MALICIOUS — 9e26c61078335ede1fe8e9463e075b149b45ea829f24be32faa594708ea620cb
MALICIOUS — 9e26c61078335ede1fe8e9463e075b149b45ea829f24be32faa594708ea620cb is a zip sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (92/100), attributed to the Mydoom family. 6 of 51 detection engines flagged it.
Identification
- SHA-256:
9e26c61078335ede1fe8e9463e075b149b45ea829f24be32faa594708ea620cb - SHA-1:
17fe08b336844cc616a214e6ecedc7d13d0bce79 - MD5:
17fa1ba0a5e3c26a7292e6e010c5d6ac - ssdeep:
384:yvxBbK26lj5Id8SpHx9jLhsznnVxA1WmP5w7GGCJlqqwMyN4fHdt:0v8IRRdsxq1DjJcqflH - TLSH:
T1992DE0D444603CA3C1B29A859C444B7CE1624F3150BA29CCDE13B4A51BFF6EFE6B5262 - Submitted as: 9e26c61078335ede1fe8e9463e075b149b45ea829f24be32faa594708ea620cb
- File type: zip · Size: 28982 bytes
- Verdict: malicious (92/100) · Family: Mydoom
Detections (6 of 51 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Win.Worm.Mydoom-90
- Microsoft Defender: Worm:Win32/Mydoom.O@mm
- Emsisoft (Emergency Kit): Worm.Generic.24461
- Trellix Stinger (McAfee): W32/Mydoom.o.o@MM!zip
- Kaspersky (KVRT): Email-Worm.Win32.Mydoom.m
Why this verdict
The malicious score of 92/100 is the fusion of 4 weighted signals:
- ClamAV (daily) flagged Win.Worm.Mydoom-90 (rule
Win.Worm.Mydoom-90) - engine signal, weight 0.90, confidence 0.95 - Embedded executable payload carved at offset 40 - static signal, weight 0.40, confidence 0.70
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
- Archive contains executables: letter.bat - static signal, weight 0.25, confidence 0.50
Archive contents (1 executable)
This zip carries 1 extracted member, each analyzed as its own sample:
- letter.bat -
ebbf9b45ed59430a486d17d916cfb647e20eec494488622bcac94e47a098bfb9
Dynamic analysis (linux)
830 behavior events · 0 ATT&CK techniques · 1 dropped files.
Runtime network
- desktop-hsgcbep
- 250.255.255.239.in-addr.arpa
- 2.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 252.0.0.224.in-addr.arpa
- b.f.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 3.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- ff02::1:3
- 224.0.0.252
- 224.0.0.251
- ff02::fb
- 169.254.255.255
- 10.240.0.255
- 10.240.0.1
- ff02::16
- 224.0.0.22
- ff02::1:2
- ff02::1:ff4c:1d1d
- ff02::2
- 255.255.255.255
- ff02::1
Dropped files
- tmp_tmp.lqUcKfFNWh -
764d8f28262e158b6f7e8076cbae144ae0768e71ca7a6b20ce85fde5c597a550
More Mydoom samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report