By using Saferwall you consent to our Terms of Service and Privacy Policy and allow us to share your submission with the security community. Learn more

Summary

Analyse score

0/ 14

No antivirus venders flagged
this file as malicious

Signature

File is not signed

Last scanned

First submission

File type

exe

exe

Basic properties

CRC32

0x963a30d

MD5

5bb2fef22dc399f586142db832cb087a

Magic

PE32+ executable (console) x86-64 (stripped to external PDB), for MS Windows

SHA1

42bb1237cd8b942d688d61066aff78e04a7045f1

SHA256

4b1cf880ae343ffc29a680c3d1aa88634ae5e969b012ab1aa29d15c6e1e6ed96

SHA512

ea1eea76e150d37eb85c3bf2aa4fdd023b7879caa59e3554bcb7818dcc7f75bc15eefafdc65855e5994bb861b82ca41af46360d7a526d0f67a15f343ebc32bc8

SSDeep

98304:33OEb5qLTEFjpEZZBvi+yR/LGGa936JHvcP:HkckZZud6GY6JP

Size

6.66MB

Packer
  • PE+(64): linker: unknown(3.0)[EXE64,console]
TrID
  • 48.7% (.EXE) Win64 Executable (generic) (10523/12/4)
  • 23.3% (.EXE) Win16 NE executable (generic) (5038/12/1)
  • 9.3% (.EXE) OS/2 Executable (generic) (2029/13)
  • 9.2% (.EXE) Generic Win/DOS Executable (2002/3)
  • 9.2% (.EXE) DOS Executable Generic (2000/1)
Tags

ExifTool File Metadata

CodeSize

2.23MB

EntryPoint

0x66a40

ExifToolVersionNumber

12.62

FileSize

7.0 MB

FileType

Win64 EXE

FileTypeExtension

exe

ImageFileCharacteristics

Executable, Large address aware, No debug

ImageVersion

1.0

InitializedDataSize

236.50KB

LinkerVersion

3.0

MachineType

AMD AMD64

MimeType

application/octet-stream

OsVersion

6.1

PeType

PE32+

Subsystem

Windows command line

SubsystemVersion

6.1

UninitializedDataSize

0

Submissions

Published Name Source Country
bad.exe web
Japan