MALICIOUS — 5a8f9f9f3ab696b43484266e8764f7c65201d92091e2fc8f21da7d7fbe8660d6
MALICIOUS — 5a8f9f9f3ab696b43484266e8764f7c65201d92091e2fc8f21da7d7fbe8660d6 is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (89/100), attributed to the Msilkrypt family. 4 of 55 detection engines flagged it.
Identification
- SHA-256:
5a8f9f9f3ab696b43484266e8764f7c65201d92091e2fc8f21da7d7fbe8660d6 - SHA-1:
a0bc33bd71c9ce54ad386a2b2af1f4c232ae212e - MD5:
17d2d3bebec4c3becabc13d254ca6c19 - imphash:
f34d5f2d4577ed6d9ceec516c1f5a744 - ssdeep:
192:IBksuXm6N7oy1bEeMZZ3tw93VnjdwqzQ3T4aHx8:q4xZEeMRAFnhwqkDzR - TLSH:
T14A221BEF2D1C4A97CABED51B1171D93E549074AE24F1228C02085B335679423D87E7AA - Submitted as: 5a8f9f9f3ab696b43484266e8764f7c65201d92091e2fc8f21da7d7fbe8660d6
- File type: pe · Size: 9728 bytes
- Verdict: malicious (89/100) · Family: Msilkrypt
Detections (4 of 55 engines)
- ClamAV (daily): Win.Malware.Msilkrypt-9839010-0
- Microsoft Defender: PWS:MSIL/Infostealer.PAC!MTB
- Emsisoft (Emergency Kit): Gen:Trojan.Mardom.PN.15
- Kaspersky (KVRT): HEUR:Trojan.MSIL.Agent.gen
Why this verdict
The malicious score of 89/100 is the fusion of 2 weighted signals:
- ClamAV (daily) flagged Win.Malware.Msilkrypt-9839010-0 (rule
Win.Malware.Msilkrypt-9839010-0) - engine signal, weight 0.90, confidence 0.95 - Embedded network infrastructure: http://tempuri.org/IUserService/GetUsersT, http://194.87.145.184:6484/UserService, 194.87.145.184 - static signal, weight 0.35, confidence 0.60
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- http://tempuri.org/IUserService/GetUsersT
- http://194.87.145.184:6484/UserService
Embedded domains
- schemas.datacontract.org
- tempuri.org
Embedded IP addresses
- 194.87.145.184
More Msilkrypt samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report