× Cookies are disabled! This site requires cookies to be enabled to work properly
SHA256: 58ef070a55cfff7710b9c1bc67f9d64c005881f95fa71b995f017cec97eee922
File name: SpecialImagePlayer.zip
Detection ratio: 3 / 56
Analysis date: 2015-12-03 02:27:17 UTC ( 5 months, 3 weeks ago )
Antivirus Result Update
Avast NSIS:Relevant-I [PUP] 20151203
Baidu-International Adware.Win32.RK.AP 20151202
ESET-NOD32 Win32/Adware.RK.AP 20151203
ALYac 20151203
AVG 20151130
AVware 20151203
Ad-Aware 20151130
AegisLab 20151202
Yandex 20151202
AhnLab-V3 20151202
Alibaba 20151203
Antiy-AVL 20151203
Arcabit 20151203
Avira (no cloud) 20151203
BitDefender 20151203
Bkav 20151202
ByteHero 20151203
CAT-QuickHeal 20151202
CMC 20151201
ClamAV 20151202
Comodo 20151202
Cyren 20151203
DrWeb 20151203
Emsisoft 20151103
F-Prot 20151203
F-Secure 20151203
Fortinet 20151202
GData 20151203
Ikarus 20151203
Jiangmin 20151201
K7AntiVirus 20151202
K7GW 20151202
Kaspersky 20151203
Malwarebytes 20151203
McAfee 20151203
McAfee-GW-Edition 20151203
eScan 20151203
Microsoft 20151203
NANO-Antivirus 20151203
Panda 20151202
Qihoo-360 20151203
Rising 20151202
SUPERAntiSpyware 20151202
Sophos 20151203
Symantec 20151202
Tencent 20151203
TheHacker 20151202
TotalDefense 20151202
TrendMicro 20151203
TrendMicro-HouseCall 20151203
VBA32 20151202
VIPRE 20151203
ViRobot 20151202
Zillya 20151201
Zoner 20151203
nProtect 20151202
The file being studied is a compressed stream! More specifically, it is a ZIP file.
Interesting properties
The studied file contains at least one Portable Executable.
Contained files
Compression metadata
Contained files
1
Uncompressed size
1596899
Highest datetime
2013-05-16 22:28:22
Lowest datetime
2013-05-16 22:28:22
Contained files by extension
exe
1
Contained files by type
Portable Executable
1
ExifTool file metadata
MIMEType
application/zip

ZipRequiredVersion
20

ZipCRC
0x6e741cd7

FileType
ZIP

ZipCompression
Deflated

ZipUncompressedSize
1596899

ZipCompressedSize
1571046

FileTypeExtension
zip

ZipFileName
SpecialImagePlayer.exe

ZipBitFlag
0

ZipModifyDate
2013:05:16 22:28:11

File identification
MD5 3056e4859f7671237e277fdb7fd5c0b8
SHA1 b40bb852dd859aabccb74d7d42f29b0a0941fa25
SHA256 58ef070a55cfff7710b9c1bc67f9d64c005881f95fa71b995f017cec97eee922
ssdeep
24576:N7I/MZNj7ZED6Xv/ZBB7W9cjP1Tl+HipzCEleVVku2aAITI+Q9I6KN4o/0BzCir6:N7siN/ZEWRWgP1Tl+H+OEcMt719I6ZoF

File size 1.5 MB ( 1571188 bytes )
File type ZIP
Magic literal
Zip archive data, at least v2.0 to extract

TrID ZIP compressed archive (100.0%)
Tags
contains-pe zip

VirusTotal metadata
First submission 2013-05-17 07:09:16 UTC ( 3 years ago )
Last submission 2015-12-03 02:27:17 UTC ( 5 months, 3 weeks ago )
File names SLIDE FOTOS - SpecialImagePlayer.zip
e4b2661ecbe54012f2e2a9bd66c8e23edf4ec1da
SpecialImagePlayer.zip
special-image-player-7194-jetelecharge.zip
file
SpecialImagePlayer.zip
file-5561116_zip
myfile
SpecialImagePlayer.zip
Advanced heuristic and reputation engines
ClamAV
Possibly Unwanted Application. While not necessarily malicious, the scanned file presents certain characteristics which depending on the user policies and environment may or may not represent a threat. For full details see: http://www.clamav.net/doc/pua.html .

Symantec reputation Suspicious.Insight
No comments. No VirusTotal Community member has commented on this item yet, be the first one to do so!

Leave your comment...

?
Post comment

You have not signed in. Only registered users can leave comments, sign in and have a voice!

No votes. No one has voted on this item yet, be the first one to do so!