× Cookies are disabled! This site requires cookies to be enabled to work properly
SHA256: d47c4112b596db6ca7409729f80894dec6b0af6da1c6699ee21aeff38ece9d04
File name: need-for-speed-underground-2-766-jetelecharge.exe
Detection ratio: 1 / 60
Analysis date: 2017-05-12 12:57:57 UTC ( 1 year, 1 month ago ) View latest
Antivirus Result Update
Jiangmin TrojanClicker.Agent.clt 20170512
Ad-Aware 20170512
AegisLab 20170512
AhnLab-V3 20170512
Alibaba 20170512
ALYac 20170512
Arcabit 20170512
Avast 20170512
AVG 20170512
Avira (no cloud) 20170512
AVware 20170512
Baidu 20170503
BitDefender 20170512
CAT-QuickHeal 20170512
ClamAV 20170512
CMC 20170511
Comodo 20170512
CrowdStrike Falcon (ML) 20170130
Cyren 20170512
DrWeb 20170512
Emsisoft 20170512
Endgame 20170503
ESET-NOD32 20170512
F-Prot 20170512
F-Secure 20170512
Fortinet 20170512
GData 20170512
Ikarus 20170512
Sophos ML 20170413
K7AntiVirus 20170512
K7GW 20170512
Kaspersky 20170512
Kingsoft 20170512
Malwarebytes 20170512
McAfee 20170512
McAfee-GW-Edition 20170511
Microsoft 20170512
eScan 20170512
NANO-Antivirus 20170512
nProtect 20170512
Palo Alto Networks (Known Signatures) 20170512
Panda 20170512
Qihoo-360 20170512
Rising 20170512
SentinelOne (Static ML) 20170330
Sophos AV 20170512
SUPERAntiSpyware 20170512
Symantec 20170511
Symantec Mobile Insight 20170512
Tencent 20170512
TheHacker 20170508
TotalDefense 20170512
TrendMicro 20170512
VBA32 20170512
VIPRE 20170512
ViRobot 20170512
Webroot 20170512
WhiteArmor 20170512
Yandex 20170510
Zillya 20170511
ZoneAlarm by Check Point 20170512
Zoner 20170512
The file being studied is a Portable Executable file! More specifically, it is a Win32 EXE file for the Windows GUI subsystem.
Packers identified
F-PROT Unicode, appended, UTF-8, ZIP
PEiD WinZip 32-bit SFX v8.x module
PE header basic information
Target machine Intel 386 or later processors and compatible processors
Compilation timestamp 2001-01-09 14:08:41
Entry Point 0x000039D8
Number of sections 5
PE sections
PE imports
RegQueryValueA
GetDeviceCaps
CreateDCA
DeleteDC
CreateFontIndirectA
DeleteObject
GetTextExtentPoint32A
SetTextAlign
ExtTextOutA
SelectObject
SetBkColor
GetBkColor
SetTextColor
DosDateTimeToFileTime
lstrlenA
lstrcmpiA
GlobalFree
FreeLibrary
ExitProcess
SetFileTime
GlobalUnlock
LoadLibraryA
GlobalAlloc
RtlUnwind
GetModuleFileNameA
WinExec
GetVolumeInformationA
_lwrite
GetCurrentDirectoryA
LocalAlloc
lstrcatA
CreateDirectoryA
GetWindowsDirectoryA
SetErrorMode
_llseek
GetCommandLineA
GetProcAddress
_lread
_lcreat
_lclose
GetModuleHandleA
FindFirstFileA
lstrcpyA
_lopen
GetACP
GlobalLock
GetDriveTypeA
LocalFree
GetEnvironmentVariableA
GlobalHandle
LocalFileTimeToFileTime
FindClose
GetVersion
SetCurrentDirectoryA
ShellExecuteA
FindExecutableA
GetParent
UpdateWindow
EndDialog
BeginPaint
KillTimer
DefWindowProcA
ShowWindow
SetWindowPos
SetWindowWord
GetSystemMetrics
OemToCharBuffA
GetWindowRect
DispatchMessageA
EnableWindow
SetDlgItemTextA
PostMessageA
GetDlgItemTextA
MessageBoxA
PeekMessageA
TranslateMessage
GetSysColor
SetActiveWindow
GetKeyState
SetWindowTextA
SendDlgItemMessageA
GetLastActivePopup
SendMessageA
GetClientRect
GetDlgItem
RegisterClassA
SetRect
InvalidateRect
wsprintfA
SetTimer
LoadCursorA
CharNextA
GetWindowWord
EndPaint
SetForegroundWindow
SetCursor
DialogBoxIndirectParamA
DestroyWindow
Number of PE resources by type
RT_ICON 2
RT_GROUP_ICON 1
Number of PE resources by language
ENGLISH US 3
PE resources
ExifTool file metadata
MIMEType
application/octet-stream

Subsystem
Windows GUI

MachineType
Intel 386 or later, and compatibles

TimeStamp
2001:01:09 15:08:41+01:00

FileType
Win32 EXE

PEType
PE32

CodeSize
18944

LinkerVersion
5.1

FileTypeExtension
exe

InitializedDataSize
10752

SubsystemVersion
4.0

EntryPoint
0x39d8

OSVersion
4.0

ImageVersion
0.0

UninitializedDataSize
0

File identification
MD5 df6d3947de051e97850a90498875efc3
SHA1 5b304fd05af0849932cafaebbe78539ed76eef4e
SHA256 d47c4112b596db6ca7409729f80894dec6b0af6da1c6699ee21aeff38ece9d04
ssdeep
6291456:CuGafJi5P9vGlI/M9tgeKyQ8LK6U8NT8/gn5RO81NtNj3yAQd3cmVfUGgSfcYFb7:CuGjFOI/OtgeBQn58lzTRfj3Ed3cmVfN

authentihash 8f47ac0a1e3ae2c268b24f0f1fb21318dd9771144568083b5675d0e336a8f4cc
imphash 78c751010579c51cdad3f096a3cbcc97
File size 345.9 MB ( 362685440 bytes )
File type Win32 EXE
Magic literal
PE32 executable for MS Windows (GUI) Intel 80386 32-bit

TrID Win32 Executable MS Visual C++ (generic) (31.5%)
Win64 Executable (generic) (27.9%)
Winzip Win32 self-extracting archive (generic) (23.2%)
Win32 Dynamic Link Library (generic) (6.6%)
Win32 Executable (generic) (4.5%)
Tags
winzip peexe software-collection

VirusTotal metadata
First submission 2016-06-22 02:05:15 UTC ( 1 year, 12 months ago )
Last submission 2018-05-18 19:30:02 UTC ( 1 month ago )
File names D47C4112B596DB6CA7409729F80894DEC6B0AF6DA1C6699EE21AEFF38ECE9D04
need-for-speed-underground-2-766-jetelecharge.exe
NFSU2_Demo.exe
NFSU2_Demo.exe
need_for_speed_underground_2_demo_jouable_1_anglais_13240.exe
NFSU2_Demo.exe
need-for-speed-underground.exe
need-for-speed-underground-2-766-jetelecharge.exe
Advanced heuristic and reputation engines
Symantec reputation Suspicious.Insight
No comments. No VirusTotal Community member has commented on this item yet, be the first one to do so!

Leave your comment...

?
Post comment

You have not signed in. Only registered users can leave comments, sign in and have a voice!

No votes. No one has voted on this item yet, be the first one to do so!