SUSPICIOUS — nvrla.exe
SUSPICIOUS — nvrla.exe is a pe sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (61/100), attributed to the execute family. 2 of 53 detection engines flagged it, exhibiting 2 ATT&CK techniques.
Identification
- SHA-256:
85f57505d90815fa330ab752b0c50e8fa82273e3f0079ee0bc8e44a49d313773 - SHA-1:
f5653a48fb3c877aad80a60ffd6e05cf372cc36f - MD5:
0d7f6bf63342ed5f9a6802ea60a85b59 - imphash:
77f4479567ca2f74b70b68e9ac12d39e - ssdeep:
24576:uJSLAeyLDhhcY6yrpuMxJBKjNlfYU7kkiiQ72K8iCs+8bVtzOgzMyFnsOy9:umAeQDh2Y6yr1fKjffYUAkiiQ72K8s+3 - TLSH:
T1B3566B2582132133F1FAE854AC9199ECC072F5BCA4B5989DA307CC5E50E9E33D9E11A7 - Submitted as: nvrla.exe
- File type: pe · Size: 1389680 bytes
- Verdict: suspicious (61/100) · Family: execute
Detections (2 of 53 engines)
- capa (capabilities): execute via PowerShell
- YARA: Yara-Rules community: YR_AntiDebug_Checks
MITRE ATT&CK
Why this verdict
The suspicious score of 61/100 is the fusion of 4 weighted signals:
- execute via PowerShell (rule
execute via PowerShell) - capa signal, weight 0.40, confidence 0.80 - YARA: Yara-Rules community flagged YR_AntiDebug_Checks (rule
YR_AntiDebug_Checks) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: https://curl.se/docs/http-cookies.html, https://curl.se/docs/alt-svc.html, https://curl.se/docs/hsts.html - static signal, weight 0.35, confidence 0.60
- encrypt data (rule
encrypt data) - capa signal, weight 0.15, confidence 0.60
Dynamic analysis (windows)
1 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- none
Embedded URLs
- https://curl.se/docs/http-cookies.html
- https://curl.se/docs/alt-svc.html
- https://curl.se/docs/hsts.html
- http://www.digicert.com/CPS0
Embedded domains
- curl.se
- example.com
- cacerts.digicert.com
- crl3.digicert.com
- www.digicert.com
- crl4.digicert.com
Embedded IP addresses
- 1.101.3.4
More execute samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report