fr.exe

Is DLL Packer Anti Debug Anti VM Signed XOR AntiVirus 30/65 Related 2714
File details Download PDF Report
File type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
File size: 306.00 KB (313344 bytes)
Compile time: 2019-11-10 22:26:49
MD5: f621f2a3658734b3e38758077c61ac18
SHA1: a88a3f6cdc9e7bbceedb5d03b322ce3f8567d4ad
SHA256: b37fd6f625c652598d1784e0234832cabea26440555f580ff6743fad2790b4ab
Import hash: f34d5f2d4577ed6d9ceec516c1f5a744
Sections 3 .text .rsrc .reloc
Directories 3 import resource relocation
First submission: 2019-11-12 00:12:03
Last submission: 2019-11-12 00:12:03
Filename detected: - fr.exe (1)
URL file hosting
hXXp://fargroup.ir/images/files/fr.exeVirusTotal
Antivirus Report
Report Date Detection Ratio Permalink Update
2019-11-11 07:02:48 [30/65] VirusTotal
PE Sections 1 suspicious
Name VAddress VSize Size MD5 SHA1
.text 0x2000 0x4bdb4 310784 9561bcd62174adc70a7b158009452def cdfed98dd680ee54cbd7fe2c52985acc54ea8d76
.rsrc 0x4e000 0x528 1536 9d5968aba53b3cac5c719ae5f2a08b60 c18fe81db696680fe7edb4b0b7063b4755936039
.reloc 0x50000 0xc 512 cccc243a2ed446db8aca4989253074a6 4cfcac398cfad21e5142939ab525091c32b2339b
Meta Info
No Meta found in this file
XOR
No XOR informations found in this file.
Signature
This file isn't digitally signed
Packer(s)
Microsoft Visual C# / Basic .NET
Microsoft Visual Studio .NET
.NET executable
Microsoft Visual C# v7.0 / Basic .NET
File found
FIle type: XML
System.Xml
FIle type: Library
USER32.dll
psapi.dll
mscoree.dll
vaultcli.dll
IP Found
No IP detected
URL(s)
No URL found

#infosec #automation

TheSystem Itself @ 2019-11-12 00:12:05