MALICIOUS — 1f1f86689f6caab069cbf0e68a24862df392ed33a790fbff04d9cf9d11b4447b.bin
MALICIOUS — 1f1f86689f6caab069cbf0e68a24862df392ed33a790fbff04d9cf9d11b4447b.bin is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (91/100), attributed to the Porcupine family. 6 of 52 detection engines flagged it.
Identification
- SHA-256:
1f1f86689f6caab069cbf0e68a24862df392ed33a790fbff04d9cf9d11b4447b - SHA-1:
b44056e9a38ebba8c63d993310a3d60f757e33ad - MD5:
3ac6135c314bf560a6040fa74cc36f5a - imphash:
f34d5f2d4577ed6d9ceec516c1f5a744 - ssdeep:
24576:UERilrETNRZ2Il+VO4itrLRJDM0gFOjT2Hf/UldQPjogq:bYGl+FitRR1CD/Uc8gq - TLSH:
T16555129E7A7D0D02D8F3C434798004ACA8791AD714AC72DACB3628D51BEFDB79424876 - Submitted as: 1f1f86689f6caab069cbf0e68a24862df392ed33a790fbff04d9cf9d11b4447b.bin
- File type: pe · Size: 1307136 bytes
- Verdict: malicious (91/100) · Family: Porcupine
Source: MalShare · first seen 2026-08-13T19:45:53.378Z · SHA-256 verified
Detections (6 of 52 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-sections:.text
- ClamAV feed: SaneSecurity foxhole_generic: Porcupine.Malware.58887.UNOFFICIAL
- YARA: Trellix/McAfee ATR: ATR_LockBit_Ransomware
- Microsoft Defender: Trojan:MSIL/Noon.ABSN!MTB
- Emsisoft (Emergency Kit): Trojan.GenericKD.81092911
- Kaspersky (KVRT): HEUR:Trojan-Spy.MSIL.Noon.gen
Why this verdict
The malicious score of 91/100 is the fusion of 3 weighted signals:
- ClamAV feed: SaneSecurity foxhole_generic flagged Porcupine.Malware.58887.UNOFFICIAL (rule
Porcupine.Malware.58887.UNOFFICIAL) - engine signal, weight 0.90, confidence 0.95 - YARA: Trellix/McAfee ATR flagged ATR_LockBit_Ransomware (rule
ATR_LockBit_Ransomware) - engine signal, weight 0.35, confidence 0.70 - Packing/obfuscation: high-entropy-sections:.text - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
More Porcupine samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report