How to remove 1122992.exe
- File Details
- Overview
- Analysis
1122992.exe
The module 1122992.exe has been detected as Ransom.Wacatac
File Details
| Product Name: |
|
| Company Name: |
|
| MD5: |
5696457aedcbad574a0081e1b4c8b9a5 |
| Size: |
3 MB |
| First Published: |
2021-11-08 21:20:29 (4 years ago) |
| Latest Published: |
2021-11-08 21:20:29 (4 years ago) |
| Status: |
Ransom.Wacatac (on last analysis) |
|
| Analysis Date: |
2021-11-08 21:20:29 (4 years ago) |
Overview
Analysis
| Subsystem: |
Windows GUI |
| PE Type: |
pe |
| OS Bitness: |
32 |
| Image Base: |
0x00400000 |
| Entry Address: |
0x004fff98 |
| Name |
Size of data |
MD5 |
| |
102912 |
82dcc302b768d752040702bd1f25d18c |
| |
17920 |
f9671e464e76262191ad6f517751994f |
| |
512 |
2c2c623434925c4845e3836a88b7ad78 |
| .idata |
512 |
d220efc76e8fb3ef5cf45e244fb748d1 |
| Q*jr%Lr8 |
2048 |
81da5496b100102296f37a5b5b4d8809 |
| .themida |
0 |
d41d8cd98f00b204e9800998ecf8427e |
| .boot |
3075072 |
9aa634bf1957c37b39153d13ab0cf62a |
| Q*jr%Lr8 |
3584 |
9f757fc6cb897a7a80bab88804a2f1a5 |
| Q*jr%Lr8 |
3584 |
4f1154ee46db5f1ccdd89b4c0aea455a |
| .rsrc |
388096 |
48d173990625d36ef680b9be6786ce29 |