Windows Analysis Report
file.exe

Overview

General Information

Sample name: file.exe
Analysis ID: 1531371
MD5: 68ad34b93eae4f0b89d315c0e3a56726
SHA1: c37548dedbefbb3c99eef1e6cb30a604995fa4de
SHA256: e9213a6488b86537a2f9a4c6a9990d028d4a08b9582f908c8517e37207d7d033
Tags: exeuser-Bitsight
Errors
  • No process behavior to analyse as no analysis process or sample was found
  • Corrupt sample or wrongly selected analyzer. Details: %1 is not a valid Win32 application.

Detection

Score: 56
Range: 0 - 100
Whitelisted: false
Confidence: 100%

Signatures

Multi AV Scanner detection for submitted file
Machine Learning detection for sample
PE file contains section with special chars
Entry point lies outside standard sections
PE file contains an invalid checksum
PE file contains sections with non-standard names
PE file does not import any functions
PE file overlay found
Uses 32bit PE files

Classification

AV Detection

barindex
Source: file.exe Virustotal: Detection: 16% Perma Link
Source: file.exe Joe Sandbox ML: detected
Source: file.exe Static PE information: EXECUTABLE_IMAGE, 32BIT_MACHINE

System Summary

barindex
Source: file.exe Static PE information: section name:
Source: file.exe Static PE information: section name: .rsrc
Source: file.exe Static PE information: section name: .idata
Source: file.exe Static PE information: section name:
Source: file.exe Static PE information: No import functions for PE file found
Source: file.exe Static PE information: Data appended to the last section found
Source: file.exe Static PE information: EXECUTABLE_IMAGE, 32BIT_MACHINE
Source: file.exe Static PE information: Section: ZLIB complexity 1.0005580357142858
Source: classification engine Classification label: mal56.winEXE@0/0@0/0
Source: file.exe Virustotal: Detection: 16%
Source: file.exe Static PE information: Raw size of gdqzmnqy is bigger than: 0x100000 < 0x198000
Source: initial sample Static PE information: section where entry point is pointing to: .taggant
Source: file.exe Static PE information: real checksum: 0x1cb93c should be: 0x1478c
Source: file.exe Static PE information: section name:
Source: file.exe Static PE information: section name: .rsrc
Source: file.exe Static PE information: section name: .idata
Source: file.exe Static PE information: section name:
Source: file.exe Static PE information: section name: gdqzmnqy
Source: file.exe Static PE information: section name: zpzeeqxh
Source: file.exe Static PE information: section name: .taggant
Source: file.exe Static PE information: section name: entropy: 7.972578796101194
No contacted IP infos