Windows Analysis Report
file.exe

Overview

General Information

Sample name: file.exe
Analysis ID: 1538206
MD5: a0f61d061ef9def76b30214dbb98792e
SHA1: f1d2493e883768b1727a65f279a48b2be175413f
SHA256: 50f1b2c577f41a52a0c323673f00dbbdbc99a84ab6eb1ec1a1a4d964fdfdc660
Tags: exeuser-Bitsight
Errors
  • No process behavior to analyse as no analysis process or sample was found
  • Corrupt sample or wrongly selected analyzer. Details: %1 is not a valid Win32 application.

Detection

Score: 52
Range: 0 - 100
Whitelisted: false
Confidence: 100%

Signatures

AI detected suspicious sample
Machine Learning detection for sample
PE file contains section with special chars
Entry point lies outside standard sections
PE file contains an invalid checksum
PE file contains sections with non-standard names
PE file overlay found
Uses 32bit PE files

Classification

AV Detection

barindex
Source: Submited Sample Integrated Neural Analysis Model: Matched 96.1% probability
Source: file.exe Joe Sandbox ML: detected
Source: file.exe Static PE information: EXECUTABLE_IMAGE, 32BIT_MACHINE

System Summary

barindex
Source: file.exe Static PE information: section name:
Source: file.exe Static PE information: section name: .rsrc
Source: file.exe Static PE information: section name: .idata
Source: file.exe Static PE information: section name:
Source: file.exe Static PE information: Data appended to the last section found
Source: file.exe Static PE information: EXECUTABLE_IMAGE, 32BIT_MACHINE
Source: file.exe Static PE information: Section: atgdqvtb ZLIB complexity 0.9955041983905166
Source: classification engine Classification label: mal52.winEXE@0/0@0/0
Source: file.exe Static file information: File size 1474560 > 1048576
Source: file.exe Static PE information: Raw size of atgdqvtb is bigger than: 0x100000 < 0x195e00
Source: initial sample Static PE information: section where entry point is pointing to: .taggant
Source: file.exe Static PE information: real checksum: 0x1cb7a2 should be: 0x16fed9
Source: file.exe Static PE information: section name:
Source: file.exe Static PE information: section name: .rsrc
Source: file.exe Static PE information: section name: .idata
Source: file.exe Static PE information: section name:
Source: file.exe Static PE information: section name: atgdqvtb
Source: file.exe Static PE information: section name: eqelhmzu
Source: file.exe Static PE information: section name: .taggant
Source: file.exe Static PE information: section name: atgdqvtb entropy: 7.953885829118027
No contacted IP infos