VirSCAN VirSCAN

1, You can UPLOAD any files, but there is 20Mb limit per file.
2, VirSCAN supports Rar/Zip decompression, but it must be less than 20 files.
3, Aplikace VirSCAN může skenovat komprimované soubory s heslem 'infected'nebo'virus'.

Language
Server load
Server Load
VirSCAN
VirSCAN

1, You can UPLOAD any files, but there is 20Mb limit per file.
2, VirSCAN supports Rar/Zip decompression, but it must be less than 20 files.
3, Aplikace VirSCAN může skenovat komprimované soubory s heslem 'infected'nebo'virus'.

MyDiskTest3.exe    Threatbook file behavior analysis report

Virscan.org multi-engine scan report
Behavior analysis report:         Habo file analysis

Basic Information

file name: MyDiskTest3.exe
file type: EXEx86
Threat level: clean
MD5: 9665a66c054ac860e7547923718591ef
sha256: 5773f2f8355f34bc9776160942dc9482f95c980ee71973ffa8b37da62238fd6e

Document Threat Intelligence IOC Report

No intelligence IOC detected

Intelligence decision system

Undetected intelligence determination system

Network behavior report

domains: 0

Document release report

File release report not detected

File process number report

nofind

Document behavior signature report

Low risk behavior
General behavior: Contains ability to find and load resources of a specific module
Suspicious behavior 0
High risk behavior 0
Low risk behavior
System Environment Detection: Contains functionality to query system information
Suspicious behavior 0
High risk behavior 0
Low risk behavior
Static File Characteristics: Found potential IP address or url in binary/memory
Suspicious behavior 0
High risk behavior 0
Low risk behavior 0
Low risk behavior
System Sensitive Operations: Disables application error messsages (SetErrorMode)
High risk behavior 0
Low risk behavior 0
Low risk behavior
Information gathering: Contains functionality to retrieve information about pressed keystrokes
High risk behavior 0
Low risk behavior 0
Low risk behavior
High risk behavior 0
Low risk behavior 0
Low risk behavior
Reverse Engineering: The binary likely contains encrypted or compressed data indicative of a packer
High risk behavior 0

Static information

Section name: MDT0
Virtual address: 0x00001000
Physical address: 0x00000400
Physical size: 0x00000000
Section permissions: RWE
Section name: MDT1
Virtual address: 0x000ae000
Physical address: 0x00000400
Physical size: 0x00024600
Section permissions: RWE
Section name: .rsrc
Virtual address: 0x000d3000
Physical address: 0x00024a00
Physical size: 0x00005e00
Section permissions: RW-
import_hash: 3243b13e562279ab7fbe2f31e45d3a95
time_stamp: 2012-03-07 00:02:30
entry_point_section: MDT1
image_base: 0x400000
entry_point: 0xd1940
name: RT_ICON
language: LANG_NEUTRAL
filetype: data
sublanguage: SUBLANG_NEUTRAL
offset: 0x000d31dc
size: 0x00000ea8
name: RT_ICON
language: LANG_NEUTRAL
filetype: data
sublanguage: SUBLANG_NEUTRAL
offset: 0x000d4088
size: 0x000008a8
name: RT_ICON
language: LANG_NEUTRAL
filetype: GLS_BINARY_LSB_FIRST
sublanguage: SUBLANG_NEUTRAL
offset: 0x000d4934
size: 0x00000568
name: RT_ICON
language: LANG_NEUTRAL
filetype: data
sublanguage: SUBLANG_NEUTRAL
offset: 0x000d4ea0
size: 0x000025a8
name: RT_ICON
language: LANG_NEUTRAL
filetype: data
sublanguage: SUBLANG_NEUTRAL
offset: 0x000d744c
size: 0x000010a8
name: RT_ICON
language: LANG_NEUTRAL
filetype: GLS_BINARY_LSB_FIRST
sublanguage: SUBLANG_NEUTRAL
offset: 0x000d84f8
size: 0x00000468
name: RT_GROUP_ICON
language: LANG_NEUTRAL
filetype: MS Windows icon resource - 6 icons, 48x48, 256-colors
sublanguage: SUBLANG_NEUTRAL
offset: 0x000d8964
size: 0x0000005a
name: RT_VERSION
language: LANG_CHINESE
filetype: data
sublanguage: SUBLANG_CHINESE_SIMPLIFIED
offset: 0x000d89c4
size: 0x00000354