MALICIOUS — 78c7bc3b21c28af4a97d2a269a27f4ad80119d6a7ba77d01745b4ba51ca0f253
MALICIOUS — 78c7bc3b21c28af4a97d2a269a27f4ad80119d6a7ba77d01745b4ba51ca0f253 is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (90/100), attributed to the Ursu family. 5 of 55 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
78c7bc3b21c28af4a97d2a269a27f4ad80119d6a7ba77d01745b4ba51ca0f253 - SHA-1:
70c27e4df62c271d20cedbaf76c5394f771e14c0 - MD5:
3a40e1be336cc159b8ed054c8c70eaf2 - imphash:
dae02f32a21e03ce65412f6e56942daa - ssdeep:
96:meavQzPTIkvjW1atEAesrwHgyzifwfe8Dl0PL/JK:UYImjWsEAeNHgRuDOk - TLSH:
T1461EE8C871380A51D375ED2E5556C4BFA4C2AC699833BA0C1E88123221A691BFE7517E - Submitted as: 78c7bc3b21c28af4a97d2a269a27f4ad80119d6a7ba77d01745b4ba51ca0f253
- File type: pe · Size: 6656 bytes
- Verdict: malicious (90/100) · Family: Ursu
Detections (5 of 55 engines)
- capa (capabilities): capability:execution/powershell
- ClamAV (daily): Win.Packed.Ursu-9757277-0
- Microsoft Defender: Trojan:MSIL/Fanny.DEA!MTB
- Emsisoft (Emergency Kit): Gen:Variant.Jalapeno.15606
- Kaspersky (KVRT): HEUR:Worm.MSIL.Agent.gen
MITRE ATT&CK
Why this verdict
The malicious score of 90/100 is the fusion of 2 weighted signals:
- ClamAV (daily) flagged Win.Packed.Ursu-9757277-0 (rule
Win.Packed.Ursu-9757277-0) - engine signal, weight 0.90, confidence 0.95 - execute via PowerShell (rule
execute via PowerShell) - capa signal, weight 0.40, confidence 0.80
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
More Ursu samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report