CLEAN — winws.exe
CLEAN — winws.exe is a pe sample analyzed by MalwareAnalyzer by Cyble with a clean verdict (25/100). 1 of 55 detection engines flagged it.
Identification
- SHA-256:
affb4f69d2ea302a7abccd5325d81826e140ddae014f1e070bc4a6c0dd555188 - SHA-1:
e660246d9b5de531d8c6ed563919d2690f47d209 - MD5:
d498e19bc7a79dd1efcb6b928cbe9909 - imphash:
a4b140fe839e54b299bb799d5e755765 - ssdeep:
3072:llblEpda/1ZqNUckRoAHzGDIAaSLECf6CuWhs/JSDxIcdDFth2zp:l/TY5czliX5mhYIcdptyp - TLSH:
T158428CB203972362DEF2EE989058CCAE1027758450714FEE8247D76C81E82B7A6F55F4 - Submitted as: winws.exe
- File type: pe · Size: 203776 bytes
- Verdict: clean (25/100)
Detections (1 of 55 engines)
- YARA: Stratosphere IPS: STRATO_Malicious_UserAgent
Why this verdict
The clean score of 25/100 is the fusion of 1 weighted signal:
- YARA: Stratosphere IPS flagged STRATO_Malicious_UserAgent (rule
STRATO_Malicious_UserAgent) - engine signal, weight 0.35, confidence 0.70
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded domains
- www.iana.org
- www.microsoft.com
Embedded IP addresses
- 10.255.255.255
- 192.168.255.255
- 172.31.255.255
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report