SUSPICIOUS — Windows7ConfigSec.exe
SUSPICIOUS — Windows7ConfigSec.exe is a pe sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (51/100), attributed to the ASPack family. 4 of 55 detection engines flagged it.
Identification
- SHA-256:
611c662a013dd45db702741076115fa324308a62c93fa95f2a4724cee8ec30a6 - SHA-1:
dff4dd2fe9010860cadd56e728d168a4e0b75747 - MD5:
0cd332591f4fc8ab4b86da60e95f424e - imphash:
691f1193f16065947032ace3a2329e55 - ssdeep:
768:esHKmM0qauedFQFtxTXKXAx6ZQgZO+uxe7DDO:eZmMyTcTXfxhgZkwO - TLSH:
T1B52DD0E34001267FD5B8C47CAE852ACF107299A219F98EECD6CC041E12D9433997F2CA - Submitted as: Windows7ConfigSec.exe
- File type: pe · Size: 27648 bytes
- Verdict: suspicious (51/100) · Family: ASPack
Detections (4 of 55 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-sections:.MPRESS1
- YARA: Yara-Rules community: YR_Packer_ASPack_MPRESS
- Detect It Easy (packer/type): DIE:MPRESS
- Microsoft Defender: flagged
Why this verdict
The suspicious score of 51/100 is the fusion of 3 weighted signals:
- YARA: Yara-Rules community flagged YR_Packer_ASPack_MPRESS (rule
YR_Packer_ASPack_MPRESS) - engine signal, weight 0.35, confidence 0.70 - Detect It Easy (packer/type) flagged DIE:MPRESS (rule
DIE:MPRESS) - engine signal, weight 0.35, confidence 0.70 - Packing/obfuscation: high-entropy-sections:.MPRESS1, MPRESS - static signal, weight 0.25, confidence 0.55
Dynamic analysis (windows)
0 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- none
More ASPack samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report