SUSPICIOUS — 82a0d00f3da7be4ac9eff2e5b165f06763f07e66cecc10d933d7848746e3ef3d
SUSPICIOUS — 82a0d00f3da7be4ac9eff2e5b165f06763f07e66cecc10d933d7848746e3ef3d is a pe sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (64/100), attributed to the Virut family. 5 of 52 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
82a0d00f3da7be4ac9eff2e5b165f06763f07e66cecc10d933d7848746e3ef3d - SHA-1:
83438fa904e0d42bf4427e297f620e4f880df7b8 - MD5:
1a055bc3886207b38136d5e87809454c - imphash:
ba2cfe060d1da5d6516ed0da35570ef3 - ssdeep:
768:jXBktp/gAkU27YgXBltix8G0kxfjaArWYV1eq/6crK3a:NAHkb8Qzin0kleA3Tua - TLSH:
T18134D0CDC42BD1E4F5E98AE234C636AC085A7112722D150DB5BFC1E417A61BB5D2890B - Submitted as: 82a0d00f3da7be4ac9eff2e5b165f06763f07e66cecc10d933d7848746e3ef3d
- File type: pe · Size: 53248 bytes
- Verdict: suspicious (64/100) · Family: Virut
Detections (5 of 52 engines)
- capa (capabilities): capability:collection/keylog
- Kaspersky (KVRT): Virus.Win32.Virut.ce
- Microsoft Defender: Trojan:Win32/Zusy.HNAA!MTB
- Emsisoft (Emergency Kit): Win32.Virtob.Gen.12
- Trellix Stinger (McAfee): W32/Virut.af.gen
MITRE ATT&CK
Why this verdict
The suspicious score of 64/100 is the fusion of 2 weighted signals:
- Kaspersky (KVRT) flagged Virus.Win32.Virut.ce (rule
Virus.Win32.Virut.ce) - engine signal, weight 0.55, confidence 0.85 - capture keystrokes (rule
capture keystrokes) - capa signal, weight 0.40, confidence 0.80
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
File paths
- C:\Program
More Virut samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report