× Cookies are disabled! This site requires cookies to be enabled to work properly
SHA256: 736933e32941a907d1e88754553064e3d26ef3c7c63abef9e5e4c84ef9b27af5
File name: 978d264dd88a4772976aff4ebe100d592fbf31aa
Detection ratio: 37 / 66
Analysis date: 2018-05-13 16:09:51 UTC ( 9 months, 2 weeks ago ) View latest
Antivirus Result Update
Ad-Aware Trojan.GenericKD.30781850 20180513
AegisLab Uds.Dangerousobject.Multi!c 20180513
Arcabit Trojan.Generic.D1D5B19A 20180513
Avast Win32:Malware-gen 20180513
AVG Win32:Malware-gen 20180513
Avira (no cloud) TR/Crypt.ZPACK.hornv 20180513
Babable Malware.HighConfidence 20180406
Baidu Win32.Trojan.WisdomEyes.16070401.9500.9990 20180511
BitDefender Trojan.GenericKD.30781850 20180513
CAT-QuickHeal Trojan.Azden 20180513
Comodo UnclassifiedMalware 20180513
CrowdStrike Falcon (ML) malicious_confidence_100% (W) 20180418
Cylance Unsafe 20180513
Cyren W32/Trojan.BSOR-7153 20180513
Emsisoft Trojan.GenericKD.30781850 (B) 20180513
Endgame malicious (high confidence) 20180507
ESET-NOD32 a variant of Win32/Kryptik.GGPE 20180513
Fortinet W32/GenKryptik.BTIX!tr 20180513
Ikarus Trojan.Win32.Crypt 20180513
Sophos ML heuristic 20180503
Kaspersky Trojan-Banker.Win32.Shiotob.woz 20180513
MAX malware (ai score=95) 20180513
McAfee Artemis!A4B143B2FB98 20180513
McAfee-GW-Edition BehavesLike.Win32.Generic.dh 20180513
Microsoft Trojan:Win32/Occamy.C 20180513
eScan Trojan.GenericKD.30781850 20180513
Palo Alto Networks (Known Signatures) generic.ml 20180513
Panda Trj/CI.A 20180513
Qihoo-360 HEUR/QVM20.1.1E05.Malware.Gen 20180513
Rising Malware.Heuristic!ET#89% (RDM+:cmRtazpB2X31nHAnyoX4qIsJMTTz) 20180513
SentinelOne (Static ML) static engine - malicious 20180225
Sophos AV Mal/Generic-S 20180513
Symantec ML.Attribute.HighConfidence 20180512
TrendMicro-HouseCall Suspicious_GEN.F47V0512 20180513
VBA32 BScope.Trojan.Agent 20180511
Webroot W32.Trojan.Gen 20180513
ZoneAlarm by Check Point Trojan-Banker.Win32.Shiotob.woz 20180513
AhnLab-V3 20180513
Alibaba 20180511
ALYac 20180513
Antiy-AVL 20180513
Avast-Mobile 20180513
AVware 20180428
Bkav 20180511
ClamAV 20180513
CMC 20180513
Cybereason None
eGambit 20180513
F-Prot 20180513
F-Secure 20180513
GData 20180513
Jiangmin 20180513
K7AntiVirus 20180513
K7GW 20180513
Kingsoft 20180513
Malwarebytes 20180513
NANO-Antivirus 20180513
nProtect 20180513
SUPERAntiSpyware 20180513
Symantec Mobile Insight 20180511
Tencent 20180513
TheHacker 20180509
TotalDefense 20180513
TrendMicro 20180513
Trustlook 20180513
VIPRE 20180513
ViRobot 20180513
Yandex 20180511
Zillya 20180511
Zoner 20180512
The file being studied is a Portable Executable file! More specifically, it is a Win32 EXE file for the Windows GUI subsystem.
FileVersionInfo properties
Copyright
© Microsoft Corporation. All rights reserved.

Product Microsoft® Visual Studio® 2015
Original name MFC140JPN.DLL
Internal name MFC140JPN.DLL
File version 14.0.23026.0 built by: WCSETUP
Description MFC Language Specific Resources
PE header basic information
Target machine Intel 386 or later processors and compatible processors
Compilation timestamp 2028-12-25 04:27:37
Entry Point 0x00002116
Number of sections 6
PE sections
PE imports
GetThreadTimes
GetProcAddress
AssignProcessToJobObject
FlsFree
GetModuleHandleW
AnyPopup
GetMessagePos
InSendMessage
CountClipboardFormats
SetWindowContextHelpId
InternetGetConnectedState
Number of PE resources by type
RT_STRING 60
RT_DIALOG 27
RT_MENU 1
RT_VERSION 1
Struct(240) 1
Number of PE resources by language
JAPANESE DEFAULT 90
PE resources
ExifTool file metadata
UninitializedDataSize
0

LinkerVersion
12.0

ImageVersion
0.0

FileSubtype
0

FileVersionNumber
14.0.23026.0

LanguageCode
Japanese

FileFlagsMask
0x003f

FileDescription
MFC Language Specific Resources

ImageFileCharacteristics
Executable, 32-bit

CharacterSet
Unicode

InitializedDataSize
212992

EntryPoint
0x2116

OriginalFileName
MFC140JPN.DLL

MIMEType
application/octet-stream

LegalCopyright
Microsoft Corporation. All rights reserved.

FileVersion
14.0.23026.0 built by: WCSETUP

TimeStamp
2028:12:24 20:27:37-08:00

FileType
Win32 EXE

PEType
PE32

InternalName
MFC140JPN.DLL

ProductVersion
14.0.23026.0

SubsystemVersion
5.0

OSVersion
5.0

FileOS
Win32

Subsystem
Windows GUI

MachineType
Intel 386 or later, and compatibles

CompanyName
Microsoft Corporation

CodeSize
0

ProductName
Microsoft Visual Studio 2015

ProductVersionNumber
14.0.23026.0

FileTypeExtension
exe

ObjectFileType
Dynamic link library

File identification
MD5 a4b143b2fb98db36d986cac28e3a1536
SHA1 978d264dd88a4772976aff4ebe100d592fbf31aa
SHA256 736933e32941a907d1e88754553064e3d26ef3c7c63abef9e5e4c84ef9b27af5
ssdeep
3072:vNaO3wnxj4DcswK4+hwTTv0ineWxqeIC4LeXecHJTj62bZQW9nGDJIGBj6Olwqa7:vNaO3lCCpa7S

authentihash cbd196e793f78181cf86076c96259a89e668e6851c6e8e38957ccebe4118fdf2
imphash eec130839b38f147818383e6b7fad7b6
File size 213.0 KB ( 218112 bytes )
File type Win32 EXE
Magic literal
PE32 executable for MS Windows (GUI) Intel 80386 32-bit

TrID Win32 Executable (generic) (35.7%)
Win16/32 Executable Delphi generic (16.4%)
OS/2 Executable (generic) (16.0%)
Generic Win/DOS Executable (15.8%)
DOS Executable Generic (15.8%)
Tags
peexe

VirusTotal metadata
First submission 2018-05-12 22:51:10 UTC ( 9 months, 2 weeks ago )
Last submission 2018-05-28 17:53:39 UTC ( 9 months ago )
File names MFC140JPN.DLL
aa
No comments. No VirusTotal Community member has commented on this item yet, be the first one to do so!

Leave your comment...

?
Post comment

You have not signed in. Only registered users can leave comments, sign in and have a voice!

No votes. No one has voted on this item yet, be the first one to do so!