× Cookies are disabled! This site requires cookies to be enabled to work properly
SHA256: 1feebb977e01cabe36018f38618ed8979f9ba1e5cbc176d0b41f1293a3bbaa6d
File name: 1feebb977e01cabe36018f38618ed8979f9ba1e5cbc176d0b41f1293a3bbaa6d
Detection ratio: 16 / 70
Analysis date: 2018-11-29 09:35:39 UTC ( 2 months, 3 weeks ago ) View latest
Antivirus Result Update
CAT-QuickHeal Trojan.Emotet.X4 20181129
ClamAV Win.Trojan.Emotet-6748801-0 20181129
CrowdStrike Falcon (ML) malicious_confidence_100% (D) 20181022
Cybereason malicious.0f0656 20180225
Cylance Unsafe 20181129
DrWeb Trojan.EmotetENT.310 20181129
Emsisoft Trojan.Emotet (A) 20181129
Endgame malicious (high confidence) 20181108
Fortinet W32/Kryptik.GNFC!tr 20181129
Microsoft Program:Win32/Unwaders.C!ml 20181129
Qihoo-360 HEUR/QVM20.1.8701.Malware.Gen 20181129
Rising Malware.Heuristic!ET#98% (RDM+:cmRtazohmMXTFg/Gf5qC2aCR0nl9) 20181129
SentinelOne (Static ML) static engine - malicious 20181011
Sophos AV Mal/EncPk-ANY 20181129
Trapmine malicious.high.ml.score 20181128
Webroot W32.Trojan.Emotet 20181129
Ad-Aware 20181129
AegisLab 20181129
AhnLab-V3 20181129
Alibaba 20180921
ALYac 20181129
Antiy-AVL 20181128
Arcabit 20181129
Avast 20181129
Avast-Mobile 20181129
AVG 20181129
Avira (no cloud) 20181129
Babable 20180918
Baidu 20181129
BitDefender 20181129
Bkav 20181128
CMC 20181128
Comodo 20181129
Cyren 20181129
eGambit 20181129
ESET-NOD32 20181129
F-Prot 20181129
F-Secure 20181129
GData 20181129
Ikarus 20181129
Sophos ML 20181128
Jiangmin 20181129
K7AntiVirus 20181129
K7GW 20181129
Kaspersky 20181129
Kingsoft 20181129
Malwarebytes 20181129
MAX 20181129
McAfee 20181129
McAfee-GW-Edition 20181129
eScan 20181129
NANO-Antivirus 20181129
Palo Alto Networks (Known Signatures) 20181129
Panda 20181128
SUPERAntiSpyware 20181128
Symantec 20181129
Symantec Mobile Insight 20181121
TACHYON 20181129
Tencent 20181129
TheHacker 20181126
TotalDefense 20181129
TrendMicro 20181129
TrendMicro-HouseCall 20181129
Trustlook 20181129
VBA32 20181129
VIPRE 20181129
ViRobot 20181129
Yandex 20181128
Zillya 20181128
ZoneAlarm by Check Point 20181129
Zoner 20181129
The file being studied is a Portable Executable file! More specifically, it is a Win32 EXE file for the Windows GUI subsystem.
FileVersionInfo properties
Copyright
© Microsoft Corporation

Product Microsoft®
Internal name securit
File version 3.00.
Description V
PE header basic information
Target machine Intel 386 or later processors and compatible processors
Compilation timestamp 2018-11-29 09:30:42
Entry Point 0x000637AD
Number of sections 5
PE sections
PE imports
GetNamedPipeClientProcessId
GetModuleHandleA
GetTimeZoneInformation
LZSeek
DdeConnect
timeGetTime
CryptCATOpen
CoInvalidateRemoteMachineBindings
Number of PE resources by type
RT_STRING 5
RT_RCDATA 1
RT_VERSION 1
Number of PE resources by language
NEUTRAL 6
ENGLISH US 1
PE resources
ExifTool file metadata
SpecialBuild
[pre-release version: pre-alpha]

SubsystemVersion
5.0

LinkerVersion
12.0

ImageVersion
0.0

FileSubtype
0

FileVersionNumber
8.0.0.0

LanguageCode
English (U.S.)

FileFlagsMask
0x003f

FileDescription
V

ImageFileCharacteristics
Executable, 32-bit

CharacterSet
Windows, Latin1

InitializedDataSize
32768

EntryPoint
0x637ad

MIMEType
application/octet-stream

LegalCopyright
Microsoft Corporation

FileVersion
3.00.

TimeStamp
2018:11:29 10:30:42+01:00

FileType
Win32 EXE

PEType
PE32

InternalName
securit

UninitializedDataSize
0

OSVersion
5.0

FileOS
Win32

Subsystem
Windows GUI

MachineType
Intel 386 or later, and compatibles

CompanyName
S Corpora

CodeSize
409600

ProductName
Microsoft

ProductVersionNumber
0.0.0.0

FileTypeExtension
exe

ObjectFileType
Dynamic link library

File identification
MD5 bcec27a0f06564c790d5c3d47ee7f9e7
SHA1 2fcbfb0b5bdaa5428f57f9b4377705b5e474a8ed
SHA256 1feebb977e01cabe36018f38618ed8979f9ba1e5cbc176d0b41f1293a3bbaa6d
ssdeep
3072:TlJvcC0RQqK5MMkiE/sDt7HewMkoeZ0NiVP44KPdwq3A:puC0RNYkiDh7PfFCNiJ41Pdw

authentihash 898d44e3603c6b3d3d3a1f494d9b37c8faa629b7e58d0eeb9dbd0d31c169868f
imphash 285e1df271ed2cb49bdd9c9ecee29ca6
File size 428.0 KB ( 438272 bytes )
File type Win32 EXE
Magic literal
PE32 executable for MS Windows (GUI) Intel 80386 32-bit

TrID Win32 Dynamic Link Library (generic) (34.2%)
Win32 Executable (generic) (23.4%)
Win16/32 Executable Delphi generic (10.7%)
OS/2 Executable (generic) (10.5%)
Generic Win/DOS Executable (10.4%)
Tags
peexe

VirusTotal metadata
First submission 2018-11-29 09:35:39 UTC ( 2 months, 3 weeks ago )
Last submission 2018-11-30 01:48:04 UTC ( 2 months, 3 weeks ago )
File names securit
No comments. No VirusTotal Community member has commented on this item yet, be the first one to do so!

Leave your comment...

?
Post comment

You have not signed in. Only registered users can leave comments, sign in and have a voice!

No votes. No one has voted on this item yet, be the first one to do so!