CLEAN — WinWrapIDE.exe
CLEAN — WinWrapIDE.exe is a pe sample analyzed by MalwareAnalyzer by Cyble with a clean verdict (25/100). 1 of 55 detection engines flagged it.
Identification
- SHA-256:
0562c588997fa9961d55c6ab1db2656344324bca8db9ea7b64fe309132b2399f - SHA-1:
12529884496d55a7a9aa96765af4ea4257499fec - MD5:
bfb25270df49bb391193a59281d5ffcf - imphash:
833845c0ff2930ce3e014a3b8d611e32 - ssdeep:
3072:Kx1YqpVm6ex62j/HB+PBFxQHQrk2PTjluzAU2TbrAVqPryEO4+ZCcr4:KX46eo2j/HI7QGk2PTjsXVq2pZCcr4 - TLSH:
T1C046749980171681D6F7D9A0BE3409CC8979F49E2071B99C1F43D0BF31E2E7B94A1C9A - Submitted as: WinWrapIDE.exe
- File type: pe · Size: 313512 bytes
- Verdict: clean (25/100)
Detections (1 of 55 engines)
- YARA: Yara-Rules community: YR_AntiDebug_Checks
Why this verdict
The clean score of 25/100 is the fusion of 1 weighted signal:
- YARA: Yara-Rules community flagged YR_AntiDebug_Checks (rule
YR_AntiDebug_Checks) - engine signal, weight 0.35, confidence 0.70
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://www.digicert.com/CPS0
- http://crl3.digicert.com/sha2-assured-cs-g1.crl05
- http://crl4.digicert.com/sha2-assured-cs-g1.crl0L
- http://www.digicert.com/ssl-cps-repository.htm0
Embedded domains
- cacerts.digicert.com
- crl4.digicert.com
- crl3.digicert.com
- www.digicert.com
- www.winwrap.com
File paths
- D:\Workroom\views\Sub_Win64_Backend_Build_VS2017\cs_work2\VC9_64\release\etc\WinWrapIDE.pdb
- E:\DEV\ww9.20\MSVC2005\WWB\
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report