× Cookies are disabled! This site requires cookies to be enabled to work properly
SHA256: d47c4112b596db6ca7409729f80894dec6b0af6da1c6699ee21aeff38ece9d04
File name: need-for-speed-underground-2-766-jetelecharge.exe
Detection ratio: 2 / 66
Analysis date: 2018-09-26 18:05:13 UTC ( 6 months, 4 weeks ago ) View latest
Antivirus Result Update
Bkav W32.eHeur.Malware09 20180925
Jiangmin TrojanClicker.Agent.clt 20180926
Ad-Aware 20180926
AegisLab 20180926
AhnLab-V3 20180926
Alibaba 20180921
ALYac 20180926
Antiy-AVL 20180926
Arcabit 20180926
Avast 20180926
Avast-Mobile 20180926
AVG 20180926
Avira (no cloud) 20180926
AVware 20180925
Babable 20180918
Baidu 20180926
BitDefender 20180926
CAT-QuickHeal 20180926
ClamAV 20180926
CMC 20180926
Comodo 20180926
CrowdStrike Falcon (ML) 20180723
Cybereason 20180225
Cylance 20180926
Cyren 20180926
DrWeb 20180926
eGambit 20180926
Emsisoft 20180926
Endgame 20180730
ESET-NOD32 20180926
F-Prot 20180926
F-Secure 20180926
Fortinet 20180926
GData 20180926
Sophos ML 20180717
K7AntiVirus 20180926
K7GW 20180926
Kaspersky 20180926
Kingsoft 20180926
Malwarebytes 20180926
MAX 20180926
McAfee 20180926
McAfee-GW-Edition 20180926
Microsoft 20180926
eScan 20180926
NANO-Antivirus 20180926
Palo Alto Networks (Known Signatures) 20180926
Panda 20180926
Qihoo-360 20180926
Rising 20180926
SentinelOne (Static ML) 20180926
Sophos AV 20180926
SUPERAntiSpyware 20180907
Symantec 20180926
Symantec Mobile Insight 20180924
TACHYON 20180926
Tencent 20180926
TheHacker 20180924
TotalDefense 20180925
TrendMicro 20180926
TrendMicro-HouseCall 20180926
Trustlook 20180926
VBA32 20180926
VIPRE 20180926
ViRobot 20180926
Yandex 20180926
Zillya 20180926
ZoneAlarm by Check Point 20180925
Zoner 20180926
The file being studied is a Portable Executable file! More specifically, it is a Win32 EXE file for the Windows GUI subsystem.
FileVersionInfo properties
Packers identified
F-PROT Unicode, appended, UTF-8, ZIP
PEiD WinZip 32-bit SFX v8.x module
PE header basic information
Target machine Intel 386 or later processors and compatible processors
Compilation timestamp 2001-01-09 14:08:41
Entry Point 0x000039D8
Number of sections 5
PE sections
PE imports
RegQueryValueA
GetDeviceCaps
CreateDCA
DeleteDC
CreateFontIndirectA
DeleteObject
GetTextExtentPoint32A
SetTextAlign
ExtTextOutA
SelectObject
SetBkColor
GetBkColor
SetTextColor
DosDateTimeToFileTime
lstrlenA
lstrcmpiA
GlobalFree
FreeLibrary
ExitProcess
SetFileTime
GlobalUnlock
LoadLibraryA
GlobalAlloc
RtlUnwind
GetModuleFileNameA
WinExec
GetVolumeInformationA
_lwrite
GetCurrentDirectoryA
LocalAlloc
lstrcatA
CreateDirectoryA
GetWindowsDirectoryA
SetErrorMode
_llseek
GetCommandLineA
GetProcAddress
_lread
_lcreat
_lclose
GetModuleHandleA
FindFirstFileA
lstrcpyA
_lopen
GetACP
GlobalLock
GetDriveTypeA
LocalFree
GetEnvironmentVariableA
GlobalHandle
LocalFileTimeToFileTime
FindClose
GetVersion
SetCurrentDirectoryA
ShellExecuteA
FindExecutableA
GetParent
UpdateWindow
EndDialog
BeginPaint
KillTimer
DefWindowProcA
ShowWindow
SetWindowPos
SetWindowWord
GetSystemMetrics
OemToCharBuffA
GetWindowRect
DispatchMessageA
EnableWindow
SetDlgItemTextA
PostMessageA
GetDlgItemTextA
MessageBoxA
PeekMessageA
TranslateMessage
GetSysColor
SetActiveWindow
GetKeyState
SetWindowTextA
SendDlgItemMessageA
GetLastActivePopup
SendMessageA
GetClientRect
GetDlgItem
RegisterClassA
SetRect
InvalidateRect
wsprintfA
SetTimer
LoadCursorA
CharNextA
GetWindowWord
EndPaint
SetForegroundWindow
SetCursor
DialogBoxIndirectParamA
DestroyWindow
Number of PE resources by type
RT_ICON 2
RT_GROUP_ICON 1
Number of PE resources by language
ENGLISH US 3
PE resources
ExifTool file metadata
MIMEType
application/octet-stream

Subsystem
Windows GUI

MachineType
Intel 386 or later, and compatibles

FileTypeExtension
exe

TimeStamp
2001:01:09 14:08:41+00:00

FileType
Win32 EXE

PEType
PE32

CodeSize
18944

LinkerVersion
5.1

ImageFileCharacteristics
No relocs, Executable, No line numbers, No symbols, 32-bit

EntryPoint
0x39d8

InitializedDataSize
10752

SubsystemVersion
4.0

ImageVersion
0.0

OSVersion
4.0

UninitializedDataSize
0

File identification
MD5 df6d3947de051e97850a90498875efc3
SHA1 5b304fd05af0849932cafaebbe78539ed76eef4e
SHA256 d47c4112b596db6ca7409729f80894dec6b0af6da1c6699ee21aeff38ece9d04
ssdeep
6291456:CuGafJi5P9vGlI/M9tgeKyQ8LK6U8NT8/gn5RO81NtNj3yAQd3cmVfUGgSfcYFb7:CuGjFOI/OtgeBQn58lzTRfj3Ed3cmVfN

authentihash 8f47ac0a1e3ae2c268b24f0f1fb21318dd9771144568083b5675d0e336a8f4cc
imphash 78c751010579c51cdad3f096a3cbcc97
File size 345.9 MB ( 362685440 bytes )
File type Win32 EXE
Magic literal
PE32 executable for MS Windows (GUI) Intel 80386 32-bit

TrID Win32 Executable MS Visual C++ (generic) (31.5%)
Win64 Executable (generic) (27.9%)
Winzip Win32 self-extracting archive (generic) (23.2%)
Win32 Dynamic Link Library (generic) (6.6%)
Win32 Executable (generic) (4.5%)
Tags
winzip peexe software-collection

VirusTotal metadata
First submission 2016-06-22 02:05:15 UTC ( 2 years, 10 months ago )
Last submission 2018-09-26 18:05:13 UTC ( 6 months, 4 weeks ago )
File names D47C4112B596DB6CA7409729F80894DEC6B0AF6DA1C6699EE21AEFF38ECE9D04
need-for-speed-underground-2-766-jetelecharge.exe
need-for-speed-underground.exe
NFSU2_Demo.exe
need_for_speed_underground_2_demo_jouable_1_anglais_13240.exe
need-for-speed-underground-2-766-jetelecharge.exe
NFSU2_Demo.exe
NFSU2_Demo.exe
Need4Speed Undergr.2_demo.exe
need-for-speed-underground-2-766-jetelecharge.exe
Advanced heuristic and reputation engines
Symantec reputation Suspicious.Insight
No comments. No VirusTotal Community member has commented on this item yet, be the first one to do so!

Leave your comment...

?
Post comment

You have not signed in. Only registered users can leave comments, sign in and have a voice!

No votes. No one has voted on this item yet, be the first one to do so!