MALICIOUS — 81d6f9fb15bba56214b03b8acf29466a91b382c47c2e348aec6edbcd7ecfd0ae
MALICIOUS — 81d6f9fb15bba56214b03b8acf29466a91b382c47c2e348aec6edbcd7ecfd0ae is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (94/100), attributed to the Zpevdo family. 7 of 52 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
81d6f9fb15bba56214b03b8acf29466a91b382c47c2e348aec6edbcd7ecfd0ae - SHA-1:
92ebb0a0c5456264d419d62fcd58002dec8bcf53 - MD5:
ad92dcd8bf1b6cedaca53d90b89db3e7 - imphash:
d41d8cd98f00b204e9800998ecf8427e - ssdeep:
1536:AsDGBTiEXDVLXkdRg+Xdsefzv/nCeKuqKTY+RAd3VGQbZhZLQ7g1Eh20PrBUP8X/:AU+NDpuRp7rbaKTYTu2ZhferBA8X0W - TLSH:
T19539E0CD103A7709CCEF1E13C6924EAEC4619EAFC2370A89524C7D61B9BC9736167089 - Submitted as: 81d6f9fb15bba56214b03b8acf29466a91b382c47c2e348aec6edbcd7ecfd0ae
- File type: pe · Size: 85814 bytes
- Verdict: malicious (94/100) · Family: Zpevdo
Detections (7 of 52 engines)
- capa (capabilities): capability:execution/powershell
- MalwareAnalyser heuristics (entropy/packer): Microsoft Linker
- ClamAV (daily): Win.Malware.Zpevdo-9950498-0
- Detect It Easy (packer/type): DIE:Microsoft Linker
- Microsoft Defender: flagged
- Emsisoft (Emergency Kit): Trojan.GenericKD.72309640
- Kaspersky (KVRT): UDS:Backdoor.MSIL.Bladabindi.gen
MITRE ATT&CK
Why this verdict
The malicious score of 94/100 is the fusion of 4 weighted signals:
- ClamAV (daily) flagged Win.Malware.Zpevdo-9950498-0 (rule
Win.Malware.Zpevdo-9950498-0) - engine signal, weight 0.90, confidence 0.95 - execute via PowerShell (rule
execute via PowerShell) - capa signal, weight 0.40, confidence 0.80 - Detect It Easy (packer/type) flagged DIE:Microsoft Linker (rule
DIE:Microsoft Linker) - engine signal, weight 0.35, confidence 0.70 - Packing/obfuscation: Microsoft Linker - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
More Zpevdo samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report