CLEAN — 1fc6fba593cb7e5d292b3fa7aa96c72dff122364676b3e1ccdc184234df8df72
CLEAN — 1fc6fba593cb7e5d292b3fa7aa96c72dff122364676b3e1ccdc184234df8df72 is a pe sample analyzed by MalwareAnalyzer by Cyble with a clean verdict (25/100). 1 of 52 detection engines flagged it.
Identification
- SHA-256:
1fc6fba593cb7e5d292b3fa7aa96c72dff122364676b3e1ccdc184234df8df72 - SHA-1:
e11911701122829540c2847ae5efeab15110a111 - MD5:
ef0e975544efa2813998bd64716800a8 - imphash:
f79678e419d25c2abd0aba317c4d3b42 - ssdeep:
6144:TLYO3HdikfZbM1EIwBw1nwuam3w9nwJzTjAOc2+XXYCrh+Oh:fisbM1EIwBw1nwKTjr+nYIh+Oh - TLSH:
T163472B9946081B33D6374E941D70FE2F10E2E4F51ABD38081A83D63E76A3CCB9855A79 - Submitted as: 1fc6fba593cb7e5d292b3fa7aa96c72dff122364676b3e1ccdc184234df8df72
- File type: pe · Size: 343896 bytes
- Verdict: clean (25/100)
Detections (1 of 52 engines)
- YARA: Yara-Rules community: YR_AntiDebug_Checks
Why this verdict
The clean score of 25/100 is the fusion of 1 weighted signal:
- YARA: Yara-Rules community flagged YR_AntiDebug_Checks (rule
YR_AntiDebug_Checks) - engine signal, weight 0.35, confidence 0.70
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- http://schemas.microsoft.com/SMI/2005/WindowsSettings
- https://www.microsoft.com
- http://www.microsoft.com/pki/certs/MicRooCerAut_2010-06-23.crt0
Embedded domains
- logging.cc
- schemas.microsoft.com
- www.microsoft.com
- crl.microsoft.com
- corp.microsoft.com
Registry keys
- HKLM\Software\Microsoft\EdgeUpdate\
- HKCU\Software\Microsoft\EdgeUpdate\
- HKLM\Software\Microsoft\Windows\CurrentVersion\MicrosoftEdge
- HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\Microsoft
- HKLM\Software\Microsoft\EdgeUpdateDev\
- HKLM\Software\Policies\Microsoft\EdgeUpdate\
- HKCU\Software\Microsoft\EdgeUpdate\ClientState\
- HKLM\Software\Microsoft\EdgeUpdate\ClientState\
- HKLM\Software\Microsoft\EdgeUpdate\ClientStateMedium\
File paths
- T:\:d:l:t:
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report