× Cookies are disabled! This site requires cookies to be enabled to work properly
SHA256: d835c69b82c1f586634e23d029de33ddfa6dabc64d73cad0df6106c197ebeb13
File name: HaloteaFreeSetup.exe
Detection ratio: 1 / 70
Analysis date: 2018-12-17 00:41:09 UTC ( 5 months ago )
Antivirus Result Update
Bkav HW32.Packed. 20181214
Ad-Aware 20181216
AegisLab 20181214
AhnLab-V3 20181216
Alibaba 20180921
ALYac 20181216
Antiy-AVL 20181216
Arcabit 20181216
Avast 20181216
Avast-Mobile 20181216
AVG 20181216
Avira (no cloud) 20181216
Babable 20180918
Baidu 20181207
BitDefender 20181216
CAT-QuickHeal 20181216
ClamAV 20181216
CMC 20181216
Comodo 20181216
CrowdStrike Falcon (ML) 20181022
Cybereason 20180225
Cylance 20181217
Cyren 20181216
DrWeb 20181216
eGambit 20181217
Emsisoft 20181216
Endgame 20181108
ESET-NOD32 20181216
F-Prot 20181216
F-Secure 20181216
Fortinet 20181216
GData 20181216
Ikarus 20181216
Sophos ML 20181128
Jiangmin 20181216
K7AntiVirus 20181216
K7GW 20181216
Kaspersky 20181216
Kingsoft 20181217
Malwarebytes 20181216
MAX 20181217
McAfee 20181216
McAfee-GW-Edition 20181216
Microsoft 20181216
eScan 20181216
NANO-Antivirus 20181216
Palo Alto Networks (Known Signatures) 20181217
Panda 20181216
Qihoo-360 20181217
Rising 20181216
SentinelOne (Static ML) 20181011
Sophos AV 20181216
SUPERAntiSpyware 20181212
Symantec 20181216
Symantec Mobile Insight 20181215
TACHYON 20181214
Tencent 20181217
TheHacker 20181216
TotalDefense 20181216
Trapmine 20181205
TrendMicro 20181216
TrendMicro-HouseCall 20181217
Trustlook 20181217
VBA32 20181214
VIPRE 20181216
ViRobot 20181216
Webroot 20181217
Yandex 20181214
Zillya 20181215
ZoneAlarm by Check Point 20181216
Zoner 20181216
The file being studied is a Portable Executable file! More specifically, it is a Win32 EXE file for the Windows GUI subsystem.
Packers identified
F-PROT NSIS, appended, UPX, Unicode
PE header basic information
Target machine Intel 386 or later processors and compatible processors
Compilation timestamp 2016-07-25 00:55:51
Entry Point 0x000033B6
Number of sections 5
PE sections
Overlays
MD5 c4bb43771487706b78d755b15c282274
File type data
Offset 74752
Size 35379947
Entropy 8.00
PE imports
RegCreateKeyExW
RegEnumValueW
RegCloseKey
OpenProcessToken
RegSetValueExW
RegDeleteValueW
RegOpenKeyExW
SetFileSecurityW
AdjustTokenPrivileges
LookupPrivilegeValueW
RegEnumKeyW
RegDeleteKeyW
RegQueryValueExW
ImageList_Create
Ord(17)
ImageList_Destroy
ImageList_AddMasked
GetDeviceCaps
CreateFontIndirectW
SelectObject
CreateBrushIndirect
SetBkMode
SetBkColor
DeleteObject
SetTextColor
SetFilePointer
GetLastError
CopyFileW
GetShortPathNameW
lstrlenA
GetModuleFileNameW
GlobalFree
WaitForSingleObject
GetExitCodeProcess
ExitProcess
GlobalUnlock
GetFileAttributesW
lstrcmpiW
GetCurrentProcess
CompareFileTime
GetWindowsDirectoryW
GetFileSize
SetFileTime
GetCommandLineW
WideCharToMultiByte
SetErrorMode
MultiByteToWideChar
lstrlenW
CreateDirectoryW
DeleteFileW
GlobalLock
ReadFile
lstrcpyA
GetPrivateProfileStringW
WritePrivateProfileStringW
GetTempFileNameW
lstrcpynW
RemoveDirectoryW
ExpandEnvironmentStringsW
lstrcpyW
GetFullPathNameW
lstrcmpiA
CreateThread
SetEnvironmentVariableW
MoveFileExW
GetModuleHandleA
GetSystemDirectoryW
GetDiskFreeSpaceW
FindNextFileW
GetTempPathW
CloseHandle
FindFirstFileW
lstrcmpW
GetModuleHandleW
lstrcatW
FreeLibrary
SearchPathW
SetCurrentDirectoryW
WriteFile
CreateFileW
GlobalAlloc
CreateProcessW
FindClose
Sleep
MoveFileW
SetFileAttributesW
GetTickCount
GetVersion
GetProcAddress
LoadLibraryExW
MulDiv
SHBrowseForFolderW
SHFileOperationW
ShellExecuteW
SHGetPathFromIDListW
SHGetSpecialFolderLocation
SHGetFileInfoW
EmptyClipboard
GetMessagePos
EndPaint
EndDialog
LoadBitmapW
SetClassLongW
DefWindowProcW
CharPrevW
PostQuitMessage
ShowWindow
SetWindowPos
SendMessageTimeoutW
GetSystemMetrics
SetWindowLongW
IsWindow
PeekMessageW
GetWindowRect
EnableWindow
SetWindowTextW
DialogBoxParamW
AppendMenuW
IsWindowEnabled
GetDlgItemTextW
MessageBoxIndirectW
GetSysColor
CheckDlgButton
DispatchMessageW
CreateWindowExW
CreateDialogParamW
ReleaseDC
BeginPaint
CreatePopupMenu
SendMessageW
SetClipboardData
GetWindowLongW
FindWindowExW
IsWindowVisible
DestroyWindow
GetClientRect
SetTimer
GetDlgItem
SetForegroundWindow
SystemParametersInfoW
LoadImageW
EnableMenuItem
ScreenToClient
InvalidateRect
wsprintfA
CharNextW
CallWindowProcW
TrackPopupMenu
RegisterClassW
FillRect
CharNextA
SetDlgItemTextW
LoadCursorW
GetSystemMenu
GetClassInfoW
GetDC
wsprintfW
CloseClipboard
DrawTextW
SetCursor
ExitWindowsEx
OpenClipboard
OleUninitialize
CoTaskMemFree
OleInitialize
CoCreateInstance
Number of PE resources by type
RT_DIALOG 12
RT_ICON 5
RT_BITMAP 1
RT_GROUP_ICON 1
RT_MANIFEST 1
Number of PE resources by language
ENGLISH US 20
PE resources
ExifTool file metadata
MIMEType
application/octet-stream

Subsystem
Windows GUI

SubsystemVersion
4.0

MachineType
Intel 386 or later, and compatibles

TimeStamp
2016:07:25 01:55:51+01:00

FileType
Win32 EXE

PEType
PE32

CodeSize
25088

LinkerVersion
6.0

FileTypeExtension
exe

InitializedDataSize
141824

ImageFileCharacteristics
No relocs, Executable, No line numbers, No symbols, 32-bit

EntryPoint
0x33b6

OSVersion
4.0

ImageVersion
6.0

UninitializedDataSize
2048

File identification
MD5 b97fe6ce2067a3472d02c0ca20d67935
SHA1 3ec4a27d2830cb12b53dd666ebaced804d89ee77
SHA256 d835c69b82c1f586634e23d029de33ddfa6dabc64d73cad0df6106c197ebeb13
ssdeep
786432:pWVUSRZDAcdBKRMM9WFdLXZmblXhaKTC5sT7BtokqyietGF:pA6cd8RMUWFRgpXwKX4

authentihash a689d214f8a256e65071982c60e2275904bc874e4dfd64fd2b8fc2fe977210c0
imphash 4ea4df5d94204fc550be1874e1b77ea7
File size 33.8 MB ( 35454699 bytes )
File type Win32 EXE
Magic literal
PE32 executable for MS Windows (GUI) Intel 80386 32-bit

TrID Win32 Executable MS Visual C++ (generic) (41.0%)
Win64 Executable (generic) (36.3%)
Win32 Dynamic Link Library (generic) (8.6%)
Win32 Executable (generic) (5.9%)
OS/2 Executable (generic) (2.6%)
Tags
nsis peexe upx overlay

VirusTotal metadata
First submission 2017-02-22 00:44:02 UTC ( 2 years, 2 months ago )
Last submission 2018-04-25 00:02:14 UTC ( 1 year ago )
File names d835c69b82c1f586634e23d029de33ddfa6dabc64d73cad0df6106c197ebeb13
HaloteaFreeSetup.exe
981133
No comments. No VirusTotal Community member has commented on this item yet, be the first one to do so!

Leave your comment...

?
Post comment

You have not signed in. Only registered users can leave comments, sign in and have a voice!

No votes. No one has voted on this item yet, be the first one to do so!