MALICIOUS — 1635ec04f069ccc8331d01fdf31132a4bc8f6fd3830ac94739df95ee093c555c
MALICIOUS — 1635ec04f069ccc8331d01fdf31132a4bc8f6fd3830ac94739df95ee093c555c is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (99/100), attributed to the Stuxnet family. 4 of 51 detection engines flagged it.
Identification
- SHA-256:
1635ec04f069ccc8331d01fdf31132a4bc8f6fd3830ac94739df95ee093c555c - SHA-1:
cb0793029c60c0bd059ff85de956619f7fdeb4fd - MD5:
f8153747bae8b4ae48837ee17172151e - imphash:
e479290b25b0e1240c9981c53a12abb9 - ssdeep:
384:GjBfuuPC3LNGL9BLKkVcr7mj3eSW0lhqaWd7pxW3KzMdYJLWd6jqdybI:mfuj3oLukV0mTeSJhm7p+KxLAmIybI - TLSH:
T1892C7C8990A9F314FAF2BFB41E59DC8C14E1B09632B52ED83151863F957A06B6827348 - Submitted as: 1635ec04f069ccc8331d01fdf31132a4bc8f6fd3830ac94739df95ee093c555c
- File type: pe · Size: 26616 bytes
- Verdict: malicious (99/100) · Family: Stuxnet
Detections (4 of 51 engines)
- ClamAV (daily): Win.Worm.Stuxnet-10
- Cyble Vision: Cyble Vision: Malicious
- Microsoft Defender: Trojan:WinNT/Stuxnet.A
- Emsisoft (Emergency Kit): Gen:Variant.Zusy.399041
Why this verdict
The malicious score of 99/100 is the fusion of 4 weighted signals:
- ClamAV (daily) flagged Win.Worm.Stuxnet-10 (rule
Win.Worm.Stuxnet-10) - engine signal, weight 0.90, confidence 0.95 - Cyble Vision flagged Cyble Vision: Malicious (rule
Cyble Vision: Malicious) - engine signal, weight 0.90, confidence 0.95 - Microsoft Defender flagged Trojan:WinNT/Stuxnet.A (rule
Trojan:WinNT/Stuxnet.A) - engine signal, weight 0.55, confidence 0.85 - Emsisoft (Emergency Kit) flagged Gen:Variant.Zusy.399041 (rule
Gen:Variant.Zusy.399041) - engine signal, weight 0.55, confidence 0.85
Dynamic analysis (windows)
1 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- none
Embedded URLs
- http://crl.verisign.com/tss-ca.crl0
- https://www.verisign.com/rpa
- https://www.verisign.com/rpa01
- http://crl.verisign.com/pca3.crl0
- http://CSC3-2004-crl.verisign.com/CSC3-2004.crl0D
- https://www.verisign.com/rpa0
Embedded domains
- crl.verisign.com
- www.verisign.com
- crl.microsoft.com
- csc3-2004-crl.verisign.com
More Stuxnet samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report