SUSPICIOUS — client32.exe
SUSPICIOUS — client32.exe is a pe sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (64/100), attributed to the RemoteAdmin family. 1 of 52 detection engines flagged it.
Identification
- SHA-256:
8000ffd1f8b32b4b85be9c3e730874865d949f9359c9a91c4386f4ff32deb180 - SHA-1:
94e8d9a259ddff360e0ea5b03580f672c66712c4 - MD5:
5f35710f5128ddf6eb2c89e724b83d11 - imphash:
a9d50692e95b79723f3e76fcf70d023e - ssdeep:
768:hEVZl6FhWr80/FK0r2bhuvtAKzCKZikGr2bhu2RPAKzCKZikZ:hG0hGNKU2huv+vv2huyYva - TLSH:
T1683C921C0AF4BB52D5361DE8483DECAFBB266388C67DC54E8231601E9253817449EFB5 - Submitted as: client32.exe
- File type: pe · Size: 120256 bytes
- Verdict: suspicious (64/100) · Family: RemoteAdmin
Detections (1 of 52 engines)
- Kaspersky (KVRT): not-a-virus:HEUR:RemoteAdmin.Win32.NetSup.gen
Why this verdict
The suspicious score of 64/100 is the fusion of 2 weighted signals:
- Kaspersky (KVRT) flagged not-a-virus:HEUR:RemoteAdmin.Win32.NetSup.gen (rule
not-a-virus:HEUR:RemoteAdmin.Win32.NetSup.gen) - engine signal, weight 0.55, confidence 0.85 - Contacted 23 external host(s) at runtime (6 HTTP) - network signal, weight 0.40, confidence 0.80
Dynamic analysis (windows)
0 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- www.msftconnecttest.com
- inference.location.live.net
- secure.globalsign.com
- ctldl.windowsupdate.com
- login.live.com
- v20.events.data.microsoft.com
- desktop-hsgcbep
- config.edge.skype.com
- windows.msn.com
- www.msn.com
- officeclient.microsoft.com
- odc.officeapps.live.com
- settings-win.data.microsoft.com
- licensing.mp.microsoft.com
- assets.msn.com
- www.bing.com
- fe3cr.delivery.mp.microsoft.com
- slscr.update.microsoft.com
- tas02.sls.update.microsoft.com
- v10.events.data.microsoft.com
Embedded URLs
- http://schemas.microsoft.com/SMI/2005/WindowsSettings
- http://schemas.microsoft.com/SMI/2016/WindowsSettings
- http://ocsp.globalsign.com/rootr30
- http://secure.globalsign.com/cacert/root-r3.crt06
- http://crl.globalsign.com/root-r3.crl0G
- https://www.globalsign.com/repository/0
- http://ocsp.globalsign.com/codesigningrootr450F
- http://secure.globalsign.com/cacert/codesigningrootr45.crt0A
- http://secure.globalsign.com/cacert/gsgccr45evcodesignca2020.crt0
- http://ocsp.globalsign.com/ca/gstsacasha384g40C
- http://ocsp2.globalsign.com/rootr606
- http://crl.globalsign.com/root-r6.crl0G
- http://www.msftconnecttest.com/connecttest.txt
- http://secure.globalsign.com/cacert/root-r3.crt
Embedded domains
- schemas.microsoft.com
- ocsp.globalsign.com
- secure.globalsign.com
- crl.globalsign.com
- www.globalsign.com
- ocsp2.globalsign.com
Embedded IP addresses
- 20.184.175.13
- 52.123.252.241
- 20.247.184.197
- 4.230.171.124
- 40.84.97.4
- 4.247.188.224
- 20.165.94.54
- 20.165.94.63
- 74.178.240.61
- 52.168.117.168
- 20.184.175.5
- 172.178.240.162
- 52.110.12.26
- 52.110.12.3
File paths
- E:\nsmsrc\nsm\1412\1412\client32\release_unicode\client32.pdb
More RemoteAdmin samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report