MALICIOUS — 2877a6c60969fcea3e5324acaf28769735fa3d7ed142f93a7ee4962688055543
MALICIOUS — 2877a6c60969fcea3e5324acaf28769735fa3d7ed142f93a7ee4962688055543 is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (87/100), attributed to the Vobfus family. 4 of 55 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
2877a6c60969fcea3e5324acaf28769735fa3d7ed142f93a7ee4962688055543 - SHA-1:
105ea5d8f357d64ed71e6a19ef5dcab2a088b162 - MD5:
ff31e99f84e5367718d13ceb71e5a027 - imphash:
4dce2fa3d2a90cbd5604eb74159c77ab - ssdeep:
768:LaLCcUwTRMmXkCke1/B/uBJK0KVMfsRyRFBoytfDN/SBnGHbAEUDEO:LqM11eZNbirbAuO - TLSH:
T16738E79B1228E543D0FAE25F1F443FDD04CE8686533B596C396F080E9AC4AB755B8A1C - Submitted as: 2877a6c60969fcea3e5324acaf28769735fa3d7ed142f93a7ee4962688055543
- File type: pe · Size: 81920 bytes
- Verdict: malicious (87/100) · Family: Vobfus
Detections (4 of 55 engines)
- ClamAV (daily): Win.Worm.Vobfus-9805080-0
- Microsoft Defender: Worm:Win32/Vobfus.F
- Emsisoft (Emergency Kit): Gen:Trojan.Chinky.2
- Kaspersky (KVRT): Worm.Win32.Vobfus.exhw
MITRE ATT&CK
Why this verdict
The malicious score of 87/100 is the fusion of 2 weighted signals:
- ClamAV (daily) flagged Win.Worm.Vobfus-9805080-0 (rule
Win.Worm.Vobfus-9805080-0) - engine signal, weight 0.90, confidence 0.95 - enumerate processes (rule
enumerate processes) - capa signal, weight 0.20, confidence 0.60
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
More Vobfus samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report