win32.exe

Version:
3.0.3.0

MD5:
7f5c54383e6b1f2e303b348135aa2f15

SHA-1:
14ddc1b69d46a87812708f260c1806e11cbf8bb9

SHA-256:
c867cb9e039f01b685847fc18e2f322db33209ffd0c6cee0bb514e44e9b1f0c1

Scanner detections:
4 / 68

Status:
Inconclusive  (not enough data for an accurate detection)

Analysis date:
6/22/2025 11:58:03 PM UTC  (a few moments ago)

Scan engine
Detection
Engine version

Emsisoft Anti-Malware
Trojan-Dropper.Win32.Agent
8.14.06.15.01

Kaspersky
Trojan-Spy.MSIL.KeyLogger
14.0.0.3707

Qihoo 360 Security
Malware.QVM03.Gen
1.0.0.1015

Sophos
Mal/Generic-S
4.98

File size:
663 KB (678,912 bytes)

Product version:
3.0.3.0

Copyright:
Copyright © 2014

Original file name:
micalj.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\ProgramData\windows services\win32.exe

File PE Metadata
Compilation timestamp:
6/12/2014 8:31:02 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
12288:Tn03bbKpazZqkihuqlJKjJMq3spARu50Y3UWXXZVHEkW8dySKB+:o3rZY8skVX2ARcDHrNX

Entry address:
0x55116

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
7.0723

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
332.5 KB (340,480 bytes)

The file win32.exe has been seen being distributed by the following URL.

Scan win32.exe - Powered by Reason Core Security