Windows
Analysis Report
HandBrake-1.6.1-x86_64-Win_GUI.exe
Overview
General Information
Detection
Score: | 3 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 80% |
Compliance
Score: | 49 |
Range: | 0 - 100 |
Signatures
Uses 32bit PE files
Queries the volume information (name, serial number etc) of a device
Sample file is different than original file name gathered from version info
PE file contains an invalid checksum
Drops PE files
Contains functionality to shutdown / reboot the system
PE file contains sections with non-standard names
Detected potential crypto function
Stores files to the Windows start menu directory
PE file contains more sections than normal
Found dropped PE file which has not been started or loaded
Contains functionality for read data from the clipboard
Classification
- System is w10x64
HandBrake-1.6.1-x86_64-Win_GUI.exe (PID: 4748 cmdline:
C:\Users\u ser\Deskto p\HandBrak e-1.6.1-x8 6_64-Win_G UI.exe MD5: AA2240842CB69CA6CE2B7233CBE9E56E)
- cleanup
⊘No configs have been found
⊘No yara matches
⊘No Sigma rule has matched
⊘No Snort rule has matched
Click to jump to signature section
Show All Signature Results
There are no malicious signatures, click here to show all signatures.
Compliance |
---|
Source: | Static PE information: |
Source: | Window detected: |