VirSCAN VirSCAN

1, You can UPLOAD any files, but there is 20Mb limit per file.
2, VirSCAN supports Rar/Zip decompression, but it must be less than 20 files.
3, Aplikace VirSCAN může skenovat komprimované soubory s heslem 'infected'nebo'virus'.
4, If your browser cannot upload files, please download VirSCAN uploader to upload.

Language
Server load
Server Load
VirSCAN
VirSCAN

1, You can UPLOAD any files, but there is 20Mb limit per file.
2, VirSCAN supports Rar/Zip decompression, but it must be less than 20 files.
3, Aplikace VirSCAN může skenovat komprimované soubory s heslem 'infected'nebo'virus'.

Basic Information

file name: 00大医凌然
file size: 272909
file type: application/x-dosexec
MD5: 901bf12364683446b5a3192891f403f6
sha1: 1b66474f4cbafcc14228dab0b9b8d393465123fa

 CreateProcess

ApplicationName:
CmdLine:
childid: 1900
childname: 1621089044247_901bf12364683446b5a3192891f403f6.exe
childpath: C:\Users\Administrator\AppData\Local\Temp\1621089044247_901bf12364683446b5a3192891f403f6.exe
drop_type:
name:
noNeedLine:
path:
pid: 2580

 Dropped Unsave

analysis_result: HEUR:Trojan.Win32.Generic
create: 0
how: write
md5: d98a971827153b789797b0a37fdde812
name: gwaqzc.exe
new_size: 266KB (272909bytes)
operation: 修改文件
path: C:\Users\Administrator\AppData\Roaming\Microsoft\gwaqzc.exe
processid: 1900
processname: 1621089044247_901bf12364683446b5a3192891f403f6.exe
sha1: ae17604211dd868d05d1e85b561c4f31b24339b6
sha256: cde7d94d83a1a5bfca10cc669fc2e550c89aeb7e0c7cfe9152eedd8b597232dc
size: 272909
this_path: /data/cuckoo/storage/analyses/2000484/files/1000/gwaqzc.exe
type: PE32 executable (GUI) Intel 80386, for MS Windows