MALICIOUS — 713145f86ca7b506a01aefe116e78bac1b4ff42e79bb26e697977e8fcb4e02c4
MALICIOUS — 713145f86ca7b506a01aefe116e78bac1b4ff42e79bb26e697977e8fcb4e02c4 is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (89/100). 4 of 52 detection engines flagged it.
Identification
- SHA-256:
713145f86ca7b506a01aefe116e78bac1b4ff42e79bb26e697977e8fcb4e02c4 - SHA-1:
6bdbff11ac2d5b7e6c918cc830769bad3c66c9eb - MD5:
d5e033968ddbcee7e73b187d65006558 - imphash:
38aa7c2ff6ef0e48a9520d6702d08df4 - ssdeep:
1536:+0nERoZdnOmiZmEFMFnMsLaTMSFWjXUdeFQZZTGFWbE6bBMYoRoqiq8EpKP1dwL2:3nEOviMEFMFndLaTCzAZToEE6ooqiq8B - TLSH:
T12B397C6123660227C5F3CC66245CCE5C8023B8F871750BBCD28FF15C61A9BB766B6896 - Submitted as: 713145f86ca7b506a01aefe116e78bac1b4ff42e79bb26e697977e8fcb4e02c4
- File type: pe · Size: 90242 bytes
- Verdict: malicious (89/100)
Detections (4 of 52 engines)
- ClamAV (daily): Win.Trojan.Agent-6943819-1
- Microsoft Defender: flagged
- Emsisoft (Emergency Kit): Win32.Sivis.A
- Kaspersky (KVRT): Virus.Win32.Agent.es
Why this verdict
The malicious score of 89/100 is the fusion of 2 weighted signals:
- ClamAV (daily) flagged Win.Trojan.Agent-6943819-1 (rule
Win.Trojan.Agent-6943819-1) - engine signal, weight 0.90, confidence 0.95 - Embedded network infrastructure: http://creativecommons.org/publicdomain/zero/1.0/, http://www.gnu.org/licenses/, 2.7.6.1 - static signal, weight 0.35, confidence 0.60
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- http://creativecommons.org/publicdomain/zero/1.0/
- http://www.gnu.org/licenses/
Embedded domains
- creativecommons.org
- cwru.edu
- gnu.org
- www.gnu.org
- debian.org
Embedded IP addresses
- 2.7.6.1
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report