuae.ae/wp-includes/fonts/whe.exeVirusTotal
Antivirus Report
Report Date Detection Ratio Permalink Update
2019-10-14 13:21:50 [45/67] VirusTotal
PE Sections 2 suspicious
Name VAddress VSize Size MD5 SHA1
.text 0x2000 0x1e584 124416 cd2c0ba0305ab46bb7d7b98de39e99ce cb4d81dc2069edd7e95b2d8a813dee6df863975d
.reloc 0x22000 0xc 512 4a254dd89109ca9ce8a93175950a9e6d d3878f459004e074a0e4046354a0c40c431accd4
Meta Info
No Meta found in this file
XOR
No XOR informations found in this file.
Signature
This file isn't digitally signed
Packer(s)
Microsoft Visual C# / Basic .NET
Microsoft Visual Studio .NET
.NET executable
Microsoft Visual C# v7.0 / Basic .NET
File found
FIle type: Library
mscoree.dll
IP Found
No IP detected
URL(s)
No URL found

#infosec #automation

TheSystem Itself @ 2019-10-21 03:54:04