MALICIOUS — GROK_24A6EC8EBF9C0867ED1C097F4A653B8D
MALICIOUS — GROK_24A6EC8EBF9C0867ED1C097F4A653B8D is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (100/100), attributed to the Fetrog family. 6 of 51 detection engines flagged it.
Identification
- SHA-256:
441f2a6775621af8c5d1ead7082e9573ad878bc90675ed55f86abfc8a9e8cc6f - SHA-1:
50b8f125ed33233a545a1aac3c9d4bb6aa34b48f - MD5:
24a6ec8ebf9c0867ed1c097f4a653b8d - imphash:
d8b4b3e994e78c3549d970d6b09456ba - ssdeep:
3072:wdWpskNQbkWD95SQcA0vWNc2gbDabSbosH4/h9:wdW/NCkU4QcA0ONc2YabKosH43 - TLSH:
T1493F6BD181163231C0FAFA587851EDADC897F86C50F81E8CA65AC46B90F8E3385F561E - Submitted as: GROK_24A6EC8EBF9C0867ED1C097F4A653B8D
- File type: pe · Size: 163840 bytes
- Verdict: malicious (100/100) · Family: Fetrog
Detections (6 of 51 engines)
- MalwareAnalyser heuristics (entropy/packer): Microsoft Linker
- ClamAV (daily): {MD5}bin.trojan.agent.7526.UNOFFICIAL
- Cyble Vision: Cyble Vision: Malicious
- Detect It Easy (packer/type): DIE:Microsoft Linker
- Microsoft Defender: Trojan:WinNT/Fetrog.A
- Emsisoft (Emergency Kit): Trojan.Agent.BHVJ
Why this verdict
The malicious score of 100/100 is the fusion of 6 weighted signals:
- ClamAV (daily) flagged {MD5}bin.trojan.agent.7526.UNOFFICIAL (rule
{MD5}bin.trojan.agent.7526.UNOFFICIAL) - engine signal, weight 0.90, confidence 0.95 - Cyble Vision flagged Cyble Vision: Malicious (rule
Cyble Vision: Malicious) - engine signal, weight 0.90, confidence 0.95 - Microsoft Defender flagged Trojan:WinNT/Fetrog.A (rule
Trojan:WinNT/Fetrog.A) - engine signal, weight 0.55, confidence 0.85 - Emsisoft (Emergency Kit) flagged Trojan.Agent.BHVJ (rule
Trojan.Agent.BHVJ) - engine signal, weight 0.55, confidence 0.85 - Detect It Easy (packer/type) flagged DIE:Microsoft Linker (rule
DIE:Microsoft Linker) - engine signal, weight 0.35, confidence 0.70 - Packing/obfuscation: Microsoft Linker - static signal, weight 0.25, confidence 0.55
Dynamic analysis (windows)
1 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- none
File paths
- c:\users\rmgree5\co\standalonegrok_2.1.1.1\gk_driver\gk_sa_driver\objfre_wnet_amd64\amd64\SaGk.pdb
More Fetrog samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report