MALICIOUS — 5ec715ffebb13abd55033956bbc72560804700287b40b7f800a78e688638f002
MALICIOUS — 5ec715ffebb13abd55033956bbc72560804700287b40b7f800a78e688638f002 is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (93/100), attributed to the Xanfpezes family. 7 of 52 detection engines flagged it.
Identification
- SHA-256:
5ec715ffebb13abd55033956bbc72560804700287b40b7f800a78e688638f002 - SHA-1:
17830ad5d3dca2c77ae2eeb5df7c23a01f3d65d8 - MD5:
5bde64b0a687e55c25675f322bd577de - imphash:
ff717ad06b5f3993c89b876c7cafd5e3 - ssdeep:
49152:EQFRHrmQG+dQG+W7RQG+ErmQG+dQG+W7kQG+dQG+fRQG+cQG+dQG+W7J+dQG+W7v:EcKebAeWeq5eaWe0nebAeWeq5e/j - TLSH:
T10F68121CAE7BA8C4C7FEDA7198A55E5F6A810A15823E0D3442A181317FDF933446732B - Submitted as: 5ec715ffebb13abd55033956bbc72560804700287b40b7f800a78e688638f002
- File type: pe · Size: 7926352 bytes
- Verdict: malicious (93/100) · Family: Xanfpezes
Detections (7 of 52 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-sections:,,,
- ClamAV (daily): Win.Trojan.Xanfpezes-9862383-0
- YARA: Yara-Rules community: YR_Packer_ASPack_MPRESS
- Detect It Easy (packer/type): DIE:Turbo Linker
- Microsoft Defender: flagged
- Emsisoft (Emergency Kit): Gen:Variant.Zusy.466969
- Kaspersky (KVRT): HEUR:Trojan.Win32.Generic
Why this verdict
The malicious score of 93/100 is the fusion of 4 weighted signals:
- ClamAV (daily) flagged Win.Trojan.Xanfpezes-9862383-0 (rule
Win.Trojan.Xanfpezes-9862383-0) - engine signal, weight 0.90, confidence 0.95 - YARA: Yara-Rules community flagged YR_Packer_ASPack_MPRESS (rule
YR_Packer_ASPack_MPRESS) - engine signal, weight 0.35, confidence 0.70 - Detect It Easy (packer/type) flagged DIE:Turbo Linker (rule
DIE:Turbo Linker) - engine signal, weight 0.35, confidence 0.70 - Packing/obfuscation: high-entropy-sections:,,,, Turbo Linker - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
More Xanfpezes samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report