× Cookies are disabled! This site requires cookies to be enabled to work properly
SHA256: ef8d0f0a612058de9cad738b5c9e3a074b2d40896327dce25c62a65190b39267
File name: afr.zip
Detection ratio: 0 / 56
Analysis date: 2016-03-31 17:20:11 UTC ( 3 years, 1 month ago ) View latest
Antivirus Result Update
Ad-Aware 20160331
AegisLab 20160331
AhnLab-V3 20160330
Alibaba 20160323
ALYac 20160331
Antiy-AVL 20160331
Arcabit 20160331
Avast 20160331
AVG 20160331
AVware 20160331
Baidu 20160331
Baidu-International 20160331
BitDefender 20160331
Bkav 20160331
CAT-QuickHeal 20160331
ClamAV 20160331
CMC 20160322
Comodo 20160331
Cyren 20160331
DrWeb 20160331
Emsisoft 20160331
ESET-NOD32 20160331
F-Prot 20160331
F-Secure 20160331
Fortinet 20160330
GData 20160331
Ikarus 20160331
Jiangmin 20160331
K7AntiVirus 20160331
K7GW 20160331
Kaspersky 20160331
Kingsoft 20160331
Malwarebytes 20160331
McAfee 20160331
McAfee-GW-Edition 20160331
Microsoft 20160331
eScan 20160331
NANO-Antivirus 20160331
nProtect 20160331
Panda 20160330
Qihoo-360 20160331
Rising 20160331
Sophos AV 20160331
SUPERAntiSpyware 20160331
Symantec 20160331
Tencent 20160331
TheHacker 20160330
TotalDefense 20160330
TrendMicro 20160331
TrendMicro-HouseCall 20160331
VBA32 20160331
VIPRE 20160331
ViRobot 20160331
Yandex 20160316
Zillya 20160331
Zoner 20160331
The file being studied is a compressed stream! More specifically, it is a ZIP file.
Interesting properties
The studied file contains at least one Portable Executable.
Contained files
Compression metadata
Contained files
4
Uncompressed size
1321770
Highest datetime
2013-01-11 12:22:08
Lowest datetime
2010-04-23 17:15:10
Contained files by extension
txt
2
diz
1
exe
1
Contained files by type
unknown
3
Portable Executable
1
ExifTool file metadata
MIMEType
application/zip

ZipRequiredVersion
20

ZipCRC
0xed45bec0

FileType
ZIP

ZipCompression
Deflated

ZipUncompressedSize
551

ZipCompressedSize
359

FileTypeExtension
zip

ZipFileName
File_Id.diz

ZipBitFlag
0

ZipModifyDate
2012:12:25 15:37:04

Execution parents
Compressed bundles
File identification
MD5 ef43f8e5df2778ebedbe1df210363eb4
SHA1 e18b09d696537b30abb59c5619ee9156320b3704
SHA256 ef8d0f0a612058de9cad738b5c9e3a074b2d40896327dce25c62a65190b39267
ssdeep
24576:FNbB4SITSnvI9V6LiySL3ah4VP9ADP9TRL3bimT46to/p:FNYSAcaaOVP9AL9JlGp

File size 1.2 MB ( 1271437 bytes )
File type ZIP
Magic literal
Zip archive data, at least v2.0 to extract

TrID ZIP compressed archive (80.0%)
PrintFox/Pagefox bitmap (var. P) (20.0%)
Tags
contains-pe zip

VirusTotal metadata
First submission 2013-01-13 10:42:54 UTC ( 6 years, 4 months ago )
Last submission 2018-11-21 06:19:32 UTC ( 6 months ago )
File names EF8D0F0A612058DE9CAD738B5C9E3A074B2D40896327DCE25C62A65190B39267
351433
myfile
bdf82021-2c20-4ece-b762-57f1bec97a6b
afr [1 271 437].zip
afr.zip
1381323842-afr.zip
afr.zip
afr 7.8.1.zip
afr.zip
afr.zip
Advanced heuristic and reputation engines
ClamAV
Possibly Unwanted Application. While not necessarily malicious, the scanned file presents certain characteristics which depending on the user policies and environment may or may not represent a threat. For full details see: https://www.clamav.net/documents/potentially-unwanted-applications-pua .

Symantec reputation Suspicious.Insight
No comments. No VirusTotal Community member has commented on this item yet, be the first one to do so!

Leave your comment...

?
Post comment

You have not signed in. Only registered users can leave comments, sign in and have a voice!

No votes. No one has voted on this item yet, be the first one to do so!