SUSPICIOUS — 7458f3a8146a5f731699d68e1ac3d4f3d87525b020852b0bf8454fb44c1c77c6.exe
SUSPICIOUS — 7458f3a8146a5f731699d68e1ac3d4f3d87525b020852b0bf8454fb44c1c77c6.exe is a pe sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (54/100). 4 of 52 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
7458f3a8146a5f731699d68e1ac3d4f3d87525b020852b0bf8454fb44c1c77c6 - SHA-1:
82afcf65d159230d634a20dea703807f0f51efd0 - MD5:
cc709b7dbbdab599842ab059df4a379c - imphash:
f34d5f2d4577ed6d9ceec516c1f5a744 - ssdeep:
393216:aSmPFLktOFIEgcQXkoKbkXBF+8+ujG1uYh5F8NdiFl:aRNIEROHKoXBU+Glydin - TLSH:
T1B471334625150DC5A2A0E366EA60B9CF61BF49D668CC32DE60A10605FED244F73FB3E1 - Submitted as: 7458f3a8146a5f731699d68e1ac3d4f3d87525b020852b0bf8454fb44c1c77c6.exe
- File type: pe · Size: 17629696 bytes
- Verdict: suspicious (54/100)
Source: MalwareBazaar · first seen 2026-08-01T00:00:00.000Z · SHA-256 verified
Detections (4 of 52 engines)
- capa (capabilities): capability:execution/powershell
- MalwareAnalyser heuristics (entropy/packer): high-entropy-sections:.text
- Microsoft Defender: Trojan:MSIL/AsyncRAT.Z!MTB
- Kaspersky (KVRT): HEUR:Trojan-Dropper.MSIL.Dapato.gen
MITRE ATT&CK
Why this verdict
The suspicious score of 54/100 is the fusion of 3 weighted signals:
- execute via PowerShell (rule
execute via PowerShell) - capa signal, weight 0.40, confidence 0.80 - Embedded network infrastructure: 8.4.6.2 - static signal, weight 0.35, confidence 0.60
- Packing/obfuscation: high-entropy-sections:.text - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- http://www.w3.org/2001/XMLSchema-instance
Embedded domains
- 2.me
- v.co
- p3.pw
- o.ws
- g.io
- v8.es
- kk.sh
- k.us
- b.uk
- tm.fr
- w.ga
- 0v.fr
- www.w3.org
Embedded IP addresses
- 8.4.6.2
File paths
- S:\ic.
- S:\fB
- N:\yeX
- C:\M(
- r:\V
- f:\i
- T:\nS{
- z:\lOe
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report