MalScore
100/100
MalFamily
Pony

wop.exe

Is DLL Packer Anti Debug Anti VM Signed XOR AntiVirus 35/69 Related 2708
File details Download PDF Report
File type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
File size: 572.00 KB (585728 bytes)
Compile time: 2019-08-02 22:21:30
MD5: e876efb719ede93e7ae4c27d3636433a
SHA1: 68e27d8c5717c4c95feffbd45e36720710bf2919
SHA256: 183598331ade7bc8533157f932a8ff94af73cb5b12e494e7959493f0cbbe67f8
Import hash: f34d5f2d4577ed6d9ceec516c1f5a744
Sections 3 .text .rsrc .reloc
Directories 3 import resource relocation
First submission: 2019-09-19 08:33:04
Last submission: 2019-09-19 08:33:04
Filename detected: - wop.exe (1)
URL file hosting
hXXp://acmestoolsmfg.com/wop.exeVirusTotal
Antivirus Report
Report Date Detection Ratio Permalink Update
2019-09-18 14:07:50 [35/69] VirusTotal
PE Sections 1 suspicious
Name VAddress VSize Size MD5 SHA1
.text 0x2000 0x38064 229888 4a0beb5c6414fa25f09e2c25e60ee19c 9511317447a1da3229e2420716f78d513d09d226
.rsrc 0x3c000 0x56818 354816 d34ea64c8dc11437ebf48c534c1d2ba5 4dab25046eeea5f7c348bef727a117209e9f350c
.reloc 0x94000 0xc 512 8a77560bea2a083153bcf51ca3cb368f ffa28472078095b4484f2d574d2f7ff64c54ad92
Meta Info
No Meta found in this file
XOR
No XOR informations found in this file.
Signature
This file isn't digitally signed
Packer(s)
Microsoft Visual C# / Basic .NET
Microsoft Visual Studio .NET
.NET executable
Microsoft Visual C# v7.0 / Basic .NET
File found
FIle type: Library
mscoree.dll
IP Found
No IP detected
URL(s)
No URL found
Behavior analysis details
Machine name Machine label Machine manager Started Ended Duration
Seven01b_64 Seven01b_64 VirtualBox 2019-09-19 10:36:44 2019-09-19 10:40:46 242

20 Behaviors detected by system signatures