By using Saferwall you consent to our Terms of Service and Privacy Policy and allow us to share your submission with the security community. Learn more

Summary

Analyse score

11/ 14

11 antivirus venders flagged
this file as malicious

Signature

File is not signed

Last scanned

First submission

File type

exe

exe

Basic properties

CRC32

0xc86a49d4

MD5

20f85ec09a12be38db35a305fae825a8

Magic

PE32 executable (GUI) Intel 80386, for MS Windows

SHA1

afcda3062546fb1d2162b77b8be89192fb1631e5

SHA256

c26dd8fda497d1db213e4e20009b20707c008ef36c88934e3db19b5230810754

SHA512

731feabbecf25f640e96357445aff366f6a8cd40b9ca6b0e7c478b6cb8a1f640e8762152023bd569fe2119f2405380ab0c1ba119e4be17165625502e84c9f920

SSDeep

24576:eJeofAq/jp98z3kiegV6eOeOe7OxmOocRLfzyFyT9O:UeofAaWkLK6eOeOe7OxmHcR1O

Size

1.19MB

Packer
  • PE: compiler: Microsoft Visual C/C++(2005)[-]
  • PE: linker: Microsoft Linker(8.0 or 11.0)[EXE32]
  • PE: overlay: AutoIt v3 compiled script(-)[-]
TrID
  • 59.5% (.CPL) Windows Control Panel Item (generic) (57583/11/19)
  • 13.5% (.SCR) Windows screen saver (13097/50/3)
  • 10.8% (.EXE) Win64 Executable (generic) (10523/12/4)
  • 5.2% (.EXE) Win16 NE executable (generic) (5038/12/1)
  • 4.6% (.EXE) Win32 Executable (generic) (4504/4/1)
Tags

ExifTool File Metadata

CharacterSet

Unicode

CodeSize

404.50KB

EntryPoint

0x53e3d

ExifToolVersionNumber

12.76

FileFlags

(none)

FileFlagsMask

0x003f

FileOs

Windows 32-bit

FileSize

1252 kB

FileSubtype

3

FileType

Win32 EXE

FileTypeExtension

exe

FileVersionNumber

0.0.0.0

ImageFileCharacteristics

No relocs, Executable, Large address aware, 32-bit

ImageVersion

0.0

InitializedDataSize

138.50KB

LanguageCode

English (British)

LinkerVersion

8.0

MachineType

Intel 386 or later, and compatibles

MimeType

application/octet-stream

ObjectFileType

Dynamic link library

OsVersion

4.0

PeType

PE32

ProductVersionNumber

0.0.0.0

Subsystem

Windows GUI

SubsystemVersion

4.0

UninitializedDataSize

0

Submissions

Published Name Source Country
autoit.bin web
N/A