MALICIOUS — 13e58c3b5e45ff821184b68ec229eee463284b0b887cddf3b8bd955439a3a525.zip
MALICIOUS — 13e58c3b5e45ff821184b68ec229eee463284b0b887cddf3b8bd955439a3a525.zip is a zip sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (87/100), attributed to the Blacklisted family. 3 of 51 detection engines flagged it.
Identification
- SHA-256:
13e58c3b5e45ff821184b68ec229eee463284b0b887cddf3b8bd955439a3a525 - SHA-1:
4b26ec3efbbc82ac96af3cd833ace7f4eade2962 - MD5:
60aaf34bead6e7a56fb5fa4ccd552b4f - ssdeep:
786432:F0EvS8iMLEnT/YC41OXv8FpPoyouUf2U4OJl2aMSfu+RvDXJoLS28SVIKs+7rAfQ:F0Vdv4FvoRuU/RlFMS2qvDX2OSaKskyi - TLSH:
T1E47B33BCE464B33B3850A9129F994677F328735FC3A25074A6C2834D3844D2A7646EB7 - Submitted as: 13e58c3b5e45ff821184b68ec229eee463284b0b887cddf3b8bd955439a3a525.zip
- File type: zip · Size: 48586493 bytes
- Verdict: malicious (87/100) · Family: Blacklisted
Detections (3 of 51 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV feed: InterServer (malware): sigs.InterServer.net.HEX.Topline.blacklisted.domain.quantsa.ru.809.UNOFFICIAL
- Microsoft Defender: Trojan:HTML/Redirector.GFL!MSR
Why this verdict
The malicious score of 87/100 is the fusion of 2 weighted signals:
- ClamAV feed: InterServer (malware) flagged sigs.InterServer.net.HEX.Topline.blacklisted.domain.quantsa.ru.809.UNOFFICIAL (rule
sigs.InterServer.net.HEX.Topline.blacklisted.domain.quantsa.ru.809.UNOFFICIAL) - engine signal, weight 0.90, confidence 0.95 - Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Embedded domains
- z.ir
- 9c.br
- s.ca
- uttu.me
- df.sg
- eg.de
- xt.tk
- xf.de
- g.tk
- 9.jp
- 9.ly
- 2w.me
- b.su
- r.fi
- k.tw
- m.au
- f.pw
- u.ua
- 9.ca
File paths
- u:\pa
- T:\:\
- k:\pmd
- v:\3!
- O:\V,
- T:\Ht/
- U:\m
- b:\s
- n:\`4
- h:\tD
- R:\c(
- J:\Ck
- a:\L
- y:\tJ
- k:\h
- W:\Q,
- m:\^
More Blacklisted samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report