whe.exe

Is DLL Packer Anti Debug Anti VM Signed XOR AntiVirus 43/67 Related 2726
File details Download PDF Report
File type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
File size: 136.50 KB (139776 bytes)
Compile time: 2019-11-19 23:03:48
MD5: f5c6c27712a5569b304ff01ca5b1c7c8
SHA1: 5f4cc37234cd430b71f3577e9ba38e5f6112ef33
SHA256: 0920dc44442e04d196db33657904fa09414b02c767c56ef06b17d6a5ef2d5f53
Import hash: f34d5f2d4577ed6d9ceec516c1f5a744
Sections 2 .text .reloc
Directories 2 import relocation
First submission: 2019-11-21 11:48:05
Last submission: 2019-11-21 11:48:05
Filename detected: - whe.exe (1)
URL file hosting
hXXp://[www].teorija.rs/storage/app/whe.exeVirusTotal
Antivirus Report
Report Date Detection Ratio Permalink Update
2019-11-20 18:05:00 [43/67] VirusTotal
PE Sections 2 suspicious
Name VAddress VSize Size MD5 SHA1
.text 0x2000 0x21d74 138752 375aa58741b0f3f027cf22cc9936ab39 712d7aa01e103d92fc582173a622dd1c015ce426
.reloc 0x24000 0xc 512 e38d0879c0864c38e591c1795b19555a 11b83dd2afcbb4a60aab48cef25a72cede53be54
Meta Info
No Meta found in this file
XOR
No XOR informations found in this file.
Signature
This file isn't digitally signed
Packer(s)
Microsoft Visual C# / Basic .NET
Microsoft Visual Studio .NET
.NET executable
Microsoft Visual C# v7.0 / Basic .NET
File found
FIle type: Library
mscoree.dll
32.dll
IP Found
No IP detected
URL(s)
No URL found

#infosec #automation

TheSystem Itself @ 2019-11-21 11:49:07