CLEAN — 57920c94c696f14eb2eb34e19ce6a5c3cf7e7d1bd32ef1d5d92adaec666103a3
CLEAN — 57920c94c696f14eb2eb34e19ce6a5c3cf7e7d1bd32ef1d5d92adaec666103a3 is a pe sample analyzed by MalwareAnalyzer by Cyble with a clean verdict (21/100). 2 of 55 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
57920c94c696f14eb2eb34e19ce6a5c3cf7e7d1bd32ef1d5d92adaec666103a3 - SHA-1:
b08c04487b5d37a3ee3533728c470be366465c30 - MD5:
9430e856cf4c099755cb06074e5af73e - imphash:
f34d5f2d4577ed6d9ceec516c1f5a744 - ssdeep:
384:25u8EPuWTUFSzLH+KLxItgxYQf/PZLHYLB5gmrpa4TqfKlNP:23aUFS3HFPXZEgmk4TNl9 - TLSH:
T1D7283CCA626C5B07D2B7E9273450E17D985274CE6BF1530C83C55A33266D933A83B22E - Submitted as: 57920c94c696f14eb2eb34e19ce6a5c3cf7e7d1bd32ef1d5d92adaec666103a3
- File type: pe · Size: 17139 bytes
- Verdict: clean (21/100)
Detections (2 of 55 engines)
- Emsisoft (Emergency Kit): Trojan.GenericKD.76004967
- Kaspersky (KVRT): HEUR:Trojan-Banker.MSIL.ClipBanker.gen
MITRE ATT&CK
Why this verdict
The clean score of 21/100 is the fusion of 1 weighted signal:
- persist via registry run key (rule
persist via registry run key) - capa signal, weight 0.35, confidence 0.60
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
File paths
- C:\Users\wordp\source\repos\WindowsApp1\WindowsApp1\obj\Debug\WindowsApp1.pdb
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report