Code:
SHA256: 0ce59c20ebc2289e32b3f11d587f67a65c9038288b94e9d7d3988800422ee1cf
SHA1: 20154838ab1f3bd3f7a954d583a3917dd7a78023
MD5: 80da13b1bffaf29a4d05941d63510fb4
File size: 79.0 KB ( 80896 bytes )
File name: yzgqdgtj.exe
File type: Win32 EXE
Tags: peexe armadillo
Detection ratio: 23 / 43
Analysis date: 2012-09-21 16:23:37 UTC ( 27 Minuten ago )
0
1
More detailsAntivirus Result Update
Agnitum - 20120921
AhnLab-V3 - 20120921
AntiVir TR/Weelsof.ng 20120921
Antiy-AVL - 20120911
Avast Win32:Weelsof-CE [Trj] 20120921
AVG Generic29.BKOI 20120921
BitDefender Trojan.Generic.KDV.733788 20120921
ByteHero - 20120921
CAT-QuickHeal - 20120921
ClamAV - 20120921
Commtouch - 20120921
Comodo UnclassifiedMalware 20120921
DrWeb Trojan.Winlock.6576 20120921
Emsisoft - 20120919
eSafe - 20120920
ESET-NOD32 Win32/Weelsof.B 20120921
F-Prot - 20120920
F-Secure Trojan.Generic.KDV.733788 20120921
Fortinet W32/Weelsof.NJ!tr 20120921
GData Trojan.Generic.KDV.733788 20120921
Ikarus Trojan.Win32.Weelsof 20120921
Jiangmin - 20120921
K7AntiVirus - 20120921
Kaspersky Trojan.Win32.Weelsof.nj 20120921
Kingsoft Win32.Troj.Weelsof.nj.(kcloud) 20120918
McAfee Artemis!80DA13B1BFFA 20120921
McAfee-GW-Edition Artemis!80DA13B1BFFA 20120921
Microsoft Trojan:Win32/Weelsof.C 20120921
Norman W32/Troj_Generic.ECFOP 20120921
nProtect Trojan.Generic.KDV.733788 20120921
Panda - 20120921
PCTools - 20120921
Rising - 20120921
Sophos Mal/Generic-L 20120921
SUPERAntiSpyware - 20120911
Symantec Trojan.Ransomlock 20120921
TheHacker - 20120920
TotalDefense - 20120920
TrendMicro - 20120921
TrendMicro-HouseCall TROJ_GEN.F47V0918 20120921
VBA32 - 20120921
VIPRE Trojan.Win32.Generic!BT 20120921
ViRobot Trojan.Win32.A.Weelsof.80896.A 20120921
Comments
Votes
Additional informationssdeep
1536:PziG/T2WnC5XuqK2ADNLxAX3Tgc98pgmbBIfQlDdwhy:PzVn0vADNlAX38XFzah
TrID
Win32 Executable Generic (68.0%)
Generic Win/DOS Executable (15.9%)
DOS Executable Generic (15.9%)
Autodesk FLIC Image File (extensions: flc, fli, cel) (0.0%)
PEiD packer identifier
Armadillo v1.71
ExifTool
MIMEType.................: application/octet-stream
Subsystem................: Windows GUI
MachineType..............: Intel 386 or later, and compatibles
TimeStamp................: 2012:09:18 16:15:48-07:00
FileType.................: Win32 EXE
PEType...................: PE32
CodeSize.................: 9728
LinkerVersion............: 9.0
EntryPoint...............: 0x3380
InitializedDataSize......: 139776
SubsystemVersion.........: 5.0
ImageVersion.............: 0.0
OSVersion................: 5.0
UninitializedDataSize....: 0
Portable Executable structural information
Compilation timedatestamp.....: 2012-09-18 23:15:48
Target machine................: 0x14C (Intel 386 or later processors and compatible processors)
Entry point address...........: 0x00003380
PE Sections...................:
Name Virtual Address Virtual Size Raw Size Entropy MD5
.text 4096 9640 9728 6.04 1fc8837ee95ae8ed942bc85047adb43e
.rdata 16384 4054 4096 5.24 aeb8b42dd071f29e161d7cdbec6c2de0
.data 20480 118988 49664 7.97 f97b3a484cc212c120839a68fa77ea7d
.rsrc 143360 16112 16384 5.88 7d38cd7af9710118275626a6cbb582da
PE Imports....................:
[[SHLWAPI.dll]]
StrCmpNIW, PathRenameExtensionW, PathFindExtensionA, PathCommonPrefixW, PathIsUNCW, PathFindExtensionW, StrStrIA, PathCanonicalizeW, PathIsRelativeW, PathIsDirectoryW, PathRemoveBackslashW, StrToIntExW, PathIsRootW, PathAddBackslashA, PathIsURLW, PathFileExistsW, PathAddBackslashW, SHGetValueW, StrCmpIW, SHDeleteValueW, PathStripToRootW, PathCombineW, PathRemoveExtensionW, PathStripPathW, SHDeleteKeyW, PathAppendA, PathIsFileSpecW, PathRemoveFileSpecW, SHCreateStreamOnFileW, StrStrIW, PathAppendW, AssocQueryStringW, PathRemoveFileSpecA, StrToIntW, StrCmpW, StrCmpNW, PathFindFileNameW, PathFindFileNameA, StrStrW, PathRemoveBlanksW, PathFileExistsA
[[KERNEL32.dll]]
CloseHandle, GetLastError, InitializeCriticalSectionAndSpinCount, HeapFree, GetStdHandle, EnterCriticalSection, GetModuleFileNameW, WaitForSingleObject, GetVersionExW, FreeLibrary, QueryPerformanceCounter, IsDebuggerPresent, HeapAlloc, GetVersionExA, GetEnvironmentStringsW, FlushFileBuffers, LoadLibraryA, WaitForSingleObjectEx, GetModuleFileNameA, DeleteCriticalSection, GetCurrentProcess, GetCurrentProcessId, WideCharToMultiByte, TlsGetValue, MultiByteToWideChar, GetStartupInfoW, SetFilePointerEx, GetProcAddress, InterlockedCompareExchange, SetFilePointer, RaiseException, GetFileSizeEx, CreateThread, GetModuleHandleA, ReadFile, InterlockedExchange, SetUnhandledExceptionFilter, WriteFile, TryEnterCriticalSection, GetSystemTimeAsFileTime, GetACP, GetModuleHandleW, SetEvent, LocalFree, TerminateProcess, FreeLibraryAndExitThread, InitializeCriticalSection, CreateFileW, FindClose, InterlockedDecrement, Sleep, GetFileType, GetTickCount, TlsSetValue, CreateFileA, ExitProcess, GetCurrentThreadId, LeaveCriticalSection, GetFileSize, SetLastError, InterlockedIncrement
[[MSVCRT.dll]]
_except_handler3, __p__fmode, __wgetmainargs, _exit, __p__commode, __setusermatherr, __dllonexit, _onexit, exit, _XcptFilter, _initterm, _controlfp, _wcmdln, strlen, _adjust_fdiv, __set_app_type
[[USER32.dll]]
RedrawWindow, RegisterWindowMessageW, EqualRect, GetCapture, LockSetForegroundWindow, LoadBitmapA, BeginDeferWindowPos, ScrollWindowEx, SetMenuItemInfoA, DialogBoxParamW, SetActiveWindow, EndDeferWindowPos, GetClassInfoA, DestroyIcon, GetWindowModuleFileNameW, GetKeyboardLayoutList, SystemParametersInfoW, RegisterClassA, DeleteMenu, SetWindowsHookExA, IsDialogMessageW, IsRectEmpty, IsDialogMessageA
[[SETUPAPI.dll]]
SetupPromptForDiskA
PE Resources..................:
Resource type Number of resources
RT_ICON 6
RT_GROUP_ICON 1
Resource language Number of resources
ENGLISH US 7
First seen by VirusTotal
2012-09-18 19:49:37 UTC ( 2 Tage, 21 Stunden ago )
Last seen by VirusTotal
2012-09-21 16:23:37 UTC ( 27 Minuten ago )
File names (max. 25)
ms.exe
0.8970216381361994.exe
yzgqdgtj.exe
ithlafmp.exe
cslazggh_old.nxe
80da13b1bffaf29a4d05941d63510fb4
file-4533320_exe
rvghtpnk.exe
phdpsljt.exe
hykngrfn.exe
ciao, andreas
Lesezeichen