MALICIOUS — 22982f883affbcf175c5448f891fd5c90e4dd507c4ffd42e7fedd7339dde7ed6
MALICIOUS — 22982f883affbcf175c5448f891fd5c90e4dd507c4ffd42e7fedd7339dde7ed6 is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (89/100). 1 of 52 detection engines flagged it.
Identification
- SHA-256:
22982f883affbcf175c5448f891fd5c90e4dd507c4ffd42e7fedd7339dde7ed6 - SHA-1:
be8fec91918f37abbd31fe269cff6bcfa225d6a4 - MD5:
37b0d00010f4edcbab196b695f14229b - imphash:
c452b207dc65baf117f06ff09c8fad54 - ssdeep:
6144:8NhHyz3IpNnYOEJUdmLJDBKJGE/iBcjSagsvINZcsFsgLPE/hnNB6S:0UzKNpEqdmLT0pKBZagUa3a6 - TLSH:
T1BB5E326E4F5A59A2EC95A1CE3008D43DB0D1FAD5623A554ACF91C0AF05BF2136CB0DAC - Submitted as: 22982f883affbcf175c5448f891fd5c90e4dd507c4ffd42e7fedd7339dde7ed6
- File type: pe · Size: 2969888 bytes
- Verdict: malicious (89/100)
Detections (1 of 52 engines)
- ClamAV (daily): Win.Malware.Genpack-9950982-0
Why this verdict
The malicious score of 89/100 is the fusion of 2 weighted signals:
- ClamAV (daily) flagged Win.Malware.Genpack-9950982-0 (rule
Win.Malware.Genpack-9950982-0) - engine signal, weight 0.90, confidence 0.95 - Embedded network infrastructure: http://www.gnu.org/software/coreutils/, http://translationproject.org/team/, http://gnu.org/licenses/gpl.html - static signal, weight 0.35, confidence 0.60
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- http://www.gnu.org/software/coreutils/
- http://translationproject.org/team/
- http://gnu.org/licenses/gpl.html
- http://www.gnu.org/gethelp/
Embedded domains
- www.gnu.org
- translationproject.org
- gnu.org
- cygwin.com
- acrobat.com
File paths
- C:\Users\a.monaldo\Desktop
- C:\Users\a.monaldo\AppData\Local\Microsoft\Windows
- c:\windows\system32\imageres.dll
- c:\program
- c:\windows\system32\ntshrui.dll
- c:\install.exe
- c:\windows\explorer.exe
- c:\windows\system32\tsworkspace.dll
- c:\windows\system32\wmploc.dll
- c:\windows\system32\intl.cpl
- c:\windows\system32\icardres.dll
- c:\windows\branding\shellbrd\shellbrd.dll
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report