CLEAN — 11472fb3aa3d893ced6ec68987595bb968542e2852c0d22898367048305d2bb6
CLEAN — 11472fb3aa3d893ced6ec68987595bb968542e2852c0d22898367048305d2bb6 is a pe sample analyzed by MalwareAnalyzer by Cyble with a clean verdict (25/100). 1 of 52 detection engines flagged it.
Identification
- SHA-256:
11472fb3aa3d893ced6ec68987595bb968542e2852c0d22898367048305d2bb6 - SHA-1:
193a6602ef77853fe051ba0019f2b70131ab7d45 - MD5:
4319c0ad9031ed944d9e48b672ba717e - imphash:
d41d8cd98f00b204e9800998ecf8427e - ssdeep:
1536:r96ZJwk1oO+huJs4HN0Auo7G+DKSOa2W2VO3GGe9rHU4n:0MFCHV1G+DKSOa2Wque9o4n - TLSH:
T18D3929CEA111271FD2736D367A50CEAF509031E9A1B8B69D8D414A727031E2BEC391D7 - Submitted as: 11472fb3aa3d893ced6ec68987595bb968542e2852c0d22898367048305d2bb6
- File type: pe · Size: 85848 bytes
- Verdict: clean (25/100)
Detections (1 of 52 engines)
- LIEF (executable format parser): lief:invalid-authenticode
Why this verdict
The clean score of 25/100 is the fusion of 1 weighted signal:
- LIEF (executable format parser) flagged lief:invalid-authenticode (rule
lief:invalid-authenticode) - engine signal, weight 0.35, confidence 0.70
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- http://www.microsoft.com/pki/certs/CSPCA.crt0
- http://www.microsoft.com/pki/certs/tspca.crt0
Embedded domains
- crl.microsoft.com
- www.microsoft.com
File paths
- C:\Loggers\MyLogger.dll;OutputAsHTML
- C:\My.dll
- C:\Logger.dll
- f:\dd\tools\devdiv\FinalPublicKey.snk
- f:\dd\vsproject\xmake\XMakeCommandLine\objr\amd64\MSBuild.pdb
- C:\\Documents
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report