SUSPICIOUS — 7z26.02-zstd-x64.exe
SUSPICIOUS — 7z26.02-zstd-x64.exe is a pe sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (39/100), attributed to the Container family. 1 of 56 detection engines flagged it.
Identification
- SHA-256:
22dc4608d911d7c831437b969db66a42d0477cd3f5d93987cae9f59774857fc1 - SHA-1:
27f24ab0d83b42981fb8067d6a30f0ed09f169da - MD5:
05ac2dda58ff183804d37a7871b458bd - imphash:
a482c03342181f767050d786be7b8b5f - ssdeep:
49152:AvRBV1SqSp7sCMMkWYqt3Fy+ho4jtp5Q4i+PljeBMJTl3/bsu213B98w8QT:gBDNSp7dM+hoM54AVeiZEOS - TLSH:
T19F5F335A4217B482E7B2CAE0AC0141FC943375ED2432E81CA90BC6ED76E4973C6F59E5 - Submitted as: 7z26.02-zstd-x64.exe
- File type: pe · Size: 3344024 bytes
- Verdict: suspicious (39/100) · Family: Container
Detections (1 of 56 engines)
- YARA: delivr.to detections: DLV_ISO_IMG_Container_Lure
Why this verdict
The suspicious score of 39/100 is the fusion of 1 weighted signal:
- YARA: delivr.to detections flagged DLV_ISO_IMG_Container_Lure (rule
DLV_ISO_IMG_Container_Lure) - engine signal, weight 0.55, confidence 0.70
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- http://schemas.microsoft.com/SMI/2005/WindowsSettings
Embedded domains
- schemas.microsoft.com
- jg.us
File paths
- Y:\7`
- f:\B
More Container samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report