MALICIOUS — 775aec2c2dc252f73df19a3eee0355abda45f01b5fbdc4f5231b4a33cf62d811
MALICIOUS — 775aec2c2dc252f73df19a3eee0355abda45f01b5fbdc4f5231b4a33cf62d811 is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (94/100), attributed to the Zusy family. 7 of 52 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
775aec2c2dc252f73df19a3eee0355abda45f01b5fbdc4f5231b4a33cf62d811 - SHA-1:
7e446ed202450d7cc44883f44075de154605c29a - MD5:
cec8bc885ce4af46018f40f6db971d11 - imphash:
430f0d0eb90755dacb454d76817d014e - ssdeep:
1536:a7zfMMknJvVvwlTHavNbA8w9KxlO9Lc3Otp15wKwYPpLKu:ufMbJOZHaV7wdZcm19w6pH - TLSH:
T13F3ACFA62850CB34EADB2C1BD844E7EDF543EC0D1B34755E82AB97396384023E60539B - Submitted as: 775aec2c2dc252f73df19a3eee0355abda45f01b5fbdc4f5231b4a33cf62d811
- File type: pe · Size: 98328 bytes
- Verdict: malicious (94/100) · Family: Zusy
Detections (7 of 52 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-sections:.MPRESS1
- ClamAV (daily): Win.Malware.Zusy-10019934-0
- YARA: Yara-Rules community: YR_Packer_ASPack_MPRESS
- Detect It Easy (packer/type): DIE:MPRESS
- Microsoft Defender: Trojan:Win32/QQPass
- Emsisoft (Emergency Kit): Trojan.GenericKD.48349002
- Kaspersky (KVRT): Trojan.Win32.Scar.oetk
MITRE ATT&CK
Why this verdict
The malicious score of 94/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Win.Malware.Zusy-10019934-0 (rule
Win.Malware.Zusy-10019934-0) - engine signal, weight 0.90, confidence 0.95 - YARA: Yara-Rules community flagged YR_Packer_ASPack_MPRESS (rule
YR_Packer_ASPack_MPRESS) - engine signal, weight 0.35, confidence 0.70 - Detect It Easy (packer/type) flagged DIE:MPRESS (rule
DIE:MPRESS) - engine signal, weight 0.35, confidence 0.70 - communicate over HTTP (rule
communicate over HTTP) - capa signal, weight 0.30, confidence 0.60 - Packing/obfuscation: high-entropy-sections:.MPRESS1, MPRESS - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
More Zusy samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report