Windows Analysis Report
PzdLFHRjMb.exe

Overview

General Information

Sample name: PzdLFHRjMb.exe
renamed because original name is a hash value
Original sample name: 17a423de386fa70146973f60e736b062.exe
Analysis ID: 1520461
MD5: 17a423de386fa70146973f60e736b062
SHA1: 83af39ba036dda67af93e11f64d48f4d3fbb9ba0
SHA256: b5bd07d284a8f96c2a61828eb14f09afc3ac056c48841ca62606763803433b08
Tags: exeuser-abuse_ch
Errors
  • No process behavior to analyse as no analysis process or sample was found
  • Corrupt sample or wrongly selected analyzer. Details: %1 is not a valid Win32 application.

Detection

Score: 48
Range: 0 - 100
Whitelisted: false
Confidence: 100%

Signatures

Multi AV Scanner detection for submitted file
PE file contains an invalid checksum
PE file does not import any functions
PE file overlay found
Uses 32bit PE files

Classification

AV Detection

barindex
Source: PzdLFHRjMb.exe ReversingLabs: Detection: 13%
Source: PzdLFHRjMb.exe Static PE information: RELOCS_STRIPPED, EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, LOCAL_SYMS_STRIPPED, LARGE_ADDRESS_AWARE, 32BIT_MACHINE
Source: PzdLFHRjMb.exe Static PE information: No import functions for PE file found
Source: PzdLFHRjMb.exe Static PE information: Data appended to the last section found
Source: PzdLFHRjMb.exe Static PE information: RELOCS_STRIPPED, EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, LOCAL_SYMS_STRIPPED, LARGE_ADDRESS_AWARE, 32BIT_MACHINE
Source: classification engine Classification label: mal48.winEXE@0/0@0/0
Source: PzdLFHRjMb.exe Static PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
Source: PzdLFHRjMb.exe ReversingLabs: Detection: 13%
Source: PzdLFHRjMb.exe Static PE information: Virtual size of .text is bigger than: 0x100000
Source: PzdLFHRjMb.exe Static PE information: Raw size of .text is bigger than: 0x100000 < 0x15d000
Source: PzdLFHRjMb.exe Static PE information: Raw size of .rdata is bigger than: 0x100000 < 0x162000
Source: PzdLFHRjMb.exe Static PE information: real checksum: 0x2fc54f should be: 0xd783e
No contacted IP infos