VirSCAN VirSCAN

1, You can UPLOAD any files, but there is 20Mb limit per file.
2, VirSCAN supports Rar/Zip decompression, but it must be less than 20 files.
3, Aplikace VirSCAN může skenovat komprimované soubory s heslem 'infected'nebo'virus'.

Language
Server load
Server Load
hxdef100.exe    Threatbook file behavior analysis report
Virscan.org multi-engine scan report
Behavior analysis report:         Habo file analysis
Basic Information
file name:hxdef100.exe
file type:EXEx86
Threat level:malicious
MD5:55cc1769cef44910bd91b7b73dee1f6c
sha256:02821f79d6aef71a94d15ee2bb72c7041aad22523eb3b81b1a53785facda03c6
Document Threat Intelligence IOC Report
No intelligence IOC detected
Intelligence decision system
Undetected intelligence determination system
Network behavior report
domains:0
dns:0
http:0
udp:0
smtp:0
icmp:0
irc:0
hosts:0
Document release report
File release report not detected
File process number report
nofind
Document behavior signature report
No file behavior report detected
Static information
Section name:CODE
Virtual address:0x00001000
Physical address:0x00000400
Physical size:0x0000de00
Section permissions:R-E
Section name:DATA
Virtual address:0x0000f000
Physical address:0x0000e200
Physical size:0x00000200
Section permissions:RW-
Section name:BSS
Virtual address:0x00010000
Physical address:0x0000e400
Physical size:0x00000000
Section permissions:RW-
Section name:.idata
Virtual address:0x00083000
Physical address:0x0000e400
Physical size:0x00000e00
Section permissions:RW-
Section name:.tls
Virtual address:0x00084000
Physical address:0x0000f200
Physical size:0x00000000
Section permissions:RW-
Section name:.rdata
Virtual address:0x00085000
Physical address:0x0000f200
Physical size:0x00000200
Section permissions:R--
Section name:.reloc
Virtual address:0x00086000
Physical address:0x0000f400
Physical size:0x00000e00
Section permissions:R--
Section name:.rsrc
Virtual address:0x00087000
Physical address:0x00010200
Physical size:0x00001000
Section permissions:R--
import_hash:22345fa4e62541740b4a703842f176c1
time_stamp:1992-06-20 06:22:17
entry_point_section:CODE
entry_point_section:CODE
image_base:0x400000
entry_point:0xeafc
name:RT_RCDATA
language:LANG_NEUTRAL
filetype:Sendmail frozen configuration
sublanguage:SUBLANG_NEUTRAL
offset:0x000870e0
size:0x00000010
name:RT_RCDATA
language:LANG_NEUTRAL
filetype:data
sublanguage:SUBLANG_NEUTRAL
offset:0x000870f0
size:0x00000068
name:RT_RCDATA
language:LANG_NEUTRAL
filetype:PE32 executable (native) Intel 80386, for MS Windows
sublanguage:SUBLANG_NEUTRAL
offset:0x00087158
size:0x00000d0e

About VirSCAN | Privacy Policy | Contact us | Links | Help VirSCAN
中国反网络病毒联盟
Powered By CentOSpol

京ICP备11007605号-12

pol

京公网安备 11010802020746号