SUSPICIOUS — image_rsrc1RE.jpg
SUSPICIOUS — image_rsrc1RE.jpg is a image sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (60/100). 1 of 54 detection engines flagged it.
Identification
- SHA-256:
451868e99982f4dd34ca10e96d7325b761fe3adecbd9f60d000d5aaf77058f35 - SHA-1:
0cf781c37da49f6d9d807cbe51af8641a54bb43c - MD5:
2b94651ca30969239a33b66a41818b5b - ssdeep:
768:qLvcyEzN6vIa92KoGU6R32K+LWqivsEck22mV7jM+fso/yQGobaC4wTMoRQXktvj:8E4vj2KTU++6t7N2rV/pIjNoQUtvhqGX - TLSH:
T19233021FA205397FD20CF96FA9CD2A2E146613CEE01B917654D2AEB8C3EE55163C4807 - Submitted as: image_rsrc1RE.jpg
- File type: image · Size: 49123 bytes
- Verdict: suspicious (60/100)
Detections (1 of 54 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
Why this verdict
The suspicious score of 60/100 is the fusion of 4 weighted signals:
- MalwareAnalyser heuristics (entropy/packer) flagged high-entropy-blob (rule
high-entropy-blob) - engine signal, weight 0.35, confidence 0.70 - QR code encodes a URL (quishing): https://me-qr.com/GlBjY24m - static signal, weight 0.35, confidence 0.65
- Embedded network infrastructure: https://me-qr.com/GlBjY24m - static signal, weight 0.35, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Embedded URLs
- https://me-qr.com/GlBjY24m
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report