× Sütik letiltva! Az oldal helyes működéséhez engedélyezni kell a sütiket.
SHA256: 48b7f78537285acb771fc17e16b0a9a75fdc07453f9c5ed2b38e43be47498df9
Fájl neve: 970188
Észlelési arány: 0 / 57
Elemzés ideje: 2017-02-02 06:48:05 UTC ( 4 hónap, 3 hét ezelőtt ) Legfrissebb megtekintése
Vírusirtó Eredmény Utolsó frissítés
Ad-Aware 20170202
AegisLab 20170202
AhnLab-V3 20170201
Alibaba 20170122
ALYac 20170202
Antiy-AVL 20170202
Arcabit 20170202
Avast 20170202
AVG 20170202
Avira (no cloud) 20170201
AVware 20170202
Baidu 20170125
BitDefender 20170202
Bkav 20170123
CAT-QuickHeal 20170202
ClamAV 20170202
CMC 20170202
Comodo 20170202
CrowdStrike Falcon (ML) 20170130
Cyren 20170202
DrWeb 20170202
Emsisoft 20170202
ESET-NOD32 20170202
F-Prot 20170202
F-Secure 20170202
Fortinet 20170202
GData 20170202
Ikarus 20170201
Invincea 20170111
Jiangmin 20170201
K7AntiVirus 20170201
K7GW 20170202
Kaspersky 20170202
Kingsoft 20170202
Malwarebytes 20170202
McAfee 20170202
McAfee-GW-Edition 20170201
Microsoft 20170202
eScan 20170202
NANO-Antivirus 20170202
nProtect 20170202
Panda 20170201
Qihoo-360 20170202
Rising 20170202
Sophos 20170202
SUPERAntiSpyware 20170202
Symantec 20170201
Tencent 20170202
TheHacker 20170129
TotalDefense 20170202
TrendMicro 20170202
TrendMicro-HouseCall 20170202
Trustlook 20170202
VBA32 20170201
VIPRE 20170202
ViRobot 20170202
WhiteArmor 20170123
Yandex 20170201
Zillya 20170201
Zoner 20170202
The file being studied is a Portable Executable file! More specifically, it is a Win32 EXE file for the Windows GUI subsystem.
FileVersionInfo properties
Copyright
Copyright (C) 2017 M8 Software

Product Spartan Portable
Original name install_spartanpo.exe
Internal name install_spartanpo
File version 16.11
Description This installer database contains the logic and data required to install Spartan Portable.
PE header basic information
Target machine Intel 386 or later processors and compatible processors
Compilation timestamp 2014-02-09 22:23:58
Entry Point 0x00031517
Number of sections 5
PE sections
Overlays
MD5 1619c0979b9c7776e5b3975b48d1d1ec
File type data
Offset 428032
Size 7015075
Entropy 7.94
PE imports
DestroyPropertySheetPage
CreatePropertySheetPageW
PropertySheetW
GetDeviceCaps
DeleteDC
CreateFontIndirectW
SetBkMode
BitBlt
GetStockObject
GetObjectW
SelectObject
CreateCompatibleDC
DeleteObject
CreateCompatibleBitmap
GetStdHandle
GetDriveTypeW
GetConsoleOutputCP
WaitForSingleObject
HeapDestroy
IsValidLocale
GetFileAttributesW
lstrcmpW
GetExitCodeProcess
DeleteCriticalSection
GetCurrentProcess
GetConsoleMode
GetLocaleInfoA
LocalAlloc
FreeEnvironmentStringsW
GetLocaleInfoW
EnumResourceLanguagesW
GetTempPathA
WideCharToMultiByte
GetStringTypeA
GetSystemTimeAsFileTime
InterlockedExchange
WriteFile
SetStdHandle
HeapReAlloc
GetStringTypeW
FreeLibrary
LocalFree
FormatMessageW
ConnectNamedPipe
InitializeCriticalSection
LoadResource
GetLogicalDriveStringsW
FindClose
InterlockedDecrement
MoveFileW
SetFileAttributesW
GetEnvironmentVariableW
SetLastError
GetSystemTime
TlsGetValue
CopyFileW
GetUserDefaultLangID
OutputDebugStringW
RemoveDirectoryW
IsDebuggerPresent
HeapAlloc
GetModuleFileNameA
lstrcmpiW
EnumSystemLocalesA
GetUserDefaultLCID
UnhandledExceptionFilter
LoadLibraryExW
MultiByteToWideChar
GetLocalTime
FlushInstructionCache
GetModuleHandleA
CreateThread
GetSystemDirectoryW
GetExitCodeThread
SetUnhandledExceptionFilter
MulDiv
IsProcessorFeaturePresent
GlobalMemoryStatus
SearchPathW
WriteConsoleA
GetVersion
SetCurrentDirectoryW
GlobalAlloc
GetDiskFreeSpaceExW
SetEndOfFile
GetCurrentThreadId
LeaveCriticalSection
WriteConsoleW
CreateToolhelp32Snapshot
InitializeCriticalSectionAndSpinCount
HeapFree
EnterCriticalSection
SetHandleCount
TerminateThread
LoadLibraryW
GetVersionExW
SetEvent
QueryPerformanceCounter
GetTickCount
TlsAlloc
FlushFileBuffers
LoadLibraryA
RtlUnwind
GetStartupInfoA
UnlockFile
GetWindowsDirectoryW
GetFileSize
OpenProcess
DeleteFileA
GetStartupInfoW
CreateDirectoryW
DeleteFileW
GetProcAddress
GetProcessHeap
GetTempFileNameW
GetModuleFileNameW
FindNextFileW
ResetEvent
GetTempFileNameA
FindFirstFileW
TerminateProcess
DuplicateHandle
GlobalLock
GetTempPathW
CreateEventW
CreateFileW
GetFileType
TlsSetValue
CreateFileA
ExitProcess
InterlockedIncrement
GetLastError
LCMapStringW
GetShortPathNameW
CreateNamedPipeW
GlobalFree
GetConsoleCP
LCMapStringA
GetEnvironmentStringsW
GlobalUnlock
LockFile
lstrlenW
Process32NextW
VirtualFree
SizeofResource
GetCurrentProcessId
LockResource
GetCommandLineW
GetCPInfo
HeapSize
InterlockedCompareExchange
Process32FirstW
lstrcpynW
GetSystemDefaultLangID
RaiseException
TlsFree
SetFilePointer
ReadFile
CloseHandle
GetACP
GetModuleHandleW
FindResourceExW
CreateProcessA
IsValidCodePage
HeapCreate
FindResourceW
CreateProcessW
Sleep
VirtualAlloc
GetOEMCP
VarUI4FromStr
OleLoadPicture
SHGetFolderPathW
SHBrowseForFolderW
ShellExecuteW
SHGetPathFromIDListW
SHGetSpecialFolderLocation
ShellExecuteExW
SHGetMalloc
PathFileExistsW
MapWindowPoints
RedrawWindow
GetMonitorInfoW
GetForegroundWindow
GetParent
CloseClipboard
EmptyClipboard
GetScrollRange
EndDialog
DestroyWindow
EnumWindows
SetFocus
ModifyMenuW
KillTimer
DestroyMenu
PostQuitMessage
ShowWindow
MessageBeep
LoadMenuW
SetWindowPos
GetWindowThreadProcessId
GetSystemMetrics
EnableMenuItem
IsWindow
PeekMessageW
GetWindowRect
EnableWindow
DialogBoxParamW
DefWindowProcW
LoadIconW
SetPropW
TranslateMessage
GetWindow
PostMessageW
GetPropW
GetDC
CreateWindowExW
CreateDialogParamW
ReleaseDC
GetDlgCtrlID
SendMessageW
UnregisterClassA
SetClipboardData
IsWindowVisible
LoadStringW
GetClientRect
SetWindowLongW
GetDlgItem
RemovePropW
MessageBoxW
MonitorFromWindow
ScreenToClient
InvalidateRect
GetScrollPos
GetSubMenu
SetTimer
LoadImageW
TrackPopupMenu
GetActiveWindow
FindWindowW
SetWindowTextW
GetWindowTextW
GetDesktopWindow
GetSystemMenu
GetWindowTextLengthW
DispatchMessageW
MsgWaitForMultipleObjects
GetWindowLongW
SetForegroundWindow
CharNextW
CallWindowProcW
ExitWindowsEx
OpenClipboard
VerQueryValueW
GetFileVersionInfoW
GetFileVersionInfoSizeW
CreateStreamOnHGlobal
CoUninitialize
CoInitialize
CoTaskMemAlloc
StgCreateDocfileOnILockBytes
CoTaskMemRealloc
CoCreateInstance
CoTaskMemFree
CreateILockBytesOnHGlobal
Number of PE resources by type
RT_DIALOG 12
RT_ICON 12
RT_STRING 10
RTF_FILE 2
RT_MENU 2
IMAGE_FILE 2
RT_MANIFEST 1
RT_VERSION 1
RT_GROUP_ICON 1
Number of PE resources by language
ENGLISH UK 43
PE resources
ExifTool file metadata
SubsystemVersion
5.0

InitializedDataSize
143872

ImageVersion
0.0

ProductName
Spartan Portable

FileVersionNumber
16.11.0.0

UninitializedDataSize
0

LanguageCode
English (British)

FileFlagsMask
0x003f

CharacterSet
Unicode

LinkerVersion
9.0

FileTypeExtension
exe

OriginalFileName
install_spartanpo.exe

MIMEType
application/octet-stream

Subsystem
Windows GUI

FileVersion
16.11

TimeStamp
2014:02:09 23:23:58+01:00

FileType
Win32 EXE

PEType
PE32

InternalName
install_spartanpo

ProductVersion
16.11

FileDescription
This installer database contains the logic and data required to install Spartan Portable.

OSVersion
5.0

FileOS
Win32

LegalCopyright
Copyright (C) 2017 M8 Software

MachineType
Intel 386 or later, and compatibles

CompanyName
M8 Software

CodeSize
283136

FileSubtype
0

ProductVersionNumber
16.11.0.0

EntryPoint
0x31517

ObjectFileType
Dynamic link library

File identification
MD5 c4d18e4521d459ee8643da7018de4203
SHA1 43cdb7d4986e3508736b9fd74282e7138814c3ac
SHA256 48b7f78537285acb771fc17e16b0a9a75fdc07453f9c5ed2b38e43be47498df9
ssdeep
196608:z5lBpKGcGBG9y/8Nj01HZZG8VwZ6pbA0WkvL:LK5GBGiII15k8XpbhfL

authentihash 1b0a79fc4b51a49a4f5e73b74071975d24613161740e2d2de2bd1d4ec57001c8
imphash f20b97c85d8b89a0f90e2b43a55284fa
Fájl méret 7.1 MB ( 7443107 bytes )
Fájl típus Win32 EXE
Magic literal
PE32 executable for MS Windows (GUI) Intel 80386 32-bit

TrID Win32 Executable Microsoft Visual Basic 6 (52.6%)
Win32 Executable MS Visual C++ (generic) (20.0%)
Win64 Executable (generic) (17.7%)
Win32 Dynamic Link Library (generic) (4.2%)
Win32 Executable (generic) (2.8%)
Tags
peexe overlay

VirusTotal metadata
First submission 2017-02-02 06:48:05 UTC ( 4 hónap, 3 hét ezelőtt )
Last submission 2017-04-14 07:58:08 UTC ( 2 hónap, 1 hét ezelőtt )
Fájl nevek install_spartanpo.exe
970188
install_spartanpo.exe
install_spartanpo
Behaviour characterization
Zemana
dll-injection

Nincsenek hozzászólások. Még egy VirusTotal felhasználó sem írt bejegyzést ehhez, legyél te az első!

Hozzászólás írása...

?
Hozzászólás elküldése

Nem vagy bejelentkezve. Csak regisztrált felhasználók írhatnak hozzászólást, jelentkezz be és oszd meg a véleményed!

Nincsenek szavazatok. Még senki nem szavazott, legyél te az első!
Condensed report! The following is a condensed report of the behaviour of the file when executed in a controlled environment. The actions and events described were either performed by the file itself or by any other process launched by the executed file or subjected to code injection by the executed file.
Opened files
Read files
Written files
Deleted files
Created processes
Opened mutexes
Runtime DLLs
UDP communications