CLEAN — 1a2b10c51dfadf67161fb7d8854850d73f352563bf5c480a5d56af90c250e9d2
CLEAN — 1a2b10c51dfadf67161fb7d8854850d73f352563bf5c480a5d56af90c250e9d2 is a pe sample analyzed by MalwareAnalyzer by Cyble with a clean verdict (25/100). 3 of 55 detection engines flagged it.
Identification
- SHA-256:
1a2b10c51dfadf67161fb7d8854850d73f352563bf5c480a5d56af90c250e9d2 - SHA-1:
3289989a13bc831f729c488b46b96de72b6c5a6d - MD5:
be8eb92806e4f983dc8b56f3d5bebcbe - imphash:
fcf1390e9ce472c7270447fc5c61a0c1 - ssdeep:
49152:eLBOBfJXAvswf2Ui0dr1hGU/AIEBdt+DlWXS5csu194wuJTBc1GaD7mb2KPD:eLBOBfKvPf/bJ/AIEBdtA5EugDDyb2i - TLSH:
T1185E23CC5264A296DBB3DE186C407D2E505170DA50BA7CE8069BD82F37A2C4FE4623D7 - Submitted as: 1a2b10c51dfadf67161fb7d8854850d73f352563bf5c480a5d56af90c250e9d2
- File type: pe · Size: 2895360 bytes
- Verdict: clean (25/100)
Detections (3 of 55 engines)
- YARA: Trellix/McAfee ATR: ATR_Conti_Ransomware
- Microsoft Defender: flagged
- Kaspersky (KVRT): UDS:Trojan.Win32.Cometer.gen
Why this verdict
The clean score of 25/100 is the fusion of 1 weighted signal:
- YARA: Trellix/McAfee ATR flagged ATR_Conti_Ransomware (rule
ATR_Conti_Ransomware) - engine signal, weight 0.35, confidence 0.70
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- http://schemas.microsoft.com/SMI/2005/WindowsSettings
Embedded domains
- to9.uk
- schemas.microsoft.com
- i.tk
- t4.cc
File paths
- D:\Projects\WinRAR\sfx\setup\build\sfxrar32\Release\sfxrar.pdb
- L:\:
- A:\/
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report