× Cookies are disabled! This site requires cookies to be enabled to work properly
SHA256: 3aa53457ec55fe3888fb198c40fec1804c59b22df84e8944136d009c54c1be2f
File name: lTTmhnUSXKBit.exe
Detection ratio: 20 / 69
Analysis date: 2018-12-15 08:22:10 UTC ( 2 months, 1 week ago ) View latest
Antivirus Result Update
Avast FileRepMalware 20181215
AVG FileRepMalware 20181215
Bkav HW32.Packed. 20181214
CAT-QuickHeal Trojan.Emotet.X4 20181214
CrowdStrike Falcon (ML) malicious_confidence_100% (D) 20181022
Cybereason malicious.c9b1b6 20180225
Cylance Unsafe 20181215
Endgame malicious (high confidence) 20181108
ESET-NOD32 a variant of Win32/Kryptik.GNVA 20181215
Sophos ML heuristic 20181128
K7AntiVirus Spyware ( 005068aa1 ) 20181214
K7GW Spyware ( 005068aa1 ) 20181215
McAfee-GW-Edition BehavesLike.Win32.Generic.ch 20181215
Microsoft Trojan:Win32/Emotet.AC!bit 20181215
Qihoo-360 HEUR/QVM20.1.E0C5.Malware.Gen 20181215
Rising Trojan.Fuerboos!8.EFC8 (TFE:2:xBEn8WEcuzM) 20181214
SentinelOne (Static ML) static engine - malicious 20181011
Sophos AV Mal/EncPk-ANX 20181215
Symantec ML.Attribute.HighConfidence 20181215
Trapmine malicious.moderate.ml.score 20181205
Ad-Aware 20181215
AegisLab 20181214
AhnLab-V3 20181214
Alibaba 20180921
ALYac 20181215
Antiy-AVL 20181215
Arcabit 20181215
Avast-Mobile 20181215
Avira (no cloud) 20181215
Babable 20180918
Baidu 20181207
BitDefender 20181215
ClamAV 20181215
CMC 20181215
Comodo 20181215
Cyren 20181215
DrWeb 20181215
eGambit 20181215
Emsisoft 20181215
F-Prot 20181215
F-Secure 20181215
Fortinet 20181215
GData 20181215
Ikarus 20181215
Jiangmin 20181215
Kaspersky 20181215
Kingsoft 20181215
Malwarebytes 20181215
MAX 20181215
McAfee 20181215
eScan 20181215
NANO-Antivirus 20181215
Palo Alto Networks (Known Signatures) 20181215
Panda 20181214
SUPERAntiSpyware 20181212
Symantec Mobile Insight 20181215
TACHYON 20181214
Tencent 20181215
TheHacker 20181213
TotalDefense 20181215
TrendMicro 20181215
TrendMicro-HouseCall 20181215
Trustlook 20181215
VBA32 20181214
ViRobot 20181214
Webroot 20181215
Yandex 20181214
Zillya 20181213
ZoneAlarm by Check Point 20181215
Zoner 20181215
The file being studied is a Portable Executable file! More specifically, it is a Win32 EXE file for the Windows GUI subsystem.
FileVersionInfo properties
PE header basic information
Target machine Intel 386 or later processors and compatible processors
Compilation timestamp 2018-12-15 16:13:16
Entry Point 0x00006E8D
Number of sections 4
PE sections
PE imports
SetSecurityAccessMask
GetColorAdjustment
GetTempFileNameW
GetNamedPipeClientProcessId
FlushProcessWriteBuffers
GetPriorityClass
GetEnvironmentStrings
GetModuleHandleW
VarCyRound
waveOutReset
Ord(29)
ExifTool file metadata
MIMEType
application/octet-stream

Subsystem
Windows GUI

MachineType
Intel 386 or later, and compatibles

FileTypeExtension
exe

TimeStamp
2018:12:15 17:13:16+01:00

FileType
Win32 EXE

PEType
PE32

CodeSize
32768

LinkerVersion
12.0

ImageFileCharacteristics
No relocs, Executable, 32-bit

EntryPoint
0x6e8d

InitializedDataSize
114688

SubsystemVersion
4.0

ImageVersion
0.0

OSVersion
5.0

UninitializedDataSize
0

File identification
MD5 4fd7d3b43c288e5f263b3456b83e58a8
SHA1 101ea7ac9b1b6eadcf9c3477d39cc4386461d1ef
SHA256 3aa53457ec55fe3888fb198c40fec1804c59b22df84e8944136d009c54c1be2f
ssdeep
3072:o2jvUVtq2Ag9c0hT4LBzGciT9tLx7LPnSsqZXA8:o2oVt+6ew7xLDYX

authentihash c82c98548dfce2f061c9d0440b4cc8bac5f5492ca36bc37ca5d56f823fcc8e5a
imphash 85fe53e2c8132efa3b09e55a52f2244c
File size 144.0 KB ( 147456 bytes )
File type Win32 EXE
Magic literal
PE32 executable for MS Windows (GUI) Intel 80386 32-bit

TrID Win32 Dynamic Link Library (generic) (34.2%)
Win32 Executable (generic) (23.4%)
Win16/32 Executable Delphi generic (10.7%)
OS/2 Executable (generic) (10.5%)
Generic Win/DOS Executable (10.4%)
Tags
peexe

VirusTotal metadata
First submission 2018-12-15 08:18:14 UTC ( 2 months, 1 week ago )
Last submission 2018-12-15 08:22:10 UTC ( 2 months, 1 week ago )
File names lTTmhnUSXKBit.exe
No comments. No VirusTotal Community member has commented on this item yet, be the first one to do so!

Leave your comment...

?
Post comment

You have not signed in. Only registered users can leave comments, sign in and have a voice!

No votes. No one has voted on this item yet, be the first one to do so!