× Cookies are disabled! This site requires cookies to be enabled to work properly
SHA256: b399e4c264cdefa2cf11f69ecdb7c914c30ee8320dc96b0b1c7dadc5f880c51a
File name: b399e4c264cdefa2cf11f69ecdb7c914c30ee8320dc96b0b1c7dadc5f880c51a
Detection ratio: 14 / 68
Analysis date: 2018-08-23 10:38:27 UTC ( 5 months, 3 weeks ago ) View latest
Antivirus Result Update
Baidu Win32.Trojan.WisdomEyes.16070401.9500.9999 20180820
Bkav HW32.Packed. 20180823
CAT-QuickHeal Trojan.Emotet.X4 20180822
CrowdStrike Falcon (ML) malicious_confidence_90% (D) 20180723
Cybereason malicious.fa4aff 20180225
Cylance Unsafe 20180823
Endgame malicious (high confidence) 20180730
Microsoft Trojan:Win32/Fuerboos.A!cl 20180823
NANO-Antivirus Virus.Win32.Gen.ccmw 20180823
Qihoo-360 HEUR/QVM19.1.6015.Malware.Gen 20180823
Rising Trojan.Fuerboos!8.EFC8 (TFE:dGZlOgSn14YwKfhPFw) 20180823
SentinelOne (Static ML) static engine - malicious 20180701
Symantec ML.Attribute.HighConfidence 20180823
Webroot W32.Trojan.Emotet 20180823
Ad-Aware 20180823
AegisLab 20180823
AhnLab-V3 20180823
Alibaba 20180713
ALYac 20180823
Antiy-AVL 20180823
Arcabit 20180823
Avast 20180823
Avast-Mobile 20180823
AVG 20180823
Avira (no cloud) 20180823
AVware 20180823
Babable 20180822
BitDefender 20180823
ClamAV 20180823
CMC 20180823
Comodo 20180823
Cyren 20180823
DrWeb 20180823
eGambit 20180823
Emsisoft 20180823
ESET-NOD32 20180823
F-Prot 20180823
F-Secure 20180823
Fortinet 20180823
GData 20180823
Ikarus 20180823
Sophos ML 20180717
Jiangmin 20180823
K7AntiVirus 20180823
K7GW 20180823
Kaspersky 20180823
Kingsoft 20180823
Malwarebytes 20180823
MAX 20180823
McAfee 20180823
McAfee-GW-Edition 20180823
eScan 20180823
Palo Alto Networks (Known Signatures) 20180823
Panda 20180822
Sophos AV 20180823
SUPERAntiSpyware 20180823
Symantec Mobile Insight 20180822
TACHYON 20180823
Tencent 20180823
TheHacker 20180821
TotalDefense 20180823
TrendMicro 20180823
TrendMicro-HouseCall 20180823
Trustlook 20180823
VBA32 20180823
VIPRE 20180823
ViRobot 20180823
Yandex 20180822
Zillya 20180822
ZoneAlarm by Check Point 20180823
Zoner 20180822
The file being studied is a Portable Executable file! More specifically, it is a Win32 EXE file for the Windows GUI subsystem.
FileVersionInfo properties
Copyright
Copyright © 2003-2017 - TortoiseSVN

Product TortoiseSVN
Original name TSVNCache.exe
Internal name TSVNCache.exe
File version 1.9.6.27867
Description TortoiseSVN status cache
PE header basic information
Target machine Intel 386 or later processors and compatible processors
Compilation timestamp 2011-06-14 09:18:59
Entry Point 0x0001CDEE
Number of sections 4
PE sections
PE imports
InitializeSid
QueryUsersOnEncryptedFile
SetTextAlign
GetMapMode
GetTextExtentPoint32A
GetCharWidth32A
LPtoDP
GetTapeParameters
DeviceIoControl
GetWindowsDirectoryW
VirtualFreeEx
lstrlenA
GetPrivateProfileStructW
GetLogicalDrives
GetCommandLineA
VirtualProtect
UnlockFileEx
GetSystemPowerStatus
GetNamedPipeClientSessionId
InitializeSecurityContextW
InternalGetWindowText
SetScrollRange
GetParent
GetKeyboardLayout
GetRawInputData
GetDesktopWindow
fwrite
srand
Number of PE resources by type
RT_ICON 10
RT_GROUP_ICON 1
RT_VERSION 1
RT_MANIFEST 1
Number of PE resources by language
NEUTRAL 11
ENGLISH US 2
PE resources
Debug information
ExifTool file metadata
UninitializedDataSize
4294967295

LinkerVersion
12.0

ImageVersion
0.0

FileSubtype
0

FileVersionNumber
1.9.6.27867

LanguageCode
English (U.S.)

FileFlagsMask
0x003f

FileDescription
TortoiseSVN status cache

ImageFileCharacteristics
Executable, 32-bit

CharacterSet
Windows, Latin1

InitializedDataSize
81920

EntryPoint
0x1cdee

OriginalFileName
TSVNCache.exe

MIMEType
application/octet-stream

LegalCopyright
Copyright 2003-2017 - TortoiseSVN

FileVersion
1.9.6.27867

TimeStamp
2011:06:14 11:18:59+02:00

FileType
Win32 EXE

PEType
PE32

InternalName
TSVNCache.exe

ProductVersion
1.9.6.27867

SubsystemVersion
5.2

OSVersion
6.0

FileOS
Win32

Subsystem
Windows GUI

MachineType
Intel 386 or later, and compatibles

CompanyName
http://tortoisesvn.net

CodeSize
0

ProductName
TortoiseSVN

ProductVersionNumber
1.9.6.27867

FileTypeExtension
exe

ObjectFileType
Executable application

Execution parents
File identification
MD5 657c51f1dc665a733eafe8a98c148d49
SHA1 ac317e7fa4aff40cadf6c144981c8f28cd328781
SHA256 b399e4c264cdefa2cf11f69ecdb7c914c30ee8320dc96b0b1c7dadc5f880c51a
ssdeep
3072:+UkZ3CcLpkGbPG5OQswj+eHiggGFj+D9fLDIPPJ8wxsdOqsJ3MBTyv//6Yf:+t5CgDK5OQZHnWOOOqsJMBmP9

authentihash 19121dafec70a9117176c6271db22365d3f3e1f2409feda82996ce75b52d6299
imphash 906f62f89d01fe103f0b47adc5a35b34
File size 208.0 KB ( 212992 bytes )
File type Win32 EXE
Magic literal
PE32 executable for MS Windows (GUI) Intel 80386 32-bit

TrID Win32 Dynamic Link Library (generic) (38.4%)
Win32 Executable (generic) (26.3%)
OS/2 Executable (generic) (11.8%)
Generic Win/DOS Executable (11.6%)
DOS Executable Generic (11.6%)
Tags
peexe

VirusTotal metadata
First submission 2018-08-23 10:38:27 UTC ( 5 months, 3 weeks ago )
Last submission 2018-08-23 10:38:27 UTC ( 5 months, 3 weeks ago )
File names 31.exe
579.exe
TSVNCache.exe
9392658.exe
CC594E4D.exe
prnisvc.exe
85.exe
prnisvc.exe
9617725.exe
Advanced heuristic and reputation engines
No comments. No VirusTotal Community member has commented on this item yet, be the first one to do so!

Leave your comment...

?
Post comment

You have not signed in. Only registered users can leave comments, sign in and have a voice!

No votes. No one has voted on this item yet, be the first one to do so!