MALICIOUS — tsk_620e0a752abc4743.tmp
MALICIOUS — tsk_620e0a752abc4743.tmp is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (81/100), attributed to the Container family. 4 of 55 detection engines flagged it, exhibiting 3 ATT&CK techniques.
Identification
- SHA-256:
3e5ee620d7f1bc4966166066d01066cdcab8ad2f9b6831cf6c0224861635e7f2 - SHA-1:
7738309b06c768bc809fd05f3b8bdb1522a361be - MD5:
9c085c3c0c7ce90407eceab0c62f5708 - imphash:
3d4e8ff5092238a78668230754a4ded3 - ssdeep:
49152:2viYUtaivJlWSM0WXo7FhDGS6Yh2ewYAJpg7xmUzWc8UecQ3/fmmowkTOU333V:PgoDyS6Oy/+X333V - TLSH:
T1B1605BDE460B7716E775C304A925BF3F04F7E81712FB448882A6C92EC2D44A72A3166D - Submitted as: tsk_620e0a752abc4743.tmp
- File type: pe · Size: 3752960 bytes
- Verdict: malicious (81/100) · Family: Container
Detections (4 of 55 engines)
- capa (capabilities): capability:collection/keylog
- YARA: delivr.to detections: DLV_ISO_IMG_Container_Lure
- YARA: JPCERT/CC: JPCERT_HUILoader_PlugX_SideLoad
- YARA: Yara-Rules community: YR_AntiDebug_Checks
MITRE ATT&CK
Why this verdict
The malicious score of 81/100 is the fusion of 7 weighted signals:
- capture keystrokes (rule
capture keystrokes) - capa signal, weight 0.40, confidence 0.80 - YARA: delivr.to detections flagged DLV_ISO_IMG_Container_Lure (rule
DLV_ISO_IMG_Container_Lure) - engine signal, weight 0.35, confidence 0.70 - YARA: JPCERT/CC flagged JPCERT_HUILoader_PlugX_SideLoad (rule
JPCERT_HUILoader_PlugX_SideLoad) - engine signal, weight 0.35, confidence 0.70 - YARA: Yara-Rules community flagged YR_AntiDebug_Checks (rule
YR_AntiDebug_Checks) - engine signal, weight 0.35, confidence 0.70 - persist via registry run key (rule
persist via registry run key) - capa signal, weight 0.35, confidence 0.60 - Embedded network infrastructure: https://www.innosetup.com/, https://www.remobjects.com/ps - static signal, weight 0.35, confidence 0.60
- communicate over HTTP (rule
communicate over HTTP) - capa signal, weight 0.30, confidence 0.60
Dynamic analysis (windows)
0 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- none
Embedded URLs
- http://schemas.microsoft.com/SMI/2005/WindowsSettings
- https://www.innosetup.com/
- https://www.remobjects.com/ps
Embedded domains
- schemas.microsoft.com
- www.innosetup.com
- www.remobjects.com
File paths
- c:\directory
- C:\DobreProgramy\IS\!\issrc-{2026-06-03}-9999999999999999999999999-PWideChar\Components\ChaCha20.pas
- C:\DobreProgramy\IS\!\issrc-{2026-06-03}-9999999999999999999999999-PWideChar\IShashes\hashes.pas
- C:\DobreProgramy\IS\!\issrc-{2026-06-03}-9999999999999999999999999-PWideChar\IShashes\blake2b.pas
- C:\DobreProgramy\IS\!\issrc-{2026-06-03}-9999999999999999999999999-PWideChar\IShashes\sha3.pas
- C:\DobreProgramy\IS\!\issrc-{2026-06-03}-9999999999999999999999999-PWideChar\IShashes\blake2s.pas
More Container samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report