f_001888

ReSharper10Crack

WZT

The file f_001888 by WZT has been detected as a potentially unwanted program by 2 anti-malware scanners.
Publisher:
WZT  (signed and verified)

Product:
ReSharper10Crack

Version:
1.0.0.0

MD5:
5e9a768a8f51b9c7ae03276ae035e6b4

SHA-1:
59d761b574acbf435b30df8527abdff4b975369e

SHA-256:
c6b79fc9115da8a6bd35611f58c5fbdc2d1fe56af44a7f5c978eb0603528ce4e

Scanner detections:
2 / 68

Status:
Potentially unwanted

Analysis date:
12/26/2024 2:13:05 PM UTC  (today)

Scan engine
Detection
Engine version

Qihoo 360 Security
QVM03.0.Malware.Gen
1.0.0.1077

Reason Heuristics
PUP.MSFree.WZT.Meta (M)
16.2.27.17

File size:
198.1 KB (202,880 bytes)

Product version:
1.0.0.0

Copyright:
Copyright © 2015

Original file name:
ReSharper10Crack.exe

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\temp\webkit\cache\f_001888

Digital Signature
Signed by:

Authority:
WZT

Valid from:
11/8/2015 9:15:49 AM

Valid to:
1/1/2040 12:59:59 AM

Subject:
CN=WZT

Issuer:
CN=WZT

Serial number:
08A8E826950F1A9940262589FCAF0B8F

File PE Metadata
Compilation timestamp:
11/18/2015 7:04:25 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
3072:cm5kveS4iM/4I6ZAVZqdCNcT9qb1n1A9o0Z9ZDBCcOhMuZpvM+Y++RW:ZieX6OZrN3RSWinIvWufWZW

Entry address:
0x31FAE

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 02, 00, 10, 00, 00, 00, 20, 00, 00, 80, 18, 00, 00, 00, 38, 00, 00, 80, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
7.9454

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
192 KB (196,608 bytes)

The file f_001888 has been seen being distributed by the following 4 URLs.

about:internet

Remove f_001888 - Powered by Reason Core Security