× Cookies are disabled! This site requires cookies to be enabled to work properly
SHA256: c9598fe89c9f4ca470ce47b556fea6289b05b1850c629c2c2f51f2efc995247c
Detection ratio: 0 / 60
Analysis date: 2018-04-12 05:46:02 UTC ( 5 months, 1 week ago ) View latest
Antivirus Result Update
Ad-Aware 20180412
AegisLab 20180412
AhnLab-V3 20180411
ALYac 20180412
Antiy-AVL 20180412
Arcabit 20180412
Avast 20180412
Avast-Mobile 20180411
AVG 20180412
Avira (no cloud) 20180411
AVware 20180412
Baidu 20180411
BitDefender 20180412
Bkav 20180410
CAT-QuickHeal 20180411
ClamAV 20180412
CMC 20180411
Comodo 20180412
CrowdStrike Falcon (ML) 20170201
Cybereason None
Cylance 20180412
Cyren 20180412
DrWeb 20180412
eGambit 20180412
Emsisoft 20180412
Endgame 20180403
ESET-NOD32 20180412
F-Prot 20180412
F-Secure 20180411
Fortinet 20180412
GData 20180412
Sophos ML 20180121
Jiangmin 20180412
K7AntiVirus 20180412
K7GW 20180412
Kaspersky 20180411
Kingsoft 20180412
Malwarebytes 20180411
MAX 20180412
McAfee 20180411
McAfee-GW-Edition 20180411
Microsoft 20180411
eScan 20180411
NANO-Antivirus 20180412
nProtect 20180411
Palo Alto Networks (Known Signatures) 20180412
Panda 20180411
Qihoo-360 20180412
Rising 20180412
SentinelOne (Static ML) 20180225
Sophos AV 20180412
SUPERAntiSpyware 20180412
Symantec 20180412
Symantec Mobile Insight 20180412
Tencent 20180412
TheHacker 20180410
TotalDefense 20180412
TrendMicro 20180412
TrendMicro-HouseCall 20180412
Trustlook 20180412
VBA32 20180411
VIPRE 20180412
ViRobot 20180412
Webroot 20180412
WhiteArmor 20180408
Yandex 20180411
Zillya 20180411
ZoneAlarm by Check Point 20180412
Zoner 20180412
The file being studied is a compressed stream! More specifically, it is a ZIP file.
Interesting properties
The studied file contains at least one Portable Executable.
Contained files
Compression metadata
Contained files
9
Uncompressed size
17573975
Highest datetime
2014-02-01 17:35:02
Lowest datetime
2011-05-11 18:39:56
Contained files by extension
cfg
2
cgz
2
bin
1
exe
1
msg
1
txt
1
Contained files by type
unknown
8
Portable Executable
1
ExifTool file metadata
MIMEType
application/zip

ZipRequiredVersion
20

ZipCRC
0x94376890

FileType
ZIP

ZipCompression
Deflated

ZipUncompressedSize
1517

ZipCompressedSize
550

FileTypeExtension
zip

ZipFileName
boot.msg

ZipBitFlag
0x0002

ZipModifyDate
2014:02:01 17:35:02

Compressed bundles
File identification
MD5 a60dbb91016d93ec5f11e64650394afb
SHA1 f70973e7e9d57a1d55c9c9122e437d20ea07eb3a
SHA256 c9598fe89c9f4ca470ce47b556fea6289b05b1850c629c2c2f51f2efc995247c
ssdeep
393216:/yEJemnY7kXwerEADaqaP7xktQjiwGJydlffAcM9Bai9bS:XY7kXweDaHP9htwyd2cMuGS

File size 16.5 MB ( 17334297 bytes )
File type ZIP
Magic literal
Zip archive data, at least v2.0 to extract

TrID ZIP compressed archive (80.0%)
PrintFox/Pagefox bitmap (var. P) (20.0%)
Tags
contains-pe zip via-tor

VirusTotal metadata
First submission 2014-02-03 01:29:28 UTC ( 4 years, 7 months ago )
Last submission 2018-08-26 21:36:26 UTC ( 3 weeks, 3 days ago )
File names 17.zip
Offline NT Password
usb140201 (ntpasswd).zip
ntpasswd_usb140201.zip
usb140201 (1).zip
usb140201.zip
usb140201.zip
Offline.NT.Password.usb140201.zip
usb140201_2.zip
c9598fe89c9f4ca470ce47b556fea6289b05b1850c629c2c2f51f2efc995247c
usb140201.zip
Password editor.zip
12 - usb140201.zip
usb-boot.zip
file-6553733_zip
usb140201(1).zip
Advanced heuristic and reputation engines
Symantec reputation Suspicious.Insight
No comments. No VirusTotal Community member has commented on this item yet, be the first one to do so!

Leave your comment...

?
Post comment

You have not signed in. Only registered users can leave comments, sign in and have a voice!

No votes. No one has voted on this item yet, be the first one to do so!