0.9
低危

0bb3d16c1d39d680a1b81d8135a2ebb6c339992ce8dbede696b238974db82d26

0bb3d16c1d39d680a1b81d8135a2ebb6c339992ce8dbede696b238974db82d26.exe

分析耗时

279s

最近分析

382天前

文件大小

9.5MB
静态报毒 动态报毒 CVE FAMILY METATYPE PLATFORM TYPE UNKNOWN WIN32 TROJAN WORM ZUSY
鹰眼引擎
DACN 0.12
FACILE 1.00
IMCLNet 0.87
MFGraph 0.00
静态判定
反病毒引擎
查杀引擎 查杀结果 查杀时间 查杀版本
Alibaba Worm:Win32/Agent.e8219ceb 20190527 0.3.0.5
Avast Win32:SillyP2P-X [Wrm] 20240331 23.9.8494.0
Baidu None 20190318 1.0.0.2
CrowdStrike win/malicious_confidence_100% (D) 20231026 1.0
Kingsoft None 20230906 None
McAfee W32/Xiquitir.ow!p2p 20240331 6.0.6.653
Tencent P2P-Worm.Win32.Small.za 20240331 1.0.0.1
静态指标
行为判定
动态指标
网络通信
与未执行 DNS 查询的主机进行通信 (2 个事件)
host 114.114.114.114
host 8.8.8.8
文件已被 VirusTotal 上 60 个反病毒引擎识别为恶意 (50 out of 60 个事件)
ALYac Gen:Variant.Zusy.317653
APEX Malicious
AVG Win32:SillyP2P-X [Wrm]
AhnLab-V3 Worm/Win32.Small.R293883
Alibaba Worm:Win32/Agent.e8219ceb
Antiy-AVL Worm/Win32.Agent.a
Arcabit Trojan.Zusy.D4D8D5
Avast Win32:SillyP2P-X [Wrm]
Avira TR/Dropper.Gen
BitDefender Gen:Variant.Zusy.317653
Bkav W32.AIDetectMalware
CAT-QuickHeal Worm.Agent.AZ4
ClamAV Win.Worm.Sillyp2p-7194313-0
CrowdStrike win/malicious_confidence_100% (D)
Cybereason malicious.263098
Cylance unsafe
Cynet Malicious (score: 100)
DeepInstinct MALICIOUS
DrWeb Win32.HLLW.Xiquit
ESET-NOD32 Win32/Agent.OHT
Elastic malicious (high confidence)
Emsisoft Gen:Variant.Zusy.317653 (B)
F-Secure Trojan.TR/Dropper.Gen
FireEye Generic.mg.e8f6cff263098d83
Fortinet W32/Agent.NIQ!worm
GData Win32.Worm.SillyP2P.A
Google Detected
Gridinsoft Worm.Win32.Small.ka!s1
Ikarus Worm.Win32.Agent
Jiangmin Worm.Small.y
K7AntiVirus EmailWorm ( 004df05b1 )
K7GW EmailWorm ( 004df05b1 )
Kaspersky P2P-Worm.Win32.Small.p
Lionic Worm.Win32.Small.tqTJ
MAX malware (ai score=89)
Malwarebytes Generic.Malware.AI.DDS
MaxSecure Trojan.Malware.121218.susgen
McAfee W32/Xiquitir.ow!p2p
MicroWorld-eScan Gen:Variant.Zusy.317653
Microsoft Worm:Win32/Small.P
NANO-Antivirus Trojan.Win32.Small.fsvyjs
Rising Worm.Agent!1.9D8A (CLASSIC)
Sangfor Suspicious.Win32.Save.ins
SentinelOne Static AI - Malicious PE
Skyhigh W32/Xiquitir.ow!p2p
Sophos Troj/Agent-BCMZ
Symantec W32.SillyP2P
TACHYON Worm/W32.SillyP2P.Zen
Tencent P2P-Worm.Win32.Small.za
Trapmine suspicious.low.ml.score
可视化分析
二进制图像
数据导入图像 288x288
数据导入图像 224x224
数据导入图像 192x192
数据导入图像 160x160
数据导入图像 128x128
数据导入图像 96x96
数据导入图像 64x64
数据导入图像 32x32
运行截图
暂无运行截图 该样本运行过程中未生成截图

👋 欢迎使用 ChatHawk

我是您的恶意软件分析助手,可以帮您分析和解读恶意软件报告。请随时向我提问!

🔍 主要威胁分析
⚡ 行为特征
🛡️ 防护建议
🔧 技术手段
🎯 检测方法
🤖

PE Compile Time

2004-02-13 06:20:39

PE Imphash

27f21db1a40f044cb2ea9aa7f88716f6

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x00005b50 0x00006000 6.363900829399006
.rdata 0x00007000 0x000009ac 0x00001000 3.957297883799786
.data 0x00008000 0x00003438 0x00002000 3.526822010201419
.rsrc 0x0000c000 0x00000ab0 0x00001000 0.0

Imports

Library KERNEL32.dll:
0x407010 FindClose
0x407014 FindNextFileA
0x407018 GetModuleHandleA
0x40701c GetStringTypeW
0x407020 GetStringTypeA
0x407024 GetModuleFileNameA
0x40702c FindFirstFileA
0x407030 Sleep
0x407034 HeapFree
0x407038 HeapAlloc
0x40703c GetStartupInfoA
0x407040 GetCommandLineA
0x407044 GetVersion
0x407048 ExitProcess
0x40704c HeapDestroy
0x407050 HeapCreate
0x407054 VirtualFree
0x407058 VirtualAlloc
0x40705c HeapReAlloc
0x407060 GetLastError
0x407064 CloseHandle
0x407068 WriteFile
0x40706c ReadFile
0x407070 TerminateProcess
0x407074 GetCurrentProcess
0x407084 WideCharToMultiByte
0x407090 SetHandleCount
0x407094 GetStdHandle
0x407098 GetFileType
0x40709c RtlUnwind
0x4070a0 SetStdHandle
0x4070a4 FlushFileBuffers
0x4070a8 CreateFileA
0x4070ac SetFilePointer
0x4070b0 GetCPInfo
0x4070b4 GetACP
0x4070b8 GetOEMCP
0x4070bc GetProcAddress
0x4070c0 LoadLibraryA
0x4070c4 SetEndOfFile
0x4070c8 MultiByteToWideChar
0x4070cc LCMapStringA
0x4070d0 LCMapStringW
0x4070d4 CreateDirectoryA
Library USER32.dll:
0x4070dc MessageBoxA
Library ADVAPI32.dll:
0x407000 RegSetValueExA
0x407004 RegCloseKey
0x407008 RegOpenKeyA

L!This program cannot be run in DOS mode.
/<kRkRkR
^iRYjR\gRXWR
AlRkS\RDiRTjRRichkR
`.rdata
@.data
UQEPh@
MU+U9U}wE
tAt2t$
YYUQSVW}
+;r>})E
UQSVW}
t6t7)E
Yu3Vt$
PUSVWu
_^H[]Ujhp@
j?UIZ;
r;]uy;
;uY;]s
pD#U#ue
j #M_|
]#\D\D
VW3;u0DP
_^[SUVW|$
_^][Vt$
3^SVt$
>+~&WPv
YSVW33395@
_^[UQQSV5d@
rt`+tE
rbtHHt.
u@u;@S9]u.E
SUV333;W~]
;|?4$j
_^][USVu
_^[UWVu
DDDDDDDDDDDDDD
It.ht lt
HHtpHHtl
YAE t!E@E
t;ERPWVEUe
~;E]xf
YY~2MQu
E_^[S?@
KVW~&|$
X_[^3^
YtF>"u
< v^S39
PY;5,@
8t9UW
YE?=t"Uq;Y
EYW6tY
8u]5@
[UQQS39
EPEPSSWM
YEPEPE
@"t)t%
F8"uF@C
@C8"u,
VW333;u3
SS@SSPVSSD$4
;t2U>;YD$
t#SSUPt$$VSS
;t<8t
u+@UY;u
3_^][YY
DSUVWh
_^][DUSVWUj
t.;t$$t(4v
VC20XC00U
]_^[]UL$
PYY\WP\@Y<v)\P\;j
P5`WP8`h
P6VYP6j
DDDDDDDDDDDDDD
<1u6=d@
t78t2=d@
|^k=D@
^#+t-Ht!Ht
5t.;t*;t
VuEPuuu
90tr0B=@
@j@3Y@
@;vAA9
Wj@Y3@
t7SWU
BBBu_[j
VPVPV5
@AA;rI3
VWuBht@
;tg5p@
tPhlt@
_^[3L$
GIt%t)
Gt/KuD$
GKu[^D$
[^_SVt$
S>Yu+Vj
_^[3VWj
YY@}>j
8YUjht@
SVWe39=@
"WWSht@
M]9}tfSuu
tMWWSuu
Mu;tVSuuu
3;u>EPj
EPVht@
E;tc]<
euWSV[
e33M;t)uVu
PKY3UQ@
;t8WY;YEt*j
BDyu>{uE
yuQyugDyu
zyu5yu-Jyun
yunKw
yu/w{uIyuQyu
yuayuQyu)yuQyu15yu{uOEuFyuSyu
yuIyu.zu.
`h````
ppxxxx
(null)
runtime error
TLOSS error
SING error
DOMAIN error
- unable to initialize heap
- not enough space for lowio initialization
- not enough space for stdio initialization
- pure virtual function call
- not enough space for _onexit/atexit table
- unable to open console device
- unexpected heap error
- unexpected multithread lock error
- not enough space for thread data
abnormal program termination
- not enough space for environment
- not enough space for arguments
- floating point not loaded
Microsoft Visual C++ Runtime Library
Runtime Error!
Program:
<program name unknown>
GetLastActivePopup
GetActiveWindow
MessageBoxA
user32.dll
GetWindowsDirectoryA
GetModuleFileNameA
GetModuleHandleA
FindClose
FindNextFileA
FindFirstFileA
KERNEL32.dll
MessageBoxA
USER32.dll
RegCloseKey
RegSetValueExA
RegOpenKeyA
ADVAPI32.dll
HeapFree
HeapAlloc
GetStartupInfoA
GetCommandLineA
GetVersion
ExitProcess
HeapDestroy
HeapCreate
VirtualFree
VirtualAlloc
HeapReAlloc
GetLastError
CloseHandle
WriteFile
ReadFile
TerminateProcess
GetCurrentProcess
UnhandledExceptionFilter
FreeEnvironmentStringsA
FreeEnvironmentStringsW
WideCharToMultiByte
GetEnvironmentStrings
GetEnvironmentStringsW
SetHandleCount
GetStdHandle
GetFileType
RtlUnwind
SetStdHandle
FlushFileBuffers
CreateFileA
SetFilePointer
GetCPInfo
GetACP
GetOEMCP
GetProcAddress
LoadLibraryA
SetEndOfFile
MultiByteToWideChar
LCMapStringA
LCMapStringW
GetStringTypeA
GetStringTypeW
CreateDirectoryA
Winamp 5.0 (full version).exe
Winamp 3 (full version).exe
Winamp 3.5 (full version).exe
Update Photoshop 7.0 to Photoshop 9.16 (Its Work!).exe
Update Photoshop 8.0 to Photoshop 9.5 (Its Work!).exe
WinAce 3.85 (with Serial).exe
Download Accelerator Plus (DAP) (full version with serial).exe
RealOne Player (Full version).exe
BsPlayer v3.exe
WinRar v6.11 (with crack).exe
WinRar 4 (with crack).exe
ContaWin 2000 (full version).exe
WinZip 9.exe
DivX 7.2 freeware.exe
3D Studio R8 (It's Work!!).exe
VirtualDub 2.1.4.exe
MSN messenger 6.3.exe
Hacha Profesional Edition.exe
Simpsons pack guiones (Temporada 2004).exe
Mazinkaiser pack fondos de escritorio.exe
Mazinkaiser comics pack.exe
Juegos JAVA para NOKIA.exe
Capitulos ineditos de DragonBall Z jamas emitidos.exe
Pack Tonos y Logos para Nokia.exe
Nero 7.5.1.0 (cracked!).exe
3D Movie Maker.exe
Silent Hill.exe
PSEmu.exe
RM2GBA.exe
WAV2MP3.exe
GBAEmu.exe
GameCube Emulator.exe
Pack 50 Juegos PS2.exe
Pack 25 Juegos GameCube.exe
Resident Evil for GameCube.exe
Visual Basic 6.exe
Visual C.exe
Visual Studio (full).exe
mugen (full).exe
Fuck my fat ass.avi.exe
German extreme violation.mpg.exe
Sexo con una menor.exe
Pedofilia pack 37 pics.exe
Follada brutal coo roto.exe
Lolita Pack 20 Pics.exe
Puta come mierda.exe
Solo para Maricas.exe
No lo Descargues.exe
Dont Download.exe
humor.exe
Dont Touch.exe
Hentai.exe
Matrix Wallpapers.exe
Terminator 3 Wallpapers.exe
Hentai Evangelion Poker.exe
Shinchan screen saver.scr
Hentai Shizuka clit.exe
a pelo.exe
Chenoa en cueros.exe
WinAmp skings and plugins.exe
FlashGet Max acceleration (Experimental).exe
VMIntel386.exe
C:\Gusanillo QueBonito@Compartir.es
Hola tio! soy el gusanillo
como va eso?
Error in zip file
El archivo tiene un formato desconocido o est daado
Zip message
El archivo zip no ha podido ser abierto
probablemente este daado
SOFTWARE\Microsoft\Windows\CurrentVersion\Run
256mb 32bit
VMIntel386
/Intelx386
/VMIntel386.exe
Pack sex very hot nude young girl porn erotic private pussy rape clitoris suck chicas fotos culos tetas coos mamadas corridas sister hermana amigas friends lesbianas mujeres desnudas putas guarras hentai.exe
EMULE.EXE
config/shareddir.dat
012345: :
SOFTWARE\Kazaa\LocalContent
012345:%s
DisableSharing
SOFTWARE\Kazaa\UserDetails
QueBonito@Compartir.es
012345: :
SOFTWARE\IMesh\Client\LocalContent
012345:%s
DisableSharing
SOFTWARE\IMesh\Client\UserDetails
QueBonito@Compartir.es
C:\Users\win7user\63e514f5ba92ea08b9fc44a72af9c5c0b60c848d9224a7ec48b515281c8d89dc.exe
(null)
((((( H

Process Tree


TCP

No TCP connections recorded.

UDP

Source Source Port Destination Destination Port
192.168.56.101 53179 224.0.0.252 5355
192.168.56.101 49642 224.0.0.252 5355
192.168.56.101 137 192.168.56.255 137
192.168.56.101 61714 114.114.114.114 53
192.168.56.101 61714 8.8.8.8 53
192.168.56.101 56933 8.8.8.8 53
192.168.56.101 138 192.168.56.255 138
192.168.56.101 58485 114.114.114.114 53
192.168.56.101 58485 8.8.8.8 53
192.168.56.101 57665 114.114.114.114 53

HTTP & HTTPS Requests

No HTTP requests performed.

ICMP traffic

No ICMP traffic performed.

IRC traffic

No IRC requests performed.

Suricata Alerts

No Suricata Alerts

Suricata TLS

No Suricata TLS

Snort Alerts

No Snort Alerts

Name 623ebf766b51343e_update photoshop 7.0 to photoshop 9.16 (it磗 work!).exe
Filepath C:\Windows\Intelx386\Update Photoshop 7.0 to Photoshop 9.16 (It磗 Work!).exe
Size 11.2MB
Processes 920 (None)
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 967a77e07406c6aab39ede9876ac1ae1
SHA1 5633a6c5cc21f665c1e7ba808e5a2f092efdaba8
SHA256 623ebf766b51343e4bc6e2b5f7e7453476cb87c6bb6e22b8487bf4076e79b7e1
CRC32 2663D959
ssdeep None
Yara None matched
VirusTotal Search for analysis
Name ce9878cb7c4d9f0b_3d studio r8 (it's work!!).exe
Filepath C:\Windows\Intelx386\3D Studio R8 (It's Work!!).exe
Size 18.2MB
Processes 920 (None)
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 cf95899fbc9679e9c3200f3e33e2b9ac
SHA1 9a82d14de6b00feb76fef88d39487a57fa6cae88
SHA256 ce9878cb7c4d9f0b637a2873366fd3619517d648ede2f7fa2b3e1a5bc787561f
CRC32 9EFF4A49
ssdeep None
Yara None matched
VirusTotal Search for analysis
Name f70b0203f04128ca_update photoshop 8.0 to photoshop 9.5 (it磗 work!).exe
Filepath C:\Windows\Intelx386\Update Photoshop 8.0 to Photoshop 9.5 (It磗 Work!).exe
Size 11.3MB
Processes 920 (None)
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 0a5fc5e298eec75dd7f2e68c0ca1ccaf
SHA1 40372d90726f8e4bfee4c65f6b893d4843064afb
SHA256 f70b0203f04128ca1aafee5112312b5346c58f55397ea5e0d5d1cda532556a1c
CRC32 30F33B44
ssdeep None
Yara None matched
VirusTotal Search for analysis
Name 98a1df5858e5c8fe_winamp 5.0 (full version).exe
Filepath C:\Windows\Intelx386\Winamp 5.0 (full version).exe
Size 12.8MB
Processes 920 (None)
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 0c55fa1c1d0a280fb8f103d19f71bdd7
SHA1 39faec05e6b1b2cba44c72092e9301169f8814be
SHA256 98a1df5858e5c8fef906e90cd3183f9af93ff09cc737c076fd7b6cc7b1d26a2a
CRC32 4AFDB5FA
ssdeep None
Yara None matched
VirusTotal Search for analysis
Name b75078a06844406e_winace 3.85 (with serial).exe
Filepath C:\Windows\Intelx386\WinAce 3.85 (with Serial).exe
Size 13.2MB
Processes 920 (None)
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 2d0244f1e2a90e9f61f0023e5e1fad8d
SHA1 38ea5842ea2d1262f57476bb5fb0349c613bb1d0
SHA256 b75078a06844406e4cf85f9332de111a934afa6364f8d143793b0d73348e87b5
CRC32 5B00FEBC
ssdeep None
Yara None matched
VirusTotal Search for analysis
Name b24488b2b61bf461_virtualdub 2.1.4.exe
Filepath C:\Windows\Intelx386\VirtualDub 2.1.4.exe
Size 11.8MB
Processes 920 (None)
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 9cadfe18180ba97898bcc5722da692fc
SHA1 7257eae3af2117c3b659ab20fb52cb9f1d8494f7
SHA256 b24488b2b61bf461e1d1aac6fcdf77dd17737b91f48947bb4535aa24442b86c5
CRC32 4DBB681D
ssdeep None
Yara None matched
VirusTotal Search for analysis
Name 9b9cece326e82bd6_mugen (full).exe
Filepath C:\Windows\Intelx386\mugen (full).exe
Size 1.9MB
Processes 920 (None)
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 b6216dd15db82c3f999903b78afccb34
SHA1 fcd0c0b90211064af53e9491788bcc1e32ad86da
SHA256 d8b7dd9f8909b463930ccceac7e04175c493ece215e9fcf3d9a2abe6e65a877f
CRC32 B952903E
ssdeep None
Yara None matched
VirusTotal Search for analysis
Name 97d66a49bb01392d_winzip 9.exe
Filepath C:\Windows\Intelx386\WinZip 9.exe
Size 11.4MB
Processes 920 (None)
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 703b7272b35c6ee5defb2d7a467dc47f
SHA1 9e6015ba826a799bdc3c34f6d3c83b565ff1929c
SHA256 97d66a49bb01392db5d6313a33fa291fe9f16ad3b9fdd1448c6f66ac7a606baf
CRC32 E80D371F
ssdeep None
Yara None matched
VirusTotal Search for analysis
Name 1d808112ba813cd5_visual c.exe
Filepath C:\Windows\Intelx386\Visual C.exe
Size 9.6MB
Processes 920 (None)
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 a3dde649ba13828d24d27cdb0b1268f4
SHA1 43097e20c1effea7eb1aab7b0eb554acc8dbf641
SHA256 1d808112ba813cd535fe9e7a7d5d32e7f7e8e74b0611882d85c139dd07f4b708
CRC32 D700F5ED
ssdeep None
Yara None matched
VirusTotal Search for analysis
Name 6d41e31e668e2889_contawin 2000 (full version).exe
Filepath C:\Windows\Intelx386\ContaWin 2000 (full version).exe
Size 10.6MB
Processes 920 (None)
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 eb293347be9d6f37fb5643ad2c7c60b5
SHA1 56dbc25d924f5573d14a2e22978bef4f7b19fb1b
SHA256 6d41e31e668e2889c3a6f03f43e3e16abc2a7e3fb6bc91a3391b608ae3cac54d
CRC32 53C8B0A2
ssdeep None
Yara None matched
VirusTotal Search for analysis
Name cb6db115459eaec1_mugen (full).exe
Filepath C:\Windows\Intelx386\mugen (full).exe
Size 4.4MB
Processes 920 (None)
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 4a3b474702eb1e58fd8fda8a723f4d59
SHA1 feabfb46234ad4d033c177758d17422a102cc500
SHA256 7f3c82ee7480b468583704a6a33600eb832d45e3d7a1fc826ed2b23edc0a6c4b
CRC32 04690D39
ssdeep None
Yara None matched
VirusTotal Search for analysis
Name 36e164f286d3caf4_mugen (full).exe
Filepath C:\Windows\Intelx386\mugen (full).exe
Size 2.9MB
Processes 920 (None)
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 7fc4742ef27da3710e4be948b3c432b5
SHA1 6792fa130d455faf6707b7e71ab32eba13a6313f
SHA256 039d1b7fce79bd8403af732de2d588a70ded9159045d0a734c8de01e0381f069
CRC32 104423B9
ssdeep None
Yara None matched
VirusTotal Search for analysis
Name 2484a228f8a21b26_nero 7.5.1.0 (cracked!).exe
Filepath C:\Windows\Intelx386\Nero 7.5.1.0 (cracked!).exe
Size 15.7MB
Processes 920 (None)
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 971157d3fd142534f5f78caaa7841fab
SHA1 d3bb1b5c53cea0a69a48efc556945e00df4c5499
SHA256 2484a228f8a21b2602e5ab159a575f1c11b0754d1cdbf4b35cb160aa13c27d85
CRC32 6BE5B644
ssdeep None
Yara None matched
VirusTotal Search for analysis
Name 978f1a6b41586e9b_msn messenger 6.3.exe
Filepath C:\Windows\Intelx386\MSN messenger 6.3.exe
Size 11.4MB
Processes 920 (None)
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 f74544ac79e8f5768c54d4147a5b9fd7
SHA1 e32330909cc209c71baefb06d198664fdfadf06a
SHA256 978f1a6b41586e9b251672116a10a2d428b66317f2d2c99175558dcfc5ebb7b5
CRC32 2526747B
ssdeep None
Yara None matched
VirusTotal Search for analysis
Name 10d09ed17063641a_visual studio (full).exe
Filepath C:\Windows\Intelx386\Visual Studio (full).exe
Size 9.5MB
Processes 920 (None)
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 8b4ba997842327a2ccdc4ed4a05b0ce5
SHA1 debe354b02da5d724a4dcdaa2aabf28feb7938fd
SHA256 10d09ed17063641abc808d1f03e3f96792bed995264422ed65fadad0edae25d9
CRC32 A6005B0B
ssdeep None
Yara None matched
VirusTotal Search for analysis
Name a4ee3a43fdd87c2a_pack 25 juegos gamecube.exe
Filepath C:\Windows\Intelx386\Pack 25 Juegos GameCube.exe
Size 9.7MB
Processes 920 (None)
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 0685b1fbb2e82b65e0cb969abf1aaba1
SHA1 9c5ca2bdfa609c7ec4e69741e968bd864b5203ff
SHA256 a4ee3a43fdd87c2a0586dd90f6fa7b3da5af216a2df4800775d0d6d37e4588d3
CRC32 27CC2580
ssdeep None
Yara None matched
VirusTotal Search for analysis
Name 93faab97e7c74aed_hacha profesional edition.exe
Filepath C:\Windows\Intelx386\Hacha Profesional Edition.exe
Size 10.0MB
Processes 920 (None)
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 1bdcacd60e4eee99c6d2ad6be595de6c
SHA1 373e30335e6adc04650059e7800c59d76a0ac530
SHA256 93faab97e7c74aed5008e9cb12976d5561bf278c78db3ab72f56e887cce09e99
CRC32 E4DD8CB6
ssdeep None
Yara None matched
VirusTotal Search for analysis
Name fae480122d249b42_rm2gba.exe
Filepath C:\Windows\Intelx386\RM2GBA.exe
Size 9.5MB
Processes 920 (None)
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 091fcd532ca79634921a77239d26cf55
SHA1 616b89b55ccabd908cd2ae344dc368fc5bf8e6b5
SHA256 fae480122d249b42d775ba138360b3403728da8c8dc8e40711cdbfab21ae97af
CRC32 0F8A5647
ssdeep None
Yara None matched
VirusTotal Search for analysis
Name a5537ef57e21075f_mugen (full).exe
Filepath C:\Windows\Intelx386\mugen (full).exe
Size 3.5MB
Processes 920 (None)
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 ca9dbf0a5a9ea8cd0c36eaf6791b31ed
SHA1 5585eaee1e1a999f0b3e7d1ecb7644717e20002b
SHA256 3a4e0504b5cc33297e68edbc6243cb6ecc92c5352c0c18e88399e37d5b16b268
CRC32 D52271ED
ssdeep None
Yara None matched
VirusTotal Search for analysis
Name 4f3e5496846f530d_realone player (full version).exe
Filepath C:\Windows\Intelx386\RealOne Player (Full version).exe
Size 10.7MB
Processes 920 (None)
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 324de333ad94df8465548c064ef73718
SHA1 7ca84216e065341a6440d4a80eaaf40558ec3049
SHA256 4f3e5496846f530dc93ae3bb70b0921ae104d4192228ab130ce7a4cb3f96e82e
CRC32 6649475A
ssdeep None
Yara None matched
VirusTotal Search for analysis
Name d11721ea00720c8a_resident evil for gamecube.exe
Filepath C:\Windows\Intelx386\Resident Evil for GameCube.exe
Size 9.6MB
Processes 920 (None)
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 cf2f458057c57c143a038edac5afc0c5
SHA1 94c51083ad944ed8c4e008202e675df3ae601dcb
SHA256 d11721ea00720c8a502ab212ce5823e908c7428429d0cf369e6cbbb31b9b6d5d
CRC32 DA9DE7FF
ssdeep None
Yara None matched
VirusTotal Search for analysis
Name 5181e46046d6280d_simpsons pack guiones (temporada 2004).exe
Filepath C:\Windows\Intelx386\Simpsons pack guiones (Temporada 2004).exe
Size 10.0MB
Processes 920 (None)
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 98b532a191dc67b5018c4c8818ce739a
SHA1 e31a2f3244d961f00e69463a99e821933136e936
SHA256 5181e46046d6280dd567a41574e65ec46290fec0a94de5be86043555c90c31f2
CRC32 09259746
ssdeep None
Yara None matched
VirusTotal Search for analysis
Name 3443028301adb911_capitulos ineditos de dragonball z jamas emitidos.exe
Filepath C:\Windows\Intelx386\Capitulos ineditos de DragonBall Z jamas emitidos.exe
Size 14.4MB
Processes 920 (None)
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 a0befa2a02be9bbd9f4798c9a7429d72
SHA1 61fa9596ee661f211f14a3d1a00819e9ecd744ac
SHA256 3443028301adb91103b23d763d5dcda12e3988dd6950e6fdc10d179ef3f0b1e7
CRC32 955586F7
ssdeep None
Yara None matched
VirusTotal Search for analysis
Name 460ca8a79784a332_silent hill.exe
Filepath C:\Windows\Intelx386\Silent Hill.exe
Size 9.7MB
Processes 920 (None)
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 1acaf81c8a5fb7b979e76ffd02bf0e6a
SHA1 1f38fb9efd4ec438c9c845eabdfefab87679e316
SHA256 460ca8a79784a33284b350e918a187dab53c5c271bc5a2e6f496e561c4afb3b6
CRC32 7605B23E
ssdeep None
Yara None matched
VirusTotal Search for analysis
Name f75ec0f39a23c6ee_psemu.exe
Filepath C:\Windows\Intelx386\PSEmu.exe
Size 9.7MB
Processes 920 (None)
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 dd26a1b5ba56360606e956d039f228b6
SHA1 c880c7095099244a82f93b1550e0f7d209c88c54
SHA256 f75ec0f39a23c6ee9625374077880fefd59207a8bff8f25269b7929254fbabac
CRC32 9AA61F36
ssdeep None
Yara None matched
VirusTotal Search for analysis
Name 2685f4de50a90df3_winrar 4 (with crack).exe
Filepath C:\Windows\Intelx386\WinRar 4 (with crack).exe
Size 11.7MB
Processes 920 (None)
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 a9888e2037f5c05bcc0879775dcd735f
SHA1 ecb9bc6ac07d787ee7f4ac6c070da2280170e8c6
SHA256 2685f4de50a90df3f578e56dc0171e1a293ac8cf05dc0b6ce3cd03b3c32b06b2
CRC32 81843EFA
ssdeep None
Yara None matched
VirusTotal Search for analysis
Name e1f7adafb6c1cd76_juegos java para nokia.exe
Filepath C:\Windows\Intelx386\Juegos JAVA para NOKIA.exe
Size 10.2MB
Processes 920 (None)
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 4a6595f78c2ee57cb81e099f31384b03
SHA1 26d35caff61299901ad0463e4883bc32e2fc52ad
SHA256 e1f7adafb6c1cd76ed202130b663df9eb0cfadfb4de304911d56609d7cf55fa0
CRC32 2EA4D634
ssdeep None
Yara None matched
VirusTotal Search for analysis
Name 36b915676fb23939_winamp 3.5 (full version).exe
Filepath C:\Windows\Intelx386\Winamp 3.5 (full version).exe
Size 12.0MB
Processes 920 (None)
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 f0f38bb7ff5231e9cc4606d6ca0f45a8
SHA1 efdcae156853737ce77ee8bab98087d8c64dd2e6
SHA256 36b915676fb23939eba581e66ad98b8e985741bc93ba0baa79a169391aad9b98
CRC32 40FDFB1E
ssdeep None
Yara None matched
VirusTotal Search for analysis
Name 79f6ad454aac6723_download accelerator plus (dap) (full version with serial).exe
Filepath C:\Windows\Intelx386\Download Accelerator Plus (DAP) (full version with serial).exe
Size 10.7MB
Processes 920 (None)
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 c8e2545844906874379e480b660dbcf9
SHA1 d6ffcb4dd1ce60cc5f782dac88b3aa6dc4fe2868
SHA256 79f6ad454aac6723baef37b61687db5716b96da3b6a587bca1ade4491903f7ac
CRC32 DBC2F572
ssdeep None
Yara None matched
VirusTotal Search for analysis
Name c37fb35faf7987ec_mazinkaiser pack fondos de escritorio.exe
Filepath C:\Windows\Intelx386\Mazinkaiser pack fondos de escritorio.exe
Size 9.9MB
Processes 920 (None)
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 a821eb26add297b6e2d28b965991aec6
SHA1 9dcd558b3531a1c1e7fa4f5969413997c3a92b1a
SHA256 c37fb35faf7987ec369bad458de5817bed49283c4c5d6e0d268f497d7be036f6
CRC32 22E57091
ssdeep None
Yara None matched
VirusTotal Search for analysis
Name 96ce42aa02f64b90_winamp 3 (full version).exe
Filepath C:\Windows\Intelx386\Winamp 3 (full version).exe
Size 11.6MB
Processes 920 (None)
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 28dac7e745a974d2f6b22408a5fd6fd3
SHA1 f0552fbd409e215f14ee43934f095adc13637eb5
SHA256 96ce42aa02f64b90dce99350c844d9a67ce337d73dbb1f8f5736410f431bb852
CRC32 8C1D8D05
ssdeep None
Yara None matched
VirusTotal Search for analysis
Name ec675a9baecb0bd6_pack tonos y logos para nokia.exe
Filepath C:\Windows\Intelx386\Pack Tonos y Logos para Nokia.exe
Size 11.1MB
Processes 920 (None)
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 af637ae52d72d14b678fc52fea3f197e
SHA1 dd406a96230fdc9c2588e3ab39ab7f119c765081
SHA256 ec675a9baecb0bd66f185fd6075176f84d72967df3ac66c78316ce449567d5c3
CRC32 C1382FBC
ssdeep None
Yara None matched
VirusTotal Search for analysis
Name 78a70d34d1aa0cff_mugen (full).exe
Filepath C:\Windows\Intelx386\mugen (full).exe
Size 544.0KB
Processes 920 (None)
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 0d4f7aa856fa0c325d414cef9711d30d
SHA1 6475e54db69e92f8d7f51d33e8eca40fdaaba441
SHA256 29b51f2c7e8041709e7db6869963b3cb8d7659a84951eb77ea8417dacde5ff69
CRC32 2D867ECD
ssdeep None
Yara None matched
VirusTotal Search for analysis
Name ea10ce9354ffaa29_gbaemu.exe
Filepath C:\Windows\Intelx386\GBAEmu.exe
Size 9.6MB
Processes 920 (None)
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 47281416207b1e63150af135975afe16
SHA1 f2b30343ea6d49e976b04bf9f420a54ce6b84303
SHA256 ea10ce9354ffaa29ec50caa5b26f28524be23043c393812c658db99518856b97
CRC32 538A3AC4
ssdeep None
Yara None matched
VirusTotal Search for analysis
Name 2cd83eb88c04ef42_mazinkaiser comics pack.exe
Filepath C:\Windows\Intelx386\Mazinkaiser comics pack.exe
Size 9.8MB
Processes 920 (None)
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 789878410a3efce90be73b2a541b8f82
SHA1 252d26b86db02dedde9fbc17b95d8eb7cdf62c4a
SHA256 2cd83eb88c04ef4289b8cdf09c5859847152be8517ca1ef613d586cf172aebe2
CRC32 59591AF6
ssdeep None
Yara None matched
VirusTotal Search for analysis
Name 7e937c95f7f38f7f_pack 50 juegos ps2.exe
Filepath C:\Windows\Intelx386\Pack 50 Juegos PS2.exe
Size 9.7MB
Processes 920 (None)
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 2ecd46868d089056da1f764fc9d444be
SHA1 56143cac022dd9291f12bbaca09eaca86eab5752
SHA256 7e937c95f7f38f7fbb7141009f5096437ff9a2e2cd54f9c3d3f952c9730dc39a
CRC32 7679CE18
ssdeep None
Yara None matched
VirusTotal Search for analysis
Name 1ef06fd49d5ebbc6_visual basic 6.exe
Filepath C:\Windows\Intelx386\Visual Basic 6.exe
Size 9.5MB
Processes 920 (None)
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 8f2f27c629b447c25baccac168c70d59
SHA1 5df381bc4f21fd052adaf27eec8e8e99c09885ec
SHA256 1ef06fd49d5ebbc66cc39f6911a09419e09f8d7f0d5abe46219406257064916d
CRC32 9E4ACEF5
ssdeep None
Yara None matched
VirusTotal Search for analysis
Name 3c4c9f148e705db4_3d movie maker.exe
Filepath C:\Windows\Intelx386\3D Movie Maker.exe
Size 9.6MB
Processes 920 (None)
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 ca270c2e8edbeeb134f9046fa42339ab
SHA1 e46d2ad39c9007e8338a75d0bdb7e5cd8ee29a3b
SHA256 3c4c9f148e705db40161f078e9cc29f8b6c043f9a8fbe274480f3a2743841a4f
CRC32 CE853BE9
ssdeep None
Yara None matched
VirusTotal Search for analysis
Name f860f49fadcaaa89_winrar v6.11 (with crack).exe
Filepath C:\Windows\Intelx386\WinRar v6.11 (with crack).exe
Size 11.9MB
Processes 920 (None)
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 daaccff74b841be7ead6179a5a904d6a
SHA1 e1a451a5a4ff0f2a31b1ddc30e62fb0dfd06f35c
SHA256 f860f49fadcaaa899bd98990190598c4ba21d0829f0f01d502af5b6be80435aa
CRC32 BEDE75D1
ssdeep None
Yara None matched
VirusTotal Search for analysis
Name 8b102dd1a75eb4eb_mugen (full).exe
Filepath C:\Windows\Intelx386\mugen (full).exe
Size 1.2MB
Processes 920 (None)
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 66985b807e4587d23ad7bcbd8a60d625
SHA1 34649fe34d6325dd4042714cf876d2312515de37
SHA256 128b5372e4d1916e306105ce374f52b7498d20aac65d9da6cc1fa32ed0d28d22
CRC32 300C830F
ssdeep None
Yara None matched
VirusTotal Search for analysis
Name dbec6092ccc9b428_gamecube emulator.exe
Filepath C:\Windows\Intelx386\GameCube Emulator.exe
Size 9.6MB
Processes 920 (None)
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 3c7b5588eee78cf6a621549a2a4a9d99
SHA1 0c9521519e15d3c63510ced2be33212629d851e2
SHA256 dbec6092ccc9b428c2718d133032ceb2d94bac9b490c42160fc8116786b92d28
CRC32 88DAC983
ssdeep None
Yara None matched
VirusTotal Search for analysis
Name bc4583c7d9c37c4e_divx 7.2 freeware.exe
Filepath C:\Windows\Intelx386\DivX 7.2 freeware.exe
Size 10.5MB
Processes 920 (None)
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 44562473bc4512104d74ac5f4d1383ce
SHA1 71d1eb2cb4a4fe84707bab8b3ab352c4478aae45
SHA256 bc4583c7d9c37c4ec8a73491d9939f1a1704bd2d970cc4eca1f0358547b5f54e
CRC32 1E02C212
ssdeep None
Yara None matched
VirusTotal Search for analysis
Name 6458e78a736d631f_wav2mp3.exe
Filepath C:\Windows\Intelx386\WAV2MP3.exe
Size 9.5MB
Processes 920 (None)
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 2a56ed698103928fd898f178e41424b7
SHA1 eab6fe1c816d3425230fe69b68cf4107535f33fa
SHA256 6458e78a736d631f6786860839030c42e9c845426ac89da9ce4f01b85ff49547
CRC32 FD25259A
ssdeep None
Yara None matched
VirusTotal Search for analysis
Name debb72152fb77c8a_bsplayer v3.exe
Filepath C:\Windows\Intelx386\BsPlayer v3.exe
Size 11.8MB
Processes 920 (None)
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 a7d0a087c26a7f958733e5a480ddf235
SHA1 84f6c191aa38425ab41874816654065474a4c54b
SHA256 debb72152fb77c8a8516bf8375eb6396d4d9da2690ba4098ee13c4c933518246
CRC32 4A1EADBB
ssdeep None
Yara None matched
VirusTotal Search for analysis
Sorry! No dropped buffers.