× Cookies are disabled! This site requires cookies to be enabled to work properly
SHA256: 9e84e79fdec7101e4f6758d82a30dfff3434534c739bca024d67b029a788f29f
File name: malware.exe
Detection ratio: 6 / 56
Analysis date: 2016-04-20 10:34:25 UTC ( 1 year, 8 months ago ) View latest
Antivirus Result Update
AegisLab Troj.W32.Gen.lMJ4 20160420
AVware Trojan.Win32.Dridex.aac (v) 20160420
Baidu Win32.Trojan.WisdomEyes.151026.9950.9999 20160420
Qihoo-360 QVM20.1.Malware.Gen 20160420
Rising PE:Malware.Generic(Thunder)!1.A1C4 [F] 20160420
VIPRE Trojan.Win32.Dridex.aac (v) 20160420
Ad-Aware 20160420
AhnLab-V3 20160419
Alibaba 20160420
ALYac 20160420
Antiy-AVL 20160420
Arcabit 20160420
Avast 20160420
AVG 20160420
Avira (no cloud) 20160420
Baidu-International 20160420
BitDefender 20160420
Bkav 20160419
CAT-QuickHeal 20160420
ClamAV 20160420
CMC 20160415
Comodo 20160420
Cyren 20160420
DrWeb 20160420
Emsisoft 20160420
ESET-NOD32 20160420
F-Prot 20160420
F-Secure 20160420
Fortinet 20160420
GData 20160420
Ikarus 20160420
Jiangmin 20160420
K7AntiVirus 20160420
K7GW 20160420
Kaspersky 20160420
Kingsoft 20160420
Malwarebytes 20160420
McAfee 20160420
McAfee-GW-Edition 20160420
Microsoft 20160420
eScan 20160420
NANO-Antivirus 20160420
nProtect 20160420
Panda 20160419
Sophos AV 20160420
SUPERAntiSpyware 20160420
Symantec 20160420
Tencent 20160420
TheHacker 20160419
TrendMicro 20160420
TrendMicro-HouseCall 20160420
VBA32 20160420
ViRobot 20160420
Yandex 20160419
Zillya 20160420
Zoner 20160420
The file being studied is a Portable Executable file! More specifically, it is a Win32 EXE file for the Windows GUI subsystem.
FileVersionInfo properties
Copyright
© ?????????? ??????????. ??? ????? ????????.

Product ???????????? ??????? Microsoft® Windows®
Original name Emet312.dll
Internal name emt7ren.dll
File version 5.0.2631.5500 .
Description Media
PE header basic information
Target machine Intel 386 or later processors and compatible processors
Compilation timestamp 2017-03-22 10:16:28
Entry Point 0x0000105A
Number of sections 7
PE sections
PE imports
LoadLibraryExA
SizeofResource
MoveFileWithProgressW
FatalExit
GetNamedPipeHandleStateW
GetLocalTime
Number of PE resources by type
TYPELIB 1
RT_STRING 1
REGISTRY 1
RT_VERSION 1
Number of PE resources by language
RUSSIAN 4
PE resources
ExifTool file metadata
SubsystemVersion
5.0

LinkerVersion
8.0

ImageVersion
0.0

FileSubtype
0

FileVersionNumber
5.1.2605.5512

UninitializedDataSize
0

LanguageCode
Russian

FileFlagsMask
0x003f

CharacterSet
Unicode

InitializedDataSize
0

EntryPoint
0x105a

OriginalFileName
Emet312.dll

MIMEType
application/octet-stream

LegalCopyright
. .

FileVersion
5.0.2631.5500 .

TimeStamp
2017:03:22 11:16:28+01:00

FileType
Win32 EXE

PEType
PE32

InternalName
emt7ren.dll

ProductVersion
5.0.2631.5512

FileDescription
Media

OSVersion
4.1

FileOS
Windows NT 32-bit

Subsystem
Windows GUI

MachineType
Intel 386 or later, and compatibles

CodeSize
61440

ProductName
Microsoft Windows

ProductVersionNumber
5.1.2605.5512

FileTypeExtension
exe

ObjectFileType
Dynamic link library

File identification
MD5 dc55a1928174d3d9341b928bd2055c29
SHA1 35a24aa05dcef3f927d57073400d9a843f63b541
SHA256 9e84e79fdec7101e4f6758d82a30dfff3434534c739bca024d67b029a788f29f
ssdeep
3072:atWGoP53BMFoT7PXM7jqu9cO6+vPbwYGy/nkTUXrxvhqEyMOkykCbZxY:iWGMBoU+eujLwYR/k4XZhqQOkykgZx

authentihash 594d75fc7bab303f6fd1b05aab10851514ee13193b9d3744a6a944aae628c705
imphash bab4d4827fb5c69deb1ed61190dfce20
File size 234.0 KB ( 239616 bytes )
File type Win32 EXE
Magic literal
PE32 executable for MS Windows (GUI) Intel 80386 32-bit

TrID Win64 Executable (generic) (64.6%)
Win32 Dynamic Link Library (generic) (15.4%)
Win32 Executable (generic) (10.5%)
Generic Win/DOS Executable (4.6%)
DOS Executable Generic (4.6%)
Tags
peexe

VirusTotal metadata
First submission 2016-04-20 10:12:43 UTC ( 1 year, 8 months ago )
Last submission 2016-12-17 05:38:38 UTC ( 1 year ago )
File names malware.exe
emt7ren.dll
87ty8hbvcr44
Emet312.dll
87ty8hbvcr44
No comments. No VirusTotal Community member has commented on this item yet, be the first one to do so!

Leave your comment...

?
Post comment

You have not signed in. Only registered users can leave comments, sign in and have a voice!

No votes. No one has voted on this item yet, be the first one to do so!
Condensed report! The following is a condensed report of the behaviour of the file when executed in a controlled environment. The actions and events described were either performed by the file itself or by any other process launched by the executed file or subjected to code injection by the executed file.
Opened files
Read files
Created mutexes
Opened mutexes
Runtime DLLs