MALICIOUS — 873_Win32.Turla.bin
MALICIOUS — 873_Win32.Turla.bin is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (92/100), attributed to the Turla family. 4 of 52 detection engines flagged it.
Identification
- SHA-256:
4c8b2e001dbf9e8b285c79514319e0a14dbb839998dd4d643d51fb11767d0cf9 - SHA-1:
3fa91f0f116cc0f19e8105bc51b91b7639605663 - MD5:
b46c792c8e051bc5c9d4cecab96e4c30 - imphash:
c57a86b0b1fc81afcd6682c7fd97d46a - ssdeep:
1536:skT8YmE3KZ1AIk23Y/VEJ0mP3azqQFKfCyLbM:ssTmE3wbZY/VEJ0mPKe4KfHLbM - TLSH:
T1E33B5BA952532551E0F6DE68EC20DDECC012B0FDD473288D6303DC5D98F1EBB89A1A88 - Submitted as: 873_Win32.Turla.bin
- File type: pe · Size: 106485 bytes
- Verdict: malicious (92/100) · Family: Turla
Detections (4 of 52 engines)
- Microsoft Defender: Backdoor:Win32/Turla.V!dha
- Emsisoft (Emergency Kit): Gen:Variant.Ulise.503269
- Trellix Stinger (McAfee): Generic Trojan.he
- Kaspersky (KVRT): HEUR:Backdoor.Win64.Generic
Why this verdict
The malicious score of 92/100 is the fusion of 4 weighted signals:
- Microsoft Defender flagged Backdoor:Win32/Turla.V!dha (rule
Backdoor:Win32/Turla.V!dha) - engine signal, weight 0.55, confidence 0.85 - Emsisoft (Emergency Kit) flagged Gen:Variant.Ulise.503269 (rule
Gen:Variant.Ulise.503269) - engine signal, weight 0.55, confidence 0.85 - Trellix Stinger (McAfee) flagged Generic Trojan.he (rule
Generic Trojan.he) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged HEUR:Backdoor.Win64.Generic (rule
HEUR:Backdoor.Win64.Generic) - engine signal, weight 0.55, confidence 0.85
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
More Turla samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report