File Path | Type and Hashes |
---|
Match Rules |
---|
File Name: | gVQwT.exe |
File Type: | PE32 executable (console) Intel 80386, for MS Windows |
SHA1: | bd356d3d2f1e5504a47d5f6d743411c721e4c8f0 |
MD5: | 2c7cb1ce9b000196db3f1ff18c84d879 |
First Seen Date: | 2018-03-14 18:44:46.238389 ( ) |
Number of Clients Seen: | 3 |
Last Analysis Date: | 2018-03-14 18:44:46.238389 ( ) |
Human Expert Analysis Date: | 2018-03-14 20:05:07.597076 ( ) |
Human Expert Analysis Result: | Malware |
Property | Value |
---|---|
magic literal enum | 1 |
file type enum | 6 |
debug artifacts | [] |
number of sections | 5 |
trid | [] |
compilation time stamp | 0x0 [Thu Jan 1 00:00:00 1970 UTC] [SUSPICIOUS] |
entry point | 0x401bc0 (.text) |
machine type | Intel 386 or later - 32Bit |
file size | 143360 |
ssdeep | |
sha256 | 1f79b551e1a35964691ebe1d424b23b571408098c14cc6ae26429962e91d89f7 |
exifinfo | [] |
mime type | application/x-dosexec |
imphash |
Name | Virtual Address | Virtual Size | Raw Size | Entropy | MD5 |
---|---|---|---|---|---|
.text | 0x1000 | 0xe2a | 0x1000 | 5.96458508508 | bbffbda161b8086e6f930913cff97ff1 |
CODE | 0x2000 | 0x24d6 | 0x3000 | 5.0546338917 | 1f45ae989a55aa0c87aa796707649dd1 |
.rdata | 0x5000 | 0x770 | 0x1000 | 2.52947135342 | cef67e0796c0c695575937872840439d |
.data | 0x6000 | 0x1cc98 | 0x1c000 | 7.16522022568 | 15240aeca754fb6d8423595f98d39e7d |
.reloc | 0x23000 | 0x682 | 0x1000 | 0.605596058441 | c69bccc99071e861929aa1d25f8aac75 |