MALICIOUS — 2b2514c23f6720925a3ce33a5d4e1828fd0c2184a30e95d00f365642f3c70df0
MALICIOUS — 2b2514c23f6720925a3ce33a5d4e1828fd0c2184a30e95d00f365642f3c70df0 is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (86/100), attributed to the Berbew family. 3 of 52 detection engines flagged it.
Identification
- SHA-256:
2b2514c23f6720925a3ce33a5d4e1828fd0c2184a30e95d00f365642f3c70df0 - SHA-1:
a598058642fcfdc6dd89c55d14ad206a132cce36 - MD5:
0360788d01fee58e14edddb9b06adb70 - imphash:
c2a87fabf96470db507b2e6b43bd92eb - ssdeep:
1536:/Kt9UlrmDe5wjv1zVqXlbPjnb/TvDH7fzPujjjjjWul:StmmDDjvJklbPjnb/TvDH7fz5m - TLSH:
T18634287ABA2F4292CEA8532D347CBDCE94E0C0EC99764D2B4537E1619491593F0B80B9 - Submitted as: 2b2514c23f6720925a3ce33a5d4e1828fd0c2184a30e95d00f365642f3c70df0
- File type: pe · Size: 57344 bytes
- Verdict: malicious (86/100) · Family: Berbew
Detections (3 of 52 engines)
- ClamAV (daily): Win.Dropper.Berbew-9106192-0
- Microsoft Defender: Backdoor:Win32/Berbew!pz
- Kaspersky (KVRT): HEUR:Trojan-Proxy.Win32.Qukart.vho
Why this verdict
The malicious score of 86/100 is the fusion of 1 weighted signal:
- ClamAV (daily) flagged Win.Dropper.Berbew-9106192-0 (rule
Win.Dropper.Berbew-9106192-0) - engine signal, weight 0.90, confidence 0.95
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
More Berbew samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report