VirusShare.com - Because Sharing is Caring

Home • Hashes • Research • About • Swag Shop

Account: Login

Please login to search and download.

System currently contains 107,869,975 malware samples.

Report for a sample recently added to the system:
b0fe7b3c2af277715a9ff392ea133201d2230221e509b37ea60f606d5f940816
VirusShare info last updated 2026-01-12 00:00:01 UTC
Detected by 18 engines  
MD5343ea750fc528c5e7058d29d31792a91
SHA1d9f92ab8b7d7192bb4e4f53568dee064a4e697af
SHA256b0fe7b3c2af277715a9ff392ea133201d2230221e509b37ea60f606d5f940816
SSDeep49152:cNKVkuevdUaplJGn89oKf0JlVumAXOIltDSJJoKhw3PoY5LMKR:3KuQRhGn89fcsmGbltDSJoVPXyo
Authentihasha6c6115b8c30b5a2b6a1bf6c964efde1cb61773e20cb31635b1ae93291830435
Size2,643,720 bytes
File TypePE32+ executable (GUI) x86-64, for MS Windows
Mime Typeapplication/x-dosexec
Extensionexe
TrIDWin64 Executable (generic) (44.4%)
Win16 NE executable (generic) (21.3%)
Windows Icons Library (generic) (8.7%)
OS/2 Executable (generic) (8.5%)
Generic Win/DOS Executable (8.4%)
Detections
(18/70)
AVGWin64:Evo-gen [Trj]
AhnLab-V3Trojan/Win.Lazy.R744075
AvastWin64:Evo-gen [Trj]
BkavW64.AIDetectMalware
CrowdStrikewin/malicious_confidence_100% (W)
CylanceUnsafe
CynetMalicious (score: 99)
ESET-NOD32Win32/Packed.VMProtect.ACX trojan
Elasticmalicious (high confidence)
FortinetW32/PossibleThreat
GridinsoftTrojan.Heur!.002121B3
IkarusWin32.Outbreak
KasperskyTrojan-Banker.Win64.CryptoClipper.if
MalwarebytesMalware.AI.352445874
McAfeeDti!B0FE7B3C2AF2
SentinelOneStatic AI - Suspicious PE
Trapminesuspicious.low.ml.score
VirITTrojan.Win64.AgentX.HMW
VirusTotal Report submitted 2026-01-10 05:27:40 UTC
ExIF Data
CharacterSetUnicode
CodeSize1234944
CompanyNameMicrosoft Corporation
EntryPoint0x39e6b4
FileDescriptionSpooler SubSystem App
FileFlags(none)
FileFlagsMask0x003f
FileOSWindows NT 32-bit
FileSize2.5 MB
FileSubtype0
FileTypeWin64 EXE
FileTypeExtensionexe
FileVersion10.0.17763.7919 (WinBuild.160101.0800)
FileVersionNumber10.0.17763.7919
ImageFileCharacteristicsExecutable, Large address aware
ImageVersion1
InitializedDataSize241664
InternalNamespoolsv.exe
LanguageCodeEnglish (U.S.)
LegalCopyright© Microsoft Corporation. All rights reserved.
LinkerVersion3
MIMETypeapplication/octet-stream
MachineTypeAMD AMD64
OSVersion6.1
ObjectFileTypeExecutable application
OriginalFileNamespoolsv.exe
PETypePE32+
ProductNameMicrosoft® Windows® Operating System
ProductVersion10.0.17763.7919
ProductVersionNumber10.0.17763.7919
SubsystemWindows GUI
SubsystemVersion6.1
TimeStamp0000:00:00 00:00:00
UninitializedDataSize0