MALICIOUS — win32.exe
MALICIOUS — win32.exe is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (100/100), attributed to the Duqu family. 4 of 51 detection engines flagged it.
Identification
- SHA-256:
9d88425e266b3a74045186837fbd71de657b47d11efefcf8b3cd185a884b5306 - SHA-1:
b3074b26b346cb76605171ba19616baf821acf66 - MD5:
c9a31ea148232b201fe7cb7db5c75f5e - imphash:
c00e20f56d65068b81a1a5324d461344 - ssdeep:
384:bJu/osVhICBqnHH1vZGHvCzQ3T022+u/IlCq7HuekK4:lw/rBQnVgHvqQ392//MRkK4 - TLSH:
T1D82C6C8B7125E311C2B1FA785865CE8D20F1B45020B51F8C73A5C82DB1EBC1B557BA69 - Submitted as: win32.exe
- File type: pe · Size: 24960 bytes
- Verdict: malicious (100/100) · Family: Duqu
Detections (4 of 51 engines)
- ClamAV (daily): {MD5}bin.trojan.duqu.7908.UNOFFICIAL
- Cyble Vision: Cyble Vision: Malicious
- Microsoft Defender: Trojan:WinNT/Duqu.B
- Emsisoft (Emergency Kit): Gen:Variant.Duqu.1
Why this verdict
The malicious score of 100/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged {MD5}bin.trojan.duqu.7908.UNOFFICIAL (rule
{MD5}bin.trojan.duqu.7908.UNOFFICIAL) - engine signal, weight 0.90, confidence 0.95 - Cyble Vision flagged Cyble Vision: Malicious (rule
Cyble Vision: Malicious) - engine signal, weight 0.90, confidence 0.95 - Microsoft Defender flagged Trojan:WinNT/Duqu.B (rule
Trojan:WinNT/Duqu.B) - engine signal, weight 0.55, confidence 0.85 - Emsisoft (Emergency Kit) flagged Gen:Variant.Duqu.1 (rule
Gen:Variant.Duqu.1) - engine signal, weight 0.55, confidence 0.85 - Embedded network infrastructure: 4.33.0.12 - static signal, weight 0.35, confidence 0.60
Dynamic analysis (windows)
1 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- none
Embedded IP addresses
- 4.33.0.12
File paths
- V:\:h:s:
More Duqu samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report