How to remove SmLAztxc1o8yfogkJXrRjbDt.exe
- File Details
- Overview
- Analysis
SmLAztxc1o8yfogkJXrRjbDt.exe
The module SmLAztxc1o8yfogkJXrRjbDt.exe has been detected as Ransom.Wacatac
File Details
Product Name: |
|
Company Name: |
|
MD5: |
4f5771aa008fb55801a3f9fba7130f69 |
Size: |
681 KB |
First Published: |
2024-07-20 23:01:35 (10 months ago) |
Latest Published: |
2024-07-31 23:03:27 (10 months ago) |
Status: |
Ransom.Wacatac (on last analysis) |
|
Analysis Date: |
2024-07-31 23:03:27 (10 months ago) |
%commonappdata% |
%temp% |
%commonappdata% |
%localappdata%\microsoft\windows\inetcache\ie |
%temp% |
%localappdata%\microsoft\windows\inetcache\ie |
%commonappdata% |
%commonappdata% |
%commonappdata% |
|
33.3% |
|
|
22.2% |
|
|
22.2% |
|
|
11.1% |
|
|
11.1% |
|
Windows 10 |
66.7% |
|
Windows 8.1 |
22.2% |
|
Windows 7 |
11.1% |
|
Analysis
Subsystem: |
Windows CUI |
PE Type: |
pe |
OS Bitness: |
32 |
Image Base: |
0x00400000 |
Entry Address: |
0x000ab93e |
MVID: |
5fe0970a-1248-4f65-8f6e-87e310f6a897 |
Name |
Size of data |
MD5 |
.text |
694784 |
740a06a2963597faba6e251ac76a9704 |
.rsrc |
2048 |
be8d91bb3bab183f0795c08dbbcde7eb |
.reloc |
512 |
ed1392a8ea25c7311fd9f70b980d8631 |