Windows Analysis Report


General Information

Sample name: cr0wdik.exe
Analysis ID: 1431502
MD5: 5524a506c0c49d3df2570808a38c3895
SHA1: 576011c0810f286b8945aaae9cd8656b75268bf6
SHA256: 7f51b7de954a8b4c25429c584ea282b9b6d7321a9032e4524f7c7ac38776dfcc
  • No process behavior to analyse as no analysis process or sample was found


Score: 48
Range: 0 - 100
Whitelisted: false
Confidence: 100%


Antivirus / Scanner detection for submitted sample
Sample file is different than original file name gathered from version info
Uses 32bit PE files


AV Detection

Source: cr0wdik.exe Avira: detected
Source: cr0wdik.exe Static PE information: EXECUTABLE_IMAGE, 32BIT_MACHINE
Source: cr0wdik.exe Static PE information: DYNAMIC_BASE, NX_COMPAT, TERMINAL_SERVER_AWARE
Source: Binary string: C:\vmagent_new\bin\joblist\621001\out\Release\360boxmain.pdb source: cr0wdik.exe
Source: cr0wdik.exe String found in binary or memory:
Source: cr0wdik.exe String found in binary or memory:
Source: cr0wdik.exe String found in binary or memory:
Source: cr0wdik.exe String found in binary or memory:
Source: cr0wdik.exe String found in binary or memory: http://ocsp.comodoca.com0
Source: cr0wdik.exe String found in binary or memory: http://ocsp.comodoca.com0&
Source: cr0wdik.exe String found in binary or memory: http://ocsp.sectigo.com0
Source: cr0wdik.exe String found in binary or memory:
Source: cr0wdik.exe String found in binary or memory:
Source: cr0wdik.exe String found in binary or memory:
Source: cr0wdik.exe Binary or memory string: OriginalFilenameSandboxMain.exe8 vs cr0wdik.exe
Source: cr0wdik.exe Static PE information: EXECUTABLE_IMAGE, 32BIT_MACHINE
Source: cr0wdik.exe Binary string: K`XD%machinename%%UserProfile%*\Documents and Settings\*\Local Settings\Temp\**\Documents and Settings\*\Local Settings\Temporary Internet Files\**\Documents and Settings\*\Cookies\**\AppData\Local\Temp\**\AppData\Roaming\Microsoft\Windows\Cookies\*\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders360SANDBOX\SHADOW360sandbox\filelist_page.xml::{26EE0668-A00A-44D7-9371-BEB064C98683}IDS_MEDIA_LIST_DESCIDS_DOCUMENT_LIST_DESCIDS_DELETE_PROMPT_MSGPreferred DropEffectIDS_COPY_PRMPT360SandBox\Shadow360SANDBOX\SHADOW\IDS_UPPER_FOLDERIDS_DATE_TIME_FMT%Y-%m-%d %H:%MC:\sxin.dllsxin64.dllSxWrapper.dllWINDOWS\SXIn.dllIDS_CRITICAL_FILE_PROMPT_MSG\Device\FloppyX
Source: classification engine Classification label: mal48.winEXE@0/0@0/0
Source: cr0wdik.exe Static PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
Source: cr0wdik.exe String found in binary or memory: 3
Source: cr0wdik.exe Static file information: File size 800000000 > 1048576
Source: cr0wdik.exe Static PE information: data directory type: IMAGE_DIRECTORY_ENTRY_IMPORT
Source: cr0wdik.exe Static PE information: data directory type: IMAGE_DIRECTORY_ENTRY_RESOURCE
Source: cr0wdik.exe Static PE information: data directory type: IMAGE_DIRECTORY_ENTRY_BASERELOC
Source: cr0wdik.exe Static PE information: data directory type: IMAGE_DIRECTORY_ENTRY_DEBUG
Source: cr0wdik.exe Static PE information: data directory type: IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG
Source: cr0wdik.exe Static PE information: data directory type: IMAGE_DIRECTORY_ENTRY_IAT
Source: cr0wdik.exe Static PE information: DYNAMIC_BASE, NX_COMPAT, TERMINAL_SERVER_AWARE
Source: cr0wdik.exe Static PE information: data directory type: IMAGE_DIRECTORY_ENTRY_DEBUG
Source: Binary string: C:\vmagent_new\bin\joblist\621001\out\Release\360boxmain.pdb source: cr0wdik.exe
No contacted IP infos