Windows Analysis Report
gIw0Mwn5vv.exe

Overview

General Information

Sample name: gIw0Mwn5vv.exe
renamed because original name is a hash value
Original sample name: 2fec1cb6fbee9ecd036e269cb9182d1f.exe
Analysis ID: 1521406
MD5: 2fec1cb6fbee9ecd036e269cb9182d1f
SHA1: e8c83a7545458c6ea92707f1ad56afde2d53afcb
SHA256: 3ee254e2d5ccb30367923bb056ce581bcc1852ad72534b8c1aee4fe9e15b023b
Tags: exeuser-abuse_ch
Errors
  • No process behavior to analyse as no analysis process or sample was found
  • Corrupt sample or wrongly selected analyzer. Details: %1 is not a valid Win32 application.

Detection

Score: 1
Range: 0 - 100
Whitelisted: false
Confidence: 80%

Signatures

PE file does not import any functions
PE file overlay found
Uses 32bit PE files

Classification

Source: gIw0Mwn5vv.exe Static PE information: EXECUTABLE_IMAGE, 32BIT_MACHINE
Source: gIw0Mwn5vv.exe Static PE information: HIGH_ENTROPY_VA, DYNAMIC_BASE, NX_COMPAT, NO_SEH, TERMINAL_SERVER_AWARE
Source: gIw0Mwn5vv.exe Static PE information: No import functions for PE file found
Source: gIw0Mwn5vv.exe Static PE information: Data appended to the last section found
Source: gIw0Mwn5vv.exe Static PE information: EXECUTABLE_IMAGE, 32BIT_MACHINE
Source: gIw0Mwn5vv.exe Static PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
Source: classification engine Classification label: unknown1.winEXE@0/0@0/0
Source: gIw0Mwn5vv.exe Static PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
Source: gIw0Mwn5vv.exe Static PE information: data directory type: IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR
Source: gIw0Mwn5vv.exe Static PE information: HIGH_ENTROPY_VA, DYNAMIC_BASE, NX_COMPAT, NO_SEH, TERMINAL_SERVER_AWARE
Source: gIw0Mwn5vv.exe Static PE information: data directory type: IMAGE_DIRECTORY_ENTRY_DEBUG
Source: gIw0Mwn5vv.exe Static PE information: section name: .text entropy: 7.997024891616452

No Behavior Graph

No contacted IP infos