MALICIOUS — 13f8cfe4648b807a0cbddd653c75254b60d1951e11e715f4e5a1a2c9ab29360b.exe
MALICIOUS — 13f8cfe4648b807a0cbddd653c75254b60d1951e11e715f4e5a1a2c9ab29360b.exe is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (90/100). 3 of 55 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
13f8cfe4648b807a0cbddd653c75254b60d1951e11e715f4e5a1a2c9ab29360b - SHA-1:
5c1ffa4074937594b8fddd76720d7943f4f5ad55 - MD5:
130176db1b368a8290ebda3ce17db7c8 - imphash:
f34d5f2d4577ed6d9ceec516c1f5a744 - ssdeep:
1536:Mtypl44jzbHI5kLP+VVVVVVVVVVVVVVVVVVVVVVVVVC7Ky7ynD:3rfukLdOyWD - TLSH:
T18B38C6B90DF47357D8E46C81ACA0C0DF4DC5D4199A69F312272BB0066A13DDB8C2A1FA - Submitted as: 13f8cfe4648b807a0cbddd653c75254b60d1951e11e715f4e5a1a2c9ab29360b.exe
- File type: pe · Size: 81688 bytes
- Verdict: malicious (90/100)
Source: MalwareBazaar · first seen 2026-08-02T00:00:00.000Z · SHA-256 verified
Detections (3 of 55 engines)
- capa (capabilities): capability:collection/keylog
- Hash: abuse.ch ThreatFox: known-malicious-hash
- Kaspersky (KVRT): not-a-virus:RemoteAdmin.MSIL.ConnectWise.d
MITRE ATT&CK
Why this verdict
The malicious score of 90/100 is the fusion of 2 weighted signals:
- Hash: abuse.ch ThreatFox flagged known-malicious-hash (rule
known-malicious-hash) - engine signal, weight 0.90, confidence 0.95 - capture keystrokes (rule
capture keystrokes) - capa signal, weight 0.40, confidence 0.80
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- http://www.digicert.com/CPS0
Embedded domains
- cacerts.digicert.com
- crl3.digicert.com
- crl4.digicert.com
- www.digicert.com
File paths
- C:\builds\cc\cwcontrol\Product\WindowsFileManager\obj\Release\ScreenConnect.WindowsFileManager.pdb
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report