× Cookies are disabled! This site requires cookies to be enabled to work properly
SHA256: 356b92361987a0e0a7372c96bd632c175946ce2ed612557845760e15dd7d2c21
File name: 124586
Detection ratio: 1 / 61
Analysis date: 2018-06-09 16:20:02 UTC ( 5 months, 1 week ago ) View latest
Antivirus Result Update
Cylance Unsafe 20180609
Ad-Aware 20180609
AegisLab 20180609
AhnLab-V3 20180609
Alibaba 20180608
ALYac 20180609
Antiy-AVL 20180609
Arcabit 20180609
Avast 20180609
Avast-Mobile 20180609
AVG 20180609
AVware 20180609
Babable 20180406
Baidu 20180608
BitDefender 20180609
Bkav 20180609
CAT-QuickHeal 20180609
ClamAV 20180609
CMC 20180609
Comodo 20180609
CrowdStrike Falcon (ML) 20180530
Cybereason 20180225
Cyren 20180609
DrWeb 20180609
eGambit 20180609
Emsisoft 20180609
Endgame 20180507
ESET-NOD32 20180609
F-Prot 20180609
F-Secure 20180609
Fortinet 20180609
GData 20180609
Ikarus 20180609
Sophos ML 20180601
Jiangmin 20180609
K7AntiVirus 20180609
K7GW 20180609
Kaspersky 20180609
Kingsoft 20180609
Malwarebytes 20180609
MAX 20180609
McAfee 20180609
McAfee-GW-Edition 20180609
Microsoft 20180609
eScan 20180609
NANO-Antivirus 20180609
Palo Alto Networks (Known Signatures) 20180609
Panda 20180609
Qihoo-360 20180609
Rising 20180609
SentinelOne (Static ML) 20180225
Sophos AV 20180609
SUPERAntiSpyware 20180609
Symantec 20180609
Symantec Mobile Insight 20180605
TACHYON 20180608
Tencent 20180609
TheHacker 20180608
TotalDefense 20180609
TrendMicro 20180609
TrendMicro-HouseCall 20180609
Trustlook 20180609
VBA32 20180608
VIPRE 20180609
ViRobot 20180609
Webroot 20180609
Yandex 20180609
Zillya 20180608
ZoneAlarm by Check Point 20180609
Zoner 20180608
The file being studied is a compressed stream! More specifically, it is a ZIP file.
Interesting properties
The studied file contains at least one Portable Executable.
Contained files
Compression metadata
Contained files
9
Uncompressed size
2144564
Highest datetime
2011-05-26 12:35:12
Lowest datetime
1999-11-19 06:43:10
Contained files by extension
cab
2
bin
1
exe
1
inx
1
hdr
1
bmp
1
ini
1
ex_
1
Contained files by type
unknown
7
BMP
1
Portable Executable
1
ExifTool file metadata
MIMEType
application/zip

ZipRequiredVersion
20

ZipCRC
0xd1c4f052

FileType
ZIP

ZipCompression
Deflated

ZipUncompressedSize
235256

ZipCompressedSize
33977

FileTypeExtension
zip

ZipFileName
setup.bmp

ZipBitFlag
0x0002

ZipModifyDate
2002:02:17 09:04:58

File identification
MD5 9c7af7b594ca242c23aaaccb8d260576
SHA1 8ff91d32839ecfe6c33ff944fc0eb14a0575a705
SHA256 356b92361987a0e0a7372c96bd632c175946ce2ed612557845760e15dd7d2c21
ssdeep
49152:K/97cpIU7yhlhcOHGPupMyUDAvnPXnz5kQ9lhW:s97m8cOHG6G0PlkQ9lM

File size 1.7 MB ( 1807350 bytes )
File type ZIP
Magic literal
Zip archive data, at least v2.0 to extract

TrID ZIP compressed archive (80.0%)
PrintFox/Pagefox bitmap (var. P) (20.0%)
Tags
contains-pe zip

VirusTotal metadata
First submission 2011-12-24 23:59:40 UTC ( 6 years, 11 months ago )
Last submission 2018-05-27 07:09:02 UTC ( 5 months, 3 weeks ago )
File names 124586
PDFUAppendDE.zip
1341958020-PDFUAppendDE.exe
Advanced heuristic and reputation engines
Symantec reputation Suspicious.Insight
No comments. No VirusTotal Community member has commented on this item yet, be the first one to do so!

Leave your comment...

?
Post comment

You have not signed in. Only registered users can leave comments, sign in and have a voice!

No votes. No one has voted on this item yet, be the first one to do so!