MALICIOUS — 4bfe2216ee63657312af1b2507c8f2bf362fdf1d63c88faba397e880c2e39430
MALICIOUS — 4bfe2216ee63657312af1b2507c8f2bf362fdf1d63c88faba397e880c2e39430 is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (72/100), attributed to the Tedy family. 2 of 51 detection engines flagged it.
Identification
- SHA-256:
4bfe2216ee63657312af1b2507c8f2bf362fdf1d63c88faba397e880c2e39430 - SHA-1:
83e54cb97644de7084126e702937f8c3a2486a2f - MD5:
f8c8f6456c5a52ef24aa426e6b121685 - imphash:
b7321417f4c48bf8bd0eec82b2ce28de - ssdeep:
384:iJYYe70V0GkjlHqQJGGbXPNShorPuVdUgZHB8d0ldZfbpumRt1II2ZqumYqpD:rLl5qzYXPNShFF/ncmR/IJZbm91 - TLSH:
T15A2FA313A16B1391E2F9D5F1E869ACDC90867828A1F22DCCA743E4E190C8F6F50F58D5 - Submitted as: 4bfe2216ee63657312af1b2507c8f2bf362fdf1d63c88faba397e880c2e39430
- File type: pe · Size: 34304 bytes
- Verdict: malicious (72/100) · Family: Tedy
Detections (2 of 51 engines)
- Emsisoft (Emergency Kit): Gen:Variant.Tedy.166218
- Trellix Stinger (McAfee): Generic Trojan.he
Why this verdict
The malicious score of 72/100 is the fusion of 2 weighted signals:
- Emsisoft (Emergency Kit) flagged Gen:Variant.Tedy.166218 (rule
Gen:Variant.Tedy.166218) - engine signal, weight 0.55, confidence 0.85 - Trellix Stinger (McAfee) flagged Generic Trojan.he (rule
Generic Trojan.he) - engine signal, weight 0.55, confidence 0.85
Dynamic analysis (windows)
1 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- none
File paths
- d:\!work\etc\hideinstaller_kis2013\Bin\Debug\win7\x64\fsflt.pdb
- C:\Windows\System32\sysprep\CRYPTBASE.dll
More Tedy samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report