Windows
Analysis Report
gnupg-w32-2.4.7_20241125.exe
Overview
General Information
Detection
Score: | 2 |
Range: | 0 - 100 |
Confidence: | 60% |
Compliance
Score: | 48 |
Range: | 0 - 100 |
Signatures
Creates a process in suspended mode (likely to inject code)
Drops PE files
Found dropped PE file which has not been started or loaded
PE file contains an invalid checksum
PE file contains executable resources (Code or Archives)
PE file contains more sections than normal
PE file contains sections with non-standard names
Queries the volume information (name, serial number etc) of a device
Sample file is different than original file name gathered from version info
Uses 32bit PE files
Classification
- System is w10x64
gnupg-w32-2.4.7_20241125.exe (PID: 7312 cmdline:
"C:\Users\ user\Deskt op\gnupg-w 32-2.4.7_2 0241125.ex e" MD5: 89B24563D66BF8A2DD854AF031298E71) notepad.exe (PID: 1348 cmdline:
"C:\Window s\system32 \NOTEPAD.E XE" C:\Pro gram Files (x86)\gnu pg\README. txt MD5: E92D3A824A0578A50D2DD81B5060145F)
- cleanup
⊘No configs have been found
⊘No yara matches
⊘No Sigma rule has matched
⊘No Suricata rule has matched
- • Compliance
- • Networking
- • System Summary
- • Data Obfuscation
- • Persistence and Installation Behavior
- • Hooking and other Techniques for Hiding and Protection
- • Malware Analysis System Evasion
- • HIPS / PFW / Operating System Protection Evasion
- • Language, Device and Operating System Detection
Click to jump to signature section
Show All Signature Results
There are no malicious signatures, click here to show all signatures.
Compliance |
---|
Source: | Static PE information: |
Source: | Window detected: |