VTI SCORE: 98/100
Dynamic Analysis Report |
Classification: - |
ef1613f88744acec36908126b21bcba9ba775f8af25a1e86988e36985dd6f6fb (SHA256)
order ref ftp.exe
Windows Exe (x86-32)
Created at 2018-10-16 10:55:00
This is a filtered view
This list contains only the embedded files and created files
Filters: |
There are no files for this filter
Filename | Category | Type | Severity | Actions |
---|
C:\Users\CIiHmnxMn6Ps\AppData\Local\Temp\tmp3B59.tmp | Created File | Text |
Whitelisted
|
...
|
»
File Reputation Information
»
Severity |
Whitelisted
|
First Seen | 2011-06-14 11:24 (UTC+2) |
Last Seen | 2018-10-16 09:28 (UTC+2) |
C:\Users\CIiHmnxMn6Ps\Desktop\order ref ftp.exe | Sample File | Binary |
Unknown
|
...
|
»
PE Information
»
Image Base | 0x400000 |
Entry Point | 0x48b20e |
Size Of Code | 0x89400 |
Size Of Initialized Data | 0xe00 |
File Type | executable |
Subsystem | windows_gui |
Machine Type | i386 |
Compile Timestamp | 2018-07-19 08:24:15+00:00 |
Version Information (11)
»
Assembly Version | 8.0.7.19 |
LegalCopyright | - |
InternalName | Reborn Stub.exe |
FileVersion | 8.0.7.19 |
CompanyName | - |
LegalTrademarks | - |
Comments | - |
ProductName | - |
ProductVersion | 8.0.7.19 |
FileDescription | - |
OriginalFilename | Reborn Stub.exe |
Sections (3)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x402000 | 0x89214 | 0x89400 | 0x200 | cnt_code, mem_execute, mem_read | 6.84 |
.rsrc | 0x48c000 | 0xb08 | 0xc00 | 0x89600 | cnt_initialized_data, mem_read | 6.63 |
.reloc | 0x48e000 | 0xc | 0x200 | 0x8a200 | cnt_initialized_data, mem_discardable, mem_read | 0.1 |
Imports (1)
»
mscoree.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
_CorExeMain | 0x0 | 0x402000 | 0x8b1dc | 0x893dc | 0x0 |
c:\users\ciihmnxmn6ps\appdata\local\microsoft\windows\inetcache\counters.dat | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\CIiHmnxMn6Ps\AppData\Local\Temp\tmp53A0.tmp | Created File | Text |
Unknown
|
...
|
»
C:\Users\CIiHmnxMn6Ps\AppData\Local\Temp\877de498-eb87-4352-dee0-40eac252a007 | Created File | Text |
Unknown
|
...
|
»