Windows Analysis Report
rdp.exe

Overview

General Information

Sample name: rdp.exe
Analysis ID: 1438254
MD5: c56cd6a873e360c58dc80796e1ff6cde
SHA1: 49be32431f0e18d8266f0cc2e561a23aca092a0c
SHA256: ba4f0f99a57739a9bc7612c95496305fda3afbfea012c9478a66299f69c650df

Detection

Score: 52
Range: 0 - 100
Whitelisted: false
Confidence: 100%

Signatures

Multi AV Scanner detection for submitted file
.NET source code contains potential unpacker
Uses 32bit PE files

Classification

AV Detection

barindex
Source: rdp.exe Virustotal: Detection: 8% Perma Link
Source: rdp.exe Static PE information: EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, LOCAL_SYMS_STRIPPED, 32BIT_MACHINE
Source: rdp.exe Static PE information: EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, LOCAL_SYMS_STRIPPED, 32BIT_MACHINE
Source: classification engine Classification label: mal52.evad.winEXE@0/0@0/0
Source: rdp.exe Static PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
Source: rdp.exe Static file information: TRID: Win32 Executable (generic) Net Framework (10011505/4) 49.80%
Source: rdp.exe Virustotal: Detection: 8%
Source: rdp.exe Static PE information: data directory type: IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR

Data Obfuscation

barindex
Source: rdp.exe, --.cs .Net Code: _0002 System.Reflection.Assembly.Load(byte[])
⊘No contacted IP infos