MALICIOUS — 1c8c488e0ab1941ad849da14bf9470efdd0391ff20fca23c805621fd85c61a26
MALICIOUS — 1c8c488e0ab1941ad849da14bf9470efdd0391ff20fca23c805621fd85c61a26 is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (89/100), attributed to the Sality family. 4 of 51 detection engines flagged it.
Identification
- SHA-256:
1c8c488e0ab1941ad849da14bf9470efdd0391ff20fca23c805621fd85c61a26 - SHA-1:
810552d026ab036f4e69d8f060c0d687b4e9d7e9 - MD5:
b118f584a29557ccec81cb98f3a523de - imphash:
5f80a6d45ff0d35e7468ce2645c54bd5 - ssdeep:
384:Wo9wB7iYpk7i/1OZu8F5SZJD3WyO80Sl:WR7iYpk2z5DJ4S - TLSH:
T1AD2DB58DA7B29984C975DAC134E0649C20733661376E440CBBF7DA6E17F2467683806F - Submitted as: 1c8c488e0ab1941ad849da14bf9470efdd0391ff20fca23c805621fd85c61a26
- File type: pe · Size: 28672 bytes
- Verdict: malicious (89/100) · Family: Sality
Detections (4 of 51 engines)
- ClamAV (daily): Win.Virus.Sality-6799858-0
- YARA: JPCERT/CC: JPCERT_HUILoader_PlugX_SideLoad
- Kaspersky (KVRT): UDS:DangerousObject.Multi.Generic
- Emsisoft (Emergency Kit): Gen:Variant.Tedy.19524
Why this verdict
The malicious score of 89/100 is the fusion of 2 weighted signals:
- ClamAV (daily) flagged Win.Virus.Sality-6799858-0 (rule
Win.Virus.Sality-6799858-0) - engine signal, weight 0.90, confidence 0.95 - YARA: JPCERT/CC flagged JPCERT_HUILoader_PlugX_SideLoad (rule
JPCERT_HUILoader_PlugX_SideLoad) - engine signal, weight 0.35, confidence 0.70
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
File paths
- C:\Program
More Sality samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report