MALICIOUS — 9e90f288d109b86f1a65addddfab4769b6f4c2b2a33f55978015ab9c10ec8976
MALICIOUS — 9e90f288d109b86f1a65addddfab4769b6f4c2b2a33f55978015ab9c10ec8976 is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (93/100), attributed to the AntiDebug family. 7 of 55 detection engines flagged it.
Identification
- SHA-256:
9e90f288d109b86f1a65addddfab4769b6f4c2b2a33f55978015ab9c10ec8976 - SHA-1:
180bff334e8dec14936d5a53447e97cf31cddf32 - MD5:
cbf0a561ce8100c7b07ec9a69d165443 - imphash:
a5effb4de201aefae267d5eef9a314ac - ssdeep:
6144:u8QPRlDgdyabtBx81IChCuQS9KwQ08BpPRwHLVZ:6RlDgdyabt7QIChCuQShd8Grj - TLSH:
T199468DCD6618A745EA338E6A6D418F5D5407B0F8847E280C0E97D07E22F0C9BE8B657D - Submitted as: 9e90f288d109b86f1a65addddfab4769b6f4c2b2a33f55978015ab9c10ec8976
- File type: pe · Size: 297888 bytes
- Verdict: malicious (93/100) · Family: AntiDebug
Detections (7 of 55 engines)
- ClamAV (daily): Win.Malware.Generic-9908111-0
- YARA: Yara-Rules community: YR_AntiDebug_Checks
- LIEF (executable format parser): lief:invalid-authenticode
- Microsoft Defender: Ransom:Win32/StopCrypt.SG!MTB
- Emsisoft (Emergency Kit): Trojan.Crypt
- Trellix Stinger (McAfee): Packed-GDT!CBF0A561CE81
- Kaspersky (KVRT): UDS:Trojan.Win32.Strab.gen
Why this verdict
The malicious score of 93/100 is the fusion of 4 weighted signals:
- ClamAV (daily) flagged Win.Malware.Generic-9908111-0 (rule
Win.Malware.Generic-9908111-0) - engine signal, weight 0.90, confidence 0.95 - YARA: Yara-Rules community flagged YR_AntiDebug_Checks (rule
YR_AntiDebug_Checks) - engine signal, weight 0.35, confidence 0.70 - LIEF (executable format parser) flagged lief:invalid-authenticode (rule
lief:invalid-authenticode) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: 50.9.42.91, 2.8.5.21 - static signal, weight 0.35, confidence 0.60
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- http://crt.sectigo.com/SectigoPublicCodeSigningRootR46.p7c0#
- https://sectigo.com/CPS0
Embedded domains
- crl.comodoca.com
- crl.sectigo.com
- crt.sectigo.com
- sectigo.com
Embedded IP addresses
- 50.9.42.91
- 2.8.5.21
File paths
- f:\dd\vctools\crt_bld\self_x86\crt\src\_file.c
- f:\dd\vctools\crt_bld\self_x86\crt\src\_sftbuf.c
- f:\dd\vctools\crt_bld\self_x86\crt\src\output.c
- f:\dd\vctools\crt_bld\self_x86\crt\src\ioinit.c
- f:\dd\vctools\crt_bld\self_x86\crt\src\stdenvp.c
- f:\dd\vctools\crt_bld\self_x86\crt\src\stdargv.c
- f:\dd\vctools\crt_bld\self_x86\crt\src\a_env.c
- f:\dd\vctools\crt_bld\self_x86\crt\src\tidtable.c
- f:\dd\vctools\crt_bld\self_x86\crt\src\mlock.c
- f:\dd\vctools\crt_bld\self_x86\crt\src\mbctype.c
- f:\dd\vctools\crt_bld\self_x86\crt\src\_getbuf.c
- f:\dd\vctools\crt_bld\self_x86\crt\src\onexit.c
- C:\wudag\cap\bogos.pdb
- T:\:d:l:t:
- f:\dd\vctools\crt_bld\self_x86\crt\src\printf.c
- f:\dd\vctools\crt_bld\self_x86\crt\src\puts.c
- f:\dd\vctools\crt_bld\self_x86\crt\src\dbgrpt.c
- f:\dd\vctools\crt_bld\self_x86\crt\src\_flsbuf.c
- f:\dd\vctools\crt_bld\self_x86\crt\src\fwrite.c
- f:\dd\vctools\crt_bld\self_x86\crt\src\fileno.c
- f:\dd\vctools\crt_bld\self_x86\crt\src\dbgheap.c
- f:\dd\vctools\crt_bld\self_x86\crt\src\crt0msg.c
- f:\dd\vctools\crt_bld\self_x86\crt\src\isatty.c
- f:\dd\vctools\crt_bld\self_x86\crt\src\wctomb.c
- f:\dd\vctools\crt_bld\self_x86\crt\src\localref.c
More AntiDebug samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report