× ¡Las cookies están desactivadas! Esta página requiere que las cookies estén activadas para funcionar correctamente
SHA256: a60c2bc7478902a4e17c81c72304074d0150e2d3893cf659f9d7a7e7827573a2
Nombre: lollipop_04150636.exe
Detecciones: 20 / 47
Fecha de análisis: 2013-05-21 08:06:58 UTC ( hace 4 años, 2 meses )
Antivirus Resultado Actualización
AntiVir Adware/Lollipop.AO.27 20130521
Avast Win32:Adware-APX [Adw] 20130521
BitDefender Trojan.GenericKDV.994861 20130521
Comodo UnclassifiedMalware 20130521
Emsisoft Trojan.Win32.Agent.AMN (A) 20130521
ESET-NOD32 a variant of Win32/Kryptik.AZAW 20130520
F-Secure Trojan.GenericKDV.994861 20130521
Fortinet W32/Kryptik.AZAW 20130521
GData Trojan.GenericKDV.994861 20130521
Ikarus Trojan.Win32.Wintrim 20130521
McAfee Artemis!CD62415B18E8 20130521
McAfee-GW-Edition Artemis!CD62415B18E8 20130521
Microsoft TrojanDownloader:Win32/Wintrim.BL 20130521
eScan Trojan.GenericKDV.994861 20130521
Norman Skintrim.DVYD 20130521
nProtect Trojan.GenericKDV.994861 20130521
Panda Trj/OCJ.E 20130520
Symantec WS.Reputation.1 20130521
TrendMicro TROJ_GEN.R0UCDEA 20130521
TrendMicro-HouseCall TROJ_GEN.R0UCDEA 20130521
Yandex 20130520
AhnLab-V3 20130520
Antiy-AVL 20130520
AVG 20130521
ByteHero 20130517
CAT-QuickHeal 20130520
ClamAV 20130521
Commtouch 20130521
DrWeb 20130521
eSafe 20130520
F-Prot 20130521
Jiangmin 20130520
K7AntiVirus 20130520
K7GW 20130520
Kaspersky 20130521
Kingsoft 20130506
Malwarebytes 20130521
NANO-Antivirus 20130521
PCTools 20130521
Rising 20130521
Sophos AV 20130521
SUPERAntiSpyware 20130521
TheHacker 20130520
TotalDefense 20130520
VBA32 20130521
VIPRE 20130521
ViRobot 20130521
The file being studied is a Portable Executable file! More specifically, it is a Win32 EXE file for the Windows GUI subsystem.
PE header basic information
Target machine Intel 386 or later processors and compatible processors
Compilation timestamp 2013-02-06 09:32:43
Entry Point 0x00003F2A
Number of sections 3
PE sections
PE imports
RegOpenKeyExA
GetLastError
InitializeCriticalSectionAndSpinCount
HeapFree
GetStdHandle
EnterCriticalSection
LCMapStringW
SetHandleCount
GetExitCodeProcess
QueryPerformanceCounter
IsDebuggerPresent
HeapAlloc
TlsAlloc
GetEnvironmentStringsW
GetModuleFileNameA
RtlUnwind
LoadLibraryA
FreeEnvironmentStringsA
DeleteCriticalSection
GetCurrentProcess
GetEnvironmentStrings
GetLocaleInfoA
GetCurrentProcessId
GetCPInfo
UnhandledExceptionFilter
InterlockedDecrement
MultiByteToWideChar
HeapSize
FreeEnvironmentStringsW
GetCommandLineA
GetProcAddress
GetStringTypeA
RaiseException
WideCharToMultiByte
TlsFree
SetUnhandledExceptionFilter
WriteFile
GetStartupInfoA
GetSystemTimeAsFileTime
GetACP
HeapReAlloc
GetStringTypeW
GetModuleHandleW
GetOEMCP
TerminateProcess
LCMapStringA
IsValidCodePage
HeapCreate
VirtualFree
TlsGetValue
Sleep
GetFileType
GetTickCount
TlsSetValue
ExitProcess
GetCurrentThreadId
LeaveCriticalSection
VirtualAlloc
SetLastError
InterlockedIncrement
CharPrevA
CharNextExA
CreateMenu
GetMenu
CharLowerBuffW
DispatchMessageA
CharLowerBuffA
CharNextA
GetMenuState
CharLowerW
TranslateMessage
GetMessageA
CharNextW
RegisterClassA
Ord(108)
Ord(111)
ExifTool file metadata
MIMEType
application/octet-stream

Subsystem
Windows GUI

MachineType
Intel 386 or later, and compatibles

TimeStamp
2013:02:06 10:32:43+01:00

FileType
Win32 EXE

PEType
PE32

CodeSize
40448

LinkerVersion
9.0

FileAccessDate
2013:05:21 09:07:03+01:00

EntryPoint
0x3f2a

InitializedDataSize
2447360

SubsystemVersion
4.0

ImageVersion
0.0

OSVersion
4.0

FileCreateDate
2013:05:21 09:07:03+01:00

UninitializedDataSize
0

File identification
MD5 cd62415b18e8bd98b6cc252d5c6dbcff
SHA1 cafe8c60a74a25a28cf33685decdb6336fb147ac
SHA256 a60c2bc7478902a4e17c81c72304074d0150e2d3893cf659f9d7a7e7827573a2
ssdeep
49152:8q6yjChIzZIsTdj+E9MqOR3WfdBnc3oy2YWGoQFrdYJf6JwLPDriTnaUrIMzOicH:36yjChIzZTTdj+E9MqOR38dBnc3oy2YS

Tamaño del fichero 2.4 MB ( 2485248 bytes )
Tipo Win32 EXE
Magic literal
PE32 executable for MS Windows (GUI) Intel 80386 32-bit

TrID Win64 Executable (generic) (51.4%)
Win32 Executable MS Visual C++ (generic) (31.3%)
Win32 Dynamic Link Library (generic) (6.6%)
Win32 Executable (generic) (6.5%)
Generic Win/DOS Executable (2.0%)
Tags
peexe

VirusTotal metadata
First submission 2013-04-18 07:40:48 UTC ( hace 4 años, 3 meses )
Last submission 2013-05-21 08:06:58 UTC ( hace 4 años, 2 meses )
Nombres lollipop_04150636.exe
Advanced heuristic and reputation engines
Symantec reputation Suspicious.Insight
No hay comentarios. Ningún usuario ha comentado aún. ¡Sea el primero en hacerlo!

Deje su comentario...

?
Enviar comentario

No ha iniciado sesión. Solo los usuarios registrados pueden escribir comentarios.

No hay votos. Nadie ha votado aún. ¡Sea el primero!
Condensed report! The following is a condensed report of the behaviour of the file when executed in a controlled environment. The actions and events described were either performed by the file itself or by any other process launched by the executed file or subjected to code injection by the executed file.