SUSPICIOUS — 014989efefb4bca12dcc195dc3a203a9778015a5321ca176eaa48ce541f8e325
SUSPICIOUS — 014989efefb4bca12dcc195dc3a203a9778015a5321ca176eaa48ce541f8e325 is a pe sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (40/100). 1 of 52 detection engines flagged it.
Identification
- SHA-256:
014989efefb4bca12dcc195dc3a203a9778015a5321ca176eaa48ce541f8e325 - SHA-1:
4faa5414c2e1492d8dab1c822b9743395676c032 - MD5:
d0a35031c836cbf90bba796fe5ad2a79 - imphash:
a206b31ff655ee9dcce420c19bc96350 - ssdeep:
3072:+8luTZOyp/uTZOockAQckAIDpAPfKrss1yyKrss1yAZDvYbNDzVYTC5wFKHHSRF:+FVREVGkAzkAZqrEdrEAZUdwFjNNFu - TLSH:
T1DD597DD193A93A54CDEE7F1AAE92621C31CBD370B119CC00D8AB60692EE72734D2355D - Submitted as: 014989efefb4bca12dcc195dc3a203a9778015a5321ca176eaa48ce541f8e325
- File type: pe · Size: 1941504 bytes
- Verdict: suspicious (40/100)
Detections (1 of 52 engines)
- LIEF (executable format parser): lief:invalid-authenticode
Why this verdict
The suspicious score of 40/100 is the fusion of 2 weighted signals:
- LIEF (executable format parser) flagged lief:invalid-authenticode (rule
lief:invalid-authenticode) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: 6.0.1.0 - static signal, weight 0.35, confidence 0.60
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- http://schemas.microsoft.com/SMI/2005/WindowsSettings
- http://www.microsoft.com/pki/certs/MicrosoftTimeStampPCA.crt0
- http://www.microsoft.com/pki/certs/MicCodSigPCA_08-31-2010.crt0
- http://crl.microsoft.com/pki/crl/products/microsoftrootcert.crl0T
- http://office.microsoft.com
- http://www.microsoft.com/pki/certs/MicRooCerAut_2010-06-23.crt0
- http://www.microsoft.com/pki/certs/MicTimStaPCA_2010-07-01.crt0
Embedded domains
- schemas.microsoft.com
- crl.microsoft.com
- www.microsoft.com
- office.microsoft.com
Embedded IP addresses
- 6.0.1.0
File paths
- F:\Office\Target\x86\ship\postc2r\x-none\winword.pdb
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report