× Cookies are disabled! This site requires cookies to be enabled to work properly
SHA256: 09f5774b0ddb7dfe9d7569d07c62b088b39b13086d04287bce6d187b7ac5ca4a
File name: emotet.exe
Detection ratio: 49 / 68
Analysis date: 2018-06-08 17:58:07 UTC ( 8 months, 2 weeks ago ) View latest
Antivirus Result Update
Ad-Aware Trojan.GenericKD.30904590 20180608
AegisLab Ml.Attribute.Gen!c 20180608
AhnLab-V3 Trojan/Win32.Emotet.R229466 20180608
ALYac Trojan.GenericKD.30904590 20180608
Antiy-AVL Trojan[Banker]/Win32.Emotet 20180608
Arcabit Trojan.Generic.D1D7910E 20180608
Avast Win32:GenX 20180608
AVG Win32:GenX 20180608
AVware Trojan.Win32.Generic!BT 20180608
Baidu Win32.Trojan.WisdomEyes.16070401.9500.9999 20180608
BitDefender Trojan.GenericKD.30904590 20180608
CAT-QuickHeal Trojan.Tiggre 20180608
CrowdStrike Falcon (ML) malicious_confidence_60% (W) 20180530
Cylance Unsafe 20180608
Cyren W32/Kryptik.EO.gen!Eldorado 20180608
DrWeb Trojan.EmotetENT.223 20180608
Emsisoft Trojan.GenericKD.30904590 (B) 20180608
Endgame malicious (high confidence) 20180507
ESET-NOD32 a variant of Win32/Kryptik.GHGF 20180608
F-Prot W32/Kryptik.EO.gen!Eldorado 20180608
F-Secure Trojan.GenericKD.30904590 20180608
Fortinet W32/Kryptik.GHGF!tr 20180608
GData Trojan.GenericKD.30904590 20180608
Ikarus Trojan.Win32.Crypt 20180608
Sophos ML heuristic 20180601
K7AntiVirus Trojan ( 0053316c1 ) 20180608
K7GW Trojan ( 0053316c1 ) 20180608
Kaspersky Trojan-Banker.Win32.Emotet.apvj 20180608
Malwarebytes Trojan.Emotet 20180608
MAX malware (ai score=94) 20180608
McAfee RDN/Generic.grp 20180608
McAfee-GW-Edition RDN/Generic.grp 20180608
Microsoft Trojan:Win32/Tiggre!rfn 20180608
eScan Trojan.GenericKD.30904590 20180608
NANO-Antivirus Trojan.Win32.Emotet.fdlcqm 20180608
Palo Alto Networks (Known Signatures) generic.ml 20180608
Panda Trj/GdSda.A 20180608
Qihoo-360 HEUR/QVM20.1.8793.Malware.Gen 20180608
SentinelOne (Static ML) static engine - malicious 20180225
Sophos AV Troj/Emotet-OE 20180608
Symantec Trojan.Gen.2 20180608
TACHYON Trojan/W32.Agent.274432.AJX 20180608
Tencent Win32.Trojan-banker.Emotet.Sxek 20180608
TrendMicro TROJ_FRS.VSN1FE18 20180608
TrendMicro-HouseCall TROJ_FRS.VSN1FE18 20180608
VBA32 TrojanBanker.Emotet 20180608
ViRobot Trojan.Win32.Z.Highconfidence.274432.E 20180608
Webroot W32.Trojan.Emotet 20180608
ZoneAlarm by Check Point Trojan-Banker.Win32.Emotet.apvj 20180608
Alibaba 20180608
Avast-Mobile 20180608
Avira (no cloud) 20180608
Babable 20180406
Bkav 20180608
ClamAV 20180608
CMC 20180608
Comodo 20180608
Cybereason 20180225
eGambit 20180608
Jiangmin 20180608
Kingsoft 20180608
Rising 20180608
SUPERAntiSpyware 20180608
Symantec Mobile Insight 20180605
TheHacker 20180608
TotalDefense 20180608
Trustlook 20180608
VIPRE 20180608
Yandex 20180529
Zillya 20180608
Zoner 20180608
The file being studied is a Portable Executable file! More specifically, it is a Win32 EXE file for the Windows GUI subsystem.
FileVersionInfo properties
Copyright
Copyright 2016 The Apache Software Foundation.

Product Apache HTTP Server
Original name htdigest.exe
Internal name htdigest.exe
File version 2.4.23
Description Apache htdigest command line utility
Comments Licensed under the Apache License, Version 2.0 (the "License"); you may not use this file except in compliance with the License. You may obtain a copy of the License at http://www.apache.org/licenses/LICENSE-2.0 Unless required by applicable law or agreed to in writing, software distributed under the License is distributed on an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. See the License for the specific language governing permissions and limitations under the License.
PE header basic information
Target machine Intel 386 or later processors and compatible processors
Compilation timestamp 2016-07-09 09:09:36
Entry Point 0x0000100F
Number of sections 6
PE sections
PE imports
CM_Get_Class_Name_ExW
CM_Free_Resource_Conflict_Handle
CertOpenStore
GetObjectType
ReleaseMutex
OpenEventW
GetConsoleCP
ScrollConsoleScreenBufferA
CopyFileA
FlsGetValue
FreeConsole
FindFirstFileNameTransactedW
FlsFree
NetShareDel
VarCyFix
VarUdateFromDate
I_RpcServerUseProtseqEp2W
RpcStringFreeA
SetupDiInstallClassW
PathCompactPathExW
GetGUIThreadInfo
GetUpdatedClipboardFormats
GetMenuBarInfo
ChangeMenuA
midiStreamPosition
midiInReset
Ord(30)
vprintf
Number of PE resources by type
RT_MANIFEST 1
RT_VERSION 1
Number of PE resources by language
ENGLISH US 2
PE resources
ExifTool file metadata
UninitializedDataSize
0

LinkerVersion
13.0

ImageVersion
0.0

FileSubtype
0

FileVersionNumber
2.4.23.0

LanguageCode
English (U.S.)

FileFlagsMask
0x003f

FileDescription
Apache htdigest command line utility

ImageFileCharacteristics
No relocs, Executable, 32-bit

CharacterSet
Unicode

InitializedDataSize
28672

EntryPoint
0x100f

OriginalFileName
htdigest.exe

MIMEType
application/octet-stream

LegalCopyright
Copyright 2016 The Apache Software Foundation.

FileVersion
2.4.23

TimeStamp
2016:07:09 02:09:36-07:00

FileType
Win32 EXE

PEType
PE32

InternalName
htdigest.exe

ProductVersion
2.4.23

SubsystemVersion
5.0

OSVersion
5.0

FileOS
Win32

Subsystem
Windows GUI

MachineType
Intel 386 or later, and compatibles

CompanyName
Apache Software Foundation

CodeSize
0

ProductName
Apache HTTP Server

ProductVersionNumber
2.4.23.0

FileTypeExtension
exe

ObjectFileType
Executable application

File identification
MD5 c0aea337f48b3c24654430101c692cb6
SHA1 53fdbf75beb41c03cc931b91d81d581bde86d9cb
SHA256 09f5774b0ddb7dfe9d7569d07c62b088b39b13086d04287bce6d187b7ac5ca4a
ssdeep
3072:lX5vzQDEScWXWz0HRMA2u5j1qjbuZdj7F:TvGcVAHRRmjbu

authentihash 62555c7f2c76301262a3bae60b2c3adb60c2f7ed131be9a1a5612923c3a4dda7
imphash 077f10dca56781306ebc033ce2490ea3
File size 268.0 KB ( 274432 bytes )
File type Win32 EXE
Magic literal
PE32 executable for MS Windows (GUI) Intel 80386 32-bit

TrID OS/2 Executable (generic) (33.6%)
Generic Win/DOS Executable (33.1%)
DOS Executable Generic (33.1%)
Tags
peexe

VirusTotal metadata
First submission 2018-05-31 11:22:39 UTC ( 8 months, 3 weeks ago )
Last submission 2018-06-22 12:48:13 UTC ( 8 months ago )
File names htdigest.exe
emotet.exe
No comments. No VirusTotal Community member has commented on this item yet, be the first one to do so!

Leave your comment...

?
Post comment

You have not signed in. Only registered users can leave comments, sign in and have a voice!

No votes. No one has voted on this item yet, be the first one to do so!