MALICIOUS — 117e1f48056e7e9902a7ea734acc2b5cf06d717ff4172a9813cb309afaad4cff
MALICIOUS — 117e1f48056e7e9902a7ea734acc2b5cf06d717ff4172a9813cb309afaad4cff is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (98/100), attributed to the Crypted family. 4 of 56 detection engines flagged it.
Identification
- SHA-256:
117e1f48056e7e9902a7ea734acc2b5cf06d717ff4172a9813cb309afaad4cff - SHA-1:
d60604c1d3445ac6cdac9215b634979dbc4b71f6 - MD5:
f171ad2b8314487428b63f9ca7753b24 - imphash:
c2a87fabf96470db507b2e6b43bd92eb - ssdeep:
6144:9BS/x+yLf9rf8xsZNWrJfED9AICf8xs15Ol5GMeKf8xsZNWrJfED9AICf8xs:9BS/xzfm4YJlSs5jP4YJlS - TLSH:
T1E64A3952E6513F8ACEE0A7D9C089F98E46E3005F31F441356A5EEB9249177AFBC08478 - Submitted as: 117e1f48056e7e9902a7ea734acc2b5cf06d717ff4172a9813cb309afaad4cff
- File type: pe · Size: 458752 bytes
- Verdict: malicious (98/100) · Family: Crypted
Detections (4 of 56 engines)
- ClamAV (daily): Win.Trojan.Crypted-29
- Microsoft Defender: Backdoor:Win32/Berbew!pz
- Emsisoft (Emergency Kit): Generic.Dacic.1.Backdoor.Hangup.A.413BFEFD
- Kaspersky (KVRT): Trojan-Proxy.Win32.Qukart.vjh
Why this verdict
The malicious score of 98/100 is the fusion of 4 weighted signals:
- ClamAV (daily) flagged Win.Trojan.Crypted-29 (rule
Win.Trojan.Crypted-29) - engine signal, weight 0.90, confidence 0.95 - Microsoft Defender flagged Backdoor:Win32/Berbew!pz (rule
Backdoor:Win32/Berbew!pz) - engine signal, weight 0.55, confidence 0.85 - Emsisoft (Emergency Kit) flagged Generic.Dacic.1.Backdoor.Hangup.A.413BFEFD (rule
Generic.Dacic.1.Backdoor.Hangup.A.413BFEFD) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged Trojan-Proxy.Win32.Qukart.vjh (rule
Trojan-Proxy.Win32.Qukart.vjh) - engine signal, weight 0.55, confidence 0.85
Dynamic analysis (windows)
0 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- none
More Crypted samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report