SUSPICIOUS — 993030fd181cc67dcaa0948f536539aff5ae10bce1aff5265018aa335365e802.exe
SUSPICIOUS — 993030fd181cc67dcaa0948f536539aff5ae10bce1aff5265018aa335365e802.exe is a pe sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (59/100), attributed to the execute family. 5 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
993030fd181cc67dcaa0948f536539aff5ae10bce1aff5265018aa335365e802 - SHA-1:
3c8837bcb81a29e1e43556381977ec2f84f0ccd1 - MD5:
5a71c21a28192c43fc0f01a20fdfadde - imphash:
bc5915915ad1a7296140438aea2928df - ssdeep:
49152:lVhnUadGMDDMiIWGrjOFKuOTV27qOvzdxFV21QOFi:2a3piMOp2ldxFV - TLSH:
T17A5CBE6A012E2270E5FFE9847C6CEECC84B1B0995073DB4D9403DE3DD452937A9E12A9 - Submitted as: 993030fd181cc67dcaa0948f536539aff5ae10bce1aff5265018aa335365e802.exe
- File type: pe · Size: 2470912 bytes
- Verdict: suspicious (59/100) · Family: execute
Source: MalwareBazaar · first seen 2026-07-26T00:00:00.000Z · SHA-256 verified
Detections (5 of 53 engines)
- capa (capabilities): execute via PowerShell
- YARA: JPCERT/CC: JPCERT_HUILoader_PlugX_SideLoad
- Kaspersky (KVRT): Trojan.Win32.AntiVM.heu
- Microsoft Defender: Trojan:Win64/Aotera.RVG!MTB
- Emsisoft (Emergency Kit): Trojan.GenericKD.80943535
MITRE ATT&CK
Why this verdict
The suspicious score of 59/100 is the fusion of 3 weighted signals:
- execute via PowerShell (rule
execute via PowerShell) - capa signal, weight 0.40, confidence 0.80 - YARA: JPCERT/CC flagged JPCERT_HUILoader_PlugX_SideLoad (rule
JPCERT_HUILoader_PlugX_SideLoad) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: 4.2.1.0 - static signal, weight 0.35, confidence 0.60
Dynamic analysis (windows)
1 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- none
Embedded domains
- s.cf
Embedded IP addresses
- 4.2.1.0
More execute samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report