MALICIOUS — 483fe88d70cb09361c27468b97b7f96bd667d8c915c9f004a27d4260367d551b.exe
MALICIOUS — 483fe88d70cb09361c27468b97b7f96bd667d8c915c9f004a27d4260367d551b.exe is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (95/100), attributed to the MPRESS family. 7 of 26 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
483fe88d70cb09361c27468b97b7f96bd667d8c915c9f004a27d4260367d551b - SHA-1:
65cfa6529fee3dfee6b6d167fe4d1b7516630700 - MD5:
f33f63ad83374e4d819a3b90fd0e3d8a - imphash:
79b3362178937bf9559741c46bb9e035 - ssdeep:
49152:Ja9uzE/G9Cgie1HCY2KcarG8PGwuGR67JeygaPK6wY2CYXsiUb5hzMLDuZhF:U9uY/l8FHckG4674ygyK02bcZ5JMLD - TLSH:
T1405E3394ECEA9D39F075082151A7312B98FE85EC14007C2EA93AFF54868D11BDE736D2 - Submitted as: 483fe88d70cb09361c27468b97b7f96bd667d8c915c9f004a27d4260367d551b.exe
- File type: pe · Size: 2918912 bytes
- Verdict: malicious (95/100) · Family: MPRESS
Detections (7 of 26 engines)
- capa (capabilities): beacon to command-and-control
- MalwareAnalyser heuristics (entropy/packer): high-entropy-sections:.MPRESS1
- YARA: Yara-Rules community: YR_Packer_ASPack_MPRESS
- Cyble Vision: Cyble Vision: risk 60
- Detect It Easy (packer/type): DIE:MPRESS 1.27-2.12
- Kaspersky (KVRT): not-a-virus:NetTool.Win64.Agent.be
- Emsisoft (Emergency Kit): Trojan.Generic.35842563
MITRE ATT&CK
Why this verdict
The malicious score of 95/100 is the fusion of 5 weighted signals:
- Cyble Vision flagged Cyble Vision: risk 60 (rule
Cyble Vision: risk 60) - engine signal, weight 0.90, confidence 0.95 - beacon to command-and-control (rule
beacon to command-and-control) - capa signal, weight 0.45, confidence 0.80 - YARA: Yara-Rules community flagged YR_Packer_ASPack_MPRESS (rule
YR_Packer_ASPack_MPRESS) - engine signal, weight 0.35, confidence 0.70 - Detect It Easy (packer/type) flagged DIE:MPRESS 1.27-2.12 (rule
DIE:MPRESS 1.27-2.12) - engine signal, weight 0.35, confidence 0.70 - Packing/obfuscation: high-entropy-sections:.MPRESS1, MPRESS 1.27-2.12 - static signal, weight 0.25, confidence 0.55
Dynamic analysis (windows)
1 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- none
More MPRESS samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report