× Cookies are disabled! This site requires cookies to be enabled to work properly
SHA256: e5465787ee6a5d9220db66816dca3c04302d2ac5f939338854bf7a64a826cdfb
File name: embu1r71.exe
Detection ratio: 0 / 43
Analysis date: 2011-09-27 01:43:03 UTC ( 5 years, 9 months ago )
Antivirus Result Update
AhnLab-V3 20110926
AntiVir 20110926
Antiy-AVL 20110926
Avast 20110926
Avast5 20110926
AVG 20110926
BitDefender 20110927
ByteHero 20110923
CAT-QuickHeal 20110926
ClamAV 20110926
Commtouch 20110927
Comodo 20110926
Emsisoft 20110927
eSafe 20110926
eTrust-Vet 20110926
F-Prot 20110927
F-Secure 20110927
Fortinet 20110927
GData 20110927
Ikarus 20110927
Jiangmin 20110926
K7AntiVirus 20110926
Kaspersky 20110927
McAfee 20110927
McAfee-GW-Edition 20110926
Microsoft 20110926
NOD32 20110927
Norman 20110926
nProtect 20110926
Panda 20110926
PCTools 20110927
Prevx 20110927
Rising 20110926
Sophos 20110927
SUPERAntiSpyware 20110927
Symantec 20110927
TheHacker 20110926
TrendMicro 20110926
TrendMicro-HouseCall 20110927
VBA32 20110926
VIPRE 20110927
ViRobot 20110926
VirusBuster 20110926
The file being studied is a Portable Executable file! More specifically, it is a Win32 EXE file for the Windows GUI subsystem.
PE header basic information
Number of sections 5
PE sections
PE imports
RegOpenKeyExW
LookupPrivilegeValueW
OpenProcessToken
RegQueryValueExW
RegCreateKeyExW
RegSetValueExW
RegCloseKey
SetFileSecurityW
SetFileSecurityA
AdjustTokenPrivileges
InitCommonControlsEx
1 more function(s) imported by ordinal)
GetOpenFileNameW
CommDlgExtendedError
GetSaveFileNameW
GetDeviceCaps
GetObjectW
CreateCompatibleBitmap
SelectObject
StretchBlt
CreateCompatibleDC
DeleteObject
DeleteDC
DeleteFileW
DeleteFileA
CreateDirectoryA
CreateDirectoryW
FindClose
FindNextFileA
FindFirstFileA
FindNextFileW
FindFirstFileW
GetTickCount
WideCharToMultiByte
GlobalAlloc
GetVersionExW
GetFullPathNameA
GetFullPathNameW
GetModuleFileNameW
FindResourceW
GetModuleHandleW
HeapAlloc
GetProcessHeap
HeapFree
HeapReAlloc
CompareStringA
ExitProcess
GetLocaleInfoW
GetNumberFormatW
DosDateTimeToFileTime
GetTimeFormatW
FileTimeToSystemTime
FileTimeToLocalFileTime
ExpandEnvironmentStringsW
WaitForSingleObject
Sleep
GetTempPathW
MoveFileExW
UnmapViewOfFile
GetCommandLineW
MapViewOfFile
CreateFileMappingW
OpenFileMappingW
SetEnvironmentVariableW
GetProcAddress
LocalFileTimeToFileTime
SystemTimeToFileTime
GetSystemTime
MultiByteToWideChar
CompareStringW
IsDBCSLeadByte
GetCPInfo
SetCurrentDirectoryW
GetCurrentDirectoryW
LoadLibraryW
FreeLibrary
SetFileAttributesW
SetFileAttributesA
GetFileAttributesW
GetFileAttributesA
WriteFile
GetStdHandle
SetLastError
ReadFile
CreateFileW
CreateFileA
GetFileType
SetEndOfFile
SetFilePointer
MoveFileW
SetFileTime
GetCurrentProcess
CloseHandle
GetLastError
GetDateFormatW
1 more function(s) imported by ordinal)
SHChangeNotify
ShellExecuteExW
SHFileOperationW
SHGetFileInfoW
SHGetSpecialFolderLocation
SHGetMalloc
SHBrowseForFolderW
SHGetPathFromIDListW
SHAutoComplete
wvsprintfW
ReleaseDC
GetDC
SendMessageW
SetDlgItemTextW
SetFocus
EndDialog
DestroyIcon
SendDlgItemMessageW
GetDlgItemTextW
GetClassNameW
DialogBoxParamW
IsWindowVisible
WaitForInputIdle
SetForegroundWindow
GetSysColor
PostMessageW
LoadBitmapW
LoadIconW
CharToOemA
OemToCharA
FindWindowExW
wvsprintfA
GetParent
MapWindowPoints
CreateWindowExW
UpdateWindow
SetWindowTextW
LoadCursorW
RegisterClassExW
SetWindowLongW
GetWindowLongW
DefWindowProcW
PeekMessageW
GetMessageW
TranslateMessage
DispatchMessageW
DestroyWindow
GetClientRect
IsWindow
CharToOemBuffW
MessageBoxW
ShowWindow
GetDlgItem
EnableWindow
OemToCharBuffA
CharUpperA
CharToOemBuffA
LoadStringW
SetWindowPos
GetWindowTextW
GetSystemMetrics
GetWindow
CharUpperW
GetWindowRect
CopyRect
CreateStreamOnHGlobal
OleInitialize
CoCreateInstance
OleUninitialize
CLSIDFromString
ExifTool file metadata
MIMEType
application/octet-stream

Subsystem
Windows GUI

MachineType
Intel 386 or later, and compatibles

TimeStamp
2010:12:17 17:14:10+01:00

FileType
Win32 EXE

PEType
PE32

CodeSize
71680

LinkerVersion
9.0

EntryPoint
0xb2ec

InitializedDataSize
25088

SubsystemVersion
5.0

ImageVersion
0.0

OSVersion
5.0

UninitializedDataSize
0

File identification
MD5 5d694b9b11f2c5b7fa59af8cf206c44f
SHA1 3f479fe2c07f01e5c78abd2236893104025f30c0
SHA256 e5465787ee6a5d9220db66816dca3c04302d2ac5f939338854bf7a64a826cdfb
ssdeep
6144:OSB1Ed0h/CB5OVhc9dkDxNBDkFk952Xe4klnHivN2z/YpJ7T3La4Xgpyzk901:O81Ed0hYcVhfDhH52X4BiwWjLapng

File size 333.3 KB ( 341268 bytes )
File type Win32 EXE
Magic literal

TrID Win64 Executable Generic (59.6%)
Win32 Executable MS Visual C++ (generic) (26.2%)
Win32 Executable Generic (5.9%)
Win32 Dynamic Link Library (generic) (5.2%)
Generic Win/DOS Executable (1.3%)
VirusTotal metadata
First submission 2011-09-27 01:43:03 UTC ( 5 years, 9 months ago )
Last submission 2011-09-27 01:43:03 UTC ( 5 years, 9 months ago )
File names embu1r71.exe
Advanced heuristic and reputation engines
Symantec reputation Suspicious.Insight
No comments. No VirusTotal Community member has commented on this item yet, be the first one to do so!

Leave your comment...

?
Post comment

You have not signed in. Only registered users can leave comments, sign in and have a voice!

No votes. No one has voted on this item yet, be the first one to do so!