Windows Analysis Report
file.exe

Overview

General Information

Sample name: file.exe
Analysis ID: 1545824
MD5: ef4f3e1111446bbe44470a3f3d3ee4f2
SHA1: 1dfa28f653d43d33750c8eae87b9106894e2c0e7
SHA256: 574c9a068bd83b0da0130d65f338f07618e0a2acbedeaa923e52503128101d16
Tags: exeuser-Bitsight
Errors
  • No process behavior to analyse as no analysis process or sample was found
  • Corrupt sample or wrongly selected analyzer. Details: %1 is not a valid Win32 application.

Detection

Score: 48
Range: 0 - 100
Whitelisted: false
Confidence: 100%

Signatures

Machine Learning detection for sample
PE file contains section with special chars
Entry point lies outside standard sections
PE file contains an invalid checksum
PE file contains sections with non-standard names
PE file overlay found
Uses 32bit PE files

Classification

AV Detection

barindex
Source: file.exe Joe Sandbox ML: detected
Source: file.exe Static PE information: EXECUTABLE_IMAGE, 32BIT_MACHINE

System Summary

barindex
Source: file.exe Static PE information: section name:
Source: file.exe Static PE information: section name: .idata
Source: file.exe Static PE information: Data appended to the last section found
Source: file.exe Static PE information: EXECUTABLE_IMAGE, 32BIT_MACHINE
Source: file.exe Static PE information: Section: ZLIB complexity 0.9981325920846394
Source: classification engine Classification label: mal48.winEXE@0/0@0/0
Source: file.exe Static file information: File size 2555904 > 1048576
Source: file.exe Static PE information: Raw size of yswfrwhx is bigger than: 0x100000 < 0x29f400
Source: initial sample Static PE information: section where entry point is pointing to: .taggant
Source: file.exe Static PE information: real checksum: 0x2ce5c5 should be: 0x275177
Source: file.exe Static PE information: section name:
Source: file.exe Static PE information: section name: .idata
Source: file.exe Static PE information: section name: yswfrwhx
Source: file.exe Static PE information: section name: eypvdvsa
Source: file.exe Static PE information: section name: .taggant
Source: file.exe Static PE information: section name: entropy: 7.984648615988983
No contacted IP infos