1.0
低危

0bf9293f80ef3cb66dc3512e3c4e3b6e53d551b3494203996a6ff0829e97043b

0bf9293f80ef3cb66dc3512e3c4e3b6e53d551b3494203996a6ff0829e97043b.exe

分析耗时

143s

最近分析

383天前

文件大小

12.3MB
静态报毒 动态报毒 CVE FAMILY METATYPE PLATFORM TYPE UNKNOWN WIN32 TROJAN WORM ZUSY
鹰眼引擎
DACN 0.12
FACILE 1.00
IMCLNet 0.71
MFGraph 0.00
静态判定
反病毒引擎
查杀引擎 查杀结果 查杀时间 查杀版本
Alibaba None 20190527 0.3.0.5
Avast Win32:SillyP2P-X [Wrm] 20200707 18.4.3895.0
Baidu Win32.Worm.Agent.bf 20190318 1.0.0.2
CrowdStrike win/malicious_confidence_100% (D) 20190702 1.0
Kingsoft None 20200707 2013.8.14.323
McAfee W32/Xiquitir.ow!p2p 20200707 6.0.6.653
Tencent Trojan.Win32.Small.p 20200707 1.0.0.1
静态指标
可执行文件包含未知的 PE 段名称,可能指示打包器(可能是误报) (4 个事件)
section .text\x00U
section .data\x00U
section .rsrc\x00s
section .hoAiXT
行为判定
动态指标
网络通信
与未执行 DNS 查询的主机进行通信 (1 个事件)
host 114.114.114.114
文件已被 VirusTotal 上 60 个反病毒引擎识别为恶意 (50 out of 60 个事件)
ALYac Gen:Variant.Zusy.299571
APEX Malicious
AVG Win32:SillyP2P-X [Wrm]
Acronis suspicious
Ad-Aware Gen:Variant.Zusy.299571
AhnLab-V3 Worm/Win32.SillyP2P.R3740
Antiy-AVL Worm[P2P]/Win32.Small.p
Arcabit Trojan.Zusy.D49233
Avast Win32:SillyP2P-X [Wrm]
Avira TR/Drop.Emuni.C
Baidu Win32.Worm.Agent.bf
BitDefender Gen:Variant.Zusy.299571
Bkav W32.GenericSmallA.Worm
CAT-QuickHeal Worm.SmallPMF.S7658096
ClamAV Win.Worm.Sillyp2p-7194313-0
Comodo P2PWorm.Win32.Small.P@32rtt9
CrowdStrike win/malicious_confidence_100% (D)
Cybereason malicious.b769d0
Cylance Unsafe
Cynet Malicious (score: 100)
Cyren W32/S-bc50cc43!Eldorado
DrWeb Win32.HLLW.Xiquit
ESET-NOD32 Win32/Agent.NIQ
Emsisoft Gen:Variant.Zusy.299571 (B)
Endgame malicious (high confidence)
F-Prot W32/S-bc50cc43!Eldorado
F-Secure Trojan.TR/Drop.Emuni.C
FireEye Generic.mg.2d5738c57b9ab0cb
Fortinet W32/Agent.NIQ!worm
GData Win32.Worm.Agent.ASR
Ikarus P2P-Worm.Win32.Small
Invincea heuristic
Jiangmin Worm.Small.t
K7AntiVirus Trojan ( 0000da801 )
K7GW Trojan ( 0000da801 )
Kaspersky P2P-Worm.Win32.Small.p
MAX malware (ai score=88)
Malwarebytes Trojan.Agent
MaxSecure Worm.W32.Small.P
McAfee W32/Xiquitir.ow!p2p
MicroWorld-eScan Gen:Variant.Zusy.299571
Microsoft Worm:Win32/Agent
NANO-Antivirus Trojan.Win32.Small.femmss
Panda W32/Xiquitir.B.worm
Qihoo-360 Worm.Win32.Small.B
Rising Malware.Heuristic!ET#83% (RDMK:cmRtazoS11+qY/FesyMpnj6wlAfl)
SUPERAntiSpyware Trojan.Agent/Gen-MSFake[All]
Sangfor Malware
Sophos W32/VB-FFH
Symantec W32.SillyP2P
可视化分析
二进制图像
数据导入图像 288x288
数据导入图像 224x224
数据导入图像 192x192
数据导入图像 160x160
数据导入图像 128x128
数据导入图像 96x96
数据导入图像 64x64
数据导入图像 32x32
运行截图
暂无运行截图 该样本运行过程中未生成截图

👋 欢迎使用 ChatHawk

我是您的恶意软件分析助手,可以帮您分析和解读恶意软件报告。请随时向我提问!

🔍 主要威胁分析
⚡ 行为特征
🛡️ 防护建议
🔧 技术手段
🎯 检测方法
🤖

PE Compile Time

2004-05-07 07:02:15

PE Imphash

27f21db1a40f044cb2ea9aa7f88716f6

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text\x00U 0x00001000 0x00005b50 0x00006000 6.366605200857055
.rdata 0x00007000 0x000009ac 0x00001000 4.014497177343175
.data\x00U 0x00008000 0x00003478 0x00002000 3.553533343605762
.rsrc\x00s 0x0000c000 0x00000958 0x00001000 2.492413503122149
.hoAiXT 0x0000d000 0x00000f66 0x00001000 0.0

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x0000c408 0x00000128 LANG_SPANISH SUBLANG_SPANISH_MODERN None
RT_ICON 0x0000c408 0x00000128 LANG_SPANISH SUBLANG_SPANISH_MODERN None
RT_GROUP_ICON 0x0000c530 0x00000022 LANG_SPANISH SUBLANG_SPANISH_MODERN None
RT_VERSION 0x0000c558 0x000003fc LANG_SPANISH SUBLANG_SPANISH_MODERN None

Imports

Library KERNEL32.dll:
0x407010 FindClose
0x407014 FindNextFileA
0x407018 GetModuleHandleA
0x40701c GetStringTypeW
0x407020 GetStringTypeA
0x407024 GetModuleFileNameA
0x40702c FindFirstFileA
0x407030 Sleep
0x407034 HeapFree
0x407038 HeapAlloc
0x40703c GetStartupInfoA
0x407040 GetCommandLineA
0x407044 GetVersion
0x407048 ExitProcess
0x40704c HeapDestroy
0x407050 HeapCreate
0x407054 VirtualFree
0x407058 VirtualAlloc
0x40705c HeapReAlloc
0x407060 GetLastError
0x407064 CloseHandle
0x407068 WriteFile
0x40706c ReadFile
0x407070 TerminateProcess
0x407074 GetCurrentProcess
0x407084 WideCharToMultiByte
0x407090 SetHandleCount
0x407094 GetStdHandle
0x407098 GetFileType
0x40709c RtlUnwind
0x4070a0 SetStdHandle
0x4070a4 FlushFileBuffers
0x4070a8 CreateFileA
0x4070ac SetFilePointer
0x4070b0 GetCPInfo
0x4070b4 GetACP
0x4070b8 GetOEMCP
0x4070bc GetProcAddress
0x4070c0 LoadLibraryA
0x4070c4 SetEndOfFile
0x4070c8 MultiByteToWideChar
0x4070cc LCMapStringA
0x4070d0 LCMapStringW
0x4070d4 CreateDirectoryA
Library USER32.dll:
0x4070dc MessageBoxA
Library ADVAPI32.dll:
0x407000 RegSetValueExA
0x407004 RegCloseKey
0x407008 RegOpenKeyA

L!This program cannot be run in DOS mode.
/<kRkRkR
^iRYjR\gRXWR
AlRkS\RDiRTjRRichkR
`.rdata
@.data
@.hoAiXT
MU+U9U}wE
tAt2t$
YYUQSVW}
+;r>})E
UQSVW}
t6t7)E
YY^54@
Yu3Vt$
PUSVWu
_^H[]Ujhp@
j?UIZ;
r;]uy;
;uY;]s
pD#U#ue
j #M_|
]#\D\D
VW3;u0DP
_^[SUVW|$
_^][Vt$
3^SVt$
>+~&WPv
YSVW33395 @
_^[UQQSV5@
rt`+tE
rbtHHt.
u@u;@S9]u.E
SUV333;W~]
;|?4$j
_^][USVu
_^[UWVu
DDDDDDDDDDDDDD
It.ht lt
HHtpHHtl
YAE t!E@E
t;ERPWVEUe
~;E]xf
YY~2MQu
E_^[S?@
KVW~&|$
X_[^3^
YtF>"u
< v^S39
PY;5l@
8t9UW
YE?=t"Uq;Y
EYW6tY
8u]5(@
[UQQS39
EPEPSSWM
YEPEPE
@"t)t%
F8"uF@C
@C8"u,
VW333;u3
SS@SSPVSSD$4
;t2U>;YD$
t#SSUPt$$VSS
;t<8t
u+@UY;u
3_^][YY
DSUVWh
_^][DUSVWUj
t.;t$$t(4v
VC20XC00U
]_^[]UL$
PYY\WP\@Y<v)\P\;j
P5`WP8`h
P6VYP6j
DDDDDDDDDDDDDD
SVW33@@
<1u6=@
t78t2=@
^#+t-Ht!Ht
5t.;t*;t
VuEPuuu
90tr0B=@
@;vAA9
t7SWU
BBBu_[j
VPVPV5
@AA;rI3
VWuBht@
;tg5p@
tPhlt@
_^[3L$
GIt%t)
Gt/KuD$
GKu[^D$
[^_SVt$
S>Yu+Vj
_^[3VWj
3^95 @
YY@}>j
8YUjht@
SVWe39=
"WWSht@
M]9}tfSuu
tMWWSuu
Mu;tVSuuu
3;u>EPj
EPVht@
E;tc]<
euWSV[
e33M;t)uVu
PKY3UQ
;t8WY;YEt*j
|)|||W|;)|Y5|B$|=
|+|C|*|(|w
|P||+.|
`h````
ppxxxx
(null)
runtime error
TLOSS error
SING error
DOMAIN error
- unable to initialize heap
- not enough space for lowio initialization
- not enough space for stdio initialization
- pure virtual function call
- not enough space for _onexit/atexit table
- unable to open console device
- unexpected heap error
- unexpected multithread lock error
- not enough space for thread data
abnormal program termination
- not enough space for environment
- not enough space for arguments
- floating point not loaded
Microsoft Visual C++ Runtime Library
Runtime Error!
Program:
<program name unknown>
GetLastActivePopup
GetActiveWindow
MessageBoxA
user32.dll
GetWindowsDirectoryA
GetModuleFileNameA
GetModuleHandleA
FindClose
FindNextFileA
FindFirstFileA
KERNEL32.dll
MessageBoxA
USER32.dll
RegCloseKey
RegSetValueExA
RegOpenKeyA
ADVAPI32.dll
HeapFree
HeapAlloc
GetStartupInfoA
GetCommandLineA
GetVersion
ExitProcess
HeapDestroy
HeapCreate
VirtualFree
VirtualAlloc
HeapReAlloc
GetLastError
CloseHandle
WriteFile
ReadFile
TerminateProcess
GetCurrentProcess
UnhandledExceptionFilter
FreeEnvironmentStringsA
FreeEnvironmentStringsW
WideCharToMultiByte
GetEnvironmentStrings
GetEnvironmentStringsW
SetHandleCount
GetStdHandle
GetFileType
RtlUnwind
SetStdHandle
FlushFileBuffers
CreateFileA
SetFilePointer
GetCPInfo
GetACP
GetOEMCP
GetProcAddress
LoadLibraryA
SetEndOfFile
MultiByteToWideChar
LCMapStringA
LCMapStringW
GetStringTypeA
GetStringTypeW
CreateDirectoryA
Winamp 5.0 (full version).exe
Winamp 3 (full version).exe
Winamp 3.5 (full version).exe
Update Photoshop 7.0 to Photoshop 9.16 (Its Work!).exe
Update Photoshop 8.0 to Photoshop 9.5 (Its Work!).exe
WinAce 3.85 (with Serial).exe
Download Accelerator Plus (DAP) (full version with serial).exe
RealOne Player (Full version).exe
BsPlayer v3.exe
WinRar v6.11 (with crack).exe
WinRar 4 (with crack).exe
ContaWin 2000 (full version).exe
WinZip 9.exe
DivX 7.2 freeware.exe
3D Studio R8 (It's Work!!).exe
VirtualDub 2.1.4.exe
MSN messenger 6.3.exe
Hacha Profesional Edition.exe
Simpsons pack guiones (Temporada 2004).exe
Mazinkaiser pack fondos de escritorio.exe
Mazinkaiser comics pack.exe
Juegos JAVA para NOKIA.exe
Capitulos ineditos de DragonBall Z jamas emitidos.exe
Pack Tonos y Logos para Nokia.exe
Nero 7.5.1.0 (cracked!).exe
Pack Photoshop CS 8 plugins.exe
3D Movie Maker.exe
Silent Hill.exe
PSEmu.exe
RM2GBA.exe
WAV2MP3.exe
GBAEmu.exe
GameCube Emulator.exe
Pack 50 Juegos PS2.exe
Pack 25 Juegos GameCube.exe
Resident Evil for GameCube.exe
Visual Basic 6.exe
Visual C.exe
Visual Studio (full).exe
mugen (full).exe
Fuck my fat ass.avi.exe
German extreme violation.mpg.exe
Sexo con una menor.exe
Pedofilia pack 37 pics.exe
Follada brutal coo roto.exe
Lolita Pack 20 Pics.exe
Puta come mierda.exe
Solo para Maricas.exe
No lo Descargues.exe
Dont Download.exe
humor.exe
Dont Touch.exe
Hentai.exe
Matrix Wallpapers.exe
Terminator 3 Wallpapers.exe
Hentai Evangelion Poker.exe
Shinchan screen saver.scr
Hentai Shizuka clit.exe
a pelo.exe
Chenoa en cueros.exe
WinAmp skings and plugins.exe
FlashGet Max acceleration (Experimental).exe
VMIntel386.exe
C:\Gusanillo QueBonito@Compartir.es
Hola tio! soy el gusanillo
como va eso?
Error in zip file
El archivo tiene un formato desconocido o est daado
Zip message
El archivo zip no ha podido ser abierto
probablemente este daado
SOFTWARE\Microsoft\Windows\CurrentVersion\Run
256mb 32bit
VMIntel386
/Intelx386
/VMIntel386.exe
Pack sex very hot nude young girl porn erotic private pussy rape clitoris suck chicas fotos culos tetas coos mamadas corridas sister hermana amigas friends lesbianas mujeres desnudas putas guarras hentai.exe
EMULE.EXE
config/shareddir.dat
012345: :
SOFTWARE\Kazaa\LocalContent
012345:%s
DisableSharing
SOFTWARE\Kazaa\UserDetails
QueBonito@Compartir.es
012345: :
SOFTWARE\IMesh\Client\LocalContent
012345:%s
DisableSharing
SOFTWARE\IMesh\Client\UserDetails
QueBonito@Compartir.es
C:\WINDOWS\system32\adfc05134a82ec11405d28ec95e9fcbaa7c970b2400c3f72cd032a6888368922.exe
33333330
{{{{{{{3
{{{{{{{33
{{{{{{{330
{{{{{{{330
{{{{{{{330
3333333
33?030
33333333
wwwwwwwwwww
DDDDDD@
DDDDDDGpw
DDDDDDGpw
DDDDDDDDDDD
wwwwwwwwwww
DDDpp@
(null)
((((( H
VS_VERSION_INFO
StringFileInfo
0c0a04b0
Comments
Microsoft
CompanyName
Microsoft
FileDescription
Microsoft
FileVersion
1, 0, 0, 1
InternalName
Microsoft
LegalCopyright
Copyright
LegalTrademarks
Debido a que es un Gusano, no creo oportuno rellenar este cuadro. jejeje
OriginalFilename
Microsoft
PrivateBuild
Microsoft
ProductName
Microsoft
ProductVersion
1, 0, 0, 1
SpecialBuild
Microsoft
VarFileInfo
Translation

Process Tree


DNS

Name Response Post-Analysis Lookup
dns.msftncsi.com A 131.107.255.255 131.107.255.255
dns.msftncsi.com AAAA fd3e:4f5a:5b81::1 131.107.255.255

TCP

No TCP connections recorded.

UDP

Source Source Port Destination Destination Port
192.168.56.101 53179 224.0.0.252 5355
192.168.56.101 49642 224.0.0.252 5355
192.168.56.101 137 192.168.56.255 137
192.168.56.101 61714 114.114.114.114 53
192.168.56.101 56933 114.114.114.114 53
192.168.56.101 138 192.168.56.255 138

HTTP & HTTPS Requests

No HTTP requests performed.

ICMP traffic

No ICMP traffic performed.

IRC traffic

No IRC requests performed.

Suricata Alerts

No Suricata Alerts

Suricata TLS

No Suricata TLS

Snort Alerts

No Snort Alerts

Name e94a85dd0124578c_mazinkaiser pack fondos de escritorio.exe
Filepath C:\Windows\Intelx386\Mazinkaiser pack fondos de escritorio.exe
Size 12.7MB
Processes 628 (None)
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 04c9603398b405aff91f718692e824be
SHA1 3b0fe6f892f1f01474750e2a6d67501bd72c38e6
SHA256 e94a85dd0124578c1fcd89d8a2838057734235448f7a8de5a2f80dbe0fd3e7f8
CRC32 58183156
ssdeep None
Yara None matched
VirusTotal Search for analysis
Name ee7d900d3a7805ef_rm2gba.exe
Filepath C:\Windows\Intelx386\RM2GBA.exe
Size 412.0KB
Processes 628 (None)
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 12fdb5b5d80f13ea49bf6820e96d795c
SHA1 e2f8b1a03df08d255e15d2f7e5a4e227e8b098f2
SHA256 9ab785c27535bff3e81103d28953bf9cc2562957bc1c797e0b360040560f7020
CRC32 B4C2F61C
ssdeep None
Yara None matched
VirusTotal Search for analysis
Name e7694b6a8cce031d_3d studio r8 (it's work!!).exe
Filepath C:\Windows\Intelx386\3D Studio R8 (It's Work!!).exe
Size 21.0MB
Processes 628 (None)
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 88d244e4e3e3866b928219699913fd76
SHA1 dbb8f4fc00c497e59f78e32432969ef0707a5461
SHA256 e7694b6a8cce031dfe1c59e7eaca8599c9d6b369ac8b419a88f831447391fa9b
CRC32 09D15EB6
ssdeep None
Yara None matched
VirusTotal Search for analysis
Name abb9edee2ff8e26c_psemu.exe
Filepath C:\Windows\Intelx386\PSEmu.exe
Size 12.5MB
Processes 628 (None)
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 53eee98e4e399f8d1408621534839df4
SHA1 8c98e34b90b46d2000a5c1fc07017639a8ad362c
SHA256 abb9edee2ff8e26cdbd5ed08f38f85e37b2e8780e4806e969759691f15e218c2
CRC32 1A987EC8
ssdeep None
Yara None matched
VirusTotal Search for analysis
Name b039f9f062fb2c3a_rm2gba.exe
Filepath C:\Windows\Intelx386\RM2GBA.exe
Size 12.3MB
Processes 628 (None)
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 07cb8183e176b358c8c62090788b09e6
SHA1 db3b0a1aa54d71efadd1a973ec88f2ddc030a3b7
SHA256 b039f9f062fb2c3aa32488c3a2aafbadbc7fca8acdbf7efbe02cffc91413c092
CRC32 92A765FD
ssdeep None
Yara None matched
VirusTotal Search for analysis
Name bb7c09cf4a2b85dc_divx 7.2 freeware.exe
Filepath C:\Windows\Intelx386\DivX 7.2 freeware.exe
Size 13.2MB
Processes 628 (None)
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 cc3575ecdaf6880c1275956e1ef54399
SHA1 425fd1a6d30243528826e5b70874de0218154c94
SHA256 bb7c09cf4a2b85dc9d5f13047392d1ebc16706c36d1295e08fa1769bb91d4950
CRC32 650DD994
ssdeep None
Yara None matched
VirusTotal Search for analysis
Name ee2b9c526f5d825b_rm2gba.exe
Filepath C:\Windows\Intelx386\RM2GBA.exe
Size 10.7MB
Processes 628 (None)
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 64682483d833bd3e944b7ab60ab35912
SHA1 489260aa68f24eb74c1a90ca0dc52882ce30b862
SHA256 d65a4d287e0fba4f676e2ee1f49916a230780f1008fc9a65f67c8a67cf1da84d
CRC32 D0421F45
ssdeep None
Yara None matched
VirusTotal Search for analysis
Name 72aab9525231a69f_silent hill.exe
Filepath C:\Windows\Intelx386\Silent Hill.exe
Size 12.5MB
Processes 628 (None)
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 caac10e0864c98077a3030062296b287
SHA1 684ed014c8850921ac281ec04e98167e3c4dfc5e
SHA256 72aab9525231a69f6c1ccee2988b712cb01291ad169f3b8468f89d44451848ed
CRC32 AB170C66
ssdeep None
Yara None matched
VirusTotal Search for analysis
Name ef4d627e0ea96f7f_rm2gba.exe
Filepath C:\Windows\Intelx386\RM2GBA.exe
Size 12.1MB
Processes 628 (None)
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 da6c301c30975d0ab85613df30d5b23c
SHA1 d3bffa804e94525191bb1cc570cf333092a7f8e2
SHA256 b644355ffb18c2f2ad318fcbd7be7295953074a3abd01b6bb0caa5b9fcd2daea
CRC32 409D77D2
ssdeep None
Yara None matched
VirusTotal Search for analysis
Name 794fb2b64c75494a_msn messenger 6.3.exe
Filepath C:\Windows\Intelx386\MSN messenger 6.3.exe
Size 14.2MB
Processes 628 (None)
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 9ad98c9d52580f9acef1824a1f1f0dfd
SHA1 7209e872fc5ff12c53f71e395cfcf7a17ede7ed9
SHA256 794fb2b64c75494aa0098a96e308e65d152feeb8f59697d3f77b6b53014977a0
CRC32 364930E4
ssdeep None
Yara None matched
VirusTotal Search for analysis
Name dcaf5f607b476598_capitulos ineditos de dragonball z jamas emitidos.exe
Filepath C:\Windows\Intelx386\Capitulos ineditos de DragonBall Z jamas emitidos.exe
Size 17.2MB
Processes 628 (None)
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 822a56e9c65b8b2ccfc80db4109c96fa
SHA1 e5d14c76bb972c9eb2aa7ac61dd4879b4ad88867
SHA256 dcaf5f607b476598b1d3e2d07507408e3187bf3f60973cf6deee9f2e59fee519
CRC32 DEBB359F
ssdeep None
Yara None matched
VirusTotal Search for analysis
Name 6ff50d7e6b38f69d_pack photoshop cs 8 plugins.exe
Filepath C:\Windows\Intelx386\Pack Photoshop CS 8 plugins.exe
Size 15.9MB
Processes 628 (None)
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 726ca05ba0e3be80776dcf357bb3ec27
SHA1 50fac16ee0e7ceaeb846580749815efdacc94581
SHA256 6ff50d7e6b38f69d56bfaa07e89b534ebc5dab193a92ca04e77dc87fc9bc08ae
CRC32 E1C542E7
ssdeep None
Yara None matched
VirusTotal Search for analysis
Name e0bd79f00bc60ed4_realone player (full version).exe
Filepath C:\Windows\Intelx386\RealOne Player (Full version).exe
Size 13.5MB
Processes 628 (None)
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 e657a365c04aece07ba93689a31827b7
SHA1 0b6aa8b2a089c3825f334c05b127d44b47733a49
SHA256 e0bd79f00bc60ed41b28d1fc4812ebccbdc7529f4b03018e52bfaa15f7dd316a
CRC32 999986E8
ssdeep None
Yara None matched
VirusTotal Search for analysis
Name be95d2a40d1e3cd3_rm2gba.exe
Filepath C:\Windows\Intelx386\RM2GBA.exe
Size 7.7MB
Processes 628 (None)
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 b55b9296376b8af531d21562ab8c57c4
SHA1 171927341ae58c5529e4f7b162c9ab68f5359549
SHA256 997d8ddebebc04b22b5af8ff1d8a3523fb23ee42158c598f34958d75d0795064
CRC32 42C6A9ED
ssdeep None
Yara None matched
VirusTotal Search for analysis
Name ce9cb04671c5d0ab_rm2gba.exe
Filepath C:\Windows\Intelx386\RM2GBA.exe
Size 6.3MB
Processes 628 (None)
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 0d0ded7168005c792f7b4de2a126d84f
SHA1 4c1b17760309ec7b20095eb9c29af63787a93607
SHA256 11762f3ba9698de26cedf760384018ceb9f44e6e6430f15f84142bc5adab0374
CRC32 1D3C64EE
ssdeep None
Yara None matched
VirusTotal Search for analysis
Name 18ea7490287a36dd_mazinkaiser comics pack.exe
Filepath C:\Windows\Intelx386\Mazinkaiser comics pack.exe
Size 12.6MB
Processes 628 (None)
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 203a1b91a74b671c42ffba1f28c1bb14
SHA1 564839fe5f1f999cd355533473de74e52e0953e7
SHA256 18ea7490287a36dd68d01b4914e46e40d848140edf5fb46b3f31d96527aedbcb
CRC32 D4106C43
ssdeep None
Yara None matched
VirusTotal Search for analysis
Name d9bd60cb629bb89d_nero 7.5.1.0 (cracked!).exe
Filepath C:\Windows\Intelx386\Nero 7.5.1.0 (cracked!).exe
Size 18.5MB
Processes 628 (None)
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 af767ce468367037830fc9c295bb116d
SHA1 3b96a245ee6c2f91a78af4740dbdd3b149a56636
SHA256 d9bd60cb629bb89d51c1139523e71c6b40ba57eccde916a9af6156e49a5be20a
CRC32 89E45C22
ssdeep None
Yara None matched
VirusTotal Search for analysis
Name 2194e96cc8886fc1_download accelerator plus (dap) (full version with serial).exe
Filepath C:\Windows\Intelx386\Download Accelerator Plus (DAP) (full version with serial).exe
Size 13.5MB
Processes 628 (None)
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 bccd8813a34cedb7dbde434ef30e3f5d
SHA1 ae0e0d2e0c82d24e6ed5ad4f594460c991e4266d
SHA256 2194e96cc8886fc1343eb919f816765c09d442a299dff8217a717d60a1e6fddd
CRC32 190E38A2
ssdeep None
Yara None matched
VirusTotal Search for analysis
Name 57a511f7a2b7ecb9_winrar v6.11 (with crack).exe
Filepath C:\Windows\Intelx386\WinRar v6.11 (with crack).exe
Size 14.7MB
Processes 628 (None)
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 cc6a3bdb9d2b21e440f709d00fda4ad3
SHA1 f33ea2bc118a8af68d6ac3b4e3e0e063830cd4c0
SHA256 57a511f7a2b7ecb91ac1adadbf0d57ec0711e5c4e9b7cc40753227a4cd4b4552
CRC32 B66E05D9
ssdeep None
Yara None matched
VirusTotal Search for analysis
Name bd47941655275fc5_juegos java para nokia.exe
Filepath C:\Windows\Intelx386\Juegos JAVA para NOKIA.exe
Size 13.0MB
Processes 628 (None)
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 12ce5c2904b127334f338afb93acdf6b
SHA1 ce2ce6e8ece6f0f2e4f4dfe5f1d9b735a3bef4ad
SHA256 bd47941655275fc515f14f40b48c80d80140dec6e234f45d4976aae334932593
CRC32 780217B9
ssdeep None
Yara None matched
VirusTotal Search for analysis
Name 6c1742aef903cb77_update photoshop 8.0 to photoshop 9.5 (it磗 work!).exe
Filepath C:\Windows\Intelx386\Update Photoshop 8.0 to Photoshop 9.5 (It磗 Work!).exe
Size 14.1MB
Processes 628 (None)
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 4b869a2cddd1d5631044b6810564f6de
SHA1 bc2b15ed7968bc49dc0d3387f15794c532a061cc
SHA256 6c1742aef903cb774d18bc65d6059e94825bee5fc90d6479329c2bf5ebaa56d0
CRC32 349673D7
ssdeep None
Yara None matched
VirusTotal Search for analysis
Name af5da99901c29b84_wav2mp3.exe
Filepath C:\Windows\Intelx386\WAV2MP3.exe
Size 1.5MB
Processes 628 (None)
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 1ac4507452d89c5d9d0d428391155a53
SHA1 b2b2327bfb109ad7266d77a4479813f7f6c34c1a
SHA256 61fd658d8b6c20f892583e4e33ff407fc52c51b03cdf7ddea5f551e3dffce943
CRC32 269C92FB
ssdeep None
Yara None matched
VirusTotal Search for analysis
Name 084552ba9a155cb4_rm2gba.exe
Filepath C:\Windows\Intelx386\RM2GBA.exe
Size 3.3MB
Processes 628 (None)
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 d07f6b0f27b4603ad2e68d43def64096
SHA1 10ca6c7def32d23993185445b071e216ec6c0c35
SHA256 838f871346708a07cb7d59f56eb29e6aba4bd338886aed46b1b320fc500026a3
CRC32 2C2A6970
ssdeep None
Yara None matched
VirusTotal Search for analysis
Name 3ebb79fa6dcc1873_winamp 5.0 (full version).exe
Filepath C:\Windows\Intelx386\Winamp 5.0 (full version).exe
Size 15.6MB
Processes 628 (None)
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 e652920ab6807555bfd64ea054613138
SHA1 44a51258a105854d0d00372ab606f882381bb05d
SHA256 3ebb79fa6dcc1873e6b57214bc6ecb7822158bb55bc947e8ac88f734d5a6cb42
CRC32 3E4EAA03
ssdeep None
Yara None matched
VirusTotal Search for analysis
Name 2ca7b0c40b17707b_winzip 9.exe
Filepath C:\Windows\Intelx386\WinZip 9.exe
Size 14.2MB
Processes 628 (None)
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 0e4937daaa3126cb6c3a971f9d8147cc
SHA1 49c68c1d40c8ab7d15fd32884ffdb738c9eb3ed7
SHA256 2ca7b0c40b17707be411faa3ef0c68080a84c2205e3feee3cea4e71083677808
CRC32 50BD1E28
ssdeep None
Yara None matched
VirusTotal Search for analysis
Name 6fc6e8253c592eb9_rm2gba.exe
Filepath C:\Windows\Intelx386\RM2GBA.exe
Size 4.4MB
Processes 628 (None)
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 01e4f290a71d9d873380a7f68e2898b4
SHA1 d16564f080b9bd41a6e6d09728d43c29f661b090
SHA256 1053f03f59da0b4f38d925a1b76d55d935274f46d12c4477600d5bde4795dbd9
CRC32 3FC4FBC2
ssdeep None
Yara None matched
VirusTotal Search for analysis
Name 2a07416897d9ff78_winamp 3.5 (full version).exe
Filepath C:\Windows\Intelx386\Winamp 3.5 (full version).exe
Size 14.8MB
Processes 628 (None)
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 e1ab22256d0b85d8ef21626546c3f366
SHA1 76795849c6103e4ac94c28229a8487b8137e2062
SHA256 2a07416897d9ff78e6c8b9fcbf891de6aa993d069e646a16d4eaba96ef1a422a
CRC32 835F0076
ssdeep None
Yara None matched
VirusTotal Search for analysis
Name 4d50f7194ef73619_3d movie maker.exe
Filepath C:\Windows\Intelx386\3D Movie Maker.exe
Size 12.4MB
Processes 628 (None)
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 11ae538aa82fbac58ba8034170c60cda
SHA1 26851d9b5439b88d227d17cad00602c16c810fe2
SHA256 4d50f7194ef73619aee15c0e4a0b047f3eb8ae74e80f5a3ec72f162c0a6ee5ef
CRC32 56DED6B3
ssdeep None
Yara None matched
VirusTotal Search for analysis
Name 3aa286bc9f98546e_virtualdub 2.1.4.exe
Filepath C:\Windows\Intelx386\VirtualDub 2.1.4.exe
Size 14.6MB
Processes 628 (None)
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 d4e68fb2dfd8d2d79d699529c399826b
SHA1 c72a842bdfd14dd9d5eb4dc15a39dc4f8883ebcc
SHA256 3aa286bc9f98546e92082df423225ee7d9ec1d23610823514e9af658f0aea952
CRC32 3F89CAD7
ssdeep None
Yara None matched
VirusTotal Search for analysis
Name 3e2013945b8d811a_winrar 4 (with crack).exe
Filepath C:\Windows\Intelx386\WinRar 4 (with crack).exe
Size 14.5MB
Processes 628 (None)
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 a05a3280d61453bcc911dbfead33331a
SHA1 12a9d0f58ed47d6bd7435cde3e146595351ba026
SHA256 3e2013945b8d811a07505aa81bb904b6d9ba3469109e9bbc53168462fa485f15
CRC32 2803D112
ssdeep None
Yara None matched
VirusTotal Search for analysis
Name 78056ae4487dda5e_contawin 2000 (full version).exe
Filepath C:\Windows\Intelx386\ContaWin 2000 (full version).exe
Size 13.4MB
Processes 628 (None)
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 a93f3b164c3b0cfe3363d4846dbd2fcd
SHA1 def335dcd7c4a6cf47cae183188f63be7cf4373e
SHA256 78056ae4487dda5e160a6f6d8f112205487ad7c0bae4715034f9409fe3c20d9f
CRC32 D2B1E7EC
ssdeep None
Yara None matched
VirusTotal Search for analysis
Name c374f5288292c19d_bsplayer v3.exe
Filepath C:\Windows\Intelx386\BsPlayer v3.exe
Size 14.6MB
Processes 628 (None)
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 decd075fe8ad72abaded7f56068c15f6
SHA1 679bb4091dc3a25229ec7cceed0c72632f79c93d
SHA256 c374f5288292c19df333741b575de20a0cd4dc7c1b1cddffd7f4acf6292ff14f
CRC32 EC201D59
ssdeep None
Yara None matched
VirusTotal Search for analysis
Name 80727c5110159562_rm2gba.exe
Filepath C:\Windows\Intelx386\RM2GBA.exe
Size 1.3MB
Processes 628 (None)
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 6b090dbda390d593b4f749e6e84418f2
SHA1 2dc0d5ab337803238fd3b065405523c2cf507865
SHA256 9629ab01c3b93fe438f5d507e50cd5be54b039a0c9dc7e817d0dbea578ea114e
CRC32 74E7F430
ssdeep None
Yara None matched
VirusTotal Search for analysis
Name c92c339e49afaf25_simpsons pack guiones (temporada 2004).exe
Filepath C:\Windows\Intelx386\Simpsons pack guiones (Temporada 2004).exe
Size 12.8MB
Processes 628 (None)
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 1c12e7ea928d8e694e3a58ec87b94651
SHA1 d2d38bc6d50798ff3119a87e98abbbfd145509cf
SHA256 c92c339e49afaf25a48b0d74e84042c0d9180b86b4f4aecfed03122f410a964e
CRC32 83884487
ssdeep None
Yara None matched
VirusTotal Search for analysis
Name 9a4152b5d14c10ce_pack tonos y logos para nokia.exe
Filepath C:\Windows\Intelx386\Pack Tonos y Logos para Nokia.exe
Size 13.9MB
Processes 628 (None)
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 8b7a85fffe70f115770a207a578c3862
SHA1 fe0703abce051a0d23236d4801dfb59b97c2be0a
SHA256 9a4152b5d14c10cea708b9b74e190bc8d75ac480d95d140e64a073cbd1ce0f55
CRC32 DD3BBA2B
ssdeep None
Yara None matched
VirusTotal Search for analysis
Name 20f0f8d296e5a95d_hacha profesional edition.exe
Filepath C:\Windows\Intelx386\Hacha Profesional Edition.exe
Size 12.8MB
Processes 628 (None)
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 bcce734aee7e611c9778e11e2d64b6b4
SHA1 48b5f02a927f412dc727c5ca7e4b81b6e3894b0c
SHA256 20f0f8d296e5a95d785cebef2433c607f35b4b03b4a65d1bbf0a427054c2a1d4
CRC32 76DEB5A3
ssdeep None
Yara None matched
VirusTotal Search for analysis
Name d18933e3e831e741_update photoshop 7.0 to photoshop 9.16 (it磗 work!).exe
Filepath C:\Windows\Intelx386\Update Photoshop 7.0 to Photoshop 9.16 (It磗 Work!).exe
Size 13.9MB
Processes 628 (None)
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 3f837058eee10fbe69e0b6f28c748694
SHA1 ad44758b71cbc0050868a29303e1a01a209eea04
SHA256 d18933e3e831e741c2445c12de9ec70b812515c714182ede2c3cf538d2e59f3b
CRC32 421E4C91
ssdeep None
Yara None matched
VirusTotal Search for analysis
Name 4a73f2467ace5211_rm2gba.exe
Filepath C:\Windows\Intelx386\RM2GBA.exe
Size 5.4MB
Processes 628 (None)
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 317241b097b810220c931431f2b867db
SHA1 e81ce516b8869af3254235255280a5300b95595d
SHA256 092b67a9614fd73c1f616bf1a98fd015b4a08c41f9a05c9c0582ca760d6e3b88
CRC32 0F17D922
ssdeep None
Yara None matched
VirusTotal Search for analysis
Name d175c68686558bd9_rm2gba.exe
Filepath C:\Windows\Intelx386\RM2GBA.exe
Size 9.1MB
Processes 628 (None)
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 875abc98e66de2c86e369398af2fc311
SHA1 b03de6a1fc17efeeaae1355ca5bcf91298be305f
SHA256 45fe27b3e2c2fface698e07e7f8d75ea69023241ad920a4d44a3fe8be8b62695
CRC32 9323184B
ssdeep None
Yara None matched
VirusTotal Search for analysis
Name d4949a0802969738_winace 3.85 (with serial).exe
Filepath C:\Windows\Intelx386\WinAce 3.85 (with Serial).exe
Size 16.0MB
Processes 628 (None)
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 a3ae5c093bf1062cd28deef4a001f300
SHA1 583ccc15dc930c4b3927107154ca6efedad18448
SHA256 d4949a08029697382b6ddc3b9d2a70858bae2fb52ba0d03cda65e48a4a8d26c9
CRC32 7355BC22
ssdeep None
Yara None matched
VirusTotal Search for analysis
Name 6c9f7547a226c1d1_winamp 3 (full version).exe
Filepath C:\Windows\Intelx386\Winamp 3 (full version).exe
Size 14.4MB
Processes 628 (None)
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 b2d06509cf6b3b29c94b4af292473a3a
SHA1 d55d67ab353df27cf5c587793200d416e9c451cc
SHA256 6c9f7547a226c1d12ecd32873d67b16baf1f28574b9f42d2aacd17f3e93158aa
CRC32 7EA74C69
ssdeep None
Yara None matched
VirusTotal Search for analysis
Name 00475f501fa03a15_rm2gba.exe
Filepath C:\Windows\Intelx386\RM2GBA.exe
Size 2.4MB
Processes 628 (None)
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 35655329073b67731cebf78d06b46352
SHA1 d0847d060e84f556c745af5b52028a1d3974acf3
SHA256 6fd65b21cd1d530f47da6047d08de65732464b88efa34058783172bc394e78b3
CRC32 4B5C879B
ssdeep None
Yara None matched
VirusTotal Search for analysis
Sorry! No dropped buffers.