Download Link:
hxxp://58.65.239.42/kjhdf23/Crypted_packedW.exe
File Name: Crypted_packedW.exe
File size: 29696 bytes
MD5...: 9810686c1f977bcd55e62f2b09ec1dfe
SHA1..: 2f69105efbb460419e54336c34623294ff67ca5f
SHA256: 1c2cdda11af3d961ac852639e8bf746af7a9060c8b4de9a805cd89849e46ddf9
SHA512: 61494d271eef9158fcfcecf844b82c0275c1213740af8c7096b199f0af4cb5b0
c83d316c8d96d31b11d82d9969c74727f0d1c7270e32771394618d44fb1cfab5
VirusTotal Result: 21/31 (67.75%)
Scanned on 05.11.2008 12:11:43 (CET)
AntiVir 7.8.0.17 2008.05.09 TR/Spy.Webmoner.GV
Avast 4.8.1169.0 2008.05.10 Win32:Webmoner-DI
AVG 7.5.0.516 2008.05.10 PSW.Delf.BTF
BitDefender 7.2 2008.05.08 Trojan.Downloader.Harnig.ZF
CAT-QuickHeal 9.50 2008.05.10 TrojanSpy.Webmoner.gv
DrWeb 4.44.0.09170 2008.05.10 Trojan.PWS.Ibank
eSafe 7.0.15.0 2008.05.09 Win32.Webmoner.gv
eTrust-Vet 31.4.5771 2008.05.08 Win32/VMalum.BXPU
Ewido 4.0 2008.05.10 Logger.Webmoner.gv
F-Secure 6.70.13260.0 2008.05.10 Trojan-Spy.Win32.Webmoner.gv
Ikarus T3.1.1.26.0 2008.05.11 Trojan-Spy.Win32.Webmoner.gv
Kaspersky 7.0.0.125 2008.05.11 Trojan-Spy.Win32.Webmoner.gv
NOD32v2 3090 2008.05.09 Win32/Spy.Webmoner.GV
Panda 9.0.0.4 2008.05.10 Trj/Webmoner.AN
Prevx1 V2 2008.05.11 Cloaked Malware
Sophos 4.29.0 2008.05.11 Mal/Generic-A
Sunbelt 3.0.1097.0 2008.05.07 Trojan-Spy.Webmoner.gv
Symantec 10 2008.05.11 Infostealer
VBA32 3.12.6.5 2008.05.10 Trojan-Spy.Win32.Webmoner.fq
VirusBuster 4.3.26:9 2008.05.10 TrojanSpy.Webmoner.GC
Webwasher-Gateway 6.6.2 2008.05.09 Trojan.Spy.Webmoner.GV
PE Structure information
( base data )
entrypointaddress.: 0x40e0c6
timedatestamp.....: 0x2a425e19 (Fri Jun 19 22:22:17 1992)
machinetype.......: 0x14c (I386)
( 10 sections )
name viradd virsiz rawdsiz ntrpy md5
DATA 0x1000 0x53b4 0x5400 7.89 44416953b52fb2249e42a7b2b022b6d5
.icode 0x7000 0x80 0x200 2.01 d65cfffb0baf86a0097e7fc576ed3a53
.data_ 0x8000 0x989 0x0 0.00 d41d8cd98f00b204e9800998ecf8427e
.text 0x9000 0x294 0x400 5.46 f36924a0b81f7c3d68a7c09a145fd6e0
.icode 0xa000 0x4 0x0 0.00 d41d8cd98f00b204e9800998ecf8427e
.rsrc 0xb000 0x18 0x200 0.20 5a752f60c94e82b1b95ea71d294b5fa5
.icode 0xc000 0x180 0x0 0.00 d41d8cd98f00b204e9800998ecf8427e
CODE 0xd000 0x200 0x200 2.29 e6ea0c76752f90fbf9ad183d9e8b9b27
.icode 0xe000 0x336 0x400 6.35 4b78185933b4fe555c9bd91ec66d9733
CODE 0xf000 0x13d 0x200 2.92 549b83b7b9f96ebda193a4779795a95b
( 2 imports )
> kernel32.dll: GetComputerNameA, GetCPInfoExA
> gdi32.dll: CreateFontA, CreateDCA