How to remove A0004744.exe
- File Details
- Overview
- Analysis
A0004744.exe
The module A0004744.exe has been detected as Ransom.Wacatac
File Details
Product Name: |
|
MD5: |
ed1675cdd5ec38907bcb3f1d056b3c68 |
Size: |
2 MB |
First Published: |
2019-04-28 01:33:41 (6 years ago) |
Latest Published: |
2024-08-08 23:01:12 (a year ago) |
Status: |
Ransom.Wacatac (on last analysis) |
|
Analysis Date: |
2024-08-08 23:01:12 (a year ago) |
%sysdrive%\system volume information\_restore{4ceafdc4-3e93-4a33-bfc8-c5fe40d9a06f} |
%sysdrive%\العاب 333\games_1 |
%sysdrive% |
%sysdrive%\$recycle.bin\s-1-5-21-1618435585-1298396562-32181316-1000 |
%sysdrive%\$recycle.bin\s-1-5-21-1618435585-1298396562-32181316-1000 |
Windows 7 |
60.0% |
|
Windows 8 |
40.0% |
|
Analysis
Subsystem: |
Windows GUI |
PE Type: |
pe |
OS Bitness: |
32 |
Image Base: |
0x00400000 |
Entry Address: |
0x0000643f |
Name |
Size of data |
MD5 |
.text |
22016 |
c64c87c9aa464d2e806c4d837bed1860 |
.rdata |
1536 |
456426414cb0467d180e86ee3e691e20 |
.data |
512 |
19e034c032410ac04ee293cd340e2b1d |
.rsrc |
22016 |
8cd0c7ee4e3b20d8dc848adbf5ec2765 |