MALICIOUS — 51925a1dfaa5278f9c60dd814c925d087c90f21b8be570d86c8f0685b806ab66
MALICIOUS — 51925a1dfaa5278f9c60dd814c925d087c90f21b8be570d86c8f0685b806ab66 is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (86/100), attributed to the Bublik family. 5 of 52 detection engines flagged it.
Identification
- SHA-256:
51925a1dfaa5278f9c60dd814c925d087c90f21b8be570d86c8f0685b806ab66 - SHA-1:
0397b74e55c2ed2834bbf2be89700f7f33168413 - MD5:
896a37ee167fe8f1a327b8537fcd093d - imphash:
027c8da71649e190289924ac24ae7f72 - ssdeep:
384:Izu49U1nYlSiWUdSWipFF9tohd4calJpjDjiHuzpf4uhZR03CaDF/cR0ITT0QJ:Ii49UCMUdSWU7tpjD1R4uh/03h/c+kvJ - TLSH:
T1712BED8E406D0E67C23718F65A32E84D618FB0E775DD36140F8EA03DA4D64E3DD1692A - Submitted as: 51925a1dfaa5278f9c60dd814c925d087c90f21b8be570d86c8f0685b806ab66
- File type: pe · Size: 24104 bytes
- Verdict: malicious (86/100) · Family: Bublik
Detections (5 of 52 engines)
- ClamAV (daily): Win.Malware.Bublik-10004834-0
- Microsoft Defender: TrojanDownloader:Win32/Upatre.AA
- Emsisoft (Emergency Kit): Trojan.GenericKD.1513778
- Trellix Stinger (McAfee): Downloader-FZY!896A37EE167F
- Kaspersky (KVRT): HEUR:Trojan.Win32.Generic
Why this verdict
The malicious score of 86/100 is the fusion of 1 weighted signal:
- ClamAV (daily) flagged Win.Malware.Bublik-10004834-0 (rule
Win.Malware.Bublik-10004834-0) - engine signal, weight 0.90, confidence 0.95
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
File paths
- C:\DOCUME~1\user\LOCALS~1\Temp\_AZTMP2_\Scan_001_23012014.exe
- C:\cjDtVS8e.exe
- C:\FX5cvC32.exe
- C:\l4soBZNj.exe
- C:\2TJWi82d.exe
- C:\PNfqFozn.exe
- C:\caeccca492265084918a5a0a6c86093f2388dbbb9cc4f04e1134cfbb56a19527
- C:\3929a54345a299da3047c487a6d52299e9c65964b1c1cec2585b4b55334f5e37
- C:\z5vTDzKM.exe
- C:\TSBXlfYK.exe
- C:\tvrql7aJ.exe
- C:\miZZAJvc.exe
- C:\nIELHJJr.exe
- C:\mw6ubP2Y.exe
- C:\kD2Bhhar.exe
- C:\cjmI8G_O.exe
- C:\m8K2DX7Q.exe
- C:\pGuBdxFC.exe
- C:\3culbe3y.exe
- C:\qVeqNiK3.exe
- C:\EqJMTzts.exe
- C:\455cacec0ff8fdad052d6f642c1b07ffb6a66807fc2610fd84821170a84e5189
- C:\c6625d79139ab64f3a899740df609e9546e6ad883c110cf15f8385cb74075ef0
- C:\ee114bab1a0436d15be364baa30b425cc63c812673aa58d1396c32732f34d307
- C:\139633f6bb98d6a9892fa1ad31c02546418dee890f335c45d3f862c7d5c0912b
More Bublik samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report