× Cookies are disabled! This site requires cookies to be enabled to work properly
SHA256: bf7f0a3cd703199b4e6919f14b5836d200c2cfc49b4a47ebf53cf9c0c33f5c7e
File name: LFOGRPOW.exe
Detection ratio: 0 / 58
Analysis date: 2017-02-22 10:27:20 UTC ( 4 months, 1 week ago )
Antivirus Result Update
Ad-Aware 20170222
AegisLab 20170222
AhnLab-V3 20170221
Alibaba 20170222
ALYac 20170222
Antiy-AVL 20170222
Arcabit 20170222
Avast 20170222
AVG 20170222
Avira (no cloud) 20170222
AVware 20170222
Baidu 20170222
BitDefender 20170222
Bkav 20170221
CAT-QuickHeal 20170222
ClamAV 20170222
CMC 20170222
Comodo 20170222
CrowdStrike Falcon (ML) 20170130
Cyren 20170222
DrWeb 20170221
Emsisoft 20170222
Endgame 20170217
ESET-NOD32 20170222
F-Prot 20170222
F-Secure 20170222
Fortinet 20170222
GData 20170222
Ikarus 20170222
Invincea 20170203
Jiangmin 20170222
K7AntiVirus 20170222
K7GW 20170222
Kaspersky 20170222
Kingsoft 20170222
Malwarebytes 20170222
McAfee 20170222
McAfee-GW-Edition 20170222
Microsoft 20170222
eScan 20170222
NANO-Antivirus 20170222
nProtect 20170222
Panda 20170221
Qihoo-360 20170222
Rising 20170222
Sophos 20170222
SUPERAntiSpyware 20170222
Symantec 20170221
Tencent 20170222
TheHacker 20170221
TrendMicro 20170222
TrendMicro-HouseCall 20170222
Trustlook 20170222
VBA32 20170221
VIPRE 20170222
ViRobot 20170222
Webroot 20170222
WhiteArmor 20170222
Yandex 20170221
Zillya 20170220
Zoner 20170222
The file being studied is a Portable Executable file! More specifically, it is a Win32 EXE file for the Windows GUI subsystem.
PE header basic information
Target machine Intel 386 or later processors and compatible processors
Compilation timestamp 2010-01-22 12:38:22
Entry Point 0x00003C21
Number of sections 3
PE sections
PE imports
SetSecurityDescriptorDacl
InitializeSecurityDescriptor
GetStockObject
GetLastError
GetCurrentProcess
TerminateProcess
CreateEventW
ReleaseMutex
GetStartupInfoA
GetCurrentProcessId
OutputDebugStringW
GetVersionExW
SetEvent
QueryPerformanceCounter
UnhandledExceptionFilter
SetUnhandledExceptionFilter
GetTickCount
ResetEvent
GetSystemTimeAsFileTime
CreateMutexW
GetCurrentThreadId
WaitForMultipleObjects
CloseHandle
SendMessageW
UpdateWindow
RegisterClassW
TranslateMessage
DefWindowProcW
LoadCursorW
LoadIconW
CreateWindowExW
GetMessageW
PostQuitMessage
ShowWindow
DispatchMessageW
ClosePrinter
GetPrinterW
EnumPrintersW
OpenPrinterW
_except_handler3
__p__fmode
_c_exit
_vsnwprintf
_acmdln
_exit
__p__commode
__setusermatherr
malloc
free
_cexit
wcscmp
exit
_XcptFilter
__getmainargs
_initterm
_controlfp
_adjust_fdiv
__set_app_type
Number of PE resources by type
RT_ICON 2
RT_GROUP_ICON 1
Number of PE resources by language
ENGLISH US 3
PE resources
Debug information
ExifTool file metadata
MIMEType
application/octet-stream

Subsystem
Windows GUI

MachineType
Intel 386 or later, and compatibles

TimeStamp
2010:01:22 13:38:22+01:00

FileType
Win32 EXE

PEType
PE32

CodeSize
13824

LinkerVersion
7.1

FileTypeExtension
exe

InitializedDataSize
3072

SubsystemVersion
4.0

EntryPoint
0x3c21

OSVersion
5.2

ImageVersion
5.2

UninitializedDataSize
0

Compressed bundles
File identification
MD5 9696e3a750d8390daf6a55b542c977c4
SHA1 bfe3b6addb34a25c057631c0e985158e5b90d47c
SHA256 bf7f0a3cd703199b4e6919f14b5836d200c2cfc49b4a47ebf53cf9c0c33f5c7e
ssdeep
384:Vebv6M6Ib7Y70OpmK3ff0Pz27K7QH9fWihcZNtEd9b:VCqK2A4cZq

authentihash 089e31704592c5f3cc2201ada8973878708d24c8d24883280d24236b6bec32c2
imphash 329340baec22945f936d58c880e1207d
File size 16.5 KB ( 16896 bytes )
File type Win32 EXE
Magic literal
PE32 executable for MS Windows (GUI) Intel 80386 32-bit

TrID Win32 Executable MS Visual C++ (generic) (42.2%)
Win64 Executable (generic) (37.3%)
Win32 Dynamic Link Library (generic) (8.8%)
Win32 Executable (generic) (6.0%)
Generic Win/DOS Executable (2.7%)
Tags
peexe

VirusTotal metadata
First submission 2010-10-29 11:27:02 UTC ( 6 years, 8 months ago )
Last submission 2017-02-22 10:27:20 UTC ( 4 months, 1 week ago )
File names DNT-000021
LFOGRPOW.EXE
LFOGRPOW.EXE
LFOGRPOW.EXE
LFOGRPOW.EXE
LFOGRPOW.exe
LFOGRPOW.EXE
No comments. No VirusTotal Community member has commented on this item yet, be the first one to do so!

Leave your comment...

?
Post comment

You have not signed in. Only registered users can leave comments, sign in and have a voice!

No votes. No one has voted on this item yet, be the first one to do so!