MALICIOUS — 7786f0452d93b98ea015c4de1e9ee2376435738b10897177a846a04c5e5ed3f0
MALICIOUS — 7786f0452d93b98ea015c4de1e9ee2376435738b10897177a846a04c5e5ed3f0 is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (91/100), attributed to the Bqrf family. 6 of 55 detection engines flagged it.
Identification
- SHA-256:
7786f0452d93b98ea015c4de1e9ee2376435738b10897177a846a04c5e5ed3f0 - SHA-1:
3d63a5f85123c997e9456d26e116dbac91928c9e - MD5:
66e3076ab13fb0ef9042983f84d56bc3 - imphash:
5f8847412f1b132dc01729c2926126aa - ssdeep:
1536:nLNIW39SaZTbFARlq7jC1OZstZu0TS3gEdUJCkb0FG6:nLlbZTZX3BAtTS3gEdUJCkb0FG6 - TLSH:
T1D4389F58031BB385DAB6DB616DA19F1E30A3B0ED507F154C1AD3C12F62E2833E9D6189 - Submitted as: 7786f0452d93b98ea015c4de1e9ee2376435738b10897177a846a04c5e5ed3f0
- File type: pe · Size: 81980 bytes
- Verdict: malicious (91/100) · Family: Bqrf
Detections (6 of 55 engines)
- ClamAV (daily): Win.Malware.Bqrf-9645595-0
- LIEF (executable format parser): lief:invalid-authenticode
- Microsoft Defender: Backdoor:Win32/Rifdoor!pz
- Emsisoft (Emergency Kit): Trojan.Agent.BQRG
- Trellix Stinger (McAfee): Agent-FSC!66E3076AB13F
- Kaspersky (KVRT): Trojan-Dropper.Win32.Agent.sbni
Why this verdict
The malicious score of 91/100 is the fusion of 3 weighted signals:
- ClamAV (daily) flagged Win.Malware.Bqrf-9645595-0 (rule
Win.Malware.Bqrf-9645595-0) - engine signal, weight 0.90, confidence 0.95 - LIEF (executable format parser) flagged lief:invalid-authenticode (rule
lief:invalid-authenticode) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: http://sf.symcb.com/sf.crl0f, https://d.symcb.com/rpa0, http://sf.symcb.com/sf.crt0 - static signal, weight 0.35, confidence 0.60
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- http://schemas.microsoft.com/SMI/2005/WindowsSettings
- http://crl.thawte.com/ThawteTimestampingCA.crl0
- http://ts-aia.ws.symantec.com/tss-ca-g2.cer0
- http://ts-crl.ws.symantec.com/tss-ca-g2.crl0
- https://www.verisign.com/rpa
- http://sf.symcb.com/sf.crl0f
- https://d.symcb.com/rpa0
- http://sf.symcb.com/sf.crt0
- https://www.verisign.com/cps0*
- https://www.verisign.com/rpa0
- http://logo.verisign.com/vslogo.gif04
- http://crl.verisign.com/pca3-g5.crl04
Embedded domains
- schemas.microsoft.com
- crl.thawte.com
- ts-aia.ws.symantec.com
- ts-crl.ws.symantec.com
- www.verisign.com
- sf.symcb.com
- d.symcb.com
- logo.verisign.com
- crl.verisign.com
File paths
- E:\Data\My
More Bqrf samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report