× Cookies are disabled! This site requires cookies to be enabled to work properly
SHA256: 6e23c6c7765a38629c10e3efcfe2d1a5e3114ce371cc032cfcc1a93374064820
File name: 6e23c6c7765a38629c10e3efcfe2d1a5e3114ce371cc032cfcc1a93374064820
Detection ratio: 42 / 67
Analysis date: 2018-12-06 12:42:21 UTC ( 2 months, 2 weeks ago ) View latest
Antivirus Result Update
Ad-Aware Trojan.GenericKD.40795659 20181206
AhnLab-V3 Trojan/Win32.Emotet.R246797 20181206
ALYac Trojan.GenericKD.40795659 20181206
Arcabit Trojan.Generic.D26E7E0B 20181206
Avast Win32:BankerX-gen [Trj] 20181206
AVG Win32:BankerX-gen [Trj] 20181206
BitDefender Trojan.GenericKD.40795659 20181206
CAT-QuickHeal Trojan.Emotet.X4 20181206
Comodo Malware@#2ncpqg1or43nf 20181206
CrowdStrike Falcon (ML) malicious_confidence_100% (W) 20181022
DrWeb Trojan.EmotetENT.315 20181206
Emsisoft Trojan.Emotet (A) 20181206
Endgame malicious (high confidence) 20181108
ESET-NOD32 a variant of Win32/Kryptik.GNHH 20181206
F-Secure Trojan.GenericKD.40795659 20181206
Fortinet W32/Kryptik.GNFC!tr 20181206
GData Trojan.GenericKD.40795659 20181206
Ikarus Trojan-Banker.Emotet 20181206
Sophos ML heuristic 20181128
K7AntiVirus Trojan ( 00542b071 ) 20181206
K7GW Trojan ( 00542b071 ) 20181206
Kaspersky Trojan-Banker.Win32.Emotet.bskf 20181206
Malwarebytes Trojan.Emotet 20181206
MAX malware (ai score=100) 20181206
McAfee Emotet-FIB!821FE37DD450 20181206
McAfee-GW-Edition Emotet-FIB!821FE37DD450 20181206
Microsoft Trojan:Win32/Emotet.BF 20181206
eScan Trojan.GenericKD.40795659 20181206
NANO-Antivirus Trojan.Win32.Emotet.fktvng 20181206
Palo Alto Networks (Known Signatures) generic.ml 20181206
Panda Trj/GdSda.A 20181206
Rising Trojan.Kryptik!8.8 (CLOUD) 20181206
SentinelOne (Static ML) static engine - malicious 20181011
Sophos AV Mal/EncPk-ANY 20181206
Symantec Trojan.Gen.2 20181206
Tencent Win32.Trojan-banker.Emotet.Dwtb 20181206
Trapmine malicious.moderate.ml.score 20181205
TrendMicro TSPY_EMOTET.THAABIAH 20181206
TrendMicro-HouseCall TSPY_EMOTET.THAABIAH 20181206
VBA32 BScope.Trojan.EmotetENT 20181205
Webroot W32.Trojan.Emotet 20181206
ZoneAlarm by Check Point Trojan-Banker.Win32.Emotet.bskf 20181206
AegisLab 20181206
Alibaba 20180921
Antiy-AVL 20181205
Avast-Mobile 20181206
Avira (no cloud) 20181206
Babable 20180918
Baidu 20181206
Bkav 20181205
CMC 20181205
Cybereason 20180225
Cyren 20181206
eGambit 20181206
F-Prot 20181206
Jiangmin 20181206
Kingsoft 20181206
Qihoo-360 20181206
SUPERAntiSpyware 20181205
Symantec Mobile Insight 20181204
TACHYON 20181206
TheHacker 20181202
TotalDefense 20181206
Trustlook 20181206
ViRobot 20181206
Yandex 20181204
Zillya 20181206
Zoner 20181206
The file being studied is a Portable Executable file! More specifically, it is a Win32 EXE file for the Windows GUI subsystem.
FileVersionInfo properties
Copyright
© Microsoft Corporation

Product Microsoft®
Internal name securit
File version 3.00.
Description V
PE header basic information
Target machine Intel 386 or later processors and compatible processors
Compilation timestamp 2018-11-29 08:45:22
Entry Point 0x000632FC
Number of sections 5
PE sections
PE imports
GetNamedPipeClientProcessId
GetModuleHandleA
GetTimeZoneInformation
LZSeek
DdeConnect
timeGetTime
CryptCATOpen
CoInvalidateRemoteMachineBindings
Number of PE resources by type
RT_STRING 5
RT_RCDATA 1
RT_VERSION 1
Number of PE resources by language
NEUTRAL 6
ENGLISH US 1
PE resources
ExifTool file metadata
SpecialBuild
[pre-release version: pre-alpha]

SubsystemVersion
5.0

LinkerVersion
12.0

ImageVersion
0.0

FileSubtype
0

FileVersionNumber
8.0.0.0

LanguageCode
English (U.S.)

FileFlagsMask
0x003f

FileDescription
V

ImageFileCharacteristics
Executable, 32-bit

CharacterSet
Windows, Latin1

InitializedDataSize
32768

EntryPoint
0x632fc

MIMEType
application/octet-stream

LegalCopyright
Microsoft Corporation

FileVersion
3.00.

TimeStamp
2018:11:29 09:45:22+01:00

FileType
Win32 EXE

PEType
PE32

InternalName
securit

UninitializedDataSize
0

OSVersion
5.0

FileOS
Win32

Subsystem
Windows GUI

MachineType
Intel 386 or later, and compatibles

CompanyName
S Corpora

CodeSize
409600

ProductName
Microsoft

ProductVersionNumber
0.0.0.0

FileTypeExtension
exe

ObjectFileType
Dynamic link library

File identification
MD5 821fe37dd450676a20f6bcae0eba5dd5
SHA1 2c7b39ca681994725c0480b112c0617f587ac0d2
SHA256 6e23c6c7765a38629c10e3efcfe2d1a5e3114ce371cc032cfcc1a93374064820
ssdeep
3072:9ypgnwr1WC22nsG30PBnu7CwO2ne3AYwoSTJdWbgSp3y:4JzfF34Bnu7Cw9njASrWbg

authentihash 62fab22bddefdf03e8495f4e6937c1d866249c8a2f57180f41a9cceca349f3dc
imphash 2ec3519d41b1238f1a9d864566628d18
File size 428.0 KB ( 438272 bytes )
File type Win32 EXE
Magic literal
PE32 executable for MS Windows (GUI) Intel 80386 32-bit

TrID Win32 Dynamic Link Library (generic) (34.2%)
Win32 Executable (generic) (23.4%)
Win16/32 Executable Delphi generic (10.7%)
OS/2 Executable (generic) (10.5%)
Generic Win/DOS Executable (10.4%)
Tags
peexe

VirusTotal metadata
First submission 2018-11-29 08:51:37 UTC ( 2 months, 3 weeks ago )
Last submission 2018-11-29 08:51:37 UTC ( 2 months, 3 weeks ago )
File names securit
No comments. No VirusTotal Community member has commented on this item yet, be the first one to do so!

Leave your comment...

?
Post comment

You have not signed in. Only registered users can leave comments, sign in and have a voice!

No votes. No one has voted on this item yet, be the first one to do so!