MALICIOUS — 54beb2f04abd2ef8d9938ea0f87ebb36ea4b057365144fc1de556f26d3a212d3
MALICIOUS — 54beb2f04abd2ef8d9938ea0f87ebb36ea4b057365144fc1de556f26d3a212d3 is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (91/100), attributed to the Zusy family. 6 of 52 detection engines flagged it.
Identification
- SHA-256:
54beb2f04abd2ef8d9938ea0f87ebb36ea4b057365144fc1de556f26d3a212d3 - SHA-1:
67de3d0acf0d41f2e91aba17c7abf3813920cc4d - MD5:
4582c1363e6c24e095c7925b5c1a55b8 - imphash:
f1a539a5b71ad53ac586f053145f08ec - ssdeep:
6144:SwaB8Kq8gAWZCZXrRosRxac16tUUQzGMsCam4:SDBq8gnU5rSBcnAy4 - TLSH:
T1DC4323B6A4945B00D7C16C8552B0E5DDFA337B8F74C055FAAE384A18337004B8AE74A7 - Submitted as: 54beb2f04abd2ef8d9938ea0f87ebb36ea4b057365144fc1de556f26d3a212d3
- File type: pe · Size: 238093 bytes
- Verdict: malicious (91/100) · Family: Zusy
Detections (6 of 52 engines)
- MalwareAnalyser heuristics (entropy/packer): UPX
- ClamAV (daily): Win.Malware.Zusy-9957983-0
- Detect It Easy (packer/type): DIE:UPX
- Microsoft Defender: Trojan:Win32/Prepscram!pz
- Emsisoft (Emergency Kit): Gen:Variant.Rootkit.25
- Kaspersky (KVRT): Trojan.Win32.Agent.neyndy
Why this verdict
The malicious score of 91/100 is the fusion of 3 weighted signals:
- ClamAV (daily) flagged Win.Malware.Zusy-9957983-0 (rule
Win.Malware.Zusy-9957983-0) - engine signal, weight 0.90, confidence 0.95 - Detect It Easy (packer/type) flagged DIE:UPX (rule
DIE:UPX) - engine signal, weight 0.35, confidence 0.70 - Packing/obfuscation: UPX, high-entropy-sections:UPX1 - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
More Zusy samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report