MALICIOUS — 7cd4596e01a473fd24f632fc66365122e58a7d22be4889a1ab6bf5935421b8f7
MALICIOUS — 7cd4596e01a473fd24f632fc66365122e58a7d22be4889a1ab6bf5935421b8f7 is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (95/100), attributed to the VMProtect family. 8 of 52 detection engines flagged it, exhibiting 2 ATT&CK techniques.
Identification
- SHA-256:
7cd4596e01a473fd24f632fc66365122e58a7d22be4889a1ab6bf5935421b8f7 - SHA-1:
1243db13c350833016b44cca4b1d0aa119f1dc18 - MD5:
07346bc8d6f92a7a1bfb90e92bea7ef8 - imphash:
2530491d48892f2e1a2d640515c13122 - ssdeep:
1536:g1VPvh/81hTx5n2sR7GCjdp87t92tzJOxvxgidzdRtk:gnu1hT2sR7o7tIExJFdxRtk - TLSH:
T11F3CE0A372051EA9D7BBFBFA5D477F9D0003602351BC24C84527180E7A9056B9AB72F2 - Submitted as: 7cd4596e01a473fd24f632fc66365122e58a7d22be4889a1ab6bf5935421b8f7
- File type: pe · Size: 117641 bytes
- Verdict: malicious (95/100) · Family: VMProtect
Detections (8 of 52 engines)
- MalwareAnalyser heuristics (entropy/packer): Themida/VMProtect
- ClamAV (daily): Win.Trojan.Agent-1388699
- YARA: Yara-Rules community: YR_Packer_VMProtect
- Detect It Easy (packer/type): DIE:MPRESS
- Microsoft Defender: Trojan:Win32/Vflooder!pz
- Emsisoft (Emergency Kit): Dump:Trojan.Agent.BYFH
- Trellix Stinger (McAfee): Agent-FEU!83C10D2F540B
- Kaspersky (KVRT): Trojan.Win32.Agent.iftf
MITRE ATT&CK
Why this verdict
The malicious score of 95/100 is the fusion of 6 weighted signals:
- ClamAV (daily) flagged Win.Trojan.Agent-1388699 (rule
Win.Trojan.Agent-1388699) - engine signal, weight 0.90, confidence 0.95 - YARA: Yara-Rules community flagged YR_Packer_VMProtect (rule
YR_Packer_VMProtect) - engine signal, weight 0.35, confidence 0.70 - Detect It Easy (packer/type) flagged DIE:MPRESS (rule
DIE:MPRESS) - engine signal, weight 0.35, confidence 0.70 - communicate over HTTP (rule
communicate over HTTP) - capa signal, weight 0.30, confidence 0.60 - Packing/obfuscation: Themida/VMProtect, MPRESS - static signal, weight 0.25, confidence 0.55
- enumerate processes (rule
enumerate processes) - capa signal, weight 0.20, confidence 0.60
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
More VMProtect samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report