vetrosploit.dll

MD5:
06cb2a6de6da04f968335bc9f97d9a08

SHA-1:
7fb005f7a9ffbb47a22a9fcbf6b71c648d615c97

SHA-256:
bfcdefe5974aeceedcba87932ef0a3a422a6e10df3cf05b960337b700273f7c0

Scanner detections:
1 / 68

Status:
Clean  (1 probable false positive detection)

Explanation:
This is mosty likely a false positive detection, the file is probably clean.

Analysis date:
11/4/2024 5:06:29 PM UTC  (today)

Scan engine
Detection
Engine version

Qihoo 360 Security
HEUR/QVM30.1.0000.Malware.Gen
1.0.0.1120

File size:
44 KB (45,056 bytes)

File type:
Dynamic link library (Win32 DLL)

Common path:
C:\users\{user}\downloads\vetrosploit.dll

File PE Metadata
Compilation timestamp:
7/9/2016 11:16:38 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
768:FfBcg9kIxBPdSdtL54LmsaLGIOiUwXpZEQ6IbsdsrjhEOZo+WrW/L:RB3RenEmsaL7lJXkDsuOZIw

Entry address:
0x730D

Entry point:
8B, FF, 55, 8B, EC, 83, 7D, 0C, 01, 75, 05, E8, 31, 05, 00, 00, FF, 75, 08, 8B, 4D, 10, 8B, 55, 0C, E8, CC, FE, FF, FF, 59, 5D, C2, 0C, 00, FF, 25, 34, 91, 00, 10, 50, 64, FF, 35, 00, 00, 00, 00, 8D, 44, 24, 0C, 2B, 64, 24, 0C, 53, 56, 57, 89, 28, 8B, E8, A1, 18, C0, 00, 10, 33, C5, 50, FF, 75, FC, C7, 45, FC, FF, FF, FF, FF, 8D, 45, F4, 64, A3, 00, 00, 00, 00, C3, 8B, 4D, F4, 64, 89, 0D, 00, 00, 00, 00, 59, 5F, 5F, 5E, 5B, 8B, E5, 5D, 51, C3, 6A, 14, 68, 40, 9C, 00, 10, E8, 47, 04, 00, 00, FF, 35, 2C, C6...
 
[+]

Code size:
29 KB (29,696 bytes)

The file vetrosploit.dll has been seen being distributed by the following 7 URLs.

http://download804.mediafire.com/pbmip7wbbqcg/.../VetroSploit.dll

http://download804.mediafire.com/imd13fu4ncgg/.../VetroSploit.dll

http://download804.mediafire.com/8b0rukys1bcg/.../VetroSploit.dll

http://download804.mediafire.com/7968ux5ojzqg/.../VetroSploit.dll

https://mega.nz/temporary/.../YxwCEQYD

http://download804.mediafire.com/y32muj0dynvg/.../VetroSploit.dll

Scan vetrosploit.dll - Powered by Reason Core Security