How to remove 5239890474.exe
- File Details
- Overview
- Analysis
5239890474.exe
The module 5239890474.exe has been detected as Ransom.Sabsik
File Details
| MD5: |
7231349e4c175b73a002c684bd8a3d0f |
| Size: |
7 MB |
| First Published: |
2022-11-20 23:31:30 (3 years ago) |
| Latest Published: |
2022-11-29 23:58:53 (3 years ago) |
| Status: |
Ransom.Sabsik (on last analysis) |
|
| Analysis Date: |
2022-11-29 23:58:53 (3 years ago) |
| %appdata% |
| %appdata% |
| %appdata% |
| %appdata% |
| %appdata% |
| %appdata% |
| Windows 10 |
66.7% |
|
| Windows 7 |
33.3% |
|
Analysis
| Subsystem: |
Windows GUI |
| PE Type: |
pe |
| OS Bitness: |
64 |
| Image Base: |
0x0000000000400000 |
| Entry Address: |
0x000014c0 |
| Name |
Size of data |
MD5 |
| .text |
4192768 |
47f033d1a4563ea633fc2ea722dd6fe8 |
| .data |
267264 |
51455d48d06c0f641899a5eb391227ed |
| .rdata |
3223552 |
186c87f0beb51f2a3d92b48db8dfb08f |
| .pdata |
24576 |
4bcf230e6c730516af99802749e432a6 |
| .xdata |
26112 |
c4f938be588c0454af1c271c936211f2 |
| .bss |
0 |
d41d8cd98f00b204e9800998ecf8427e |
| .edata |
512 |
a6a261a283a3850641e5854eb861a388 |
| .idata |
6144 |
a778667a6784f6e52feefc5f19a2a0d2 |
| .CRT |
512 |
590505a35046ed84e221996b80395896 |
| .tls |
512 |
bf619eac0cdf3f68d496ea9344137e8b |
| .reloc |
55296 |
ce683b62bc8aff8b9128f3cecc7e42a3 |