MALICIOUS — INTC_BOOT.IMA
MALICIOUS — INTC_BOOT.IMA is a unknown sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (93/100), attributed to the UNOFFICIAL family. 2 of 46 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
5b9a87b1b38ec40bbce93f180e958237766ee64af550325f67bc4896ddcaa5d2 - SHA-1:
b5b143dd822a3bd16c69012e05d06a04d107444b - MD5:
26fd86a41abc424093ea8f3734c16430 - ssdeep:
24576:onDBUyUO6LYmzF7ctsoFmNPPPPPPPPPPPPPPPPPPPPPPPPPPPPPPPPPPPPPPPPP:onxODzpfoF - TLSH:
T1B6525BF4900B8A79F74C4389FC4244DC9AC35E6A692FC661B0089B3656E11F3DB6D2D2 - Submitted as: INTC_BOOT.IMA
- File type: unknown · Size: 921600 bytes
- Verdict: malicious (93/100) · Family: UNOFFICIAL
Source: theZoo · first seen 2026-07-26T03:29:57.426Z · SHA-256 not source-verified
Detections (2 of 46 engines)
- capa (capabilities): beacon to command-and-control
- ClamAV (daily): {HEX}bin.trojan.generic.int40.88.UNOFFICIAL
MITRE ATT&CK
Why this verdict
The malicious score of 93/100 is the fusion of 3 weighted signals:
- ClamAV (daily) flagged {HEX}bin.trojan.generic.int40.88.UNOFFICIAL (rule
{HEX}bin.trojan.generic.int40.88.UNOFFICIAL) - engine signal, weight 0.90, confidence 0.95 - beacon to command-and-control (rule
beacon to command-and-control) - capa signal, weight 0.45, confidence 0.80 - Embedded network infrastructure: http://www.nedstat.nl/cgi-bin/viewstat?name=midiwebcom, http://www.nedstat.nl/cgi-bin/nedstat.gif?name=midiwebcom, http://www.xscount.com/cgi/xsc.show?id= - static signal, weight 0.35, confidence 0.60
Embedded URLs
- http://www.nedstat.nl/cgi-bin/viewstat?name=midiwebcom
- http://www.nedstat.nl/cgi-bin/nedstat.gif?name=midiwebcom
- http://www.xscount.com/cgi/xsc.show?id=
- http://www.xscount.com/cgi/xsc.gif?id=
- http://www.xscount.com/cgi/xsc.show?id=midiwebcom
- http://www.xscount.com/cgi/xsc.gif?id=midiwebcom&ref=nojavascript&tc=notc
Embedded domains
- www.nedstat.nl
- www.xscount.com
- indyvax.iupui.edu
- bsu-cs.bsu.edu
- leo.bsuvc.bsu.edu
File paths
- D:\LANG\TC\INCLUDE\STDLIB.H
- D:\LANG\TC\INCLUDE\IOSTREAM.H
More UNOFFICIAL samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report