SUSPICIOUS — 1916bcfd18745e4980bec361aaf8c048242038cd5c8520d4564726780795d5d2
SUSPICIOUS — 1916bcfd18745e4980bec361aaf8c048242038cd5c8520d4564726780795d5d2 is a pe sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (55/100), attributed to the 0day family. 2 of 55 detection engines flagged it.
Identification
- SHA-256:
1916bcfd18745e4980bec361aaf8c048242038cd5c8520d4564726780795d5d2 - SHA-1:
93f8d1b93d0364b823101731649c59616f48e829 - MD5:
1fee6a04e04efe6d6994f3eeb35e2837 - imphash:
0ba39925cc55187335fdc1a6bb929fef - ssdeep:
49152:ztj2wQbIyDZC+OzNK2RrpfcShnsEgk5zboZ+zSudKI:h+5Q+SRrpfcShns3CwaRKI - TLSH:
T1AE6163723076A114F6F9BDA4C4BD542C8163697AB1A467CE460F208122FD2E3D5FBC4A - Submitted as: 1916bcfd18745e4980bec361aaf8c048242038cd5c8520d4564726780795d5d2
- File type: pe · Size: 3889716 bytes
- Verdict: suspicious (55/100) · Family: 0day
Detections (2 of 55 engines)
- YARA: InQuest Labs: CVE_2018_4878_0day_ITW
- LIEF (executable format parser): lief:invalid-authenticode
Why this verdict
The suspicious score of 55/100 is the fusion of 3 weighted signals:
- YARA: InQuest Labs flagged CVE_2018_4878_0day_ITW (rule
CVE_2018_4878_0day_ITW) - engine signal, weight 0.35, confidence 0.70 - LIEF (executable format parser) flagged lief:invalid-authenticode (rule
lief:invalid-authenticode) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: https://chromium.googlesource.com/a/native_client/pnacl-clang.git, https://chromium.googlesource.com/a/native_client/pnacl-llvm.git - static signal, weight 0.35, confidence 0.60
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://www.digicert.com/CPS0
- http://crl3.digicert.com/sha2-assured-cs-g1.crl05
- http://crl4.digicert.com/sha2-assured-cs-g1.crl0L
- http://crl3.digicert.com/sha2-assured-ts.crl02
- http://crl4.digicert.com/sha2-assured-ts.crl0
- https://chromium.googlesource.com/a/native_client/pnacl-clang.git
- https://chromium.googlesource.com/a/native_client/pnacl-llvm.git
Embedded domains
- cacerts.digicert.com
- crl4.digicert.com
- crl3.digicert.com
- www.digicert.com
- enter.cc
- core.cc
- dispatcher.cc
- blink.net
- thunks.cc
- node.cc
- chromium.googlesource.com
File paths
- c:\jenkins\workspace\8-2-build-windows-amd64-cygwin\jdk8u281\880\build\windows-amd64\jdk\objs\policytool_objs\policytool.pdb
- C:\Program
- R:\Sg
More 0day samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report