1, You can UPLOAD any files, but there is 20Mb limit per file.
2, VirSCAN supports Rar/Zip decompression, but it must be less than 20 files.
3, VirSCAN can scan compressed files with password 'infected' or 'virus'.
Virscan.org multi-engine scan report |
Behavior analysis report: Habo file analysis |
Basic Information | |
---|---|
file name: | w-kg12.exe |
file type: | EXEx86 |
Submission time: | 2018-10-10 15:30:24 |
Threat level: | malicious |
MD5: | 1a3ef7b96688871fb793472b41d432bf |
sha256: | 4846602248a56ba8b4295d2cac614b4861defd98ae8f4528e79265d375a4a128 |
Document Threat Intelligence IOC Report | |
---|---|
No intelligence IOC detected |
Intelligence decision system | |
---|---|
Undetected intelligence determination system |
Network behavior report | |
---|---|
domains: | 0 |
dns: | 0 |
http: | 0 |
Document release report | |
---|---|
File release report not detected |
File process number report | |
---|---|
Process details: | 0 |
Document behavior signature report |
---|
Static information | |
---|---|
PE section table information | |
Section name: | .text |
Virtual address: | 0x00001000 |
Physical address: | 0x00000200 |
Physical size: | 0x00000000 |
Section permissions: | RWE |
Section name: | .data |
Virtual address: | 0x00005000 |
Physical address: | 0x00000200 |
Physical size: | 0x00001800 |
Section permissions: | RWE |
Section name: | .rsrc |
Virtual address: | 0x00007000 |
Physical address: | 0x00001a00 |
Physical size: | 0x00000200 |
Section permissions: | RW- |
PE basic information | |
import_hash: | 837c25c2579db69dabe8e2336d5b8f65 |
time_stamp: | 2010-08-29 18:38:42 |
entry_point_section: | .data |
entry_point_section: | .data |
image_base: | 0x400000 |
entry_point: | 0x64b0 |
PE resource information | |
name: | RT_DIALOG |
language: | LANG_ENGLISH |
filetype: | empty |
sublanguage: | SUBLANG_ENGLISH_US |
offset: | 0x00004060 |
size: | 0x000002ae |