SUSPICIOUS — 3b93f0b2a1c1ef8234925dadefd46ec98f5bc05437e895398239631383542f6a
SUSPICIOUS — 3b93f0b2a1c1ef8234925dadefd46ec98f5bc05437e895398239631383542f6a is a pe sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (49/100). 4 of 55 detection engines flagged it.
Identification
- SHA-256:
3b93f0b2a1c1ef8234925dadefd46ec98f5bc05437e895398239631383542f6a - SHA-1:
5f61899adb89e83be1d370299d508f5f587fc664 - MD5:
9ea7165fb15b5a18270bbc49a23788df - imphash:
08ce2bb5c289c22487015109b09aeba3 - ssdeep:
196608:0zEd4N5mzjtgIOiBh9vA8ShGOs2gqQ342tsuMoUOGJ:0zEdRzjtgI3BXvAhGOrgZ42SfVOc - TLSH:
T1956833E7DC30A08BECEA485D553F1E8D98FEE80E722E592D80C6D4874852C5B1BB6C15 - Submitted as: 3b93f0b2a1c1ef8234925dadefd46ec98f5bc05437e895398239631383542f6a
- File type: pe · Size: 7643668 bytes
- Verdict: suspicious (49/100)
Detections (4 of 55 engines)
- MalwareAnalyser heuristics (entropy/packer): Themida/VMProtect
- Detect It Easy (packer/type): DIE:Themida/Winlicense
- Microsoft Defender: Trojan:Win32/Wacatac.B!ml
- Kaspersky (KVRT): VHO:Trojan.MSIL.Inject.gen
Why this verdict
The suspicious score of 49/100 is the fusion of 3 weighted signals:
- Detect It Easy (packer/type) flagged DIE:Themida/Winlicense (rule
DIE:Themida/Winlicense) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: https://d.symcb.com/rpa0, http://s.symcb.com/universal-root.crl0, https://d.symcb.com/rpa0@ - static signal, weight 0.35, confidence 0.60
- Packing/obfuscation: Themida/VMProtect, high-entropy-sections: , ,.boot, Themida/Winlicense - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://d.symcb.com/rpa0
- http://s.symcb.com/universal-root.crl0
- https://d.symcb.com/rpa0@
- http://ts-crl.ws.symantec.com/sha256-tss-ca.crl0
- http://ts-aia.ws.symantec.com/sha256-tss-ca.cer0
Embedded domains
- d.symcb.com
- s.symcb.com
- ts-crl.ws.symantec.com
- ts-aia.ws.symantec.com
- pki-crl.symauth.com
File paths
- p:\u7
- W:\@b
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report