MALICIOUS — 91018e44bcca550d00129d80d3cfeef8f9c539edcfdff8194a8d993dec974d9f
MALICIOUS — 91018e44bcca550d00129d80d3cfeef8f9c539edcfdff8194a8d993dec974d9f is a unknown sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (72/100). 2 of 54 detection engines flagged it.
Identification
- SHA-256:
91018e44bcca550d00129d80d3cfeef8f9c539edcfdff8194a8d993dec974d9f - SHA-1:
8e4d1facffa1b5c57fe2a9e2a83b0d1f7abfba77 - MD5:
a3738175f809f435a10d5e78c33611d4 - ssdeep:
48:6v96a/X6CFGFVD5f7iKn/wC8p8yTLJP3RGKMbnz0oZ2ml/sw1UzRafZm:RkTNP2Tz0oZ2ml/5hfZm - TLSH:
T1C915B863E2994FEF8A01B80800325073E4077BDB70703296B645D7D3DC2AE19B9200E7 - Submitted as: 91018e44bcca550d00129d80d3cfeef8f9c539edcfdff8194a8d993dec974d9f
- File type: unknown · Size: 2381 bytes
- Verdict: malicious (72/100)
Detections (2 of 54 engines)
- Microsoft Defender: Backdoor:ASP/WebShell.C!MTB
- Kaspersky (KVRT): Trojan.ASP.Agent.ck
Why this verdict
The malicious score of 72/100 is the fusion of 2 weighted signals:
- Microsoft Defender flagged Backdoor:ASP/WebShell.C!MTB (rule
Backdoor:ASP/WebShell.C!MTB) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged Trojan.ASP.Agent.ck (rule
Trojan.ASP.Agent.ck) - engine signal, weight 0.55, confidence 0.85
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded domains
- system.io
- usmr01exch01.g-c-i.com
File paths
- c:\windows\system32\cmd.exe
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report