MALICIOUS — 5ce4e58cb88b7dc88396f316d0b85e1297598170e37a3366137b8d623a43a65d
MALICIOUS — 5ce4e58cb88b7dc88396f316d0b85e1297598170e37a3366137b8d623a43a65d is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (87/100), attributed to the Pwsx family. 5 of 52 detection engines flagged it.
Identification
- SHA-256:
5ce4e58cb88b7dc88396f316d0b85e1297598170e37a3366137b8d623a43a65d - SHA-1:
8f8e4a1ed6006236c00d4fb302a8fc3f6612df5e - MD5:
d11f731a25220bcd29cebc4c771523f6 - imphash:
d41d8cd98f00b204e9800998ecf8427e - ssdeep:
98304:1U3BhUKvDlARLczii8hKNIBFeKpAoVDkMQ26uYEAZVnXlTv:1KB/vDSRLcuFheCFLpvql2fOnXlb - TLSH:
T1DF60227CCD70D2BFFF7E0B97180256DE367A382C58A4285B000CBB11E91965727716AA - Submitted as: 5ce4e58cb88b7dc88396f316d0b85e1297598170e37a3366137b8d623a43a65d
- File type: pe · Size: 3521899 bytes
- Verdict: malicious (87/100) · Family: Pwsx
Detections (5 of 52 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-sections::jLr%*Z
- ClamAV (daily): Win.Packed.Pwsx-9908212-0
- Microsoft Defender: Trojan:MSIL/AgentTesla!MSR
- Emsisoft (Emergency Kit): Gen:Variant.MSILHeracles.46651
- Kaspersky (KVRT): HEUR:Trojan.MSIL.Gorgon.gen
Why this verdict
The malicious score of 87/100 is the fusion of 2 weighted signals:
- ClamAV (daily) flagged Win.Packed.Pwsx-9908212-0 (rule
Win.Packed.Pwsx-9908212-0) - engine signal, weight 0.90, confidence 0.95 - Packing/obfuscation: high-entropy-sections::jLr%*Z - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded domains
- o.pl
- z.su
File paths
- W:\O{
- W:\M
More Pwsx samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report