MALICIOUS — 655b44d8c0fe5e162fc4948570c26c82981ae922b6614106af6a0cab5dca734b
MALICIOUS — 655b44d8c0fe5e162fc4948570c26c82981ae922b6614106af6a0cab5dca734b is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (82/100), attributed to the Rahiwi family. 5 of 25 detection engines flagged it.
Identification
- SHA-256:
655b44d8c0fe5e162fc4948570c26c82981ae922b6614106af6a0cab5dca734b - SHA-1:
0657ca0805b7f5076d67d952902772120fa6f1d2 - MD5:
2584375144443180c425152222e17b75 - imphash:
1b675db9a912fecbf83526e2fd37cf23 - ssdeep:
6144:2WC4YgB9GiyhWC4YgB9GiyoWC4YgB9GiyhWC4YgB9GiyhWC4YgB9Giyd:FtJ9GiJtJ9GiGtJ9GiJtJ9GiJtJ9Gi4 - TLSH:
T18243E1C3653A3616DED7B0FA2084150F67A9C4801C7BECD44E6B81187B2872B69FD867 - Submitted as: 655b44d8c0fe5e162fc4948570c26c82981ae922b6614106af6a0cab5dca734b
- File type: pe · Size: 233878 bytes
- Verdict: malicious (82/100) · Family: Rahiwi
Detections (5 of 25 engines)
- MalwareAnalyser heuristics (entropy/packer): Petite
- Detect It Easy (packer/type): DIE:Petite 2.2
- Microsoft Defender: Worm:Win32/Rahiwi!pz
- Emsisoft (Emergency Kit): Gen:Variant.Worm.VB.75
- Kaspersky (KVRT): Email-Worm.Win32.Brontok.am
Why this verdict
The malicious score of 82/100 is the fusion of 4 weighted signals:
- Microsoft Defender flagged Worm:Win32/Rahiwi!pz (rule
Worm:Win32/Rahiwi!pz) - engine signal, weight 0.55, confidence 0.85 - Emsisoft (Emergency Kit) flagged Gen:Variant.Worm.VB.75 (rule
Gen:Variant.Worm.VB.75) - engine signal, weight 0.55, confidence 0.85 - Detect It Easy (packer/type) flagged DIE:Petite 2.2 (rule
DIE:Petite 2.2) - engine signal, weight 0.35, confidence 0.70 - Packing/obfuscation: Petite, high-entropy-sections:.petite, Petite 2.2 - static signal, weight 0.25, confidence 0.55
Dynamic analysis (windows)
0 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- none
More Rahiwi samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report