MALICIOUS — 7b067a91d88ee1735a7b49fc197b9c85aaf89d6a734ca666f2a8bf4121df89f8
MALICIOUS — 7b067a91d88ee1735a7b49fc197b9c85aaf89d6a734ca666f2a8bf4121df89f8 is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (89/100), attributed to the Agentwdcr family. 4 of 55 detection engines flagged it.
Identification
- SHA-256:
7b067a91d88ee1735a7b49fc197b9c85aaf89d6a734ca666f2a8bf4121df89f8 - SHA-1:
ce96580e43ffe3e350c9d05c017cbfc7e1630cc1 - MD5:
708490e88c94d110bfbc256aac207d18 - imphash:
02e66475975b49c5175b8b7406061d0e - ssdeep:
384:cMNn5/Hkj5JhkMP+OijAA4cOYWO6O9OqeMUUVfTwk:v//O3+O54nUCfTwk - TLSH:
T1A42B71BD832F0A16C1339BD1CB32E44DA1AEFCF81D9DF61A584B503546C286FAC25525 - Submitted as: 7b067a91d88ee1735a7b49fc197b9c85aaf89d6a734ca666f2a8bf4121df89f8
- File type: pe · Size: 23480 bytes
- Verdict: malicious (89/100) · Family: Agentwdcr
Detections (4 of 55 engines)
- ClamAV (daily): Win.Trojan.Agentwdcr-2
- Microsoft Defender: TrojanDownloader:Win32/Upatre.AA
- Emsisoft (Emergency Kit): Trojan.AgentWDCR.AFH
- Kaspersky (KVRT): HEUR:Trojan.Win32.Generic
Why this verdict
The malicious score of 89/100 is the fusion of 2 weighted signals:
- ClamAV (daily) flagged Win.Trojan.Agentwdcr-2 (rule
Win.Trojan.Agentwdcr-2) - engine signal, weight 0.90, confidence 0.95 - Embedded network infrastructure: http://notepad-plus-plus.org/contributors - static signal, weight 0.35, confidence 0.60
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- http://notepad-plus-plus.org/contributors
Embedded domains
- notepad-plus-plus.org
File paths
- C:\Users\Jerry\Desktop\New
- C:\a4ae774dd79220a7d341e1a5f4e0c413be57e6e2ec8b8617c08e5e230cd36f5b
- C:\SRoJPo6y.exe
- C:\nlLcCBp3.exe
- C:\TsgGyN1p.exe
- C:\JM4EjzI1.exe
- C:\15572e0bd46962e456268d35b1bab5bbb433093a5daa9109c1f070136f23a856
- C:\Documents
- C:\uWqxXdhi.exe
- C:\hSqJEvV7.exe
- C:\Xtcnqstu.exe
- C:\DvZIsKl1.exe
- C:\z5v4Nrks.exe
- C:\951a6c95919bb803fc48d8addcef514e9ffb0d9e102fd28f52772f46a4697a16
- C:\27aff73f2041919d0a20b9f7d5dd315f7e20ea7e8cec8c690f7672a53889d85d
- C:\66e1c971dcde9033bff0b4a836d715a2db5370a4670e35a687f18a4e3c920022
- C:\fM4KYTW5.exe
- C:\GROogi_F.exe
- C:\Ks_GDH38.exe
- C:\kA5WH6RB.exe
- C:\fy7bNK6J.exe
- C:\tPT8hG_N.exe
- C:\xwrCqGpC.exe
- C:\cqUxzH7W.exe
- C:\JS1hjxHE.exe
More Agentwdcr samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report