vmprotect.exe

VMProtect

Permyakov Ivan

Publisher:
PolyTech  (signed by Permyakov Ivan)

Product:
VMProtect

Version:
1.7.0.3222

MD5:
27a34f39dec126704d80b90d23ae9137

SHA-1:
53cec64450121175fe9751dd1609c6233fdf67ba

SHA-256:
5befc8a8f5711d096f3bb0bcd086b68e423b88c81391e9be213004f69ee7eb47

Scanner detections:
2 / 68

Status:
Clean  (2 probable false positive detections)

Explanation:
These detections are probably false positives (erroneous), the file is probably malware free.

Analysis date:
4/23/2024 10:28:35 PM UTC  (today)

Scan engine
Detection
Engine version

K7 AntiVirus
Trojan
13.174.10306

Sophos
Mal/Scribble-D
4.95

File size:
1.5 MB (1,619,624 bytes)

Product version:
1.7

Copyright:
Copyright 2003-2008 PolyTech

File type:
Executable application (Win32 EXE)

Language:
Russian (Russia)

Digital Signature
Signed by:

Authority:
The USERTRUST Network

Valid from:
5/23/2008 1:00:00 AM

Valid to:
5/24/2009 12:59:59 AM

Subject:
CN=Permyakov Ivan, O=Permyakov Ivan, STREET="Uktusskaya str.47, #54", L=Ekaterinburg, S=Russia, PostalCode=623701, C=RU

Issuer:
CN=UTN-USERFirst-Object, OU=http://www.usertrust.com, O=The USERTRUST Network, L=Salt Lake City, S=UT, C=US

Serial number:
009DED74587A504D63EA7DEDB184272385

File PE Metadata
Compilation timestamp:
6/19/1992 11:22:17 PM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
49152:TyY0mUWSyf+n08fnYXebgduxzUpIQTAEhAT:+Y0qZf+npv8eUduNUpIZEhw

Entry address:
0x302970

Entry point:
68, 76, C3, FB, DF, E8, 68, 41, 16, 00, 58, 55, 0D, CA, 7B, 69, 23, D1, 8B, 99, 51, C0, CA, 6E, 1B, 99, 80, 43, 4D, 2D, AF, 88, 33, 3E, 67, 45, D9, 49, 0C, 89, F5, 66, DF, D5, 7B, FB, 83, CE, 4A, B3, A0, D0, AE, 44, BB, 28, AB, C3, A5, A5, 27, D6, F9, A7, BE, DD, 29, 82, B8, 0C, 8D, 76, 0A, 4B, 18, D7, AA, EF, C7, DD, E1, 7D, 41, 2F, FB, BA, 9D, 5D, D4, 6D, 94, 44, AE, 31, 54, 74, 17, 59, 89, 33, 4C, 73, 4A, 46, 78, 00, 2A, 83, 4B, 7F, ED, 9E, 5B, 9C, F3, BD, D0, C4, 36, 5F, D0, 1D, DF, B5, 22, 62, 0F, E1...
 
[+]

Entropy:
7.9387  (probably packed)

Code size:
4.4 MB (4,617,216 bytes)

Scan vmprotect.exe - Powered by Reason Core Security