SUSPICIOUS — 59450aa592585b4a3e0fdcfa8ae76e06905102afd4fc0b86b56b5f0ae244fea3
SUSPICIOUS — 59450aa592585b4a3e0fdcfa8ae76e06905102afd4fc0b86b56b5f0ae244fea3 is a pe sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (51/100), attributed to the VMProtect family. 6 of 55 detection engines flagged it.
Identification
- SHA-256:
59450aa592585b4a3e0fdcfa8ae76e06905102afd4fc0b86b56b5f0ae244fea3 - SHA-1:
3f810382cbb66693ebb9599ab5fc5eec9f9d65c3 - MD5:
b350b4cfbee7b6656c128d0e41ea99d4 - imphash:
5e3037e8027c03026eb0d96b2c08d22d - ssdeep:
12288:WET7enAVM5Yjg8Bf+X8P1ILqTo+GOav1qbD3mS/c0UocQnOgZIcQXZGnCk:WpnhCgKPiLqTo+GL1u4X1CsXZGnV - TLSH:
T1FF50237308244FA2E251CB9F1D087E3D127458BE12A8ED4F9A98C94E1BB6CC351295FD - Submitted as: 59450aa592585b4a3e0fdcfa8ae76e06905102afd4fc0b86b56b5f0ae244fea3
- File type: pe · Size: 760615 bytes
- Verdict: suspicious (51/100) · Family: VMProtect
Detections (6 of 55 engines)
- MalwareAnalyser heuristics (entropy/packer): Themida/VMProtect
- YARA: Yara-Rules community: YR_Packer_VMProtect
- Detect It Easy (packer/type): DIE:Turbo Linker
- Microsoft Defender: Trojan:Win32/Convagent.EM!MTB
- Emsisoft (Emergency Kit): Gen:Variant.Barys.160809
- Kaspersky (KVRT): HEUR:Trojan.Win32.Convagent.gen
Why this verdict
The suspicious score of 51/100 is the fusion of 3 weighted signals:
- YARA: Yara-Rules community flagged YR_Packer_VMProtect (rule
YR_Packer_VMProtect) - engine signal, weight 0.35, confidence 0.70 - Detect It Easy (packer/type) flagged DIE:Turbo Linker (rule
DIE:Turbo Linker) - engine signal, weight 0.35, confidence 0.70 - Packing/obfuscation: Themida/VMProtect, high-entropy-sections:.vmp1, Turbo Linker - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
More VMProtect samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report