MALICIOUS — 6f30dbcf361e5bc663e4937869bc2645634a7ef9bf9fdc77aac30f49d42ffb21
MALICIOUS — 6f30dbcf361e5bc663e4937869bc2645634a7ef9bf9fdc77aac30f49d42ffb21 is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (91/100), attributed to the Cerber family. 6 of 52 detection engines flagged it.
Identification
- SHA-256:
6f30dbcf361e5bc663e4937869bc2645634a7ef9bf9fdc77aac30f49d42ffb21 - SHA-1:
5444c8a44a6c36e1e91fa73bb2888dc1ec12fabf - MD5:
988f5e1310ba802277f1ea4bcf0f5a45 - imphash:
9d560bb94b3a2b1bdd141d9b845d32ba - ssdeep:
3072:V1OaLScP5lL6UwS4oVemA6J2g7ke/PWiud3uWHWABIippBl:HOtcqUwS4JmA6Jl7F/PWiuvBRppBl - TLSH:
T14145CE422D1233BBD4FF633EE36D555EB05D58A4A8604B0C0296C251269D4EF2EDB2E3 - Submitted as: 6f30dbcf361e5bc663e4937869bc2645634a7ef9bf9fdc77aac30f49d42ffb21
- File type: pe · Size: 270696 bytes
- Verdict: malicious (91/100) · Family: Cerber
Detections (6 of 52 engines)
- MalwareAnalyser heuristics (entropy/packer): MPRESS
- ClamAV (daily): Win.Malware.Cerber-6803884-0
- Detect It Easy (packer/type): DIE:MPRESS
- Microsoft Defender: Trojan:Win32/Zbot.SIBL!MTB
- Emsisoft (Emergency Kit): Trojan.Lethic.Gen.11
- Kaspersky (KVRT): HEUR:Trojan.Win32.Generic
Why this verdict
The malicious score of 91/100 is the fusion of 3 weighted signals:
- ClamAV (daily) flagged Win.Malware.Cerber-6803884-0 (rule
Win.Malware.Cerber-6803884-0) - engine signal, weight 0.90, confidence 0.95 - Detect It Easy (packer/type) flagged DIE:MPRESS (rule
DIE:MPRESS) - engine signal, weight 0.35, confidence 0.70 - Packing/obfuscation: MPRESS - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
More Cerber samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report