× Cookies are disabled! This site requires cookies to be enabled to work properly
SHA256: c7a53b22c8514b81423aeb0a920e0fa20df08a956d6144764148f984c82042f5
File name: UQgbLtGW415vMb.exe
Detection ratio: 23 / 70
Analysis date: 2018-12-15 09:46:45 UTC ( 2 months, 1 week ago ) View latest
Antivirus Result Update
Avast FileRepMalware 20181215
AVG FileRepMalware 20181215
Bkav HW32.Packed. 20181214
CAT-QuickHeal Trojan.Emotet.X4 20181214
CrowdStrike Falcon (ML) malicious_confidence_100% (W) 20181022
Cybereason malicious.ef4696 20180225
Cylance Unsafe 20181215
Endgame malicious (high confidence) 20181108
ESET-NOD32 a variant of Win32/Kryptik.GNVA 20181215
Sophos ML heuristic 20181128
K7AntiVirus Spyware ( 005068aa1 ) 20181214
K7GW Spyware ( 005068aa1 ) 20181215
Kaspersky UDS:DangerousObject.Multi.Generic 20181215
McAfee-GW-Edition BehavesLike.Win32.Generic.ch 20181215
Microsoft Trojan:Win32/Emotet.AC!bit 20181215
Palo Alto Networks (Known Signatures) generic.ml 20181215
Qihoo-360 HEUR/QVM20.1.E0EE.Malware.Gen 20181215
Rising Trojan.Fuerboos!8.EFC8 (TFE:dGZlOgJHFPKNzEd+lQ) 20181214
SentinelOne (Static ML) static engine - malicious 20181011
Symantec ML.Attribute.HighConfidence 20181215
Trapmine malicious.moderate.ml.score 20181205
Webroot W32.Trojan.Emotet 20181215
ZoneAlarm by Check Point UDS:DangerousObject.Multi.Generic 20181215
Ad-Aware 20181215
AegisLab 20181214
AhnLab-V3 20181214
Alibaba 20180921
ALYac 20181215
Antiy-AVL 20181215
Arcabit 20181215
Avast-Mobile 20181215
Avira (no cloud) 20181215
Babable 20180918
Baidu 20181207
BitDefender 20181215
ClamAV 20181215
CMC 20181215
Comodo 20181215
Cyren 20181215
DrWeb 20181215
eGambit 20181215
Emsisoft 20181215
F-Prot 20181215
F-Secure 20181215
Fortinet 20181215
GData 20181215
Ikarus 20181215
Jiangmin 20181215
Kingsoft 20181215
Malwarebytes 20181215
MAX 20181215
McAfee 20181215
eScan 20181215
NANO-Antivirus 20181215
Panda 20181214
Sophos AV 20181215
SUPERAntiSpyware 20181212
Symantec Mobile Insight 20181215
TACHYON 20181214
Tencent 20181215
TheHacker 20181213
TotalDefense 20181215
TrendMicro 20181215
TrendMicro-HouseCall 20181215
Trustlook 20181215
VBA32 20181214
VIPRE 20181214
ViRobot 20181214
Yandex 20181214
Zillya 20181213
Zoner 20181215
The file being studied is a Portable Executable file! More specifically, it is a Win32 EXE file for the Windows GUI subsystem.
FileVersionInfo properties
PE header basic information
Target machine Intel 386 or later processors and compatible processors
Compilation timestamp 2018-12-15 16:40:50
Entry Point 0x00006BBB
Number of sections 4
PE sections
PE imports
SetSecurityAccessMask
GetColorAdjustment
GetTempFileNameW
GetNamedPipeClientProcessId
FlushProcessWriteBuffers
GetPriorityClass
GetEnvironmentStrings
GetModuleHandleW
VarCyRound
waveOutReset
Ord(29)
ExifTool file metadata
MIMEType
application/octet-stream

Subsystem
Windows GUI

MachineType
Intel 386 or later, and compatibles

FileTypeExtension
exe

TimeStamp
2018:12:15 08:40:50-08:00

FileType
Win32 EXE

PEType
PE32

CodeSize
32768

LinkerVersion
12.0

ImageFileCharacteristics
No relocs, Executable, 32-bit

EntryPoint
0x6bbb

InitializedDataSize
114688

SubsystemVersion
4.0

ImageVersion
0.0

OSVersion
5.0

UninitializedDataSize
0

Execution parents
File identification
MD5 e07c500b848df76d0a068166e19efc50
SHA1 c038a48ef46968472c76952dddcb69d4662dd512
SHA256 c7a53b22c8514b81423aeb0a920e0fa20df08a956d6144764148f984c82042f5
ssdeep
1536:10lnkzYGu49RUM13e7eusa0+WfCL+otz9QVMda85qZ20ywU/8dLl3+S3S7W17cr2:WnksJkB5Keus13otT5qZTIuZ3nZcFWT

authentihash 6bdbde9dd592189b605901eccc840ac04563ff8682033d397718e293ceb58571
imphash 825cf9068b74ab2c3488c0435dabea92
File size 144.0 KB ( 147456 bytes )
File type Win32 EXE
Magic literal
PE32 executable for MS Windows (GUI) Intel 80386 32-bit

TrID Win32 Dynamic Link Library (generic) (34.2%)
Win32 Executable (generic) (23.4%)
Win16/32 Executable Delphi generic (10.7%)
OS/2 Executable (generic) (10.5%)
Generic Win/DOS Executable (10.4%)
Tags
peexe

VirusTotal metadata
First submission 2018-12-15 08:46:32 UTC ( 2 months, 1 week ago )
Last submission 2019-01-10 07:25:01 UTC ( 1 month, 2 weeks ago )
File names UQgbLtGW415vMb.exe
907.exe
output.114713304.txt
5E3yqHjYA5.exe
e07c500b848df76d0a068166e19efc50
No comments. No VirusTotal Community member has commented on this item yet, be the first one to do so!

Leave your comment...

?
Post comment

You have not signed in. Only registered users can leave comments, sign in and have a voice!

No votes. No one has voted on this item yet, be the first one to do so!