MALICIOUS — 3ea98de8eb624a2bcab8a309c6f5e1f624243fe8d2397f03d3752c92db67c38e
MALICIOUS — 3ea98de8eb624a2bcab8a309c6f5e1f624243fe8d2397f03d3752c92db67c38e is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (87/100), attributed to the Nanocore family. 6 of 51 detection engines flagged it.
Identification
- SHA-256:
3ea98de8eb624a2bcab8a309c6f5e1f624243fe8d2397f03d3752c92db67c38e - SHA-1:
4cb34a2fe9d14938a6a7248b025e7e414c46289c - MD5:
7524e01313bbc7569f944bff65c5e735 - imphash:
f34d5f2d4577ed6d9ceec516c1f5a744 - ssdeep:
12288:Nwhy2iNECVXrvJ0OQx4FkOkw4lLdbJJuq+jXHYvItp2S:NwI1FVXrGOnTL4pZOowtp2S - TLSH:
T1054B128F505C53B3C9A23953FC43C4DDDA3B615BCDB42AC10646291A6099E1F0A6B8FB - Submitted as: 3ea98de8eb624a2bcab8a309c6f5e1f624243fe8d2397f03d3752c92db67c38e
- File type: pe · Size: 499712 bytes
- Verdict: malicious (87/100) · Family: Nanocore
Detections (6 of 51 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-sections:.text
- ClamAV (daily): Win.Dropper.Nanocore-9937382-0
- Microsoft Defender: Trojan:MSIL/AgentTesla.PDS!MTB
- Emsisoft (Emergency Kit): Trojan.Crypt
- Trellix Stinger (McAfee): AgentTesla-FDFG!7524E01313BB
- Kaspersky (KVRT): UDS:Trojan-PSW.MSIL.Agensla.gen
Why this verdict
The malicious score of 87/100 is the fusion of 2 weighted signals:
- ClamAV (daily) flagged Win.Dropper.Nanocore-9937382-0 (rule
Win.Dropper.Nanocore-9937382-0) - engine signal, weight 0.90, confidence 0.95 - Packing/obfuscation: high-entropy-sections:.text - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded domains
- dn.fi
- londonbikers.com
More Nanocore samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report