How to remove WindowsService.exe
- File Details
- Overview
- Analysis
WindowsService.exe
The module WindowsService.exe has been detected as Ransom.Sabsik
File Details
MD5: |
1d7d93fa84ba7c5a5c8b1d62acbb048d |
Size: |
5 MB |
First Published: |
2022-06-20 23:57:01 (2 years ago) |
Latest Published: |
2024-03-28 23:01:35 (15 hours ago) |
Status: |
Ransom.Sabsik (on last analysis) |
|
Analysis Date: |
2024-03-28 23:01:35 (15 hours ago) |
%localappdata% |
%localappdata% |
%localappdata% |
%localappdata% |
%localappdata% |
%localappdata% |
%localappdata% |
%localappdata% |
%localappdata% |
%localappdata% |
|
13.6% |
|
|
9.1% |
|
|
9.1% |
|
|
4.5% |
|
|
4.5% |
|
|
4.5% |
|
|
4.5% |
|
|
4.5% |
|
|
4.5% |
|
|
4.5% |
|
|
4.5% |
|
|
4.5% |
|
|
4.5% |
|
|
4.5% |
|
|
4.5% |
|
|
4.5% |
|
|
4.5% |
|
|
4.5% |
|
Windows 10 |
72.7% |
|
Windows 7 |
13.6% |
|
Windows 8.1 |
9.1% |
|
Windows Vista |
4.5% |
|
Analysis
Subsystem: |
Windows CUI |
PE Type: |
pe |
OS Bitness: |
64 |
Image Base: |
0x0000000140000000 |
Entry Address: |
0x0076b85b |
Name |
Size of data |
MD5 |
.text |
0 |
d41d8cd98f00b204e9800998ecf8427e |
.rdata |
0 |
d41d8cd98f00b204e9800998ecf8427e |
.data |
0 |
d41d8cd98f00b204e9800998ecf8427e |
.pdata |
0 |
d41d8cd98f00b204e9800998ecf8427e |
.vmp0 |
0 |
d41d8cd98f00b204e9800998ecf8427e |
.vmp1 |
5579776 |
851abcfa9878a10a27dfce4b7514e4f1 |
.rsrc |
512 |
ae876518a743e87cb8e14374a0e5499e |