SUSPICIOUS — 943d34d8b382a05a4b5115354362358cf1309c717f3b84c579b6442b713eb0ef
SUSPICIOUS — 943d34d8b382a05a4b5115354362358cf1309c717f3b84c579b6442b713eb0ef is a pe sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (40/100), attributed to the AntiDebug family. 3 of 52 detection engines flagged it.
Identification
- SHA-256:
943d34d8b382a05a4b5115354362358cf1309c717f3b84c579b6442b713eb0ef - SHA-1:
652a2cf177d6c29770101b679777e2de26063c28 - MD5:
889b6c225c66a045bb8163e9985491ef - imphash:
3eedf23f8b208860c154cc0073d0f2cc - ssdeep:
6144:00xmjpgEs2cc2RzaylQW85dlyaVdpe+1X7ptQRTe4E/8L:Nc932RzQW8NyabYqAhe4EEL - TLSH:
T1B448AF4E851F6B60C735DF106D41AE4E20E3309A34BDF8250583CD6E77E3523A972A6A - Submitted as: 943d34d8b382a05a4b5115354362358cf1309c717f3b84c579b6442b713eb0ef
- File type: pe · Size: 386387 bytes
- Verdict: suspicious (40/100) · Family: AntiDebug
Detections (3 of 52 engines)
- YARA: Yara-Rules community: YR_AntiDebug_Checks
- Emsisoft (Emergency Kit): Gen:Variant.Hancitor.2
- Kaspersky (KVRT): UDS:Trojan-Downloader.Win32.Squirelwaffle.gen
Why this verdict
The suspicious score of 40/100 is the fusion of 2 weighted signals:
- YARA: Yara-Rules community flagged YR_AntiDebug_Checks (rule
YR_AntiDebug_Checks) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: 6.1.4.4 - static signal, weight 0.35, confidence 0.60
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded IP addresses
- 6.1.4.4
File paths
- c:\Engine\Crop_enter\earth\Necessary.pdb
- N:\:e:n:x:
- M:\:m:t:
- L:\:a:f:w:
- P:\:h:t:
- X:\:`:d:h:l:p:t:x:
More AntiDebug samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report