How to remove WeAreDevs_API.dll
- File Details
- Overview
- Analysis
WeAreDevs_API.dll
The module WeAreDevs_API.dll has been detected as Ransom.Sabsik
File Details
| Product Name: |
|
| MD5: |
0025193fb8ac07ab3bac031604fa4c2f |
| Size: |
607 KB |
| First Published: |
2023-01-08 23:39:57 (3 years ago) |
| Latest Published: |
2025-02-04 23:01:37 (11 months ago) |
| Status: |
Ransom.Sabsik (on last analysis) |
|
| Analysis Date: |
2025-02-04 23:01:37 (11 months ago) |
| %profile%\downloads |
| %desktop% |
| %sysdrive%\mateo\escritorio |
| %sysdrive%\загрузки\scoped_dir5824_1707031471 |
| %sysdrive%\загрузки\2129_timm3h\scoped_dir3196_576157290 |
| %sysdrive%\загрузки\scoped_dir5720_904953376 |
| %sysdrive%\загрузки\scoped_dir5276_488758068 |
| %sysdrive%\загрузки\scoped_dir7284_2135749586 |
| %sysdrive%\$recycle.bin\s-1-5-21-51164742-3470473915-141664889-1001 |
| %sysdrive%\$recycle.bin\s-1-5-21-51164742-3470473915-141664889-1001 |
|
46.4% |
|
|
17.9% |
|
|
17.9% |
|
|
7.1% |
|
|
3.6% |
|
|
3.6% |
|
|
3.6% |
|
Analysis
| Subsystem: |
Windows CUI |
| PE Type: |
pe |
| OS Bitness: |
32 |
| Image Base: |
0x00400000 |
| Entry Address: |
0x000992ce |
| MVID: |
bad94c07-6d4e-47f9-88d6-d05724ae1155 |
| Typelib ID: |
6d8a8bf5-f458-403a-a65f-8989c36536fd |
| Name |
Size of data |
MD5 |
| .text |
619520 |
c6194ac0962cd9b3f3a051d3e010379b |
| .rsrc |
1536 |
704278e810981b701db11cda9b908e03 |
| .reloc |
512 |
8c4cf48c064f80be038c1e612af88f23 |