MALICIOUS — 2889d0fb016f38cbb94eb44009bd8d1378f48f4e8d9c20526d39424a148654e6
MALICIOUS — 2889d0fb016f38cbb94eb44009bd8d1378f48f4e8d9c20526d39424a148654e6 is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (86/100), attributed to the Crypted family. 4 of 52 detection engines flagged it.
Identification
- SHA-256:
2889d0fb016f38cbb94eb44009bd8d1378f48f4e8d9c20526d39424a148654e6 - SHA-1:
1a459b70ae248877cec03bb8f5feafdc81c3f9e7 - MD5:
f6f5c701945f6dae55026d5f287ea490 - imphash:
95e6f8741083e0c7d9a63d45e2472360 - ssdeep:
1536:VkyxDrBuJ76xZ0w4652ETj1ijD7oqLfhvEinPU2OlWmHm7:3xDrBuJRTfhvEil7 - TLSH:
T19D3A4A9132A1B03FDF889143611A655C8CD1C87344F02D9A2666C5ED67BE2DB8A3FBC4 - Submitted as: 2889d0fb016f38cbb94eb44009bd8d1378f48f4e8d9c20526d39424a148654e6
- File type: pe · Size: 93184 bytes
- Verdict: malicious (86/100) · Family: Crypted
Detections (4 of 52 engines)
- ClamAV (daily): Win.Trojan.Crypted-29
- Microsoft Defender: Backdoor:Win32/Berbew!pz
- Emsisoft (Emergency Kit): Backdoor.Hangup.B
- Kaspersky (KVRT): Trojan-Spy.Win32.Qukart.af
Why this verdict
The malicious score of 86/100 is the fusion of 1 weighted signal:
- ClamAV (daily) flagged Win.Trojan.Crypted-29 (rule
Win.Trojan.Crypted-29) - engine signal, weight 0.90, confidence 0.95
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
More Crypted samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report