whe.exe

Is DLL Packer Anti Debug Anti VM Signed XOR AntiVirus 47/71 Related 2627
File details Download PDF Report
File type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
File size: 636.50 KB (651776 bytes)
Compile time: 2019-10-13 23:40:59
MD5: ecc496081ac6c46e7b588cb5313e9485
SHA1: 60385f37a3dfcf32740df18a30e8333d9ad1626e
SHA256: 138e40ff3d24fbfc282cb25a589c1890ffd8da632e190e5d1ae22b2a291ddd43
Import hash: f34d5f2d4577ed6d9ceec516c1f5a744
Sections 3 .text .rsrc .reloc
Directories 3 import resource relocation
First submission: 2019-10-20 23:12:09
Last submission: 2019-10-20 23:12:09
Filename detected: - whe.exe (1)
URL file hosting
hXXp://gessuae.ae/wp-includes/images/smilies/whe.exeVirusTotal
Antivirus Report
Report Date Detection Ratio Permalink Update
2019-10-16 13:45:29 [47/71] VirusTotal
PE Sections 2 suspicious
Name VAddress VSize Size MD5 SHA1
.text 0x2000 0x9e634 649216 91576ac5a364e8ca71ea068619c8873d 17c5db5f50a6e30d3c41c7ce0aa3f65c8a566b45
.rsrc 0xa2000 0x600 1536 249e5d5fd82513bee3d9345e3ee52efa 2f9aec577c9f3eae41d4d79c51c356749a0c0934
.reloc 0xa4000 0xc 512 14ad605bc0980e9deda6920a76e4a30a e6231e27bd13aee96dba8f8e87694c815011a0d8
Meta Info
No Meta found in this file
XOR
No XOR informations found in this file.
Signature
This file isn't digitally signed
Packer(s)
Microsoft Visual C# / Basic .NET
Microsoft Visual Studio .NET
.NET executable
Microsoft Visual C# v7.0 / Basic .NET
File found
FIle type: Library
mscoree.dll
IP Found
1.8.8.8
URL(s)
No URL found

#infosec #automation

TheSystem Itself @ 2019-10-20 23:12:09