Windows Analysis Report
ogsYF5OdQc.exe

Overview

General Information

Sample name: ogsYF5OdQc.exe
renamed because original name is a hash value
Original sample name: 8a4cc88206caf0deecf0f8bf4f599656.exe
Analysis ID: 1521405
MD5: 8a4cc88206caf0deecf0f8bf4f599656
SHA1: 7c40cc072dc07392a6aa8824e2e18b649d8afe51
SHA256: f8bdaca71010e85371e4eaca32b6de4335cdf3d9e4b00d4d5151fbcc95e3d5c8
Tags: exeuser-abuse_ch
Errors
  • No process behavior to analyse as no analysis process or sample was found
  • Corrupt sample or wrongly selected analyzer. Details: %1 is not a valid Win32 application.

Detection

Score: 1
Range: 0 - 100
Whitelisted: false
Confidence: 80%

Signatures

PE file does not import any functions
PE file overlay found
Uses 32bit PE files

Classification

Source: ogsYF5OdQc.exe Static PE information: EXECUTABLE_IMAGE, 32BIT_MACHINE
Source: ogsYF5OdQc.exe Static PE information: HIGH_ENTROPY_VA, DYNAMIC_BASE, NX_COMPAT, NO_SEH, TERMINAL_SERVER_AWARE
Source: ogsYF5OdQc.exe Static PE information: No import functions for PE file found
Source: ogsYF5OdQc.exe Static PE information: Data appended to the last section found
Source: ogsYF5OdQc.exe Static PE information: EXECUTABLE_IMAGE, 32BIT_MACHINE
Source: ogsYF5OdQc.exe Static PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
Source: classification engine Classification label: unknown1.winEXE@0/0@0/0
Source: ogsYF5OdQc.exe Static PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
Source: ogsYF5OdQc.exe Static PE information: data directory type: IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR
Source: ogsYF5OdQc.exe Static PE information: HIGH_ENTROPY_VA, DYNAMIC_BASE, NX_COMPAT, NO_SEH, TERMINAL_SERVER_AWARE
Source: ogsYF5OdQc.exe Static PE information: data directory type: IMAGE_DIRECTORY_ENTRY_DEBUG
Source: ogsYF5OdQc.exe Static PE information: section name: .text entropy: 7.987934047990933

No Behavior Graph

No contacted IP infos