MalScore
100/100
MalFamily
Ispy

major.exe

Is DLL Packer Anti Debug Anti VM Signed XOR AntiVirus 12/69 Related 2620
File details Download PDF Report
File type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
File size: 1201.50 KB (1230336 bytes)
Compile time: 2019-08-11 06:29:27
MD5: ca86985dc32ff6d87a9a60826a8e4de7
SHA1: e8efef92f6a57e2f424c4a27dcc63733d871eaa8
SHA256: 4aee12bc36e0a149ccc3a3d07156fc409063342dc22c9b834f418270172c9888
Import hash: f34d5f2d4577ed6d9ceec516c1f5a744
Sections 3 .text .rsrc .reloc
Directories 3 import resource relocation
First submission: 2019-09-26 11:45:04
Last submission: 2019-09-26 11:45:04
Filename detected: - major.exe (1)
URL file hosting
hXXp://fomoportugal.com/major.exeVirusTotal
Antivirus Report
Report Date Detection Ratio Permalink Update
2019-09-26 07:57:14 [12/69] VirusTotal
PE Sections 2 suspicious
Name VAddress VSize Size MD5 SHA1
.text 0x2000 0x11be04 1163264 6a6ba8ddafafefc5556801e42e85e8ed f94d4556edfa3dd7d817931fb682a3964954a0cf
.rsrc 0x11e000 0x101d0 66048 6896d544da47847fdf85d9ade8979006 29b83772b0e91d0b366f58bb1392e6122992b48f
.reloc 0x130000 0xc 512 d6636ff3a56f03da335191e9f78f2d84 870bb5932aaa846d0e29980c706361c3c9e4c8bd
Meta Info
No Meta found in this file
XOR
No XOR informations found in this file.
Signature
This file isn't digitally signed
Packer(s)
Microsoft Visual C# / Basic .NET
Microsoft Visual Studio .NET
.NET executable
Microsoft Visual C# v7.0 / Basic .NET
File found
FIle type: XML
SourceCode.Workflow.Management.WorklistCriteria.Xml.Filters.xml
SourceCode.Workflow.Management.Process.Xml.ProcInsFilters.xml
SourceCode.Workflow.Management.Error.Xml.Filters.xml
SourceCode.Workflow.Management.Permissions.Xml.PermissionsFilters.xml
SourceCode.Workflow.Management.Process.Xml.ProcessFilters.xml
SourceCode.Workflow.Management.Permissions.Xml.AdminFilters.xml
System.Xml
FIle type: Query DB
SourceCode.Workflow.Management.Archiving.InitLogDB.sql
SourceCode.Workflow.Management.Archiving.SP.sql
SourceCode.Workflow.Management.Archiving.Archive.sql
SourceCode.Workflow.Management.Archiving.Import.sql
SourceCode.Workflow.Management.Archiving.Create.sql
SourceCode.Workflow.Management.Archiving.ArchiveInfo.sql
SourceCode.Workflow.Management.Archiving.Tables.sql
SourceCode.Workflow.Management.Archiving.Indexes.sql
SourceCode.Workflow.Management.Archiving.DesignData.sql
SourceCode.Workflow.Management.Archiving.Tbl.sql
FIle type: Library
mscoree.dll
IP Found
No IP detected
URL(s)
http://
https://
http://www.w3.org/2001/XMLSchema
http://www.w3.org/2001/XMLSchema-instance
Behavior analysis details
Machine name Machine label Machine manager Started Ended Duration
Seven01_64 Seven01_64 VirtualBox 2019-09-26 11:44:20 2019-09-26 11:47:24 184

17 Behaviors detected by system signatures